Tianchong Gao

dblp:195/7423 · DBLP profile ↗
← Back
24ranked-venue papers
15as first author
11since 2021 · last 2025
0000-0001-6620-7707ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 13 · 8 first-author · 3 since 2021Security and privacy · 5 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Affinity Backdoor Attacks in Point Clouds: A Novel Method Resilient to Corruption
abstract
As three-dimensional (3D) point cloud technology has advanced, the security concerns that surround point cloud classification models have garnered increasing attention. Attackers poison the training dataset of a model to mislead model classification, which is known as a backdoor attack. Considering the uncertainty in environmental factors and point cloud sampling equipment, point cloud data may be subject to various types of corruption. While some existing classification models, e.g., PointNet and PointNet++, include corruption invariance in their designs, backdoor triggers are more vulnerable to corruption because of their small size. When corrupted, backdoor samples are more likely to be misclassified into their original categories than are clean samples. The reason is that the backdoor samples, which manipulate the model, are closer to the decision boundary than the clean samples are. To mitigate the detrimental effects of sample feature deviation, this paper proposes a novel backdoor attack method that is robust to corruption. We introduce the concept of affinity based on the high-level idea that the affinity category can facilitate the shift of sample features when corrupted. Afterward, we apply the adversarial attack method to distort the decision boundary to generate backdoor samples. The experimental results demonstrate that the proposed method achieves a high attack success rate and exhibits superior robustness against corruption compared with previous backdoor attack methods.
Tianchong Gao, Yongming Pan
IEEE Trans. Inf. Forensics Secur.1
2025 Vaccination Against Backdoor Attacks on Federated Learning Systems
Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao, Ryan Hosler
IEEE Trans. Syst. Man Cybern. Syst.4
2024 Subjective Logic-based Decentralized Federated Learning for Non-IID Data
abstract
Existing Federated Learning (FL) methods are highly influenced by the training data distribution. In the single global model FL systems, users with highly non-IID data do not improve the global model, and neither does the global model work well on their local data distribution. Even with the clustering-based FL approaches, not all participants get clustered adequately enough for the models to fulfill their local demands. In this work, we design a modified subjective logic-based FL system utilizing the distribution-based similarity among users. Each participant has complete control over their own aggregated model, with handpicked contributions from other participants. The existing clustered model only satisfies a subset of clients, while our individual aggregated models satisfy all the clients. We design a decentralized FL approach, which functions without a trusted central server; the communication and computation overhead is distributed among the clients. We also develop a layer-wise secret-sharing scheme to amplify privacy. We experimentally show that our approach improves the performance of each participant’s aggregated model on their local distribution over the existing single global model and clustering-based approach.
Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao
ARES4
2024 Graph Representation Learning on Novel Feature Based Graphs for Network Intrusion Detection
abstract
Network Intrusions are an ever present threat in the modern age of instant transmission of data over the cyberspace. Ideally, an effective cybersecurity mechanism will detect an attack before it affects a given network. Hence, organizations utilize Network Intrusion Detection Systems (NIDS) to monitor incoming network traffic for all potential misuses. For this research, we present a novel method for aggregating network traffic into a graph for representation learning capable of outperforming existing NIDS in literature. We apply and validate our methods on numerous publically available network flow datasets for demonstrable and concrete performance evaluation.
Ryan Hosler, Agnideven Palanisamy Sundar, Xukai Zou, Feng Li 0001, Tianchong Gao
GLOBECOM5
2024 Toward Multimodal Vertical Federated Learning: A Traffic Analysis Case Study
abstract
Federated Learning (FL) is an emerging subclass of Artificial Intelligence that decentralizes the learning process. Unlike the well-studied Horizontal Federated Learning (HFL), which requires the feature space of all participants to be the same, the newly emerging Vertical Federated Learning (VFL) allows participants to hold different features, provided the sample space is the same. This unique aspect enables VFL to incorporate features from different data modalities, a capability that has not yet been sufficiently explored. Currently, VFL researchers adapt datasets originally used for HFL by splitting the data vertically, whether it is text, tabular, or image data. In this paper, we extend the application of VFL to multimodal datasets, specifically in the field of Intelligent Transportation. We build models by combining local models from participants holding CCTV image datasets and Traffic flow tabular datasets. Due to the absence of suitable existing datasets, we introduce a new dataset, the INDOT traffic dataset, which also supports sequential training across time and distance. Our experiments demonstrate the efficiency of VFL in the multimodal traffic analysis scenario and aim to expand the scope of VFL research.
Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao
ICCCN4
2024 Federated learning backdoor attack detection with persistence diagram
Zihan Ma 0008, Tianchong Gao
Comput. Secur.2
2024 Graph classification using high-difference-frequency subgraph embedding
Tianchong Gao
Neurocomputing1
2024 Generating-Based Attacks to Online Social Networks
abstract
Online social network (OSN) privacy leakage problem addresses more and more users’ concerns. Studying the problem from attackers’ view could tell us how to prevent further data leakage. Currently, attackers mainly focus on mapping identities between their background knowledge and the published data to collect useful information. However, it becomes difficult to find the global optimal mapping strategy because of the complexity of the OSN data. This article proposes a novel generating-based attack on OSN data, no longer restricted to mapping-based information collection. Generally, the proposed scheme learns OSN properties from the attackers’ background knowledge and employs the knowledge to fill the unknown area in the published data. The proposed scheme employs a generative adversarial network to ensure the similarity between the generated graph and the published data. The conditional information is also added in the generation process such that the generated graph is restricted to the conditions under attackers’ background knowledge. Experimental results show that the proposed scheme successfully infer private information with real-world OSN datasets.
Tianchong Gao, Yucheng Bian, Feng Li 0001, Agnideven Palanisamy Sundar
IEEE Trans. Comput. Soc. Syst.1
2023 Unsupervised Deep Learning for an Image Based Network Intrusion Detection System
abstract
The most cost-effective method of cybersecurity is prevention. Therefore, organizations and individuals utilize Network Intrusion Detection Systems (NIDS) to inspect network flow for potential intrusions. However, Deep Learning based NIDS still struggle with high false alarm rates and detecting novel and unseen attacks. Therefore, in this paper, we propose a novel NIDS framework based on generating images from feature vectors and applying Unsupervised Deep Learning. For evaluation, we apply this method on four publicly available datasets and have demonstrated an accuracy improvement of up to 8.25 % when compared to Deep Learning models applied to the original feature vectors.
Ryan Hosler, Agnideven Palanisamy Sundar, Xukai Zou, Feng Li 0001, Tianchong Gao
GLOBECOM5
2022 Machine Learning-based Online Social Network Privacy Preservation
abstract
Online data privacy draws more and more concerns. Online Social Network (OSN) service providers employ anonymization mechanisms to preserve private information and data utility. However, these mechanisms mostly focus on the traditional definitions about privacy and utility. Recently, both benign data scientists and attackers utilize machine learning methods to extract information from OSNs. This paper aims to present a novel angle of balancing privacy and utility under machine learning. The proposed scheme perturbs the data that breaks the attackers' learning results and protect the benign third parties' learning results. To preserve both privacy and utility, we propose two different anonymization approaches to solve the multi-objective optimization problem. The first approach combines the two objectives. It utilizes the deep learning model, Generative Adversarial Network (GAN), to sequentially learns the two objectives and generates graphs. The second approach analyzes the differences between the two objects on structures. It utilizes Integrated Gradient (IG) in learning to break attackers' learning results. It structurally rewires edges to preserve third parties' learning results afterwards. The experiment results show that both approaches work well in privacy preservation.
