{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:45:26Z","timestamp":1784303126394,"version":"3.55.0"},"reference-count":99,"publisher":"Association for Computing Machinery (ACM)","issue":"1","license":[{"start":{"date-parts":[[2024,12,11]],"date-time":"2024-12-11T00:00:00Z","timestamp":1733875200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by-sa\/4.0\/"}],"funder":[{"name":"Department of Defense Multidisciplinary Research Program of the University Research Initiative","award":["W911NF-21-1-0322"],"award-info":[{"award-number":["W911NF-21-1-0322"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Trans. Priv. Secur."],"published-print":{"date-parts":[[2025,2,28]]},"abstract":"<jats:p>Most machine learning applications rely on centralized learning processes, opening up the risk of exposure of their training datasets. While federated learning (FL) mitigates to some extent these privacy risks, it relies on a trusted aggregation server for training a shared global model. Recently, new distributed learning architectures based on Peer-to-Peer Federated Learning (P2PFL) offer advantages in terms of both privacy and reliability. Still, their resilience to poisoning attacks during training has not been investigated. In this article, we propose new backdoor attacks for P2PFL that leverage structural graph properties to select the malicious nodes, and achieve high attack success, while remaining stealthy. We evaluate our attacks under various realistic conditions, including multiple graph topologies, limited adversarial visibility of the network, and clients with non-IID data. Finally, we show the limitations of existing defenses adapted from FL and design a new defense that successfully mitigates the backdoor attacks, without an impact on model accuracy.<\/jats:p>","DOI":"10.1145\/3691633","type":"journal-article","created":{"date-parts":[[2024,10,22]],"date-time":"2024-10-22T10:04:28Z","timestamp":1729591468000},"page":"1-28","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":5,"title":["Backdoor Attacks in Peer-to-Peer Federated Learning"],"prefix":"10.1145","volume":"28","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-8760-878X","authenticated-orcid":false,"given":"Georgios","family":"Syros","sequence":"first","affiliation":[{"name":"Northeastern University - Boston Campus, Boston, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2947-6323","authenticated-orcid":false,"given":"Gokberk","family":"Yar","sequence":"additional","affiliation":[{"name":"Northeastern University - Boston Campus, Boston, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-3411-8912","authenticated-orcid":false,"given":"Simona","family":"Boboila","sequence":"additional","affiliation":[{"name":"Northeastern University - Boston Campus, Boston, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9649-6789","authenticated-orcid":false,"given":"Cristina","family":"Nita-Rotaru","sequence":"additional","affiliation":[{"name":"Northeastern University - Boston Campus, Boston, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4979-5292","authenticated-orcid":false,"given":"Alina","family":"Oprea","sequence":"additional","affiliation":[{"name":"Northeastern University - Boston Campus, Boston, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,12,11]]},"reference":[{"key":"e_1_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978318"},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1103\/RevModPhys.74.47"},{"key":"e_1_3_2_4_2","volume-title":"AISTATS","author":"Bagdasaryan Eugene","year":"2020","unstructured":"Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. In AISTATS. PMLR."},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1007\/s10462-018-9654-y"},{"key":"e_1_3_2_6_2","first-page":"473","volume-title":"AISTATS","author":"Bellet Aur\u00e9lien","year":"2018","unstructured":"Aur\u00e9lien Bellet, Rachid Guerraoui, Mahsa Taziki, and Marc Tommasi. 