<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.3 20070202//EN" "journalpublishing.dtd">
<article article-type="research-article" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xml:lang="EN">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">Front. Digit. Health</journal-id>
<journal-title>Frontiers in Digital Health</journal-title>
<abbrev-journal-title abbrev-type="pubmed">Front. Digit. Health</abbrev-journal-title>
<issn pub-type="epub">2673-253X</issn>
<publisher>
<publisher-name>Frontiers Media S.A.</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="doi">10.3389/fdgth.2025.1603630</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Digital Health</subject>
<subj-group>
<subject>Technology and Code</subject>
</subj-group>
</subj-group>
</article-categories>
<title-group>
<article-title>Horizontal federated learning and assessment of Cox models</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author" corresp="yes"><name><surname>Westers</surname><given-names>Frank</given-names></name>
<xref ref-type="aff" rid="aff1"><sup>1</sup></xref>
<xref ref-type="corresp" rid="cor1">&#x002A;</xref><uri xlink:href="https://loop.frontiersin.org/people/2901289/overview"/><role content-type="https://credit.niso.org/contributor-roles/writing-original-draft/"/><role content-type="https://credit.niso.org/contributor-roles/writing-review-editing/"/><role content-type="https://credit.niso.org/contributor-roles/investigation/"/><role content-type="https://credit.niso.org/contributor-roles/methodology/"/><role content-type="https://credit.niso.org/contributor-roles/software/"/><role content-type="https://credit.niso.org/contributor-roles/validation/"/></contrib>
<contrib contrib-type="author"><name><surname>Leder</surname><given-names>Sam</given-names></name>
<xref ref-type="aff" rid="aff1"><sup>1</sup></xref><uri xlink:href="https://loop.frontiersin.org/people/2901229/overview" /><role content-type="https://credit.niso.org/contributor-roles/writing-original-draft/"/><role content-type="https://credit.niso.org/contributor-roles/writing-review-editing/"/><role content-type="https://credit.niso.org/contributor-roles/investigation/"/><role content-type="https://credit.niso.org/contributor-roles/methodology/"/><role content-type="https://credit.niso.org/contributor-roles/software/"/><role content-type="https://credit.niso.org/contributor-roles/validation/"/><role content-type="https://credit.niso.org/contributor-roles/visualization/"/></contrib>
<contrib contrib-type="author"><name><surname>Tealdi</surname><given-names>Lucia</given-names></name>
<xref ref-type="aff" rid="aff2"><sup>2</sup></xref><role content-type="https://credit.niso.org/contributor-roles/investigation/"/><role content-type="https://credit.niso.org/contributor-roles/software/"/><role content-type="https://credit.niso.org/contributor-roles/writing-review-editing/"/></contrib>
</contrib-group>
<aff id="aff1"><label><sup>1</sup></label><institution>Applied Cryptography &#x0026; Quantum Applications, Netherlands Institute for Applied Scientific Research (TNO)</institution>, <addr-line>The Hague</addr-line>, <country>Netherlands</country></aff>
<aff id="aff2"><label><sup>2</sup></label><institution>Data Science, Netherlands Institute for Applied Scientific Research (TNO)</institution>, <addr-line>The Hague</addr-line>, <country>Netherlands</country></aff>
<author-notes>
<fn fn-type="edited-by"><p><bold>Edited by:</bold> Lisette van van Gemert-Pijnen, University of Twente, Netherlands</p></fn>
<fn fn-type="edited-by"><p><bold>Reviewed by:</bold> Varsha Gouthamchand, Maastricht University, Netherlands</p>
<p>Dr. Hari Gonaygunta, University of the Cumberlands, United States</p></fn>
<corresp id="cor1"><label>&#x002A;</label><bold>Correspondence:</bold> Frank Westers <email>frank.westers@tno.nl</email></corresp>
</author-notes>
<pub-date pub-type="epub"><day>12</day><month>06</month><year>2025</year></pub-date>
<pub-date pub-type="collection"><year>2025</year></pub-date>
<volume>7</volume><elocation-id>1603630</elocation-id>
<history>
<date date-type="received"><day>31</day><month>03</month><year>2025</year></date>
<date date-type="accepted"><day>26</day><month>05</month><year>2025</year></date>
</history>
<permissions>
<copyright-statement>&#x00A9; 2025 Westers, Leder and Tealdi.</copyright-statement>
<copyright-year>2025</copyright-year><copyright-holder>Westers, Leder and Tealdi</copyright-holder><license license-type="open-access" xlink:href="http://creativecommons.org/licenses/by/4.0/">
<p>This is an open-access article distributed under the terms of the <ext-link ext-link-type="uri" xlink:href="http://creativecommons.org/licenses/by/4.0/">Creative Commons Attribution License (CC BY)</ext-link>. The use, distribution or reproduction in other forums is permitted, provided the original author(s) and the copyright owner(s) are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.</p></license>
</permissions>
<abstract>
<p>The Cox Proportional Hazards model is a widely used method for survival analysis in medical research. However, training an accurate model requires access to a sufficiently large dataset, which is often challenging due to data fragmentation. A potential solution is to combine data from multiple medical institutions, but privacy constraints typically prevent direct data sharing. Federated learning offers a privacy-preserving alternative by allowing multiple parties to collaboratively train a model without exchanging raw data. In this work, we develop algorithms for training Cox models in a federated setting, leveraging survival stacking to facilitate distributed learning. In addition, we introduce a novel secure computation of Schoenfeld residuals, a key diagnostic tool for validating the Cox model. We provide an open-source implementation of our approach and present empirical results that demonstrate the accuracy and benefits of federated Cox regression.</p>
</abstract>
<kwd-group>
<kwd>Cox regression</kwd>
<kwd>federated learning</kwd>
<kwd>multiparty computation (MPC)</kwd>
<kwd>privacy enhanced technologies (pet)</kwd>
<kwd>survival analysis</kwd>
<kwd>open-source software</kwd>
</kwd-group><counts>
<fig-count count="3"/>
<table-count count="5"/><equation-count count="219"/><ref-count count="20"/><page-count count="11"/><word-count count="0"/></counts><custom-meta-wrap><custom-meta><meta-name>section-at-acceptance</meta-name><meta-value>Health Technology Implementation</meta-value></custom-meta></custom-meta-wrap>
</article-meta>
</front>
<body><sec id="s1" sec-type="intro"><label>1</label><title>Introduction</title>
<p>Survival modeling is a common type of data analysis; it aims to predict the time until some event occurs based on historical data. In healthcare, this is often used to study the influence of certain covariates - such as biomarkers or drug use - on the occurrence of some adverse event. The Cox proportional hazard model is a common model for survival analysis in medical research. However, researchers do not always have enough data available to reliably fit a Cox model. Combining the data of multiple medical centers or other parties, such as health insurance providers, would help address this issue, but is often not possible due to privacy restrictions or legislation. This leads to less accurate models and predictions or to potentially useful covariates being ignored.</p>
<p>Federated learning can be used to fit statistical models on distributed data. It allows multiple parties to fit a model without sharing the underlying data. Only certain statistics are shared. However, one of the requirements of federated learning is that the loss function is separable, which is not the case for the Cox model. In this paper, we show a solution for training a Cox model on horizontally partitioned data. Horizontal partitioning here means hospitals have datasets with different patients, but the same type of data on each patient. In addition, we show how to securely compute the Schoenfeld residuals on horizontally partitioned data, which can be used to assess a model computed using federated learning. Finally, we provide a comparison between these methods and existing (centralized) implementations.</p>
<p>The organization of this paper is as follows. In <xref ref-type="sec" rid="s2">Section 2</xref> we describe the methods used: the background of the Cox model, federated learning, the survival stacking technique, logistic regression in a federated setting, as well as Schoenfeld residuals and our secure approach. Then in <xref ref-type="sec" rid="s3">Section 3</xref> we present the main results of our research; our objective is to quantify the benefits of federated Cox regression and compare different optimizers. Finally, in <xref ref-type="sec" rid="s4">Section 4</xref> we discuss our results in the context of prior research, give limitations of our work, and formulate further research questions.</p>
</sec>
<sec id="s2" sec-type="methods"><label>2</label><title>Methods</title>
<sec id="s2a"><label>2.1</label><title>The Cox model</title>
<p>The Cox Proportional Hazards (CPH) model, introduced by Cox in 1972 (<xref ref-type="bibr" rid="B1">1</xref>), is a widely used statistical method to analyze survival data. It aims to quantify the relationship between survival time and one or more explanatory variables, known as covariates, without requiring strong assumptions about the baseline hazard function. The model is particularly useful in medical and epidemiological research to study the effect of covariates on survival outcomes.</p>
<p>The Cox model expresses the hazard function, which describes the instantaneous risk of failure at time <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM1"><mml:mi>t</mml:mi></mml:math></inline-formula> for an individual with a given set of covariates, as:<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM1"><mml:mi>&#x03BB;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mrow><mml:mi mathvariant="bold">Z</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mrow><mml:mi mathvariant="bold">Z</mml:mi></mml:mrow></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:msub><mml:mi>Z</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>+</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:msub><mml:mi>Z</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>+</mml:mo><mml:mo>&#x22EF;</mml:mo><mml:mo>+</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mi>p</mml:mi></mml:msub><mml:msub><mml:mi>Z</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:mrow></mml:msup></mml:math></disp-formula>Here <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM2"><mml:mrow><mml:mi mathvariant="bold">Z</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>Z</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>Z</mml:mi><mml:mi>p</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> represents the vector of covariates and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM3"><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow></mml:math></inline-formula> are the corresponding regression coefficients. <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM4"><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> is the baseline hazard function, representing the hazard when all covariates are zero. The key feature of the Cox model is its proportional hazards assumption: the hazard function for different individuals is proportional over time. If a coefficient <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM5"><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is positive, the corresponding covariate <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM6"><mml:msub><mml:mi>Z</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> increases the hazard, which means a higher risk of failure. Conversely, a negative <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM7"><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> implies a protective effect, which reduces the hazard.</p>
<p>A major advantage of the Cox model is that it does not require a specification of the baseline hazard <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM8"><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, making it a semi-parametric model. To estimate the coefficients <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM9"><mml:mi>&#x03B2;</mml:mi></mml:math></inline-formula>, the Cox model maximizes the <italic>partial likelihood</italic>. Suppose we have a data set <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM10"><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold">Z</mml:mi></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:math></inline-formula>, where <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM11"><mml:msub><mml:mrow><mml:mi mathvariant="bold">Z</mml:mi></mml:mrow><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> are the covariates, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM12"><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is the observed survival time, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM13"><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> is the event indicator (1 if an event occurred, 0 if censored) for individual <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM14"><mml:mi>i</mml:mi></mml:math></inline-formula>. Then, the partial likelihood is given by:<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM2"><mml:mtable columnalign="right left" rowspacing=".5em" columnspacing="thickmathspace" displaystyle="true"><mml:mtr><mml:mtd><mml:mrow><mml:mi mathvariant="script">L</mml:mi><mml:mo mathvariant="script" stretchy="false">(</mml:mo><mml:mi>&#x03B2;</mml:mi><mml:mo mathvariant="script" stretchy="false">)</mml:mo></mml:mrow></mml:mtd><mml:mtd><mml:mo>=</mml:mo><mml:munder><mml:mo>&#x220F;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mo>;</mml:mo><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow></mml:munder><mml:mi>P</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>i</mml:mi><mml:mtext>&#xA0;fails</mml:mtext><mml:mspace width="thinmathspace" /><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mspace width="thinmathspace" /><mml:mi>R</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo stretchy="false">)</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd /><mml:mtd><mml:mo>=</mml:mo><mml:mrow><mml:mfrac><mml:mrow><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold">Z</mml:mi></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow><mml:mrow><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>j</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mrow><mml:mi mathvariant="script">R</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:munder><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold">Z</mml:mi></mml:mrow><mml:mi>j</mml:mi></mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:mfrac></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>Here, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM15"><mml:mrow><mml:mi mathvariant="script">R</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>i</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2265;</mml:mo><mml:mi>t</mml:mi><mml:mo fence="false" stretchy="false">}</mml:mo></mml:math></inline-formula>, that is, the set of individuals still in the study at <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM16"><mml:mi>t</mml:mi></mml:math></inline-formula>, or <italic>risk set</italic>. Maximizing this likelihood leads to estimates of the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM17"><mml:mi>&#x03B2;</mml:mi></mml:math></inline-formula> coefficients, which quantify the effect of covariates on survival. The statistical significance of these estimates can be assessed using hypothesis tests such as the Wald test, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM18"><mml:mi>p</mml:mi></mml:math></inline-formula>-values, or likelihood ratio test. The Schoenfeld residual test can be used to test whether a data set satisfies the proportional hazard assumption.</p>
