{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,11]],"date-time":"2026-05-11T10:34:52Z","timestamp":1778495692415,"version":"3.51.4"},"reference-count":209,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"9","license":[{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,9,1]],"date-time":"2025-09-01T00:00:00Z","timestamp":1756684800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Plan of China","doi-asserted-by":"publisher","award":["2024YFE0202700"],"award-info":[{"award-number":["2024YFE0202700"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["U2433216"],"award-info":[{"award-number":["U2433216"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100004608","name":"Natural Science Foundation of Jiangsu Province","doi-asserted-by":"publisher","award":["BK20231337"],"award-info":[{"award-number":["BK20231337"]}],"id":[{"id":"10.13039\/501100004608","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100010023","name":"Natural Science Foundation of Jiangsu Higher Education Institutions of China","doi-asserted-by":"publisher","award":["24KJB520032"],"award-info":[{"award-number":["24KJB520032"]}],"id":[{"id":"10.13039\/501100010023","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Neural Netw. Learning Syst."],"published-print":{"date-parts":[[2025,9]]},"DOI":"10.1109\/tnnls.2025.3563537","type":"journal-article","created":{"date-parts":[[2025,5,15]],"date-time":"2025-05-15T13:33:32Z","timestamp":1747316012000},"page":"15643-15663","source":"Crossref","is-referenced-by-count":22,"title":["Threats and Defenses in the Federated Learning Life Cycle: A Comprehensive Survey and Challenges"],"prefix":"10.1109","volume":"36","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9842-2209","authenticated-orcid":false,"given":"Yanli","family":"Li","sequence":"first","affiliation":[{"name":"School of Artificial Intelligence and Computer Science, Nantong University, Nantong, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6025-3021","authenticated-orcid":false,"given":"Zhongliang","family":"Guo","sequence":"additional","affiliation":[{"name":"School of Computer Science, University of St Andrews, St Andrews, U.K."}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5257-9227","authenticated-orcid":false,"given":"Nan","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Electrical and Computer Engineering, The University of Sydney, Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5678-472X","authenticated-orcid":false,"given":"Huaming","family":"Chen","sequence":"additional","affiliation":[{"name":"School of Electrical and Computer Engineering, The University of Sydney, Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1130-0888","authenticated-orcid":false,"given":"Dong","family":"Yuan","sequence":"additional","affiliation":[{"name":"School of Electrical and Computer Engineering, The University of Sydney, Sydney, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3180-7347","authenticated-orcid":false,"given":"Weiping","family":"Ding","sequence":"additional","affiliation":[{"name":"School of Artificial Intelligence and Computer Science, Nantong University, Nantong, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2021.3124599"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/JSTSP.2022.3152445"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1561\/2200000083"},{"key":"ref4","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. 20th Int. Conf. Artif. Intell. Statist.","volume":"54","author":"McMahan"},{"key":"ref5","article-title":"Federated learning for mobile keyboard prediction","author":"Hard","year":"2018","journal-title":"arXiv:1811.03604"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2023.119830"},{"key":"ref7","first-page":"81","article-title":"AGGREGATHOR: Byzantine machine learning via robust gradient aggregation","volume-title":"Proc. Mach. Learn. Syst. (MLSys)","volume":"1","author":"Damaskinos"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1007\/s00446-022-00427-9"},{"key":"ref9","first-page":"1605","article-title":"Local model poisoning attacks to Byzantine-robust federated learning","volume-title":"Proc. 29th USENIX Secur. Symp.","author":"Fang"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/MWC.017.2100714"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3182979"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1016\/j.earscirev.2022.103991"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC57700.2023.00088"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i10.17118"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-020-04831-9"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3216981"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3150363"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1016\/j.inffus.2022.09.011"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3322785"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2023.03.033"