{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T01:37:11Z","timestamp":1784079431244,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":88,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,6,19]],"date-time":"2024-06-19T00:00:00Z","timestamp":1718755200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100006374","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2308730, CNS-2302689, CNS-2319277, CMMI-2326341, ECCS-2216926, CNS-2241713, CNS-2331302 and CNS-2339686"],"award-info":[{"award-number":["CNS-2308730, CNS-2302689, CNS-2319277, CMMI-2326341, ECCS-2216926, CNS-2241713, CNS-2331302 and CNS-2339686"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,6,19]]},"DOI":"10.1145\/3714393.3726517","type":"proceedings-article","created":{"date-parts":[[2025,6,4]],"date-time":"2025-06-04T18:38:47Z","timestamp":1749062327000},"page":"60-71","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":6,"title":["Harmonizing Differential Privacy Mechanisms for Federated Learning: Boosting Accuracy and Convergence"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-8139-7366","authenticated-orcid":false,"given":"Shuya","family":"Feng","sequence":"first","affiliation":[{"name":"University of Connecticut, Storrs, CT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0619-6361","authenticated-orcid":false,"given":"Meisam","family":"Mohammady","sequence":"additional","affiliation":[{"name":"Iowa State University, Ames, IA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-0538-6669","authenticated-orcid":false,"given":"Hanbin","family":"Hong","sequence":"additional","affiliation":[{"name":"University of Connecticut, Storrs, CT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-5439-7485","authenticated-orcid":false,"given":"Shenao","family":"Yan","sequence":"additional","affiliation":[{"name":"University of Connecticut, Storrs, CT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1499-5558","authenticated-orcid":false,"given":"Ashish","family":"Kundu","sequence":"additional","affiliation":[{"name":"Cisco Ressearch, San Jose, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5616-060X","authenticated-orcid":false,"given":"Binghui","family":"Wang","sequence":"additional","affiliation":[{"name":"Illinois Institute of Technology, Chicago, IL, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4095-4506","authenticated-orcid":false,"given":"Yuan","family":"Hong","sequence":"additional","affiliation":[{"name":"University of Connecticut, Storrs, CT, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,6,4]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"crossref","unstructured":"Martin Abadi Andy Chu Ian Goodfellow H Brendan McMahan Ilya Mironov Kunal Talwar and Li Zhang. 2016. Deep learning with differential privacy. In CCS.","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_2_1","volume-title":"Federated learning and differential privacy for medical image analysis. Scientific reports","author":"Adnan Mohammed","year":"2022","unstructured":"Mohammed Adnan, Shivam Kalra, Jesse C Cresswell, Graham W Taylor, and Hamid R Tizhoosh. 2022. Federated learning and differential privacy for medical image analysis. Scientific reports (2022)."},{"key":"e_1_3_2_1_3_1","volume-title":"The skellam mechanism for differentially private federated learning. NIPS","author":"Agarwal Naman","year":"2021","unstructured":"Naman Agarwal, Peter Kairouz, and Ziyu Liu. 2021. The skellam mechanism for differentially private federated learning. NIPS (2021)."