<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.1 20151215//EN" "http://jats.nlm.nih.gov/publishing/1.1/JATS-journalpublishing1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:mml="http://www.w3.org/1998/Math/MathML" xml:lang="en" article-type="research-article" dtd-version="1.1">
<front>
<journal-meta>
<journal-id journal-id-type="pmc">CSSE</journal-id>
<journal-id journal-id-type="nlm-ta">CSSE</journal-id>
<journal-id journal-id-type="publisher-id">CSSE</journal-id>
<journal-title-group>
<journal-title>Computer Systems Science &#x0026; Engineering</journal-title>
</journal-title-group>
<issn pub-type="ppub">0267-6192</issn>
<publisher>
<publisher-name>Tech Science Press</publisher-name>
<publisher-loc>USA</publisher-loc>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="publisher-id">40194</article-id>
<article-id pub-id-type="doi">10.32604/csse.2023.040194</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Article</subject>
</subj-group>
</article-categories>
<title-group>
<article-title>Efficient DP-FL: Efficient Differential Privacy Federated Learning Based on Early Stopping Mechanism</article-title>
<alt-title alt-title-type="left-running-head">Efficient DP-FL: Efficient Differential Privacy Federated Learning Based on Early Stopping Mechanism</alt-title>
<alt-title alt-title-type="right-running-head">Efficient DP-FL: Efficient Differential Privacy Federated Learning Based on Early Stopping Mechanism</alt-title>
</title-group>
<contrib-group>
<contrib id="author-1" contrib-type="author">
<name name-style="western"><surname>Jiao</surname><given-names>Sanxiu</given-names></name><xref ref-type="aff" rid="aff-1">1</xref></contrib>
<contrib id="author-2" contrib-type="author" corresp="yes">
<name name-style="western"><surname>Cai</surname><given-names>Lecai</given-names></name><xref ref-type="aff" rid="aff-2">2</xref><email>ybxyclc@163.com</email></contrib>
<contrib id="author-3" contrib-type="author">
<name name-style="western"><surname>Meng</surname><given-names>Jintao</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-4" contrib-type="author">
<name name-style="western"><surname>Zhao</surname><given-names>Yue</given-names></name><xref ref-type="aff" rid="aff-3">3</xref></contrib>
<contrib id="author-5" contrib-type="author">
<name name-style="western"><surname>Cheng</surname><given-names>Kui</given-names></name><xref ref-type="aff" rid="aff-2">2</xref></contrib>
<aff id="aff-1"><label>1</label><institution>College of Automation and Information Engineering, Sichuan University of Science and Engineering</institution>, <addr-line>Yibin, 644000</addr-line>, <country>China</country></aff>
<aff id="aff-2"><label>2</label><institution>Sanjiang Research Institute of Artificial Intelligence and Robotics, Yibin University</institution>, <addr-line>Yibin, 644000</addr-line>, <country>China</country></aff>
<aff id="aff-3"><label>3</label><institution>Science and Technology on Communication Security Laboratory, China Electronics Technology Corporation 30th Research Institute</institution>, <addr-line>Chengdu, 610041</addr-line>, <country>China</country></aff>
</contrib-group>
<author-notes>
<corresp id="cor1"><label>&#x002A;</label>Corresponding Author: Lecai Cai. Email: <email>ybxyclc@163.com</email></corresp>
</author-notes>
<pub-date date-type="collection" publication-format="electronic">
<year>2024</year></pub-date>
<pub-date date-type="pub" publication-format="electronic"><day>26</day><month>1</month><year>2024</year>
</pub-date>
<volume>48</volume>
<issue>1</issue>
<fpage>247</fpage>
<lpage>265</lpage>
<history>
<date date-type="received">
<day>08</day>
<month>3</month>
<year>2023</year>
</date>
<date date-type="accepted">
<day>27</day>
<month>4</month>
<year>2023</year>
</date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2024 Jiao et al.</copyright-statement>
<copyright-year>2024</copyright-year>
<copyright-holder>Jiao et al.</copyright-holder>
<license xlink:href="https://creativecommons.org/licenses/by/4.0/">
<license-p>This work is licensed under a <ext-link ext-link-type="uri" xlink:type="simple" xlink:href="https://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution 4.0 International License</ext-link>, which permits unrestricted use, distribution, and reproduction in any medium, provided the original work is properly cited.</license-p>
</license>
</permissions>
<self-uri content-type="pdf" xlink:href="TSP_CSSE_40194.pdf"></self-uri>
<abstract>
<p>Federated learning is a distributed machine learning framework that solves data security and data island problems faced by artificial intelligence. However, federated learning frameworks are not always secure, and attackers can attack customer privacy information by analyzing parameters in the training process of federated learning models. To solve the problems of data security and availability during federated learning training, this paper proposes an Efficient Differential Privacy Federated Learning Algorithm based on early stopping mechanism (Efficient DP-FL). This method inherits the advantages of differential privacy and federated learning and improves the performance of model training while protecting the parameter information uploaded by the client during the training process. Specifically, in the federated learning framework, this article uses an adaptive DP-FL method for gradient descent training, which makes the model converge faster than traditional stochastic gradient descent. In addition, due to model convergence, noise should be reduced accordingly. This paper introduces an early stopping mechanism to improve data availability. This paper demonstrates the performance improvement of the Efficient DP-FL algorithm through simulation experiments on real MNIST and Fashion-MNIST datasets. Experimental show that the efficient DP-FL algorithm is significantly superior to other algorithms.</p>
</abstract>
<kwd-group kwd-group-type="author">
<kwd>Differential privacy</kwd>
<kwd>federated learning</kwd>
<kwd>data security</kwd>
<kwd>artificial intelligence</kwd>
</kwd-group>
<funding-group>
<award-group id="awg1">
<funding-source>Communication Security Laboratory Science and Technology</funding-source>
<award-id>61421030209012105</award-id>
</award-group>
<award-group id="awg2">
<funding-source>Sichuan Provincial Science and Technology</funding-source>
<award-id>2019YFN0104</award-id>
</award-group>
<award-group id="awg3">
<funding-source>Yibin Science and Technology</funding-source>
<award-id>2021GY008</award-id>
</award-group>
<award-group id="awg4">
<funding-source>Sichuan University of Science and Engineering</funding-source>
<award-id>Y2022154</award-id>
</award-group>
</funding-group>
</article-meta>
</front>
<body>
<sec id="s1">
<label>1</label>
<title>Introduction</title>
<p>In recent years, with the rapid development of machine learning technology, smart devices have generated massive amounts of data. Machine learning [<xref ref-type="bibr" rid="ref-1">1</xref>&#x2013;<xref ref-type="bibr" rid="ref-5">5</xref>] techniques are widely used to process these data. However, centralized machine learning requires enormous computing power and attracts centralized attacks. To save computing power and ensure the confidentiality of the client&#x2019;s local private data, a feasible solution is to put the client&#x2019;s locally trained model into the federated learning framework for processing. Since federated learning trains data locally and does not upload private data, the privacy overhead of the client is effectively reduced. Therefore, federated learning is widely used in the Industrial Internet of Things [<xref ref-type="bibr" rid="ref-6">6</xref>&#x2013;<xref ref-type="bibr" rid="ref-10">10</xref>], Blockchain [<xref ref-type="bibr" rid="ref-11">11</xref>&#x2013;<xref ref-type="bibr" rid="ref-15">15</xref>], and Smart Healthcare [<xref ref-type="bibr" rid="ref-16">16</xref>&#x2013;<xref ref-type="bibr" rid="ref-18">18</xref>].</p>
<p>Although federated learning can effectively prevent the leakage of users&#x2019; local private data, adversaries can still attack the model by analyzing the parameters of the local federated learning model [<xref ref-type="bibr" rid="ref-19">19</xref>&#x2013;<xref ref-type="bibr" rid="ref-25">25</xref>]. Therefore, ensuring the privacy and security of users&#x2019; local data is a challenge.</p>
<p>To address this issue, DP is widely used for privacy protection in deep learning [<xref ref-type="bibr" rid="ref-26">26</xref>&#x2013;<xref ref-type="bibr" rid="ref-29">29</xref>]. For example, Abadi et al. [<xref ref-type="bibr" rid="ref-30">30</xref>] proposed to use DP for deep learning and developed a new differential privacy stochastic gradient descent (DP-SGD) algorithm. Lee et al. [<xref ref-type="bibr" rid="ref-31">31</xref>] improved upon DP-SGD and allocate a privacy budget in each training session. Recently, DP has also been used in federated learning scenarios [<xref ref-type="bibr" rid="ref-32">32</xref>&#x2013;<xref ref-type="bibr" rid="ref-35">35</xref>]. For example, Wei et al. [<xref ref-type="bibr" rid="ref-32">32</xref>] proposed to use DP for federated learning and proposed a new framework (NbAFL) based on differential privacy federated learning by adding Gaussian noise before the parameter aggregation of the client model. Xu et al. [<xref ref-type="bibr" rid="ref-33">33</xref>] proposed an Adaptive Fast Convergent Learning Algorithm (ADADP) with a provable privacy budget, when the client participates in model training, the model can show good training performance at a fixed privacy level. Truex et al. [<xref ref-type="bibr" rid="ref-34">34</xref>] proposed a hybrid approach based on DP and Secure Multi-Party Computation (SMC) to prevent inference attacks and generate the better models. However, this also consumes more communication resources. Therefore, it is necessary to design a more efficient differential privacy federated learning algorithm.</p>
<p>To address these challenges, this article proposes an efficient differential privacy federated learning method based on an early stopping mechanism. To summarize, our contributions to this paper focus on three points:
<list list-type="bullet">
<list-item>
<p>An Efficient DP-FL algorithm was proposed. Specifically, the algorithm inherits the advantages of differential privacy and federated learning and protects the actual parameters uploaded by the client during the training process.</p></list-item>
<list-item>
<p>The Efficient DP-FL algorithm adds an early stopping mechanism to reduces unnecessary noise and improve the availability of the data.</p></list-item>
<list-item>
<p>The efficiency of the proposed method is shown through theoretical analysis and simulation experiments.</p></list-item>
</list></p>
<p>The rest of this paper is organized as follows. In <xref ref-type="sec" rid="s2">Section 2</xref>, some initial preparations for our algorithm are provided. <xref ref-type="sec" rid="s3">Section 3</xref> proposes an efficient differential privacy federated learning scheme based on an early stopping mechanism, and <xref ref-type="sec" rid="s4">Section 4</xref> conducts privacy analysis. Experiments is in <xref ref-type="sec" rid="s5">Section 5</xref>. <xref ref-type="sec" rid="s6">Section 6</xref> gives the conclusion. The basic concepts and meanings of the symbols are summarized in <xref ref-type="table" rid="table-1">Table 1</xref>.</p>
<table-wrap id="table-1">
<label>Table 1</label>
<caption>
<title>Summary of main natation</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th><inline-formula id="ieqn-1"><mml:math id="mml-ieqn-1"><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow></mml:math></inline-formula></th>
<th>A randomized algorithm for DP</th>
</tr>
</thead>
<tbody>
<tr>
<td><inline-formula id="ieqn-2"><mml:math id="mml-ieqn-2"><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x1D4F7;</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td>Adjacent datasets</td>
</tr>
<tr>
<td><inline-formula id="ieqn-3"><mml:math id="mml-ieqn-3"><mml:mo>&#x03B5;</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B4;</mml:mo></mml:math></inline-formula></td>
<td>The parameters related to differential privacy</td>
</tr>
<tr>
<td><inline-formula id="ieqn-4"><mml:math id="mml-ieqn-4"><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>The <italic>i</italic>-<italic>th</italic> client</td>
</tr>
<tr>
<td><inline-formula id="ieqn-5"><mml:math id="mml-ieqn-5"><mml:mi>D</mml:mi></mml:math></inline-formula></td>
<td>The dataset held by all the clients</td>
</tr>
<tr>
<td><inline-formula id="ieqn-6"><mml:math id="mml-ieqn-6"><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
<td>The dataset held by the owner <inline-formula id="ieqn-7"><mml:math id="mml-ieqn-7"><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula></td>
</tr>
<tr>
<td><inline-formula id="ieqn-8"><mml:math id="mml-ieqn-8"><mml:mrow><mml:mo>|</mml:mo><mml:mo>.</mml:mo><mml:mo>|</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td>The cardinality of a set</td>
</tr>
<tr>
<td><inline-formula id="ieqn-9"><mml:math id="mml-ieqn-9"><mml:mi>N</mml:mi></mml:math></inline-formula></td>
<td>The number of all clients</td>
</tr>
<tr>
<td><inline-formula id="ieqn-10"><mml:math id="mml-ieqn-10"><mml:mi>H</mml:mi></mml:math></inline-formula></td>
<td>Lot size for local training once</td>
</tr>
<tr>
<td><inline-formula id="ieqn-11"><mml:math id="mml-ieqn-11"><mml:mi>t</mml:mi></mml:math></inline-formula></td>
<td>The subscript of the <italic>t</italic>-<italic>th</italic> communication round</td>
</tr>
<tr>
<td><inline-formula id="ieqn-12"><mml:math id="mml-ieqn-12"><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow></mml:math></inline-formula></td>
<td>The number of communication rounds is T</td>
</tr>
<tr>
<td><inline-formula id="ieqn-13"><mml:math id="mml-ieqn-13"><mml:msub><mml:mrow><mml:mtext>F</mml:mtext></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>w</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula></td>
<td>The loss function from the <italic>i-th</italic> local client</td>
</tr>
<tr>
<td><inline-formula id="ieqn-14"><mml:math id="mml-ieqn-14"><mml:msup><mml:mi>w</mml:mi><mml:mrow><mml:mn>0</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula></td>
<td>Initial model parameters of the global model</td>
</tr>
<tr>
<td><inline-formula id="ieqn-15"><mml:math id="mml-ieqn-15"><mml:msup><mml:mi>w</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msup></mml:math></inline-formula></td>
<td>Local training parameters in <italic>t</italic>-<italic>th</italic> communication round</td>
</tr>
<tr>
<td><inline-formula id="ieqn-16"><mml:math id="mml-ieqn-16"><mml:mi>w</mml:mi></mml:math></inline-formula></td>
<td>The vector of model parameters</td>
</tr>
<tr>
<td><inline-formula id="ieqn-17"><mml:math id="mml-ieqn-17"><mml:msup><mml:mi>w</mml:mi><mml:mrow><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:mrow></mml:msup></mml:math></inline-formula></td>
<td>The optimal parameters that the local loss function</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec id="s2">
<label>2</label>
<title>Preliminaries</title>
<sec id="s2_1">
<label>2.1</label>
<title>Federated Learning</title>
