{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T15:41:54Z","timestamp":1783525314983,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":86,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,11,21]],"date-time":"2024-11-21T00:00:00Z","timestamp":1732147200000},"content-version":"vor","delay-in-days":372,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"AI Singapore Programme","award":["AISG2-RP-2020-018"],"award-info":[{"award-number":["AISG2-RP-2020-018"]}]},{"name":"C3AI"},{"name":"Amazon Research Award"},{"name":"DARPA GARD","award":["HR00112020007"],"award-info":[{"award-number":["HR00112020007"]}]},{"DOI":"10.13039\/100000001","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["1910100,2046726,2046795,2205329"],"award-info":[{"award-number":["1910100,2046726,2046795,2205329"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100000879","name":"Alfred P. Sloan Foundation","doi-asserted-by":"publisher","id":[{"id":"10.13039\/100000879","id-type":"DOI","asserted-by":"publisher"}]},{"name":"DARPA contract","award":["N66001-15-C-4066"],"award-info":[{"award-number":["N66001-15-C-4066"]}]},{"name":"NSF ACTION Institute"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3623193","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"1511-1525","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":18,"title":["Unraveling the Connections between Privacy and Certified Robustness in Federated Learning Against Poisoning Attacks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5460-3785","authenticated-orcid":false,"given":"Chulin","family":"Xie","sequence":"first","affiliation":[{"name":"University of Illinois at Urbana-Champaign, Urbana, IL, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-2603-5550","authenticated-orcid":false,"given":"Yunhui","family":"Long","sequence":"additional","affiliation":[{"name":"University of Illinois at Urbana-Champaign, Urbana, IL, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1039-8369","authenticated-orcid":false,"given":"Pin-Yu","family":"Chen","sequence":"additional","affiliation":[{"name":"IBM Research, New York, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6539-6443","authenticated-orcid":false,"given":"Qinbin","family":"Li","sequence":"additional","affiliation":[{"name":"UC Berkeley, Berkeley, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4023-419X","authenticated-orcid":false,"given":"Sanmi","family":"Koyejo","sequence":"additional","affiliation":[{"name":"Stanford University, Stanford, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4883-7267","authenticated-orcid":false,"given":"Bo","family":"Li","sequence":"additional","affiliation":[{"name":"University of Illinois at Urbana-Champaign, Urbana, IL, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_1_2_1","volume-title":"Proceedings of the 32nd International Conference on Neural Information Processing Systems. 7575--7586","author":"Agarwal Naman","year":"2018","unstructured":"Naman Agarwal, Ananda Theertha Suresh, Felix Yu, Sanjiv Kumar, and H Brendan McMahan. 2018. cpSGD: communication-efficient and differentially-private distributed SGD. In Proceedings of the 32nd International Conference on Neural Information Processing Systems. 7575--7586."},{"key":"e_1_3_2_1_3_1","volume-title":"ICML Workshop on Federated Learning for User Privacy and Data Confidentiality.","author":"Asoodeh Shahab","year":"2020","unstructured":"Shahab Asoodeh and F Calmon. 2020. Differentially private federated learning: An information-theoretic perspective. In ICML Workshop on Federated Learning for User Privacy and Data Confidentiality."},{"key":"e_1_3_2_1_4_1","volume-title":"International Conference on Artificial Intelligence and Statistics. PMLR, 2938--2948","author":"Bagdasaryan Eugene","year":"2020","unstructured":"Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. In International Conference on Artificial Intelligence and Statistics. PMLR, 2938--2948."