</sec>
<sec id="s2b"><label>2.2</label><title>Federated learning of Cox models</title>
<p>One limiting factor in medical research is often the availability of reliable patient data. In addition, these data are often restricted to a single institution or region, resulting in datasets that may lack diversity and generalizability. Privacy concerns and regulatory constraints make it difficult to share sensitive health data between institutions. These challenges have spurred research into privacy-preserving methods that enable collaborative studies while protecting patient confidentiality (<xref ref-type="bibr" rid="B2">2</xref>).</p>
<p>Federated Learning (FL) is one such method that allows multiple institutions to collaboratively train a model without sharing raw data (<xref ref-type="bibr" rid="B3">3</xref>). In federated learning, the data remains decentralized, and only model updates, such as gradients, are exchanged between institutions. The federated learning process generally consists of three steps:
<list list-type="simple">
<list-item><label>1.</label>
<p>Each participating institution computes an update to the model using its local data and sends this update to a central aggregator.</p></list-item>
<list-item><label>2.</label>
<p>The aggregator combines the local updates to produce a global model update and distributes it to all participants.</p></list-item>
<list-item><label>3.</label>
<p>Each institution updates its local model with the new global update. This process is repeated until a stopping criterion is met.</p></list-item>
</list>A common approach to aggregation is averaging, which is also used in this work. For updates, we use the gradients in a gradient descent optimization process. It is important to note that some information, namely the gradients, is being shared with the server. In cases where this is a problem, the server can be replaced by a secret-sharing scheme of a form of homomorphic encryption or differential privacy can be used.</p>
<p>Although federated learning appears to be a natural fit for Cox regression &#x2014; where each institution computes gradients with respect to the partial likelihood and the gradients are averaged for a global update &#x2014; this approach is not straightforward. The reason is that the partial likelihood in the Cox model involves summing over all individuals in the risk set at a given time. Since each institution only has access to its own local dataset, this value in the partial likelihood cannot be accurately computed locally. Naively computing it locally would effectively result in a stratified Cox model.</p>
<p>To overcome this challenge, we employ a technique known as <italic>survival stacking</italic>. The core idea is that the coefficients in the Cox model approximate those obtained from logistic regression when the dataset is transformed by stacking (<xref ref-type="bibr" rid="B4">4</xref>). Since logistic regression has a separable loss function, it can be trained in a federated manner. First, each party locally survival stacks its dataset. The parties then collaboratively perform federated logistic regression using the transformed data. The outcome is an approximation of the Cox model. Its quality can then be assessed using (federated) metrics.</p>
<p>In the following sections, we describe the survival stacking technique in more detail, demonstrate its implementation, and show the process for federated Cox modeling using this approach.</p>
<sec id="s2b1"><label>2.2.1</label><title>Survival stacking</title>
<p>Survival stacking is a method that transforms a right-censored survival dataset into a classification dataset. This procedure is detailed in (<xref ref-type="bibr" rid="B4">4</xref>); here, we provide a brief overview.</p>
<p>Given a survival dataset <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM19"><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold">Z</mml:mi></mml:mrow><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:math></inline-formula>, the goal is to construct a classification dataset <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM20"><mml:msup><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msup></mml:math></inline-formula>. The resulting dataset consists of a matrix of independent variables <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM21"><mml:mrow><mml:mi mathvariant="bold">X</mml:mi></mml:mrow></mml:math></inline-formula> and a target vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM22"><mml:mrow><mml:mi mathvariant="bold">y</mml:mi></mml:mrow></mml:math></inline-formula> containing boolean outcomes. The matrix <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM23"><mml:mrow><mml:mi mathvariant="bold">X</mml:mi></mml:mrow></mml:math></inline-formula> includes all covariates from <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM24"><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow></mml:math></inline-formula>, along with additional columns representing risk set indicators corresponding to each event time point <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM25"><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> where <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM26"><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>. <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM27"><mml:msup><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msup></mml:math></inline-formula> is built iteratively, by &#x201C;stacking&#x201D; the risk sets at the different failure times. More specifically, for each event time point <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM28"><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> where <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM29"><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>, the procedure is as follows:
<list list-type="simple">
<list-item><label>1.</label>
<p>Identify the risk set <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM30"><mml:mrow><mml:mi mathvariant="script">R</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, which includes all subjects still under observation at time <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM31"><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula>.</p></list-item>
<list-item><label>2.</label>
<p>For each subject in <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM32"><mml:mrow><mml:mi mathvariant="script">R</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, add a row to <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM33"><mml:msup><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msup></mml:math></inline-formula> that replicates their covariates from <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM34"><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow></mml:math></inline-formula>.</p></list-item>
<list-item><label>3.</label>
<p>Set the corresponding risk set indicator to 1.</p></list-item>
<list-item><label>4.</label>
<p>Update the target vector <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM35"><mml:mrow><mml:mi mathvariant="bold">y</mml:mi></mml:mrow></mml:math></inline-formula>: assign 1 to the subject who experienced the event at <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM36"><mml:msub><mml:mi>t</mml:mi><mml:mi>i</mml:mi></mml:msub></mml:math></inline-formula> and 0 to all others.</p></list-item>
</list>As an example consider the dataset:<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM3"><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mtext>Covariates</mml:mtext></mml:mtd><mml:mtd><mml:mtext>Times</mml:mtext></mml:mtd><mml:mtd><mml:mtext>Event</mml:mtext></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mo>(</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:msub><mml:mi>x</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>x</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>x</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mtd></mml:mtr></mml:mtable><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:mtd><mml:mtd><mml:mrow><mml:mo>(</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:msub><mml:mi>t</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>t</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>t</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>2</mml:mn></mml:mtd></mml:mtr></mml:mtable><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:mtd><mml:mtd><mml:mrow><mml:mo>(</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>0</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mtd></mml:mtr></mml:mtable><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>Since events occur at <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM37"><mml:msub><mml:mi>t</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM38"><mml:msub><mml:mi>t</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula> (where <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM39"><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM40"><mml:msub><mml:mi>&#x03B4;</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:math></inline-formula>), we construct <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM41"><mml:msup><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msup></mml:math></inline-formula> with three columns: one for the covariate and two for the risk set indicators. At <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM42"><mml:msub><mml:mi>t</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula>, the risk set includes all subjects. Each subject is added to <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM43"><mml:msup><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msup></mml:math></inline-formula> with the first risk set indicator set to 1. The target value is 1 for the event at <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM44"><mml:msub><mml:mi>t</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:math></inline-formula> (subject 0) and 0 for others:<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM4"><mml:msup><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msup><mml:mo>=</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mtext>Covariates</mml:mtext></mml:mtd><mml:mtd><mml:mtext>Target</mml:mtext></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mo>(</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:msub><mml:mi>x</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mtd><mml:mtd><mml:mn>1</mml:mn></mml:mtd><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>x</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mtd><mml:mtd><mml:mn>1</mml:mn></mml:mtd><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>x</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mtd><mml:mtd><mml:mn>1</mml:mn></mml:mtd><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr></mml:mtable><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:mtd><mml:mtd><mml:mrow><mml:mo>(</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mn>1</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr></mml:mtable><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>At <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM45"><mml:msub><mml:mi>t</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula>, only subject 2 remains in the risk set. We add this subject to <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM46"><mml:msup><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msup></mml:math></inline-formula> with the second risk set indicator set to 1 and the target value set to 1 (since subject 2 experienced the event at <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM47"><mml:msub><mml:mi>t</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:math></inline-formula>):<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM5"><mml:msup><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msup><mml:mo>=</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mtext>Covariates</mml:mtext></mml:mtd><mml:mtd><mml:mtext>Target</mml:mtext></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mrow><mml:mo>(</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:msub><mml:mi>x</mml:mi><mml:mn>0</mml:mn></mml:msub></mml:mtd><mml:mtd><mml:mn>1</mml:mn></mml:mtd><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>x</mml:mi><mml:mn>1</mml:mn></mml:msub></mml:mtd><mml:mtd><mml:mn>1</mml:mn></mml:mtd><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>x</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mtd><mml:mtd><mml:mn>1</mml:mn></mml:mtd><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>x</mml:mi><mml:mn>2</mml:mn></mml:msub></mml:mtd><mml:mtd><mml:mn>0</mml:mn></mml:mtd><mml:mtd><mml:mn>1</mml:mn></mml:mtd></mml:mtr></mml:mtable><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:mtd><mml:mtd><mml:mrow><mml:mo>(</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:mn>1</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mn>0</mml:mn></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mn>1</mml:mn></mml:mtd></mml:mtr></mml:mtable><mml:mo>)</mml:mo></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>For a more comprehensive explanation of survival stacking and its theoretical justification, see (<xref ref-type="bibr" rid="B4">4</xref>). The main result is that applying logistic regression to the resulting stacked dataset provides an approximation of the Cox proportional hazards model coefficients.</p>
</sec>
<sec id="s2b2"><label>2.2.2</label><title>Federated logistic regression</title>
<p>Federated learning of logistic regression enables multiple parties to collaboratively train a logistic regression model without sharing their local data. This decentralized approach preserves privacy while allowing the computation of a global model across distributed datasets. In the following, we outline the basic procedure for federated logistic regression.</p>
