“…Geyer et al [65] first applied DP under Gaussian Mechanism to federated learning to preserve clients' level privacy. While they only achieved 78%,92%, and 96% accuracy with ( , m, n) = (8, 11, 100), (8,54,1000), (8,12,10, 000) on MNIST with differential privacy, where ( , m, n) represented the privacy budget, communication rounds, and clients number, respectively. LDP was first exploited for federated learning by Bhowmick et al [66].…”