{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T07:50:00Z","timestamp":1782978600246,"version":"3.54.5"},"reference-count":47,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,6,21]],"date-time":"2026-06-21T00:00:00Z","timestamp":1782000000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"},{"start":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T00:00:00Z","timestamp":1782950400000},"content-version":"vor","delay-in-days":11,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0"}],"funder":[{"DOI":"10.13039\/501100001784","name":"Victoria University","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100001784","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Brain Inf."],"published-print":{"date-parts":[[2026,12]]},"DOI":"10.1186\/s40708-026-00313-1","type":"journal-article","created":{"date-parts":[[2026,6,21]],"date-time":"2026-06-21T06:25:29Z","timestamp":1782023129000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Evaluating multi-level membership inference risk in federated EEG learning"],"prefix":"10.1186","volume":"13","author":[{"given":"Taslima","family":"Khanam","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Siuly","family":"Siuly","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kate","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Frank","family":"Whittaker","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hua","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,21]]},"reference":[{"key":"313_CR1","doi-asserted-by":"crossref","unstructured":"Praveena HD, Subhas C, Lakshmi AJ, Venkatanaresh M, Geetha P (2025) Foundations of brain informatics: an overview. Brain Inform Technol 1\u201323","DOI":"10.1002\/9781394345625.ch1"},{"issue":"1","key":"313_CR2","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1186\/s40708-021-00141-5","volume":"8","author":"P Patel","year":"2021","unstructured":"Patel P, R. R, and, Annavarapu RN (2021) EEG-based human emotion recognition using entropy as a feature extraction measure. Brain Inf 8(1):20","journal-title":"Brain Inf"},{"issue":"1","key":"313_CR3","doi-asserted-by":"publisher","first-page":"13","DOI":"10.1186\/s40708-025-00260-3","volume":"12","author":"MNA Tawhid","year":"2025","unstructured":"Tawhid MNA, Siuly S, Kabir E, Li Y (2025) Advancing Alzheimer\u2019s disease detection: a novel convolutional neural network based framework leveraging EEG data and segment length analysis: MN Ahad Tawhid et al. Brain Inf 12(1):13","journal-title":"Brain Inf"},{"issue":"10","key":"313_CR4","doi-asserted-by":"publisher","first-page":"e0335511","DOI":"10.1371\/journal.pone.0335511","volume":"20","author":"T Khanam","year":"2025","unstructured":"Khanam T, Siuly S, Ahmad K, Wang H (2025) A novel channel reduction concept to enhance the classification of motor imagery tasks in brain-computer interface systems. PLoS ONE 20(10):e0335511","journal-title":"PLoS ONE"},{"issue":"1","key":"313_CR5","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1109\/MC.2017.9","volume":"50","author":"M Satyanarayanan","year":"2017","unstructured":"Satyanarayanan M (2017) The emergence of edge computing. Computer 50(1):30\u201339","journal-title":"Computer"},{"key":"313_CR6","doi-asserted-by":"publisher","first-page":"106775","DOI":"10.1016\/j.knosys.2021.106775","volume":"216","author":"C Zhang","year":"2021","unstructured":"Zhang C, Xie Y, Bai H, Yu B, Li W, Gao Y (2021) A survey on federated learning. Knowl Based Syst 216:106775","journal-title":"Knowl Based Syst"},{"key":"313_CR7","doi-asserted-by":"crossref","unstructured":"Kurupathi SR, Maass W (2020) Survey on federated learning towards privacy preserving AI. Proc Comput Sci Inf Technol (CSIT) 1\u201319","DOI":"10.5121\/csit.2020.101120"},{"key":"313_CR8","first-page":"374","volume":"1","author":"K Bonawitz","year":"2019","unstructured":"Bonawitz K et al (2019) Towards federated learning at scale: system design. Proc Mach Learn Syst 1:374\u2013388","journal-title":"Proc Mach Learn Syst"},{"issue":"3","key":"313_CR9","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1109\/MSP.2020.2975749","volume":"37","author":"T Li","year":"2020","unstructured":"Li T, Sahu AK, Talwalkar A, Smith V (2020) Federated learning: challenges, methods, and future directions. IEEE Signal Process Mag 37(3):50\u201360","journal-title":"IEEE Signal Process Mag"},{"key":"313_CR10","doi-asserted-by":"crossref","unstructured":"Kaikaus M, Ahmed S, Yousuf MA, Moni MA (2024) SeizureFed: federated learning for pediatric seizure detection through EEG using E-ResNet. In: Proceedings of the 3rd international conference on computing advancements, pp 838\u2013846","DOI":"10.1145\/3723178.3723289"},{"key":"313_CR11","doi-asserted-by":"publisher","first-page":"3442","DOI":"10.1109\/TNSRE.2024.3457504","volume":"32","author":"T Jia","year":"2024","unstructured":"Jia T, Meng L, Li S, Liu J, Wu D (2024) Federated motor imagery classification for privacy-preserving brain-computer interfaces. IEEE Trans Neural Syst Rehabil Eng 32:3442\u20133451","journal-title":"IEEE Trans Neural Syst Rehabil Eng"},{"issue":"4","key":"313_CR12","doi-asserted-by":"publisher","first-page":"3061","DOI":"10.1109\/TNET.2024.3377655","volume":"32","author":"F Wang","year":"2024","unstructured":"Wang F, Hugh E, Li B (2024) More than enough is too much: adaptive defenses against gradient leakage in production federated learning. IEEE\/ACM Trans Netw 32(4):3061\u20133075","journal-title":"IEEE\/ACM Trans Networking"},{"key":"313_CR13","unstructured":"Hasan J (2023) Security and privacy issues of federated learning, arXiv preprint arXiv:2307.12181"},{"key":"313_CR14","doi-asserted-by":"crossref","unstructured":"Salem A, Zhang Y, Humbert M, Berrang P, Fritz M, Backes M (2018) Ml-leaks: model and data independent membership inference attacks and defenses on machine learning models, arXiv preprint arXiv:1806.01246","DOI":"10.14722\/ndss.2019.23119"},{"key":"313_CR15","doi-asserted-by":"crossref","unstructured":"Nasr M, Shokri R, Houmansadr A (2019) Comprehensive privacy analysis of deep learning: passive and active white-box inference attacks against centralized and federated learning. In: 2019 IEEE symposium on security and privacy (SP). IEEE, pp 739\u2013753","DOI":"10.1109\/SP.2019.00065"},{"key":"313_CR16","doi-asserted-by":"crossref","unstructured":"Melis L, Song C, De Cristofaro E, Shmatikov V (2019) Exploiting unintended feature leakage in collaborative learning. In: 2019 IEEE symposium on security and privacy (SP). IEEE, pp 691\u2013706","DOI":"10.1109\/SP.2019.00029"},{"key":"313_CR17","doi-asserted-by":"crossref","unstructured":"Guo P et al (2025) A new federated learning framework against gradient inversion attacks. In: Proceedings of the AAAI conference on artificial intelligence, vol. 39, no. 16, pp 16969\u201316977","DOI":"10.1609\/aaai.v39i16.33865"},{"key":"313_CR18","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1561\/0400000042","volume":"9","author":"C Dwork","year":"2014","unstructured":"Dwork C, Roth A (2014) The algorithmic foundations of differential privacy. Found Trends\u00ae Theor Comput Sci 9:3\u20134","journal-title":"Found Trends\u00ae Theoretical Comput Sci"},{"key":"313_CR19","unstructured":"Jayaraman B, Evans D (2019) Evaluating differentially private machine learning in practice. In: 28th USENIX security symposium (USENIX security 19), pp 1895\u20131912"},{"key":"313_CR20","doi-asserted-by":"crossref","unstructured":"Abadi M et al (2016) Deep learning with differential privacy. In: Proceedings of the 2016 ACM SIGSAC conference on computer and communications security, pp 308\u2013318","DOI":"10.1145\/2976749.2978318"},{"key":"313_CR21","doi-asserted-by":"crossref","unstructured":"Mironov I (2017), August R\u00e9nyi differential privacy. In: 2017 IEEE 30th computer security foundations symposium (CSF). IEEE, pp 263\u2013275","DOI":"10.1109\/CSF.2017.11"},{"issue":"4","key":"313_CR22","first-page":"1","volume":"57","author":"L Bai","year":"2024","unstructured":"Bai L, Hu H, Ye Q, Li H, Wang L, Xu J (2024) Membership inference attacks and defenses in federated learning: a survey. ACM-CSUR 57(4):1\u201335","journal-title":"ACM-CSUR"},{"key":"313_CR23","doi-asserted-by":"crossref","unstructured":"Wang X, Wang N, Wu L, Guan Z, Du X, Guizani M GBMIA: gradient-based membership inference attack in federated learning. In: ICC (2023) -IEEE international conference on communications, 2023. IEEE, pp 5066\u20135071","DOI":"10.1109\/ICC45041.2023.10279702"},{"issue":"6","key":"313_CR24","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3460427","volume":"54","author":"X Yin","year":"2021","unstructured":"Yin X, Zhu Y, Hu J (2021) A comprehensive survey of privacy-preserving federated learning: a taxonomy, review, and future directions. ACM Comput Surv (CSUR) 54(6):1\u201336","journal-title":"ACM Comput Surv (CSUR)"},{"key":"313_CR25","doi-asserted-by":"crossref","unstructured":"Shokri