{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,2]],"date-time":"2026-04-02T06:50:24Z","timestamp":1775112624006,"version":"3.50.1"},"reference-count":49,"publisher":"IEEE","license":[{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-009"},{"start":{"date-parts":[[2023,5,1]],"date-time":"2023-05-01T00:00:00Z","timestamp":1682899200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-001"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023,5]]},"DOI":"10.1109\/sp46215.2023.10179362","type":"proceedings-article","created":{"date-parts":[[2023,7,21]],"date-time":"2023-07-21T17:18:15Z","timestamp":1689959895000},"page":"737-754","source":"Crossref","is-referenced-by-count":23,"title":["BayBFed: Bayesian Backdoor Defense for Federated Learning"],"prefix":"10.1109","author":[{"given":"Kavita","family":"Kumari","sequence":"first","affiliation":[{"name":"Technical University of Darmstadt"}]},{"given":"Phillip","family":"Rieger","sequence":"additional","affiliation":[{"name":"Technical University of Darmstadt"}]},{"given":"Hossein","family":"Fereidooni","sequence":"additional","affiliation":[{"name":"Technical University of Darmstadt"}]},{"given":"Murtuza","family":"Jadliwala","sequence":"additional","affiliation":[{"name":"The University of Texas at San Antonio"}]},{"given":"Ahmad-Reza","family":"Sadeghi","sequence":"additional","affiliation":[{"name":"Technical University of Darmstadt"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS51616.2021.00086"},{"key":"ref2","first-page":"1803","article-title":"How to explain individual classification decisions","volume":"11","author":"Baehrens","year":"2010","journal-title":"The Journal of Machine Learning Research"},{"key":"ref3","article-title":"How To Backdoor Federated Learning","author":"Bagdasaryan","year":"2020","journal-title":"AISTATS"},{"key":"ref4","article-title":"Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent","author":"Blanchard","year":"2017","journal-title":"NIPS"},{"key":"ref5","article-title":"Distance dependent chinese restaurant processes","volume-title":"ICML.","author":"Blei","year":"2010"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.3150\/16-BEJ855"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i8.16849"},{"key":"ref9","article-title":"Sever: A robust meta-algorithm for stochastic optimization","volume-title":"ICML.","author":"Diakonikolas","year":"2019"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2015.46"},{"key":"ref11","article-title":"Local model poisoning attacks to byzantine-robust federated learning","author":"Fang","year":"2020","journal-title":"USENIX Security"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23153"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SPW53761.2021.00017"},{"key":"ref14","article-title":"The limitations of federated learning in sybil settings","author":"Fung","year":"2020","journal-title":"RAID"},{"key":"ref15","article-title":"The hidden vulnerability of distributed learning in byzantium","volume-title":"ICML.","author":"Guerraoui","year":"2018"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCN49398.2020.9209670"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1214\/aos\/1018031207"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1017\/9781316104477"},{"key":"ref19","article-title":"Abnormal client behavior detection in federated learning","author":"Li","year":"2019"},{"key":"ref20","article-title":"Learning to detect malicious clients for robust federated learning","author":"Li","year":"2020"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2020.2975749"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1016\/j.jmp.2019.04.004"},{"key":"ref23","article-title":"Communication-Efficient Learning of Deep Networks from Decentralized Data","author":"McMahan","year":"2017","journal-title":"AISTATS"},{"key":"ref24","volume-title":"Federated learning: Collaborative Machine Learning without Centralized Training Data","author":"McMahan","year":"2017"},{"key":"ref25","article-title":"Learning differentially private recurrent language models","author":"McMahan","year":"2017"},{"key":"ref26","article-title":"Learning Differentially Private Language Models Without Losing Accuracy","author":"McMahan","year":"2018","journal-title":"ICLR"},{"key":"ref27","article-title":"Byzantine-Robust Federated Machine Learning through Adaptive Model Averaging","author":"Mu\u00f1oz-Gonz\u00e1lez","year":"2019"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23054"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2019.00080"},{"key":"ref30","article-title":"FLAME: taming backdoors in federated learning","author":"Nguyen","year":"2022","journal-title":"USENIX Security"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.14722\/diss.2020.23003"},{"key":"ref32","article-title":"A stick-breaking construction of the beta process","author":"Paisley","year":"2010","journal-title":"ICML"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2022.3153135"},{"key":"ref34","article-title":"Close the Gate: Detecting Backdoored Models in Federated Learning based on Client-Side Deep Layer Output Analysis","author":"Rieger","year":"2022"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23156"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-11723-8_9"},{"key":"ref37","doi-asserted-by":"crossref","DOI":"10.1145\/2991079.2991125","article-title":"Auror: Defending Against Poisoning Attacks in Collaborative Deep Learning Systems","author":"Shen","year":"2016","journal-title":"ACSAC"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/tmc.2018.2866249"},{"key":"ref39","article-title":"Spectral chinese restaurant processes: Nonparametric clustering based on similarities","volume-title":"AISTATS. JMLR Workshop and Conference Proceedings","author":"Socher"},{"key":"ref40","author":"Sun","year":"2019","journal-title":"Can you really backdoor federated learning?"},{"key":"ref41","article-title":"Hierarchical beta processes and the indian buffet process","volume-title":"AISTATS.","author":"Thibaux","year":"2007"},{"key":"ref42","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","author":"Wang","year":"2020","journal-title":"NeurIPS"},{"key":"ref43","article-title":"Mitigating backdoor attacks in federated learning","author":"Wu","year":"2020"},{"key":"ref44","article-title":"Crfl: Certifiably robust federated learning against backdoor attacks","volume-title":"ICML.","author":"Xie","year":"2021"},{"key":"ref45","article-title":"DBA: Distributed Backdoor Attacks against Federated Learning","author":"Xie","year":"2020","journal-title":"ICLR"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/s41666-020-00082-4"},{"key":"ref47","article-title":"Applied federated learning: Improving google keyboard query suggestions","author":"Yang","year":"2018"},{"key":"ref48","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"ICML.","author":"Yin","year":"2018"},{"key":"ref49","article-title":"Bayesian nonparametric federated learning of neural networks","volume-title":"ICML.","author":"Yurochkin","year":"2019"}],"event":{"name":"2023 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2023,5,21]]},"end":{"date-parts":[[2023,5,25]]}},"container-title":["2023 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10179215\/10179280\/10179362.pdf?arnumber=10179362","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,20]],"date-time":"2024-07-20T05:11:15Z","timestamp":1721452275000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10179362\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,5]]},"references-count":49,"URL":"https:\/\/doi.org\/10.1109\/sp46215.2023.10179362","relation":{},"subject":[],"published":{"date-parts":[[2023,5]]}}}