<?xml version="1.0" encoding="utf-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.3 20070202//EN" "journalpublishing.dtd">
<article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" article-type="research-article" dtd-version="2.3" xml:lang="EN">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">Front. Artif. Intell.</journal-id>
<journal-title>Frontiers in Artificial Intelligence</journal-title>
<abbrev-journal-title abbrev-type="pubmed">Front. Artif. Intell.</abbrev-journal-title>
<issn pub-type="epub">2624-8212</issn>
<publisher>
<publisher-name>Frontiers Media S.A.</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="doi">10.3389/frai.2025.1653437</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Artificial Intelligence</subject>
<subj-group>
<subject>Original Research</subject>
</subj-group>
</subj-group>
</article-categories>
<title-group>
<article-title>Entropy-adaptive differential privacy federated learning for student performance prediction and privacy protection: a case study in Python programming</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes">
<name>
<surname>Chen</surname>
<given-names>Shanwei</given-names>
</name>
<xref ref-type="aff" rid="aff1"><sup>1</sup></xref>
<xref ref-type="corresp" rid="c001"><sup>&#x002A;</sup></xref>
<uri xlink:href="https://loop.frontiersin.org/people/3006266/overview"/>
<role content-type="https://credit.niso.org/contributor-roles/conceptualization/"/>
<role content-type="https://credit.niso.org/contributor-roles/methodology/"/>
<role content-type="https://credit.niso.org/contributor-roles/software/"/>
<role content-type="https://credit.niso.org/contributor-roles/writing-original-draft/"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname>Qi</surname>
<given-names>Xiuzhi</given-names>
</name>
<xref ref-type="aff" rid="aff2"><sup>2</sup></xref>
<role content-type="https://credit.niso.org/contributor-roles/data-curation/"/>
<role content-type="https://credit.niso.org/contributor-roles/investigation/"/>
<role content-type="https://credit.niso.org/contributor-roles/visualization/"/>
<role content-type="https://credit.niso.org/contributor-roles/writing-original-draft/"/>
</contrib>
</contrib-group>
<aff id="aff1"><sup>1</sup><institution>College of Education, Baoji University of Arts and Sciences</institution>, <addr-line>Baoji</addr-line>, <country>China</country></aff>
<aff id="aff2"><sup>2</sup><institution>Academy of Fine Arts, Baoji University of Arts and Sciences</institution>, <addr-line>Baoji</addr-line>, <country>China</country></aff>
<author-notes>
<fn fn-type="edited-by" id="fn0001">
<p>Edited by: <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/1380942/overview">Rajendra Prasath</ext-link>, Indian Institute of Information Technology, Sri City, India</p>
</fn>
<fn fn-type="edited-by" id="fn0002">
<p>Reviewed by: <ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/2182528/overview">Agung Triayudi</ext-link>, Universitas Nasional, Indonesia</p>
<p><ext-link ext-link-type="uri" xlink:href="https://loop.frontiersin.org/people/3135624/overview">Vikas Verma</ext-link>, ICFAI University, Jaipur, India</p>
</fn>
<corresp id="c001">&#x002A;Correspondence: Shanwei Chen, <email>chenshanwei@bjwlxy.edu.cn</email></corresp>
</author-notes>
<pub-date pub-type="epub">
<day>08</day>
<month>09</month>
<year>2025</year>
</pub-date>
<pub-date pub-type="collection">
<year>2025</year>
</pub-date>
<volume>8</volume>
<elocation-id>1653437</elocation-id>
<history>
<date date-type="received">
<day>25</day>
<month>06</month>
<year>2025</year>
</date>
<date date-type="accepted">
<day>19</day>
<month>08</month>
<year>2025</year>
</date>
</history>
<permissions>
<copyright-statement>Copyright &#x00A9; 2025 Chen and Qi.</copyright-statement>
<copyright-year>2025</copyright-year>
<copyright-holder>Chen and Qi</copyright-holder>
<license xlink:href="http://creativecommons.org/licenses/by/4.0/">
<p>This is an open-access article distributed under the terms of the Creative Commons Attribution License (CC BY). The use, distribution or reproduction in other forums is permitted, provided the original author(s) and the copyright owner(s) are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.</p>
</license>
</permissions>
<abstract>
<p>In the context of the digital transformation of engineering education, protecting student data privacy has become a key challenge for enabling data-driven instruction. This study proposes an Entropy-Adaptive Differential Privacy Federated Learning method (EADP-FedAvg) to enhance the accuracy of student performance prediction while ensuring data privacy. Based on online test records from Python programming courses for Electronic Engineering students (grade 2021&#x2013;2023) at the School of Physics and Optoelectronic Technology, Baoji University of Arts and Sciences, China, the study uses a Multilayer Perceptron (MLP) model and 10 distributed clients for training. Under different privacy budgets (<italic>&#x03B5;</italic>&#x202F;=&#x202F;0.1, 1e-6, and 1.0), EADP-FedAvg achieves a test accuracy of 92.7%, macro-average score of 92.1%, and entropy of 0.207, outperforming standard federated learning and approaching centralized learning performance. The results demonstrate that by adaptively adjusting the noise level based on output entropy, EADP-FedAvg effectively balances privacy preservation and model accuracy. This method offers a novel solution for analyzing privacy-sensitive educational data in engineering education.</p>
</abstract>
<kwd-group>
<kwd>federated learning</kwd>
<kwd>entropy-adaptive differential privacy</kwd>
<kwd>student performance prediction</kwd>
<kwd>distributed data analysis</kwd>
<kwd>Python programming</kwd>
</kwd-group>
<contract-num rid="cn1">23XJA880001</contract-num>
<contract-sponsor id="cn1">Humanities and Social Science Fund of Ministry of Education of China<named-content content-type="fundref-id">10.13039/501100013139</named-content></contract-sponsor>
<counts>
<fig-count count="3"/>
<table-count count="9"/>
<equation-count count="8"/>
<ref-count count="22"/>
<page-count count="12"/>
<word-count count="7894"/>
</counts>
<custom-meta-wrap>
<custom-meta>
<meta-name>section-at-acceptance</meta-name>
<meta-value>Machine Learning and Artificial Intelligence</meta-value>
</custom-meta>
</custom-meta-wrap>
</article-meta>
</front>
<body>
<sec sec-type="intro" id="sec1">
<label>1</label>
<title>Introduction</title>
<p>The digital transformation of engineering education has led to an unprecedented increase in student data, offering valuable opportunities for optimizing instructional strategies and enabling personalized learning. These datasets, ranging from learning behaviors and academic performance to interaction records, form the foundation for analyzing student outcomes and improving teaching quality (<xref ref-type="bibr" rid="ref16">Shou et al., 2024</xref>). In many undergraduate engineering programs, Python Programming is a core course that cultivates computational thinking and coding skills. Its delivery via online platforms generates large-scale structured datasets, making it an ideal setting for data-driven educational research. However, the sensitive nature of student data raises critical privacy concerns, especially under the tightening global data protection regulations and evolving educational ethics standards (<xref ref-type="bibr" rid="ref8">Marshall et al., 2022</xref>).</p>
<p>To address this challenge, we propose Entropy-Adaptive Differential Privacy Federated Averaging (EADP-FedAvg)&#x2014;a method designed to improve prediction accuracy in Python programming courses while safeguarding student privacy. Federated Learning (FL) is a decentralized machine learning framework that allows multiple clients to collaboratively train a model without sharing raw data, making it naturally suited for privacy-sensitive educational applications (<xref ref-type="bibr" rid="ref12">Moshawrab et al., 2023</xref>). However, conventional FL combined with fixed-noise Differential Privacy (DP) often suffers from significant performance degradation due to excessive noise (<xref ref-type="bibr" rid="ref5">Elgabli and Mesbah, 2024</xref>). EADP-FedAvg tackles this issue by dynamically adjusting noise intensity based on the model&#x2019;s average output entropy, achieving a more effective balance between privacy and accuracy, even under stringent privacy budgets.</p>
<p>This study uses 2,452 online test records from 493 students majoring in Electronic Engineering (Classes of 2021&#x2013;2023) at Baoji University of Arts and Sciences. The dataset includes 17 features such as course click counts, assignment scores, and study duration, along with four performance categories: Fail, Passed, Good, and Excellent. The experiments are conducted in a simulated environment using 10 federated clients and a Multilayer Perceptron (MLP) model.</p>
<p>The study focuses on the following research questions:</p>
<list list-type="order">
<list-item>
<p>How can FL protect student test data privacy and improve prediction accuracy in Python programming courses?</p>
</list-item>
<list-item>
<p>How does entropy-adaptive differential privacy enhance conventional FL by optimizing the privacy-accuracy trade-off?</p>
</list-item>
<list-item>
<p>What is the potential of EADP-FedAvg for privacy-preserving data analysis in engineering education?</p>
</list-item>
</list>
<p>The remainder of this paper is structured as follows. Section 2 reviews the latest research developments and clarifies the innovative positioning of this study within the fields of FL and privacy preservation. Section 3 presents the data sources and outlines the model architecture. Section 4 describes the experimental setup and provides a detailed explanation of the model design. Section 5 offers a comparative analysis of three models using evaluation metrics such as confusion matrices and information entropy. Finally, Section 6 summarizes the key findings and explores potential directions for future research.</p>
</sec>
<sec id="sec2">
<label>2</label>
<title>Related research</title>
<sec id="sec3">
<label>2.1</label>
<title>FL in engineering education</title>
<p>FL is a decentralized machine learning framework that enables multiple clients to collaboratively train models without sharing their raw data (<xref ref-type="bibr" rid="ref9">McMahan et al., 2016</xref>). In Python programming courses, students generate a wealth of data through online tests and learning platforms, including performance records, behavioral features, and submission logs. While this data provides valuable resources for predicting student outcomes, traditional centralized machine learning methods require aggregating data on a central server, which raises significant privacy concerns and presents integration challenges due to data fragmentation (<xref ref-type="bibr" rid="ref2">Bonawitz et al., 2021</xref>). FL addresses these issues by performing localized training and aggregating model parameters, making it particularly suitable for privacy-sensitive educational environments.</p>
<p>In engineering education, FL has already been applied to programming course data analysis. For instance, <xref ref-type="bibr" rid="ref4">Christiansen et al. (2023)</xref> introduced a federated framework for cross-institutional analysis of programming course data to predict student performance, demonstrating FL&#x2019;s generalizability in heterogeneous data environments. Similarly, <xref ref-type="bibr" rid="ref18">Truex et al. (2019)</xref> employed FL to analyze C++ course test data, using distributed training to protect student privacy while maintaining model accuracy. These studies suggest that FL can support data-driven teaching optimization in a privacy-compliant manner.</p>
