I am a Computer Science PhD student at the University of British Columbia (UBC) Systopia Lab supervised by Mathias Lécuyer. I received my MSc. and B.S. in Statistics at UBC, where I was advised by Aline Talhouk and Lang Wu. In summer 2025, I worked with Sepid Hosseini, Mengyao Zhai and Thibaut Durand at RBC Borealis.
My research focuses on data privacy in machine learning, including (1) designing efficient privacy-preserving algorithms with provable guarantees, (2) auditing privacy leakage in trained machine learning models, and (3) adapting privacy tools to domain-specific problems, such as fair classification and test-time adaptation.
Selected Projects
See my Google Scholar profile for a full list.
Private and Stable Test-time Adaptation with Differential Privacy
Zefeng Li*, Qiaoyue Tang*, Mathias Lécuyer, Evan Shelhamer (* alphabetical order)
International Conference on Machine Learning (ICML) 2026
Paper
- Improve test-time adaptation (TTA) performance using differentially private training techniques, enabling trained models to adapt to new and distributionally shifted test data with reduced error while preserving privacy guarantees.
- Evaluate on pretrained ViT and ConvNeXT models using ImageNet-C and ImageNet-R corruption benchmarks.
FairNVT: Improving Fairness via Noise Injection in Vision Transformers
Qiaoyue Tang, Sepidehsadat Hosseini, Mengyao Zhai, Thibaut Durand, Greg Mori
Transactions on Machine Learning Research (TMLR) 2026
Paper
- Develop a unified framework that improves both prediction- and representation-level fairness when fine-tuning biased pretrained models for downstream tasks.
- Show consistent fairness gains across vision and language benchmarks while preserving downstream accuracy.
On the Performance of Differentially Private Optimization with Heavy-Tail Class Imbalance
Qiaoyue Tang, Alain Zhiyanov, and Mathias Lécuyer
High-dimensional Learning Dynamics Workshop @ ICML 2025
Paper
- Investigate the behavior of differentially private optimizers under heavy-tail class imbalance, a setting common in real-world data such as language modeling.
PANORAMIA: Privacy Auditing of Machine Learning Models without Retraining
Mishaal Kazmi*, Hadrien Lautraite*, Alireza Akbari*, Qiaoyue Tang*, Mauricio Soroco, Tao Wang, Sébastien Gambs, Mathias Lécuyer (* equal contribution)
Neural Information Processing Systems (NeurIPS) 2024
Paper / Code / Slides
- Develop a retraining-free privacy auditing framework that uses synthetic non-member data to evaluate membership inference attacks on target models.
- Perform theoretical analysis that establishes rigorous guidelines for privacy auditing under the proposed framework.
DP-AdamBC: Your DP-Adam Is Actually DP-SGD (Unless You Apply Bias Correction)
Qiaoyue Tang, Frederick Shpilevskiy, Mathias Lécuyer
AAAI Conference on Artificial Intelligence (AAAI) 2024 (Oral, 2.3%)
Also presented at Workshop on Trustworthy and Reliable Large-Scale Machine Learning Models @ ICLR 2023
Paper / Code / Slides
- Demonstrate that DP noise biases Adam’s second moment estimator, collapsing DP-Adam into DP-SGD with momentum and breaking the sign-descent behavior that drives Adam’s performance.
- Propose DP-AdamBC, a bias-corrected variant of DP-Adam, with accompanying theoretical analysis.
DP-SGD-LF: Improving Utility under Differentially Private Learning via Layer Freezing
Qiaoyue Tang, Mathias Lécuyer
Paper
- Propose a layer-freezing variant of DP-SGD that improves utility at fixed privacy budget, supported by both theoretical analysis and empirical evaluation.
