{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,9]],"date-time":"2026-01-09T13:49:53Z","timestamp":1767966593133,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":138,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T00:00:00Z","timestamp":1774828800000},"content-version":"vor","delay-in-days":365,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"U.S. National Science Foundation","award":["CNS-2349610"],"award-info":[{"award-number":["CNS-2349610"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,3,30]]},"DOI":"10.1145\/3676641.3716014","type":"proceedings-article","created":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T16:47:32Z","timestamp":1743094052000},"page":"913-932","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Practical Federated Recommendation Model Learning Using ORAM with Controlled Privacy"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-0069-4542","authenticated-orcid":false,"given":"Jinyu","family":"Liu","sequence":"first","affiliation":[{"name":"The Pennsylvania State University, University Park, PA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7626-2651","authenticated-orcid":false,"given":"Wenjie","family":"Xiong","sequence":"additional","affiliation":[{"name":"Virginia Tech, Blacksburg, VA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6409-9888","authenticated-orcid":false,"given":"G. Edward","family":"Suh","sequence":"additional","affiliation":[{"name":"NVIDIA, Westford, MA, USA and Cornell University, Ithaca, NY, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0321-8406","authenticated-orcid":false,"given":"Kiwan","family":"Maeng","sequence":"additional","affiliation":[{"name":"The Pennsylvania State University, University Park, PA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,3,30]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_2_1","unstructured":"Arm. 2023. TrustZone for Cortex-A. https:\/\/www.arm.com\/ technologies\/trustzone-for-cortex-a."},{"key":"e_1_3_2_1_3_1","unstructured":"ARMLtd. 2021. Arm Cortex-M series processors. https:\/\/developer. arm.com\/ip-products\/processors\/cortex-m."},{"key":"e_1_3_2_1_4_1","volume-title":"Element level differential privacy: The right granularity of privacy. arXiv preprint arXiv:1912.04042","author":"Asi Hilal","year":"2019","unstructured":"Hilal Asi, John Duchi, and Omid Javidbakht. 2019. Element level differential privacy: The right granularity of privacy. arXiv preprint arXiv:1912.04042 (2019)."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813649"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/EUROSP57164.2023.00023"},{"key":"e_1_3_2_1_7_1","volume-title":"When the Curious Abandon Honesty: Federated Learning Is Not Private. In 8th IEEE European Symposium on Security and Privacy, EuroS&P 2023","author":"Boenisch Franziska","year":"2023","unstructured":"Franziska Boenisch, Adam Dziedzic, Roei Schuster, Ali Shahin Shamsabadi, Ilia Shumailov, and Nicolas Papernot. 2023. When the Curious Abandon Honesty: Federated Learning Is Not Private. In 8th IEEE European Symposium on Security and Privacy, EuroS&P 2023, Delft, Netherlands, July 3--7, 2023. IEEE, 175--199. doi:10.1109\/ EUROSP57164.2023.00020"},{"key":"e_1_3_2_1_8_1","volume-title":"Practical secure aggregation for federated learning on user-held data. arXiv preprint arXiv:1611.04482","author":"Bonawitz Keith","year":"2016","unstructured":"Keith Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone, HBrendan McMahan, Sarvar Patel, Daniel Ramage, Aaron Segal, and Karn Seth. 2016. Practical secure aggregation for federated learning on user-held data. arXiv preprint arXiv:1611.04482 (2016)."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA51647.2021.00012"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2020.3014880"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23320"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2934680"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCD46524.2019.00087"},{"key":"e_1_3_2_1_14_1","volume-title":"HPCA 2020","author":"Che Yuezhi","year":"2020","unstructured":"Yuezhi Che and Rujia Wang. 2020. Multi-Range Supported Oblivious RAMfor Efficient Block Data Retrieval. In IEEE International Sym posium on High Performance Computer Architecture, HPCA 2020, San Diego, CA, USA, February 22--26, 2020. IEEE, 369--382. doi:10.1109\/ HPCA47549.2020.00038"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354226"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2988450.2988454"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/2959100.2959190"},{"key":"e_1_3_2_1_18_1","unstructured":"Criteo AI Labs. 2024. Criteo Research Datasets. https:\/\/ailab.criteo. com\/ressources\/."