{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T14:14:52Z","timestamp":1784211292413,"version":"3.55.0"},"reference-count":42,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2021,1,1]],"date-time":"2021-01-01T00:00:00Z","timestamp":1609459200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62020106013"],"award-info":[{"award-number":["62020106013"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61972454"],"award-info":[{"award-number":["61972454"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61802051"],"award-info":[{"award-number":["61802051"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61772121"],"award-info":[{"award-number":["61772121"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61728102"],"award-info":[{"award-number":["61728102"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100012542","name":"Sichuan Science and Technology Program","doi-asserted-by":"publisher","award":["2020JDTD0007"],"award-info":[{"award-number":["2020JDTD0007"]}],"id":[{"id":"10.13039\/100012542","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100012542","name":"Sichuan Science and Technology Program","doi-asserted-by":"publisher","award":["2020YFG0298"],"award-info":[{"award-number":["2020YFG0298"]}],"id":[{"id":"10.13039\/100012542","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002865","name":"Chongqing Science and Technology Commission","doi-asserted-by":"publisher","award":["cstc2018jcyjAX0703"],"award-info":[{"award-number":["cstc2018jcyjAX0703"]}],"id":[{"id":"10.13039\/501100002865","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for Chinese Central Universities","doi-asserted-by":"publisher","award":["ZYGX2020ZB027"],"award-info":[{"award-number":["ZYGX2020ZB027"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2021]]},"DOI":"10.1109\/tifs.2021.3108434","type":"journal-article","created":{"date-parts":[[2021,8,30]],"date-time":"2021-08-30T20:52:03Z","timestamp":1630356723000},"page":"4574-4588","source":"Crossref","is-referenced-by-count":333,"title":["Privacy-Enhanced Federated Learning Against Poisoning Adversaries"],"prefix":"10.1109","volume":"16","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2625-3896","authenticated-orcid":false,"given":"Xiaoyuan","family":"Liu","sequence":"first","affiliation":[{"name":"School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1961-7946","authenticated-orcid":false,"given":"Hongwei","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9764-9345","authenticated-orcid":false,"given":"Guowen","family":"Xu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zongqi","family":"Chen","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, University of Electronic Science and Technology of China, Chengdu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaoming","family":"Huang","sequence":"additional","affiliation":[{"name":"CETC Cyberspace Security Research Institute Company Ltd., Chengdu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5720-0941","authenticated-orcid":false,"given":"Rongxing","family":"Lu","sequence":"additional","affiliation":[{"name":"Faculty of Computer Science (FCS), University of New Brunswick (UNB), Fredericton, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"ref35","article-title":"ADADELTA: An adaptive learning rate method","author":"zeiler","year":"2012","journal-title":"arXiv 1212 5701"},{"key":"ref12","first-page":"1310","article-title":"Privacy-preserving deep learning","author":"shokri","year":"2015","journal-title":"Proc 53rd Annu Allerton Conf Commun Control Comput (Allerton)"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363207"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3012480"},{"key":"ref37","article-title":"Generalized Byzantine-tolerant SGD","author":"xie","year":"2018","journal-title":"arXiv 1802 10116"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417885"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.2986205"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-00296-0_5"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-48910-X_16"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1007\/s12083-019-00869-2"},{"key":"ref33","article-title":"Distributed momentum for byzantine-resilient learning","author":"el-mhamdi","year":"2020","journal-title":"arXiv 2003 00010"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1016\/S0893-6080(98)00116-6"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.001.1900461"},{"key":"ref1","article-title":"Advances and open problems in federated learning","author":"kairouz","year":"2019","journal-title":"arXiv 1912 04977"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3005909"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363216"},{"key":"ref19","first-page":"1895","article-title":"Evaluating differentially private machine learning in practice","author":"jayaraman","year":"2019","journal-title":"Proc USENIX Security07"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24351"},{"key":"ref24","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in byzantium","author":"guerraoui","year":"2018","journal-title":"Proc ICML"},{"key":"ref23","first-page":"8632","article-title":"A little is enough: Circumventing defenses for distributed learning","author":"baruch","year":"2019","journal-title":"Proc NeurIPS"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"ref25","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","author":"yin","year":"2018","journal-title":"Proc ICML"},{"key":"ref20","first-page":"10320","article-title":"DETOX: A redundancy-based framework for faster and more robust gradient aggregation","author":"rajput","year":"2019","journal-title":"Proc NeurIPS"},{"key":"ref42","first-page":"1","article-title":"Slalom: Fast, verifiable and private execution of neural networks in trusted hardware","author":"tramer","year":"2018","journal-title":"Proc ICLR"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM41043.2020.9155414"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2020.3041404"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3154503"},{"key":"ref28","article-title":"Poisoning attacks against support vector machines","author":"biggio","year":"2012","journal-title":"arXiv 1206 6389"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2929409"},{"key":"ref29","first-page":"2938","article-title":"How to backdoor federated learning","author":"bagdasaryan","year":"2020","journal-title":"Proc PMLR AISTATS"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2020.2977378"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2981379"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"ref3","doi-asserted-by":"crossref","first-page":"133","DOI":"10.1007\/978-3-030-32692-0_16","article-title":"Privacy-preserving federated brain tumour segmentation","volume":"11861","author":"zhu","year":"2019","journal-title":"Machine Learning in Medical Imaging"},{"key":"ref6","first-page":"119","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","author":"blanchard","year":"2017","journal-title":"Proc NeurIPS"},{"key":"ref5","article-title":"Inverting gradients&#x2014;How easy is it to break privacy in federated learning?","author":"geiping","year":"2020","journal-title":"arXiv 2003 14053"},{"key":"ref40","first-page":"1605","article-title":"Local model poisoning attacks to byzantine-robust federated learning","author":"fang","year":"2020","journal-title":"Proc USENIX Security07"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9151439\/09524709.pdf?arnumber=9524709","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,2,4]],"date-time":"2023-02-04T04:58:43Z","timestamp":1675486723000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/9524709\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021]]},"references-count":42,"URL":"https:\/\/doi.org\/10.1109\/tifs.2021.3108434","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021]]}}}