2018. Personalized and private peer-to-peer machine learning. In AISTATS. 473\u2013481."},{"key":"e_1_3_2_7_2","first-page":"634","volume-title":"ICML","author":"Bhagoji Arjun Nitin","year":"2019","unstructured":"Arjun Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin B. Calo. 2019. Analyzing federated learning through an adversarial lens. In ICML. 634\u2013643. Retrieved from http:\/\/proceedings.mlr.press\/v97\/bhagoji19a.html"},{"key":"e_1_3_2_8_2","unstructured":"Battista Biggio Blaine Nelson and Pavel Laskov. 2013. Poisoning Attacks against Support Vector Machines. arXiv:1206.6389 [cs.LG] https:\/\/arxiv.org\/abs\/1206.6389"},{"key":"e_1_3_2_9_2","unstructured":"Peva Blanchard El Mahdi El Mhamdi Rachid Guerraoui and Julien Stainer. 2017. Machine learning with adversaries: Byzantine tolerant gradient descent. In Advances in Neural Information Processing Systems I. Guyon U. Von Luxburg S. Bengio H. Wallach R. Fergus S. Vishwanathan and R. Garnett (Eds.). Vol. 30. Curran Associates Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2017\/file\/f4b9ec30ad9f68f89b29639786cb62ef-Paper.pdf"},{"key":"e_1_3_2_10_2","first-page":"1175","volume-title":"CCS","author":"Bonawitz Keith","year":"2017","unstructured":"Keith Bonawitz, Vladimir Ivanov, Ben Kreuter, Antonio Marcedone, H. Brendan McMahan, Sarvar Patel, Daniel Ramage, Aaron Segal, and Karn Seth. 2017. Practical secure aggregation for privacy-preserving machine learning. In CCS. 1175\u20131191."},{"issue":"1","key":"e_1_3_2_11_2","first-page":"35","article-title":"Structural holes: Unpacking Burt\u2019s redundancy measures","volume":"20","author":"Borgatti Stephen P.","year":"1997","unstructured":"Stephen P. Borgatti. 1997. Structural holes: Unpacking Burt\u2019s redundancy measures. Connections 20, 1 (1997), 35\u201338.","journal-title":"Connections"},{"key":"e_1_3_2_12_2","first-page":"659","volume-title":"Social Stratification","author":"Burt Ronald S.","year":"2018","unstructured":"Ronald S. Burt. 2018. Structural holes. In Social Stratification. Routledge, 659\u2013663."},{"key":"e_1_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/844128.844156"},{"key":"e_1_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML54575.2023.00021"},{"key":"e_1_3_2_16_2","unstructured":"Xinyun Chen Chang Liu Bo Li Kimberly Lu and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv:1712.05526 [cs.CR] https:\/\/arxiv.org\/abs\/1712.05526"},{"key":"e_1_3_2_17_2","volume-title":"ESORICS","author":"Chernikova Alesia","year":"2022","unstructured":"Alesia Chernikova, Nicol\u00f2 Gozzi, Simona Boboila, Priyanka Angadi, John Loughner, Matthew Wilden, Nicola Perra, Tina Eliassi-Rad, and Alina Oprea. 2022. Cyber network resilience against self-propagating malware attacks. In ESORICS. Springer."},{"key":"e_1_3_2_18_2","doi-asserted-by":"crossref","unstructured":"Gregory Cohen Saeed Afshar Jonathan Tapson and Andr\u00e9 van Schaik. 2017. EMNIST: An extension of MNIST to handwritten letters. arXiv:1702.05373 [cs.CV] https:\/\/arxiv.org\/abs\/1702.05373","DOI":"10.1109\/IJCNN.2017.7966217"},{"key":"e_1_3_2_19_2","unstructured":"Jeff Daily Abhinav Vishnu Charles Siegel Thomas Warfel and Vinay Amatya. 2018. GossipGraD: Scalable Deep Learning using Gossip Communication based Asynchronous Gradient Descent. arXiv:1803.05880 [cs.DC] https:\/\/arxiv.org\/abs\/1803.05880"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","unstructured":"Li Deng. 2012. The MNIST database of handwritten digit images for machine learning research [Best of the Web]. IEEE Signal Processing Magazine 29 6 (2012) 141\u2013142. 10.1109\/MSP.2012.2211477","DOI":"10.1109\/MSP.2012.2211477"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/1326320.1326324"},{"key":"e_1_3_2_22_2","first-page":"70","volume-title":"IEEE Sarnoff Symposium","author":"Dong Ziqian","year":"2015","unstructured":"Ziqian Dong, Zheng Wang, Wen Xie, Obinna Emelumadu, Chuanbi Lin, and Roberto Rojas-Cessa. 