{"id":"https://openalex.org/W7130568227","doi":"https://doi.org/10.1109/tifs.2026.3666295","title":"Model Inversion Attack Against Federated Unlearning","display_name":"Model Inversion Attack Against Federated Unlearning","publication_year":2026,"publication_date":"2026-01-01","ids":{"openalex":"https://openalex.org/W7130568227","doi":"https://doi.org/10.1109/tifs.2026.3666295"},"language":null,"primary_location":{"id":"doi:10.1109/tifs.2026.3666295","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2026.3666295","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5126380880","display_name":"Lei Zhou","orcid":null},"institutions":[{"id":"https://openalex.org/I9842412","display_name":"Nanjing University of Aeronautics and Astronautics","ror":"https://ror.org/01scyh794","country_code":"CN","type":"education","lineage":["https://openalex.org/I9842412"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Lei Zhou","raw_affiliation_strings":["College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing, Jiangsu, China"],"raw_orcid":"https://orcid.org/0009-0001-9385-4763","affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing, Jiangsu, China","institution_ids":["https://openalex.org/I9842412"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100750950","display_name":"Youwen Zhu","orcid":"https://orcid.org/0000-0003-4365-9713"},"institutions":[{"id":"https://openalex.org/I9842412","display_name":"Nanjing University of Aeronautics and Astronautics","ror":"https://ror.org/01scyh794","country_code":"CN","type":"education","lineage":["https://openalex.org/I9842412"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Youwen Zhu","raw_affiliation_strings":["College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing, Jiangsu, China"],"raw_orcid":"https://orcid.org/0000-0003-4365-9713","affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing, Jiangsu, China","institution_ids":["https://openalex.org/I9842412"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5126389479","display_name":"Rongke Liu","orcid":null},"institutions":[{"id":"https://openalex.org/I9842412","display_name":"Nanjing University of Aeronautics and Astronautics","ror":"https://ror.org/01scyh794","country_code":"CN","type":"education","lineage":["https://openalex.org/I9842412"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Rongke Liu","raw_affiliation_strings":["College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing, Jiangsu, China"],"raw_orcid":"https://orcid.org/0000-0003-4204-8793","affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing, Jiangsu, China","institution_ids":["https://openalex.org/I9842412"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.22288434,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"21","issue":null,"first_page":"2342","last_page":"2357"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.751800000667572,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.751800000667572,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.14470000565052032,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.017799999564886093,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/information-privacy","display_name":"Information privacy","score":0.5523999929428101},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.5303999781608582},{"id":"https://openalex.org/keywords/information-sensitivity","display_name":"Information sensitivity","score":0.4697999954223633},{"id":"https://openalex.org/keywords/bridge","display_name":"Bridge (graph theory)","score":0.4586000144481659},{"id":"https://openalex.org/keywords/private-information-retrieval","display_name":"Private information retrieval","score":0.44200000166893005},{"id":"https://openalex.org/keywords/inversion","display_name":"Inversion (geology)","score":0.4269999861717224},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.4196000099182129},{"id":"https://openalex.org/keywords/focus","display_name":"Focus (optics)","score":0.4099999964237213}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8517000079154968},{"id":"https://openalex.org/C123201435","wikidata":"https://www.wikidata.org/wiki/Q456632","display_name":"Information privacy","level":2,"score":0.5523999929428101},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.5303999781608582},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.49070000648498535},{"id":"https://openalex.org/C137822555","wikidata":"https://www.wikidata.org/wiki/Q2587068","display_name":"Information sensitivity","level":2,"score":0.4697999954223633},{"id":"https://openalex.org/C100776233","wikidata":"https://www.wikidata.org/wiki/Q2532492","display_name":"Bridge (graph theory)","level":2,"score":0.4586000144481659},{"id":"https://openalex.org/C99221444","wikidata":"https://www.wikidata.org/wiki/Q1532069","display_name":"Private information retrieval","level":2,"score":0.44200000166893005},{"id":"https://openalex.org/C1893757","wikidata":"https://www.wikidata.org/wiki/Q3653001","display_name":"Inversion (geology)","level":3,"score":0.4269999861717224},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.4196000099182129},{"id":"https://openalex.org/C192209626","wikidata":"https://www.wikidata.org/wiki/Q190909","display_name":"Focus (optics)","level":2,"score":0.4099999964237213},{"id":"https://openalex.org/C23130292","wikidata":"https://www.wikidata.org/wiki/Q5275358","display_name":"Differential privacy","level":2,"score":0.40959998965263367},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.3763999938964844},{"id":"https://openalex.org/C2777212361","wikidata":"https://www.wikidata.org/wiki/Q5127848","display_name":"Class (philosophy)","level":2,"score":0.3610000014305115},{"id":"https://openalex.org/C2779201187","wikidata":"https://www.wikidata.org/wiki/Q2775060","display_name":"Information