{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T13:17:31Z","timestamp":1782307051026,"version":"3.54.5"},"reference-count":123,"publisher":"Springer Science and Business Media LLC","issue":"8","license":[{"start":{"date-parts":[[2025,11,19]],"date-time":"2025-11-19T00:00:00Z","timestamp":1763510400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,11,19]],"date-time":"2025-11-19T00:00:00Z","timestamp":1763510400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["SN COMPUT. SCI."],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>Machine learning (ML) relies on data to train models and make predictions, but when multiple parties collaborate, data privacy concerns arise. Organisations often resort to data silos to protect sensitive information and intellectual property, limiting the potential benefits of joint learning. Collaborative Machine Learning (CML) seeks to address this challenge by enabling parties to share insights rather than raw data, enhancing privacy while maintaining model performance. However, research has shown that CML architectures remain vulnerable to attacks such as data reconstruction and inference, primarily due to shared elements like metadata, model parameters, and decisions, necessary for insight exchange. In response, various privacy-enhancing techniques have been proposed, each offering privacy protection for individual shared elements instead of all. In this Systematisation of Knowledge (SoK) paper, we analyse and categorise existing CML privacy solutions to assess their objectives. Based on this, we introduce a framework to systematically classify privacy guarantees across different approaches, providing a structured taxonomy. By defining distinct privacy classes and mapping solutions accordingly, our work seeks to empower stakeholders to make informed decisions when adopting CML strategies.<\/jats:p>","DOI":"10.1007\/s42979-025-04482-4","type":"journal-article","created":{"date-parts":[[2025,11,19]],"date-time":"2025-11-19T13:02:23Z","timestamp":1763557343000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["SoK: Towards Privacy-Centric Collaborative Machine Learning\u2014A Classification Framework for Privacy Solutions"],"prefix":"10.1007","volume":"6","author":[{"given":"Pakayal Edmond","family":"Boar","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6620-9083","authenticated-orcid":false,"given":"Pradip Kumar","family":"Sharma","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Raja Naeem","family":"Akram","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wanpeng","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,11,19]]},"reference":[{"issue":"12","key":"4482_CR1","doi-asserted-by":"publisher","first-page":"9625","DOI":"10.1109\/TNNLS.2022.3169347","volume":"34","author":"J Wang","year":"2022","unstructured":"Wang J, Pal A, Yang Q, Kant K, Zhu K, Guo S. Collaborative machine learning: schemes, robustness, and privacy. IEEE Trans Neural Netw Learn Syst. 2022;34(12):9625\u201342.","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"issue":"3","key":"4482_CR2","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1109\/MSP.2020.2975749","volume":"37","author":"T Li","year":"2020","unstructured":"Li T, Sahu AK, Talwalkar A, Smith V. Federated learning: challenges, methods, and future directions. IEEE Signal Process Mag. 2020;37(3):50\u201360.","journal-title":"IEEE Signal Process Mag"},{"key":"4482_CR3","unstructured":"Vepakomma P, Gupta O, Swedish T, Raskar R.: Split learning for health: Distributed deep learning without sharing raw patient data. 2018; arXiv preprint arXiv:1812.00564."},{"key":"4482_CR4","doi-asserted-by":"crossref","unstructured":"Thapa C, Arachchige PCM, Camtepe S, Sun L. Splitfed: when federated learning meets split learning. In: Proceedings of the AAAI Conference on Artificial Intelligence, 2022;36:8485\u20138493","DOI":"10.1609\/aaai.v36i8.20825"},{"issue":"1","key":"4482_CR5","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1038\/s41746-020-00323-1","volume":"3","author":"N Rieke","year":"2020","unstructured":"Rieke N, Hancox J, Li W, Milletari F, Roth HR, Albarqouni S, et al. The future of digital health with federated learning. NPJ Digit Med. 2020;3(1):119.","journal-title":"NPJ Digit Med"},{"key":"4482_CR6","unstructured":"Hard A, Rao K, Mathews R, Ramaswamy S, Beaufays F, Augenstein S, Eichner H, Kiddon C, Ramage D. Federated learning for mobile keyboard prediction. 2018. arXiv preprint arXiv:1811.03604."},{"issue":"2","key":"4482_CR7","doi-asserted-by":"publisher","first-page":"17","DOI":"10.1145\/3299887.3299891","volume":"47","author":"N Polyzotis","year":"2018","unstructured":"Polyzotis N, Roy S, Whang SE, Zinkevich M. Data lifecycle challenges in production machine learning: a survey. ACM SIGMOD Rec. 2018;47(2):17\u201328.","journal-title":"ACM SIGMOD Rec"},{"key":"4482_CR8","unstructured":"Fu C, Zhang X, Ji S, Chen J, Wu J, Guo S, Zhou J, Liu A.X, Wang T. Label inference attacks against vertical federated learning. In: 31st USENIX Security Symposium (USENIX Security 22), 2022;397\u20131414."