{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,20]],"date-time":"2026-05-20T17:14:26Z","timestamp":1779297266865,"version":"3.51.4"},"reference-count":58,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-017"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-012"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,11,1]],"date-time":"2026-11-01T00:00:00Z","timestamp":1793491200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-004"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Neural Networks"],"published-print":{"date-parts":[[2026,11]]},"DOI":"10.1016\/j.neunet.2026.109095","type":"journal-article","created":{"date-parts":[[2026,5,12]],"date-time":"2026-05-12T06:37:17Z","timestamp":1778567837000},"page":"109095","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["DDFL: dual defense against poisoning attacks in privacy-preserving federated learning"],"prefix":"10.1016","volume":"203","author":[{"given":"Cheng","family":"Guo","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-6535-7138","authenticated-orcid":false,"given":"Moyan","family":"Tian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xueguang","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-9083-6612","authenticated-orcid":false,"given":"Hui","family":"Sun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yingmo","family":"Jie","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.neunet.2026.109095_bib0001","series-title":"Proceedings of the 39th international conference on machine learning","first-page":"162,10","article-title":"Sharp-maml: Sharpness-aware model-agnostic meta learning","author":"Abbas","year":"2022"},{"key":"10.1016\/j.neunet.2026.109095_bib0002","doi-asserted-by":"crossref","DOI":"10.1016\/j.neunet.2024.106768","article-title":"Membershield: A framework for federated learning with membership privacy","volume":"181","author":"Ahmed","year":"2025","journal-title":"Neural Networks"},{"key":"10.1016\/j.neunet.2026.109095_bib0003","doi-asserted-by":"crossref","DOI":"10.1016\/j.neunet.2024.106688","article-title":"Addressing unreliable local models in federated learning through unlearning","volume":"180","author":"Ameen","year":"2024","journal-title":"Neural Networks"},{"key":"10.1016\/j.neunet.2026.109095_bib0004","series-title":"Advances in neural information processing systems","article-title":"A little is enough: Circumventing defenses for distributed learning","volume":"vol. 32","author":"Baruch","year":"2019"},{"key":"10.1016\/j.neunet.2026.109095_bib0005","series-title":"Advances in neural information processing systems","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume":"vol. 30","author":"Blanchard","year":"2017"},{"key":"10.1016\/j.neunet.2026.109095_bib0006","series-title":"NDSS","article-title":"FLTrust: Byzantine-robust federated learning via trust bootstrapping","author":"Cao","year":"2021"},{"key":"10.1016\/j.neunet.2026.109095_bib0007","series-title":"Proceedings of the AAI conference on artificial intelligence","first-page":"6885","article-title":"Provably secure federated learning against malicious clients","author":"Cao","year":"2021"},{"key":"10.1016\/j.neunet.2026.109095_bib0008","series-title":"Proceedings of the 39th international conference on machine learning","first-page":"2890","article-title":"Revisiting label smoothing and knowledge distillation compatibility: What was missing?","volume":"162","author":"Chandrasegaran","year":"2022"},{"key":"10.1016\/j.neunet.2026.109095_bib0009","doi-asserted-by":"crossref","first-page":"5749","DOI":"10.1109\/TIFS.2023.3315125","article-title":"APFed: Anti-poisoning attacks in privacy-preserving heterogeneous federated learning","volume":"18","author":"Chen","year":"2023","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.neunet.2026.109095_bib0010","series-title":"29th usenix security symposium (USENIX security 20)","first-page":"1605","article-title":"Local model poisoning attacks to byzantine-robust federated learning","author":"Fang","year":"2020"},{"key":"10.1016\/j.neunet.2026.109095_bib0011","series-title":"Proceedings of the 34th international conference on machine learning","first-page":"1126","article-title":"Model-agnostic meta-learning for fast adaptation of deep networks","volume":"70","author":"Finn","year":"2017"},{"key":"10.1016\/j.neunet.2026.109095_bib0012","unstructured":"Fu, S., Xie, C., Li, B., & Chen, Q. (2021). Attack-resistant federated learning with residual-based reweighting. https:\/\/arxiv.org\/abs\/1912.11464."