REVIEW 3 major objections 4 minor 45 references
Similarity Weighted Aggregation with Global Differential Privacy for Federated Brain Lesion Segmentation
T0 review · 3 major / 4 minor · reviewed 2026-08-15 · deepseek-v4-flash
Pith's one-line read Similarity-weighted federated aggregation can carry per-round differential privacy while keeping brain-tumor segmentation competitive, with near-baseline Dice at a per-round budget of 10.
desk verdict The DP claim is broken twice—per-tensor composition is not accounted for and the empirical sensitivity is not a worst-case bound—but the combination is new, the paper is honest, and it deserves a real review. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The load-bearing object is Algorithm 1, the DP-SimAgg aggregation pipeline: (1) L2 clipping bounds each collaborator update to radius $C$, which makes sensitivity finite; (2) similarity-weighted averaging assigns normalized weights based on L2 distance from the unweighted mean, down-weighting divergent updates; (3) sensitivity is estimated empirically by replacing one clipped update with a vector of norm $C$ and measuring the L2 change in the weighted aggregate; (4) Gaussian noise is added with standard deviation $\frac{\Delta_f}{\epsilon_0}\sqrt{2\ln(1.25/\delta_0)}$. The paper's formal per-round $(\epsilon_0,\delta_0)$-DP claim rests on the Gaussian mechanism applied to this estimated sensitivity.
What would settle it
Run one round of Algorithm 1 on a small synthetic federated problem, enumerate all neighboring datasets that differ in one clipped collaborator update (including antipodal and zero replacements), recompute the similarity weights under each neighbor, and compare the largest observed change in the aggregate to the empirical $\Delta_f$ the algorithm would use. If any neighbor moves the output by more than $\Delta_f$, the noise injected for that round is too small and the stated per-round $(\epsilon_0,\delta_0)$-DP guarantee is violated.
Extended reading notes
Core claim
The discovery is that server-side differential privacy can be layered onto similarity-weighted aggregation without destroying segmentation utility. Concretely, after L2-clipping every collaborator update to norm at most $C$, the server forms a weighted average in which updates close to the consensus receive higher weight; it then estimates the L2 sensitivity $\Delta_f$ by swapping one collaborator's clipped update for a worst-case bounded tensor and measuring how much the aggregate changes; finally it adds Gaussian noise with standard deviation $\frac{\Delta_f}{\epsilon_0}\sqrt{2\ln(1.25/\delta_0)}$. On the benchmark, per-round $\epsilon_0=10$ yields whole-tumor Dice 0.7962 versus 0.7896 for the non-private baseline, while per-round $\epsilon_0=1$ yields whole-tumor Dice 0.5274, roughly 10–15 points below baseline. The privacy statement is explicit that the guarantee is per-round and holds under the assumed sensitivity bound.
Load-bearing premise
The per-round privacy guarantee assumes that the sensitivity estimated from one simulated neighboring update is a valid upper bound on the true worst-case sensitivity of the similarity-weighted aggregate; if any real neighboring dataset moves the aggregate more than that estimate, the injected noise is too small and the stated $(\epsilon,\delta)$-DP guarantee does not hold.
Editorial extensions
If this is right
- At per-round $\epsilon_0=10$ (cumulative 200 over 20 rounds), the whole-tumor Dice of 0.7962 slightly exceeds the non-private baseline of 0.7896, with all lesion Dice within a few points of baseline.
- At per-round $\epsilon_0=1$ (cumulative 20), Dice drops by roughly 10–15 points relative to baseline but remains in the range of reported inter-rater variability for glioblastoma segmentation.
- Because clipping, weighting, sensitivity estimation, and noise injection all run server-side, collaborators need no changes to local training, and wall-clock time, memory, and energy stay within about 5% of non-private runs.
- The formal guarantee is per-round $(\epsilon_0,\delta_0)$-DP under the assumed sensitivity bound; with basic sequential composition the 20-round cumulative budget is reported as 20 or 200.
- The method does not depend on any collaborator-side modification, so it can be dropped into existing federated medical-imaging deployments that already use a central aggregator.
