{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,15]],"date-time":"2026-07-15T17:17:11Z","timestamp":1784135831079,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":77,"publisher":"ACM","content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,10,27]]},"DOI":"10.1145\/3746027.3755742","type":"proceedings-article","created":{"date-parts":[[2025,10,25]],"date-time":"2025-10-25T06:55:00Z","timestamp":1761375300000},"page":"7045-7054","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["FeatShield: Isolating Malicious Feature Extractors for Backdoor-Robust Federated Learning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-9030-6406","authenticated-orcid":false,"given":"Zhou","family":"Tan","sequence":"first","affiliation":[{"name":"College of Computer and Data Science, Fuzhou University, Fuzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0008-0202-4723","authenticated-orcid":false,"given":"De","family":"Li","sequence":"additional","affiliation":[{"name":"School of Computer Science and Engineering, Guangxi Normal University, GUi Lin, Gui lin, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5425-6333","authenticated-orcid":false,"given":"Yirui","family":"Huang","sequence":"additional","affiliation":[{"name":"College of Computer and Data Science, Fuzhou University, Fuzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8087-9769","authenticated-orcid":false,"given":"Jia-Li","family":"Yin","sequence":"additional","affiliation":[{"name":"College of Computer and Data Science, Fuzhou University, Fuzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4238-3295","authenticated-orcid":false,"given":"Ximeng","family":"Liu","sequence":"additional","affiliation":[{"name":"College of Computer and Data Science, Fuzhou University, Fuzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,10,27]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00521-023-09410-2"},{"key":"e_1_3_2_1_2_1","volume-title":"Perdoor: Persistent non-uniform backdoors in federated learning using adversarial perturbations. arXiv preprint arXiv:2205.13523","author":"Alam Manaar","year":"2022","unstructured":"Manaar Alam, Esha Sarkar, and Michail Maniatakos. 2022. Perdoor: Persistent non-uniform backdoors in federated learning using adversarial perturbations. arXiv preprint arXiv:2205.13523 (2022)."},{"key":"e_1_3_2_1_3_1","volume-title":"International conference on artificial intelligence and statistics. PMLR, 2938-2948","author":"Bagdasaryan Eugene","year":"2020","unstructured":"Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. In International conference on artificial intelligence and statistics. PMLR, 2938-2948."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICIP.2019.8802997"},{"key":"e_1_3_2_1_5_1","volume-title":"International conference on machine learning. PMLR, 634-643","author":"Bhagoji Arjun Nitin","year":"2019","unstructured":"Arjun Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin Calo. 2019. Analyzing federated learning through an adversarial lens. In International conference on machine learning. PMLR, 634-643."},{"key":"e_1_3_2_1_6_1","volume-title":"Rachid Guerraoui, and Julien Stainer.","author":"Blanchard Peva","year":"2017","unstructured":"Peva Blanchard, El Mahdi El Mhamdi, Rachid Guerraoui, and Julien Stainer. 2017. Machine learning with adversaries: Byzantine tolerant gradient descent. Advances in neural information processing systems, Vol. 30 (2017)."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3404885"},{"key":"e_1_3_2_1_8_1","volume-title":"Fltrust: Byzantine-robust federated learning via trust bootstrapping. arXiv preprint arXiv:2012.13995","author":"Cao Xiaoyu","year":"2020","unstructured":"Xiaoyu Cao, Minghong Fang, Jia Liu, and Neil Zhenqiang Gong. 2020. Fltrust: Byzantine-robust federated learning via trust bootstrapping. arXiv preprint arXiv:2012.13995 (2020)."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i8.16849"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2022.3212174"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00414"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3151193"},{"key":"e_1_3_2_1_13_1","volume-title":"Fedbe: Making bayesian model ensemble applicable to federated learning. arXiv preprint arXiv:2009.01974","author":"Chen Hong-You","year":"2020","unstructured":"Hong-You Chen and Wei-Lun Chao. 2020. Fedbe: Making bayesian model ensemble applicable to federated learning. arXiv preprint arXiv:2009.01974 (2020)."