{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T02:13:19Z","timestamp":1773713599123,"version":"3.50.1"},"reference-count":54,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62441226"],"award-info":[{"award-number":["62441226"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62372356"],"award-info":[{"award-number":["62372356"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100018925","name":"111 Center","doi-asserted-by":"crossref","award":["B16037"],"award-info":[{"award-number":["B16037"]}],"id":[{"id":"10.13039\/501100018925","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,3]]},"DOI":"10.1109\/tdsc.2025.3627244","type":"journal-article","created":{"date-parts":[[2025,11,20]],"date-time":"2025-11-20T18:44:52Z","timestamp":1763664292000},"page":"3285-3302","source":"Crossref","is-referenced-by-count":0,"title":["Enhancing Security and Privacy in Multi-Server Federated Learning"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-8037-6769","authenticated-orcid":false,"given":"Xingwen","family":"Zhao","sequence":"first","affiliation":[{"name":"State Key Laboratory of Integrated Service Networks, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-0305-9013","authenticated-orcid":false,"given":"Yongfeng","family":"Bu","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Service Networks, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6870-6657","authenticated-orcid":false,"given":"Kai","family":"Fan","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Service Networks, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8310-7169","authenticated-orcid":false,"given":"Hui","family":"Li","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Integrated Service Networks, Xidian University, Xi&#x2019;an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. Artif. Intell. Statist.","author":"McMahan","year":"2017"},{"key":"ref2","article-title":"Fully decentralized federated learning","volume-title":"Proc. 3rd Workshop Bayesian Deep Learn.","volume":"2","author":"Lalitha","year":"2018"},{"issue":"6","key":"ref3","doi-asserted-by":"crossref","first-page":"156","DOI":"10.1109\/MNET.001.2100253","article-title":"Decentralized federated learning for UAV networks: Architecture, challenges, and opportunities","volume":"35","author":"Qu","year":"2021","journal-title":"IEEE Netw."},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.3233\/978-1-61499-098-7-870"},{"key":"ref5","first-page":"4583","article-title":"Federated variance-reduced stochastic gradient descent with robustness to Byzantine attacks","volume-title":"IEEE Trans. Signal Process.","volume":"68","author":"Wu","year":"2020"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011544"},{"key":"ref7","article-title":"iDLG: Improved deep leakage from gradients","author":"Zhao","year":"2020"},{"key":"ref8","first-page":"14747","article-title":"Deep leakage from gradients","volume-title":"Proc. Adv. Neural Inf. Process. Syst. 32: Annu. Conf. Neural Inf. Process. Syst.","author":"Zhu","year":"2019"},{"key":"ref9","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin","year":"2018"},{"key":"ref10","first-page":"119","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. Adv. Neural Inf. Process. Syst. 30: Annu. Conf. Neural Inf. Process. Syst.","author":"Blanchard","year":"2017"},{"issue":"3\u20134","key":"ref11","first-page":"211","article-title":"The algorithmic foundations of differential privacy","volume-title":"Found. Trends Theor. Comput. Sci.","volume":"9","author":"Dwork","year":"2013"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/1536414.1536440"},{"key":"ref13","first-page":"160","article-title":"Protocols for secure computations","volume-title":"Proc. 23rd Annu. Symp. Found. Comput. Sci.","author":"Yao","year":"1982"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3433638"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/3547139"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-5906-5"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-024-10766-7"},{"key":"ref19","article-title":"Differentially private federated learning: A systematic review","author":"Fu","year":"2024"},{"key":"ref20","first-page":"5311","article-title":"Learning from history for Byzantine robust optimization","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Karimireddy","year":"2021"},{"key":"ref21","first-page":"8632","article-title":"A little is enough: Circumventing defenses for distributed learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst. 32: Annu. Conf. Neural Inf. Process. Syst.","author":"Baruch","year":"2019"},{"key":"ref22","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2021.24434","article-title":"Fltrust: Byzantine-robust federated learning via trust bootstrapping","volume-title":"Proc. 28th Annu. Netw. Distrib. Syst. Secur. Symp., NDSS 2021, Virtually","author":"Cao","year":"2021"},{"key":"ref23","first-page":"301","article-title":"The limitations of federated learning in sybil settings","volume-title":"Proc. 23rd Int. symp. Res. Attacks, Intrusions Defenses","author":"Fung","year":"2020"},{"key":"ref24","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2022.110178","article-title":"Fl-defender: Combating targeted attacks in federated learning","volume":"260","author":"Jebreel","year":"2023","journal-title":"Knowl.-Based Syst."