{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T16:26:35Z","timestamp":1780763195979,"version":"3.54.1"},"reference-count":86,"publisher":"Springer Science and Business Media LLC","issue":"S1","license":[{"start":{"date-parts":[[2023,7,23]],"date-time":"2023-07-23T00:00:00Z","timestamp":1690070400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,7,23]],"date-time":"2023-07-23T00:00:00Z","timestamp":1690070400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Artif Intell Rev"],"published-print":{"date-parts":[[2023,10]]},"DOI":"10.1007\/s10462-023-10550-z","type":"journal-article","created":{"date-parts":[[2023,7,23]],"date-time":"2023-07-23T10:01:28Z","timestamp":1690106488000},"page":"1337-1374","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":21,"title":["Gradient leakage attacks in federated learning"],"prefix":"10.1007","volume":"56","author":[{"given":"Haimei","family":"Gong","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Liangjun","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaoyang","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuanqi","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Omary","family":"Gastro","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4571-6454","authenticated-orcid":false,"given":"Lei","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9747-9895","authenticated-orcid":false,"given":"Ke","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhen","family":"Guo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,7,23]]},"reference":[{"key":"10550_CR1","doi-asserted-by":"publisher","unstructured":"Abadi M, Chu A, Goodfellow I, Talwar K, Zhang L (2021) Deep learning with differential privacy. In: Proceedings of the ACM SIGSAC conference on computer and communications security. https:\/\/doi.org\/10.1145\/2976749.2978318","DOI":"10.1145\/2976749.2978318"},{"key":"10550_CR2","unstructured":"Agarwal N, Suresh AT, Yu F, Kumar S, Mcmahan HB (2018) cpsgd communication-efficient and differentially-private distributed sgd. Preprint at CoRR. http:\/\/arxiv.org\/abs\/1805.10559"},{"key":"10550_CR3","unstructured":"Ali S, Huang R, Mahyar N (2019) Poison frogs! targeted clean-label poisoning attacks on neural networks. In: NIPS. http:\/\/arxiv.org\/abs\/1804.00792"},{"issue":"19669466","key":"10550_CR4","doi-asserted-by":"publisher","first-page":"6092","DOI":"10.1109\/TII.2020.2974555","volume":"16","author":"PCM Arachchige","year":"2020","unstructured":"Arachchige PCM, Bertok P (2020) A trustworthy privacy preserving framework for machine learning in industrial iot system. IEEE Trans Ind Inf 16(19669466):6092\u20136102. https:\/\/doi.org\/10.1109\/TII.2020.2974555","journal-title":"IEEE Trans Ind Inf"},{"issue":"7","key":"10550_CR5","doi-asserted-by":"publisher","first-page":"5827","DOI":"10.1109\/JIOT.2019.2952146","volume":"7","author":"M Arachchige","year":"2020","unstructured":"Arachchige M, Chamikara P, Bertok P, Khalil I, Dongxi L, Seyit C, Atiquzzaman M (2020) Local differential privacy for deep learning. IEEE Internet Things J 7(7):5827\u20135842. https:\/\/doi.org\/10.1109\/JIOT.2019.2952146","journal-title":"IEEE Internet Things J"},{"key":"10550_CR6","unstructured":"Arjun NB, Supriyo C, Prateek M (2017) Analyzing federated learning through an adversarial lens. In: ICML. http:\/\/arxiv.org\/abs\/1811.12470"},{"key":"10550_CR7","unstructured":"Bonawitz K, Ivanov V, Kreuter B, Marcedone A (2016) Practical secure aggregation for federated learning on user-held