{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T05:17:58Z","timestamp":1780636678747,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":52,"publisher":"ACM","license":[{"start":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T00:00:00Z","timestamp":1638748800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2021,12,6]]},"DOI":"10.1145\/3485832.3488014","type":"proceedings-article","created":{"date-parts":[[2021,12,6]],"date-time":"2021-12-06T13:42:32Z","timestamp":1638798152000},"page":"45-60","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":55,"title":["Efficient, Private and Robust Federated Learning"],"prefix":"10.1145","author":[{"given":"Meng","family":"Hao","sequence":"first","affiliation":[{"name":"University of Electronic Science and Technology of China, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hongwei","family":"Li","sequence":"additional","affiliation":[{"name":"University of Electronic Science and Technology of China, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Guowen","family":"Xu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hanxiao","family":"Chen","sequence":"additional","affiliation":[{"name":"University of Electronic Science and Technology of China, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tianwei","family":"Zhang","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2021,12,6]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339819"},{"key":"e_1_3_2_1_2_1","first-page":"1333","article-title":"Privacy-preserving deep learning via additively homomorphic encryption","volume":"13","author":"Aono Yoshinori","year":"2017","unstructured":"Yoshinori Aono, Takuya Hayashi, Lihua Wang, Shiho Moriai, 2017. Privacy-preserving deep learning via additively homomorphic encryption. IEEE Transactions on Information Forensics and Security 13, 5(2017), 1333\u20131345.","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516738"},{"key":"e_1_3_2_1_4_1","volume-title":"Proceedings of AISTATS. 2938\u20132948","author":"Bagdasaryan Eugene","year":"2020","unstructured":"Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. In Proceedings of AISTATS. 2938\u20132948."},{"key":"e_1_3_2_1_5_1","volume-title":"Proceedings of NeuIPS.","author":"Baruch Moran","year":"2019","unstructured":"Moran Baruch, Gilad Baruch, and Yoav Goldberg. 2019. A little is enough: Circumventing defenses for distributed learning. In Proceedings of NeuIPS."},{"key":"e_1_3_2_1_6_1","volume-title":"Proceedings of CRYPTO. 420\u2013432","author":"Beaver Donald","year":"1991","unstructured":"Donald Beaver. 1991. Efficient multiparty protocols using circuit randomization. In Proceedings of CRYPTO. 420\u2013432."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417885"},{"key":"e_1_3_2_1_8_1","volume-title":"Proceedings of ICML. 634\u2013643","author":"Bhagoji Arjun\u00a0Nitin","year":"2019","unstructured":"Arjun\u00a0Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin Calo. 2019. Analyzing federated learning through an adversarial lens. In Proceedings of ICML. 634\u2013643."},{"key":"e_1_3_2_1_9_1","volume-title":"Proceedings of NeurIPS. 118\u2013128","author":"Blanchard Peva","year":"2017","unstructured":"Peva Blanchard, El\u00a0Mahdi El\u00a0Mhamdi, Rachid Guerraoui, and Julien Stainer. 2017. Machine learning with adversaries: Byzantine tolerant gradient descent. In Proceedings of NeurIPS. 118\u2013128."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of USENIX Security. 2111\u20132128","author":"Chen Hao","year":"2020","unstructured":"Hao Chen, Ilaria Chillotti, Yihe Dong, Oxana Poburinnaya, Ilya Razenshteyn, and M\u00a0Sadegh Riazi. 2020. {SANNS}: Scaling up secure approximate k-nearest neighbors search. In Proceedings of USENIX Security. 2111\u20132128."},{"key":"e_1_3_2_1_13_1","volume-title":"Proceedings of USENIX NSDI. 259\u2013282","author":"Corrigan-Gibbs Henry","year":"2017","unstructured":"Henry Corrigan-Gibbs and Dan Boneh. 2017. Prio: Private, robust, and scalable computation of aggregate statistics. In Proceedings of USENIX NSDI. 259\u2013282."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2015.23113"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIT.1976.1055638"},{"key":"e_1_3_2_1_16_1","volume-title":"Proceedings of ICML.","author":"El\u00a0Mhamdi El\u00a0Mahdi","year":"2018","unstructured":"El\u00a0Mahdi El\u00a0Mhamdi, Rachid Guerraoui, and S\u00e9bastien Louis\u00a0Alexandre Rouault. 