{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T20:11:46Z","timestamp":1778271106668,"version":"3.51.4"},"reference-count":47,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,8,1]],"date-time":"2026-08-01T00:00:00Z","timestamp":1785542400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100003213","name":"Beijing Municipal Education Commission","doi-asserted-by":"publisher","award":["KM202311232013"],"award-info":[{"award-number":["KM202311232013"]}],"id":[{"id":"10.13039\/501100003213","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100015247","name":"State Grid Shandong Electric Power Company","doi-asserted-by":"publisher","award":["52062625000F"],"award-info":[{"award-number":["52062625000F"]}],"id":[{"id":"10.13039\/501100015247","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2022YFB2701501"],"award-info":[{"award-number":["2022YFB2701501"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2022YFB2701503"],"award-info":[{"award-number":["2022YFB2701503"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Information Sciences"],"published-print":{"date-parts":[[2026,8]]},"DOI":"10.1016\/j.ins.2026.123436","type":"journal-article","created":{"date-parts":[[2026,3,31]],"date-time":"2026-03-31T06:43:39Z","timestamp":1774939419000},"page":"123436","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["A semantic-aware GNN malicious node detection framework via training-bias timing-sequence modeling over centralized federated learning"],"prefix":"10.1016","volume":"746","author":[{"given":"Chen","family":"Liang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mingtao","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Thar","family":"Baker","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lu","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yu-an","family":"Tan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuanzhang","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lu","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hongyi","family":"Liu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.ins.2026.123436_bib0005","series-title":"Artificial Intelligence and Statistics","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","author":"McMahan","year":"2017"},{"issue":"6","key":"10.1016\/j.ins.2026.123436_bib0010","doi-asserted-by":"crossref","DOI":"10.1016\/j.ipm.2022.103061","article-title":"Federated Learning Review: fundamentals, enabling technologies, and future applications","volume":"59","author":"Banabilah","year":"2022","journal-title":"Inf. Process. Manag."},{"key":"10.1016\/j.ins.2026.123436_bib0015","doi-asserted-by":"crossref","DOI":"10.1016\/j.engappai.2024.108128","article-title":"A comprehensive review on federated Learning for data-sensitive application: open issues & challenges","volume":"133","author":"Narula","year":"2024","journal-title":"Eng. Appl. Artif. Intell."},{"issue":"2","key":"10.1016\/j.ins.2026.123436_bib0020","doi-asserted-by":"crossref","DOI":"10.1016\/j.ipm.2022.103162","article-title":"Seeing is believing: towards interactive visual exploration of data privacy in federated learning","volume":"60","author":"Guo","year":"2023","journal-title":"Inf. Process. Manag."},{"key":"10.1016\/j.ins.2026.123436_bib0025","author":"Lyu"},{"key":"10.1016\/j.ins.2026.123436_bib0030","first-page":"1","article-title":"A study on the efficiency of combined reconstruction and poisoning attacks in federated Learning","volume":"00","author":"Becker","year":"2025","journal-title":"J. Data Sci. Intell. Syst."},{"key":"10.1016\/j.ins.2026.123436_bib0035","doi-asserted-by":"crossref","first-page":"18","DOI":"10.1016\/j.future.2024.01.009","article-title":"Benchmarking robustness and privacy-preserving methods in federated learning","volume":"155","author":"Alebouyeh","year":"2024","journal-title":"Futur. Gener. Comput. Syst."},{"key":"10.1016\/j.ins.2026.123436_bib0040","series-title":"Federated Learning: Privacy and Incentive","first-page":"153","article-title":"A principled approach to data valuation for federated learning","author":"Wang","year":"2020"},{"key":"10.1016\/j.ins.2026.123436_bib0045","first-page":"30","article-title":"Inductive representation learning on large graphs","author":"Hamilton","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"issue":"12","key":"10.1016\/j.ins.2026.123436_bib0050","doi-asserted-by":"crossref","first-page":"10","DOI":"10.55248\/gengpi.5.1224.3512","article-title":"Federated Learning and data privacy: a review of challenges and opportunities","volume":"5","author":"Myakala","year":"2024","journal-title":"Int. J. Res. Publ. Rev."