VLDB 2026 Research / reviewers in the wild / expert
Qian Chen 0032
dblp:11/1394-32
· DBLP profile ↗
19ranked-venue papers
9as first author
19since 2021 · last 2026
0000-0002-6956-8185ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 4 first-author · 8 since 2021Computer networks · 5 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AGAM: A randomly initialized policy network for action mask fusion in reinforcement learning
Buqing Xue, Qian Chen 0032, Zilong Wang 0001, Linkang Du, Tao Hu 0002 |
Knowl. Based Syst. | 2 |
| 2026 | EvaFL: An Efficient Verifiable Privacy-Preserving Federated Learning Against Malicious ServersabstractFederated Learning (FL) preserves client data privacy by distributing model training but remains vulnerable to inference attacks (e.g., gradient inversion). Existing secure aggregation schemes mitigate basic privacy threats, but most of them are under the semi-honest server assumption. Malicious servers can corrupt the global model through forging aggregation results. Moreover, the high interaction rounds and communication complexity of the existing schemes still constrain their feasibility in large-scale distributed deployment scenarios. To tackle these challenges, we propose EvaFL, an efficient verifiable privacy-preserving federated learning against malicious servers, which reduces the communication overhead and privacy threats from malicious severs. We propose the system model of EvaFL and give the concrete protocol. We leverage the linear homomorphism property of Shamir secret sharing under discrete logarithm assumption to reuse the mask seed shares, which avoids the communication overhead caused by share distribution in multiple rounds of iterations. In addition, by integrating consistency checking into the unmasking step, we further reduce one round interaction. To resist malicious servers, we adopt linear homomorphic hash to realize the correctness verification of the aggregation results. Finally, we implement and evaluate our EvaFL based on MNIST and CIFAR10 datasets to show its feasibility for privacy training. The single round aggregation completion time of EvaFL is reduced by 69% compared to BBGLR (CCS 2020) and by 11% compared to Flamingo (S&P 2023). Xiaoyi Yang 0001, Xing Zou, Qian Chen 0032, Baodong Qin, Yanqi Zhao, Yong Yu 0002 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | RankFL: Robustness and Privacy-Preserving Federated Learning Scheme Against Poisoning AttacksabstractDistinguishing between benign and poisoned gradients hidden behind cryptographic masks is a critical challenge in privacy-preserving federated learning (FL). Existing robust aggregation defenses suffer from two primary limitations: (1) susceptibility to manipulation, where adversaries induce deviations from standard protocols to bypass statistics-based defenses (e.g., mean or median), and (2) limited detection granularity, where the reliance on coarse statistics under encryption fails to identify subtle or coordinated poisoning behaviors. To address these issues, we propose RankFL, a poison-robust and privacy-preserving FL scheme that leverages order sorting over ciphertext gradients. RankFL utilizes an efficient Paillier-based two-party comparison protocol to construct a joint order tree, facilitating quartile-driven filtering of malicious updates without compromising individual gradient privacy. Furthermore, we introduce RankFL-Extend, which incorporates zero-knowledge proof-of-knowledge and bidirectional verification to secure the ranking process against active adversaries. We provide a rigorous theoretical analysis to establish the scheme's privacy, indistinguishability, and convergence guarantees. Extensive experiments across diverse datasets and attack scenarios demonstrate that the proposed scheme achieves a$3\%$accuracy improvement over state-of-the-art defenses under poisoning attacks. Qian Chen 0032, Tom H. Luan, Zhou Su 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | Medishuffle: Auditable Coin Mixing Scheme for Internet of Medical ThingsabstractThe widespread adoption of the Internet of Medical Things (IoMT) has spurred the development of blockchain-based models for medical data sharing, designed to ensure both data trustworthiness and privacy protection. In these models, data owners upload medical data to the blockchain via anonymized transactions, enabling researchers to access and analyze the on-chain data. Existing approaches often utilize coin-mixing techniques to obscure the relationships between transacting parties on the blockchain, thereby