\section{Detailed Results of Membership Inference Attacks on Federated Learning}\label{sec:appendix_federated_attack_result}

\begin{table}[htbp]
    \centering
    \setlength\tabcolsep{4 pt}
    \begin{tabular}{lcccccc}
        \toprule
\multirow{2}{*}{Features}   & \multicolumn{3}{c}{\texttt{3D-CNN}} & \multicolumn{3}{c}{\texttt{2D-slice-mean}} \\
                            \cmidrule(lr){2-4} \cmidrule(lr){5-7}
                            &D1 & D2 & D3 &D1 & D2 & D3\\
        \cmidrule(r){1-1}   \cmidrule(lr){2-2} \cmidrule(lr){3-3} \cmidrule(lr){4-4}  \cmidrule(lr){5-5} \cmidrule(lr){6-6} \cmidrule(lr){7-7}

    Set 1 & \tiny{$60.08 \pm 0.06$ (56)} & \tiny{$57.75 \pm 0.15$ (30)} & \tiny{$59.01 \pm 0.34$ (29)}
          & \tiny{$58.15 \pm 0.07$ (56)} & \tiny{$55.27 \pm 0.03$ (37)} & \tiny{$58.55 \pm 0.38$ (24)}\\
    Set 2 & \tiny{$60.09 \pm 0.06$ (56)} & \tiny{$59.97 \pm 0.29$ (30)} & \tiny{$63.59 \pm 0.35$ (26)}
          & \tiny{$58.04 \pm 0.23$ (56)} & \tiny{$60.41 \pm 0.22$ (29)} & \tiny{$63.73 \pm 0.27$ (25)}\\
    Set 3 & \tiny{$60.06 \pm 0.04$ (56)} & \tiny{$61.00 \pm 0.47$ (28)} & \tiny{$64.12 \pm 0.52$ (25)}
          & \tiny{$58.11 \pm 0.22$ (56)} & \tiny{$60.28 \pm 0.73$ (29)} & \tiny{$63.81 \pm 0.55$ (24)}\\
        \bottomrule
    \end{tabular}
    \caption{Average membership inference attack accuracies on models trained using federated learning across all environments using different feature sets. Standard deviations are reported over 5 runs. Number in parentheses indicate the median total number of successful attacks over 5 runs.
    \\
    \\
    \textbf{Table Legend:}\\
     \hspace{3em} \null\qquad D1: Uniform \& IID data distribution \\
     \  \null\qquad D2: Uniform \& non-IID data distribution \\
     \  \null\qquad D3: Skewed  \& non-IID data distribution \\
     \  \null\qquad Set 1: Gradient magnitude\\
     \  \null\qquad Set 2: Gradient magnitude + prediction + label\\
     \  \null\qquad Set 3: Gradient magnitude + prediction + label + gradient (\texttt{conv 6} + \texttt{output})
    }
    \label{tab:attack_result_feature}
\end{table}

\newcommand{\MidNumber}{50}
\newcommand{\ApplyGradient}[2]{%
    \ifdim #1 pt > 50 pt
        \pgfmathsetmacro{\PercentColor}{2*(#1 - \MidNumber)} %
        \colorbox{red!\PercentColor!yellow}{\npdecimalsign{.}\nprounddigits{2}$\numprint{#1}$$\pm$\npdecimalsign{.}\nprounddigits{2}$\numprint{#2}$}
    \else
    {\npdecimalsign{.}\nprounddigits{2}$\numprint{#1}$$\pm$ \npdecimalsign{.}\nprounddigits{2}$\numprint{#2}$}
    \fi
}


\begin{table}[htbp]
\footnotesize
    \rotatebox{90}{
        \setlength\tabcolsep{0 pt}
    \begin{tabular}{cc}
    \toprule
        Environment & \texttt{3D-CNN}\\
        \midrule
        \shortstack{Uniform\\ \&\\ IID} &
        \setlength\tabcolsep{0pt}
        \begin{tabular}{|l|c|c|c|c|c|c|c|c|}
            \hline
              & L1 & L2 & L3 & L4 & L5 & L6 & L7 & L8\\
              \hline
              L1&                                              & \ApplyGradient{60.62}{0.660113626582578}  &\ApplyGradient{60.71}{0.606630035524123}   &\ApplyGradient{59.85}{0.691917625154904} &	\ApplyGradient{59.89}{0.724051103168829}    &\ApplyGradient{59.17}{0.575108685380429}	&\ApplyGradient{60.64}{0.45880278987818}    &\ApplyGradient{60.15}{0.508674748734393}\\
              \hline
