Jianan Zhao 0005

dblp:135/9355-5 · DBLP profile ↗
← Back
2ranked-venue papers
2as first author
2since 2021 · last 2025
0000-0002-1859-3436ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2025 Enabling Gradient Inversion Attack Against SplitFed Learning via L2 Norm Amplification
abstract
SplitFed Learning (SFL) represents a compelling distributed learning paradigm tailored for resource-constrained edge computing scenarios, wherein the privacy threat posed by Gradient Inversion Attacks (GIA) remains challenging. The unique architecture of SFL restricts the fed server’s access only to the client-side model’sdeficient gradients, which lack essential information about the original data. This absence of complete gradient information hinders traditional GIA methods, which rely on complete gradient information for effective data reconstruction, thereby significantly diminishing their effectiveness in the SFL context. In this paper, we propose a novel attack against SFL calledDeficient Gradient-based Inversion Attack(DGIA), which reconstructs original training data by artificially amplifying the ℓ2norm of deficient gradients. Through extensive evaluation of how GIA performance varies with different gradient magnitudes, we observe a definitive correlation between the gradient ℓ2norm and attack performance. Based on this correlation, we further optimize DGIA to identify the optimal gradient amplification scale that maximizes the information encoded in deficient gradients. This compensates for the restricted access to complete gradients and enhances the attack performance. We conduct extensive experiments to demonstrate DGIA’s performance across various SFL scenarios compared with other GIA schemes and show attack efficacy under general defenses.
Jianan Zhao 0005, Wenjuan Tang, Kuan Zhang 0001, Hongbo Jiang 0001
IEEE Trans. Inf. Forensics Secur.1
2021 Efficient GSW-Style Fully Homomorphic Encryption over the Integers
abstract
We propose a GSW-style fully homomorphic encryption scheme over the integers (FHE-OI) that is more efficient than the prior work by Benarroch et al. (PKC 2017). To reduce the expansion of ciphertexts, our scheme consists of two types of ciphertexts: integers and vectors. Moreover, the computational efficiency in the homomorphic evaluation can be improved by hybrid homomorphic operations between integers and vectors. In particular, when performing vector-integer multiplications, the evaluation has the computational complexity of Ο γ log γ and thus outperforms all prior FHE-OI schemes. To slow down the noise growth in homomorphic multiplications, we introduce a new noise management method called sequentialization; therefore, the noise in the resulting ciphertext increases by a factor of l ⋅ poly λ rather than poly λ l in general multiplications, where l is the number of multiplications. As a result, the circuit with larger multiplicative depth can be evaluated under the same parameter settings. Finally, to further reduce the size of ciphertexts, we apply ciphertext truncation and obtain the integer ciphertext of size Ο λ log λ , thus additionally reducing the size of the vector ciphertext in Benarroch’s scheme from Ο ˜ λ 4 to Ο λ 2 log 2 λ .
Jianan Zhao 0005, Ruwei Huang, Bo Yang 0069
Secur. Commun. Networks1