2015. An experimental study of small world network model for wireless networks. In IEEE Sarnoff Symposium. 70\u201375."},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-45748-8_24"},{"issue":"1","key":"e_1_3_2_24_2","first-page":"17","article-title":"On the evolution of random graphs","volume":"5","author":"Erdos Paul","year":"1960","unstructured":"Paul Erdos, Alfr\u00e9d R\u00e9nyi, et\u00a0al. 1960. On the evolution of random graphs. Publ. Math. Inst. Hung. Acad. Sci 5, 1 (1960), 17\u201360.","journal-title":"Publ. Math. Inst. Hung. Acad. Sci"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","unstructured":"Stefanie Warnat-Herresthal et al.2021. Swarm learning for decentralized and confidential clinical machine learning.Nature 594 7862 (June 2021) 265\u2013270. 10.1038\/s41586-021-03583-3","DOI":"10.1038\/s41586-021-03583-3"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","unstructured":"Cheng Fang Zhixiong Yang and Waheed U Bajwa. 2022. BRIDGE: Byzantine-resilient decentralized gradient descent. IEEE Transactions on Signal and Information Processing over Networks 8 (2022) 610\u2013626. 10.1109\/TSIPN.2022.3188456","DOI":"10.1109\/TSIPN.2022.3188456"},{"key":"e_1_3_2_27_2","volume-title":"USENIX Security","author":"Fang Minghong","year":"2020","unstructured":"Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Gong. 2020. Local model poisoning attacks to Byzantine-Robust federated learning. In USENIX Security."},{"key":"e_1_3_2_28_2","first-page":"301","volume-title":"23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID\u201920)","author":"Fung Clement","year":"2020","unstructured":"Clement Fung, Chris J. M. Yoon, and Ivan Beschastnikh. 2020. The limitations of federated learning in sybil settings. In 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID\u201920). USENIX Association, San Sebastian, 301\u2013316. Retrieved fromhttps:\/\/www.usenix.org\/conference\/raid2020\/presentation\/fung"},{"key":"e_1_3_2_29_2","volume-title":"Advances in Neural Information Processing Systems","author":"Geiping Jonas","year":"2020","unstructured":"Jonas Geiping, Hartmut Bauermeister, Hannah Dr\u00f6ge, and Michael Moeller. 2020. Inverting gradients\u2014how easy is it to break privacy in federated learning?. In Advances in Neural Information Processing Systems."},{"key":"e_1_3_2_30_2","doi-asserted-by":"crossref","unstructured":"Filip Granqvist Matt Seigel Rogier van Dalen Aine Cahill Stephen Shum and Matthias Paulik. 2020. Improving on-device speaker verification using federated learning with privacy. arXiv:2008.02651 [eess.AS] https:\/\/arxiv.org\/abs\/2008.02651","DOI":"10.21437\/Interspeech.2020-2944"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1002\/rob.21918"},{"key":"e_1_3_2_32_2","unstructured":"Tianyu Gu Brendan Dolan-Gavitt and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv:1708.06733 [cs.CR] https:\/\/arxiv.org\/abs\/1708.06733"},{"key":"e_1_3_2_33_2","doi-asserted-by":"publisher","unstructured":"Tianyu Gu Kang Liu Brendan Dolan-Gavitt and Siddharth Garg. 2019. Badnets: Evaluating backdooring attacks on deep neural networks. IEEE Access 7 (2019) 47230\u201347244. 10.1109\/ACCESS.2019.2909068","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_2_34_2","unstructured":"El Mahdi El Mhamdi Rachid Guerraoui and S\u00e9bastien Rouault. 2018. The hidden vulnerability of distributed learning in byzantium. arXiv:1802.07927 [stat.ML] https:\/\/arxiv.org\/abs\/1802.07927"},{"key":"e_1_3_2_35_2","unstructured":"Nirupam Gupta and Nitin H Vaidya. 