{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T15:13:20Z","timestamp":1776784400872,"version":"3.51.2"},"reference-count":53,"publisher":"Association for Computing Machinery (ACM)","issue":"6","license":[{"start":{"date-parts":[[2023,11,20]],"date-time":"2023-11-20T00:00:00Z","timestamp":1700438400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2018AAA0101100"],"award-info":[{"award-number":["2018AAA0101100"]}]},{"name":"Hong Kong RGC TRS","award":["T41-603\/20-R"],"award-info":[{"award-number":["T41-603\/20-R"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Intell. Syst. Technol."],"published-print":{"date-parts":[[2023,12,31]]},"abstract":"<jats:p>\n            <jats:bold>Federated learning (FL)<\/jats:bold>\n            enables participating parties to collaboratively build a global model with boosted utility without disclosing private data information. Appropriate protection mechanisms have to be adopted to fulfill the opposing requirements in preserving\n            <jats:italic>privacy<\/jats:italic>\n            and maintaining high model\n            <jats:italic>utility<\/jats:italic>\n            . In addition, it is a mandate for a federated learning system to achieve high\n            <jats:italic>efficiency<\/jats:italic>\n            in order to enable large-scale model training and deployment. We propose a unified federated learning framework that reconciles horizontal and vertical federated learning. Based on this framework, we formulate and quantify the trade-offs between privacy leakage, utility loss, and efficiency reduction, which leads us to the\n            <jats:bold>No-Free-Lunch (NFL)<\/jats:bold>\n            theorem for the federated learning system. NFL indicates that it is unrealistic to expect an FL algorithm to simultaneously provide excellent privacy, utility, and efficiency in certain scenarios. We then analyze the lower bounds for the privacy leakage, utility loss, and efficiency reduction for several widely-adopted protection mechanisms, including\n            <jats:italic>Randomization<\/jats:italic>\n            ,\n            <jats:italic>Homomorphic Encryption<\/jats:italic>\n            ,\n            <jats:italic>Secret Sharing,<\/jats:italic>\n            and\n            <jats:italic>Compression<\/jats:italic>\n            . Our analysis could serve as a guide for selecting protection parameters to meet particular requirements.\n          <\/jats:p>","DOI":"10.1145\/3595185","type":"journal-article","created":{"date-parts":[[2023,5,5]],"date-time":"2023-05-05T12:14:01Z","timestamp":1683288841000},"page":"1-32","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":38,"title":["Trading Off Privacy, Utility, and Efficiency in Federated Learning"],"prefix":"10.1145","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9065-6852","authenticated-orcid":false,"given":"Xiaojin","family":"Zhang","sequence":"first","affiliation":[{"name":"Hong Kong University of Science and Technology, Hong Kong"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2016-9503","authenticated-orcid":false,"given":"Yan","family":"Kang","sequence":"additional","affiliation":[{"name":"WeBank, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2587-6028","authenticated-orcid":false,"given":"Kai","family":"Chen","sequence":"additional","affiliation":[{"name":"Hong Kong University of Science and Technology, Hong Kong"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8162-7096","authenticated-orcid":false,"given":"Lixin","family":"Fan","sequence":"additional","affiliation":[{"name":"WeBank, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5059-8360","authenticated-orcid":false,"given":"Qiang","family":"Yang","sequence":"additional","affiliation":[{"name":"WeBank and Hong Kong University of Science and Technology, Hong Kong"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2023,11,20]]},"reference":[{"key":"e_1_3_3_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_3_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3501813"},{"issue":"5","key":"e_1_3_3_4_2","first-page":"1333","article-title":"Privacy-preserving deep learning via additively homomorphic encryption","volume":"13","author":"Aono Yoshinori","year":"2017","unstructured":"Yoshinori Aono, Takuya Hayashi, Lihua Wang, Shiho Moriai, et\u00a0al. 2017. Privacy-preserving deep learning via additively homomorphic encryption. IEEE Transactions on Information Forensics and Security 13, 5 (2017), 1333\u20131345.","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"e_1_3_3_5_2","doi-asserted-by":"crossref","first-page":"346","DOI":"10.1007\/978-3-030-75765-6_28","volume-title":"Advances in Knowledge Discovery and Data Mining","author":"Atarashi Kyohei","year":"2021","unstructured":"Kyohei Atarashi and Masakazu Ishihata. 