{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,2,21]],"date-time":"2025-02-21T02:00:03Z","timestamp":1740103203496,"version":"3.37.3"},"reference-count":36,"publisher":"IEEE","license":[{"start":{"date-parts":[[2024,6,19]],"date-time":"2024-06-19T00:00:00Z","timestamp":1718755200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,6,19]],"date-time":"2024-06-19T00:00:00Z","timestamp":1718755200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100007219","name":"Natural Science Foundation of Shanghai","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100007219","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024,6,19]]},"DOI":"10.1109\/iwqos61813.2024.10682906","type":"proceedings-article","created":{"date-parts":[[2024,9,26]],"date-time":"2024-09-26T17:41:00Z","timestamp":1727372460000},"page":"1-10","source":"Crossref","is-referenced-by-count":0,"title":["FedTrojan: Corrupting Federated Learning via Zero-Knowledge Federated Trojan Attacks"],"prefix":"10.1109","author":[{"given":"Shan","family":"Chang","sequence":"first","affiliation":[{"name":"Donghua University,China"}]},{"given":"Ye","family":"Liu","sequence":"additional","affiliation":[{"name":"Donghua University,China"}]},{"given":"Zhijian","family":"Lin","sequence":"additional","affiliation":[{"name":"Donghua University,China"}]},{"given":"Hongzi","family":"Zhu","sequence":"additional","affiliation":[{"name":"Shanghai Jiao Tong University,China"}]},{"given":"Bingzhu","family":"Zhu","sequence":"additional","affiliation":[{"name":"Donghua University,China"}]},{"given":"Cong","family":"Wang","sequence":"additional","affiliation":[{"name":"City University of Hong Kong,Hong Kong"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Artificial intelligence and statistics","author":"McMahan","year":"2017"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2023.3315746"},{"article-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain","year":"2017","author":"Gu","key":"ref3"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/j.engappai.2023.107166"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/ICPADS47876.2019.00042"},{"article-title":"Mitigating sybils in federated learning poisoning","year":"2018","author":"Fung","key":"ref7"},{"article-title":"Mitigating backdoor attacks in federated learning","year":"2020","author":"Wu","key":"ref8"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102819"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP49357.2023.10095895"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","year":"2017","author":"Chen","key":"ref13"},{"article-title":"Label-consistent backdoor attacks","year":"2019","author":"Turner","key":"ref14"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV48922.2021.01175"},{"key":"ref17","first-page":"18944","article-title":"Backdoor attack with imperceptible input and latent modification","volume":"34","author":"Doan","year":"2021","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS51616.2021.00086"},{"key":"ref19","first-page":"1505","article-title":"Blind backdoors in deep learning models","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Bagdasaryan"},{"key":"ref20","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"International Conference on Artificial Intelligence and Statistics","author":"Bagdasaryan"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423362"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/3374664.3379534"},{"key":"ref23","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"International Conference on Machine Learning","author":"Bhagoji"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2023.3237397"},{"article-title":"Dba: Distributed backdoor attacks against federated learning","volume-title":"International Conference on Learning Representations","author":"Xie","key":"ref25"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref27"},{"article-title":"Estimating a dirichlet distribution","year":"2000","author":"Minka","key":"ref28"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref30","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume":"30","author":"Blanchard","year":"2017","journal-title":"Advances in Neural Information Processing Systems"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/tsp.2022.3153135"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/3154503"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"ref35","first-page":"1605","article-title":"Local model poisoning attacks to byzantine-robust federated learning","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Fang"},{"article-title":"Dynamic backdoor attacks against federated learning","year":"2020","author":"Huang","key":"ref36"}],"event":{"name":"2024 IEEE\/ACM 32nd International Symposium on Quality of Service (IWQoS)","start":{"date-parts":[[2024,6,19]]},"location":"Guangzhou, China","end":{"date-parts":[[2024,6,21]]}},"container-title":["2024 IEEE\/ACM 32nd International Symposium on Quality of Service (IWQoS)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10682818\/10682608\/10682906.pdf?arnumber=10682906","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,27]],"date-time":"2024-09-27T18:27:48Z","timestamp":1727461668000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10682906\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,6,19]]},"references-count":36,"URL":"https:\/\/doi.org\/10.1109\/iwqos61813.2024.10682906","relation":{},"subject":[],"published":{"date-parts":[[2024,6,19]]}}}