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3543873.3587681"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1016\/j.iotcps.2023.04.001"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2024.3362191"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TAI.2024.3363670"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3678181"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1145\/3664650"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-024-10846-8"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1007\/s10115-024-02117-3"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1007\/s40747-024-01664-0"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/tbdata.2025.3527202"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/tii.2025.3528569"},{"key":"ref36","first-page":"1","article-title":"A survey of attack and defense techniques for federated learning systems","author":"Gao","year":"2023","journal-title":"Chin. J. Comput."},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.3390\/fi13030073"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3274119"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.3233\/978-1-61499-098-7-870"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103936"},{"key":"ref41","first-page":"1","article-title":"A little is enough: Circumventing defenses for distributed learning","volume-title":"Proc. NIPS","author":"Baruch"},{"key":"ref42","first-page":"261","article-title":"Fall of empires: Breaking Byzantine-tolerant SGD by inner product manipulation","volume-title":"Proc. 35th Uncertainty Artif. Intell. Conf.","author":"Xie"},{"key":"ref43","first-page":"1","article-title":"Machine learning with adversaries: Byzantine tolerant gradient descent","volume-title":"Proc. NIPS","author":"Blanchard"},{"key":"ref44","first-page":"5650","article-title":"Byzantine-robust distributed learning: Towards optimal statistical rates","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Yin"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58951-6_24"},{"issue":"30","key":"ref47","first-page":"1","article-title":"Attacks against federated learning defense systems and their mitigation","volume":"24","author":"Lewis","year":"2023","journal-title":"J. Mach. Learn. Res."},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/s10836-022-06035-6"},{"key":"ref49","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref50","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume-title":"Proc. NIPS","author":"Wang"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1109\/WCNC49053.2021.9417334"},{"key":"ref52","first-page":"1846","article-title":"Free-rider attacks on model aggregation in federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Stat.","author":"Fraboni"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2023.3280406"},{"key":"ref54","article-title":"Incentives for federated learning: A hypothesis elicitation approach","author":"Liu","year":"2020","journal-title":"arXiv:2007.10596"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2019.2952332"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1109\/ICPR48806.2021.9412599"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2024.120475"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3231121"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/VCIP.2018.8698609"},{"key":"ref60","first-page":"1","article-title":"Explaining and harnessing adversarial examples","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Goodfellow"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.48550\/ARXIV.1706.06083"},{"key":"ref62","first-page":"1","article-title":"Adversarial machine learning at scale","volume-title":"Int. Conf. Learn. Represent. (ICLR)","author":"Kurakin"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/3128572.3140448"},{"key":"ref64","first-page":"1","article-title":"Decision-based adversarial attacks: Reliable attacks against black-box machine learning models","volume-title":"Proc. Int. Conf. Learn. Represent. (ICLR)","author":"Brendel"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23119"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.3233\/JCS-191362"},{"issue":"6","key":"ref67","first-page":"2833","article-title":"Survey on security and privacy of federated learning models","volume":"34","author":"Gu","year":"2023","journal-title":"Ruan Jian Xue Bao\/J. Softw."