{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T22:27:05Z","timestamp":1780439225562,"version":"3.54.1"},"reference-count":509,"publisher":"Emerald","issue":"1-2","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2021,6,23]]},"abstract":"<jats:p>Federated learning (FL) is a machine learning setting where many clients (e.g., mobile devices or whole organizations) collaboratively train a model under the orchestration of a central server (e.g., service provider), while keeping the training data decentralized. FL embodies the principles of focused data collection and minimization, and can mitigate many of the systemic privacy risks and costs resulting from traditional, centralized machine learning and data science approaches. Motivated by the explosive growth in FL research, this monograph discusses recent advances and presents an extensive collection of open problems and challenges.<\/jats:p>","DOI":"10.1561\/2200000083","type":"journal-article","created":{"date-parts":[[2020,12,2]],"date-time":"2020-12-02T12:36:36Z","timestamp":1606912596000},"page":"1-210","source":"Crossref","is-referenced-by-count":4039,"title":["Advances and Open Problems in Federated Learning"],"prefix":"10.1108","volume":"14","author":[{"given":"Peter","family":"Kairouz","sequence":"first","affiliation":[{"name":"Google Research, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"H. Brendan","family":"McMahan","sequence":"additional","affiliation":[{"name":"Google Research, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"140","published-online":{"date-parts":[[2021,6,23]]},"reference":[{"key":"2026033012251646900_ref001","first-page":"1273","volume-title":"Communication-efficient learning of deep networks from decentralized data","author":"McMahan"},{"key":"2026033012251646900_ref002","first-page":"169","article-title":"On data banks and privacy homomorphisms","volume-title":"Foundations of Secure Computation, Academia Press","author":"Rivest","year":"1978"},{"key":"2026033012251646900_ref003","first-page":"160","volume-title":"Protocols for secure computations","author":"Yao"},{"key":"2026033012251646900_ref004","first-page":"439","volume-title":"Privacy-preserving data mining","author":"Agrawal"},{"issue":"2","key":"2026033012251646900_ref005","doi-asserted-by":"crossref","first-page":"161","DOI":"10.1007\/s10115-007-0073-7","article-title":"Privacy-preserving SVM classification","volume":"14","author":"Vaidya","year":"2008","journal-title":"Knowl. Inf. Syst."},{"issue":"3","key":"2026033012251646900_ref006","doi-asserted-by":"crossref","first-page":"50","DOI":"10.1109\/MSP.2020.2975749","article-title":"Federated learning: Challenges, methods, and future directions","volume":"37","author":"Li","year":"2020","journal-title":"IEEE Signal Process. Mag."},{"key":"2026033012251646900_ref007","volume-title":"Federated learning: Collaborative machine learning without centralized training data","author":"McMahan","year":"2017"},{"issue":"8","key":"2026033012251646900_ref008","article-title":"Learning with privacy at scale","volume":"1","author":"Differential Privacy Team","year":"2017","journal-title":"Apple Machine Learning Journal"},{"key":"2026033012251646900_ref009","doi-asserted-by":"publisher","volume-title":"RAPPOR: Randomized aggregatable privacy-preserving ordinal response","author":"Erlingsson","DOI":"10.1145\/2660267.2660348"},{"key":"2026033012251646900_ref010","unstructured":"M.\n              Chen\n            , R.Mathews, T.Ouyang, and F.Beaufays, \u201cFederated learning of out-of-vocabulary words,\u201d arXiv preprint 1903.10635, 2019. [Online]. Available: http:\/\/arxiv.org\/abs\/1903.10635."},{"key":"2026033012251646900_ref011","article-title":"Federated learning for mobile keyboard prediction","volume-title":"arXiv preprint","author":"Hard","year":"2018"},{"key":"2026033012251646900_ref012","article-title":"Google\u2019s Sundar Pichai: Privacy should not be a luxury good","volume-title":"New York Times","author":"Pichai","year":"2019"},{"key":"2026033012251646900_ref013","article-title":"Federated learning for emoji prediction in a mobile keyboard","volume-title":"arXiv preprint","author":"Ramaswamy","year":"2019"},{"key":"2026033012251646900_ref014","article-title":"Applied federated learning: Improving Google keyboard query suggestions","volume-title":"arXiv preprint","author":"Yang","year":"2018"},{"key":"2026033012251646900_ref015","unstructured":"support.google\n          , Your chats stay private while Messages improves suggestions, 2019. [Online]. Available: https:\/\/support.google.com\/messages\/answer\/9327902. Retrieved Aug. 2019."},{"key":"2026033012251646900_ref016","unstructured":"Apple\n          , Private federated learning (NeurIPS 2019 Expo Talk Abstract), https:\/\/nips.cc\/ExpoConferences\/2019\/schedule?talk_id=40, 2019."},{"key":"2026033012251646900_ref017","unstructured":"Apple\n          , Designing for privacy (video and slide deck), Apple WWDC, https:\/\/developer.apple.com\/videos\/play\/wwdc2019\/708, 2019."},{"key":"2026033012251646900_ref018","unstructured":"W.\n              de Brouwer\n            \n          , The federated future is ready for shipping, https:\/\/medium.com\/@_doc_ai\/the-federated-future-is-ready-for-shipping-d17ff40f43e3, Mar.2019."},{"key":"2026033012251646900_ref019","article-title":"Federated learning for keyword spotting","volume-title":"arXiv preprint","author":"Leroy","year":"2018"},{"key":"2026033012251646900_ref020","unstructured":"WeBank\n          , WeBank and Swiss re signed cooperation MoU, 2019. [Online]. Available: https:\/\/www.fedai.org\/news\/webank-and-swiss-re-signed-cooperation-mou\/. Retrieved Aug. 2019."},{"key":"2026033012251646900_ref021","unstructured":"EU CORDIS\n          , Machine learning ledger orchestration for drug discovery, 2019. [Online]. Available: https:\/\/cordis.europa.eu\/project\/rcn\/223634\/factsheet\/en?WT.mc_id=RSS-Feed&WT.rss_f=project&WT.rss_a=223634&WT.rss_ev=a. Retrieved Aug. 2019."},{"key":"2026033012251646900_ref022","unstructured":"Feature Cloud\n          , Feature Cloud: Our vision, 2019. [Online]. Available: https:\/\/featurecloud.eu\/about\/our-vision\/. Retrieved Aug. 2019."},{"key":"2026033012251646900_ref023","unstructured":"ai.intel\n          , Federated learning for medical imaging, 2019. [Online]. Available: https:\/\/www.intel.ai\/federated-learning-for-medical-imaging\/. Retrieved Aug. 2019."},{"key":"2026033012251646900_ref024","first-page":"1","article-title":"Deep learning-based classification of mesothelioma improves prediction of patient outcome","volume-title":"Nature Medicine","author":"Courtiol","year":"2019"},{"key":"2026033012251646900_ref025","unstructured":"Musketeer\n          , Musketeer: About, 2019. [Online]. Available: http:\/\/musketeer.eu\/project\/. Retrieved Aug. 2019."},{"key":"2026033012251646900_ref026","unstructured":"The TFF Authors\n          , Tensor Flow Federated, 2019. [Online]. Available: https:\/\/www.tensorflow.org\/federated."},{"key":"2026033012251646900_ref027","unstructured":"The FATE Authors\n          , Federated AI technology enabler, 2019. [Online]. Available: https:\/\/www.fedai.org\/."},{"key":"2026033012251646900_ref028","article-title":"A generic framework for privacy preserving deep learning","volume-title":"arXiv preprint","author":"Ryffel","year":"2018"},{"key":"2026033012251646900_ref029","unstructured":"The Leaf Authors\n          , Leaf, 2019. [Online]. Available: https:\/\/leaf.cmu.edu\/."},{"key":"2026033012251646900_ref030","unstructured":"The PaddleFL Authors\n          , PaddleFL, 2019. [Online]. Available: https:\/\/github.com\/PaddlePaddle\/PaddleFL."},{"key":"2026033012251646900_ref031","unstructured":"N.\n              Clara\n            \n          , The clara training framework authors, 2019. [Online]. Available: https:\/\/developer.nvidia.com\/clara."},{"key":"2026033012251646900_ref032","volume-title":"Towards federated learning at scale: System design","author":"Bonawitz"},{"key":"2026033012251646900_ref033","first-page":"1223","volume-title":"Large scale distributed deep networks","author":"Dean"},{"key":"2026033012251646900_ref034","volume-title":"Tensor Flow: Large-scale machine learning on heterogeneous systems","author":"Abadi","year":"2015"},{"key":"2026033012251646900_ref035","volume-title":"Decentralized collaborative learning of personalized models over networks","author":"Vanhaesebrouck"},{"key":"2026033012251646900_ref036","volume-title":"Can decentralized algorithms outperform centralized algorithms? A case study for decentralized parallel stochastic gradient descent","author":"Lian"},{"issue":"6","key":"2026033012251646900_ref037","doi-asserted-by":"crossref","first-page":"2508","DOI":"10.1109\/TIT.2006.874516","article-title":"Randomized gossip algorithms","volume":"52","author":"Boyd","year":"2006","journal-title":"IEEE Trans. Inform. Theor."},{"key":"2026033012251646900_ref038","volume-title":"Stochastic gradient push for distributed deep learning","author":"Assran"},{"key":"2026033012251646900_ref039","volume-title":"Personalized and Private Peer-to-Peer Machine Learning","author":"Bellet"},{"key":"2026033012251646900_ref040","volume-title":"Gossip dual averaging for decentralized optimization of pairwise functions","author":"Colin"},{"key":"2026033012251646900_ref041","article-title":"GADMM: Fast and communication efficient framework for distributed machine learning","volume-title":"arXiv preprint","author":"Elgabli","year":"2019"},{"key":"2026033012251646900_ref042","volume-title":"Decentralized stochastic optimization and Gossip algorithms with compressed communication","author":"Koloskova"},{"key":"2026033012251646900_ref043","volume-title":"Peer-to-peer federated learning on graphs","author":"Lalitha","year":"2019"},{"key":"2026033012251646900_ref044","volume-title":"D2: Decentralized training over decentralized data","author":"Tang"},{"key":"2026033012251646900_ref045","article-title":"Central server free federated learning over single-sided trust social networks","volume-title":"arXiv preprint","author":"He","year":"2019"},{"key":"2026033012251646900_ref046","first-page":"4541","volume-title":"COLA: Decentralized linear learning","author":"He"},{"key":"2026033012251646900_ref047","article-title":"Distributed learning over unreliable networks","volume-title":"arXiv preprint","author":"Yu","year":"2018"},{"key":"2026033012251646900_ref048","article-title":"Decentralized gradient methods: Does topology matter","volume-title":"AISTATS","author":"Neglia","year":"2020"},{"key":"2026033012251646900_ref049","doi-asserted-by":"crossref","unstructured":"J.\n              Wang\n            , A.Sahu, G.Joshi, and S.Kar, \u201cMATCHA: Speeding up decentralized SGD via matching decomposition sampling,\u201d Preprint, May2019. [Online]. Available: https:\/\/arxiv.org\/abs\/1905.09435.","DOI":"10.1109\/ICC47138.2019.9123209"},{"key":"2026033012251646900_ref050","volume-title":"Asynchronous decentralized parallel stochastic gradient descent","author":"Lian"},{"key":"2026033012251646900_ref051","volume-title":"Decentralized deep learning with arbitrary communication compression","author":"Koloskova"},{"key":"2026033012251646900_ref052","volume-title":"A unified theory of decentralized SGD with changing topology and local updates","author":"Koloskova"},{"key":"2026033012251646900_ref053","unstructured":"J.\n              Wang\n             and G.Joshi, \u201cCooperative SGD: A unified framework for the design and analysis of communication-efficient SGD algorithms,\u201d Preprint, Aug., 2018. [Online]. Available: https:\/\/arxiv.org\/abs\/1808.07576."