{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,21]],"date-time":"2026-04-21T14:53:10Z","timestamp":1776783190368,"version":"3.51.2"},"reference-count":68,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"am","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-22-1-2305"],"award-info":[{"award-number":["N00014-22-1-2305"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000006","name":"Office of Naval Research","doi-asserted-by":"publisher","award":["N00014-21-1-2472"],"award-info":[{"award-number":["N00014-21-1-2472"]}],"id":[{"id":"10.13039\/100000006","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["CNS-2212565"],"award-info":[{"award-number":["CNS-2212565"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000001","name":"National Science Foundation","doi-asserted-by":"publisher","award":["ECCS-2512911"],"award-info":[{"award-number":["ECCS-2512911"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Netw."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/ton.2025.3636809","type":"journal-article","created":{"date-parts":[[2025,12,8]],"date-time":"2025-12-08T18:39:36Z","timestamp":1765219176000},"page":"2004-2019","source":"Crossref","is-referenced-by-count":2,"title":["Cooperative Decentralized Backdoor Attacks on Vertical Federated Learning"],"prefix":"10.1109","volume":"34","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-3472-1847","authenticated-orcid":false,"given":"Seohyun","family":"Lee","sequence":"first","affiliation":[{"name":"Elmore Family School of Electrical and Computer Engineering, Purdue University, West Lafayette, IN, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3013-8978","authenticated-orcid":false,"given":"Wenzhi","family":"Fang","sequence":"additional","affiliation":[{"name":"Elmore Family School of Electrical and Computer Engineering, Purdue University, West Lafayette, IN, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3615-7400","authenticated-orcid":false,"given":"Anindya","family":"Bijoy Das","sequence":"additional","affiliation":[{"name":"Department of Electrical and Computer Engineering, The University of Akron, Akron, OH, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4266-4000","authenticated-orcid":false,"given":"Seyyedali","family":"Hosseinalipour","sequence":"additional","affiliation":[{"name":"Department of Electrical Engineering, University at Buffalo-SUNY, Buffalo, NY, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5922-4787","authenticated-orcid":false,"given":"David J.","family":"Love","sequence":"additional","affiliation":[{"name":"Elmore Family School of Electrical and Computer Engineering, Purdue University, West Lafayette, IN, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2771-3521","authenticated-orcid":false,"given":"Christopher G.","family":"Brinton","sequence":"additional","affiliation":[{"name":"Elmore Family School of Electrical and Computer Engineering, Purdue University, West Lafayette, IN, USA"}]}],"member":"263","reference":[{"key":"ref1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","volume-title":"Proc. 20th Int. Conf. Artif. Intell. Statist.","volume":"54","author":"McMahan"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3075203"},{"key":"ref3","first-page":"634","article-title":"Analyzing federated learning through an adversarial lens","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Bhagoji"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/657"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/LANMAN52105.2021.9478813"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3368879"},{"key":"ref7","first-page":"2938","article-title":"How to backdoor federated learning","volume-title":"Proc. Int. Conf. Artif. Intell. Statist.","author":"Bagdasaryan"},{"key":"ref8","article-title":"Vertical federated learning: Challenges, methodologies and experiments","author":"Wei","year":"2022","journal-title":"arXiv:2202.04309"},{"key":"ref9","article-title":"PyVertical: A vertical federated learning framework for multi-headed SplitNN","author":"Romanini","year":"2021","journal-title":"arXiv:2104.00489"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.3390\/s24030968"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2023.3275161"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE51399.2021.00023"},{"key":"ref13","first-page":"1397","article-title":"Label inference attacks against vertical federated learning","volume-title":"Proc. 31st USENIX Security Symp. (USENIX Security)","author":"Fu"},{"key":"ref14","article-title":"Overlearning reveals sensitive attributes","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Song"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i7.26083"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2018.8599802"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/PlatCon63925.2024.10830741"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3262614"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/jstsp.2025.3560914"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ICC51166.2024.10622460"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/SPAWC48557.2020.9154332"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP.2019.8683121"},{"key":"ref23","article-title":"Mitigating Sybils in federated learning poisoning","author":"Fung","year":"2018","journal-title":"arXiv:1808.04866"},{"key":"ref24","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Wang"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3529836.3529845"},{"key":"ref26","article-title":"DBA: Distributed backdoor attacks against federated learning","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Xie"},{"key":"ref27","first-page":"1415","article-title":"FLAME: Taming backdoors in federated learning","volume-title":"Proc. USENIX Secur. Symp.","author":"Nguyen"},{"key":"ref28","first-page":"301","article-title":"The limitations of federated learning in Sybil settings","volume-title":"Proc. Int. Symp. Res. Attacks","author":"Fung"},{"key":"ref29","first-page":"4387","article-title":"The non-IID data quagmire of decentralized machine learning","volume-title":"Proc. Int. Conf. Mach. Learn.","volume":"1","author":"Hsieh"},{"key":"ref30","article-title":"Badsfl: Backdoor attack against scaffold federated learning","author":"Han","year":"2024","journal-title":"arXiv:2411.16167"},{"key":"ref31","first-page":"5132","article-title":"SCAFFOLD: Stochastic controlled averaging for federated learning","volume-title":"Proc. Int. Conf. Mach. Learn.","author":"Karimireddy"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3422622"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-43415-0_24"},{"key":"ref35","first-page":"2743","article-title":"VILLAIN: Backdoor attacks against vertical split learning","volume-title":"Proc. USENIX Secur. Symp.","author":"Bai"},{"key":"ref36","article-title":"Backdoor attacks and defenses in feature-partitioned collaborative learning","author":"Liu","year":"2020","journal-title":"arXiv:2007.03608"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3327853"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/ICDM58522.2023.00013"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2024\/877"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00008"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2024.3352628"},{"key":"ref42","article-title":"Universal adversarial backdoor attacks to fool vertical federated learning in cloud-edge collaboration","author":"Chen","year":"2023","journal-title":"arXiv:2304.11432"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1312.6114"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/SMC.2018.00080"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1214\/aoms\/1177729694"},{"key":"ref47","article-title":"TVAE: Triplet-based variational autoencoder using metric learning","author":"Ishfaq","year":"2018","journal-title":"arXiv:1802.04403"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN52387.2021.9533325"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.5555\/3524938.3525087"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1090\/qam\/102435"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1137\/16M1080173"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2022.3214122"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.21136\/CMJ.1973.101168"},{"key":"ref54","article-title":"VAFL: A method of vertical asynchronous federated learning","author":"Chen","year":"2020","journal-title":"arXiv:2007.06081"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2211477"},{"key":"ref56","article-title":"Fashion-MNIST: A novel image dataset for benchmarking machine learning algorithms","author":"Xiao","year":"2017","journal-title":"arXiv:1708.07747"},{"key":"ref57","article-title":"Learning multiple layers of features from tiny images","author":"Krizhevsky","year":"2009"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.2118\/18761-MS"},{"key":"ref59","first-page":"4003","article-title":"Self-supervised relational reasoning for representation learning","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Patacchiola"},{"key":"ref60","first-page":"26342","article-title":"CHiLS: Zero-shot image classification with hierarchical label sets","volume-title":"Proc. Int. Conf. Mach. Learn. (ICML)","author":"Novack"},{"key":"ref61","article-title":"Adam: A method for stochastic optimization","author":"Kingma","year":"2014","journal-title":"arXiv:1412.6980"},{"key":"ref62","first-page":"8026","article-title":"PyTorch: An imperative style, high-performance deep learning library","volume-title":"Proc. Adv. neural Inf. Process. Syst.","volume":"32","author":"Paszke"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30131"},{"key":"ref64","first-page":"14774","article-title":"Deep leakage from gradients","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","author":"Mu"},{"key":"ref65","article-title":"An image is worth 16\u00d716 words: Transformers for image recognition at scale","volume-title":"Proc. Int. Conf. Learn. Represent.","author":"Dosovitskiy"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00633"},{"key":"ref67","doi-asserted-by":"publisher","DOI":"10.1109\/WACV56688.2023.00491"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01687"}],"container-title":["IEEE Transactions on Networking"],"original-title":[],"link":[{"URL":"https:\/\/ieeexplore.ieee.org\/ielam\/10723154\/11317935\/11281881-aam.pdf","content-type":"application\/pdf","content-version":"am","intended-application":"syndication"},{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10723154\/11317935\/11281881.pdf?arnumber=11281881","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,12]],"date-time":"2026-01-12T21:59:36Z","timestamp":1768255176000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11281881\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":68,"URL":"https:\/\/doi.org\/10.1109\/ton.2025.3636809","relation":{},"ISSN":["2998-4157"],"issn-type":[{"value":"2998-4157","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}