{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T16:52:52Z","timestamp":1784134372208,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":119,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,4,30]],"date-time":"2023-04-30T00:00:00Z","timestamp":1682812800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,4,30]]},"DOI":"10.1145\/3543873.3587681","type":"proceedings-article","created":{"date-parts":[[2023,4,28]],"date-time":"2023-04-28T11:36:14Z","timestamp":1682681774000},"page":"1167-1176","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":57,"title":["A Survey of Trustworthy Federated Learning with Perspectives on Security, Robustness and Privacy"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4185-8663","authenticated-orcid":false,"given":"Yifei","family":"Zhang","sequence":"first","affiliation":[{"name":"The Chinese University of Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4517-5379","authenticated-orcid":false,"given":"Dun","family":"Zeng","sequence":"additional","affiliation":[{"name":"University of Electronic Science and Technology of China and Peng Cheng Lab, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9705-7913","authenticated-orcid":false,"given":"Jinglong","family":"Luo","sequence":"additional","affiliation":[{"name":"Harbin Institute of Technology and Peng Cheng Lab, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5550-6461","authenticated-orcid":false,"given":"Zenglin","family":"Xu","sequence":"additional","affiliation":[{"name":"Harbin Institute of Technology and Peng Cheng Lab, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8106-6447","authenticated-orcid":false,"given":"Irwin","family":"King","sequence":"additional","affiliation":[{"name":"The Chinese University of Hong Kong, Hong Kong"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,4,30]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"crossref","unstructured":"Martin Abadi Andy Chu Ian Goodfellow H\u00a0Brendan McMahan Ilya Mironov Kunal Talwar and Li Zhang. 2016. Deep learning with differential privacy. In CCS.","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_2_1","unstructured":"Naman Agarwal Ananda\u00a0Theertha Suresh Felix\u00a0X. Yu Sanjiv Kumar and Brendan McMahan. 2018. cpSGD: Communication-efficient and differentially-private distributed SGD. In NeurIPS."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"crossref","unstructured":"Scott Alfeld Xiaojin Zhu and Paul Barford. 2016. Data Poisoning Attacks against Autoregressive Models. In AAAI.","DOI":"10.1609\/aaai.v30i1.10237"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS51616.2021.00086"},{"key":"e_1_3_2_1_5_1","volume-title":"Privacy-preserving deep learning via additively homomorphic encryption. TIFS","author":"Aono Yoshinori","year":"2017","unstructured":"Yoshinori Aono, Takuya Hayashi, Lihua Wang, Shiho Moriai, 2017. Privacy-preserving deep learning via additively homomorphic encryption. TIFS (2017)."},{"key":"e_1_3_2_1_6_1","volume-title":"Hacking smart machines with smarter ones: How to extract meaningful data from machine learning classifiers. ArXiv arXiv:1306.4447","author":"Ateniese Giuseppe","year":"2013","unstructured":"Giuseppe Ateniese, Giovanni Felici, Luigi\u00a0V Mancini, Angelo Spognardi, Antonio Villani, and Domenico Vitali. 2013. Hacking smart machines with smarter ones: How to extract meaningful data from machine learning classifiers. ArXiv arXiv:1306.4447 (2013)."},{"key":"e_1_3_2_1_7_1","unstructured":"Eugene Bagdasaryan Andreas Veit Yiqing Hua Deborah Estrin and Vitaly Shmatikov. 2020. How To Backdoor Federated Learning. In AISTATS."},{"key":"e_1_3_2_1_8_1","volume-title":"Safer: Sparse secure aggregation for federated learning. ArXiv","author":"Beguier Constance","year":"2020","unstructured":"Constance Beguier and Eric\u00a0W Tramel. 2020. Safer: Sparse secure aggregation for federated learning. ArXiv (2020)."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417885"},{"key":"e_1_3_2_1_10_1","unstructured":"Arjun\u00a0Nitin Bhagoji Supriyo Chakraborty Prateek Mittal and Seraphin\u00a0B. Calo. 2019. Analyzing Federated Learning through an Adversarial Lens. In ICML."