{"id":"https://openalex.org/W4412446159","doi":"https://doi.org/10.1109/tifs.2025.3589127","title":"GI-NAS: Boosting Gradient Inversion Attacks Through Adaptive Neural Architecture Search","display_name":"GI-NAS: Boosting Gradient Inversion Attacks Through Adaptive Neural Architecture Search","publication_year":2025,"publication_date":"2025-01-01","ids":{"openalex":"https://openalex.org/W4412446159","doi":"https://doi.org/10.1109/tifs.2025.3589127"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2025.3589127","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2025.3589127","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5056788762","display_name":"Wenbo Yu","orcid":null},"institutions":[{"id":"https://openalex.org/I4210114105","display_name":"Tsinghua\u2013Berkeley Shenzhen Institute","ror":"https://ror.org/02hhwwz98","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210114105","https://openalex.org/I95457486","https://openalex.org/I99065089"]},{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Wenbo Yu","raw_affiliation_strings":["Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, Guangdong, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, Guangdong, China","institution_ids":["https://openalex.org/I4210114105","https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5109393372","display_name":"Hao F","orcid":null},"institutions":[{"id":"https://openalex.org/I4210114105","display_name":"Tsinghua\u2013Berkeley Shenzhen Institute","ror":"https://ror.org/02hhwwz98","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210114105","https://openalex.org/I95457486","https://openalex.org/I99065089"]},{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hao Fang","raw_affiliation_strings":["Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, Guangdong, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, Guangdong, China","institution_ids":["https://openalex.org/I4210114105","https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100427338","display_name":"Bin Chen","orcid":"https://orcid.org/0000-0002-4798-230X"},"institutions":[{"id":"https://openalex.org/I204983213","display_name":"Harbin Institute of Technology","ror":"https://ror.org/01yqg2h08","country_code":"CN","type":"education","lineage":["https://openalex.org/I204983213"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Bin Chen","raw_affiliation_strings":["School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen, Guangdong, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen, Guangdong, China","institution_ids":["https://openalex.org/I204983213"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101371691","display_name":"Xiaohang Sui","orcid":"https://orcid.org/0009-0002-3653-5894"},"institutions":[{"id":"https://openalex.org/I204983213","display_name":"Harbin Institute of Technology","ror":"https://ror.org/01yqg2h08","country_code":"CN","type":"education","lineage":["https://openalex.org/I204983213"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiaohang Sui","raw_affiliation_strings":["School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen, Guangdong, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, Harbin Institute of Technology, Shenzhen, Guangdong, China","institution_ids":["https://openalex.org/I204983213"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100429133","display_name":"Chuan Chen","orcid":"https://orcid.org/0000-0002-7048-3445"},"institutions":[{"id":"https://openalex.org/I157773358","display_name":"Sun Yat-sen University","ror":"https://ror.org/0064kty71","country_code":"CN","type":"education","lineage":["https://openalex.org/I157773358"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chuan Chen","raw_affiliation_strings":["School of Computer Science and Engineering, Sun Yat-sen University, Guangzhou, Guangdong, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, Sun Yat-sen University, Guangzhou, Guangdong, China","institution_ids":["https://openalex.org/I157773358"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100620225","display_name":"Hao Wu","orcid":"https://orcid.org/0000-0001-7575-5756"},"institutions":[{"id":"https://openalex.org/I4210089559","display_name":"Shenzhen Metro (China)","ror":"https://ror.org/008hpge95","country_code":"CN","type":"company","lineage":["https://openalex.org/I4210089559"]},{"id":"https://openalex.org/I4210114105","display_name":"Tsinghua\u2013Berkeley Shenzhen Institute","ror":"https://ror.org/02hhwwz98","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210114105","https://openalex.org/I95457486","https://openalex.org/I99065089"]},{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hao Wu","raw_affiliation_strings":["Shenzhen ShenNong Information Technology Company Ltd., Shenzhen, Guangdong, China","Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, Guangdong, China"],"affiliations":[{"raw_affiliation_string":"Shenzhen ShenNong Information Technology Company Ltd., Shenzhen, Guangdong, China","institution_ids":["https://openalex.org/I4210089559"]},{"raw_affiliation_string":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, Guangdong, China","institution_ids":["https://openalex.org/I4210114105","https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034104790","display_name":"Shu\u2010Tao