{"as_of":"2026-08-19T08:02:00Z","caps":{"database_statements":6,"inbound":100,"outbound":100},"context_digest":"sha256:bb11421279d76ca6374ec5ba5af4d8fe23bb8e17ac45673a1730d9f36aab7608","coverage":[{"denominator":76,"lane":"reference_resolution","note":"Typed states for the displayed outbound observations.","records_observed":76,"source":"paper_references, paper_reference_links","source_observed_at":"2026-08-15T20:46:59.463287Z","state":"measured"},{"denominator":77,"lane":"standing_notices","note":"One-hop event checks from named stored sources.","records_observed":77,"source":"scholarly_work_events, retraction_status_cache","source_observed_at":"2026-08-19T06:32:44.657259+00:00","state":"measured"},{"denominator":1,"lane":"inbound_itemization","note":"Pith citing papers itemized under the disclosed page cap.","records_observed":1,"source":"paper_references, paper_reference_links","source_observed_at":"2026-05-11T02:06:13.515696Z","state":"measured"},{"denominator":1,"lane":"external_citation_measurements","note":"A source-named dated measurement, never combined with another source.","records_observed":0,"source":"arxiv_reference","source_observed_at":"2026-05-11T03:55:57.345828Z","state":"measured"}],"external_citation_measurements":[],"inbound":[{"citation":{"cited_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"cited_work":{"arxiv_id":"2505.12019","doi":null,"metadata_source":"arxiv_reference","pith_arxiv_id":"2505.12019","snapshot_observed_at":"2026-06-05T21:23:00.469572Z","title":"Fl-plas: Federated learning with partial layer aggregation for backdoor defense against high-ratio malicious clients","venue":null,"work_id":"cb4e3371-0065-4a14-85e1-81fe65aa6079","year":2025},"citing_paper":{"arxiv_id":"2605.07860","last_updated":"2026-05-08T15:20:22Z","snapshot_observed_at":"2026-08-12T13:57:39.116506Z","submitted_at":"2026-05-08T15:20:22Z","title":"On the Tradeoffs of On-Device Generative Models in Federated Predictive Maintenance Systems","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-05-11T02:06:13.515696Z"},"links":{"cited_paper":"/paper/2505.12019","citing_paper":"/paper/2605.07860"},"observation_digest":"sha256:dc00937856c657f9ef3c5649696c22ccc8e1a6b48af01dec1689eaaf5617e39c","observation_id":"4475419d-606b-4985-9937-407bc42c8d28","resolution":{"observed_at":"2026-05-11T03:55:57.347877Z","resolver_source":"arxiv_id","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}}],"links":{"evidence":"/evidence","html":"/paper/2505.12019/citation-record","integrity":"/paper/2505.12019/integrity","json":"/paper/2505.12019/citation-record.json","paper":"/paper/2505.12019"},"outbound":[{"citation":{"cited_paper":{"arxiv_id":"1610.05492","last_updated":"2017-10-30T20:52:14Z","snapshot_observed_at":"2026-08-13T17:19:46.488095Z","submitted_at":"2016-10-18T09:11:51Z","title":"Federated Learning: Strategies for Improving Communication Efficiency","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1610.05492","snapshot_observed_at":"2026-08-15T20:46:59.156571Z","title":"Federated learning: Strategies for improving communication efficiency","venue":null,"work_id":null,"year":2016},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":1,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.156571Z"},"links":{"cited_paper":"/paper/1610.05492","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:53b5ec5ad1d9cb4e7459e66207fe776a9a82bbb18d8a41fa48390f005727f500","observation_id":"628a6754-36c9-463d-ad77-b9f32a785887","resolution":{"observed_at":"2026-08-15T20:46:59.156571Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.434819Z","title":"Communication- efficient learning of deep networks from decentralized data","venue":null,"work_id":"8480e05b-faca-466e-98f8-8a4656366105","year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":2,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.161816Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:ee78642c8dd38636d766234af2c387db4c83b3c2e17144f0e0e564abbe7c968c","observation_id":"b5fc46fe-38a7-410b-bfbe-a04d8ca3d162","resolution":{"observed_at":"2026-08-15T20:47:00.439682Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.422325Z","title":"Vulnerabilities in federated learning","venue":null,"work_id":"313548c2-71e2-4acb-a25c-8183c73d2e4f","year":2021},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":3,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.166106Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:8bb64d9426514316deb6ddfebe0f5afc7fed226644ccb7720b9fc89e26791c3c","observation_id":"a7c53513-f035-41f3-9c53-fe64eab88e78","resolution":{"observed_at":"2026-08-15T20:47:00.426555Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.410048Z","title":"Defending against backdoors in federated learning with robust learning rate","venue":null,"work_id":"2d2f78b5-3a4f-457a-8399-d8bd4120fa06","year":2021},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":4,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.170781Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:a36a028166f5296d2d53cf63620b01b9c36b9aee3d541938c3d0aa9695b6ab8b","observation_id":"216bdf9b-6d02-47a2-9e3b-e3b7a4cd4cfc","resolution":{"observed_at":"2026-08-15T20:47:00.414155Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1712.05526","last_updated":"2017-12-15T04:26:26Z","snapshot_observed_at":"2026-07-06T06:14:30.795326Z","submitted_at":"2017-12-15T04:26:26Z","title":"Targeted Backdoor Attacks on Deep Learning Systems Using Data Poisoning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1712.05526","snapshot_observed_at":"2026-08-15T20:46:59.174973Z","title":"Targeted backdoor attacks on deep learning systems using data poisoning","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":5,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.174973Z"},"links":{"cited_paper":"/paper/1712.05526","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:845b4ffc6a50a59e32243f997c9f4fda16206fcad809930e18068805a7fc77ad","observation_id":"4052a6b0-f4ab-4edd-8209-07c3f7fb0395","resolution":{"observed_at":"2026-08-15T20:46:59.174973Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1708.06733","last_updated":"2019-03-11T20:45:33Z","snapshot_observed_at":"2026-08-12T15:43:59.037380Z","submitted_at":"2017-08-22T17:31:54Z","title":"BadNets: Identifying Vulnerabilities in the Machine Learning Model Supply Chain","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1708.06733","snapshot_observed_at":"2026-08-15T20:46:59.179416Z","title":"Badnets: Identifying vulnerabilities in the machine learning model supply