Adversarial Training and Differential Privacy-Style Noise Injection for Privacy-Preserving Vertical Federated Learning
Abstract
1. Introduction
1.1. Problem Statement
1.2. Objectives of the Study
- To analyze the vulnerabilities of standard VFL systems to both adversarial attacks and label inference attacks.
- To show how adversarial training (AT) improves adversarial robustness but measurably weakens label privacy, quantifying this trade-off across modalities.
- To introduce a differential-privacy-style calibrated noise stage that restores the label privacy weakened by AT without sacrificing the robustness gains.
- To demonstrate empirically, across five datasets spanning three modalities, that adversarial robustness and label privacy are complementary rather than competing objectives in VFL environments.
2. Related Works
2.1. Vertical Federated Learning
2.2. Challenges in the VFL Environment
2.3. Label Inference Attacks in VFL
2.4. Adversarial Machine Learning and Adaptive Defenses
2.5. Review of Related Works
2.5.1. Privacy and Label Inference Defenses in VFL
2.5.2. Adversarial Robustness Techniques in VFL
2.5.3. Property-Level and Other Threats
3. Methodology
3.1. Framework for the Improved Defense Mechanism
3.2. Dataset Description and Preprocessing
3.2.1. Vision Datasets
3.2.2. Textual Dataset
3.2.3. Tabular Dataset
3.3. Model Architecture Design
3.3.1. Training Strategy
3.3.2. Training Loop for VFL
- Forward Pass: The active and passive parties both process their local inputs and produce embeddings through their respective bottom models.
- Fusion and Prediction: The embeddings are collected and concatenated, then passed to the top model to generate global logits.
- Backward Pass: The gradients of the global loss are backpropagated to each party to update their local parameter.
3.3.3. Knowledge Distillation + -Anonymity (KD)
| Algorithm 1. KD (Knowledge Distillation + -Anonymity, Student Training). |
| Input: Training data D_train, Test data D_test, Teacher_Soft_Labels Output: Trained student model M_student, Accuracy ACC_KDk 1. Initialize Model: ) 2. For each epoch in EPOCHS do: For each batch in D_train do: a. Student forward pass: b. Teacher forward pass (frozen): c. Apply temperature scaling: d. Apply -anonymity: e. Compute KD loss = f. Compute CE loss = g. Total loss = h. Backpropagate and update student parameters 3. Evaluate M_student on D_test to compute ACC_KDk 4. Save trained M_student 5. Return M_student, ACC_KDk |
3.3.4. Adversarial Training (KD + AT)
- Vision datasets: The adversarial examples were crafted using the fast gradient sign method (FGSM) calculated as , where represents the magnitude of the perturbation set to .
- Textual datasets: A normalized gradient ascent was used for feature vectors, with the perturbation calculated as , with set to 0.1 and 0.05 for Criteo and Yahoo! Answers, respectively.
| Algorithm 2. KD+AT Implementation |
| Input: D_train, D_test, Teacher model M_teacher, Parameters Output: Trained adversarial student model M_AT, Accuracy ACC_KDk_AT 1. Initialize model 2. For each epoch in EPOCHS do: For each batch (x, y) in D_train do: Generate adversarial examples: i. Compute gradient g = ii. Perturb input: b. Forward pass with x_adv: s_logits = M_AT(x_adv) c. Teacher forward pass: d. Apply temperature scaling + k-anonymity: t_soft_k e. Compute KD loss = f. Compute CE loss = CrossEntropy(s_logits, y) g. Total loss = h. Backpropagate and update student parameters 3. Evaluate M_AT on D_test to compute ACC_KDk_AT 4. Save trained M_AT Return M_AT, ACC_KDk_AT |
3.3.5. Differential Privacy
| Algorithm 3. KD+AT with Differential Privacy |
| Input: D_train, D_test, Teacher model M_teacher, Parameters (T, k, λ, ε, noise_multiplier) Output: Trained private student model M_DP, Accuracy ACC_KDk_AT_DP
|
3.3.6. Training Objectives for the Pipeline
3.4. Evaluation Metrics
- Top-1 Accuracy: A metric is used to determine the frequency with which a model predicts the correct label. It is the ratio of correct sample predictions to the total number of samples in a dataset. An interpretation summary of the metrics is presented later in Table 5 for clarity.