<p>Consider <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM48"><mml:mi>K</mml:mi></mml:math></inline-formula> parties, each holding a local dataset <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM49"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mi>k</mml:mi></mml:msub><mml:mo>=</mml:mo><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold">X</mml:mi></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:math></inline-formula>, where <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM50"><mml:msub><mml:mrow><mml:mi mathvariant="bold">X</mml:mi></mml:mrow><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> represents the feature matrix and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM51"><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is the binary target variable. The goal is to jointly estimate the logistic regression parameters <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM52"><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow></mml:math></inline-formula> by minimizing the following loss function:<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM6"><mml:mrow><mml:mi mathvariant="script">L</mml:mi></mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>K</mml:mi></mml:mrow></mml:munderover><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:mrow></mml:munderover><mml:mrow><mml:mo>[</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>y</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msubsup><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x2212;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mi>log</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>1</mml:mn><mml:mo>&#x2212;</mml:mo><mml:msubsup><mml:mi>y</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msubsup><mml:mo stretchy="false">)</mml:mo><mml:mo>]</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:math></disp-formula>where
<list list-type="simple">
<list-item><label>1.</label>
<p><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM53"><mml:msub><mml:mi>n</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula> is the number of subjects in <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM54"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula></p></list-item>
<list-item><label>2.</label>
<p><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM55"><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM56"><mml:mi>i</mml:mi></mml:math></inline-formula>th subject in <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM57"><mml:msub><mml:mi>y</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula>, i.e., the true label for <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM58"><mml:mi>i</mml:mi></mml:math></inline-formula>th entry in <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM59"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula>.</p></list-item>
<list-item><label>3.</label>
<p><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM60"><mml:msubsup><mml:mi>y</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msubsup></mml:math></inline-formula> is the prediction for the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM61"><mml:mi>i</mml:mi></mml:math></inline-formula>th subject in <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM62"><mml:msub><mml:mrow><mml:mi mathvariant="script">D</mml:mi></mml:mrow><mml:mi>k</mml:mi></mml:msub></mml:math></inline-formula>. This is computed using<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM7"><mml:msubsup><mml:mi>y</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msubsup><mml:mo>=</mml:mo><mml:mi>&#x03C3;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="bold">X</mml:mi></mml:mrow><mml:mrow><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mi>T</mml:mi></mml:msubsup><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mrow><mml:mfrac><mml:mn>1</mml:mn><mml:mrow><mml:mn>1</mml:mn><mml:mo>+</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:mo>&#x2212;</mml:mo><mml:msubsup><mml:mrow><mml:mi mathvariant="bold">X</mml:mi></mml:mrow><mml:mrow><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mi>T</mml:mi></mml:msubsup><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow></mml:mrow></mml:msup></mml:mrow></mml:mfrac></mml:mrow></mml:math></disp-formula></p></list-item>
</list>As we can see, the loss function can be computed locally by each party. By averaging the gradients of the local losses, we can compute the gradient of the entire data set. The algorithm starts with an initialization step: a central server initializes the model parameters <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM63"><mml:msup><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mn>0</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup></mml:math></inline-formula> and shares them with all participating parties. Next, each party <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM64"><mml:mi>k</mml:mi></mml:math></inline-formula> computes the gradient of the local objective function with respect to <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM65"><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow></mml:math></inline-formula>:<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM8"><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:msub><mml:mrow><mml:mi mathvariant="script">L</mml:mi></mml:mrow><mml:mi>k</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:msub><mml:mi>n</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:mrow></mml:munderover><mml:mrow><mml:mo>[</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>y</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:mrow><mml:mo>&#x2032;</mml:mo></mml:msubsup><mml:mo>&#x2212;</mml:mo><mml:msub><mml:mi>y</mml:mi><mml:mrow><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:msub><mml:mrow><mml:mi mathvariant="bold">X</mml:mi></mml:mrow><mml:mrow><mml:mi>k</mml:mi><mml:mi>i</mml:mi></mml:mrow></mml:msub><mml:mo>]</mml:mo></mml:mrow></mml:math></disp-formula>The server collects the local updates and takes a weighted average based on the relative size of the data sets. This is the global gradient, which is multiplied by the step size <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM66"><mml:mi>&#x03B7;</mml:mi></mml:math></inline-formula> to compute the global update on the model.<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM9"><mml:msup><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo>+</mml:mo><mml:mn>1</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo>=</mml:mo><mml:msup><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo>&#x2212;</mml:mo><mml:mi>&#x03B7;</mml:mi><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>k</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>K</mml:mi></mml:mrow></mml:munderover><mml:mrow><mml:mfrac><mml:mi>n</mml:mi><mml:msub><mml:mi>n</mml:mi><mml:mi>k</mml:mi></mml:msub></mml:mfrac></mml:mrow><mml:mi mathvariant="normal">&#x2207;</mml:mi><mml:msub><mml:mrow><mml:mi mathvariant="script">L</mml:mi></mml:mrow><mml:mi>k</mml:mi></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:msup><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msup><mml:mo stretchy="false">)</mml:mo><mml:mo>,</mml:mo></mml:math></disp-formula>The updated model is distributed to the different parties. These steps are repeated until convergence has been reached. There are many different ways for the aggregator to determine the step size. In this research, we have tested multiple optimizers, of which the results are given in <xref ref-type="sec" rid="s3">Section 3</xref>.</p>
</sec>
<sec id="s2b3"><label>2.2.3</label><title>Federated Cox regression</title>
<p>We can combine survival stacking with federated learning to collaboratively fit a Cox proportional hazards model without sharing raw data. Each participating party independently applies survival stacking to its dataset. Subsequently, the parties engage in a federated logistic regression procedure to fit a logistic regression model on their stacked datasets. The resulting logistic regression coefficients are approximations of the Cox model coefficients. To perform survival stacking, each party must know the time points of the failures. In some cases, these might be considered sensitive data. A solution to this problem is to collaboratively compute the highest time point [by sharing the maximum time point, or using multi -party computation (<xref ref-type="bibr" rid="B5">5</xref>)]. Next, we split the time frame into a predetermined number of time points. For each time point, we take the risk set at that point and set the values to 1 for subjects who experience a failure close to that time frame (<xref ref-type="bibr" rid="B6">6</xref>). This also reduces the size of the stacked dataset, which can result in more accurate models. In <xref ref-type="sec" rid="s3">Section 3</xref>, we also demonstrate that this method effectively estimates the Cox model coefficients in a federated setting. The code includes the computation of several statistics, such as the Wald statistic and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM67"><mml:mi>p</mml:mi></mml:math></inline-formula>-values.</p>
</sec>
</sec>
<sec id="s2c"><label>2.3</label><title>Secure Schoenfeld residuals</title>
<p>One of the key assumptions of the Cox model is the so-called <italic>proportional hazards assumption</italic>. The hazard function can be thought of as the risk of an individual having an event at a given time. The proportional hazards assumption now states that this hazard can be split up in two parts: the baseline and a linear combination of the individual&#x2019;s covariates, and that this baseline is the same for all individuals. Furthermore, it is assumed that both the covariates and the model parameters are time-invariant, i.e., they remain the same over the entire course of the study. Recall from <xref ref-type="sec" rid="s2a">Section 2.1</xref> that the hazard for individual <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM68"><mml:mi>i</mml:mi></mml:math></inline-formula> is given by<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM10"><mml:mi>&#x03BB;</mml:mi><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mrow><mml:msub><mml:mi mathvariant="bold">Z</mml:mi><mml:mi mathvariant="bold">i</mml:mi></mml:msub></mml:mrow><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo><mml:mo>&#x22C5;</mml:mo><mml:msup><mml:mi>e</mml:mi><mml:mrow><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mrow><mml:msub><mml:mi mathvariant="bold">Z</mml:mi><mml:mi mathvariant="bold">i</mml:mi></mml:msub></mml:mrow></mml:mrow></mml:msup><mml:mo>,</mml:mo></mml:math></disp-formula>where <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM69"><mml:msub><mml:mi>&#x03BB;</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo stretchy="false">(</mml:mo><mml:mi>t</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> is the common baseline hazard, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM70"><mml:mrow><mml:msub><mml:mi mathvariant="bold">Z</mml:mi><mml:mi mathvariant="bold">i</mml:mi></mml:msub></mml:mrow></mml:math></inline-formula> are the covariates of the individual and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM71"><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow></mml:math></inline-formula> are the model&#x2019;s parameters.</p>
<p>Now, this is a very strong assumption that needs to be validated. For this we use Schoenfeld residuals, a concept published by David Schoenfeld in 1982 (<xref ref-type="bibr" rid="B7">7</xref>). Simply put, the idea is to compare the actual covariates in the dataset with the covariates predicted by the model. Now, the model does not primarily seek to predict the covariate values, but at the time just before each failure, we can compute the risk-weighted average of the covariate over the relevant risk set and compare that to the actual covariate. We then plot these residuals and inspect them; if they are distributed as random noise, we conclude that the proportional hazards assumption holds, but if there is a clear time dependence in the residuals, we are more likely to reject the assumption.</p>
<p>We have implemented the calculation of Schoenfeld residuals in a secure multi-party computation (MPC) setting, using the MPyC library (<xref ref-type="bibr" rid="B8">8</xref>). This calculation is to be performed by the cooperating parties after the federated Cox regression. In order to speed up the calculation as much as possible, the parties can preprocess the data and perform precomputations in order to simplify the actual MPC calculation as much as possible.</p>
<sec id="s2c1"><label>2.3.1</label><title>Approach</title>
<p>We describe our novel approach to securely compute the Schoenfeld residuals in a federated setting. We assume that every party has access to the trained model coefficients <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM72"><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow></mml:math></inline-formula>, as well as their own data. The protocol consists of four steps: preprocessing, sharing of failure times, precomputation, and the MPC calculation.
<list list-type="simple">
<list-item><label>1.</label>
<p>Preprocessing: each dataset contains one event per row. An event can be either a failure or a censoring. Every row also contains the time of the event and the individual&#x2019;s covariates. In this step, each party perturbs all of their event times by a small random value. This is only done to ensure that there are no duplicate times in the complete dataset. Then the party&#x2019;s data is sorted by the new perturbed event times.</p></list-item>
<list-item><label>2.</label>
<p>Sharing of failure times: here the parties communicate all of the failure times (including perturbation) in their dataset. Note that these times are generally considered sensitive, as they might leak some information about individuals in case of extremely small datasets. However, the Schoenfeld residuals themselves must be plotted against these failure times, so they are required to be public for the protocol to be useful.</p></list-item>
<list-item><label>3.</label>
