A financial services company trains a gradient-boosted classification model on a dataset that includes customer account balances. The security team wants to limit how much any single customer's balance can influence the model's learned parameters, because an attacker who obtains the trained model could otherwise probe it to recover specific training values. Which technique should they apply during training to cap the influence of individual records?
Differential privacy bounds each training record's contribution by clipping per-example gradients to a fixed norm, then adds calibrated noise to the aggregate update. This mathematically limits how much any one account balance can shift the learned parameters, so an attacker probing the released model cannot reliably infer whether a specific customer's record was present or recover its exact value.
Why this answer
Differential privacy with per-record gradient clipping and calibrated noise is the only listed technique that formally bounds how much any single training record can change the model's parameters. That bound is what prevents an attacker with access to the trained model from reliably reconstructing or confirming individual customer balances, whereas hashing, regularization, and at-rest encryption leave the influence of individual records unbounded.
Exam trap
The trap here is assuming that any privacy-preserving preprocessing step, such as hashing or encryption, limits how much a training record influences the model, when only differential privacy provides that formal bound.