},{"key":"e_1_3_2_1_4_1","volume-title":"Yun Dong, Yuan Hong, and Binghui Wang.","author":"Arevalo Caridad Arroyo","year":"2024","unstructured":"Caridad Arroyo Arevalo, Sayedeh Leila Noorbakhsh, Yun Dong, Yuan Hong, and Binghui Wang. 2024. Task-Agnostic Privacy-Preserving Representation Learning for Federated Learning against Attribute Inference Attacks. In AAAI."},{"key":"e_1_3_2_1_5_1","volume-title":"Flower: A Friendly Federated Learning Research Framework. arXiv preprint arXiv:2007.14390","author":"Beutel Daniel J","year":"2020","unstructured":"Daniel J Beutel, Taner Topal, Akhil Mathur, Xinchi Qiu, Javier Fernandez-Marques, Yan Gao, et al. 2020. Flower: A Friendly Federated Learning Research Framework. arXiv preprint arXiv:2007.14390 (2020)."},{"key":"e_1_3_2_1_6_1","volume-title":"Protection against reconstruction and its applications in private federated learning. arXiv preprint arXiv:1812.00984","author":"Bhowmick Abhishek","year":"2018","unstructured":"Abhishek Bhowmick, John Duchi, Julien Freudiger, Gaurav Kapoor, and Ryan Rogers. 2018. Protection against reconstruction and its applications in private federated learning. arXiv preprint arXiv:1812.00984 (2018)."},{"key":"e_1_3_2_1_7_1","volume-title":"Proc. VLDB Endow.","author":"Bindschaedler Vincent","year":"2017","unstructured":"Vincent Bindschaedler, Reza Shokri, and Carl A. Gunter. 2017. Plausible Deniability for Privacy-Preserving Data Synthesis. Proc. VLDB Endow. (2017)."},{"key":"e_1_3_2_1_8_1","volume-title":"S&P","author":"Carlini Nicholas","year":"1897","unstructured":"Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, and Florian Tramer. 2022. Membership inference attacks from first principles. In S&P. IEEE, 1897--1914."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"crossref","unstructured":"Thee Chanyaswad Alex Dytso H Vincent Poor and Prateek Mittal. 2018. Mvg mechanism: Differential privacy under matrix-valued query. In CCS.","DOI":"10.1145\/3243734.3243750"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2022.3159236"},{"key":"e_1_3_2_1_11_1","volume-title":"PPT: A Privacy-Preserving Global Model Training Protocol for Federated Learning in P2P Networks. arXiv preprint arXiv:2101.02281","author":"Chen Qian","year":"2021","unstructured":"Qian Chen, Zilong Wang, Wenjing Zhang, and Xiaodong Lin. 2021. PPT: A Privacy-Preserving Global Model Training Protocol for Federated Learning in P2P Networks. arXiv preprint arXiv:2101.02281 (2021)."},{"key":"e_1_3_2_1_12_1","volume-title":"Differentially Private Data Generative Models. arXiv preprint arXiv:1812.02274","author":"Chen Qingrong","year":"2018","unstructured":"Qingrong Chen, Chong Xiang, Minhui Xue, Bo Li, Nikita Borisov, Dali Kaarfar, and Haojin Zhu. 2018. Differentially Private Data Generative Models. arXiv preprint arXiv:1812.02274 (2018)."},{"key":"e_1_3_2_1_13_1","volume-title":"Federated Learning with Differential Privacy and Secure Multiparty Computation","author":"Chen Xiaochen","year":"2023","unstructured":"Xiaochen Chen, Yongqiang Li, Yuncheng Wang, Jiacheng Liu, and Kim-Kwang Raymond Choo. 2023. Federated Learning with Differential Privacy and Secure Multiparty Computation. IEEE Transactions on Information Forensics and Security (2023)."},{"key":"e_1_3_2_1_14_1","volume-title":"Federated Learning of Large Language Models with Differential Privacy. arXiv preprint arXiv:2306.10635","author":"Dagan Idan","year":"2023","unstructured":"Idan Dagan, Tomer Gafni, Oleksii Romanenko, and Idit Keidar. 2023. Federated Learning of Large Language Models with Differential Privacy. arXiv preprint arXiv:2306.10635 (2023)."