REVIEW 3 major objections 6 minor 1 cited by
Membership Inference Attacks and Defenses in Federated Learning: A Survey
T0 review · 3 major / 6 minor · reviewed 2026-08-11 · deepseek-v4-flash
Pith's one-line read A survey of membership inference in federated learning claims the field splits into update-based and trend-based attacks, with four defense families.
desk verdict Useful FL-specific MIA survey, but the update/trend taxonomy needs a cleaner decision rule before the 'unique' claim holds. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The machinery that carries the survey is the two-branch attack taxonomy. Update-based attacks treat one or more exchanged model updates as evidence; they include original-gradient attacks, gradient-difference attacks, shadow-training attacks on a local or global model, and attacks that modify the model's structure (for example, embedding ReLU-gated neurons that only member samples activate). Trend-based attacks instead follow an indicator across rounds—the prediction score of the ground-truth label, the training loss, adversarial robustness, or final-layer bias—and compare its trajectory between members and non-members. On the defense side, the organizing machinery is the four-category split into partial sharing, secure aggregation, noise perturbation, and anomaly detection, with the survey using these categories to tabulate each method's threat model, advantages, and limitations.
What would settle it
Find a published federated-learning membership inference attack that cannot be assigned to either the update-based or the trend-based branch; the taxonomy is also falsified if no rule is given for resolving the paper's own dual listing of Zhu et al. [59], which currently appears in both branches.
Extended reading notes
Core claim
On its own terms, this survey establishes a systematic map of membership inference attacks and defenses in federated learning, which it argues no earlier survey has provided. Its organizing proposal is that every FL membership inference attack exploits either the exchanged update itself—original gradients, gradient differences across rounds, shadow-trained models, or deliberately modified model structure—or the trajectory of an indicator such as prediction confidence, loss, adversarial robustness, or bias across training rounds. It pairs this with four defense families: withholding part of the update, cryptographically hiding updates, adding noise, and detecting malicious updates. The survey also argues that FL membership inference differs from centralized learning because attackers are insiders during training, see historical model versions, and can attack actively, and because a second, stronger target exists: source-level membership, which identifies which client's data a record belongs to.
Load-bearing premise
The survey's value rests on the claim that every published membership inference attack in federated learning fits exactly one of the two categories, update-based or trend-based, with no attack left out and no attack needing dual listing.
Editorial extensions
If this is right
- A reader can use the two-branch attack taxonomy to place any new FL membership inference attack and to see which threat models it addresses, including record-level versus source-level goals and passive versus active strategies.
- Each defense family protects a different slice of the threat space, so the survey implies that practical privacy in FL will usually require combining partial sharing, noise, or aggregation rather than relying on one mechanism.
- Because FL attacks run during training and use historical model versions, defenses validated in centralized learning should not be assumed to transfer to the federated setting.
- The field lacks a unified evaluation benchmark, and current attack metrics such as accuracy can mislead; future evaluations should include false-positive rates and test realistic non-IID, partial-participation settings.
- Emerging frameworks such as peer-to-peer, blockchain-based, and vertical FL remain understudied, making them the most likely places where new membership inference attacks will appear.
Reading between the lines
- Editorial inference: the taxonomy is presented as dividing the field, but the paper's own Table 3 lists Zhu et al. [59] under both update-based and trend-based attacks, so a stated rule for primary assignment, or a third 'hybrid' branch, would be needed to make the partition truly disjoint.
- Editorial inference: a practical extension the paper gestures at but does not build is a shared evaluation harness where the same datasets, networks, and attack protocols compare all four defense families; the survey's comparison tables show why current numbers cannot be cross-compared.
- Editorial inference: source-level membership—identifying which client's data holds a record—looks like the FL-specific privacy harm most likely to grow, since it leaks both the record and the institution, and tracking how defenses trade off against it is a natural next study.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The manuscript surveys membership inference attacks (MIAs) and defenses in federated learning (FL). It proposes a two-category taxonomy for attacks—update-based and trend-based—and a four-category taxonomy for defenses (partial sharing, secure aggregation, noise perturbation, anomaly detection). It compares these with centralized learning settings, presents summary tables of attacks and defenses, and discusses future research directions. The paper claims to be the first survey specifically focused on MIAs and defenses in the FL domain.
Significance. If the taxonomy is accepted, the survey provides a useful organizational map of a rapidly growing area. The paper collects a broad set of recent works, including 2023–2024 results, and structures them into attack/defense tables that are convenient for readers entering the field. The comparisons with centralized learning and the discussion of open problems are valuable. However, the central contribution—the unique attack taxonomy—is not defined with enough precision to be reliable, and there are several inconsistencies in the reported metadata. These issues must be addressed before the paper can serve as a dependable reference.
major comments (3)
- [Section 3.5, Table 3, Sections 4.1.1 and 4.2.1] The proposed update-based versus trend-based taxonomy is not shown to be disjoint or exhaustive. The same work, Zhu et al. [59], is classified under both 'Gradient difference' (update-based) in Table 3 and 'Loss trajectory' (trend-based) in Table 3, and Section 4 describes this work both as extending gradient differences across rounds (Section 4.1.1) and as using multi-round model updates and loss trajectories (Section 4.2.1). The paper provides no decision rule for papers that propose multiple attack methods, and no argument establishes that every surveyed attack falls into exactly one category. Because the paper's central claim is that this taxonomy is unique and organizes the field, the taxonomy must be either redefined so the categories are disjoint, or the paper must explicitly state how multi-method papers are handled and justify exhaustiveness.
- [Abstract and Section 1 (Contributions)] The claim that this is 'the first survey of MIAs and defenses in the FL domain' requires qualification. The paper itself cites Reference [39] (a CSUR survey on MIAs in machine learning that includes FL works) and Reference [40] (a survey on defenses against MIAs). While these works are not dedicated exclusively to FL, the novelty claim as stated is too strong. The authors should either provide a precise definition of what counts as an FL-specific survey or soften the claim to 'the first dedicated FL-focused survey' with a comparison to the coverage in [39] and [40].
- [Section 4.2.1] The text repeatedly refers to 'Hue et al. [29]' when describing the source inference attack, but the reference list and the rest of the paper use 'Hu et al. [29]' (Hongsheng Hu et al.). This name error, combined with the inconsistent year in Table 4 for Truex et al. [97], suggests that the survey's citation metadata was not carefully cross-checked. For a survey whose value depends on accurate attribution, these errors need to be corrected across the manuscript.
minor comments (6)
- [Abstract] The phrase 'deep leaning' should be 'deep learning'.
- [Table 4] Truex et al. [97] is listed with year 2018, but the reference list gives 2021 (IEEE TSC, with an online date of 2019). Please use the published version year consistently.
- [Table 5] The technique column for Zari et al. [35] reads 'Predication sequence'; this should be 'Prediction sequence'.
- [Table 6] The legend for the 'Unique' column uses the symbols ' ', 'G #', and '#' with spacing that is likely a formatting artifact; please ensure the legend is printed correctly and the symbols are consistent with the table body.
