Ping Xiong 0001

dblp:15/3392-1 · DBLP profile ↗
← Back
49ranked-venue papers
8as first author
30since 2021 · last 2026
0000-0003-3289-3061ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Databases, data management, data science and information retrieval · 15 · 2 first-author · 8 since 2021Security and privacy · 13 · 11 since 2021Systems, architecture and hardware · 11 · 3 first-author · 5 since 2021Artificial intelligence and machine learning · 8 · 1 first-author · 3 since 2021Computer networks · 4 · 2 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2
YearPublicationVenuePosition
2026 IncentEn-Fed: An incentive-driven ensemble framework for heterogeneous federated learning
Ping Xiong 0001, Tianqing Zhu
J. Inf. Secur. Appl.3
2026 Zero-Shot Class Unlearning via Layer-Wise Relevance Analysis and Neuronal Path Perturbation
abstract
Machine unlearning is a technique that removes specific data influences from trained models without the need for extensive retraining. However, it faces several key challenges, including the lack of explanation, privacy concerns during the unlearning process, and the high demand for time and computational resources. This paper presents a novel unlearning approach to tackle above challenges by employing Layer-wise Relevance Analysis and Neuronal Path Perturbation. Our method balances machine unlearning performance and model utility by identifying and perturbing highly relevant neurons, thus achieving effective unlearning. Using unseen data that has not been presented in the original training set, our method achieves zero-shot unlearning, which allows for the removal of specific class knowledge without accessing the original training data during the unlearning process. This approach ensures robust privacy protection. Experimental results demonstrate that our approach effectively removes targeted data from the target unlearning model while maintaining the model's utility, offering a practical solution for privacy-preserving machine learning. Our code is available athttps://github.com/ChangWenhan/LRA-NPP-Unlearning
Wenhan Chang, Tianqing Zhu, Ping Xiong 0001, Faqian Guan, Wanlei Zhou 0001
IEEE Trans. Dependable Secur. Comput.3
2025 FedMP: A Multi-prototype Heterogeneous Federated Learning Framework
Huanhuan Chi, Zhenni Liu, Ping Xiong 0001
KSEM (3)4
2025 Research on Online Log Anomaly Detection Model Based on Informer
abstract
ABSTRACT To address the limitations of conventional reactive log anomaly detection in high‐availability systems, this paper presents OADS—an online anomaly detection system that synergizes time‐series prediction with real‐time detection. The system features LSP‐Informer, a multivariate log sequence predictor built upon Informer architecture and enhanced by a novel weighted combination loss (WCL) that simultaneously optimizes both prediction accuracy and semantic consistency. Furthermore, OADS implements a unique prediction‐detection cascade by integrating LSP‐Informer with a Temporal Convolutional Network + Attention (TCNA)‐based Log Anomaly Detection Model (LADM), enabling proactive anomaly forecasting 5–10 steps ahead. Experimental results on HDFS logs demonstrate exceptional performance: The TCNA‐based LADM achieves an F1‐score of 0.9860, while LSP‐Informer maintains a 0.9801 F1‐score for 5‐step‐ahead prediction. The complete OADS system successfully predicts potential anomalies in advance, maintaining a robust 0.73+ Jaccard index under heavy masking conditions while preserving interpretability in real‐world deployments.
Yimin Guo 0001, Yiling Sun, Ping Xiong 0001
Concurr. Comput. Pract. Exp.3
2025 A survey on machine unlearning: Techniques and new emerged privacy risks
Hengzhu Liu, Ping Xiong 0001, Tianqing Zhu, Philip S. Yu
J. Inf. Secur. Appl.2
2025 ID-HFL: Incentive-driven heterogeneous federated learning based on game theory and differential privacy
Huanhuan Chi, Zhenni Liu, Xiaming Tu, Ping Xiong 0001, Tianqing Zhu
Knowl. Based Syst.4
2025 Decentralized Self-Auditing Multiple Cloud Storage in Compressed Provable Data Possession
abstract
As cloud storage becomes popular, more and more users tend to outsource their data to powerful cloud severs. To prevent a single point of failure, users prefer to store data on multiple cloud servers from different cloud service providers. However, after outsourcing data to cloud servers, users lose the control of their data, which may incur many serious security issues, such as abnormal data tampering and deleting. It is necessary for users to audit multiple cloud storage aperiodically. In this article, we aim to design a decentralized self-auditing solution for multiple cloud storage, in which cloud servers can audit the integrity of each other, and thus no third-party entity is required. First, based on basic algebra, our protocol realizes decentralized self-auditing multiple cloud storage that only involves encrypted user data. Second, we design a proof exchanging mechanism, making any number of cloud servers form the same final integrity proof with a linear number of interactions. Third, our solution can achieve cloud dynamics, which can freely enable and disable a cloud server to provide storage service. At last, security proof and performance evaluation show that the proposed protocol has provable security and high efficiency.
