{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T14:33:37Z","timestamp":1784644417940,"version":"3.55.0"},"reference-count":56,"publisher":"Privacy Enhancing Technologies Symposium Advisory Board","issue":"2","license":[{"start":{"date-parts":[[2022,3,3]],"date-time":"2022-03-03T00:00:00Z","timestamp":1646265600000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/3.0"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,4,1]]},"abstract":"<jats:title>Abstract<\/jats:title>\n               <jats:p>Vertical federated learning (VFL), a variant of federated learning, has recently attracted increasing attention. An <jats:italic>active party<\/jats:italic> having the true labels jointly trains a model with other parties (referred to as <jats:italic>passive parties<\/jats:italic>) in order to use more features to achieve higher model accuracy. During the prediction phase, all the parties collaboratively compute the predicted confidence scores of each target record and the results will be finally returned to the active party. However, a recent study by Luo <jats:italic>et al<\/jats:italic>. [28] pointed out that the active party can use these confidence scores to reconstruct passive-party features and cause severe privacy leakage.<\/jats:p>\n               <jats:p>In this paper, we conduct a comprehensive analysis of privacy leakage in VFL frameworks during the prediction phase. Our study improves on previous work [28] regarding two aspects. We first design a general gradient-based reconstruction attack framework that can be flexibly applied to simple logistic regression models as well as multi-layer neural networks. Moreover, besides performing the attack under the white-box setting, we give the first attempt to conduct the attack under the black-box setting. Extensive experiments on a number of real-world datasets show that our proposed attack is effective under different settings and can achieve at best twice or thrice of a reduction of attack error compared to previous work [28]. We further analyze a list of potential mitigation approaches and compare their privacy-utility performances. Experimental results demonstrate that privacy leakage from the confidence scores is a <jats:italic>substantial<\/jats:italic> privacy risk in VFL frameworks during the prediction phase, which cannot be simply solved by crypto-based confidentiality approaches. On the other hand, processing the confidence scores with information compression and randomization approaches can provide strengthened privacy protection.<\/jats:p>","DOI":"10.2478\/popets-2022-0045","type":"journal-article","created":{"date-parts":[[2022,3,5]],"date-time":"2022-03-05T04:35:06Z","timestamp":1646454906000},"page":"263-281","source":"Crossref","is-referenced-by-count":41,"title":["Comprehensive Analysis of Privacy Leakage in Vertical Federated Learning During Prediction"],"prefix":"10.56553","volume":"2022","author":[{"given":"Xue","family":"Jiang","sequence":"first","affiliation":[{"name":"Technical University of Munich ; Huawei Technologies D\u00fcsseldorf GmbH"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xuebing","family":"Zhou","sequence":"additional","affiliation":[{"name":"Huawei Technologies D\u00fcsseldorf GmbH"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jens","family":"Grossklags","sequence":"additional","affiliation":[{"name":"Technical University of Munich"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"35752","published-online":{"date-parts":[[2022,3,3]]},"reference":[{"key":"2022060207221359739_j_popets-2022-0045_ref_001","doi-asserted-by":"crossref","unstructured":"[1] Mart\u00edn Abadi, Andy Chu, Ian J. Goodfellow, H. Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pages 308\u2013318. ACM, 2016.10.1145\/2976749.2978318","DOI":"10.1145\/2976749.2978318"},{"key":"2022060207221359739_j_popets-2022-0045_ref_002","unstructured":"[2] Nick Angelou, Ayoub Benaissa, Bogdan Cebere, William Clark, Adam James Hall, Michael A. Hoeh, Daniel Liu, Pavlos Papadopoulos, Robin Roehm, Robert Sandmann, Phillipp Schoppmann, and Tom Titcombe. Asymmetric private set intersection with applications to contact tracing and private vertical federated machine learning. CoRR, abs\/2011.09350, 2020."},{"key":"2022060207221359739_j_popets-2022-0045_ref_003","unstructured":"[3] Sean Augenstein, H. Brendan McMahan, Daniel Ramage, Swaroop Ramaswamy, Peter Kairouz, Mingqing Chen, Rajiv Mathews, and Blaise Ag\u00fcera y Arcas. Generative models for effective ML on private, decentralized datasets. In 8th International Conference on Learning Representations. OpenReview.net, 2020."},{"key":"2022060207221359739_j_popets-2022-0045_ref_004","doi-asserted-by":"crossref","unstructured":"[4] L\u00e9on Bottou. Large-scale machine learning with stochastic gradient descent. In 19th International Conference on Computational Statistics, pages 177\u2013186, 2010.10.1007\/978-3-7908-2604-3_16","DOI":"10.1007\/978-3-7908-2604-3_16"},{"key":"2022060207221359739_j_popets-2022-0045_ref_005","unstructured":"[5] Nicholas Carlini, Chang Liu, \u00dalfar Erlingsson, Jernej Kos, and Dawn Song. The secret sharer: Evaluating and testing unintended memorization in neural networks. In 28th USENIX Security Symposium, pages 267\u2013284, 2019."},{"key":"2022060207221359739_j_popets-2022-0045_ref_006","unstructured":"[6] Tianyi Chen, Xiao Jin, Yuejiao Sun, and Wotao Yin. VAFL: A method of vertical asynchronous federated learning. CoRR, abs\/2007.06081, 2020."},{"key":"2022060207221359739_j_popets-2022-0045_ref_007","doi-asserted-by":"crossref","unstructured":"[7] Kewei Cheng, Tao Fan, Yilun Jin, Yang Liu, Tianjian Chen, Dimitrios Papadopoulos, and Qiang Yang. Secureboost: A lossless federated learning framework. IEEE Intelligent Systems, 2021.10.1109\/MIS.2021.3082561","DOI":"10.1109\/MIS.2021.3082561"},{"key":"2022060207221359739_j_popets-2022-0045_ref_008","doi-asserted-by":"crossref","unstructured":"[8] Emiliano De Cristofaro and Gene Tsudik. Practical private set intersection protocols with linear complexity. In 14th International Conference on Financial Cryptography and Data Security, volume 6052 of Lecture Notes in Computer Science, pages 143\u2013159. Springer, 2010.10.1007\/978-3-642-14577-3_13","DOI":"10.1007\/978-3-642-14577-3_13"},{"key":"2022060207221359739_j_popets-2022-0045_ref_009","doi-asserted-by":"crossref","unstructured":"[9] Ivan Damg\u00e5rd and Mads Jurik. A generalisation, a simplification and some applications of Paillier\u2019s probabilistic public-key system. In Kwangjo Kim, editor, Public Key Cryptography, 4th International Workshop on Practice and Theory in Public Key Cryptography, volume 1992 of Lecture Notes in Computer Science, pages 119\u2013136. Springer, 2001.10.1007\/3-540-44586-2_9","DOI":"10.1007\/3-540-44586-2_9"},{"key":"2022060207221359739_j_popets-2022-0045_ref_010","unstructured":"[10] Dheeru Dua and Casey Graff. UCI machine learning repository, 2017. http:\/\/archive.ics.uci.edu\/ml."},{"key":"2022060207221359739_j_popets-2022-0045_ref_011","doi-asserted-by":"crossref","unstructured":"[11] Cynthia Dwork and Aaron Roth. The algorithmic foundations of differential privacy. Foundations and Trends in Theoretical Computer Science, 9(3-4):211\u2013407, 2014.10.1561\/0400000042","DOI":"10.1561\/0400000042"},{"key":"2022060207221359739_j_popets-2022-0045_ref_012","unstructured":"[12] Siwei Feng and Han Yu. Multi-participant multi-class vertical federated learning. CoRR, abs\/2001.11154, 2020."