{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,17]],"date-time":"2026-06-17T18:19:20Z","timestamp":1781720360891,"version":"3.54.5"},"reference-count":31,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,11]]},"DOI":"10.1109\/tdsc.2025.3590175","type":"journal-article","created":{"date-parts":[[2025,7,17]],"date-time":"2025-07-17T18:01:57Z","timestamp":1752775317000},"page":"6732-6747","source":"Crossref","is-referenced-by-count":5,"title":["FL-CDF: Collaborative Defense Framework for Backdoor Mitigation in Federated Learning"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5647-0958","authenticated-orcid":false,"given":"Haiyan","family":"Zhang","sequence":"first","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5583-4155","authenticated-orcid":false,"given":"Xinghua","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5437-3572","authenticated-orcid":false,"given":"Yinbin","family":"Miao","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1874-9792","authenticated-orcid":false,"given":"Shunjie","family":"Yuan","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mengyao","family":"Zhu","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4238-3295","authenticated-orcid":false,"given":"Ximeng","family":"Liu","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Intelligent Vehicle Safety Technology, Chongqing Changan Automobile Co., Ltd., Chongqing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3491-8146","authenticated-orcid":false,"given":"Robert H.","family":"Deng","sequence":"additional","affiliation":[{"name":"School of Information Systems, Singapore Management University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","first-page":"4285","article-title":"SoteriaFL: A unified framework for private federated learning with communication compression","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref2","first-page":"17871","article-title":"SemiFL: Semi-supervised federated learning for unlabeled clients with alternate training","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Diao"},{"key":"ref3","first-page":"38831","article-title":"FedSR: A simple and effective domain generalization method for federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Nguyen"},{"key":"ref4","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref5","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bhagoji"},{"key":"ref6","first-page":"1","article-title":"DBA: Distributed backdoor attacks against federated learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xie"},{"key":"ref7","first-page":"2237","article-title":"$\\lbrace${PatchGuard$\\rbrace$}: A provably robust defense against adversarial patches via small receptive fields and masking","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Xiang"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2022.3153135"},{"key":"ref9","first-page":"7587","article-title":"SparseFed: Mitigating model poisoning attacks in federated learning with sparsification","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Panda"},{"key":"ref10","article-title":"Certified robustness in federated learning","author":"Alfarra","year":"2022"},{"key":"ref11","first-page":"11372","article-title":"CRFL: Certifiably robust federated learning against backdoor attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Xie"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3108434"},{"key":"ref14","first-page":"1415","article-title":"FLAME: Taming backdoors in federated learning","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Nguyen"},{"key":"ref15","first-page":"12613","article-title":"FL-WBC: Enhancing robustness against model poisoning attacks in federated learning from a client perspective","volume-title":"Proc. 35th Int. Conf. Neural Inf. Process. Syst.","author":"Sun"},{"key":"ref16","first-page":"1","article-title":"Flip: A provable defense framework for backdoor mitigation in federated learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Zhang"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01458"},{"key":"ref19","first-page":"9727","article-title":"Effective backdoor defense by exploiting sensitivity of poisoned samples","volume-title":"Proc. Adv. Neural Inf. Process. Syst. 35: Annu. Conf. Neural Inf. Process. Syst.","author":"Chen"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i8.16849"},{"key":"ref21","first-page":"5636","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref22","first-page":"301","article-title":"The limitations of federated learning in Sybil settings","volume-title":"Proc. Int. Symp. Res. Attacks, Intrusions Defenses","author":"Fung"},{"key":"ref23","first-page":"119","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Blanchard"},{"key":"ref24","first-page":"3518","article-title":"The hidden vulnerability of distributed learning in Byzantium","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"El Mahdi"},{"key":"ref25","first-page":"9268","article-title":"Defending against backdoors in federated learning with robust learning rate","volume-title":"Proc. AAAI Conf. Artif. Intell.","author":"Mustafa"},{"key":"ref26","first-page":"16913","article-title":"Adversarial neuron pruning purifies backdoored deep models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wu"},{"key":"ref27","first-page":"22285","article-title":"One-shot neural backdoor erasing via adversarial weight masking","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Chai"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1016\/j.jesp.2013.03.013"},{"key":"ref29","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. 20th Int. Conf. Artif. Intell. Statist.","author":"McMahan"},{"key":"ref30","first-page":"26429","article-title":"Neurotoxin: Durable backdoors in federated learning","volume-title":"Proc. 39th Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/JETCAS.2024.3450527"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11242243\/11082570.pdf?arnumber=11082570","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T21:00:43Z","timestamp":1763154043000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11082570\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11]]},"references-count":31,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3590175","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11]]}}}