enhancing privacy. However, such solutions face challenges related to inefficiency and limited data usability, making them unsuitable for deployment in blockchain-based medical scenarios. To address the issue, we propose Medishuffle, an auditable coin-mixing protocol tailored for IoMT applications. Medishuffle introduces a polynomial-based group signature algorithm to facilitate the shuffling process, leveraging identity anonymity instead of traditional data encryption to reduce computational overhead. Additionally, the traceability feature of group signatures enables auditors to reconstruct the sequence of obfuscated transactions when necessary. Through theoretical analysis, we demonstrate that Medishuffle ensures both the unforgeability and traceability of signatures under the random oracle model in the query process. Using experiments, we show that Medishuffle outperforms existing solutions by offering enhanced functionality without a significant increase in computational overhead, making it a practical and efficient solution for IoMT-based medical data sharing. Tom H. Luan, Yinbin Miao, Qian Chen 0032 |
IEEE Internet Things J. | 4 |
| 2025 | Efficient and Privacy-Preserving Network Intrusion Detection Based on Federated Learning in SDN-Enabled IIoT NetworkabstractModern decentralized deep learning methods for network intrusion detection in Software-Defined Networking (SDN)-enabled Industrial Internet of Things (IIoT) environments encounter significant challenges, particularly for IIoT data heterogeneity and privacy leakage. To this end, we propose a novel framework for network intrusion detection, dubbed SFLNID, that improves Federated Learning (FL) to ensure both efficient training and privacy preservation in SDN-enabled IIoT. Specifically, we firstly design joint optimization mechanism for unbalanced and non-IID data, which introduces a Focal loss as the loss function, and leverages the Wasserstein distance between global and local models as the regularization term. In addition, we improve adaptive differential privacy with dynamic gradient clipping techniques, adjusting the clip-threshold based on Holt exponential smoothing to achieve privacy protection during the local model training. Moreover, we develop a customized CNN-GRU model tailored for FL-based network intrusion detection to make a tradeoff between model accuracy and overheads. Theoretical analysis confirms the convergence and privacy guarantees of SFLNID. Extensive experiments, conducted on well-known IIoT datasets including ToN-IoT, RT-IoT and Edge-IIoT, demonstrate that SFLNID outperforms the state-of-the-art methods in terms of detection accuracy, communication overhead, and cooperative privacy preservation. Tao Hu 0002, Qian Chen 0032, Yuxiang Hu 0004, Saifeng Hou, Haonan Yan, Peng Yi 0003, Zixi Cui |
IEEE Internet Things J. | 2 |
| 2025 | A Proactive Defense Against Model Poisoning Attacks in Federated LearningabstractModel poisoning attacks greatly jeopardize the application of federated learning (FL). The effectiveness of existing defenses is susceptible to the latest model poisoning attacks, leading to a decrease in prediction accuracy. Besides, these defenses are intractable to distinguish benign outliers from malicious gradients, which further compromises the model generalization. In this work, we propose a novel proactive defense named${\sf RECESS}$against model poisoning attacks. Different from the passive analysis in previous defenses,${\sf RECESS}$proactively queries each participating client with a delicately constructed aggregation gradient, accompanied by the detection of malicious clients according to their responses with higher accuracy. Furthermore, RECESS uses a new trust scoring mechanism to robustly aggregate gradients. Unlike previous methods that score each iteration, RECESS considers clients’ performance correlation across multiple iterations to estimate the trust score, substantially increasing fault tolerance. Finally, we extensively evaluate${\sf RECESS}$on typical model architectures and four datasets under various settings. We also evaluated the defensive effectiveness against other types of poisoning attacks, the sensitivity of hyperparameters, and adaptive adversarial attacks. Experimental results show the superiority of${\sf RECESS}$in terms of reducing accuracy loss caused by the latest model poisoning attacks over five classic and two state-of-the-art defenses. Haonan Yan, Chengbo Zheng, Qian Chen 0032, Bin Wang 0062, Hui Li 0006, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | DP-DID: A Dynamic and Proactive Decentralized Identity SystemabstractDecentralized identity (DID) is a transformative paradigm that leverages blockchain, decentralized identifiers and verifiable credentials (VCs) to enable self-sovereign and decentralized identity management with myriad application areas. However, existing DID implementations are confronted with two key challenges: insufficient decentralization and vulnerability to mobile adversary attacks. First, they paradoxically introduce central identity resolvers, intermediaries or static committees to manage critical identity services, key management or credential issuance, which violates the decentralized controlling aim against a single point of failure. Second, these systems are vulnerable to mobile adversaries who can gradually compromise multiple nodes or committee members over a long period, eventually seizing control of the system. In this paper, we propose DP-DID, the first dynamic and proactive decentralized identity system specifically designed to resist mobile adversary attacks in dynamic committee settings. To eliminate centralized authorities, DP-DID leverages blockchain, dynamic committees and BLS1signatures, which achieves decentralization. In addition, we design a dynamic and batch proactive secret sharing (DBPSS) scheme for DP-DID to ensure proactive security against mobile adversary attacks. This is achieved by allowing at mostt(threshold) committees to be corrupted per period, with the set of corrupted committees changing dynamically even if all players are eventually compromised. By incorporating DBPSS, DP-DID achieves efficient key management for multiple users in dynamic settings, enhancing overall system scalability. Through rigorous analysis, DP-DID is proven to be forward secure and secure against mobile adversary attacks under a widely adopted malicious model. Extensive experiments show that DP-DID has efficient performance, and our DBPSS scheme outperforms FaB-DPSS by over 11.67× in key handover efficiency. Yang Xiao 0014, Qian Chen 0032, Yong Zhi Lim, Xuefeng Liu 0002, Qingqi Pei, Jianying Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | DeFedGCN: Privacy-Preserving Decentralized Federated GCN for Recommender SystemabstractFederated recommender system (RS), a prevailing distributed paradigm, has been spawning significant interest in exploiting locally stored but tremendous data to predict items best aligned with clients. However, federated RS suffers severely from a single point of failure due to the dependency on the central server, leading to potential denial of service (DoS) attacks. To address this security weakness, in this paper, we propose a decentralized privacy-preserving federated graph convolutional network for RS, dubbed DeFedGCN. Specifically, DeFedGCN aggregates local updates by a decentralized consensus-reaching process and customizes local models for personalized recommendation, where the aggregation is enhanced by local differential privacy to resist model inversion attacks. More importantly, to promote the recommendation performance, DeFedGCN conducts asub-graph expansionbased on the private set interaction to explore high-order interactions among clients and items. Theoretical analysis confirms the effectiveness and privacy guarantee of DeFedGCN. Additionally, we conduct extensive experiments on four widespread real-world databases. The recommendation performance of DeFedGCN outperforms the state-of-the-art federated RS algorithms without security protection against DoS attacks by up to 7.4%. Qian Chen 0032, Zilong Wang 0001, Mengqing Yan, Haonan Yan, Xiaodong Lin 0001, Jianying Zhou 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2024 | PAGE: Equilibrate Personalization and Generalization in Federated LearningabstractFederated learning (FL) is becoming a major driving force behind machine learning as a service, where customers (clients) collaboratively benefit from shared local updates under the orchestration of the service provider (server). Representing clients' current demands and the server's future demand, local model personalization and global model generalization are separately investigated, as the ill-effects of data heterogeneity enforce the community to focus on one over the other. However, these two seemingly competing goals are of equal importance rather than black and white issues, and should be achieved simultaneously. In this paper, we propose the first algorithm to balance personalization and generalization on top of game theory, dubbed PAGE, which