Yang Yang 0022, Yanjiao Chen, Ping Xiong 0001, Fei Chen 0003, Jing Chen 0003
IEEE Trans. Dependable Secur. Comput.3
2025 Trojan Attack on Machine Unlearning: Security Risk of the Right to be Forgotten
abstract
The Right to be Forgottenand related legislation mandate that every individual has the right to withdraw their consent to the use of their personal data. These laws and regulations led to the development of a new concept – machine unlearning. Recently, various machine unlearning approaches have been proposed to remove the influence of data sample(s) from a trained model. However, alongside all the achievements, there are still loopholes that may cause significant losses for the model owner. We found that it might be dangerous to remove the influence of some “well-designed” data samples from a pre-trained model. An adversary may craft some poisonous data and take advantage of the unlearning request to manipulate an unlearned model. In this paper, we exploit the vulnerabilities of the fast retraining-based unlearning strategy and propose a new data poisoning attack to demonstrate the risks they may bring about. The attack is triggered by submitting an unlearning request on adversarially designed data samples, and it enables an adversary to steer a model to a target location in the parameter space. We provide theoretical analyses to show the feasibility of such an attack regarding the gradient of the poisonous data. Furthermore, the experimental results on real-world datasets demonstrate that the attack strategy is effective.
Lefeng Zhang, Tianqing Zhu, Ping Xiong 0001, Wanlei Zhou 0001
IEEE Trans. Dependable Secur. Comput.3
2025 Game-Theoretic Machine Unlearning: Mitigating Extra Privacy Leakage
abstract
With the extensive use of machine learning technologies, data providers encounter increasing privacy risks. Recent legislation, such as GDPR, obligates organizations to remove requested data and its influence from a trained model. Machine unlearning is an emerging technique designed to enable machine learning models to erase users’ private information. Although several efficient machine unlearning schemes have been proposed, these methods still have limitations. First, removing the contributions of partial data may lead to model performance degradation. Second, discrepancies between the original and generated unlearned models can be exploited by attackers to obtain target sample’s information, resulting in additional privacy leakage risks. To address above challenges, we proposed a game-theoretic machine unlearning algorithm that simulates the competitive relationship between unlearning performance and privacy protection. This algorithm comprises unlearning and privacy modules. The unlearning module possesses a loss function composed of model distance and classification error, which is used to derive the optimal strategy. The privacy module aims to make it difficult for an attacker to infer membership information from the unlearned data, thereby reducing the privacy leakage risk during the unlearning process. Additionally, the experimental results on real-world datasets demonstrate that this game-theoretic unlearning algorithm’s effectiveness and its ability to generate an unlearned model with a performance similar to that of the retrained one while mitigating extra privacy leakage risks.
Hengzhu Liu, Tianqing Zhu, Lefeng Zhang, Ping Xiong 0001
IEEE Trans. Inf. Forensics Secur.4
2025 The Price of Unlearning: Identifying Unlearning Risk in Edge Computing
abstract
Machine unlearning is an emerging paradigm that aims to make machine learning models “forget” what they have learned about particular data. It fulfills the requirements of privacy legislation (e.g., General Data Protection Regulation), which stipulates that individuals have the autonomy to determine the usage of their personal data. However, alongside all the achievements, there are still loopholes in machine unlearning that may cause significant losses for the system, especially in edge computing. Edge computing is a distributed computing paradigm with the purpose of migrating data–processing tasks closer to terminal devices. While various machine unlearning approaches have been proposed to erase the influence of data sample(s), we claim that it might be dangerous to directly apply them in the realm of edge computing. A malicious edge node may broadcast (possibly fake) unlearning requests to a target data sample (s) and then analyze the behavior of edge devices to infer useful information. In this article, we exploited the vulnerabilities of current machine unlearning strategies in edge computing and proposed a new inference attack to highlight the potential privacy risk. Furthermore, we developed a defense method against this particular type of attack and proposed the price of unlearning ( PoU ) as a means to evaluate the inefficiency it brings to an edge computing system. We provide theoretical analyses to show the upper bound of the PoU using tools borrowed from game theory. The experimental results on real-world datasets demonstrate that the proposed defense strategy is effective and capable of preventing an adversary from deducing useful information.
