{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:41:51Z","timestamp":1784302911417,"version":"3.55.0"},"reference-count":134,"publisher":"MDPI AG","issue":"1","license":[{"start":{"date-parts":[[2022,12,20]],"date-time":"2022-12-20T00:00:00Z","timestamp":1671494400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001659","name":"Deutsche Forschungsgemeinschaft (DFG, German Research Foundation)","doi-asserted-by":"publisher","award":["251805230\/GRK2050"],"award-info":[{"award-number":["251805230\/GRK2050"]}],"id":[{"id":"10.13039\/501100001659","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Sensors"],"abstract":"<jats:p>Deep learning pervades heavy data-driven disciplines in research and development. The Internet of Things and sensor systems, which enable smart environments and services, are settings where deep learning can provide invaluable utility. However, the data in these systems are very often directly or indirectly related to people, which raises privacy concerns. Federated learning (FL) mitigates some of these concerns and empowers deep learning in sensor-driven environments by enabling multiple entities to collaboratively train a machine learning model without sharing their data. Nevertheless, a number of works in the literature propose attacks that can manipulate the model and disclose information about the training data in FL. As a result, there has been a growing belief that FL is highly vulnerable to severe attacks. Although these attacks do indeed highlight security and privacy risks in FL, some of them may not be as effective in production deployment because they are feasible only given special\u2014sometimes impractical\u2014assumptions. In this paper, we investigate this issue by conducting a quantitative analysis of the attacks against FL and their evaluation settings in 48 papers. This analysis is the first of its kind to reveal several research gaps with regard to the types and architectures of target models. Additionally, the quantitative analysis allows us to highlight unrealistic assumptions in some attacks related to the hyper-parameters of the model and data distribution. Furthermore, we identify fallacies in the evaluation of attacks which raise questions about the generalizability of the conclusions. As a remedy, we propose a set of recommendations to promote adequate evaluations.<\/jats:p>","DOI":"10.3390\/s23010031","type":"journal-article","created":{"date-parts":[[2022,12,21]],"date-time":"2022-12-21T02:31:33Z","timestamp":1671589893000},"page":"31","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":19,"title":["Federated Learning Attacks Revisited: A Critical Discussion of Gaps, Assumptions, and Evaluation Setups"],"prefix":"10.3390","volume":"23","author":[{"given":"Aidmar","family":"Wainakh","sequence":"first","affiliation":[{"name":"Telecooperation Lab, Technical University of Darmstadt, 64289 Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4262-6613","authenticated-orcid":false,"given":"Ephraim","family":"Zimmer","sequence":"additional","affiliation":[{"name":"Telecooperation Lab, Technical University of Darmstadt, 64289 Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sandeep","family":"Subedi","sequence":"additional","affiliation":[{"name":"Telecooperation Lab, Technical University of Darmstadt, 64289 Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jens","family":"Keim","sequence":"additional","affiliation":[{"name":"Telecooperation Lab, Technical University of Darmstadt, 64289 Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tim","family":"Grube","sequence":"additional","affiliation":[{"name":"Telecooperation Lab, Technical University of Darmstadt, 64289 Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shankar","family":"Karuppayah","sequence":"additional","affiliation":[{"name":"National Advanced IPv6 Centre (NAv6), University of Science Malaysia, Penang 11800, Malaysia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Alejandro","family":"Sanchez Guinea","sequence":"additional","affiliation":[{"name":"Telecooperation Lab, Technical University of Darmstadt, 64289 Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Max","family":"M\u00fchlh\u00e4user","sequence":"additional","affiliation":[{"name":"Telecooperation Lab, Technical University of Darmstadt, 64289 Darmstadt, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2022,12,20]]},"reference":[{"key":"ref_1","unstructured":"Arp, D., Quiring, E., Pendlebury, F., Warnecke, A., Pierazzi, F., Wressnegger, C., Cavallaro, L., and Rieck, K. (2020). Dos and Do nots of Machine Learning in Computer Security. arXiv."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"281","DOI":"10.1049\/cit2.12003","article-title":"SDN-based intrusion detection system for IoT using deep learning classifier (IDSIoT-SDL)","volume":"6","author":"Wani","year":"2021","journal-title":"CAAI Trans. Intell. Technol."