{"id":"https://openalex.org/W4392931300","doi":"https://doi.org/10.1109/tdsc.2024.3376790","title":"Towards Practical Backdoor Attacks on Federated Learning Systems","display_name":"Towards Practical Backdoor Attacks on Federated Learning Systems","publication_year":2024,"publication_date":"2024-03-18","ids":{"openalex":"https://openalex.org/W4392931300","doi":"https://doi.org/10.1109/tdsc.2024.3376790"},"language":"en","primary_location":{"id":"doi:10.1109/tdsc.2024.3376790","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2024.3376790","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5016502133","display_name":"Chenghui Shi","orcid":"https://orcid.org/0000-0001-8799-9045"},"institutions":[{"id":"https://openalex.org/I168879160","display_name":"Zhejiang University of Science and Technology","ror":"https://ror.org/05mx0wr29","country_code":"CN","type":"education","lineage":["https://openalex.org/I168879160"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Chenghui Shi","raw_affiliation_strings":["College of Computer Science and Technology, Zhejiang University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I168879160"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5058611515","display_name":"Shouling Ji","orcid":"https://orcid.org/0000-0003-4268-372X"},"institutions":[{"id":"https://openalex.org/I168879160","display_name":"Zhejiang University of Science and Technology","ror":"https://ror.org/05mx0wr29","country_code":"CN","type":"education","lineage":["https://openalex.org/I168879160"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Shouling Ji","raw_affiliation_strings":["College of Computer Science and Technology, Zhejiang University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I168879160"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5074846459","display_name":"Xudong Pan","orcid":"https://orcid.org/0000-0003-1394-0395"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xudong Pan","raw_affiliation_strings":["School of Computer Science and Technology, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101722406","display_name":"Xuhong Zhang","orcid":"https://orcid.org/0000-0002-8571-9780"},"institutions":[{"id":"https://openalex.org/I168879160","display_name":"Zhejiang University of Science and Technology","ror":"https://ror.org/05mx0wr29","country_code":"CN","type":"education","lineage":["https://openalex.org/I168879160"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xuhong Zhang","raw_affiliation_strings":["College of Computer Science and Technology, Zhejiang University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I168879160"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101652939","display_name":"Mi Zhang","orcid":"https://orcid.org/0000-0003-3567-3478"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Mi Zhang","raw_affiliation_strings":["School of Computer Science and Technology, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5052437722","display_name":"Min Yang","orcid":"https://orcid.org/0000-0001-9714-5545"},"institutions":[{"id":"https://openalex.org/I24943067","display_name":"Fudan University","ror":"https://ror.org/013q1eq08","country_code":"CN","type":"education","lineage":["https://openalex.org/I24943067"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Min Yang","raw_affiliation_strings":["School of Computer Science and Technology, Fudan University, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, Fudan University, Shanghai, China","institution_ids":["https://openalex.org/I24943067"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5045140292","display_name":"Jun Zhou","orcid":"https://orcid.org/0000-0001-6033-6102"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jun Zhou","raw_affiliation_strings":["Ant Group, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"Ant Group, Hangzhou, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069353502","display_name":"Jianwei Yin","orcid":"https://orcid.org/0000-0003-4703-7348"},"institutions":[{"id":"https://openalex.org/I168879160","display_name":"Zhejiang University of Science and Technology","ror":"https://ror.org/05mx0wr29","country_code":"CN","type":"education","lineage":["https://openalex.org/I168879160"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jianwei Yin","raw_affiliation_strings":["College of Computer Science and