{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T08:13:32Z","timestamp":1783930412485,"version":"3.55.0"},"reference-count":40,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T00:00:00Z","timestamp":1783900800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T00:00:00Z","timestamp":1783900800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"Central Government Guiding Local Scientific and Technological Development Fund of Shanxi Province","award":["YDZJSX2025D029"],"award-info":[{"award-number":["YDZJSX2025D029"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n                  <jats:p>\n                    Backdoor attacks pose a serious threat to Internet-of-Things (IoT) federated learning. In IoT deployments, pronounced non-independent and identically distributed (non-IID) data heterogeneity causes benign client updates to exhibit substantial variability across devices. Meanwhile, the physical exposure of IoT devices increases the risk of large-scale compromise and elevated malicious participation. Such variability allows poisoned updates to blend into natural fluctuations, rendering many robust aggregation and detection-based defenses unreliable. We propose\n                    <jats:italic>FedDSG<\/jats:italic>\n                    , a server-side defense that combines a semantic bias filter and a geometric direction constraint to counter backdoor manipulation. FedDSG first extracts a novel scale-invariant semantic cue from the last-layer bias of client updates to identify abnormal target-class reinforcement, staying effective even when benign bias patterns differ substantially across clients. The remaining updates are then constrained using a reference derived from a small trusted anchor set, limiting adversarial drift. This sequential design links semantic cues with geometric structure, where the former removes clearly suspicious updates and the latter stabilizes the residual ones, preventing misdetection-induced drift amplification while avoiding distortion of benign updates. The method does not alter client behavior or communication and adds minimal server-side overhead. Extensive experiments on MNIST, Fashion-MNIST, CIFAR-10, and SVHN under non-IID distributions with high malicious participation demonstrate the robustness of FedDSG. It reduces the attack success rate to 0.003, 0.006, 0.007, and 0.091, respectively, with only marginal accuracy loss and consistently achieves the highest Overall Performance Score (OPS), reflecting a superior trade-off between robustness and accuracy. Code and data availability information is provided in the\n                    <jats:italic>Availability of data and materials<\/jats:italic>\n                    section.\n                  <\/jats:p>","DOI":"10.1186\/s42400-026-00625-z","type":"journal-article","created":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T08:03:17Z","timestamp":1783929797000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Feddsg: backdoor defense via semantic filter and geometric constraint in federated learning"],"prefix":"10.1186","volume":"9","author":[{"given":"Jiabao","family":"Zhang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2773-3429","authenticated-orcid":false,"given":"Jianhua","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuhong","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhuangzhuang","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhihui","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dan","family":"Yu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yongle","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,13]]},"reference":[{"issue":"11","key":"625_CR1","doi-asserted-by":"publisher","first-page":"19694","DOI":"10.1109\/JIOT.2024.3368754","volume":"11","author":"S Alharbi","year":"2024","unstructured":"Alharbi S, Guo Y, Yu W (2024) Collusive backdoor attacks in federated learning frameworks for iot systems. IEEE Internet Things J 11(11):19694\u201319707. https:\/\/doi.org\/10.1109\/JIOT.2024.3368754","journal-title":"IEEE Internet Things J"},{"issue":"22","key":"625_CR2","doi-asserted-by":"publisher","first-page":"47163","DOI":"10.1109\/JIOT.2025.3600617","volume":"12","author":"O Ben Atia","year":"2025","unstructured":"Ben Atia O, Al Samara M, Bennis I, Gaber J, Abouaissa A, Lorenz P (2025) Securing federated learning in iot: a survey of attacks, defenses, and frameworks. IEEE Internet Things J 