{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,22]],"date-time":"2026-07-22T16:15:56Z","timestamp":1784736956675,"version":"3.55.0"},"reference-count":209,"publisher":"Association for Computing Machinery (ACM)","issue":"11","funder":[{"DOI":"10.13039\/100000144","name":"Division of Computer and Network Systems","doi-asserted-by":"publisher","award":["CNS-2029038, and CNS-2135988"],"award-info":[{"award-number":["CNS-2029038, and CNS-2135988"]}],"id":[{"id":"10.13039\/100000144","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2026,8,30]]},"abstract":"<jats:p>In recent years, privacy and security concerns in machine learning have promoted trusted federated learning to the forefront of research. Differential privacy has emerged as the de facto standard for privacy protection in federated learning due to its rigorous mathematical foundation and provable guarantee. Despite extensive research on algorithms that incorporate differential privacy within federated learning, there remains an evident deficiency in systematic reviews that categorize and synthesize these studies.<\/jats:p>\n                  <jats:p>Our work presents a systematic overview of the differentially private federated learning. Existing taxonomies have not adequately considered objects and level of privacy protection provided by various differential privacy models in federated learning. To rectify this gap, we propose a new taxonomy of differentially private federated learning based on definition and guarantee of various differential privacy models and federated scenarios. Our classification allows for a clear delineation of the protected objects across various differential privacy models and their respective neighborhood levels within federated learning environments. Furthermore, we explore the applications of differential privacy in federated learning scenarios. Our work provide valuable insights into privacy-preserving federated learning and suggest practical directions for future research.<\/jats:p>","DOI":"10.1145\/3801079","type":"journal-article","created":{"date-parts":[[2026,3,16]],"date-time":"2026-03-16T20:45:51Z","timestamp":1773693951000},"page":"1-38","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Differentially Private Federated Learning: A Systematic Review"],"prefix":"10.1145","volume":"58","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-9337-1452","authenticated-orcid":false,"given":"Jie","family":"Fu","sequence":"first","affiliation":[{"name":"Stevens Institute of Technology","place":["Hoboken, United States"]},{"name":"East China Normal University","place":["Hoboken, United States"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4095-4506","authenticated-orcid":false,"given":"Yuan","family":"Hong","sequence":"additional","affiliation":[{"name":"University of Connecticut","place":["Storrs, United States"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-1605-7054","authenticated-orcid":false,"given":"Xinpeng","family":"Ling","sequence":"additional","affiliation":[{"name":"Tongji University","place":["Shanghai, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3475-9552","authenticated-orcid":false,"given":"Leixia","family":"Wang","sequence":"additional","affiliation":[{"name":"Northeastern University","place":["Shenyang, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6211-1262","authenticated-orcid":false,"given":"Xun","family":"Ran","sequence":"additional","affiliation":[{"name":"The Hong Kong Polytechnic University","place":["Hong Kong, Hong Kong"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-1317-1761","authenticated-orcid":false,"given":"Zhiyu","family":"Sun","sequence":"additional","affiliation":[{"name":"East China Normal University","place":["Shanghai, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3913-815X","authenticated-orcid":false,"given":"Wendy Hui","family":"Wang","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Stevens Institute of Technology","place":["Hoboken, United States"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2231-3652","authenticated-orcid":false,"given":"Zhili","family":"Chen","sequence":"additional","affiliation":[{"name":"East China Normal University","place":["Shanghai, China"]}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6424-8633","authenticated-orcid":false,"given":"Yang","family":"Cao","sequence":"additional","affiliation":[{"name":"Institute of Science Tokyo","place":["Tokyo, Japan"]}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,18]]},"reference":[{"key":"e_1_3_3_2_2","doi-asserted-by":"crossref","first-page":"308","DOI":"10.1145\/2976749.2978318","volume-title":"Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security","author":"Abadi Martin","year":"2016","unstructured":"Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security. 308\u2013318."},{"key":"e_1_3_3_3_2","first-page":"15293","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence","author":"Abourayya Amr","year":"2025","unstructured":"Amr Abourayya, Jens Kleesiek, Kanishka Rao, Erman Ayday, Bharat Rao, Geoffrey I. Webb, and Michael Kamp. 2025. Little is enough: Boosting privacy by sharing only hard labels in federated semi-supervised learning. In Proceedings of the AAAI Conference on Artificial Intelligence. 15293\u201315301."},{"key":"e_1_3_3_4_2","unstructured":"Naman Agarwal Peter Kairouz and Ziyu Liu. 2021. The skellam mechanism for differentially private federated learning. Advances in Neural Information Processing Systems 34 (2021) 5052\u20135064."},{"key":"e_1_3_3_5_2","unstructured":"Naman Agarwal Ananda Theertha Suresh Felix Xinnan X Yu Sanjiv Kumar and Brendan McMahan. 2018. cpSGD: Communication-efficient and differentially-private distributed SGD. Advances in Neural Information Processing Systems 31 (2018) 7575\u20137586."},{"key":"e_1_3_3_6_2","unstructured":"Muhammad Ammad-Ud-Din Elena Ivannikova Suleiman A. Khan Were Oyomno Qiang Fu Kuan Eeik Tan and Adrian Flanagan. 2019. Federated collaborative filtering for privacy-preserving personalized recommendation system. arXiv:1901.09888. Retrieved from https:\/\/arxiv.org\/abs\/1901.09888"},{"key":"e_1_3_3_7_2","unstructured":"Galen Andrew Om Thakkar Brendan McMahan and Swaroop Ramaswamy. 2021. Differentially private learning with adaptive clipping. Advances in Neural Information Processing Systems 34 (2021) 17455\u201317466."},{"key":"e_1_3_3_8_2","first-page":"2496","volume-title":"Proceedings of the International Conference on Artificial Intelligence and Statistics","author":"Balle Borja","year":"2020","unstructured":"Borja Balle, Gilles Barthe, Marco Gaboardi, Justin Hsu, and Tetsuya Sato. 2020. Hypothesis testing interpretations and renyi differential privacy. In Proceedings of the International Conference on Artificial Intelligence and Statistics. PMLR, 2496\u20132506."},{"key":"e_1_3_3_9_2","doi-asserted-by":"crossref","first-page":"638","DOI":"10.1007\/978-3-030-26951-7_22","volume-title":"Advances in Cryptology\u2013CRYPTO 2019: 39th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 18\u201322, 2019, Proceedings, Part II 39","author":"Balle Borja","year":"2019","unstructured":"Borja Balle, James Bell, Adri\u00e0 Gasc\u00f3n, and Kobbi Nissim. 2019. The privacy blanket of the shuffle model. In Advances in Cryptology\u2013CRYPTO 2019: 39th Annual International Cryptology Conference, Santa Barbara, CA, USA, August 18\u201322, 2019, Proceedings, Part II 39. Springer, 638\u2013667."},{"key":"e_1_3_3_10_2","first-page":"1569","volume-title":"Proceedings of the 34th USENIX Security Symposium","author":"Bao Ergute","year":"2025","unstructured":"Ergute Bao, Yangfan Jiang, Fei Wei, Xiaokui Xiao, Zitao Li, Yaliang Li, and Bolin Ding. 2025. Unlocking the power of differentially private zeroth-order optimization for fine-tuning LLMs. In Proceedings of the 34th USENIX Security Symposium. 1569\u20131588."},{"key":"e_1_3_3_11_2","first-page":"1945","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Bietti Alberto","year":"2022","unstructured":"Alberto Bietti, Chen-Yu Wei, Miroslav Dudik, John Langford, and Steven Wu. 2022. Personalization improves privacy-accuracy tradeoffs in federated learning. In Proceedings of the International Conference on Machine Learning. PMLR, 1945\u20131962."},{"key":"e_1_3_3_12_2","doi-asserted-by":"crossref","first-page":"441","DOI":"10.1145\/3132747.3132769","volume-title":"Proceedings of the 26th Symposium on Operating Systems Principles","author":"Bittau Andrea","year":"2017","unstructured":"Andrea Bittau, \u00dalfar Erlingsson, Petros Maniatis, Ilya Mironov, Ananth Raghunathan, David Lie, Mitch Rudominer, Ushasree Kode, Julien Tinnes, and Bernhard Seefeld. 2017. Prochlo: Strong privacy for analytics in the crowd. In Proceedings of the 26th Symposium on Operating Systems Principles. 441\u2013459."},{"key":"e_1_3_3_13_2","doi-asserted-by":"crossref","first-page":"1175","DOI":"10.1145\/3133956.3133982","volume-title":"Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security","author":"Bonawitz Keith","year":"2017","unstructured":"Keith Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone, H. Brendan McMahan, Sarvar Patel, Daniel Ramage, Aaron Segal, and Karn Seth. 2017. Practical secure aggregation for privacy-preserving machine learning. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. 1175\u20131191."},{"key":"e_1_3_3_14_2","first-page":"635","volume-title":"Proceedings of the Theory of Cryptography Conference","author":"Bun Mark","year":"2016","unstructured":"Mark Bun and Thomas Steinke. 2016. Concentrated differential privacy: Simplifications, extensions, and lower bounds. In Proceedings of the Theory of Cryptography Conference. Springer, 635\u2013658."},{"key":"e_1_3_3_15_2","unstructured":"Cl\u00e9ment L. Canonne Gautam Kamath and Thomas Steinke. 2020. The discrete gaussian for differential privacy. Advances in Neural Information Processing Systems 33 (2020) 15676\u201315688."},{"key":"e_1_3_3_16_2","doi-asserted-by":"crossref","unstructured":"T.