2021. Vertical federated learning for higher-order factorization machines. In Advances in Knowledge Discovery and Data Mining, Kamal Karlapalem, Hong Cheng, Naren Ramakrishnan, R. K. Agrawal, P. Krishna Reddy, Jaideep Srivastava, and Tanmoy Chakraborty (Eds.). Springer International Publishing, Cham, 346\u2013357."},{"key":"e_1_3_3_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/MARK.1979.8817296"},{"key":"e_1_3_3_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_3_3_8_2","first-page":"3312","article-title":"Breaking the communication-privacy-accuracy trilemma","volume":"33","author":"Chen Wei-Ning","year":"2020","unstructured":"Wei-Ning Chen, Peter Kairouz, and Ayfer Ozgur. 2020. Breaking the communication-privacy-accuracy trilemma. Advances in Neural Information Processing Systems 33 (2020), 3312\u20133324.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_3_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2021.3082561"},{"key":"e_1_3_3_10_2","first-page":"10647","volume-title":"Advances in Neural Information Processing Systems","author":"Deasy Jacob","year":"2020","unstructured":"Jacob Deasy, Nikola Simidjievski, and Pietro Li\u00f3. 2020. Constraining variational inference with geometric Jensen-Shannon divergence. In Advances in Neural Information Processing Systems, H. Larochelle, M. Ranzato, R. Hadsell, M. F. Balcan, and H. Lin (Eds.), Vol. 33. Curran Associates, Inc., 10647\u201310658."},{"key":"e_1_3_3_11_2","doi-asserted-by":"crossref","first-page":"1401","DOI":"10.1109\/Allerton.2012.6483382","volume-title":"2012 50th Annual Allerton Conference on Communication, Control, and Computing (Allerton)","author":"Calmon Fl\u00e1vio du Pin","year":"2012","unstructured":"Fl\u00e1vio du Pin Calmon and Nadia Fawaz. 2012. Privacy against statistical inference. In 2012 50th Annual Allerton Conference on Communication, Control, and Computing (Allerton). IEEE, 1401\u20131408."},{"key":"e_1_3_3_12_2","doi-asserted-by":"publisher","DOI":"10.1561\/0400000042"},{"key":"e_1_3_3_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2003.813506"},{"key":"e_1_3_3_14_2","doi-asserted-by":"publisher","DOI":"10.3390\/fi13040094"},{"key":"e_1_3_3_15_2","first-page":"1397","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Fu Chong","year":"2022","unstructured":"Chong Fu, Xuhong Zhang, Shouling Ji, Jinyin Chen, Jingzheng Wu, Shanqing Guo, Jun Zhou, Alex X. Liu, and Ting Wang. 2022. Label inference attacks against vertical federated learning. In 31st USENIX Security Symposium (USENIX Security 22). USENIX Association, Boston, MA, 1397\u20131414. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/fu-chong."},{"key":"e_1_3_3_16_2","unstructured":"Jonas Geiping Hartmut Bauermeister Hannah Dr\u00f6ge and Michael Moeller. 2020. Inverting gradients - How easy is it to break privacy in federated learning?(NIPS\u201920). Curran Associates Inc. Red Hook NY USA Article 1421 11 pages. 1421"},{"key":"e_1_3_3_17_2","volume-title":"A Fully Homomorphic Encryption Scheme","author":"Gentry Craig","year":"2009","unstructured":"Craig Gentry. 2009. A Fully Homomorphic Encryption Scheme. Stanford University."},{"key":"e_1_3_3_18_2","article-title":"Differentially private federated learning: A client level perspective","author":"Geyer Robin C.","year":"2017","unstructured":"Robin C. Geyer, Tassilo Klein, and Moin Nabi. 2017. Differentially private federated learning: A client level perspective. arXiv preprint arXiv:1712.07557 (2017).","journal-title":"arXiv preprint arXiv:1712.07557"},{"key":"e_1_3_3_19_2","doi-asserted-by":"crossref","unstructured":"Bin Gu Zhiyuan Dang Xiang Li and Heng Huang. 2020. Federated doubly stochastic kernel learning for vertically partitioned data(KDD\u201920). Association for Computing Machinery New York NY USA 2483\u20132493.","DOI":"10.1145\/3394486.3403298"},{"key":"e_1_3_3_20_2","article-title":"Federated deep learning with Bayesian privacy","author":"Gu Hanlin","year":"2021","unstructured":"Hanlin Gu, Lixin Fan, Bowen Li, Yan Kang, Yuan Yao, and Qiang Yang. 2021. Federated deep learning with Bayesian privacy. arXiv preprint arXiv:2109.13012 (2021).","journal-title":"arXiv preprint arXiv:2109.13012"},{"key":"e_1_3_3_21_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2018.05.003"},{"key":"e_1_3_3_22_2","unstructured":"Andrew Hard Chlo\u00e9 M. Kiddon Daniel Ramage Francoise Beaufays Hubert Eichner Kanishka Rao Rajiv Mathews and Sean Augenstein. 