},{"key":"e_1_3_2_1_11_1","volume-title":"Protection against reconstruction and its applications in private federated learning. ArXiv","author":"Bhowmick Abhishek","year":"2018","unstructured":"Abhishek Bhowmick, John Duchi, Julien Freudiger, Gaurav Kapoor, and Ryan Rogers. 2018. Protection against reconstruction and its applications in private federated learning. ArXiv (2018)."},{"key":"e_1_3_2_1_12_1","unstructured":"Battista Biggio Blaine Nelson and Pavel Laskov. 2012. Poisoning Attacks against Support Vector Machines. In ICML."},{"key":"e_1_3_2_1_13_1","unstructured":"Peva Blanchard El\u00a0Mahdi\u00a0El Mhamdi Rachid Guerraoui and Julien Stainer. 2017. Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent. In NeurIPS."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Keith Bonawitz Vladimir Ivanov Ben Kreuter Antonio Marcedone H\u00a0Brendan McMahan Sarvar Patel Daniel Ramage Aaron Segal and Karn Seth. 2017. Practical secure aggregation for privacy-preserving machine learning. In CCCS.","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1177\/1550147720919698"},{"key":"e_1_3_2_1_16_1","unstructured":"Xiaoyu Cao Minghong Fang Jia Liu and Neil\u00a0Zhenqiang Gong. 2021. FLTrust: Byzantine-robust Federated Learning via Trust Bootstrapping. In NDSS."},{"key":"e_1_3_2_1_17_1","volume-title":"Privacy preserving distributed machine learning with federated learning. Computer Communications","author":"Arachchige\u00a0Pathum Chamikara Mahawaga","year":"2021","unstructured":"Mahawaga Arachchige\u00a0Pathum Chamikara, Peter Bertok, Ibrahim Khalil, Dongxi Liu, and Seyit Camtepe. 2021. Privacy preserving distributed machine learning with federated learning. Computer Communications (2021)."},{"key":"e_1_3_2_1_18_1","volume-title":"Cronus: Robust and heterogeneous collaborative learning with black-box knowledge transfer. ArXiv","author":"Chang Hongyan","year":"2019","unstructured":"Hongyan Chang, Virat Shejwalkar, Reza Shokri, and Amir Houmansadr. 2019. Cronus: Robust and heterogeneous collaborative learning with black-box knowledge transfer. ArXiv (2019)."},{"key":"e_1_3_2_1_19_1","volume-title":"Property inference from poisoning. ArXiv","author":"Chase Melissa","year":"2021","unstructured":"Melissa Chase, Esha Ghosh, and Saeed Mahloujifar. 2021. Property inference from poisoning. ArXiv (2021)."},{"key":"e_1_3_2_1_20_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. ArXiv","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. ArXiv (2017)."},{"key":"e_1_3_2_1_21_1","volume-title":"A training-integrity privacy-preserving federated learning scheme with trusted execution environment. Information Sciences","author":"Chen Yu","year":"2020","unstructured":"Yu Chen, Fang Luo, Tong Li, Tao Xiang, Zheli Liu, and Jin Li. 2020. A training-integrity privacy-preserving federated learning scheme with trusted execution environment. Information Sciences (2020)."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3477114.3488765"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.3233\/FAIA200290"},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"crossref","unstructured":"Whitfield Diffie and Martin\u00a0E Hellman. 2022. New directions in cryptography. In Democratizing Cryptography: The Work of Whitfield Diffie and Martin Hellman.","DOI":"10.1145\/3549993.3550007"},{"key":"e_1_3_2_1_25_1","volume-title":"EaSTFLy: Efficient and secure ternary federated learning. Computers & Security","author":"Dong Ye","year":"2020","unstructured":"Ye Dong, Xiaojun Chen, Liyan Shen, and Dakui Wang. 2020. EaSTFLy: Efficient and secure ternary federated learning. Computers & Security (2020)."},{"key":"e_1_3_2_1_26_1","volume-title":"On the difficulties of disclosure prevention in statistical databases or the case for differential privacy. Journal of Privacy and Confidentiality","author":"Dwork Cynthia","year":"2010","unstructured":"Cynthia Dwork and Moni Naor. 2010. On the difficulties of disclosure prevention in statistical databases or the case for differential privacy. Journal of Privacy and Confidentiality (2010)."},{"key":"e_1_3_2_1_27_1","unstructured":"Minghong Fang Xiaoyu Cao Jinyuan Jia and Neil Gong. 2020. Local model poisoning attacks to { Byzantine-Robust} federated learning. In USENIX Security."