},{"key":"2026033012251646900_ref054","volume-title":"Fully decentralized joint learning of personalized models and collaboration graphs","author":"Zantedeschi","year":"2019"},{"key":"2026033012251646900_ref055","article-title":"Robust and communication-efficient collaborative learning","volume-title":"arXiv:1907.10595","author":"Reisizadeh","year":"2019"},{"key":"2026033012251646900_ref056","article-title":"DeepSqueeze: Parallel stochastic gradient descent with double-pass error-compensated compression","volume-title":"arXiv preprint","author":"Tang","year":"2019"},{"key":"2026033012251646900_ref057","doi-asserted-by":"crossref","volume-title":"Differentially private distributed optimization","author":"Huang","DOI":"10.1145\/2684464.2684480"},{"key":"2026033012251646900_ref058","article-title":"Privacy amplification by decentralization","volume-title":"arXiv preprint","author":"Cyffers","year":"2020"},{"issue":"2014","key":"2026033012251646900_ref059","first-page":"1","article-title":"Ethereum: A secure decentralised generalised transaction ledger","volume":"151","author":"Wood","year":"2014","journal-title":"Ethereum Project Yellow Paper"},{"key":"2026033012251646900_ref060","first-page":"1175","volume-title":"Practical secure aggregation for privacy-preserving machine learning","author":"Bonawitz"},{"key":"2026033012251646900_ref061","first-page":"185","volume-title":"Ekiden: A platform for confidentiality-preserving, trustworthy, and performant smart contracts","author":"Cheng"},{"key":"2026033012251646900_ref062","volume-title":"Learning differentially private recurrent language models","author":"McMahan"},{"key":"2026033012251646900_ref063","article-title":"Federated machine learning: Concept and applications","volume":"abs\/1902.04885","author":"Yang","year":"2019","journal-title":"CoRR"},{"key":"2026033012251646900_ref064","article-title":"Se-cureBoost: A lossless federated learning framework","volume":"abs\/1901.08755","author":"Cheng","year":"2019","journal-title":"CoRR"},{"key":"2026033012251646900_ref065","article-title":"Private federated learning on vertically partitioned data via entity resolution and additively homomorphic encryption","volume-title":"arXiv preprint","author":"Hardy","year":"2017"},{"key":"2026033012251646900_ref066","article-title":"A communication efficient vertical federated learning framework","volume":"abs\/1912.11187","author":"Liu","year":"2019","journal-title":"CoRR"},{"issue":"4","key":"2026033012251646900_ref067","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1109\/MIS.2020.2988525","article-title":"A secure federated transfer learning framework","volume":"35","author":"Liu","year":"2020","journal-title":"IEEE Intelligent Systems"},{"key":"2026033012251646900_ref068","article-title":"Learning privately over distributed features: An ADMM sharing approach","volume-title":"arXiv preprint","author":"Hu","year":"2019"},{"key":"2026033012251646900_ref069","article-title":"Backdoor attacks and defenses in feature-partitioned collaborative learning","volume-title":"arXiv preprint","author":"Liu","year":"2020"},{"issue":"10","key":"2026033012251646900_ref070","doi-asserted-by":"crossref","first-page":"1345","DOI":"10.1109\/TKDE.2009.191","article-title":"A survey on transfer learning","volume":"22","author":"Pan","year":"2010","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"key":"2026033012251646900_ref071","article-title":"IBM federated learning: An enterprise framework white paper V0.1","volume-title":"arXiv preprint","author":"Ludwig","year":"2020"},{"key":"2026033012251646900_ref072","doi-asserted-by":"crossref","DOI":"10.1109\/JIOT.2019.2940820","article-title":"Incentive mechanism for reliable federated learning: A joint optimization approach to combining reputation and contract theory","volume-title":"IEEE Internet of Things Journal","author":"Kang","year":"2019"},{"key":"2026033012251646900_ref073","first-page":"1","volume-title":"Incentive design for efficient federated learning in mobile networks: A contract theory approach","author":"Kang"},{"issue":"4","key":"2026033012251646900_ref074","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1109\/MIS.2020.2987774","article-title":"A sustainable incentive scheme for federated learning","volume":"35","author":"Yu","year":"2020","journal-title":"IEEE Intelligent Systems"},{"issue":"11","key":"2026033012251646900_ref075","doi-asserted-by":"crossref","first-page":"2524","DOI":"10.1109\/TPDS.2020.2996273","article-title":"Towards fair and privacy-preserving federated deep models","volume":"31","author":"Lyu","year":"2020","journal-title":"IEEE Transactions on Parallel and Distributed Systems"},{"key":"2026033012251646900_ref076","doi-asserted-by":"publisher","first-page":"887","DOI":"10.1145\/3097983.3098118","volume-title":"Federated tensor factorization for computational phenotyping","author":"Kim"},{"key":"2026033012251646900_ref077","doi-asserted-by":"crossref","volume-title":"Privacy-preserving tensor factorization for collaborative health data analysis","author":"Ma","DOI":"10.1145\/3357384.3357878"},{"key":"2026033012251646900_ref078","first-page":"1","article-title":"Distributed learning of deep neural network over multiple agents","volume-title":"Journal of Network and Computer Applications","author":"Gupta","year":"2018"},{"key":"2026033012251646900_ref079","article-title":"Split learning for health: Distributed deep learning without sharing raw patient data","volume-title":"arXiv preprint","author":"Vepakomma","year":"2018"},{"key":"2026033012251646900_ref080","article-title":"SplitNN-driven vertical partitioning","volume-title":"arXiv preprint","author":"Ceballos","year":"2018"},{"key":"2026033012251646900_ref081","article-title":"Detailed comparison of communication efficiency of split learning and federated learning","volume-title":"arXiv preprint","author":"Singh","year":"2019"},{"key":"2026033012251646900_ref082","first-page":"6659","volume-title":"Training neural networks using features replay","author":"Huo"},{"key":"2026033012251646900_ref083","first-page":"1627","volume-title":"Decoupled neural interfaces using synthetic gradients","author":"Jaderberg"},{"key":"2026033012251646900_ref084","article-title":"ExpertMatcher: Automating ML model selection for clients using hidden representations","volume-title":"arXiv preprint","author":"Sharma","year":"2019"},{"key":"2026033012251646900_ref085","doi-asserted-by":"crossref","DOI":"10.1109\/ICDMW51313.2020.00134","article-title":"Nopeek: Information leakage reduction to share activations in distributed deep learning","volume-title":"arXiv preprint","author":"Vepakomma","year":"2020"},{"issue":"6","key":"2026033012251646900_ref086","doi-asserted-by":"crossref","first-page":"2769","DOI":"10.1214\/009053607000000505","article-title":"Measuring and testing dependence by correlation of distances","volume":"35","author":"Sz\u00e9kely","year":"2007","journal-title":"The Annals of Statistics"},{"issue":"1","key":"2026033012251646900_ref087","doi-asserted-by":"crossref","first-page":"960","DOI":"10.1214\/18-EJS1403","article-title":"Supervised dimensionality reduction via distance correlation maximization","volume":"12","author":"Vepakomma","year":"2018","journal-title":"Electronic Journal of Statistics"},{"key":"2026033012251646900_ref088","article-title":"DISCO: Dynamic and invariant sensitive channel obfuscation for deep neural networks","volume-title":"arXiv preprint","author":"Singh","year":"2020"},{"issue":"1","key":"2026033012251646900_ref089","doi-asserted-by":"crossref","DOI":"10.1016\/j.patcog.2011.06.019","article-title":"A unifying view on dataset shift in classification","volume":"45","author":"Moreno-Torres","year":"2012","journal-title":"Pattern Recogn."},{"key":"2026033012251646900_ref090","volume-title":"Dataset Shift in Machine Learning","author":"Quionero-Candela","year":"2009"},{"key":"2026033012251646900_ref091","unstructured":"K.\n              Hsieh\n            , A.Phanishayee, O.Mutlu, and P. B.Gibbons, The non-IID data quagmire of decentralized machine learning, 2019. [Online]. Available: https:\/\/arxiv.org\/abs\/1910.00189."},{"key":"2026033012251646900_ref092","volume-title":"Semi-cyclic stochastic gradient descent","author":"Eichner"},{"key":"2026033012251646900_ref093","article-title":"Dataset distillation","volume-title":"arXiv preprint","author":"Wang","year":"2018"},{"key":"2026033012251646900_ref094","volume-title":"Graph oracle models, lower bounds, and gaps for parallel stochastic optimization","author":"Woodworth"},{"key":"2026033012251646900_ref095","first-page":"1647","author":"Cotter","year":"2011"},{"issue":"6","key":"2026033012251646900_ref096","first-page":"165","article-title":"Optimal distributed online prediction using mini-batches","volume":"13","author":"Dekel","year":"2012","journal-title":"J. Mach. Learn. Res."},{"issue":"1","key":"2026033012251646900_ref097","doi-asserted-by":"crossref","first-page":"365","DOI":"10.1007\/s10107-010-0434-y","article-title":"An optimal method for stochastic composite optimization","volume":"133","author":"Lan","year":"2012","journal-title":"Math. Program."},{"key":"2026033012251646900_ref098","article-title":"Parallel restarted SGD for non-convex optimization with faster convergence and less communication","volume-title":"arXiv preprint","author":"Yu","year":"2018"},{"key":"2026033012251646900_ref099","volume-title":"Local SGD converges fast and communicates little","author":"Stich"},{"key":"2026033012251646900_ref100","article-title":"The error-feedback framework: Better rates for SGD with delayed gradients and compressed communication","volume-title":"arXiv:1909.05350","author":"Stich","year":"2019"},{"key":"2026033012251646900_ref101","first-page":"5132","volume-title":"Scaffold: Stochastic controlled averaging for federated learning","author":"Karimireddy"},{"key":"2026033012251646900_ref102","unstructured":"A.\n              Khaled\n            , K.Mishchenko, and P.Richt\u00e1rik, Better communication complexity for local SGD, 2019. [Online]. Available: https:\/\/arxiv.org\/abs\/1909.04746."},{"key":"2026033012251646900_ref103","volume-title":"Don\u2019t use large mini-batches, use local SGD","author":"Lin"},{"key":"2026033012251646900_ref104","article-title":"Communication trade-offs for synchronized distributed SGD with large step size","volume-title":"NeurIPS","author":"Patel","year":"2019"},{"key":"2026033012251646900_ref105","article-title":"Fedpaq: A communication-efficient federated learning method with periodic averaging and quantization","volume-title":"arXiv preprint","author":"Reisizadeh","year":"2019"},{"key":"2026033012251646900_ref106","article-title":"Is local SGD better than minibatch SGD?","volume-title":"arXiv preprint","author":"Woodworth","year":"2020"},{"key":"2026033012251646900_ref107","first-page":"685","volume-title":"Deep learning with elastic averaging SGD","author":"Zhang"},{"key":"2026033012251646900_ref108","article-title":"Local SGD with periodic averaging: Tighter analysis and adaptive synchronization","volume-title":"arXiv preprint","author":"Haddadpour","year":"2019"},{"key":"2026033012251646900_ref109","first-page":"795","volume-title":"Linear convergence of gradient and proximal-gradient methods under the Polyak-\u0142ojasiewicz condition","author":"Karimi"},{"key":"2026033012251646900_ref110","volume-title":"Adaptive communication strategies for best error-runtime trade-offs in communication-efficient distributed SGD","author":"Wang"},{"key":"2026033012251646900_ref111","first-page":"7611","volume-title":"Tackling the objective inconsistency problem in heterogeneous federated optimization","author":"Wang"},{"key":"2026033012251646900_ref112","doi-asserted-by":"crossref","volume-title":"Slow and stale gradients can win the race: Error-runtime trade-offs in distributed SGD","author":"Dutta","DOI":"10.1109\/JSAIT.2021.3103770"},{"key":"2026033012251646900_ref113","unstructured":"T.\n              Li\n            , A. K.Sahu, M.Zaheer, M.Sanjabi, A.Talwalkar, and V.Smith, Federated optimization in heterogeneous networks, 2018. [Online]. Available: https:\/\/arxiv.org\/abs\/1812.06127."},{"key":"2026033012251646900_ref114","article-title":"Communication efficient decentralized training with multiple local updates","volume-title":"arXiv preprint","author":"Li","year":"2019"},{"key":"2026033012251646900_ref115","unstructured":"A.\n              Khaled\n            , K.Mishchenko, and P.Richt\u00e1rik, First analysis of local GD on heterogeneous data, 2019. [Online]. Available: https:\/\/arxiv.org\/abs\/1909.04715."