{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T21:37:04Z","timestamp":1784065024820,"version":"3.55.0"},"reference-count":40,"publisher":"Association for Computing Machinery (ACM)","issue":"12","license":[{"start":{"date-parts":[[2024,11,22]],"date-time":"2024-11-22T00:00:00Z","timestamp":1732233600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61802298"],"award-info":[{"award-number":["61802298"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002858","name":"China Postdoctoral Science Foundation","doi-asserted-by":"publisher","award":["2020T130513"],"award-info":[{"award-number":["2020T130513"]}],"id":[{"id":"10.13039\/501100002858","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Commun. ACM"],"published-print":{"date-parts":[[2024,12]]},"abstract":"<jats:p>\n            Federated learning (FL) has great potential for large-scale machine learning (ML) without exposing raw data. Differential privacy (DP) is the\n            <jats:italic>de facto<\/jats:italic>\n            standard of privacy protection with provable guarantees. Advances in ML suggest that DP would be a perfect fit for FL with comprehensive privacy preservation. Hence, extensive efforts have been devoted to achieving practically usable FL with DP, which however is still challenging. Practitioners often not only are not fully aware of its development and categorization, but also face a hard choice between privacy and utility. Therefore, it calls for a holistic review of current advances and an investigation into the challenges and opportunities for highly usable FL systems with a DP guarantee. In this article, we first introduce the primary concepts of FL and DP, and highlight the benefits of integration. We then review the current developments by categorizing different paradigms and notions. Aiming at usable FL with DP, we present the optimization principles to seek a better tradeoff between model utility and privacy loss. Finally, we discuss future challenges in the emergent areas and relevant research topics.\n          <\/jats:p>","DOI":"10.1145\/3650028","type":"journal-article","created":{"date-parts":[[2024,11,14]],"date-time":"2024-11-14T14:17:07Z","timestamp":1731593827000},"page":"66-77","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":20,"title":["Belt and Braces: When Federated Learning Meets Differential Privacy"],"prefix":"10.1145","volume":"67","author":[{"given":"Xuebin","family":"Ren","sequence":"first","affiliation":[{"name":"Xi'an Jiaotong University, National Engineering Laboratory for Big Data Analytics, Xi'an, Shaanxi, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shusen","family":"Yang","sequence":"additional","affiliation":[{"name":"Xi'an Jiaotong University, National Engineering Laboratory for Big Data Analytics, Xi'an, Shaanxi, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Cong","family":"Zhao","sequence":"additional","affiliation":[{"name":"Imperial College London, Department of Computing, London, London, United Kingdom of Great Britain and Northern Ireland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Julie","family":"McCann","sequence":"additional","affiliation":[{"name":"Imperial College London, Department of Computing, London, London, United Kingdom of Great Britain and Northern Ireland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zongben","family":"Xu","sequence":"additional","affiliation":[{"name":"Xi'an Jiaotong University, National Engineering Laboratory for Big Data Analytics, Xi'an, Shaanxi, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,11,22]]},"reference":[{"key":"e_1_3_1_2_2","doi-asserted-by":"crossref","unstructured":"Abadi M. et al. Deep learning with differential privacy. In Proceedings of ACM CCS (2016) 308\u2013318.","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_1_3_2","unstructured":"Agarwal N. Kairouz P. and Liu Z. The skellam mechanism for differentially private federated learning. In Proceedings of NeurIPS 34 (2021)."