{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,20]],"date-time":"2026-07-20T10:05:31Z","timestamp":1784541931403,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":79,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,8,25]]},"DOI":"10.1145\/3708821.3736194","type":"proceedings-article","created":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T06:30:56Z","timestamp":1755066656000},"page":"456-472","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["Toward Malicious Clients Detection in Federated Learning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3525-7442","authenticated-orcid":false,"given":"Zhihao","family":"Dou","sequence":"first","affiliation":[{"name":"Duke University, Durham, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-7824-3394","authenticated-orcid":false,"given":"Jiaqi","family":"Wang","sequence":"additional","affiliation":[{"name":"Hainan Normal University, Haikou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1349-6135","authenticated-orcid":false,"given":"Wei","family":"Sun","sequence":"additional","affiliation":[{"name":"Wichita State University, Wichita, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0146-5101","authenticated-orcid":false,"given":"Zhuqing","family":"Liu","sequence":"additional","affiliation":[{"name":"University of North Texas, Denton, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1365-3911","authenticated-orcid":false,"given":"Minghong","family":"Fang","sequence":"additional","affiliation":[{"name":"University of Louisville, Louisville, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,8,24]]},"reference":[{"key":"e_1_3_3_2_2_2","volume-title":"Federated Learning: Collaborative Machine Learning without Centralized Training Data","unstructured":"[n. d.]. Federated Learning: Collaborative Machine Learning without Centralized Training Data. https:\/\/ai.googleblog.com\/2017\/04\/federated-learning-collaborative.html"},{"key":"e_1_3_3_2_3_2","volume-title":"Utilization of FATE in Risk Management of Credit in Small and Micro Enterprises","unstructured":"[n. d.]. Utilization of FATE in Risk Management of Credit in Small and Micro Enterprises. https:\/\/www.fedai.org\/cases\/utilization-of-fate-in-risk-management-of-credit-in-small-and-micro-enterprises\/"},{"key":"e_1_3_3_2_4_2","volume-title":"CCS","author":"Abadi Martin","year":"2016","unstructured":"Martin Abadi, Andy Chu, Ian Goodfellow, H\u00a0Brendan McMahan, Ilya Mironov, Kunal Talwar, and Li Zhang. 2016. Deep learning with differential privacy. In CCS."},{"key":"e_1_3_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i10.28971"},{"key":"e_1_3_3_2_6_2","volume-title":"AISTATS","author":"Bagdasaryan Eugene","year":"2020","unstructured":"Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. In AISTATS."},{"key":"e_1_3_3_2_7_2","volume-title":"NeurIPS","author":"Baruch Gilad","year":"2019","unstructured":"Gilad Baruch, Moran Baruch, and Yoav Goldberg. 2019. A little is enough: Circumventing defenses for distributed learning. In NeurIPS."},{"key":"e_1_3_3_2_8_2","volume-title":"arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2211.08413","author":"Beltr\u00e1n Enrique Tom\u00e1s\u00a0Mart\u00ednez","year":"2022","unstructured":"Enrique Tom\u00e1s\u00a0Mart\u00ednez Beltr\u00e1n, Mario\u00a0Quiles P\u00e9rez, Pedro Miguel\u00a0S\u00e1nchez S\u00e1nchez, Sergio\u00a0L\u00f3pez Bernal, G\u00e9r\u00f4me Bovet, Manuel\u00a0Gil P\u00e9rez, Gregorio\u00a0Mart\u00ednez P\u00e9rez, and Alberto\u00a0Huertas Celdr\u00e1n. 2022. Decentralized Federated Learning: Fundamentals, State-of-the-art, Frameworks, Trends, and Challenges. In arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2211.08413."