<p>Precomputation: this is where most of the computational work is done. Each party (separately) computes the following values for each individual <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM73"><mml:mi>i</mml:mi></mml:math></inline-formula>:<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM11"><mml:mtable columnalign="right left" rowspacing=".5em" columnspacing="thickmathspace" displaystyle="true"><mml:mtr><mml:mtd><mml:msub><mml:mi>H</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mtd><mml:mtd><mml:mo>=</mml:mo><mml:mi>exp</mml:mi><mml:mo>&#x2061;</mml:mo><mml:mrow><mml:mo>(</mml:mo><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>j</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mrow><mml:mi>m</mml:mi></mml:mrow></mml:munderover><mml:msub><mml:mi>C</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>)</mml:mo></mml:mrow><mml:mo>,</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mtd><mml:mtd><mml:mo>=</mml:mo><mml:msub><mml:mi>C</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>&#x22C5;</mml:mo><mml:msub><mml:mi>H</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM74"><mml:msub><mml:mi>C</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM75"><mml:mi>j</mml:mi></mml:math></inline-formula>th covariate of individual <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM76"><mml:mi>i</mml:mi></mml:math></inline-formula>, and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM77"><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mi>m</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> are the coefficients of the model for each covariate. For individual <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM78"><mml:mi>i</mml:mi></mml:math></inline-formula>, we call <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM79"><mml:msub><mml:mi>H</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> the hazard, and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM80"><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> the weight for the <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM81"><mml:mi>j</mml:mi></mml:math></inline-formula>th covariate. Next, let <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM82"><mml:mrow><mml:mi mathvariant="bold">f</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>K</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> be the vector of sorted failure times shared in the previous step and furthermore <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM83"><mml:msub><mml:mi>F</mml:mi><mml:mi>p</mml:mi></mml:msub></mml:math></inline-formula> the set of failures that belong to this party <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM84"><mml:mi>p</mml:mi></mml:math></inline-formula>, then let for each individual <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM85"><mml:mi>i</mml:mi></mml:math></inline-formula><disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM12"><mml:mtable columnalign="right left" rowspacing=".5em" columnspacing="thickmathspace" displaystyle="true"><mml:mtr><mml:mtd><mml:mi>H</mml:mi><mml:msub><mml:mi>V</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mtd><mml:mtd><mml:mo>=</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>k</mml:mi><mml:mspace width="thinmathspace" /><mml:mo>&#x003A;</mml:mo><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace"/><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2265;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow></mml:munder><mml:msub><mml:mi>H</mml:mi><mml:mi>j</mml:mi></mml:msub><mml:mo>,</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>W</mml:mi><mml:msub><mml:mi>V</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mtd><mml:mtd><mml:mo>=</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mo fence="false" stretchy="false">{</mml:mo><mml:mi>k</mml:mi><mml:mspace width="thinmathspace" /><mml:mo>&#x003A;</mml:mo><mml:mspace width="thinmathspace" /><mml:mspace width="thinmathspace"/><mml:msub><mml:mi>t</mml:mi><mml:mrow><mml:mi>k</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2265;</mml:mo><mml:msub><mml:mi>f</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo fence="false" stretchy="false">}</mml:mo></mml:mrow></mml:munder><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>,</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>C</mml:mi><mml:msub><mml:mi>V</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mtd><mml:mtd><mml:mo>=</mml:mo><mml:mrow><mml:mo>{</mml:mo><mml:mtable rowspacing="4pt" columnspacing="1em"><mml:mtr><mml:mtd><mml:msub><mml:mi>C</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mspace width="2em" /></mml:mtd><mml:mtd><mml:mtext>&#xA0;if&#xA0;</mml:mtext><mml:msub><mml:mi>f</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2208;</mml:mo><mml:msub><mml:mi>F</mml:mi><mml:mi>p</mml:mi></mml:msub><mml:mspace width="2em" /></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mn>10</mml:mn><mml:mi>p</mml:mi><mml:mi>t</mml:mi><mml:mn>0</mml:mn><mml:mspace width="2em" /></mml:mtd><mml:mtd><mml:mn>10</mml:mn><mml:mi>p</mml:mi><mml:mi>t</mml:mi><mml:mtext>&#xA0;if&#xA0;</mml:mtext><mml:msub><mml:mi>f</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2209;</mml:mo><mml:msub><mml:mi>F</mml:mi><mml:mi>p</mml:mi></mml:msub><mml:mspace width="2em" /></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mspace width="2em" /></mml:mtd></mml:mtr></mml:mtable><mml:mo fence="true" stretchy="true" symmetric="true"></mml:mo></mml:mrow></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM86"><mml:mrow><mml:mi mathvariant="bold">t</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>t</mml:mi><mml:mn>0</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>t</mml:mi><mml:mi>n</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> are the times of the events. These values are not very useful on their own, but rather facilitate a simpler calculation in the last step.</p></list-item>
<list-item><label>4.</label>
<p>MPC calculation: following the precomputation, this step is straightforward. However, it happens in the encrypted domain, meaning that none of the inputs is actually visible to other parties. We first present the calculation without encryption:<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM13"><mml:mtable columnalign="right left" rowspacing=".5em" columnspacing="thickmathspace" displaystyle="true"><mml:mtr><mml:mtd><mml:mi>T</mml:mi><mml:msub><mml:mi>H</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mtd><mml:mtd><mml:mo>=</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>P</mml:mi></mml:mrow></mml:munder><mml:mi>H</mml:mi><mml:msubsup><mml:mi>V</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>T</mml:mi><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mtd><mml:mtd><mml:mo>=</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>P</mml:mi></mml:mrow></mml:munder><mml:mi>W</mml:mi><mml:msubsup><mml:mi>V</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>T</mml:mi><mml:msub><mml:mi>C</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mtd><mml:mtd><mml:mo>=</mml:mo><mml:munder><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mspace width="thinmathspace" /><mml:mi>p</mml:mi><mml:mo>&#x2208;</mml:mo><mml:mi>P</mml:mi></mml:mrow></mml:munder><mml:mi>C</mml:mi><mml:msubsup><mml:mi>V</mml:mi><mml:mi>i</mml:mi><mml:mrow><mml:mo stretchy="false">(</mml:mo><mml:mi>p</mml:mi><mml:mo stretchy="false">)</mml:mo></mml:mrow></mml:msubsup><mml:mo>,</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>E</mml:mi><mml:msub><mml:mi>C</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mtd><mml:mtd><mml:mo>=</mml:mo><mml:mrow><mml:mfrac><mml:mrow><mml:mi>T</mml:mi><mml:msub><mml:mi>W</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mrow><mml:mrow><mml:mi>T</mml:mi><mml:msub><mml:mi>H</mml:mi><mml:mrow><mml:mi>i</mml:mi></mml:mrow></mml:msub></mml:mrow></mml:mfrac></mml:mrow><mml:mo>,</mml:mo></mml:mtd></mml:mtr><mml:mtr><mml:mtd><mml:mi>S</mml:mi><mml:msub><mml:mi>R</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mtd><mml:mtd><mml:mo>=</mml:mo><mml:mi>T</mml:mi><mml:msub><mml:mi>C</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub><mml:mo>&#x2212;</mml:mo><mml:mi>E</mml:mi><mml:msub><mml:mi>C</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:mtd></mml:mtr></mml:mtable></mml:math></disp-formula>where <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM87"><mml:mi>S</mml:mi><mml:msub><mml:mi>R</mml:mi><mml:mrow><mml:mi>i</mml:mi><mml:mi>j</mml:mi></mml:mrow></mml:msub></mml:math></inline-formula> is the desired Schoenfeld for individual <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM88"><mml:mi>i</mml:mi></mml:math></inline-formula> and covariate <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM89"><mml:mi>j</mml:mi></mml:math></inline-formula>.</p></list-item>
</list>Now, the secure approach involves a technique called secret sharing, in which all parties own a &#x201C;piece&#x201D; of each secret value. This means that none of them individually knows anything about the secret (except possibly the party that secret-shared it), but all of them together can reconstruct the secret. The technique is based on polynomial interpolation and was introduced by Adi Shamir in 1979 (<xref ref-type="bibr" rid="B9">9</xref>). The additions we do in this protocol are very straightforward under secret sharing, so the main bottleneck is the set of divisions that have to be performed. This is not very complicated, although it does require many communication rounds between the parties.</p>
<p>With this approach, the parties can securely validate the federated Cox model. This is very useful, as this validation is almost always done in practice, but doing it in the clear would nullify the privacy enhancement of the federated training. Hence, being able to do both parts securely makes the whole model more valuable.</p>
</sec>
<sec id="s2c2"><label>2.3.2</label><title>Evaluation</title>
<p>As mentioned, the standard approach in evaluation Schoenfeld residuals is to plot them and inspect them visually. As an example, we plot the residuals for the age covariate of the Rotterdam Tumor Bank dataset in <xref ref-type="fig" rid="F1">Figure&#x00A0;1</xref>, as computed by the approach described above. We see that the residuals do not show a clear time dependence in this case, also indicated by the fact that the fitted line is close to the constant line through zero. This indicates that indeed the residuals are independently and identically distributed around zero and so the Proportional Hazards Assumption holds. However, we note that this is often a quite subjective measurement and is difficult to quantify exactly.</p>
<fig id="F1" position="float"><label>Figure 1</label>
<caption><p>Schoenfeld residuals for the age covariate in the Rotterdam Tumor Bank dataset. The dots represent individual residuals, and the line is a smoothed LOWESS fit.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="fdgth-07-1603630-g001.tif"/>
</fig>
</sec>
</sec>
</sec>
<sec id="s3" sec-type="results"><label>3</label><title>Results</title>
<sec id="s3a"><label>3.1</label><title>Open-source implementation</title>
<p>We provide an open source Python implementation of the described algorithms; see <ext-link ext-link-type="uri" xlink:href="https://github.com/TNO-FL/protocols.cox_regression">https://github.com/TNO-FL/protocols.cox&#x005F;regression</ext-link>.</p>
<p>The implementation includes modules for survival stacking, Schoenfeld residuals, and some generic utilities. The main functionality - the training of the distributed Cox model - happens in a client-server model. In simplified terms, the parties (each having a dataset) are separate clients, and the server only facilitates the protocol. The clients all perform an optimization step on their data, send it to the server, who then aggregates these steps to update the global model accordingly, and sends the updated model back to each of the clients. For example, each hospital would run the client and configure the URL of the server, which is usually run by an independent third party. The implementation details and recommended usage are also described in the repository.</p>
</sec>
<sec id="s3b"><label>3.2</label><title>Experiments</title>
<p>In this section, we present various experiments conducted to evaluate the performance of the proposed algorithm. By comparing our approach to established reference implementations, we can better quantify any inaccuracies introduced by survival stacking relative to directly applying a Cox model. In <xref ref-type="sec" rid="s3b1">Section 3.2.1</xref> we compare different optimizers against a reference implementation, then in <xref ref-type="sec" rid="s3b2">Section 3.2.2</xref> we analyze the impact of survival stacking. Next, <xref ref-type="sec" rid="s3b3">Section 3.2.3</xref> motivates the applicability by demonstrating both separate and collaborative models, and finally <xref ref-type="sec" rid="s3b4">Section 3.2.4</xref> presents the accuracy of both survival stacking and federated learning in the context of the Cox model.</p>
<sec id="s3b1"><label>3.2.1</label><title>Comparison of optimizers</title>
<p>We begin by comparing the effectiveness of different optimization methods for fitting a logistic regression model on stacked data. Survival stacking significantly increases the size of the dataset, resulting in a high proportion of zero values in the risk set indicator columns. Furthermore, the target vector contains very few positive labels, leading to a sparse dataset with a highly imbalanced class distribution. As a consequence, a model that sets all coefficients to zero already achieves a high accuracy score. To assess the performance of our approach, we therefore compare it against the <monospace>coxph</monospace> implementation in the <monospace>lifelines</monospace> software package (<xref ref-type="bibr" rid="B10">10</xref>). We compare with a reference implementation, instead of using scores like a C-index or calibration plots, as evaluating the accuracy of a Cox model purely through numerical metrics is challenging and often requires contextual and domain knowledge. By comparing our approach to established reference implementations, we can better quantify any inaccuracies introduced by survival stacking relative to directly applying a Cox model.</p>
<p>The results of our evaluation on two datasets are presented in <xref ref-type="table" rid="T1">Tables&#x00A0;1</xref> and <xref ref-type="table" rid="T2">2</xref>. Each experiment was repeated 10 times until convergence and the results were subsequently averaged.</p>
<table-wrap id="T1" position="float"><label>Table 1</label>
<caption><p>The outcomes for several solvers on the Rotterdam Tumor Bank dataset.</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th valign="top" align="left">Solver</th>
<th valign="top" align="center">age</th>
<th valign="top" align="center">grade</th>
<th valign="top" align="center">node</th>
<th valign="top" align="center">pgr</th>
<th valign="top" align="center">er</th>
<th valign="top" align="center">meno</th>
<th valign="top" align="center">hormon</th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left">Lifelines (<xref ref-type="bibr" rid="B10">10</xref>)</td>
<td valign="top" align="center">0.0184</td>
<td valign="top" align="center">0.3772</td>
<td valign="top" align="center">0.0881</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM90"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0004</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM91"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0001</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM92"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0369</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM93"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0388</td>
</tr>
<tr>
<td valign="top" align="left">Gradient Descent</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM94"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0388</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM95"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.7026</td>
