{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T15:17:26Z","timestamp":1783610246732,"version":"3.55.0"},"reference-count":48,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T00:00:00Z","timestamp":1782086400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T00:00:00Z","timestamp":1782086400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,6,22]]},"DOI":"10.1109\/dsn69566.2026.00032","type":"proceedings-article","created":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T19:41:43Z","timestamp":1783539703000},"page":"198-211","source":"Crossref","is-referenced-by-count":1,"title":["Beyond Corner Patches: Semantics-Aware Backdoor Attack in Federated Learning"],"prefix":"10.1109","author":[{"given":"Kavindu","family":"Herath","sequence":"first","affiliation":[{"name":"Purdue University,Department of Electrical and Computer Engineering,West Lafayette,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Joshua","family":"Zhao","sequence":"additional","affiliation":[{"name":"Purdue University,Department of Electrical and Computer Engineering,West Lafayette,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Saurabh","family":"Bagchi","sequence":"additional","affiliation":[{"name":"Purdue University,Department of Electrical and Computer Engineering,West Lafayette,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proceedings of the 20th International Conference on Artificial Intelligence and Statistics (AISTATS)","author":"McMahan"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1561\/2200000083"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3030072"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3724113"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.01164"},{"key":"ref6","article-title":"Federated learning: Strategies for improving communication efficiency","volume-title":"NIPS Workshop on Private Multi-Party Machine Learning","author":"Konecn\u00fd"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/DSN-W65791.2025.00079"},{"key":"ref8","article-title":"Federated learning for mobile keyboard prediction","author":"Hard","year":"2019"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00387"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00030"},{"key":"ref11","article-title":"Federated optimization in heterogeneous networks","volume-title":"Proceedings of Machine Learning and Systems (MLSys)","author":"Li"},{"key":"ref12","article-title":"How to backdoor federated learning","volume-title":"Proceedings of the 23rd International Conference on Artificial Intelligence and Statistics (AISTATS)","author":"Bagdasaryan"},{"key":"ref13","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"Proceedings of the 36th International Conference on Machine Learning (ICML)","author":"Bhagoji"},{"key":"ref14","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","author":"Wang","year":"2020","journal-title":"Advances in Neural Information Processing Systems (NeurIPS)"},{"key":"ref15","article-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain","volume-title":"Proceedings of the IEEE International Conference on Machine Learning and Applications (ICMLA)","author":"Gu"},{"key":"ref16","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref18","article-title":"DBA: Distributed backdoor attacks against federated learning","volume-title":"International Conference on Learning Representations (ICLR)","author":"Xie"},{"key":"ref19","article-title":"Machine learning with adversaries: Byzantine-tolerant gradient descent","author":"Blanchard","year":"2017","journal-title":"Advances in Neural Information Processing Systems (NeurIPS)"},{"key":"ref20","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proceedings of the 35th International Conference on Machine Learning (ICML)","author":"Yin"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00614"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00391"},{"key":"ref24","first-page":"9389","article-title":"Just how toxic is data poisoning? a unified benchmark for backdoor and data poisoning attacks","volume-title":"International Conference on Machine Learning","author":"Schwarzschild"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.52202\/068431-0766"},{"key":"ref26","article-title":"Label-consistent backdoor attacks","author":"Turner","year":"2019"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01175"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"ref31","article-title":"Can you really backdoor federated learning?","author":"Sun","year":"2019"},{"key":"ref32","article-title":"Backdoor attacks and defenses in federated learning: Survey, challenges and future research directions","author":"Zhang","year":"2022"},{"key":"ref33","article-title":"The hidden vulnerability of distributed learning in byzantium","volume-title":"Proceedings of the 35th International Conference on Machine Learning (ICML) Workshop","author":"El Mhamdi"},{"key":"ref34","first-page":"1415","article-title":"Flame: Taming backdoors in federated learning","volume-title":"Proceedings of the 31st USENIX Security Symposium","author":"Nguyen"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1145\/3579856.3582836"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i8.20903"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3093711"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670307"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3719027.3744883"},{"key":"ref41","article-title":"Guiding instruction-based image editing via multimodal large language models","volume-title":"International Conference on Learning Representations (ICLR)","author":"Fu"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3704413.3764465"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/CSCWD64889.2025.11033366"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref45","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2015.425"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2012.02.016"},{"key":"ref48","article-title":"Umap: Uniform manifold approximation and projection for dimension reduction","author":"McInnes","year":"2018"}],"event":{"name":"2026 56th Annual IEEE International Conference on Dependable Systems and Networks (DSN)","location":"Charlotte, NC, USA","start":{"date-parts":[[2026,6,22]]},"end":{"date-parts":[[2026,6,25]]}},"container-title":["2026 56th Annual IEEE International Conference on Dependable Systems and Networks (DSN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11593123\/11593173\/11593174.pdf?arnumber=11593174","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T05:12:19Z","timestamp":1783573939000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11593174\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,22]]},"references-count":48,"URL":"https:\/\/doi.org\/10.1109\/dsn69566.2026.00032","relation":{},"subject":[],"published":{"date-parts":[[2026,6,22]]}}}