reshapes FL as a co-opetition game between clients and the server. To explore the equilibrium, PAGE further formulates the game as Markov decision processes, and leverages the reinforcement learning algorithm, which simplifies the solving complexity. Extensive experiments on four widespread datasets show that PAGE outperforms state-of-the-art FL baselines in terms of global and local prediction accuracy simultaneously, and the accuracy can be improved by up to 35.20% and 39.91%, respectively. In addition, biased variants of PAGE imply promising adaptiveness to demand shifts in practice. Qian Chen 0032, Zilong Wang 0001, Jiaqi Hu 0003, Haonan Yan, Jianying Zhou 0001, Xiaodong Lin 0001 |
WWW | 1 |
| 2024 | QP-LDP for Better Global Model Performance in Federated LearningabstractFederated learning (FL) enhanced by local differential privacy (LDP) has gained promising privacy-preserving capabilities against privacy attacks on local contributions. In this context, noise-discounting LDP methods have been widely investigated to provide better model performance and stronger privacy guarantees. However, prior art calibrate privacy guarantees by distinct LDP definitions, resulting in nonuniform privacy-preserving capabilities. In this article, aligned with the standard LDP definition, we proposed QP-LDP, a noise-discounting algorithm for FL, which can yield better model performance without any privacy loss. Specifically, QP-LDP precisely disturbs noncommon components of quantized local contributions, which are selected by an extended multiparty private set intersection process. In particular, QP-LDP can comprehensively protect two types of local contributions, i.e., local models and gradients for prevailing FedAvg and FedSGD, respectively. Through theoretical analysis, QP-LDP provides component-level indistinguishability for clients’ private local contributions and rigorous convergence guarantees for the global model. Extensive experiments on four widespread databases show that, compared to the standard LDP method, the global model prediction accuracy and convergence rate achieved by QP-LDP can be improved by up to 14.99% and 23.08%, respectively. More importantly, QP-LDP achieves the same level of privacy-preserving capabilities against privacy attacks as the standard LDP method. Qian Chen 0032, Zilong Wang 0001, Haonan Yan, Xiaodong Lin 0001, Jianying Zhou 0001 |
IEEE Internet Things J. | 1 |
| 2024 | CODER: Protecting Privacy in Image Retrieval With Differential PrivacyabstractImage retrieval techniques can be easily abused to violate personal privacy with images containing individuals' sensitive information. For example, people's identity information can be inferred from their face photos. Therefore, images should be sanitized before being shared or transmitted. However, previous works on image privacy protection suffer from either no provable privacy protection or poor utility with privacy guarantee. In this work, we proposeCODER, a privacy protection mechanism in image retrieval, with provable privacy guarantee as well as improved utility. In particular,CODERachieves metric differential privacy and adopts a newly proposed distortion metric definition which measures the distance more precisely to improve utility. The novel distortion metric can be applied to an arbitrary k-dimensional metric space with stronger image privacy protection. We theoretically analyze the privacy guarantee and rigorous utility bound ofCODER. We also experimentally compare its performance with two state-of-the-art works on two widely used face datasets. The results show thatCODERsignificantly improves the utility of the protected images and demonstrates its superiority in terms of the privacy-utility trade-off over the compared works. Finally, we perform reliability verification on both discriminative and generative models to demonstrate the practicality ofCODER Haonan Yan, Wenjing Zhang 0002, Qian Chen 0032, Bin Wang 0062, Hui Li 0006, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | RECESS Vaccine for Federated Learning: Proactive Defense Against Model Poisoning AttacksabstractModel poisoning attacks greatly jeopardize the application of federated learning (FL). The effectiveness of existing defenses is susceptible to the latest model poisoning attacks, leading to a decrease in prediction accuracy. Besides, these defenses are intractable to distinguish benign outliers from malicious gradients, which further compromises the model generalization. In this work, we propose a novel defense including detection and