{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,16]],"date-time":"2026-06-16T09:44:54Z","timestamp":1781603094529,"version":"3.54.5"},"reference-count":81,"publisher":"Association for Computing Machinery (ACM)","issue":"4","license":[{"start":{"date-parts":[[2023,12,19]],"date-time":"2023-12-19T00:00:00Z","timestamp":1702944000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Proc. ACM Interact. Mob. Wearable Ubiquitous Technol."],"published-print":{"date-parts":[[2023,12,19]]},"abstract":"<jats:p>Federated Learning (FL) aims to improve machine learning privacy by allowing several data owners in edge and ubiquitous computing systems to collaboratively train a model, while preserving their local training data private, and sharing only model training parameters. However, FL systems remain vulnerable to privacy attacks, and in particular, to membership inference attacks that allow adversaries to determine whether a given data sample belongs to participants' training data, thus, raising a significant threat in sensitive ubiquitous computing systems. Indeed, membership inference attacks are based on a binary classifier that is able to differentiate between member data samples used to train a model and non-member data samples not used for training. In this context, several defense mechanisms, including differential privacy, have been proposed to counter such privacy attacks. However, the main drawback of these methods is that they may reduce model accuracy while incurring non-negligible computational costs. In this paper, we precisely address this problem with PASTEL, a FL privacy-preserving mechanism that is based on a novel multi-objective learning function. On the one hand, PASTEL decreases the generalization gap to reduce the difference between member data and non-member data, and on the other hand, PASTEL reduces model loss and leverages adaptive gradient descent optimization for preserving high model accuracy. Our experimental evaluations conducted on eight widely used datasets and five model architectures show that PASTEL significantly reduces membership inference attack success rates by up to -28%, reaching optimal privacy protection in most cases, with low to no perceptible impact on model accuracy.<\/jats:p>","DOI":"10.1145\/3633808","type":"journal-article","created":{"date-parts":[[2024,1,12]],"date-time":"2024-01-12T12:52:04Z","timestamp":1705063924000},"page":"1-29","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":8,"title":["PASTEL"],"prefix":"10.1145","volume":"7","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8422-4209","authenticated-orcid":false,"given":"Fatima","family":"Elhattab","sequence":"first","affiliation":[{"name":"INSA Lyon -- LIRIS, Lyon, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0558-0123","authenticated-orcid":false,"given":"Sara","family":"Bouchenak","sequence":"additional","affiliation":[{"name":"INSA Lyon -- LIRIS, Lyon, France"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3530-6977","authenticated-orcid":false,"given":"C\u00e9dric","family":"Boscher","sequence":"additional","affiliation":[{"name":"INSA Lyon -- LIRIS, Lyon, France"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,1,12]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.3390\/s22041373"},{"key":"e_1_2_1_3_1","volume-title":"AdaGrad Avoids Saddle Points. In International Conference on Machine Learning, ICML 2022","volume":"771","author":"Antonakopoulos Kimon","year":"2022","unstructured":"Kimon Antonakopoulos, Panayotis Mertikopoulos, Georgios Piliouras, and Xiao Wang. 2022. AdaGrad Avoids Saddle Points. In International Conference on Machine Learning, ICML 2022, 17-23 July 2022 (Proceedings of Machine Learning Research, Vol. 162), Kamalika Chaudhuri, Stefanie Jegelka, Le Song, Csaba Szepesv\u00e1ri, Gang Niu, and Sivan Sabato (Eds.). PMLR, Baltimore, Maryland, USA, 731--771."