{"id":"https://openalex.org/W4385589237","doi":"https://doi.org/10.1109/tifs.2023.3302161","title":"EGIA: An External Gradient Inversion Attack in Federated Learning","display_name":"EGIA: An External Gradient Inversion Attack in Federated Learning","publication_year":2023,"publication_date":"2023-01-01","ids":{"openalex":"https://openalex.org/W4385589237","doi":"https://doi.org/10.1109/tifs.2023.3302161"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2023.3302161","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2023.3302161","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5014372778","display_name":"Haotian Liang","orcid":"https://orcid.org/0000-0003-2575-731X"},"institutions":[{"id":"https://openalex.org/I125839683","display_name":"Beijing Institute of Technology","ror":"https://ror.org/01skt4w74","country_code":"CN","type":"education","lineage":["https://openalex.org/I125839683","https://openalex.org/I890469752"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Haotian Liang","raw_affiliation_strings":["School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0003-2575-731X","affiliations":[{"raw_affiliation_string":"School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China","institution_ids":["https://openalex.org/I125839683"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5001159156","display_name":"Youqi Li","orcid":"https://orcid.org/0000-0003-3867-5997"},"institutions":[{"id":"https://openalex.org/I125839683","display_name":"Beijing Institute of Technology","ror":"https://ror.org/01skt4w74","country_code":"CN","type":"education","lineage":["https://openalex.org/I125839683","https://openalex.org/I890469752"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Youqi Li","raw_affiliation_strings":["School of Computer Science and Technology, Beijing Institute of Technology, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0003-3867-5997","affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, Beijing Institute of Technology, Beijing, China","institution_ids":["https://openalex.org/I125839683"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100380072","display_name":"Chuan Zhang","orcid":"https://orcid.org/0000-0001-7684-8540"},"institutions":[{"id":"https://openalex.org/I125839683","display_name":"Beijing Institute of Technology","ror":"https://ror.org/01skt4w74","country_code":"CN","type":"education","lineage":["https://openalex.org/I125839683","https://openalex.org/I890469752"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chuan Zhang","raw_affiliation_strings":["School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0001-7684-8540","affiliations":[{"raw_affiliation_string":"School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China","institution_ids":["https://openalex.org/I125839683"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058120371","display_name":"Ximeng Liu","orcid":"https://orcid.org/0000-0002-4238-3295"},"institutions":[{"id":"https://openalex.org/I80947539","display_name":"Fuzhou University","ror":"https://ror.org/011xvna82","country_code":"CN","type":"education","lineage":["https://openalex.org/I80947539"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ximeng Liu","raw_affiliation_strings":["College of Computer and Data Science, Fuzhou University, Fuzhou, China"],"raw_orcid":"https://orcid.org/0000-0002-4238-3295","affiliations":[{"raw_affiliation_string":"College of Computer and Data Science, Fuzhou University, Fuzhou, China","institution_ids":["https://openalex.org/I80947539"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100634361","display_name":"Liehuang Zhu","orcid":"https://orcid.org/0000-0003-3277-3887"},"institutions":[{"id":"https://openalex.org/I125839683","display_name":"Beijing Institute of Technology","ror":"https://ror.org/01skt4w74","country_code":"CN","type":"education","lineage":["https://openalex.org/I125839683","https://openalex.org/I890469752"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Liehuang Zhu","raw_affiliation_strings":["School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China"],"raw_orcid":"https://orcid.org/0000-0003-3277-3887","affiliations":[{"raw_affiliation_string":"School of Cyberspace Science and Technology, Beijing Institute of Technology, Beijing, China","institution_ids":["https://openalex.org/I125839683"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":6.2001,"has_fulltext":false,"cited_by_count":38,"citation_normalized_percentile":{"value":0.97224265,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":100},"biblio":{"volume":"18","issue":null,"first_page":"4984","last_page":"4995"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.991100013256073,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9821000099182129,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8658755421638489},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.7733748555183411},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.7376558184623718},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.586844265460968},{"id":"https://openalex.org/keywords/inversion","display_name":"Inversion (geology)","score":0.5621466636657715},{"id":"https://openalex.org/keywords/server","display_name":"Server","score":0.5425640940666199},{"id":"https://openalex.org/keywords/single-point-of-failure","display_name":"Single point of failure","score":0.4673393666744232},{"id":"https://openalex.org/keywords/threat-model","display_name":"Threat model","score":0.46512600779533386},{"id":"https://openalex.org/keywords/adversary-model","display_name":"Adversary model","score":0.45551884174346924},{"id":"https://openalex.org/keywords/focus","display_name":"Focus (optics)","score":0.4193107485771179},{"id":"https://openalex.org/keywords/distributed-computing","display_name":"Distributed computing","score":0.305126428604126},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.30436667799949646},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.25805914402008057}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8658755421638489},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.7733748555183411},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.7376558184623718},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.586844265460968},{"id":"https://openalex.org/C1893757","wikidata":"https://www.wikidata.org/wiki/Q3653001","display_name":"Inversion (geology)","level":3,"score":0.5621466636657715},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.5425640940666199},{"id":"https://openalex.org/C165136773","wikidata":"https://www.wikidata.org/wiki/Q1363179","display_name":"Single point of failure","level":2,"score":0.4673393666744232},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.46512600779533386},{"id":"https://openalex.org/C7606001","wikidata":"https://www.wikidata.org/wiki/Q4686702","display_name":"Adversary model","level":3,"score":0.45551884174346924},{"id":"https://openalex.org/C192209626","wikidata":"https://www.wikidata.org/wiki/Q190909","display_name":"Focus (optics)","level":2,"score":0.4193107485771179},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.305126428604126},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.30436667799949646},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.25805914402008057},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0},{"id":"https://openalex.org/C120665830","wikidata":"https://www.wikidata.org/wiki/Q14620","display_name":"Optics","level":1,"score":0.0},{"id":"https://openalex.org/C109007969","wikidata":"https://www.wikidata.org/wiki/Q749565","display_name":"Structural basin","level":2,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tifs.2023.3302161","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2023.3302161","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1129519853","display_name":null,"funder_award_id":"62102027","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G1358063641","display_name":null,"funder_award_id":"2021M700434","funder_id":"https://openalex.org/F4320321543","funder_display_name":"China Postdoctoral Science Foundation"},{"id":"https://openalex.org/G3382174471","display_name":null,"funder_award_id":"2021YFB2700503","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"},{"id":"https://openalex.org/G3549477485","display_name":null,"funder_award_id":"BX20220029","funder_id":"https://openalex.org/F4320321543","funder_display_name":"China Postdoctoral Science Foundation"},{"id":"https://openalex.org/G3830888734","display_name":null,"funder_award_id":"2021TQ0042","funder_id":"https://openalex.org/F4320321543","funder_display_name":"China Postdoctoral Science Foundation"},{"id":"https://openalex.org/G4110199667","display_name":null,"funder_award_id":"2021TQ0041","funder_id":"https://openalex.org/F4320321543","funder_display_name":"China Postdoctoral Science Foundation"},{"id":"https://openalex.org/G422805606","display_name":null,"funder_award_id":"2022M710007","funder_id":"https://openalex.org/F4320321543","funder_display_name":"China Postdoctoral Science Foundation"},{"id":"https://openalex.org/G4376067305","display_name":null,"funder_award_id":"2021M700435","funder_id":"https://openalex.org/F4320321543","funder_display_name":"China Postdoctoral Science Foundation"},{"id":"https://openalex.org/G4407196569","display_name":null,"funder_award_id":"62202051","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G8412797348","display_name":null,"funder_award_id":"62102028","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320321543","display_name":"China