| [1] |
Deng S, Zhao H, Fang W, et al. Edge intelligence: the confluence of edge computing and artificial intelligence[J]. IEEE Internet of Things Journal, 2020, 7(8): 7457-7469.
|
| [2] |
McMahan H B, Moore E, Ramage D, et al. Communication-efficient learning of deep networks from decentralized data [C]// AISTATS 2017. New York: JMLR.org, 2017: 1273-1282.
|
| [3] |
Beltrán E T M, Pérez M Q, Sánchez P M S, et al. Decentralized federated learning: fundamentals, state of the art, frameworks, trends, and challenges [J]. IEEE Communications Surveys and Tutorials, 2023, 25(4): 2983-3013.
|
| [4] |
Gong X, Chen Y, Wang Q, et al. Backdoor attacks and defenses in federated learning: state-of-the-art, taxonomy, and future directions [J]. IEEE Wireless Communications, 2023, 30(2): 114-121.
|
| [5] |
Liu T, Zhang Y, Feng Z, et al. Beyond traditional threats: a persistent backdoor attack on federated learning [C]// AAAI 2024. Palo Alto: AAAI Press, 2024: 21359-21367.
|
| [6] |
Han X, Zhang X, Lan X, et al. BadSFL: backdoor attack against scaffold federated learning [PP/OL]. V2. arXiv (2024-11-26) [2025-01-23]. .
|
| [7] |
Li S, Cheng Y, Wang W, et al. Learning to detect malicious clients for robust federated learning [PP/OL]. arXiv (2020-02-01) [2025-02-02]. .
|
| [8] |
Wang H, Sreenivasan K, Rajput S, et al. Attack of the tails: yes, you really can backdoor federated learning [C]// NeurIPS 2020. Red Hook: Curran Associates Inc., 2020: 16070-16084.
|
| [9] |
Molina Coronado B. Celtibero: robust layered aggregation for federated learning [PP/OL]. V2. arXiv (2018-09-20) [2025-02-12]. .
|
| [10] |
Chen H, Chen X, Peng L, et al. FLRAM: robust aggregation technique for defense against Byzantine poisoning attacks in federated learning [J]. Electronics, 2023, 12(21): No.4463.
|
| [11] |
Mai P, Yan R, Pang Y. RFLPA: a robust federated learning framework against poisoning attacks with secure aggregation [C]// NeurIPS 2024. Red Hook: Curran Associates Inc., 2024: 104329-104356.
|
| [12] |
Zhang Z, Cao X, Jia J, et al. FLDetector: defending federated learning against model poisoning attacks via detecting malicious clients [C]// KDD 2022. New York: ACM, 2022: 2545-2555.
|
| [13] |
陈谦,柴政,王子龙,等.基于生成对抗网络的联邦学习中投毒攻击检测方案[J].计算机应用, 2023, 43(12): 3790-3798.
|
|
Chen Qian, Chai Zheng, Wang Zilong, et al. Poisoning attack detection scheme based on generative adversarial network for federated learning [J]. Journal of Computer Applications, 2023, 43(12): 3790-3798.
|
| [14] |
Han S, Wu W, Buyukates B, et al. Kick bad guys out! conditionally activated anomaly detection in federated learning with zero-knowledge proof verification [PP/OL]. V4. arXiv (2024-10-07) [2025-03-10]. .
|
| [15] |
Ghosh A, Hong J, Yin D, et al. Robust federated learning in a heterogeneous environment [PP/OL]. V2. arXiv (2019-10-09) [2025-03-12]. .
|
| [16] |
Bagdasaryan E, Veit A, Hua Y, et al. How to backdoor federated learning [C]// AISTATS 2020. New York: JMLR.org, 2020: 2938-2948.
|
| [17] |
Blanchard P, El Mhamdi E M, Guerraoui R, et al. Machine learning with adversaries: Byzantine tolerant gradient descent [C]// NeurIPS 2017. Red Hook: Curran Associates Inc., 2017: 118-128.
|
| [18] |
Pillutla K, Kakade S M, Harchaoui Z. Robust aggregation for federated learning [J]. IEEE Transactions on Signal Processing, 2022, 70: 1142-1154.
|
| [19] |
Hao L, Hao K, Wei B, et al. Multi-target federated backdoor attack based on feature aggregation [J]. Pattern Recognition, 2026, 172(Pt A): No.112333.
|
| [20] |
Xie C, Chen M, Chen P Y, et al. CRFL: certifiably robust federated learning against backdoor attacks [C]// ICML 2021. New York: JMLR.org, 2021: 11372-11382.
|
| [21] |
Nguyen T D, Rieger P, Chen H, et al. FLAME: taming backdoors in federated learning [C]// USENIX Security 2022. Berkeley: USENIX Association, 2022: 1415-1432.
|
| [22] |
Fung C, Yoon C J M, Beschastnikh I. The limitations of federated learning in Sybil settings [C]// RAID 2020. Berkeley: USENIX Association, 2020: 301-316.
|
| [23] |
Xu J, Zhang Z, Hu R. Detecting backdoor attacks in federated learning via direction alignment inspection [C]// CVPR 2025. Piscataway: IEEE, 2025: 20654-20664.
|
| [24] |
Huang S, Li Y, Chen C, et al. Multi-metrics adaptively identifies backdoors in federated learning [C]// ICCV 2023. Piscataway: IEEE, 2023: 4629-4639.
|
| [25] |
Purohit K, Das S, Bhattacharya S, et al. A data-driven defense against edge-case model poisoning attacks on federated learning [PP/OL]. V2. arXiv (2024-08-14) [2025-01-02]. .
|
| [26] |
Huang S, Li Y, Yan X, et al. Scope: on detecting constrained backdoor attacks in federated learning [J]. IEEE Transactions on Information Forensics and Security, 2025, 20: 3302-3315.
|
| [27] |
Wang S, Hayase J, Fanti G, et al. Towards a defense against federated backdoor attacks under continuous training [PP/OL]. V4. arXiv (2023-01-31) [2025-03-27]. .
|
| [28] |
Chen M, Mao B, Ma T. FedSA: a staleness-aware asynchronous federated learning algorithm with non-IID data [J]. Future Generation Computer Systems, 2021, 120: 1-12.
|
| [29] |
Uddin M P, Xiang Y, Hasan M, et al. A systematic literature review of robust federated learning: issues, solutions, and future research directions [J]. ACM Computing Surveys, 2025, 57(10): No.245.
|
| [30] |
陈学斌,屈昌盛.面向联邦学习的后门攻击与防御综述[J].计算机应用, 2024, 44(11): 3459-3469.
|
|
Chen Xuebin, Qu Changsheng. Overview of backdoor attacks and defenses in federated learning [J]. Journal of Computer Applications, 2024, 44(11): 3459-3469.
|