{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T15:45:26Z","timestamp":1784303126965,"version":"3.55.0"},"reference-count":24,"publisher":"MDPI AG","issue":"2","license":[{"start":{"date-parts":[[2024,2,14]],"date-time":"2024-02-14T00:00:00Z","timestamp":1707868800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2022YFB2701400"],"award-info":[{"award-number":["2022YFB2701400"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["62272124"],"award-info":[{"award-number":["62272124"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["62361010"],"award-info":[{"award-number":["62361010"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["[2020]5017"],"award-info":[{"award-number":["[2020]5017"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["[2020]61"],"award-info":[{"award-number":["[2020]61"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["[2019]56"],"award-info":[{"award-number":["[2019]56"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["GZUAMT2021KF[01]"],"award-info":[{"award-number":["GZUAMT2021KF[01]"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]},{"name":"National Natural Science Foundation of China","award":["2022YFB2701400"],"award-info":[{"award-number":["2022YFB2701400"]}]},{"name":"National Natural Science Foundation of China","award":["62272124"],"award-info":[{"award-number":["62272124"]}]},{"name":"National Natural Science Foundation of China","award":["62361010"],"award-info":[{"award-number":["62361010"]}]},{"name":"National Natural Science Foundation of China","award":["[2020]5017"],"award-info":[{"award-number":["[2020]5017"]}]},{"name":"National Natural Science Foundation of China","award":["[2020]61"],"award-info":[{"award-number":["[2020]61"]}]},{"name":"National Natural Science Foundation of China","award":["[2019]56"],"award-info":[{"award-number":["[2019]56"]}]},{"name":"National Natural Science Foundation of China","award":["GZUAMT2021KF[01]"],"award-info":[{"award-number":["GZUAMT2021KF[01]"]}]},{"name":"Guizhou Science Contract Plat Talent","award":["2022YFB2701400"],"award-info":[{"award-number":["2022YFB2701400"]}]},{"name":"Guizhou Science Contract Plat Talent","award":["62272124"],"award-info":[{"award-number":["62272124"]}]},{"name":"Guizhou Science Contract Plat Talent","award":["62361010"],"award-info":[{"award-number":["62361010"]}]},{"name":"Guizhou Science Contract Plat Talent","award":["[2020]5017"],"award-info":[{"award-number":["[2020]5017"]}]},{"name":"Guizhou Science Contract Plat Talent","award":["[2020]61"],"award-info":[{"award-number":["[2020]61"]}]},{"name":"Guizhou Science Contract Plat Talent","award":["[2019]56"],"award-info":[{"award-number":["[2019]56"]}]},{"name":"Guizhou Science Contract Plat Talent","award":["GZUAMT2021KF[01]"],"award-info":[{"award-number":["GZUAMT2021KF[01]"]}]},{"name":"Research Project of Guizhou University for Talent Introduction","award":["2022YFB2701400"],"award-info":[{"award-number":["2022YFB2701400"]}]},{"name":"Research Project of Guizhou University for Talent Introduction","award":["62272124"],"award-info":[{"award-number":["62272124"]}]},{"name":"Research Project of Guizhou University for Talent Introduction","award":["62361010"],"award-info":[{"award-number":["62361010"]}]},{"name":"Research Project of Guizhou University for Talent Introduction","award":["[2020]5017"],"award-info":[{"award-number":["[2020]5017"]}]},{"name":"Research Project of Guizhou University for Talent Introduction","award":["[2020]61"],"award-info":[{"award-number":["[2020]61"]}]},{"name":"Research Project of Guizhou University for Talent Introduction","award":["[2019]56"],"award-info":[{"award-number":["[2019]56"]}]},{"name":"Research Project of Guizhou University for Talent Introduction","award":["GZUAMT2021KF[01]"],"award-info":[{"award-number":["GZUAMT2021KF[01]"]}]},{"name":"Cultivation Project of Guizhou University, PR China","award":["2022YFB2701400"],"award-info":[{"award-number":["2022YFB2701400"]}]},{"name":"Cultivation Project of Guizhou University, PR China","award":["62272124"],"award-info":[{"award-number":["62272124"]}]},{"name":"Cultivation Project of Guizhou University, PR China","award":["62361010"],"award-info":[{"award-number":["62361010"]}]},{"name":"Cultivation Project of Guizhou University, PR China","award":["[2020]5017"],"award-info":[{"award-number":["[2020]5017"]}]},{"name":"Cultivation Project of Guizhou University, PR China","award":["[2020]61"],"award-info":[{"award-number":["[2020]61"]}]},{"name":"Cultivation Project of Guizhou University, PR China","award":["[2019]56"],"award-info":[{"award-number":["[2019]56"]}]},{"name":"Cultivation Project of Guizhou University, PR China","award":["GZUAMT2021KF[01]"],"award-info":[{"award-number":["GZUAMT2021KF[01]"]}]},{"name":"Open Fund of Key Laboratory of Advanced Manufacturing Technology, Ministry of Education, PR China","award":["2022YFB2701400"],"award-info":[{"award-number":["2022YFB2701400"]}]},{"name":"Open Fund of Key Laboratory of Advanced Manufacturing Technology, Ministry of Education, PR China","award":["62272124"],"award-info":[{"award-number":["62272124"]}]},{"name":"Open Fund