2021. Byzantine fault-tolerance in peer-to-peer distributed gradient-descent. arXiv:2101.12316 [cs.DC] https:\/\/arxiv.org\/abs\/2101.12316"},{"key":"e_1_3_2_36_2","doi-asserted-by":"crossref","DOI":"10.69554\/TCFN5165","article-title":"Understanding the scope and impact of the California Consumer Privacy Act of 2018","author":"Harding Elizabeth Liz","year":"2019","unstructured":"Elizabeth Liz Harding, Jarno J. Vanto, Reece Clark, L. Hannah Ji, and Sara C. Ainsworth. 2019. Understanding the scope and impact of the California Consumer Privacy Act of 2018. Journal of Data Protection & Privacy (2019).","journal-title":"Journal of Data Protection & Privacy"},{"key":"e_1_3_2_37_2","unstructured":"Lie He Sai Praneeth Karimireddy and Martin Jaggi. 2023. Byzantine-robust Decentralized Learning via ClippedGossip. arXiv:2202.01545 [cs.LG] https:\/\/arxiv.org\/abs\/2202.01545"},{"key":"e_1_3_2_38_2","doi-asserted-by":"publisher","unstructured":"Kevin Hoffman David Zage and Cristina Nita-Rotaru. 2007. A survey of attacks on reputation systems. ACM Comput. Surv. 42 1 Article 1 (Dec. 2009) 31 pages. 10.1145\/1592451.1592452","DOI":"10.1145\/1592451.1592452"},{"key":"e_1_3_2_39_2","unstructured":"Chenghao Hu Jingyan Jiang and Zhi Wang. 2019. Decentralized Federated Learning: A Segmented Gossip Approach. (2019). arXiv:1908.07782. Retrieved from https:\/\/arxiv.org\/abs\/1908.07782"},{"key":"e_1_3_2_40_2","unstructured":"Matthew Jagielski and Alina Oprea. 2021. Does differential privacy defeat data poisoning? In ICLR Workshop on Distributed and Private Machine Learning. https:\/\/dp-ml.github.io\/2021-workshop-ICLR\/files\/23.pdf"},{"key":"e_1_3_2_41_2","first-page":"19","volume-title":"S&P","author":"Jagielski Matthew","year":"2018","unstructured":"Matthew Jagielski, Alina Oprea, Battista Biggio, Chang Liu, Cristina Nita-Rotaru, and Bo Li. 2018. Manipulating machine learning: Poisoning attacks and countermeasures for regression learning. In S&P. IEEE, 19\u201335."},{"issue":"6","key":"e_1_3_2_42_2","doi-asserted-by":"crossref","first-page":"10384","DOI":"10.1109\/JIOT.2019.2938800","article-title":"A new small-world IoT routing mechanism based on Cayley graphs","volume":"6","author":"Jiang Yuna","year":"2019","unstructured":"Yuna Jiang, Xiaohu Ge, Yi Zhong, Guoqiang Mao, and Yonghui Li. 2019. A new small-world IoT routing mechanism based on Cayley graphs. IEEE Internet of Things Journal 6, 6 (2019), 10384\u201310395.","journal-title":"IEEE Internet of Things Journal"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","unstructured":"Peter Kairouz H. Brendan McMahan Brendan Avent Aur\u00e9lien Bellet Mehdi Bennis Arjun Nitin Bhagoji Kallista Bonawitz Zachary Charles Graham Cormode Rachel Cummings Rafael G. L. D\u2019Oliveira Hubert Eichner Salim El Rouayheb David Evans Josh Gardner Zachary Garrett Adri\u00e0 Gasc\u00f3n Badih Ghazi Phillip B. Gibbons Marco Gruteser Zaid Harchaoui Chaoyang He Lie He Zhouyuan Huo Ben Hutchinson Justin Hsu Martin Jaggi Tara Javidi Gauri Joshi Mikhail Khodak Jakub Konecn\u00fd Aleksandra Korolova Farinaz Koushanfar Sanmi Koyejo Tancr\u00e8de Lepoint Yang Liu Prateek Mittal Mehryar Mohri Richard Nock Ayfer \u00d6zg\u00fcr Rasmus Pagh Hang Qi Daniel Ramage Ramesh Raskar Mariana Raykova Dawn Song Weikang Song Sebastian U. Stich Ziteng Sun Ananda Theertha Suresh Florian Tram\u00e8r Praneeth Vepakomma Jianyu Wang Li Xiong Zheng Xu Qiang Yang Felix X. Yu Han Yu and Sen Zhao. 2021. Advances and open problems in federated learning. Foundations and TrendsR in Machine Learning 14 1\u20132 (2021) 1\u2013210. 10.1561\/2200000083","DOI":"10.1561\/2200000083"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","unstructured":"Latif U. Khan Shashi Raj Pandey Nguyen H. Tran Walid Saad Zhu Han Minh N. H. Nguyen and Choong Seon Hong. 2020. Federated learning for edge networks: Resource optimization and incentive mechanism. IEEE Communications Magazine 58 10 (2020) 88\u201393. 