},{"key":"e_1_3_2_1_19_1","unstructured":"Ian Cutress. 2015. A Few Notes on Intel's Knights Landing and MC DRAMModesfromSC15. https:\/\/www.anandtech.com\/show\/9794\/a few-notes-on-intels-knights-landing-and-mcdram-modes-from sc15."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/3--540"},{"key":"e_1_3_2_1_21_1","volume-title":"Proceedings of the 13th ACM Conference on Recommender Systems. 457--461","author":"Pe\u00f1a J","year":"2019","unstructured":"ErikaDuriakova,EliasZTragos,BarrySmyth,NeilHurley,FranciscoJ Pe\u00f1a, Panagiotis Symeonidis, James Geraci, and Aonghus Lawlor. 2019. PDMFRec: a decentralised matrix factorisation with tunable user-centric privacy. In Proceedings of the 13th ACM Conference on Recommender Systems. 457--461."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"crossref","unstructured":"Cynthia Dwork Aaron Roth et al. 2014. The algorithmic founda tions of differential privacy. Foundations and Trends\u00ae in Theoretical Computer Science 9 3--4 (2014) 211--407.","DOI":"10.1561\/0400000042"},{"key":"e_1_3_2_1_23_1","volume-title":"Proceedings of Machine Learning and Sys tems 2019","author":"Eisenman Assaf","year":"2019","unstructured":"Assaf Eisenman, Maxim Naumov, Darryl Gardner, Misha Smelyan skiy, Sergey Pupyrev, Kim M. Hazelwood, Asaf Cidon, and Sachin Katti. 2019. Bandana: Using Non-Volatile Memory for Storing Deep Learning Models. In Proceedings of Machine Learning and Sys tems 2019, MLSys 2019, Stanford, CA, USA, March 31- April 2, 2019, AmeetTalwalkar, Virginia Smith, and Matei Zaharia (Eds.). mlsys.org. https:\/\/proceedings.mlsys.org\/book\/277.pd"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3336191.3371856"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382536.2382540"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/FCCM.2015.58"},{"key":"e_1_3_2_1_27_1","volume-title":"Chris JM Yoon, and Ivan Beschastnikh","author":"Fung Clement","year":"2018","unstructured":"Clement Fung, Chris JM Yoon, and Ivan Beschastnikh. 2018. Mit igating sybils in federated learning poisoning. arXiv preprint arXiv:1808.04866 (2018)."},{"key":"e_1_3_2_1_28_1","unstructured":"GDPR.EU. 2024. A guide to GDPR data privacy requirements. https: \/\/gdpr.eu\/data-privacy\/."},{"key":"e_1_3_2_1_29_1","volume-title":"Inferential privacy guarantees for differentially private mechanisms. arXiv preprint arXiv:1603.01508","author":"Ghosh Arpita","year":"2016","unstructured":"Arpita Ghosh and Robert Kleinberg. 2016. Inferential privacy guarantees for differentially private mechanisms. arXiv preprint arXiv:1603.01508 (2016)."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/28395.28416"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/233551.233553"},{"key":"e_1_3_2_1_32_1","unstructured":"Shay Gueron. 2016. A Memory Encryption Engine Suitable for General Purpose Processors. IACR Cryptol. ePrint Arch. (2016) 204. http:\/\/eprint.iacr.org\/2016\/204"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.24963\/IJCAI.2017\/239"},{"key":"e_1_3_2_1_34_1","unstructured":"Ian Hamilton. 2021. Oculus Quest Keyboard Option Sends 'Aggregate Modeling Data' To Facebook. https:\/\/www.uploadvr.com\/facebook quest-keyboard-data\/."},{"key":"e_1_3_2_1_35_1","volume-title":"Federated learning for mobile keyboard prediction. arXiv preprint arXiv:1811.03604","author":"Hard Andrew","year":"2018","unstructured":"Andrew Hard, Kanishka Rao, Rajiv Mathews, Swaroop Ramaswamy, Fran\u00e7oise Beaufays, Sean Augenstein, Hubert Eichner, Chlo\u00e9 Kiddon, and Daniel Ramage. 2018. Federated learning for mobile keyboard prediction. arXiv preprint arXiv:1811.03604 (2018)."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/2827872"},{"key":"e_1_3_2_1_37_1","volume-title":"Workshop on Trustwor thy and Socially Responsible Machine Learning, NeurIPS","author":"Hashemi Hanieh","year":"2022","unstructured":"Hanieh Hashemi, Wenjie Xiong, Liu Ke, Kiwan Maeng, Murali An navaram, G Edward Suh, and Hsien-Hsin S Lee. 2022. Private data leakage via exploiting access patterns of sparse features in deep learning-based recommendation systems. In Workshop on Trustwor thy and Socially Responsible Machine Learning, NeurIPS 2022."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/3038912.3052569"},{"key":"e_1_3_2_1_39_1","volume-title":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases. Springer, 317--332","author":"Heged's Istv\u00e1n","year":"2019","unstructured":"Istv\u00e1n Heged's, G\u00e1bor Danner, and M\u00e1rk Jelasity. 