-H. Hubert Chan Elaine Shi and Dawn Song. 2011. Private and continual release of statistics. ACM Transactions on Information and System Security 14 3 (2011) 1\u201324.","DOI":"10.1145\/2043621.2043626"},{"key":"e_1_3_3_17_2","first-page":"7354","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Chang Woong-Gi","year":"2019","unstructured":"Woong-Gi Chang, Tackgeun You, Seonguk Seo, Suha Kwak, and Bohyung Han. 2019. Domain-specific batch normalization for unsupervised domain adaptation. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 7354\u20137362."},{"key":"e_1_3_3_18_2","doi-asserted-by":"crossref","unstructured":"Liwei Che Jiaqi Wang Yao Zhou and Fenglong Ma. 2023. Multimodal federated learning: A survey. Sensors 23 15 (2023) 6986.","DOI":"10.3390\/s23156986"},{"key":"e_1_3_3_19_2","doi-asserted-by":"crossref","unstructured":"E. Chen Yang Cao and Yifei Ge. 2024. A generalized shuffle framework for privacy amplification: Strengthening privacy guarantees and enhancing utility. In Proceedings of the AAAI Conference on Artificial Intelligence 38 10 (2024) 11267\u201311275.","DOI":"10.1609\/aaai.v38i10.29005"},{"key":"e_1_3_3_20_2","doi-asserted-by":"crossref","unstructured":"Lin Chen Xiaofeng Ding Zhifeng Bao Pan Zhou and Hai Jin. 2024. Differentially private federated learning on non-iid data: Convergence analysis and adaptive optimization. IEEE Transactions on Knowledge and Data Engineering 36 9 (2024) 4567\u20134581.","DOI":"10.1109\/TKDE.2024.3379001"},{"key":"e_1_3_3_21_2","first-page":"2287","volume-title":"Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining","author":"Chen Mia Xu","year":"2019","unstructured":"Mia Xu Chen, Benjamin N. Lee, Gagan Bansal, Yuan Cao, Shuyuan Zhang, Justin Lu, Jackie Tsay, Yinan Wang, Andrew M. Dai, Zhifeng Chen, et\u00a0al. 2019. Gmail smart compose: Real-time assisted writing. In Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. 2287\u20132295."},{"key":"e_1_3_3_22_2","unstructured":"Tianyi Chen Xiao Jin Yuejiao Sun and Wotao Yin. 2020. Vafl: A method of vertical asynchronous federated learning. arXiv:2007.06081. Retrieved from https:\/\/arxiv.org\/abs\/2007.06081"},{"key":"e_1_3_3_23_2","first-page":"3056","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Chen Wei-Ning","year":"2022","unstructured":"Wei-Ning Chen, Christopher A. Choquette Choo, Peter Kairouz, and Ananda Theertha Suresh. 2022. The fundamental price of secure aggregation in differentially private federated learning. In Proceedings of the International Conference on Machine Learning. PMLR, 3056\u20133089."},{"key":"e_1_3_3_24_2","first-page":"3490","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Chen Wei-Ning","year":"2022","unstructured":"Wei-Ning Chen, Ayfer Ozgur, and Peter Kairouz. 2022. The poisson binomial mechanism for unbiased federated learning with secure aggregation. In Proceedings of the International Conference on Machine Learning. PMLR, 3490\u20133506."},{"key":"e_1_3_3_25_2","doi-asserted-by":"crossref","unstructured":"Xi Chen Sentao Miao and Yining Wang. 2023. Differential privacy in personalized pricing with nonparametric demand models. Operations Research 71 2 (2023) 581\u2013602.","DOI":"10.1287\/opre.2022.2347"},{"key":"e_1_3_3_26_2","first-page":"10122","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Cheng Anda","year":"2022","unstructured":"Anda Cheng, Peisong Wang, Xi Sheryl Zhang, and Jian Cheng. 2022. Differentially private federated learning with local regularization and sparsification. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 10122\u201310131."},{"key":"e_1_3_3_27_2","doi-asserted-by":"crossref","first-page":"375","DOI":"10.1007\/978-3-030-17653-2_13","volume-title":"Advances in Cryptology\u2013EUROCRYPT 2019: 38th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Darmstadt, Germany, May 19\u201323, 2019, Proceedings, Part I 38","author":"Cheu Albert","year":"2019","unstructured":"Albert Cheu, Adam Smith, Jonathan Ullman, David Zeber, and Maxim Zhilyaev. 2019. Distributed differential privacy via shuffling. In Advances in Cryptology\u2013EUROCRYPT 2019: 38th Annual International Conference on the Theory and Applications of Cryptographic Techniques, Darmstadt, Germany, May 19\u201323, 2019, Proceedings, Part I 38. Springer, 375\u2013403."},{"key":"e_1_3_3_28_2","unstructured":"Olivia Choudhury Aris Gkoulalas-Divanis Theodoros Salonidis Issa Sylla Yoonyoung Park Grace Hsu and Amar Das. 2019. Differential privacy-enabled federated learning for sensitive health data. arXiv:1910.02578. Retrieved from https:\/\/arxiv.org\/abs\/1910.02578"},{"key":"e_1_3_3_29_2","first-page":"20","volume-title":"Proceedings of the Conference on Fairness, Accountability, and Transparency","author":"Cummings Rachel","year":"2018","unstructured":"Rachel Cummings and Deven Desai. 2018. The role of differential privacy in gdpr compliance. In Proceedings of the Conference on Fairness, Accountability, and Transparency. 20."},{"key":"e_1_3_3_30_2","unstructured":"Zhongxiang Dai Bryan Kian Hsiang Low and Patrick Jaillet. 2021. Differentially private federated Bayesian optimization with distributed exploration. Advances in Neural Information Processing Systems 34 (2021) 9125\u20139139."},{"key":"e_1_3_3_31_2","volume-title":"Proceedings of the ICLR 2022 Workshop on PAIR 2Struct: Privacy, Accountability, Interpretability, Robustness, Reasoning on Structured Data","author":"Daigavane Ameya","year":"2022","unstructured":"Ameya Daigavane, Gagan Madan, Aditya Sinha, Abhradeep Guha Thakurta, Gaurav Aggarwal, and Prateek Jain. 2022. Node-level differentially private graph neural networks. In Proceedings of the ICLR 2022 Workshop on PAIR 2Struct: Privacy, Accountability, Interpretability, Robustness, Reasoning on Structured Data."},{"key":"e_1_3_3_32_2","first-page":"643","volume-title":"Proceedings of the Annual Cryptology Conference","author":"Damg\u00e5rd Ivan","year":"2012","unstructured":"Ivan Damg\u00e5rd, Valerio Pastro, Nigel Smart, and Sarah Zakarias. 2012. Multiparty computation from somewhat homomorphic encryption. In Proceedings of the Annual Cryptology Conference. Springer, 643\u2013662."},{"key":"e_1_3_3_33_2","unstructured":"Soham De Leonard Berrada Jamie Hayes Samuel L. Smith and Borja Balle. 2022. Unlocking high-accuracy differentially private image classification through scale. arXiv:2204.13650. Retrieved from https:\/\/arxiv.org\/abs\/2204.13650"},{"key":"e_1_3_3_34_2","volume-title":"Proceedings of the NeurIPS 2022 Workshop on Distribution Shifts: Connecting Methods and Applications","author":"Dodwadmath Akshay","year":"2022","unstructured":"Akshay Dodwadmath and Sebastian U. Stich. 2022. Preserving privacy with PATE for heterogeneous data. In Proceedings of the NeurIPS 2022 Workshop on Distribution Shifts: Connecting Methods and Applications."},{"key":"e_1_3_3_35_2","doi-asserted-by":"crossref","unstructured":"Jinshuo Dong Aaron Roth and Weijie Su. 2022. Gaussian differential privacy. Journal of the Royal Statistical Society: Series B (Statistical Methodology) 84 1 (2022) 3\u201337.","DOI":"10.1111\/rssb.12454"},{"key":"e_1_3_3_36_2","unstructured":"John Duchi Martin J. Wainwright and Michael I. Jordan. 2013. Local privacy and minimax bounds: Sharp rates for probability estimation. Advances in Neural Information Processing Systems 26 (2013) 1529\u20131537."},{"key":"e_1_3_3_37_2","doi-asserted-by":"crossref","unstructured":"John C. Duchi Michael I. Jordan and Martin J. Wainwright. 2018. Minimax optimal procedures for locally private estimation. Journal of the American Statistical Association 113 521 (2018) 182\u2013201.","DOI":"10.1080\/01621459.2017.1389735"},{"key":"e_1_3_3_38_2","doi-asserted-by":"crossref","first-page":"265","DOI":"10.1007\/11681878_14","volume-title":"Theory of Cryptography: Third Theory of Cryptography Conference, TCC 2006, New York, NY, USA, March 4-7, 2006. Proceedings 3","author":"Dwork Cynthia","year":"2006","unstructured":"Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith. 2006. Calibrating noise to sensitivity in private data analysis. In Theory of Cryptography: Third Theory of Cryptography Conference, TCC 2006, New York, NY, USA, March 4-7, 2006. Proceedings 3. Springer, 265\u2013284."},{"key":"e_1_3_3_39_2","first-page":"715","volume-title":"Proceedings of the 42nd ACM Symposium on Theory of Computing","author":"Dwork Cynthia","year":"2010","unstructured":"Cynthia Dwork, Moni Naor, Toniann Pitassi, and Guy N. Rothblum. 2010. Differential privacy under continual observation. In Proceedings of the 42nd ACM Symposium on Theory of Computing. 715\u2013724."},{"key":"e_1_3_3_40_2","doi-asserted-by":"crossref","unstructured":"Cynthia Dwork and Aaron Roth. 2014. The algorithmic foundations of differential privacy. Foundations and Trends\u00ae in Theoretical Computer Science 9 3\u20134 (2014) 211\u2013407.","DOI":"10.1561\/0400000042"},{"key":"e_1_3_3_41_2","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1109\/FOCS.2010.12","volume-title":"Proceedings of the 2010 IEEE 51st Annual Symposium on Foundations of Computer Science","author":"Dwork Cynthia","year":"2010","unstructured":"Cynthia Dwork, Guy N. Rothblum, and Salil Vadhan. 2010. Boosting and differential privacy. In Proceedings of the 2010 IEEE 51st Annual Symposium on Foundations of Computer Science. IEEE, 51\u201360."},{"key":"e_1_3_3_42_2","doi-asserted-by":"crossref","unstructured":"Ahmed El Ouadrhiri and Ahmed Abdelhadi. 2022. Differential privacy for deep and federated learning: A survey. IEEE Access 10 (2022) 22359\u201322380.","DOI":"10.1109\/ACCESS.2022.3151670"},{"key":"e_1_3_3_43_2","unstructured":"Alessandro Epasto Mohammad Mahdian Jieming Mao Vahab Mirrokni and Lijie Ren. 2020. Smoothly bounding user contributions in differential privacy. Advances in Neural Information Processing Systems 33 (2020) 13999\u201314010."},{"key":"e_1_3_3_44_2","first-page":"2468","volume-title":"Proceedings of the 30th Annual ACM-SIAM Symposium on Discrete Algorithms","author":"Erlingsson \u00dalfar","year":"2019","unstructured":"\u00dalfar Erlingsson, Vitaly Feldman, Ilya Mironov, Ananth Raghunathan, Kunal Talwar, and Abhradeep Thakurta. 