{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,20]],"date-time":"2026-03-20T06:25:08Z","timestamp":1773987908327,"version":"3.50.1"},"reference-count":51,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF","doi-asserted-by":"publisher","award":["ECCS#1923739"],"award-info":[{"award-number":["ECCS#1923739"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2023]]},"DOI":"10.1109\/tifs.2023.3280032","type":"journal-article","created":{"date-parts":[[2023,5,25]],"date-time":"2023-05-25T17:47:54Z","timestamp":1685036874000},"page":"3289-3304","source":"Crossref","is-referenced-by-count":29,"title":["SAFELearning: Secure Aggregation in Federated Learning With Backdoor Detectability"],"prefix":"10.1109","volume":"18","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2710-5115","authenticated-orcid":false,"given":"Zhuosheng","family":"Zhang","sequence":"first","affiliation":[{"name":"Electrical and Computer Engineering Department, Stevens Institute of Technology, Hoboken, NJ, USA"}]},{"given":"Jiarui","family":"Li","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering Department, Stevens Institute of Technology, Hoboken, NJ, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6484-4382","authenticated-orcid":false,"given":"Shucheng","family":"Yu","sequence":"additional","affiliation":[{"name":"Electrical and Computer Engineering Department, Stevens Institute of Technology, Hoboken, NJ, USA"}]},{"given":"Christian","family":"Makaya","sequence":"additional","affiliation":[{"name":"HP Inc., Palo Alto, CA, USA"}]}],"member":"263","reference":[{"key":"ref13","article-title":"How to backdoor federated learning","author":"bagdasaryan","year":"2018","journal-title":"arXiv 1807 00459"},{"key":"ref12","article-title":"Poisoning attacks against support vector machines","author":"biggio","year":"2012","journal-title":"arXiv 1206 6389"},{"key":"ref15","first-page":"26","article-title":"SecureNN: Efficient and private neural network training","author":"wagh","year":"2019","journal-title":"Proc PETS"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"ref11","article-title":"Mitigating sybils in federated learning poisoning","author":"fung","year":"2018","journal-title":"arXiv 1808 04866"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"ref17","first-page":"35","article-title":"ABY3: A mixed protocol framework for machine learning","author":"mohassel","year":"2018","journal-title":"Proc ACM SIGSAC Conf Comput Commun Secur (CCS)"},{"key":"ref16","first-page":"1651","article-title":"Gazelle: A low latency framework for secure neural network inference","author":"juvekar","year":"2018","journal-title":"Proc 27th USENIX Secur Symp (USENIX Secur )"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3196494.3196522"},{"key":"ref51","first-page":"1737","article-title":"Deep learning with limited numerical precision","author":"gupta","year":"2015","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1976.1055638"},{"key":"ref46","first-page":"5330","article-title":"Can decentralized algorithms outperform centralized algorithms? A case study for decentralized parallel stochastic gradient descent","volume":"30","author":"lian","year":"2017","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref45","article-title":"On the convergence of FedAvg on non-IID data","author":"li","year":"2019","journal-title":"arXiv 1907 02189"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"ref47","first-page":"1","article-title":"DBA: Distributed backdoor attacks against federated learning","author":"xie","year":"2019","journal-title":"Proc Int Conf Learn Represent"},{"key":"ref42","article-title":"Mitigating Sybil attacks on differential privacy based federated learning","author":"jiang","year":"2020","journal-title":"arXiv 2010 10572"},{"key":"ref41","article-title":"Robust aggregation for adaptive privacy preserving federated learning in healthcare","author":"grama","year":"2020","journal-title":"arXiv 2009 08294"},{"key":"ref44","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","author":"mcmahan","year":"2017","journal-title":"Proc Artif Intell Statist"},{"key":"ref43","article-title":"SafeNet: The unreasonable effectiveness of ensembles in private collaborative learning","author":"chaudhari","year":"2022","journal-title":"arXiv 2205 09986"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3169918"},{"key":"ref8","article-title":"I have a dream! (differentially private smart metering)","author":"\u00e1cs","year":"2011","journal-title":"Proc Int Workshop Inf Hiding"},{"key":"ref7","article-title":"Privacy-preserving aggregation of time-series data","author":"shi","year":"2011","journal-title":"Proc Network and Distributed System Security Symp (NDSS)"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2015.2484326"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2018.2888775"},{"key":"ref3","year":"2019","journal-title":"Federated learning Collaborative machine learning without centralized training data"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-32946-3_15"},{"key":"ref5","article-title":"Advances and open problems in federated learning","author":"kairouz","year":"2019","journal-title":"arXiv 1912 04977"},{"key":"ref40","article-title":"Generalized Byzantine-tolerant SGD","author":"xie","year":"2018","journal-title":"arXiv 1802 10116"},{"key":"ref35","first-page":"1605","article-title":"Local model poisoning attacks to Byzantine-robust federated learning","author":"fang","year":"2020","journal-title":"Proc 29th USENIX Secur Symp (USENIX Secur )"},{"key":"ref34","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","author":"bhagoji","year":"2019","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45748-8_24"},{"key":"ref36","article-title":"A little is enough: Circumventing defenses for distributed learning","author":"baruch","year":"2019","journal-title":"arXiv 1902 06156"},{"key":"ref31","first-page":"1","article-title":"Trojaning attack on neural networks","author":"liu","year":"2017","journal-title":"Proc 25th Annu Netw Distrib Syst Secur Symp (NDSS)"},{"key":"ref30","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"gu","year":"2017","journal-title":"arXiv 1708 06733"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991125"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/2046684.2046692"},{"key":"ref2","year":"2019","journal-title":"Under the hood of the Pixel 2 How AI is supercharging hardware"},{"key":"ref1","article-title":"Federated learning: Strategies for improving communication efficiency","author":"kone?n?","year":"2016","journal-title":"arXiv 1610 05492"},{"key":"ref39","first-page":"903","article-title":"DRACO: Byzantine-resilient distributed training via redundant gradients","author":"chen","year":"2018","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref24","author":"bell","year":"2020","journal-title":"Secure Single-Server Vector Aggregation With (Poly)Logarithmic Overhead"},{"key":"ref23","article-title":"Differentially private federated learning: A client level perspective","author":"geyer","year":"2017","journal-title":"arXiv 1712 07557"},{"key":"ref26","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","author":"yin","year":"2018","journal-title":"Proc Int Conf Mach Learn"},{"key":"ref25","first-page":"119","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","author":"blanchard","year":"2017","journal-title":"Proc Adv Neural Inf Process Syst"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.30"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23241"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2021.103561"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3108434"},{"key":"ref29","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"chen","year":"2017","journal-title":"arXiv 1712 05526"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/10206\/9970396\/10136231-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10206\/9970396\/10136231.pdf?arnumber=10136231","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,6,26]],"date-time":"2023-06-26T18:30:25Z","timestamp":1687804225000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10136231\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"references-count":51,"URL":"https:\/\/doi.org\/10.1109\/tifs.2023.3280032","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023]]}}}