},{"key":"e_1_3_2_1_15_1","volume-title":"Differentially Private Federated Learning with Local Randomization and Adaptive Optimization","author":"Ding Hao","year":"2023","unstructured":"Hao Ding, Xiangyu Gao, Ming Li, and Qian Tang. 2023. Differentially Private Federated Learning with Local Randomization and Adaptive Optimization. IEEE Transactions on Information Forensics and Security (2023)."},{"key":"e_1_3_2_1_16_1","volume-title":"33rd International Colloquium, ICALP 2006, Venice, Italy, July 10--14, 2006, Proceedings, Part II 33","author":"Dwork Cynthia","year":"2006","unstructured":"Cynthia Dwork. 2006. Differential privacy. In Automata, Languages and Programming: 33rd International Colloquium, ICALP 2006, Venice, Italy, July 10--14, 2006, Proceedings, Part II 33. Springer."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Cynthia Dwork Guy N Rothblum and Salil Vadhan. 2010. Boosting and Differential Privacy. In FOCS. 51--60.","DOI":"10.1109\/FOCS.2010.12"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"crossref","unstructured":"Vitaly Feldman Audra McMillan and Kunal Talwar. 2023. Stronger privacy amplification by shuffling for R\u00e9nyi and approximate differential privacy. In SODA. SIAM.","DOI":"10.1137\/1.9781611977554.ch181"},{"key":"e_1_3_2_1_20_1","volume-title":"DPI: Ensuring Strict Differential Privacy for Infinite Data Streaming","author":"Feng Shuya","year":"2024","unstructured":"Shuya Feng, Meisam Mohammady, Han Wang, Xiaochen Li, Zhan Qin, and Yuan Hong. 2024. DPI: Ensuring Strict Differential Privacy for Infinite Data Streaming. In IEEE S&P."},{"key":"e_1_3_2_1_21_1","volume-title":"User-Level Differential Privacy Against Attribute Inference Attack of Speech Emotion Recognition in Federated Learning. arXiv preprint arXiv:2202.01684","author":"Feng Tiantian","year":"2022","unstructured":"Tiantian Feng, Raghuveer Peri, and Shrikanth Narayanan. 2022. User-Level Differential Privacy Against Attribute Inference Attack of Speech Emotion Recognition in Federated Learning. arXiv preprint arXiv:2202.01684 (2022)."},{"key":"e_1_3_2_1_22_1","volume-title":"Privacy Amplification by Iteration in Federated Learning. arXiv preprint arXiv:2305.15046","author":"Fort Stanislav","year":"2023","unstructured":"Stanislav Fort, Stefanie G\u00fcnther, Zolt\u00e1n Szab\u00f3, Andrew McMillan, and Vitaly Feldman. 2023. Privacy Amplification by Iteration in Federated Learning. arXiv preprint arXiv:2305.15046 (2023)."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"crossref","unstructured":"Matt Fredrikson Somesh Jha and Thomas Ristenpart. 2015. Model inversion attacks that exploit confidence information and basic countermeasures. In CCS. 1322--1333.","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_1_24_1","volume-title":"Zhili Chen, and Yang Cao.","author":"Fu Jie","year":"2024","unstructured":"Jie Fu, Yuan Hong, Xinpeng Ling, Leixia Wang, Xun Ran, Zhiyu Sun, Wendy Hui Wang, Zhili Chen, and Yang Cao. 2024. Differentially Private Federated Learning: A Systematic Review. CoRR, Vol. abs\/2405.08299 (2024)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"crossref","unstructured":"Karan Ganju Qi Wang Wei Yang Carl A Gunter and Nikita Borisov. 2018. Property Inference Attacks on Fully Connected Neural Networks using Permutation Invariant Representations. In CCS.","DOI":"10.1145\/3243734.3243834"},{"key":"e_1_3_2_1_26_1","first-page":"16937","article-title":"Inverting gradients-how easy is it to break privacy in federated learning","volume":"33","author":"Geiping Jonas","year":"2020","unstructured":"Jonas Geiping, Hartmut Bauermeister, Hannah Dr\u00f6ge, and Michael Moeller. 