10.1109\/MCOM.001.1900649","DOI":"10.1109\/MCOM.001.1900649"},{"key":"e_1_3_2_45_2","doi-asserted-by":"publisher","DOI":"10.1109\/TITS.2021.3054625"},{"key":"e_1_3_2_46_2","doi-asserted-by":"publisher","DOI":"10.1145\/1386790.1386835"},{"key":"e_1_3_2_47_2","first-page":"1885","volume-title":"ICML","author":"Koh Pang Wei","year":"2017","unstructured":"Pang Wei Koh and Percy Liang. 2017. Understanding black-box predictions via influence functions. In ICML. PMLR, 1885\u20131894."},{"key":"e_1_3_2_48_2","unstructured":"Anastasia Koloskova Tao Lin Sebastian U. Stich and Martin Jaggi. 2020. Decentralized Deep Learning with Arbitrary Communication Compression. arXiv:1907.09356 [cs.LG] https:\/\/arxiv.org\/abs\/1907.09356"},{"key":"e_1_3_2_49_2","volume-title":"NIPS Workshop on Private Multi-Party ML","author":"Kone\u010dn\u00fd Jakub","year":"2016","unstructured":"Jakub Kone\u010dn\u00fd, H. Brendan McMahan, Felix X. Yu, Peter Richtarik, Ananda Theertha Suresh, and Dave Bacon. 2016. Federated learning: Strategies for improving communication efficiency. In NIPS Workshop on Private Multi-Party ML."},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623212"},{"key":"e_1_3_2_51_2","volume-title":"IEEE Symposium on Security and Privacy","author":"Kumar Ankit","year":"2024","unstructured":"Ankit Kumar, Max von Hippel, Pete Manolios, and Cristina Nita-Rotaru. 2024. In IEEE Symposium on Security and Privacy."},{"key":"e_1_3_2_52_2","volume-title":"ACC","author":"Kuwaranancharoen Kananart","year":"2020","unstructured":"Kananart Kuwaranancharoen, Lei Xin, and Shreyas Sundaram. 2020. Byzantine-resilient distributed optimization of multi-dimensional functions. In ACC."},{"key":"e_1_3_2_53_2","unstructured":"Anusha Lalitha Osman Cihan Kilinc Tara Javidi and Farinaz Koushanfar. 2019. Peer-to-peer federated learning on graphs. arXiv:1901.11173 [cs.LG] https:\/\/arxiv.org\/abs\/1901.11173"},{"key":"e_1_3_2_54_2","first-page":"965","volume-title":"ICDE","author":"Li Qinbin","year":"2022","unstructured":"Qinbin Li, Yiqun Diao, Quan Chen, and Bingsheng He. 2022. Federated learning on non-iid data silos: An experimental study. In ICDE. IEEE, 965\u2013978."},{"key":"e_1_3_2_55_2","volume-title":"Advances in Neural Information Processing Systems","author":"Lian Xiangru","year":"2017","unstructured":"Xiangru Lian, Ce Zhang, Huan Zhang, Cho-Jui Hsieh, Wei Zhang, and Ji Liu. 2017. Can decentralized algorithms outperform centralized algorithms? A case study for decentralized parallel stochastic gradient descent. In Advances in Neural Information Processing Systems. I. Guyon, U. Von Luxburg, S. Bengio, H. Wallach, R. Fergus, S. Vishwanathan, and R. Garnett (Eds.), Vol. 30. Curran Associates, Inc. Retrieved from https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2017\/file\/f75526659f31040afeb61cb7133e4e6d-Paper.pdf"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","unstructured":"Wei Yang Bryan Lim Nguyen Cong Luong Dinh Thai Hoang Yutao Jiao Ying-Chang Liang Qiang Yang Dusit Niyato and Chunyan Miao. 2020. Federated learning in mobile edge networks: A comprehensive survey. IEEE Communications Surveys & Tutorials 22 3 (2020) 2031\u20132063. 10.1109\/COMST.2020.2986024","DOI":"10.1109\/COMST.2020.2986024"},{"key":"e_1_3_2_57_2","volume-title":"INFOCOM","author":"Liu Changlei","year":"2012","unstructured":"Changlei Liu and Guohong Cao. 2012. Distributed critical location coverage in wireless sensor networks with lifetime constraint. In INFOCOM. IEEE."},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1504\/IJBET.2017.087722"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","unstructured":"Fl\u00e1vio VC Martins Eduardo G Carrano Elizabeth F Wanner Ricardo HC Takahashi and Geraldo R Mateus. 2010. A hybrid multiobjective evolutionary approach for improving the performance of wireless sensor networks. IEEE Sensors Journal 11 3 (2011) 545\u2013554. 