{"id":"https://openalex.org/W4300991139","doi":"https://doi.org/10.1109/tdsc.2022.3196646","title":"Poisoning-Assisted Property Inference Attack Against Federated Learning","display_name":"Poisoning-Assisted Property Inference Attack Against Federated Learning","publication_year":2022,"publication_date":"2022-08-05","ids":{"openalex":"https://openalex.org/W4300991139","doi":"https://doi.org/10.1109/tdsc.2022.3196646"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2022.3196646","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_indexed_in_scopus":true,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"journal-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100422345","display_name":"Zhibo Wang","orcid":"https://orcid.org/0000-0002-5804-3279"},"institutions":[{"id":"https://openalex.org/I168879160","display_name":"Zhejiang University of Science and Technology","ror":"https://ror.org/05mx0wr29","country_code":"CN","type":"education","lineage":["https://openalex.org/I168879160"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhibo Wang","raw_affiliation_strings":["School of Cyber Science and Technology, ZJU-Hangzhou Global Scientific and Technological Innovation Center, Zhejiang University, Hangzhou, Zhejiang, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Technology, ZJU-Hangzhou Global Scientific and Technological Innovation Center, Zhejiang University, Hangzhou, Zhejiang, China","institution_ids":["https://openalex.org/I168879160"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5015051163","display_name":"Yuting Huang","orcid":"https://orcid.org/0000-0001-8773-1786"},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"funder","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yuting Huang","raw_affiliation_strings":["School of Cyber Science and Engineering, Wuhan University, Wuhan, Hubei, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Wuhan University, Wuhan, Hubei, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5085556383","display_name":"Mengkai Song","orcid":"https://orcid.org/0000-0002-7907-3469"},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"funder","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Mengkai Song","raw_affiliation_strings":["School of Cyber Science and Engineering, Wuhan University, Wuhan, Hubei, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Wuhan University, Wuhan, Hubei, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5102735309","display_name":"Libing Wu","orcid":"https://orcid.org/0000-0002-6863-3280"},"institutions":[{"id":"https://openalex.org/I37461747","display_name":"Wuhan University","ror":"https://ror.org/033vjfk17","country_code":"CN","type":"funder","lineage":["https://openalex.org/I37461747"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Libing Wu","raw_affiliation_strings":["School of Cyber Science and Engineering, Wuhan University, Wuhan, Hubei, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Engineering, Wuhan University, Wuhan, Hubei, China","institution_ids":["https://openalex.org/I37461747"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5036168675","display_name":"Xue Feng","orcid":"https://orcid.org/0000-0002-9057-1549"},"institutions":[],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Feng Xue","raw_affiliation_strings":["Technology Co., LTD, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"Technology Co., LTD, Hangzhou, China","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5105297718","display_name":"Kui Ren","orcid":"https://orcid.org/0000-0002-1969-2591"},"institutions":[{"id":"https://openalex.org/I76130692","display_name":"Zhejiang University","ror":"https://ror.org/00a2xv884","country_code":"CN","type":"funder","lineage":["https://openalex.org/I76130692"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Kui Ren","raw_affiliation_strings":["School of Cyber Science and Technology, Zhejiang Provincial Key Laboratory of Blockchain and Cyberspace Governance, Zhejiang University, Hangzhou, Zhejiang, China"],"affiliations":[{"raw_affiliation_string":"School of Cyber Science and Technology, Zhejiang Provincial Key Laboratory of Blockchain and Cyberspace Governance, Zhejiang University, Hangzhou, Zhejiang, China","institution_ids":["https://openalex.org/I76130692"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":4.076,"has_fulltext":false,"cited_by_count":30,"citation_normalized_percentile":{"value":0.999972,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":98},"biblio":{"volume":"20","issue":"4","first_page":"3328","last_page":"3340"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9995,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9839,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/discriminative-model","display_name":"Discriminative model","score":0.64745957}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.78779155},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.78516304},{"id":"https://openalex.org/C189950617","wikidata":"https://www.wikidata.org/wiki/Q937228","display_name":"Property (philosophy)","level":2,"score":0.675182},{"id":"https://openalex.org/C97931131","wikidata":"https://www.wikidata.org/wiki/Q5282087","display_name":"Discriminative