- Top-5 Accuracy: This is used to indicate the number of times a correct label shows up in the top 5 predicted classes of a model. It was included particularly for the CIFAR-100 dataset due to its large number of classes.
- F1-Score and AUC: These provide a balanced model performance evaluation for binary tabular and multi-class text datasets.
- Robust Accuracy: This is measured as the ratio of resilience to perturbation. It is the accuracy of the model in the face of adversarial attack.
- Attack Success Rate (Top-1 ASR, Top-5 ASR): This is used to determine the level of privacy leakage by measuring the accuracy of a label inference attempt on a model.
- Privacy Leakage Index: This is a composite metric used for observing privacy–utility balance during model performance evaluation.
4. Experiments
4.1. Analysis of the Vision Datasets
4.2. Analysis of the Textual Dataset
4.3. Analysis of the Tabular Dataset
4.4. Summary of Results
4.4.1. Model Utility
4.4.2. Adversarial Robustness
| Dataset | Stage | Communication/Epoch | Time/Epoch (Measured) |
|---|---|---|---|
| Yahoo! Answers | OA | 204.7 MB | 6.3 s |
| KD | 204.7 MB | 5.7 s | |
| KD+AT | 204.7 MB | 8.6 s | |
| KD+AT+DP | 204.7 MB | 8.8 s | |
| Criteo CTR | OA | 41.0 MB | 7.6 s |
| KD | 41.0 MB | 8.2 s | |
| KD+AT | 41.0 MB | 11.0 s | |
| KD+AT+DP | 41.0 MB | 11.3 s | |
| CIFAR-10 | All stages | 51.2 MB | Not retained |
| CIFAR-100 | All stages | 51.2 MB | Not retained |
| CINIC-10 | All stages | 184.3 MB | Not retained |
4.4.3. Label Privacy
4.4.4. Training Stability
4.4.5. Broader Implications
5. Conclusions
5.1. Recommendations
- Privacy-preserving VFL implementations should embrace adaptive noise control mechanisms to ensure noise variance scales as gradient sensitivity increases.
- The availability of benchmark datasets and standardized scripts for threat model evaluations would aid reproducibility across the research community. This will be helpful in accelerating the progress made towards achieving privacy-preserving FL at scale.
- Finance, healthcare, marketing and other domains holding sensitive user information should embrace multi-stage defense mechanisms for an added layer of security. The organizations should also embrace integrating training-based defense mechanisms with homomorphic masking techniques.
5.2. Future Work
Author Contributions
Funding
Data Availability Statement
Conflicts of Interest
References
- Menard, P.; Bott, G.J. Artificial Intelligence Misuse and Concern for Information Privacy: New Construct Validation and Future Directions. Inf. Syst. J. 2025, 35, 322–367. [Google Scholar]
- Ajagbe, S.A.; Awotunde, J.B.; Florez, H. Ensuring Intrusion Detection for IoT Services Through an Improved CNN. SN Comput. Sci. 2024, 5, 49. [Google Scholar] [CrossRef] [Scilit]
- Taiwo, G.; Vadera, S.; Alameer, A. Vision Transformers for Automated Detection of Pig Interactions in Groups. Smart Agric. Technol. 2025, 10, 100774. [Google Scholar] [CrossRef] [Scilit]
- Wieringa, J.; Kannan, P.K.; Ma, X.; Reutterer, T.; Risselada, H.; Skiera, B. Data Analytics in a Privacy-Concerned World. J. Bus. Res. 2021, 122, 915–925. [Google Scholar] [CrossRef] [Scilit]
- Fu, A.; Zhang, J.; Yang, Q. Label Inference Attacks Against Vertical Federated Learning. IEEE Trans. Inf. Forensics Secur. 2022, 17, 1162–1174. [Google Scholar] [CrossRef] [Scilit]
- Kairouz, P.; McMahan, H.B.; Avent, B.; Bellet, A.; Bennis, M.; Bhagoji, A.N.; Bonawitz, K.; Charles, Z.; Cormode, G.; Cummings, R.; et al. Advances and Open Problems in Federated Learning. Found. Trends Mach. Learn. 2021, 14, 1–210. [Google Scholar] [CrossRef] [Scilit]
- Niknam, S.; Dhillon, H.S.; Reed, J.H. Federated Learning for Wireless Communications: Motivation, Opportunities, and Challenges. IEEE Commun. Mag. 2020, 58, 46–51. [Google Scholar] [CrossRef] [Scilit]
- McMahan, H.B.; Moore, E.; Ramage, D.; Hampson, S.; Arcas, B.A. Communication-Efficient Learning of Deep Networks from Decentralized Data. In Proceedings of the 20th International Conference on Artificial Intelligence and Statistics; PMLR: London, UK, 2017; pp. 1273–1282. Available online: https://proceedings.mlr.press/v54/mcmahan17a.html (accessed on 5 August 2025).