2019. Decentral ized recommendation based on matrix factorization: A comparison of gossip and federated learning. In Joint European Conference on Machine Learning and Knowledge Discovery in Databases. Springer, 317--332."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/TVLSI.2017.2785222"},{"key":"e_1_3_2_1_41_1","volume-title":"Proceedings of Machine Learning and Systems 2022","author":"Huba Dzmitry","year":"2022","unstructured":"Dzmitry Huba, John Nguyen, Kshitiz Malik, Ruiyu Zhu, Mike Rab bat, Ashkan Yousefpour, Carole-Jean Wu, Hongyuan Zhan, Pavel Ustinov, Harish Srinivas, Kaikai Wang, Anthony Shoumikhin, Jesik Min, and Mani Malek. 2022. PAPAYA: Practical, Private, and Scal able Federated Learning. In Proceedings of Machine Learning and Systems 2022, MLSys 2022, Santa Clara, CA, USA, August 29- Sep tember 1, 2022, Diana Marculescu, Yuejie Chi, and Carole-Jean Wu (Eds.). mlsys.org. https:\/\/proceedings.mlsys.org\/paper\/2022\/hash\/ f340f1b1f65b6df5b5e3f94d95b11daf-Abstract.html"},{"key":"e_1_3_2_1_42_1","volume-title":"Abhinav Aggar wal, and Nathanael Teissier","author":"Imola Jacob","year":"2022","unstructured":"Jacob Imola, Shiva Kasiviswanathan, Stephen White, Abhinav Aggar wal, and Nathanael Teissier. 2022. Balancing utility and scalability in metric differential privacy. In Uncertainty in Artificial Intelligence. PMLR, 885--894."},{"key":"e_1_3_2_1_43_1","unstructured":"Intel. 2023. Intel\u00ae Software Guard Extensions. https: \/\/www.intel.com\/content\/www\/us\/en\/developer\/tools\/software guard-extensions\/overview.html."},{"key":"e_1_3_2_1_44_1","unstructured":"Intel. 2024. Intel\u00ae Trust Domain Extensions (Intel\u00ae TDX). https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/tools\/trust domain-extensions\/documentation.html."},{"key":"e_1_3_2_1_45_1","volume-title":"Proceedings of the 6th IEEE\/ACM international conference on big data computing, applications and technologies. 53--58","author":"Scavuzzo Marco","year":"2019","unstructured":"AmirJalalirad, Marco Scavuzzo, Catalin Capota, and Michael Sprague. 2019. A simple and efficient federated recommender system. In Proceedings of the 6th IEEE\/ACM international conference on big data computing, applications and technologies. 53--58."},{"key":"e_1_3_2_1_46_1","volume-title":"Mitigating sybil attacks on differential privacy based federated learning. arXiv preprint arXiv:2010.10572","author":"Jiang Yupeng","year":"2020","unstructured":"Yupeng Jiang, Yong Li, Yipeng Zhou, and Xi Zheng. 2020. Mitigating sybil attacks on differential privacy based federated learning. arXiv preprint arXiv:2010.10572 (2020)."},{"key":"e_1_3_2_1_47_1","volume-title":"2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom). IEEE, 355--362","unstructured":"YupengJiang,YongLi,YipengZhou,andXiZheng.2021. Sybilattacks and defense on differential privacy based federated learning. In 2021 IEEE 20th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom). IEEE, 355--362."},{"key":"e_1_3_2_1_48_1","volume-title":"Proceedings of the 32nd International Conference on Machine Learning, ICML 2015, Lille, France, 6--11 July 2015 (JMLR Workshop and Conference Proceedings","volume":"1385","author":"Kairouz Peter","year":"2015","unstructured":"Peter Kairouz, Sewoong Oh, and Pramod Viswanath. 2015. The Composition Theorem for Differential Privacy. In Proceedings of the 32nd International Conference on Machine Learning, ICML 2015, Lille, France, 6--11 July 2015 (JMLR Workshop and Conference Proceedings, Vol. 37). JMLR.org, 1376--1385. http:\/\/proceedings.mlr.press\/v37\/ kairouz15.html"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM.2018.00035"},{"key":"e_1_3_2_1_50_1","volume-title":"International Conference on Machine Learning, ICML 2023","volume":"15899","author":"Kariyappa Sanjay","year":"2023","unstructured":"Sanjay Kariyappa, Chuan Guo, Kiwan Maeng, Wenjie Xiong, G. Ed ward Suh, Moinuddin K. Qureshi, and Hsien-Hsin S. Lee. 2023. Cock tail Party Attack: Breaking Aggregation-Based Privacy in Federated Learning Using Independent Component Analysis. In International Conference on Machine Learning, ICML 2023, 23--29 July 2023, Honolulu, Hawaii, USA (Proceedings of Machine Learning Research, Vol. 202), Andreas Krause, Emma Brunskill, Kyunghyun Cho, Barbara Engel hardt, Sivan Sabato, and Jonathan Scarlett (Eds.). PMLR, 