{"as_of":"2026-08-17T12:19:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:82a6d868b44cdf1fcb0d16b1321f5e70ec9eed70c2ded3039edf5591f0159baf","coverage":[{"denominator":76,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":76,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-15T20:46:59.463287Z","state":"measured"},{"denominator":77,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":77,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-17T06:30:58.91139+00:00","state":"measured"},{"denominator":1,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":1,"source":"paper_references, paper_reference_links","source_observed_at":"2026-05-11T02:06:13.515696Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-05-11T03:55:57.345828Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"cited_work":{"arxiv_id":"2505.12019","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2505.12019","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Fl-plas: Federated learning with partial layer aggregation for backdoor defense against high-ratio malicious clients","venue":null,"work_id":"cb4e3371-0065-4a14-85e1-81fe65aa6079","year":2025},"citing_paper":{"arxiv_id":"2605.07860","last_updated":"2026-05-08T15:20:22Z","snapshot_observed_at":"2026-08-12T13:57:39.116506Z","submitted_at":"2026-05-08T15:20:22Z","title":"On the Tradeoffs of On-Device Generative Models in Federated Predictive Maintenance Systems","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-05-11T02:06:13.515696Z"},"links":{"cited_paper":"/paper/2505.12019","citing_paper":"/paper/2605.07860"},"observation_digest":"sha256:4d30f0a2383c51de327871dc89937ebd678f8813238a28462feb6bd3711a9250","observation_id":"4475419d-606b-4985-9937-407bc42c8d28","resolution":{"observed_at":"2026-05-11T03:55:57.347877Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2505.12019/citation-record","integrity":"/paper/2505.12019/integrity","json":"/paper/2505.12019/citation-record.json","paper":"/paper/2505.12019"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"1610.05492","last_updated":"2017-10-30T20:52:14Z","snapshot_observed_at":"2026-08-13T17:19:46.488095Z","submitted_at":"2016-10-18T09:11:51Z","title":"Federated Learning: Strategies for Improving Communication Efficiency","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1610.05492","snapshot_observed_at":"2026-08-15T20:46:59.156571Z","title":"Federated learning: Strategies for improving communication efficiency","venue":null,"work_id":null,"year":2016},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.156571Z"},"links":{"cited_paper":"/paper/1610.05492","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:fe4915628c16652875c3946b8c11c831d06f8722f2b3e876cbabd1ea92726b17","observation_id":"628a6754-36c9-463d-ad77-b9f32a785887","resolution":{"observed_at":"2026-08-15T20:46:59.156571Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.434819Z","title":"Communication- efficient learning of deep networks from decentralized data","venue":null,"work_id":"8480e05b-faca-466e-98f8-8a4656366105","year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.161816Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:d2d0fa9aadc5cfdbe937bec38e83a7fa134b0f59df96986d7facfa4d0e88d164","observation_id":"b5fc46fe-38a7-410b-bfbe-a04d8ca3d162","resolution":{"observed_at":"2026-08-15T20:47:00.439682Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.422325Z","title":"Vulnerabilities in federated learning","venue":null,"work_id":"313548c2-71e2-4acb-a25c-8183c73d2e4f","year":2021},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.166106Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:5d22d84897f40a8246bc82ec1caa96b4a7cc093b964a2ab102544b2eefb2e9f9","observation_id":"a7c53513-f035-41f3-9c53-fe64eab88e78","resolution":{"observed_at":"2026-08-15T20:47:00.426555Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.410048Z","title":"Defending against backdoors in federated learning with robust learning rate","venue":null,"work_id":"2d2f78b5-3a4f-457a-8399-d8bd4120fa06","year":2021},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.170781Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:e2a26c4991af822cc60a7edfe787d6c28b1489daf9e0a8419be7951739bf528b","observation_id":"216bdf9b-6d02-47a2-9e3b-e3b7a4cd4cfc","resolution":{"observed_at":"2026-08-15T20:47:00.414155Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1712.05526","last_updated":"2017-12-15T04:26:26Z","snapshot_observed_at":"2026-07-06T06:14:30.795326Z","submitted_at":"2017-12-15T04:26:26Z","title":"Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1712.05526","snapshot_observed_at":"2026-08-15T20:46:59.174973Z","title":"Targeted backdoor attacks on deep learning systems using data poisoning","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.174973Z"},"links":{"cited_paper":"/paper/1712.05526","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:6c12209cbbb62eb7d231aa81e6b87089e0dc0d5d5cf5aa41f004dc423a980411","observation_id":"4052a6b0-f4ab-4edd-8209-07c3f7fb0395","resolution":{"observed_at":"2026-08-15T20:46:59.174973Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1708.06733","last_updated":"2019-03-11T20:45:33Z","snapshot_observed_at":"2026-08-12T15:43:59.037380Z","submitted_at":"2017-08-22T17:31:54Z","title":"BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1708.06733","snapshot_observed_at":"2026-08-15T20:46:59.179416Z","title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.179416Z"},"links":{"cited_paper":"/paper/1708.06733","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:c91dfd1e097216dd6da51c6f98120a809ae9e4dc56c07314a395cd8d83ea4921","observation_id":"0c12bd55-f91a-4f47-8e07-df0e95e65c6a","resolution":{"observed_at":"2026-08-15T20:46:59.179416Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.397508Z","title":"How to backdoor federated learning","venue":null,"work_id":"aca490d7-83cc-45fb-a498-02357de04709","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.184255Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:291cc8a0357dde4ed4613a5dd19160911ae3e81c6b9ddd846c0b27ab9a6714bc","observation_id":"e9e0ea98-9d14-41b9-867d-df94004f5ba1","resolution":{"observed_at":"2026-08-15T20:47:00.401443Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.383531Z","title":"Data