},{"key":"e_1_3_1_4_2","unstructured":"Agarwal N. et al. cpSGD: Communication-efficient and differentially-private distributed SGD. In Proceedings of NeurIPS (2018) 7564\u20137575."},{"key":"e_1_3_1_5_2","article-title":"Privacy amplification via random check-ins","author":"Balle B.","year":"2020","unstructured":"Balle, B. et al. Privacy amplification via random check-ins. In\u00a0Proceedings of NeurIPS 33\u00a0(2020).","journal-title":"Proceedings of NeurIPS 33"},{"key":"e_1_3_1_6_2","doi-asserted-by":"crossref","unstructured":"Bonawitz K. et al. Practical secure aggregation for privacy-preserving machine learning. In Proceedings of ACM CCS (2017) 1175\u20131191.","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_3_1_7_2","doi-asserted-by":"crossref","unstructured":"Chen M. et al. When machine unlearning jeopardizes privacy. In Proceedings of ACM CCS (2021) 896\u2013911.","DOI":"10.1145\/3460120.3484756"},{"key":"e_1_3_1_8_2","first-page":"13773","article-title":"Understanding gradient clipping in private SGD: A geometric perspective","author":"Chen X.","year":"2020","unstructured":"Chen, X., Wu, S.Z., and Hong, M. Understanding gradient clipping in private SGD: A geometric perspective. In\u00a0Proceedings of NeurIPS 33\u00a0(2020), 13773\u201313782.","journal-title":"Proceedings of NeurIPS 33"},{"key":"e_1_3_1_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/3387107"},{"issue":"6","key":"e_1_3_1_10_2","first-page":"1","article-title":"Privacy aware learning","author":"Duchi J.C.","year":"2014","unstructured":"Duchi, J.C., Jordan, M.I., and Wainwright, M.J. Privacy aware learning. J. ACM 61,\u00a06 (2014), 1\u201357.","journal-title":"J. ACM 61"},{"key":"e_1_3_1_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/1866739.1866758"},{"key":"e_1_3_1_12_2","doi-asserted-by":"publisher","DOI":"10.1561\/0400000042"},{"key":"e_1_3_1_13_2","unstructured":"Erlingsson \u00da. et al. Encode shuffle analyze privacy revisited: Formalizations and empirical evaluation. arXiv:2001.03618 (2020)."},{"key":"e_1_3_1_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3470449"},{"key":"e_1_3_1_15_2","unstructured":"Geyer R.C. Klein T. and Nabi M. Differentially private federated learning: A client level perspective. arXiv:1712.07557 (2017)."},{"key":"e_1_3_1_16_2","doi-asserted-by":"crossref","unstructured":"Girgis A.M. et al. On the R\u00e9nyi differential privacy of the shuffle model. In Proceedings of ACM CCS (2021) 2321\u20132341.","DOI":"10.1145\/3460120.3484794"},{"key":"e_1_3_1_17_2","unstructured":"Hyland S.L. and Tople S. An empirical study on the intrinsic privacy of sgd. In Theory and Practice of Differential Privacy (CCS Worshop) (2020)."},{"key":"e_1_3_1_18_2","unstructured":"Kairouz P. Liu Z. and Steinke T. The distributed discrete Gaussian mechanism for federated learning with secure aggregation. In Proceedings of ICML (2021) 5201\u20135212."},{"key":"e_1_3_1_19_2","unstructured":"Kairouz P. et al. Practical and private (deep) learning without sampling or shuffling. In Proceedings of ICML (2021) 5213\u20135225."},{"key":"e_1_3_1_20_2","doi-asserted-by":"publisher","DOI":"10.1561\/2200000083"},{"key":"e_1_3_1_21_2","unstructured":"Konecn\u00fd J. et al. Federated learning: Strategies for improving communication efficiency. In Proceedings of NeurIPS (2016) 5\u201310."},{"key":"e_1_3_1_22_2","unstructured":"Li T. Hu S. Beirami A. and Smith V. Ditto: Fair and robust federated learning through personalization. In Proceedings of ICML (2021) 6357\u20136368."},{"key":"e_1_3_1_23_2","unstructured":"Li T. Liu Z. Sekar V. and Smith V. Privacy for free: Communication-efficient learning with differential privacy using sketches. arXiv:1911.00972 (2019)."},{"issue":"2","key":"e_1_3_1_24_2","first-page":"1243","article-title":"Multi-stage asynchronous federated learning with adaptive differential privacy","volume":"46","author":"Li Y.","year":"2024","unstructured":"Li, Y. et al. Multi-stage asynchronous federated learning with adaptive differential privacy. In Proceedings of\u00a0IEEE Trans. Pattern Anal. Mach. Intell. 