Privacy-Preserving ML Inference Patents: Leader & Long Tail 2026
- One filer dominates. the leading assignee holds 52 of 67 records in scope, with four other ranked entities trailing far behind — down to a single filing for the fifth.
- Filing peaked in 2021 at 29 records and fell to 5 by 2024, an 83% drop over that span — though 2025-26 counts are still filling in as publication catches up with filing.
- Claims cluster in AI computing and data processing. 74.6% of records carry a G06N class and 64.2% carry G06F, while commerce-side G06Q applications sit at just 16.4%.
Filing growth compares 2021 (29 records) with 2024 (5) — a three-year span. 2024 is the most recent year we treat as complete: publication lags filing by roughly 18 months, so 2025 onwards are still filling in and any growth rate that ends there would understate the field. Top-5 share is the combined record count of the five largest assignees divided by all 67 records in scope (CR5), not by the ranked leaders only.
What this landscape covers
This landscape tracks patent families addressing privacy-preserving machine learning inference — techniques that let a model produce predictions without exposing the underlying data, the model weights, or both, to the counterparty running the computation. The search scope pulls records that discuss accuracy loss, latency overhead, plaintext inference, threat model, trust assumptions, or practicality alongside core terms like secure multiparty inference and encrypted model inference. That claim-description filter matters: it screens for filings that actually engage with the trade-offs of deploying these techniques, not just ones that mention privacy in passing.
67 records fall within scope, spanning filings from 2017 through a partial 2026 year. The assignee ranking returned by the data endpoint lists five companies, and together they account for all 67 records — there is no long tail of unranked filers sitting outside this group in the dataset as captured.
Filing trends and technology composition
The filing curve and the IPC breakdown together show a field that surged sharply, cooled off, and left its claim density concentrated in a narrow band of computing classes rather than spread across the stack.
A sharp rise and an unfinished decline
Filings sat at zero in 2017 and climbed to a peak of 29 records in 2021, then dropped to 5 by 2024 — an 83% decline over that three-year window. Because publication trails filing by roughly 18 months, the 2025 and 2026 figures are still incomplete and should not be read as continued decline; they simply have not finished arriving yet.
Concentration in AI and data-processing classes
G06N (computing arrangements based on AI models) appears in 74.6% of the 67 records, and G06F (electric digital data processing) in 64.2% — the two together anchor most filings. H04L (digital information transmission) shows up in 38.8%, consistent with the transport and protocol layer secure inference depends on, while G06Q (commerce and admin processing) trails at 16.4% and niche classes like G10L, A01K and A61P each sit under 5%, marking narrow application pockets rather than core claim territory.
Shares are the percentage of the 67 records in scope. A patent can carry several IPC classes, so the shares add up to more than 100%.
Go deeper on Privacy-Preserving Machine Learning Inference with Eureka
This page is one run against one query. Ask Eureka your own question about privacy-preserving machine learning inference and every answer comes back with the patent numbers behind it.
Try EurekaThe most-cited records in this scope
Privacy preserving machine learning via gradient boosting (US20230034384A1)
The filing describes a privacy-preserving machine learning platform in which a first computing system, one of several multi-party computation (MPC) systems, receives an inference request carrying a share of a user profile. It determines a predicted label from a first machine learning model plus a predicted residue value indicating the label's likely error, computing its own share of that residue from the profile share and a second model share held elsewhere in the MPC set.Filed by Google LLC, published 2023-02-02.