data. http:\/\/arxiv.org\/abs\/1611.04482"},{"key":"10550_CR8","first-page":"10","volume":"23","author":"Z Bu","year":"2020","unstructured":"Bu Z, Dong J (2020) Deep learning with gaussian differential privacy. Harvard Data Sci Rev 23:10","journal-title":"Harvard Data Sci Rev"},{"key":"10550_CR9","unstructured":"Carlini N, Liu C (2019) The secret sharer: evaluating and testing unintended memorization in neural networks. In: Proceedings of the 28th USENIX conference on security symposium August 2019. pp 267\u2013284"},{"key":"10550_CR10","unstructured":"Carlini N, Tramer F, Wallace E, Jagielski M (2021) Extracting training data from large language models. Preprint at http:\/\/arxiv.org\/abs\/2012.07805"},{"issue":"5","key":"10550_CR11","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1109\/MIS.2020.3014880","volume":"36","author":"D Chai","year":"2019","unstructured":"Chai D, Wang L, Chen K, Yang Q (2019) Secure federated matrix factorization. IEEE Intell Syst 36(5):11\u201320. https:\/\/doi.org\/10.1109\/MIS.2020.3014880","journal-title":"IEEE Intell Syst"},{"issue":"7","key":"10550_CR12","doi-asserted-by":"publisher","first-page":"140","DOI":"10.1007\/978-3-642-31680-7-8","volume":"7384","author":"H Chan","year":"2012","unstructured":"Chan H, Li M (2012) Differentially private continual monitoring of heavy hitters from distributed streams. Int Symp Privacy Enhancing Technol Symp 7384(7):140\u2013159. https:\/\/doi.org\/10.1007\/978-3-642-31680-7-8","journal-title":"Int Symp Privacy Enhancing Technol Symp"},{"issue":"23","key":"10550_CR13","doi-asserted-by":"publisher","first-page":"653","DOI":"10.1007\/s00778-013-0344-8","volume":"12","author":"R Chen","year":"2019","unstructured":"Chen R, Fung B, Yu PS (2019) Correlated network data publication via differential privacy. VLDB J 12(23):653\u2013676. https:\/\/doi.org\/10.1007\/s00778-013-0344-8","journal-title":"VLDB J"},{"issue":"21408420","key":"10550_CR14","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1109\/MIS.2021.3082561","volume":"36","author":"K Cheng","year":"2021","unstructured":"Cheng K, Fan T, Liu YJY (2021) Secureboost: a lossless federated learning framework. IEEE Intell Syst 36(21408420):87\u201398. https:\/\/doi.org\/10.1109\/MIS.2021.3082561","journal-title":"IEEE Intell Syst"},{"key":"10550_CR15","first-page":"1","volume":"25","author":"J Dean","year":"2012","unstructured":"Dean J (2012) Large scale distributed deep networks. Adv Neural Inf Process Syst 25:1","journal-title":"Adv Neural Inf Process Syst"},{"issue":"4","key":"10550_CR16","doi-asserted-by":"publisher","first-page":"1645","DOI":"10.1109\/TDSC.2019.2933844","volume":"18","author":"S Dolev","year":"2021","unstructured":"Dolev S, Gupta P, Li Y (2021) Privacy preserving secret shared computations using mapreduce. IEEE Trans Depend Secure Comput 18(4):1645\u20131666. https:\/\/doi.org\/10.1109\/TDSC.2019.2933844","journal-title":"IEEE Trans Depend Secure Comput"},{"key":"10550_CR17","doi-asserted-by":"publisher","unstructured":"Dosovitskiy A, Brox T (2016) Inverting visual representations with convolutional networks. In: IEEE conference on computer vision and pattern recognition (CVPR). https:\/\/doi.org\/10.1109\/CVPR.2016.522","DOI":"10.1109\/CVPR.2016.522"},{"issue":"5","key":"10550_CR18","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1109\/RWS.2014.6830099","volume":"46","author":"N Dowlin","year":"2016","unstructured":"Dowlin N, Gilad-Bachrach R (2016) Cryptonets: applying neural networks to encrypted data with high throughput and accuracy. CoRR 