<p>Let us observe the system of FL consisting of <inline-formula id="ieqn-18"><mml:math id="mml-ieqn-18"><mml:mi>N</mml:mi></mml:math></inline-formula> clients and an aggregation server, as shown in <xref ref-type="fig" rid="fig-1">Fig. 1</xref>. <inline-formula id="ieqn-19"><mml:math id="mml-ieqn-19"><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> represents the dataset of the local client <inline-formula id="ieqn-20"><mml:math id="mml-ieqn-20"><mml:msub><mml:mi>U</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula>, <inline-formula id="ieqn-21"><mml:math id="mml-ieqn-21"><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>,</mml:mo><mml:mi>N</mml:mi><mml:mo>}</mml:mo></mml:mrow><mml:mo>.</mml:mo></mml:math></inline-formula> The task of the aggregation server is to train the model from the relevant parameter information of the local clients. The training of the local client aims to find the optimal vector <inline-formula id="ieqn-22"><mml:math id="mml-ieqn-22"><mml:mi>w</mml:mi></mml:math></inline-formula> of the model to minimize some loss function. In general form, the weight that the server aggregate receives from <inline-formula id="ieqn-23"><mml:math id="mml-ieqn-23"><mml:mi>N</mml:mi></mml:math></inline-formula> local clients is as follows:</p>
<p><disp-formula id="eqn-1">
<label>(1)</label>
<mml:math id="mml-eqn-1" display="block"><mml:mi>w</mml:mi><mml:mo>=</mml:mo><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>N</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>p</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></disp-formula></p>
<p>where <inline-formula id="ieqn-24"><mml:math id="mml-ieqn-24"><mml:mi>w</mml:mi></mml:math></inline-formula> is the parameter vector aggregated by the server, <inline-formula id="ieqn-25"><mml:math id="mml-ieqn-25"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is the parameter vector trained on the <italic>i</italic>-<italic>th</italic> client, and <inline-formula id="ieqn-26"><mml:math id="mml-ieqn-26"><mml:mi>N</mml:mi></mml:math></inline-formula> is the number of all clients. <inline-formula id="ieqn-27"><mml:math id="mml-ieqn-27"><mml:msub><mml:mi>p</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mo>|</mml:mo></mml:mrow></mml:mfrac></mml:mstyle><mml:mo>&#x2265;</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>, <inline-formula id="ieqn-28"><mml:math id="mml-ieqn-28"><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>N</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>p</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, <inline-formula id="ieqn-29"><mml:math id="mml-ieqn-29"><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mo>|</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow></mml:mrow></mml:msubsup><mml:mrow><mml:mo>|</mml:mo><mml:msub><mml:mrow><mml:mtext>D</mml:mtext></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>|</mml:mo></mml:mrow></mml:math></inline-formula> is the total number of all datasets, <inline-formula id="ieqn-30"><mml:math id="mml-ieqn-30"><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is the dataset of the <italic>i</italic>-<italic>th</italic> local client. <inline-formula id="ieqn-31"><mml:math id="mml-ieqn-31"><mml:msub><mml:mrow><mml:mtext>F</mml:mtext></mml:mrow><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mo>.</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is the loss function of the <italic>i</italic>-<italic>th</italic> local client, The optimization task of federated learning can be expressed as:</p>
<p><disp-formula id="eqn-2">
<label>(2)</label>
<mml:math id="mml-eqn-2" display="block"><mml:msup><mml:mi>w</mml:mi><mml:mrow><mml:mo>&#x2217;</mml:mo></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:munder><mml:mrow><mml:mi>a</mml:mi><mml:mi>r</mml:mi><mml:mi>g</mml:mi><mml:mi>m</mml:mi><mml:mi>i</mml:mi><mml:mi>n</mml:mi></mml:mrow><mml:mrow><mml:mi>w</mml:mi></mml:mrow></mml:munder><mml:mo>&#x2061;</mml:mo><mml:msubsup><mml:mo movablelimits="false">&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>N</mml:mi></mml:mrow></mml:msubsup><mml:msub><mml:mi>p</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>D</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:mi>w</mml:mi><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<fig id="fig-1">
<label>Figure 1</label>
<caption>
<title>A differential privacy federated learning training model with the hidden adversary</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_40194-fig-1.tif"/>
</fig>
<p>The steps of each round of the training process of the federated learning general system are as follows:
<list list-type="bullet">
<list-item>
<p><bold>Local training:</bold> All local clients use local samples to update the model based on the original data, and send the locally trained model parameters to the aggregation server.</p></list-item>
<list-item>
<p><bold>Model aggregation:</bold> The server aggregates and averages the parameters uploaded by each local client and updates the global model.</p></list-item>
<list-item>
<p><bold>Parameters broadcasting:</bold> The aggregation server broadcasts the updated the current parameters to each local client.</p></list-item>
<list-item>
<p><bold>Model updating:</bold> Each local client updates the local model with the latest parameters received and tests the performance of the current model.</p></list-item>
</list></p>
</sec>
<sec id="s2_2">
<label>2.2</label>
<title>Threat Model</title>
<p>In this paper, the server is assumed to be honest but curious. Although the single dataset of the <italic>i</italic>-<italic>th</italic> client is stored locally in FL, the parameter <inline-formula id="ieqn-32"><mml:math id="mml-ieqn-32"><mml:msub><mml:mi>w</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> needs to be shared with the aggregation server, which may disclose the client&#x2019;s private. Therefore, semi-honest models are vulnerable to member inference attacks and attribute inference attack. Specifically, an adversary can perform attribute inference attacks by extracting training data during model training or by extracting feature vectors of training data [<xref ref-type="bibr" rid="ref-36">36</xref>&#x2013;<xref ref-type="bibr" rid="ref-40">40</xref>]. For example, Salem et al. [<xref ref-type="bibr" rid="ref-41">41</xref>] proposed a hybrid generative model, which assumes that the adversary has black-box access to the model and has specific samples as prior knowledge, the adversary can judge whether the training set of the model contains feature samples, and thus initiate Membership inference attack. Lacharit&#x00E9; et al. [<xref ref-type="bibr" rid="ref-42">42</xref>] proposed an approximate attribute inference attack, which is a method to enable range queries when the model provides little security. To sum up, the adversary may launch inference attacks based on the parameter information obtained during model training. Therefore, the threat model presented in this article is reasonable.</p>
</sec>
<sec id="s2_3">
<label>2.3</label>
<title>Differential Privacy</title>
<p>In recent years, DP has become a standard concept for federated learning privacy protection and has been widely used in federated learning data analysis tasks.</p>
<p><bold>Definition 1:</bold> <inline-formula id="ieqn-33"><mml:math id="mml-ieqn-33"><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x03B5;</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B4;</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>D</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>: A randomized algorithm <inline-formula id="ieqn-34"><mml:math id="mml-ieqn-34"><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mo>&#x003A;</mml:mo><mml:mo>&#x03C7;</mml:mo><mml:mo stretchy="false">&#x2192;</mml:mo><mml:mrow><mml:mo>&#x211B;</mml:mo></mml:mrow></mml:math></inline-formula> with domain <inline-formula id="ieqn-35"><mml:math id="mml-ieqn-35"><mml:mo>&#x03C7;</mml:mo></mml:math></inline-formula> and range <inline-formula id="ieqn-36"><mml:math id="mml-ieqn-36"><mml:mrow><mml:mo>&#x211B;</mml:mo></mml:mrow></mml:math></inline-formula> satisfies <inline-formula id="ieqn-37"><mml:math id="mml-ieqn-37"><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x03B5;</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B4;</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>D</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> if for any two adjacent datasets <inline-formula id="ieqn-38"><mml:math id="mml-ieqn-38"><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x1D4F7;</mml:mo></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mo>&#x03C7;</mml:mo></mml:math></inline-formula> and for all measurable sets <inline-formula id="ieqn-39"><mml:math id="mml-ieqn-39"><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mo>&#x211B;</mml:mo></mml:mrow></mml:math></inline-formula>, it holds that</p>
<p><disp-formula id="eqn-3">
<label>(3)</label>
<mml:math id="mml-eqn-3" display="block"><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow><mml:mo>&#x2264;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:mrow></mml:msup><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>&#x1D4F7;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo>&#x03B4;</mml:mo></mml:math></disp-formula></p>
<p>A Gaussian mechanism defined in [<xref ref-type="bibr" rid="ref-33">33</xref>] can be used to guarantee <inline-formula id="ieqn-40"><mml:math id="mml-ieqn-40"><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x03B5;</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B4;</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>D</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>.</p>
</sec>
</sec>
<sec id="s3">
<label>3</label>
<title>The Proposed Approach</title>
<p>To reduce privacy costs and improve the model convergence rate, Efficient DP-FL uses an adaptive learning rate for the gradient descent training model. In addition, Efficient DP-FL adds Gaussian noise to the gradient, and the gradient performs adaptive noise processing according to the adaptive learning rate, thereby improving the performance of model training. To further mitigate the impact of noise on model performance, the algorithm introduces an early stopping mechanism. The following will introduce the Efficient DP-FL method and give its differential privacy guarantee.</p>
<sec id="s3_1">
<label>3.1</label>
<title>Adaptive DP-FL</title>
<p>The gradient descent method is commonly used to train deep learning models. The goal of training the model is to obtain the smallest loss function value. To minimize the local loss function, usually a subset of the data is randomly selected and the parameter <inline-formula id="ieqn-41"><mml:math id="mml-ieqn-41"><mml:msup><mml:mi>w</mml:mi><mml:mrow><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">&#x2190;</mml:mo><mml:msup><mml:mi>w</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03B1;</mml:mi><mml:msub><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:mrow><mml:mrow><mml:msup><mml:mi>w</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msub><mml:msub><mml:mi>F</mml:mi><mml:mrow><mml:mrow><mml:mtext>i&#xA0;</mml:mtext></mml:mrow></mml:mrow></mml:msub><mml:mrow><mml:mo>(</mml:mo><mml:msub><mml:mi>x</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msup><mml:mi>w</mml:mi><mml:mrow><mml:mi>t</mml:mi></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mo>.</mml:mo></mml:math></inline-formula> The learning rate determines the step of the gradient descent update. If the learning rate is too large, it will fall into the dilemma of the local optimal solution. If the learning rate is too small, it will take a long time to obtain the optimal solution. Therefore, how to set an appropriate learning rate to avoid falling into a local optimal solution is a challenge we face. Relevant scholars have proposed more advanced optimizers, such as Adadelta, Adagrad, RMSProp, etc., to solve the above problems, and they update parameters by adaptively adjusting the learning rate.</p>
<p>Efficient DP-FL uses an approach similar to adaptive gradient descent with the Adam optimizer. The framework proposed in this paper is not only suitable for other types of gradient descent, but also for adaptive gradient descent with added noise.</p>
<p><bold>Theorem 1:</bold> For any <inline-formula id="ieqn-42"><mml:math id="mml-ieqn-42"><mml:mo>&#x03B5;</mml:mo><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-43"><mml:math id="mml-ieqn-43"><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>&#x003E;</mml:mo><mml:mn>2</mml:mn><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>1.25</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo>&#x03B4;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, the Gaussian Mechanism parameter <inline-formula id="ieqn-44"><mml:math id="mml-ieqn-44"><mml:mi>&#x03C3;</mml:mi><mml:mo>&#x2265;</mml:mo><mml:mi>c</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:math></inline-formula> is <inline-formula id="ieqn-45"><mml:math id="mml-ieqn-45"><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x03B5;</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B4;</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>D</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>.</p>
<p>To ensure that the Gaussian noise distribution <inline-formula id="ieqn-46"><mml:math id="mml-ieqn-46"><mml:mi>&#x03BE;</mml:mi><mml:mo>&#x223C;</mml:mo><mml:mrow><mml:mtext>N&#xA0;</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> satisfies <inline-formula id="ieqn-47"><mml:math id="mml-ieqn-47"><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x03B5;</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B4;</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>D</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>, Dwork et al. [<xref ref-type="bibr" rid="ref-43">43</xref>] choosed the noise range <inline-formula id="ieqn-48"><mml:math id="mml-ieqn-48"><mml:mi>&#x03C3;</mml:mi><mml:mo>&#x2265;</mml:mo><mml:mi>c</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:math></inline-formula> and the <inline-formula id="ieqn-49"><mml:math id="mml-ieqn-49"><mml:mi>c</mml:mi><mml:mo>&#x2265;</mml:mo><mml:msqrt><mml:mn>2</mml:mn><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>1.25</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo>&#x03B4;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:msqrt></mml:math></inline-formula>, here <inline-formula id="ieqn-50"><mml:math id="mml-ieqn-50"><mml:mi>N</mml:mi></mml:math></inline-formula> denotes the noise distribution, <inline-formula id="ieqn-51"><mml:math id="mml-ieqn-51"><mml:mo>&#x03B5;</mml:mo><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> denotes the additive noise value of a particular data in the dataset, <inline-formula id="ieqn-52"><mml:math id="mml-ieqn-52"><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi></mml:math></inline-formula> is the sensitivity, <inline-formula id="ieqn-53"><mml:math id="mml-ieqn-53"><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mo>=</mml:mo><mml:munder><mml:mo movablelimits="true" form="prefix">max</mml:mo><mml:mrow><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x1D4F7;</mml:mo></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mo>&#x03C7;</mml:mo></mml:mrow></mml:munder><mml:msub><mml:mrow><mml:mo symmetric="true">&#x2016;</mml:mo><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo>&#x1D4F7;</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo symmetric="true">&#x2016;</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, and <inline-formula id="ieqn-54"><mml:math id="mml-ieqn-54"><mml:mo>&#x03B4;</mml:mo></mml:math></inline-formula> is the probability of breaking the strict differential privacy. Theorem 1 is proved as follows:</p>
<p><italic>Proof</italic>. There is a dataset <inline-formula id="ieqn-55"><mml:math id="mml-ieqn-55"><mml:mi>D</mml:mi></mml:math></inline-formula> and a query function <inline-formula id="ieqn-56"><mml:math id="mml-ieqn-56"><mml:mi>f</mml:mi></mml:math></inline-formula>, and the mechanism will return <inline-formula id="ieqn-57"><mml:math id="mml-ieqn-57"><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03BE;</mml:mi></mml:mrow></mml:math></inline-formula>, where the Gaussian noise is normally distributed. The noise <inline-formula id="ieqn-58"><mml:math id="mml-ieqn-58"><mml:mrow><mml:mo>&#x1D4A9;</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is added. For now, assume <inline-formula id="ieqn-59"><mml:math id="mml-ieqn-59"><mml:mi>f</mml:mi></mml:math></inline-formula> is a real-valued function, so</p>
