{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,24]],"date-time":"2025-06-24T06:40:08Z","timestamp":1750747208095,"version":"3.41.0"},"reference-count":29,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,5,5]],"date-time":"2025-05-05T00:00:00Z","timestamp":1746403200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,5,5]],"date-time":"2025-05-05T00:00:00Z","timestamp":1746403200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,5,5]]},"DOI":"10.1109\/cscwd64889.2025.11033366","type":"proceedings-article","created":{"date-parts":[[2025,6,23]],"date-time":"2025-06-23T17:24:40Z","timestamp":1750699480000},"page":"1857-1862","source":"Crossref","is-referenced-by-count":0,"title":["A Physical Backdoor Attack Against Practical Federated Learning"],"prefix":"10.1109","author":[{"given":"Yang","family":"Li","sequence":"first","affiliation":[{"name":"Shenzhen Graduate School, Peking University,Guangdong Provincial Key Laboratory of Ultra High Definition Immersive Media Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiangtao","family":"Lu","sequence":"additional","affiliation":[{"name":"Shenzhen Graduate School, Peking University,Guangdong Provincial Key Laboratory of Ultra High Definition Immersive Media Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Guibo","family":"Luo","sequence":"additional","affiliation":[{"name":"Shenzhen Graduate School, Peking University,Guangdong Provincial Key Laboratory of Ultra High Definition Immersive Media Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yuesheng","family":"Zhu","sequence":"additional","affiliation":[{"name":"Shenzhen Graduate School, Peking University,Guangdong Provincial Key Laboratory of Ultra High Definition Immersive Media Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","author":"McMahan","year":"2017","journal-title":"Artificial intelligence and statistics"},{"key":"ref2","article-title":"Federated learning for mobile keyboard prediction","author":"Hard","year":"2018","journal-title":"arXiv preprint"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2021.3081560"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.21203\/rs.3.rs-1005694\/v1"},{"key":"ref5","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"International conference on artificial intelligence and statistics","author":"Bagdasaryan"},{"key":"ref6","article-title":"Dba: Distributed backdoor attacks against federated learning","volume-title":"International conference on learning representations","author":"Xie","year":"2019"},{"key":"ref7","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume":"33","author":"Wang","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref8","article-title":"Badnets: Identifying vulnera-bilities in the machine learning model supply chain","author":"Gu","year":"2017","journal-title":"arXiv preprint"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom53373.2021.00093"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1016\/j.engappai.2023.107166"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01299"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"ref14","article-title":"Ma-chine learning with adversaries: Byzantine tolerant gradient descent","volume":"30","author":"Blanchard","year":"2017","journal-title":"Advances in neural information processing systems"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.29007\/21r5"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2022.3153135"},{"key":"ref17","first-page":"301","article-title":"The limitations of federated learning in sybil settings","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020)","author":"Fung"},{"key":"ref18","first-page":"11372","article-title":"Crfl: Certifiably robust federated learning against backdoor attacks","volume-title":"International Conference on Machine Learning","author":"Xie"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00429"},{"key":"ref20","first-page":"429","article-title":"Federated optimization in heterogeneous networks","volume-title":"Proceedings of Machine learning and systems","volume":"2","author":"Li"},{"key":"ref21","first-page":"7611","article-title":"Tackling the ob-jective inconsistency problem in heterogeneous federated optimization","volume":"33","author":"Wang","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2211477"},{"volume-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref23"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref26","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014","journal-title":"arXiv preprint"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2017.243"},{"key":"ref28","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv preprint arXiv"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.319"}],"event":{"name":"2025 28th International Conference on Computer Supported Cooperative Work in Design (CSCWD)","start":{"date-parts":[[2025,5,5]]},"location":"Compiegne, France","end":{"date-parts":[[2025,5,7]]}},"container-title":["2025 28th International Conference on Computer Supported Cooperative Work in Design (CSCWD)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11033175\/11033221\/11033366.pdf?arnumber=11033366","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,24]],"date-time":"2025-06-24T06:05:20Z","timestamp":1750745120000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11033366\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,5]]},"references-count":29,"URL":"https:\/\/doi.org\/10.1109\/cscwd64889.2025.11033366","relation":{},"subject":[],"published":{"date-parts":[[2025,5,5]]}}}