{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,24]],"date-time":"2025-09-24T02:10:01Z","timestamp":1758679801891,"version":"3.44.0"},"publisher-location":"Cham","reference-count":32,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032056658","type":"print"},{"value":"9783032056634","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,9,25]],"date-time":"2025-09-25T00:00:00Z","timestamp":1758758400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,9,25]],"date-time":"2025-09-25T00:00:00Z","timestamp":1758758400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-05663-4_8","type":"book-chapter","created":{"date-parts":[[2025,9,24]],"date-time":"2025-09-24T01:43:03Z","timestamp":1758678183000},"page":"80-90","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Mitigating Data Exfiltration Attacks Through Layer-Wise Learning Rate Decay Fine-Tuning"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0007-2747-1637","authenticated-orcid":false,"given":"Elie","family":"Thellier","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Huiyu","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nicholas","family":"Ayache","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6050-5949","authenticated-orcid":false,"given":"Herv\u00e9","family":"Delingette","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,9,25]]},"reference":[{"key":"8_CR1","doi-asserted-by":"publisher","first-page":"1302","DOI":"10.1016\/j.procs.2023.10.118","volume":"225","author":"T Gentner","year":"2023","unstructured":"Gentner, T., Neitzel, T., Schulze, J., Gerschner, F., Theissler, A.: Data lakes in healthcare: applications and benefits from the perspective of data sources and players. Proc. Comput. Sci. 225, 1302\u20131311 (2023)","journal-title":"Proc. Comput. Sci."},{"issue":"6","key":"8_CR2","doi-asserted-by":"publisher","first-page":"305","DOI":"10.1038\/s42256-020-0186-1","volume":"2","author":"GA Kaissis","year":"2020","unstructured":"Kaissis, G.A., Makowski, M.R., R\u00fcckert, D., Braren, R.F.: Secure, privacy-preserving and federated machine learning in medical imaging. Nat. Mach. Intell. 2(6), 305\u2013311 (2020)","journal-title":"Nat. Mach. Intell."},{"key":"8_CR3","unstructured":"Gong, X., et al.: Hidden data privacy breaches in federated learning. arXiv preprint arXiv:2411.18269 (2024)"},{"key":"8_CR4","unstructured":"Wu, M., et al.: Evaluation of inference attack models for deep learning on medical data. arXiv preprint arXiv:2011.00177 (2020)"},{"key":"8_CR5","doi-asserted-by":"publisher","unstructured":"Xu, T., Liu, C., Zhang, K., Zhang, J.: Membership inference attacks against medical databases. In: International Conference on Neural Information Processing, pp. 15\u201325. Springer (2023). https:\/\/doi.org\/10.1007\/978-981-99-8138-0_2","DOI":"10.1007\/978-981-99-8138-0_2"},{"key":"8_CR6","doi-asserted-by":"crossref","unstructured":"Dibbo, S.V.: Sok: model inversion attack landscape: taxonomy, challenges, and future roadmap. In: 2023 IEEE 36th Computer Security Foundations Symposium (CSF), pp. 439\u2013456. IEEE (2023)","DOI":"10.1109\/CSF57540.2023.00027"},{"key":"8_CR7","unstructured":"Luzon, E., Amit, G., Weiss, R., Mirsky, Y.: Memory backdoor attacks on neural networks. arXiv preprint arXiv:2411.14516 (2024)"},{"key":"8_CR8","doi-asserted-by":"crossref","unstructured":"Yeom, S., Giacomelli, I., Fredrikson, M., Jha, S.: Privacy risk in machine learning: Analyzing the connection to overfitting. In: 2018 IEEE 31st Computer Security Foundations Symposium (CSF), pp. 268\u2013282. IEEE (2018)","DOI":"10.1109\/CSF.2018.00027"},{"key":"8_CR9","doi-asserted-by":"crossref","unstructured":"Amit, G., Levy, M., Mirsky, Y.: Transpose attack: Stealing datasets with bidirectional training. arXiv preprint arXiv:2311.07389 (2023)","DOI":"10.14722\/ndss.2024.23325"},{"key":"8_CR10","doi-asserted-by":"publisher","unstructured":"Li, H., Ayache, N., Delingette, H.: Data stealing attack on medical images: Is it safe to export networks from data lakes? In: International Workshop on Distributed, Collaborative, and Federated Learning. pp. 28\u201336. Springer (2022). https:\/\/doi.org\/10.1007\/978-3-031-18523-6_3","DOI":"10.1007\/978-3-031-18523-6_3"},{"key":"8_CR11","unstructured":"Carlini, N., et al.: Extracting training data from diffusion models. In: 32nd USENIX Security Symposium (USENIX Security 23), pp. 5253\u20135270 (2023)"},{"issue":"1","key":"8_CR12","doi-asserted-by":"publisher","first-page":"1953","DOI":"10.1038\/s41598-022-05539-7","volume":"12","author":"M Adnan","year":"2022","unstructured":"Adnan, M., Kalra, S., Cresswell, J.C., Taylor, G.W., Tizhoosh, H.R.: Federated learning and differential privacy for medical image analysis. Sci. Rep. 12(1), 1953 (2022)","journal-title":"Sci. Rep."},{"key":"8_CR13","doi-asserted-by":"publisher","first-page":"619","DOI":"10.1007\/s11517-006-0081-x","volume":"44","author":"A Giakoumaki","year":"2006","unstructured":"Giakoumaki, A., Pavlopoulos, S., Koutsouris, D.: Secure and efficient health data management through multiple watermarking on medical images. Med. Biol. Eng. Compu. 44, 619\u2013631 (2006)","journal-title":"Med. Biol. Eng. Compu."},{"key":"8_CR14","doi-asserted-by":"crossref","unstructured":"Liu, K., Dolan-Gavitt, B., Garg, S.: Fine-pruning: Defending against backdooring attacks on deep neural networks. In: International Symposium on Research in Attacks, Intrusions, and Defenses, pp. 273\u2013294. Springer (2018)","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"8_CR15","unstructured":"Sha, Z., He, X., Berrang, P., Humbert, M., Zhang, Y.: Fine-tuning is all you need to mitigate backdoor attacks. arXiv preprint arXiv:2212.09067 (2022)"},{"key":"8_CR16","doi-asserted-by":"crossref","unstructured":"Li, H., Ayache, N., Delingette, H.: Generative medical image anonymization based on latent code projection and optimization. In: 2025 IEEE 22nd International Symposium on Biomedical Imaging (ISBI), pp.\u00a01\u20134. IEEE (2025)","DOI":"10.1109\/ISBI60581.2025.10981125"},{"key":"8_CR17","doi-asserted-by":"crossref","unstructured":"Seo, J., Lee, S.H., Lee, T.Y., Moon, S., Park, G.M.: Generative unlearning for any identity. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 9151\u20139161 (2024)","DOI":"10.1109\/CVPR52733.2024.00874"},{"key":"8_CR18","unstructured":"Ginsburg, B., Gitman, I., You, Y.: Large batch training of convolutional networks with layer-wise adaptive rate scaling. In: ICLR\u00a02018 Conference (2018)"},{"key":"8_CR19","doi-asserted-by":"crossref","unstructured":"Ro, Y., Choi, J.Y.: Autolr: layer-wise pruning and auto-tuning of learning rates in fine-tuning of deep networks. In: Proceedings of the AAAI Conference on Artificial Intelligence (AAAI 2021), pp. 2486\u20132494 (2021)","DOI":"10.1609\/aaai.v35i3.16350"},{"key":"8_CR20","unstructured":"Dong, X., Bao, J., et al.: Clip itself is a strong fine-tuner: Achieving 85.7% and 88.0% top-1 accuracy with vit-b and vit-l on imagenet. arXiv preprint arXiv:2212.06138 (2022)"},{"key":"8_CR21","unstructured":"Loshchilov, I., Hutter, F.: Decoupled weight decay regularization. In: International Conference on Learning Representations (ICLR) (2019)"},{"key":"8_CR22","doi-asserted-by":"crossref","unstructured":"Yang, J., Shi, R., Ni, B.: Medmnist classification decathlon: a lightweight automl benchmark for medical image analysis. In: IEEE 18th International Symposium on Biomedical Imaging (ISBI), pp. 191\u2013195 (2021)","DOI":"10.1109\/ISBI48211.2021.9434062"},{"key":"8_CR23","doi-asserted-by":"crossref","unstructured":"Tschandl, P., Rosendahl, C., Kittler, H.: The ham10000 dataset, a large collection of multi-source dermatoscopic images of common pigmented skin lesions. Sci. Data, 180161 (2018)","DOI":"10.1038\/sdata.2018.161"},{"key":"8_CR24","unstructured":"Codella, N., et\u00a0al.: Skin lesion analysis toward melanoma detection 2018: A challenge hosted by the international skin imaging collaboration (isic). arXiv preprint arXiv:1902.03368 (2019)"},{"key":"8_CR25","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"issue":"1","key":"8_CR26","doi-asserted-by":"publisher","first-page":"41","DOI":"10.1038\/s41597-022-01721-8","volume":"10","author":"J Yang","year":"2023","unstructured":"Yang, J., et al.: Medmnist v2-a large-scale lightweight benchmark for 2d and 3d biomedical image classification. Scientific Data 10(1), 41 (2023)","journal-title":"Scientific Data"},{"key":"8_CR27","doi-asserted-by":"crossref","unstructured":"Wang, X., Peng, Y., et\u00a0al.: Chestx-ray8: hospital-scale chest x-ray database and benchmarks on weakly-supervised classification and localization of common thorax diseases. In: CVPR, pp. 3462\u20133471 (2017)","DOI":"10.1109\/CVPR.2017.369"},{"key":"8_CR28","doi-asserted-by":"crossref","unstructured":"Johnson, A.E., et al.: Mimic-cxr-jpg, a large publicly available database of labeled chest radiographs. arXiv preprint arXiv:1901.07042 (2019)","DOI":"10.1038\/s41597-019-0322-0"},{"key":"8_CR29","doi-asserted-by":"crossref","unstructured":"Huang, G., Liu, Z., Van Der\u00a0Maaten, L., Weinberger, K.Q.: Densely connected convolutional networks. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition (CVPR), pp. 4700\u20134708 (2017)","DOI":"10.1109\/CVPR.2017.243"},{"key":"8_CR30","unstructured":"Li, H.: Data exfiltration and anonymization of medical images based on generative models. Ph.D. thesis, Universit\u00e9 C\u00f4te d\u2019Azur (2024)"},{"issue":"4","key":"8_CR31","doi-asserted-by":"publisher","first-page":"600","DOI":"10.1109\/TIP.2003.819861","volume":"13","author":"Z Wang","year":"2004","unstructured":"Wang, Z., Bovik, A.C., Sheikh, H.R., Simoncelli, E.P.: Image quality assessment: from error visibility to structural similarity. IEEE Trans. Image Process. 13(4), 600\u2013612 (2004)","journal-title":"IEEE Trans. Image Process."},{"key":"8_CR32","doi-asserted-by":"crossref","unstructured":"Zhang, R., Isola, P., Efros, A.A., Shechtman, E., Wang, O.: The unreasonable effectiveness of deep features as a perceptual metric. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 586\u2013595 (2018)","DOI":"10.1109\/CVPR.2018.00068"}],"container-title":["Lecture Notes in Computer Science","Bridging Regulatory Science and Medical Imaging Evaluation; and Distributed, Collaborative, and Federated Learning"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-05663-4_8","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,24]],"date-time":"2025-09-24T01:43:18Z","timestamp":1758678198000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-05663-4_8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,25]]},"ISBN":["9783032056658","9783032056634"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-05663-4_8","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9,25]]},"assertion":[{"value":"25 September 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"MICCAI","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Medical Image Computing and Computer-Assisted Intervention","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Daejeon","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Korea (Republic of)","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"27 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"miccai2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/conferences.miccai.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}