              L2& \ApplyGradient{59.68}{0.195576072156076}    &                                           &\ApplyGradient{60.57}{0.690651865993287}   &\ApplyGradient{60.02}{0.665770230635165} &	\ApplyGradient{59.86}{0.582451714736945}    &\ApplyGradient{59.1}{0.322102468168136}	&\ApplyGradient{60.63}{0.531036721894071}   &\ApplyGradient{60.15}{0.452769256906869}\\
              \hline
              L3& \ApplyGradient{59.78}{0.148323969741917}    & \ApplyGradient{60.59}{0.405277682583191}  &                                           &\ApplyGradient{60.18}{0.461789995560754} &	\ApplyGradient{60.19}{0.481404196076435}    &\ApplyGradient{59.55}{0.127475487839821}	&\ApplyGradient{60.63}{0.28195744359743}    &\ApplyGradient{60.48}{0.277488738510233}\\
              \hline
              L4& \ApplyGradient{59.92}{0.256417628099161}    & \ApplyGradient{60.29}{0.395916657896587}  &\ApplyGradient{60.89}{0.25347583711273}    &                                         & \ApplyGradient{60.14}{0.315039680040467}    &\ApplyGradient{59.45}{0.287228132326895}	&\ApplyGradient{60.73}{0.236114379062352}   &\ApplyGradient{60.58}{0.201866292381862}\\
              \hline
              L5& \ApplyGradient{59.86}{0.326726185054088}    & \ApplyGradient{60.22}{0.246475150877326}  &\ApplyGradient{60.85}{0.127475487839818}   &\ApplyGradient{59.94}{0.359513560244957} &	                                            &\ApplyGradient{59.41}{0.263153947338816}	&\ApplyGradient{60.48}{0.329013677527244}   &\ApplyGradient{60.55}{0.340954542424645}\\
              \hline
              L6& \ApplyGradient{59.98}{0.297069015550258}    & \ApplyGradient{59.98}{0.354612464529945}  &\ApplyGradient{60.56}{0.405277682583194}   &\ApplyGradient{59.56}{0.470903387118841} &	\ApplyGradient{60.07}{0.566347949585764}    &	                                        &\ApplyGradient{60.7}{0.467707173346746}    &\ApplyGradient{60.32}{0.479061582680137}\\
              \hline
              L7& \ApplyGradient{60.08}{0.448051336344397}    & \ApplyGradient{60.05}{0.375832409459326}  &\ApplyGradient{60.81}{0.366401419211222}   &\ApplyGradient{59.77}{0.178885438199983} &	\ApplyGradient{60.}{0.302076149339867}      &\ApplyGradient{59.28}{0.311448230047949}	&                                           &\ApplyGradient{60.29}{0.348926926447355}\\
              \hline
              L8& \ApplyGradient{59.0875}{0.295451631687264}  & \ApplyGradient{59.125}{0.239791576165637} &\ApplyGradient{60.15}{0.32403703492039}    &\ApplyGradient{59.275}{0.388372673257703}&	\ApplyGradient{59.3375}{0.118145390656315}  &\ApplyGradient{58.975}{0.239791576165633}	&\ApplyGradient{59.6625}{0.252899848424894} &                                        \\
              \hline
        \end{tabular}
        \\
        \\
        \shortstack{Uniform \\ \& \\ non-IID} &
        \setlength\tabcolsep{0pt}
        \begin{tabular}{|l|c|c|c|c|c|c|c|c|}
            \hline
            & L1 & L2 & L3 & L4 & L5 & L6 & L7 & L8\\
            \hline
            L1&                                         &\ApplyGradient{56.2}{1.44178708552962}     &\ApplyGradient{38.34}{0.510392006206994}   &\ApplyGradient{33.06}{0.733484832835689}   &   \ApplyGradient{72.72}{0.359861084308931}    &\ApplyGradient{55.92}{1.21993852304122}    &   \ApplyGradient{38.25}{0.325960120260132}    &\ApplyGradient{32.99}{0.712741187248219}\\