Technology, Zhejiang University, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Zhejiang University, Hangzhou, China","institution_ids":["https://openalex.org/I168879160"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100428026","display_name":"Ting Wang","orcid":"https://orcid.org/0000-0003-4927-5833"},"institutions":[{"id":"https://openalex.org/I59553526","display_name":"Stony Brook University","ror":"https://ror.org/05qghxh33","country_code":"US","type":"education","lineage":["https://openalex.org/I59553526"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Ting Wang","raw_affiliation_strings":["Department of Computer Science, Stony Brook University, Stony Brook, NY, USA"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, Stony Brook University, Stony Brook, NY, USA","institution_ids":["https://openalex.org/I59553526"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":9,"corresponding_author_ids":["https://openalex.org/A5016502133"],"corresponding_institution_ids":["https://openalex.org/I168879160"],"apc_list":null,"apc_paid":null,"fwci":2.7801,"has_fulltext":false,"cited_by_count":8,"citation_normalized_percentile":{"value":0.91088883,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":"21","issue":"6","first_page":"5431","last_page":"5447"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9986000061035156,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9986000061035156,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.9955999851226807,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9955000281333923,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9839869737625122},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8129898309707642},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.5538576245307922}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9839869737625122},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8129898309707642},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.5538576245307922}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tdsc.2024.3376790","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tdsc.2024.3376790","pdf_url":null,"source":{"id":"https://openalex.org/S133795288","display_name":"IEEE Transactions on Dependable and Secure Computing","issn_l":"1545-5971","issn":["1545-5971","1941-0018","2160-9209"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310320439","host_organization_name":"IEEE Computer Society","host_organization_lineage":["https://openalex.org/P4310320439","https://openalex.org/P4310319808"],"host_organization_lineage_names":["IEEE Computer Society","Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Dependable and Secure Computing","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G6758494209","display_name":null,"funder_award_id":"62102360","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":63,"referenced_works":["https://openalex.org/W1509966554","https://openalex.org/W1522301498","https://openalex.org/W2530417694","https://openalex.org/W2535838896","https://openalex.org/W2591882872","https://openalex.org/W2734358244","https://openalex.org/W2753783305","https://openalex.org/W2767079719","https://openalex.org/W2774423163","https://openalex.org/W2788816110","https://openalex.org/W2789911054","https://openalex.org/W2807363941","https://openalex.org/W2897865027","https://openalex.org/W2900120080","https://openalex.org/W2912213068","https://openalex.org/W2934843808","https://openalex.org/W2942091739","https://openalex.org/W2948685905","https://openalex.org/W2950447132","https://openalex.org/W2963456518","https://openalex.org/W2972594657","https://openalex.org/W2981645102","https://openalex.org/W2990595670","https://openalex.org/W3037913917","https://openalex.org/W3048684575","https://openalex.org/W3048715803","https://openalex.org/W3106047871","https://openalex.org/W3118608800","https://openalex.org/W4206320562","https://openalex.org/W4221129260","https://openalex.org/W4289300166","https://openalex.org/W4297687186","https://openalex.org/W4298221930","https://openalex.org/W4301295444","https://openalex.org/W6630649318","https://openalex.org/W6631190155","https://openalex.org/W6677580257","https://openalex.org/W6728757088","https://openalex.org/W6734565475","https://openalex.org/W6746720608","https://openalex.org/W6746897123","https://openalex.org/W6748786