{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T17:45:28Z","timestamp":1784828728289,"version":"3.55.0"},"reference-count":100,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"4","license":[{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"ARC DECRA","award":["DE210101458"],"award-info":[{"award-number":["DE210101458"]}]},{"name":"Cloud Technology Endowed Professorship"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2024,7]]},"DOI":"10.1109\/tdsc.2023.3321565","type":"journal-article","created":{"date-parts":[[2023,10,3]],"date-time":"2023-10-03T18:08:06Z","timestamp":1696356486000},"page":"3012-3029","source":"Crossref","is-referenced-by-count":34,"title":["Source Inference Attacks: Beyond Membership Inference Attacks in Federated Learning"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4455-4227","authenticated-orcid":false,"given":"Hongsheng","family":"Hu","sequence":"first","affiliation":[{"name":"The University of Auckland, Auckland, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7353-4159","authenticated-orcid":false,"given":"Xuyun","family":"Zhang","sequence":"additional","affiliation":[{"name":"Macquarie University, Macquarie Park, NSW, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7714-9848","authenticated-orcid":false,"given":"Zoran","family":"Salcic","sequence":"additional","affiliation":[{"name":"The University of Auckland, Auckland, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1539-7939","authenticated-orcid":false,"given":"Lichao","family":"Sun","sequence":"additional","affiliation":[{"name":"Lehigh University, Bethlehem, PA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9208-5336","authenticated-orcid":false,"given":"Kim-Kwang Raymond","family":"Choo","sequence":"additional","affiliation":[{"name":"The University of Texas at San Antonio, San Antonio, TX, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7245-0367","authenticated-orcid":false,"given":"Gillian","family":"Dobbie","sequence":"additional","affiliation":[{"name":"The University of Auckland, Auckland, New Zealand"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1016\/j.clsr.2013.03.010"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.2139\/ssrn.3275571"},{"key":"ref3","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"McMahan"},{"key":"ref4","first-page":"4427","article-title":"Federated multi-task learning","volume":"30","author":"Smith","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref5","article-title":"LEAF: A benchmark for federated settings","author":"Caldas","year":"2018"},{"key":"ref6","first-page":"374","article-title":"Towards federated learning at scale: System design","volume-title":"Proc. Mach. Learn. Syst.","volume":"1","author":"Bonawitz"},{"key":"ref7","article-title":"A collaborative online AI engine for CT-based COVID-19 diagnosis","author":"Xu","year":"2020","journal-title":"medRxiv"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63076-8_2"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3338501.3357370"},{"key":"ref13","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2023.23171","article-title":"PPA: Preference profiling attack against federated learning","volume-title":"Proc. Netw. Distrib. Syst. Secur. Symp.","author":"Zhou"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243834"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1371\/journal.pgen.1000167"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.14722\/diss.2020.23004"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3523273"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/S0140-6736(20)30792-3"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3216981"},{"key":"ref22","article-title":"FedMD: Heterogenous federated learning via model distillation","author":"Li","year":"2019"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM51629.2021.00129"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2021.3124599"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3387107"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63076-8_1"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3460427"},{"key":"ref29","first-page":"429","article-title":"Federated optimization in heterogeneous networks","volume-title":"Proc. Mach. Learn. Syst.","volume":"2","author":"Li"},{"key":"ref30","first-page":"5132","article-title":"SCAFFOLD: Stochastic controlled averaging for federated learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Karimireddy"},{"key":"ref31","first-page":"2351","article-title":"Ensemble distillation for robust model fusion in federated learning","volume":"33","author":"Lin","year":"2020","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref32","article-title":"Cronus: Robust and heterogeneous collaborative learning with black-box knowledge transfer","author":"Chang","year":"2019"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102378"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICC40277.2020.9148790"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCN49398.2020.9209744"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583359"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref38","article-title":"Robbing the Fed: Directly obtaining private data in federated learning with modified models","author":"Fowl","year":"2021"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/eurosp57164.2023.00020"},{"key":"ref40","volume-title":"Applied Statistics and Probability for Engineers","author":"Montgomery","year":"2010"},{"key":"ref41","first-page":"5558","article-title":"White-box versus black-box: Bayes optimal strategies for membership inference","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Sablayrolles"},{"key":"ref42","first-page":"2654","article-title":"Do deep nets really need to be deep?","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Ba"},{"key":"ref43","article-title":"Distilling the knowledge in a neural network","author":"Hinton","year":"2015"},{"key":"ref44","first-page":"2893","article-title":"Moonshine: Distilling with cheap convolutions","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Crowley"},{"key":"ref45","article-title":"On