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Chen, Z. (2022). Research on Internet Security Situation Awareness Prediction Technology based on Improved RBF Neural Network Algorithm. J. Comput. Cogn. Eng., 1.","DOI":"10.47852\/bonviewJCCE149145205514"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Yao, Y., Peng, Z., Xiao, B., and Guan, J. (2017, January 21\u201325). An efficient learning-based approach to multi-objective route planning in a smart city. Proceedings of the 2017 IEEE International Conference on Communications (ICC), Paris, France.","DOI":"10.1109\/ICC.2017.7997454"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"2701","DOI":"10.1109\/TMC.2018.2879933","article-title":"When urban safety index inference meets location-based data","volume":"18","author":"Peng","year":"2018","journal-title":"IEEE Trans. Mob. Comput."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"155","DOI":"10.1109\/MWC.001.1900559","article-title":"Real-time cache-aided route planning based on mobile edge computing","volume":"27","author":"Yao","year":"2020","journal-title":"IEEE Wirel. Commun."},{"key":"ref_7","unstructured":"Lin, J., Chen, W.M., Cai, H., Gan, C., and Han, S. (2021, January 6\u201314). MCUNetV2: Memory-Efficient Patch-based Inference for Tiny Deep Learning. Proceedings of the Annual Conference on Neural Information Processing Systems (NeurIPS), Virtual."},{"key":"ref_8","unstructured":"Mirshghallah, F., Taram, M., Vepakomma, P., Singh, A., Raskar, R., and Esmaeilzadeh, H. (2020). Privacy in deep learning: A survey. arXiv."},{"key":"ref_9","unstructured":"McMahan, H.B., Moore, E., Ramage, D., Hampson, S., and Arcas, B.A. (2016). Communication-efficient learning of deep networks from decentralized data. arXiv."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"108426","DOI":"10.1016\/j.compeleceng.2022.108426","article-title":"A secure cryptosystem using DNA cryptography and DNA steganography for the cloud-based IoT infrastructure","volume":"104","author":"Namasudra","year":"2022","journal-title":"Comput. Electr. Eng."},{"key":"ref_11","first-page":"585","article-title":"A new table based protocol for data accessing in cloud computing","volume":"33","author":"Namasudra","year":"2017","journal-title":"J. Inf. Sci. Eng."},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"102835","DOI":"10.1016\/j.jnca.2020.102835","article-title":"DNA computing and table based data accessing in the cloud environment","volume":"172","author":"Namasudra","year":"2020","journal-title":"J. Netw. Comput. Appl."},{"key":"ref_13","first-page":"18","article-title":"An efficient and time saving web service based android application","volume":"2","author":"Sarkar","year":"2015","journal-title":"SSRG Int. J. Comput. Sci. Eng. (SSRG-IJCSE)"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Gutub, A. (2022). Boosting image watermarking authenticity spreading secrecy from counting-based secret-sharing. CAAI Trans. Intell. Technol.","DOI":"10.1049\/cit2.12093"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Verma, R., Kumari, A., Anand, A., and Yadavalli, V. (2022). Revisiting Shift Cipher Technique for Amplified Data Security. J. Comput. Cogn. Eng.","DOI":"10.47852\/bonviewJCCE2202261"},{"key":"ref_16","unstructured":"Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D., and Shmatikov, V. (2020, January 26\u201328). How to backdoor federated learning. Proceedings of the International Conference on Artificial Intelligence and Statistics, Virtual."},{"key":"ref_17","unstructured":"Bhagoji, A.N., Chakraborty, S., Mittal, P., and Calo, S. (2018, January 3\u20138). Model poisoning attacks in federated learning. Proceedings of the 32nd Conference on Neural Information Processing Systems, Montr\u00e9al, QC, Canada."},{"key":"ref_18","unstructured":"Hitaj, B., Ateniese, G., and Perez-Cruz, F. (November, January 30). Deep Models under the GAN: Information leakage from collaborative deep learning. Proceedings of the ACM Conference on Computer and Communications Security, Dallas, TX, USA."},{"key":"ref_19","unstructured":"Zhu, L., Liu, Z., and Han, S. (2019, January 8\u201314). Deep leakage from gradients. Proceedings of the Advances in Neural Information Processing Systems, Vancouver, BC, Canada."},{"key":"ref_20","unstructured":"Zhao, B., Mopuri, K.R., and Bilen, H. (2020). iDLG: Improved Deep Leakage from Gradients. arXiv."},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Zhang, J., Zhang, J., Chen, J., and Yu, S. (2020, January 7\u201311). GAN Enhanced Membership Inference: A Passive Local Attack in Federated Learning. Proceedings of the ICC 2020-2020 IEEE International Conference on Communications (ICC), Dublin, Ireland.","DOI":"10.1109\/ICC40277.2020.9148790"},{"key":"ref_22","doi-asserted-by":"crossref","unstructured":"Enthoven, D., and Al-Ars, Z. (2021). Fidel: Reconstructing private training samples from weight updates in federated learning. arXiv.","DOI":"10.1109\/IOTSMS58070.2022.10062088"},{"key":"ref_23","doi-asserted-by":"crossref","unstructured":"Shejwalkar, V., Houmansadr, A., Kairouz, P., and Ramage, D. (2021). Back to the drawing board: A critical evaluation of poisoning attacks on federated learning. arXiv.","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"ref_24","unstructured":"Kairouz, P., McMahan, H.B., Avent, B., Bellet, A., Bennis, M., Bhagoji, A.N., Bonawitz, K., Charles, Z., Cormode, G., and Cummings, R. (2019). Advances and open problems in federated learning. arXiv."