},{"key":"4482_CR9","doi-asserted-by":"crossref","unstructured":"Hitaj B, Ateniese G, Perez-Cruz F. Deep models under the gan: information leakage from collaborative deep learning. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, 2017;603\u2013618.","DOI":"10.1145\/3133956.3134012"},{"key":"4482_CR10","unstructured":"Lyu L, Chen C. A novel attribute reconstruction attack in federated learning. 2021; arXiv preprint arXiv:2108.06910."},{"key":"4482_CR11","doi-asserted-by":"crossref","unstructured":"Pasquini D, Ateniese G, Bernaschi M. Unleashing the tiger: Inference attacks on split learning. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, 2021;2113\u20132129","DOI":"10.1145\/3460120.3485259"},{"key":"4482_CR12","doi-asserted-by":"crossref","unstructured":"Hu H, Salcic Z, Sun L, Dobbie G, Zhang X. Source inference attacks in federated learning. In: 2021 IEEE International Conference on Data Mining (ICDM), 2021;1102\u20131107. IEEE.","DOI":"10.1109\/ICDM51629.2021.00129"},{"issue":"3","key":"4482_CR13","doi-asserted-by":"publisher","first-page":"2031","DOI":"10.1109\/COMST.2020.2986024","volume":"22","author":"WYB Lim","year":"2020","unstructured":"Lim WYB, Luong NC, Hoang DT, Jiao Y, Liang Y-C, Yang Q, et al. Federated learning in mobile edge networks: A comprehensive survey. IEEE Communications Surveys & Tutorials. 2020;22(3):2031\u201363.","journal-title":"IEEE Communications Surveys & Tutorials"},{"issue":"6","key":"4482_CR14","doi-asserted-by":"publisher","first-page":"851","DOI":"10.1109\/TBDATA.2022.3159236","volume":"10","author":"C Chen","year":"2022","unstructured":"Chen C, Lyu L, Yu H, Chen G. Practical attribute reconstruction attack against federated learning. IEEE Trans Big Data. 2022;10(6):851\u201363.","journal-title":"IEEE Trans Big Data"},{"key":"4482_CR15","doi-asserted-by":"crossref","unstructured":"Shokri R, Strobel M, Zick Y. On the privacy risks of model explanations. In: Proceedings of the 2021 AAAI\/ACM Conference on AI, Ethics, and Society, 2021:231\u2013241.","DOI":"10.1145\/3461702.3462533"},{"key":"4482_CR16","unstructured":"Yang X, Sun J, Yao Y, Xie J, Wang C. Differentially private label protection in split learning. 2022; arXiv preprint arXiv:2203.02073."},{"issue":"11","key":"4482_CR17","doi-asserted-by":"publisher","first-page":"338","DOI":"10.3390\/fi14110338","volume":"14","author":"M Asad","year":"2022","unstructured":"Asad M, Aslam M, Jilani SF, Shaukat S, Tsukada M. Shfl: K-anonymity-based secure hierarchical federated learning framework for smart healthcare systems. Future Internet. 2022;14(11):338.","journal-title":"Future Internet"},{"issue":"4","key":"4482_CR18","doi-asserted-by":"publisher","first-page":"94","DOI":"10.3390\/fi13040094","volume":"13","author":"H Fang","year":"2021","unstructured":"Fang H, Qian Q. Privacy preserving machine learning with homomorphic encryption and federated learning. Future Internet. 2021;13(4):94.","journal-title":"Future Internet"},{"key":"4482_CR19","unstructured":"Pereteanu G-L, Alansary A, Passerat-Palmbach J. Split he: fast secure inference combining split learning and homomorphic encryption. 2022; arXiv preprint arXiv:2202.13351."},{"key":"4482_CR20","unstructured":"Ding S, Hu C. An investigation of smart contract for cml model training. 2022; arXiv preprint arXiv:2209.05017."},{"issue":"8","key":"4482_CR21","doi-asserted-by":"publisher","first-page":"4734","DOI":"10.1109\/TCOMM.2020.2990686","volume":"68","author":"SR Pokhrel","year":"2020","unstructured":"Pokhrel SR, Choi J. Federated learning with blockchain for autonomous vehicles: Analysis and design challenges. IEEE Trans Commun. 2020;68(8):4734\u201346.","journal-title":"IEEE Trans Commun"},{"key":"4482_CR22","unstructured":"Poirot MG, Vepakomma P, Chang K, Kalpathy-Cramer J, Gupta R, Raskar R. Split learning for collaborative deep learning in healthcare. 2019; arXiv preprint arXiv:1912.12115."},{"issue":"2","key":"4482_CR23","doi-asserted-by":"publisher","first-page":"72","DOI":"10.1109\/MWC.001.1900119","volume":"27","author":"J Kang","year":"2020","unstructured":"Kang J, Xiong Z, Niyato D, Zou Y, Zhang Y, Guizani M. Reliable federated learning for mobile networks. IEEE Wirel Commun. 2020;27(2):72\u201380.","journal-title":"IEEE Wirel Commun"},{"issue":"2","key":"4482_CR24","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3298981","volume":"10","author":"Q Yang","year":"2019","unstructured":"Yang Q, Liu Y, Chen T, Tong Y. Federated machine learning: concept and applications. ACM Trans Intell Syst Technol (TIST). 2019;10(2):1\u201319.","journal-title":"ACM Trans Intell Syst Technol (TIST)"},{"key":"4482_CR25","unstructured":"Lalitha A, Kilinc OC, Javidi T, Koushanfar F. Peer-to-peer federated learning on graphs. 2019; arXiv preprint arXiv:1901.11173."},{"issue":"2","key":"4482_CR26","doi-asserted-by":"publisher","first-page":"1631","DOI":"10.1007\/s11277-022-09624-y","volume":"125","author":"R Gupta","year":"2022","unstructured":"Gupta R, Alam T. Survey on federated-learning approaches in distributed environment. Wirel Pers Commun. 