},{"key":"e_1_3_3_2_9_2","volume-title":"ICML","author":"Bhagoji Arjun\u00a0Nitin","year":"2019","unstructured":"Arjun\u00a0Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin Calo. 2019. Analyzing federated learning through an adversarial lens. In ICML."},{"key":"e_1_3_3_2_10_2","volume-title":"NeurIPS","author":"Blanchard Peva","year":"2017","unstructured":"Peva Blanchard, El\u00a0Mahdi El\u00a0Mhamdi, Rachid Guerraoui, and Julien Stainer. 2017. Machine learning with adversaries: Byzantine tolerant gradient descent. In NeurIPS."},{"key":"e_1_3_3_2_11_2","volume-title":"SysML","author":"Bonawitz Keith","year":"2019","unstructured":"Keith Bonawitz. 2019. Towards federated learning at scale: System design. In SysML."},{"key":"e_1_3_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453104"},{"key":"e_1_3_3_2_13_2","volume-title":"NeurIPS","author":"Caldas Sebastian","year":"2019","unstructured":"Sebastian Caldas, Sai Meher\u00a0Karthik Duddu, Peter Wu, Tian Li, Jakub Konen, H.\u00a0Brendan Mcmahan, Virginia Smith, and Ameet Talwalkar. 2019. LEAF: A Benchmark for Federated Settings. In NeurIPS."},{"key":"e_1_3_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-37456-2_14"},{"key":"e_1_3_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"e_1_3_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW56347.2022.00383"},{"key":"e_1_3_3_2_17_2","volume-title":"CVPR","author":"Cazenavette George","year":"2022","unstructured":"George Cazenavette, Tongzhou Wang, Antonio Torralba, Alexei\u00a0A Efros, and Jun-Yan Zhu. 2022. Dataset distillation by matching training trajectories. In CVPR."},{"key":"e_1_3_3_2_18_2","volume-title":"ICLR","author":"Chang Hongyan","year":"2023","unstructured":"Hongyan Chang and Reza Shokri. 2023. Bias propagation in federated learning. In ICLR."},{"key":"e_1_3_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE55515.2023.00177"},{"key":"e_1_3_3_2_20_2","volume-title":"IEEE transactions on pattern analysis and machine intelligence","author":"Cheng Yizong","year":"1995","unstructured":"Yizong Cheng. 1995. Mean shift, mode seeking, and clustering. In IEEE transactions on pattern analysis and machine intelligence."},{"key":"e_1_3_3_2_21_2","volume-title":"AISTATS","author":"Coates Adam","year":"2011","unstructured":"Adam Coates, Andrew Ng, and Honglak Lee. 2011. An analysis of single-layer networks in unsupervised feature learning. In AISTATS."},{"key":"e_1_3_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_3_2_23_2","unstructured":"Zhihao Dou Jiaqi Wang Wei Sun Zhuqing Liu and Minghong Fang. 2025. Toward Malicious Clients Detection in Federated Learning. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2505.09110 (2025)."},{"key":"e_1_3_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/2090236.2090255"},{"key":"e_1_3_3_2_25_2","volume-title":"NeurIPS","author":"El-Mhamdi El\u00a0Mahdi","year":"2021","unstructured":"El\u00a0Mahdi El-Mhamdi, Sadegh Farhadkhani, Rachid Guerraoui, Arsany Guirguis, L\u00ea-Nguy\u00ean Hoang, and S\u00e9bastien Rouault. 2021. Collaborative learning in the jungle (decentralized, byzantine, heterogeneous, asynchronous and nonconvex learning). In NeurIPS."},{"key":"e_1_3_3_2_26_2","volume-title":"USENIX Security Symposium","author":"Fang Minghong","year":"2020","unstructured":"Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Gong. 2020. Local model poisoning attacks to Byzantine-robust federated learning. In USENIX Security Symposium."