- [Section 6.1] In the paragraph 'Reasons for Information Leakage', the phrase 'in the black setting' should be 'in the black-box setting'.
- [Section 3.5 and Section 4.1] The definition of 'update-based attacks' as leveraging 'one or more historical versions of the target model' overlaps with the definition of 'trend-based attacks' as analyzing 'the trajectory of specific indicators'; consider clarifying the distinction by emphasizing the type of evidence (parameter/gradient values vs. derived scalar indicators) rather than the use of historical snapshots.
Circularity Check
No circularity: the survey organizes external literature, and the dual listing of one attack in the taxonomy is a classification concern, not a circular derivation.
full rationale
This paper is a survey and contains no derivation chain whose outputs are equivalent to its inputs. The attack and defense taxonomies are organizational definitions applied to external prior work, not fitted parameters or predicted quantities: the paper does not derive an attack or defense result from its own categories. The claim to be the first FL-specific MIA survey is a novelty assertion supported by comparison with prior surveys (Table 2), not a mathematical result. Several works by the present authors are cited ([24], [25], [140], [166], [170]), but they appear in background discussion and future-direction pointers, not as the load-bearing justification for the taxonomy or for any surveyed result. The classification of Zhu et al. [59] under both 'Gradient difference' and 'Loss trajectory' (Table 3) indicates that the update-based versus trend-based partition is not shown to be disjoint, but this is a taxonomy-quality issue about exhaustiveness and mutual exclusivity, not circularity: no claim is reduced to its own premise by construction. Therefore, no significant circularity is present.
Assumptions & free parameters
assumptions (2)
- domain assumption Membership inference attacks in FL can be exhaustively partitioned into update-based and trend-based categories.
- domain assumption The set of papers surveyed is representative and complete for the stated comprehensiveness claim.
Cite this review
Pith. "Pith review of Membership Inference Attacks and Defenses in Federated Learning: A Survey." pith.science (2026). https://pith.science/paper/V2TJLYO2
@misc{pith2026241206157,
author = {Pith},
title = {Pith review of: Membership Inference Attacks and Defenses in Federated Learning: A Survey},
year = {2026},
howpublished = {\url{https://pith.science/paper/V2TJLYO2}},
note = {Machine review of arXiv:2412.06157}
}
read the original abstract
Federated learning is a decentralized machine learning approach where clients train models locally and share model updates to develop a global model. This enables low-resource devices to collaboratively build a high-quality model without requiring direct access to the raw training data. However, despite only sharing model updates, federated learning still faces several privacy vulnerabilities. One of the key threats is membership inference attacks, which target clients' privacy by determining whether a specific example is part of the training set. These attacks can compromise sensitive information in real-world applications, such as medical diagnoses within a healthcare system. Although there has been extensive research on membership inference attacks, a comprehensive and up-to-date survey specifically focused on it within federated learning is still absent. To fill this gap, we categorize and summarize membership inference attacks and their corresponding defense strategies based on their characteristics in this setting. We introduce a unique taxonomy of existing attack research and provide a systematic overview of various countermeasures. For these studies, we thoroughly analyze the strengths and weaknesses of different approaches. Finally, we identify and discuss key future research directions for readers interested in advancing the field.
Figures
Figures from the paper (4 more)
Forward citations
Cited by 1 Pith paper
-
Synthetic Data Can Mislead Evaluations: Membership Inference as Machine Text Detection
Membership inference attacks on LLMs score synthetic text as more 'member-like' than real training data, so using synthetic data as non-members produces misleading memorization conclusions.
Reference graph
Works this paper leans on
-
[59]
Gongxi Zhu, Donghao Li, Hanlin Gu, Yuxing Han, Yuan Yao, Lixin Fan, and Qiang Yang. 2024. Evaluating Membership Inference Attacks and Defenses in Federated Learning. arXiv preprint arXiv:2402.06289 (2024)
arXiv 2024
-
[97]
Stacey Truex, Ling Liu, and Mehmet Emre Gursoy. 2021. Demystifying Membership Inference Attacks in Machine Learning as a Service. IEEE Transactions on Services Computing 14, 6 (2021), 2073–2089. https://doi.org/10.1109/TSC. 2019.2897554
arXiv 2021
-
[28]
Anastasia Pustozerova, Rudolf Mayer, and ” ”. 2020. Information leaks in federated learning. In Proceedings of the Network and Distributed System Security Symposium , Vol. 10
2020
-
[39]
Hongsheng Hu, Zoran Salcic, Lichao Sun, Gillian Dobbie, Philip S Yu, and Xuyun Zhang. 2022. Membership inference attacks on machine learning: A survey. ACM Computing Surveys (CSUR) 54, 11s (2022), 1–37
2022
-
[40]
Li Hu, Anli Yan, Hongyang Yan, Jin Li, Teng Huang, Yingying Zhang, Changyu Dong, and Chunsheng Yang. 2023. Defenses to Membership Inference Attacks: A Survey. Comput. Surveys (2023)
2023
-
[29]
Hongsheng Hu, Zoran Salcic, Lichao Sun, Gillian Dobbie, and Xuyun Zhang. 2021. Source inference attacks in federated learning. In 2021 IEEE International Conference on Data Mining (ICDM) . IEEE, 1102–1107
2021
-
[1]
Wenyi Zhao, Rama Chellappa, P Jonathon Phillips, and Azriel Rosenfeld. 2003. Face recognition: A literature survey. ACM computing surveys (CSUR) 35, 4 (2003), 399–458
2003
-
[2]
Alex Krizhevsky, Ilya Sutskever, and Geoffrey E Hinton. 2017. Imagenet classification with deep convolutional neural networks. Commun. ACM 60, 6 (2017), 84–90
2017
Show all 175 references
-
[3]
Jia Deng, Wei Dong, Richard Socher, Li-Jia Li, Kai Li, and Li Fei-Fei. 2009. ImageNet: A large-scale hierarchical image database. In 2009 IEEE Conference on Computer Vision and Pattern Recognition . 248–255
2009
-
[4]
Gao Huang, Zhuang Liu, Laurens Van Der Maaten, and Kilian Q Weinberger. 2017. Densely connected convolutional networks. In Proceedings of the IEEE conference on computer vision and pattern recognition . 4700–4708
2017
-
[5]
Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep residual learning for image recognition. In Proceedings of the IEEE conference on computer vision and pattern recognition . 770–778
2016
-
[6]
Jacob Devlin Ming-Wei Chang Kenton and Lee Kristina Toutanova. 2019. BERT: Pre-training of Deep Bidirectional Transformers for Language Understanding. In Proceedings of NAACL-HLT. 4171–4186
2019
-
[7]
Justyna Sarzynska-Wawer, Aleksander Wawer, Aleksandra Pawlak, Julia Szymanowska, Izabela Stefaniak, Michal Jarkiewicz, and Lukasz Okruszek. 2021. Detecting formal thought disorder by deep contextualized word representa- tions. Psychiatry Research 304 (2021), 114135
2021
-
[8]
Tomas Mikolov, Kai Chen, Greg Corrado, and Jeffrey Dean. 2013. Efficient estimation of word representations in vector space. International Conference on Learning Representations (2013)
2013
-
[9]
Ilya Sutskever, Oriol Vinyals, and Quoc V Le. 2014. Sequence to sequence learning with neural networks. Advances in neural information processing systems 27 (2014)
2014
-
[10]
GDPR. 2019. General Data Protection Regulation. https://gdpr-info.eu/
2019
-
[11]
CCPA. 2018. California Consumer Privacy Act. https://leginfo.legislature.ca.gov/
2018
-
[12]
Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication- efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics. PMLR, 1273–1282. ACM Comput. Surv., Vol. 37, No. 4, Article 111. P...