Reading between the lines
- If the empirical sensitivity estimate ever understates the true worst-case sensitivity—for example with colluding collaborators who alter both updates and similarity weights—the per-round privacy guarantee would not hold even though the accounting says it should; replacing the empirical estimate with the paper's own conservative $4C$ bound would make the guarantee unconditional at the price of muc
- The paper reports only basic sequential composition; using Rényi DP or moments-accountant composition would lower the cumulative budget without changing the mechanism, so the reported privacy cost is conservative in that dimension.
- A direct comparison against differentially private FedAvg under the same budgets would isolate how much of the retained utility comes from similarity weighting rather than from central DP; the paper lists this as future work.
- The unused $4C$ analytical bound in the supplement is not what Algorithm 1 calibrates to; testing whether noise calibrated to the empirical estimate still protects all neighboring datasets could be done by exhaustively checking one-round outputs on a small synthetic federated problem.
Signed reviews
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper proposes DP-SimAgg, a server-side differentially private variant of similarity-weighted aggregation for federated brain lesion segmentation. The method clips collaborator updates, computes similarity weights, estimates the L2 sensitivity of the aggregation empirically via a simulated neighboring dataset, injects Gaussian noise calibrated to that estimate, and reports per-round (epsilon_0, delta_0)-DP with basic composition over 20 rounds. Experiments on the FeTS 2022 dataset with a 3D residual U-Net show Dice scores of 0.6357/0.5305/0.5274 for ET/TC/WT at epsilon_0=1 and near-baseline performance at epsilon_0=10. The central claim is that this mechanism provides formal per-round differential privacy guarantees while retaining competitive segmentation accuracy.
Significance. If the privacy guarantee were sound, the paper would be a useful engineering contribution: it provides a complete algorithmic specification, evaluates on a challenging multi-institutional benchmark using a standard architecture, and reports computational overhead that is genuinely small relative to training cost. The authors also deserve credit for explicitly acknowledging in the limitations section that the empirical sensitivity estimate is not a formal upper bound and that tighter accounting methods exist. However, the central privacy claim is the main selling point, and it is not supported by the mechanism as implemented. The paper cannot be accepted as a formal differential privacy contribution without correcting the sensitivity calibration and the composition accounting, and the experimental results would need to be regenerated under a valid mechanism.
major comments (3)
- [Section III-F and Algorithm 1] The privacy accounting is incorrect because a single communication round is not one invocation of the Gaussian mechanism. Algorithm 1 applies the clipping, sensitivity estimation, and AddGaussianNoise steps separately to each weight/bias tensor (lines 1-21) and also noise-perturbs every non-weight tensor with Delta_f=C (lines 22-26). For a 95-layer, 33M-parameter network there are many tensors, so the round-level mechanism is the composition of m tensor-level Gaussian mechanisms. Section III-F states that each round applies one invocation with per-round budget (epsilon_0, delta_0), but under the paper's own basic-composition convention the round guarantee is at best (m*epsilon_0, m*delta_0) and the 20-round total is at least 20*m*epsilon_0, not 20*epsilon_0. This is a load-bearing error: the reported epsilon_total values (20 and 200) do not follow from the described mechanism.
- [Algorithm 1, lines 17-19, and Section III-D] The estimated sensitivity Delta_f is not a valid upper bound on the L2 sensitivity of the actual aggregation function. Algorithm 1 computes the neighboring aggregate pm' using the same similarity weights Wnorm that were derived from the original tensor set T (lines 14-18), whereas the true aggregation function recomputes the similarity weights from the neighboring tensor set. The paper itself concedes in Section III-D that this approach 'does not yield a formal tight upper bound on the sensitivity,' and Supplementary Remark VI.2 confirms that the analytical 4C bound is not used in Algorithm 1. Consequently, the Gaussian noise standard deviation sigma = Delta_f/epsilon_0 * sqrt(2 ln(1.25/delta_0)) is not guaranteed to satisfy (epsilon_0, delta_0)-DP even for a single tensor, and any real neighboring dataset that induces a larger weight change than the simulated one will have insufficient noise.
