<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.4 20241031//EN" "JATS-journalpublishing1-4.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article" dtd-version="1.4" xml:lang="en">
  <front>
    <journal-meta>
      <journal-id journal-id-type="publisher-id">jcc</journal-id>
      <journal-title-group>
        <journal-title>Journal of Computer and Communications</journal-title>
      </journal-title-group>
      <issn pub-type="epub">2327-5227</issn>
      <issn pub-type="ppub">2327-5219</issn>
      <publisher>
        <publisher-name>Scientific Research Publishing</publisher-name>
      </publisher>
    </journal-meta>
    <article-meta>
      <article-id pub-id-type="doi">10.4236/jcc.2026.148002</article-id>
      <article-id pub-id-type="publisher-id">jcc-153253</article-id>
      <article-categories>
        <subj-group>
          <subject>Article</subject>
        </subj-group>
        <subj-group>
          <subject>Computer Science</subject>
          <subject>Communications</subject>
        </subj-group>
      </article-categories>
      <title-group>
        <article-title>Privacy, Security, and Trust Challenges in Federated Learning: A Systematic Review and Future Research Agenda</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <name name-style="western">
            <surname>Nyapete</surname>
            <given-names>Mitende Nicholus</given-names>
          </name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <name name-style="western">
            <surname>Omolo</surname>
            <given-names>Richard</given-names>
          </name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <name name-style="western">
            <surname>Masinde</surname>
            <given-names>Newton</given-names>
          </name>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
      </contrib-group>
      <aff id="aff1"><label>1</label> Department of Computer Science and Software Engineering, Jaramogi Oginga Odinga University of Science and Technology, Bondo, Kenya </aff>
      <author-notes>
        <fn fn-type="conflict" id="fn-conflict">
          <p>The authors declare no conflicts of interest regarding the publication of this paper.</p>
        </fn>
      </author-notes>
      <pub-date pub-type="epub">
        <day>14</day>
        <month>08</month>
        <year>2026</year>
      </pub-date>
      <pub-date pub-type="collection">
        <month>08</month>
        <year>2026</year>
      </pub-date>
      <volume>14</volume>
      <issue>08</issue>
      <fpage>26</fpage>
      <lpage>48</lpage>
      <history>
        <date date-type="received">
          <day>08</day>
          <month>07</month>
          <year>2026</year>
        </date>
        <date date-type="accepted">
          <day>15</day>
          <month>08</month>
          <year>2026</year>
        </date>
        <date date-type="published">
          <day>18</day>
          <month>08</month>
          <year>2026</year>
        </date>
      </history>
      <permissions>
        <copyright-statement>© 2026 by the authors and Scientific Research Publishing Inc.</copyright-statement>
        <copyright-year>2026</copyright-year>
        <license license-type="open-access">
          <license-p> This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license ( <ext-link ext-link-type="uri" xlink:href="https://creativecommons.org/licenses/by/4.0/">https://creativecommons.org/licenses/by/4.0/</ext-link> ). </license-p>
        </license>
      </permissions>
      <self-uri content-type="doi" xlink:href="https://doi.org/10.4236/jcc.2026.148002">https://doi.org/10.4236/jcc.2026.148002</self-uri>
      <abstract>
        <p><bold>Background:</bold> Federated Learning has emerged as a distributed machine learning paradigm that enables entities to collaboratively train artificial intelligence models without directly sharing client raw data. Federated learning enhances privacy, security, and regulatory compliance while still enabling the development of a robust, accurate, aggregated global model. Despite successes of federated learning architecture in improving the integrity, confidentiality, and availability of data between communicating entities, the model faces privacy and security challenges that hinder its widespread adoption and effectiveness in real-world applications. The systematic review aims to explore federated learning architecture that have been applied to train AI models without direct sharing of client raw data, discuss how these models have been applied in training AI to provide privacy and accountability as well as long-term elimination planning, and address the methodological strengths, limitations, and challenges in implementing them, and policy and strategic implications. <bold>Methods</bold>: The study presents a systematic review of federated learning architectures to investigate privacy challenges in the federated learning architecture, with a focus on the strengths, weaknesses, and practical applications of different approaches. Following PRISMA 2020 guidelines, Literature screening was done on sixteen databases (Google Scholar, Semantic Scholar, PubMed, Springer Nature, Research Gate, ScienceDirect, IEEE, Scilit, ACM digital library, Wiley online library, SciSpace, National foundation (.gov), HAL open science database, open Ukrainian citation index, open review, Iniria, and nature.com) since their inception upto march 2026. Eligible articles were screened, and data extracted from the articles, architecture type analysed, and trust challenges. <bold>Results:</bold> Following systematic screening, 208 studies met the inclusion criteria. The most prevalent architectures were privacy-focused architectures. From the analysis results, the study found that limited fairness, scalability, and transparency are the major gaps in the existing literature that need to be addressed in future studies. <bold>Conclusion</bold>: The study concludes that future federated learning architectures should be tailored to address fairness, scalability, and transparency, which will be critical in achieving effective privacy in computer systems, thereby improving client confidence.</p>
      </abstract>
      <kwd-group kwd-group-type="author-generated" xml:lang="en">
        <kwd>Federated Learning</kwd>
        <kwd>Attacks</kwd>
        <kwd>Privacy</kwd>
        <kwd>Security</kwd>
        <kwd>Scalability</kwd>
        <kwd>Fairness</kwd>
        <kwd>Transparency</kwd>
        <kwd>Trust Challenges</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec1">
      <title>1. Introduction</title>
      <p>Federated Learning has emerged as a distributed machine learning paradigm that allows entities to collaboratively train artificial intelligence models without direct sharing of client raw data [<xref ref-type="bibr" rid="B1">1</xref>]. This is achieved by keeping data localized on user devices. Federated learning enhance privacy, security, and regulatory compliance while still allowing development of robust and accurate aggregated global model, this decentralization of has increasingly gain popularity in critical sectors: healthcare, finance, education, Internet of Things (IoT), edge computing, environment monitoring, emergency systems, transport infrastructure management, material science, and smart systems, where data integrity, confidentiality, and availability are of major concerns [<xref ref-type="bibr" rid="B2">2</xref>].</p>
      <p>Despite many successes of federated learning architecture in improving integrity, confidentiality, and availability of data between communicating entities, the model still experiences several privacy and security challenges that hinder its widespread use, adoption, and effectiveness in real-life applications. These privacy and security challenges have been found to include communication overhead due to frequent model updates, statistical heterogeneity arising from non-independent and identically distributed data, limited transparency and explainability of the learned model, fairness among clients, and vulnerability to attacks [<xref ref-type="bibr" rid="B3">3</xref>], additionally, scalability, trustworthiness, struggler effect, and coordination among distributed participants remains a significant drawback in the model. These trust challenges affect the performance and reliability of the model and data utility, therefore impacting the effectiveness of privacy-preserving learning. The trust challenges that have been observed in the standard federated learning architecture have led to the growing need for the development of a privacy-preserving federated learning architecture that ensures transparency and scalability. In this study, privacy was defined as protection of raw client data and model updates from unauthorized inference and or reconstruction, security was defined as resilience of the training and aggregation process against poisoning, backdoor, and inference attacks, and trust was defined as the distribution of accountability, auditability, and verifiability across participants, reducing reliance on any single party. The study analysed articles that have carried out the implementation of federated learning architecture for privacy preservation and security to identify the existing gaps, trust challenges and innovations that are needed to improve performance of the architecture and reduce bias, improve transparency, accountability, scalability, and fairness to meet key principles of privacy in federated learning environment.</p>
    </sec>
    <sec id="sec2">
      <title>2. Methods</title>
      <sec id="sec2dot1">
        <title>2.1. Study Design</title>
        <p>A comprehensive systematic search was conducted across sixteen peer-reviewed databases: Google Scholar, Semantic Scholar, PubMed, Springer Nature, research gate, ScienceDirect, IEEE, Scilit, ACM digital library, Wiley online library, SciSpace, National foundation (.gov), HAL open science database, open Ukrainian citation index, open review, Iniria, and nature.com from inception to March 2026. The review process adhered to the PRISMA 2020 guidelines [<xref ref-type="bibr" rid="B4">4</xref>] for systematic reviews and meta-analyses. The research questions that were used to guide this study review were: 1) What privacy-preservation, security, and trust mechanisms for federated learning architectures have been proposed, and threats being addressed? 2) What methodological strengths, limitations, implementation challenges, and policy implications have been reported for each mechanism category?</p>
      </sec>
      <sec id="sec2dot2">
        <title>2.2. Search Strategy</title>
        <p>Sixteen scientific databases were searched for suitable studies using search terms “federated learning, privacy in federated learning”, “security in federated learning” and “challenge”, search results was restricted to title, abstract, and affiliation fields while using the corresponding search terms. The results obtained from the search for the terms and corresponding keywords were merged using ‘OR’, and the combined results were further combined using a Boolean operator ‘AND’ as shown in <bold>Table 1</bold>. The results obtained from the search were imported into Zotero software for duplicate removal and screening.</p>
        <p><bold>Table 1.</bold>Search concept groups and terms.</p>
        <table-wrap id="tbl1">
          <label>Table 1</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>No.</bold>
                </td>
                <td>
                  <bold>Concept</bold>
                  <bold>Group</bold>
                </td>
                <td>
                  <bold>Search</bold>
                  <bold>Terms</bold>
                  <bold>(combined</bold>
                  <bold>using</bold>
                  <bold>OR)</bold>
                </td>
              </tr>
              <tr>
                <td>1</td>
                <td>Core technology</td>
                <td>
                  Federated learning
                  <bold>OR</bold>
                  FL
                </td>
              </tr>
              <tr>
                <td>2</td>
                <td>Privacy</td>
                <td>
                  Privacy
                  <bold>OR</bold>
                  Privacy-preserving
                  <bold>OR</bold>
                  Data confidentiality
                  <bold>OR</bold>
                  Differential privacy
                </td>
              </tr>
              <tr>
                <td>3</td>
                <td>Security</td>
                <td>
                  Security
                  <bold>OR</bold>
                  Adversarial attack
                  <bold>OR</bold>
                  Poisoning attack
                  <bold>OR</bold>
                  Backdoor attack
                  <bold>OR</bold>
                  Gradient leakage
                  <bold>OR</bold>
                  Model inversion
                </td>
              </tr>
              <tr>
                <td>4</td>
                <td>Trust</td>
                <td>
                  Trust
                  <bold>OR</bold>
                  Trustworthy
                  <bold>OR</bold>
                  Blockchain
                  <bold>OR</bold>
                  Decentralized trust
                  <bold>OR</bold>
                  Auditability
                </td>
              </tr>
              <tr>
                <td>5</td>
                <td>Fairness</td>
                <td>
                  Fairness
                  <bold>OR</bold>
                  Bias
                  <bold>OR</bold>
                  Equitable aggregation
                </td>
              </tr>
              <tr>
                <td>6</td>
                <td>Scalability</td>
                <td>
                  Scalability
                  <bold>OR</bold>
                  Cross-device
                  <bold>OR</bold>
                  Resource-constrained
                  <bold>OR</bold>
                  Communication overhead
                </td>
              </tr>
              <tr>
                <td>7</td>
                <td>Transparency</td>
                <td>
                  Transparency
                  <bold>OR</bold>
                  Explainability
                  <bold>OR</bold>
                  Accountability
                </td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p>And the complete Boolean search string that was applied is “Federated learning <bold>OR</bold> FL” AND “ Privacy <bold>OR</bold> Privacy-preserving <bold>OR</bold> Data confidentiality <bold>OR</bold> Differential privacy <bold>OR</bold> Security <bold>OR</bold> Adversarial attack <bold>OR</bold> Poisoning attack <bold>OR</bold> Backdoor attack <bold>OR</bold> Gradient leakage <bold>OR</bold> Model inversion <bold>OR</bold> Trust <bold>OR</bold> Trustworthy <bold>OR</bold> Blockchain <bold>OR</bold> Decentralized trust <bold>OR</bold> Auditability <bold>OR</bold> Fairness <bold>OR</bold> Bias <bold>OR</bold> Equitable aggregation <bold>OR</bold> Scalability <bold>OR</bold> Cross-device <bold>OR</bold> Resource-constrained <bold>OR</bold> Communication overhead Transparency <bold>OR</bold> Explainability <bold>OR</bold> Accountability”.</p>
        <p><bold>Table 2</bold> describes the inclusion and exclusion criteria that were used to filter out records that did not fit within the predetermined inclusion and exclusion criteria at this stage.</p>
        <p><bold>Table 2.</bold> Inclusion and exclusion criteria.</p>
        <table-wrap id="tbl2">
          <label>Table 2</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Inclusion</bold>
                  <bold>Criteria</bold>
                </td>
                <td>
                  <bold>Exclusion</bold>
                  <bold>Criteria</bold>
                </td>
              </tr>
              <tr>
                <td>Published after January 2015</td>
                <td>Published before January 2015</td>
              </tr>
              <tr>
                <td>Papers proposing or evaluating a mechanism addressing privacy, security, or trust in federated learning (including fairness, scalability, or transparency as a stated design goal)</td>
                <td>Papers not addressing privacy, security, or trust in federated learning</td>
              </tr>
              <tr>
                <td>Papers reporting an explicit threat model or adversarial setting (such as honest-but-curious server, malicious client, external eavesdropper)</td>
                <td>Papers with no stated threat model or adversarial assumption</td>
              </tr>
              <tr>
                <td>Papers published in English</td>
                <td>Studies published in languages other than English</td>
              </tr>
              <tr>
                <td>Scientific peer-reviewed publication (Journal or Conference paper)</td>
                <td>Systematic reviews, meta-analyses, editorials, and non-peer-reviewed preprints</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
      </sec>
      <sec id="sec2dot3">
        <title>2.3. Quality Evaluation</title>
        <p>The quality of methodology of studies included was assessed, and the evaluation concentrated on major points of model development and reporting, such as the clarity of the problem and modelling objective, outcomes, transparency in model construct and modelling parameter, connection with prior federated learning architecture studies, sensitivity analysis, and trust challenges associated with federated learning architecture. There was also an evaluation of additional issues, including parameter specification and model transparency. The methodological quality of each parameter included in the study was appraised using a structured five-item rubric derived from the evaluation criteria applied throughout this review (<bold>Table 3</bold>). Each item was scored as 0-absent, 1-partially addressed, and 2-fully addressed, yielding a score of 10 per study.</p>
        <p>Extracted data were cross-checked by a second reviewer for a random 20% sample of included studies to verify extraction accuracy; discrepancies were resolved by reference to the source text. The methodological quality of each included study was appraised using a structured five-item rubric derived from the evaluation criteria applied throughout this review (<bold>Table 4</bold>). Each item was scored 0 (absent), 1 (partially addressed), or 2 (fully addressed), yielding a total possible score of 10 per study.</p>
        <p><bold>Table 3.</bold> Data extraction fields.</p>
        <table-wrap id="tbl3">
          <label>Table 3</label>
          <table>
            <tbody>
              <tr>
                <td>No.</td>
