{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,4]],"date-time":"2026-03-04T09:14:52Z","timestamp":1772615692757,"version":"3.50.1"},"reference-count":51,"publisher":"Oxford University Press (OUP)","issue":"11","license":[{"start":{"date-parts":[[2022,10,1]],"date-time":"2022-10-01T00:00:00Z","timestamp":1664582400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/academic.oup.com\/journals\/pages\/open_access\/funder_policies\/chorus\/standard_publication_model"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key R&D Program of China","doi-asserted-by":"publisher","award":["2020YFB2103802"],"award-info":[{"award-number":["2020YFB2103802"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U21A20463"],"award-info":[{"award-number":["U21A20463"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities of China","doi-asserted-by":"publisher","award":["KKJB32000153"],"award-info":[{"award-number":["KKJB32000153"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022,11,11]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Centralized machine learning methods require the aggregation of data collected from clients. Due to the awareness of data privacy, however, the aggregation of raw data collected by Internet of Things (IoT) devices is not feasible in many scenarios. Federated learning (FL), a kind of distributed learning framework, can be running on multiple IoT devices. It aims to resolve the issues of privacy leakage by training a model locally on the client-side, other than on the server-side that aggregates all the raw data. However, there are still threats of poisoning attacks in FL. Label flipping attacks, typical data poisoning attacks in FL, aim to poison the global model by sending model updates trained by the data with mismatched labels. The central parameter aggregation server is hard to detect the label flipping attacks due to its inaccessibility to the client in a typical FL system. In this work, we are motivated to prevent label flipping poisoning attacks by observing the changes in model parameters that were trained by different single labels. We propose a novel detection method called average weight of each class in its associated fully connected layer. In this method, we detect label flipping attacks by identifying the differences of classes in the data based on the weight assignments in a fully connected layer of the neural network model and use the statistical algorithm to recognize the malicious clients. We conduct extensive experiments on benchmark data like Fashion-MNIST and Intrusion Detection Evaluation Dataset (CIC-IDS2017). Comprehensive experimental results demonstrated that our method has the detection accuracy over 90% for the identification of the attackers flipping labels.<\/jats:p>","DOI":"10.1093\/comjnl\/bxac124","type":"journal-article","created":{"date-parts":[[2022,10,3]],"date-time":"2022-10-03T09:28:28Z","timestamp":1664789308000},"page":"2849-2859","source":"Crossref","is-referenced-by-count":14,"title":["AWFC: Preventing Label Flipping Attacks Towards Federated Learning for Intelligent IoT"],"prefix":"10.1093","volume":"65","author":[{"given":"Zhuo","family":"Lv","sequence":"first","affiliation":[{"name":"State Grid Henan Electric Power Research Institute , Zhengzhou 450052, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hongbo","family":"Cao","sequence":"additional","affiliation":[{"name":"Beijing Key Laboratory of Security and Privacy in Intelligent Transportation , Beijing Jiaotong University, No.3 Shangyuancun, Haidian, Beijing 100044, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Feng","family":"Zhang","sequence":"additional","affiliation":[{"name":"Zhejiang Key Laboratory of Multi-dimensional Perception Technology , Application and Cybersecurity, Hangzhou 310053, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuange","family":"Ren","sequence":"additional","affiliation":[{"name":"Beijing Key Laboratory of Security and Privacy in Intelligent Transportation , Beijing Jiaotong University, No.3 Shangyuancun, Haidian, Beijing 100044, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Bin","family":"Wang","sequence":"additional","affiliation":[{"name":"Zhejiang Key Laboratory of Multi-dimensional Perception Technology , Application and Cybersecurity, Hangzhou 310053, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Cen","family":"Chen","sequence":"additional","affiliation":[{"name":"State Grid Henan Electric Power Research Institute , Zhengzhou 450052, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Nuannuan","family":"Li","sequence":"additional","affiliation":[{"name":"State Grid Henan Electric Power Research Institute , Zhengzhou 450052, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hao","family":"Chang","sequence":"additional","affiliation":[{"name":"State Grid Henan Electric Power Research Institute , Zhengzhou 