- [Supplementary Proposition VI.1 and Section IV] The analytical 4C bound cannot rescue the privacy claim as stated. Proposition VI.1 is a per-tensor bound, and it would still need to be combined with the missing composition across tensors within each round and across the 20 rounds. More importantly, the experimental results in Section IV were produced using the empirical sensitivity estimate, not the 4C bound. If the authors were to implement a valid mechanism using the 4C bound per tensor, the noise scale would increase substantially (by a factor related to 4C / Delta_f_empirical, and further by the tensor-count factor in composition), and the reported Dice scores at epsilon_0=1 and epsilon_0=10 would likely change materially. No evidence is provided that the utility results would be preserved under a correct privacy accounting.
minor comments (4)
- [Table 2] The abstract reports Dice scores of 0.6357/0.5305/0.5274 for ET/TC/WT at epsilon_0=1, but Table 2 labels these values as DICE LABEL1, DICE LABEL2, and DICE LABEL4, respectively. The mapping between the composite regions (ET, TC, WT) and the label-based rows is confusing and should be clarified, especially because the text in Section IV assigns label 1 to necrotic core, label 2 to edema, and label 4 to enhancing tumor.
- [Section V, Limitations and Future Directions] The sentence beginning 'While providing per-round (epsilon_0, delta_0)-DP guarantees' appears grammatically incomplete; a period is missing after 'sensitivity bound.' Also, the phrase 'minimal additional overhead computational cost' in Section VI should be reworded to 'minimal additional computational overhead.'
- [Algorithm 1, line 17] The line 'T'[0] <- 1*C' is ambiguous: it is unclear whether this sets the entire first tensor to a constant tensor with norm C, a scalar, or a vector of ones scaled by C. The pseudo-code should specify the construction of the adversarial neighbor tensor explicitly, since the sensitivity estimate depends on this construction.
- [Section III-F] The statement that delta_total <= 20*10^-5 = 2*10^-4 assumes basic composition for delta, but the per-tensor composition issue also affects the delta accounting: if the round is m composed mechanisms, the round-level delta should be m*delta_0 under basic composition, so the total delta would be larger than reported.
Circularity Check
No significant circularity: the DP mechanism is a standard Gaussian-mechanism application and the utility results are empirical; main weaknesses are an unproven sensitivity bound and per-tensor composition accounting, which are soundness gaps rather than reductions to inputs.
full rationale
The paper's claimed derivation chain is: clip updates, compute similarity weights, estimate an empirical L2 sensitivity via one simulated neighboring tensor, inject Gaussian noise with the standard formula sigma = Delta_f / epsilon_0 * sqrt(2 ln(1.25/delta_0)), and assert per-round (epsilon_0, delta_0)-DP with basic composition over 20 rounds. Each step is either a standard external DP theorem (Dwork-Roth, McMahan et al.) or an empirical measurement (Dice on FeTS 2022); none of the utility numbers are forced by the privacy parameters, and the Gaussian mechanism is not defined in terms of the reported Dice results. The SimAgg aggregation scheme is taken from the authors' prior work, but that work is externally benchmarked (FeTS 2021/2022 challenges) and is used as a baseline/comparison, not as a self-justifying uniqueness theorem; the DP extension is an independent contribution. The paper itself concedes that the empirical sensitivity 'does not yield a formal tight upper bound' (Sec. III-D), and Algorithm 1 noises each tensor separately while Sec. III-F counts one mechanism per round. These are correctness/soundness problems in the privacy accounting, not instances where a prediction is equivalent to its input by construction. Under the instruction to reserve circularity findings for exhibited Eq.-equals-input reductions, no load-bearing circular step is present. Score 2 reflects the noticeable but non-load-bearing self-citation lineage; the central DP derivation has independent content.
Assumptions & free parameters
free parameters (4)
- L2 clipping bound C =
100
- Empirical sensitivity estimate Delta_f =
Data-dependent, recomputed each round
- epsilon_safe =
1e-8
- Per-round privacy budget epsilon_0 =
1 and 10
assumptions (5)
- standard math The Gaussian mechanism with sigma = Delta_f / epsilon_0 * sqrt(2 ln(1.25/delta_0)) yields (epsilon_0, delta_0)-DP when Delta_f is a true upper bound on the L2 sensitivity.
- standard math Basic sequential composition: T rounds at (epsilon_0, delta_0) give (T epsilon_0, T delta_0)-DP.
- ad hoc to paper The empirical sensitivity estimate from one simulated neighbor is assumed to be an upper bound on the worst-case sensitivity of the actual aggregation mechanism.
- domain assumption Neighboring datasets differ in exactly one collaborator's model update, not in one patient's data.
