{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T21:22:44Z","timestamp":1772227364543,"version":"3.50.1"},"reference-count":50,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U2433205"],"award-info":[{"award-number":["U2433205"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100013058","name":"Jiangsu Provincial Key Research and Development Program","doi-asserted-by":"publisher","award":["BE2022068"],"award-info":[{"award-number":["BE2022068"]}],"id":[{"id":"10.13039\/501100013058","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100013058","name":"Jiangsu Provincial Key Research and Development Program","doi-asserted-by":"publisher","award":["BE2022068-1"],"award-info":[{"award-number":["BE2022068-1"]}],"id":[{"id":"10.13039\/501100013058","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2026.3666295","type":"journal-article","created":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T20:56:43Z","timestamp":1771534603000},"page":"2342-2357","source":"Crossref","is-referenced-by-count":0,"title":["Model Inversion Attack Against Federated Unlearning"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0009-0001-9385-4763","authenticated-orcid":false,"given":"Lei","family":"Zhou","sequence":"first","affiliation":[{"name":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing, Jiangsu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4365-9713","authenticated-orcid":false,"given":"Youwen","family":"Zhu","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing, Jiangsu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4204-8793","authenticated-orcid":false,"given":"Rongke","family":"Liu","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing, Jiangsu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2021.3076443"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-57959-7"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.69554\/TCFN5165"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.5040\/9781782258674.0010"},{"key":"ref5","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. 20th Int. Conf. Artif. Intell. Statist.","volume":"54","author":"McMahan"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3679014"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3520614"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2024.3382726"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/IWQOS52092.2021.9521274"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3297905"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512222"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM48880.2022.9796721"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179336"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3531141"},{"key":"ref15","first-page":"14774","article-title":"Deep leakage from gradients","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","author":"Mu"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3302161"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2025.3530988"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3318944"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2024.3405939"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CISS56502.2023.10089719"},{"key":"ref21","article-title":"IDLG: Improved deep leakage from gradients","volume-title":"arXiv:2001.02610","author":"Zhao","year":"2020"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"ref23","article-title":"R-GAP: Recursive gradient attack on privacy","author":"Zhu","year":"2020","journal-title":"arXiv:2010.07733"},{"key":"ref24","article-title":"Understanding training-data leakage from gradients in neural networks for image classification","author":"Chen","year":"2021","journal-title":"arXiv:2111.10178"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00248"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3368879"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2008.2008420"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CCNC49032.2021.9369498"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2023.3345388"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3539597.3570463"},{"key":"ref31","volume-title":"Deep Learning","author":"Goodfellow","year":"2016"},{"key":"ref32","first-page":"16937","article-title":"Inverting gradients-how easy is it to break privacy in federated learning?","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","volume":"33","author":"Geiping"},{"key":"ref33","first-page":"1","article-title":"Are all layers created equal?","author":"Zhang","year":"2019","journal-title":"J. Mach. Learn. Res."},{"key":"ref34","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref37","first-page":"19332","article-title":"Federated learning from pre-trained models: A contrastive learning approach","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","author":"Tan"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.01151"},{"key":"ref39","first-page":"19406","article-title":"Where to begin? On the impact of pre-training and initialization in federated learning","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Nguyen"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3510033"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref42","first-page":"1","article-title":"Very deep convolutional networks for large-scale image recognition","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Simonyan"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP53844.2022.00027"},{"key":"ref44","first-page":"6381","article-title":"Gradient obfuscation gives a false sense of security in federated learning","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Yue"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00919"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS51616.2021.00081"},{"key":"ref48","first-page":"7232","article-title":"Evaluating gradient inversion attacks and defenses in federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","volume":"34","author":"Huang"},{"key":"ref49","first-page":"6439","article-title":"SoK: Gradient inversion attacks in federated learning","volume-title":"Proc. 34th USENIX Secur. Symp.","author":"Carletti"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3297369"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11400570.pdf?arnumber=11400570","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T20:48:31Z","timestamp":1772225311000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11400570\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":50,"URL":"https:\/\/doi.org\/10.1109\/tifs.2026.3666295","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}