<p>However, several challenges remain in applying FL to educational data analysis. First, data heterogeneity across clients can hinder model convergence (<xref ref-type="bibr" rid="ref11">Mora et al., 2024</xref>). Second, when FL is combined with DP, the use of fixed noise levels often degrades prediction performance (<xref ref-type="bibr" rid="ref15">Sattler et al., 2019</xref>). Third, centralized AI methods that rely on aggregating data into a single location fall short of meeting privacy demands (<xref ref-type="bibr" rid="ref17">Song and others, 2023</xref>). Lastly, existing FL research has rarely explored adaptive noise mechanisms that dynamically balance privacy protection with model performance.</p>
</sec>
<sec id="sec4">
<label>2.2</label>
<title>Privacy-preserving technologies in education</title>
<p>As engineering education undergoes digital transformation, protecting student data privacy has become a cornerstone of data-driven instruction. In many technical courses such as Python Programming, the online test data generated often contains sensitive information which, if mishandled, may lead to privacy breaches. To address this issue, various privacy-preserving technologies have been introduced into educational contexts, including DP, data anonymization, Secure Multi-Party Computation (SMPC), and Homomorphic Encryption (HE). These methods aim to protect student privacy while still supporting high-precision performance prediction, making them particularly well-suited for privacy-sensitive educational environments.</p>
<p>DP ensures that individual data cannot be reverse-engineered by injecting carefully calibrated noise into model outputs or parameters. It is considered the gold standard in educational data analysis (<xref ref-type="bibr" rid="ref13">Pakina and Pujari, 2024</xref>). In this study, DP can be used to safeguard test scores and behavioral data. For example, (<xref ref-type="bibr" rid="ref20">Zhan et al., 2024</xref>) proposed a Gaussian mechanism&#x2013;based DP method for predicting student performance that maintained high accuracy under a privacy budget of <italic>&#x03B5;</italic>&#x202F;=&#x202F;0.1. However, traditional DP approaches often apply a fixed noise level, which can significantly degrade model performance&#x2014;especially when working with small datasets (<xref ref-type="bibr" rid="ref1">Afrose et al., 2021</xref>).</p>
<p>Data anonymization is a fundamental technique that reduces the risk of individual identification by removing or replacing personally identifiable information (PII), such as student IDs or names. In educational data processing, anonymization allows for meaningful analysis while protecting student identities. For instance, <xref ref-type="bibr" rid="ref3">Chicaiza et al. (2020)</xref> applied k-anonymity to anonymize learning data from programming courses. This technique generalizes or suppresses sensitive attributes so that each record is indistinguishable from at least k other records based on quasi-identifiers. It enabled cross-class comparison without exposing student identities. However, k-anonymity often leads to information loss&#x2014;especially in high-dimensional datasets&#x2014;by reducing the granularity of key features, which can limit deeper data analysis and compromise model performance.</p>
<p>Secure Multi-Party Computation (SMPC) allows multiple parties to jointly compute functions over their data without revealing the data itself. As noted by <xref ref-type="bibr" rid="ref6">Khan (2024)</xref>, this approach is particularly suitable for collaborative research across institutions&#x2014;such as sharing behavioral data across schools for joint analysis. While SMPC ensures that local data remains private, it requires substantial coordination among parties and may introduce significant communication overhead and system complexity.</p>
<p>HE enables direct computation on encrypted data such that the decrypted result is identical to what would have been obtained using plaintext inputs. The fully homomorphic encryption scheme proposed by <xref ref-type="bibr" rid="ref21">Zhang et al. (2024)</xref> laid the foundation for this area. In theory, HE allows training and prediction to occur entirely in the encrypted domain, offering the highest level of data privacy. However, current HE methods still face challenges of high computational complexity and low efficiency, making them difficult to deploy in real-time educational scenarios.</p>
</sec>
<sec id="sec5">
<label>2.3</label>
<title>Student data privacy in programming courses</title>
<p>The privacy challenges associated with programming course data stem primarily from its high dimensionality and heterogeneity. In courses like Python Programming, online test data often includes numerical features such as scores and discrete features such as click counts. Analyzing such complex data typically requires sophisticated models, which increases the risk of privacy leakage. Traditional methods like data anonymization reduce risk by removing identifiers, but often result in significant information loss, limiting the depth of analysis (<xref ref-type="bibr" rid="ref14">Salas and Domingo-Ferrer, 2018</xref>). Techniques such as Secure Multi-Party Computation (SMPC) and Homomorphic Encryption (HE) enable privacy-preserving computation but are computationally intensive, making them impractical for real-time analysis of large-scale course data (<xref ref-type="bibr" rid="ref7">Liu, 2024</xref>).</p>
<p>DP has emerged as the preferred method for protecting student privacy in programming courses by adding noise to safeguard data. For example, <xref ref-type="bibr" rid="ref10">Miller and Chattopadhyay (2024)</xref> applied DP to test score data in a database course and achieved high prediction accuracy under a privacy budget of <italic>&#x03B5;</italic>&#x202F;=&#x202F;0.1. However, the use of fixed-noise DP can degrade model performance, particularly on small datasets. Adaptive DP, which dynamically adjusts the noise level, has demonstrated the ability to strike a better balance between noise and model utility (<xref ref-type="bibr" rid="ref19">Yang et al., 2023</xref>). In response to these practical challenges, this study proposes the EADP-FedAvg method, which leverages average information entropy to dynamically adjust noise intensity.</p>
</sec>
</sec>
<sec id="sec6">
<label>3</label>
<title>Data and methods</title>
<sec id="sec7">
<label>3.1</label>
<title>Data definition</title>
<p>The dataset was collected from the Python Programming course offered at Baoji University of Arts and Sciences, School of Physics and Optoelectronic Technology, and includes data from students majoring in Electronic Engineering. Specifically, it covers three academic cohorts: Class of 2021 (four classes), Class of 2022 (four classes), and Class of 2023 (four classes). The course is a mandatory semester-long program aimed at developing students&#x2019; programming proficiency and algorithmic thinking. A total of 493 students participated, generating 2,465 test records, of which 2,452 remained after data cleaning.</p>
<p>Each semester includes five online tests, conducted through a Learning Management System (LMS), capturing test scores, learning behavior, and anonymized student demographics. The performance labels are divided into four categories: Fail, Passed, Good, and Excellent.</p>
<p>The total score for each test was 100 points, comprising four types of questions. Multiple-choice questions included 5 items worth 4 points each, totaling 20 points. These primarily assessed students&#x2019; understanding of fundamental syntax and core programming concepts, such as variable naming rules, reserved keywords, and operator usage. Fill-in-the-blank questions consisted of 3 items worth 5 points each, totaling 15 points. Students were required to complete specific code snippets, often involving string formatting techniques or loop structures. True/False questions included 5 items worth 3 points each, totaling 15 points. These tested students&#x2019; logical reasoning skills, for example, their understanding of increment operations or data type distinctions. Programming problems made up the remaining 50 points across 2 questions. Students were tasked with solving practical coding challenges, such as determining whether a number is even or odd, or implementing a list summation function. Scoring for these items considered the correctness of input handling, logical implementation, and the accuracy of the program output.</p>
<p>Learning behavior features include submission frequency, response time, and error frequency, totaling 10 features that reflect learning patterns and course difficulty.</p>
<p>Student demographic features include gender and age, allowing exploration of background influences on performance.</p>
<p>As shown in <xref ref-type="table" rid="tab1">Table 1</xref>, the dataset contains 17 features: 5 related to scores, 10 to behavioral patterns, and 2 to student demographics, along with 4-class categorical labels. It spans multiple classes and cohorts, making it a structured and heterogeneous dataset ideal for FL experimentation.</p>
<table-wrap position="float" id="tab1">
<label>Table 1</label>
<caption>
<p>Data set statistics.</p>
</caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th align="left" valign="top" rowspan="2">Category</th>
<th align="center" valign="top" colspan="5">Details</th>
<th align="center" valign="top" rowspan="2">Total</th>
</tr>
<tr>
<th align="center" valign="middle">Grade</th>
<th align="center" valign="middle">Class 1</th>
<th align="center" valign="middle">Class 2</th>
<th align="center" valign="middle">Class 3</th>
<th align="center" valign="middle">Class 4</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" valign="middle" rowspan="3">Grade enrollment</td>
<td align="center" valign="middle">2021</td>
<td align="center" valign="middle">41</td>
<td align="center" valign="middle">40</td>
<td align="center" valign="middle">43</td>
<td align="center" valign="middle">42</td>
<td align="center" valign="middle">166</td>
</tr>
<tr>
<td align="center" valign="middle">2022</td>
<td align="center" valign="middle">39</td>
<td align="center" valign="middle">42</td>
<td align="center" valign="middle">41</td>
<td align="center" valign="middle">41</td>
<td align="center" valign="middle">163</td>
</tr>
<tr>
<td align="center" valign="middle">2023</td>
<td align="center" valign="middle">39</td>
<td align="center" valign="middle">40</td>
<td align="center" valign="middle">43</td>
<td align="center" valign="middle">42</td>
<td align="center" valign="middle">164</td>
</tr>
<tr>
<td align="left" valign="middle" rowspan="2">Gender distribution</td>
<td align="center" valign="middle">Male</td>
<td align="center" valign="middle" colspan="5">252</td>
</tr>
<tr>
<td align="center" valign="middle">Female</td>
<td align="center" valign="middle" colspan="5">241</td>
</tr>
<tr>
<td align="left" valign="middle" rowspan="4">Data set overview</td>
<td align="center" valign="middle">Total Students</td>
<td align="center" valign="middle" colspan="5">493</td>
</tr>
<tr>
<td align="center" valign="middle">Total Records</td>
<td align="center" valign="middle" colspan="5">2,452</td>
</tr>
<tr>
<td align="center" valign="middle">Feature Dimensions</td>
<td align="center" valign="middle" colspan="5">17</td>
</tr>
<tr>
<td align="center" valign="middle">Labels</td>
<td align="center" valign="middle" colspan="5">Fail, Passed, Good, Excellent</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>Participation in this study was voluntary, and all students were fully informed of the research objectives before data collection. The study was approved by the Ethics Committee of the School of Education, Baoji University of Arts and Sciences (Approval No.: BJWLXY-2024-023). All data were anonymized immediately after collection by removing identifiable information such as names and class designations, and each record was assigned a unique code to protect student privacy.</p>
