{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T23:39:59Z","timestamp":1785973199949,"version":"3.56.0"},"reference-count":42,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100018537","name":"National Science and Technology Major Project","doi-asserted-by":"publisher","award":["2021ZD0201302"],"award-info":[{"award-number":["2021ZD0201302"]}],"id":[{"id":"10.13039\/501100018537","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Knowledge-Based Systems"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.knosys.2026.116476","type":"journal-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T20:28:09Z","timestamp":1782851289000},"page":"116476","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["FedTOF: Mitigating poisoning attacks in Federated Learning via tail orthogonal forgetting"],"prefix":"10.1016","volume":"350","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-7823-9726","authenticated-orcid":false,"given":"Cong","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yifan","family":"Cao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ziqiao","family":"Yin","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0540-3779","authenticated-orcid":false,"given":"Binghui","family":"Guo","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"78","reference":[{"key":"10.1016\/j.knosys.2026.116476_b1","series-title":"Artificial Intelligence and Statistics","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","author":"McMahan","year":"2017"},{"issue":"2","key":"10.1016\/j.knosys.2026.116476_b2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3298981","article-title":"Federated machine learning: Concept and applications","volume":"10","author":"Yang","year":"2019","journal-title":"ACM Trans. Intell. Syst. Technol. (TIST)"},{"issue":"1","key":"10.1016\/j.knosys.2026.116476_b3","doi-asserted-by":"crossref","first-page":"199","DOI":"10.1109\/JIOT.2021.3079916","article-title":"Consumer, commercial, and industrial iot (in) security: Attack taxonomy and case studies","volume":"9","author":"Xenofontos","year":"2021","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.knosys.2026.116476_b4","series-title":"2023 IEEE International Conference on Communications Workshops","first-page":"1253","article-title":"Poisoning attacks in federated edge learning for digital twin 6g-enabled iots: An anticipatory study","author":"Ferrag","year":"2023"},{"key":"10.1016\/j.knosys.2026.116476_b5","series-title":"2021 IEEE Wireless Communications and Networking Conference","first-page":"1","article-title":"Shielding federated learning: A new attack approach and its defense","author":"Wan","year":"2021"},{"key":"10.1016\/j.knosys.2026.116476_b6","series-title":"International Conference on Artificial Intelligence and Statistics","first-page":"2938","article-title":"How to backdoor federated learning","author":"Bagdasaryan","year":"2020"},{"key":"10.1016\/j.knosys.2026.116476_b7","series-title":"Computer Security\u2013ESORICS 2020: 25th European Symposium on Research in Computer Security, ESORICS 2020, Guildford, UK, September 14\u201318, 2020, Proceedings, Part I 25","first-page":"480","article-title":"Data poisoning attacks against federated learning systems","author":"Tolpegin","year":"2020"},{"key":"10.1016\/j.knosys.2026.116476_b8","series-title":"27th USENIX Security Symposium","first-page":"1299","article-title":"When does machine learning fail? generalized transferability for evasion and poisoning attacks","author":"Suciu","year":"2018"},{"issue":"2","key":"10.1016\/j.knosys.2026.116476_b9","doi-asserted-by":"crossref","first-page":"49","DOI":"10.1109\/MSEC.2018.2888775","article-title":"Privacy-preserving machine learning: Threats and solutions","volume":"17","author":"Al-Rubaie","year":"2019","journal-title":"IEEE Secur. Priv."},{"key":"10.1016\/j.knosys.2026.116476_b10","article-title":"A little is enough: Circumventing defenses for distributed learning","volume":"32","author":"Baruch","year":"2019","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.knosys.2026.116476_b11","series-title":"NDSS","article-title":"Manipulating the byzantine: Optimizing model poisoning attacks and defenses for federated learning","author":"Shejwalkar","year":"2021"},{"key":"10.1016\/j.knosys.2026.116476_b12","unstructured":"Minghong Fang, Xiaoyu Cao, Jinyuan Jia, Neil Gong, Local model poisoning attacks to byzantine-robust federated learning, in: 29th USENIX Security Symposium, USENIX Security 20, 2020, pp. 1605\u20131622."