- domain assumption A trusted central aggregator is available.
Cite this review
Pith. "Pith review of Similarity Weighted Aggregation with Global Differential Privacy for Federated Brain Lesion Segmentation." pith.science (2026). https://pith.science/paper/2EWHP5NB
@misc{pith2026260800872,
author = {Pith},
title = {Pith review of: Similarity Weighted Aggregation with Global Differential Privacy for Federated Brain Lesion Segmentation},
year = {2026},
howpublished = {\url{https://pith.science/paper/2EWHP5NB}},
note = {Machine review of arXiv:2608.00872}
}
read the original abstract
Federated Learning (FL) enables collaborative training of machine learning models across multiple institutions without sharing sensitive data, making it particularly suitable for medical imaging applications. However, heterogeneous data distributions across institutions and potential information leakage through model updates remain important challenges. In this work, we propose DP-SimAgg, a privacy-preserving federated learning framework that integrates similarity-weighted aggregation with a server-side differential privacy mechanism. The proposed method applies L2 clipping to bound collaborator updates, computes similarity-based aggregation weights to mitigate the effects of non-IID data distributions, and injects calibrated Gaussian noise at the central server, providing per-round privacy guarantees under the assumed sensitivity bound. The framework is implemented using Intel's OpenFL platform and evaluated on the FeTS 2022 dataset consisting of 1251 multi-modal MRI scans for brain tumor segmentation. Experimental results demonstrate that DP-SimAgg maintains competitive segmentation performance while providing privacy protection. Under a strict per-round privacy budget (epsilon = 1, cumulative epsilon_total = 20 over 20 rounds), the method achieves Dice scores of 0.6357, 0.5305, and 0.5274 for the enhancing tumor (ET), tumor core (TC), and whole tumor (WT) regions, respectively. With a more relaxed per-round budget (epsilon = 10, cumulative epsilon_total = 200), performance approaches that of the non-private baseline while incorporating a central Gaussian mechanism with per-round (epsilon, delta)-DP accounting under the assumed sensitivity bound. These results highlight the potential of DP-SimAgg for enabling privacy-preserving collaborative learning in medical imaging applications.
Figures
Reference graph
Works this paper leans on
-
[1]
Machine learning for medical imaging: Methodological failures and recommendations for the future,
G. Varoquaux and V . Cheplygina, “Machine learning for medical imaging: Methodological failures and recommendations for the future,” NPJ Digital Medicine, vol. 5, no. 1, p. 48, 2022
work page 2022
-
[2]
M. J. Sheller, B. Edwards, G. A. Reina, J. Martin, S. Pati, A. Kotrotsou, M. Milchenko, W. Xu, D. Marcus, R. R. Colen et al., “Federated learning in medicine: Facilitating multi-institutional collaborations without sharing patient data,” Scientific Reports, vol. 10, no. 1, p. 12598, 2020
work page 2020
-
[3]
S. Bakas, H. Akbari, A. Sotiras, M. Bilello, M. Rozycki, J. S. Kirby, J. B. Freymann, K. Farahani, and C. Davatzikos, “Advancing The Cancer Genome Atlas glioma MRI collections with expert segmentation labels and radiomic features,” Scientific Data, vol. 4, no. 1, p. 170117, 2017
work page 2017
-
[4]
Hipaa legislation means more delicate handling of data,
M. May, “Hipaa legislation means more delicate handling of data,” Nature Medicine, vol. 16, no. 3, pp. 250–251, 2010
work page 2010
-
[5]
Finnish perspective on using synthetic health data to protect privacy: The privasa project,
T. Pitkämäki, T. Pahikkala, I. M. Perez, P. Movahedi, V . Nieminen, T. Southerington, J. Vaiste, M. Jafaritadi, M. I. Khan, E. Kontio, P. Ranttila, J. Pajula, H. Pölönen, A. Degerli, J. Plomp, and A. Airola, “Finnish perspective on using synthetic health data to protect privacy: The privasa project,” Applied Computing and Intelligence, vol. 4, no. 2, pp. ...