2019. Amplification by shuffling: From local to central differential privacy via anonymity. In Proceedings of the 30th Annual ACM-SIAM Symposium on Discrete Algorithms. SIAM, 2468\u20132479."},{"key":"e_1_3_3_45_2","doi-asserted-by":"crossref","first-page":"1054","DOI":"10.1145\/2660267.2660348","volume-title":"Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security","author":"Erlingsson \u00dalfar","year":"2014","unstructured":"\u00dalfar Erlingsson, Vasyl Pihur, and Aleksandra Korolova. 2014. Rappor: Randomized aggregatable privacy-preserving ordinal response. In Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security. 1054\u20131067."},{"key":"e_1_3_3_46_2","first-page":"211","volume-title":"Proceedings of the 22nd ACM SIGMOD-SIGACT-SIGART Symposium on Principles of Database Systems","author":"Evfimievski Alexandre","year":"2003","unstructured":"Alexandre Evfimievski, Johannes Gehrke, and Ramakrishnan Srikant. 2003. Limiting privacy breaches in privacy preserving data mining. In Proceedings of the 22nd ACM SIGMOD-SIGACT-SIGART Symposium on Principles of Database Systems. 211\u2013222."},{"key":"e_1_3_3_47_2","first-page":"1","volume-title":"Proceedings of the 2024 18th International Conference on Ubiquitous Information Management and Communication.","author":"Farooqi Shaista Ashraf","year":"2024","unstructured":"Shaista Ashraf Farooqi, Aedah Abd Rahman, and Amna Saad. 2024. Differential privacy based federated learning techniques in IoMT: A review. In Proceedings of the 2024 18th International Conference on Ubiquitous Information Management and Communication.IEEE, 1\u20137."},{"key":"e_1_3_3_48_2","doi-asserted-by":"crossref","first-page":"954","DOI":"10.1145\/3357713.3384290","volume-title":"Proceedings of the 52nd Annual ACM SIGACT Symposium on Theory of Computing","author":"Feldman Vitaly","year":"2020","unstructured":"Vitaly Feldman. 2020. Does learning require memorization? a short tale about a long tail. In Proceedings of the 52nd Annual ACM SIGACT Symposium on Theory of Computing. 954\u2013959."},{"key":"e_1_3_3_49_2","doi-asserted-by":"crossref","first-page":"954","DOI":"10.1109\/FOCS52979.2021.00096","volume-title":"Proceedings of the 2021 IEEE 62nd Annual Symposium on Foundations of Computer Science","author":"Feldman Vitaly","year":"2022","unstructured":"Vitaly Feldman, Audra McMillan, and Kunal Talwar. 2022. Hiding among the clones: A simple and nearly optimal analysis of privacy amplification by shuffling. In Proceedings of the 2021 IEEE 62nd Annual Symposium on Foundations of Computer Science. IEEE, 954\u2013964."},{"key":"e_1_3_3_50_2","first-page":"60","volume-title":"Proceedings of the 15th ACM Conference on Data and Application Security and Privacy","author":"Feng Shuya","year":"2024","unstructured":"Shuya Feng, Meisam Mohammady, Hanbin Hong, Shenao Yan, Ashish Kundu, Binghui Wang, and Yuan Hong. 2024. Harmonizing differential privacy mechanisms for federated learning: Boosting accuracy and convergence. In Proceedings of the 15th ACM Conference on Data and Application Security and Privacy. 60\u201371."},{"key":"e_1_3_3_51_2","first-page":"2960","volume-title":"Proceedings of the IEEE International Conference on Computer Vision","author":"Fernando Basura","year":"2013","unstructured":"Basura Fernando, Amaury Habrard, Marc Sebban, and Tinne Tuytelaars. 2013. Unsupervised visual domain adaptation using subspace alignment. In Proceedings of the IEEE International Conference on Computer Vision. 2960\u20132967."},{"key":"e_1_3_3_52_2","unstructured":"Pierre Foret Ariel Kleiner Hossein Mobahi and Behnam Neyshabur. 2021. Sharpness-aware minimization for efficiently improving generalization. In International Conference on Learning Representations (ICLR 2021)."},{"key":"e_1_3_3_53_2","doi-asserted-by":"crossref","unstructured":"Arik Friedman Shlomo Berkovsky and Mohamed Ali Kaafar. 2016. A differential privacy framework for matrix factorization recommender systems. User Modeling and User-Adapted Interaction 26 5 (2016) 425\u2013458.","DOI":"10.1007\/s11257-016-9177-7"},{"key":"e_1_3_3_54_2","first-page":"1397","volume-title":"Proceedings of the 31st USENIX Security Symposium","author":"Fu Chong","year":"2022","unstructured":"Chong Fu, Xuhong Zhang, Shouling Ji, Jinyin Chen, Jingzheng Wu, Shanqing Guo, Jun Zhou, Alex X. Liu, and Ting Wang. 2022. Label inference attacks against vertical federated learning. In Proceedings of the 31st USENIX Security Symposium. 1397\u20131414."},{"key":"e_1_3_3_55_2","first-page":"656","volume-title":"Proceedings of the 2022 IEEE International Conference on Trust, Security and Privacy in Computing and Communications","author":"Fu Jie","year":"2022","unstructured":"Jie Fu, Zhili Chen, and Xiao Han. 2022. Adap DP-FL: Differentially private federated learning with adaptive noise. In Proceedings of the 2022 IEEE International Conference on Trust, Security and Privacy in Computing and Communications. IEEE, 656\u2013663."},{"key":"e_1_3_3_56_2","doi-asserted-by":"crossref","unstructured":"Jie Fu Qingqing Ye Haibo Hu Zhili Chen Lulu Wang Kuncan Wang and Xun Ran. 2024. DPSUR: Accelerating differentially private stochastic gradient descent using selective update and release. Proceedings of the VLDB Endowment 17 6 (2024) 1200\u20131213.","DOI":"10.14778\/3648160.3648164"},{"key":"e_1_3_3_57_2","unstructured":"Robin C. Geyer Tassilo Klein and Moin Nabi. 2017. Differentially private federated learning: A client level perspective. arXiv:1712.07557. Retrieved from https:\/\/arxiv.org\/abs\/1712.07557"},{"key":"e_1_3_3_58_2","unstructured":"Badih Ghazi Noah Golowich Ravi Kumar Pasin Manurangsi and Chiyuan Zhang. 2021. Deep learning with label differential privacy. Advances in Neural Information Processing Systems 34 (2021) 27131\u201327145."},{"key":"e_1_3_3_59_2","first-page":"2521","volume-title":"Proceedings of the International Conference on Artificial Intelligence and Statistics","author":"Girgis Antonious","year":"2021","unstructured":"Antonious Girgis, Deepesh Data, Suhas Diggavi, Peter Kairouz, and Ananda Theertha Suresh. 2021. Shuffled model of differential privacy in federated learning. In Proceedings of the International Conference on Artificial Intelligence and Statistics. PMLR, 2521\u20132529."},{"key":"e_1_3_3_60_2","first-page":"338","volume-title":"Proceedings of the 2021 IEEE International Symposium on Information Theory","author":"Girgis Antonious M.","year":"2021","unstructured":"Antonious M. Girgis, Deepesh Data, and Suhas Diggavi. 2021. Differentially private federated learning with shuffling and client self-sampling. In Proceedings of the 2021 IEEE International Symposium on Information Theory. IEEE, 338\u2013343."},{"key":"e_1_3_3_61_2","doi-asserted-by":"crossref","unstructured":"Mehmet Emre Gursoy Acar Tamersoy Stacey Truex Wenqi Wei and Ling Liu. 2019. Secure and utility-aware data collection with condensed local differential privacy. IEEE Transactions on Dependable and Secure Computing 18 5 (2019) 2365\u20132378.","DOI":"10.1109\/TDSC.2019.2949041"},{"key":"e_1_3_3_62_2","unstructured":"Farzin Haddadpour and Mehrdad Mahdavi. 2019. On the convergence of local descent methods in federated learning. arXiv:1910.14425. Retrieved from https:\/\/arxiv.org\/abs\/1910.14425"},{"key":"e_1_3_3_63_2","doi-asserted-by":"crossref","unstructured":"Zaobo He Lintao Wang and Zhipeng Cai. 2024. Clustered federated learning with adaptive local differential privacy on heterogeneous IoT data. IEEE Internet of Things Journal 11 1 (2024) 137\u2013146.","DOI":"10.1109\/JIOT.2023.3299947"},{"key":"e_1_3_3_64_2","unstructured":"Geoffrey Hinton Oriol Vinyals and Jeff Dean. 2015. Distilling the knowledge in a neural network. arXiv:1503.02531. Retrieved from https:\/\/arxiv.org\/abs\/1503.02531"},{"key":"e_1_3_3_65_2","first-page":"100","volume-title":"Proceedings of the International Workshop on Trustworthy Federated Learning","author":"Hoech Haley","year":"2022","unstructured":"Haley Hoech, Roman Rischke, Karsten M\u00fcller, and Wojciech Samek. 2022. FedAUXfdp: Differentially private one-shot federated distillation. In Proceedings of the International Workshop on Trustworthy Federated Learning. Springer, 100\u2013114."},{"key":"e_1_3_3_66_2","doi-asserted-by":"crossref","unstructured":"Samuel Horv\u00e1th Dmitry Kovalev Konstantin Mishchenko Peter Richt\u00e1rik and Sebastian Stich. 2023. Stochastic distributed learning with gradient quantization and double-variance reduction. Optimization Methods and Software 38 1 (2023) 91\u2013106.","DOI":"10.1080\/10556788.2022.2117355"},{"key":"e_1_3_3_67_2","first-page":"2232","volume-title":"Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining","author":"Hu Yaochen","year":"2019","unstructured":"Yaochen Hu, Di Niu, Jianming Yang, and Shengping Zhou. 2019. FDML: A collaborative machine learning framework for distributed features. In Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. 2232\u20132240."},{"key":"e_1_3_3_68_2","doi-asserted-by":"crossref","unstructured":"Xixi Huang Ye Ding Zoe L. Jiang Shuhan Qi Xuan Wang and Qing Liao. 2020. DP-FL: A novel differentially private federated learning framework for the unbalanced data. World Wide Web 23 4 (2020) 2529\u20132545.","DOI":"10.1007\/s11280-020-00780-4"},{"key":"e_1_3_3_69_2","doi-asserted-by":"crossref","unstructured":"Zonghao Huang Rui Hu Yuanxiong Guo Eric Chan-Tin and Yanmin Gong. 2019. DP-ADMM: ADMM-based distributed learning with differential privacy. IEEE Transactions on Information Forensics and Security 15 (2019) 1002\u20131012.","DOI":"10.1109\/TIFS.2019.2931068"},{"key":"e_1_3_3_70_2","unstructured":"Jacob Imola and Kamalika Chaudhuri. 2021. Privacy amplification via bernoulli sampling. arXiv:2105.10594. Retrieved from https:\/\/arxiv.org\/abs\/2105.10594"},{"key":"e_1_3_3_71_2","doi-asserted-by":"crossref","unstructured":"Matthew Jagielski Milad Nasr Katherine Lee Christopher A. Choquette-Choo Nicholas Carlini and Florian Tramer. 