{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T05:01:13Z","timestamp":1785474073297,"version":"3.56.0"},"reference-count":37,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T00:00:00Z","timestamp":1782864000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,7]]},"DOI":"10.1109\/eurosp68448.2026.00045","type":"proceedings-article","created":{"date-parts":[[2026,7,30]],"date-time":"2026-07-30T19:09:54Z","timestamp":1785438594000},"page":"592-607","source":"Crossref","is-referenced-by-count":0,"title":["GDBR: Label Recovery Attack Against Partial Gradient Encryption in Federated Learning"],"prefix":"10.1109","author":[{"given":"Rui","family":"Zhang","sequence":"first","affiliation":[{"name":"The University of Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ka-Ho","family":"Chow","sequence":"additional","affiliation":[{"name":"The University of Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Federated learning: Strategies for improving communication efficiency","volume-title":"NeurIPS Workshop on Private Multi-Party Machine Learning (PMPML)","author":"Kone\u010dn\u1ef3"},{"key":"ref2","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (AISTATS)","author":"McMahan"},{"key":"ref3","first-page":"374","article-title":"Towards federated learning at scale: System design","volume-title":"Proceedings of the 2nd Machine Learning and Systems (MLSys)","author":"Bonawitz"},{"key":"ref4","first-page":"545","article-title":"A framework for evaluating gradient leakage attacks in federated learning","volume-title":"Proceedings of the 25th European Symposium on Research in Computer Security (ESORICS)","author":"Wei"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/791"},{"key":"ref6","article-title":"iDLG: Improved deep leakage from gradients","author":"Zhao","year":"2020"},{"key":"ref7","first-page":"1727","article-title":"Revealing and protecting labels in distributed training","volume-title":"Proceedings of the 35th Conference on Neural Information Processing Systems (NeurIPS)","author":"Dang"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"ref9","article-title":"Towards general deep leakage in federated learning","volume-title":"AAAI Workshop on Trustable, Verifiable and Auditable Federated Learning (FL-AAAI-22)","author":"Geng"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2022-0043"},{"key":"ref11","article-title":"Instancewise batch label restoration via gradients in federated learning","volume-title":"Proceedings of the 11th International Conference on Learning Representations (ICLR)","author":"Ma"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2023.120068"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1002\/aisy.202400836"},{"key":"ref14","first-page":"493","article-title":"BatchCrypt: Efficient homomorphic encryption for cross-silo federated learning","volume-title":"2020 USENIX annual technical conference (USENIX ATC)","author":"Zhang"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.3390\/fi13040094"},{"key":"ref16","article-title":"Deep leakage from gradients","author":"Zhu","year":"2019","journal-title":"Advances in Neural Information Processing Systems (NeurIPS)"},{"key":"ref17","first-page":"16937","article-title":"Inverting gradients - how easy is it to break privacy in federated learning?","volume-title":"Proceedings of the 34th Conference on Neural Information Processing Systems (NeurIPS)","author":"Geiping"},{"key":"ref18","article-title":"R-GAP: Recursive gradient attack on privacy","volume-title":"Proceedings of the 9th International Conference on Learning Representations (ICLR)","author":"Zhu"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.52202\/068431-0590"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.52202\/068431-0555"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP43922.2022.9746443"},{"key":"ref22","article-title":"FedML-HE: An efficient homomorphic-encryption-based privacy-preserving federated learning system","author":"Jin","year":"2023"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3392424"},{"key":"ref24","article-title":"SHE-LoRA: Selective homomorphic encryption for federated tuning with heterogeneous lora","author":"Liu","year":"2025"},{"key":"ref25","article-title":"SenseCrypt: Sensitivity-guided selective homomorphic encryption for joint federated learning in cross-device scenarios","author":"Li","year":"2025"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.2118\/18761-MS"},{"key":"ref28","article-title":"Learning multiple layers of features from tiny images","volume-title":"Technical Report","author":"Krizhevsky","year":"2009"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.21236\/ada164453"},{"key":"ref31","doi-asserted-by":"crossref","DOI":"10.1145\/3065386","article-title":"ImageNet classification with deep convolutional neural networks","volume-title":"Proceedings of the 26th Conference on Neural Information Processing Systems (NeurIPS)","author":"Krizhevsky"},{"key":"ref32","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref34","article-title":"An image is worth 16x16 words: Transformers for image recognition at scale","volume-title":"Proceedings of the 9th International Conference on Learning Representations (ICLR)","author":"Dosovitskiy"},{"key":"ref35","article-title":"PyTorch: An imperative style, high-performance deep learning library","volume-title":"Proceedings of the 33rd Conference on Neural Information Processing Systems (NeurIPS)","author":"Paszke"},{"key":"ref36","article-title":"Posterior probability-based label recovery attack in federated learning","volume-title":"ICLR Workshop on Privacy Regulation and Protection in Machine Learning (PML)","author":"Zhang"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.123"}],"event":{"name":"2026 IEEE 11th European Symposium on Security and Privacy (EuroS&P)","location":"Lisbon, Portugal","start":{"date-parts":[[2026,7,6]]},"end":{"date-parts":[[2026,7,10]]}},"container-title":["2026 IEEE 11th European Symposium on Security and Privacy (EuroS&amp;P)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11624144\/11623655\/11624281.pdf?arnumber=11624281","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,31]],"date-time":"2026-07-31T04:53:33Z","timestamp":1785473613000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11624281\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7]]},"references-count":37,"URL":"https:\/\/doi.org\/10.1109\/eurosp68448.2026.00045","relation":{},"subject":[],"published":{"date-parts":[[2026,7]]}}}