{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,13]],"date-time":"2026-01-13T13:35:50Z","timestamp":1768311350680,"version":"3.49.0"},"reference-count":52,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62572280"],"award-info":[{"award-number":["62572280"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U24A20244"],"award-info":[{"award-number":["U24A20244"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U23A20302"],"award-info":[{"award-number":["U23A20302"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100014219","name":"Shandong Science Fund for Excellent Young Scholars","doi-asserted-by":"publisher","award":["2023HWYQ-007"],"award-info":[{"award-number":["2023HWYQ-007"]}],"id":[{"id":"10.13039\/501100014219","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2025.3630065","type":"journal-article","created":{"date-parts":[[2025,11,6]],"date-time":"2025-11-06T18:52:08Z","timestamp":1762455128000},"page":"929-944","source":"Crossref","is-referenced-by-count":0,"title":["General Backdoor-Resilient Federated Learning via Multi-Armed Bandit-Based Knowledge Distillation"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-8048-2166","authenticated-orcid":false,"given":"Senmao","family":"Qi","sequence":"first","affiliation":[{"name":"Institute of Intelligent Computing, School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hao","family":"Ma","sequence":"additional","affiliation":[{"name":"Institute of Intelligent Computing, School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4579-5380","authenticated-orcid":false,"given":"Yifei","family":"Zou","sequence":"additional","affiliation":[{"name":"Institute of Intelligent Computing, School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5303-0700","authenticated-orcid":false,"given":"Peng","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, The University of Aizu, Aizuwakamatsu, Japan"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8266-4561","authenticated-orcid":false,"given":"Hanlin","family":"Gu","sequence":"additional","affiliation":[{"name":"WeBank AI Laboratory, WeBank, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8907-2064","authenticated-orcid":false,"given":"Zhenzhen","family":"Xie","sequence":"additional","affiliation":[{"name":"Institute of Intelligent Computing, School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8162-7096","authenticated-orcid":false,"given":"Lixin","family":"Fan","sequence":"additional","affiliation":[{"name":"WeBank AI Laboratory, WeBank, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5912-4647","authenticated-orcid":false,"given":"Xiuzhen","family":"Cheng","sequence":"additional","affiliation":[{"name":"Institute of Intelligent Computing, School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6835-5981","authenticated-orcid":false,"given":"Dongxiao","family":"Yu","sequence":"additional","affiliation":[{"name":"Institute of Intelligent Computing, School of Computer Science and Technology, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. Artif. Intell. Statist.","author":"McMahan"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2021.106775"},{"key":"ref3","article-title":"Backdoor attacks and defenses in federated learning: Survey, challenges and future research directions","author":"Dung Nguyen","year":"2023","journal-title":"arXiv:2303.02213"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1016\/j.hcc.2025.100321"},{"key":"ref5","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. AISTATS","author":"Bagdasaryan"},{"key":"ref6","first-page":"118","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. NIPS","volume":"30","author":"Blanchard"},{"key":"ref7","article-title":"Mitigating Sybils in federated learning poisoning","author":"Fung","year":"2018","journal-title":"arXiv:1808.04866"},{"key":"ref8","first-page":"508","article-title":"AUROR: Defending against poisoning attacks in collaborative deep learning systems","volume-title":"Proc. 32nd Annu. Conf. Comput. Security Appl.","author":"Shen"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"ref10","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref11","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in byzantium","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Guerraoui"},{"key":"ref12","article-title":"Can you really backdoor federated learning?","author":"Sun","year":"2019","journal-title":"arXiv:1911.07963"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/cns62487.2024.10735680"},{"key":"ref14","article-title":"Mitigating backdoor attacks in federated learning","author":"Wu","year":"2020","journal-title":"arXiv:2011.01767"},{"key":"ref15","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume-title":"Proc. NeurIPS","author":"Wang"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3280032"},{"key":"ref17","first-page":"8632","article-title":"A little is enough: Circumventing defenses for distributed learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Baruch"},{"key":"ref18","article-title":"Machine unlearning fails to remove data poisoning attacks","author":"Pawelczyk","year":"2024","journal-title":"arXiv:2406.17216"},{"key":"ref19","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"Proc. ICML","author":"Bhagoji"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i10.17118"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103366"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3354049"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref24","article-title":"Targeted backdoor attacks on deep learning systems using data poisoning","author":"Chen","year":"2017","journal-title":"arXiv:1712.05526"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref26","article-title":"Revisiting the assumption of latent separability for backdoor defenses","author":"Qi","year":"2022","journal-title":"ICLR"},{"key":"ref27","article-title":"DBA: Distributed backdoor attacks against federated learning","volume-title":"Proc. ICLR","author":"Xie"},{"key":"ref28","first-page":"26429","article-title":"Neurotoxin: Durable backdoors in federated learning","volume-title":"Proc. ICML","author":"Zhang"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2022.3153135"},{"key":"ref30","first-page":"1415","article-title":"FLAME: Taming backdoors in federated learning","volume-title":"Proc. 31st USENIX Security Symp. (USENIX Secur.)","author":"Nguyen"},{"key":"ref31","article-title":"Batch label inference and replacement attacks in black-boxed vertical federated learning","author":"Liu","year":"2021","journal-title":"arXiv:2112.05409"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3202687"},{"key":"ref33","article-title":"WaNet-imperceptible warping-based backdoor attack","author":"Nguyen","year":"2021","journal-title":"arXiv:2102.10369"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179401"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1503.02531"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.21437\/Interspeech.2016-1190"},{"key":"ref37","article-title":"Neural attention distillation: Erasing backdoor triggers from deep neural networks","author":"Li","year":"2021","journal-title":"arXiv:2101.05930"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2022\/206"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.3390\/electronics12234838"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML64287.2025.00018"},{"key":"ref41","article-title":"DROP: Poison dilution via knowledge distillation for federated learning","author":"Syros","year":"2025","journal-title":"arXiv:2502.07011"},{"key":"ref42","article-title":"BDPFL: Backdoor defense for personalized federated learning via explainable distillation","author":"Zhu","year":"2025","journal-title":"arXiv:2503.06554"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1016\/j.hcc.2025.100310"},{"key":"ref44","article-title":"Decentralized federated learning: A survey and perspective","author":"Yuan","year":"2023","journal-title":"arXiv:2306.01603"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2023\/150"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref47","article-title":"BackdoorBox: A Python toolbox for backdoor learning","volume-title":"Proc. ICLR Workshop","author":"Li"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.52202\/079017-2451"},{"key":"ref49","first-page":"53090","article-title":"Fedgame: A game-theoretic defense against backdoor attacks in federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"36","author":"Jia"},{"key":"ref50","first-page":"1605","article-title":"Local model poisoning attacks to Byzantine robust federated learning","volume-title":"Proc. 29th USENIX Secur. Symp. (USENIX Secur.)","author":"Fang"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1145\/3474085.3475254"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11230822.pdf?arnumber=11230822","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,13]],"date-time":"2026-01-13T08:18:37Z","timestamp":1768292317000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11230822\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":52,"URL":"https:\/\/doi.org\/10.1109\/tifs.2025.3630065","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}