2018. The Hidden Vulnerability of Distributed Learning in Byzantium. In Proceedings of ICML."},{"key":"e_1_3_2_1_17_1","unstructured":"Junfeng Fan and Frederik Vercauteren. 2012. Somewhat practical fully homomorphic encryption.IACR Cryptology ePrint Archive(2012)."},{"key":"e_1_3_2_1_18_1","volume-title":"Proceedings of USENIX Security. 1605\u20131622","author":"Fang Minghong","year":"2020","unstructured":"Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Gong. 2020. Local model poisoning attacks to Byzantine-robust federated learning. In Proceedings of USENIX Security. 1605\u20131622."},{"key":"e_1_3_2_1_19_1","unstructured":"FeatureCloud. [n.d.]. Transforming health care and medical research with federated learning. https:\/\/featurecloud.eu\/about\/our-vision\/."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR46437.2021.00018"},{"key":"e_1_3_2_1_21_1","volume-title":"Proceedings of NeurIPS.","author":"Geiping Jonas","year":"2020","unstructured":"Jonas Geiping, Hartmut Bauermeister, Hannah Dr\u00f6ge, and Michael Moeller. 2020. Inverting Gradients\u2013How easy is it to break privacy in federated learning?. In Proceedings of NeurIPS."},{"key":"e_1_3_2_1_22_1","volume-title":"Byzantine-Robust and Privacy-Preserving Framework for FedML. In ICLR Workshop on Security and Safety in Machine Learning Systems.","author":"Hashemi Hanieh","year":"2021","unstructured":"Hanieh Hashemi, Yongqin Wang, Chuan Guo, and Murali Annavaram. 2021. Byzantine-Robust and Privacy-Preserving Framework for FedML. In ICLR Workshop on Security and Safety in Machine Learning Systems."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_24_1","volume-title":"Secure byzantine-robust machine learning. arXiv:2006.04747","author":"He Lie","year":"2020","unstructured":"Lie He, Sai\u00a0Praneeth Karimireddy, and Martin Jaggi. 2020. Secure byzantine-robust machine learning. arXiv:2006.04747 (2020)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-45146-4_9"},{"key":"e_1_3_2_1_27_1","volume-title":"Proceedings of USENIX Security. 1651\u20131669","author":"Juvekar Chiraag","year":"2018","unstructured":"Chiraag Juvekar, Vinod Vaikuntanathan, and Anantha Chandrakasan. 2018. GAZELLE: A low latency framework for secure neural network inference. In Proceedings of USENIX Security. 1651\u20131669."},{"key":"e_1_3_2_1_28_1","volume-title":"Advances and open problems in federated learning. arXiv:1912.04977","author":"Kairouz Peter","year":"2019","unstructured":"Peter Kairouz, H\u00a0Brendan McMahan, Brendan Avent, Aur\u00e9lien Bellet, Mehdi Bennis, Arjun\u00a0Nitin Bhagoji, Keith Bonawitz, Zachary Charles, Graham Cormode, Rachel Cummings, 2019. Advances and open problems in federated learning. arXiv:1912.04977 (2019)."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCN49398.2020.9209670"},{"key":"e_1_3_2_1_30_1","volume-title":"Backpropagation applied to handwritten zip code recognition. Neural computation 1, 4","author":"LeCun Yann","year":"1989","unstructured":"Yann LeCun, Bernhard Boser, John\u00a0S Denker, Donnie Henderson, Richard\u00a0E Howard, Wayne Hubbard, and Lawrence\u00a0D Jackel. 1989. Backpropagation applied to handwritten zip code recognition. Neural computation 1, 4 (1989), 541\u2013551."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2020.3023430"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"e_1_3_2_1_33_1","volume-title":"Proceedings of AISTATS. 1273\u20131282","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise\u00a0Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Proceedings of AISTATS. 1273\u20131282."},{"key":"e_1_3_2_1_34_1","volume-title":"Proceedings of USENIX Security. 2505\u20132522","author":"Mishra Pratyush","year":"2020","unstructured":"Pratyush Mishra, Ryan Lehmkuhl, Akshayaram Srinivasan, Wenting Zheng, and Raluca\u00a0Ada Popa. 2020. Delphi: A cryptographic inference service for neural networks. In Proceedings of USENIX Security. 2505\u20132522."