{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,20]],"date-time":"2026-08-20T16:23:38Z","timestamp":1787243018183,"version":"build-2736575974"},"publisher-location":"New York, NY, USA","reference-count":60,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,11,7]],"date-time":"2022-11-07T00:00:00Z","timestamp":1667779200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,11,7]]},"DOI":"10.1145\/3548606.3560557","type":"proceedings-article","created":{"date-parts":[[2022,11,7]],"date-time":"2022-11-07T06:41:28Z","timestamp":1667803288000},"page":"2429-2443","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":96,"title":["Eluding Secure Aggregation in Federated Learning via Model Inconsistency"],"prefix":"10.1145","author":[{"given":"Dario","family":"Pasquini","sequence":"first","affiliation":[{"name":"EPFL, Lausanne, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Danilo","family":"Francati","sequence":"additional","affiliation":[{"name":"Aarhus University, Aarhus, Denmark"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Giuseppe","family":"Ateniese","sequence":"additional","affiliation":[{"name":"George Mason University, Fairfax, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,11,7]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2021. TensorFlow Federated. https:\/\/www.tensorflow.org\/federated Accessed: 2021-12-09  2021. TensorFlow Federated. https:\/\/www.tensorflow.org\/federated Accessed: 2021-12-09"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_3_1","volume-title":"Wortman Vaughan (Eds.)","volume":"34","author":"Agarwal Naman","year":"2021","unstructured":"Naman Agarwal , Peter Kairouz , and Ziyu Liu . 2021 . The Skellam Mechanism for Differentially Private Federated Learning. In Advances in Neural Information Processing Systems,, M. Ranzato, A. Beygelzimer, Y. Dauphin, P.S. Liang, and J . Wortman Vaughan (Eds.) , Vol. 34 . Curran Associates, Inc., 5052--5064. https:\/\/proceedings.neurips.cc\/paper\/ 2021\/file\/285baacbdf8fda1de94b19282acd23e2-Paper.pdf Naman Agarwal, Peter Kairouz, and Ziyu Liu. 2021. The Skellam Mechanism for Differentially Private Federated Learning. In Advances in Neural Information Processing Systems,, M. Ranzato, A. Beygelzimer, Y. Dauphin, P.S. Liang, and J. Wortman Vaughan (Eds.), Vol. 34. Curran Associates, Inc., 5052--5064. https:\/\/proceedings.neurips.cc\/paper\/2021\/file\/285baacbdf8fda1de94b19282acd23e2-Paper.pdf"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2015.071829"},{"key":"e_1_3_2_1_5_1","volume-title":"Jamie Ryan Kiros, and Geoffrey E. Hinton","author":"Ba Jimmy Lei","year":"2016","unstructured":"Jimmy Lei Ba , Jamie Ryan Kiros, and Geoffrey E. Hinton . 2016 . Layer Normalization . arxiv: 1607.06450 [stat.ML] Jimmy Lei Ba, Jamie Ryan Kiros, and Geoffrey E. Hinton. 2016. Layer Normalization. arxiv: 1607.06450 [stat.ML]"},{"key":"e_1_3_2_1_6_1","volume-title":"SAFER: Sparse Secure Aggregation for Federated Learning. arXiv preprint arXiv:2007.14861","author":"Beguier Constance","year":"2020","unstructured":"Constance Beguier and Eric W Tramel . 2020 . SAFER: Sparse Secure Aggregation for Federated Learning. arXiv preprint arXiv:2007.14861 (2020). Constance Beguier and Eric W Tramel. 2020. SAFER: Sparse Secure Aggregation for Federated Learning. arXiv preprint arXiv:2007.14861 (2020)."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417885"},{"key":"e_1_3_2_1_8_1","volume-title":"Ilia Shumailov, and Nicolas Papernot.","author":"Boenisch Franziska","year":"2021","unstructured":"Franziska Boenisch , Adam Dziedzic , Roei Schuster , Ali Shahin Shamsabadi , Ilia Shumailov, and Nicolas Papernot. 2021 . When the Curious Abandon Honesty: Federated Learning Is Not Private. CoRR , Vol. abs\/ 2112 .02918 (2021). showeprint[arXiv]2112.02918 https:\/\/arxiv.org\/abs\/2112.02918 Franziska Boenisch, Adam Dziedzic, Roei Schuster, Ali Shahin Shamsabadi, Ilia Shumailov, and Nicolas Papernot. 