{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T19:10:15Z","timestamp":1773774615994,"version":"3.50.1"},"reference-count":107,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2024,6,1]],"date-time":"2024-06-01T00:00:00Z","timestamp":1717200000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,6,1]],"date-time":"2024-06-01T00:00:00Z","timestamp":1717200000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"name":"the Key Research Program for Colleges and Universities in Henan Province in China","award":["23A520021"],"award-info":[{"award-number":["23A520021"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Wireless Pers Commun"],"published-print":{"date-parts":[[2024,6]]},"DOI":"10.1007\/s11277-024-11372-0","type":"journal-article","created":{"date-parts":[[2024,6,25]],"date-time":"2024-06-25T17:09:14Z","timestamp":1719335354000},"page":"2201-2242","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Research Progress on Security and Privacy of Federated Learning: A Survey"],"prefix":"10.1007","volume":"136","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5608-3640","authenticated-orcid":false,"given":"Xingpo","family":"Ma","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mengfan","family":"Yan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,6,25]]},"reference":[{"issue":"2","key":"11372_CR1","doi-asserted-by":"publisher","first-page":"1342","DOI":"10.1109\/COMST.2021.3058573","volume":"23","author":"OA Wahab","year":"2021","unstructured":"Wahab, O. A., Mourad, A., Otrok, H., & Taleb, T. (2021). Federated machine learning: Survey, multi-level classification, desirable criteria and future directions in communication and networking systems. IEEE Communications Surveys & Tutorials, 23(2), 1342\u20131397.","journal-title":"IEEE Communications Surveys & Tutorials"},{"issue":"7","key":"11372_CR2","doi-asserted-by":"publisher","first-page":"6348","DOI":"10.1109\/JIOT.2020.2966778","volume":"7","author":"B Yin","year":"2020","unstructured":"Yin, B., Yin, H., Wu, Y., & Jiang, Z. (2020). FDC: A secure federated deep learning mechanism for data collaborations in the Internet of Things. IEEE Internet of Things Journal, 7(7), 6348\u20136359.","journal-title":"IEEE Internet of Things Journal"},{"key":"11372_CR3","first-page":"17","volume":"12","author":"H Bo","year":"2016","unstructured":"Bo, H. (2016). \u201cNetwork security Law\u2019\u2019 provides legal protection for our data management. China Telecommunications Trade, 12, 17\u201319.","journal-title":"China Telecommunications Trade"},{"key":"11372_CR4","doi-asserted-by":"crossref","unstructured":"de Souza, L. A. C., Rebello, G. A. F., Camilo, G. F., Guimar\u00e3es, L. C., & Duarte, O. C. M. (2020). DFedForest: Decentralized federated forest. In 2020 IEEE international conference on blockchain (blockchain) (pp. 90\u201397). IEEE.","DOI":"10.1109\/Blockchain50366.2020.00019"},{"key":"11372_CR5","doi-asserted-by":"crossref","unstructured":"Shokri, R., & Shmatikov, V. (2015). Privacy-preserving deep learning. In Proceedings of the 22nd ACM SIGSAC conference on computer and communications security (pp. 1310\u20131321).","DOI":"10.1145\/2810103.2813687"},{"issue":"10","key":"11372_CR6","doi-asserted-by":"publisher","first-page":"2430","DOI":"10.1109\/JSAC.2020.3000372","volume":"38","author":"M Song","year":"2020","unstructured":"Song, M., Wang, Z., Zhang, Z., Song, Y., Wang, Q., Ren, J., & Qi, H. (2020). Analyzing user-level privacy attack against federated learning. IEEE Journal on Selected Areas in Communications, 38(10), 2430\u20132444.","journal-title":"IEEE Journal on Selected Areas in Communications"},{"key":"11372_CR7","doi-asserted-by":"crossref","unstructured":"Zhang, J., Chen, B., Yu, S., & Deng, H. (2019). PEFL: A privacy-enhanced federated learning scheme for big data analytics. In 2019 IEEE global communications conference (GLOBECOM) (pp. 1\u20136). IEEE.","DOI":"10.1109\/GLOBECOM38437.2019.9014272"},{"issue":"7","key":"11372_CR8","doi-asserted-by":"publisher","first-page":"1513","DOI":"10.1109\/TPDS.2020.3044223","volume":"32","author":"M Shayan","year":"2020","unstructured":"Shayan, M., Fung, C., Yoon, C. J., & Beschastnikh, I. (2020). Biscotti: A blockchain system for private and secure federated learning. IEEE Transactions on Parallel and Distributed Systems, 32(7), 1513\u20131525.","journal-title":"IEEE Transactions on Parallel and Distributed Systems"},{"issue":"5","key":"11372_CR9","first-page":"12","volume":"8","author":"W Janhan","year":"2022","unstructured":"Janhan, W., Shijing, S., Janzong, W., & Jing, X. (2022). Federated learning attack and defense survey. Big Data Research, 8(5), 12\u201332.","journal-title":"Big Data Research"},{"key":"11372_CR10","unstructured":"Tiankai, L., Bi, Z., & Guang, C. (2021). Federated learning surveyconcept, technology, application and challenge. Journal of Computer Applications."