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Wang, Z., Song, M., Zhang, Z., Song, Y., Wang, Q., and Qi, H. (May, January 29). Beyond Inferring Class Representatives: Client-Level Privacy Leakage from Federated Learning. Proceedings of the 38th Annual IEEE International Conference on Computer Communications (INFOCOM 2019), Paris, France.","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"ref_26","doi-asserted-by":"crossref","unstructured":"Wainakh, A., Guinea, A.S., Grube, T., and M\u00fchlh\u00e4user, M. (2020, January 7\u201311). Enhancing privacy via hierarchical federated learning. Proceedings of the 2020 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), Genoa, Italy.","DOI":"10.1109\/EuroSPW51379.2020.00053"},{"key":"ref_27","unstructured":"Nasr, M., Shokri, R., and Houmansadr, A. (2019, January 19\u201323). Comprehensive privacy analysis of deep learning. Proceedings of the 2019 IEEE Symposium on Security and Privacy, San Francisco, CA, USA."},{"key":"ref_28","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Sinha, A., and Wellman, M.P. (2018, January 24\u201326). Sok: Security and privacy in machine learning. Proceedings of the 2018 IEEE European Symposium on Security and Privacy (EuroS&P), London, UK.","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1109\/MSEC.2018.2888775","article-title":"Privacy-Preserving Machine Learning: Threats and Solutions","volume":"17","author":"Chang","year":"2019","journal-title":"IEEE Secur. Priv."},{"key":"ref_30","unstructured":"De Cristofaro, E. (2020). An Overview of Privacy in Machine Learning. arXiv."},{"key":"ref_31","unstructured":"Rigaki, M., and Garcia, S. (2020). A Survey of Privacy Attacks in Machine Learning. arXiv."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Zhang, J., Li, C., Ye, J., and Qu, G. (2020, January 7\u20139). Privacy Threats and Protection in Machine Learning. Proceedings of the 2020 on Great Lakes Symposium on VLSI, Knoxville, TN, USA.","DOI":"10.1145\/3386263.3407599"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"4566","DOI":"10.1109\/ACCESS.2020.3045078","article-title":"Privacy and Security Issues in Deep Learning: A Survey","volume":"9","author":"Liu","year":"2020","journal-title":"IEEE Access"},{"key":"ref_34","doi-asserted-by":"crossref","unstructured":"Enthoven, D., and Al-Ars, Z. (2020). An Overview of Federated Deep Learning Privacy Attacks and Defensive Strategies. arXiv.","DOI":"10.1007\/978-3-030-70604-3_8"},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Lyu, L., Yu, H., and Yang, Q. (2020). Threats to Federated Learning: A Survey. arXiv.","DOI":"10.1007\/978-3-030-63076-8_1"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"20","DOI":"10.1109\/MSEC.2020.3039941","article-title":"A Taxonomy of Attacks on Federated Learning","volume":"19","author":"Jere","year":"2020","journal-title":"IEEE Security Privacy"},{"key":"ref_37","unstructured":"Li, Q., Wen, Z., Wu, Z., Hu, S., Wang, N., and He, B. (2019). A survey on federated learning systems: Vision, hype and reality for data privacy and protection. arXiv."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"140699","DOI":"10.1109\/ACCESS.2020.3013541","article-title":"Federated learning: A survey on enabling technologies, protocols, and applications","volume":"8","author":"Aledhari","year":"2020","journal-title":"IEEE Access"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Petersen, K., Feldt, R., Mujtaba, S., and Mattsson, M. (2008, January 26\u201327). Systematic mapping studies in software engineering. Proceedings of the 12th International Conference on Evaluation and Assessment in Software Engineering (EASE), Bari, Italy.","DOI":"10.14236\/ewic\/EASE2008.8"},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.infsof.2015.03.007","article-title":"Guidelines for conducting systematic mapping studies in software engineering: An update","volume":"64","author":"Petersen","year":"2015","journal-title":"Inf. Softw. Technol."},{"key":"ref_41","unstructured":"Kitchenham, B., and Charters, S. (2007). Guidelines for Performing Systematic Literature Reviews in Software Engineering, University of Durham. EBSE Technical Report."