15884--15899. https:\/\/proceedings.mlr.press\/v202\/kariyappa23a.html"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3289600.3290968"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1145\/2514689"},{"key":"e_1_3_2_1_53_1","volume-title":"Proceedings of the 56th Annual","author":"Kim Seah","year":"2023","unstructured":"Seah Kim, Jerry Zhao, Krste Asanovic, Borivoje Nikolic, and Yakun Sophia Shao. 2023. AuRORA: Virtualized Accelerator Orches tration for Multi-Tenant Workloads. In Proceedings of the 56th Annual"},{"key":"e_1_3_2_1_54_1","volume-title":"3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7--9, 2015, Con ference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds.). http:\/\/arxiv.org\/abs\/1412","author":"Diederik","unstructured":"Diederik P. Kingma and Jimmy Ba. 2015. Adam: A Method for Sto chastic Optimization. In 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7--9, 2015, Con ference Track Proceedings, Yoshua Bengio and Yann LeCun (Eds.). http:\/\/arxiv.org\/abs\/1412.6980"},{"key":"e_1_3_2_1_55_1","volume-title":"Private Learning with Public Features. In International Conference on Artificial Intelligence and Statistics, 2--4","volume":"4158","author":"Krichene Walid","year":"2024","unstructured":"Walid Krichene, Nicolas Mayoraz, Steffen Rendle, Shuang Song, Abhradeep Thakurta, and Li Zhang. 2024. Private Learning with Public Features. In International Conference on Artificial Intelligence and Statistics, 2--4 May 2024, Palau de Congressos, Valencia, Spain (Pro ceedings of Machine Learning Research, Vol. 238). PMLR, 4150--4158. https:\/\/proceedings.mlr.press\/v238\/krichene24a.html"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3489517.3530547"},{"key":"e_1_3_2_1_57_1","volume-title":"International Conference on Machine Learning, ICML 2022","volume":"11827","author":"Lai Fan","year":"2022","unstructured":"Fan Lai, Yinwei Dai, Sanjay Sri Vallabh Singapuram, Jiachen Liu, Xi angfeng Zhu, HarshaV.Madhyastha,andMosharafChowdhury.2022. FedScale: BenchmarkingModelandSystemPerformanceofFederated Learning at Scale. In International Conference on Machine Learning, ICML 2022, 17--23 July 2022, Baltimore, Maryland, USA (Proceedings of Machine Learning Research, Vol. 162), Kamalika Chaudhuri, Stefanie Jegelka, Le Song, Csaba Szepesv\u00e1ri, Gang Niu, and Sivan Sabato (Eds.). PMLR, 11814--11827. https:\/\/proceedings.mlr.press\/v162\/lai22a.html"},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.2301.10904"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/3342195.3387532"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA.2005.14"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/3466752.3480089"},{"key":"e_1_3_2_1_62_1","unstructured":"Kif Leswing. 2022. Facebook says Apple iOS privacy change will result in $10 billion revenue hit this year. https:\/\/www.cnbc.com\/2022\/02\/02\/facebook-says-apple-ios privacy-change-will-cost-10-billion-this-year.html."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2014.11.003"},{"key":"e_1_3_2_1_64_1","volume-title":"Proceedings of the Ninth ACM International Conference on Web Search and Data Mining. 377--386","unstructured":"MuLi,ZiqiLiu,AlexanderJSmola,andYu-XiangWang.2016. Difacto: Distributed factorization machines. In Proceedings of the Ninth ACM International Conference on Web Search and Data Mining. 377--386."},{"key":"e_1_3_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833768"},{"key":"e_1_3_2_1_66_1","volume-title":"CIPHERLEAKS: Breaking Constant-time Cryp tography on AMD SEV via the Ciphertext Side Channel. In 30th USENIXSecuritySymposium,USENIXSecurity2021,August11--13,2021, Michael D","author":"Li Mengyuan","year":"2021","unstructured":"Mengyuan Li, Yinqian Zhang, Huibo Wang, Kang Li, and Yue qiang Cheng. 2021. CIPHERLEAKS: Breaking Constant-time Cryp tography on AMD SEV via the Ciphertext Side Channel. In 30th USENIXSecuritySymposium,USENIXSecurity2021,August11--13,2021, Michael D. Bailey and Rachel Greenstadt (Eds.). USENIX Associa tion, 717--732. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/ presentation\/li-mengyuan"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00103"},{"key":"e_1_3_2_1_68_1","volume-title":"Proceedings of the 29th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, ASPLOS 2024. ACM.","author":"Lim Juntaek","unstructured":"Juntaek Lim, Youngeun Kwon, Ranggi Hwang, Kiwan Maeng, G. Ed ward Suh, and Minsoo Rhu. 2024. LazyDP: Co-Designing Algorithm Software for Scalable Training of Differentially Private Recommenda tion Models. In Proceedings of the 29th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, ASPLOS 2024. ACM."