<p><disp-formula id="eqn-4">
<label>(4)</label>
<mml:math id="mml-eqn-4" display="block"><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mo>=</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mi>f</mml:mi><mml:mo>=</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mi>f</mml:mi></mml:math></disp-formula></p>
<p>To study the different probability of adjacent dataset <inline-formula id="ieqn-60"><mml:math id="mml-ieqn-60"><mml:mi>D</mml:mi></mml:math></inline-formula> and <inline-formula id="ieqn-61"><mml:math id="mml-ieqn-61"><mml:msup><mml:mi>D</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:math></inline-formula>, the probability is obtained by the noise generation algorithm. The numerator in the ratio above describes the probability of observing <inline-formula id="ieqn-62"><mml:math id="mml-ieqn-62"><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mi>x</mml:mi></mml:math></inline-formula> when the dataset is <inline-formula id="ieqn-63"><mml:math id="mml-ieqn-63"><mml:mi>D</mml:mi></mml:math></inline-formula>, and the denominator corresponds to the probability of observing this same value when the dataset is <inline-formula id="ieqn-64"><mml:math id="mml-ieqn-64"><mml:msup><mml:mi>D</mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:math></inline-formula>. the privacy loss is:</p>
<p><disp-formula id="eqn-5">
<label>(5)</label>
<mml:math id="mml-eqn-5" display="block"><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mfrac><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mrow><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>x</mml:mi><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup></mml:mfrac></mml:math></disp-formula></p>
<p>Furthermore, looking at the absolute value.</p>
<p><disp-formula id="eqn-6">
<label>(6)</label>
<mml:math id="mml-eqn-6" display="block"><mml:mrow><mml:mo>|</mml:mo><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mfrac><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mrow><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>x</mml:mi><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup></mml:mfrac><mml:mo>|</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mo>[</mml:mo><mml:mi>x</mml:mi><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>]</mml:mo></mml:mrow></mml:mrow></mml:msup><mml:mo>|</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mn>2</mml:mn><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mfrac><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mo>+</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:msup><mml:mi>f</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>|</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>whenever <inline-formula id="ieqn-65"><mml:math id="mml-ieqn-65"><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>&#x003C;</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:math></inline-formula>, the quantity is bounded by <inline-formula id="ieqn-66"><mml:math id="mml-ieqn-66"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:math></inline-formula> To ensure privacy loss bounded by <inline-formula id="ieqn-67"><mml:math id="mml-ieqn-67"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:math></inline-formula> , with a probability of at least <inline-formula id="ieqn-68"><mml:math id="mml-ieqn-68"><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:mo>&#x03B4;</mml:mo></mml:math></inline-formula>, it is required that:</p>
<p><disp-formula id="eqn-7">
<label>(7)</label>
<mml:math id="mml-eqn-7" display="block"><mml:mo movablelimits="true" form="prefix">Pr</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mi>x</mml:mi><mml:mo>|</mml:mo></mml:mrow><mml:mo>&#x2265;</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo>]</mml:mo></mml:mrow><mml:mo>&#x003C;</mml:mo><mml:mo>&#x03B4;</mml:mo></mml:math></disp-formula></p>
<p>assume that <inline-formula id="ieqn-69"><mml:math id="mml-ieqn-69"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>&#x2264;</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi></mml:math></inline-formula>, using the tail bound.</p>
<p><disp-formula id="eqn-8">
<label>(8)</label>
<mml:math id="mml-eqn-8" display="block"><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>&#x003E;</mml:mo><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>]</mml:mo></mml:mrow><mml:mo>&#x2264;</mml:mo><mml:mfrac><mml:mi>&#x03C3;</mml:mi><mml:msqrt><mml:mn>2</mml:mn><mml:mrow><mml:mi mathvariant="normal">&#x03C0;</mml:mi></mml:mrow></mml:msqrt></mml:mfrac><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mi>t</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup></mml:math></disp-formula></p>
<p><disp-formula id="eqn-9">
<label>(9)</label>
<mml:math id="mml-eqn-9" display="block"><mml:mfrac><mml:mi>&#x03C3;</mml:mi><mml:msqrt><mml:mn>2</mml:mn><mml:mrow><mml:mi mathvariant="normal">&#x03C0;</mml:mi></mml:mrow></mml:msqrt></mml:mfrac><mml:mfrac><mml:mn>1</mml:mn><mml:mi>t</mml:mi></mml:mfrac><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mi>t</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:msup><mml:mi>x</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup><mml:mo>&#x003C;</mml:mo><mml:mo>&#x03B4;</mml:mo><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:math></disp-formula></p>
<p><disp-formula id="eqn-10">
<label>(10)</label>
<mml:math id="mml-eqn-10" display="block"><mml:mo stretchy="false">&#x27FA;</mml:mo><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:mi>t</mml:mi><mml:mi>&#x03C3;</mml:mi></mml:mfrac><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mfrac><mml:msup><mml:mi>t</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mn>2</mml:mn><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mfrac><mml:mo>&#x003E;</mml:mo><mml:mrow><mml:mi>ln</mml:mi></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:msqrt><mml:mn>2</mml:mn><mml:mi>&#x03C0;</mml:mi></mml:msqrt><mml:mo>&#x03B4;</mml:mo><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>Taking <inline-formula id="ieqn-70"><mml:math id="mml-ieqn-70"><mml:mrow><mml:mtext>t</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn></mml:math></inline-formula>,we get</p>
<p><disp-formula id="eqn-11">
<label>(11)</label>
<mml:math id="mml-eqn-11" display="block"><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>&#x03C3;</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>2</mml:mn><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>&#x003E;</mml:mo><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:msqrt><mml:mn>2</mml:mn><mml:mrow><mml:mi mathvariant="normal">&#x03C0;</mml:mi></mml:mrow></mml:msqrt><mml:mo>&#x03B4;</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msqrt><mml:mfrac><mml:mn>2</mml:mn><mml:mrow><mml:mi mathvariant="normal">&#x03C0;</mml:mi></mml:mrow></mml:mfrac></mml:msqrt><mml:mfrac><mml:mn>1</mml:mn><mml:mo>&#x03B4;</mml:mo></mml:mfrac><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>Let us write <inline-formula id="ieqn-71"><mml:math id="mml-ieqn-71"><mml:mi>&#x03C3;</mml:mi><mml:mo>=</mml:mo><mml:mi>c</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:math></inline-formula>, then.</p>
<p><disp-formula id="eqn-12">
<label>(12)</label>
<mml:math id="mml-eqn-12" display="block"><mml:mfrac><mml:mn>1</mml:mn><mml:mi>&#x03C3;</mml:mi></mml:mfrac><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mfrac><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi></mml:mrow></mml:mfrac><mml:mo>&#x2212;</mml:mo><mml:mfrac><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi></mml:mrow><mml:mn>2</mml:mn></mml:mfrac><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mi>&#x03C3;</mml:mi></mml:mfrac><mml:mrow><mml:mo>[</mml:mo><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mfrac><mml:mo>)</mml:mo></mml:mrow><mml:mfrac><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi></mml:mrow></mml:mfrac><mml:mo>&#x2212;</mml:mo><mml:mfrac><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi></mml:mrow><mml:mn>2</mml:mn></mml:mfrac><mml:mo>]</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mtext>c</mml:mtext></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mfrac><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn><mml:mrow><mml:mtext>c</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<p>when <inline-formula id="ieqn-72"><mml:math id="mml-ieqn-72"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>&#x2264;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> and <inline-formula id="ieqn-73"><mml:math id="mml-ieqn-73"><mml:mrow><mml:mtext>c</mml:mtext></mml:mrow><mml:mo>&#x2265;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, we can obtain <inline-formula id="ieqn-74"><mml:math id="mml-ieqn-74"><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>c</mml:mtext></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn><mml:mrow><mml:mtext>c</mml:mtext></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2265;</mml:mo><mml:mi>c</mml:mi><mml:mo>&#x2212;</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac></mml:mstyle></mml:math></inline-formula>. So <inline-formula id="ieqn-75"><mml:math id="mml-ieqn-75"><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mn>1</mml:mn><mml:mi>&#x03C3;</mml:mi></mml:mfrac></mml:mstyle><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi></mml:mrow></mml:mfrac></mml:mstyle><mml:mo>&#x2212;</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi></mml:mrow><mml:mn>2</mml:mn></mml:mfrac></mml:mstyle><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula><inline-formula id="ieqn-76"><mml:math id="mml-ieqn-76"><mml:mo>&#x003E;</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula> provided <inline-formula id="ieqn-77"><mml:math id="mml-ieqn-77"><mml:mrow><mml:mtext>c</mml:mtext></mml:mrow><mml:mo>&#x2265;</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mn>3</mml:mn><mml:mn>2</mml:mn></mml:mfrac></mml:mstyle></mml:math></inline-formula>. Therefore focus on the <inline-formula id="ieqn-78"><mml:math id="mml-ieqn-78"><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:msup><mml:mi>t</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mfrac></mml:mstyle></mml:math></inline-formula> term.</p>
<p><disp-formula id="eqn-13">
<label>(13)</label>
<mml:math id="mml-eqn-13" display="block"><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mn>2</mml:mn><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mfrac><mml:mfrac><mml:mrow><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi></mml:mrow></mml:mfrac><mml:mo>&#x2212;</mml:mo><mml:mfrac><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi></mml:mrow><mml:mn>2</mml:mn></mml:mfrac><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mn>2</mml:mn><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mfrac><mml:msup><mml:mrow><mml:mo>[</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:mfrac><mml:mo>&#x2212;</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac><mml:mo>)</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mn>2</mml:mn></mml:mfrac><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>+</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>4</mml:mn><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p>
<p>Due to <inline-formula id="ieqn-79"><mml:math id="mml-ieqn-79"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>&#x2264;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, the derivative of <inline-formula id="ieqn-80"><mml:math id="mml-ieqn-80"><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>+</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>4</mml:mn><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> concerning for to <inline-formula id="ieqn-81"><mml:math id="mml-ieqn-81"><mml:mi>c</mml:mi></mml:math></inline-formula> is positive in the scope we are considering <inline-formula id="ieqn-82"><mml:math id="mml-ieqn-82"><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>c</mml:mtext></mml:mrow><mml:mo>&#x2265;</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mn>3</mml:mn><mml:mn>2</mml:mn></mml:mfrac></mml:mstyle><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula>, so <inline-formula id="ieqn-83"><mml:math id="mml-ieqn-83"><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>+</mml:mo><mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>4</mml:mn><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2265;</mml:mo><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mn>8</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>9</mml:mn></mml:math></inline-formula> and it suffices to ensure.</p>
<p><disp-formula id="eqn-14">
<label>(14)</label>
<mml:math id="mml-eqn-14" display="block"><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mn>8</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>9</mml:mn><mml:mo>&#x003E;</mml:mo><mml:mn>2</mml:mn><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msqrt><mml:mfrac><mml:mn>2</mml:mn><mml:mrow><mml:mi mathvariant="normal">&#x03C0;</mml:mi></mml:mrow></mml:mfrac></mml:msqrt><mml:mfrac><mml:mn>1</mml:mn><mml:mo>&#x03B4;</mml:mo></mml:mfrac><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>In order words, it needs that</p>
<p><disp-formula id="eqn-15">
<label>(15)</label>
<mml:math id="mml-eqn-15" display="block"><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>&#x003E;</mml:mo><mml:mn>2</mml:mn><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msqrt><mml:mfrac><mml:mn>2</mml:mn><mml:mi>&#x03C0;</mml:mi></mml:mfrac></mml:msqrt><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mo>&#x03B4;</mml:mo></mml:mfrac><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mrow><mml:mtext>e</mml:mtext></mml:mrow><mml:mrow><mml:mfrac><mml:mn>8</mml:mn><mml:mn>9</mml:mn></mml:mfrac></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:mn>2</mml:mn><mml:mi>&#x03C0;</mml:mi></mml:mfrac><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mn>2</mml:mn><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mfrac><mml:mn>1</mml:mn><mml:mo>&#x03B4;</mml:mo></mml:mfrac><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:msup><mml:mrow><mml:mtext>e</mml:mtext></mml:mrow><mml:mrow><mml:mfrac><mml:mn>8</mml:mn><mml:mn>9</mml:mn></mml:mfrac></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p>which, since <inline-formula id="ieqn-84"><mml:math id="mml-ieqn-84"><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>&#x03C0;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:msup><mml:mrow><mml:mtext>e</mml:mtext></mml:mrow><mml:mrow><mml:mn>8</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mn>9</mml:mn></mml:mrow></mml:msup><mml:mo>&#x003C;</mml:mo><mml:mn>1.55</mml:mn><mml:mo>,</mml:mo></mml:math></inline-formula> is satisfied whenever <inline-formula id="ieqn-85"><mml:math id="mml-ieqn-85"><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>&#x003E;</mml:mo><mml:mn>2</mml:mn><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>1.25</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo>&#x03B4;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>.</mml:mo></mml:math></inline-formula></p>
