{"id":"e5a62f2a-eb72-467d-bbe4-33e8f7374141","arxiv_id":"2505.05872","paper_version":1,"verdict":"CONDITIONAL","confidence":"HIGH","novelty_score":4.0,"correctness_risk":"medium","formal_verification":"none","parameter_count":0,"one_line_summary":"A structured review that classifies split learning attacks and defenses into a three-axis taxonomy (strategy, constraints, effectiveness) and identifies research gaps.","lead":"This paper organizes published attacks and defenses for split learning, a way to train AI across phones or hospitals without sharing raw data. It groups them by strategy, constraints, and effectiveness, and lists open problems for the field.","discovery_kind":"review","skeptic_critique":{"model":"deepseek-v4-flash","headline":"Table 2's binary attack/defense split is internally contradicted: Gawron et al. [22] is an attack paper listed as a defense, while Li et al. [45] and PCAT [92] include defenses but are listed attack-only, so the taxonomy's central indexing table is unreliable.","rationale":"The paper's central contribution is a reusable systematization of split-learning security; the value of such a taxonomy is exactly the correctness of its classification of primary sources. Thus the reliability of Table 2 is load-bearing, not cosmetic. The evidence is internal: Section 4.1.1.1 and Section 4.3 describe Gawron et al. as an attack that defeats DP, while Table 2 places it in the defense block with a DP strategy. Li et al. and PCAT are similarly misrepresented. These examples indicate a systematic classification problem rather than a one-off typo. The paper does contain useful material: defined attack and defense strategy categories, equations for each family, and a plausible set of open challenges. Those contributions remain after the errors are acknowledged, but the taxonomy cannot be trusted until the table is re-derived from primary sources. A single verification of the 44 rows against abstracts/titles, using an explicit attack-row/defense-row rule, would settle whether the issue is isolated or systemic. If many mismatches appear, the conditional recommendation should be enforced; if only one or two, a targeted correction suffices. The reader's conditional verdict is appropriate; no verdict change is needed.","tokens_in":30562,"tokens_out":5733,"duration_ms":58573,"concrete_test":"Reclassify all 44 Table 2 rows using the papers' own abstracts/titles with a fixed rule: a work belongs in the attack block iff it presents at least one adversary methodology, and in the defense block iff it presents at least one mitigation. Confirm the three contested rows: Gawron et al. [22] ('attacks against differentially private split learning') should be in the attack block, while PCAT [92] ('and target defenses') and Li et al. [45] ('and protection') should have non-NA entries in both columns. If even these three rows fail the rule, the binary table misrepresents at least 3 of 44 entries and the taxonomy's core indexing is unreliable.","verdict_should_be":"UNCHANGED","load_bearing_attack":"The paper's central promise is a taxonomy that systematically classifies SL attacks and defenses along strategies, constraints, and effectiveness. Table 2 is the main artifact that operationalizes this classification for the 44 surveyed papers, so its reliability is load-bearing. Table 2 presents a strict binary: defense rows in the top block and attack rows in the bottom block, each with a single Attack Strategy and a single Defense Strategy, with NA in the other column. This binary is contradicted by the paper's own text. Section 4.1.1.1 and Section 4.3 describe Gawron et al. [22] as a feature-space-hijacking attack that defeats differential privacy, yet Table 2 places [22] in the defense block with Defense Strategy 'Differential Privacy' and Attack Strategy 'NA'. Li et al. [45] is cited in Section 3 as the no-label SL variant and in Section 4.1.2.1 as a gradient-label-inference attack source; its title includes 'and protection', and its role in NLSL suggests it also proposes a defense, but Table 2 lists it as attack-only with Defense Strategy 'NA'. PCAT [92] similarly proposes both a pseudo-client attack and target defenses, yet appears only in the attack block. These are not cosmetic: if the taxonomizer cannot consistently distinguish attack papers from defense papers, the derived categories, distribution figures, and gap analysis built on those categories may misrepresent the literature. A reader cannot treat Table 2 as a trustworthy index for the survey's conclusions.","agreement_with_reader":"agree"},"referee_report":{"model":"deepseek-v4-flash","summary":"This paper presents a systematization of security attacks and defenses in split learning (SL). It introduces a taxonomy with three dimensions—strategies, constraints, and effectiveness—for both attacks (data reconstruction, label inference, property inference, model manipulation) and defenses (data perturbation, secure computation, structural/protocol modifications, and detection). It reviews SL variants, gives formalized attack and defense formulations, summarizes the surveyed works in Table 2, and derives observations and open research directions, including broadening threat models beyond semi-honest adversaries, studying under-explored NLSL and MHSL variants, and designing uncertainty-aware defenses.","tokens_in":30932,"tokens_out":6402,"duration_ms":61367,"significance":"If the taxonomy is made