{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,10]],"date-time":"2026-06-10T08:37:16Z","timestamp":1781080636995,"version":"3.54.1"},"reference-count":53,"publisher":"Elsevier BV","issue":"1","license":[{"start":{"date-parts":[[2021,6,1]],"date-time":"2021-06-01T00:00:00Z","timestamp":1622505600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2021,6,1]],"date-time":"2021-06-01T00:00:00Z","timestamp":1622505600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2021,2,1]],"date-time":"2021-02-01T00:00:00Z","timestamp":1612137600000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["High-Confidence Computing"],"published-print":{"date-parts":[[2021,6]]},"DOI":"10.1016\/j.hcc.2021.100002","type":"journal-article","created":{"date-parts":[[2021,3,23]],"date-time":"2021-03-23T06:14:15Z","timestamp":1616480055000},"page":"100002","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":26,"title":["Towards multi-party targeted model poisoning attacks against federated learning systems"],"prefix":"10.1016","volume":"1","author":[{"given":"Zheyi","family":"Chen","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Pu","family":"Tian","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1444-8925","authenticated-orcid":false,"given":"Weixian","family":"Liao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wei","family":"Yu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.hcc.2021.100002_bib0001","series-title":"Thirtieth AAAI Conference on Artificial Intelligence","article-title":"Data poisoning attacks against autoregressive models","author":"Alfeld","year":"2016"},{"key":"10.1016\/j.hcc.2021.100002_bib0002","series-title":"Advances in Neural Information Processing Systems","first-page":"4613","article-title":"Byzantine stochastic gradient descent","author":"Alistarh","year":"2018"},{"key":"10.1016\/j.hcc.2021.100002_bib0003","article-title":"How to backdoor federated learning","author":"Bagdasaryan","year":"2018","journal-title":"arXiv preprint arXiv:1807.00459"},{"issue":"2","key":"10.1016\/j.hcc.2021.100002_bib0004","doi-asserted-by":"crossref","first-page":"121","DOI":"10.1007\/s10994-010-5188-5","article-title":"The security of machine learning","volume":"81","author":"Barreno","year":"2010","journal-title":"Machine Learning"},{"key":"10.1016\/j.hcc.2021.100002_bib0005","series-title":"Advances in Neural Information Processing Systems","first-page":"8632","article-title":"A little is enough: Circumventing defenses for distributed learning","author":"Baruch","year":"2019"},{"key":"10.1016\/j.hcc.2021.100002_bib0006","series-title":"International Conference on Machine Learning","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","author":"Bhagoji","year":"2019"},{"key":"10.1016\/j.hcc.2021.100002_bib0007","series-title":"Proceedings of the 29th International Coference on International Conference on Machine Learning","first-page":"1467","article-title":"Poisoning attacks against support vector machines","author":"Biggio","year":"2012"},{"key":"10.1016\/j.hcc.2021.100002_bib0008","series-title":"Advances in Neural Information Processing Systems","first-page":"119","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","author":"Blanchard","year":"2017"},{"key":"10.1016\/j.hcc.2021.100002_bib0009","series-title":"2019 IEEE 39th International Conference on Distributed Computing Systems (ICDCS)","first-page":"144","article-title":"Trading private range counting over big iot data","author":"Cai","year":"2019"},{"key":"10.1016\/j.hcc.2021.100002_bib0010","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv preprint arXiv:1712.05526"},{"key":"10.1016\/j.hcc.2021.100002_bib0011","first-page":"1","article-title":"Zero knowledge clustering based adversarial mitigation in heterogeneous federated learning","author":"Chen","year":"2020","journal-title":"IEEE Transactions on Network Science and Engineering"},{"key":"10.1016\/j.hcc.2021.100002_bib0012","series-title":"Differential privacy-enabled federated learning for sensitive health data","author":"Choudhury","year":"2019"},{"key":"10.1016\/j.hcc.2021.100002_bib0013","article-title":"Adversarial attack on graph structured