},{"key":"e_1_3_2_1_5_1","volume-title":"International Conference on Artificial Intelligence and Statistics. PMLR, 2496--2506","author":"Balle Borja","year":"2020","unstructured":"Borja Balle, Gilles Barthe, Marco Gaboardi, Justin Hsu, and Tetsuya Sato. 2020. Hypothesis testing interpretations and renyi differential privacy. In International Conference on Artificial Intelligence and Statistics. PMLR, 2496--2506."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS.2014.56"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/62212.62213"},{"key":"e_1_3_2_1_8_1","volume-title":"International Conference on Machine Learning. 634--643","author":"Bhagoji Arjun Nitin","year":"2019","unstructured":"Arjun Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin Calo. 2019. Analyzing Federated Learning through an Adversarial Lens. In International Conference on Machine Learning. 634--643."},{"key":"e_1_3_2_1_9_1","volume-title":"Protection against reconstruction and its applications in private federated learning. arXiv preprint arXiv:1812.00984","author":"Bhowmick Abhishek","year":"2018","unstructured":"Abhishek Bhowmick, John Duchi, Julien Freudiger, Gaurav Kapoor, and Ryan Rogers. 2018. Protection against reconstruction and its applications in private federated learning. arXiv preprint arXiv:1812.00984 (2018)."},{"key":"e_1_3_2_1_10_1","volume-title":"Proceedings of the 29th International Coference on International Conference on Machine Learning. 1467--1474","author":"Biggio Battista","year":"2012","unstructured":"Battista Biggio, Blaine Nelson, and Pavel Laskov. 2012. Poisoning attacks against support vector machines. Proceedings of the 29th International Coference on International Conference on Machine Learning. 1467--1474."},{"key":"e_1_3_2_1_11_1","volume-title":"Rachid Guerraoui, and Julien Stainer.","author":"Blanchard Peva","year":"2017","unstructured":"Peva Blanchard, El Mahdi El Mhamdi, Rachid Guerraoui, and Julien Stainer. 2017. Machine learning with adversaries: Byzantine tolerant gradient descent. In NeurIPS. 118--128."},{"key":"e_1_3_2_1_12_1","first-page":"374","article-title":"Towards federated learning at scale: System design","volume":"1","author":"Bonawitz Keith","year":"2019","unstructured":"Keith Bonawitz, Hubert Eichner, Wolfgang Grieskamp, Dzmitry Huba, Alex Ingerman, Vladimir Ivanov, Chloe Kiddon, Jakub Kone\u010dn\u1ef3, Stefano Mazzocchi, Brendan McMahan, et al. 2019. Towards federated learning at scale: System design. Proceedings of Machine Learning and Systems, Vol. 1 (2019), 374--388.","journal-title":"Proceedings of Machine Learning and Systems"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"Keith Bonawitz Vladimir Ivanov Ben Kreuter Antonio Marcedone H Brendan McMahan Sarvar Patel Daniel Ramage Aaron Segal and Karn Seth. 2017. Practical secure aggregation for privacy-preserving machine learning. In CCS.","DOI":"10.1145\/3133956.3133982"},{"key":"e_1_3_2_1_14_1","volume-title":"Ioannis Ch Paschalidis, and Wei Shi","author":"Brisimi Theodora S","year":"2018","unstructured":"Theodora S Brisimi, Ruidi Chen, Theofanie Mela, Alex Olshevsky, Ioannis Ch Paschalidis, and Wei Shi. 2018. Federated learning of predictive models from federated electronic health records. International journal of medical informatics, Vol. 112 (2018), 59--67."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i8.16849"},{"key":"e_1_3_2_1_16_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00988"},{"key":"e_1_3_2_1_18_1","volume-title":"international conference on machine learning. PMLR, 1310--1320","author":"Cohen Jeremy","year":"2019","unstructured":"Jeremy Cohen, Elan Rosenfeld, and Zico Kolter. 