chain","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":6,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.179416Z"},"links":{"cited_paper":"/paper/1708.06733","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:62b1b50cc8c370bbbef0e32424f63acfa4a97f63cf608bdfa37d792d57b44702","observation_id":"0c12bd55-f91a-4f47-8e07-df0e95e65c6a","resolution":{"observed_at":"2026-08-15T20:46:59.179416Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.397508Z","title":"How to backdoor federated learning","venue":null,"work_id":"aca490d7-83cc-45fb-a498-02357de04709","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":7,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.184255Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:891f0c3d4f6a02b9b43debedf5594e592175ddc3efa56b3cb45024168325a0bb","observation_id":"e9e0ea98-9d14-41b9-867d-df94004f5ba1","resolution":{"observed_at":"2026-08-15T20:47:00.401443Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.383531Z","title":"Data poisoning attacks against federated learning systems","venue":null,"work_id":"ba42d4a1-494b-48f6-b448-0f724001ee99","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":8,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.188343Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:5cdb2efbad3dbeb17666ecea84ce3e28655cec67b271fe95554f5e0f0d59de6e","observation_id":"fbec6874-2126-4fca-90d7-42eac3d30eae","resolution":{"observed_at":"2026-08-15T20:47:00.388565Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.369827Z","title":"Lfighter: Defend- ing against the label-flipping attack in federated learning","venue":null,"work_id":"ddf2b4cd-ec94-4bfb-90a7-c1c680036939","year":2024},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":9,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.192482Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:f7c4d3a48177de14c56478da3edb2c71a84a1c27672c55155af9f7f4ada3de42","observation_id":"4ddc3bfd-161d-49dc-898b-14cba833af26","resolution":{"observed_at":"2026-08-15T20:47:00.374034Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2007.05084","last_updated":"2020-07-09T21:50:54Z","snapshot_observed_at":"2026-08-16T01:57:26.654751Z","submitted_at":"2020-07-09T21:50:54Z","title":"Attack of the Tails: Yes, You Really Can Backdoor Federated Learning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2007.05084","snapshot_observed_at":"2026-08-15T20:46:59.196443Z","title":"Attack of the tails: Yes, you really can backdoor federated learning","venue":null,"work_id":null,"year":2007},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":10,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.196443Z"},"links":{"cited_paper":"/paper/2007.05084","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:cf3ffc46b152d305a4afb0f0282f0870d6b13a697483c8ce14cf5472cdbcf337","observation_id":"9d9f491b-2da7-4b4d-8870-9d9ce40fe085","resolution":{"observed_at":"2026-08-15T20:46:59.196443Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.357407Z","title":"On the vulnerability of backdoor defenses for federated learning","venue":null,"work_id":"58276fc1-500b-4cbf-b201-b795164fa17e","year":2023},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":11,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.200875Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:3ee6cab273657babc4faa94b16da31b5028bd86c4dbcbaffee0f3a49d049f1c3","observation_id":"2eae8392-1c94-491d-bcf9-410386682d16","resolution":{"observed_at":"2026-08-15T20:47:00.361357Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.344524Z","title":"Backdoor federated learning by poisoning backdoor-critical layers","venue":null,"work_id":"41dc0e39-749f-4079-a7f9-994e64c6d9be","year":2024},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":12,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.204839Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:b5a6faac5168f298eaf6f532f69e430cf3675efb0275726f1219a64c23fba193","observation_id":"dade1b77-8672-43fc-a441-6e3797517e6a","resolution":{"observed_at":"2026-08-15T20:47:00.349004Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2003.02133","last_updated":"2020-03-04T15:30:10Z","snapshot_observed_at":"2026-08-15T13:53:57.947911Z","submitted_at":"2020-03-04T15:30:10Z","title":"Threats to Federated Learning: A Survey","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2003.02133","snapshot_observed_at":"2026-08-15T20:46:59.208880Z","title":"Threats to federated learning: A survey.arXiv preprint arXiv:2003.02133, 2020","venue":null,"work_id":null,"year":2003},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":13,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.208880Z"},"links":{"cited_paper":"/paper/2003.02133","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:900f521ccf6b4222828cf0eebbf11047fb02e76f585597054c23474c7b311332","observation_id":"260aae2f-dcd6-49cd-8d80-cee6be1c9eb0","resolution":{"observed_at":"2026-08-15T20:46:59.208880Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.331253Z","title":"Giannakis, and Qing Ling","venue":null,"work_id":"4953ad00-3527-457a-83b8-210857f25ec0","year":2019},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":14,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.212952Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:de4b21c68976b88d95c7ebad31e3b2195a30123387f8ca2f62bb5b099aaebd48","observation_id":"4196438b-f561-404c-a943-45fdf616d445","resolution":{"observed_at":"2026-08-15T20:47:00.335692Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1911.07963","last_updated":"2019-12-02T19:00:11Z","snapshot_observed_at":"2026-08-17T17:57:37.740446Z","submitted_at":"2019-11-18T21:25:03Z","title":"Can You Really Backdoor Federated Learning?","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1911.07963","snapshot_observed_at":"2026-08-15T20:46:59.216845Z","title":"Can you really backdoor federated learning? arXiv preprint arXiv:1911.07963, 2019","venue":null,"work_id":null,"year":1911},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":15,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.216845Z"},"links":{"cited_paper":"/paper/1911.07963","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:5e299ae04446557d455b9667681e5af4d9f847c8423b75175a43cc4b70d8eb29","observation_id":"2746a314-7624-4552-bad3-e67725cc083a","resolution":{"observed_at":"2026-08-15T20:46:59.216845Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2002.00211","last_updated":"2020-02-01T14:09:48Z","snapshot_observed_at":"2026-08-07T00:07:33.465634Z","submitted_at":"2020-02-01T14:09:48Z","title":"Learning to Detect Malicious Clients for Robust Federated Learning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2002.00211","snapshot_observed_at":"2026-08-15T20:46:59.220971Z","title":"Learning to detect malicious clients for robust federated