Pith. sign in

REVIEW 4 major objections 5 minor 297 references

A Survey of Secure Semantic Communications

T0 review · 4 major / 5 minor · reviewed 2026-08-10 · deepseek-v4-flash

Pith's one-line read This survey maps secure semantic communication onto three life-cycle phases and matches threats to defense families.

desk verdict A genuinely useful survey of secure SemCom, but the threat taxonomy needs a fix before it is a reliable reference. read the letter →

arxiv 2501.00842 v2 pith:V7QRNSUE submitted 2025-01-01 cs.CR eess.IVeess.SP

classification cs.CReess.IVeess.SP
keywords Semanticcommunicationwirelesssecurityprivacy6Gfederatedlearningphysical-layerthreattaxonomybackdoorattacks
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

Semantic communication (SemCom) replaces bit-perfect transmission with the transfer of meaning: transmitters extract semantic features, receivers reconstruct intent, and both sides rely on AI models as a shared knowledge base. This survey tries to establish that the security and privacy problems of that new setting are not a random list but a structured map, organized by the life cycle of the system: model training, model transfer, and semantic information transmission. For each stage it names the threats—poisoning, gradient leakage, server compromise, bottleneck failures, model-slice attacks, semantic adversarial, eavesdropping, inference, and jamming attacks—and then matches them to nine families of defenses, including robust learning, differential privacy, cryptography, blockchain, model compression, and physical-layer security. A reader who accepts the map can locate where an attack enters a SemCom system and which defense family should meet it, and can see which phases still lack mature protections.

What carries the argument

The organizing device is the SemCom life cycle, defined as the sequence from federated model training on cloud and edge servers, through model and model-slice transfer between nodes, to online semantic information transmission between a transmitter and receiver. Around this life cycle the paper wraps a two-sided taxonomy: a threat table keyed to confidentiality, integrity, and availability, and a defense table that groups countermeasures into nine families. The taxonomy does the argument's work by forcing every attack into a phase and every defense into a category, which is what lets the survey claim completeness and lets readers see which cells of the map are empty or underdeveloped.

What would settle it

Open the two papers cited for the bottleneck category (markers [85] and [98] in the survey) and check whether either describes an adversary that deliberately exhausts bandwidth or causes dropout; if both describe only capacity limits and resource contention, then that row of the threat table is not an attack, and the survey's adversarial threat taxonomy is contradicted by its own evidence.

Watch

Extended reading notes

Core claim

The paper's central claim is that securing SemCom can be understood phase by phase because each phase has its own assets and exposure. During model training, the asset is the knowledge base and the risks are poisoning, gradient leakage, server compromise, and communication bottlenecks in federated updates. During model transfer, the asset is the model or its slices, and the risks are availability loss and forgery. During semantic information transmission, the asset is the meaning carried by semantic symbols, and the risks are adversarial perturbation, eavesdropping, inference, and jamming. The paper then claims that existing defenses—from data cleaning and robust aggregation to homomorphic encryption, blockchain, and physical-layer security—can be classified to cover exactly these threats, and it identifies open problems where coverage is still thin. The contribution is not a new protocol but a taxonomy that turns a scattered literature into a decision aid.

Load-bearing premise

The survey's claim depends on its threat taxonomy being genuinely a list of adversarial acts; at least one named category, 'attacks against communication bottlenecks,' describes bandwidth limits and edge-server dropout that can occur without any adversary, so if that category is not a real attack class the map mixes resource constraints with malicious actions.

Editorial extensions

If this is right

  • A researcher who encounters a new attack on a SemCom system can first locate it in one of the three life-cycle phases and then narrow the defense search to the corresponding family in the nine-category table.
  • Defenses developed for general federated learning and AI security—robust aggregation, data cleaning, differential privacy, backdoor detection—transfer to the training and transfer phases of SemCom rather than applying only to the wireless transmission stage.
  • Cryptography and blockchain are positioned as protection for model updates and model slices, while physical-layer security is positioned for semantic eavesdropping, inference, and jamming, giving each defense family a clear home.
  • The survey's open-problem list—dynamic data cleaning, explainable robust learning, differential-privacy-based deep JSCC, efficient homomorphic encrypted SemCom, smart-contract-enabled SemCom, and semantic channel fingerprint databases—defines a concrete near-term research agenda for the field.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • A testable extension is to split the 'bottleneck' category into adversarial denial-of-service versus non-malicious resource constraints, since the two need different defenses and the survey currently treats them together.
  • The phase-by-phase map suggests that semantic fidelity—how well meaning survives an attack—could serve as a unified evaluation metric across all nine defense families, a metric the survey itself does not apply.
  • If the taxonomy is right, then securing the model transfer phase deserves as much attention as securing the wireless channel, because model-slice forgery and availability attacks can corrupt semantic communication before any symbol is sent.
  • The survey borrows heavily from federated-learning security; a natural next step it leaves implicit is to benchmark which transferred defenses preserve reconstruction quality under realistic channel noise, not just classification accuracy.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 5 minor

Summary. This survey aims to provide a comprehensive, structured overview of security and privacy in semantic communication (SemCom). It organizes the field around a three-phase life cycle—model training, model transfer, and semantic information transmission—and, for each phase, lists representative threats and maps them to defensive technologies such as data cleaning, robust learning, backdoor defenses, adversarial training, differential privacy, cryptography, blockchain, model compression, and physical-layer security. The paper also includes architectural background, tables of threats and defenses, and a set of future research directions.

Significance. If the taxonomy were reliable, the survey would be a useful entry point for researchers because of its broad citation coverage, its life-cycle organization, and its tabular summaries of both attacks and defenses. The tables provide a quick reference that is genuinely convenient. However, the paper's central contribution is the threat taxonomy and its defense mapping, and part of that taxonomy conflates non-adversarial resource constraints with intentional attacks. Because the reliability of the entire structured map depends on that taxonomy, the survey's practical value for threat modeling is currently limited. The paper does not contain machine-checked proofs or reproducible experiments, but as a survey its value is organizational, and that value is real once the categorization errors are corrected.

major comments (4)
  1. [§3.3.4 and Table 3] The category "attacks against communication bottlenecks" does not describe an attack. The phenomena listed in §3.3.4—high communication overhead, limited bandwidth, delays causing edge-server dropout, and data heterogeneity—are resource constraints and reliability issues that can occur with no adversary present. The paper itself acknowledges in §3.2.3 that typical availability issues include non-malicious hardware failures and software downtime. Yet Table 3 lists "attacks against communication bottlenecks" as a training-stage threat with property "Availability," and Table 4 pairs model compression with this category as a defensive measure. This conflates non-adversarial engineering limits with malicious security threats and undermines the reliability of the life-cycle-to-threat mapping. Please either reframe this entry as a non-adversarial availability challenge, or introduce an explicit adversary model that makes it an attack, and adjust Tables 3 and 4 accordingly.
  2. [§3.4.1 and Table 3] The "model slice availability attacks" category mixes at least three distinct issues: confidentiality failures caused by insufficient isolation, fairness problems caused by uneven resource allocation, and Denial-of-Service attacks. The table row states that such attacks "corrupt the parameters of the model slices," which is an integrity effect rather than an availability effect. Because the same category is assigned the single property "Availability," the CIA labeling is internally inconsistent. Please decompose these into separate threat entries with consistent security properties, or rewrite the category so that it describes one coherent attack type.
  3. [§3.3.2, Eq. (1)] Equation (1) is not a derivation and is notationally ill-defined. The quantities ∇W and ∇W′ are not defined, the function f(x′,s′,y′) is not defined, and the constraint "x′,s′,y′ ∼ f(x′,s′,y′)" is circular unless f is a sampling distribution, which is not what the surrounding text states. Earlier in the same subsection, x′ is used for both the original information and the semantic information, compounding the ambiguity. Because this equation is offered as the basis for the claim that SemCom gradient leakage is "deeper and easier," it needs either a precise formulation with all variables defined or an explicit downgrade to an informal illustrative statement.
  4. [§3.5, Eqs. (2)–(3)] The advantage function Adv[A,E] = |Pr(M0 − M1)| is not a well-formed probability expression: M0 and M1 are defined as events, so the expression should be a difference of probabilities (e.g., |Pr[M0] − Pr[M1]|), typically expressed as a guessing advantage relative to 1/2. Equation (3) adds "model" as an extra argument but never defines the distribution over models or the associated advantage function. As written, these equations do not state the semantic-security claim that the text attributes to them. Please replace them with a standard semantic-security definition and then state, as a separate formal assumption, how the attacker's possession of a reconstructed model affects the advantage.
minor comments (5)
  1. [§4.5, Eq. (4)] The (ε,δ)-differential privacy inequality is misstated: it should read Pr[M(d_C) ∈ S_C] ≤ e^ε · Pr[M(d′_C) ∈ S_C] + δ, not Pr[e^ε M(d′_C) ∈ S_C] + δ.
  2. [§3.3.1, §3.3.4, Table 3] There are several typos and grammatical errors: "Backdoor attack is a special kind of backdoor attacks," "the cloude server," "exmaple," and "V ulnerability" in Table 3. A careful proofreading pass is needed.
  3. [Table 2] The acronym table appears to have a formatting problem in the DNN/PHE row, where entries seem to be merged. Please check the table layout.
  4. [§4.1, §4.2, §4.3] Repeated phrases such as "The below, as shown in Table 5, the following content" are ungrammatical and should be revised to plain introductory sentences.
  5. [§3.5.2] The sentence "privacy properties of SemCom degrade much more grace" contains a typo (probably "gracefully") and should be corrected.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: the paper is a taxonomic survey with no derivational claims that reduce to their inputs.

full rationale

This is a survey paper rather than a derivation, so the circularity patterns involving fitted inputs, self-referential equations, and imported uniqueness theorems do not apply. The paper's contribution is a lifecycle-based organization of existing threats and defenses in secure semantic communication. Its equations (Eq. 1 for gradient approximation, Eqs. 2-3 for semantic advantage, Eq. 4 for differential privacy) restate standard definitions from cited prior work and are not used to generate predictions from fitted parameters. The taxonomy does contain a questionable classification: §3.3.4 labels high communication overhead, limited bandwidth, and edge-server dropout as 'attacks against communication bottlenecks,' even though the described phenomena can be non-adversarial resource constraints; however, this is a correctness and scope concern about the threat model, not a circular reduction. Similarly, the paper's reliance on works plausibly from its own group (e.g., [183] on homomorphic-encrypted deep JSCC) is one example within a broad survey of defense technologies, and accepting or rejecting that work does not force the survey's organizational claims. No load-bearing step is equivalent by construction to its input, so the appropriate circularity score is 0.

Assumptions & free parameters 0 free parameters · 1 assumptions · 0 invented entities

No free parameters or invented entities are introduced because the paper is a literature review. The primary unstated premise is that the surveyed literature is representative and correctly summarized.

assumptions (1)
  • domain assumption The cited works are accurately represented and their conclusions are correct.
    The survey's statements about threats and defenses rely on the validity of the referenced papers. If several key references are mischaracterized, the survey's conclusions could be wrong.

how reviews work

0 comments
Cite this review

Pith. "Pith review of A Survey of Secure Semantic Communications." pith.science (2026). https://pith.science/paper/V7QRNSUE

@misc{pith2026250100842,
  author       = {Pith},
  title        = {Pith review of: A Survey of Secure Semantic Communications},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/V7QRNSUE}},
  note         = {Machine review of arXiv:2501.00842}
}
read the original abstract

Semantic communication (SemCom) is regarded as a promising and revolutionary technology in 6G, aiming to transcend the constraints of ``Shannon's trap" by filtering out redundant information and extracting the core of effective data. Compared to traditional communication paradigms, SemCom offers several notable advantages, such as reducing the burden on data transmission, enhancing network management efficiency, and optimizing resource allocation. Numerous researchers have extensively explored SemCom from various perspectives, including network architecture, theoretical analysis, potential technologies, and future applications. However, as SemCom continues to evolve, a multitude of security and privacy concerns have arisen, posing threats to the confidentiality, integrity, and availability of SemCom systems. This paper presents a comprehensive survey of the technologies that can be utilized to secure SemCom. Firstly, we elaborate on the entire life cycle of SemCom, which includes the model training, model transfer, and semantic information transmission phases. Then, we identify the security and privacy issues that emerge during these three stages. Furthermore, we summarize the techniques available to mitigate these security and privacy threats, including data cleaning, robust learning, defensive strategies against backdoor attacks, adversarial training, differential privacy, cryptography, blockchain technology, model compression, and physical-layer security. Lastly, this paper outlines future research directions to guide researchers in related fields.