            \hline
            L2& \ApplyGradient{56.36}{2.19641753771909} &                                           &\ApplyGradient{52.8}{1.08570253753042}     &\ApplyGradient{39.7}{1.3242922638149}      &   \ApplyGradient{56.61}{2.40660549322069}     &\ApplyGradient{63.28}{0.120415945787921}   &  \ApplyGradient{51.03}{1.10657128102983}      &\ApplyGradient{40.2}{1.41774468787578}\\
            \hline
            L3& \ApplyGradient{32.76}{0.954856010087386}&\ApplyGradient{49.15}{0.825378700960959}   &                                           &\ApplyGradient{66.09}{1.50016665740844}    &   \ApplyGradient{32.42}{0.768602628150594}    &\ApplyGradient{49.63}{0.773466224214089}   &  \ApplyGradient{63.43}{0.485540935452412}     &\ApplyGradient{66.61}{1.18974787245029}\\
            \hline
            L4& \ApplyGradient{32.05}{0.285043856274785}&\ApplyGradient{41.5}{0.1}                  &\ApplyGradient{59.98}{0.135092560861064}   &                                           &   \ApplyGradient{32.45}{0.25495097567964}     &\ApplyGradient{43.12}{0.185741756210066}   &  \ApplyGradient{61.45}{0.106066017177978}     &\ApplyGradient{69.86}{0.210356839679627}\\
            \hline
            L5& \ApplyGradient{72.28}{0.189076704011891}&\ApplyGradient{54.02}{0.148323969741915}   &\ApplyGradient{37.46}{0.338008875623113}   &\ApplyGradient{33.53}{0.233452350598576}   &                                               &\ApplyGradient{54.09}{0.207364413533279}   &  \ApplyGradient{37.43}{0.103682206766638}     &\ApplyGradient{33.59}{0.167332005306815}\\
            \hline
            L6& \ApplyGradient{59.79}{1.22034831093422} &\ApplyGradient{62.71}{0.55610250853596}    &\ApplyGradient{51.31}{0.95420123663722}    &\ApplyGradient{37.86}{0.844393273303382}   &   \ApplyGradient{59.59}{1.45146477738869}     &                                           &  \ApplyGradient{49.37}{0.686112235716576}     &\ApplyGradient{38.51}{0.862699252346959}\\
            \hline
            L7& \ApplyGradient{31.96}{0.761084752179415}&\ApplyGradient{49.26}{0.565022123460668}   &\ApplyGradient{64.98}{0.201866292381867}   &\ApplyGradient{66.4}{1.06360236930913}     &   \ApplyGradient{31.46}{0.801872807869179}    &\ApplyGradient{49.72}{0.539212388581715}   &                                               &\ApplyGradient{67.11}{0.649422820664627}\\
            \hline
            L8& \ApplyGradient{32.88}{0.263628526529284}&\ApplyGradient{42.03}{0.787876893937118}   &\ApplyGradient{59.64}{1.2431814026923}     &\ApplyGradient{69.93}{0.236114379062347}   &   \ApplyGradient{33.26}{0.0961769203083572}   &\ApplyGradient{43.15}{0.853668553948195}   &  \ApplyGradient{61.23}{0.649615270756468}     &                                        \\
            \hline
        \end{tabular}
        \\
        \\
        \shortstack{Skewed \\ \&  \\ non-IID} &
        \setlength\tabcolsep{0pt}
        \begin{tabular}{|l|c|c|c|c|c|c|c|c|}
            \hline
            & L1 & L2 & L3 & L4 & L5 & L6 & L7 & L8\\
            \hline
            L1&                                             &\ApplyGradient{66.85}{0.375832409459322}   &  \ApplyGradient{40.96}{0.258360213655277} &   \ApplyGradient{30.8609958506224}{0.652991613693672} & \ApplyGradient{64.4397759103641}{1.39125057154698}    &\ApplyGradient{59.4128787878787}{0.332115112059683}    &\ApplyGradient{40.1278772378516}{0.245976778282231}    & \ApplyGradient{31.3793103448275}{1.09723466046189}\\