},{"key":"e_1_3_2_1_14_1","volume-title":"HotProtein: A novel framework for protein thermostability prediction and editing. NeurIPS 2022","author":"Chen Tianlong","year":"2022","unstructured":"Tianlong Chen and Chengyue Gong. 2022. HotProtein: A novel framework for protein thermostability prediction and editing. NeurIPS 2022 (2022)."},{"key":"e_1_3_2_1_15_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_1_16_1","first-page":"2921","article-title":"EMNIST: Extending MNIST to handwritten letters. In 2017 international joint conference on neural networks (IJCNN)","author":"Cohen Gregory","year":"2017","unstructured":"Gregory Cohen, Saeed Afshar, Jonathan Tapson, and Andre Van Schaik. 2017. EMNIST: Extending MNIST to handwritten letters. In 2017 international joint conference on neural networks (IJCNN). IEEE, 2921-2926.","journal-title":"IEEE"},{"key":"e_1_3_2_1_17_1","volume-title":"Cinic-10 is not imagenet or cifar-10. arXiv preprint arXiv:1810.03505","author":"Darlow Luke N","year":"2018","unstructured":"Luke N Darlow, Elliot J Crowley, Antreas Antoniou, and Amos J Storkey. 2018. Cinic-10 is not imagenet or cifar-10. arXiv preprint arXiv:1810.03505 (2018)."},{"key":"e_1_3_2_1_18_1","volume-title":"29th USENIX security symposium (USENIX Security 20). 1605-1622.","author":"Fang Minghong","unstructured":"Minghong Fang, Xiaoyu Cao, Jinyuan Jia, and Neil Gong. 2020. Local model poisoning attacks to {Byzantine-Robust} federated learning. In 29th USENIX security symposium (USENIX Security 20). 1605-1622."},{"key":"e_1_3_2_1_19_1","volume-title":"Attack-resistant federated learning with residual-based reweighting. arXiv preprint arXiv:1912.11464","author":"Fu Shuhao","year":"2019","unstructured":"Shuhao Fu, Chulin Xie, Bo Li, and Qifeng Chen. 2019. Attack-resistant federated learning with residual-based reweighting. arXiv preprint arXiv:1912.11464 (2019)."},{"key":"e_1_3_2_1_20_1","volume-title":"Mitigating sybils in federated learning poisoning. arXiv","author":"Fung C","year":"2018","unstructured":"C Fung, CJM Yoon, and I Beschastnikh. [n.d.]. Mitigating sybils in federated learning poisoning. arXiv 2018. arXiv preprint arXiv:1808.04866 ( [n.,d.])."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/3422622"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-24797-2"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2019.2909068"},{"key":"e_1_3_2_1_24_1","volume-title":"International conference on machine learning. PMLR, 3521-3530","author":"Guerraoui Rachid","year":"2018","unstructured":"Rachid Guerraoui, S\u00e9bastien Rouault, et al., 2018. The hidden vulnerability of distributed learning in byzantium. In International conference on machine learning. PMLR, 3521-3530."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00461"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICCV51070.2023.00429"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIS.2024.3392334"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.00990"},{"key":"e_1_3_2_1_29_1","volume-title":"European Conference on Computer Vision. Springer, 247-265","author":"Huang Wenke","year":"2024","unstructured":"Wenke Huang, Mang Ye, Zekun Shi, Bo Du, and Dacheng Tao. 2024b. Fisher calibration for backdoor-robust heterogeneous federated learning. In European Conference on Computer Vision. Springer, 247-265."},{"key":"e_1_3_2_1_30_1","volume-title":"Parameter Disparities Dissection for Backdoor Defense in Heterogeneous Federated Learning. In The Thirty-eighth Annual Conference on Neural Information Processing Systems.","author":"Huang Wenke","year":"2024","unstructured":"Wenke Huang, Mang Ye, Zekun Shi, Guancheng Wan, He Li, and Bo Du. 2024c. Parameter Disparities Dissection for Backdoor Defense in Heterogeneous Federated Learning. In The Thirty-eighth Annual Conference on Neural Information Processing Systems."