{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T04:45:12Z","timestamp":1784781912033,"version":"3.55.0"},"reference-count":74,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2025,4,8]],"date-time":"2025-04-08T00:00:00Z","timestamp":1744070400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Knowl. Discov. Data"],"published-print":{"date-parts":[[2025,4,30]]},"abstract":"<jats:p>Federated Learning (FL) is a decentralized model training framework that aims to merge isolated data islands while maintaining data privacy. However, recent studies have revealed that Generative Adversarial Network (GAN)-based attacks can be employed in FL to learn the distribution of private datasets and reconstruct recognizable images. In this article, we exploit defenses against GAN-based attacks in FL and propose a framework, Anti-GAN, to prevent attackers from learning the real distribution of the victim\u2019s data. The core idea of Anti-GAN is to manipulate the visual features of private training images to make them indistinguishable to human eyes even restored by attackers. Specifically, Anti-GAN projects the private dataset onto a GAN\u2019s generator and combines the generated fake images with the actual images to create the training dataset, which is then used for federated model training. The experimental results demonstrate that Anti-GAN is effective in preventing attackers from learning the distribution of private images while causing minimal harm to the accuracy of the federated model.<\/jats:p>","DOI":"10.1145\/3719350","type":"journal-article","created":{"date-parts":[[2025,2,26]],"date-time":"2025-02-26T15:34:11Z","timestamp":1740584051000},"page":"1-20","update-policy":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Exploiting Defenses against GAN-Based Feature Inference Attacks in Federated Learning"],"prefix":"10.1145","volume":"19","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0001-9671-5104","authenticated-orcid":false,"given":"Xinjian","family":"Luo","sequence":"first","affiliation":[{"name":"National University of Singapore, Singapore, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0001-3763-2330","authenticated-orcid":false,"given":"Xianglong","family":"Zhang","sequence":"additional","affiliation":[{"name":"University of Science and Technology Beijing, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,4,8]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_3_2","unstructured":"Apple.com. 2023. Differential Privacy. Retrieved July 28 2024 from https:\/\/2.zoppoz.workers.dev:443\/https\/www.apple.com\/privacy\/docs\/Differential_Privacy_Overview.pdf"},{"key":"e_1_3_2_4_2","first-page":"2938","volume-title":"International Conference on Artificial Intelligence and Statistics","author":"Bagdasaryan Eugene","year":"2020","unstructured":"Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. In International Conference on Artificial Intelligence and Statistics. PMLR, 2938\u20132948."},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00099"},{"key":"e_1_3_2_7_2","first-page":"267","volume-title":"28th USENIX Security Symposium (USENIX Security \u201919)","author":"Carlini Nicholas","year":"2019","unstructured":"Nicholas Carlini, Chang Liu, \u00dalfar Erlingsson, Jernej Kos, and Dawn Song. 2019. The secret sharer: Evaluating and testing unintended memorization in neural networks. In 28th USENIX Security Symposium (USENIX Security \u201919), 267\u2013284."},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417238"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243834"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00018"},{"key":"e_1_3_2_13_2","unstructured":"Robin C. Geyer Tassilo Klein and Moin Nabi. 2017. Differentially private federated learning: A client level perspective. arXiv:1712.07557. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/1712.07557"},{"key":"e_1_3_2_14_2","first-page":"2672","article-title":"Generative adversarial nets","author":"Goodfellow Ian","year":"2014","unstructured":"Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio. 2014. Generative adversarial nets. In Advances in Neural Information Processing Systems, 2672\u20132680.","journal-title":"In Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_15_2","first-page":"5767","volume-title":"Advances in Neural Information Processing Systems","author":"Gulrajani Ishaan","year":"2017","unstructured":"Ishaan Gulrajani, Faruk Ahmed, Martin Arjovsky, Vincent Dumoulin, and Aaron C. Courville. 2017. Improved training of Wasserstein GANs. In Advances in Neural Information Processing Systems, 5767\u20135777."},{"key":"e_1_3_2_16_2","first-page":"8056","volume-title":"International Conference on Machine Learning","author":"Guo Chuan","year":"2022","unstructured":"Chuan Guo, Brian Karrer, Kamalika Chaudhuri, and Laurens van der Maaten. 2022. Bounding training data reconstruction in private (deep) learning. In International Conference on Machine Learning. PMLR, 8056\u20138071."},{"key":"e_1_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-19-8991-9_29"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"e_1_3_2_21_2","first-page":"4507","volume-title":"International Conference on Machine Learning","author":"Huang Yangsibo","year":"2020","unstructured":"Yangsibo Huang, Zhao Song, Kai Li, and Sanjeev Arora. 2020. InstaHide: Instance-hiding schemes for private distributed learning. In International Conference on Machine Learning. PMLR, 4507\u20134518."