poisoning attacks against federated learning systems","venue":null,"work_id":"ba42d4a1-494b-48f6-b448-0f724001ee99","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.188343Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:d66489affbcacc0be2f7b1745b2d6ac474e3df736f357e2ccba3c32463cf9e05","observation_id":"fbec6874-2126-4fca-90d7-42eac3d30eae","resolution":{"observed_at":"2026-08-15T20:47:00.388565Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.369827Z","title":"Lfighter: Defend- ing against the label-flipping attack in federated learning","venue":null,"work_id":"ddf2b4cd-ec94-4bfb-90a7-c1c680036939","year":2024},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.192482Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:99f86a6f6e492992162ed59de1b37d55c669540ee735d3ea5c1f0d59eaecc519","observation_id":"4ddc3bfd-161d-49dc-898b-14cba833af26","resolution":{"observed_at":"2026-08-15T20:47:00.374034Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2007.05084","last_updated":"2020-07-09T21:50:54Z","snapshot_observed_at":"2026-08-16T01:57:26.654751Z","submitted_at":"2020-07-09T21:50:54Z","title":"Attack of the Tails: Yes, You Really Can Backdoor Federated Learning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2007.05084","snapshot_observed_at":"2026-08-15T20:46:59.196443Z","title":"Attack of the tails: Yes, you really can backdoor federated learning","venue":null,"work_id":null,"year":2007},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.196443Z"},"links":{"cited_paper":"/paper/2007.05084","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:43932eb7b3562cc8cd0a4f4336f26e88521d0aba6c43d53e2a2dd5da9bd4e65a","observation_id":"9d9f491b-2da7-4b4d-8870-9d9ce40fe085","resolution":{"observed_at":"2026-08-15T20:46:59.196443Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.357407Z","title":"On the vulnerability of backdoor defenses for federated learning","venue":null,"work_id":"58276fc1-500b-4cbf-b201-b795164fa17e","year":2023},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.200875Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:7817f135771ca36a1b895b93e415ca69a04543e30b4890a3cc946c38f8922aee","observation_id":"2eae8392-1c94-491d-bcf9-410386682d16","resolution":{"observed_at":"2026-08-15T20:47:00.361357Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.344524Z","title":"Backdoor federated learning by poisoning backdoor-critical layers","venue":null,"work_id":"41dc0e39-749f-4079-a7f9-994e64c6d9be","year":2024},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.204839Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:9fd0d893b9ac571138e3663dca6f17ed08b2d8e02340a03816230d340f87da65","observation_id":"dade1b77-8672-43fc-a441-6e3797517e6a","resolution":{"observed_at":"2026-08-15T20:47:00.349004Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2003.02133","last_updated":"2020-03-04T15:30:10Z","snapshot_observed_at":"2026-08-15T13:53:57.947911Z","submitted_at":"2020-03-04T15:30:10Z","title":"Threats to Federated Learning: A Survey","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2003.02133","snapshot_observed_at":"2026-08-15T20:46:59.208880Z","title":"Threats to federated learning: A survey.arXiv preprint arXiv:2003.02133, 2020","venue":null,"work_id":null,"year":2003},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.208880Z"},"links":{"cited_paper":"/paper/2003.02133","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:6f1933d84a5cdf59f6e4e414e187448681ef518d66c2d07abfc8b91fce2fac32","observation_id":"260aae2f-dcd6-49cd-8d80-cee6be1c9eb0","resolution":{"observed_at":"2026-08-15T20:46:59.208880Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.331253Z","title":"Giannakis, and Qing Ling","venue":null,"work_id":"4953ad00-3527-457a-83b8-210857f25ec0","year":2019},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.212952Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:a4931bc1ab346afccb899547caccb6981bd8d52c39243418d928a6dfd9e4a400","observation_id":"4196438b-f561-404c-a943-45fdf616d445","resolution":{"observed_at":"2026-08-15T20:47:00.335692Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1911.07963","last_updated":"2019-12-02T19:00:11Z","snapshot_observed_at":"2026-08-09T08:16:29.597021Z","submitted_at":"2019-11-18T21:25:03Z","title":"Can You Really Backdoor Federated Learning?","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1911.07963","snapshot_observed_at":"2026-08-15T20:46:59.216845Z","title":"Can you really backdoor federated learning? arXiv preprint arXiv:1911.07963, 2019","venue":null,"work_id":null,"year":1911},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.216845Z"},"links":{"cited_paper":"/paper/1911.07963","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:3c25efd495a71f709121793bb71772c0697ff2dacf54307c9c8efd85900405fa","observation_id":"2746a314-7624-4552-bad3-e67725cc083a","resolution":{"observed_at":"2026-08-15T20:46:59.216845Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2002.00211","last_updated":"2020-02-01T14:09:48Z","snapshot_observed_at":"2026-08-07T00:07:33.465634Z","submitted_at":"2020-02-01T14:09:48Z","title":"Learning to Detect Malicious Clients for Robust Federated Learning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2002.00211","snapshot_observed_at":"2026-08-15T20:46:59.220971Z","title":"Learning to detect malicious clients for robust federated learning","venue":null,"work_id":null,"year":2002},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.220971Z"},"links":{"cited_paper":"/paper/2002.00211","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:4ee01d8bcda49064a81b02f9cadae18810bf5ae9203db550c0f7d031bcddc28f","observation_id":"662c3bd4-b52a-457d-945c-3521099037d5","resolution":{"observed_at":"2026-08-15T20:46:59.220971Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.317787Z","title":"Fltrust: Byzantine-robust federated learning via trust