},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Cummaudo, A., Vasa, R., and Grundy, J. (2019, January 19\u201320). What should I document? A preliminary systematic mapping study into API documentation knowledge. Proceedings of the 2019 ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM), Recife, Brazil.","DOI":"10.1109\/ESEM.2019.8870148"},{"key":"ref_43","first-page":"1","article-title":"Comparison of Software Design Models: An Extended Systematic Mapping Study","volume":"52","author":"Farias","year":"2019","journal-title":"ACM Comput. Surv. (CSUR)"},{"key":"ref_44","doi-asserted-by":"crossref","first-page":"102","DOI":"10.1007\/s00766-005-0021-6","article-title":"Requirements engineering paper classification and evaluation criteria: A proposal and a discussion","volume":"11","author":"Wieringa","year":"2006","journal-title":"Requir. Eng."},{"key":"ref_45","doi-asserted-by":"crossref","unstructured":"Bonawitz, K., Ivanov, V., Kreuter, B., Marcedone, A., McMahan, H.B., Patel, S., Ramage, D., Segal, A., and Seth, K. (November, January 30). Practical secure aggregation for privacy-preserving machine learning. Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, TX, USA.","DOI":"10.1145\/3133956.3133982"},{"key":"ref_46","unstructured":"McMahan, H.B., Ramage, D., Talwar, K., and Zhang, L. (2017). Learning differentially private language models without losing accuracy. arXiv."},{"key":"ref_47","unstructured":"Balle, B., Kairouz, P., McMahan, H.B., Thakkar, O., and Thakurta, A. (2020). Privacy Amplification via Random Check-Ins. arXiv."},{"key":"ref_48","doi-asserted-by":"crossref","unstructured":"Shokri, R., Stronati, M., Song, C., and Shmatikov, V. (2017, January 22\u201324). Membership inference attacks against machine learning models. Proceedings of the 2017 IEEE Symposium on Security and Privacy (SP), San Jose, CA, USA.","DOI":"10.1109\/SP.2017.41"},{"key":"ref_49","doi-asserted-by":"crossref","unstructured":"Ganju, K., Wang, Q., Yang, W., Gunter, C.A., and Borisov, N. (2018, January 15\u201319). Property inference attacks on fully connected neural networks using permutation invariant representations. Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, Toronto, ON, Canada.","DOI":"10.1145\/3243734.3243834"},{"key":"ref_50","doi-asserted-by":"crossref","unstructured":"Tolpegin, V., Truex, S., Gursoy, M.E., and Liu, L. (2020, January 14\u201318). Data Poisoning Attacks Against Federated Learning Systems. Proceedings of the European Symposium on Research in Computer Security, Guildford, UK.","DOI":"10.1007\/978-3-030-58951-6_24"},{"key":"ref_51","unstructured":"Fang, M., Cao, X., Jia, J., and Gong, N.Z. (2019). Local model poisoning attacks to Byzantine-robust federated learning. arXiv."},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Luo, X., Wu, Y., Xiao, X., and Ooi, B.C. (2020). Feature Inference Attack on Model Predictions in Vertical Federated Learning. arXiv.","DOI":"10.1109\/ICDE51399.2021.00023"},{"key":"ref_53","first-page":"135","article-title":"LOGAN: Membership Inference Attacks Against Generative Models","volume":"2019","author":"Hayes","year":"2019","journal-title":"Proc. Priv. Enhancing Technol."},{"key":"ref_54","unstructured":"Mahloujifar, S., Mahmoody, M., and Mohammed, A. (2019, January 10\u201315). Universal multi-party poisoning attacks. Proceedings of the 36th International Conference on Machine Learning ICML, Long Beach, CA, USA."},{"key":"ref_55","unstructured":"Xiao, H., Rasul, K., and Vollgraf, R. (2017). Fashion-mnist: A novel image dataset for benchmarking machine learning algorithms. arXiv."},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Pustozerova, A., and Mayer, R. (2020, January 23\u201326). Information Leaks in Federated Learning. Proceedings of the Network and Distributed System Security Symposium, San Diego, CA, USA.","DOI":"10.14722\/diss.2020.23004"},{"key":"ref_57","doi-asserted-by":"crossref","unstructured":"Shokri, R., and Shmatikov, V. (2015, January 12\u201316). Privacy-preserving deep learning. Proceedings of the 22nd ACM SIGSAC conference on Computer and Communications Security, Denver, CO, USA.","DOI":"10.1145\/2810103.2813687"},{"key":"ref_58","unstructured":"Kone\u010dn\u1ef3, J., McMahan, H.B., Yu, F.X., Richt\u00e1rik, P., Suresh, A.T., and Bacon, D. (2016). Federated learning: Strategies for improving communication efficiency. arXiv."},{"key":"ref_59","doi-asserted-by":"crossref","first-page":"2073","DOI":"10.1109\/TSC.2019.2897554","article-title":"Demystifying Membership Inference Attacks in Machine Learning as a Service","volume":"14","author":"Truex","year":"2019","journal-title":"IEEE Trans. Serv. Comput."},{"key":"ref_60","first-page":"1333","article-title":"Privacy-preserving deep learning via additively homomorphic encryption","volume":"13","author":"Aono","year":"2017","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref_61","unstructured":"Yin, D., Chen, Y., Ramchandran, K., and Bartlett, P. (2018). Byzantine-robust distributed learning: Towards optimal statistical rates. arXiv."