{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T02:12:51Z","timestamp":1773713571703,"version":"3.50.1"},"reference-count":39,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,3,1]],"date-time":"2026-03-01T00:00:00Z","timestamp":1772323200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U2333207"],"award-info":[{"award-number":["U2333207"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62271128"],"award-info":[{"award-number":["62271128"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62472020"],"award-info":[{"award-number":["62472020"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Key R&#x0026;D projects of Sichuan Provincial Science and Technology Plan","award":["2022ZDZX0004"],"award-info":[{"award-number":["2022ZDZX0004"]}]},{"name":"Sichuan Provincial Science and Technology Plan"},{"name":"Unveiling and Leading","award":["2023YFG0374"],"award-info":[{"award-number":["2023YFG0374"]}]},{"name":"Unveiling and Leading","award":["2023YFG0373"],"award-info":[{"award-number":["2023YFG0373"]}]},{"name":"Sichuan Province Regional Innovation Cooperation Project","award":["2025YFHZ0302"],"award-info":[{"award-number":["2025YFHZ0302"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Dependable and Secure Comput."],"published-print":{"date-parts":[[2026,3]]},"DOI":"10.1109\/tdsc.2025.3630175","type":"journal-article","created":{"date-parts":[[2025,11,6]],"date-time":"2025-11-06T18:55:47Z","timestamp":1762455347000},"page":"2745-2759","source":"Crossref","is-referenced-by-count":0,"title":["How to Defend Against Large-Scale Model Poisoning Attacks in Federated Learning: A Vertical Solution"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6562-818X","authenticated-orcid":false,"given":"Jinbo","family":"Wang","sequence":"first","affiliation":[{"name":"School of Information and Software Engineering, University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2222-9178","authenticated-orcid":false,"given":"Ruijin","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Information and Software Engineering, University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2300-8817","authenticated-orcid":false,"given":"Fengli","family":"Zhang","sequence":"additional","affiliation":[{"name":"School of Information and Software Engineering, University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. Artif. Intell. Statist.","author":"McMahan"},{"key":"ref2","doi-asserted-by":"crossref","DOI":"10.1016\/j.knosys.2025.113339","article-title":"Stand-in model protection: Synthetic defense for membership inference and model inversion attacks","volume":"316","author":"Chen","year":"2025","journal-title":"Knowl.-Based Syst."},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"ref4","first-page":"16937","article-title":"Inverting gradients-how easy is it to break privacy in federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Geiping"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3538266"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3585385"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103270"},{"key":"ref8","first-page":"1605","article-title":"Local model poisoning attacks to $\\lbrace${Byzantine-Robust$\\rbrace$} federated learning","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Fang"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW56347.2022.00383"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.017.2100714"},{"key":"ref11","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/MC.2017.62"},{"key":"ref14","first-page":"119","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. Adv. Neural Inf. Process. Syst. 30","author":"Blanchard"},{"key":"ref15","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref16","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in byzantium","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Guerraoui"},{"key":"ref17","first-page":"508","article-title":"Auror: Defending against poisoning attacks in collaborative deep learning systems","volume-title":"Proc. 32nd Annu. Conf. Comput. Secur. Appl.","author":"Shen"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3108434"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3169918"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-17143-7_22"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.52202\/079017-3314"},{"key":"ref22","article-title":"Fltrust: Byzantine-robust federated learning via trust bootstrapping","author":"Cao","year":"2022"},{"key":"ref23","article-title":"Protecting federated learning from extreme model poisoning attacks via multidimensional time series anomaly detection","author":"Gabrielli","year":"2024"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539231"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2021.3116668"},{"key":"ref26","article-title":"Very deep vaes generalize autoregressive models and can outperform them on images","author":"Child","year":"2021"},{"key":"ref27","article-title":"Scaling autoregressive models for content-rich text-to-image generation","author":"Yu","year":"2022"},{"key":"ref28","first-page":"597","article-title":"Convergence analysis of two-layer neural networks with relu activation","volume-title":"Proc. 31st Int. Conf. Neural Inf. Process. Syst.","author":"Li"},{"key":"ref29","article-title":"A convergence analysis of gradient descent for deep linear neural networks","author":"Arora","year":"2019"},{"key":"ref30","article-title":"On the convergence of fedavg on non-IID data","author":"Li","year":"2020"},{"key":"ref31","article-title":"Untargeted attack against federated recommendation systems via poisonous item embeddings and the defense","author":"Yu","year":"2022"},{"key":"ref32","article-title":"FedREDefense: Defending against model poisoning attacks for federated learning using model update reconstruction error","volume-title":"Proc. 41st Int. Conf. Mach. Learn.","author":"Xie"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"ref34","article-title":"Learning transferable visual models from natural language supervision","author":"Radford","year":"2021"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1002\/rsa.20218"},{"key":"ref37","volume-title":"A Little is Enough: Circumventing Defenses for Distributed Learning","author":"Baruch","year":"2019"},{"key":"ref38","article-title":"Adam: A method for stochastic optimization","author":"Kingma","year":"2017"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TSMC.1971.4308316"}],"container-title":["IEEE Transactions on Dependable and Secure Computing"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/8858\/11434575\/11231098.pdf?arnumber=11231098","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,17]],"date-time":"2026-03-17T01:15:28Z","timestamp":1773710128000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11231098\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,3]]},"references-count":39,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tdsc.2025.3630175","relation":{},"ISSN":["1545-5971","1941-0018","2160-9209"],"issn-type":[{"value":"1545-5971","type":"print"},{"value":"1941-0018","type":"electronic"},{"value":"2160-9209","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,3]]}}}