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/3316781"},{"key":"e_1_3_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISPASS51385.2021.00033"},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3604930.3605717"},{"key":"e_1_3_2_1_72_1","volume-title":"Advances in Neural Information Processing Systems 36: Annual Conference on Neural Information Pro cessing Systems 2023","author":"Maeng Kiwan","year":"2023","unstructured":"Kiwan Maeng, Chuan Guo, Sanjay Kariyappa, and G Edward Suh. 2023. Bounding the Invertibility of Privacy-preserving Instance En coding using Fisher Information. In Advances in Neural Information Processing Systems 36: Annual Conference on Neural Information Pro cessing Systems 2023, NeurIPS 2023."},{"key":"e_1_3_2_1_73_1","unstructured":"Kiwan Maeng Haiyu Lu Luca Melis John Nguyen Mike Rabbat and Carole-Jean Wu. 2023. RF2. https:\/\/github.com\/facebookresearch\/RF2."},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1145\/3523227.3546759"},{"key":"e_1_3_2_1_75_1","volume-title":"Proceedings of Machine Learning and Systems 2020","author":"Mattson Peter","year":"2020","unstructured":"Peter Mattson, Christine Cheng, Gregory F. Diamos, Cody Coleman, Paulius Micikevicius, David A. Patterson, Hanlin Tang, Gu-Yeon Wei, Peter Bailis, Victor Bittorf, David Brooks, Dehao Chen, Debo Dutta, Udit Gupta, Kim M. Hazelwood, Andy Hock, Xinyuan Huang, Daniel Kang, David Kanter, Naveen Kumar, Jeffery Liao, Deepak Narayanan, Tayo Oguntebi, Gennady Pekhimenko, Lillian Pentecost, Vijay Janapa Reddi, Taylor Robie, Tom St. John, Carole-Jean Wu, Lingjie Xu, Cliff Young, and Matei Zaharia. 2020. MLPerf Training Benchmark. In Proceedings of Machine Learning and Systems 2020"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1145\/3240323.3240354"},{"key":"e_1_3_2_1_77_1","volume-title":"Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, AISTATS 2017, 20--22","volume":"1282","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Ag\u00fcera y Arcas. 2017. Communication-Efficient Learning of Deep Networks from Decentralized Data. In Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, AISTATS 2017, 20--22 April 2017, Fort Lauderdale, FL, USA (Proceedings of Machine Learning Research, Vol. 54), Aarti Singh and Xiaojin (Jerry) Zhu (Eds.). PMLR, 1273--1282. http:\/\/proceedings.mlr.press\/v54\/ mcmahan17a.html"},{"key":"e_1_3_2_1_78_1","volume-title":"6th International Conference on Learning Representations, ICLR","author":"McMahan H. Brendan","year":"2018","unstructured":"H. Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. 2018. Learning Differentially Private Recurrent Language Models. In 6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, April 30- May 3, 2018, Conference Track Proceedings. OpenReview.net. https:\/\/openreview.net\/forum?id= BJ0hF1Z0b"},{"key":"e_1_3_2_1_79_1","unstructured":"Matthew Mead. 2022. History of Costs of RAM vs. Hard drives vs. SSDs. https:\/\/azrael.digipen.edu\/ mmead\/www\/Courses\/CS180\/ram hd-ssd-prices.html."},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v32i1.11714"},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00045"},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"publisher","DOI":"10.1145\/2858792"},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"publisher","DOI":"10.1145\/3579371.3589045"},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00069"},{"key":"e_1_3_2_1_85_1","unstructured":"Maxim Naumov Dheevatsa Mudigere Hao-Jun Michael Shi Jianyu Huang Narayanan Sundaraman Jongsoo Park Xiaodong Wang Udit Gupta Carole-Jean Wu Alisson G. Azzolini Dmytro Dzhulgakov Andrey Mallevich Ilia Cherniavskii Yinghai Lu Raghuraman Krish namoorthi Ansha Yu Volodymyr Kondratenko Stephanie Pereira Xianjie Chen Wenlin Chen Vijay Rao Bill Jia Liang Xiong and Misha Smelyanskiy. 2019. Deep Learning Recommendation Model for Personalization and Recommendation Systems. CoRR abs\/1906.00091 (2019). arXiv:1906.00091 http:\/\/arxiv.org\/abs\/1906.00091"},{"key":"e_1_3_2_1_86_1","doi-asserted-by":"publisher","DOI":"10.1145\/3523227.3546769"},{"key":"e_1_3_2_1_87_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372224.3419188"},{"key":"e_1_3_2_1_88_1","unstructured":"Pavan Sabnagapati. 2020. Ad Display\/Click Data on Taobao.com. https:\/\/www.kaggle.com\/datasets\/pavansanagapati\/ad displayclick-data-on-taobaocom."