},{"key":"ref_62","unstructured":"Shen, S., Tople, S., and Saxena, P. (2016, January 5\u20138). Auror: Defending against poisoning attacks in collaborative deep learning systems. Proceedings of the 32nd Annual Conference on Computer Security Applications, Los Angeles, CA, USA."},{"key":"ref_63","unstructured":"Chen, C.L., Golubchik, L., and Paolieri, M. (2020). Backdoor attacks on federated meta-learning. arXiv."},{"key":"ref_64","first-page":"14","article-title":"BlockShare: A Blockchain empowered system for privacy-preserving verifiable data sharing","volume":"1","author":"Peng","year":"2022","journal-title":"Bull. IEEE Comput. Soc. Tech. Commum. Data Eng."},{"key":"ref_65","doi-asserted-by":"crossref","first-page":"173","DOI":"10.1109\/TNSE.2021.3050781","article-title":"Vfchain: Enabling verifiable and auditable federated learning via blockchain systems","volume":"9","author":"Peng","year":"2021","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"ref_66","unstructured":"Dacrema, M.F., Cremonesi, P., and Jannach, D. (2019, January 16\u201320). Are We Really Making Much Progress? A Worrying Analysis of Recent Neural Recommendation Approaches. Proceedings of the 13th ACM Conference on Recommender Systems, Association for Computing Machinery, RecSys \u201919, Copenhagen, Denmark."},{"key":"ref_67","unstructured":"Bhagoji, A.N., Chakraborty, S., Mittal, P., and Calo, S. (2019, January 10\u201315). Analyzing federated learning through an adversarial lens. Proceedings of the 36th International Conference on Machine Learning, ICML, Long Beach, CA, USA."},{"key":"ref_68","unstructured":"Wang, L., Xu, S., Wang, X., and Zhu, Q. (2019). Eavesdrop the Composition Proportion of Training Labels in Federated Learning. arXiv."},{"key":"ref_69","doi-asserted-by":"crossref","unstructured":"Melis, L., Song, C., De Cristofaro, E., and Shmatikov, V. (2019, January 20\u201322). Exploiting unintended feature leakage in collaborative learning. Proceedings of the IEEE Symposium on Security and Privacy, San Francisco, CA, USA.","DOI":"10.1109\/SP.2019.00029"},{"key":"ref_70","doi-asserted-by":"crossref","unstructured":"Mao, Y., Zhu, X., Zheng, W., Yuan, D., and Ma, J. (2019, January 23\u201325). A Novel client Membership Leakage Attack in Collaborative Deep Learning. Proceedings of the 2019 11th International Conference on Wireless Communications and Signal Processing (WCSP), Xi\u2019an, China.","DOI":"10.1109\/WCSP.2019.8927871"},{"key":"ref_71","doi-asserted-by":"crossref","unstructured":"Liu, K.S., Xiao, C., Li, B., and Gao, J. (2019, January 8\u201311). Performing co-membership attacks against deep generative models. Proceedings of the IEEE International Conference on Data Mining, ICDM, Beijing, China.","DOI":"10.1109\/ICDM.2019.00056"},{"key":"ref_72","unstructured":"Sun, Z., Kairouz, P., Suresh, A.T., and McMahan, H.B. (2019). Can You Really Backdoor Federated Learning?. arXiv."},{"key":"ref_73","doi-asserted-by":"crossref","unstructured":"Zhang, J., Chen, J., Wu, D., Chen, B., and Yu, S. (2019, January 5\u20138). Poisoning attack in federated learning using generative adversarial nets. Proceedings of the 2019 18th IEEE International Conference on Trust, Security and Privacy in Computing and Communications\/13th IEEE International Conference on Big Data Science and Engineering, TrustCom\/BigDataSE, Rotorua, New Zealand.","DOI":"10.1109\/TrustCom\/BigDataSE.2019.00057"},{"key":"ref_74","first-page":"110061D","article-title":"Model poisoning attacks against distributed machine learning systems","volume":"Volume 11006","author":"Tomsett","year":"2019","journal-title":"Proceedings of the Artificial Intelligence and Machine Learning for Multi-Domain Operations Applications"},{"key":"ref_75","doi-asserted-by":"crossref","unstructured":"Cao, D., Chang, S., Lin, Z., Liu, G., and Sun, D. (2019, January 4\u20136). Understanding distributed poisoning attack in federated learning. Proceedings of the 2019 IEEE 25th International Conference on Parallel and Distributed Systems (ICPADS), Tianjin, China.","DOI":"10.1109\/ICPADS47876.2019.00042"},{"key":"ref_76","first-page":"8635","article-title":"A Little Is Enough: Circumventing Defenses For Distributed Learning","volume":"32","author":"Baruch","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"ref_77","unstructured":"Fung, C., Yoon, C.J., and Beschastnikh, I. (2018). Mitigating sybils in federated learning poisoning. arXiv."},{"key":"ref_78","unstructured":"Wei, W., Liu, L., Loper, M., Chow, K.H., Gursoy, M.E., Truex, S., and Wu, Y. (2020). A Framework for Evaluating Gradient Leakage Attacks in Federated Learning. arXiv."},{"key":"ref_79","unstructured":"Geiping, J., Bauermeister, H., Dr\u00f6ge, H., and Moeller, M. (2020). Inverting Gradients\u2014How easy is it to break privacy in federated learning?. arXiv."},{"key":"ref_80","unstructured":"Sun, G., Cong, Y., Dong, J., Wang, Q., and Liu, J. (2020). Data Poisoning Attacks on Federated Machine Learning. arXiv."