{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,12]],"date-time":"2026-05-12T18:01:20Z","timestamp":1778608880922,"version":"3.51.4"},"reference-count":68,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2024,9,1]],"date-time":"2024-09-01T00:00:00Z","timestamp":1725148800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,9,1]],"date-time":"2024-09-01T00:00:00Z","timestamp":1725148800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,9,1]],"date-time":"2024-09-01T00:00:00Z","timestamp":1725148800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61732010"],"award-info":[{"award-number":["61732010"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"SJTU-Huawei Joint Laboratory"},{"name":"Shanghai Key Laboratory of Scalable Computing and Systems"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2024,9]]},"DOI":"10.1109\/tdsc.2024.3362534","type":"journal-article","created":{"date-parts":[[2024,2,6]],"date-time":"2024-02-06T19:30:13Z","timestamp":1707247813000},"page":"4843-4860","source":"Crossref","is-referenced-by-count":13,"title":["Siren+: Robust Federated Learning With Proactive Alarming and Differential Privacy"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-7566-1589","authenticated-orcid":false,"given":"Hanxi","family":"Guo","sequence":"first","affiliation":[{"name":"Shanghai Key Laboratory of Scalable Computing and Systems, School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1444-2657","authenticated-orcid":false,"given":"Hao","family":"Wang","sequence":"additional","affiliation":[{"name":"Computer Science and Engineering, Louisiana State University, Baton Rouge, LA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5965-3140","authenticated-orcid":false,"given":"Tao","family":"Song","sequence":"additional","affiliation":[{"name":"Shanghai Key Laboratory of Scalable Computing and Systems, School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5536-503X","authenticated-orcid":false,"given":"Yang","family":"Hua","sequence":"additional","affiliation":[{"name":"EEECS\/ECIT, Queen&#x0027;s University Belfast, Belfast, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9592-8490","authenticated-orcid":false,"given":"Ruhui","family":"Ma","sequence":"additional","affiliation":[{"name":"Shanghai Key Laboratory of Scalable Computing and Systems, School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8242-9972","authenticated-orcid":false,"given":"Xiulang","family":"Jin","sequence":"additional","affiliation":[{"name":"Huawei Technologies Company Ltd, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhengui","family":"Xue","sequence":"additional","affiliation":[{"name":"School of Mathematics and Physics, Queen&#x0027;s University Belfast, Belfast, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4714-7400","authenticated-orcid":false,"given":"Haibing","family":"Guan","sequence":"additional","affiliation":[{"name":"Shanghai Key Laboratory of Scalable Computing and Systems, School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3472883.3486990"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-57959-7"},{"key":"ref3","first-page":"1","article-title":"Federated learning: Strategies for improving communication efficiency","volume-title":"Proc. NeurIPS Workshop Private Multi-Party Mach. Learn.","author":"Kone\u010dn\u00fd"},{"key":"ref4","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"McMahan"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2017.2736066"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.5555\/2685048.2685095"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2015.2472014"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2020.2975749"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"ref10","first-page":"1","article-title":"Learning differentially private recurrent language models","volume-title":"Proc. Int. Conf. Learn. Representations","author":"McMahan"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1038\/s41746-020-00323-1"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/s41666-020-00082-4"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2021.3124599"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63076-8_1"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/357172.357176"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"ref17","first-page":"14747","article-title":"Deep leakage from gradients","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Zhu"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011544"},{"key":"ref19","first-page":"1605","article-title":"Local model poisoning attacks to byzantine-robust federated learning","volume-title":"Proc. USENIX Secur. Symp.","author":"Fang"},{"key":"ref20","article-title":"Learning to detect malicious clients for robust federated learning","author":"Li","year":"2020"},{"key":"ref21","first-page":"261","article-title":"Fall of empires: Breaking byzantine-tolerant SGD by inner product manipulation","volume-title":"Proc. 35th Conf. Uncertainty Artif. Intell.","author":"Xie"},{"key":"ref22","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bhagoji"},{"key":"ref23","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref24","first-page":"1","article-title":"DBA: Distributed backdoor attacks against federated learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xie"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"ref28","article-title":"iDLG: Improved deep leakage from gradients","author":"Zhao","year":"2020"},{"key":"ref29","first-page":"119","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Blanchard"},{"key":"ref30","first-page":"5636","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i8.16849"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3154503"},{"key":"ref33","first-page":"3518","article-title":"The hidden vulnerability of distributed learning in Byzantium","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"El Mhamdi"},{"key":"ref34","first-page":"902","article-title":"DRACO: Byzantine-resilient distributed training via redundant gradients","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Chen"},{"key":"ref35","first-page":"4618","article-title":"Byzantine stochastic gradient descent","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Alistarh"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3093711"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2022.3167434"},{"key":"ref38","article-title":"FLIP: A provable defense framework for backdoor mitigation in federated learning","author":"Zhang","year":"2022"},{"key":"ref39","first-page":"12613","article-title":"FL-WBC: Enhancing robustness against model poisoning attacks in federated learning from a client perspective","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Sun"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3378679.3394533"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ISIT44484.2020.9174426"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3037194"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2988575"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23054"},{"key":"ref45","article-title":"A general approach to adding differential privacy to iterative training procedures","author":"McMahan","year":"2018"},{"key":"ref46","article-title":"Differentially private federated learning: A client level perspective","author":"Geyer","year":"2017"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2991416"},{"key":"ref48","article-title":"Federated learning with non-IID data","author":"Zhao","year":"2018"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"ref50","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017"},{"key":"ref51","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1007\/11761679_29"},{"key":"ref56","first-page":"1","article-title":"Model poisoning attacks in federated learning","volume-title":"Proc. NeurIPS Workshop Secur. Mach. Learn.","author":"Bhagoji"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58951-6_24"},{"key":"ref58","article-title":"Generalized Byzantine-tolerant SGD","author":"Xie","year":"2018"},{"key":"ref59","first-page":"7074","article-title":"Defending against saddle point attack in Byzantine-robust distributed learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1976.1055638"},{"key":"ref61","first-page":"265","article-title":"TensorFlow: A system for large-scale machine learning","volume-title":"Proc. USENIX Symp. Operating Syst. Des. Implementation","author":"Abadi"},{"key":"ref62","article-title":"TensorFlow privacy","year":"2019"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref64","article-title":"Differentially private learning with adaptive clipping","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Andrew"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref66","article-title":"Can you really backdoor federated learning?","author":"Sun","year":"2019"},{"key":"ref67","first-page":"6893","article-title":"Zeno: Distributed stochastic gradient descent with suspicion-based fault-tolerance","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Xie"},{"key":"ref68","first-page":"10495","article-title":"ZENO++: Robust fully asynchronous SGD","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Xie"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/8858\/10663874\/10423198.pdf?arnumber=10423198","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,9,4]],"date-time":"2024-09-04T21:08:07Z","timestamp":1725484087000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10423198\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,9]]},"references-count":68,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2024.3362534","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,9]]}}}