2019a. Certified adversarial robustness via randomized smoothing. In international conference on machine learning. PMLR, 1310--1320."},{"key":"e_1_3_2_1_19_1","volume-title":"International Conference on Machine Learning. PMLR, 1310--1320","author":"Cohen Jeremy","year":"2019","unstructured":"Jeremy Cohen, Elan Rosenfeld, and Zico Kolter. 2019b. Certified adversarial robustness via randomized smoothing. In International Conference on Machine Learning. PMLR, 1310--1320."},{"key":"e_1_3_2_1_20_1","volume-title":"International Conference on Learning Representations.","author":"Dvijotham Krishnamurthy","year":"2020","unstructured":"Krishnamurthy (Dj) Dvijotham, Jamie Hayes, Borja Balle, Zico Kolter, Chongli Qin, Andras Gyorgy, Kai Xiao, Sven Gowal, and Pushmeet Kohli. 2020. A framework for robustness certification of smoothed classifiers using f-divergences. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"crossref","unstructured":"Cynthia Dwork Krishnaram Kenthapadi Frank McSherry Ilya Mironov and Moni Naor. 2006. Our data ourselves: Privacy via distributed noise generation. In Advances in Cryptology - EUROCRYPT.","DOI":"10.1007\/11761679_29"},{"key":"e_1_3_2_1_22_1","first-page":"3","article-title":"The Algorithmic Foundations of Differential Privacy","volume":"9","author":"Dwork Cynthia","year":"2014","unstructured":"Cynthia Dwork and Aaron Roth. 2014. The Algorithmic Foundations of Differential Privacy. Foundations and Trends in Theoretical Computer Science, Vol. 9, 3--4 (2014), 211--407.","journal-title":"Foundations and Trends in Theoretical Computer Science"},{"key":"e_1_3_2_1_23_1","volume-title":"The Hidden Vulnerability of Distributed Learning in Byzantium. In International Conference on Machine Learning.","author":"El Mhamdi El Mahdi","year":"2018","unstructured":"El Mahdi El Mhamdi, Rachid Guerraoui, and S\u00e9bastien Louis Alexandre Rouault. 2018. The Hidden Vulnerability of Distributed Learning in Byzantium. In International Conference on Machine Learning."},{"key":"e_1_3_2_1_24_1","volume-title":"USENIX Security Symposium. 1605--1622","author":"Fang Minghong","year":"2020","unstructured":"Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Gong. 2020. Local model poisoning attacks to Byzantine-robust federated learning. In USENIX Security Symposium. 1605--1622."},{"key":"e_1_3_2_1_25_1","volume-title":"Sharpness-aware Minimization for Efficiently Improving Generalization. In International Conference on Learning Representations.","author":"Foret Pierre","year":"2021","unstructured":"Pierre Foret, Ariel Kleiner, Hossein Mobahi, and Behnam Neyshabur. 2021. Sharpness-aware Minimization for Efficiently Improving Generalization. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_26_1","volume-title":"Attack-resistant federated learning with residual-based reweighting. arXiv preprint arXiv:1912.11464","author":"Fu Shuhao","year":"2019","unstructured":"Shuhao Fu, Chulin Xie, Bo Li, and Qifeng Chen. 2019. Attack-resistant federated learning with residual-based reweighting. arXiv preprint arXiv:1912.11464 (2019)."},{"key":"e_1_3_2_1_27_1","volume-title":"The Limitations of Federated Learning in Sybil Settings. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses ({RAID}","author":"Fung Clement","year":"2020","unstructured":"Clement Fung, Chris JM Yoon, and Ivan Beschastnikh. 2020. The Limitations of Federated Learning in Sybil Settings. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses ({RAID} 2020). 301--316."},{"key":"e_1_3_2_1_28_1","volume-title":"Differentially private federated learning: A client level perspective. arXiv preprint arXiv:1712.07557","author":"Geyer Robin C","year":"2017","unstructured":"Robin C Geyer, Tassilo Klein, and Moin Nabi. 2017. Differentially private federated learning: A client level perspective. arXiv preprint arXiv:1712.07557 (2017)."