Zhou Tan

dblp:157/0906 · DBLP profile ↗
← Back
14ranked-venue papers
5as first author
12since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-author · 4 since 2021Computer networks · 3 · 3 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 DoBlock: Blocking Malicious Association Propagation for Backdoor-Robust Federated Learning Under Domain Skew
abstract
Federated Learning (FL) enables privacy-preserving distributed training but remains vulnerable to backdoor attacks. Attackers can embed malicious trigger-label associations into the global model by participating in the aggregation process. Existing defense methods typically defend against backdoor attacks by detecting and filtering malicious updates that deviate from benign ones. However, we find that these defenses fail under domain skew, where differing feature distributions across clients increase update heterogeneity, making it harder to distinguish malicious updates from benign ones. To address this challenge, we propose DoBlock, a novel defense that utilizes an aggregatable domain infuser incapable of embedding malicious associations, through federated training to facilitate cross-domain knowledge sharing. Moreover, DoBlock prevents malicious association propagation by isolating local models from aggregation, as local models remain client-specific and rely solely on local data for training. Experiments on five domain skew datasets (Digits, PACS, VLCS, Office-Caltech10, and DomainNet) show that DoBlock maintains attack success rates below 2.5%, while achieving the highest main task accuracy, demonstrating superior robustness without sacrificing benign performance.
Zhou Tan, Yirui Huang, Duanshu Fang, Jia-Li Yin, Shouling Ji
AAAI1
2026 FedEG: Towards Fair Federated Learning via Expert-Guided Knowledge Transfer
Zhou Tan, Jianjing Zhu, Chen Dong 0002, Ximeng Liu
ICC2
2026 FedSC: Backdoor Defense in Federated Learning via Model Splitting and Benign Consensus Clustering
Jianjing Zhu, Zhou Tan, Ximeng Liu
ICC2
2026 Toward Federated Learning Against Noisy Clients via CLIP-Guided Prototypes
abstract
Federated Noisy Labels Learning (FNLL) allows global model to be jointly trained on multiple clients with varying degrees of noisy labels while preserving privacy, and despite recent research advances, distinguishing between client clean and noisy samples is still tricky since the distribution of labels among clients is always both noisy and class-imbalanced, leading to the poor performance of existing FNLL methods. To address this problem, we propose a novel framework called FedPN, the first framework to utilize Contrastive Language-Image Pre-training (CLIP) for federated noisy labels tasks. Then, to achieve higher performance for the global model, we introduce an attention based Prototype Adapter to identify more plausible local data for local model training, further improving training stability. We validate the effectiveness of FedPN by conducting extensive experiments on benchmark datasets under both Independently and Identically Distributed (IID) and Non-IID data partitions. The experimental results show that FedPN can effectively filter noisy samples from different clients, and compared with the state of-the-art FNLL method, the FedPN achieves at most and at least 8.39% and 0.88% performance improvement in the case of highly heterogeneous noisy labels.
Zhou Tan, Yirui Huang, Chunpei Li, Ximeng Liu
IEEE Trans. Big Data1
2025 FedMKD: Personalized Federated Learning with Memory Knowledge Distillation
abstract
In recent years, privacy concerns have been receiving increasing attention. Federated learning (FL) has emerged to address privacy challenges in machine learning. In this framework, a group of clients collaborates with a server, where clients upload model parameters instead of raw data. In FL, a key challenge is the presence of non-independent and identically distributed data among clients. To address this issue, we propose a personalized federated learning algorithm (FedMKD) that fully considers the characteristics of the previous round's model. Our algorithm leverages knowledge distillation and gradient descent to optimize the proportion of global model parameters used during the initialization process. FedMKD combines the strengths of the global and memory models to initialize the local model. It effectively retains historical information during training, enhancing the local model's performance. Extensive experimental results demonstrate the effectiveness of our proposed algorithm in addressing statistical heterogeneity issues. FedMKD achieves up to a 10.66% improvement in test accuracy compared to eight state-of-the-art baselines.