2017
-
[13]
Bo Zhao, Konda Reddy Mopuri, and Hakan Bilen. 2020. idlg: Improved deep leakage from gradients. arXiv preprint arXiv:2001.02610 (2020)
2020 arXiv
-
[14]
Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep leakage from gradients. Advances in neural information processing systems 32 (2019)
2019
-
[15]
Akiyoshi Sannai. 2018. Reconstruction of training samples from loss functions. arXiv preprint arXiv:1805.07337 (2018)
2018 arXiv
-
[16]
Meng Shen, Huan Wang, Bin Zhang, Liehuang Zhu, Ke Xu, Qi Li, and Xiaojiang Du. 2020. Exploiting unintended property leakage in blockchain-assisted federated learning for intelligent edge computing. IEEE Internet of Things Journal 8, 4 (2020), 2265–2275
2020
-
[17]
Luca Melis, Congzheng Song, Emiliano De Cristofaro, and Vitaly Shmatikov. 2019. Exploiting unintended feature leakage in collaborative learning. In 2019 IEEE symposium on security and privacy (SP) . IEEE, 691–706
2019
-
[18]
Briland Hitaj, Giuseppe Ateniese, and Fernando Perez-Cruz. 2017. Deep models under the GAN: information leakage from collaborative deep learning. In Proceedings of the 2017 ACM SIGSAC conference on computer and communications security. 603–618
2017
-
[19]
Matt Fredrikson, Somesh Jha, and Thomas Ristenpart. 2015. Model inversion attacks that exploit confidence informa- tion and basic countermeasures. In Proceedings of the 22nd ACM SIGSAC conference on computer and communications security. 1322–1333
2015
-
[20]
Zhibo Wang, Mengkai Song, Zhifei Zhang, Yang Song, Qian Wang, and Hairong Qi. 2019. Beyond inferring class representatives: User-level privacy leakage from federated learning. In IEEE INFOCOM 2019-IEEE conference on computer communications. IEEE, 2512–2520
2019
-
[21]
Nils Homer, Szabolcs Szelinger, Margot Redman, David Duggan, Waibhav Tembe, Jill Muehling, John V Pearson, Dietrich A Stephan, Stanley F Nelson, and David W Craig. 2008. Resolving individuals contributing trace amounts of DNA to highly complex mixtures using high-density SNP g...
2008
-
[22]
Reza Shokri, Marco Stronati, Congzheng Song, and Vitaly Shmatikov. 2017. Membership inference attacks against machine learning models. In 2017 IEEE symposium on security and privacy (SP) . IEEE, 3–18
2017
-
[23]
Apostolos Pyrgelis, Carmela Troncoso, and Emiliano De Cristofaro. 2018. Knock knock, who’s there? Membership inference on aggregate location data. Network and Distributed System Security Symposium (2018)
2018
-
[24]
Hongyang Yan, Shuhao Li, Yajie Wang, Yaoyuan Zhang, Kashif Sharif, Haibo Hu, and Yuanzhang Li. 2022. Membership Inference Attacks Against Deep Learning Models Via Logits Distribution. IEEE Transactions on Dependable and Secure Computing (2022)
2022
-
[25]
Yaxin Xiao, Qingqing Ye, Haibo Hu, Huadi Zheng, Chengfang Fang, and Jie Shi. 2022. MExMI: Pool-based Active Model Extraction Crossover Membership Inference. Advances in Neural Information Processing Systems 35 (2022), 10203–10216
2022
-
[26]
Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019. Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In 2019 IEEE symposium on security and privacy (SP). IEEE, 739–753
2019
-
[27]
Jingwen Zhang, Jiale Zhang, Junjun Chen, and Shui Yu. 2020. Gan enhanced membership inference: A passive local attack in federated learning. In ICC 2020-2020 IEEE International Conference on Communications (ICC) . IEEE, 1–6
2020
-
[30]
Yuhao Gu, Yuebin Bai, and Shubin Xu. 2022. CS-MIA: Membership inference attack based on prediction confidence series in federated learning. Journal of Information Security and Applications 67 (2022), 103201
2022
-
[31]
Umang Gupta, Dimitris Stripelis, Pradeep K Lam, Paul Thompson, José Luis Ambite, and Greg Ver Steeg. 2021. Membership inference attacks on deep regression models for neuroimaging. In Medical Imaging with Deep Learning . PMLR, 228–251
2021
-
[32]
Zhenpeng Liu, Ruilin Li, Dewei Miao, Lele Ren, and Yonggang Zhao. 2022. Membership Inference Defense in Distributed Federated Learning Based on Gradient Differential Privacy and Trust Domain Division Mechanisms. Security and Communication Networks 2022 (2022)
2022
-
[33]
Jiacheng Li, Ninghui Li, and Bruno Ribeiro. 2023. Effective passive membership inference attacks in federated learning against overparameterized models. In 11th International Conference on Learning Representations (ICLR)
2023
-
[34]
Georg Pichler, Marco Romanelli, Leonardo Rey Vega, and Pablo Piantanida. 2022. Perfectly Accurate Membership Inference by a Dishonest Central Server in Federated Learning. arXiv preprint arXiv:2203.16463 (2022)
2022 arXiv
-
[35]
Oualid Zari, Chuan Xu, and Giovanni Neglia. 2021. Efficient passive membership inference attack in federated learning. In NeurIPS PriML workshop. ACM Comput. Surv., Vol. 37, No. 4, Article 111. Publication date: August XXXX. 111:30 Bai et al
2021
-
[36]
Anshuman Suri, Pallika Kanani, Virendra J Marathe, and Daniel W Peterson. 2022. Subject Membership Inference Attacks in Federated Learning. arXiv preprint arXiv:2206.03317 (2022)
2022 arXiv
-
[37]
Alysa Ziying Tan, Han Yu, Lizhen Cui, and Qiang Yang. 2022. Towards personalized federated learning. IEEE Transactions on Neural Networks and Learning Systems (2022)
2022
-
[38]
Georgios Drainakis, Konstantinos V Katsaros, Panagiotis Pantazopoulos, Vasilis Sourlas, and Angelos Amditis. 2020. Federated vs. centralized machine learning under privacy-elastic users: A comparative analysis. In 2020 IEEE 19th International Symposium on Network Computing and...