2021. When the Curious Abandon Honesty: Federated Learning Is Not Private. CoRR, Vol. abs\/2112.02918 (2021). showeprint[arXiv]2112.02918 https:\/\/arxiv.org\/abs\/2112.02918"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_3_2_1_10_1","volume-title":"David Petrou, Daniel Ramage, and Jason Roselander.","author":"Bonawitz K. A.","year":"2019","unstructured":"K. A. Bonawitz , Hubert Eichner , Wolfgang Grieskamp , Dzmitry Huba , Alex Ingerman , Vladimir Ivanov , Chlo\u00e9 M Kiddon , Jakub Kone\u010dn\u00fd , Stefano Mazzocchi , Brendan McMahan , Timon Van Overveldt , David Petrou, Daniel Ramage, and Jason Roselander. 2019 . Towards Federated Learning at Scale : System Design. In SysML 2019. https:\/\/arxiv.org\/abs\/1902.01046 To appear. K. A. Bonawitz, Hubert Eichner, Wolfgang Grieskamp, Dzmitry Huba, Alex Ingerman, Vladimir Ivanov, Chlo\u00e9 M Kiddon, Jakub Kone\u010dn\u00fd, Stefano Mazzocchi, Brendan McMahan, Timon Van Overveldt, David Petrou, Daniel Ramage, and Jason Roselander. 2019. Towards Federated Learning at Scale: System Design. In SysML 2019. https:\/\/arxiv.org\/abs\/1902.01046 To appear."},{"key":"e_1_3_2_1_11_1","unstructured":"Tom B. Brown Benjamin Mann Nick Ryder Melanie Subbiah J. Kaplan Prafulla Dhariwal Arvind Neelakantan Pranav Shyam Girish Sastry Amanda Askell Sandhini Agarwal Ariel Herbert-Voss Gretchen Krueger T. Henighan R. Child A. Ramesh Daniel M. Ziegler Jeff Wu Clemens Winter Christopher Hesse Mark Chen Eric Sigler Mateusz Litwin Scott Gray Benjamin Chess Jack Clark Christopher Berner Sam McCandlish Alec Radford Ilya Sutskever and Dario Amodei. 2020. Language Models are Few-Shot Learners. (2020).  Tom B. Brown Benjamin Mann Nick Ryder Melanie Subbiah J. Kaplan Prafulla Dhariwal Arvind Neelakantan Pranav Shyam Girish Sastry Amanda Askell Sandhini Agarwal Ariel Herbert-Voss Gretchen Krueger T. Henighan R. Child A. Ramesh Daniel M. Ziegler Jeff Wu Clemens Winter Christopher Hesse Mark Chen Eric Sigler Mateusz Litwin Scott Gray Benjamin Chess Jack Clark Christopher Berner Sam McCandlish Alec Radford Ilya Sutskever and Dario Amodei. 2020. Language Models are Few-Shot Learners. (2020)."},{"key":"e_1_3_2_1_12_1","volume-title":"Alexander Viand, Nicolas K\u00fcchler, and Anwar Hithnawi.","author":"Burkhalter Lukas","year":"2021","unstructured":"Lukas Burkhalter , Hidde Lycklama \u00e0 Nijeholt , Alexander Viand, Nicolas K\u00fcchler, and Anwar Hithnawi. 2021 . RoFL: Attestable Robustness for Secure Federated Learning . arxiv: 2107.03311 [cs.CR] Lukas Burkhalter, Hidde Lycklama \u00e0 Nijeholt, Alexander Viand, Nicolas K\u00fcchler, and Anwar Hithnawi. 2021. RoFL: Attestable Robustness for Secure Federated Learning. arxiv: 2107.03311 [cs.CR]"},{"key":"e_1_3_2_1_13_1","volume-title":"The Fundamental Price of Secure Aggregation in Differentially Private Federated Learning. arXiv preprint arXiv:2203.03761","author":"Chen Wei-Ning","year":"2022","unstructured":"Wei-Ning Chen , Christopher A Choquette-Choo , Peter Kairouz , and Ananda Theertha Suresh . 2022a. The Fundamental Price of Secure Aggregation in Differentially Private Federated Learning. arXiv preprint arXiv:2203.03761 ( 2022 ). Wei-Ning Chen, Christopher A Choquette-Choo, Peter Kairouz, and Ananda Theertha Suresh. 2022a. The Fundamental Price of Secure Aggregation in Differentially Private Federated Learning. arXiv preprint arXiv:2203.03761 (2022)."},{"key":"e_1_3_2_1_14_1","volume-title":"Proceedings of the 39th International Conference on Machine Learning (Proceedings of Machine Learning Research","volume":"3506","author":"Chen Wei-Ning","year":"2022","unstructured":"Wei-Ning Chen , Ayfer Ozgur , and Peter Kairouz . 2022 b. The Poisson Binomial Mechanism for Unbiased Federated Learning with Secure Aggregation . In Proceedings of the 39th International Conference on Machine Learning (Proceedings of Machine Learning Research , Vol. 162),, Kamalika Chaudhuri, Stefanie Jegelka, Le Song, Csaba Szepesvari, Gang Niu, and Sivan Sabato (Eds.). PMLR, 3490-- 3506 . https:\/\/proceedings.mlr.press\/v162\/chen22s.html Wei-Ning Chen, Ayfer Ozgur, and Peter Kairouz. 