46(5):201\u2013210. https:\/\/doi.org\/10.1109\/RWS.2014.6830099","journal-title":"CoRR"},{"key":"10550_CR19","doi-asserted-by":"crossref","unstructured":"Duan J, Li X, Gao S, Wang J, Zhong Z (2021) SSGD: a safe and efficient method of gradient descent. http:\/\/arxiv.org\/abs\/2012.02076","DOI":"10.1155\/2021\/5404061"},{"issue":"6","key":"10550_CR20","doi-asserted-by":"publisher","first-page":"171","DOI":"10.1561\/0400000042","volume":"12","author":"C Dwork","year":"2013","unstructured":"Dwork C, Roth A (2013) The algorithmic foundations of differential privacy. Found Trends Theor Comput Sci 12(6):171\u2013189. https:\/\/doi.org\/10.1561\/0400000042","journal-title":"Found Trends Theor Comput Sci"},{"key":"10550_CR21","doi-asserted-by":"crossref","unstructured":"Fan L, Ng KW, Ju C, Zhang T (2020) Rethinking privacy preserving deep learning: how to evaluate and thwart privacy attacks. Preprint at http:\/\/arxiv.org\/abs\/2006.11601","DOI":"10.1007\/978-3-030-63076-8_3"},{"key":"10550_CR22","unstructured":"Felix S, Simon W (2019) Robust and communication-efficient federated learning from non-IID data. http:\/\/arxiv.org\/abs\/1903.02891"},{"key":"10550_CR23","doi-asserted-by":"publisher","unstructured":"Fredrikson M, Jha S, Ristenpart T (2015) Model inversion attacks that exploit confidence information and basic countermeasures. In: The 22nd ACM SIGSAC conference. https:\/\/doi.org\/10.1145\/2810103.2813677","DOI":"10.1145\/2810103.2813677"},{"key":"10550_CR24","doi-asserted-by":"publisher","unstructured":"Fu Y, Wang H, Xu K (2019) Mixup based privacy preserving mixed collaboration learning. In: IEEE international conference on service-oriented system engineering. https:\/\/doi.org\/10.1109\/SOSE.2019.00047","DOI":"10.1109\/SOSE.2019.00047"},{"key":"10550_CR25","doi-asserted-by":"publisher","unstructured":"Gaier A, Ha D (2019) Weight agnostic neural networks. https:\/\/doi.org\/10.13140\/RG.2.2.16025.88169","DOI":"10.13140\/RG.2.2.16025.88169"},{"key":"10550_CR26","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243834","author":"K Ganju","year":"2018","unstructured":"Ganju K, Wang Q, Yang W (2018) Property inference attacks on fully connected neural networks using permutation invariant representations. Comput Commun Secur. https:\/\/doi.org\/10.1145\/3243734.3243834","journal-title":"Comput Commun Secur"},{"key":"10550_CR27","unstructured":"Geiping J, Bauermeister H (2020) Inverting gradients-how easy is it to break privacy in federated learning. http:\/\/github.com\/JonasGeiping\/invertinggradients"},{"key":"10550_CR28","unstructured":"Gu T, Dolan-Gavitt B (2017) Badnets: Identifying vulnerabilities in the machine learning model supply chain. In: Cryptography and security. http:\/\/arxiv.org\/abs\/1708.06733"},{"key":"10550_CR29","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2010.85","author":"M Hardt","year":"2010","unstructured":"Hardt M, Rothblum GN (2010) A multiplicative weights mechanism for privacy-preserving data analysis. Adv Neural Inf Process Syst. https:\/\/doi.org\/10.1109\/FOCS.2010.85","journal-title":"Adv Neural Inf Process Syst"},{"key":"10550_CR30","doi-asserted-by":"publisher","unstructured":"Hitaj B, Ateniese G, Perez-Cruz F (2017) Deep models under the gan: information leakage from collaborative deep learning. In: ACM CCS. https:\/\/doi.org\/10.1145\/3133956.3134012","DOI":"10.1145\/3133956.3134012"},{"key":"10550_CR31","unstructured":"Huang Y, Song Z, Li K (2019) Instahide: instance-hiding schemes for private distributed learning. Preprint at