{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T20:42:48Z","timestamp":1768941768724,"version":"3.49.0"},"reference-count":36,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"NSFC Projects","award":["U23A20304"],"award-info":[{"award-number":["U23A20304"]}]},{"name":"NSFC Projects","award":["U25A20428"],"award-info":[{"award-number":["U25A20428"]}]},{"name":"NSFC Projects","award":["62572502"],"award-info":[{"award-number":["62572502"]}]},{"name":"NSFC Projects","award":["62302539"],"award-info":[{"award-number":["62302539"]}]},{"DOI":"10.13039\/501100001809","name":"Beijing Advanced Innovation Center for Future Blockchain and Privacy Computing","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2026.3652013","type":"journal-article","created":{"date-parts":[[2026,1,12]],"date-time":"2026-01-12T21:59:20Z","timestamp":1768255160000},"page":"1050-1064","source":"Crossref","is-referenced-by-count":0,"title":["Casper: A Causality-Inspired Defense With Confounder Against Label Inference Attacks in Vertical Split Federated Learning"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1867-0972","authenticated-orcid":false,"given":"Meng","family":"Shen","sequence":"first","affiliation":[{"name":"School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0005-3387-7911","authenticated-orcid":false,"given":"Jin","family":"Meng","sequence":"additional","affiliation":[{"name":"School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China"}]},{"given":"Bohan","family":"Peng","sequence":"additional","affiliation":[{"name":"School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5511-0720","authenticated-orcid":false,"given":"Xiangyun","family":"Tang","sequence":"additional","affiliation":[{"name":"School of Information Engineering and the Key Laboratory of Ethnic Language Intelligent Analysis and Security Governance, Minzu University of China, Beijing, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5974-1589","authenticated-orcid":false,"given":"Wei","family":"Wang","sequence":"additional","affiliation":[{"name":"Ministry of Education Key Laboratory for Intelligent Networks and Network Security, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7442-7416","authenticated-orcid":false,"given":"Dusit","family":"Niyato","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science, Nanyang Technological University, Jurong West, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3277-3887","authenticated-orcid":false,"given":"Liehuang","family":"Zhu","sequence":"additional","affiliation":[{"name":"School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2024.3352628"},{"key":"ref2","first-page":"1397","article-title":"Label inference attacks against vertical federated learning","volume-title":"Proc. 31st USENIX Security Symp. (USENIX Security)","author":"Fu"},{"key":"ref3","article-title":"Label leakage and protection in two-party split learning","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Li"},{"key":"ref4","doi-asserted-by":"crossref","first-page":"2881","DOI":"10.1109\/TIFS.2024.3356821","article-title":"Similarity-based label inference attack against training and inference of split learning","volume":"19","author":"Liu","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref5","article-title":"Label inference attack against split learning under regression setting","author":"Xie","year":"2023","journal-title":"arXiv:2301.07284"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/PAAP60200.2023.10391773"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2024.3474717"},{"key":"ref8","first-page":"20296","article-title":"FedVS: Straggler-resilient and privacy-preserving vertical federated learning for split models","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li"},{"key":"ref9","article-title":"Deep leakage from gradients","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Zhu"},{"key":"ref10","first-page":"3252","article-title":"Error feedback fixes SignSGD and other gradient compression schemes","volume-title":"Proc. Int. Conf. Mach. Learn.","volume":"97","author":"Karimireddy"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813687"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2022.3231277"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2024.3349863"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/BigData62323.2024.10825545"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.52202\/079017-1412"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-01585-4_5"},{"key":"ref17","volume-title":"The Book of Why: The New Science of Cause and Effect","author":"Pearl","year":"2018"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01177"},{"key":"ref19","article-title":"Causality based front-door defense against backdoor attack on language models","volume-title":"Proc. 41st Int. Conf. Mach. Learn. (ICML)","author":"Liu","year":"2024"},{"key":"ref20","first-page":"32789","article-title":"ConfounderGAN: Protecting image data privacy with causal confounder","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Tian"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1103\/PhysRevE.69.066138"},{"key":"ref22","first-page":"37","article-title":"Autoencoders, unsupervised learning, and deep architectures","volume-title":"Proc. ICML Workshop Unsupervised Transf. Learn.","author":"Baldi"},{"key":"ref23","first-page":"5171","article-title":"On variational bounds of mutual information","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Poole"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2014.2320500"},{"key":"ref25","first-page":"1321","article-title":"On calibration of modern neural networks","volume-title":"Proc. 34th Intl. Conf. Mach. Learn","author":"Guo"},{"key":"ref26","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/cvpr.2009.5206848"},{"key":"ref28","article-title":"Breast cancer wisconsin (diagnostic)","author":"Wolberg","year":"1993"},{"key":"ref29","article-title":"Character-level convolutional networks for text classification","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"28","author":"Zhang"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/iccv.2015.123"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1561\/2200000083"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1810.04805"},{"key":"ref33","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2025.240046","article-title":"URVFL: Undetectable data reconstruction attack on vertical federated learning","volume-title":"Proc. Netw. Distrib. Syst. Secur. Symp. (NDSS)","author":"Yao"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3275161"},{"key":"ref35","doi-asserted-by":"crossref","first-page":"748","DOI":"10.1109\/TIFS.2023.3327853","article-title":"Backdoor attack against split neural network-based vertical federated learning","volume":"19","author":"He","year":"2024","journal-title":"IEEE Trans. Inf. Forensics Security"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/sp54263.2024.00008"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11341912.pdf?arnumber=11341912","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T07:26:21Z","timestamp":1768893981000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11341912\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":36,"URL":"https:\/\/doi.org\/10.1109\/tifs.2026.3652013","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}