{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,4]],"date-time":"2026-08-04T15:53:34Z","timestamp":1785858814238,"version":"3.56.0"},"reference-count":67,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2022YFB3102100"],"award-info":[{"award-number":["2022YFB3102100"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100017607","name":"Shenzhen Municipal Fundamental Research Program","doi-asserted-by":"publisher","award":["JCYJ20220818102414030"],"award-info":[{"award-number":["JCYJ20220818102414030"]}],"id":[{"id":"10.13039\/501100017607","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Major Key Project of Peng Cheng Laboratory","award":["PCL2024A05"],"award-info":[{"award-number":["PCL2024A05"]}]},{"name":"Shenzhen Science and Technology Program","award":["ZDSYS20210623091809029"],"award-info":[{"award-number":["ZDSYS20210623091809029"]}]},{"DOI":"10.13039\/100013261","name":"Guangdong Provincial Key Laboratory of Novel Security Intelligence Technologies","doi-asserted-by":"publisher","award":["2022B1212010005"],"award-info":[{"award-number":["2022B1212010005"]}],"id":[{"id":"10.13039\/100013261","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2024.3522792","type":"journal-article","created":{"date-parts":[[2024,12,26]],"date-time":"2024-12-26T19:06:50Z","timestamp":1735240010000},"page":"928-943","source":"Crossref","is-referenced-by-count":7,"title":["Gradient Inversion of Text-Modal Data in Distributed Learning"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1605-4527","authenticated-orcid":false,"given":"Zipeng","family":"Ye","sequence":"first","affiliation":[{"name":"Guangdong Provincial Key Laboratory of Novel Security Intelligence Technologies, School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8357-1655","authenticated-orcid":false,"given":"Wenjian","family":"Luo","sequence":"additional","affiliation":[{"name":"Guangdong Provincial Key Laboratory of Novel Security Intelligence Technologies, School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qi","family":"Zhou","sequence":"additional","affiliation":[{"name":"Guangdong Provincial Key Laboratory of Novel Security Intelligence Technologies, School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yubo","family":"Tang","sequence":"additional","affiliation":[{"name":"Guangdong Provincial Key Laboratory of Novel Security Intelligence Technologies, School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhenqian","family":"Zhu","sequence":"additional","affiliation":[{"name":"Guangdong Provincial Key Laboratory of Novel Security Intelligence Technologies, School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8840-723X","authenticated-orcid":false,"given":"Yuhui","family":"Shi","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Southern University of Science and Technology, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yan","family":"Jia","sequence":"additional","affiliation":[{"name":"Guangdong Provincial Key Laboratory of Novel Security Intelligence Technologies, School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. 20th Int. Conf. Artif. Intell. Statist.","author":"McMahan"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2021.3118346"},{"key":"ref3","article-title":"Deep leakage from gradients","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Zhu"},{"key":"ref4","first-page":"16937","article-title":"Inverting gradients-how easy is it to break privacy in federated learning?","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Geiping"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"ref6","first-page":"7641","article-title":"LAMP: Extracting text from gradients with language model priors","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"35","author":"Balunovic"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/11787006_1"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813687"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3139777"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.findings-emnlp.305"},{"key":"ref12","first-page":"8130","article-title":"Recovering private text in federated learning of language models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"35","author":"Gupta"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1613\/jair.2934"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-95663-3"},{"key":"ref15","article-title":"Efficient estimation of word representations in vector space","author":"Mikolov","year":"2013","journal-title":"arXiv:1301.3781"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/D14-1162"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/W18-5446"},{"key":"ref18","article-title":"Sequence to sequence learning with neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"27","author":"Sutskever"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.03762"},{"key":"ref20","article-title":"Improving language understanding by generative pre-training","author":"Radford","year":"2018","journal-title":"OpenAI Blog"},{"key":"ref21","article-title":"LLaMA: Open and efficient foundation language models","author":"Touvron","year":"2023","journal-title":"arXiv:2302.13971"},{"key":"ref22","first-page":"1877","article-title":"Language models