<p>Let <inline-formula id="ieqn-86"><mml:math id="mml-ieqn-86"><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:msub><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>&#x222A;</mml:mo><mml:msub><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula>, where <inline-formula id="ieqn-87"><mml:math id="mml-ieqn-87"><mml:msub><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mo>&#x003A;</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>|</mml:mo></mml:mrow><mml:mo>&#x2264;</mml:mo><mml:mi>c</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>}</mml:mo></mml:mrow></mml:math></inline-formula> and <inline-formula id="ieqn-88"><mml:math id="mml-ieqn-88"><mml:msub><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow><mml:mo>&#x003A;</mml:mo><mml:mrow><mml:mo>|</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>|</mml:mo></mml:mrow><mml:mo>&#x003E;</mml:mo><mml:mi>c</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>}</mml:mo></mml:mrow></mml:math></inline-formula>. For any subset <inline-formula id="ieqn-89"><mml:math id="mml-ieqn-89"><mml:mrow><mml:mtext>S</mml:mtext></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="double-struck">R</mml:mi></mml:mrow></mml:math></inline-formula>, <inline-formula id="ieqn-90"><mml:math id="mml-ieqn-90"><mml:mi>x</mml:mi><mml:mo>&#x223C;</mml:mo><mml:mrow><mml:mo>&#x1D4A9;</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, and define</p>
<p><disp-formula id="eqn-16">
<label>(16)</label>
<mml:math id="mml-eqn-16" display="block"><mml:msub><mml:mrow><mml:mtext>S</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p><disp-formula id="eqn-17">
<label>(17)</label>
<mml:math id="mml-eqn-17" display="block"><mml:msub><mml:mrow><mml:mtext>S</mml:mtext></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mo stretchy="false">|</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mtext>R</mml:mtext></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>}</mml:mo></mml:mrow></mml:math></disp-formula></p>
<p><disp-formula id="eqn-18">
<label>(18)</label>
<mml:math id="mml-eqn-18" display="block"><mml:mi>P</mml:mi><mml:mi>r</mml:mi><mml:mrow><mml:mo>[</mml:mo><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mtext>S</mml:mtext></mml:mrow><mml:mo>]</mml:mo></mml:mrow><mml:mo>=</mml:mo><mml:mo movablelimits="true" form="prefix">Pr</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mtext>S</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo>]</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mo movablelimits="true" form="prefix">Pr</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mi>f</mml:mi><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>+</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mtext>S</mml:mtext></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub><mml:mo>]</mml:mo></mml:mrow><mml:mo>&#x2264;</mml:mo><mml:msup><mml:mrow><mml:mtext>e</mml:mtext></mml:mrow><mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:mrow></mml:msup><mml:mo stretchy="false">(</mml:mo><mml:mo movablelimits="true" form="prefix">Pr</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mrow><mml:mtext>S</mml:mtext></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub><mml:mo stretchy="false">]</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mo>&#x03B4;</mml:mo></mml:math></disp-formula></p>
<p>yielding <inline-formula id="ieqn-91"><mml:math id="mml-ieqn-91"><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x03B5;</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B4;</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>D</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula> for the Gaussian mechanism in one dimension.</p>
<p><bold>Lemma 1:</bold> <inline-formula id="ieqn-92"><mml:math id="mml-ieqn-92"><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x225C;</mml:mo><mml:mi>f</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>x</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>+</mml:mo><mml:mrow><mml:mtext>N&#xA0;</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mi>&#x03C3;</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>, Let <inline-formula id="ieqn-93"><mml:math id="mml-ieqn-93"><mml:mo>&#x03B5;</mml:mo><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:mn>1</mml:mn><mml:mo>)</mml:mo></mml:mrow></mml:math></inline-formula> be arbitrary. For <inline-formula id="ieqn-94"><mml:math id="mml-ieqn-94"><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>&#x003E;</mml:mo><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>1.25</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo>&#x03B4;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, the Gaussian Mechanism with parameter <inline-formula id="ieqn-95"><mml:math id="mml-ieqn-95"><mml:mi>&#x03C3;</mml:mi><mml:mo>&#x2265;</mml:mo><mml:mi>c</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mi>&#x03F5;</mml:mi></mml:math></inline-formula> is <inline-formula id="ieqn-96"><mml:math id="mml-ieqn-96"><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x03B5;</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B4;</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>D</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>, where <inline-formula id="ieqn-97"><mml:math id="mml-ieqn-97"><mml:mrow><mml:mtext>N&#xA0;</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mi>&#x03C3;</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is a Gaussian distribution with mean 0 and standard deviation <inline-formula id="ieqn-98"><mml:math id="mml-ieqn-98"><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mi>&#x03C3;</mml:mi></mml:math></inline-formula>. When <inline-formula id="ieqn-99"><mml:math id="mml-ieqn-99"><mml:mo>&#x03B4;</mml:mo><mml:mo>&#x003E;</mml:mo><mml:mn>1.25</mml:mn><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mo>&#x2212;</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> and <inline-formula id="ieqn-100"><mml:math id="mml-ieqn-100"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>&#x003C;</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, the Gaussian mechanism is applied to the real-valued function <inline-formula id="ieqn-101"><mml:math id="mml-ieqn-101"><mml:mi>f</mml:mi></mml:math></inline-formula> with sensitivity <inline-formula id="ieqn-102"><mml:math id="mml-ieqn-102"><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi></mml:math></inline-formula> satisfies <inline-formula id="ieqn-103"><mml:math id="mml-ieqn-103"><mml:mrow><mml:mo>(</mml:mo><mml:mo>&#x03B5;</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B4;</mml:mo><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mi>D</mml:mi><mml:mi>P</mml:mi></mml:math></inline-formula>. Lemma 1 is proved as follows:</p>
<p>Based on the proof of Theorem 1. we have the Gaussian noise distribution in this paper is subject to <inline-formula id="ieqn-104"><mml:math id="mml-ieqn-104"><mml:mi>x</mml:mi><mml:mo>&#x223C;</mml:mo><mml:mrow><mml:mo>&#x1D4A9;</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mi>&#x03C3;</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, when <inline-formula id="ieqn-105"><mml:math id="mml-ieqn-105"><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>&#x003E;</mml:mo><mml:mn>2</mml:mn><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>1.25</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo>&#x03B4;</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, we have</p>
<p><disp-formula id="eqn-19">
<label>(19)</label>
<mml:math id="mml-eqn-19" display="block"><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mi>&#x03C3;</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>&#x2265;</mml:mo><mml:msup><mml:mi>c</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mfrac><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mfrac><mml:mo>&#x003E;</mml:mo><mml:mn>2</mml:mn><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>1.21</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mo>&#x03B4;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mfrac><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mfrac></mml:math></disp-formula></p>
<p>Namely,</p>
<p><disp-formula id="eqn-20">
<label>(20)</label>
<mml:math id="mml-eqn-20" display="block"><mml:mo>&#x03B4;</mml:mo><mml:mo>&#x003E;</mml:mo><mml:mn>1.25</mml:mn><mml:msup><mml:mrow><mml:mtext>e</mml:mtext></mml:mrow><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:msup><mml:mi>&#x03C3;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow><mml:mrow><mml:msup><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup></mml:mrow></mml:mrow></mml:msup></mml:math></disp-formula></p>
<p>Considering the above differential privacy mechanism, the noise scope affects the privacy cost of the client and the convergence speed of the federated learning training process. Therefore, choosing the appropriate noise level remains a significant research problem. In this paper, the distribution of adding Gaussian noise to the gradient obeys the normal distribution <inline-formula id="ieqn-106"><mml:math id="mml-ieqn-106"><mml:mrow><mml:mtext>N&#xA0;</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mn>0</mml:mn><mml:mo>,</mml:mo><mml:msup><mml:mrow><mml:mo>(</mml:mo><mml:msqrt><mml:mn>2</mml:mn></mml:msqrt><mml:mrow><mml:mi mathvariant="normal">&#x0394;</mml:mi></mml:mrow><mml:mi>f</mml:mi><mml:mi>&#x03C3;</mml:mi><mml:mo>)</mml:mo></mml:mrow><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msup><mml:mo>)</mml:mo></mml:mrow><mml:mo>.</mml:mo></mml:math></inline-formula></p>
</sec>
<sec id="s3_2">
<label>3.2</label>
<title>Early Stopping</title>
<p>The early stopping mechanism its commonly used regularization technique in deep neural networks, and its performance is usually better than general regularization methods. Its popularity is mainly due to its effectiveness and simplicity. The model stores and updates the current best parameters during training. When the error on the validation set does not improve further within a pre-specified number of iterations, the algorithm terminates and uses the last best parameters. This process is more formally described in Algorithm 1.</p>
<p>When training large models with sufficient representational power to the point of overfitting, we often observe that the training error gradually decreases over time but the validation error rises again. The early stopping mechanism is mainly a trade-off between training time and generalization error. It reduces communication overhead while obtaining optimal parameters. And because the algorithm reduces the number of communications, thereby also reducing the noise, the introduction of the early stopping mechanism improves the utility of the data.</p>
</sec>
<sec id="s3_3">
<label>3.3</label>
<title>Efficient DP-FL and Main Results</title>
<p>To protect the safety of parameters during federated learning training, it can be considered to add Gaussian noise to each sample gradient. However, adding too much Gaussian noise to the parameters can destroy the performance of the model. Therefore, we need to control the impact of parameter training on model performance during federated learning training. This approach has been extensively studied in previous work [<xref ref-type="bibr" rid="ref-30">30</xref>,<xref ref-type="bibr" rid="ref-33">33</xref>,<xref ref-type="bibr" rid="ref-44">44</xref>], and we make some modifications, especially about the privacy budget. Its training process is shown in Algorithm 2.</p>
<fig id="fig-7">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_40194-fig-7.tif"/>
</fig>
</sec>
</sec>
<sec id="s4">
<label>4</label>
<title>Privacy Analysis</title>
<p>Many researchers have studied the loss of privacy under specific noise. For example, Beimel et al. [<xref ref-type="bibr" rid="ref-45">45</xref>] proposed a privacy amplification theorem, where <inline-formula id="ieqn-126"><mml:math id="mml-ieqn-126"><mml:mrow><mml:mtext>q</mml:mtext></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mtext>L</mml:mtext></mml:mrow><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mtext>N</mml:mtext></mml:mrow></mml:math></inline-formula> is the sampling ratio, where each step is satisfying <inline-formula id="ieqn-127"><mml:math id="mml-ieqn-127"><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>q</mml:mtext></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mtext>q</mml:mtext></mml:mrow><mml:mo>&#x03B4;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mtext>DP</mml:mtext></mml:mrow></mml:math></inline-formula>. Furthermore, Dwork et al. [<xref ref-type="bibr" rid="ref-43">43</xref>] proposed the strong combination theorem, where each step satisfies <inline-formula id="ieqn-128"><mml:math id="mml-ieqn-128"><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>q</mml:mtext></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:msqrt><mml:mrow><mml:mtext>Tln</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B4;</mml:mi></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:msqrt><mml:mo>,</mml:mo><mml:mrow><mml:mtext>Tq</mml:mtext></mml:mrow><mml:mo>&#x03B4;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mtext>DP</mml:mtext></mml:mrow></mml:math></inline-formula> in the case of sampling. However, the strong combination theorem does not take into account the specific noise distribution. Therefore, we adopt the moment account method of Abadi et al. [<xref ref-type="bibr" rid="ref-30">30</xref>] and show that for a specific range of noise and threshold values, Algorithm 2 satisfies <inline-formula id="ieqn-129"><mml:math id="mml-ieqn-129"><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>q</mml:mtext></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:msqrt><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow></mml:msqrt><mml:mo>,</mml:mo><mml:mo>&#x03B4;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mtext>DP</mml:mtext></mml:mrow></mml:math></inline-formula>. Compared with the strong combination theorem, the moment account method of Abadi et al. [<xref ref-type="bibr" rid="ref-30">30</xref>] and show that for a specific range of noise and threshold values, Algorithm 2 satisfies <inline-formula id="ieqn-130"><mml:math id="mml-ieqn-130"><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>q</mml:mtext></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:msqrt><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow></mml:msqrt><mml:mo>,</mml:mo><mml:mo>&#x03B4;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mtext>DP</mml:mtext></mml:mrow></mml:math></inline-formula>. Compared with the strong combination theorem, the moment account makes both bounds tighter, reducing the <inline-formula id="ieqn-131"><mml:math id="mml-ieqn-131"><mml:msqrt><mml:mi>ln</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mn>1</mml:mn><mml:mrow><mml:mo>/</mml:mo></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B4;</mml:mi></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:msqrt></mml:math></inline-formula> and <inline-formula id="ieqn-132"><mml:math id="mml-ieqn-132"><mml:mi>T</mml:mi><mml:mi>q</mml:mi></mml:math></inline-formula> parts of <inline-formula id="ieqn-133"><mml:math id="mml-ieqn-133"><mml:mo>&#x03B4;</mml:mo></mml:math></inline-formula> in the privacy budget <inline-formula id="ieqn-134"><mml:math id="mml-ieqn-134"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow></mml:math></inline-formula>. Therefore, applying the method of moment account leads to tighter bounds and thus obtains a more accurate estimate of the overall privacy loss.</p>
<p><inline-formula id="ieqn-135"><mml:math id="mml-ieqn-135"><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow></mml:math></inline-formula> denotes the output result and the random variable <inline-formula id="ieqn-136"><mml:math id="mml-ieqn-136"><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x1D4F7;</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> denotes the privacy loss, defined as:</p>
