{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,8]],"date-time":"2026-06-08T15:57:47Z","timestamp":1780934267966,"version":"3.54.1"},"reference-count":51,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,12,1]],"date-time":"2026-12-01T00:00:00Z","timestamp":1796083200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100013804","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100013804","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Pattern Recognition"],"published-print":{"date-parts":[[2026,12]]},"DOI":"10.1016\/j.patcog.2026.113963","type":"journal-article","created":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T22:57:06Z","timestamp":1779145026000},"page":"113963","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"PA","title":["Fairness-aware differentially private model training without sensitive attributes for face recognition"],"prefix":"10.1016","volume":"180","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5951-3789","authenticated-orcid":false,"given":"Fengrui","family":"Hao","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuzhao","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tianlong","family":"Gu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xuemin","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.patcog.2026.113963_b1","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2024.111227","article-title":"Local and global feature attention fusion network for face recognition","volume":"161","author":"Wang","year":"2025","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113963_b2","article-title":"Deep leakage from gradients","volume":"32","author":"Zhu","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113963_b3","article-title":"Practical privacy-preserving federated learning based on multiparty homomorphic encryption for large-scale models","author":"Qin","year":"2025","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113963_b4","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2024.110890","article-title":"Improving the utility of differentially private clustering through dynamical processing","volume":"157","author":"Byun","year":"2025","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113963_b5","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2025.104647","article-title":"dK-DGDP: A differential privacy approach on directed social network graphs","author":"Hao","year":"2025","journal-title":"Comput. Secur."},{"key":"10.1016\/j.patcog.2026.113963_b6","doi-asserted-by":"crossref","DOI":"10.1016\/j.neucom.2024.127663","article-title":"Differential privacy in deep learning: A literature survey","volume":"589","author":"Pan","year":"2024","journal-title":"Neurocomputing"},{"key":"10.1016\/j.patcog.2026.113963_b7","doi-asserted-by":"crossref","unstructured":"T. Farrand, F. Mireshghallah, S. Singh, A. Trask, Neither private nor fair: Impact of data imbalance on utility and fairness in differential privacy, in: Proceedings of the 2020 Workshop on Privacy-Preserving Machine Learning in Practice, 2020, pp. 15\u201319.","DOI":"10.1145\/3411501.3419419"},{"key":"10.1016\/j.patcog.2026.113963_b8","doi-asserted-by":"crossref","unstructured":"Y. Zhang, Z. Wang, R. Hu, X. Duan, Y. Zheng, B. Huai, J. Han, J. Sang, Poisoning for debiasing: Fair recognition via eliminating bias uncovered in data poisoning, in: Proceedings of the 32nd ACM International Conference on Multimedia, 2024, pp. 1866\u20131874.","DOI":"10.1145\/3664647.3681524"},{"key":"10.1016\/j.patcog.2026.113963_b9","doi-asserted-by":"crossref","unstructured":"D. Xu, W. Du, X. Wu, Removing disparate impact on model accuracy in differentially private stochastic gradient descent, in: Proceedings of the 27th ACM SIGKDD Conference on Knowledge Discovery & Data Mining, 2021, pp. 1924\u20131932.","DOI":"10.1145\/3447548.3467268"},{"key":"10.1016\/j.patcog.2026.113963_b10","first-page":"2168","article-title":"What you see is what you get: Principled deep learning via distributional generalization","volume":"35","author":"Kulynych","year":"2022","journal-title":"Adv. Neural Inf. Process. Syst."},{"issue":"6","key":"10.1016\/j.patcog.2026.113963_b11","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3673224","article-title":"Toward a privacy-preserving face recognition system: A survey of leakages and solutions","volume":"57","author":"Laishram","year":"2025","journal-title":"ACM Comput. Surv."},{"key":"10.1016\/j.patcog.2026.113963_b12","series-title":"International Conference on Machine Learning","first-page":"3192","article-title":"Differentially private optimization on large model at small cost","author":"Bu","year":"2023"},{"key":"10.1016\/j.patcog.2026.113963_b13","first-page":"17455","article-title":"Differentially private learning with adaptive clipping","volume":"34","author":"Andrew","year":"2021","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113963_b14","doi-asserted-by":"crossref","first-page":"41727","DOI":"10.52202\/075280-1808","article-title":"Automatic clipping: Differentially private deep learning made easier and stronger","volume":"36","author":"Bu","year":"2023","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113963_b15","series-title":"International Conference on Machine Learning","first-page":"27204","article-title":"Differentially