{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T16:03:14Z","timestamp":1780588994837,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":62,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1145\/3779208.3785390","type":"proceedings-article","created":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:21:58Z","timestamp":1780586518000},"page":"1108-1124","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["C\n                    <scp>lie<\/scp>\n                    ND: Client-Side Neuron-Level Detection against Poisoning Attacks on Cross-Silo Federated Learning"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5550-5845","authenticated-orcid":false,"given":"Mengyao","family":"Ma","sequence":"first","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6438-5224","authenticated-orcid":false,"given":"Shuofeng","family":"Liu","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5984-7981","authenticated-orcid":false,"given":"Viet","family":"Vo","sequence":"additional","affiliation":[{"name":"Swinburne University of Technology, Melbourne, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1365-3911","authenticated-orcid":false,"given":"Minghong","family":"Fang","sequence":"additional","affiliation":[{"name":"University of Louisville, Kentucky, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3289-6599","authenticated-orcid":false,"given":"Surya","family":"Nepal","sequence":"additional","affiliation":[{"name":"CSIRO's Data61, Sydney, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6390-9890","authenticated-orcid":false,"given":"Guangdong","family":"Bai","sequence":"additional","affiliation":[{"name":"The University of Queensland, Brisbane, Australia and City University of Hong Kong, Kowloon Tong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,4]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2025. TEXAS hospital dataset. https:\/\/healthdata.dshs.texas.gov\/dashboard\/hospitals\/texas-hospital-data."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS51616.2021.00086"},{"key":"e_1_3_2_1_3_1","volume-title":"Proceedings of the International Conference on Artificial Intelligence and Statistics (AISTATS). PMLR.","author":"Bagdasaryan Eugene","year":"2020","unstructured":"Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. In Proceedings of the International Conference on Artificial Intelligence and Statistics (AISTATS). PMLR."},{"key":"e_1_3_2_1_4_1","volume-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS)","volume":"32","author":"Baruch Gilad","year":"2019","unstructured":"Gilad Baruch, Moran Baruch, and Yoav Goldberg. 2019. A little is enough: Circumventing defenses for distributed learning. In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS), Vol. 32."},{"key":"e_1_3_2_1_5_1","volume-title":"Proceedings of the International Conference on Machine Learning (ICML). PMLR, 634\u2013643","author":"Bhagoji Arjun Nitin","year":"2019","unstructured":"Arjun Nitin Bhagoji, Supriyo Chakraborty, Prateek Mittal, and Seraphin Calo. 2019. Analyzing federated learning through an adversarial lens. In Proceedings of the International Conference on Machine Learning (ICML). PMLR, 634\u2013643."},{"key":"e_1_3_2_1_6_1","volume-title":"Proceedings of the 29th International Coference on International Conference on Machine Learning (ICML). 1467\u20131474","author":"Biggio Battista","year":"2012","unstructured":"Battista Biggio, Blaine Nelson, and Pavel Laskov. 2012. Poisoning attacks against support vector machines. In Proceedings of the 29th International Coference on International Conference on Machine Learning (ICML). 1467\u20131474."},{"key":"e_1_3_2_1_7_1","volume-title":"Proceedings of the 31st International Conference on Neural Information Processing Systems (NeurIPS).","author":"Blanchard Peva","year":"2017","unstructured":"Peva Blanchard, El Mahdi El Mhamdi, Rachid Guerraoui, and Julien Stainer. 2017. Machine learning with adversaries: Byzantine tolerant gradient descent. In Proceedings of the 31st International Conference on Neural Information Processing Systems (NeurIPS)."},{"key":"e_1_3_2_1_8_1","volume-title":"Proceedings of the 2nd SysML Conference.","author":"Bonawitz Keith","year":"2019","unstructured":"Keith Bonawitz, Hubert Eichner, Wolfgang Grieskamp, Dzmitry Huba, Alex Ingerman, Vladimir Ivanov, Chlo\u00e9 Kiddon, Jakub Kone\u010dn\u00fd, Stefano Mazzocchi, H Brendan McMahan, Tim Van Overveldt, Dimitrios Petrou, Daniel Ramage, and Jason Roselander. 2019. Towards federated learning at scale: System design. In Proceedings of the 2nd SysML Conference."},{"key":"e_1_3_2_1_9_1","volume-title":"Convex optimization","author":"Boyd Stephen P","unstructured":"Stephen P Boyd and Lieven Vandenberghe. 2004. Convex optimization. Cambridge university press."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24434"},{"key":"e_1_3_2_1_11_1","volume-title":"Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526","author":"Chen Xinyun","year":"2017","unstructured":"Xinyun Chen, Chang Liu, Bo Li, Kimberly Lu, and Dawn Song. 2017. Targeted backdoor attacks on deep learning systems using data poisoning. arXiv preprint arXiv:1712.05526 (2017)."