46, 2 (2024), 1243\u20131256.","journal-title":"Proceedings of\u00a0"},{"key":"e_1_3_1_25_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i10.17053"},{"key":"e_1_3_1_26_2","doi-asserted-by":"crossref","unstructured":"Liu R. Cao Y. Yoshikawa M. and Chen H. Fedsel: Federated sgd under local differential privacy with top-k dimension selection. In Proceedings of DASFAA (2020) 485\u2013501.","DOI":"10.1007\/978-3-030-59410-7_33"},{"key":"e_1_3_1_27_2","unstructured":"McMahan B. et al. Communication-efficient learning of deep networks from decentralized data. In Proceedings of AISTAS (2017) 1273\u20131282."},{"key":"e_1_3_1_28_2","unstructured":"McMahan H.B. Ramage D. Talwar K. and Zhang L. Learning differentially private recurrent language models. In Proceedings of ICLR (2018) 1\u201310."},{"key":"e_1_3_1_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3624010"},{"key":"e_1_3_1_30_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2020.07.009"},{"key":"e_1_3_1_31_2","doi-asserted-by":"crossref","unstructured":"Roy Chowdhury A. et al. Crypt\u03f5: Crypto-assisted differential privacy on untrusted servers. In Proceedings of ACM SIGMOD (2020) 603\u2013619.","DOI":"10.1145\/3318464.3380596"},{"key":"e_1_3_1_32_2","doi-asserted-by":"crossref","unstructured":"Shokri R. and Shmatikov V. Privacy-preserving deep learning. In Proceedings of ACM CCS (2015) 1310\u20131321.","DOI":"10.1145\/2810103.2813687"},{"key":"e_1_3_1_33_2","doi-asserted-by":"crossref","unstructured":"Shokri R. Stronati M. Song C. and Shmatikov V. Membership inference attacks against machine learning models. In Proceedings of IEEE S&P (2017) 3\u201318.","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_1_34_2","doi-asserted-by":"crossref","unstructured":"Sun L. and Lyu L. Federated model distillation with noise-free differential privacy. In Proceedings of IJCAI (2021) 1563\u20131570.","DOI":"10.24963\/ijcai.2021\/216"},{"key":"e_1_3_1_35_2","doi-asserted-by":"crossref","unstructured":"Sun L. Qian J. and Chen X. LDP-FL: Practical private aggregation in federated learning with local differential privacy. In Proceedings\u00a0of IJCAI (2021) 1571\u20131578.","DOI":"10.24963\/ijcai.2021\/217"},{"key":"e_1_3_1_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/3418290"},{"key":"e_1_3_1_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2988575"},{"key":"e_1_3_1_38_2","doi-asserted-by":"crossref","unstructured":"Xu J. Zhang W. and Wang F. A(DP)2SGD: Asynchronous decentralized parallel stochastic gradient descent with differential privacy. In Proceedings of\u00a0IEEE Trans. Pattern Anal. Mach. Intell. 44 11 (2022) 8036\u20138047.","DOI":"10.1109\/TPAMI.2021.3107796"},{"key":"e_1_3_1_39_2","doi-asserted-by":"publisher","DOI":"10.14778\/2350229.2350253"},{"key":"e_1_3_1_40_2","unstructured":"Zhu L. Liu Z. and Han S. Deep leakage from gradients. In Proceedings of NeurIPS (2019) 14774\u201314784."},{"key":"e_1_3_1_41_2","first-page":"7634","volume-title":"Proceedings of ICML","author":"Zhu Y.","year":"2019","unstructured":"Zhu, Y. and Wang, Y.-X. Poission subsampled r\u00e9nyi differential privacy. In Proceedings of ICML. PMLR\u00a0(2019), 7634\u20137642."}],"container-title":["Communications of the ACM"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3650028","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3650028","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:03:43Z","timestamp":1750291423000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3650028"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,11,22]]},"references-count":40,"journal-issue":{"issue":"12","published-print":{"date-parts":[[2024,12]]}},"alternative-id":["10.1145\/3650028"],"URL":"https:\/\/doi.org\/10.1145\/3650028","relation":{},"ISSN":["0001-0782","1557-7317"],"issn-type":[{"value":"0001-0782","type":"print"},{"value":"1557-7317","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,11,22]]},"assertion":[{"value":"2020-09-27","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}