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2020-0080"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00065"},{"key":"e_1_3_2_1_38_1","volume-title":"FLGUARD: Secure and Private Federated Learning. arXiv preprint arXiv:2101.02281(2021).","author":"Nguyen Thien\u00a0Duc","year":"2021","unstructured":"Thien\u00a0Duc Nguyen, Phillip Rieger, Hossein Yalame, Helen M\u00f6llering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, Azalia Mirhoseini, Ahmad-Reza Sadeghi, Thomas Schneider, 2021. FLGUARD: Secure and Private Federated Learning. arXiv preprint arXiv:2101.02281(2021)."},{"key":"e_1_3_2_1_39_1","volume-title":"Privacy should not be a luxury good. The New York Times","author":"Pichai Sundar","year":"2019","unstructured":"Sundar Pichai. 2019. Privacy should not be a luxury good. The New York Times (2019)."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417274"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"e_1_3_2_1_42_1","volume-title":"Fully homomorphic SIMD operations. Designs, codes and cryptography 71, 1","author":"Smart P","year":"2014","unstructured":"Nigel\u00a0P Smart and Frederik Vercauteren. 2014. Fully homomorphic SIMD operations. Designs, codes and cryptography 71, 1 (2014), 57\u201381."},{"key":"e_1_3_2_1_43_1","volume-title":"Byzantine-resilient secure federated learning","author":"So Jinhyun","year":"2020","unstructured":"Jinhyun So, Ba\u015fak G\u00fcler, and A\u00a0Salman Avestimehr. 2020. Byzantine-resilient secure federated learning. IEEE Journal on Selected Areas in Communications (2020)."},{"key":"e_1_3_2_1_44_1","volume-title":"Proceedings of USENIX Security. 991\u20131008","author":"Van\u00a0Bulck Jo","year":"2018","unstructured":"Jo Van\u00a0Bulck, Marina Minkin, Ofir Weisse, Daniel Genkin, Baris Kasikci, Frank Piessens, Mark Silberstein, Thomas\u00a0F Wenisch, Yuval Yarom, and Raoul Strackx. 2018. Foreshadow: Extracting the keys to the intel {SGX} kingdom with transient out-of-order execution. In Proceedings of USENIX Security. 991\u20131008."},{"key":"e_1_3_2_1_45_1","unstructured":"Cong Xie Oluwasanmi Koyejo and Indranil Gupta. 2020. Fall of empires: Breaking Byzantine-tolerant SGD by inner product manipulation. In Uncertainty in Artificial Intelligence. 261\u2013270."},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2019.2929409"},{"key":"e_1_3_2_1_47_1","volume-title":"Applied federated learning: Improving google keyboard query suggestions. arXiv:1812.02903","author":"Yang Timothy","year":"2018","unstructured":"Timothy Yang, Galen Andrew, Hubert Eichner, Haicheng Sun, Wei Li, Nicholas Kong, Daniel Ramage, and Fran\u00e7oise Beaufays. 2018. Applied federated learning: Improving google keyboard query suggestions. arXiv:1812.02903 (2018)."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1982.45"},{"key":"e_1_3_2_1_49_1","volume-title":"Proceedings of ICML. 5650\u20135659","author":"Yin Dong","year":"2018","unstructured":"Dong Yin, Yudong Chen, Ramchandran Kannan, and Peter Bartlett. 2018. Byzantine-robust distributed learning: Towards optimal statistical rates. In Proceedings of ICML. 5650\u20135659."},{"key":"e_1_3_2_1_50_1","volume-title":"Proceedings of USENIX ATC. 493\u2013506","author":"Zhang Chengliang","year":"2020","unstructured":"Chengliang Zhang, Suyi Li, Junzhe Xia, Wei Wang, Feng Yan, and Yang Liu. 2020. Batchcrypt: Efficient homomorphic encryption for cross-silo federated learning. In Proceedings of USENIX ATC. 493\u2013506."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24351"},{"key":"e_1_3_2_1_52_1","volume-title":"Proceedings of NeurIPS.","author":"Zhu Ligeng","year":"2019","unstructured":"Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep Leakage from Gradients. In Proceedings of NeurIPS."}],"event":{"name":"ACSAC '21: Annual Computer Security Applications Conference","location":"Virtual Event USA","acronym":"ACSAC '21"},"container-title":["Annual Computer Security Applications Conference"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3488014","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3485832.3488014","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T19:18:30Z","timestamp":1755890310000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3485832.3488014"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,12,6]]},"references-count":52,"alternative-id":["10.1145\/3485832.3488014","10.1145\/3485832"],"URL":"https:\/\/doi.org\/10.1145\/3485832.3488014","relation":{},"subject":[],"published":{"date-parts":[[2021,12,6]]},"assertion":[{"value":"2021-12-06","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}