Xia","orcid":"https://orcid.org/0000-0002-8639-982X"},"institutions":[{"id":"https://openalex.org/I4210114105","display_name":"Tsinghua\u2013Berkeley Shenzhen Institute","ror":"https://ror.org/02hhwwz98","country_code":"CN","type":"facility","lineage":["https://openalex.org/I4210114105","https://openalex.org/I95457486","https://openalex.org/I99065089"]},{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shu-Tao Xia","raw_affiliation_strings":["Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, Guangdong, China"],"affiliations":[{"raw_affiliation_string":"Tsinghua Shenzhen International Graduate School, Tsinghua University, Shenzhen, Guangdong, China","institution_ids":["https://openalex.org/I4210114105","https://openalex.org/I99065089"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100665814","display_name":"Ke Xu","orcid":"https://orcid.org/0000-0003-2587-8517"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ke Xu","raw_affiliation_strings":["Department of Computer Science and Technology, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Technology, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5056788762"],"corresponding_institution_ids":["https://openalex.org/I4210114105","https://openalex.org/I99065089"],"apc_list":null,"apc_paid":null,"fwci":2.4849,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.90506696,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":99},"biblio":{"volume":"20","issue":null,"first_page":"7648","last_page":"7662"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9921000003814697,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9921000003814697,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9750999808311462,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11775","display_name":"COVID-19 diagnosis using AI","score":0.9470999836921692,"subfield":{"id":"https://openalex.org/subfields/2741","display_name":"Radiology, Nuclear Medicine and Imaging"},"field":{"id":"https://openalex.org/fields/27","display_name":"Medicine"},"domain":{"id":"https://openalex.org/domains/4","display_name":"Health Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7794630527496338},{"id":"https://openalex.org/keywords/boosting","display_name":"Boosting (machine learning)","score":0.5673748850822449},{"id":"https://openalex.org/keywords/inversion","display_name":"Inversion (geology)","score":0.5639568567276001},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.5273737907409668},{"id":"https://openalex.org/keywords/architecture","display_name":"Architecture","score":0.4720533490180969},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.4593527615070343},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.4105365574359894},{"id":"https://openalex.org/keywords/geology","display_name":"Geology","score":0.08377262949943542}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7794630527496338},{"id":"https://openalex.org/C46686674","wikidata":"https://www.wikidata.org/wiki/Q466303","display_name":"Boosting (machine learning)","level":2,"score":0.5673748850822449},{"id":"https://openalex.org/C1893757","wikidata":"https://www.wikidata.org/wiki/Q3653001","display_name":"Inversion (geology)","level":3,"score":0.5639568567276001},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.5273737907409668},{"id":"https://openalex.org/C123657996","wikidata":"https://www.wikidata.org/wiki/Q12271","display_name":"Architecture","level":2,"score":0.4720533490180969},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.4593527615070343},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.4105365574359894},{"id":"https://openalex.org/C127313418","wikidata":"https://www.wikidata.org/wiki/Q1069","display_name":"Geology","level":0,"score":0.08377262949943542},{"id":"https://openalex.org/C109007969","wikidata":"https://www.wikidata.org/wiki/Q749565","display_name":"Structural basin","level":2,"score":0.0},{"id":"https://openalex.org/C142362112","wikidata":"https://www.wikidata.org/wiki/Q735","display_name":"Art","level":0,"score":0.0},{"id":"https://openalex.org/C153349607","wikidata":"https://www.wikidata.org/wiki/Q36649","display_name":"Visual arts","level":1,"score":0.0},{"id":"https://openalex.org/C151730666","wikidata":"https://www.wikidata.org/wiki/Q7205","display_name":"Paleontology","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tifs.2025.3589127","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2025.3589127","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G2802018518","display_name":null,"funder_award_id":"62171248","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G6595704328","display_name":null,"funder_award_id":"62301189","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G8239621031","display_name":null,"funder_award_id":"62176269","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":56,"referenced_works":["https://openalex.org/W32403112","https://openalex.org/W1901129140","https://openalex.org/W2001610032","https://openalex.org/W2007339694","https://openalex.org/W2019704260","https://openalex.org/W2108598243","https://openalex.org/W2119717200","https://openalex.org/W2151967815","https://openalex.org/W2194775991","https