{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T22:38:52Z","timestamp":1776983932538,"version":"3.51.4"},"publisher-location":"Cham","reference-count":28,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032234469","type":"print"},{"value":"9783032234476","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-23447-6_17","type":"book-chapter","created":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T22:03:55Z","timestamp":1776981835000},"page":"369-389","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Antitoxin: A Framework for\u00a0Controlling Persistent Backdoors in\u00a0Federated Learning"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4212-0217","authenticated-orcid":false,"given":"Neeraj","family":"Karamchandani","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-5688-448X","authenticated-orcid":false,"given":"Chen","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-1065-2540","authenticated-orcid":false,"given":"Piyush","family":"Nagasubramaniam","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0741-5511","authenticated-orcid":false,"given":"Dinghao","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1047-7967","authenticated-orcid":false,"given":"Sencun","family":"Zhu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,4,24]]},"reference":[{"key":"17_CR1","unstructured":"Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D., Shmatikov, V.: How to backdoor federated learning. In: International Conference on Artificial Intelligence and Statistics, pp. 2938\u20132948. PMLR (2020)"},{"key":"17_CR2","unstructured":"Baruch, G., Baruch, M., Goldberg, Y.: A little is enough: circumventing defenses for distributed learning. Adv. Neural Inf. Process. Syst. 32 (2019)"},{"key":"17_CR3","unstructured":"Bhagoji, A.N., Chakraborty, S., Mittal, P., Calo, S.: Analyzing federated learning through an adversarial lens. In: International Conference on Machine Learning, pp. 634\u2013643. PMLR (2019)"},{"key":"17_CR4","unstructured":"Cheng, G., Chadha, K., Duchi, J.: Federated asymptotics: a model to compare federated learning algorithms. In: International Conference on Artificial Intelligence and Statistics, pp. 10650\u201310689. PMLR (2023)"},{"key":"17_CR5","unstructured":"Fung, C., Yoon, C.J., Beschastnikh, I.: Mitigating sybils in federated learning poisoning. arXiv preprint arXiv:1808.04866 (2018)"},{"key":"17_CR6","doi-asserted-by":"crossref","unstructured":"Gao, L., Fu, H., Li, L., Chen, Y., Xu, M., Xu, C.Z.: FedDC: federated learning with non-IID data via local drift decoupling and correction. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 10112\u201310121 (2022)","DOI":"10.1109\/CVPR52688.2022.00987"},{"key":"17_CR7","doi-asserted-by":"crossref","unstructured":"Hitaj, B., Ateniese, G., Perez-Cruz, F.: Deep models under the GAN: information leakage from collaborative deep learning. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 603\u2013618 (2017)","DOI":"10.1145\/3133956.3134012"},{"key":"17_CR8","doi-asserted-by":"crossref","unstructured":"Kabir, E., Song, Z., Rashid, M.R.U., Mehnaz, S.: Flshield: a validation based federated learning framework to defend against poisoning attacks. In: 2024 IEEE Symposium on Security and Privacy (SP), pp. 2572\u20132590. IEEE (2024)","DOI":"10.1109\/SP54263.2024.00141"},{"key":"17_CR9","doi-asserted-by":"crossref","unstructured":"Li, H., et al.: 3DFED: adaptive and extensible framework for covert backdoor attack in federated learning. In: 2023 IEEE Symposium on Security and Privacy (SP), pp. 1893\u20131907. IEEE (2023)","DOI":"10.1109\/SP46215.2023.10179401"},{"key":"17_CR10","doi-asserted-by":"crossref","unstructured":"Liu, K., Dolan-Gavitt, B., Garg, S.: Fine-pruning: defending against backdooring attacks on deep neural networks. In: International Symposium on Research in Attacks, Intrusions, and Defenses, pp. 273\u2013294. Springer (2018)","DOI":"10.1007\/978-3-030-00470-5_13"},{"issue":"10","key":"17_CR11","doi-asserted-by":"publisher","first-page":"5877","DOI":"10.3390\/app13105877","volume":"13","author":"T Liu","year":"2023","unstructured":"Liu, T., et al.: Efficient and secure federated learning for financial applications. Appl. Sci. 13(10), 5877 (2023)","journal-title":"Appl. Sci."