},{"key":"e_1_3_2_1_31_1","unstructured":"Wendy Kan. 2019. Lending Club Loan Data. https:\/\/www.kaggle.com\/datasets\/wendykan\/lending-club-loandata"},{"key":"e_1_3_2_1_32_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPAMI.2023.3322785"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/5.726791"},{"key":"e_1_3_2_1_35_1","volume-title":"Deep partition aggregation: Provable defense against general poisoning attacks. arXiv preprint arXiv:2006.14768","author":"Levine Alexander","year":"2020","unstructured":"Alexander Levine and Soheil Feizi. 2020. Deep partition aggregation: Provable defense against general poisoning attacks. arXiv preprint arXiv:2006.14768 (2020)."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDE53745.2022.00077"},{"key":"e_1_3_2_1_37_1","volume-title":"Unveiling Impact of Frequency Components on Membership Inference Attacks for Diffusion Models. arXiv preprint arXiv:2505.20955","author":"Lian Puwei","year":"2025","unstructured":"Puwei Lian, Yujun Cai, and Songze Li. 2025. Unveiling Impact of Frequency Components on Membership Inference Attacks for Diffusion Models. arXiv preprint arXiv:2505.20955 (2025)."},{"key":"e_1_3_2_1_38_1","volume-title":"Ensemble distillation for robust model fusion in federated learning. Advances in neural information processing systems","author":"Lin Tao","year":"2020","unstructured":"Tao Lin, Lingjing Kong, Sebastian U Stich, and Martin Jaggi. 2020. Ensemble distillation for robust model fusion in federated learning. Advances in neural information processing systems, Vol. 33 (2020), 2351-2363."},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i19.30131"},{"key":"e_1_3_2_1_40_1","first-page":"5972","article-title":"No fear of heterogeneity: Classifier calibration for federated learning with non-iid data","volume":"34","author":"Luo Mi","year":"2021","unstructured":"Mi Luo, Fei Chen, Dapeng Hu, Yifan Zhang, Jian Liang, and Jiashi Feng. 2021. No fear of heterogeneity: Classifier calibration for federated learning with non-iid data. Advances in Neural Information Processing Systems, Vol. 34 (2021), 5972-5984.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_41_1","first-page":"1273","article-title":"Communication-efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Artificial intelligence and statistics. PMLR, 1273-1282.","journal-title":"PMLR"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN54540.2023.10191260"},{"key":"e_1_3_2_1_43_1","volume-title":"NIPS workshop on deep learning and unsupervised feature learning","volume":"2011","author":"Netzer Yuval","year":"2011","unstructured":"Yuval Netzer, Tao Wang, Adam Coates, Alessandro Bissacco, Baolin Wu, Andrew Y Ng, et al., 2011. Reading digits in natural images with unsupervised feature learning. In NIPS workshop on deep learning and unsupervised feature learning, Vol. 2011. Granada, 4."},{"key":"e_1_3_2_1_44_1","first-page":"1415","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Nguyen Thien Duc","year":"2022","unstructured":"Thien Duc Nguyen, Phillip Rieger, Roberta De Viti, Huili Chen, Bj\u00f6rn B Brandenburg, Hossein Yalame, Helen M\u00f6llering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, et al., 2022. {FLAME}: Taming backdoors in federated learning. In 31st USENIX Security Symposium (USENIX Security 22). 1415-1432."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v35i10.17118"},{"key":"e_1_3_2_1_46_1","volume-title":"International Conference on Artificial Intelligence and Statistics. PMLR, 7587-7624","author":"Panda Ashwinee","year":"2022","unstructured":"Ashwinee Panda, Saeed Mahloujifar, Arjun Nitin Bhagoji, Supriyo Chakraborty, and Prateek Mittal. 2022. Sparsefed: Mitigating model poisoning attacks in federated learning with sparsification. In International Conference on Artificial Intelligence and Statistics. PMLR, 7587-7624."},{"key":"e_1_3_2_1_47_1","volume-title":"Sageflow: Robust federated learning against both stragglers and adversaries. Advances in neural information processing systems","author":"Park Jungwuk","year":"2021","unstructured":"Jungwuk Park, Dong-Jun Han, Minseok Choi, and Jaekyun Moon. 2021. Sageflow: Robust federated learning against both stragglers and adversaries. Advances in neural information processing systems, Vol. 34 (2021), 840-851."