{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,12]],"date-time":"2026-03-12T11:49:16Z","timestamp":1773316156809,"version":"3.50.1"},"publisher-location":"Singapore","reference-count":40,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819562084","type":"print"},{"value":"9789819562091","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-6209-1_14","type":"book-chapter","created":{"date-parts":[[2026,1,2]],"date-time":"2026-01-02T02:25:30Z","timestamp":1767320730000},"page":"250-269","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Detecting Stealthy Backdoor Attacks in\u00a0Federated Learning via\u00a0Wavelet Analysis on\u00a0Dynamic Dimensions"],"prefix":"10.1007","author":[{"given":"Tian","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bing","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiale","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hao","family":"Sui","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,1,2]]},"reference":[{"key":"14_CR1","unstructured":"McMahan, B., et al.: Communication-efficient learning of deep networks from decentralized data. In: Artificial Intelligence and Statistics, pp. 1273\u20131282. PMLR (2017)"},{"key":"14_CR2","unstructured":"Sun, Z., et al.: Can you really backdoor federated learning? arXiv preprint arXiv:1911.07963 (2019)"},{"key":"14_CR3","unstructured":"Zhang, Z., et al.: Neurotoxin: durable backdoors in federated learning. In: International Conference on Machine Learning, pp. 26429\u201326446. PMLR (2022)"},{"key":"14_CR4","first-page":"16070","volume":"33","author":"H Wang","year":"2020","unstructured":"Wang, H., et al.: Attack of the tails: yes, you really can backdoor federated learning. Adv. Neural. Inf. Process. Syst. 33, 16070\u201316084 (2020)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"14_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1007\/978-3-030-00470-5_13","volume-title":"Research in Attacks, Intrusions, and Defenses","author":"K Liu","year":"2018","unstructured":"Liu, K., Dolan-Gavitt, B., Garg, S.: Fine-pruning: defending against backdooring attacks on deep neural networks. In: Bailey, M., Holz, T., Stamatogiannakis, M., Ioannidis, S. (eds.) RAID 2018. LNCS, vol. 11050, pp. 273\u2013294. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-00470-5_13"},{"key":"14_CR6","doi-asserted-by":"crossref","unstructured":"Wang, B., et al.: Neural cleanse: identifying and mitigating backdoor attacks in neural networks. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 707\u2013723. IEEE (2019)","DOI":"10.1109\/SP.2019.00031"},{"key":"14_CR7","doi-asserted-by":"crossref","unstructured":"Huang, S., et al.: Scope: on detecting constrained backdoor attacks in federated learning. IEEE Trans. Inf. Forensics Secur. (2025)","DOI":"10.1109\/TIFS.2025.3533899"},{"key":"14_CR8","doi-asserted-by":"publisher","first-page":"4752","DOI":"10.1109\/TIFS.2024.3384846","volume":"19","author":"J Zhang","year":"2024","unstructured":"Zhang, J., et al.: FLPurifier: backdoor defense in federated learning via decoupled contrastive training. IEEE Trans. Inf. Forensics Secur. 19, 4752\u20134766 (2024)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"14_CR9","doi-asserted-by":"crossref","unstructured":"Cao, X., Jia, J., Gong, N.Z.: Provably secure federated learning against malicious clients. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 35, no. 8, pp. 6885\u20136893 (2021)","DOI":"10.1609\/aaai.v35i8.16849"},{"key":"14_CR10","unstructured":"Wu, C., et al.: Mitigating backdoor attacks in federated learning. arXiv preprint arXiv:2011.01767 (2020)"},{"issue":"5","key":"14_CR11","doi-asserted-by":"publisher","first-page":"4559","DOI":"10.1109\/TDSC.2024.3354049","volume":"21","author":"J Zhang","year":"2024","unstructured":"Zhang, J., et al.: BadCleaner: defending backdoor attacks in federated learning via attention-based multi-teacher distillation. IEEE Trans. Dependable Secure Comput. 