{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T23:48:41Z","timestamp":1782949721726,"version":"3.54.5"},"publisher-location":"Singapore","reference-count":44,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819722617","type":"print"},{"value":"9789819722594","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-981-97-2259-4_13","type":"book-chapter","created":{"date-parts":[[2024,4,24]],"date-time":"2024-04-24T09:02:31Z","timestamp":1713949351000},"page":"168-181","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Unveiling Backdoor Risks Brought by\u00a0Foundation Models in\u00a0Heterogeneous Federated Learning"],"prefix":"10.1007","author":[{"given":"Xi","family":"Li","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chen","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jiaqi","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,4,25]]},"reference":[{"key":"13_CR1","unstructured":"Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D., Shmatikov, V.: How to backdoor federated learning. In: AISTATS, vol.\u00a0108, pp. 2938\u20132948. PMLR (2020)"},{"issue":"15","key":"13_CR2","doi-asserted-by":"publisher","first-page":"6986","DOI":"10.3390\/s23156986","volume":"23","author":"L Che","year":"2023","unstructured":"Che, L., Wang, J., Zhou, Y., Ma, F.: Multimodal federated learning: a survey. Sensors 23(15), 6986 (2023)","journal-title":"Sensors"},{"key":"13_CR3","unstructured":"Chen, X., Liu, C., Li, B., Lu, K., Song, D.: Targeted backdoor attacks on deep learning systems using data poisoning. arXiv:1712.05526 (2017)"},{"key":"13_CR4","doi-asserted-by":"crossref","unstructured":"Chou, S., Chen, P., Ho, T.: How to backdoor diffusion models? In: CVPR, pp. 4015\u20134024. IEEE (2023)","DOI":"10.1109\/CVPR52729.2023.00391"},{"key":"13_CR5","doi-asserted-by":"publisher","first-page":"138872","DOI":"10.1109\/ACCESS.2019.2941376","volume":"7","author":"J Dai","year":"2019","unstructured":"Dai, J., Chen, C., Li, Y.: A backdoor attack against LSTM-based text classification systems. IEEE Access 7, 138872\u2013138878 (2019)","journal-title":"IEEE Access"},{"key":"13_CR6","unstructured":"Dong, Q., et al.: A survey for in-context learning. arXiv preprint arXiv:2301.00234 (2022)"},{"key":"13_CR7","unstructured":"Gu, T., Dolan-Gavitt, B., Garg, S.: Badnets: identifying vulnerabilities in the machine learning model supply chain. CoRR abs\/1708.06733 (2017)"},{"key":"13_CR8","doi-asserted-by":"crossref","unstructured":"He, K., Zhang, X., Ren, S., Sun, J.: Deep residual learning for image recognition. In: Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition, pp. 770\u2013778 (2016)","DOI":"10.1109\/CVPR.2016.90"},{"key":"13_CR9","unstructured":"Hinton, G.E., Vinyals, O., Dean, J.: Distilling the knowledge in a neural network. CoRR abs\/1503.02531 (2015)"},{"key":"13_CR10","doi-asserted-by":"crossref","unstructured":"Huang, W., Ye, M., Du, B.: Learn from others and be yourself in heterogeneous federated learning. In: CVPR, pp. 10133\u201310143. IEEE (2022)","DOI":"10.1109\/CVPR52688.2022.00990"},{"key":"13_CR11","unstructured":"Kairouz, P., et\u00a0al.: Advances and open problems in federated learning. Found. Trends\u00ae Mach. Learn. 