2022;125(2):1631\u201352.","journal-title":"Wirel Pers Commun"},{"issue":"16","key":"4482_CR27","doi-asserted-by":"publisher","first-page":"5983","DOI":"10.3390\/s22165983","volume":"22","author":"Q Duan","year":"2022","unstructured":"Duan Q, Hu S, Deng R, Lu Z. Combined federated and split learning in edge computing for ubiquitous intelligence in internet of things: state-of-the-art and future directions. Sensors. 2022;22(16):5983.","journal-title":"Sensors"},{"key":"4482_CR28","doi-asserted-by":"crossref","unstructured":"He Z, Zhang T, Lee RB. Model inversion attacks against collaborative inference. In: Proceedings of the 35th Annual Computer Security Applications Conference, 2019;148\u2013162.","DOI":"10.1145\/3359789.3359824"},{"key":"4482_CR29","doi-asserted-by":"publisher","unstructured":"Wang Z, Song M, Zhang Z, Song Y, Wang Q, Qi H. Beyond inferring class representatives: User-level privacy leakage from federated learning. In: IEEE INFOCOM 2019 - IEEE Conference on Computer Comms, 2019;2512\u20132520. https:\/\/doi.org\/10.1109\/INFOCOM.2019.8737416.","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"4482_CR30","unstructured":"Suri A, Kanani P, Marathe VJ, Peterson DW. Subject membership inference attacks in federated learning. 2022; arXiv preprint arXiv:2206.03317."},{"issue":"1","key":"4482_CR31","doi-asserted-by":"publisher","first-page":"118","DOI":"10.1109\/MNET.117.2200065","volume":"37","author":"Y-A Xie","year":"2022","unstructured":"Xie Y-A, Kang J, Niyato D, Van NTT, Luong NC, Liu Z, et al. Securing federated learning: a covert communication-based approach. IEEE Netw. 2022;37(1):118\u201324.","journal-title":"IEEE Netw"},{"key":"4482_CR32","doi-asserted-by":"crossref","unstructured":"Lyu L, Yu H, Yang Q. Threats to federated learning: a survey. 2020. arXiv preprint arXiv:2003.02133.","DOI":"10.1007\/978-3-030-63076-8_1"},{"issue":"1\u20132","key":"4482_CR33","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1561\/2200000083","volume":"14","author":"P Kairouz","year":"2021","unstructured":"Kairouz P, McMahan HB, Avent B, Bellet A, Bennis M, Bhagoji AN, et al. Advances and open problems in federated learning. Found Trends Mach Learn. 2021;14(1\u20132):1\u2013210.","journal-title":"Found Trends Mach Learn"},{"key":"4482_CR34","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1007\/s00357-020-09373-2","volume":"38","author":"MC Thrun","year":"2021","unstructured":"Thrun MC, Ultsch A. Using projection-based clustering to find distance-and density-based clusters in high-dimensional data. J Classif. 2021;38:280\u2013312.","journal-title":"J Classif"},{"key":"4482_CR35","doi-asserted-by":"crossref","unstructured":"Nguyen N-B, Chandrasegaran K, Abdollahzadeh M, Cheung N-M. Re-thinking model inversion attacks against deep neural networks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2023;16384\u201316393.","DOI":"10.1109\/CVPR52729.2023.01572"},{"key":"4482_CR36","doi-asserted-by":"crossref","unstructured":"Fredrikson M, Jha S, Ristenpart T. Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, 2015;1322\u20131333.","DOI":"10.1145\/2810103.2813677"},{"key":"4482_CR37","doi-asserted-by":"crossref","unstructured":"Shokri R, Stronati M, Song C, Shmatikov V. Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy (SP), 2017;3\u201318. IEEE.","DOI":"10.1109\/SP.2017.41"},{"issue":"1","key":"4482_CR38","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1109\/MSP.2017.2765202","volume":"35","author":"A Creswell","year":"2018","unstructured":"Creswell A, White T, Dumoulin V, Arulkumaran K, Sengupta B, Bharath AA. Generative adversarial networks: an overview. IEEE Signal Process Mag. 2018;35(1):53\u201365.","journal-title":"IEEE Signal Process Mag"},{"key":"4482_CR39","doi-asserted-by":"crossref","unstructured":"Xie Y, Chen B, Zhang J, Li W. Algans: enhancing membership inference attacks in federated learning with gans and active learning. In: 2022 IEEE International Symposium on Product Compliance Engineering-Asia (ISPCE-ASIA), 2022;1\u20136. IEEE.","DOI":"10.1109\/ISPCE-ASIA57917.2022.9971068"},{"issue":"2","key":"4482_CR40","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1109\/MSEC.2020.3039941","volume":"19","author":"MS Jere","year":"2020","unstructured":"Jere MS, Farnan T, Koushanfar F. A taxonomy of attacks on federated learning. IEEE Secur Privacy. 2020;19(2):20\u20138.","journal-title":"IEEE Secur Privacy"},{"key":"4482_CR41","unstructured":"Liu J, Lyu X. Clustering label inference attack against practical split learning. 2022. arXiv preprint arXiv:2203.05222."},{"key":"4482_CR42","unstructured":"Titcombe T, Hall AJ, Papadopoulos P, Romanini D. Practical defences against model inversion attacks for split neural networks. 2021. arXiv preprint arXiv:2104.05743."},{"key":"4482_CR43","doi-asserted-by":"crossref","unstructured":"Erdo\u011fan E, K\u00fcp\u00e7\u00fc A, \u00c7i\u00e7ek AE. Unsplit: data-oblivious model inversion, model stealing, and label inference attacks against split learning. In: Proceedings of the 21st Workshop on Privacy in the Electronic Society, 2022; 115\u2013124.","DOI":"10.1145\/3559613.3563201"},{"key":"4482_CR44","doi-asserted-by":"crossref","unstructured":"Li J, Rakin AS, Chen X, He Z, Fan D, Chakrabarti C. Ressfl: a resistance transfer framework for defending model inversion attack in split federated learning. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2022;10194\u201310202.","DOI":"10.1109\/CVPR52688.2022.00995"},{"key":"4482_CR45","doi-asserted-by":"crossref","unstructured":"Xu J, Hong C, Huang J, Chen LY, Decouchant J. Agic: approximate gradient inversion attack on federated learning. In: 2022 41st Int. Symposium on Reliable Distributed Systems (SRDS), 2022;12\u201322. IEEE.","DOI":"10.1109\/SRDS55811.2022.00012"},{"key":"4482_CR46","doi-asserted-by":"crossref","unstructured":"Nielsen C, Tuladhar A, Forkert ND. Investigating the vulnerability of federated learning-based diabetic retinopathy grade classification to gradient inversion attacks. In: International Workshop on Ophthalmic Medical Image Analysis, 2022;183\u2013192. Springer.","DOI":"10.1007\/978-3-031-16525-2_19"},{"key":"4482_CR47","first-page":"16937","volume":"33","author":"J Geiping","year":"2020","unstructured":"Geiping J, Bauermeister H, Dr\u00f6ge H, Moeller M. Inverting gradients-how easy is it to break privacy in federated learning? Adv Neural Inf Process Syst. 2020;33:16937\u201347.","journal-title":"Adv Neural Inf Process Syst"},{"key":"4482_CR48","doi-asserted-by":"publisher","first-page":"4984","DOI":"10.1109\/TIFS.2023.3302161","volume":"18","author":"H Liang","year":"2023","unstructured":"Liang H, Li Y, Zhang C, Liu X, Zhu L. Egia: an external gradient inversion attack in federated learning. IEEE Trans Inf Forensics Secur. 2023;18:4984\u201395.","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"6","key":"4482_CR49","doi-asserted-by":"publisher","first-page":"839","DOI":"10.1109\/TBDATA.2023.3239116","volume":"10","author":"J Geng","year":"2023","unstructured":"Geng J, Mou Y, Li Q, Li F, Beyan O, Decker S, et al. Improved gradient inversion attacks and defenses in federated learning. IEEE Trans Big Data. 2023;10(6):839\u201350.","journal-title":"IEEE Trans Big Data"},{"key":"4482_CR50","doi-asserted-by":"crossref","unstructured":"Melis L, Song C, De\u00a0Cristofaro E, Shmatikov V. Exploiting unintended feature leakage in collaborative learning. In: 2019 IEEE Symposium on Security and Privacy (SP), 2019;691\u2013706. IEEE.","DOI":"10.1109\/SP.2019.00029"},{"key":"4482_CR51","doi-asserted-by":"crossref","unstructured":"Luo X, Wu Y, Xiao X, Ooi BC. Feature inference attack on model predictions in vertical federated learning. In: 2021 IEEE 37th International Conference on Data Engineering (ICDE), 2021;181\u2013192. IEEE.","DOI":"10.1109\/ICDE51399.2021.00023"},{"key":"4482_CR52","doi-asserted-by":"crossref","unstructured":"Feng T, Hashemi H, Hebbar R, Annavaram M, Narayanan SS. Attribute inference attack of speech emotion recognition in federated learning settings. 2021. arXiv preprint arXiv:2112.13416.","DOI":"10.21437\/Interspeech.2022-10060"},{"key":"4482_CR53","unstructured":"Orekondy T, Oh SJ, Zhang Y, Schiele B, Fritz M. Gradient-leaks: understanding and controlling deanonymization in federated learning. 2018. arXiv preprint arXiv:1805.05838."},{"key":"4482_CR54","unstructured":"Gao X, Zhang L. $$\\{$$PCAT$$\\}$$: Functionality and data stealing from split learning by $$\\{$$Pseudo-Client$$\\}$$ attack. In: 32nd USENIX Security Symposium (USENIX Security 23), 2023;5271\u20135288."},{"key":"4482_CR55","doi-asserted-by":"crossref","unstructured":"Senavirathne N, Torra V. On the role of data anonymization in machine learning privacy. In: 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), 2020;664\u2013675. IEEE.","DOI":"10.1109\/TrustCom50675.2020.00093"},{"issue":"05","key":"4482_CR56","doi-asserted-by":"publisher","first-page":"557","DOI":"10.1142\/S0218488502001648","volume":"10","author":"L Sweeney","year":"2002","unstructured":"Sweeney L. k-anonymity: a model for protecting privacy. Internat J Uncertain Fuzziness Knowl-Based Syst. 2002;10(05):557\u201370.","journal-title":"Internat J Uncertain Fuzziness Knowl-Based Syst"},{"issue":"1","key":"4482_CR57","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1145\/1217299.1217302","volume":"1","author":"A Machanavajjhala","year":"2007","unstructured":"Machanavajjhala A, Kifer D, Gehrke J, Venkitasubramaniam M. l-diversity: privacy beyond k-anonymity. ACM Trans Knowl Discov Data (TKDD). 2007;1(1):3.","journal-title":"ACM Trans Knowl Discov Data (TKDD)"},{"key":"4482_CR58","doi-asserted-by":"crossref","unstructured":"Li N, Li T, Venkatasubramanian S. t-closeness: privacy beyond k-anonymity and l-diversity. In: 2007 IEEE 23rd International Conference on Data Engineering, 2006;106\u2013115. IEEE.","DOI":"10.1109\/ICDE.2007.367856"},{"key":"4482_CR59","unstructured":"Choudhury O, Gkoulalas-Divanis A, Salonidis T, Sylla I, Park Y, Hsu G, Das A. A syntactic approach for privacy-preserving federated learning. In: ECAI 2020, 2020;1762\u20131769."