Tianjia Lin, Zhou Tan, Ximeng Liu
ICC2
2025 Achieving Zero-Glance Unlearning with Data-Free Inversion and Selective Parameters Suppression
abstract
In machine learning (ML), data deletion involves more than just removing data from a dataset. Machine unlearning enables ML models to eliminate the effects of specific data that needs to be deleted. Under zero-glance settings, we may lack the right to utilize the data slated for removal during unlearning, thereby heightening the complexity. To address this challenge, we propose UISPS, which employs data-free inversion to generate replacement data for unavailable forgotten data. Utilizing the generated data, we propose selective parameter suppression to address the issue of catastrophic forgetting during unlearning effectively. Its interpretability improves the reliability of unlearning under zero-glance conditions. The experiments demonstrate that UISPS performs forgotten tasks with commendable results. Meanwhile, UISPS maintains higher accuracy on retained data, improving it by up to 3.34% while reducing the attack success rate of membership inference attacks by 25.85% ∼ 39.54% compared to the state-of-the-art.
Puwei Lian, Xiao Ke, Zhou Tan, Ximeng Liu
ICME3
2025 FedRog: Robust Federated Graph Classification for Strong Heterogeneity and High-Noise Scenarios
abstract
Federated graph classification has emerged as a promising paradigm for privacy-preserving graph learning across distributed clients. However, real-world federated scenarios often suffer from severe data heterogeneity and label noise, which significantly degrade model performance. To address these challenges, we propose FedRog, a robust and personalized federated graph neural network framework that improves generalization under non-IID and noisy label settings. FedRog introduces a parameter-aware selection and fine-tuning mechanism to align global and local representations, and a neighbor embedding consistency constraint to enhance robustness against noisy supervision. Furthermore, a fine-grained, importance-guided global aggregation strategy based on Fisher information is employed to mitigate unreliable updates from low-quality clients. We conduct extensive experiments on 16 graph classification datasets under five heterogeneous data partition settings. Results show that FedRog consistently achieves competitive or superior performance compared to 14 baselines in terms of both accuracy and robustness under clean and noisy conditions.
Zhou Tan, Zeming Gan, Tiange Xia, Xianxian Li
ACM Multimedia2
2025 FeatShield: Isolating Malicious Feature Extractors for Backdoor-Robust Federated Learning
abstract
Federated learning remains vulnerable to backdoor attacks through malicious parameter updates, with existing defenses limited by homogeneous data assumptions or reliance on gradient anomaly detection. We reveal that FedAvg's critical flaw lies in malicious feature extractor propagation: aggregating poisoned extractors degrades defense accuracy to <70% across five benchmarks, while benign extractors with poisoned headers retain an average of 89.36% defense accuracy. Therefore, we propose FeatShield, a feature-space isolation framework that prevents backdoor propagation via non-aggregated local extractors trained on clean client data. FeatShield introduces 1) variance-aware alignment, adaptively balancing client-specific features and global consistency using local variance metrics, and 2) adversarial feature synthesis, generating non-linear synthetic features via GAN to enhance the global prediction header's generalization on main tasks. Extensive experiments on eight real-world datasets show that FeatShield achieves the best defense performance. For instance, under heterogeneous data (Dirichlet β=0.5) and strong attacks (50% malicious clients), FeatShield achieves 99.26-99.89% defense accuracy and main task accuracy exceeding FedAvg by 1.32-5.70%, demonstrating its superior resistance to backdoor attacks without sacrificing the benign performance.
Zhou Tan, Yirui Huang, Jia-Li Yin, Ximeng Liu
ACM Multimedia1
2025 FedUNL: Utilizing Noisy Labels for Improved Robustness in Federated Learning
abstract
With the growing significance of federated learning (FL) in preserving data privacy, addressing the challenge of noisy labels has become critical. Conventional methods typically focus on filtering or reweighting noisy samples, often overlooking their inherent informational value. To exploit this value, we propose FedUNL, a novel framework for robust FL under label noise. FedUNL uses a Gaussian Mixture Model (GMM) to identify noisy clients and samples based on sample and class losses. Noisy models are then constructed with these samples, and knowledge distillation is employed to extract useful knowledge, supporting main model training and enabling effective noise correction. Distinct strategies are applied to train clean and noisy clients. Experimental results demonstrate that FedUNL improves accuracy by 0.31% to 3.41% over state-of-the-art (SOTA) methods, particularly excelling in challenging scenarios with high noise levels and non-IID data distributions.