2022b. The Poisson Binomial Mechanism for Unbiased Federated Learning with Secure Aggregation. In Proceedings of the 39th International Conference on Machine Learning (Proceedings of Machine Learning Research, Vol. 162),, Kamalika Chaudhuri, Stefanie Jegelka, Le Song, Csaba Szepesvari, Gang Niu, and Sivan Sabato (Eds.). PMLR, 3490--3506. https:\/\/proceedings.mlr.press\/v162\/chen22s.html"},{"key":"e_1_3_2_1_15_1","volume-title":"Communication-Computation Efficient Secure Aggregation for Federated Learning. arXiv preprint arXiv:2012.05433","author":"Choi Beongjun","year":"2020","unstructured":"Beongjun Choi , Jy-yong Sohn, Dong-Jun Han , and Jaekyun Moon . 2020. Communication-Computation Efficient Secure Aggregation for Federated Learning. arXiv preprint arXiv:2012.05433 ( 2020 ). Beongjun Choi, Jy-yong Sohn, Dong-Jun Han, and Jaekyun Moon. 2020. Communication-Computation Efficient Secure Aggregation for Federated Learning. arXiv preprint arXiv:2012.05433 (2020)."},{"key":"e_1_3_2_1_16_1","volume-title":"A Downsampled Variant of ImageNet as an Alternative to the CIFAR datasets. CoRR","author":"Chrabaszcz Patryk","year":"2017","unstructured":"Patryk Chrabaszcz , Ilya Loshchilov , and Frank Hutter . 2017. A Downsampled Variant of ImageNet as an Alternative to the CIFAR datasets. CoRR , Vol. abs\/ 1707 .08819 ( 2017 ). showeprint[arXiv]1707.08819 http:\/\/arxiv.org\/abs\/1707.08819 Patryk Chrabaszcz, Ilya Loshchilov, and Frank Hutter. 2017. A Downsampled Variant of ImageNet as an Alternative to the CIFAR datasets. CoRR, Vol. abs\/1707.08819 (2017). showeprint[arXiv]1707.08819 http:\/\/arxiv.org\/abs\/1707.08819"},{"key":"e_1_3_2_1_17_1","volume-title":"Contemporary cryptology","author":"Cramer Ronald","unstructured":"Ronald Cramer and Ivan Damg\u00e5rd . 2005. Multiparty computation, an introduction . In Contemporary cryptology . Springer , 41--87. Ronald Cramer and Ivan Damg\u00e5rd. 2005. Multiparty computation, an introduction. In Contemporary cryptology. Springer, 41--87."},{"key":"e_1_3_2_1_18_1","volume-title":"Local Model Poisoning Attacks to Byzantine-Robust Federated Learning","author":"Fang Minghong","unstructured":"Minghong Fang , Xiaoyu Cao , Jinyuan Jia , and Neil Zhenqiang Gong . 2020. Local Model Poisoning Attacks to Byzantine-Robust Federated Learning . USENIX Association , USA. Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Zhenqiang Gong. 2020. Local Model Poisoning Attacks to Byzantine-Robust Federated Learning. USENIX Association, USA."},{"key":"e_1_3_2_1_19_1","volume-title":"Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models. arXiv preprint arXiv:2110.13057","author":"Fowl Liam","year":"2021","unstructured":"Liam Fowl , Jonas Geiping , Wojtek Czaja , Micah Goldblum , and Tom Goldstein . 2021. Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models. arXiv preprint arXiv:2110.13057 ( 2021 ). Liam Fowl, Jonas Geiping, Wojtek Czaja, Micah Goldblum, and Tom Goldstein. 2021. Robbing the Fed: Directly Obtaining Private Data in Federated Learning with Modified Models. arXiv preprint arXiv:2110.13057 (2021)."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_1_21_1","volume-title":"Lin (Eds.)","volume":"33","author":"Geiping Jonas","year":"2020","unstructured":"Jonas Geiping , Hartmut Bauermeister , Hannah Dr\u00f6ge , and Michael Moeller . 2020 . Inverting Gradients - How easy is it to break privacy in federated learning?. In Advances in Neural Information Processing Systems,, H. Larochelle, M. Ranzato, R. Hadsell, M. F. Balcan, and H . Lin (Eds.) , Vol. 33 . Curran Associates, Inc., 16937--16947. https:\/\/proceedings.neurips.cc\/paper\/ 2020\/file\/c4ede56bbd98819ae6112b20ac6bf145-Paper.pdf Jonas Geiping, Hartmut Bauermeister, Hannah Dr\u00f6ge, and Michael Moeller. 