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSP.2022.3153135"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i13.29385"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599898"},{"key":"e_1_3_2_1_51_1","volume-title":"Privacy inference attack and defense in centralized and federated learning: A comprehensive survey","author":"Rao Bosen","year":"2024","unstructured":"Bosen Rao, Jiale Zhang, Di Wu, Chengcheng Zhu, Xiaobing Sun, and Bing Chen. 2024. Privacy inference attack and defense in centralized and federated learning: A comprehensive survey. IEEE Transactions on Artificial Intelligence (2024)."},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2022.108588"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"crossref","unstructured":"Virat Shejwalkar and Amir Houmansadr. 2021. Manipulating the byzantine: Optimizing model poisoning attacks and defenses for federated learning. In NDSS.","DOI":"10.14722\/ndss.2021.24498"},{"key":"e_1_3_2_1_54_1","volume-title":"Matei Grama, Jonathan Passerat-Palmbach, Daniel Rueckert, and Amir Alansary.","author":"Sturluson Stef\u00e1n P\u00e1ll","year":"2021","unstructured":"Stef\u00e1n P\u00e1ll Sturluson, Samuel Trew, Luis Mu noz-Gonz\u00e1lez, Matei Grama, Jonathan Passerat-Palmbach, Daniel Rueckert, and Amir Alansary. 2021. Fedrad: Federated robust adaptive distillation. arXiv preprint arXiv:2112.01405 (2021)."},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v36i8.20819"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.neunet.2024.107016"},{"key":"e_1_3_2_1_57_1","volume-title":"Clustered Federated Learning with Inference Hash Codes Based Local Sensitive Hashing. In International Conference on Information Security and Cryptology. Springer, 73-90","author":"Tan Zhou","year":"2023","unstructured":"Zhou Tan, Ximeng Liu, Yan Che, and Yuyang Wang. 2023. Clustered Federated Learning with Inference Hash Codes Based Local Sensitive Hashing. In International Conference on Information Security and Cryptology. Springer, 73-90."},{"key":"e_1_3_2_1_58_1","volume-title":"Attack of the tails: Yes, you really can backdoor federated learning. Advances in neural information processing systems","author":"Wang Hongyi","year":"2020","unstructured":"Hongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma, Saurabh Agarwal, Jy-yong Sohn, Kangwook Lee, and Dimitris Papailiopoulos. 2020. Attack of the tails: Yes, you really can backdoor federated learning. Advances in neural information processing systems, Vol. 33 (2020), 16070-16084."},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-19778-9_23"},{"key":"e_1_3_2_1_60_1","volume-title":"Speech commands: A dataset for limited-vocabulary speech recognition. arXiv preprint arXiv:1804.03209","author":"Warden Pete","year":"2018","unstructured":"Pete Warden. 2018. Speech commands: A dataset for limited-vocabulary speech recognition. arXiv preprint arXiv:1804.03209 (2018)."},{"key":"e_1_3_2_1_61_1","volume-title":"Mitigating backdoor attacks in federated learning. arXiv preprint arXiv:2011.01767","author":"Wu Chen","year":"2020","unstructured":"Chen Wu, Xian Yang, Sencun Zhu, and Prasenjit Mitra. 2020. Mitigating backdoor attacks in federated learning. arXiv preprint arXiv:2011.01767 (2020)."},{"key":"e_1_3_2_1_62_1","volume-title":"Data-efficient backdoor attacks. arXiv preprint arXiv:2204.12281","author":"Xia Pengfei","year":"2022","unstructured":"Pengfei Xia, Ziqiang Li, Wei Zhang, and Bin Li. 2022. Data-efficient backdoor attacks. arXiv preprint arXiv:2204.12281 (2022)."},{"key":"e_1_3_2_1_63_1","volume-title":"Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms. arXiv preprint arXiv:1708.07747","author":"Xiao Han","year":"2017","unstructured":"Han Xiao, Kashif Rasul, and Roland Vollgraf. 2017. Fashion-mnist: a novel image dataset for benchmarking machine learning algorithms. arXiv preprint arXiv:1708.07747 (2017)."},{"key":"e_1_3_2_1_64_1","volume-title":"International Conference on Machine Learning. PMLR, 11372-11382","author":"Xie Chulin","year":"2021","unstructured":"Chulin Xie, Minghao Chen, Pin-Yu Chen, and Bo Li. 2021. Crfl: Certifiably robust federated learning against backdoor attacks. In International Conference on Machine Learning. PMLR, 11372-11382."