- Adeniyi, J.K.; Ajagbe, S.A.; Adeniyi, E.A.; Mudali, P.; Adigun, M.O.; Adeniyi, T.T.; Ajibola, O. A Biometrics-Generated Private/Public Key Cryptography for a Blockchain-Based E-Voting System. Egypt. Inform. J. 2024, 25, 100447. [Google Scholar] [CrossRef] [Scilit]
- Chakraborty, A.; Dahal, C.; Gupta, V. Federated Retrieval-Augmented Generation: A Systematic Mapping Study. arXiv 2025, arXiv:2505.18906v1. [Google Scholar]
- Khan, A.; Thij, M.; Wilbik, A. Vertical Federated Learning: A Structured Literature Review. Knowl. Inf. Syst. 2025, 67, 3205–3243. [Google Scholar] [CrossRef] [Scilit]
- Arazzi, M.; Nicolazzo, S.; Nocera, A. A Defense Mechanism against Label Inference Attacks in Vertical Federated Learning. Neurocomputing 2025, 624, 129476. [Google Scholar] [CrossRef] [Scilit]
- Liu, Y.; Zou, T.; Kang, Y.; Liu, W.; He, Y.; Yi, Z.; Yang, Q. Batch Label Inference and Replacement Attacks in Black-Boxed Vertical Federated Learning. arXiv 2022, arXiv:2112.05409. [Google Scholar]
- Xu, J.; Zhang, Z.; Hu, R. Achieving Byzantine-Resilient Federated Learning via Layer-Adaptive Sparsified Model Aggregation. In Proceedings of the 2025 IEEE/CVF Winter Conference on Applications of Computer Vision (WACV), Tucson, AZ, USA, 26 February–6 March 2025; pp. 1508–1517. [Google Scholar]
- Aono, Y.; Hayashi, T.; Wang, L.; Moriai, S. Privacy-Preserving Deep Learning via Additively Homomorphic Encryption. IEEE Trans. Inf. Forensics Secur. 2017, 13, 1333–1345. [Google Scholar]
- Ye, M.; Shen, W.; Du, B.; Snezhko, E.; Kovalev, V.; Yuen, P.C. Vertical Federated Learning for Effectiveness, Security, Applicability: A Survey. arXiv 2024, arXiv:2405.17495. [Google Scholar]
- Luo, X.; Wu, Y.; Xiao, X.; Ooi, B.C. Feature Inference Attack on Model Predictions in Vertical Federated Learning. In Proceedings of the 37th International Conference on Data Engineering (ICDE), Chania, Greece, 19–22 April 2021; pp. 181–192. [Google Scholar]
- Wei, K.; Li, J.; Ma, C.; Ding, M.; Wei, S.; Wu, F.; Chen, G.; Ranbaduge, T. Vertical Federated Learning: Challenges, Methodologies and Experiments. arXiv 2022, arXiv:2202.04309. [Google Scholar]
- Al Farsi, A.; Khan, A.; Mughal, M.R.; Bait-Suwailam, M.M. Privacy and Security Challenges in Federated Learning for UAV Systems: A Systematic Review. IEEE Access 2025, 13, 86599–86615. [Google Scholar] [CrossRef] [Scilit]
- Hu, K.; Gong, S.; Zhang, Q.; Seng, C.; Xia, M.; Jiang, S. An Overview of Implementing Security and Privacy in Federated Learning. Artif. Intell. Rev. 2024, 57, 204. [Google Scholar] [CrossRef] [Scilit]
- Azeez, N.A.; Malomo, O.S.; Aaron, D.S.; Ademoye, A.A.; Okerinde, O.M.; Otolehi, U.D.; Lukman, O.O. Artificial Intelligence in Cybersecurity: A Comparative Review of Its Role across the Cyber Kill Chain. Univ. Ib. J. Sci. Log. ICT Res. 2025, 14, 153. [Google Scholar]
- Azeez, N.A.; Ademoye, A.A.; Malomo, O.S.; Okerinde OMAaron, D.S.; Vyver, C.V. Investigation of Augmented Datasets for Security in Internet of Medical Things (IoMT) Ecosystems. Computers 2026, 15, 369. [Google Scholar] [CrossRef] [Scilit]