},{"key":"e_1_3_2_1_29_1","volume-title":"International Conference on Artificial Intelligence and Statistics. PMLR, 2521--2529","author":"Girgis Antonious","year":"2021","unstructured":"Antonious Girgis, Deepesh Data, Suhas Diggavi, Peter Kairouz, and Ananda Theertha Suresh. 2021. Shuffled model of differential privacy in federated learning. In International Conference on Artificial Intelligence and Statistics. PMLR, 2521--2529."},{"key":"e_1_3_2_1_30_1","unstructured":"Alec Go Richa Bhayani and Lei Huang. 2009. Twitter sentiment classification using distant supervision. (2009)."},{"key":"e_1_3_2_1_31_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_2_1_33_1","volume-title":"Probability inequalities for sums of bounded random variables. The Collected Works of Wassily Hoeffding","author":"Hoeffding Wassily","unstructured":"Wassily Hoeffding. 1994. Probability inequalities for sums of bounded random variables. The Collected Works of Wassily Hoeffding. Springer, 409--426."},{"key":"e_1_3_2_1_34_1","volume-title":"Tudor Dumitracs, and Nicolas Papernot.","author":"Hong Sanghyun","year":"2020","unstructured":"Sanghyun Hong, Varun Chandrasekaran, Yiug itcan Kaya, Tudor Dumitracs, and Nicolas Papernot. 2020. On the effectiveness of mitigating data poisoning attacks with gradient shaping. arXiv preprint arXiv:2002.11497 (2020)."},{"key":"e_1_3_2_1_35_1","volume-title":"Measuring the effects of non-identical data distribution for federated visual classification. arXiv preprint arXiv:1909.06335","author":"Harry Hsu Tzu-Ming","year":"2019","unstructured":"Tzu-Ming Harry Hsu, Hang Qi, and Matthew Brown. 2019. Measuring the effects of non-identical data distribution for federated visual classification. arXiv preprint arXiv:1909.06335 (2019)."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046684.2046692"},{"key":"e_1_3_2_1_37_1","volume-title":"Advances in Neural Information Processing Systems","volume":"33","author":"Jagielski Matthew","year":"2020","unstructured":"Matthew Jagielski, Jonathan Ullman, and Alina Oprea. 2020. Auditing Differentially Private Machine Learning: How Private is Private SGD? Advances in Neural Information Processing Systems, Vol. 33 (2020)."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i9.16971"},{"key":"e_1_3_2_1_39_1","unstructured":"Jinyuan Jia Yupei Liu Xiaoyu Cao and Neil Zhenqiang Gong. 2022. Certified Robustness of Nearest Neighbors against Data Poisoning and Backdoor Attacks. AAAI."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1561\/9781680837896"},{"key":"e_1_3_2_1_41_1","unstructured":"Alex Krizhevsky. 2009. Learning multiple layers of features from tiny images. Technical Report."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00044"},{"key":"e_1_3_2_1_43_1","volume-title":"Deep partition aggregation: Provable defense against general poisoning attacks. ICLR","author":"Levine Alexander","year":"2021","unstructured":"Alexander Levine and Soheil Feizi. 2021. Deep partition aggregation: Provable defense against general poisoning attacks. ICLR (2021)."},{"key":"e_1_3_2_1_44_1","volume-title":"SoK: Certified Robustness for Deep Neural Networks. In 2023 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 94--115","author":"Li Linyi","year":"2022","unstructured":"Linyi Li, Tao Xie, and Bo Li. 2022. SoK: Certified Robustness for Deep Neural Networks. In 2023 IEEE Symposium on Security and Privacy (SP). IEEE Computer Society, 94--115."},{"key":"e_1_3_2_1_45_1","volume-title":"Manzil Zaheer, Maziar Sanjabi, Ameet Talwalkar, and Virginia Smith.","author":"Li Tian","year":"2018","unstructured":"Tian Li, Anit Kumar Sahu, Manzil Zaheer, Maziar Sanjabi, Ameet Talwalkar, and Virginia Smith. 