{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T20:07:09Z","timestamp":1780603629206,"version":"3.54.1"},"reference-count":57,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"3","license":[{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T00:00:00Z","timestamp":1777593600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"New Generation Artificial Intelligence-National Science and Technology Major Project","award":["2025ZD0123504"],"award-info":[{"award-number":["2025ZD0123504"]}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["2242025K30025"],"award-info":[{"award-number":["2242025K30025"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U2441240"],"award-info":[{"award-number":["U2441240"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Ye Qisun Science Foundation","award":["62441238"],"award-info":[{"award-number":["62441238"]}]},{"name":"Ministry of Education Humanities and Social Sciences Project","award":["24JDSZ3073"],"award-info":[{"award-number":["24JDSZ3073"]}]},{"DOI":"10.13039\/501100001381","name":"National Research Foundation Singapore","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001381","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100008629","name":"Info-communications Media Development Authority","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100008629","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62502346"],"award-info":[{"award-number":["62502346"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,5]]},"DOI":"10.1109\/tdsc.2026.3655785","type":"journal-article","created":{"date-parts":[[2026,1,19]],"date-time":"2026-01-19T20:57:40Z","timestamp":1768856260000},"page":"5462-5479","source":"Crossref","is-referenced-by-count":0,"title":["Sleight: Hidden Data Privacy Breaches in Federated Learning"],"prefix":"10.1109","volume":"23","author":[{"given":"Xueluan","family":"Gong","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuji","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Computer Science, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-6063-8817","authenticated-orcid":false,"given":"Shuike","family":"Li","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mengyuan","family":"Sun","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4282-3307","authenticated-orcid":false,"given":"Songze","family":"Li","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Southeast University, Nanjing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chen","family":"Chen","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8967-8525","authenticated-orcid":false,"given":"Qian","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7479-7970","authenticated-orcid":false,"given":"Kwok-Yan","family":"Lam","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23325"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1987.1057284"},{"key":"ref5","first-page":"1505","article-title":"Blind backdoors in deep learning models","volume-title":"Proc. USENIX Secur. Symp.","author":"Bagdasaryan","year":"2021"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP57164.2023.00023"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP57164.2023.00020"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"ref9","article-title":"Understanding training-data leakage from gradients in neural networks for image classification","author":"Chen","year":"2021"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS51616.2021.00010"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2014.2363139"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2023\/394"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.23055"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1561\/9781601988195"},{"key":"ref15","article-title":"Imagenette: A smaller subset of 10 easily classified classes from imagenet","year":"2019"},{"key":"ref16","article-title":"Robbing the fed: Directly obtaining private data in federated learning with modified models","volume-title":"Proc. 10th Int. Conf. Learn. Representations","author":"Fowl","year":"2022"},{"key":"ref17","article-title":"Decepticons: Corrupted transformers breach privacy in federated learning for language models","volume-title":"Proc. 11th Int. Conf. Learn. Representations","author":"Fowl","year":"2023"},{"key":"ref18","article-title":"Hiding in plain sight: Disguising data stealing attacks in federated learning","volume-title":"Proc. 12th Int. Conf. Learn. Representations","author":"Garov","year":"2023"},{"key":"ref19","first-page":"16937","article-title":"Inverting gradients-how easy is it to break privacy in federated learning?","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Geiping","year":"2020"},{"key":"ref20","article-title":"Differentially private federated learning: A client level perspective","volume-title":"Proc. Annu. Neural Inform. Process. Syst. Workshops","author":"Geyer","year":"2017"},{"key":"ref21","first-page":"8130","article-title":"Recovering private text in federated learning of language models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"35","author":"Gupta","year":"2022"},{"key":"ref22","first-page":"629","article-title":"Gaia:$\\lbrace${Geo-Distributed $\\rbrace$} machine learning approaching $\\lbrace${ LAN$\\rbrace$} speeds","volume-title":"Proc. USENIX Symp. Networked Syst. Des. Implementation","author":"Hsieh","year":"2017"},{"key":"ref23","first-page":"29898","article-title":"Gradient inversion with generative image prior","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Jeon","year":"2021"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1561\/9781680837896"},{"key":"ref25","article-title":"Federated learning: Strategies for improving communication efficiency","author":"Konecn","year":"2016"},{"key":"ref26","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref27","first-page":"5959","article-title":"Gradient disaggregation: Breaking privacy in federated learning by reconstructing the user participant matrix","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Lam","year":"2021"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00989"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/j.sigpro.2018.10.019"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3427228.3427268"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM48880.2022.9796935"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2026.241870"},{"key":"ref34","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. Artif. Intell. Statist.","author":"McMahan","year":"2017"},{"key":"ref35","first-page":"10","article-title":"Adaptive federated dropout: Improving communication efficiency and generalization for federated learning","volume-title":"Proc. IEEE Conf. Comput. Commun. Workshops","author":"Nader","year":"2021"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560557"},{"key":"ref37","article-title":"Aggregating capacity in fl through successive layer training for computationally-constrained devices","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"36","author":"Pfeiffer"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-10-5421-1_9"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00919"},{"key":"ref40","article-title":"Collapse-aware triplet decoupling for adversarially robust image retrieval","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Tian","year":"2024"},{"key":"ref41","article-title":"SAPAG: A self-adaptive privacy attack from gradients","author":"Wang","year":"2020"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/ISCC53001.2021.9631425"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"ref44","article-title":"A framework for evaluating gradient leakage attacks in federated learning","author":"Wei","year":"2020"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS51616.2021.00081"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/LWC.2022.3149783"},{"key":"ref47","first-page":"23668","article-title":"Fishing for user data in large-batch federated learning via gradient magnification","volume-title":"Proc. Int. Conf. Mach. Learn.","volume":"162","author":"Wen","year":"2022"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3227761"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3360891"},{"key":"ref50","first-page":"179","article-title":"Representations des nombres naturels par une somme de nombres de fibonacci on de nombres de lucas","author":"Zeckendorf","year":"1972","journal-title":"Bull. De La Soc. Royale Des Sci. De Liege"},{"key":"ref51","article-title":"Why gradient clipping accelerates training: A theoretical justification for adaptivity","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang","year":"2019"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-22677-9_4"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00387"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/sp54263.2024.00030"},{"key":"ref56","article-title":"R-GAP: Recursive gradient attack on privacy","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Zhu","year":"2021"},{"key":"ref57","article-title":"Deep leakage from gradients","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Zhu","year":"2019"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11517592\/11359012.pdf?arnumber=11359012","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T19:59:01Z","timestamp":1780603141000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11359012\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5]]},"references-count":57,"journal-issue":{"issue":"3"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2026.3655785","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5]]}}}