<td valign="top" align="center">0.0883</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM96"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0013</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM97"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0006</td>
<td valign="top" align="center">0.4068</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM98"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0023</td>
</tr>
<tr>
<td valign="top" align="left">Momentum</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM99"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0303</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM100"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.7117</td>
<td valign="top" align="center">0.1086</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM101"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.2274</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM102"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.2481</td>
<td valign="top" align="center">0.2179</td>
<td valign="top" align="center">0.1404</td>
</tr>
<tr>
<td valign="top" align="left">Adam</td>
<td valign="top" align="center">0.0185</td>
<td valign="top" align="center">0.3807</td>
<td valign="top" align="center">0.0936</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM103"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0004</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM104"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0001</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM105"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0298</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM106"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0699</td>
</tr>
<tr>
<td valign="top" align="left">Newton Cholesky</td>
<td valign="top" align="center">0.0184</td>
<td valign="top" align="center">0.3780</td>
<td valign="top" align="center">0.0928</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM107"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0004</td>
<td valign="top" align="center">0.0000</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM108"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0313</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM109"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0632</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="table-fn1"><p>Lifelines is the reference implementation. The other rows are obtained by fitting logistic regression on a central stacked dataset with 50 time bins. For gradient descent and momentum ran <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM110"><mml:mn>100.000</mml:mn></mml:math></inline-formula> iterations with <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM111"><mml:mi>l</mml:mi><mml:mi>r</mml:mi><mml:mo>=</mml:mo><mml:mn>0.001</mml:mn></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM112"><mml:mi>v</mml:mi><mml:mo>=</mml:mo><mml:mn>0.9</mml:mn></mml:math></inline-formula>. For Adam, we used 50.000 iterations and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM113"><mml:mo stretchy="false">(</mml:mo><mml:mi>l</mml:mi><mml:mi>r</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>0.001</mml:mn><mml:mo>,</mml:mo><mml:mn>0.9</mml:mn><mml:mo>,</mml:mo><mml:mn>0.999</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Newton&#x2013;Raphson converged in less than 25 rounds.</p></fn>
</table-wrap-foot>
</table-wrap>
<table-wrap id="T2" position="float"><label>Table 2</label>
<caption><p>The outcomes for several solvers on the Colon dataset.</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th valign="top" align="left">Solver</th>
<th valign="top" align="center">sex</th>
<th valign="top" align="center">age</th>
<th valign="top" align="center">obstruct</th>
<th valign="top" align="center">perfor</th>
<th valign="top" align="center">adhere</th>
<th valign="top" align="center">nodes</th>
<th valign="top" align="center">surg</th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left">Lifelines (<xref ref-type="bibr" rid="B10">10</xref>)</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM114"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1512</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM115"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0041</td>
<td valign="top" align="center">0.2209</td>
<td valign="top" align="center">0.2107</td>
<td valign="top" align="center">0.2603</td>
<td valign="top" align="center">0.0872</td>
<td valign="top" align="center">0.2717</td>
</tr>
<tr>
<td valign="top" align="left">Gradient Descent</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM116"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0392</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM117"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.6952</td>
<td valign="top" align="center">0.0880</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM118"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0013</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM119"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0003</td>
<td valign="top" align="center">0.4120</td>
<td valign="top" align="center">0.0228</td>
</tr>
<tr>
<td valign="top" align="left">Momentum</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM120"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.4718</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM121"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0650</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM122"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.2323</td>
<td valign="top" align="center">0.0090</td>
<td valign="top" align="center">0.2597</td>
<td valign="top" align="center">0.0583</td>
<td valign="top" align="center">0.0774</td>
</tr>
<tr>
<td valign="top" align="left">Adam</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM123"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1465</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM124"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0043</td>
<td valign="top" align="center">0.2214</td>
<td valign="top" align="center">0.2162</td>
<td valign="top" align="center">0.2713</td>
<td valign="top" align="center">0.0945</td>
<td valign="top" align="center">0.2762</td>
</tr>
<tr>
<td valign="top" align="left">Newton Cholesky</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM125"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1425</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM126"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0042</td>
<td valign="top" align="center">0.2198</td>
<td valign="top" align="center">0.2108</td>
<td valign="top" align="center">0.2708</td>
<td valign="top" align="center">0.0961</td>
<td valign="top" align="center">0.2752</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="table-fn2"><p>Lifelines is the reference implementation. The other rows are obtained by fitting logistic regression on a central stacked dataset with 50 time bins. For gradient descent and momentum ran <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM127"><mml:mn>100.000</mml:mn></mml:math></inline-formula> iterations with <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM128"><mml:mi>l</mml:mi><mml:mi>r</mml:mi><mml:mo>=</mml:mo><mml:mn>0.001</mml:mn></mml:math></inline-formula> and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM129"><mml:mi>v</mml:mi><mml:mo>=</mml:mo><mml:mn>0.9</mml:mn></mml:math></inline-formula>. For Adam, we used 50.000 iterations and <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM130"><mml:mo stretchy="false">(</mml:mo><mml:mi>l</mml:mi><mml:mi>r</mml:mi><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mn>2</mml:mn></mml:msub><mml:mo stretchy="false">)</mml:mo><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:mn>0.001</mml:mn><mml:mo>,</mml:mo><mml:mn>0.9</mml:mn><mml:mo>,</mml:mo><mml:mn>0.999</mml:mn><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>. Newton&#x2013;Raphson converged in less than 25 rounds.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>The findings indicate that both the Adam optimizer and the Newton&#x2013;Raphson method converge to values close to the reference Cox parameters. Adam requires a greater number of communication rounds, whereas Newton&#x2013;Raphson involves transmitting the Hessian matrix, which can be large. The choice between these methods thus represents a trade-off between the frequency and the size of communication. This trade-off largely depends on the size of the Hessian matrix, which is primarily influenced by the number of time bins used in the analysis.</p>
</sec>
<sec id="s3b2"><label>3.2.2</label><title>Accuracy of survival stacking</title>
<p>We also evaluate the accuracy of our survival stacking approach, first in a centralized setting and then in a federated one. Rather than evaluating our implementation using independent measures, we benchmark our results against reference implementations in <monospace>lifelines</monospace> and <monospace>R</monospace>.</p>
<p>A key factor influencing the accuracy of survival stacking is the number of time bins used. In the original stacking approach, a new stack was added for each failure event. However, this strategy can lead to excessively large models, which is impractical, particularly in the context of federated learning. To address this issue, we employ time binning, as described in <xref ref-type="sec" rid="s2b3">Section 2.2.3</xref>. We therefore evaluate the performance of survival stacking across different numbers of time bins. The results for various datasets are presented in <xref ref-type="table" rid="T3">Tables&#x00A0;3</xref> and <xref ref-type="table" rid="T4">4</xref>.</p>
<table-wrap id="T3" position="float"><label>Table 3</label>
<caption><p>The results for the Rotterdam Tumor Bank dataset in a central setting for different number of bins.</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th valign="top" align="left">&#x0023; bins</th>
<th valign="top" align="center">age</th>
<th valign="top" align="center">grade</th>
<th valign="top" align="center">node</th>
<th valign="top" align="center">pgr</th>
<th valign="top" align="center">er</th>
<th valign="top" align="center">meno</th>
<th valign="top" align="center">hormon</th>
<th valign="top" align="center">Distance</th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left">Lifelines (<xref ref-type="bibr" rid="B10">10</xref>)</td>
<td valign="top" align="center">0.0184</td>
<td valign="top" align="center">0.3772</td>
<td valign="top" align="center">0.0881</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM131"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0004</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM132"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0001</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM133"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0369</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM134"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0388</td>
<td valign="top" align="center"/>
</tr>
<tr>
<td valign="top" align="left">1</td>
<td valign="top" align="center">0.0186</td>
<td valign="top" align="center">0.4127</td>
<td valign="top" align="center">0.1887</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM135"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0004</td>
<td valign="top" align="center">0.0002</td>
<td valign="top" align="center">0.0581</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM136"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.6878</td>
<td valign="top" align="center">0.6646</td>
</tr>
<tr>
<td valign="top" align="left">10</td>
<td valign="top" align="center">0.0184</td>
<td valign="top" align="center">0.3926</td>
<td valign="top" align="center">0.1113</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM137"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0004</td>
<td valign="top" align="center">0.0000</td>
<td valign="top" align="center">0.0009</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM138"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1718</td>
<td valign="top" align="center">0.1411</td>
</tr>
<tr>
<td valign="top" align="left">25</td>
<td valign="top" align="center">0.0186</td>
<td valign="top" align="center">0.3832</td>
<td valign="top" align="center">0.0974</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM139"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0004</td>
<td valign="top" align="center">0.0000</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM140"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0276</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM141"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0939</td>
<td valign="top" align="center">0.0569</td>
</tr>
<tr>
<td valign="top" align="left">50</td>
<td valign="top" align="center">0.0184</td>
<td valign="top" align="center">0.3780</td>
<td valign="top" align="center">0.0928</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM142"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0004</td>
<td valign="top" align="center">0.0000</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM143"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0313</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM144"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0632</td>
<td valign="top" align="center">0.0255</td>
</tr>
<tr>
<td valign="top" align="left">75</td>
<td valign="top" align="center">0.0185</td>
<td valign="top" align="center">0.3761</td>
<td valign="top" align="center">0.0914</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM145"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0004</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM146"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0001</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM147"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0355</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM148"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0603</td>
<td valign="top" align="center">0.0218</td>
</tr>
<tr>
<td valign="top" align="left">100</td>
<td valign="top" align="center">0.0182</td>
<td valign="top" align="center">0.3740</td>
<td valign="top" align="center">0.0903</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM149"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0004</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM150"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0001</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM151"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0323</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM152"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0555</td>
<td valign="top" align="center">0.0178</td>
</tr>
<tr>
<td valign="top" align="left">300</td>
<td valign="top" align="center">0.0181</td>
<td valign="top" align="center">0.3704</td>