Tianchong Gao, Feng Li 0001
AsiaCCS1
2022 Distributed Swift and Stealthy Backdoor Attack on Federated Learning
abstract
Federated Learning (FL) provides enhanced privacy over traditional centralized learning; unfortunately, it is also as susceptible to backdoor attacks, just like its centralized counterpart. Conventionally, in data poisoning-based backdoor attacks, all the malicious participants overlay the same single trigger pattern on a subset of their private data during local training. The same trigger is used to induce the backdoor in the otherwise benign global model at inference time. Such single trigger attacks can be detected and removed with relative ease as they undermine the distributed nature of FL. In this work, we focus on building an attack scheme where each batch of malicious clients uses sizably discrete local triggers during local training, with the ability to invoke the attack with a single small inference trigger during the global model testing. The larger size of the trigger pattern ensures prolonged attack longevity even after the termination of the attack. We conduct extensive experiments to show that our approach is far faster, stealthier, and more effective than the centralized trigger approach. The stealthiness of our work is explained using the DeepLIFT visual feature interpretation method.
Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao
NAS4
2020 Deep Dynamic Clustering of Spam Reviewers using Behavior-Anomaly-based Graph Embedding
abstract
Online reviews have become an increasingly important factor in the purchase decision of a customer. However, many spammers write deceptive reviews to alter the credibility of a product/service. Often than not, these spammers exhibit group behavior, which can be exploited to differentiate them from authentic reviewers. Such behaviors are found in spammers working together as well as with crowdsourced review manipulators. The existing graph-based spammer detection approaches do not capture the dynamic and nonlinear relationship between the users. This paper aims to address this issue by introducing a method to use a deep structure embedding approach that preserves highly nonlinear structural information along with the dynamic aspects of user reviews to identify and cluster the spam users. It is worth mentioning that, in the experiment with real datasets, our method captures about 92% of all spam reviewers using an unsupervised learning approach.
Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Tianchong Gao
GLOBECOM4
2020 Multi-Armed-Bandit-based Shilling Attack on Collaborative Filtering Recommender Systems
abstract
Collaborative Filtering (CF) is a popular recommendation system that makes recommendations based on similar users’ preferences. Though it is widely used, CF is prone to Shilling/Profile Injection attacks, where fake profiles are injected into the CF system to alter its outcome. Most of the existing shilling attacks do not work on online systems and cannot be efficiently implemented in real-world applications. In this paper, we introduce an efficient Multi-Armed-Bandit-based reinforcement learning method to practically execute online shilling attacks. Our method works by reducing the uncertainty associated with the item selection process and finds the most optimal items to enhance attack reach. Such practical online attacks open new avenues for research in building more robust recommender systems. We treat the recommender system as a black box, making our method effective irrespective of the type of CF used. Finally, we also experimentally test our approach against popular state-of-the-art shilling attacks.
Agnideven Palanisamy Sundar, Feng Li 0001, Xukai Zou, Qin Hu 0001, Tianchong Gao
MASS5
2019 Sharing Social Networks Using a Novel Differentially Private Graph Model
abstract
Online social networks (OSNs) often contain sensitive information about individuals. Therefore, anonymizing social network data before releasing it becomes an important issue. Recent research introduces several graph abstraction models to extract graph features and add sufficient noise to achieve differential privacy.In this paper, we design and analyze a comprehensive differentially private graph model that combines the dK-1, dK-2, and dK-3 series together. The dK-1 series stores the degree frequency, the dK-2 series adds the joint degree frequency, and the dK-3 series contains the linking information between edges. In our scheme, low dimensional data makes the regeneration process more executable and effective, while high dimensional data preserves additional utility of the graph. As the higher dimensional model is more sensitive to the noise, we carefully design the executing sequence. The final released graph increases the graph utility under differential privacy.
Tianchong Gao, Feng Li 0001
CCNC1
2019 Efficient Content Delivery via Interest Queueing
abstract
Content sharing is an approach to relieve the congestion of cellular networks with alternative communication technologies such as the Wi-Fi and bluetooth. Through a Content Delivery Network (CDN), only a small portion of users need to download the data directly. Other users obtain packets from these users through short-range communications. However, the uncertainty of movement of mobile users challenges the effectiveness of CDNs. Unlike previous CDN solutions, in this paper, we present a novel scheme that studies the probabilistic meeting of users. When the accessibility to the cellular network is limited, we apply the queueing theory to guide the downloading or waiting strategies of users. In this system, the users who hold the content become seeds in the CDN and benefit their neighbors. Therefore we also consider the seed growing performance in the strategy. The purpose of our scheme is to let every user efficiently obtain their target content with restricted cellular data. The evaluation results show that our scheme gains significant satisfaction throughput improvements compared to the performance of basic downloading strategies.