2018. Federated Learning for Mobile Keyboard Prediction. (2018). https:\/\/arxiv.org\/abs\/1811.03604."},{"key":"e_1_3_3_23_2","doi-asserted-by":"publisher","DOI":"10.1561\/2200000083"},{"key":"e_1_3_3_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2022.3188292"},{"key":"e_1_3_3_25_2","article-title":"Federated optimization: Distributed machine learning for on-device intelligence","volume":"1610","author":"Kone\u010dn\u00fd Jakub","year":"2016","unstructured":"Jakub Kone\u010dn\u00fd, H. Brendan McMahan, Daniel Ramage, and Peter Richt\u00e1rik. 2016. Federated optimization: Distributed machine learning for on-device intelligence. CoRR abs\/1610.02527 (2016). arXiv:1610.02527http:\/\/arxiv.org\/abs\/1610.02527.","journal-title":"CoRR"},{"key":"e_1_3_3_26_2","article-title":"Federated learning: Strategies for improving communication efficiency","author":"Kone\u010dn\u1ef3 Jakub","year":"2016","unstructured":"Jakub Kone\u010dn\u1ef3, H. Brendan McMahan, Felix X. Yu, Peter Richt\u00e1rik, Ananda Theertha Suresh, and Dave Bacon. 2016. Federated learning: Strategies for improving communication efficiency. arXiv preprint arXiv:1610.05492 (2016).","journal-title":"arXiv preprint arXiv:1610.05492"},{"key":"e_1_3_3_27_2","volume-title":"International Conference on Learning Representations","author":"Li Oscar","year":"2022","unstructured":"Oscar Li, Jiankai Sun, Xin Yang, Weihao Gao, Hongyi Zhang, Junyuan Xie, Virginia Smith, and Chong Wang. 2022. Label leakage and protection in two-party split learning. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=cOtBRgsf2fO."},{"key":"e_1_3_3_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2020.2986024"},{"key":"e_1_3_3_29_2","article-title":"Vertical federated learning","author":"Liu Yang","year":"2022","unstructured":"Yang Liu, Yan Kang, Tianyuan Zou, Yanhong Pu, Yuanqin He, Xiaozhou Ye, Ye Ouyang, Ya-Qin Zhang, and Qiang Yang. 2022. Vertical federated learning. arXiv preprint arXiv:2211.12814 (2022).","journal-title":"arXiv preprint arXiv:2211.12814"},{"key":"e_1_3_3_30_2","article-title":"Sharing models or coresets: A study based on membership inference attack","author":"Lu Hanlin","year":"2020","unstructured":"Hanlin Lu, Changchang Liu, Ting He, Shiqiang Wang, and Kevin S. Chan. 2020. Sharing models or coresets: A study based on membership inference attack. arXiv preprint arXiv:2007.02977 (2020).","journal-title":"arXiv preprint arXiv:2007.02977"},{"key":"e_1_3_3_31_2","doi-asserted-by":"crossref","first-page":"1627","DOI":"10.1109\/Allerton.2013.6736724","volume-title":"2013 51st Annual Allerton Conference on Communication, Control, and Computing (Allerton)","author":"Makhdoumi Ali","year":"2013","unstructured":"Ali Makhdoumi and Nadia Fawaz. 2013. Privacy-utility tradeoff under statistical uncertainty. In 2013 51st Annual Allerton Conference on Communication, Control, and Computing (Allerton). IEEE, 1627\u20131634."},{"key":"e_1_3_3_32_2","first-page":"1273","volume-title":"Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (Proceedings of Machine Learning Research)","volume":"54","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (Proceedings of Machine Learning Research), Aarti Singh and Jerry Zhu (Eds.), Vol. 54. PMLR, 1273\u20131282. https:\/\/proceedings.mlr.press\/v54\/mcmahan17a.html."},{"key":"e_1_3_3_33_2","first-page":"1273","volume-title":"Artificial Intelligence and Statistics","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Artificial Intelligence and Statistics. PMLR, 1273\u20131282."