- Finlayson, S.G.; Bowers, J.D.; Ito, J.; Zittrain, J.L.; Beam, A.L.; Kohane, I.S. Adversarial Attacks on Medical Machine Learning. Science 2019, 363, 1287–1289. [Google Scholar] [CrossRef] [Scilit] [PubMed]
- Azeez, N.A.; Adefemi, F.; Olayinka Fasina, E.P.; Venter, I.M. Evaluation of a Flexible Column-Based Access Control Security Model forMedical-Based Information. J. Comput. Sci. Its Appl. 2015, 22, 24–31. [Google Scholar]
- Zhan, P.; Yang, J.; Wang, H.; Zheng, C.; Wang, L. Rethinking Word-level Adversarial Attack: The Trade-off Between Efficiency, Effectiveness, and Imperceptibility. In Proceedings of the Joint International Conference on Computational Linguistics, Language Resources and Evaluation (LREC-COLING 2024), Torino, Italy, 20–25 May 2024; ELRA Language Resource Association: Paris, France, 2024; pp. 14037–14052. [Google Scholar]
- Jedrzejewski, F.V.; Thode, L.; Fischbach, J.; Gorschek, T.; Mendez, D.; Lavesson, N. Adversarial Machine Learning in Industry: A Systematic Literature Review. Comput. Secur. 2024, 145, 103988. [Google Scholar] [CrossRef] [Scilit]
- Azeez, N.A.; Venter, I.M. Towards ensuring scalability, interoperability and efficient access control in a multi-domain grid-based environment. Afr. Res. J. 2013, 104. [Google Scholar] [CrossRef] [Scilit]
- Yan, Z.; Yao, Y.; Wen, X.; Zhang, J.; Fan, K. LADSG: Label-Anonymized Distillation and Similar Gradient Substitution for Label Privacy in Vertical Federated Learning. arXiv 2025, arXiv:2506.06742. [Google Scholar]
- Wang, Y.; Lv, Q.; Zhang, H.; Zhao, M.; Sun, Y.; Ran, L.; Li, T. Beyond Model Splitting: Preventing Label Inference Attacks in Vertical Federated Learning with Dispersed Training. World Wide Web 2023, 26, 2691–2707. [Google Scholar] [CrossRef] [Scilit]
- Azeez, N.A.; Iliyas, H.D. Implementation of a 4-tier Cloud-Based Architecture for Collaborative Health Care Delivery. Niger. J. Technol. Dev. 2016, 13, 17–25. [Google Scholar] [CrossRef] [Scilit]
- Ding, L.; Bao, H.; Lv, Q.; Zhang, F.; Zhang, Z.; Han, J.; Ding, S. Threshold Filtering for Detecting Label Inference Attacks in Vertical Federated Learning. Electronics 2024, 13, 4376. [Google Scholar] [CrossRef] [Scilit]
- Bai, L.; Zhang, X.; Zhang, S.; Ye, Q.; Hu, H. ProVFL: Property Inference Attacks against Vertical Federated Learning. IEEE Trans. Inf. Forensics Secur. 2025, 20, 6529–6543. [Google Scholar] [CrossRef] [Scilit]
- Azeez, N.A.; Tajudeen, A. A Survey On Categorization of Threat Intelligence and Trust-Based Sharing Strategies on Cyber Attack. Vokasi Unesa Bull. Eng. Technol. Appl. Sci. 2025, 2, 128–143. [Google Scholar] [CrossRef] [Scilit]







| Method | Privacy Defense | Robustness Defense | Guarantee | Modalities Evaluated | LIA Types |
|---|---|---|---|---|---|
| DP baseline | Yes | No | Formal (ε) | Single | Passive |
| KDk [12] | Yes | No | Empirical | Vision | Passive/Direct |
| LADSG [28] | Yes | No | Empirical | Tabular/Text | Passive/Active/Direct |
| Dispersed training [29] | Yes | No | Empirical | Vision | Passive |
| ProVFL | No | No | No | Vision | Property inference |