Tianchong Gao, Feng Li 0001
ICC1
2019 De-Anonymization of Dynamic Online Social Networks via Persistent Structures
abstract
Service providers of Online Social Networks (OSNs) periodically publish anonymized OSN data, which creates an opportunity for adversaries to de-anonymize the data and identify target users. Most commonly, these adversaries use de-anonymization mechanisms that focus on static graphs. Some mechanisms separate dynamic OSN data into slices of static graphs, in order to apply a traditional de-anonymization attack. However, these mechanisms do not account for the evolution of OSNs, which limits their attack performance. In this paper, we provide a novel angle, persistent homology, to capture the evolution of OSNs. Persistent homology barcodes show the birth time and death time of holes, i.e., polygons, in OSN graphs. After extracting the evolution of holes, we apply a two-phase de-anonymization attack. First, holes are mapped together according to the similarity of birth/death time. Second, already mapped holes are converted into super nodes and we view them as seed nodes. We then grow the mapping based on these seed nodes. Our de-anonymization mechanism is extremely compatible to the adversaries who suffer latency in relationship collection, which is very similar to real-world cases.
Tianchong Gao, Feng Li 0001
ICC1
2019 PHDP: Preserving Persistent Homology in Differentially Private Graph Publications
abstract
Online social networks (OSNs) routinely share and analyze user data. This requires protection of sensitive user information. Researchers have proposed several techniques to anonymize the data of OSNs. Some differential-privacy techniques claim to preserve graph utility under certain graph metrics, as well as guarantee strict privacy. However, each graph utility metric reveals the whole graph in specific aspects.We employ persistent homology to give a comprehensive description of the graph utility in OSNs. This paper proposes a novel anonymization scheme, called PHDP, which preserves persistent homology and satisfies differential privacy. To strengthen privacy protection, we add exponential noise to the adjacency matrix of the network and find the number of adding/deleting edges. To maintain persistent homology, we collect edges along persistent structures and avoid perturbation on these edges. Our regeneration algorithms balance persistent homology with differential privacy, publishing an anonymized graph with a guarantee of both. Evaluation result show that the PHDP-anonymized graph achieves high graph utility, both in graph metrics and application metrics.
Tianchong Gao, Feng Li 0001
INFOCOM1
2019 Privacy-Preserving Sketching for Online Social Network Data Publication
abstract
Releasing private data can cause panic to both Online Social Network (OSN) users and service providers. Therefore, anonymization mechanisms are proposed to protect data before sharing it. However, some of these mechanisms set unrealistic privacy demands but cannot defend against real-world de-anonymization attacks.In this paper, we introduce an anonymization algorithm based on All-Distance Sketch (ADS). Sketching can significantly limit attackers’ confidence, as well as provide accurate estimation about shortest path length and other utility metrics. Because sketching removes large amounts of edges, it is invulnerable to seed-based and subgraph-based de-anonymization attacks. However, existing sketching algorithms do not add dummy edges and paths. Adversaries have low false positive in extracting linking information, which challenges the privacy performance. We propose the novel bottom-(l, k) sketch to defend against these advanced attacks. We develop a scheme to add and delete enough edges to satisfy our privacy demand. The experiment results show that our published graphs are closely matched with the original graphs under some metrics, preserving utility, while 80% edges are removed, ensuring privacy.
Tianchong Gao, Feng Li 0001
SECON1
2019 Android Malware Detection via Graphlet Sampling
abstract
Android systems are widely used in mobile & wireless distributed systems. In the near future, Android is believed to dominate the mobile distributed environment. However, with the popularity of Android-based smartphones/tablets comes the rampancy of Android-based malware. In this paper, we propose a novel topological signature of Android apps based on the function call graphs (FCGs) extracted from their Android App PacKages (APKs). Specifically, by leveraging recent advances on graphlet mining, the proposed method fully captures the invocator-invocatee relationship at local neighborhoods in an FCG without exponentially inflating the state space. Using real benign app and malware samples, we demonstrate that our method, App topologiCal signature through graphleT Sampling (ACTS), can detect malware and identify malware families robustly and efficiently. More importantly, we demonstrate that, without augmenting the FCG with any semantic features such as bytecode-based vertex typing, local topological information captured by ACTS alone can achieve a high malware detection accuracy. Since ACTS only uses structural features, which are orthogonal to semantic features, it is expected that combining them would give a greater improvement in malware detection accuracy than combining non-orthogonal semantic features.
