{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T20:02:03Z","timestamp":1778788923326,"version":"3.51.4"},"reference-count":45,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62572206"],"award-info":[{"award-number":["62572206"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,1]]},"DOI":"10.1109\/tdsc.2025.3604514","type":"journal-article","created":{"date-parts":[[2025,9,2]],"date-time":"2025-09-02T17:33:00Z","timestamp":1756834380000},"page":"250-262","source":"Crossref","is-referenced-by-count":1,"title":["Fine-Grained Poisoning Framework Against Federated Learning"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-1735-2024","authenticated-orcid":false,"given":"Minghui","family":"Li","sequence":"first","affiliation":[{"name":"School of Software Engineering, Huazhong University of Science and Technology, Hubei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6805-6401","authenticated-orcid":false,"given":"Hangtao","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Huazhong University of Science and Technology, Hubei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5611-3483","authenticated-orcid":false,"given":"Yanjun","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of Technology Sydney, Ultimo, NSW, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-5282-6362","authenticated-orcid":false,"given":"Li","family":"Zeng","sequence":"additional","affiliation":[{"name":"School of Mathematics and Computational Science, Xiangtan University, Hunan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1355-3870","authenticated-orcid":false,"given":"Chao","family":"Chen","sequence":"additional","affiliation":[{"name":"School of Accounting, Information System and Supply Chain, RMIT University, Melbourne, VIC, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-1936-7993","authenticated-orcid":false,"given":"Qiyun","family":"Shao","sequence":"additional","affiliation":[{"name":"China Mobile Commun Grp Company Ltd., Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1247-5092","authenticated-orcid":false,"given":"Wei","family":"Wan","sequence":"additional","affiliation":[{"name":"Faculty of Data Science, City University of Macau, Macau, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0042-9045","authenticated-orcid":false,"given":"Shengshan","family":"Hu","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Huazhong University of Science and Technology, Hubei, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9330-2662","authenticated-orcid":false,"given":"Leo Yu","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Information and Communication Technology, Griffith University, Nathan, QLD, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"ref2","article-title":"Federated learning: Collaborative machine learning without centralized training data","author":"McMahan","year":"2017"},{"key":"ref3","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. 20th Int. Conf. Artif. Intell. Statist.","author":"McMahan"},{"key":"ref4","article-title":"DarkFed: A data-free backdoor attack in federated learning","author":"Li","year":"2024"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3372634"},{"key":"ref6","first-page":"8632","article-title":"A little is enough: Circumventing defenses for distributed learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Baruch"},{"key":"ref7","first-page":"1623","article-title":"Local model poisoning attacks to byzantine-robust federated learning","volume-title":"Proc. 29th USENIX Conf. Secur. Symp.","author":"Fang"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2023\/508"},{"key":"ref10","article-title":"Adaptive federated optimization","author":"Reddi","year":"2020"},{"key":"ref11","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. 23rd Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref12","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume-title":"Proc. 34th Int. Conf. Neural Inf. Process. Syst.","author":"Wang"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539231"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"ref15","first-page":"5636","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref16","first-page":"5311","article-title":"Learning from history for byzantine robust optimization","volume-title":"Proc. 38th Int. Conf. Mach. Learn.","author":"Karimireddy"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3093711"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3333555"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3350206"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011544"},{"key":"ref21","first-page":"261","article-title":"Fall of empires: Breaking byzantine-tolerant SGD by inner product manipulation","volume-title":"Proc. 35th Uncertainty Artif. Intell. Conf.","author":"Xie"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW56347.2022.00383"},{"key":"ref23","article-title":"Can you really backdoor federated learning?","author":"Sun","year":"2019"},{"key":"ref24","first-page":"118","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Blanchard"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2023.3237397"},{"key":"ref26","first-page":"11372","article-title":"CRFL: Certifiably robust federated learning against backdoor attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Xie"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2021.3099723"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE53745.2022.00077"},{"key":"ref29","first-page":"907","article-title":"Characterizing internal evasion attacks in federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Kim"},{"key":"ref30","article-title":"Generalized byzantine-tolerant SGD","author":"Xie","year":"2018"},{"key":"ref31","volume-title":"An Introduction to Optimization","author":"Chong","year":"2013"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464816"},{"key":"ref33","article-title":"UMAP: Uniform manifold approximation and projection for dimension reduction","author":"McInnes","year":"2018"},{"key":"ref34","first-page":"35007","article-title":"Learning to attack federated learning: A model-based reinforcement learning attack framework","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref35","first-page":"1273","article-title":"On the convergence of FedAvg on non-IID data","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Li"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330765"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2017.7966217"},{"key":"ref38","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01045"},{"issue":"1","key":"ref40","first-page":"3","article-title":"A public domain dataset for human activity recognition using smartphones","volume":"3","author":"Anguita","year":"2013","journal-title":"Esann"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1561\/9781680837896"},{"key":"ref42","first-page":"429","article-title":"Federated optimization in heterogeneous networks","volume-title":"Proc. Mach. Learn. Syst.","volume":"2","author":"Li"},{"key":"ref43","first-page":"1","article-title":"Secure federated learning against model poisoning attacks via client filtering","volume-title":"Proc. ICLR Workshop Backdoor Attacks Defenses Mach. Learn.","author":"Yaldiz"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i8.20903"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3212174"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11354469\/11146550.pdf?arnumber=11146550","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T23:23:22Z","timestamp":1768951402000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11146550\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1]]},"references-count":45,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3604514","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1]]}}}