{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,24]],"date-time":"2026-07-24T03:55:15Z","timestamp":1784865315624,"version":"3.55.0"},"reference-count":195,"publisher":"Springer Science and Business Media LLC","issue":"8","license":[{"start":{"date-parts":[[2025,5,13]],"date-time":"2025-05-13T00:00:00Z","timestamp":1747094400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,5,13]],"date-time":"2025-05-13T00:00:00Z","timestamp":1747094400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"DOI":"10.13039\/501100001795","name":"University of Southern Queensland","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100001795","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Artif Intell Rev"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>The rapid adoption of deep learning in sensitive domains has brought tremendous benefits. However, this widespread adoption has also given rise to serious vulnerabilities, particularly model inversion\u00a0(MI) attacks, posing a significant threat to the privacy and integrity of personal data. The increasing prevalence of these attacks in applications such as biometrics, healthcare, and finance has created an urgent need to understand their mechanisms, impacts, and defense methods. This survey aims to fill the gap in the literature by providing a structured and in-depth review of MI attacks and defense strategies. Our contributions include a systematic taxonomy of MI attacks, extensive research on attack techniques and defense mechanisms, and a discussion about the challenges and future research directions in this evolving field. By exploring the technical and ethical implications of MI attacks, this survey aims to offer insights into the impact of AI-powered systems on privacy, security, and trust. In conjunction with this survey, we have developed a comprehensive repository to support research on MI attacks and defenses. The repository includes state-of-the-art research papers, datasets, evaluation metrics, and other resources to meet the needs of both novice and experienced researchers interested in MI attacks and defenses, as well as the broader field of AI security and privacy. The repository will be continuously maintained to ensure its relevance and utility. It is accessible at <jats:ext-link xmlns:xlink=\"http:\/\/www.w3.org\/1999\/xlink\" xlink:href=\"https:\/\/github.com\/overgter\/Deep-Learning-Model-Inversion-Attacks-and-Defenses\" ext-link-type=\"uri\">https:\/\/github.com\/overgter\/Deep-Learning-Model-Inversion-Attacks-and-Defenses<\/jats:ext-link>.<\/jats:p>","DOI":"10.1007\/s10462-025-11248-0","type":"journal-article","created":{"date-parts":[[2025,5,13]],"date-time":"2025-05-13T01:54:52Z","timestamp":1747101292000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":47,"title":["Deep learning model inversion attacks and defenses: a comprehensive survey"],"prefix":"10.1007","volume":"58","author":[{"given":"Wencheng","family":"Yang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Song","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Di","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Taotao","family":"Cai","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yanming","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shicheng","family":"Wei","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yiying","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xu","family":"Yang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhaohui","family":"Tang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yan","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,5,13]]},"reference":[{"key":"11248_CR1","volume":"74","author":"E Antwi-Boasiako","year":"2023","unstructured":"Antwi-Boasiako E, Zhou S, Liao Y, Dong Y (2023) Privacy-preserving distributed deep learning via LWE-based certificateless additively homomorphic encryption (cahe). J Inform Secur Appl 74:103462","journal-title":"J Inform Secur Appl"},{"issue":"9","key":"11248_CR2","doi-asserted-by":"publisher","first-page":"12919","DOI":"10.1007\/s13369-024-08884-z","volume":"49","author":"I Al-Hejri","year":"2024","unstructured":"Al-Hejri I, Azzedin F, Almuhammadi S, Eltoweissy M (2024) Lightweight secure and scalable scheme for data transmission in the internet of things. Arab J Sci Eng 49(9):12919\u201312934","journal-title":"Arab J Sci Eng"},{"issue":"5","key":"11248_CR3","first-page":"2061","volume":"18","author":"Y Alufaisan","year":"2020","unstructured":"Alufaisan Y, Kantarcioglu M, Zhou Y (2020) Robust transparency against model inversion attacks. IEEE Trans Dependable Secure Comput 18(5):2061\u20132073","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"11248_CR4","unstructured":"Alhalabi B (2023) Ensembles of pruned deep neural networks for accurate and privacy preservation in iot applications. Phd thesis, Birmingham City University. http:\/\/www.open-access.bcu.ac.uk\/15070\/"},{"key":"11248_CR5","doi-asserted-by":"crossref","unstructured":"Ahmad S, Mahmood K, Fuller B (2022) Inverting biometric models with fewer samples: Incorporating the output of multiple models. 2022 IEEE International Joint Conference on Biometrics (IJCB). IEEE, Piscataway, USA, pp 1\u201311","DOI":"10.1109\/IJCB54206.2022.10007997"},{"key":"11248_CR6","doi-asserted-by":"crossref","unstructured":"An S, Tao G, Xu Q, Liu Y, Shen G, Yao Y, Xu J, Zhang X (2022) Mirror: Model inversion for deep learning network with high fidelity. In: Proceedings of the 29th Network and Distributed System Security Symposium. https:\/\/par.nsf.gov\/servlets\/purl\/10376663","DOI":"10.14722\/ndss.2022.24335"},{"key":"11248_CR7","unstructured":"Bishop CM, Nasrabadi NM (2006) Pattern Recognition and Machine Learning vol. 4. Springer, Cham, Switzerland. https:\/\/link.springer.com\/book\/9780387310732"},{"key":"11248_CR8","doi-asserted-by":"crossref","unstructured":"Chen Y, Abrahamyan L, Sahli H, Deligiannis N (2024) Learned model compression for efficient and privacy-preserving federated learning. Authorea Preprints","DOI":"10.36227\/techrxiv.171073597.75352317\/v1"},{"key":"11248_CR9","unstructured":"Carlini N, Hayes J, Nasr M, Jagielski M, Sehwag V, Tramer F, Balle B, Ippolito D, Wallace E (2023) Extracting training data from diffusion models. In: 32nd USENIX Security Symposium (USENIX Security 23), pp. 5253\u20135270 https:\/\/www.usenix.org\/conference\/usenixsecurity23\/presentation\/carlini"},{"key":"11248_CR10","unstructured":"Chen S, Jia R, Qi G.-J (2020) Improved techniques for model inversion attacks. https:\/\/openreview.net\/forum?id=unRf7cz1o1"},{"key":"11248_CR11","doi-asserted-by":"crossref","unstructured":"Chen S, Kahla M, Jia R, Qi G-J (2021) Knowledge-enriched distributional model inversion attacks. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp 16178\u201316187. http:\/\/openaccess.thecvf.com\/content\/ICCV2021\/html\/Chen_Knowledge-Enriched_Distributional_Model_Inversion_Attacks_ICCV_2021_paper.html","DOI":"10.1109\/ICCV48922.2021.01587"},{"key":"11248_CR12","doi-asserted-by":"crossref","unstructured":"Chen Y, Lent H, Bjerva J (2024) Text embedding inversion attacks on multilingual language models. Preprint at arXiv:2401.12192","DOI":"10.18653\/v1\/2024.acl-long.422"},{"key":"11248_CR13","doi-asserted-by":"publisher","unstructured":"Cui Y, Meerza SIA, Li Z, Liu L, Zhang J, Liu J (2023) Recup-fl: Reconciling utility and privacy in federated learning via user-configurable privacy defense. In: Proceedings of the ACM Asia Conference on Computer and Communications Security, pp 80\u201394. ACM, Melbourne VIC Australia. https:\/\/doi.org\/10.1145\/3579856.3582819","DOI":"10.1145\/3579856.3582819"},{"key":"11248_CR14","unstructured":"Chu T, Yang M, Laoutaris N, Markopoulou A (2023) Priprune: Quantifying and preserving privacy in pruned federated learning. Preprint at arXiv:2310.19958"},{"key":"11248_CR15","doi-asserted-by":"publisher","unstructured":"Chen Y, Zhang J, Bi Y, Hu X, Hu T, Xue Z, Yi R, Liu Y, Tai Y (2025) Image inversion: a survey from gans to diffusion and beyond https:\/\/doi.org\/10.48550\/arXiv.2502.11974. arXiv:2502.11974","DOI":"10.48550\/arXiv.2502.11974"},{"key":"11248_CR16","doi-asserted-by":"crossref","unstructured":"Dibbo SV, Breuer A, Moore J, Teti M (2024) Improving robustness to model inversion attacks via sparse coding architectures. European Conference on Computer Vision (ECCV 2024)","DOI":"10.1007\/978-3-031-72989-8_7"},{"key":"11248_CR17","doi-asserted-by":"crossref","unstructured":"Deng J, Dong W, Socher R, Li L-J, Li K, Fei-Fei L (2009) Imagenet: A large-scale hierarchical image database. In: 2009 IEEE Conference on Computer Vision and Pattern Recognition, pp. 248\u2013255. Ieee, Piscataway, USA. https:\/\/ieeexplore.ieee.org\/abstract\/document\/5206848\/","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"11248_CR18","doi-asserted-by":"crossref","unstructured":"Dibbo SV (2023) Sok: Model inversion attack landscape: Taxonomy, challenges, and future roadmap. In: 2023 IEEE 36th Computer Security Foundations Symposium (CSF), pp 439\u2013456. IEEE, Piscataway, USA. https:\/\/ieeexplore.ieee.org\/abstract\/document\/10221914\/?casa_token=ll4qd67NzeEAAAAA:4hztSa9NT1bHOToVGrvduZuYjvD8vcu0lwyiTLO1EE5PftwD3qjkAtUbJQ16r88c2q_lHk4ZjA","DOI":"10.1109\/CSF57540.2023.00027"},{"key":"11248_CR19","doi-asserted-by":"publisher","unstructured":"Dai C, Lu L, Zhou P (2025) Stealing training data from large language models in decentralized training through activation inversion attack https:\/\/doi.org\/10.48550\/arXiv.2502.16086. arXiv:2502.16086","DOI":"10.48550\/arXiv.2502.16086"},{"key":"11248_CR20","doi-asserted-by":"publisher","DOI":"10.21553\/rev-jec.338","author":"T-N Dao","year":"2024","unstructured":"Dao T-N, Nguyen TP (2024) Performance analysis of gradient inversion attack in federated learning with healthcare systems. REV J Electron Commun. https:\/\/doi.org\/10.21553\/rev-jec.338","journal-title":"REV J Electron Commun"},{"key":"11248_CR21","volume-title":"The concise encyclopedia of statistics","author":"Y Dodge","year":"2008","unstructured":"Dodge Y (2008) The concise encyclopedia of statistics. Springer, Cham"},{"key":"11248_CR22","doi-asserted-by":"crossref","unstructured":"Ding S, Zhang L, Pan M, Yuan X (2024) Patrol: Privacy-oriented pruning for collaborative inference against model inversion attacks. In: Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision, pp 4716\u20134725. https:\/\/openaccess.thecvf.com\/content\/WACV2024\/html\/Ding_PATROL_Privacy-Oriented_Pruning_for_Collaborative_Inference_Against_Model_Inversion_Attacks_WACV_2024_paper.html","DOI":"10.1109\/WACV57701.2024.00465"},{"key":"11248_CR23","unstructured":"Fan M, Chen C, Wang C, Li X, Zhou W, Huang J (2023) Refiner: Data refining against gradient leakage attacks in federated learning. Preprint at arXiv:2212.02042"},{"key":"11248_CR24","doi-asserted-by":"crossref","unstructured":"Fang H, Chen B, Wang X, Wang Z, Xia S-T (2023) Gifd: A generative gradient inversion method with feature domain optimization. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp 4967\u20134976. http:\/\/openaccess.thecvf.com\/content\/ICCV2023\/html\/Fang_GIFD_A_Generative_Gradient_Inversion_Method_with_Feature_Domain_Optimization_ICCV_2023_paper.html","DOI":"10.1109\/ICCV51070.2023.00458"},{"key":"11248_CR25","doi-asserted-by":"publisher","unstructured":"Fredrikson M, Jha S, Ristenpart T (2015) Model inversion attacks that exploit confidence information and basic countermeasures. In: Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security, pp 1322\u20131333. ACM, Denver Colorado USA. https:\/\/doi.org\/10.1145\/2810103.2813677","DOI":"10.1145\/2810103.2813677"},{"key":"11248_CR26","doi-asserted-by":"publisher","unstructured":"Fan M, Liu Y, Chen C, Wang C, Qiu M, Zhou W (2024) Guardian: Guarding against gradient leakage with provable defense for federated learning. In: Proceedings of the 17th ACM International Conference on Web Search and Data Mining, pp 190\u2013198. ACM, Merida Mexico. https:\/\/doi.org\/10.1145\/3616855.3635758","DOI":"10.1145\/3616855.3635758"},{"key":"11248_CR27","unstructured":"Fredrikson M, Lantz E, Jha S, Lin S, Page D, Ristenpart T (2014) Privacy in pharmacogenetics: An End-to-End case study of personalized warfarin dosing. In: 23rd USENIX Security Symposium (USENIX Security 14), pp 17\u201332. https:\/\/www.usenix.org\/conference\/usenixsecurity14\/technical-sessions\/presentation\/fredrikson_matthew"},{"issue":"11","key":"11248_CR28","doi-asserted-by":"publisher","first-page":"697","DOI":"10.3390\/info15110697","volume":"15","author":"G Feretzakis","year":"2024","unstructured":"Feretzakis G, Papaspyridis K, Gkoulalas-Divanis A, Verykios VS (2024) Privacy-preserving techniques in generative ai and large language models: a narrative review. Information 15(11):697","journal-title":"Information"},{"key":"11248_CR29","unstructured":"Fang H, Qiu Y, Yu H, Yu W, Kong J, Chong B, Chen B, Wang X, Xia S-T, Xu K (2024) Privacy leakage on DNNS: a survey of model inversion attacks and defenses. Preprint at arXiv:2402.04013"},{"key":"11248_CR30","first-page":"16937","volume":"33","author":"J Geiping","year":"2020","unstructured":"Geiping J, Bauermeister H, Dr\u00f6ge H, Moeller M (2020) Inverting gradients-how easy is it to break privacy in federated learning? Adv Neural Inf Process Syst 33:16937\u201316947","journal-title":"Adv Neural Inf Process Syst"},{"key":"11248_CR31","unstructured":"Goldsteen A, Ezov G, Farkash A (2020) Reducing risk of model inversion using privacy-guided training. Preprint at arXiv:2006.15877"},{"key":"11248_CR32","doi-asserted-by":"crossref","unstructured":"Gao W, Guo S, Zhang T, Qiu H, Wen Y, Liu Y (2021) Privacy-preserving collaborative learning with automatic transformation search. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 114\u2013123. http:\/\/openaccess.thecvf.com\/content\/CVPR2021\/html\/Gao_Privacy-Preserving_Collaborative_Learning_With_Automatic_Transformation_Search_CVPR_2021_paper.html","DOI":"10.1109\/CVPR46437.2021.00018"},{"issue":"S1","key":"11248_CR33","doi-asserted-by":"publisher","first-page":"1337","DOI":"10.1007\/s10462-023-10550-z","volume":"56","author":"H Gong","year":"2023","unstructured":"Gong H, Jiang L, Liu X, Wang Y, Gastro O, Wang L, Zhang K, Guo Z (2023) Gradient leakage attacks in federated learning. Artif Intell Rev 56(S1):1337\u20131374. https:\/\/doi.org\/10.1007\/s10462-023-10550-z","journal-title":"Artif Intell Rev"},{"key":"11248_CR34","doi-asserted-by":"crossref","unstructured":"Galloway T, Karakolios K, Ma Z, Perdisci R, Keromytis A, Antonakakis M (2024) Practical attacks against DNS reputation systems. In: 2024 IEEE Symposium on Security and Privacy (SP), pp 233\u2013233. IEEE Computer Society, Piscataway, USA. https:\/\/tillsongalloway.com\/sp2024winter-final30.pdf","DOI":"10.1109\/SP54263.2024.00266"},{"key":"11248_CR35","unstructured":"Goodfellow I (2016) Deep learning. MIT press"},{"key":"11248_CR36","doi-asserted-by":"publisher","unstructured":"Guo P, Zeng S, Chen W, Zhang X, Ren W, Zhou Y, Qu L (2024) A new federated learning framework against gradient inversion attacks https:\/\/doi.org\/10.48550\/arXiv.2412.07187. arXiv:2412.07187","DOI":"10.48550\/arXiv.2412.07187"},{"issue":"9","key":"11248_CR37","doi-asserted-by":"publisher","first-page":"10650","DOI":"10.1109\/TPAMI.2023.3262813","volume":"45","author":"W Gao","year":"2023","unstructured":"Gao W, Zhang X, Guo S, Zhang T, Xiang T, Qiu H, Wen Y, Liu Y (2023) Automatic transformation search against deep leakage from gradients. IEEE Trans Pattern Anal Mach Intell 45(9):10650\u201310668","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"11248_CR38","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2024.111983","volume":"299","author":"K Gao","year":"2024","unstructured":"Gao K, Zhu T, Ye D, Zhou W (2024) Defending against gradient inversion attacks in federated learning via statistical machine unlearning. Knowl Based Syst 299:111983","journal-title":"Knowl Based Syst"},{"key":"11248_CR39","doi-asserted-by":"crossref","unstructured":"Han G, Choi J, Lee H, Kim J (2023) Reinforcement learning-based black-box model inversion attacks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 20504\u201320513. http:\/\/openaccess.thecvf.com\/content\/CVPR2023\/html\/Han_Reinforcement_Learning-Based_Black-Box_Model_Inversion_Attacks_CVPR_2023_paper.html","DOI":"10.1109\/CVPR52729.2023.01964"},{"key":"11248_CR40","first-page":"7232","volume":"34","author":"Y Huang","year":"2021","unstructured":"Huang Y, Gupta S, Song Z, Li K, Arora S (2021) Evaluating gradient inversion attacks and defenses in federated learning. Adv Neural Inf Process Syst 34:7232\u20137241","journal-title":"Adv Neural Inf Process Syst"},{"key":"11248_CR41","doi-asserted-by":"crossref","unstructured":"Ho S-T, Hao KJ, Chandrasegaran K, Nguyen N-B, Cheung N-M (2024) Model inversion robustness: can transfer learning help? In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 