bootstrapping","venue":null,"work_id":"ef25ce8e-170c-4eb1-9524-1b92ab28a09f","year":2021},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.225007Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:c7ae786ad94db3e41ab294f0e9912d920fe67b517189e0946ea93fe138679f33","observation_id":"6b06f5ce-e3dd-47df-a078-02afdb49dd51","resolution":{"observed_at":"2026-08-15T20:47:00.322445Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.228856Z","title":"{FLAME}: Taming backdoors in federated learning","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.228856Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:35f58f9089c350e91cf28b08acea269954f3b4fa5c977ae98ba0efa3d008b98f","observation_id":"565313d2-c4e7-4185-bba9-2b9df3d1d625","resolution":{"observed_at":"2026-08-15T20:46:59.228856Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.297191Z","title":"Machine learning with adversaries: Byzantine tolerant gradient descent","venue":null,"work_id":"34759ee0-584a-4bf1-aa16-1855455ade40","year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.232920Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:6cff4faa488b36c99c0570dc4caa24aad6b001770a3cb3d0d7a3b321e08e1605","observation_id":"c5369117-0988-46bb-bd38-05b19bf38ed1","resolution":{"observed_at":"2026-08-15T20:47:00.301147Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.285231Z","title":"Backdooring convolutional neural networks via targeted weight perturbations","venue":null,"work_id":"32856758-c0bc-4c75-bc1d-338ff5105a06","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.236849Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:0f798adb1a615367426e2a5f2163f0672d0866282cd96bbdd9c0f73edfb85968","observation_id":"6a4bb6a5-936a-4190-9e4f-58049b6fcc5e","resolution":{"observed_at":"2026-08-15T20:47:00.289217Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.273326Z","title":"Data poisoning attacks and defenses to crowdsourcing systems","venue":null,"work_id":"4f373290-a731-4412-90ea-e8cd14323fb7","year":2021},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.240783Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:387bd1547b1171ed1ab3dcab1e030b1be67a78a4c0f8307a13e82e80fc80e146","observation_id":"2d548116-c73f-46d5-a0c7-fb8ea56fd084","resolution":{"observed_at":"2026-08-15T20:47:00.277203Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.261102Z","title":"Poisoning attacks to graph-based recommender systems","venue":null,"work_id":"5213d8bd-0bd1-4ae2-ba69-35bf9808a79d","year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.244691Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:a98520eb5d88d1a7444d330b83c87ed5dd57338668b45405f604ef51e3cf7f0c","observation_id":"36027c5c-3a86-429e-9b07-3093c7d9c391","resolution":{"observed_at":"2026-08-15T20:47:00.265119Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.249159Z","title":"Fake co-visitation injection attacks to recommender systems","venue":null,"work_id":"fd7fb15f-1dd8-44a7-be5c-a4da03a6db21","year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.248727Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:e5993335559e3c968f991db1868c9dc65da5d206327e9fab93513c30b4c4e040","observation_id":"3ef81319-0178-4ed5-bc1c-286135ef027f","resolution":{"observed_at":"2026-08-15T20:47:00.253075Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.236705Z","title":"Exploiting machine learning to subvert your spam filter","venue":null,"work_id":"f09180fa-55f2-4660-a125-bd630dcac697","year":2008},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.252533Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:a34d6bee8063386fe8b3fd7223f03a6150724c88c6a0ec2f90b9796873f4c53b","observation_id":"7f89b187-bcfe-4598-a64b-5a3d30cb21da","resolution":{"observed_at":"2026-08-15T20:47:00.241011Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1912.04977","last_updated":"2021-03-09T03:03:49Z","snapshot_observed_at":"2026-08-13T11:40:49.533339Z","submitted_at":"2019-12-10T20:55:41Z","title":"Advances and Open Problems in Federated Learning","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1912.04977","snapshot_observed_at":"2026-08-15T20:46:59.256703Z","title":"Advances and open problems in federated learning","venue":null,"work_id":null,"year":1912},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.256703Z"},"links":{"cited_paper":"/paper/1912.04977","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:3490e53cb38acd06c10607df4732544e90cf0c829fe5f157fd911ef728afe681","observation_id":"db390e47-3344-4f1f-9c2f-7316b56109ec","resolution":{"observed_at":"2026-08-15T20:46:59.256703Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2007.08745","last_updated":"2022-02-16T06:39:39Z","snapshot_observed_at":"2026-07-06T09:39:02.518657Z","submitted_at":"2020-07-17T04:09:20Z","title":"Backdoor Learning: A Survey","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2007.08745","snapshot_observed_at":"2026-08-15T20:46:59.260987Z","title":"Backdoor learning: A survey","venue":null,"work_id":null,"year":2007},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.260987Z"},"links":{"cited_paper":"/paper/2007.08745","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:5ba5c1ebe465cbcef660ed47282de71820090e00c3302cccb1df0f9c58920b46","observation_id":"09b0fdbc-8bed-4fe0-a594-eadbf2ef6740","resolution":{"observed_at":"2026-08-15T20:46:59.260987Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2006.09365","last_updated":"2023-11-22T09:08:15Z","snapshot_observed_at":"2026-08-07T05:21:15.626151Z","submitted_at":"2020-06-16T17:58:53Z","title":"Byzantine-Robust Learning on Heterogeneous Datasets via Bucketing","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2006.09365","snapshot_observed_at":"2026-08-15T20:46:59.265312Z","title":"Byzantine-robust learning on heterogeneous datasets via resampling","venue":null,"work_id":null,"year":2006},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.265312Z"},"links":{"cited_paper":"/paper/2006.09365","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:4537b7a325d0d0b7bd9286af741d01110688b2c82c535269db268f0e42850fbc","observation_id":"49e3a2a1-fe5f-4cba-b243-b19c2834a517","resolution":{"observed_at":"2026-08-15T20:46:59.265312Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1909.06335","last_updated":"2019-09-13T17:26:20Z","snapshot_observed_at":"2026-08-16T05:00:17.345539Z","submitted_at":"2019-09-13T17:26:20Z","title":"Measuring