Zhou Tan, Ziyun Lin, Ximeng Liu
SMC2
2025 FedPD: Defending federated prototype learning against backdoor attacks
Zhou Tan, Puwei Lian, Ximeng Liu, Yan Che
Neural Networks1
2023 Clustered Federated Learning with Inference Hash Codes Based Local Sensitive Hashing
Zhou Tan, Ximeng Liu, Yan Che
Inscrypt (2)1
2021 Adaptive Clipping Bound of Deep Learning with Differential Privacy
abstract
Deep learning has been extensively applied in many fields, such as image segmentation, voice recognition, automatic language translation. However, many malicious attackers attempt to attack the model which was trained to accomplish a deep learning assignment via various schemes. Recently, differential privacy technology has been proposed to defend against such attacks via sacrificing the accuracy of model. Therefore, many optimization methods have been proposed to reduce the overall privacy cost, and aim to seek a tradeoff between privacy and utility. In this paper, we propose an approach based on the cluster technology to get a tighter clipping bound for differential privacy deep learning model. In addition, we quantify the clipping bound with an objective function of standard deviation and prove our scheme in an analytically way. A large number of experiments setting on real-datasets demonstrate that our adaptive clipping bound method is better than the previous method which sets the clipping bound constantly.
Zhou Tan, Xianxian Li
TrustCom3
2020 Differential Privacy Preservation in Interpretable Feedforward-Designed Convolutional Neural Networks
abstract
Feedforward-designed convolutional neural network (FF-CNN) is an interpretable network. The parameter training of the model does not require backpropagation (BP) and optimization algorithms (SGD). The entire network is based on the statistical data output by the previous layer, and the parameters of the current layer are obtained through one-pass manner. Since the network complexity under the FF design is lower than the BP algorithm, FF-CNN has better utility than the BP training method in the directions of semi-supervised learning, ensemble learning, and continuous subspace learning. However, the FF-CNN training process or model release will cause the privacy of training data to be leaked. In this paper, we analyze and verify that the attacker can obtain the private information of the original training data after mastering the training parameters of FF-CNN and the partial output responses. Therefore, the privacy protection of training data is imperative. However, due to the particularity of the FF-CNN training method, the existing deep learning privacy protection technology is not applicable. So we proposed an algorithm called differential privacy subspace approximation with adjusted bias (DPSaab) to protect the training data in FF-CNN. According to the different contribution of the model filters to the output response, we design the privacy budget allocation according to the ratio of the eigenvalues and allocate a larger privacy budget to the filter with a large contribution, and vice versa. Extensive experiments on MNIST, Fashion-MNIST, and CIFAR-10 datasets show that DPSaab algorithm has better utility than existing privacy protection technologies.
Zhou Tan, Xianxian Li
TrustCom3
2014 CSF protein dynamic driver network: At the crossroads of brain tumorigenesis
abstract
To get a better understanding of the ongoing in situ environmental changes preceding the brain tumorigenesis, we assessed cerebrospinal fluid (CSF) proteome profile changes in a glioma rat model in which brain tumor invariably develop after a single in utero exposure to the neurocarcinogen ethylnitrosourea (ENU). Computationally, the CSF proteome profile dynamics during the tumorigenesis can be modeled as non-smooth or even abrupt state changes. Such brain tumor environment transition analysis, correlating the CSF composition changes with the development of early cellular hyperplasia, can reveal the pathogenesis process at network level during a time before the image detection of the tumors. In this controlled rat model study, matched ENU and salineexposed rats' CSF proteomics changes were quantified at approximately 30, 60, 90, 120, 150 days of age (P30, P60, P90, P120, P150). We applied our transition-based network entropy (TNE) method to compute the CSF proteome changes in the ENU rat model and test the hypothesis of the critical transition state prior to impending hyperplasia. Our analysis identified a dynamic driver network (DDN) of CSF proteins related with the emerging tumorigenesis progressing from the non-hyperplasia state. The DDN associated leading network CSF proteins can allow the early detection of such dynamics before the catastrophic shift to the clear clinical landmarks in gliomas. An improved understanding of the critical transition state (P60) during the brain tumor progression can provide the scientific groundwork to device novel therapeutics preventing tumor formation.
Changlin Fu, Zhou Tan, Rui Liu 0009, Shiying Hao, Pei Chen 0004, Taichang Jang, Milton Merchant, John C. Whitin, Oxford Wang, Minyi Guo, Harvey J. Cohen, Lawrence Recht, Xuefeng Bruce Ling
BIBM2