{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T20:20:52Z","timestamp":1778098852972,"version":"3.51.4"},"publisher-location":"Cham","reference-count":39,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030968953","type":"print"},{"value":"9783030968960","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-030-96896-0_15","type":"book-chapter","created":{"date-parts":[[2022,7,7]],"date-time":"2022-07-07T12:16:52Z","timestamp":1657196212000},"page":"337-361","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Data Leakage in Federated Learning"],"prefix":"10.1007","author":[{"given":"Xiao","family":"Jin","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pin-Yu","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tianyi","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,2,8]]},"reference":[{"key":"15_CR1","unstructured":"Beguier C, Tramel EW (2020) SAFER: Sparse secure aggregation for federated learning. arXiv, eprint:200714861"},{"key":"15_CR2","unstructured":"Chen T, Jin X, Sun Y, Yin W (2020) VAFL: a method of vertical asynchronous federated learning. In: International workshop on federated learning for user privacy and data confidentiality in conjunction with ICML"},{"key":"15_CR3","unstructured":"Cheng K, Fan T, Jin Y, Liu Y, Chen T, Yang Q (2019) Secureboost: A lossless federated learning framework. arXiv, eprint:190108755"},{"key":"15_CR4","doi-asserted-by":"crossref","unstructured":"Dwork C, Smith A, Steinke T, Ullman J, Vadhan S (2015) Robust traceability from trace amounts. In: 2015 IEEE 56th annual symposium on foundations of computer science, USA, pp 650\u2013669","DOI":"10.1109\/FOCS.2015.46"},{"key":"15_CR5","doi-asserted-by":"crossref","unstructured":"Fan L, Ng K, Ju C, Zhang T, Liu C, Chan CS, Yang Q (2020) Rethinking privacy preserving deep learning: How to evaluate and thwart privacy attacks. arXiv, eprint:200611601","DOI":"10.1007\/978-3-030-63076-8_3"},{"key":"15_CR6","doi-asserted-by":"crossref","unstructured":"Fredrikson M, Jha S, Ristenpart T (2015) Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22nd ACM SIGSAC conference on computer and communications security. Association for Computing Machinery, New York, NY, pp 1322\u20131333","DOI":"10.1145\/2810103.2813677"},{"key":"15_CR7","first-page":"16937","volume":"33","author":"J Geiping","year":"2020","unstructured":"Geiping J, Bauermeister H, Dr\u00f6ge H, Moeller M (2020) Inverting gradients - how easy is it to break privacy in federated learning? In: Advances in neural information processing systems, vol 33, pp 16937\u201316947","journal-title":"Advances in neural information processing systems, vol"},{"key":"15_CR8","volume-title":"Digital image processing","author":"RC Gonzalez","year":"1992","unstructured":"Gonzalez RC, Woods RE (1992) Digital image processing. Addison-Wesley, New York"},{"key":"15_CR9","doi-asserted-by":"crossref","unstructured":"Guerraoui R, Gupta N, Pinot R, Rouault S, Stephan J (2021) Differential privacy and byzantine resilience in SGD: Do they add up? arXiv, eprint:210208166","DOI":"10.1145\/3465084.3467919"},{"key":"15_CR10","unstructured":"Guo S, Zhang T, Xiang T, Liu Y (2020) Differentially private decentralized learning. arXiv, eprint:200607817"},{"key":"15_CR11","doi-asserted-by":"crossref","unstructured":"Hitaj B, Ateniese G, P\u00e9rez-Cruz F (2017) Deep models under the GAN: information leakage from collaborative deep learning. arXiv, eprint:170207464","DOI":"10.1145\/3133956.3134012"},{"key":"15_CR12","doi-asserted-by":"crossref","unstructured":"Huang Y, Song Z, Chen D, Li K, Arora