the Effects of Non-Identical Data Distribution for Federated Visual Classification","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1909.06335","snapshot_observed_at":"2026-08-15T20:46:59.269254Z","title":"Measuring the effects of non-identical data distribution for federated visual classification","venue":null,"work_id":null,"year":1909},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.269254Z"},"links":{"cited_paper":"/paper/1909.06335","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:0cee5143a7d61e478c717b231429a5692fe1cc07068b096d6588f9998df80a07","observation_id":"5ba3842a-91b0-45cd-a1dc-fe8b9c207107","resolution":{"observed_at":"2026-08-15T20:46:59.269254Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1412.6572","last_updated":"2015-03-20T20:19:16Z","snapshot_observed_at":"2026-08-12T17:13:46.394331Z","submitted_at":"2014-12-20T01:17:12Z","title":"Explaining and Harnessing Adversarial Examples","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1412.6572","snapshot_observed_at":"2026-08-15T20:46:59.273346Z","title":"Explaining and harnessing adversarial examples","venue":null,"work_id":null,"year":2014},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.273346Z"},"links":{"cited_paper":"/paper/1412.6572","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:40104057d07a60bb3f5cb3d1721892d8441e44e6897573087324c3f10f9abf6e","observation_id":"617e94f5-6b4e-4a2e-9c58-6f38c4f525f2","resolution":{"observed_at":"2026-08-15T20:46:59.273346Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.224464Z","title":"The limitations of deep learning in adversarial settings","venue":null,"work_id":"53f7aa8b-37b0-45d1-927f-58cedbceb66b","year":2016},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.277097Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:ec1babe391bf543d9bba5e284bb3c2fe7063551bd0a2ad5a785dd0dde95d7e58","observation_id":"4661f1e9-3062-4157-9b47-e080f3c68835","resolution":{"observed_at":"2026-08-15T20:47:00.228445Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.212011Z","title":"Terminal brain damage: Exposing the graceless degradation in deep neural networks under hardware fault attacks","venue":null,"work_id":"87039591-3633-4c05-9850-3e8621783ef9","year":2019},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.281002Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:74f6b2b6e9230f89a62a37a13cbc6f5ddf0f039162fa2acd213c3f77f0c1db18","observation_id":"e86f0cbb-4fbd-4371-8ec3-7f0d914b16ec","resolution":{"observed_at":"2026-08-15T20:47:00.216304Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.199131Z","title":"Antidote: understanding and defending against poisoning of anomaly detectors","venue":null,"work_id":"4136c549-0939-4ed5-8c5a-2a8823e39efe","year":2009},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.284854Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:8136024ac7c625decb5ce747cf7d8fc92dce1fe7c10022a5614ed5c49603b0e8","observation_id":"833223c5-bc26-427b-8ed4-f0abf23a68ad","resolution":{"observed_at":"2026-08-15T20:47:00.203431Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.187031Z","title":"Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein","venue":null,"work_id":"65d612e5-3de7-4cb5-a65b-c707507bdf3d","year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.288662Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:73980c5d2997af2eb8d7d03114501055dd0a12c2b1d9e50071ca16df68b80ecf","observation_id":"f06ecca4-5bb3-4c13-8991-59e893255fcf","resolution":{"observed_at":"2026-08-15T20:47:00.191092Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.174715Z","title":"When does machine learning fail? generalized transferability for evasion and poisoning attacks","venue":null,"work_id":"906568bf-4b3c-4b14-b376-8e7b6066287a","year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.292485Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:16bd3286ebd10ff84997f28fad3c057a537bbeb3c1a7cac9d232f82e97069820","observation_id":"e1e9185e-806b-4cb6-9984-8e0cb95ec25a","resolution":{"observed_at":"2026-08-15T20:47:00.178724Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.162004Z","title":"Attacking graph-based classification via manipulating the graph structure","venue":null,"work_id":"e9dbe5c1-8a37-4120-9fd5-827a7f508c5f","year":2019},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.296789Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:6a82d05aaea71d1531236baf3b967996c1ce8b631640c624d6ed53de3116c5c6","observation_id":"b7acef71-fe2c-4089-ad0c-d1dcf90ffb97","resolution":{"observed_at":"2026-08-15T20:47:00.166317Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.149076Z","title":"Poisoning attacks against support vector machines","venue":null,"work_id":"b132c7be-0fb8-4cfd-ac36-2edd5592fff8","year":2012},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.300741Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:f2b7d85cbf9d2dd6911dec528ba112c286ba64cced7645096d9bf5d7bf159a48","observation_id":"6daa4b75-5f16-4387-bc81-07496230f474","resolution":{"observed_at":"2026-08-15T20:47:00.153332Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.135905Z","title":"Manipulating machine learning: Poisoning attacks and countermeasures for regression learning","venue":null,"work_id":"919e4809-24ea-44b9-887d-6ade93409b85","year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.304607Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:ea5ed01a7f7ac399119e8405c2f125cea1afde24729eafa296548ff8c4158f00","observation_id":"d1b532bb-8943-4f22-9406-f239ff93afcf","resolution":{"observed_at":"2026-08-15T20:47:00.140464Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.123792Z","title":"Data poisoning attacks on factorization-based collaborative filtering","venue":null,"work_id":"b506cd03-aa36-4d0d-a8cc-379f77e3e655","year":2016},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.308466Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:bc83435a8a36945ca178aa70667543b617775b26aabb545b468b64c0835a0474","observation_id":"d18f68a5-685c-49bb-9f58-ca0aaa8b8a25","resolution":{"observed_at":"2026-08-15T20:47:00.127861Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.111575Z","title":"Towards