{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,10]],"date-time":"2026-04-10T01:49:42Z","timestamp":1775785782232,"version":"3.50.1"},"reference-count":96,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2025,5,1]],"date-time":"2025-05-01T00:00:00Z","timestamp":1746057600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,5,1]],"date-time":"2025-05-01T00:00:00Z","timestamp":1746057600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,5,1]],"date-time":"2025-05-01T00:00:00Z","timestamp":1746057600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2021YFB3101100"],"award-info":[{"award-number":["2021YFB3101100"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U20A20177"],"award-info":[{"award-number":["U20A20177"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U24A20336"],"award-info":[{"award-number":["U24A20336"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U22B2022"],"award-info":[{"award-number":["U22B2022"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Wuhan Science and Technology Joint Project for Building a Strong Transportation Country","award":["2023-2-7"],"award-info":[{"award-number":["2023-2-7"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Ind. Inf."],"published-print":{"date-parts":[[2025,5]]},"DOI":"10.1109\/tii.2025.3528569","type":"journal-article","created":{"date-parts":[[2025,2,4]],"date-time":"2025-02-04T19:01:52Z","timestamp":1738695712000},"page":"3528-3540","source":"Crossref","is-referenced-by-count":10,"title":["Secure Federated Learning for Cloud-Fog Automation: Vulnerabilities, Challenges, Solutions, and Future Directions"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7749-2718","authenticated-orcid":false,"given":"Zhuangzhuang","family":"Zhang","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9897-1953","authenticated-orcid":false,"given":"Libing","family":"Wu","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0306-2691","authenticated-orcid":false,"given":"Jiong","family":"Jin","sequence":"additional","affiliation":[{"name":"School of Science, Computing and Engineering Technologies, Swinburne University of Technology, Hawthorn, VIC, Australia"}]},{"given":"Enshu","family":"Wang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Wuhan University, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8403-1776","authenticated-orcid":false,"given":"Bingyi","family":"Liu","sequence":"additional","affiliation":[{"name":"School of Computer Science and Artificial Intelligence, Wuhan University of Technology, Wuhan, China"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7207-0716","authenticated-orcid":false,"given":"Qing-Long","family":"Han","sequence":"additional","affiliation":[{"name":"School of Science, Computing and Engineering Technologies, Swinburne University of Technology, Hawthorn, VIC, Australia"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2023.3272696"},{"key":"ref2","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. Artif. Intell. Statist.","author":"McMahan","year":"2017"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1145\/3678181"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3216981"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3460427"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2020.2975749"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2021.3124599"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2021.3090430"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2023.3316615"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3095077"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2024.3382875"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3679013"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2024.3407584"},{"key":"ref14","first-page":"1605","article-title":"Local model poisoning attacks to byzantine-robust federated learning","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Fang","year":"2020"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3327853"},{"key":"ref17","first-page":"1","article-title":"A3FL: Adversarially adaptive backdoor attacks to federated learning","volume-title":"Proc. 37th Conf. Neural Inf. Process. Syst.","author":"Zhang","year":"2023"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2023.3271432"},{"key":"ref19","first-page":"43228","article-title":"Surrogate model extension (SME): A fast and accurate weight update attack on federated learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhu","year":"2023"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS51616.2021.00086"},{"key":"ref21","first-page":"1415","article-title":"FLAME: Taming backdoors in federated learning","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Nguyen","year":"2022"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3221899"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2022.3196404"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813687"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58607-2_11"},{"key":"ref27","first-page":"3454","article-title":"Input-aware dynamic backdoor attack","volume-title":"Proc. 34th Int. Conf. Neural Inf. Process. Syst.","author":"Nguyen","year":"2020"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3128646"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.01445"},{"key":"ref30","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in Byzantium","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Mhamdi","year":"2018"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"ref32","first-page":"5714","article-title":"Active membership inference attack under local differential privacy in federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Nguyen","year":"2023"},{"key":"ref33","first-page":"14747","article-title":"Deep leakage from gradients","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Zhu","year":"2019"},{"key":"ref34","first-page":"16937","article-title":"Inverting gradients - how easy is it to break privacy in federated learning?","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Geiping","year":"2020"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"ref36","first-page":"1","article-title":"Robbing the Fed: Directly obtaining private data in federated learning with modified models","volume-title":"Proc. Tenth Int. Conf. Learn. Representations","author":"Fowl","year":"2022"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP57164.2023.00020"},{"key":"ref38","first-page":"1","article-title":"R-GAP: Recursive gradient attack on privacy","volume-title":"Proc. 9th Int. Conf. Learn. Representations","author":"Zhu","year":"2021"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3196646"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1145\/3603216.3624964"},{"key":"ref41","first-page":"118","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. 31st Int. Conf. Neural Inf. Process. Syst.","author":"Blanchard","year":"2017"},{"key":"ref42","article-title":"Byzantine-robust federated machine learning through adaptive model averaging","author":"Muoz-Gonzlez","year":"2019"},{"key":"ref43","first-page":"301","article-title":"The limitations of federated learning in sybil settings","volume-title":"Proc. 23 rd Int. Symp. Res. Attacks, Intrusions Defenses","author":"Fung","year":"2020"},{"key":"ref44","first-page":"497","article-title":"FLOD: Oblivious defender for private Byzantine-robust federated learning with dishonest-majority","volume-title":"Proc. Eur. Symp. Res. Comput. Secur.","author":"Dong","year":"2021"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539231"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i8.20903"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2022.3167434"},{"key":"ref48","first-page":"6365","article-title":"FedVal: Different good or different bad in federated learning","volume-title":"Proc. 32nd USENIX Secur. Symp.","author":"Valadi","year":"2023"},{"key":"ref49","first-page":"43158","article-title":"LeadFL: Client self-defense against model poisoning in federated learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Zhu","year":"2023"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00141"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23233"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00271"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/TSUSC.2024.3379440"},{"key":"ref54","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin","year":"2018"},{"key":"ref55","first-page":"508","article-title":"Auror: Defending against poisoning attacks in collaborative deep learning systems","volume-title":"Proc. 32nd Annu. Conf. Comput. Secur. Appl.","author":"Shen","year":"2016"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011544"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1016\/j.sigpro.2023.109222"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2020.3041404"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2021.3140131"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.2971598"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3169918"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2022.3161673"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2022.3209200"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3340745"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2021.3131175"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-023-38569-4"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2023.3237636"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3326983"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2023.3331726"},{"key":"ref70","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2024.101107"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3368879"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3174394"},{"key":"ref74","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3293417"},{"key":"ref75","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24119"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23005"},{"key":"ref77","first-page":"2201","article-title":"MUSE: Secure inference resilient to malicious clients","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Lehmkuhl","year":"2021"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2017.2787987"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3241057"},{"key":"ref80","doi-asserted-by":"publisher","DOI":"10.14778\/3503585.3503592"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2929409"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3043139"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2020.3036166"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3126323"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2022.11.124"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3267112"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1109\/TC.2022.3169436"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2024.3370938"},{"key":"ref89","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3357288"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2024.3407670"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2024.3363712"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103562"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1145\/3570953"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2019.2952332"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2021.3100258"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3289832"}],"container-title":["IEEE Transactions on Industrial Informatics"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/9424\/10979801\/10870877.pdf?arnumber=10870877","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,4,30]],"date-time":"2025-04-30T04:38:26Z","timestamp":1745987906000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10870877\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5]]},"references-count":96,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tii.2025.3528569","relation":{},"ISSN":["1551-3203","1941-0050"],"issn-type":[{"value":"1551-3203","type":"print"},{"value":"1941-0050","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,5]]}}}