<p>The dataset, sourced from a Python programming course at a single institution and focused on students from a single academic major of Electronic Engineering, may not fully capture the diversity of broader educational contexts. Although the EADP-FedAvg method has been thoroughly validated in this specific setting (see Section 5.2), future research will integrate datasets from multiple institutions and diverse disciplines to enhance the generalizability of the proposed approach.</p>
</sec>
<sec id="sec8">
<label>3.2</label>
<title>Data preprocessing</title>
<p>To ensure the quality of the Python Programming online test dataset and improve compatibility with the MLP model used in EADP-FedAvg, this study applied four preprocessing steps to the 2,452 valid records: data cleaning, feature extraction, normalization, and data splitting. These steps addressed missing values, outliers, and discrepancies in feature scale.</p>
<sec id="sec9">
<label>3.2.1</label>
<title>Data cleaning</title>
<p>Out of the initial 2,465 raw records, 13 invalid entries were removed. These included records missing programming scores, submissions with response times under 5&#x202F;min, duplicate entries, and records containing abnormal values. Additionally, error logs not related to Python syntax were excluded to maintain data consistency. After cleaning, 2,452 records remained for analysis.</p>
</sec>
<sec id="sec10">
<label>3.2.2</label>
<title>Feature extraction</title>
<p>Seventeen features were extracted from the cleaned dataset. These included 5 score-related features (total score, multiple choice, fill-in-the-blank, true/false, and programming), 10 behavior-related features (such as submission count and response time), and 2 demographic features (gender and age). Each feature vector was defined at the individual test attempt level, without temporal aggregation, to align with the tabular input requirements of the MLP model.</p>
</sec>
<sec id="sec11">
<label>3.2.3</label>
<title>Data normalization</title>
<p>Due to the varying scales of different features, z-score normalization was applied to standardize the data:</p>
<disp-formula id="E1">
<label>(1)</label>
<mml:math id="M1">
<mml:mi>z</mml:mi>
<mml:mo>=</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:mi>x</mml:mi>
<mml:mo>&#x2212;</mml:mo>
<mml:mi mathvariant="normal">&#x03BC;</mml:mi>
</mml:mrow>
<mml:mi>&#x03C3;</mml:mi>
</mml:mfrac>
<mml:mspace width="0.25em"/>
</mml:math>
</disp-formula>
<p>In <xref ref-type="disp-formula" rid="E1">Equation 1</xref>, <inline-formula>
<mml:math id="M2">
<mml:mi>x</mml:mi>
</mml:math>
</inline-formula> is the original value, &#x03BC; is the mean, and &#x03C3; is the standard deviation. After normalization, the transformed features have a mean of 0 and a standard deviation of 1, which improves model training stability. Gender and categorical label data were excluded from this step, as normalization was unnecessary.</p>
</sec>
<sec id="sec12">
<label>3.2.4</label>
<title>Data splitting</title>
<p>By anonymizing student IDs and test identifiers, the final dataset of 2,452 records was constructed by merging score, behavior, and demographic features. The dataset was split into a training set and a test set at an 8:2 ratio, resulting in 1,961 training samples and 491 test samples, following standard practices in educational data mining. The training data was distributed across 10 clients, with each client receiving approximately 196 records. To simplify training, independent and identically distributed (IID) sampling was used. The test set was reserved for global evaluation.</p>
</sec>
</sec>
<sec id="sec13">
<label>3.3</label>
<title>EADP-FedAvg</title>
<sec id="sec14">
<label>3.3.1</label>
<title>Theoretical foundation</title>
<p>FL enables multiple clients to collaboratively train a global model without sharing their raw data. By relying on local updates and model parameter aggregation, FL inherently supports privacy preservation and is well-suited for distributed educational data scenarios like the one in this study.</p>
<p>However, despite its decentralized structure, FL still presents potential privacy vulnerabilities. Prior research has demonstrated that adversaries can exploit uploaded model parameters or gradients to infer characteristics of the original training data, and in some cases, even reconstruct parts of the raw samples. These attacks are known as gradient inversion attacks or model reconstruction attacks. The fundamental cause lies in the fact that model parameters are directly influenced by training data; thus, they carry imprints of individual samples, especially when client datasets are small or the model architecture is complex. This increases the risk that updates may leak identifiable personal features.</p>
<p>As a result, the structural design of FL alone is insufficient to guarantee complete privacy. To strengthen the privacy protection mechanism, techniques such as DP can be employed. DP introduces randomness to model updates in each training round, statistically masking the influence of any single data point and reducing the identifiability embedded in model parameters.</p>
<p>Differential Privacy achieves this by injecting noise into model outputs or parameters, ensuring that the probability distributions of algorithm outputs over neighboring datasets remain statistically similar. The formal DP definition is shown in <xref ref-type="disp-formula" rid="E2">Equation 2</xref>:</p>
<disp-formula id="E2">
<label>(2)</label>
<mml:math id="M3">
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo stretchy="true">[</mml:mo>
<mml:mi>S</mml:mi>
<mml:mo stretchy="true">(</mml:mo>
<mml:mi>D</mml:mi>
<mml:mo stretchy="true">)</mml:mo>
<mml:mo>&#x2208;</mml:mo>
<mml:mi>T</mml:mi>
<mml:mo stretchy="true">]</mml:mo>
<mml:mo>&#x2264;</mml:mo>
<mml:msup>
<mml:mi>e</mml:mi>
<mml:mi>&#x03B5;</mml:mi>
</mml:msup>
<mml:mo>&#x00B7;</mml:mo>
<mml:msub>
<mml:mi>P</mml:mi>
<mml:mi>r</mml:mi>
</mml:msub>
<mml:mo stretchy="true">[</mml:mo>
<mml:mi>S</mml:mi>
<mml:mo stretchy="true">(</mml:mo>
<mml:mi>D</mml:mi>
<mml:mo>&#x2032;</mml:mo>
<mml:mo stretchy="true">)</mml:mo>
<mml:mo>&#x2208;</mml:mo>
<mml:mi>T</mml:mi>
<mml:mo stretchy="true">]</mml:mo>
<mml:mo>+</mml:mo>
<mml:mi>&#x03B4;</mml:mi>
</mml:math>
</disp-formula>
<p>Here, <italic>&#x03B5;</italic> is the privacy budget that quantifies the strength of the privacy guarantee, and <italic>&#x03B4;</italic> is the failure probability. <italic>S(D)</italic> and <italic>S(D&#x2032;)</italic> denote the algorithm&#x2019;s output distributions over two neighboring datasets, <italic>D</italic> and <italic>D&#x2032;</italic>. Traditional DP-FedAvg methods apply fixed Gaussian noise with the following standard deviation (<xref ref-type="disp-formula" rid="E3">Equation 3</xref>):</p>
<disp-formula id="E3">
<label>(3)</label>
<mml:math id="M4">
<mml:mi>&#x03C3;</mml:mi>
<mml:mo>=</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:mi mathvariant="italic">&#x0394;f</mml:mi>
<mml:mo>&#x00B7;</mml:mo>
<mml:msqrt>
<mml:mrow>
<mml:mn>2</mml:mn>
<mml:mo>ln</mml:mo>
<mml:mo stretchy="true">(</mml:mo>
<mml:mfrac>
<mml:mn>1.25</mml:mn>
<mml:mi>&#x03B4;</mml:mi>
</mml:mfrac>
<mml:mo stretchy="true">)</mml:mo>
</mml:mrow>
</mml:msqrt>
</mml:mrow>
<mml:mi>&#x03B5;</mml:mi>
</mml:mfrac>
<mml:mspace width="0.25em"/>
</mml:math>
</disp-formula>
<p>Where <italic>&#x0394;f</italic> represents the sensitivity of the function. However, using fixed noise often compromises model performance, especially in small-scale or heterogeneous educational data settings. To address this limitation, EADP-FedAvg introduces an entropy-adaptive mechanism. It dynamically adjusts the noise intensity based on the average information entropy of the model&#x2019;s predictions on a test dataset. The adjustment function is shown in <xref ref-type="disp-formula" rid="E4">Equation 4</xref>:</p>
<disp-formula id="E4">
<label>(4)</label>
<mml:math id="M5">
<mml:mi>&#x03C3;</mml:mi>
<mml:mo>=</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:mi mathvariant="italic">&#x0394;f</mml:mi>
<mml:mo>&#x00B7;</mml:mo>
<mml:msqrt>
<mml:mrow>
<mml:mn>2</mml:mn>
<mml:mo>ln</mml:mo>
<mml:mo stretchy="true">(</mml:mo>
<mml:mfrac>
<mml:mn>1.25</mml:mn>
<mml:mi>&#x03B4;</mml:mi>
</mml:mfrac>
<mml:mo stretchy="true">)</mml:mo>
</mml:mrow>
</mml:msqrt>
</mml:mrow>
<mml:mi>&#x03B5;</mml:mi>
</mml:mfrac>
<mml:mo>&#x00B7;</mml:mo>
<mml:mo stretchy="true">(</mml:mo>
<mml:mfrac>
<mml:mn>1</mml:mn>
<mml:mrow>
<mml:mi>avg</mml:mi>
<mml:mo>_</mml:mo>
<mml:mtext>entropy</mml:mtext>
</mml:mrow>
</mml:mfrac>
<mml:mo stretchy="true">)</mml:mo>
<mml:mspace width="0.25em"/>
</mml:math>
</disp-formula>
<p>Where avg_entropy represents the average entropy of predicted probability distributions, calculated as <xref ref-type="disp-formula" rid="E5">Equation 5</xref>:</p>
<disp-formula id="E5">
<label>(5)</label>
<mml:math id="M6">
<mml:mi>avg</mml:mi>
<mml:mo>_</mml:mo>
<mml:mtext>entropy</mml:mtext>
<mml:mo>=</mml:mo>
<mml:mo>&#x2212;</mml:mo>
<mml:mo>&#x2211;</mml:mo>
<mml:msub>
<mml:mi>p</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>log</mml:mo>
<mml:mo stretchy="true">(</mml:mo>
<mml:msub>
<mml:mi>p</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo stretchy="true">)</mml:mo>
<mml:mspace width="0.25em"/>
</mml:math>
</disp-formula>
<p>The fixed privacy budget (&#x03B5;&#x202F;=&#x202F;0.1, &#x03B4;&#x202F;=&#x202F;1e-6) ensures consistent privacy protection across all clients but may not fully accommodate varying privacy needs based on data sensitivity or client heterogeneity. A personalized privacy budget, dynamically adjusting &#x03B5; per client or training phase, could further optimize the privacy-performance trade-off, as explored in future work.</p>
<p>When entropy is high, noise is reduced to improve performance; when entropy is low, noise is increased to enhance privacy protection.</p>
</sec>
<sec id="sec15">
<label>3.3.2</label>
<title>Algorithm design</title>
<p>The EADP-FedAvg algorithm proposed in this study is based on the classic FedAvg framework, with the addition of entropy-adaptive Gaussian noise in the global aggregation phase to enhance differential privacy protection. The core procedure is as follows: first, the server randomly initializes the global model parameters and distributes them to 10 clients, each containing approximately 196 local training samples. Next, each client trains a local MLP model using its data and predefined hyperparameters, completing one local update. Third, each client computes the information entropy based on the predicted probability distribution of its local model on the test data. The server then collects all clients&#x2019; entropy results and calculates the global avg_entropy. In the fourth step, the server aggregates the uploaded model parameters and adds Gaussian noise adaptively based on the current avg_entropy value to achieve differential privacy protection. This process is repeated for a total of 200 communication rounds.</p>
<p>The EADP-FedAvg algorithm in this study is shown in <xref ref-type="table" rid="tab2">Table 2</xref>:</p>
<table-wrap position="float" id="tab2">
<label>Table 2</label>
<caption>
<p>EADP-FedAvg algorithm.</p>
</caption>
<table frame="hsides" rules="groups">
<tbody>
<tr>
<td align="left" valign="top">
<inline-graphic xlink:href="frai-08-1653437-i001.tif" mimetype="image" mime-subtype="tiff">
<alt-text content-type="machine-generated">Flowchart for aggregating local model parameters with differential privacy. Inputs include local model parameters, privacy budget, privacy failure probability, sensitivity, and average information entropy. The output is global model parameters. Steps involve initializing global parameters, aggregating local parameters, computing noise standard deviation, adding differential privacy noise, and returning global parameters. Mathematical operations and loops are detailed for each step.</alt-text>
</inline-graphic>
</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
</sec>
<sec id="sec16">
<label>4</label>
<title>Experimental design</title>
<sec id="sec17">
<label>4.1</label>
<title>Experimental setup</title>