2020. Inverting Gradients - How easy is it to break privacy in federated learning?. In Advances in Neural Information Processing Systems,, H. Larochelle, M. Ranzato, R. Hadsell, M. F. Balcan, and H. Lin (Eds.), Vol. 33. Curran Associates, Inc., 16937--16947. https:\/\/proceedings.neurips.cc\/paper\/2020\/file\/c4ede56bbd98819ae6112b20ac6bf145-Paper.pdf"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3043139"},{"key":"e_1_3_2_1_23_1","volume-title":"Federated Learning for Mobile Keyboard Prediction. arxiv","author":"Hard Andrew","year":"1811","unstructured":"Andrew Hard , Kanishka Rao , Rajiv Mathews , Swaroop Ramaswamy , Fran\u00e7oise Beaufays , Sean Augenstein , Hubert Eichner , Chlo\u00e9 Kiddon , and Daniel Ramage . 2019. Federated Learning for Mobile Keyboard Prediction. arxiv : 1811 .03604 [cs.CL] Andrew Hard, Kanishka Rao, Rajiv Mathews, Swaroop Ramaswamy, Fran\u00e7oise Beaufays, Sean Augenstein, Hubert Eichner, Chlo\u00e9 Kiddon, and Daniel Ramage. 2019. Federated Learning for Mobile Keyboard Prediction. arxiv: 1811.03604 [cs.CL]"},{"key":"e_1_3_2_1_24_1","volume-title":"Deep Residual Learning for Image Recognition. In 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 770--778","author":"He K.","year":"2016","unstructured":"K. He , X. Zhang , S. Ren , and J. Sun . 2016 . Deep Residual Learning for Image Recognition. In 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 770--778 . https:\/\/doi.org\/10.1109\/CVPR. 2016 .90 10.1109\/CVPR.2016.90 K. He, X. Zhang, S. Ren, and J. Sun. 2016. Deep Residual Learning for Image Recognition. In 2016 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). 770--778. https:\/\/doi.org\/10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"e_1_3_2_1_26_1","volume-title":"Densely Connected Convolutional Networks. In 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). IEEE Computer Society","author":"Huang G.","year":"2017","unstructured":"G. Huang , Z. Liu , L. Van Der Maaten, and K. Q. Weinberger. 2017 . Densely Connected Convolutional Networks. In 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). IEEE Computer Society , Los Alamitos, CA, USA, 2261--2269. https:\/\/doi.org\/10.1109\/CVPR. 2017 .243 10.1109\/CVPR.2017.243 G. Huang, Z. Liu, L. Van Der Maaten, and K. Q. Weinberger. 2017. Densely Connected Convolutional Networks. In 2017 IEEE Conference on Computer Vision and Pattern Recognition (CVPR). IEEE Computer Society, Los Alamitos, CA, USA, 2261--2269. https:\/\/doi.org\/10.1109\/CVPR.2017.243"},{"key":"e_1_3_2_1_27_1","volume-title":"Evaluating Gradient Inversion Attacks and Defenses in Federated Learning. In Thirty-Fifth Conference on Neural Information Processing Systems. https:\/\/openreview.net\/forum?id=0CDKgyYaxC8","author":"Huang Yangsibo","year":"2021","unstructured":"Yangsibo Huang , Samyak Gupta , Zhao Song , Kai Li , and Sanjeev Arora . 2021 . Evaluating Gradient Inversion Attacks and Defenses in Federated Learning. In Thirty-Fifth Conference on Neural Information Processing Systems. https:\/\/openreview.net\/forum?id=0CDKgyYaxC8 Yangsibo Huang, Samyak Gupta, Zhao Song, Kai Li, and Sanjeev Arora. 2021. Evaluating Gradient Inversion Attacks and Defenses in Federated Learning. In Thirty-Fifth Conference on Neural Information Processing Systems. https:\/\/openreview.net\/forum?id=0CDKgyYaxC8"},{"key":"e_1_3_2_1_28_1","volume-title":"Fastsecagg: Scalable secure aggregation for privacy-preserving federated learning. arXiv preprint arXiv:2009.11248","author":"Kadhe Swanand","year":"2020","unstructured":"Swanand Kadhe , Nived Rajaraman , O Ozan Koyluoglu , and Kannan Ramchandran . 2020 . Fastsecagg: Scalable secure aggregation for privacy-preserving federated learning. arXiv preprint arXiv:2009.11248 (2020). Swanand Kadhe, Nived Rajaraman, O Ozan Koyluoglu, and Kannan Ramchandran. 2020. Fastsecagg: Scalable secure aggregation for privacy-preserving federated learning. arXiv preprint arXiv:2009.11248 (2020)."},{"key":"e_1_3_2_1_29_1","volume-title":"International Conference on Machine Learning. PMLR, 5201--5212","author":"Kairouz Peter","year":"2021","unstructured":"Peter Kairouz , Ziyu Liu , and Thomas Steinke . 