Bridging Differential Privacy and Byzantine-Robustness via Model Aggregation