2020
-
[41]
H Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. 2018. Learning Differentially Private Recurrent Language Models. In International Conference on Learning Representations
2018
-
[42]
Robin C Geyer, Tassilo Klein, and Moin Nabi. 2017. Differentially private federated learning: A client level perspective. arXiv preprint arXiv:1712.07557 (2017)
2017 arXiv
-
[43]
Ahmed Salem, Yang Zhang, Mathias Humbert, Pascal Berrang, Mario Fritz, and Michael Backes. 2019. ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. In 26th Annual Network and Distributed System Security Symposium, NDSS 20...
2019
-
[44]
Avital Shafran, Shmuel Peleg, and Yedid Hoshen. 2021. Membership inference attacks are easier on difficult problems. In Proceedings of the IEEE/CVF International Conference on Computer Vision . 14820–14829
2021
-
[45]
Zheng Li and Yang Zhang. 2021. Membership leakage in label-only exposures. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security . 880–895
2021
-
[46]
Christopher A Choquette-Choo, Florian Tramer, Nicholas Carlini, and Nicolas Papernot. 2021. Label-only membership inference attacks. In International conference on machine learning . PMLR, 1964–1974
2021
-
[47]
Klas Leino and Matt Fredrikson. 2020. Stolen Memories: Leveraging Model Memorization for Calibrated White-Box Membership Inference. In 29th USENIX security symposium (USENIX Security 20) . 1605–1622
2020
-
[48]
Florian Tramèr, Reza Shokri, Ayrton San Joaquin, Hoang Le, Matthew Jagielski, Sanghyun Hong, and Nicholas Carlini
-
[49]
Yufei Chen, Chao Shen, Yun Shen, Cong Wang, and Yang Zhang. 2022. Amplifying Membership Exposure via Data Poisoning. In Advances in Neural Information Processing Systems
2022
-
[50]
Qinbin Li, Zeyi Wen, Zhaomin Wu, Sixu Hu, Naibo Wang, Yuan Li, Xu Liu, and Bingsheng He. 2021. A survey on federated learning systems: vision, hype and reality for data privacy and protection. IEEE Transactions on Knowledge and Data Engineering (2021)
2021
-
[51]
Peter Kairouz, H Brendan McMahan, Brendan Avent, Aurélien Bellet, Mehdi Bennis, Arjun Nitin Bhagoji, Kallista Bonawitz, Zachary Charles, Graham Cormode, Rachel Cummings, et al . 2021. Advances and open problems in federated learning. Foundations and Trends® in Machine Learning...
2021
-
[52]
Qiang Yang, Yang Liu, Tianjian Chen, and Yongxin Tong. 2019. Federated machine learning: Concept and applications. ACM Transactions on Intelligent Systems and Technology (TIST) 10, 2 (2019), 1–19
2019
-
[53]
Lingjuan Lyu, Han Yu, Xingjun Ma, Chen Chen, Lichao Sun, Jun Zhao, Qiang Yang, and S Yu Philip. 2022. Privacy and robustness in federated learning: Attacks and defenses. IEEE transactions on neural networks and learning systems (2022)
2022
-
[54]
Lingjuan Lyu, Han Yu, and Qiang Yang. 2020. Threats to Federated Learning: A Survey. ArXiv abs/2003.02133 (2020)
2020 arXiv
-
[55]
Junpeng Zhang, Mengqian Li, Shuiguang Zeng, Bin Xie, and Dongmei Zhao. 2021. A survey on security and privacy threats to federated learning. In 2021 International Conference on Networking and Network Applications (NaNA) . 319–326. https://doi.org/10.1109/NaNA53684.2021.00062
2021
-
[56]
Nader Bouacida and Prasant Mohapatra. 2021. Vulnerabilities in federated learning.IEEE Access 9 (2021), 63229–63249
2021
-
[57]
Malhar S Jere, Tyler Farnan, and Farinaz Koushanfar. 2020. A taxonomy of attacks on federated learning. IEEE Security & Privacy 19, 2 (2020), 20–28
2020
-
[58]
Huiqiang Chen, Tianqing Zhu, Tao Zhang, Wanlei Zhou, and Philip S Yu. 2023. Privacy and Fairness in Federated Learning: on the Perspective of Trade-off. Comput. Surveys (2023)
2023
-
[60]
Hongkyu Lee, Jeehyeong Kim, Seyoung Ahn, Rasheed Hussain, Sunghyun Cho, and Junggab Son. 2021. Digestive neural networks: A novel defense strategy against inference attacks in federated learning. computers & security 109 (2021), 102378. ACM Comput. Surv., Vol. 37, No. 4, Artic...
2021
-
[61]
Jiale Chen, Jiale Zhang, Yanchao Zhao, Hao Han, Kun Zhu, and Bing Chen. 2020. Beyond model-level membership privacy leakage: an adversarial approach in federated learning. In 2020 29th International Conference on Computer Communications and Networks (ICCCN) . IEEE, 1–9
2020
-
[62]
Reza Shokri and Vitaly Shmatikov. 2015. Privacy-preserving deep learning. In Proceedings of the 22nd ACM SIGSAC conference on computer and communications security . 1310–1321
2015
-
[63]
Alham Aji and Kenneth Heafield. 2017. Sparse Communication for Distributed Gradient Descent. In EMNLP 2017: Conference on Empirical Methods in Natural Language Processing . Association for Computational Linguistics (ACL), 440–445
2017
-
[64]
Andrew C Yao. 1982. Protocols for secure computations. In 23rd annual symposium on foundations of computer science (sfcs 1982). IEEE, 160–164
1982
-
[65]
Xue Yang, Yan Feng, Weijun Fang, Jun Shao, Xiaohu Tang, Shu-Tao Xia, and Rongxing Lu. 2022. An accuracy-lossless perturbation method for defending privacy attacks in federated learning. In Proceedings of the ACM Web Conference
2022
-
[66]
Mohammad Naseri, Jamie Hayes, and Emiliano De Cristofaro. 2022. Local and Central Differential Privacy for Robustness and Privacy in Federated Learning. In 29th Annual Network and Distributed System Security Symposium, NDSS 2022, San Diego, California, USA, April 24-28, 2022 ....
2022
-
[67]
Mengyao Ma, Yanjun Zhang, Pathum Chamikara Mahawaga Arachchige, Leo Yu Zhang, Mohan Baruwal Chhetri, and Guangdong Bai. 2023. LoDen: Making Every Client in Federated Learning a Defender Against the Poisoning Membership Inference Attacks. In Proceedings of the 2023 ACM Asia Con...