},{"key":"4482_CR60","doi-asserted-by":"crossref","unstructured":"Dwork C. Differential privacy. In: International Colloquium on Automata, Languages, and Programming, 2006;1\u201312. Springer.","DOI":"10.1007\/11787006_1"},{"key":"4482_CR61","doi-asserted-by":"publisher","unstructured":"Kim H, Doh I. Privacy enhanced federated learning utilizing differential privacy and interplanetary file system. In: 2023 International Conference on Information Networking (ICOIN), 2023;312\u2013317. https:\/\/doi.org\/10.1109\/ICOIN56518.2023.10049019.","DOI":"10.1109\/ICOIN56518.2023.10049019"},{"issue":"4","key":"4482_CR62","doi-asserted-by":"publisher","first-page":"446","DOI":"10.1016\/j.dcan.2021.11.006","volume":"8","author":"C Wang","year":"2022","unstructured":"Wang C, Wu X, Liu G, Deng T, Peng K, Wan S. Safeguarding cross-silo federated learning with local differential privacy. Digit Commun Netw. 2022;8(4):446\u201354.","journal-title":"Digit Commun Netw"},{"key":"4482_CR63","doi-asserted-by":"crossref","unstructured":"Abuadbba S, Kim K, Kim M, Thapa C, Camtepe SA, Gao Y, Kim H, Nepal S. Can we use split learning on 1d cnn models for privacy preserving training? In: Proceedings of the 15th ACM Asia Conference on Computer and Communications Security, 2020;305\u2013318.","DOI":"10.1145\/3320269.3384740"},{"key":"4482_CR64","doi-asserted-by":"crossref","unstructured":"Sun L, Qian J, Chen X. Ldp-fl: practical private aggregation in federated learning with local differential privacy. 2020. arXiv preprint arXiv:2007.15789.","DOI":"10.24963\/ijcai.2021\/217"},{"key":"4482_CR65","doi-asserted-by":"publisher","first-page":"3454","DOI":"10.1109\/TIFS.2020.2988575","volume":"15","author":"K Wei","year":"2020","unstructured":"Wei K, Li J, Ding M, Ma C, Yang HH, Farokhi F, et al. Federated learning with differential privacy: algorithms and performance analysis. IEEE Trans Inf Forensics Secur. 2020;15:3454\u201369. https:\/\/doi.org\/10.1109\/TIFS.2020.2988575.","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"3","key":"4482_CR66","doi-asserted-by":"publisher","first-page":"177","DOI":"10.1109\/MWC.015.2200462","volume":"31","author":"M Wu","year":"2023","unstructured":"Wu M, Cheng G, Li P, Yu R, Wu Y, Pan M, et al. Split learning with differential privacy for integrated terrestrial and non-terrestrial networks. IEEE Wirel Commun. 2023;31(3):177\u201384. https:\/\/doi.org\/10.1109\/MWC.015.2200462.","journal-title":"IEEE Wirel Commun"},{"issue":"4","key":"4482_CR67","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3214303","volume":"51","author":"A Acar","year":"2018","unstructured":"Acar A, Aksu H, Uluagac AS, Conti M. A survey on homomorphic encryption schemes: theory and implementation. ACM Comput Surv (Csur). 2018;51(4):1\u201335.","journal-title":"ACM Comput Surv (Csur)"},{"key":"4482_CR68","unstructured":"Khan T, Nguyen K, Michalas A. Split ways: privacy-preserving training of encrypted data using split learning. 2023. arXiv preprint arXiv:2301.08778."},{"key":"4482_CR69","unstructured":"Goldreich O. Secure multi-party computation. Manuscript. Preliminary version, 1998;78(110)."},{"issue":"8","key":"4482_CR70","doi-asserted-by":"publisher","first-page":"6178","DOI":"10.1109\/JIOT.2020.3022911","volume":"8","author":"Y Li","year":"2020","unstructured":"Li Y, Zhou Y, Jolfaei A, Yu D, Xu G, Zheng X. Privacy-preserving federated learning framework based on chained secure multiparty computing. IEEE Internet Things J. 2020;8(8):6178\u201386.","journal-title":"IEEE Internet Things J"},{"key":"4482_CR71","unstructured":"Li X, Dowsley R, De Cock M. Privacy-preserving feature selection with secure multiparty computation. In: International Conference on Machine Learning, 2021;6326\u20136336. PMLR."},{"key":"4482_CR72","unstructured":"Mugunthan V, Polychroniadou A, Byrd D, Balch TH. Smpai: secure multi-party computation for federated learning. In: Proceedings of the NeurIPS 2019 Workshop on Robust AI in Financial Services, 2019;1\u20139. MIT Press Cambridge, MA, USA."},{"key":"4482_CR73","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-70992-5","volume-title":"Privacy-Preserving Data Mining: Models and Algorithms","author":"CC Aggarwal","year":"2008","unstructured":"Aggarwal CC, Yu PS. Privacy-Preserving Data Mining: Models and Algorithms. New York, NY: Springer; 2008."},{"key":"4482_CR74","doi-asserted-by":"crossref","unstructured":"Jallepalli D, Ravikumar NC, Badarinath PV, Uchil S, Suresh MA. Federated learning for object detection in autonomous vehicles. In: 2021 IEEE Seventh International Conference on Big Data Computing, 2021;107\u2013114. IEEE.","DOI":"10.1109\/BigDataService52369.2021.00018"},{"issue":"5","key":"4482_CR75","doi-asserted-by":"publisher","first-page":"3241","DOI":"10.1109\/TWC.2020.2971981","volume":"19","author":"SR Pandey","year":"2020","unstructured":"Pandey SR, Tran NH, Bennis M, Tun YK, Manzoor A, Hong CS. A crowdsourcing framework for on-device federated learning. IEEE Trans Wirel Commun. 2020;19(5):3241\u201356.","journal-title":"IEEE Trans Wirel Commun"},{"key":"4482_CR76","unstructured":"Yang M, Lyu L, Zhao J, Zhu T, Lam K-Y. Local differential privacy and its applications: a comprehensive survey. 2020. arXiv preprint arXiv:2008.03686."