},{"key":"e_1_2_1_4_1","volume-title":"Aaditya Kumar Singh, and Sunav Choudhary","author":"Arivazhagan Manoj Ghuhan","year":"2019","unstructured":"Manoj Ghuhan Arivazhagan, Vinay Aggarwal, Aaditya Kumar Singh, and Sunav Choudhary. 2019. Federated Learning with Personalization Layers. arXiv:1912.00818 1912.00818 (2019)."},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2015.071829"},{"key":"e_1_2_1_6_1","volume-title":"On Adaptive Sampling Algorithms for IoT Devices. In IEEE International Conference on Communications (ICC","author":"Ben-Aboud Yassine","year":"2021","unstructured":"Yassine Ben-Aboud, Daniel Bonilla Licea, Mounir Ghogho, and Abdellatif Kobbane. 2021. On Adaptive Sampling Algorithms for IoT Devices. In IEEE International Conference on Communications (ICC 2021). Montreal, QC, Canada, 1--7."},{"key":"e_1_2_1_7_1","volume-title":"Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent. In Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017","author":"Blanchard Peva","year":"2017","unstructured":"Peva Blanchard, El Mahdi El Mhamdi, Rachid Guerraoui, and Julien Stainer. 2017. Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent. In Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017, December 4-9, 2017, Long Beach, CA, USA, Isabelle Guyon, Ulrike von Luxburg, Samy Bengio, Hanna M. Wallach, Rob Fergus, S. V. N. Vishwanathan, and Roman Garnett (Eds.). Advances in Neural Information Processing Systems, Long Beach, CA, USA, 119--129."},{"key":"e_1_2_1_8_1","volume-title":"Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent. In Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017","author":"Blanchard Peva","year":"2017","unstructured":"Peva Blanchard, El Mahdi El Mhamdi, Rachid Guerraoui, and Julien Stainer. 2017. Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent. In Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017, December 4-9, 2017, Isabelle Guyon, Ulrike von Luxburg, Samy Bengio, Hanna M. Wallach, Rob Fergus, S. V. N. Vishwanathan, and Roman Garnett (Eds.). NIPS, Long Beach, CA, USA, 119--129."},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"e_1_2_1_13_1","unstructured":"Lorenzo Cavallaro Johannes Kinder Sadia Afroz Battista Biggio Nicholas Carlini Yuval Elovici and Asaf Shabtai (Eds.). 2019. HybridAlpha: An Efficient Approach for Privacy-Preserving Federated Learning. ACM."},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-17140-6_10"},{"key":"e_1_2_1_15_1","volume-title":"Bias Propagation in Federated Learning. In The Eleventh International Conference on Learning Representations, ICLR 2023","author":"Chang Hongyan","year":"2023","unstructured":"Hongyan Chang and Reza Shokri. 2023. Bias Propagation in Federated Learning. In The Eleventh International Conference on Learning Representations, ICLR 2023, Kigali, Rwanda, May 1-5, 2023. OpenReview.net. https:\/\/openreview.net\/pdf?id=V7CYzdruWdm"},{"key":"e_1_2_1_16_1","unstructured":"Bhaskar Ray Chaudhury Linyi Li Mintong Kang Bo Li and Ruta Mehta. 2022. Fairness in Federated Learning via Core-Stability. In NeurIPS. http:\/\/papers.nips.cc\/paper_files\/paper\/2022\/hash\/25e92e33ac8c35fd49f394c37f21b6da-Abstract-Conference.html"},{"key":"e_1_2_1_17_1","volume-title":"The Tenth International Conference on Learning Representations, ICLR 2022","author":"Chen Dingfan","year":"2022","unstructured":"Dingfan Chen, Ning Yu, and Mario Fritz. 2022. RelaxLoss: Defending Membership Inference Attacks without Losing Utility. In The Tenth International Conference on Learning Representations, ICLR 2022, April 25-29, 2022. OpenReview.net, Virtual Event."},{"key":"e_1_2_1_18_1","volume-title":"The Tenth International Conference on Learning Representations, ICLR 2022","author":"Chen Dingfan","year":"2022","unstructured":"Dingfan Chen, Ning Yu, and Mario Fritz. 