},{"key":"e_1_3_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3567991"},{"key":"e_1_3_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1145\/3701716.3715491"},{"key":"e_1_3_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.241796"},{"key":"e_1_3_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3696410.3714728"},{"key":"e_1_3_3_2_31_2","volume-title":"CCS","author":"Fang Minghong","year":"2024","unstructured":"Minghong Fang, Zifan Zhang, Hairi, Prashant Khanduri, Jia Liu, Songtao Lu, Yuchen Liu, and Neil Gong. 2024. Byzantine-robust decentralized federated learning. In CCS."},{"key":"e_1_3_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24620"},{"key":"e_1_3_3_2_33_2","volume-title":"NeurIPS","author":"Hardt Moritz","year":"2016","unstructured":"Moritz Hardt, Eric Price, and Nati Srebro. 2016. Equality of opportunity in supervised learning. In NeurIPS."},{"key":"e_1_3_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.2307\/2346830"},{"key":"e_1_3_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1038\/s41467-023-38569-4"},{"key":"e_1_3_3_2_37_2","volume-title":"ICLR","author":"Karimireddy Sai\u00a0Praneeth","year":"2022","unstructured":"Sai\u00a0Praneeth Karimireddy, Lie He, and Martin Jaggi. 2022. Byzantine-robust learning on heterogeneous datasets via bucketing. In ICLR."},{"key":"e_1_3_3_2_38_2","volume-title":"ICML","author":"Karimireddy Sai\u00a0Praneeth","year":"2020","unstructured":"Sai\u00a0Praneeth Karimireddy, Satyen Kale, Mehryar Mohri, Sashank Reddi, Sebastian Stich, and Ananda\u00a0Theertha Suresh. 2020. Scaffold: Stochastic controlled averaging for federated learning. In ICML."},{"key":"e_1_3_3_2_39_2","volume-title":"ICML","author":"Kim Jang-Hyun","year":"2022","unstructured":"Jang-Hyun Kim, Jinuk Kim, Seong\u00a0Joon Oh, Sangdoo Yun, Hwanjun Song, Joonhyun Jeong, Jung-Woo Ha, and Hyun\u00a0Oh Song. 2022. Dataset condensation via efficient synthetic-data parameterization. In ICML."},{"key":"e_1_3_3_2_40_2","unstructured":"A. Krizhevsky and G. Hinton. 2009. Learning multiple layers of features from tiny images. Handbook of Systemic Autoimmune Diseases (2009)."},{"key":"e_1_3_3_2_41_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179362"},{"key":"e_1_3_3_2_42_2","unstructured":"Yann LeCun Corinna Cortes and CJ Burges. 1998. MNIST handwritten digit database. Available: http:\/\/yann. lecun. com\/exdb\/mnist (1998)."},{"key":"e_1_3_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011544"},{"key":"e_1_3_3_2_44_2","volume-title":"USENIX Security Symposium","author":"Li Songze","year":"2024","unstructured":"Songze Li and Yanbo Dai. 2024. BackdoorIndicator: Leveraging OOD Data for Proactive Backdoor Detection in Federated Learning. In USENIX Security Symposium."},{"key":"e_1_3_3_2_45_2","volume-title":"ICML","author":"Li Tian","year":"2021","unstructured":"Tian Li, Shengyuan Hu, Ahmad Beirami, and Virginia Smith. 2021. Ditto: Fair and robust federated learning through personalization. In ICML."},{"key":"e_1_3_3_2_46_2","volume-title":"MLSys","author":"Li Tian","year":"2020","unstructured":"Tian Li, Anit\u00a0Kumar Sahu, Manzil Zaheer, Maziar Sanjabi, Ameet Talwalkar, and Virginia Smith. 2020. Federated optimization in heterogeneous networks. In MLSys."},{"key":"e_1_3_3_2_47_2","volume-title":"ICLR","author":"Li Tian","year":"2020","unstructured":"Tian Li, Maziar Sanjabi, Ahmad Beirami, and Virginia Smith. 2020. Fair resource allocation in federated learning. In ICLR."