{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,8]],"date-time":"2026-03-08T01:39:26Z","timestamp":1772933966585,"version":"3.50.1"},"reference-count":36,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,12,8]],"date-time":"2025-12-08T00:00:00Z","timestamp":1765152000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,12,8]],"date-time":"2025-12-08T00:00:00Z","timestamp":1765152000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,12,8]]},"DOI":"10.1109\/bigdata66926.2025.11402518","type":"proceedings-article","created":{"date-parts":[[2026,3,6]],"date-time":"2026-03-06T20:57:57Z","timestamp":1772830677000},"page":"3491-3500","source":"Crossref","is-referenced-by-count":0,"title":["NeuroScope: Trigger-Induced Activation Analysis for Backdoor Detection in Federated Learning"],"prefix":"10.1109","author":[{"given":"Kang","family":"Yang","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Nanjing University of Science and Technology,Nanjing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Chungen","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Mathematics and Statistics, Nanjing University of Science and Technology,Nanjing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lei","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Mathematics and Statistics, Nanjing University of Science and Technology,Nanjing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Pan","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Nanjing University of Science and Technology,Nanjing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Rui","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Nanjing University of Science and Technology,Nanjing,China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Artificial intelligence and statistics","author":"McMahan","year":"2017"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2024.3475578"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-60548-3_18"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1038\/s41598-020-69250-1"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23153"},{"key":"ref6","first-page":"1605","article-title":"Local model poisoning attacks to {Byzantine-Robust} federated learning","volume-title":"29th USENIX security symposium (USENIX Security 20)","author":"Fang","year":"2020"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011544"},{"key":"ref8","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"International conference on artificial intelligence and statistics","author":"Bagdasaryan","year":"2020"},{"key":"ref9","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume":"33","author":"Wang","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.14722\/diss.2020.23003"},{"key":"ref11","article-title":"A survey of secure computation using trusted execution environments","author":"Li","year":"2023","journal-title":"arXiv preprint"},{"key":"ref12","article-title":"Software grand exposure: \\{SGX\\} cache attacks are practical","author":"Brasser","year":"2017","journal-title":"11th USENIX workshop on offensive technologies (WOOT 17)"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS51616.2021.00086"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i8.16849"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23054"},{"key":"ref16","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"International conference on machine learning","author":"Yin","year":"2018"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-51399-2_7"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-51399-2_6"},{"key":"ref19","first-page":"301","article-title":"The limitations of federated learning in sybil settings","volume-title":"23rd International symposium on research in attacks, intrusions and defenses (RAID 2020)","author":"Fung","year":"2020"},{"key":"ref20","article-title":"Byzantine-robust federated machine learning through adaptive model averaging","author":"Mu\u00f1oz-Gonz\u00e1lez","year":"2019","journal-title":"arXiv preprint"},{"key":"ref21","first-page":"1415","article-title":"\\{FLAME\\}: Taming backdoors in federated learning","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Nguyen","year":"2022"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179362"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23156"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.2986205"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23233"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/1644893.1644895"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"ref28","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv preprint"},{"key":"ref29","article-title":"Intel sgx explained","author":"Costan","year":"2016","journal-title":"Cryptology ePrint Archive"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3291047"},{"key":"ref31","first-page":"12","article-title":"Amd memory encryption","volume":"13","author":"Kaplan","year":"2016","journal-title":"White paper"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359809"},{"key":"ref33","volume-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref34","article-title":"Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017","journal-title":"arXiv preprint"},{"key":"ref35","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume":"30","author":"Blanchard","year":"2017","journal-title":"Advances in neural information processing systems"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2022.3153135"}],"event":{"name":"2025 IEEE International Conference on Big Data (BigData)","location":"Macau, China","start":{"date-parts":[[2025,12,8]]},"end":{"date-parts":[[2025,12,11]]}},"container-title":["2025 IEEE International Conference on Big Data (BigData)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11400704\/11400712\/11402518.pdf?arnumber=11402518","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,7]],"date-time":"2026-03-07T06:56:26Z","timestamp":1772866586000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11402518\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12,8]]},"references-count":36,"URL":"https:\/\/doi.org\/10.1109\/bigdata66926.2025.11402518","relation":{},"subject":[],"published":{"date-parts":[[2025,12,8]]}}}