},{"key":"2022060207221359739_j_popets-2022-0045_ref_013","doi-asserted-by":"crossref","unstructured":"[13] Michael J. Freedman, Kobbi Nissim, and Benny Pinkas. Efficient private matching and set intersection. In International Conference on the Theory and Applications of Cryptographic Techniques, volume 3027 of Lecture Notes in Computer Science, pages 1\u201319. Springer, 2004.10.1007\/978-3-540-24676-3_1","DOI":"10.1007\/978-3-540-24676-3_1"},{"key":"2022060207221359739_j_popets-2022-0045_ref_014","doi-asserted-by":"crossref","unstructured":"[14] Ananda L. Freire, Guilherme A. Barreto, Marcus Veloso, and Antonio T. Varela. Short-term memory mechanisms in neural network learning of robot navigation tasks: A case study. In 6th Latin American Robotics Symposium, pages 1\u20136. IEEE, 2009.10.1109\/LARS.2009.5418323","DOI":"10.1109\/LARS.2009.5418323"},{"key":"2022060207221359739_j_popets-2022-0045_ref_015","unstructured":"[15] Jonas Geiping, Hartmut Bauermeister, Hannah Dr\u00f6ge, and Michael Moeller. Inverting gradients - How easy is it to break privacy in federated learning? In Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020. Curran Associates Inc., 2020."},{"key":"2022060207221359739_j_popets-2022-0045_ref_016","unstructured":"[16] Andrew Hard, Kanishka Rao, Rajiv Mathews, Fran\u00e7oise Beaufays, Sean Augenstein, Hubert Eichner, Chlo\u00e9 Kiddon, and Daniel Ramage. Federated learning for mobile keyboard prediction. CoRR, abs\/1811.03604, 2018."},{"key":"2022060207221359739_j_popets-2022-0045_ref_017","unstructured":"[17] Stephen Hardy, Wilko Henecka, Hamish Ivey-Law, Richard Nock, Giorgio Patrini, Guillaume Smith, and Brian Thorne. Private federated learning on vertically partitioned data via entity resolution and additively homomorphic encryption. CoRR, abs\/1711.10677, 2017."},{"key":"2022060207221359739_j_popets-2022-0045_ref_018","doi-asserted-by":"crossref","unstructured":"[18] Briland Hitaj, Giuseppe Ateniese, and Fernando P\u00e9rez-Cruz. Deep models under the GAN: Information leakage from collaborative deep learning. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pages 603\u2013618. ACM, 2017.10.1145\/3133956.3134012","DOI":"10.1145\/3133956.3134012"},{"key":"2022060207221359739_j_popets-2022-0045_ref_019","unstructured":"[19] Yaochen Hu, Di Niu, Jianming Yang, and Shengping Zhou. FDML: A collaborative machine learning framework for distributed features. In Ankur Teredesai, Vipin Kumar, Ying Li, R\u00f3mer Rosales, Evimaria Terzi, and George Karypis, editors, Proceedings of the 25th ACM SIGKDD International Conference on Knowledge Discovery & Data Mining, pages 2232\u20132240, 2019."},{"key":"2022060207221359739_j_popets-2022-0045_ref_020","unstructured":"[20] Yan Huang, David Evans, and Jonathan Katz. Private set intersection: Are garbled circuits better than custom protocols? In 19th Annual Network and Distributed System Security Symposium. The Internet Society, 2012."},{"key":"2022060207221359739_j_popets-2022-0045_ref_021","unstructured":"[21] Bargav Jayaraman and David Evans. Evaluating differentially private machine learning in practice. In 28th USENIX Security Symposium, pages 1895\u20131912. USENIX Association, 2019."},{"key":"2022060207221359739_j_popets-2022-0045_ref_022","doi-asserted-by":"crossref","unstructured":"[22] Xue Jiang, Xuebing Zhou, and Jens Grossklags. Privacy-preserving high-dimensional data collection with federated generative autoencoder. Proceedings on Privacy Enhancing Technologies, 2022(1):481\u2013500, 2022.10.2478\/popets-2022-0024","DOI":"10.2478\/popets-2022-0024"},{"key":"2022060207221359739_j_popets-2022-0045_ref_023","unstructured":"[23] Diederik P. Kingma and Jimmy Ba. Adam: A method for stochastic optimization. In 3rd International Conference on Learning Representations, ICLR 2015, Conference Track Proceedings, 2015."