2024. Students parrot their teachers: Membership inference on model distillation. Advances in Neural Information Processing Systems 36 (2024) 44382\u201344397.","DOI":"10.52202\/075280-1921"},{"key":"e_1_3_3_72_2","unstructured":"Matthew Jagielski Jonathan Ullman and Alina Oprea. 2020. Auditing differentially private machine learning: How private is private sgd? Advances in Neural Information Processing Systems 33 (2020) 22205\u201322216."},{"key":"e_1_3_3_73_2","doi-asserted-by":"crossref","unstructured":"Xue Jiang Xuebing Zhou and Jens Grossklags. 2022. Signds-fl: Local differentially private federated learning with sign-based dimension selection. ACM Transactions on Intelligent Systems and Technology 13 5 (2022) 1\u201322.","DOI":"10.1145\/3517820"},{"key":"e_1_3_3_74_2","first-page":"5201","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Kairouz Peter","year":"2021","unstructured":"Peter Kairouz, Ziyu Liu, and Thomas Steinke. 2021. The distributed discrete gaussian mechanism for federated learning with secure aggregation. In Proceedings of the International Conference on Machine Learning. PMLR, 5201\u20135212."},{"key":"e_1_3_3_75_2","doi-asserted-by":"crossref","unstructured":"Peter Kairouz H. Brendan McMahan Brendan Avent Aur\u00e9lien Bellet Mehdi Bennis Arjun Nitin Bhagoji Kallista Bonawitz Zachary Charles Graham Cormode Rachel Cummings et\u00a0al. 2021. Advances and open problems in federated learning. Foundations and trends\u00ae in Machine Learning 14 1\u20132 (2021) 1\u2013210.","DOI":"10.1561\/2200000083"},{"key":"e_1_3_3_76_2","first-page":"5132","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Karimireddy Sai Praneeth","year":"2020","unstructured":"Sai Praneeth Karimireddy, Satyen Kale, Mehryar Mohri, Sashank Reddi, Sebastian Stich, and Ananda Theertha Suresh. 2020. Scaffold: Stochastic controlled averaging for federated learning. In Proceedings of the International Conference on Machine Learning. PMLR, 5132\u20135143."},{"key":"e_1_3_3_77_2","doi-asserted-by":"crossref","unstructured":"Fumiyuki Kato Yang Cao and Masatoshi Yoshikawa. 2023. Olive: Oblivious federated learning on trusted execution environment against the risk of sparsification. Proceedings of the VLDB Endowment 16 10 (2023) 2404\u20132417.","DOI":"10.14778\/3603581.3603583"},{"key":"e_1_3_3_78_2","first-page":"2826","volume-title":"Proceedings of the VLDB Endowment. International Conference on Very Large Data Bases","author":"Kato Fumiyuki","year":"2024","unstructured":"Fumiyuki Kato, Li Xiong, Shun Takagi, Yang Cao, and Masatoshi Yoshikawa. 2024. ULDP-FL: Federated learning with across-silo user-level differential privacy. In Proceedings of the VLDB Endowment. International Conference on Very Large Data Bases. 2826."},{"key":"e_1_3_3_79_2","first-page":"304","volume-title":"Proceedings of the 2021 IEEE European Symposium on Security and Privacy.","author":"Kerkouche Raouf","year":"2021","unstructured":"Raouf Kerkouche, Gergely \u00c1cs, Claude Castelluccia, and Pierre Genev\u00e8s. 2021. Compression boosts differentially private federated learning. In Proceedings of the 2021 IEEE European Symposium on Security and Privacy.IEEE, 304\u2013318."},{"key":"e_1_3_3_80_2","unstructured":"Diederik P. Kingma and Jimmy Ba. 2015. Adam: A method for stochastic optimization. In International Conference on Learning Representations (ICLR\u201915)."},{"key":"e_1_3_3_81_2","doi-asserted-by":"crossref","unstructured":"Yehuda Koren Steffen Rendle and Robert M. Bell. 2021. Advances in collaborative filtering. In Recommender Systems Handbook. 91\u2013142.","DOI":"10.1007\/978-1-0716-2197-4_3"},{"key":"e_1_3_3_82_2","unstructured":"Daniel Levy Ziteng Sun Kareem Amin Satyen Kale Alex Kulesza Mehryar Mohri and Ananda Theertha Suresh. 2021. Learning with user-level privacy. Advances in Neural Information Processing Systems 34 (2021) 12466\u201312479."},{"key":"e_1_3_3_83_2","first-page":"32","volume-title":"Proceedings of the 7th ACM Symposium on Information, Computer and Communications Security","author":"Li Ninghui","year":"2012","unstructured":"Ninghui Li, Wahbeh Qardaji, and Dong Su. 2012. On sampling, anonymization, and differential privacy or, k-anonymization meets differential privacy. In Proceedings of the 7th ACM Symposium on Information, Computer and Communications Security. 32\u201333."},{"key":"e_1_3_3_84_2","unstructured":"Oscar Li Jiankai Sun Xin Yang Weihao Gao Hongyi Zhang Junyuan Xie Virginia Smith and Chong Wang. 2022. Label leakage and protection in two-party split learning. In International Conference on Learning Representations (ICLR\u201922)."},{"key":"e_1_3_3_85_2","doi-asserted-by":"crossref","unstructured":"Qinbin Li Zeyi Wen Zhaomin Wu Sixu Hu Naibo Wang Yuan Li Xu Liu and Bingsheng He. 2021. A survey on federated learning systems: Vision hype and reality for data privacy and protection. IEEE Transactions on Knowledge and Data Engineering 35 4 (2021) 3347\u20133366.","DOI":"10.1109\/TKDE.2021.3124599"},{"key":"e_1_3_3_86_2","doi-asserted-by":"crossref","unstructured":"Xiaochen Li Yuke Hu Weiran Liu Hanwen Feng Li Peng Yuan Hong Kui Ren and Zhan Qin. 2022. OpBoost: A vertical federated tree boosting framework based on order-preserving desensitization. In Proceedings of the VLDB Endowment 16 2 (2022) 202\u2013215.","DOI":"10.14778\/3565816.3565823"},{"key":"e_1_3_3_87_2","doi-asserted-by":"crossref","unstructured":"Yipeng Li and Xinchen Lyu. 2024. Convergence analysis of sequential federated learning on heterogeneous data. Advances in Neural Information Processing Systems 36 (2024) 56700\u201356755.","DOI":"10.52202\/075280-2477"},{"key":"e_1_3_3_88_2","unstructured":"Yige Li Xixiang Lyu Nodens Koren Lingjuan Lyu Bo Li and Xingjun Ma. 2021. Neural attention distillation: Erasing backdoor triggers from deep neural networks. In International Conference on Learning Representations (ICLR\u201921)."},{"key":"e_1_3_3_89_2","first-page":"380","volume-title":"Proceedings of the International Conference on Ubiquitous Security","author":"Li Yuting","year":"2022","unstructured":"Yuting Li, Guojun Wang, Tao Peng, and Guanghui Feng. 2022. FedTA: Locally-differential federated learning with Top-k mechanism and adam optimization. In Proceedings of the International Conference on Ubiquitous Security. Springer, 380\u2013391."},{"key":"e_1_3_3_90_2","doi-asserted-by":"crossref","unstructured":"Zhize Li Haoyu Zhao Boyue Li and Yuejie Chi. 2022. SoteriaFL: A unified framework for private federated learning with communication compression. Advances in Neural Information Processing Systems 35 (2022) 4285\u20134300.","DOI":"10.52202\/068431-0310"},{"key":"e_1_3_3_91_2","first-page":"2071","volume-title":"Proceedings of the IEEE International Conference on Communications","author":"Lian Zhuotao","year":"2022","unstructured":"Zhuotao Lian, Qinglin Yang, Qingkui Zeng, and Chunhua Su. 2022. Webfed: Cross-platform federated learning framework based on web browser with local differential privacy. In Proceedings of the IEEE International Conference on Communications. IEEE, 2071\u20132076."},{"key":"e_1_3_3_92_2","doi-asserted-by":"crossref","unstructured":"Tianchi Liao Lele Fu Lei Zhang Lei Yang Chuan Chen Michael K. Ng Huawei Huang and Zibin Zheng. 2025. Privacy-preserving vertical federated learning with tensor decomposition for data missing features. IEEE Transactions on Information Forensics and Security 20 (2025) 3445\u20133460.","DOI":"10.1109\/TIFS.2025.3552033"},{"key":"e_1_3_3_93_2","unstructured":"Seng Pei Liew Satoshi Hasegawa and Tsubasa Takahashi. 2022. Shuffled check-in: Privacy amplification towards practical distributed learning. arXiv:2206.03151. Retrieved from https:\/\/arxiv.org\/abs\/2206.03151"},{"key":"e_1_3_3_94_2","doi-asserted-by":"crossref","unstructured":"Wanyu Lin Baochun Li and Cong Wang. 2022. Towards private learning on decentralized graphs with local differential privacy. IEEE Transactions on Information Forensics and Security 17 (2022) 2936\u20132946.","DOI":"10.1109\/TIFS.2022.3198283"},{"key":"e_1_3_3_95_2","first-page":"349","volume-title":"Proceedings of the 2024 IEEE 25th International Symposium on a World of Wireless, Mobile and Multimedia Networks","author":"Ling Xinpeng","year":"2024","unstructured":"Xinpeng Ling, Jie Fu, Kuncan Wang, Haitao Liu, and Zhili Chen. 2024. ALI-DPFL: Differentially private federated learning with adaptive local iterations. In Proceedings of the 2024 IEEE 25th International Symposium on a World of Wireless, Mobile and Multimedia Networks. IEEE, 349\u2013358."},{"key":"e_1_3_3_96_2","unstructured":"Hongbin Liu Lun Wang Om Thakkar Abhradeep Thakurta and Arun Narayanan. 2024. Differentially private parameter-efficient fine-tuning for large asr models. arXiv:2410.01948. Retrieved from https:\/\/arxiv.org\/abs\/2410.01948"},{"key":"e_1_3_3_97_2","doi-asserted-by":"crossref","unstructured":"Junxu Liu Jian Lou Li Xiong Jinfei Liu and Xiaofeng Meng. 2021. Projected federated averaging with heterogeneous differential privacy. Proceedings of the VLDB Endowment 15 4 (2021) 828\u2013840.","DOI":"10.14778\/3503585.3503592"},{"key":"e_1_3_3_98_2","first-page":"303","volume-title":"Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security","author":"Liu Junxu","year":"2024","unstructured":"Junxu Liu, Jian Lou, Li Xiong, Jinfei Liu, and Xiaofeng Meng. 2024. Cross-silo federated learning with record-level personalized differential privacy. In Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security. 303\u2013317."},{"key":"e_1_3_3_99_2","first-page":"8688","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence","author":"Liu Ruixuan","year":"2021","unstructured":"Ruixuan Liu, Yang Cao, Hong Chen, Ruoyang Guo, and Masatoshi Yoshikawa. 2021. Flame: Differentially private federated learning in the shuffle model. In Proceedings of the AAAI Conference on Artificial Intelligence. 8688\u20138696."},{"key":"e_1_3_3_100_2","first-page":"485","volume-title":"Database Systems for Advanced Applications: 25th International Conference, DASFAA 2020, Jeju, South Korea, September 24\u201327, 2020, Proceedings, Part I 25","author":"Liu Ruixuan","year":"2020","unstructured":"Ruixuan Liu, Yang Cao, Masatoshi Yoshikawa, and Hong Chen. 2020. Fedsel: Federated sgd under local differential privacy with top-k dimension selection. In Database Systems for Advanced Applications: 25th International Conference, DASFAA 2020, Jeju, South Korea, September 24\u201327, 2020, Proceedings, Part I 25. Springer, 485\u2013501."