{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,26]],"date-time":"2026-04-26T13:30:36Z","timestamp":1777210236691,"version":"3.51.4"},"reference-count":61,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["92270123"],"award-info":[{"award-number":["92270123"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Research Grants Council","award":["15226221"],"award-info":[{"award-number":["15226221"]}]},{"name":"Research Grants Council","award":["15208923"],"award-info":[{"award-number":["15208923"]}]},{"name":"Research Grants Council","award":["15224124"],"award-info":[{"award-number":["15224124"]}]},{"name":"Open Research Fund of the State Key Laboratory of Blockchain and Data Security"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3581743","type":"journal-article","created":{"date-parts":[[2025,6,20]],"date-time":"2025-06-20T17:27:06Z","timestamp":1750440426000},"page":"6529-6543","source":"Crossref","is-referenced-by-count":1,"title":["ProVFL: Property Inference Attacks Against Vertical Federated Learning"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7202-3178","authenticated-orcid":false,"given":"Li","family":"Bai","sequence":"first","affiliation":[{"name":"Department of Electrical and Electronic Engineering, The Hong Kong Polytechnic University, Hong Kong"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1267-5182","authenticated-orcid":false,"given":"Xinwei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Electrical and Electronic Engineering, The Hong Kong Polytechnic University, Hong Kong"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3031-3721","authenticated-orcid":false,"given":"Sen","family":"Zhang","sequence":"additional","affiliation":[{"name":"Department of Electrical and Electronic Engineering, The Hong Kong Polytechnic University, Hong Kong"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1547-2847","authenticated-orcid":false,"given":"Qingqing","family":"Ye","sequence":"additional","affiliation":[{"name":"Department of Electrical and Electronic Engineering, The Hong Kong Polytechnic University, Hong Kong"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9008-2112","authenticated-orcid":false,"given":"Haibo","family":"Hu","sequence":"additional","affiliation":[{"name":"Department of Electrical and Electronic Engineering, The Hong Kong Polytechnic University, Hong Kong"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. Int. Conf. Artif. Intell. Stat. (AISTATS)","volume":"54","author":"McMahan"},{"key":"ref2","first-page":"994","article-title":"CAFE: Catastrophic data leakage in vertical federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","volume":"34","author":"Jin"},{"key":"ref3","first-page":"1397","article-title":"Label inference attacks against vertical federated learning","volume-title":"Proc. 31st USENIX Security Symp. (USENIX Security)","author":"Fu"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1016\/j.sysarc.2022.102474"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/EIECS53707.2021.9587935"},{"key":"ref6","article-title":"VAFL: A method of vertical asynchronous federated learning","author":"Chen","year":"2020","journal-title":"arXiv:2007.06081"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2024.3352628"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00023"},{"key":"ref9","article-title":"Feature reconstruction attacks and countermeasures of DNN training in vertical federated learning","author":"Ye","year":"2022","journal-title":"arXiv:2210.06771"},{"key":"ref10","article-title":"Is vertical logistic regression privacy-preserving? A comprehensive privacy analysis and beyond","author":"Hu","year":"2022","journal-title":"arXiv:2207.09087"},{"key":"ref11","first-page":"1","article-title":"Label leakage and protection in two-party split learning","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Li"},{"key":"ref12","article-title":"Label leakage and protection from forward embedding in vertical federated learning","author":"Sun","year":"2022","journal-title":"arXiv:2203.01451"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML54575.2023.00020"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1504\/IJSN.2015.071829"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833623"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179334"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560662"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2023.3309701"},{"key":"ref19","first-page":"2687","article-title":"Leakage of dataset properties in multi-party machine learning","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Secur.)","author":"Zhang"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"ref21","first-page":"1","article-title":"Overlearning reveals sensitive attributes","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Song"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243834"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23019"},{"key":"ref24","article-title":"PriSampler: Mitigating property inference of diffusion models","author":"Hu","year":"2023","journal-title":"arXiv:2306.05208"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3453555"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3196646"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485259"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ICME52920.2022.9859857"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-51482-1_2"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0121"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2024.3356164"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2022-0045"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359824"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00151"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/153"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/1993636.1993736"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01263"},{"key":"ref40","article-title":"One-shot face recognition by promoting underrepresented classes","author":"Guo","year":"2017","journal-title":"arXiv:1707.05574"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01267-0_45"},{"key":"ref42","first-page":"1","article-title":"Deep inside convolutional networks: Visualising image classification models and saliency maps","volume-title":"Proc. Workshop Int. Conf. Learn. Represent. (ICLR)","author":"Simonyan"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref44","first-page":"3319","article-title":"Axiomatic attribution for deep networks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Sundararajan"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00361"},{"key":"ref46","volume-title":"UCI Machine Learning Repository","author":"Dua","year":"2017"},{"key":"ref47","first-page":"202","article-title":"Scaling up the accuracy of Naive-Bayes classifiers: A decision-tree hybrid","volume-title":"Proc. 2nd Int. Conf. Knowl. Discovery Data Mining","volume":"96","author":"Kohavi"},{"key":"ref48","article-title":"LSAC national longitudinal bar passage study. LSAC research report series","author":"Wightman","year":"1998"},{"key":"ref49","first-page":"35051","article-title":"TabLeak: Tabular data leakage in federated learning","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Vero"},{"key":"ref50","volume-title":"Texas Hospital Inpatient Discharge Public Use Data File","year":"2006"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417270"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939785"},{"key":"ref53","article-title":"Practical privacy attacks on vertical federated learning","author":"Weng","year":"2020","journal-title":"arXiv:2011.09290"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/1646396.1646452"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1002\/widm.8"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1007\/s10994-010-5221-8"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/1961189.1961199"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.61838\/jaiai.1.2.5"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813687"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-97-5562-2_14"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3477325"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/11045555.pdf?arnumber=11045555","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,4]],"date-time":"2025-07-04T17:50:11Z","timestamp":1751651411000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11045555\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":61,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3581743","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}