},{"key":"11372_CR11","unstructured":"Shuang, S., Xiaohui, L., Yan, L., & Xing, Z. (2021). Survey on security and privacy protection in different scenarios of federated learning. Application Research of Computers, 3527\u20133534."},{"issue":"5","key":"11372_CR12","first-page":"77","volume":"7","author":"Z Chuanxin","year":"2021","unstructured":"Chuanxin, Z., Yi, S., Degang, W., & Huawei, G. (2021). Survey of federated learning research. Chinese Journal of Network and Information Security, 7(5), 77\u201392.","journal-title":"Chinese Journal of Network and Information Security"},{"key":"11372_CR13","unstructured":"Zhuangzhuang, W., Hongsong, C., Limin, Y., & Lifang, C. (2021). Review of federal learning and data security. Intelligent Computer and Applications, (01), 126\u2013129+133."},{"issue":"5","key":"11372_CR14","first-page":"10","volume":"52","author":"C Bing","year":"2020","unstructured":"Bing, C., Xiang, C., Jiale, Z., & Yuanyuan, X. (2020). Survey of security and privacy in federated learning. Journal of Nanjing University of Aeronautics & Astronautics, 52(5), 10.","journal-title":"Journal of Nanjing University of Aeronautics & Astronautics"},{"issue":"4","key":"11372_CR15","first-page":"9","volume":"39","author":"Z Jun","year":"2020","unstructured":"Jun, Z., Guoying, F., & Nan, W. (2020). Survey on security and privacy preserving in federated learning. Journal of Xihua University (Natural Science Edition), 39(4), 9.","journal-title":"Journal of Xihua University (Natural Science Edition)"},{"key":"11372_CR16","first-page":"6","volume":"25","author":"W Jia","year":"2020","unstructured":"Jia, W., & Lu, M. (2020). Analysis of federated learning. Modern Computer, 25, 6.","journal-title":"Modern Computer"},{"issue":"2","key":"11372_CR17","doi-asserted-by":"publisher","first-page":"639","DOI":"10.1007\/s40747-020-00247-z","volume":"7","author":"H Zhu","year":"2021","unstructured":"Zhu, H., Zhang, H., & Jin, Y. (2021). From federated learning to federated neural architecture search: A survey. Complex & Intelligent Systems, 7(2), 639\u2013657.","journal-title":"Complex & Intelligent Systems"},{"key":"11372_CR18","unstructured":"Kone\u010dn\u1ef3, J., McMahan, H. B., Yu, F. X., Richt\u00e1rik, P., Suresh, A. T., & Bacon, D. (2016). Federated learning: Strategies for improving communication efficiency. arXiv preprint arXiv:1610.05492."},{"key":"11372_CR19","unstructured":"Kone\u010dn\u1ef3, J., McMahan, H. B., Ramage, D., & Richt\u00e1rikk, P. (2016). Federated optimization: Distributed machine learning for on-device intelligence. arXiv preprint arXiv:1610.02527."},{"key":"11372_CR20","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., & y Arcas, B. A. (2017). Communication-efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics (pp. 1273\u20131282)."},{"key":"11372_CR21","unstructured":"Changyin, L., Xuebin, C., Chundi, M., & Shufen. (2021). Improved federated average algorithm based on tomographic analysis. Computer Science, 48(8), 32\u201340."},{"key":"11372_CR22","unstructured":"Biying, P., Haihua, Q., & Jialun, Z. (2019). Research on federated machine learning techniques with different data distributions. Proceedings of 5G network innovation symposium."},{"key":"11372_CR23","unstructured":"Li, Q., Wen, Z., Wu, Z., Hu, S., Wang, N., Li,Y., Liu, X., Li, Y., & He, B. (2021). A survey on federated learning systems: vision, hype and reality for data privacy and protection. IEEE Transactions on Knowledge and Data Engineering."},{"key":"11372_CR24","doi-asserted-by":"crossref","unstructured":"Kairouz, P., McMahan, H. B., Avent, B., Bellet, A., Bennis, M., Bhagoji, A. N., & Zhao, S. (2021). Advances and open problems in federated learning. Foundations and Trends\u00ae in Machine Learning, 14(1\u20132), 1\u2013210.","DOI":"10.1561\/2200000083"},{"issue":"2","key":"11372_CR25","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3298981","volume":"10","author":"Q Yang","year":"2019","unstructured":"Yang, Q., Liu, Y., Chen, T., & Tong, Y. (2019). Federated machine learning: Concept and applications. ACM Transactions on Intelligent Systems and Technology (TIST), 10(2), 1\u201319.","journal-title":"ACM Transactions on Intelligent Systems and Technology (TIST)"},{"key":"11372_CR26","doi-asserted-by":"crossref","unstructured":"Leroy, D., Coucke, A., Lavril, T., Gisselbrecht, T., & Dureau, J. (2019). Federated learning for keyword spotting. In Icassp 2019-2019 IEEE international conference on acoustics, speech and signal processing (ICASSP) (pp. 6341\u20136345).","DOI":"10.1109\/ICASSP.2019.8683546"},{"key":"11372_CR27","unstructured":"McMahan, H. B., Moore, E., Ramage, D., & Arcas, B. A. (2016). Federated learning of deep networks using model averaging. arXiv preprint arXiv:1602.05629."