Qizhi Zhang 0007

dblp:04/6390-7 · DBLP profile ↗
← Back
4ranked-venue papers
0as first author
4since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2025 ObfusLM: Privacy-preserving Language Model Service against Embedding Inversion Attacks
abstract
Yu Lin, Ruining Yang, Yunlong Mao, Qizhi Zhang, Jue Hong, Quanwei Cai, Ye Wu, Huiqi Liu, Zhiyu Chen, Bing Duan, Sheng Zhong. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025.
Ruining Yang, Yunlong Mao, Qizhi Zhang 0007, Jue Hong, Quanwei Cai 0003, Huiqi Liu, Bing Duan, Sheng Zhong 0002
ACL (1)4
2025 Suda: An Efficient and Secure Unbalanced Data Alignment Framework for Vertical Privacy-Preserving Machine Learning
Lushan Song, Qizhi Zhang 0007, Daode Zhang, Weili Han, Jue Hong, Quanwei Cai 0003
USENIX Security Symposium2
2025 Toward Efficient and Secure Collaborative SQL Analyses of Billion-Scale Datasets
abstract
Designing an efficient and secure collaborative SQL analysis system that supports large-scale dataset inputs is a very challenging task. In this paper, we present FedQuery, an MPC-based solution for efficient and secure collaborative analysis that is able to handle billion-scale dataset inputs. FedQuery introduces novel designs in its system architecture, the underlying MPC primitives, and oblivious SQL operators as well as their combinations, significantly reducing communication and computation overhead. Comprehensive experiments on real-world datasets show that FedQuery achieves large performance improvements over state-of-the-art baselines at both the operator and query levels. Additionally, it can handle complex SQL queries on datasets up to ten billion entries in less than 14 hours.
Qizhi Zhang 0007, Yuan Zhang 0004, Quanwei Cai 0003, Jue Hong, Sheng Zhong 0002
IEEE Trans. Inf. Forensics Secur.2
2024 An Inversion Attack Against Obfuscated Embedding Matrix in Language Model Inference
abstract
With the rapidly-growing deployment of large language model (LLM) inference services, privacy concerns have arisen regarding to the user input data.Recent studies are exploring transforming user inputs to obfuscated embedded vectors, so that the data will not be eavesdropped by service provides.However, in this paper we show that again, without a solid and deliberate security design and analysis, such embedded vector obfuscation failed to protect users' privacy.We demonstrate the conclusion via conducting a novel inversion attack called Element-wise Differential Nearest Neighbor (EDNN) on the glide-reflection proposed in (Mishra et al., 2024), and the result showed that the original user input text can be 100% recovered from the obfuscated embedded vectors.We further analyze security requirements on embedding obfuscation and present several remedies to our proposed attack.
Qizhi Zhang 0007, Quanwei Cai 0003, Jue Hong, Wu Ye, Huiqi Liu, Bing Duan
EMNLP2