<p><bold>Definition 2:</bold> At s, <inline-formula id="ieqn-137"><mml:math id="mml-ieqn-137"><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x1D4F7;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x225C;</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mo movablelimits="true" form="prefix">Pr</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mo movablelimits="true" form="prefix">Pr</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>&#x1D4F7;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow></mml:mrow></mml:mfrac></mml:mstyle></mml:math></inline-formula></p>
<p>The moment mother function of the privacy loss random variable is:</p>
<p><bold>Definition 3: </bold><inline-formula id="ieqn-138"><mml:math id="mml-ieqn-138"><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mrow><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mo>;</mml:mo><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x1D4F7;</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x225C;</mml:mo><mml:mi>l</mml:mi><mml:mi>o</mml:mi><mml:mi>g</mml:mi><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">E</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>&#x223C;</mml:mo><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>d</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msub><mml:mo stretchy="false">[</mml:mo><mml:mi>e</mml:mi><mml:mi>x</mml:mi><mml:mi>p</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x1D4F7;</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">]</mml:mo><mml:mo>.</mml:mo></mml:math></inline-formula></p>
<fig id="fig-8">
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_40194-fig-8.tif"/>
</fig>
<p><inline-formula id="ieqn-178"><mml:math id="mml-ieqn-178"><mml:mi>&#x03B3;</mml:mi></mml:math></inline-formula> is any positive integer, to satisfy the definition of differential privacy, it is necessary to iterate over all <inline-formula id="ieqn-179"><mml:math id="mml-ieqn-179"><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x1D4F7;</mml:mo></mml:mrow></mml:math></inline-formula> prime to obtain <inline-formula id="ieqn-180"><mml:math id="mml-ieqn-180"><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mrow><mml:mrow><mml:mi>&#x02133;</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, which we define as:</p>
<p><bold>Definition 4: </bold><inline-formula id="ieqn-181"><mml:math id="mml-ieqn-181"><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mrow><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x225C;</mml:mo><mml:munder><mml:mrow><mml:mo form="prefix">max</mml:mo></mml:mrow><mml:mrow><mml:mi>d</mml:mi><mml:mo>,</mml:mo><mml:msup><mml:mi>d</mml:mi><mml:mrow><mml:msup><mml:mi></mml:mi><mml:mo>&#x2032;</mml:mo></mml:msup></mml:mrow></mml:msup></mml:mrow></mml:munder><mml:mo>&#x2061;</mml:mo><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mrow><mml:mrow><mml:mi>&#x02133;</mml:mi></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mo>;</mml:mo><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mo>&#x1D4F7;</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula></p>
<p><bold>Theorem 2:</bold> Let <inline-formula id="ieqn-182"><mml:math id="mml-ieqn-182"><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mrow><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> be defined as above; <inline-formula id="ieqn-183"><mml:math id="mml-ieqn-183"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>&#x003E;</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>, the random algorithm <inline-formula id="ieqn-184"><mml:math id="mml-ieqn-184"><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mrow><mml:mtext>is</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mo>&#x03B4;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mtext>DP</mml:mtext></mml:mrow></mml:math></inline-formula> for</p>
<p><disp-formula id="eqn-21">
<label>(21)</label>
<mml:math id="mml-eqn-21" display="block"><mml:mrow><mml:mi mathvariant="normal">&#x03B4;</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:munder><mml:mo movablelimits="true" form="prefix">min</mml:mo><mml:mrow><mml:mi>&#x03B3;</mml:mi></mml:mrow></mml:munder><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mrow><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></disp-formula></p>
<p>According to Definitions 2, 3 and 4, we can prove Theorem 2, the proof is as follows:</p>
<p><italic>Proof</italic>. We have <inline-formula id="ieqn-185"><mml:math id="mml-ieqn-185"><mml:mfrac linethickness="0pt"><mml:mrow><mml:mo movablelimits="true" form="prefix">Pr</mml:mo><mml:mo stretchy="false">[</mml:mo><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2265;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo stretchy="false">]</mml:mo></mml:mrow><mml:mrow><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>&#x223C;</mml:mo><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac><mml:mo>&#x2264;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B4;</mml:mi></mml:mrow></mml:math></inline-formula>, then</p>
<p><disp-formula id="eqn-22">
<label>(22)</label>
<mml:math id="mml-eqn-22" display="block"><mml:mfrac linethickness="0pt"><mml:mrow><mml:mo movablelimits="true" form="prefix">Pr</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2265;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>]</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>&#x223C;</mml:mo><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:mfrac><mml:mo>=</mml:mo><mml:mfrac linethickness="0pt"><mml:mrow><mml:mo movablelimits="true" form="prefix">Pr</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2265;</mml:mo><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B3;</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>&#x223C;</mml:mo><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:mfrac></mml:math></disp-formula></p>
<p>(Markov&#x2019;s): <inline-formula id="ieqn-186"><mml:math id="mml-ieqn-186"><mml:mrow><mml:mtext>P</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo>&#x2265;</mml:mo><mml:mrow><mml:mtext>a</mml:mtext></mml:mrow><mml:mo fence="false" stretchy="false">}</mml:mo><mml:mo>&#x2264;</mml:mo><mml:mstyle displaystyle="true" scriptlevel="0"><mml:mfrac><mml:mrow><mml:mrow><mml:mi mathvariant="double-struck">E</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>x</mml:mtext></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:mtext>a</mml:mtext></mml:mrow></mml:mfrac></mml:mstyle></mml:math></inline-formula>, we have</p>
<p><disp-formula id="eqn-23">
<label>(23)</label>
<mml:math id="mml-eqn-23" display="block"><mml:mfrac linethickness="0pt"><mml:mrow><mml:mo movablelimits="true" form="prefix">Pr</mml:mo><mml:mrow><mml:mo>[</mml:mo><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2265;</mml:mo><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B3;</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>&#x223C;</mml:mo><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:mfrac><mml:mo>&#x2264;</mml:mo><mml:mfrac><mml:mrow><mml:msub><mml:mrow><mml:mi mathvariant="double-struck">E</mml:mi></mml:mrow><mml:mrow><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>&#x223C;</mml:mo><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>&#x1D4F6;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:msub><mml:mrow><mml:mo>[</mml:mo><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mtext>Q</mml:mtext></mml:mrow><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mo>&#x1D4AA;</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>]</mml:mo></mml:mrow></mml:mrow><mml:mrow><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B3;</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>)</mml:mo></mml:mrow></mml:mrow></mml:mfrac><mml:mo>&#x2264;</mml:mo><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B1;</mml:mi></mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B3;</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>)</mml:mo></mml:mrow><mml:mo>&#x2264;</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B4;</mml:mi></mml:mrow></mml:math></disp-formula></p>
<p>So, for any <inline-formula id="ieqn-187"><mml:math id="mml-ieqn-187"><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>&#x003E;</mml:mo><mml:mn>0</mml:mn></mml:math></inline-formula>, <inline-formula id="ieqn-188"><mml:math id="mml-ieqn-188"><mml:mrow><mml:mi mathvariant="normal">&#x03B4;</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:munder><mml:mrow><mml:mo form="prefix">min</mml:mo></mml:mrow><mml:mrow><mml:mi>&#x03B3;</mml:mi></mml:mrow></mml:munder><mml:mo>&#x2061;</mml:mo><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>&#x03B1;</mml:mi><mml:mrow><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow></mml:mrow></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03B3;</mml:mi><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, the mechanism <inline-formula id="ieqn-189"><mml:math id="mml-ieqn-189"><mml:mrow><mml:mo>&#x2133;</mml:mo></mml:mrow></mml:math></inline-formula> is <inline-formula id="ieqn-190"><mml:math id="mml-ieqn-190"><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mo>&#x03B4;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mtext>DP</mml:mtext></mml:mrow></mml:math></inline-formula>.</p>
<p>In each training iteration, the entire dataset satisfies <inline-formula id="ieqn-191"><mml:math id="mml-ieqn-191"><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>q</mml:mtext></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:mo>,</mml:mo><mml:mrow><mml:mtext>q</mml:mtext></mml:mrow><mml:mo>&#x03B4;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mtext>DP</mml:mtext></mml:mrow></mml:math></inline-formula> based on random sampling. Assume that the clipping threshold <inline-formula id="ieqn-192"><mml:math id="mml-ieqn-192"><mml:mi>C</mml:mi></mml:math></inline-formula> and noise <inline-formula id="ieqn-193"><mml:math id="mml-ieqn-193"><mml:mi>&#x03C3;</mml:mi></mml:math></inline-formula> are properly chosen using the method moment account method. In this case, it can be proved that Algorithm 2 satisfies <inline-formula id="ieqn-194"><mml:math id="mml-ieqn-194"><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mtext>q</mml:mtext></mml:mrow><mml:mrow><mml:mi mathvariant="normal">&#x03B5;</mml:mi></mml:mrow><mml:msqrt><mml:mrow><mml:mtext>T</mml:mtext></mml:mrow></mml:msqrt><mml:mo>,</mml:mo><mml:mo>&#x03B4;</mml:mo><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mrow><mml:mtext>DP</mml:mtext></mml:mrow></mml:math></inline-formula>, according to Definitions 2, 3, 4, where <inline-formula id="ieqn-195"><mml:math id="mml-ieqn-195"><mml:mi>T</mml:mi></mml:math></inline-formula> denotes the total number of iterations.</p>
</sec>
<sec id="s5">
<label>5</label>
<title>Experimental Results and Comparison</title>
<sec id="s5_1">
<label>5.1</label>
<title>Experimental Results</title>
<p>This section conducted extensive comparative experiments on the MNIST and the Fashion-MNIST datasets to evaluate the performance of the proposed Efficient DP-FL scheme. As a baseline for comparison, we choose to compare with the state-of-the-art research scheme [<xref ref-type="bibr" rid="ref-30">30</xref>,<xref ref-type="bibr" rid="ref-33">33</xref>,<xref ref-type="bibr" rid="ref-44">44</xref>]. Finally, the experiment is completed under the NVIDIA GeForce RTX 2080TI GPU (64 GB RAM) and Windows 10 system, and the model training is conducted under the PyTorch framework. Experiments have shown that the Efficient DP-FL method is better than previous research methods.</p>
<p>Experimental settings: The experiment uses the MNIST handwritten digit recognition and the Fashion-MNIST clothing classification dataset. Both datasets consist of 70000 sheets 28 &#x00D7; 28 grayscale image, all of which are divided into 10 categories, with 60000 samples used for training and 10000 samples used for testing. This paper uses a shallow CNN, which consists of two convolutional layers and two fully connected layers. Convolutional Layer Use 5 &#x00D7; 5 convolutions with stride 1. The first convolution outputs 12 for each image 6 &#x00D7; 6 &#x00D7; 64 tensors, second convolution for each image output 6 &#x00D7; 6 &#x00D7; 64 tensors. Then ReLU and 2 &#x00D7; 2 maximum pooling layers flatten the second convolution layer into a vector that is fed to a fully connected layer with 384 units. This article divided the training data from 10 clients into non-IID segments based on digital tags and divided into an average of 400 segments. Each customer is assigned 40 random data segments, so each customer&#x2019;s sample has two or five tags. Each round of experiments is set at 1000 epochs. We use a fixed value <inline-formula id="ieqn-196"><mml:math id="mml-ieqn-196"><mml:mo>&#x03B4;</mml:mo><mml:mo>=</mml:mo><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>5</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>, the initial learning rate using MNIST is 0.001 and Fashion-MNIST is 0.002. <inline-formula id="ieqn-197"><mml:math id="mml-ieqn-197"><mml:msub><mml:mrow><mml:mi mathvariant="normal">&#x03C1;</mml:mi></mml:mrow><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> in Adaptive DP-FL is set to 0.9 and <inline-formula id="ieqn-198"><mml:math id="mml-ieqn-198"><mml:msub><mml:mi>&#x03C1;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> is set to 0.999. The clipping threshold <inline-formula id="ieqn-199"><mml:math id="mml-ieqn-199"><mml:mi>C</mml:mi></mml:math></inline-formula> is a popular component of SGD combined with ML and for DP based on FL frameworks, consideration should be given to appropriate clipping threshold <inline-formula id="ieqn-200"><mml:math id="mml-ieqn-200"><mml:mi>C</mml:mi></mml:math></inline-formula>.</p>
<sec id="s5_1_1">
<label>5.1.1</label>
<title>Model Performance for Adaptive DP-FL Method on MNIST and Fashion-MNIST Datasets</title>
<p><xref ref-type="fig" rid="fig-2">Fig. 2</xref> investigates the effect of Adaptive DP-FL&#x2019;s approach on model performance. The accuracy and loss of the Adaptive DP-FL method and the method without ADADP are compared. We set clipping threshold <inline-formula id="ieqn-201"><mml:math id="mml-ieqn-201"><mml:mi>C</mml:mi><mml:mo>=</mml:mo><mml:mn>4</mml:mn></mml:math></inline-formula> and privacy budget <inline-formula id="ieqn-202"><mml:math id="mml-ieqn-202"><mml:mo>&#x03B5;</mml:mo><mml:mo>=</mml:mo><mml:mn>2</mml:mn></mml:math></inline-formula> in the MNIST and Fashion-MNIST datasets. Both methods in the MNIST and Fashion-MNIST datasets use constant noise scale <inline-formula id="ieqn-203"><mml:math id="mml-ieqn-203"><mml:mi>&#x03C3;</mml:mi><mml:mo>=</mml:mo><mml:mn>2.0</mml:mn></mml:math></inline-formula> and constant <inline-formula id="ieqn-204"><mml:math id="mml-ieqn-204"><mml:mo>&#x03B4;</mml:mo><mml:mo>=</mml:mo><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>5</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>. Set the initial learning rate of the experiment in the MNIST dataset to 0.002and in the Fashion-MNIST dataset to 0.001 and set <inline-formula id="ieqn-205"><mml:math id="mml-ieqn-205"><mml:msub><mml:mi>&#x03C1;</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> to 0.9, and <inline-formula id="ieqn-206"><mml:math id="mml-ieqn-206"><mml:msub><mml:mi>&#x03C1;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> to 0.999. We can see that in the MNIST dataset, the final convergence accuracy of the model using Adaptive DP-FL is 94.58% and the model using ADADP is 92.03%. In the Fashion-MNIST dataset, the final convergence accuracy of the model using Adaptive DP-FL is 88.38% and the model using ADADP is 79.91%. For both datasets, the Adaptive DP-FL method significantly outperforms the ADADP method.</p>
<fig id="fig-2">
<label>Figure 2</label>
<caption>