| This work | Yes | Yes | Empirical | Tabular/Text/Vision | Passive/Active/Direct/Perturbed |
| Dataset | Domain | Size (Samples × Features) | Task Type | Evaluation Focus |
|---|---|---|---|---|
| CIFAR-10 | Image | 50,000 images 32 × 32 RGB) in 10 classes | Multiclass Classification | Baseline benchmark for adversarial robustness on simple vision tasks |
| CIFAR-100 | Image | 50,000 images 32 × 32 RGB) in 100 classes | Multiclass Classification | Stress-test robustness and distillation under high-granularity class |
| CINIC-10 | Image | 180,000 images 32 × 32 RGB in 10 classes | Multiclass Classification | Larger-scale benchmark bridging to validate generalization |
| Yahoo! Answers | Text | 50,000 5000 features across 10 classes | Textual/Natural Language Processing | Evaluation of the model on high-dimensional sparse text representations with semantic variability. |
| Criteo CTR | Tabular | 80,000 13 continuous 26 categorical features | Binary Classification | Assesses the generalization of the model on multi-modal data |
| Dataset | Bottom-Model Architecture | Top-Model Architecture |
|---|---|---|
| CIFAR-10 | Shallow VGG CNN | MLP (3-Layer) |
| CIFAR-100 | Shallow VGG CNN | MLP (3-Layer) |
| CINIC-10 | Shallow VGG CNN | MLP (3-Layer) |
| Yahoo! Answers | MLP (2-Layer) | MLP (2-Layer) |
| Criteo | Linear+ReLU | MLP (3-Layer) |
| Dataset | Mode | Party A |
|---|---|---|
| CIFAR-10 | Vision | 1 × 32 × 32 |
| CIFAR-100 | Vision | 1 × 32 × 32 |
| CINIC-10 | Vision | 1 × 32 × 32 |
| Yahoo! Answers | Text | 768 |
| Criteo CTR | Tabular | 6 |
| Model | Primary Goal | Defense Mechanism |
|---|---|---|
| OA | Implement the baseline performance and subsequent vulnerability reference | None—trained only on clean data |
| KD | Privacy-preservation mechanism against gradient-based label inference attacks | Knowledge distillation + data anonymization |
| KD+AT | Goes a step further by combining privacy-preserving measures and robustness against both gradient and perturbed LIAs | KD framework + FGSM-based adversarial training |
| KD+AT+DP | Recovers the privacy leakage caused by the introduction of AT | Differential-privacy-style noise injection |
| Model | Clean ACC | Robust ACC | Robustness Gap | F1-Score | AUC | Passive ASR | Direct ASR | Active ASR | PertASR | PLI |
|---|---|---|---|---|---|---|---|---|---|---|
| OA | 87.55 | 50.46 | 37.09 | 87.50 | 99.07 | 23.06 | 65.40 | 35.63 | 26.90 | 44.34 |
| KD | 87.59 | 60.72 | 26.87 | 87.51 | 99.05 | 25.58 | 56.41 | 39.91 | 19.03 | 51.59 |
| KD+AT | 86.39 | 84.64 | 1.75 | 86.34 | 98.93 | 40.38 | 34.04 | 43.39 | 10.01 | 58.41 |
| KD+AT+DP | 86.37 | 85.81 | 0.56 | 86.34 | 98.86 | 18.25 | 14.11 | 43.39 | 10.01 | 81.32 |
| Model | Clean ACC | Robust ACC | Robustness Gap | F1-Score | AUC | Passive ASR | Direct ASR | Active ASR | PertASR | PLI |
|---|---|---|---|---|---|---|---|---|---|---|
| OA | 63.74 | 39.71 | 24.03 | 63.58 | 98.69 | 4.75 | 9.07 | 20.57 | 14.73 | 59.34 |
| KD | 64.64 | 42.03 | 22.61 | 64.36 | 98.69 | 2.52 | 8.11 | 14.70 | 11.07 | 63.38 |
| KD+AT | 63.52 | 57.20 | 6.32 | 63.27 | 98.64 | 2.55 | 7.53 | 17.94 | 9.84 | 87.75 |