},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813677"},{"key":"e_1_3_2_1_29_1","unstructured":"Matthew Fredrikson Eric Lantz Somesh Jha Simon Lin David Page and Thomas Ristenpart. 2014. Privacy in pharmacogenetics: An { End-to-End} case study of personalized warfarin dosing. In USENIX Security."},{"key":"e_1_3_2_1_30_1","volume-title":"Dancing in the dark: Private multi-party machine learning in an untrusted setting. ArXiv","author":"Fung Clement","year":"2018","unstructured":"Clement Fung, Jamie Koerner, Stewart Grant, and Ivan Beschastnikh. 2018. Dancing in the dark: Private multi-party machine learning in an untrusted setting. ArXiv (2018)."},{"key":"e_1_3_2_1_31_1","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID","author":"Fung Clement","year":"2020","unstructured":"Clement Fung, Chris\u00a0JM Yoon, and Ivan Beschastnikh. 2020. The limitations of federated learning in sybil settings. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020)."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CDC.2018.8619133"},{"key":"e_1_3_2_1_33_1","unstructured":"Jonas Geiping Hartmut Bauermeister Hannah Dr\u00f6ge and Michael Moeller. 2020. Inverting Gradients - How easy is it to break privacy in federated learning?. In NeurIPS."},{"key":"e_1_3_2_1_34_1","volume-title":"Differentially private federated learning: A client level perspective. ArXiv","author":"Geyer C","year":"2017","unstructured":"Robin\u00a0C Geyer, Tassilo Klein, and Moin Nabi. 2017. Differentially private federated learning: A client level perspective. ArXiv (2017)."},{"key":"e_1_3_2_1_35_1","volume-title":"V eri fl: Communication-efficient and fast verifiable aggregation for federated learning. TIFS","author":"Guo Xiaojie","year":"2020","unstructured":"Xiaojie Guo, Zheli Liu, Jin Li, Jiqiang Gao, Boyu Hou, Changyu Dong, and Thar Baker. 2020. V eri fl: Communication-efficient and fast verifiable aggregation for federated learning. TIFS (2020)."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"crossref","unstructured":"Yufei Han and Xiangliang Zhang. 2020. Robust Federated Learning via Collaborative Machine Teaching. In AAAI.","DOI":"10.1609\/aaai.v34i04.5826"},{"key":"e_1_3_2_1_37_1","volume-title":"Efficient and privacy-enhanced federated learning for industrial artificial intelligence","author":"Hao Meng","year":"2019","unstructured":"Meng Hao, Hongwei Li, Xizhao Luo, Guowen Xu, Haomiao Yang, and Sen Liu. 2019. Efficient and privacy-enhanced federated learning for industrial artificial intelligence. IEEE Trans Industr Inform (2019)."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICC.2019.8761267"},{"key":"e_1_3_2_1_39_1","unstructured":"Chaoyang He Murali Annavaram and Salman Avestimehr. 2020. Group Knowledge Transfer: Federated Learning of Large CNNs at the Edge. In NeurIPS."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134012"},{"key":"e_1_3_2_1_41_1","volume-title":"Multiple Perspectives on Artificial Intelligence in Healthcare","author":"Househ Mowafa","unstructured":"Mowafa Househ, Elizabeth Borycki, and Andre Kushniruk. 2021. Multiple Perspectives on Artificial Intelligence in Healthcare. Springer."},{"key":"e_1_3_2_1_42_1","unstructured":"Kevin Hsieh Amar Phanishayee Onur Mutlu and Phillip\u00a0B. Gibbons. 2020. The Non-IID Data Quagmire of Decentralized Machine Learning. In ICML."},{"key":"e_1_3_2_1_43_1","volume-title":"Personalized federated learning with differential privacy. IoT-J","author":"Hu Rui","year":"2020","unstructured":"Rui Hu, Yuanxiong Guo, Hongning Li, Qingqi Pei, and Yanmin Gong. 2020. Personalized federated learning with differential privacy. IoT-J (2020)."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3302505.3310070"},{"key":"e_1_3_2_1_45_1","volume-title":"SCAFFOLD: Stochastic Controlled Averaging for Federated Learning. In ICML.","author":"Karimireddy Sai\u00a0Praneeth","year":"2020","unstructured":"Sai\u00a0Praneeth Karimireddy, Satyen Kale, Mehryar Mohri, Sashank\u00a0J. Reddi, Sebastian\u00a0U. Stich, and Ananda\u00a0Theertha Suresh. 2020. SCAFFOLD: Stochastic Controlled Averaging for Federated Learning. In ICML."