{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,4,18]],"date-time":"2025-04-18T04:13:09Z","timestamp":1744949589566,"version":"3.40.4"},"reference-count":32,"publisher":"Oxford University Press (OUP)","issue":"4","license":[{"start":{"date-parts":[[2024,12,7]],"date-time":"2024-12-07T00:00:00Z","timestamp":1733529600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/pages\/standard-publication-reuse-rights"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372268"],"award-info":[{"award-number":["62372268"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100007129","name":"Shandong Provincial Natural Science Foundation","doi-asserted-by":"publisher","award":["ZR2022LZH013","ZR2021LZH007"],"award-info":[{"award-number":["ZR2022LZH013","ZR2021LZH007"]}],"id":[{"id":"10.13039\/501100007129","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Major Scientific and Technological Innovation Projects of Shandong Province","award":["2024CXGC010114"],"award-info":[{"award-number":["2024CXGC010114"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,4,12]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Federated learning (FL) often uses local differential privacy (LDP) to prevent leaking data privacy through gradients. However, due to the high dimension of gradients, LDP will encounter the problem of privacy budget explosion in the application, resulting in low accuracy of the training model. To overcome this shortcoming, we propose a differential privacy FL protocol incorporating a control matrix and double shuffles. The control matrix, generated by the analyzer, is responsible for governing the selection and upload of clients\u2019 gradients. Double shufflers shuffle the control matrix and clients\u2019 gradients, respectively, so that the control matrix is invisible to the server and the gradient is anonymous to the server. In addition, the existing differential private FL often uses the same clipping scale for gradients clipping to facilitate determining the noise scale. However, this will bring too many clipping errors for the large gradients and too many noise errors for the small ones. To solve these problems, we propose an adaptive clipping scheme. Experiments on the real-world datasets show that our proposed methods achieve higher testing accuracy.<\/jats:p>","DOI":"10.1093\/comjnl\/bxae122","type":"journal-article","created":{"date-parts":[[2024,12,10]],"date-time":"2024-12-10T23:20:32Z","timestamp":1733872832000},"page":"431-443","source":"Crossref","is-referenced-by-count":0,"title":["FLDS: differentially private federated learning with double shufflers"],"prefix":"10.1093","volume":"68","author":[{"given":"Qingqiang","family":"Qi","sequence":"first","affiliation":[{"name":"School of Cyber Science and Technology, Shandong University , Qingdao 266237 ,","place":["China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xingye","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Shandong University , Qingdao 266237 ,","place":["China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chengyu","family":"Hu","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Shandong University , Qingdao 266237 ,","place":["China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Peng","family":"Tang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Shandong University , Qingdao 266237 ,","place":["China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhiyuan","family":"Su","sequence":"additional","affiliation":[{"name":"System Software Product Department, Inspur Electronic Information Industry Co., Ltd , Shandong 250013 ,","place":["China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shanqing","family":"Guo","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Technology, Shandong University , Qingdao 266237 ,","place":["China"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2024,12,7]]},"reference":[{"volume-title":"Federal Act on Data Protection","year":"2020","author":"SR 235.1","key":"2025041706120780200_ref1"},{"volume-title":"Personal Information Protection and Electronic Documents Act","year":"2000","author":"S.C.2000, c.5","key":"2025041706120780200_ref2"},{"volume-title":"General Data Protection Regulation","year":"2016","author":"OJ L 119, 04.05.2016; cor. OJ L 127, 23.5.2018","key":"2025041706120780200_ref3"},{"key":"2025041706120780200_ref4","first-page":"5132","article-title":"SCAFFOLD: stochastic controlled averaging for federated learning","volume-title":"Proceedings of the 37th International Conference on Machine Learning, virtual place, 13-18 July","author":"Karimireddy","year":"2020"},{"key":"2025041706120780200_ref5","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2019.23119","article-title":"Ml-leaks: Model and data independent membership inference attacks and defenses on machine learning models","volume-title":"Proceedings of the Network and Distributed Systems Security (NDSS) Symposium, San Diego, CA, USA, 24-27 February","author":"Salem","year":"2019"},{"key":"2025041706120780200_ref6","first-page":"268","article-title":"Privacy risk in machine learning: Analyzing the connection to overfitting","volume-title":"Proceedings of IEEE 31st computer security foundations symposium (CSF), Oxford, UK, 9-12 July","author":"Yeom","year":"2018"},{"key":"2025041706120780200_ref7","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1561\/0400000042","article-title":"The algorithmic foundations of differential privacy","volume":"9","author":"Dwork","year":"2014","journal-title":"Found Trends Theor Comput Sci"},{"key":"2025041706120780200_ref8","first-page":"638","article-title":"Collecting and analyzing multidimensional data with local differential privacy","volume-title":"Proceedings of IEEE 35th International Conference on Data Engineering (ICDE), Macau SAR, CN, 8-11 April","author":"Wang","year":"2019"},{"volume-title":"Data Privacy Protection Method, Server Device and Client Device for Federated Learning","year":"2024","author":"Kao","key":"2025041706120780200_ref9"},{"volume-title":"Dynamic Differential Privacy to Federated Learning Systems","year":"2024","author":"Ou","key":"2025041706120780200_ref10"},{"key":"2025041706120780200_ref11","doi-asserted-by":"publisher","first-page":"8688","DOI":"10.1609\/aaai.v35i10.17053","article-title":"Flame: Differentially private federated learning in the shuffle model","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence, virtual place, 2-9 February","author":"Liu","year":"2021"},{"key":"2025041706120780200_ref12","first-page":"638","article-title":"The privacy blanket of the shuffle model","volume-title":"Proceedings of the 39th Annual International Cryptology Conference(CRYPTO), Santa Barbara, CA, USA, 18\u201322 August, Part II","author":"Balle","year":"2019"},{"key":"2025041706120780200_ref13","first-page":"6280","article-title":"Privacy amplification by subsampling: tight analyses via couplings and divergences","volume-title":"Proceedings of the 32nd International Conference on Neural Information Processing Systems, Montr\u00e9al, CA, 3-8 December","author":"Balle","year":"2018"},{"key":"2025041706120780200_ref14","first-page":"308","article-title":"Deep learning with differential privacy","volume-title":"Proceedings of the ACM SIGSAC conference on computer and communications security, Vienna, AU, 24-28 October","author":"Abadi","year":"2016"},{"key":"2025041706120780200_ref15","first-page":"13773","article-title":"Understanding gradient clipping in private SGD: a geometric perspective","volume":"33","author":"Chen","year":"2020","journal-title":"Adv Neural Inf Process Syst"},{"key":"2025041706120780200_ref16","first-page":"17455","article-title":"Differentially private learning with adaptive clipping","volume":"34","author":"Andrew","year":"2021","journal-title":"Adv Neural Inf Process Syst"},{"key":"2025041706120780200_ref17","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, Ft. Lauderdale, FL, USA, 20-22 April","author":"McMahan","year":"2017"},{"key":"2025041706120780200_ref18","doi-asserted-by":"crossref","DOI":"10.24963\/ijcai.2021\/216","article-title":"Federated model distillation with noise-free differential privacy","volume-title":"Proceedings of theThirtieth International Joint Conference on Artificial Intelligence, Montreal, 19-27 August","author":"Sun"},{"key":"2025041706120780200_ref19","first-page":"338","article-title":"Differentially private federated learning with shuffling and client self-sampling","volume-title":"Proceedings of IEEE International Symposium on Information Theory (ISIT), Melbourne, Victoria, AU, 12\u201320 July","author":"Girgis","year":"2021"},{"key":"2025041706120780200_ref20","first-page":"1571","article-title":"LDP-FL: practical private aggregation in federated learning with local differential privacy","volume-title":"Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence, Montreal, 19-27 August","author":"Sun","year":"2021"},{"author":"van der Veen","key":"2025041706120780200_ref21","article-title":"Three tools for practical differential privacy"},{"key":"2025041706120780200_ref22","first-page":"383","article-title":"Private adaptive gradient methods for convex optimization","volume-title":"Proceedings of the 38th International Conference on Machine Learning, virtual place, 18-24 July","author":"Asi","year":"2021"},{"key":"2025041706120780200_ref23","article-title":"Exploring the limits of differentially private deep learning with group-wise clipping","volume-title":"Proceedings of The Eleventh International Conference on Learning Representations, Kigali, RW, 1-5 May","author":"He","year":"2023"},{"key":"2025041706120780200_ref24","first-page":"51","article-title":"Boosting and differential privacy","volume-title":"Proceedings of IEEE 51st Annual Symposium on Foundations of Computer Science, Las Vegas, Nevada, 23-26 October","author":"Dwork","year":"2010"},{"key":"2025041706120780200_ref25","doi-asserted-by":"crossref","first-page":"441","DOI":"10.1145\/3132747.3132769","article-title":"Prochlo: strong privacy for analytics in the crowd","volume-title":"Proceedings of the 26th symposium on operating systems principles, Shanghai CN, 28 October","author":"Bittau","year":"2017"},{"key":"2025041706120780200_ref26","first-page":"954","article-title":"Hiding among the clones: a simple and nearly optimal analysis of privacy amplification by shuffling","volume-title":"Proceedings of IEEE 62nd Annual Symposium on Foundations of Computer Science (FOCS), virtual place, 7-10 Feb","author":"Feldman","year":"2022"},{"key":"2025041706120780200_ref27","first-page":"428","article-title":"Adaptive clipping bound of deep learning with differential privacy","volume-title":"Proceedings of IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Shenyang, N, 20-22 October","author":"Hu","year":"2021"},{"key":"2025041706120780200_ref28","doi-asserted-by":"publisher","first-page":"383","DOI":"10.1080\/01621459.1974.10482962","article-title":"The influence curve and its role in robust estimation","volume":"69","author":"Hampel","year":"1974","journal-title":"J Am Stat Assoc"},{"key":"2025041706120780200_ref29","doi-asserted-by":"publisher","first-page":"764","DOI":"10.1016\/j.jesp.2013.03.013","article-title":"Detecting outliers: do not use standard deviation around the mean, use absolute deviation around the median","volume":"49","author":"Leys","year":"2013","journal-title":"J Exp Soc Psychol"},{"key":"2025041706120780200_ref30","doi-asserted-by":"publisher","first-page":"1273","DOI":"10.1080\/01621459.1993.10476408","article-title":"Alternatives to the median absolute deviation","volume":"88","author":"Rousseeuw","year":"1993","journal-title":"J Am Stat Assoc"},{"key":"2025041706120780200_ref31","first-page":"1","article-title":"When machine learning meets privacy: a survey and outlook","volume":"54","author":"Liu","year":"2021","journal-title":"ACM Comput Surv"},{"key":"2025041706120780200_ref32","first-page":"399","article-title":"SoK: security and privacy in machine learning","volume-title":"Proceedings of IEEE European Symposium on Security and Privacy, London, UK, 24-26 April","author":"Papernot"}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/advance-article-pdf\/doi\/10.1093\/comjnl\/bxae122\/60983063\/bxae122.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/advance-article-pdf\/doi\/10.1093\/comjnl\/bxae122\/60983063\/bxae122.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,17]],"date-time":"2025-04-17T10:12:37Z","timestamp":1744884757000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/68\/4\/431\/7918703"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,7]]},"references-count":32,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2024,12,7]]},"published-print":{"date-parts":[[2025,4,12]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxae122","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"type":"print","value":"0010-4620"},{"type":"electronic","value":"1460-2067"}],"subject":[],"published-other":{"date-parts":[[2025,4]]},"published":{"date-parts":[[2024,12,7]]}}}