<title>Model performance for adaptive DP-FL method on MNIST and fashion-MNIST datasets</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_40194-fig-2.tif"/>
</fig>
</sec>
<sec id="s5_1_2">
<label>5.1.2</label>
<title>Performance Comparison of Algorithms under Different Noise Scales</title>
<p>As a multi-party collaborative training model method, federated learning its local private data for model training. The data is saved locally on the client and the trained local model is updated to the server, which aggregates the local model. However, federated learning has a natural privacy protection effect. An attacker can still infer local private data through the model parameters of the client or server. Therefore, we introduce a differential privacy technology lighter than the cryptographic method. However, the introduction of differential privacy usually seriously affects the utility of data while protecting data privacy security. To solve this problem, this article proposes a secure and efficient DP-FL scheme. During each update process of the model, add the Gaussian noise to the sample gradient in the differential privacy technology and then iteratively update by an adaptive algorithm. The scheme strengthens the privacy security of the model and improves its performance. To test the robustness of the algorithm under different noise scales, this paper compared the performance of three different algorithms, DPFL-SGD, DPFL-PRMSProp, and the algorithm proposed in this paper under different noise conditions. In general, the larger the noise scale added, the lower the data availability and the worse the model performance.</p>
<p>As seen in <xref ref-type="fig" rid="fig-3">Fig. 3</xref>, in each plot, <inline-formula id="ieqn-207"><mml:math id="mml-ieqn-207"><mml:mo>&#x03B4;</mml:mo><mml:mo>=</mml:mo><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>5</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>, keeping <inline-formula id="ieqn-208"><mml:math id="mml-ieqn-208"><mml:mo>&#x03B5;</mml:mo></mml:math></inline-formula> fixed, in the same noise scale, we can observe that when adding noise scales <inline-formula id="ieqn-209"><mml:math id="mml-ieqn-209"><mml:mi>&#x03C3;</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>4</mml:mn><mml:mo>,</mml:mo><mml:mn>8</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B5;</mml:mo><mml:mo>=</mml:mo><mml:mn>0.5</mml:mn></mml:math></inline-formula>, the final accuracy of the three algorithms is 87.81%, 84.19%, and 77.77%. The overall effect of Efficient DP-FL and DPFL-PRMSProp using adaptive algorithm is better than that of DPFL-SGD, which may be due to the DPSGD algorithm being prone to falling into local optima. Specifically, in the early stages of experiments, the accuracy of our model changes faster, followed by DPFL-PRMSProp, and the improvement of DPFL-SGD is slower. In the later stage of the experiment, the convergence speed of the adaptive differential privacy federated learning algorithm tends to stabilize, and the overall performance is better than the DPFL-PRMSProp and DPFL-SGD algorithms. Under different noise scales, we can observe from <xref ref-type="fig" rid="fig-3">Fig. 3</xref> that the final accuracy of adding noise scales <inline-formula id="ieqn-210"><mml:math id="mml-ieqn-210"><mml:mi>&#x03C3;</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B5;</mml:mo><mml:mo>=</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo></mml:math></inline-formula> are 92.79%, 93.48%, and 94.69%, respectively. The final accuracies of adding noise scales <inline-formula id="ieqn-211"><mml:math id="mml-ieqn-211"><mml:mi>&#x03C3;</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mn>4</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B5;</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, are 88.39%, 91.45%, and 92.58%, and the final accuracies of noise scales <inline-formula id="ieqn-212"><mml:math id="mml-ieqn-212"><mml:mi>&#x03C3;</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>4</mml:mn><mml:mo>,</mml:mo><mml:mn>8</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B5;</mml:mo><mml:mo>=</mml:mo><mml:mn>0.5</mml:mn></mml:math></inline-formula> are 77.77%, 84.19%, and 87.81%. That is, the final accuracy of adding noise scales <inline-formula id="ieqn-213"><mml:math id="mml-ieqn-213"><mml:mi>&#x03C3;</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo>,</mml:mo><mml:mn>2</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B5;</mml:mo><mml:mo>=</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo></mml:math></inline-formula> are 4.4%, 2.03%, 2.11% higher than adding noise scales <inline-formula id="ieqn-214"><mml:math id="mml-ieqn-214"><mml:mi>&#x03C3;</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>2</mml:mn><mml:mo>,</mml:mo><mml:mn>4</mml:mn><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo><mml:mo>&#x03B5;</mml:mo><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, and 15.02%, 9.29%, 6.88% higher than large noise. Therefore, the greater the noise, the greater the impact on the convergence performance of the model. The impact of moderate noise is next. The smaller the noise, the smaller the impact on algorithm performance.</p>
<fig id="fig-3">
<label>Figure 3</label>
<caption>
<title>The effect of different noise scales on the convergence performance of the algorithm</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_40194-fig-3.tif"/>
</fig>
<p>The federated learning model with adaptive differential privacy is less sensitive to the size of the noise scale. Experiments show that with a fixed 1000 rounds of communication iterations, our algorithm has faster convergence speed and better final results. Our scheme can achieve better model performance with lower communication costs when applied to actual demand scenarios.</p>
</sec>
<sec id="s5_1_3">
<label>5.1.3</label>
<title>Model Performance for Early Stopping Mechanism on MNIST and Fashion-MNIST Datasets</title>
<p>It can be seen from <xref ref-type="fig" rid="fig-4">Fig. 4</xref> that after adding the early stopping mechanism, different algorithms converge in advance. On the MNIST dataset, ADADP converges early with 91.20% accuracy in 762 epochs. Compared with the fixed-setting 1000-round iteration experiment, it saves 238 rounds of communication overhead while achieving similar performance. Our algorithm converges ahead of time with 94.01% accuracy in 639 rounds, which saves 361 rounds of communication overhead while achieving similar performance. On the Fashion-MNIST dataset, ADADP converges early with 91.62% accuracy at 834 rounds. Compared with the fixed-set 1000-round iteration experiment, it saves 166 rounds of communication overhead while achieving similar performance. Our algorithm converges ahead of time with 94.93% accuracy in 785 rounds, which saves 215 rounds of communication overhead while achieving similar performance. At the same time, we can see that our algorithm outperforms previous methods. To sum up, the early stopping mechanism can reduce communication overhead while ensuring the convergence of the model. Therefore, compared to other methods, our algorithm is better able to improve data utility while keeping data safe.</p>
<fig id="fig-4">
<label>Figure 4</label>
<caption>
<title>Performance for early stopping mechanism on MNIST and fashion-MNIST datasets</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_40194-fig-4.tif"/>
</fig>
</sec>
<sec id="s5_1_4">
<label>5.1.4</label>
<title>Model Performance for Efficient DP-FL Method on MNIST and Fashion-MNIST Datasets</title>
<p><xref ref-type="fig" rid="fig-5">Fig. 5</xref> investigates the performance of the Efficient DP-FL method on the MNIST and the Fashion-MNIST datasets. The Efficient DP-FL method combines the effects of Adaptive DP-FL and Early Stopping mechanism on model performance. The accuracy and loss of differential privacy federated learning methods with adaptive Gaussian noise and constant noise without adaptation are compared. We set the same clipping threshold <inline-formula id="ieqn-215"><mml:math id="mml-ieqn-215"><mml:mi>C</mml:mi><mml:mo>=</mml:mo><mml:mn>4</mml:mn></mml:math></inline-formula> in the MNIST and Fashion-MNIST datasets. The two methods in the MNIST dataset and Fashion-MNIST dataset have constant noise scale <inline-formula id="ieqn-216"><mml:math id="mml-ieqn-216"><mml:mi>&#x03C3;</mml:mi><mml:mo>=</mml:mo><mml:mn>2.0</mml:mn></mml:math></inline-formula> (Because the larger the noise value, the greater the impact on the performance of the model. Setting the noise value too small does not protect data. Through a large number of experiments, it has been found that when the noise value is set to 2, the model performance is the best.) and constant <inline-formula id="ieqn-217"><mml:math id="mml-ieqn-217"><mml:mo>&#x03B4;</mml:mo><mml:mo>=</mml:mo><mml:msup><mml:mn>10</mml:mn><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:mn>5</mml:mn></mml:mrow></mml:msup></mml:math></inline-formula>, privacy budget <inline-formula id="ieqn-218"><mml:math id="mml-ieqn-218"><mml:mo>&#x03B5;</mml:mo><mml:mo>=</mml:mo><mml:mn>2</mml:mn></mml:math></inline-formula>, set the initial learning rate of the experiment in the MNIST dataset to 0.002 and in the Fashion-MNIST dataset to 0.001, set <inline-formula id="ieqn-219"><mml:math id="mml-ieqn-219"><mml:msub><mml:mi>&#x03C1;</mml:mi><mml:mrow><mml:mn>1</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> to 0.9, and <inline-formula id="ieqn-220"><mml:math id="mml-ieqn-220"><mml:msub><mml:mi>&#x03C1;</mml:mi><mml:mrow><mml:mn>2</mml:mn></mml:mrow></mml:msub></mml:math></inline-formula> to 0.999. We can see that in the MNIST dataset, the model using Efficient DP-FL converges when the accuracy reaches 94.61% in 578 rounds, and the model using ADADP converges when the accuracy reaches 93.40% in 506 rounds. In the Fashion-MNIST dataset, the model using Efficient DP-FL converges when the accuracy is 94.29% in 636 rounds, and the model using ADADP converges when the accuracy is 92.18% in 751 rounds. For these two data sets, the final accuracy of using Efficient DP-FL is 1.21% and 2.11% higher than that of the method using ADADP, respectively, and the number of communication rounds using Efficient DP-FL is different from that of the method using ADADP. The reduction is 71 rounds, 115 rounds, which shows that the Efficient DP-FL method can save more communication overhead. In addition, we also observed that the Efficient DP-FL method (combining Adaptive DP-FL and Early Stopping mechanism) outperformed the previous Adaptive DP-FL and Early Stopping mechanism method on both datasets. The Efficient DP-FL communication overhead is reduced by 133 rounds and 149 rounds, respectively, compared with the Adaptive DP-FL and Early Stopping mechanism methods alone.</p>
<fig id="fig-5">
<label>Figure 5</label>
<caption>
<title>Performance for efficient DP-FL method on MNIST and fashion-MNIST datasets</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_40194-fig-5.tif"/>
</fig>
</sec>
</sec>
<sec id="s5_2">
<label>5.2</label>
<title>Comparison</title>
<p><xref ref-type="table" rid="table-2">Table 2</xref> shows a comparison of the studied algorithms, including data security, data utility, adaptation, and communication cost. The above comparison shows that our algorithm can simultaneously satisfy data security, data utility, an adaptability and reduce communication overhead. In contrast, other algorithms do not have this capability. Specifically, reference [<xref ref-type="bibr" rid="ref-30">30</xref>] proposed a DPSGD algorithm for the first time, which uses a Gaussian down-sampling mechanism and uses moment calculation technology to measure privacy loss. Although this algorithm can effectively protect the data security of local clients, adding a large amount of noise to the algorithm will reduce the usefulness of the data, and the algorithm cannot adaptively reduce noise [<xref ref-type="bibr" rid="ref-33">33</xref>]. An ADADP algorithm was proposed, which adaptively adjusts the noise range under a given privacy level, enabling the algorithm to converge quickly [<xref ref-type="bibr" rid="ref-44">44</xref>]. A UDP algorithm with a CRD method are proposed. The UDP algorithm can effectively protect the data security of local users, and a UDP algorithm with a CRD method can effectively reduce the number of communication rounds. However, compared to the scheme proposed in this article, this algorithm cannot effectively improve the utilization rate of data, and the communication cost is not as low as the proposed scheme. However, compared with Efficient DP-FL algorithm, this algorithm cannot effectively improve the utility of data and reduce the communication cost-effectively. In summary, the Efficient DP-FL algorithm fully satisfies the advantages of data security, data utility, adaptability, and low communication overhead. The above is a qualitative analysis of different algorithms. The following will quantitatively analyze the communication costs of different schemes, as shown in <xref ref-type="fig" rid="fig-6">Fig. 6</xref>. Quantitative comparative analysis has been added.</p>
<table-wrap id="table-2">
<label>Table 2</label>
<caption>
<title>Comparison of existing research algorithms</title>
</caption>
<table frame="hsides">
<colgroup>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
<col align="left"/>
</colgroup>
<thead>
<tr>
<th>Algorithms</th>
<th>Data security</th>
<th>Data utility</th>
<th>Adaptivity</th>
<th>Communication cost reduction</th>
</tr>
</thead>
<tbody>
<tr>
<td>Scheme [<xref ref-type="bibr" rid="ref-30">30</xref>]</td>
<td><inline-formula id="ieqn-221"><mml:math id="mml-ieqn-221"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td>&#x00D7;</td>
<td>&#x00D7;</td>
<td>&#x00D7;</td>
</tr>
<tr>
<td>Scheme [<xref ref-type="bibr" rid="ref-33">33</xref>]</td>
<td><inline-formula id="ieqn-222"><mml:math id="mml-ieqn-222"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td>&#x00D7;</td>
<td><inline-formula id="ieqn-223"><mml:math id="mml-ieqn-223"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td>&#x00D7;</td>
</tr>
<tr>
<td>Scheme [<xref ref-type="bibr" rid="ref-44">44</xref>]</td>
<td><inline-formula id="ieqn-224"><mml:math id="mml-ieqn-224"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td>&#x00D7;</td>
<td>&#x00D7;</td>
<td><inline-formula id="ieqn-225"><mml:math id="mml-ieqn-225"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
</tr>
<tr>
<td>Our scheme</td>
<td><inline-formula id="ieqn-226"><mml:math id="mml-ieqn-226"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-227"><mml:math id="mml-ieqn-227"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-228"><mml:math id="mml-ieqn-228"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
<td><inline-formula id="ieqn-229"><mml:math id="mml-ieqn-229"><mml:mo>&#x221A;</mml:mo></mml:math></inline-formula></td>
</tr>
</tbody>
</table>
</table-wrap><fig id="fig-6">
<label>Figure 6</label>
<caption>
<title>Communication cost comparison of different scheme</title>
</caption>
<graphic mimetype="image" mime-subtype="tif" xlink:href="CSSE_40194-fig-6.tif"/>
</fig>
<p><xref ref-type="fig" rid="fig-6">Fig. 6</xref> compares the time cost of a round of communication for different schemes. The proposed scheme uses adaptive learning rates to adjust the gradient descent train process to avoid model overfitting and fluctuations, and uses an early shutdown system to reduce noise, ensuring that federated learning schemes train efficiently while protecting data security. The communication cost comparison results are shown in <xref ref-type="fig" rid="fig-6">Fig. 6</xref>. Looking at <xref ref-type="fig" rid="fig-6">Fig. 6</xref>, we can draw the following conclusions.