2021 . The distributed discrete gaussian mechanism for federated learning with secure aggregation . In International Conference on Machine Learning. PMLR, 5201--5212 . Peter Kairouz, Ziyu Liu, and Thomas Steinke. 2021. The distributed discrete gaussian mechanism for federated learning with secure aggregation. In International Conference on Machine Learning. PMLR, 5201--5212."},{"key":"e_1_3_2_1_30_1","volume-title":"Federated Optimization: Distributed Machine Learning for On-Device Intelligence. arxiv: 1610.02527 [cs.LG]","author":"Jakub","year":"2016","unstructured":"Jakub Kone?n\u00fd, H. Brendan McMahan , Daniel Ramage , and Peter Richt\u00e1rik . 2016 . Federated Optimization: Distributed Machine Learning for On-Device Intelligence. arxiv: 1610.02527 [cs.LG] Jakub Kone?n\u00fd, H. Brendan McMahan, Daniel Ramage, and Peter Richt\u00e1rik. 2016. Federated Optimization: Distributed Machine Learning for On-Device Intelligence. arxiv: 1610.02527 [cs.LG]"},{"key":"e_1_3_2_1_31_1","volume-title":"Ananda Theertha Suresh, and Dave Bacon","author":"Kone\u010dn\u00fd Jakub","year":"2017","unstructured":"Jakub Kone\u010dn\u00fd , H. Brendan McMahan , Felix X. Yu , Peter Richt\u00e1rik , Ananda Theertha Suresh, and Dave Bacon . 2017 . Federated Learning : Strategies for Improving Communication Efficiency . arxiv: 1610.05492 [cs.LG] Jakub Kone\u010dn\u00fd, H. Brendan McMahan, Felix X. Yu, Peter Richt\u00e1rik, Ananda Theertha Suresh, and Dave Bacon. 2017. Federated Learning: Strategies for Improving Communication Efficiency. arxiv: 1610.05492 [cs.LG]"},{"key":"e_1_3_2_1_32_1","unstructured":"Alex Krizhevsky. 2009. Learning Multiple Layers of Features from Tiny Images.  Alex Krizhevsky. 2009. Learning Multiple Layers of Features from Tiny Images."},{"key":"e_1_3_2_1_33_1","volume-title":"Proceedings of the 38th International Conference on Machine Learning.","author":"Lam Maximilian","year":"2021","unstructured":"Maximilian Lam , Gu-Yeon Wei , David Brooks , Vijay Janapa Reddi , and Michael Mitzenmacher . 2021 . Gradient Disaggregation: Breaking Privacy in Federated Learning by Reconstructing the User Participant Matrix . In Proceedings of the 38th International Conference on Machine Learning. Maximilian Lam, Gu-Yeon Wei, David Brooks, Vijay Janapa Reddi, and Michael Mitzenmacher. 2021. Gradient Disaggregation: Breaking Privacy in Federated Learning by Reconstructing the User Participant Matrix. In Proceedings of the 38th International Conference on Machine Learning."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.4208\/cicp.OA-2020-0165"},{"key":"e_1_3_2_1_35_1","unstructured":"Brendan McMahan Eider Moore Daniel Ramage Seth Hampson and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics. PMLR 1273--1282.  Brendan McMahan Eider Moore Daniel Ramage Seth Hampson and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics. PMLR 1273--1282."},{"key":"e_1_3_2_1_36_1","unstructured":"H. Brendan McMahan and Thakurta Abhradeep. 2022. Federated Learning with Formal Differential Privacy Guarantees. https:\/\/ai.googleblog.com\/2022\/02\/federated-learning-with-formal.html Accessed: 2022-08-01.  H. Brendan McMahan and Thakurta Abhradeep. 2022. Federated Learning with Formal Differential Privacy Guarantees. https:\/\/ai.googleblog.com\/2022\/02\/federated-learning-with-formal.html Accessed: 2022-08-01."},{"key":"e_1_3_2_1_37_1","volume-title":"Learning Differentially Private Recurrent Language Models. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=BJ0hF1Z0b","author":"McMahan H. Brendan","year":"2018","unstructured":"H. Brendan McMahan , Daniel Ramage , Kunal Talwar , and Li Zhang . 2018 . Learning Differentially Private Recurrent Language Models. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=BJ0hF1Z0b H. Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. 