{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,26]],"date-time":"2026-02-26T15:23:07Z","timestamp":1772119387058,"version":"3.50.1"},"publisher-location":"New York, NY, USA","reference-count":21,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,5,8]],"date-time":"2025-05-08T00:00:00Z","timestamp":1746662400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,5,8]]},"DOI":"10.1145\/3701716.3715494","type":"proceedings-article","created":{"date-parts":[[2025,5,23]],"date-time":"2025-05-23T16:12:56Z","timestamp":1748016776000},"page":"1365-1369","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Poisoning Attacks and Defenses to Federated Unlearning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-4088-3495","authenticated-orcid":false,"given":"Wenbin","family":"Wang","sequence":"first","affiliation":[{"name":"ShanghaiTech University, Shanghai, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-0190-1827","authenticated-orcid":false,"given":"Qiwen","family":"Ma","sequence":"additional","affiliation":[{"name":"Xidian University, Xi'an, China"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-5382-9493","authenticated-orcid":false,"given":"Zifan","family":"Zhang","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7505-9718","authenticated-orcid":false,"given":"Yuchen","family":"Liu","sequence":"additional","affiliation":[{"name":"North Carolina State University, Raleigh, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0146-5101","authenticated-orcid":false,"given":"Zhuqing","family":"Liu","sequence":"additional","affiliation":[{"name":"University of North Texas, Denton, USA"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1365-3911","authenticated-orcid":false,"given":"Minghong","family":"Fang","sequence":"additional","affiliation":[{"name":"University of Louisville, Louisville, USA"}]}],"member":"320","published-online":{"date-parts":[[2025,5,23]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Eugene Bagdasaryan Andreas Veit Yiqing Hua Deborah Estrin and Vitaly Shmatikov. 2020. How to backdoor federated learning. In AISTATS."},{"key":"e_1_3_2_1_2_1","unstructured":"Gilad Baruch Moran Baruch and Yoav Goldberg. 2019. A little is enough: Circumventing defenses for distributed learning. In NeurIPS."},{"key":"e_1_3_2_1_3_1","volume-title":"Rachid Guerraoui, and Julien Stainer.","author":"Blanchard Peva","year":"2017","unstructured":"Peva Blanchard, El Mahdi El Mhamdi, Rachid Guerraoui, and Julien Stainer. 2017. Machine learning with adversaries: Byzantine tolerant gradient descent. In NeurIPS."},{"key":"e_1_3_2_1_4_1","volume-title":"Fltrust: Byzantine-robust federated learning via trust bootstrapping. In NDSS.","author":"Cao Xiaoyu","year":"2021","unstructured":"Xiaoyu Cao, Minghong Fang, Jia Liu, and Neil Zhenqiang Gong. 2021. Fltrust: Byzantine-robust federated learning via trust bootstrapping. In NDSS."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179336"},{"key":"e_1_3_2_1_6_1","volume-title":"USENIX Security Symposium.","author":"Fang Minghong","year":"2020","unstructured":"Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Gong. 2020. Local model poisoning attacks to Byzantine-robust federated learning. In USENIX Security Symposium."},{"key":"e_1_3_2_1_7_1","volume-title":"Neil Zhenqiang Gong, and Elizabeth S Bentley","author":"Fang Minghong","year":"2022","unstructured":"Minghong Fang, Jia Liu, Neil Zhenqiang Gong, and Elizabeth S Bentley. 2022. Aflguard: Byzantine-robust asynchronous federated learning. In ACSAC."},{"key":"e_1_3_2_1_8_1","volume-title":"Sundararaja Sitharama Iyengar, and Haibo Yang","author":"Fang Minghong","year":"2025","unstructured":"Minghong Fang, Seyedsina Nabavirazavi, Zhuqing Liu, Wei Sun, Sundararaja Sitharama Iyengar, and Haibo Yang. 2025. Do We Really Need to Design New Byzantine-robust Aggregation Rules?. In NDSS."