            \hline
            L2& \ApplyGradient{67.9}{0.601040764008566}     &                                           &  \ApplyGradient{50.38}{0.496990945591563} &   \ApplyGradient{35.4045643153526}{1.32672658178167}  & \ApplyGradient{48.9775910364145}{0.861373004015934}   &\ApplyGradient{54.9810606060606}{0.280916609359689}    &\ApplyGradient{43.1713554987212}{0.52414070414116}     & \ApplyGradient{32.3448275862069}{1.6698344845246}\\
            \hline
            L3& \ApplyGradient{40.26}{0.4954795656735}      &\ApplyGradient{50.31}{0.629880941130944}   &                                           &   \ApplyGradient{62.3132780082987}{1.09450895195283}  & \ApplyGradient{33.6134453781512}{0.786062476213019}   &\ApplyGradient{46.8371212121212}{0.452171832814901}    &\ApplyGradient{64.9872122762148}{0.595693846488613}    & \ApplyGradient{59.9310344827586}{1.9222398251267}\\
            \hline
            L4& \ApplyGradient{36.86}{0.0821583836257736}   &\ApplyGradient{40.38}{0.201866292381862}   &  \ApplyGradient{60.66}{0.761084752179417} &                                                       & \ApplyGradient{35.9943977591036}{0.171532895152887}   &\ApplyGradient{41.3446969696969}{0.218008796083709}    &\ApplyGradient{65.9846547314578}{0.361691448177279}    & \ApplyGradient{83.1034482758621}{0.172413793103448}\\
            \hline
            L5& \ApplyGradient{58.36}{0.646529195009787}    &\ApplyGradient{51.96}{1.04546640309481}    &  \ApplyGradient{36.82}{1.81817215906525}  &   \ApplyGradient{34.2946058091286}{1.80398038369944}  &                                                       &\ApplyGradient{58.9772727272727}{0.15560299929124}     &\ApplyGradient{36.4450127877237}{1.05061871644212}     & \ApplyGradient{32.4482758620689}{1.58676901584049}\\
            \hline
            L6& \ApplyGradient{67.88}{2.3962470657259}      &\ApplyGradient{60.44}{4.63079366847628}    &  \ApplyGradient{35.74}{2.27222358054836}  &   \ApplyGradient{28.0394190871369}{2.36567976415736}  & \ApplyGradient{70.7422969187675}{1.33182157782952}    &                                                       & \ApplyGradient{34.3989769820971}{1.06606982100593}    & \ApplyGradient{26.7586206896551}{2.74620048839725}\\
            \hline
            L7& \ApplyGradient{35.89}{0.537819672380995}    &\ApplyGradient{42.13}{0.637965516309464}   &  \ApplyGradient{64.86}{0.426321474945844} &   \ApplyGradient{78.7033195020746}{0.320990631675645} & \ApplyGradient{33.375350140056}{0.269403138118635}    &\ApplyGradient{43.3712121212121}{0.354323616171769}    &                                                       & \ApplyGradient{81.1379310344827}{0.261478463588001} \\
            \hline
            L8& \ApplyGradient{39.64}{0.185067555233216}    &\ApplyGradient{40.89}{0.124498995979887}   &  \ApplyGradient{53.93}{0.428077095860078} &   \ApplyGradient{76.3589211618257}{0.177413188552774} & \ApplyGradient{39.4817927170868}{0.229067608316472}   &\ApplyGradient{41.9696969696969}{0.103735332860831}    &\ApplyGradient{62.5319693094629}{0.15661699122655}     &    \\
        \hline
        \end{tabular}
        \\
        \bottomrule
    \end{tabular}
    }\\