2022. RelaxLoss: Defending Membership Inference Attacks without Losing Utility. In The Tenth International Conference on Learning Representations, ICLR 2022, April 25-29, 2022. OpenReview.net, Virtual Event."},{"key":"e_1_2_1_19_1","volume-title":"GAN-Leaks: A Taxonomy of Membership Inference Attacks against GANs. ArXiv abs\/1909.03935","author":"Chen Dingfan","year":"2019","unstructured":"Dingfan Chen, Ning Yu, Yang Zhang, and Mario Fritz. 2019. GAN-Leaks: A Taxonomy of Membership Inference Attacks against GANs. ArXiv abs\/1909.03935 (2019)."},{"key":"e_1_2_1_20_1","volume-title":"Label-Only Membership Inference Attacks. ArXiv abs\/2007.14321","author":"Choquette-Choo Christopher A.","year":"2021","unstructured":"Christopher A. Choquette-Choo, Florian Tram\u00e8r, Nicholas Carlini, and Nicolas Papernot. 2021. Label-Only Membership Inference Attacks. ArXiv abs\/2007.14321 (2021)."},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2017.7952190"},{"key":"e_1_2_1_22_1","first-page":"3","article-title":"The Algorithmic Foundations of Differential Privacy","volume":"9","author":"Dwork Cynthia","year":"2014","unstructured":"Cynthia Dwork and Aaron Roth. 2014. The Algorithmic Foundations of Differential Privacy. Found. Trends Theor. Comput. Sci. 9, 3--4 (2014), 211--407.","journal-title":"Found. Trends Theor. Comput. Sci."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.3390\/fi13040094"},{"key":"e_1_2_1_24_1","volume-title":"sqSGD: Locally Private and Communication Efficient Federated Learning. ArXiv abs\/2206.10565","author":"Feng Yan","year":"2022","unstructured":"Yan Feng, Tao Xiong, Ruofan Wu, LingJuan Lv, and Leilei Shi. 2022. sqSGD: Locally Private and Communication Efficient Federated Learning. ArXiv abs\/2206.10565 (2022). arXiv:2206.10565"},{"key":"e_1_2_1_25_1","volume-title":"Label Inference Attacks Against Vertical Federated Learning. In 31st USENIX Security Symposium, USENIX Security 2022","author":"Fu Chong","year":"2022","unstructured":"Chong Fu, Xuhong Zhang, Shouling Ji, Jinyin Chen, Jingzheng Wu, Shanqing Guo, Jun Zhou, Alex X. Liu, and Ting Wang. 2022. Label Inference Attacks Against Vertical Federated Learning. In 31st USENIX Security Symposium, USENIX Security 2022, Boston, MA, USA, August 10-12, 2022, Kevin R. B. Butler and Kurt Thomas (Eds.). USENIX Association, 1397--1414. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/fu-chong"},{"key":"e_1_2_1_26_1","volume-title":"Training Speech Recognition Models with Federated Learning: A Quality\/Cost Framework. In IEEE International Conference on Acoustics, Speech and Signal Processing, ICASSP 2021","author":"Guliani Dhruv","year":"2021","unstructured":"Dhruv Guliani, Fran\u00e7oise Beaufays, and Giovanni Motta. 2021. Training Speech Recognition Models with Federated Learning: A Quality\/Cost Framework. In IEEE International Conference on Acoustics, Speech and Signal Processing, ICASSP 2021, June 6-11, 2021. IEEE, Toronto, ON, Canada, 3080--3084."},{"key":"e_1_2_1_27_1","volume-title":"Federated Learning with Compression: Unified Analysis and Sharp Guarantees. In The 24th International Conference on Artificial Intelligence and Statistics, AISTATS 2021","volume":"2358","author":"Haddadpour Farzin","year":"2021","unstructured":"Farzin Haddadpour, Mohammad Mahdi Kamani, Aryan Mokhtari, and Mehrdad Mahdavi. 2021. Federated Learning with Compression: Unified Analysis and Sharp Guarantees. In The 24th International Conference on Artificial Intelligence and Statistics, AISTATS 2021, April 13-15, 2021 (Proceedings of Machine Learning Research, Vol. 130), Arindam Banerjee and Kenji Fukumizu (Eds.). PMLR, Virtual Event, 2350--2358."},{"key":"e_1_2_1_28_1","unstructured":"Andrew Hard Chlo\u00e9 M Kiddon Daniel Ramage Francoise Beaufays Hubert Eichner Kanishka Rao Rajiv Mathews and Sean Augenstein. 2018. Federated Learning for Mobile Keyboard Prediction."