{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,30]],"date-time":"2025-08-30T16:10:24Z","timestamp":1756570224787,"version":"3.44.0"},"publisher-location":"Cham","reference-count":38,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031944574","type":"print"},{"value":"9783031944581","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,8,31]],"date-time":"2025-08-31T00:00:00Z","timestamp":1756598400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,8,31]],"date-time":"2025-08-31T00:00:00Z","timestamp":1756598400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-031-94458-1_11","type":"book-chapter","created":{"date-parts":[[2025,8,30]],"date-time":"2025-08-30T15:54:37Z","timestamp":1756569277000},"page":"226-248","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["FLKT: Improving the\u00a0Fidelity and\u00a0Robustness of\u00a0Federated Learning Aggregation Rules via\u00a0the\u00a0Key-Data and\u00a0Trap-Model"],"prefix":"10.1007","author":[{"given":"Peng","family":"Tang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaojie","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xinpeng","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weidong","family":"Qiu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zheng","family":"Huang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,8,31]]},"reference":[{"key":"11_CR1","doi-asserted-by":"publisher","unstructured":"Abadi, M., et al.: Deep learning with differential privacy. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 308\u2013318. CCS \u201916 (2016). https:\/\/doi.org\/10.1145\/2976749.2978318","DOI":"10.1145\/2976749.2978318"},{"key":"11_CR2","unstructured":"Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D., Shmatikov, V.: How to backdoor federated learning. In: Proceedings of the Twenty Third International Conference on Artificial Intelligence and Statistics, vol.\u00a0108, pp. 2938\u20132948. PMLR (2020). https:\/\/proceedings.mlr.press\/v108\/bagdasaryan20a.html"},{"key":"11_CR3","unstructured":"Baruch, M., Baruch, G., Goldberg, Y.: A little is enough: circumventing defenses for distributed learning. In: Neural Information Processing Systems (2019)"},{"key":"11_CR4","unstructured":"Bhagoji, A.N., Chakraborty, S., Mittal, P., Calo, S.: Analyzing federated learning through an adversarial lens. In: Proceedings of the 36th International Conference on Machine Learning, vol.\u00a097, pp. 634\u2013643. PMLR (2019). https:\/\/proceedings.mlr.press\/v97\/bhagoji19a.html"},{"key":"11_CR5","unstructured":"Biggio, B., Nelson, B., Laskov, P.: Poisoning attacks against support vector machines. In: Proceedings of the 29th International Conference on International Conference on Machine Learning, pp. 1467\u20131474. Omnipress (2012)"},{"key":"11_CR6","unstructured":"Blanchard, P., El\u00a0Mhamdi, E.M., Guerraoui, R., Stainer, J.: Machine learning with adversaries: byzantine tolerant gradient descent. In: Proceedings of the 31st International Conference on Neural Information Processing Systems, pp. 118\u2014-128. Curran Associates Inc. (2017)"},{"key":"11_CR7","doi-asserted-by":"publisher","unstructured":"Cao, X., Fang, M., Liu, J., Gong, N.Z.: FLTrust: byzantine-robust federated learning via trust bootstrapping. In: Proceedings of the 2021 Network and Distributed System Security Symposium (2021). https:\/\/doi.org\/10.14722\/ndss.2021.24434","DOI":"10.14722\/ndss.2021.24434"},{"key":"11_CR8","unstructured":"Chen, D., Yu, N., Fritz, M.: Relaxloss: defending membership inference attacks without losing utility. In: International Conference on Learning Representations (2022). https:\/\/openreview.net\/forum?id=FEDfGWVZYIn"},{"key":"11_CR9","doi-asserted-by":"publisher","first-page":"141","DOI":"10.1109\/MSP.2012.2211477","volume":"29","author":"L Deng","year":"2012","unstructured":"Deng, L.: The MNIST database of handwritten digit images for machine learning research [best of the web]. IEEE Sig. Process. Mag. 29, 141\u2013142 (2012). https:\/\/doi.org\/10.1109\/MSP.2012.2211477","journal-title":"IEEE Sig. Process. Mag."