},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00029"},{"key":"ref69","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243834"},{"key":"ref70","first-page":"2687","article-title":"Leakage of dataset properties in multi-party machine learning","volume-title":"Proc. 30th USENIX Secur. Symp.","author":"Zhang"},{"key":"ref71","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2019.8737416"},{"key":"ref73","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813687"},{"key":"ref74","first-page":"1","article-title":"Deep leakage from gradients","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Mu"},{"key":"ref75","first-page":"16937","article-title":"Inverting gradients - how easy is it to break privacy in federated learning?","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"33","author":"Geiping"},{"key":"ref76","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00989"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.01607"},{"key":"ref78","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00978"},{"issue":"2","key":"ref79","first-page":"429","article-title":"Review of deep gradient inversion attacks and defenses in federated learning","volume":"46","author":"Sun","year":"2024","journal-title":"J. Electron. Inf. Technol."},{"key":"ref80","first-page":"1","article-title":"Large scale GAN training for high fidelity natural image synthesis","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Brock"},{"key":"ref81","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00813"},{"key":"ref82","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00874"},{"key":"ref83","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2020.10.007"},{"key":"ref84","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2022.3229277"},{"key":"ref85","doi-asserted-by":"publisher","DOI":"10.1109\/TWC.2023.3245621"},{"key":"ref86","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2008.11"},{"key":"ref87","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623134"},{"key":"ref88","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.2020.3035868"},{"key":"ref89","article-title":"Machine learning in the presence of an adversary: Attacking and defending the SpamBayes spam filter","author":"Saini","year":"2008"},{"key":"ref90","doi-asserted-by":"publisher","DOI":"10.1145\/1128817.1128824"},{"key":"ref91","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3027980"},{"key":"ref92","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i4.28095"},{"key":"ref93","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2022.3168011"},{"key":"ref94","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i7.25955"},{"key":"ref95","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103319"},{"key":"ref96","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2020.3043458"},{"key":"ref97","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/378"},{"key":"ref98","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE53745.2022.00105"},{"key":"ref99","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103336"},{"key":"ref100","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2023.110384"},{"key":"ref101","first-page":"3353","article-title":"Adversarial training for free","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"32","author":"Shafahi"},{"key":"ref102","first-page":"5142","article-title":"Towards understanding knowledge distillation","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Phuong"},{"key":"ref103","doi-asserted-by":"publisher","DOI":"10.1109\/PERCOM50583.2021.9439129"},{"key":"ref104","first-page":"2351","article-title":"Ensemble distillation for robust model fusion in federated learning","volume-title":"Proc. NIPS","volume":"33","author":"Lin"},{"key":"ref105","first-page":"9","article-title":"Distilling the knowledge in a neural network","volume":"1050","author":"Hinton","year":"2015","journal-title":"stat"},{"key":"ref106","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00993"},{"key":"ref107","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-00470-5_13"},{"key":"ref108","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3166101"},{"key":"ref109","volume-title":"Introduction to Coding Theory","author":"Van Lint","year":"1998"},{"key":"ref110","first-page":"903","article-title":"DRACO: Byzantine-resilient distributed training via redundant gradients","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Chen"},{"key":"ref111","first-page":"1","article-title":"DETOX: A redundancy-based framework for faster and more robust gradient aggregation","volume-title":"Proc. 33rd Int. Conf. Neural Inf. Process. Syst.","volume":"32","author":"Rajput"},{"key":"ref112","first-page":"3521","article-title":"The hidden vulnerability of distributed learning in Byzantium","volume-title":"Proc. 35th Int. Conf. Mach. Learn.","author":"El Mhamdi"},{"key":"ref113","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2022.3153135"},{"key":"ref114","doi-asserted-by":"publisher","DOI":"10.1109\/ICPADS47876.2019.00042"},{"key":"ref115","article-title":"Byzantine-robust federated machine learning through adaptive model averaging","author":"Mu\u00f1oz-Gonz\u00e1lez","year":"2019","journal-title":"arXiv:1909.05125"},{"key":"ref116","doi-asserted-by":"publisher","DOI":"10.1109\/CDC40024.2019.9029245"},{"key":"ref117","article-title":"Generalized Byzantine-tolerant