12183\u201312193. https:\/\/openaccess.thecvf.com\/content\/CVPR2024\/html\/Ho_Model_Inversion_Robustness_Can_Transfer_Learning_Help_CVPR_2024_paper.html","DOI":"10.1109\/CVPR52733.2024.01158"},{"key":"11248_CR42","doi-asserted-by":"publisher","unstructured":"Huang J, Hong C, Chen LY, Roos S (2024) Gradient inversion of federated diffusion models https:\/\/doi.org\/10.48550\/arXiv.2405.20380. arXiv:2405.20380","DOI":"10.48550\/arXiv.2405.20380"},{"key":"11248_CR43","unstructured":"Huang GB, Mattar M, Berg T, Learned-Miller E (2008) Labeled faces in the wild: A database forstudying face recognition in unconstrained environments. In: Workshop on Faces in\u2019Real-Life\u2019Images: Detection, Alignment, and Recognition. https:\/\/inria.hal.science\/inria-00321923\/document"},{"issue":"5","key":"11248_CR44","doi-asserted-by":"publisher","first-page":"1743","DOI":"10.1109\/TSE.2020.3034721","volume":"48","author":"Y He","year":"2020","unstructured":"He Y, Meng G, Chen K, Hu X, He J (2020) Towards security threats of deep learning systems: a survey. IEEE Trans Software Eng 48(5):1743\u20131770","journal-title":"IEEE Trans Software Eng"},{"key":"11248_CR45","unstructured":"Heusel M, Ramsauer H, Unterthiner T, Nessler B, Hochreiter S (2017) Gans trained by a two time-scale update rule converge to a local nash equilibrium. Adv Neural Inform Process Syst 30"},{"key":"11248_CR46","doi-asserted-by":"crossref","unstructured":"Hung J (2023) Models as personal data. Available at SSRN 4504856","DOI":"10.2139\/ssrn.4504856"},{"key":"11248_CR47","unstructured":"Hu H, Wang S, Dong T, Xue M (2024) Learn what you want to unlearn: unlearning inversion attacks against machine unlearning. In: 2024 IEEE Symposium on Security and Privacy (SP), pp 262\u2013262. IEEE, Piscataway, USA. https:\/\/www.computer.org\/csdl\/proceedings-article\/sp\/2024\/313000a262\/1WPcZmo5z2w"},{"key":"11248_CR48","unstructured":"Huang Y, Wang Y, Li J, Yang L, Song K, Wang L (2024) Adaptive hybrid masking strategy for privacy-preserving face recognition against model inversion attack. Preprint at arXiv:2403.10558"},{"issue":"7","key":"11248_CR49","doi-asserted-by":"publisher","first-page":"2044","DOI":"10.1109\/TMI.2023.3239391","volume":"42","author":"A Hatamizadeh","year":"2023","unstructured":"Hatamizadeh A, Yin H, Molchanov P, Myronenko A, Li W, Dogra P, Feng A, Flores MG, Kautz J, Xu D et al (2023) Do gradient inversion attacks make federated learning unsafe? IEEE Trans Med Imaging 42(7):2044\u20132056","journal-title":"IEEE Trans Med Imaging"},{"key":"11248_CR50","doi-asserted-by":"crossref","unstructured":"Issa W, Moustafa N, Turnbull B, Choo K-KR (2024) Rve-pfl: Robust variational encoder-based personalised federated learning against model inversion attacks. IEEE Transactions on Information Forensics and Security","DOI":"10.1109\/TIFS.2024.3368879"},{"key":"11248_CR51","unstructured":"Jang J, Lyu H, Yang HJ (2023) Patch-mi: Enhancing model inversion attacks via patch-based reconstruction. Preprint at arXiv:2312.07040"},{"issue":"12","key":"11248_CR52","doi-asserted-by":"publisher","first-page":"10374","DOI":"10.1109\/TNNLS.2022.3166101","volume":"34","author":"Y Jiang","year":"2022","unstructured":"Jiang Y, Wang S, Valls V, Ko BJ, Lee W-H, Leung KK, Tassiulas L (2022) Model pruning enables efficient federated learning on edge devices. IEEE Transact Neural Netw Learn Syst 34(12):10374\u201310386","journal-title":"IEEE Transact Neural Netw Learn Syst"},{"key":"11248_CR53","doi-asserted-by":"crossref","unstructured":"Karras T (2019) A style-based generator architecture for generative adversarial networks. Preprint at arXiv:1812.04948","DOI":"10.1109\/CVPR.2019.00453"},{"key":"11248_CR54","doi-asserted-by":"crossref","unstructured":"Kahla M, Chen S, Just HA, Jia R (2022) Label-only model inversion attacks via boundary repulsion. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 15045\u201315053. http:\/\/openaccess.thecvf.com\/content\/CVPR2022\/html\/Kahla_Label-Only_Model_Inversion_Attacks_via_Boundary_Repulsion_CVPR_2022_paper.html","DOI":"10.1109\/CVPR52688.2022.01462"},{"key":"11248_CR55","doi-asserted-by":"crossref","unstructured":"Krall A, Finke D, Yang H (2020) Gradient mechanism to preserve differential privacy and deter against model inversion attacks in healthcare analytics. In: 2020 42nd Annual International Conference of the IEEE Engineering in Medicine & Biology Society (EMBC), pp 5714\u20135717. IEEE, Piscataway, USA","DOI":"10.1109\/EMBC44109.2020.9176834"},{"key":"11248_CR56","unstructured":"Krizhevsky A, Hinton G (2009) Learning multiple layers of features from tiny images"},{"key":"11248_CR57","unstructured":"Krizhevsky A, Nair V, Hinton G (2010) Cifar-10 (Canadian Institute for Advanced Research) 5(4):1. http:\/\/www.cs.toronto.edu\/kriz\/cifar.html"},{"issue":"3","key":"11248_CR58","first-page":"1100","volume":"15","author":"M Khosravy","year":"2021","unstructured":"Khosravy M, Nakamura K, Hirose Y, Nitta N, Babaguchi N (2021) Model inversion attack: analysis under gray-box scenario on deep learning based face recognition system. KSII Transact Internet Inform Syst (TIIS) 15(3):1100\u20131118","journal-title":"KSII Transact Internet Inform Syst (TIIS)"},{"key":"11248_CR59","doi-asserted-by":"publisher","first-page":"357","DOI":"10.1109\/TIFS.2022.3140687","volume":"17","author":"M Khosravy","year":"2022","unstructured":"Khosravy M, Nakamura K, Hirose Y, Nitta N, Babaguchi N (2022) Model inversion attack by integration of deep generative models: privacy-sensitive face generation from a face recognition system. IEEE Trans Inf Forensics Secur 17:357\u2013372","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"6","key":"11248_CR60","doi-asserted-by":"publisher","first-page":"473","DOI":"10.1038\/s42256-021-00337-8","volume":"3","author":"G Kaissis","year":"2021","unstructured":"Kaissis G, Ziller A, Passerat-Palmbach J, Ryffel T, Usynin D, Trask A, Lima I Jr, Mancuso J, Jungmann F, Steinborn M-M (2021) End-to-end privacy preserving deep learning on multi-institutional medical imaging. Nat Mach Intell 3(6):473\u2013484","journal-title":"Nat Mach Intell"},{"key":"11248_CR61","doi-asserted-by":"publisher","unstructured":"Li H, Chen Y, Luo J, Wang J, Peng H, Kang Y, Zhang X, Hu Q, Chan C, Xu Z, Hooi B, Song Y (2024) Privacy in large language models: Attacks, defenses and future directions https:\/\/doi.org\/10.48550\/arXiv.2310.10383. arXiv:2310.10383","DOI":"10.48550\/arXiv.2310.10383"},{"issue":"7","key":"11248_CR62","doi-asserted-by":"publisher","first-page":"900","DOI":"10.1109\/TCSVT.2005.848345","volume":"15","author":"W Lin","year":"2005","unstructured":"Lin W, Dong L, Xue P (2005) Visual distortion gauge based on discrimination of noticeable contrast changes. IEEE Trans Circuits Syst Video Technol 15(7):900\u2013909","journal-title":"IEEE Trans Circuits Syst Video Technol"},{"key":"11248_CR63","unstructured":"LeCun Y (1998) The MNIST database of handwritten digits. http:\/\/yann.lecun.com\/exdb\/mnist\/"},{"key":"11248_CR64","unstructured":"Lin Y, Han S, Mao H, Wang Y, Dally B (2018) Deep gradient compression: Reducing the communication bandwidth for distributed training. In: International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=SkhQHMW0W"},{"key":"11248_CR65","doi-asserted-by":"publisher","unstructured":"Li O, Hao Y, Wang Z, Zhu B, Wang S, Zhang Z, Feng F (2024) Model inversion attacks through target-specific conditional diffusion models. https:\/\/doi.org\/10.48550\/arXiv.2407.11424. arXiv:2407.11424","DOI":"10.48550\/arXiv.2407.11424"},{"key":"11248_CR66","doi-asserted-by":"publisher","first-page":"5860","DOI":"10.1109\/TIFS.2023.3309095","volume":"18","author":"H Liu","year":"2023","unstructured":"Liu H, Li B, Gao C, Xie P, Zhao C (2023) Privacy-encoded federated learning against gradient-based data reconstruction attacks. IEEE Trans Inf Forensics Secur 18:5860\u20135875","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"11248_CR67","doi-asserted-by":"crossref","unstructured":"Liu Z, Luo P, Wang X, Tang X (2015) Deep learning face attributes in the wild. In: Proceedings of the IEEE International Conference on Computer Vision, pp 3730\u20133738. http:\/\/openaccess.thecvf.com\/content_iccv_2015\/html\/Liu_Deep_Learning_Face_ICCV_2015_paper.html","DOI":"10.1109\/ICCV.2015.425"},{"key":"11248_CR68","doi-asserted-by":"crossref","unstructured":"Liang H, Li Y, Zhang C, Liu X, Zhu L (2023) EGIA: An external gradient inversion attack in federated learning. IEEE Transactions on Information Forensics and Security","DOI":"10.1109\/TIFS.2023.3302161"},{"key":"11248_CR69","doi-asserted-by":"crossref","unstructured":"Li J, Rakin AS, Chen X, He Z, Fan D, Chakrabarti C (2022) RESSFL: a resistance transfer framework for defending model inversion attack in split federated learning. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 10194\u201310202","DOI":"10.1109\/CVPR52688.2022.00995"},{"key":"11248_CR70","doi-asserted-by":"crossref","unstructured":"Liu Y-H, Shen Y-C, Chen H-W, Chen M-S (2024) Construct a secure cnn against gradient inversion attack. In: Pacific-Asia Conference on Knowledge Discovery and Data Mining. Springer, Cham, pp 250\u2013261","DOI":"10.1007\/978-981-97-2259-4_19"},{"key":"11248_CR71","unstructured":"Liu S, Wang Z, Lei Q (2024) Data reconstruction attacks and defenses: a systematic evaluation. Preprint at arXiv:2402.09478"},{"key":"11248_CR72","doi-asserted-by":"crossref","unstructured":"Liu R, Wang D, Ren Y, Wang Z, Guo K, Qin Q, Liu X (2024) Unstoppable attack: Label-only model inversion via conditional diffusion model. IEEE Transactions on Information Forensics and Security","DOI":"10.1109\/TIFS.2024.3372815"},{"key":"11248_CR73","doi-asserted-by":"crossref","unstructured":"Lu J, Xue L, Wan W, Li M, Zhang LY, Hu S (2023) Preserving privacy of input features across all stages of collaborative learning. In: 2023 IEEE Intl Conf on Parallel & Distributed Processing with Applications, Big Data & Cloud Computing, Sustainable Computing & Communications, Social Computing & Networking (ISPA\/BDCloud\/SocialCom\/SustainCom). IEEE, Piscataway, pp 191\u2013198. https:\/\/ieeexplore.ieee.org\/abstract\/document\/10491741\/","DOI":"10.1109\/ISPA-BDCloud-SocialCom-SustainCom59178.2023.00058"},{"key":"11248_CR74","doi-asserted-by":"publisher","unstructured":"Li W, Yu P, Cheng Y, Yan J, Zhang Z (2024) Efficient and privacy-enhanced federated learning based on parameter degradation. IEEE Transactions on Services Computing, pp 1\u201316 https:\/\/doi.org\/10.1109\/TSC.2024.3399659","DOI":"10.1109\/TSC.2024.3399659"},{"key":"11248_CR75","doi-asserted-by":"publisher","unstructured":"Liu T, Yao H, Wu T, Qin Z, Lin F, Ren K, Chen C (2024) Mitigating privacy risks in LLM embeddings from embedding inversion. Preprint at https:\/\/doi.org\/10.48550\/arXiv.2411.05034","DOI":"10.48550\/arXiv.2411.05034"},{"issue":"11","key":"11248_CR76","doi-asserted-by":"publisher","first-page":"9373","DOI":"10.1002\/int.22997","volume":"37","author":"Z Luo","year":"2022","unstructured":"Luo Z, Zhu C, Fang L, Kou G, Hou R, Wang X (2022) An effective and practical gradient inversion attack. Int J Intell Syst 37(11):9373\u20139389","journal-title":"Int J Intell Syst"},{"key":"11248_CR77","doi-asserted-by":"crossref","unstructured":"Li Z, Zhang J, Liu L, Liu J (2022) Auditing privacy defenses in federated learning via generative gradient leakage. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 10132\u201310142. http:\/\/openaccess.thecvf.com\/content\/CVPR2022\/html\/Li_Auditing_Privacy_Defenses_in_Federated_Learning_via_Generative_Gradient_Leakage_CVPR_2022_paper.html","DOI":"10.1109\/CVPR52688.2022.00989"},{"key":"11248_CR78","doi-asserted-by":"crossref","unstructured":"Makhdoom I, Abolhasan M, Lipman J, Shariati N, Franklin D, Piccardi M (2024) Securing personally identifiable information: a survey of Sota techniques, and a way forward. IEEE Access","DOI":"10.1109\/ACCESS.2024.3447017"},{"key":"11248_CR79","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1016\/j.dss.2014.03.001","volume":"62","author":"S Moro","year":"2014","unstructured":"Moro S, Cortez P, Rita P (2014) A data-driven approach to predict the success of bank telemarketing. Decis Support Syst 62:22\u201331","journal-title":"Decis Support Syst"},{"key":"11248_CR80","doi-asserted-by":"crossref","unstructured":"Milner L (2024) Threat models to machine unlearning","DOI":"10.20944\/preprints202409.2068.v1"},{"key":"11248_CR81","doi-asserted-by":"publisher","unstructured":"MaungMaung A, Kiya H (2023) Generative model-based attack on learnable image encryption for privacy-preserving deep learning. Preprint at https:\/\/doi.org\/10.48550\/arXiv.2303.05036","DOI":"10.48550\/arXiv.2303.05036"},{"key":"11248_CR82","doi-asserted-by":"crossref","unstructured":"Masuda H, Kita K, Koizumi Y, Takemasa J, Hasegawa T (2021) Model fragmentation, shuffle and aggregation to mitigate model inversion in federated learning. In: 2021 IEEE International Symposium on Local and Metropolitan Area Networks (LANMAN). IEEE, Piscataway, pp 1\u20136","DOI":"10.1109\/LANMAN52105.2021.9478813"},{"key":"11248_CR83","doi-asserted-by":"crossref","unstructured":"Melis L, Song C, De\u00a0Cristofaro E, Shmatikov V (2019) Exploiting unintended feature leakage in collaborative learning. In: 2019 IEEE Symposium on Security and Privacy (SP). IEEE, Piscataway, pp 691\u2013706. https:\/\/ieeexplore.ieee.org\/abstract\/document\/8835269\/","DOI":"10.1109\/SP.2019.00029"},{"key":"11248_CR84","doi-asserted-by":"publisher","first-page":"129385","DOI":"10.1109\/ACCESS.2021.3112684","volume":"9","author":"K Madono","year":"2021","unstructured":"Madono K, Tanaka M, Onishi M, Ogawa T (2021) SIA-GAN: Scrambling inversion attack using generative adversarial network. IEEE Access 9:129385\u2013129393","journal-title":"IEEE Access"},{"key":"11248_CR85","doi-asserted-by":"publisher","unstructured":"Morris JX, Zhao W, Chiu JT, Shmatikov V, Rush AM (2023) Language model inversion https:\/\/doi.org\/10.48550\/arXiv.2311.13647. arXiv:2311.13647","DOI":"10.48550\/arXiv.2311.13647"},{"key":"11248_CR86","doi-asserted-by":"crossref","unstructured":"Nguyen N-B, Chandrasegaran K, Abdollahzadeh M, Cheung N-M (2023) Re-thinking model inversion attacks against deep neural networks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 16384\u201316393","DOI":"10.1109\/CVPR52729.2023.01572"},{"key":"11248_CR87","unstructured":"Nguyen B-N, Chandrasegaran K, Abdollahzadeh M, Cheung N-MM (2024) Label-only model inversion attacks via knowledge transfer. Adv Neural Inform Process Syst 36"},{"key":"11248_CR88","unstructured":"Nguyen K (2024) Enhancing data privacy in artificial intelligence"},{"key":"11248_CR89","unstructured":"Netzer Y, Wang T, Coates A, Bissacco A, Wu B, Ng AY (2011) Reading digits in natural images with unsupervised feature learning. In: NIPS Workshop on Deep Learning and Unsupervised Feature Learning, vol. 2011. Granada, London, p 4. http:\/\/research.google.com\/pubs\/archive\/37648.pdf"},{"key":"11248_CR90","doi-asserted-by":"crossref","unstructured":"Niu B, Wang X, Zhang L, Guo S, Cao J, Li F (2023) A sensitivity-aware and block-wise pruning method for privacy-preserving federated learning. In: GLOBECOM 2023-2023 IEEE Global Communications Conference. IEEE, Piscataway, pp 4259\u20134264. https:\/\/ieeexplore.ieee.org\/abstract\/document\/10437766\/?casa_token=_FWictAIJdUAAAAA:siA8OJE4dnr4nYeujVkRpJNJxE55YbSDKvOiuigbJFzlMZR6kvWRTezu3OT0Yhen4cdxMEXZqw","DOI":"10.1109\/GLOBECOM54140.2023.10437766"},{"issue":"1","key":"11248_CR91","doi-asserted-by":"publisher","first-page":"6560","DOI":"10.1038\/s41598-024-56115-0","volume":"14","author":"TPV Nguyen","year":"2024","unstructured":"Nguyen TPV, Yang W, Tang Z, Xia X, Mullens AB, Dean JA, Li Y (2024) Lightweight federated learning for STIS\/HIV prediction. Sci Rep 14(1):6560","journal-title":"Sci Rep"},{"key":"11248_CR92","unstructured":"Noorbakhsh SL, Zhang B, Hong Y, Wang B (2024) Inf2Guard: An Information-Theoretic framework for learning Privacy-Preserving representations against inference attacks. In: 33rd USENIX Security Symposium (USENIX Security 24), pp 2405\u20132422. https:\/\/www.usenix.org\/conference\/usenixsecurity24\/presentation\/noorbakhsh"},{"key":"11248_CR93","doi-asserted-by":"crossref","unstructured":"Ovi PR, Dey E, Roy N, Gangopadhyay A (2023) Mixed quantization enabled federated learning to tackle gradient inversion attacks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 5046\u20135054","DOI":"10.1109\/CVPRW59228.2023.00533"},{"key":"11248_CR94","doi-asserted-by":"crossref","unstructured":"Pizzi K, Boenisch F, Sahin U, B\u00f6ttinger K (2023) Introducing model inversion attacks on automatic speaker recognition. Preprint at arXiv:2301.03206","DOI":"10.21437\/SPSC.2022-3"},{"key":"11248_CR95","doi-asserted-by":"crossref","unstructured":"Pang S, Chen Y, Deng J, Wu J, Bai Y, Xu W (2024) Adversarial for good-defending training data privacy with adversarial attack wisdom. In: 2024 IEEE International Conference on Metaverse Computing, Networking, and Applications (MetaCom), pp. 