reliable, this paper would be a useful reference: it consolidates a fragmented literature, distinguishes protection from detection, provides mathematical summaries of representative attacks and defenses, and offers concrete, falsifiable open problems such as adaptive differential privacy for SL and entropy-based cut-layer selection. The contribution is not circular: the taxonomy's structure does not depend on the truth of the authors' own attack and defense results, even though those works are cited. The main weaknesses are the reliability of Table 2 and the incomplete operationalization of two of the three claimed dimensions; once those are corrected, the paper could serve as a standard index for SL security research.","major_comments":[{"comment":"Table 2 places Gawron et al. [22] in the defense block with Defense Strategy 'Differential Privacy' and Attack Strategy 'NA'. This contradicts the manuscript's own description: Section 4.1.1.1 and Supplementary B present [22] as a feature-space-hijacking attack, and Section 4.3 lists [22] among works showing that differential privacy is insufficient against advanced SL attacks. Section 5.1.1.1 also cites [22] as a paper on how DP should be applied, repeating the miscategorization. Because Table 2 is the central index from which the distribution figures and gap analysis are built, this is a load-bearing reliability error, not a cosmetic one.","section":"Table 2; Sections 4.1.1.1, 4.3, 5.1.1.1"},{"comment":"The binary structure of Table 2 cannot represent papers that propose both attacks and defenses. Section 2 states that each paper was classified 'considering multiple aspects such as the defense mechanisms it proposes in case of an attack paper and the attacks it addresses in case of a defense paper,' yet Table 2 assigns exactly one of Attack Strategy or Defense Strategy and fills the other with 'NA.' Li et al. [45], whose title is 'Label Leakage and Protection in Two-party Split Learning' and which is the basis of No-Label SL in Section 3, is listed only as 'Label Inference - Gradient-Based Label Inference' with Defense 'NA'; Zhang et al. [92] (PCAT), whose title explicitly includes 'target defenses,' is likewise attack-only. The taxonomy needs a schema that records both contributions, or the 'NA' entries need to mean 'not addressed' rather than 'not applicable.'","section":"Table 2; Section 2; Sections 4.1.2.1 and 4.1.1.3"},{"comment":"The claimed three-dimensional classification is only partially operationalized. The abstract and Section 2 promise categorization along strategies, constraints, and effectiveness, but Table 2 contains only strategy columns; constraints and effectiveness are presented as narrative groupings in Sections 4.2, 4.3, 5.2, and 5.3 without per-paper coded entries. A reader cannot verify or reuse the constraint and effectiveness dimensions from the paper's central artifact, so the systematic claim of the taxonomy is currently stronger than the evidence it ships.","section":"Table 2; Sections 4.2, 4.3, 5.2, 5.3"}],"minor_comments":[{"comment":"'Wat are the common techniques' should read 'What are the common techniques.'","section":"Section 1, RQ5"},{"comment":"'Khann et al. [38]' should read 'Khan et al. [38].'","section":"Section 5.1.1.2"},{"comment":"Several cross-references are misplaced: Section 5.2 refers to 'attacks discussed in Section 5.3.1,' which is a defense subsection, and Section 4.2 refers forward to 'Section 5.3.1' for the threat model discussion.","section":"Sections 4.2 and 5.2"},{"comment":"References [32] and [33] appear to be the same paper (Ismail and Shukla, arXiv:2307.03197), yet the text cites both without distinguishing them.","section":"References [32] and [33]"},{"comment":"The distribution figures report counts without an underlying data table; please make the counts derivable from Table 2 or add a supplementary data table.","section":"Figures 4, 5, 7, and 8"}],"recommendation":"major_revision","confidential_remarks":"The manuscript is within the journal's scope and the central idea is salvageable. The main risk is that the survey's indexing table is not trustworthy as published; I have therefore asked for a structural fix and a full verification of Table 2 against each cited paper. The self-citations are frequent but not disproportionate for a group active in this exact subfield."},"author_rebuttal":null,"desk_editor":{"model":"deepseek-v4-flash","letter":"Useful systematization with a real indexing problem. The three-axis framing—strategy, constraints, effectiveness—is a genuine step beyond the prior SL surveys, and the combined attack/defense treatment plus gap analysis (NLSL, MHSL understudied) gives the community a shared structure to argue against. The math is standard but presented cleanly, and the self-citations (Unsplit, SplitGuard, CURE) are not load-bearing in the taxonomy. Credit where due: this is the most complete SL security survey to date in scope.\n\nThe soft spots are concentrated in Table 2, the paper's central artifact. Several rows contradict the paper's own text. Gawron et al. [22] is described as a feature-space hijacking attack that defeats DP, yet appears in the defense block with Defense Strategy 'Differential Privacy.' Li et al. [45] is presented as the no-label SL variant and as a label-protection method, yet Table 2 lists it as attack-only with NA defense. PCAT [92]—the title literally says 'and target defenses'—is attack-only in the table. These are not cosmetic. If the indexing table cannot consistently separate attacks from defenses, the distribution figures and gap analysis built on those rows inherit the errors. References [32] and [33] are the same paper. The methodology section describes a search and snowballing but reports no counts, exclusion log, or inter-rater process, so the 'systematic' claim is weaker than the word implies.