},{"key":"2022060207221359739_j_popets-2022-0045_ref_024","doi-asserted-by":"crossref","unstructured":"[24] Wenqi Li, Fausto Milletar\u00ec, Daguang Xu, Nicola Rieke, Jonny Hancox, Wentao Zhu, Maximilian Baust, Yan Cheng, S\u00e9bastien Ourselin, M. Jorge Cardoso, and Andrew Feng. Privacy-preserving federated brain tumour segmentation. In 10th International Workshop on Machine Learning in Medical Imaging, volume 11861 of Lecture Notes in Computer Science, pages 133\u2013141. Springer, 2019.10.1007\/978-3-030-32692-0_16","DOI":"10.1007\/978-3-030-32692-0_16"},{"key":"2022060207221359739_j_popets-2022-0045_ref_025","unstructured":"[25] Yang Liu, Yingting Liu, Zhijie Liu, Yuxuan Liang, Chuishi Meng, Junbo Zhang, and Yu Zheng. Federated forest. IEEE Transactions on Big Data, 2020.10.1109\/TBDATA.2020.2992755"},{"key":"2022060207221359739_j_popets-2022-0045_ref_026","unstructured":"[26] Linpeng Lu and Ning Ding. Multi-party private set intersection in vertical federated learning. In 19th IEEE International Conference on Trust, Security and Privacy in Computing and Communications, pages 707\u2013714. IEEE, 2020."},{"key":"2022060207221359739_j_popets-2022-0045_ref_027","unstructured":"[27] Songtao Lu, Yawen Zhang, and Yunlong Wang. Decentralized federated learning for electronic health records. In 54th Annual Conference on Information Sciences and Systems, pages 1\u20135. IEEE, 2020."},{"key":"2022060207221359739_j_popets-2022-0045_ref_028","unstructured":"[28] Xinjian Luo, Yuncheng Wu, Xiaokui Xiao, and Beng Chin Ooi. Feature inference attack on model predictions in vertical federated learning. In 37th IEEE International Conference on Data Engineering, pages 181\u2013192. IEEE, 2021."},{"key":"2022060207221359739_j_popets-2022-0045_ref_029","unstructured":"[29] Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Ag\u00fcera y Arcas. Communication-efficient learning of deep networks from decentralized data. In Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, volume 54 of Proceedings of Machine Learning Research, pages 1273\u20131282, 2017."},{"key":"2022060207221359739_j_popets-2022-0045_ref_030","doi-asserted-by":"crossref","unstructured":"[30] Luca Melis, Congzheng Song, Emiliano De Cristofaro, and Vitaly Shmatikov. Exploiting unintended feature leakage in collaborative learning. In 2019 IEEE Symposium on Security and Privacy, pages 691\u2013706. IEEE, 2019.10.1109\/SP.2019.00029","DOI":"10.1109\/SP.2019.00029"},{"key":"2022060207221359739_j_popets-2022-0045_ref_031","doi-asserted-by":"crossref","unstructured":"[31] S\u00e9rgio Moro, Paulo Cortez, and Paulo Rita. A data-driven approach to predict the success of bank telemarketing. Decision Support Systems, 62:22\u201331, 2014.10.1016\/j.dss.2014.03.001","DOI":"10.1016\/j.dss.2014.03.001"},{"key":"2022060207221359739_j_popets-2022-0045_ref_032","doi-asserted-by":"crossref","unstructured":"[32] Milad Nasr, Reza Shokri, and Amir Houmansadr. Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In 2019 IEEE Symposium on Security and Privacy, pages 739\u2013753. IEEE, 2019.10.1109\/SP.2019.00065","DOI":"10.1109\/SP.2019.00065"},{"key":"2022060207221359739_j_popets-2022-0045_ref_033","unstructured":"[33] Fabian Pedregosa, Ga\u00ebl Varoquaux, Alexandre Gramfort, Vincent Michel, Bertrand Thirion, Olivier Grisel, Mathieu Blondel, Peter Prettenhofer, Ron Weiss, Vincent Dubourg, et al. Scikit-learn: Machine learning in Python. The Journal of Machine Learning Research, 12:2825\u20132830, 2011."},{"key":"2022060207221359739_j_popets-2022-0045_ref_034","doi-asserted-by":"crossref","unstructured":"[34] Le Trieu Phong, Yoshinori Aono, Takuya Hayashi, Lihua Wang, and Shiho Moriai. Privacy-preserving deep learning via additively homomorphic encryption. IEEE Transactions on Information Forensics and Security, 13(5):1333\u20131345, 2017.10.1109\/TIFS.2017.2787987","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"2022060207221359739_j_popets-2022-0045_ref_035","unstructured":"[35] Swaroop Ramaswamy, Rajiv Mathews, Kanishka Rao, and Fran\u00e7oise Beaufays. Federated learning for emoji prediction in a mobile keyboard. CoRR, abs\/1906.04329, 2019."