},{"issue":"3","key":"11372_CR28","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/978-3-031-01585-4","volume":"13","author":"Q Yang","year":"2019","unstructured":"Yang, Q., Liu, Y., Cheng, Y., Kang, Y., Chen, T., & Yu, H. (2019). Federated learning. Synthesis Lectures on Artificial Intelligence and Machine Learning, 13(3), 1\u2013207.","journal-title":"Synthesis Lectures on Artificial Intelligence and Machine Learning"},{"key":"11372_CR29","doi-asserted-by":"crossref","unstructured":"Christen, P. (2012). Data matching: concepts and techniques for record linkage, entity resolution, and duplicate detection.","DOI":"10.1007\/978-3-642-31164-2"},{"issue":"1","key":"11372_CR30","first-page":"165","volume":"53","author":"Z Yan","year":"2016","unstructured":"Yan, Z., Guoliang, L., & Jianhua, F. (2016). A survey on entity alignment of knowledge base. Journal of Computer Research and Development, 53(1), 165.","journal-title":"Journal of Computer Research and Development"},{"issue":"1","key":"11372_CR31","first-page":"54","volume":"40","author":"G Lipeng","year":"2018","unstructured":"Lipeng, G., & Hui, Z. (2018). Convolutional neural network based on pelus softplus nonlinear excitation function. Journal of Shenyang University of Technology, 40(1), 54\u201359.","journal-title":"Journal of Shenyang University of Technology"},{"issue":"1","key":"11372_CR32","doi-asserted-by":"publisher","first-page":"35","DOI":"10.3233\/IA-200075","volume":"15","author":"S Saha","year":"2021","unstructured":"Saha, S., & Ahmad, T. (2021). Federated transfer learning: Concept and applications. Intelligenza Artificiale, 15(1), 35\u201344.","journal-title":"Intelligenza Artificiale"},{"issue":"10","key":"11372_CR33","doi-asserted-by":"publisher","first-page":"1345","DOI":"10.1109\/TKDE.2009.191","volume":"22","author":"SJ Pan","year":"2009","unstructured":"Pan, S. J., & Yang, Q. (2009). A survey on transfer learning. IEEE Transactions on Knowledge and Data Engineering, 22(10), 1345\u20131359.","journal-title":"IEEE Transactions on Knowledge and Data Engineering"},{"issue":"4","key":"11372_CR34","doi-asserted-by":"publisher","first-page":"83","DOI":"10.1109\/MIS.2020.2988604","volume":"35","author":"Y Chen","year":"2020","unstructured":"Chen, Y., Qin, X., Wang, J., Yu, C., & Gao, W. (2020). Fedhealth: A federated transfer learning framework for wearable healthcare. IEEE Intelligent Systems, 35(4), 83\u201393.","journal-title":"IEEE Intelligent Systems"},{"key":"11372_CR35","doi-asserted-by":"crossref","unstructured":"Lu, C., Fan, Y., Wu, X., & Zhang, J. (2021). Fmfparking: Federated matrix factorization for parking lot recommendation. In 2021 IEEE seventh international conference on big data computing service and applications (bigdataservice) (pp. 131\u2013136).","DOI":"10.1109\/BigDataService52369.2021.00021"},{"key":"11372_CR36","doi-asserted-by":"crossref","unstructured":"Hao, M., Li, H., Xu, G., Liu, S., & Yang, H. (2019). Towards efficient and privacy-preserving federated deep learning. In ICC 2019-2019 IEEE international conference on communications (ICC) (pp. 1\u20136).","DOI":"10.1109\/ICC.2019.8761267"},{"issue":"1","key":"11372_CR37","doi-asserted-by":"publisher","first-page":"234","DOI":"10.1109\/MNET.011.2000263","volume":"35","author":"Y Li","year":"2020","unstructured":"Li, Y., Chen, C., Liu, N., Huang, H., Zheng, Z., & Yan, Q. (2020). A blockchain-based decentralized federated learning framework with committee consensus. IEEE Network, 35(1), 234\u2013241.","journal-title":"IEEE Network"},{"key":"11372_CR38","doi-asserted-by":"crossref","unstructured":"Liu, Y., Ma, Z., Liu, X., Ma, S., Nepal, S., Deng, R. H., & Ren, K. (2020). Boosting privately: Federated extreme gradient boosting for mobile crowd-sensing. In 2020 IEEE 40th international conference on distributed computing systems (ICDCS) (pp. 1\u201311).","DOI":"10.1109\/ICDCS47774.2020.00017"},{"issue":"10","key":"11372_CR39","doi-asserted-by":"publisher","first-page":"6532","DOI":"10.1109\/TII.2019.2945367","volume":"16","author":"M Hao","year":"2019","unstructured":"Hao, M., Li, H., Luo, X., Xu, G., Yang, H., & Liu, S. (2019). Efficient and privacy-enhanced federated learning for industrial artificial intelligence. IEEE Transactions on Industrial Informatics, 16(10), 6532\u20136542.","journal-title":"IEEE Transactions on Industrial Informatics"},{"issue":"6","key":"11372_CR40","doi-asserted-by":"publisher","first-page":"4177","DOI":"10.1109\/TII.2019.2942190","volume":"16","author":"Y Lu","year":"2019","unstructured":"Lu, Y., Huang, X., Dai, Y., Maharjan, S., & Zhang, Y. (2019). Blockchain and federated learning for privacy-preserved data sharing in industrial iot. IEEE Transactions on Industrial Informatics, 16(6), 4177\u20134186.","journal-title":"IEEE Transactions on Industrial Informatics"},{"key":"11372_CR41","doi-asserted-by":"crossref","unstructured":"Wan, W., Lu, J., Hu, S., Zhang, L. Y., & Pei, X. (2021). Shielding