                <td>Field</td>
                <td>Description</td>
              </tr>
              <tr>
                <td>1</td>
                <td>Citation/reference ID</td>
                <td>Author (s), year, and reference number as used in this review</td>
              </tr>
              <tr>
                <td>2</td>
                <td>Application domain</td>
                <td>Healthcare, finance, IoT, edge computing, general-purpose</td>
              </tr>
              <tr>
                <td>3</td>
                <td>Primary mechanism category</td>
                <td>Cryptographic/Differential privacy/Blockchain-based/ Attack-and-defines/Architectural-governance</td>
              </tr>
              <tr>
                <td>4</td>
                <td>Trust model assumed</td>
                <td>Honest-but-curious server, malicious adversary, or not specified.</td>
              </tr>
              <tr>
                <td>5</td>
                <td>Threat actor (s) considered</td>
                <td>Server, client, external eavesdropper, colluding server-client</td>
              </tr>
              <tr>
                <td>6</td>
                <td>Granularity of protection</td>
                <td>Sample-level, client-level, or update-level</td>
              </tr>
              <tr>
                <td>7</td>
                <td>Privacy/security mechanisms addressed,</td>
                <td>Model poisoning, gradient leakage, model inversion, and reconstruction attack</td>
              </tr>
              <tr>
                <td>8</td>
                <td>Evaluation metric (s) reported</td>
                <td>
                  Model accuracy, privacy budget (
                  <italic>є</italic>
                  ,
                  <italic>δ</italic>
                  ), communication cost, and latency
                </td>
              </tr>
              <tr>
                <td>9</td>
                <td>Dataset (s) used</td>
                <td>Benchmark dataset, real-world dataset, or simulated/synthetic data</td>
              </tr>
              <tr>
                <td>10</td>
                <td>Reported strengths</td>
                <td>As stated by the original authors</td>
              </tr>
              <tr>
                <td>11</td>
                <td>Reported limitations</td>
                <td>As stated by the original authors</td>
              </tr>
              <tr>
                <td>12</td>
                <td>Quality appraisal score</td>
                <td>
                  Score assigned using the rubric in
                  <bold>Table 4</bold>
                </td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
        <p><bold>Table 4.</bold> Quality appraisal rubric.</p>
        <table-wrap id="tbl4">
          <label>Table 4</label>
          <table>
            <tbody>
              <tr>
                <td>
                  <bold>Criterion</bold>
                </td>
                <td>
                  <bold>0</bold>
                  <bold>-</bold>
                  <bold>Absent</bold>
                </td>
                <td>
                  <bold>1</bold>
                  <bold>-</bold>
                  <bold>Partial</bold>
                </td>
                <td>
                  <bold>2-Fully</bold>
                  <bold>Addressed</bold>
                </td>
              </tr>
              <tr>
                <td>Problem and modelling objective clarity</td>
                <td>Not stated</td>
                <td>Implied but not explicit</td>
                <td>Explicitly stated</td>
              </tr>
              <tr>
                <td>Outcome/results reporting</td>
                <td>Not reported</td>
                <td>Partially quantified</td>
                <td>Fully quantified with defined metrics</td>
              </tr>
              <tr>
                <td>Model and parameter transparency</td>
                <td>Not disclosed</td>
                <td>Partially disclosed (architecture only)</td>
                <td>Fully disclosed (privacy budget, architecture, dataset all reported)</td>
              </tr>
              <tr>
                <td>Threat model specification</td>
                <td>Not stated</td>
                <td>Vague (“adversary” undefined)</td>
                <td>Explicit (adversary type and actor named)</td>
              </tr>
              <tr>
                <td>Comparison with prior federated learning work</td>
                <td>Absent</td>
                <td>Cited without direct comparison</td>
                <td>Explicit comparative discussion of strengths/limitations relative to prior work</td>
              </tr>
            </tbody>
          </table>
        </table-wrap>
      </sec>
      <sec id="sec2dot4">
        <title>2.4. Model Grouping and Evaluation Framework</title>
        <p>In order to provide a systematic synthesis of federated learning architecture, we classified the studies that were included based on the main aim of the research. All of the eligible modelling studies were found in the process of full-text screening. Within each model, we identified and compared the essential characteristics of all the included models.</p>
      </sec>
    </sec>
    <sec id="sec3">
      <title>3. Results</title>
      <sec id="sec3dot1">
        <title>3.1. Study Selection</title>
        <p>A total of 395 articles were identified from the search. 30 duplicates were removed, which led to 365 articles being screened by title and abstract, with 145 articles selected for full-text evaluation. For final analysis, 73 articles [<xref ref-type="bibr" rid="B1">1</xref>]-[<xref ref-type="bibr" rid="B3">3</xref>], [<xref ref-type="bibr" rid="B5">5</xref>]-[<xref ref-type="bibr" rid="B74">74</xref>] were included in the final analysis (<xref ref-type="fig" rid="fig1">Figure 1</xref>). The number of full-text articles that were rejected after careful screening was 64. This comprised of studies that were not analysing privacy preservation (n = 20), reviews (n = 29), and those that did not include attacks (n = 15).</p>
        <fig id="fig1">
          <label>Figure 1</label>
          <graphic xlink:href="https://html.scirp.org/file/1733610-rId13.jpeg?20260818042205" />
        </fig>
        <p><bold>Figure 1.</bold> Summary of systematic screening of identified articles.</p>
      </sec>
      <sec id="sec3dot2">
        <title>3.2. Classification of Privacy-Preserving Models in Federated Learning Architecture</title>
        <p>3.2.1. Model Grouping and Evaluation Framework</p>
        <p>To provide a systematic synthesis of the mechanisms that address privacy-preserving, security, and trust in federated learning architectures, the studies reviewed were classified according to the primary mechanism used to protect data confidentiality, resist adversarial manipulation, or distributed accountability across the federated learning lifecycle (local training, communication, and aggregation). All eligible studies identified were grouped into five broad categories based on the dominant privacy-preservation strategy employed.</p>
        <p>1) Cryptographic privacy-preserving models which rely on secure multiparty computation, homomorphic encryption, or Zero-Knowledge Proofs (ZKPs) to mathematically guarantee that raw data or gradients are never exposed in plaintext to the aggregator or other participants.</p>
        <p>2) Perturbation-based architectures (Differential Privacy, DP) which inject calibrated statistical noise into gradients, model updates, or aggregated outputs to bound the privacy loss of any individual participant’s data.</p>
        <p>3) Blockchain-based decentralized trust models which remove or minimize reliance on a central aggregator by distributing trust, auditability, and incentive management across a distributed ledger.</p>
        <p>4) Attack-and-defence models which characterize the Privacy and security threat surface of federated learning (inference attacks, model inversion, poisoning, backdoors) and propose corresponding robust-aggregation or detection mechanisms.</p>
        <p>5) Architectural and governance frameworks which address privacy holistically at the level of system design reference architectures, fairness and accountability layers, and healthcare/IoT-specific deployment patterns rather than through a single cryptographic or statistical mechanism.</p>
        <p>Within each category, the essential characteristics of the included models were compared using the following evaluation criteria.</p>
        <p>1) Model structure and assumptions covering trust model assumed (honest-but-curious vs malicious adversary), the threat actors considered (server, client, external eavesdropper), and the granularity of protection (sample-level, client-level, or update-level privacy).</p>
        <p>2) Privacy mechanism address: model poisoning, gradient leakages, and inversion, and reconstruction attacks.</p>
        <p>3) Strengths and limitations examined in terms of computational and communication overhead, scalability to cross-device settings, utility-privacy trade-off, and resistance to adaptive adversaries.</p>
        <p>4) Comparative advantages—identifying what differentiates each model from others within or across categories.</p>
        <p>5) Contextual use cases suggesting the settings in which each model type is most applicable, such as cross-silo healthcare consortia, cross-device mobile networks, or IoT edge environments.</p>
        <p>3.2.2. Cryptographic Privacy-Preserving Models</p>
        <p>Cryptographic approaches form substantial portion of the analysed literature, which reflect the emphasis on provable, rather than merely empirical privacy guarantees. Secure multiparty computation allows multiple clients to jointly compute an aggregate model update without any single party learning the others’ raw contributions. Work in this vein has been applied specifically to sensitive domains, including financial applications, where SMC has been combined with differential privacy to satisfy regulatory confidentiality requirements [<xref ref-type="bibr" rid="B5">5</xref>], and histopathology imaging, where cluster-based SMC has been used to protect diagnostic data shared across hospitals [<xref ref-type="bibr" rid="B6">6</xref>]. Extensive investigations have indicated that federated learning architecture is fundamentally multiparty computation problem, arguing that many aggregation protocols can be understood as specialized instances of general SMC theory [<xref ref-type="bibr" rid="B7">7</xref>]; other work has systematically catalogued the safeguards needed to secure the federated learning framework as a whole [<xref ref-type="bibr" rid="B8">8</xref>].</p>
        <p>Homomorphic Encryption (HE) extends this guarantee by allowing the aggregator to perform arithmetic operations (summation of gradients) directly on encrypted ciphertexts, so that the server never has access to any client’s update in plaintext. Systems such as FedML-HE have demonstrated that HE-based aggregation can be efficient enough for practical deployment [<xref ref-type="bibr" rid="B9">9</xref>]. At the same time, other studies have proposed multiparty homomorphic encryption schemes tailored for secure aggregation in federated learning [<xref ref-type="bibr" rid="B10">10</xref>] and have surveyed HE is broader contributions to privacy-preserving healthcare analytics [<xref ref-type="bibr" rid="B11">11</xref>]. HE has also been extended beyond conventional deep networks to spiking neural network architectures, indicating the mechanism’s generalizability across model families [<xref ref-type="bibr" rid="B12">12</xref>]. A parallel line of work has applied simpler symmetric or asymmetric encryption models directly to federated learning update transmission to secure communication channels against eavesdropping [<xref ref-type="bibr" rid="B13">13</xref>].</p>
        <p>Zero-Knowledge proofs constitute the third cryptographic pillar, which enable clients or server to prove that computation was performed honestly without revealing data or model parameters. zk-SNARK-based frameworks have been proposed to make blockchain-based FL verifiable end-to-end, ensuring that both training and aggregation steps can be audited without compromising confidentiality [<xref ref-type="bibr" rid="B14">14</xref>]-[<xref ref-type="bibr" rid="B16">16</xref>]. Related work has combined ZKPs with decentralized federated learning to eliminate the need for a trusted central verifier [<xref ref-type="bibr" rid="B17">17</xref>][<xref ref-type="bibr" rid="B18">18</xref>], and quantum-resistant ZKP constructions have been explored for user authentication in adjacent distributed-systems contexts [<xref ref-type="bibr" rid="B19">19</xref>].</p>
        <p><bold>Comparative</bold><bold>Advantage</bold></p>
        <p>Cryptographic models offer strong privacy guarantees since they do not rely on statistical assumptions about the adversary behaviour, their limitation is computational and communication overhead, which restricts their application in a resource-constrained, cross-device settings such as mobile phones or IoT sensors, and confines most reported deployments to cross-setting scenarios with a small number of well-resourced institutional participants.</p>
        <p>3.2.3. Differential Privacy</p>
        <p>Differential Privacy has become the most widely adopted statistical framework for bounding privacy loss in federated learning, owing to its composability and its formal (<italic>є</italic>, <italic>δ</italic>)-guarantee that is independent of the adversary’s auxiliary knowledge. Foundational work establishes an algorithmic and performance trade-offs of applying differential privacy directly to the federated learning training loop, showing that carefully calibrated noise addition can preserve acceptable model utility while providing rigorous privacy bounds [<xref ref-type="bibr" rid="B20">20</xref>]. Subsequent studies have extended these foundations to secure, stateful aggregation protocols that combine differential privacy with cryptographic secure aggregation to reduce the amount of noise required for a given privacy budget [<xref ref-type="bibr" rid="B5">5</xref>], and have surveyed the wide variance in how differential privacy has been operationalized across the federated learning literature, noting substantial inconsistency in reported privacy budgets and threat models [<xref ref-type="bibr" rid="B21">21</xref>].</p>
        <p>Several studies have examined differential privacy behaviour under real-world deployment constraints. Mobility and client churn have been shown to affect the achievable Privacy-utility trade-off in differentially private federated learning, since intermittent client participation complicates privacy accounting across multiple communication rounds [<xref ref-type="bibr" rid="B22">22</xref>]. Hybrid approaches that integrate differential privacy and lightweight cryptographic techniques have been suggested to be implemented in cross-IoT platforms in order to balance confidentiality and limited computational budget of edge devices [<xref ref-type="bibr" rid="B23">23</xref>]. Studies have also explored joint application of differential privacy and secure aggregation “belt and braces” strategy to defend simultaneously against curious servers and colluding clients [<xref ref-type="bibr" rid="B24">24</xref>]. Differential privacy has also been applied beyond the core federated learning literature to public health data sharing more broadly, illustrating its transferability as a privacy accounting framework for epidemiological and health-system data releases [<xref ref-type="bibr" rid="B25">25</xref>], and to location-based services, where geographic granularity introduces additional re-identification risk beyond that of conventional tabular data [<xref ref-type="bibr" rid="B26">26</xref>].</p>
        <p><bold>Comparative</bold><bold>Advantage</bold></p>
        <p>Differential privacy mechanisms are largely lightweight and can be placed on top of standard FedAvg aggregation pipeline with little architectural change, making them attractive for cross-device federated learning at scale. Their central limitation is the well-documented privacy-utility trade-off: strong privacy guarantees (small <italic>є</italic>) tend to degrade model accuracy, particularly for non-IID client data distributions, and most of the reviewed studies do not specify how privacy budgets should be tuned for realistic multi-round training regimes.</p>
        <p>3.2.4. Blockchain-Based Decentralized Trust Architecture</p>
        <p>A large and rapidly growing subset of the literature addresses privacy not through a cryptographic primitive alone, but by redesigning the federated learning architecture to remove the single point of trust represented by a central aggregation server. Blockchain-based federated learning frameworks distribute the aggregation, auditing, and incentive functions across a distributed ledger to prevent unilateral inspection by a party, tampering or withhold client contributions. Systematic surveys have mapped this particular design for IoT deployments, and privacy guarantees across architectures [<xref ref-type="bibr" rid="B27">27</xref>]. Comparative studies of blockchain against centralized authentication architectures also suggest that blockchain-based designs are advantageous where IoT devices cannot rely on a persistently available, trusted third party [<xref ref-type="bibr" rid="B28">28</xref>].</p>
        <p>Specific architectural contributions including committee consensus frameworks reduce computational burden of a full-network validation as it preserve decentralized trust [<xref ref-type="bibr" rid="B29">29</xref>]; trustworthy federated learning architectures that combine blockchain with reputation-based client selection to mitigate free-riding and malicious participation [<xref ref-type="bibr" rid="B30">30</xref>]; and audit-oriented designs that use blockchain to provide transparent, tamper-evident logging of encrypted training data provenance without revealing the data itself [<xref ref-type="bibr" rid="B31">31</xref>][<xref ref-type="bibr" rid="B32">32</xref>]. Game-theoretic incentive mechanisms layered on top of blockchain have also been proposed to align individual client incentives with honest participation, addressing a privacy-adjacent concern: clients who anticipate no reputational or financial benefit have reduced incentive to protect the integrity of their contributions [<xref ref-type="bibr" rid="B33">33</xref>].</p>
