{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T20:17:16Z","timestamp":1776889036041,"version":"3.51.2"},"reference-count":32,"publisher":"Oxford University Press (OUP)","issue":"8","license":[{"start":{"date-parts":[[2025,3,4]],"date-time":"2025-03-04T00:00:00Z","timestamp":1741046400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/pages\/standard-publication-reuse-rights"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,8,14]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Differential privacy can effectively help federated learning resist privacy attacks from various parties. However, existing approaches that use differential privacy for privacy protection greatly decrease the model performance of federated learning, especially in scenarios with complex model structures and large parameters. In this paper, we propose a novel privacy preservation scheme for federated learning that combines automatic gradient clipping and gradient transformation perturbation. Our approach primarily reduces the impact of differential privacy on federated learning from two aspects. Firstly, we efficiently control the gradient sensitivity by using automatic gradient clipping instead of traditional threshold clipping. Secondly, we utilize the space transformation technique to alleviate the dramatic accuracy degradation of the model caused by the insertion noise. Extensive experiments on various benchmark datasets demonstrate that our approach achieves a good trade-off between data privacy and effectiveness under the same privacy budget.<\/jats:p>","DOI":"10.1093\/comjnl\/bxaf015","type":"journal-article","created":{"date-parts":[[2025,2,13]],"date-time":"2025-02-13T07:18:14Z","timestamp":1739431094000},"page":"939-952","source":"Crossref","is-referenced-by-count":1,"title":["Towards effective privacy preservation in federated learning with automatic gradient clipping and gradient transformation perturbation"],"prefix":"10.1093","volume":"68","author":[{"given":"Chuanyin","family":"Wang","sequence":"first","affiliation":[{"name":"Institute of Information Engineering , Chinese Academy of Sciences, Beijing, 100085,","place":["China"]},{"name":"State Key Laboratory of Cyberspace Security Defense , Beijing, 100085,","place":["China"]},{"name":"School of Cyber Security , University of Chinese Academy of Sciences, Beijing, 100049,","place":["China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yifei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering , Chinese Academy of Sciences, Beijing, 100085,","place":["China"]},{"name":"State Key Laboratory of Cyberspace Security Defense , Beijing, 100085,","place":["China"]}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Neng","family":"Gao","sequence":"additional","affiliation":[{"name":"Institute of Information Engineering , Chinese Academy of Sciences, Beijing, 100085,","place":["China"]},{"name":"State Key Laboratory of Cyberspace Security Defense , Beijing, 100085,","place":["China"]}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2025,3,4]]},"reference":[{"key":"2025081702465811200_ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, AISTATS 2017, Fort Lauderdale, FL, USA, April 20\u201322","author":"McMahan","year":"2017"},{"key":"2025081702465811200_ref2","first-page":"1","article-title":"R-GAP: recursive gradient attack on privacy","volume-title":"9th International Conference on Learning Representations, ICLR 2021, Virtual Event, Austria, May 3-7","author":"Zhu","year":"2021"},{"key":"2025081702465811200_ref3","first-page":"14747","article-title":"Deep leakage from gradients","volume-title":"Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019, Vancouver, BC, Canada, December 8-14","author":"Zhu","year":"2019"},{"key":"2025081702465811200_ref4","first-page":"5959","article-title":"Gradient disaggregation: breaking privacy in federated learning by reconstructing the user participant matrix","volume-title":"Proceedings of the 38th International Conference on Machine Learning, ICML 2021, Virtual Event, 18-24 July","author":"Lam","year":"2021"},{"key":"2025081702465811200_ref5","first-page":"265","article-title":"Calibrating noise to sensitivity in private data analysis","volume-title":"Theory of Cryptography, Third Theory of Cryptography