},{"key":"10.1016\/j.neunet.2026.109095_bib0013","series-title":"23rd international symposium on research in attacks, intrusions and defenses (raid 2020)","first-page":"301","article-title":"The limitations of federated learning in sybil settings","author":"Fund","year":"2020"},{"key":"10.1016\/j.neunet.2026.109095_bib0014","series-title":"Advances in Neural Information Processing Systems","first-page":"16937","article-title":"Inverting gradients - how easy is it to break privacy in federated learning?","volume":"33","author":"Geiping","year":"2020"},{"issue":"5","key":"10.1016\/j.neunet.2026.109095_bib0015","doi-asserted-by":"crossref","first-page":"4843","DOI":"10.1109\/TDSC.2024.3362534","article-title":"Siren+: Robust federated learning with proactive alarming and differential privacy","volume":"21","author":"Guo","year":"2024","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"10.1016\/j.neunet.2026.109095_bib0016","series-title":"IEEE\/CVF International conference on computer vision (ICCV)","first-page":"4999","article-title":"Towards attack-tolerant federated learning via critical parameter analysis","author":"Han","year":"2023"},{"key":"10.1016\/j.neunet.2026.109095_bib0017","doi-asserted-by":"crossref","DOI":"10.1016\/j.neunet.2024.106574","article-title":"Subgraph-level federated graph neural network for privacy-preserving recommendation with meta-learning","volume":"179","author":"Han","year":"2024","journal-title":"Neural Networks"},{"key":"10.1016\/j.neunet.2026.109095_bib0018","series-title":"2016 IEEE conference on computer vision and pattern recognition (CVPR)","first-page":"770","article-title":"Deep residual learning for image recognition","author":"He","year":"2016"},{"key":"10.1016\/j.neunet.2026.109095_bib0019","unstructured":"Hinton, G., Vinyals, O., & Dean, J. (2015). Distilling the knowledge in a neural network. https:\/\/arxiv.org\/abs\/1503.02531."},{"key":"10.1016\/j.neunet.2026.109095_bib0020","series-title":"Proceedings of the 2017 ACM sigsac conference on computer and communications security","first-page":"603","article-title":"Deep models under the gan: Information leakage from collaborative deep learning","author":"Hitaj","year":"2017"},{"issue":"9","key":"10.1016\/j.neunet.2026.109095_bib0021","first-page":"5149","article-title":"Meta-learning in neural networks: A survey","volume":"44","author":"Hospedales","year":"2022","journal-title":"IEEE Transactions on Pattern Analysis and Machine Intelligence"},{"issue":"5","key":"10.1016\/j.neunet.2026.109095_bib0022","doi-asserted-by":"crossref","first-page":"6703","DOI":"10.1109\/TNNLS.2022.3212627","article-title":"Enhanced security and privacy via fragmented federated learning","volume":"35","author":"Jebreel","year":"2024","journal-title":"IEEE Transactions on Neural Networks and Learning Systems"},{"key":"10.1016\/j.neunet.2026.109095_bib0023","doi-asserted-by":"crossref","first-page":"111","DOI":"10.1016\/j.neunet.2023.11.019","article-title":"Lfighter: Defending against the label-flipping attack in federated learning","volume":"170","author":"Jebreel","year":"2024","journal-title":"Neural Networks"},{"key":"10.1016\/j.neunet.2026.109095_bib0024","series-title":"Proceedings of the 38th international conference on machine learning","first-page":"139,5311","article-title":"Learning from history for byzantine robust optimization","author":"Karimireddy","year":"2021"},{"issue":"4","key":"10.1016\/j.neunet.2026.109095_bib0025","article-title":"Learning multiple layers of features from tiny images","volume":"1","author":"Krizhevsky","year":"2009","journal-title":"Handbook of Systemic Autoimmune Diseases"},{"key":"10.1016\/j.neunet.2026.109095_bib0026","doi-asserted-by":"crossref","unstructured":"Lepinski, M., & Kent, S. (2008). Additional diffie-hellman groups for use with ietf standards. RFC 5114.","DOI":"10.17487\/rfc5114"},{"key":"10.1016\/j.neunet.2026.109095_bib0027","series-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition (CVPR)","article-title":"Learning to learn from noisy labeled data","author":"Li","year":"2019"},{"key":"10.1016\/j.neunet.2026.109095_bib0028","doi-asserted-by":"crossref","first-page":"4358","DOI":"10.1109\/TIFS.2024.3378006","article-title":"Efficiently achieving privacy preservation and poisoning attack resistance in federated learning","volume":"19","author":"Li","year":"2024","journal-title":"IEEE Transactions on Information Forensics and Security"},{"issue":"1","key":"10.1016\/j.neunet.2026.109095_bib0029","doi-asserted-by":"crossref","first-page":"27","DOI":"10.1109\/TDSC.2016.2536601","article-title":"Efficient and privacy-preserving outsourced calculation of rational