{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,13]],"date-time":"2025-11-13T04:11:33Z","timestamp":1763007093348,"version":"3.45.0"},"publisher-location":"Singapore","reference-count":30,"publisher":"Springer Nature Singapore","isbn-type":[{"type":"print","value":"9789819530540"},{"type":"electronic","value":"9789819530557"}],"license":[{"start":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T00:00:00Z","timestamp":1763078400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T00:00:00Z","timestamp":1763078400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-3055-7_22","type":"book-chapter","created":{"date-parts":[[2025,11,13]],"date-time":"2025-11-13T04:07:08Z","timestamp":1763006828000},"page":"279-293","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["FusionMIA: Enhancing Membership Inference Attacks with\u00a0Spy Clients and\u00a0Shadow Models in\u00a0Federated Learning"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-4027-3210","authenticated-orcid":false,"given":"Xiang","family":"Lan","sequence":"first","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4798-082X","authenticated-orcid":false,"given":"Jiayin","family":"Li","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1658-4931","authenticated-orcid":false,"given":"Zuobin","family":"Ying","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9431-5342","authenticated-orcid":false,"given":"Xingshuo","family":"Han","sequence":"additional","affiliation":[]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9121-0171","authenticated-orcid":false,"given":"Shengmin","family":"Xu","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2025,11,14]]},"reference":[{"issue":"1","key":"22_CR1","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1561\/2200000083","volume":"14","author":"P Kairouz","year":"2021","unstructured":"Kairouz, P., McMahan, H.B., Avent, B., et al.: Advances and open problems in federated learning. Found. Trends Mach. Learn. 14(1), 1\u2013210 (2021)","journal-title":"Found. Trends Mach. Learn."},{"key":"22_CR2","doi-asserted-by":"crossref","unstructured":"Lyu, L., Yu, H., Yang, Q.: Threats to federated learning: a survey. arXiv preprint arXiv:2003.02133 (2020)","DOI":"10.1007\/978-3-030-63076-8_1"},{"issue":"2","key":"22_CR3","first-page":"1364","volume":"19","author":"G Xu","year":"2022","unstructured":"Xu, G., Li, H., Zhang, Y., Xu, S., Ning, J., Deng, R.: Privacy-preserving federated deep learning with irregular users. IEEE Trans. Dependable Secure Comput. 19(2), 1364\u20131381 (2022)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"22_CR4","doi-asserted-by":"publisher","first-page":"911","DOI":"10.1109\/TIFS.2019.2929409","volume":"15","author":"G Xu","year":"2020","unstructured":"Xu, G., Li, H., Liu, S., Yang, K., Lin, X.: VerifyNet: Secure and verifiable federated learning. IEEE Trans. Inf. Forensics Secur. 15, 911\u2013926 (2020)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"2","key":"22_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3298981","volume":"10","author":"Q Yang","year":"2019","unstructured":"Yang, Q., Liu, Y., Chen, T., Tong, Y.: Federated machine learning: Concept and applications. ACM Trans. Intell. Syst. Technol. 10(2), 1\u201319 (2019)","journal-title":"ACM Trans. Intell. Syst. Technol."},{"issue":"7","key":"22_CR6","doi-asserted-by":"publisher","first-page":"1552","DOI":"10.1109\/TPDS.2020.3040887","volume":"32","author":"T Huang","year":"2021","unstructured":"Huang, T., Lin, W., Wu, W., He, L., Li, K., Zomaya, A.Y.: An efficiency-boosting client selection scheme for federated learning with fairness guarantee. IEEE Trans. Parallel Distrib. Syst. 32(7), 1552\u20131564 (2021)","journal-title":"IEEE Trans. Parallel Distrib. Syst."},{"key":"22_CR7","doi-asserted-by":"publisher","first-page":"1736","DOI":"10.1109\/TIFS.2020.3043139","volume":"16","author":"X Guo","year":"2021","unstructured":"Guo, X., et al.: VeriFL: Communication-efficient and fast verifiable aggregation for federated learning. IEEE Trans. Inf. Forensics Secur. 