},{"key":"e_1_3_3_2_48_2","volume-title":"ICLR","author":"Li Xiang","year":"2020","unstructured":"Xiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang, and Zhihua Zhang. 2020. On the convergence of fedavg on non-iid data. In ICLR."},{"key":"e_1_3_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.00366"},{"key":"e_1_3_3_2_50_2","volume-title":"AISTATS","author":"McMahan H.\u00a0Brendan","year":"2017","unstructured":"H.\u00a0Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise\u00a0Ag\u00fcera y Arcas. 2017. Communication-Efficient Learning of Deep Networks from Decentralized Data. In AISTATS."},{"key":"e_1_3_3_2_51_2","volume-title":"ICML","author":"Mohri Mehryar","year":"2019","unstructured":"Mehryar Mohri, Gary Sivek, and Ananda\u00a0Theertha Suresh. 2019. Agnostic federated learning. In ICML."},{"key":"e_1_3_3_2_52_2","volume-title":"USENIX Security Symposium","author":"Mozaffari Hamid","year":"2023","unstructured":"Hamid Mozaffari, Virat Shejwalkar, and Amir Houmansadr. 2023. Every Vote Counts: Ranking-Based Training of Federated Learning to Resist Poisoning Attacks. In USENIX Security Symposium."},{"key":"e_1_3_3_2_53_2","unstructured":"Luis Mu\u00f1oz-Gonz\u00e1lez Kenneth\u00a0T Co and Emil\u00a0C Lupu. 2019. Byzantine-robust federated machine learning through adaptive model averaging. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/1909.05125 (2019)."},{"key":"e_1_3_3_2_54_2","volume-title":"CCS","author":"Naseri Mohammad","year":"2022","unstructured":"Mohammad Naseri, Yufei Han, Enrico Mariconti, Yun Shen, Gianluca Stringhini, and Emiliano De\u00a0Cristofaro. 2022. Cerberus: Exploring Federated Prediction of Security Events. In CCS."},{"key":"e_1_3_3_2_55_2","volume-title":"NeurIPS","author":"Nguyen Thuy\u00a0Dung","year":"2023","unstructured":"Thuy\u00a0Dung Nguyen, Tuan\u00a0A Nguyen, Anh Tran, Khoa\u00a0D Doan, and Kok-Seng Wong. 2023. Iba: Towards irreversible backdoor attacks in federated learning. In NeurIPS."},{"key":"e_1_3_3_2_56_2","volume-title":"USENIX Security Symposium","author":"Nguyen Thien\u00a0Duc","year":"2022","unstructured":"Thien\u00a0Duc Nguyen, Phillip Rieger, Roberta De\u00a0Viti, Huili Chen, Bj\u00f6rn\u00a0B Brandenburg, Hossein Yalame, Helen M\u00f6llering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, et\u00a0al. 2022. FLAME: Taming backdoors in federated learning. In USENIX Security Symposium."},{"key":"e_1_3_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i10.17118"},{"key":"e_1_3_3_2_58_2","unstructured":"Matthias Paulik Matt Seigel Henry Mason Dominic Telaar Joris Kluivers Rogier van Dalen Chi\u00a0Wai Lau Luke Carlson Filip Granqvist Chris Vandevelde et\u00a0al. 2021. Federated evaluation and tuning for on-device personalization: System design & applications. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2102.08503 (2021)."},{"key":"e_1_3_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52729.2023.01172"},{"key":"e_1_3_3_2_60_2","volume-title":"NeurIPS","author":"Rajput Shashank","year":"2019","unstructured":"Shashank Rajput, Hongyi Wang, Zachary Charles, and Dimitris Papailiopoulos. 2019. DETOX: A redundancy-based framework for faster and more robust gradient aggregation. In NeurIPS."},{"key":"e_1_3_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2022.23156"},{"key":"e_1_3_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"e_1_3_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"e_1_3_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-58951-6_24"},{"key":"e_1_3_3_2_65_2","unstructured":"Jianyu Wang Qinghua Liu Hao Liang Gauri Joshi and H\u00a0Vincent Poor. 2020. Tackling the objective inconsistency problem in heterogeneous federated optimization. NeurIPS."