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00011"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.2211477"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.5555\/3489212.3489304"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.241796"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690292"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.24620"},{"key":"e_1_3_2_1_19_1","volume-title":"Shi-han Wang, Jason Martin, Parsa Mirhaji, Prashant Shah, and Spyridon Bakas.","author":"Foley Patrick","year":"2022","unstructured":"Patrick Foley, Micah J Sheller, Brandon Edwards, Sarthak Pati, Walter Riviera, Mansi Sharma, Prakash Narayana Moorthy, Shi-han Wang, Jason Martin, Parsa Mirhaji, Prashant Shah, and Spyridon Bakas. 2022. OpenFL: the open federated learning library. Physics in Medicine & Biology (2022)."},{"key":"e_1_3_2_1_20_1","volume-title":"Proceedings of the 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID). 301\u2013316","author":"Fung Clement","year":"2020","unstructured":"Clement Fung, Chris JM Yoon, and Ivan Beschastnikh. 2020. The limitations of federated learning in sybil settings. In Proceedings of the 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID). 301\u2013316."},{"key":"e_1_3_2_1_21_1","volume-title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733","author":"Gu Tianyu","year":"2017","unstructured":"Tianyu Gu, Brendan Dolan-Gavitt, and Siddharth Garg. 2017. Badnets: Identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733 (2017)."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1080\/01621459.1963.10500830"},{"key":"e_1_3_2_1_23_1","volume-title":"Cross-silo federated learning: Challenges and opportunities. arXiv preprint arXiv:2206.12949","author":"Huang Chao","year":"2022","unstructured":"Chao Huang, Jianwei Huang, and Xin Liu. 2022. Cross-silo federated learning: Challenges and opportunities. arXiv preprint arXiv:2206.12949 (2022)."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00057"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00113"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00141"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1561\/2200000083"},{"key":"e_1_3_2_1_28_1","volume-title":"Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security (CCS). 1526\u20131540","author":"Krau\u00df Torsten","year":"2023","unstructured":"Torsten Krau\u00df and Alexandra Dmitrienko. 2023. Mesas: Poisoning defense for federated learning resilient against adaptive attackers. In Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security (CCS). 1526\u20131540."},{"key":"e_1_3_2_1_29_1","unstructured":"Alex Krizhevsky Geoffrey Hinton et al. 2009. Learning multiple layers of features from tiny images. (2009)."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v33i01.33011544"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00242"},{"key":"e_1_3_2_1_32_1","volume-title":"Proceedings of the 33rd USENIX Security Symposium (USENIX Security). 6507\u20136524","author":"Liu Shuofeng","year":"2024","unstructured":"Shuofeng Liu, Zihan Wang, Minhui Xue, Long Wang, Yuanchao Zhang, and Guangdong Bai. 2024. Being transparent is merely the beginning: enforcing purpose limitation with polynomial approximation. In Proceedings of the 33rd USENIX Security Symposium (USENIX Security). 6507\u20136524."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3627673.3679850"},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/3579856.3590334"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-99-7584-6_7"},{"key":"e_1_3_2_1_36_1","volume-title":"Proceedings of the Artificial Intelligence and Statistics (AISTATS). PMLR.","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep networks from decentralized data. In Proceedings of the Artificial Intelligence and Statistics (AISTATS). PMLR."},{"key":"e_1_3_2_1_37_1","volume-title":"Proceedings of the 31st USENIX Security Symposium (USENIX Security). 1415\u20131432","author":"Nguyen Thien Duc","year":"2022","unstructured":"Thien Duc Nguyen, Phillip Rieger, Roberta De Viti, Huili Chen, Bj\u00f6rn B Brandenburg, Hossein Yalame, Helen M\u00f6llering, Hossein Fereidooni, Samuel Marchal, Markus Miettinen, et al. 2022. {FLAME}: Taming backdoors in federated learning. In Proceedings of the 31st USENIX Security Symposium (USENIX Security). 1415\u20131432."