190\u2013197. IEEE, Piscataway, USA. https:\/\/ieeexplore.ieee.org\/abstract\/document\/10740022\/?casa_token=-lqpCoQvvJMAAAAA:NpuGcvAQS2Z5syj_BpMIuTtIoacQuIOoshd04V06WlNCbDABGvPmTypWaZDW8Wdp9iEFFAoLEw","DOI":"10.1109\/MetaCom62920.2024.00040"},{"key":"11248_CR96","unstructured":"Petrov I, Dimitrov DI, Baader M, M\u00fcller MN, Vechev M (2024) DAGER: Exact gradient inversion for large language models. Preprint at arXiv:2405.15586"},{"key":"11248_CR97","doi-asserted-by":"crossref","unstructured":"Prakash P, Ding J, Li H, Errapotu SM, Pei Q, Pan M (2020) Privacy preserving facial recognition against model inversion attacks. In: GLOBECOM 2020-2020 IEEE Global Communications Conference. IEEE, Piscataway, pp 1\u20136","DOI":"10.1109\/GLOBECOM42002.2020.9322508"},{"issue":"1","key":"11248_CR98","doi-asserted-by":"publisher","first-page":"889","DOI":"10.32604\/cmc.2022.021830","volume":"71","author":"W Pei","year":"2022","unstructured":"Pei W, Li Y, Siuly S, Wen P (2022) A hybrid deep learning scheme for multi-channel sleep stage classification. Comput Mater Continua 71(1):889\u2013905","journal-title":"Comput Mater Continua"},{"key":"11248_CR99","doi-asserted-by":"publisher","unstructured":"Peng X, Liu F, Zhang J, Lan L, Ye J, Liu T, Han B (2022) Bilateral dependency optimization: Defending against model-inversion attacks. In: Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining. ACM, Washington, pp 1358\u20131367. https:\/\/doi.org\/10.1145\/3534678.3539376","DOI":"10.1145\/3534678.3539376"},{"key":"11248_CR100","doi-asserted-by":"publisher","unstructured":"Papadopoulos G, Satsangi Y, Eloul S, Pistoia M (2024) In: Goharian N, Tonellotto N, He Y, Lipani A, McDonald G, Macdonald C, Ounis I (eds.) Absolute Variation Distance: An Inversion Attack Evaluation Metric for Federated Learning. Lecture Notes in Computer Science, vol. 14611. Springer, Cham, pp 243\u2013256. https:\/\/doi.org\/10.1007\/978-3-031-56066-8_20","DOI":"10.1007\/978-3-031-56066-8_20"},{"key":"11248_CR101","doi-asserted-by":"crossref","unstructured":"Palihawadana C, Wiratunga N, Kalutarage H, Wijekoon A (2023) Mitigating gradient inversion attacks in federated learning with frequency transformation. In: European Symposium on Research in Computer Security. Springer, Cham, pp 750\u2013760","DOI":"10.1007\/978-3-031-54129-2_44"},{"key":"11248_CR102","doi-asserted-by":"crossref","unstructured":"Pengcheng L, Yi J, Zhang L (2018) Query-efficient black-box attack by active learning. In: 2018 IEEE International Conference on Data Mining (ICDM). IEEE, Piscataway, pp 1200\u20131205. https:\/\/ieeexplore.ieee.org\/abstract\/document\/8594968\/","DOI":"10.1109\/ICDM.2018.00159"},{"key":"11248_CR103","doi-asserted-by":"crossref","unstructured":"Pan X, Zhang M, Ji S, Yang M (2020) Privacy risks of general-purpose language models. In: 2020 IEEE Symposium on Security and Privacy (SP). IEEE, Piscataway, pp 1314\u20131331","DOI":"10.1109\/SP40000.2020.00095"},{"key":"11248_CR104","doi-asserted-by":"crossref","unstructured":"Qi G, Chen Y, Mao X, Hui B, Li X, Zhang R, Xue H (2023) Model inversion attack via dynamic memory learning. In: Proceedings of the 31st ACM International Conference on Multimedia, pp 5614\u20135622","DOI":"10.1145\/3581783.3612072"},{"key":"11248_CR105","doi-asserted-by":"crossref","unstructured":"Qiu Y, Fang H, Yu H, Chen B, Qiu M, Xia S-T (2024) A closer look at gan priors: Exploiting intermediate features for enhanced model inversion attacks. In: ECCV 2024. https:\/\/www.ecva.net\/papers\/eccv_2024\/papers_ECCV\/papers\/04642.pdf","DOI":"10.1007\/978-3-031-73411-3_7"},{"key":"11248_CR106","doi-asserted-by":"crossref","unstructured":"Qi T, Wang H, Huang Y (2024) Towards the robustness of differentially private federated learning. Proc AAAI Conf Artif Intell 38:19911\u201319919. https:\/\/ojs.aaai.org\/index.php\/AAAI\/article\/view\/29967","DOI":"10.1609\/aaai.v38i18.29967"},{"key":"11248_CR107","doi-asserted-by":"publisher","unstructured":"Qiu Y, Yu H, Fang H, Yu W, Chen B, Wang X, Xia S-T, Xu K (2024) MIBENCH: a comprehensive benchmark for model inversion attack and defense https:\/\/doi.org\/10.48550\/arXiv.2410.05159. arXiv:2410.05159","DOI":"10.48550\/arXiv.2410.05159"},{"key":"11248_CR108","doi-asserted-by":"crossref","unstructured":"Qiu P, Zhang X, Ji S, Fu C, Yang X, Wang T (2024) Hashvfl: Defending against data reconstruction attacks in vertical federated learning. IEEE Transactions on Information Forensics and Security","DOI":"10.1109\/TIFS.2024.3356164"},{"key":"11248_CR109","unstructured":"Ren H, Deng J, Xie X, Ma X, Ma J (2023) Gradient leakage defense with key-lock module for federated learning. Preprint at arXiv:2305.04095"},{"issue":"4","key":"11248_CR110","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3624010","volume":"56","author":"M Rigaki","year":"2023","unstructured":"Rigaki M, Garcia S (2023) A survey of privacy attacks in machine learning. ACM Comput Surv 56(4):1\u201334","journal-title":"ACM Comput Surv"},{"issue":"1","key":"11248_CR111","doi-asserted-by":"publisher","first-page":"10","DOI":"10.1186\/s40708-021-00130-8","volume":"8","author":"JS Ra","year":"2021","unstructured":"Ra JS, Li T, Li Y (2021) A novel spectral entropy-based index for assessing the depth of anaesthesia. Brain Inform 8(1):10. https:\/\/doi.org\/10.1186\/s40708-021-00130-8","journal-title":"Brain Inform"},{"issue":"1","key":"11248_CR112","doi-asserted-by":"publisher","first-page":"349","DOI":"10.1007\/s10586-022-03596-1","volume":"26","author":"S Shin","year":"2023","unstructured":"Shin S, Boyapati M, Suo K, Kang K, Son J (2023) An empirical analysis of image augmentation against model inversion attack in federated learning. Clust Comput 26(1):349\u2013366","journal-title":"Clust Comput"},{"key":"11248_CR113","doi-asserted-by":"crossref","unstructured":"Slokom M, Wolf P-P, Larson M (2023) Exploring privacy-preserving techniques on synthetic data as a defense against model inversion attacks. In: International Conference on Information Security. Springer, Cham, pp 3\u201323","DOI":"10.1007\/978-3-031-49187-0_1"},{"key":"11248_CR114","unstructured":"Struppek L, Hintersdorf D, Correia ADA, Adler A, Kersting K (2022) Plug & play attacks: Towards robust and flexible model inversion attacks. Preprint at arXiv:2201.12179"},{"key":"11248_CR115","unstructured":"Struppek L, Hintersdorf D, Kersting K (2023) Be careful what you smooth for: Label smoothing can be a privacy shield but also a catalyst for model inversion attacks. Preprint at arXiv:2310.06549"},{"key":"11248_CR116","unstructured":"Shi Y, Kotevska O, Reshniak V, Singh A, Raskar R (2024) Dealing doubt: Unveiling threat models in gradient inversion attacks under federated learning, a survey and taxonomy. Preprint at arXiv:2405.10376"},{"key":"11248_CR117","doi-asserted-by":"publisher","unstructured":"Shu Y, Li S, Dong T, Meng Y, Zhu H (2025) Model inversion in split learning for personalized llms: New insights from information bottleneck theory https:\/\/doi.org\/10.48550\/arXiv.2501.05965. arXiv:2501.05965","DOI":"10.48550\/arXiv.2501.05965"},{"key":"11248_CR118","doi-asserted-by":"crossref","unstructured":"Sun J, Li A, Wang B, Yang H, Li H, Chen Y (2021) Soteria: Provable defense against privacy leakage in federated learning from representation perspective. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 9311\u20139319. http:\/\/openaccess.thecvf.com\/content\/CVPR2021\/html\/Sun_Soteria_Provable_Defense_Against_Privacy_Leakage_in_Federated_Learning_From_CVPR_2021_paper.html","DOI":"10.1109\/CVPR46437.2021.00919"},{"key":"11248_CR119","doi-asserted-by":"crossref","unstructured":"Scheliga D, M\u00e4der P, Seeland M (2022) Precode-a generic model extension to prevent deep gradient leakage. In: Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision, pp 1849\u20131858. http:\/\/openaccess.thecvf.com\/content\/WACV2022\/html\/Scheliga_PRECODE_-_A_Generic_Model_Extension_To_Prevent_Deep_Gradient_WACV_2022_paper.html","DOI":"10.1109\/WACV51458.2022.00366"},{"key":"11248_CR120","doi-asserted-by":"crossref","unstructured":"Scheliga D, M\u00e4der P, Seeland M (2023) Dropout is not all you need to prevent gradient leakage. Proc AAAI Conf Artif Intell 37:9733\u20139741. https:\/\/ojs.aaai.org\/index.php\/AAAI\/article\/view\/26163","DOI":"10.1609\/aaai.v37i8.26163"},{"key":"11248_CR121","doi-asserted-by":"crossref","unstructured":"Singh S, Sharma PK, Moon SY, Park JH (2024) Advanced lightweight encryption algorithms for IoT devices: survey, challenges and solutions. J Ambient Intell Human Comput 1\u201318","DOI":"10.1007\/s12652-017-0494-4"},{"key":"11248_CR122","doi-asserted-by":"crossref","unstructured":"Shokri R, Stronati M, Song C, Shmatikov V (2017) Membership inference attacks against machine learning models. In: 2017 IEEE Symposium on Security and Privacy (SP). IEEE, Piscataway, pp 3\u201318. https:\/\/ieeexplore.ieee.org\/abstract\/document\/7958568\/","DOI":"10.1109\/SP.2017.41"},{"key":"11248_CR123","doi-asserted-by":"crossref","unstructured":"Sen J, Waghela H, Rakshit S (2024) Privacy in federated learning. Preprint at arXiv:2408.08904","DOI":"10.5772\/intechopen.1006677"},{"key":"11248_CR124","doi-asserted-by":"crossref","unstructured":"Tian Z, Cui L, Zhang C, Tan S, Yu S, Tian Y (2023) The role of class information in model inversion attacks against image deep learning classifiers. IEEE Transactions on Dependable and Secure Computing","DOI":"10.1109\/TDSC.2023.3306748"},{"key":"11248_CR125","unstructured":"Thapa B (2024) Assessing the viability of privacy, ethics, and utility in machine learning experiments via analysis of structured data. Phd thesis, Marymount University"},{"key":"11248_CR126","unstructured":"Titcombe T, Hall AJ, Papadopoulos P, Romanini D (2021) Practical defences against model inversion attacks for split neural networks. Preprint at arXiv:2104.05743"},{"key":"11248_CR127","doi-asserted-by":"publisher","unstructured":"Tran V-H, Nguyen N-B, Mai ST, Vandierendonck H, Cheung N-m (2024) Defending against model inversion attacks via random erasing. https:\/\/doi.org\/10.48550\/arXiv.2409.01062. arXiv:2409.01062","DOI":"10.48550\/arXiv.2409.01062"},{"issue":"1","key":"11248_CR128","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1038\/sdata.2018.161","volume":"5","author":"P Tschandl","year":"2018","unstructured":"Tschandl P, Rosendahl C, Kittler H (2018) The ham10000 dataset, a large collection of multi-source dermatoscopic images of common pigmented skin lesions. Sci Data 5(1):1\u20139","journal-title":"Sci Data"},{"key":"11248_CR129","doi-asserted-by":"publisher","first-page":"205520762412984","DOI":"10.1177\/20552076241298425","volume":"10","author":"Z Tang","year":"2024","unstructured":"Tang Z, Van Nguyen TP, Yang W, Xia X, Chen H, Mullens AB, Dean JA, Osborne SR, Li Y (2024) High security and privacy protection model for STI\/HIV risk prediction. Digit Health 10:20552076241298424. https:\/\/doi.org\/10.1177\/20552076241298425","journal-title":"Digit Health"},{"key":"11248_CR130","doi-asserted-by":"publisher","first-page":"69686","DOI":"10.1109\/ACCESS.2023.3286696","volume":"11","author":"H Ullah","year":"2023","unstructured":"Ullah H, Manickam S, Obaidat M, Laghari SUA, Uddin M (2023) Exploring the potential of metaverse technology in healthcare: applications, challenges, and future directions. IEEE Access 11:69686\u201369707","journal-title":"IEEE Access"},{"key":"11248_CR131","unstructured":"Vero M, Balunovi\u0107 M, Dimitrov DI, Vechev M (2023) Tableak: tabular data leakage in federated learning. In: Proceedings of the 40th International Conference on Machine Learning. ICML\u201923, vol. 202. JMLR.org, Honolulu, pp 35051\u201335083"},{"issue":"2133","key":"11248_CR132","doi-asserted-by":"publisher","first-page":"20180083","DOI":"10.1098\/rsta.2018.0083","volume":"376","author":"M Veale","year":"2018","unstructured":"Veale M, Binns R, Edwards L (2018) Algorithms that remember: model inversion attacks and data protection law. Philosoph Transact R Soc A 376(2133):20180083. https:\/\/doi.org\/10.1098\/rsta.2018.0083","journal-title":"Philosoph Transact R Soc A"},{"key":"11248_CR133","unstructured":"Virmaux A, Scaman K (2018) Lipschitz regularity of deep neural networks: analysis and efficient estimation. Adv Neural Inform Process Syst 31"},{"key":"11248_CR134","unstructured":"Wu D, Bai J, Song Y, Chen J, Zhou W, Xiang Y, Sajjanhar A (2024) Fedinverse: Evaluating privacy leakage in federated learning. In: The Twelfth International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=nTNgkEIfeb"},{"issue":"4","key":"11248_CR135","doi-asserted-by":"publisher","first-page":"600","DOI":"10.1109\/TIP.2003.819861","volume":"13","author":"Z Wang","year":"2004","unstructured":"Wang Z, Bovik AC, Sheikh HR, Simoncelli EP (2004) Image quality assessment: from error visibility to structural similarity. IEEE Trans Image Process 13(4):600\u2013612","journal-title":"IEEE Trans Image Process"},{"key":"11248_CR136","unstructured":"Wu R, Chen X, Guo C, Weinberger KQ (2023) Learning to invert: Simple adaptive attacks for gradient inversion in federated learning. In: Uncertainty in Artificial Intelligence, pp 2293\u20132303. PMLR, USA"},{"key":"11248_CR137","doi-asserted-by":"crossref","unstructured":"Wan G, Du H, Yuan X, Yang J, Chen M, Xu J (2023) Enhancing privacy preservation in federated learning via learning rate perturbation. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp 4772\u20134781. http:\/\/openaccess.thecvf.com\/content\/ICCV2023\/html\/Wan_Enhancing_Privacy_Preservation_in_Federated_Learning_via_Learning_Rate_Perturbation_ICCV_2023_paper.html","DOI":"10.1109\/ICCV51070.2023.00440"},{"key":"11248_CR138","first-page":"9706","volume":"34","author":"K-C Wang","year":"2021","unstructured":"Wang K-C, Fu Y, Li K, Khisti A, Zemel R, Makhzani A (2021) Variational model inversion attacks. Adv Neural Inf Process Syst 34:9706\u20139719","journal-title":"Adv Neural Inf Process Syst"},{"key":"11248_CR139","doi-asserted-by":"crossref","unstructured":"Wang Y, Guo S, Deng Y, Zhang H, Fang Y (2024) Privacy-preserving task-oriented semantic communications against model inversion attacks. IEEE Transactions on Wireless Communications","DOI":"10.1109\/TWC.2024.3369170"},{"key":"11248_CR140","doi-asserted-by":"crossref","unstructured":"Wang J, Guo S, Xie X, Qi H (2022) Protect privacy from gradient leakage attack in federated learning. In: IEEE INFOCOM 2022-IEEE Conference on Computer Communications. IEEE, Piscataway, pp 580\u2013589. https:\/\/ieeexplore.ieee.org\/abstract\/document\/9796841\/","DOI":"10.1109\/INFOCOM48880.2022.9796841"},{"key":"11248_CR141","doi-asserted-by":"crossref","unstructured":"Wang F, Hugh E, Li B (2024) More than enough is too much: Adaptive defenses against gradient leakage in production federated learning. IEEE\/ACM Transactions on Networking","DOI":"10.1109\/TNET.2024.3377655"},{"key":"11248_CR142","doi-asserted-by":"crossref","unstructured":"Wu J, Hayat M, Zhou M, Harandi M (2024) Concealing sensitive samples against gradient leakage in federated learning. Proc AAAI Conf Artif Intell 38:21717\u201321725. https:\/\/ojs.aaai.org\/index.php\/AAAI\/article\/view\/30171","DOI":"10.1609\/aaai.v38i19.30171"},{"key":"11248_CR143","doi-asserted-by":"crossref","unstructured":"Wang S, Ji Z, Xiang L, Zhang H, Wang X, Zhou C, Li B (2024) Crafter: Facial feature crafting against inversion-based identity theft on deep models. Preprint at arXiv:2401.07205","DOI":"10.14722\/ndss.2024.23326"},{"key":"11248_CR144","doi-asserted-by":"crossref","unstructured":"Wang Q, Kurz D (2022) Reconstructing training data from diverse ml models by ensemble inversion. In: Proceedings of the IEEE\/CVF Winter Conference on Applications of Computer Vision, pp 2909\u20132917","DOI":"10.1109\/WACV51458.2022.00392"},{"key":"11248_CR145","unstructured":"Wang Z, Lee J, Lei Q (2023) Reconstructing training data from model gradient, provably. In: International Conference on Artificial Intelligence and Statistics. PMLR, USA, pp 6595\u20136612. https:\/\/proceedings.mlr.press\/v206\/wang23g.html"},{"key":"11248_CR146","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2024.102620","volume":"113","author":"L Wu","year":"2025","unstructured":"Wu L, Liu Z, Pu B, Wei K, Cao H, Yao S (2025) DGGI: Deep generative gradient inversion with diffusion model. Inform Fusion 113:102620","journal-title":"Inform Fusion"},{"key":"11248_CR147","doi-asserted-by":"publisher","unstructured":"Wei S, Li Y, Yang W (2023) In: Li, Y, Huang, Z, Sharma, M, Chen, L, Zhou, R. (eds.) An Adaptive Feature Fusion Network for Alzheimer\u2019s Disease Prediction. Lecture Notes in Computer Science, vol 14305. Springer, Singapore, pp 271\u2013282. https:\/\/doi.org\/10.1007\/978-981-99-7108-4_23","DOI":"10.1007\/978-981-99-7108-4_23"},{"key":"11248_CR148","doi-asserted-by":"crossref","unstructured":"Wang X, Peng Y, Lu L, Lu Z, Bagheri M, Summers RM (2017) CHESTX-ray8: Hospital-scale chest X-ray database and benchmarks on weakly-supervised classification and localization of common thorax diseases. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 2097\u20132106. http:\/\/openaccess.thecvf.com\/content_cvpr_2017\/html\/Wang_ChestX-ray8_Hospital-Scale_Chest_CVPR_2017_paper.html","DOI":"10.1109\/CVPR.2017.369"},{"key":"11248_CR149","unstructured":"Wang Z, Simoncelli EP, Bovik AC (2003) Multiscale structural similarity for image quality assessment. In: The Thrity-Seventh Asilomar Conference on Signals, Systems & Computers, 2003, vol 2. IEEE, Piscataway, pp 1398\u20131402. https:\/\/ieeexplore.ieee.org\/abstract\/document\/1292216\/"},{"key":"11248_CR150","unstructured":"Wang Y, Si C, Wu X (2015) Regression model fitting under differential privacy and model inversion attack. In: Twenty-fourth International Joint Conference on Artificial Intelligence. https:\/\/www.ijcai.org\/Proceedings\/15\/Papers\/146.pdf"},{"key":"11248_CR151","unstructured":"Wan Y, Xu H, Liu X, Ren J, Fan W, Tang J (2022) Defense against gradient leakage attacks via learning to obscure data. Preprint at arXiv:2206.00769"},{"key":"11248_CR152","unstructured":"Wen J, Yiu S-M, Hui LC (2021) Defending against model inversion attack by adversarial examples. In: 2021 IEEE International Conference on Cyber Security and Resilience (CSR). IEEE, Piscataway, pp 551\u2013556. https:\/\/ieeexplore.ieee.org\/abstract\/document\/9527945\/?casa_token=a3XfNJBs85QAAAAA:ByY_p7v1JcKNENgQdU3x0a0xGn1B8EV8zbPKYGe7ad5QhkgOrhd1vaIHBagqY6DJ-T9ijJdmaQ"},{"key":"11248_CR153","first-page":"11666","volume":"35","author":"T Wang","year":"2021","unstructured":"Wang T, Zhang Y, Jia R (2021) Improving robustness to model inversion attacks via mutual information regularization. Proc AAAI Conf Artif Intell 35:11666\u201311673","journal-title":"Proc AAAI Conf Artif Intell"},{"key":"11248_CR154","doi-asserted-by":"crossref","unstructured":"Xu J, Hong C, Huang J, Chen LY, Decouchant J (2022) Agic: Approximate gradient inversion attack on federated learning. In: 2022 41st International Symposium on Reliable Distributed Systems (SRDS). IEEE, Piscataway, pp 12\u201322","DOI":"10.1109\/SRDS55811.2022.00012"},{"key":"11248_CR155","doi-asserted-by":"crossref","unstructured":"Xue L, Hu S, Zhao R, Zhang LY, Hu S, Sun L, Yao D (2024) Revisiting gradient pruning: A dual realization for defending against gradient attacks. Proc AAAI Conf Artif Intell 38:6404\u20136412. https:\/\/ojs.aaai.org\/index.php\/AAAI\/article\/view\/28460","DOI":"10.1609\/aaai.v38i6.28460"},{"key":"11248_CR156","doi-asserted-by":"publisher","unstructured":"Xiao D, Li J, Li M (2024) In: Luo B, Cheng L, Wu Z-G, Li H, Li C (eds.) Privacy-Preserving Federated Compressed Learning Against Data Reconstruction Attacks Based on Secure Data. Communications in Computer and Information Science, vol 1969. Springer, Singapore, pp 325\u2013339.https:\/\/doi.org\/10.1007\/978-981-99-8184-7_25","DOI":"10.1007\/978-981-99-8184-7_25"},{"key":"11248_CR157","doi-asserted-by":"publisher","unstructured":"Xiao H, Rasul K, Vollgraf R (2017) Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms https:\/\/doi.org\/10.48550\/arXiv.1708.07747. arXiv:1708.07747","DOI":"10.48550\/arXiv.1708.07747"},{"key":"11248_CR158","doi-asserted-by":"publisher","unstructured":"Xu Y, Zhang S, Ding Y, Wang Z (2024) Secure distributed machine learning client selection algorithm based on privacy leakage weight. In: 2024 5th International Seminar on Artificial Intelligence, Networking and Information Technology (AINIT), pp 790\u2013794. https:\/\/doi.org\/10.1109\/AINIT61980.2024.10581838. https:\/\/ieeexplore.ieee.org\/abstract\/document\/10581838","DOI":"10.1109\/AINIT61980.2024.10581838"},{"key":"11248_CR159","doi-asserted-by":"crossref","unstructured":"Yuan X, Chen K, Zhang J, Zhang W, Yu N, Zhang Y (2023) Pseudo label-guided model inversion attack via conditional generative adversarial network. Proc AAAI Conf Artif Intell 37:3349\u20133357. https:\/\/ojs.aaai.org\/index.php\/AAAI\/article\/view\/25442","DOI":"10.1609\/aaai.v37i3.25442"},{"key":"11248_CR160","unstructured":"Yu W, Fang H, Chen B, Sui X, Chen C, Wu H, Xia S-T, Xu, K (2024) GI-NAS: Boosting gradient inversion attacks through adaptive neural architecture search. Preprint at arXiv:2405.20725"},{"key":"11248_CR161","doi-asserted-by":"publisher","unstructured":"Yang X, Feng Y, Fang W, Shao J, Tang X, Xia S-T, Lu R (2022) An accuracy-lossless perturbation method for defending privacy attacks in federated learning. In: Proceedings of the ACM Web Conference 2022, pp 732\u2013742. ACM, Virtual Event, Lyon France. https:\/\/doi.org\/10.1145\/3485447.3512233","DOI":"10.1145\/3485447.3512233"},{"key":"11248_CR162","doi-asserted-by":"crossref","unstructured":"Yang H, Ge M, Xue D, Xiang K, Li H, Lu R (2023) Gradient leakage attacks in federated learning: Research frontiers, taxonomy and future directions. IEEE Network","DOI":"10.1109\/MNET.001.2300140"},{"key":"11248_CR163","doi-asserted-by":"crossref","unstructured":"Yang C, Hang S, Ding Y, Li C, Liang H, Liu Z (2024) Gradient leakage defense in federated learning using gradient perturbation-based dynamic clipping. In: 2024 IEEE International Conference on Web Services (ICWS), pp 178\u2013187. IEEE, Piscataway, USA. https:\/\/ieeexplore.ieee.org\/abstract\/document\/10707585\/","DOI":"10.1109\/ICWS62655.2024.00039"},{"issue":"3","key":"11248_CR164","doi-asserted-by":"publisher","first-page":"1437","DOI":"10.1109\/TDSC.2023.3285071","volume":"21","author":"Z Ye","year":"2023","unstructured":"Ye Z, Luo W, Naseem ML, Yang X, Shi Y, Jia Y (2023) C2FMI: Corse-to-fine black-box model inversion attack. IEEE Trans Dependable Secure Comput 21(3):1437\u20131450","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"11248_CR165","doi-asserted-by":"crossref","unstructured":"Ye Z, Luo W, Zhou Q, Zhu Z, Shi Y, Jia Y (2024) Gradient inversion attacks: Impact factors analyses and privacy enhancement. IEEE Transactions on Pattern Analysis and Machine Intelligence","DOI":"10.1109\/TPAMI.2024.3430533"},{"key":"11248_CR166","first-page":"19983","volume":"38","author":"Z Ye","year":"2024","unstructured":"Ye Z, Luo W, Zhou Q, Tang Y (2024) High-fidelity gradient inversion in distributed learning. Proc AAAI Conf Artif Intell 38:19983\u201319991","journal-title":"Proc AAAI Conf Artif Intell"},{"key":"11248_CR167","doi-asserted-by":"crossref","unstructured":"Yin H, Molchanov P, Alvarez JM, Li Z, Mallya A, Hoiem D, Jha NK, Kautz J (2020) Dreaming to distill: Data-free knowledge transfer via deepinversion. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 8715\u20138724. http:\/\/openaccess.thecvf.com\/content_CVPR_2020\/html\/Yin_Dreaming_to_Distill_Data-Free_Knowledge_Transfer_via_DeepInversion_CVPR_2020_paper.html","DOI":"10.1109\/CVPR42600.2020.00874"},{"key":"11248_CR168","doi-asserted-by":"crossref","unstructured":"Yin H, Mallya A, Vahdat A, Alvarez JM, Kautz J, Molchanov P (2021) See through gradients: Image batch recovery via gradinversion. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 16337\u201316346. http:\/\/openaccess.thecvf.com\/content\/CVPR2021\/html\/Yin_See_Through_Gradients_Image_Batch_Recovery_via_GradInversion_CVPR_2021_paper.html","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"11248_CR169","unstructured":"Yoshimura S, Nakamura K, Nitta N, Babaguchi N (2021) Model inversion attack against a face recognition system in a black-box setting. In: 2021 Asia-Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC). IEEE, Piscataway, pp 1800\u20131807"},{"key":"11248_CR170","unstructured":"Yu H, Qiu Y, Fang H, Chen B, Yu S, Wang B, Xia S-T, Xu K (2024) Calor: Towards comprehensive model inversion defense. Preprint at arXiv:2410.05814"},{"issue":"7","key":"11248_CR171","doi-asserted-by":"publisher","first-page":"3566","DOI":"10.3390\/s23073566","volume":"23","author":"W Yang","year":"2023","unstructured":"Yang W, Wang S, Cui H, Tang Z, Li Y (2023) A review of homomorphic encryption for privacy-preserving biometrics. Sensors 23(7):3566","journal-title":"Sensors"},{"issue":"13","key":"11248_CR172","doi-asserted-by":"publisher","first-page":"2985","DOI":"10.3390\/s19132985","volume":"19","author":"W Yang","year":"2019","unstructured":"Yang W, Wang S, Hu J, Ibrahim A, Zheng G, Macedo M, Johnstone M, Valli C (2019) A cancelable iris- and steganography-based user authentication system for the internet of things. Sensors 19(13):2985. https:\/\/doi.org\/10.3390\/s19132985","journal-title":"Sensors"},{"issue":"2","key":"11248_CR173","doi-asserted-by":"publisher","first-page":"141","DOI":"10.3390\/sym11020141","volume":"11","author":"W