{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T15:49:18Z","timestamp":1781020158109,"version":"3.54.1"},"reference-count":58,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"1","license":[{"start":{"date-parts":[[2021,11,20]],"date-time":"2021-11-20T00:00:00Z","timestamp":1637366400000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,1,1]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Business intelligence and AI services often involve the collection of copious amounts of multidimensional personal data. Since these data usually contain sensitive information of individuals, the direct collection can lead to privacy violations. Local differential privacy (LDP) is currently considered a state-ofthe-art solution for privacy-preserving data collection. However, existing LDP algorithms are not applicable to high-dimensional data; not only because of the increase in computation and communication cost, but also poor data utility.<\/jats:p><jats:p>In this paper, we aim at addressing the<jats:italic>curse-of-dimensionality<\/jats:italic>problem in LDP-based high-dimensional data collection. Based on the idea of machine learning and data synthesis, we propose DP-F<jats:sc>ed<\/jats:sc>-W<jats:sc>ae<\/jats:sc>, an efficient privacy-preserving framework for collecting high-dimensional categorical data. With the combination of a generative autoencoder, federated learning, and differential privacy, our framework is capable of privately learning the statistical distributions of local data and generating high utility synthetic data on the server side without revealing users\u2019 private information. We have evaluated the framework in terms of data utility and privacy protection on a number of real-world datasets containing 68\u2013124 classification attributes. We show that our framework outperforms the LDP-based baseline algorithms in capturing joint distributions and correlations of attributes and generating high-utility synthetic data. With a local privacy guarantee \u2208 = 8, the machine learning models trained with the synthetic data generated by the baseline algorithm cause an accuracy loss of 10% ~ 30%, whereas the accuracy loss is significantly reduced to less than 3% and at best even less than 1% with our framework. Extensive experimental results demonstrate the capability and efficiency of our framework in synthesizing high-dimensional data while striking a satisfactory utility-privacy balance.<\/jats:p>","DOI":"10.2478\/popets-2022-0024","type":"journal-article","created":{"date-parts":[[2021,11,21]],"date-time":"2021-11-21T02:45:59Z","timestamp":1637462759000},"page":"481-500","source":"Crossref","is-referenced-by-count":18,"title":["Privacy-Preserving High-dimensional Data Collection with Federated Generative Autoencoder"],"prefix":"10.56553","volume":"2022","author":[{"given":"Xue","family":"Jiang","sequence":"first","affiliation":[{"name":"Technische Universit\u00e4t M\u00fcnchen , Huawei Technologies D\u00fcsseldorf GmbH"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xuebing","family":"Zhou","sequence":"additional","affiliation":[{"name":"Huawei Technologies D\u00fcsseldorf GmbH"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jens","family":"Grossklags","sequence":"additional","affiliation":[{"name":"Technische Universit\u00e4t M\u00fcnchen"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"35752","published-online":{"date-parts":[[2021,11,20]]},"reference":[{"key":"2022062314364079599_j_popets-2022-0024_ref_001","doi-asserted-by":"crossref","unstructured":"[1] Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pages 