{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T18:38:51Z","timestamp":1780511931204,"version":"3.54.1"},"reference-count":53,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key R&D Program of China","doi-asserted-by":"publisher","award":["2023YFB3107500"],"award-info":[{"award-number":["2023YFB3107500"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62220106004"],"award-info":[{"award-number":["62220106004"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62232013"],"award-info":[{"award-number":["62232013"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Technology Innovation Leading Program of Shaanxi","award":["2022KXJ-093"],"award-info":[{"award-number":["2022KXJ-093"]}]},{"name":"Technology Innovation Leading Program of Shaanxi","award":["2023KXJ-033"],"award-info":[{"award-number":["2023KXJ-033"]}]},{"DOI":"10.13039\/100017413","name":"Innovation Fund of Xidian","doi-asserted-by":"publisher","award":["YJSJ24015"],"award-info":[{"award-number":["YJSJ24015"]}],"id":[{"id":"10.13039\/100017413","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2024.3515793","type":"journal-article","created":{"date-parts":[[2024,12,11]],"date-time":"2024-12-11T22:29:47Z","timestamp":1733956187000},"page":"1519-1534","source":"Crossref","is-referenced-by-count":6,"title":["Local Differential Privacy Is Not Enough: A Sample Reconstruction Attack Against Federated Learning With Local Differential Privacy"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3683-407X","authenticated-orcid":false,"given":"Zhichao","family":"You","sequence":"first","affiliation":[{"name":"School of Computer Science and Technology, Xidian University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5745-0545","authenticated-orcid":false,"given":"Xuewen","family":"Dong","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Xidian University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5628-7328","authenticated-orcid":false,"given":"Shujun","family":"Li","sequence":"additional","affiliation":[{"name":"School of System and Computing, The University of New South Wales, Canberra, ACT, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ximeng","family":"Liu","sequence":"additional","affiliation":[{"name":"College of Computer and Data Science, Fuzhou University, Fuzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3479-5713","authenticated-orcid":false,"given":"Siqi","family":"Ma","sequence":"additional","affiliation":[{"name":"School of System and Computing, The University of New South Wales, Canberra, ACT, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8448-705X","authenticated-orcid":false,"given":"Yulong","family":"Shen","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Xidian University, Xi'an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1561\/2200000083"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3372634"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2023.01.019"},{"key":"ref4","article-title":"Federated learning: Collaborative machine learning without centralized training data","volume-title":"Google Research Blog","author":"McMahan","year":"2017"},{"key":"ref5","article-title":"Federated evaluation and tuning for on-device personalization: System design & and applications","author":"Paulik","year":"2021","journal-title":"arXiv:2102.08503"},{"issue":"226","key":"ref6","first-page":"1","article-title":"FATE: An industrial grade platform for collaborative learning with data protection","volume":"22","author":"Liu","year":"2021","journal-title":"J. Mach. Learn. Res."},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63076-8_2"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3227761"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"ref10","first-page":"1","article-title":"Robbing the fed: Directly obtaining private data in federated learning with modified models","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Fowl"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP57164.2023.00020"},{"key":"ref12","article-title":"A framework for evaluating gradient leakage attacks in federated learning","author":"Wei","year":"2020","journal-title":"arXiv:2004.10397"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560557"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00874"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP57164.2023.00023"},{"key":"ref16","first-page":"29898","article-title":"Gradient inversion with generative image prior","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Jeon"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00978"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2020.3000372"},{"key":"ref19","first-page":"994","article-title":"CAFE: Catastrophic data leakage in vertical federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Jin"},{"key":"ref20","article-title":"R-gap: Recursive gradient attack on privacy","author":"Zhu","year":"2021","journal-title":"arXiv:2010.07733"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2988575"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3168556"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2991416"},{"key":"ref24","first-page":"1379","article-title":"Efficient differentially private secure aggregation for federated learning via hardness of learning with errors","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Stevens"},{"key":"ref25","first-page":"3989","article-title":"Exploring the security boundary of data reconstruction via neuron exclusivity analysis","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Pan"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3140687"},{"key":"ref27","article-title":"On the inadequacy of similarity-based privacy metrics: Reconstruction attacks against \u2018truly anonymous synthetic data","author":"Ganev","year":"2023","journal-title":"arXiv:2312.05114"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3089713"},{"key":"ref29","first-page":"1","article-title":"Generative adversarial networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Goodfellow"},{"key":"ref30","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. 20th Int. Conf. Artif. Intell. Statist.","volume":"54","author":"McMahan"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1561\/9781601988195"},{"key":"ref32","first-page":"1","article-title":"Learning differentially private recurrent language models","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"McMahan"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23054"},{"key":"ref34","first-page":"16937","article-title":"Inverting gradients\u2014How easy is it to break privacy in federated learning?","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Geiping"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00371"},{"key":"ref37","article-title":"A comprehensive survey on segment anything model for vision and beyond","author":"Zhang","year":"2023","journal-title":"arXiv:2305.08196"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-024-44824-z"},{"key":"ref39","article-title":"Segment anything in non-Euclidean domains: Challenges and opportunities","author":"Jing","year":"2023","journal-title":"arXiv:2304.11595"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1080\/03610920701826088"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/1-84628-168-7"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i11.29140"},{"key":"ref43","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref44","article-title":"Caltech-256 object category dataset","author":"Griffin","year":"2007"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICVGIP.2008.47"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2009.2025923"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2023.3302016"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.33969\/J-NaNA.2023.030404"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01167"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr.2017.243"},{"key":"ref52","first-page":"6105","article-title":"EfficientNet: Rethinking model scaling for convolutional neural networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Tan"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.4324\/9781410605337-29"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/10793076.pdf?arnumber=10793076","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,5]],"date-time":"2025-02-05T18:47:52Z","timestamp":1738781272000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10793076\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":53,"URL":"https:\/\/doi.org\/10.1109\/tifs.2024.3515793","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}