2018. Federated optimization in heterogeneous networks. arXiv preprint arXiv:1812.06127 (2018)."},{"key":"e_1_3_2_1_46_1","volume-title":"Exploring private federated learning with laplacian smoothing. arXiv preprint arXiv:2005.00218","author":"Liang Zhicong","year":"2020","unstructured":"Zhicong Liang, Bao Wang, Quanquan Gu, Stanley Osher, and Yuan Yao. 2020. Exploring private federated learning with laplacian smoothing. arXiv preprint arXiv:2005.00218 (2020)."},{"key":"e_1_3_2_1_47_1","volume-title":"Certifiably Robust Interpretation via R\u00e9nyi Differential Privacy. Artif. Intell","author":"Liu Ao","year":"2022","unstructured":"Ao Liu, Xiaoyu Chen, Sijia Liu, Lirong Xia, and Chuang Gan. 2022a. Certifiably Robust Interpretation via R\u00e9nyi Differential Privacy. Artif. Intell., Vol. 313, C (dec 2022), 14."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.14778\/3503585.3503592"},{"key":"e_1_3_2_1_49_1","first-page":"5925","article-title":"On privacy and personalization in cross-silo federated learning","volume":"35","author":"Liu Ken","year":"2022","unstructured":"Ken Liu, Shengyuan Hu, Steven Z Wu, and Virginia Smith. 2022b. On privacy and personalization in cross-silo federated learning. Advances in Neural Information Processing Systems, Vol. 35 (2022), 5925--5940.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.24963\/ijcai.2019\/657"},{"key":"e_1_3_2_1_51_1","volume-title":"Dopamine: Differentially Private Federated Learning on Medical Data. The Second AAAI Workshop on Privacy-Preserving Artificial Intelligence (PPAI-21)","author":"Malekzadeh Mohammad","year":"2021","unstructured":"Mohammad Malekzadeh, Burak Hasircioglu, Nitish Mital, Kunal Katarya, Mehmet Emre Ozfatura, and Deniz Gunduz. 2021. Dopamine: Differentially Private Federated Learning on Medical Data. The Second AAAI Workshop on Privacy-Preserving Artificial Intelligence (PPAI-21) (2021)."},{"key":"e_1_3_2_1_52_1","volume-title":"Proceedings of the 20th International Conference on Artificial Intelligence and Statistics","volume":"54","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-Efficient Learning of Deep Networks from Decentralized Data. In Proceedings of the 20th International Conference on Artificial Intelligence and Statistics, Vol. 54. PMLR, 1273--1282."},{"key":"e_1_3_2_1_53_1","volume-title":"Learning Differentially Private Recurrent Language Models. In International Conference on Learning Representations.","author":"McMahan H Brendan","year":"2018","unstructured":"H Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. 2018. Learning Differentially Private Recurrent Language Models. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/1559845.1559850"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/CSF.2017.11"},{"key":"e_1_3_2_1_56_1","volume-title":"Local and Central Differential Privacy for Robustness and Privacy in Federated Learning. NDSS","author":"Naseri Mohammad","year":"2022","unstructured":"Mohammad Naseri, Jamie Hayes, and Emiliano De Cristofaro. 2022. Local and Central Differential Privacy for Robustness and Privacy in Federated Learning. NDSS (2022)."},{"key":"e_1_3_2_1_57_1","volume-title":"USENIX Security Symposium.","author":"Nguyen Thien Duc","year":"2022","unstructured":"Thien Duc Nguyen, Phillip Rieger, Roberta De Viti, Huili Chen, et al. 2022. {FLAME}: Taming backdoors in federated learning. In USENIX Security Symposium."},{"key":"e_1_3_2_1_58_1","volume-title":"International Conference on Artificial Intelligence and Statistics. PMLR, 10110--10145","author":"Noble Maxence","year":"2022","unstructured":"Maxence Noble, Aur\u00e9lien Bellet, and Aymeric Dieuleveut. 2022. Differentially private federated learning on heterogeneous data. In International Conference on Artificial Intelligence and Statistics. PMLR, 10110--10145."