{"id":"https://openalex.org/W4406794207","doi":"https://doi.org/10.1109/tifs.2025.3533899","title":"Scope: On Detecting Constrained Backdoor Attacks in Federated Learning","display_name":"Scope: On Detecting Constrained Backdoor Attacks in Federated Learning","publication_year":2025,"publication_date":"2025-01-01","ids":{"openalex":"https://openalex.org/W4406794207","doi":"https://doi.org/10.1109/tifs.2025.3533899"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2025.3533899","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2025.3533899","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5076686948","display_name":"Siquan Huang","orcid":"https://orcid.org/0000-0003-0648-3405"},"institutions":[{"id":"https://openalex.org/I90610280","display_name":"South China University of Technology","ror":"https://ror.org/0530pts50","country_code":"CN","type":"education","lineage":["https://openalex.org/I90610280"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Siquan Huang","raw_affiliation_strings":["School of Computer Science and Engineering, South China University of Technology, Guangzhou, China"],"raw_orcid":"https://orcid.org/0000-0003-0648-3405","affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, South China University of Technology, Guangzhou, China","institution_ids":["https://openalex.org/I90610280"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5005222486","display_name":"Yijiang Li","orcid":"https://orcid.org/0000-0003-0644-7199"},"institutions":[{"id":"https://openalex.org/I36258959","display_name":"University of California San Diego","ror":"https://ror.org/0168r3w48","country_code":"US","type":"education","lineage":["https://openalex.org/I36258959"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yijiang Li","raw_affiliation_strings":["Department of Electrical and Computer Engineering, University of California San Diego, La Jolla, CA, USA","University of California San Diego, La Jolla, California, United States"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering, University of California San Diego, La Jolla, CA, USA","institution_ids":["https://openalex.org/I36258959"]},{"raw_affiliation_string":"University of California San Diego, La Jolla, California, United States","institution_ids":["https://openalex.org/I36258959"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5032278260","display_name":"Xingfu Yan","orcid":"https://orcid.org/0000-0002-3026-0976"},"institutions":[{"id":"https://openalex.org/I187400657","display_name":"South China Normal University","ror":"https://ror.org/01kq0pv72","country_code":"CN","type":"education","lineage":["https://openalex.org/I187400657"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xingfu Yan","raw_affiliation_strings":["School of Computer Science, South China Normal University, Guangzhou, China","South China Normal University, Guangzhou, China"],"raw_orcid":"https://orcid.org/0000-0002-3026-0976","affiliations":[{"raw_affiliation_string":"School of Computer Science, South China Normal University, Guangzhou, China","institution_ids":["https://openalex.org/I187400657"]},{"raw_affiliation_string":"South China Normal University, Guangzhou, China","institution_ids":["https://openalex.org/I187400657"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101828088","display_name":"Ying Gao","orcid":"https://orcid.org/0000-0002-8925-8192"},"institutions":[{"id":"https://openalex.org/I90610280","display_name":"South China University of Technology","ror":"https://ror.org/0530pts50","country_code":"CN","type":"education","lineage":["https://openalex.org/I90610280"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Ying Gao","raw_affiliation_strings":["School of Computer Science and Engineering, South China University of Technology, Guangzhou, China"],"raw_orcid":"https://orcid.org/0000-0002-8925-8192","affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, South China University of Technology, Guangzhou, China","institution_ids":["https://openalex.org/I90610280"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5111432189","display_name":"Chong Chen","orcid":"https://orcid.org/0000-0001-6278-120X"},"institutions":[{"id":"https://openalex.org/I90610280","display_name":"South China University of Technology","ror":"https://ror.org/0530pts50","country_code":"CN","type":"education","lineage":["https://openalex.org/I90610280"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chong Chen","raw_affiliation_strings":["School of Computer Science and Engineering, South China University of Technology, Guangzhou, China"],"raw_orcid":"https://orcid.org/0000-0001-6278-120X","affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, South China University of