21(5), 4559\u20134573 (2024)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"14_CR12","unstructured":"Blanchard, P., et al.: Machine learning with adversaries: byzantine tolerant gradient descent. In: Advances in Neural Information Processing Systems 30 (2017)"},{"key":"14_CR13","unstructured":"Fung, C., Yoon, C.J.M., Beschastnikh, I.: The limitations of federated learning in Sybil settings. In: 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020), pp. 301\u2013316 (2020)"},{"key":"14_CR14","unstructured":"Nguyen, T.D., et al.: FLAME: taming backdoors in federated learning. In: 31st USENIX Security Symposium (USENIX Security 2022), pp. 1415\u20131432 (2022)"},{"key":"14_CR15","doi-asserted-by":"crossref","unstructured":"Rieger, P., et al.: DeepSight: mitigating backdoor attacks in federated learning through deep model inspection. arXiv preprint arXiv:2201.00763 (2022)","DOI":"10.14722\/ndss.2022.23156"},{"key":"14_CR16","doi-asserted-by":"crossref","unstructured":"Zhang, Z., et al.: FLdetector: defending federated learning against model poisoning attacks via detecting malicious clients. In: Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, pp. 2545\u20132555 (2022)","DOI":"10.1145\/3534678.3539231"},{"key":"14_CR17","doi-asserted-by":"crossref","unstructured":"Huang, S., et al.: Multi-metrics adaptively identifies backdoors in federated learning. In: Proceedings of the IEEE\/CVF International Conference on Computer Vision, pp. 4652\u20134662 (2023)","DOI":"10.1109\/ICCV51070.2023.00429"},{"key":"14_CR18","unstructured":"Li, S., Dai, Y.: BackdoorIndicator: leveraging OOD data for proactive backdoor detection in federated learning. In: 33rd USENIX Security Symposium (USENIX Security 2024), pp. 4193\u20134210 (2024)"},{"key":"14_CR19","unstructured":"Dai, Y., Li, S.: Chameleon: adapting to peer images for planting durable backdoors in federated learning. In: International Conference on Machine Learning, pp. 6712\u20136725. PMLR (2023)"},{"key":"14_CR20","doi-asserted-by":"crossref","unstructured":"Pan, Z., et al.: One-shot backdoor removal for federated learning. IEEE Internet Things J. (2024)","DOI":"10.1109\/JIOT.2024.3438150"},{"key":"14_CR21","unstructured":"Bagdasaryan, E., et al.: How to backdoor federated learning. In: International Conference on Artificial Intelligence and Statistics, pp. 2938\u20132948. PMLR (2020)"},{"key":"14_CR22","doi-asserted-by":"publisher","DOI":"10.1016\/j.engappai.2023.107166","volume":"127","author":"TD Nguyen","year":"2024","unstructured":"Nguyen, T.D., et al.: Backdoor attacks and defenses in federated learning: survey, challenges and future research directions. Eng. Appl. Artif. Intell. 127, 107166 (2024)","journal-title":"Eng. Appl. Artif. Intell."},{"key":"14_CR23","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"480","DOI":"10.1007\/978-3-030-58951-6_24","volume-title":"Computer Security \u2013 ESORICS 2020","author":"V Tolpegin","year":"2020","unstructured":"Tolpegin, V., Truex, S., Gursoy, M.E., Liu, L.: Data poisoning attacks against federated learning systems. In: Chen, L., Li, N., Liang, K., Schneider, S. (eds.) ESORICS 2020, Part I. LNCS, vol. 12308, pp. 480\u2013501. Springer, Cham (2020). https:\/\/doi.org\/10.1007\/978-3-030-58951-6_24"},{"key":"14_CR24","doi-asserted-by":"crossref","unstructured":"Zheng, X., Dong, Q., Fu, A.: WMDefense: using watermark to defense byzantine attacks in federated learning. In: IEEE INFOCOM 2022-IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), pp. 1\u20136. IEEE (2022)","DOI":"10.1109\/INFOCOMWKSHPS54753.2022.9798217"},{"key":"14_CR25","unstructured":"Tran, B., Li, J., Madry, A.: Spectral signatures in backdoor attacks. In: Advances in Neural Information Processing Systems 31 (2018)"},{"issue":"5","key":"14_CR26","first-page":"2088","volume":"18","author":"S Li","year":"2020","unstructured":"Li, S., et al.: Invisible backdoor attacks on deep neural networks via steganography and regularization. IEEE Trans. Dependable Secure Comput. 18(5), 2088\u20132105 (2020)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"14_CR27","unstructured":"Chen, X., et al.: Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)"},{"key":"14_CR28","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103366","volume":"132","author":"C Zhu","year":"2023","unstructured":"Zhu, C., et al.: ADFL: defending backdoor attacks in federated learning via adversarial distillation. Comput. Secur. 132, 103366 (2023)","journal-title":"Comput. Secur."