<td valign="top" align="center">0.0883</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM153"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0004</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM154"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0001</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM155"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0342</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM156"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0509</td>
<td valign="top" align="center">0.0141</td>
</tr>
<tr>
<td valign="top" align="left">400</td>
<td valign="top" align="center">0.0180</td>
<td valign="top" align="center">0.3693</td>
<td valign="top" align="center">0.0879</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM157"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0004</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM158"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0001</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM159"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0331</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM160"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0507</td>
<td valign="top" align="center">0.0148</td>
</tr>
<tr>
<td valign="top" align="left">500</td>
<td valign="top" align="center">0.0179</td>
<td valign="top" align="center">0.3684</td>
<td valign="top" align="center">0.0876</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM161"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0004</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM162"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0001</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM163"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0328</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM164"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0512</td>
<td valign="top" align="center">0.0158</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="table-fn3"><p>The distance is the Euclidean distance from the reference implementation.</p></fn>
</table-wrap-foot>
</table-wrap>
<table-wrap id="T4" position="float"><label>Table 4</label>
<caption><p>The results for the colon dataset in a central setting for different number of bins.</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th valign="top" align="left">&#x0023; bins</th>
<th valign="top" align="center">age</th>
<th valign="top" align="center">grade</th>
<th valign="top" align="center">node</th>
<th valign="top" align="center">pgr</th>
<th valign="top" align="center">er</th>
<th valign="top" align="center">meno</th>
<th valign="top" align="center">hormon</th>
<th valign="top" align="center">Distance</th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left">Lifelines (<xref ref-type="bibr" rid="B10">10</xref>)</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM165"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1512</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM166"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0041</td>
<td valign="top" align="center">0.2209</td>
<td valign="top" align="center">0.2107</td>
<td valign="top" align="center">0.2603</td>
<td valign="top" align="center">0.0872</td>
<td valign="top" align="center">0.2717</td>
<td valign="top" align="center">0.0000</td>
</tr>
<tr>
<td valign="top" align="left">1</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM167"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1027</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM168"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0055</td>
<td valign="top" align="center">0.2131</td>
<td valign="top" align="center">0.2545</td>
<td valign="top" align="center">0.4824</td>
<td valign="top" align="center">0.1818</td>
<td valign="top" align="center">0.4012</td>
<td valign="top" align="center">0.2817</td>
</tr>
<tr>
<td valign="top" align="left">10</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM169"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1347</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM170"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0044</td>
<td valign="top" align="center">0.2212</td>
<td valign="top" align="center">0.2452</td>
<td valign="top" align="center">0.2883</td>
<td valign="top" align="center">0.1203</td>
<td valign="top" align="center">0.3074</td>
<td valign="top" align="center">0.0680</td>
</tr>
<tr>
<td valign="top" align="left">25</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM171"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1350</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM172"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0044</td>
<td valign="top" align="center">0.2235</td>
<td valign="top" align="center">0.1996</td>
<td valign="top" align="center">0.2783</td>
<td valign="top" align="center">0.1026</td>
<td valign="top" align="center">0.2803</td>
<td valign="top" align="center">0.0320</td>
</tr>
<tr>
<td valign="top" align="left">50</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM173"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1431</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM174"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0042</td>
<td valign="top" align="center">0.2224</td>
<td valign="top" align="center">0.2043</td>
<td valign="top" align="center">0.2651</td>
<td valign="top" align="center">0.0966</td>
<td valign="top" align="center">0.2768</td>
<td valign="top" align="center">0.0157</td>
</tr>
<tr>
<td valign="top" align="left">75</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM175"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1445</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM176"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0041</td>
<td valign="top" align="center">0.2205</td>
<td valign="top" align="center">0.2051</td>
<td valign="top" align="center">0.2670</td>
<td valign="top" align="center">0.0946</td>
<td valign="top" align="center">0.2754</td>
<td valign="top" align="center">0.0138</td>
</tr>
<tr>
<td valign="top" align="left">100</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM177"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1452</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM178"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0040</td>
<td valign="top" align="center">0.2215</td>
<td valign="top" align="center">0.2079</td>
<td valign="top" align="center">0.2658</td>
<td valign="top" align="center">0.0937</td>
<td valign="top" align="center">0.2759</td>
<td valign="top" align="center">0.0116</td>
</tr>
<tr>
<td valign="top" align="left">200</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM179"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1465</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM180"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0040</td>
<td valign="top" align="center">0.2185</td>
<td valign="top" align="center">0.2171</td>
<td valign="top" align="center">0.2679</td>
<td valign="top" align="center">0.0936</td>
<td valign="top" align="center">0.2792</td>
<td valign="top" align="center">0.0150</td>
</tr>
<tr>
<td valign="top" align="left">300</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM181"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1470</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM182"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0040</td>
<td valign="top" align="center">0.2186</td>
<td valign="top" align="center">0.2187</td>
<td valign="top" align="center">0.2721</td>
<td valign="top" align="center">0.0942</td>
<td valign="top" align="center">0.2813</td>
<td valign="top" align="center">0.0192</td>
</tr>
<tr>
<td valign="top" align="left">400</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM183"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1473</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM184"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0041</td>
<td valign="top" align="center">0.2166</td>
<td valign="top" align="center">0.2223</td>
<td valign="top" align="center">0.2733</td>
<td valign="top" align="center">0.0947</td>
<td valign="top" align="center">0.2845</td>
<td valign="top" align="center">0.0236</td>
</tr>
<tr>
<td valign="top" align="left">500</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM185"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1476</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM186"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0041</td>
<td valign="top" align="center">0.2168</td>
<td valign="top" align="center">0.2248</td>
<td valign="top" align="center">0.2752</td>
<td valign="top" align="center">0.0953</td>
<td valign="top" align="center">0.2860</td>
<td valign="top" align="center">0.0269</td>
</tr>
<tr>
<td valign="top" align="left">No binning</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM187"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.1473</td>
<td valign="top" align="center"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM188"><mml:mo>&#x2212;</mml:mo></mml:math></inline-formula>0.0041</td>
<td valign="top" align="center">0.2179</td>
<td valign="top" align="center">0.1932</td>
<td valign="top" align="center">0.2542</td>
<td valign="top" align="center">0.0860</td>
<td valign="top" align="center">0.2646</td>
<td valign="top" align="center">0.0205</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="table-fn4"><p>The distance is the Euclidean distance from the reference implementation.</p></fn>
</table-wrap-foot>
</table-wrap>
<p>We see that more time bins lead to better results, up to a certain value. Introducing more time bins beyond that point leads to a more sparse dataset, without adding much more information. For both the Rotterdam and Colon dataset, the optimal number of time bins was 100. The optimal number of bins also depends on the size of the dataset. Interestingly, time-binning can result in models closer to the reference Cox model than the original stacking method.</p>
</sec>
<sec id="s3b3"><label>3.2.3</label><title>Benefit of federated learning</title>
<p>In this experiment, we evaluate the advantages of federated learning over training a Cox model locally. We use the colon dataset (<xref ref-type="bibr" rid="B11">11</xref>) and split the dataset uniformly at random, so that every party has nearly the same number of data points. To ensure robustness, we repeat the experiment 10 times with different splits. The results are in <xref ref-type="table" rid="T5">Table&#x00A0;5</xref>. Examples are also shown in <xref ref-type="fig" rid="F2">Figure&#x00A0;2</xref>, which presents partial results visually.</p>
<table-wrap id="T5" position="float"><label>Table 5</label>
<caption><p>Comparison in accuracy loss for federated and individual models.</p></caption>
<table frame="hsides" rules="groups">
<colgroup>
<col align="left"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
<col align="center"/>
</colgroup>
<thead>
<tr>
<th valign="top" align="center" rowspan="2">Exp.</th>
<th valign="top" align="center" colspan="2"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM189"><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mn>2</mml:mn></mml:math></inline-formula></th>
<th valign="top" align="center" colspan="2"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM190"><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mn>3</mml:mn></mml:math></inline-formula></th>
<th valign="top" align="center" colspan="2"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM191"><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mn>4</mml:mn></mml:math></inline-formula></th>
<th valign="top" align="center" colspan="2"><inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM192"><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mn>5</mml:mn></mml:math></inline-formula></th>
</tr>
<tr>
<th valign="top" align="center">Fed.</th>
<th valign="top" align="center">Ind.</th>
<th valign="top" align="center">Fed.</th>
<th valign="top" align="center">Ind.</th>
<th valign="top" align="center">Fed.</th>
<th valign="top" align="center">Ind.</th>
<th valign="top" align="center">Fed.</th>
<th valign="top" align="center">Ind.</th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left">1</td>
<td valign="top" align="center">0.086692</td>
<td valign="top" align="center">0.508615</td>
<td valign="top" align="center">0.186127</td>
<td valign="top" align="center">0.763789</td>
<td valign="top" align="center">0.301681</td>
<td valign="top" align="center">1.298265</td>
<td valign="top" align="center">0.367590</td>
<td valign="top" align="center">1.793961</td>
</tr>
<tr>
<td valign="top" align="left">2</td>
<td valign="top" align="center">0.085923</td>
<td valign="top" align="center">0.253846</td>
<td valign="top" align="center">0.090872</td>
<td valign="top" align="center">0.750492</td>
<td valign="top" align="center">0.233104</td>
<td valign="top" align="center">1.333657</td>
<td valign="top" align="center">0.221824</td>
<td valign="top" align="center">1.318142</td>
</tr>
<tr>
<td valign="top" align="left">3</td>
<td valign="top" align="center">0.105217</td>
<td valign="top" align="center">0.925193</td>
<td valign="top" align="center">0.150346</td>
<td valign="top" align="center">1.014060</td>
<td valign="top" align="center">0.118710</td>
<td valign="top" align="center">1.258620</td>
<td valign="top" align="center">0.197675</td>
<td valign="top" align="center">1.339609</td>
</tr>
<tr>
<td valign="top" align="left">4</td>
<td valign="top" align="center">0.094011</td>
<td valign="top" align="center">0.861348</td>
<td valign="top" align="center">0.183629</td>
<td valign="top" align="center">1.191052</td>
<td valign="top" align="center">0.396855</td>
<td valign="top" align="center">1.530512</td>
<td valign="top" align="center">0.318490</td>
<td valign="top" align="center">1.325883</td>
</tr>
<tr>
<td valign="top" align="left">5</td>
<td valign="top" align="center">0.074628</td>
<td valign="top" align="center">0.912278</td>
<td valign="top" align="center">0.213943</td>
<td valign="top" align="center">1.117565</td>
<td valign="top" align="center">0.229633</td>
<td valign="top" align="center">1.535407</td>
<td valign="top" align="center">0.269670</td>
<td valign="top" align="center">5.035956</td>
</tr>
<tr>
<td valign="top" align="left">6</td>
<td valign="top" align="center">0.085935</td>
<td valign="top" align="center">0.607380</td>
<td valign="top" align="center">0.192031</td>
<td valign="top" align="center">0.696788</td>
<td valign="top" align="center">0.228756</td>
<td valign="top" align="center">1.167630</td>
<td valign="top" align="center">0.243405</td>
<td valign="top" align="center">1.397925</td>
</tr>
<tr>
<td valign="top" align="left">7</td>
<td valign="top" align="center">0.094830</td>
<td valign="top" align="center">0.513158</td>
<td valign="top" align="center">0.242559</td>
<td valign="top" align="center">1.691819</td>
<td valign="top" align="center">0.174044</td>
<td valign="top" align="center">1.454943</td>
<td valign="top" align="center">0.450566</td>
<td valign="top" align="center">1.888442</td>
</tr>
<tr>
<td valign="top" align="left">8</td>
<td valign="top" align="center">0.082531</td>
<td valign="top" align="center">0.698606</td>
<td valign="top" align="center">0.206044</td>
<td valign="top" align="center">1.099592</td>