},{"key":"e_1_3_3_101_2","unstructured":"Shang Liu Yang Cao Takao Murakami Weiran Liu Seng Pei Liew Tsubasa Takahashi Jinfei Liu and Masatoshi Yoshikawa. 2024. Federated graph analytics with differential privacy. arXiv:2405.20576. Retrieved from https:\/\/arxiv.org\/abs\/2405.20576"},{"key":"e_1_3_3_102_2","doi-asserted-by":"crossref","unstructured":"Xiao-Yang Liu Rongyi Zhu Daochen Zha Jiechao Gao Shan Zhong Matt White and Meikang Qiu. 2025. Differentially private low-rank adaptation of large language model using federated learning. ACM Transactions on Management Information Systems 16 2 (2025) 1\u201324.","DOI":"10.1145\/3682068"},{"key":"e_1_3_3_103_2","doi-asserted-by":"crossref","unstructured":"Yi Liu J. Q. James Jiawen Kang Dusit Niyato and Shuyu Zhang. 2020. Privacy-preserving traffic flow prediction: A federated learning approach. IEEE Internet of Things Journal 7 8 (2020) 7751\u20137763.","DOI":"10.1109\/JIOT.2020.2991401"},{"key":"e_1_3_3_104_2","doi-asserted-by":"crossref","unstructured":"Yang Liu Yan Kang Chaoping Xing Tianjian Chen and Qiang Yang. 2020. A secure federated transfer learning framework. IEEE Intelligent Systems 35 4 (2020) 70\u201382.","DOI":"10.1109\/MIS.2020.2988525"},{"key":"e_1_3_3_105_2","unstructured":"Yuhan Liu Ananda Theertha Suresh Felix Xinnan X Yu Sanjiv Kumar and Michael Riley. 2020. Learning discrete distributions: User vs item-level privacy. Advances in Neural Information Processing Systems 33 (2020) 20965\u201320976."},{"key":"e_1_3_3_106_2","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence","author":"Liu Yixuan","year":"2023","unstructured":"Yixuan Liu, Suyun Zhao, Li Xiong, Yuhan Liu, and Hong Chen. 2023. Echo of Neighbors: Privacy amplification for personalized private federated learning with shuffle model. In Proceedings of the AAAI Conference on Artificial Intelligence."},{"key":"e_1_3_3_107_2","doi-asserted-by":"crossref","unstructured":"Yunlong Lu Xiaohong Huang Yueyue Dai Sabita Maharjan and Yan Zhang. 2019. Differentially private asynchronous federated learning for mobile edge computing in urban informatics. IEEE Transactions on Industrial Informatics 16 3 (2019) 2134\u20132143.","DOI":"10.1109\/TII.2019.2942179"},{"key":"e_1_3_3_108_2","doi-asserted-by":"crossref","unstructured":"Alexander Selvikvag Lundervold and Arvid Lundervold. 2019. An overview of deep learning in medical imaging focusing on MRI. Zeitschrift f\u00fcr Medizinische Physik 29 2 (2019) 102\u2013127.","DOI":"10.1016\/j.zemedi.2018.11.002"},{"key":"e_1_3_3_109_2","first-page":"195","volume-title":"Proceedings of the European Symposium on Research in Computer Security","author":"Arachchige Pathum Chamikara Mahawaga","year":"2022","unstructured":"Pathum Chamikara Mahawaga Arachchige, Dongxi Liu, Seyit Camtepe, Surya Nepal, Marthie Grobler, Peter Bertok, and Ibrahim Khalil. 2022. Local differential privacy for federated learning. In Proceedings of the European Symposium on Research in Computer Security. Springer, 195\u2013216."},{"key":"e_1_3_3_110_2","first-page":"34461","volume-title":"Proceedings of the 41st International Conference on Machine Learning","author":"Malekmohammadi Saber","year":"2024","unstructured":"Saber Malekmohammadi, Yaoliang Yu, and Yang Cao. 2024. Noise-aware algorithm for heterogeneous differentially private federated learning. In Proceedings of the 41st International Conference on Machine Learning. 34461\u201334498."},{"key":"e_1_3_3_111_2","unstructured":"Mohammad Malekzadeh Burak Hasircioglu Nitish Mital Kunal Katarya Mehmet Emre Ozfatura and Deniz G\u00fcnd\u00fcz. 2021. Dopamine: Differentially private federated learning on medical data. arXiv:2101.11693. Retrieved from https:\/\/arxiv.org\/abs\/2101.11693"},{"key":"e_1_3_3_112_2","unstructured":"Yunlong Mao Zexi Xin Zhenyu Li Jue Hong Yang Qingyou and Sheng Zhong. 2022. Secure split learning against property inference and data reconstruction attacks. OpenReview\/NeurIPS 2022 Submission."},{"key":"e_1_3_3_113_2","unstructured":"K. J. Mathews and C. M. Bowman. 2018. The california consumer privacy act of 2018. California Assembly Bill 375 (20172018 Reg. Sess.)."},{"key":"e_1_3_3_114_2","first-page":"1273","volume-title":"Proceedings of the Artificial Intelligence and Statistics","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Proceedings of the Artificial Intelligence and Statistics. PMLR, 1273\u20131282."},{"key":"e_1_3_3_115_2","unstructured":"H. Brendan McMahan Daniel Ramage Kunal Talwar and Li Zhang. 2018. Learning differentially private recurrent language models. In International Conference on Learning Representations (ICLR\u201918)."},{"key":"e_1_3_3_116_2","first-page":"94","volume-title":"Proceedings of the 48th Annual IEEE Symposium on Foundations of Computer Science","author":"McSherry Frank","year":"2007","unstructured":"Frank McSherry and Kunal Talwar. 2007. Mechanism design via differential privacy. In Proceedings of the 48th Annual IEEE Symposium on Foundations of Computer Science. IEEE, 94\u2013103."},{"key":"e_1_3_3_117_2","doi-asserted-by":"crossref","first-page":"691","DOI":"10.1109\/SP.2019.00029","volume-title":"Proceedings of the 2019 IEEE Symposium on Security and Privacy","author":"Melis Luca","year":"2019","unstructured":"Luca Melis, Congzheng Song, Emiliano De Cristofaro, and Vitaly Shmatikov. 2019. Exploiting unintended feature leakage in collaborative learning. In Proceedings of the 2019 IEEE Symposium on Security and Privacy. IEEE, 691\u2013706."},{"key":"e_1_3_3_118_2","first-page":"342","volume-title":"Proceedings of the 15th ACM Conference on Recommender Systems","author":"Minto Lorenzo","year":"2021","unstructured":"Lorenzo Minto, Moritz Haller, Benjamin Livshits, and Hamed Haddadi. 2021. Stronger privacy for federated collaborative filtering with implicit feedback. In Proceedings of the 15th ACM Conference on Recommender Systems. 342\u2013350."},{"key":"e_1_3_3_119_2","doi-asserted-by":"crossref","first-page":"263","DOI":"10.1109\/CSF.2017.11","volume-title":"Proceedings of the 2017 IEEE 30th Computer Security Foundations Symposium","author":"Mironov Ilya","year":"2017","unstructured":"Ilya Mironov. 2017. R\u00e9nyi differential privacy. In Proceedings of the 2017 IEEE 30th Computer Security Foundations Symposium. IEEE, 263\u2013275."},{"key":"e_1_3_3_120_2","doi-asserted-by":"crossref","first-page":"19","DOI":"10.1109\/SP.2017.12","volume-title":"Proceedings of the 2017 IEEE Symposium on Security and Privacy","author":"Mohassel Payman","year":"2017","unstructured":"Payman Mohassel and Yupeng Zhang. 2017. Secureml: A system for scalable privacy-preserving machine learning. In Proceedings of the 2017 IEEE Symposium on Security and Privacy. IEEE, 19\u201338."},{"key":"e_1_3_3_121_2","doi-asserted-by":"crossref","unstructured":"Mohammad Naseri Jamie Hayes and Emiliano De Cristofaro. 2022. Local and central differential privacy for robustness and privacy in federated learning. Network and Distributed System Security Symposium (NDSS\u201922).","DOI":"10.14722\/ndss.2022.23054"},{"key":"e_1_3_3_122_2","first-page":"1631","volume-title":"Proceedings of the 32nd USENIX Security Symposium","author":"Nasr Milad","year":"2023","unstructured":"Milad Nasr, Jamie Hayes, Thomas Steinke, Borja Balle, Florian Tram\u00e8r, Matthew Jagielski, Nicholas Carlini, and Andreas Terzis. 2023. Tight auditing of differentially private machine learning. In Proceedings of the 32nd USENIX Security Symposium. 1631\u20131648."},{"key":"e_1_3_3_123_2","doi-asserted-by":"crossref","first-page":"739","DOI":"10.1109\/SP.2019.00065","volume-title":"Proceedings of the 2019 IEEE Symposium on Security and Privacy","author":"Nasr Milad","year":"2019","unstructured":"Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019. Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In Proceedings of the 2019 IEEE Symposium on Security and Privacy. IEEE, 739\u2013753."},{"key":"e_1_3_3_124_2","unstructured":"Th\u00f4ng T. Nguy\u00ean Xiaokui Xiao Yin Yang Siu Cheung Hui Hyejin Shin and Junbum Shin. 2016. Collecting and analyzing data from smart device users with local differential privacy. arXiv:1606.05053. Retrieved from https:\/\/arxiv.org\/abs\/1606.05053"},{"key":"e_1_3_3_125_2","first-page":"10110","volume-title":"Proceedings of the International Conference on Artificial Intelligence and Statistics","author":"Noble Maxence","year":"2022","unstructured":"Maxence Noble, Aur\u00e9lien Bellet, and Aymeric Dieuleveut. 2022. Differentially private federated learning on heterogeneous data. In Proceedings of the International Conference on Artificial Intelligence and Statistics. PMLR, 10110\u201310145."},{"key":"e_1_3_3_126_2","unstructured":"Seungeun Oh Jihong Park Sihun Baek Hyelin Nam Praneeth Vepakomma Ramesh Raskar Mehdi Bennis and Seong-Lyun Kim. 2022. Differentially private cutmix for split learning with vision transformer. arXiv:2210.15986. Retrieved from https:\/\/arxiv.org\/abs\/2210.15986"},{"key":"e_1_3_3_127_2","first-page":"1626","volume-title":"Proceedings of the 2025 International Wireless Communications and Mobile Computing","author":"Pan Qianqian","year":"2025","unstructured":"Qianqian Pan and Jun Wu. 2025. Selective privacy-preserving federated learning for large language model fine-tuning. In Proceedings of the 2025 International Wireless Communications and Mobile Computing. IEEE, 1626\u20131631."},{"key":"e_1_3_3_128_2","doi-asserted-by":"crossref","unstructured":"Qianqian Pan Jun Wu Ali Kashif Bashir Jianhua Li Wu Yang and Yasser D. Al-Otaibi. 