{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,16]],"date-time":"2026-05-16T16:09:30Z","timestamp":1778947770590,"version":"3.51.4"},"reference-count":56,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"6","license":[{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,11,1]],"date-time":"2025-11-01T00:00:00Z","timestamp":1761955200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2025,11]]},"DOI":"10.1109\/tdsc.2025.3595518","type":"journal-article","created":{"date-parts":[[2025,8,4]],"date-time":"2025-08-04T18:48:14Z","timestamp":1754333294000},"page":"7157-7171","source":"Crossref","is-referenced-by-count":1,"title":["General Test-Time Backdoor Detection in Split Neural Network-Based Vertical Federated Learning"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1874-9792","authenticated-orcid":false,"given":"Shunjie","family":"Yuan","sequence":"first","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5583-4155","authenticated-orcid":false,"given":"Xinghua","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6221-0754","authenticated-orcid":false,"given":"Xuelin","family":"Cao","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5647-0958","authenticated-orcid":false,"given":"Haiyan","family":"Zhang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Services Networks, School of Cyber Engineering, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3491-8146","authenticated-orcid":false,"given":"Robert H.","family":"Deng","sequence":"additional","affiliation":[{"name":"School of Information Systems, Singapore Management University, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1877","article-title":"Language models are few-shot learners","volume-title":"Proc. Int. Conf. Neural Inf. Process. Syst.","author":"Brown"},{"key":"ref2","article-title":"GPT-4 technical report","author":"Achiam","year":"2023"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1038\/s41586-021-03819-2"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2020.3032227"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ICCVW.2015.58"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01819"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-57959-7"},{"key":"ref8","doi-asserted-by":"crossref","first-page":"1","DOI":"10.54648\/GTCJ2012001","article-title":"New consumer product safety laws in Canada and the United States: Business on the border","volume":"7","author":"Kiselbach","year":"2012","journal-title":"Glob. Trade Cust. J."},{"key":"ref9","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. 20th Int. Conf. Artif. Intell. Statist.","author":"McMahan"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3387107"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00008"},{"key":"ref12","first-page":"2743","article-title":"VILLAIN: Backdoor attacks against vertical split learning","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Bai"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3327853"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM58522.2023.00013"},{"key":"ref15","article-title":"RVFR: Robust vertical federated learning via feature subspace recovery","volume-title":"Proc. NeurIPS Workshop New Front. Federated Learn.: Privacy, Fairness, Robustness, Personalization Data Ownership","author":"Liu"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-70903-6_15"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/BigData62323.2024.10825545"},{"key":"ref18","article-title":"Split learning for health: Distributed deep learning without sharing raw patient data","author":"Vepakomma","year":"2018"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref20","article-title":"Unlearnable examples: Making personal data unexploitable","volume-title":"Proc. 9th Int. Conf. Learn. Representations","author":"Huang"},{"key":"ref21","article-title":"Label leakage and protection in two-party split learning","volume-title":"Proc. Tenth Int. Conf. Learn. Representations","author":"Li"},{"key":"ref22","first-page":"1397","article-title":"Label inference attacks against vertical federated learning","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Fu"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1145\/3359789.3359790"},{"key":"ref24","article-title":"Scale-up: An efficient black-box input-level backdoor detection via analyzing scaled prediction consistency","volume-title":"Proc. 11th Int. Conf. Learn. Representations","author":"Guo"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref28","article-title":"Neural attention distillation: Erasing backdoor triggers from deep neural networks","volume-title":"Proc. 9th Int. Conf. Learn. Representations","author":"Li"},{"key":"ref29","first-page":"19837","article-title":"Reconstructive neuron pruning for backdoor defense","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Li"},{"key":"ref30","first-page":"14900","article-title":"Anti-backdoor learning: Training clean models on poisoned data","volume-title":"Proc. 34th Annu. Conf. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref31","first-page":"1685","article-title":"Towards a proactive ML approach for detecting backdoor poison samples","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Qi"},{"key":"ref32","first-page":"119","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. 30th Annu. Conf. Neural Inf. Process. Syst.","author":"Blanchard"},{"key":"ref33","first-page":"5636","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref34","first-page":"301","article-title":"The limitations of federated learning in sybil settings","volume-title":"Proc. 23rd Int. Symp. Res. Attacks, Intrusions Defenses","author":"Fung"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3169918"},{"key":"ref36","article-title":"Abnormal client behavior detection in federated learning","author":"Li","year":"2019"},{"key":"ref37","article-title":"Learning to detect malicious clients for robust federated learning","author":"Li","year":"2020"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00429"},{"key":"ref39","article-title":"Mitigating backdoor attacks in federated learning","author":"Wu","year":"2020"},{"key":"ref40","first-page":"7587","article-title":"SparseFed: Mitigating model poisoning attacks in federated learning with sparsification","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Panda"},{"key":"ref41","first-page":"43158","article-title":"LeadFL: Client self-defense against model poisoning in federated learning","volume-title":"Proc. 40th Int. Conf. Mach. Learn.","author":"Zhu"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3384846"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.74"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2024.3352628"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-25952-7_6"},{"key":"ref46","first-page":"797","article-title":"Faster private set intersection based on OT extension","volume-title":"Proc. 23rd USENIX Secur. Symp.","author":"Benny"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom50675.2020.00098"},{"key":"ref49","article-title":"Fair and efficient contribution valuation for vertical federated learning","volume-title":"Proc. 9th Int. Conf. Learn. Representations","author":"Fan"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1056\/NEJM199610103351501"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.15585\/mmwr.mm6643a2"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref53","first-page":"32","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref54","article-title":"CINIC-10 is not imagenet or CIFAR-10","author":"Darlow","year":"2018"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01445"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11242243\/11112534.pdf?arnumber=11112534","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,14]],"date-time":"2025-11-14T21:00:53Z","timestamp":1763154053000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11112534\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11]]},"references-count":56,"journal-issue":{"issue":"6"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3595518","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11]]}}}