},{"key":"2026033012251646900_ref116","article-title":"On the convergence of Fed Avg on non-IID data","volume-title":"arXiv preprint","author":"Li","year":"2019"},{"key":"2026033012251646900_ref117","article-title":"On the linear speedup analysis of communication efficient momentum SGD for distributed non-convex optimization","volume-title":"arXiv preprint","author":"Yu","year":"2019"},{"key":"2026033012251646900_ref118","article-title":"Local adaalter: Communication-efficient stochastic gradient descent with adaptive learning rates","volume-title":"arXiv preprint","author":"Xie","year":"2019"},{"issue":"61","key":"2026033012251646900_ref119","first-page":"2121","article-title":"Adaptive subgradient methods for online learning and stochastic optimization","volume":"12","author":"Duchi","year":"2011","journal-title":"J. Mach. Learn. Res."},{"key":"2026033012251646900_ref120","article-title":"Adaptive bound optimization for online convex optimization","volume-title":"arXiv preprint","author":"McMahan","year":"2010"},{"key":"2026033012251646900_ref121","article-title":"Adaptive federated optimization","volume-title":"arXiv preprint","author":"Reddi","year":"2020"},{"key":"2026033012251646900_ref122","article-title":"Measuring the effects of non-identical data distribution for federated visual classification","volume-title":"arXiv preprint","author":"Hsu","year":"2019"},{"key":"2026033012251646900_ref123","article-title":"SlowMo: Improving communication-efficient distributed SGD with slow momentum","volume-title":"arXiv preprint","author":"Wang","year":"2019"},{"key":"2026033012251646900_ref124","article-title":"Mime: Mimicking centralized stochastic algorithms in federated learning","volume-title":"arXiv preprint","author":"Karimireddy","year":"2020"},{"issue":"9","key":"2026033012251646900_ref125","doi-asserted-by":"crossref","first-page":"1389","DOI":"10.1109\/LSP.2018.2859596","article-title":"DJAM: Distributed Jacobi asynchronous method for learning personal models","volume":"25","author":"Almeida","year":"2018","journal-title":"IEEE Signal Process. Lett."},{"key":"2026033012251646900_ref126","article-title":"Federated evaluation of on-device personalization","volume-title":"arXiv preprint","author":"Wang","year":"2019"},{"key":"2026033012251646900_ref127","article-title":"A survey on multi-task learning","volume":"abs\/1707.08114","author":"Zhang","year":"2017","journal-title":"CoRR"},{"key":"2026033012251646900_ref128","volume-title":"Federated multi-task learning","author":"Smith"},{"key":"2026033012251646900_ref129","article-title":"Three approaches for personalization with applications to federated learning","volume-title":"arXiv preprint","author":"Mansour","year":"2020"},{"issue":"1-2","key":"2026033012251646900_ref130","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1007\/s10994-009-5152-4","article-title":"A theory of learning from different domains","volume":"79","author":"Ben-David","year":"2010","journal-title":"Mach. Learn."},{"key":"2026033012251646900_ref131","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1016\/j.tcs.2013.09.027","article-title":"Domain adaptation and sample bias correction theory and algorithm for regression","volume":"519","author":"Cortes","year":"2014","journal-title":"Theor. Comput. Sci."},{"key":"2026033012251646900_ref132","article-title":"Multiple-source adaptation with domain classifiers","volume-title":"arXiv preprint","author":"Cortes","year":"2020"},{"key":"2026033012251646900_ref133","article-title":"Domain adaptation: Learning bounds and algorithms","volume-title":"arXiv preprint","author":"Mansour","year":"2009"},{"key":"2026033012251646900_ref134","article-title":"A theory of multiple-source adaptation with limited target labeled data","volume-title":"arXiv preprint","author":"Mansour","year":"2020"},{"key":"2026033012251646900_ref135","doi-asserted-by":"crossref","first-page":"149","DOI":"10.1613\/jair.731","article-title":"A model of inductive bias learning","volume":"12","author":"Baxter","year":"2000","journal-title":"J. Artif. Intell. Res."},{"key":"2026033012251646900_ref136","volume-title":"Model-agnostic meta-learning for fast adaptation of deep networks","author":"Finn"},{"key":"2026033012251646900_ref137","article-title":"On first-order meta-learning algorithms","volume-title":"arXiv preprint","author":"Nichol","year":"2018"},{"key":"2026033012251646900_ref138","volume-title":"Adaptive gradient-based meta-learning methods","author":"Khodak"},{"key":"2026033012251646900_ref139","article-title":"Improving federated learning personalization via model agnostic meta learning","volume-title":"arXiv preprint","author":"Jiang","year":"2019"},{"key":"2026033012251646900_ref140","doi-asserted-by":"crossref","DOI":"10.1109\/ASRU46091.2019.9003775","article-title":"Personalization of end-to-end speech recognition on mobile devices for named entities","volume-title":"arXiv preprint","author":"Sim","year":"2019"},{"key":"2026033012251646900_ref141","article-title":"Personalized federated learning: A meta-learning approach","volume-title":"arXiv preprint| arXiv:2002.07948","author":"Fallah","year":"2020"},{"key":"2026033012251646900_ref142","article-title":"Differentially private meta-learning","volume-title":"arXiv preprint","author":"Li","year":"2019"},{"key":"2026033012251646900_ref143","volume-title":"One shot learning of simple visual concepts","author":"Lake"},{"key":"2026033012251646900_ref144","volume-title":"Optimization as a model for few-shot learning","author":"Ravi"},{"key":"2026033012251646900_ref145","volume-title":"Lifelong machine learning systems: Beyond learning algorithms","author":"Silver"},{"key":"2026033012251646900_ref146","first-page":"4080","volume-title":"Prototypical networks for few-shot learning","author":"Snell"},{"key":"2026033012251646900_ref147","first-page":"8246","volume-title":"Algorithms and theory for multiple-source adaptation","author":"Hoffman"},{"key":"2026033012251646900_ref148","first-page":"1041","volume-title":"Domain adaptation with multiple sources","author":"Mansour"},{"key":"2026033012251646900_ref149","volume-title":"Agnostic Federated Learning","author":"Mohri"},{"key":"2026033012251646900_ref150","doi-asserted-by":"crossref","DOI":"10.1007\/978-3-642-31164-2","volume-title":"Data Matching: Concepts and Techniques for Record Linkage, Entity Resolution, and Duplicate Detection","author":"Christen","year":"2012"},{"key":"2026033012251646900_ref151","doi-asserted-by":"crossref","volume-title":"A novel error-tolerant anonymous linking code","author":"Schnell","DOI":"10.2139\/ssrn.3549247"},{"key":"2026033012251646900_ref152","volume-title":"Efficient private record linkage of very large datasets","author":"Schnell"},{"key":"2026033012251646900_ref153","article-title":"Salvaging federated learning by local adaptation","volume-title":"arXiv preprint","author":"Yu","year":"2020"},{"key":"2026033012251646900_ref154","first-page":"1909","volume-title":"Fast learning from distributed datasets without entity matching","author":"Patrini"},{"issue":"3","key":"2026033012251646900_ref155","doi-asserted-by":"crossref","first-page":"289","DOI":"10.1080\/08839519508945477","article-title":"StatLog: Comparison of classification algorithms on large real-world problems","volume":"9","author":"King","year":"1995","journal-title":"Appl. Artif. Intell."},{"key":"2026033012251646900_ref156","first-page":"304","volume-title":"Automatic parameter selection by minimizing estimated error","author":"Kohavi"},{"key":"2026033012251646900_ref157","doi-asserted-by":"crossref","first-page":"40","DOI":"10.1007\/978-1-4899-3099-6_2","volume-title":"Networks and Chaos-Statistical and Probabilistic Aspects","author":"Ripley","year":"1993"},{"key":"2026033012251646900_ref158","first-page":"2546","volume-title":"Algorithms for hyper-parameter optimization","author":"Bergstra"},{"key":"2026033012251646900_ref159","article-title":"BOHB: Robust and efficient hyperparameter optimization at scale","volume-title":"arXiv preprint","author":"Falkner","year":"2018"},{"key":"2026033012251646900_ref160","article-title":"Hyperparameter optimization with approximate gradient","volume-title":"arXiv preprint","author":"Pedregosa","year":"2016"},{"key":"2026033012251646900_ref161","first-page":"2171","volume-title":"Scalable Bayesian optimization using deep neural networks","author":"Snoek"},{"key":"2026033012251646900_ref162","article-title":"On the outsized importance of learning rates in local update methods","volume-title":"arXiv preprint","author":"Charles","year":"2020"},{"key":"2026033012251646900_ref163","doi-asserted-by":"crossref","volume-title":"Federated learning with autotuned communication-efficient secure aggregation","author":"Bonawitz","DOI":"10.1109\/IEEECONF44664.2019.9049066"},{"key":"2026033012251646900_ref164","article-title":"Differentially private learning with adaptive clipping","volume-title":"arXiv preprint","author":"Thakkar","year":"2019"},{"key":"2026033012251646900_ref165","first-page":"459","volume-title":"Neural optimizer search with reinforcement learning","author":"Bello"},{"key":"2026033012251646900_ref166","article-title":"Efficient multi-objective neural architecture search via Lamarckian evolution","volume-title":"arXiv preprint","author":"Elsken","year":"2018"},{"key":"2026033012251646900_ref167","article-title":"DARTS: Differentiable architecture search","volume-title":"arXiv preprint","author":"Liu","year":"2018"},{"key":"2026033012251646900_ref168","first-page":"7816","volume-title":"Neural architecture optimization","author":"Luo"},{"key":"2026033012251646900_ref169","volume-title":"Milenas: Efficient neural architecture search via mixed-level reformulation","author":"He"},{"key":"2026033012251646900_ref170","first-page":"2902","volume-title":"Large-scale evolution of image classifiers","author":"Real"},{"key":"2026033012251646900_ref171","first-page":"4780","volume-title":"Regularized evolution for image classifier architecture search","author":"Real"},{"key":"2026033012251646900_ref172","first-page":"4092","volume-title":"Efficient neural architecture search via parameter sharing","author":"Pham"},{"key":"2026033012251646900_ref173","article-title":"SNAS: Stochastic neural architecture search","volume-title":"arXiv preprint","author":"Xie","year":"2018"},{"key":"2026033012251646900_ref174","article-title":"Weight agnostic neural networks","volume-title":"arXiv preprint","author":"Gaier","year":"2019"},{"key":"2026033012251646900_ref175","article-title":"FedNAS: Federated deep learning via neural architecture search","volume-title":"arXiv preprint","author":"He","year":"2020"},{"key":"2026033012251646900_ref176","unstructured":"S.\n              Augenstein\n            , H. B.McMahan, D.Ramage, S.Ramaswamy, P.Kairouz, M.Chen, R.Mathews, and B. A.y Arcas, Generative models for effective ML on private, decentralized datasets, 2019. [Online]. Available: https:\/\/arxiv.org\/abs\/1911.06679."},{"key":"2026033012251646900_ref177","article-title":"Federated learning: Strategies for improving communication efficiency","volume-title":"arXiv preprint","author":"Kone\u010dn\u00fd","year":"2016"},{"issue":"12","key":"2026033012251646900_ref178","doi-asserted-by":"crossref","first-page":"7835","DOI":"10.1109\/TIT.2020.3028440","article-title":"Inference under information constraints I: Lower bounds from chi-square contraction","volume":"66","author":"Acharya","year":"2020","journal-title":"IEEE Trans. Inform. Theor."},{"issue":"236","key":"2026033012251646900_ref179","first-page":"1","article-title":"Lower bounds for learning distributions under communication constraints via Fisher information","volume":"21","author":"Barnes","year":"2020","journal-title":"J. Mach. Learn. Res."