2023
-
[68]
Vladimir Vapnik. 1991. Principles of risk minimization for learning theory. Advances in neural information processing systems 4 (1991)
1991
-
[69]
David Saad. 1998. Online algorithms and stochastic approximations. Online Learning 5, 3 (1998), 6
1998
-
[70]
John Duchi, Elad Hazan, and Yoram Singer. 2011. Adaptive subgradient methods for online learning and stochastic optimization. Journal of machine learning research 12, 7 (2011)
2011
-
[71]
Diederik P Kingma and Jimmy Ba. 2015. Adam: A Method for Stochastic Optimization. In 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings
2015
-
[72]
Jie Xu, Benjamin S Glicksberg, Chang Su, Peter Walker, Jiang Bian, and Fei Wang. 2021. Federated learning for healthcare informatics. Journal of Healthcare Informatics Research 5 (2021), 1–19
2021
-
[73]
Dinh C Nguyen, Quoc-Viet Pham, Pubudu N Pathirana, Ming Ding, Aruna Seneviratne, Zihuai Lin, Octavia Dobre, and Won-Joo Hwang. 2022. Federated learning for smart healthcare: A survey. ACM Computing Surveys (CSUR) 55, 3 (2022), 1–37
2022
-
[74]
Latif U Khan, Walid Saad, Zhu Han, Ekram Hossain, and Choong Seon Hong. 2021. Federated learning for internet of things: Recent advances, taxonomy, and open challenges. IEEE Communications Surveys & Tutorials 23, 3 (2021), 1759–1799
2021
-
[75]
Dinh C Nguyen, Ming Ding, Pubudu N Pathirana, Aruna Seneviratne, Jun Li, and H Vincent Poor. 2021. Federated learning for internet of things: A comprehensive survey. IEEE Communications Surveys & Tutorials 23, 3 (2021), 1622–1658
2021
-
[76]
Yutao Huang, Lingyang Chu, Zirui Zhou, Lanjun Wang, Jiangchuan Liu, Jian Pei, and Yong Zhang. 2021. Personalized cross-silo federated learning on non-iid data. In Proceedings of the AAAI Conference on Artificial Intelligence , Vol. 35. 7865–7873
2021
-
[77]
Othmane Marfoq, Chuan Xu, Giovanni Neglia, and Richard Vidal. 2020. Throughput-optimal topology design for cross-silo federated learning. Advances in Neural Information Processing Systems 33 (2020), 19478–19487
2020
-
[78]
Qinbin Li, Zeyi Wen, and Bingsheng He. 2020. Practical federated gradient boosting decision trees. In Proceedings of the AAAI conference on artificial intelligence , Vol. 34. 4642–4649
2020
-
[79]
Yang Liu, Yan Kang, Chaoping Xing, Tianjian Chen, and Qiang Yang. 2020. A secure federated transfer learning framework. IEEE Intelligent Systems 35, 4 (2020), 70–82
2020
-
[80]
Dashan Gao, Yang Liu, Anbu Huang, Ce Ju, Han Yu, and Qiang Yang. 2019. Privacy-preserving Heterogeneous Federated Transfer Learning. In 2019 IEEE International Conference on Big Data (Big Data) . IEEE, 2552–2559
2019
-
[81]
Shreya Sharma, Chaoping Xing, Yang Liu, and Yan Kang. 2019. Secure and efficient federated transfer learning. In 2019 IEEE international conference on big data (Big Data) . IEEE, 2569–2576
2019
-
[82]
Stacey Truex, Nathalie Baracaldo, Ali Anwar, Thomas Steinke, Heiko Ludwig, Rui Zhang, and Yi Zhou. 2019. A hybrid approach to privacy-preserving federated learning. In Proceedings of the 12th ACM workshop on artificial intelligence and security. 1–11
2019
-
[83]
Kin Sum Liu, Chaowei Xiao, Bo Li, and Jie Gao. 2019. Performing co-membership attacks against deep generative models. In 2019 IEEE International Conference on Data Mining (ICDM) . IEEE, 459–467. ACM Comput. Surv., Vol. 37, No. 4, Article 111. Publication date: August XXXX. 111...
2019
-
[84]
Hongbin Liu, Jinyuan Jia, Wenjie Qu, and Neil Zhenqiang Gong. 2021. EncoderMI: Membership inference against pre-trained encoders in contrastive learning. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. 2081–2095
2021
-
[85]
Samuel Yeom, Irene Giacomelli, Matt Fredrikson, and Somesh Jha. 2018. Privacy risk in machine learning: Analyzing the connection to overfitting. In 2018 IEEE 31st computer security foundations symposium (CSF) . IEEE, 268–282
2018
-
[86]
Liwei Song and Prateek Mittal. 2021. Systematic Evaluation of Privacy Risks of Machine Learning Models. In USENIX Security Symposium
2021
-
[87]
Lauren Watson, Chuan Guo, Graham Cormode, and Alexandre Sablayrolles. 2022. On the Importance of Difficulty Calibration in Membership Inference Attacks. In International Conference on Learning Representations
2022
-
[88]
Nicholas Carlini, Steve Chien, Milad Nasr, Shuang Song, Andreas Terzis, and Florian Tramer. 2022. Membership inference attacks from first principles. In 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 1897–1914
2022
-
[89]
Alexandre Sablayrolles, Matthijs Douze, Cordelia Schmid, Yann Ollivier, and Hervé Jégou. 2019. White-box vs black-box: Bayes optimal strategies for membership inference. InInternational Conference on Machine Learning. PMLR, 5558–5567
2019
-
[90]
Junxiang Zheng, Yongzhi Cao, and Hanpin Wang. 2021. Resisting membership inference attacks through knowledge distillation. Neurocomputing 452 (2021), 114–126
2021
-
[91]
Bargav Jayaraman and David Evans. 2019. Evaluating differentially private machine learning in practice. In 28th USENIX Security Symposium (USENIX Security 19) . 1895–1912
2019
-
[92]
Jinyuan Jia, Ahmed Salem, Michael Backes, Yang Zhang, and Neil Zhenqiang Gong. 2019. Memguard: Defending against black-box membership inference attacks via adversarial examples. In Proceedings of the 2019 ACM SIGSAC conference on computer and communications security . 259–274
2019
-
[93]
Yanchao Zhao, Jiale Chen, Jiale Zhang, Zilu Yang, Huawei Tu, Hao Han, Kun Zhu, and Bing Chen. 2021. User-Level Membership Inference for Federated Learning in Wireless Network Environment. Wireless Communications and Mobile Computing 2021 (2021)
2021
-
[94]
Hanlin Lu, Ming-Ju Li, Ting He, Shiqiang Wang, Vijaykrishnan Narayanan, and Kevin S Chan. 2020. Robust coreset construction for distributed machine learning. IEEE Journal on Selected Areas in Communications 38, 10 (2020), 2400–2417
2020
-
[95]
Alka Luqman, Anupam Chattopadhyay, and Kwok-Yan Lam. 2023. Membership Inference Vulnerabilities in Peer- to-Peer Federated Learning. In Proceedings of the 2023 Secure and Trustworthy Deep Learning Systems Workshop . 1–5
2023
-
[96]
Soumya Banerjee, Sandip Roy, Sayyed Farid Ahamed, Devin Quinn, Marc Vucovich, Dhruv Nandakumar, Kevin Choi, Abdul Rahman, Edward Bowen, and Sachin Shetty. 2024. Mia-bad: An approach for enhancing membership inference attack and its mitigation with federated learning. In 2024 I...