leakage","level":2,"score":0.3495999872684479},{"id":"https://openalex.org/C3017597292","wikidata":"https://www.wikidata.org/wiki/Q25052250","display_name":"Privacy protection","level":2,"score":0.33550000190734863},{"id":"https://openalex.org/C2992525071","wikidata":"https://www.wikidata.org/wiki/Q50818671","display_name":"Federated learning","level":2,"score":0.30730000138282776},{"id":"https://openalex.org/C67186912","wikidata":"https://www.wikidata.org/wiki/Q367664","display_name":"Data modeling","level":2,"score":0.3003999888896942},{"id":"https://openalex.org/C2776945810","wikidata":"https://www.wikidata.org/wiki/Q17006654","display_name":"Data anonymization","level":3,"score":0.2903999984264374},{"id":"https://openalex.org/C75684735","wikidata":"https://www.wikidata.org/wiki/Q858810","display_name":"Big data","level":2,"score":0.2858999967575073},{"id":"https://openalex.org/C193934123","wikidata":"https://www.wikidata.org/wiki/Q7246028","display_name":"Privacy by Design","level":3,"score":0.28439998626708984},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.27639999985694885},{"id":"https://openalex.org/C69360830","wikidata":"https://www.wikidata.org/wiki/Q1172237","display_name":"Data Protection Act 1998","level":2,"score":0.2685999870300293},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.2599000036716461}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tifs.2026.3666295","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2026.3666295","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.689583957195282,"id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G1249581021","display_name":null,"funder_award_id":"BE2022068-1","funder_id":"https://openalex.org/F4320327777","funder_display_name":"Jiangsu Provincial Key Research and Development Program"},{"id":"https://openalex.org/G1775673648","display_name":null,"funder_award_id":"BE2022068","funder_id":"https://openalex.org/F4320327777","funder_display_name":"Jiangsu Provincial Key Research and Development Program"},{"id":"https://openalex.org/G3509694358","display_name":null,"funder_award_id":"No. U25A20427","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G3886854543","display_name":null,"funder_award_id":"U2433205","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5113688066","display_name":null,"funder_award_id":"No. U2433205","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7595169600","display_name":null,"funder_award_id":"No. BE2022068-1","funder_id":"https://openalex.org/F4320327777","funder_display_name":"Jiangsu Provincial Key Research and Development Program"},{"id":"https://openalex.org/G8706063612","display_name":null,"funder_award_id":"No. BE2022068","funder_id":"https://openalex.org/F4320327777","funder_display_name":"Jiangsu Provincial Key Research and Development Program"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320327777","display_name":"Jiangsu Provincial Key Research and Development Program","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"In":[0],"response":[1],"to":[2,8,17,48,71,95,138,161,174],"emerging":[3],"regulations":[4],"on":[5,40,85,203],"the":[6,24,49,81,86,114,127,132,140,147,157,163,171],"\u201cright":[7],"be":[9],"forgotten\u201d,":[10],"federated":[11,30,66],"unlearning":[12,42,67,128,137],"(FU)":[13],"has":[14],"been":[15],"proposed":[16],"ensure":[18],"privacy":[19,51,74,87,182,196],"compliance":[20],"by":[21,54],"efficiently":[22],"eliminating":[23],"influence":[25,164],"of":[26,143,149,159,165,218],"specific":[27,166],"data":[28],"from":[29],"learning":[31],"(FL)":[32],"models.":[33],"However,":[34],"existing":[35],"FU":[36,55,98,160,172,209],"studies":[37],"primarily":[38],"focus":[39],"improving":[41],"efficiency,":[43],"with":[44],"little":[45],"attention":[46],"given":[47],"potential":[50,73,188],"risks":[52],"introduced":[53],"itself.":[56],"To":[57],"bridge":[58],"this":[59],"research":[60],"gap,":[61],"we":[62,185],"propose":[63],"a":[64,193],"novel":[65],"inversion":[68],"attack":[69],"(FUIA)":[70],"expose":[72],"leakage":[75],"in":[76,90,170,181],"FU.":[77,91],"This":[78],"work":[79],"represents":[80],"first":[82],"systematic":[83],"study":[84],"vulnerabilities":[88,169],"inherent":[89],"FUIA":[92,154,213],"can":[93],"apply":[94],"three":[96],"major":[97],"scenarios:":[99],"sample":[100],"unlearning,":[101,103,106],"client":[102],"and":[104,110,130,135,198,207],"class":[105],"demonstrating":[107],"broad":[108],"applicability":[109],"threat":[111],"potential.":[112],"Specifically,":[113],"server,":[115],"acting":[116],"as":[117],"an":[118],"honest-but-curious":[119],"attacker,":[120],"continuously":[121],"records":[122],"model":[123,199],"parameter":[124],"changes":[125],"throughout":[126],"process":[129,173],"analyzes":[131],"differences":[133],"before":[134],"after":[136],"infer":[139],"gradient":[141],"information":[142,217],"forgotten":[144,176,219],"data,":[145,167,177],"enabling":[146],"reconstruction":[148],"its":[150],"features":[151],"or":[152],"labels.":[153],"directly":[155],"undermines":[156],"goal":[158],"eliminate":[162],"exploiting":[168],"reconstruct":[175],"thereby":[178],"revealing":[179],"flaws":[180],"protection.":[183],"Moreover,":[184],"explore":[186],"two":[187],"defense":[189],"strategies":[190],"that":[191,212],"introduce":[192],"trade-off":[194],"between":[195],"protection":[197],"performance.":[200],"Extensive":[201],"experiments":[202],"multiple":[204],"benchmark":[205],"datasets":[206],"various":[208],"methods":[210],"demonstrate":[211],"effectively":[214],"reveals":[215],"private":[216],"data.":[220]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-02-20T00:00:00"}