},{"key":"ref_81","doi-asserted-by":"crossref","unstructured":"Nguyen, T.D., Rieger, P., Miettinen, M., and Sadeghi, A.R. (2020, January 23\u201326). Poisoning Attacks on Federated Learning-based IoT Intrusion Detection System. Proceedings of the Decentralized IoT Systems and Security (DISS), San Diego, CA, USA.","DOI":"10.14722\/diss.2020.23003"},{"key":"ref_82","doi-asserted-by":"crossref","first-page":"2430","DOI":"10.1109\/JSAC.2020.3000372","article-title":"Analyzing user-level privacy attack against federated learning","volume":"38","author":"Song","year":"2020","journal-title":"IEEE J. Sel. Areas Commun."},{"key":"ref_83","doi-asserted-by":"crossref","first-page":"3310","DOI":"10.1109\/JIOT.2020.3023126","article-title":"PoisonGAN: Generative Poisoning Attacks against Federated Learning in Edge Computing Systems","volume":"8","author":"Zhang","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_84","unstructured":"Zhu, J., and Blaschko, M. (2020). R-GAP: Recursive Gradient Attack on Privacy. arXiv."},{"key":"ref_85","unstructured":"Mo, F., Borovykh, A., Malekzadeh, M., Haddadi, H., and Demetriou, S. (2020). Layer-wise Characterization of Latent Information Leakage in Federated Learning. arXiv."},{"key":"ref_86","unstructured":"Wu, F. (November, January 30). PLFG: A Privacy Attack Method Based on Gradients for Federated Learning. Proceedings of the International Conference on Security and Privacy in Digital Economy, Quzhou, China."},{"key":"ref_87","unstructured":"Wang, Y., Deng, J., Guo, D., Wang, C., Meng, X., Liu, H., Ding, C., and Rajasekaran, S. (2020). SAPAG: A Self-Adaptive Privacy Attack From Gradients. arXiv."},{"key":"ref_88","first-page":"227","article-title":"Subject Property Inference Attack in Collaborative Learning","volume":"Volume 1","author":"Xu","year":"2020","journal-title":"Proceedings of the 2020 12th International Conference on Intelligent Human\u2013Machine Systems and Cybernetics (IHMSC)"},{"key":"ref_89","doi-asserted-by":"crossref","unstructured":"Chen, J., Zhang, J., Zhao, Y., Han, H., Zhu, K., and Chen, B. (2020, January 3\u20136). Beyond Model-Level Membership Privacy Leakage: An Adversarial Approach in Federated Learning. Proceedings of the 2020 29th International Conference on Computer Communications and Networks (ICCCN), Honolulu, HI, USA.","DOI":"10.1109\/ICCCN49398.2020.9209744"},{"key":"ref_90","unstructured":"Lu, H., Liu, C., He, T., Wang, S., and Chan, K.S. (2020). Sharing Models or Coresets: A Study based on Membership Inference Attack. arXiv."},{"key":"ref_91","doi-asserted-by":"crossref","unstructured":"Xu, X., Wu, J., Yang, M., Luo, T., Duan, X., Li, W., Wu, Y., and Wu, B. (2020, January 9\u201313). Information Leakage by Model Weights on Federated Learning. Proceedings of the 2020 Workshop on Privacy-Preserving Machine Learning in Practice, Virtual.","DOI":"10.1145\/3411501.3419423"},{"key":"ref_92","unstructured":"Qian, J., Nassar, H., and Hansen, L.K. (2020). Minimal conditions analysis of gradient-based reconstruction in Federated Learning. arXiv."},{"key":"ref_93","unstructured":"Xie, C., Koyejo, O., and Gupta, I. (2020, January 3\u20136). Fall of empires: Breaking Byzantine-tolerant SGD by inner product manipulation. Proceedings of the Uncertainty in Artificial Intelligence, Toronto, ON, Canada."},{"key":"ref_94","doi-asserted-by":"crossref","unstructured":"Wainakh, A., M\u00fc\u00dfig, T., Grube, T., and M\u00fchlh\u00e4user, M. (2021, January 9\u201312). Label leakage from gradients in distributed machine learning. Proceedings of the 2021 IEEE 18th Annual Consumer Communications & Networking Conference (CCNC), Las Vegas, NV, USA.","DOI":"10.1109\/CCNC49032.2021.9369498"},{"key":"ref_95","doi-asserted-by":"crossref","first-page":"2265","DOI":"10.1109\/JIOT.2020.3028110","article-title":"Exploiting Unintended Property Leakage in Blockchain-Assisted Federated Learning for Intelligent Edge Computing","volume":"8","author":"Shen","year":"2020","journal-title":"IEEE Internet Things J."},{"key":"ref_96","unstructured":"Fu, C., Zhang, X., Ji, S., Chen, J., Wu, J., Guo, S., Zhou, J., Liu, A.X., and Wang, T. (2022, January 10\u201312). Label Inference Attacks Against Vertical Federated Learning. Proceedings of the 31st USENIX Security Symposium (USENIX Security 22), Boston, MA, USA."},{"key":"ref_97","doi-asserted-by":"crossref","unstructured":"Wainakh, A., Ventola, F., M\u00fc\u00dfig, T., Keim, J., Cordero, C.G., Zimmer, E., Grube, T., Kersting, K., and M\u00fchlh\u00e4user, M. (2021). User Label Leakage from Gradients in Federated Learning. arXiv.","DOI":"10.2478\/popets-2022-0043"},{"key":"ref_98","doi-asserted-by":"crossref","unstructured":"Shejwalkar, V., and Houmansadr, A. (2021, January 21\u201325). Manipulating the Byzantine: Optimizing Model Poisoning Attacks and Defenses for Federated Learning. Proceedings of the Network and Distributed Systems Security (NDSS) Symposium 2021, Virtual.","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref_99","doi-asserted-by":"crossref","first-page":"479","DOI":"10.1109\/JSAIT.2021.3054610","article-title":"Turbo-Aggregate: Breaking the Quadratic Aggregation Barrier in Secure Federated Learning","volume":"2","author":"So","year":"2021","journal-title":"IEEE J. Sel. Areas Inf. Theory"},{"key":"ref_100","unstructured":"Hosseinalipour, S., Azam, S.S., Brinton, C.G., Michelusi, N., Aggarwal, V., Love, D.J., and Dai, H. (2020). Multi-stage hybrid federated learning over large-scale wireless fog networks. arXiv."