<td valign="top" align="center">0.162499</td>
<td valign="top" align="center">1.337512</td>
<td valign="top" align="center">0.320388</td>
<td valign="top" align="center">1.318446</td>
</tr>
<tr>
<td valign="top" align="left">9</td>
<td valign="top" align="center">0.085296</td>
<td valign="top" align="center">0.373202</td>
<td valign="top" align="center">0.214295</td>
<td valign="top" align="center">1.094962</td>
<td valign="top" align="center">0.306755</td>
<td valign="top" align="center">1.179061</td>
<td valign="top" align="center">0.551078</td>
<td valign="top" align="center">4.566361</td>
</tr>
<tr>
<td valign="top" align="left">10</td>
<td valign="top" align="center">0.097963</td>
<td valign="top" align="center">0.783727</td>
<td valign="top" align="center">0.142877</td>
<td valign="top" align="center">0.875390</td>
<td valign="top" align="center">0.317852</td>
<td valign="top" align="center">1.532268</td>
<td valign="top" align="center">0.353232</td>
<td valign="top" align="center">4.702105</td>
</tr>
<tr>
<td valign="top" align="left">avg.</td>
<td valign="top" align="center">0.089302</td>
<td valign="top" align="center">0.643735</td>
<td valign="top" align="center">0.182272</td>
<td valign="top" align="center">1.029550</td>
<td valign="top" align="center">0.246988</td>
<td valign="top" align="center">1.362787</td>
<td valign="top" align="center">0.329391</td>
<td valign="top" align="center">2.468683</td>
</tr>
</tbody>
</table>
<table-wrap-foot>
<fn id="table-fn5"><p>Each row displays results of a different experiment with randomly split data. For <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM193"><mml:mn>2</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mn>5</mml:mn></mml:math></inline-formula> parties, both models are compared to the ideal case of the central Cox model, and the accuracy loss is measured as the Manhattan distance of the model&#x2019;s parameters to those of the ideal model. A lower value therefore means a better approximation of the ideal model. The last row contains the average of the experiments. The colon dataset was again used.</p></fn>
</table-wrap-foot>
</table-wrap>
<fig id="F2" position="float"><label>Figure 2</label>
<caption><p>Comparison between the central Cox model and the models trained only on an individual parties&#x2019; data (<inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM194"><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mn>4</mml:mn></mml:math></inline-formula> parties).</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="fdgth-07-1603630-g002.tif"/>
</fig>
<p>In <xref ref-type="table" rid="T5">Table&#x00A0;5</xref>, we assess the benefits of federated learning in terms of model accuracy, by performing a comprehensive comparison. This table presents the accuracy loss of the federated models alongside that of individually trained models. To ensure a fair comparison, each pair of federated and individual models (corresponding to the same row and number of parties) is trained on identical data partitions.</p>
<p>We measure the accuracy of a model by comparing it to the ideal central Cox model (trained on all of the combined data) and take the accuracy loss to be the Manhattan distance between the coefficients of both models. That is, let <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM195"><mml:mrow><mml:msup><mml:mi>&#x03B2;</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msup></mml:mrow><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msubsup><mml:mi>&#x03B2;</mml:mi><mml:mn>1</mml:mn><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msubsup><mml:mi>&#x03B2;</mml:mi><mml:mi>m</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula> be the optimal coefficients of the central Cox model, and consider some other model with coefficients <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM196"><mml:mrow><mml:mi>&#x03B2;</mml:mi></mml:mrow><mml:mo>=</mml:mo><mml:mo stretchy="false">(</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mn>1</mml:mn></mml:msub><mml:mo>,</mml:mo><mml:mo>&#x2026;</mml:mo><mml:mo>,</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mi>m</mml:mi></mml:msub><mml:mo stretchy="false">)</mml:mo></mml:math></inline-formula>, then we define that model&#x2019;s accuracy loss as<disp-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="UDM14"><mml:munderover><mml:mo>&#x2211;</mml:mo><mml:mrow><mml:mi>i</mml:mi><mml:mo>=</mml:mo><mml:mn>1</mml:mn></mml:mrow><mml:mi>m</mml:mi></mml:munderover><mml:mo fence="false" stretchy="false">|</mml:mo><mml:msub><mml:mi>&#x03B2;</mml:mi><mml:mi>i</mml:mi></mml:msub><mml:mo>&#x2212;</mml:mo><mml:msubsup><mml:mi>&#x03B2;</mml:mi><mml:mi>i</mml:mi><mml:mo>&#x2217;</mml:mo></mml:msubsup><mml:mo fence="false" stretchy="false">|</mml:mo><mml:mo>.</mml:mo></mml:math></disp-formula>A lower value corresponds to a better approximation of the optimal model. We opt for this approach since we wish to assess how well we can fit a Cox model in a federated setting. Therefore, we compare with a reference implementation, instead of using scores like a C-index or calibration plots. Additionally, evaluating the accuracy of a Cox model purely through numerical metrics is challenging and often requires contextual and domain knowledge.</p>
<p>Our findings show that federated models consistently yield results significantly closer to those of the central Cox model than their individually trained counterparts. Although some variance is observed, primarily due to randomness in data partitioning, the accuracy loss in the individual models is approximately 5 to 8 times greater than that of the corresponding federated models. Moreover, for both federated and individual models, accuracy loss increases with the number of parties. This is likely due to the fixed size of the total dataset: as <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM197"><mml:mi>n</mml:mi></mml:math></inline-formula> increases, the data available to each individual party decreases, making it more challenging to fit accurate models. However, in a real-world scenario, adding more parties would typically contribute additional data rather than merely redistributing a fixed dataset. As a result, we expect that increasing the number of parties in practice would enhance model quality by incorporating more diverse information.</p>
<p>Furthermore, <xref ref-type="fig" rid="F2">Figure&#x00A0;2</xref> shows a particular example to illustrate the difference between the models. We see that in this case the individual parties&#x2019; best models are quite inaccurate and in most cases not comparable to the ideal centralized model. For instance, the model trained by Party 2 overestimates the coefficients for the covariates sex, obstruct, and perfor, while underestimating the coefficient for surg. Consequently, this misestimate leads to over- and underestimation of the effects of these covariates on survival probabilities, resulting in less reliable predictions. This highlights that models trained on a limited subset of the data generally perform significantly worse than those trained on the complete dataset. This demonstrates the clear benefits of collaborative approaches such as federated learning, which enable improved model performance without requiring data centralization.</p>
</sec>
<sec id="s3b4"><label>3.2.4</label><title>Accuracy of federated Cox regression</title>
<p>We now evaluate the accuracy of the federated Cox regression model. Survival stacking and data federation can both lead to inaccuracies in the outcome model. Here we assess this loss in accuracy, by testing it on the colon dataset with 25 bins.</p>
<p><xref ref-type="fig" rid="F3">Figure&#x00A0;3</xref> presents the results of the central Cox model and the central logistic regression model, both of which assume a fully centralized setting where all data is aggregated in a single location. Alongside these, it shows the outcomes of the federated Cox regression for varying numbers of participating parties. Note that the central Cox model is the same as in <xref ref-type="fig" rid="F2">Figure&#x00A0;2</xref>. However, while <xref ref-type="fig" rid="F2">Figure&#x00A0;2</xref> examines individual Cox models trained by a single party on a fraction of the complete dataset (with a fixed number of parties, <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM198"><mml:mi>n</mml:mi><mml:mo>=</mml:mo><mml:mn>4</mml:mn></mml:math></inline-formula>), here we evaluate federated models trained across all <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM199"><mml:mi>n</mml:mi></mml:math></inline-formula> parties, where <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM200"><mml:mn>2</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mn>5</mml:mn></mml:math></inline-formula>.</p>
<fig id="F3" position="float"><label>Figure 3</label>
<caption><p>Comparison between the central (ideal) model, the model with survival stacking, and models trained by federated learning with <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM201"><mml:mn>2</mml:mn><mml:mo>&#x2264;</mml:mo><mml:mi>n</mml:mi><mml:mo>&#x2264;</mml:mo><mml:mn>5</mml:mn></mml:math></inline-formula> parties.</p></caption>
<graphic xmlns:xlink="http://www.w3.org/1999/xlink" xlink:href="fdgth-07-1603630-g003.tif"/>
</fig>
<p>This figure indicates that the federated models closely approximate the centrally trained Cox model. Furthermore, the sources of error introduced by survival stacking and federated learning do not necessarily compound. For example, for the covariate sex, the central logistic regression model overestimates the coefficient relative to the central Cox regression model, whereas the federated regression model underestimates it relative to the central logistic regression model. This interaction results in a slight improvement in the overall estimation. The <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM202"><mml:mi>p</mml:mi></mml:math></inline-formula>-values give an indication of the error.</p>
<p>Our results demonstrate that federated models produce significantly more accurate predictions than models trained independently by individual parties. These findings underscore the benefits of collaborative model training, particularly in scenarios where direct data sharing is not feasible. Federated learning thus presents a viable approach for improving Cox model accuracy while preserving data privacy.</p>
</sec>
</sec>
</sec>
<sec id="s4" sec-type="discussion"><label>4</label><title>Discussion</title>
<sec id="s4a"><label>4.1</label><title>Related work</title>
<p>The Cox model has been extensively studied in the scientific community [see, e.g., (<xref ref-type="bibr" rid="B12">12</xref>) for an overview], and several approaches have been proposed for fitting a Cox model in a federated setting using privacy-preserving methods. Some studies employ statistical learning techniques (<xref ref-type="bibr" rid="B6">6</xref>, <xref ref-type="bibr" rid="B13">13</xref>, <xref ref-type="bibr" rid="B14">14</xref>), while others utilize secure multi-party computation (MPC) (<xref ref-type="bibr" rid="B15">15</xref>) or related cryptographic techniques (<xref ref-type="bibr" rid="B16">16</xref>). Furthermore, the combination of survival stacking with federated learning has been explored in previous work, often in conjunction with custom classifiers rather than logistic regression (<xref ref-type="bibr" rid="B17">17</xref>&#x2013;<xref ref-type="bibr" rid="B19">19</xref>).</p>
<p>However, many of these existing solutions involve sharing time-to-event information between participating institutions. In our approach, we treat time as a privacy-sensitive variable during the learning phase and ensure that it is not shared. Some alternative methods also avoid sharing time, but instead report only model performance metrics such as the concordance index (c-index). Our findings indicate that multiple distinct models can yield the same c-index, and furthermore, the c-index is not a reliable performance metric in all scenarios (<xref ref-type="bibr" rid="B20">20</xref>). To address this limitation, we compare models trained using our distributed approach against known models from the centralized setting.</p>
<p>Furthermore, we incorporate statistical significance testing through <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM203"><mml:mi>p</mml:mi></mml:math></inline-formula>-value computation and implement a commonly used diagnostic tool in medical research: Schoenfeld residuals. To the best of our knowledge, this is the first study to compute Schoenfeld residuals on distributed data.</p>
</sec>
<sec id="s4b"><label>4.2</label><title>Performance</title>
<p>While our proposed approach yields very significant privacy and security benefits, this comes at the cost of computational complexity. It is clear that these privacy-preserving methods (in this case federated learning and MPC) introduce some additional overhead, both in computational effort and communication time, compared to a centralized approach. That being said, federated learning does not introduce a large amount of overhead, as the protocol only requires parties to communicate relatively small updates to the model, and the dominating computation is still calculating these updates (which is required regardless of federated learning). MPC introduces comparatively more overhead, but arguably this is still manageable. Specifically because the computation in question (that of Schoenfeld residuals) is not extremely complex. Furthermore, we see in general that training a model such as the Cox Proportional Hazards Model is not a time-constrained task; often there is quite some time available and it is not vital for the training process to complete in seconds. In this way, the additional overhead is not as destructive as it is in some other applications. Finally, we argue that this drawback does not weigh up against the benefit of added privacy, specifically because we are considering sensitive patient data. In fact, using a central model is theoretically better than using a federated model, but the latter is practically much better than not collaborating with data at all.</p>
</sec>
<sec id="s4c"><label>4.3</label><title>Further research</title>
<p>Our approach focuses on horizontally partitioned data, where each individual is associated with a single party that has access to all covariates for that individual. In contrast, vertically partitioned data refers to a setting in which all parties have records for the same individuals but possess only a subset of the covariates. Horizontal partitioning is more straightforward to implement in a federated learning framework, as each party can independently evaluate individuals and observe their respective events. In a vertically partitioned setting, however, no single party has access to both the outcome events and the full set of covariates, making model training significantly more complex. Additionally, survival stacking is also requires communication between the parties. The complexity and development of vertically federated Cox regression using survival stacking remains an open research problem.</p>