},{"key":"e_1_3_2_1_38_1","first-page":"5315","article-title":"Flamby: Datasets and benchmarks for cross-silo federated learning in realistic healthcare settings","volume":"35","author":"du Terrail Jean Ogier","year":"2022","unstructured":"Jean Ogier du Terrail, Samy-Safwan Ayed, Edwige Cyffers, Felix Grimberg, Chaoyang He, Regis Loeb, Paul Mangold, Tanguy Marchand, Othmane Marfoq, Erum Mushtaq, et al. 2022. Flamby: Datasets and benchmarks for cross-silo federated learning in realistic healthcare settings. Proceedings of the Advances in Neural Information Processing Systems (NeurIPS) 35 (2022), 5315\u20135334.","journal-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS)"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1145\/3580305.3599346"},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1080\/00031305.1994.10476030"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1057\/jt.2009.5"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23233"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00271"},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1213\/ANE.0000000000002864"},{"key":"e_1_3_2_1_45_1","first-page":"19655","article-title":"Hydra: Pruning adversarially robust neural networks","volume":"33","author":"Sehwag Vikash","year":"2020","unstructured":"Vikash Sehwag, Shiqi Wang, Prateek Mittal, and Suman Jana. 2020. Hydra: Pruning adversarially robust neural networks. In Proceedings of the Advances in Neural Information Processing Systems (NeurIPS), Vol. 33. 19655\u201319666.","journal-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurIPS)"},{"key":"e_1_3_2_1_46_1","volume-title":"Proceedings of the 30th USENIX Security Symposium (USENIX Security). 1487\u20131504","author":"Severi Giorgio","year":"2021","unstructured":"Giorgio Severi, Jim Meyer, Scott Coull, and Alina Oprea. 2021. {Explanation-Guided} backdoor poisoning attacks against malware classifiers. In Proceedings of the 30th USENIX Security Symposium (USENIX Security). 1487\u20131504."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24498"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833647"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.41"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/72.788640"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP61157.2025.00163"},{"key":"e_1_3_2_1_52_1","first-page":"16070","article-title":"Attack of the tails: Yes, you really can backdoor federated learning","volume":"33","author":"Wang Hongyi","year":"2020","unstructured":"Hongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma, Saurabh Agarwal, Jy-yong Sohn, Kangwook Lee, and Dimitris Papailiopoulos. 2020. Attack of the tails: Yes, you really can backdoor federated learning. In Proceedings of the Advances in Neural Information Processing Systems (NeurlPS), Vol. 33. 16070\u201316084.","journal-title":"Proceedings of the Advances in Neural Information Processing Systems (NeurlPS)"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00233"},{"key":"e_1_3_2_1_54_1","volume-title":"Risky-Free: Adaptable Model Usage Control. arXiv preprint arXiv:2511.18772","author":"Wang Zihan","year":"2025","unstructured":"Zihan Wang, Zhongkui Ma, Xinguo Feng, Chuan Yan, Dongge Liu, Ruoxi Sun, Derui Wang, Minhui Xue, and Guangdong Bai. 2025. Re-Key-Free, Risky-Free: Adaptable Model Usage Control. arXiv preprint arXiv:2511.18772 (2025)."},{"key":"e_1_3_2_1_55_1","volume-title":"Proceedings of the International Conference on Learning Representations (ICLR).","author":"Xie Chulin","year":"2019","unstructured":"Chulin Xie, Keli Huang, Pin-Yu Chen, and Bo Li. 2019. Dba: Distributed backdoor attacks against federated learning. In Proceedings of the International Conference on Learning Representations (ICLR)."},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354209"},{"key":"e_1_3_2_1_57_1","volume-title":"Proceedings of the International Conference on Machine Learning(ICML). PMLR.","author":"Yin Dong","year":"2018","unstructured":"Dong Yin, Yudong Chen, Ramchandran Kannan, and Peter Bartlett. 2018. Byzantine-robust distributed learning: Towards optimal statistical rates. In Proceedings of the International Conference on Machine Learning(ICML). PMLR."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00958"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00026"},{"key":"e_1_3_2_1_60_1","volume-title":"Proceedings of the 2020 USENIX Annual Technical Conference (USENIX ATC). 493\u2013506","author":"Zhang Chengliang","year":"2020","unstructured":"Chengliang Zhang, Suyi Li, Junzhe Xia, Wei Wang, Feng Yan, and Yang Liu. 2020. {BatchCrypt}: Efficient homomorphic encryption for {Cross-Silo} federated learning. In Proceedings of the 2020 USENIX Annual Technical Conference (USENIX ATC). 493\u2013506."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/3534678.3539231"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.2986205"}],"event":{"name":"ASIA CCS '26: ACM Asia Conference on Computer and Communications Security","location":"Bangalore India","acronym":"ASIA CCS '26","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3779208.3785390","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,4]],"date-time":"2026-06-04T15:37:09Z","timestamp":1780587429000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3779208.3785390"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":62,"alternative-id":["10.1145\/3779208.3785390","10.1145\/3779208"],"URL":"https:\/\/doi.org\/10.1145\/3779208.3785390","relation":{},"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"2026-06-04","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}