\n\nNone of this kills the paper. The taxonomy itself is coherent, and the errors are fixable with a careful pass over the 44 rows and a stricter definition of what counts as attack vs. defense (many papers do both). I'd send it to peer review with a request for that revision. The readership—split-learning researchers and newcomers—will get value from the architecture overview and the gap list even before the table is fixed.","headline":"Useful SL security taxonomy whose central Table 2 misclassifies several papers; fixable with revision.","tokens_in":31409,"tokens_out":3387,"would_cite":false,"duration_ms":31370,"reading_group":"maybe","serious_thinker":"yes","would_accept_peer_review":true},"rs_alignment":null,"lean_confirmation":null,"pith_extraction":{"msc":[],"pacs":[],"model":"deepseek-v4-flash","headline":"This paper builds a taxonomy of split-learning attacks and defenses along strategy, constraint, and effectiveness, then locates the field's open problems.","keywords":["split learning","taxonomy","attacks","defenses","differential privacy","homomorphic encryption","feature-space hijacking","label inference"],"falsifier":"Inspect Table 2: [22] is an attack paper demonstrating feature-space hijacking against differentially private split learning, yet it is listed in the defense block with strategy 'Differential Privacy', while [45] proposes label-protection defenses yet is listed as attack-only with 'NA' for defense. A reader could re-derive the taxonomy from the cited papers and check whether the three dimensions are applied consistently; systematic misclassification would invalidate the survey's counts and gap analysis.","tokens_in":30421,"feed_emoji":"🧩","tokens_out":3637,"duration_ms":37424,"temperature":0.7,"pith_summary":"Split learning lets resource-constrained clients train deep models by sharing intermediate activations, or 'smashed data,' with a server—but that sharing creates a recurring leak point. The paper argues that the scattered attack and defense literature can be organized into a single framework with three axes: the strategy employed, the operational constraints, and the measured effectiveness. If the framework holds, researchers gain a shared language for positioning new attacks and defenses, and the field's blind spots become visible—for example, the heavy reliance on semi-honest adversary assumptions and the neglect of no-label and multi-hop split learning. The paper also argues that the cut layer, where smashed data and gradients cross the client–server boundary, is the invariant weak point across all split-learning variants.","feed_headline":"Three axes sort split-learning attacks and defenses","feed_subtitle":"The review finds the cut layer is the recurring leak point and maps where the field's open problems lie.","key_machinery":"The organizing device is a three-dimensional taxonomy (strategies, constraints, effectiveness) applied to a table of surveyed papers, with the cut layer—the interface where smashed data $z_c$ and gradients $\\nabla z_c$ pass between client and server—identified as the recurring architectural vulnerability that most attacks exploit and most defenses try to protect.","core_discovery":"The paper claims that the security and privacy landscape of split learning can be systematically taxonomized along three dimensions: strategies (what the attack or defense actually does), constraints (the adversarial capabilities and operational assumptions), and effectiveness (how well it works and at what cost). Applying this framework to the surveyed literature, it claims to identify the dominant attack vectors—data reconstruction, label inference, property inference, and model manipulation—and the corresponding defense families, including differential privacy, homomorphic encryption, function secret sharing, architectural modification, and detection mechanisms. The central substantive finding is that intermediate representations and gradients exchanged at the cut layer leak sensitive information across all split-learning variants, so that defenses aimed only at raw inputs are insufficient. The paper further claims that most existing work assumes semi-honest adversaries, leaving stronger threats such as collusion and malicious manipulation underexplored, and that no-label and multi-hop split learning remain the least characterized variants.","pith_inferences":["The same three-axis structure could be applied beyond split learning to any protocol that exchanges intermediate representations, since the leak mechanism is generic rather than architecture-specific.","The taxonomy's own misclassifications—an attack paper listed as a defense and a defense paper listed as attack-only—suggest the community would benefit from a living, versioned classification that is corrected as papers are re-examined.","If the cut layer is truly the invariant weak point, then quantifying information leakage in $z_c$ with information-theoretic measures could offer a principled way to select cut points, connecting this paper's observations to