{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:14:57Z","timestamp":1766441697075,"version":"3.48.0"},"publisher-location":"New York, NY, USA","reference-count":78,"publisher":"ACM","funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62473047, U23A20332, 62272381, 623B2081, 62372490, W2412110"],"award-info":[{"award-number":["62473047, U23A20332, 62272381, 623B2081, 62372490, W2412110"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100017596","name":"Natural Science Basic Research Program of Shaanxi Province","doi-asserted-by":"publisher","award":["2023-JC-JQ-50"],"award-info":[{"award-number":["2023-JC-JQ-50"]}],"id":[{"id":"10.13039\/501100017596","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,11,19]]},"DOI":"10.1145\/3719027.3744805","type":"proceedings-article","created":{"date-parts":[[2025,11,22]],"date-time":"2025-11-22T23:32:38Z","timestamp":1763854358000},"page":"1679-1693","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Sylva: Tailoring Personalized Adversarial Defense in Pre-trained Models via Collaborative Fine-tuning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5484-985X","authenticated-orcid":false,"given":"Tianyu","family":"Qi","sequence":"first","affiliation":[{"name":"Sun Yat-sen University, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5321-5740","authenticated-orcid":false,"given":"Lei","family":"Xue","sequence":"additional","affiliation":[{"name":"Sun Yat-sen University, Shenzhen, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4528-1489","authenticated-orcid":false,"given":"Yufeng","family":"Zhan","sequence":"additional","affiliation":[{"name":"Beijing Institute of Technology, Beijing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0934-5035","authenticated-orcid":false,"given":"Xiaobo","family":"Ma","sequence":"additional","affiliation":[{"name":"Xi'an Jiaotong University, Xi'an, China"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,11,22]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.52202\/079017-3197"},{"key":"e_1_3_2_1_2_1","unstructured":"ASME. 2025. Battery-Powered EVs Now Match Gas Cars in Lifespan. https:\/\/www.asme.org\/topics-resources\/content\/new-study-finds-battery-powered-evs-now-match-gas-cars-in-lifespan."},{"key":"e_1_3_2_1_3_1","volume-title":"Qwen-vl: A frontier large vision-language model with versatile abilities. arXiv preprint arXiv:2308.12966","author":"Bai Jinze","year":"2023","unstructured":"Jinze Bai, Shuai Bai, Shusheng Yang, Shijie Wang, Sinan Tan, Peng Wang, Junyang Lin, Chang Zhou, and Jingren Zhou. 2023. Qwen-vl: A frontier large vision-language model with versatile abilities. arXiv preprint arXiv:2308.12966 (2023)."},{"key":"e_1_3_2_1_4_1","unstructured":"Baidu. 2022. Apollo D-KIT Advanced. https:\/\/apollo.baidu.com\/community\/apollo_d_kit."},{"key":"e_1_3_2_1_5_1","first-page":"1196","article-title":"Pre-trained adversarial perturbations","author":"Ban Yuanhao","year":"2022","unstructured":"Yuanhao Ban and Yinpeng Dong. 2022. Pre-trained adversarial perturbations. In Proceedings of the Neural Information Processing Systems. 1196-1209.","journal-title":"Proceedings of the Neural Information Processing Systems."},{"key":"e_1_3_2_1_6_1","first-page":"3569","article-title":"Calfat: Calibrated federated adversarial training with label skewness","author":"Chen Chen","year":"2022","unstructured":"Chen Chen, Yuchen Liu, Xingjun Ma, and Lingjuan Lyu. 2022. Calfat: Calibrated federated adversarial training with label skewness. In Proceedings of the Neural Information Processing Systems. 3569-3581.","journal-title":"Proceedings of the Neural Information Processing Systems."},{"key":"e_1_3_2_1_7_1","volume-title":"Proceedings of the International Conference on Artificial Intelligence and Statistics. 