Differential privacy
Adds calibrated noise so that the presence or absence of any single record has a bounded effect on outputs — a standard countermeasure against inference about individual contributors. Composable with secure aggregation and TEEs.
Relates to: Membership inference.