},{"key":"2026033012251646900_ref180","first-page":"1011","volume-title":"Communication lower bounds for statistical estimation problems via a distributed data processing inequality","author":"Braverman"},{"key":"2026033012251646900_ref181","doi-asserted-by":"crossref","DOI":"10.1109\/JSAIT.2020.3042094","article-title":"rTop-k: A statistical estimation approach to distributed SGD","volume-title":"arXiv preprint","author":"Barnes","year":"2020"},{"key":"2026033012251646900_ref182","first-page":"2328","volume-title":"Information-theoretic lower bounds for distributed statistical estimation with communication constraints","author":"Zhang"},{"key":"2026033012251646900_ref183","first-page":"1","volume-title":"Geometric lower bounds for distributed parameter estimation under communication constraints","author":"Han"},{"key":"2026033012251646900_ref184","first-page":"1709","volume-title":"QSGD: Communication-efficient SGD via gradient quantization and encoding","author":"Alistarh"},{"issue":"1","key":"2026033012251646900_ref185","doi-asserted-by":"crossref","first-page":"217","DOI":"10.1109\/JSAIT.2020.2985917","article-title":"Qsparse-local-SGD: Distributed SGD with quantization, sparsification, and local computations","volume":"1","author":"Basu","year":"2020","journal-title":"IEEE Sel. Areas Inf. Theor."},{"key":"2026033012251646900_ref186","article-title":"Natural compression for distributed deep learning","volume-title":"arXiv preprint","author":"Horvath","year":"2019"},{"key":"2026033012251646900_ref187","doi-asserted-by":"crossref","first-page":"62","DOI":"10.3389\/fams.2018.00062","article-title":"Randomized distributed mean estimation: Accuracy vs. communication","volume":"4","author":"Kone\u010dn\u00fd","year":"2018","journal-title":"Frontiers in Applied Mathematics and Statistics"},{"key":"2026033012251646900_ref188","first-page":"3329","volume-title":"Distributed mean estimation with limited communication","author":"Suresh"},{"key":"2026033012251646900_ref189","article-title":"Distributed fixed point methods with compressed iterates","volume-title":"arXiv preprint","author":"Chraibi","year":"2019"},{"key":"2026033012251646900_ref190","article-title":"Expanding the reach of federated learning by reducing client resource requirements","volume-title":"arXiv preprint","author":"Caldas","year":"2018"},{"key":"2026033012251646900_ref191","first-page":"3973","volume-title":"Fedboost: A communication-efficient algorithm for federated learning","author":"Hamer"},{"key":"2026033012251646900_ref192","first-page":"14068","volume-title":"Group knowledge transfer: Federated learning of large cnns at the edge","author":"He"},{"key":"2026033012251646900_ref193","volume-title":"Error feedback fixes SignSGD and other gradient compression schemes","author":"Karimireddy"},{"key":"2026033012251646900_ref194","article-title":"Deep gradient compression: Reducing the communication bandwidth for distributed training","volume-title":"arXiv preprint","author":"Lin","year":"2017"},{"key":"2026033012251646900_ref195","article-title":"Robust and communication-efficient federated learning from non-IID data","volume-title":"arXiv preprint","author":"Sattler","year":"2019"},{"key":"2026033012251646900_ref196","volume-title":"PowerSGD: Practical low-rank gradient compression for distributed optimization","author":"Vogels"},{"key":"2026033012251646900_ref197","article-title":"What is the state of neural network pruning?","volume-title":"arXiv preprint","author":"Blalock","year":"2020"},{"key":"2026033012251646900_ref198","first-page":"3123","volume-title":"BinaryConnect: Training deep neural networks with binary weights during propagations","author":"Courbariaux"},{"key":"2026033012251646900_ref199","article-title":"Deep compression: Compressing deep neural networks with pruning, trained quantization and huffman coding","volume-title":"arXiv preprint","author":"Han","year":"2015"},{"key":"2026033012251646900_ref200","first-page":"2849","volume-title":"Fixed point quantization of deep convolutional networks","author":"Lin"},{"key":"2026033012251646900_ref201","article-title":"Model compression by entropy penalized reparameterization","volume-title":"arXiv preprint","author":"Oktay","year":"2019"},{"key":"2026033012251646900_ref202","article-title":"To prune, or not to prune: Exploring the efficacy of pruning for model compression","volume-title":"arXiv preprint","author":"Zhu","year":"2017"},{"key":"2026033012251646900_ref203","volume-title":"Elements of Information Theory","author":"Cover","year":"2012"},{"key":"2026033012251646900_ref204","first-page":"5745","volume-title":"Multiscale quantization for fast similarity search","author":"Wu"},{"key":"2026033012251646900_ref205","article-title":"VqSGD: Vector quantized stochastic gradient descent","volume-title":"arXiv preprint","author":"Gandikota","year":"2019"},{"key":"2026033012251646900_ref206","article-title":"Practical secure aggregation for federated learning on user-held data","volume-title":"arXiv preprint","author":"Bonawitz","year":"2016"},{"key":"2026033012251646900_ref207","first-page":"308","volume-title":"Deep learning with differential privacy","author":"Abadi"},{"key":"2026033012251646900_ref208","first-page":"1253","volume-title":"Secure single-server aggregation with (poly)logarithmic overhead","author":"Bell"},{"key":"2026033012251646900_ref209","first-page":"7564","volume-title":"CpSGD: Communication-efficient and differentially-private distributed SGD","author":"Agarwal"},{"key":"2026033012251646900_ref210","article-title":"Communication-efficient on-device machine learning: Federated distillation and augmentation under non-IID private data","volume":"abs\/1811.11479","author":"Jeong","year":"2018","journal-title":"CoRR"},{"key":"2026033012251646900_ref211","article-title":"Wireless network intelligence at the edge","volume":"abs\/1812.02858","author":"Park","year":"2018","journal-title":"CoRR"},{"key":"2026033012251646900_ref212","article-title":"Federated learning for ultra-reliable low-latency V2V communications","volume":"abs\/1805.09253","author":"Samarakoon","year":"2018","journal-title":"CoRR"},{"key":"2026033012251646900_ref213","article-title":"Over-the-air function computation in sensor networks","volume":"abs\/1612.02307","author":"Abari","year":"2016","journal-title":"CoRR"},{"key":"2026033012251646900_ref214","doi-asserted-by":"crossref","DOI":"10.1109\/TCOMM.2021.3078783","article-title":"Harnessing wireless channels for scalable and privacy-preserving federated learning","volume-title":"IEEE Trans. Comm.","author":"Elgabli"},{"key":"2026033012251646900_ref215","article-title":"Decentralized online learning: Take benefits from others\u2019 data without sharing your own to track global trend","volume-title":"arXiv preprint","author":"Zhao","year":"2019"},{"key":"2026033012251646900_ref216","article-title":"A comprehensive guide to Bayesian convolutional neural network with variational inference","volume-title":"arXiv preprint","author":"Shridhar","year":"2019"},{"key":"2026033012251646900_ref217","article-title":"Decentralized Bayesian learning over graphs","volume-title":"arXiv preprint","author":"Lalitha","year":"2019"},{"key":"2026033012251646900_ref218","article-title":"Privacy in deep learning: A survey","volume-title":"arXiv preprint","author":"Mireshghallah","year":"2020"},{"key":"2026033012251646900_ref219","doi-asserted-by":"publisher","first-page":"441","DOI":"10.1145\/3132747.3132769","volume-title":"Prochlo: Strong privacy for analytics in the crowd","author":"Bittau"},{"key":"2026033012251646900_ref220","unstructured":"NSA\n          , Defense in depth: A practical strategy for achieving Information Assurance in today\u2019s highly networked environments, 2012. [Online]. Available: https:\/\/apps.nsa.gov\/iaarchive\/library\/ia-guidance\/archive\/defense-in-depth.cfm."},{"key":"2026033012251646900_ref221","first-page":"162","volume-title":"How to generate and exchange secrets (extended abstract)","author":"Andrew"},{"key":"2026033012251646900_ref222","first-page":"805","volume-title":"High-throughput semi-honest secure three-party computation with an honest majority","author":"Araki"},{"key":"2026033012251646900_ref223","first-page":"325","volume-title":"Secure multiparty computation goes live","author":"Bogetoft"},{"key":"2026033012251646900_ref224","first-page":"57","volume-title":"Deploying secure multi-party computation for financial data analysis - (short paper)","author":"Bogdanov"},{"key":"2026033012251646900_ref225","first-page":"73","volume-title":"Secure MPC for analytics as a web application","author":"Lapets"},{"key":"2026033012251646900_ref226","first-page":"225","volume-title":"High-throughput secure three-party computation for malicious adversaries and an honest majority","author":"Furukawa"},{"key":"2026033012251646900_ref227","first-page":"738","article-title":"Private intersection-sum protocol with applications to attributing aggregate ad conversions","volume-title":"IACR Cryptology ePrint Archive","author":"Ion","year":"2017"},{"key":"2026033012251646900_ref228","first-page":"723","article-title":"On deploying secure computing commercially: Private intersection-sum protocols and their business applications","volume":"2019","author":"Ion","year":"2019","journal-title":"IACR Cryptology ePrint Archive"},{"key":"2026033012251646900_ref229","first-page":"145","volume-title":"Extending oblivious transfers efficiently","author":"Ishai"},{"key":"2026033012251646900_ref230","first-page":"483","volume-title":"Fast ho-momorphic evaluation of deep discretized neural networks","author":"Bourse"},{"key":"2026033012251646900_ref231","first-page":"201","volume-title":"CryptoNets: Applying neural networks to encrypted data with high throughput and accuracy","author":"Gilad-Bachrach"},{"issue":"4","key":"2026033012251646900_ref232","doi-asserted-by":"crossref","first-page":"345","DOI":"10.1515\/popets-2017-0053","article-title":"Privacy-preserving distributed linear regression on high-dimensional data","volume":"2017","author":"Gasc\u00f3n","year":"2017","journal-title":"PoPETs"},{"key":"2026033012251646900_ref233","doi-asserted-by":"crossref","volume-title":"QUOTIENT: Two-party secure neural network training and prediction","author":"Agrawal","DOI":"10.1145\/3319535.3339819"},{"key":"2026033012251646900_ref234","doi-asserted-by":"publisher","first-page":"218","DOI":"10.1145\/28395.28420","volume-title":"How to play any mental game","author":"Goldreich"},{"key":"2026033012251646900_ref235","first-page":"334","volume-title":"Privacy-preserving ridge regression on hundreds of millions of records","author":"Nikolaenko"},{"key":"2026033012251646900_ref236","first-page":"19","volume-title":"SecureML: A system for scalable privacy-preserving machine learning","author":"Mohassel"},{"key":"2026033012251646900_ref237","first-page":"131","article-title":"Secure evaluation of quantized neural networks","volume":"2019","author":"Barak","year":"2019","journal-title":"IACR Cryptology ePrint Archive"},{"key":"2026033012251646900_ref238","first-page":"169","volume-title":"Fully homomorphic encryption using ideal lattices","author":"Gentry"},{"key":"2026033012251646900_ref239","first-page":"868","volume-title":"Fully homomorphic encryption without modulus switching from classical GapSVP","author":"Brakerski"},{"key":"2026033012251646900_ref240","first-page":"144","article-title":"Somewhat practical fully homomorphic encryption","volume":"2012","author":"Fan","year":"2012","journal-title":"IACR Cryptology ePrint Archive"},{"key":"2026033012251646900_ref241","first-page":"309","volume-title":"(leveled) Fully homomorphic encryption without bootstrapping","author":"Brakerski"},{"key":"2026033012251646900_ref242","first-page":"311","volume-title":"Scale-invariant fully homomorphic encryption over the integers","author":"Coron"},{"key":"2026033012251646900_ref243","unstructured":"HElib, https:\/\/github.com\/homenc\/HElib, Oct.2019."},{"key":"2026033012251646900_ref244","volume-title":"Lattigo 2.0.0","year":"2020"},{"key":"2026033012251646900_ref245","unstructured":"PALISADE lattice cryptography library, https:\/\/gitlab.com\/palisade\/palisade-release, Oct.2019."