},{"key":"e_1_3_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01188"},{"key":"e_1_3_3_2_67_2","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3517395"},{"key":"e_1_3_3_2_68_2","doi-asserted-by":"publisher","DOI":"10.1145\/3701716.3715494"},{"key":"e_1_3_3_2_69_2","volume-title":"ICLR","author":"Xie Chulin","year":"2020","unstructured":"Chulin Xie, Keli Huang, Pin-Yu Chen, and Bo Li. 2020. Dba: Distributed backdoor attacks against federated learning. In ICLR."},{"key":"e_1_3_3_2_70_2","volume-title":"ICML","author":"Xie Cong","year":"2019","unstructured":"Cong Xie, Sanmi Koyejo, and Indranil Gupta. 2019. Zeno: Distributed stochastic gradient descent with suspicion-based fault-tolerance. In ICML."},{"key":"e_1_3_3_2_71_2","volume-title":"ICML","author":"Xie Yueqi","year":"2024","unstructured":"Yueqi Xie, Minghong Fang, and Neil\u00a0Zhenqiang Gong. 2024. FedREDefense: Defending against Model Poisoning Attacks for Federated Learning using Model Update Reconstruction Error. In ICML."},{"key":"e_1_3_3_2_72_2","volume-title":"ICML","author":"Yin Dong","year":"2018","unstructured":"Dong Yin, Yudong Chen, Kannan Ramchandran, and Peter Bartlett. 2018. Byzantine-Robust Distributed Learning: Towards Optimal Statistical Rates. In ICML."},{"key":"e_1_3_3_2_73_2","doi-asserted-by":"publisher","DOI":"10.1145\/3589334.3645492"},{"key":"e_1_3_3_2_74_2","volume-title":"CCS","author":"Zeng Yi","year":"2023","unstructured":"Yi Zeng, Minzhou Pan, Hoang\u00a0Anh Just, Lingjuan Lyu, Meikang Qiu, and Ruoxi Jia. 2023. Narcissus: A practical clean-label backdoor attack with limited information. In CCS."},{"key":"e_1_3_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539231"},{"key":"e_1_3_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.23919\/IFIPNetworking62109.2024.10619763"},{"key":"e_1_3_3_2_77_2","volume-title":"ICML","author":"Zhang Zhengming","year":"2022","unstructured":"Zhengming Zhang, Ashwinee Panda, Linyue Song, Yaoqing Yang, Michael Mahoney, Prateek Mittal, Ramchandran Kannan, and Joseph Gonzalez. 2022. Neurotoxin: Durable backdoors in federated learning. In ICML."},{"key":"e_1_3_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.1109\/WACV56688.2023.00645"},{"key":"e_1_3_3_2_79_2","volume-title":"ICLR","author":"Zhao Bo","year":"2021","unstructured":"Bo Zhao, Konda\u00a0Reddy Mopuri, and Hakan Bilen. 2021. Dataset condensation with gradient matching. In ICLR."},{"key":"e_1_3_3_2_80_2","volume-title":"ICML","author":"Zhu Zhuangdi","year":"2021","unstructured":"Zhuangdi Zhu, Junyuan Hong, and Jiayu Zhou. 2021. Data-free knowledge distillation for heterogeneous federated learning. In ICML."}],"event":{"name":"ASIA CCS '25: 20th ACM Asia Conference on Computer and Communications Security","location":"Hanoi Vietnam","acronym":"ASIA CCS '25","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 20th ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3708821.3736194","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,13]],"date-time":"2025-08-13T07:25:55Z","timestamp":1755069955000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3708821.3736194"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,24]]},"references-count":79,"alternative-id":["10.1145\/3708821.3736194","10.1145\/3708821"],"URL":"https:\/\/doi.org\/10.1145\/3708821.3736194","relation":{},"subject":[],"published":{"date-parts":[[2025,8,24]]},"assertion":[{"value":"2025-08-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}