Postdoctoral Science Foundation","ror":"https://ror.org/0426zh255"},{"id":"https://openalex.org/F4320335777","display_name":"National Key Research and Development Program of China","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":48,"referenced_works":["https://openalex.org/W2186615578","https://openalex.org/W2591882872","https://openalex.org/W2622263826","https://openalex.org/W2766273648","https://openalex.org/W2767079719","https://openalex.org/W2774000609","https://openalex.org/W2781091734","https://openalex.org/W2785456003","https://openalex.org/W2884711234","https://openalex.org/W2963456518","https://openalex.org/W2963540401","https://openalex.org/W2970408908","https://openalex.org/W2977797911","https://openalex.org/W3000479830","https://openalex.org/W3016632787","https://openalex.org/W3018397821","https://openalex.org/W3033686777","https://openalex.org/W3138815606","https://openalex.org/W3167424384","https://openalex.org/W3173298348","https://openalex.org/W3175192640","https://openalex.org/W3212378239","https://openalex.org/W3213758553","https://openalex.org/W4205368719","https://openalex.org/W4206426144","https://openalex.org/W4226047321","https://openalex.org/W4226461837","https://openalex.org/W4285166735","https://openalex.org/W4287632157","https://openalex.org/W4287822453","https://openalex.org/W4289656845","https://openalex.org/W4308644262","https://openalex.org/W4318619660","https://openalex.org/W4320013936","https://openalex.org/W4360995097","https://openalex.org/W6686509673","https://openalex.org/W6728757088","https://openalex.org/W6739622702","https://openalex.org/W6745115194","https://openalex.org/W6746839373","https://openalex.org/W6748579526","https://openalex.org/W6753209298","https://openalex.org/W6773039429","https://openalex.org/W6775563089","https://openalex.org/W6776213126","https://openalex.org/W6803316053","https://openalex.org/W6803951002","https://openalex.org/W6841030189"],"related_works":["https://openalex.org/W4320018150","https://openalex.org/W4239582170","https://openalex.org/W2918664383","https://openalex.org/W2034199088","https://openalex.org/W2085319386","https://openalex.org/W1551379303","https://openalex.org/W2136110824","https://openalex.org/W2076205949","https://openalex.org/W2904814116","https://openalex.org/W2016320410"],"abstract_inverted_index":{"Federated":[0],"learning":[1,9],"(FL)":[2],"has":[3,16,112,161],"achieved":[4],"state-of-the-art":[5],"performance":[6],"in":[7,41,89,102,157],"distributed":[8],"tasks":[10],"with":[11],"privacy":[12],"requirements.":[13],"However,":[14,58],"it":[15],"been":[17,113],"discovered":[18],"that":[19,99,121,185],"FL":[20,73,103],"is":[21,48,71,189],"vulnerable":[22],"to":[23,35,50,173],"adversarial":[24],"attacks.":[25],"The":[26,179],"typical":[27],"gradient":[28],"inversion":[29],"attacks":[30],"primarily":[31],"focus":[32],"on":[33,96,169],"attempting":[34],"obtain":[36],"the":[37,46,53,56,61,64,72,90,97,108,127,135,138,153,159,163,175,186],"client\u2019s":[38],"private":[39,128],"input":[40,129],"a":[42,80,148],"white-box":[43],"manner,":[44],"where":[45],"adversary":[47,124,160],"assumed":[49],"be":[51],"either":[52],"client":[54],"or":[55],"server.":[57],"if":[59,133],"both":[60,134],"clients":[62,136],"and":[63,68,137,142],"server":[65,139],"are":[66,104,140],"honest":[67,141],"fully":[69,143],"trusted,":[70],"secure?":[74],"In":[75],"this":[76,117],"paper,":[77],"we":[78,94,119],"propose":[79],"novel":[81],"method":[82,188],"called":[83],"External":[84],"Gradient":[85],"Inversion":[86],"Attack":[87],"(EGIA)":[88],"grey-box":[91],"settings.":[92],"Specifically,":[93],"concentrate":[95],"point":[98],"public-shared":[100],"gradients":[101,131],"always":[105],"transmitted":[106],"through":[107],"intermediary":[109],"nodes,":[110],"which":[111,158],"widely":[114],"ignored.":[115],"On":[116],"basis,":[118],"demonstrate":[120],"an":[122],"external":[123],"can":[125],"reconstruct":[126],"using":[130],"even":[132],"trusted.":[144],"We":[145,165],"also":[146],"provide":[147],"comprehensive":[149],"theoretical":[150],"analysis":[151],"of":[152,177,181],"black-box":[154],"attack":[155],"scenario":[156],"only":[162],"gradients.":[164],"perform":[166],"extensive":[167],"experiments":[168,183],"multiple":[170],"real-world":[171],"datasets":[172],"test":[174],"effectiveness":[176],"EGIA.":[178],"outcomes":[180],"our":[182],"validate":[184],"EGIA":[187],"highly":[190],"effective.":[191]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":19},{"year":2024,"cited_by_count":12},{"year":2023,"cited_by_count":4}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
