Rui Wang 0070

dblp:06/2293-70 · DBLP profile ↗
← Back
11ranked-venue papers
1as first author
11since 2021 · last 2026
0000-0001-8495-3631ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 4 · 4 since 2021Security and privacy · 3 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Privacy-Preserving Chunk Scheduling in a BitTorrent Implementation of Federated Learning
Naicheng Li, Javad Dogani, Rui Wang 0070, Kaitai Liang, Nikolaos Laoutaris
ICDCS3
2026 FLAB: Exploring anomaly bias in backdoor attacks
Shaoxiong Wang, Lianhua Wang, Rui Wang 0070
Expert Syst. Appl.4
2025 LADDER: Multi-Objective Backdoor Attack via Evolutionary Algorithm
Dazhuang Liu, Yanqi Qiao, Rui Wang 0070, Kaitai Liang, Georgios Smaragdakis
NDSS3
2025 Low-Frequency Black-Box Backdoor Attack via Evolutionary Algorithm
abstract
Convolutional Neural Networks (CNNs) that have excelled in diverse computer vision tasks are vulnerable to backdoor attacks, enabling attacker-controlled predictions via specific triggers. Restricted to spatial domains, recent research exploits perceptual traits by embedding triggers in the frequency domain, yielding pixel-level indistinguishable perturbations. In black-box settings, restricted access to model and training process necessitates advanced trigger designs. Current frequency-based attacks manipulate magnitude spectra, introducing discrepancies between clean and poisoned data, though vulnerable to common image processing operations like compression and filtering. In this paper, we propose a robust low-frequency backdoor attack (LFBA) in black-box setup that minimally perturbs spectrum components and maintains the perceptual similarity in spatial space simultaneously. Our methodology capitalizes on the insight that optimal triggers can be located in low-frequency regions to maximize attack effectiveness, robustness against image transformation operations, and stealthiness in dual space. To effectively explore the discrete frequency space, we utilize simulated annealing (SA), a form of evolutionary algorithm, to optimize the properties of trigger including the frequency bands to be manipulated and the perturbation of each band under restricted attack scenario. Extensive experiments on both CNNs and Vision Transformers (ViT) confirm the effectiveness and robustness of LFBA against image processing operations and state-of-the-art backdoor defenses. Furthermore, LFBA exhibits inherent stealthiness in both spatial and frequency spaces, making it resistant to human and frequency inspection.
Yanqi Qiao, Dazhuang Liu, Rui Wang 0070, Kaitai Liang
WACV3
2025 FedCmp: Byzantine-robust federated learning through clustering model update parameters
Shaoxiong Wang, Rui Wang 0070
Inf. Sci.3
2024 FEVERLESS: Fast and Secure Vertical Federated Learning Based on XGBoost for Decentralized Labels
abstract
Vertical Federated Learning (VFL) enables multiple clients to collaboratively train a global model over vertically partitioned data without leaking private local information. Tree-based models, like XGBoost and LightGBM, have been widely used in VFL to enhance the interpretation and efficiency of training. However, there is a fundamental lack of research on how to conduct VFL securely over distributed labels. This work is the first to fill this gap by designing a novel protocol, called FEVERLESS, based on XGBoost. FEVERLESS leverages secure aggregation via information masking technique and global differential privacy provided by a fairly and randomly selected noise leader to prevent private information from being leaked in the training process. Furthermore, it provides label and data privacy against honest-but-curious adversaries even in the case of collusion of$n - 2$out of n clients. We present a comprehensive security and efficiency analysis for our design, and the empirical results from our experiments demonstrate that FEVERLESS is fast and secure. In particular, it outperforms the solution based on additive homomorphic encryption in runtime cost and provides better accuracy than the local differential privacy approach.
