{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,15]],"date-time":"2025-08-15T02:32:55Z","timestamp":1755225175478,"version":"3.43.0"},"publisher-location":"New York, NY, USA","reference-count":44,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,8,25]]},"DOI":"10.1145\/3708821.3733865","type":"proceedings-article","created":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T06:30:56Z","timestamp":1755066656000},"page":"501-516","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Unraveling Elevated Data Leakage in Split Learning for Fine-Tuning Stable Diffusion Models"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1084-0690","authenticated-orcid":false,"given":"Fei","family":"Wang","sequence":"first","affiliation":[{"name":"University of Toronto, Toronto, Ontario, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6932-7971","authenticated-orcid":false,"given":"Yan","family":"Zhu","sequence":"additional","affiliation":[{"name":"University of California, Berkeley, Berkeley, California, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2404-0974","authenticated-orcid":false,"given":"Baochun","family":"Li","sequence":"additional","affiliation":[{"name":"University of Toronto, Toronto, Ontario, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,8,24]]},"reference":[{"key":"e_1_3_3_2_2_2","unstructured":"[n. d.]. gettyimages. https:\/\/www.gettyimages.ca\/."},{"key":"e_1_3_3_2_3_2","unstructured":"[n. d.]. The Hugging Face Hub. https:\/\/huggingface.co\/models."},{"key":"e_1_3_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_3_2_6_2","unstructured":"Tim Dockhorn Tianshi Cao Arash Vahdat and Karsten Kreis. 2023. Differentially Private Diffusion Models. Transactions on Machine Learning Research (2023)."},{"key":"e_1_3_3_2_7_2","volume-title":"Proc.\u00a0International Conference on Learning Representations (ICLR)","author":"Dosovitskiy Alexey","year":"2021","unstructured":"Alexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn, Xiaohua Zhai, Thomas Unterthiner, Mostafa Dehghani, Matthias Minderer, Georg Heigold, Sylvain Gelly, Jakob Uszkoreit, and Neil Houlsby. 2021. An Image is Worth 16x16 Words: Transformers for Image Recognition at Scale. In Proc.\u00a0International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.522"},{"key":"e_1_3_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1145\/3559613.3563201"},{"key":"e_1_3_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_3_2_11_2","doi-asserted-by":"crossref","unstructured":"Rinon Gal Or Patashnik Haggai Maron Amit\u00a0H Bermano Gal Chechik and Daniel Cohen-Or. 2022. StyleGAN-NADA: CLIP-Guided Domain Adaptation of Image Generators. ACM Transactions on Graphics (TOG) 41 4 (2022) 1\u201313.","DOI":"10.1145\/3528223.3530164"},{"key":"e_1_3_3_2_12_2","first-page":"5271","volume-title":"Proc.\u00a0the 32nd USENIX Security Symposium","author":"Gao Xinben","year":"2023","unstructured":"Xinben Gao and Lan Zhang. 2023. PCAT: Functionality and Data Stealing from Split Learning by Pseudo-Client Attack. In Proc.\u00a0the 32nd USENIX Security Symposium. 5271\u20135288."},{"key":"e_1_3_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359824"},{"key":"e_1_3_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.595"},{"key":"e_1_3_3_2_16_2","volume-title":"Proc.\u00a0International Conference on Learning Representations (ICLR)","author":"Hjelm R\u00a0Devon","year":"2019","unstructured":"R\u00a0Devon Hjelm, Alex Fedorov, Samuel Lavoie-Marchildon, Karan Grewal, Phil Bachman, Adam Trischler, and Yoshua Bengio. 2019. Learning Deep Representations by Mutual Information Estimation and Maximization. In Proc.\u00a0International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_3_2_17_2","volume-title":"Proc.\u00a0International Conference on Learning Representations (ICLR)","author":"Hu Edward\u00a0J","year":"2022","unstructured":"Edward\u00a0J Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu, Yuanzhi Li, Shean Wang, Lu Wang, and Weizhu Chen. 2022. LoRA: Low-Rank Adaptation of Large Language Models. In Proc.\u00a0International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_3_2_18_2","unstructured":"Yangsibo Huang Samyak Gupta Zhao Song Kai Li and Sanjeev Arora. 2021. Evaluating Gradient Inversion Attacks and Defenses in Federated Learning. Advances in Neural Information Processing Systems (NeurIPS) 34 (2021) 7232\u20137241."},{"key":"e_1_3_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00453"},{"key":"e_1_3_3_2_20_2","unstructured":"Alex Krizhevsky Vinod Nair and Geoffrey Hinton. [n. d.]. CIFAR-100 (Canadian Institute for Advanced Research). https:\/\/www.cs.toronto.edu\/\u00a0kriz\/cifar.html. Accessed: 2023-10."},{"key":"e_1_3_3_2_21_2","doi-asserted-by":"crossref","unstructured":"Y. Lecun L. Bottou Y. Bengio and P. Haffner. 1998. Gradient-Based Learning Applied to Document Recognition. Proc.