},{"key":"10.1016\/j.ins.2026.123436_bib0055","author":"Lyu"},{"key":"10.1016\/j.ins.2026.123436_bib0060","series-title":"International Conference on Artificial Intelligence and Statistics","first-page":"2938","article-title":"How to backdoor federated learning","author":"Bagdasaryan","year":"2020"},{"key":"10.1016\/j.ins.2026.123436_bib0065","series-title":"2024 11th International Symposium on Telecommunications (IST)","first-page":"470","article-title":"Federated learning: attacks, defenses, opportunities and challenges","author":"Shirvani","year":"2024"},{"key":"10.1016\/j.ins.2026.123436_bib0070","author":"Jahan"},{"issue":"13","key":"10.1016\/j.ins.2026.123436_bib0075","doi-asserted-by":"crossref","first-page":"2512:1","DOI":"10.3390\/electronics14132512","article-title":"A review on federated learning architectures for Privacy-Preserving AI: lightweight and secure cloud\u2013edge\u2013end collaboration","volume":"14","author":"Zhan","year":"2025","journal-title":"Electronics"},{"key":"10.1016\/j.ins.2026.123436_bib0080","author":"Mammen"},{"issue":"2","key":"10.1016\/j.ins.2026.123436_bib0085","doi-asserted-by":"crossref","first-page":"165:1","DOI":"10.1007\/s40747-024-01664-0","article-title":"A survey of security threats in federated learning","volume":"11","author":"Feng","year":"2025","journal-title":"Complex Intell. Syst."},{"key":"10.1016\/j.ins.2026.123436_bib0090","author":"Madry"},{"key":"10.1016\/j.ins.2026.123436_bib0095","series-title":"International Conference on Machine Learning","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","author":"Bhagoji","year":"2019"},{"key":"10.1016\/j.ins.2026.123436_bib0100","series-title":"Proceedings of the Thirtieth International Joint Conference on Artificial Intelligence","first-page":"3125","article-title":"Demiguise attack: crafting invisible semantic adversarial perturbations with perceptual similarity","author":"Wang","year":"2021"},{"key":"10.1016\/j.ins.2026.123436_bib0105","series-title":"ICASSP 2020-2020 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","first-page":"3747","article-title":"WITCHcraft: efficient PGD attacks with random step size","author":"Chiang","year":"2020"},{"key":"10.1016\/j.ins.2026.123436_bib0110","author":"Vo"},{"issue":"3","key":"10.1016\/j.ins.2026.123436_bib0115","doi-asserted-by":"crossref","first-page":"1789","DOI":"10.1109\/TDSC.2022.3164073","article-title":"Stealthy and flexible trojan in deep learning framework","volume":"20","author":"Wang","year":"2022","journal-title":"IEEE Trans. Dependable Secure Comput."},{"issue":"2","key":"10.1016\/j.ins.2026.123436_bib0120","doi-asserted-by":"crossref","first-page":"1357","DOI":"10.1109\/TNSE.2025.3528831","article-title":"Label-Flipping attacks in GNN-based federated learning","volume":"12","author":"Yu","year":"2025","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"10.1016\/j.ins.2026.123436_bib0125","author":"Lin"},{"key":"10.1016\/j.ins.2026.123436_bib0130","first-page":"37","article-title":"Data poisoning attacks on federated machine learning","author":"Reddy","year":"2024","journal-title":"Reinf. Plast."},{"issue":"1","key":"10.1016\/j.ins.2026.123436_bib0135","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s10994-021-06119-y","article-title":"Stronger data poisoning attacks break data sanitization defenses","volume":"111","author":"Koh","year":"2022","journal-title":"Mach. Learn."},{"key":"10.1016\/j.ins.2026.123436_bib0140","series-title":"European Symposium on Research in Computer Security","first-page":"480","article-title":"Data poisoning attacks against federated learning systems","author":"Tolpegin","year":"2020"},{"issue":"3","key":"10.1016\/j.ins.2026.123436_bib0145","doi-asserted-by":"crossref","first-page":"73:1","DOI":"10.3390\/fi13030073","article-title":"Deep model poisoning attack on federated learning","volume":"13","author":"Zhou","year":"2021","journal-title":"Future Internet"},{"key":"10.1016\/j.ins.2026.123436_bib0150","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2024.103936","article-title":"Fedimp: parameter importance-based model poisoning attack against federated learning system","volume":"144","author":"Li","year":"2024","journal-title":"Comput. Secur."},{"issue":"1","key":"10.1016\/j.ins.2026.123436_bib0155","doi-asserted-by":"crossref","first-page":"116","DOI":"10.1109\/TNNLS.2024.3394252","article-title":"Leverage variational graph representation for model poisoning on federated learning","volume":"36","author":"Li","year":"2024","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"10.1016\/j.ins.2026.123436_bib0160","series-title":"2022 IEEE 38th International Conference on Data Engineering (ICDE)","first-page":"2643","article-title":"Fedrecattack: model poisoning attack to federated recommendation","author":"Rong","year":"2022"},{"key":"10.1016\/j.ins.2026.123436_bib0165","series-title":"Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition","first-page":"3396","article-title":"Mpaf: model poisoning attacks to federated learning based on fake nodes","author":"Cao","year":"2022"},{"key":"10.1016\/j.ins.2026.123436_bib0170","first-page":"1","article-title":"Enhanced