http:\/\/arxiv.org\/abs\/2010.02772"},{"key":"10550_CR32","unstructured":"Jakub K, McMahan HB, Ramage D, Peter R (2016) Federated optimization: distributed machine learning for on-device intelligence. Preprint at http:\/\/arxiv.org\/abs\/1610.02527"},{"key":"10550_CR33","unstructured":"Jayaraman B, Evans D (2019)Evaluating differentially private machine learning in practice. In: USENIX security symposium. http:\/\/arxiv.org\/abs\/1902.08874"},{"issue":"1","key":"10550_CR34","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/TNNLS.2022.3212627","volume":"1","author":"NM Jebreel","year":"2022","unstructured":"Jebreel NM, Domingo-Ferrer J, Blanco-Justicia AD (2022) Enhanced security and privacy via fragmented federated learning. IEEE Trans Neural Netw Learn Syst 1(1):1\u201315. https:\/\/doi.org\/10.1109\/TNNLS.2022.3212627","journal-title":"IEEE Trans Neural Netw Learn Syst"},{"key":"10550_CR35","first-page":"492","volume":"17","author":"P Kairouz","year":"2015","unstructured":"Kairouz P, Oh S, Viswanath P (2015) Extremal mechanisms for local differential privacy. J Mach Learn Res 17:492","journal-title":"J Mach Learn Res"},{"key":"10550_CR36","unstructured":"Kairouz P, McMahan B, Avent B (2021) Advances and open problems in federated learning. http:\/\/arxiv.org\/abs\/1912.04977V1"},{"key":"10550_CR37","unstructured":"Lin Y, Han S, Mao H (2020) Deep gradient compression: reducing the communication bandwidth for distributed training. In: ICLR workshop. http:\/\/arxiv.org\/abs\/1712.01887"},{"issue":"1966","key":"10550_CR38","doi-asserted-by":"publisher","first-page":"346","DOI":"10.7544\/issn1000-1239.2020.20190455","volume":"2","author":"J Liu","year":"2020","unstructured":"Liu J, Meng X (2020) Survey on privacy-presering machine learning. J Comput Res Dev 2(1966):346\u2013362. https:\/\/doi.org\/10.7544\/issn1000-1239.2020.20190455","journal-title":"J Comput Res Dev"},{"issue":"45","key":"10550_CR39","doi-asserted-by":"publisher","first-page":"503","DOI":"10.1007\/BF01589116","volume":"8","author":"DC Liu","year":"2019","unstructured":"Liu DC, Nocedal J (2019) On the limited memory bfgs method for large scale optimization. Math Progr 8(45):503\u2013528. https:\/\/doi.org\/10.1007\/BF01589116","journal-title":"Math Progr"},{"issue":"5","key":"10550_CR40","doi-asserted-by":"publisher","first-page":"907","DOI":"10.1109\/TCSS.2019.2916086","volume":"6","author":"G Liu","year":"2019","unstructured":"Liu G, Wang C, Peng K, Huang H (2019) Socinf: membership inference attacks on social media health data with machine learning. CoRR 6(5):907\u2013921. https:\/\/doi.org\/10.1109\/TCSS.2019.2916086","journal-title":"CoRR"},{"issue":"19894246","key":"10550_CR41","doi-asserted-by":"publisher","first-page":"70","DOI":"10.1109\/MIS.2020.2988525","volume":"4","author":"Y Liu","year":"2020","unstructured":"Liu Y, Kang Y, Xing C, Chen T, Yang Q (2020) A secure federated transfer learning framework. IEEE Intell Syst 4(19894246):70\u201382. https:\/\/doi.org\/10.1109\/MIS.2020.2988525","journal-title":"IEEE Intell Syst"},{"key":"10550_CR42","doi-asserted-by":"publisher","unstructured":"Lu Z, Shen H (2019) A new lower bound of privacy budget for distributed differential privacy. In: 18th international conference on parallel and distributed computing. https:\/\/doi.org\/10.1109\/PDCAT.2017.00014","DOI":"10.1109\/PDCAT.2017.00014"},{"issue":"11","key":"10550_CR43","doi-asserted-by":"publisher","first-page":"3079","DOI":"10.1109\/TPDS.2021.3129612","volume":"33","author":"Y Mao","year":"2022","unstructured":"Mao