CIPHER: A Differentially Private Federated Framework for Privacy-Preserving Multi-Criteria Group Decision Making
Group multi-criteria decision making (MCDM) in distributed organizations demands aggregating private preference matrices across multiple decision-makers, raising serious data privacy challenges. Centralized aggregation exposes individual evaluations to unauthorized disclosure, while secure multi-party computation (SMPC) imposes prohibitive communication overhead. This paper introduces CIPHER (Collaborative Information-Privacy Hierarchical fEderated decision-making fRamework), a novel framework integrating federated learning with formal differential privacy (DP) guarantees for multi-criteria group decision making. CIPHER enables geographically distributed decision-makers to contribute local evaluation matrices toward a globally consistent alternative ranking while preserving (ε, δ)-differential privacy. The framework applies a calibrated Gaussian mechanism to locally computed TOPSIS closeness coefficients before federated aggregation, providing rigorous mathematical privacy guarantees without exposing raw preference data. Theoretical bounds on rank distortion as a function of privacy budget epsilon are derived, alongside convergence guarantees under heterogeneous decision-maker weight distributions. CIPHER is evaluated on three publicly available datasets: green supplier selection (Mendeley Data, n=31), healthcare resource allocation (CMS HCRIS, n=47), and financial portfolio prioritization (OR-Library, n=85 assets). CIPHER achieves Kendall τ > 0.91 at ε=1.0, reduces communication overhead by 99.9% versus SMPC, and maintains robust utility under K=20 distributed decision-makers, establishing CIPHER as a practical, privacy-first solution for multi-stakeholder decision environments.