poisoning of deep learning algorithms with back-gradient optimization","venue":null,"work_id":"142eb2ab-8419-4fba-b034-1e28cc3dbdb4","year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.312319Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:84ed6c53dc20eaebb145165f1fd25de0950bc1099c5fecfbd18df82baf0c79f8","observation_id":"142cabd6-0b68-4844-8c97-c63a7039adf5","resolution":{"observed_at":"2026-08-15T20:47:00.115688Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.097169Z","title":"Is feature selection secure against training data poisoning? In Proceedings of the 32nd International Conference on Machine Learning, ICML, volume 37, pages 1689–1698","venue":null,"work_id":"72d2f95a-a222-4472-bd29-1f94d3daa3cd","year":2015},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.316678Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:34bae89a4c8aa2b16dbcea9be85e22cc4caa114951aeeefdf440dd1425e613b9","observation_id":"6f8c30dc-8714-4409-9ea0-dde061011096","resolution":{"observed_at":"2026-08-15T20:47:00.102137Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.083479Z","title":"Local model poisoning attacks to byzantine-robust federated learning","venue":null,"work_id":"05222dae-6572-4794-b3c1-acc00ef2946c","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":41,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.320874Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:976506bc3b32f9f6185f123392382d0911fb534468d0017d5e8ccffcdb2c316a","observation_id":"fe4eb3e5-7e89-45b0-af6a-121d3c95d244","resolution":{"observed_at":"2026-08-15T20:47:00.087864Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.069410Z","title":"A little is enough: Circumventing defenses for distributed learning","venue":null,"work_id":"49690e24-9237-43f4-bb31-c78e7b487ee2","year":2019},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.324740Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:10f45d1234b60ff7cec1f108c50a6d71c33b10e509498fefec20ecad08867201","observation_id":"f265cbf2-012f-40a8-ae4f-fe6b85fdfa73","resolution":{"observed_at":"2026-08-15T20:47:00.074117Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.055277Z","title":"Fall of empires: Breaking byzantine-tolerant SGD by inner product manipulation","venue":null,"work_id":"437f9067-df19-49f7-9a61-05ba1a5b8787","year":2019},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":43,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.328997Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:f04ce35e4c47e029c5d546df93f719f054da4b8b9c651dc4d7949ef0f07b0ab6","observation_id":"309ed70f-4848-471f-a6ec-3ffb7d624be6","resolution":{"observed_at":"2026-08-15T20:47:00.060188Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.042344Z","title":null,"venue":null,"work_id":"a9d68738-2170-4d5a-80a7-64f4bedbdb3a","year":2019},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.332804Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:37468c77c501caab6b7236e0a16fb77371da104e905268b36d7913bd022a4a85","observation_id":"81c479bb-13c7-4f8f-8b22-d567ff6fc807","resolution":{"observed_at":"2026-08-15T20:47:00.046525Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.028280Z","title":"DBA: distributed backdoor attacks against federated learning","venue":null,"work_id":"c7112d56-a959-4f87-ba54-a72bafb38ef4","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.336639Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:2c593cb55c4876bd34ff7e13a77ca338289a3837f0afbb340045af28c2f4d14a","observation_id":"0d2b1d81-8598-4456-9bb4-1b406c19a06e","resolution":{"observed_at":"2026-08-15T20:47:00.033408Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.007102Z","title":"Neural trojans","venue":null,"work_id":"dc9dfaa3-7335-4d54-9e20-db5bb497cce4","year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":46,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.344424Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:3371bf669f0750cd330585e57d0c77c19d7c2643b111ca8b4f52fc0685c94607","observation_id":"036fb7cc-c657-4fe4-b2f9-a5467a6c16c3","resolution":{"observed_at":"2026-08-15T20:47:00.011019Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.993577Z","title":"Februus: Input purification defense against trojan attacks on deep neural network systems","venue":null,"work_id":"bc0d828f-9680-47e8-8513-28f58a28166b","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.348463Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:6a19d731e087c5ce012fa1d47d045f7903e2f66c726caae11617c65fe7f884bc","observation_id":"e87ae1b7-a21d-4f0a-8a02-b5048c90c923","resolution":{"observed_at":"2026-08-15T20:46:59.998037Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2005.00060","last_updated":"2020-07-03T03:49:28Z","snapshot_observed_at":"2026-08-09T20:06:29.660919Z","submitted_at":"2020-04-30T19:12:50Z","title":"Bridging Mode Connectivity in Loss Landscapes and Adversarial Robustness","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2005.00060","snapshot_observed_at":"2026-08-15T20:46:59.352317Z","title":"Bridging mode connectivity in loss landscapes and adversarial robustness","venue":null,"work_id":null,"year":2005},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":48,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.352317Z"},"links":{"cited_paper":"/paper/2005.00060","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:01dec61ff22cb50c556228e85fb73304cd988f4bd2a1412ce8418bf3f5abd1c2","observation_id":"dc98f9be-8ffb-4570-879a-9fa17a5f3bf4","resolution":{"observed_at":"2026-08-15T20:46:59.352317Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.980498Z","title":"Fine-pruning: Defending against backdooring attacks on deep neural networks","venue":null,"work_id":"d8dd0497-2431-4354-8338-f82f1a72910f","year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.356479Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:8a02287d8a4fa63f7a2a78c3e743df8be407c845d1b27fb8b1f3a842ec6197e5","observation_id":"e566a417-08e2-4d4a-964b-07ae8c25ec8e","resolution":{"observed_at":"2026-08-15T20:46:59.984988Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.360704Z","title":"Spectral