},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.632"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560663"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00113"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2023.3349323"},{"key":"e_1_3_2_26_2","unstructured":"Yangfan Jiang Xinjian Luo Yin Yang and Xiaokui Xiao. 2024. Calibrating noise for group privacy in subsampled mechanisms. arXiv:2408.09943. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2408.09943"},{"key":"e_1_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417872"},{"key":"e_1_3_2_28_2","first-page":"1","volume-title":"3rd International Conference on Learning Representations (ICLR \u201915)","author":"Kingma Diederik P.","year":"2015","unstructured":"Diederik P. Kingma and Jimmy Ba. 2015. Adam: A method for stochastic optimization. In 3rd International Conference on Learning Representations (ICLR \u201915), 1\u201315."},{"key":"e_1_3_2_29_2","unstructured":"Alex Krizhevsky and Geoffrey Hinton. 2009. Learning Multiple Layers of Features from Tiny Images. Technical report. University of Toronto Toronto Ontario. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/www.cs.toronto.edu\/~kriz\/learning-features-2009-TR.pdf"},{"key":"e_1_3_2_30_2","first-page":"1522","volume-title":"International Conference on Artificial Intelligence and Statistics","author":"Lin Zinan","year":"2021","unstructured":"Zinan Lin, Vyas Sekar, and Giulia Fanti. 2021. On the privacy properties of GAN-generated samples. In International Conference on Artificial Intelligence and Statistics. PMLR, 1522\u20131530."},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"e_1_3_2_32_2","doi-asserted-by":"crossref","unstructured":"Xinjian Luo Yangfan Jiang Fei Wei Yuncheng Wu Xiaokui Xiao and Beng Chin Ooi. 2024. Exploring privacy and fairness risks in sharing diffusion models: An adversarial perspective. IEEE Transactions on Information Forensics and Security 19 (2024) 8109\u20138124.","DOI":"10.1109\/TIFS.2024.3453555"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560573"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00023"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i2.20084"},{"key":"e_1_3_2_36_2","unstructured":"Xinjian Luo and Xianglong Zhang. 2020. Exploiting defenses against GAN-based feature inference attacks in federated learning. arXiv:2004.12571. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2004.12571"},{"key":"e_1_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833623"},{"key":"e_1_3_2_38_2","first-page":"1273","volume-title":"Artificial Intelligence and Statistics","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Artificial Intelligence and Statistics. PMLR, 1273\u20131282."},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN54540.2023.10191260"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"e_1_3_2_41_2","unstructured":"Mehdi Mirza and Simon Osindero. 2014. Conditional generative adversarial nets. arXiv:1411.1784. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/1411.1784"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"e_1_3_2_43_2","first-page":"467","volume-title":"European Conference on Computer Vision","author":"Na Dongbin","year":"2022","unstructured":"Dongbin Na, Sangwoo Ji, and Jong Kim. 2022. Unrestricted black-box adversarial attack using GAN with limited queries. In European Conference on Computer Vision. Springer, 467\u2013482."},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"e_1_3_2_45_2","first-page":"1","volume-title":"4th International Conference on Learning Representations (ICLR \u201916)","author":"Radford Alec","year":"2016","unstructured":"Alec Radford, Luke Metz, and Soumith Chintala. 2016. Unsupervised representation learning with deep convolutional generative adversarial networks. In 4th International Conference on Learning Representations (ICLR \u201916), 1\u201316."},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"e_1_3_2_47_2","doi-asserted-by":"publisher","DOI":"10.1109\/WACV51458.2022.00366"},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i8.26163"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813687"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.1186\/s40537-019-0197-0"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2020.2993966"},{"key":"e_1_3_2_53_2","doi-asserted-by":"publisher","DOI":"10.1145\/3338501.3357370"},{"key":"e_1_3_2_54_2","first-page":"9690","volume-title":"International Conference on Machine Learning","author":"Van Amersfoort Joost","year":"2020","unstructured":"Joost Van Amersfoort, Lewis Smith, Yee Whye Teh, and Yarin Gal. 2020. Uncertainty estimation using a single deep deterministic neural network. In International Conference on Machine Learning. PMLR, 9690\u20139700."},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1109\/TIP.2003.819861"},{"key":"e_1_3_2_56_2","first-page":"3328","article-title":"Poisoning-assisted property inference attack against federated learning","author":"Wang Zhibo","year":"2022","unstructured":"Zhibo Wang, Yuting Huang, Mengkai Song, Libing Wu, Feng Xue, and Kui Ren. 2022. Poisoning-assisted property inference attack against federated learning. IEEE Transactions on Dependable and Secure Computing 20, 4 (2022), 3328\u20133340.","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"e_1_3_2_57_2","doi-asserted-by":"crossref","first-page":"2512","DOI":"10.1109\/INFOCOM.2019.8737416","article-title":"Beyond inferring class representatives: User-level privacy leakage from federated learning","author":"Wang Zhibo","year":"2019","unstructured":"Zhibo Wang, Mengkai Song, Zhifei Zhang, Yang Song, Qian Wang, and Hairong Qi. 2019. Beyond inferring class representatives: User-level privacy leakage from federated learning. In IEEE Conference on Computer Communications (IEEE INFOCOM \u201919). IEEE, 2512\u20132520.","journal-title":"IEEE Conference on Computer Communications (IEEE INFOCOM \u201919)"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58951-6_27"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2016.32"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.14778\/3407790.3407811"},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.5555\/3304222.3304312"},{"key":"e_1_3_2_62_2","unstructured":"Han Xiao Kashif Rasul and Roland Vollgraf. 