Yang","year":"2019","unstructured":"Yang W, Wang S, Hu J, Zheng G, Valli C (2019) Security and accuracy of fingerprint-based biometrics: a review. Symmetry 11(2):141. https:\/\/doi.org\/10.3390\/sym11020141","journal-title":"Symmetry"},{"key":"11248_CR174","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102583","volume":"114","author":"W Yang","year":"2022","unstructured":"Yang W, Wang S, Kang JJ, Johnstone MN, Bedari A (2022) A linear convolution-based cancelable fingerprint biometric authentication system. Comput Security 114:102583","journal-title":"Comput Security"},{"key":"11248_CR175","doi-asserted-by":"publisher","unstructured":"Yuan Z, Wu F, Long Y, Xiao C, Li B (2022) In: Avidan, S, Brostow, G, Ciss\u00e9, M, Farinella, G.M, Hassner, T. (eds.) SecretGen: Privacy Recovery on Pre-trained Models via Distribution Discrimination. Lecture Notes in Computer Science, vol 13665. Springer, Cham, pp 139\u2013155. https:\/\/doi.org\/10.1007\/978-3-031-20065-6_9","DOI":"10.1007\/978-3-031-20065-6_9"},{"issue":"4","key":"11248_CR176","doi-asserted-by":"publisher","first-page":"919","DOI":"10.1007\/s10207-023-00670-6","volume":"22","author":"Z Yang","year":"2023","unstructured":"Yang Z, Yang S, Huang Y, Mart\u00ednez J-F, L\u00f3pez L, Chen Y (2023) AAIA: an efficient aggregation scheme against inverting attack for federated learning. Int J Inf Secur 22(4):919\u2013930","journal-title":"Int J Inf Secur"},{"key":"11248_CR177","doi-asserted-by":"crossref","unstructured":"Zhang K, Cheng S, Shen G, Ribeiro B, An S, Chen P-Y, Zhang X, Li N (2025) Censor: Defense against gradient inversion via orthogonal subspace Bayesian sampling. NDSS 2025","DOI":"10.14722\/ndss.2025.230915"},{"key":"11248_CR178","doi-asserted-by":"crossref","unstructured":"Zhang R, Guo S, Wang J, Xie X, Tao D (2022) A survey on gradient inversion: Attacks, defenses and future directions. In: Proceedings of the Thirty-First International Joint Conference on Artificial Intelligence (IJCAI-22). https:\/\/www.ijcai.org\/proceedings\/2022\/0791.pdf","DOI":"10.24963\/ijcai.2022\/791"},{"key":"11248_CR179","unstructured":"Zhang R, Hidano S, Koushanfar F (2022) Text revealer: Private text reconstruction via model inversion attacks against transformers. Preprint at arXiv:2209.10505"},{"key":"11248_CR180","doi-asserted-by":"crossref","unstructured":"Zhu H, Huang L, Xie Z (2024) GGI: Generative gradient inversion attack in federated learning. In: 2024 6th International Conference on Data-driven Optimization of Complex Systems (DOCS). IEEE, Piscataway, pp 379\u2013384","DOI":"10.1109\/DOCS63458.2024.10704504"},{"key":"11248_CR181","unstructured":"Zhu H, Huang L, Xie Z (2024) Privacy attack in federated learning is not easy: an experimental study. Preprint at arXiv:2409.19301"},{"key":"11248_CR182","doi-asserted-by":"publisher","DOI":"10.1016\/j.array.2024.100347","volume":"22","author":"J Zhang","year":"2024","unstructured":"Zhang J, Hou C, Yang X, Yang X, Yang W, Cui H (2024) Advancing face detection efficiency: utilizing classification networks for lowering false positive incidences. Array 22:100347","journal-title":"Array"},{"key":"11248_CR183","doi-asserted-by":"crossref","unstructured":"Zhang R, Isola P, Efros AA, Shechtman E, Wang O (2018) The unreasonable effectiveness of deep features as a perceptual metric. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp 586\u2013595. http:\/\/openaccess.thecvf.com\/content_cvpr_2018\/html\/Zhang_The_Unreasonable_Effectiveness_CVPR_2018_paper.html","DOI":"10.1109\/CVPR.2018.00068"},{"key":"11248_CR184","doi-asserted-by":"crossref","unstructured":"Zhang Y, Jia R, Pei H, Wang W, Li B, Song D (2020) The secret revealer: Generative model-inversion attacks against deep neural networks. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp 253\u2013261. http:\/\/openaccess.thecvf.com\/content_CVPR_2020\/html\/Zhang_The_Secret_Revealer_Generative_Model-Inversion_Attacks_Against_Deep_Neural_Networks_CVPR_2020_paper.html","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"11248_CR185","unstructured":"Zhu L, Liu Z, Han S (2019) Deep leakage from gradients. Adv Neural Inform Process Syst 32"},{"issue":"9","key":"11248_CR186","doi-asserted-by":"publisher","first-page":"8729","DOI":"10.1109\/TKDE.2022.3207915","volume":"35","author":"Z Zhang","year":"2022","unstructured":"Zhang Z, Liu Q, Huang Z, Wang H, Lee C-K, Chen E (2022) Model inversion attacks against graph neural networks. IEEE Trans Knowl Data Eng 35(9):8729\u20138741","journal-title":"IEEE Trans Knowl Data Eng"},{"key":"11248_CR187","unstructured":"Zhao B, Mopuri KR, Bilen H (2020) IDLG: Improved deep leakage from gradients. Preprint at arXiv:2001.02610"},{"key":"11248_CR188","doi-asserted-by":"crossref","unstructured":"Zhang Q, Ma J, Xiao Y, Lou J, Xiong L (2020) Broadening differential privacy for deep learning against model inversion attacks. In: 2020 IEEE International Conference on Big Data (Big Data). IEEE, Piscataway, pp 1061\u20131070","DOI":"10.1109\/BigData50022.2020.9378274"},{"key":"11248_CR189","doi-asserted-by":"crossref","unstructured":"Zhu Z, Shi Y, Luo J, Wang F, Peng C, Fan P, Letaief KB (2023) Fedlp: Layer-wise pruning mechanism for communication-computation efficient federated learning. In: ICC 2023-IEEE International Conference on Communications. IEEE, Piscataway, pp 1250\u20131255. https:\/\/ieeexplore.ieee.org\/abstract\/document\/10278563\/?casa_token=U4r-_Nyvfv8AAAAA:TsCOgSkVhZ75KIPlbOfBeZvMEpF1xBApvMdZLR56Sq9KUCxeKg_idHP9Z0UahTo-cCO_aimABA","DOI":"10.1109\/ICC45041.2023.10278563"},{"key":"11248_CR190","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.103039","volume":"125","author":"Z Zhang","year":"2023","unstructured":"Zhang Z, Tianqing Z, Ren W, Xiong P, Choo K-KR (2023) Preserving data privacy in federated learning through large gradient pruning. Comput Security 125:103039","journal-title":"Comput Security"},{"key":"11248_CR191","doi-asserted-by":"crossref","unstructured":"Zhang X, Wei X-Y, Wu J, Zhang T, Zhang Z, Lei Z, Li Q (2024) Compositional inversion for stable diffusion models. Proc AAAI Conf Artif Intell 38:7350\u20137358. https:\/\/ojs.aaai.org\/index.php\/AAAI\/article\/view\/28565","DOI":"10.1609\/aaai.v38i7.28565"},{"issue":"8","key":"11248_CR192","doi-asserted-by":"publisher","first-page":"2378","DOI":"10.1109\/TIP.2011.2109730","volume":"20","author":"L Zhang","year":"2011","unstructured":"Zhang L, Zhang L, Mou X, Zhang D (2011) FSIM: a feature similarity index for image quality assessment. IEEE Trans Image Process 20(8):2378\u20132386","journal-title":"IEEE Trans Image Process"},{"key":"11248_CR193","doi-asserted-by":"crossref","unstructured":"Zhao X, Zhang W, Xiao X, Lim B (2021) Exploiting explanations for model inversion attacks. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp 682\u2013692. http:\/\/openaccess.thecvf.com\/content\/ICCV2021\/html\/Zhao_Exploiting_Explanations_for_Model_Inversion_Attacks_ICCV_2021_paper.html","DOI":"10.1109\/ICCV48922.2021.00072"},{"key":"11248_CR194","doi-asserted-by":"crossref","unstructured":"Zhou S, Zhu T, Ye D, Zhou W, Zhao W (2024) Inversion-guided defense: Detecting model stealing attacks by output inverting. IEEE Transactions on Information Forensics and Security","DOI":"10.1109\/TIFS.2024.3376190"},{"key":"11248_CR195","doi-asserted-by":"publisher","unstructured":"Zhou Z, Zhu J, Yu F, Li X, Peng X, Liu T, Han B (2024) Model inversion attacks: A survey of approaches and countermeasures. https:\/\/doi.org\/10.48550\/arXiv.2411.10023. arXiv:2411.10023","DOI":"10.48550\/arXiv.2411.10023"}],"container-title":["Artificial Intelligence Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-025-11248-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10462-025-11248-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-025-11248-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,23]],"date-time":"2025-06-23T10:36:39Z","timestamp":1750674999000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10462-025-11248-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,13]]},"references-count":195,"journal-issue":{"issue":"8","published-online":{"date-parts":[[2025,8]]}},"alternative-id":["11248"],"URL":"https:\/\/doi.org\/10.1007\/s10462-025-11248-0","relation":{},"ISSN":["1573-7462"],"issn-type":[{"value":"1573-7462","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5,13]]},"assertion":[{"value":"25 April 2025","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 May 2025","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"242"}}