},{"key":"2022060207221359739_j_popets-2022-0045_ref_036","unstructured":"[36] Daniele Romanini, Adam James Hall, Pavlos Papadopoulos, Tom Titcombe, Abbas Ismail, Tudor Cebere, Robert Sandmann, Robin Roehm, and Michael A. Hoeh. PyVertical: A vertical federated learning framework for multi-headed splitNN. CoRR, abs\/2104.00489, 2021."},{"key":"2022060207221359739_j_popets-2022-0045_ref_037","unstructured":"[37] Stacey Truex, Ling Liu, Mehmet Emre Gursoy, Lei Yu, and Wenqi Wei. Demystifying membership inference attacks in machine learning as a service. IEEE Transactions on Services Computing, 2019."},{"key":"2022060207221359739_j_popets-2022-0045_ref_038","doi-asserted-by":"crossref","unstructured":"[38] Jaideep Vaidya and Chris Clifton. Privacy preserving association rule mining in vertically partitioned data. In Proceedings of the Eighth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pages 639\u2013644. ACM, 2002.10.1145\/775047.775142","DOI":"10.1145\/775047.775142"},{"key":"2022060207221359739_j_popets-2022-0045_ref_039","doi-asserted-by":"crossref","unstructured":"[39] Jaideep Vaidya and Chris Clifton. Privacy-preserving k-means clustering over vertically partitioned data. In Proceedings of the Ninth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pages 206\u2013215. ACM, 2003.10.1145\/956750.956776","DOI":"10.1145\/956750.956776"},{"key":"2022060207221359739_j_popets-2022-0045_ref_040","doi-asserted-by":"crossref","unstructured":"[40] Jaideep Vaidya and Chris Clifton. Privacy preserving naive Bayes classifier for vertically partitioned data. In Proceedings of the 2004 SIAM International Conference on Data Mining, pages 522\u2013526. SIAM, 2004.10.1137\/1.9781611972740.59","DOI":"10.1137\/1.9781611972740.59"},{"key":"2022060207221359739_j_popets-2022-0045_ref_041","doi-asserted-by":"crossref","unstructured":"[41] Jaideep Vaidya, Chris Clifton, Murat Kantarcioglu, and Scott Patterson. Privacy-preserving decision trees over vertically partitioned data. ACM Transactions on Knowledge Discovery from Data, 2(3):1\u201327, 2008.10.1145\/1409620.1409624","DOI":"10.1145\/1409620.1409624"},{"key":"2022060207221359739_j_popets-2022-0045_ref_042","unstructured":"[42] Chang Wang, Jian Liang, Mingkai Huang, Bing Bai, Kun Bai, and Hao Li. Hybrid differentially private federated learning on vertically partitioned data. CoRR, abs\/2009.02763, 2020."},{"key":"2022060207221359739_j_popets-2022-0045_ref_043","doi-asserted-by":"crossref","unstructured":"[43] Qian Wang, Minxin Du, Xiuying Chen, Yanjiao Chen, Pan Zhou, Xiaofeng Chen, and Xinyi Huang. Privacy-preserving collaborative model learning: The case of word vector training. IEEE Transactions on Knowledge and Data Engineering, 30(12):2381\u20132393, 2018.","DOI":"10.1109\/TKDE.2018.2819673"},{"key":"2022060207221359739_j_popets-2022-0045_ref_044","doi-asserted-by":"crossref","unstructured":"[44] Yichuan Wang, Yuying Tian, Xinyue Yin, and Xinhong Hei. A trusted recommendation scheme for privacy protection based on federated learning. CCF Transactions on Networking, 3(3-4):218\u2013228, 2020.10.1007\/s42045-020-00045-8","DOI":"10.1007\/s42045-020-00045-8"},{"key":"2022060207221359739_j_popets-2022-0045_ref_045","unstructured":"[45] Haiqin Weng, Juntao Zhang, Feng Xue, Tao Wei, Shouling Ji, and Zhiyuan Zong. Privacy leakage of real-world vertical federated learning. CoRR, abs\/2011.09290, 2020."