},{"key":"e_1_3_2_1_89_1","doi-asserted-by":"publisher","DOI":"10.1613\/JAIR.1.14649"},{"key":"e_1_3_2_1_90_1","doi-asserted-by":"publisher","DOI":"10.1145\/3579371.3589111"},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO56248.2022.00021"},{"key":"e_1_3_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.2305.05065"},{"key":"e_1_3_2_1_93_1","volume-title":"AB-ORAM: Constructing Adjustable Buckets for Space Reduction in Ring ORAM. In 2023 IEEE International Symposium on High Performance Computer Architecture (HPCA). 361--373","author":"Raoufi Mehrnoosh","year":"2023","unstructured":"Mehrnoosh Raoufi, Jun Yang, Xulong Tang, and Youtao Zhang. 2023. AB-ORAM: Constructing Adjustable Buckets for Space Reduction in Ring ORAM. In 2023 IEEE International Symposium on High Performance Computer Architecture (HPCA). 361--373. doi:10.1109\/ HPCA56546.2023.10071064"},{"key":"e_1_3_2_1_94_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA53966.2022.00034"},{"key":"e_1_3_2_1_95_1","unstructured":"Sashank Reddi Zachary Charles Manzil Zaheer Zachary Gar rett Keith Rush Jakub Kone?n"},{"key":"e_1_3_2_1_96_1","volume-title":"Adaptive federated optimization. arXiv preprint arXiv:2003.00295","author":"Kumar Sanjiv","year":"2020","unstructured":"y, Sanjiv Kumar, and H Brendan McMahan. 2020. Adaptive federated optimization. arXiv preprint arXiv:2003.00295 (2020)."},{"key":"e_1_3_2_1_97_1","unstructured":"LingRen ChristopherW.Fletcher AlbertKwon EmilStefanov Elaine Shi Marten van Dijk and Srinivas Devadas. 2014. Ring ORAM: Closing the Gap Between Small and Large Client Storage Oblivious RAM. IACR Cryptol. ePrint Arch. (2014) 997. http:\/\/eprint.iacr.org\/ 2014\/997"},{"key":"e_1_3_2_1_98_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508148.2485971"},{"key":"e_1_3_2_1_99_1","unstructured":"Holger Roth Michael Zephyr and Ahmed Harouni. 2021. Federated Learning with Homomorphic Encryption. https:\/\/developer.nvidia. com\/blog\/federated-learning-with-homomorphic-encryption\/."},{"key":"e_1_3_2_1_100_1","unstructured":"Samsung. 2021. Samsung NVMe\u2122 SSD 980 PRO Data Sheet. https:\/\/download.semiconductor.samsung.com\/resources\/data sheet\/Samsung-NVMe-SSD-980-PRO-Data Sheet_Rev.2.1_230509_10129505081019.pdf."},{"key":"e_1_3_2_1_101_1","volume-title":"International Conference on Information Security Practic","author":"Ahmed","unstructured":"Ahmed E Samy and \u0160ar\u00af unas Girdzijauskas. 2023. Mitigating Sybil at tacks in federated learning. In International Conference on Information Security Practic"},{"key":"e_1_3_2_1_102_1","volume-title":"NDSS 2018","author":"Sasy Sajin","year":"2018","unstructured":"Sajin Sasy, Sergey Gorbunov, and Christopher W. Fletcher. 2018. Ze roTrace : Oblivious Memory Primitives from Intel SGX. In 25th An nual Network and Distributed System Security Symposium, NDSS 2018, San Diego, California, USA, February 18--21, 2018. The Internet Soci ety. https:\/\/www.ndss-symposium.org\/wp-content\/uploads\/2018\/ 02\/ndss2018_02B-4_Sasy_paper.pdf"},{"key":"e_1_3_2_1_103_1","volume-title":"Advances in Neural In formation Processing Systems 34: Annual Conference on Neural In formation Processing Systems","author":"Singhal Karan","year":"2021","unstructured":"Karan Singhal, Hakim Sidahmed, Zachary Garrett, Shanshan Wu, John Rush, and Sushant Prakash. 2021. Federated Reconstruc tion: Partially Local Federated Learning. In Advances in Neural In formation Processing Systems 34: Annual Conference on Neural In formation Processing Systems 2021, NeurIPS 2021, December 6--14, 2021, virtual, Marc'Aurelio Ranzato, Alina Beygelzimer, Yann N. Dauphin, Percy Liang, and Jennifer Wortman Vaughan (Eds.). 11220--11232. https:\/\/proceedings.neurips.cc\/paper\/2021\/hash\/ 5d44a2b0d85aa1a4dd3f218be6422c66-Abstract.html"},{"key":"e_1_3_2_1_104_1","unstructured":"Solidigm.[n.d.]. D7-P5620. https:\/\/www.solidigm.com\/products\/data center\/d7\/p5620.html."},{"key":"e_1_3_2_1_105_1","doi-asserted-by":"publisher","DOI":"10.1145\/3489525.3511672"},{"key":"e_1_3_2_1_106_1","doi-asserted-by":"publisher","DOI":"10.1609\/aimag.v42i3.18140"},{"key":"e_1_3_2_1_107_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.25"},{"key":"e_1_3_2_1_108_1","volume-title":"NDSS 2012, San Diego, California, USA, February 5--8, 2012. The Internet Society. https:\/\/www.ndss symposium.org\/ndss2012\/towards-practical-oblivious-ram","author":"Stefanov Emil","year":"2012","unstructured":"Emil Stefanov, Elaine Shi, and Dawn Xiaodong Song. 2012. To wards Practical Oblivious RAM. In 19th Annual Network and Dis tributed System Security Symposium, NDSS 2012, San Diego, California, USA, February 5--8, 2012. The Internet Society. https:\/\/www.ndss symposium.org\/ndss2012\/towards-practical-oblivious-ram"},{"key":"e_1_3_2_1_109_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516660"},{"key":"e_1_3_2_1_110_1","doi-asserted-by":"publisher","DOI":"10.1145\/782814.782838"},{"key":"e_1_3_2_1_111_1","doi-asserted-by":"publisher","DOI":"10.1145\/3357384.3357895"},{"key":"e_1_3_2_1_112_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA53966.2022.00081"},{"key":"e_1_3_2_1_113_1","unstructured":"The White House. 