},{"key":"ref25","doi-asserted-by":"crossref","first-page":"1639","DOI":"10.1109\/TIFS.2022.3169918","article-title":"ShieldFL: Mitigating model poisoning attacks in privacy-preserving federated learning","volume":"17","author":"Ma","year":"2022","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/tnnls.2022.3212627"},{"key":"ref27","doi-asserted-by":"crossref","first-page":"2059","DOI":"10.1109\/TIFS.2022.3176191","article-title":"PVD-FL: A privacy-preserving and verifiable decentralized federated learning framework","volume":"17","author":"Zhao","year":"2022","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/blockchain55522.2022.00034"},{"key":"ref29","article-title":"Decentralized federated learning: A segmented gossip approach","author":"Hu","year":"2019"},{"key":"ref30","first-page":"4574","article-title":"Privacy-enhanced federated learning against poisoning adversaries","volume-title":"IEEE Trans. Inf. Forensics Secur.","volume":"16","author":"Liu","year":"2021"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-025-11170-5"},{"key":"ref32","first-page":"365","article-title":"LSFLl: A lightweight and secure federated learning scheme for edge computing","volume-title":"IEEE Trans. Inf. Forensics Secur.","volume":"18","author":"Zhang","year":"2023"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/tits.2022.3152156"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2022.3215574"},{"key":"ref35","article-title":"Janus: Dual-server multi-round secure aggregation with verifiability for federated learning","author":"Pu","year":"2025"},{"key":"ref36","first-page":"2848","article-title":"Privacy-preserving byzantine-robust federated learning via blockchain systems","volume-title":"IEEE Trans. Inf. Forensics Secur.","volume":"17","author":"Miao","year":"2022"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/Blockchain55522.2022.00074"},{"issue":"5","key":"ref38","first-page":"614","article-title":"A blockchain-based audit approach for encrypted data in federated learning","volume-title":"Digit. Commun. Netw.","volume":"8","author":"Sun","year":"2022"},{"key":"ref39","first-page":"911","article-title":"VerifyNet: Secure and verifiable federated learning","volume-title":"IEEE Trans. Inf. Forensics Secur.","volume":"15","author":"Xu","year":"2020"},{"issue":"2","key":"ref40","first-page":"117","article-title":"Bandwidth optimal all-reduce algorithms for clusters of workstations","volume-title":"J. Parallel Distrib. Comput.","volume":"69","author":"Patarasuk","year":"2009"},{"key":"ref41","article-title":"Gossipgrad: Scalable deep learning using gossip communication based asynchronous gradient descent","author":"Daily","year":"2018"},{"issue":"11","key":"ref42","first-page":"2524","article-title":"Towards fair and privacy-preserving federated deep models","volume-title":"IEEE Trans. Parallel Distrib. Syst.","volume":"31","author":"Lyu","year":"2020"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOMWKSHPS51825.2021.9484437"},{"issue":"5","key":"ref44","first-page":"3492","article-title":"Security and privacy-enhanced federated learning for anomaly detection in IoT infrastructures","volume-title":"IEEE Trans. Ind. Informat.","volume":"18","author":"Cui","year":"2022"},{"key":"ref45","first-page":"1467","article-title":"Poisoning attacks against support vector machines","volume-title":"Proc. 29th Int. Conf. Mach. Learn.","author":"Biggio","year":"2012"},{"key":"ref46","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan","year":"2020"},{"key":"ref47","first-page":"739","article-title":"Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning","volume-title":"Proc. IEEE Symp. Secur. Privacy","author":"Nasr","year":"2019"},{"key":"ref48","first-page":"691","article-title":"Exploiting unintended feature leakage in collaborative learning","volume-title":"Proc. IEEE Symp. Secur. Privacy","author":"Melis","year":"2019"},{"key":"ref49","first-page":"16937","article-title":"Inverting gradients-how easy is it to break privacy in federated learning?","volume":"33","author":"Geiping","journal-title":"in Proc. Adv. Neural Inf. Process. Syst."},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3724113"},{"key":"ref51","first-page":"142","article-title":"Learning word vectors for sentiment analysis","volume-title":"Proc. 49th Annu. Meeting Assoc. Comput. Linguist.: Hum. Lang. Technol.","author":"Maas","year":"2011"},{"key":"ref52","article-title":"Very deep convolutional networks for large-scale image recognition","author":"Simonyan","year":"2014"},{"key":"ref53","doi-asserted-by":"crossref","first-page":"319","DOI":"10.1007\/3-540-46805-6","article-title":"Object recognition with gradient-based learning","volume-title":"Proc. Shape, Contour Grouping Comput. Vis.","author":"Forsyth","year":"1999"},{"key":"ref54","article-title":"Cronus: Robust and heterogeneous collaborative learning with black-box knowledge transfer","author":"Chang","year":"2019"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11434575\/11261884.pdf?arnumber=11261884","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T01:16:20Z","timestamp":1773710180000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11261884\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3]]},"references-count":54,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3627244","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3]]}}}