Lefeng Zhang, Tianqing Zhu, Ping Xiong 0001, Wanlei Zhou 0001
ACM Trans. Multim. Comput. Commun. Appl.3
2024 Enhancing Privacy in Machine Unlearning: Posterior Perturbation Against Membership Inference Attack
Hengzhu Liu, Huanhuan Chi, Ping Xiong 0001
ICA3PP (6)4
2024 BSRA: Blockchain-Based Secure Remote Authentication Scheme for Fog-Enabled Internet of Things
abstract
The insufficient trustworthiness of fog nodes in fog computing leads to new security and privacy problems in communication between entities. Existing authentication schemes rely on a trusted third party, or assume that fog nodes are trustworthy, or the authentication overhead is high, which is inconsistent with the characteristics of fog computing. To solve the problem of secure communication in the fog computing environment, we propose an efficient blockchain-based secure remote authentication protocol for the fog-enabled Internet of Things (BSRA). Specifically, blockchain is introduced to construct distributed trust for the fog computing environment. Only lightweight cryptographic primitives, such as physical unclonable functions (PUFs) and cryptographic hash functions, are exploited to design the authentication scheme. In addition, we use temporary identities and the authentication-piggybacking-synchronization to ensure the anonymity and effectiveness of the authentication scheme. We conduct security analysis to demonstrate that BSRA can provide guarantees against various known attacks. We also evaluate the performance of BSRA from several aspects, and the results show that BSRA is effective.
Yimin Guo 0001, Zhenfeng Zhang, Yajun Guo, Ping Xiong 0001
IEEE Internet Things J.4
2024 A provably secure and practical end-to-end authentication scheme for tactile Industrial Internet of Things
Yimin Guo 0001, Yajun Guo, Ping Xiong 0001, Fan Yang 0034, Chengde Zhang
Pervasive Mob. Comput.3
2024 Deeper Insight Into Why Authentication Schemes in IoT Environments Fail to Achieve the Desired Security
abstract
Designing an efficient and secure authentication scheme is an significant means to ensure the security of IoT systems. Hundreds of authentication schemes tailored for IoT environments have been proposed in recent years, and regrettably, many of them were soon found to have succumbed to security vulnerabilities. In an effort to investigate the underlying reason for this, Wang et al. (at TIFS’23) recently analyzed the vulnerability of authentication schemes from the perspective of provable security. However, we observe that some authentication schemes with sound security proofs and heuristic security analysis are also not resistant to certain attacks, and even those that have been improved several times are still not immune. To explore the deep-seated reasons for security vulnerabilities in IoT authentication schemes, we divide security attacks into explicit and implicit attacks and find that many authentication schemes exhibit security under explicit attacks but are rendered vulnerable under implicit attacks. Further, we propose the relationship between the design goals of security attributes of authentication schemes and implicit attacks, analyze the vulnerability of three typical authentication schemes under implicit attacks, and find that only the security attributes capable of resisting the strongest implicit attacks are secure. Finally, we offer some specific suggestions on how to achieve the security attribute goals.
Yimin Guo 0001, Yajun Guo, Ping Xiong 0001, Fan Yang 0034, Chengde Zhang
IEEE Trans. Inf. Forensics Secur.3
2024 Heterogeneous Ensemble Federated Learning With GAN-Based Privacy Preservation
abstract
Multi-party collaborative learning has become a paradigm for large-scale knowledge discovery in the era of big data. As a typical form of collaborative learning, federated learning (FL) has received widespread research attention in recent years. In practice, however, FL faces a range of challenges such as objective inconsistency, communication and synchronization issues, due to the heterogeneity in the clients' local datasets and devices. In this paper, we propose EnsembleFed, a novel ensemble framework for heterogeneous FL. The proposed framework first allows each client to train a local model with full autonomy and without having to consider the heterogeneity of local datasets. The confidence scores of training samples output by each local model are then perturbed to defend against membership inference attacks, after which they are submitted to the server for use in constructing the global model. We apply a GAN-based method to generate calibrated noise for confidence perturbation. Benefiting from the ensemble framework, EnsembleFed disengages from the restriction of real-time synchronization and achieves collaborative learning with lower communication costs than traditional FL. Experiments on real-world datasets demonstrate that the proposed EnsembleFed can significantly improve the performance of the global model while also effectively defending against membership inference attacks.