R, Stronati M, Song C, Shmatikov V (2017) Membership inference attacks against machine learning models. In: 2017 IEEE symposium on security and privacy (SP). IEEE, pp 3\u201318","DOI":"10.1109\/SP.2017.41"},{"key":"313_CR26","doi-asserted-by":"crossref","unstructured":"Yang Y et al (2023) Fortifying federated learning against membership inference attacks via client-level input perturbation. In: 2023 53rd annual IEEE\/IFIP international conference on dependable systems and networks (DSN). IEEE, pp 288\u2013301","DOI":"10.1109\/DSN58367.2023.00037"},{"key":"313_CR27","doi-asserted-by":"publisher","first-page":"106768","DOI":"10.1016\/j.neunet.2024.106768","volume":"181","author":"F Ahmed","year":"2025","unstructured":"Ahmed F, Sanchez D, Haddi Z, Domingo-Ferrer J (2025) MemberShield: a framework for federated learning with membership privacy. Neural Netw 181:106768","journal-title":"Neural Netw"},{"key":"313_CR28","doi-asserted-by":"publisher","first-page":"120068","DOI":"10.1016\/j.ins.2023.120068","volume":"658","author":"X Wang","year":"2024","unstructured":"Wang X, Wu L, Guan Z (2024) GradDiff: gradient-based membership inference attacks against federated distillation with differential comparison. Inf Sci 658:120068","journal-title":"Inf Sci"},{"issue":"1","key":"313_CR29","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1186\/s40708-020-00105-1","volume":"7","author":"MK Siddiqui","year":"2020","unstructured":"Siddiqui MK, Morales-Menendez R, Huang X, Hussain N (2020) A review of epileptic seizure detection using machine learning classifiers. Brain Inf 7(1):5","journal-title":"Brain Inf"},{"issue":"4","key":"313_CR30","doi-asserted-by":"publisher","first-page":"1491","DOI":"10.1007\/s12008-020-00715-3","volume":"14","author":"MK Siddiqui","year":"2020","unstructured":"Siddiqui MK, Huang X, Morales-Menendez R, Hussain N, Khatoon K (2020) Machine learning based novel cost-sensitive seizure detection classifier for imbalanced EEG data sets. Int J Interact Des Manuf (IJIDeM) 14(4):1491\u20131509","journal-title":"Int J Interact Des Manuf (IJIDeM)"},{"issue":"5","key":"313_CR31","doi-asserted-by":"publisher","first-page":"2312","DOI":"10.1109\/TCSS.2022.3184818","volume":"10","author":"K Xia","year":"2022","unstructured":"Xia K et al (2022) Privacy-preserving brain\u2013computer interfaces: a systematic review. IEEE Trans Comput Social Syst 10(5):2312\u20132324","journal-title":"IEEE Trans Comput Social Syst"},{"key":"313_CR32","doi-asserted-by":"crossref","unstructured":"Cobilean V, Mavikumbure HS, Drake D, Stuart M, Manic M (2025) Investigating membership inference attacks against CNN models for BCI systems. IEEE J Biomed Health Inf","DOI":"10.1109\/JBHI.2025.3593443"},{"key":"313_CR33","doi-asserted-by":"crossref","unstructured":"Khanam T, Siuly S, Wang K, Wang H (2024) Based-BCI technology. In: Health information science: 13th International Conference, HIS Hong Kong, China, December 8\u201310, 2024, Proceedings, 2025, vol. 15336. Springer Nature, p 209","DOI":"10.1007\/978-981-96-5597-7_19"},{"key":"313_CR34","doi-asserted-by":"crossref","unstructured":"Khanam T, Siuly S, Wang K, Zheng Z (2024) A privacy-preserving encryption framework for big data analysis. In: International Conference on Web Information Systems Engineering. Springer, pp 84\u201394","DOI":"10.1007\/978-981-96-0576-7_7"},{"issue":"3","key":"313_CR35","doi-asserted-by":"publisher","first-page":"036057","DOI":"10.1088\/1741-2552\/ad593b","volume":"21","author":"J Jin","year":"2024","unstructured":"Jin J et al (2024) A cross-dataset adaptive domain selection transfer learning framework for motor imagery-based brain-computer interfaces. J Neural Eng 21(3):036057","journal-title":"J Neural Eng"},{"key":"313_CR36","doi-asserted-by":"publisher","first-page":"119","DOI":"10.1016\/j.patrec.2017.12.017","volume":"126","author":"S Barra","year":"2019","unstructured":"Barra S, Fraschini M, Casanova A, Castiglione A, Fenu G (2019) PhysioUnicaDB: a dataset of EEG and ECG simultaneously acquired. Pattern Recognit Lett 126:119\u2013122","journal-title":"Pattern Recognit Lett"},{"key":"313_CR37","doi-asserted-by":"crossref","unstructured":"Naseri M, Fernandez-Marques J, Gao Y, Pan H (2024) Privacy-preserving federated learning using flower framework. In: Proceedings of the 30th ACM SIGKDD conference on knowledge discovery and data mining, pp 