<list list-type="bullet">
<list-item>
<p>The scheme [<xref ref-type="bibr" rid="ref-30">30</xref>] has the longest running time, while the schemes [<xref ref-type="bibr" rid="ref-33">33</xref>] and [<xref ref-type="bibr" rid="ref-44">44</xref>] have the lowest running time. The above comparison shows that the scheme proposed in this article is effective.</p>
</list-item>
<list-item>
<p>Because Fashion MNIST is a set of 28 &#x00D7; 28 grayscale clothing images, its image data is more complex than MNIST, the four schemes on MNIST have shorter runtime than those on Fashion-MNIST.</p></list-item>
</list></p>
</sec>
</sec>
<sec id="s6">
<label>6</label>
<title>Conclusion</title>
<p>The main contributions of this article are reflected in three aspects. Firstly, an Efficient DP-FL algorithm is proposed, which has higher accuracy than previous algorithms. In addition, the Efficient DP-FL algorithm adds an early stopping mechanism to improve the utility of the data. Secondly, it is strictly proved mathematically that the Efficient DP-FL algorithm satisfies differential privacy. Thirdly, the Efficient DP-FL algorithm is applied to train a CNN model on a deep learning network with real datasets, and the better performance of the Efficient DP-FL algorithm compared to previous methods is evaluated through experiments.</p>
<p>Based on the Efficient DP-FL proposed in this article, many further tasks deserve attention. In particular, this article uses a shallow neural network model, and the deeper neural network model is worth further research. In addition, you can apply the techniques in this article to language modeling tasks through experience in the MNIST and Fashion-MNIST.</p>
</sec>
</body>
<back>
<ack>
<p>The authors wish to express their appreciation to the reviewers for their helpful suggestions which greatly improved the presentation of this paper.</p>
</ack>
<sec><title>Funding Statement</title>
<p>This work was supported in part by the Communication Security Laboratory Science and Technology Fund under Grant No. 61421030209012105, in part by the Sichuan Provincial Science and Technology Department Project under Grant 2019YFN0104, in part by the Yibin Science and Technology Plan Project under Grant 2021GY008, and in part by the Sichuan University of Science and Engineering Postgraduate Innovation Fund Project under Grant Y2022154.</p></sec>
<sec><title>Author Contributions</title>
<p>Study conception and design: Sanxiu Jiao; data collection: Jintao Meng; analysis and interpretation of results: Sanxiu Jiao, Yue Zhao, Lecai Cai; draft manuscript preparation: Kui Cheng. All authors reviewed the results and approved the final version of the manuscript.</p></sec>
<sec sec-type="data-availability"><title>Availability of Data and Materials</title>
<p>All data are derived from public datasets.</p></sec>
<sec sec-type="COI-statement"><title>Conflicts of Interest</title>
<p>The authors declare they have no conflicts of interest to report regarding the present study.</p>
</sec>
<ref-list content-type="authoryear">
<title>References</title>
<ref id="ref-1"><label>[1]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J. G.</given-names> <surname>Greener</surname></string-name>, <string-name><given-names>S. M.</given-names> <surname>Kandathil</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Moffat</surname></string-name> and <string-name><given-names>D. T.</given-names> <surname>Jones</surname></string-name></person-group>, &#x201C;<article-title>A guide to machine learning for biologists</article-title>,&#x201D; <source>Nature Reviews Molecular Cell Biology</source>, vol. <volume>23</volume>, no. <issue>1</issue>, pp. <fpage>40</fpage>&#x2013;<lpage>55</lpage>, <year>2022</year>; <pub-id pub-id-type="pmid">34518686</pub-id></mixed-citation></ref>
<ref id="ref-2"><label>[2]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T. R.</given-names> <surname>Ramesh</surname></string-name>, <string-name><given-names>U. K.</given-names> <surname>Lilhore</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Poongodi</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Simaiya</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Kaur</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Predictive analysis of heart diseases with machine learning approaches</article-title>,&#x201D; <source>Malaysian Journal of Computer Science</source>, pp. <fpage>132</fpage>&#x2013;<lpage>148</lpage>, <year>2022</year>. <pub-id pub-id-type="doi">10.22452/mjcs.sp2022no1.10</pub-id></mixed-citation></ref>
<ref id="ref-3"><label>[3]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Ali</surname></string-name>, <string-name><given-names>T. M.</given-names> <surname>Ghazal</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Ahmed</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Abbas</surname></string-name>, <string-name><given-names>M. A.</given-names> <surname>Khan</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Fusion-based supply chain collaboration using machine learning techniques</article-title>,&#x201D; <source>Intelligent Automation &#x0026; Soft Computing</source>, vol. <volume>31</volume>, no. <issue>3</issue>, pp. <fpage>1671</fpage>&#x2013;<lpage>1687</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-4"><label>[4]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Gao</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>Q.</given-names> <surname>Liu</surname></string-name></person-group>, &#x201C;<article-title>Image representations of numerical simulations for training neural networks</article-title>,&#x201D; <source>Computer Modeling in Engineering &#x0026; Sciences</source>, vol. <volume>134</volume>, no. <issue>2</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>13</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-5"><label>[5]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Gao</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>Q.</given-names> <surname>Liu</surname></string-name></person-group>, &#x201C;<article-title>Predicting the pore-pressure and temperature of fire-loaded concrete by a hybrid neural network</article-title>,&#x201D; <source>International Journal of Computational Methods</source>, vol. <volume>19</volume>, no. <issue>8</issue>, pp. <fpage>247</fpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-6"><label>[6]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Y.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Zhao</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Kang</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Yassine</surname></string-name> and <string-name><given-names>D.</given-names> <surname>Niyato</surname></string-name></person-group>, &#x201C;<article-title>Communication-efficient and attack-resistant federated edge learning for Industrial Internet of Things</article-title>,&#x201D; <source>ACM Transactions on Internet Technology</source>, vol. <volume>22</volume>, no. <issue>3</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>22</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-7"><label>[7]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Xue</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Huang</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Baker</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Privacy-preserving and traceable federated learning for data sharing in industrial IoT applications</article-title>,&#x201D; <source>Expert Systems with Applications</source>, vol. <volume>213</volume>, pp. <fpage>119036</fpage>, <year>2023</year>. <pub-id pub-id-type="doi">10.1016/j.eswa.2022.119036</pub-id></mixed-citation></ref>
<ref id="ref-8"><label>[8]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Imteaj</surname></string-name>, <string-name><given-names>U.</given-names> <surname>Thakker</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Li</surname></string-name> and <string-name><given-names>M. H.</given-names> <surname>Amini</surname></string-name></person-group>, &#x201C;<article-title>A survey on federated learning for resource-constrained IoT devices</article-title>,&#x201D; <source>IEEE Internet of Things Journal</source>, vol. <volume>9</volume>, no. <issue>1</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>24</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-9"><label>[9]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D. C.</given-names> <surname>Nguyen</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Ding</surname></string-name>, <string-name><given-names>P. N.</given-names> <surname>Pathirana</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Seneviratne</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Li</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Federated learning for Internet of Things: A comprehensive survey</article-title>,&#x201D; <source>IEEE Communications Surveys &#x0026; Tutorials</source>, vol. <volume>23</volume>, no. <issue>3</issue>, pp. <fpage>1622</fpage>&#x2013;<lpage>1658</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-10"><label>[10]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>T.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Gao</surname></string-name>, <string-name><given-names>C.</given-names> <surname>He</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Krishnamachari</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Federated learning for the internet of things: Applications, challenges, and opportunities</article-title>,&#x201D; <source>IEEE Internet of Things Magazine</source>, vol. <volume>5</volume>, no. <issue>1</issue>, pp. <fpage>24</fpage>&#x2013;<lpage>29</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-11"><label>[11]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Ouyang</surname></string-name>, <string-name><given-names>F. Y.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Tian</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Jia</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Qi</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Artificial identification: A novel privacy framework for federated learning based on blockchain</article-title>,&#x201D; <source>IEEE Transactions on Computational Social Systems</source>, pp. <fpage>1</fpage>&#x2013;<lpage>10</lpage>, <year>2023</year>. <pub-id pub-id-type="doi">10.1109/TCSS.2022.3226861</pub-id></mixed-citation></ref>
<ref id="ref-12"><label>[12]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Yazdinejad</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Dehghantanha</surname></string-name>, <string-name><given-names>R. M.</given-names> <surname>Parizi</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Hammoudeh</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Karimipour</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Block hunter: Federated learning for cyber threat hunting in blockchain-based IIoT networks</article-title>,&#x201D; <source>IEEE Transactions on Industrial Informatics</source>, vol. <volume>18</volume>, no. <issue>11</issue>, pp. <fpage>8356</fpage>&#x2013;<lpage>8366</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-13"><label>[13]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Islam</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Al Amin</surname></string-name> and <string-name><given-names>S. Y.</given-names> <surname>Shin</surname></string-name></person-group>, &#x201C;<article-title>FBI: A federated learning-based blockchain-embedded data accumulation scheme using drones for internet of things</article-title>,&#x201D; <source>IEEE Wireless Communications Letters</source>, vol. <volume>11</volume>, no. <issue>5</issue>, pp. <fpage>972</fpage>&#x2013;<lpage>976</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-14"><label>[14]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Lakhan</surname></string-name>, <string-name><given-names>M. A.</given-names> <surname>Mohammed</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Kadry</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Al-Qahtani</surname></string-name>, <string-name><given-names>M. S.</given-names> <surname>Maashi</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Federated learning-aware multi-objective modeling and blockchain-enable system for IIoT applications</article-title>,&#x201D; <source>Computers and Electrical Engineering</source>, vol. <volume>100</volume>, pp. <fpage>107839</fpage>, <year>2022</year>. <pub-id pub-id-type="doi">10.1016/j.compeleceng.2022.107839</pub-id></mixed-citation></ref>
<ref id="ref-15"><label>[15]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Issa</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Moustafa</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Turnbull</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Sohrabi</surname></string-name> and <string-name><given-names>Z.</given-names> <surname>Tari</surname></string-name></person-group>, &#x201C;<article-title>Blockchain-based federated learning for securing Internet of Things: A comprehensive survey</article-title>,&#x201D; <source>ACM Computing Surveys</source>, vol. <volume>55</volume>, no. <issue>9</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>43</lpage>, <year>2023</year>.</mixed-citation></ref>
<ref id="ref-16"><label>[16]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Ali</surname></string-name>, <string-name><given-names>F.</given-names> <surname>Naeem</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Tariq</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Kaddoum</surname></string-name></person-group>, &#x201C;<article-title>Federated learning for privacy preservation in smart healthcare systems: A comprehensive survey</article-title>,&#x201D; <source>IEEE Journal of Biomedical and Health Informatics</source>, vol. <volume>27</volume>, no. <issue>2</issue>, pp. <fpage>778</fpage>&#x2013;<lpage>789</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-17"><label>[17]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K. S.</given-names> <surname>Arikumar</surname></string-name>, <string-name><given-names>S. B.</given-names> <surname>Prathiba</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Alazab</surname></string-name>, <string-name><given-names>T. R.</given-names> <surname>Gadekallu</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Pandya</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>FL-PMI: Federated learning-based person movement identification through wearable devices in smart healthcare systems</article-title>,&#x201D; <source>Sensors</source>, vol. <volume>22</volume>, no. <issue>4</issue>, pp. <fpage>1377</fpage>, <year>2022</year>; <pub-id pub-id-type="pmid">35214282</pub-id></mixed-citation></ref>
<ref id="ref-18"><label>[18]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>D. C.</given-names> <surname>Nguyen</surname></string-name>, <string-name><given-names>Q. V.</given-names> <surname>Pham</surname></string-name>, <string-name><given-names>P. N.</given-names> <surname>Pathirana</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Ding</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Seneviratne</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Federated learning for smart healthcare: A survey</article-title>,&#x201D; <source>ACM Computing Surveys</source>, vol. <volume>55</volume>, no. <issue>3</issue>, pp. <fpage>1</fpage>&#x2013;<lpage>37</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-19"><label>[19]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P.</given-names> <surname>Manoharan</surname></string-name>, <string-name><given-names>R.</given-names> <surname>Walia</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Iwendi</surname></string-name>, <string-name><given-names>T. A.</given-names> <surname>Ahanger</surname></string-name>, <string-name><given-names>S. T.</given-names> <surname>Suganthi</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>SVM-based generative adverserial networks for federated learning and edge computing attack model and outpoising</article-title>,&#x201D; <source>Expert Systems</source>, vol. <volume>40</volume>, no. <issue>5</issue>, pp. <fpage>e13072</fpage>, <year>2022</year>. <pub-id pub-id-type="doi">10.1111/exsy.13072</pub-id></mixed-citation></ref>
<ref id="ref-20"><label>[20]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>H.</given-names> <surname>Hu</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Salcic</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Sun</surname></string-name>, <string-name><given-names>G.</given-names> <surname>Dobbie</surname></string-name> and <string-name><given-names>X.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Source inference attacks in federated learning</article-title>,&#x201D; in <conf-name>2021 IEEE Int. Conf. on Data Mining (ICDM)</conf-name>, <publisher-loc>Auckland, New Zealand</publisher-loc>, pp. <fpage>1102</fpage>&#x2013;<lpage>1107</lpage>, <year>2021</year>. </mixed-citation></ref>
<ref id="ref-21"><label>[21]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>B.</given-names> <surname>Ghimire</surname></string-name> and <string-name><given-names>D. B.</given-names> <surname>Rawat</surname></string-name></person-group>, &#x201C;<article-title>Recent advances on federated learning for cybersecurity and cybersecurity for federated learning for Internet of Things</article-title>,&#x201D; <source>IEEE Internet of Things Journal</source>, vol. <volume>9</volume>, no. <issue>11</issue>, pp. <fpage>8229</fpage>&#x2013;<lpage>8249</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-22"><label>[22]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Fu</surname></string-name>, <string-name><given-names>X.</given-names> <surname>Zhang</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Ji</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Wu</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Label inference attacks against vertical federated learning</article-title>,&#x201D; in <conf-name>31st USENIX Security Symp. (USENIX Security 22)</conf-name>, <publisher-loc>Boston, MA</publisher-loc>, pp. <fpage>1397</fpage>&#x2013;<lpage>1414</lpage>, <year>2022</year>. </mixed-citation></ref>