2018. Learning Differentially Private Recurrent Language Models. In International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=BJ0hF1Z0b"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"e_1_3_2_1_39_1","volume-title":"Proceedings of the 27th International Conference on International Conference on Machine Learning","author":"Nair Vinod","unstructured":"Vinod Nair and Geoffrey E. Hinton . 2010. Rectified Linear Units Improve Restricted Boltzmann Machines . In Proceedings of the 27th International Conference on International Conference on Machine Learning ( Haifa, Israel) (ICML'10). Omnipress, Madison, WI, USA, 807--814. Vinod Nair and Geoffrey E. Hinton. 2010. Rectified Linear Units Improve Restricted Boltzmann Machines. In Proceedings of the 27th International Conference on International Conference on Machine Learning (Haifa, Israel) (ICML'10). Omnipress, Madison, WI, USA, 807--814."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"e_1_3_2_1_41_1","volume-title":"Federated learning with buffered asynchronous aggregation. arXiv preprint arXiv:2106.06639","author":"Nguyen John","year":"2021","unstructured":"John Nguyen , Kshitiz Malik , Hongyuan Zhan , Ashkan Yousefpour , Michael Rabbat , Mani Malek , and Dzmitry Huba . 2021. Federated learning with buffered asynchronous aggregation. arXiv preprint arXiv:2106.06639 ( 2021 ). John Nguyen, Kshitiz Malik, Hongyuan Zhan, Ashkan Yousefpour, Michael Rabbat, Mani Malek, and Dzmitry Huba. 2021. Federated learning with buffered asynchronous aggregation. arXiv preprint arXiv:2106.06639 (2021)."},{"key":"e_1_3_2_1_42_1","volume-title":"Theory-Oriented Deep Leakage from Gradients via Linear Equation Solver. arxiv","author":"Pan Xudong","year":"2010","unstructured":"Xudong Pan , Mi Zhang , Yifan Yan , Jiaming Zhu , and Min Yang . 2020. Theory-Oriented Deep Leakage from Gradients via Linear Equation Solver. arxiv : 2010 .13356 [cs.CR] Xudong Pan, Mi Zhang, Yifan Yan, Jiaming Zhu, and Min Yang. 2020. Theory-Oriented Deep Leakage from Gradients via Linear Equation Solver. arxiv: 2010.13356 [cs.CR]"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"crossref","unstructured":"Dario Pasquini Danilo Francati and Giuseppe Ateniese. 2021. Eluding Secure Aggregation in Federated Learning via Model Inconsistency. https:\/\/arxiv.org\/abs\/2111.07380  Dario Pasquini Danilo Francati and Giuseppe Ateniese. 2021. Eluding Secure Aggregation in Federated Learning via Model Inconsistency. https:\/\/arxiv.org\/abs\/2111.07380","DOI":"10.1145\/3548606.3560557"},{"key":"e_1_3_2_1_44_1","volume-title":"Robust Aggregation for Federated Learning. arxiv","author":"Pillutla Krishna","year":"1912","unstructured":"Krishna Pillutla , Sham M. Kakade , and Zaid Harchaoui . 2019. Robust Aggregation for Federated Learning. arxiv : 1912 .13445 [stat.ML] Krishna Pillutla, Sham M. Kakade, and Zaid Harchaoui. 2019. Robust Aggregation for Federated Learning. arxiv: 1912.13445 [stat.ML]"},{"key":"e_1_3_2_1_45_1","unstructured":"Alec Radford Jeff Wu Rewon Child David Luan Dario Amodei and Ilya Sutskever. 2019. Language Models are Unsupervised Multitask Learners. (2019).  Alec Radford Jeff Wu Rewon Child David Luan Dario Amodei and Ilya Sutskever. 2019. Language Models are Unsupervised Multitask Learners. (2019)."},{"key":"e_1_3_2_1_46_1","volume-title":"Training production language models without memorizing user data. arXiv preprint arXiv:2009.10031","author":"Ramaswamy Swaroop","year":"2020","unstructured":"Swaroop Ramaswamy , Om Thakkar , Rajiv Mathews , Galen Andrew , H Brendan McMahan , and Francc oise Beaufays . 2020. Training production language models without memorizing user data. arXiv preprint arXiv:2009.10031 ( 2020 ). Swaroop Ramaswamy, Om Thakkar, Rajiv Mathews, Galen Andrew, H Brendan McMahan, and Francc oise Beaufays. 2020. Training production language models without memorizing user data. arXiv preprint arXiv:2009.10031 (2020)."},{"key":"e_1_3_2_1_47_1","volume-title":"Proceedings of the 22nd ACM SIGSAC conference on computer and communications security. 1310--1321","author":"Shokri Reza","year":"2015","unstructured":"Reza Shokri and Vitaly Shmatikov . 