{"id":"https://openalex.org/W4416250705","doi":"https://doi.org/10.1109/ijcnn64981.2025.11229350","title":"Foundation Models in Federated Learning: Assessing Backdoor Vulnerabilities","display_name":"Foundation Models in Federated Learning: Assessing Backdoor Vulnerabilities","publication_year":2025,"publication_date":"2025-06-30","ids":{"openalex":"https://openalex.org/W4416250705","doi":"https://doi.org/10.1109/ijcnn64981.2025.11229350"},"language":null,"primary_location":{"id":"doi:10.1109/ijcnn64981.2025.11229350","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn64981.2025.11229350","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100407758","display_name":"Xi Li","orcid":"https://orcid.org/0000-0003-3023-1662"},"institutions":[{"id":"https://openalex.org/I32389192","display_name":"University of Alabama at Birmingham","ror":"https://ror.org/008s83205","country_code":"US","type":"education","lineage":["https://openalex.org/I32389192"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Xi Li","raw_affiliation_strings":["University of Alabama at Birmingham"],"affiliations":[{"raw_affiliation_string":"University of Alabama at Birmingham","institution_ids":["https://openalex.org/I32389192"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100705638","display_name":"Chen Wu","orcid":"https://orcid.org/0000-0001-6461-8377"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Chen Wu","raw_affiliation_strings":["Meta"],"affiliations":[{"raw_affiliation_string":"Meta","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100365369","display_name":"Jiaqi Wang","orcid":"https://orcid.org/0000-0002-8523-3975"},"institutions":[{"id":"https://openalex.org/I130769515","display_name":"Pennsylvania State University","ror":"https://ror.org/04p491231","country_code":"US","type":"education","lineage":["https://openalex.org/I130769515"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jiaqi Wang","raw_affiliation_strings":["The Pennsylvania State University"],"affiliations":[{"raw_affiliation_string":"The Pennsylvania State University","institution_ids":["https://openalex.org/I130769515"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5100407758"],"corresponding_institution_ids":["https://openalex.org/I32389192"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.19427667,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.8266000151634216,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.8266000151634216,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.11069999635219574,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11307","display_name":"Domain Adaptation and Few-Shot Learning","score":0.005799999926239252,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.963100016117096},{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.8062000274658203},{"id":"https://openalex.org/keywords/robustness","display_name":"Robustness (evolution)","score":0.6656000018119812},{"id":"https://openalex.org/keywords/compromise","display_name":"Compromise","score":0.611299991607666},{"id":"https://openalex.org/keywords/threat-model","display_name":"Threat model","score":0.5149999856948853},{"id":"https://openalex.org/keywords/foundation","display_name":"Foundation (evidence)","score":0.4731000065803528},{"id":"https://openalex.org/keywords/federated-learning","display_name":"Federated learning","score":0.41690000891685486}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.963100016117096},{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.8062000274658203},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7215999960899353},{"id":"https://openalex.org/C63479239","wikidata":"https://www.wikidata.org/wiki/Q7353546","display_name":"Robustness (evolution)","level":3,"score":0.6656000018119812},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6340000033378601},{"id":"https://openalex.org/C46355384","wikidata":"https://www.wikidata.org/wiki/Q726686","display_name":"Compromise","level":2,"score":0.611299991607666},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.5149999856948853},{"id":"https://openalex.org/C2780966255","wikidata":"https://www.wikidata.org/wiki/Q5474306","display_name":"Foundation (evidence)","level":2,"score":0.4731000065803528},{"id":"https://openalex.org/C2992525071","wikidata":"https://www.wikidata.org/wiki/Q50818671","display_name":"Federated learning","level":2,"score":0.41690000891685486},{"id":"https://openalex.org/C37736160","wikidata":"https://www.wikidata.org/wiki/Q1801315","display_name":"Adversarial system","level":2,"score":0.35569998621940613},{"id":"https://openalex.org/C2779965156","wikidata":"https://www.wikidata.org/wiki/Q5227350","display_name":"Data