Y, Hong W, Zhu B, Zhu Z, Zhang Y, Zhong S (2022) Secure deep neural network models publishing against membership inference attacks via training task parallelism. IEEE Trans Parallel Distrib Syst 33(11):3079\u20133091. https:\/\/doi.org\/10.1109\/TPDS.2021.3129612","journal-title":"IEEE Trans Parallel Distrib Syst"},{"key":"10550_CR44","unstructured":"McMahan HB, Moore E, Ramage D (2017) Communication-efficient learning of deep networks from decentralized data. In: Proceedings of the 20th international conference on artificial intelligence and statistics (AISTATS). http:\/\/arxiv.org\/abs\/1602.05629"},{"key":"10550_CR45","unstructured":"McMahan HB, Moore E, Ramage D (2020) Federated learning of deep networks using model averaging. Preprint at http:\/\/arxiv.org\/abs\/1602.05629"},{"issue":"5","key":"10550_CR46","doi-asserted-by":"publisher","first-page":"691","DOI":"10.1109\/SP.2019.00029","volume":"1","author":"L Melis","year":"2019","unstructured":"Melis L, Song C, De Cristofaro E (2019) Exploiting unintended feature leakage in collaborative learning. IEEE Trans Inf Forensic Secur 1(5):691\u2013706. https:\/\/doi.org\/10.1109\/SP.2019.00029","journal-title":"IEEE Trans Inf Forensic Secur"},{"key":"10550_CR47","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12","author":"P Mohassel","year":"2017","unstructured":"Mohassel P, Zhang Y (2017) Secureml: a system for scalable privacy preserving machine learning. IEEE Symp Secur Privacy. https:\/\/doi.org\/10.1109\/SP.2017.12","journal-title":"IEEE Symp Secur Privacy"},{"issue":"3","key":"10550_CR48","doi-asserted-by":"publisher","first-page":"739","DOI":"10.1109\/SP.2019.00065","volume":"36","author":"M Nasr","year":"2019","unstructured":"Nasr M, Shokri R, Houmansadr A (2019) Comprehensive privacy analysis of deep learning: passive and active white-box inference attacks against centralized and federated learning. IEEE Symp Secur Privacy 36(3):739\u2013753. https:\/\/doi.org\/10.1109\/SP.2019.00065","journal-title":"IEEE Symp Secur Privacy"},{"key":"10550_CR49","unstructured":"Ovi PR, Dey E, Roy N (2022) Mixed precision quantization to tackle gradient leakage attacks in federated learning. http:\/\/arxiv.org\/abs\/2210.13457"},{"key":"10550_CR50","doi-asserted-by":"publisher","first-page":"1314","DOI":"10.1109\/SP40000.2020.00095","volume":"5","author":"X Pan","year":"2020","unstructured":"Pan X, Zhang M, Ji S, Yang M (2020a) Privacy risks of general-purpose language models. IEEE Symp Secur Privacy 5:1314\u20131331. https:\/\/doi.org\/10.1109\/SP40000.2020.00095","journal-title":"IEEE Symp Secur Privacy"},{"issue":"45","key":"10550_CR51","first-page":"503","volume":"10","author":"X Pan","year":"2020","unstructured":"Pan X, Zhang M, Yan Y (2020b) Theory-oriented deep leakage from gradients via linear equation solver. Cryptogr Secur 10(45):503\u2013528","journal-title":"Cryptogr Secur"},{"key":"10550_CR52","unstructured":"Pfohl SR, Dai AM, Heller K (2019) Federated and differentially private learning for electronic health records. Preprint at CoRR. http:\/\/arxiv.org\/abs\/1911.05861"},{"key":"10550_CR53","doi-asserted-by":"publisher","unstructured":"Phong LT, Aono Y, Hayashi T, Wang L, Moriai S (2017) Privacy-preserving deep learning: revisited and enhanced. In: International conference on applications and techniques in information security (ATIS). https:\/\/doi.org\/10.1007\/978-981-10-5421-1-9","DOI":"10.1007\/978-981-10-5421-1-9"},{"issue":"5","key":"10550_CR54","doi-asserted-by":"publisher","first-page":"1333","DOI":"10.1109\/TIFS.2017.2787987","volume":"13","author":"LT