{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T03:28:23Z","timestamp":1777865303249,"version":"3.51.4"},"reference-count":45,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,19]],"date-time":"2025-10-19T00:00:00Z","timestamp":1760832000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,10,19]]},"DOI":"10.1109\/iccv51701.2025.00155","type":"proceedings-article","created":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:45:49Z","timestamp":1777491949000},"page":"1580-1589","source":"Crossref","is-referenced-by-count":0,"title":["Mind the Cost of Scaffold! Benign Clients May Even Become Accomplices of Backdoor Attack"],"prefix":"10.1109","author":[{"given":"Xingshuo","family":"Han","sequence":"first","affiliation":[{"name":"Nanjing University of Aeronautics and Astronautics, College of Computer Science and Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xuanye","family":"Zhang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiang","family":"Lan","sequence":"additional","affiliation":[{"name":"Fujian Normal University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Haozhao","family":"Wang","sequence":"additional","affiliation":[{"name":"Huazhong University of Science and Technology"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shengmin","family":"Xu","sequence":"additional","affiliation":[{"name":"Fujian Normal University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shen","family":"Ren","sequence":"additional","affiliation":[{"name":"Continental Automotive Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jason","family":"Zeng","sequence":"additional","affiliation":[{"name":"Zero Gravity Labs"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ming","family":"Wu","sequence":"additional","affiliation":[{"name":"Zero Gravity Labs"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Michael","family":"Heinrich","sequence":"additional","affiliation":[{"name":"Zero Gravity Labs"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tianwei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/tai.2024.3465441"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/COINS57856.2023.10189281"},{"key":"ref3","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"International conference on artificial intelligence and statistics","author":"Bagdasaryan","year":"2020"},{"key":"ref4","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"International Conference on Machine Learning","author":"Bhagoji","year":"2019"},{"key":"ref5","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume":"30","author":"Blanchard","year":"2017","journal-title":"Advances in neural information processing systems"},{"key":"ref6","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv preprint"},{"key":"ref7","first-page":"6712","article-title":"Chameleon: Adapting to peer images for planting durable backdoors in federated learning","volume-title":"International Conference on Machine Learning","author":"Dai","year":"2023"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2211477"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i10.26393"},{"key":"ref10","article-title":"Abc-fl: anomalous and benign client classification in federated learning","author":"Jeong","year":"2021","journal-title":"arXiv preprint"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1561\/2200000083"},{"key":"ref12","first-page":"5132","article-title":"Scaffold: Stochastic controlled averaging for federated learning","volume-title":"International conference on machine learning","author":"Karimireddy","year":"2020"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1073\/pnas.1611835114"},{"key":"ref14","volume-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1155\/2022\/4835776"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.52202\/068431-2787"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/DSA52907.2021.00081"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179401"},{"key":"ref19","first-page":"10713","article-title":"Modelcontrastive federated learning","volume-title":"Proceedings of the IEEE\/CVF conference on computer vision and pattern recognition","author":"Li","year":"2021"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2021.3124599"},{"key":"ref21","first-page":"429","article-title":"Federated optimization in heterogeneous networks","volume-title":"Proceedings of Machine learning and systems","volume":"2","author":"Li","year":"2020"},{"key":"ref22","article-title":"On the convergence of fedavg on non-iid data","author":"Li","year":"2019","journal-title":"arXiv preprint"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i7.26083"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3508398.3519363"},{"key":"ref27","first-page":"1273","article-title":"Communicationefficient learning of deep networks from decentralized data","volume-title":"Artificial intelligence and statistics","author":"McMahan","year":"2017"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00821"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/sp54263.2024.00008"},{"key":"ref30","first-page":"1415","article-title":"\\{FLAME\\}: Taming backdoors in federated learning","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Nguyen","year":"2022"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2896"},{"key":"ref32","first-page":"7587","article-title":"Sparsefed: Mitigating model poisoning attacks in federated learning with sparsification","volume-title":"International Conference on Artificial Intelligence and Statistics","author":"Panda","year":"2022"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.3390\/electronics12081805"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.29007\/21r5"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/SSCI50451.2021.9659839"},{"key":"ref36","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume":"33","author":"Wang","year":"2020","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref37","article-title":"Federated learning with matched averaging","author":"Wang","journal-title":"arXiv preprint"},{"key":"ref38","first-page":"7611","article-title":"Tackling the objective inconsistency problem in heterogeneous federated optimization","volume":"33","author":"Wang","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref39","article-title":"Thinking two moves ahead: Anticipating other users improves backdoor attacks in federated learning","author":"Wen","year":"2022","journal-title":"arXiv preprint"},{"key":"ref40","article-title":"Dba: Distributed backdoor attacks against federated learning","volume-title":"International conference on learning representations","author":"Xie","year":"2019"},{"key":"ref41","first-page":"11372","article-title":"Crfl: Certifiably robust federated learning against backdoor attacks","volume-title":"International Conference on Machine Learning","author":"Xie","year":"2021"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1145\/3649316"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2675"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom\/BigDataSE.2019.00057"},{"key":"ref45","first-page":"26429","article-title":"Neurotoxin: Durable backdoors in federated learning","volume-title":"International Conference on Machine Learning","author":"Zhang","year":"2022"}],"event":{"name":"2025 IEEE\/CVF International Conference on Computer Vision (ICCV)","location":"Honolulu, HI, USA","start":{"date-parts":[[2025,10,19]]},"end":{"date-parts":[[2025,10,25]]}},"container-title":["2025 IEEE\/CVF International Conference on Computer Vision (ICCV)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11443115\/11443287\/11444174.pdf?arnumber=11444174","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T06:11:16Z","timestamp":1777529476000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11444174\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,19]]},"references-count":45,"URL":"https:\/\/doi.org\/10.1109\/iccv51701.2025.00155","relation":{},"subject":[],"published":{"date-parts":[[2025,10,19]]}}}