},{"issue":"2","key":"4482_CR77","doi-asserted-by":"publisher","first-page":"734","DOI":"10.3390\/app12020734","volume":"12","author":"J Park","year":"2022","unstructured":"Park J, Lim H. Privacy-preserving federated learning using homomorphic encryption. Appl Sci. 2022;12(2):734.","journal-title":"Appl Sci"},{"key":"4482_CR78","doi-asserted-by":"publisher","unstructured":"Jallepalli D, Ravikumar NC, Badarinath PV, Uchil S, Suresh MA. Federated learning for object detection in autonomous vehicles. In: 2021 IEEE Seventh Int. Conference on Big Data, 2021. https:\/\/doi.org\/10.1109\/BigDataService52369.2021.00018.","DOI":"10.1109\/BigDataService52369.2021.00018"},{"key":"4482_CR79","unstructured":"Dwork C, Feldman V. Privacy-preserving prediction. In: Bubeck S, Perchet V, Rigollet P. (eds.) Proceedings of the 31st Conference on Learning Theory. Proceedings of Machine Learning Research, vol. 75, pp. 1693\u20131702. PMLR, Stockholm, Sweden. 2018. https:\/\/proceedings.mlr.press\/v75\/dwork18a.html."},{"key":"4482_CR80","unstructured":"Smilkov D, Thorat N, Kim B, Vi\u00e9gas F, Wattenberg M. Smoothgrad: removing noise by adding noise. 2017. arXiv preprint arXiv:1706.03825."},{"key":"4482_CR81","doi-asserted-by":"crossref","unstructured":"Jiang L, Tan R, Lou X, Lin G. On lightweight privacy-preserving collaborative learning for internet-of-things objects. In: Proceedings of the International Conference on Internet of Things Design and Implementation, 2019;70\u201381.","DOI":"10.1145\/3302505.3310070"},{"key":"4482_CR82","unstructured":"Bhowmick A, Duchi J, Freudiger J, Kapoor G, Rogers R. Protection against reconstruction and its applications in private federated learning. 2018. arXiv preprint arXiv:1812.00984."},{"key":"4482_CR83","doi-asserted-by":"crossref","unstructured":"Yang X, Feng Y, Fang W, Shao J, Tang X, Xia S-T, Lu R. An accuracy-lossless perturbation method for defending privacy attacks in federated learning. In: Proceedings of the ACM Web Conference 2022, 2022;732\u2013742.","DOI":"10.1145\/3485447.3512233"},{"key":"4482_CR84","doi-asserted-by":"crossref","unstructured":"Gade S, Vaidya NH. Privacy-preserving distributed learning via obfuscated stochastic gradients. In: 2018 IEEE Conference on Decision and Control (CDC), 2018;184\u2013191. IEEE.","DOI":"10.1109\/CDC.2018.8619133"},{"key":"4482_CR85","unstructured":"Geyer RC, Klein T, Nabi M. Differentially private federated learning: A client level perspective. 2017; arXiv preprint arXiv:1712.07557."},{"key":"4482_CR86","doi-asserted-by":"crossref","unstructured":"Hao M, Li H, Xu G, Liu S, Yang H. Towards efficient and privacy-preserving federated deep learning. In: ICC 2019-2019 IEEE International Conference on Communications, 2019;1\u20136. IEEE.","DOI":"10.1109\/ICC.2019.8761267"},{"issue":"10","key":"4482_CR87","doi-asserted-by":"publisher","first-page":"9530","DOI":"10.1109\/JIOT.2020.2991416","volume":"7","author":"R Hu","year":"2020","unstructured":"Hu R, Guo Y, Li H, Pei Q, Gong Y. Personalized federated learning with differential privacy. IEEE Internet Things J. 2020;7(10):9530\u20139.","journal-title":"IEEE Internet Things J"},{"key":"4482_CR88","doi-asserted-by":"crossref","unstructured":"Zhao Y, Zhao J, Yang M, Wang T, Wang N, Lyu L, Niyato D, Lam K-Y. Local differential privacy based federated learning for internet of things, 2020.","DOI":"10.1109\/JIOT.2020.3037194"},{"key":"4482_CR89","doi-asserted-by":"crossref","unstructured":"Truex S, Liu L, Chow K-H, Gursoy ME, Wei W. Ldp-fed: federated learning with local differential privacy. In: Proceedings of the Third ACM International Workshop on Edge Systems, Analytics and Networking, 2020;61\u201366.","DOI":"10.1145\/3378679.3394533"},{"key":"4482_CR90","doi-asserted-by":"crossref","unstructured":"Wang Y, Tong Y, Shi D. Federated latent dirichlet allocation: a local differential privacy based framework. In: Proceedings of the AAAI Conference on Artificial Intelligence, 2020;34:6283\u20136290.","DOI":"10.1609\/aaai.v34i04.6096"},{"key":"4482_CR91","doi-asserted-by":"crossref","unstructured":"Liu R, Cao Y, Yoshikawa M, Chen H. Fedsel: Federated sgd under local differential privacy with top-k dimension selection. In: Database Systems for Advanced Applications: 25th International Conference, DASFAA 2020, Jeju, South Korea, September 24\u201327, 2020, Proceedings, Part I 25, 2020;485\u2013501. Springer.","DOI":"10.1007\/978-3-030-59410-7_33"},{"issue":"5","key":"4482_CR92","doi-asserted-by":"publisher","first-page":"155014772091969","DOI":"10.1177\/1550147720919698","volume":"16","author":"H Cao","year":"2020","unstructured":"Cao H, Liu S, Zhao R, Xiong X. Ifed: a novel federated learning framework for local differential privacy in power internet of things. Int J Distrib Sens Netw. 2020;16(5):1550147720919698.","journal-title":"Int J Distrib Sens Netw"},{"issue":"3","key":"4482_CR93","doi-asserted-by":"publisher","first-page":"2134","DOI":"10.1109\/TII.2019.2942179","volume":"16","author":"Y Lu","year":"2019","unstructured":"Lu Y, Huang X, Dai Y, Maharjan S, Zhang Y. Differentially private asynchronous federated learning for mobile edge computing in urban informatics. IEEE Trans Ind Inf. 2019;16(3):2134\u201343.","journal-title":"IEEE Trans Ind Inf"},{"key":"4482_CR94","unstructured":"Naseri M, Hayes J, De Cristofaro E. Local and central differential privacy for robustness and privacy in federated learning. 