308\u2013318, New York, NY, USA, 2016. Association for Computing Machinery.10.1145\/2976749.2978318","DOI":"10.1145\/2976749.2978318"},{"key":"2022062314364079599_j_popets-2022-0024_ref_002","doi-asserted-by":"crossref","unstructured":"[2] Mohammad Alaggan, Mathieu Cunche, and S\u00e9bastien Gambs. Privacy-preserving Wi-Fi analytics. Proceedings on Privacy Enhancing Technologies, 2018(2):4\u201326, 2018.10.1515\/popets-2018-0010","DOI":"10.1515\/popets-2018-0010"},{"key":"2022062314364079599_j_popets-2022-0024_ref_003","doi-asserted-by":"crossref","unstructured":"[3] Mohammad Alaggan, S\u00e9bastien Gambs, and Anne-Marie Kermarrec. BLIP: Non-interactive differentially-private similarity computation on Bloom filters. In Andr\u00e9a W. Richa and Christian Scheideler, editors, Stabilization, Safety, and Security of Distributed Systems - 14th International Symposium, volume 7596 of Lecture Notes in Computer Science, pages 202\u2013216, Toronto, Canada, 2012. Springer.10.1007\/978-3-642-33536-5_20","DOI":"10.1007\/978-3-642-33536-5_20"},{"key":"2022062314364079599_j_popets-2022-0024_ref_004","unstructured":"[4] Dan Alistarh, Torsten Hoefler, Mikael Johansson, Nikola Konstantinov, Sarit Khirirat, and C\u00e9dric Renggli. The convergence of sparsified gradient methods. In Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems 2018, pages 5977\u20135987, Montreal, Canada, 2018."},{"key":"2022062314364079599_j_popets-2022-0024_ref_005","unstructured":"[5] Sean Augenstein, H. Brendan McMahan, Daniel Ramage, Swaroop Ramaswamy, Peter Kairouz, Mingqing Chen, Rajiv Mathews, and Blaise Ag\u00fcera y Arcas. Generative models for effective ML on private, decentralized datasets. In Proceedings of the 8th International Conference on Learning Representations (ICLR), virtual, 2020. OpenReview.net."},{"key":"2022062314364079599_j_popets-2022-0024_ref_006","unstructured":"[6] Raef Bassily, Kobbi Nissim, Uri Stemmer, and Abhradeep Guha Thakurta. Practical locally private heavy hitters. In Advances in Neural Information Processing Systems, pages 2288\u20132296, Long Beach, CA, USA, 2017. Curran Associates Inc."},{"key":"2022062314364079599_j_popets-2022-0024_ref_007","unstructured":"[7] Gabrielle Berman, Sara de la Rosa, and Tanya Accone. Ethical considerations when using geospatial technologies for evidence generation. Technical report, Innocenti Research Briefs, 2018."},{"key":"2022062314364079599_j_popets-2022-0024_ref_008","unstructured":"[8] Jeremy Bernstein, Yu-Xiang Wang, Kamyar Azizzadenesheli, and Animashree Anandkumar. SIGNSGD: Compressed optimisation for non-convex problems. In Jennifer G. Dy and Andreas Krause, editors, Proceedings of the 35th International Conference on Machine Learning, ICML 2018, Stock-holmsm\u00e4ssan, Stockholm, Sweden, July 10-15, 2018, volume 80 of Proceedings of Machine Learning Research, pages 559\u2013568. PMLR, 2018."},{"key":"2022062314364079599_j_popets-2022-0024_ref_009","doi-asserted-by":"crossref","unstructured":"[9] Keith Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone, Brendan McMahan, Sarvar Patel, Daniel Ramage, Aaron Segal, and Karn Seth. Practical secure aggregation for privacy-preserving machine learning. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pages 1175\u20131191, New York, NY, USA, 2017. Association for Computing Machinery.10.1145\/3133956.3133982","DOI":"10.1145\/3133956.3133982"},{"key":"2022062314364079599_j_popets-2022-0024_ref_010","doi-asserted-by":"crossref","unstructured":"[10] Nader Bouacida, Jiahui Hou, Hui Zang, and Xin Liu. Adaptive federated dropout: Improving communication effi-ciency and generalization for federated learning. CoRR, abs\/2011.04050, 2020.","DOI":"10.1109\/INFOCOMWKSHPS51825.2021.9484526"},{"key":"2022062314364079599_j_popets-2022-0024_ref_011","doi-asserted-by":"crossref","unstructured":"[11] Mark Bun, Jelani Nelson, and Uri Stemmer. Heavy hitters and the structure of local privacy. In Proceedings of the 37th ACM SIGMOD-SIGACT-SIGAI Symposium on Principles of Database Systems, pages 435\u2013447, New York, NY, USA, 2018. Association for Computing Machinery.10.1145\/3196959.3196981","DOI":"10.1145\/3196959.3196981"},{"key":"2022062314364079599_j_popets-2022-0024_ref_012","doi-asserted-by":"crossref","unstructured":"[12] Joseph A. Calandrino, Ann Kilzer, Arvind Narayanan, Edward W. Felten, and Vitaly Shmatikov. \u201cYou might also like\u201d: Privacy risks of collaborative filtering. In 2011 IEEE Symposium on Security and Privacy (S&P), pages 231\u2013246, Berkeley, California, USA, 2011. IEEE Computer Society.10.1109\/SP.2011.40","DOI":"10.1109\/SP.2011.40"},{"key":"2022062314364079599_j_popets-2022-0024_ref_013","unstructured":"[13] Sebastian Caldas, Jakub Kone\u010dn\u00fd, H. Brendan McMahan, and Ameet Talwalkar. Expanding the reach of federated learning by reducing client resource requirements. CoRR, abs\/1812.07210, 2018."},{"key":"2022062314364079599_j_popets-2022-0024_ref_014","unstructured":"[14] Differential Privacy Team. Learning with privacy at scale. Apple Machine Learning Journal, 1(8), 2017."},{"key":"2022062314364079599_j_popets-2022-0024_ref_015","unstructured":"[15] Bolin Ding, Janardhan Kulkarni, and Sergey Yekhanin. Collecting telemetry data privately. In Advances in Neural Information Processing Systems, pages 3571\u20133580, Long Beach, CA, USA, 2017. Curran Associates Inc."},{"key":"2022062314364079599_j_popets-2022-0024_ref_016","doi-asserted-by":"crossref","unstructured":"[16] Nikoli Dryden, Tim Moon, Sam Ade Jacobs, and Brian Van Essen. Communication quantization for data-parallel training of deep neural networks. In 2nd Workshop on Machine Learning in HPC Environments, MLHPC@SC, pages 1\u20138, Salt Lake City, UT, USA, 2016. IEEE Computer Society.10.1109\/MLHPC.2016.004","DOI":"10.1109\/MLHPC.2016.004"},{"key":"2022062314364079599_j_popets-2022-0024_ref_017","unstructured":"[17] Dheeru Dua and Casey Graff. UCI machine learning repository, 2017."},{"key":"2022062314364079599_j_popets-2022-0024_ref_018","doi-asserted-by":"crossref","unstructured":"[18] Marco F. Duarte and Yu Hen Hu. Vehicle classification in distributed sensor networks. Journal of Parallel and Distributed Computing, 64(7):826\u2013838, 2004.10.1016\/j.jpdc.2004.03.020","DOI":"10.1016\/j.jpdc.2004.03.020"},{"key":"2022062314364079599_j_popets-2022-0024_ref_019","doi-asserted-by":"crossref","unstructured":"[19] John C. Duchi, Michael I. Jordan, and Martin J. Wainwright. Minimax optimal procedures for locally private estimation. Journal of the American Statistical Association, 113(521):182\u2013201, 2018.10.1080\/01621459.2017.1389735","DOI":"10.1080\/01621459.2017.1389735"},{"key":"2022062314364079599_j_popets-2022-0024_ref_020","doi-asserted-by":"crossref","unstructured":"[20] Cynthia Dwork, Moni Naor, Omer Reingold, Guy N. Roth-blum, and Salil Vadhan. On the complexity of differentially private data release: Efficient algorithms and hardness results. In Proceedings of the Forty-First Annual ACM Symposium on Theory of Computing, pages 381\u2013390, Bethesda, MD, USA, 