12(22):47163\u201347190. https:\/\/doi.org\/10.1109\/JIOT.2025.3600617","journal-title":"IEEE Internet Things J"},{"key":"625_CR3","unstructured":"Bhagoji AN, Chakraborty S, Mittal P, Calo S (2019) Analyzing federated learning through an adversarial lens. In: Proceedings of the 36th international conference on machine learning (ICML), pp 634\u2013643"},{"key":"625_CR4","unstructured":"Biggio B, Nelson B, Laskov P (2012) Poisoning Attacks Against Support Vector Machines. In: Proceedings of the 29th international conference on machine learning (ICML), pp 1467\u20131474"},{"key":"625_CR5","first-page":"119","volume":"30","author":"P Blanchard","year":"2017","unstructured":"Blanchard P, El Mhamdi EM, Guerraoui R, Stainer J (2017) Machine learning with adversaries: byzantine tolerant gradient descent. Adv Neural Inf Process Syst (NeurIPS) 30:119\u2013129","journal-title":"Adv Neural Inf Process Syst (NeurIPS)"},{"key":"625_CR6","doi-asserted-by":"publisher","unstructured":"Cao X, Fang M, Liu J, Gong NZ (2021) FLTrust: byzantine-robust federated learning via trust bootstrapping. In: Network and distributed system security symposium (NDSS). https:\/\/doi.org\/10.14722\/ndss.2021.24434","DOI":"10.14722\/ndss.2021.24434"},{"key":"625_CR7","doi-asserted-by":"publisher","unstructured":"Ding B, Yang P, Huang SJ (2025) FedDLAD: a federated learning dual-layer anomaly detection framework for enhancing resilience against backdoor attacks. In: Proceedings of the 34th international joint conference on artificial intelligence (IJCAI), pp 5021\u20135029. https:\/\/doi.org\/10.24963\/ijcai.2025\/559","DOI":"10.24963\/ijcai.2025\/559"},{"key":"625_CR8","unstructured":"El Mhamdi EM, Guerraoui R, Rouault S (2018) The hidden vulnerability of distributed learning in byzantium. In: Proceedings of the 35th international conference on machine learning (ICML), pp 3521\u20133530"},{"key":"625_CR9","doi-asserted-by":"crossref","unstructured":"Espinoza Castellon F, Singh D, Mayoue A, Gouy-Pailler C (2023) FUBA: federated uncovering of backdoor attacks for heterogeneous data. In: 2023 IEEE international conference on trust, privacy and security in intelligent systems and applications (TPS-ISA), pp 55\u201363","DOI":"10.1109\/TPS-ISA58951.2023.00017"},{"key":"625_CR10","unstructured":"Fang M, Cao X, Jia J, Gong NZ (2020) Local model poisoning attacks to byzantine-robust federated learning. In: 29th USENIX security symposium (USENIX Security 20), pp 1605\u20131622"},{"key":"625_CR11","unstructured":"Fan M, Hu Z, Wang F, Chen C (2025) Bad-pfl: exploring backdoor attacks against personalized federated learning. arXiv preprint arXiv:2501.12736"},{"key":"625_CR12","unstructured":"Fung C, Yoon CJM, Beschastnikh I (2020) The limitations of federated learning in sybil settings. In: Proceedings of the 23rd international symposium on research in attacks, intrusions and defenses (RAID), pp 301\u2013316"},{"issue":"11","key":"625_CR13","doi-asserted-by":"publisher","first-page":"8229","DOI":"10.1109\/JIOT.2022.3150363","volume":"9","author":"B Ghimire","year":"2022","unstructured":"Ghimire B, Rawat DB (2022) Recent advances on federated learning for cybersecurity and cybersecurity for federated learning for internet of things. IEEE Internet Things J 9(11):8229\u20138249. https:\/\/doi.org\/10.1109\/JIOT.2022.3150363","journal-title":"IEEE Internet Things J"},{"key":"625_CR14","unstructured":"Gu T, Dolan-Gavitt B, Garg S (2017) Badnets: identifying vulnerabilities in the machine learning model supply chain. arXiv preprint arXiv:1708.06733"},{"issue":"4","key":"625_CR15","doi-asserted-by":"publisher","first-page":"7116","DOI":"10.1109\/JIOT.2023.3314748","volume":"11","author":"G Hu","year":"2023","unstructured":"Hu G, Li H, Fan W, Zhang Y (2023) Efficient byzantine-robust and privacy-preserving federated learning on compressive domain. IEEE Internet Things J 11(4):7116\u20137127. https:\/\/doi.org\/10.1109\/JIOT.2023.3314748","journal-title":"IEEE Internet Things J"},{"key":"625_CR16","unstructured":"Krizhevsky A, Hinton G (2009) Learning multiple layers of features from tiny images. University of Toronto Tech Report"},{"issue":"11","key":"625_CR17","doi-asserted-by":"publisher","first-page":"2278","DOI":"10.1109\/5.726791","volume":"86","author":"Y LeCun","year":"1998","unstructured":"LeCun Y, Bottou L, Bengio Y, Haffner P (1998) Gradient-based learning applied to document recognition. Proc IEEE 86(11):2278\u20132324. https:\/\/doi.org\/10.1109\/5.726791","journal-title":"Proc