| KD+AT+DP | 60.09 | 59.41 | 0.68 | 59.82 | 98.34 | 2.52 | 6.77 | 12.38 | 9.84 | 96.08 |
| Model | Clean ACC | Robust ACC | Robustness Gap | F1-Score | AUC | Passive ASR | Direct ASR | Active ASR | PertASR | PLI |
|---|---|---|---|---|---|---|---|---|---|---|
| OA | 79.17 | 33.80 | 45.37 | 79.13 | 97.84 | 45.25 | 50.82 | 68.55 | 40.74 | 23.37 |
| KD | 79.51 | 43.09 | 36.42 | 79.46 | 97.94 | 26.72 | 40.11 | 35.72 | 21.06 | 39.71 |
| KD+AT | 77.82 | 74.36 | 3.46 | 77.77 | 97.61 | 29.86 | 26.39 | 43.29 | 13.36 | 67.02 |
| KD+AT+DP | 76.60 | 75.30 | 1.30 | 76.51 | 97.32 | 16.18 | 19.93 | 33.51 | 12.31 | 82.41 |
| Model | Clean ACC | Robust ACC | Robustness Gap | F1-Score | AUC | Passive ASR | Direct ASR | Active ASR | Perturbed ASR | PLI |
|---|---|---|---|---|---|---|---|---|---|---|
| OA | 72.76 | 65.06 | 7.70 | 72.24 | 95.16 | 12.83 | 20.86 | 38.52 | 11.58 | 77.94 |
| KD | 73.13 | 64.46 | 8.67 | 72.61 | 95.22 | 9.99 | 19.67 | 17.80 | 10.28 | 79.33 |
| KD+AT | 72.96 | 70.12 | 2.84 | 72.37 | 95.23 | 18.11 | 17.40 | 18.27 | 13.32 | 78.71 |
| KD+AT+DP | 72.84 | 69.95 | 2.89 | 72.26 | 95.24 | 9.75 | 18.34 | 26.73 | 10.71 | 86.68 |
| Model | Clean ACC | Robust ACC | Robustness Gap | F1-Score | AUC | Passive ASR | Direct ASR | Active ASR | PertASR | PLI |
|---|---|---|---|---|---|---|---|---|---|---|
| OA | 75.80 | 72.26 | 3.54 | 71.01 | 70.88 | 73.08 | 47.52 | 74.47 | 74.47 | 25.67 |
| KD | 75.67 | 72.82 | 2.85 | 71.52 | 70.79 | 74.78 | 74.10 | 69.91 | 36.66 | 24.28 |
| KD+AT | 74.72 | 74.66 | 0.06 | 73.31 | 69.25 | 55.22 | 70.10 | 74.47 | 73.90 | 44.74 |
| KD+AT+DP | 75.10 | 74.52 | 0.58 | 73.17 | 69.59 | 25.54 | 67.30 | 63.21 | 47.83 | 73.88 |
Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2026 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license.
Share and Cite
Azeez, N.A.; Malomo, O.S.; Okerinde, O.M.; Ademoye, A.A.; Aaron, D.S.; Vyver, C.V.D.; Ogbonna, C.E. Adversarial Training and Differential Privacy-Style Noise Injection for Privacy-Preserving Vertical Federated Learning. Informatics 2026, 13, 127. https://doi.org/10.3390/informatics13080127
Azeez NA, Malomo OS, Okerinde OM, Ademoye AA, Aaron DS, Vyver CVD, Ogbonna CE. Adversarial Training and Differential Privacy-Style Noise Injection for Privacy-Preserving Vertical Federated Learning. Informatics. 2026; 13(8):127. https://doi.org/10.3390/informatics13080127
Chicago/Turabian StyleAzeez, Nureni Ayofe, Oluwatobi Sunday Malomo, Omotolani Mary Okerinde, Abdullateef Akorede Ademoye, Damilola Seun Aaron, Charles Van Der Vyver, and Chijioke Erasmus Ogbonna. 2026. "Adversarial Training and Differential Privacy-Style Noise Injection for Privacy-Preserving Vertical Federated Learning" Informatics 13, no. 8: 127. https://doi.org/10.3390/informatics13080127
APA StyleAzeez, N. A., Malomo, O. S., Okerinde, O. M., Ademoye, A. A., Aaron, D. S., Vyver, C. V. D., & Ogbonna, C. E. (2026). Adversarial Training and Differential Privacy-Style Noise Injection for Privacy-Preserving Vertical Federated Learning. Informatics, 13(8), 127. https://doi.org/10.3390/informatics13080127