215-223","author":"Coates Adam","year":"2011","unstructured":"Adam Coates, Andrew Ng, and Honglak Lee. 2011. An analysis of single-layer networks in unsupervised feature learning. In Proceedings of the International Conference on Artificial Intelligence and Statistics. 215-223."},{"key":"e_1_3_2_1_8_1","volume-title":"Proceedings of the International Conference on Machine Learning. 2206-2216","author":"Croce Francesco","year":"2020","unstructured":"Francesco Croce and Matthias Hein. 2020. Reliable evaluation of adversarial robustness with an ensemble of diverse parameter-free attacks. In Proceedings of the International Conference on Machine Learning. 2206-2216."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3559388"},{"key":"e_1_3_2_1_10_1","volume-title":"Efficient spatial indexing for constrained nearest-neighbor search in metric spaces. arXiv preprint arXiv:1511.00628","author":"Dolatshah Mohamad","year":"2015","unstructured":"Mohamad Dolatshah, Ali Hadian, and Behrouz Minaei-Bidgoli. 2015. Ball*-tree: Efficient spatial indexing for constrained nearest-neighbor search in metric spaces. arXiv preprint arXiv:1511.00628 (2015)."},{"key":"e_1_3_2_1_11_1","volume-title":"Proceedings of the International Conference on Learning Representations.","author":"Dosovitskiy Alexey","year":"2021","unstructured":"Alexey Dosovitskiy, Lucas Beyer, Alexander Kolesnikov, Dirk Weissenborn, Xiaohua Zhai, Thomas Unterthiner, Mostafa Dehghani, Matthias Minderer, Georg Heigold, Sylvain Gelly, Jakob Uszkoreit, and Neil Houlsby. 2021. An image is worth 16x16 words: Transformers for image recognition at scale. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3437801.3441593"},{"key":"e_1_3_2_1_13_1","volume-title":"Proceedings of the USENIX Security Symposium. 1605-1622","author":"Fang Minghong","year":"2020","unstructured":"Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Gong. 2020. Local model poisoning attacks to byzantine-robust federated learning. In Proceedings of the USENIX Security Symposium. 1605-1622."},{"key":"e_1_3_2_1_14_1","volume-title":"Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572","author":"Goodfellow Ian J","year":"2014","unstructured":"Ian J Goodfellow, Jonathon Shlens, and Christian Szegedy. 2014. Explaining and harnessing adversarial examples. arXiv preprint arXiv:1412.6572 (2014)."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/TMC.2023.3302410"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_17_1","volume-title":"Lisa Anne Hendricks, Johannes Welbl, Aidan Clark, et al.","author":"Hoffmann Jordan","year":"2022","unstructured":"Jordan Hoffmann, Sebastian Borgeaud, Arthur Mensch, Elena Buchatskaya, Trevor Cai, Eliza Rutherford, Diego de Las Casas, Lisa Anne Hendricks, Johannes Welbl, Aidan Clark, et al., 2022. Training compute-optimal large language models. arXiv preprint arXiv:2203.15556 (2022)."},{"key":"e_1_3_2_1_18_1","first-page":"7893","article-title":"Federated robustness propagation: sharing adversarial robustness in heterogeneous federated learning","author":"Hong Junyuan","year":"2023","unstructured":"Junyuan Hong, Haotao Wang, Zhangyang Wang, and Jiayu Zhou. 2023. Federated robustness propagation: sharing adversarial robustness in heterogeneous federated learning. In Proceedings of the Association for the Advancement of Artificial Intelligence. 7893-7901.","journal-title":"Proceedings of the Association for the Advancement of Artificial Intelligence."},{"key":"e_1_3_2_1_19_1","volume-title":"Proceedings of the International Conference on Learning Representations.","author":"Hu Edward J","year":"2022","unstructured":"Edward J Hu, Yelong Shen, Phillip Wallis, Zeyuan Allen-Zhu, Yuanzhi Li, Shean Wang, Lu Wang, and Weizhu Chen. 2022. Lora: Low-rank adaptation of large language models. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833644"},{"key":"e_1_3_2_1_21_1","first-page":"583","volume-title":"Nature","volume":"596","author":"Jumper John","year":"2021","unstructured":"John Jumper, Richard Evans, Alexander Pritzel, Tim Green, Michael Figurnov, Olaf Ronneberger, Kathryn Tunyasuvunakool, Russ Bates, Augustin \u017d\u00eddek, Anna Potapenko, et al., 2021. Highly accurate protein structure prediction with AlphaFold. Nature, Vol. 596, 7873 (2021), 583-589."},{"key":"e_1_3_2_1_22_1","volume-title":"Proceedings of the Conference on Computer and Communications Security. 1526-1540","author":"Krau\u00df Torsten","year":"2023","unstructured":"Torsten Krau\u00df, and Alexandra Dmitrienko. 2023. Mesas: Poisoning defense for federated learning resilient against adaptive attackers. In Proceedings of the Conference on Computer and Communications Security. 1526-1540."},{"key":"e_1_3_2_1_23_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR42600.2020.00035"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/2640087.2644155"},{"key":"e_1_3_2_1_26_1","volume-title":"Proceedings of the International Conference on Machine Learning. 19504-19526","author":"Li Qinbin","year":"2023","unstructured":"Qinbin Li, Bingsheng He, and Dawn Song. 2023a. Adversarial collaborative learning on non-iid features. In Proceedings of the International Conference on Machine Learning. 19504-19526."},{"key":"e_1_3_2_1_27_1","volume-title":"Proceedings of the Machine Learning and Systems. 429-450","author":"Li Tian","year":"2020","unstructured":"Tian Li, Anit Kumar Sahu, Manzil Zaheer, Maziar Sanjabi, Ameet Talwalkar, and Virginia Smith. 2020b. Federated optimization in heterogeneous networks. In Proceedings of the Machine Learning and Systems. 429-450."},{"key":"e_1_3_2_1_28_1","volume-title":"Proceedings of the International Conference on Learning Representations.","author":"Li Xiang","year":"2020","unstructured":"Xiang Li, Kaixuan Huang, Wenhao Yang, Shusen Wang, and Zhihua Zhang. 2020a. On the convergence of fedavg on non-iid data. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_2_1_29_1","volume-title":"Proceedings of the International Conference on Machine Learning. 19932-19959","author":"Li Xiaoxiao","year":"2023","unstructured":"Xiaoxiao Li, Zhao Song, and Jiaming Yang. 2023b. Federated adversarial learning: A framework with convergence analysis. In Proceedings of the International Conference on Machine Learning. 19932-19959."},{"key":"e_1_3_2_1_30_1","volume-title":"Proceedings of the USENIX Security Symposium. 3629-3645","author":"Liu Hongbin","year":"2022","unstructured":"Hongbin Liu, Jinyuan Jia, and Neil Zhenqiang Gong. 2022b. PoisonedEncoder: Poisoning the unlabeled pre-training data in contrastive learning. In Proceedings of the USENIX Security Symposium. 3629-3645."},{"key":"e_1_3_2_1_31_1","first-page":"34892","article-title":"Visual instruction tuning","author":"Liu Haotian","year":"2023","unstructured":"Haotian Liu, Chunyuan Li, Qingyang Wu, and Yong Jae Lee. 2023. Visual instruction tuning. In Proceedings of the Neural Information Processing Systems. 34892-34916.","journal-title":"Proceedings of the Neural Information Processing Systems."},{"key":"e_1_3_2_1_32_1","first-page":"8392","article-title":"A robust adversarial training approach to machine reading comprehension","author":"Liu Kai","year":"2020","unstructured":"Kai Liu, Xin Liu, An Yang, Jing Liu, Jinsong Su, Sujian Li, and Qiaoqiao She. 2020. A robust adversarial training approach to machine reading comprehension. In Proceedings of the Association for the Advancement of Artificial Intelligence. 8392-8400.","journal-title":"Proceedings of the Association for the Advancement of Artificial Intelligence."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/TWC.2022.3190512"},{"key":"e_1_3_2_1_34_1","volume-title":"Zhengxiao Du, Zhilin Yang, and Jie Tang.","author":"Liu Xiao","year":"2022","unstructured":"Xiao Liu, Kaixuan Ji, Yicheng Fu, Weng Lam Tam, Zhengxiao Du, Zhilin Yang, and Jie Tang. 2022a. P-tuning v2: Prompt tuning can be comparable to fine-tuning universally across scales and tasks. In Proceedings of the Association for Computational Linguistics. 