Figures

Figures reproduced from arXiv: 2501.00842 by the authors.

Figure 1
Figure 1. Organizations of this paper. 3 provides the security and privacy violation issues during each stage of Sem￾Com. Sec. 4 provides insights into existing defense mechanisms to enhance the security and privacy of SemCom. Sec. 5 looks forward to the future research direction. Finally, Sec. 6 concludes this paper. The acronyms used in this paper are listed in Tab. 2 [PITH_FULL_IMAGE:figures/full_fig_p009_1.png] view at source ↗
Figure 2
Figure 2. Comparison of the link-level architecture between traditional communication [PITH_FULL_IMAGE:figures/full_fig_p011_2.png] view at source ↗
Figure 3
Figure 3. Network-level architecture of SemCom systems, where the semantic collabora [PITH_FULL_IMAGE:figures/full_fig_p013_3.png] view at source ↗
Figures from the paper (24 more)
Figure 4
Figure 4. Figure 4: Life cycle of SemComs, where a centralized model is first trained on the cloud [PITH_FULL_IMAGE:figures/full_fig_p016_4.png]
Figure 5
Figure 5. Figure 5: Data cleaning in DL [117], where the process ensures the quality and consistency [PITH_FULL_IMAGE:figures/full_fig_p031_5.png]
Figure 6
Figure 6. Figure 6: Diagram of FL [125], where data is processed in a decentralized manner by [PITH_FULL_IMAGE:figures/full_fig_p037_6.png]
Figure 7
Figure 7. Figure 7: Malicious client attacks in FL [129], where malicious clients attempt to leak [PITH_FULL_IMAGE:figures/full_fig_p039_7.png]
Figure 8
Figure 8. Figure 8: Comparison of noise distributions under the expectation-based model and the [PITH_FULL_IMAGE:figures/full_fig_p041_8.png]
Figure 9
Figure 9. Figure 9: Classification of neural network backdoor defense [139], where the process of [PITH_FULL_IMAGE:figures/full_fig_p044_9.png]
Figure 10
Figure 10. Figure 10: The workflow of meta-classifier defense [139], where the data that reflect the [PITH_FULL_IMAGE:figures/full_fig_p049_10.png]
Figure 11
Figure 11. Figure 11: Process of adversarial training [150], where adversarial training enhances tradi [PITH_FULL_IMAGE:figures/full_fig_p051_11.png]
Figure 12
Figure 12. Figure 12: Semantic distance minimization mechanism [152], where lines of the same [PITH_FULL_IMAGE:figures/full_fig_p055_12.png]
Figure 13
Figure 13. Figure 13: Differential privacy mechanism [162], where depicts a privacy-preserving system [PITH_FULL_IMAGE:figures/full_fig_p061_13.png]
Figure 14
Figure 14. Figure 14: The three phase of differential privacy deployed in DL model [163], where [PITH_FULL_IMAGE:figures/full_fig_p062_14.png]
Figure 15
Figure 15. Figure 15: The architecture of a Paillier federated network [181], where each client requests [PITH_FULL_IMAGE:figures/full_fig_p073_15.png]
Figure 16
Figure 16. Figure 16: The diagram of SMPC [194], where multiple parties collaboratively com [PITH_FULL_IMAGE:figures/full_fig_p075_16.png]
Figure 17
Figure 17. Figure 17: SGX Diagram [186], where secret shares and random masks are combined with [PITH_FULL_IMAGE:figures/full_fig_p079_17.png]
Figure 18
Figure 18. Figure 18: Schematic diagram of the algorithm based on the FFT [187], where secret shares [PITH_FULL_IMAGE:figures/full_fig_p081_18.png]
Figure 19
Figure 19. Figure 19: Functional diagram of a blockchain network [217], where blockchain transaction [PITH_FULL_IMAGE:figures/full_fig_p085_19.png]
Figure 20
Figure 20. Figure 20: An illustrative framework of Blockchain-Semantic ecosystems [218], where be [PITH_FULL_IMAGE:figures/full_fig_p089_20.png]
Figure 21
Figure 21. Figure 21: Combination of model pruning and FL [231], where two stages are involved, [PITH_FULL_IMAGE:figures/full_fig_p097_21.png]
Figure 22
Figure 22. Figure 22: Comparison between quantization aware training and post training quanti [PITH_FULL_IMAGE:figures/full_fig_p099_22.png]
Figure 23
Figure 23. Figure 23: Residual error based knowledge distillation [238], where the Assistant (middle) [PITH_FULL_IMAGE:figures/full_fig_p105_23.png]
Figure 24
Figure 24. Figure 24: Semantic-bit coexisting communication framework [263], where a single-cell [PITH_FULL_IMAGE:figures/full_fig_p111_24.png]
Figure 25
Figure 25. Figure 25: Semantic-forward for cooperative communications [286], where SemComs are [PITH_FULL_IMAGE:figures/full_fig_p116_25.png]
Figure 26
Figure 26. Figure 26: Unified framework for IRS-aided SemCom systems [274], where the edge device [PITH_FULL_IMAGE:figures/full_fig_p117_26.png]
Figure 27
Figure 27. Figure 27: Environment semantics enabled PLA [279], where angle-delay features are ex [PITH_FULL_IMAGE:figures/full_fig_p120_27.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

297 extracted references · 41 canonical work pages

  1. [1]

    C.-X. Wang, X. You, X. Gao, X. Zhu, Z. Li, C. Zhang, H. Wang, Y. Huang, Y. Chen, H. Haas, et al., On the road to 6g: Visions, require- ments, key technologies, and testbeds, IEEE Communications Surveys & Tutorials 25 (2) (2023) 905–974

  2. [2]

    URL https://www.itu.int/rec/R-REC-M.2160/en

    ITU-R, M.2160 : Framework and overall objectives of the future de- velopment of imt for 2030 and beyond (2023). URL https://www.itu.int/rec/R-REC-M.2160/en

  3. [3]

    Zhang, W

    P. Zhang, W. Xu, Y. Liu, X. Qin, K. Niu, S. Cui, G. Shi, Z. Qin, X. Xu, F. Wang, et al., Intellicise wireless networks from semantic communica- tions: A survey, research issues, and challenges, IEEE Communications Surveys & Tutorials (2024)

  4. [4]

    C. E. Shannon, A mathematical theory of communication, ACM SIG- MOBILE mobile computing and communications review 5 (1) (2001) 3–55

  5. [5]

    X. Xu, B. Xu, S. Han, C. Dong, H. Xiong, R. Meng, P. Zhang, Task- oriented and semantic-aware heterogeneous networks for artificial in- telligence of things: Performance analysis and optimization, IEEE In- ternet of Things Journal (2023)

  6. [6]

    B. Xu, R. Meng, Y. Chen, X. Xu, C. Dong, H. Sun, Latent seman- tic diffusion-based channel adaptive de-noising semcom for future 6g systems, in: GLOBECOM 2023-2023 IEEE Global Communications Conference, IEEE, 2023, pp. 1229–1234

  7. [7]

    K. Niu, P. Zhang, A mathematical theory of semantic communication, Journal on Communications (2024) 1–52

  8. [8]

    Y. Shao, Q. Cao, D. G¨ und¨ uz, A theory of semantic communication, IEEE Transactions on Mobile Computing (2024)

Show all 297 references
  1. [9]

    G. Xin, P. Fan, K. B. Letaief, Semantic communication: A survey of its theoretical development (2024). 129

  2. [10]

    Zhang, X

    P. Zhang, X. Xu, C. Dong, K. Niu, H. Liang, Z. Liang, X. Qin, M. Sun, H. Chen, N. Ma, et al., Model division multiple access for seman- tic communications, Frontiers of Information Technology & Electronic Engineering 24 (6) (2023) 801–812

  3. [11]

    Chaccour, W

    C. Chaccour, W. Saad, M. Debbah, Z. Han, H. V. Poor, Less data, more knowledge: Building next generation semantic communication networks, IEEE Communications Surveys & Tutorials (2024)

  4. [12]

    Liang, H

    C. Liang, H. Du, Y. Sun, D. Niyato, J. Kang, D. Zhao, M. A. Imran, Generative ai-driven semantic communication networks: Architecture, technologies and applications, IEEE Transactions on Cognitive Com- munications and Networking (2024)

  5. [13]

    Xu, T.-Y

    J. Xu, T.-Y. Tung, B. Ai, W. Chen, Y. Sun, D. G¨ und¨ uz, Deep joint source-channel coding for semantic communications, IEEE Communi- cations Magazine 61 (11) (2023) 42–48

  6. [14]

    Nemati, J

    M. Nemati, J. Park, J. Choi, Vq-vae empowered wireless communica- tion for joint source-channel coding and beyond, in: GLOBECOM 2023 - 2023 IEEE Global Communications Conference, 2023, pp. 3155–3160

  7. [15]

    H. Wu, Y. Shao, C. Bian, K. Mikolajczyk, D. G¨ und¨ uz, Deep joint source-channel coding for adaptive image transmission over mimo chan- nels, IEEE Transactions on Wireless Communications 23 (10) (2024) 15002–15017

  8. [16]

    Huang, D

    J. Huang, D. Li, C. Huang, X. Qin, W. Zhang, Joint task and data- oriented semantic communications: A deep separate source-channel coding scheme, IEEE Internet of Things Journal 11 (2) (2024) 2255– 2272

  9. [17]

    Y. Wang, S. Han, X. Xu, H. Liang, R. Meng, C. Dong, P. Zhang, Fea- ture importance-aware task-oriented semantic transmission and opti- mization, IEEE Transactions on Cognitive Communications and Net- working (2024)

  10. [18]

    M. U. Lokumarambage, V. S. S. Gowrisetty, H. Rezaei, T. Sivalingam, N. Rajatheva, A. Fernando, Wireless end-to-end image transmission system using semantic communications, IEEE Access 11 (2023) 37149– 37163. 130

  11. [19]

    S. Wang, J. Dai, Z. Liang, K. Niu, Z. Si, C. Dong, X. Qin, P. Zhang, Wireless deep video semantic transmission, IEEE Journal on Selected Areas in Communications 41 (1) (2022) 214–229

  12. [20]

    S. Yao, K. Niu, S. Wang, J. Dai, Semantic coding for text transmission: An iterative design, IEEE Transactions on Cognitive Communications and Networking 8 (4) (2022) 1594–1603

  13. [21]

    T. Han, Q. Yang, Z. Shi, S. He, Z. Zhang, Semantic-preserved commu- nication system for highly efficient speech transmission, IEEE Journal on Selected Areas in Communications 41 (1) (2023) 245–259

  14. [22]

    M. Shen, J. Wang, H. Du, D. Niyato, X. Tang, J. Kang, Y. Ding, L. Zhu, Secure semantic communications: Challenges, approaches, and opportunities, IEEE Network (2023)

  15. [23]