2020. Inverting gradients-how easy is it to break privacy in federated learning? NeurIPS, Vol. 33 (2020), 16937--16947.","journal-title":"NeurIPS"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISIT.2014.6875258"},{"key":"e_1_3_2_1_28_1","volume-title":"NeurIPS","volume":"30","author":"Geumlek Joseph","year":"2017","unstructured":"Joseph Geumlek, Shuang Song, and Kamalika Chaudhuri. 2017. Renyi differential privacy mechanisms for posterior sampling. NeurIPS, Vol. 30 (2017)."},{"key":"e_1_3_2_1_29_1","volume-title":"Differentially private federated learning: A client level perspective. arXiv preprint arXiv:1712.07557","author":"Geyer Robin C","year":"2017","unstructured":"Robin C Geyer, Tassilo Klein, and Moin Nabi. 2017. Differentially private federated learning: A client level perspective. arXiv preprint arXiv:1712.07557 (2017)."},{"key":"e_1_3_2_1_30_1","volume-title":"Suhas Diggavi, Peter Kairouz, and Ananda Theertha Suresh.","author":"Girgis Antonious M","year":"2021","unstructured":"Antonious M Girgis, Deepesh Data, Suhas Diggavi, Peter Kairouz, and Ananda Theertha Suresh. 2021a. Shuffled model of federated learning: Privacy, accuracy and communication trade-offs. IEEE journal on selected areas in information theory, Vol. 2, 1 (2021), 464--478."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484794"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-023-10550-z"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0008"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijforecast.2016.02.001"},{"key":"e_1_3_2_1_36_1","volume-title":"DeSMP: Differential Privacy-exploited Stealthy Model Poisoning Attacks in Federated Learning. arXiv preprint arXiv:2102.03070","author":"Hossain Md Tamjid","year":"2021","unstructured":"Md Tamjid Hossain, Shafkat Islam, Shahriar Badsha, and Haoting Shen. 2021. DeSMP: Differential Privacy-exploited Stealthy Model Poisoning Attacks in Federated Learning. arXiv preprint arXiv:2102.03070 (2021)."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2991416"},{"key":"e_1_3_2_1_38_1","volume-title":"Cafe: Catastrophic data leakage in vertical federated learning. NeurIPS","author":"Jin Xiao","year":"2021","unstructured":"Xiao Jin, Pin-Yu Chen, Chia-Yi Hsu, Chia-Mu Yu, and Tianyi Chen. 2021. Cafe: Catastrophic data leakage in vertical federated learning. NeurIPS (2021)."},{"key":"e_1_3_2_1_39_1","volume-title":"Scaffold: Stochastic controlled averaging for federated learning. In ICML. PMLR.","author":"Karimireddy Sai Praneeth","year":"2020","unstructured":"Sai Praneeth Karimireddy, Satyen Kale, Mehryar Mohri, Sashank Reddi, Sebastian Stich, and Ananda Theertha Suresh. 2020. Scaffold: Stochastic controlled averaging for federated learning. In ICML. PMLR."},{"key":"e_1_3_2_1_40_1","volume-title":"Federated Learning In Adversarial Settings. arXiv preprint arXiv:2001.05641","author":"Kerkouche Raouf","year":"2020","unstructured":"Raouf Kerkouche, Gergely \u00c1cs, and Claude Castelluccia. 2020. Federated Learning In Adversarial Settings. arXiv preprint arXiv:2001.05641 (2020)."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"crossref","unstructured":"Amol Khanna Vincent Schaffer Gamze G\u00fcrsoy and Mark Gerstein. 