federated learning: A new attack approach and its defense. In 2021 IEEE wireless communications and networking conference (wcnc) (pp. 1\u20137).","DOI":"10.1109\/WCNC49053.2021.9417334"},{"issue":"6","key":"11372_CR42","doi-asserted-by":"publisher","first-page":"4049","DOI":"10.1109\/TII.2021.3085960","volume":"18","author":"B Jia","year":"2021","unstructured":"Jia, B., Zhang, X., Liu, J., Zhang, Y., Huang, K., & Liang, Y. (2021). Blockchain-enabled federated learning data protection aggregation scheme with differential privacy and homomorphic encryption in iiot. IEEE Transactions on Industrial Informatics, 18(6), 4049\u20134058.","journal-title":"IEEE Transactions on Industrial Informatics"},{"issue":"5","key":"11372_CR43","doi-asserted-by":"publisher","first-page":"3492","DOI":"10.1109\/TII.2021.3107783","volume":"18","author":"L Cui","year":"2021","unstructured":"Cui, L., Qu, Y., Xie, G., Zeng, D., Li, R., Shen, S., & Yu, S. (2021). Security and privacy-enhanced federated learning for anomaly detection in IoT infrastructures. IEEE Transactions on Industrial Informatics, 18(5), 3492\u20133500.","journal-title":"IEEE Transactions on Industrial Informatics"},{"issue":"2","key":"11372_CR44","doi-asserted-by":"publisher","first-page":"1333","DOI":"10.1109\/TII.2021.3095506","volume":"18","author":"Z Su","year":"2021","unstructured":"Su, Z., Wang, Y., Luan, T. H., Zhang, N., Li, F., Chen, T., & Cao, H. (2021). Secure and efficient federated learning for smart grid with edge-cloud collaboration. IEEE Transactions on Industrial Informatics, 18(2), 1333\u20131344.","journal-title":"IEEE Transactions on Industrial Informatics"},{"key":"11372_CR45","unstructured":"Mugunthan, V., Rahman, R., & Kagal, L. (2020). Blockflow: An accountable and privacy-preserving solution for federated learning. arXiv preprint arXiv:2007.03856."},{"key":"11372_CR46","doi-asserted-by":"publisher","first-page":"276","DOI":"10.1109\/OJCS.2021.3099108","volume":"2","author":"R Hu","year":"2021","unstructured":"Hu, R., Guo, Y., & Gong, Y. (2021). Concentrated differentially private federated learning with performance analysis. IEEE Open Journal of the Computer Society, 2, 276\u2013289.","journal-title":"IEEE Open Journal of the Computer Society"},{"issue":"4","key":"11372_CR47","doi-asserted-by":"publisher","first-page":"50","DOI":"10.1109\/MIS.2020.2993966","volume":"35","author":"A Triastcyn","year":"2020","unstructured":"Triastcyn, A., & Faltings, B. (2020). Federated generative privacy. IEEE Intelligent Systems, 35(4), 50\u201357.","journal-title":"IEEE Intelligent Systems"},{"key":"11372_CR48","doi-asserted-by":"crossref","unstructured":"Paul, S., Sengupta, P., & Mishra, S. (2020). Flaps: Federated learning and privately scaling. In 2020 IEEE 17th international conference on mobile ad hoc and sensor systems (MASS) (pp. 13\u201319).","DOI":"10.1109\/MASS50613.2020.00011"},{"issue":"3","key":"11372_CR49","doi-asserted-by":"publisher","first-page":"463","DOI":"10.1109\/LCOMM.2014.2385095","volume":"19","author":"L Sun","year":"2014","unstructured":"Sun, L., Ren, P., Du, Q., Wang, Y., & Gao, Z. (2014). Security-aware relaying scheme for cooperative networks with untrusted relay nodes. IEEE Communications Letters, 19(3), 463\u2013466.","journal-title":"IEEE Communications Letters"},{"key":"11372_CR50","doi-asserted-by":"crossref","unstructured":"Lee, H., Kim, J., Hussain, R., Cho, S., & Son, J. (2021). On defensive neural networks against inference attack in federated learning. In Icc 2021-IEEE international conference on communications(pp. 1\u20136).","DOI":"10.1109\/ICC42927.2021.9500936"},{"key":"11372_CR51","doi-asserted-by":"crossref","unstructured":"Kerkouche, R., \u00c1cs, G., Castelluccia, C., & Genev\u00e8s, P. (2021). Compression boosts differentially private federated learning. In 2021 IEEE European symposium on security and privacy (euros & p) (pp. 304\u2013318).","DOI":"10.1109\/EuroSP51992.2021.00029"},{"issue":"2","key":"11372_CR52","doi-asserted-by":"publisher","first-page":"1084","DOI":"10.1109\/TNSE.2020.2996612","volume":"8","author":"H Yang","year":"2020","unstructured":"Yang, H., He, H., Zhang, W., & Cao, X. (2020). Fedsteg: A federated transfer learning framework for secure image steganalysis. IEEE Transactions on Network Science and Engineering, 8(2), 1084\u20131094.","journal-title":"IEEE Transactions on Network Science and Engineering"},{"issue":"7","key":"11372_CR53","doi-asserted-by":"publisher","first-page":"5080","DOI":"10.1109\/JIOT.2021.3110097","volume":"9","author":"C Liu","year":"2021","unstructured":"Liu, C., Guo, S., Guo, S., Yan, Y., Qiu, X., & Zhang, S. (2021). Ltsm: Lightweight and trusted sharing mechanism of IoT data in smart city. IEEE Internet of Things Journal, 9(7), 5080\u20135093.","journal-title":"IEEE