        <p>Blockchain has additionally been combined with the cryptographic and perturbation mechanisms discussed above to create hybrid, defence-in-depth systems: examples include zk-SNARK-verified blockchain FL [<xref ref-type="bibr" rid="B14">14</xref>]-[<xref ref-type="bibr" rid="B18">18</xref>], blockchain-secured federated learning explicitly designed to resist poisoning attacks (BPFL) [<xref ref-type="bibr" rid="B34">34</xref>], and frameworks integrating adaptive differential privacy with blockchain and dynamic masking specifically for Internet-of-Vehicles applications, which also incorporate explainable AI (XAI) components to support auditability [<xref ref-type="bibr" rid="B35">35</xref>]. Domain-specific deployments include a blockchain-entangled FL architecture for healthcare 5.0 systems [<xref ref-type="bibr" rid="B36">36</xref>] and blockchain-secured LSTM autoencoder models for transaction-level anomaly detection [<xref ref-type="bibr" rid="B37">37</xref>].</p>
        <p><bold>Comparative</bold><bold>Advantage</bold></p>
        <p>Blockchain-based models are distinctive in addressing trust distribution rather than data confidentiality; therefore, they are valuable where the central-server threat model is of primary concern and where auditability are regulatory requirements. Their limitation include: 1) consensus latency, and 2) storage overhead of the ledger.</p>
        <p>3.2.5. Attack-and-Defence Models</p>
        <p>A substantial body of work approaches federated learning privacy not by proposing a protective mechanism directly, but by characterizing the attack surface that motivates such mechanisms, and by proposing corresponding defences. On the attack side, studies have demonstrated that federated learning very design, which requires clients to share gradients or model updates, creates channels for gradient leakage and model inversion attacks that can reconstruct substantial information about a client’s private training data [<xref ref-type="bibr" rid="B38">38</xref>][<xref ref-type="bibr" rid="B39">39</xref>]. Backdoor attacks, in which a malicious client trains a submodel to embed a hidden trigger while evading server-side anomaly detection, have been shown to succeed even under standard FedAvg aggregation [<xref ref-type="bibr" rid="B40">40</xref>], and refined evasion variants of such attacks continue to be documented [<xref ref-type="bibr" rid="B41">41</xref>]. Data poisoning attacks that corrupt the training process by injecting mislabelled or adversarial perturbed samples have similarly been catalogued and benchmarked [<xref ref-type="bibr" rid="B42">42</xref>]. Attacks that specifically defeat secure aggregation protocols by exploiting model inconsistency between rounds illustrate that cryptographic protection of the aggregation channel does not, by itself, guarantee input privacy if the aggregation protocol’s assumptions are violated [<xref ref-type="bibr" rid="B43">43</xref>][<xref ref-type="bibr" rid="B44">44</xref>].</p>
        <p>Robust-aggregation method has been proposed to detect and down weight anomalous and Byzantine client updates, thereby limiting the impact of poisoning and backdoor attacks without requiring a fully cryptographic pipeline [<xref ref-type="bibr" rid="B45">45</xref>][<xref ref-type="bibr" rid="B46">46</xref>]. Provable defence frameworks such as FLIP explicitly target backdoor mitigation with formal guarantees rather than purely heuristic anomaly detection [<xref ref-type="bibr" rid="B47">47</xref>]. Comprehensive surveys have organized this attack–defence literature into structured taxonomies covering the full federated learning pipeline from data collection, through local training, to aggregation, and have highlighted persistent gaps between attacks demonstrated in controlled experimental settings and the assumptions realistic federated learning deployments can satisfy [<xref ref-type="bibr" rid="B48">48</xref>]-[<xref ref-type="bibr" rid="B53">53</xref>]. A recurring critique in this sub-literature is that many published attacks and defences rely on idealized assumptions (full visibility into the global model, a fixed, known number of malicious clients) that may not transfer to production-scale, cross-device FL systems [<xref ref-type="bibr" rid="B51">51</xref>].</p>
        <p>Related, though conceptually adjacent, is a smaller set of studies that address fairness and bias as privacy-relevant concerns, since biased aggregation can itself leak information about which client populations are under- or over-represented in the global model. Fairness-aware aggregation methods based on core-stability concepts [<xref ref-type="bibr" rid="B54">54</xref>] and multi-gradient descent with fairness guidance (FedMDFG) [<xref ref-type="bibr" rid="B55">55</xref>] have been proposed alongside broader surveys of bias and fairness in machine learning that contextualize these FL-specific contributions within the wider algorithmic fairness literature [<xref ref-type="bibr" rid="B56">56</xref>]-[<xref ref-type="bibr" rid="B58">58</xref>]. Techniques for mitigating bias directly during federated aggregation have also been proposed as a complementary safeguard alongside privacy-preserving mechanisms [<xref ref-type="bibr" rid="B59">59</xref>].</p>
        <p><bold>Comparative</bold><bold>Advantage</bold></p>
        <p>This category is unique in that its primary contribution is diagnostic rather than protective. It defines the threat models that the other four categories of models are designed to counter. Its main limitation, noted consistently across the surveyed literature, is a persistent gap between attack sophistication (which continues to escalate, such as refined backdoor evasion [<xref ref-type="bibr" rid="B41">41</xref>]) and the generalizability of defence.</p>
      </sec>
      <sec id="sec3dot3">
        <title>3.3. Architectural and Governance Frameworks</title>
        <p>Final category included studies that address federated learning privacy holistically at the system architecture level, rather than through a discrete cryptographic, statistical, or ledger-based mechanism. Reference architecture articles have suggested structured taxonomies of architectural patterns for federated learning systems, incorporating privacy, security, and communication efficiency as design dimensions not as after-the-fact additions [<xref ref-type="bibr" rid="B60">60</xref>][<xref ref-type="bibr" rid="B61">61</xref>]. Decentralized federated learning research have documented a shift from single-server aggregation to peer-to-peer and gossip-based topologies, arguing that decentralization itself constitutes a privacy-enhancing design choice by removing the aggregator as a single point of data exposure [<xref ref-type="bibr" rid="B1">1</xref>][<xref ref-type="bibr" rid="B62">62</xref>][<xref ref-type="bibr" rid="B63">63</xref>]. Scalable, fault-tolerant, and decentralized architectures have been proposed to provide and maintain privacy guarantees under node churn and partial network failures [<xref ref-type="bibr" rid="B64">64</xref>], and general-purpose federated learning platforms such as FED have been engineered to make privacy-preserving deployment configurations more accessible to non-specialist adopters [<xref ref-type="bibr" rid="B65">65</xref>].</p>
        <p>Domain-specific governance frameworks are especially prominent in healthcare, reflecting the sector’s stringent regulatory requirements. Studies have scoped the intersection of federated learning, privacy-enhancing technologies, and data protection law in medical research [<xref ref-type="bibr" rid="B66">66</xref>], examined FL’s suitability for handling privacy-sensitive medical data more broadly [<xref ref-type="bibr" rid="B67">67</xref>], and reviewed clinical applications and technical architectures for healthcare federated learning specifically [<xref ref-type="bibr" rid="B68">68</xref>]. Neuroimaging-specific architectures have been developed to secure multi-site brain-imaging consortia [<xref ref-type="bibr" rid="B69">69</xref>], and privacy-preserving FL has been applied to accelerate AI adoption in internet-of-medical-things (IoMT) environments [<xref ref-type="bibr" rid="B70">70</xref>]. Reviews of privacy preservation for federated learning in healthcare argue that architectural and regulatory alignment over single technical mechanism is binding constraint adoption [<xref ref-type="bibr" rid="B71">71</xref>]. Some studies have addressed specific challenge of anonymizing healthcare data prior to its use in federated learning pipelines, treating anonymization as architectural pre-processing layer rather than a training-time mechanism [<xref ref-type="bibr" rid="B72">72</xref>][<xref ref-type="bibr" rid="B73">73</xref>].</p>
        <p><bold>Comparative</bold><bold>Advantage</bold></p>
        <p>The architectural and governance frameworks are the only category that clearly address organizational and regulatory constraints alongside technical privacy mechanisms. Their limitation is frequent descriptive/taxonomic rather than prescriptive, offering design guidance over deployable protocols, and their practical impact depends heavily on faithful the implementers are in translating architectural recommendations into working systems.</p>
      </sec>
      <sec id="sec3dot4">
        <title>3.4. Strengths of Existing Architectures</title>
        <p>Across all five set of categories, the analysis results demonstrated a rich, complementary toolkit for addressing privacy in federated learning at various points in the training pipeline. Cryptographic models offer the strongest formal guarantees against both honest but curious and malicious adversaries; Differential privacy models offer lightweight, composable privacy accounting well suited to large scale cross device deployment; blockchain based models address the structural risk posed by a single trusted aggregator; attack and defence studies provide the empirical grounding needed to prioritize which threats matter most in practice; and architectural frameworks connect these technical mechanisms to the regulatory and organizational realities of deployment domains such as healthcare and IoT. Several studies further demonstrate that these mechanisms are not mutually exclusive: Differential privacy has been combined with secure aggregation [<xref ref-type="bibr" rid="B5">5</xref>][<xref ref-type="bibr" rid="B24">24</xref>], and blockchain has been combined with ZKPs [<xref ref-type="bibr" rid="B14">14</xref>]-[<xref ref-type="bibr" rid="B17">17</xref>] and with adaptive differential privacy and masking [<xref ref-type="bibr" rid="B35">35</xref>], suggesting that defence-in-depth approaches are both feasible and increasingly common.</p>
      </sec>
      <sec id="sec3dot5">
        <title>3.5. Limitations of Current Architectures</title>
        <p>Despite these strengths, several limitations recur throughout the literature. Strong differential privacy guarantee reduces model accuracy, and small number of studies have provided practical guidance on selecting privacy budgets for realistic, non-IID, multi-round federated learning settings [<xref ref-type="bibr" rid="B20">20</xref>]. While cryptographic models offer strong guarantees, they impose computational and communication overheads which prohibits smooth cross-device and resource-constrained deployments, effectively restricting their practical use to well-resourced cross-silo consortia [<xref ref-type="bibr" rid="B9">9</xref>][<xref ref-type="bibr" rid="B10">10</xref>]. Blockchain-based federated learning models provide consensus latency and ledger storage overhead, and, as noted above, typically require a complementary content-protection mechanism, since they secure the aggregation process rather than the substance of client updates. Attack and defence studies are frequently validated against narrow, idealized threat models and single attacks, limiting confidence that reported defences generalize to adaptive real-world adversaries [<xref ref-type="bibr" rid="B51">51</xref>]. Despite the architectural and governance frameworks providing valuable connections to technical and regulatory considerations, they are often descriptive rather than prescriptive, providing implementers with no concrete benchmarked configurations.</p>
      </sec>
      <sec id="sec3dot6">
        <title>3.6. Application and Use Case</title>
        <p>The literature demonstrated several converging applications of privacy-preserving federated learning architecture. Cryptographic and differential privacy mechanisms in healthcare have been combined with governance frameworks to support multi-institutional model training without centralizing patient data [<xref ref-type="bibr" rid="B66">66</xref>]-[<xref ref-type="bibr" rid="B69">69</xref>][<xref ref-type="bibr" rid="B71">71</xref>]. Lightweight hybrid differential privacy-cryptographic schemes and blockchain-secured architectures in IoT and edge environments have been proposed to accommodate constrained device resources while still providing auditable privacy guarantees [<xref ref-type="bibr" rid="B23">23</xref>][<xref ref-type="bibr" rid="B27">27</xref>][<xref ref-type="bibr" rid="B35">35</xref>]. Secure multiparty computation and differential privacy have been jointly deployed in finance to satisfy regulatory confidentiality requirements while enabling cross-institutional fraud detection and risk modelling [<xref ref-type="bibr" rid="B5">5</xref>][<xref ref-type="bibr" rid="B74">74</xref>]. Across all domains, attack-and-defence studies play a cross-cutting diagnostic role, informing which other mechanisms are prioritized for a given deployment’s threat model.</p>
      </sec>
      <sec id="sec3dot7">
        <title>3.7. Cross-Cutting Themes and Practical Implications</title>
        <p>Several themes recur across the five architecture categories: “no single mechanism has achieved strong formal privacy guarantees and low computational overhead at the same time” the literature consistently frames privacy-preserving federated learning design as a trade-off space rather than a solved problem, with cryptographic models trading efficiency for guarantee strength, and differential privacy models trading accuracy for guarantee strength. “Trust-model assumptions are frequently under-specified” many studies do not clearly distinguish between honest but curious and actively malicious adversary models, which complicates comparison across proposed mechanisms and across the surveyed categories. “Collusion between the server and a subset of clients remains inadequately addressed” in a large share of the reviewed cryptographic and differential privacy literature, even though this threat model is increasingly recognized as realistic in cross-silo deployments with commercial competitors as co-participants. Auditability and non-repudiation, ability to verify, after the fact, that a training round was conducted correctly and privately, emerge as a distinct requirement that neither differential privacy nor conventional cryptographic aggregation fully satisfies on its own, motivating the growing integration of blockchain and ZKP-based verification alongside these mechanisms [<xref ref-type="bibr" rid="B14">14</xref>]-[<xref ref-type="bibr" rid="B18">18</xref>]. Fifth, “regulatory alignment”, particularly in healthcare and financial domains, is treated as a binding constraint on adoption, independent of technical maturity, reinforcing the role of architectural and governance frameworks as a necessary complement to the four more technically defined categories [<xref ref-type="bibr" rid="B66">66</xref>][<xref ref-type="bibr" rid="B71">71</xref>].</p>
        <p>A further cross-cutting weakness, echoed across the attack-and-defence literature, is that privacy evaluation in federated learning research is rarely adversarial in the way real deployments require, most reported defences are validated against the specific attack used to motivate the paper, rather than against an adaptive adversary aware of the defence mechanism itself [<xref ref-type="bibr" rid="B51">51</xref>]. This mirrors a broader methodological gap in which formal privacy guarantees (<italic>є</italic>-DP bounds, cryptographic security proofs) are not always matched by empirical red-team evaluation of the deployed system as a whole.</p>
      </sec>
      <sec id="sec3dot8">
        <title>3.8. Comparative Advantages of Different Architecture Approaches</title>
        <p>The five categories of privacy-preserving federated learning architecture reviewed here serve complementary rather than competing roles in securing the federated learning pipeline. Cryptographic architectures (SMC, HE, ZKPs) form the strongest layer of protection against a curious or malicious aggregator, and are appropriate where regulatory or contractual requirements demand provable, rather than probabilistic, privacy guarantees such as in cross-institutional healthcare or financial consortia with a small number of high-value participants [<xref ref-type="bibr" rid="B5">5</xref>][<xref ref-type="bibr" rid="B9">9</xref>]-[<xref ref-type="bibr" rid="B11">11</xref>]. Differential privacy models offer a lightweight composable mechanism that is well suited to a large-scale cross-device federated learning, where cryptographic overhead is prohibitive. However, their guarantees come at the cost of model utility, and their practical calibration remains an open challenge [<xref ref-type="bibr" rid="B20">20</xref>][<xref ref-type="bibr" rid="B21">21</xref>]. Blockchain-based models help in addressing structurally different concern: eliminating a single trusted aggregator. They are most valuable where auditability, non-repudiation, or incentive alignment across mutually distrusting organizations is the primary requirement, rather than the confidentiality of any individual update in isolation [<xref ref-type="bibr" rid="B27">27</xref>][<xref ref-type="bibr" rid="B30">30</xref>]. Attack-and-defence models do not, in themselves, constitute a deployable privacy mechanism. However, they determine which of the other three technical categories should be prioritized for a given threat model, and their findings increasingly motivate hybrid, defence-in-depth architectures that combine, for instance, DP with secure aggregation, or blockchain with ZKPs [<xref ref-type="bibr" rid="B5">5</xref>][<xref ref-type="bibr" rid="B24">24</xref>][<xref ref-type="bibr" rid="B35">35</xref>]. Architectural and governance frameworks provide organizational framework translating technical guarantees into regulatory compliant, auditable systems, particularly in healthcare domain where legal and technical requirements are tightly coupled [<xref ref-type="bibr" rid="B66">66</xref>][<xref ref-type="bibr" rid="B68">68</xref>][<xref ref-type="bibr" rid="B71">71</xref>].</p>