},{"key":"e_1_3_2_1_46_1","unstructured":"Bo Li Yining Wang Aarti Singh and Yevgeniy Vorobeychik. 2016. Data Poisoning Attacks on Factorization-Based Collaborative Filtering. In NeurIPS."},{"key":"e_1_3_2_1_47_1","volume-title":"Fedmd: Heterogenous federated learning via model distillation. ArXiv","author":"Li Daliang","year":"2019","unstructured":"Daliang Li and Junpu Wang. 2019. Fedmd: Heterogenous federated learning via model distillation. ArXiv (2019)."},{"key":"e_1_3_2_1_48_1","volume-title":"RSA: Byzantine-Robust Stochastic Aggregation Methods for Distributed Learning from Heterogeneous Datasets. In AAAI.","author":"Li Liping","year":"2019","unstructured":"Liping Li, Wei Xu, Tianyi Chen, Georgios\u00a0B. Giannakis, and Qing Ling. 2019. RSA: Byzantine-Robust Stochastic Aggregation Methods for Distributed Learning from Heterogeneous Datasets. In AAAI."},{"key":"e_1_3_2_1_49_1","volume-title":"Learning to detect malicious clients for robust federated learning. ArXiv","author":"Li Suyi","year":"2020","unstructured":"Suyi Li, Yong Cheng, Wei Wang, Yang Liu, and Tianjian Chen. 2020. Learning to detect malicious clients for robust federated learning. ArXiv (2020)."},{"key":"e_1_3_2_1_50_1","volume-title":"Ditto: Fair and Robust Federated Learning Through Personalization. In ICML.","author":"Li Tian","year":"2021","unstructured":"Tian Li, Shengyuan Hu, Ahmad Beirami, and Virginia Smith. 2021. Ditto: Fair and Robust Federated Learning Through Personalization. In ICML."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/MNET.011.2000604"},{"key":"e_1_3_2_1_52_1","volume-title":"Trustworthy ai: A computational perspective. ArXiv","author":"Liu Haochen","year":"2021","unstructured":"Haochen Liu, Yiqi Wang, Wenqi Fan, Xiaorui Liu, Yaxin Li, Shaili Jain, Yunhao Liu, Anil\u00a0K Jain, and Jiliang Tang. 2021. Trustworthy ai: A computational perspective. ArXiv (2021)."},{"key":"e_1_3_2_1_53_1","volume-title":"Technical Report: Assisting Backdoor Federated Learning with Whole Population Knowledge Alignment. ArXiv","author":"Liu Tian","year":"2022","unstructured":"Tian Liu, Xueyang Hu, and Tao Shu. 2022. Technical Report: Assisting Backdoor Federated Learning with Whole Population Knowledge Alignment. ArXiv (2022)."},{"key":"e_1_3_2_1_54_1","volume-title":"Adaptive privacy-preserving federated learning. Peer-to-Peer Networking and Applications","author":"Liu Xiaoyuan","year":"2020","unstructured":"Xiaoyuan Liu, Hongwei Li, Guowen Xu, Rongxing Lu, and Miao He. 2020. Adaptive privacy-preserving federated learning. Peer-to-Peer Networking and Applications (2020)."},{"key":"e_1_3_2_1_55_1","volume-title":"Sharing models or coresets: A study based on membership inference attack. ArXiv","author":"Lu Hanlin","year":"2020","unstructured":"Hanlin Lu, Changchang Liu, Ting He, Shiqiang Wang, and Kevin\u00a0S Chan. 2020. Sharing models or coresets: A study based on membership inference attack. ArXiv (2020)."},{"key":"e_1_3_2_1_56_1","volume-title":"Differentially private asynchronous federated learning for mobile edge computing in urban informatics","author":"Lu Yunlong","year":"2019","unstructured":"Yunlong Lu, Xiaohong Huang, Yueyue Dai, Sabita Maharjan, and Yan Zhang. 2019. Differentially private asynchronous federated learning for mobile edge computing in urban informatics. IEEE Trans Industr Inform (2019)."},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63076-8_1"},{"key":"e_1_3_2_1_58_1","volume-title":"Nike-based fast privacy-preserving highdimensional data aggregation for mobile devices","author":"Mandal Kalikinkar","year":"2018","unstructured":"Kalikinkar Mandal, Guang Gong, and Chuyi Liu. 2018. Nike-based fast privacy-preserving highdimensional data aggregation for mobile devices. IEEE T Depend Secure; Technical Report; University of Waterloo: Waterloo, ON, Canada (2018)."},{"key":"e_1_3_2_1_59_1","unstructured":"Brendan McMahan Eider Moore Daniel Ramage Seth Hampson and Blaise\u00a0Ag\u00fcera y Arcas. 2017. Communication-Efficient Learning of Deep Networks from Decentralized Data. In AISTATS."},{"key":"e_1_3_2_1_60_1","unstructured":"H.\u00a0Brendan McMahan Daniel Ramage Kunal Talwar and Li Zhang. 