2017. Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms. arXiv:1708.07747. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/1708.07747"},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2010.247"},{"key":"e_1_3_2_64_2","unstructured":"LeCun Yann Cortes Corinna and J. C. Burges Christopher. 1998. The MNIST Database of Handwritten Digits. Retrieved July 28 2024 from https:\/\/2.zoppoz.workers.dev:443\/http\/yann.lecun.com\/exdb\/mnist\/"},{"key":"e_1_3_2_65_2","first-page":"3320","volume-title":"27th International Conference on Neural Information Processing Systems (NIPS \u201914)","author":"Yosinski Jason","year":"2014","unstructured":"Jason Yosinski, Jeff Clune, Yoshua Bengio, and Hod Lipson. 2014. How transferable are features in deep neural networks? In 27th International Conference on Neural Information Processing Systems (NIPS \u201914). MIT Press, Cambridge, MA, 3320\u20133328."},{"key":"e_1_3_2_66_2","unstructured":"Ashkan Yousefpour Igor Shilov Alexandre Sablayrolles Davide Testuggine Karthik Prasad Mani Malek John Nguyen Sayan Ghosh Akash Bharadwaj Jessica Zhao et al. 2021. Opacus: User-friendly differential privacy library in PyTorch. arXiv:2109.12298. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2109.12298"},{"key":"e_1_3_2_67_2","first-page":"493","volume-title":"2020 USENIX Annual Technical Conference (USENIX ATC \u201920)","author":"Zhang Chengliang","year":"2020","unstructured":"Chengliang Zhang, Suyi Li, Junzhe Xia, Wei Wang, Feng Yan, and Yang Liu. 2020. {BatchCrypt}: Efficient homomorphic encryption for {Cross-Silo} federated learning. In 2020 USENIX Annual Technical Conference (USENIX ATC \u201920), 493\u2013506."},{"key":"e_1_3_2_68_2","first-page":"1","volume-title":"6th International Conference on Learning Representations (ICLR \u201918)","author":"Zhang Hongyi","year":"2018","unstructured":"Hongyi Zhang, Moustapha Ciss\u00e9, Yann N. Dauphin, and David Lopez-Paz. 2018. Mixup: Beyond empirical risk minimization. In 6th International Conference on Learning Representations (ICLR \u201918). OpenReview.net, 1\u201313."},{"key":"e_1_3_2_69_2","first-page":"26048","volume-title":"International Conference on Machine Learning (ICML \u201922)","author":"Zhang Xinwei","year":"2022","unstructured":"Xinwei Zhang, Xiangyi Chen, Mingyi Hong, Zhiwei Steven Wu, and Jinfeng Yi. 2022. Understanding clipping for federated learning: Convergence and client-level differential privacy. In International Conference on Machine Learning (ICML \u201922), 26048\u201326067."},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00033"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.00072"},{"key":"e_1_3_2_72_2","first-page":"14747","volume-title":"Annual Conference on Neural Information Processing Systems (NeurIPS \u201919)","author":"Zhu Ligeng","year":"2019","unstructured":"Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep leakage from gradients. In Annual Conference on Neural Information Processing Systems (NeurIPS \u201919), 14747\u201314756."},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-96530-3"},{"key":"e_1_3_2_74_2","unstructured":"Xiaochen Zhu Xinjian Luo Yuncheng Wu Yangfan Jiang Xiaokui Xiao and Beng Chin Ooi. 2023. Passive inference attacks on split learning via adversarial regularization. arXiv:2310.10483. Retrieved from https:\/\/2.zoppoz.workers.dev:443\/https\/arxiv.org\/abs\/2310.10483"},{"key":"e_1_3_2_75_2","first-page":"5251","volume-title":"33rd USENIX Security Symposium (USENIX Security \u201924)","author":"Zhuang Yuanxin","year":"2024","unstructured":"Yuanxin Zhuang, Chuan Shi, Mengmei Zhang, Jinghui Chen, Lingjuan Lyu, Pan Zhou, and Lichao Sun. 2024. Unveiling the secrets without data: Can graph neural networks be exploited through data-free model extraction attacks? In 33rd USENIX Security Symposium (USENIX Security \u201924). USENIX Association, 5251\u20135268."}],"container-title":["ACM Transactions on Knowledge Discovery from Data"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3719350","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3719350","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T18:43:21Z","timestamp":1750272201000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3719350"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,4,8]]},"references-count":74,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2025,4,30]]}},"alternative-id":["10.1145\/3719350"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3719350","relation":{},"ISSN":["1556-4681","1556-472X"],"issn-type":[{"value":"1556-4681","type":"print"},{"value":"1556-472X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,4,8]]},"assertion":[{"value":"2023-12-14","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-02-15","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-04-08","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}