signatures in backdoor attacks","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":50,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.360704Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:a4249d61751ca7a5654d2ddc0e4e258830ffdd4f013591dd49eb09fd091b32cb","observation_id":"990d3f4d-da1c-4dc7-8e0e-05dbb72786a8","resolution":{"observed_at":"2026-08-15T20:46:59.360704Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1811.03728","last_updated":"2018-11-09T01:08:00Z","snapshot_observed_at":"2026-08-16T05:42:20.700873Z","submitted_at":"2018-11-09T01:08:00Z","title":"Detecting Backdoor Attacks on Deep Neural Networks by Activation Clustering","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1811.03728","snapshot_observed_at":"2026-08-15T20:46:59.364517Z","title":"Detecting backdoor attacks on deep neural networks by activation clustering.arXiv preprint arXiv:1811.03728, 2018","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.364517Z"},"links":{"cited_paper":"/paper/1811.03728","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:30a0ddad5a171133663294aeecc2ec6bf96ed25bd4dac4835d9024c2ca4f21a3","observation_id":"5124a28d-afe1-4923-be23-4de00daf5b1e","resolution":{"observed_at":"2026-08-15T20:46:59.364517Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.957125Z","title":"Demon in the variant: Statistical analysis of dnns for robust backdoor contamination detection","venue":null,"work_id":"7ad543bf-64c7-4095-810b-ae6d198c608e","year":2021},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":52,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.368663Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:e5b4754e5066a8e83085165eccbe0a7203efcf222c0f4e8fe4af71e5b3ffca93","observation_id":"fcb72861-4f83-41ed-9f94-ba82f75f31a0","resolution":{"observed_at":"2026-08-15T20:46:59.961728Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.943757Z","title":"Baffle: Backdoor detection via feedback-based federated learning","venue":null,"work_id":"948648c9-3292-432c-9d6a-2c9247da84e8","year":2021},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":53,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.372693Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:e9204e51fc39e67d03c56ebc004b8e5c0a10f9406c512c7a72cd68c8b16498e8","observation_id":"c824a161-dca0-4a87-8da8-cfd0aaf90670","resolution":{"observed_at":"2026-08-15T20:46:59.948265Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.930055Z","title":"Strip: A defence against trojan attacks on deep neural networks","venue":null,"work_id":"bb0ac983-814a-4739-a26a-32d0d440dbf5","year":2019},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":54,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.376785Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:8805c254dce2ec9bd8772c6090c7f00a80f8d08afb756b570d32c874923aa424","observation_id":"9838a3bf-f74e-4657-bfbd-1aabe0c0596a","resolution":{"observed_at":"2026-08-15T20:46:59.934682Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1912.01206","last_updated":"2019-12-03T05:58:51Z","snapshot_observed_at":"2026-07-06T08:41:36.239537Z","submitted_at":"2019-12-03T05:58:51Z","title":"Deep Probabilistic Models to Detect Data Poisoning Attacks","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1912.01206","snapshot_observed_at":"2026-08-15T20:46:59.380682Z","title":"Deep probabilistic models to detect data poisoning attacks","venue":null,"work_id":null,"year":1912},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":55,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.380682Z"},"links":{"cited_paper":"/paper/1912.01206","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:8393059bf201f8d156d122c15ac224e4672b14d13e9c111292e570f7a9f05b7e","observation_id":"d8220cac-d5a3-4506-af0a-702516a1adb9","resolution":{"observed_at":"2026-08-15T20:46:59.380682Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2006.14871","last_updated":"2022-07-28T18:22:05Z","snapshot_observed_at":"2026-08-11T06:13:31.384269Z","submitted_at":"2020-06-26T09:09:27Z","title":"Can We Mitigate Backdoor Attack Using Adversarial Detection Methods?","version":2},"cited_work":{"arxiv_id":"2006.14871","doi":null,"metadata_source":"pith","pith_arxiv_id":"2006.14871","snapshot_observed_at":"2026-08-15T20:46:59.562264Z","title":"Can We Mitigate Backdoor Attack Using Adversarial Detection Methods?","venue":"cs.LG","work_id":"0bbb24f2-6cb1-469d-8aa0-e947f1398293","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":56,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.384827Z"},"links":{"cited_paper":"/paper/2006.14871","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:a67572183de3ce627f2c5bf736220bcd3abad538782ee8c90b4f8926ec3338e7","observation_id":"14f0d770-92c4-4776-a143-e0aa6d0c6f07","resolution":{"observed_at":"2026-08-15T20:46:59.568759Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.917071Z","title":"Fedinv: Byzantine-robust federated learning by inversing local model updates","venue":null,"work_id":"743b82a4-62f9-4d5a-9734-fb9d2f0ab58c","year":2022},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":57,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.388926Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:4bd901e1b0222b697b4dc81229958587cc66242716b06b692a72a2790c38320d","observation_id":"48974221-f73c-440c-bc26-b80ec2d2ad8b","resolution":{"observed_at":"2026-08-15T20:46:59.921419Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.903797Z","title":"Flip: A provable defense framework for backdoor mitigation in federated learning","venue":null,"work_id":"84f43739-7337-4550-8f83-8bdf685ce189","year":2023},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":58,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.392869Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:861ac9d4f592be9d3f0f35a7cbd77561bfa8ac37f1fb6ca64befefd0b9d9fe5f","observation_id":"f1c94e5c-40cc-4d36-a06c-c4d3f45fdbb4","resolution":{"observed_at":"2026-08-15T20:46:59.908172Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2207.08486","last_updated":"2025-03-25T07:50:17Z","snapshot_observed_at":"2026-08-16T16:45:13.720632Z","submitted_at":"2022-07-18T10:10:45Z","title":"Using