<p>Experiments were conducted on a high-performance computing platform simulating a FL environment with multiple collaborating clients. To improve training efficiency and model convergence speed, the hardware setup included a multi-core CPU and sufficient RAM to ensure smooth parallel computation. On the software side, the PyTorch framework was used, along with techniques such as data loading acceleration, gradient clipping, and the Adam optimizer to enhance training stability and performance. The system configuration is detailed in <xref ref-type="table" rid="tab3">Table 3</xref>:</p>
<table-wrap position="float" id="tab3">
<label>Table 3</label>
<caption>
<p>Experimental environment settings.</p>
</caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th/>
<th align="left" valign="top">Environment</th>
<th align="left" valign="top">System parameters</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" valign="top" rowspan="3">Hardware</td>
<td align="left" valign="top">CPU</td>
<td align="left" valign="top">Intel Core i7-9850H, @4.6&#x202F;GHz, 6&#x6838;</td>
</tr>
<tr>
<td align="left" valign="top">RAM</td>
<td align="left" valign="top">64GB</td>
</tr>
<tr>
<td align="left" valign="middle">GPU</td>
<td align="left" valign="middle">NVIDIA GeForce RTX 2080(8GB GDDR6)</td>
</tr>
<tr>
<td align="left" valign="top" rowspan="4">Software</td>
<td align="left" valign="top">Operating system</td>
<td align="left" valign="top">Windows 10, 64bit</td>
</tr>
<tr>
<td align="left" valign="top">Virtualization</td>
<td align="left" valign="top">VMware Workstation 16</td>
</tr>
<tr>
<td align="left" valign="top">Python</td>
<td align="left" valign="top">Python 3.7</td>
</tr>
<tr>
<td align="left" valign="top">ML Framework</td>
<td align="left" valign="top">Pytorch 1.9.1</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The hardware setup includes a 6-core, 12-thread Intel Core i7-9850H processor with a maximum turbo frequency of 4.6&#x202F;GHz, 64&#x202F;GB of RAM, and a dedicated NVIDIA GeForce RTX 2080 GPU. This configuration effectively supports high-performance parallel training of multiple clients and accelerates model convergence. The software environment runs on 64-bit Windows 10, with the EADP-FedAvg algorithm and MLP model implemented using Python 3.7 and PyTorch 1.9.1. VMware Workstation 16 is used to simulate isolated client environments for distributed FL. The Python environment is equipped with commonly used libraries such as NumPy, SciPy, and Scikit-learn for feature engineering, model evaluation, and statistical analysis. PyTorch offers efficient tensor operations and automatic differentiation to speed up MLP model training and optimization.</p>
<p>The EADP-FedAvg experiment uses 10 clients, each performing local training with an MLP model. The model architecture includes 17 input features, two hidden layers with 128 and 64 neurons respectively, and a final output layer producing probabilities for four classes which is suitable for tabular classification tasks. Training parameters were carefully tuned to balance convergence speed and predictive performance. DP is ensured via the Gaussian mechanism, with noise standard deviation dynamically computed using the entropy-adaptive formula detailed in Section 3.3.1.</p>
<p>The use of 10 clients is intended to strike a balance between computational efficiency and representativeness of data distribution, ensuring each client receives a sufficient number of training samples. This supports stable local training, mitigates biases due to data imbalance, and enhances both model robustness and experimental reproducibility.</p>
<p>The full experimental parameter settings are provided in <xref ref-type="table" rid="tab4">Table 4</xref>.</p>
<table-wrap position="float" id="tab4">
<label>Table 4</label>
<caption>
<p>Experimental parameter settings.</p>
</caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th/>
<th align="left" valign="top">Parameter</th>
<th align="left" valign="top">Value</th>
<th align="left" valign="top">Description</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" valign="top" rowspan="9">FL parameters</td>
<td align="left" valign="top">Number of clients</td>
<td align="left" valign="top">10</td>
<td align="left" valign="top">Simulates distributed training data across 12 classes</td>
</tr>
<tr>
<td align="left" valign="top">Global epochs</td>
<td align="left" valign="top">200</td>
<td align="left" valign="top">Total number of training epochs</td>
</tr>
<tr>
<td align="left" valign="top">Local iterations</td>
<td align="left" valign="top">5</td>
<td align="left" valign="top">Number of local training rounds before each global aggregation</td>
</tr>
<tr>
<td align="left" valign="top">Batch size</td>
<td align="left" valign="top">10</td>
<td align="left" valign="top">Number of samples per batch in local training</td>
</tr>
<tr>
<td align="left" valign="top">Optimizer</td>
<td align="left" valign="top">SGD</td>
<td align="left" valign="top">&#x2013;</td>
</tr>
<tr>
<td align="left" valign="top">Learning rate</td>
<td align="left" valign="top">0.01</td>
<td align="left" valign="top">&#x2013;</td>
</tr>
<tr>
<td align="left" valign="top">Momentum</td>
<td align="left" valign="top">0.5</td>
<td align="left" valign="top">Speeds up convergence and prevents oscillation</td>
</tr>
<tr>
<td align="left" valign="top">Loss function</td>
<td align="left" valign="top">Cross-entropy loss</td>
<td align="left" valign="top">Suitable for 4-class classification tasks</td>
</tr>
<tr>
<td align="left" valign="top">Entropy computation</td>
<td align="left" valign="top">Client-side prediction entropy &#x2192; Server average</td>
<td align="left" valign="top">Each client calculates entropy based on predicted probabilities on the test data, then uploads to the server for aggregation</td>
</tr>
<tr>
<td align="left" valign="top" rowspan="3">Differential privacy parameters</td>
<td align="left" valign="top">Privacy budget &#x03B5;</td>
<td align="left" valign="top">0.1</td>
<td align="left" valign="top">Strength parameter for differential privacy</td>
</tr>
<tr>
<td align="left" valign="top">Tolerance probability &#x03B4;</td>
<td align="left" valign="top">1.00E-06</td>
<td align="left" valign="top">Acceptable probability of privacy breach</td>
</tr>
<tr>
<td align="left" valign="top">Sensitivity &#x0394;f</td>
<td align="left" valign="top">1</td>
<td align="left" valign="top">Sensitivity based on standardized features</td>
</tr>
<tr>
<td align="left" valign="top">Noise mechanism parameters</td>
<td align="left" valign="top">Noise std. deviation &#x03C3;</td>
<td align="left" valign="top">Dynamically adjusted using entropy-adaptive formula</td>
<td align="left" valign="top">See Section 3.3.1 for details</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>To comprehensively evaluate the performance of EADP-FedAvg, two baseline models are set up for comparison. The first is the conventional FL model, which uses the classical FedAvg algorithm. It shares the same MLP architecture and training parameters but does not apply any differential privacy mechanisms. This helps assess the performance of FL without entropy-adaptive enhancements. The second baseline is a centralized learning model, where the MLP is trained directly on the complete dataset of 2,452 records without any privacy protection. This serves as the theoretical upper bound in terms of model performance.</p>
<p>The experiment compares EADP-FedAvg with these two baselines across three evaluation metrics on the test set: accuracy, macro-average score, and average information entropy. The primary goal is to demonstrate that EADP-FedAvg can achieve strong model performance while providing privacy protection under a privacy budget of <italic>&#x03B5;</italic>&#x202F;=&#x202F;0.1. To ensure result stability and reliability, each experiment is repeated 20 times, and the average results are reported to mitigate the effects of randomness.</p>
</sec>
<sec id="sec18">
<label>4.2</label>
<title>Model and parameters</title>
<sec id="sec19">
<label>4.2.1</label>
<title>Model architecture</title>
<p>To accommodate the tabular data structure of the Python Programming course, the EADP-FedAvg method employs a Multi-Layer Perceptron (MLP) model. MLP is a type of feedforward neural network known for its simplicity and efficiency, particularly well-suited for structured data in multi-class classification tasks (<xref ref-type="bibr" rid="ref001">Witten et al., 2016</xref>). The choice of MLP is motivated by the dataset&#x2019;s static tabular format, with 17 features (5 score features, 10 behavioral features, and 2 demographic features) that do not explicitly include time-series information, enabling efficient modeling with low computational complexity. However, behavioral features like login frequency may contain latent temporal patterns (e.g., sequential login activities over the course duration), which MLP cannot fully capture, as discussed in Section 6. The model architecture used in this study is as follows:</p>
<list list-type="order">
<list-item>
<p>Input Layer: 17 features including 5 score features, 10 behavioral features, and 2 demographic features.</p>
</list-item>
<list-item>
<p>Hidden Layer 1: 128 neurons with ReLU activation to capture non-linear relationships among features.</p>
</list-item>
<list-item>
<p>Hidden Layer 2: 64 neurons with ReLU activation to further extract high-level features.</p>
</list-item>
<list-item>
<p>Output Layer: 4 neurons corresponding to the 4 classification labels, outputting class probabilities.</p>
</list-item>
</list>
<p>The forward propagation process of the MLP consists of three sequentially connected linear layers. Between the first two layers, ReLU activation functions are introduced to enhance the model&#x2019;s non-linear expression capability. First, the input data passes through the first linear transformation, followed by ReLU activation to produce the output of Hidden Layer 1. This output then proceeds through the second linear transformation and another ReLU activation, resulting in the output of Hidden Layer 2. Finally, this output is fed into the third linear layer to produce the model&#x2019;s final predictions.</p>
<p>The MLP architecture is relatively simple and has low computational complexity, making it well-suited for small-scale educational data as in this study. It processes 17-dimensional vectors directly, and the total number of trainable parameters in this MLP model is 10,820.</p>
</sec>
<sec id="sec20">
<label>4.2.2</label>
<title>Detailed training procedure</title>
<p>The training process of EADP-FedAvg is based on the Federated Averaging algorithm, with the addition of entropy-adaptive Gaussian noise during the global aggregation phase. To isolate the effect of the entropy-adaptive mechanism and ensure experimental controllability, we assume independently and IID data across the 10 clients, enabling consistent statistical properties. However, in real-world educational settings, client data are often non-IID due to heterogeneous student behaviors such as varying login patterns or learning paces, which may impact global model convergence, as discussed in Section 6.</p>
<p>The steps are as follows:</p>
<list list-type="simple">
<list-item>
<p>1.&#x00A0;&#x00A0;Global Initialization. The central server first initializes the MLP model parameters and randomly distributes the same initial weights to 10 clients.</p>
</list-item>
<list-item>
<p>2.&#x00A0;&#x00A0;Local Training. Each client trains its MLP model using local data, optimizing with the cross-entropy loss function (<xref ref-type="disp-formula" rid="E6">Equation 6</xref>):</p>
</list-item>
</list>
<disp-formula id="E6">
<label>(6)</label>
<mml:math id="M7">
<mml:mi>L</mml:mi>
<mml:mo>=</mml:mo>
<mml:mo>&#x2212;</mml:mo>
<mml:mfrac>
<mml:mn>1</mml:mn>
<mml:mi>n</mml:mi>
</mml:mfrac>
<mml:mo>&#x2211;</mml:mo>
<mml:mo stretchy="true">[</mml:mo>
<mml:msub>
<mml:mi>y</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo>log</mml:mo>
<mml:mo stretchy="true">(</mml:mo>
<mml:mover accent="true">
<mml:msub>