Phong","year":"2019","unstructured":"Phong LT, Aono Y, Hayashi T, Wang L, Moriai S (2019) Privacy-preserving deep learning via additively homomorphic encryption. IEEE Trans Inf Forensic Secur 13(5):1333\u20131345. https:\/\/doi.org\/10.1109\/TIFS.2017.2787987","journal-title":"IEEE Trans Inf Forensic Secur"},{"issue":"22330865","key":"10550_CR55","doi-asserted-by":"publisher","first-page":"3922","DOI":"10.1109\/TIFS.2022.3214717","volume":"17","author":"K Rajkumar","year":"2022","unstructured":"Rajkumar K, Goswami A, Lakshmanan R (2022) Comment on federated learning with differential privacy: algorithms and performance analysis. IEEE Trans Inf Forensic Secur 17(22330865):3922\u20133924. https:\/\/doi.org\/10.1109\/TIFS.2022.3214717","journal-title":"IEEE Trans Inf Forensic Secur"},{"key":"10550_CR56","unstructured":"Sablayrolles A, Douze M, Ollivier Y (2019) White box vs black-box: Bayes optimal strategies for membership inference. In: ICML. http:\/\/arxiv.org\/abs\/1908.11229"},{"key":"10550_CR57","first-page":"314","volume":"9","author":"A Salem","year":"2018","unstructured":"Salem A, Zhang Y, Humbert M (2018) Ml-leaks: model and data independent membership inference attacks and defenses on machine learning models. CoRR 9:314\u2013331","journal-title":"CoRR"},{"key":"10550_CR58","unstructured":"Salem A, Bhattacharya A, Backes M, Fritz M, Zhang Y (2019) Updates-leak: data set inference and reconstruction attacks in online learning. Preprint at http:\/\/arxiv.org\/abs\/1904.01067"},{"key":"10550_CR59","doi-asserted-by":"publisher","unstructured":"Scheliga D, Mader P (2021) Precode a generic model extension to prevent deep gradient leakage. In: IEEE\/CVF winter conference on applications of computer vision (WACV). https:\/\/doi.org\/10.1109\/WACV51458.2022.00366","DOI":"10.1109\/WACV51458.2022.00366"},{"key":"10550_CR60","unstructured":"Sharma P, Shamout FE, Clifton DA (2019) Preserving patient privacy while training a predictive model of in-hospital mortality. Preprint at CoRR. http:\/\/arxiv.org\/abs\/1912.00354"},{"key":"10550_CR61","doi-asserted-by":"publisher","unstructured":"Shokri R, Shmatikov V (2015) Privacy-preserving deep learning. In: 53rd annual allerton conference on communication, control, and computing. https:\/\/doi.org\/10.1109\/ALLERTON.2015.7447103","DOI":"10.1109\/ALLERTON.2015.7447103"},{"issue":"16981420","key":"10550_CR62","doi-asserted-by":"publisher","first-page":"1314","DOI":"10.1109\/SP.2017.41","volume":"5","author":"R Shokri","year":"2021","unstructured":"Shokri R, Stronati M, Song C (2021a) Membership inference attacks against machine learning models. IEEE Symp Secur Privacy 5(16981420):1314\u20131331. https:\/\/doi.org\/10.1109\/SP.2017.41","journal-title":"IEEE Symp Secur Privacy"},{"key":"10550_CR63","unstructured":"Shokri R, Strobel M, Zick Y (2021b) Privacy risks of explaining machine learning models. Preprint at http:\/\/arxiv.org\/abs\/1907.00164v1"},{"key":"10550_CR64","doi-asserted-by":"publisher","unstructured":"Song C, Ristenpart T, Shmatikov V (2017) Machine learning models that remember too much. In: Acm Sigsac Conference 30 October 2017. https:\/\/doi.org\/10.1145\/3133956.313407","DOI":"10.1145\/3133956.313407"},{"issue":"1","key":"10550_CR65","first-page":"1929","volume":"15","author":"N Srivastava","year":"2014","unstructured":"Srivastava N, Hinton G, Krizhevsky A (2014) Dropout: a simple way to prevent neural networks from overfitting. J Mach Learn Res 15(1):1929\u20131958","journal-title":"J