aggregation, named RECESS, to serve as a “vaccine” for FL against model poisoning attacks. Different from the passive analysis in previous defenses, RECESS proactively queries each participating client with a delicately constructed aggregation gradient, accompanied by the detection of malicious clients according to their responses with higher accuracy. Further, RECESS adopts a newly proposed trust scoring based mechanism to robustly aggregate gradients. Rather than previous methods of scoring in each iteration, RECESS takes into account the correlation of clients’ performance over multiple iterations to estimate the trust score, bringing in a significant increase in detection fault tolerance. Finally, we extensively evaluate RECESS on typical model architectures and four datasets under various settings including white/black-box, cross-silo/device FL, etc. Experimental results show the superiority of RECESS in terms of reducing accuracy loss caused by the latest model poisoning attacks over five classic and two state-of-the-art defenses. Haonan Yan, Wenjing Zhang 0002, Qian Chen 0032, Wenhai Sun, Hui Li 0006, Xiaodong Lin 0001 |
NeurIPS | 3 |
| 2023 | PPT: A privacy-preserving global model training protocol for federated learning in P2P networks
Qian Chen 0032, Zilong Wang 0001, Wenjing Zhang 0002, Xiaodong Lin 0001 |
Comput. Secur. | 1 |
| 2023 | FedDual: Pair-Wise Gossip Helps Federated Learning in Large Decentralized NetworksabstractThere is a significant recent interest in collaboratively training a machine learning (ML) model without collecting data to a central server. Federated learning (FL) emerges as an efficient solution mitigating systemic privacy risks and communication costs. However, conventional FL inherited from parameter server designs relies too much on a central server, which may lead to privacy risks, communication bottlenecks, or a single point of failure. In this paper, we propose an asynchronous and hierarchical local gradient aggregation and global model update algorithm, FedDual, under three different security considerations for FL in large decentralized networks. Particularly, FedDual preserves privacy by introducing local differential privacy (LDP) and aggregates local gradients asynchronously and hierarchically via a pair-wise gossip algorithm, which is more competitive than previous gossip-based decentralized FL methods in terms of privacy preservation and communication efficiency, and offers more computational efficiency compared to existing blockchain-assisted decentralized FL methods. Further, we devise a noise cutting trick based on Private Set Intersection (PSI) to mitigate the prediction performance loss of the global model caused by the leveraged LDP. Rigorous analyses show that FedDual helps decentralized FL achieve the same convergence rate of$\mathcal {O}\left({\frac {1}{T}}\right) $as centralized ML theoretically. Ingenious experiments on MNIST, CIFAR-10, and FEMNIST confirm that the model prediction performance gained from FedDual is close to centralized ML. More importantly, the proposed noise cutting trick helps FedDual to train better global models than LDP-based FL methods in terms of prediction performance and convergence rate. Qian Chen 0032, Zilong Wang 0001, Xiaodong Lin 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Dap-FL: Federated Learning Flourishes by Adaptive Tuning and Secure AggregationabstractFederated learning (FL), an attractive and promising distributed machine learning paradigm, has sparked extensive interest in exploiting tremendous data stored on ubiquitous mobile devices. However, conventional FL suffers severely from resource heterogeneity, as clients with weak computational and communication capabilities may be unable to complete local training using the same local training hyper-parameters. In this article, we propose Dap-FL, a deep deterministic policy gradient (DDPG)-assisted adaptive FL system, in which local learning rates and local training epochs are adaptively adjusted by all resource-heterogeneous clients through locally deployed DDPG-assisted adaptive hyper-parameter selection schemes. Particularly, the rationality of the proposed hyper-parameter selection scheme is confirmed through rigorous mathematical proof. Besides, due to the thoughtlessness of security consideration of adaptive FL systems in previous studies, we introduce the Paillier cryptosystem to aggregate local models in a secure and privacy-preserving manner. Rigorous analyses show that the proposed Dap-FL system could protect clients’ private