Research map / Federated learning and privacy
Privacy attacks and secure learning: research map
364 accepted papers on Privacy attacks and secure learning in Federated learning and privacy, from ICML, NeurIPS, ICLR, CVPR and AAAI (2016–2026), grouped into 2 clusters and 6 approaches. The busiest year so far is 2026.
Within Federated learning and privacy, its share shrank from 17.6% in 2023–24 to 15.6% in 2025–26 (131 → 142 papers at ICML, NeurIPS, CVPR and AAAI, the venues with data for all four years).
Explore Privacy attacks and secure learning in the interactive map
Working on something in this topic? Describe your idea in scime atlas to see which approach it falls under, the closest papers by meaning and how crowded the spot has become.
Approaches and key papers
preserving · vfl · encryption · 194 papers
Approaches in this cluster:
- Encryption-based private learning (105 papers)
Use homomorphic encryption and private synthetic data for privacy-preserving learning. - Private federated aggregation (50 papers)
Secure aggregation and encrypted gradients for efficient, fair federated learning. - Visual privacy and face de-identification (39 papers)
Obfuscate faces and private content in images while keeping utility.
Most cited and most cited since 2024:
- CryptoNets: Applying Neural Networks to Encrypted Data with High Throughput and Accuracy (ICML 2016 · 1,289 citations)
- Slalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware (ICLR 2019 · 245 citations)
- Privacy-Preserving Face Recognition Using Trainable Feature Subtraction (CVPR 2024 · 33 citations)
- No Prejudice! Fair Federated Graph Neural Networks for Personalized Recommendation (AAAI 2024 · 32 citations)
attack · defense · backdoor · 170 papers
Approaches in this cluster:
- Defending federated learning against poisoning (76 papers)
Detect and mitigate malicious clients and backdoors in federated learning with provable defenses. - Gradient inversion attacks (47 papers)
Reconstruct training data from shared gradients and defend against such leakage. - Membership inference and auditing (47 papers)
Attack and audit models for privacy leakage with membership inference and statistical tests.
Most cited and most cited since 2024:
- Inverting Gradients - How easy is it to break privacy in federated learning? (NeurIPS 2020 · 206 citations)
- Soteria: Provable Defense Against Privacy Leakage in Federated Learning From Representation Perspective (CVPR 2021 · 168 citations)
- Revamping Federated Learning Security from a Defender's Perspective: A Unified Defense with Homomorphic Encrypted Data Space (CVPR 2024 · 43 citations)
- Model Poisoning Attacks to Federated Learning via Multi-Round Consistency (CVPR 2025 · 28 citations)
