| 1 |
MCMAHAN H B, MOORE E, RAMAGE D, et al. Communication-efficient learning of deep networks from decentralized data[EB/OL]. [2025-02-10]. https://arxiv.org/pdf/1602.05629.
|
| 2 |
吴若岚, 陈玉玲, 豆慧, 等. 抗攻击的联邦学习隐私保护算法. 计算机工程, 2025, 51 (2): 179- 187.
doi: 10.19678/j.issn.1000-3428.0068705
|
|
WU R L , CHEN Y L , DOU H , et al. Privacy preserving algorithm using federated learning against attacks. Computer Engineering, 2025, 51 (2): 179- 187.
doi: 10.19678/j.issn.1000-3428.0068705
|
| 3 |
熊世强, 何道敬, 王振东, 等. 联邦学习及其安全与隐私保护研究综述. 计算机工程, 2024, 50 (5): 1- 15.
|
|
XIONG S Q , HE D J , WANG Z D , et al. Review of federated learning and its security and privacy protection. Computer Engineering, 2024, 50 (5): 1- 15.
|
| 4 |
张世文, 陈双, 梁伟, 等. 联邦学习中的攻击手段与防御机制研究综述. 计算机工程与应用, 2024, 60 (5): 1- 16.
|
|
ZHANG S W , CHEN S , LIANG W , et al. Survey on attack methods and defense mechanisms in federated learning. Computer Engineering and Applications, 2024, 60 (5): 1- 16.
|
| 5 |
|
| 6 |
WANG Y L , ZHAO M H , LI S H , et al. Dispersed pixel perturbation-based imperceptible backdoor trigger for image classifier models. IEEE Transactions on Information Forensics and Security, 2022, 17, 3091- 3106.
doi: 10.1109/TIFS.2022.3202687
|
| 7 |
NING R, LI J, XIN C S, et al. Hibernated backdoor: a mutual information empowered backdoor attack to deep neural networks[C]//Proceedings of the AAAI Conference on Artificial Intelligence. Palo Alto, USA: AAAI Press, 2022: 10309-10318.
|
| 8 |
LI S F , XUE M H , ZHAO B Z H , et al. Invisible backdoor attacks on deep neural networks via steganography and regularization. IEEE Transactions on Dependable and Secure Computing, 2021, 18 (5): 2088- 2105.
|
| 9 |
ZHAO S H, MA X J, ZHENG X, et al. Clean-label backdoor attacks on video recognition models[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Washington D.C., USA: IEEE Press, 2020: 14431-14440.
|
| 10 |
|
| 11 |
BARNI M, KALLAS K, TONDI B. A new backdoor attack in CNNS by training set corruption without label poisoning[C]//Proceedings of the IEEE International Conference on Image Processing (ICIP). Washington D.C., USA: IEEE Press, 2019: 101-105.
|
| 12 |
|
| 13 |
LIN D Q, GUO Y C, SUN H, et al. FedCluster: a federated learning framework for cross-device private ECG classification[C]//Proceedings of the IEEE INFOCOM Conference on Computer Communications Workshops. Washington D.C., USA: IEEE Press, 2022: 1-6.
|
| 14 |
CAO X Y, GONG N Z. MPAF: model poisoning attacks to federated learning based on fake clients[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition Workshops (CVPRW). Washington D.C., USA: IEEE Press, 2022: 3395-3403.
|
| 15 |
SAHA A, SUBRAMANYA A, PIRSIAVASH H. Hidden trigger backdoor attacks[C]//Proceedings of the AAAI Conference on Artificial Intelligence. Palo Alto, USA: AAAI Press, 2020: 11957-11965.
|
| 16 |
CHELLAPPA R, FOWL L, GOLDBLUM M, et al. Sleeper agent: scalable hidden trigger backdoors for neural networks trained from scratch[C]//Proceedings of the Advances in Neural Information Processing Systems 35. Louisiana, USA: Neural Information Processing Systems Foundation, Inc, 2022: 19165-19178.
|
| 17 |
NING R, LI J, XIN C S, et al. Invisible poison: a blackbox clean label backdoor attack to deep neural networks[C]//Proceedings of the IEEE Conference on Computer Communications. Washington D.C., USA: IEEE Press, 2021: 1-10.
|
| 18 |
QUIRING E, RIECK K. Backdooring and poisoning neural networks with image-scaling attacks[C]//Proceedings of the IEEE Security and Privacy Workshops (SPW). Washington D.C., USA: IEEE Press, 2020: 41-47.
|
| 19 |
|
| 20 |
|
| 21 |
XIE C L, HUANG K L, CHEN P Y, et al. DBA: distributed backdoor attacks against federated learning[C]//Proceedings of International Conference on Learning Representations. New York, USA: [s. n], 2019: 1-10.
|
| 22 |
|
| 23 |
ZENG Y, PAN M Z, JUST H A, et al. Narcissus: a practical clean-label backdoor attack with limited information[C]//Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security. New York, USA: ACM Press, 2023: 771-785.
|
| 24 |
SHANNON C E . Communication theory of secrecy systems. Bell System Technical Journal, 1949, 28 (4): 656- 715.
doi: 10.1002/j.1538-7305.1949.tb00928.x
|
| 25 |
LI Y M. Poisoning-based backdoor attacks in computer vision[C]//Proceedings of the AAAI Conference on Artificial Intelligence. Palo Alto, USA: AAAI Press, 2023: 16121-16122.
|
| 26 |
JIANG W B, LI H W, XU G W, et al. Color backdoor: a robust poisoning attack in color space[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR). Washington D.C., USA: IEEE Press, 2023: 8133-8142.