10.1109\/JSEN.2010.2048897","DOI":"10.1109\/JSEN.2010.2048897"},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","unstructured":"Ian McGraw Rohit Prabhavalkar Raziel Alvarez Montse Gonzalez Arenas Kanishka Rao David Rybach Ouais Alsharif Hasim Sak Alexander Gruenstein Francoise Beaufays and Carolina Parada. 2016. Personalized speech recognition on mobile devices. In 2016 IEEE International Conference on Acoustics Speech and Signal Processing (ICASSP). 5955\u20135959. 10.1109\/ICASSP.2016.7472820","DOI":"10.1109\/ICASSP.2016.7472820"},{"key":"e_1_3_2_61_2","volume-title":"Artificial Intelligence and Statistics","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Artificial Intelligence and Statistics. PMLR."},{"key":"e_1_3_2_62_2","volume-title":"ICLR","author":"McMahan H. Brendan","year":"2018","unstructured":"H. Brendan McMahan, Daniel Ramage, Kunal Talwar, and Li Zhang. 2018. Learning differentially private recurrent language models. In ICLR."},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.5555\/2886521.2886721"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1038\/s42256-021-00373-4"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.1137\/S003614450342480"},{"key":"e_1_3_2_66_2","volume-title":"USENIX Security Symposium","author":"Nguyen Thien Duc","year":"2022","unstructured":"Thien Duc Nguyen, Phillip Rieger, Huili Chen, Hossein Yalame, Helen M\u00f6llering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, Azalia Mirhoseini, Shaza Zeitouni, Farinaz Koushanfar, Ahmad Sadeghi, and Thomas Schneider. 2022. FLAME: Taming backdoors in federated learning. In USENIX Security Symposium. Retrieved from https:\/\/api.semanticscholar.org\/CorpusID:263886687"},{"key":"e_1_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2016.99"},{"key":"e_1_3_2_68_2","volume-title":"The PageRank Citation Ranking: Bringing Order to the Web.","author":"Page Lawrence","year":"1999","unstructured":"Lawrence Page, Sergey Brin, Rajeev Motwani, and Terry Winograd. 1999. The PageRank Citation Ranking: Bringing Order to the Web.Technical Report. Stanford InfoLab."},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","unstructured":"Jie Peng Weiyu Li and Qing Ling. 2021. Byzantine-robust decentralized stochastic optimization over static and time-varying networks. Signal Processing 183 (2021) 108020. 10.1016\/j.sigpro.2021.108020","DOI":"10.1016\/j.sigpro.2021.108020"},{"key":"e_1_3_2_70_2","first-page":"3735","volume-title":"31st USENIX Security Symposium (USENIX Security\u201922)","author":"Pr\u00fcnster Bernd","year":"2022","unstructured":"Bernd Pr\u00fcnster, Alexander Marsalek, and Thomas Zefferer. 2022. Total eclipse of the heart \u2013 disrupting the InterPlanetary file system. In 31st USENIX Security Symposium (USENIX Security\u201922). USENIX Association, Boston, MA, 3735\u20133752. Retrieved fromhttps:\/\/www.usenix.org\/conference\/usenixsecurity22\/presentation\/prunster"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2020.2975212"},{"key":"e_1_3_2_72_2","volume-title":"29th Annual Network and Distributed System Security Symposium, NDSS 2022, San Diego, California, USA, April 24\u201328, 2022","author":"Rieger Phillip","year":"2022","unstructured":"Phillip Rieger, Thien Duc Nguyen, Markus Miettinen, and Ahmad-Reza Sadeghi. 2022. DeepSight: Mitigating backdoor attacks in federated learning through deep model inspection. In 29th Annual Network and Distributed System Security Symposium, NDSS 2022, San Diego, California, USA, April 24\u201328, 2022. The Internet Society. Retrieved from https:\/\/www.ndss-symposium.org\/ndss-paper\/auto-draft-205\/"},{"key":"e_1_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1103\/PhysRevE.75.027105"},{"key":"e_1_3_2_74_2","volume-title":"CNS","author":"Severi Giorgio","year":"2022","unstructured":"Giorgio Severi, Matthew Jagielski, G\u00f6kberk Yar, Yuxuan Wang, Alina Oprea, and Cristina Nita-Rotaru. 