Research map / Federated learning and privacy
Differential privacy: research map
774 accepted papers on Differential privacy in Federated learning and privacy, from ICML, NeurIPS, ICLR, CVPR and AAAI (2016–2026), grouped into 2 clusters and 9 approaches. The busiest year so far is 2026.
Within Federated learning and privacy, its share held steady from 28.9% in 2023–24 to 29.1% in 2025–26 (215 → 266 papers at ICML, NeurIPS, CVPR and AAAI, the venues with data for all four years).
Explore Differential privacy in the interactive map
Working on something in this topic? Describe your idea in scime atlas to see which approach it falls under, the closest papers by meaning and how crowded the spot has become.
Approaches and key papers
estimation · error · algorithms · 502 papers
Approaches in this cluster:
- Privacy accounting and mechanisms (127 papers)
Develop tighter composition bounds and noise mechanisms for differential privacy. - Private online and user-level learning (116 papers)
Analyze private learning in online, shuffle and user-level settings. - Local-DP and private estimation (113 papers)
Estimate means and statistics under local or central privacy with minimax rates. - Private data analysis frameworks (105 papers)
Design private release, counting and sensitivity-bounding methods for data analysis. - Differentially private clustering (41 papers)
Give approximation algorithms for private k-means and clustering.
Most cited and most cited since 2024:
- Scalable Private Learning with PATE (ICLR 2018 · 313 citations)
- Collecting Telemetry Data Privately (NeurIPS 2017 · 262 citations)
- Prior-itizing Privacy: A Bayesian Approach to Setting the Privacy Budget in Differential Privacy (NeurIPS 2024 · 9 citations)
- One-shot Empirical Privacy Estimation for Federated Learning (ICLR 2024 · 5 citations)
dp sgd · gradient · clipping · 272 papers
Approaches in this cluster:
- Private training with public data (96 papers)
Reduce accuracy loss of differentially private models with public data, finetuning and new mechanisms. - Differentially private synthetic data (81 papers)
Generate private synthetic data or text and in-context examples under differential privacy. - DP-SGD refinements (60 papers)
Make private stochastic gradient descent cheaper and more practical, without sampling or at scale. - Differentially private federated learning (35 papers)
Apply clipping and noise in federated learning with client-level privacy.
Most cited and most cited since 2024:
- Learning Differentially Private Recurrent Language Models (ICLR 2018 · 743 citations)
- PATE-GAN: Generating Synthetic Data with Differential Privacy Guarantees (ICLR 2019 · 278 citations)
- DP-AdamBC: Your DP-Adam Is Actually DP-SGD (Unless You Apply Bias Correction) (AAAI 2024 · 12 citations)
- Position: Considerations for Differentially Private Learning with Large-Scale Public Pretraining (ICML 2024 · 9 citations)
