{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,21]],"date-time":"2026-01-21T14:02:14Z","timestamp":1769004134386,"version":"3.49.0"},"reference-count":43,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"1","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Natural Science Basic Research Program of Shaanxi Program","award":["2024JC-JCQN-67"],"award-info":[{"award-number":["2024JC-JCQN-67"]}]},{"name":"Shaanxi Province QinChuangYuan","award":["2022KXJ-054"],"award-info":[{"award-number":["2022KXJ-054"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,1]]},"DOI":"10.1109\/tdsc.2025.3618769","type":"journal-article","created":{"date-parts":[[2025,10,7]],"date-time":"2025-10-07T17:55:17Z","timestamp":1759859717000},"page":"1543-1559","source":"Crossref","is-referenced-by-count":0,"title":["Model Stability Defense Against Model Poisoning in Federated Learning"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5507-3424","authenticated-orcid":false,"given":"Qi","family":"Guo","sequence":"first","affiliation":[{"name":"Air Traffic Control and Navigation School, Air Force Engineering University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6979-3537","authenticated-orcid":false,"given":"Di","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7682-5653","authenticated-orcid":false,"given":"Yong","family":"Qi","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0394-4432","authenticated-orcid":false,"given":"Saiyu","family":"Qi","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1073-7810","authenticated-orcid":false,"given":"Qian","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Minghao","family":"Yao","sequence":"additional","affiliation":[{"name":"School of Computer Science and Technology, Xi&#x2019;an Jiaotong University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0262-7678","authenticated-orcid":false,"given":"Kaitai","family":"Liang","sequence":"additional","affiliation":[{"name":"Cybersecurity Group, Delft University of Technology, Delft, The Netherlands"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"McMahan","year":"2017"},{"key":"ref2","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin","year":"2018"},{"key":"ref3","first-page":"1","article-title":"FLTrust: Byzantine-robust federated learning via trust bootstrapping","volume-title":"Proc. 28th Annu. Netw. Distrib. Syst. Secur. Symp.","author":"Cao","year":"2021"},{"key":"ref4","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in Byzantium","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Guerraoui","year":"2018"},{"key":"ref5","first-page":"7587","article-title":"SparseFed: Mitigating model poisoning attacks in federated learning with sparsification","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Panda","year":"2022"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539231"},{"key":"ref7","first-page":"118","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. 31st Int. Conf. Neural Inf. Process. Syst.","author":"Blanchard","year":"2017"},{"key":"ref8","first-page":"1605","article-title":"Local model poisoning attacks to Byzantine-robust federated learning","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Fang","year":"2020"},{"key":"ref9","first-page":"8635","article-title":"A little is enough: Circumventing defenses for distributed learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Baruch","year":"2019"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2022.3212174"},{"key":"ref11","first-page":"54460","article-title":"FedREDefense: Defending against model poisoning attacks for federated learning using model update reconstruction error","volume-title":"Proc. 41st Int. Conf. Mach. Learn.","author":"Xie","year":"2024"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v39i18.34094"},{"key":"ref13","article-title":"FEDCLEAN: Byzantine defense by clustering errors of activation maps in non-IID federated learning environments","author":"Ghali","year":"2025"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2025.3555193"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3216981"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2024.3520134"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2025.3533029"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2024.3461449"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2021.3135422"},{"key":"ref20","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan","year":"2020"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"ref23","first-page":"6106","article-title":"Poison frogs! Targeted clean-label poisoning attacks on neural networks","volume-title":"Proc. 32nd Int. Conf. Neural Inf. Process. Syst.","author":"Shafahi","year":"2018"},{"key":"ref24","first-page":"1299","article-title":"When does machine learning FAIL? Generalized transferability for evasion and poisoning attacks","volume-title":"Proc. 27th USENIX Secur. Symp.","author":"Suciu","year":"2018"},{"key":"ref25","article-title":"Can you really backdoor federated learning?","author":"Sun","year":"2019"},{"key":"ref26","first-page":"1","article-title":"DBA: Distributed backdoor attacks against federated learning","volume-title":"Proc. Int. Conf. Learn. Representations","author":"Xie","year":"2020"},{"key":"ref27","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wang","year":"2020"},{"key":"ref28","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bhagoji","year":"2019"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref30","article-title":"Robust learning with Jacobian regularization","author":"Hoffman","year":"2019"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.4467\/20838476SI.18.003.10408"},{"key":"ref32","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.2118\/18761-MS"},{"key":"ref35","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017"},{"key":"ref36","first-page":"1097","article-title":"ImageNet classification with deep convolutional neural networks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Krizhevsky","year":"2012"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.5555\/2188385.2188395"},{"key":"ref38","first-page":"2960","article-title":"Practical Bayesian optimization of machine learning algorithms","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Snoek","year":"2012"},{"key":"ref39","first-page":"2113","article-title":"Gradient-based hyperparameter optimization through reversible learning","volume-title":"Proc. 32nd Int. Conf. Mach. Learn.","author":"Maclaurin","year":"2015"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/2834892.2834896"},{"key":"ref41","first-page":"649","article-title":"Character-level convolutional networks for text classification","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhang","year":"2015"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.5244\/C.30.87"},{"key":"ref43","article-title":"ALBERT: A lite BERT for self-supervised learning of language representations","volume-title":"Proc. 8th Int. Conf. Learn. Representations","author":"Lan","year":"2020"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11354469\/11194751.pdf?arnumber=11194751","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,20]],"date-time":"2026-01-20T23:23:13Z","timestamp":1768951393000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11194751\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,1]]},"references-count":43,"journal-issue":{"issue":"1"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3618769","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,1]]}}}