61-68."},{"key":"e_1_3_2_1_35_1","volume-title":"Adv-bnn: Improved adversarial defense through robust bayesian neural network. arXiv preprint arXiv:1810.01279","author":"Liu Xuanqing","year":"2018","unstructured":"Xuanqing Liu, Yao Li, Chongruo Wu, and Cho-Jui Hsieh. 2018. Adv-bnn: Improved adversarial defense through robust bayesian neural network. arXiv preprint arXiv:1810.01279 (2018)."},{"key":"e_1_3_2_1_36_1","volume-title":"Proceedings of the International Conference on Machine Learning.","author":"Liu Zechun","year":"2024","unstructured":"Zechun Liu, Changsheng Zhao, Forrest Iandola, Chen Lai, Yuandong Tian, Igor Fedorov, Yunyang Xiong, Ernie Chang, Yangyang Shi, Raghuraman Krishnamoorthi, et al., 2024. Mobilellm: Optimizing sub-billion parameter language models for on-device use cases. In Proceedings of the International Conference on Machine Learning."},{"key":"e_1_3_2_1_37_1","first-page":"5972","article-title":"No fear of heterogeneity: Classifier calibration for federated learning with non-iid data","author":"Luo Mi","year":"2021","unstructured":"Mi Luo, Fei Chen, Dapeng Hu, Yifan Zhang, Jian Liang, and Jiashi Feng. 2021. No fear of heterogeneity: Classifier calibration for federated learning with non-iid data. In Proceedings of the Neural Information Processing Systems. 5972-5984.","journal-title":"Proceedings of the Neural Information Processing Systems."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3169918"},{"key":"e_1_3_2_1_39_1","volume-title":"Proceedings of the International Conference on Learning Representations.","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards deep learning models resistant to adversarial attacks. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPRW59228.2023.00334"},{"key":"e_1_3_2_1_41_1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Proceedings of the Artificial Intelligence and Statistics. 1273-1282.","journal-title":"Proceedings of the Artificial Intelligence and Statistics."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2019.00930"},{"key":"e_1_3_2_1_43_1","first-page":"561","article-title":"Ray: A distributed framework for emerging AI applications","author":"Moritz Philipp","year":"2018","unstructured":"Philipp Moritz, Robert Nishihara, Stephanie Wang, Alexey Tumanov, Richard Liaw, Eric Liang, Melih Elibol, Zongheng Yang, William Paul, Michael I Jordan, et al., 2018. Ray: A distributed framework for emerging AI applications. In Proceedings of the Operating Systems Design and Implementation. 561-577.","journal-title":"Proceedings of the Operating Systems Design and Implementation."},{"key":"e_1_3_2_1_44_1","unstructured":"NVIDIA. 2021. Jetson AGX Orin. https:\/\/www.nvidia.com\/en-us\/autonomous-machines\/embedded-systems\/jetson-orin\/."},{"key":"e_1_3_2_1_45_1","unstructured":"NVIDIA. 2024a. AI Drives Future of Transportation at Asia's Largest Automotive Show. https:\/\/blogs.nvidia.com\/blog\/nvidia-partners-auto-china\/."},{"key":"e_1_3_2_1_46_1","unstructured":"NVIDIA. 2024b. Wave of EV Makers Choose NVIDIA DRIVE for Automated Driving. https:\/\/nvidianews.nvidia.com\/news\/wave-of-ev-makers-choose-nvidia-drive-for-automated-driving."},{"key":"e_1_3_2_1_47_1","first-page":"9268","article-title":"Defending against backdoors in federated learning with robust learning rate","author":"Ozdayi Mustafa Safa","year":"2021","unstructured":"Mustafa Safa Ozdayi, Murat Kantarcioglu, and Yulia R Gel. 2021. Defending against backdoors in federated learning with robust learning rate. In Proceedings of the Association for the Advancement of Artificial Intelligence. 9268-9276.","journal-title":"Proceedings of the Association for the Advancement of Artificial Intelligence."