S (2020) TextHide: Tackling data privacy in language understanding tasks. In: The conference on empirical methods in natural language processing","DOI":"10.18653\/v1\/2020.findings-emnlp.123"},{"key":"15_CR13","unstructured":"Huang Y, Su Y, Ravi S, Song Z, Arora S, Li K (2020) Privacy-preserving learning via deep net pruning. arXiv, eprint:200301876"},{"key":"15_CR14","first-page":"118","volume-title":"International workshop on federated learning for user privacy and data confidentiality. West","author":"Z Li","year":"2019","unstructured":"Li Z, Huang Z, Chen C, Hong C (2019) Quantification of the leakage in federated learning. In: International workshop on federated learning for user privacy and data confidentiality. West 118\u2013120 Vancouver Convention Center, Vancouver"},{"key":"15_CR15","unstructured":"Li O, Sun J, Yang X, Gao W, Zhang H, Xie J, Smith V, Wang C (2021) Label leakage and protection in two-party split learning. arXiv, eprint:210208504"},{"key":"15_CR16","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1007\/978-3-540-25952-7_6","volume-title":"2nd Symposium on intelligence and security informatics (ISI 2004)","author":"G Liang","year":"2004","unstructured":"Liang G, Chawathe SS (2004) Privacy-preserving inter-database operations. In: 2nd Symposium on intelligence and security informatics (ISI 2004), Berlin, Heidelberg, pp 66\u201382"},{"key":"15_CR17","doi-asserted-by":"crossref","unstructured":"Liu R, Cao Y, Yoshikawa M, Chen H (2020) FedSel: Federated SGD under local differential privacy with top-k dimension selection. arXiv, eprint:200310637","DOI":"10.1007\/978-3-030-59410-7_33"},{"key":"15_CR18","doi-asserted-by":"crossref","unstructured":"Liu Y, Kang Y, Zhang X, Li L, Cheng Y, Chen T, Hong M, Yang Q (2020) A communication efficient vertical federated learning framework. arXiv, eprint:191211187","DOI":"10.1007\/978-3-031-01585-4_5"},{"key":"15_CR19","unstructured":"Long Y, Bindschaedler V, Wang L, Bu D, Wang X, Tang H, Gunter CA, Chen K (2018) Understanding membership inferences on well-generalized learning models. arXiv, eprint:180204889"},{"key":"15_CR20","doi-asserted-by":"crossref","unstructured":"Lyu L, Yu H, Ma X, Sun L, Zhao J, Yang Q, Yu PS (2020) Privacy and robustness in federated learning: Attacks and defenses. arXiv, eprint:201206337","DOI":"10.1007\/978-3-030-63076-8_1"},{"key":"15_CR21","unstructured":"McMahan HB, Moore E, Ramage D, y Arcas BA (2016) Federated learning of deep networks using model averaging. arXiv, eprint:160205629"},{"key":"15_CR22","unstructured":"Melis L, Song C, Cristofaro ED, Shmatikov V (2018) Inference attacks against collaborative learning. In: Proceedings of the 35th annual computer security applications conference. Association for Computing Machinery, New York, NY, pp 148\u2013162"},{"key":"15_CR23","unstructured":"Niu C, Wu F, Tang S, Hua L, Jia R, Lv C, Wu Z, Chen G (2019) Secure federated submodel learning. arXiv, eprint:191102254"},{"key":"15_CR24","doi-asserted-by":"crossref","unstructured":"Pan X, Zhang M, Yan Y, Zhu J, Yang M (2020) Theory-oriented deep leakage from gradients via linear equation solver. arXiv, eprint:201013356","DOI":"10.1007\/978-3-030-63076-8_2"},{"key":"15_CR25","unstructured":"Qian J, Nassar H, Hansen LK (2021) On the limits to learning input data from gradients. arXiv, eprint:201015718"},{"key":"15_CR26","doi-asserted-by":"crossref","unstructured":"Scannapieco M, Figotin I, Bertino E, Elmagarmid A (2007) Privacy preserving schema and data matching. In: Proceedings of the ACM SIGMOD international conference on management of data, Beijing, pp 653\u2013664","DOI":"10.1145\/1247480.1247553"},{"key":"15_CR27","doi-asserted-by":"crossref","unstructured":"Shokri R, Shmatikov V (2015) Privacy-preserving deep learning. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, Association for Computing Machinery, New York, NY, CCS \u201915, pp 1310\u20131321","DOI":"10.1145\/2810103.2813687"},{"key":"15_CR28","doi-asserted-by":"crossref","unstructured":"Shokri R, Stronati M, Song C, Shmatikov V (2017) Membership inference attacks against machine learning models. In: 2017 IEEE symposium on security and privacy (SP), pp 3\u201318","DOI":"10.1109\/SP.2017.41"},{"key":"15_CR29","doi-asserted-by":"crossref","unstructured":"So J, Guler B, Avestimehr AS (2021) Byzantine-resilient secure federated learning. arXiv, eprint:200711115","DOI":"10.1109\/JSAC.2020.3041404"},{"key":"15_CR30","doi-asserted-by":"crossref","unstructured":"So J, Guler B, Avestimehr AS (2021) Turbo-aggregate: Breaking the quadratic aggregation barrier in secure federated learning. arXiv, eprint:200204156","DOI":"10.1109\/JSAIT.2021.3054610"},{"key":"15_CR31","doi-asserted-by":"crossref","unstructured":"Sun L, Lyu L (2020) Federated model distillation with noise-free differential privacy. arXiv, eprint:200905537","DOI":"10.24963\/ijcai.2021\/216"},{"key":"15_CR32","doi-asserted-by":"crossref","unstructured":"Sun J, Li A, Wang B, Yang H, Li H, Chen Y (2020) Provable defense against privacy leakage in federated learning from representation perspective. arXiv, eprint:201206043","DOI":"10.1109\/CVPR46437.2021.00919"},{"key":"15_CR33","doi-asserted-by":"publisher","DOI":"10.1137\/1.9780898719574","volume-title":"Numerical linear algebra","author":"LN Trefethen","year":"1997","unstructured":"Trefethen LN, Bau D (1997) Numerical linear algebra. SIAM, Philadelphia"},{"key":"15_CR34","unstructured":"Wei W, Liu L, Loper M, Chow KH, Gursoy ME, Truex S, Wu Y (2020) A framework for evaluating gradient leakage attacks in federated learning. arXiv, eprint:200410397"},{"key":"15_CR35","doi-asserted-by":"crossref","unstructured":"Wei K, Li J, Ding M, Ma C, Su H, Zhang B, Poor HV (2021) User-level privacy-preserving federated learning: Analysis and performance optimization. arXiv, eprint:200300229","DOI":"10.1109\/TMC.2021.3056991"},{"key":"15_CR36","doi-asserted-by":"crossref","unstructured":"Yang Q, Liu Y, Chen T, Tong Y (2019) Federated machine learning: Concept and applications, vol 10. Association for Computing Machinery, New York, NY","DOI":"10.1145\/3298981"},{"key":"15_CR37","unstructured":"Zhao B, Mopuri KR, Bilen H (2020) iDLG: Improved deep leakage from gradients. arXiv, eprint:200102610"},{"key":"15_CR38","unstructured":"Zhu J, Blaschko MB (2021) R-GAP: Recursive gradient attack on privacy. In: International conference on learning representations"},{"key":"15_CR39","unstructured":"Zhu L, Liu Z, Han S (2019) Deep leakage from gradients. In: Advances in neural information processing systems, Vancouver, pp 14774\u201314784"}],"container-title":["Federated Learning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-96896-0_15","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,7]],"date-time":"2022-07-07T12:29:38Z","timestamp":1657196978000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-96896-0_15"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783030968953","9783030968960"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-96896-0_15","relation":{},"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"8 February 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}