    Z. Yang, M. Chen, G. Li, Y. Yang, Z. Zhang, Secure semantic commu- nications: Fundamentals and challenges, IEEE Network (2024)

  16. [24]

    S. Guo, Y. Wang, N. Zhang, Z. Su, T. H. Luan, Z. Tian, X. Shen, A survey on semantic communication networks: Architecture, security, and privacy, arXiv preprint arXiv:2405.01221 (2024)

  17. [25]

    H. Du, J. Wang, D. Niyato, J. Kang, Z. Xiong, M. Guizani, D. I. Kim, Rethinking wireless communication security in semantic internet of things, IEEE Wireless Communications 30 (3) (2023) 36–43

  18. [26]

    Y. Chen, Q. Yang, Z. Shi, J. Chen, The model inversion eavesdropping attack in semantic communication systems, in: GLOBECOM 2023- 2023 IEEE Global Communications Conference, IEEE, 2023, pp. 5171– 5177

  19. [27]

    Y. Wang, S. Guo, Y. Deng, H. Zhang, Y. Fang, Privacy-preserving task-oriented semantic communications against model inversion at- tacks, IEEE Transactions on Wireless Communications (2024)

  20. [28]

    T.-Y. Tung, D. G¨ und¨ uz, Deep joint source-channel and encryption cod- ing: Secure semantic communications, in: ICC 2023 - IEEE Inter- national Conference on Communications, 2023, pp. 5620–5625. doi: 10.1109/ICC45041.2023.10278612. 131

  21. [29]

    X. Luo, Z. Chen, M. Tao, F. Yang, Encrypted semantic communica- tion using adversarial training for privacy preserving, IEEE Communi- cations Letters 27 (6) (2023) 1486–1490. doi:10.1109/LCOMM.2023. 3269768

  22. [30]

    Y. Chen, Q. Yang, Z. Shi, J. Chen, The model inversion eavesdropping attack in semantic communication systems, in: GLOBECOM 2023 - 2023 IEEE Global Communications Conference, 2023, pp. 5171–5177. doi:10.1109/GLOBECOM54140.2023.10436996

  23. [31]

    G. Chen, G. Nan, Z. Jiang, H. Du, R. Shi, Q. Cui, X. Tao, Lightweight and robust wireless semantic communications, IEEE Communications Letters (2024) 1–1 doi:10.1109/LCOMM.2024.3409559

  24. [32]

    Y. Li, Z. Shi, H. Hu, Y. Fu, H. Wang, H. Lei, Secure semantic com- munications: From perspective of physical layer security, IEEE Com- munications Letters 28 (10) (2024) 2243–2247. doi:10.1109/LCOMM. 2024.3452715

  25. [33]

    X. Mu, Y. Liu, Semantic communication-assisted physical layer secu- rity over fading wiretap channels (2024). arXiv:2402.14581. URL https://arxiv.org/abs/2402.14581

  26. [34]

    Y. Liu, J. Wen, Z. Zhang, K. Zhu, J. Kang, Learning-based power control for secure covert semantic communication (2024).arXiv:2407. 07475. URL https://arxiv.org/abs/2407.07475

  27. [35]

    Q. Qin, Y. Rong, G. Nan, S. Wu, X. Zhang, Q. Cui, X. Tao, Se- curing semantic communications with physical-layer semantic encryp- tion and obfuscation, in: ICC 2023 - IEEE International Conference on Communications, 2023, pp. 5608–5613. doi:10.1109/ICC45041. 2023.10279807

  28. [36]

    S. Tang, C. Liu, Q. Yang, S. He, D. Niyato, Secure semantic communi- cation for image transmission in the presence of eavesdroppers, arXiv preprint arXiv:2404.12170 (2024)

  29. [37]

    R. Xu, G. Li, Z. Yang, M. Chen, Y. Liu, J. Li, Covert and re- liable semantic communication against cross-layer privacy inference 132 over wireless edge networks, in: 2024 IEEE Wireless Communica- tions and Networking Conference (WCNC), 2024, pp. 1–6. doi: 10.1109/WCNC57260.20...

  30. [38]

    D. Won, G. Woraphonbenjakul, A. B. Wondmagegn, A. T. Tran, D. Lee, D. S. Lakew, S. Cho, Resource management, security, and privacy issues in semantic communications: A survey, IEEE Commu- nications Surveys & Tutorials (2024)

  31. [39]

    Y. E. Sagduyu, T. Erpek, S. Ulukus, A. Yener, Is semantic communi- cation secure? a tale of multi-domain adversarial attacks, IEEE Com- munications Magazine 61 (11) (2023) 50–55. doi:10.1109/MCOM.006. 2200878

  32. [40]

    H. Du, J. Wang, D. Niyato, J. Kang, Z. Xiong, M. Guizani, D. I. Kim, Rethinking wireless communication security in semantic internet of things, IEEE Wireless Communications 30 (3) (2023) 36–43. doi: 10.1109/MWC.011.2200547

  33. [41]

    M. Shen, J. Wang, H. Du, D. Niyato, X. Tang, J. Kang, Y. Ding, L. Zhu, Secure semantic communications: Challenges, approaches, and opportunities, IEEE Network 38 (4) (2024) 197–206. doi:10.1109/ MNET.2023.3327111

  34. [42]

    Z. Yang, M. Chen, G. Li, Y. Yang, Z. Zhang, Secure semantic com- munications: Fundamentals and challenges, IEEE Network (2024) 1– 1doi:10.1109/MNET.2024.3411027

  35. [43]

    Luo, H.-H

    X. Luo, H.-H. Chen, Q. Guo, Semantic communications: Overview, open issues, and future research directions, IEEE Wireless Communi- cations 29 (1) (2022) 210–219. doi:10.1109/MWC.101.2100269

  36. [44]

    J. He, X. Luo, J. Kang, H. Du, Z. Xiong, C. Chen, D. Niyato, X. Shen, Toward mixture-of-experts enabled trustworthy semantic communica- tion for 6g networks (2024). arXiv:2409.15695. URL https://arxiv.org/abs/2409.15695

  37. [45]

    Zhang, X

    P. Zhang, X. Xu, C. Dong, S. Han, B. Wang, Intellicise communication system: model-driven semantic communications, The Journal of China Universities of Posts and Telecommunications 29 (1) (2022) 11. 133

  38. [46]

    Z. Wang, B. Lin, L. Sun, Y. Wang, Intelligent task offloading for 6g- enabled maritime iot based on reinforcement learning, in: 2021 Inter- national Conference on Security, Pattern Analysis, and Cybernetics (SPAC), 2021, pp. 566–570

  39. [47]

    G. Shi, Y. Xiao, Y. Li, D. Gao, X. Xie, Semantic communication net- working for the intelligence of everything, Chinese Journal on Internet of Things 5 (2021) 26–36

  40. [48]

    G. Shi, Y. Li, X. Xie, Semantic communications: Outcome of the in- telligence era, Pattern Recognition and Artificial Intelligence 31 (2018) 91–99

  41. [49]

    C. Liu, C. Guo, Y. Yang, C. Feng, Q. Sun, J. Chen, Intelligent task- oriented semantic communication method in artificial intelligence of things, Journal on Communications 11 (2021) 97–108

  42. [50]

    Yining, H

    W. Yining, H. Shujun, X. Xiaodong, M. Rui, L. Haotai, D. Chen, Z. Ping, Intellicise model transmission for semantic communication in intelligence-native 6g networks, China Communications 21 (7) (2024) 95–112

  43. [51]

    Fedus, B

    W. Fedus, B. Zoph, N. Shazeer, Switch transformers: Scaling to trillion parameter models with simple and efficient sparsity, Journal of Machine Learning Research 23 (120) (2022) 1–39

  44. [52]

    Fui-Hoon Nah, R

    F. Fui-Hoon Nah, R. Zheng, J. Cai, K. Siau, L. Chen, Generative ai and chatgpt: Applications, challenges, and ai-human collaboration (2023)

  45. [53]

    H. Chen, S. Chen, C. He, H. Li, A scalable semantic communication system based on meta-learning, in: 2024 International Wireless Com- munications and Mobile Computing (IWCMC), IEEE, 2024, pp. 561– 566

  46. [54]

    Q. Wu, F. Liu, H. Xia, T. Zhang, Semantic transfer between different tasks in the semantic communication system, in: 2022 IEEE Wireless Communications and Networking Conference (WCNC), IEEE, 2022, pp. 566–571. 134

  47. [55]

    C. Liu, Y. Zhou, Y. Chen, S.-H. Yang, Knowledge distillation based se- mantic communications for multiple users, IEEE Transactions on Wire- less Communications (2023)

  48. [56]

    D. Li, J. Wang, Fedmd: Heterogenous federated learning via model distillation, arXiv preprint arXiv:1910.03581 (2019)

  49. [57]

    Y. Wang, W. Ni, W. Yi, X. Xu, P. Zhang, A. Nallanathan, Fed- erated contrastive learning for personalized semantic communication, IEEE Communications Letters 28 (8) (2024) 1875–1879.doi:10.1109/ LCOMM.2024.3415431

  50. [58]

    L. X. Nguyen, H. Q. Le, Y. L. Tun, P. S. Aung, Y. K. Tun, Z. Han, C. S. Hong, An efficient federated learning framework for training semantic communication systems, IEEE Transactions on Vehicular Technology (2024)

  51. [59]

    H. Sun, S. Li, F. R. Yu, Q. Qi, J. Wang, J. Liao, Toward communication-efficient federated learning in the internet of things with edge computing, IEEE Internet of Things Journal 7 (11) (2020) 11053–11067

  52. [60]

    X. Cao, T. Ba¸ sar, S. Diggavi, Y. C. Eldar, K. B. Letaief, H. V. Poor, J. Zhang, Communication-efficient distributed learning: An overview, IEEE journal on selected areas in communications 41 (4) (2023) 851– 873

  53. [61]

    C. Dong, H. Liang, X. Xu, S. Han, B. Wang, P. Zhang, Semantic communication system based on semantic slice models propagation, IEEE Journal on Selected Areas in Communications 41 (1) (2022) 202– 213

  54. [62]

    Z. Li, H. Li, L. Meng, Model compression for deep neural networks: A survey, Computers 12 (3) (2023)

  55. [63]

    P. Qi, D. Chiaro, A. Guzzo, M. Ianni, G. Fortino, F. Piccialli, Model aggregation techniques in federated learning: A comprehensive survey, Future Generation Computer Systems 150 (2024) 272–293

  56. [64]

    Wheeler, B

    D. Wheeler, B. Natarajan, Engineering semantic communication: A survey, IEEE Access 11 (2023) 13965–13995. 135

  57. [65]

    Y. Liu, X. Wang, Z. Ning, M. Zhou, L. Guo, B. Jedari, A survey on semantic communications: technologies, solutions, applications and challenges, Digital Communications and Networks (2023)

  58. [66]

    Samonas, D

    S. Samonas, D. Coss, The cia strikes back: Redefining confidentiality, integrity and availability in security., Journal of Information System Security 10 (3) (2014)

  59. [67]

    Dilmaghani, M

    S. Dilmaghani, M. R. Brust, G. Danoy, N. Cassagnes, J. Pecero, P. Bou- vry, Privacy and security of big data in ai systems: A research and standards perspective, in: 2019 IEEE International Conference on Big Data (Big Data), IEEE, 2019, pp. 5737–5743

  60. [68]

    Sweeney, Simple demographics often identify people uniquely, Health (San Francisco) 671 (2000) (2000) 1–34

    L. Sweeney, Simple demographics often identify people uniquely, Health (San Francisco) 671 (2000) (2000) 1–34

  61. [69]