local models against chosen-plaintext attacks and chosen-message attacks in a widely used honest-but-curious participants and active adversaries security model. More importantly, through ingenious and extensive experiments, the proposed Dap-FL achieves higher model prediction accuracy than two state-of-the-art RL-assisted FL methods, i.e., 6.03% higher than DDPG-based FL and 7.85% higher than DQN-based FL. In addition, experimental results also show that the proposed Dap-FL achieves higher global model prediction accuracy and faster convergence rates than conventional FL, and the comprehensiveness of the adjusted local training hyper-parameters is validated. Qian Chen 0032, Zilong Wang 0001, Jiawei Chen 0010, Haonan Yan, Xiaodong Lin 0001 |
IEEE Trans. Parallel Distributed Syst. | 1 |
| 2022 | An Upper Bound of the Set Size of Perfect Sequences with Optimal Cross-correlationabstractThe set of perfect sequences with optimal cross-correlation has applications in communication and radar systems. Many different constructions, which are called optimal sets of perfect sequences according to Sarwate bound, have been studied in the literature. However, Song et al. and Zhang et al. recently showed that the set size of these constructions can be improved, since the term related to size vanishes for perfect sequences in Sarwate bound. Until now, we don’t know whether the set size of these constructions is optimal, though they are all called optimal sets. We studied the problem of the set size of perfect sequences with optimal cross-correlation, and showed that the set size must be upper bounded by the length of the perfect sequences in this paper. Zilong Wang 0001, Qian Chen 0032, Guang Gong |
ISIT | 2 |
| 2022 | CFL: Cluster Federated Learning in Large-Scale Peer-to-Peer Networks
Qian Chen 0032, Zilong Wang 0001, Jiawei Chen 0010, Dan Xiao, Xiaodong Lin 0001 |
ISC | 1 |
| 2022 | QP-LDP for better global model performance in federated learningabstractWith the deployment of local differential privacy (LDP), federated learning (FL) has gained stronger privacy-preserving capability against inference-type attacks. However, existing LDP methods reduce global model performance. In this paper, we propose a QP-LDP algorithm for FL to obtain a better-performed global model without losing privacy guarantees defined by the original LDP. Different from previous LDP methods for FL, QP-LDP improves the global model performance by precisely disturbing the non-common components of quantized local contributions. In addition, QP-LDP comprehensively protects two types of local contributions. Through security analysis, QP-LDP provides the probability indistinguishability of clients' private local contributions at a component-level. More importantly, ingenious experiments show that with the deployment of QP-LDP, the global model outperforms that in the original LDP-based FL in terms of prediction accuracy and convergence rate. Qian Chen 0032, Zilong Wang 0001, Jiawei Chen 0010, Haonan Yan, Xiaodong Lin 0001 |
MSN | 1 |
| 2022 | LLDP: A Layer-wise Local Differential Privacy in Federated LearningabstractFederated learning (FL) combined with local differential privacy (LDP) has attracted considerable attention due to its privacy-preserving capability against inference-type attacks, e.g., model inversion attacks and membership inference attacks. However, the noise introduced by LDP reduces the global model performance, while decreasing the noise by setting a larger privacy budget sacrifices the privacy guarantees. In this paper, we propose a layer-wise LDP for the FL system, dubbed LLDP, which disturbs various layers of a local model according to clients’ self-assigned privacy budgets. With the deployment of LLDP, clients could train a highly accurate and rapid-converged global model without loosing privacy guarantees. Through extensive security analyses, the proposed LLDP scheme helps the entire local model achieve (ε,δ)-LDP, and the probability indistinguishability of the local model is achieved under the widespread semi-honest threat model. Ingenious experiments show that LLDP improves the global model prediction and convergence rate by 3.38% and 4.76% on the CIFAR-10 dataset compared to the state-of-the-art LDP method with the same privacy budget. In addition, given the same training target (loss value), LLDP requires a 26.67% lower privacy budget, providing stronger privacy guarantees against model inversion attacks. Qian Chen 0032, Zilong Wang 0001, Jiawei Chen 0010, Haonan Yan, Xiaodong Lin 0001 |
TrustCom | 1 |