    \caption{Matrix of the membership inference attack accuracy on a per learner basis for the \texttt{3D-CNN} model across every federated learning environment. Rows are the attacking learner and columns are the attacked learner. Colored cells indicate successful attacks and more heated cells specify higher attack accuracies. The results are over 5 runs.}
    \label{tab:3d_cnn_detailed_results}
\end{table}


\begin{table}[htbp]
\footnotesize
\rotatebox{90}{
        \setlength\tabcolsep{0 pt}
    \begin{tabular}{cc}
    \toprule
        Environment & \texttt{2D-slice-mean}\\
        \midrule
        \shortstack{Uniform  \\ \&\\ IID } &
        \setlength\tabcolsep{0pt}
        \begin{tabular}{|l|c|c|c|c|c|c|c|c|}
            \hline
            & L1 & L2 & L3 & L4 & L5 & L6 & L7 & L8\\
            \hline
            L1&                                         & \ApplyGradient{58.63}{1.80298363830624}   &\ApplyGradient{57.18}{2.26842456343604}    &\ApplyGradient{57.15}{1.61283911162893}    &\ApplyGradient{57.41}{1.07319616100693}    &\ApplyGradient{56.89}{1.4284607099952}     &\ApplyGradient{57.02}{1.19300041911141}    &\ApplyGradient{57.77}{1.53850576859497}\\
            \hline
            L2& \ApplyGradient{57.49}{0.700357051795723}&                                           &\ApplyGradient{58.74}{1.00024996875781}    &\ApplyGradient{57.93}{0.88572004606422}    &\ApplyGradient{57.82}{0.790253124005214}   &\ApplyGradient{58.15}{0.483476990145345}   &\ApplyGradient{57.63}{0.947760518274526}   &\ApplyGradient{59.32}{1.15303946159704}\\
            \hline
            L3& \ApplyGradient{58.22}{0.68062471303942} & \ApplyGradient{60.61}{0.658027355054483}  &                                           &\ApplyGradient{58.81}{0.379802580296666}   &\ApplyGradient{58.95}{0.577711000414564}   &\ApplyGradient{58.7}{0.447213595499957}    &\ApplyGradient{58.66}{0.60971304726076}    &\ApplyGradient{60.29}{0.437892680916225}\\
            \hline
            L4& \ApplyGradient{57.07}{0.80513973942416} & \ApplyGradient{58.69}{1.14422462829638}   &\ApplyGradient{57.18}{0.94247015867878}    &                                           &\ApplyGradient{57.43}{0.696957674468113}   &\ApplyGradient{58.2}{0.899305287430249}    &\ApplyGradient{56.34}{0.993352908084532}   &\ApplyGradient{58.01}{0.953546013572495}\\
            \hline
            L5& \ApplyGradient{57.69}{1.11825757319143} & \ApplyGradient{60.28}{1.64984847789123}   &\ApplyGradient{58.64}{1.98254886446715}    &\ApplyGradient{58.26}{1.09110036201992}    &                                           &\ApplyGradient{57.99}{1.5745634315581}     &\ApplyGradient{57.85}{1.6393596310755}     &\ApplyGradient{59.26}{1.55980768045295}\\
            \hline
            L6& \ApplyGradient{56.35}{0.632455532033673}& \ApplyGradient{58.94}{0.80109300333981}   &\ApplyGradient{56.85}{1.06242646804379}    &\ApplyGradient{57.2}{0.639335592627218}    &\ApplyGradient{56.47}{0.583737954907849}   &                                           &\ApplyGradient{55.98}{1.04019228991567}    &\ApplyGradient{58.34}{1.05971694333912}\\
            \hline
            L7& \ApplyGradient{58.0}{0.443001128666734} & \ApplyGradient{60.62}{0.475131560728181}  &\ApplyGradient{59.24}{0.901665126307989}   &\ApplyGradient{58.65}{0.29580398915498}    &\ApplyGradient{59.14}{0.645561770863178}   &\ApplyGradient{58.31}{1.14913010577567}    &                                           &\ApplyGradient{59.91}{0.521296460759137}\\