018","https://openalex.org/W6748805329","https://openalex.org/W6750462152","https://openalex.org/W6752600739","https://openalex.org/W6755616390","https://openalex.org/W6755988804","https://openalex.org/W6756074407","https://openalex.org/W6756091659","https://openalex.org/W6756333562","https://openalex.org/W6756840679","https://openalex.org/W6758201434","https://openalex.org/W6760759230","https://openalex.org/W6761059766","https://openalex.org/W6762462524","https://openalex.org/W6764838729","https://openalex.org/W6770634426","https://openalex.org/W6771533808","https://openalex.org/W6780640148","https://openalex.org/W6787633081","https://openalex.org/W6787972765","https://openalex.org/W6839074529","https://openalex.org/W7056673059"],"related_works":["https://openalex.org/W2748952813","https://openalex.org/W4320031223","https://openalex.org/W3015678314","https://openalex.org/W4281902577","https://openalex.org/W4200629851","https://openalex.org/W3009072493","https://openalex.org/W4386185023","https://openalex.org/W4317672133","https://openalex.org/W3140988292","https://openalex.org/W4386080799"],"abstract_inverted_index":{"Federated":[0],"Learning":[1],"(FL)":[2],"is":[3,64,76,123],"nowadays":[4],"one":[5],"of":[6,59,105,135,154,177,201,226,243],"the":[7,56,70,103,106,144,166,178,199,202,227,241,251],"most":[8],"promising":[9],"paradigms":[10],"for":[11,48,79],"privacy-preserving":[12],"distributed":[13],"learning.":[14],"Without":[15],"revealing":[16],"its":[17,39],"local":[18,40],"private":[19],"data":[20],"to":[21,29,44,69,96,125,159,254],"outsiders,":[22],"a":[23,31,45,77,115,151,189,195],"client":[24,80,95],"in":[25,143,165],"FL":[26,107,120,136,141,245],"systems":[27,121,137,246],"collaborates":[28],"build":[30],"global":[32],"Deep":[33],"Neural":[34],"Network":[35],"(DNN)":[36],"by":[37,66],"submitting":[38],"model":[41],"parameter":[42],"update":[43,58],"central":[46],"server":[47],"iterative":[49],"aggregation.":[50],"With":[51],"secure":[52],"multi-party":[53],"computation":[54],"protocols,":[55],"submitted":[57],"<italic":[60],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[61],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">any":[62],"client</i>":[63],"also":[65,90],"design":[67,75],"invisible":[68],"server.":[71],"Seemingly,":[72],"this":[73,111,182],"standard":[74],"win-win":[78],"privacy":[81,219],"and":[82,129,138,168,221,250],"service":[83],"provider":[84],"utility.":[85],"Ironically,":[86],"any":[87,99],"attacker":[88],"may":[89],"use":[91,133],"manipulated":[92],"or":[93,162],"impersonated":[94],"submit":[97],"almost":[98],"attack":[100,118,186,191],"payloads":[101],"under":[102],"umbrella":[104],"protocol":[108],"itself.":[109],"In":[110,181],"work,":[112],"we":[113,148,207],"craft":[114],"practical":[116],"backdoor":[117,171,185,235,248],"on":[119,131,198],"that":[122],"proved":[124],"be":[126,160],"simultaneously":[127],"effective":[128,257],"stealthy":[130],"diverse":[132],"cases":[134],"leading":[139],"commercial":[140],"platforms":[142],"real":[145],"world.":[146],"Basically,":[147],"first":[149],"identify":[150],"small":[152],"number":[153],"redundant":[155,174],"neurons":[156,175],"which":[157],"tend":[158],"rarely":[161],"slightly":[163],"updated":[164],"model,":[167],"then":[169],"inject":[170],"into":[172],"these":[173],"instead":[176],"whole":[179],"model.":[180],"way,":[183],"our":[184,234],"can":[187],"achieve":[188],"high":[190],"success":[192],"rate":[193],"with":[194],"minor":[196],"impact":[197],"accuracy":[200],"original":[203],"task.":[204],"As":[205],"countermeasures,":[206],"further":[208],"consider":[209],"several":[210],"common":[211],"technical":[212],"choices":[213],"including":[214],"robust":[215],"aggregation":[216],"mechanisms,":[217],"differential":[218],"mechanism,s":[220],"network":[222],"pruning.":[223],"However,":[224],"none":[225],"defenses":[228],"show":[229],"desirable":[230],"defense":[231,258],"capability":[232],"against":[233,247],"attack.":[236],"Our":[237],"results":[238],"strongly":[239],"highlight":[240],"vulnerability":[242],"existing":[244],"attacks":[249],"urgent":[252],"need":[253],"develop":[255],"more":[256],"mechanisms.":[259]},"counts_by_year":[{"year":2025,"cited_by_count":7},{"year":2024,"cited_by_count":1}],"updated_date":"2026-03-27T05:58:40.876381","created_date":"2025-10-10T00:00:00"}