14(1\u20132), 1\u2013210 (2021)"},{"key":"13_CR12","unstructured":"Kandpal, N., Jagielski, M., Tram\u00e8r, F., Carlini, N.: Backdoor attacks for in-context learning with language models. CoRR abs\/2307.14692 (2023)"},{"key":"13_CR13","doi-asserted-by":"crossref","unstructured":"Kirillov, A., et al.: Segment anything (2023)","DOI":"10.1109\/ICCV51070.2023.00371"},{"key":"13_CR14","unstructured":"Krizhevsky, A., Nair, V., Hinton, G.: Cifar-10 (Canadian institute for advanced research) (2009). http:\/\/www.cs.toronto.edu\/~kriz\/cifar.html"},{"key":"13_CR15","unstructured":"Li, D., Wang, J.: FedMD: heterogenous federated learning via model distillation. CoRR abs\/1910.03581 (2019). http:\/\/arxiv.org\/abs\/1910.03581"},{"key":"13_CR16","doi-asserted-by":"crossref","unstructured":"Li, L., Song, D., Li, X., Zeng, J., Ma, R., Qiu, X.: Backdoor attacks on pre-trained models by layerwise weight poisoning. In: EMNLP (2021)","DOI":"10.18653\/v1\/2021.emnlp-main.241"},{"key":"13_CR17","doi-asserted-by":"crossref","unstructured":"Li, X., Wang, S., Huang, R., Gowda, M., Kesidis, G.: Temporal-distributed backdoor attack against video based action recognition. In: AAAI (2024)","DOI":"10.1609\/aaai.v38i4.28104"},{"key":"13_CR18","unstructured":"Li, X., Wang, S., Wu, C., Zhou, H., Wang, J.: Backdoor threats from compromised foundation models to federated learning. CoRR abs\/2311.00144 (2023)"},{"key":"13_CR19","unstructured":"Lin, T., Kong, L., Stich, S.U., Jaggi, M.: Ensemble distillation for robust model fusion in federated learning. In: NeurIPS (2020)"},{"key":"13_CR20","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102819","volume":"121","author":"S Lu","year":"2022","unstructured":"Lu, S., Li, R., Liu, W., Chen, X.: Defense against backdoor attack in federated learning. Comput. Secur. 121, 102819 (2022)","journal-title":"Comput. Secur."},{"key":"13_CR21","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., Arcas, B.A.: Communication-efficient learning of deep networks from decentralized data. In: AISTATS, pp. 1273\u20131282. PMLR (2017)"},{"key":"13_CR22","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., Arcas, B.A.: Communication-efficient learning of deep networks from decentralized data. In: AISTATS (2017)"},{"key":"13_CR23","unstructured":"OpenAI: Gpt-3: Language models (2020). https:\/\/openai.com\/research\/gpt-3"},{"key":"13_CR24","doi-asserted-by":"crossref","unstructured":"Rieger, P., Nguyen, T.D., Miettinen, M., Sadeghi, A.: Deepsight: mitigating backdoor attacks in federated learning through deep model inspection. In: NDSS. The Internet Society (2022)","DOI":"10.14722\/ndss.2022.23156"},{"key":"13_CR25","doi-asserted-by":"crossref","unstructured":"Rombach, R., Blattmann, A., Lorenz, D., Esser, P., Ommer, B.: High-resolution image synthesis with latent diffusion models (2022)","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"13_CR26","unstructured":"Sanh, V., Debut, L., Chaumond, J., Wolf, T.: DistilBERT, a distilled version of BERT: smaller, faster, cheaper and lighter (2020)"},{"key":"13_CR27","unstructured":"Shi, J., Liu, Y., Zhou, P., Sun, L.: BadGPT: exploring security vulnerabilities of ChatGPT via backdoor attacks to instructGPT. CoRR abs\/2304.12298 (2023)"},{"key":"13_CR28","unstructured":"Socher, R., et al.: Recursive deep models for semantic compositionality over a sentiment treebank. In: EMNLP, pp. 1631\u20131642. ACL (2013)"},{"key":"13_CR29","doi-asserted-by":"crossref","unstructured":"Sun, L., Lyu, L.: Federated model distillation with noise-free differential privacy. In: Zhou, Z. (ed.) IJCAI, pp. 1563\u20131570. ijcai.org (2021)","DOI":"10.24963\/ijcai.2021\/216"},{"key":"13_CR30","unstructured":"Touvron, H., et\u00a0al.: Llama: open and efficient foundation language models. arXiv preprint arXiv:2302.13971 (2023)"},{"key":"13_CR31","unstructured":"Wang, B., et al.: Decodingtrust: a comprehensive assessment of trustworthiness in GPT models. CoRR abs\/2306.11698 (2023)"},{"key":"13_CR32","unstructured":"Wang, H., et al.: Attack of the tails: yes, you really can backdoor federated learning. In: NeurIPS (2020)"},{"key":"13_CR33","doi-asserted-by":"crossref","unstructured":"Wang, J., Ma, F.: Federated learning for rare disease detection: a survey (2023)","DOI":"10.20517\/rdodj.2023.16"},{"key":"13_CR34","unstructured":"Wang, J., et al.: Towards personalized federated learning via heterogeneous model reassembly. arXiv preprint arXiv:2308.08643 (2023)"},{"key":"13_CR35","doi-asserted-by":"crossref","unstructured":"Wu, C., Yang, X., Zhu, S., Mitra, P.: Toward cleansing backdoored neural networks in federated learning. In: ICDCS, pp. 820\u2013830. IEEE (2022)","DOI":"10.1109\/ICDCS54860.2022.00084"},{"key":"13_CR36","doi-asserted-by":"crossref","unstructured":"Wu, C., Wu, F., Liu, R., Lyu, L., Huang, Y., Xie, X.: Fedkd: communication efficient federated learning via knowledge distillation. CoRR abs\/2108.13323 (2021)","DOI":"10.1038\/s41467-022-29763-x"},{"key":"13_CR37","doi-asserted-by":"crossref","unstructured":"Xiang, Z., Miller, D.J., Chen, S., Li, X., Kesidis, G.: A backdoor attack against 3D point cloud classifiers. In: ICCV (2021)","DOI":"10.1109\/ICCV48922.2021.00750"},{"key":"13_CR38","unstructured":"Xie, C., Chen, M., Chen, P., Li, B.: CRFL: certifiably robust federated learning against backdoor attacks. In: ICML, vol.\u00a0139, pp. 11372\u201311382. PMLR (2021)"},{"key":"13_CR39","unstructured":"Xie, C., Huang, K., Chen, P., Li, B.: DBA: distributed backdoor attacks against federated learning. In: ICLR. OpenReview.net (2020)"},{"key":"13_CR40","unstructured":"Xu, J., Ma, M.D., Wang, F., Xiao, C., Chen, M.: Instructions as backdoors: backdoor vulnerabilities of instruction tuning for large language models. CoRR abs\/2305.14710 (2023)"},{"key":"13_CR41","doi-asserted-by":"crossref","unstructured":"Yi, L., Wang, G., Liu, X., Shi, Z., Yu, H.: FedGH: heterogeneous federated learning with generalized global header. In: MM, pp. 8686\u20138696. ACM (2023)","DOI":"10.1145\/3581783.3611781"},{"key":"13_CR42","unstructured":"Yu, S., Qian, W., Jannesari, A.: Resource-aware federated learning using knowledge extraction and multi-model fusion. CoRR abs\/2208.07978 (2022)"},{"key":"13_CR43","unstructured":"Zhang, X., Zhao, J.J., LeCun, Y.: Character-level convolutional networks for text classification. In: NeurIPS, pp. 649\u2013657 (2015)"},{"key":"13_CR44","unstructured":"Zhuang, W., Chen, C., Lyu, L.: When foundation model meets federated learning: motivations, challenges, and future directions. CoRR abs\/2306.15546 (2023)"}],"container-title":["Lecture Notes in Computer Science","Advances in Knowledge Discovery and Data Mining"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-97-2259-4_13","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,4,24]],"date-time":"2024-04-24T23:17:44Z","timestamp":1714000664000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-97-2259-4_13"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9789819722617","9789819722594"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-981-97-2259-4_13","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"25 April 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"PAKDD","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Pacific-Asia Conference on Knowledge Discovery and Data Mining","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Taipei","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Taiwan","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"7 May 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 May 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"pakdd2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/pakdd2024.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}