},{"issue":"8","key":"e_1_3_3_34_2","doi-asserted-by":"crossref","first-page":"5168","DOI":"10.1109\/TCOMM.2021.3083316","article-title":"Fast federated learning by balancing communication trade-offs","volume":"69","author":"Nori Milad Khademi","year":"2021","unstructured":"Milad Khademi Nori, Sangseok Yun, and Il-Min Kim. 2021. Fast federated learning by balancing communication trade-offs. IEEE Transactions on Communications 69, 8 (2021), 5168\u20135182.","journal-title":"IEEE Transactions on Communications"},{"key":"e_1_3_3_35_2","doi-asserted-by":"publisher","DOI":"10.5555\/1756123.1756146"},{"key":"e_1_3_3_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2903658"},{"key":"e_1_3_3_37_2","doi-asserted-by":"publisher","DOI":"10.1038\/s41746-020-00323-1"},{"key":"e_1_3_3_38_2","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2013.2253320"},{"key":"e_1_3_3_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/359168.359176"},{"key":"e_1_3_3_40_2","doi-asserted-by":"publisher","DOI":"10.1145\/3383313.3411528"},{"key":"e_1_3_3_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/3338501.3357370"},{"key":"e_1_3_3_42_2","doi-asserted-by":"publisher","DOI":"10.1145\/3378679.3394533"},{"key":"e_1_3_3_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/ALLERTON.2017.8262832"},{"key":"e_1_3_3_44_2","first-page":"212","article-title":"Adaptive communication strategies to achieve the best error-runtime trade-off in local-update SGD","volume":"1","author":"Wang Jianyu","year":"2019","unstructured":"Jianyu Wang and Gauri Joshi. 2019. Adaptive communication strategies to achieve the best error-runtime trade-off in local-update SGD. Proceedings of Machine Learning and Systems 1 (2019), 212\u2013229.","journal-title":"Proceedings of Machine Learning and Systems"},{"key":"e_1_3_3_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2016.2584610"},{"key":"e_1_3_3_46_2","doi-asserted-by":"publisher","DOI":"10.1038\/s41586-021-03583-3"},{"key":"e_1_3_3_47_2","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"e_1_3_3_48_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"e_1_3_3_49_2","first-page":"493","volume-title":"2020 USENIX Annual Technical Conference (USENIX ATC 20)","author":"Zhang Chengliang","year":"2020","unstructured":"Chengliang Zhang, Suyi Li, Junzhe Xia, Wei Wang, Feng Yan, and Yang Liu. 2020. BatchCrypt: Efficient homomorphic encryption for cross-silo federated learning. In 2020 USENIX Annual Technical Conference (USENIX ATC 20). USENIX Association, 493\u2013506. https:\/\/www.usenix.org\/conference\/atc20\/presentation\/zhang-chengliang."},{"key":"e_1_3_3_50_2","first-page":"1","volume-title":"2019 IEEE Global Communications Conference (GLOBECOM)","author":"Zhang Jiale","year":"2019","unstructured":"Jiale Zhang, Bing Chen, Shui Yu, and Hai Deng. 2019. PEFL: A privacy-enhanced federated learning scheme for big data analytics. In 2019 IEEE Global Communications Conference (GLOBECOM). IEEE, 1\u20136."},{"key":"e_1_3_3_51_2","doi-asserted-by":"publisher","DOI":"10.1145\/3563219"},{"key":"e_1_3_3_52_2","article-title":"iDLG: Improved deep leakage from gradients","author":"Zhao Bo","year":"2020","unstructured":"Bo Zhao, Konda Reddy Mopuri, and Hakan Bilen. 2020. iDLG: Improved deep leakage from gradients. arXiv preprint arXiv:2001.02610 (2020).","journal-title":"arXiv preprint arXiv:2001.02610"},{"key":"e_1_3_3_53_2","volume-title":"Advances in Neural Information Processing Systems","author":"Zhu Ligeng","year":"2019","unstructured":"Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep leakage from gradients. In Advances in Neural Information Processing Systems, H. Wallach, H. Larochelle, A. Beygelzimer, F. d'Alch\u00e9-Buc, E. Fox, and R. Garnett (Eds.), Vol. 32. Curran Associates, Inc.https:\/\/proceedings.neurips.cc\/paper\/2019\/file\/60a6c4002cc7b29142def8871531281a-Paper.pdf."},{"key":"e_1_3_3_54_2","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2022.3192121"}],"container-title":["ACM Transactions on Intelligent Systems and Technology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3595185","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3595185","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:49:08Z","timestamp":1750182548000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3595185"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,20]]},"references-count":53,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2023,12,31]]}},"alternative-id":["10.1145\/3595185"],"URL":"https:\/\/doi.org\/10.1145\/3595185","relation":{},"ISSN":["2157-6904","2157-6912"],"issn-type":[{"value":"2157-6904","type":"print"},{"value":"2157-6912","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,11,20]]},"assertion":[{"value":"2022-08-30","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-03-26","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2023-11-20","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}