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560557"},{"key":"e_1_3_2_1_49_1","first-page":"7852","article-title":"Fairvfl: A fair vertical federated learning framework with contrastive adversarial learning","author":"Qi Tao","year":"2022","unstructured":"Tao Qi, Fangzhao Wu, Chuhan Wu, Lingjuan Lyu, Tong Xu, Hao Liao, Zhongliang Yang, Yongfeng Huang, and Xing Xie. 2022. Fairvfl: A fair vertical federated learning framework with contrastive adversarial learning. In Proceedings of the Neural Information Processing Systems. 7852-7865.","journal-title":"Proceedings of the Neural Information Processing Systems."},{"key":"e_1_3_2_1_50_1","volume-title":"Sylva: Tailoring Personalized Adversarial Defense in Pre-trained Models via Collaborative Fine-tuning. arXiv preprint arXiv:2506.05402","author":"Qi Tianyu","year":"2025","unstructured":"Tianyu Qi, Lei Xue, Yufeng Zhan, and Xiaobo Ma. 2025a. Sylva: Tailoring Personalized Adversarial Defense in Pre-trained Models via Collaborative Fine-tuning. arXiv preprint arXiv:2506.05402 (2025)."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS57875.2023.00047"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM52122.2024.10621369"},{"key":"e_1_3_2_1_53_1","volume-title":"Robin: An Efficient Hierarchical Federated Learning Framework Via a Learning-Based Synchronization Scheme","author":"Qi Tianyu","year":"2025","unstructured":"Tianyu Qi, Yufeng Zhan, Peng Li, and Yuanqing Xia. 2025b. Robin: An Efficient Hierarchical Federated Learning Framework Via a Learning-Based Synchronization Scheme. IEEE Transactions on Cloud Computing (2025)."},{"key":"e_1_3_2_1_54_1","volume-title":"Proceedings of the International Conference on Machine Learning. 8748-8763","author":"Radford Alec","year":"2021","unstructured":"Alec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, et al., 2021. Learning transferable visual models from natural language supervision. In Proceedings of the International Conference on Machine Learning. 8748-8763."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1007\/s11263-015-0816-y"},{"key":"e_1_3_2_1_56_1","volume-title":"Low-Rank Adversarial PGD Attack. arXiv preprint arXiv:2410.12607","author":"Savostianova Dayana","year":"2024","unstructured":"Dayana Savostianova, Emanuele Zangrando, and Francesco Tudisco. 2024. Low-Rank Adversarial PGD Attack. arXiv preprint arXiv:2410.12607 (2024)."},{"key":"e_1_3_2_1_57_1","volume-title":"A value for n-person games. Contribution to the Theory of Games","author":"Shapley Lloyd S","year":"1953","unstructured":"Lloyd S Shapley. 1953. A value for n-person games. Contribution to the Theory of Games, Vol. 2 (1953)."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN.2011.6033395"},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/TEVC.2019.2890858"},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1109\/BigData62323.2024.10825712"},{"key":"e_1_3_2_1_62_1","volume-title":"Proceedings of the International Conference on Learning Representations.","author":"Tram\u00e8r Florian","year":"2018","unstructured":"Florian Tram\u00e8r, Alexey Kurakin, Nicolas Papernot, Ian Goodfellow, Dan Boneh, and Patrick McDaniel. 2018. Ensemble adversarial training: Attacks and defenses. In Proceedings of the International Conference on Learning Representations."},{"key":"e_1_3_2_1_63_1","volume-title":"Proceedings of the Conference on Language Modeling.","author":"Wagner Nicolas","year":"2024","unstructured":"Nicolas Wagner, Dongyang Fan, and Martin Jaggi. 2024. Personalized collaborative fine-tuning for on-device large language models. In Proceedings of the Conference on Language Modeling."},{"key":"e_1_3_2_1_64_1","first-page":"29515","article-title":"Towards personalized federated learning via heterogeneous model reassembly","author":"Wang Jiaqi","year":"2024","unstructured":"Jiaqi Wang, Xingyi Yang, Suhan Cui, Liwei Che, Lingjuan Lyu, Dongkuan DK Xu, and Fenglong Ma. 2024. Towards personalized federated learning via heterogeneous model reassembly. In Proceedings of the Neural Information Processing Systems. 