{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T21:23:17Z","timestamp":1772227397995,"version":"3.50.1"},"reference-count":28,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100007129","name":"Natural Science Foundation of Shandong Province","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100007129","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2026.3666296","type":"journal-article","created":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T20:56:43Z","timestamp":1771534603000},"page":"2373-2388","source":"Crossref","is-referenced-by-count":0,"title":["Model Hijacking Attack in Federated Learning"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4466-7523","authenticated-orcid":false,"given":"Zheng","family":"Li","sequence":"first","affiliation":[{"name":"School of Cyber Science and Technology, the State Key Laboratory of Cryptography and Digital Economy Security, and Shandong Key Laboratory of Artificial Intelligence Security, Shandong University, Qingdao, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-0867-6308","authenticated-orcid":false,"given":"Siyuan","family":"Wu","sequence":"additional","affiliation":[{"name":"Trusted Computing and Information Assurance Laboratory, Institute of Software, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-5060-8411","authenticated-orcid":false,"given":"Ruichuan","family":"Chen","sequence":"additional","affiliation":[{"name":"Nokia Bell Labs, Stuttgart, Baden-W\u00fcrttemberg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3431-8194","authenticated-orcid":false,"given":"Paarijaat","family":"Aditya","sequence":"additional","affiliation":[{"name":"Nokia Bell Labs, Stuttgart, Baden-W\u00fcrttemberg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Istemi Ekin","family":"Akkus","sequence":"additional","affiliation":[{"name":"Nokia Bell Labs, Stuttgart, Baden-W\u00fcrttemberg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Manohar","family":"Vanga","sequence":"additional","affiliation":[{"name":"Nokia Bell Labs, Stuttgart, Baden-W\u00fcrttemberg, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-4415-3676","authenticated-orcid":false,"given":"Min","family":"Zhang","sequence":"additional","affiliation":[{"name":"Trusted Computing and Information Assurance Laboratory, Institute of Software, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-3815-6221","authenticated-orcid":false,"given":"Hao","family":"Li","sequence":"additional","affiliation":[{"name":"Trusted Computing and Information Assurance Laboratory, Institute of Software, Chinese Academy of Sciences, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3612-7348","authenticated-orcid":false,"given":"Yang","family":"Zhang","sequence":"additional","affiliation":[{"name":"CISPA Helmholtz Center for Information Security, Saarbr&#xFC;cken, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"OpenMined: An Open-Source Community for Private AI and Federated Learning","year":"2025"},{"key":"ref2","volume-title":"The MNIST dataset","year":"2024"},{"key":"ref3","volume-title":"The CIFAR-10 dataset","year":"2024"},{"key":"ref4","volume-title":"The GTSRB dataset","year":"2025"},{"key":"ref5","volume-title":"The TinyImageNet dataset","year":"2025"},{"key":"ref6","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref7","first-page":"1","article-title":"Poisoning attacks against support vector machines","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Biggio"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-7908-2604-3_16"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00987"},{"key":"ref10","article-title":"BadNets: Identifying vulnerabilities in the machine learning model supply chain","author":"Gu","year":"2017","journal-title":"arXiv:1708.06733"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"ref13","first-page":"1","article-title":"Federated learning: Strategies for improving communication efficiency","volume-title":"Proc. NIPS Workshop Private Multi-Party Mach. Learn.","author":"Konecn\u00fd"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23291"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-01264-9_8"},{"key":"ref16","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. 20th Int. Conf. Artif. Intell. Statist.","volume":"54","author":"McMahan"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.001.1900461"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3052973.3053009"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.36"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23064"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"ref23","article-title":"Robust and communication-efficient federated learning from non-IID data","author":"Sattler","year":"2019","journal-title":"arXiv:1903.02891"},{"key":"ref24","article-title":"Two-in-one: A model hijacking attack against text generation models","author":"Si","year":"2022","journal-title":"arxiv: 2208.11180"},{"key":"ref25","article-title":"Data poisoning attack against unsupervised node embedding methods","author":"Sun","year":"2018","journal-title":"arXiv:1810.12881"},{"issue":"86","key":"ref26","first-page":"2579","article-title":"Visualizing data using t-SNE","volume":"9","author":"Maaten","year":"2008","journal-title":"J. Mach. Learn. Res."},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23198"},{"key":"ref28","first-page":"39879","article-title":"FedDisco: Federated learning with discrepancy-aware collaboration","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Ye"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11400663.pdf?arnumber=11400663","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,2,27]],"date-time":"2026-02-27T20:48:31Z","timestamp":1772225311000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11400663\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":28,"URL":"https:\/\/doi.org\/10.1109\/tifs.2026.3666296","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}