Tian Wen

dblp:164/9587 · DBLP profile ↗
← Back
8ranked-venue papers
1as first author
8since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Representation Decorrelation Guided Robust Image Retrieval Against Label Noise
Xuefeng Jiang 0001, Tian Wen, Lvhua Wu, Yuwei Wang 0003, Min Liu 0001
IEEE Trans. Big Data2
2026 Representation Optimal Matching for Federated Learning With Noisy Labels in Remote Sensing
abstract
Remote sensing (RS) applications increasingly operate over distributed infrastructures that integrate space-airground- sea resources with edge intelligence, yet remains challenging to centralize due to geographic dispersion, cross-institution barriers and privacy regulations. Federated learning (FL), a promising privacy-preserving distributed learning paradigm, has garnered wide attention. However, the practical application of FL for RS encounters the issue of label noise stemming from inevitable annotation errors. In this work, we pioneer an early investigation of label noise in distributed RS tasks. We introduce the Federated Representation Optimal Matching (FedROM) framework, which guides robust representation alignment in the presence of noisy labels without requiring auxiliary data or transmitting extra sensitive information. Specifically, FedROM focuses on the robust local updating process, where clients first identify underlying noisy samples from the perspectives of both per-sample loss value and latent representation space. Subsequently, inspired by the optimal transport technique, we adaptively align the latent representations of identified noisy samples with their corresponding closest class centroids with the least representation matching distance, where class centroids are averaged by the latent representations of other relatively clean samples. This reduces the misleading effects caused by noisy samples and guides the model to capture more robust semantic features in the latent representation space. Theoretical analysis proves the robustness and convergence of FedROM. Extensive experiments on two real-world distributed RS datasets covering multi-source domains and varying label noise rates demonstrate the robustness of FedROM against eighteen baseline methods. Meanwhile, FedROM also surpasses its counterparts in conditions of no label noise, narrowing the gap with the centralized training. To facilitate related communities, our code is open-sourced athttps://github.com/Sprinter1999/ROM.
Xuefeng Jiang 0001, Tian Wen, Jinliang Yuan, Huashuo Liu, Lvhua Wu, Yuwei Wang 0003, Min Liu 0001
IEEE Trans. Mob. Comput.2
2026 Recursive Offloading for LLM Serving in Multi-Tier Networks
abstract
Heterogeneous device-edge-cloud computing infrastructures have become the backbone of modern telecommunication operators and Wide Area Networks (WANs), providing multi-tier computational support for emerging intelligent applications. With the rapid proliferation of Large Language Model (LLM) services, efficiently coordinating inference tasks and reducing communication burden within these multi-tier network architectures becomes a critical deployment challenge. Current LLM serving paradigms exhibit significant limitations: on-device deployment restricts service to lightweight LLMs due to hardware constraints, while cloud-centric deployment encounters resource congestion and considerable prompt communication overhead during peak periods. Model-cascading inference, though better suited for multi-tier networks, depends on static, manually-tuned thresholds that cannot adapt to dynamic network conditions or varying task complexities. To address these challenges, we propose RecServe, a recursive offloading framework tailored for LLM serving in multi-tier networks. RecServe introduces a task-specific hierarchical confidence evaluation mechanism that guides offloading decisions based on inferred task complexity in progressively scaled LLMs across device, edge, and cloud tiers. To further enable intelligent task routing across tiers, RecServe employs a sliding-window-based dynamic offloading strategy with quantile interpolation, enabling real-time tracking of historical confidence distributions and adaptive offloading threshold adjustments. This design allows inference tasks to be recursively offloaded to higher tiers only when necessary, optimizing heterogeneous resource utilization while reducing cross-tier communication with little compromise on service quality. Theoretical analysis provides distinct conditions under which RecServe is expected to achieve reduced communication burden and computational costs. Experiments on eight datasets demonstrate that RecServe outperforms CasServe in both service quality and communication efficiency, and reduces the communication burden by over 50% compared to centralized cloud-based serving.