450052, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wei","family":"Wang","sequence":"additional","affiliation":[{"name":"Beijing Key Laboratory of Security and Privacy in Intelligent Transportation , Beijing Jiaotong University, No.3 Shangyuancun, Haidian, Beijing 100044, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"286","published-online":{"date-parts":[[2022,10,1]]},"reference":[{"key":"2022111713012972200_ref1","doi-asserted-by":"crossref","DOI":"10.3390\/en11113089","article-title":"Multi-step short-term power consumption forecasting with a hybrid deep learning strategy","volume":"11","author":"Yan","year":"2018","journal-title":"Energies"},{"key":"2022111713012972200_ref2","doi-asserted-by":"crossref","first-page":"2860","DOI":"10.1109\/TIP.2019.2891888","article-title":"Deep representation learning with part loss for person re-identification","volume":"28","author":"Yao","year":"2019","journal-title":"IEEE Trans. Image Process."},{"key":"2022111713012972200_ref3","doi-asserted-by":"crossref","first-page":"2129","DOI":"10.1007\/s11277-018-5930-z","article-title":"Visual speech recognition using optical flow and hidden Markov model","volume":"106","author":"Sharma","year":"2019","journal-title":"Wirel. Pers. Commun."},{"key":"2022111713012972200_ref4","doi-asserted-by":"crossref","first-page":"6153","DOI":"10.1109\/TII.2020.3039500","article-title":"Personalized APIs recommendation with cognitive knowledge mining for industrial systems","volume":"17","author":"Yin","year":"2021","journal-title":"IEEE Trans. Ind. Informatics"},{"key":"2022111713012972200_ref5","first-page":"1","article-title":"Hgate: heterogeneous graph attention auto-encoders","author":"Wang","year":"2021","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"2022111713012972200_ref6","doi-asserted-by":"crossref","first-page":"3035","DOI":"10.1007\/s12652-018-0803-6","article-title":"Effective android malware detection with a hybrid model based on deep autoencoder and convolutional neural network","volume":"10","author":"Wang","year":"2019","journal-title":"J. Ambient Intell. Humaniz. Comput."},{"key":"2022111713012972200_ref7","doi-asserted-by":"crossref","first-page":"1701","DOI":"10.1109\/CVPR.2014.220","volume-title":"2014 IEEE Conference on Computer Vision and Pattern Recognition, CVPR 2014","author":"Taigman","year":"2014"},{"key":"2022111713012972200_ref8","doi-asserted-by":"crossref","first-page":"82","DOI":"10.1109\/TBIOM.2019.2908436","article-title":"A fast and accurate system for face detection, identification, and verification","volume":"1","author":"Ranjan","year":"2019","journal-title":"IEEE Trans. Biom. Behav. Identity Sci."},{"key":"2022111713012972200_ref9","doi-asserted-by":"crossref","first-page":"1310","DOI":"10.1145\/2810103.2813687","volume-title":"Proceedings of the 22nd ACM SIGSAC Conference on Computer and Communications Security","author":"Shokri","year":"2015"},{"key":"2022111713012972200_ref10","doi-asserted-by":"crossref","first-page":"2272","DOI":"10.1007\/s11036-021-01846-x","article-title":"SDTIOA: modeling the timed privacy requirements of iot service composition: A user interaction perspective for automatic transformation from BPEL to timed automata","volume":"26","author":"Gao","year":"2021","journal-title":"Mob. Netw. Appl."},{"key":"2022111713012972200_ref11","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/TITS.2021.3098355","article-title":"A hybrid approach to trust node assessment and management for vanets cooperative data communication: historical interaction perspective","author":"Gao","year":"2021","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"2022111713012972200_ref12","doi-asserted-by":"crossref","first-page":"1184","DOI":"10.1109\/TMC.2019.2903186","article-title":"Privacy risk analysis and mitigation of analytics libraries in the android ecosystem","volume":"19","author":"Liu","year":"2020","journal-title":"IEEE Trans. Mob. Comput."},{"key":"2022111713012972200_ref13","doi-asserted-by":"crossref","first-page":"2204","DOI":"10.1109\/TITS.2017.2777990","article-title":"Creditcoin: a privacy-preserving blockchain-based incentive announcement network for communications of smart vehicles","volume":"19","author":"Li","year":"2018","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"2022111713012972200_ref14","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1561\/2200000083","article-title":"Advances and open problems in federated learning","volume":"14","author":"Ka","year":"2021","journal-title":"Found. Trends Mach. Learn."},{"key":"2022111713012972200_ref15","doi-asserted-by":"crossref","first-page":"12:1","DOI":"10.1145\/3298981","article-title":"Federated machine learning: Concept and applications","volume":"10","author":"Yang","year":"2019","journal-title":"ACM Trans. Intell. Syst. Technol."