2018. Learning Differentially Private Recurrent Language Models. In ICLR."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"crossref","unstructured":"Luca Melis Congzheng Song Emiliano De\u00a0Cristofaro and Vitaly Shmatikov. 2019. Exploiting unintended feature leakage in collaborative learning. In SP.","DOI":"10.1109\/SP.2019.00029"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"crossref","unstructured":"Luca Melis Congzheng Song Emiliano De\u00a0Cristofaro and Vitaly Shmatikov. 2019. Exploiting unintended feature leakage in collaborative learning. In SP.","DOI":"10.1109\/SP.2019.00029"},{"key":"e_1_3_2_1_63_1","unstructured":"El\u00a0Mahdi\u00a0El Mhamdi Rachid Guerraoui and S\u00e9bastien Rouault. 2018. The Hidden Vulnerability of Distributed Learning in Byzantium. In ICML."},{"key":"e_1_3_2_1_64_1","volume-title":"Layer-wise characterization of latent information leakage in federated learning. ArXiv","author":"Mo Fan","year":"2020","unstructured":"Fan Mo, Anastasia Borovykh, Mohammad Malekzadeh, Hamed Haddadi, and Soteris Demetriou. 2020. Layer-wise characterization of latent information leakage in federated learning. ArXiv (2020)."},{"key":"e_1_3_2_1_65_1","volume-title":"Byzantine-robust federated machine learning through adaptive model averaging. ArXiv","author":"Mu\u00f1oz-Gonz\u00e1lez Luis","year":"2019","unstructured":"Luis Mu\u00f1oz-Gonz\u00e1lez, Kenneth\u00a0T Co, and Emil\u00a0C Lupu. 2019. Byzantine-robust federated machine learning through adaptive model averaging. ArXiv (2019)."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"crossref","unstructured":"Milad Nasr Reza Shokri and Amir Houmansadr. 2019. Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. In SP.","DOI":"10.1109\/SP.2019.00065"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"crossref","unstructured":"Kang\u00a0Loon Ng Zichen Chen Zelei Liu Han Yu Yang Liu and Qiang Yang. 2020. A Multi-player Game for Studying Federated Learning Incentive Schemes. In IJCAI.","DOI":"10.24963\/ijcai.2020\/769"},{"key":"e_1_3_2_1_68_1","volume-title":"Robust aggregation for federated learning. ArXiv","author":"Pillutla Krishna","year":"2019","unstructured":"Krishna Pillutla, Sham\u00a0M Kakade, and Zaid Harchaoui. 2019. Robust aggregation for federated learning. ArXiv (2019)."},{"key":"e_1_3_2_1_69_1","volume-title":"Towards Federated Learning with Byzantine-Robust Client Weighting. Applied Sciences","author":"Portnoy Amit","year":"2022","unstructured":"Amit Portnoy, Yoav Tirosh, and Danny Hendler. 2022. Towards Federated Learning with Byzantine-Robust Client Weighting. Applied Sciences (2022)."},{"key":"e_1_3_2_1_70_1","volume-title":"Mitigating byzantine attacks in federated learning. ArXiv","author":"Prakash Saurav","year":"2020","unstructured":"Saurav Prakash and Amir\u00a0Salman Avestimehr. 2020. Mitigating byzantine attacks in federated learning. ArXiv (2020)."},{"key":"e_1_3_2_1_71_1","unstructured":"Amirhossein Reisizadeh Farzan Farnia Ramtin Pedarsani and Ali Jadbabaie. 2020. Robust Federated Learning: The Case of Affine Distribution Shifts. In NeurIPS."},{"key":"e_1_3_2_1_72_1","volume-title":"Survey on federated learning threats: concepts, taxonomy on attacks and defences, experimental study and challenges. Information Fusion","author":"Rodr\u00edguez-Barroso Nuria","year":"2023","unstructured":"Nuria Rodr\u00edguez-Barroso, Daniel Jim\u00e9nez-L\u00f3pez, M\u00a0Victoria Luz\u00f3n, Francisco Herrera, and Eugenio Mart\u00ednez-C\u00e1mara. 2023. Survey on federated learning threats: concepts, taxonomy on attacks and defences, experimental study and challenges. Information Fusion (2023)."},{"key":"e_1_3_2_1_73_1","volume-title":"Poisoning Deep Learning based Recommender Model in Federated Learning Scenarios. ArXiv","author":"Rong Dazhong","year":"2022","unstructured":"Dazhong Rong, Qinming He, and Jianhai Chen. 2022. Poisoning Deep Learning based Recommender Model in Federated Learning Scenarios. ArXiv (2022)."},{"key":"e_1_3_2_1_74_1","volume-title":"Reconstruction of training samples from loss functions. ArXiv","author":"Sannai Akiyoshi","year":"2018","unstructured":"Akiyoshi Sannai. 2018. Reconstruction of training samples from loss functions. ArXiv (2018)."