Hengzhu Liu, Huanhuan Chi, Ping Xiong 0001
IEEE Trans. Sustain. Comput.4
2023 Preserving data privacy in federated learning through large gradient pruning
Zhiqiu Zhang, Tianqing Zhu, Wei Ren 0002, Ping Xiong 0001, Kim-Kwang Raymond Choo
Comput. Secur.4
2023 Decentralized privacy-preserving truth discovery for crowd sensing
Ping Xiong 0001, Guirong Li, Hengzhu Liu, Yiyi Hu
Inf. Sci.1
2023 Migrating federated learning to centralized learning with the leverage of unlabeled data
Tianqing Zhu, Wei Ren 0002, Dongmei Zhang 0006, Ping Xiong 0001
Knowl. Inf. Syst.5
2023 FedRecovery: Differentially Private Machine Unlearning for Federated Learning Frameworks
abstract
Over the past decades, the abundance of personal data has led to the rapid development of machine learning models and important advances in artificial intelligence (AI). However, alongside all the achievements, there are increasing privacy threats and security risks that may cause significant losses for data providers. Recent legislation requires that the private information about a user should be removed from a database as well as machine learning models upon certain deletion requests. While erasing data records from memory storage is straightforward, it is often challenging to remove the influence of particular data samples from a model that has already been trained. Machine unlearning is an emerging paradigm that aims to make machine learning models “forget” what they have learned about particular data. Nevertheless, the unlearning issue for federated learning has not been completely addressed due to its special working mode. First, existing solutions crucially rely on retraining-based model calibration, which is likely unavailable and can pose new privacy risks for federated learning frameworks. Second, today’s efficient unlearning strategies are mainly designed for convex problems, which are incapable of handling more complicated learning tasks like neural networks. To overcome these limitations, we took advantage of differential privacy and developed an efficient machine unlearning algorithm named FedRecovery. The FedRecovery erases the impact of a client by removing a weighted sum of gradient residuals from the global model, and tailors the Gaussian noise to make the unlearned model and retrained model statistically indistinguishable. Furthermore, the algorithm neither requires retraining-based fine-tuning nor needs the assumption of convexity. Theoretical analyses show the rigorous indistinguishability guarantee. Additionally, the experiment results on real-world datasets demonstrate that the FedRecovery is efficient and is able to produce a model that performs similarly to the retrained one.
Lefeng Zhang, Tianqing Zhu, Ping Xiong 0001, Wanlei Zhou 0001
IEEE Trans. Inf. Forensics Secur.4
2023 Precise Facial Landmark Detection by Reference Heatmap Transformer
abstract
Most facial landmark detection methods predict landmarks by mapping the input facial appearance features to landmark heatmaps and have achieved promising results. However, when the face image is suffering from large poses, heavy occlusions and complicated illuminations, they cannot learn discriminative feature representations and effective facial shape constraints, nor can they accurately predict the value of each element in the landmark heatmap, limiting their detection accuracy. To address this problem, we propose a novel Reference Heatmap Transformer (RHT) by introducing reference heatmap information for more precise facial landmark detection. The proposed RHT consists of a Soft Transformation Module (STM) and a Hard Transformation Module (HTM), which can cooperate with each other to encourage the accurate transformation of the reference heatmap information and facial shape constraints. Then, a Multi-Scale Feature Fusion Module (MSFFM) is proposed to fuse the transformed heatmap features and the semantic features learned from the original face images to enhance feature representations for producing more accurate target heatmaps. To the best of our knowledge, this is the first study to explore how to enhance facial landmark detection by transforming the reference heatmap information. The experimental results from challenging benchmark datasets demonstrate that our proposed method outperforms the state-of-the-art methods in the literature.
Jun Wan 0005, Jun Liu 0036, Jie Zhou 0009, Zhihui Lai 0001, LinLin Shen, Ping Xiong 0001, Wenwen Min
IEEE Trans. Image Process.7
2023 Adversarial Attacks Against Deep Generative Models on Data: A Survey
abstract
Deep generative models have gained much attention given their ability to generate data for applications as varied as healthcare to financial technology to surveillance, and many more - the most popular models being generative adversarial networks (GANs) and variational auto-encoders (VAEs). Yet, as with all machine learning models, ever is the concern over security breaches and privacy leaks and deep generative models are no exception. In fact, these models have advanced so rapidly in recent years that work on their security is still in its infancy. In an attempt to audit the current and future threats against these models, and to provide a roadmap for defense preparations in the short term, we prepared this comprehensive and specialized survey on the security and privacy preservation of GANs and VAEs. Our focus is on the inner connection between attacks and model architectures and, more specifically, on five components of deep generative models: the training data, the latent code, the generators/decoders of GANs/VAEs, the discriminators/encoders of GANs/VAEs, and the generated data. For each model, component and attack, we review the current research progress and identify the key challenges. The paper concludes with a discussion of possible future attacks and research directions in the field.