<mml:mi>y</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo stretchy="true">&#x0302;</mml:mo>
</mml:mover>
<mml:mo stretchy="true">)</mml:mo>
<mml:mo>+</mml:mo>
<mml:mo stretchy="true">(</mml:mo>
<mml:mn>1</mml:mn>
<mml:mo>&#x2212;</mml:mo>
<mml:msub>
<mml:mi>y</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo stretchy="true">)</mml:mo>
<mml:mo>log</mml:mo>
<mml:mo stretchy="true">(</mml:mo>
<mml:mn>1</mml:mn>
<mml:mo>&#x2212;</mml:mo>
<mml:mover accent="true">
<mml:msub>
<mml:mi>y</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo stretchy="true">&#x0302;</mml:mo>
</mml:mover>
<mml:mo stretchy="true">)</mml:mo>
<mml:mo stretchy="true">]</mml:mo>
<mml:mspace width="0.25em"/>
</mml:math>
</disp-formula>
<p>Which <inline-formula>
<mml:math id="M8">
<mml:msub>
<mml:mi>y</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
</mml:math>
</inline-formula> represents the true label, <inline-formula>
<mml:math id="M9">
<mml:mover accent="true">
<mml:msub>
<mml:mi>y</mml:mi>
<mml:mi>i</mml:mi>
</mml:msub>
<mml:mo stretchy="true">&#x0302;</mml:mo>
</mml:mover>
</mml:math>
</inline-formula> represents the predicted probability, and n is the number of samples.</p>
<list list-type="simple">
<list-item>
<p>3.&#x00A0;&#x00A0;Entropy Computation. Each client computes the information entropy based on the predicted probability distribution of its local model on the test data. These entropy values are sent to the server and averaged to generate the global average entropy, as described in Section 3.3.1.</p>
</list-item>
<list-item>
<p>4.&#x00A0;&#x00A0;Global Aggregation. The server receives the locally trained model parameters from the 10 clients and performs a weighted average to update the global model. To enhance privacy protection, entropy-adaptive Gaussian noise is added to the aggregated parameters in accordance with differential privacy constraints (<xref ref-type="disp-formula" rid="E7">Equation 7</xref>). The noise standard deviation and addition mechanism are detailed in Section 3.3.1. The noise is added to each layer&#x2019;s aggregated weights:</p>
</list-item>
</list>
<disp-formula id="E7">
<label>(7)</label>
<mml:math id="M10">
<mml:msub>
<mml:mi>w</mml:mi>
<mml:mi>avg</mml:mi>
</mml:msub>
<mml:mo stretchy="true">[</mml:mo>
<mml:mi>k</mml:mi>
<mml:mo stretchy="true">]</mml:mo>
<mml:mo>=</mml:mo>
<mml:mi>dp</mml:mi>
<mml:mo>_</mml:mo>
<mml:mi>add</mml:mi>
<mml:mo>_</mml:mo>
<mml:mtext>noise</mml:mtext>
<mml:mo stretchy="true">(</mml:mo>
<mml:msub>
<mml:mi>w</mml:mi>
<mml:mi>avg</mml:mi>
</mml:msub>
<mml:mo stretchy="true">[</mml:mo>
<mml:mi>k</mml:mi>
<mml:mo stretchy="true">]</mml:mo>
<mml:mo>,</mml:mo>
<mml:mi mathvariant="normal">&#x03C3;</mml:mi>
<mml:mo stretchy="true">)</mml:mo>
</mml:math>
</disp-formula>
<p>Which <inline-formula>
<mml:math id="M11">
<mml:msub>
<mml:mi>w</mml:mi>
<mml:mi>avg</mml:mi>
</mml:msub>
<mml:mo stretchy="true">[</mml:mo>
<mml:mi>k</mml:mi>
<mml:mo stretchy="true">]</mml:mo>
</mml:math>
</inline-formula> represents the aggregated weights of the <inline-formula>
<mml:math id="M12">
<mml:mi>k</mml:mi>
<mml:mo>&#x2212;</mml:mo>
<mml:mi mathvariant="italic">th</mml:mi>
</mml:math>
</inline-formula> layer, and the <inline-formula>
<mml:math id="M13">
<mml:mi>dp</mml:mi>
<mml:mo>_</mml:mo>
<mml:mi>add</mml:mi>
<mml:mo>_</mml:mo>
<mml:mtext>noise</mml:mtext>
</mml:math>
</inline-formula> function adds Gaussian noise to those parameters.</p>
<list list-type="simple">
<list-item>
<p>5.&#x00A0;&#x00A0;Model Broadcasting. The updated global parameters are broadcast back to each client to commence the next training round.</p>
</list-item>
<list-item>
<p>6.&#x00A0;&#x00A0;Epochs Termination. The global training proceeds for 200 epochs until completion.</p>
</list-item>
</list>
</sec>
<sec id="sec21">
<label>4.2.3</label>
<title>Parameter settings</title>
<p>Key parameters of the MLP and EADP-FedAvg were tuned to ensure convergence and privacy protection, as summarized in <xref ref-type="table" rid="tab5">Table 5</xref>:</p>
<table-wrap position="float" id="tab5">
<label>Table 5</label>
<caption>
<p>Overview of EADP-FedAvg and MLP parameter configuration.</p>
</caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th align="left" valign="top">Category</th>
<th align="left" valign="top">Parameter name</th>
<th align="left" valign="top">Value or description</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" valign="top" rowspan="7">Model parameters</td>
<td align="left" valign="top">Input dimension</td>
<td align="left" valign="top">17</td>
</tr>
<tr>
<td align="left" valign="top">Output dimension</td>
<td align="left" valign="top">4</td>
</tr>
<tr>
<td align="left" valign="top">Activation function</td>
<td align="left" valign="top">ReLU</td>
</tr>
<tr>
<td align="left" valign="top">Hidden layer structure</td>
<td/>
</tr>
<tr>
<td align="left" valign="top">&#x251C;&#x2500; Layer 1</td>
<td align="left" valign="top">Linear(17&#x202F;&#x2192;&#x202F;128), ReLU</td>
</tr>
<tr>
<td align="left" valign="top">&#x251C;&#x2500; Layer 2</td>
<td align="left" valign="top">Linear(128&#x202F;&#x2192;&#x202F;64), ReLU</td>
</tr>
<tr>
<td align="left" valign="top">&#x2514;&#x2500; Output layer</td>
<td align="left" valign="top">Linear(64&#x202F;&#x2192;&#x202F;4 &#x6216; 2), No activation</td>
</tr>
<tr>
<td align="left" valign="top" rowspan="7">Training parameters</td>
<td align="left" valign="top">Number of clients</td>
<td align="left" valign="top">10</td>
</tr>
<tr>
<td align="left" valign="top">Global communication epochs</td>
<td align="left" valign="top">200</td>
</tr>
<tr>
<td align="left" valign="top">Local iterations per Client</td>
<td align="left" valign="top">5</td>
</tr>
<tr>
<td align="left" valign="top">Batch size</td>
<td align="left" valign="top">10</td>
</tr>
<tr>
<td align="left" valign="top">Learning rate</td>
<td align="left" valign="top">0.01</td>
</tr>
<tr>
<td align="left" valign="top">Momentum</td>
<td align="left" valign="top">0.5</td>
</tr>
<tr>
<td align="left" valign="top">Loss function</td>
<td align="left" valign="top">Cross Entropy</td>
</tr>
<tr>
<td align="left" valign="top" rowspan="3">Privacy parameters</td>
<td align="left" valign="top">Privacy budget</td>
<td align="left" valign="top">&#x03B5;&#x202F;=&#x202F;0.1, &#x03B4;&#x202F;=&#x202F;1e<sup>&#x2212;6</sup></td>
</tr>
<tr>
<td align="left" valign="top">Sensitivity</td>
<td align="left" valign="top">&#x2206;<italic>f</italic> =&#x202F;1.0</td>
</tr>
<tr>
<td align="left" valign="top">Noise</td>
<td align="left" valign="top">Gaussian Mechanism</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
</sec>
</sec>
<sec id="sec22">
<label>5</label>
<title>Experimental results and analysis</title>
<sec id="sec23">
<label>5.1</label>
<title>Comparative analysis of the training</title>
<p>Performance evaluation employs the following metrics:</p>
<list list-type="simple">
<list-item>
<p>1.&#x00A0;&#x00A0;Accuracy. The proportion of correctly predicted samples, it is calculated as shown in <xref ref-type="disp-formula" rid="E8">Equation 8</xref>:</p>
</list-item>
</list>
<disp-formula id="E8">
<label>(8)</label>
<mml:math id="M14">
<mml:mtext>Accuracy</mml:mtext>
<mml:mo>=</mml:mo>
<mml:mfrac>
<mml:mrow>
<mml:msubsup>
<mml:mo>&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>=</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mi>k</mml:mi>
</mml:msubsup>
<mml:msub>
<mml:mi>TP</mml:mi>
<mml:mi mathvariant="normal">i</mml:mi>
</mml:msub>
</mml:mrow>
<mml:mrow>
<mml:msubsup>
<mml:mo>&#x2211;</mml:mo>
<mml:mrow>
<mml:mi>i</mml:mi>
<mml:mo>=</mml:mo>
<mml:mn>1</mml:mn>
</mml:mrow>
<mml:mi>k</mml:mi>
</mml:msubsup>
<mml:mo stretchy="true">(</mml:mo>
<mml:msub>
<mml:mi>TP</mml:mi>
<mml:mi mathvariant="normal">i</mml:mi>
</mml:msub>
<mml:mo>+</mml:mo>
<mml:msub>
<mml:mi>TN</mml:mi>
<mml:mi mathvariant="normal">i</mml:mi>
</mml:msub>
<mml:mo>+</mml:mo>
<mml:msub>
<mml:mi>FP</mml:mi>
<mml:mi mathvariant="normal">i</mml:mi>
</mml:msub>
<mml:mo>+</mml:mo>
<mml:msub>
<mml:mi>FN</mml:mi>
<mml:mi mathvariant="normal">i</mml:mi>
</mml:msub>
<mml:mo stretchy="true">)</mml:mo>
</mml:mrow>
</mml:mfrac>
<mml:mspace width="0.25em"/>
</mml:math>
</disp-formula>
<list list-type="simple">
<list-item>
<p>2.&#x00A0;&#x00A0;Training Loss. Cross-entropy loss, measuring model convergence (formula in Section 4.2.2).</p>
</list-item>
<list-item>
<p>3.&#x00A0;&#x00A0;Average Information Entropy. Quantifies the uncertainty of the predictions and guides the noise adjustment in EADP-FedAvg (formula in Section 3.3.1).</p>
</list-item>
</list>
<p>Each of the three models was trained on the training set over 20 independent random trials, with each trial running for 200 epochs. The training data presented here represent the average results from these 20 trials.</p>
<p>In the centralized learning training process shown in <xref ref-type="fig" rid="fig1">Figure 1</xref>, the model&#x2019;s loss converges to 0.055, indicating excellent optimization. Accuracy stabilizes around the 150th epoch, reaching 98%. After 200 epochs, the average information entropy remains low at 0.111, demonstrating the model&#x2019;s strong grasp of the data distribution and efficient fitting.</p>
<fig position="float" id="fig1">
<label>Figure 1</label>
<caption>
<p>Centralized learning training process.</p>
</caption>
<graphic xlink:href="frai-08-1653437-g001.tif" mimetype="image" mime-subtype="tiff">
<alt-text content-type="machine-generated">Three line graphs display training metrics over 200 epochs. The left graph shows average loss decreasing from 1.1 to 0.055. The center graph shows average accuracy increasing to 98.343%. The right graph shows average entropy decreasing to 0.111.</alt-text>
</graphic>
</fig>
<p><xref ref-type="fig" rid="fig2">Figure 2</xref> illustrates the training performance of DP-FedAvg under privacy protection mechanisms. The model&#x2019;s loss converges at 0.188, noticeably higher than centralized learning. Accuracy reaches 88.577% after 200 epochs. However, due to the additional noise introduced by differential privacy, the average information entropy increases to 0.374, indicating increased uncertainty in predictions despite maintaining reasonable accuracy.</p>
<fig position="float" id="fig2">
<label>Figure 2</label>
<caption>
<p>DP-FedAvg training process.</p>
</caption>
<graphic xlink:href="frai-08-1653437-g002.tif" mimetype="image" mime-subtype="tiff">
<alt-text content-type="machine-generated">Three graphs depict training metrics over epochs. Left: Average training loss decreases, flattening around 0.188. Center: Average training accuracy rises to about 88.577%. Right: Average entropy declines, stabilizing near 0.374. Each graph includes 20 runs.</alt-text>
</graphic>
</fig>
<p><xref ref-type="fig" rid="fig3">Figure 3</xref> presents the training process of EADP-FedAvg, which incorporates entropy-adaptive noise adjustment. Under this improved strategy, the model loss converges faster to just 0.01. Accuracy improves to 91.229% at 200 epochs, showing a clear enhancement compared to DP-FedAvg. Meanwhile, average information entropy drops to 0.207, reflecting a better balance between privacy protection and model performance achieved by the entropy-adaptive mechanism.</p>
<fig position="float" id="fig3">
<label>Figure 3</label>
<caption>
<p>EADP-FedAvg training process.</p>
</caption>
<graphic xlink:href="frai-08-1653437-g003.tif" mimetype="image" mime-subtype="tiff">
<alt-text content-type="machine-generated">Three line graphs showing training metrics over epochs during 20 runs. The first graph, in blue, depicts training loss decreasing from 1.0 to approximately 0.01. The second graph, in green, shows accuracy increasing from around 63 percent to 91.229 percent. The third graph, in orange, illustrates average entropy declining from 1.4 to 0.207. The parameters Epsilon, Delta, and Sensitivity are shown as 0.1, 1e-06, and 1.0, respectively.</alt-text>
</graphic>
</fig>