2024. Executive Order on Preventing Access to Americans' Bulk Sensitive Personal Data and United States Government-Related Data by Countries of Con cern. https:\/\/www.whitehouse.gov\/briefing-room\/presidential actions\/2024\/02\/28\/executive-order-on-preventing-access-to americans-bulk-sensitive-personal-data-and-united-states government-related-data-by-countries-of-concern\/."},{"key":"e_1_3_2_1_114_1","volume-title":"22nd International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2019","author":"Tople Shruti","year":"2019","unstructured":"Shruti Tople, Yaoqi Jia, and Prateek Saxena. 2019. PRO-ORAM: Prac tical Read-Only Oblivious RAM. In 22nd International Symposium on Research in Attacks, Intrusions and Defenses, RAID 2019, Chaoyang Dis trict, Beijing, China, September 23--25, 2019. USENIX Association, 197 211. https:\/\/www.usenix.org\/conference\/raid2019\/presentation\/tople"},{"key":"e_1_3_2_1_115_1","doi-asserted-by":"publisher","DOI":"10.1145\/3338501.3357370"},{"key":"e_1_3_2_1_116_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA61900.2025.00041"},{"key":"e_1_3_2_1_117_1","doi-asserted-by":"publisher","DOI":"10.1145\/3476886.3477511"},{"key":"e_1_3_2_1_118_1","volume-title":"Proceedings of Machine Learning and Systems 2023","author":"Wang Ewen","year":"2023","unstructured":"Ewen Wang, Boyi Chen, Mosharaf Chowdhury, Ajay Kannan, and Franco Liang. 2023. FLINT: A Platform for Federated Learning Inte gration. In Proceedings of Machine Learning and Systems 2023, MLSys 2023, Miami Beach, FL, USA, June 4- June 8, 2023. mlsys.org."},{"key":"e_1_3_2_1_119_1","doi-asserted-by":"publisher","DOI":"10.1145\/3124749.3124754"},{"key":"e_1_3_2_1_120_1","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3450078"},{"key":"e_1_3_2_1_121_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCA.2017.9"},{"key":"e_1_3_2_1_122_1","volume-title":"D-ORAM: Path ORAMDelegation for Low Execution Interference on Cloud Servers with Untrusted Memory. In IEEE International Symposium on High Performance Computer Architecture, HPCA 2018","author":"Wang Rujia","year":"2018","unstructured":"Rujia Wang, Youtao Zhang, and Jun Yang. 2018. D-ORAM: Path ORAMDelegation for Low Execution Interference on Cloud Servers with Untrusted Memory. In IEEE International Symposium on High Performance Computer Architecture, HPCA 2018, Vienna, Austria, Feb ruary 24--28, 2018. IEEE Computer Society, 416--427. doi:10.1109\/ HPCA.2018.00043"},{"key":"e_1_3_2_1_123_1","doi-asserted-by":"publisher","DOI":"10.1145\/3445814.3446763"},{"key":"e_1_3_2_1_124_1","volume-title":"Personalized recommendation systems: Five hot research topics you must know. Microsoft Research Lab-Asia (2018)e and Experience","author":"Xie X","unstructured":"X Xie, J Lian, Z Liu, X Wang, F Wu, H Wang, and Z Chen. 2018. Personalized recommendation systems: Five hot research topics you must know. Microsoft Research Lab-Asia (2018)e and Experience. Springer, 36--51."},{"key":"e_1_3_2_1_125_1","volume-title":"Federated Learning of Gboard Language Models with Differential Privacy. arXiv preprint arXiv:2305.18465","author":"Choo Choquette","year":"2023","unstructured":"ZhengXu,YanxiangZhang,GalenAndrew,ChristopherAChoquette Choo, Peter Kairouz, H Brendan McMahan, Jesse Rosenstock, and YuanboZhang.2023. Federated Learning of Gboard Language Models with Differential Privacy. arXiv preprint arXiv:2305.18465 (2023)."},{"key":"e_1_3_2_1_126_1","doi-asserted-by":"publisher","DOI":"10.1145\/3442381.3449851"},{"key":"e_1_3_2_1_127_1","volume-title":"Applied federated learning: Improving google keyboard query sug gestions. arXiv preprint arXiv:1812.02903","author":"Yang Timothy","year":"2018","unstructured":"Timothy Yang, Galen Andrew, Hubert Eichner, Haicheng Sun, Wei Li, Nicholas Kong, Daniel Ramage, and Fran\u00e7oise Beaufays. 2018. Applied federated learning: Improving google keyboard query sug gestions. arXiv preprint arXiv:1812.02903 (2018)."