},{"key":"10.1016\/j.knosys.2026.116476_b13","series-title":"International Conference on Machine Learning","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","author":"Bhagoji","year":"2019"},{"key":"10.1016\/j.knosys.2026.116476_b14","series-title":"29th USENIX Security Symposium","first-page":"1605","article-title":"Local model poisoning attacks to {Byzantine-Robust} federated learning","author":"Fang","year":"2020"},{"key":"10.1016\/j.knosys.2026.116476_b15","article-title":"Machine learning with adversaries: byzantine tolerant gradient descent","volume":"30","author":"Blanchard","year":"2017","journal-title":"Adv. Neural Inf. Process. Syst."},{"key":"10.1016\/j.knosys.2026.116476_b16","doi-asserted-by":"crossref","unstructured":"Qi Xia, Zeyi Tao, Zijiang Hao, Qun Li, Faba: an algorithm for fast aggregation against byzantine attacks in distributed neural networks, in: IJCAI, 2019.","DOI":"10.24963\/ijcai.2019\/670"},{"key":"10.1016\/j.knosys.2026.116476_b17","series-title":"International Conference on Machine Learning","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in byzantium","author":"Guerraoui","year":"2018"},{"key":"10.1016\/j.knosys.2026.116476_b18","series-title":"International Conference on Machine Learning","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","author":"Yin","year":"2018"},{"issue":"11","key":"10.1016\/j.knosys.2026.116476_b19","doi-asserted-by":"crossref","first-page":"12935","DOI":"10.1109\/TII.2024.3431020","article-title":"Rfl-apia: A comprehensive framework for mitigating poisoning attacks and promoting model aggregation in iiot federated learning","volume":"20","author":"Li","year":"2024","journal-title":"IEEE Trans. Ind. Informatics"},{"key":"10.1016\/j.knosys.2026.116476_b20","series-title":"International Conference on Machine Learning","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","author":"Yin","year":"2018"},{"key":"10.1016\/j.knosys.2026.116476_b21","series-title":"Joint European Conference on Machine Learning and Knowledge Discovery in Databases","first-page":"213","article-title":"Slsgd: Secure and efficient distributed on-device machine learning","author":"Xie","year":"2019"},{"key":"10.1016\/j.knosys.2026.116476_b22","doi-asserted-by":"crossref","unstructured":"Mengyao Ma, Yanjun Zhang, Pathum Chamikara Mahawaga Arachchige, Leo Yu Zhang, Mohan Baruwal Chhetri, Guangdong Bai, Loden: Making every client in federated learning a defender against the poisoning membership inference attacks, in: Proceedings of the 2023 ACM Asia Conference on Computer and Communications Security, 2023, pp. 122\u2013135.","DOI":"10.1145\/3579856.3590334"},{"issue":"9","key":"10.1016\/j.knosys.2026.116476_b23","doi-asserted-by":"crossref","first-page":"16289","DOI":"10.1109\/JIOT.2024.3351371","article-title":"A robust and efficient federated learning algorithm against adaptive model poisoning attacks","volume":"11","author":"Yang","year":"2024","journal-title":"IEEE Internet Things J."},{"key":"10.1016\/j.knosys.2026.116476_b24","series-title":"Computer Security\u2013ESORICS 2020: 25th European Symposium on Research in Computer Security, ESORICS 2020, Guildford, UK, September 14\u201318, 2020, Proceedings, Part I 25","first-page":"480","article-title":"Data poisoning attacks against federated learning systems","author":"Tolpegin","year":"2020"},{"key":"10.1016\/j.knosys.2026.116476_b25","series-title":"Artificial Intelligence and Statistics","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","author":"McMahan","year":"2017"},{"issue":"12","key":"10.1016\/j.knosys.2026.116476_b26","doi-asserted-by":"crossref","DOI":"10.1007\/s11704-025-40924-1","article-title":"Enhancing poisoning attack mitigation in federated learning through perturbation-defense complementarity on history gradients","volume":"19","author":"Wang","year":"2025","journal-title":"Front. Comput. Sci."