{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,20]],"date-time":"2026-03-20T16:28:24Z","timestamp":1774024104535,"version":"3.50.1"},"reference-count":30,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2024.3490861","type":"journal-article","created":{"date-parts":[[2024,11,4]],"date-time":"2024-11-04T18:34:42Z","timestamp":1730745282000},"page":"175-190","source":"Crossref","is-referenced-by-count":8,"title":["Evaluating Security and Robustness for Split Federated Learning Against Poisoning Attacks"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-7440-554X","authenticated-orcid":false,"given":"Xiaodong","family":"Wu","sequence":"first","affiliation":[{"name":"Department of Electrical and Computer Engineering and the Ingenuity Labs Research Institute, Queen&#x2019;s University, Kingston, ON, Canada"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-5927-1584","authenticated-orcid":false,"given":"Henry","family":"Yuan","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, Queen&#x2019;s University, Kingston, ON, Canada"}]},{"given":"Xiangman","family":"Li","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering and the Ingenuity Labs Research Institute, Queen&#x2019;s University, Kingston, ON, Canada"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5639-0883","authenticated-orcid":false,"given":"Jianbing","family":"Ni","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering and the Ingenuity Labs Research Institute, Queen&#x2019;s University, Kingston, ON, Canada"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5720-0941","authenticated-orcid":false,"given":"Rongxing","family":"Lu","sequence":"additional","affiliation":[{"name":"Faculty of Computer Science, University of New Brunswick, Fredericton, NB, Canada"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i8.20825"},{"key":"ref2","article-title":"Split learning for health: Distributed deep learning without sharing raw patient data","author":"Vepakomma","year":"2018","journal-title":"arXiv:1812.00564"},{"key":"ref3","first-page":"1595","article-title":"PrivateFL: Accurate, differentially private federated learning via personalized data transformation","volume-title":"Proc. USENIX Secur.","author":"Yang"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/DSN58367.2023.00037"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3108434"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.2988575"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.23112"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.23171"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/DSN58367.2023.00033"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SPW59333.2023.00010"},{"key":"ref11","first-page":"1","article-title":"Every vote counts: Ranking-based training of federated learning to resist poisoning attacks","volume-title":"Proc. USENIX Secur.","author":"Mozaffari"},{"key":"ref12","first-page":"39299","article-title":"Data poisoning attacks against multimodal encoders","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yang"},{"key":"ref13","article-title":"BERT: Pre-training of deep bidirectional transformers for language understanding","author":"Devlin","year":"2018","journal-title":"arXiv:1810.04805"},{"key":"ref14","first-page":"5753","article-title":"XlNet: Generalized autoregressive pretraining for language understanding","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Yang"},{"key":"ref15","article-title":"Poisoning attacks against support vector machines","author":"Biggio","year":"2012","journal-title":"arXiv:1206.6389"},{"key":"ref16","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Bhagoji"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom\/BigDataSE.2019.00057"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3169918"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-23599-3_30"},{"key":"ref20","article-title":"Analyzing the vulnerabilities in SplitFed learning: Assessing the robustness against data poisoning attacks","author":"Ismail","year":"2023","journal-title":"arXiv:2307.03197"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1145\/3560905.3568302"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58951-6_24"},{"key":"ref23","article-title":"Mitigating sybils in federated learning poisoning","author":"Fung","year":"2018","journal-title":"arXiv:1808.04866"},{"key":"ref24","first-page":"7587","article-title":"SparseFed: Mitigating model poisoning attacks in federated learning with sparsification","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Panda"},{"key":"ref25","article-title":"FLTrust: Byzantine-robust federated learning via trust bootstrapping","author":"Cao","year":"2020","journal-title":"arXiv:2012.13995"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23156"},{"key":"ref28","article-title":"Explaining and harnessing adversarial examples","author":"Goodfellow","year":"2014","journal-title":"arXiv:1412.6572"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833647"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/10741585.pdf?arnumber=10741585","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T08:20:29Z","timestamp":1735719629000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10741585\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":30,"URL":"https:\/\/doi.org\/10.1109\/tifs.2024.3490861","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}