{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,26]],"date-time":"2026-03-26T07:29:50Z","timestamp":1774510190174,"version":"3.50.1"},"reference-count":65,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001381","name":"National Research Foundation, Singapore and Infocomm Media Development Authority under its Trust Tech Funding Initiative, and Singapore Ministry of Education Academic Research Fund","doi-asserted-by":"publisher","award":["RG91\/22"],"award-info":[{"award-number":["RG91\/22"]}],"id":[{"id":"10.13039\/501100001381","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3533907","type":"journal-article","created":{"date-parts":[[2025,1,24]],"date-time":"2025-01-24T18:28:39Z","timestamp":1737743319000},"page":"2632-2647","source":"Crossref","is-referenced-by-count":26,"title":["Toward Efficient and Certified Recovery From Poisoning Attacks in Federated Learning"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3349-3863","authenticated-orcid":false,"given":"Yu","family":"Jiang","sequence":"first","affiliation":[{"name":"College of Computing and Data Science (CCDS), Nanyang Technological University, Jurong West, Singapore"}]},{"given":"Jiyuan","family":"Shen","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science (CCDS), Nanyang Technological University, Jurong West, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4060-0839","authenticated-orcid":false,"given":"Ziyao","family":"Liu","sequence":"additional","affiliation":[{"name":"Digital Trust Centre (DTC), Nanyang Technological University, Jurong West, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6624-9752","authenticated-orcid":false,"given":"Chee Wei","family":"Tan","sequence":"additional","affiliation":[{"name":"College of Computing and Data Science (CCDS), Nanyang Technological University, Jurong West, Singapore"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7479-7970","authenticated-orcid":false,"given":"Kwok-Yan","family":"Lam","sequence":"additional","affiliation":[{"name":"CCDS and DTC, Nanyang Technological University, Jurong West, Singapore"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1561\/2200000083"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/OJCOMS.2024.3423362"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2021.106775"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/tbdata.2022.3190835"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2020.2975749"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.3390\/bdcc7020108"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2022.110178"},{"key":"ref9","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2024.3410014"},{"key":"ref11","first-page":"119","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","author":"Blanchard"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63076-8_1"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539231"},{"key":"ref14","article-title":"Learning to detect malicious clients for robust federated learning","author":"Li","year":"2020","journal-title":"arXiv:2002.00211"},{"key":"ref15","first-page":"508","article-title":"AUROR: Defending against poisoning attacks in collaborative deep learning systems","volume-title":"Proc. 32nd Annu. Conf. Comput. Security Appl.","author":"Shen"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179336"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/IWQOS52092.2021.9521274"},{"key":"ref18","article-title":"Federated unlearning: How to efficiently erase a client in FL?","author":"Halimi","year":"2022","journal-title":"arXiv:2207.05521"},{"key":"ref19","article-title":"Privacy-preserving federated unlearning with certified client removal","author":"Liu","year":"2024","journal-title":"arXiv:2404.09724"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM48880.2022.9796721"},{"key":"ref21","article-title":"Guaranteeing data privacy in federated unlearning with dynamic user participation","author":"Liu","year":"2024","journal-title":"arXiv:2406.00966"},{"key":"ref22","article-title":"Threats, attacks, and defenses in machine unlearning: A survey","author":"Liu","year":"2024","journal-title":"arXiv:2403.13682"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.14778\/3641204.3641220"},{"issue":"1","key":"ref24","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3679014","article-title":"A survey on federated unlearning: Challenges, methods, and future directions","volume":"57","author":"Liu","year":"2025","journal-title":"ACM Comput. Surv."},{"key":"ref25","first-page":"8632","article-title":"A little is enough: Circumventing defenses for distributed learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NIPS)","author":"Baruch"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/tdsc.2024.3355458"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3163592"},{"key":"ref29","article-title":"Generalized Byzantine-tolerant SGD","author":"Xie","year":"2018","journal-title":"arXiv:1802.10116"},{"key":"ref30","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref31","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in Byzantium","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"El Mhamdi"},{"key":"ref32","first-page":"1605","article-title":"Local model poisoning attacks to Byzantine-robust federated learning","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Fang"},{"key":"ref33","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. 20th Int. Conf. Artif. Intell. Statist.","author":"McMahan"},{"key":"ref34","first-page":"429","article-title":"Federated optimization in heterogeneous networks","volume-title":"Proc. Mach. Learn. Syst.","author":"Li"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/LCOMM.2023.3286478"},{"key":"ref36","first-page":"7611","article-title":"Tackling the objective inconsistency problem in heterogeneous federated optimization","volume-title":"Proc. NIPS","author":"Wang"},{"key":"ref37","first-page":"5132","article-title":"SCAFFOLD: Stochastic controlled averaging for federated learning","volume-title":"Proc. 37th Int. Conf. Mach. Learn.","volume":"119","author":"Karimireddy"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"ref39","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017","journal-title":"arXiv:1708.06733"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.3021407"},{"key":"ref42","first-page":"1505","article-title":"Blind backdoors in deep learning models","volume-title":"Proc. 30th USENIX Secur. Symp. (USENIX Secur.)","author":"Bagdasaryan"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i07.6871"},{"key":"ref44","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Bhagoji"},{"key":"ref45","first-page":"1","article-title":"DBA: Distributed backdoor attacks against federated learning","volume-title":"Proc. 8th Int. Conf. Learn. Represent. (ICLR)","author":"Xie"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i8.16849"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3295949"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3372634"},{"key":"ref49","volume-title":"Elements of Information Theory","author":"Cover","year":"1999"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00983"},{"key":"ref51","first-page":"26293","article-title":"Personalized federated learning via variational Bayesian inference","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3108434"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3169918"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1561\/9781601988195"},{"key":"ref56","article-title":"SIFU: Sequential informed federated unlearning for efficient and provable client unlearning in federated optimization","author":"Fraboni","year":"2022","journal-title":"arXiv:2211.11656"},{"key":"ref57","article-title":"Certified data removal from machine learning models","author":"Guo","year":"2019","journal-title":"arXiv:1911.03030"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611974997"},{"key":"ref59","article-title":"Adam: A method for stochastic optimization","author":"Kingma","year":"2014","journal-title":"arXiv:1412.6980"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2211477"},{"key":"ref62","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017","journal-title":"arXiv:1708.07747"},{"key":"ref63","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref64","first-page":"649","article-title":"Character-level convolutional networks for text classification","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst. (NeurIPS)","author":"Zhang"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.03762"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/10852413.pdf?arnumber=10852413","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,14]],"date-time":"2025-03-14T17:46:33Z","timestamp":1741974393000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10852413\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":65,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3533907","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}