Tianqing Zhu, Zhiqiu Zhang, Ping Xiong 0001, Wanlei Zhou 0001
IEEE Trans. Knowl. Data Eng.5
2023 A Robust Game-Theoretical Federated Learning Framework With Joint Differential Privacy
abstract
Federated learning is a promising distributed machine learning paradigm that has been playing a significant role in providing privacy-preserving learning solutions. However, alongside all its achievements, there are also limitations. First, traditional frameworks assume that all the clients are voluntary and so will want to participate in training only for improving the model’s accuracy. However, in reality, clients usually want to be adequately compensated for the data and resources they will use before participating. Second, today’s frameworks do not offer sufficient protection against malicious participants who try to skew a jointly trained model with poisoned updates. To address these concerns, we have developed a more robust federated learning scheme based on joint differential privacy. The framework provides two game-theoretic mechanisms to motivate clients to participate in training. These mechanisms are dominant-strategy truthful, individual rational, and budget-balanced. Further, the influence an adversarial client can have is quantified and restricted, and data privacy is similarly guaranteed in quantitative terms. Experiments with different training models on real-word datasets demonstrate the effectiveness of the proposed approach.
Lefeng Zhang, Tianqing Zhu, Ping Xiong 0001, Wanlei Zhou 0001, Philip S. Yu
IEEE Trans. Knowl. Data Eng.3
2023 A Game-Theoretic Federated Learning Framework for Data Quality Improvement
abstract
Federated learning is a promising distributed machine learning paradigm that has been playing a significant role in privacy-preserving machine learning tasks. However, alongside all its achievements, the framework has limitations. First, traditional frameworks assume that all clients want to improve model accuracy and so participation is voluntary. However, in reality, clients usually want to be appropriately compensated for the data and resources they will need to commit to the training process before contributing. Second, today's frameworks allow clients to perturb their parameter updates locally, which introduces a great deal of noise to the trained model and can seriously impact model accuracy. To address these concerns, we have developed a private reward game that incentivizes clients to contribute high-quality data to the training process. The game converges to a Nash equilibrium under the guarantee of joint differential privacy, and each client maximizes their reward following an equilibrium strategy. The noise injected into the model is reduced by introducing a centralized differential privacy model that aggregates the parameters and compensates clients via a data trading market. Experimental simulations show the rationales behind and effectiveness of the proposed game approach. Additionally, we present comparisons between different training models to demonstrate the performance of the proposed approach in real-world scenarios.
Lefeng Zhang, Tianqing Zhu, Ping Xiong 0001, Wanlei Zhou 0001, Philip S. Yu
IEEE Trans. Knowl. Data Eng.3
2022 A privacy preservation method for multiple-source unstructured data in online social networks
Chenguang Wang 0008, Tianqing Zhu, Ping Xiong 0001, Wei Ren 0002, Kim-Kwang Raymond Choo
Comput. Secur.3
2022 PriTxt: A privacy risk assessment method for text data based on semantic correlation learning
abstract
Summary Privacy risk assessment plays a fundamental role in privacy preservation, as it determines the extent to which subsequent processing (such as generalization and obfuscation), should be applied to the sensitive data. However, most existing works on privacy risk assessment have focused on structured data, while unstructured text data remain relatively underexplored due to the complexity of natural language. In this article, we propose a novel method, PriTxt, for evaluating the privacy risk associated with text data by exploiting the semantic correlation. Using definitions derived from the General Data Protection Regulation (GDPR), a de facto standard of privacy preservation in practice, PriTxt first defines the private features that related to individual privacy in order to locate the sensitive words. By using the word2vec algorithm, a word‐embedding model is further constructed to identify the quasi‐sensitive words that are semantically correlated to the private features. The privacy risk of a given text is finally evaluated by aggregating the weighted risks of the sensitive and the quasi‐sensitive words in the text. Experiments on real‐world datasets demonstrate that the proposed PriTxt is effective for conducting risk assessment on text data and further outperforms the traditional methods.
Ping Xiong 0001, Yunli Zhu, Tianqing Zhu
Concurr. Comput. Pract. Exp.1
2022 Location privacy preservation through kernel transformation
abstract
Summary The frequent data leak scandals of recent years indicate that service providers who hold personal data may not be reliable as they claim. We assert that sensitive user information must be sanitized locally before it is sent to service providers if it is to be protected. The LPPK privacy‐preserving framework presented in this article is a local sanitization scheme, for location‐based services (LBSs). It applies a fog‐computing structure in which a private map is generated by the LBS server with kernel transformation for each user. A fog device then provides location services for each user according to the private map. Without colluding, neither the LBS server nor the fog device can deduce a user's real location. Experiments conducted on real‐world data sets demonstrate that LPPK delivers sufficient query accuracy at a level significantly higher than existing approaches while preserving location privacy.
Lefeng Zhang, Guanghua Song, Danyang Zhu, Wei Ren 0002, Ping Xiong 0001
Concurr. Comput. Pract. Exp.5
2022 The Dynamic Privacy-Preserving Mechanisms for Online Dynamic Social Networks
abstract
Networks that constantly transmit information and change structure are becoming increasingly prevalent. However, traditional privacy models are designed to protect static information, such as records in a database or a person’s profile information, which seldom changes. This conflict between static models and dynamic environments is dramatically hindering the effectiveness and efficiency of privacy preservation in today’s dynamic world. Hence, in this paper, we formally define the concept of dynamic privacy, present two novel perspectives, privacy propagation and accumulation, on the way private information can spread through dynamic cyberspace, and develop associated theories and mechanisms for preserving privacy in advanced complex networks, such as social networking sites where data are constantly being released, shared, and exchanged.
