VLDB 2026 Research / reviewers in the wild / expert
Hengrun Zhang 0001
dblp:161/8209-1
· DBLP profile ↗
7ranked-venue papers
3as first author
5since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 2 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Guard Against Infringement: An Anti-Distillation Federated Learning Watermarking FrameworkabstractTo balance the gap between data privacy and the need for data fusion, federated learning (FL) has been proposed and has become a hot-point method to address data silos and privacy issues. However, AI models exchanged in FL face risks such as illegal copying, redistribution and/or free-riding. To address these risks, FL watermarking frameworks have been proposed to assert and protect the intellectual property (IP) of models, which are resistant to popular watermark removal attacks. Knowledge distillation has recently been of significant contribution to FL convergence performance optimization but brings vulnerability to FL watermark robustness with distillation attack, which enables attackers to maintain high performance on the main task while erasing the watermarks. In response, we introduce a new FL watermarking framework called FedRW, which focuses specifically on anti-distillation. FedRW employs model regularization techniques to bind the main task parameters with the watermark task parameters, thereby enhancing resistance to distillation attacks. Extensive experiments confirm the threat of distillation attacks in FL and demonstrate that FedRW is more resistant to distillation compared to existing FL watermarking frameworks. Xiao Yi, Hengrun Zhang 0001, Huiqun Yu, Guisheng Fan, Haojin Zhu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | VDSV: Client Selection in Federated Learning Based on Value Density and Secondary VerificationabstractClient selection has been widely considered in Federated Learning (FL) to reduce communication overhead while ensuring proper convergence performance. Due to data heterogeneity in FL, a representative subset of participants should take into account both intra-and inter-client diversity. While existing works usually emphasize on one of them, this paper proposes a VDSV (client selection based on Value Density and Secondary Verification) framework, which optimizes the client selection strategy from both sides. Therein, intra-and inter-client diversity are respectively measured based on a designed client data score as well as gradient distance and direction. Afterwards, a client selection model is established based on a proposed metric, called client value density. Besides, a secondary validation method is developed to dynamically tweak the current client selection and model aggregation strategies. The general idea of the above design is based on the theoretical convergence analysis and the observation that the client contribution to the global model can get changed throughout the learning process. The experimental results demonstrate that VDSV can achieve higher convergence rates and ensure comparable model performance. In specific, our method can reduce the communication rounds by an average of 37.88%, which saves noticeable communication overhead. Weichao Ding, Qi Min, Fei Luo 0002, Hengrun Zhang 0001 |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2023 | Federated Graph Neural Network for Fast Anomaly Detection in Controller Area NetworksabstractDue to the lack of CAN frame encryption and authentication, CAN bus is vulnerable to various attacks, which can in general be divided into message injection, suspension, and falsification. Existing CAN bus anomaly detection mechanisms either can only detect one or two of these attacks, or require numerous CAN messages during predictions, which can hardly realize real-time performance. In this paper, we propose a CAN bus anomaly detection system that can detect all these attacks simultaneously in as short as 3 milliseconds (ms) based on Graph Neural Network (GNN). This work generates directed attributed graphs based on CAN message streams in given message intervals. Node attributes denote data contents in CAN messages while each edge attribute represents the frequency of a typical CAN ID pair in the given interval. Afterwards, a GNN is trained based on generated CAN message graphs. Considering highly imbalanced training data, a two-stage classifier cascade is developed in this paper, which is composed of a one-class classifier for anomaly detection and a multi-class classifier for attack classification. An openmax layer is further introduced to the multi-class classifier to tackle new anomalies from unknown classes. To take advantage of crowdsourcing while protecting user data privacy, we adopt federated learning to train a universal model that covers different driving scenarios and vehicle states. Extensive experiment results show the effectiveness and efficiency of our methodology. Hengrun Zhang 0001, Kai Zeng 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Communication-Aware Secret Share Placement in Hierarchical Edge ComputingabstractSecret sharing (SS) and secure multiparty computation (MPC) are now widely considered for privacy-preserving data processing. However, related applications can suffer from large transmission overhead. In this article, we propose a