        <p>Theretofore the is no single modelling category implemented individually can address full range of federated privacy risks. An integrative combination of cryptographic or differential privacy protection of update content, blockchain-based distribution of aggregation trust, attack-informed robust-aggregation defences, and governance frameworks aligned with domain-specific regulation offers a more complete and context-specific platform for privacy-preserving federated learning deployment than any individual mechanism reviewed in isolation.</p>
      </sec>
      <sec id="sec3dot9">
        <title>3.9. Contextual Application of the Architectures</title>
        <p>The applicability of each of the privacy-preserving architecture category depends on deployment context, sensitivity and regulatory status of data involved, resource constraints of participating clients, and trust relationship between participants and the aggregator.</p>
        <p>Cryptographic models are informative in cross-platform settings with a small number of well-resourced institutional participants for instance hospitals, banks, and research consortia, where computational overhead of SMC, HE, or ZKPs is affordable and where formal, auditable privacy guarantees are a contractual or regulatory necessity [<xref ref-type="bibr" rid="B5">5</xref>][<xref ref-type="bibr" rid="B9">9</xref>][<xref ref-type="bibr" rid="B10">10</xref>].</p>
        <p>Differential privacy models are suited to cross-device with large numbers of resource-constrained clients which include mobile phones and IoT devices, where lightweight noise injection can be layered on top of standard FedAvg-style aggregation without prohibitive overhead. However, careful privacy-budget tuning is required to preserve model utility under non-IID data [<xref ref-type="bibr" rid="B20">20</xref>][<xref ref-type="bibr" rid="B22">22</xref>][<xref ref-type="bibr" rid="B23">23</xref>].</p>
        <p>Blockchain-based models are most applicable where no single participant is willing to act as, or be trusted as, a central aggregator, for example, in multi-organizational IoT consortia or competitive commercial settings, and where auditability of the training process is itself a requirement, independent of the confidentiality of any single update [<xref ref-type="bibr" rid="B27">27</xref>][<xref ref-type="bibr" rid="B30">30</xref>][<xref ref-type="bibr" rid="B36">36</xref>].</p>
        <p>Attack-and-defence models are most valuable during the threat-modelling and risk-assessment phase of federated learning system design, informing which combination of the other three technical categories should be deployed for a given adversarial context, and are particularly critical in high-stakes domains where poisoning or backdoor attacks could have safety-critical consequences [<xref ref-type="bibr" rid="B40">40</xref>][<xref ref-type="bibr" rid="B42">42</xref>][<xref ref-type="bibr" rid="B45">45</xref>][<xref ref-type="bibr" rid="B47">47</xref>].</p>
        <p>Architectural and governance frameworks are most applicable in regulated domains, principally healthcare and finance, where technical privacy mechanisms must be embedded within a broader compliance and consent-management structure, and where the interoperability of multiple institutions’ data governance policies is itself a design constraint [<xref ref-type="bibr" rid="B66">66</xref>][<xref ref-type="bibr" rid="B68">68</xref>][<xref ref-type="bibr" rid="B71">71</xref>].</p>
      </sec>
    </sec>
    <sec id="sec4">
      <title>4. Discussion</title>
      <p>The classification aggregates the privacy, security, and trust mechanisms that has been used in federated learning architectures into five categories: 1) cryptographic models, 2) differential privacy models, 3) blockchain-based decentralized trust models, 4) attack-and-defence models, and 5) architectural and governance frameworks, each addressing distinct layer of the privacy, security, and trust challenge inherent to distributed model training. This grouping mirrors the broader observation in the federated learning literature that no single technique fully resolves the tension between data utility, communication and computation cost, and formal privacy guarantees; rather, the reviewed studies suggest that privacy in federated learning is best understood as a layered, defence-in-depth problem rather than one solvable through a single mechanism.</p>
      <p>Cryptographic approaches that are provable guarantee are required and computational resources permit in healthcare and financial applications [<xref ref-type="bibr" rid="B5">5</xref>][<xref ref-type="bibr" rid="B9">9</xref>]-[<xref ref-type="bibr" rid="B11">11</xref>]. Differential privacy dominates when scalability to large client populations is paramount, at the cost of a well-documented, only partially resolved utility trade-off [<xref ref-type="bibr" rid="B20">20</xref>]. Blockchain-based architectures have emerged as a response to a structurally distinct concern, the risk posed by a single trusted aggregator, and increasingly serve as a substrate on which cryptographic and differential privacy mechanisms are layered to provide end-to-end verifiable privacy [<xref ref-type="bibr" rid="B14">14</xref>]-[<xref ref-type="bibr" rid="B18">18</xref>][<xref ref-type="bibr" rid="B35">35</xref>]. The attack-and-defence literature serves as the field’s risk-assessment layer, continually revealing new leakage channels (gradient inversion, backdoor evasion, secure-aggregation defeating attacks) that motivate revisions to the other three categories [<xref ref-type="bibr" rid="B41">41</xref>][<xref ref-type="bibr" rid="B43">43</xref>][<xref ref-type="bibr" rid="B44">44</xref>][<xref ref-type="bibr" rid="B51">51</xref>]. Architectural and governance frameworks are indispensable in translating technical mechanisms into deployable, systems compliant to regulations, especially in healthcare where legal restriction on access to patient data are significant a barrier to adoption [<xref ref-type="bibr" rid="B66">66</xref>][<xref ref-type="bibr" rid="B68">68</xref>][<xref ref-type="bibr" rid="B71">71</xref>].</p>
      <p>Gaps observed during classification process warrant serious attention in future research. These include: the trade-off between privacy guarantee strength and computational overhead, and differentiated privacy alone cannot suffice against a determined adversary, secondly, the collusion between the aggregating server and a subset of malicious clients is inadequately modelled across many of the reviewed literature, despite its relevance. Third, evaluation of the proposed defences against adaptive, defence-aware adversaries rather than the static, single-variant attacks remains rare, limiting confidence in real-world robustness, and lastly, the integration of privacy-preserving mechanisms with governance and regulatory frameworks, rather than treating them as an afterthought to a purely technical solution, is likely to be decisive in determining whether privacy-preserving federated learning architectures move from experimental prototypes to operational deployment at scale. The classification therefore indicates that future research should consider implementation of hybrid designs combining cryptographic and deferential privacy with blockchain-based.</p>
    </sec>
    <sec id="sec5">
      <title>5. Conclusion</title>
      <p>This systematic review demonstrates how a federated learning architecture for privacy preservation relies on both strict methodology and practical applications. The review offers researchers and policy-makers a clear framework for assessing modelling techniques in the context of their question. A federated learning architecture should consider scalability, fairness, and transparency in its implementation to ensure robustness and enhance privacy. Federated learning architecture remains the most widely used methods for enhancing privacy and offer the benefit of handling uncertainty. While modelling has advanced, more precise work is needed to meet evolving requirements. Privacy-preservation architectures should consider addressing scalability, fairness, and transparency in future developments, thereby strengthening federated learning architecture, improving privacy and accountability.</p>
    </sec>
    <sec id="sec6">
      <title>Author Contributions</title>
      <p>Mitende Nicholus Nyapete: Conceptualization, Formal Analysis; Funding acquisition, Investigation, Methodology, Resources, Software, Validation, Writing-original draft, Writing review &amp; editing; Richard Omolo: Supervision, Writing-review &amp; editing; Newton Masinde: Supervision, Writing-review &amp; editing.</p>
    </sec>
    <sec id="sec7">
      <title>Acknowledgements</title>
      <p>The authors would like to thank the School of Informatics and Innovative Systems at Jaramogi Oginga Odinga University of Science and Technology for providing a conducive environment for conducting this research. Richard Omolo Newton Masinde for their constructive suggestions and comments.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <title>References</title>
      <ref id="B1">
        <label>1.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Gabrielli, E., Pietro, A.D., Fenoglio, D., Pica, G. and Tolomei, G. (2026) A Survey on Decentralized Federated Learning. arXiv:2308.04604.</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Gabrielli, E.</string-name>
              <string-name>Pietro, A.D.</string-name>
              <string-name>Fenoglio, D.</string-name>
              <string-name>Pica, G.</string-name>
              <string-name>Tolomei, G.</string-name>
            </person-group>
            <year>2026</year>
            <article-title>A Survey on Decentralized Federated Learning</article-title>
            <fpage>2308</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B2">
        <label>2.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Li, T., Sahu, A.K., Talwalkar, A. and Smith, V. (2020) Federated Learning: Challenges, Methods, and Future Directions. <italic>IEEE</italic><italic>Signal</italic><italic>Processing</italic><italic>Magazine</italic>, 37, 50-60. https://doi.org/10.1109/msp.2020.2975749 <pub-id pub-id-type="doi">10.1109/msp.2020.2975749</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/msp.2020.2975749">https://doi.org/10.1109/msp.2020.2975749</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Li, T.</string-name>
              <string-name>Sahu, A.K.</string-name>
              <string-name>Talwalkar, A.</string-name>
              <string-name>Smith, V.</string-name>
              <string-name>Challenges, M</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Federated Learning: Challenges, Methods, and Future Directions</article-title>
            <source>IEEE Signal Processing Magazine</source>
            <volume>37</volume>
            <pub-id pub-id-type="doi">10.1109/msp.2020.2975749</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B3">
        <label>3.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Shahid, O., Pouriyeh, S., Parizi, R.M., Sheng, Q.Z., Srivastava, G. and Zhao, L. (2021) Communication Efficiency in Federated Learning: Achievements and Challenges. arXiv:2107.10996. http://arxiv.org/abs/2107.10996</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Shahid, O.</string-name>
              <string-name>Pouriyeh, S.</string-name>
              <string-name>Parizi, R.M.</string-name>
              <string-name>Sheng, Q.Z.</string-name>
              <string-name>Srivastava, G.</string-name>
              <string-name>Zhao, L.</string-name>
            </person-group>
            <year>2021</year>
            <article-title>Communication Efficiency in Federated Learning: Achievements and Challenges</article-title>
            <fpage>2107</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B4">
        <label>4.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Page, M.J., McKenzie, J.E., Bossuyt, P.M., Boutron, I., Hoffmann, T.C., Mulrow, C.D., <italic>et al</italic>. (2021) The PRISMA 2020 Statement: An Updated Guideline for Reporting Systematic Reviews. <italic>BMJ</italic>, 372, n71. https://doi.org/10.1136/bmj.n71 <pub-id pub-id-type="doi">10.1136/bmj.n71</pub-id><pub-id pub-id-type="pmid">33782057</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1136/bmj.n71">https://doi.org/10.1136/bmj.n71</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Page, M.J.</string-name>
              <string-name>McKenzie, J.E.</string-name>
              <string-name>Bossuyt, P.M.</string-name>
              <string-name>Boutron, I.</string-name>
              <string-name>Hoffmann, T.C.</string-name>
              <string-name>Mulrow, C.D.</string-name>
            </person-group>
            <year>2021</year>
            <article-title>The PRISMA 2020 Statement: An Updated Guideline for Reporting Systematic Reviews</article-title>
            <source>BMJ</source>
            <volume>372</volume>
            <pub-id pub-id-type="doi">10.1136/bmj.n71</pub-id>
            <pub-id pub-id-type="pmid">33782057</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B5">
        <label>5.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Ball, M., Bell-Clark, J., Gascon, A., Kairouz, P., Oh, S. and Xie, Z. (2024) Secure Stateful Aggregation: A Practical Protocol with Applications in Differentially-Private Federated Learning. arXiv:2410.11368.</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Ball, M.</string-name>
              <string-name>Bell-Clark, J.</string-name>
              <string-name>Gascon, A.</string-name>
              <string-name>Kairouz, P.</string-name>
              <string-name>Oh, S.</string-name>
              <string-name>Xie, Z.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Secure Stateful Aggregation: A Practical Protocol with Applications in Differentially-Private Federated Learning</article-title>
            <fpage>2410</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B6">
        <label>6.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Hosseini, S.M., Sikaroudi, M., Babaei, M. and Tizhoosh, H.R. (2022) Cluster Based Secure Multi-Party Computation in Federated Learning for Histopathology Images. In: Albarqouni, S., <italic>et al</italic>., Eds., <italic>Lecture</italic><italic>Notes</italic><italic>in</italic><italic>Computer</italic><italic>Science</italic>, Springer, 110-118. https://doi.org/10.1007/978-3-031-18523-6_11 <pub-id pub-id-type="doi">10.1007/978-3-031-18523-6_11</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/978-3-031-18523-6_11">https://doi.org/10.1007/978-3-031-18523-6_11</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Hosseini, S.M.</string-name>
              <string-name>Sikaroudi, M.</string-name>
              <string-name>Babaei, M.</string-name>
              <string-name>Tizhoosh, H.R.</string-name>
              <string-name>Albarqouni, S.</string-name>
              <string-name>Science, S</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Cluster Based Secure Multi-Party Computation in Federated Learning for Histopathology Images</article-title>
            <source>In: Albarqouni</source>
            <volume>110</volume>
            <pub-id pub-id-type="doi">10.1007/978-3-031-18523-6_11</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B7">
        <label>7.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Liu, F., Zheng, Z., Shi, Y., Tong, Y. and Zhang, Y. (2024) A Survey on Federated Learning: A Perspective from Multi-Party Computation. <italic>Frontiers</italic><italic>of</italic><italic>Computer</italic><italic>Science</italic>, 18, Article ID: 181336. https://doi.org/10.1007/s11704-023-3282-7 <pub-id pub-id-type="doi">10.1007/s11704-023-3282-7</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s11704-023-3282-7">https://doi.org/10.1007/s11704-023-3282-7</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Liu, F.</string-name>
              <string-name>Zheng, Z.</string-name>
              <string-name>Shi, Y.</string-name>
              <string-name>Tong, Y.</string-name>
              <string-name>Zhang, Y.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>A Survey on Federated Learning: A Perspective from Multi-Party Computation</article-title>
            <source>Frontiers of Computer Science</source>
            <volume>18</volume>
            <fpage>181336</fpage>
            <elocation-id>ID</elocation-id>
            <pub-id pub-id-type="doi">10.1007/s11704-023-3282-7</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B8">
        <label>8.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Ma, C., Li, J., Ding, M., Yang, H.H., Shu, F., Quek, T.Q.S. and Poor, H.V. (2020) On Safeguarding Privacy and Security in the Framework of Federated Learning. arXiv:1909.06512. http://arxiv.org/abs/1909.06512</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Ma, C.</string-name>
              <string-name>Li, J.</string-name>
              <string-name>Ding, M.</string-name>
              <string-name>Yang, H.H.</string-name>
              <string-name>Shu, F.</string-name>
              <string-name>Quek, T.Q.S.</string-name>
              <string-name>Poor, H.V.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>On Safeguarding Privacy and Security in the Framework of Federated Learning</article-title>
            <fpage>1909</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B9">
        <label>9.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Jin, W., Yao, Y., Han, S., Joe-Wong, C., Ravi, S., Avestimehr, S. and He, C. (2023) FedML-HE: An Efficient Homomorphic-Encryption-Based Privacy-Preserving Federated Learning System. arXiv:2303.10837. http://arxiv.org/abs/2303.10837</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Jin, W.</string-name>
              <string-name>Yao, Y.</string-name>
              <string-name>Han, S.</string-name>
              <string-name>Joe-Wong, C.</string-name>
              <string-name>Ravi, S.</string-name>
              <string-name>Avestimehr, S.</string-name>
              <string-name>He, C.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>FedML-HE: An Efficient Homomorphic-Encryption-Based Privacy-Preserving Federated Learning System</article-title>
            <fpage>2303</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B10">
        <label>10.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Hosseini, E., Chen, S. and Khisti, A. (2025) Secure Aggregation in Federated Learning Using Multiparty Homomorphic Encryption. arXiv:2503.00581.</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Hosseini, E.</string-name>
              <string-name>Chen, S.</string-name>
              <string-name>Khisti, A.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Secure Aggregation in Federated Learning Using Multiparty Homomorphic Encryption</article-title>