numbers","volume":"15","author":"Liu","year":"2018","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"10.1016\/j.neunet.2026.109095_bib0030","doi-asserted-by":"crossref","first-page":"4574","DOI":"10.1109\/TIFS.2021.3108434","article-title":"Privacy-enhanced federated learning against poisoning adversaries","volume":"16","author":"Liu","year":"2021","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.neunet.2026.109095_bib0031","series-title":"Threats to federated learning","first-page":"3","author":"Lyu","year":"2020"},{"issue":"12","key":"10.1016\/j.neunet.2026.109095_bib0032","doi-asserted-by":"crossref","first-page":"3690","DOI":"10.1109\/TPDS.2022.3167434","article-title":"Differentially private byzantine-robust federated learning","volume":"33","author":"Ma","year":"2022","journal-title":"IEEE Transactions on Parallel and Distributed Systems"},{"key":"10.1016\/j.neunet.2026.109095_bib0033","doi-asserted-by":"crossref","first-page":"1639","DOI":"10.1109\/TIFS.2022.3169918","article-title":"ShieldFL: Mitigating model poisoning attacks in privacy-preserving federated learning","volume":"17","author":"Ma","year":"2022","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.neunet.2026.109095_bib0034","series-title":"Proceedings of the 20th international conference on artificial intelligence and statistics","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","author":"McMahan","year":"2017"},{"key":"10.1016\/j.neunet.2026.109095_bib0035","series-title":"2019 IEEE symposium on security and privacy (sp)","first-page":"691","article-title":"Exploiting unintended feature leakage in collaborative learning","author":"Melis","year":"2019"},{"key":"10.1016\/j.neunet.2026.109095_bib0036","doi-asserted-by":"crossref","first-page":"2848","DOI":"10.1109\/TIFS.2022.3196274","article-title":"Privacy-preserving byzantine-robust federated learning via blockchain systems","volume":"17","author":"Miao","year":"2022","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.neunet.2026.109095_bib0037","doi-asserted-by":"crossref","first-page":"5814","DOI":"10.1109\/TIFS.2024.3402113","article-title":"RFed: Robustness-Enhanced privacy-preserving federated learning against poisoning attack","volume":"19","author":"Miao","year":"2024","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.neunet.2026.109095_bib0038","series-title":"NIPS Workshop on Deep Learning and Unsupervised Feature Learning","first-page":"4","article-title":"Reading digits in natural images with unsupervised feature learning","author":"Netzer","year":"2011"},{"key":"10.1016\/j.neunet.2026.109095_bib0039","series-title":"Proceedings of the 29th ACM SIGKDD conference on knowledge discovery and data mining","first-page":"1850","article-title":"Feddefender: Client-side attack-tolerant federated learning","author":"Park","year":"2023"},{"key":"10.1016\/j.neunet.2026.109095_bib0040","article-title":"FedART: A neural model integrating federated learning and adaptive resonance theory","volume":"108","author":"Pateria","year":"2025","journal-title":"Neural Networks"},{"issue":"7","key":"10.1016\/j.neunet.2026.109095_bib0041","doi-asserted-by":"crossref","first-page":"2168","DOI":"10.1109\/JSAC.2020.3041404","article-title":"Byzantine-resilient secure federated learning","volume":"39","author":"So","year":"2021","journal-title":"IEEE Journal on Selected Areas in Communications"},{"key":"10.1016\/j.neunet.2026.109095_bib0042","series-title":"NDSS","article-title":"Manipulating the byzantine: Optimizing model poisoning attacks and defenses for federated learning","author":"Shejwalkar","year":"2021"},{"issue":"13","key":"10.1016\/j.neunet.2026.109095_bib0043","doi-asserted-by":"crossref","first-page":"11365","DOI":"10.1109\/JIOT.2021.3128646","article-title":"Data poisoning attacks on federated machine learning","volume":"9","author":"Sun","year":"2022","journal-title":"IEEE Internet of Things Journal"},{"key":"10.1016\/j.neunet.2026.109095_bib0044","series-title":"Advances in Neural Information Processing Systems","first-page":"12613","article-title":"FL-WBC: Enhancing robustness against model poisoning attacks in federated learning from a client perspective","volume":"34","author":"Sun","year":"2021"},{"key":"10.1016\/j.neunet.2026.109095_bib0045","unstructured":"Sun, Z., Kairouz, P., Suresh, A., & McMahan, H. (2019). Can you really backdoor federated learning?https:\/\/arxiv.org\/abs\/1911.07963."