sharing","level":3,"score":0.34940001368522644},{"id":"https://openalex.org/C114466953","wikidata":"https://www.wikidata.org/wiki/Q6034165","display_name":"Initialization","level":2,"score":0.3149999976158142},{"id":"https://openalex.org/C9652623","wikidata":"https://www.wikidata.org/wiki/Q190109","display_name":"Field (mathematics)","level":2,"score":0.2676999866962433},{"id":"https://openalex.org/C18762648","wikidata":"https://www.wikidata.org/wiki/Q42213","display_name":"Work (physics)","level":2,"score":0.26269999146461487},{"id":"https://openalex.org/C121822524","wikidata":"https://www.wikidata.org/wiki/Q5157582","display_name":"Computer security model","level":2,"score":0.26010000705718994},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.26010000705718994},{"id":"https://openalex.org/C46686674","wikidata":"https://www.wikidata.org/wiki/Q466303","display_name":"Boosting (machine learning)","level":2,"score":0.25940001010894775},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.2531999945640564},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.25270000100135803}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/ijcnn64981.2025.11229350","is_oa":false,"landing_page_url":"https://doi.org/10.1109/ijcnn64981.2025.11229350","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2025 International Joint Conference on Neural Networks (IJCNN)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":24,"referenced_works":["https://openalex.org/W2194775991","https://openalex.org/W2973217491","https://openalex.org/W3046764764","https://openalex.org/W3087391814","https://openalex.org/W3196832521","https://openalex.org/W4214563788","https://openalex.org/W4220822151","https://openalex.org/W4283702393","https://openalex.org/W4312428735","https://openalex.org/W4312473456","https://openalex.org/W4312933868","https://openalex.org/W4313042326","https://openalex.org/W4316661314","https://openalex.org/W4360982308","https://openalex.org/W4385627126","https://openalex.org/W4390190425","https://openalex.org/W4393148063","https://openalex.org/W4393154589","https://openalex.org/W4395098201","https://openalex.org/W4401042878","https://openalex.org/W4404782897","https://openalex.org/W4404782964","https://openalex.org/W4412888589","https://openalex.org/W4414198420"],"related_works":[],"abstract_inverted_index":{"Federated":[0],"Learning":[1],"(FL),":[2],"a":[3,37],"privacy-preserving":[4],"machine":[5],"learning":[6],"framework,":[7],"faces":[8],"significant":[9],"data-related":[10],"challenges.":[11],"For":[12],"example,":[13],"the":[14,58,76,94,139,149,159],"lack":[15],"of":[16,142,161],"suitable":[17],"public":[18],"datasets":[19,43,91],"leads":[20],"to":[21,92,144],"ineffective":[22],"information":[23],"exchange,":[24],"especially":[25],"in":[26,86,113,156,158],"heterogeneous":[27],"environments":[28],"with":[29],"uneven":[30],"data":[31,47],"distribution.":[32],"Foundation":[33],"Models":[34],"(FMs)":[35],"offer":[36],"promising":[38],"solution":[39],"by":[40,105],"generating":[41],"synthetic":[42,90],"that":[44,68],"mimic":[45],"client":[46],"distributions,":[48],"aiding":[49],"model":[50],"initialization":[51],"and":[52,62,88,135],"knowledge":[53],"sharing":[54],"among":[55],"clients.":[56],"However,":[57],"interaction":[59],"between":[60],"FMs":[61,87],"FL":[63,114,120,143,157],"introduces":[64],"new":[65,101],"attack":[66,129],"vectors":[67],"remain":[69],"largely":[70],"unexplored.":[71],"This":[72],"work":[73],"therefore":[74],"assesses":[75],"backdoor":[77],"vulnerabilities":[78],"exploiting":[79],"FMs,":[80],"where":[81],"attackers":[82],"exploit":[83],"safety":[84],"issues":[85],"poison":[89],"compromise":[93],"entire":[95],"system.":[96],"Unlike":[97],"traditional":[98],"attacks,":[99],"these":[100,117,145],"threats":[102],"are":[103],"characterized":[104],"their":[106],"one-time,":[107],"external":[108],"nature,":[109],"requiring":[110],"minimal":[111],"involvement":[112],"training.":[115],"Given":[116],"uniqueness,":[118],"current":[119],"defense":[121],"strategies":[122],"provide":[123],"limited":[124],"robustness":[125],"against":[126],"this":[127],"novel":[128,146],"approach.":[130],"Extensive":[131],"experiments":[132],"across":[133],"image":[134],"text":[136],"domains":[137],"reveal":[138],"high":[140],"susceptibility":[141],"threats,":[147],"emphasizing":[148],"urgent":[150],"need":[151],"for":[152],"enhanced":[153],"security":[154],"measures":[155],"era":[160],"FMs<sup":[162],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[163],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">1</sup>.":[164]},"counts_by_year":[],"updated_date":"2026-03-07T16:01:11.037858","created_date":"2025-11-14T00:00:00"}