Tianqing Zhu, Jin Li 0002, Xiangyu Hu 0006, Ping Xiong 0001, Wanlei Zhou 0001
IEEE Trans. Knowl. Data Eng.4
2021 Privacy Risk Assessment for Text Data Based on Semantic Correlation Learning
Ping Xiong 0001, Yunli Zhu, Tianqing Zhu
WASA (3)1
2021 An optimized differential privacy scheme with reinforcement learning in VANET
Tao Zhang 0055, Sheng Shen 0005, Tianqing Zhu, Ping Xiong 0001
Comput. Secur.5
2021 Privacy preservation for image data: A GAN-based method
abstract
The importance of protecting personal information, like, a person's address or health history, is well known and commonly discussed. However, images also contain sensitive information that can compromise a person's privacy or be used for nefarious purposes. To date, most methods for preserving privacy with images have relied on obfuscation techniques, such as pixelation, blurring, or masking parts of the image. However, new face-recognition technologies driven by deep learning are showing cracks in the old techniques. Moreover, faceless recognition is presenting a whole new set of challenges for image privacy. The core of these issues it is how to ensure privacy while still being able to see and use the image. Our solution is a model based on a generative adversarial network that protects identity information while preserving face features of the original image as much as possible. The premise is to generate a fake image of a face that shares all the same attributes as the original image, for example, a brown-eyed child smiling. With this strategy, the image remains useful, but no person or algorithm could determine the identity of the pictured individual. The framework consists of three parts: a detection module, an image creation module, and an image transformation module. The detection module extracts the attribute labels. The image creation module generates images of faces, and the image transformation module transforms the fake features to match the attributes in the original image. A comprehensive set of experiments shows the effectiveness of the proposed framework.
Zhenfei Chen, Tianqing Zhu, Ping Xiong 0001, Chenguang Wang 0008, Wei Ren 0002
Int. J. Intell. Syst.3
2020 Privacy and Utility Trade-Off for Textual Analysis via Calibrated Multivariate Perturbations
Jingye Tang, Tianqing Zhu, Ping Xiong 0001, Wei Ren 0002
NSS3
2020 Private collaborative filtering under untrusted recommender server
Ping Xiong 0001, Lefeng Zhang, Tianqing Zhu, Gang Li 0009, Wanlei Zhou 0001
Future Gener. Comput. Syst.1
2020 Differentially private model publishing in cyber physical systems
Tianqing Zhu, Ping Xiong 0001, Gang Li 0009, Wanlei Zhou 0001, Philip S. Yu
Future Gener. Comput. Syst.2
2020 Secure and efficient outsourcing computation on large-scale linear regressions
Yang Yang 0022, Ping Xiong 0001, Fei Chen 0003
Inf. Sci.2
2020 Correlated Differential Privacy: Feature Selection in Machine Learning
abstract
Privacy preserving in machine learning is a crucial issue in industry informatics since data used for training in industries usually contain sensitive information. Existing differentially private machine learning algorithms have not considered the impact of data correlation, which may lead to more privacy leakage than expected in industrial applications. For example, data collected for traffic monitoring may contain some correlated records due to temporal correlation or user correlation. To fill this gap, in this article, we propose a correlation reduction scheme with differentially private feature selection considering the issue of privacy loss when data have correlation in machine learning tasks. The proposed scheme involves five steps with the goal of managing the extent of data correlation, preserving the privacy, and supporting accuracy in the prediction results. In this way, the impact of data correlation is relieved with the proposed feature selection scheme, and moreover the privacy issue of data correlation in learning is guaranteed. The proposed method can be widely used in machine learning algorithms, which provide services in industrial areas. Experiments show that the proposed scheme can produce better prediction results with machine learning tasks and fewer mean square errors for data queries compared to existing schemes.