},{"key":"e_1_3_2_1_59_1","unstructured":"Adam Paszke Sam Gross Francisco Massa et al. 2019. PyTorch: An Imperative Style High-Performance Deep Learning Library. NeurIPS. 8024--8035."},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.3115\/v1\/D14-1162"},{"key":"e_1_3_2_1_61_1","volume-title":"Robust aggregation for federated learning. arXiv preprint arXiv:1912.13445","author":"Pillutla Krishna","year":"2019","unstructured":"Krishna Pillutla, Sham M Kakade, and Zaid Harchaoui. 2019. Robust aggregation for federated learning. arXiv preprint arXiv:1912.13445 (2019)."},{"key":"e_1_3_2_1_62_1","unstructured":"PyTorch. 2021. Opacus - Train PyTorch models with Differential Privacy. (2021). https:\/\/opacus.ai\/"},{"key":"e_1_3_2_1_63_1","unstructured":"Google Research. 2023. Distributed differential privacy for federated learning. https:\/\/ai.googleblog.com\/2023\/03\/distributed-differential-privacy-for.html. (2023). Accessed: 2023-08-16."},{"key":"e_1_3_2_1_64_1","unstructured":"MIT Technology Review. 2019. How Apple personalizes Siri without hoovering up your data. https:\/\/www.technologyreview.com\/2019\/12\/11\/131629\/apple-ai-personalizes-siri-federated-learning\/. (2019). Accessed: 2023-08-16."},{"key":"e_1_3_2_1_65_1","volume-title":"International Conference on Machine Learning. PMLR, 8230--8241","author":"Rosenfeld Elan","year":"2020","unstructured":"Elan Rosenfeld, Ezra Winston, Pradeep Ravikumar, and Zico Kolter. 2020. Certified robustness to label-flipping attacks via randomized smoothing. In International Conference on Machine Learning. PMLR, 8230--8241."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3195970.3196023"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"crossref","unstructured":"Virat Shejwalkar and Amir Houmansadr. 2021. Manipulating the byzantine: Optimizing model poisoning attacks and defenses for federated learning. In NDSS.","DOI":"10.14722\/ndss.2021.24498"},{"key":"e_1_3_2_1_68_1","volume-title":"Make Landscape Flatter in Differentially Private Federated Learning. CVPR","author":"Shi Yifan","year":"2023","unstructured":"Yifan Shi, Yingqi Liu, Kang Wei, Li Shen, Xueqian Wang, and Dacheng Tao. 2023. Make Landscape Flatter in Differentially Private Federated Learning. CVPR (2023)."},{"key":"e_1_3_2_1_69_1","volume-title":"Ananda Theertha Suresh, and H Brendan McMahan","author":"Sun Ziteng","year":"2019","unstructured":"Ziteng Sun, Peter Kairouz, Ananda Theertha Suresh, and H Brendan McMahan. 2019. Can you really backdoor federated learning? arXiv preprint arXiv:1911.07963 (2019)."},{"key":"e_1_3_2_1_70_1","volume-title":"Garnett (Eds.)","volume":"31","author":"Tran Brandon","year":"2018","unstructured":"Brandon Tran, Jerry Li, and Aleksander Madry. 2018. Spectral Signatures in Backdoor Attacks. In Advances in Neural Information Processing Systems, S. Bengio, H. Wallach, H. Larochelle, K. Grauman, N. Cesa-Bianchi, and R. Garnett (Eds.), Vol. 31."},{"key":"e_1_3_2_1_71_1","unstructured":"Stephen Tu. 2013. Lecture 20: Introduction to Differential Privacy. (2013). https:\/\/stephentu.github.io\/writeups\/6885-lec20-b.pdf"},{"key":"e_1_3_2_1_72_1","volume-title":"Attack of the tails: Yes, you really can backdoor federated learning. NeurIPS","author":"Wang Hongyi","year":"2020","unstructured":"Hongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma, Saurabh Agarwal, Jy-yong Sohn, Kangwook Lee, and Dimitris Papailiopoulos. 2020. Attack of the tails: Yes, you really can backdoor federated learning. NeurIPS (2020)."},{"key":"e_1_3_2_1_73_1","volume-title":"International Conference on Machine Learning. PMLR, 22769--22783","author":"Wang Wenxiao","year":"2022","unstructured":"Wenxiao Wang, Alexander J Levine, and Soheil Feizi. 