data","author":"Dai","year":"2018","journal-title":"arXiv preprint arXiv:1806.02371"},{"key":"10.1016\/j.hcc.2021.100002_bib0014","series-title":"Proceedings of the 35th International Conference on Machine Learning","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in Byzantium","volume":"80","author":"El Mhamdi","year":"2018"},{"key":"10.1016\/j.hcc.2021.100002_bib0015","series-title":"2018 IEEE Security and Privacy Workshops (SPW)","first-page":"50","article-title":"Black-box generation of adversarial text sequences to evade deep learning classifiers","author":"Gao","year":"2018"},{"key":"10.1016\/j.hcc.2021.100002_bib0016","series-title":"Advances in Neural Information Processing Systems","first-page":"10921","article-title":"Statistical analysis of nearest neighbor methods for anomaly detection","author":"Gu","year":"2019"},{"key":"10.1016\/j.hcc.2021.100002_bib0017","doi-asserted-by":"crossref","first-page":"24411","DOI":"10.1109\/ACCESS.2018.2830661","article-title":"A survey of deep learning: Platforms, applications and emerging research trends","volume":"6","author":"Hatcher","year":"2018","journal-title":"IEEE Access"},{"key":"10.1016\/j.hcc.2021.100002_bib0018","series-title":"2018 IEEE Symposium on Security and Privacy (SP)","first-page":"19","article-title":"Manipulating machine learning: Poisoning attacks and countermeasures for regression learning","author":"Jagielski","year":"2018"},{"key":"10.1016\/j.hcc.2021.100002_bib0019","series-title":"Proceedings of the 2017 Conference on Empirical Methods in Natural Language Processing","first-page":"2021","article-title":"Adversarial examples for evaluating reading comprehension systems","author":"Jia","year":"2017"},{"key":"10.1016\/j.hcc.2021.100002_bib0020","doi-asserted-by":"crossref","DOI":"10.1109\/TVT.2020.2977378","article-title":"Poisoning and evasion attacks against deep learning algorithms in autonomous vehicles","author":"Jiang","year":"2020","journal-title":"IEEE Transactions on Vehicular Technology"},{"key":"10.1016\/j.hcc.2021.100002_bib0021","series-title":"NIPS Workshop on Private Multi-Party Machine Learning","article-title":"Federated learning: Strategies for improving communication efficiency","author":"Konecny","year":"2016"},{"key":"10.1016\/j.hcc.2021.100002_bib0022","series-title":"Artificial Intelligence Safety and Security","first-page":"99","article-title":"Adversarial examples in the physical world","author":"Kurakin","year":"2018"},{"key":"10.1016\/j.hcc.2021.100002_bib0023","series-title":"The MNIST database of handwritten digits, 2009","author":"LeCun","year":"2009"},{"issue":"1","key":"10.1016\/j.hcc.2021.100002_bib0024","doi-asserted-by":"crossref","first-page":"96","DOI":"10.1109\/MNET.2018.1700202","article-title":"Learning iot in edge: Deep learning for the internet of things with edge computing","volume":"32","author":"Li","year":"2018","journal-title":"IEEE network"},{"key":"10.1016\/j.hcc.2021.100002_bib0025","doi-asserted-by":"crossref","first-page":"104673","DOI":"10.1109\/ACCESS.2019.2931659","article-title":"Search engine for the internet of things: Lessons from web search, vision, and opportunities","volume":"7","author":"Liang","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.hcc.2021.100002_bib0026","doi-asserted-by":"crossref","first-page":"15132","DOI":"10.1109\/ACCESS.2018.2806881","article-title":"A survey on big data market: Pricing, trading and protection","volume":"6","author":"Liang","year":"2018","journal-title":"IEEE Access"},{"issue":"9","key":"10.1016\/j.hcc.2021.100002_bib0027","doi-asserted-by":"crossref","first-page":"8738","DOI":"10.1109\/TVT.2018.2845744","article-title":"Data integrity attacks against dynamic route guidance in transportation-based cyber-physical systems: Modeling, analysis, and defense","volume":"67","author":"Lin","year":"2018","journal-title":"IEEE Transactions on Vehicular Technology"},{"issue":"5","key":"10.1016\/j.hcc.2021.100002_bib0028","doi-asserted-by":"crossref","first-page":"1125","DOI":"10.1109\/JIOT.2017.2683200","article-title":"A survey on internet of things: Architecture, enabling technologies, security and privacy, and