2021. Joint protection of energy security and information privacy for energy harvesting: An incentive federated learning approach. IEEE Transactions on Industrial Informatics 18 5 (2021) 3473\u20133483.","DOI":"10.1109\/TII.2021.3105492"},{"key":"e_1_3_3_129_2","doi-asserted-by":"crossref","unstructured":"Sinno Jialin Pan Ivor W. Tsang James T. Kwok and Qiang Yang. 2010. Domain adaptation via transfer component analysis. IEEE Transactions on Neural Networks 22 2 (2010) 199\u2013210.","DOI":"10.1109\/TNN.2010.2091281"},{"key":"e_1_3_3_130_2","first-page":"1","volume-title":"Proceedings of the 2021 IEEE Global Communications Conference","author":"Pan Yanghe","year":"2021","unstructured":"Yanghe Pan, Jianbing Ni, and Zhou Su. 2021. Fl-pate: Differentially private federated learning with knowledge transfer. In Proceedings of the 2021 IEEE Global Communications Conference. IEEE, 1\u20136."},{"key":"e_1_3_3_131_2","unstructured":"Nicolas Papernot Mart\u0131n Abadi Ulfar Erlingsson Ian Goodfellow and Kunal Talwar. 2017. Semi-supervised knowledge transfer for deep learning from private training data. stat 1050 (2017) 3."},{"key":"e_1_3_3_132_2","volume-title":"Proceedings of the International Conference on Learning Representations","author":"Papernot Nicolas","year":"2018","unstructured":"Nicolas Papernot, Shuang Song, Ilya Mironov, Ananth Raghunathan, Kunal Talwar, and Ulfar Erlingsson. 2018. Scalable private learning with pate. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_3_133_2","doi-asserted-by":"crossref","first-page":"2113","DOI":"10.1145\/3460120.3485259","volume-title":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","author":"Pasquini Dario","year":"2021","unstructured":"Dario Pasquini, Giuseppe Ateniese, and Massimo Bernaschi. 2021. Unleashing the tiger: Inference attacks on split learning. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. 2113\u20132129."},{"key":"e_1_3_3_134_2","doi-asserted-by":"crossref","unstructured":"Sudipta Paul and Subhankar Mishra. 2020. ARA: Aggregated RAPPOR and analysis for centralized differential privacy. SN Computer Science 1 1 (2020) 22.","DOI":"10.1007\/s42979-019-0023-y"},{"key":"e_1_3_3_135_2","doi-asserted-by":"crossref","unstructured":"Victor Perrier Hassan Jameel Asghar and Dali Kaafar. 2019. Private continual release of real-valued data streams. Network and Distributed System Security Symposium (NDSS\u201919).","DOI":"10.14722\/ndss.2019.23535"},{"key":"e_1_3_3_136_2","doi-asserted-by":"crossref","unstructured":"Tao Qi Fangzhao Wu Chuhan Wu Liang He Yongfeng Huang and Xing Xie. 2023. Differentially private knowledge transfer for federated learning. Nature Communications 14 1 (2023) 3785.","DOI":"10.1038\/s41467-023-38794-x"},{"key":"e_1_3_3_137_2","doi-asserted-by":"crossref","unstructured":"Oded Regev. 2009. On lattices learning with errors random linear codes and cryptography. Journal of the ACM 56 6 (2009) 1\u201340.","DOI":"10.1145\/1568318.1568324"},{"key":"e_1_3_3_138_2","doi-asserted-by":"crossref","unstructured":"Xuebin Ren Shusen Yang Cong Zhao Julie McCann and Zongben Xu. 2024. Belt and braces: When federated learning meets differential privacy. Communications of the ACM 67 12 (2024) 66\u201377.","DOI":"10.1145\/3650028"},{"key":"e_1_3_3_139_2","doi-asserted-by":"crossref","first-page":"603","DOI":"10.1145\/3318464.3380596","volume-title":"Proceedings of the 2020 ACM SIGMOD International Conference on Management of Data","author":"Chowdhury Amrita Roy","year":"2020","unstructured":"Amrita Roy Chowdhury, Chenghong Wang, Xi He, Ashwin Machanavajjhala, and Somesh Jha. 2020. Crypt \\(\\epsilon\\) : Crypto-assisted differential privacy on untrusted servers. In Proceedings of the 2020 ACM SIGMOD International Conference on Management of Data. 603\u2013619."},{"key":"e_1_3_3_140_2","doi-asserted-by":"crossref","first-page":"1926","DOI":"10.1109\/SP46215.2023.10179422","volume-title":"Proceedings of the 2023 IEEE Symposium on Security and Privacy","author":"Ruan Wenqiang","year":"2023","unstructured":"Wenqiang Ruan, Mingxin Xu, Wenjing Fang, Li Wang, Lei Wang, and Weili Han. 2023. Private, efficient, and accurate: Protecting models trained by multi-party learning with differential privacy. In Proceedings of the 2023 IEEE Symposium on Security and Privacy. IEEE, 1926\u20131943."},{"key":"e_1_3_3_141_2","unstructured":"Minseok Ryu and Kibaek Kim. 2022. Differentially private federated learning via inexact ADMM with multiple local updates. arXiv:2202.09409. Retrieved from https:\/\/arxiv.org\/abs\/2202.09409"},{"key":"e_1_3_3_142_2","first-page":"3223","volume-title":"Proceedings of the 32nd USENIX Security Symposium","author":"Sajadmanesh Sina","year":"2023","unstructured":"Sina Sajadmanesh, Ali Shahin Shamsabadi, Aur\u00e9lien Bellet, and Daniel Gatica-Perez. 2023. GAP: Differentially private graph neural networks with aggregation perturbation. In Proceedings of the 32nd USENIX Security Symposium. 3223\u20133240."},{"key":"e_1_3_3_143_2","doi-asserted-by":"crossref","first-page":"327","DOI":"10.1109\/SP46215.2023.10179281","volume-title":"Proceedings of the 2023 IEEE Symposium on Security and Privacy","author":"Salem Ahmed","year":"2023","unstructured":"Ahmed Salem, Giovanni Cherubin, David Evans, Boris K\u00f6pf, Andrew Paverd, Anshuman Suri, Shruti Tople, and Santiago Zanella-B\u00e9guelin. 2023. SoK: Let the privacy games begin! A unified treatment of data inference privacy in machine learning. In Proceedings of the 2023 IEEE Symposium on Security and Privacy. IEEE, 327\u2013345."},{"key":"e_1_3_3_144_2","volume-title":"Proceedings of the Network and Distributed Systems Security Symposium 2019","author":"Salem Ahmed","year":"2019","unstructured":"Ahmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang, Mario Fritz, and Michael Backes. 2019. ML-Leaks: Model and data independent membership inference attacks and defenses on machine learning models. In Proceedings of the Network and Distributed Systems Security Symposium 2019."},{"key":"e_1_3_3_145_2","first-page":"24552","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Shi Yifan","year":"2023","unstructured":"Yifan Shi, Yingqi Liu, Kang Wei, Li Shen, Xueqian Wang, and Dacheng Tao. 2023. Make landscape flatter in differentially private federated learning. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 24552\u201324562."},{"key":"e_1_3_3_146_2","doi-asserted-by":"crossref","unstructured":"Hyejin Shin Sungwook Kim Junbum Shin and Xiaokui Xiao. 2018. Privacy enhanced matrix factorization for recommendation with local differential privacy. IEEE Transactions on Knowledge and Data Engineering 30 9 (2018) 1770\u20131782.","DOI":"10.1109\/TKDE.2018.2805356"},{"key":"e_1_3_3_147_2","doi-asserted-by":"crossref","unstructured":"John G. Skellam. 1946. The frequency distribution of the difference between two Poisson variates belonging to different populations. Journal of the Royal Statistical Society Series A: Statistics in Society 109 3 (1946) 296\u2013296.","DOI":"10.2307\/2981372"},{"key":"e_1_3_3_148_2","doi-asserted-by":"crossref","unstructured":"Congzheng Song Thomas Ristenpart and Vitaly Shmatikov. 2017. Machine learning models that remember too much. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (CCS\u201917). 587\u2013601.","DOI":"10.1145\/3133956.3134077"},{"key":"e_1_3_3_149_2","first-page":"1379","volume-title":"Proceedings of the 31st USENIX Security Symposium","author":"Stevens Timothy","year":"2022","unstructured":"Timothy Stevens, Christian Skalka, Christelle Vincent, John Ring, Samuel Clark, and Joseph Near. 2022. Efficient differentially private secure aggregation for federated learning via hardness of learning with errors. In Proceedings of the 31st USENIX Security Symposium. 1379\u20131395."},{"key":"e_1_3_3_150_2","unstructured":"Pierre Stock Igor Shilov Ilya Mironov and Alexandre Sablayrolles. 2022. Defending against reconstruction attacks with r\u00e9nyi differential privacy. arXiv preprint arXiv:2202.07623 (2022)."},{"key":"e_1_3_3_151_2","doi-asserted-by":"crossref","unstructured":"Lichao Sun and Lingjuan Lyu. 2021. Federated model distillation with noise-free differential privacy. In Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence (IJCAI\u201921). 1563\u20131570.","DOI":"10.24963\/ijcai.2021\/216"},{"key":"e_1_3_3_152_2","volume-title":"Proceedings of the 30th International Joint Conference on Artificial Intelligence","author":"Sun Lichao","year":"2021","unstructured":"Lichao Sun, Jianwei Qian, and Xun Chen. 2021. LDP-FL: Practical private aggregation in federated learning with local differential privacy. In Proceedings of the 30th International Joint Conference on Artificial Intelligence. International Joint Conferences on Artificial Intelligence Organization."},{"key":"e_1_3_3_153_2","first-page":"3329","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Suresh Ananda Theertha","year":"2017","unstructured":"Ananda Theertha Suresh, X. Yu Felix, Sanjiv Kumar, and H. Brendan McMahan. 2017. Distributed mean estimation with limited communication. In Proceedings of the International Conference on Machine Learning. PMLR, 3329\u20133337."},{"key":"e_1_3_3_154_2","unstructured":"Hideaki Takahashi Jingjing Liu and Yang Liu. 2023. Eliminating label leakage in tree-based vertical federated learning. arXiv:2307.10318. Retrieved from https:\/\/arxiv.org\/abs\/2307.10318"},{"key":"e_1_3_3_155_2","doi-asserted-by":"crossref","unstructured":"Youming Tao Shuzhen Chen Congwei Zhang Di Wang Dongxiao Yu Xiuzhen Cheng and Falko Dressler. 2024. Private over-the-air federated learning at band-limited edge. IEEE Transactions on Mobile Computing 23 12 (2024) 12444\u201312460.","DOI":"10.1109\/TMC.2024.3411295"},{"key":"e_1_3_3_156_2","doi-asserted-by":"crossref","unstructured":"Zhihua Tian Rui Zhang Xiaoyang Hou Lingjuan Lyu Tianyi Zhang Jian Liu and Kui Ren. 2024. FederBoost: Private federated learning for GBDT. IEEE Transactions on Dependable and Secure Computing 21 3 (2024) 1274\u20131285.","DOI":"10.1109\/TDSC.2023.3276365"},{"key":"e_1_3_3_157_2","doi-asserted-by":"crossref","unstructured":"Zhiliang Tian Yingxiu Zhao Ziyue Huang Yu-Xiang Wang Nevin L. Zhang and He He. 2022. Seqpate: Differentially private text generation via knowledge distillation. Advances in Neural Information Processing Systems 35 (2022) 11117\u201311130.","DOI":"10.52202\/068431-0808"},{"key":"e_1_3_3_158_2","first-page":"2587","volume-title":"Proceedings of the 2019 IEEE International Conference on Big Data.","author":"Triastcyn Aleksei","year":"2019","unstructured":"Aleksei Triastcyn and Boi Faltings. 