Internet of Things Journal"},{"key":"11372_CR54","doi-asserted-by":"crossref","unstructured":"Zhou, P. (2020). Federated deep payload classification for industrial internet with cloud-edge architecture. In 2020 16th international conference on mobility, sensing and networking (MSN) (pp. 228\u2013235).","DOI":"10.1109\/MSN50589.2020.00048"},{"key":"11372_CR55","doi-asserted-by":"crossref","unstructured":"Xin, B., Yang, W., Geng, Y., Chen, S., Wang, S., & Huang, L. (2020). Private fl-gan: Differential privacy synthetic data generation based on federated learning. In Icassp 2020-2020 IEEE international conference on acoustics, speech and signal processing (ICASSP) (pp. 2927\u20132931).","DOI":"10.1109\/ICASSP40776.2020.9054559"},{"key":"11372_CR56","doi-asserted-by":"publisher","first-page":"205071","DOI":"10.1109\/ACCESS.2020.3037474","volume":"8","author":"MA Rahman","year":"2020","unstructured":"Rahman, M. A., Hossain, M. S., Islam, M. S., Alrajeh, N. A., & Muhammad, G. (2020). Secure and provenance enhanced internet of health things framework: A blockchain managed federated learning approach. IEEE Access, 8, 205071\u2013205087.","journal-title":"IEEE Access"},{"key":"11372_CR57","doi-asserted-by":"crossref","unstructured":"Yang, J., Fu, C., Liu, X. Y., & Walid, A. (2021). Recommendations in smart devices using federated tensor learning. IEEE Internet of Things Journal.","DOI":"10.1109\/JIOT.2021.3116505"},{"key":"11372_CR58","doi-asserted-by":"publisher","first-page":"914","DOI":"10.1109\/ACCESS.2016.2538818","volume":"4","author":"J Suomalainen","year":"2016","unstructured":"Suomalainen, J., & Julku, J. (2016). Enhancing privacy of information brokering in smart districts by adaptive pseudonymization. IEEE Access, 4, 914\u2013927.","journal-title":"IEEE Access"},{"key":"11372_CR59","doi-asserted-by":"publisher","first-page":"3454","DOI":"10.1109\/TIFS.2020.2988575","volume":"15","author":"K Wei","year":"2020","unstructured":"Wei, K., Li, J., Ding, M., Ma, C., Yang, H. H., Farokhi, F., Jin, S., Quek, T. Q. S., & Poor, H. V. (2020). Federated learning with differential privacy: Algorithms and performance analysis. IEEE Transactions on Information Forensics and Security, 15, 3454\u20133469.","journal-title":"IEEE Transactions on Information Forensics and Security"},{"issue":"5","key":"11372_CR60","doi-asserted-by":"publisher","first-page":"11","DOI":"10.1109\/MIS.2020.3014880","volume":"36","author":"D Chai","year":"2020","unstructured":"Chai, D., Wang, L., Chen, K., & Yang, Q. (2020). Secure federated matrix factorization. IEEE Intelligent Systems, 36(5), 11\u201320.","journal-title":"IEEE Intelligent Systems"},{"issue":"6","key":"11372_CR61","doi-asserted-by":"publisher","first-page":"87","DOI":"10.1109\/MIS.2021.3082561","volume":"36","author":"K Cheng","year":"2021","unstructured":"Cheng, K., Fan, T., Jin, Y., Liu, Y., Chen, T., Papadopoulos, D., & Yang, Q. (2021). Secureboost: A lossless federated learning framework. IEEE Intelligent Systems, 36(6), 87\u201398.","journal-title":"IEEE Intelligent Systems"},{"issue":"3","key":"11372_CR62","doi-asserted-by":"publisher","first-page":"73","DOI":"10.3390\/fi13030073","volume":"13","author":"X Zhou","year":"2021","unstructured":"Zhou, X., Xu, M., Wu, Y., & Zheng, N. (2021). Deep model poisoning attack on federated learning. Future Internet, 13(3), 73.","journal-title":"Future Internet"},{"issue":"10","key":"11372_CR63","first-page":"2049","volume":"56","author":"H Yingzhe","year":"2019","unstructured":"Yingzhe, H., Xingbo, H., Jinwen, H., Guozhu, M., & Kai, C. (2019). Privacy and security issues in machine learning systems: A survey. Journal of Computer Research and Development, 56(10), 2049\u20132070.","journal-title":"Journal of Computer Research and Development"},{"key":"11372_CR64","unstructured":"Biggio, B., Nelson, B., & Laskov, P. (2012). Poisoning attacks against support vector machines. arXiv preprint arXiv:1206.6389."},{"key":"11372_CR65","unstructured":"Shafahi, A., Huang, W. R., Najibi, M., Suciu, O., Studer, C., Dumitras, T., & Goldstein, T. (2018). Poison frogs! targeted clean-label poisoning attacks on neural networks. Advances in neural information processing systems, 31."},{"key":"11372_CR66","doi-asserted-by":"crossref","unstructured":"Mu\u00f1oz-Gonz\u00e1lez, L., Biggio, B., Demontis, A., Paudice, A., Wongrassamee, V., Lupu, E. C., & Roli, F. (2017). Towards poisoning of deep learning algorithms with back-gradient optimization. In Proceedings of the 10th ACM workshop on artificial intelligence and security (pp. 27\u201338).","DOI":"10.1145\/3128572.3140451"},{"key":"11372_CR67","doi-asserted-by":"crossref","unstructured":"Jagielski, M., Oprea, A., Biggio, B., Liu, C., Nita-Rotaru, C., & Li, B. (2018). Manipulating machine learning: Poisoning attacks and countermeasures for regression learning. In 2018 IEEE symposium on security and privacy (SP) (pp. 19\u201335).","DOI":"10.1109\/SP.2018.00057"},{"key":"11372_CR68","doi-asserted-by":"crossref","unstructured":"Fang, M., Gong, N. Z., & Liu, J. (2020). Influence function based data poisoning attacks to top-n recommender systems. In Proceedings of the web conference 2020 (pp. 3019\u20133025).","DOI":"10.1145\/3366423.3380072"},{"key":"11372_CR69","unstructured":"Xiao, H., Biggio, B., Brown, G., Fumera, G., Eckert, C., & Roli, F. (2015). Is feature selection secure against training data poisoning? In International conference on machine learning (pp. 1689\u20131698)."