2009. ACM.10.1145\/1536414.1536467","DOI":"10.1145\/1536414.1536467"},{"key":"2022062314364079599_j_popets-2022-0024_ref_021","doi-asserted-by":"crossref","unstructured":"[21] Cynthia Dwork and Aaron Roth. The algorithmic foundations of differential privacy. Foundations and Trends in Theoretical Computer Science, 9(3\u20134):211\u2013407, 2014.10.1561\/0400000042","DOI":"10.1561\/0400000042"},{"key":"2022062314364079599_j_popets-2022-0024_ref_022","unstructured":"[22] \u00dalfar Erlingsson, Vitaly Feldman, Ilya Mironov, Ananth Raghunathan, Shuang Song, Kunal Talwar, and Abhradeep Thakurta. Encode, shuffle, analyze privacy revisited: Formalizations and empirical evaluation. CoRR, abs\/2001.03618, 2020."},{"key":"2022062314364079599_j_popets-2022-0024_ref_023","doi-asserted-by":"crossref","unstructured":"[23] \u00dalfar Erlingsson, Vasyl Pihur, and Aleksandra Korolova. Rappor: Randomized aggregatable privacy-preserving ordinal response. In Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security, pages 1054\u20131067, Scottsdale, AZ, USA, 2014. ACM.10.1145\/2660267.2660348","DOI":"10.1145\/2660267.2660348"},{"key":"2022062314364079599_j_popets-2022-0024_ref_024","doi-asserted-by":"crossref","unstructured":"[24] Giulia Fanti, Vasyl Pihur, and \u00dalfar Erlingsson. Building a Rappor with the unknown: Privacy-preserving learning of associations and data dictionaries. Proceedings on Privacy Enhancing Technologies, 3:1\u201321, 2016.","DOI":"10.1515\/popets-2016-0015"},{"key":"2022062314364079599_j_popets-2022-0024_ref_025","unstructured":"[25] Jonas Geiping, Hartmut Bauermeister, Hannah Dr\u00f6ge, and Michael Moeller. Inverting gradients \u2013 How easy is it to break privacy in federated learning? In Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, virtual, 2020. Curran Associates Inc."},{"key":"2022062314364079599_j_popets-2022-0024_ref_026","unstructured":"[26] Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio. Generative adversarial nets. In Advances in Neural Information Processing Systems, pages 2672\u20132680, Montreal, Quebec, Canada, 2014. Curran Associates Inc."},{"key":"2022062314364079599_j_popets-2022-0024_ref_027","doi-asserted-by":"crossref","unstructured":"[27] Markus Herdin, Nicolai Czink, H\u00fcseyin \u00d6zcelik, and Ernst Bonek. Correlation matrix distance, a meaningful measure for evaluation of non-stationary MIMO channels. In 2005 IEEE 61st Vehicular Technology Conference, volume 1, pages 136\u2013140, Stockholm, Sweden, 2005. IEEE.","DOI":"10.1109\/VETECS.2005.1543265"},{"key":"2022062314364079599_j_popets-2022-0024_ref_028","unstructured":"[28] Nikita Ivkin, Daniel Rothchild, Enayat Ullah, Vladimir Braverman, Ion Stoica, and Raman Arora. Communicationefficient distributed SGD with sketching. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, pages 13144\u201313154, Vancouver, BC, Canada, 2019."},{"key":"2022062314364079599_j_popets-2022-0024_ref_029","unstructured":"[29] Bargav Jayaraman, Lingxiao Wang, David Evans, and Quanquan Gu. Distributed learning without distress: Privacy-preserving empirical risk minimization. In Advances in Neural Information Processing Systems, pages 6343\u20136354. Curran Associates Inc., 2018."},{"key":"2022062314364079599_j_popets-2022-0024_ref_030","unstructured":"[30] Yuang Jiang, Shiqiang Wang, Bong-Jun Ko, Wei-Han Lee, and Leandros Tassiulas. Model pruning enables efficient federated learning on edge devices. CoRR, abs\/1909.12326, 2019."