IEEE"},{"key":"625_CR18","doi-asserted-by":"crossref","unstructured":"Li Y, Zhao Y, Zhu C, Zhang J (2025) Infighting in the dark: Multi-label backdoor attack in federated learning. In: Proc. IEEE\/CVF Conf. Computer Vision and Pattern Recognition (CVPR). pp 25770\u201325779","DOI":"10.1109\/CVPR52734.2025.02400"},{"issue":"12","key":"625_CR19","doi-asserted-by":"publisher","first-page":"10385","DOI":"10.1109\/JIOT.2023.3237806","volume":"10","author":"T Liu","year":"2023","unstructured":"Liu T, Hu X, Shu T (2023) Facilitating early-stage backdoor attacks in federated learning with whole population distribution inference. IEEE Internet Things J 10(12):10385\u201310399. https:\/\/doi.org\/10.1109\/JIOT.2023.3237806","journal-title":"IEEE Internet Things J"},{"issue":"9","key":"625_CR20","doi-asserted-by":"publisher","first-page":"15075","DOI":"10.1109\/JIOT.2023.3345075","volume":"11","author":"S Liu","year":"2024","unstructured":"Liu S, Li Z, Sun Q, Chen L, Zhang X, Duan L (2024) FLOW: a robust federated learning framework to defend against model poisoning attacks in iot. IEEE Internet Things J 11(9):15075\u201315086. https:\/\/doi.org\/10.1109\/JIOT.2023.3345075","journal-title":"IEEE Internet Things J"},{"key":"625_CR21","unstructured":"McMahan B, Moore E, Ramage D, Hampson S, Agueray Arcas B (2017) Communication-efficient learning of deep networks from decentralized data. In: Proceedings of the 20th international conference on artificial intelligence and statistics (AISTATS), pp 1273\u20131282"},{"issue":"4","key":"625_CR22","doi-asserted-by":"publisher","first-page":"2545","DOI":"10.1109\/JIOT.2021.3077803","volume":"9","author":"V Mothukuri","year":"2022","unstructured":"Mothukuri V, Khare P, Parizi RM, Pouriyeh S, Dehghantanha A, Srivastava G (2022) Federated-learning-based anomaly detection for iot security attacks. IEEE Internet Things J 9(4):2545\u20132554. https:\/\/doi.org\/10.1109\/JIOT.2021.3077803","journal-title":"IEEE Internet Things J"},{"key":"625_CR23","unstructured":"Netzer Y, Wang T, Coates A, Bissacco A, Wu B, Ng AY (2011) Reading digits in natural images with unsupervised feature learning. In: NIPS workshop on deep learning and unsupervised feature learning"},{"key":"625_CR24","unstructured":"Nguyen TD, Rieger P, Chen H, Miettinen M, Sadeghi AR (2022) FLAME: taming backdoors in federated learning. In: 31st USENIX security symposium (USENIX Security 22). pp 1415\u20131432"},{"key":"625_CR25","unstructured":"Nguyen T, Nguyen DT, Doan KD, Wong KS (2024) Non-cooperative backdoor attacks in federated learning: A new threat landscape. arXiv preprint arXiv:2407.07917"},{"issue":"23","key":"625_CR26","doi-asserted-by":"publisher","first-page":"37718","DOI":"10.1109\/JIOT.2024.3438150","volume":"11","author":"Z Pan","year":"2024","unstructured":"Pan Z, Ying Z, Wang Y, Zhang C, Li C, Zhu L (2024) One-shot backdoor removal for federated learning. IEEE Internet Things J 11(23):37718\u201337730. https:\/\/doi.org\/10.1109\/JIOT.2024.3438150","journal-title":"IEEE Internet Things J"},{"key":"625_CR27","unstructured":"Szela\u0327g JK, Chin JJ, Yip SC (2025) Adaptive adversaries in byzantine-robust federated learning: a survey. Cryptology ePrint Archive, Paper 2025\/510. https:\/\/eprint.iacr.org\/2025\/510"},{"issue":"6","key":"625_CR28","doi-asserted-by":"publisher","first-page":"10115","DOI":"10.1109\/JIOT.2023.3325634","volume":"11","author":"Y Wang","year":"2024","unstructured":"Wang Y, Zhai DH, Han D, Guan Y, Xia Y (2024) MITDBA: mitigating dynamic backdoor attacks in federated learning for iot applications. IEEE Internet Things J 11(6):10115\u201310132. https:\/\/doi.org\/10.1109\/JIOT.2023.3325634","journal-title":"IEEE Internet Things J"},{"issue":"24","key":"625_CR29","doi-asserted-by":"publisher","first-page":"39276","DOI":"10.1109\/JIOT.2024.3406992","volume":"11","author":"H Wang","year":"2024","unstructured":"Wang H, Mu X, Wang D, Xu Q, Li K (2024) Defending against data and model backdoor attacks in federated learning. IEEE Internet Things J 11(24):39276\u201339294. https:\/\/doi.org\/10.1109\/JIOT.2024.3406992","journal-title":"IEEE Internet Things J"},{"key":"625_CR30","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2025.130415","volume":"300","author":"H Wang","year":"2026","unstructured":"Wang H, Wang S, Wang L, Wang R (2026) FLAB: exploring anomaly bias in backdoor attacks. Expert Syst Appl 300:130415. https:\/\/doi.org\/10.1016\/j.eswa.2025.130415","journal-title":"Expert