Conference, TCC 2006, New York, NY, USA, March 4-7","author":"Dwork","year":"2006"},{"key":"2025081702465811200_ref6","article-title":"Differentially private federated learning: a client level perspective","author":"Geyer","year":"2017"},{"key":"2025081702465811200_ref7","article-title":"Learning differentially private recurrent language models","volume-title":"6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, April 30\u2013May 3","author":"McMahan","year":"2018"},{"key":"2025081702465811200_ref8","first-page":"2604","article-title":"Wireless federated learning with local differential privacy","volume-title":"IEEE International Symposium on Information Theory, ISIT 2020, Los Angeles, CA, USA, June 21-26","author":"Seif","year":"2020"},{"key":"2025081702465811200_ref9","first-page":"10112","article-title":"Differentially private federated learning with local regularization and sparsification","volume-title":"IEEE\/CVF Conference on Computer Vision and Pattern Recognition, CVPR 2022, New Orleans, LA, USA, June 18-24","author":"Cheng","year":"2022"},{"key":"2025081702465811200_ref10","first-page":"1571","article-title":"LDP-FL: practical private aggregation in federated learning with local differential privacy","volume-title":"Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence, IJCAI 2021, Virtual Event \/ Montreal, Canada, August 19-27","author":"Sun","year":"2021"},{"key":"2025081702465811200_ref11","doi-asserted-by":"publisher","first-page":"8836","DOI":"10.1109\/JIOT.2020.3037194","article-title":"Local differential privacy-based federated learning for internet of things","volume":"8","author":"Zhao","year":"2021","journal-title":"IEEE Internet Things J"},{"key":"2025081702465811200_ref12","article-title":"Gradient descent happens in a tiny subspace","author":"Gur-Ari","year":"2018"},{"key":"2025081702465811200_ref13","first-page":"3017","article-title":"Low-rank gradient approximation for memory-efficient on-device training of deep neural network","volume-title":"IEEE International Conference on Acoustics, Speech and Signal Processing, ICASSP 2020, Barcelona, Spain, May 4-8","author":"Gooneratne","year":"2020"},{"key":"2025081702465811200_ref14","first-page":"1463","article-title":"Federated learning with sparsification-amplified privacy and adaptive optimization","volume-title":"Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence, IJCAI 2021, Virtual Event \/ Montreal, Canada, August 19-27","author":"Hu","year":"2021"},{"key":"2025081702465811200_ref15","first-page":"308","article-title":"Deep learning with differential privacy","volume-title":"Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, Vienna, Austria, October 24-28","author":"Abadi","year":"2016"},{"key":"2025081702465811200_ref16","doi-asserted-by":"publisher","first-page":"1002","DOI":"10.1109\/TIFS.2019.2931068","article-title":"DP-ADMM: ADMM-based distributed learning with differential privacy","volume":"15","author":"Huang","year":"2020","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"2025081702465811200_ref17","first-page":"1310","article-title":"Privacy-preserving deep learning","volume-title":"Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, Denver, CO, USA, October 12-16","author":"Shokri","year":"2015"},{"key":"2025081702465811200_ref18","first-page":"61","article-title":"LDP-fed: federated learning with local differential privacy","volume-title":"Proceedings of the 3rd International Workshop on Edge Systems, Analytics and Networking, EdgeSys@EuroSys 2020, Heraklion, Greece, April 27","author":"Truex","year":"2020"},{"key":"2025081702465811200_ref19","doi-asserted-by":"crossref","DOI":"10.1109\/TMC.2023.3343288","article-title":"Federated learning with sparsified model perturbation: improving accuracy under client-level differential privacy","volume":"23","author":"Hu","year":"2024","journal-title":"IEEE Trans Mob Comput"},{"key":"2025081702465811200_ref20","doi-asserted-by":"publisher","first-page":"464","DOI":"10.1109\/JSAIT.2021.3056102","article-title":"Shuffled model of federated learning: privacy, accuracy and communication trade-offs","volume":"2","author":"Girgis","year":"2021","journal-title":"IEEE J Sel Areas Inf Theory"},{"key":"2025081702465811200_ref21","doi-asserted-by":"crossref","first-page":"1310","DOI":"10.1109\/TII.2021.3073925","article-title":"Privacy