VLDB 2026 Research / reviewers in the wild / expert
Xiaochen Zhu 0003
dblp:117/6165-3
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2026
0009-0007-2456-7406ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Privacy-Conscious Algorithm Design Via PAC Privacy
Mayuri Sridhar, Xiaochen Zhu 0003, Srini Devadas |
SP | 2 |
| 2025 | Passive Inference Attacks on Split Learning via Adversarial Regularization
Xiaochen Zhu 0003, Xinjian Luo, Yuncheng Wu, Yangfan Jiang 0001, Xiaokui Xiao, Beng Chin Ooi |
NDSS | 1 |
| 2024 | On Data Distribution Leakage in Cross-Silo Federated LearningabstractFederated learning (FL) has emerged as a promising privacy-preserving machine learning paradigm, enabling data owners to collaboratively train a joint model by sharing model parameters instead of private training data. However, recent studies reveal the privacy risks in FL by inferring private training data from model parameters. Therefore, differential privacy (DP) is incorporated into FL to safeguard training data. Nevertheless, DP does not provide a strong theoretical guarantee for protecting data distribution, which is also highly sensitive in thecross-siloFL scenarios as it may reflect the business secrets of data owners. In this paper, we develop two attack methods to investigate the potential risks of data distribution leakage in differentially private cross-silo FL. We highlight that an honest-but-curious server can successfully infer both the feature and label distributions of each party's training data without any background knowledge. Specifically, the first attack applies when models are differentiable, while the second attack caters to non-differentiable classification models. Extensive experiments on six benchmark datasets validate the effectiveness of the proposed attacks. The results demonstrate that the state-of-the-art DP-SGD algorithm is still vulnerable to the inference attack on data distribution, emphasizing the necessity of designing more advanced privacy-preserving FL frameworks. Yangfan Jiang 0001, Xinjian Luo, Yuncheng Wu, Xiaochen Zhu 0003, Xiaokui Xiao, Beng Chin Ooi |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2023 | Blink: Link Local Differential Privacy in Graph Neural Networks via Bayesian EstimationabstractGraph neural networks (GNNs) have gained an increasing amount of popularity due to their superior capability in learning node embeddings for various graph inference tasks, but training them can raise privacy concerns. To address this, we propose using link local differential privacy over decentralized nodes, enabling collaboration with an untrusted server to train GNNs without revealing the existence of any link. Our approach spends the privacy budget separately on links and degrees of the graph for the server to better denoise the graph topology using Bayesian estimation, alleviating the negative impact of LDP on the accuracy of the trained GNNs. We bound the mean absolute error of the inferred link probabilities against the ground truth graph topology. We then propose two variants of our LDP mechanism complementing each other in different privacy settings, one of which estimates fewer links under lower privacy budgets to avoid false positive link estimates when the uncertainty is high, while the other utilizes more information and performs better given relatively higher privacy budgets. Furthermore, we propose a hybrid variant that combines both strategies and is able to perform better across different privacy budgets. Extensive experiments show that our approach outperforms existing methods in terms of accuracy under varying privacy budgets. Xiaochen Zhu 0003, Vincent Y. F. Tan, Xiaokui Xiao |
CCS | 1 |