Yuwei Wang 0003, Min Liu 0001, Bo Gao 0006, Jinda Lu, Zheming Yang, Tian Wen
IEEE Trans. Mob. Comput.9
2025 Exploring Subtle Manipulation Vulnerabilities in Federated Distillation
abstract
Federated Distillation (FD) offers significant advantages over conventional Federated Learning (FL) by transmitting model outputs (logits) instead of model parameters, reducing communication costs and supporting heterogeneous model architectures. However, FD systems remain vulnerable to poisoning attacks, where local logits are manipulated to corrupt the global aggregation process. The current defense mechanism, represented by SVAFD, attempts to counter malicious updates using cosine similarity. However, we find that such a method fails to detect subtle perturbations and scale variations in logits. To expose these weaknesses, we propose the Federated Distillation Similarity-Based Attack (FDSA), a three-stage attack comprising peak shuffle, mean regression, and dynamic scaling. FDSA subtly manipulates client logits to evade detection while significantly degrading the robustness of server-side aggregation. By altering class priorities, increasing logit entropy, and dynamically adjusting scaling factors, FDSA maintains high cosine similarity to mask its malicious intent. Experiments on FMNIST and SVHN show that FDSA surpasses five state-of-the-art baseline attacks in reducing model accuracy, with ablation studies confirming its robustness across diverse settings. The source code of this paper is available at https://github.com/SHOWY118/FDSA.
Peiyan Chen, Changsheng Wan, Tian Wen
TrustCom4
2025 Peak-controlled logits poisoning attack in federated distillation
abstract
Federated Distillation (FD) is an innovative distributed machine learning paradigm that enables efficient and flexible cross-device knowledge transfer through knowledge distillation, without the need to upload large-scale model parameters to a central server. Although FD has attracted increasing attention in recent years, its security aspects remain relatively underexplored. Existing attack methods targeting traditional federated learning mainly focus on the transmission of model parameters and gradients, while attacks specifically designed for the unnormalized outputs (logits) in the emerging FD paradigm are still lacking. To fill this research gap and contribute to the enhancement of FD’s security, we previously proposed the Federated Distillation Logits Attack (FDLA), which manipulates the logits transmitted during communication to mislead and degrade the performance of client models. However, FDLA has limitations in controlling its impact on participants with different roles or identities and lacks a systematic investigation into the effects of malicious interventions at various stages of knowledge transfer. To overcome these limitations, we propose a more advanced and controllable logits poisoning method—Peak-Controlled Federated Distillation Logits Attack (PCFDLA). PCFDLA enhances the effectiveness of FDLA by precisely controlling the peak values of logits to adjust the intensity of the attack. This method generates highly misleading perturbations that achieve stronger attack performance while maintaining a similar level of stealthiness to FDLA when detection is based on differences in model parameters. Moreover, we introduce a novel evaluation metric to more comprehensively assess the performance of such attacks. Experimental results show that PCFDLA significantly increases the destructive impact on victim models while maintaining high stealth. It consistently achieves superior performance across multiple datasets, highlighting its potential threat to the security of federated distillation systems.
Yuhan Tang, Bo Gao 0006, Tian Wen, Yuwei Wang 0003
Discov. Comput.4
2024 Logits Poisoning Attack in Federated Distillation
Yuhan Tang, Bo Gao 0006, Tian Wen, Yuwei Wang 0003
KSEM (3)4
2024 RTIFed: A Reputation based Triple-step Incentive mechanism for energy-aware Federated learning over battery-constricted devices
Tian Wen, Huixin Wu, Danxin Wang, Weishan Zhang, Yuwei Wang 0003, Shaohua Cao
Comput. Networks1
2024 FedQMIX: Communication-efficient federated learning via multi-agent reinforcement learning
abstract
Since the data samples on client devices are usually non-independent and non-identically distributed (non-IID), this will challenge the convergence of federated learning (FL) and reduce communication efficiency. This paper proposes FedQMIX, a node selection algorithm based on multi-agent reinforcement learning(MARL), to address these challenges. Firstly, we observe a connection between model weights and data distribution, and a clustering algorithm can group clients with similar data distribution into the same cluster. Secondly, we propose a QMIX-based mechanism that learns to select devices from clustering results in each communication round to maximize the reward, penalizing the use of more communication rounds and thereby improving the communication efficiency of FL. Finally, experiments show that FedQMIX can reduce the number of communication rounds by 11% and 30% on the MNIST and CIFAR-10 datasets, respectively, compared to the baseline algorithm(Favor).
Shaohua Cao, Tian Wen, Quancheng Zheng, Weishan Zhang, Danyang Zheng 0001
High Confid. Comput.3