2024
-
[98]
Wei Yuan, Chaoqun Yang, Quoc Viet Hung Nguyen, Lizhen Cui, Tieke He, and Hongzhi Yin. 2023. Interaction-level Membership Inference Attack Against Federated Recommender Systems. In Proceedings of the Web Conference 2023 . 1–10
2023
-
[99]
Truc Nguyen, Phung Lai, Khang Tran, NhatHai Phan, and My T Thai. 2023. Active Membership Inference Attack under Local Differential Privacy in Federated Learning. In International Conference on Artificial Intelligence and Statistics, 25-27 April 2023, Palau de Congressos, Valen...
2023
-
[100]
Yanjun Zhang, Guangdong Bai, Mahawaga Arachchige Pathum Chamikara, Mengyao Ma, Liyue Shen, Jingwei Wang, Surya Nepal, Minhui Xue, Long Wang, and Joseph Liu. 2023. AgrEvader: Poisoning Membership Inference against Byzantine-robust Federated Learning. In Proceedings of the ACM W...
2023
-
[101]
Gaoyang Liu, Zehao Tian, Jian Chen, Chen Wang, and Jiangchuan Liu. 2023. TEAR: Exploring Temporal Evolution of Adversarial Robustness for Membership Inference Attacks against Federated Learning. IEEE Transactions on Information Forensics and Security (2023)
2023
-
[102]
Liwei Zhang, Linghui Li, Xiaoyong Li, Binsi Cai, Yali Gao, Ruobin Dou, and Luying Chen. 2023. Efficient Membership Inference Attacks against Federated Learning via Bias Differences. In Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defen...
2023
-
[103]
Dan Feldman, Matthew Faulkner, and Andreas Krause. 2011. Scalable training of mixture models via coresets. Advances in neural information processing systems 24 (2011)
2011
-
[104]
Martin Abadi, Andy Chu, Ian Goodfellow, H Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep learning with differential privacy. In Proceedings of the 2016 ACM SIGSAC conference on computer and communications ACM Comput. Surv., Vol. 37, No. 4, Article 111. P...
2016
-
[105]
Jeremy Bernstein, Jiawei Zhao, Kamyar Azizzadenesheli, and Anima Anandkumar. 2018. signSGD with Majority Vote is Communication Efficient and Fault Tolerant. In International Conference on Learning Representations
2018
-
[106]
Zilu Yang, Yanchao Zhao, and Jiale Zhang. 2023. FD-Leaks: Membership Inference Attacks Against Federated Distillation Learning. In Web and Big Data: 6th International Joint Conference, APWeb-W AIM 2022, Nanjing, China, November 25–27, 2022, Proceedings, Part III . Springer, 364–378
2023
-
[107]
Thomas G Dietterich. 2000. Ensemble methods in machine learning. In International workshop on multiple classifier systems. Springer, 1–15
2000
-
[108]
Xiangnan He, Lizi Liao, Hanwang Zhang, Liqiang Nie, Xia Hu, and Tat-Seng Chua. 2017. Neural collaborative filtering. In Proceedings of the 26th international conference on world wide web . 173–182
2017
-
[109]
Xiangnan He, Kuan Deng, Xiang Wang, Yan Li, Yongdong Zhang, and Meng Wang. 2020. Lightgcn: Simplifying and powering graph convolution network for recommendation. In Proceedings of the 43rd International ACM SIGIR conference on research and development in Information Retrieval ...
2020
-
[110]
Bargav Jayaraman, Lingxiao Wang, Katherine Knipmeyer, Quanquan Gu, and David Evans. 2021. Revisiting Member- ship Inference Under Realistic Assumptions. Proceedings on Privacy Enhancing Technologies 2021, 2 (2021)
2021
-
[111]
Virendra J Marathe and Pallika Kanani. 2022. Subject Granular Differential Privacy in Federated Learning. arXiv preprint arXiv:2206.03617 (2022)
2022 arXiv
-
[112]
Liwei Song, Reza Shokri, and Prateek Mittal. 2019. Privacy risks of securing machine learning models against adversarial examples. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security . 241–257
2019
-
[113]
Yiyong Liu, Zhengyu Zhao, Michael Backes, and Yang Zhang. 2022. Membership inference attacks by exploiting loss trajectory. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security . 2085–2098
2022
-
[114]
Sebastian U Stich, Jean-Baptiste Cordonnier, and Martin Jaggi. 2018. Sparsified SGD with memory. Advances in Neural Information Processing Systems 31 (2018)
2018
-
[115]
Aritra Dutta, El Houcine Bergou, Ahmed M Abdelmoniem, Chen-Yu Ho, Atal Narayan Sahu, Marco Canini, and Panos Kalnis. 2020. On the discrepancy between the theoretical analysis and practical implementations of compressed communication for distributed deep learning. In Proceeding...
2020
-
[116]
Yujun Lin, Song Han, Huizi Mao, Yu Wang, and William J Dally. 2018. Deep gradient compression: Reducing the communication bandwidth for distributed training. In 6th International Conference on Learning Representations, ICLR 2018, Vancouver, BC, Canada, April 30 - May 3, 2018, ...
2018
-
[117]
Wei Dai, Yi Zhou, Nanqing Dong, Hao Zhang, and Eric Xing. 2019. Toward Understanding the Impact of Staleness in Distributed Machine Learning. In International Conference on Learning Representations
2019
-
[118]
Yusuke Tsuzuku, Hiroto Imachi, and Takuya Akiba. 2018. Variance-based Gradient Compression for Efficient Distributed Deep Learning. In 6th International Conference on Learning Representations, ICLR 2018
2018
-
[119]
Chong Fu, Xuhong Zhang, Shouling Ji, Jinyin Chen, Jingzheng Wu, Shanqing Guo, Jun Zhou, Alex X Liu, and Ting Wang. 2022. Label inference attacks against vertical federated learning. In 31st USENIX Security Symposium (USENIX Security 22). 1397–1414
2022
-
[120]
Hongyan Chang, Virat Shejwalkar, Reza Shokri, and Amir Houmansadr. 2019. Cronus: Robust and heterogeneous collaborative learning with black-box knowledge transfer. arXiv preprint arXiv:1912.11279 (2019)
2019 arXiv
-
[121]
Dimitris Stripelis, Umang Gupta, Nikhil Dhinagar, Greg Ver Steeg, Paul M Thompson, and José Luis Ambite. 2022. Towards Sparsified Federated Neuroimaging Models via Weight Pruning. In Distributed, Collaborative, and Federated Learning, and Affordable AI and Healthcare for Resou...