learning","venue":null,"work_id":null,"year":2002},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":16,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.220971Z"},"links":{"cited_paper":"/paper/2002.00211","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:e6cfcebabb57e8bcff5398a0a6348e997a922d5cc659aba96aaa0fdc31ab5dc3","observation_id":"662c3bd4-b52a-457d-945c-3521099037d5","resolution":{"observed_at":"2026-08-15T20:46:59.220971Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.317787Z","title":"Fltrust: Byzantine-robust federated learning via trust bootstrapping","venue":null,"work_id":"ef25ce8e-170c-4eb1-9524-1b92ab28a09f","year":2021},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":17,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.225007Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:cc8c716e0321a48cc3ec003b0dee383285e48708ae800bdb816c1cd8037363d3","observation_id":"6b06f5ce-e3dd-47df-a078-02afdb49dd51","resolution":{"observed_at":"2026-08-15T20:47:00.322445Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.228856Z","title":"{FLAME}: Taming backdoors in federated learning","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":18,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.228856Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:c680abe056ffa1bde1817ac3daf2061a58ea8763a184868477534e77f3623dac","observation_id":"565313d2-c4e7-4185-bba9-2b9df3d1d625","resolution":{"observed_at":"2026-08-15T20:46:59.228856Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.297191Z","title":"Machine learning with adversaries: Byzantine tolerant gradient descent","venue":null,"work_id":"34759ee0-584a-4bf1-aa16-1855455ade40","year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":19,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.232920Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:b1ae9c02f613c21ac0c63e6d985f54a1da6b850515e295bcad802813d1fca30a","observation_id":"c5369117-0988-46bb-bd38-05b19bf38ed1","resolution":{"observed_at":"2026-08-15T20:47:00.301147Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.285231Z","title":"Backdooring convolutional neural networks via targeted weight perturbations","venue":null,"work_id":"32856758-c0bc-4c75-bc1d-338ff5105a06","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":20,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.236849Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:cd34299e1e947f277e4a79fa745eebee4fd4473e1fec2d9ec6e767a531e5e7ef","observation_id":"6a4bb6a5-936a-4190-9e4f-58049b6fcc5e","resolution":{"observed_at":"2026-08-15T20:47:00.289217Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.273326Z","title":"Data poisoning attacks and defenses to crowdsourcing systems","venue":null,"work_id":"4f373290-a731-4412-90ea-e8cd14323fb7","year":2021},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":21,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.240783Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:8e0db15f276217969ac1dc5a61c383b400df8ed168a0098bcf215a4a31519bc2","observation_id":"2d548116-c73f-46d5-a0c7-fb8ea56fd084","resolution":{"observed_at":"2026-08-15T20:47:00.277203Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.261102Z","title":"Poisoning attacks to graph-based recommender systems","venue":null,"work_id":"5213d8bd-0bd1-4ae2-ba69-35bf9808a79d","year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":22,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.244691Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:da7774b994493bee88dbf6f2a21c52ad832ab615a54f31c17674a699c1116443","observation_id":"36027c5c-3a86-429e-9b07-3093c7d9c391","resolution":{"observed_at":"2026-08-15T20:47:00.265119Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.249159Z","title":"Fake co-visitation injection attacks to recommender systems","venue":null,"work_id":"fd7fb15f-1dd8-44a7-be5c-a4da03a6db21","year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":23,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.248727Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:77454a75ef8f0b4dbd1fde76d96b4ab683c9231e89627faaaf9b6fdc64cdc52f","observation_id":"3ef81319-0178-4ed5-bc1c-286135ef027f","resolution":{"observed_at":"2026-08-15T20:47:00.253075Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.236705Z","title":"Exploiting machine learning to subvert your spam filter","venue":null,"work_id":"f09180fa-55f2-4660-a125-bd630dcac697","year":2008},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":24,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.252533Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:df205366e6c07315953855a71e8fabb86a5f3ac828ec9f3f65a0272846372f76","observation_id":"7f89b187-bcfe-4598-a64b-5a3d30cb21da","resolution":{"observed_at":"2026-08-15T20:47:00.241011Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1912.04977","last_updated":"2021-03-09T03:03:49Z","snapshot_observed_at":"2026-08-13T11:40:49.533339Z","submitted_at":"2019-12-10T20:55:41Z","title":"Advances and Open Problems in Federated Learning","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1912.04977","snapshot_observed_at":"2026-08-15T20:46:59.256703Z","title":"Advances and open problems in federated learning","venue":null,"work_id":null,"year":1912},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":25,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.256703Z"},"links":{"cited_paper":"/paper/1912.04977","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:d72b6dbcd9fb1a0132d5fd707b36cda91c8a4940d0d12fcdb966405a861ba99b","observation_id":"db390e47-3344-4f1f-9c2f-7316b56109ec","resolution":{"observed_at":"2026-08-15T20:46:59.256703Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2007.08745","last_updated":"2022-02-16T06:39:39Z","snapshot_observed_at":"2026-07-06T09:39:02.518657Z","submitted_at":"2020-07-17T04:09:20Z","title":"Backdoor Learning: A Survey","version":5},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2007.08745","snapshot_observed_at":"2026-08-15T20:46:59.260987Z","title":"Backdoor learning: A survey","venue":null,"work_id":null,"year":2007},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":26,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.260987Z"},"links":{"cited_paper":"/paper/2007.08745","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:eccd28abd8651759aae02a47636d83ea5012988ab33c46784caa70f07c0ee339","observation_id":"09b0fdbc-8bed-4fe0-a594-eadbf2ef6740","resolution":{"observed_at":"2026-08-15T20:46:59.260987Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2006.09365","last_updated":"2023-11-22T09:08:15Z","snapshot_observed_at":"2026-08-07T05:21:15.626151Z","submitted_at":"2020-06-16T17:58:53Z","title":"Byzantine-Robust Learning on Heterogeneous Datasets via Bucketing","version":6},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2006.09365","snapshot_observed_at":"2026-08-15T20:46:59.265312Z","title":"Byzantine-robust