},{"key":"2026033012251646900_ref246","volume-title":"Microsoft SEAL (release 3.6)","year":"2020"},{"key":"2026033012251646900_ref247","volume-title":"SHELL","year":"2020"},{"key":"2026033012251646900_ref248","article-title":"A review of homomorphic encryption libraries for secure computation","volume-title":"arXiv preprint","author":"Sathya","year":"2018"},{"key":"2026033012251646900_ref249","first-page":"239","volume-title":"On key recovery attacks against existing somewhat homomorphic encryption schemes","author":"Chenal"},{"key":"2026033012251646900_ref250","first-page":"997","article-title":"Turning HATE into LOVE: Homomorphic ad hoc threshold encryption for scalable MPC","volume":"2018","author":"Reyzin","year":"2018","journal-title":"IACR Cryptology ePrint Archive"},{"key":"2026033012251646900_ref251","first-page":"196","volume-title":"Honeycrisp: Large-scale differentially private aggregation without a trusted core","author":"Roth"},{"key":"2026033012251646900_ref252","first-page":"2435","volume-title":"A formal foundation for secure remote execution of enclaves","author":"Subramanyan"},{"key":"2026033012251646900_ref253","article-title":"Architecture instruction set extensions programming reference","volume-title":"Intel Corporation","author":"Intel","year":"2012"},{"issue":"086","key":"2026033012251646900_ref254","first-page":"1","article-title":"Intel SGX explained","volume":"2016","author":"Costan","year":"2016","journal-title":"IACR Cryptology ePrint Archive"},{"key":"2026033012251646900_ref255","unstructured":"Arm trustzone\n          , Arm Trust Zone Technology, https:\/\/developer.arm.com\/ip-products\/security-ip\/trustzone(accessed Dec. 5, 2019)."},{"key":"2026033012251646900_ref256","unstructured":"Android trusty\n          , Android trusty TEE, https:\/\/source.android.com\/security\/trusty(accessed Dec. 5, 2019)."},{"key":"2026033012251646900_ref257","first-page":"857","volume-title":"Sanctum: Minimal hardware extensions for strong software isolation","author":"Costan"},{"key":"2026033012251646900_ref258","volume-title":"Slalom: Fast, verifiable and private execution of neural networks in trusted hardware","author":"Tram\u00e8r"},{"key":"2026033012251646900_ref259","first-page":"991","volume-title":"Foreshadow: Extracting the keys to the intel SGX kingdom with transient out-of-order execution","author":"Van Bulck"},{"key":"2026033012251646900_ref260","first-page":"118","volume-title":"I have a DREAM!: DiffeRentially privatE smArt Metering","author":"\u00c1cs"},{"key":"2026033012251646900_ref261","article-title":"Turbo-aggregate: Breaking the quadratic aggregation barrier in secure federated learning","volume-title":"arXiv preprint","author":"So","year":"2020"},{"issue":"5","key":"2026033012251646900_ref262","doi-asserted-by":"crossref","first-page":"463","DOI":"10.1109\/TDSC.2015.2484326","article-title":"A comprehensive comparison of multiparty secure additions with differential privacy","volume":"14","author":"Goryczka","year":"2017","journal-title":"IEEE Trans. Dependable Sec. Comput."},{"key":"2026033012251646900_ref263","first-page":"200","volume-title":"Privacy-preserving stream aggregation with fault tolerance","author":"Chan"},{"key":"2026033012251646900_ref264","first-page":"132","volume-title":"Secure computation on the web: Computing without simultaneous interaction","author":"Halevi"},{"key":"2026033012251646900_ref265","volume-title":"Privacy-preserving aggregation of time-series data","author":"Shi"},{"issue":"101101","key":"2026033012251646900_ref266","article-title":"SEPIA: Privacy-preserving aggregation of multi-domain network events and statistics","volume":"1","author":"Burkhart","year":"2010","journal-title":"Network"},{"key":"2026033012251646900_ref267","first-page":"259","volume-title":"Prio: Private, robust, and scalable computation of aggregate statistics","author":"Corrigan-Gibbs"},{"key":"2026033012251646900_ref268","first-page":"94","volume-title":"Glimmers: Resolving the privacy\/trust quagmire","author":"Lie"},{"issue":"2","key":"2026033012251646900_ref269","doi-asserted-by":"crossref","DOI":"10.1145\/358549.358563","article-title":"Untraceable electronic mail, return addresses, and digital pseudonyms","volume":"24","author":"Chaum","year":"1981","journal-title":"Communications of the ACM"},{"issue":"2","key":"2026033012251646900_ref270","doi-asserted-by":"crossref","first-page":"115","DOI":"10.1515\/popets-2016-0008","article-title":"Riffle","volume":"2016","author":"Kwon","year":"2016","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"2026033012251646900_ref271","doi-asserted-by":"crossref","DOI":"10.21236\/ADA465464","volume-title":"Tor: The second-generation onion router","author":"Dingledine","year":"2004"},{"key":"2026033012251646900_ref272","first-page":"364","volume-title":"Replication is not needed: Single database, computationally-private information retrieval","author":"Kushilevitz"},{"issue":"6","key":"2026033012251646900_ref273","doi-asserted-by":"crossref","first-page":"965","DOI":"10.1145\/293347.293350","article-title":"Private information retrieval","volume":"45","author":"Chor","year":"1998","journal-title":"J. ACM"},{"key":"2026033012251646900_ref274","first-page":"2006","volume-title":"On the computational practicality of private information retrieval","author":"Sion"},{"key":"2026033012251646900_ref275","article-title":"A lattice-based computationally-efficient private information retrieval protocol","volume-title":"Cryptol. ePrint Arch., Report","author":"Aguilar-Melchor","year":"2007"},{"issue":"2","key":"2026033012251646900_ref276","doi-asserted-by":"crossref","first-page":"155","DOI":"10.1515\/popets-2016-0010","article-title":"XPIR: Private information retrieval for everyone","volume":"2016","author":"Aguilar-Melchor","year":"2016","journal-title":"Proceedings on Privacy Enhancing Technologies"},{"key":"2026033012251646900_ref277","first-page":"962","volume-title":"PIR with compressed queries and amortized query processing","author":"Angel"},{"key":"2026033012251646900_ref278","first-page":"438","volume-title":"Compressible FHE with applications to PIR","author":"Gentry"},{"key":"2026033012251646900_ref279","first-page":"158","volume-title":"Revisiting the computational practicality of private information retrieval","author":"Olumofin"},{"key":"2026033012251646900_ref280","first-page":"1483","article-title":"Communication-computation trade-offs in PIR","volume":"2019","author":"Ali","year":"2019","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"2026033012251646900_ref281","doi-asserted-by":"publisher","first-page":"1099","DOI":"10.1109\/ALLERTON.2017.8262860","volume-title":"Private information retrieval with side information: The single server case","author":"Kadhe"},{"key":"2026033012251646900_ref282","doi-asserted-by":"publisher","first-page":"1002","DOI":"10.1145\/3243734.3243821","volume-title":"Private stateful information retrieval","author":"Patel"},{"key":"2026033012251646900_ref283","first-page":"1075","article-title":"Private information retrieval with sublinear online time","volume":"2019","author":"Corrigan-Gibbs","year":"2019","journal-title":"IACR Cryptology ePrint Archive"},{"key":"2026033012251646900_ref284","doi-asserted-by":"publisher","first-page":"275","DOI":"10.1109\/CCC.2005.2","volume-title":"A geometric approach to information-theoretic private information retrieval","author":"Woodruff"},{"key":"2026033012251646900_ref285","doi-asserted-by":"publisher","first-page":"1744","DOI":"10.1109\/ISIT.2018.8437805","volume-title":"Lifting private information retrieval from two to any number of messages","author":"D\u2019Oliveira"},{"key":"2026033012251646900_ref286","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/ITW.2018.8613532","volume-title":"Staircase-PIR: Universally robust private information retrieval","author":"Bitar"},{"key":"2026033012251646900_ref287","first-page":"1011","article-title":"Private join and compute from PIR with default","volume":"2020","author":"Lepoint","year":"2020","journal-title":"IACR Cryptol. ePrint Arch."},{"key":"2026033012251646900_ref288","doi-asserted-by":"crossref","volume-title":"ON-OFF privacy with correlated requests","author":"Naim","DOI":"10.1109\/ISIT.2019.8849461"},{"key":"2026033012251646900_ref289","doi-asserted-by":"crossref","volume-title":"Preserving ON-OFF privacy for past and future requests","author":"Ye","DOI":"10.1109\/ITW44776.2019.8989319"},{"key":"2026033012251646900_ref290","doi-asserted-by":"publisher","first-page":"265","DOI":"10.1007\/11681878_14","volume-title":"Calibrating noise to sensitivity in private data analysis","author":"Dwork"},{"key":"2026033012251646900_ref291","first-page":"1","volume-title":"Differential privacy: A survey of results","author":"Dwork"},{"issue":"3-4","key":"2026033012251646900_ref292","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1561\/0400000042","article-title":"The algorithmic foundations of differential privacy","volume":"9","author":"Dwork","year":"2014","journal-title":"Foundations and Trends in Theoretical Computer Science"},{"issue":"309","key":"2026033012251646900_ref293","doi-asserted-by":"crossref","first-page":"63","DOI":"10.1080\/01621459.1965.10480775","article-title":"Randomized response: A survey technique for eliminating evasive answer bias","volume":"60","author":"Warner","year":"1965","journal-title":"J. Am. Stat. Assoc."},{"issue":"3","key":"2026033012251646900_ref294","doi-asserted-by":"crossref","first-page":"793","DOI":"10.1137\/090756090","article-title":"What can we learn privately?","volume":"40","author":"Kasiviswanathan","year":"2011","journal-title":"SIAM J. Comput."},{"key":"2026033012251646900_ref295","volume-title":"Collecting telemetry data privately","author":"Ding"},{"key":"2026033012251646900_ref296","article-title":"Differentially-private \u2018draw and discard\u2019 machine learning","volume":"abs\/1807.04369","author":"Pihur","year":"2018","journal-title":"CoRR"},{"key":"2026033012251646900_ref297","unstructured":"J.\n              Ullman\n            \n          , Tight lower bounds for locally differentially private selection, Tech. Rep., abs\/1802.02638, 2018. [Online]. Available: http:\/\/arxiv.org\/abs\/1802.02638."},{"key":"2026033012251646900_ref298","first-page":"375","volume-title":"Distributed differential privacy via shuffling","author":"Cheu"},{"key":"2026033012251646900_ref299","first-page":"486","volume-title":"Our data, ourselves: Privacy via distributed noise generation","author":"Dwork"},{"key":"2026033012251646900_ref300","article-title":"Distributed differentially private averaging with improved utility and robustness to malicious parties","volume-title":"arXiv preprint","author":"Sabater","year":"2020"},{"key":"2026033012251646900_ref301","first-page":"351","volume-title":"Universally utility-maximizing privacy mechanisms","author":"Ghosh"},{"key":"2026033012251646900_ref302","first-page":"735","volume-title":"Differentially private aggregation of distributed time-series with transformation and encryption","author":"Rastogi"},{"key":"2026033012251646900_ref303","first-page":"2468","volume-title":"Amplification by shuffling: From local to central differential privacy via anonymity","author":"Erlingsson"},{"key":"2026033012251646900_ref304","doi-asserted-by":"publisher","first-page":"638","DOI":"10.1007\/978-3-030-26951-7\\_22","volume-title":"The privacy blanket of the shuffle model","author":"Balle"},{"key":"2026033012251646900_ref305","volume-title":"On distributed differential privacy and counting distinct elements","author":"Chen"},{"key":"2026033012251646900_ref306","volume-title":"Private counting from anonymous messages: Near-optimal accuracy with vanishing communication overhead","author":"Ghazi"},{"key":"2026033012251646900_ref307","article-title":"Scalable and differentially private distributed aggregation in the shuffled model","volume-title":"arXiv preprint","author":"Ghazi","year":"2019"},{"key":"2026033012251646900_ref308","first-page":"798","volume-title":"Private aggregation from fewer anonymous messages","author":"Ghazi"},{"key":"2026033012251646900_ref309","article-title":"On the power of multiple anonymous messages","volume-title":"arXiv:1908. 