Mohammad Malekzadeh

Principal Scientist at Microsoft

prof_pic.jpg

As a member of Microsoft’s Applied Sciences Group, I develop efficient on-device machine learning models that bring faster, smarter AI to Windows and personal devices.

Previously, I was a Senior Research Scientist at Nokia Bell Labs, where I led the Device Intelligence team and worked with Prof. Fahim Kawsar and the wider Pervasive Systems team. We developed machine learning solutions for private data and personal devices, to advance personalized healthcare applications through multimodal sensing and on-device machine learning. We prioritized multi-modality, data and compute efficiency, individual privacy, and personalization to drive innovations that elevate human well-being. Explore our research papers and open-source code: CLEF, PaPaGei, CroSSL, PRIMUS, AdaBet, SoundCollage, Centaur, and Salted DNNs.

Before that, I was a Research Associate at Imperial College London, working with Prof. Deniz Gunduz and the IPC Lab team on Privacy-Preserving and Trustworthy Machine Learning. My postdoctoral work includes Dopamine and Honest-but-Curious Nets. During my PhD, I held a Research Assistant position at Imperial College London, where I contributed to the EPSRC Databox Project, engineering a privacy-aware analytics platform that empowers users to control personal data flow in IoT ecosystems.

I earned my PhD in Computer Science at Queen Mary University of London. I had the opportunity to work with Prof. Hamed Haddadi, Dr. Richard G. Clegg, and Prof. Andrea Cavallaro. My PhD research focused on developing machine learning algorithms for privacy-preserving personal data analytics, particularly for data captured by mobile and wearable devices. During my PhD, I also interned at Brave Software Research, where I explored privacy-preserving techniques to enhance content personalization. Open-source projects from my PhD include P2B, MotionSense, Replacement Autoencoder, and DANA.

Research & engineering

Selected projects & impact

All publications

Privacy in human sensing

Mitigating Privacy Leakage in Human Sensing

An anonymizer retains application-specific motion information while suppressing private information.
DANA architecture with dimension-adaptive pooling for sensor readings.

We created the MotionSense benchmark and developed on-device models that transform mobile and wearable sensor data to retain useful activity information while limiting identity leakage. We achieved over 92% activity recognition with under 7% re-identification in the reported sensing experiments.

Wearable intelligence

Physiology-Inspired Self-Supervised Learning for Wearable Intelligence

PaPaGei architecture using pulse morphology and signal-quality measures to learn PPG representations.
CLEF pretraining combines ECG signals and clinical metadata with contrastive learning.

We developed PaPaGei for optical pulse signals (PPG), PRIMUS for motion (IMU), and CLEF for ECG, bringing physiological knowledge, multimodal alignment, and clinical context into model pretraining. These open, reproducible models generalize across domains and populations; CLEF transfers knowledge from clinical 12-lead ECGs to single-lead wearables.

Collaborative learning

Private and Efficient Cross-Device Federated Learning

P2B combines randomized local reporting with a trusted shuffler to update a model using differentially private feedback.
Centaur distributes data selection and model training across constrained devices, access points, and a server.

We built P2B for differentially private personalization and Dopamine for private medical-image training, and co-led Centaur to make federated learning practical on constrained devices. Dopamine ranked first in the ITU privacy-preserving healthcare AI/ML competition; Centaur reduces storage, communication, and training latency.

Secure edge inference

Uncovering and Mitigating Vulnerabilities in ML Inference at the Edge

A client-side salt changes the interpretation of classifier outputs in a split neural network.
Honest-but-Curious Nets reveal sensitive attributes through classifier outputs.

We showed how classifier outputs can covertly reveal sensitive attributes and even enable input reconstruction. We then proposed Salted DNNs, a client-side defense for split inference. This defense makes outputs uninterpretable without the client’s salt, while preserving nearly identical accuracy and efficiency.