SGD","author":"Xie","year":"2018","journal-title":"arXiv:1802.10116"},{"key":"ref118","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2020.3012952"},{"key":"ref119","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-65745-1_12"},{"key":"ref120","first-page":"840","article-title":"Sageflow: Robust federated learning against both stragglers and adversaries","volume-title":"Proc. Adv. Neural Inf. Process. Syst. (NeurIPS)","volume":"34","author":"Park"},{"key":"ref121","first-page":"6893","article-title":"Zeno: Distributed stochastic gradient descent with suspicion-based fault-tolerance","volume-title":"Proc. 36th Int. Conf. Mach. Learn.","author":"Xie"},{"key":"ref122","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2019.2946020"},{"key":"ref123","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.2986205"},{"key":"ref124","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-38991-8_39"},{"key":"ref125","article-title":"Honest score client selection scheme: Preventing federated learning label flipping attacks in non-IID scenarios","author":"Li","year":"2023","journal-title":"arXiv:2311.05826"},{"key":"ref126","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP40776.2020.9054676"},{"key":"ref127","first-page":"1","article-title":"Robust federated learning in a heterogeneous environment","volume-title":"Proc. ICML (Workshop)","author":"Ghosh"},{"key":"ref128","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i18.29967"},{"key":"ref129","doi-asserted-by":"publisher","DOI":"10.1007\/s10618-022-00912-6"},{"key":"ref130","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2020.3002796"},{"key":"ref131","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011544"},{"key":"ref132","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30181"},{"key":"ref133","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2020.3015958"},{"key":"ref134","first-page":"17455","article-title":"Differentially private learning with adaptive clipping","volume-title":"Proc. Annu. Conf. Neural Inf. Process. Syst.","volume":"34","author":"Andrew"},{"key":"ref135","first-page":"12613","article-title":"FL-WBC: Enhancing robustness against model poisoning attacks in federated learning from a client perspective","volume-title":"Proc. NeurIPS","author":"Sun"},{"key":"ref136","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2022.11.124"},{"key":"ref137","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3072611"},{"key":"ref138","doi-asserted-by":"publisher","DOI":"10.1145\/3524104"},{"key":"ref139","doi-asserted-by":"publisher","DOI":"10.1561\/9781601988195"},{"key":"ref140","article-title":"Differentially private federated learning: A client level perspective","author":"Geyer","year":"2017","journal-title":"arXiv:1712.07557"},{"key":"ref141","first-page":"1","article-title":"Learning differentially private recurrent language models","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"McMahan"},{"key":"ref142","article-title":"Sharpness-aware minimization for efficiently improving generalization","author":"Foret","year":"2020","journal-title":"arXiv:2010.01412"},{"key":"ref143","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00988"},{"key":"ref144","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00770"},{"key":"ref145","article-title":"Hybrid differentially private federated learning on vertically partitioned data","author":"Wang","year":"2020","journal-title":"arXiv:2009.02763"},{"key":"ref146","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2013.53"},{"key":"ref147","doi-asserted-by":"publisher","DOI":"10.1145\/3378679.3394533"},{"key":"ref148","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.3037194"},{"key":"ref149","article-title":"Differentially private federated learning: A systematic review","author":"Fu","year":"2024","journal-title":"arXiv:2405.08299"},{"key":"ref150","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23054"},{"key":"ref151","doi-asserted-by":"publisher","DOI":"10.1007\/s11280-020-00780-4"},{"key":"ref152","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2021.3056991"},{"key":"ref153","first-page":"2251","article-title":"Federated f-differential privacy","volume-title":"Proc. 24th Int. Conf. Artif. Intell. Statist.","volume":"130","author":"Zheng"},{"key":"ref154","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2021\/216"},{"key":"ref155","first-page":"72181","article-title":"Dynamic personalized federated learning with adaptive differential privacy","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"36","author":"Yang"},{"key":"ref156","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.02352"},{"key":"ref157","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2023.3331726"},{"key":"ref158","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-023-38569-4"},{"key":"ref159","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2024.121035"},{"key":"ref160","doi-asserted-by":"publisher","DOI":"10.1145\/3458864.3466628"},{"key":"ref161","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2024.04.024"},{"key":"ref162","doi-asserted-by":"publisher","DOI":"10.1109\/TCE.2023.3315415"},{"key":"ref163","article-title":"Fully