of Key Laboratory of Advanced Manufacturing Technology, Ministry of Education, PR China","award":["62361010"],"award-info":[{"award-number":["62361010"]}]},{"name":"Open Fund of Key Laboratory of Advanced Manufacturing Technology, Ministry of Education, PR China","award":["[2020]5017"],"award-info":[{"award-number":["[2020]5017"]}]},{"name":"Open Fund of Key Laboratory of Advanced Manufacturing Technology, Ministry of Education, PR China","award":["[2020]61"],"award-info":[{"award-number":["[2020]61"]}]},{"name":"Open Fund of Key Laboratory of Advanced Manufacturing Technology, Ministry of Education, PR China","award":["[2019]56"],"award-info":[{"award-number":["[2019]56"]}]},{"name":"Open Fund of Key Laboratory of Advanced Manufacturing Technology, Ministry of Education, PR China","award":["GZUAMT2021KF[01]"],"award-info":[{"award-number":["GZUAMT2021KF[01]"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>Federated learning (FL) is a distributed machine learning framework that enables scattered participants to collaboratively train machine learning models without revealing information to other participants. Due to its distributed nature, FL is susceptible to being manipulated by malicious clients. These malicious clients can launch backdoor attacks by contaminating local data or tampering with local model gradients, thereby damaging the global model. However, existing backdoor attacks in distributed scenarios have several vulnerabilities. For example, (1) the triggers in distributed backdoor attacks are mostly visible and easily perceivable by humans; (2) these triggers are mostly applied in the spatial domain, inevitably corrupting the semantic information of the contaminated pixels. To address these issues, this paper introduces a frequency-domain injection-based backdoor attack in FL. Specifically, by performing a Fourier transform, the trigger and the clean image are linearly mixed in the frequency domain, injecting the low-frequency information of the trigger into the clean image while preserving its semantic information. Experiments on multiple image classification datasets demonstrate that the attack method proposed in this paper is stealthier and more effective in FL scenarios compared to existing attack methods.<\/jats:p>","DOI":"10.3390\/e26020164","type":"journal-article","created":{"date-parts":[[2024,2,14]],"date-time":"2024-02-14T09:30:18Z","timestamp":1707903018000},"page":"164","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":6,"title":["Federated Learning Backdoor Attack Based on Frequency Domain Injection"],"prefix":"10.3390","volume":"26","author":[{"given":"Jiawang","family":"Liu","sequence":"first","affiliation":[{"name":"State Key Laboratory of Public Big Data, College of Compute Science and Technology, Guizhou University, Guiyang 550025, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8733-4596","authenticated-orcid":false,"given":"Changgen","family":"Peng","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Public Big Data, College of Compute Science and Technology, Guizhou University, Guiyang 550025, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6590-5757","authenticated-orcid":false,"given":"Weijie","family":"Tan","sequence":"additional","affiliation":[{"name":"State Key Laboratory of Public Big Data, College of Compute Science and Technology, Guizhou University, Guiyang 550025, China"},{"name":"Key Laboratory of Advanced Manufacturing Technology of Ministry of Education, Guizhou University, Guiyang 550025, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chenghui","family":"Shi","sequence":"additional","affiliation":[{"name":"College of Computer Science and Technology, Zhejiang University, Hangzhou 310058, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2024,2,14]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3339474","article-title":"Federated Machine Learning: Concept and Applications","volume":"10","author":"Yang","year":"2019","journal-title":"ACM Trans. Intell. Syst. Technol. (TIST)"},{"key":"ref_2","unstructured":"McMahan, B., Moore, E., Ramage, D., Hampson, S., and y Arcas, B.A. (2017, January 20\u201322). Communication-efficient learning of deep networks from decentralized data. Proceedings of the Artificial Intelligence and Statistics, Lauderdale, FL, USA."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Long, G., Tan, Y., Jiang, J., and Zhang, C. (2020). Federated Learning: Privacy and Incentive, Springer International Publishing.","DOI":"10.1007\/978-3-030-63076-8_17"},{"key":"ref_4","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3501813","article-title":"Federated learning for healthcare: Systematic review and architecture proposal","volume":"13","author":"Antunes","year":"2022","journal-title":"ACM Trans. Intell. Syst. Technol. (TIST)"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"340","DOI":"10.1109\/MNET.011.2000379","article-title":"Toward smart security enhancement of federated learning networks","volume":"35","author":"Tan","year":"2020","journal-title":"IEEE Netw."},{"key":"ref_6","unstructured":"Li, X., Wang, S., Wu, C., Zhou, H., and Wang, J. (2023). Backdoor Threats from Compromised Foundation Models to Federated Learning. arXiv."