://openalex.org/W2263338482","https://openalex.org/W2606891064","https://openalex.org/W2765811365","https://openalex.org/W2773706593","https://openalex.org/W2796265726","https://openalex.org/W2885487916","https://openalex.org/W2897830718","https://openalex.org/W2930926105","https://openalex.org/W2962770929","https://openalex.org/W2962785568","https://openalex.org/W2962919941","https://openalex.org/W2963136578","https://openalex.org/W2963383962","https://openalex.org/W2963456518","https://openalex.org/W2964013315","https://openalex.org/W2970408908","https://openalex.org/W3012066402","https://openalex.org/W3016632787","https://openalex.org/W3094502228","https://openalex.org/W3094542121","https://openalex.org/W3096831136","https://openalex.org/W3109695251","https://openalex.org/W3117702776","https://openalex.org/W3123459983","https://openalex.org/W3138597937","https://openalex.org/W3155296704","https://openalex.org/W3163767593","https://openalex.org/W3172312230","https://openalex.org/W3175192640","https://openalex.org/W3203780767","https://openalex.org/W3217220299","https://openalex.org/W4200227341","https://openalex.org/W4239181501","https://openalex.org/W4285605911","https://openalex.org/W4312617935","https://openalex.org/W4312809802","https://openalex.org/W4383754164","https://openalex.org/W4385570839","https://openalex.org/W4385589237","https://openalex.org/W4387105517","https://openalex.org/W4387808640","https://openalex.org/W4389428762","https://openalex.org/W4390871834","https://openalex.org/W4390872039","https://openalex.org/W4390873739","https://openalex.org/W4392940376","https://openalex.org/W4409261802"],"related_works":["https://openalex.org/W2125652721","https://openalex.org/W1540371141","https://openalex.org/W1549363203","https://openalex.org/W2147697413","https://openalex.org/W2154063878","https://openalex.org/W4231274751","https://openalex.org/W2556012038","https://openalex.org/W1489772951","https://openalex.org/W1538046993","https://openalex.org/W2571255492"],"abstract_inverted_index":{"Gradient":[0,147],"Inversion":[1,148],"Attacks":[2],"invert":[3],"the":[4,14,99,117,123,133,157,161,200,207,214],"transmitted":[5],"gradients":[6],"in":[7,48,226],"Federated":[8],"Learning":[9],"(FL)":[10],"systems":[11],"to":[12,65,72,86,97,180,209,213],"reconstruct":[13],"sensitive":[15,235],"data":[16,56,236],"of":[17,28,103,126,202,234,244],"local":[18],"clients":[19],"and":[20,63,130,159,195],"have":[21,95],"raised":[22],"considerable":[23],"privacy":[24,246],"concerns.":[25],"A":[26],"majority":[27],"gradient":[29,182,215],"inversion":[30,183,216],"methods":[31],"rely":[32],"heavily":[33],"on":[34],"explicit":[35],"prior":[36,101,143],"knowledge":[37,102,144],"(e.g.,":[38],"a":[39,111],"well":[40],"pre-trained":[41,76],"generative":[42],"model),":[43],"which":[44,78,154],"is":[45,52],"often":[46,59],"unavailable":[47,64],"realistic":[49],"scenarios.":[50],"This":[51,120],"because":[53],"real-world":[54,227],"client":[55],"distributions":[57],"are":[58,206],"highly":[60],"heterogeneous,":[61],"domain-specific,":[62],"attackers,":[66],"making":[67],"it":[68],"impractical":[69],"for":[70,115],"attackers":[71],"obtain":[73],"perfectly":[74],"matched":[75],"models,":[77],"inevitably":[79],"suffer":[80],"from":[81],"fundamental":[82],"distribution":[83],"shifts":[84],"relative":[85],"target":[87],"private":[88],"data.":[89],"To":[90,199],"alleviate":[91],"this":[92,136,221],"issue,":[93],"researchers":[94],"proposed":[96,172],"leverage":[98],"implicit":[100,127,142,162],"an":[104],"over-parameterized":[105],"network.":[106],"However,":[107],"they":[108],"only":[109],"utilize":[110],"fixed":[112],"neural":[113,165],"architecture":[114],"all":[116],"attack":[118,177],"settings.":[119],"would":[121],"hinder":[122],"adaptive":[124],"use":[125],"architectural":[128],"priors":[129,163],"consequently":[131],"limit":[132],"generalizability.":[134],"In":[135],"paper,":[137],"we":[138,205],"further":[139],"exploit":[140],"such":[141],"by":[145,230],"proposing":[146],"via":[149],"Neural":[150],"Architecture":[151],"Search":[152],"(GI-NAS),":[153],"adaptively":[155],"searches":[156],"network":[158],"captures":[160],"behind":[164],"architectures.":[166],"Extensive":[167],"experiments":[168],"verify":[169],"that":[170,220],"our":[171,203],"GI-NAS":[173],"can":[174],"achieve":[175],"superior":[176],"performance":[178],"compared":[179],"state-of-the-art":[181],"methods,":[184],"even":[185],"under":[186],"more":[187],"practical":[188],"settings":[189],"with":[190],"high-resolution":[191],"images,":[192],"large-sized":[193],"batches,":[194],"advanced":[196],"defense":[197],"strategies.":[198],"best":[201],"knowledge,":[204],"first":[208],"successfully":[210],"introduce":[211],"NAS":[212],"community.":[217],"We":[218],"believe":[219],"work":[222],"exposes":[223],"critical":[224],"vulnerabilities":[225],"federated":[228],"learning":[229],"demonstrating":[231],"high-fidelity":[232],"reconstruction":[233],"without":[237],"requiring":[238],"domain-specific":[239],"priors,":[240],"forcing":[241],"urgent":[242],"reassessment":[243],"FL":[245],"safeguards.":[247]},"counts_by_year":[{"year":2026,"cited_by_count":1}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