2019. Federated learning with bayesian differential privacy. In Proceedings of the 2019 IEEE International Conference on Big Data.IEEE, 2587\u20132596."},{"key":"e_1_3_3_159_2","first-page":"9583","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Triastcyn Aleksei","year":"2020","unstructured":"Aleksei Triastcyn and Boi Faltings. 2020. Bayesian differential privacy for machine learning. In Proceedings of the International Conference on Machine Learning. PMLR, 9583\u20139592."},{"key":"e_1_3_3_160_2","doi-asserted-by":"crossref","first-page":"61","DOI":"10.1145\/3378679.3394533","volume-title":"Proceedings of the 3rd ACM International Workshop on Edge Systems, Analytics and Networking","author":"Truex Stacey","year":"2020","unstructured":"Stacey Truex, Ling Liu, Ka-Ho Chow, Mehmet Emre Gursoy, and Wenqi Wei. 2020. LDP-Fed: Federated learning with local differential privacy. In Proceedings of the 3rd ACM International Workshop on Edge Systems, Analytics and Networking. 61\u201366."},{"key":"e_1_3_3_161_2","doi-asserted-by":"crossref","unstructured":"Tim Van Erven and Peter Harremos. 2014. R\u00e9nyi divergence and Kullback-Leibler divergence. IEEE Transactions on Information Theory 60 7 (2014) 3797\u20133820.","DOI":"10.1109\/TIT.2014.2320500"},{"key":"e_1_3_3_162_2","volume-title":"Proceedings of the 14th ACM Conference on Data and Application Security and Privacy","author":"Varun Matta","year":"2024","unstructured":"Matta Varun, Shuya Feng, Han Wang, Shamik Sural, and Yuan Hong. 2024. Towards accurate and stronger local differential privacy for federated learning with staircase randomized response. In Proceedings of the 14th ACM Conference on Data and Application Security and Privacy. ACM."},{"key":"e_1_3_3_163_2","doi-asserted-by":"crossref","unstructured":"Sheng Wan Dashan Gao Hanlin Gu and Daning Hu. 2023. FedPDD: A privacy-preserving double distillation framework for cross-silo federated recommendation. In International Joint Conference on Neural Networks (IJCNN\u201923). 1\u20138.","DOI":"10.1109\/IJCNN54540.2023.10191850"},{"key":"e_1_3_3_164_2","doi-asserted-by":"crossref","unstructured":"Baocang Wang Yange Chen Hang Jiang and Zhen Zhao. 2023. PPeFL: Privacy-preserving edge federated learning with local differential privacy. IEEE Internet of Things Journal 10 17 (2023).","DOI":"10.1109\/JIOT.2023.3264259"},{"key":"e_1_3_3_165_2","doi-asserted-by":"crossref","unstructured":"Boxin Wang Yibo Zhang Yuan Cao Bo Li Hugh McMahan Sewoong Oh Zheng Xu and Manzil Zaheer. 2024. Can public large language models help private cross-device federated learning? Findings of the Association for Computational Linguistics: NAACL-HLT 2024. 934\u2013949.","DOI":"10.18653\/v1\/2024.findings-naacl.59"},{"key":"e_1_3_3_166_2","unstructured":"Chang Wang Jian Liang Mingkai Huang Bing Bai Kun Bai and Hao Li. 2020. Hybrid differentially private federated learning on vertically partitioned data. arXiv:2009.02763. Retrieved from https:\/\/arxiv.org\/abs\/2009.02763"},{"key":"e_1_3_3_167_2","doi-asserted-by":"crossref","unstructured":"Chen Wang Xinkui Wu Gaoyang Liu Tianping Deng Kai Peng and Shaohua Wan. 2022. Safeguarding cross-silo federated learning with local differential privacy. Digital Communications and Networks 8 4 (2022) 446\u2013454.","DOI":"10.1016\/j.dcan.2021.11.006"},{"key":"e_1_3_3_168_2","unstructured":"Di Wang Lijie Hu Huanyu Zhang Marco Gaboardi and Jinhui Xu. 2023. Generalized linear models in non-interactive local differential privacy with public data. Journal of Machine Learning Research 24 132 (2023) 1\u201357."},{"key":"e_1_3_3_169_2","first-page":"6628","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Wang Di","year":"2019","unstructured":"Di Wang and Jinhui Xu. 2019. On sparse linear regression in the local differential privacy model. In Proceedings of the International Conference on Machine Learning. PMLR, 6628\u20136637."},{"key":"e_1_3_3_170_2","doi-asserted-by":"crossref","first-page":"2809","DOI":"10.1145\/3548606.3560636","volume-title":"Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security","author":"Wang Han","year":"2022","unstructured":"Han Wang, Hanbin Hong, Li Xiong, Zhan Qin, and Yuan Hong. 2022. L-srr: Local differential privacy for location-based services with staircase randomized response. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security. 2809\u20132823."},{"key":"e_1_3_3_171_2","unstructured":"Lun Wang Ruoxi Jia and Dawn Song. 2020. D2P-Fed: Differentially private federated learning with efficient communication. arXiv:2006.13039. Retrieved from https:\/\/arxiv.org\/abs\/2006.13039"},{"key":"e_1_3_3_172_2","first-page":"638","volume-title":"Proceedings of the 2019 IEEE 35th International Conference on Data Engineering","author":"Wang Ning","year":"2019","unstructured":"Ning Wang, Xiaokui Xiao, Yin Yang, Jun Zhao, Siu Cheung Hui, Hyejin Shin, Junbum Shin, and Ge Yu. 2019. Collecting and analyzing multidimensional data with local differential privacy. In Proceedings of the 2019 IEEE 35th International Conference on Data Engineering. IEEE, 638\u2013649."},{"key":"e_1_3_3_173_2","first-page":"729","volume-title":"Proceedings of the 26th USENIX Security Symposium","author":"Wang Tianhao","year":"2017","unstructured":"Tianhao Wang, Jeremiah Blocki, Ninghui Li, and Somesh Jha. 2017. Locally differentially private protocols for frequency estimation. In Proceedings of the 26th USENIX Security Symposium. 729\u2013745."},{"key":"e_1_3_3_174_2","doi-asserted-by":"crossref","first-page":"1237","DOI":"10.1145\/3460120.3484750","volume-title":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","author":"Wang Tianhao","year":"2021","unstructured":"Tianhao Wang, Joann Qiongna Chen, Zhikun Zhang, Dong Su, Yueqiang Cheng, Zhou Li, Ninghui Li, and Somesh Jha. 2021. Continuous release of data streams under both centralized and local differential privacy. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. 1237\u20131253."},{"key":"e_1_3_3_175_2","first-page":"6283","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence","author":"Wang Yansheng","year":"2020","unstructured":"Yansheng Wang, Yongxin Tong, and Dingyuan Shi. 2020. Federated latent dirichlet allocation: A local differential privacy based framework. In Proceedings of the AAAI Conference on Artificial Intelligence. 6283\u20136290."},{"key":"e_1_3_3_176_2","doi-asserted-by":"crossref","first-page":"2512","DOI":"10.1109\/INFOCOM.2019.8737416","volume-title":"Proceedings of the IEEE INFOCOM 2019-IEEE Conference on Computer Communications","author":"Wang Zhibo","year":"2019","unstructured":"Zhibo Wang, Mengkai Song, Zhifei Zhang, Yang Song, Qian Wang, and Hairong Qi. 2019. Beyond inferring class representatives: User-level privacy leakage from federated learning. In Proceedings of the IEEE INFOCOM 2019-IEEE Conference on Computer Communications. IEEE, 2512\u20132520."},{"key":"e_1_3_3_177_2","doi-asserted-by":"crossref","unstructured":"Stanley L. Warner. 1965. Randomized response: A survey technique for eliminating evasive answer bias. Journal of the American Statistical Association 60 309 (1965) 63\u201369.","DOI":"10.1080\/01621459.1965.10480775"},{"key":"e_1_3_3_178_2","first-page":"2885","volume-title":"Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security","author":"Wei Jianxin","year":"2022","unstructured":"Jianxin Wei, Ergute Bao, Xiaokui Xiao, and Yin Yang. 2022. Dpis: An enhanced mechanism for differentially private sgd with importance sampling. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security. 2885\u20132899."},{"key":"e_1_3_3_179_2","doi-asserted-by":"crossref","unstructured":"Kang Wei Jun Li Ming Ding Chuan Ma Hang Su Bo Zhang and H. Vincent Poor. 2021. User-level privacy-preserving federated learning: Analysis and performance optimization. IEEE Transactions on Mobile Computing 21 9 (2021) 3388\u20133401.","DOI":"10.1109\/TMC.2021.3056991"},{"key":"e_1_3_3_180_2","doi-asserted-by":"crossref","unstructured":"Kang Wei Jun Li Ming Ding Chuan Ma Howard H. Yang Farhad Farokhi Shi Jin Tony Q. S. Quek and H. Vincent Poor. 2020. Federated learning with differential privacy: Algorithms and performance analysis. IEEE Transactions on Information Forensics and Security 15 (2020) 3454\u20133469.","DOI":"10.1109\/TIFS.2020.2988575"},{"key":"e_1_3_3_181_2","unstructured":"Chuhan Wu Fangzhao Wu Yang Cao Yongfeng Huang and Xing Xie. 2021. Fedgnn: Federated graph neural network for privacy-preserving recommendation. arXiv:2102.04925. Retrieved from https:\/\/arxiv.org\/abs\/2102.04925"},{"key":"e_1_3_3_182_2","first-page":"2005","volume-title":"Proceedings of the 2022 IEEE Symposium on Security and Privacy","author":"Wu Fan","year":"2022","unstructured":"Fan Wu, Yunhui Long, Ce Zhang, and Bo Li. 2022. Linkteller: Recovering private edges from graph neural networks via influence analysis. In Proceedings of the 2022 IEEE Symposium on Security and Privacy. IEEE, 2005\u20132024."},{"key":"e_1_3_3_183_2","doi-asserted-by":"crossref","unstructured":"Maoqiang Wu Dongdong Ye Jiahao Ding Yuanxiong Guo Rong Yu and Miao Pan. 2021. Incentivizing differentially private federated learning: A multidimensional contract approach. IEEE Internet of Things Journal 8 13 (2021) 10639\u201310651.","DOI":"10.1109\/JIOT.2021.3050163"},{"key":"e_1_3_3_184_2","doi-asserted-by":"crossref","unstructured":"Yuncheng Wu Shaofeng Cai Xiaokui Xiao Gang Chen and Beng Chin Ooi. 2020. Privacy preserving vertical federated learning for tree-based models. In Proceedings of the VLDB Endowment 13 11 (2020) 2090\u20132103.","DOI":"10.14778\/3407790.3407811"},{"key":"e_1_3_3_185_2","doi-asserted-by":"crossref","unstructured":"Zihang Xiang Tianhao Wang Wanyu Lin and Di Wang. 2023. Practical differentially private and byzantine-resilient federated learning. Proceedings of the ACM on Management of Data 1 2 (2023) 1\u201326.","DOI":"10.1145\/3589264"},{"key":"e_1_3_3_186_2","first-page":"2354","volume-title":"Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security","author":"Xu Shuangqing","year":"2025","unstructured":"Shuangqing Xu, Yifeng Zheng, and Zhongyun Hua. 2025. Harnessing sparsification in federated learning: A secure, efficient, and differentially private realization. In Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security. 