            <fpage>2503</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B11">
        <label>11.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Munjal, K. and Bhatia, R. (2023) A Systematic Review of Homomorphic Encryption and Its Contributions in Healthcare Industry. <italic>Complex &amp; Intelligent Systems</italic>, 9, 3759-3786. https://doi.org/10.1007/s40747-022-00756-z <pub-id pub-id-type="doi">10.1007/s40747-022-00756-z</pub-id><pub-id pub-id-type="pmid">35531323</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/s40747-022-00756-z">https://doi.org/10.1007/s40747-022-00756-z</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Munjal, K.</string-name>
              <string-name>Bhatia, R.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>A Systematic Review of Homomorphic Encryption and Its Contributions in Healthcare Industry</article-title>
            <source>Complex &amp; Intelligent Systems</source>
            <volume>9</volume>
            <pub-id pub-id-type="doi">10.1007/s40747-022-00756-z</pub-id>
            <pub-id pub-id-type="pmid">35531323</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B12">
        <label>12.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Nikfam, F., Casaburi, R., Marchisio, A., Martina, M. and Shafique, M. (2023) A Homomorphic Encryption Framework for Privacy-Preserving Spiking Neural Networks. <italic>Information</italic>, 14, Article 537. https://doi.org/10.3390/info14100537 <pub-id pub-id-type="doi">10.3390/info14100537</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/info14100537">https://doi.org/10.3390/info14100537</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Nikfam, F.</string-name>
              <string-name>Casaburi, R.</string-name>
              <string-name>Marchisio, A.</string-name>
              <string-name>Martina, M.</string-name>
              <string-name>Shafique, M.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>A Homomorphic Encryption Framework for Privacy-Preserving Spiking Neural Networks</article-title>
            <source>Information</source>
            <volume>14</volume>
            <elocation-id>537</elocation-id>
            <pub-id pub-id-type="doi">10.3390/info14100537</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B13">
        <label>13.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Hussien, N., Hussien, N.M., Salman, S.A. and Aljanabi, M. (2023) Secure Federated Learning with a Homomorphic Encryption Model. <italic>International Journal Papier Advance and Scientific Review</italic>, 4, 1-7. https://doi.org/10.47667/ijpasr.v4i3.235 <pub-id pub-id-type="doi">10.47667/ijpasr.v4i3.235</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.47667/ijpasr.v4i3.235">https://doi.org/10.47667/ijpasr.v4i3.235</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Hussien, N.</string-name>
              <string-name>Hussien, N.M.</string-name>
              <string-name>Salman, S.A.</string-name>
              <string-name>Aljanabi, M.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Secure Federated Learning with a Homomorphic Encryption Model</article-title>
            <source>International Journal Papier Advance and Scientific Review</source>
            <volume>4</volume>
            <pub-id pub-id-type="doi">10.47667/ijpasr.v4i3.235</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B14">
        <label>14.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Bellachia, A.A., Bouchiha, M.A., Ghamri-Doudane, Y. and Rabah, M. (2025) VerifBFL: Leveraging ZK-SNARKs for a Verifiable Blockchained Federated Learning. <italic>NOMS</italic>2025-2025 <italic>IEEE Network Operations and Management Symposium</italic>, Honolulu, 12-16 May 2025, 1-9. https://doi.org/10.1109/noms57970.2025.11073628 <pub-id pub-id-type="doi">10.1109/noms57970.2025.11073628</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/noms57970.2025.11073628">https://doi.org/10.1109/noms57970.2025.11073628</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Bellachia, A.A.</string-name>
              <string-name>Bouchiha, M.A.</string-name>
              <string-name>Ghamri-Doudane, Y.</string-name>
              <string-name>Rabah, M.</string-name>
              <string-name>Symposium, H</string-name>
            </person-group>
            <year>2025</year>
            <article-title>VerifBFL: Leveraging ZK-SNARKs for a Verifiable Blockchained Federated Learning</article-title>
            <source>NOMS 2025-2025 IEEE Network Operations and Management Symposium</source>
            <volume>12</volume>
            <pub-id pub-id-type="doi">10.1109/noms57970.2025.11073628</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B15">
        <label>15.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Ebrahimi, E., Sober, M., Hoang, A., Ileri, C.U., Sanders, W. and Schulte, S. (2024) Blockchain-Based Federated Learning Utilizing Zero-Knowledge Proofs for Verifiable Training and Aggregation. 2024 <italic>IEEE International Conference on Blockchain</italic> ( <italic>Blockchain</italic>), Copenhagen, 19-22 August 2024, 54-63. https://doi.org/10.1109/blockchain62396.2024.00017 <pub-id pub-id-type="doi">10.1109/blockchain62396.2024.00017</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/blockchain62396.2024.00017">https://doi.org/10.1109/blockchain62396.2024.00017</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Ebrahimi, E.</string-name>
              <string-name>Sober, M.</string-name>
              <string-name>Hoang, A.</string-name>
              <string-name>Ileri, C.U.</string-name>
              <string-name>Sanders, W.</string-name>
              <string-name>Schulte, S.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Blockchain-Based Federated Learning Utilizing Zero-Knowledge Proofs for Verifiable Training and Aggregation</article-title>
            <source>2024 IEEE International Conference on Blockchain (Blockchain)</source>
            <volume>19</volume>
            <pub-id pub-id-type="doi">10.1109/blockchain62396.2024.00017</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B16">
        <label>16.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Yang, J., Zhang, W., Guo, Z. and Gao, Z. (2023) Trustdfl: A Blockchain-Based Verifiable and Trusty Decentralized Federated Learning Framework. <italic>Electronics</italic>, 13, 86. https://doi.org/10.3390/electronics13010086 <pub-id pub-id-type="doi">10.3390/electronics13010086</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/electronics13010086">https://doi.org/10.3390/electronics13010086</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Yang, J.</string-name>
              <string-name>Zhang, W.</string-name>
              <string-name>Guo, Z.</string-name>
              <string-name>Gao, Z.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Trustdfl: A Blockchain-Based Verifiable and Trusty Decentralized Federated Learning Framework</article-title>
            <source>Electronics</source>
            <volume>13</volume>
            <pub-id pub-id-type="doi">10.3390/electronics13010086</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B17">
        <label>17.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Ahmadi, M. and Nourmohammadi, R. (2024) ZkFDL: An Efficient and Privacy-Preserving Decentralized Federated Learning with Zero Knowledge Proof. 2024 <italic>IEEE 3rd International Conference on AI in Cybersecurity</italic> ( <italic>ICAIC</italic>), Houston, 7-9 February 2024, 1-10. https://doi.org/10.1109/icaic60265.2024.10433831 <pub-id pub-id-type="doi">10.1109/icaic60265.2024.10433831</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/icaic60265.2024.10433831">https://doi.org/10.1109/icaic60265.2024.10433831</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Ahmadi, M.</string-name>
              <string-name>Nourmohammadi, R.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>ZkFDL: An Efficient and Privacy-Preserving Decentralized Federated Learning with Zero Knowledge Proof</article-title>
            <source>2024 IEEE 3rd International Conference on AI in Cybersecurity (ICAIC)</source>
            <volume>7</volume>
            <pub-id pub-id-type="doi">10.1109/icaic60265.2024.10433831</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B18">
        <label>18.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Byrd, D. and Polychroniadou, A. (2020) Differentially Private Secure Multi-Party Computation for Federated Learning in Financial Applications. <italic>Proceedings of the First ACM International Conference on AI in Finance</italic>, New York, 15-16 October 2020, 1-9. https://doi.org/10.1145/3383455.3422562 <pub-id pub-id-type="doi">10.1145/3383455.3422562</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/3383455.3422562">https://doi.org/10.1145/3383455.3422562</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Byrd, D.</string-name>
              <string-name>Polychroniadou, A.</string-name>
              <string-name>Finance, N</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Differentially Private Secure Multi-Party Computation for Federated Learning in Financial Applications</article-title>
            <source>Proceedings of the First ACM International Conference on AI in Finance</source>
            <volume>15</volume>
            <pub-id pub-id-type="doi">10.1145/3383455.3422562</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B19">
        <label>19.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">García-Cid, M.I., Bodanapu, D., Gatto, A., Martelli, P., Martín, V. and Ortiz, L. (2024) Experimental Implementation of a Quantum Zero-Knowledge Proof for User Authentication. <italic>Optics Express</italic>, 32, Article 15955. https://doi.org/10.1364/oe.517754 <pub-id pub-id-type="doi">10.1364/oe.517754</pub-id><pub-id pub-id-type="pmid">38859234</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1364/oe.517754">https://doi.org/10.1364/oe.517754</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Cid, M.I.</string-name>
              <string-name>Bodanapu, D.</string-name>
              <string-name>Gatto, A.</string-name>
              <string-name>Martelli, P.</string-name>
              <string-name>Ortiz, L.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Experimental Implementation of a Quantum Zero-Knowledge Proof for User Authentication</article-title>
            <source>Optics Express</source>
            <volume>32</volume>
            <elocation-id>15955</elocation-id>
            <pub-id pub-id-type="doi">10.1364/oe.517754</pub-id>
            <pub-id pub-id-type="pmid">38859234</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B20">
        <label>20.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Wei, K., Li, J., Ding, M., Ma, C., Yang, H.H., Farokhi, F., <italic>et al</italic>. (2020) Federated Learning with Differential Privacy: Algorithms and Performance Analysis. <italic>IEEE Transactions on Information Forensics and Security</italic>, 15, 3454-3469. https://doi.org/10.1109/tifs.2020.2988575 <pub-id pub-id-type="doi">10.1109/tifs.2020.2988575</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/tifs.2020.2988575">https://doi.org/10.1109/tifs.2020.2988575</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Wei, K.</string-name>
              <string-name>Li, J.</string-name>
              <string-name>Ding, M.</string-name>
              <string-name>Ma, C.</string-name>
              <string-name>Yang, H.H.</string-name>
              <string-name>Farokhi, F.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Federated Learning with Differential Privacy: Algorithms and Performance Analysis</article-title>
            <source>IEEE Transactions on Information Forensics and Security</source>
            <volume>15</volume>
            <pub-id pub-id-type="doi">10.1109/tifs.2020.2988575</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B21">
        <label>21.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Fu, J., Hong, Y., Ling, X., Wang, L., Ran, X., Sun, Z., Wang, W.H., Chen, Z. and Cao, Y. (2024) Differentially Private Federated Learning: A Systematic Review. arXiv:2405.08299.</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Fu, J.</string-name>
              <string-name>Hong, Y.</string-name>
              <string-name>Ling, X.</string-name>
              <string-name>Wang, L.</string-name>
              <string-name>Ran, X.</string-name>
              <string-name>Sun, Z.</string-name>
              <string-name>Wang, W.H.</string-name>
              <string-name>Chen, Z.</string-name>
              <string-name>Cao, Y.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Differentially Private Federated Learning: A Systematic Review</article-title>
            <fpage>2405</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B22">
        <label>22.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Kim, E. and Lee, E. (2024) Evaluating the Impact of Mobility on Differentially Private Federated Learning. <italic>Applied Sciences</italic>, 14, Article 5245. https://doi.org/10.3390/app14125245 <pub-id pub-id-type="doi">10.3390/app14125245</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/app14125245">https://doi.org/10.3390/app14125245</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Kim, E.</string-name>
              <string-name>Lee, E.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Evaluating the Impact of Mobility on Differentially Private Federated Learning</article-title>
            <source>Applied Sciences</source>
            <volume>14</volume>
            <elocation-id>5245</elocation-id>
            <pub-id pub-id-type="doi">10.3390/app14125245</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B23">
        <label>23.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Ibrahim Khalaf, O., Ashokkumar, S.R., Algburi, S., Anupallavi, S., Selvaraj, D., Sharif, M.S., <italic>et al</italic>. (2024) Federated Learning with Hybrid Differential Privacy for Secure and Reliable Cross‐IoT Platform Knowledge Sharing. <italic>Security and Privacy</italic>, 7, e374. https://doi.org/10.1002/spy2.374 <pub-id pub-id-type="doi">10.1002/spy2.374</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1002/spy2.374">https://doi.org/10.1002/spy2.374</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Khalaf, O.</string-name>
              <string-name>Ashokkumar, S.R.</string-name>
              <string-name>Algburi, S.</string-name>
              <string-name>Anupallavi, S.</string-name>
              <string-name>Selvaraj, D.</string-name>
              <string-name>Sharif, M.S.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Federated Learning with Hybrid Differential Privacy for Secure and Reliable Cross‐IoT Platform Knowledge Sharing</article-title>
            <source>Security and Privacy</source>
            <volume>7</volume>
            <pub-id pub-id-type="doi">10.1002/spy2.374</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B24">
        <label>24.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Ren, X., Yang, S., Zhao, C., McCann, J. and Xu, Z. (2024) Belt and Braces: When Federated Learning Meets Differential Privacy. <italic>Communications of the ACM</italic>, 67, 66-77. https://doi.org/10.1145/3650028 <pub-id pub-id-type="doi">10.1145/3650028</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/3650028">https://doi.org/10.1145/3650028</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Ren, X.</string-name>
              <string-name>Yang, S.</string-name>
              <string-name>Zhao, C.</string-name>
              <string-name>McCann, J.</string-name>
              <string-name>Xu, Z.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Belt and Braces: When Federated Learning Meets Differential Privacy</article-title>
            <source>Communications of the ACM</source>
            <volume>67</volume>
            <pub-id pub-id-type="doi">10.1145/3650028</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B25">
        <label>25.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Dyda, A., Purcell, M., Curtis, S., Field, E., Pillai, P., Ricardo, K., <italic>et al</italic>. (2021) Differential Privacy for Public Health Data: An Innovative Tool to Optimize Information Sharing While Protecting Data Confidentiality. <italic>Patterns</italic>, 2, Article 100366. https://doi.org/10.1016/j.patter.2021.100366 <pub-id pub-id-type="doi">10.1016/j.patter.2021.100366</pub-id><pub-id pub-id-type="pmid">34909703</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.patter.2021.100366">https://doi.org/10.1016/j.patter.2021.100366</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Dyda, A.</string-name>
              <string-name>Purcell, M.</string-name>
              <string-name>Curtis, S.</string-name>
              <string-name>Field, E.</string-name>
              <string-name>Pillai, P.</string-name>
              <string-name>Ricardo, K.</string-name>
            </person-group>
            <year>2021</year>
            <article-title>Differential Privacy for Public Health Data: An Innovative Tool to Optimize Information Sharing While Protecting Data Confidentiality</article-title>
            <source>Patterns</source>
            <volume>2</volume>
            <elocation-id>100366</elocation-id>
            <pub-id pub-id-type="doi">10.1016/j.patter.2021.100366</pub-id>
            <pub-id pub-id-type="pmid">34909703</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B26">
        <label>26.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Wang, B., Li, H., Ren, X. and Guo, Y. (2023) An Efficient Differential Privacy-Based Method for Location Privacy Protection in Location-Based Services. <italic>Sensors</italic>, 23, Article 5219. https://doi.org/10.3390/s23115219 <pub-id pub-id-type="doi">10.3390/s23115219</pub-id><pub-id pub-id-type="pmid">37299946</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/s23115219">https://doi.org/10.3390/s23115219</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Wang, B.</string-name>
              <string-name>Li, H.</string-name>
              <string-name>Ren, X.</string-name>
              <string-name>Guo, Y.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>An Efficient Differential Privacy-Based Method for Location Privacy Protection in Location-Based Services</article-title>
            <source>Sensors</source>
            <volume>23</volume>
            <elocation-id>5219</elocation-id>
            <pub-id pub-id-type="doi">10.3390/s23115219</pub-id>
            <pub-id pub-id-type="pmid">37299946</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B27">