2022. Network-level adversaries in federated learning. In CNS. IEEE."},{"key":"e_1_3_2_75_2","unstructured":"Ali Shafahi W. Ronny Huang Mahyar Najibi Octavian Suciu Christoph Studer Tudor Dumitras and Tom Goldstein. 2018. Poison frogs! Targeted clean-label poisoning attacks on neural networks. In Advances in Neural Information Processing Systems S. Bengio H. Wallach H. Larochelle K. Grauman N. Cesa-Bianchi and R. Garnett (Eds.). Vol. 31. Curran Associates Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2018\/file\/22722a343513ed45f14905eb07621686-Paper.pdf"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"e_1_3_2_78_2","first-page":"1299","volume-title":"USENIX Security","author":"Suciu Octavian","year":"2018","unstructured":"Octavian Suciu, Radu Marginean, Yigitcan Kaya, Hal Daume III, and Tudor Dumitras. 2018. When does machine learning FAIL? Generalized transferability for evasion and poisoning attacks. In USENIX Security. 1299\u20131316."},{"key":"e_1_3_2_79_2","unstructured":"Ziteng Sun Peter Kairouz Ananda Theertha Suresh and H. Brendan McMahan. 2019. Can you really backdoor federated learning? arXiv:1911.07963 [cs.LG] https:\/\/arxiv.org\/abs\/1911.07963"},{"key":"e_1_3_2_80_2","first-page":"4848","volume-title":"ICML","author":"Tang Hanlin","year":"2018","unstructured":"Hanlin Tang, Xiangru Lian, Ming Yan, Ce Zhang, and Ji Liu. 2018. \\(D^2\\) : Decentralized training over decentralized data. In ICML. 4848\u20134856."},{"key":"e_1_3_2_81_2","unstructured":"Michael Teng and Frank Wood. 2018. Bayesian distributed stochastic gradient descent. In Advances in Neural Information Processing Systems S. Bengio H. Wallach H. Larochelle K. Grauman N. Cesa-Bianchi and R. Garnett (Eds.). Vol. 31. Curran Associates Inc. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2018\/file\/86b20716fbd5b253d27cec43127089bc-Paper.pdf"},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58951-6_24"},{"key":"e_1_3_2_83_2","first-page":"509","volume-title":"Artificial Intelligence and Statistics","author":"Vanhaesebrouck Paul","year":"2017","unstructured":"Paul Vanhaesebrouck, Aur\u00e9lien Bellet, and Marc Tommasi. 2017. Decentralized collaborative learning of personalized models over networks. In Artificial Intelligence and Statistics. PMLR, 509\u2013517."},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","unstructured":"Apostol Vassilev Alina Oprea Alie Fordyce and Hyrum Andersen. 2024. Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations. (2024-01-04 05:01:002024). DOI:DOI:10.6028\/NIST.AI.100-2e2023","DOI":"10.6028\/NIST.AI.100-2e2023"},{"issue":"3152676","key":"e_1_3_2_85_2","first-page":"10","article-title":"The EU general data protection regulation (GDPR)","volume":"10","author":"Voigt Paul","year":"2017","unstructured":"Paul Voigt and Axel Von dem Bussche. 2017. The EU general data protection regulation (GDPR). A Practical Guide, 1st Ed., Cham: Springer 10, 3152676 (2017), 10\u20135555.","journal-title":"A Practical Guide, 1st Ed., Cham: Springer"},{"key":"e_1_3_2_86_2","unstructured":"Dimitris Vyzovitis Yusef Napora Dirk McCormick David Dias and Yiannis Psaras. 2020. GossipSub: Attack-resilient message propagation in the filecoin and ETH2.0 networks. arXiv:2007.02754 [cs.NI] https:\/\/arxiv.org\/abs\/2007.02754"},{"key":"e_1_3_2_87_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2007.912394"},{"key":"e_1_3_2_88_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00031"},{"key":"e_1_3_2_89_2","unstructured":"Hongyi Wang Kartik Sreenivasan Shashank Rajput Harit Vishwakarma Saurabh Agarwal Jy-yong Sohn Kangwook Lee and Dimitris Papailiopoulos. 