<p>Overall, the experimental results demonstrate that EADP-FedAvg outperforms DP-FedAvg with superior convergence, achieving lower training loss and higher accuracy after 200 epochs. This improvement stems from the entropy-adaptive noise mechanism, which dynamically reduces noise interference when prediction uncertainty is high, thereby preserving more useful information. Although centralized learning attains the highest accuracy and lowest entropy with minimal loss, it lacks any data privacy protection. In contrast, EADP-FedAvg effectively balances privacy protection and convergence efficiency while maintaining strong model performance.</p>
</sec>
<sec id="sec24">
<label>5.2</label>
<title>Comparative analysis in the testing</title>
<p>To further compare the generalization performance of the three models in multi-class classification tasks, <xref ref-type="table" rid="tab6">Tables 6</xref>&#x2013;<xref ref-type="table" rid="tab8">8</xref> present the confusion matrix results on the test set for centralized learning, DP-FedAvg, and EADP-FedAvg, respectively. The four predicted labels&#x2014;Fail, Passed, Good, and Excellent&#x2014;correspond to students&#x2019; performance levels in the course. Below each confusion matrix, the Precision for each class is provided to evaluate the model&#x2019;s local prediction accuracy.</p>
<table-wrap position="float" id="tab6">
<label>Table 6</label>
<caption>
<p>Confusion matrix for centralized learning.</p>
</caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th rowspan="2" colspan="2"/>
<th align="center" valign="top" colspan="4">
<bold>Predicted</bold>
</th>
</tr>
<tr>
<th align="center" valign="middle">
<bold>Fail</bold>
</th>
<th align="center" valign="middle">
<bold>Passed</bold>
</th>
<th align="center" valign="middle">
<bold>Good</bold>
</th>
<th align="center" valign="middle">
<bold>Excellent</bold>
</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" valign="middle" rowspan="4">Actual</td>
<td align="center" valign="middle">Fail</td>
<td align="center" valign="middle">69</td>
<td align="center" valign="middle">2</td>
<td align="center" valign="middle">1</td>
<td align="center" valign="middle">0</td>
</tr>
<tr>
<td align="center" valign="middle">Passed</td>
<td align="center" valign="middle">1</td>
<td align="center" valign="middle">144</td>
<td align="center" valign="middle">0</td>
<td align="center" valign="middle">3</td>
</tr>
<tr>
<td align="center" valign="middle">Good</td>
<td align="center" valign="middle">2</td>
<td align="center" valign="middle">3</td>
<td align="center" valign="middle">173</td>
<td align="center" valign="middle">2</td>
</tr>
<tr>
<td align="center" valign="middle">Excellent</td>
<td align="center" valign="middle">0</td>
<td align="center" valign="middle">0</td>
<td align="center" valign="middle">1</td>
<td align="center" valign="middle">90</td>
</tr>
<tr>
<td rowspan="2"/>
<td align="center" valign="middle">Total</td>
<td align="center" valign="top">72</td>
<td align="center" valign="top">149</td>
<td align="center" valign="top">175</td>
<td align="center" valign="top">95</td>
</tr>
<tr>
<td align="center" valign="middle">Precision</td>
<td align="center" valign="top">0.958</td>
<td align="center" valign="top">0.966</td>
<td align="center" valign="top">0.989</td>
<td align="center" valign="top">0.947</td>
</tr>
</tbody>
</table>
</table-wrap>
<table-wrap position="float" id="tab7">
<label>Table 7</label>
<caption>
<p>Confusion matrix for DP-FedAvg.</p>
</caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th rowspan="2" colspan="2"/>
<th align="center" valign="top" colspan="4">
<bold>Predicted</bold>
</th>
</tr>
<tr>
<th align="center" valign="middle">
<bold>Fail</bold>
</th>
<th align="center" valign="middle">
<bold>Passed</bold>
</th>
<th align="center" valign="middle">
<bold>Good</bold>
</th>
<th align="center" valign="middle">
<bold>Excellent</bold>
</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" valign="middle" rowspan="4">Actual</td>
<td align="center" valign="middle">Fail</td>
<td align="center" valign="middle">60</td>
<td align="center" valign="middle">7</td>
<td align="center" valign="middle">4</td>
<td align="center" valign="middle">1</td>
</tr>
<tr>
<td align="center" valign="middle">Passed</td>
<td align="center" valign="middle">5</td>
<td align="center" valign="middle">131</td>
<td align="center" valign="middle">7</td>
<td align="center" valign="middle">5</td>
</tr>
<tr>
<td align="center" valign="middle">Good</td>
<td align="center" valign="middle">3</td>
<td align="center" valign="middle">8</td>
<td align="center" valign="middle">158</td>
<td align="center" valign="middle">11</td>
</tr>
<tr>
<td align="center" valign="middle">Excellent</td>
<td align="center" valign="middle">1</td>
<td align="center" valign="middle">1</td>
<td align="center" valign="middle">3</td>
<td align="center" valign="middle">86</td>
</tr>
<tr>
<td rowspan="2"/>
<td align="center" valign="middle">Total</td>
<td align="center" valign="top">69</td>
<td align="center" valign="top">147</td>
<td align="center" valign="top">172</td>
<td align="center" valign="top">103</td>
</tr>
<tr>
<td align="center" valign="middle">Precision</td>
<td align="center" valign="top">0.870</td>
<td align="center" valign="top">0.891</td>
<td align="center" valign="top">0.919</td>
<td align="center" valign="top">0.835</td>
</tr>
</tbody>
</table>
</table-wrap>
<table-wrap position="float" id="tab8">
<label>Table 8</label>
<caption>
<p>Confusion Matrix for EADP-FedAvg.</p>
</caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th rowspan="2" colspan="2"/>
<th align="left" valign="top" colspan="4">
<bold>Predicted</bold>
</th>
</tr>
<tr>
<th align="center" valign="middle">
<bold>Fail</bold>
</th>
<th align="center" valign="middle">
<bold>Passed</bold>
</th>
<th align="center" valign="middle">
<bold>Good</bold>
</th>
<th align="center" valign="middle">
<bold>Excellent</bold>
</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" valign="middle" rowspan="4">Actual</td>
<td align="center" valign="middle">Fail</td>
<td align="center" valign="middle">68</td>
<td align="center" valign="middle">3</td>
<td align="center" valign="middle">1</td>
<td align="center" valign="middle">0</td>
</tr>
<tr>
<td align="center" valign="middle">Passed</td>
<td align="center" valign="middle">4</td>
<td align="center" valign="middle">135</td>
<td align="center" valign="middle">6</td>
<td align="center" valign="middle">3</td>
</tr>
<tr>
<td align="center" valign="middle">Good</td>
<td align="center" valign="middle">2</td>
<td align="center" valign="middle">5</td>
<td align="center" valign="middle">164</td>
<td align="center" valign="middle">9</td>
</tr>
<tr>
<td align="center" valign="middle">Excellent</td>
<td align="center" valign="middle">0</td>
<td align="center" valign="middle">1</td>
<td align="center" valign="middle">2</td>
<td align="center" valign="middle">88</td>
</tr>
<tr>
<td rowspan="2"/>
<td align="center" valign="middle">Total</td>
<td align="center" valign="top">74</td>
<td align="center" valign="top">144</td>
<td align="center" valign="top">173</td>
<td align="center" valign="top">100</td>
</tr>
<tr>
<td align="center" valign="middle">Precision</td>
<td align="center" valign="top">0.919</td>
<td align="center" valign="top">0.938</td>
<td align="center" valign="top">0.948</td>
<td align="center" valign="top">0.880</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>From the results, the centralized learning model demonstrates the highest accuracy across all categories. In particular, the <italic>Good</italic> and <italic>Passed</italic> categories achieve Precisions of 0.989 and 0.966, respectively, reflecting superior overall predictive performance with minimal misclassification.</p>
<p>In contrast, the performance of the DP-FedAvg model drops notably after introducing fixed-intensity noise (<italic>&#x03B5;</italic>&#x202F;=&#x202F;0.1). Precision for the <italic>Fail</italic> class falls to 0.87, and for the <italic>Excellent</italic> class to 0.835, suggesting reduced stability in predictions under differential privacy constraints. The EADP-FedAvg model, on the other hand, incorporates an entropy-adaptive noise mechanism. By dynamically adjusting noise levels while maintaining the same privacy budget, it improves predictive accuracy. In the <italic>Good</italic> and <italic>Passed</italic> classes, Precisions reach 0.948 and 0.938 respectively, which is significantly better than DP-FedAvg and approaching the level of centralized learning.</p>
<p>The final summary of experimental results is as follows:</p>
<p><xref ref-type="table" rid="tab9">Table 9</xref> provides an overview of the overall performance of the three models. The centralized model ranks highest in accuracy (0.969), macro average score (0.965), and lowest average entropy (0.111), but it lacks any privacy-preserving capability.</p>
<table-wrap position="float" id="tab9">
<label>Table 9</label>
<caption>
<p>Summary of performance comparison.</p>
</caption>
<table frame="hsides" rules="groups">
<thead>
<tr>
<th align="left" valign="top">Model</th>
<th align="left" valign="top">Accuracy</th>
<th align="left" valign="top">Macro average score</th>
<th align="left" valign="top">Average entropy</th>
</tr>
</thead>
<tbody>
<tr>
<td align="left" valign="top">Centralized machine learning</td>
<td align="center" valign="top">0.969</td>
<td align="center" valign="top">0.965</td>
<td align="center" valign="top">0.111</td>
</tr>
<tr>
<td align="left" valign="top">DP-FedAvg</td>
<td align="center" valign="top">0.886</td>
<td align="center" valign="top">0.879</td>
<td align="center" valign="top">0.374</td>
</tr>
<tr>
<td align="left" valign="top">EADP-FedAvg</td>
<td align="center" valign="top">0.927</td>
<td align="center" valign="top">0.921</td>
<td align="center" valign="top">0.207</td>
</tr>
</tbody>
</table>
</table-wrap>
<p>The DP-FedAvg model shows decreased accuracy (0.886) and increased average entropy (0.374), indicating higher uncertainty in predictions under privacy constraints.</p>
<p>EADP-FedAvg demonstrates notable improvements, with accuracy rising to 0.927 and macro average score to 0.921, while average entropy drops to 0.207&#x2014;validating the effectiveness of the entropy-adaptive mechanism in enhancing model robustness and performance.</p>
<p>Moreover, EADP-FedAvg shows a marked improvement in recognizing high-performing students (<italic>Excellent</italic> category), with recall increasing by approximately 4% compared to DP-FedAvg. This is particularly important in evaluation systems, such as programming courses, where high-end performance matters significantly.</p>
<p>By dynamically adjusting the noise scale based on average entropy, the model achieves an effective trade-off between privacy preservation and predictive performance. This design demonstrates strong stability in heterogeneous data environments&#x2014;such as those combining academic scores and behavioral features&#x2014;and offers promising potential for generalization and privacy adaptability.</p>
</sec>
</sec>
<sec sec-type="conclusions" id="sec25">
<label>6</label>
<title>Conclusion</title>
<p>This study proposed an EADP-FedAvg, designed to predict student performance in engineering education scenarios. The dataset was collected from the School of Physics and Optoelectronic Technology at Baoji University of Arts and Sciences, covering students majoring in Electronic Engineering from cohorts 2021 to 2023. It includes 2,452 records from online assessments in the Python Programming course. Under a strict privacy budget (<italic>&#x03B5;</italic>&#x202F;=&#x202F;0.1, <italic>&#x03B4;</italic>&#x202F;=&#x202F;1e-6), the proposed model successfully protected individual student data while achieving high predictive performance. On the test set, EADP-FedAvg attained an accuracy of 92.7%, significantly outperforming the conventional DP-FedAvg (88.6%) and approaching the performance upper bound of centralized machine learning (96.9%), demonstrating both adaptability and practical utility.</p>