2354\u20132368."},{"key":"e_1_3_3_187_2","doi-asserted-by":"crossref","unstructured":"Yin Xu Mingjun Xiao An Liu and Jie Wu. 2022. Edge resource prediction and auction for distributed spatial crowdsourcing with differential privacy. IEEE Internet of Things Journal 9 17 (2022) 15554\u201315569.","DOI":"10.1109\/JIOT.2022.3183006"},{"key":"e_1_3_3_188_2","first-page":"7969","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Xu Zheng","year":"2023","unstructured":"Zheng Xu, Maxwell Collins, Yuxiao Wang, Liviu Panait, Sewoong Oh, Sean Augenstein, Ting Liu, Florian Schroff, and H. Brendan McMahan. 2023. Learning to generate image embeddings with user-level differential privacy. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 7969\u20137980."},{"key":"e_1_3_3_189_2","doi-asserted-by":"crossref","unstructured":"Zheng Xu Yanxiang Zhang Galen Andrew Christopher A. Choquette-Choo Peter Kairouz H. Brendan McMahan Jesse Rosenstock and Yuanbo Zhang. 2023. Federated learning of gboard language models with differential privacy. In Proceedings of the 61st Annual Meeting of the Association for Computational Linguistics (Industry Track). 629\u2013639.","DOI":"10.18653\/v1\/2023.acl-industry.60"},{"key":"e_1_3_3_190_2","first-page":"484","volume-title":"Proceedings of the 2021 IEEE 6th International Conference on Computer and Communication Systems","author":"Yang Ge","year":"2021","unstructured":"Ge Yang, Shaowei Wang, and Haijie Wang. 2021. Federated learning with personalized local differential privacy. In Proceedings of the 2021 IEEE 6th International Conference on Computer and Communication Systems. IEEE, 484\u2013489."},{"key":"e_1_3_3_191_2","doi-asserted-by":"crossref","unstructured":"Qiang Yang Yang Liu Tianjian Chen and Yongxin Tong. 2019. Federated machine learning: Concept and applications. ACM Transactions on Intelligent Systems and Technology 10 2 (2019) 1\u201319.","DOI":"10.1145\/3298981"},{"key":"e_1_3_3_192_2","doi-asserted-by":"crossref","first-page":"306","DOI":"10.1145\/3719027.3765151","volume-title":"Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security","author":"Yang Qin","year":"2025","unstructured":"Qin Yang, Nicholas Stout, Meisam Mohammady, Han Wang, Ayesha Samreen, Christopher J. Quinn, Yan Yan, Ashish Kundu, and Yuan Hong. 2025. Plrv-o: Advancing differentially private deep learning via privacy loss random variable optimization. In Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security. 306\u2013320."},{"key":"e_1_3_3_193_2","volume-title":"Proceedings of the 37th Conference on Neural Information Processing Systems","author":"Yang Xiyuan","year":"2023","unstructured":"Xiyuan Yang, Wenke Huang, and Mang Ye. 2023. Dynamic personalized federated learning with adaptive differential privacy. In Proceedings of the 37th Conference on Neural Information Processing Systems."},{"key":"e_1_3_3_194_2","unstructured":"Xin Yang Jiankai Sun Yuanshun Yao Junyuan Xie and Chong Wang. 2022. Differentially private label protection in split learning. arXiv:2203.02073. Retrieved from https:\/\/arxiv.org\/abs\/2203.02073"},{"key":"e_1_3_3_195_2","first-page":"1595","volume-title":"Proceedings of the 32nd USENIX Security Symposium","author":"Yang Yuchen","year":"2023","unstructured":"Yuchen Yang, Bo Hui, Haolin Yuan, Neil Gong, and Yinzhi Cao. 2023. \\(\\lbrace\\) PrivateFL \\(\\rbrace\\) : Accurate, differentially private federated learning via personalized data transformation. In Proceedings of the 32nd USENIX Security Symposium. 1595\u20131612."},{"key":"e_1_3_3_196_2","first-page":"9461","volume-title":"Proceedings of the IEEE International Conference on Acoustics, Speech and Signal Processing","author":"Zhang Jiaojiao","year":"2024","unstructured":"Jiaojiao Zhang, Dominik Fay, and Mikael Johansson. 2024. Dynamic privacy allocation for locally differentially private federated learning with composite objectives. In Proceedings of the IEEE International Conference on Acoustics, Speech and Signal Processing. IEEE, 9461\u20139465."},{"key":"e_1_3_3_197_2","volume-title":"Proceedings of the AAAI Conference on Artificial Intelligence","author":"Zhang Kun","year":"2015","unstructured":"Kun Zhang, Mingming Gong, and Bernhard Sch\u00f6lkopf. 2015. Multi-source domain adaptation: A causal view. In Proceedings of the AAAI Conference on Artificial Intelligence."},{"key":"e_1_3_3_198_2","first-page":"1701","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Zhang Ruiliang","year":"2014","unstructured":"Ruiliang Zhang and James Kwok. 2014. Asynchronous distributed ADMM for consensus optimization. In Proceedings of the International Conference on Machine Learning. PMLR, 1701\u20131709."},{"key":"e_1_3_3_199_2","unstructured":"Shaobo Zhang Jiyong Zhang Gengming Zhu Saiqin Long and Zhetao Li. 2024. Personalized federated learning method based on bregman divergence and differential privacy (in Chinese). Journal of Software 35 11 (2024) 5249\u20135262."},{"key":"e_1_3_3_200_2","volume-title":"Proceedings of the International Conference on Machine Learning, ICML 2022","author":"Zhang Xinwei","year":"2022","unstructured":"Xinwei Zhang, Xiangyi Chen, Mingyi Hong, Zhiwei Steven Wu, and Jinfeng Yi. 2022. Understanding clipping for federated learning: Convergence and client-level differential privacy. In Proceedings of the International Conference on Machine Learning, ICML 2022."},{"key":"e_1_3_3_201_2","first-page":"253","volume-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Zhang Yuheng","year":"2020","unstructured":"Yuheng Zhang, Ruoxi Jia, Hengzhi Pei, Wenxiao Wang, Bo Li, and Dawn Song. 2020. The secret revealer: Generative model-inversion attacks against deep neural networks. In Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition. 253\u2013261."},{"key":"e_1_3_3_202_2","doi-asserted-by":"crossref","unstructured":"Yi Zhang Yunfan Lu and Fengxia Liu. 2023. A systematic survey for differential privacy techniques in federated learning. Journal of Information Security 14 2 (2023) 111\u2013135.","DOI":"10.4236\/jis.2023.142008"},{"key":"e_1_3_3_203_2","unstructured":"Bo Zhao Konda Reddy Mopuri and Hakan Bilen. 2020. idlg: Improved deep leakage from gradients. arXiv:2001.02610. Retrieved from https:\/\/arxiv.org\/abs\/2001.02610"},{"key":"e_1_3_3_204_2","doi-asserted-by":"crossref","unstructured":"Jianzhe Zhao Mengbo Yang Ronglin Zhang Wuganjing Song Jiali Zheng Jingran Feng and Stan Matwin. 2022. Privacy-enhanced federated learning: A restrictively self-sampled and data-perturbed local differential privacy method. Electronics 11 23 (2022) 4007.","DOI":"10.3390\/electronics11234007"},{"key":"e_1_3_3_205_2","doi-asserted-by":"crossref","unstructured":"Yang Zhao Jun Zhao Mengmeng Yang Teng Wang Ning Wang Lingjuan Lyu Dusit Niyato and Kwok-Yan Lam. 2020. Local differential privacy-based federated learning for internet of things. IEEE Internet of Things Journal 8 11 (2020) 8836\u20138853.","DOI":"10.1109\/JIOT.2020.3037194"},{"key":"e_1_3_3_206_2","first-page":"2251","volume-title":"Proceedings of the International Conference on Artificial Intelligence and Statistics","author":"Zheng Qinqing","year":"2021","unstructured":"Qinqing Zheng, Shuxiao Chen, Qi Long, and Weijie Su. 2021. Federated f-differential privacy. In Proceedings of the International Conference on Artificial Intelligence and Statistics. PMLR, 2251\u20132259."},{"key":"e_1_3_3_207_2","doi-asserted-by":"crossref","first-page":"724","DOI":"10.1109\/SP.2019.00045","volume-title":"Proceedings of the 2019 IEEE Symposium on Security and Privacy","author":"Zheng Wenting","year":"2019","unstructured":"Wenting Zheng, Raluca Ada Popa, Joseph E. Gonzalez, and Ion Stoica. 2019. Helen: Maliciously secure coopetitive learning for linear models. In Proceedings of the 2019 IEEE Symposium on Security and Privacy. IEEE, 724\u2013738."},{"key":"e_1_3_3_208_2","doi-asserted-by":"crossref","unstructured":"Juexiao Zhou Siyuan Chen Yulian Wu Haoyang Li Bin Zhang Longxi Zhou Yan Hu Zihang Xiang Zhongxiao Li Ningning Chen et\u00a0al. 2024. PPML-Omics: A privacy-preserving federated machine learning method protects patients\u2019 privacy in omic data. Science Advances 10 5 (2024) eadh8601.","DOI":"10.1126\/sciadv.adh8601"},{"key":"e_1_3_3_209_2","doi-asserted-by":"crossref","unstructured":"Zhou Zhou Youliang Tian and Changgen Peng. 2021. Privacy-preserving federated learning framework with general aggregation and multiparty entity matching. Wireless Communications and Mobile Computing 2021 (2021) 1\u201314.","DOI":"10.1155\/2021\/6692061"},{"key":"e_1_3_3_210_2","first-page":"7634","volume-title":"Proceedings of the International Conference on Machine Learning","author":"Zhu Yuqing","year":"2019","unstructured":"Yuqing Zhu and Yu-Xiang Wang. 2019. Poission subsampled r\u00e9nyi differential privacy. In Proceedings of the International Conference on Machine Learning. PMLR, 7634\u20137642."}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3801079","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,18]],"date-time":"2026-04-18T11:43:29Z","timestamp":1776512609000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3801079"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,18]]},"references-count":209,"journal-issue":{"issue":"11","published-print":{"date-parts":[[2026,8,30]]}},"alternative-id":["10.1145\/3801079"],"URL":"https:\/\/doi.org\/10.1145\/3801079","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4,18]]},"assertion":[{"value":"2024-05-16","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-12-09","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2026-04-18","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}