| [1] LIU T, ZHANG Y, FENG Z, et al. Beyond traditional threats: A persistent backdoor attack on federated learning [C]//Proceedings of the AAAI Conference on Artificial Intelligence. Palo Alto: AAAI, 2024: 21359-21367.
[2] ZHANG Z, PANDA A, SONG L, et al. Neurotoxin: Durable backdoors in federated learning[C]//Proceedings of the 39th International Conference on Machine Learning. Cambridge, MA: PMLR, 2022: 26429-26446.
[3] BAGDASARYAN E, VEIT A, HUA Y, et al. How to backdoor federated learning[C]//Proceedings of the 23rd International Conference on Artificial Intelligence and Statistics. Cambridge, MA: PMLR, 2020: 2938-2948.
[4] XIE C, HUANG K, CHEN P Y, et al. DBA: Distributed backdoor attacks against federated learning[EB/OL]. 8th International Conference on Learning Representations, ICLR 2020. (2020-04-26)[2025-08-15]. https://openreview.net/forum?id=rkgyS0VFvr.
[5] WENGER E, PASSANANTI J, BHAGOJI A N, et al. Backdoor attacks against deep learning systems in the physical world [C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. Piscataway, NJ: IEEE, 2021: 6206?6215.
[6] DAI Y, LI S. Chameleon: Adapting to peer images for planting durable backdoors in federated learning[C]//Proceedings of the 40th International Conference on Machine Learning. Cambridge, MA: PMLR, 2023: 6712-6725.
[7] WANG H, SREENIVASAN K, RAJPUT S, et al. Attack of the tails: Yes, you really can backdoor federated learning[EB/OL].(2020-12-06)[2025-08-15]. https://proceedings.neurips.cc/paper/2020.
[8] LI M, WAN W, NING Y, et al. DarkFed: A data?free backdoor attack in federated learning [EB/OL]. 2024[2025-08-15]. https://arxiv.org/abs/2405.03299.
[9] BAGDASARYAN E, SHMATIKOV V. Blind backdoors in deep learning models[EB/OL]. (2021-08-11)[2025-08-15]. https://www.usenix.org/conference/usenixsecurity21/presentation/bagdasaryan.
[10] LYU X, HAN Y, WANG W, et al. Poisoning with Cerberus: Stealthy and colluded backdoor attack against federated learning [C]//Proceedings of the AAAI Conference on Artificial Intelligence. Palo Alto: AAAI, 2023, 37: 9020?9028.
[11] NGUYEN T D, NGUYEN T A, TRAN A, et al. IBA: Towards irreversible backdoor attacks in federated learning [C]//Advances in Neural Information Processing Systems. Red Hook, NY: Curran Associates, 2023: 66364-66376.
[12] ZHANG H, JIA J, CHEN J, et al. A3FL: Adversarially adaptive backdoor attacks to federated learning [C]//Advances in Neural Information Processing Systems. Red Hook, NY: Curran Associates, 2023: 61213?61233.
[13] RIEGER P, NGUYEN T D, MIETTINEN M, et al. DeepSight: Mitigating backdoor attacks in federated learning through deep model inspection[EB/OL]. 29th Annual Network and Distributed System Security Symposium. San Diego, California, USA: NDSS , 2022: 24-28.
[14] SUN Z, KAIROUZ P, SURESH A T, et al. Can you really backdoor federated learning?[EB/OL]. 2019[2025-08-15]. https://arxiv.org/abs/1911.07963.
[15] OZDAYI M S, KANTARCIOGLU M, GEL Y R. Defending against backdoors in federated learning with robust learning rate[C]//Proceedings of the AAAI Conference on Artificial Intelligence. Palo Alto: AAAI, 2021: 9268-9276.
[16] ANDREINA S, MARSON G A, M?LLERING H, et al. BAFFLe: Backdoor detection via feedback-based federated learning[C]//2021 IEEE 41st International Conference on Distributed Computing Systems. Piscataway, NJ: IEEE, 2021: 852-863.
[17] MCMAHAN B, MOORE E, RAMAGE D, et al. Communication-efficient learning of deep networks from decentralized data[C]//Proceedings of the 20th International Conference on Artificial Intelligence and Statistics. Cambridge, MA: PMLR, 2017: 1273-1282.
[18] KHOSLA P, TETERWAK P, WANG C, et al. Supervised contrastive learning[C]//Advances in Neural Information Processing Systems. Red Hook, NY: Curran Associates, 2020: 18661-18673. |