threat and defense for federated learning with non-iid data in AIoT","volume":"18","author":"Xiong","year":"2021","journal-title":"IEEE Trans Industr Inform"},{"key":"2025081702465811200_ref22","first-page":"24","article-title":"Differential privacy in federated dynamic gradient clipping based on gradient norm","volume-title":"Algorithms and Architectures for Parallel Processing - 23rd International Conference, ICA3PP 2023, Tianjin, China, October 20-22","author":"Mao","year":"2023"},{"key":"2025081702465811200_ref23","first-page":"635","article-title":"Concentrated differential privacy: simplifications, extensions, and lower bounds","volume-title":"Theory of Cryptography - 14th International Conference, TCC 2016-B, Beijing, China, October 31 - November 3","author":"Bun","year":"2016"},{"key":"2025081702465811200_ref24","first-page":"332","article-title":"Differentially private model publishing for deep learning","volume-title":"2019 IEEE Symposium on Security and Privacy, SP 2019, San Francisco, CA, USA, May 19-23","author":"Yu","year":"2019"},{"key":"2025081702465811200_ref25","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3460427","article-title":"A comprehensive survey of privacy-preserving federated learning: a taxonomy, review, and future directions","volume":"54","author":"Yin","year":"2021","journal-title":"ACM Comput Surv"},{"key":"2025081702465811200_ref26","first-page":"17455","article-title":"Differentially private learning with adaptive clipping","volume-title":"Advances in Neural Information Processing Systems 34: Annual Conference on Neural Information Processing Systems 2021, NeurIPS 2021, virtual, December 6-14","author":"Andrew","year":"2021"},{"key":"2025081702465811200_ref27","article-title":"Automatic clipping: differentially private deep learning made easier and stronger","author":"Bu","year":"2022"},{"key":"2025081702465811200_ref28","first-page":"10444","article-title":"Differentially private learning with per-sample adaptive clipping","volume-title":"Thirty-Seventh AAAI Conference on Artificial Intelligence, AAAI 2023, Thirty-Fifth Conference on Innovative Applications of Artificial Intelligence, IAAI 2023, Thirteenth Symposium on Educational Advances in Artificial Intelligence, EAAI 2023, Washington, DC, USA, February 7-14","author":"Xia","year":"2023"},{"key":"2025081702465811200_ref29","first-page":"1","article-title":"Bypassing the ambient dimension: private SGD with gradient subspace identification","volume-title":"9th International Conference on Learning Representations, ICLR 2021, Virtual Event, Austria, May 3-7","author":"Zhou","year":"2021"},{"key":"2025081702465811200_ref30","first-page":"1","article-title":"Do not let privacy overbill utility: gradient embedding perturbation for private learning","volume-title":"9th International Conference on Learning Representations, ICLR 2021, Virtual Event, Austria, May 3-7","author":"Yu","year":"2021"},{"key":"2025081702465811200_ref31","first-page":"5132","article-title":"SCAFFOLD: stochastic controlled averaging for federated learning","volume-title":"Proceedings of the 37th International Conference on Machine Learning, ICML 2020, Virtual Event, July 13-18","author":"Karimireddy","year":"2020"},{"key":"2025081702465811200_ref32","first-page":"770","article-title":"Deep residual learning for image recognition","volume-title":"2016 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2016, Las Vegas, NV, USA, June 27-30","author":"He","year":"2016"}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/68\/8\/939\/62263688\/bxaf015.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/68\/8\/939\/62263688\/bxaf015.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,17]],"date-time":"2025-08-17T06:47:10Z","timestamp":1755413230000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/68\/8\/939\/8051621"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,4]]},"references-count":32,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2025,3,4]]},"published-print":{"date-parts":[[2025,8,14]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxaf015","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2025,8]]},"published":{"date-parts":[[2025,3,4]]}}}