},{"key":"e_1_2_1_29_1","volume-title":"Deep Residual Learning for Image Recognition. In 2016 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2016","author":"He Kaiming","year":"2016","unstructured":"Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep Residual Learning for Image Recognition. In 2016 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2016. IEEE Computer Society, Las Vegas, NV, USA, June 27-30, 2016, 770--778."},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1587\/transinf.2017ICP0013"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2013.6706807"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2305.16446"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363201"},{"key":"e_1_2_1_35_1","unstructured":"Peter Kairouz H. Brendan McMahan Brendan Avent Aur\u00e9lien Bellet Mehdi Bennis Arjun Nitin Bhagoji Kallista A. Bonawitz Zachary Charles Graham Cormode Rachel Cummings Rafael G. L. D'Oliveira Salim El Rouayheb David Evans Josh Gardner Zachary Garrett Adri\u00e0 Gasc\u00f3n Badih Ghazi Phillip B. Gibbons Marco Gruteser Za\u00efd Harchaoui Chaoyang He Lie He Zhouyuan Huo Ben Hutchinson Justin Hsu Martin Jaggi Tara Javidi Gauri Joshi Mikhail Khodak Jakub Kone\u010dn\u00fd Aleksandra Korolova Farinaz Koushanfar Sanmi Koyejo Tancr\u00e8de Lepoint Yang Liu Prateek Mittal Mehryar Mohri Richard Nock Ayfer \u00d6zg\u00fcr Rasmus Pagh Mariana Raykova Hang Qi Daniel Ramage Ramesh Raskar Dawn Song Weikang Song Sebastian U. Stich Ziteng Sun Ananda Theertha Suresh Florian Tram\u00e8r Praneeth Vepakomma Jianyu Wang Li Xiong Zheng Xu Qiang Yang Felix X. Yu Han Yu and Sen Zhao. 2019. Advances and Open Problems in Federated Learning. ArXiv abs\/1912.04977 (2019). arXiv:1912.04977"},{"key":"e_1_2_1_36_1","volume-title":"Proceedings of the 38th International Conference on Machine Learning (Proceedings of Machine Learning Research","volume":"5355","author":"Kaya Yigitcan","year":"2021","unstructured":"Yigitcan Kaya and Tudor Dumitras. 2021. When Does Data Augmentation Help With Membership Inference Attacks?. In Proceedings of the 38th International Conference on Machine Learning (Proceedings of Machine Learning Research, Vol. 139), Marina Meila and Tong Zhang (Eds.). PMLR, 5345--5355. https:\/\/proceedings.mlr.press\/v139\/kaya21a.html"},{"key":"e_1_2_1_37_1","volume-title":"Kingma and Jimmy Ba","author":"Diederik","year":"2015","unstructured":"Diederik P. Kingma and Jimmy Ba. 2015. Adam: A Method for Stochastic Optimization. ArXiv abs\/1412.6980 (2015)."},{"key":"e_1_2_1_38_1","volume-title":"Federated Optimization: Distributed Machine Learning for On-Device Intelligence. ArXiv abs\/1610.02527","author":"Kone\u010dn\u00fd Jakub","year":"2016","unstructured":"Jakub Kone\u010dn\u00fd, H. Brendan McMahan, Daniel Ramage, and Peter Richt\u00e1rik. 2016. Federated Optimization: Distributed Machine Learning for On-Device Intelligence. ArXiv abs\/1610.02527 (2016). arXiv:1610.02527"},{"key":"e_1_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1002\/0471722065"},{"key":"e_1_2_1_40_1","unstructured":"Alex Krizhevsky Vinod Nair and Geoffrey Hinton. 2010. CIFAR-10 (Canadian Institute for Advanced Research). http:\/\/www.cs.toronto.edu\/ kriz\/cifar.html."},{"key":"e_1_2_1_41_1","series-title":"SIAM Series on Optimization","volume-title":"Stochastic Approximation and Optimization of Random Systems","author":"Kushner Harold J","unstructured":"Harold J Kushner and George G Yin. 1997. Stochastic Approximation and Optimization of Random Systems. SIAM Series on Optimization, Society for Industrial and Applied Mathematics, Philadelphia."},{"key":"e_1_2_1_42_1","volume-title":"Membership Inference Attacks and Defenses in Supervised Learning via Generalization Gap. ArXiv abs\/2002.12062","author":"Li Jiacheng","year":"2020","unstructured":"Jiacheng Li, Ninghui Li, and Bruno Ribeiro. 