| # | Publication no. | Patent title | Citations |
|---|---|---|---|
| 1 | US20210049298A1 | Privacy preserving machine learning model training | 30 |
| 2 | US20230034384A1 | Privacy preserving machine learning via gradient boosting | 21 |
| 3 | US20230214684A1 | Privacy preserving machine learning using secure multi-party computation | 18 |
| 4 | US20230205915A1 | Privacy preserving machine learning for content distribution and analysis | 14 |
| 5 | US20210089819A1 | Privacy enhanced machine learning | 13 |
| 6 | US20230078704A1 | Privacy preserving machine learning labelling | 10 |
| 7 | WO2022169447A1 | Privacy preserving machine learning for content distribution and analysis | 6 |
| 8 | US20220318644A1 | Privacy preserving machine learning predictions | 6 |
| 9 | WO2022081150A1 | Privacy preserving machine learning predictions | 5 |
| 10 | US20250272585A1 | Training and performing inference operations of machine learning models using secure multi-party computation | 4 |
Citation counts inside a searched corpus favour older filings, since they have had more time to accumulate citations — treat this table as a signal of influence on the field, not a ranking of current relevance.
Each row carries its publication number; clicking a row searches Eureka by that number.
Put your own technology through the same analysis
Eureka on the web
When you want the answer in the next five minutes.
The agent works the prompt against patents and technical literature, citing every source.
Run your analysis now →MCP server & REST API
When it has to run inside your own pipeline.
Patent search, landscape analysis and assignee resolution as MCP tools. Drop them into any agent framework, or call REST directly.
Browse MCP servers →What the data means for a filing or freedom-to-operate decision
Three patterns stand out once the ranking, the trend and the class breakdown are read together: one filer's dominance, a filing wave that has already crested, and a technology stack that concentrates claims in a narrow set of computing classes.
One company sets the claim baseline
The leading assignee accounts for the large majority of records in scope, with the remaining four ranked entities holding far fewer each, down to a single filing for the fifth. Any freedom-to-operate review in this space has to start with that one portfolio rather than assume a fragmented field.
The 2021 filing wave has passed
Filings peaked at 29 in 2021 and fell to 5 by 2024, an 83% drop over three years. That decline reflects a real cooling after an initial surge of interest rather than a data artefact, though the very latest years are still incomplete due to publication lag.
Claims sit in core AI computing, not commerce applications
Three in four records touch AI-model computing classes and nearly two-thirds touch general digital data processing, while business and commerce-specific applications remain a minority. That split suggests the foundational inference mechanics are heavily claimed while sector-specific deployments are comparatively open.
Eureka can read the same corpus for gaps instead of for coverage: under-claimed branches adjacent to privacy-preserving machine learning inference, with the prior art for and against each one.
Who is filing, and where the gate sits
The ranking is short and top-heavy: one company's filings outnumber the other four combined many times over, and recent-year momentum shows even the active filers pulling back.
The dominant filer sets the terms
The top-ranked assignee's portfolio covers most of the scoped filings, meaning its claim scope on core MPC-based inference mechanics is the first thing to check before building anything adjacent. Its latest-year filing count fell 50% year-on-year, consistent with the broader post-2021 cooldown.
Institutional and enterprise filers hold small, static portfolios
The remaining four ranked assignees — spanning a software licensing arm, a financial institution, a research university and an IT services firm — each hold markedly fewer records than the leader, and most show zero filings in the latest year, including one entity down 100% year-on-year.
Filing is spread across four major offices
The United States leads receiving-office counts, but Europe, India and the WIPO/PCT route each carry a meaningful share, indicating that protection strategies in this space are not US-only. India's 13 filings in particular signal active regional interest beyond the traditional US/EPO axis.
| Assignee | Recent year | YoY |
|---|---|---|
| Google LLC | 1 | -50% |
| Microsoft Technology Licensing, LLC | 0 | — |
| JPMorgan Chase Bank, N.A. | 0 | — |
| Massachusetts Institute of Technology | 0 | -100% |
| Tata Consultancy Services Limited | 0 | — |
Where to take this next
The dataset points to a field with a dominant early filer, a cooled filing wave, and several under-claimed application branches. Turning that into a filing or freedom-to-operate decision means going deeper on the specific claims that matter to your use case.
Map the leader's claim boundaries
Before filing anything touching MPC-based inference, pull the leading assignee's full claim set to see exactly where its coverage starts and stops.