},{"key":"14_CR29","unstructured":"Xie, C., et al.: CRFL: certifiably robust federated learning against backdoor attacks. In: International Conference on Machine Learning, pp. 11372\u201311382. PMLR (2021)"},{"key":"14_CR30","doi-asserted-by":"crossref","unstructured":"Ozdayi, M.S., Kantarcioglu, M., Gel, Y.R.: Defending against backdoors in federated learning with robust learning rate. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 35, no. 10, pp. 9268\u20139276 (2021)","DOI":"10.1609\/aaai.v35i10.17118"},{"key":"14_CR31","doi-asserted-by":"crossref","unstructured":"Li, H., et al.: 3DFED: adaptive and extensible framework for covert backdoor attack in federated learning. In: 2023 IEEE Symposium on Security and Privacy (SP), pp. 1893\u20131907. IEEE (2023)","DOI":"10.1109\/SP46215.2023.10179401"},{"key":"14_CR32","doi-asserted-by":"crossref","unstructured":"Cheng, H., Zhang, M., Shi, J.Q.: A survey on deep neural network pruning: taxonomy, comparison, analysis, and recommendations. IEEE Trans. Pattern Anal. Mach. Intell. (2024)","DOI":"10.1109\/TPAMI.2024.3447085"},{"issue":"6","key":"14_CR33","doi-asserted-by":"publisher","first-page":"2931","DOI":"10.1007\/s12559-024-10313-0","volume":"16","author":"J Tmamna","year":"2024","unstructured":"Tmamna, J., et al.: Pruning deep neural networks for green energy efficient models: a survey. Cogn. Comput. 16(6), 2931\u20132952 (2024)","journal-title":"Cogn. Comput."},{"key":"14_CR34","doi-asserted-by":"publisher","first-page":"33876","DOI":"10.52202\/068431-2455","volume":"35","author":"R Cai","year":"2022","unstructured":"Cai, R., et al.: Randomized channel shuffling: minimal-overhead backdoor attack detection without clean datasets. Adv. Neural. Inf. Process. Syst. 35, 33876\u201333889 (2022)","journal-title":"Adv. Neural. Inf. Process. Syst."},{"key":"14_CR35","unstructured":"Hong, J., et al.: Revisiting data-free knowledge distillation with poisoned teachers. In: International Conference on Machine Learning, pp. 13199\u201313212. PMLR (2023)"},{"issue":"1","key":"14_CR36","first-page":"69","volume":"315","author":"SG Mallat","year":"1989","unstructured":"Mallat, S.G.: Multiresolution approximations and wavelet orthonormal bases of L2(R). Trans. Am. Math. Soc. 315(1), 69\u201387 (1989)","journal-title":"Trans. Am. Math. Soc."},{"key":"14_CR37","doi-asserted-by":"crossref","unstructured":"Meyer, Y.: Wavelets and Operators, vol. 37. Cambridge University Press (1992)","DOI":"10.1017\/CBO9780511623820"},{"issue":"7","key":"14_CR38","doi-asserted-by":"publisher","first-page":"674","DOI":"10.1109\/34.192463","volume":"11","author":"SG Mallat","year":"1989","unstructured":"Mallat, S.G.: A theory for multiresolution signal decomposition: the wavelet representation. IEEE Trans. Pattern Anal. Mach. Intell. 11(7), 674\u2013693 (1989)","journal-title":"IEEE Trans. Pattern Anal. Mach. Intell."},{"issue":"7","key":"14_CR39","doi-asserted-by":"publisher","first-page":"909","DOI":"10.1002\/cpa.3160410705","volume":"41","author":"I Daubechies","year":"1988","unstructured":"Daubechies, I.: Orthonormal bases of compactly supported wavelets. Commun. Pure Appl. Math. 41(7), 909\u2013996 (1988)","journal-title":"Commun. Pure Appl. Math."},{"key":"14_CR40","unstructured":"Gu, T., Dolan-Gavitt, B., Garg, S.: Badnets: identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017)"}],"container-title":["Lecture Notes in Computer Science","Information Security and Cryptology"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-6209-1_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T17:43:23Z","timestamp":1773251003000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-6209-1_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9789819562084","9789819562091"],"references-count":40,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-6209-1_14","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"2 January 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"Inscrypt","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information Security and Cryptology","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Xi'an","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 October 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 October 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cisc22025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/inscrypt2025.xidian.edu.cn\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}