model","level":2,"score":0.64745957},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.5651607},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.50265765},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.4787973},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.47309807},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2022.3196646","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_indexed_in_scopus":true,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.61,"display_name":"Reduced inequalities","id":"https://metadata.un.org/sdg/10"}],"grants":[{"funder":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China","award_id":"61872274"},{"funder":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China","award_id":"U20A20182"},{"funder":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China","award_id":"62122066"}],"datasets":[],"versions":[],"referenced_works_count":31,"referenced_works":["https://openalex.org/W114517082","https://openalex.org/W2051267297","https://openalex.org/W2116612304","https://openalex.org/W2156579478","https://openalex.org/W2168231600","https://openalex.org/W2535690855","https://openalex.org/W2591882872","https://openalex.org/W2786233556","https://openalex.org/W2810065831","https://openalex.org/W2886444620","https://openalex.org/W2887995258","https://openalex.org/W2897830718","https://openalex.org/W2899461894","https://openalex.org/W2903356604","https://openalex.org/W2947642149","https://openalex.org/W2963456518","https://openalex.org/W2964162474","https://openalex.org/W2980189717","https://openalex.org/W2983140679","https://openalex.org/W3033686777","https://openalex.org/W3035556513","https://openalex.org/W3035644192","https://openalex.org/W3048715803","https://openalex.org/W3096738375","https://openalex.org/W3103245149","https://openalex.org/W3118608800","https://openalex.org/W3138597937","https://openalex.org/W3194761092","https://openalex.org/W4291984345","https://openalex.org/W4297687186","https://openalex.org/W4318619660"],"related_works":["https://openalex.org/W4389116644","https://openalex.org/W4205463238","https://openalex.org/W3103844505","https://openalex.org/W2965546495","https://openalex.org/W2761785940","https://openalex.org/W259157601","https://openalex.org/W2544678430","https://openalex.org/W2153315159","https://openalex.org/W2110523656","https://openalex.org/W1482209366"],"abstract_inverted_index":{"Federated":[0],"learning":[1,9,69],"(FL)":[2],"has":[3,71,97],"emerged":[4],"as":[5,43],"an":[6],"ideal":[7],"privacy-preserving":[8],"technique":[10],"which":[11,141],"can":[12,105,161],"train":[13],"a":[14,18,117,157,165,177],"global":[15,95],"model":[16,96,139,160,199],"in":[17,26,79,107,136,200],"collaborative":[19],"way":[20],"while":[21,77],"preserving":[22],"the":[23,27,52,61,68,94,137,143,146,150,153,170,183,189,193,212,224],"private":[24],"data":[25,63,147,187],"local.":[28],"However,":[29],"recent":[30],"advances":[31],"have":[32],"demonstrated":[33],"that":[34,64,130,221],"FL":[35,102],"is":[36,129],"still":[37],"vulnerable":[38],"to":[39,57,191,207],"inference":[40,54,85,121,227],"attacks,":[41,51],"such":[42],"reconstruction":[44],"attack":[45,86,122,159],"and":[46,108],"membership":[47],"inference.":[48],"Among":[49],"these":[50],"property":[53,84,120,226],"attack,":[55],"aiming":[56],"infer":[58],"properties":[59],"of":[60,145,152,185,196],"training":[62,186],"are":[65,205],"irrelevant":[66],"with":[67],"objective,":[70],"not":[72],"received":[73],"too":[74],"much":[75],"attention":[76],"resulting":[78],"severe":[80],"privacy":[81],"leakage.":[82],"Existing":[83],"approaches":[87],"either":[88],"cannot":[89],"achieve":[90],"satisfactory":[91],"performance":[92],"when":[93],"converged":[98],"or":[99],"under":[100],"dynamic":[101],"where":[103],"participants":[104,204],"drop":[106,109],"out":[110],"freely.":[111],"In":[112],"this":[113],"paper,":[114],"we":[115,175],"propose":[116],"novel":[118],"poisoning-assisted":[119],"(PAPI-attack)":[123],"against":[124,229],"FL.":[125,201,230],"The":[126],"key":[127],"insight":[128],"there":[131],"exists":[132],"underlying":[133],"discriminative":[134],"ability":[135],"periodic":[138],"updates,":[140],"reflects":[142],"change":[144],"distribution,":[148],"especially":[149],"occurrence":[151],"sensitive":[154,213],"property.":[155,214],"Thus,":[156],"binary":[158],"be":[162],"constructed":[163],"by":[164,181],"malicious":[166],"participant":[167],"for":[168],"inferring":[169],"unintended":[171],"information.":[172],"More":[173],"importantly,":[174],"present":[176],"property-specific":[178],"poisoning":[179],"mechanism":[180],"modifying":[182],"label":[184],"from":[188],"adversary":[190],"distort":[192],"decision":[194],"boundary":[195],"shared":[197],"(global)":[198],"Consequently,":[202],"benign":[203],"induced":[206],"disclose":[208],"more":[209],"information":[210],"about":[211],"Extensive":[215],"experiments":[216],"on":[217],"real-world":[218],"datasets":[219],"demonstrate":[220],"PAPI-attack":[222],"outperforms":[223],"state-of-the-art":[225],"attacks":[228]},"abstract_inverted_index_v3":null,"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4300991139","counts_by_year":[{"year":2025,"cited_by_count":3},{"year":2024,"cited_by_count":12},{"year":2023,"cited_by_count":13},{"year":2022,"cited_by_count":1},{"year":2020,"cited_by_count":1}],"updated_date":"2025-05-05T00:38:02.595208","created_date":"2022-10-04"}