work page 2024
-
[6]
D. Ng, X. Lan, M. M.-S. Yao, W. P. Chan, and M. Feng, “Federated learning: A collaborative effort to achieve better medical imaging models for individual sites that have small labelled datasets,” Quantitative Imaging in Medicine and Surgery, vol. 11, no. 2, p. 852, 2021
work page 2021
-
[7]
Communication-efficient learning of deep networks from decentralized data,
H. B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y Arcas, “Communication-efficient learning of deep networks from decentralized data,” in Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, 2017, pp. 1273–1282
work page 2017
-
[8]
Fed- erated learning with matched averaging,
H. Wang, M. Yurochkin, Y . Sun, D. Papailiopoulos, and Y . Khazaeni, “Fed- erated learning with matched averaging,” arXiv preprint arXiv:2002.06440, 2020
arXiv 2002
Show all 45 references
-
[9]
Regularized weight aggregation in networked federated learning for glioblastoma segmentation,
M. I. Khan, M. A. Azeem, E. Alhoniemi, E. Kontio, S. A. Khan, and M. Jafaritadi, “Regularized weight aggregation in networked federated learning for glioblastoma segmentation,” arXiv preprint arXiv:2301.12617, 2023
2023 arXiv
-
[10]
Federated learning with non-iid data,
Y . Zhao, M. Li, L. Lai, N. Suda, D. Civin, and V . Chandra, “Federated learning with non-iid data,” arXiv preprint arXiv:1806.00582, 2018
2018 arXiv
-
[11]
Advances and open problems in federated learning,
P. Kairouz, H. B. McMahan, B. Avent, A. Bellet, M. Bennis, A. N. Bhagoji, K. Bonawitz, Z. Charles, G. Cormode, R. Cummings et al., “Advances and open problems in federated learning,” Foundations and Trends in Machine Learning, vol. 14, no. 1–2, pp. 1–210, 2021
2021
-
[12]
SCAFFOLD: Stochastic controlled averaging for federated learning,
S. P. Karimireddy, S. Kale, M. Mohri, S. Reddi, S. Stich, and A. T. Suresh, “SCAFFOLD: Stochastic controlled averaging for federated learning,” in ICML, 2020, pp. 5132–5143
2020
-
[13]
Inverting gradients – how easy is it to break privacy in federated learning?
J. Geiping, H. Bauermeister, H. Dröge, and M. Moeller, “Inverting gradients – how easy is it to break privacy in federated learning?” arXiv preprint arXiv:2003.14053, 2020
2003 arXiv
-
[14]
Membership inference attacks against machine learning models,
R. Shokri, M. Stronati, and V . Shmatikov, “Membership inference attacks against machine learning models,” CoRR, vol. abs/1610.05820, 2016
2016 arXiv
-
[15]
Privacy preservation in federated learning: An insightful survey from the GDPR perspective,
N. Truong, K. Sun, S. Wang, F. Guitton, and Y . Guo, “Privacy preservation in federated learning: An insightful survey from the GDPR perspective,” arXiv preprint arXiv:2011.05411, 2021
2011 arXiv
-
[16]
Survey on federated learning threats: Concepts, taxonomy on attacks and defences, experimental study and challenges,
N. Rodríguez-Barroso, D. Jiménez-López, M. V . Luzón, F. Herrera, and E. Martínez-Cámara, “Survey on federated learning threats: Concepts, taxonomy on attacks and defences, experimental study and challenges,” Information Fusion, vol. 90, pp. 148–173, 2023
2023
-
[17]
Adap- tive weight aggregation in federated learning for brain tumor segmentation,
M. I. Khan, M. Jafaritadi, E. Alhoniemi, E. Kontio, and S. A. Khan, “Adap- tive weight aggregation in federated learning for brain tumor segmentation,” in International MICCAI Brainlesion Workshop. Springer, 2021, pp. 455–469
2021
-
[18]
Towards fair decentralized benchmarking of healthcare AI algorithms with the federated tumor segmentation (FeTS) challenge,
M. Zenk, U. Baid, S. Pati, A. Linardos, B. Edwards, M. Sheller, P. Foley, A. Aristizabal, D. Zimmerer, A. Gruzdev et al., “Towards fair decentralized benchmarking of healthcare AI algorithms with the federated tumor segmentation (FeTS) challenge,” Nature Communications, vol. 1...
