{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,30]],"date-time":"2025-10-30T08:28:39Z","timestamp":1761812919310,"version":"build-2065373602"},"publisher-location":"Cham","reference-count":39,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032081230","type":"print"},{"value":"9783032081247","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,10,31]],"date-time":"2025-10-31T00:00:00Z","timestamp":1761868800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,10,31]],"date-time":"2025-10-31T00:00:00Z","timestamp":1761868800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-08124-7_16","type":"book-chapter","created":{"date-parts":[[2025,10,30]],"date-time":"2025-10-30T08:23:27Z","timestamp":1761812607000},"page":"258-278","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Exploring Backdoor Attacks in\u00a0Federated Learning Under Parameter-Efficient Fine-Tuning"],"prefix":"10.1007","author":[{"given":"Xiaofei","family":"Huang","sequence":"first","affiliation":[]},{"given":"Xiaojie","family":"Zhu","sequence":"additional","affiliation":[]},{"given":"Chi","family":"Chen","sequence":"additional","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2025,10,31]]},"reference":[{"key":"16_CR1","unstructured":"Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D., Shmatikov, V.: How to backdoor federated learning. In: International Conference on Artificial Intelligence and Statistics, pp. 2938\u20132948. PMLR (2020)"},{"key":"16_CR2","unstructured":"Bhagoji, A.N., Chakraborty, S., Mittal, P., Calo, S.: Analyzing federated learning through an adversarial lens. In: International Conference on Machine Learning, pp. 634\u2013643. PMLR (2019)"},{"key":"16_CR3","unstructured":"Blanchard, P., El\u00a0Mhamdi, E.M., Guerraoui, R., Stainer, J.: Machine learning with adversaries: byzantine tolerant gradient descent. In: Advances in Neural Information Processing Systems, vol. 30 (2017)"},{"key":"16_CR4","unstructured":"Bonawitz, K.: Towards federated learning at scale: system design. arXiv preprint arXiv:1902.01046 (2019)"},{"key":"16_CR5","doi-asserted-by":"crossref","unstructured":"Chen, G., Liu, F., Meng, Z., Liang, S.: Revisiting parameter-efficient tuning: are we really there yet? arXiv preprint arXiv:2202.07962 (2022)","DOI":"10.18653\/v1\/2022.emnlp-main.168"},{"key":"16_CR6","unstructured":"Chen, H.Y., Tu, C.H., Li, Z., Shen, H.W., Chao, W.L.: On the importance and applicability of pre-training for federated learning. arXiv preprint arXiv:2206.11488 (2022)"},{"key":"16_CR7","doi-asserted-by":"crossref","unstructured":"Choe, M., Park, C., Seo, C., Kim, H.: SDBA: a stealthy and long-lasting durable backdoor attack in federated learning. arXiv preprint arXiv:2409.14805 (2024)","DOI":"10.1109\/TDSC.2025.3593640"},{"key":"16_CR8","doi-asserted-by":"publisher","first-page":"138872","DOI":"10.1109\/ACCESS.2019.2941376","volume":"7","author":"J Dai","year":"2019","unstructured":"Dai, J., Chen, C., Li, Y.: A backdoor attack against LSTM-based text classification systems. IEEE Access 7, 138872\u2013138878 (2019)","journal-title":"IEEE Access"},{"key":"16_CR9","unstructured":"Devlin, J.: BERT: pre-training of deep bidirectional transformers for language understanding. arXiv preprint arXiv:1810.04805 (2018)"},{"key":"16_CR10","doi-asserted-by":"crossref","unstructured":"Ding, N., et\u00a0al.: Delta tuning: a comprehensive study of parameter efficient methods for pre-trained language models. arXiv preprint arXiv:2203.06904 (2022)","DOI":"10.21203\/rs.3.rs-1553541\/v1"},{"key":"16_CR11","doi-asserted-by":"crossref","unstructured":"Feng, J., Lai, Y., Sun, H., Ren, B.: SADBA: self-adaptive distributed backdoor attack against federated learning. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a039, pp. 16568\u201316576 (2025)","DOI":"10.1609\/aaai.v39i16.33820"},{"key":"16_CR12","unstructured":"Ge, S., Wu, F., Wu, C., Qi, T., Huang, Y., Xie, X.: FedNER: medical named entity recognition with federated learning. arXiv preprint arXiv:2003.09288 (2020)"},{"key":"16_CR13","unstructured":"Goodfellow, I.J., Shlens, J., Szegedy, C.: Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)"},{"key":"16_CR14","unstructured":"Gu, T., Dolan-Gavitt, B., Garg, S.: BadNets: identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017)"},{"key":"16_CR15","doi-asserted-by":"publisher","first-page":"47230","DOI":"10.1109\/ACCESS.2019.2909068","volume":"7","author":"T Gu","year":"2019","unstructured":"Gu, T., Liu, K., Dolan-Gavitt, B., Garg, S.: BadNets: evaluating backdooring attacks on deep neural networks. IEEE Access 7, 47230\u201347244 (2019). https:\/\/doi.org\/10.1109\/ACCESS.2019.2909068","journal-title":"IEEE Access"},{"key":"16_CR16","unstructured":"Han, Z., Gao, C., Liu, J., Zhang, J., Zhang, S.Q.: Parameter-efficient fine-tuning for large models: a comprehensive survey. arXiv preprint arXiv:2403.14608 (2024)"},{"key":"16_CR17","unstructured":"He, S., Yan, Q., Wu, F., Wang, L., L\u00e9cuyer, M., Beschastnikh, I.: GlueFL: reconciling client sampling and model masking for bandwidth efficient federated learning. In: Proceedings of Machine Learning and Systems, vol. 5, pp. 695\u2013707 (2023)"},{"key":"16_CR18","unstructured":"Houlsby, N., et al.: Parameter-efficient transfer learning for NLP. In: International Conference on Machine Learning, pp. 2790\u20132799. PMLR (2019)"},{"key":"16_CR19","unstructured":"Hu, E.J., et al.: LoRA: low-rank adaptation of large language models. arXiv preprint arXiv:2106.09685 (2021)"},{"key":"16_CR20","doi-asserted-by":"crossref","unstructured":"Kurita, K., Michel, P., Neubig, G.: Weight poisoning attacks on pre-trained models. arXiv preprint arXiv:2004.06660 (2020)","DOI":"10.18653\/v1\/2020.acl-main.249"},{"key":"16_CR21","doi-asserted-by":"crossref","unstructured":"Li, X.L., Liang, P.: Prefix-tuning: optimizing continuous prompts for generation. arXiv preprint arXiv:2101.00190 (2021)","DOI":"10.18653\/v1\/2021.acl-long.353"},{"key":"16_CR22","unstructured":"Liang, J., Hu, D., Feng, J.: Do we really need to access the source data? Source hypothesis transfer for unsupervised domain adaptation. In: International Conference on Machine Learning, pp. 6028\u20136039. PMLR (2020)"},{"key":"16_CR23","doi-asserted-by":"crossref","unstructured":"Lin, B.Y., et al.: FedNLP: benchmarking federated learning methods for natural language processing tasks. arXiv preprint arXiv:2104.08815 (2021)","DOI":"10.18653\/v1\/2022.findings-naacl.13"},{"key":"16_CR24","doi-asserted-by":"crossref","unstructured":"Liu, R., et al.: No one left behind: Inclusive federated learning over heterogeneous devices. In: Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, pp. 3398\u20133406 (2022)","DOI":"10.1145\/3534678.3539086"},{"key":"16_CR25","doi-asserted-by":"crossref","unstructured":"Liu, T., Zhang, Y., Feng, Z., Yang, Z., Xu, C., Man, D., Yang, W.: Beyond traditional threats: a persistent backdoor attack on federated learning. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol.\u00a038, pp. 21359\u201321367 (2024)","DOI":"10.1609\/aaai.v38i19.30131"},{"key":"16_CR26","unstructured":"Liu, Y.: RoBERTa: a robustly optimized bert pretraining approach. arXiv preprint arXiv:1907.11692, vol. 364 (2019)"},{"key":"16_CR27","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., y\u00a0Arcas, B.A.: Communication-efficient learning of deep networks from decentralized data. In: Artificial Intelligence and Statistics, pp. 1273\u20131282. PMLR (2017)"},{"key":"16_CR28","unstructured":"Nguyen, J., Wang, J., Malik, K., Sanjabi, M., Rabbat, M.: Where to begin? On the impact of pre-training and initialization in federated