{"id":"https://openalex.org/W4385482833","doi":"https://doi.org/10.1109/ijcnn54540.2023.10191260","title":"Privacy Inference-Empowered Stealthy Backdoor Attack on Federated Learning under Non-IID Scenarios","display_name":"Privacy Inference-Empowered Stealthy Backdoor Attack on Federated Learning under Non-IID Scenarios","publication_year":2023,"publication_date":"2023-06-18","ids":{"openalex":"https://openalex.org/W4385482833","doi":"https://doi.org/10.1109/ijcnn54540.2023.10191260"},"language":"en","primary_location":{"id":"doi:10.1109/ijcnn54540.2023.10191260","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn54540.2023.10191260","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101189501","display_name":"Haochen Mei","orcid":null},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Haochen Mei","raw_affiliation_strings":["School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University,Shanghai,China","School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University,Shanghai,China","institution_ids":["https://openalex.org/I183067930"]},{"raw_affiliation_string":"School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5007267530","display_name":"Gaolei Li","orcid":"https://orcid.org/0000-0003-3913-5001"},"institutions":[{"id":"https://openalex.org/I183067930","display_name":"Shanghai Jiao Tong University","ror":"https://ror.org/0220qvk04","country_code":"CN","type":"education","lineage":["https://openalex.org/I183067930"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Gaolei Li","raw_affiliation_strings":["School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University,Shanghai,China","Shanghai Key Laboratory of Integrated Administration Technologies for Information Security, Shanghai, China","School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University,Shanghai,China","institution_ids":["https://openalex.org/I183067930"]},{"raw_affiliation_string":"Shanghai Key Laboratory of Integrated Administration Technologies for Information Security, Shanghai, China","institution_ids":[]},{"raw_affiliation_string":"School of Electronic Information and Electrical Engineering, Shanghai Jiao Tong University, Shanghai, China","institution_ids":["https://openalex.org/I183067930"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100702646","display_name":"Jun Wu","orcid":"https://orcid.org/0000-0002-1512-524X"},"institutions":[{"id":"https://openalex.org/I150744194","display_name":"Waseda University","ror":"https://ror.org/00ntfnx83","country_code":"JP","type":"education","lineage":["https://openalex.org/I150744194"]}],"countries":["JP"],"is_corresponding":false,"raw_author_name":"Jun Wu","raw_affiliation_strings":["Graduate School of Information, Production and Systems, Waseda University,Fukuoka,Japan","Graduate School of Information, Production and Systems, Waseda University, Fukuoka, Japan"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Graduate School of Information, Production and Systems, Waseda University,Fukuoka,Japan","institution_ids":["https://openalex.org/I150744194"]},{"raw_affiliation_string":"Graduate School of Information, Production and Systems, Waseda University, Fukuoka, Japan","institution_ids":["https://openalex.org/I150744194"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5008993283","display_name":"Longfei Zheng","orcid":"https://orcid.org/0000-0003-3604-2598"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Longfei Zheng","raw_affiliation_strings":["Ant Group,China","Ant Group, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Ant Group,China","institution_ids":[]},{"raw_affiliation_string":"Ant Group, China","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":3.1001,"has_fulltext":false,"cited_by_count":20,"citation_normalized_percentile":{"value":0.93165521,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"10"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9423999786376953,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9971723556518555},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7304245233535767},{"id":"https://openalex.org/keywords/inference","display_name":"Inference","score":0.7024116516113281},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4941730797290802},{"id":"https://openalex.org/keywords/scheme","display_name":"Scheme (mathematics)","score":0.49264317750930786},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.4506823420524597},{"id":"https://openalex.org/keywords/adversarial-system","display_name":"Adversarial system","score":0.44923996925354004},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.418615460395813},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3718872666358948},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.3672144412994385},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.09461328387260437}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9971723556518555},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7304245233535767},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.7024116516113281},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4941730797290802},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.49264317750930786},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.4506823420524597},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.44923996925354004},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.418615460395813},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3718872