2020. Attack of the tails: Yes you really can backdoor federated learning. In Advances in Neural Information Processing Systems H. Larochelle M. Ranzato R. Hadsell M.F. Balcan and H. Lin (Eds.). Vol. 33. Curran Associates Inc. 16070\u201316084. https:\/\/proceedings.neurips.cc\/paper_files\/paper\/2020\/file\/b8ffa41d4e492f0fad2f13e29e1762eb-Paper.pdf"},{"key":"e_1_3_2_90_2","volume-title":"NIPS","author":"Wang Jianyu","year":"2020","unstructured":"Jianyu Wang, Qinghua Liu, Hao Liang, Gauri Joshi, and H. Vincent Poor. 2020. Tackling the objective inconsistency problem in heterogeneous federated optimization. In NIPS. ACM, Article 638, 13 pages."},{"key":"e_1_3_2_91_2","doi-asserted-by":"publisher","DOI":"10.1038\/30918"},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.1109\/CDC.2012.6425904"},{"key":"e_1_3_2_93_2","first-page":"23668","volume-title":"ICML","author":"Wen Yuxin","year":"2022","unstructured":"Yuxin Wen, Jonas Geiping, Liam Fowl, Micah Goldblum, and Tom Goldstein. 2022. Fishing for user data in large-batch federated learning via gradient magnification. In ICML, Vol. 162. 23668\u201323684."},{"key":"e_1_3_2_94_2","volume-title":"ICML","author":"Xiao Huang","year":"2015","unstructured":"Huang Xiao, Battista Biggio, Gavin Brown, Giorgio Fumera, Claudia Eckert, and Fabio Roli. 2015. Is feature selection secure against training data poisoning?. In ICML."},{"key":"e_1_3_2_95_2","unstructured":"Han Xiao Kashif Rasul and Roland Vollgraf. 2017. Fashion-MNIST: A Novel Image Dataset for Benchmarking Machine Learning Algorithms. arXiv:1708.07747 [cs.LG] https:\/\/arxiv.org\/abs\/1708.07747"},{"key":"e_1_3_2_96_2","unstructured":"Cong Xie Oluwasanmi Koyejo and Indranil Gupta. 2018. Phocas: Dimensional byzantine-resilient stochastic gradient descent. arXiv:1805.09682 [cs.DC] https:\/\/arxiv.org\/abs\/1805.09682"},{"key":"e_1_3_2_97_2","doi-asserted-by":"publisher","DOI":"10.1109\/TSIPN.2019.2928176"},{"key":"e_1_3_2_98_2","first-page":"5650","volume-title":"Proceedings of the 35th International Conference on Machine Learning (Proceedings of Machine Learning Research)","volume":"80","author":"Yin Dong","year":"2018","unstructured":"Dong Yin, Yudong Chen, Ramchandran Kannan, and Peter Bartlett. 2018. Byzantine-robust distributed learning: Towards optimal statistical rates. In Proceedings of the 35th International Conference on Machine Learning (Proceedings of Machine Learning Research), Jennifer Dy and Andreas Krause (Eds.), Vol. 80. PMLR, 5650\u20135659. Retrieved from https:\/\/proceedings.mlr.press\/v80\/yin18a.html"},{"key":"e_1_3_2_99_2","first-page":"7252","volume-title":"ICML","author":"Yurochkin Mikhail","year":"2019","unstructured":"Mikhail Yurochkin, Mayank Agarwal, Soumya Ghosh, Kristjan Greenewald, Nghia Hoang, and Yasaman Khazaeni. 2019. Bayesian nonparametric federated learning of neural networks. In ICML, Vol. 97. PMLR, 7252\u20137261."},{"key":"e_1_3_2_100_2","doi-asserted-by":"publisher","unstructured":"Shuai Zhang Lina Yao Aixin Sun and Yi Tay. 2019. Deep learning based recommender system: A survey and new perspectives. ACM Comput. Surv. 52 1 Article 5 (Feb. 2019) 38 pages. 10.1145\/3285029","DOI":"10.1145\/3285029"}],"container-title":["ACM Transactions on Privacy and Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3691633","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3691633","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:09:40Z","timestamp":1750295380000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3691633"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,11]]},"references-count":99,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,2,28]]}},"alternative-id":["10.1145\/3691633"],"URL":"https:\/\/doi.org\/10.1145\/3691633","relation":{},"ISSN":["2471-2566","2471-2574"],"issn-type":[{"value":"2471-2566","type":"print"},{"value":"2471-2574","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,11]]},"assertion":[{"value":"2024-02-15","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-07-30","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-12-11","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}