communication-aware secret share placement strategy to optimize communication overhead by minimizing transmission hop counts in a hierarchical edge computing architecture. Meanwhile, relevant privacy constraints in SS can still be guaranteed. We show that the constructed optimization problem is NP-hard, and efficient heuristic algorithms can be applied to find suboptimal solutions. With this consideration, we first evaluate two traditional heuristics, i.e., the genetic algorithm (GA) and particle swarm optimization (PSO). Besides, we introduce two basic heuristics, i.e., top-down and bottom-up heuristic, which can outperform GA and PSO in certain cases. Finally, we propose an algorithm, called bottom-up top-down (BUTD) heuristic, which can outperform all of the above four heuristics when communication among different shares of the same secret is comparable to that among different secrets. Comprehensive experimental results demonstrate the advantage of the proposed algorithms. Hengrun Zhang 0001, Kai Zeng 0001 |
IEEE Internet Things J. | 1 |
| 2021 | Federated Continuous Learning With Broad Network ArchitectureabstractFederated learning (FL) is a machine-learning setting, where multiple clients collaboratively train a model under the coordination of a central server. The clients' raw data are locally stored, and each client only uploads the trained weight to the server, which can mitigate the privacy risks from the centralized machine learning. However, most of the existing FL models focus on one-time learning without consideration for continuous learning. Continuous learning supports learning from streaming data continuously, so it can adapt to environmental changes and provide better real-time performance. In this article, we present a federated continuous learning scheme based on broad learning (FCL-BL) to support efficient and accurate federated continuous learning (FCL). In FCL-BL, we propose a weighted processing strategy to solve the catastrophic forgetting problem, so FCL-BL can handle continuous learning. Then, we develop a local-independent training solution to support fast and accurate training in FCL-BL. The proposed solution enables us to avoid using a time-consuming synchronous approach while addressing the inaccurate-training issue rooted in the previous asynchronous approach. Moreover, we introduce a batch-asynchronous approach and broad learning (BL) technique to guarantee the high efficiency of FCL-BL. Specifically, the batch-asynchronous approach reduces the number of client-server interaction rounds, and the BL technique supports incremental learning without retraining when learning newly produced data. Finally, theoretical analysis and experimental results further illustrate that FCL-BL is superior to the existing FL schemes in terms of efficiency and accuracy in FCL. Junqing Le, Nankun Mu, Hengrun Zhang 0001, Kai Zeng 0001, Xiaofeng Liao 0001 |
IEEE Trans. Cybern. | 4 |
| 2019 | Pairwise Markov Chain: A Task Scheduling Strategy for Privacy-Preserving SIFT on EdgeabstractIn this paper, we propose a task scheduling strategy, which can achieve image feature extraction on edge while ensuring privacy. Our task scheduling strategy applies to a fairly popular privacy-preserving Scale-Invariant Feature Transform SIFT scheme, where images to be processed are firstly randomly split into two portions for encryption and transmitted to two different edge nodes for feature extraction. Then, in the edge, our task scheduling strategy will re-assign these two portions to proper edge nodes for processing. During the whole process, two portions of the same image should not be assigned to the same edge node in order to preserve privacy. We show that this privacy constraint can be enforced through constructing a pairwise Markov chain, and carefully designing system states and transition probabilities. We further formulate the whole task scheduling problem as a stochastic latency minimization problem and solve it by converting it into a linear programming problem. Simulation results show that our proposed task scheduling strategy can achieve lower latency than baseline strategies while satisfying the privacy constraint. Hengrun Zhang 0001, Kai Zeng 0001 |
INFOCOM | 1 |
| 2018 | A Survey on Security, Privacy, and Trust in Mobile CrowdsourcingabstractWith the popularity of sensor-rich mobile devices (e.g., smart phones and wearable devices), mobile crowdsourcing (MCS) has emerged as an effective method for data collection and processing. Compared with traditional wireless sensor networking, MCS holds many advantages such as mobility, scalability, cost-efficiency, and human intelligence. However, MCS still faces many challenges with regard to security, privacy, and trust. This paper provides a survey of these challenges and discusses potential solutions. We analyze the characteristics of MCS, identify its security threats, and outline essential requirements on a secure, privacy-preserving, and trustworthy MCS system. Further, we review existing solutions based on these requirements and compare their pros and cons. Finally, we point out open issues and propose some future research directions. Wei Feng 0010, Zheng Yan 0002, Hengrun Zhang 0001, Kai Zeng 0001, Yu Xiao 0001, Y. Thomas Hou 0001 |
IEEE Internet Things J. | 3 |