    Shokri, M

    R. Shokri, M. Stronati, C. Song, V. Shmatikov, Membership inference attacks against machine learning models, in: 2017 IEEE Symposium on Security and Privacy (SP), 2017, pp. 3–18

  62. [70]

    Ganju, Q

    K. Ganju, Q. Wang, W. Yang, C. A. Gunter, N. Borisov, Property inference attacks on fully connected neural networks using permu- tation invariant representations, in: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, 2018, p. 619–633

  63. [71]

    Tram` er, F

    F. Tram` er, F. Zhang, A. Juels, M. K. Reiter, T. Ristenpart, Stealing machine learning models via prediction apis, in: Proceedings of the 25th USENIX Conference on Security Symposium, SEC’16, USENIX Association, USA, 2016, p. 601–618

  64. [72]

    S. J. Oh, M. Augustin, M. Fritz, B. Schiele, Towards reverse- engineering black-box neural networks, in: ICLR, 2018

  65. [73]

    Eykholt, I

    K. Eykholt, I. Evtimov, E. Fernandes, B. Li, A. Rahmati, C. Xiao, A. Prakash, T. Kohno, D. Song, Robust physical-world attacks on deep learning visual classification, in: Proceedings of the IEEE conference on computer vision and pattern recognition, 2018, pp. 1625–1634

  66. [74]

    Moosavi-Dezfooli, A

    S.-M. Moosavi-Dezfooli, A. Fawzi, P. Frossard, Deepfool: a simple and accurate method to fool deep neural networks, in: Proceedings of the 136 IEEE conference on computer vision and pattern recognition, 2016, pp. 2574–2582

  67. [75]

    Biggio, K

    B. Biggio, K. Rieck, D. Ariu, C. Wressnegger, I. Corona, G. Giacinto, F. Roli, Poisoning behavioral malware clustering, in: Proceedings of the 2014 workshop on artificial intelligent and security workshop, 2014, pp. 27–36

  68. [76]

    Newell, R

    A. Newell, R. Potharaju, L. Xiang, C. Nita-Rotaru, On the practical- ity of integrity attacks on document-level sentiment analysis, in: Pro- ceedings of the 2014 Workshop on Artificial Intelligent and Security Workshop, 2014, pp. 83–93

  69. [77]

    J. H. Hinnefeld, P. Cooman, N. Mammo, R. Deese, Evaluating fairness metrics in the presence of dataset bias, arXiv preprint arXiv:1809.09245 (2018)

  70. [78]

    L. Fowl, J. Geiping, W. Czaja, M. Goldblum, T. Goldstein, Robbing the fed: Directly obtaining private data in federated learning with modified models, arXiv preprint arXiv:2110.13057 (2021)

  71. [79]

    Z. Wang, J. Wang, D. Shi, X. Duan, Impact identification and as- sessment of cyber contingencies on measurement availability of power systems, IET Generation, Transmission, and Distribution (2022)

  72. [80]

    Khodak, M.-F

    M. Khodak, M.-F. F. Balcan, A. S. Talwalkar, Adaptive gradient-based meta-learning methods, Advances in Neural Information Processing Systems 32 (2019)

  73. [81]

    Y. Zhao, M. Li, L. Lai, N. Suda, D. Civin, V. Chandra, Federated learning with non-iid data, arXiv preprint arXiv:1806.00582 (2018)

  74. [82]

    Hinton, O

    G. Hinton, O. Vinyals, J. Dean, et al., Distilling the knowledge in a neural network, arXiv preprint arXiv:1503.02531 2 (7) (2015)

  75. [83]

    McMahan, E

    B. McMahan, E. Moore, D. Ramage, S. Hampson, B. A. y. Arcas, Communication-Efficient Learning of Deep Networks from Decentral- ized Data, in: A. Singh, J. Zhu (Eds.), Proceedings of the 20th Inter- national Conference on Artificial Intelligence and Statistics, Vol. 54 of Proce...

  76. [84]

    Y. Sun, J. Liu, J. Wang, Y. Cao, N. Kato, When machine learning meets privacy in 6g: A survey, IEEE Communications Surveys Tutori- als 22 (4) (2020) 2694–2724

  77. [85]

    Mothukuri, R

    V. Mothukuri, R. M. Parizi, S. Pouriyeh, Y. Huang, A. Dehghantanha, G. Srivastava, A survey on security and privacy of federated learning, Future Generation Computer Systems 115 (2021) 619–640

  78. [86]

    D. Cao, S. Chang, Z. Lin, G. Liu, D. Sun, Understanding distributed poisoning attack in federated learning, in: 2019 IEEE 25th Inter- national Conference on Parallel and Distributed Systems (ICPADS), IEEE, 2019, pp. 233–239

  79. [87]

    A. N. Bhagoji, S. Chakraborty, P. Mittal, S. Calo, Analyzing federated learning through an adversarial lens, in: International Conference on Machine Learning, PMLR, 2019, pp. 634–643

  80. [88]

    Blanchard, E

    P. Blanchard, E. M. El Mhamdi, R. Guerraoui, J. Stainer, Machine learning with adversaries: Byzantine tolerant gradient descent, Ad- vances in Neural Information Processing Systems 30 (2017)

  81. [89]

    J. Kang, Z. Xiong, C. Jiang, Y. Liu, S. Guo, Y. Zhang, D. Niyato, C. Leung, C. Miao, Scalable and communication-efficient decentralized federated edge learning with multi-blockchain framework, in: Interna- tional Conference on Blockchain and Trustworthy Systems, Springer, 2020...

  82. [90]

    J. Peng, H. Xing, L. Xu, S. Luo, P. Dai, L. Feng, J. Song, B. Zhao, Z. Xiao, Adversarial reinforcement learning based data poisoning at- tacks defense for task-oriented multi-user semantic communication, IEEE Transactions on Mobile Computing (2024)

  83. [91]

    T. Gu, K. Liu, B. Dolan-Gavitt, S. Garg, Badnets: Evaluating back- dooring attacks on deep neural networks, IEEE Access 7 (2019) 47230– 47244

  84. [92]

    Bagdasaryan, A

    E. Bagdasaryan, A. Veit, Y. Hua, D. Estrin, V. Shmatikov, How to backdoor federated learning, in: International Conference on Artificial Intelligence and Statistics, PMLR, 2020, pp. 2938–2948. 138

  85. [93]

    M. Fang, X. Cao, J. Jia, N. Gong, Local model poisoning attacks to {Byzantine-Robust} federated learning, in: 29th USENIX Security Symposium (USENIX Security 20), 2020, pp. 1605–1622

  86. [94]

    C. Xie, K. Huang, P.-Y. Chen, B. Li, Dba: Distributed backdoor at- tacks against federated learning, in: International Conference on Learn- ing Representations, 2019

  87. [95]

    L. Zhu, Z. Liu, S. Han, Deep leakage from gradients, Advances in Neural Information Processing Systems 32 (2019)

  88. [96]

    B. Zhao, K. R. Mopuri, H. Bilen, idlg: Improved deep leakage from gradients, arXiv preprint arXiv:2001.02610 (2020)

  89. [97]

    H. Yin, A. Mallya, A. Vahdat, J. M. Alvarez, J. Kautz, P. Molchanov, See through gradients: Image batch recovery via gradinversion, in: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2021, pp. 16337–16346

  90. [98]

    Z. Liu, J. Guo, W. Yang, J. Fan, K.-Y. Lam, J. Zhao, Privacy- preserving aggregation in federated learning: A survey, IEEE Transac- tions on Big Data (2022)

  91. [99]

    J. F. Shoch, Packet fragmentation in inter-network protokols, Com- puter Networks (1976) 3 (1) (1979) 3–8

  92. [100]

    Bommasani, D

    R. Bommasani, D. A. Hudson, E. Adeli, R. Altman, S. Arora, S. von Arx, M. S. Bernstein, J. Bohg, A. Bosselut, E. Brunskill, et al., On the opportunities and risks of foundation models, arXiv preprint arXiv:2108.07258 (2021)

  93. [101]

    Vaswani, N

    A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, L. Kaiser, I. Polosukhin, Attention is all you need, in: Pro- ceedings of the 31st International Conference on Neural Information Processing Systems, NIPS’17, Curran Associates Inc., Red Hook, NY, USA, 201...

  94. [102]

    Devlin, M.-W

    J. Devlin, M.-W. Chang, K. Lee, K. Toutanova, Bert: Pre-training of deep bidirectional transformers for language understanding, arXiv preprint arXiv:1810.04805 (2018). 139

  95. [103]

    Brown, B

    T. Brown, B. Mann, N. Ryder, M. Subbiah, J. D. Kaplan, P. Dhariwal, A. Neelakantan, P. Shyam, G. Sastry, A. Askell, et al., Language mod- els are few-shot learners, Advances in neural information processing systems 33 (2020) 1877–1901

  96. [104]

    W. ZENG, T. SU, H. W ANG, Y. TIAN, W. GAO, Pengcheng-pangu: Large-scale autoregressive pre-trained chinese language model with auto-parallel computation and its application, ZTE technology (2022)

  97. [105]

    Fedus, B

    W. Fedus, B. Zoph, N. Shazeer, Switch transformers: Scaling to tril- lion parameter models with simple and efficient sparsity, Journal of Machine Learning Research 23 (120) (2022) 1–39. URL http://jmlr.org/papers/v23/21-0998.html

  98. [106]

    S. Sun, W. Chen, J. Bian, X. Liu, T.-Y. Liu, Slim-dp: a multi-agent system for communication-efficient distributed deep learning, in: Pro- ceedings of the 17th International Conference on Autonomous Agents and MultiAgent Systems, 2018, pp. 721–729

  99. [107]

    H. Li, C. Hu, J. Jiang, Z. Wang, Y. Wen, W. Zhu, Jalad: Joint accuracy-and latency-aware deep structure decoupling for edge-cloud execution, in: 2018 IEEE 24th international conference on parallel and distributed systems (ICPADS), IEEE, 2018, pp. 671–678

  100. [108]

    Teerapittayanon, B

    S. Teerapittayanon, B. McDanel, H.-T. Kung, Branchynet: Fast in- ference via early exiting from deep neural networks, in: 2016 23rd International Conference on Pattern Recognition (ICPR), IEEE, 2016, pp. 2464–2469

  101. [109]

    X. Tang, X. Chen, L. Zeng, S. Yu, L. Chen, Joint multiuser dnn par- titioning and computational resource allocation for collaborative edge intelligence, IEEE Internet of Things Journal 8 (12) (2020) 9511–9522

  102. [110]

    Bellare, S

    M. Bellare, S. Tessaro, A. Vardy, Semantic security for the wiretap channel, in: Annual Cryptology Conference, Springer, 2012, pp. 294– 311

  103. [111]

    Huang, N

    S. Huang, N. Papernot, I. Goodfellow, Y. Duan, P. Abbeel, Adversarial attacks on neural network policies, arXiv preprint arXiv:1702.02284 (2017). 140

  104. [112]

    Luo, H.-H

    X. Luo, H.-H. Chen, Q. Guo, Semantic communications: Overview, open issues, and future research directions, IEEE Wireless Communi- cations 29 (1) (2022) 210–219

  105. [113]

    Y. E. Sagduyu, T. Erpek, S. Ulukus, A. Yener, Is semantic communi- cation secure? a tale of multi-domain adversarial attacks, IEEE Com- munications Magazine 61 (11) (2023) 50–55

  106. [114]

    R. Meng, H. Zhao, B. Xu, Y. Wang, X. Xu, S. Lv, X. Tao, P. Zhang, Tdgcn-based mobile multiuser physical-layer authentication for ei- enabled iiot, arXiv preprint arXiv:2411.08628 (2024)

  107. [115]

