OSCR

Security Analysis of a Federated Learning Framework for Medical Image-to-Image Translation.

Overview

Authors: Ciro Benito Raggio1, Lina Bucher2, Oliver Blanck3, Francesco Cicone4, Paolo Zaffino4, Maria Francesca Spadea1
  1. Institute of Biomedical Engineering, Karlsruhe Institute of Technology,Fritz-Haber-Weg 1, 76131 Karlsruhe, Baden-Württemberg Germany
  2. Department of Physics and Astronomy, Heidelberg University,Im Neuenheimer Feld 226, 69120 Heidelberg, Baden-Württemberg Germany
  3. Department of Radiation Oncology, University Hospital Schleswig-Holstein,Feldstrasse 21, 24105 Kiel, Schleswig-Holstein Germany
  4. Department of Experimental and Clinical Medicine, Magna Graecia University,Viale Europa, 88100 Catanzaro, Calabria Italy
Journal: Journal of medical systems, volume 50, issue 1, article 108
Dates: received 24 April 2026; accepted 27 June 2026; published online 4 July 2026; in print 2026
Type: Research article · Language: English
License: CC BY
Identifiers: DOI 10.1007/s10916-026-02436-8 · PMID 42400864 · PMCID PMC13332882 · OpenAlex W7167327242
Open access: hybrid, a free copy (OpenAlex)
Status: data only
Categories: structural MRI / diffusion (modality), other (modality), human (organism)
Methods: Connectivity, Statistics, Machine learning
Keywords: Federated learning, Image-to-image translation, Synthetic computed tomography, Security attacks
MeSH: Computer Security*, Federated Learning*, Image Processing, Computer-Assisted*, Magnetic Resonance Imaging*, Confidentiality, Humans, Tomography, X-Ray Computed (* major topic)
Topic: Adversarial Robustness in Machine Learning (Artificial Intelligence, Computer Science), according to OpenAlex
Funding: Karlsruher Institut für Technologie (KIT) (4220)
Citations: not cited yet (Europe PMC); 46 references in the paper

Abstract

Federated Learning (FL) emerged as a privacy-preserving paradigm for collaborative training of deep learning models across institutions without sharing patient data. This approach has been applied to complex tasks such as medical image-to-image (I2I) translation, including MRI-to-synthetic CT (sCT) generation. However, existing federated I2I frameworks often assume privacy preservation as an inherent property of FL rather than a requirement to be explicitly validated, leaving their robustness to representative adversarial threat scenarios largely unexplored. In this study, we evaluated the vulnerability of a federated MRI-to-sCT translation framework (FedSynthCT-Brain) to three representative attack classes: Deep Leakage from Gradients (DLG), Federated Membership Inference Attack (FedMIA), and data poisoning. The efficacy of corresponding defense mechanisms, such as Secure Aggregation (SecAgg) and Byzantine-robust median aggregation (FedMedian), were assessed. DLG enabled only the recovery of coarse anatomical structures, with no clinically identifiable details (SSIM 0.16, PSNR 11 dB) across clients, suggesting limited vulnerability under the evaluated DLG setting. In contrast, FedMIA achieved high membership discrimination, with AUC scores between 0.92 and 0.99, revealing a critical privacy vulnerability. The introduction of SecAgg reduced AUC values to near-random levels (0.23–0.56) across all centers without impacting synthesis quality. Under high-noise poisoning, the standard federated averaging (FedAvg) aggregation rendered the federation inoperative, while FedMedian restored performance close to the no-poisoning baseline in most scenarios, with significant residual degradation in specific center configurations. At low noise levels, the advantage of FedMedian was less consistent, as low-level noise injection may be indistinguishable from natural heterogeneity across centers, potentially enabling stealthy degradation. These findings demonstrate that federated I2I translation frameworks are not inherently secure and require explicit, multi-layered evaluation. As FL is increasingly adopted in clinical workflows, our results underscore the necessity of integrating cryptographic, algorithmic, and infrastructural safeguards for secure deployment.