29515-29531.","journal-title":"Proceedings of the Neural Information Processing Systems."},{"key":"e_1_3_2_1_65_1","volume-title":"Proceedings of the International Conference on Machine Learning. 54561-54575","author":"Xie Luyuan","year":"2024","unstructured":"Luyuan Xie, Manqing Lin, Tianyu Luan, Cong Li, Yuejian Fang, Qingni Shen, and Zhonghai Wu. 2024. MH-pFLID: Model heterogeneous personalized federated learning via injection and distillation for medical data analysis. In Proceedings of the International Conference on Machine Learning. 54561-54575."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52733.2024.01443"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3420126"},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/3636534.3649361"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2020.2967772"},{"key":"e_1_3_2_1_70_1","volume-title":"Proceedings of the International Conference on Machine Learning. 7472-7482","author":"Zhang Hongyang","year":"2019","unstructured":"Hongyang Zhang, Yaodong Yu, Jiantao Jiao, Eric Xing, Laurent El Ghaoui, and Michael Jordan. 2019. Theoretically principled trade-off between robustness and accuracy. In Proceedings of the International Conference on Machine Learning. 7472-7482."},{"key":"e_1_3_2_1_71_1","first-page":"11237","article-title":"Fedala: Adaptive local aggregation for personalized federated learning","author":"Zhang Jianqing","year":"2023","unstructured":"Jianqing Zhang, Yang Hua, Hao Wang, Tao Song, Zhengui Xue, Ruhui Ma, and Haibing Guan. 2023a. Fedala: Adaptive local aggregation for personalized federated learning. In Proceedings of the Association for the Advancement of Artificial Intelligence. 11237-11244.","journal-title":"Proceedings of the Association for the Advancement of Artificial Intelligence."},{"key":"e_1_3_2_1_72_1","first-page":"11245","article-title":"Delving into the adversarial robustness of federated learning","author":"Zhang Jie","year":"2023","unstructured":"Jie Zhang, Bo Li, Chen Chen, Lingjuan Lyu, Shuang Wu, Shouhong Ding, and Chao Wu. 2023b. Delving into the adversarial robustness of federated learning. In Proceedings of the Association for the Advancement of Artificial Intelligence. 11245-11253.","journal-title":"Proceedings of the Association for the Advancement of Artificial Intelligence."},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/3472456.3473513"},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/ASE51524.2021.9678843"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/3511808.3557232"},{"key":"e_1_3_2_1_76_1","doi-asserted-by":"publisher","DOI":"10.1145\/3581783.3612454"},{"key":"e_1_3_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00244"},{"key":"e_1_3_2_1_78_1","volume-title":"Proceedings of the Neural Information Processing Systems Workshop.","author":"Zizzo Giulio","year":"2020","unstructured":"Giulio Zizzo, Ambrish Rawat, Mathieu Sinn, and Beat Buesser. 2020. Fat: Federated adversarial training. In Proceedings of the Neural Information Processing Systems Workshop."}],"event":{"name":"CCS '25: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Taipei Taiwan","acronym":"CCS '25"},"container-title":["Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3719027.3744805","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,22]],"date-time":"2025-12-22T22:07:53Z","timestamp":1766441273000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3719027.3744805"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,19]]},"references-count":78,"alternative-id":["10.1145\/3719027.3744805","10.1145\/3719027"],"URL":"https:\/\/doi.org\/10.1145\/3719027.3744805","relation":{},"subject":[],"published":{"date-parts":[[2025,11,19]]},"assertion":[{"value":"2025-11-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}