    Pirayesh, H

    H. Pirayesh, H. Zeng, Jamming attacks and anti-jamming strategies in wireless networks: A comprehensive survey, IEEE communications surveys & tutorials 24 (2) (2022) 767–809

  108. [116]

    R. Tang, D. Gao, M. Yang, T. Guo, H. Wu, G. Shi, Gan-inspired intel- ligent jamming and anti-jamming strategy for semantic communication systems, in: 2023 IEEE International Conference on Communications Workshops (ICC Workshops), IEEE, 2023, pp. 1623–1628

  109. [117]

    S. E. Whang, J.-G. Lee, Data collection and quality challenges for deep learning, Proceedings of the VLDB Endowment 13 (12) (2020) 3429– 3432

  110. [118]

    Rajan, Data cleaning for machine learning systems-a survey (2024)

    A. Rajan, Data cleaning for machine learning systems-a survey (2024)

  111. [119]

    X. Chu, I. F. Ilyas, S. Krishnan, J. Wang, Data cleaning: Overview and emerging challenges, in: Proceedings of the 2016 international confer- ence on management of data, 2016, pp. 2201–2206

  112. [120]

    G. Y. Lee, L. Alzamil, B. Doskenov, A. Termehchy, A survey on data cleaning methods for improved machine learning model performance, arXiv preprint arXiv:2109.07127 (2021)

  113. [121]

    S. Tang, S. Yuan, Y. Zhu, Data preprocessing techniques in convolu- tional neural network based on fault diagnosis towards rotating ma- chinery, IEEE Access 8 (2020) 149487–149496

  114. [122]

    K. H. Tae, Y. Roh, Y. H. Oh, H. Kim, S. E. Whang, Data cleaning for accurate, fair, and robust models: A big data-ai integration approach, 141 in: Proceedings of the 3rd international workshop on data management for end-to-end machine learning, 2019, pp. 1–4

  115. [123]

    P. Li, X. Rao, J. Blase, Y. Zhang, X. Chu, C. Zhang, Cleanml: A study for evaluating the impact of data cleaning on ml classification tasks, in: 2021 IEEE 37th International Conference on Data Engineering (ICDE), IEEE, 2021, pp. 13–24

  116. [124]

    Lotfi, M

    I. Lotfi, M. Qaraqe, A. Ghrayeb, D. Niyato, Vmguard: Reputation- based incentive mechanism for poisoning attack detection in vehicular metaverse, IEEE Transactions on Vehicular Technology (2025)

  117. [125]

    Zhang, F

    X. Zhang, F. Li, Z. Zhang, Q. Li, C. Wang, J. Wu, Enabling execution assurance of federated learning at untrusted participants, in: IEEE IN- FOCOM 2020-IEEE Conference on Computer Communications, IEEE, 2020, pp. 1877–1886

  118. [126]

    Pillutla, S

    K. Pillutla, S. M. Kakade, Z. Harchaoui, Robust aggregation for feder- ated learning, IEEE Transactions on Signal Processing 70 (2022) 1142– 1154

  119. [127]

    Ghosh, J

    A. Ghosh, J. Hong, D. Yin, K. Ramchandran, Robust federated learn- ing in a heterogeneous environment, arXiv preprint arXiv:1906.06629 (2019)

  120. [128]

    X. Fang, M. Ye, Robust federated learning with noisy and heteroge- neous clients, in: Proceedings of the IEEE/CVF Conference on Com- puter Vision and Pattern Recognition, 2022, pp. 10072–10081

  121. [129]

    L. Lyu, H. Yu, X. Ma, C. Chen, L. Sun, J. Zhao, Q. Yang, S. Y. Philip, Privacy and robustness in federated learning: Attacks and defenses, IEEE transactions on neural networks and learning systems (2022)

  122. [130]

    Sattler, S

    F. Sattler, S. Wiedemann, K.-R. M¨ uller, W. Samek, Robust and communication-efficient federated learning from non-iid data, IEEE transactions on neural networks and learning systems 31 (9) (2019) 3400–3413

  123. [131]

    F. Ang, L. Chen, N. Zhao, Y. Chen, W. Wang, F. R. Yu, Robust federated learning with noisy communication, IEEE Transactions on Communications 68 (6) (2020) 3452–3464. 142

  124. [132]

    B. Tran, J. Li, A. Madry, Spectral signatures in backdoor attacks, Advances in neural information processing systems 31 (2018)

  125. [133]

    B. Chen, W. Carvalho, N. Baracaldo, H. Ludwig, B. Edwards, T. Lee, I. Molloy, B. Srivastava, Detecting backdoor attacks on deep neural net- works by activation clustering, arXiv preprint arXiv:1811.03728 (2018)

  126. [134]

    Geiping, L

    J. Geiping, L. Fowl, G. Somepalli, M. Goldblum, M. Moeller, T. Gold- stein, What doesn’t kill you makes you robust (er): How to adver- sarially train against data poisoning, arXiv preprint arXiv:2102.13624 (2021)

  127. [135]

    Y. Gao, C. Xu, D. Wang, S. Chen, D. C. Ranasinghe, S. Nepal, Strip: A defence against trojan attacks on deep neural networks, in: Proceedings of the 35th annual computer security applications conference, 2019, pp. 113–125

  128. [136]

    Huang, W

    S. Huang, W. Peng, Z. Jia, Z. Tu, One-pixel signature: Characteriz- ing cnn models for backdoor detection, in: Computer Vision–ECCV 2020: 16th European Conference, Glasgow, UK, August 23–28, 2020, Proceedings, Part XXVII 16, Springer, 2020, pp. 326–341

  129. [137]

    K. Liu, B. Dolan-Gavitt, S. Garg, Fine-pruning: Defending against backdooring attacks on deep neural networks, in: International sym- posium on research in attacks, intrusions, and defenses, Springer, 2018, pp. 273–294

  130. [138]

    Y. Zhou, R. Q. Hu, Y. Qian, Backdoor attacks and defenses on semantic-symbol reconstruction in semantic communications, arXiv preprint arXiv:2404.13279 (2024)

  131. [139]

    Jiang, M

    Q. Jiang, M. Li, Y. Sun, Overview of deep neural network backdoor defense, Journal of Cyber Security 9 (4) (2024)

  132. [140]

    Hayase, W

    J. Hayase, W. Kong, R. Somani, S. Oh, Spectre: Defending against backdoor attacks using robust statistics, in: International Conference on Machine Learning, PMLR, 2021, pp. 4129–4139

  133. [141]

    Schulth, C

    L. Schulth, C. Berghoff, M. Neu, Detecting backdoor poisoning at- tacks on deep neural networks by heatmap clustering, arXiv preprint arXiv:2204.12848 (2022). 143

  134. [142]

    Chan, Y.-S

    A. Chan, Y.-S. Ong, Poison as a cure: Detecting & neutralizing variable-sized backdoor attacks in deep neural networks, arXiv preprint arXiv:1911.08040 (2019)

  135. [143]

    S. Hong, V. Chandrasekaran, Y. Kaya, T. Dumitra¸ s, N. Papernot, On the effectiveness of mitigating data poisoning attacks with gradient shaping, arXiv preprint arXiv:2002.11497 (2020)

  136. [144]

    Subedar, N

    M. Subedar, N. Ahuja, R. Krishnan, I. J. Ndiour, O. Tickoo, Deep probabilistic models to detect data poisoning attacks, arXiv preprint arXiv:1912.01206 (2019)

  137. [145]

    Y. Liu, Y. Xie, A. Srivastava, Neural trojans, in: 2017 IEEE Inter- national Conference on Computer Design (ICCD), IEEE, 2017, pp. 45–48

  138. [146]

    H. Qiu, Y. Zeng, S. Guo, T. Zhang, M. Qiu, B. Thuraisingham, Deep- sweep: An evaluation framework for mitigating dnn backdoor attacks using data augmentation, in: Proceedings of the 2021 ACM Asia Con- ference on Computer and Communications Security, 2021, pp. 363–377

  139. [147]

    B. Wang, Y. Yao, S. Shan, H. Li, B. Viswanath, H. Zheng, B. Y. Zhao, Neural cleanse: Identifying and mitigating backdoor attacks in neural networks, in: 2019 IEEE symposium on security and privacy (SP), IEEE, 2019, pp. 707–723

  140. [148]

    L. Zhu, R. Ning, C. Wang, C. Xin, H. Wu, Gangsweep: Sweep out neu- ral backdoors by gan, in: Proceedings of the 28th ACM International Conference on Multimedia, 2020, pp. 3173–3181

  141. [149]

    D. Wu, Y. Wang, Adversarial neuron pruning purifies backdoored deep models, Advances in Neural Information Processing Systems 34 (2021) 16913–16925

  142. [150]

    W. Zhao, S. Alwidian, Q. H. Mahmoud, Adversarial training methods for deep learning: A systematic review, Algorithms 15 (8) (2022) 283

  143. [151]

    Q. Hu, G. Zhang, Z. Qin, Y. Cai, G. Yu, G. Y. Li, Robust semantic communications against semantic noise, in: 2022 IEEE 96th Vehicular Technology Conference (VTC2022-Fall), IEEE, 2022, pp. 1–6. 144

  144. [152]

    J. Kang, J. He, H. Du, Z. Xiong, Z. Yang, X. Huang, S. Xie, Adver- sarial attacks and defenses for semantic communication in vehicular metaverses, IEEE Wireless Communications 30 (4) (2023) 48–55

  145. [153]

    G. Nan, Z. Li, J. Zhai, Q. Cui, G. Chen, X. Du, X. Zhang, X. Tao, Z. Han, T. Q. Quek, Physical-layer adversarial robustness for deep learning-based semantic communications, IEEE Journal on Selected Areas in Communications 41 (8) (2023) 2592–2608

  146. [154]

    X. Luo, Z. Chen, M. Tao, F. Yang, Encrypted semantic communication using adversarial training for privacy preserving, IEEE Communica- tions Letters 27 (6) (2023) 1486–1490

  147. [155]

    Y. Wang, D. Zou, J. Yi, J. Bailey, X. Ma, Q. Gu, Improving adversarial robustness requires revisiting misclassified examples, in: International conference on learning representations, 2019

  148. [156]

    G. W. Ding, Y. Sharma, K. Y. C. Lui, R. Huang, Mma training: Direct input space margin maximization through adversarial training, arXiv preprint arXiv:1812.02637 (2018)

  149. [157]

    Cheng, Q

    M. Cheng, Q. Lei, P.-Y. Chen, I. Dhillon, C.-J. Hsieh, Cat: Cus- tomized adversarial training for improved robustness, arXiv preprint arXiv:2002.06789 (2020)

  150. [158]

    B. He, F. Wang, T. Q. Quek, Secure semantic communication via paired adversarial residual networks, IEEE Wireless Communications Letters (2024)

  151. [159]

    I. J. Goodfellow, J. Shlens, C. Szegedy, Explaining and harnessing adversarial examples, arXiv preprint arXiv:1412.6572 (2014)

  152. [160]

    Zhang, Y

    H. Zhang, Y. Yu, J. Jiao, E. Xing, L. El Ghaoui, M. Jordan, Theoret- ically principled trade-off between robustness and accuracy, in: Inter- national conference on machine learning, PMLR, 2019, pp. 7472–7482

  153. [161]

    Dwork, Differential privacy: A survey of results, in: Interna- tional conference on theory and applications of models of computation, Springer, 2008, pp

    C. Dwork, Differential privacy: A survey of results, in: Interna- tional conference on theory and applications of models of computation, Springer, 2008, pp. 1–19. 145

  154. [162]

    P. Jain, M. Gyanchandani, N. Khare, Differential privacy: its techno- logical prescriptive using big data, Journal of Big Data 5 (1) (2018) 1–24

  155. [163]