\u00a0the IEEE 86 11 (1998) 2278\u20132324.","DOI":"10.1109\/5.726791"},{"key":"e_1_3_3_2_22_2","volume-title":"Advances in Neural Information Processing Systems (NeurIPS)","author":"Li Ziang","year":"2023","unstructured":"Ziang Li, Mengda Yang, Yaxin Liu, Juan Wang, Hongxin Hu, Wenzhe Yi, and Xiaoyang Xu. 2023. GAN You See Me? Enhanced Data Reconstruction Attacks against Split Inference. In Advances in Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7299155"},{"key":"e_1_3_3_2_24_2","unstructured":"Sourab Mangrulkar Sylvain Gugger Lysandre Debut Younes Belkada and Sayak Paul. 2022. PEFT: State-of-the-Art Parameter-Efficient Fine-Tuning Methods. https:\/\/github.com\/huggingface\/peft."},{"key":"e_1_3_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2017.11"},{"key":"e_1_3_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00509"},{"key":"e_1_3_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485259"},{"key":"e_1_3_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"e_1_3_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24574-4_28"},{"key":"e_1_3_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02155"},{"key":"e_1_3_3_2_31_2","volume-title":"Proc.\u00a0International Conference on Learning Representations (ICLR)","author":"Simonyan Karen","year":"2014","unstructured":"Karen Simonyan and Andrew Zisserman. 2014. Very Deep Convolutional Networks for Large-Scale Image Recognition. In Proc.\u00a0International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_3_2_32_2","unstructured":"Nitish Srivastava Geoffrey Hinton Alex Krizhevsky Ilya Sutskever and Ruslan Salakhutdinov. 2014. Dropout: A Simple Way to Prevent Neural Networks from Overfitting. Journal of Machine Learning Research 15 56 (2014) 1929\u20131958. http:\/\/jmlr.org\/papers\/v15\/srivastava14a.html"},{"key":"e_1_3_3_2_33_2","unstructured":"Tom Titcombe Adam\u00a0J Hall Pavlos Papadopoulos and Daniele Romanini. 2021. Practical Defences against Model Inversion Attacks for Split Neural Networks. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2104.05743 ICLR Workshop on Distributed and Private Machine Learning (2021)."},{"key":"e_1_3_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"e_1_3_3_2_35_2","unstructured":"Praneeth Vepakomma Otkrist Gupta Tristan Swedish and Ramesh Raskar. 2018. Split Learning for Health: Distributed Deep Learning without Sharing Raw Patient Data. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1812.00564 ICLR AI for Social Good Workshop (2018)."},{"key":"e_1_3_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDMW51313.2020.00134"},{"key":"e_1_3_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM53939.2023.10228919"},{"key":"e_1_3_3_2_38_2","volume-title":"Proc.\u00a0International Conference on Learning Representations (ICLR)","author":"Wang Yulin","year":"2021","unstructured":"Yulin Wang, Zanlin Ni, Shiji Song, Le Yang, and Gao Huang. 2021. Revisiting Locally Supervised Learning: an Alternative to End-to-end Training. In Proc.\u00a0International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_3_2_39_2","doi-asserted-by":"crossref","unstructured":"Zhou Wang A.C. Bovik H.R. Sheikh and E.P. Simoncelli. 2004. Image Quality Assessment: From Error Visibility to Structural Similarity. IEEE Transactions on Image Processing 13 4 (2004) 600\u2013612.","DOI":"10.1109\/TIP.2003.819861"},{"key":"e_1_3_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58951-6_27"},{"key":"e_1_3_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354261"},{"key":"e_1_3_3_2_42_2","volume-title":"NeurIPS 2021 Workshop Privacy in Machine Learning","author":"Yousefpour Ashkan","year":"2021","unstructured":"Ashkan Yousefpour, Igor Shilov, Alexandre Sablayrolles, Davide Testuggine, Karthik Prasad, Mani Malek, John Nguyen, Sayan Ghosh, Akash Bharadwaj, Jessica Zhao, Graham Cormode, and Ilya Mironov. 2021. Opacus: User-Friendly Differential Privacy Library in PyTorch. In NeurIPS 2021 Workshop Privacy in Machine Learning."},{"key":"e_1_3_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00068"},{"key":"e_1_3_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"e_1_3_3_2_45_2","unstructured":"Yanchong Zheng. 2021. Dropout against Deep Leakage from Gradients. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2108.11106 (2021)."}],"event":{"name":"ASIA CCS '25: 20th ACM Asia Conference on Computer and Communications Security","location":"Hanoi Vietnam","acronym":"ASIA CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 20th ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3708821.3733865","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T07:31:06Z","timestamp":1755070266000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3708821.3733865"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,24]]},"references-count":44,"alternative-id":["10.1145\/3708821.3733865","10.1145\/3708821"],"URL":"https:\/\/doi.org\/10.1145\/3708821.3733865","relation":{},"subject":[],"published":{"date-parts":[[2025,8,24]]},"assertion":[{"value":"2025-08-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}