learning. arXiv preprint arXiv:2206.15387 (2022)"},{"key":"16_CR29","unstructured":"Nguyen, T.D., et\u00a0al.: $$\\{$$FLAME$$\\}$$: taming backdoors in federated learning. In: 31st USENIX Security Symposium (USENIX Security 2022), pp. 1415\u20131432 (2022)"},{"issue":"8","key":"16_CR30","first-page":"9","volume":"1","author":"A Radford","year":"2019","unstructured":"Radford, A., et al.: Language models are unsupervised multitask learners. OpenAI blog 1(8), 9 (2019)","journal-title":"OpenAI blog"},{"key":"16_CR31","doi-asserted-by":"crossref","unstructured":"Sui, D., Chen, Y., Zhao, J., Jia, Y., Xie, Y., Sun, W.: FedED: federated learning via ensemble distillation for medical relation extraction. In: Proceedings of the 2020 Conference on Empirical Methods in Natural Language Processing (EMNLP), pp. 2118\u20132128 (2020)","DOI":"10.18653\/v1\/2020.emnlp-main.165"},{"key":"16_CR32","unstructured":"Sun, Z., Kairouz, P., Suresh, A.T., McMahan, H.B.: Can you really backdoor federated learning? arXiv preprint arXiv:1911.07963 (2019)"},{"key":"16_CR33","unstructured":"Xie, C., Huang, K., Chen, P.Y., Li, B.: DBA: distributed backdoor attacks against federated learning. In: International Conference on Learning Representations (2019)"},{"key":"16_CR34","doi-asserted-by":"crossref","unstructured":"Yang, Y., Zhou, J., Wong, N., Zhang, Z.: LoRETTA: low-rank economic tensor-train adaptation for ultra-low-parameter fine-tuning of large language models. arXiv preprint arXiv:2402.11417 (2024)","DOI":"10.18653\/v1\/2024.naacl-long.174"},{"key":"16_CR35","unstructured":"Zeng, Y., Zhang, X., Li, H.: Multi-grained vision language pre-training: aligning texts with visual concepts. arXiv preprint arXiv:2111.08276 (2021)"},{"key":"16_CR36","unstructured":"Zhang, J., Zhu, C., Di\u00a0Wu, X.S., Yong, J., Long, G.: BADFSS: backdoor attacks on federated self-supervised learning. In: Proceedings of the 33rd International Joint Conference on Artificial Intelligence (IJCAI) (2021)"},{"key":"16_CR37","doi-asserted-by":"crossref","unstructured":"Zhang, Z., et al.: FedPETuning: when federated learning meets the parameter-efficient tuning methods of pre-trained language models. In: Annual Meeting of the Association of Computational Linguistics 2023, pp. 9963\u20139977. Association for Computational Linguistics (ACL) (2023)","DOI":"10.18653\/v1\/2023.findings-acl.632"},{"key":"16_CR38","unstructured":"Zhu, L., Liu, Z., Han, S.: Deep leakage from gradients. In: Advances in Neural Information Processing Systems, vol. 32 (2019)"},{"key":"16_CR39","unstructured":"Zhuang, H., Yu, M., Wang, H., Hua, Y., Li, J., Yuan, X.: Backdoor federated learning by poisoning backdoor-critical layers. arXiv preprint arXiv:2308.04466 (2023)"}],"container-title":["Lecture Notes in Computer Science","Information Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-08124-7_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,30]],"date-time":"2025-10-30T08:23:52Z","timestamp":1761812632000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-08124-7_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,31]]},"ISBN":["9783032081230","9783032081247"],"references-count":39,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-08124-7_16","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,10,31]]},"assertion":[{"value":"31 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ISC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Seoul","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Korea (Republic of)","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20 October 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 October 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"isw2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/isc25.skku.edu\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}