16, 1736\u20131751 (2021)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"22_CR8","doi-asserted-by":"crossref","unstructured":"Bonawitz, K., Ivanov, V., Kreuter, B., et al.: Practical secure aggregation for privacy-preserving machine learning. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 1175\u20131191 (2017)","DOI":"10.1145\/3133956.3133982"},{"key":"22_CR9","doi-asserted-by":"crossref","unstructured":"Wang, Z., Song, M., Zhang, Z., et al.: Beyond inferring class representatives: User-level privacy leakage from federated learning. In: IEEE Conference on Computer Communications, pp. 2512\u20132520 (2019)","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"22_CR10","unstructured":"McMahan, H.B., Moore, E., Ramage, D., et al.: Communication-efficient learning of deep networks from decentralized data. In: Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, vol. 54, pp. 1273\u20131282 (2017)"},{"key":"22_CR11","doi-asserted-by":"crossref","unstructured":"Nasr, M., Shokri, R., Houmansadr, A.: Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In: 2019 IEEE Symposium on Security and Privacy, pp. 739\u2013753 (2019)","DOI":"10.1109\/SP.2019.00065"},{"key":"22_CR12","doi-asserted-by":"crossref","unstructured":"Salem, A., Zhang, Y., Humbert, M., et al.: ML-Leaks: Model and data independent membership inference attacks and defenses on machine learning models. arXiv preprint arXiv:1806.01246 (2018)","DOI":"10.14722\/ndss.2019.23119"},{"issue":"5","key":"22_CR13","first-page":"404","volume":"2","author":"J Niu","year":"2024","unstructured":"Niu, J., Liu, P., Zhu, X., et al.: A survey on membership inference attacks and defenses in machine learning. J. Inf. Intel. 2(5), 404\u2013454 (2024)","journal-title":"J. Inf. Intel."},{"issue":"2","key":"22_CR14","doi-asserted-by":"publisher","first-page":"333","DOI":"10.1109\/TAI.2024.3363670","volume":"6","author":"B Rao","year":"2025","unstructured":"Rao, B., Zhang, J., Wu, D., et al.: Privacy inference attack and defense in centralized and federated learning: a comprehensive survey. IEEE Trans. Artif. Intell. 6(2), 333\u2013353 (2025)","journal-title":"IEEE Trans. Artif. Intell."},{"key":"22_CR15","doi-asserted-by":"crossref","unstructured":"Gu, Y., Bai, Y., Xu, S.: CS-MIA: Membership inference attack based on prediction confidence series in federated learning. J. Inf. Secur. Appl. 67, (2022)","DOI":"10.1016\/j.jisa.2022.103201"},{"key":"22_CR16","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., et al.: Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy, pp. 3\u201318 (2017)","DOI":"10.1109\/SP.2017.41"},{"key":"22_CR17","doi-asserted-by":"crossref","unstructured":"Melis, L., Song, C., De Cristofaro, E., et al.: Exploiting unintended feature leakage in collaborative learning. In: 2019 IEEE Symposium on Security and Privacy, pp. 691\u2013706 (2019)","DOI":"10.1109\/SP.2019.00029"},{"issue":"1","key":"22_CR18","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1109\/TDSC.2021.3128679","volume":"20","author":"W Gao","year":"2023","unstructured":"Gao, W., Wang, B., Zhang, X., et al.: Secure aggregation is insecure: category inference attack on federated learning. IEEE Trans. Dependable Secure Comput. 20(1), 147\u2013160 (2023)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"issue":"11","key":"22_CR19","doi-asserted-by":"publisher","first-page":"139","DOI":"10.1145\/3422622","volume":"63","author":"I Goodfellow","year":"2020","unstructured":"Goodfellow, I., Pouget-Abadie, J., Mirza, M., et al.: Generative adversarial networks. Commun. ACM 63(11), 139\u2013144 (2020)","journal-title":"Commun. ACM"},{"key":"22_CR20","doi-asserted-by":"crossref","unstructured":"Carlini, N., Wagner, D.: Towards Evaluating the Robustness of Neural Networks. In: 2017 IEEE Symposium on Security and Privacy, pp. 39\u201357 (2017)","DOI":"10.1109\/SP.2017.49"},{"key":"22_CR21","unstructured":"Krizhevsky, A.: Learning multiple layers of features from tiny images. Technical Report, (2009)"},{"issue":"4","key":"22_CR22","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3704633","volume":"57","author":"L Bai","year":"2024","unstructured":"Bai, L., Hu, H., Ye, Q., et al.: Membership inference attacks and defenses in federated learning: a survey. ACM Comput. Surv. 57(4), 1\u201335 (2024)","journal-title":"ACM Comput. Surv."