2025
-
[19]
The MICCAI federated tumor segmentation (FeTS) challenge 2024: Efficient and robust aggregation methods,
A. Linardos, S. Pati, U. Baid, B. Edwards, P. Foley, K. Ta, V . Chung, M. Sheller, M. I. Khan, M. Jafaritadi, E. Kontio, S. Khan, L. Machler, I. Ezhov, S. Shit, J. C. Paetzold, G. Grimberg, M. A. Nickel, D. Naccache, V . Siomos, J. Passerat-Palmbach, G. Tarroni, D. Kim, L. L. ...
2024
-
[20]
Openfl: An open-source framework for federated learning,
G. A. Reina, A. Gruzdev, P. Foley, O. Perepelkina, M. Sharma, I. Davidyuk, I. Trushkin, M. Radionov, A. Mokrov, D. Agapov, J. Martin, B. Edwards, M. J. Sheller, S. Pati, P. N. Moorthy, S.-h. Wang, P. Shah, and S. Bakas, “Openfl: An open-source framework for federated learning,...
2022
-
[21]
Federated optimization in heterogeneous networks,
T. Li, A. K. Sahu, M. Zaheer, M. Sanjabi, A. Talwalkar, and V . Smith, “Federated optimization in heterogeneous networks,” in MLSys, 2020
2020
-
[22]
Tackling the objective inconsistency problem in heterogeneous federated optimization,
J. Wang, Q. Liu, H. Liang, G. Joshi, and H. V . Poor, “Tackling the objective inconsistency problem in heterogeneous federated optimization,” in Advances in Neural Information Processing Systems, vol. 33, 2020, pp. 7611–7623
2020
-
[23]
Machine learning with adversaries: Byzantine tolerant gradient descent,
P. Blanchard, E. M. El Mhamdi, R. Guerraoui, and J. Stainer, “Machine learning with adversaries: Byzantine tolerant gradient descent,” in Advances in Neural Information Processing Systems, vol. 30, 2017
2017
-
[24]
Byzantine-robust distributed learning: Towards optimal statistical rates,
D. Yin, Y . Chen, R. Kannan, and P. Bartlett, “Byzantine-robust distributed learning: Towards optimal statistical rates,” in Proceedings of the 35th In- ternational Conference on Machine Learning, ser. Proceedings of Machine Learning Research, vol. 80, 2018, pp. 5650–5659
2018
-
[25]
Adap- tive weight aggregation in federated learning for brain tumor segmentation,
M. I. Khan, M. Jafaritadi, E. Alhoniemi, E. Kontio, and S. A. Khan, “Adap- tive weight aggregation in federated learning for brain tumor segmentation,” in Brainlesion: Glioma, Multiple Sclerosis, Stroke and Traumatic Brain Injuries, A. Crimi and S. Bakas, Eds. Cham: Springer I...
2022
-
[26]
Differential privacy,
C. Dwork, “Differential privacy,” in Automata, Languages and Program- ming, 2006, pp. 1–12
2006
-
[27]
The algorithmic foundations of differential privacy,
C. Dwork and A. Roth, “The algorithmic foundations of differential privacy,” Foundations and Trends in Theoretical Computer Science, vol. 9, no. 3–4, pp. 211–407, 2014
2014
-
[28]
A firm foundation for private data analysis,
C. Dwork, “A firm foundation for private data analysis,” Communications of the ACM, vol. 54, no. 1, pp. 86–95, 2011
2011
-
[29]
Deep learning with differential privacy,
M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Talwar, and L. Zhang, “Deep learning with differential privacy,” in Proceedings of VOLUME 4, 2016 11 IEEE Access the 2016 ACM SIGSAC Conference on Computer and Communications Security, 2016, pp. 308–318
2016
-
[30]
Differentially private federated learning: A client level perspective,
R. C. Geyer, T. Klein, and M. Nabi, “Differentially private federated learning: A client level perspective,” in NIPS Workshop on Private Multi- Party Machine Learning, 2017
2017
-
[31]
Gaussian differential privacy,
J. Dong, A. Roth, and W. J. Su, “Gaussian differential privacy,” CoRR, vol. abs/1905.02383, 2019
1905 arXiv
-
[32]
Rényi differential privacy,
I. Mironov, “Rényi differential privacy,” in 2017 IEEE 30th Computer Security Foundations Symposium (CSF). IEEE, 2017, pp. 263–275
2017