            \hline
            L8& \ApplyGradient{57.2}{1.25099960031968}  & \ApplyGradient{59.85}{1.05}               &\ApplyGradient{57.53}{1.27798669789634}    &\ApplyGradient{57.64}{1.17760349863611}    &\ApplyGradient{57.58}{0.975064100456991}   &\ApplyGradient{56.72}{1.09121491925284}    &\ApplyGradient{57.24}{1.11769852822665}    &\\
            \hline
        \end{tabular}
        \\
        \\
        \shortstack{Uniform \\  \& \\ non-IID} &
        \setlength\tabcolsep{0pt}
        \begin{tabular}{|l|c|c|c|c|c|c|c|c|}
            \hline
            & L1 & L2 & L3 & L4 & L5 & L6 & L7 & L8\\
            \hline
            L1&                                           &\ApplyGradient{56.83}{0.604772684568343}   &\ApplyGradient{40.44}{0.741114026314437}   &\ApplyGradient{33.88}{1.07738108392527}    &\ApplyGradient{72.73}{0.317411404962078}   &\ApplyGradient{56.43}{0.463141447076376}   &\ApplyGradient{40.01}{0.811171991626928}   &\ApplyGradient{34.05}{1.32617872098748}\\
            \hline
            L2& \ApplyGradient{59.07}{1.81369788002302}   &                                           &\ApplyGradient{52.73}{1.05273453443877}    &\ApplyGradient{40.41}{1.77988763690296}    &\ApplyGradient{59.39}{2.51132435181121}    &\ApplyGradient{62.05}{0.59686681931566}    &\ApplyGradient{51.43}{1.21942609452152}    &\ApplyGradient{40.63}{1.72322372314218}\\
            \hline
            L3& \ApplyGradient{33.18}{1.08662320976501}   &\ApplyGradient{49.95}{0.717635004720365}   &                                           &\ApplyGradient{62.79}{1.01143462467922}    &\ApplyGradient{33.07}{0.770227239196331}   &\ApplyGradient{50.2}{1.05178419839813}     &\ApplyGradient{62.57}{0.219658826364885}   &\ApplyGradient{64.12}{0.672309452558865}\\
            \hline
            L4& \ApplyGradient{29.7}{0.817771361689807}   &\ApplyGradient{40.12}{0.393064880140671}   &\ApplyGradient{58.87}{0.391471582621272}   &                                           &\ApplyGradient{30.81}{0.838450952650183}   &\ApplyGradient{41.31}{0.245967477524977}   &\ApplyGradient{59.6}{0.390512483795333}    &\ApplyGradient{68.8}{0.0612372435695746}\\
            \hline
            L5& \ApplyGradient{73.26}{0.629880941130943}  &\ApplyGradient{57.04}{0.905124300855964}   &\ApplyGradient{41.14}{0.705691150575092}   &\ApplyGradient{35.02}{0.436749356038449}   &                                           &\ApplyGradient{56.7}{0.699999999999998}    &\ApplyGradient{40.89}{0.637769550856732}   &\ApplyGradient{35.1}{0.382426463519458}\\
            \hline
            L6& \ApplyGradient{57.6}{3.65342305242632}    &\ApplyGradient{60.62}{1.78065999000371}    &\ApplyGradient{51.98}{1.24779806058513}    &\ApplyGradient{41.79}{2.88127575910394}    &\ApplyGradient{57.86}{3.44408913938068}    &                                           &\ApplyGradient{51.52}{1.78836517523687}    &\ApplyGradient{42.38}{3.2948065193574}\\
            \hline
            L7& \ApplyGradient{31.39}{1.28520426392072}   &\ApplyGradient{48.18}{0.894147638815874}   &\ApplyGradient{62.86}{0.517687164221794}   &\ApplyGradient{64.07}{1.20187353744061}    &\ApplyGradient{31.54}{1.93597520645281}    &\ApplyGradient{48.46}{0.659924238075858}   &                                           &\ApplyGradient{65.36}{1.06501173702452}\\