2022. Privacy-preserving Model Training for Disease Prediction Using Federated Learning with Differential Privacy. In EMBC.","DOI":"10.1109\/EMBC48229.2022.9871742"},{"key":"e_1_3_2_1_42_1","volume-title":"Technical Report","author":"Krizhevsky Alex","unstructured":"Alex Krizhevsky, Vinod Nair, and Geoffrey Hinton. 2009. CIFAR-10 (Canadian Institute for Advanced Research). Technical Report. University of Toronto."},{"key":"e_1_3_2_1_43_1","volume-title":"Mendeley Data","author":"Kus Sammy","year":"2022","unstructured":"Sammy Kus. 2022. Medical MNIST. Mendeley Data (2022)."},{"key":"e_1_3_2_1_44_1","volume-title":"Gradient-based learning applied to document recognition. Proc","author":"LeCun Yann","year":"1998","unstructured":"Yann LeCun, L\u00e9on Bottou, Yoshua Bengio, and Patrick Haffner. 1998. Gradient-based learning applied to document recognition. Proc. IEEE (1998)."},{"key":"e_1_3_2_1_45_1","volume-title":"Federated Learning with Data and Model Privacy Preservation. arXiv preprint arXiv:2306.08005","author":"Li Jing","year":"2023","unstructured":"Jing Li, Daoxin Lin, Huaxin Shu, Yuan Wang, and Xindong Liu. 2023. Federated Learning with Data and Model Privacy Preservation. arXiv preprint arXiv:2306.08005 (2023)."},{"key":"e_1_3_2_1_46_1","volume-title":"A survey on federated learning systems: vision, hype and reality for data privacy and protection","author":"Li Qinbin","year":"2021","unstructured":"Qinbin Li, Zeyi Wen, Zhaomin Wu, Sixu Hu, Naibo Wang, Yuan Li, Xu Liu, and Bingsheng He. 2021. A survey on federated learning systems: vision, hype and reality for data privacy and protection. IEEE Transactions on Knowledge and Data Engineering (2021)."},{"key":"e_1_3_2_1_47_1","unstructured":"Qinbin Li Zhaomin Wu Zeyi Wen and Bingsheng He. 2020. Privacy-preserving gradient boosting decision trees. In AAAI."},{"key":"e_1_3_2_1_48_1","unstructured":"Zhuohang Li Jiaxin Zhang Luyang Liu and Jian Liu. 2022. Auditing privacy defenses in federated learning via generative gradient leakage. In CVPR."},{"key":"e_1_3_2_1_49_1","volume-title":"Tighter Privacy Bounds for Subsampled Mechanisms in Federated Learning. arXiv preprint arXiv:2304.02140","author":"Liu Xinwei","year":"2023","unstructured":"Xinwei Liu, Penghui Zhao, Chao Li, and Jiawen Zhang. 2023. Tighter Privacy Bounds for Subsampled Mechanisms in Federated Learning. arXiv preprint arXiv:2304.02140 (2023)."},{"key":"e_1_3_2_1_50_1","volume-title":"Abd El-Latif","author":"Liu Yi","year":"2020","unstructured":"Yi Liu, Jialiang Peng, Jiawen Kang, Abdullah M. Iliyasu, Dusit Niyato, and Ahmed A. Abd El-Latif. 2020. A Secure Federated Learning Framework For 5G Networks. arXiv preprint arXiv:2001.05637 (2020)."},{"key":"e_1_3_2_1_51_1","volume-title":"Mario Fritz, and Yang Zhang.","author":"Liu Yugeng","year":"2022","unstructured":"Yugeng Liu, Rui Wen, Xinlei He, Ahmed Salem, Zhikun Zhang, Michael Backes, Emiliano De Cristofaro, Mario Fritz, and Yang Zhang. 2022. ML-Doctor: Holistic Risk Assessment of Inference Attacks Against Machine Learning Models. In USENIX Security 22. USENIX Association."},{"key":"e_1_3_2_1_52_1","volume-title":"Federated Multi-Task Learning with Differential Privacy. arXiv preprint arXiv:2307.03449","author":"Luo Yitong","year":"2023","unstructured":"Yitong Luo, Jiaheng Zhang, Qiaoyu Tan, Yu-Xiang Wang, and Qiang Yang. 2023. Federated Multi-Task Learning with Differential Privacy. arXiv preprint arXiv:2307.03449 (2023)."},{"key":"e_1_3_2_1_53_1","volume-title":"A novel attribute reconstruction attack in federated learning. arXiv preprint arXiv:2108.06910","author":"Lyu Lingjuan","year":"2021","unstructured":"Lingjuan Lyu and Chen Chen. 2021. A novel attribute reconstruction attack in federated learning. arXiv preprint arXiv:2108.06910 (2021)."