2022
-
[122]
Xiaoyong Yuan and Lan Zhang. 2022. Membership inference attacks and defenses in neural network pruning. In 31st USENIX Security Symposium (USENIX Security 22) . 4561–4578
2022
-
[123]
Le Trieu Phong, Yoshinori Aono, Takuya Hayashi, Lihua Wang, Shiho Moriai, et al. 2017. Privacy-preserving deep learning via additively homomorphic encryption. IEEE Transactions on Information Forensics and Security 13, 5 (2017), 1333–1345
2017
-
[124]
Ruinian Li, Yinhao Xiao, Cheng Zhang, Tianyi Song, and Chunqiang Hu. 2018. Cryptographic algorithms for privacy-preserving online applications. Math. Found. Comput. 1, 4 (2018), 311–330
2018
-
[125]
Xuefei Yin, Yanming Zhu, and Jiankun Hu. 2021. A comprehensive survey of privacy-preserving federated learning: A taxonomy, review, and future directions. ACM Computing Surveys (CSUR) 54, 6 (2021), 1–36
2021
-
[126]
Payman Mohassel and Yupeng Zhang. 2017. Secureml: A system for scalable privacy-preserving machine learning. In 2017 IEEE symposium on security and privacy (SP) . IEEE, 19–38
2017
-
[127]
Keith Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone, H Brendan McMahan, Sarvar Patel, Daniel Ramage, Aaron Segal, and Karn Seth. 2017. Practical secure aggregation for privacy-preserving machine learning. In proceedings of the 2017 ACM SIGSAC Conference on Computer...
2017
-
[128]
Suhel Sayyad. 2020. Privacy preserving deep learning using secure multiparty computation. In2020 Second International Conference on Inventive Research in Computing Applications (ICIRCA) . IEEE, 139–142
2020
-
[129]
Hossein Fereidooni, Samuel Marchal, Markus Miettinen, Azalia Mirhoseini, Helen Möllering, Thien Duc Nguyen, Phillip Rieger, Ahmad-Reza Sadeghi, Thomas Schneider, Hossein Yalame, et al. 2021. SAFELearn: secure aggregation for private federated learning. In 2021 IEEE Security an...
2021
-
[130]
Khac-Hoang Ngo, Johan Östman, Giuseppe Durisi, and Alexandre Graell i Amat. 2024. Secure Aggregation Is Not Private Against Membership Inference Attacks. In Joint European Conference on Machine Learning and Knowledge Discovery in Databases. Springer, 180–198
2024
-
[131]
Jiqiang Gao, Boyu Hou, Xiaojie Guo, Zheli Liu, Ying Zhang, Kai Chen, and Jin Li. 2021. Secure aggregation is insecure: Category inference attack on federated learning. IEEE Transactions on Dependable and Secure Computing (2021)
2021
-
[132]
Cynthia Dwork, Frank McSherry, Kobbi Nissim, and Adam Smith. 2006. Calibrating noise to sensitivity in private data analysis. In Theory of cryptography conference . Springer, 265–284
2006
-
[133]
Ronald L Rivest, Len Adleman, Michael L Dertouzos, et al . 1978. On data banks and privacy homomorphisms. Foundations of secure computation 4, 11 (1978), 169–180
1978
-
[134]
Yang Bai and Mingyu Fan. 2021. A method to improve the privacy and security for federated learning. In 2021 IEEE 6th International Conference on Computer and Communication Systems (ICCCS) . IEEE, 704–708
2021
-
[135]
Chengliang Zhang, Suyi Li, Junzhe Xia, Wei Wang, Feng Yan, and Yang Liu. 2020. Batchcrypt: Efficient homomorphic encryption for cross-silo federated learning. In Proceedings of the 2020 USENIX Annual Technical Conference (USENIX ATC 2020)
2020
-
[136]
Xiang Ma, Haijian Sun, Rose Qingyang Hu, and Yi Qian. 2022. A New Implementation of Federated Learning for Privacy and Security Enhancement. In GLOBECOM 2022-2022 IEEE Global Communications Conference . IEEE, 4885–4890
2022
-
[137]
Yang Liu, Yan Kang, Tianyuan Zou, Yanhong Pu, Yuanqin He, Xiaozhou Ye, Ye Ouyang, Ya-Qin Zhang, and Qiang Yang. 2022. Vertical Federated Learning. arXiv preprint arXiv:2211.12814 (2022)
2022 arXiv
-
[138]
Chen Zhang, Yu Xie, Hang Bai, Bin Yu, Weihong Li, and Yuan Gao. 2021. A survey on federated learning. Knowledge- Based Systems 216 (2021), 106775
2021
-
[139]
Cynthia Dwork. 2008. Differential privacy: A survey of results. In International conference on theory and applications of models of computation . Springer, 1–19
2008
-
[140]
Huadi Zheng, Haibo Hu, and Ziyang Han. 2020. Preserving user privacy for machine learning: Local differential privacy or federated machine learning? IEEE Intelligent Systems 35, 4 (2020), 5–14
2020
-
[141]
Ulfar Erlingsson, Ilya Mironov, Ananth Raghunathan, and Shuang Song. 2019. That which we call private. arXiv preprint arXiv:1908.03566 (2019)
2019 arXiv
-
[142]
Daniel Bernau, Günther Eibl, Philip W Grassal, Hannah Keller, and Florian Kerschbaum. 2021. Quantifying identifia- bility to choose and audit𝜖 in differentially private deep learning. Proceedings of the VLDB Endowment 14, 13 (2021), 3335–3347
2021
-
[143]
Rob Hall, Alessandro Rinaldo, and Larry Wasserman. 2013. Differential privacy for functions and functional data. The Journal of Machine Learning Research 14, 1 (2013), 703–727
2013
-
[144]
Thomas Humphries, Simon Oya, Lindsey Tulloch, Matthew Rafuse, Ian Goldberg, Urs Hengartner, and Florian Kerschbaum. 2023. Investigating Membership Inference Attacks under Data Dependencies. In 36th IEEE Computer Security Foundations Symposium, CSF 2023, Dubrovnik, Croatia, Jul...
2023
-
[145]
Milad Nasr, Shuang Songi, Abhradeep Thakurta, Nicolas Papernot, and Nicholas Carlin. 2021. Adversary instantiation: Lower bounds for differentially private machine learning. In 2021 IEEE Symposium on security and privacy (SP) . IEEE, 866–882
2021
-
[146]
Stacey Truex, Ling Liu, Ka-Ho Chow, Mehmet Emre Gursoy, and Wenqi Wei. 2020. LDP-Fed: Federated Learning with Local Differential Privacy. In Proceedings of the Third ACM International Workshop on Edge Systems, Analytics and Networking
2020
-
[147]
Md Atiqur Rahman, Tanzila Rahman, Robert Laganière, Noman Mohammed, and Yang Wang. 2018. Membership Inference Attack against Differentially Private Deep Learning Model. Trans. Data Priv. 11, 1 (2018), 61–79
2018
-
[148]
Marco Avella-Medina. 2021. Privacy-preserving parametric inference: a case for robust statistics. J. Amer. Statist. Assoc. 116, 534 (2021), 969–983
2021
-
[149]
Mengjiao Zhang and Shusen Wang. 2021. Matrix sketching for secure collaborative machine learning. InInternational Conference on Machine Learning . PMLR, 12589–12599
2021
-
[150]
Yuanyuan Xie, Bing Chen, Jiale Zhang, and Di Wu. 2021. Defending against Membership Inference Attacks in Federated learning via Adversarial Example. In 2021 17th International Conference on Mobility, Sensing and Networking (MSN). 153–160. https://doi.org/10.1109/MSN53354.2021.00036
2021
-
[151]
Yuchen Yang, Haolin Yuan, Bo Hui, Neil Gong, Neil Fendley, Philippe Burlina, and Yinzhi Cao. 2023. Fortifying Federated Learning against Membership Inference Attacks via Client-level Input Perturbation. In 2023 53rd Annual ACM Comput. Surv., Vol. 37, No. 4, Article 111. Public...