a quantitative design rule.","A testable extension would be to take papers excluded because they do not explicitly reference split learning and see whether their attacks or defenses transfer to the split-learning setting, which would reveal whether the taxonomy's boundaries are too narrow."],"forward_implications":["New attacks and defenses can be positioned against a common reference grid, making it easier to compare results across papers that use different split-learning variants and datasets.","The cut-layer bottleneck means that privacy defenses must act directly on smashed data and gradients, not only on raw inputs, or reconstruction and label-inference attacks will persist.","Differential privacy alone is not a sufficient defense in split learning; the survey cites multiple attacks that circumvent it, so defenses should combine noise with architectural or protocol changes.","Research attention should shift toward no-label split learning and multi-hop split learning, whose distinct trust and communication structures create unexplored attack surfaces.","Threat models need to move beyond semi-honest adversaries to include malicious and colluding parties, since several surveyed attacks (poisoning, backdoors, hijacking) exceed semi-honest assumptions."],"supporting_citations":[{"why":"Introduces split learning and its vanilla architecture, providing the foundation that the taxonomy organizes.","marker":"[25]"},{"why":"Defines the feature-space hijacking attack at the cut layer, the canonical data reconstruction attack in the survey.","marker":"[59]"},{"why":"Presents model inversion and label inference attacks on split learning, used by the taxonomy as evidence of gradient leakage.","marker":"[10]"},{"why":"Studies label leakage and protection in two-party split learning; the paper itself notes its placement in the table is misleading.","marker":"[45]"},{"why":"Demonstrates backdoor attacks against vertical split learning, supporting the model manipulation category.","marker":"[4]"},{"why":"Proposes a client-side backdoor defense using weight anomaly detection, representing the detection defense family.","marker":"[69]"},{"why":"Shows a pseudo-client attack that steals model functionality and client data, central to the functionality-stealing subcategory.","marker":"[92]"},{"why":"Provides similarity-based and smashed-data label inference attacks, underpinning the label inference category.","marker":"[48]"}],"fun_headline_variants":["Split-learning risks cluster at the cut layer","Three-axis map exposes split-learning leak points","Cut-layer gradients leak in all split-learning variants","Mapping split-learning threats and defenses along three axes","Split-learning taxonomy: cut layer is the core leak"],"cache_read_input_tokens":3200,"weakest_assumption_plain":"The taxonomy holds together only if every surveyed paper is sorted correctly into attack or defense; internal evidence shows at least two placements that appear wrong, and if these are not isolated, the framework misrepresents the literature.","fun_headline_variants_meta":{"raw":{"variants":["Split-learning risks cluster at the cut layer","Three-axis map exposes split-learning leak points","Cut-layer gradients leak in all split-learning variants","Mapping split-learning threats and defenses along three axes","Split-learning taxonomy: cut layer is the core leak"]},"model":"deepseek-v4-flash","effort":"low","cost_usd":0.000457,"raw_usage":{"total_tokens":2240,"prompt_tokens":836,"completion_tokens":1404,"prompt_tokens_details":{"cached_tokens":384},"prompt_cache_hit_tokens":384,"prompt_cache_miss_tokens":452,"completion_tokens_details":{"reasoning_tokens":1334}},"tokens_in":452,"tokens_out":1404,"duration_ms":11713,"temperature":1.0,"reasoning_tokens":1334,"cache_read_input_tokens":384,"cache_creation_input_tokens":0},"cache_creation_input_tokens":0},"created_at":"2026-08-15T22:53:26.955223+00:00","model_set":{"reader":"deepseek-v4-flash"},"falsifier":"Inspect Table 2: [22] is an attack paper demonstrating feature-space hijacking against differentially private split learning, yet it is listed in the defense block with strategy 'Differential Privacy', while [45] proposes label-protection defenses yet is listed as attack-only with 'NA' for defense. A reader could re-derive the taxonomy from the cited papers and check whether the three dimensions are applied consistently; systematic misclassification would invalidate the survey's counts and gap analysis.","supporting_citations":[{"cited_title":"Gupta and R","cited_arxiv_id":null,"evidence_quote":"Introduces split learning and its vanilla architecture, providing the foundation that the taxonomy organizes."},{"cited_title":"Pasquini, G","cited_arxiv_id":null,"evidence_quote":"Defines the feature-space hijacking attack at the cut layer, the canonical data reconstruction attack in the survey."},{"cited_title":"Rieger, A","cited_arxiv_id":null,"evidence_quote":"Proposes a client-side backdoor defense using weight anomaly detection, representing the detection defense family."},{"cited_title":"Zhang, X","cited_arxiv_id":null,"evidence_quote":"Shows a pseudo-client attack that steals model functionality and client data, central to the functionality-stealing subcategory."},{"cited_title":null,"cited_arxiv_id":null,"evidence_quote":"Provides similarity-based and smashed-data label inference attacks, underpinning the label inference category."}],"review_version":1}