{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,29]],"date-time":"2026-03-29T06:51:31Z","timestamp":1774767091530,"version":"3.50.1"},"reference-count":56,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"7","license":[{"start":{"date-parts":[[2023,7,1]],"date-time":"2023-07-01T00:00:00Z","timestamp":1688169600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,7,1]],"date-time":"2023-07-01T00:00:00Z","timestamp":1688169600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,7,1]],"date-time":"2023-07-01T00:00:00Z","timestamp":1688169600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Med. Imaging"],"published-print":{"date-parts":[[2023,7]]},"DOI":"10.1109\/tmi.2023.3239391","type":"journal-article","created":{"date-parts":[[2023,1,24]],"date-time":"2023-01-24T19:07:08Z","timestamp":1674587228000},"page":"2044-2056","source":"Crossref","is-referenced-by-count":97,"title":["Do Gradient Inversion Attacks Make Federated Learning Unsafe?"],"prefix":"10.1109","volume":"42","author":[{"given":"Ali","family":"Hatamizadeh","sequence":"first","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA"}]},{"given":"Hongxu","family":"Yin","sequence":"additional","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA"}]},{"given":"Pavlo","family":"Molchanov","sequence":"additional","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA"}]},{"given":"Andriy","family":"Myronenko","sequence":"additional","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1081-2830","authenticated-orcid":false,"given":"Wenqi","family":"Li","sequence":"additional","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA"}]},{"given":"Prerna","family":"Dogra","sequence":"additional","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA"}]},{"given":"Andrew","family":"Feng","sequence":"additional","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA"}]},{"given":"Mona G","family":"Flores","sequence":"additional","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA"}]},{"given":"Jan","family":"Kautz","sequence":"additional","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4621-881X","authenticated-orcid":false,"given":"Daguang","family":"Xu","sequence":"additional","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3662-8743","authenticated-orcid":false,"given":"Holger R.","family":"Roth","sequence":"additional","affiliation":[{"name":"NVIDIA, Santa Clara, CA, USA"}]}],"member":"263","reference":[{"key":"ref13","first-page":"8253","article-title":"FetchSGD: Communication-efficient federated learning with sketching","author":"rothchild","year":"2020","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3447548.3470814"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1038\/s42256-021-00390-3"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"ref14","first-page":"16937","article-title":"Inverting gradients-how easy is it to break privacy in federated learning?","volume":"33","author":"geiping","year":"2020","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref53","article-title":"Adaptive federated optimization","author":"reddi","year":"2020","journal-title":"arXiv 2003 00295"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1038\/s42256-020-0186-1"},{"key":"ref11","first-page":"5132","article-title":"Scaffold: Stochastic controlled averaging for federated learning","author":"karimireddy","year":"2020","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"ref10","first-page":"429","article-title":"Federated optimization in heterogeneous networks","volume":"2","author":"li","year":"2020","journal-title":"Proc Mach Learn Syst"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1038\/s42256-021-00337-8"},{"key":"ref19","first-page":"448","article-title":"Batch normalization: Accelerating deep network training by reducing internal covariate shift","author":"ioffe","year":"2015","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-60548-3_13"},{"key":"ref50","article-title":"FedBN: Federated learning on non-IID features via local batch normalization","author":"li","year":"2021","journal-title":"arXiv 2102 07623"},{"key":"ref46","article-title":"Rotterdam EyePACS AIROGS train set","author":"de vente","year":"2021","journal-title":"Proc IEEE Int Symp Biomed Imag"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.369"},{"key":"ref48","doi-asserted-by":"crossref","first-page":"600","DOI":"10.1109\/TIP.2003.819861","article-title":"Image quality assessment: From error visibility to structural similarity","volume":"13","author":"wang","year":"2004","journal-title":"IEEE Trans Image Process"},{"key":"ref47","article-title":"NVIDIA FLARE: Federated learning from simulation to real-world","author":"roth","year":"2022","journal-title":"Proc Int Workshop Federated Learn (NeurIPS)"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00919"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1016\/j.compbiomed.2021.104319"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3010287"},{"key":"ref49","first-page":"1","article-title":"Visualizing data using t-SNE","volume":"9","author":"van der maaten","year":"2008","journal-title":"J Mach Learn Res"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1038\/s41591-021-01506-3"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1093\/jamia\/ocaa341"},{"key":"ref9","article-title":"Advances and open problems in federated learning","author":"kairouz","year":"2019","journal-title":"arXiv 1912 04977"},{"key":"ref4","first-page":"181","article-title":"Federated learning for breast density classification: A real-world implementation","author":"roth","year":"2020","journal-title":"Domain Adaptation and Representation Transfer and Distributed and Collaborative Learning"},{"key":"ref3","first-page":"92","article-title":"Multi-institutional deep learning modeling without sharing patient data: A feasibility study on brain tumor segmentation","author":"sheller","year":"2018","journal-title":"Proc Int MICCAI Brainlesion Workshop"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-60548-3_17"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1038\/s41598-020-69250-1"},{"key":"ref40","article-title":"A general approach to adding differential privacy to iterative training procedures","author":"mcmahan","year":"2018","journal-title":"arXiv 1812 06210"},{"key":"ref35","first-page":"1","article-title":"Differential privacy has disparate impact on model accuracy","volume":"32","author":"bagdasaryan","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1038\/s41598-022-05539-7"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813687"},{"key":"ref36","article-title":"Systematic evaluation of privacy risks of machine learning models","author":"song","year":"2020","journal-title":"arXiv 2003 10595"},{"key":"ref31","first-page":"133","article-title":"Privacy-preserving federated brain tumour segmentation","author":"li","year":"2019","journal-title":"Proc Int Workshop Mach Learn Med Imag"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1038\/s41598-021-93030-0"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2020.07.009"},{"key":"ref32","article-title":"Differentially private federated learning with Laplacian smoothing","author":"liang","year":"2020","journal-title":"arXiv 2005 00218"},{"key":"ref2","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","author":"mcmahan","year":"2017","journal-title":"Proc 20th Int Conf Artif Intell Statist"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1038\/s41746-020-00323-1"},{"key":"ref39","article-title":"Local and central differential privacy for robustness and privacy in federated learning","author":"naseri","year":"2020","journal-title":"arXiv 2009 03561"},{"key":"ref38","first-page":"493","article-title":"Batchcrypt: Efficient homomorphic encryption for cross-silo federated learning","author":"zhang","year":"2020","journal-title":"Proc USENIX Annu Tech Conf (USENIX ATC)"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00874"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref26","article-title":"Local differential privacy and its applications: A comprehensive survey","author":"yang","year":"2020","journal-title":"arXiv 2008 03686"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/11681878_14"},{"key":"ref20","first-page":"1","article-title":"Deep leakage from gradients","volume":"32","author":"zhu","year":"2019","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref27","article-title":"Understanding the sparse vector technique for differential privacy","author":"lyu","year":"2016","journal-title":"arXiv 1603 01699"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00220"}],"container-title":["IEEE Transactions on Medical Imaging"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/42\/10168838\/10025466.pdf?arnumber=10025466","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,7,17]],"date-time":"2023-07-17T17:43:05Z","timestamp":1689615785000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10025466\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,7]]},"references-count":56,"journal-issue":{"issue":"7"},"URL":"https:\/\/doi.org\/10.1109\/tmi.2023.3239391","relation":{},"ISSN":["0278-0062","1558-254X"],"issn-type":[{"value":"0278-0062","type":"print"},{"value":"1558-254X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,7]]}}}