applications","volume":"4","author":"Lin","year":"2017","journal-title":"IEEE Internet of Things Journal"},{"key":"10.1016\/j.hcc.2021.100002_bib0029","doi-asserted-by":"crossref","first-page":"79523","DOI":"10.1109\/ACCESS.2019.2920763","article-title":"Secure internet of things (iot)-based smart-world critical infrastructures: Survey, case study and research opportunities","volume":"7","author":"Liu","year":"2019","journal-title":"IEEE Access"},{"key":"10.1016\/j.hcc.2021.100002_bib0030","series-title":"Trojaning attack on neural networks","author":"Liu","year":"2018"},{"key":"10.1016\/j.hcc.2021.100002_bib0031","series-title":"Proceedings of the Twenty-Eighth International Joint Conference on Artificial Intelligence, IJCAI-19","first-page":"4732","article-title":"Data poisoning against differentially-private learners: Attacks and defenses","author":"Ma","year":"2019"},{"key":"10.1016\/j.hcc.2021.100002_bib0032","series-title":"Proceedings of the 20th International Conference on Artificial Intelligence and Statistics","first-page":"1273","article-title":"Communication-Efficient Learning of Deep Networks from Decentralized Data","volume":"54","author":"McMahan","year":"2017"},{"issue":"4","key":"10.1016\/j.hcc.2021.100002_bib0033","doi-asserted-by":"crossref","first-page":"2923","DOI":"10.1109\/COMST.2018.2844341","article-title":"Deep learning for iot big data and streaming analytics: A survey","volume":"20","author":"Mohammadi","year":"2018","journal-title":"IEEE Communications Surveys Tutorials"},{"key":"10.1016\/j.hcc.2021.100002_bib0034","series-title":"Proceedings of the 10th ACM Workshop on Artificial Intelligence and Security","first-page":"27","article-title":"Towards poisoning of deep learning algorithms with back-gradient optimization","author":"Mu\u00f1oz-Gonz\u00e1lez","year":"2017"},{"key":"10.1016\/j.hcc.2021.100002_bib0035","first-page":"1","article-title":"Realizing the heterogeneity: A self-organized federated learning framework for iot","author":"Pang","year":"2020","journal-title":"IEEE Internet of Things Journal"},{"key":"10.1016\/j.hcc.2021.100002_bib0036","series-title":"2016 IEEE European Symposium on Security and Privacy (EuroS&P)","first-page":"372","article-title":"The limitations of deep learning in adversarial settings","author":"Papernot","year":"2016"},{"issue":"1","key":"10.1016\/j.hcc.2021.100002_bib0037","first-page":"1929","article-title":"Dropout: a simple way to prevent neural networks from overfitting","volume":"15","author":"Srivastava","year":"2014","journal-title":"The journal of machine learning research"},{"key":"10.1016\/j.hcc.2021.100002_bib0038","article-title":"Federated variance-reduced stochastic gradient descent with robustness to byzantine attacks","author":"Wu","year":"2019","journal-title":"arXiv preprint arXiv:1912.12716"},{"key":"10.1016\/j.hcc.2021.100002_bib0039","series-title":"International Conference on Machine Learning","first-page":"1689","article-title":"Is feature selection secure against training data poisoning?","author":"Xiao","year":"2015"},{"key":"10.1016\/j.hcc.2021.100002_bib0040","article-title":"Zeno: Distributed stochastic gradient descent with suspicion-based fault-tolerance","author":"Xie","year":"2018","journal-title":"arXiv preprint arXiv:1805.10032"},{"key":"10.1016\/j.hcc.2021.100002_bib0041","series-title":"Zeno++: Robust fully asynchronous {sgd}","author":"Xie","year":"2020"},{"key":"10.1016\/j.hcc.2021.100002_bib0042","doi-asserted-by":"crossref","first-page":"78238","DOI":"10.1109\/ACCESS.2018.2884906","article-title":"A survey on industrial internet of things: A cyber-physical systems perspective","volume":"6","author":"Xu","year":"2018","journal-title":"IEEE Access"},{"key":"10.1016\/j.hcc.2021.100002_bib0043","series-title":"2020 IEEE Intl Conf on Dependable, Autonomic and Secure Computing, Intl Conf on Pervasive Intelligence and Computing, Intl Conf on Cloud and Big Data Computing, Intl Conf on Cyber Science and Technology Congress (DASC\/PiCom\/CBDCom\/CyberSciTech)","first-page":"21","article-title":"On data integrity attacks against industrial internet of