learning on heterogeneous datasets via resampling","venue":null,"work_id":null,"year":2006},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":27,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.265312Z"},"links":{"cited_paper":"/paper/2006.09365","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:4caa4ddc39e40508dc1580763830d31307b6bddde6be5d5ea3eff08c91301981","observation_id":"49e3a2a1-fe5f-4cba-b243-b19c2834a517","resolution":{"observed_at":"2026-08-15T20:46:59.265312Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1909.06335","last_updated":"2019-09-13T17:26:20Z","snapshot_observed_at":"2026-08-16T05:00:17.345539Z","submitted_at":"2019-09-13T17:26:20Z","title":"Measuring the Effects of Non-Identical Data Distribution for Federated Visual Classification","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1909.06335","snapshot_observed_at":"2026-08-15T20:46:59.269254Z","title":"Measuring the effects of non-identical data distribution for federated visual classification","venue":null,"work_id":null,"year":1909},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":28,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.269254Z"},"links":{"cited_paper":"/paper/1909.06335","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:428e4025f5352e940d5ac9595ea6a145e2e3111871d43227967e1191abfe0527","observation_id":"5ba3842a-91b0-45cd-a1dc-fe8b9c207107","resolution":{"observed_at":"2026-08-15T20:46:59.269254Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1412.6572","last_updated":"2015-03-20T20:19:16Z","snapshot_observed_at":"2026-08-19T07:17:20.004918Z","submitted_at":"2014-12-20T01:17:12Z","title":"Explaining and Harnessing Adversarial Examples","version":3},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1412.6572","snapshot_observed_at":"2026-08-15T20:46:59.273346Z","title":"Explaining and harnessing adversarial examples","venue":null,"work_id":null,"year":2014},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":29,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.273346Z"},"links":{"cited_paper":"/paper/1412.6572","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:5ed0e6550e63a937add2ebf40ce3bdc841bc90c7d58e2675e6e15212e6df269b","observation_id":"617e94f5-6b4e-4a2e-9c58-6f38c4f525f2","resolution":{"observed_at":"2026-08-15T20:46:59.273346Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.224464Z","title":"The limitations of deep learning in adversarial settings","venue":null,"work_id":"53f7aa8b-37b0-45d1-927f-58cedbceb66b","year":2016},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":30,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.277097Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:c5dc8459ee6bf3c446d7d2ed5a2126808c0c67ada84aab91e64ead8eb89a359e","observation_id":"4661f1e9-3062-4157-9b47-e080f3c68835","resolution":{"observed_at":"2026-08-15T20:47:00.228445Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.212011Z","title":"Terminal brain damage: Exposing the graceless degradation in deep neural networks under hardware fault attacks","venue":null,"work_id":"87039591-3633-4c05-9850-3e8621783ef9","year":2019},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":31,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.281002Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:b15602e1cf250f31b11ed5a5a25b852b772ba4237d59bbea05656f56a803fe9c","observation_id":"e86f0cbb-4fbd-4371-8ec3-7f0d914b16ec","resolution":{"observed_at":"2026-08-15T20:47:00.216304Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.199131Z","title":"Antidote: understanding and defending against poisoning of anomaly detectors","venue":null,"work_id":"4136c549-0939-4ed5-8c5a-2a8823e39efe","year":2009},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":32,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.284854Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:79e6b3c6a00be3bae6a0c8d52f9262628c8e8b3286c4139eaa141c7aa0f43c93","observation_id":"833223c5-bc26-427b-8ed4-f0abf23a68ad","resolution":{"observed_at":"2026-08-15T20:47:00.203431Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.187031Z","title":"Ronny Huang, Mahyar Najibi, Octavian Suciu, Christoph Studer, Tudor Dumitras, and Tom Goldstein","venue":null,"work_id":"65d612e5-3de7-4cb5-a65b-c707507bdf3d","year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":33,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.288662Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:6c67693627482ec71efb0934bb233c068094e291fbdba47ac4c1ca5e34790cd4","observation_id":"f06ecca4-5bb3-4c13-8991-59e893255fcf","resolution":{"observed_at":"2026-08-15T20:47:00.191092Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.174715Z","title":"When does machine learning fail? generalized transferability for evasion and poisoning attacks","venue":null,"work_id":"906568bf-4b3c-4b14-b376-8e7b6066287a","year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":34,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.292485Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:6142290bf5b794ffa321c0470fb0f5ed6ed8894c6c43d5d99d1443b516ac1204","observation_id":"e1e9185e-806b-4cb6-9984-8e0cb95ec25a","resolution":{"observed_at":"2026-08-15T20:47:00.178724Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.162004Z","title":"Attacking graph-based classification via manipulating the graph structure","venue":null,"work_id":"e9dbe5c1-8a37-4120-9fd5-827a7f508c5f","year":2019},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":35,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.296789Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:d1fc3c8e8b1a37794242c34c1327dabe545380be7d342a86d8cc3f0953274826","observation_id":"b7acef71-fe2c-4089-ad0c-d1dcf90ffb97","resolution":{"observed_at":"2026-08-15T20:47:00.166317Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.149076Z","title":"Poisoning attacks against support vector machines","venue":null,"work_id":"b132c7be-0fb8-4cfd-ac36-2edd5592fff8","year":2012},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":36,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.300741Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:dafd94f967ad1d1df137d53eaf7018ffbe5838ca268a36075f3f1830675d7802","observation_id":"6daa4b75-5f16-4387-bc81-07496230f474","resolution":{"observed_at":"2026-08-15T20:47:00.153332Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.135905Z","title":"Manipulating machine learning: Poisoning attacks and countermeasures for regression