11358","author":"Ghazi","year":"2019"},{"key":"2026033012251646900_ref310","first-page":"15:1","volume-title":"Pure differentially private summation from anonymous messages","author":"Ghazi"},{"key":"2026033012251646900_ref311","first-page":"747","volume-title":"BLENDER: Enabling local search with a hybrid differential privacy model","author":"Avent"},{"key":"2026033012251646900_ref312","volume-title":"The power of synergy in differential privacy: Combining a small curator with local randomizers","author":"Beimel"},{"key":"2026033012251646900_ref313","first-page":"21","volume-title":"Checking computations in polylogarithmic time","author":"Babai"},{"issue":"4","key":"2026033012251646900_ref314","doi-asserted-by":"crossref","first-page":"1253","DOI":"10.1137\/S0097539795284959","article-title":"Computationally sound proofs","volume":"30","author":"Micali","year":"2000","journal-title":"SIAM J. Comput."},{"key":"2026033012251646900_ref315","first-page":"113","volume-title":"Delegating computation: Interactive proofs for muggles","author":"Goldwasser"},{"key":"2026033012251646900_ref316","first-page":"465","volume-title":"Non-interactive verifiable computing: Outsourcing computation to untrusted workers","author":"Gennaro"},{"issue":"1","key":"2026033012251646900_ref317","doi-asserted-by":"crossref","first-page":"186","DOI":"10.1137\/0218012","article-title":"The knowledge complexity of interactive proof systems","volume":"18","author":"Goldwasser","year":"1989","journal-title":"SIAM J. Comput."},{"issue":"2","key":"2026033012251646900_ref318","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1145\/2856449","article-title":"Pinocchio: Nearly practical verifiable computation","volume":"59","author":"Parno","year":"2016","journal-title":"Commun. ACM"},{"key":"2026033012251646900_ref319","volume-title":"Efficient identification and signatures for smart cards","author":"Schnorr"},{"key":"2026033012251646900_ref320","unstructured":"Damg\u00e5rd\n          , On \u03c3 protocols, http:\/\/www.cs.au.dk\/~ivan\/Sigma.pdf, 2010."},{"key":"2026033012251646900_ref321","doi-asserted-by":"crossref","volume-title":"From extractable collision resistance to succinct non-interactive arguments of knowledge, and back again","author":"Bitansky","DOI":"10.1145\/2090236.2090263"},{"key":"2026033012251646900_ref322","first-page":"626","volume-title":"Quadratic span programs and succinct NIZKs without PCPs","author":"Gennaro"},{"key":"2026033012251646900_ref323","first-page":"253","volume-title":"Geppetto: Versatile verifiable computation","author":"Costello"},{"key":"2026033012251646900_ref324","unstructured":"libsnark: A c++ library for zkSNARK proofs, https:\/\/github.com\/scipr-lab\/libsnark, Dec.2019."},{"key":"2026033012251646900_ref325","first-page":"459","volume-title":"Zerocash: Decentralized anonymous payments from bitcoin","author":"Ben-Sasson"},{"key":"2026033012251646900_ref326","first-page":"733","volume-title":"Libra: Succinct zero-knowledge proofs with optimal prover computation","author":"Xie"},{"key":"2026033012251646900_ref327","doi-asserted-by":"crossref","volume-title":"Ligero: Lightweight sublinear arguments without a trusted setup","author":"Ames","DOI":"10.1145\/3133956.3134104"},{"key":"2026033012251646900_ref328","volume-title":"Bulletproofs: Short proofs for confidential transactions and more","author":"B\u00fcnz"},{"key":"2026033012251646900_ref329","doi-asserted-by":"crossref","volume-title":"Doubly-efficient zksnarks without trusted setup","author":"Wahby","DOI":"10.1109\/SP.2018.00060"},{"key":"2026033012251646900_ref330","first-page":"701","volume-title":"Scalable zero knowledge with no trusted setup","author":"Ben-Sasson"},{"key":"2026033012251646900_ref331","first-page":"67","volume-title":"Zero-knowledge proofs on secret-shared data via fully linear PCPs","author":"Boneh"},{"key":"2026033012251646900_ref332","first-page":"19","volume-title":"Sealed-glass proofs: Using transparent enclaves to prove and sell knowledge","author":"Tram\u00e8r"},{"key":"2026033012251646900_ref333","first-page":"253","volume-title":"Pioneer: Verifying code integrity and enforcing untampered code execution on legacy systems","author":"Seshadri"},{"key":"2026033012251646900_ref334","volume-title":"SMART: Secure and minimal architecture for (establishing dynamic) root of trust","author":"Eldefrawy"},{"key":"2026033012251646900_ref335","first-page":"10:1","volume-title":"TrustLite: A security architecture for tiny embedded devices","author":"Koeberl"},{"key":"2026033012251646900_ref336","first-page":"1","volume-title":"A minimalist approach to remote attestation","author":"Francillon"},{"key":"2026033012251646900_ref337","article-title":"The secret sharer: Measuring unintended neural network memorization and extracting secrets","volume-title":"arXiv preprint","author":"Carlini","year":"2018"},{"key":"2026033012251646900_ref338","article-title":"Extracting training data from large language models","volume-title":"arXiv preprint","author":"Carlini","year":"2020"},{"key":"2026033012251646900_ref339","first-page":"1322","volume-title":"Model inversion attacks that exploit confidence information and basic counter-measures","author":"Fredrikson"},{"key":"2026033012251646900_ref340","article-title":"Exploiting unintended feature leakage in collaborative learning","volume-title":"arXiv preprint","author":"Melis","year":"2018"},{"key":"2026033012251646900_ref341","first-page":"3","volume-title":"Membership inference attacks against machine learning models","author":"Shokri"},{"key":"2026033012251646900_ref342","first-page":"268","volume-title":"Privacy risk in machine learning: Analyzing the connection to overfitting","author":"Yeom"},{"key":"2026033012251646900_ref343","article-title":"Theoretical guarantees for model auditing with finite adversaries","volume-title":"arXiv preprint","author":"Diaz","year":"2019"},{"key":"2026033012251646900_ref344","article-title":"Protection against reconstruction and its applications in private federated learning","volume-title":"arXiv preprint","author":"Bhowmick","year":"2018"},{"key":"2026033012251646900_ref345","article-title":"A general approach to adding differential privacy to iterative training procedures","volume-title":"arXiv preprint","author":"McMahan","year":"2018"},{"key":"2026033012251646900_ref346","first-page":"51","volume-title":"Boosting and differential privacy","author":"Dwork"},{"issue":"6","key":"2026033012251646900_ref347","doi-asserted-by":"crossref","first-page":"4037","DOI":"10.1109\/TIT.2017.2685505","article-title":"The composition theorem for differential privacy","volume":"63","author":"Kairouz","year":"2017","journal-title":"IEEE Trans. Inform. Theor."},{"key":"2026033012251646900_ref348","first-page":"263","volume-title":"R\u00e9nyi differential privacy","author":"Mironov"},{"key":"2026033012251646900_ref349","article-title":"R\u00e9nyi differential privacy of the sampled Gaussian mechanism","volume-title":"arXiv preprint","author":"Mironov","year":"2019"},{"key":"2026033012251646900_ref350","article-title":"Subsampled R\u00e9nyi differential privacy and analytical moments accountant","volume-title":"arXiv preprint","author":"Wang","year":"2018"},{"key":"2026033012251646900_ref351","article-title":"Training production language models without memorizing user data","volume-title":"arXiv preprint","author":"Ramaswamy","year":"2020"},{"key":"2026033012251646900_ref352","article-title":"Tempered sigmoid activations for deep learning with differential privacy","volume-title":"arXiv preprint","author":"Papernot","year":"2020"},{"key":"2026033012251646900_ref353","article-title":"Differentially private learning needs better features (or much more data)","volume-title":"arXiv preprint","author":"Tram\u00e8r","year":"2020"},{"key":"2026033012251646900_ref354","first-page":"263","volume-title":"Bounding user contributions: A bias-variance trade-off in differential privacy","author":"Amin"},{"key":"2026033012251646900_ref355","article-title":"AdaCliP: Adaptive clipping for private SGD","volume-title":"arXiv preprint","author":"Pichapati","year":"2019"},{"key":"2026033012251646900_ref356","first-page":"20965","volume-title":"Learning discrete distributions: User vs item-level privacy","author":"Liu"},{"key":"2026033012251646900_ref357","first-page":"521","volume-title":"Privacy amplification by iteration","author":"Feldman"},{"key":"2026033012251646900_ref358","first-page":"4623","volume-title":"Advances in Neural Information Processing Systems","author":"Balle"},{"key":"2026033012251646900_ref359","volume-title":"Practical and private (deep) learning without sampling or shuffling","author":"Kairouz","year":"2021"},{"key":"2026033012251646900_ref360","first-page":"16","volume-title":"Parallel random numbers: As easy as 1, 2, 3","author":"Salmon"},{"key":"2026033012251646900_ref361","first-page":"126","volume-title":"Computational differential privacy","author":"Mironov"},{"key":"2026033012251646900_ref362","volume-title":"Differential privacy under fire.","author":"Haeberlen"},{"key":"2026033012251646900_ref363","first-page":"650","volume-title":"On significance of the least significant bits for differential privacy","author":"Mironov"},{"key":"2026033012251646900_ref364","first-page":"475","volume-title":"Detecting violations of differential privacy","author":"Ding"},{"key":"2026033012251646900_ref365","first-page":"22205","volume-title":"Auditing differentially private machine learning: How private is private SGD?","author":"Jagielski"},{"key":"2026033012251646900_ref366","article-title":"Minimax rates of estimating approximate differential privacy","volume-title":"arXiv preprint","author":"Liu","year":"2019"},{"key":"2026033012251646900_ref367","article-title":"HEAX: High-performance architecture for computation on homomorphically encrypted data in the cloud","volume-title":"arXiv preprint","author":"Riazi","year":"2019"},{"key":"2026033012251646900_ref368","first-page":"10825","volume-title":"Differentially private change-point detection","author":"Cummings"},{"key":"2026033012251646900_ref369","first-page":"8864","volume-title":"Differential privacy for growing databases","author":"Cummings"},{"key":"2026033012251646900_ref370","doi-asserted-by":"crossref","DOI":"10.1145\/3313276.3316336","article-title":"The structure of optimal private tests for simple hypotheses","volume-title":"arXiv preprint","author":"Canonne","year":"2019"},{"key":"2026033012251646900_ref371","first-page":"510","volume-title":"Privacy preserving synthetic data release using deep learning","author":"Abay"},{"key":"2026033012251646900_ref372","first-page":"601","volume-title":"Stealing machine learning models via prediction APIs","author":"Tram\u00e8r"},{"key":"2026033012251646900_ref373","first-page":"251","volume-title":"The sybil attack","author":"Douceur"},{"issue":"16","key":"2026033012251646900_ref374","first-page":"1","article-title":"Practical locally private heavy hitters","volume":"21","author":"Bassily","year":"2020","journal-title":"J. Mach. Learn. Res."