},{"key":"17_CR12","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., y\u00a0Arcas, B.A.: Communication-efficient learning of deep networks from decentralized data. In: Artificial Intelligence and Statistics, pp. 1273\u20131282. PMLR (2017)"},{"key":"17_CR13","unstructured":"McMahan, H.B., Ramage, D., Talwar, K., Zhang, L.: Learning differentially private recurrent language models. arXiv preprint arXiv:1710.06963 (2017)"},{"key":"17_CR14","unstructured":"Nguyen, T.D., et\u00a0al.: $$\\{$$FLAME$$\\}$$: taming backdoors in federated learning. In: 31st USENIX Security Symposium (USENIX Security 2022), pp. 1415\u20131432 (2022)"},{"key":"17_CR15","unstructured":"Panda, A., Mahloujifar, S., Bhagoji, A.N., Chakraborty, S., Mittal, P.: SparseFed: mitigating model poisoning attacks in federated learning with sparsification. In: International Conference on Artificial Intelligence and Statistics, pp. 7587\u20137624. PMLR (2022)"},{"key":"17_CR16","unstructured":"Paulik, M., et\u00a0al.: Federated evaluation and tuning for on-device personalization: system design & applications. arXiv preprint arXiv:2102.08503 (2021)"},{"key":"17_CR17","doi-asserted-by":"crossref","unstructured":"Prayitno, et al.: A systematic review of federated learning in the healthcare area: From the perspective of data properties and applications. Appl. Sci. 11(23), 11191 (2021)","DOI":"10.3390\/app112311191"},{"key":"17_CR18","doi-asserted-by":"crossref","unstructured":"Rieger, P., Nguyen, T.D., Miettinen, M., Sadeghi, A.R.: DeepSight: mitigating backdoor attacks in federated learning through deep model inspection. arXiv preprint arXiv:2201.00763 (2022)","DOI":"10.14722\/ndss.2022.23156"},{"key":"17_CR19","doi-asserted-by":"crossref","unstructured":"Shejwalkar, V., Houmansadr, A., Kairouz, P., Ramage, D.: Back to the drawing board: a critical evaluation of poisoning attacks on production federated learning. In: 2022 IEEE Symposium on Security and Privacy (SP), pp. 1354\u20131371. IEEE (2022)","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"17_CR20","unstructured":"Sun, Z., Kairouz, P., Suresh, A.T., McMahan, H.B.: Can you really backdoor federated learning? arXiv preprint arXiv:1911.07963 (2019)"},{"key":"17_CR21","doi-asserted-by":"crossref","unstructured":"Wang, B., et al.: Neural cleanse: identifying and mitigating backdoor attacks in neural networks. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 707\u2013723. IEEE (2019)","DOI":"10.1109\/SP.2019.00031"},{"key":"17_CR22","unstructured":"Wang, H., et al.: Attack of the tails: yes, you really can backdoor federated learning. Adv. Neural Inf. Process. Syst. 33, 16070\u201316084 (2020)"},{"issue":"2","key":"17_CR23","doi-asserted-by":"publisher","first-page":"513","DOI":"10.1007\/s13042-022-01647-y","volume":"14","author":"J Wen","year":"2023","unstructured":"Wen, J., Zhang, Z., Lan, Y., Cui, Z., Cai, J., Zhang, W.: A survey on federated learning: challenges and applications. Int. J. Mach. Learn. Cybern. 14(2), 513\u2013535 (2023)","journal-title":"Int. J. Mach. Learn. Cybern."},{"key":"17_CR24","first-page":"81933","volume":"37","author":"PY Weng","year":"2024","unstructured":"Weng, P.Y., Hoang, M., Nguyen, L., Thai, M.T., Weng, L., Hoang, N.: Probabilistic federated prompt-tuning with non-IID and imbalanced data. Adv. Neural. Inf. Process. Syst. 37, 81933\u201381958 (2024)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"17_CR25","unstructured":"Wu, C., Yang, X., Zhu, S., Mitra, P.: Mitigating backdoor attacks in federated learning. arXiv preprint arXiv:2011.01767 (2020)"},{"key":"17_CR26","first-page":"61213","volume":"36","author":"H Zhang","year":"2023","unstructured":"Zhang, H., Jia, J., Chen, J., Lin, L., Wu, D.: A3FL: adversarially adaptive backdoor attacks to federated learning. Adv. Neural. Inf. Process. Syst. 36, 61213\u201361233 (2023)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"17_CR27","doi-asserted-by":"crossref","unstructured":"Zhang, L., Shen, L., Ding, L., Tao, D., Duan, L.Y.: Fine-tuning global model via data-free knowledge distillation for non-IID federated learning. In: Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, pp. 10174\u201310183 (2022)","DOI":"10.1109\/CVPR52688.2022.00993"},{"key":"17_CR28","unstructured":"Zhang, Z., et al.: Neurotoxin: Durable backdoors in federated learning. In: Chaudhuri, K., Jegelka, S., Song, L., Szepesvari, C., Niu, G., Sabato, S. (eds.) Proceedings of the 39th International Conference on Machine Learning. Proceedings of Machine Learning Research, vol.\u00a0162, pp. 26429\u201326446. PMLR (2022). https:\/\/proceedings.mlr.press\/v162\/zhang22w.html"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-23447-6_17","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T22:03:59Z","timestamp":1776981839000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-23447-6_17"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032234469","9783032234476"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-23447-6_17","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"value":"1867-8211","type":"print"},{"value":"1867-822X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"24 April 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SecureComm","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security and Privacy in Communication Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Xiangtan","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 July 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"6 July 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"securecomm2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/securecomm.eai-conferences.org\/2025\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}