the convergence of FedAvg on Non-IID data","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Li"},{"key":"ref46","first-page":"1895","article-title":"Evaluating differentially private machine learning in practice","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Jayaraman"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2020.2975749"},{"key":"ref48","article-title":"DBA: Distributed backdoor attacks against federated learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xie"},{"key":"ref49","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref50","first-page":"7252","article-title":"Bayesian nonparametric federated learning of neural networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yurochkin"},{"key":"ref51","article-title":"Measuring the effects of non-identical data distribution for federated visual classification","author":"Hsu","year":"2019","journal-title":"arXiv: 1909.06335"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134077"},{"key":"ref53","first-page":"267","article-title":"The secret sharer: Evaluating and testing unintended memorization in neural networks","volume-title":"Proc. 28th USENIX Secur. Symp.","author":"Carlini"},{"key":"ref54","article-title":"ML privacy meter: Aiding regulatory compliance by quantifying the privacy risks of machine learning","author":"Murakonda","year":"2020"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/3446776"},{"key":"ref56","first-page":"1225","article-title":"Train faster, generalize better: Stability of stochastic gradient descent","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Hardt"},{"key":"ref57","article-title":"Federated learning with Non-IID data","author":"Zhao","year":"2018"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813687"},{"key":"ref60","article-title":"Differentially private federated learning: A client level perspective","author":"Geyer","year":"2017"},{"key":"ref61","article-title":"Learning differentially private recurrent language models","volume-title":"Proc. Int. Conf. Learn. Representations","author":"McMahan"},{"key":"ref62","article-title":"Toward robustness and privacy in federated learning: Experimenting with local and central differential privacy","author":"Naseri","year":"2020"},{"issue":"1","key":"ref63","first-page":"61","article-title":"Membership inference attack against differentially private deep learning model","volume":"11","author":"Rahman","year":"2018","journal-title":"Trans. Data Priv."},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref65","article-title":"Learning differentially private recurrent language models","author":"McMahan","year":"2017"},{"issue":"1","key":"ref66","first-page":"1929","article-title":"Dropout: A simple way to prevent neural networks from overfitting","volume":"15","author":"Srivastava","year":"2014","journal-title":"J. Mach. Learn. Res."},{"key":"ref67","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref69","first-page":"2633","article-title":"Extracting training data from large language models","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Carlini"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00023"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.5555\/2969033.2969125"},{"key":"ref72","article-title":"iDLG: Improved deep leakage from gradients","author":"Zhao","year":"2020"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3196646"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560573"},{"key":"ref76","first-page":"2615","article-title":"Systematic evaluation of privacy risks of machine learning models","volume-title":"Proc. USENIX Secur. Symp.","author":"Song"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1145\/3605764.3623906"},{"key":"ref78","article-title":"Membership inference attacks against text-to-image generation models","author":"Wu","year":"2022"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1145\/3560830.3563734"},{"key":"ref80","article-title":"M^ 4i: Multi-modal models membership inference","author":"Hu","year":"2022"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539392"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3154029"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2018.00027"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19821-2_21"},{"key":"ref85","first-page":"4561","article-title":"Membership inference attacks and defenses in neural network pruning","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Yuan"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/532"},{"key":"ref87","first-page":"493","article-title":"{BatchCrypt}: Efficient homomorphic encryption for {Cross-Silo} federated learning","volume-title":"Proc. USENIX Annu. Tech. Conf.","author":"Zhang"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2021.3082561"},{"key":"ref89","article-title":"Private federated learning on vertically partitioned data via entity resolution and additively homomorphic encryption","author":"Hardy","year":"2017"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-17277-0_9"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2020.2988525"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.30"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3146448"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3212627"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"ref97","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/217"},{"key":"ref98","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2988575"},{"key":"ref99","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2021.3056991"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1109\/TWC.2022.3188502"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/10592103\/10269696.pdf?arnumber=10269696","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,18]],"date-time":"2024-07-18T06:10:04Z","timestamp":1721283004000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10269696\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7]]},"references-count":100,"journal-issue":{"issue":"4"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2023.3321565","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,7]]}}}