    J. Zhao, Y. Chen, W. Zhang, Differential privacy preservation in deep learning: Challenges, opportunities and solutions, IEEE Access 7 (2019) 48901–48911

  156. [164]

    K. Wei, J. Li, M. Ding, C. Ma, H. H. Yang, F. Farokhi, S. Jin, T. Q. Quek, H. V. Poor, Federated learning with differential privacy: Algo- rithms and performance analysis, IEEE Transactions on Information Forensics and Security 15 (2020) 3454–3469

  157. [165]

    Shokri, V

    R. Shokri, V. Shmatikov, Privacy-preserving deep learning, in: Pro- ceedings of the 22nd ACM SIGSAC conference on computer and com- munications security, 2015, pp. 1310–1321

  158. [166]

    H. Liu, B. Wang, R. Meng, S. Han, X. Xu, Adaptive privacy budget- based differential privacy co-training for wireless semantic communica- tion, in: 2024 IEEE Wireless Communications and Networking Con- ference (WCNC), IEEE, 2024, pp. 1–6

  159. [167]

    Chaudhuri, C

    K. Chaudhuri, C. Monteleoni, A. D. Sarwate, Differentially private empirical risk minimization., Journal of Machine Learning Research 12 (3) (2011)

  160. [168]

    N. Phan, X. Wu, H. Hu, D. Dou, Adaptive laplace mechanism: Dif- ferential privacy preservation in deep learning, in: 2017 IEEE interna- tional conference on data mining (ICDM), IEEE, 2017, pp. 385–394

  161. [169]

    G. Acs, L. Melis, C. Castelluccia, E. De Cristofaro, Differentially pri- vate mixture of generative neural networks, IEEE Transactions on Knowledge and Data Engineering 31 (6) (2018) 1109–1121

  162. [170]

    H. Li, L. Xiong, X. Jiang, J. Liu, Differentially private histogram pub- lication for dynamic datasets: an adaptive sampling approach, in: Pro- ceedings of the 24th ACM international on conference on information and knowledge management, 2015, pp. 1001–1010. 146

  163. [171]

    S. Song, K. Chaudhuri, A. D. Sarwate, Stochastic gradient descent with differentially private updates, in: 2013 IEEE global conference on signal and information processing, IEEE, 2013, pp. 245–248

  164. [172]

    Abadi, A

    M. Abadi, A. Chu, I. Goodfellow, H. B. McMahan, I. Mironov, K. Tal- war, L. Zhang, Deep learning with differential privacy, in: Proceedings of the 2016 ACM SIGSAC conference on computer and communica- tions security, 2016, pp. 308–318

  165. [173]

    Hitaj, G

    B. Hitaj, G. Ateniese, F. Perez-Cruz, Deep models under the gan: In- formation leakage from collaborative deep learning, in: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, CCS ’17, Association for Computing Machinery, New York, NY, USA, ...

  166. [174]

    Z. Wang, M. Song, Z. Zhang, Y. Song, Q. Wang, H. Qi, Beyond in- ferring class representatives: User-level privacy leakage from federated learning, in: IEEE INFOCOM 2019 - IEEE Conference on Computer Communications, 2019, pp. 2512–2520

  167. [175]

    Winslett, J

    M. Winslett, J. Zhang, Z. Zhang, X. Xiao, Y. Yang, Functional mecha- nism: regression analysis under differential privacy, Proceedings of the VLDB Endowment (2012)

  168. [176]

    N. Phan, Y. Wang, X. Wu, D. Dou, Differential privacy preservation for deep auto-encoders: an application of human behavior prediction, in: Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 30, 2016

  169. [177]

    Zhang, S

    X. Zhang, S. Ji, T. Wang, Differentially private releasing via deep generative model (technical report), arXiv preprint arXiv:1801.01594 (2018)

  170. [178]

    W. Chen, S. Tang, Q. Yang, Enhancing image privacy in semantic communication over wiretap channels leveraging differential privacy, arXiv preprint arXiv:2405.09234 (2024)

  171. [179]

    Cormode, C

    G. Cormode, C. Procopiuc, D. Srivastava, E. Shen, T. Yu, Differen- tially private spatial decompositions, in: 2012 IEEE 28th International Conference on Data Engineering, IEEE, 2012, pp. 20–31. 147

  172. [180]

    Y. Aono, T. Hayashi, L. Wang, S. Moriai, et al., Privacy-preserving deep learning via additively homomorphic encryption, IEEE transac- tions on information forensics and security 13 (5) (2017) 1333–1345

  173. [181]

    H. Fang, Q. Qian, Privacy preserving machine learning with homomor- phic encryption and federated learning, Future Internet 13 (4) (2021) 94

  174. [182]

    J.-W. Lee, H. Kang, Y. Lee, W. Choi, J. Eom, M. Deryabin, E. Lee, J. Lee, D. Yoo, Y.-S. Kim, et al., Privacy-preserving machine learn- ing with fully homomorphic encryption for deep neural network, iEEE Access 10 (2022) 30039–30054

  175. [183]

    R. Meng, D. Fan, H. Gao, Y. Yuan, B. Wang, X. Xu, M. Sun, C. Dong, X. Tao, P. Zhang, et al., Secure semantic communication with homo- morphic encryption, arXiv preprint arXiv:2501.10182 (2025)

  176. [184]

    Goldreich, Secure multi-party computation, Manuscript

    O. Goldreich, Secure multi-party computation, Manuscript. Prelimi- nary version 78 (110) (1998) 1–108

  177. [185]

    Mugunthan, A

    V. Mugunthan, A. Polychroniadou, D. Byrd, T. H. Balch, Smpai: Se- cure multi-party computation for federated learning, in: Proceedings of the NeurIPS 2019 Workshop on Robust AI in Financial Services, Vol. 21, MIT Press Cambridge, MA, USA, 2019

  178. [186]

    Zhang, Z

    Y. Zhang, Z. Wang, J. Cao, R. Hou, D. Meng, Shufflefl: Gradient- preserving federated learning using trusted execution environment, in: Proceedings of the 18th ACM international conference on computing frontiers, 2021, pp. 161–168

  179. [187]

    Kadhe, N

    S. Kadhe, N. Rajaraman, O. O. Koyluoglu, K. Ramchandran, Fast- secagg: Scalable secure aggregation for privacy-preserving federated learning, arXiv preprint arXiv:2009.11248 (2020)

  180. [188]

    Chehimi, C

    M. Chehimi, C. Chaccour, C. K. Thomas, W. Saad, Quantum seman- tic communications for resource-efficient quantum networking, IEEE Communications Letters 28 (4) (2024) 803–807

  181. [189]

    Nunavath, N

    N. Nunavath, N. Hello, E. C. Strinati, R. Bassoli, F. H. Fitzek, Towards quantum semantic communications: A framework for integrating quan- tum and semantic technologies, Authorea Preprints (2024). 148

  182. [190]

    Khalid, M

    U. Khalid, M. S. Ulum, A. Farooq, T. Q. Duong, O. A. Dobre, H. Shin, Quantum semantic communications for metaverse: Principles and chal- lenges, IEEE Wireless Communications 30 (4) (2023) 26–36

  183. [191]

    Gentry, Fully homomorphic encryption using ideal lattices, in: Pro- ceedings of the forty-first annual ACM symposium on Theory of com- puting, 2009, pp

    C. Gentry, Fully homomorphic encryption using ideal lattices, in: Pro- ceedings of the forty-first annual ACM symposium on Theory of com- puting, 2009, pp. 169–178

  184. [192]

    Zhang, S

    C. Zhang, S. Li, J. Xia, W. Wang, F. Yan, Y. Liu, {BatchCrypt}: Effi- cient homomorphic encryption for {Cross-Silo} federated learning, in: 2020 USENIX annual technical conference (USENIX ATC 20), 2020, pp. 493–506

  185. [193]

    X. Sun, P. Zhang, J. K. Liu, J. Yu, W. Xie, Private machine learning classification based on fully homomorphic encryption, IEEE Transac- tions on Emerging Topics in Computing 8 (2) (2018) 352–364

  186. [194]

    C. Zhao, S. Zhao, M. Zhao, Z. Chen, C.-Z. Gao, H. Li, Y.-a. Tan, Secure multi-party computation: theory, practice and applications, In- formation Sciences 476 (2019) 357–372

  187. [195]

    V. Chen, V. Pastro, M. Raykova, Secure computation for machine learning with spdz, arXiv preprint arXiv:1901.00329 (2019)

  188. [196]

    Knott, S

    B. Knott, S. Venkataraman, A. Hannun, S. Sengupta, M. Ibrahim, L. van der Maaten, Crypten: Secure multi-party computation meets machine learning, Advances in Neural Information Processing Systems 34 (2021) 4961–4973

  189. [197]

    S. Wagh, D. Gupta, N. Chandran, Securenn: 3-party secure compu- tation for neural network training, Proceedings on Privacy Enhancing Technologies (2019)

  190. [198]

    S. Wagh, S. Tople, F. Benhamouda, E. Kushilevitz, P. Mittal, T. Rabin, Falcon: Honest-majority maliciously secure framework for private deep learning, arXiv preprint arXiv:2004.02229 (2020)

  191. [199]

    Damg ˚ ard, M

    I. Damg ˚ ard, M. Geisler, M. Krøigaard, J. B. Nielsen, Asynchronous multiparty computation: Theory and implementation, in: Interna- tional workshop on public key cryptography, Springer, 2009, pp. 160– 179. 149

  192. [200]

    Jauernig, A.-R

    P. Jauernig, A.-R. Sadeghi, E. Stapf, Trusted execution environments: properties, applications, and challenges, IEEE Security & Privacy 18 (2) (2020) 56–60

  193. [201]

    F. Mo, A. S. Shamsabadi, K. Katevas, S. Demetriou, I. Leontiadis, A. Cavallaro, H. Haddadi, Darknetz: towards model privacy at the edge using trusted execution environments, in: Proceedings of the 18th In- ternational Conference on Mobile Systems, Applications, and Services, 2...

  194. [202]

    F. Mo, H. Haddadi, K. Katevas, E. Marin, D. Perino, N. Kourtellis, Ppfl: Privacy-preserving federated learning with trusted execution en- vironments, in: Proceedings of the 19th annual international conference on mobile systems, applications, and services, 2021, pp. 94–108

  195. [203]

    A. P. Kalapaaking, I. Khalil, M. S. Rahman, M. Atiquzzaman, X. Yi, M. Almashor, Blockchain-based federated learning with secure aggre- gation in trusted execution environment for internet-of-things, IEEE Transactions on Industrial Informatics 19 (2) (2022) 1703–1714

  196. [204]

    Mondal, Y

    A. Mondal, Y. More, R. H. Rooparaghunath, D. Gupta, Poster: Fla- tee: Federated learning across trusted execution environments, in: 2021 IEEE European Symposium on Security and Privacy (EuroS&P), IEEE, 2021, pp. 707–709

  197. [205]

    Z. Liu, J. Guo, K.-Y. Lam, J. Zhao, Efficient dropout-resilient aggre- gation for privacy-preserving machine learning, IEEE Transactions on Information Forensics and Security 18 (2022) 1839–1854

  198. [206]

    Bonawitz, V

    K. Bonawitz, V. Ivanov, B. Kreuter, A. Marcedone, H. B. McMahan, S. Patel, D. Ramage, A. Segal, K. Seth, Practical secure aggregation for federated learning on user-held data, arXiv preprint arXiv:1611.04482 (2016)

  199. [207]

    Kairouz, Z

    P. Kairouz, Z. Liu, T. Steinke, The distributed discrete gaussian mech- anism for federated learning with secure aggregation, in: International Conference on Machine Learning, PMLR, 2021, pp. 5201–5212

  200. [208]