Technology, Guangzhou, China","institution_ids":["https://openalex.org/I90610280"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5111111992","display_name":"Leyu Shi","orcid":"https://orcid.org/0009-0007-4233-5385"},"institutions":[{"id":"https://openalex.org/I90610280","display_name":"South China University of Technology","ror":"https://ror.org/0530pts50","country_code":"CN","type":"education","lineage":["https://openalex.org/I90610280"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Leyu Shi","raw_affiliation_strings":["School of Computer Science and Engineering, South China University of Technology, Guangzhou, China"],"raw_orcid":"https://orcid.org/0009-0007-4233-5385","affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, South China University of Technology, Guangzhou, China","institution_ids":["https://openalex.org/I90610280"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100458389","display_name":"Biao Chen","orcid":"https://orcid.org/0000-0001-9730-7284"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Biao Chen","raw_affiliation_strings":["Nanfang Media Group, Guangzhou, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Nanfang Media Group, Guangzhou, China","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5105759393","display_name":"Wing W. Y. Ng","orcid":"https://orcid.org/0000-0003-0783-3585"},"institutions":[{"id":"https://openalex.org/I90610280","display_name":"South China University of Technology","ror":"https://ror.org/0530pts50","country_code":"CN","type":"education","lineage":["https://openalex.org/I90610280"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Wing W. Y. Ng","raw_affiliation_strings":["School of Computer Science and Engineering, South China University of Technology, Guangzhou, China"],"raw_orcid":"https://orcid.org/0000-0003-0783-3585","affiliations":[{"raw_affiliation_string":"School of Computer Science and Engineering, South China University of Technology, Guangzhou, China","institution_ids":["https://openalex.org/I90610280"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":8,"corresponding_author_ids":["https://openalex.org/A5076686948"],"corresponding_institution_ids":["https://openalex.org/I90610280"],"apc_list":null,"apc_paid":null,"fwci":21.5373,"has_fulltext":false,"cited_by_count":10,"citation_normalized_percentile":{"value":0.99194556,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":98,"max":99},"biblio":{"volume":"20","issue":null,"first_page":"3302","last_page":"3315"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9991000294685364,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9944999814033508,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.9940000176429749,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/backdoor","display_name":"Backdoor","score":0.9584800004959106},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8491376638412476},{"id":"https://openalex.org/keywords/scope","display_name":"Scope (computer science)","score":0.7943254709243774},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.529029130935669},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.39903542399406433},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.09097445011138916}],"concepts":[{"id":"https://openalex.org/C2781045450","wikidata":"https://www.wikidata.org/wiki/Q254569","display_name":"Backdoor","level":2,"score":0.9584800004959106},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8491376638412476},{"id":"https://openalex.org/C2778012447","wikidata":"https://www.wikidata.org/wiki/Q1034415","display_name":"Scope (computer science)","level":2,"score":0.7943254709243774},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.529029130935669},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.39903542399406433},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.09097445011138916}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tifs.2025.3533899","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2025.3533899","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G1694589888","display_name":null,"funder_award_id":"62476095","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2379366273","display_name":null,"funder_award_id":"62476100","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7440696079","display_name":null,"funder_award_id":"62302173","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":55,"referenced_works":["https://openalex.org/W151377110","https://openalex.org/W1672197616","https://openalex.org/W2027595342","https://openalex.org/W2035890032","https://openalex.org/W2064675550","https://openalex.org/W2103868202","https://openalex.org/W2112796928","https://openalex.org/W2160642098","https://openalex.org/W2535838896","https://openalex.org/W2734358244","https://