learning","venue":null,"work_id":"919e4809-24ea-44b9-887d-6ade93409b85","year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":37,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.304607Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:bb96b7e559b09976298f5e8d277b57e757005b1df2ecfd70109f84fe45895959","observation_id":"d1b532bb-8943-4f22-9406-f239ff93afcf","resolution":{"observed_at":"2026-08-15T20:47:00.140464Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.123792Z","title":"Data poisoning attacks on factorization-based collaborative filtering","venue":null,"work_id":"b506cd03-aa36-4d0d-a8cc-379f77e3e655","year":2016},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":38,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.308466Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:4b4bf9820c564acf823888131edd4873394abe87859cd7a96e81e4df6474f2ab","observation_id":"d18f68a5-685c-49bb-9f58-ca0aaa8b8a25","resolution":{"observed_at":"2026-08-15T20:47:00.127861Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.111575Z","title":"Towards poisoning of deep learning algorithms with back-gradient optimization","venue":null,"work_id":"142eb2ab-8419-4fba-b034-1e28cc3dbdb4","year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":39,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.312319Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:21d2368c819dbe22160112c363066331f0a9f3c736172175c3f72f9773a19fb8","observation_id":"142cabd6-0b68-4844-8c97-c63a7039adf5","resolution":{"observed_at":"2026-08-15T20:47:00.115688Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.097169Z","title":"Is feature selection secure against training data poisoning? In Proceedings of the 32nd International Conference on Machine Learning, ICML, volume 37, pages 1689–1698","venue":null,"work_id":"72d2f95a-a222-4472-bd29-1f94d3daa3cd","year":2015},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":40,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.316678Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:02620105197079a7fe142f7883191921184f88b227c71e46007da0ec5f32f04c","observation_id":"6f8c30dc-8714-4409-9ea0-dde061011096","resolution":{"observed_at":"2026-08-15T20:47:00.102137Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.083479Z","title":"Local model poisoning attacks to byzantine-robust federated learning","venue":null,"work_id":"05222dae-6572-4794-b3c1-acc00ef2946c","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":41,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.320874Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:f9f6ea45628624b9de7d929156891345c318876fe405b54f68084bcc31b9b79a","observation_id":"fe4eb3e5-7e89-45b0-af6a-121d3c95d244","resolution":{"observed_at":"2026-08-15T20:47:00.087864Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.069410Z","title":"A little is enough: Circumventing defenses for distributed learning","venue":null,"work_id":"49690e24-9237-43f4-bb31-c78e7b487ee2","year":2019},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":42,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.324740Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:542bb8f69a0d7b12ff5189d2a4ce13ae8ae63556717e48bd79b8d41d5e3026af","observation_id":"f265cbf2-012f-40a8-ae4f-fe6b85fdfa73","resolution":{"observed_at":"2026-08-15T20:47:00.074117Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.055277Z","title":"Fall of empires: Breaking byzantine-tolerant SGD by inner product manipulation","venue":null,"work_id":"437f9067-df19-49f7-9a61-05ba1a5b8787","year":2019},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":43,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.328997Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:098f4d63602eee0e504d990c36fb3294f9d8f5ffff817ef21ab7ab4c1aa36f46","observation_id":"309ed70f-4848-471f-a6ec-3ffb7d624be6","resolution":{"observed_at":"2026-08-15T20:47:00.060188Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.042344Z","title":null,"venue":null,"work_id":"a9d68738-2170-4d5a-80a7-64f4bedbdb3a","year":2019},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":44,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.332804Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:f1711719a5b1f5cb7c3d562506903e5a2600648e34eaba547d9fec442cfe4b13","observation_id":"81c479bb-13c7-4f8f-8b22-d567ff6fc807","resolution":{"observed_at":"2026-08-15T20:47:00.046525Z","resolver_source":"raw_fallback","status":"unresolved"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.028280Z","title":"DBA: distributed backdoor attacks against federated learning","venue":null,"work_id":"c7112d56-a959-4f87-ba54-a72bafb38ef4","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":45,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.336639Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:02c7da8ed5604c0d6d358e5f8113e42d21efbec24af7fc6714dc5bf5292fa722","observation_id":"0d2b1d81-8598-4456-9bb4-1b406c19a06e","resolution":{"observed_at":"2026-08-15T20:47:00.033408Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:47:00.007102Z","title":"Neural trojans","venue":null,"work_id":"dc9dfaa3-7335-4d54-9e20-db5bb497cce4","year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":46,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.344424Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:d7f0e7e2f48503761f47d779494ca8fba98189a2c2b8484d1e5f09f7bda116af","observation_id":"036fb7cc-c657-4fe4-b2f9-a5467a6c16c3","resolution":{"observed_at":"2026-08-15T20:47:00.011019Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.993577Z","title":"Februus: Input purification defense against trojan attacks on deep neural network systems","venue":null,"work_id":"bc0d828f-9680-47e8-8513-28f58a28166b","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":47,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.348463Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:37bdf0d436d6fba50468aabc63f2793d046d55466d8b242305c1db29a8dd3159","observation_id":"e87ae1b7-a21d-4f0a-8a02-b5048c90c923","resolution":{"observed_at":"2026-08-15T20:46:59.998037Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2005.00060","last_updated":"2020-07-03T03:49:28Z","snapshot_observed_at":"2026-08-09T20:06:29.660919Z","submitted_at":"2020-04-30T19:12:50Z","title":"Bridging Mode Connectivity in Loss Landscapes and Adversarial Robustness","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2005.00060","snapshot_observed_at":"2026-08-15T20:46:59.352317Z","title":"Bridging mode connectivity in loss landscapes and adversarial robustness","venue":null,"work_id":null,"year":2005},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":48,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.352317Z"},"links":{"cited_paper":"/paper/2005.00060","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:6dbe0e2b686be9b5415fe09e0e5e56f29d19b4e29d2beb839f804674d29cabea","observation_id":"dc98f9be-8ffb-4570-879a-9fa17a5f3bf4","resolution":{"observed_at":"2026-08-15T20:46:59.352317Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.980498Z","title":"Fine-pruning: Defending against backdooring attacks on deep neural networks","venue":null,"work_id":"d8dd0497-2431-4354-8338-f82f1a72910f","year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":49,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.356479Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:78bbbfa5ee4724947abfb1c6bcb01204cd78cf9888933bb8e1b8f7c686676855","observation_id":"e566a417-08e2-4d4a-964b-07ae8c25ec8e","resolution":{"observed_at":"2026-08-15T20:46:59.984988Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.360704Z","title":"Spectral signatures in backdoor attacks","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":50,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.360704Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:57c54c0c4d86a8b824210eebe04d6265060d4ef0f8f7e566fc422263747729ed","observation_id":"990d3f4d-da1c-4dc7-8e0e-05dbb72786a8","resolution":{"observed_at":"2026-08-15T20:46:59.360704Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"1811.03728","last_updated":"2018-11-09T01:08:00Z","snapshot_observed_at":"2026-08-16T05:42:20.700873Z","submitted_at":"2018-11-09T01:08:00Z","title":"Detecting Backdoor Attacks on Deep Neural Networks by Activation Clustering","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1811.03728","snapshot_observed_at":"2026-08-15T20:46:59.364517Z","title":"Detecting backdoor attacks on deep neural networks by activation clustering.arXiv preprint arXiv:1811.03728, 2018","venue":null,"work_id":null,"year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":51,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.364517Z"},"links":{"cited_paper":"/paper/1811.03728","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:dd139fd9db1523ef3bf0a1f7842dd455560be37c306a6eb61d54e6a274f6c419","observation_id":"5124a28d-afe1-4923-be23-4de00daf5b1e","resolution":{"observed_at":"2026-08-15T20:46:59.364517Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.957125Z","title":"Demon in the variant: Statistical analysis of dnns for robust backdoor contamination detection","venue":null,"work_id":"7ad543bf-64c7-4095-810b-ae6d198c608e","year":2021},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":52,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.368663Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:7c83fd7248c512027201a8e4d2777d3ef23b4d1d9bb105016aaa1f67d4b36475","observation_id":"fcb72861-4f83-41ed-9f94-ba82f75f31a0","resolution":{"observed_at":"2026-08-15T20:46:59.961728Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.943757Z","title":"Baffle: Backdoor detection via feedback-based federated learning","venue":null,"work_id":"948648c9-3292-432c-9d6a-2c9247da84e8","year":2021},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":53,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.372693Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:fc58f5c2dbcabba5f7d4837a7d13f7d13105d1e51050813a9058fe6525f0eba5","observation_id":"c824a161-dca0-4a87-8da8-cfd0aaf90670","resolution":{"observed_at":"2026-08-15T20:46:59.948265Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.930055Z","title":"Strip: A defence against trojan attacks on deep neural networks","venue":null,"work_id":"bb0ac983-814a-4739-a26a-32d0d440dbf5","year":2019},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":54,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.376785Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:70b6efeac2f1890179ec9c6a4a233fba71249bd3d8e2e06dd4b0373dc1e29011","observation_id":"9838a3bf-f74e-4657-bfbd-1aabe0c0596a","resolution":{"observed_at":"2026-08-15T20:46:59.934682Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1912.01206","last_updated":"2019-12-03T05:58:51Z","snapshot_observed_at":"2026-08-19T05:43:56.803627Z","submitted_at":"2019-12-03T05:58:51Z","title":"Deep Probabilistic Models to Detect Data Poisoning Attacks","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1912.01206","snapshot_observed_at":"2026-08-15T20:46:59.380682Z","title":"Deep probabilistic models to detect data poisoning attacks","venue":null,"work_id":null,"year":1912},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":55,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.380682Z"},"links":{"cited_paper":"/paper/1912.01206","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:83596bbf4034f89ef2a26f5338c5204e411b282765501f234d9ee3f32f6d9b8d","observation_id":"d8220cac-d5a3-4506-af0a-702516a1adb9","resolution":{"observed_at":"2026-08-15T20:46:59.380682Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2006.14871","last_updated":"2022-07-28T18:22:05Z","snapshot_observed_at":"2026-08-11T06:13:31.384269Z","submitted_at":"2020-06-26T09:09:27Z","title":"Can We Mitigate Backdoor Attack Using Adversarial Detection Methods?","version":2},"cited_work":{"arxiv_id":"2006.14871","doi":null,"metadata_source":"pith","pith_arxiv_id":"2006.14871","snapshot_observed_at":"2026-08-15T20:46:59.562264Z","title":"Can We Mitigate Backdoor Attack Using Adversarial Detection Methods?","venue":"cs.LG","work_id":"0bbb24f2-6cb1-469d-8aa0-e947f1398293","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":56,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.384827Z"},"links":{"cited_paper":"/paper/2006.14871","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:0936bb016b63fcbac5f922d2d010c6be0f09f38db2ce83e951c7ad22341acd4d","observation_id":"14f0d770-92c4-4776-a143-e0aa6d0c6f07","resolution":{"observed_at":"2026-08-15T20:46:59.568759Z","resolver_source":"local_arxiv","status":"verified_exact"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.917071Z","title":"Fedinv: Byzantine-robust federated learning by inversing local model updates","venue":null,"work_id":"743b82a4-62f9-4d5a-9734-fb9d2f0ab58c","year":2022},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":57,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.388926Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:665a37cce4d9c9de09750fb4c942f2aec0e204500a1ef97cb2bfa4d0d72cba0d","observation_id":"48974221-f73c-440c-bc26-b80ec2d2ad8b","resolution":{"observed_at":"2026-08-15T20:46:59.921419Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.903797Z","title":"Flip: A provable defense framework for backdoor mitigation in federated learning","venue":null,"work_id":"84f43739-7337-4550-8f83-8bdf685ce189","year":2023},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":58,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.392869Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:c4c4405877962efeb6928c2bdadcb0d7963c3e505438e796e404bdd06605d34a","observation_id":"f1c94e5c-40cc-4d36-a06c-c4d3f45fdbb4","resolution":{"observed_at":"2026-08-15T20:46:59.908172Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"2207.08486","last_updated":"2025-03-25T07:50:17Z","snapshot_observed_at":"2026-08-17T15:06:07.008604Z","submitted_at":"2022-07-18T10:10:45Z","title":"Using