    L. Zhao, J. Jiang, B. Feng, Q. Wang, C. Shen, Q. Li, Sear: Secure and efficient aggregation for byzantine-robust federated learning, IEEE 150 Transactions on Dependable and Secure Computing 19 (5) (2021) 3329– 3342

  201. [209]

    D. Li, Z. Luo, B. Cao, Blockchain-based federated learning methodolo- gies in smart environments, Cluster Computing (2021) 1–15

  202. [210]

    H. Kim, J. Park, M. Bennis, S.-L. Kim, On-device federated learning via blockchain and its latency analysis, arXiv preprint arXiv:1808.03949 (2018)

  203. [211]

    Z. Peng, J. Xu, X. Chu, S. Gao, Y. Yao, R. Gu, Y. Tang, Vfchain: enabling verifiable and auditable federated learning via blockchain sys- tems, IEEE Transactions on Network Science and Engineering 9 (1) (2021) 173–186

  204. [212]

    H. B. Desai, M. S. Ozdayi, M. Kantarcioglu, Blockfla: Accountable federated learning via hybrid blockchain architecture, in: Proceedings of the eleventh ACM conference on data and application security and privacy, 2021, pp. 101–112

  205. [213]

    Y. Lu, X. Huang, K. Zhang, S. Maharjan, Y. Zhang, Blockchain em- powered asynchronous federated learning for secure data sharing in in- ternet of vehicles, IEEE Transactions on Vehicular Technology 69 (4) (2020) 4298–4311

  206. [214]

    Y. Qu, L. Gao, T. H. Luan, Y. Xiang, S. Yu, B. Li, G. Zheng, De- centralized privacy using blockchain-enabled federated learning in fog computing, IEEE Internet of Things Journal 7 (6) (2020) 5171–5183

  207. [215]

    Majeed, C

    U. Majeed, C. S. Hong, Flchain: Federated learning via mec-enabled blockchain network, in: 2019 20th Asia-Pacific Network Operations and Management Symposium (APNOMS), 2019, pp. 1–4

  208. [216]

    Q. Lu, X. Xu, Adaptable blockchain-based systems: A case study for product traceability, IEEE Software 34 (6) (2017) 21–27

  209. [217]

    A. A. Monrat, O. Schel´ en, K. Andersson, A survey of blockchain from the perspectives of applications, challenges, and opportunities, Ieee Access 7 (2019) 117134–117151. 151

  210. [218]

    Y. Lin, Z. Gao, H. Du, D. Niyato, J. Wang, Verifiable and efficient semantic blockchain, in: GLOBECOM 2023-2023 IEEE Global Com- munications Conference, IEEE, 2023, pp. 2602–2607

  211. [219]

    Y. Lin, C. Wu, M. L. Fikri, J. Wu, J. Li, L. Zhong, Y. Ji, Blockchain- based edge-assisted knowledge base management for semantic commu- nication in remote driving, in: 2023 IEEE 31st International Confer- ence on Network Protocols (ICNP), IEEE, 2023, pp. 1–6

  212. [220]

    Liang, B

    C. Liang, B. Shanmugam, S. Azam, A. Karim, A. Islam, M. Zamani, S. Kavianpour, N. B. Idris, Intrusion detection system for the internet of things based on blockchain and multi-agent systems, Electronics 9 (7) (2020) 1120

  213. [221]

    Y. Li, C. Chen, N. Liu, H. Huang, Z. Zheng, Q. Yan, A blockchain- based decentralized federated learning framework with committee con- sensus, IEEE Network 35 (1) (2020) 234–241

  214. [222]

    H. Kim, J. Park, M. Bennis, S.-L. Kim, Blockchained on-device feder- ated learning, IEEE Communications Letters 24 (6) (2019) 1279–1283

  215. [223]

    Rathore, B

    S. Rathore, B. W. Kwon, J. H. Park, Blockseciotnet: Blockchain-based decentralized security architecture for iot network, Journal of Network and Computer Applications 143 (2019) 167–177

  216. [224]

    Preuveneers, V

    D. Preuveneers, V. Rimmer, I. Tsingenopoulos, J. Spooren, W. Joosen, E. Ilie-Zudor, Chained anomaly detection models for federated learn- ing: An intrusion detection case study, Applied Sciences 8 (12) (2018) 2663

  217. [225]

    Y. Liu, J. Peng, J. Kang, A. M. Iliyasu, D. Niyato, A. A. Abd El-Latif, A secure federated learning framework for 5g networks, IEEE Wireless Communications 27 (4) (2020) 24–31

  218. [226]

    B. Li, C. Chenli, X. Xu, Y. Shi, T. Jung, Dlbc: A deep learning-based consensus in blockchains for deep learning services, arXiv preprint arXiv:1904.07349 (2019)

  219. [227]

    Y. Lu, X. Huang, K. Zhang, S. Maharjan, Y. Zhang, Blockchain em- powered asynchronous federated learning for secure data sharing in in- ternet of vehicles, IEEE Transactions on Vehicular Technology 69 (4) (2020) 4298–4311. 152

  220. [228]

    Lugan, P

    S. Lugan, P. Desbordes, E. Brion, L. X. R. Tormo, A. Legay, B. Macq, Secure architectures implementing trusted coalitions for blockchained distributed learning (tclearn), Ieee Access 7 (2019) 181789–181799

  221. [229]

    S. Awan, F. Li, B. Luo, M. Liu, Poster: A reliable and accountable privacy-preserving federated learning framework using the blockchain, in: Proceedings of the 2019 ACM SIGSAC conference on computer and communications security, 2019, pp. 2561–2563

  222. [230]

    Shayan, C

    M. Shayan, C. Fung, C. J. Yoon, I. Beschastnikh, Biscotti: A blockchain system for private and secure federated learning, IEEE Transactions on Parallel and Distributed Systems 32 (7) (2020) 1513– 1525

  223. [231]

    Jiang, S

    Y. Jiang, S. Wang, V. Valls, B. J. Ko, W.-H. Lee, K. K. Leung, L. Tas- siulas, Model pruning enables efficient federated learning on edge de- vices, IEEE Transactions on Neural Networks and Learning Systems 34 (12) (2022) 10374–10386

  224. [232]

    S. Ding, L. Zhang, M. Pan, X. Yuan, Patrol: Privacy-oriented pruning for collaborative inference against model inversion attacks, in: Proceed- ings of the IEEE/CVF Winter Conference on Applications of Computer Vision, 2024, pp. 4716–4725

  225. [233]

    H. Xie, Z. Qin, A lite distributed semantic communication system for internet of things, IEEE Journal on Selected Areas in Communications 39 (1) (2020) 142–153

  226. [234]

    Nagel, M

    M. Nagel, M. Fournarakis, R. A. Amjad, Y. Bondarenko, M. Van Baalen, T. Blankevoort, A white paper on neural network quantization, arXiv preprint arXiv:2106.08295 (2021)

  227. [235]

    J. Park, Y. Oh, Y. Kim, Y.-S. Jeon, Vision transformer-based semantic communications with importance-aware quantization, arXiv preprint arXiv:2412.06038 (2024)

  228. [236]

    Swaminathan, D

    S. Swaminathan, D. Garg, R. Kannan, F. Andres, Sparse low rank factorization for deep neural network compression, Neurocomputing 398 (2020) 185–196. 153

  229. [237]

    Idelbayev, M

    Y. Idelbayev, M. A. Carreira-Perpin´ an, Low-rank compression of neu- ral nets: Learning the rank of each layer, in: Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition, 2020, pp. 8049–8059

  230. [238]

    M. Gao, Y. Wang, L. Wan, Residual error based knowledge distillation, Neurocomputing 433 (2021) 154–161

  231. [239]

    H. Xing, H. Ma, Z. Xiao, B. Zhao, J. Peng, S. Luo, L. Feng, L. Xu, Feddistillsc: A distributed semantic communication system based on federated distillation, in: 2023 IEEE 23rd International Conference on Communication Technology (ICCT), IEEE, 2023, pp. 506–510

  232. [240]

    H. Nam, J. Park, J. Choi, M. Bennis, S.-L. Kim, Language-oriented communication with semantic coding and knowledge distillation for text-to-image generation, in: ICASSP 2024-2024 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP), IEEE, 2024, pp....

  233. [241]

    Albaseer, M

    A. Albaseer, M. Abdallah, Tailoring semantic communication at net- work edge: A novel approach using dynamic knowledge distillation, arXiv preprint arXiv:2401.10214 (2024)

  234. [242]

    Y. Wang, C. Wang, Z. Wang, S. Zhou, H. Liu, J. Bi, C. Ding, S. Ra- jasekaran, Against membership inference attack: Pruning is all you need, arXiv preprint arXiv:2008.13578 (2020)

  235. [243]

    X. Yuan, L. Zhang, Membership inference attacks and defenses in neu- ral network pruning, in: 31st USENIX Security Symposium (USENIX Security 22), 2022, pp. 4561–4578

  236. [244]

    S. Ye, K. Xu, S. Liu, H. Cheng, J.-H. Lambrechts, H. Zhang, A. Zhou, K. Ma, Y. Wang, X. Lin, Adversarial robustness vs. model compression, or both?, in: Proceedings of the IEEE/CVF International Conference on Computer Vision, 2019, pp. 111–120

  237. [245]

    S.-J. Lee, Y. H. Lee, Asymmetric weight pruning for resource-limited iot devices in semantic communications, in: 2024 15th International Conference on Information and Communication Technology Conver- gence (ICTC), IEEE, 2024, pp. 182–183. 154

  238. [246]

    Gholami, S

    A. Gholami, S. Kim, Z. Dong, Z. Yao, M. W. Mahoney, K. Keutzer, A survey of quantization methods for efficient neural network inference, in: Low-Power Computer Vision, Chapman and Hall/CRC, 2022, pp. 291–326

  239. [247]

    J. Lee, D. Kim, B. Ham, Network quantization with element-wise gradi- ent scaling, in: Proceedings of the IEEE/CVF conference on computer vision and pattern recognition, 2021, pp. 6448–6457

  240. [248]

    Bhalgat, J

    Y. Bhalgat, J. Lee, M. Nagel, T. Blankevoort, N. Kwak, Lsq+: Im- proving low-bit quantization through learnable offsets and better ini- tialization, in: Proceedings of the IEEE/CVF conference on computer vision and pattern recognition workshops, 2020, pp. 696–697

  241. [249]

    W. Shao, M. Chen, Z. Zhang, P. Xu, L. Zhao, Z. Li, K. Zhang, P. Gao, Y. Qiao, P. Luo, Omniquant: Omnidirectionally calibrated quantiza- tion for large language models, arXiv preprint arXiv:2308.13137 (2023)

  242. [250]

    Y. Xu, L. Xie, X. Gu, X. Chen, H. Chang, H. Zhang, Z. Chen, X. Zhang, Q. Tian, Qa-lora: Quantization-aware low-rank adaptation of large language models, arXiv preprint arXiv:2309.14717 (2023)

  243. [251]

    J. Xue, Y. Zhao, S. Huang, W. Liao, J. C.-W. Chan, S. G. Kong, Mul- tilayer sparsity-based tensor decomposition for low-rank tensor com- pletion, IEEE Transactions on Neural Networks and Learning Systems 33 (11) (2021) 6916–6930

  244. [252]

    A.-H. Phan, K. Sobolev, K. Sozykin, D. Ermilov, J. Gusak, P. Tichavsk` y, V. Glukhov, I. Oseledets, A. Cichocki, Stable low-rank tensor decomposition for compression of convolutional neural network, in: Computer Vision–ECCV 2020: 16th European Conference, Glas- gow, UK, August...