},{"key":"e_1_3_2_1_128_1","doi-asserted-by":"publisher","DOI":"10.1145\/3298689.3346996"},{"key":"e_1_3_2_1_129_1","doi-asserted-by":"publisher","DOI":"10.1145\/2749469.2750413"},{"key":"e_1_3_2_1_130_1","volume-title":"Revisiting Square Root ORAM: Efficient Random Access in Multi-party Computation. In IEEE Symposium on Security and Privacy, SP 2016","author":"Zahur Samee","year":"2016","unstructured":"Samee Zahur, Xiao Wang, Mariana Raykova, Adri\u00e0 Gasc\u00f3n, Jack Doerner, David Evans, and Jonathan Katz. 2016. Revisiting Square Root ORAM: Efficient Random Access in Multi-party Computation. In IEEE Symposium on Security and Privacy, SP 2016, San Jose, CA, USA, May 22--26, 2016. IEEE Computer Society, 218--234. doi:10.1109\/ SP.2016.21"},{"key":"e_1_3_2_1_131_1","volume-title":"ICML 2024","author":"Zhai Jiaqi","year":"2024","unstructured":"Jiaqi Zhai, Lucy Liao, Xing Liu, Yueming Wang, Rui Li, Xuan Cao, Leon Gao, Zhaojie Gong, Fangda Gu, Jiayuan He, Yinghai Lu, and Yu Shi. 2024. Actions Speak Louder than Words: Trillion-Parameter Sequential Transducers for Generative Recommendations. In Forty f irst International Conference on Machine Learning, ICML 2024, Vienna, Austria, July 21--27, 2024. OpenReview.net. https:\/\/openreview.net\/ forum?id=xye7iNsgXn"},{"key":"e_1_3_2_1_132_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO.2018.00082"},{"key":"e_1_3_2_1_133_1","doi-asserted-by":"publisher","DOI":"10.1145\/2830772.2830787"},{"key":"e_1_3_2_1_134_1","volume-title":"Private Federated Learning in Gboard. arXiv preprint arXiv:2306.14793","author":"Zhang Yuanbo","year":"2023","unstructured":"Yuanbo Zhang, Daniel Ramage, Zheng Xu, Yanxiang Zhang, Shumin Zhai, and Peter Kairouz. 2023. Private Federated Learning in Gboard. arXiv preprint arXiv:2306.14793 (2023)."},{"key":"e_1_3_2_1_135_1","volume-title":"Proceedings of Machine Learning and Systems 2020","author":"Zhao Weijie","year":"2020","unstructured":"Weijie Zhao, Deping Xie, Ronglai Jia, Yulei Qian, Ruiquan Ding, Ming mingSun, andPing Li. 2020. Distributed Hierarchical GPU Parameter Server for Massive Scale Deep Learning Ads Systems. In Proceedings of Machine Learning and Systems 2020, MLSys 2020, Austin, TX, USA, March 2--4, 2020, Inderjit S. Dhillon, Dimitris S. Papailiopoulos, and Vivienne Sze (Eds.). mlsys.org. https:\/\/proceedings.mlsys.org\/book\/ 315.pdf"},{"key":"e_1_3_2_1_136_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33015941"},{"key":"e_1_3_2_1_137_1","doi-asserted-by":"publisher","DOI":"10.1145\/3219819.3219823"},{"key":"e_1_3_2_1_138_1","volume-title":"Advances in Neural Information Process ing Systems 32: Annual Conference on Neural Information Process ing Systems","author":"Zhu Ligeng","year":"2019","unstructured":"Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep Leak age from Gradients. In Advances in Neural Information Process ing Systems 32: Annual Conference on Neural Information Process ing Systems 2019, NeurIPS 2019, December 8--14, 2019, Vancouver, BC, Canada, Hanna M. Wallach, Hugo Larochelle, Alina Beygelz imer, Florence d'Alch\u00e9-Buc, Emily B. Fox, and Roman Garnett (Eds.). 14747--14756. https:\/\/proceedings.neurips.cc\/paper\/2019\/ hash\/60a6c4002cc7b29142def8871531281a-Abstract.html"}],"event":{"name":"ASPLOS '25: 30th ACM International Conference on Architectural Support for Programming Languages and Operating Systems","location":"Rotterdam Netherlands","acronym":"ASPLOS '25","sponsor":["SIGPLAN ACM Special Interest Group on Programming Languages","SIGOPS ACM Special Interest Group on Operating Systems","SIGARCH ACM Special Interest Group on Computer Architecture"]},"container-title":["Proceedings of the 30th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3676641.3716014","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/abs\/10.1145\/3676641.3716014","content-type":"text\/html","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3676641.3716014","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3676641.3716014","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T11:10:36Z","timestamp":1755774636000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3676641.3716014"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,30]]},"references-count":138,"alternative-id":["10.1145\/3676641.3716014","10.1145\/3676641"],"URL":"https:\/\/doi.org\/10.1145\/3676641.3716014","relation":{},"subject":[],"published":{"date-parts":[[2025,3,30]]},"assertion":[{"value":"2025-03-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}