2015 . Privacy-preserving deep learning . In Proceedings of the 22nd ACM SIGSAC conference on computer and communications security. 1310--1321 . Reza Shokri and Vitaly Shmatikov. 2015. Privacy-preserving deep learning. In Proceedings of the 22nd ACM SIGSAC conference on computer and communications security. 1310--1321."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_49_1","volume-title":"Basak G\u00fc ler, and Amir Salman Avestimehr","author":"So Jinhyun","year":"2021","unstructured":"Jinhyun So , Ramy E. Ali , Basak G\u00fc ler, and Amir Salman Avestimehr . 2021 a. Secure Aggregation for Buffered Asynchronous Federated Learning. CoRR , Vol. abs\/ 2110 .02177 (2021). showeprint[arXiv]2110.02177 https:\/\/arxiv.org\/abs\/2110.02177 Jinhyun So, Ramy E. Ali, Basak G\u00fc ler, and Amir Salman Avestimehr. 2021a. Secure Aggregation for Buffered Asynchronous Federated Learning. CoRR, Vol. abs\/2110.02177 (2021). showeprint[arXiv]2110.02177 https:\/\/arxiv.org\/abs\/2110.02177"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAIT.2021.3054610"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.5555\/2627435.2670313"},{"key":"e_1_3_2_1_52_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Stevens Timothy","year":"2022","unstructured":"Timothy Stevens , Christian Skalka , Christelle Vincent , John Ring , Samuel Clark , and Joseph Near . 2022 . Efficient Differentially Private Secure Aggregation for Federated Learning via Hardness of Learning with Errors . In 31st USENIX Security Symposium (USENIX Security 22) . USENIX Association, Boston, MA. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/stevens Timothy Stevens, Christian Skalka, Christelle Vincent, John Ring, Samuel Clark, and Joseph Near. 2022. Efficient Differentially Private Secure Aggregation for Federated Learning via Hardness of Learning with Errors. In 31st USENIX Security Symposium (USENIX Security 22). USENIX Association, Boston, MA. https:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/stevens"},{"key":"e_1_3_2_1_53_1","volume-title":"\u0141 ukasz Kaiser, and Illia Polosukhin","author":"Vaswani Ashish","year":"2017","unstructured":"Ashish Vaswani , Noam Shazeer , Niki Parmar , Jakob Uszkoreit , Llion Jones , Aidan N Gomez , \u0141 ukasz Kaiser, and Illia Polosukhin . 2017 . Attention is All you Need. In Advances in Neural Information Processing Systems, I. Guyon, U. V. Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, and R. Garnett (Eds.), Vol. 30 . Curran Associates, Inc . https:\/\/proceedings.neurips.cc\/paper\/2017\/file\/3f5ee243547dee91fbd053c1c4a845aa-Paper.pdf Ashish Vaswani, Noam Shazeer, Niki Parmar, Jakob Uszkoreit, Llion Jones, Aidan N Gomez, \u0141 ukasz Kaiser, and Illia Polosukhin. 2017. Attention is All you Need. In Advances in Neural Information Processing Systems, I. Guyon, U. V. Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, and R. Garnett (Eds.), Vol. 30. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper\/2017\/file\/3f5ee243547dee91fbd053c1c4a845aa-Paper.pdf"},{"key":"e_1_3_2_1_54_1","volume-title":"Asynchronous Federated Learning on Heterogeneous Devices: A Survey. CoRR","author":"Xu Chenhao","year":"2021","unstructured":"Chenhao Xu , Youyang Qu , Yong Xiang , and Longxiang Gao . 2021. Asynchronous Federated Learning on Heterogeneous Devices: A Survey. CoRR , Vol. abs\/ 2109 .04269 ( 2021 ). showeprint[arXiv]2109.04269 https:\/\/arxiv.org\/abs\/2109.04269 Chenhao Xu, Youyang Qu, Yong Xiang, and Longxiang Gao. 2021. Asynchronous Federated Learning on Heterogeneous Devices: A Survey. CoRR, Vol. abs\/2109.04269 (2021). showeprint[arXiv]2109.04269 https:\/\/arxiv.org\/abs\/2109.04269"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2019.2929409"},{"key":"e_1_3_2_1_56_1","volume-title":"APPLIED FEDERATED LEARNING: IMPROVING GOOGLE KEYBOARD QUERY SUGGESTIONS. ArXiv","author":"Yang Timothy","year":"2018","unstructured":"Timothy Yang , Galen Andrew , Hubert Eichner , Haicheng Sun , Wei Li , Nicholas Kong , Daniel Ramage , and Fran\u00e7oise Beaufays . 