  245. [253]

    Piratla, P

    V. Piratla, P. Netrapalli, S. Sarawagi, Efficient domain generalization via common-specific low-rank decomposition, in: International confer- ence on machine learning, PMLR, 2020, pp. 7728–7738

  246. [254]

    S. I. Mirzadeh, M. Farajtabar, A. Li, N. Levine, A. Matsukawa, H. Ghasemzadeh, Improved knowledge distillation via teacher assis- 155 tant, in: Proceedings of the AAAI conference on artificial intelligence, Vol. 34, 2020, pp. 5191–5198

  247. [255]

    U. Asif, J. Tang, S. Harrer, Ensemble knowledge distillation for learning improved and efficient networks, in: ECAI 2020, IOS Press, 2020, pp. 953–960

  248. [256]

    G. Wu, S. Gong, Peer collaborative learning for online knowledge dis- tillation, in: Proceedings of the AAAI Conference on artificial intelli- gence, Vol. 35, 2021, pp. 10302–10310

  249. [257]

    Zhang, Z

    H. Zhang, Z. Hu, W. Qin, M. Xu, M. Wang, Adversarial co-distillation learning for image recognition, Pattern Recognition 111 (2021) 107659

  250. [258]

    Zhang, M

    Z. Zhang, M. Sabuncu, Self-distillation as instance-specific label smoothing, Advances in Neural Information Processing Systems 33 (2020) 2184–2195

  251. [259]

    Papernot, P

    N. Papernot, P. McDaniel, X. Wu, S. Jha, A. Swami, Distillation as a defense to adversarial perturbations against deep neural networks, in: 2016 IEEE symposium on security and privacy (SP), IEEE, 2016, pp. 582–597

  252. [260]

    S. Ham, J. Park, D.-J. Han, J. Moon, Neo-kd: knowledge-distillation- based adversarial training for robust multi-exit neural networks, Ad- vances in Neural Information Processing Systems 36 (2024)

  253. [261]

    L. X. Nguyen, K. Kim, Y. L. Tun, S. S. Hassan, Y. K. Tun, Z. Han, C. S. Hong, Optimizing multi-user semantic communication via transfer learning and knowledge distillation, arXiv preprint arXiv:2406.03773 (2024)

  254. [262]

    X. Lu, K. Zhu, J. Li, Y. Zhang, Efficient knowledge base synchro- nization in semantic communication network: A federated distillation approach, in: 2024 IEEE Wireless Communications and Networking Conference (WCNC), IEEE, 2024, pp. 1–6

  255. [263]

    Zhang, G

    M. Zhang, G. Zhu, R. Jin, X. Chen, Q. Shi, C. Zhong, K. Huang, Beamforming design for semantic-bit coexisting communication sys- tem, arXiv preprint arXiv:2403.11693 (2024). 156

  256. [264]

    M. Wu, Z. Gao, Z. Wang, D. Niyato, G. K. Karagiannidis, S. Chen, Deep joint semantic coding and beamforming for near-space airship- borne massive mimo network, arXiv preprint arXiv:2405.19889 (2024)

  257. [265]

    A. D. Raha, A. Adhikary, M. Gain, Y. M. Park, C. S. Hong, To- wards ultra-reliable 6g: Semantics empowered robust beamforming for millimeter-wave networks, in: NOMS 2024-2024 IEEE Network Oper- ations and Management Symposium, IEEE, 2024, pp. 1–7

  258. [266]

    Y. Yang, M. Shikh-Bahaei, Z. Yang, C. Huang, W. Xu, Z. Zhang, Se- cure design for integrated sensing and semantic communication system, in: 2024 IEEE Wireless Communications and Networking Conference (WCNC), IEEE, 2024, pp. 1–7

  259. [267]

    J. Dai, H. Fan, Z. Zhao, Y. Sun, Z. Yang, Secure resource allocation for integrated sensing and semantic communication system, in: 2024 IEEE International Conference on Communications Workshops (ICC Workshops), IEEE, 2024, pp. 1225–1230

  260. [268]

    Zhang, J

    W. Zhang, J. Chen, Y. Kuo, Y. Zhou, Artificial-noise-aided optimal beamforming in layered physical layer security, IEEE Communications Letters 23 (1) (2018) 72–75

  261. [269]

    Jiang, Y

    Y. Jiang, Y. Zou, J. Ouyang, J. Zhu, Secrecy energy efficiency opti- mization for artificial noise aided physical-layer security in ofdm-based cognitive radio networks, IEEE Transactions on Vehicular Technology 67 (12) (2018) 11858–11872

  262. [270]

    X. Luo, B. Yin, Z. Chen, B. Xia, J. Wang, Autoencoder-based semantic communication systems with relay channels, in: 2022 IEEE Interna- tional Conference on Communications Workshops (ICC Workshops), IEEE, 2022, pp. 711–716

  263. [271]

    B. Tang, L. Huang, Q. Li, A. Pandharipande, X. Ge, Cooperative semantic communication with on-demand semantic forwarding, IEEE Open Journal of the Communications Society (2023)

  264. [272]

    J. Guo, H. Chen, B. Song, Y. Chi, C. Yuen, F. R. Yu, G. Y. Li, D. Niyato, Distributed task-oriented communication networks with multimodal semantic relay and edge intelligence, IEEE Communica- tions Magazine (2024). 157

  265. [273]

    H. Du, J. Wang, D. Niyato, J. Kang, Z. Xiong, J. Zhang, X. Shen, Semantic communications for wireless sensing: Ris-aided encoding and self-supervised decoding, IEEE Journal on Selected Areas in Commu- nications 41 (8) (2023) 2547–2562

  266. [274]

    Huang, C

    Y. Huang, C. Cai, X. Yuan, Y.-J. A. Zhang, Joint active and pas- sive beamforming for ris-aided semantic communication, IEEE Trans- actions on Vehicular Technology (2024)

  267. [275]

    S. Chen, Y. Hui, Y. Qin, Y. Yuan, W. Meng, X. Luo, H.-H. Chen, Ris- based on-the-air semantic communications–a diffractional deep neural network approach, IEEE Wireless Communications (2024)

  268. [276]

    Y. Sun, Z. Lin, K. An, D. Li, C. Li, Y. Zhu, D. W. K. Ng, N. Al- Dhahir, J. Wang, Multi-functional ris-assisted semantic anti-jamming communication and computing in integrated aerial-ground networks, IEEE Journal on Selected Areas in Communications (2024)

  269. [277]

    Zhang, G

    X. Zhang, G. Li, J. Zhang, A. Hu, Z. Hou, B. Xiao, Deep-learning-based physical-layer secret key generation for fdd systems, IEEE Internet of Things Journal 9 (8) (2021) 6081–6094

  270. [278]

    R. Zhao, Q. Qin, N. Xu, G. Nan, Q. Cui, X. Tao, Semkey: Boosting secret key generation for ris-assisted semantic communication systems, in: 2022 IEEE 96th Vehicular Technology Conference (VTC2022-Fall), IEEE, 2022, pp. 1–5

  271. [279]

    N. Gao, Q. Huang, C. Li, S. Jin, M. Matthaiou, Esanet: Environ- ment semantics enabled physical layer authentication, IEEE Wireless Communications Letters (2023)

  272. [280]

    Y. Ma, H. Fang, L. Liang, X. Wang, Physical layer authentication enhancement via random watermark hopping, IEEE Internet of Things Journal (2024)

  273. [281]

    A. D. Raha, K. Kim, A. Adhikary, M. Gain, Z. Han, C. S. Hong, Advancing ultra-reliable 6g: Transformer and semantic localization empowered robust beamforming in millimeter-wave communications, arXiv preprint arXiv:2406.02000 (2024). 158

  274. [282]

    J. Dai, H. Fan, Z. Zhao, Y. Xu, Z. Yang, X. Gan, Z. Zhang, Joint com- munication and computation design for secure integrated sensing and semantic communication system, Science China Information Sciences 68 (3) (2025) 132301

  275. [283]

    C. Wang, Z. Li, X.-G. Xia, J. Shi, J. Si, Y. Zou, Physical layer security enhancement using artificial noise in cellular vehicle-to-everything (c- v2x) networks, IEEE Transactions on Vehicular Technology 69 (12) (2020) 15253–15268

  276. [284]

    T. V. Pham, A. T. Pham, S. Ishihara, Design of energy-efficient arti- ficial noise for physical layer security in visible light communications, IEEE Transactions on Green Communications and Networking (2024)

  277. [285]

    Z. Hu, C. You, T. Liu, D. Wen, Y. Hu, Y. Cui, Y. Gong, K. Huang, Semantic communication meets edge intelligence: Semantic-relay-aided text transmissions, IEEE Internet of Things Journal (2024)

  278. [286]

    W. Lin, Y. Yan, L. Li, Z. Han, T. Matsumoto, Semantic-forward relay- ing: A novel framework towards 6g cooperative communications, IEEE Communications Letters (2024)

  279. [287]

    L. Wang, W. Wu, F. Zhou, Z. Qin, Q. Wu, Irs-enhanced secure seman- tic communication networks: Cross-layer and context-awared resource allocation, arXiv preprint arXiv:2411.01821 (2024)

  280. [288]

    Y. Wang, W. Yang, P. Guan, Y. Zhao, Z. Xiong, Star-ris-assisted pri- vacy protection in semantic communication system, IEEE Transactions on Vehicular Technology (2024)

  281. [289]

    Aldaghri, H

    N. Aldaghri, H. Mahdavifar, Physical layer secret key generation in static environments, IEEE Transactions on Information Forensics and Security 15 (2020) 2692–2705

  282. [290]

    L. Jin, X. Xu, S. Han, J. Liu, R. Meng, H. Chen, Ris-assisted phys- ical layer key generation and transmit power minimization, in: 2022 IEEE Wireless Communications and Networking Conference (WCNC), IEEE, 2022, pp. 2065–2070. 159

  283. [291]

    N. Gao, Y. Han, N. Li, S. Jin, M. Matthaiou, When physical layer key generation meets ris: Opportunities, challenges, and road ahead, IEEE Wireless Communications (2024)

  284. [292]

    R. Meng, B. Xu, X. Xu, M. Sun, B. Wang, S. Han, S. Lv, P. Zhang, A survey of machine learning-based physical-layer authentication in wire- less communications, Journal of Network and Computer Applications (2024) 104085

  285. [293]

    R. Meng, X. Xu, B. Wang, H. Sun, S. Xia, S. Han, P. Zhang, Physical- layer authentication based on hierarchical variational autoencoder for industrial internet of things, IEEE Internet of Things Journal 10 (3) (2022) 2528–2544

  286. [294]

    R. Meng, X. Xu, H. Zhao, B. Wang, G. Li, B. Xu, P. Zhang, Multiobservation-multichannel-attribute-based multiuser authentica- tion for industrial wireless edge networks, IEEE Transactions on In- dustrial Informatics 20 (2) (2023) 2097–2108

  287. [295]

    R. Meng, X. Xu, G. Li, B. Xu, F. Zhu, B. Wang, P. Zhang, Multi- dimensional fingerprints-based multi-attacker detection for 6g systems, IEEE Internet of Things Journal (2023)

  288. [296]

    Arzykulov, A

    S. Arzykulov, A. Celik, G. Nauryzbayev, A. M. Eltawil, Artificial noise and ris-aided physical layer security: Optimal ris partitioning and power control, IEEE Wireless Communications Letters 12 (6) (2023) 992–996

  289. [297]

    R. Meng, F. Zhu, X. Xu, L. Jin, B. Wang, B. Xu, H. Meng, P. Zhang, Efficient gaussian process classification-based physical-layer authenti- cation with configurable fingerprints for 6g-enabled iot, arXiv preprint arXiv:2307.12263 (2023). 160

Pith tools

Reviewed August 10, 2026 · model on record in the stance chip above.