2022. Improved certified defenses against data poisoning with (deterministic) finite aggregation. In International Conference on Machine Learning. PMLR, 22769--22783."},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.naacl-main.87"},{"key":"e_1_3_2_1_75_1","volume-title":"The 22nd International Conference on Artificial Intelligence and Statistics. PMLR, 1226--1235","author":"Wang Yu-Xiang","year":"2019","unstructured":"Yu-Xiang Wang, Borja Balle, and Shiva Prasad Kasiviswanathan. 2019. Subsampled r\u00e9nyi differential privacy and analytical moments accountant. In The 22nd International Conference on Artificial Intelligence and Statistics. PMLR, 1226--1235."},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179451"},{"key":"e_1_3_2_1_77_1","volume-title":"Mitigating Backdoor Attacks in Federated Learning. arXiv preprint arXiv:2011.01767","author":"Wu Chen","year":"2020","unstructured":"Chen Wu, Xian Yang, Sencun Zhu, and Prasenjit Mitra. 2020. Mitigating Backdoor Attacks in Federated Learning. arXiv preprint arXiv:2011.01767 (2020)."},{"key":"e_1_3_2_1_78_1","volume-title":"International Conference on Machine Learning. PMLR, 11372--11382","author":"Xie Chulin","year":"2021","unstructured":"Chulin Xie, Minghao Chen, Pin-Yu Chen, and Bo Li. 2021. Crfl: Certifiably robust federated learning against backdoor attacks. In International Conference on Machine Learning. PMLR, 11372--11382."},{"key":"e_1_3_2_1_79_1","volume-title":"International Conference on Learning Representations.","author":"Xie Chulin","year":"2020","unstructured":"Chulin Xie, Keli Huang, Pin-Yu Chen, and Bo Li. 2020. Dba: Distributed backdoor attacks against federated learning. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_80_1","doi-asserted-by":"publisher","DOI":"10.3390\/a15070233"},{"key":"e_1_3_2_1_81_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-23551-2_2"},{"key":"e_1_3_2_1_82_1","volume-title":"USENIX Security Symposium.","author":"Yang Yuchen","year":"2023","unstructured":"Yuchen Yang, Bo Hui, Haolin Yuan, Neil Gong, and Yinzhi Cao. 2023. PRIVATEFL: Accurate, Differentially Private Federated Learning via Personalized Data Transformation. In USENIX Security Symposium."},{"key":"e_1_3_2_1_83_1","volume-title":"International Conference on Machine Learning. PMLR, 5650--5659","author":"Yin Dong","year":"2018","unstructured":"Dong Yin, Yudong Chen, Ramchandran Kannan, and Peter Bartlett. 2018. Byzantine-robust distributed learning: Towards optimal statistical rates. In International Conference on Machine Learning. PMLR, 5650--5659."},{"key":"e_1_3_2_1_84_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00019"},{"key":"e_1_3_2_1_85_1","volume-title":"Garnett (Eds.)","volume":"32","author":"Zhu Ligeng","year":"2019","unstructured":"Ligeng Zhu, Zhijian Liu, and Song Han. 2019. Deep Leakage from Gradients. In NeurIPS, H. Wallach, H. Larochelle, A. Beygelzimer, F. dtextquotesingle Alch\u00e9-Buc, E. Fox, and R. Garnett (Eds.), Vol. 32. Curran Associates, Inc."},{"key":"e_1_3_2_1_86_1","unstructured":"Yuqing Zhu Xiang Yu Yi-Hsuan Tsai Francesco Pittaluga Masoud Faraki Manmohan Chandraker and Yu-Xiang Wang. 2021. Voting-based Approaches For Differentially Private Federated Learning. (2021)."}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623193","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3623193","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3623193","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:43:00Z","timestamp":1755740580000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623193"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":86,"alternative-id":["10.1145\/3576915.3623193","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3623193","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}