model poisoning attack and multi-strategy defense in federated learning","author":"Yang","year":"2025","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"1","key":"10.1016\/j.ins.2026.123436_bib0175","doi-asserted-by":"crossref","first-page":"16:1","DOI":"10.1007\/s43926-025-00108-6","article-title":"Securing Federated Learning: a defense strategy against targeted data poisoning attack","volume":"5","author":"Khraisat","year":"2025","journal-title":"Discov. Internet Things"},{"key":"10.1016\/j.ins.2026.123436_bib0180","doi-asserted-by":"crossref","first-page":"346","DOI":"10.1016\/j.comcom.2022.09.012","article-title":"Federated learning for intrusion detection system: concepts, challenges and future directions","volume":"195","author":"Agrawal","year":"2022","journal-title":"Comput. Commun."},{"issue":"6","key":"10.1016\/j.ins.2026.123436_bib0185","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1007\/s10462-024-10796-1","article-title":"Anomaly detection and defense techniques in federated Learning: a comprehensive review","volume":"57","author":"Zhang","year":"2024","journal-title":"Artif. Intell. Rev."},{"key":"10.1016\/j.ins.2026.123436_bib0190","first-page":"1","article-title":"FADngs: federated learning for anomaly detection","author":"Dong","year":"2024","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"10.1016\/j.ins.2026.123436_bib0195","doi-asserted-by":"crossref","DOI":"10.1016\/j.infsof.2023.107371","article-title":"Vulnerability detection based on federated learning","volume":"167","author":"Zhang","year":"2024","journal-title":"Inf. Softw. Technol."},{"issue":"8","key":"10.1016\/j.ins.2026.123436_bib0200","doi-asserted-by":"crossref","first-page":"4292","DOI":"10.3390\/app15084292","article-title":"Optimizing activation function for parameter reduction in CNNs on CIFAR-10 and CINIC-10","volume":"15","author":"Vasilev","year":"2025","journal-title":"Appl. Sci."},{"key":"10.1016\/j.ins.2026.123436_bib0205","series-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"issue":"10","key":"10.1016\/j.ins.2026.123436_bib0210","doi-asserted-by":"crossref","first-page":"803","DOI":"10.17485\/IJST\/v18i10.121","article-title":"A comparative study of optimization techniques in deep learning using the MNIST dataset","volume":"18","author":"Selvakumari","year":"2025","journal-title":"Indian J. Sci. Technol."},{"key":"10.1016\/j.ins.2026.123436_bib0215","series-title":"NIPS Workshop Deep Learn.Unsupervised Feature Learn","article-title":"Reading digits in natural images with unsupervised feature learning.in proc","author":"Netzer","year":"2011"},{"key":"10.1016\/j.ins.2026.123436_bib0220","series-title":"Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining","first-page":"2545","article-title":"Fldetector: defending federated learning against model poisoning attacks via detecting malicious nodes","author":"Zhang","year":"2022"},{"key":"10.1016\/j.ins.2026.123436_bib0225","doi-asserted-by":"crossref","first-page":"1142","DOI":"10.1109\/TSP.2022.3153135","article-title":"Robust aggregation for federated learning","volume":"70","author":"Pillutla","year":"2022","journal-title":"IEEE Trans. Signal Process."},{"key":"10.1016\/j.ins.2026.123436_bib0230","first-page":"30","article-title":"Machine learning with adversaries: byzantine tolerant gradient descent","author":"Blanchard","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"issue":"6","key":"10.1016\/j.ins.2026.123436_bib0235","doi-asserted-by":"crossref","first-page":"5259","DOI":"10.1109\/TDSC.2024.3372634","article-title":"FedDMC: efficient and robust federated learning via detecting malicious nodes","volume":"21","author":"Mu","year":"2024","journal-title":"IEEE Trans. Dependable Secure Comput."}],"container-title":["Information Sciences"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0020025526003671?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0020025526003671?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,8]],"date-time":"2026-05-08T19:11:37Z","timestamp":1778267497000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0020025526003671"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,8]]},"references-count":47,"alternative-id":["S0020025526003671"],"URL":"https:\/\/doi.org\/10.1016\/j.ins.2026.123436","relation":{},"ISSN":["0020-0255"],"issn-type":[{"value":"0020-0255","type":"print"}],"subject":[],"published":{"date-parts":[[2026,8]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"A semantic-aware GNN malicious node detection framework via training-bias timing-sequence modeling over centralized federated learning","name":"articletitle","label":"Article Title"},{"value":"Information Sciences","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.ins.2026.123436","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Inc. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"123436"}}