Syst Appl"},{"key":"625_CR31","unstructured":"Wang H, Sreenivasan K, Rajput S, Vishwakarma H, Agarwal S, Sohn JY, Lee K, Papailiopoulos D (2020) Attack of the tails: yes, you really can backdoor federated learning. In: Advances in neural information processing systems (NeurIPS), vol. 33"},{"key":"625_CR32","unstructured":"Xiao H, Rasul K, Vollgraf R (2017) Fashion-MNIST: a novel image dataset for benchmarking machine learning algorithms. arXiv preprint arXiv:1708.07747"},{"key":"625_CR33","unstructured":"Xie C, Huang K, Chen PY, Li B (2020) DBA: distributed backdoor attacks against federated learning. In: International conference on learning representations (ICLR)"},{"issue":"9","key":"625_CR34","doi-asserted-by":"publisher","first-page":"16289","DOI":"10.1109\/JIOT.2024.3351371","volume":"11","author":"H Yang","year":"2024","unstructured":"Yang H, Gu D, He J (2024) A robust and efficient federated learning algorithm against adaptive model poisoning attacks. IEEE Internet Things J 11(9):16289\u201316302. https:\/\/doi.org\/10.1109\/JIOT.2024.3351371","journal-title":"IEEE Internet Things J"},{"key":"625_CR35","doi-asserted-by":"crossref","unstructured":"Yang Q, Yan P, Wu X, Zhang J, Song T, Hua Y, Wang H, Wang L, Guan H (2025) Stealthy backdoor attack in federated learning via adaptive layer-wise gradient alignment. In: Proc. IEEE\/CVF Int. Conf. Computer Vision (ICCV) pp 29163\u201329172","DOI":"10.1109\/ICCV51701.2025.02708"},{"key":"625_CR36","unstructured":"Yin D, Chen Y, Kannan R, Bartlett P (2018) Byzantine-robust distributed learning: towards optimal statistical rates. In: Proceedings of the 35th international conference on machine learning (ICML), pp 5650\u20135659"},{"key":"625_CR37","doi-asserted-by":"publisher","first-page":"365","DOI":"10.1109\/TIFS.2022.3221899","volume":"18","author":"Z Zhang","year":"2023","unstructured":"Zhang Z, Wu L, Ma C, Li J, Wang J, Wang Q, Yu S (2023) LSFL: a lightweight and secure federated learning scheme for edge computing. IEEE Trans Inf Forensics Secur 18:365\u2013379. https:\/\/doi.org\/10.1109\/TIFS.2022.3221899","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"6","key":"625_CR38","doi-asserted-by":"publisher","first-page":"848","DOI":"10.1109\/TSUSC.2024.3379440","volume":"9","author":"Z Zhang","year":"2024","unstructured":"Zhang Z, Wu L, He D, Li J, Lu N, Wei X (2024) Using third-party auditor to help federated learning: an efficient byzantine-robust federated learning. IEEE Trans Sustainable Comput 9(6):848\u2013861. https:\/\/doi.org\/10.1109\/TSUSC.2024.3379440","journal-title":"IEEE Trans Sustainable Comput"},{"issue":"12","key":"625_CR39","doi-asserted-by":"publisher","first-page":"13615","DOI":"10.1109\/TMC.2025.3590799","volume":"24","author":"Z Zhang","year":"2025","unstructured":"Zhang Z, Wu L, Wang Z, Hu J, Ma C, Liu Q (2025) Cost-efficient and secure federated learning for edge computing. IEEE Trans Mob Comput 24(12):13615\u201313632. https:\/\/doi.org\/10.1109\/TMC.2025.3590799","journal-title":"IEEE Trans Mob Comput"},{"issue":"5","key":"625_CR40","doi-asserted-by":"publisher","first-page":"3528","DOI":"10.1109\/TII.2025.3528569","volume":"21","author":"Z Zhang","year":"2025","unstructured":"Zhang Z, Wu L, Jin J, Wang E, Liu B, Han QL (2025) Secure federated learning for cloud-fog automation: vulnerabilities, challenges, solutions, and future directions. IEEE Trans Industr Inf 21(5):3528\u20133540. https:\/\/doi.org\/10.1109\/TII.2025.3528569","journal-title":"IEEE Trans Industr Inf"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-026-00625-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-026-00625-z","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-026-00625-z.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,13]],"date-time":"2026-07-13T08:03:24Z","timestamp":1783929804000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1186\/s42400-026-00625-z"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,13]]},"references-count":40,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2026,12]]}},"alternative-id":["625"],"URL":"https:\/\/doi.org\/10.1186\/s42400-026-00625-z","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,13]]},"assertion":[{"value":"25 March 2026","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 July 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 July 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interest"}}],"article-number":"189"}}