{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:41:08Z","timestamp":1783438868032,"version":"3.54.6"},"reference-count":38,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"UNSW Canberra and Australian Research","award":["DE230100116"],"award-info":[{"award-number":["DE230100116"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,1]]},"DOI":"10.1109\/tdsc.2025.3604778","type":"journal-article","created":{"date-parts":[[2025,9,2]],"date-time":"2025-09-02T17:33:00Z","timestamp":1756834380000},"page":"175-192","source":"Crossref","is-referenced-by-count":1,"title":["LGP: Layerwise Gradient Purify for Robust Federated Learning Against Poisoning Attacks"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4366-1373","authenticated-orcid":false,"given":"Wael","family":"Issa","sequence":"first","affiliation":[{"name":"University of New South Wales, Canberra, ACT, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6127-9349","authenticated-orcid":false,"given":"Nour","family":"Moustafa","sequence":"additional","affiliation":[{"name":"University of New South Wales, Canberra, ACT, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0440-5032","authenticated-orcid":false,"given":"Benjamin","family":"Turnbull","sequence":"additional","affiliation":[{"name":"University of New South Wales, Canberra, ACT, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1235-9673","authenticated-orcid":false,"given":"Zahir","family":"Tari","sequence":"additional","affiliation":[{"name":"RMIT University, Melbourne, VIC, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","first-page":"119","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. Adv. neural Inf. Process. Syst.","author":"Blanchard"},{"key":"ref2","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in Byzantium","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Guerraoui"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/DSN58367.2023.00036"},{"key":"ref4","first-page":"261","article-title":"Fall of empires: Breaking Byzantine-tolerant SGD by inner product manipulation","volume-title":"Proc. 35th Uncertainty Artif. Intell. Conf.","author":"Xie"},{"key":"ref5","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. 23rd Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS54860.2022.00120"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"ref9","first-page":"1605","article-title":"Local model poisoning attacks to Byzantine-Robust federated learning","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Fang"},{"key":"ref10","first-page":"8632","article-title":"A little is enough: Circumventing defenses for distributed learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Baruch"},{"key":"ref11","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bhagoji"},{"key":"ref12","first-page":"11372","article-title":"CRFL: Certifiably robust federated learning against backdoor attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Xie"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3128646"},{"key":"ref14","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wang"},{"key":"ref15","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3154503"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2022.3153135"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW56347.2022.00383"},{"key":"ref19","first-page":"10320","article-title":"DETOX: A redundancy-based framework for faster and more robust gradient aggregation","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Rajput"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011544"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2021.3128164"},{"key":"ref22","first-page":"5311","article-title":"Learning from history for Byzantine robust optimization","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Karimireddy"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2023.3237397"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9054676"},{"key":"ref25","first-page":"560","article-title":"signSGD: Compressed optimisation for non-convex problems","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bernstein"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/CCWC60891.2024.10427896"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom53373.2021.00071"},{"key":"ref28","first-page":"5972","article-title":"No fear of heterogeneity: Classifier calibration for federated learning with non-IID data","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Luo"},{"key":"ref29","first-page":"3519","article-title":"Similarity of neural network representations revisited","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Kornblith"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2016.2608001"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1016\/j.physa.2021.126433"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2014.08.081"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref34","first-page":"32","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref35","first-page":"649","article-title":"Character-level convolutional networks for text classification","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhang"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3022862"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"ref38","first-page":"301","article-title":"The limitations of federated learning in sybil settings","volume-title":"Proc. 23rd Int. Symp. Res. Attacks Intrusions Defenses","author":"Fung"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11354469\/11146597.pdf?arnumber=11146597","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T23:22:58Z","timestamp":1768951378000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11146597\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1]]},"references-count":38,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3604778","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1]]}}}