},{"key":"11372_CR70","unstructured":"Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D., & Shmatikov, V. (2020). How to backdoor federated learning. In International conference on artificial intelligence and statistics (pp. 2938\u20132948)."},{"key":"11372_CR71","doi-asserted-by":"crossref","unstructured":"Liu, Y., Ma, S., Aafer, Y., Lee, W. C., Zhai, J., Wang, W., & Zhang, X. (2017). Trojaning attack on neural networks.","DOI":"10.14722\/ndss.2018.23291"},{"key":"11372_CR72","unstructured":"Yin, D., Chen, Y., Kannan, R., & Bartlett, P. (2018). Byzantine-robust distributed learning: Towards optimal statistical rates. In International conference on machine learning (pp. 5650\u20135659)."},{"key":"11372_CR73","doi-asserted-by":"crossref","unstructured":"Lyu, L., Yu, H., & Yang, Q. (2020). Threats to federated learning: A survey. arXiv preprint arXiv:2003.02133.","DOI":"10.1007\/978-3-030-63076-8_1"},{"key":"11372_CR74","doi-asserted-by":"crossref","unstructured":"Nasr, M., Shokri, R., & Houmansadr, A. (2019). Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In 2019 IEEE symposium on security and privacy (sp) (pp. 739\u2013753).","DOI":"10.1109\/SP.2019.00065"},{"key":"11372_CR75","doi-asserted-by":"crossref","unstructured":"Dong, Y., Su, H., Wu, B., Li, Z., Liu, W., Zhang, T., & Zhu, J. (2019). Efficient decision-based black-box adversarial attacks on face recognition. In Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (pp. 7714\u20137722).","DOI":"10.1109\/CVPR.2019.00790"},{"key":"11372_CR76","unstructured":"Yin, Z., Yuan, Y., Guo, P., & Zhou, P. (2021). Backdoor attacks on federated learning with lottery ticket hypothesis. arXiv preprint arXiv:2109.10512."},{"issue":"4","key":"11372_CR77","first-page":"1","volume":"13","author":"H Ren","year":"2022","unstructured":"Ren, H., Deng, J., & Xie, X. (2022). Grnn: Generative regression neural network-a data leakage attack for federated learning. ACM Transactions on Intelligent Systems and Technology (TIST), 13(4), 1\u201324.","journal-title":"ACM Transactions on Intelligent Systems and Technology (TIST)"},{"key":"11372_CR78","doi-asserted-by":"crossref","unstructured":"Hitaj, B., Ateniese, G., & Perez-Cruz, F. (2017). Deep models under the gan: Information leakage from collaborative deep learning. In Proceedings of the 2017 ACM SIGSAC conference on computer and communications security (pp. 603\u2013618).","DOI":"10.1145\/3133956.3134012"},{"key":"11372_CR79","doi-asserted-by":"crossref","unstructured":"Phong, L. T., Aono, Y., Hayashi, T., Wang, L., & Moriai, S. (2017). Privacy-preserving deep learning: Revisited and enhanced. In International conference on applications and techniques in information security (pp. 100\u2013110).","DOI":"10.1007\/978-981-10-5421-1_9"},{"key":"11372_CR80","unstructured":"Tram\u00e8r, F., Zhang, F., Juels, A., Reiter, M. K., & Ristenpart, T. (2016). Stealing machine learning models via prediction $$\\{$$APIs$$\\}$$. In 25th usenix security symposium (usenix security 16) (pp. 601\u2013618)."},{"issue":"2133","key":"11372_CR81","doi-asserted-by":"publisher","first-page":"20180083","DOI":"10.1098\/rsta.2018.0083","volume":"376","author":"M Veale","year":"2018","unstructured":"Veale, M., Binns, R., & Edwards, L. (2018). Algorithms that remember: Model inversion attacks and data protection law. Philosophical Transactions of the Royal Society A: Mathematical, Physical and Engineering Sciences, 376(2133), 20180083.","journal-title":"Philosophical Transactions of the Royal Society A: Mathematical, Physical and Engineering Sciences"},{"key":"11372_CR82","doi-asserted-by":"crossref","unstructured":"Fredrikson, M., Jha, S., & Ristenpart, T. (2015). Model inversion attacks that exploit confidence information and basic countermeasures. In Proceedings of the 22nd ACM SIGSAC conference on computer and communications security (pp. 1322\u20131333).","DOI":"10.1145\/2810103.2813677"},{"issue":"2","key":"11372_CR83","doi-asserted-by":"publisher","first-page":"1055","DOI":"10.1109\/TNSE.2020.3014385","volume":"8","author":"Y Wang","year":"2020","unstructured":"Wang, Y., Su, Z., Zhang, N., & Benslimane, A. (2020). Learning in the air: Secure federated learning for UAV-assisted crowdsensing. IEEE