Tao Zhang 0055, Tianqing Zhu, Ping Xiong 0001, Huan Huo, Zahir Tari, Wanlei Zhou 0001
IEEE Trans. Ind. Informatics3
2019 Optimizing rewards allocation for privacy-preserving spatial crowdsourcing
Ping Xiong 0001, Danyang Zhu, Lefeng Zhang, Wei Ren 0002, Tianqing Zhu
Comput. Commun.1
2019 A differentially private method for crowdsourcing data submission
abstract
Summary In recent years, the ubiquity of mobile devices has made spatial crowdsourcing a successful business platform for conducting spatiotemporal projects. In spatial crowdsourcing, workers contribute to a project by performing a task at a specific location. However, these platforms present serious threats to people's location privacy because sensitive information may be leaked from submitted spatiotemporal data. As a result, people may be hesitant to join spatial crowdsourcing projects, which hampers further applications of this business model. In this paper, we propose a private spatial crowdsourcing data submission algorithm, called PS‐Sub. This is a differentially private method that preserves people's location privacy and provides acceptable data utility. Rigorous privacy analyses theoretically demonstrate the privacy guarantees inherent in the proposed model. Experiments based on real‐world datasets were conducted using practical evaluation metrics. The results show that our method is able to achieve location privacy preservation efficiently, at an acceptable cost for spatial crowdsourcing applications.
Lefeng Zhang, Ping Xiong 0001, Wei Ren 0002, Tianqing Zhu
Concurr. Comput. Pract. Exp.2
2018 Answering differentially private queries for continual datasets release
Tianqing Zhu, Gang Li 0009, Ping Xiong 0001, Wanlei Zhou 0001
Future Gener. Comput. Syst.3
2017 Differentially private query learning: From data publishing to model publishing
abstract
As one of the most influential privacy definitions, differential privacy provides a rigorous and provable privacy guarantee for data publishing. However, the curator has to release a large number of queries in a batch or a synthetic dataset in the Big Data era. Two challenges need to be tackled: one is how to decrease the correlation between large sets of queries, while the other is how to predict on fresh queries. This paper transfers the data publishing problem to a machine learning problem, in which queries are considered as training samples and a prediction model will be released rather than query results or synthetic datasets. When the model is published, it can be used to answer current submitted queries and predict results for fresh queries from the public. Compared with the traditional method, the proposed prediction model enhances the accuracy of query results for non-interactive publishing. We prove that learning model can successfully retain the utility of published queries while preserving privacy.
Tianqing Zhu, Ping Xiong 0001, Gang Li 0009, Wanlei Zhou 0001, Philip S. Yu
IEEE BigData2
2016 Semantic analysis in location privacy preserving
abstract
Summary With the increasing use of location‐based services, location privacy has recently started raising serious concerns. Location perturbation and obfuscation are most widely used for location privacy preserving. To protect a user from being identified, a cloaked spatial region that contains otherk− 1 nearest neighbors of the user is submitted to the location‐based service provider, instead of the accurate position. In this paper, we consider the location‐aware applications that services are different among regions. In such scenarios, the semantic distance between users should be considered besides the Euclidean distance for searching the neighbors of a user. We define a novel distance measurement that combines the semantic and the Euclidean distance to address the privacy‐preserving issue in the aforementioned applications. We also present an algorithmkNNH to implement our proposed method. Moreover, we conduct performance study experiments on the proposed algorithm. The experimental results further suggest that the proposed distance metric and the algorithm can successfully retain the utility of the location services while preserving users' privacy. Copyright © 2015 John Wiley & Sons, Ltd.
Ping Xiong 0001, Lefeng Zhang, Tianqing Zhu
Concurr. Comput. Pract. Exp.1
2016 A differentially private algorithm for location data release
Ping Xiong 0001, Tianqing Zhu, Wenjia Niu, Gang Li 0009
Knowl. Inf. Syst.1
2016 Privacy-preserving topic model for tagging recommender systems
Tianqing Zhu, Gang Li 0009, Wanlei Zhou 0001, Ping Xiong 0001, Cao Yuan
Knowl. Inf. Syst.4
2015 Correlated Differential Privacy: Hiding Information in Non-IID Data Set
abstract
Privacy preserving on data mining and data release has attracted an increasing research interest over a number of decades. Differential privacy is one influential privacy notion that offers a rigorous and provable privacy guarantee for data mining and data release. Existing studies on differential privacy assume that in a data set, records are sampled independently. However, in real-world applications, records in a data set are rarely independent. The relationships among records are referred to as correlated information and the data set is defined as correlated data set. A differential privacy technique performed on a correlated data set will disclose more information than expected, and this is a serious privacy violation. Although recent research was concerned with this new privacy violation, it still calls for a solid solution for the correlated data set. Moreover, how to decrease the large amount of noise incurred via differential privacy in correlated data set is yet to be explored. To fill the gap, this paper proposes an effective correlated differential privacy solution by defining the correlated sensitivity and designing a correlated data releasing mechanism. With consideration of the correlated levels between records, the proposed correlated sensitivity can significantly decrease the noise compared with traditional global sensitivity. The correlated data releasing mechanism correlated iteration mechanism is designed based on an iterative method to answer a large number of queries. Compared with the traditional method, the proposed correlated differential privacy solution enhances the privacy guarantee for a correlated data set with less accuracy cost. Experimental results show that the proposed solution outperforms traditional differential privacy in terms of mean square error on large group of queries. This also suggests the correlated differential privacy can successfully retain the utility while preserving the privacy.