private sharpness-aware training","author":"Park","year":"2023"},{"key":"10.1016\/j.patcog.2026.113963_b16","series-title":"Forty-First International Conference on Machine Learning","article-title":"Differentially private bias-term fine-tuning of foundation models","author":"Bu","year":"2024"},{"key":"10.1016\/j.patcog.2026.113963_b17","series-title":"Differential privacy and fairness in decisions and learning tasks: A survey","author":"Fioretto","year":"2022"},{"key":"10.1016\/j.patcog.2026.113963_b18","first-page":"27555","article-title":"Differentially private empirical risk minimization under the fairness lens","volume":"34","author":"Tran","year":"2021","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113963_b19","first-page":"9932","article-title":"Differentially private and fair deep learning: A lagrangian dual approach","volume":"vol. 35","author":"Tran","year":"2021"},{"issue":"9","key":"10.1016\/j.patcog.2026.113963_b20","doi-asserted-by":"crossref","first-page":"5557","DOI":"10.1109\/TNNLS.2021.3129592","article-title":"Balancing learning model privacy, fairness, and accuracy with early stopping criteria","volume":"34","author":"Zhang","year":"2023","journal-title":"IEEE Trans. Neural Networks Learn. Syst."},{"key":"10.1016\/j.patcog.2026.113963_b21","unstructured":"A. Lowy, D. Gupta, M. Razaviyayn, Stochastic Differentially Private and Fair Learning, in: International Conference on Learning Representation, 2023."},{"key":"10.1016\/j.patcog.2026.113963_b22","doi-asserted-by":"crossref","unstructured":"T. Zhao, E. Dai, K. Shu, S. Wang, Towards fair classifiers without sensitive attributes: Exploring biases in related features, in: Proceedings of the Fifteenth ACM International Conference on Web Search and Data Mining, 2022, pp. 1433\u20131442.","DOI":"10.1145\/3488560.3498493"},{"key":"10.1016\/j.patcog.2026.113963_b23","series-title":"International Conference on Machine Learning","first-page":"43258","article-title":"Weak proxies are sufficient and preferable for fairness with missing sensitive attributes","author":"Zhu","year":"2023"},{"key":"10.1016\/j.patcog.2026.113963_b24","doi-asserted-by":"crossref","first-page":"19152","DOI":"10.52202\/068431-1392","article-title":"Fairness without demographics through knowledge distillation","volume":"35","author":"Chai","year":"2022","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113963_b25","unstructured":"S. Lu, Y. Wang, X. Wang, Debiasing attention mechanism in transformer without demographics, in: The Twelfth International Conference on Learning Representations, 2024."},{"key":"10.1016\/j.patcog.2026.113963_b26","first-page":"728","article-title":"Fairness without demographics through adversarially reweighted learning","volume":"33","author":"Lahoti","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113963_b27","series-title":"International Conference on Machine Learning","first-page":"28448","article-title":"Simple and fast group robustness by automatic feature reweighting","author":"Qiu","year":"2023"},{"key":"10.1016\/j.patcog.2026.113963_b28","unstructured":"A. Kappiyath, A. Chaudhuri, A.K. Jaiswal, Z. Liu, Y. Li, X. Zhu, L. Yin, SEBRA : Debiasing through Self-Guided Bias Ranking, in: The Thirteenth International Conference on Learning Representations, 2025."},{"key":"10.1016\/j.patcog.2026.113963_b29","doi-asserted-by":"crossref","unstructured":"Y. Zhu, J. Li, Y. Bian, Z. Zheng, L. Chen, One fits all: Learning fair graph neural networks for various sensitive attributes, in: Proceedings of the 30th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, 2024, pp. 4688\u20134699.","DOI":"10.1145\/3637528.3672029"},{"key":"10.1016\/j.patcog.2026.113963_b30","doi-asserted-by":"crossref","unstructured":"Y. Zhu, J. Li, L. Chen, Z. Zheng, The devil is in the data: Learning fair graph neural networks via partial knowledge distillation, in: Proceedings of the 17th ACM International Conference on Web Search and Data Mining, 2024, pp. 1012\u20131021.","DOI":"10.1145\/3616855.3635768"},{"key":"10.1016\/j.patcog.2026.113963_b31","series-title":"2025 IEEE 41st International Conference on Data Engineering","first-page":"265","article-title":"Towards fair graph neural networks via graph counterfactual without sensitive attributes","author":"Wang","year":"2025"},{"key":"10.1016\/j.patcog.2026.113963_b32","series-title":"fairgnn-wod: Fair Graph Learning Without Complete Demographics","author":"Wang","year":"2025"},{"key":"10.1016\/j.patcog.2026.113963_b33","first-page":"2107","article-title":"Towards fair graph learning without demographic information","volume":"vol. 258","author":"Wang","year":"2025"},{"issue":"3\u20134","key":"10.1016\/j.patcog.2026.113963_b34","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1561\/0400000042","article-title":"The algorithmic foundations of differential privacy","volume":"9","author":"Dwork","year":"2014","journal-title":"Found. Trends\u00ae Theor. Computer Sci."