},{"key":"2022062314364079599_j_popets-2022-0024_ref_031","doi-asserted-by":"crossref","unstructured":"[31] Shiva Prasad Kasiviswanathan, Homin K. Lee, Kobbi Nissim, Sofya Raskhodnikova, and Adam Smith. What can we learn privately? SIAM Journal on Computing, 40(3):793\u2013826, Jan 2011.10.1137\/090756090","DOI":"10.1137\/090756090"},{"key":"2022062314364079599_j_popets-2022-0024_ref_032","unstructured":"[32] Fran\u00e7ois Kawala, Ahlame Douzal-Chouakria, Eric Gaussier, and Eustache Dimert. Pr\u00e9dictions d\u2019activit\u00e9 dans les r\u00e9seaux sociaux en ligne. In 4i\u00e8me conf\u00e9rence sur les mod\u00e8les et l\u2019analyse des r\u00e9seaux : Approches math\u00e9matiques et informatiques, page 16, France, 2013."},{"key":"2022062314364079599_j_popets-2022-0024_ref_033","unstructured":"[33] Diederik P. Kingma and Max Welling. Auto-encoding variational Bayes. In Proceedings of the 2nd International Conference on Learning Representations (ICLR), Banff, AB, Canada, 2014. OpenReview.net."},{"key":"2022062314364079599_j_popets-2022-0024_ref_034","unstructured":"[34] Ron Kohavi. Scaling up the accuracy of Naive-Bayes classifiers: A decision-tree hybrid. In Proceedings of the SIGKDD Conference on Knowledge Discovery and Data Mining, pages 202\u2013207, Portland, Oregon, USA, 1996. AAAI Press."},{"key":"2022062314364079599_j_popets-2022-0024_ref_035","unstructured":"[35] Yann LeCun, Corinna Cortes, and CJ Burges. MNIST handwritten digit database. ATT Labs [Online]. Available: http:\/\/yann.lecun.com\/exdb\/mnist, 2, 2010."},{"key":"2022062314364079599_j_popets-2022-0024_ref_036","unstructured":"[36] Haoran Li, Li Xiong, and Xiaoqian Jiang. Differentially private synthesization of multi-dimensional data using copula functions. In Advances in Database Technology: Proceedings of the International Conference on Extending Database Technology, volume 2014, pages 475\u2013486, Athens, Greece, 2014. NIH Public Access, OpenProceedings.org."},{"key":"2022062314364079599_j_popets-2022-0024_ref_037","doi-asserted-by":"crossref","unstructured":"[37] Ruixuan Liu, Yang Cao, Masatoshi Yoshikawa, and Hong Chen. Fedsel: Federated SGD under local differential privacy with top-k dimension selection. In Database Systems for Advanced Applications - 25th International Conference, DASFAA 2020, Jeju, South Korea, September 24-27, 2020, Proceedings, Part I, volume 12112 of Lecture Notes in Computer Science, pages 485\u2013501. Springer, 2020.10.1007\/978-3-030-59410-7_33","DOI":"10.1007\/978-3-030-59410-7_33"},{"key":"2022062314364079599_j_popets-2022-0024_ref_038","unstructured":"[38] Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Ag\u00fcera y Arcas. Communicationefficient learning of deep networks from decentralized data. In Artificial Intelligence and Statistics, pages 1273\u20131282, Fort Lauderdale, FL, USA, 2017. PMLR."},{"key":"2022062314364079599_j_popets-2022-0024_ref_039","unstructured":"[39] Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. Learning differentially private recurrent language models. In Proceedings of the International Conference on Learning Representations, Vancouver, BC, Canada, 2018. OpenReview.net."},{"key":"2022062314364079599_j_popets-2022-0024_ref_040","doi-asserted-by":"crossref","unstructured":"[40] Milad Nasr, Reza Shokri, and Amir Houmansadr. Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In 2019 IEEE Symposium on Security and Privacy (S&P), pages 739\u2013753, San Francisco, CA, USA\u201e 2019. IEEE.10.1109\/SP.2019.00065","DOI":"10.1109\/SP.2019.00065"},{"key":"2022062314364079599_j_popets-2022-0024_ref_041","doi-asserted-by":"crossref","unstructured":"[41] Noseong Park, Mahmoud Mohammadi, Kshitij Gorde, Sushil Jajodia, Hongkyu Park, and Youngmin Kim. Data synthesis based on generative adversarial networks. Proceedings of the VLDB Endowment, 11(10):1071\u20131083, 2018.10.14778\/3231751.3231757","DOI":"10.14778\/3231751.3231757"},{"key":"2022062314364079599_j_popets-2022-0024_ref_042","doi-asserted-by":"crossref","unstructured":"[42] John C. Platt. Fast Training of Support Vector Machines Using Sequential Minimal Optimization, page 185\u2013208. MIT Press, Cambridge, MA, USA, 1999.","DOI":"10.7551\/mitpress\/1130.003.0016"},{"key":"2022062314364079599_j_popets-2022-0024_ref_043","doi-asserted-by":"crossref","unstructured":"[43] Zhan Qin, Yin Yang, Ting Yu, Issa Khalil, Xiaokui Xiao, and Kui Ren. Heavy hitter estimation over set-valued data with local differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pages 192\u2013203, Vienna, Austria, 2016. ACM.10.1145\/2976749.2978409","DOI":"10.1145\/2976749.2978409"},{"key":"2022062314364079599_j_popets-2022-0024_ref_044","doi-asserted-by":"crossref","unstructured":"[44] Xuebin Ren, Chia-Mu Yu, Weiren Yu, Shusen Yang, Xinyu Yang, Julie A McCann, and S Yu Philip. LoPub: High-dimensional crowdsourced data publication with local differential privacy. IEEE Transactions on Information Forensics and Security, 13(9):2151\u20132166, 2018.","DOI":"10.1109\/TIFS.2018.2812146"},{"key":"2022062314364079599_j_popets-2022-0024_ref_045","doi-asserted-by":"crossref","unstructured":"[45] Frank Seide, Hao Fu, Jasha Droppo, Gang Li, and Dong Yu. 1-bit stochastic gradient descent and its application to data-parallel distributed training of speech dnns. In Haizhou Li, Helen M. Meng, Bin Ma, Engsiong Chng, and Lei Xie, editors, INTERSPEECH 2014, 15th Annual Conference of the International Speech Communication Association, pages 1058\u20131062, Singapore, 2014. ISCA.10.21437\/Interspeech.2014-274","DOI":"10.21437\/Interspeech.2014-274"},{"key":"2022062314364079599_j_popets-2022-0024_ref_046","unstructured":"[46] Theresa Stadler, Bristena Oprisanu, and Carmela Troncoso. Synthetic data - A privacy mirage. CoRR, abs\/2011.07018, 2020."},{"key":"2022062314364079599_j_popets-2022-0024_ref_047","unstructured":"[47] Sebastian U. Stich, Jean-Baptiste Cordonnier, and Martin Jaggi. Sparsified SGD with memory. In Advances in Neural Information Processing Systems 31: Annual Conference on Neural Information Processing Systems 2018, pages 4452\u20134463, Montreal, Canada, 2018."},{"key":"2022062314364079599_j_popets-2022-0024_ref_048","unstructured":"[48] Ilya Tolstikhin, Olivier Bousquet, Sylvain Gelly, and Bernhard Sch\u00f6lkopf. Wasserstein auto-encoders. In International Conference on Learning Representations (ICLR 2018), Vancouver, BC, Canada, 2018. OpenReview.net."},{"key":"2022062314364079599_j_popets-2022-0024_ref_049","doi-asserted-by":"crossref","unstructured":"[49] Reihaneh Torkzadehmahani, Peter Kairouz, and Benedict Paten. DP-CGAN: Differentially private synthetic data and label generation. In Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition \u2013 Workshops, pages 98\u2013104, Long Beach, CA, USA, 2019. Computer Vision Foundation \/IEEE.10.1109\/CVPRW.2019.00018","DOI":"10.1109\/CVPRW.2019.00018"},{"key":"2022062314364079599_j_popets-2022-0024_ref_050","doi-asserted-by":"crossref","unstructured":"[50] Aleksei Triastcyn and Boi Faltings. Federated generative privacy. IEEE Intelligent Systems, 35(4):50\u201357, 2020.10.1109\/MIS.2020.2993966","DOI":"10.1109\/MIS.2020.2993966"},{"key":"2022062314364079599_j_popets-2022-0024_ref_051","doi-asserted-by":"crossref","unstructured":"[51] Stacey