<p>The core advantage of EADP-FedAvg lies in its integration of FL&#x2019;s distributed architecture with an entropy-adaptive differential privacy mechanism. The model dynamically reduces the intensity of added noise during high-entropy phases, thereby minimizing disruption to training, while increasing noise in low-entropy phases to reinforce privacy protection. This effectively mitigates the performance degradation commonly caused by static-noise mechanisms. As shown in Section 5.1, after 200 training rounds, the final loss of the EADP-FedAvg model converged to 0.01, and its accuracy reached 91.229%, outperforming DP-FedAvg&#x2019;s final loss of 0.188 and accuracy of 88.577%. Moreover, the model&#x2019;s average information entropy significantly decreased to 0.207&#x2014;substantially lower than DP-FedAvg&#x2019;s 0.374&#x2014;indicating greater predictive certainty and model stability, thereby confirming the practical effectiveness of EADP-FedAvg&#x2019;s theoretical foundation.</p>
<p>Despite the promising results, the study has several limitations. First, the dataset, sourced from a Python programming course at a single institution and focused on students from a single major, may not fully capture the diversity of broader educational contexts. Although the dataset includes 2,452 records and the EADP-FedAvg method has been rigorously validated in this specific setting, achieving a test accuracy of 92.7%, its generalizability to other institutions or disciplines remains to be explored. Second, the use of a fixed privacy budget (<italic>&#x03B5;</italic> =&#x202F;0.1, <italic>&#x03B4;</italic> =&#x202F;1e-6) ensures consistent privacy protection across all clients but may not fully accommodate varying privacy needs based on data sensitivity, client heterogeneity, or task requirements. This uniform approach, while effective in achieving 92.7% test accuracy, could introduce excessive noise for less sensitive data or insufficient protection for highly sensitive data, potentially impacting model performance in diverse educational scenarios. Third, the model is based on an MLP architecture, which, while effective for the static tabular data used in this study, lacks the capability to model temporal dependencies inherent in students&#x2019; learning behaviors, such as sequential patterns in login activities or performance trends over the course duration. Moreover, the study compares only three models, including centralized machine learning, DP-FedAvg, and EADP-FedAvg, all using the MLP architecture, as shown in <xref ref-type="table" rid="tab9">Table 9</xref>. This limits the exploration of diverse architectures and federated learning algorithms, potentially restricting the evaluation of EADP-FedAvg&#x2019;s robustness across varied settings. Finally, for experimental simplicity, the study assumes independently and IID data across the 10 clients for training and testing, as detailed in Section 4.2.2. This assumption, while enabling controlled evaluation of EADP-FedAvg&#x2019;s entropy-adaptive mechanism, does not address the more realistic non-IID distribution prevalent in federated learning, where client data may exhibit heterogeneous distributions. Such heterogeneity could degrade global model convergence or introduce biased predictions in real-world educational settings.</p>
<p>To address these limitations, future work can explore several directions for improvement and extension. First, to enhance the generalizability of EADP-FedAvg, we plan to validate the model across datasets from multiple institutions and diverse academic disciplines, such as Computer Science, Mechanical Engineering, and Mathematics, as well as different course types like Java Programming or Data Science, to ensure robustness across varied educational contexts, as detailed in <xref ref-type="supplementary-material" rid="SM1">Supplementary Table S1</xref>. Second, to address varying privacy needs, we plan to develop a dynamic privacy budget control mechanism, adjusting <italic>&#x03B5;</italic> based on factors such as data sensitivity, client-specific entropy levels, or training phases, to optimize the privacy-performance trade-off across heterogeneous educational datasets, as outlined in <xref ref-type="supplementary-material" rid="SM1">Supplementary Table S4</xref>. Third, to capture temporal dependencies in student behavior data, we plan to explore alternative model architectures, such as Recurrent Neural Networks (RNNs) or Transformers, to model sequential patterns like login sequences or performance trends over the course duration, and compare these with MLP and centralized models, as detailed in <xref ref-type="supplementary-material" rid="SM1">Supplementary Table S3</xref>. Fourth, to address the non-IID nature of real-world educational datasets, we plan to develop personalized federated learning algorithms, such as client clustering based on behavioral similarity or local model fine-tuning with meta-learning techniques, such as Model-Agnostic Meta-Learning (MAML). These approaches will mitigate the impact of heterogeneous student behaviors on global model convergence. Finally, to enhance deployment efficiency, we plan to explore techniques such as asynchronous updates, model compression, and gradient sparsification. To further enhance transparency while adhering to privacy constraints, we plan to explore sharing aggregated or synthetic datasets compliant with China&#x2019;s Personal Information Protection Law (PIPL) and ethical guidelines, as detailed in <xref ref-type="supplementary-material" rid="SM1">Supplementary Table S5</xref>. All detailed enhancement plans are provided in the <xref ref-type="supplementary-material" rid="SM1">Supplementary material</xref> document.</p>
<p>The proposed EADP-FedAvg approach achieves a desirable balance between accuracy and privacy preservation, offering a practical path for privacy-aware modeling and intelligent learning analytics in engineering education. Future research will continue to enhance the model&#x2019;s generalization capabilities, improve temporal modeling, and expand support for personalized privacy mechanisms, advancing the application of FL in the domain of intelligent education systems.</p>
</sec>
</body>
<back>
<sec sec-type="data-availability" id="sec26">
<title>Data availability statement</title>
<p>The datasets presented in this article are not readily available because the datasets (2,452 records from a Python programming course at Baoji University of Arts and Sciences) contain sensitive student information and are protected under China&#x2019;s Personal Information Protection Law (PIPL) and institutional ethical guidelines (Approval No.: BJWLXY-2024-023), precluding public availability. Researchers may request access to the anonymized dataset by contacting the Ethics Committee of the School of Education, Baoji University of Arts and Sciences or the correspondence author, subject to approval and data use agreements. Requests to access the datasets should be directed to <email>webmaster@bjwlxy.edu.cn</email> or Shanwei Chen, <email>chenshanwei@bjwlxy.edu.cn</email>.</p>
</sec>
<sec sec-type="ethics-statement" id="sec27">
<title>Ethics statement</title>
<p>The studies involving humans were approved by ethics committee on human experimentation School of Education Baoji University of Arts and Sciences. The studies were conducted in accordance with the local legislation and institutional requirements. Written informed consent for participation was not required from the participants or the participants&#x2019; legal guardians/next of kin in accordance with the national legislation and institutional requirements.</p>
</sec>
<sec sec-type="author-contributions" id="sec28">
<title>Author contributions</title>
<p>SC: Conceptualization, Methodology, Software, Writing &#x2013; original draft. XQ: Data curation, Investigation, Visualization, Writing &#x2013; original draft.</p>
</sec>
<sec sec-type="funding-information" id="sec29">
<title>Funding</title>
<p>The author(s) declare that financial support was received for the research and/or publication of this article. This research was funded by the Humanities and Social Science Fund of Ministry of Education of China (MOE), grant number 23XJA880001.</p>
</sec>
<ack>
<p>The authors are grateful to the Humanities and Social Science Fund of Minis-try of Education of China (MOE) with grant number 23XJA880001, which helped fund the research. The authors also thank Baoji University of Arts and Sciences that helped manage the grant. Meanwhile, the authors would like to thank the editor and reviewers for their useful comments and suggestions, which were greatly help in improving the quality of the paper.</p>
</ack>
<sec sec-type="COI-statement" id="sec30">
<title>Conflict of interest</title>
<p>The authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.</p>
</sec>
<sec sec-type="ai-statement" id="sec31">
<title>Generative AI statement</title>
<p>The authors declare that no Gen AI was used in the creation of this manuscript.</p>
<p>Any alternative text (alt text) provided alongside figures in this article has been generated by Frontiers with the support of artificial intelligence and reasonable efforts have been made to ensure accuracy, including review by the authors wherever possible. If you identify any issues, please contact us.</p>
</sec>
<sec sec-type="disclaimer" id="sec32">
<title>Publisher&#x2019;s note</title>
<p>All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.</p>
</sec>
<sec sec-type="supplementary-material" id="sec33">
<title>Supplementary material</title>
<p>The Supplementary material for this article can be found online at: <ext-link xlink:href="https://www.frontiersin.org/articles/10.3389/frai.2025.1653437/full#supplementary-material" ext-link-type="uri">https://www.frontiersin.org/articles/10.3389/frai.2025.1653437/full#supplementary-material</ext-link></p>
<supplementary-material xlink:href="Table_1.DOCX" id="SM1" mimetype="application/vnd.openxmlformats-officedocument.wordprocessingml.document" xmlns:xlink="http://www.w3.org/1999/xlink"/>
</sec>
<ref-list>
<title>References</title>
<ref id="ref1"><citation citation-type="other"><person-group person-group-type="author"><name><surname>Afrose</surname><given-names>S.</given-names></name> <name><surname>Hashem</surname><given-names>T.</given-names></name> <name><surname>Ali</surname><given-names>M. E.</given-names></name></person-group> (<year>2021</year>). &#x201C;<article-title>Frequent itemsets mining with a guaranteed local differential privacy in small datasets</article-title>&#x201D; in <source>Proceedings of the 33rd international conference on scientific and statistical database management</source>.</citation></ref>
<ref id="ref2"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Bonawitz</surname><given-names>K.</given-names></name> <name><surname>Kairouz</surname><given-names>P.</given-names></name> <name><surname>McMahan</surname><given-names>B.</given-names></name> <name><surname>Ramage</surname><given-names>D.</given-names></name></person-group> (<year>2021</year>). <article-title>Federated learning and privacy: building privacy-preserving systems for machine learning and data science on decentralized data</article-title>. <source>Queue</source> <volume>19</volume>, <fpage>87</fpage>&#x2013;<lpage>114</lpage>. doi: <pub-id pub-id-type="doi">10.1145/3494834.3500240</pub-id></citation></ref>
<ref id="ref3"><citation citation-type="other"><person-group person-group-type="author"><name><surname>Chicaiza</surname><given-names>J.</given-names></name> <name><surname>Cabrera-Loayza</surname><given-names>M. C.</given-names></name> <name><surname>Elizalde</surname><given-names>R.</given-names></name> <name><surname>Piedra</surname><given-names>N.</given-names></name></person-group> (<year>2020</year>). &#x201C;<article-title>Application of data anonymization in learning analytics</article-title>&#x201D; in <source>Proceedings of the 3rd international conference on applications of intelligent systems</source>.</citation></ref>