are few-shot learners","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Brown"},{"key":"ref23","article-title":"BERT: Pre-training of deep bidirectional transformers for language understanding","author":"Devlin","year":"2018","journal-title":"arXiv:1810.04805"},{"key":"ref24","first-page":"9","article-title":"Language models are unsupervised multitask learners","volume":"1","author":"Radford","year":"2019","journal-title":"OpenAI Blog"},{"key":"ref25","article-title":"IDLG: Improved deep leakage from gradients","author":"Zhao","year":"2020","journal-title":"arXiv:2001.02610"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2020.2975749"},{"key":"ref28","first-page":"5132","article-title":"SCAFFOLD: Stochastic controlled averaging for federated learning","volume-title":"Proc. 37th Int. Conf. Mach. Learn.","volume":"119","author":"Karimireddy"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/j.engappai.2024.107927"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3501813"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63076-8_17"},{"key":"ref32","article-title":"Federated learning for mobile keyboard prediction","author":"Hard","year":"2018","journal-title":"arXiv:1811.03604"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i18.29975"},{"key":"ref34","article-title":"R-GAP: Recursive gradient attack on privacy","author":"Zhu","year":"2020","journal-title":"arXiv:2010.07733"},{"key":"ref35","article-title":"Understanding training-data leakage from gradients in neural networks for image classification","volume-title":"Proc. NeurIPS Workshop","author":"Chen"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2022-0043"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00874"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.5555\/3045118.3045167"},{"key":"ref39","first-page":"29898","article-title":"Gradient inversion with generative image prior","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Jeon"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00989"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3430533"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/312624.312649"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2988575"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2024.3417930"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-96884-1_19"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1002\/int.22818"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2022.09.011"},{"key":"ref50","first-page":"23668","article-title":"Fishing for user data in large-batch federated learning via gradient magnification","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Wen"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560557"},{"key":"ref52","article-title":"Scale-MIA: A scalable model inversion attack against secure federated learning via latent space reconstruction","author":"Shi","year":"2023","journal-title":"arXiv:2311.05808"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00030"},{"key":"ref54","article-title":"Robbing the fed: Directly obtaining private data in federated learning with modified models","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Fowl"},{"key":"ref55","first-page":"1081","article-title":"A scalable hierarchical distributed language model","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"21","author":"Mnih"},{"key":"ref56","article-title":"LEAF: A benchmark for federated settings","author":"Caldas","year":"2018","journal-title":"arXiv:1812.01097"},{"key":"ref57","article-title":"Pointer sentinel mixture models","author":"Merity","year":"2016","journal-title":"arXiv:1609.07843"},{"key":"ref58","volume-title":"Elon Musk\u2014Wikipedia, the Free Encyclopedia","year":"2023"},{"key":"ref59","article-title":"Opening the black box of deep neural networks via information","author":"Shwartz-Ziv","year":"2017","journal-title":"arXiv:1703.00810"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1201\/b10905-6"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.findings-emnlp.372"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2020.emnlp-demos.6"},{"key":"ref63","first-page":"74","article-title":"ROUGE: A package for automatic evaluation of summaries","volume-title":"Proc. Text Summarization Branches Out","author":"Lin"},{"key":"ref64","article-title":"Adam: A method for stochastic optimization","author":"Kingma","year":"2014","journal-title":"arXiv:1412.6980"},{"key":"ref65","article-title":"On position embeddings in BERT","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Wang"},{"key":"ref66","first-page":"1243","article-title":"Convolutional sequence to sequence learning","volume-title":"Proc. 34th Int. Conf. Mach. Learn.","author":"Gehring"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N18-2074"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/10816194.pdf?arnumber=10816194","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,14]],"date-time":"2025-01-14T19:44:29Z","timestamp":1736883869000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10816194\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":67,"URL":"https:\/\/doi.org\/10.1109\/tifs.2024.3522792","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}