{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,10]],"date-time":"2026-02-10T16:06:01Z","timestamp":1770739561611,"version":"3.49.0"},"reference-count":67,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100019031","name":"Science and Technology Innovation Key Research and Development Program of Chongqing","doi-asserted-by":"publisher","award":["CSTB2025TIAD-STX0032"],"award-info":[{"award-number":["CSTB2025TIAD-STX0032"]}],"id":[{"id":"10.13039\/501100019031","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100014219","name":"National Science Fund for Distinguished Young Scholars of China","doi-asserted-by":"publisher","award":["62325604"],"award-info":[{"award-number":["62325604"]}],"id":[{"id":"10.13039\/501100014219","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62441618"],"award-info":[{"award-number":["62441618"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62276271"],"award-info":[{"award-number":["62276271"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62572079"],"award-info":[{"award-number":["62572079"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62572083"],"award-info":[{"award-number":["62572083"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2026.3659045","type":"journal-article","created":{"date-parts":[[2026,1,28]],"date-time":"2026-01-28T20:58:37Z","timestamp":1769633917000},"page":"1842-1857","source":"Crossref","is-referenced-by-count":0,"title":["A Wolf in Sheep\u2019s Clothing: Unveiling a Stealthy Backdoor Attack in Subgraph Federated Learning"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9044-4841","authenticated-orcid":false,"given":"Hao","family":"Yu","sequence":"first","affiliation":[{"name":"College of Computer Science and Technology, National University of Defense Technology, Changsha, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6997-0406","authenticated-orcid":false,"given":"Wenjing","family":"Yang","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, National University of Defense Technology, Changsha, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6198-9498","authenticated-orcid":false,"given":"Chuan","family":"Ma","sequence":"additional","affiliation":[{"name":"College of Computer Science, Chongqing University, Chongqing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2489-573X","authenticated-orcid":false,"given":"Lingyuan","family":"Meng","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, National University of Defense Technology, Changsha, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3294-5071","authenticated-orcid":false,"given":"Liang","family":"Du","sequence":"additional","affiliation":[{"name":"School of Computer and Information Technology, Shanxi University, Taiyuan, Shanxi, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9439-4623","authenticated-orcid":false,"given":"Tao","family":"Xiang","sequence":"additional","affiliation":[{"name":"College of Computer Science, Chongqing University, Chongqing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9066-1475","authenticated-orcid":false,"given":"Xinwang","family":"Liu","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, National University of Defense Technology, Changsha, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3335-5700","authenticated-orcid":false,"given":"Kunlun","family":"He","sequence":"additional","affiliation":[{"name":"Medical Big Data Research Center, Chinese PLA General Hospital, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1396","article-title":"Personalized subgraph federated learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Baek"},{"key":"ref2","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1088\/1742-5468\/2008\/10\/P10008"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1093\/bioinformatics\/bti1007"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583392"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670307"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24620"},{"key":"ref8","first-page":"1","article-title":"Fast graph representation learning with PyTorch geometric","volume-title":"Proc. ICLR Workshop Represent. Learn. Graphs Manifolds","author":"Fey"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-658-40442-0_9"},{"key":"ref10","first-page":"1024","article-title":"Inductive representation learning on large graphs","volume-title":"Proc. NIPS","author":"Hamilton"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3485447.3512093"},{"key":"ref12","article-title":"Measuring the effects of non-identical data distribution for federated visual classification","author":"Hsu","year":"2019","journal-title":"arXiv:1909.06335"},{"key":"ref13","first-page":"1","article-title":"Open graph benchmark: Datasets for machine learning on graphs","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Hu"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3402361"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2024.3418862"},{"key":"ref16","first-page":"1","article-title":"DGraph: A large-scale financial dataset for graph anomaly detection","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Huang"},{"key":"ref17","article-title":"Understanding isomorphism bias in graph data sets","author":"Ivanov","year":"2019","journal-title":"arXiv:1910.12091"},{"key":"ref18","first-page":"13144","article-title":"Communication-efficient distributed SGD with sketching","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Ivkin"},{"key":"ref19","first-page":"1","article-title":"Categorical reparameterization with Gumbel\u2013Softmax","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Jang"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1038\/s42256-025-01107-6"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i7.25977"},{"key":"ref22","article-title":"METIS: Unstructured graph partitioning and sparse matrix ordering system","author":"Karypis","year":"1997"},{"key":"ref23","first-page":"1","article-title":"Subgraph federated learning for local generalization","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Kim"},{"key":"ref24","first-page":"1","article-title":"Semi-supervised classification with graph convolutional networks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Kipf"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623212"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.241366"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179401"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3362147"},{"issue":"1","key":"ref29","first-page":"429","article-title":"Federated optimization in heterogeneous networks","volume":"2","author":"Tian","year":"2018","journal-title":"Mach. Learn. Syst."},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2023.3282989"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2025.3582689"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3541890"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/2766462.2767755"},{"key":"ref35","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. 20th Int. Conf. Artif. Intell. Statist.","volume":"54","author":"McMahan"},{"key":"ref36","first-page":"1","article-title":"IBA: Towards irreversible backdoor attacks in federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Nguyen"},{"key":"ref37","first-page":"1","article-title":"FLAME: Taming backdoors in federated learning","volume-title":"Proc. USENIX Secur.","author":"Nguyen"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i10.17118"},{"key":"ref39","first-page":"8026","article-title":"PyTorch: An imperative style, high-performance deep learning library","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Paszke"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1093\/bioinformatics\/btad703"},{"key":"ref41","first-page":"12311","article-title":"Invertible Gaussian reparameterization: Revisiting the Gumbel\u2013Softmax","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Potapczynski"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23233"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-019-01228-7"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1609\/aimag.v29i3.2157"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3459637.3482393"},{"key":"ref46","first-page":"1","article-title":"Graph attention networks","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Veli\u010dkovi\u0107"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-57959-7"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00068"},{"key":"ref49","first-page":"1","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wang"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-022-30714-9"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/669"},{"key":"ref52","first-page":"1523","article-title":"Graph backdoor","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Xi"},{"key":"ref53","first-page":"1","article-title":"DBA: Distributed backdoor attacks against federated learning","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Xie"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/3633206"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2024\/877"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1007\/s00778-023-00790-4"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690187"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2024.3483274"},{"key":"ref59","first-page":"40888","article-title":"Graph contrastive backdoor attacks","volume-title":"Proc. Int. Conf. Mach. Learn.","volume":"202","author":"Zhang"},{"key":"ref60","first-page":"1","article-title":"A3FL: Adversarially adaptive backdoor attacks to federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhang"},{"key":"ref61","article-title":"FLIP: A provable defense framework for backdoor mitigation in federated learning","author":"Zhang","year":"2022","journal-title":"arXiv:2210.12873"},{"key":"ref62","first-page":"6671","article-title":"Subgraph federated learning with missing neighbor generation","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhang"},{"key":"ref63","first-page":"1","article-title":"GNNGuard: Defending graph neural networks against adversarial attacks","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhang"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/3450569.3463560"},{"key":"ref65","first-page":"26429","article-title":"Neurotoxin: Durable backdoors in federated learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhang"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3536612"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1145\/3292500.3330851"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11367024.pdf?arnumber=11367024","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,9]],"date-time":"2026-02-09T21:03:52Z","timestamp":1770671032000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11367024\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":67,"URL":"https:\/\/doi.org\/10.1109\/tifs.2026.3659045","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}