2023
-
[152]
Peva Blanchard, El Mahdi El Mhamdi, Rachid Guerraoui, and Julien Stainer. 2017. Machine learning with adversaries: Byzantine tolerant gradient descent. Advances in neural information processing systems 30 (2017)
2017
-
[153]
Dong Yin, Yudong Chen, Ramchandran Kannan, and Peter Bartlett. 2018. Byzantine-robust distributed learning: Towards optimal statistical rates. In International Conference on Machine Learning . PMLR, 5650–5659
2018
-
[154]
Xiaoyu Cao, Minghong Fang, Jia Liu, and Neil Zhenqiang Gong. 2021. FLTrust: Byzantine-robust Federated Learning via Trust Bootstrapping. In 28th Annual Network and Distributed System Security Symposium, NDSS 2021, virtually, February 21-25, 2021. The Internet Society
2021
-
[155]
Jiacheng Li, Ninghui Li, and Bruno Ribeiro. 2020. Membership inference attacks and defenses in supervised learning via generalization gap. arXiv preprint arXiv:2002.12062 3, 7 (2020)
2020 arXiv
-
[156]
Lixin Fan, Kam Woh Ng, Ce Ju, Tianyu Zhang, Chang Liu, Chee Seng Chan, and Qiang Yang. 2020. Rethinking privacy preserving deep learning: How to evaluate and thwart privacy attacks. Federated Learning: Privacy and Incentive (2020), 32–50
2020
-
[157]
Shahbaz Rezaei and Xin Liu. 2021. On the difficulty of membership inference attacks. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition . 7892–7900
2021
-
[158]
Andrew Hard, Kanishka Rao, Rajiv Mathews, Swaroop Ramaswamy, Françoise Beaufays, Sean Augenstein, Hubert Eichner, Chloé Kiddon, and Daniel Ramage. 2018. Federated learning for mobile keyboard prediction. arXiv preprint arXiv:1811.03604 (2018)
2018 arXiv
-
[159]
Lingchen Zhao, Lihao Ni, Shengshan Hu, Yaniiao Chen, Pan Zhou, Fu Xiao, and Libing Wu. 2018. Inprivate digging: Enabling tree-based distributed data mining with differential privacy. In IEEE INFOCOM 2018-IEEE Conference on Computer Communications. IEEE, 2087–2095
2018
-
[160]
Rui Wang, Heju Li, and Erwu Liu. 2021. Blockchain-based federated learning in mobile edge networks with application in internet of vehicles. arXiv preprint arXiv:2103.01116 (2021)
2021 arXiv
-
[161]
Yang Zhao, Jun Zhao, Linshan Jiang, Rui Tan, Dusit Niyato, Zengxiang Li, Lingjuan Lyu, and Yingbo Liu. 2020. Privacy-preserving blockchain-based federated learning for IoT devices. IEEE Internet of Things Journal 8, 3 (2020), 1817–1829
2020
-
[162]
Bin Gu, Zhiyuan Dang, Xiang Li, and Heng Huang. 2020. Federated doubly stochastic kernel learning for vertically partitioned data. In Proceedings of the 26th ACM SIGKDD international conference on knowledge discovery & data mining. 2483–2493
2020
-
[163]
Arjun Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin Calo. 2019. Analyzing federated learning through an adversarial lens. In International Conference on Machine Learning . PMLR, 634–643
2019
-
[164]
Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Zhenqiang Gong. 2020. Local model poisoning attacks to byzantine-robust federated learning. In Proceedings of the 29th USENIX Conference on Security Symposium . 1623–1640
2020
-
[165]
Di Cao, Shan Chang, Zhijian Lin, Guohua Liu, and Donghong Sun. 2019. Understanding distributed poisoning attack in federated learning. In 2019 IEEE 25th International Conference on Parallel and Distributed Systems (ICPADS) . IEEE, 233–239
2019
-
[166]
Leixia Wang, Qingqing Ye, Haibo Hu, Xiaofeng Meng, and Kai Huang. 2024. LDP-Purifier: Defending against Poisoning Attacks in Local Differential Privacy. In International Conference on Database Systems for Advanced Applications . Springer, 3–18
2024
-
[167]
Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. In International Conference on Artificial Intelligence and Statistics . PMLR, 2938–2948
2020
-
[168]
Chulin Xie, Keli Huang, Pin-Yu Chen, and Bo Li. 2020. Dba: Distributed backdoor attacks against federated learning. In International conference on learning representations
2020
-
[169]
C-L Chen, Leana Golubchik, and Marco Paolieri. 2020. Backdoor Attacks on Federated Meta-Learning. In 34th Conference on Neural Information Processing Systems
2020
-
[170]
Haoyang Li, Qingqing Ye, Haibo Hu, Jin Li, Leixia Wang, Chengfang Fang, and Jie Shi. 2023. 3DFed: Adaptive and Extensible Framework for Covert Backdoor Attack in Federated Learning. In 2023 IEEE Symposium on Security and Privacy (SP). IEEE, 1893–1907
2023
-
[171]
Ming Yang, Hang Cheng, Fei Chen, Ximeng Liu, Meiqing Wang, and Xibin Li. 2023. Model poisoning attack in differential privacy-based federated learning. Information Sciences 630 (2023), 158–172
2023
-
[172]
Florian Tramèr, Fan Zhang, Ari Juels, Michael K Reiter, and Thomas Ristenpart. 2016. Stealing Machine Learning Models via Prediction APIs.. In USENIX security symposium, Vol. 16. 601–618
2016
-
[173]
Yugeng Liu, Rui Wen, Xinlei He, Ahmed Salem, Zhikun Zhang, Michael Backes, Emiliano De Cristofaro, Mario Fritz, and Yang Zhang. 2022. ML-Doctor: Holistic Risk Assessment of Inference Attacks Against Machine Learning Models. In 31st USENIX Security Symposium (USENIX Security 22...
2022
-
[2019]
The Internet Society
-
[2022]
In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security
Truth serum: Poisoning machine learning models to reveal their secrets. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security . 2779–2792
2022
Reviewed August 11, 2026 · model on record in the stance chip above.
Discussion (0). Continue with ORCID to comment.