        <label>27.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Jiang, Y., Ma, B., Wang, X., Yu, G., Yu, P., Wang, Z., <italic>et al</italic>. (2024) Blockchained Federated Learning for Internet of Things: A Comprehensive Survey. <italic>ACM Computing Surveys</italic>, 56, 1-37. https://doi.org/10.1145/3659099 <pub-id pub-id-type="doi">10.1145/3659099</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/3659099">https://doi.org/10.1145/3659099</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Jiang, Y.</string-name>
              <string-name>Ma, B.</string-name>
              <string-name>Wang, X.</string-name>
              <string-name>Yu, G.</string-name>
              <string-name>Yu, P.</string-name>
              <string-name>Wang, Z.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Blockchained Federated Learning for Internet of Things: A Comprehensive Survey</article-title>
            <source>ACM Computing Surveys</source>
            <volume>56</volume>
            <pub-id pub-id-type="doi">10.1145/3659099</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B28">
        <label>28.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Khalil, U., Malik, O.A., Uddin, M. and Chen, C.-L. (2022) A Comparative Analysis on Blockchain versus Centralized Authentication Architectures for IoT-Enabled Smart Devices in Smart Cities: A Comprehensive Review, Recent Advances, and Future Research Directions. <italic>Sensors</italic>, 22, Article 5168. https://doi.org/10.3390/s22145168 <pub-id pub-id-type="doi">10.3390/s22145168</pub-id><pub-id pub-id-type="pmid">35890848</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/s22145168">https://doi.org/10.3390/s22145168</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Khalil, U.</string-name>
              <string-name>Malik, O.A.</string-name>
              <string-name>Uddin, M.</string-name>
              <string-name>Chen, C.</string-name>
              <string-name>Review, R</string-name>
            </person-group>
            <year>2022</year>
            <article-title>A Comparative Analysis on Blockchain versus Centralized Authentication Architectures for IoT-Enabled Smart Devices in Smart Cities: A Comprehensive Review, Recent Advances, and Future Research Directions</article-title>
            <source>Sensors</source>
            <volume>22</volume>
            <elocation-id>5168</elocation-id>
            <pub-id pub-id-type="doi">10.3390/s22145168</pub-id>
            <pub-id pub-id-type="pmid">35890848</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B29">
        <label>29.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Li, Y., Chen, C., Liu, N., Huang, H., Zheng, Z. and Yan, Q. (2021) A Blockchain-Based Decentralized Federated Learning Framework with Committee Consensus. <italic>IEEE Network</italic>, 35, 234-241. https://doi.org/10.1109/mnet.011.2000263 <pub-id pub-id-type="doi">10.1109/mnet.011.2000263</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/mnet.011.2000263">https://doi.org/10.1109/mnet.011.2000263</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Li, Y.</string-name>
              <string-name>Chen, C.</string-name>
              <string-name>Liu, N.</string-name>
              <string-name>Huang, H.</string-name>
              <string-name>Zheng, Z.</string-name>
              <string-name>Yan, Q.</string-name>
            </person-group>
            <year>2021</year>
            <article-title>A Blockchain-Based Decentralized Federated Learning Framework with Committee Consensus</article-title>
            <source>IEEE Network</source>
            <volume>35</volume>
            <pub-id pub-id-type="doi">10.1109/mnet.011.2000263</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B30">
        <label>30.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Lo, S.K., Liu, Y., Lu, Q., Wang, C., Xu, X., Paik, H.-Y. and Zhu, L. (2021) Block-Chain-Based Trustworthy Federated Learning Architecture. arXiv:2108.06912.</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Lo, S.K.</string-name>
              <string-name>Liu, Y.</string-name>
              <string-name>Lu, Q.</string-name>
              <string-name>Wang, C.</string-name>
              <string-name>Xu, X.</string-name>
              <string-name>Paik, H.</string-name>
              <string-name>Zhu, L.</string-name>
            </person-group>
            <year>2021</year>
            <article-title>Block-Chain-Based Trustworthy Federated Learning Architecture</article-title>
            <fpage>2108</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B31">
        <label>31.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Noh, S. and Rhee, K. (2024) Transparent and Accountable Training Data Sharing in Decentralized Machine Learning Systems. <italic>Computers</italic>, <italic>Materials &amp; Continua</italic>, 79, 3805-3826. https://doi.org/10.32604/cmc.2024.050949 <pub-id pub-id-type="doi">10.32604/cmc.2024.050949</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.32604/cmc.2024.050949">https://doi.org/10.32604/cmc.2024.050949</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Noh, S.</string-name>
              <string-name>Rhee, K.</string-name>
              <string-name>Computers, M</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Transparent and Accountable Training Data Sharing in Decentralized Machine Learning Systems</article-title>
            <source>Computers</source>
            <volume>79</volume>
            <pub-id pub-id-type="doi">10.32604/cmc.2024.050949</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B32">
        <label>32.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Sun, Z., Wan, J., Yin, L., Cao, Z., Luo, T. and Wang, B. (2022) A Blockchain-Based Audit Approach for Encrypted Data in Federated Learning. <italic>Digital Communications and Networks</italic>, 8, 614-624. https://doi.org/10.1016/j.dcan.2022.05.006 <pub-id pub-id-type="doi">10.1016/j.dcan.2022.05.006</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.dcan.2022.05.006">https://doi.org/10.1016/j.dcan.2022.05.006</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Sun, Z.</string-name>
              <string-name>Wan, J.</string-name>
              <string-name>Yin, L.</string-name>
              <string-name>Cao, Z.</string-name>
              <string-name>Luo, T.</string-name>
              <string-name>Wang, B.</string-name>
            </person-group>
            <year>2022</year>
            <article-title>A Blockchain-Based Audit Approach for Encrypted Data in Federated Learning</article-title>
            <source>Digital Communications and Networks</source>
            <volume>8</volume>
            <pub-id pub-id-type="doi">10.1016/j.dcan.2022.05.006</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B33">
        <label>33.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Tang, W., Liu, E., Ni, W., Qu, X., Huang, B., Li, K., <italic>et al</italic>. (2025) Game-Theoretic Incentive Mechanism for Blockchain-Based Federated Learning. <italic>IEEE Transactions on Mobile Computing</italic>, 24, 10363-10376. https://doi.org/10.1109/tmc.2025.3567355 <pub-id pub-id-type="doi">10.1109/tmc.2025.3567355</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/tmc.2025.3567355">https://doi.org/10.1109/tmc.2025.3567355</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Tang, W.</string-name>
              <string-name>Liu, E.</string-name>
              <string-name>Ni, W.</string-name>
              <string-name>Qu, X.</string-name>
              <string-name>Huang, B.</string-name>
              <string-name>Li, K.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Game-Theoretic Incentive Mechanism for Blockchain-Based Federated Learning</article-title>
            <source>IEEE Transactions on Mobile Computing</source>
            <volume>24</volume>
            <pub-id pub-id-type="doi">10.1109/tmc.2025.3567355</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B34">
        <label>34.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Ren, Y., Hu, M., Yang, Z., Feng, G. and Zhang, X. (2024) BPFL: Blockchain-Based Privacy-Preserving Federated Learning against Poisoning Attack. <italic>Information Sciences</italic>, 665, Article 120377. https://doi.org/10.1016/j.ins.2024.120377 <pub-id pub-id-type="doi">10.1016/j.ins.2024.120377</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.ins.2024.120377">https://doi.org/10.1016/j.ins.2024.120377</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Ren, Y.</string-name>
              <string-name>Hu, M.</string-name>
              <string-name>Yang, Z.</string-name>
              <string-name>Feng, G.</string-name>
              <string-name>Zhang, X.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>BPFL: Blockchain-Based Privacy-Preserving Federated Learning against Poisoning Attack</article-title>
            <source>Information Sciences</source>
            <volume>665</volume>
            <elocation-id>120377</elocation-id>
            <pub-id pub-id-type="doi">10.1016/j.ins.2024.120377</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B35">
        <label>35.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Narkedimilli, S., Sriram, A.V., Makam, S., Sathvik, M. and Mallellu, S.P. (2025) FAPL-DM-BC: A Secure and Scalable FL Framework with Adaptive Privacy and Dynamic Masking, Blockchain, and XAI for the IoVs. arXiv:2501.01063.</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Narkedimilli, S.</string-name>
              <string-name>Sriram, A.V.</string-name>
              <string-name>Makam, S.</string-name>
              <string-name>Sathvik, M.</string-name>
              <string-name>Mallellu, S.P.</string-name>
              <string-name>Masking, B</string-name>
            </person-group>
            <year>2025</year>
            <article-title>FAPL-DM-BC: A Secure and Scalable FL Framework with Adaptive Privacy and Dynamic Masking, Blockchain, and XAI for the IoVs</article-title>
            <fpage>2501</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B36">
        <label>36.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Rehman, A., Abbas, S., Khan, M.A., Ghazal, T.M., Adnan, K.M. and Mosavi, A. (2022) A Secure Healthcare 5.0 System Based on Blockchain Technology Entangled with Federated Learning Technique. <italic>Computers in Biology and Medicine</italic>, 150, Article 106019. https://doi.org/10.1016/j.compbiomed.2022.106019 <pub-id pub-id-type="doi">10.1016/j.compbiomed.2022.106019</pub-id><pub-id pub-id-type="pmid">36162198</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.compbiomed.2022.106019">https://doi.org/10.1016/j.compbiomed.2022.106019</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Rehman, A.</string-name>
              <string-name>Abbas, S.</string-name>
              <string-name>Khan, M.A.</string-name>
              <string-name>Ghazal, T.M.</string-name>
              <string-name>Adnan, K.M.</string-name>
              <string-name>Mosavi, A.</string-name>
            </person-group>
            <year>2022</year>
            <article-title>A Secure Healthcare 5</article-title>
            <source>0 System Based on Blockchain Technology Entangled with Federated Learning Technique. Computers in Biology and Medicine</source>
            <volume>150</volume>
            <elocation-id>106019</elocation-id>
            <pub-id pub-id-type="doi">10.1016/j.compbiomed.2022.106019</pub-id>
            <pub-id pub-id-type="pmid">36162198</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B37">
        <label>37.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Vijay Anand, R., Magesh, G., Alagiri, I., Brahmam, M.G., Balusamy, B., Selvan, C.P., <italic>et al</italic>. (2025) Design of an Improved Model Using Federated Learning and LSTM Autoencoders for Secure and Transparent Blockchain Network Transactions. <italic>Scientific Reports</italic>, 15, Article No. 1615. https://doi.org/10.1038/s41598-024-83564-4 <pub-id pub-id-type="doi">10.1038/s41598-024-83564-4</pub-id><pub-id pub-id-type="pmid">39794364</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1038/s41598-024-83564-4">https://doi.org/10.1038/s41598-024-83564-4</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Anand, R.</string-name>
              <string-name>Magesh, G.</string-name>
              <string-name>Alagiri, I.</string-name>
              <string-name>Brahmam, M.G.</string-name>
              <string-name>Balusamy, B.</string-name>
              <string-name>Selvan, C.P.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Design of an Improved Model Using Federated Learning and LSTM Autoencoders for Secure and Transparent Blockchain Network Transactions</article-title>
            <source>Scientific Reports</source>
            <volume>15</volume>
            <elocation-id>No</elocation-id>
            <pub-id pub-id-type="doi">10.1038/s41598-024-83564-4</pub-id>
            <pub-id pub-id-type="pmid">39794364</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B38">
        <label>38.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Liu, P., Xu, X. and Wang, W. (2022) Threats, Attacks and Defenses to Federated Learning: Issues, Taxonomy and Perspectives. <italic>Cybersecurity</italic>, 5, Article No. 4. https://doi.org/10.1186/s42400-021-00105-6 <pub-id pub-id-type="doi">10.1186/s42400-021-00105-6</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1186/s42400-021-00105-6">https://doi.org/10.1186/s42400-021-00105-6</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Liu, P.</string-name>
              <string-name>Xu, X.</string-name>
              <string-name>Wang, W.</string-name>
              <string-name>Threats, A</string-name>
              <string-name>Issues, T</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Threats, Attacks and Defenses to Federated Learning: Issues, Taxonomy and Perspectives</article-title>
            <source>Cybersecurity</source>
            <volume>5</volume>
            <elocation-id>No</elocation-id>
            <pub-id pub-id-type="doi">10.1186/s42400-021-00105-6</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B39">
        <label>39.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Sikandar, H.S., Waheed, H., Tahir, S., Malik, S.U.R. and Rafique, W. (2023) A Detailed Survey on Federated Learning Attacks and Defenses. <italic>Electronics</italic>, 12, Article 260. https://doi.org/10.3390/electronics12020260 <pub-id pub-id-type="doi">10.3390/electronics12020260</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/electronics12020260">https://doi.org/10.3390/electronics12020260</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Sikandar, H.S.</string-name>
              <string-name>Waheed, H.</string-name>
              <string-name>Tahir, S.</string-name>
              <string-name>Malik, S.U.R.</string-name>
              <string-name>Rafique, W.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>A Detailed Survey on Federated Learning Attacks and Defenses</article-title>
            <source>Electronics</source>
            <volume>12</volume>
            <elocation-id>260</elocation-id>
            <pub-id pub-id-type="doi">10.3390/electronics12020260</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B40">
        <label>40.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D. and Shmatikov, V. (2020) How to Backdoor Federated Learning. <italic>Proceedings of the Twenty Third International Conference on Artificial Intelligence and Statistics</italic>, 108, 2938-2948.</mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Bagdasaryan, E.</string-name>
              <string-name>Veit, A.</string-name>
              <string-name>Hua, Y.</string-name>
              <string-name>Estrin, D.</string-name>
              <string-name>Shmatikov, V.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>How to Backdoor Federated Learning</article-title>
            <source>Proceedings of the Twenty Third International Conference on Artificial Intelligence and Statistics</source>
            <volume>108</volume>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B41">
        <label>41.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Wang, Q., Wu, Y., Xuan, H. and Wu, H. (2024) FLARE: A Backdoor Attack to Federated Learning with Refined Evasion. <italic>Mathematics</italic>, 12, Article 3751. https://doi.org/10.3390/math12233751 <pub-id pub-id-type="doi">10.3390/math12233751</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/math12233751">https://doi.org/10.3390/math12233751</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Wang, Q.</string-name>
              <string-name>Wu, Y.</string-name>
              <string-name>Xuan, H.</string-name>
              <string-name>Wu, H.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>FLARE: A Backdoor Attack to Federated Learning with Refined Evasion</article-title>
            <source>Mathematics</source>
            <volume>12</volume>
            <elocation-id>3751</elocation-id>
            <pub-id pub-id-type="doi">10.3390/math12233751</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B42">
        <label>42.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Tolpegin, V., Truex, S., Gursoy, M.E. and Liu, L. (2020) Data Poisoning Attacks against Federated Learning Systems. In: Chen, L., Li, N., Liang, K. and Schneider, S., Eds., <italic>Lecture Notes in Computer Science</italic>, Springer International Publishing, 480-501. https://doi.org/10.1007/978-3-030-58951-6_24 <pub-id pub-id-type="doi">10.1007/978-3-030-58951-6_24</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/978-3-030-58951-6_24">https://doi.org/10.1007/978-3-030-58951-6_24</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Tolpegin, V.</string-name>
              <string-name>Truex, S.</string-name>
              <string-name>Gursoy, M.E.</string-name>
              <string-name>Liu, L.</string-name>
              <string-name>Chen, L.</string-name>
              <string-name>Li, N.</string-name>
              <string-name>Liang, K.</string-name>
              <string-name>Schneider, S.</string-name>
              <string-name>Science, S</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Data Poisoning Attacks against Federated Learning Systems</article-title>
            <source>In: Chen</source>
            <volume>480</volume>
            <pub-id pub-id-type="doi">10.1007/978-3-030-58951-6_24</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B43">
        <label>43.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Pasquini, D., Francati, D. and Ateniese, G. (2022) Eluding Secure Aggregation in Federated Learning via Model Inconsistency. Proceedings of the 2022 <italic>ACM SIGSAC Conference on Computer and Communications Security</italic>, Los Angeles, 7-11 November 2022, 2429-2443. https://doi.org/10.1145/3548606.3560557 <pub-id pub-id-type="doi">10.1145/3548606.3560557</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/3548606.3560557">https://doi.org/10.1145/3548606.3560557</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Pasquini, D.</string-name>