Reproduced under the paper's license (CC BY), from the paper cited above.

Code

The paper links to its data, not to its authors' code: see the Data section.

Tracing map

A tracing map links a paper to the code its authors published: this paper has none, so it has no map.

Data

Datasets cited

Data Availability

Restrictions apply to the availability of the data supporting the findings of this study from Centers A, B and C which were used under licence for this study and are therefore not publicly available. The data from Center D and Center E were extracted from the public SynthRAD2023 Grand Challenge dataset and are available at 10.5281/zenodo.7260705.

Reproduced under the paper's license (CC BY), from the paper cited above.

Versions

The history of this record: each version stored by the harvester or made by a correction of its authors or of the maintainers of its code, and what changed in its facts. The texts of the paper (its abstract, its availability statements) are not part of it; versions that changed only those are not listed.

Version 2, 28 September 2026

  • Publisher: — → Springer Science+Business Media

Version 1, 27 September 2026: the first record

Recorded: type, language, journal, volume, issue, pages, dates, 6 authors, 4 keywords, 7 MeSH terms, 1 funder, 31 references.

Cite

This paper

Raggio, C. B., Bucher, L., Blanck, O., Cicone, F., Zaffino, P., & Spadea, M. F. (2026). Security Analysis of a Federated Learning Framework for Medical Image-to-Image Translation. Journal of medical systems, 50(1), 108. https://doi.org/10.1007/s10916-026-02436-8

BibTeX

@article{raggio2026security,
author = {Raggio, Ciro Benito and Bucher, Lina and Blanck, Oliver and Cicone, Francesco and Zaffino, Paolo and Spadea, Maria Francesca},
title = {{Security Analysis of a Federated Learning Framework for Medical Image-to-Image Translation}},
journal = {Journal of medical systems},
year = {2026},
month = jul,
volume = {50},
number = {1},
pages = {108},
publisher = {Springer Science+Business Media},
issn = {0148-5598},
doi = {10.1007/s10916-026-02436-8},
url = {https://doi.org/10.1007/s10916-026-02436-8},
pmid = {42400864},
pmcid = {PMC13332882}
}

RIS

TY - JOUR
AU - Raggio, Ciro Benito
AU - Bucher, Lina
AU - Blanck, Oliver
AU - Cicone, Francesco
AU - Zaffino, Paolo
AU - Spadea, Maria Francesca
TI - Security Analysis of a Federated Learning Framework for Medical Image-to-Image Translation
T2 - Journal of medical systems
J2 - J Med Syst
PY - 2026
DA - 2026/07/04
VL - 50
IS - 1
SP - 108
SN - 0148-5598
PB - Springer Science+Business Media
DO - 10.1007/s10916-026-02436-8
UR - https://doi.org/10.1007/s10916-026-02436-8
LA - en
ER -

CSL-JSON

{
"id": "10.1007/s10916-026-02436-8",
"type": "article-journal",
"title": "Security Analysis of a Federated Learning Framework for Medical Image-to-Image Translation",
"container-title": "Journal of medical systems",
"author": [
{
"family": "Raggio",
"given": "Ciro Benito"
},
{
"family": "Bucher",
"given": "Lina"
},
{
"family": "Blanck",
"given": "Oliver"
},
{
"family": "Cicone",
"given": "Francesco"
},
{
"family": "Zaffino",
"given": "Paolo"
},
{
"family": "Spadea",
"given": "Maria Francesca"
}
],
"container-title-short": "J Med Syst",
"volume": "50",
"issue": "1",
"page": "108",
"DOI": "10.1007/s10916-026-02436-8",
"PMID": "42400864",
"PMCID": "PMC13332882",
"ISSN": "0148-5598",
"publisher": "Springer Science+Business Media",
"URL": "https://doi.org/10.1007/s10916-026-02436-8",
"language": "en",
"issued": {
"date-parts": [
[
2026,
7,
4
]
]
}
}

Similar papers

The papers with a page that share the most with this one: the tools found in their code, their categories, datasets, cited references and authors, the rarest counting most.