},{"key":"e_1_3_2_1_54_1","unstructured":"Brendan McMahan Eider Moore Daniel Ramage Seth Hampson and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics. 1273--1282."},{"key":"e_1_3_2_1_55_1","volume-title":"Learning Differentially Private Recurrent Language Models. In International Conference on Learning Representations.","author":"McMahan H. Brendan","year":"2018","unstructured":"H. Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. 2018. Learning Differentially Private Recurrent Language Models. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_56_1","volume-title":"R\u00e9nyi differential privacy. In 2017 IEEE 30th computer security foundations symposium (CSF)","author":"Mironov Ilya","unstructured":"Ilya Mironov. 2017. R\u00e9nyi differential privacy. In 2017 IEEE 30th computer security foundations symposium (CSF). IEEE."},{"key":"e_1_3_2_1_57_1","volume-title":"arXiv preprint arXiv:1908.10530","author":"Mironov Ilya","year":"2019","unstructured":"Ilya Mironov, Kunal Talwar, and Li Zhang. 2019. R\\'enyi differential privacy of the sampled gaussian mechanism. arXiv preprint arXiv:1908.10530 (2019)."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417259"},{"key":"e_1_3_2_1_59_1","volume-title":"Local and central differential privacy for robustness and privacy in federated learning. arXiv preprint arXiv:2009.03561","author":"Naseri Mohammad","year":"2020","unstructured":"Mohammad Naseri, Jamie Hayes, and Emiliano De Cristofaro. 2020. Local and central differential privacy for robustness and privacy in federated learning. arXiv preprint arXiv:2009.03561 (2020)."},{"key":"e_1_3_2_1_60_1","volume-title":"Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning","author":"Nasr Milad","unstructured":"Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019. Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In IEEE S&P. IEEE."},{"key":"e_1_3_2_1_61_1","volume-title":"Efficient Byzantine-Robust and Provably Privacy-Preserving Federated Learning. arXiv preprint arXiv:2407.19703","author":"Nie Chenfei","year":"2024","unstructured":"Chenfei Nie, Qiang Li, Yuxin Yang, Yuede Ji, and Binghui Wang. 2024. Efficient Byzantine-Robust and Provably Privacy-Preserving Federated Learning. arXiv preprint arXiv:2407.19703 (2024)."},{"key":"e_1_3_2_1_62_1","volume-title":"SoK: Let the privacy games begin! A unified treatment of data inference privacy in machine learning","author":"Salem Ahmed","unstructured":"Ahmed Salem, Giovanni Cherubin, David Evans, Boris K\u00f6pf, Andrew Paverd, Anshuman Suri, Shruti Tople, and Santiago Zanella-B\u00e9guelin. 2023. SoK: Let the privacy games begin! A unified treatment of data inference privacy in machine learning. In IEEE S&P. IEEE."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"crossref","unstructured":"Lu Shi Jiangang Shu Weizhe Zhang and Yang Liu. 2021. HFL-DP: Hierarchical Federated Learning with Differential Privacy. In GLOBECOM.","DOI":"10.1109\/GLOBECOM46510.2021.9685644"},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_65_1","volume-title":"Federated Model Distillation with Noise-Free Differential Privacy. arXiv preprint arXiv:2012.04187","author":"Sun Lichao","year":"2020","unstructured":"Lichao Sun and Lingjuan Lyu. 2020. Federated Model Distillation with Noise-Free Differential Privacy. arXiv preprint arXiv:2012.04187 (2020)."