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"107166","DOI":"10.1016\/j.engappai.2023.107166","article-title":"Backdoor attacks and defenses in federated learning: Survey, challenges and future research directions","volume":"127","author":"Nguyen","year":"2024","journal-title":"Eng. Appl. Artif. Intell."},{"key":"ref_8","unstructured":"Zhu, H. (2020). On the relationship between (secure) multi-party computation and (secure) federated learning. arXiv."},{"key":"ref_9","unstructured":"Bagdasaryan, E., Veit, A., Hua, Y., Estrin, D., and Shmatikov, V. (2020, January 26\u201328). How to backdoor federated learning. Proceedings of the International Conference on Artificial Intelligence and Statistics, Online."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Doan, B.G., Abbasnejad, E., and Ranasinghe, D.C. (2020, January 7\u201311). Februus: Input purification defense against trojan attacks on deep neural network systems. Proceedings of the Annual Computer Security Applications Conference, Austin, TX, USA.","DOI":"10.1145\/3427228.3427264"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Feng, Y., Ma, B., Zhang, J., Zhao, S., Xia, Y., and Tao, D. (2022, January 18\u201324). Fiba: Frequency-injection based backdoor attack in medical image analysis. Proceedings of the IEEE\/CVF Conference on Computer Vision and Pattern Recognition, New Orleans, LA, USA.","DOI":"10.1109\/CVPR52688.2022.02021"},{"key":"ref_12","unstructured":"Zhao, P. (2021). Towards Robust Image Classification with Deep Learning and Real-Time DNN Inference on Mobile. [Doctoral Dissertation, Northeastern University]."},{"key":"ref_13","unstructured":"Xie, C., Huang, K., Chen, P.Y., and Li, B. (2020, January 26\u201330). Dba: Distributed backdoor attacks against federated learning. Proceedings of the 8th International Conference on Learning Representations, ICLR 2020, Addis Ababa, Ethiopia."},{"key":"ref_14","unstructured":"Dai, Y., and Li, S. (2023). Chameleon: Adapting to Peer Images for Planting Durable Backdoors in Federated Learning. arXiv."},{"key":"ref_15","unstructured":"Gu, T., Dolan-Gavitt, B., and BadNets, S. (2017, January 10\u201312). Identifying vulnerabilities in the machine learning model supply chain. Proceedings of the Neural Information Processing Symposium Workshop Mach. Learning Security (MLSec), Boston, MA, USA."},{"key":"ref_16","unstructured":"Chen, X., Liu, C., Li, B., Lu, K., and Song, D. (2017). Targeted backdoor attacks on deep learning systems using data poisoning. arXiv."},{"key":"ref_17","unstructured":"Turner, A., Tsipras, D., and Madry, A. (2019, January 6\u20139). Clean-label backdoor attacks. Proceedings of the 2019 International Conference on Learning Representations (ICLR), New Orleans, LA, USA."},{"key":"ref_18","unstructured":"Luo, N., Li, Y., Wang, Y., Wu, S., Tan, Y.A., and Zhang, Q. (2022). Enhancing clean label backdoor attack with two-phase specific triggers. arXiv."},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Wang, B., Yao, Y., Shan, S., Li, H., Viswanath, B., Zheng, H., and Zhao, B.Y. (2019, January 20\u201322). Neural cleanse: Identifying and mitigating backdoor attacks in neural networks. Proceedings of the 2019 IEEE Symposium on Security and Privacy (SP), San Francisco, CA, USA.","DOI":"10.1109\/SP.2019.00031"},{"key":"ref_20","unstructured":"Liu, K., Dolan-Gavitt, B., and Garg, S. (2018). International Symposium on Research in Attacks, Intrusions, and Defenses, Springer International Publishing."},{"key":"ref_21","unstructured":"Mu\u00f1oz-Gonz\u00e1lez, L., Co, K.T., and Lupu, E.C. (2019). Byzantine-robust federated machine learning through adaptive model averaging. arXiv."},{"key":"ref_22","unstructured":"Shen, S., Tople, S., and Saxena, P. (2016, January 5\u20139). Auror: Defending against poisoning attacks in collaborative deep learning systems. Proceedings of the 32nd Annual Conference on Computer Security Applications, Los Angeles, CA, USA."},{"key":"ref_23","unstructured":"Xie, C., Chen, M., Chen, P.Y., and Li, B. (2021, January 18\u201324). Crfl: Certifiably robust federated learning against backdoor attacks. Proceedings of the International Conference on Machine Learning, Virtual."},{"key":"ref_24","doi-asserted-by":"crossref","unstructured":"Ozdayi, M.S., Kantarcioglu, M., and Gel, Y.R. (2021, January 2\u20139). Defending against backdoors in federated learning with robust learning rate. Proceedings of the AAAI Conference on Artificial Intelligence, Virtual.","DOI":"10.1609\/aaai.v35i10.17118"}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/26\/2\/164\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,10]],"date-time":"2025-10-10T13:59:42Z","timestamp":1760104782000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/26\/2\/164"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,2,14]]},"references-count":24,"journal-issue":{"issue":"2","published-online":{"date-parts":[[2024,2]]}},"alternative-id":["e26020164"],"URL":"https:\/\/doi.org\/10.3390\/e26020164","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,2,14]]}}}