            \hline
            L8& \ApplyGradient{30.99}{1.9265902522332}    &\ApplyGradient{41.21}{0.652303610292015}   &\ApplyGradient{59.09}{0.677679865423196}   &\ApplyGradient{69.12}{0.480364444979015}   &\ApplyGradient{32.09}{1.9004604705176}     &\ApplyGradient{42.16}{0.285919569109918}   &\ApplyGradient{59.84}{0.347131099154196}   &\\
            \hline
        \end{tabular}
        \\
        \\
        \shortstack{Skewed \\ \& \\ non-IID} &
        \setlength\tabcolsep{0pt}
        \begin{tabular}{|l|c|c|c|c|c|c|c|c|}
            \hline
            & L1 & L2 & L3 & L4 & L5 & L6 & L7 & L8\\
            \hline
            L1&                                         &\ApplyGradient{66.09}{0.970438045420727}   &\ApplyGradient{42.84}{0.85834142391009}    &\ApplyGradient{29.7717842323651}{0.756088160638666}    &\ApplyGradient{58.4453781512605}{1.06041001296732}     &\ApplyGradient{56.3825757575758}{0.466808997873715}    &\ApplyGradient{38.9002557544757}{0.52257843329163}     &\ApplyGradient{28.0689655172413}{0.735542379575922}\\
            \hline
            L2& \ApplyGradient{66.99}{0.648459713474939}&                                           &\ApplyGradient{51.77}{0.480364444979016}   &\ApplyGradient{33.50622406639}{0.663211195671379}      &\ApplyGradient{48.3613445378151}{0.847020566622334}    &\ApplyGradient{54.6022727272727}{0.416020504478941}    &\ApplyGradient{43.2992327365728}{0.357141689098956}    &\ApplyGradient{29.7241379310345}{0.628778707889999}\\
            \hline
            L3& \ApplyGradient{42.59}{1.51261363209512} &\ApplyGradient{50.25}{1.41818546036828}    &                                           &\ApplyGradient{66.3796680497925}{3.14244305405788}     &\ApplyGradient{35.1960784313725}{2.19088091857272}     &\ApplyGradient{46.8371212121212}{0.994543625236067}    &\ApplyGradient{65.2941176470588}{1.98848076904605}     &\ApplyGradient{59.7586206896551}{4.53484330545104}\\
            \hline
            L4& \ApplyGradient{36.79}{0.861249092887766}&\ApplyGradient{41.14}{0.730924072664186}   &\ApplyGradient{62.6}{1.41067359796659}     &                                                       &\ApplyGradient{35.6302521008403}{1.22438926138302}     &\ApplyGradient{41.7045454545454}{0.566601337183768}    &\ApplyGradient{67.314578005115}{1.30597661705237}      &\ApplyGradient{82.3103448275862}{0.917202488156598}\\
            \hline
            L5& \ApplyGradient{58.25}{0.548862460002504}&\ApplyGradient{51.2}{0.982980162566875}    &\ApplyGradient{36.05}{0.739087274954725}   &\ApplyGradient{32.7904564315352}{1.2358120271869}      &                                                       &\ApplyGradient{57.6515151515151}{0.409502808909817}    &\ApplyGradient{35.8056265984654}{0.658288372185869}    &\ApplyGradient{31.4827586206896}{0.964593153841328}\\
            \hline
            L6& \ApplyGradient{63.94}{1.37949266036467} &\ApplyGradient{57.05}{1.74176634483503}    &\ApplyGradient{37.25}{1.14673449411797}    &\ApplyGradient{30.4771784232365}{2.86976223526042}     &\ApplyGradient{70.7563025210084}{2.70927868229758}     &                                                       &\ApplyGradient{34.6547314578005}{1.40374030691177}     &\ApplyGradient{29.0344827586206}{4.51678070828178}\\
            \hline