},{"key":"2022060207221359739_j_popets-2022-0045_ref_046","doi-asserted-by":"crossref","unstructured":"[46] Yuncheng Wu, Shaofeng Cai, Xiaokui Xiao, Gang Chen, and Beng Chin Ooi. Privacy preserving vertical federated learning for tree-based models. Proceedings of the VLDB Endowment, 13(11):2090\u20132103, 2020.10.14778\/3407790.3407811","DOI":"10.14778\/3407790.3407811"},{"key":"2022060207221359739_j_popets-2022-0045_ref_047","unstructured":"[47] Bangzhou Xin, Wei Yang, Yangyang Geng, Sheng Chen, Shaowei Wang, and Liusheng Huang. Private fl-gan: Differential privacy synthetic data generation based on federated learning. In 2020 IEEE International Conference on Acoustics, Speech and Signal Processing, pages 2927\u20132931. IEEE, 2020."},{"key":"2022060207221359739_j_popets-2022-0045_ref_048","unstructured":"[48] Kai Yang, Tao Fan, Tianjian Chen, Yuanming Shi, and Qiang Yang. A quasi-Newton method based vertical federated learning framework for logistic regression. CoRR, abs\/1912.00513, 2019."},{"key":"2022060207221359739_j_popets-2022-0045_ref_049","doi-asserted-by":"crossref","unstructured":"[49] Liu Yang, Ben Tan, Vincent W. Zheng, Kai Chen, and Qiang Yang. Federated recommendation systems. In Federated Learning - Privacy and Incentive, volume 12500 of Lecture Notes in Computer Science, pages 225\u2013239. Springer, 2020.10.1007\/978-3-030-63076-8_16","DOI":"10.1007\/978-3-030-63076-8_16"},{"key":"2022060207221359739_j_popets-2022-0045_ref_050","doi-asserted-by":"crossref","unstructured":"[50] Qiang Yang, Yang Liu, Tianjian Chen, and Yongxin Tong. Federated machine learning: Concept and applications. ACM Transactions on Intelligent Systems and Technology, 10(2):12:1\u201312:19, 2019.","DOI":"10.1145\/3298981"},{"key":"2022060207221359739_j_popets-2022-0045_ref_051","unstructured":"[51] Shengwen Yang, Bing Ren, Xuhui Zhou, and Liping Liu. Parallel distributed logistic regression for vertical federated learning without third-party coordinator. CoRR, abs\/1911.09824, 2019."},{"key":"2022060207221359739_j_popets-2022-0045_ref_052","unstructured":"[52] Ziqi Yang, Bin Shao, Bohan Xuan, Ee-Chien Chang, and Fan Zhang. Defending model inversion and membership inference attacks via prediction purification. CoRR, abs\/2005.03915, 2020."},{"key":"2022060207221359739_j_popets-2022-0045_ref_053","unstructured":"[53] Andrew Chi-Chih Yao. Protocols for secure computations (extended abstract). In 23rd Annual Symposium on Foundations of Computer Science, pages 160\u2013164. IEEE Computer Society, 1982."},{"key":"2022060207221359739_j_popets-2022-0045_ref_054","doi-asserted-by":"crossref","unstructured":"[54] Hwanjo Yu, Jaideep Vaidya, and Xiaoqian Jiang. Privacy-preserving SVM classification on vertically partitioned data. In 10th Pacific-Asia Conference on Knowledge Discovery and Data Mining, volume 3918 of Lecture Notes in Computer Science, pages 647\u2013656. Springer, 2006.10.1007\/11731139_74","DOI":"10.1007\/11731139_74"},{"key":"2022060207221359739_j_popets-2022-0045_ref_055","unstructured":"[55] Bo Zhao, Konda Reddy Mopuri, and Hakan Bilen. iDLG: Improved deep leakage from gradients. CoRR, abs\/2001.02610, 2020."},{"key":"2022060207221359739_j_popets-2022-0045_ref_056","unstructured":"[56] Ligeng Zhu, Zhijian Liu, and Song Han. Deep leakage from gradients. In Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems, pages 14747\u201314756, 2019."}],"container-title":["Proceedings on Privacy Enhancing Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.sciendo.com\/pdf\/10.2478\/popets-2022-0045","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,7,20]],"date-time":"2022-07-20T16:32:04Z","timestamp":1658334724000},"score":1,"resource":{"primary":{"URL":"https:\/\/petsymposium.org\/popets\/2022\/popets-2022-0045.php"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,3]]},"references-count":56,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2022,3,3]]},"published-print":{"date-parts":[[2022,4,1]]}},"alternative-id":["10.2478\/popets-2022-0045"],"URL":"https:\/\/doi.org\/10.2478\/popets-2022-0045","relation":{},"ISSN":["2299-0984"],"issn-type":[{"value":"2299-0984","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3,3]]}}}