2018 . APPLIED FEDERATED LEARNING: IMPROVING GOOGLE KEYBOARD QUERY SUGGESTIONS. ArXiv , Vol. abs\/ 1812 .02903 (2018). Timothy Yang, Galen Andrew, Hubert Eichner, Haicheng Sun, Wei Li, Nicholas Kong, Daniel Ramage, and Fran\u00e7oise Beaufays. 2018. APPLIED FEDERATED LEARNING: IMPROVING GOOGLE KEYBOARD QUERY SUGGESTIONS. ArXiv, Vol. abs\/1812.02903 (2018)."},{"key":"e_1_3_2_1_57_1","volume-title":"2021 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR). IEEE Computer Society","author":"Yin H.","year":"2021","unstructured":"H. Yin , A. Mallya , A. Vahdat , J. M. Alvarez , J. Kautz , and P. Molchanov . 2021. See through Gradients: Image Batch Recovery via Grad Inversion . In 2021 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR). IEEE Computer Society , Los Alamitos, CA, USA, 16332--16341. https:\/\/doi.org\/10.1109\/CVPR46437. 2021 .01607 10.1109\/CVPR46437.2021.01607 H. Yin, A. Mallya, A. Vahdat, J. M. Alvarez, J. Kautz, and P. Molchanov. 2021. See through Gradients: Image Batch Recovery via Grad Inversion. In 2021 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR). IEEE Computer Society, Los Alamitos, CA, USA, 16332--16341. https:\/\/doi.org\/10.1109\/CVPR46437.2021.01607"},{"key":"e_1_3_2_1_58_1","volume-title":"Salvaging Federated Learning by Local Adaptation. CoRR","author":"Yu Tao","year":"2020","unstructured":"Tao Yu , Eugene Bagdasaryan , and Vitaly Shmatikov . 2020. Salvaging Federated Learning by Local Adaptation. CoRR , Vol. abs\/ 2002 .04758 ( 2020 ). showeprint[arXiv]2002.04758 https:\/\/arxiv.org\/abs\/2002.04758 Tao Yu, Eugene Bagdasaryan, and Vitaly Shmatikov. 2020. Salvaging Federated Learning by Local Adaptation. CoRR, Vol. abs\/2002.04758 (2020). showeprint[arXiv]2002.04758 https:\/\/arxiv.org\/abs\/2002.04758"},{"key":"e_1_3_2_1_59_1","volume-title":"Blaschko","author":"Zhu Junyi","year":"2020","unstructured":"Junyi Zhu and Matthew B . Blaschko . 2020 . R-GAP: Recursive Gradient Attack on Privacy. CoRR , Vol. abs\/ 2010 .07733 (2020). showeprint[arXiv]2010.07733 https:\/\/arxiv.org\/abs\/2010.07733 Junyi Zhu and Matthew B. Blaschko. 2020. R-GAP: Recursive Gradient Attack on Privacy. CoRR, Vol. abs\/2010.07733 (2020). showeprint[arXiv]2010.07733 https:\/\/arxiv.org\/abs\/2010.07733"},{"key":"e_1_3_2_1_60_1","volume-title":"Garnett (Eds.)","volume":"32","author":"Zhu Ligeng","year":"2019","unstructured":"Ligeng Zhu , Zhijian Liu , and Song Han . 2019 . Deep Leakage from Gradients. In Advances in Neural Information Processing Systems, H. Wallach, H. Larochelle, A. Beygelzimer, F. dtextquotesingle Alch\u00e9-Buc, E. Fox, and R . Garnett (Eds.) , Vol. 32 . Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper\/ 2019\/file\/60a6c4002cc7b29142def8871531281a-Paper.pdf Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep Leakage from Gradients. In Advances in Neural Information Processing Systems, H. Wallach, H. Larochelle, A. Beygelzimer, F. dtextquotesingle Alch\u00e9-Buc, E. Fox, and R. Garnett (Eds.), Vol. 32. Curran Associates, Inc. https:\/\/proceedings.neurips.cc\/paper\/2019\/file\/60a6c4002cc7b29142def8871531281a-Paper.pdf"}],"event":{"name":"CCS '22: 2022 ACM SIGSAC Conference on Computer and Communications Security","location":"Los Angeles CA USA","acronym":"CCS '22","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3548606.3560557","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3548606.3560557","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T13:50:57Z","timestamp":1750168257000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3548606.3560557"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,7]]},"references-count":60,"alternative-id":["10.1145\/3548606.3560557","10.1145\/3548606"],"URL":"https:\/\/doi.org\/10.1145\/3548606.3560557","relation":{},"subject":[],"published":{"date-parts":[[2022,11,7]]},"assertion":[{"value":"2022-11-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}