},{"key":"10.1016\/j.neunet.2026.109095_bib0046","series-title":"Proceedings of the 12th ACM workshop on artificial intelligence and security","first-page":"1","article-title":"A hybrid approach to privacy-preserving federated learning","author":"Truex","year":"2019"},{"key":"10.1016\/j.neunet.2026.109095_bib0047","doi-asserted-by":"crossref","first-page":"569","DOI":"10.1016\/j.neunet.2023.10.006","article-title":"Divide-and-conquer the nas puzzle in resource-constrained federated learning systems","volume":"168","author":"Venkatesha","year":"2023","journal-title":"Neural Networks"},{"key":"10.1016\/j.neunet.2026.109095_bib0048","series-title":"International conference on learning representations","article-title":"Dba: Distributed backdoor attacks against federated learning","author":"Xie","year":"2020"},{"key":"10.1016\/j.neunet.2026.109095_bib0049","unstructured":"Xie, C., Koyejo, O., & Gupta, I. (2018). Generalized byzantine-tolerant sgd. https:\/\/arxiv.org\/abs\/1802.10116."},{"key":"10.1016\/j.neunet.2026.109095_bib0050","doi-asserted-by":"crossref","first-page":"911","DOI":"10.1109\/TIFS.2019.2929409","article-title":"Verifynet: Secure and verifiable federated learning","volume":"15","author":"Xu","year":"2020","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.neunet.2026.109095_bib0051","series-title":"Proceedings of the 35th international conference on machine learning","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume":"vol. 80","author":"Yin","year":"2018"},{"key":"10.1016\/j.neunet.2026.109095_bib0052","doi-asserted-by":"crossref","DOI":"10.1016\/j.neunet.2024.106436","article-title":"Self-balancing incremental broad learning system with privacy protection","volume":"178","author":"Zhang","year":"2024","journal-title":"Neural Networks"},{"key":"10.1016\/j.neunet.2026.109095_bib0053","doi-asserted-by":"crossref","first-page":"365","DOI":"10.1109\/TIFS.2022.3221899","article-title":"LSFL: A lightweight and secure federated learning scheme for edge computing","volume":"18","author":"Zhang","year":"2023","journal-title":"IEEE Transactions on Information Forensics and Security"},{"issue":"5","key":"10.1016\/j.neunet.2026.109095_bib0054","doi-asserted-by":"crossref","first-page":"3329","DOI":"10.1109\/TDSC.2021.3093711","article-title":"SEAR: Secure and efficient aggregation for byzantine-robust federated learning","volume":"19","author":"Zhao","year":"2022","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"10.1016\/j.neunet.2026.109095_bib0055","doi-asserted-by":"crossref","first-page":"2059","DOI":"10.1109\/TIFS.2022.3176191","article-title":"PVD-FL: A privacy-preserving and verifiable decentralized federated learning framework","volume":"17","author":"Zhao","year":"2022","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"10.1016\/j.neunet.2026.109095_bib0056","series-title":"2025 IEEE international conference on multimedia and expo (ICME)","first-page":"1","article-title":"A novel differential privacy federated learning framework: An adaptive budget allocation and reversion method","author":"Zhao","year":"2025"},{"key":"10.1016\/j.neunet.2026.109095_bib0057","series-title":"2025 IEEE international conference on multimedia and expo (ICME)","first-page":"1","article-title":"MIPP-FL: Personalized layer privacy protection federated learning based on mutual information","author":"Zhao","year":"2025"},{"key":"10.1016\/j.neunet.2026.109095_bib0058","series-title":"Advances in Neural Information Processing Systems","first-page":"14747","article-title":"Deep leakage from gradients","volume":"32","author":"Zhu","year":"2019"}],"container-title":["Neural Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0893608026005551?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0893608026005551?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,20]],"date-time":"2026-05-20T16:54:24Z","timestamp":1779296064000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0893608026005551"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,11]]},"references-count":58,"alternative-id":["S0893608026005551"],"URL":"https:\/\/doi.org\/10.1016\/j.neunet.2026.109095","relation":{},"ISSN":["0893-6080"],"issn-type":[{"value":"0893-6080","type":"print"}],"subject":[],"published":{"date-parts":[[2026,11]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"DDFL: dual defense against poisoning attacks in privacy-preserving federated learning","name":"articletitle","label":"Article Title"},{"value":"Neural Networks","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.neunet.2026.109095","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 Elsevier Ltd. All rights are reserved, including those for text and data mining, AI training, and similar technologies.","name":"copyright","label":"Copyright"}],"article-number":"109095"}}