},{"key":"10.1016\/j.knosys.2026.116476_b27","series-title":"International Conference on Machine Learning","first-page":"6893","article-title":"Zeno: Distributed stochastic gradient descent with suspicion-based fault-tolerance","author":"Xie","year":"2019"},{"key":"10.1016\/j.knosys.2026.116476_b28","series-title":"Fltrust: byzantine-robust federated learning via trust bootstrapping","author":"Cao","year":"2020"},{"key":"10.1016\/j.knosys.2026.116476_b29","first-page":"3405","article-title":"A new ensemble adversarial attack powered by long-term gradient memories","volume":"vol. 34","author":"Che","year":"2020"},{"key":"10.1016\/j.knosys.2026.116476_b30","series-title":"Federated learning with non-iid data","author":"Zhao","year":"2018"},{"key":"10.1016\/j.knosys.2026.116476_b31","series-title":"International Conference on Machine Learning","first-page":"5132","article-title":"Scaffold: Stochastic controlled averaging for federated learning","author":"Karimireddy","year":"2020"},{"key":"10.1016\/j.knosys.2026.116476_b32","first-page":"8788","article-title":"Seizing critical learning periods in federated learning","volume":"vol. 36","author":"Yan","year":"2022"},{"key":"10.1016\/j.knosys.2026.116476_b33","series-title":"2021 17th International Conference on Mobility, Sensing and Networking","first-page":"167","article-title":"Desmp: Differential privacy-exploited stealthy model poisoning attacks in federated learning","author":"Hossain","year":"2021"},{"key":"10.1016\/j.knosys.2026.116476_b34","doi-asserted-by":"crossref","DOI":"10.1109\/TETC.2026.3661199","article-title":"Fairrfl: Fair and robust federated learning in the presence of selfish clients","author":"Augello","year":"2026","journal-title":"IEEE Trans. Emerg. Top. Comput."},{"key":"10.1016\/j.knosys.2026.116476_b35","series-title":"Poisoning attacks against support vector machines","author":"Biggio","year":"2012"},{"key":"10.1016\/j.knosys.2026.116476_b36","doi-asserted-by":"crossref","unstructured":"Liping Li, Wei Xu, Tianyi Chen, Georgios B. Giannakis, Qing Ling, Rsa: Byzantine-robust stochastic aggregation methods for distributed learning from heterogeneous datasets, in: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 33, 2019, pp. 1544\u20131551.","DOI":"10.1609\/aaai.v33i01.33011544"},{"key":"10.1016\/j.knosys.2026.116476_b37","doi-asserted-by":"crossref","unstructured":"Zhangming Chan, Juntao Li, Xiaopeng Yang, Xiuying Chen, Wenpeng Hu, Dongyan Zhao, Rui Yan, Modeling personalization in continuous space for response generation via augmented wasserstein autoencoders, in: Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing, Emnlp-Ijcnlp, 2019, pp. 1931\u20131940.","DOI":"10.18653\/v1\/D19-1201"},{"key":"10.1016\/j.knosys.2026.116476_b38","series-title":"2022 18th International Conference on Mobility, Sensing and Networking","first-page":"178","article-title":"Shielding federated learning: Mitigating byzantine attacks with less constraints","author":"Li","year":"2022"},{"key":"10.1016\/j.knosys.2026.116476_b39","series-title":"International Conference on Machine Learning","first-page":"5311","article-title":"Learning from history for byzantine robust optimization","author":"Karimireddy","year":"2021"},{"key":"10.1016\/j.knosys.2026.116476_b40","series-title":"Byzantine-resilient non-convex stochastic gradient descent","author":"Allen-Zhu","year":"2020"},{"key":"10.1016\/j.knosys.2026.116476_b41","doi-asserted-by":"crossref","unstructured":"Zaixi Zhang, Xiaoyu Cao, Jinyuan Jia, Neil Zhenqiang Gong, Fldetector: Defending federated learning against model poisoning attacks via detecting malicious clients, in: Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining, 2022, pp. 2545\u20132555.","DOI":"10.1145\/3534678.3539231"},{"key":"10.1016\/j.knosys.2026.116476_b42","doi-asserted-by":"crossref","DOI":"10.1016\/j.comnet.2025.111442","article-title":"Flcom: Robust federated learning against strong model poisoning attacks","volume":"269","author":"Li","year":"2025","journal-title":"Comput. Netw."}],"container-title":["Knowledge-Based Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0950705126012025?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0950705126012025?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,8,5]],"date-time":"2026-08-05T22:39:44Z","timestamp":1785969584000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0950705126012025"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":42,"alternative-id":["S0950705126012025"],"URL":"https:\/\/doi.org\/10.1016\/j.knosys.2026.116476","relation":{},"ISSN":["0950-7051"],"issn-type":[{"value":"0950-7051","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"FedTOF: Mitigating poisoning attacks in Federated Learning via tail orthogonal forgetting","name":"articletitle","label":"Article Title"},{"value":"Knowledge-Based Systems","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.knosys.2026.116476","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Published by Elsevier B.V.","name":"copyright","label":"Copyright"}],"article-number":"116476"}}