2020. Membership Inference Attacks and Defenses in Supervised Learning via Generalization Gap. ArXiv abs\/2002.12062 (2020). arXiv:2002.12062"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3022911"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1186\/s42400-021-00105-6"},{"key":"e_1_2_1_45_1","volume-title":"Deep Learning Face Attributes in the Wild. In 2015 IEEE International Conference on Computer Vision, ICCV 2015, December 7-13","author":"Liu Ziwei","year":"2015","unstructured":"Ziwei Liu, Ping Luo, Xiaogang Wang, and Xiaoou Tang. 2015. Deep Learning Face Attributes in the Wild. In 2015 IEEE International Conference on Computer Vision, ICCV 2015, December 7-13, 2015. IEEE Computer Society, Santiago, Chile, 3730--3738."},{"key":"e_1_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63076-8_1"},{"key":"e_1_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1145\/3302505.3310068"},{"key":"e_1_2_1_48_1","volume-title":"Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, AISTATS 2017","volume":"1282","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Ag\u00fcera y Arcas. 2017. Communication-Efficient Learning of Deep Networks from Decentralized Data. In Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, AISTATS 2017, 20-22 April 2017, (Proceedings of Machine Learning Research, Vol. 54), Aarti Singh and Xiaojin (Jerry) Zhu (Eds.). PMLR, Fort Lauderdale, FL, USA, 1273--1282."},{"key":"e_1_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/1810891.1810916"},{"key":"e_1_2_1_50_1","volume-title":"Exploiting Unintended Feature Leakage in Collaborative Learning. 2019 IEEE Symposium on Security and Privacy (SP 2019)","author":"Melis Luca","year":"2019","unstructured":"Luca Melis, Congzheng Song, Emiliano De Cristofaro, and Vitaly Shmatikov. 2019. Exploiting Unintended Feature Leakage in Collaborative Learning. 2019 IEEE Symposium on Security and Privacy (SP 2019) 10.1109 (May 2019)."},{"key":"e_1_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0016-0032(96)00063-4"},{"key":"e_1_2_1_52_1","volume-title":"Layer-wise Characterization of Latent Information Leakage in Federated Learning. ArXiv abs\/2010.08762","author":"Mo Fan","year":"2020","unstructured":"Fan Mo, Anastasia Borovykh, Mohammad Malekzadeh, Hamed Haddadi, and Soteris Demetriou. 2020. Layer-wise Characterization of Latent Information Leakage in Federated Learning. ArXiv abs\/2010.08762 (2020). arXiv:2010.08762"},{"key":"e_1_2_1_53_1","volume-title":"Quantifying Information Leakage from Gradients. ArXiv abs\/2105.13929","author":"Mo Fan","year":"2021","unstructured":"Fan Mo, Anastasia Borovykh, Mohammad Malekzadeh, Hamed Haddadi, and Soteris Demetriou. 2021. Quantifying Information Leakage from Gradients. ArXiv abs\/2105.13929 (2021). arXiv:2105.13929"},{"key":"e_1_2_1_54_1","volume-title":"Toward Robustness and Privacy in Federated Learning: Experimenting with Local and Central Differential Privacy. ArXiv abs\/2009.03561","author":"Naseri Mohammad","year":"2020","unstructured":"Mohammad Naseri, Jamie Hayes, and Emiliano De Cristofaro. 2020. Toward Robustness and Privacy in Federated Learning: Experimenting with Local and Central Differential Privacy. ArXiv abs\/2009.03561 (2020). arXiv:2009.03561"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"e_1_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"e_1_2_1_57_1","volume-title":"Deep Federated Learning for Autonomous Driving. In 2022 IEEE Intelligent Vehicles Symposium, IV 2022","author":"Nguyen Anh","year":"2022","unstructured":"Anh Nguyen, Tuong Do, Minh Tran, Binh X. Nguyen, Chien Duong, Tu Phan, Erman Tjiputra, and Quang D. Tran. 2022. Deep Federated Learning for Autonomous Driving. In 2022 IEEE Intelligent Vehicles Symposium, IV 2022, June 4-9, 2022. IEEE, Aachen, Germany, 1824--1830."},{"key":"e_1_2_1_58_1","volume-title":"Semi-supervised Knowledge Transfer for Deep Learning from Private Training Data. ArXiv abs\/1610.05755","author":"Papernot Nicolas","year":"2017","unstructured":"Nicolas Papernot, Mart\u00edn Abadi, \u00dalfar Erlingsson, Ian J. Goodfellow, and Kunal Talwar. 