-
[33]
Election of collabo- rators via reinforcement learning for federated brain tumor segmentation,
M. I. Khan, E. Kontio, S. A. Khan, and M. Jafaritadi, “Election of collabo- rators via reinforcement learning for federated brain tumor segmentation,” arXiv preprint arXiv:2412.20253, 2024
2024 arXiv
-
[34]
Recommender engine driven client selection in federated brain tumor segmentation,
——, “Recommender engine driven client selection in federated brain tumor segmentation,” arXiv preprint arXiv:2412.20250, 2024
2024 arXiv
-
[35]
Secure, privacy-preserving and federated machine learning in medical imaging,
G. A. Kaissis, M. R. Makowski, D. Rückert, and R. F. Braren, “Secure, privacy-preserving and federated machine learning in medical imaging,” Nature Machine Intelligence, vol. 2, no. 6, pp. 305–311, 2020
2020
-
[36]
signsgd: Compressed optimisation for non-convex problems,
J. Bernstein, Y .-X. Wang, K. Azizzadenesheli, and A. Anandkumar, “signsgd: Compressed optimisation for non-convex problems,” in Inter- national conference on machine learning. PMLR, 2018, pp. 560–569
2018
-
[37]
Noisy signsgd is more differentially private than you (might) think,
R. Jin and H. Dai, “Noisy signsgd is more differentially private than you (might) think,” in Forty-second International Conference on Machine Learning, 2025
2025
-
[38]
Biomedical image analysis competitions: The state of current participation practice,
L. Maier-Hein et al., “Biomedical image analysis competitions: The state of current participation practice,” arXiv preprint arXiv:2212.08568, 2023
2023
-
[39]
The new WHO classification of brain tumours,
P. Kleihues, P. C. Burger, and B. W. Scheithauer, “The new WHO classification of brain tumours,” Brain Pathology, vol. 3, no. 3, pp. 255–268, 1993
1993
-
[40]
Glioblastoma multiforme: A review of its epidemiology and pathogenesis through clinical presentation and treatment,
F. Hanif, K. Muzaffar, K. Perveen, S. M. Malhi, and S. U. Simjee, “Glioblastoma multiforme: A review of its epidemiology and pathogenesis through clinical presentation and treatment,” Asian Pacific Journal of Cancer Prevention, vol. 18, no. 1, p. 3, 2017
2017
-
[41]
Segmentation labels for the pre-operative scans of the TCGA-GBM collection,
S. Bakas, H. Akbari, A. Sotiras, M. Bilello, M. Rozycki, J. Kirby, J. Freymann, K. Farahani, and C. Davatzikos, “Segmentation labels for the pre-operative scans of the TCGA-GBM collection,” 2017, dataset
2017
-
[42]
Segmentation labels for the pre-operative scans of the TCGA-LGG collection,
——, “Segmentation labels for the pre-operative scans of the TCGA-LGG collection,” 2017, dataset
2017
-
[43]
U-net: Convolutional networks for biomedical image segmentation,
O. Ronneberger, P. Fischer, and T. Brox, “U-net: Convolutional networks for biomedical image segmentation,” in Medical Image Computing and Computer-Assisted Intervention (MICCAI), 2015, pp. 234–241
2015
-
[44]
The federated tumor segmentation (FeTS) challenge 2022,
S. Bakas, S. Pati, M. Sheller, A. Karargyris, P. Mattson, B. Edwards, U. Baid, Y . Chen, R. T. Shinohara, J. Martin, B. Menze, M. Zenk, K. Maier-Hein, R. Floca, A. Reinke, L. Maier-Hein, F. Isensee, D. Zimmerer, and Y . Chen, “The federated tumor segmentation (FeTS) challenge ...
2022
-
[45]
Privacyfl: A simulator for privacy-preserving and secure federated learning,
V . Mugunthan, A. Peraire-Bueno, and L. Kagal, “Privacyfl: A simulator for privacy-preserving and secure federated learning,” arXiv preprint arXiv:2002.08423, 2020. 12 VOLUME 4, 2016 Khanet al.: DP-SimAgg for Privacy-Preserving Federated Brain Lesion Segmentation SUPPLEMENTARY...
2002 arXiv
Reviewed August 15, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.