Mach Learn Res"},{"key":"10550_CR66","unstructured":"Stacey T, Nathalie B, Ali A (2018) A hybrid approach to privacy-preserving federated learning. Preprint at http:\/\/arxiv.org\/abs\/1812.03224"},{"key":"10550_CR67","doi-asserted-by":"publisher","unstructured":"Sun C, Shrivastava A, Singh S, Gupta A (2017) Revisiting unreasonable effectiveness of data in deep learning era. Preprint at CoRR. pp 2380\u20137504. http:\/\/arXiv.org\/abs\/1707.02968, https:\/\/doi.org\/10.1109\/ICCV.2017.97","DOI":"10.1109\/ICCV.2017.97"},{"issue":"6","key":"10550_CR68","doi-asserted-by":"publisher","first-page":"152103","DOI":"10.1109\/ACCESS.2019.2947295","volume":"7","author":"Z Sun","year":"2019","unstructured":"Sun Z, Wang Y, Shu M (2019) Differential privacy for data and model publishing of medical data. IEEE Access 7(6):152103\u2013152114. https:\/\/doi.org\/10.1109\/ACCESS.2019.2947295","journal-title":"IEEE Access"},{"key":"10550_CR69","unstructured":"Tsuzuku Y, Imachi H, Akiba T (2010) Variance-based gradient compression for efficient distributed deep learning. In: ICLR workshop. http:\/\/arxiv.org\/abs\/1802.06058"},{"key":"10550_CR70","unstructured":"Verma V, Lamb A, Beckham C (2019) Manifold mixup: better representations by interpolating hidden states. In: ICLR 2019 conference blind submission. http:\/\/arxiv.org\/abs\/1806.05236"},{"key":"10550_CR71","doi-asserted-by":"publisher","unstructured":"Wang Z, Song M, Zhang Z (2019) Beyond inferring class representatives: user-level privacy leakage from federated learning. In: IEEE conference on computer communications, 2 May 2019. https:\/\/doi.org\/10.1109\/INFOCOM.2019.8737416","DOI":"10.1109\/INFOCOM.2019.8737416"},{"issue":"19679192","key":"10550_CR72","doi-asserted-by":"publisher","first-page":"3454","DOI":"10.1109\/TIFS.2020.2988575","volume":"4","author":"K Wei","year":"2020","unstructured":"Wei K, Li J, Ding M, Ma CHH (2020a) Vincent poor: federated learning with differential privacy: algorithms and performance analysis. IEEE Trans Inf Forensic Secur 4(19679192):3454\u20133469. https:\/\/doi.org\/10.1109\/TIFS.2020.2988575","journal-title":"IEEE Trans Inf Forensic Secur"},{"key":"10550_CR73","unstructured":"Wei W, Liu L, Loper M (2020b) A framework for evaluating gradient leakage attacks in federated learning. Preprint at http:\/\/arxiv.org\/abs\/2004.10397"},{"issue":"9","key":"10550_CR74","doi-asserted-by":"publisher","first-page":"2358","DOI":"10.1109\/TIFS.2019.2897874","volume":"14","author":"C Xu","year":"2019","unstructured":"Xu C, Ren J, Zhang D, Zhang Y (2019) Ganobfuscator mitigating information leakage under gan via differential privacy. IEEE Trans Inf Forensic Secur 14(9):2358\u20132371. https:\/\/doi.org\/10.1109\/TIFS.2019.2897874","journal-title":"IEEE Trans Inf Forensic Secur"},{"issue":"1911","key":"10550_CR75","first-page":"46","volume":"2","author":"J Xu","year":"2020","unstructured":"Xu J, Benjamin S, Wang F (2020) Federated learning for healthcare informatics. Mach Learn 2(1911):46\u201364","journal-title":"Mach Learn"},{"key":"10550_CR76","unstructured":"Yan F, Yang X, Fang W, Xia S-T (2021) A practical privacy-preserving method in federated deep learning. In: Network and distributed system security (NDSS) symposium. http:\/\/arxiv.org\/abs\/2002.09843"},{"key":"10550_CR77","doi-asserted-by":"publisher","first-page":"645","DOI":"10.1145\/3298981","volume":"2","author":"Q Yang","year":"2019","unstructured":"Yang Q, Liu Y, Chen T, Tong Y (2019) Federated machine learning: concept and