},{"key":"2022111713012972200_ref16","article-title":"Privacy and robustness in federated learning: attacks and defenses","volume":"abs\/2012.06337","author":"Lyu","year":"2020","journal-title":"CoRR"},{"key":"2022111713012972200_ref17","doi-asserted-by":"crossref","first-page":"4002","DOI":"10.1109\/TNSM.2021.3125395","article-title":"Real-time multiple-workflow scheduling in cloud environments","volume":"18","author":"Ma","year":"2021","journal-title":"IEEE Trans. Netw. Serv. Manag."},{"key":"2022111713012972200_ref18","first-page":"1273","volume-title":"Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, AISTATS 2017","author":"McMahan","year":"2017"},{"key":"2022111713012972200_ref19","article-title":"Federated optimization: Distributed optimization beyond the datacenter","volume":"abs\/1511.03575","author":"Kone\u010dn\u00fd","year":"2015","journal-title":"CoRR"},{"key":"2022111713012972200_ref20","doi-asserted-by":"crossref","first-page":"4","DOI":"10.1186\/s42400-021-00105-6","article-title":"Threats, attacks and defenses to federated learning: issues, taxonomy and perspectives","volume":"5","author":"Liu","year":"2022","journal-title":"Cybersecur."},{"key":"2022111713012972200_ref21","first-page":"634","volume-title":"Proceedings of the 36th International Conference on Machine Learning, ICML 2019","author":"Bhagoji","year":"2019"},{"key":"2022111713012972200_ref22","first-page":"8632","volume-title":"Advances in Neural Information Processing Systems 32: Annual Conference on Neural Information Processing Systems 2019, NeurIPS 2019","author":"Baruch","year":"2019"},{"key":"2022111713012972200_ref23","doi-asserted-by":"crossref","first-page":"670","DOI":"10.1109\/TGCN.2021.3067374","article-title":"SSUR: an approach to optimizing virtual machine allocation strategy based on user requirements for cloud data center","volume":"5","author":"Huang","year":"2021","journal-title":"IEEE Trans. Green Commun. Netw."},{"key":"2022111713012972200_ref24","volume-title":"Proceedings of the 29th International Conference on Machine Learning, ICML 2012","author":"Biggio","year":"2012"},{"key":"2022111713012972200_ref25","volume-title":"8th International Conference on Learning Representations, ICLR 2020","author":"Xie","year":"2020"},{"key":"2022111713012972200_ref26","volume-title":"Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020","author":"Wang","year":"2020"},{"key":"2022111713012972200_ref27","article-title":"Mitigating sybils in federated learning poisoning","volume":"abs\/1808.04866","author":"Fung","year":"2018","journal-title":"CoRR"},{"key":"2022111713012972200_ref28","doi-asserted-by":"crossref","first-page":"436","DOI":"10.1038\/nature14539","article-title":"Deep learning","volume":"521","author":"LeCun","year":"2015","journal-title":"Nature"},{"key":"2022111713012972200_ref29","doi-asserted-by":"crossref","first-page":"308","DOI":"10.1145\/2976749.2978318","volume-title":"Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security","author":"Abadi","year":"2016"},{"key":"2022111713012972200_ref30","doi-asserted-by":"crossref","first-page":"619","DOI":"10.1016\/j.future.2020.10.007","article-title":"A survey on security and privacy of federated learning","volume":"115","author":"Mothukuri","year":"2021","journal-title":"Fut. Gener. Comput. Syst."},{"key":"2022111713012972200_ref31","doi-asserted-by":"crossref","first-page":"87","DOI":"10.1109\/MIS.2021.3082561","article-title":"Secureboost: a lossless federated learning framework","volume":"36","author":"Cheng","year":"2021","journal-title":"IEEE Intell. Syst."},{"key":"2022111713012972200_ref32","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1109\/MIS.2020.2988525","article-title":"A secure federated transfer learning framework","volume":"35","author":"Liu","year":"2020","journal-title":"IEEE Intell. Syst."},{"key":"2022111713012972200_ref33","doi-asserted-by":"crossref","first-page":"1622","DOI":"10.1109\/COMST.2021.3075439","article-title":"Federated learning for internet of things: A comprehensive survey","volume":"23","author":"Nguyen","year":"2021","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"2022111713012972200_ref34","doi-asserted-by":"crossref","first-page":"103","DOI":"10.1016\/j.knosys.2014.06.018","article-title":"Autonomic intrusion detection: adaptively detecting anomalies over unlabeled audit data streams in computer networks","volume":"70","author":"Wang","year":"2014","journal-title":"Knowl. Based Syst."},{"key":"2022111713012972200_ref35","doi-asserted-by":"crossref","first-page":"555","DOI":"10.1109\/TITS.2020.3018259","article-title":"Detecting anomalies in intelligent vehicle charging and station power supply systems with multi-head attention models","volume":"22","author":"Li","year":"2021","journal-title":"IEEE Trans. Intell. Transp. Syst."