{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,30]],"date-time":"2026-03-30T14:00:08Z","timestamp":1774879208216,"version":"3.50.1"},"reference-count":47,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U24B20182"],"award-info":[{"award-number":["U24B20182"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62122066"],"award-info":[{"award-number":["62122066"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62472158"],"award-info":[{"award-number":["62472158"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62102337"],"award-info":[{"award-number":["62102337"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Key Research and Development Program of China","award":["2021ZD0112803"],"award-info":[{"award-number":["2021ZD0112803"]}]},{"name":"Key Research and Development Program of Zhejiang","award":["2024C01164"],"award-info":[{"award-number":["2024C01164"]}]},{"name":"Key Research and Development Program of Zhejiang","award":["2022C01018"],"award-info":[{"award-number":["2022C01018"]}]},{"name":"Science and Technology Innovation Program of Hunan Province","award":["2024RC3102"],"award-info":[{"award-number":["2024RC3102"]}]},{"DOI":"10.13039\/501100004735","name":"Natural Science Foundation of Hunan Province, China","doi-asserted-by":"publisher","award":["2023JJ40174"],"award-info":[{"award-number":["2023JJ40174"]}],"id":[{"id":"10.13039\/501100004735","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2025]]},"DOI":"10.1109\/tifs.2025.3586491","type":"journal-article","created":{"date-parts":[[2025,7,7]],"date-time":"2025-07-07T13:48:26Z","timestamp":1751896106000},"page":"7061-7076","source":"Crossref","is-referenced-by-count":3,"title":["Poisoning Attacks to Knowledge Distillation-Based Federated Learning Under Robust Aggregation Rules"],"prefix":"10.1109","volume":"20","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-2763-2695","authenticated-orcid":false,"given":"Xiaoyi","family":"Pang","sequence":"first","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security and the School of Cyber Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5804-3279","authenticated-orcid":false,"given":"Zhibo","family":"Wang","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security and the School of Cyber Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Defang","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jiahui","family":"Hu","sequence":"additional","affiliation":[{"name":"School of Mathematics and Computer Sciences, Nanchang University, Nanchang, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6221-8142","authenticated-orcid":false,"given":"Peng","family":"Sun","sequence":"additional","affiliation":[{"name":"College of Computer Science and Electronic Engineering, Hunan University, Changsha, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-3432-3445","authenticated-orcid":false,"given":"Meng","family":"Luo","sequence":"additional","affiliation":[{"name":"School of Computing, National University of Singapore, Singapore, Singapore"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1969-2591","authenticated-orcid":false,"given":"Kui","family":"Ren","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Blockchain and Data Security and the School of Cyber Science and Technology, Zhejiang University, Hangzhou, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i08.7021"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1038\/s41598-020-69250-1"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2020.2988604"},{"key":"ref4","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. 20th Int. Conf. Artif. Intell. Statist.","volume":"54","author":"McMahan"},{"key":"ref5","article-title":"On the convergence of FedAvg on non-IID data","author":"Li","year":"2019","journal-title":"arXiv:1907.02189"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM42981.2021.9488877"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2020.3000372"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2021.3118354"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2023.3317870"},{"key":"ref10","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Bhagoji"},{"key":"ref11","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref12","first-page":"1893","article-title":"Data poisoning attacks on factorization-based collaborative filtering","volume-title":"Proc. NIPS","author":"Li"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58951-6_24"},{"key":"ref15","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume-title":"Proc. NIPS","author":"Wang"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103270"},{"key":"ref17","first-page":"8635","article-title":"A little is enough: Circumventing defenses for distributed learning","volume-title":"Proc. 33rd Int. Conf. Neural Inf. Process. Syst.","author":"Baruch"},{"key":"ref18","first-page":"1605","article-title":"Local model poisoning attacks to Byzantine-robust federated learning","volume-title":"Proc. 29th USENIX Secur. Symp. (USENIX Secur.)","author":"Fang"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW56347.2022.00383"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2023.02.025"},{"key":"ref22","first-page":"118","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. NIPS","author":"Blanchard"},{"key":"ref23","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in Byzantium","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"El Mhamdi"},{"key":"ref24","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref25","first-page":"1","article-title":"SignSGD with majority vote is communication efficient and fault tolerant","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Bernstein"},{"key":"ref26","article-title":"Byzantine-robust federated machine learning through adaptive model averaging","author":"Mu\u00f1oz-Gonz\u00e1lez","year":"2019","journal-title":"arXiv:1909.05125"},{"key":"ref27","article-title":"FedMD: Heterogenous federated learning via model distillation","author":"Li","year":"2019","journal-title":"arXiv:1910.03581"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-022-29763-x"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00993"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3183170"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2023.3315066"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-023-44383-9"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3349295"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/JSEN.2024.3357798"},{"key":"ref35","article-title":"Logit poisoning attack in distillation-based federated learning and its countermeasures","author":"Yu","year":"2024","journal-title":"arXiv:2401.17746"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-97-5498-4_22"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1503.02531"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.016.2300523"},{"key":"ref39","first-page":"12878","article-title":"Data-free knowledge distillation for heterogeneous federated learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhu"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2023.3272801"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS54860.2022.00120"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2022.3153135"},{"key":"ref43","article-title":"Generalized Byzantine-tolerant SGD","author":"Xie","year":"2018","journal-title":"arXiv:1802.10116"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/OJCS.2020.2993259"},{"key":"ref45","article-title":"Byzantine-robust federated learning through collaborative malicious gradient filtering","author":"Xu","year":"2021","journal-title":"arXiv:2109.05872"},{"key":"ref46","first-page":"1","article-title":"Neural attention distillation: Erasing backdoor triggers from deep neural networks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Li"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.2299\/jsp.24.141"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/10810755\/11072238.pdf?arnumber=11072238","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,15]],"date-time":"2025-07-15T05:36:25Z","timestamp":1752557785000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11072238\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"references-count":47,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3586491","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]}}}