2020. arXiv preprint arXiv:2009.03561."},{"issue":"13","key":"4482_CR95","doi-asserted-by":"publisher","first-page":"10639","DOI":"10.1109\/JIOT.2021.3050163","volume":"8","author":"M Wu","year":"2021","unstructured":"Wu M, Ye D, Ding J, Guo Y, Yu R, Pan M. Incentivizing differentially private federated learning: a multidimensional contract approach. IEEE Internet Things J. 2021;8(13):10639\u201351.","journal-title":"IEEE Internet Things J"},{"issue":"4","key":"4482_CR96","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1109\/MIS.2020.3010335","volume":"35","author":"H Zheng","year":"2020","unstructured":"Zheng H, Hu H, Han Z. Preserving user privacy for machine learning: local differential privacy or federated machine learning? IEEE Intell Syst. 2020;35(4):5\u201314.","journal-title":"IEEE Intell Syst"},{"key":"4482_CR97","doi-asserted-by":"crossref","unstructured":"Triastcyn A, Faltings B. Federated learning with bayesian differential privacy. In: 2019 IEEE International Conference on Big Data (Big Data), 2019;2587\u20132596. IEEE.","DOI":"10.1109\/BigData47090.2019.9005465"},{"key":"4482_CR98","doi-asserted-by":"crossref","unstructured":"Hong S, Lin X, Duan L. Lightweight federated learning with differential privacy and straggler resilience. 2024; arXiv preprint arXiv:2412.06120 [cs.LG].","DOI":"10.1109\/INFOCOM55648.2025.11044562"},{"issue":"4","key":"4482_CR99","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1109\/MIS.2020.2988604","volume":"35","author":"Y Chen","year":"2020","unstructured":"Chen Y, Qin X, Wang J, Yu C, Gao W. Fedhealth: a federated transfer learning framework for wearable healthcare. IEEE Intell Syst. 2020;35(4):83\u201393.","journal-title":"IEEE Intell Syst"},{"issue":"5","key":"4482_CR100","first-page":"1333","volume":"13","author":"Y Aono","year":"2017","unstructured":"Aono Y, Hayashi T, Wang L, Moriai S, et al. Privacy-preserving deep learning via additively homomorphic encryption. IEEE Trans Inf Forensics Secur. 2017;13(5):1333\u201345.","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"4482_CR101","doi-asserted-by":"crossref","unstructured":"Zhang J, Chen B, Yu S, Deng H. Pefl: a privacy-enhanced federated learning scheme for big data analytics. In: 2019 IEEE Global Comms Conference, 2019;1\u20136. IEEE.","DOI":"10.1109\/GLOBECOM38437.2019.9014272"},{"key":"4482_CR102","unstructured":"Zhang C, Li S, Xia J, Wang W, Yan F, Liu Y. $$\\{$$BatchCrypt$$\\}$$: Efficient homomorphic encryption for $$\\{$$Cross-Silo$$\\}$$ federated learning. In: 2020 USENIX Annual Technical Conference (USENIX ATC 20), 2020;493\u2013506."},{"key":"4482_CR103","doi-asserted-by":"crossref","unstructured":"Zhang X, Fu A, Wang H, Zhou C, Chen Z. A privacy-preserving and verifiable federated learning scheme. In: ICC 2020-2020 IEEE International Conference on Communications (ICC), 2020;1\u20136. IEEE.","DOI":"10.1109\/ICC40277.2020.9148628"},{"issue":"4","key":"4482_CR104","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1109\/MIS.2020.2988525","volume":"35","author":"Y Liu","year":"2020","unstructured":"Liu Y, Kang Y, Xing C, Chen T, Yang Q. A secure federated transfer learning framework. IEEE Intell Syst. 2020;35(4):70\u201382.","journal-title":"IEEE Intell Syst"},{"issue":"8","key":"4482_CR105","doi-asserted-by":"publisher","first-page":"2864","DOI":"10.3390\/app10082864","volume":"10","author":"M Asad","year":"2020","unstructured":"Asad M, Moustafa A, Ito T. Fedopt: towards communication efficiency and privacy preservation in federated learning. Appl Sci. 2020;10(8):2864.","journal-title":"Appl Sci"},{"key":"4482_CR106","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2020.101824","volume":"94","author":"Y Dong","year":"2020","unstructured":"Dong Y, Chen X, Shen L, Wang D. Eastfly: efficient and secure ternary federated learning. Comput Secur. 2020;94:101824.","journal-title":"Comput Secur"},{"key":"4482_CR107","unstructured":"Hardy S, Henecka W, Ivey-Law H, Nock R, Patrini G, Smith G, Thorne B. Private federated learning on vertically partitioned data via entity resolution and additively homomorphic encryption. 2017; arXiv preprint arXiv:1711.10677."},{"key":"4482_CR108","doi-asserted-by":"crossref","unstructured":"Szatmari T-I, Petersen MK, Korzepa MJ, Giannetsos T. Modelling audiological preferences using federated learning. In: Adjunct Publication of the 28th ACM Conference on User Modeling, Adaptation and Personalization, 2020;187\u2013190.","DOI":"10.1145\/3386392.3399560"},{"key":"4482_CR109","unstructured":"Choi B, Sohn J-y, Han D-J, Moon J. Communication-computation efficient secure aggregation for federated learning. 2020. arXiv preprint arXiv:2012.05433."