Tianqing Zhu, Ping Xiong 0001, Gang Li 0009, Wanlei Zhou 0001
IEEE Trans. Inf. Forensics Secur.2
2015 Privacy preserving data release for tagging recommender systems
abstract
Tagging recommender systems allow Internet users to annotate resources with personalized tags. The connection among users, resources and these annotations, often called a folksonomy, permits users the freedom to explore tags, and to obtain recommendations. Releasing these tagging datasets accelerat es both commercial and research work on recommender systems. However, tagging recommender systems has been confronted with serious privacy concerns because adversaries may re-identify a user and her/his sensitive information from the tagging dataset using a little background information. Recently, several private techniques have been proposed to address the problem, but most of them lack a strict privacy notion, and can hardly resist the number of possible attacks. This paper proposes an private releasing algorithm to perturb users’ profile in a strict privacy notion, differential privacy, with the goal of preserving a user’s identity in a tagging dataset. The algorithm includes three privacy-preserving operations: Private Tag Clustering is used to shrink the randomized domain and Private Tag Selection is then applied to find the most suitable replacement tags for the original tags. To hide the numbers of tags, the third operation, Weight Perturbation, finally adds Laplace noise to the weight of tags. We present extensive experimental results on two real world datasets, De.licio.us and Bibsonomy. While the personalization algorithm is successful in both cases, our results further suggest the private releasing algorithm can successfully retain the utility of the datasets while preserving users’ identity.
Tianqing Zhu, Gang Li 0009, Yongli Ren, Wanlei Zhou 0001, Ping Xiong 0001
Web Intell.5
2014 Deferentially Private Tagging Recommendation Based on Topic Model
Tianqing Zhu, Gang Li 0009, Wanlei Zhou 0001, Ping Xiong 0001, Cao Yuan
PAKDD (1)4
2014 Privacy Preserving in Location Data Release: A Differential Privacy Approach
Ping Xiong 0001, Tianqing Zhu, Lei Pan 0002, Wenjia Niu, Gang Li 0009
PRICAI1
2014 An effective privacy preserving algorithm for neighborhood-based collaborative filtering
Tianqing Zhu, Yongli Ren, Wanlei Zhou 0001, Jia Rong, Ping Xiong 0001
Future Gener. Comput. Syst.5
2013 Differential privacy for neighborhood-based collaborative filtering
abstract
As a popular technique in recommender systems, Collaborative Filtering (CF) has received extensive attention in recent years. However, its privacy-related issues, especially for neighborhood-based CF methods, can not be overlooked. The aim of this study is to address the privacy issues in the context of neighborhood-based CF methods by proposing a Private Neighbor Collaborative Filtering (PNCF) algorithm. The algorithm includes two privacy-preserving operations: Private Neighbor Selection and Recommendation-Aware Sensitivity. Private Neighbor Selection is constructed on the basis of the notion of differential privacy to privately choose neighbors. Recommendation-Aware Sensitivity is introduced to enhance the performance of recommendations. Theoretical and experimental analysis are provided to show the proposed algorithm can preserve differential privacy while retaining the accuracy of recommendations.
Tianqing Zhu, Gang Li 0009, Yongli Ren, Wanlei Zhou 0001, Ping Xiong 0001
ASONAM5
2013 Privacy Preserving for Tagging Recommender Systems
abstract
Tagging recommender systems allow Internet users to annotate resources with personalized tags. The connection among users, resources and these annotations, often called afolksonomy, permits users the freedom to explore tags, and to obtain recommendations. Releasing these tagging datasets accelerates both commercial and research work on recommender systems. However, adversaries may re-identify a user and her/his sensitivity information from the tagging dataset using a little background information. Recently, several private techniques have been proposed to address the problem, but most of them lack a strict privacy notion, and can hardly resist the number of possible attacks. This paper proposes an private releasing algorithm to perturb users' profile in a strict privacy notion, differential privacy, with the goal of preserving a user's identity in a tagging dataset. The algorithm includes three privacy preserving operations: Private Tag Clustering is used to shrink the randomized domain and Private Tag Selection is then applied to find the most suitable replacement tags for the original tags. To hide the numbers of tags, the third operation, Weight Perturbation, finally adds Lap lace noise to the weight of tags We present extensive experimental results on two real world datasets, Delicious and Bibsonomy. While the personalization algorithmis successful in both cases.
Tianqing Zhu, Gang Li 0009, Yongli Ren, Wanlei Zhou 0001, Ping Xiong 0001
Web Intelligence5