|
| 27 |
|
| 28 |
ZHONG H T, LIAO C, SQUICCIARINI A C, et al. Backdoor embedding in convolutional neural network models via invisible perturbation[C]//Proceedings of the 10th ACM Conference on Data and Application Security and Privacy. New York, USA: ACM Press, 2020: 97-108.
|
| 29 |
LI Z S, CHEN M M, HE Y F, et al. An efficient framework for detection and recognition of numerical traffic signs[C]//Proceedings of IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP). Washington D.C., USA: IEEE Press, 2022: 2235-2239.
|
| 30 |
BAN Y H, DONG Y P. Pre-trained adversarial perturbations[C]//Proceedings of the Advances in Neural Information Processing Systems 35. New Orleans, USA: Neural Information Processing Systems Foundation, Inc. 2022: 1196-1209.
|
| 31 |
|
| 32 |
ZHANG Z, PANDA A, SONG L, et al. Neurotoxin: durable backdoors in federated learning[C]//Proceedings of International Conference on Machine Learning. New York, USA: [s. n], 2022: 26429-26446.
|
| 33 |
LYU X T, HAN Y F, WANG W, et al. Poisoning with cerberus: stealthy and colluded backdoor attack against federated learning[C]// Proceedings of the AAAI Conference on Artificial Intelligence. Palo Alto, USA: AAAI Press, 2023: 9020-9028.
|
| 34 |
ANTONANTE P, VEER S, LEUNG K, et al. Task-aware risk estimation of perception failures for autonomous vehicles[EB/OL]. [2025-02-10]. https://arxiv.org/abs/2305.01870.
|
| 35 |
PASZKE A, LERER A, KILLEN T, et al. PyTorch: an imperative style, high-performance deep learning library[C]//Proceedings of Conference on Advances in Neural Information Processing Systems. New York, USA: [s. n], 2019, 32.
|
| 36 |
|
| 37 |
STALLKAMP J, SCHLIPSING M, SALMEN J, et al. The German traffic sign recognition benchmark: a multi-class classification competition[C]//Proceedings of the 2011 International Joint Conference on Neural Networks. Washington D.C., USA: IEEE Press, 2011: 1453-1460.
|
| 38 |
HE K M, ZHANG X Y, REN S Q, et al. Deep residual learning for image recognition[C]//Proceedings of the IEEE Conference on Computer Vision and Pattern Recognition. Washington D.C., USA: IEEE Press, 2016: 770-778.
|
| 39 |
万志成, 郑静. 基于狄利克雷过程高斯混合模型的变分推断. 杭州电子科技大学学报(自然科学版), 2021, 41 (5): 54- 61.
|
|
WAN Z C , ZHEGN J . Variational inference for Gaussian mixture model based on Dirichlet process. Journal of Hangzhou University (Natural Sciences), 2021, 41 (5): 54- 61.
|
| 40 |
|
| 41 |
GU T Y, DOLAN-GAVITT B, GARG S. BadNets: identifying vulnerabilities in the machine learning model supply chain[EB/OL]. [2025-02-10]. https://arxiv.org/pdf/1708.06733.
|
| 42 |
COLAS C, SIGAUD O, OUDEYER P Y. How many random seeds? statistical power analysis in deep reinforcement learning experiments[EB/OL]. [2025-02-10]. https://arxiv.org/pdf/1806.08295.
|
| 43 |
NGUYEN T D , NGUYEN T , LE NGUYEN P , et al. Backdoor attacks and defenses in federated learning: survey, challenges and future research directions. Engineering Applications of Artificial Intelligence, 2024, 127, 107166.
doi: 10.1016/j.engappai.2023.107166
|
| 44 |
GONG X , CHEN Y , WANG Q , et al. Backdoor attacks and defenses in federated learning: state-of-the-art, taxonomy, and future directions. IEEE Wireless Communications, 2022, 30 (2): 114- 121.
|
| 45 |
SWARTZ C A . Some geometrical properties of residual maps. Geophysics, 1954, 19 (1): 46- 70.
doi: 10.1190/1.1437970
|
| 46 |
WANG Z , BOVIK A C , SHEIKH H R , et al. Image quality assessment: from error visibility to structural similarity. IEEE Transactions on Image Processing, 2004, 13 (4): 600- 612.
doi: 10.1109/TIP.2003.819861
|
| 47 |
ZHANG R, ISOLA P, EFROS A A, et al. The unreasonable effectiveness of deep features as a perceptual metric[C]//Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition. Washington D.C., USA: IEEE Press, 2018: 586-595.
|
| 48 |
|
| 49 |
CHEN Y D, SU L L, XU J M. Distributed statistical machine learning in adversarial settings: Byzantine gradient descent[C]//Proceedings of the ACM on Measurement and Analysis of Computing Systems. New York, USA: ACM Press, 2017: 1-25.
|
| 50 |
DAMASKINOS G, MHAMDI E M E, GUERRAOUI R, et al. Asynchronous Byzantine machine learning (the case of SGD)[EB/OL]. [2025-02-10]. https://arxiv.org/pdf/1802.07928.
|
| 51 |
XIE C, KOYEJO O, GUPTA I. Zeno: distributed stochastic gradient descent with suspicion-based fault-tolerance[EB/OL]. [2025-02-10]. https://arxiv.org/abs/1805.10032.
|
| 52 |
YIN D, CHEN Y D, KANNAN R, et al. Byzantine-robust distributed learning: towards optimal statistical rates[EB/OL]. [2025-02-10]. https://arxiv.org/pdf/1803.01498.
|
| 53 |
|
| 54 |
|
| 55 |
|