},{"key":"e_1_3_2_1_66_1","volume-title":"Federated Learning with Adaptive Differential Privacy","author":"Sun Lichao","year":"2023","unstructured":"Lichao Sun, Jianwei Qian, and Xiang Chen. 2023. Federated Learning with Adaptive Differential Privacy. IEEE TDSC (2023)."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/BigData47090.2019.9005465"},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2014.2320500"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"crossref","unstructured":"Matta Varun Shuya Feng Han Wang Shamik Sural and Yuan Hong. 2024. Towards Accurate and Stronger Local Differential Privacy for Federated Learning with Staircase Randomized Response. In CODASP. 307--318.","DOI":"10.1145\/3626232.3653279"},{"key":"e_1_3_2_1_70_1","volume-title":"Analytical composition of differential privacy via the edgeworth accountant. arXiv preprint arXiv:2206.04236","author":"Wang Hua","year":"2022","unstructured":"Hua Wang, Sheng Gao, Huanyu Zhang, Milan Shen, and Weijie J Su. 2022a. Analytical composition of differential privacy via the edgeworth accountant. arXiv preprint arXiv:2206.04236 (2022)."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539417"},{"key":"e_1_3_2_1_72_1","volume-title":"A Platform-Free Proof of Federated Learning Consensus Mechanism for Sustainable Blockchains. arXiv preprint arXiv:2202.01884","author":"Wang Yuntao","year":"2022","unstructured":"Yuntao Wang, Haixia Peng, Zhou Su, Tom H Luan, Abderrahim Benslimane, and Yuan Wu. 2022b. A Platform-Free Proof of Federated Learning Consensus Mechanism for Sustainable Blockchains. arXiv preprint arXiv:2202.01884 (2022)."},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"crossref","unstructured":"Yu-Xiang Wang Borja Balle and Shiva Prasad Kasiviswanathan. 2019. Subsampled R\u00e9nyi differential privacy and analytical moments accountant. In AISTATS.","DOI":"10.29012\/jpc.723"},{"key":"e_1_3_2_1_74_1","volume-title":"Federated Learning With Differential Privacy: Algorithms and Performance Analysis","author":"Wei Kang","year":"2020","unstructured":"Kang Wei, Jun Li, Ming Ding, Chuan Ma, Howard H. Yang, Farhad Farokhi, Shi Jin, Tony Q. S. Quek, and H. Vincent Poor. 2020. Federated Learning With Differential Privacy: Algorithms and Performance Analysis. IEEE Transactions on Information Forensics and Security (2020)."},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3293417"},{"key":"e_1_3_2_1_76_1","volume-title":"Canary in a Coalmine: Better Membership Inference with Ensembled Adversarial Queries. arXiv preprint arXiv:2210.10750","author":"Wen Yuxin","year":"2022","unstructured":"Yuxin Wen, Arpit Bansal, Hamid Kazemi, Eitan Borgnia, Micah Goldblum, Jonas Geiping, and Tom Goldstein. 2022. Canary in a Coalmine: Better Membership Inference with Ensembled Adversarial Queries. arXiv preprint arXiv:2210.10750 (2022)."},{"key":"e_1_3_2_1_77_1","volume-title":"Fedmed: A federated learning framework for language modeling. Sensors","author":"Wu Xing","year":"2020","unstructured":"Xing Wu, Zhaowang Liang, and Jianjia Wang. 2020. Fedmed: A federated learning framework for language modeling. Sensors (2020)."},{"key":"e_1_3_2_1_78_1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2010.247"},{"key":"e_1_3_2_1_79_1","first-page":"57","article-title":"Federated learning with privacy-preserving and model protection","volume":"613","author":"Xu Mingzhe","year":"2022","unstructured":"Mingzhe Xu, Gen Li, Jiaojiao Zheng, Qian Xiao, and Jian Liu. 2022. Federated learning with privacy-preserving and model protection. Information Sciences, Vol. 613 (2022), 57--71.","journal-title":"Information Sciences"},{"key":"e_1_3_2_1_80_1","volume-title":"A Secret Sharing-Inspired Robust Distributed Backdoor Attack to Federated Learning. ACM Transactions on Privacy and Security","author":"Yang Yuxin","year":"2025","unstructured":"Yuxin Yang, Qiang Li, Yuede Ji, and Binghui Wang. 2025. A Secret Sharing-Inspired Robust Distributed Backdoor Attack to Federated Learning. ACM Transactions on Privacy and Security (2025)."