VLDB 2026 Research / reviewers in the wild / expert
Hongyan Chang
dblp:152/5447
· DBLP profile ↗
4ranked-venue papers
4as first author
4since 2021 · last 2025
0000-0002-0569-0173ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Context-Aware Membership Inference Attacks against Pre-trained Large Language ModelsabstractMembership Inference Attacks (MIAs) on pretrained Large Language Models (LLMs) aim at determining if a data point was part of the model's training set.Prior MIAs that are built for classification models fail at LLMs, due to ignoring the generative nature of LLMs across token sequences.In this paper, we present a novel attack on pre-trained LLMs that adapts MIA statistical tests to the perplexity dynamics of subsequences within a data point.Our method significantly outperforms prior approaches, revealing context-dependent memorization patterns in pre-trained LLMs. Hongyan Chang, Ali Shahin Shamsabadi, Kleomenis Katevas, Hamed Haddadi 0001, Reza Shokri |
EMNLP | 1 |
| 2024 | Efficient Privacy Auditing in Federated Learning
Hongyan Chang, Brandon Edwards, Anindya S. Paul, Reza Shokri |
USENIX Security Symposium | 1 |
| 2023 | Bias Propagation in Federated Learning
Hongyan Chang, Reza Shokri |
ICLR | 1 |
| 2021 | On the Privacy Risks of Algorithmic FairnessabstractAlgorithmic fairness and privacy are essential pillars of trustworthy machine learning. Fair machine learning aims at minimizing discrimination against protected groups by, for example, imposing a constraint on models to equalize their behavior across different groups. This can subsequently change the influence of training data points on the fair model, in a disproportionate way. We study how this can change the information leakage of the model about its training data. We analyze the privacy risks of group fairness (e.g., equalized odds) through the lens of membership inference attacks: inferring whether a data point is used for training a model. We show that fairness comes at the cost of privacy, and this cost is not distributed equally: the information leakage of fair models increases significantly on the unprivileged subgroups, which are the ones for whom we need fair learning. We show that the more biased the training data is, the higher the privacy cost of achieving fairness for the unprivileged subgroups will be. We provide comprehensive empirical analysis for general machine learning algorithms. Hongyan Chang, Reza Shokri |
EuroS&P | 1 |