applications. ACM Trans Intell Syst Technol 2:645\u2013666. https:\/\/doi.org\/10.1145\/3298981","journal-title":"ACM Trans Intell Syst Technol"},{"key":"10550_CR78","doi-asserted-by":"publisher","unstructured":"Yin H, Mallya A, Vahdat A (2021) See through gradients: image batch recovery via GradInversion. In: IEEE\/CVF conference on computer vision and pattern recognition (CVPR). https:\/\/doi.org\/10.1109\/CVPR46437.2021.01607","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"10550_CR79","doi-asserted-by":"crossref","unstructured":"Yu D, Zhang H, Chen W, Liu TY, Yin J (2019) Gradient perturbation is underrated for differentially private convex optimization. In: International joint conference on artificial intelligence (IJCAI). http:\/\/arxiv.org\/abs\/1911.11363","DOI":"10.24963\/ijcai.2020\/431"},{"key":"10550_CR80","unstructured":"Yu D, Zhang H, Chen W, Liu T (2021) Do Not let privacy overbill utility: gradient embedding perturbation for private learning. In: ICML. http:\/\/arxiv.org\/abs\/2102.12677"},{"key":"10550_CR81","unstructured":"Zhang H, Cisse M (2018) Mixup: beyond empirical risk minimization. Preprint at ICLR. http:\/\/arxiv.org\/abs\/1710.09412"},{"key":"10550_CR82","unstructured":"Zhang J, He T, Sra S (2019) Why gradient clipping accelerates training: a theoretical justification for adaptivity. In: International conference on learning representations. In: ICLR workshop. http:\/\/arxiv.org\/abs\/1905.11881"},{"key":"10550_CR83","doi-asserted-by":"publisher","unstructured":"Zhang Y, Jia R, Pei H (2020) The secret revealer: generative model-inversion attacks against deep neural networks. In: IEEE\/CVF conference on computer vision and pattern recognition (CVPR). https:\/\/doi.org\/10.1109\/CVPR42600.2020.00033","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"10550_CR84","unstructured":"Zhao B, Mopuri KR, Bilen H (2020) idlg: improved deep leakage from gradients. http:\/\/github.com\/PatrickZH\/Improved-Deep-Leakage-from-Gradients"},{"key":"10550_CR85","unstructured":"Zhu J, Blaschko MB (2021) R-GAP: recursive gradient attack on privacy. http:\/\/github.com\/JunyiZhu-AI\/R-GAP"},{"key":"10550_CR86","doi-asserted-by":"crossref","unstructured":"Zhu L, Liu Z (2019) Deep leakage from gradient. http:\/\/github.com\/mit-han-lab\/dlg","DOI":"10.1007\/978-3-030-63076-8_2"}],"container-title":["Artificial Intelligence Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-023-10550-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10462-023-10550-z\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-023-10550-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,10,21]],"date-time":"2023-10-21T10:33:56Z","timestamp":1697884436000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10462-023-10550-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,7,23]]},"references-count":86,"journal-issue":{"issue":"S1","published-print":{"date-parts":[[2023,10]]}},"alternative-id":["10550"],"URL":"https:\/\/doi.org\/10.1007\/s10462-023-10550-z","relation":{},"ISSN":["0269-2821","1573-7462"],"issn-type":[{"value":"0269-2821","type":"print"},{"value":"1573-7462","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,7,23]]},"assertion":[{"value":"1 July 2023","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 July 2023","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}},{"value":"Not applicable.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical approval"}},{"value":"Not applicable.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent to participate"}}]}}