Anomaly Detection to Detect Poisoning Attacks in Federated Learning Applications","version":4},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2207.08486","snapshot_observed_at":"2026-08-15T20:46:59.396695Z","title":"Using anomaly detection to detect poisoning attacks in federated learning applications","venue":null,"work_id":null,"year":2022},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":59,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.396695Z"},"links":{"cited_paper":"/paper/2207.08486","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:705a968195e0d4e4abd9760cf088dc6c888ba41ae41547fcdf6e6fbc4eca8e9e","observation_id":"086b95fe-533d-422f-bc1b-0d6e28ef4057","resolution":{"observed_at":"2026-08-15T20:46:59.396695Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.400671Z","title":"Exploiting shared representations for personalized federated learning","venue":null,"work_id":null,"year":2021},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":60,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.400671Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:c90cdd9ef8053877d3d1d5de3d5f13300e3a876a7219732f8625ef023f41f827","observation_id":"e511639d-2ca9-4659-bcc9-a58fe15599b7","resolution":{"observed_at":"2026-08-15T20:46:59.400671Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.881612Z","title":"Efficient wireless federated learning with partial model aggregation","venue":null,"work_id":"57648391-84a5-4533-9e2f-c32b0b577cfc","year":2024},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":61,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.404662Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:1a02f0ee9808f396e04df001c7a7b11823f1b664643c318d5960e29819156257","observation_id":"016e92c2-d0ae-4037-885a-1cac6b60d188","resolution":{"observed_at":"2026-08-15T20:46:59.886035Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.868416Z","title":"Federated learning with partial model personalization","venue":null,"work_id":"01e9831e-8d2e-43f8-9926-77f3fade4027","year":2022},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":62,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.408620Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:72731ed38523bfe0675dd4e6667633ff8acbe7e145b24402b342e724dda414f6","observation_id":"e91b606f-d71a-4b48-b00d-b47466865502","resolution":{"observed_at":"2026-08-15T20:46:59.872782Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1912.00818","last_updated":"2019-12-02T14:29:00Z","snapshot_observed_at":"2026-08-16T08:02:37.158308Z","submitted_at":"2019-12-02T14:29:00Z","title":"Federated Learning with Personalization Layers","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1912.00818","snapshot_observed_at":"2026-08-15T20:46:59.412628Z","title":"Federated learning with personalization layers","venue":null,"work_id":null,"year":1912},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":63,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.412628Z"},"links":{"cited_paper":"/paper/1912.00818","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:4bca4e2b1050846a0abcc8bf326e1cde54ccb11fcc9455142755b5e5c1515aac","observation_id":"23e5d9e7-71f3-40a6-8e3b-ee390cd83685","resolution":{"observed_at":"2026-08-15T20:46:59.412628Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.416762Z","title":"Personalized federated learning with moreau envelopes","venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":64,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.416762Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:45a5dc6da7050d0df1d6156bb238e4f9ec21909fb417b68b3eb428809360df5a","observation_id":"1c39584a-327c-4c48-b80e-25d92e8d9edd","resolution":{"observed_at":"2026-08-15T20:46:59.416762Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2305.15706","last_updated":"2023-05-25T04:25:55Z","snapshot_observed_at":"2026-08-16T15:29:54.263126Z","submitted_at":"2023-05-25T04:25:55Z","title":"pFedSim: Similarity-Aware Model Aggregation Towards Personalized Federated Learning","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2305.15706","snapshot_observed_at":"2026-08-15T20:46:59.421002Z","title":"arXiv preprint arXiv:2305.15706, 2023","venue":null,"work_id":null,"year":2023},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":65,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.421002Z"},"links":{"cited_paper":"/paper/2305.15706","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:9ba8e3ba7b9f46cd9b7c5a11e14b43dcbdbd17f9c644bbd5fc061b0f08b802cd","observation_id":"15ded010-e57d-4a7e-b4c1-775e26c7b163","resolution":{"observed_at":"2026-08-15T20:46:59.421002Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":{"arxiv_id":"2003.13376","last_updated":"2020-08-02T08:51:07Z","snapshot_observed_at":"2026-08-13T23:09:09.904759Z","submitted_at":"2020-03-30T12:12:51Z","title":"End-to-End Evaluation of Federated Learning and Split Learning for Internet of Things","version":2},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"2003.13376","snapshot_observed_at":"2026-08-15T20:46:59.426048Z","title":"End-to-end evaluation of federated learning and split learning for internet of things","venue":null,"work_id":null,"year":2003},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":66,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.426048Z"},"links":{"cited_paper":"/paper/2003.13376","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:1d96562857d021829723840b4c4a30cbb333dcee99d398eb004a9cfb10900436","observation_id":"9ad22181-4d3f-49bc-a2d8-32d1f2310f33","resolution":{"observed_at":"2026-08-15T20:46:59.426048Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.847316Z","title":"Revisiting personalized federated learning: Robustness against backdoor attacks","venue":null,"work_id":"ff7f01d5-26d3-4c32-a21b-8866d9bb96d1","year":2023},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":67,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.430288Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:717a4d717ab8a51e9ed536d6c8b9fd621e2d0181ad891f843db535fa36da705e","observation_id":"5862e7e1-643e-4777-943d-f42ecee13668","resolution":{"observed_at":"2026-08-15T20:46:59.851565Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.833978Z","title":"One-pixel signature: Characterizing cnn models for backdoor