openalex.org/W2744999500","https://openalex.org/W2798250294","https://openalex.org/W2807363941","https://openalex.org/W2912213068","https://openalex.org/W2934843808","https://openalex.org/W2990595670","https://openalex.org/W2995022099","https://openalex.org/W3175919946","https://openalex.org/W4213446860","https://openalex.org/W4221129260","https://openalex.org/W4226047321","https://openalex.org/W4285166735","https://openalex.org/W4288057793","https://openalex.org/W4290948380","https://openalex.org/W4311167586","https://openalex.org/W4378195077","https://openalex.org/W4385187226","https://openalex.org/W4387359750","https://openalex.org/W4388856889","https://openalex.org/W4390871473","https://openalex.org/W4390874361","https://openalex.org/W4391406919","https://openalex.org/W4392477550","https://openalex.org/W4393973474","https://openalex.org/W4401980693","https://openalex.org/W6635487554","https://openalex.org/W6637373629","https://openalex.org/W6684512959","https://openalex.org/W6728757088","https://openalex.org/W6743581629","https://openalex.org/W6743688258","https://openalex.org/W6743821447","https://openalex.org/W6748786018","https://openalex.org/W6752600739","https://openalex.org/W6761040187","https://openalex.org/W6770634426","https://openalex.org/W6771533808","https://openalex.org/W6780640148","https://openalex.org/W6784747331","https://openalex.org/W6787633081","https://openalex.org/W6787656162","https://openalex.org/W6787972765","https://openalex.org/W6804490005","https://openalex.org/W6839074529","https://openalex.org/W7056673059"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W4320031223","https://openalex.org/W4200629851","https://openalex.org/W4281902577","https://openalex.org/W4309417370","https://openalex.org/W4292107232","https://openalex.org/W3009072493","https://openalex.org/W4401407399"],"abstract_inverted_index":{"Federated":[0],"learning":[1],"(FL)":[2],"allows":[3],"multiple":[4],"clients":[5],"to":[6,16,26,41,45,101,117,132,172],"train":[7],"an":[8],"efficient":[9],"deep-learning":[10],"model":[11],"collaboratively":[12],"but":[13,175],"is":[14],"susceptible":[15],"backdoor":[17,89,106,136],"attacks.":[18,47],"Traditional":[19],"detection-based":[20],"defenses":[21,62,155],"depend":[22],"on":[23,38,64],"specific":[24],"metrics":[25,40],"distinguish":[27],"client":[28],"gradients.":[29,93,137],"Defense-aware":[30],"attackers":[31],"exploit":[32],"this":[33],"by":[34,85,156],"constraining":[35],"attack":[36,92,170],"gradients":[37],"these":[39],"evade":[42,173],"detection,":[43],"leading":[44],"metric-constrained":[46],"This":[48],"paper":[49],"concretely":[50],"instantiates":[51],"such":[52],"threats":[53],"and":[54,98,108,134,146],"introduces":[55],"cosine-constrained":[56,80,163],"attacks,":[57],"which":[58],"successfully":[59],"compromise":[60],"advanced":[61],"based":[63],"cosine":[65,83],"distance.":[66],"To":[67],"address":[68],"the":[69,87,103,162,185],"aforementioned":[70],"challenge,":[71],"we":[72,121,166],"propose":[73],"Scope,":[74,174],"a":[75,123,157,168],"novel":[76,124],"defense":[77],"that":[78,150],"detects":[79],"attacks":[81],"using":[82],"distance":[84],"exposing":[86],"constrained":[88],"dimensions":[90,107],"of":[91,187],"Scope":[94,151],"employs":[95],"dimension-wise":[96],"normalization":[97],"differential":[99],"scaling":[100],"amplify":[102],"distinction":[104],"between":[105],"benign":[109],"or":[110],"unused":[111],"ones,":[112],"countering":[113],"sophisticated":[114],"attackers\u2019":[115],"attempts":[116],"obscure":[118],"them.":[119],"Moreover,":[120],"develop":[122],"clustering":[125],"approach,":[126],"namely":[127],"Dominant":[128],"Gradient":[129],"Clustering":[130],"(DGC),":[131],"isolate":[133],"eliminate":[135],"Extensive":[138],"experiments":[139],"across":[140],"various":[141],"datasets,":[142],"models,":[143],"FL":[144],"settings,":[145],"adversary":[147],"scenarios":[148],"demonstrate":[149],"consistently":[152],"outperforms":[153],"existing":[154],"significant":[158],"margin,":[159],"especially":[160],"against":[161],"attack.":[164],"Additionally,":[165],"present":[167],"Scope-tailored":[169],"designed":[171],"it":[176],"remains":[177],"ineffective":[178],"even":[179],"when":[180],"maximizing":[181],"stealthiness,":[182],"further":[183],"underscoring":[184],"robustness":[186],"Scope.":[188],"We":[189],"release":[190],"our":[191],"source":[192],"code":[193],"at:":[194],"<uri":[195],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[196],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">https://github.com/siquanhuang/Scope</uri>.":[197]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":7}],"updated_date":"2026-04-26T08:31:28.666265","created_date":"2025-10-10T00:00:00"}