},{"key":"2026033012251646900_ref375","first-page":"131","volume-title":"Marginal release under local differential privacy","author":"Cormode"},{"key":"2026033012251646900_ref376","first-page":"429","volume-title":"Local privacy and statistical minimax rates","author":"Duchi"},{"key":"2026033012251646900_ref377","first-page":"2879","volume-title":"Extremal mechanisms for local differential privacy","author":"Kairouz"},{"key":"2026033012251646900_ref378","first-page":"2436","volume-title":"Discrete distribution estimation under local privacy","author":"Kairouz"},{"key":"2026033012251646900_ref379","doi-asserted-by":"crossref","DOI":"10.1109\/TIT.2018.2809790","article-title":"Optimal schemes for discrete distribution estimation under locally differential privacy","volume-title":"IEEE Trans. Inform. Theor.","author":"Ye","year":"2018"},{"key":"2026033012251646900_ref380","article-title":"Privacy loss in Apple\u2019s implementation of differential privacy on MacOS 10.12","volume":"abs\/1709.02753","author":"Tang","year":"2017","journal-title":"CoRR"},{"issue":"4","key":"2026033012251646900_ref381","doi-asserted-by":"crossref","first-page":"48","DOI":"10.2478\/popets-2020-0062","article-title":"The power of the hybrid model for mean estimation","volume":"2020","author":"Avent","year":"2020","journal-title":"Proceedings on Privacy Enhancing Technologies (PETS)"},{"key":"2026033012251646900_ref382","volume-title":"Communication Complexity","author":"Kushilevitz","year":"1997"},{"key":"2026033012251646900_ref383","first-page":"3312","volume-title":"Breaking the communication-privacy-accuracy trilemma","author":"Chen"},{"key":"2026033012251646900_ref384","first-page":"657","volume-title":"Private summation in the multi-message shuffle model","author":"Balle"},{"key":"2026033012251646900_ref385","first-page":"127","volume-title":"Local, private, efficient protocols for succinct histograms","author":"Bassily"},{"key":"2026033012251646900_ref386","first-page":"94","volume-title":"Mechanism design via differential privacy.","author":"McSherry"},{"key":"2026033012251646900_ref387","first-page":"552","volume-title":"Tight lower bounds for differentially private selection","author":"Steinke"},{"key":"2026033012251646900_ref388","article-title":"Shuffled model of federated learning: Privacy, communication and accuracy trade-offs","volume-title":"arXiv preprint","author":"Girgis","year":"2020"},{"key":"2026033012251646900_ref389","article-title":"The distributed discrete gaussian mechanism for federated learning with secure aggregation","volume-title":"arXiv preprint","author":"Kairouz","year":"2021"},{"key":"2026033012251646900_ref390","doi-asserted-by":"crossref","DOI":"10.1109\/ITW44776.2019.8989342","article-title":"On the upload versus download cost for secure and private matrix multiplication","volume-title":"ArXiv, abs\/1906.10684","author":"Chang","year":"2019"},{"key":"2026033012251646900_ref391","article-title":"On the capacity of secure distributed matrix multiplication","volume":"abs\/1908.06957","author":"Jia","year":"2019","journal-title":"CoRR"},{"key":"2026033012251646900_ref392","article-title":"Secure federated submodel learning","volume-title":"arXiv preprint","author":"Niu","year":"2019"},{"key":"2026033012251646900_ref393","article-title":"Privacy for the protected (only)","volume":"abs\/1506.00242","author":"Kearns","year":"2015","journal-title":"CoRR"},{"issue":"1","key":"2026033012251646900_ref394","doi-asserted-by":"crossref","first-page":"3:1","DOI":"10.1145\/2514689","article-title":"Pufferfish: A framework for mathematical privacy definitions","volume":"39","author":"Kifer","year":"2014","journal-title":"ACM Trans. Database Sys."},{"issue":"1","key":"2026033012251646900_ref395","doi-asserted-by":"crossref","first-page":"171","DOI":"10.1257\/aer.20170627","article-title":"An economic analysis of privacy protection and statistical accuracy as social choices","volume":"109","author":"Abowd","year":"2019","journal-title":"Am. Econ. Rev."},{"key":"2026033012251646900_ref396","article-title":"Bringing differential privacy into the experimental economics lab: Theory and an application to a public-good game","volume-title":"Working paper","author":"Cummings","year":"2019"},{"key":"2026033012251646900_ref397","first-page":"1467","volume-title":"Poisoning attacks against support vector machines","author":"Biggio"},{"key":"2026033012251646900_ref398","doi-asserted-by":"crossref","volume-title":"Trojaning attack on neural networks","author":"Liu","DOI":"10.14722\/ndss.2018.23291"},{"key":"2026033012251646900_ref399","article-title":"How to backdoor federated learning","volume-title":"arXiv preprint","author":"Bagdasaryan","year":"2018"},{"key":"2026033012251646900_ref400","first-page":"634","volume-title":"Analyzing federated learning through an adversarial lens","author":"Bhagoji"},{"key":"2026033012251646900_ref401","volume-title":"Explaining and harnessing adversarial examples","author":"Goodfellow"},{"key":"2026033012251646900_ref402","article-title":"Intriguing properties of neural networks","volume-title":"ICLR","author":"Szegedy","year":"2013"},{"key":"2026033012251646900_ref403","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","volume-title":"arXiv preprint","author":"Chen","year":"2017"},{"key":"2026033012251646900_ref404","volume-title":"Byzantine stochastic gradient descent","author":"Alistarh"},{"key":"2026033012251646900_ref405","first-page":"118","volume-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","author":"Blanchard"},{"key":"2026033012251646900_ref406","first-page":"44:1","article-title":"Distributed statistical machine learning in adversarial settings: Byzantine gradient descent","volume":"1","author":"Chen","year":"2017","journal-title":"POMACS"},{"key":"2026033012251646900_ref407","volume-title":"DRACO: Byzantine-resilient distributed training via redundant gradients","author":"Chen"},{"key":"2026033012251646900_ref408","volume-title":"The hidden vulnerability of distributed learning in Byzantium","author":"El Mhamdi"},{"key":"2026033012251646900_ref409","first-page":"81","volume-title":"Casting out demons: Sanitizing training data for anomaly sensors","author":"Cretu"},{"key":"2026033012251646900_ref410","first-page":"3517","volume-title":"Certified defenses for data poisoning attacks","author":"Steinhardt"},{"key":"2026033012251646900_ref411","first-page":"1596","volume-title":"Sever: A robust meta-algorithm for stochastic optimization","author":"Diakonikolas"},{"key":"2026033012251646900_ref412","first-page":"387","volume-title":"Evasion attacks against machine learning at test time","author":"Biggio"},{"key":"2026033012251646900_ref413","first-page":"39","volume-title":"Towards evaluating the robustness of neural networks","author":"Carlini"},{"key":"2026033012251646900_ref414","article-title":"Explaining and harnessing adversarial examples","volume-title":"ICLR","author":"Goodfellow","year":"2015"},{"key":"2026033012251646900_ref415","article-title":"Towards deep learning models resistant to adversarial attacks","volume-title":"ICLR","author":"Madry","year":"2017"},{"issue":"3","key":"2026033012251646900_ref416","doi-asserted-by":"crossref","first-page":"382","DOI":"10.1145\/357172.357176","article-title":"The Byzantine generals problem","volume":"4","author":"Lamport","year":"1982","journal-title":"ACM Trans. Program. Lang. Syst."},{"key":"2026033012251646900_ref417","volume-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","author":"Yin"},{"key":"2026033012251646900_ref418","doi-asserted-by":"crossref","volume-title":"Fault-Tolerant Multi-Agent Optimization: Optimal Iterative Distributed Algorithms","author":"Su","DOI":"10.1145\/2933057.2933105"},{"key":"2026033012251646900_ref419","doi-asserted-by":"crossref","volume-title":"Byzantine-resilient secure federated learning","author":"So","DOI":"10.1109\/JSAC.2020.3041404"},{"key":"2026033012251646900_ref420","article-title":"Robust aggregation for federated learning","volume-title":"arXiv preprint","author":"Pillutla","year":"2019"},{"key":"2026033012251646900_ref421","volume-title":"Practical distributed learning: Secure machine learning with communication-efficient local updates","author":"Xie"},{"key":"2026033012251646900_ref422","article-title":"Local model poisoning attacks to Byzantine-robust federated learning","volume-title":"arXiv preprint","author":"Fang","year":"2019"},{"key":"2026033012251646900_ref423","article-title":"A little is enough: Circumventing defenses for distributed learning","volume-title":"arXiv preprint","author":"Baruch","year":"2019"},{"key":"2026033012251646900_ref424","article-title":"DETOX: A redundancy-based framework for faster and more robust gradient aggregation","volume-title":"arXiv preprint","author":"Rajput","year":"2019"},{"key":"2026033012251646900_ref425","first-page":"2719","article-title":"Data encoding for byzantine-resilient distributed optimization","volume-title":"IEEE Trans. Inform. Theor.","author":"Data","year":"2020"},{"key":"2026033012251646900_ref426","article-title":"Backdoor attacks on federated meta-learning","volume-title":"arXiv preprint","author":"Chen","year":"2020"},{"key":"2026033012251646900_ref427","article-title":"SentiNet: Detecting physical attacks against deep learning systems","volume-title":"arXiv preprint","author":"Chou","year":"2018"},{"key":"2026033012251646900_ref428","first-page":"273","volume-title":"Fine-pruning: Defending against backdooring attacks on deep neural networks","author":"Liu"},{"key":"2026033012251646900_ref429","first-page":"5739","volume-title":"Learning with bad training data via iterative trimmed loss minimization","author":"Shen"},{"key":"2026033012251646900_ref430","first-page":"8000","volume-title":"Spectral signatures in backdoor attacks","author":"Tran"},{"key":"2026033012251646900_ref431","volume-title":"Neural cleanse: Identifying and mitigating backdoor attacks in neural networks","author":"Wang"},{"key":"2026033012251646900_ref432","article-title":"Mitigating sybils in federated learning poisoning","volume-title":"arXiv preprint","author":"Fung","year":"2018"},{"key":"2026033012251646900_ref433","first-page":"1885","volume-title":"Understanding black-box predictions via influence functions","author":"Koh"},{"key":"2026033012251646900_ref434","first-page":"6893","volume-title":"Zeno: Distributed stochastic gradient descent with suspicion-based fault-tolerance","author":"Xie"},{"key":"2026033012251646900_ref435","article-title":"Zeno++: Robust asynchronous SGD with arbitrary number of Byzantine workers","volume-title":"arXiv preprint","author":"Xie","year":"2019"},{"key":"2026033012251646900_ref436","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","volume-title":"arXiv preprint","author":"Gu","year":"2017"},{"key":"2026033012251646900_ref437","article-title":"Stronger data poisoning attacks break data sanitization defenses","volume-title":"arXiv preprint","author":"Koh","year":"2018"},{"key":"2026033012251646900_ref438","volume-title":"Machine teaching: An inverse problem to machine learning and an approach toward optimal education","author":"Zhu"},{"key":"2026033012251646900_ref439","doi-asserted-by":"crossref","volume-title":"Using machine teaching to identify optimal training-set attacks on machine learners","author":"Mei","DOI":"10.1609\/aaai.v29i1.9569"},{"key":"2026033012251646900_ref440","article-title":"A rotation and a translation suffice: Fooling CNNs with simple transformations","volume-title":"arXiv preprint","author":"Engstrom","year":"2017"},{"key":"2026033012251646900_ref441","article-title":"Testing robustness against unforeseen adversaries","volume-title":"arXiv preprint","author":"Kang","year":"2019"},{"key":"2026033012251646900_ref442","article-title":"Wasserstein adversarial examples via projected sinkhorn iterations","volume-title":"ICML","author":"Wong","year":"2019"},{"key":"2026033012251646900_ref443","article-title":"Adversarial machine learning at scale","volume-title":"arXiv preprint","author":"Kurakin","year":"2016"},{"key":"2026033012251646900_ref444","first-page":"15","volume-title":"ZOO: Zeroth order optimization based black-box attacks to deep neural networks without training substitute models","author":"Chen"},{"key":"2026033012251646900_ref445","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","volume-title":"arXiv preprint","author":"Brendel","year":"2017"},{"key":"2026033012251646900_ref446","volume-title":"Ensemble adversarial training: Attacks and defenses","author":"Tram\u00e8r"},{"key":"2026033012251646900_ref447","first-page":"506","volume-title":"Practical black-box attacks against machine learning","author":"Papernot"},{"key":"2026033012251646900_ref448","article-title":"Obfuscated gradients give a false sense of security: Circumventing defenses to adversarial examples","volume-title":"ICML","author":"Athalye","year":"2018"},{"key":"2026033012251646900_ref449","article-title":"Adversarial training for free","volume-title":"Neur IPS","author":"Shafahi","year":"2019"},{"key":"2026033012251646900_ref450","doi-asserted-by":"crossref","DOI":"10.1109\/CVPR.2019.00059","article-title":"Feature denoising for improving adversarial robustness","volume-title":"CVPR","author":"Xie","year":"2019"},{"key":"2026033012251646900_ref451","article-title":"Attacking the Madry defense model with L_1-based adversarial examples","volume-title":"arXiv preprint","author":"Sharma","year":"2017"},{"key":"2026033012251646900_ref452","article-title":"Adversarial training and robustness for multiple perturbations","volume-title":"arXiv preprint","author":"Tram\u00e8r","year":"2019"},{"key":"2026033012251646900_ref453","first-page":"9561","volume-title":"Fundamental tradeoffs between invariance and sensitivity to adversarial perturbations","author":"Tram\u00e8r"},{"key":"2026033012251646900_ref454","article-title":"Detecting backdoor attacks on deep neural networks by activation clustering","volume-title":"arXiv preprint","author":"Chen","year":"2018"},{"key":"2026033012251646900_ref455","article-title":"Can you really backdoor federated learning?","volume-title":"arXiv preprint","author":"Sun","year":"2019"},{"key":"2026033012251646900_ref456","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume-title":"arXiv preprint","author":"Wang","year":"2020"},{"key":"2026033012251646900_ref457","volume-title":"Data poisoning against differentially-private learners: Attacks and defenses","author":"Ma"},{"key":"2026033012251646900_ref458","article-title":"Differentially private federated learning: A client level perspective","volume":"abs\/1712. 