},{"issue":"3","key":"22_CR23","first-page":"2341","volume":"20","author":"L Liu","year":"2023","unstructured":"Liu, L., Wang, Y., Liu, G., Peng, K., Wang, C.: Membership inference attacks against machine learning models via prediction sensitivity. IEEE Trans. Dependable Secure Comput. 20(3), 2341\u20132347 (2023)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"issue":"6","key":"22_CR24","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3460427","volume":"54","author":"X Yin","year":"2022","unstructured":"Yin, X., Zhu, Y., Hu, J.: A comprehensive survey of privacy-preserving federated learning: a taxonomy, review, and future directions. ACM Comput. Surv. 54(6), 1\u201336 (2022)","journal-title":"ACM Comput. Surv."},{"key":"22_CR25","first-page":"429","volume":"2","author":"T Li","year":"2020","unstructured":"Li, T., Sahu, A.K., Zaheer, M., et al.: Federated optimization in heterogeneous networks. Proc. Mach. Learn. Syst. 2, 429\u2013450 (2020)","journal-title":"Proc. Mach. Learn. Syst."},{"key":"22_CR26","doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Jha, S., Ristenpart, T.: Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp. 1322\u20131333 (2015)","DOI":"10.1145\/2810103.2813677"},{"key":"22_CR27","doi-asserted-by":"publisher","first-page":"4996","DOI":"10.1109\/TIFS.2023.3303718","volume":"18","author":"G Liu","year":"2023","unstructured":"Liu, G., Tian, Z., Chen, J., Wang, C., Liu, J.: TEAR: Exploring temporal evolution of adversarial robustness for membership inference attacks against federated learning. IEEE Trans. Inf. Forensics Secur. 18, 4996\u20135010 (2023)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"22_CR28","doi-asserted-by":"crossref","unstructured":"Yeom, S., Giacomelli, I., Fredrikson, M., et al.: Privacy risk in machine learning: Analyzing the connection to overfitting. In: 2018 IEEE 31st Computer Security Foundations Symposium, pp. 268\u2013282 (2018)","DOI":"10.1109\/CSF.2018.00027"},{"issue":"5","key":"22_CR29","doi-asserted-by":"publisher","first-page":"1333","DOI":"10.1109\/TIFS.2017.2787987","volume":"13","author":"Y Aono","year":"2018","unstructured":"Aono, Y., Hayashi, T., Wang, L., et al.: Privacy-preserving deep learning via additively homomorphic encryption. IEEE Trans. Inf. Forensics Secur. 13(5), 1333\u20131345 (2018)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"22_CR30","unstructured":"Zhu, L., Liu, Z., Han, S.: Deep leakage from gradients. In: International Conference on Neural Information Processing Systems, vol. 32 (2019)"}],"container-title":["Lecture Notes in Computer Science","Knowledge Science, Engineering and Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-3055-7_22","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,13]],"date-time":"2025-11-13T04:07:13Z","timestamp":1763006833000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-3055-7_22"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,14]]},"ISBN":["9789819530540","9789819530557"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-3055-7_22","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2025,11,14]]},"assertion":[{"value":"14 November 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"KSEM","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Knowledge Science, Engineering and Management","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Macao","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 August 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 August 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"ksem2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/ksem2025.scimeeting.cn\/en\/web\/index\/27434","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}