},{"key":"2022111713012972200_ref36","doi-asserted-by":"crossref","first-page":"284","DOI":"10.1016\/j.ins.2019.09.024","article-title":"Botmark: automated botnet detection with hybrid analysis of flow-based and graph-based traffic behaviors","volume":"511","author":"Wang","year":"2020","journal-title":"Inform. Sci."},{"key":"2022111713012972200_ref37","doi-asserted-by":"crossref","first-page":"1869","DOI":"10.1109\/TIFS.2014.2353996","article-title":"Exploring permission-induced risk in android applications for malicious application detection","volume":"9","author":"Wang","year":"2014","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"2022111713012972200_ref38","doi-asserted-by":"crossref","first-page":"1772","DOI":"10.1109\/TIFS.2017.2687880","article-title":"DAPASA: detecting android piggybacked apps through sensitive subgraph analysis","volume":"12","author":"Fan","year":"2017","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"2022111713012972200_ref39","doi-asserted-by":"crossref","first-page":"987","DOI":"10.1016\/j.future.2017.01.019","article-title":"Detecting android malicious apps and categorizing benign apps with ensemble of classifiers","volume":"78","author":"Wang","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"2022111713012972200_ref40","doi-asserted-by":"crossref","first-page":"30","DOI":"10.1016\/j.future.2017.04.041","article-title":"Characterizing android apps\u2019 behavior for effective detection of malapps at large scale","volume":"75","author":"Wang","year":"2017","journal-title":"Future Gener. Comput. Syst."},{"key":"2022111713012972200_ref41","doi-asserted-by":"crossref","first-page":"1133","DOI":"10.1109\/TNSE.2020.2968505","article-title":"Contractward: automated vulnerability detection models for Ethereum smart contracts","volume":"8","author":"Wang","year":"2021","journal-title":"IEEE Trans. Netw. Sci. Eng."},{"key":"2022111713012972200_ref42","first-page":"1605","volume-title":"29th USENIX Security Symposium, USENIX Security 2020","author":"Fang","year":"2020"},{"key":"2022111713012972200_ref43","doi-asserted-by":"crossref","first-page":"508","DOI":"10.1145\/2991079.2991125","volume-title":"Proceedings of the 32nd Annual Conference on Computer Security Applications, ACSAC 2016","author":"Shen","year":"2016"},{"key":"2022111713012972200_ref44","doi-asserted-by":"crossref","first-page":"96","DOI":"10.1145\/3219617.3219655","volume-title":"Abstracts of the 2018 ACM International Conference on Measurement and Modeling of Computer Systems, SIGMETRICS 2018","author":"Chen","year":"2018"},{"key":"2022111713012972200_ref45","first-page":"119","volume-title":"Advances in Neural Information Processing Systems 30: Annual Conference on Neural Information Processing Systems 2017","author":"Blanchard","year":"2017"},{"key":"2022111713012972200_ref46","article-title":"Attack-resistant federated learning with residual-based reweighting","volume":"abs\/1912.11464","author":"Fu","year":"2019","journal-title":"CoRR"},{"key":"2022111713012972200_ref47","first-page":"2938","volume-title":"The 23rd International Conference on Artificial Intelligence and Statistics, AISTATS 2020","author":"Bagdasaryan","year":"2020"},{"key":"2022111713012972200_ref48","article-title":"Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms","volume":"abs\/1708.07747","author":"Xiao","year":"2017","journal-title":"CoRR"},{"key":"2022111713012972200_ref49","first-page":"108","volume-title":"Proceedings of the 4th International Conference on Information Systems Security and Privacy, ICISSP 2018","author":"Sharafaldin","year":"2018"},{"key":"2022111713012972200_ref50","article-title":"Evolving deep neural networks","volume":"abs\/1703.00548","author":"Miikkulainen","year":"2017","journal-title":"CoRR"},{"key":"2022111713012972200_ref51","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1016\/j.comcom.2007.10.010","article-title":"Processing of massive audit data streams for real-time anomaly intrusion detection","volume":"31","author":"Wang","year":"2008","journal-title":"Comput. Commun."}],"container-title":["The Computer Journal"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/65\/11\/2849\/47089052\/bxac124.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/academic.oup.com\/comjnl\/article-pdf\/65\/11\/2849\/47089052\/bxac124.pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,2,15]],"date-time":"2023-02-15T20:22:08Z","timestamp":1676492528000},"score":1,"resource":{"primary":{"URL":"https:\/\/academic.oup.com\/comjnl\/article\/65\/11\/2849\/6741165"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,10,1]]},"references-count":51,"journal-issue":{"issue":"11","published-online":{"date-parts":[[2022,10,1]]},"published-print":{"date-parts":[[2022,11,11]]}},"URL":"https:\/\/doi.org\/10.1093\/comjnl\/bxac124","relation":{},"ISSN":["0010-4620","1460-2067"],"issn-type":[{"value":"0010-4620","type":"print"},{"value":"1460-2067","type":"electronic"}],"subject":[],"published-other":{"date-parts":[[2022,11]]},"published":{"date-parts":[[2022,10,1]]}}}