Transactions on Network Science and Engineering, 8(2), 1055\u20131069.","journal-title":"IEEE Transactions on Network Science and Engineering"},{"key":"11372_CR84","doi-asserted-by":"crossref","unstructured":"Fereidooni, H., Marchal, S., Miettinen, M., Mirhoseini, A., M\u00f6llering, H., Nguyen, T. D., Rieger, P., Sadeghi, A., Schneider, T., & Yalame, H. (2021). Safelearn: Secure aggregation for private federated learning. In 2021 IEEE security and privacy workshops (SPW) (pp. 56\u201362).","DOI":"10.1109\/SPW53761.2021.00017"},{"key":"11372_CR85","doi-asserted-by":"crossref","unstructured":"Ching, C. W., Lin, T. C., Chang, K. H., Yao, C. C., & Kuo, J. J. (2020). Model partition defense against GAN attacks on collaborative learning via mobile edge computing. In Globecom 2020-2020 IEEE global communications conference (pp. 1\u20136).","DOI":"10.1109\/GLOBECOM42002.2020.9322591"},{"key":"11372_CR86","doi-asserted-by":"crossref","unstructured":"Lu, L., & Ding, N. (2020). Multi-party private set intersection in vertical federated learning. In 2020 IEEE 19th international conference on trust, security and privacy in computing and communications (trustcom) (pp. 707\u2013714).","DOI":"10.1109\/TrustCom50675.2020.00098"},{"key":"11372_CR87","unstructured":"Bhagoji, A. N., Chakraborty, S., Mittal, P., & Calo, S. (2019). Analyzing federated learning through an adversarial lens. In International conference on machine learning (pp. 634\u2013643)."},{"key":"11372_CR88","unstructured":"Ma, X., Li, B., Wang, Y., Erfani, S. M., Wijewickrema, S., Schoenebeck, G., Schoenebeck, G., Song, D., Houle, M. E., & Bailey, J. (2018). Characterizing adversarial subspaces using local intrinsic dimensionality. arXiv preprint arXiv:1801.02613."},{"key":"11372_CR89","doi-asserted-by":"crossref","unstructured":"Ross, A., & Doshi-Velez, F. (2018). Improving the adversarial robustness and interpretability of deep neural networks by regularizing their input gradients. In Proceedings of the AAAI conference on artificial intelligence (Vol. 32).","DOI":"10.1609\/aaai.v32i1.11504"},{"key":"11372_CR90","doi-asserted-by":"crossref","unstructured":"Zantedeschi, V., Nicolae, M. I., & Rawat, A. (2017). Efficient defenses against adversarial attacks. In Proceedings of the 10th ACM workshop on artificial intelligence and security (pp. 39-49).","DOI":"10.1145\/3128572.3140449"},{"key":"11372_CR91","doi-asserted-by":"crossref","unstructured":"Papernot, N., McDaniel, P., Wu, X., Jha, S., & Swami, A. (2016). Distillation as a defense to adversarial perturbations against deep neural networks. In 2016 IEEE symposium on security and privacy (SP) (pp. 582\u2013597).","DOI":"10.1109\/SP.2016.41"},{"key":"11372_CR92","doi-asserted-by":"crossref","unstructured":"Dwork, C., & Roth, A. (2014). The algorithmic foundations of differential privacy. Foundations and Trends\u00ae in Theoretical Computer Science, 9(3\u20134), 211\u2013407.","DOI":"10.1561\/0400000042"},{"issue":"3","key":"11372_CR93","doi-asserted-by":"publisher","first-page":"2134","DOI":"10.1109\/TII.2019.2942179","volume":"16","author":"Y Lu","year":"2019","unstructured":"Lu, Y., Huang, X., Dai, Y., Maharjan, S., & Zhang, Y. (2019). Differentially private asynchronous federated learning for mobile edge computing in urban informatics. IEEE Transactions on Industrial Informatics, 16(3), 2134\u20132143.","journal-title":"IEEE Transactions on Industrial Informatics"},{"issue":"4","key":"11372_CR94","doi-asserted-by":"publisher","first-page":"94","DOI":"10.3390\/fi13040094","volume":"13","author":"H Fang","year":"2021","unstructured":"Fang, H., & Qian, Q. (2021). Privacy preserving machine learning with homomorphic encryption and federated learning. Future Internet, 13(4), 94.","journal-title":"Future Internet"},{"key":"11372_CR95","unstructured":"Zhang, C., Li, S., Xia, J., Wang, W., Yan, F., & Liu, Y. (2020). $$\\{$$BatchCrypt$$\\}$$: Efficient homomorphic encryption for $$\\{$$Cross-Silo$$\\}$$ federated learning. In 2020 usenix annual technical conference (usenix atc 20) (pp. 493\u2013506)."},{"issue":"7","key":"11372_CR96","first-page":"1830","volume":"29","author":"Z Li","year":"2018","unstructured":"Li, Z., Gui, X., Gu, Y., Li, X. S., Dai, H. J., & Zhang, X. J. (2018). Survey on homomorphic encryption algorithm and its application in the privacy-preserving for cloud computing. Journal of Software, 29(7), 1830\u20131851.","journal-title":"Journal of Software"},{"key":"11372_CR97","unstructured":"Jayaraman, B., Wang, L., Evans, D., & Gu, Q. (2018). Distributed learning without distress: Privacy-preserving empirical risk minimization. Advances in Neural Information Processing Systems, 31."