            L7& \ApplyGradient{35.66}{1.28860389569487} &\ApplyGradient{41.3}{1.59882769553195}     &\ApplyGradient{64.11}{0.856883889450609}   &\ApplyGradient{78.3091286307054}{1.19486135261327}     &\ApplyGradient{33.8375350140056}{1.30203147332168}     &\ApplyGradient{43.1060606060606}{1.32980982435925}     &                                                       &\ApplyGradient{80.6206896551724}{2.30867155052006}\\
            \hline
            L8& \ApplyGradient{39.6}{0.203100960115899} &\ApplyGradient{40.83}{0.168077363139717}   &\ApplyGradient{55.53}{0.785493475466219}   &\ApplyGradient{77.064315352697}{0.718131582523692}     &\ApplyGradient{39.7338935574229}{0.189205267312431}    &\ApplyGradient{42.4810606060605}{0.10797115767983}     &\ApplyGradient{63.6317135549872}{0.333463038629306}    &\\
            \hline
        \end{tabular}
        \\
        \bottomrule
    \end{tabular}
    }
    \\
    \caption{Matrix of the membership inference attack accuracy on a per learner basis for the \texttt{2D-slice-mean} model across every federated learning environment. Rows are the attacking learner and columns are the attacked learner. Colored cells indicate successful attacks and more heated cells specify higher attack accuracies. The results are over 5 random runs.}
    \label{tab:2d_cnn_detailed_results}
\end{table}



In \sectionref{subsec:federated_result}, we discussed summary results of attacks on models trained via federated learning. Here, we provide a more detailed analysis of the attack results. \tableref{tab:attack_result_feature} compares the attack performance of different feature sets. We observe that in federated environments with similar data sizes and homogeneous data distribution, i.e., Uniform \& IID, all attacks succeeded. However, when the local data size and the data distribution across learners are heterogeneous, the total number of successful attacks decreases, indicating that attacks are sensitive to data distribution. It is interesting to note that even though using only magnitudes as a feature resulted in poor average attack performance, these features may be more robust to distribution shift and have more successful attacks in some cases. Investigating and designing more robust features for membership inference attacks may lead to even more adverse attacks.


\tableref{tab:3d_cnn_detailed_results,tab:2d_cnn_detailed_results} visualize the attack results on a per learner basis. Each row indicates the attacker, and the column indicates the results of the attack on the attacked learner. We observe that the attack performance is correlated with the distribution similarity. For example, for the Uniform \& non-IID distribution, learners L1 and L5 have a similar distribution and hence the attack from L1 on L5 or vice-versa has higher accuracies. However, the attack vulnerabilities are not symmetric; for example, the accuracy of the attack from L3 to L8, or L7 to L4 is higher than vice-versa, even though both learners have trained on the same number of samples. Such differences may be due to the neural network's tendency to overfit differently over diverse local data distributions, which in this case is the age range. An adversary with some more privileged information like knowledge of the distribution of labels or outputs will design more sophisticated attacks.