Anomaly Detection to Detect Poisoning Attacks in Federated Learning Applications","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2207.08486","snapshot_observed_at":"2026-08-15T20:46:59.396695Z","title":"Using anomaly detection to detect poisoning attacks in federated learning applications","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":59,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.396695Z"},"links":{"cited_paper":"/paper/2207.08486","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:3785d1a859097a7978edecebfe25089aa52712ff032c699c898219796154bb52","observation_id":"086b95fe-533d-422f-bc1b-0d6e28ef4057","resolution":{"observed_at":"2026-08-15T20:46:59.396695Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.400671Z","title":"Exploiting shared representations for personalized federated learning","venue":null,"work_id":null,"year":2021},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":60,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.400671Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:3dd33538860c96a6e054b010aab3caad8ce558aceeef0495ea3959452e99be76","observation_id":"e511639d-2ca9-4659-bcc9-a58fe15599b7","resolution":{"observed_at":"2026-08-15T20:46:59.400671Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.881612Z","title":"Efficient wireless federated learning with partial model aggregation","venue":null,"work_id":"57648391-84a5-4533-9e2f-c32b0b577cfc","year":2024},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":61,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.404662Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:a1cbf726922fe9e9146bea9112ae38ea17bc8b1ae382bb1d6293e56e034734f9","observation_id":"016e92c2-d0ae-4037-885a-1cac6b60d188","resolution":{"observed_at":"2026-08-15T20:46:59.886035Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.868416Z","title":"Federated learning with partial model personalization","venue":null,"work_id":"01e9831e-8d2e-43f8-9926-77f3fade4027","year":2022},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":62,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.408620Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:d844dd8a660b8adb3aae3f2ff4ccedcbbd85d48494cef1aa58831fd9d274b14a","observation_id":"e91b606f-d71a-4b48-b00d-b47466865502","resolution":{"observed_at":"2026-08-15T20:46:59.872782Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1912.00818","last_updated":"2019-12-02T14:29:00Z","snapshot_observed_at":"2026-08-16T08:02:37.158308Z","submitted_at":"2019-12-02T14:29:00Z","title":"Federated Learning with Personalization Layers","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1912.00818","snapshot_observed_at":"2026-08-15T20:46:59.412628Z","title":"Federated learning with personalization layers","venue":null,"work_id":null,"year":1912},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":63,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.412628Z"},"links":{"cited_paper":"/paper/1912.00818","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:4a50628525e30a4eef94343ad3ef68f136cf19a36067a261cd1aaaad682a32cb","observation_id":"23e5d9e7-71f3-40a6-8e3b-ee390cd83685","resolution":{"observed_at":"2026-08-15T20:46:59.412628Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.416762Z","title":"Personalized federated learning with moreau envelopes","venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":64,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.416762Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:85eba85f6420467395c73c925bb99472b6db43bbd010961b6efe55a5f235fad4","observation_id":"1c39584a-327c-4c48-b80e-25d92e8d9edd","resolution":{"observed_at":"2026-08-15T20:46:59.416762Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2305.15706","last_updated":"2023-05-25T04:25:55Z","snapshot_observed_at":"2026-08-16T15:29:54.263126Z","submitted_at":"2023-05-25T04:25:55Z","title":"pFedSim: Similarity-Aware Model Aggregation Towards Personalized Federated Learning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.15706","snapshot_observed_at":"2026-08-15T20:46:59.421002Z","title":"arXiv preprint arXiv:2305.15706, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":65,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.421002Z"},"links":{"cited_paper":"/paper/2305.15706","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:ffb91f8abec30910cc671cbeae4be6d34c892c23fccadf0ea8ea5741c5f44d1d","observation_id":"15ded010-e57d-4a7e-b4c1-775e26c7b163","resolution":{"observed_at":"2026-08-15T20:46:59.421002Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2003.13376","last_updated":"2020-08-02T08:51:07Z","snapshot_observed_at":"2026-08-13T23:09:09.904759Z","submitted_at":"2020-03-30T12:12:51Z","title":"End-to-End Evaluation of Federated Learning and Split Learning for Internet of Things","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2003.13376","snapshot_observed_at":"2026-08-15T20:46:59.426048Z","title":"End-to-end evaluation of federated learning and split learning for internet of things","venue":null,"work_id":null,"year":2003},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":66,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.426048Z"},"links":{"cited_paper":"/paper/2003.13376","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:9e3a9fa5a136c3c4663035aa17e89a97277e11b618aab40d1d1b090e8bec72d7","observation_id":"9ad22181-4d3f-49bc-a2d8-32d1f2310f33","resolution":{"observed_at":"2026-08-15T20:46:59.426048Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.847316Z","title":"Revisiting personalized federated learning: Robustness against backdoor