Tianchong Gao, Wei Peng 0007, Devkishen Sisodia, Tanay Kumar Saha, Feng Li 0001, Mohammad Al Hasan
IEEE Trans. Mob. Comput.1
2018 Studying the utility preservation in social network anonymization via persistent homology
Tianchong Gao, Feng Li 0001
Comput. Secur.1
2018 Local Differential Privately Anonymizing Online Social Networks Under HRG-Based Model
abstract
Following the trend of online social networks (OSNs) data sharing and publishing, users raise serious concerns on OSN privacy. Differential privacy is a mechanism to anonymize sensitive data. It employs graph abstraction models, such as the hierarchical random graph (HRG) model, to extract graph features and then add sufficient noise. However, the noise amount, determined by the sensitivity, is usually proportional to the size of the whole network. Therefore, achieving global differential privacy may harm the utility of releasing graphs. In this paper, we define the notion of group-based local differential privacy. In particular, by resolving the network into 1-neighborhood graphs and applying HRG-based methods, our scheme preserves differential privacy and reduces the noise scale on the local graphs. By deploying the grouping algorithm, our scheme abandons the attempt to anonymize every relationship to be ordinary, but we focus on the similarities in HRG models. In the final released graph, each individual user in one group is not distinguishable, which greatly enhances the OSN privacy. We experimentally evaluate our approach on three real-world OSNs. It produces synthetic graphs that are more closely matched with the originals compared with the existing differential-privacy results.
Tianchong Gao, Feng Li 0001, Yu Chen 0002, Xukai Zou
IEEE Trans. Comput. Soc. Syst.1
2017 Preserving Graph Utility in Anonymized Social Networks? A Study on the Persistent Homology
abstract
Following the trend of privacy preserving online social network publishing, various anonymization mechanisms have been designed and employed. Many differential privacybased mechanisms claim that they can preserve the utility as well as guarantee the privacy. Their utility analysis are always based on some specifically chosen metrics.This paper aims to find a novel angle that describing the network in multiple scales. Persistent homology is such a high level metric that it reveals the parameterized topological features with various scales and it is applicable for read-world applications. In this paper, four differential privacy mechanisms employing different models are analyzed under the traditional graph metrics and the persistent homology. The evaluation results demonstrate that all algorithms can partially or conditionally preserve certain traditional graph utilities, but none of them are suitable for all metrics. Furthermore, none of the existing mechanisms can fully preserve the persistent homology, especially in high dimensions, which implies that the true graph utility is lost.
Tianchong Gao, Feng Li 0001
MASS1
2017 Using Persistent Homology to Represent Online Social Network Graphs
abstract
Online Social Networks (OSNs) are simple, unweighted graphs used to store information in the context of social media and emails. Accurately representing the connectivity and features of these graphs is important in applications of graph utility and differential privacy. Current methods of describing these network graphs use graph metrics such as the shortest-path betweenness centrality, clustering coefficient, and degree distribution. Although these metrics are sufficient in providing information about a particular aspect of network graphs, they fail to give a multi-faceted snapshot of an OSN. Persistent homology provides a novel method for a comprehensive visual representation of the information stored in network graphs. By translating a network graph to a persistent homology barcode format, the correlation in key features between the figures will be observed against various utility metrics. This paper evaluates the persistent homology barcodes of OSNs across social media platforms and provides a means of analyzing network graphs without revealing sensitive information.
Tianchong Gao, Feng Li 0001
MASS1
2017 Preserving Local Differential Privacy in Online Social Networks
Tianchong Gao, Feng Li 0001, Yu Chen 0002, Xukai Zou
WASA1