},{"key":"ref_101","doi-asserted-by":"crossref","unstructured":"Liu, L., Zhang, J., Song, S., and Letaief, K. (2020, January 7\u201311). Client-edge-cloud hierarchical federated learning. Proceedings of the 2020 IEEE International Conference on Communications (ICC), Dublin, Ireland.","DOI":"10.1109\/ICC40277.2020.9148862"},{"key":"ref_102","doi-asserted-by":"crossref","unstructured":"Yates, A., Nogueira, R., and Lin, J. (2021, January 8\u201312). Pretrained Transformers for Text Ranking: BERT and Beyond. Proceedings of the 14th ACM International Conference on Web Search and Data Mining, Virtual.","DOI":"10.1145\/3437963.3441667"},{"key":"ref_103","doi-asserted-by":"crossref","first-page":"448","DOI":"10.1016\/j.ins.2020.09.001","article-title":"Exploiting relational tag expansion for dynamic user profile in a tag-aware ranking recommender system","volume":"545","author":"Pan","year":"2021","journal-title":"Inf. Sci."},{"key":"ref_104","doi-asserted-by":"crossref","unstructured":"Balaban, S. (2015). Deep learning and face recognition: The state of the art. arXiv.","DOI":"10.1117\/12.2181526"},{"key":"ref_105","first-page":"1","article-title":"High performance logistic regression for privacy-preserving genome analysis","volume":"14","author":"Dowsley","year":"2021","journal-title":"BMC Med. Genom."},{"key":"ref_106","doi-asserted-by":"crossref","first-page":"101203","DOI":"10.1016\/j.aei.2020.101203","article-title":"The use of decision tree based predictive models for improving the culvert inspection process","volume":"47","author":"Gao","year":"2021","journal-title":"Adv. Eng. Inform."},{"key":"ref_107","unstructured":"Yang, T., Andrew, G., Eichner, H., Sun, H., Li, W., Kong, N., Ramage, D., and Beaufays, F. (2018). Applied federated learning: Improving google keyboard query suggestions. arXiv."},{"key":"ref_108","unstructured":"Hard, A., Rao, K., Mathews, R., Ramaswamy, S., Beaufays, F., Augenstein, S., Eichner, H., Kiddon, C., and Ramage, D. (2018). Federated learning for mobile keyboard prediction. arXiv."},{"key":"ref_109","doi-asserted-by":"crossref","unstructured":"Abadi, M., McMahan, H.B., Chu, A., Mironov, I., Zhang, L., Goodfellow, I., and Talwar, K. (2016, January 24\u201328). Deep learning with differential privacy. Proceedings of the ACM Conference on Computer and Communications Security, Vienna, Austria.","DOI":"10.1145\/2976749.2978318"},{"key":"ref_110","unstructured":"Davenport, C. (2021, June 23). Gboard Passes One Billion Installs on the Play Store. Available online: https:\/\/www.androidpolice.com\/2018\/08\/22\/gboard-passes-one-billion-installs-play-store\/."},{"key":"ref_111","doi-asserted-by":"crossref","unstructured":"Jayaraman, B., Wang, L., Evans, D., and Gu, Q. (2020). Revisiting membership inference under realistic assumptions. arXiv.","DOI":"10.2478\/popets-2021-0031"},{"key":"ref_112","unstructured":"Long, Y., Bindschaedler, V., and Gunter, C.A. (2017). Towards measuring membership privacy. arXiv."},{"key":"ref_113","doi-asserted-by":"crossref","unstructured":"Salem, A., Zhang, Y., Humbert, M., Berrang, P., Fritz, M., and Backes, M. (2019, January 24\u201327). ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. Proceedings of the Network and Distributed Systems Security (NDSS) Symposium, San Diego, CA, USA.","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref_114","unstructured":"Hamner, B. (2021, May 31). Popular Datasets Over Time. Available online: https:\/\/www.kaggle.com\/benhamner\/popular-datasets-over-time\/code."},{"key":"ref_115","doi-asserted-by":"crossref","first-page":"2278","DOI":"10.1109\/5.726791","article-title":"Gradient-based learning applied to document recognition","volume":"86","author":"LeCun","year":"1998","journal-title":"Proc. IEEE"},{"key":"ref_116","unstructured":"Hargreaves, T. (2021, June 01). Is It Time to Ditch the MNIST Dataset?. 2020., Available online: https:\/\/www.ttested.com\/ditch-mnist\/."