},{"key":"11_CR10","doi-asserted-by":"crossref","unstructured":"Dong, Y., Chen, X., Li, K., Wang, D., Zeng, S.: FLOD: oblivious defender for private byzantine-robust federated learning with dishonest-majority. In: Computer Security \u2013 ESORICS 2021, pp. 497\u2013518. Springer (2021)","DOI":"10.1007\/978-3-030-88418-5_24"},{"key":"11_CR11","unstructured":"Fang, M., Cao, X., Jia, J., Gong, N.Z.: Local model poisoning attacks to byzantine-robust federated learning. In: Proceedings of the 29th USENIX Conference on Security Symposium, pp. 1623\u20131640. USENIX Association (2020)"},{"key":"11_CR12","unstructured":"Guo, C., Pleiss, G., Sun, Y., Weinberger, K.Q.: On calibration of modern neural networks. In: Proceedings of the 34th International Conference on Machine Learning, vol. 70, pp. 1321\u20131330. ICML\u201917, JMLR.org (2017)"},{"key":"11_CR13","doi-asserted-by":"publisher","unstructured":"Guo, H., et al.: Siren: byzantine-robust federated learning via proactive alarming. In: Proceedings of the ACM Symposium on Cloud Computing, pp. 47\u201360. ACM (2021). https:\/\/doi.org\/10.1145\/3472883.3486990","DOI":"10.1145\/3472883.3486990"},{"key":"11_CR14","unstructured":"Jayaraman, B., Evans, D.: Evaluating differentially private machine learning in practice. In: 28th USENIX Security Symposium (USENIX Security 19), pp. 1895\u20131912. USENIX Association, Santa Clara, CA (2019). https:\/\/www.usenix.org\/conference\/usenixsecurity19\/presentation\/jayaraman"},{"key":"11_CR15","unstructured":"Kone\u010dn\u1ef3, J., McMahan, H.B., Yu, F.X., Richt\u00e1rik, P., Suresh, A.T., Bacon, D.: Federated learning: strategies for improving communication efficiency. arXiv preprint arXiv:1610.05492 (2016)"},{"key":"11_CR16","unstructured":"Krizhevsky, A., Hinton, G.: Learning multiple layers of features from tiny images. In: Handbook of Systemic Autoimmune Diseases, vol. 1 (2009)"},{"key":"11_CR17","doi-asserted-by":"publisher","unstructured":"Li, L., Xu, W., Chen, T., Giannakis, G.B., Ling, Q.: RSA: byzantine-robust stochastic aggregation methods for distributed learning from heterogeneous datasets. In: Proceedings of the Thirty-Third AAAI Conference on Artificial Intelligence. AAAI Press (2019). https:\/\/doi.org\/10.1609\/aaai.v33i01.33011544","DOI":"10.1609\/aaai.v33i01.33011544"},{"key":"11_CR18","doi-asserted-by":"publisher","unstructured":"Lin, F., Ling, Q., Xiong, Z.: Byzantine-resilient distributed large-scale matrix completion. In: Proceedings of the IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), pp. 8167\u20138171 (2019). https:\/\/doi.org\/10.1109\/ICASSP.2019.8683121","DOI":"10.1109\/ICASSP.2019.8683121"},{"key":"11_CR19","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., Arcas, B.A.Y.: Communication-efficient learning of deep networks from decentralized data. In: Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, pp. 1273\u20131282. PMLR (2017). https:\/\/proceedings.mlr.press\/v54\/mcmahan17a.html"},{"key":"11_CR20","unstructured":"Mhamdi, E.M.E., Guerraoui, R., Rouault, S.: The hidden vulnerability of distributed learning in byzantium. In: International Conference on Machine Learning (2018)"},{"key":"11_CR21","unstructured":"M\u00fcller, R., Kornblith, S., Hinton, G.: When does label smoothing help? In: Proceedings of the 33rd International Conference on Neural Information Processing Systems. Red Hook, NY, USA (2019)"},{"key":"11_CR22","unstructured":"Mu\u00f1oz-Gonz\u00e1lez, L., Co, K.T., Lupu, E.C.: Byzantine-robust federated machine learning through adaptive model averaging. arXiv preprint arXiv:1909.05125 (2019)"},{"key":"11_CR23","unstructured":"Pereyra, G., Tucker, G., Chorowski, J., \u0141ukasz Kaiser, Hinton, G.: Regularizing neural networks by penalizing confident output distributions. arXiv preprint arXiv:1701.06548 (2017)"},{"key":"11_CR24","doi-asserted-by":"crossref","unstructured":"Pichler, G., Romanelli, M., Vega, L.R., Piantanida, P.: Perfectly accurate membership inference by a dishonest central server in federated learning. IEEE Trans. Depend. Secure Comput. (2023)","DOI":"10.1109\/TDSC.2023.3326230"},{"key":"11_CR25","unstructured":"Rezaei, S., Liu, X.: Towards the infeasibility of membership inference on deep models. arXiv preprint arXiv:2005.13702 (2020)"},{"key":"11_CR26","doi-asserted-by":"publisher","unstructured":"Rezaei, S., Liu, X.: On the difficulty of membership inference attacks. In: 2021 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pp. 7888\u20137896 (2021). https:\/\/doi.org\/10.1109\/CVPR46437.2021.00780","DOI":"10.1109\/CVPR46437.2021.00780"},{"key":"11_CR27","doi-asserted-by":"crossref","unstructured":"Salem, A., Zhang, Y., Humbert, M., Berrang, P., Fritz, M., Backes, M.: ML-leaks: model and data independent membership inference attacks and defenses on machine learning models. In: Proceedings of the 2019 Network and