07557","author":"Geyer","year":"2017","journal-title":"CoRR"},{"key":"2026033012251646900_ref459","doi-asserted-by":"publisher","first-page":"656","DOI":"10.1109\/SP.2019.00044","volume-title":"Certified robustness to adversarial examples with differential privacy","author":"L\u00e9cuyer"},{"key":"2026033012251646900_ref460","first-page":"117","volume-title":"Efficient asynchronous secure multiparty distributed computation","author":"Srinathan"},{"key":"2026033012251646900_ref461","first-page":"567","volume-title":"Learning to label aerial images from noisy data","author":"Mnih"},{"key":"2026033012251646900_ref462","first-page":"1196","volume-title":"Learning with noisy labels","author":"Natarajan"},{"key":"2026033012251646900_ref463","first-page":"214","volume-title":"Fairness through awareness","author":"Dwork"},{"key":"2026033012251646900_ref464","volume-title":"Fairness and Machine Learning","author":"Barocas","year":"2019"},{"key":"2026033012251646900_ref465","article-title":"Prediction-based decisions and fairness: A catalogue of choices, assumptions, and definitions","volume-title":"arXiv preprint","author":"Mitchell","year":"2018"},{"key":"2026033012251646900_ref466","first-page":"4066","volume-title":"Counterfactual fairness","author":"Kusner"},{"key":"2026033012251646900_ref467","first-page":"643","volume-title":"Fairness-aware learning through regularization approach","author":"Kamishima"},{"key":"2026033012251646900_ref468","first-page":"77","volume-title":"Gender shades: Intersectional accuracy disparities in commercial gender classification","author":"Buolamwini"},{"key":"2026033012251646900_ref469","article-title":"Fair resource allocation in federated learning","volume-title":"arXiv preprint","author":"Li","year":"2019"},{"issue":"2","key":"2026033012251646900_ref470","doi-asserted-by":"crossref","first-page":"185","DOI":"10.1177\/0093854818811379","article-title":"Layers of bias: A unified approach for understanding problems with risk assessment","volume":"46","author":"Eckhouse","year":"2019","journal-title":"Criminal Justice and Behavior"},{"key":"2026033012251646900_ref471","article-title":"Dirty data, bad predictions: How civil rights violations impact police data, predictive policing systems, and justice","volume-title":"New York University Law Review Online, Forthcoming","author":"Richardson","year":"2019"},{"key":"2026033012251646900_ref472","first-page":"127","volume-title":"\u2018privacy is not for me, it\u2019s for those rich women\u2019: Performative privacy practices on mobile phones by women in South Asia","author":"Sambasivan"},{"key":"2026033012251646900_ref473","article-title":"Censored and fair universal representations using generative adversarial models","volume-title":"arXiv preprint","author":"Kairouz","year":"2020"},{"key":"2026033012251646900_ref474","first-page":"1934","volume-title":"Fairness without demographics in repeated loss minimization","author":"Hashimoto"},{"key":"2026033012251646900_ref475","first-page":"1944","volume-title":"Multicalibration: Calibration for the (computationally-identifiable) masses","author":"H\u00e9bert-Johnson"},{"key":"2026033012251646900_ref476","doi-asserted-by":"crossref","volume-title":"On the compatibility of privacy and fairness","author":"Cummings","DOI":"10.1145\/3314183.3323847"},{"key":"2026033012251646900_ref477","article-title":"Differentially private fair learning","volume":"abs\/1812.02696","author":"Jagielski","year":"2018","journal-title":"CoRR"},{"key":"2026033012251646900_ref478","article-title":"Differential privacy has disparate impact on model accuracy","volume":"abs\/1905.12101","author":"Bagdasaryan","year":"2019","journal-title":"CoRR"},{"key":"2026033012251646900_ref479","article-title":"Fair decision making using privacy-protected data","volume":"abs\/1905.12744","author":"Kuppam","year":"2019","journal-title":"CoRR"},{"key":"2026033012251646900_ref480","doi-asserted-by":"crossref","volume-title":"Privacy risks of securing machine learning models against adversarial examples","author":"Song","DOI":"10.1145\/3319535.3354211"},{"key":"2026033012251646900_ref481","volume-title":"Learning adversarially fair and transferable representations","author":"Bertr\u00e1n"},{"key":"2026033012251646900_ref482","article-title":"Learning anonymized representations with adversarial neural networks","volume":"abs\/1802.09386","author":"Feutry","year":"2018","journal-title":"CoRR"},{"key":"2026033012251646900_ref483","volume-title":"Learning adversarially fair and transferable representations","author":"Madras"},{"key":"2026033012251646900_ref484","volume-title":"Privacy-preserving adversarial representation learning in ASR: Reality or illusion","author":"Srivastava"},{"key":"2026033012251646900_ref485","doi-asserted-by":"crossref","first-page":"59","DOI":"10.1016\/j.ijmedinf.2018.01.007","article-title":"Federated learning of predictive models from federated electronic health records","volume":"112","author":"Brisimi","year":"2018","journal-title":"Int. J. Med. Informat."},{"issue":"8","key":"2026033012251646900_ref486","first-page":"945","article-title":"Distributed deep learning networks among institutions for medical imaging","volume":"25","author":"Chang","year":"2018","journal-title":"JAMIA"},{"key":"2026033012251646900_ref487","first-page":"441261","article-title":"Current clinical use of polygenic scores will risk exacerbating health disparities","volume-title":"BioRxiv","author":"Martin","year":"2019"},{"key":"2026033012251646900_ref488","article-title":"Device heterogeneity in federated learning: A superquantile approach","volume-title":"arXiv preprint","author":"Laguel","year":"2020"},{"key":"2026033012251646900_ref489","volume-title":"Personalized Federated Learning with Moreau Envelopes","author":"Dinh"},{"key":"2026033012251646900_ref490","article-title":"Beyond individual and group fairness","volume":"abs\/2008.09490","author":"Awasthi","year":"2020","journal-title":"CoRR"},{"key":"2026033012251646900_ref491","first-page":"3323","volume-title":"Equality of opportunity in supervised learning","author":"Hardt"},{"key":"2026033012251646900_ref492","volume-title":"Fairness constraints: Mechanisms for fair classification","author":"Zafar"},{"key":"2026033012251646900_ref493","volume-title":"Federated analytics: Collaborative data science without data collection","author":"Ramage","year":"2020"},{"issue":"423","key":"2026033012251646900_ref494","doi-asserted-by":"crossref","first-page":"1001","DOI":"10.1080\/01621459.1993.10476368","article-title":"Post-stratification: A modeler\u2019s perspective","volume":"88","author":"Little","year":"1993","journal-title":"J. Am. Stat. Assoc."},{"key":"2026033012251646900_ref495","article-title":"Flower: A friendly federated learning research framework","volume-title":"arXiv preprint","author":"Beutel","year":"2020"},{"key":"2026033012251646900_ref496","first-page":"8024","volume-title":"Pytorch: An imperative style, high-performance deep learning library","author":"Paszke"},{"key":"2026033012251646900_ref497","unstructured":"J.\n              Bradbury\n            , R.Frostig, P.Hawkins, M. J.Johnson, C.Leary, D.Maclaurin, G.Necula, A.Paszke, J.VanderPlas, S.Wanderman-Milne, and Q.Zhang, JAX: Composable transformations of Python+NumPy programs, 2018. [Online]. Available: http:\/\/github.com\/google\/jax."},{"key":"2026033012251646900_ref498","doi-asserted-by":"publisher","first-page":"2135","DOI":"10.1145\/2939672.2945397","volume-title":"CNTK: Microsoft\u2019s open-source deep-learning toolkit","author":"Seide"},{"key":"2026033012251646900_ref499","article-title":"Federated heavy hitters discovery with differential privacy","volume-title":"arXiv preprint","author":"Zhu","year":"2019"},{"key":"2026033012251646900_ref500","article-title":"FedML: A research library and benchmark for federated machine learning","volume-title":"arXiv preprint","author":"He","year":"2020"},{"key":"2026033012251646900_ref501","doi-asserted-by":"crossref","first-page":"270","DOI":"10.1016\/j.inffus.2020.07.009","article-title":"Federated learning and differential privacy: Software tools analysis, the sherpa.ai FL framework and methodological guidelines for preserving data privacy","volume":"64","author":"Rodr\u00edguez-Barroso","year":"2020","journal-title":"Inform. Fusion"},{"key":"2026033012251646900_ref502","unstructured":"PyVertical Authors\n          , PyVertical, 2020. [Online]. Available: https:\/\/github.com\/OpenMined\/PyVertical."},{"key":"2026033012251646900_ref503","unstructured":"The Paddle Paddle Authors\n          , Paddle Paddle, 2019. [Online]. Available: http:\/\/www.paddlepaddle.org\/."},{"key":"2026033012251646900_ref504","unstructured":"The Fedlearner Authors\n          , Fedlearner, 2020. [Online]. Available: https:\/\/github.com\/bytedance\/fedlearner."},{"key":"2026033012251646900_ref505","article-title":"EMNIST: An extension of MNIST to handwritten letters","volume-title":"arXiv preprint","author":"Cohen","year":"2017"},{"key":"2026033012251646900_ref506","article-title":"LEAF: A benchmark for federated settings","volume-title":"arXiv preprint","author":"Caldas","year":"2018"},{"key":"2026033012251646900_ref507","unstructured":"The Google-Landmark-v2 Authors\n          , Google landmark dataset v2, 2019. [Online]. Available: https:\/\/github.com\/cvdfoundation\/google-landmark."},{"key":"2026033012251646900_ref508","article-title":"Real-world image datasets for federated learning","volume-title":"arXiv preprint","author":"Luo","year":"2019"},{"issue":"15","key":"2026033012251646900_ref509","doi-asserted-by":"crossref","first-page":"1486","DOI":"10.1056\/NEJMlim035027","article-title":"HIPAA regulations - a new era of medical-record privacy?","volume":"348","author":"Annas","year":"2003","journal-title":"NEJM"}],"container-title":["Foundations and Trends\u00ae in Machine Learning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.emerald.com\/ftmal\/article-pdf\/14\/1-2\/1\/11147179\/2200000083en.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/www.emerald.com\/ftmal\/article-pdf\/14\/1-2\/1\/11147179\/2200000083en.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T18:10:43Z","timestamp":1777486243000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.emerald.com\/ftmal\/article\/14\/1-2\/1\/1332154\/Advances-and-Open-Problems-in-Federated-Learning"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,6,23]]},"references-count":509,"journal-issue":{"issue":"1-2","published-print":{"date-parts":[[2021,6,23]]}},"URL":"https:\/\/doi.org\/10.1561\/2200000083","relation":{},"ISSN":["1935-8237","1935-8245"],"issn-type":[{"value":"1935-8237","type":"print"},{"value":"1935-8245","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,6,23]]}}}