},{"key":"e_1_3_2_1_81_1","volume-title":"On convergence of FedProx: Local dissimilarity invariant bounds, non-smoothness and beyond. NeurIPS","author":"Yuan Xiaotong","year":"2022","unstructured":"Xiaotong Yuan and Ping Li. 2022. On convergence of FedProx: Local dissimilarity invariant bounds, non-smoothness and beyond. NeurIPS (2022)."},{"key":"e_1_3_2_1_82_1","volume-title":"Gan enhanced membership inference: A passive local attack in federated learning","author":"Zhang Jingwen","unstructured":"Jingwen Zhang, Jiale Zhang, Junjun Chen, and Shui Yu. 2020. Gan enhanced membership inference: A passive local attack in federated learning. In ICC. IEEE."},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"crossref","unstructured":"Zhifei Zhang Yang Song and Hairong Qi. 2017. Age progression\/regression by conditional adversarial autoencoder. In CVPR. 5810--5818.","DOI":"10.1109\/CVPR.2017.463"},{"key":"e_1_3_2_1_84_1","volume-title":"International Conference on Artificial Intelligence and Statistics. PMLR.","author":"Zheng Qinqing","year":"2021","unstructured":"Qinqing Zheng, Shuxiao Chen, Qi Long, and Weijie Su. 2021. Federated f-differential privacy. In International Conference on Artificial Intelligence and Statistics. PMLR."},{"key":"e_1_3_2_1_85_1","unstructured":"Wei Zhou Jiacheng Mao Ankai Xu Shutian Wan Qianqian Gong Xin Li Yi Wen and Jian Li. 2023. Tight Privacy Composition Analysis for Federated Learning. In ICML."},{"key":"e_1_3_2_1_86_1","volume-title":"Efficient Differentially Private Federated Learning for Heterogeneous Data. arXiv preprint arXiv:2306.08750","author":"Zhu Haonan","year":"2023","unstructured":"Haonan Zhu and Ruoxi Ding. 2023. Efficient Differentially Private Federated Learning for Heterogeneous Data. arXiv preprint arXiv:2306.08750 (2023)."},{"key":"e_1_3_2_1_87_1","volume-title":"NeurIPS","volume":"32","author":"Zhu Ligeng","year":"2019","unstructured":"Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep leakage from gradients. NeurIPS, Vol. 32 (2019)."},{"key":"e_1_3_2_1_88_1","unstructured":"Yuqing Zhu Jinshuo Dong and Yu-Xiang Wang. 2022. Optimal Accounting of Differential Privacy via Characteristic Function. In AISTATS."}],"event":{"name":"CODASPY '25: Fifteenth ACM Conference on Data and Application Security and Privacy","location":"Pittsburgh PA USA","acronym":"CODASPY '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the Fifteenth ACM Conference on Data and Application Security and Privacy"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3714393.3726517","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3714393.3726517","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T16:28:23Z","timestamp":1780417703000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3714393.3726517"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,19]]},"references-count":88,"alternative-id":["10.1145\/3714393.3726517","10.1145\/3714393"],"URL":"https:\/\/doi.org\/10.1145\/3714393.3726517","relation":{},"subject":[],"published":{"date-parts":[[2024,6,19]]},"assertion":[{"value":"2025-06-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}