I am a Computer Science PhD student at the University of British Columbia (UBC) Systopia Lab supervised by Mathias Lécuyer. I received my MSc. and B.S. in Statistics at UBC, where I was advised by Aline Talhouk and Lang Wu. In summer 2025, I worked with Sepid Hosseini, Mengyao Zhai and Thibaut Durand at RBC Borealis.

My research focuses on data privacy in machine learning, including (1) designing efficient privacy-preserving algorithms with provable guarantees, (2) auditing privacy leakage in trained machine learning models, and (3) adapting privacy tools to domain-specific problems, such as fair classification and test-time adaptation.

Selected Projects

See my Google Scholar profile for a full list.

Shared first authorship is denoted with *.


Private and Stable Test-time Adaptation with Differential Privacy
Zefeng Li*, Qiaoyue Tang*, Mathias Lécuyer, Evan Shelhamer
International Conference on Machine Learning (ICML) 2026
Paper

  • Improve test-time adaptation (TTA) performance using differentially private training techniques, enabling trained models to adapt to new and distributionally shifted test data with reduced error while preserving privacy guarantees.
  • Evaluate on pretrained ViT and ConvNeXT models using ImageNet-C and ImageNet-R corruption benchmarks.

FairNVT: Improving Fairness via Noise Injection in Vision Transformers
Qiaoyue Tang, Sepidehsadat Hosseini, Mengyao Zhai, Thibaut Durand, Greg Mori
Transactions on Machine Learning Research (TMLR) 2026
Also presented at Algorithmic Fairness Across Alignment Procedures and Agentic Systems (AFAA) Workshop @ ICLR 2026
Paper

  • Develop a unified framework that improves both prediction- and representation-level fairness when fine-tuning biased pretrained models for downstream tasks.
  • Show consistent fairness gains across vision and language benchmarks while preserving downstream accuracy.

On the Performance of Differentially Private Optimization with Heavy-Tail Class Imbalance
Qiaoyue Tang, Alain Zhiyanov, and Mathias Lécuyer
High-dimensional Learning Dynamics Workshop @ ICML 2025
Paper

  • Investigate the behavior of differentially private optimizers under heavy-tail class imbalance, a setting common in real-world data such as language modeling.

PANORAMIA: Privacy Auditing of Machine Learning Models without Retraining
Mishaal Kazmi*, Hadrien Lautraite*, Alireza Akbari*, Qiaoyue Tang*, Mauricio Soroco, Tao Wang, Sébastien Gambs, Mathias Lécuyer
Neural Information Processing Systems (NeurIPS) 2024
Also presented at Theory and Practice of Differential Privacy (TPDP) 2024
Paper / Code / Slides

  • Develop a retraining-free privacy auditing framework that uses synthetic non-member data to evaluate membership inference attacks on target models.
  • Perform theoretical analysis that establishes rigorous guidelines for privacy auditing under the proposed framework.

DP-AdamBC: Your DP-Adam Is Actually DP-SGD (Unless You Apply Bias Correction)
Qiaoyue Tang, Frederick Shpilevskiy, Mathias Lécuyer
AAAI Conference on Artificial Intelligence (AAAI) 2024 (Oral, 2.3%)
Also presented at Workshop on Trustworthy and Reliable Large-Scale Machine Learning Models @ ICLR 2023
Paper / Code / Slides

  • Demonstrate that DP noise biases Adam’s second moment estimator, collapsing DP-Adam into DP-SGD with momentum and breaking the sign-descent behavior that drives Adam’s performance.
  • Propose DP-AdamBC, a bias-corrected variant of DP-Adam, with accompanying theoretical analysis.

DP-SGD-LF: Improving Utility under Differentially Private Learning via Layer Freezing
Qiaoyue Tang, Mathias Lécuyer
Paper

  • Propose a layer-freezing variant of DP-SGD that improves utility at fixed privacy budget, supported by both theoretical analysis and empirical evaluation.