things","author":"Xu","year":"2020"},{"issue":"9","key":"10.1016\/j.hcc.2021.100002_bib0044","doi-asserted-by":"crossref","first-page":"833","DOI":"10.1002\/sec.835","article-title":"On false data injection attacks against kalman filtering in power system dynamic state estimation","volume":"9","author":"Yang","year":"2016","journal-title":"Security and Communication Networks"},{"issue":"2","key":"10.1016\/j.hcc.2021.100002_bib0045","first-page":"12","article-title":"Federated machine learning: Concept and applications","volume":"10","author":"Yang","year":"2019","journal-title":"ACM Transactions on Intelligent Systems and Technology (TIST)"},{"issue":"3","key":"10.1016\/j.hcc.2021.100002_bib0046","doi-asserted-by":"crossref","first-page":"717","DOI":"10.1109\/TPDS.2013.92","article-title":"On false data-injection attacks against power system state estimation: Modeling and countermeasures","volume":"25","author":"Yang","year":"2014","journal-title":"IEEE Transactions on Parallel and Distributed Systems"},{"key":"10.1016\/j.hcc.2021.100002_bib0047","series-title":"International Conference on Machine Learning","first-page":"5636","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","author":"Yin","year":"2018"},{"key":"10.1016\/j.hcc.2021.100002_bib0048","article-title":"Defending against saddle point attack in byzantine-robust distributed learning","author":"Yin","year":"2018","journal-title":"arXiv preprint arXiv:1806.05358"},{"issue":"2","key":"10.1016\/j.hcc.2021.100002_bib0049","doi-asserted-by":"crossref","first-page":"91","DOI":"10.1002\/sec.957","article-title":"An integrated detection system against false data injection attacks in the smart grid","volume":"8","author":"Yu","year":"2015","journal-title":"Security and Communication Networks"},{"issue":"9","key":"10.1016\/j.hcc.2021.100002_bib0050","doi-asserted-by":"crossref","first-page":"2805","DOI":"10.1109\/TNNLS.2018.2886017","article-title":"Adversarial examples: Attacks and defenses for deep learning","volume":"30","author":"Yuan","year":"2019","journal-title":"IEEE transactions on neural networks and learning systems"},{"key":"10.1016\/j.hcc.2021.100002_bib0051","series-title":"Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition","first-page":"4302","article-title":"Adversarial attacks beyond the image space","author":"Zeng","year":"2019"},{"key":"10.1016\/j.hcc.2021.100002_bib0052","series-title":"International Conference on Algorithms and Architectures for Parallel Processing","first-page":"595","article-title":"Pdgan: A novel poisoning defense method in federated learning using generative adversarial network","author":"Zhao","year":"2019"},{"issue":"5","key":"10.1016\/j.hcc.2021.100002_bib0053","doi-asserted-by":"crossref","first-page":"968","DOI":"10.1109\/JSAC.2020.2980802","article-title":"Privacy-preserved data sharing towards multiple parties in industrial iots","volume":"38","author":"Zheng","year":"2020","journal-title":"IEEE Journal on Selected Areas in Communications"}],"container-title":["High-Confidence Computing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2667295221000039?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2667295221000039?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,9,9]],"date-time":"2025-09-09T08:38:09Z","timestamp":1757407089000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2667295221000039"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,6]]},"references-count":53,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,6]]}},"alternative-id":["S2667295221000039"],"URL":"https:\/\/doi.org\/10.1016\/j.hcc.2021.100002","relation":{},"ISSN":["2667-2952"],"issn-type":[{"value":"2667-2952","type":"print"}],"subject":[],"published":{"date-parts":[[2021,6]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Towards multi-party targeted model poisoning attacks against federated learning systems","name":"articletitle","label":"Article Title"},{"value":"High-Confidence Computing","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.hcc.2021.100002","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2021 The Author(s). Published by Elsevier B.V. on behalf of Shandong University","name":"copyright","label":"Copyright"}],"article-number":"100002"}}