{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,29]],"date-time":"2026-03-29T06:51:22Z","timestamp":1774767082829,"version":"3.50.1"},"reference-count":43,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Project of China","award":["2023YFF0725500"],"award-info":[{"award-number":["2023YFF0725500"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62432006"],"award-info":[{"award-number":["62432006"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62272276"],"award-info":[{"award-number":["62272276"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Taishan Scholars Program","award":["tsqn202306007"],"award-info":[{"award-number":["tsqn202306007"]}]},{"name":"Taishan Scholars Program","award":["tsqn202408317"],"award-info":[{"award-number":["tsqn202408317"]}]},{"DOI":"10.13039\/501100007129","name":"Natural Science Foundation of Shandong Province","doi-asserted-by":"publisher","award":["ZR2024JQ001"],"award-info":[{"award-number":["ZR2024JQ001"]}],"id":[{"id":"10.13039\/501100007129","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Xiaomi Fund"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,11]]},"DOI":"10.1109\/tdsc.2025.3577267","type":"journal-article","created":{"date-parts":[[2025,6,6]],"date-time":"2025-06-06T13:44:49Z","timestamp":1749217489000},"page":"5906-5917","source":"Crossref","is-referenced-by-count":4,"title":["Sophon: Byzantine-Robust Federated Learning via Dual Trust Mechanism"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4306-9406","authenticated-orcid":false,"given":"Xiaoqiang","family":"Gui","sequence":"first","affiliation":[{"name":"School of Software, Shandong University, Jinan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1667-6705","authenticated-orcid":false,"given":"Guoxian","family":"Yu","sequence":"additional","affiliation":[{"name":"School of Software, Shandong University, Jinan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5890-0365","authenticated-orcid":false,"given":"Jun","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Software, Shandong University, Jinan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5271-5417","authenticated-orcid":false,"given":"Zhongmin","family":"Yan","sequence":"additional","affiliation":[{"name":"School of Software, Shandong University, Jinan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5974-1589","authenticated-orcid":false,"given":"Wei","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Software, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2140-9596","authenticated-orcid":false,"given":"Carlotta","family":"Domeniconi","sequence":"additional","affiliation":[{"name":"Department of Computer Science, George Mason University, Fairfax, VA, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8262-8883","authenticated-orcid":false,"given":"Lizhen","family":"Cui","sequence":"additional","affiliation":[{"name":"School of Software, Shandong University, Jinan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"McMahan"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3298981"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1002\/9781119594307"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1561\/9781680837896"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3264697"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3239007"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3346183"},{"issue":"226","key":"ref8","first-page":"1","article-title":"Fate: An industrial grade platform for collaborative learning with data protection","volume":"22","author":"Liu","year":"2021","journal-title":"J. Mach. Learn. Res."},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/s41666-020-00082-4"},{"key":"ref10","first-page":"118","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Blanchard"},{"key":"ref11","first-page":"8635","article-title":"A little is enough: Circumventing defenses for distributed learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Baruch"},{"key":"ref12","first-page":"1605","article-title":"Local model poisoning attacks to byzantine-robust federated learning","volume-title":"Proc. USENIX Secur. Symp.","author":"Fang"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/357172.357176"},{"key":"ref15","first-page":"1","article-title":"SLALOM: Fast, verifiable and private execution of neural networks in trusted hardware","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Tramer"},{"key":"ref16","first-page":"723","article-title":"SOTER: Guarding black-box inference for general neural networks at the edge","volume-title":"Proc. USENIX Annu. Tech. Conf.","author":"Shen"},{"key":"ref17","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in byzantium","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Guerraoui"},{"key":"ref18","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011544"},{"key":"ref20","first-page":"1","article-title":"Byzantine-robust learning on heterogeneous datasets via bucketing","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Karimireddy"},{"key":"ref21","first-page":"301","article-title":"The limitations of federated learning in sybil settings","volume-title":"Proc. 23rd Int. Symp. Res. Attacks, Intrusions Defenses","author":"Fung"},{"key":"ref22","article-title":"TESSERACT: Gradient flip score to secure federated learning against model poisoning attacks","author":"Sharma","year":"2021"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-90019-9_12"},{"key":"ref24","first-page":"840","article-title":"Sageflow: Robust federated learning against both stragglers and adversaries","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Park"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"ref26","first-page":"6893","article-title":"Zeno: Distributed stochastic gradient descent with suspicion-based fault-tolerance","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Xie"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1038\/nature10166"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1038\/nature08987"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2022.10.120"},{"key":"ref30","first-page":"10495","article-title":"Zeno++: Robust fully asynchronous SGD","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Xie"},{"key":"ref31","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref32","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bhagoji"},{"key":"ref33","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","author":"Wang","year":"2020"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3488014"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23113"},{"key":"ref36","first-page":"809","article-title":"Cheetah: Lean and fast secure two-party deep neural network inference","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Huang"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1986.25"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref39","first-page":"1","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref40","first-page":"437","article-title":"A public domain dataset for human activity recognition using smartphones","volume-title":"Proc. Eur. Symp. Artif. Neural Netw.","author":"Anguita"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3190359"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1038\/323533a0"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11242243\/11027323.pdf?arnumber=11027323","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T21:01:14Z","timestamp":1763154074000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11027323\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11]]},"references-count":43,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3577267","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11]]}}}