{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,11]],"date-time":"2026-03-11T08:30:06Z","timestamp":1773217806134,"version":"3.50.1"},"reference-count":39,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,6,18]],"date-time":"2023-06-18T00:00:00Z","timestamp":1687046400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,6,18]],"date-time":"2023-06-18T00:00:00Z","timestamp":1687046400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,6,18]]},"DOI":"10.1109\/ijcnn54540.2023.10191260","type":"proceedings-article","created":{"date-parts":[[2023,8,2]],"date-time":"2023-08-02T17:30:03Z","timestamp":1690997403000},"page":"1-10","source":"Crossref","is-referenced-by-count":20,"title":["Privacy Inference-Empowered Stealthy Backdoor Attack on Federated Learning under Non-IID Scenarios"],"prefix":"10.1109","author":[{"given":"Haochen","family":"Mei","sequence":"first","affiliation":[{"name":"School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University,Shanghai,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Gaolei","family":"Li","sequence":"additional","affiliation":[{"name":"School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University,Shanghai,China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jun","family":"Wu","sequence":"additional","affiliation":[{"name":"Graduate School of Information, Production and Systems, Waseda University,Fukuoka,Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Longfei","family":"Zheng","sequence":"additional","affiliation":[{"name":"Ant Group,China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i12.17291"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3422622"},{"key":"ref37","article-title":"Eliminating back-door triggers for deep neural networks using attention relation graph distillation","author":"xia","year":"2022","journal-title":"ArXiv Preprint"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"ref36","article-title":"Detecting backdoor attacks on deep neural networks by activation clustering","author":"chen","year":"2018","journal-title":"ArXiv Preprint"},{"key":"ref31","article-title":"Flguard: Secure and private federated learning","author":"nguyen","year":"2021","journal-title":"Crytography and Security"},{"key":"ref30","first-page":"301","article-title":"The limitations of federated learning in sybil settings","author":"fung","year":"2020","journal-title":"RAID"},{"key":"ref11","first-page":"26429","article-title":"Neurotoxin: Durable backdoors in federated learning","author":"zhang","year":"2022","journal-title":"International Conference on Machine Learning"},{"key":"ref33","first-page":"1","article-title":"Backdoor attacks and defenses in federated learning: State-of-the-art, taxonomy, and future directions","author":"gong","year":"2022","journal-title":"IEEE Wireless Communications"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2022.3173996"},{"key":"ref32","first-page":"1415","article-title":"Flame: Taming backdoors in federated learning","author":"nguyen","year":"2022","journal-title":"USENIX Security Symposium (USENIX Security)"},{"key":"ref2","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1561\/2200000083","article-title":"Advances and open problems in federated learning","volume":"14","author":"kairouz","year":"2021","journal-title":"Foundations and Trends\ufffd in Machine Learning"},{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","author":"mcmahan","year":"2017","journal-title":"Artificial Intelligence and Statistics"},{"key":"ref17","first-page":"10946","article-title":"Federated Learning with Only Positive Labels","author":"yu","year":"2020","journal-title":"ICML"},{"key":"ref39","first-page":"429","article-title":"Federated optimization in heterogeneous networks","volume":"2","author":"li","year":"2020","journal-title":"Proceedings of Machine Learning and Systems"},{"key":"ref16","article-title":"Federated Learning with Non-IID Data","author":"zhao","year":"2018","journal-title":"ArXiv Preprint"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref19","article-title":"Can you really backdoor federated learning?","author":"sun","year":"2019","journal-title":"ArXiv Preprint"},{"key":"ref18","first-page":"1","article-title":"Dba: Distributed backdoor attacks against federated learning","author":"xie","year":"2020","journal-title":"International Conference on Learning Representations"},{"key":"ref24","article-title":"Semi-Supervised Learning with Generative Adversarial Networks","author":"odena","year":"2016","journal-title":"ArXiv Preprint"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00152"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2019.00361"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2011.5995566"},{"key":"ref22","first-page":"691","article-title":"Exploiting un-intended feature leakage in collaborative learning","author":"melis","year":"2019","journal-title":"IEEE Symposium on Security and Privacy (SP)"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.011.2000783"},{"key":"ref28","article-title":"Unsupervised Representation Learning with Deep Convolutional Generative Adversarial Networks","author":"radford","year":"2016","journal-title":"ArXiv Preprint"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3065386"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.23915\/distill.00003"},{"key":"ref8","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume":"33","author":"wang","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref7","first-page":"634","article-title":"Analyzing feder-ated learning through an adversarial lens","author":"bhagoji","year":"2019","journal-title":"International Conference on Machine Learning (ICML)"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3023126"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3116431"},{"key":"ref3","article-title":"Badnets: Identifying vulnera-bilities in the machine learning model supply chain","author":"gu","year":"2017","journal-title":"ArXiv Preprint"},{"key":"ref6","first-page":"2938","article-title":"How to backdoor federated learning","author":"bagdasaryan","year":"2020","journal-title":"International Conference on Artificial Intelligence and Statistics"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM48099.2022.10001370"}],"event":{"name":"2023 International Joint Conference on Neural Networks (IJCNN)","location":"Gold Coast, Australia","start":{"date-parts":[[2023,6,18]]},"end":{"date-parts":[[2023,6,23]]}},"container-title":["2023 International Joint Conference on Neural Networks (IJCNN)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10190990\/10190992\/10191260.pdf?arnumber=10191260","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,8,21]],"date-time":"2023-08-21T17:42:47Z","timestamp":1692639767000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10191260\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,6,18]]},"references-count":39,"URL":"https:\/\/doi.org\/10.1109\/ijcnn54540.2023.10191260","relation":{},"subject":[],"published":{"date-parts":[[2023,6,18]]}}}