{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,11,25]],"date-time":"2025-11-25T05:08:34Z","timestamp":1764047314988,"version":"3.37.3"},"reference-count":55,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100000780","name":"European Commission","doi-asserted-by":"publisher","award":["101070052","101070627","101073920"],"award-info":[{"award-number":["101070052","101070627","101073920"]}],"id":[{"id":"10.13039\/501100000780","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE J. Emerg. Sel. Topics Circuits Syst."],"published-print":{"date-parts":[[2024]]},"DOI":"10.1109\/jetcas.2024.3450527","type":"journal-article","created":{"date-parts":[[2024,8,27]],"date-time":"2024-08-27T17:23:30Z","timestamp":1724779410000},"page":"1-1","source":"Crossref","is-referenced-by-count":2,"title":["Stealthy Backdoor Attack against Federated Learning through Frequency Domain by Backdoor Neuron Constraint and Model Camouflage"],"prefix":"10.1109","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-0180-0096","authenticated-orcid":false,"given":"Yanqi","family":"Qiao","sequence":"first","affiliation":[{"name":"Faculty of Electrical Engineering, Mathematics and Computer Science, Delft University of Technology, Delft, The Netherlands"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7250-1264","authenticated-orcid":false,"given":"Dazhuang","family":"Liu","sequence":"additional","affiliation":[{"name":"Faculty of Electrical Engineering, Mathematics and Computer Science, Delft University of Technology, Delft, The Netherlands"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8495-3631","authenticated-orcid":false,"given":"Rui","family":"Wang","sequence":"additional","affiliation":[{"name":"Faculty of Electrical Engineering, Mathematics and Computer Science, Delft University of Technology, Delft, The Netherlands"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0262-7678","authenticated-orcid":false,"given":"Kaitai","family":"Liang","sequence":"additional","affiliation":[{"name":"Faculty of Electrical Engineering, Mathematics and Computer Science, Delft University of Technology, Delft, The Netherlands"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. 20th Int. Conf. Artif. Intell. Statist.","author":"McMahan"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.001.1900461"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2024.3352628"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3299573"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3263598"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2023.3272801"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2023.3269062"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/tsg.2024.3399396"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1038\/s41591-021-01506-3"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/IV51971.2022.9827020"},{"key":"ref11","first-page":"1","article-title":"A little is enough: Circumventing defenses for distributed learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Baruch"},{"key":"ref12","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Bhagoji"},{"article-title":"DBA: Distributed backdoor attacks against federated learning","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Xie","key":"ref13"},{"key":"ref14","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref15","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Wang"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179401"},{"key":"ref17","first-page":"61213","article-title":"A3FL: Adversarially adaptive backdoor attacks to federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"36","author":"Zhang"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-37456-2_14"},{"key":"ref19","first-page":"26429","article-title":"Neurotoxin: Durable backdoors in federated learning","volume-title":"Proc. 39th Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref20","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i10.17118"},{"key":"ref22","first-page":"1415","article-title":"FLAME: Taming backdoors in federated learning","volume-title":"Proc. 31st USENIX Security Symp. (USENIX Security)","author":"Nguyen"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23156"},{"key":"ref24","article-title":"A Fourier perspective on model robustness in computer vision","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Yin"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-36708-4_22"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19778-9_23"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.02021"},{"key":"ref28","article-title":"Practical secure aggregation for federated learning on user-held data","author":"Bonawitz","year":"2016","journal-title":"arXiv:1611.04482"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i8.20903"},{"key":"ref30","first-page":"429","article-title":"Federated optimization in heterogeneous networks","volume-title":"Proc. 3rd Mach. Learn. Syst. Conf.","volume":"2","author":"Li"},{"key":"ref31","article-title":"A communication efficient collaborative learning framework for distributed features","author":"Liu","year":"2019","journal-title":"arXiv:1912.11187"},{"key":"ref32","first-page":"6357","article-title":"Ditto: Fair and robust federated learning through personalization","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58951-6_24"},{"key":"ref34","first-page":"6712","article-title":"Chameleon: Adapting to peer images for planting durable backdoors in federated learning","volume-title":"Proc. 40th Int. Conf. Mach. Learn.","author":"Dai"},{"key":"ref35","first-page":"21554","article-title":"Robust federated learning: The case of affine distribution shifts","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Reisizadeh"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i8.16849"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"ref39","first-page":"11372","article-title":"CRFL: Certifiably robust federated learning against backdoor attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Xie"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539231"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00983"},{"key":"ref42","first-page":"1","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"30","author":"Blanchard"},{"key":"ref43","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in Byzantium","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"El Mhamdi"},{"key":"ref44","article-title":"Can you really backdoor federated learning?","author":"Sun","year":"2019","journal-title":"arXiv:1911.07963"},{"key":"ref45","first-page":"560","article-title":"signSGD: Compressed optimisation for non-convex problems","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","volume":"80","author":"Bernstein"},{"key":"ref46","first-page":"7587","article-title":"SparseFed: Mitigating model poisoning attacks in federated learning with sparsification","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","volume":"151","author":"Panda"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"volume-title":"The Mnist Database of Handwritten Digits","year":"1998","author":"LeCun","key":"ref48"},{"key":"ref49","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017","journal-title":"arXiv:1708.07747"},{"article-title":"Learning multiple layers of features from tiny images","year":"2009","author":"Krizhevsky","key":"ref50"},{"key":"ref51","article-title":"LEAF: A benchmark for federated settings","author":"Caldas","year":"2018","journal-title":"arXiv:1812.01097"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref54","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv:1712.05526"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833647"}],"container-title":["IEEE Journal on Emerging and Selected Topics in Circuits and Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/5503868\/5751207\/10649604.pdf?arnumber=10649604","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,12,14]],"date-time":"2024-12-14T06:54:14Z","timestamp":1734159254000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10649604\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"references-count":55,"URL":"https:\/\/doi.org\/10.1109\/jetcas.2024.3450527","relation":{},"ISSN":["2156-3357","2156-3365"],"issn-type":[{"type":"print","value":"2156-3357"},{"type":"electronic","value":"2156-3365"}],"subject":[],"published":{"date-parts":[[2024]]}}}