},{"key":"4482_CR110","doi-asserted-by":"crossref","unstructured":"Gao D, Liu Y, Huang A, Ju C, Yu H, Yang Q. Privacy-preserving heterogeneous federated transfer learning. In: 2019 IEEE International Conference on Big Data (Big Data), 2019;2552\u20132559. IEEE.","DOI":"10.1109\/BigData47090.2019.9005992"},{"key":"4482_CR111","unstructured":"Reich D, Todoki A, Dowsley R, De Cock M, et al. Privacy-preserving classification of personal text messages with secure multi-party computation. Advances in Neural Information Processing Systems 2019;32."},{"key":"4482_CR112","unstructured":"Reich D, Todoki A, Dowsley R, De Cock M, Nascimento A. Privacy-preserving classification of personal text messages with secure multi-party computation: an application to hate-speech detection. Proceedings of the 33rd International Conference on Neural Information Processing Systems. Curran Associates Inc., Red Hook, NY, USA, 2019; Article 337, 3757\u201369."},{"key":"4482_CR113","doi-asserted-by":"crossref","unstructured":"Xu R, Baracaldo N, Zhou Y, Anwar A, Ludwig H. Hybridalpha: An efficient approach for privacy-preserving federated learning. In: Proceedings of the 12th ACM Workshop on Artificial Intelligence and Security, 2019;13\u201323.","DOI":"10.1145\/3338501.3357371"},{"key":"4482_CR114","doi-asserted-by":"crossref","unstructured":"Bonawitz K, Ivanov V, Kreuter B, Marcedone A, McMahan HB, Patel S, Ramage D, Segal A, Seth K. Practical secure aggregation for privacy-preserving machine learning. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, 2017;1175\u20131191.","DOI":"10.1145\/3133956.3133982"},{"key":"4482_CR115","unstructured":"Chang H, Shejwalkar V, Shokri R, Houmansadr A. Cronus: Robust and heterogeneous collaborative learning with black-box knowledge transfer. 2019. arXiv preprint arXiv:1912.11279."},{"key":"4482_CR116","unstructured":"Heikkil\u00e4 MA. On joint noise scaling in differentially private federated learning with multiple local steps. 2024. arXiv preprint arXiv:2407.19286 [cs.LG]."},{"issue":"1","key":"4482_CR117","doi-asserted-by":"publisher","first-page":"233","DOI":"10.3390\/s25010233","volume":"25","author":"Y Dong","year":"2025","unstructured":"Dong Y, Luo W, Wang X, Zhang L, Xu L, Zhou Z, et al. Multi-task federated split learning across multi-modal data with privacy preservation. Sensors. 2025;25(1):233. https:\/\/doi.org\/10.3390\/s25010233.","journal-title":"Sensors"},{"key":"4482_CR118","doi-asserted-by":"crossref","unstructured":"Xia J, Wu M, et al. She-sfl: an efficient and privacy-preserving heterogeneous federated split learning architecture based on homomorphic encryption. Future Generation Computer Systems, 2025. In press.","DOI":"10.1016\/j.future.2025.108101"},{"key":"4482_CR119","doi-asserted-by":"publisher","DOI":"10.1145\/3460427","author":"X Yin","year":"2021","unstructured":"Yin X, Zhu Y, Hu J. A comprehensive survey of privacy-preserving federated learning: a taxonomy, review, and future directions. ACM Comput Surv. 2021. https:\/\/doi.org\/10.1145\/3460427.","journal-title":"ACM Comput Surv"},{"key":"4482_CR120","doi-asserted-by":"crossref","unstructured":"Rodr\u00edguez-Barroso N, L\u00f3pez DJ, Luz\u00f3n MV, Herrera F, Mart\u00ednez-C\u00e1mara E. Survey on federated learning threats: concepts, taxonomy on attacks and defences, experimental study and challenges. 2022, arXiv preprint arXiv:2201.08135.","DOI":"10.1016\/j.inffus.2022.09.011"},{"key":"4482_CR121","unstructured":"Xu R, Baracaldo N, Joshi J. Privacy-preserving machine learning: methods, challenges and directions. 2021. arXiv preprint arXiv:2108.04417."},{"key":"4482_CR122","unstructured":"Piotrowska AM, Hayes J, Elahi T, Meiser S, Danezis G. The loopix anonymity system. In: 26th USENIX Security Symposium (USENIX Security 17), pp. 1199\u20131216. USENIX Association, Vancouver, BC. 2017, https:\/\/www.usenix.org\/conference\/usenixsecurity17\/technical-sessions\/presentation\/piotrowska."},{"key":"4482_CR123","unstructured":"Piotrowska A, Hayes J, Elahi T, Meiser S, Danezis G. The Loopix Anonymity System. 2017; arxiv:1703.00536."}],"container-title":["SN Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-025-04482-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s42979-025-04482-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s42979-025-04482-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,19]],"date-time":"2025-11-19T13:03:03Z","timestamp":1763557383000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s42979-025-04482-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":123,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["4482"],"URL":"https:\/\/doi.org\/10.1007\/s42979-025-04482-4","relation":{},"ISSN":["2661-8907"],"issn-type":[{"value":"2661-8907","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"24 July 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"16 October 2025","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"19 November 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"Not applicable","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Research Involving Human and\/or Animals"}},{"value":"Not applicable","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics Approval and Consent to Participate"}}],"article-number":"972"}}