detection","venue":null,"work_id":"b96aa3c2-b214-4074-a6b9-61e1f73944b6","year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":68,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.434309Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:a7d24e1f984de89f0968cda58c6d357fb23936e1329d74eb8d960b47f2feb9f4","observation_id":"a5f98215-0422-4f2c-ab36-05348519d429","resolution":{"observed_at":"2026-08-15T20:46:59.838472Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.821117Z","title":"Xmam: X-raying models with a matrix to reveal backdoor attacks for federated learning","venue":null,"work_id":"16ba898d-6cd8-4bc1-a9c8-e75c392e1cbe","year":2024},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":69,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.438310Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:eefb6a40dc2177577e455d85794ecd78210d660df257d6fd0ef3882007354aa9","observation_id":"ffab6e22-76f6-4010-ad1e-5707eb8bf66e","resolution":{"observed_at":"2026-08-15T20:46:59.825320Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.442331Z","title":"Gradient-based learning applied to document recognition","venue":null,"work_id":null,"year":1998},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":70,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.442331Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:db1fc1094e1a0fab70c8a8d451e39eb2e362448b87ee8b79994be77249869690","observation_id":"ef2fc77b-f403-4145-b8cb-05c2475924c9","resolution":{"observed_at":"2026-08-15T20:46:59.442331Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.446310Z","title":"Handwritten digit recognition with a back-propagation network.Advances in neural information processing systems, 2, 1989","venue":null,"work_id":null,"year":1989},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":71,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.446310Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:4d23cae2c778f116f03f1deebfbe8a149239194278f3fa49529857e9f7ded772","observation_id":"e563ed44-6932-4fd1-b7ee-741d365dc6fa","resolution":{"observed_at":"2026-08-15T20:46:59.446310Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.450356Z","title":"Learning multiple layers of features from tiny images","venue":null,"work_id":null,"year":2009},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":72,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.450356Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:21f3dee338b89b934e9d14c2f0f1769c349a628aab772429a23e37f1d637162e","observation_id":"bfeb4a41-137c-4832-b623-8405364a9f31","resolution":{"observed_at":"2026-08-15T20:46:59.450356Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.783923Z","title":"Deep residual learning for image recognition","venue":null,"work_id":"5e4a2906-dfeb-4b39-9f51-d2c9615efd56","year":2016},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":73,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.454492Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:3c2f32ea5908774cb05129f4e7ef71ff61ba33de4f38ec44cb5c67a491192ca9","observation_id":"7b8b65b9-1b10-4f71-a55e-57d8ba8063d4","resolution":{"observed_at":"2026-08-15T20:46:59.788315Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":{"arxiv_id":"1704.04861","last_updated":"2017-04-17T03:57:34Z","snapshot_observed_at":"2026-07-06T02:11:23.670680Z","submitted_at":"2017-04-17T03:57:34Z","title":"MobileNets: Efficient Convolutional Neural Networks for Mobile Vision Applications","version":1},"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":"1704.04861","snapshot_observed_at":"2026-08-15T20:46:59.458791Z","title":"Mobilenets: Efficient convolutional neural networks for mobile vision applications","venue":null,"work_id":null,"year":2017},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":74,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.458791Z"},"links":{"cited_paper":"/paper/1704.04861","citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:6f370c5a4fe2c9658367147270e123eb3b6573fca9e4b21e2e3b20444b99eab9","observation_id":"175686b9-f703-431b-a961-57f0b1bc55fa","resolution":{"observed_at":"2026-08-15T20:46:59.458791Z","resolver_source":null,"status":"unresolved"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":"raw_reference","pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.770779Z","title":"Byzantine-robust distributed learning: Towards optimal statistical rates","venue":null,"work_id":"73915efc-b69e-4009-8b10-2f01ba424157","year":2018},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":75,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.463287Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:f9d24b2674704d257ec05b85f2b231270fd1f5bc2a4054b5feefe1c522ccb0df","observation_id":"ee5caf8f-5c8d-41a7-b001-9616608e23bb","resolution":{"observed_at":"2026-08-15T20:46:59.775069Z","resolver_source":"raw_fallback","status":"verified_fuzzy"},"standing_notice":{"events":[],"observation":"No event found in the named queried sources as of 2026-08-19T06:32:44.657259+00:00.","reason":null,"source_receipts":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"state":"measured"}},{"citation":{"cited_paper":null,"cited_work":{"arxiv_id":null,"doi":null,"metadata_source":null,"pith_arxiv_id":null,"snapshot_observed_at":"2026-08-15T20:46:59.340558Z","title":null,"venue":null,"work_id":null,"year":2020},"citing_paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients","version":1},"reference_index":2020,"source":"pdf_text","source_observed_at":"2026-08-15T20:46:59.340558Z"},"links":{"citing_paper":"/paper/2505.12019"},"observation_digest":"sha256:b7b82b27cd289495e4d96288b728d758f4bd809f96c3cce56c2d2220d56586a4","observation_id":"69c3a31f-1aeb-44c6-a488-d22bcb7dd5ea","resolution":{"observed_at":"2026-08-15T20:46:59.340558Z","resolver_source":null,"status":"parse_uncertain"},"standing_notice":{"events":[],"reason":"canonical_work_link_unavailable","source_receipts":[],"state":"unavailable"}}],"paper":{"arxiv_id":"2505.12019","last_updated":"2025-05-17T14:16:47Z","latest_version":1,"primary_category":"cs.CR","snapshot_observed_at":"2026-08-19T07:16:36.992407Z","submitted_at":"2025-05-17T14:16:47Z","title":"FL-PLAS: Federated Learning with Partial Layer Aggregation for Backdoor Defense Against High-Ratio Malicious Clients"},"reference_resolution":{"displayed":76,"state_counts":{"malformed_identifier":0,"metadata_mismatch":0,"parse_uncertain":1,"unresolved":28,"verified_exact":1,"verified_fuzzy":46},"total_outbound_references":76},"refusal":"A citation records a reference. It does not transfer a finding from one paper to another.","schema":"pith.paper-citation-record.v1","standing_sources":[{"observed_at":"2026-08-19T06:32:44.657259+00:00","source":"crossref"},{"observed_at":"2026-08-19T06:32:39.956319+00:00","source":"retraction_watch"}],"thesis":"As of 19 August 2026, this Paper Citation Record lists 76 of 76 outbound references and 1 inbound Pith citation observation for arXiv:2505.12019."}