              <string-name>Francati, D.</string-name>
              <string-name>Ateniese, G.</string-name>
              <string-name>Security, L</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Eluding Secure Aggregation in Federated Learning via Model Inconsistency</article-title>
            <source>Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security</source>
            <volume>7</volume>
            <pub-id pub-id-type="doi">10.1145/3548606.3560557</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B44">
        <label>44.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Zhang, Y., Behnia, R., Yavuz, A.A., Ebrahimi, R. and Bertino, E. (2024) Uncovering Attacks and Defenses in Secure Aggregation for Federated Deep Learning. 2024 <italic>IEEE International Conference on Data Mining Workshops</italic> ( <italic>ICDMW</italic>), Abu Dhabi, 9 December 2024, 650-656. https://doi.org/10.1109/icdmw65004.2024.00090 <pub-id pub-id-type="doi">10.1109/icdmw65004.2024.00090</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/icdmw65004.2024.00090">https://doi.org/10.1109/icdmw65004.2024.00090</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Zhang, Y.</string-name>
              <string-name>Behnia, R.</string-name>
              <string-name>Yavuz, A.A.</string-name>
              <string-name>Ebrahimi, R.</string-name>
              <string-name>Bertino, E.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Uncovering Attacks and Defenses in Secure Aggregation for Federated Deep Learning</article-title>
            <source>2024 IEEE International Conference on Data Mining Workshops (ICDMW)</source>
            <volume>9</volume>
            <pub-id pub-id-type="doi">10.1109/icdmw65004.2024.00090</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B45">
        <label>45.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Shi, J., Wan, W., Hu, S., Lu, J. and Yu Zhang, L. (2022) Challenges and Approaches for Mitigating Byzantine Attacks in Federated Learning. 2022 <italic>IEEE International Con</italic><italic>ference on Trust</italic>, <italic>Security and Privacy in Computing and Communication</italic><italic>s</italic>( <italic>TrustCom</italic>), Wuhan, 9-11 December 2022, 139-146. https://doi.org/10.1109/trustcom56396.2022.00030 <pub-id pub-id-type="doi">10.1109/trustcom56396.2022.00030</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/trustcom56396.2022.00030">https://doi.org/10.1109/trustcom56396.2022.00030</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Shi, J.</string-name>
              <string-name>Wan, W.</string-name>
              <string-name>Hu, S.</string-name>
              <string-name>Lu, J.</string-name>
              <string-name>Zhang, L.</string-name>
              <string-name>Trust, S</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Challenges and Approaches for Mitigating Byzantine Attacks in Federated Learning</article-title>
            <source>2022 IEEE International Conference on Trust</source>
            <volume>9</volume>
            <pub-id pub-id-type="doi">10.1109/trustcom56396.2022.00030</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B46">
        <label>46.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Wan, W., Hu, S., Lu, J., Zhang, L.Y., Jin, H. and He, Y. (2022) Shielding Federated Learning: Robust Aggregation with Adaptive Client Selection. <italic>Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence</italic>, Guangzhou, 29-31 August 2025, 753-760. https://doi.org/10.24963/ijcai.2022/106 <pub-id pub-id-type="doi">10.24963/ijcai.2022/106</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.24963/ijcai.2022/106">https://doi.org/10.24963/ijcai.2022/106</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Wan, W.</string-name>
              <string-name>Hu, S.</string-name>
              <string-name>Lu, J.</string-name>
              <string-name>Zhang, L.Y.</string-name>
              <string-name>Jin, H.</string-name>
              <string-name>He, Y.</string-name>
              <string-name>Intelligence, G</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Shielding Federated Learning: Robust Aggregation with Adaptive Client Selection</article-title>
            <source>Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence</source>
            <volume>29</volume>
            <pub-id pub-id-type="doi">10.24963/ijcai.2022/106</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B47">
        <label>47.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Zhang, K., Tao, G., Xu, Q., Cheng, S., An, S., Liu, Y., Feng, S., Shen, G., Chen, P.-Y., Ma, S. and Zhang, X. (2023) FLIP: A Provable Defense Framework for Backdoor Mitigation in Federated Learning. arXiv:2210.12873.</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Zhang, K.</string-name>
              <string-name>Tao, G.</string-name>
              <string-name>Xu, Q.</string-name>
              <string-name>Cheng, S.</string-name>
              <string-name>An, S.</string-name>
              <string-name>Liu, Y.</string-name>
              <string-name>Feng, S.</string-name>
              <string-name>Shen, G.</string-name>
              <string-name>Chen, P.</string-name>
              <string-name>Ma, S.</string-name>
              <string-name>Zhang, X.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>FLIP: A Provable Defense Framework for Backdoor Mitigation in Federated Learning</article-title>
            <fpage>2210</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B48">
        <label>48.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Benmalek, M., Benrekia, M.A. and Challal, Y. (2022) Security of Federated Learning: Attacks, Defensive Mechanisms, and Challenges. <italic>Revue</italic><italic>d</italic>’ <italic>Intelligence</italic><italic>Artificielle</italic>, 36, 49-59. https://doi.org/10.18280/ria.360106 <pub-id pub-id-type="doi">10.18280/ria.360106</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.18280/ria.360106">https://doi.org/10.18280/ria.360106</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Benmalek, M.</string-name>
              <string-name>Benrekia, M.A.</string-name>
              <string-name>Challal, Y.</string-name>
              <string-name>Attacks, D</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Security of Federated Learning: Attacks, Defensive Mechanisms, and Challenges</article-title>
            <source>Revue d’Intelligence Artificielle</source>
            <volume>36</volume>
            <pub-id pub-id-type="doi">10.18280/ria.360106</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B49">
        <label>49.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Chen, Y., Gui, Y., Lin, H., Gan, W. and Wu, Y. (2022) Federated Learning Attacks and Defenses: A Survey. 2022 <italic>IEEE International Conference on Big Data</italic> ( <italic>Big Data</italic>), Osaka, 17-20 December 2022, 4256-4265. https://doi.org/10.1109/bigdata55660.2022.10020431 <pub-id pub-id-type="doi">10.1109/bigdata55660.2022.10020431</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/bigdata55660.2022.10020431">https://doi.org/10.1109/bigdata55660.2022.10020431</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Chen, Y.</string-name>
              <string-name>Gui, Y.</string-name>
              <string-name>Lin, H.</string-name>
              <string-name>Gan, W.</string-name>
              <string-name>Wu, Y.</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Federated Learning Attacks and Defenses: A Survey</article-title>
            <source>2022 IEEE International Conference on Big Data (Big Data)</source>
            <volume>17</volume>
            <pub-id pub-id-type="doi">10.1109/bigdata55660.2022.10020431</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B50">
        <label>50.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Moshawrab, M., Adda, M., Bouzouane, A., Ibrahim, H. and Raad, A. (2024) Securing Federated Learning: Approaches, Mechanisms and Opportunities. <italic>Electronics</italic>, 13, Article 3675. https://doi.org/10.3390/electronics13183675 <pub-id pub-id-type="doi">10.3390/electronics13183675</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/electronics13183675">https://doi.org/10.3390/electronics13183675</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Moshawrab, M.</string-name>
              <string-name>Adda, M.</string-name>
              <string-name>Bouzouane, A.</string-name>
              <string-name>Ibrahim, H.</string-name>
              <string-name>Raad, A.</string-name>
              <string-name>Approaches, M</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Securing Federated Learning: Approaches, Mechanisms and Opportunities</article-title>
            <source>Electronics</source>
            <volume>13</volume>
            <elocation-id>3675</elocation-id>
            <pub-id pub-id-type="doi">10.3390/electronics13183675</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B51">
        <label>51.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Wainakh, A., Zimmer, E., Subedi, S., Keim, J., Grube, T., Karuppayah, S., <italic>et al</italic>. (2022) Federated Learning Attacks Revisited: A Critical Discussion of Gaps, Assumptions, and Evaluation Setups. <italic>Sensors</italic>, 23, Article 31. https://doi.org/10.3390/s23010031 <pub-id pub-id-type="doi">10.3390/s23010031</pub-id><pub-id pub-id-type="pmid">36616629</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/s23010031">https://doi.org/10.3390/s23010031</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Wainakh, A.</string-name>
              <string-name>Zimmer, E.</string-name>
              <string-name>Subedi, S.</string-name>
              <string-name>Keim, J.</string-name>
              <string-name>Grube, T.</string-name>
              <string-name>Karuppayah, S.</string-name>
              <string-name>Gaps, A</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Federated Learning Attacks Revisited: A Critical Discussion of Gaps, Assumptions, and Evaluation Setups</article-title>
            <source>Sensors</source>
            <volume>23</volume>
            <elocation-id>31</elocation-id>
            <pub-id pub-id-type="doi">10.3390/s23010031</pub-id>
            <pub-id pub-id-type="pmid">36616629</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B52">
        <label>52.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Xie, X., Hu, C., Ren, H. and Deng, J. (2024) A Survey on Vulnerability of Federated Learning: A Learning Algorithm Perspective. <italic>Neurocomputing</italic>, 573, Article 127225. https://doi.org/10.1016/j.neucom.2023.127225 <pub-id pub-id-type="doi">10.1016/j.neucom.2023.127225</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.neucom.2023.127225">https://doi.org/10.1016/j.neucom.2023.127225</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Xie, X.</string-name>
              <string-name>Hu, C.</string-name>
              <string-name>Ren, H.</string-name>
              <string-name>Deng, J.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>A Survey on Vulnerability of Federated Learning: A Learning Algorithm Perspective</article-title>
            <source>Neurocomputing</source>
            <volume>573</volume>
            <elocation-id>127225</elocation-id>
            <pub-id pub-id-type="doi">10.1016/j.neucom.2023.127225</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B53">
        <label>53.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Zakaria, F. and Khalid, S.K. (2025) A Review of Federated Learning Attacks: Threat Models and Defence Strategies. <italic>International Journal of Advanced Computer Science and Applications</italic>, 16, 544-554. https://doi.org/10.14569/ijacsa.2025.0160754 <pub-id pub-id-type="doi">10.14569/ijacsa.2025.0160754</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.14569/ijacsa.2025.0160754">https://doi.org/10.14569/ijacsa.2025.0160754</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Zakaria, F.</string-name>
              <string-name>Khalid, S.K.</string-name>
            </person-group>
            <year>2025</year>
            <article-title>A Review of Federated Learning Attacks: Threat Models and Defence Strategies</article-title>
            <source>International Journal of Advanced Computer Science and Applications</source>
            <volume>16</volume>
            <pub-id pub-id-type="doi">10.14569/ijacsa.2025.0160754</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B54">
        <label>54.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Chaudhury, B.R., Li, L., Kang, M., Li, B. and Mehta, R. (2022) Fairness in Federated Learning via Core-Stability. <italic>Advances in Neural Information Processing Systems</italic> 35, New Orleans, 28 November-9 December 2022, 5738-5750. https://doi.org/10.52202/068431-0415 <pub-id pub-id-type="doi">10.52202/068431-0415</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.52202/068431-0415">https://doi.org/10.52202/068431-0415</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Chaudhury, B.R.</string-name>
              <string-name>Li, L.</string-name>
              <string-name>Kang, M.</string-name>
              <string-name>Li, B.</string-name>
              <string-name>Mehta, R.</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Fairness in Federated Learning via Core-Stability</article-title>
            <source>Advances in Neural Information Processing Systems 35</source>
            <volume>28</volume>
            <pub-id pub-id-type="doi">10.52202/068431-0415</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B55">
        <label>55.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Pan, Z., Wang, S., Li, C., Wang, H., Tang, X. and Zhao, J. (2023) FedMDFG: Federated Learning with Multi-Gradient Descent and Fair Guidance. <italic>Proceedings of the AAAI Conference on Artificial Intelligence</italic>, 37, 9364-9371. https://doi.org/10.1609/aaai.v37i8.26122 <pub-id pub-id-type="doi">10.1609/aaai.v37i8.26122</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1609/aaai.v37i8.26122">https://doi.org/10.1609/aaai.v37i8.26122</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Pan, Z.</string-name>
              <string-name>Wang, S.</string-name>
              <string-name>Li, C.</string-name>
              <string-name>Wang, H.</string-name>
              <string-name>Tang, X.</string-name>
              <string-name>Zhao, J.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>FedMDFG: Federated Learning with Multi-Gradient Descent and Fair Guidance</article-title>
            <source>Proceedings of the AAAI Conference on Artificial Intelligence</source>
            <volume>37</volume>
            <pub-id pub-id-type="doi">10.1609/aaai.v37i8.26122</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B56">
        <label>56.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Mehrabi, N., Morstatter, F., Saxena, N., Lerman, K. and Galstyan, A. (2021) A Survey on Bias and Fairness in Machine Learning. <italic>ACM Computing Surveys</italic>, 54, 1-35. https://doi.org/10.1145/3457607 <pub-id pub-id-type="doi">10.1145/3457607</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1145/3457607">https://doi.org/10.1145/3457607</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Mehrabi, N.</string-name>
              <string-name>Morstatter, F.</string-name>
              <string-name>Saxena, N.</string-name>
              <string-name>Lerman, K.</string-name>
              <string-name>Galstyan, A.</string-name>
            </person-group>
            <year>2021</year>
            <article-title>A Survey on Bias and Fairness in Machine Learning</article-title>
            <source>ACM Computing Surveys</source>
            <volume>54</volume>
            <pub-id pub-id-type="doi">10.1145/3457607</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B57">
        <label>57.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Mukhtiar, N., Mahmood, A. and Sheng, Q.Z. (2025) Fairness in Federated Learning: Trends, Challenges, and Opportunities. <italic>Advanced Intelligent Systems</italic>, 7, Article 2400836. https://doi.org/10.1002/aisy.202400836 <pub-id pub-id-type="doi">10.1002/aisy.202400836</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1002/aisy.202400836">https://doi.org/10.1002/aisy.202400836</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Mukhtiar, N.</string-name>
              <string-name>Mahmood, A.</string-name>
              <string-name>Sheng, Q.Z.</string-name>
              <string-name>Trends, C</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Fairness in Federated Learning: Trends, Challenges, and Opportunities</article-title>
            <source>Advanced Intelligent Systems</source>
            <volume>7</volume>
            <elocation-id>2400836</elocation-id>
            <pub-id pub-id-type="doi">10.1002/aisy.202400836</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B58">
        <label>58.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Taik, A., Chehbouni, K. and Farnadi, G. (2025) Fairness in Federated Learning: Fairness for Whom? <italic>Proceedings of the AAAI</italic>/ <italic>ACM Conference on AI</italic>, <italic>Ethics</italic>, <italic>and Society</italic>, 8, 2456-2469. https://doi.org/10.1609/aies.v8i3.36730 <pub-id pub-id-type="doi">10.1609/aies.v8i3.36730</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1609/aies.v8i3.36730">https://doi.org/10.1609/aies.v8i3.36730</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Taik, A.</string-name>
              <string-name>Chehbouni, K.</string-name>
              <string-name>Farnadi, G.</string-name>
              <string-name>AI, E</string-name>
            </person-group>
            <year>2025</year>
            <article-title>Fairness in Federated Learning: Fairness for Whom? Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society, 8, 2456-2469</article-title>
            <pub-id pub-id-type="doi">10.1609/aies.v8i3.36730</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B59">
        <label>59.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Abay, A., Zhou, Y., Baracaldo, N., Rajamoni, S., Chuba, E. and Ludwig, H. (2020) Mitigating Bias in Federated Learning. arXiv:2012.02447.</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Abay, A.</string-name>
              <string-name>Zhou, Y.</string-name>
              <string-name>Baracaldo, N.</string-name>
              <string-name>Rajamoni, S.</string-name>
              <string-name>Chuba, E.</string-name>