},{"key":"e_1_3_2_1_75_1","volume-title":"Federated knowledge distillation. ArXiv","author":"Seo Hyowoon","year":"2020","unstructured":"Hyowoon Seo, Jihong Park, Seungeun Oh, Mehdi Bennis, and Seong-Lyun Kim. 2020. Federated knowledge distillation. ArXiv (2020)."},{"key":"e_1_3_2_1_76_1","volume-title":"Exploiting unintended property leakage in blockchain-assisted federated learning for intelligent edge computing. IoT-J","author":"Shen Meng","year":"2020","unstructured":"Meng Shen, Huan Wang, Bin Zhang, Liehuang Zhu, Ke Xu, Qi Li, and Xiaojiang Du. 2020. Exploiting unintended property leakage in blockchain-assisted federated learning for intelligent edge computing. IoT-J (2020)."},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"crossref","unstructured":"Reza Shokri Marco Stronati Congzheng Song and Vitaly Shmatikov. 2017. Membership inference attacks against machine learning models. In SP.","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_78_1","volume-title":"The EU approach to ethics guidelines for trustworthy artificial intelligence. Computer Law Review International","author":"Smuha A","year":"2019","unstructured":"Nathalie\u00a0A Smuha. 2019. The EU approach to ethics guidelines for trustworthy artificial intelligence. Computer Law Review International (2019)."},{"key":"e_1_3_2_1_79_1","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2020.3000372"},{"key":"e_1_3_2_1_80_1","volume-title":"Can you really backdoor federated learning?ArXiv","author":"Sun Ziteng","year":"2019","unstructured":"Ziteng Sun, Peter Kairouz, Ananda\u00a0Theertha Suresh, and H\u00a0Brendan McMahan. 2019. Can you really backdoor federated learning?ArXiv (2019)."},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1109\/TNNLS.2022.3160699"},{"key":"e_1_3_2_1_82_1","doi-asserted-by":"crossref","unstructured":"Vale Tolpegin Stacey Truex Mehmet\u00a0Emre Gursoy and Ling Liu. 2020. Data poisoning attacks against federated learning systems. In ESORICS.","DOI":"10.1007\/978-3-030-58951-6_24"},{"key":"e_1_3_2_1_83_1","doi-asserted-by":"crossref","unstructured":"Stacey Truex Ling Liu Ka-Ho Chow Mehmet\u00a0Emre Gursoy and Wenqi Wei. 2020. LDP-Fed: Federated learning with local differential privacy.","DOI":"10.1145\/3378679.3394533"},{"key":"e_1_3_2_1_84_1","volume-title":"Demystifying membership inference attacks in machine learning as a service","author":"Truex Stacey","year":"2019","unstructured":"Stacey Truex, Ling Liu, Mehmet\u00a0Emre Gursoy, Lei Yu, and Wenqi Wei. 2019. Demystifying membership inference attacks in machine learning as a service. IEEE Transactions on Services Computing (2019)."},{"key":"e_1_3_2_1_85_1","unstructured":"Hongyi Wang Kartik Sreenivasan Shashank Rajput Harit Vishwakarma Saurabh Agarwal Jy-yong Sohn Kangwook Lee and Dimitris\u00a0S. Papailiopoulos. 2020. Attack of the Tails: Yes You Really Can Backdoor Federated Learning. In NeurIPS."},{"key":"e_1_3_2_1_86_1","unstructured":"Jianyu Wang Qinghua Liu Hao Liang Gauri Joshi and H.\u00a0Vincent Poor. 2020. Tackling the Objective Inconsistency Problem in Heterogeneous Federated Optimization. In NeurIPS."},{"key":"e_1_3_2_1_87_1","volume-title":"Eavesdrop the composition proportion of training labels in federated learning. ArXiv","author":"Wang Lixu","year":"2019","unstructured":"Lixu Wang, Shichao Xu, Xiao Wang, and Qi Zhu. 2019. Eavesdrop the composition proportion of training labels in federated learning. ArXiv (2019)."},{"key":"e_1_3_2_1_88_1","doi-asserted-by":"crossref","unstructured":"Yansheng Wang Yongxin Tong and Dingyuan Shi. 2020. Federated Latent Dirichlet Allocation: A Local Differential Privacy Based Framework. In AAAI.","DOI":"10.1609\/aaai.v34i04.6096"},{"key":"e_1_3_2_1_89_1","volume-title":"Beyond inferring class representatives: User-level privacy leakage from federated learning","author":"Wang Zhibo","unstructured":"Zhibo Wang, Mengkai Song, Zhifei Zhang, Yang Song, Qian Wang, and Hairong Qi. 2019. Beyond inferring class representatives: User-level privacy leakage from federated learning. In IEEE INFOCOM."