Shiwei Lu

dblp:154/2343 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0002-6600-1300ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 UPGP:Backdoor defense via unlearning perturbation and orthogonality-constraint gradient projection
Jingtai Li, Xiujiu Yuan, Jiwei Tian, Shiwei Lu, Dengxiu Yu
Pattern Recognit.4
2024 FedDAA: a robust federated learning framework to protect privacy and defend against adversarial attack
Shiwei Lu, Ruihu Li
Frontiers Comput. Sci.1
2023 Top-k sparsification with secure aggregation for privacy-preserving federated learning
Shiwei Lu, Ruihu Li, Chaofeng Guan
Comput. Secur.1
2022 Defense against backdoor attack in federated learning
Shiwei Lu, Ruihu Li
Comput. Secur.1
2022 Defense against local model poisoning attacks to byzantine-robust federated learning
Shiwei Lu, Ruihu Li, Yuena Ma
Frontiers Comput. Sci.1
2021 Boundary augment: A data augment method to defend poison attack
abstract
Abstract In recent years, Deep Neural Networks(DNNs) have been applied in many fields such as computer vision and natural language processing. Many third‐party cloud training platforms have been built to facilitate many individual users or small enterprises for training their models, for example, Colab(google) or AWS cloud platform. For these cloud platforms, there exist many potentially fatal risks, including poison attacks. At the same time, as for federated learning, poison attack is also a severe threat to which. In this paper, a novel method to defend against poison attacks by estimating the distribution of poison data and retraining the backdoor model with a few training data is introduced. The estimated distribution under the manifold DeepFool algorithm fits the poison data well, which can be used to search the manifold boundary of the poisoned data and the clean. Unlike empirical defense methods, the authors' approach is attack‐agnostic, which means that the approach is robust for the various attack methods. Also, it is proven that the adversarial training approach is a practical approach to defend against the poison attack. The authors' approach is tested on the datasets MNIST , CIFAR‐10 , GTSRB and ImageNet . The accuracy of the retrained model decreases slightly, but the ASR drops drastically, which proves that our approach has a powerful generalization to defend against the most poison attacks.
Yuena Ma, Shiwei Lu
IET Image Process.3