<p>In this study, we provide model assessment by incorporating <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM204"><mml:mi>p</mml:mi></mml:math></inline-formula>-values and Schoenfeld residuals in the code. However, in the evaluation of medical models, additional validation techniques, such as calibration plots, are commonly used in practice. Implementing these methods in a privacy-preserving manner could further improve the applicability and robustness of our approach.</p>
<p>Additionally, the number of time bins is a critical parameter in survival stacking, directly influencing model accuracy. Selecting an appropriate number of bins is essential for reliable estimation. Developing methods to determine the optimal number of bins prior to model training would be a valuable extension to this work, improving both efficiency and predictive performance.</p>
</sec>
</sec>
</body>
<back>
<sec id="s5" sec-type="data-availability"><title>Data availability statement</title>
<p>Publicly available datasets were analyzed in this study. This data can be found here: <ext-link ext-link-type="uri" xlink:href="https://search.r-project.org/CRAN/refmans/condSURV/html/colonCS.html">https://search.r-project.org/CRAN/refmans/condSURV/html/colonCS.html</ext-link>.</p>
</sec>
<sec id="s6" sec-type="author-contributions"><title>Author contributions</title>
<p>FW: Writing &#x2013; original draft, Writing &#x2013; review &#x0026; editing, Investigation, Methodology, Software, Validation; SL: Writing &#x2013; original draft, Writing &#x2013; review &#x0026; editing, Investigation, Methodology, Software, Validation, Visualization; LT: Investigation, Software, Writing &#x2013; review &#x0026; editing.</p>
</sec>
<sec id="s7" sec-type="funding-information"><title>Funding</title>
<p>The author(s) declare that financial support was received for the research and/or publication of this article. This research has been performed as part of the ITEA4 project 20050 &#x201C;Secur-e-health&#x201D;.</p>
</sec>
<ack><title>Acknowledgments</title>
<p>This research has been performed as part of the ITEA4 project 20050 &#x201C;Secur-e-health&#x201D;. The authors have no conflicts of interest to declare. Artificial intelligence has been used for grammar and spelling checks.</p>
</ack>
<sec id="s8" sec-type="COI-statement"><title>Conflict of interest</title>
<p>The authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.</p>
</sec>
<sec id="s9" sec-type="ai-statement"><title>Generative AI statement</title>
<p>The author(s) declare that Generative AI was used in the creation of this manuscript exclusively for spelling checks.</p>
</sec>
<sec id="s10" sec-type="disclaimer"><title>Publisher&#x0027;s note</title>
<p>All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.</p>
</sec>
<ref-list><title>References</title>
<ref id="B1"><label>1.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Cox</surname><given-names>DR</given-names></name></person-group>. <article-title>Regression models and life-tables</article-title>. <source>J R Stat Soc Ser B (Methodol)</source>. (<year>1972</year>) <volume>34</volume>(<issue>2</issue>):<fpage>187</fpage>&#x2013;<lpage>202</lpage>. <pub-id pub-id-type="doi">10.1111/j.2517-6161.1972.tb00899.x</pub-id></citation></ref>
<ref id="B2"><label>2.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Cho</surname><given-names>H</given-names></name><name><surname>Froelicher</surname><given-names>D</given-names></name><name><surname>Dokmai</surname><given-names>N</given-names></name><name><surname>Nandi</surname><given-names>A</given-names></name><name><surname>Sadhuka</surname><given-names>S</given-names></name><name><surname>Hong</surname><given-names>MM</given-names></name><etal/></person-group>. <article-title>Privacy-enhancing technologies in biomedical data science</article-title>. <source>Annu Rev Biomed Data Sci</source>. (<year>2024</year>) <volume>7</volume>:<fpage>317</fpage>&#x2013;<lpage>43</lpage>. <pub-id pub-id-type="doi">10.1146/annurev-biodatasci-120423-120107</pub-id><pub-id pub-id-type="pmid">39178425</pub-id></citation></ref>
<ref id="B3"><label>3.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>McMahan</surname><given-names>B</given-names></name><name><surname>Moore</surname><given-names>E</given-names></name><name><surname>Ramage</surname><given-names>D</given-names></name><name><surname>Hampson</surname><given-names>S</given-names></name><name><surname>y Arcas</surname><given-names>BA</given-names></name></person-group>. <article-title>Communication-efficient learning of deep networks from decentralized data</article-title>. <comment>In: <italic>Artificial Intelligence and Statistics</italic>. PMLR (2017). p. 1273&#x2013;82</comment>.</citation></ref>
<ref id="B4"><label>4.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Craig</surname><given-names>E</given-names></name><name><surname>Zhong</surname><given-names>C</given-names></name><name><surname>Tibshirani</surname><given-names>R</given-names></name></person-group>. <article-title>Survival stacking: casting survival analysis as a classification problem</article-title>. <comment><italic>arXiv:2107.13480</italic> [Preprint] (2021)</comment>. <pub-id pub-id-type="doi">10.48550/arXiv.2107.13480</pub-id></citation></ref>
<ref id="B5"><label>5.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Yao</surname><given-names>AC</given-names></name></person-group>. <article-title>Protocols for secure computations</article-title>. <comment>In: <italic>23rd Annual Symposium on Foundations of Computer Science (SFCS 1982)</italic> (1982). p. 160&#x2013;4</comment>.</citation></ref>
<ref id="B6"><label>6.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Andreux</surname><given-names>M</given-names></name><name><surname>Manoel</surname><given-names>A</given-names></name><name><surname>Menuet</surname><given-names>R</given-names></name><name><surname>Saillard</surname><given-names>C</given-names></name><name><surname>Simpson</surname><given-names>C</given-names></name></person-group>. <article-title>Federated survival analysis with discrete-time Cox models</article-title>. <comment><italic>CoRR</italic>, <italic>abs/2006.08997</italic> (2020)</comment>.</citation></ref>
<ref id="B7"><label>7.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Schoenfeld</surname><given-names>D</given-names></name></person-group>. <article-title>Partial residuals for the proportional hazards regression model</article-title>. <source>Biometrika</source>. (<year>1982</year>) <volume>69</volume>(<issue>1</issue>):<fpage>239</fpage>&#x2013;<lpage>41</lpage>. <pub-id pub-id-type="doi">10.1093/biomet/69.1.239</pub-id></citation></ref>
<ref id="B8"><label>8.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Schoenmakers</surname><given-names>B</given-names></name></person-group>. <article-title>MPyC: multiparty computation in Python</article-title>. (<year>2018</year>). <comment>Available at:</comment> <ext-link ext-link-type="uri" xlink:href="https://github.com/lschoe/mpyc">https://github.com/lschoe/mpyc</ext-link> <comment>(Accessed March 31, 2025)</comment>.</citation></ref>
<ref id="B9"><label>9.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Shamir</surname><given-names>A</given-names></name></person-group>. <article-title>How to share a secret</article-title>. <source>Commun ACM</source>. (<year>1979</year>) <volume>22</volume>(<issue>11</issue>):<fpage>612</fpage>&#x2013;<lpage>3</lpage>. <pub-id pub-id-type="doi">10.1145/359168.359176</pub-id></citation></ref>
<ref id="B10"><label>10.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Davidson-Pilon</surname><given-names>C</given-names></name></person-group>. <article-title>Lifelines, survival analysis in Python</article-title> (<year>2019</year>). <comment>Available at:</comment> <ext-link ext-link-type="uri" xlink:href="https://github.com/camDavidsonPilon/lifelines">https://github.com/camDavidsonPilon/lifelines</ext-link> <comment>(Accessed March 31, 2025)</comment></citation></ref>
<ref id="B11"><label>11.</label><citation citation-type="other"><collab>The R Project for Statistical Computing</collab>. <article-title>Chemotherapy for stage b/c colon cancer</article-title>. <comment>Available at:</comment> <ext-link ext-link-type="uri" xlink:href="https://search.r-project.org/CRAN/refmans/condSURV/html/colonCS.html">https://search.r-project.org/CRAN/refmans/condSURV/html/colonCS.html</ext-link> <comment>(Accessed March 27, 2025)</comment>.</citation></ref>
<ref id="B12"><label>12.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Kalbfleisch</surname><given-names>JD</given-names></name><name><surname>Schaubel</surname><given-names>DE</given-names></name></person-group>. <article-title>Fifty years of the Cox model</article-title>. <source>Annu Rev Stat Appl</source>. (<year>2023</year>) <volume>10</volume>:<fpage>1</fpage>&#x2013;<lpage>23</lpage>. <pub-id pub-id-type="doi">10.1146/annurev-statistics-033021-014043</pub-id></citation></ref>
<ref id="B13"><label>13.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Lu</surname><given-names>C-L</given-names></name><name><surname>Wang</surname><given-names>S</given-names></name><name><surname>Ji</surname><given-names>Z</given-names></name><name><surname>Wu</surname><given-names>Y</given-names></name><name><surname>Xiong</surname><given-names>L</given-names></name><name><surname>Jiang</surname><given-names>X</given-names></name><etal/></person-group>. <article-title>WebDISCO: a web service for distributed Cox model learning without patient-level data sharing</article-title>. <source>J Am Med Inform Assoc JAMIA</source>. (<year>2015</year>) <volume>22</volume>(<issue>6</issue>):<fpage>1212</fpage>&#x2013;<lpage>9</lpage>. <pub-id pub-id-type="doi">10.1093/jamia/ocv083</pub-id><pub-id pub-id-type="pmid">26159465</pub-id></citation></ref>
<ref id="B14"><label>14.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Masciocchi</surname><given-names>C</given-names></name><name><surname>Gottardelli</surname><given-names>B</given-names></name><name><surname>Savino</surname><given-names>M</given-names></name><name><surname>Boldrini</surname><given-names>L</given-names></name><name><surname>Martino</surname><given-names>A</given-names></name><name><surname>Mazzarella</surname><given-names>C</given-names></name><etal/></person-group>. <article-title>Federated Cox Proportional Hazards Model with multicentric privacy-preserving LASSO feature selection for survival analysis from the perspective of personalized medicine</article-title>. <comment>In: <italic>2022 IEEE 35th International Symposium on Computer-Based Medical Systems (CBMS)</italic> (2022). p. 25&#x2013;31. ISSN: 2372&#x2013;9198</comment>.</citation></ref>
<ref id="B15"><label>15.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Kamphorst</surname><given-names>B</given-names></name><name><surname>Rooijakkers</surname><given-names>T</given-names></name><name><surname>Veugen</surname><given-names>T</given-names></name><name><surname>Cellamare</surname><given-names>M</given-names></name><name><surname>Knoors</surname><given-names>D</given-names></name></person-group>. <article-title>Accurate training of the Cox proportional hazards model on vertically-partitioned data while preserving privacy</article-title>. <source>BMC Med Inform Decis Mak</source>. (<year>2022</year>) <volume>22</volume>(<issue>1</issue>):<fpage>49</fpage>. <pub-id pub-id-type="doi">10.1186/s12911-022-01771-3</pub-id><pub-id pub-id-type="pmid">35209883</pub-id></citation></ref>
<ref id="B16"><label>16.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Imakura</surname><given-names>A</given-names></name><name><surname>Tsunoda</surname><given-names>R</given-names></name><name><surname>Kagawa</surname><given-names>R</given-names></name><name><surname>Yamagata</surname><given-names>K</given-names></name><name><surname>Sakurai</surname><given-names>T</given-names></name></person-group>. <article-title>DC-COX: Data collaboration Cox proportional hazards model for privacy-preserving survival analysis on multiple parties</article-title>. <source>J Biomed Inform</source>. (<year>2023</year>) <volume>137</volume>:<fpage>104264</fpage>. <pub-id pub-id-type="doi">10.1016/j.jbi.2022.104264</pub-id><pub-id pub-id-type="pmid">36462599</pub-id></citation></ref>
<ref id="B17"><label>17.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Kvamme</surname><given-names>H</given-names></name><name><surname>Borgan</surname><given-names>&#x00D8;</given-names></name><name><surname>Scheel</surname><given-names>I</given-names></name></person-group>. <article-title>Time-to-event prediction with neural networks and Cox regression</article-title>. <source>J Mach Learn Res</source>. (<year>2019</year>) <volume>20</volume>(<issue>129</issue>):<fpage>1</fpage>&#x2013;<lpage>30</lpage>. <pub-id pub-id-type="doi">10.48550/arXiv.1907.0082</pub-id></citation></ref>
<ref id="B18"><label>18.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Van Ness</surname><given-names>M</given-names></name><name><surname>Bosschieter</surname><given-names>T</given-names></name><name><surname>Din</surname><given-names>N</given-names></name><name><surname>Ambrosy</surname><given-names>A</given-names></name><name><surname>Sandhu</surname><given-names>A</given-names></name><name><surname>Udell</surname><given-names>M</given-names></name></person-group>. <article-title>Interpretable survival analysis for heart failure risk prediction</article-title>. <comment>In: <italic>Machine Learning for Health (ML4H)</italic>. PMLR (2023). p. 574&#x2013;93</comment>.</citation></ref>
<ref id="B19"><label>19.</label><citation citation-type="other"><person-group person-group-type="author"><name><surname>Zhang</surname><given-names>DK</given-names></name><name><surname>Toni</surname><given-names>F</given-names></name><name><surname>Williams</surname><given-names>M</given-names></name></person-group>. <article-title>A federated Cox model with non-proportional hazards</article-title>. <comment>In: <italic>Multimodal AI in Healthcare: A Paradigm Shift in Health Intelligence</italic>. Springer (2022). p. 171&#x2013;85</comment>.</citation></ref>
<ref id="B20"><label>20.</label><citation citation-type="journal"><person-group person-group-type="author"><name><surname>Blanche</surname><given-names>P</given-names></name><name><surname>Kattan</surname><given-names>MW</given-names></name><name><surname>Gerds</surname><given-names>TA</given-names></name></person-group>. <article-title>The c-index is not proper for the evaluation of <inline-formula><mml:math xmlns:mml="http://www.w3.org/1998/Math/MathML" id="IM205"><mml:mi>t</mml:mi></mml:math></inline-formula>-year predicted risks</article-title>. <source>Biostatistics</source>. (<year>2019</year>) <volume>20</volume>(<issue>2</issue>):<fpage>347</fpage>&#x2013;<lpage>57</lpage>. <pub-id pub-id-type="doi">10.1093/biostatistics/kxy006</pub-id><pub-id pub-id-type="pmid">29462286</pub-id></citation></ref></ref-list>
</back>
</article>