},{"key":"ref_117","doi-asserted-by":"crossref","unstructured":"Deng, J., Dong, W., Socher, R., Li, L.J., Li, K., and Fei-Fei, L. (2009, January 20\u201325). Imagenet: A large-scale hierarchical image database. Proceedings of the 2009 IEEE Conference on Computer Vision and Pattern Recognition, Miami, FL, USA.","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref_118","doi-asserted-by":"crossref","unstructured":"Goodfellow, I.J., Erhan, D., Carrier, P.L., Courville, A., Mirza, M., Hamner, B., Cukierski, W., Tang, Y., Thaler, D., and Lee, D.H. (2013, January 3\u20137). Challenges in representation learning: A report on three machine learning contests. Proceedings of the International Conference on Neural Information Processing, Daegu, Republic of Korea.","DOI":"10.1007\/978-3-642-42051-1_16"},{"key":"ref_119","unstructured":"Codella, N., Rotemberg, V., Tschandl, P., Celebi, M.E., Dusza, S., Gutman, D., Helba, B., Kalloo, A., Liopyris, K., and Marchetti, M. (2019). Skin lesion analysis toward melanoma detection 2018: A challenge hosted by the international skin imaging collaboration (isic). arXiv."},{"key":"ref_120","doi-asserted-by":"crossref","unstructured":"Cohen, G., Afshar, S., Tapson, J., and Van Schaik, A. (2017, January 14\u201319). EMNIST: Extending MNIST to handwritten letters. Proceedings of the 2017 International Joint Conference on Neural Networks (IJCNN), Anchorage, AK, USA.","DOI":"10.1109\/IJCNN.2017.7966217"},{"key":"ref_121","unstructured":"Luo, J., Wu, X., Luo, Y., Huang, A., Huang, Y., Liu, Y., and Yang, Q. (2019). Real-world image datasets for federated learning. arXiv."},{"key":"ref_122","unstructured":"Caldas, S., Wu, P., Li, T., Konecn\u00fd, J., McMahan, H.B., Smith, V., and Talwalkar, A. (2018). LEAF: A Benchmark for Federated Settings. arXiv."},{"key":"ref_123","unstructured":"Simonyan, K., and Zisserman, A. (2014). Very deep convolutional networks for large-scale image recognition. arXiv."},{"key":"ref_124","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., and Sun, J. (2016, January 27\u201330). Deep residual learning for image recognition. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Las Vegas, NV, USA.","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref_125","doi-asserted-by":"crossref","unstructured":"Huang, G., Liu, Z., Van Der Maaten, L., and Weinberger, K.Q. (2017, January 21\u201326). Densely connected convolutional networks. Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, Honolulu, HI, USA.","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref_126","doi-asserted-by":"crossref","first-page":"211","DOI":"10.1007\/s11263-015-0816-y","article-title":"ImageNet Large Scale Visual Recognition Challenge","volume":"115","author":"Russakovsky","year":"2015","journal-title":"Int. J. Comput. Vis. (IJCV)"},{"key":"ref_127","doi-asserted-by":"crossref","unstructured":"Kim, Y., Park, W., Roh, M.C., and Shin, J. (2020, January 13\u201319). Groupface: Learning latent groups and constructing group-based representations for face recognition. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, Seattle, WA, USA.","DOI":"10.1109\/CVPR42600.2020.00566"},{"key":"ref_128","unstructured":"Evtimov, I., Cui, W., Kamar, E., Kiciman, E., Kohno, T., and Li, J. (2020). Security and Machine Learning in the Real World. arXiv."},{"key":"ref_129","doi-asserted-by":"crossref","unstructured":"Liu, K., Dolan-Gavitt, B., and Garg, S. (2018, January 10\u201312). Fine-pruning: Defending against backdooring attacks on deep neural networks. Proceedings of the International Symposium on Research in Attacks, Intrusions, and Defenses, Heraklion, Greece.","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref_130","unstructured":"Tan, M., and Le, Q. (2019, January 9\u201315). Efficientnet: Rethinking model scaling for convolutional neural networks. Proceedings of the International Conference on Machine Learning, Long Beach, CA, USA."},{"key":"ref_131","doi-asserted-by":"crossref","first-page":"2222","DOI":"10.1109\/TNNLS.2016.2582924","article-title":"LSTM: A search space odyssey","volume":"28","author":"Greff","year":"2016","journal-title":"IEEE Trans. Neural Networks Learn. Syst."},{"key":"ref_132","unstructured":"Ryffel, T., Trask, A., Dahl, M., Wagner, B., Mancuso, J., Rueckert, D., and Passerat-Palmbach, J. (2018). A generic framework for privacy preserving deep learning. arXiv."},{"key":"ref_133","first-page":"1","article-title":"Federated learning","volume":"13","author":"Yang","year":"2019","journal-title":"Synth. Lect. Artif. Intell. Mach. Learn."},{"key":"ref_134","unstructured":"He, C., Li, S., Thus, J., Zhang, M., Wang, H., Wang, X., Vepakomma, P., Singh, A., Qiu, H., and Shen, L. (2020). Fedml: A research library and benchmark for federated machine learning. arXiv."}],"container-title":["Sensors"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/1\/31\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T01:44:53Z","timestamp":1760147093000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1424-8220\/23\/1\/31"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,20]]},"references-count":134,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2023,1]]}},"alternative-id":["s23010031"],"URL":"https:\/\/doi.org\/10.3390\/s23010031","relation":{},"ISSN":["1424-8220"],"issn-type":[{"value":"1424-8220","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,12,20]]}}}