},{"key":"e_1_3_2_1_90_1","volume-title":"Federated learning with differential privacy: Algorithms and performance analysis. TIFS","author":"Wei Kang","year":"2020","unstructured":"Kang Wei, Jun Li, Ming Ding, Chuan Ma, Howard\u00a0H Yang, Farhad Farokhi, Shi Jin, Tony\u00a0QS Quek, and H\u00a0Vincent Poor. 2020. Federated learning with differential privacy: Algorithms and performance analysis. TIFS (2020)."},{"key":"e_1_3_2_1_91_1","doi-asserted-by":"crossref","unstructured":"Wenqi Wei Ling Liu Margaret Loper Ka-Ho Chow Mehmet\u00a0Emre Gursoy Stacey Truex and Yanzhao Wu. 2020. A framework for evaluating client privacy leakages in federated learning. In ESORICS.","DOI":"10.1007\/978-3-030-58951-6_27"},{"key":"e_1_3_2_1_92_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2020.3012952"},{"key":"e_1_3_2_1_93_1","volume-title":"Differential privacy via wavelet transforms. TKDE","author":"Xiao Xiaokui","year":"2010","unstructured":"Xiaokui Xiao, Guozhang Wang, and Johannes Gehrke. 2010. Differential privacy via wavelet transforms. TKDE (2010)."},{"key":"e_1_3_2_1_94_1","volume-title":"CRFL: Certifiably Robust Federated Learning against Backdoor Attacks. In ICML.","author":"Xie Chulin","year":"2021","unstructured":"Chulin Xie, Minghao Chen, Pin-Yu Chen, and Bo Li. 2021. CRFL: Certifiably Robust Federated Learning against Backdoor Attacks. In ICML."},{"key":"e_1_3_2_1_95_1","volume-title":"DBA: Distributed Backdoor Attacks against Federated Learning. In ICLR.","author":"Xie Chulin","year":"2020","unstructured":"Chulin Xie, Keli Huang, Pin-Yu Chen, and Bo Li. 2020. DBA: Distributed Backdoor Attacks against Federated Learning. In ICLR."},{"key":"e_1_3_2_1_96_1","volume-title":"SLSGD: Secure and efficient distributed on-device machine learning. In ECML.","author":"Xie Cong","year":"2019","unstructured":"Cong Xie, Oluwasanmi Koyejo, and Indranil Gupta. 2019. SLSGD: Secure and efficient distributed on-device machine learning. In ECML."},{"key":"e_1_3_2_1_97_1","unstructured":"Cong Xie Sanmi Koyejo and Indranil Gupta. 2020. Zeno++: Robust Fully Asynchronous SGD. In ICML."},{"key":"e_1_3_2_1_98_1","volume-title":"Verifynet: Secure and verifiable federated learning. TIFS","author":"Xu Guowen","year":"2019","unstructured":"Guowen Xu, Hongwei Li, Sen Liu, Kan Yang, and Xiaodong Lin. 2019. Verifynet: Secure and verifiable federated learning. TIFS (2019)."},{"key":"e_1_3_2_1_99_1","doi-asserted-by":"crossref","unstructured":"Mingxue Xu and Xiangyang Li. 2020. Subject property inference attack in collaborative learning. In IHMSC.","DOI":"10.1109\/IHMSC49165.2020.00057"},{"key":"e_1_3_2_1_100_1","unstructured":"Xiaoyun Xu Jingzheng Wu Mutian Yang Tianyue Luo Xu Duan Weiheng Li Yanjun Wu and Bin Wu. 2020. Information leakage by model weights on federated learning."},{"key":"e_1_3_2_1_101_1","doi-asserted-by":"publisher","DOI":"10.5555\/1382436.1382751"},{"key":"e_1_3_2_1_102_1","unstructured":"Dong Yin Yudong Chen Kannan Ramchandran and Peter\u00a0L. Bartlett. 2018. Byzantine-Robust Distributed Learning: Towards Optimal Statistical Rates. In ICML."},{"key":"e_1_3_2_1_103_1","unstructured":"Hongxu Yin Arun Mallya Arash Vahdat Jose\u00a0M Alvarez Jan Kautz and Pavlo Molchanov. 2021. See through gradients: Image batch recovery via gradinversion. In CVPR."},{"key":"e_1_3_2_1_104_1","volume-title":"Gradient Obfuscation Gives a False Sense of Security in Federated Learning. ArXiv","author":"Yue Kai","year":"2022","unstructured":"Kai Yue, Richeng Jin, Chau-Wai Wong, Dror Baron, and Huaiyu Dai. 2022. Gradient Obfuscation Gives a False Sense of Security in Federated Learning. ArXiv (2022)."},{"key":"e_1_3_2_1_105_1","unstructured":"Chengliang Zhang Suyi Li Junzhe Xia Wei Wang Feng Yan and Yang Liu. 2020. BatchCrypt: Efficient Homomorphic Encryption for Cross-Silo Federated Learning. In USENIX ATC."},{"key":"e_1_3_2_1_106_1","volume-title":"Citadel: Protecting data privacy and model confidentiality for collaborative learning. In SoCC.","author":"Zhang Chengliang","year":"2021","unstructured":"Chengliang Zhang, Junzhe Xia, Baichen Yang, Huancheng Puyang, Wei Wang, Ruichuan Chen, Istemi\u00a0Ekin Akkus, Paarijaat Aditya, and Feng Yan. 2021. Citadel: Protecting data privacy and model confidentiality for collaborative learning. In SoCC."