Distributed System Security Symposium (2019)","DOI":"10.14722\/ndss.2019.23119"},{"key":"11_CR28","doi-asserted-by":"crossref","unstructured":"Shejwalkar, V., Houmansadr, A.: Manipulating the byzantine: Optimizing model poisoning attacks and defenses for federated learning. In: Proceedings 2021 Network and Distributed System Security Symposium (2021)","DOI":"10.14722\/ndss.2021.24498"},{"key":"11_CR29","doi-asserted-by":"publisher","unstructured":"Shejwalkar, V., Houmansadr, A., Kairouz, P., Ramage, D.: Back to the drawing board: a critical evaluation of poisoning attacks on production federated learning. In: 2022 IEEE Symposium on Security and Privacy (SP), pp. 1354\u20131371 (2022). https:\/\/doi.org\/10.1109\/SP46214.2022.9833647","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"11_CR30","doi-asserted-by":"crossref","unstructured":"Shen, L., Zhang, Y., Wang, J., Bai, G.: Better together: attaining the triad of byzantine-robust federated learning via local update amplification. In: Proceedings of the 38th Annual Computer Security Applications Conference, pp. 201\u2013213. ACM (2022)","DOI":"10.1145\/3564625.3564658"},{"key":"11_CR31","unstructured":"Suciu, O., M\u0103rginean, R., Kaya, Y., Daum\u00e9, H., Dumitra\u015f, T.: When does machine learning fail? Generalized transferability for evasion and poisoning attacks. In: Proceedings of the 27th USENIX Conference on Security Symposium, pp. 1299\u20131316. USENIX Association (2018)"},{"key":"11_CR32","unstructured":"Wang, H., et al.: Attack of the tails: yes, you really can backdoor federated learning. Adv. Neural Inf. Process. Syst. (2020). https:\/\/par.nsf.gov\/biblio\/10227029"},{"key":"11_CR33","unstructured":"Xie, Y., et al.: Robust federated learning against both data heterogeneity and poisoning attack via aggregation optimization. arXiv preprint arXiv:2211.05554v2 (2022)"},{"key":"11_CR34","doi-asserted-by":"publisher","unstructured":"Ye, J., Maddi, A., Murakonda, S.K., Bindschaedler, V., Shokri, R.: Enhanced membership inference attacks against machine learning models. In: Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, pp. 3093\u20133106. CCS \u201922 (2022). https:\/\/doi.org\/10.1145\/3548606.3560675","DOI":"10.1145\/3548606.3560675"},{"key":"11_CR35","doi-asserted-by":"publisher","unstructured":"Yeom, S., Giacomelli, I., Fredrikson, M., Jha, S.: Privacy risk in machine learning: analyzing the connection to overfitting. In: Proceedings of the 2018 IEEE 31st Computer Security Foundations Symposium (CSF), pp. 268\u2013282 (2018). https:\/\/doi.org\/10.1109\/CSF.2018.00027","DOI":"10.1109\/CSF.2018.00027"},{"key":"11_CR36","unstructured":"Yin, D., Chen, Y., Kannan, R., Bartlett, P.: Byzantine-robust distributed learning: towards optimal statistical rates. In: Proceedings of the 35th International Conference on Machine Learning, vol.\u00a080, pp. 5650\u20135659. PMLR (2018). https:\/\/proceedings.mlr.press\/v80\/yin18a.html"},{"key":"11_CR37","unstructured":"Zhao, B., Mopuri, K.R., Bilen, H.: iDLG: improved deep leakage from gradients. arXiv preprint arXiv:2001.02610 (2020)"},{"key":"11_CR38","unstructured":"Zhu, L., Liu, Z., Han, S.: Deep leakage from gradients. In: Annual Conference on Neural Information Processing Systems (2019)"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-94458-1_11","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,30]],"date-time":"2025-08-30T15:54:44Z","timestamp":1756569284000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-94458-1_11"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,31]]},"ISBN":["9783031944574","9783031944581"],"references-count":38,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-94458-1_11","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"value":"1867-8211","type":"print"},{"value":"1867-822X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,8,31]]},"assertion":[{"value":"31 August 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SecureComm","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security and Privacy in Communication Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Dubai","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"United Arab Emirates","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28 October 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"securecomm2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/securecomm.eai-conferences.org\/2024\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}