[1] doi:10.1002/alz.71822 [code]
SynthPET: A 3D generative AI approach for FDG-PET image synthesis from T1-weighted MRI and ASL CBF in Alzheimer's disease.
Journal: Alzheimer's & dementia : the journal of the Alzheimer's Association
In common: structural MRI / diffusion, 2 references
[2] doi:10.3389/frai.2026.1852196
FuzzyFed-CNN: secure and explainable multimodal federated learning for early Alzheimer's diagnosis.
Journal: Frontiers in artificial intelligence
In common: structural MRI / diffusion, 1 reference
[3] doi:10.1038/s41598-026-55847-5
Federated MobileNetV2 with ensemble meta-learning for privacy-preserving brain tumor classification.
Journal: Scientific reports
In common: structural MRI / diffusion, 1 reference
[4] doi:10.1002/hbm.70508 [code]
Cyclic 2.5D Perceptual Loss for Cross-Modal 3D Medical Image Synthesis: T1w MRI to Tau PET.
Journal: Human brain mapping
In common: structural MRI / diffusion, 1 reference
[5] doi:10.1002/hbm.70629
Characterising the Diffusion Functional Signature of Negative BOLD With Interleaved TMS-fMRI in the Human Brain.
Journal: Human brain mapping
In common: other, structural MRI / diffusion, 1 reference
[6] doi:10.1038/s44400-026-00115-6
Brain age gradients as intermediate phenotypes linking plasma p-tau217 to cognition in community-dwelling older adults.
Journal: NPJ dementia
In common: other, structural MRI / diffusion, 1 reference
[7] doi:10.3389/fnins.2026.1858490 [code]
Comparison of subject-to-template registration schemes using CT and MR radiotherapy images with brain lesions.
Journal: Frontiers in neuroscience
In common: other, 1 reference
[8] doi:10.1002/advs.202523009 [code]
Personalized Network-Guided Neuromodulation Enhances Human Working Memory.
Journal: Advanced science (Weinheim, Baden-Wurttemberg, Germany)
In common: other, 1 reference
[9] doi:10.1038/s41467-026-72917-4 [code]
OFC-induced network modularity improves positive symptoms and attentional alertness in schizophrenia: a combined rTMS-fMRI study.
Journal: Nature communications
In common: other, 1 reference
[10] doi:10.1016/j.ynirp.2026.100405
White matter microstructure and motor function in amnestic mild cognitive impairment and Alzheimer's dementia.
Journal: Neuroimage. Reports
In common: structural MRI / diffusion, 1 reference

Contribute

The authors of this paper can claim it, correct its record and validate its tracing map, and the maintainers of its code (its owner, or a public member of its organization) correct what it says of their repository; anyone signed in can ask for its removal. Every request goes to OSCR's own machine, which answers it; your account page follows them.

Sign in with ORCID to claim this paper as one of its authors, correct its record or validate its tracing map: when the paper's metadata lists your ORCID iD, you are recognized at once. Maintainers of its code: sign in with GitHub, then claim the repository on your account page.

Request its removal

To ask OSCR to remove this record, the copies of its authors' scripts or its tracing map, use the removal request page: signed in, you say who you are, what to remove and why, then review and confirm the request. Published rules decide every request (how).

Discussion, reproductions, activity

Discussion: questions and error reports about this paper and its code, from signed-in readers and its authors. It opens with sign-in.

Reproductions: reports from readers who ran the authors' code: what they reproduced, with which environment, commit and data. It opens with sign-in.

Activity: what happens around this paper: new versions of its record, its map's validation, discussions and reproductions. It opens with sign-in.