decentralized federated learning","volume-title":"Proc. 3rd Workshop Bayesian Deep Learn. (NeurIPS)","volume":"2","author":"Lalitha"},{"key":"ref164","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-10-5421-1_9"},{"key":"ref165","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2019.8761267"},{"key":"ref166","doi-asserted-by":"publisher","DOI":"10.1109\/JSTSP.2015.2427113"},{"key":"ref167","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24119"},{"key":"ref168","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3392424"},{"key":"ref169","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.02302"},{"key":"ref170","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1982.38"},{"key":"ref171","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"ref172","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCN49398.2020.9209670"},{"key":"ref173","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2024.120481"},{"key":"ref174","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2020.02.037"},{"key":"ref175","doi-asserted-by":"publisher","DOI":"10.1038\/s41591-021-01506-3"},{"key":"ref176","doi-asserted-by":"publisher","DOI":"10.2196\/24207"},{"key":"ref177","doi-asserted-by":"publisher","DOI":"10.1016\/j.media.2023.102965"},{"key":"ref178","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3376790"},{"key":"ref179","doi-asserted-by":"publisher","DOI":"10.1016\/j.artmed.2024.103024"},{"key":"ref180","article-title":"The hidden adversarial vulnerabilities of medical federated learning","author":"Darzi","year":"2023","journal-title":"arXiv:2310.13893"},{"key":"ref181","doi-asserted-by":"publisher","DOI":"10.1109\/BIBM58861.2023.10385829"},{"key":"ref182","doi-asserted-by":"publisher","DOI":"10.3390\/s22145195"},{"key":"ref183","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2024.3423457"},{"key":"ref184","doi-asserted-by":"publisher","DOI":"10.1109\/JBHI.2022.3171852"},{"key":"ref185","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2019.2945367"},{"key":"ref186","doi-asserted-by":"publisher","DOI":"10.1016\/j.compag.2025.110048"},{"key":"ref187","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOMWKSHPS61880.2024.10620772"},{"key":"ref188","doi-asserted-by":"publisher","DOI":"10.1109\/WF-IoT62078.2024.10811131"},{"key":"ref189","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3327953"},{"key":"ref190","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2024.3368754"},{"key":"ref191","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3325634"},{"key":"ref192","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3275161"},{"key":"ref193","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2023.3324962"},{"key":"ref194","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30131"},{"key":"ref195","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3172936"},{"key":"ref196","doi-asserted-by":"publisher","DOI":"10.1109\/DSC61021.2023.10354149"},{"key":"ref197","doi-asserted-by":"publisher","DOI":"10.1051\/sands\/2022003"},{"key":"ref198","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2023.120295"},{"key":"ref199","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3337638"},{"key":"ref200","doi-asserted-by":"publisher","DOI":"10.1109\/WCNC57260.2024.10571158"},{"key":"ref201","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2023.3348204"},{"key":"ref202","doi-asserted-by":"publisher","DOI":"10.1109\/TPWRS.2023.3267463"},{"key":"ref203","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM54140.2023.10437420"},{"key":"ref204","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2022.3197770"},{"key":"ref205","doi-asserted-by":"publisher","DOI":"10.1109\/TCE.2023.3339702"},{"key":"ref206","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijpe.2023.109095"},{"key":"ref207","first-page":"35051","article-title":"TabLeak: Tabular data leakage in federated learning","volume-title":"Proc. 40th Int. Conf. Mach. Learn.","author":"Vero"},{"key":"ref208","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i7.26083"},{"key":"ref209","doi-asserted-by":"publisher","DOI":"10.1109\/TMI.2023.3239391"}],"container-title":["IEEE Transactions on Neural Networks and Learning Systems"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/5962385\/11151745\/11005480.pdf?arnumber=11005480","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T17:47:08Z","timestamp":1757353628000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11005480\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9]]},"references-count":209,"journal-issue":{"issue":"9"},"URL":"https:\/\/doi.org\/10.1109\/tnnls.2025.3563537","relation":{},"ISSN":["2162-237X","2162-2388"],"issn-type":[{"value":"2162-237X","type":"print"},{"value":"2162-2388","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,9]]}}}