2017. Semi-supervised Knowledge Transfer for Deep Learning from Private Training Data. ArXiv abs\/1610.05755 (2017)."},{"key":"e_1_2_1_59_1","volume-title":"Scalable Private Learning with PATE. ArXiv abs\/1802.08908","author":"Papernot Nicolas","year":"2018","unstructured":"Nicolas Papernot, Shuang Song, Ilya Mironov, Ananth Raghunathan, Kunal Talwar, and \u00dalfar Erlingsson. 2018. Scalable Private Learning with PATE. ArXiv abs\/1802.08908 (2018)."},{"key":"e_1_2_1_60_1","unstructured":"Guilherme Perin and Stjepan Picek. 2020. On the Influence of Optimizers in Deep Learning-based Side-channel Analysis. Cryptology ePrint Archive Paper 2020\/977. https:\/\/eprint.iacr.org\/2020\/977."},{"key":"e_1_2_1_61_1","volume-title":"The future of digital health with federated learning. npj Digital Medicine 3 (12","author":"Rieke Nicola","year":"2020","unstructured":"Nicola Rieke, Jonny Hancox, Wenqi Li, Fausto Milletari, Holger Roth, Shadi Albarqouni, Spyridon Bakas, Mathieu Galtier, Bennett Landman, Klaus Maier-Hein, S\u00e9bastien Ourselin, Micah Sheller, Ronald Summers, Andrew Trask, Daguang Xu, Maximilian Baust, and Manuel Jorge Cardoso. 2020. The future of digital health with federated learning. npj Digital Medicine 3 (12 2020)."},{"key":"e_1_2_1_62_1","volume-title":"ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. In 26th Annual Network and Distributed System Security Symposium, NDSS 2019","author":"Salem Ahmed","year":"2019","unstructured":"Ahmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang, Mario Fritz, and Michael Backes. 2019. ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. In 26th Annual Network and Distributed System Security Symposium, NDSS 2019, February 24-27, 2019. The Internet Society, San Diego, California, USA."},{"key":"e_1_2_1_63_1","volume-title":"Membership Inference Attacks Against Machine Learning Models. In IEEE Symposium on Security and Privacy, S&P","author":"Shokri Reza","year":"2017","unstructured":"Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017. Membership Inference Attacks Against Machine Learning Models. In IEEE Symposium on Security and Privacy, S&P 2017. IEEE, San Jose, CA, USA, 3--18."},{"key":"e_1_2_1_64_1","volume-title":"3rd International Conference on Learning Representations, ICLR","author":"Simonyan Karen","year":"2015","unstructured":"Karen Simonyan and Andrew Zisserman. 2015. Very Deep Convolutional Networks for Large-Scale Image Recognition. In 3rd International Conference on Learning Representations, ICLR 2015, May 7-9, 2015, Conference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds.). ICLR, San Diego, CA, USA."},{"key":"e_1_2_1_65_1","volume-title":"A disciplined approach to neural network hyper-parameters: Part 1 - learning rate, batch size, momentum, and weight decay. ArXiv abs\/1803.09820","author":"Smith Leslie N.","year":"2018","unstructured":"Leslie N. Smith. 2018. A disciplined approach to neural network hyper-parameters: Part 1 - learning rate, batch size, momentum, and weight decay. ArXiv abs\/1803.09820 (2018). arXiv:1803.09820"},{"key":"e_1_2_1_66_1","volume-title":"Proceedings of the 36th International Conference on Machine Learning, ICML 2019","volume":"5965","author":"Staib Matthew","year":"2019","unstructured":"Matthew Staib, Sashank J. Reddi, Satyen Kale, Sanjiv Kumar, and Suvrit Sra. 2019. Escaping Saddle Points with Adaptive Gradient Methods. In Proceedings of the 36th International Conference on Machine Learning, ICML 2019, 9-15 June 2019, (Proceedings of Machine Learning Research, Vol. 97), Kamalika Chaudhuri and Ruslan Salakhutdinov (Eds.). PMLR, Long Beach, California, USA, 5956--5965."