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"crossref","unstructured":"Minghong Fang Zifan Zhang Prashant Khanduri Jia Liu Songtao Lu Yuchen Liu Neil Gong et al. 2024. Byzantine-robust decentralized federated learning. In CCS.","DOI":"10.1145\/3658644.3670307"},{"key":"e_1_3_2_1_10_1","unstructured":"Rachid Guerraoui S\u00e9bastien Rouault et al. 2018. The hidden vulnerability of distributed learning in byzantium. In ICML."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","unstructured":"Ziyao Liu Yu Jiang Jiyuan Shen Minyi Peng Kwok-Yan Lam Xingliang Yuan and Xiaoning Liu. 2024. A survey on federated unlearning: Challenges methods and future directions. In ACM Computing Surveys.","DOI":"10.1145\/3679014"},{"key":"e_1_3_2_1_12_1","unstructured":"H. Brendan McMahan Eider Moore Daniel Ramage Seth Hampson and Blaise Ag\u00fcera y Arcas. 2017. Communication-Efficient Learning of Deep Networks from Decentralized Data. In AISTATS."},{"key":"e_1_3_2_1_13_1","volume-title":"USENIX Security Symposium.","author":"Nguyen Thien Duc","year":"2022","unstructured":"Thien Duc Nguyen, Phillip Rieger, Roberta De Viti, Huili Chen, Bj\u00f6rn B Brandenburg, Hossein Yalame, Helen M\u00f6llering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, et al. 2022. FLAME: Taming backdoors in federated learning. In USENIX Security Symposium."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"crossref","unstructured":"Virat Shejwalkar and Amir Houmansadr. 2021. Manipulating the byzantine: Optimizing model poisoning attacks and defenses for federated learning. In NDSS.","DOI":"10.14722\/ndss.2021.24498"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"crossref","unstructured":"Xinyi Sheng Wei Bao and Liming Ge. 2024. Robust Federated Unlearning. In CIKM.","DOI":"10.1145\/3627673.3679817"},{"key":"e_1_3_2_1_16_1","unstructured":"Youming Tao Cheng-Long Wang Miao Pan et al. 2024. Communication efficient and provable federated unlearning. In VLDB."},{"key":"e_1_3_2_1_17_1","volume-title":"Poisoning Attacks and Defenses to Federated Unlearning. arXiv preprint arXiv:2501.17396","author":"Wang Wenbin","year":"2025","unstructured":"Wenbin Wang, Qiwen Ma, Zifan Zhang, Yuchen Liu, Zhuqing Liu, and Minghong Fang. 2025. Poisoning Attacks and Defenses to Federated Unlearning. arXiv preprint arXiv:2501.17396 (2025)."},{"key":"e_1_3_2_1_18_1","unstructured":"Yueqi Xie Minghong Fang and Neil Zhenqiang Gong. 2024. FedREDefense: Defending against Model Poisoning Attacks for Federated Learning using Model Update Reconstruction Error. In ICML."},{"key":"e_1_3_2_1_19_1","unstructured":"Dong Yin Yudong Chen Ramchandran Kannan and Peter Bartlett. 2018. Byzantine-robust distributed learning: Towards optimal statistical rates. In ICML."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3589334.3645492"},{"key":"e_1_3_2_1_21_1","volume-title":"Poisoning Attacks on Federated Learning-based Wireless Traffic Prediction. In IFIP\/IEEE Networking Conference.","author":"Zhang Zifan","year":"2024","unstructured":"Zifan Zhang, Minghong Fang, Jiayuan Huang, and Yuchen Liu. 2024. Poisoning Attacks on Federated Learning-based Wireless Traffic Prediction. In IFIP\/IEEE Networking Conference."}],"event":{"name":"WWW '25: The ACM Web Conference 2025","location":"Sydney NSW Australia","acronym":"WWW '25","sponsor":["SIGWEB ACM Special Interest Group on Hypertext, Hypermedia, and Web"]},"container-title":["Companion Proceedings of the ACM on Web Conference 2025"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3701716.3715494","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3701716.3715494","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,8]],"date-time":"2025-10-08T03:02:11Z","timestamp":1759892531000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3701716.3715494"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,5,8]]},"references-count":21,"alternative-id":["10.1145\/3701716.3715494","10.1145\/3701716"],"URL":"https:\/\/doi.org\/10.1145\/3701716.3715494","relation":{},"subject":[],"published":{"date-parts":[[2025,5,8]]},"assertion":[{"value":"2025-05-23","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}