},{"key":"e_1_3_2_1_107_1","volume-title":"Trustworthy Graph Neural Networks: Aspects, Methods and Trends. ArXiv","author":"Zhang He","year":"2022","unstructured":"He Zhang, Bang Wu, Xingliang Yuan, Shirui Pan, Hanghang Tong, and Jian Pei. 2022. Trustworthy Graph Neural Networks: Aspects, Methods and Trends. ArXiv (2022)."},{"key":"e_1_3_2_1_108_1","unstructured":"Wanrong Zhang Shruti Tople and Olga Ohrimenko. 2021. Leakage of Dataset Properties in { Multi-Party} Machine Learning. In USENIX Security."},{"key":"e_1_3_2_1_109_1","doi-asserted-by":"crossref","unstructured":"Xianglong Zhang Anmin Fu Huaqun Wang Chunyi Zhou and Zhenzhu Chen. 2020. A privacy-preserving and verifiable federated learning scheme. In ICC.","DOI":"10.1109\/ICC40277.2020.9148628"},{"key":"e_1_3_2_1_110_1","volume-title":"Additively homomorphical encryption based deep neural network for asymmetrically collaborative machine learning. ArXiv","author":"Zhang Yifei","year":"2020","unstructured":"Yifei Zhang and Hao Zhu. 2020. Additively homomorphical encryption based deep neural network for asymmetrically collaborative machine learning. ArXiv (2020)."},{"key":"e_1_3_2_1_111_1","doi-asserted-by":"crossref","unstructured":"Zaixi Zhang Xiaoyu Cao Jinyuan Jia and Neil\u00a0Zhenqiang Gong. 2022. FLDetector: Defending Federated Learning Against Model Poisoning Attacks via Detecting Malicious Clients. In KDD.","DOI":"10.1145\/3534678.3539231"},{"key":"e_1_3_2_1_112_1","volume-title":"Anonymous and privacy-preserving federated learning with industrial big data. TII","author":"Zhao Bin","year":"2021","unstructured":"Bin Zhao, Kai Fan, Kan Yang, Zilong Wang, Hui Li, and Yintang Yang. 2021. Anonymous and privacy-preserving federated learning with industrial big data. TII (2021)."},{"key":"e_1_3_2_1_113_1","volume-title":"idlg: Improved deep leakage from gradients. ArXiv","author":"Zhao Bo","year":"2020","unstructured":"Bo Zhao, Konda\u00a0Reddy Mopuri, and Hakan Bilen. 2020. idlg: Improved deep leakage from gradients. ArXiv (2020)."},{"key":"e_1_3_2_1_114_1","doi-asserted-by":"crossref","unstructured":"Bo Zhao Peng Sun Tao Wang and Keyu Jiang. 2022. FedInv: Byzantine-robust Federated Learning by Inversing Local Model Updates. (2022).","DOI":"10.1609\/aaai.v36i8.20903"},{"key":"e_1_3_2_1_115_1","volume-title":"SMSS: Secure member selection strategy in federated learning","author":"Zhao Kun","year":"2020","unstructured":"Kun Zhao, Wei Xi, Zhi Wang, Jizhong Zhao, Ruimeng Wang, and Zhiping Jiang. 2020. SMSS: Secure member selection strategy in federated learning. IEEE Intelligent Systems (2020)."},{"key":"e_1_3_2_1_116_1","volume-title":"Federated learning with non-iid data. ArXiv","author":"Zhao Yue","year":"2018","unstructured":"Yue Zhao, Meng Li, Liangzhen Lai, Naveen Suda, Damon Civin, and Vikas Chandra. 2018. Federated learning with non-iid data. ArXiv (2018)."},{"key":"e_1_3_2_1_117_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neucom.2021.07.098"},{"key":"e_1_3_2_1_118_1","doi-asserted-by":"crossref","unstructured":"Ligeng Zhu Zhijian Liu and Song Han. 2019. Deep Leakage from Gradients. In NeurIPS.","DOI":"10.1007\/978-3-030-63076-8_2"},{"key":"e_1_3_2_1_119_1","unstructured":"Zhuangdi Zhu Junyuan Hong and Jiayu Zhou. 2021. Data-Free Knowledge Distillation for Heterogeneous Federated Learning. In ICML."}],"event":{"name":"WWW '23: The ACM Web Conference 2023","location":"Austin TX USA","acronym":"WWW '23","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Companion Proceedings of the ACM Web Conference 2023"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3543873.3587681","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3543873.3587681","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T23:29:59Z","timestamp":1755818999000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3543873.3587681"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,4,30]]},"references-count":119,"alternative-id":["10.1145\/3543873.3587681","10.1145\/3543873"],"URL":"https:\/\/doi.org\/10.1145\/3543873.3587681","relation":{},"subject":[],"published":{"date-parts":[[2023,4,30]]},"assertion":[{"value":"2023-04-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}