{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T09:17:27Z","timestamp":1780391847423,"version":"3.54.1"},"reference-count":54,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-nc-nd\/4.0\/"}],"funder":[{"DOI":"10.13039\/100006639","name":"German Research Foundation","doi-asserted-by":"publisher","award":["WA 3907\/7-1"],"award-info":[{"award-number":["WA 3907\/7-1"]}],"id":[{"id":"10.13039\/100006639","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Swedish Innovation Agency","award":["2021-04783"],"award-info":[{"award-number":["2021-04783"]}]},{"DOI":"10.13039\/501100004359","name":"Swedish Research Council","doi-asserted-by":"crossref","award":["2020-03687"],"award-info":[{"award-number":["2020-03687"]}],"id":[{"id":"10.13039\/501100004359","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100004359","name":"Swedish Research Council","doi-asserted-by":"crossref","award":["2023-05065"],"award-info":[{"award-number":["2023-05065"]}],"id":[{"id":"10.13039\/501100004359","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Wallenberg AI, Autonomous Systems and Software Program (WASP) funded by the Knut and Alice Wallenberg Foundation"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3539964","type":"journal-article","created":{"date-parts":[[2025,2,10]],"date-time":"2025-02-10T18:29:28Z","timestamp":1739212168000},"page":"2577-2592","source":"Crossref","is-referenced-by-count":27,"title":["FedGT: Identification of Malicious Clients in Federated Learning With Secure Aggregation"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5341-9954","authenticated-orcid":false,"given":"Marvin","family":"Xhemrishi","sequence":"first","affiliation":[{"name":"TUM School of Computation, Information and Technology, Technical University of Munich, Munich, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4138-0508","authenticated-orcid":false,"given":"Johan","family":"\u00d6stman","sequence":"additional","affiliation":[{"name":"AI Sweden, Gothenburg, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5174-1947","authenticated-orcid":false,"given":"Antonia","family":"Wachter-Zeh","sequence":"additional","affiliation":[{"name":"TUM School of Computation, Information and Technology, Technical University of Munich, Munich, Germany"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5725-869X","authenticated-orcid":false,"given":"Alexandre Graell i","family":"Amat","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering, Chalmers University of Technology, Gothenburg, Sweden"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. Int. Conf. Artif. Intell. Stats. (AISTATS)","volume":"54","author":"McMahan"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"ref4","article-title":"Data leakage in federated averaging","volume":"2022","author":"Dimitrov","year":"2022","journal-title":"Trans. Mach. Learn. Res."},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417885"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1561\/2200000083"},{"key":"ref8","first-page":"8635","article-title":"A little is enough: Circumventing defenses for distributed learning","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst. (NeurIPS)","author":"Baruch"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58951-6_24"},{"key":"ref10","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst. (NeurIPS)","author":"Wang"},{"key":"ref11","first-page":"301","article-title":"The limitations of federated learning in Sybil settings","volume-title":"Proc. Int. Symp. Res. Attacks, Intrusions Defenses (RAID)","author":"Fung"},{"key":"ref12","first-page":"119","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst. (NeurIPS)","author":"Blanchard"},{"key":"ref13","first-page":"5636","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Yin"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/ICPADS47876.2019.00042"},{"key":"ref15","article-title":"Learning to detect malicious clients for robust federated learning","author":"Li","year":"2020","journal-title":"arXiv:2002.00211"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3330144"},{"key":"ref17","first-page":"1415","article-title":"FLAME: Taming backdoors in federated learning","volume-title":"Proc. USENIX Secur.","author":"Nguyen"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539231"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.017.2100714"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1214\/aoms\/1177731363"},{"key":"ref21","first-page":"5315","article-title":"FLamby: Datasets and benchmarks for cross-silo federated learning in realistic healthcare settings","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","author":"Terrail"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"ref23","volume-title":"Project Aurora: The Power of Data, Technology and Collaboration to Combat Money Laundering Across Institutions and Borders","year":"2023"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijmedinf.2018.01.007"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2020.3041404"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2022.3153135"},{"key":"ref27","article-title":"SAFELearning: Enable backdoor detectability in federated learning with secure aggregation","author":"Zhang","year":"2021","journal-title":"arXiv:2102.02402"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2023.3237397"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1561\/0100000099"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2023-0030"},{"key":"ref31","volume-title":"The Theory of Error-correcting Codes","volume":"16","author":"MacWilliams","year":"1977"},{"key":"ref32","volume-title":"Bounds on the Minimum Distance of Linear Codes and Quantum Codes","author":"Grassl","year":"2007"},{"key":"ref33","volume-title":"Database of Channel Codes and ML Simulation Results","author":"Helmling","year":"2019"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1982.1056489"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1016\/0377-0427(87)90125-7"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1080\/01969727408546059"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/ISIT50566.2022.9834750"},{"key":"ref38","first-page":"694","article-title":"LightSecAgg: A lightweight and versatile design for secure aggregation in federated learning","volume-title":"Proc. Mach. Learn. Syst. (MLSys)","author":"So"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1974.1055186"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/18.910572"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1978.1055821"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/CISS50987.2021.9400279"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1021\/acs.jcim.3c00799"},{"key":"ref44","volume-title":"MNIST Handwritten Digit Database","author":"LeCun","year":"2010"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/ISBI.2018.8363547"},{"key":"ref47","volume-title":"CIFAR-10 (canadian Institute for Advanced Research)","author":"Krizhevsky","year":"2009"},{"key":"ref48","first-page":"6105","article-title":"EfficientNet: Rethinking model scaling for convolutional neural networks","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Tan"},{"key":"ref49","first-page":"1641","article-title":"Justinian\u2019s GAAvernor: Robust distributed learning with gradient aggregation agent","volume-title":"Proc. USENIX Secur. Symp.","author":"Pan"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"ref51","first-page":"840","article-title":"Sageflow: Robust federated learning against both stragglers and adversaries","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","author":"Park"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV.2017.324"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1016\/S0019-9958(60)90287-4"},{"key":"ref54","article-title":"Measuring the effects of non-identical data distribution for federated visual classification","author":"Harry Hsu","year":"2019","journal-title":"arXiv:1909.06335"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/10879404.pdf?arnumber=10879404","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,5]],"date-time":"2025-03-05T18:43:46Z","timestamp":1741200226000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10879404\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":54,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3539964","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}