},{"key":"e_1_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/217"},{"key":"e_1_2_1_68_1","first-page":"07963","article-title":"Can You Really Backdoor Federated Learning? ArXiv abs\/1911.07963 (2019)","volume":"1911","author":"Sun Ziteng","year":"2019","unstructured":"Ziteng Sun, Peter Kairouz, Ananda Theertha Suresh, and H. Brendan McMahan. 2019. Can You Really Backdoor Federated Learning? ArXiv abs\/1911.07963 (2019). ArXiv:1911.07963","journal-title":"ArXiv"},{"key":"e_1_2_1_69_1","doi-asserted-by":"crossref","unstructured":"Elham Tabassi Kevin Burns Michael Hadjimichael Andres Molina-Markham and Julian Sexton. 2019. A taxonomy and terminology of adversarial machine learning.","DOI":"10.6028\/NIST.IR.8269-draft"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSC.2019.2897554"},{"key":"e_1_2_1_71_1","volume-title":"Federated Learning with Matched Averaging. In 8th International Conference on Learning Representations, ICLR 2020","author":"Wang Hongyi","year":"2020","unstructured":"Hongyi Wang, Mikhail Yurochkin, Yuekai Sun, Dimitris S. Papailiopoulos, and Yasaman Khazaeni. 2020. Federated Learning with Matched Averaging. In 8th International Conference on Learning Representations, ICLR 2020, Addis Ababa, Ethiopia, April 26-30, 2020. OpenReview.net, Addis Ababa, Ethiopia."},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3196646"},{"key":"e_1_2_1_73_1","volume-title":"Speech Commands: A Dataset for Limited-Vocabulary Speech Recognition. ArXiv abs\/1804.03209","author":"Warden Pete","year":"2018","unstructured":"Pete Warden. 2018. Speech Commands: A Dataset for Limited-Vocabulary Speech Recognition. ArXiv abs\/1804.03209 (2018)."},{"key":"e_1_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2022.110014"},{"key":"e_1_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"e_1_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"e_1_2_1_77_1","volume-title":"Opacus: User-Friendly Differential Privacy Library in PyTorch. ArXiv abs\/2109.12298","author":"Yousefpour Ashkan","year":"2021","unstructured":"Ashkan Yousefpour, Igor Shilov, Alexandre Sablayrolles, Davide Testuggine, Karthik Prasad, Mani Malek, John Nguyen, Sayan Ghosh, Akash Bharadwaj, Jessica Zhao, Graham Cormode, and Ilya Mironov. 2021. Opacus: User-Friendly Differential Privacy Library in PyTorch. ArXiv abs\/2109.12298 (2021). arXiv:2109.12298"},{"key":"e_1_2_1_78_1","volume-title":"Federated Learning with Non-IID Data. ArXiv abs\/1806.00582","author":"Zhao Yue","year":"2018","unstructured":"Yue Zhao, Meng Li, Liangzhen Lai, Naveen Suda, Damon Civin, and Vikas Chandra. 2018. Federated Learning with Non-IID Data. ArXiv abs\/1806.00582 (2018). https:\/\/api.semanticscholar.org\/CorpusID:46936175"},{"key":"e_1_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2020\/642"},{"key":"e_1_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3146448"},{"key":"e_1_2_1_81_1","first-page":"17","article-title":"Deep Leakage from Gradients","volume":"12500","author":"Zhu Ligeng","year":"2020","unstructured":"Ligeng Zhu and Song Han. 2020. Deep Leakage from Gradients. Springer 12500 (2020), 17--31.","journal-title":"Springer"}],"container-title":["Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3633808","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3633808","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,27]],"date-time":"2025-08-27T16:59:59Z","timestamp":1756313999000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3633808"}},"subtitle":["Privacy-Preserving Federated Learning in Edge Computing"],"short-title":[],"issued":{"date-parts":[[2023,12,19]]},"references-count":81,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2023,12,19]]}},"alternative-id":["10.1145\/3633808"],"URL":"https:\/\/doi.org\/10.1145\/3633808","relation":{},"ISSN":["2474-9567"],"issn-type":[{"value":"2474-9567","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,12,19]]},"assertion":[{"value":"2024-01-12","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}