Explore assignee claims in EurekaCheck the under-claimed branches
Speech, agricultural and therapeutic-compound applications of secure inference show low record counts — worth a targeted search before assuming the space is open.
Run a white space search in EurekaTrack post-2024 filings as they publish
Because of publication lag, 2025-26 activity is still incomplete. Set up monitoring to catch new filings as they land rather than relying on the current partial-year counts.
Set up filing alerts in EurekaCommon questions about this landscape
One assignee holds 52 of the 67 records in scope for this dataset, making it by far the largest filer in the field as captured here. The remaining four ranked assignees hold much smaller portfolios, with the fifth-ranked entity holding only a single filing. Anyone assessing freedom-to-operate in this space should treat that leading portfolio as the primary reference point, since it covers the bulk of documented claim territory on secure multiparty inference and encrypted model inference.
Filing activity peaked in 2021 at 29 records and had fallen to 5 by 2024, an 83% decline over that three-year window. That is a genuine cooldown after an initial surge rather than a sign the technology is dead — filing waves like this often follow an early land-grab period. Note that 2025 and 2026 figures in any dataset will look artificially low because patent publication typically lags filing by about 18 months, so those recent years are not yet complete.
The dataset shows heavy concentration in two IPC subclasses: G06N, covering computing arrangements based on AI models, appears in 74.6% of the 67 records, and G06F, covering general electric digital data processing, appears in 64.2%. H04L, digital information transmission, shows up in 38.8% of records, reflecting the networking layer that secure inference protocols run over. Because records can carry multiple IPC classes, these percentages overlap and add to more than 100%.
The smallest IPC classes in this dataset — G10L (speech and audio), A01K (animal husbandry and fishing), and A61P (therapeutic activity of compounds) — each account for under 5% of the 67 records, suggesting these application branches have not been heavily claimed even though the underlying secure-inference mechanics are dense with prior art from the dominant filer. A first claim in one of these areas would likely combine a known MPC or homomorphic-inference technique with a domain-specific data pipeline, such as encrypted speech-feature extraction or field-sensor inference for livestock monitoring, rather than trying to claim new core cryptographic mechanics.
The United States leads with 24 filings among the receiving offices tracked, followed by the European Patent Office at 14 and India at 13, with the WIPO/PCT route accounting for 11 filings. Israel and Austria show minimal activity at 2 and 1 filings respectively. The spread across US, Europe, India and PCT filings indicates that protection strategies for privacy-preserving inference are pursued across multiple major markets rather than concentrated in a single jurisdiction.
Research Privacy-Preserving Machine Learning Inference in depth with Eureka
Go past this page: query the whole privacy-preserving machine learning inference corpus yourself, in your own scope.
Every answer comes back with patent numbers you can open.
Disclaimer. This page is generated from Patsnap Eureka data drawn from a limited snapshot of global patent and scientific-literature records, and is provided for general information and reference only.
Patent data carries inherent limitations: recent filings (typically the most recent 18–24 months) are under-counted due to standard publication lag; counts may be reported at either a patent-family or a patent-record basis and are not always directly comparable; classification, applicant-name, and citation data may contain errors, duplicates, or omissions; and the underlying search query defines and constrains the scope shown. As a result, the analysis may be incomplete or inaccurate and may not reflect the full technology landscape.
Nothing on this page constitutes an exhaustive prior-art, novelty, freedom-to-operate, or validity search, nor does it constitute legal, financial, investment, or professional advice, and it should not be relied upon as such. Any patent, commercial, or strategic decision should be verified independently and reviewed with qualified patent, legal, and domain professionals. Patsnap makes no warranties, express or implied, as to the accuracy, completeness, or fitness for any particular purpose of the information presented.
Machine translation. Assignee and organisation names originally recorded in Chinese, Japanese or Korean have been rendered into English by an AI translation step so that the tables stay readable. These renderings are best-effort and may not match a company’s registered English name; the original name is what the underlying patent record carries, and it is what any Eureka query launched from this page uses.