666358948},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.3672144412994385},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.09461328387260437},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ijcnn54540.2023.10191260","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn54540.2023.10191260","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.800000011920929,"id":"https://metadata.un.org/sdg/16"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":57,"referenced_works":["https://openalex.org/W2019464758","https://openalex.org/W2412510955","https://openalex.org/W2535388113","https://openalex.org/W2591882872","https://openalex.org/W2618530766","https://openalex.org/W2748789698","https://openalex.org/W2767079719","https://openalex.org/W2807006176","https://openalex.org/W2807363941","https://openalex.org/W2810065831","https://openalex.org/W2903356604","https://openalex.org/W2934843808","https://openalex.org/W2963306805","https://openalex.org/W2963456518","https://openalex.org/W2963684088","https://openalex.org/W2964162474","https://openalex.org/W2982802130","https://openalex.org/W2990595670","https://openalex.org/W2995022099","https://openalex.org/W2995164118","https://openalex.org/W3018749413","https://openalex.org/W3038022836","https://openalex.org/W3042368254","https://openalex.org/W3084847664","https://openalex.org/W3096831136","https://openalex.org/W3106047871","https://openalex.org/W3113458348","https://openalex.org/W3118840986","https://openalex.org/W3173670432","https://openalex.org/W3202935128","https://openalex.org/W4213110664","https://openalex.org/W4283311307","https://openalex.org/W4285205054","https://openalex.org/W4285206772","https://openalex.org/W4285601739","https://openalex.org/W4289300166","https://openalex.org/W4318619660","https://openalex.org/W4320029366","https://openalex.org/W6685352114","https://openalex.org/W6715189028","https://openalex.org/W6728757088","https://openalex.org/W6743581629","https://openalex.org/W6752029299","https://openalex.org/W6752600739","https://openalex.org/W6755987517","https://openalex.org/W6756074407","https://openalex.org/W6756840679","https://openalex.org/W6759238902","https://openalex.org/W6771533808","https://openalex.org/W6776372214","https://openalex.org/W6780640148","https://openalex.org/W6787633081","https://openalex.org/W6788531746","https://openalex.org/W6838950291","https://openalex.org/W6839074529","https://openalex.org/W6840331315","https://openalex.org/W7056673059"],"related_works":["https://openalex.org/W4320031223","https://openalex.org/W4320018150","https://openalex.org/W4328053081","https://openalex.org/W4366850823","https://openalex.org/W3086120435","https://openalex.org/W2918664383","https://openalex.org/W2040808657","https://openalex.org/W4320855730","https://openalex.org/W106056076","https://openalex.org/W2135200719"],"abstract_inverted_index":{"Federated":[0],"learning":[1,134],"(FL)":[2],"naturally":[3],"faces":[4],"the":[5,26,29,43,113,141,151,155,194],"problem":[6],"of":[7,31,65],"data":[8,51,66,94,116,161],"heterogeneity":[9],"in":[10,178,200],"real-world":[11],"scenarios,":[12],"but":[13],"this":[14,73],"is":[15,58,103,198],"often":[16],"overlooked":[17],"by":[18],"studies":[19],"on":[20,34,98,127,184],"FL":[21,35,87,202],"security":[22],"and":[23,69,118,176,187,203],"privacy.":[24],"On":[25,42],"one":[27],"hand,":[28,45],"effectiveness":[30,175],"backdoor":[32,82,124,133,152,170],"attacks":[33,171],"may":[36,48],"drop":[37],"significantly":[38],"under":[39,88],"non-IID":[40,89,179,201],"scenarios.":[41,90,180],"other":[44],"malicious":[46],"clients":[47],"steal":[49],"private":[50],"through":[52],"privacy":[53,70,79],"inference":[54],"attacks.":[55,125],"Therefore,":[56],"it":[57,164],"necessary":[59],"to":[60,105,143,150,172],"have":[61],"a":[62,77,92,107,131,138],"comprehensive":[63],"perspective":[64],"heterogeneity,":[67],"backdoor,":[68],"inference.":[71],"In":[72],"paper,":[74],"we":[75,129],"propose":[76],"novel":[78],"inference-empowered":[80],"stealthy":[81,204],"attack":[83],"(PI-SBA)":[84],"scheme":[85,197],"for":[86,123],"Firstly,":[91],"diverse":[93],"reconstruction":[95],"mechanism":[96],"based":[97,183],"generative":[99],"adversarial":[100],"networks":[101],"(GANs)":[102],"proposed":[104,195],"produce":[106],"supplementary":[108],"dataset,":[109],"which":[110,146],"can":[111,165],"improve":[112,173],"attacker's":[114],"local":[115],"distribution":[117],"support":[119],"more":[120],"sophisticated":[121],"strategies":[122],"Based":[126],"this,":[128],"design":[130],"source-specified":[132],"(SSBL)":[135],"strategy":[136],"as":[137],"demonstration,":[139],"allowing":[140],"adversary":[142],"arbitrarily":[144],"specify":[145],"classes":[147],"are":[148],"susceptible":[149],"trigger.":[153],"Since":[154],"PI-SBA":[156,196],"has":[157],"an":[158],"independent":[159],"poisoned":[160],"synthesis":[162],"process,":[163],"be":[166],"integrated":[167],"into":[168],"existing":[169],"their":[174],"stealthiness":[177],"Extensive":[181],"experiments":[182],"MNIST,":[185],"CIFAR10":[186],"Youtube":[188],"Aligned":[189],"Face":[190],"datasets":[191],"demonstrate":[192],"that":[193],"effective":[199],"against":[205],"state-of-the-art":[206],"defense":[207],"methods.":[208]},"counts_by_year":[{"year":2025,"cited_by_count":7},{"year":2024,"cited_by_count":8},{"year":2023,"cited_by_count":4},{"year":2020,"cited_by_count":1}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