},{"key":"10.1016\/j.patcog.2026.113963_b35","series-title":"Theory of Cryptography: Third Theory of Cryptography Conference, TCC 2006, New York, NY, USA, March 4-7, 2006. Proceedings 3","first-page":"265","article-title":"Calibrating noise to sensitivity in private data analysis","author":"Dwork","year":"2006"},{"key":"10.1016\/j.patcog.2026.113963_b36","doi-asserted-by":"crossref","unstructured":"M. Abadi, A. Chu, I. Goodfellow, H.B. McMahan, I. Mironov, K. Talwar, L. Zhang, Deep learning with differential privacy, in: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, 2016, pp. 308\u2013318.","DOI":"10.1145\/2976749.2978318"},{"key":"10.1016\/j.patcog.2026.113963_b37","article-title":"Equality of opportunity in supervised learning","volume":"29","author":"Hardt","year":"2016","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113963_b38","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2026.113499","article-title":"Stealthy backdoor attack method targeting group fairness in self-supervised learning","author":"Hao","year":"2026","journal-title":"Pattern Recognit."},{"key":"10.1016\/j.patcog.2026.113963_b39","doi-asserted-by":"crossref","unstructured":"Y. Wang, Y. Zhao, Y. Dong, H. Chen, J. Li, T. Derr, Improving fairness in graph neural networks via mitigating sensitive attribute leakage, in: Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, 2022, pp. 1938\u20131948.","DOI":"10.1145\/3534678.3539404"},{"key":"10.1016\/j.patcog.2026.113963_b40","series-title":"UCI Machine Learning Repository","author":"Asuncion","year":"2007"},{"key":"10.1016\/j.patcog.2026.113963_b41","first-page":"17652","article-title":"Pruning has a disparate impact on model accuracy","volume":"35","author":"Tran","year":"2022","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113963_b42","first-page":"65618","article-title":"Private (stochastic) non-convex optimization revisited: Second-order stationary points and excess risks","volume":"36","author":"Liu","year":"2023","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113963_b43","doi-asserted-by":"crossref","unstructured":"S. Park, J. Lee, P. Lee, S. Hwang, D. Kim, H. Byun, Fair contrastive learning for facial attribute classification, in: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, 2022, pp. 10389\u201310398.","DOI":"10.1109\/CVPR52688.2022.01014"},{"key":"10.1016\/j.patcog.2026.113963_b44","first-page":"78696","article-title":"Bounding training data reconstruction in dp-sgd","volume":"36","author":"Hayes","year":"2023","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.patcog.2026.113963_b45","series-title":"Unlocking high-accuracy differentially private image classification through scale","author":"De","year":"2022"},{"key":"10.1016\/j.patcog.2026.113963_b46","unstructured":"S. Jung, T. Park, S. Chun, T. Moon, Re-weighting Based Group Fairness Regularization via Classwise Robust Optimization, in: The Eleventh International Conference on Learning Representations, ICLR 2023, Kigali, Rwanda, May 1-5, 2023, 2023."},{"key":"10.1016\/j.patcog.2026.113963_b47","doi-asserted-by":"crossref","unstructured":"M. Du, X. Yue, S.S. Chow, T. Wang, C. Huang, H. Sun, Dp-forward: Fine-tuning and inference on language models with differential privacy in forward pass, in: Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, 2023, pp. 2665\u20132679.","DOI":"10.1145\/3576915.3616592"},{"key":"10.1016\/j.patcog.2026.113963_b48","doi-asserted-by":"crossref","unstructured":"Z. Liu, P. Luo, X. Wang, X. Tang, Deep learning face attributes in the wild, in: Proceedings of the IEEE International Conference on Computer Vision, 2015, pp. 3730\u20133738.","DOI":"10.1109\/ICCV.2015.425"},{"key":"10.1016\/j.patcog.2026.113963_b49","doi-asserted-by":"crossref","unstructured":"Z. Zhang, Y. Song, H. Qi, Age progression\/regression by conditional adversarial autoencoder, in: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, 2017, pp. 5810\u20135818.","DOI":"10.1109\/CVPR.2017.463"},{"key":"10.1016\/j.patcog.2026.113963_b50","doi-asserted-by":"crossref","unstructured":"M. Feldman, S.A. Friedler, J. Moeller, C. Scheidegger, S. Venkatasubramanian, Certifying and removing disparate impact, in: Proceedings of the 21th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, 2015, pp. 259\u2013268.","DOI":"10.1145\/2783258.2783311"},{"key":"10.1016\/j.patcog.2026.113963_b51","series-title":"31st USENIX Security Symposium","first-page":"4525","article-title":"{Ml-doctor}: Holistic risk assessment of inference attacks against machine learning models","author":"Liu","year":"2022"}],"container-title":["Pattern Recognition"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0031320326009283?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0031320326009283?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,6,8]],"date-time":"2026-06-08T14:59:55Z","timestamp":1780930795000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0031320326009283"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,12]]},"references-count":51,"alternative-id":["S0031320326009283"],"URL":"https:\/\/doi.org\/10.1016\/j.patcog.2026.113963","relation":{},"ISSN":["0031-3203"],"issn-type":[{"value":"0031-3203","type":"print"}],"subject":[],"published":{"date-parts":[[2026,12]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Fairness-aware differentially private model training without sensitive attributes for face recognition","name":"articletitle","label":"Article Title"},{"value":"Pattern Recognition","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.patcog.2026.113963","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"113963"}}