Truex, Nathalie Baracaldo, Ali Anwar, Thomas Steinke, Heiko Ludwig, Rui Zhang, and Yi Zhou. A hybrid approach to privacy-preserving federated learning. In Proceedings of the 12th ACM Workshop on Artificial Intelligence and Security, pages 1\u201311, 2019.10.1145\/3338501.3357370","DOI":"10.1145\/3338501.3357370"},{"key":"2022062314364079599_j_popets-2022-0024_ref_052","doi-asserted-by":"crossref","unstructured":"[52] Ning Wang, Xiaokui Xiao, Yin Yang, Jun Zhao, Siu Cheung Hui, Hyejin Shin, Junbum Shin, and Ge Yu. Collecting and analyzing multidimensional data with local differential privacy. In Proceedings of the 35th IEEE International Conference on Data Engineering, pages 638\u2013649, 2019.10.1109\/ICDE.2019.00063","DOI":"10.1109\/ICDE.2019.00063"},{"key":"2022062314364079599_j_popets-2022-0024_ref_053","unstructured":"[53] Teng Wang, Xinyu Yang, Xuebin Ren, Wei Yu, and Shusen Yang. Locally private high-dimensional crowdsourced data release based on copula functions. IEEE Transactions on Services Computing, pages 1\u20131, 2019.10.1109\/TSC.2019.2961092"},{"key":"2022062314364079599_j_popets-2022-0024_ref_054","doi-asserted-by":"crossref","unstructured":"[54] Tianhao Wang, Ninghui Li, and Somesh Jha. Locally differentially private frequent itemset mining. In 2018 IEEE Symposium on Security and Privacy, pages 127\u2013143, San Francisco, California, USA, 2018. IEEE Computer Society.10.1109\/SP.2018.00035","DOI":"10.1109\/SP.2018.00035"},{"key":"2022062314364079599_j_popets-2022-0024_ref_055","doi-asserted-by":"crossref","unstructured":"[55] Zhibo Wang, Mengkai Song, Zhifei Zhang, Yang Song, Qian Wang, and Hairong Qi. Beyond inferring class representatives: User-level privacy leakage from federated learning. In IEEE Conference on Computer Communications (INFOCOM), pages 2512\u20132520, Paris, France, 2019. IEEE.10.1109\/INFOCOM.2019.8737416","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"2022062314364079599_j_popets-2022-0024_ref_056","unstructured":"[56] Han Xiao, Kashif Rasul, and Roland Vollgraf. Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms. CoRR, abs\/1708.07747, 2017."},{"key":"2022062314364079599_j_popets-2022-0024_ref_057","doi-asserted-by":"crossref","unstructured":"[57] Jun Zhang, Graham Cormode, Cecilia M Procopiuc, Divesh Srivastava, and Xiaokui Xiao. Privbayes: Private data release via Bayesian networks. ACM Transactions on Database Systems, 42(4):25:1\u201325:41, 2017.","DOI":"10.1145\/3134428"},{"key":"2022062314364079599_j_popets-2022-0024_ref_058","doi-asserted-by":"crossref","unstructured":"[58] Yang Zhao, Jun Zhao, Mengmeng Yang, Teng Wang, Ning Wang, Lingjuan Lyu, Dusit Niyato, and Kwok-Yan Lam. Local differential privacy based federated learning for internet of things. IEEE Internet of Things Journal, 2020.10.1109\/JIOT.2020.3037194","DOI":"10.1109\/JIOT.2020.3037194"}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.sciendo.com\/pdf\/10.2478\/popets-2022-0024","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,12]],"date-time":"2024-09-12T19:17:19Z","timestamp":1726168639000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2022\/popets-2022-0024.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,11,20]]},"references-count":58,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2021,11,20]]},"published-print":{"date-parts":[[2022,1,1]]}},"alternative-id":["10.2478\/popets-2022-0024"],"URL":"https:\/\/doi.org\/10.2478\/popets-2022-0024","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,11,20]]}}}