},{"issue":"7","key":"11372_CR98","first-page":"2127","volume":"31","author":"T Zuowen","year":"2020","unstructured":"Zuowen, T., & Lianfu, Z. (2020). Survey on privacy preserving techniques for machine learning. Journal of Software, 31(7), 2127\u201321.","journal-title":"Journal of Software"},{"key":"11372_CR99","doi-asserted-by":"crossref","unstructured":"Truex, S., Baracaldo, N., Anwar, A., Steinke, T., Ludwig, H., Zhang, R., & Zhou, Y. (2019). A hybrid approach to privacy-preserving federated learning. In Proceedings of the 12th ACM workshop on artificial intelligence and security (pp. 1\u201311).","DOI":"10.1145\/3338501.3357370"},{"key":"11372_CR100","doi-asserted-by":"crossref","unstructured":"Bonawitz, K., Ivanov, V., Kreuter, B., Marcedone, A., McMahan, H. B., Patel, S., Ramage, D., Segal, A., & Seth, K. (2017). Practical secure aggregation for privacy-preserving machine learning. In proceedings of the 2017 ACM SIGSAC conference on computer and communications security (pp. 1175\u20131191).","DOI":"10.1145\/3133956.3133982"},{"key":"11372_CR101","doi-asserted-by":"publisher","first-page":"198275","DOI":"10.1109\/ACCESS.2020.3034602","volume":"8","author":"H Zhu","year":"2020","unstructured":"Zhu, H., Goh, R. S. M., & Ng, W. K. (2020). Privacy-preserving weighted federated learning within the secret sharing framework. IEEE Access, 8, 198275\u2013198284.","journal-title":"IEEE Access"},{"key":"11372_CR102","unstructured":"Hardy, S., Henecka, W., Ivey-Law, H., Nock, R., Patrini, G., Smith, G., & Thorne, B. (2017). Private federated learning on vertically partitioned data via entity resolution and additively homomorphic encryption. arXiv preprint arXiv:1711.10677."},{"issue":"6","key":"11372_CR103","doi-asserted-by":"publisher","first-page":"1279","DOI":"10.1109\/LCOMM.2019.2921755","volume":"24","author":"H Kim","year":"2019","unstructured":"Kim, H., Park, J., Bennis, M., & Kim, S. L. (2019). Blockchained on-device federated learning. IEEE Communications Letters, 24(6), 1279\u20131283.","journal-title":"IEEE Communications Letters"},{"key":"11372_CR104","doi-asserted-by":"crossref","unstructured":"Lu, Y., Huang, X., Zhang, K., Maharjan, S., & Zhang, Y. (2020). Low-latency federated learning and blockchain for edge association in digital twin empowered 6g networks. IEEE Transactions on Industrial Informatics, 17(7),","DOI":"10.1109\/TII.2020.3017668"},{"issue":"6","key":"11372_CR105","doi-asserted-by":"publisher","first-page":"5171","DOI":"10.1109\/JIOT.2020.2977383","volume":"7","author":"Y Qu","year":"2020","unstructured":"Qu, Y., Gao, L., Luan, T. H., Xiang, Y., Yu, S., Li, B., & Zheng, G. (2020). Decentralized privacy using blockchain-enabled federated learning in fog computing. IEEE Internet of Things Journal, 7(6), 5171\u20135183.","journal-title":"IEEE Internet of Things Journal"},{"issue":"9","key":"11372_CR106","doi-asserted-by":"publisher","first-page":"6092","DOI":"10.1109\/TII.2020.2974555","volume":"16","author":"PCM Arachchige","year":"2020","unstructured":"Arachchige, P. C. M., Bertok, P., Khalil, I., Liu, D., Camtepe, S., & Atiquzzaman, M. (2020). A trustworthy privacy preserving framework for machine learning in industrial iot systems. IEEE Transactions on Industrial Informatics, 16(9), 6092\u20136102.","journal-title":"IEEE Transactions on Industrial Informatics"},{"issue":"16","key":"11372_CR107","doi-asserted-by":"publisher","first-page":"12806","DOI":"10.1109\/JIOT.2021.3072611","volume":"8","author":"DC Nguyen","year":"2021","unstructured":"Nguyen, D. C., Ding, M., Pham, Q. V., Pathirana, P. N., Le, L. B., Seneviratne, A., Li, J., Niyato, D., & Poor, H. V. (2021). Federated learning meets blockchain in edge computing: Opportunities and challenges. IEEE Internet of Things Journal, 8(16), 12806\u201312825.","journal-title":"IEEE Internet of Things Journal"}],"container-title":["Wireless Personal Communications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11277-024-11372-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11277-024-11372-0\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11277-024-11372-0.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,9]],"date-time":"2024-07-09T13:16:48Z","timestamp":1720531008000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11277-024-11372-0"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6]]},"references-count":107,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2024,6]]}},"alternative-id":["11372"],"URL":"https:\/\/doi.org\/10.1007\/s11277-024-11372-0","relation":{},"ISSN":["0929-6212","1572-834X"],"issn-type":[{"value":"0929-6212","type":"print"},{"value":"1572-834X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,6]]},"assertion":[{"value":"8 June 2024","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"25 June 2024","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors have no Conflict of interest to declare that are relevant to the content of this article.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conficts of interest"}}]}}