attacks","venue":null,"work_id":"ff7f01d5-26d3-4c32-a21b-8866d9bb96d1","year":2023},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":67,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.430288Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:5844e081346485c0ab36e5c2d41baab7e98677838bf7c1d34a01e0690f5f5c70","observation_id":"5862e7e1-643e-4777-943d-f42ecee13668","resolution":{"observed_at":"2026-08-15T20:46:59.851565Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.833978Z","title":"One-pixel signature: Characterizing cnn models for backdoor detection","venue":null,"work_id":"b96aa3c2-b214-4074-a6b9-61e1f73944b6","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":68,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.434309Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:11b72977a71d31ba5c0a8df8589c84c0620acf871e0bed2a1e3b222b36b05609","observation_id":"a5f98215-0422-4f2c-ab36-05348519d429","resolution":{"observed_at":"2026-08-15T20:46:59.838472Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.821117Z","title":"Xmam: X-raying models with a matrix to reveal backdoor attacks for federated learning","venue":null,"work_id":"16ba898d-6cd8-4bc1-a9c8-e75c392e1cbe","year":2024},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":69,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.438310Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:102d2c6f0c7ce93b06066e017d046dbaf3d01fed199ec20657f7ca1890f394c0","observation_id":"ffab6e22-76f6-4010-ad1e-5707eb8bf66e","resolution":{"observed_at":"2026-08-15T20:46:59.825320Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.442331Z","title":"Gradient-based learning applied to document recognition","venue":null,"work_id":null,"year":1998},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":70,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.442331Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:ecb3b2ca482db79fc13d2d9135bebc5a6c10b7cc540f6978a2beb79995fb64f5","observation_id":"ef2fc77b-f403-4145-b8cb-05c2475924c9","resolution":{"observed_at":"2026-08-15T20:46:59.442331Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.446310Z","title":"Handwritten digit recognition with a back-propagation network.Advances in neural information processing systems, 2, 1989","venue":null,"work_id":null,"year":1989},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":71,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.446310Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:e56b216de73aa61d8de101ef8e76e8d4669343eb69ab1b5c419ef1cbeaa87beb","observation_id":"e563ed44-6932-4fd1-b7ee-741d365dc6fa","resolution":{"observed_at":"2026-08-15T20:46:59.446310Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.450356Z","title":"Learning multiple layers of features from tiny images","venue":null,"work_id":null,"year":2009},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":72,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.450356Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:f06b9f6456f05502e55f653085434cdee2009f2f0d84b37b3fc3ee9d791fef98","observation_id":"bfeb4a41-137c-4832-b623-8405364a9f31","resolution":{"observed_at":"2026-08-15T20:46:59.450356Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.783923Z","title":"Deep residual learning for image recognition","venue":null,"work_id":"5e4a2906-dfeb-4b39-9f51-d2c9615efd56","year":2016},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":73,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.454492Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:a7504fe1f93c39697c376f5232f39b085d2b7f77a6fa746f446e9f842d7f2727","observation_id":"7b8b65b9-1b10-4f71-a55e-57d8ba8063d4","resolution":{"observed_at":"2026-08-15T20:46:59.788315Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1704.04861","last_updated":"2017-04-17T03:57:34Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2017-04-17T03:57:34Z","title":"MobileNets: Efficient Convolutional Neural Networks for Mobile Vision Applications","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1704.04861","snapshot_observed_at":"2026-08-15T20:46:59.458791Z","title":"Mobilenets: Efficient convolutional neural networks for mobile vision applications","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":74,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.458791Z"},"links":{"cited_paper":"/paper/1704.04861","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:1cd3bfa1e4ff28dd9fb708929bfdfca6223b9789c23e3990e7e92183da0615c8","observation_id":"175686b9-f703-431b-a961-57f0b1bc55fa","resolution":{"observed_at":"2026-08-15T20:46:59.458791Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.770779Z","title":"Byzantine-robust distributed learning: Towards optimal statistical rates","venue":null,"work_id":"73915efc-b69e-4009-8b10-2f01ba424157","year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":75,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.463287Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:295b13e2919b301d3153361aa6dddd7f636a0c097cea6092d0bdb3950e1fcc45","observation_id":"ee5caf8f-5c8d-41a7-b001-9616608e23bb","resolution":{"observed_at":"2026-08-15T20:46:59.775069Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-17T06:30:58.91139+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.340558Z","title":null,"venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":2020,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.340558Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:ec70c42e11754027ec065ae0a6dfb6bc405222fb880b70dcfd6e581037a67f96","observation_id":"69c3a31f-1aeb-44c6-a488-d22bcb7dd5ea","resolution":{"observed_at":"2026-08-15T20:46:59.340558Z","resolver_source":null,"status":"parse_uncertain"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-17T11:39:13.342971Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients"},"reference_resolution":{"displayed":76,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":1,"unresolved":28,"verified_exact":1,"verified_fuzzy":46},"total_outbound_references":76},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-17T06:30:58.91139+00:00","source":"crossref"},{"observed_at":"2026-08-17T06:30:54.323127+00:00","source":"retraction_watch"}],"thesis":"As of 17 August 2026, this Paper Citation Record lists 76 of 76 outbound references and 1 inbound Pith citation observation for arXiv:2505.12019."}