},{"key":"e_1_3_2_1_65_1","volume-title":"International conference on learning representations.","author":"Xie Chulin","year":"2019","unstructured":"Chulin Xie, Keli Huang, Pin-Yu Chen, and Bo Li. 2019. Dba: Distributed backdoor attacks against federated learning. In International conference on learning representations."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1145\/3339474"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/3581783.3611781"},{"key":"e_1_3_2_1_68_1","volume-title":"International conference on machine learning. Pmlr, 5650-5659","author":"Yin Dong","year":"2018","unstructured":"Dong Yin, Yudong Chen, Ramchandran Kannan, and Peter Bartlett. 2018. Byzantine-robust distributed learning: Towards optimal statistical rates. In International conference on machine learning. Pmlr, 5650-5659."},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2022.3203233"},{"key":"e_1_3_2_1_70_1","volume-title":"Flpurifier: backdoor defense in federated learning via decoupled contrastive training","author":"Zhang Jiale","year":"2024","unstructured":"Jiale Zhang, Chengcheng Zhu, Xiaobing Sun, Chunpeng Ge, Bing Chen, Willy Susilo, and Shui Yu. 2024. Flpurifier: backdoor defense in federated learning via decoupled contrastive training. IEEE Transactions on Information Forensics and Security (2024)."},{"key":"e_1_3_2_1_71_1","volume-title":"Flip: A provable defense framework for backdoor mitigation in federated learning. arXiv preprint arXiv:2210.12873","author":"Zhang Kaiyuan","year":"2022","unstructured":"Kaiyuan Zhang, Guanhong Tao, Qiuling Xu, Siyuan Cheng, Shengwei An, Yingqi Liu, Shiwei Feng, Guangyu Shen, Pin-Yu Chen, Shiqing Ma, et al., 2022c. Flip: A provable defense framework for backdoor mitigation in federated learning. arXiv preprint arXiv:2210.12873 (2022)."},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539231"},{"key":"e_1_3_2_1_73_1","volume-title":"International Conference on Machine Learning. PMLR, 26429-26446","author":"Zhang Zhengming","year":"2022","unstructured":"Zhengming Zhang, Ashwinee Panda, Linyue Song, Yaoqing Yang, Michael Mahoney, Prateek Mittal, Ramchandran Kannan, and Joseph Gonzalez. 2022b. Neurotoxin: Durable backdoors in federated learning. In International Conference on Machine Learning. PMLR, 26429-26446."},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01478"},{"key":"e_1_3_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOMWKSHPS54753.2022.9798217"},{"key":"e_1_3_2_1_76_1","volume-title":"Imperceptible backdoor attack: From input space to feature representation. arXiv preprint arXiv:2205.03190","author":"Zhong Nan","year":"2022","unstructured":"Nan Zhong, Zhenxing Qian, and Xinpeng Zhang. 2022. Imperceptible backdoor attack: From input space to feature representation. arXiv preprint arXiv:2205.03190 (2022)."},{"key":"e_1_3_2_1_77_1","volume-title":"BDPFL: Backdoor Defense for Personalized Federated Learning via Explainable Distillation. arXiv preprint arXiv:2503.06554","author":"Zhu Chengcheng","year":"2025","unstructured":"Chengcheng Zhu, Jiale Zhang, Di Wu, and Guodong Long. 2025. BDPFL: Backdoor Defense for Personalized Federated Learning via Explainable Distillation. arXiv preprint arXiv:2503.06554 (2025)."}],"event":{"name":"MM '25: The 33rd ACM International Conference on Multimedia","location":"Dublin Ireland","acronym":"MM '25","sponsor":["SIGMM ACM Special Interest Group on Multimedia"]},"container-title":["Proceedings of the 33rd ACM International Conference on Multimedia"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3746027.3755742","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,10]],"date-time":"2025-12-10T03:57:51Z","timestamp":1765339071000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3746027.3755742"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,27]]},"references-count":77,"alternative-id":["10.1145\/3746027.3755742","10.1145\/3746027"],"URL":"https:\/\/doi.org\/10.1145\/3746027.3755742","relation":{},"subject":[],"published":{"date-parts":[[2025,10,27]]},"assertion":[{"value":"2025-10-27","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}