Rui Wang 0070, Oguzhan Ersoy, Hangyu Zhu, Yaochu Jin, Kaitai Liang
IEEE Trans. Big Data1
2024 AN-GCN: An Anonymous Graph Convolutional Network Against Edge-Perturbing Attacks
abstract
Recent studies have revealed the vulnerability of graph convolutional networks (GCNs) to edge-perturbing attacks, such as maliciously inserting or deleting graph edges. However, theoretical proof of such vulnerability remains a big challenge, and effective defense schemes are still open issues. In this article, we first generalize the formulation of edge-perturbing attacks and strictly prove the vulnerability of GCNs to such attacks in node classification tasks. Following this, an anonymous GCN, named AN-GCN, is proposed to defend against edge-perturbing attacks. In particular, we present a node localization theorem to demonstrate how GCNs locate nodes during their training phase. In addition, we design a staggered Gaussian noise-based node position generator and a spectral graph convolution-based discriminator (in detecting the generated node positions). Furthermore, we provide an optimization method for the designed generator and discriminator. It is demonstrated that the AN-GCN is secure against edge-perturbing attacks in node classification tasks, as AN-GCN is developed to classify nodes without the edge information (making it impossible for attackers to perturb edges anymore). Extensive evaluations verify the effectiveness of the general edge-perturbing attack (G-EPA) model in manipulating the classification results of the target nodes. More importantly, the proposed AN-GCN can achieve 82.7% in node classification accuracy without the edge-reading permission, which outperforms the state-of-the-art GCN.
Ao Liu 0005, Beibei Li 0002, Tao Li 0016, Pan Zhou 0001, Rui Wang 0070
IEEE Trans. Neural Networks Learn. Syst.5
2023 Federated Synthetic Data Generation with Stronger Security Guarantees
abstract
Synthetic data generation plays a crucial role in many areas where data is scarce and privacy/confidentiality is a significant concern. Generative Adversarial Networks (GANs), arguably one of the most widely used data synthesis techniques, allow for the training of a model (i.e., generator) that can generate real-looking data by playing a min-max game with a discriminator model. When multiple organizations are reluctant to share their sensitive data, GANs models can be trained in a federated manner, commonly with the use of differential privacy (DP). In order to achieve a reasonable level of model utility, DP trades privacy exhibiting vulnerability to various attacks (e.g., membership inference attack). In this paper, we propose a hybrid solution, PP-FedGAN, to the asynchronous federated, privacy-preserving training of GANs models by combining the CKKS homomorphic encryption (HE) scheme with differential privacy. The addition of HE results in around 10 seconds of overhead on the client side per round and 115 seconds on the entire training procedure. We also analyze the security of PP-FedGAN under the honest-but-curious security model. Where stronger security guarantees are required, our proposal presents a better alternative to solutions that only employ DP.
Ali Reza Ghavamipour, Fatih Turkmen, Rui Wang 0070, Kaitai Liang
SACMAT3
2022 FLVoogd: Robust And Privacy Preserving Federated Learning
Rui Wang 0070, Yanqi Qiao, Emmanouil A. Panaousis, Kaitai Liang
ACML2
2022 More is Better (Mostly): On the Backdoor Attacks in Federated Graph Neural Networks
abstract
Graph Neural Networks (GNNs) are a class of deep learning-based methods for processing graph domain information. GNNs have recently become a widely used graph analysis method due to their superior ability to learn representations for complex graph data. Due to privacy concerns and regulation restrictions, centralized GNNs can be difficult to apply to data-sensitive scenarios. Federated learning (FL) is an emerging technology developed for privacy-preserving settings when several parties need to train a shared global model collaboratively. Although several research works have applied FL to train GNNs (Federated GNNs), there is no research on their robustness to backdoor attacks.
Jing Xu 0028, Rui Wang 0070, Stefanos Koffas, Kaitai Liang, Stjepan Picek
ACSAC2
2021 Distributed additive encryption and quantization for privacy preserving federated deep learning
Hangyu Zhu, Rui Wang 0070, Yaochu Jin, Kaitai Liang, Jianting Ning
Neurocomputing2