              <string-name>Ludwig, H.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Mitigating Bias in Federated Learning</article-title>
            <fpage>2012</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B60">
        <label>60.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Lo, S.K., Lu, Q., Paik, H. and Zhu, L. (2021) FLRA: A Reference Architecture for Federated Learning Systems. In: Biffl, S., Navarro, E., Löwe, W., Sirjani, M., Mirandola, R. and Weyns, D., Eds., <italic>Lecture Notes in Computer Science</italic>, Springer International Publishing, 83-98. https://doi.org/10.1007/978-3-030-86044-8_6 <pub-id pub-id-type="doi">10.1007/978-3-030-86044-8_6</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1007/978-3-030-86044-8_6">https://doi.org/10.1007/978-3-030-86044-8_6</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Lo, S.K.</string-name>
              <string-name>Lu, Q.</string-name>
              <string-name>Paik, H.</string-name>
              <string-name>Zhu, L.</string-name>
              <string-name>Biffl, S.</string-name>
              <string-name>Navarro, E.</string-name>
              <string-name>Sirjani, M.</string-name>
              <string-name>Mirandola, R.</string-name>
              <string-name>Weyns, D.</string-name>
              <string-name>Science, S</string-name>
            </person-group>
            <year>2021</year>
            <article-title>FLRA: A Reference Architecture for Federated Learning Systems</article-title>
            <source>In: Biffl</source>
            <volume>83</volume>
            <pub-id pub-id-type="doi">10.1007/978-3-030-86044-8_6</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B61">
        <label>61.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Lo, S.K., Lu, Q., Zhu, L., Paik, H., Xu, X. and Wang, C. (2021) Architectural Patterns for the Design of Federated Learning Systems. arXiv:2101.02373. http://arxiv.org/abs/2101.02373</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Lo, S.K.</string-name>
              <string-name>Lu, Q.</string-name>
              <string-name>Zhu, L.</string-name>
              <string-name>Paik, H.</string-name>
              <string-name>Xu, X.</string-name>
              <string-name>Wang, C.</string-name>
            </person-group>
            <year>2021</year>
            <article-title>Architectural Patterns for the Design of Federated Learning Systems</article-title>
            <fpage>2101</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B62">
        <label>62.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Gabrielli, E., Pica, G. and Tolomei, G. (2023) A Survey on Decentralized Federated Learning. arXiv:2308.04604. http://arxiv.org/abs/2308.04604</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Gabrielli, E.</string-name>
              <string-name>Pica, G.</string-name>
              <string-name>Tolomei, G.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>A Survey on Decentralized Federated Learning</article-title>
            <fpage>2308</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B63">
        <label>63.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Hallaji, E., Razavi-Far, R., Saif, M., Wang, B. and Yang, Q. (2024) Decentralized Federated Learning: A Survey on Security and Privacy. <italic>IEEE Transactions on Big Data</italic>, 10, 194-213. https://doi.org/10.1109/tbdata.2024.3362191 <pub-id pub-id-type="doi">10.1109/tbdata.2024.3362191</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/tbdata.2024.3362191">https://doi.org/10.1109/tbdata.2024.3362191</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Hallaji, E.</string-name>
              <string-name>Razavi-Far, R.</string-name>
              <string-name>Saif, M.</string-name>
              <string-name>Wang, B.</string-name>
              <string-name>Yang, Q.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Decentralized Federated Learning: A Survey on Security and Privacy</article-title>
            <source>IEEE Transactions on Big Data</source>
            <volume>10</volume>
            <pub-id pub-id-type="doi">10.1109/tbdata.2024.3362191</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B64">
        <label>64.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">De Lacour, D., Lacoste, M., Südholt, M. and Traoré, J. (2023) Towards Scalable Resilient Federated Learning: A Fully Decentralised Approach. 2023 <italic>IEEE International Conference on Pervasive Computing and Communications Workshops and Other Affiliated Events</italic>( <italic>PerCom</italic><italic>Workshops</italic>), Atlanta, 13-17 March 2023, 621-627. https://doi.org/10.1109/percomworkshops56833.2023.10150295 <pub-id pub-id-type="doi">10.1109/percomworkshops56833.2023.10150295</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/percomworkshops56833.2023.10150295">https://doi.org/10.1109/percomworkshops56833.2023.10150295</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Lacour, D.</string-name>
              <string-name>Lacoste, M.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Towards Scalable Resilient Federated Learning: A Fully Decentralised Approach</article-title>
            <source>2023 IEEE International Conference on Pervasive Computing and Communications Workshops and Other Affiliated Events (PerCom Workshops)</source>
            <volume>13</volume>
            <pub-id pub-id-type="doi">10.1109/percomworkshops56833.2023.10150295</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B65">
        <label>65.</label>
        <citation-alternatives>
          <mixed-citation publication-type="confproc">Ekmefjord, M., Ait-Mlouk, A., Alawadi, S., Akesson, M., Singh, P., Spjuth, O., <italic>et al</italic>. (2022) Scalable Federated Machine Learning with FEDn. 2022 22 <italic>nd IEEE International Symposium on Cluster</italic>, <italic>Cloud and Internet Computing</italic> ( <italic>CCGrid</italic>), Taormina, 16-19 May 2022, 555-564. https://doi.org/10.1109/ccgrid54584.2022.00065 <pub-id pub-id-type="doi">10.1109/ccgrid54584.2022.00065</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/ccgrid54584.2022.00065">https://doi.org/10.1109/ccgrid54584.2022.00065</ext-link></mixed-citation>
          <element-citation publication-type="confproc">
            <person-group person-group-type="author">
              <string-name>Ekmefjord, M.</string-name>
              <string-name>Ait-Mlouk, A.</string-name>
              <string-name>Alawadi, S.</string-name>
              <string-name>Akesson, M.</string-name>
              <string-name>Singh, P.</string-name>
              <string-name>Spjuth, O.</string-name>
              <string-name>Cluster, C</string-name>
            </person-group>
            <year>2022</year>
            <article-title>Scalable Federated Machine Learning with FEDn</article-title>
            <source>2022 22nd IEEE International Symposium on Cluster</source>
            <volume>16</volume>
            <pub-id pub-id-type="doi">10.1109/ccgrid54584.2022.00065</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B66">
        <label>66.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Brauneck, A., Schmalhorst, L., Kazemi Majdabadi, M.M., Bakhtiari, M., Völker, U., Baumbach, J., <italic>et al</italic>. (2023) Federated Machine Learning, Privacy-Enhancing Technologies, and Data Protection Laws in Medical Research: Scoping Review. <italic>Journal of Medical Internet Research</italic>, 25, e41588. https://doi.org/10.2196/41588 <pub-id pub-id-type="doi">10.2196/41588</pub-id><pub-id pub-id-type="pmid">36995759</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.2196/41588">https://doi.org/10.2196/41588</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Brauneck, A.</string-name>
              <string-name>Schmalhorst, L.</string-name>
              <string-name>Majdabadi, M.M.</string-name>
              <string-name>Bakhtiari, M.</string-name>
              <string-name>Baumbach, J.</string-name>
              <string-name>Learning, P</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Federated Machine Learning, Privacy-Enhancing Technologies, and Data Protection Laws in Medical Research: Scoping Review</article-title>
            <source>Journal of Medical Internet Research</source>
            <volume>25</volume>
            <pub-id pub-id-type="doi">10.2196/41588</pub-id>
            <pub-id pub-id-type="pmid">36995759</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B67">
        <label>67.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Aouedi, O., Sacco, A., Piamrat, K. and Marchetto, G. (2023) Handling Privacy-Sensitive Medical Data with Federated Learning: Challenges and Future Directions. <italic>IEEE Journal of Biomedical and Health Informatics</italic>, 27, 790-803. https://doi.org/10.1109/jbhi.2022.3185673 <pub-id pub-id-type="doi">10.1109/jbhi.2022.3185673</pub-id><pub-id pub-id-type="pmid">35737624</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/jbhi.2022.3185673">https://doi.org/10.1109/jbhi.2022.3185673</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Aouedi, O.</string-name>
              <string-name>Sacco, A.</string-name>
              <string-name>Piamrat, K.</string-name>
              <string-name>Marchetto, G.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Handling Privacy-Sensitive Medical Data with Federated Learning: Challenges and Future Directions</article-title>
            <source>IEEE Journal of Biomedical and Health Informatics</source>
            <volume>27</volume>
            <pub-id pub-id-type="doi">10.1109/jbhi.2022.3185673</pub-id>
            <pub-id pub-id-type="pmid">35737624</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B68">
        <label>68.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Teo, Z.L., Jin, L., Liu, N., Li, S., Miao, D., Zhang, X., <italic>et al</italic>. (2024) Federated Machine Learning in Healthcare: A Systematic Review on Clinical Applications and Technical Architecture. <italic>Cell Reports Medicine</italic>, 5, Article 101419. https://doi.org/10.1016/j.xcrm.2024.101419 <pub-id pub-id-type="doi">10.1016/j.xcrm.2024.101419</pub-id><pub-id pub-id-type="pmid">38340728</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.xcrm.2024.101419">https://doi.org/10.1016/j.xcrm.2024.101419</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Teo, Z.L.</string-name>
              <string-name>Jin, L.</string-name>
              <string-name>Liu, N.</string-name>
              <string-name>Li, S.</string-name>
              <string-name>Miao, D.</string-name>
              <string-name>Zhang, X.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Federated Machine Learning in Healthcare: A Systematic Review on Clinical Applications and Technical Architecture</article-title>
            <source>Cell Reports Medicine</source>
            <volume>5</volume>
            <elocation-id>101419</elocation-id>
            <pub-id pub-id-type="doi">10.1016/j.xcrm.2024.101419</pub-id>
            <pub-id pub-id-type="pmid">38340728</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B69">
        <label>69.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Stripelis, D., Gupta, U., Saleem, H., Dhinagar, N., Ghai, T., Anastasiou, C., <italic>et al</italic>. (2024) A Federated Learning Architecture for Secure and Private Neuroimaging Analysis. <italic>Patterns</italic>, 5, Article 101031. https://doi.org/10.1016/j.patter.2024.101031 <pub-id pub-id-type="doi">10.1016/j.patter.2024.101031</pub-id><pub-id pub-id-type="pmid">39233693</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.patter.2024.101031">https://doi.org/10.1016/j.patter.2024.101031</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Stripelis, D.</string-name>
              <string-name>Gupta, U.</string-name>
              <string-name>Saleem, H.</string-name>
              <string-name>Dhinagar, N.</string-name>
              <string-name>Ghai, T.</string-name>
              <string-name>Anastasiou, C.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>A Federated Learning Architecture for Secure and Private Neuroimaging Analysis</article-title>
            <source>Patterns</source>
            <volume>5</volume>
            <elocation-id>101031</elocation-id>
            <pub-id pub-id-type="doi">10.1016/j.patter.2024.101031</pub-id>
            <pub-id pub-id-type="pmid">39233693</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B70">
        <label>70.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Rachakonda, S., Moorthy, S., Jain, A., Bukharev, A., Bucur, A., Manni, F., <italic>et al</italic>. (2023) Privacy Enhancing and Scalable Federated Learning to Accelerate AI Implementation in Cross-Silo and IoMT Environments. <italic>IEEE Journal of Biomedical and Health Informatics</italic>, 27, 744-755. https://doi.org/10.1109/jbhi.2022.3185418 <pub-id pub-id-type="doi">10.1109/jbhi.2022.3185418</pub-id><pub-id pub-id-type="pmid">35731757</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1109/jbhi.2022.3185418">https://doi.org/10.1109/jbhi.2022.3185418</ext-link></mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Rachakonda, S.</string-name>
              <string-name>Moorthy, S.</string-name>
              <string-name>Jain, A.</string-name>
              <string-name>Bukharev, A.</string-name>
              <string-name>Bucur, A.</string-name>
              <string-name>Manni, F.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Privacy Enhancing and Scalable Federated Learning to Accelerate AI Implementation in Cross-Silo and IoMT Environments</article-title>
            <source>IEEE Journal of Biomedical and Health Informatics</source>
            <volume>27</volume>
            <pub-id pub-id-type="doi">10.1109/jbhi.2022.3185418</pub-id>
            <pub-id pub-id-type="pmid">35731757</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B71">
        <label>71.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Pati, S., Kumar, S., Varma, A., Edwards, B., Lu, C., Qu, L., <italic>et al</italic>. (2024) Privacy Preservation for Federated Learning in Health Care. <italic>Patterns</italic>, 5, Article 100974. https://doi.org/10.1016/j.patter.2024.100974 <pub-id pub-id-type="doi">10.1016/j.patter.2024.100974</pub-id><pub-id pub-id-type="pmid">39081567</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1016/j.patter.2024.100974">https://doi.org/10.1016/j.patter.2024.100974</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Pati, S.</string-name>
              <string-name>Kumar, S.</string-name>
              <string-name>Varma, A.</string-name>
              <string-name>Edwards, B.</string-name>
              <string-name>Lu, C.</string-name>
              <string-name>Qu, L.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>Privacy Preservation for Federated Learning in Health Care</article-title>
            <source>Patterns</source>
            <volume>5</volume>
            <elocation-id>100974</elocation-id>
            <pub-id pub-id-type="doi">10.1016/j.patter.2024.100974</pub-id>
            <pub-id pub-id-type="pmid">39081567</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B72">
        <label>72.</label>
        <citation-alternatives>
          <mixed-citation publication-type="journal">Choudhury, O., Gkoulalas-Divanis, A., Salonidis, T., Sylla, I., Park, Y., Hsu, G. and Das, A. (2020) Anonymizing Data for Privacy-Preserving Federated Learning. arXiv:2002.09096. http://arxiv.org/abs/2002.09096</mixed-citation>
          <element-citation publication-type="journal">
            <person-group person-group-type="author">
              <string-name>Choudhury, O.</string-name>
              <string-name>Gkoulalas-Divanis, A.</string-name>
              <string-name>Salonidis, T.</string-name>
              <string-name>Sylla, I.</string-name>
              <string-name>Park, Y.</string-name>
              <string-name>Hsu, G.</string-name>
              <string-name>Das, A.</string-name>
            </person-group>
            <year>2020</year>
            <article-title>Anonymizing Data for Privacy-Preserving Federated Learning</article-title>
            <fpage>2002</fpage>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B73">
        <label>73.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Olatunji, I.E., Rauch, J., Katzensteiner, M. and Khosla, M. (2024) A Review of Anonymization for Healthcare Data. <italic>Big Data</italic>, 12, 538-555. https://doi.org/10.1089/big.2021.0169 <pub-id pub-id-type="doi">10.1089/big.2021.0169</pub-id><pub-id pub-id-type="pmid">35271377</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.1089/big.2021.0169">https://doi.org/10.1089/big.2021.0169</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Olatunji, I.E.</string-name>
              <string-name>Rauch, J.</string-name>
              <string-name>Katzensteiner, M.</string-name>
              <string-name>Khosla, M.</string-name>
            </person-group>
            <year>2024</year>
            <article-title>A Review of Anonymization for Healthcare Data</article-title>
            <source>Big Data</source>
            <volume>12</volume>
            <pub-id pub-id-type="doi">10.1089/big.2021.0169</pub-id>
            <pub-id pub-id-type="pmid">35271377</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
      <ref id="B74">
        <label>74.</label>
        <citation-alternatives>
          <mixed-citation publication-type="other">Liu, T., Wang, Z., He, H., Shi, W., Lin, L., An, R., <italic>et al</italic>. (2023) Efficient and Secure Federated Learning for Financial Applications. <italic>Applied Sciences</italic>, 13, Article 5877. https://doi.org/10.3390/app13105877 <pub-id pub-id-type="doi">10.3390/app13105877</pub-id><ext-link ext-link-type="uri" xlink:href="https://doi.org/10.3390/app13105877">https://doi.org/10.3390/app13105877</ext-link></mixed-citation>
          <element-citation publication-type="other">
            <person-group person-group-type="author">
              <string-name>Liu, T.</string-name>
              <string-name>Wang, Z.</string-name>
              <string-name>He, H.</string-name>
              <string-name>Shi, W.</string-name>
              <string-name>Lin, L.</string-name>
              <string-name>An, R.</string-name>
            </person-group>
            <year>2023</year>
            <article-title>Efficient and Secure Federated Learning for Financial Applications</article-title>
            <source>Applied Sciences</source>
            <volume>13</volume>
            <elocation-id>5877</elocation-id>
            <pub-id pub-id-type="doi">10.3390/app13105877</pub-id>
          </element-citation>
        </citation-alternatives>
      </ref>
    </ref-list>
  </back>
</article>