6422\u20136423","DOI":"10.1145\/3637528.3671447"},{"issue":"4","key":"313_CR38","doi-asserted-by":"publisher","first-page":"83","DOI":"10.3390\/jsan14040083","volume":"14","author":"C Aggarwal","year":"2025","unstructured":"Aggarwal C, Nair DG, Mohammadi JA, Nair JJ, Ott J (2025) Can differential privacy hinder poisoning attack detection in federated learning? J Sens Actuator Netw 14(4):83","journal-title":"J Sens Actuator Networks"},{"key":"313_CR39","doi-asserted-by":"crossref","unstructured":"Chen X, Jia T, Wu D (2024) A3E: aligned and augmented adversarial ensemble for accurate, robust and privacy-preserving EEG decoding, arXiv preprint arXiv:2412.11390","DOI":"10.2139\/ssrn.5414878"},{"issue":"1","key":"313_CR40","first-page":"1","volume":"4","author":"R Sarathy","year":"2011","unstructured":"Sarathy R, Muralidhar K (2011) Evaluating laplace noise addition to satisfy differential privacy for numeric data. Trans Data Priv 4(1):1\u201317","journal-title":"Trans Data Priv"},{"key":"313_CR41","doi-asserted-by":"crossref","unstructured":"Nasr M, Shokri R, Houmansadr A (2018), October Machine learning with membership privacy using adversarial regularization. In: Proceedings of the 2018 ACM SIGSAC conference on computer and communications security, pp 634\u2013646","DOI":"10.1145\/3243734.3243855"},{"issue":"1","key":"313_CR42","doi-asserted-by":"publisher","first-page":"5","DOI":"10.1023\/A:1010933404324","volume":"45","author":"L Breiman","year":"2001","unstructured":"Breiman L (2001) Random forests. Mach Learn 45(1):5\u201332","journal-title":"Mach Learn"},{"issue":"4","key":"313_CR43","doi-asserted-by":"publisher","first-page":"2555","DOI":"10.1109\/JIOT.2021.3089713","volume":"9","author":"X Yuan","year":"2021","unstructured":"Yuan X, Ma X, Zhang L, Fang Y, Wu D (2021) Beyond class-level privacy leakage: Breaking record-level privacy in federated learning. IEEE Internet Things J 9(4):2555\u20132565","journal-title":"IEEE Internet Things J"},{"key":"313_CR44","doi-asserted-by":"publisher","first-page":"6650","DOI":"10.1109\/TIFS.2024.3404857","volume":"19","author":"Z Li","year":"2024","unstructured":"Li Z, Ren M, Li Q, Jiang F, Sun Z (2024) Improving transferability of adversarial samples via critical region-oriented feature-level attack. IEEE Trans Inf Forensics Secur 19:6650\u20136664","journal-title":"IEEE Trans Inf Forensics Secur"},{"key":"313_CR45","doi-asserted-by":"crossref","unstructured":"Wu H, Shi L, Ye J, Fan Y, Lv Z (2024) The client-level GAN-based data reconstruction attack and defense in clustered federated learning. In: International conference on wireless artificial intelligent computing systems and application. Springer, pp 466\u2013478","DOI":"10.1007\/978-3-031-71464-1_38"},{"key":"313_CR46","unstructured":"Zhu L, Liu Z, Han S (2019) Deep leakage from gradients. Adv Neural Inf Process Syst 32"},{"key":"313_CR47","first-page":"16937","volume":"33","author":"J Geiping","year":"2020","unstructured":"Geiping J, Bauermeister H, Dr\u00f6ge H, Moeller M (2020) Inverting gradients-how easy is it to break privacy in federated learning? Adv Neural Inf Process Syst 33:16937\u201316947","journal-title":"Adv Neural Inf Process Syst"}],"container-title":["Brain Informatics"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s40708-026-00313-1","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s40708-026-00313-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s40708-026-00313-1.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T07:21:33Z","timestamp":1782976893000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s40708-026-00313-1"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,21]]},"references-count":47,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2026,12]]}},"alternative-id":["313"],"URL":"https:\/\/doi.org\/10.1186\/s40708-026-00313-1","relation":{},"ISSN":["2198-4018","2198-4026"],"issn-type":[{"value":"2198-4018","type":"print"},{"value":"2198-4026","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,21]]},"assertion":[{"value":"8 January 2026","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"9 June 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"21 June 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"This study uses publicly available anonymised EEG datasets and therefore did not require institutional ethics approval.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"The authors declare no competing interests.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"26"}}