<ref id="ref-23"><label>[23]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>V.</given-names> <surname>Shejwalkar</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Houmansadr</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Kairouz</surname></string-name> and <string-name><given-names>D.</given-names> <surname>Ramage</surname></string-name></person-group>, &#x201C;<article-title>Back to the drawing board: A critical evaluation of poisoning attacks on production federated learning</article-title>,&#x201D; in <conf-name>2022 IEEE Symp. on Security and Privacy (SP)</conf-name>, <publisher-loc>Francisco, CA, USA</publisher-loc>, pp. <fpage>1354</fpage>&#x2013;<lpage>1371</lpage>, <year>2022</year>. </mixed-citation></ref>
<ref id="ref-24"><label>[24]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Lyu</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Yu</surname></string-name> and <string-name><given-names>G.</given-names> <surname>Chen</surname></string-name></person-group>, &#x201C;<article-title>Practical attribute reconstruction attack against federated learning</article-title>,&#x201D; <source>IEEE Transactions on Big Data</source>, pp. <fpage>1</fpage>, <year>2022</year>. <pub-id pub-id-type="doi">10.1109/TBDATA.2022.3159236</pub-id></mixed-citation></ref>
<ref id="ref-25"><label>[25]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>B.</given-names> <surname>McMahan</surname></string-name>, <string-name><given-names>E.</given-names> <surname>Moore</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Ramage</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Hampson</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Arcas</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Communication-efficient learning of deep networks from decentralized data, artificial intelligence and statistics</article-title>,&#x201D; <source>PMLR</source>, vol. <volume>54</volume>, pp. <fpage>1273</fpage>&#x2013;<lpage>1282</lpage>, <year>2017</year>.</mixed-citation></ref>
<ref id="ref-26"><label>[26]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Jin</surname></string-name>, <string-name><given-names>E.</given-names> <surname>McMurtry</surname></string-name>, <string-name><given-names>B. I. P.</given-names> <surname>Rubinstein</surname></string-name> and <string-name><given-names>O.</given-names> <surname>Ohrimenko</surname></string-name></person-group>, &#x201C;<article-title>Are we there yet? Timing and floating-point attacks on differential privacy systems</article-title>,&#x201D; in <conf-name>2022 IEEE Symp. on Security and Privacy (SP)</conf-name>, <publisher-loc>Francisco, CA, USA</publisher-loc>, pp. <fpage>473</fpage>&#x2013;<lpage>488</lpage>, <year>2022</year>. </mixed-citation></ref>
<ref id="ref-27"><label>[27]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Bu</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Dong</surname></string-name>, <string-name><given-names>Q.</given-names> <surname>Long</surname></string-name> and <string-name><given-names>W. J.</given-names> <surname>Su</surname></string-name></person-group>, &#x201C;<article-title>Deep learning with gaussian differential privacy</article-title>,&#x201D; <source>Harvard Data Science Review</source>, vol. <volume>2020</volume>, no. <issue>23</issue>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-28"><label>[28]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>P. C. M.</given-names> <surname>Arachchige</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Bertok</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Khalil</surname></string-name>, <string-name><given-names>D.</given-names> <surname>Liu</surname></string-name> and <string-name><given-names>S.</given-names> <surname>Camtepe</surname></string-name></person-group>, &#x201C;<article-title>Local differential privacy for deep learning</article-title>,&#x201D; <source>IEEE Internet of Things Journal</source>, vol. <volume>7</volume>, no. <issue>7</issue>, pp. <fpage>5827</fpage>&#x2013;<lpage>5842</lpage>, <year>2019</year>.</mixed-citation></ref>
<ref id="ref-29"><label>[29]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>N.</given-names> <surname>Papernot</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Thakurta</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Song</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Chien</surname></string-name> and <string-name><given-names>&#x00DA;.</given-names> <surname>Erlingsson</surname></string-name></person-group>, &#x201C;<article-title>Tempered sigmoid activations for deep learning with differential privacy</article-title>,&#x201D; <source>Proceedings of the AAAI Conference on Artificial Intelligence</source>, vol. <volume>35</volume>, no. <issue>10</issue>, pp. <fpage>9312</fpage>&#x2013;<lpage>9321</lpage>, <year>2021</year>. <pub-id pub-id-type="doi">10.1609/aaai.v35i10.17123</pub-id></mixed-citation></ref>
<ref id="ref-30"><label>[30]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>M.</given-names> <surname>Abadi</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Chu</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Goodfellow</surname></string-name>, <string-name><given-names>H. B.</given-names> <surname>McMahan</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Mironov</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Deep learning with differential privacy</article-title>,&#x201D; in <conf-name>Proc. of the 2016 ACM SIGSAC Conf. on Computer and Communications Security</conf-name>, pp. <fpage>308</fpage>&#x2013;<lpage>318</lpage>, <year>2016</year>. <pub-id pub-id-type="doi">10.1145/2976749.2978318</pub-id></mixed-citation></ref>
<ref id="ref-31"><label>[31]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Lee</surname></string-name> and <string-name><given-names>D.</given-names> <surname>Kifer</surname></string-name></person-group>, &#x201C;<article-title>Concentrated differentially private gradient descent with adaptive per-iteration privacy budget</article-title>,&#x201D; in <conf-name>Proc. of the 24th ACM SIGKDD Int. Conf. on Knowledge Discovery &#x0026; Data Mining</conf-name>, pp. <fpage>1656</fpage>&#x2013;<lpage>1665</lpage>, <year>2018</year>. <pub-id pub-id-type="doi">10.1145/3219819.3220076</pub-id></mixed-citation></ref>
<ref id="ref-32"><label>[32]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Wei</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Ding</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Ma</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Yang</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>Federated learning with differential privacy: Algorithms and performance analysis</article-title>,&#x201D; <source>IEEE Transactions on Information Forensics and Security</source>, vol. <volume>15</volume>, pp. <fpage>3454</fpage>&#x2013;<lpage>3469</lpage>, <year>2020</year>.</mixed-citation></ref>
<ref id="ref-33"><label>[33]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>Z.</given-names> <surname>Xu</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Shi</surname></string-name>, <string-name><given-names>A. X.</given-names> <surname>Liu</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Zhao</surname></string-name> and <string-name><given-names>L.</given-names> <surname>Chen</surname></string-name></person-group>, &#x201C;<article-title>An adaptive and fast convergent approach to differentially private deep learning</article-title>,&#x201D; in <conf-name>IEEE INFOCOM 2020-IEEE Conf. on Computer Communications</conf-name>, <publisher-loc>Toronto, ON, Canada</publisher-loc>, pp. <fpage>1867</fpage>&#x2013;<lpage>1876</lpage>, <year>2020</year>. </mixed-citation></ref>
<ref id="ref-34"><label>[34]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>S.</given-names> <surname>Truex</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Baracaldo</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Anwar</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Steinke</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Ludwig</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>A hybrid approach to privacy-preserving federated learning</article-title>,&#x201D; in <conf-name>Proc. of the 12th ACM Workshop on Artificial Intelligence and Security</conf-name>, pp. <fpage>1</fpage>&#x2013;<lpage>11</lpage>, <year>2019</year>. <pub-id pub-id-type="doi">10.1145/3338501.3357370</pub-id></mixed-citation></ref>
<ref id="ref-35"><label>[35]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Q.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Wen</surname></string-name>, <string-name><given-names>Z.</given-names> <surname>Wu</surname></string-name>, <string-name><given-names>S.</given-names> <surname>Hu</surname></string-name>, <string-name><given-names>N.</given-names> <surname>Wang</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>A survey on federated learning systems: Vision, hype and reality for data privacy and protection</article-title>,&#x201D; <source>IEEE Transactions on Knowledge and Data Engineering</source>, vol. <volume>35</volume>, no. <issue>4</issue>, pp. <fpage>3347</fpage>&#x2013;<lpage>3366</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-36"><label>[36]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>L.</given-names> <surname>Wang</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Lin</surname></string-name>, <string-name><given-names>T.</given-names> <surname>Yao</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Xiong</surname></string-name> and <string-name><given-names>K.</given-names> <surname>Liang</surname></string-name></person-group>, &#x201C;<article-title>FABRICF: Fast and secure unbounded cross-system encrypted data sharing in cloud computing</article-title>,&#x201D; <source>IEEE Transactions on Dependable and Secure Computing</source>, pp. <fpage>1</fpage>&#x2013;<lpage>13</lpage>, <year>2023</year>. <pub-id pub-id-type="doi">10.1109/TDSC.2023.3240820</pub-id></mixed-citation></ref>
<ref id="ref-37"><label>[37]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>W.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>P.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>K.</given-names> <surname>Liang</surname></string-name></person-group>, &#x201C;<article-title>HPAKE: Honey password-authenticated key exchange for fast and safer online authentication</article-title>,&#x201D; <source>IEEE Transactions on Information Forensics and Security</source>, vol. <volume>18</volume>, pp. <fpage>1596</fpage>&#x2013;<lpage>1609</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-38"><label>[38]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>J.</given-names> <surname>Feng</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Xiong</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>Y.</given-names> <surname>Xiang</surname></string-name> and <string-name><given-names>K. H.</given-names> <surname>Yeh</surname></string-name></person-group>, &#x201C;<article-title>Scalable and revocable attribute-based data sharing with short revocation list for IIoT</article-title>,&#x201D; <source>IEEE Internet of Things Journal</source>, vol. <volume>10</volume>, no. <issue>6</issue>, pp. <fpage>4815</fpage>&#x2013;<lpage>4829</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-39"><label>[39]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>Q.</given-names> <surname>Mei</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Yang</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Chen</surname></string-name>, <string-name><given-names>L.</given-names> <surname>Wang</surname></string-name> and <string-name><given-names>H.</given-names> <surname>Xiong</surname></string-name></person-group>, &#x201C;<article-title>Expressive data sharing and self-controlled fine-grained data deletion in cloud-assisted IoT</article-title>,&#x201D; <source>IEEE Transactions on Dependable and Secure Computing</source>, vol. <volume>18</volume>, pp. <fpage>1</fpage>&#x2013;<lpage>16</lpage>, <year>2022</year>.</mixed-citation></ref>
<ref id="ref-40"><label>[40]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>X.</given-names> <surname>Huang</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Xiong</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Chen</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Yang</surname></string-name></person-group>, &#x201C;<article-title>Efficient revocable storage attribute-based encryption with arithmetic span programs in cloud-assisted internet of things</article-title>,&#x201D; <source>IEEE Transactions on Cloud Computing</source>, vol. <volume>11</volume>, no. <issue>2</issue>, pp. <fpage>1273</fpage>&#x2013;<lpage>1285</lpage>, <year>2023</year>.</mixed-citation></ref>
<ref id="ref-41"><label>[41]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Salem</surname></string-name>, <string-name><given-names>A.</given-names> <surname>Bhattacharya</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Backes</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Fritz</surname></string-name> and <string-name><given-names>Y.</given-names> <surname>Zhang</surname></string-name></person-group>, &#x201C;<article-title>Updates-Leak: Data set inference and reconstruction attacks in online learning</article-title>,&#x201D; in <conf-name>29th USENIX Security Symp. (USENIX Security 20)</conf-name>, <publisher-name>USENIX Association</publisher-name>, pp. <fpage>1291</fpage>&#x2013;<lpage>1308</lpage>, <year>2020</year>. <ext-link ext-link-type="uri" xlink:href="https://www.usenix.org/conference/usenixsecurity20/presentation/salem">https://www.usenix.org/conference/usenixsecurity20/presentation/salem</ext-link></mixed-citation></ref>
<ref id="ref-42"><label>[42]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>M. S.</given-names> <surname>Lacharit&#x00E9;</surname></string-name>, <string-name><given-names>B.</given-names> <surname>Minaud</surname></string-name> and <string-name><given-names>K. G.</given-names> <surname>Paterson</surname></string-name></person-group>, &#x201C;<article-title>Improved reconstruction attacks on encrypted data using range query leakage</article-title>,&#x201D; in <conf-name>2018 IEEE Symp. on Security and Privacy (SP)</conf-name>, <publisher-loc>Francisco, CA, USA</publisher-loc>, pp. <fpage>297</fpage>&#x2013;<lpage>314</lpage>, <year>2018</year>. </mixed-citation></ref>
<ref id="ref-43"><label>[43]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>C.</given-names> <surname>Dwork</surname></string-name>, <string-name><given-names>K.</given-names> <surname>Kenthapadi</surname></string-name>, <string-name><given-names>F.</given-names> <surname>McSherry</surname></string-name>, <string-name><given-names>I.</given-names> <surname>Mironov</surname></string-name> and <string-name><given-names>M.</given-names> <surname>Naor</surname></string-name></person-group>, &#x201C;<article-title>Our data, ourselves: Privacy via distributed noise generation</article-title>,&#x201D; in <conf-name>Annual Int. Conf. on the Theory and Applications of Cryptographic Techniques</conf-name>, <publisher-loc>Berlin, Heidelberg</publisher-loc>, <publisher-name>Springer</publisher-name>, vol. <volume>4004</volume>, pp. <fpage>486</fpage>&#x2013;<lpage>503</lpage>, <year>2006</year>. </mixed-citation></ref>
<ref id="ref-44"><label>[44]</label><mixed-citation publication-type="journal"><person-group person-group-type="author"><string-name><given-names>K.</given-names> <surname>Wei</surname></string-name>, <string-name><given-names>J.</given-names> <surname>Li</surname></string-name>, <string-name><given-names>M.</given-names> <surname>Ding</surname></string-name>, <string-name><given-names>C.</given-names> <surname>Ma</surname></string-name>, <string-name><given-names>H.</given-names> <surname>Su</surname></string-name> <etal>et al.</etal></person-group><italic>,</italic> &#x201C;<article-title>User-level privacy-preserving federated learning: Analysis and performance optimization</article-title>,&#x201D; <source>IEEE Transactions on Mobile Computing</source>, vol. <volume>21</volume>, no. <issue>9</issue>, pp. <fpage>3388</fpage>&#x2013;<lpage>3401</lpage>, <year>2021</year>.</mixed-citation></ref>
<ref id="ref-45"><label>[45]</label><mixed-citation publication-type="conf-proc"><person-group person-group-type="author"><string-name><given-names>A.</given-names> <surname>Beimel</surname></string-name>, <string-name><given-names>S. P.</given-names> <surname>Kasiviswanathan</surname></string-name> and <string-name><given-names>K.</given-names> <surname>Nissim</surname></string-name></person-group>, &#x201C;<article-title>Bounds on the sample complexity for private learning and private data release</article-title>,&#x201D; in <conf-name>Theory of Cryptography Conf.</conf-name>, <publisher-loc>Berlin, Heidelberg</publisher-loc>, <publisher-name>Springer</publisher-name>, pp. <fpage>437</fpage>&#x2013;<lpage>454</lpage>, <year>2010</year>. </mixed-citation></ref>
</ref-list>
</back></article>