<ref id="ref4"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Christiansen</surname><given-names>S. H.</given-names></name> <name><surname>Juebei</surname><given-names>C.</given-names></name> <name><surname>Xiangyun</surname><given-names>D.</given-names></name></person-group> (<year>2023</year>). <article-title>Cross-institutional collaboration in engineering education&#x2013;a systematic review study</article-title>. <source>Eur. J. Eng. Educ.</source> <volume>48</volume>, <fpage>1102</fpage>&#x2013;<lpage>1129</lpage>. doi: <pub-id pub-id-type="doi">10.1080/03043797.2023.2228727</pub-id></citation></ref>
<ref id="ref5"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Elgabli</surname><given-names>A.</given-names></name> <name><surname>Mesbah</surname><given-names>W.</given-names></name></person-group> (<year>2024</year>). <article-title>A novel approach for differential privacy-preserving federated learning</article-title>. <source>IEEE Open J. Commun. Soc.</source> <volume>1</volume>, <fpage>1</fpage>&#x2013;<lpage>10</lpage>. doi: <pub-id pub-id-type="doi">10.1109/OJCOMS.2024.3521651</pub-id></citation></ref>
<ref id="ref6"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Khan</surname><given-names>S.</given-names></name></person-group> (<year>2024</year>). <article-title>Secure multi-party computation for privacy preservation in big data analytics</article-title>. <source>J. Big Data Privacy Manage.</source> <volume>2</volume>, <fpage>168</fpage>&#x2013;<lpage>179</lpage>. Available at: <ext-link xlink:href="https://jbdpm.com/index.php/journal/article/view/42" ext-link-type="uri">https://jbdpm.com/index.php/journal/article/view/42</ext-link></citation></ref>
<ref id="ref7"><citation citation-type="other"><person-group person-group-type="author"><name><surname>Liu</surname><given-names>T.</given-names></name></person-group> (<year>2024</year>). &#x201C;<article-title>Research on privacy techniques based on multi-party secure computation</article-title>&#x201D; in <source>2024 3rd international conference on artificial intelligence and autonomous robot systems</source>.</citation></ref>
<ref id="ref8"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Marshall</surname><given-names>R.</given-names></name> <name><surname>Pardo</surname><given-names>A.</given-names></name> <name><surname>Smith</surname><given-names>D.</given-names></name> <name><surname>Watson</surname><given-names>T.</given-names></name></person-group> (<year>2022</year>). <article-title>Implementing next generation privacy and ethics research in education technology</article-title>. <source>Br. J. Educ. Technol.</source> <volume>53</volume>, <fpage>737</fpage>&#x2013;<lpage>755</lpage>. doi: <pub-id pub-id-type="doi">10.1111/bjet.13224</pub-id></citation></ref>
<ref id="ref9"><citation citation-type="other"><person-group person-group-type="author"><name><surname>McMahan</surname><given-names>H. B.</given-names></name> <name><surname>Yu</surname><given-names>F. X.</given-names></name> <name><surname>Richtarik</surname><given-names>P.</given-names></name> <name><surname>Suresh</surname><given-names>A. T.</given-names></name> <name><surname>Bacon</surname><given-names>D.</given-names></name></person-group> (<year>2016</year>). &#x201C;<article-title>Federated learning: Strategies for improving communication efficiency</article-title>&#x201D; in <source>Proceedings of the 29th conference on neural information processing systems, Barcelona, Spain</source>.</citation></ref>
<ref id="ref10"><citation citation-type="other"><person-group person-group-type="author"><name><surname>Miller</surname><given-names>J.</given-names></name> <name><surname>Chattopadhyay</surname><given-names>A.</given-names></name></person-group> (<year>2024</year>). &#x201C;<article-title>Integrating differential privacy in modern database curriculum</article-title>&#x201D; in <source>2024 IEEE integrated STEM education conference</source>.</citation></ref>
<ref id="ref11"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Mora</surname><given-names>A.</given-names></name> <name><surname>Bujari</surname><given-names>A.</given-names></name> <name><surname>Bellavista</surname><given-names>P.</given-names></name></person-group> (<year>2024</year>). <article-title>Enhancing generalization in federated learning with heterogeneous data: a comparative literature review</article-title>. <source>Futur. Gener. Comput. Syst.</source> <volume>1</volume>, <fpage>1</fpage>&#x2013;<lpage>10</lpage>. doi: <pub-id pub-id-type="doi">10.1016/j.future.2024.03.027</pub-id></citation></ref>
<ref id="ref12"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Moshawrab</surname><given-names>M.</given-names></name> <name><surname>Adda</surname><given-names>M.</given-names></name> <name><surname>Bouzouane</surname><given-names>A.</given-names></name> <name><surname>Ibrahim</surname><given-names>H.</given-names></name> <name><surname>Raad</surname><given-names>A.</given-names></name></person-group> (<year>2023</year>). <article-title>Reviewing federated learning aggregation algorithms; strategies, contributions, limitations and future perspectives</article-title>. <source>Electronics</source> <volume>12</volume>, <fpage>1</fpage>&#x2013;<lpage>35</lpage>. doi: <pub-id pub-id-type="doi">10.3390/electronics12102287</pub-id>, PMID: <pub-id pub-id-type="pmid">40789738</pub-id></citation></ref>
<ref id="ref13"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Pakina</surname><given-names>A. K.</given-names></name> <name><surname>Pujari</surname><given-names>M.</given-names></name></person-group> (<year>2024</year>). <article-title>Differential privacy at the edge: a federated learning framework for GDPR-compliant TinyML deployments</article-title>. <source>IOSR J. Comput. Engin.</source> <volume>26</volume>, <fpage>52</fpage>&#x2013;<lpage>64</lpage>. doi: <pub-id pub-id-type="doi">10.9790/0661-2602045264</pub-id></citation></ref>
<ref id="ref14"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Salas</surname><given-names>J.</given-names></name> <name><surname>Domingo-Ferrer</surname><given-names>J.</given-names></name></person-group> (<year>2018</year>). <article-title>Some basics on privacy techniques, anonymization and their big data challenges</article-title>. <source>Math. Comput. Sci.</source> <volume>12</volume>, <fpage>263</fpage>&#x2013;<lpage>274</lpage>. doi: <pub-id pub-id-type="doi">10.1007/s11786-018-0344-6</pub-id></citation></ref>
<ref id="ref15"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Sattler</surname><given-names>F.</given-names></name> <name><surname>Wiedemann</surname><given-names>S.</given-names></name> <name><surname>M&#x00FC;ller</surname><given-names>K.-R.</given-names></name> <name><surname>Samek</surname><given-names>W.</given-names></name></person-group> (<year>2019</year>). <article-title>Robust and communication-efficient federated learning from non-iiD data</article-title>. <source>IEEE Transact. Neural Networks Learn. Syst.</source> <volume>31</volume>, <fpage>3400</fpage>&#x2013;<lpage>3413</lpage>. doi: <pub-id pub-id-type="doi">10.1109/TNNLS.2019.2944481</pub-id>, PMID: <pub-id pub-id-type="pmid">31689214</pub-id></citation></ref>
<ref id="ref16"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Shou</surname><given-names>Z.</given-names></name> <name><surname>Xie</surname><given-names>M.</given-names></name> <name><surname>Mo</surname><given-names>J.</given-names></name> <name><surname>Zhang</surname><given-names>H.</given-names></name></person-group> (<year>2024</year>). <article-title>Predicting student performance in online learning: a multidimensional time-series data analysis approach</article-title>. <source>Appl. Sci.</source> <volume>14</volume>:<fpage>2522</fpage>. doi: <pub-id pub-id-type="doi">10.3390/app14062522</pub-id></citation></ref>
<ref id="ref17"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Song</surname><given-names>J.</given-names></name> <name><surname>Jung</surname><given-names>H</given-names></name> <name><surname>Chun</surname><given-names>S</given-names></name> <name><surname>Lee</surname><given-names>H</given-names></name> <name><surname>Kang</surname><given-names>M</given-names></name> <name><surname>Park</surname><given-names>M</given-names></name> <etal/></person-group>. (<year>2023</year>). <article-title>How to decentralize the internet: a focus on data consolidation and user privacy</article-title>. <source>Comput. Netw.</source> <volume>234</volume>:<fpage>109911</fpage>. doi: <pub-id pub-id-type="doi">10.1016/j.comnet.2023.109911</pub-id></citation></ref>
<ref id="ref18"><citation citation-type="confproc"><person-group person-group-type="author"><name><surname>Truex</surname><given-names>S.</given-names></name> <etal/></person-group>., <article-title>A hybrid approach to privacy-preserving federated learning</article-title>, in <conf-name>Proceedings of the 12th ACM workshop on artificial intelligence and security</conf-name>, (<year>2019</year>)</citation></ref>
<ref id="ref001"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Witten</surname><given-names>I. H.</given-names></name> <name><surname>Frank</surname><given-names>E.</given-names></name> <name><surname>Hall</surname><given-names>M. A.</given-names></name> <name><surname>Pal</surname><given-names>C. J.</given-names></name></person-group> (<year>2016</year>). <article-title>Data Mining: Practical Machine Learning Tools and Techniques, 4th ed</article-title>. <publisher-loc>Cambridge, MA</publisher-loc>: <publisher-name>Morgan Kaufmann</publisher-name>., PMID: <pub-id pub-id-type="pmid">31689214</pub-id></citation></ref>
<ref id="ref19"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Yang</surname><given-names>X.</given-names></name> <name><surname>Huang</surname><given-names>W.</given-names></name> <name><surname>Ye</surname><given-names>M.</given-names></name></person-group> (<year>2023</year>). <article-title>Dynamic personalized federated learning with adaptive differential privacy</article-title>. <source>Adv. Neural Inf. Proces. Syst.</source> <volume>36</volume>, <fpage>72181</fpage>&#x2013;<lpage>72192</lpage>. Available at: <ext-link xlink:href="https://proceedings.neurips.cc/paper_files/paper/2023/file/e4724af0e2a0d52ce5a0a4e084b87f59-Paper-Conference.pdf" ext-link-type="uri">https://proceedings.neurips.cc/paper_files/paper/2023/file/e4724af0e2a0d52ce5a0a4e084b87f59-Paper-Conference.pdf</ext-link></citation></ref>
<ref id="ref20"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Zhan</surname><given-names>C.</given-names></name> <name><surname>Joksimovi&#x0107;</surname><given-names>S.</given-names></name> <name><surname>Ladjal</surname><given-names>D.</given-names></name> <name><surname>Rakotoarivelo</surname><given-names>T.</given-names></name> <name><surname>Marshall</surname><given-names>R.</given-names></name> <name><surname>Pardo</surname><given-names>A.</given-names></name></person-group> (<year>2024</year>). <article-title>Preserving both privacy and utility in learning analytics</article-title>. <source>IEEE Trans. Learn. Technol.</source> <volume>17</volume>, <fpage>1615</fpage>&#x2013;<lpage>1627</lpage>. doi: <pub-id pub-id-type="doi">10.1109/TLT.2024.3393766</pub-id></citation></ref>
<ref id="ref21"><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Zhang</surname><given-names>J.</given-names></name> <name><surname>Cheng</surname><given-names>X.</given-names></name> <name><surname>Yang</surname><given-names>L.</given-names></name> <name><surname>Hu</surname><given-names>J.</given-names></name> <name><surname>Liu</surname><given-names>X.</given-names></name> <name><surname>Chen</surname><given-names>K.</given-names></name></person-group> (<year>2024</year>). <article-title>Sok: fully homomorphic encryption accelerators</article-title>. <source>ACM Comput. Surv.</source> <volume>56</volume>, <fpage>1</fpage>&#x2013;<lpage>32</lpage>. doi: <pub-id pub-id-type="doi">10.1145/3676955</pub-id></citation></ref>
</ref-list>
</back>
</article>