VLDB 2026 Research / reviewers in the wild / expert
Honglu Jiang
dblp:201/1241
· DBLP profile ↗
17ranked-venue papers
4as first author
15since 2021 · last 2026
0000-0001-6014-0396ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 4 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CHPFL: Clustered adaptive hierarchical federated learning for edge-level personalizationabstractFederated learning faces challenges with non-IID data distributions, often resulting in suboptimal performance for individual clients with the global model. To address this issue, we propose a clustered hierarchical personalized federated learning (CHPFL) framework, which provides edge-level personalization to effectively overcomes non-IID data and alleviates the overfitting in the personalization process. The three-layer framework makes the learning and personalization process more feasible compared to traditional two-layer federated learning, as edge servers typically offer greater computing power and more efficient communication with the cloud server. Specifically, we use the K-Means++ clustering algorithm to group local clients based on their model updates, ensuring that clients with similar data distributions are clustered together and assigned to the same edge server. Each edge server then generates a personalized model by blending the global model with the edge model, which is adaptively updated and optimized through multiple iterations. Additionally, we introduce a novel aggregation rule on the cloud server to produce a global model with improved performance. Experiments on the MNIST, FMNIST, and KMNIST datasets demonstrate that CHPFL effectively overcomes non-IID data distribution and outperforms HPFL, APFL, and FedALA in non-IID settings. Lihua Song, Honglu Jiang, Shuhua Wei |
High Confid. Comput. | 3 |
| 2025 | ADT++: Advanced Adversarial Distributional Training with Class-Wise RobustnessabstractAdversarial training (AT) is widely regarded as a leading defense strategy for improving the robustness of deep learning models against adversarial attacks. However, existing AT methods often rely on a single attack strategy during training, which limits the exploration of the perturbation space and leads to poor generalization robustness against stronger, unseen, or adaptive adversarial attacks. Moreover, most AT approaches overlook class-wise robustness–the observed variation in robustness across different image classes–by focusing solely on average performance over the entire dataset. In this paper, we present Advanced Distributional Training with Class-wise Robustness (ADT++), a novel adversarial training framework that significantly improves generalization robustness against unseen and sophisticated adversarial attacks. Following the standard adversarial training framework, ADT++ is formulated as a minmax optimization problem, where the inner maximization aims to learn the worst-case adversarial distribution around adversarial examples to further explore the perturbation space. The outer minimization seeks to find model parameters that minimize the expected loss of the maximum inner loss. To further improve the generalization robustness, ADT++ leverages the class-wise robustness phenomenon by targeting the most vulnerable image classes with high-loss adversarial attacks to generate more impactful adversarial examples. Extensive evaluations on benchmark datasets and against various AT defense methods and adversarial attacks confirm the effectiveness of ADT++ in improving model robustness against stronger and adaptive attacks. The source code of ADT++ can be found.11https://github.com/LAiSR-SK/ADT2Plus Samer Khamaiseh, Deirdre Jost, Anas M. R. Alsobeh, Abdullah S. Al-Alaj, Honglu Jiang |
DSAA | 5 |
| 2025 | Utility-Enhanced Personalized Privacy Preservation in Hierarchical Federated LearningabstractFederated learning (FL) is a distributed learning framework that allows clients to jointly train a model by uploading parameter updates rather than sharing local data. FL deployed on a client-edge-cloud hierarchical architecture, named Hierarchical Federated Learning (HFL), can accelerate model training and accommodate more clients with reduced communication cost via edge aggregation. Unfortunately, HFL suffers from privacy risks since the submitted parameters from clients are vulnerable to privacy attacks. To address this issue, we propose a novel Differential Privacy (DP) definition tailored for HFL, i.e., Group Local Differential Privacy (GLDP). We design the Sampling-Randomizing-Shuffling (SRS) mechanism to implement GLDP in HFL, where the sampling process is employed to achieve a stronger level of privacy protection with less noise added. By combining the randomized response and the shuffling mechanism, our proposed SRS mechanism can achieve client-level personalization within$\rho _{k}$-GLDP for privacy preservation while balancing model performance and privacy protection in HFL. Privacy analysis and convergence analysis are conducted to provide theoretical performance guarantees. Experimental results based on real-world datasets verify the effectiveness of SRS. Jianan Chen 0009, Honglu Jiang, Qin Hu 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2024 | Curse to Blessing: Leveraging Model Inversion Attacks to Detect Backdoor Attacks in Federated LearningabstractFederated Learning (FL) offers significant advancements in user/data privacy, learning quality, model efficiency, scalability, and network communication latency. However, it faces notable security challenges, particularly with the emergence of backdoor attacks. The distributed nature of FL complicates the development of backdoor-resistant systems compared to traditional machine learning environments. In this paper, we propose a novel approach to turn the perceived curse of model inversion (MI) attacks into a blessing, using them as a tool for detecting backdoor attacks in FL environments. Leveraging MI outputs, we propose a K-means-based feature extraction and Isolation-Forest-based anomaly detection algorithm to analyze behavior and detect abnormal learning performance, thereby identifying backdoor attacks. Experimental results demonstrate the effectiveness and superior performance of our method in detecting backdoor attacks within FL systems. Zhaowen Chen, Caleb Mostyn, Honglu Jiang, Xianglong Feng |
IPCCC | 4 |
| 2024 | Byzantine-Robust Federated Learning Based on Blockchain
Lihua Song, Chenying Cai, Shuhua Wei, Rochishnu Banerjee, Xianglong Feng, Honglu Jiang |
WASA (1) | 6 |
| 2023 | Adaptive Edge-Level Personalization on Hierarchical Federated LearningabstractFederated learning faces the challenge of non-IID data distribution while the global model doesn’t achieve well for individual clients. To address this challenge, we propose hierarchical personalized federated learning (HPFL) and achieve edge-level personalization, which overcomes non-IID data distribution and alleviates the overfitting of the pesonalization process. The three-layer framework makes the learning and personalization process more feasible than traditional two-layer federated learning since real-world edge servers usually have sufficient computing power than local clients and have efficient communication with the cloud server. In our approach, the personalized model on each edge server is generated by mixing the global model and edge model, which can be updated based on adaptive mixing parameter and optimized after multiple iterations. Experiments on MNIST and FMNIST show that the proposed HPFL overcomes non-IID data distribution, achieves comparable performance to traditional two-layer personalization APFL and outperforms HierFAVG under non-IID data setting. Lihua Song, Honglu Jiang, Shuhua Wei |
IPCCC | 3 |
| 2023 | Applications of Differential Privacy in Social Network Analysis: A SurveyabstractDifferential privacy provides strong privacy preservation guarantee in information sharing. As social network analysis has been enjoying many applications, it opens a new arena for applications of differential privacy. This article presents a comprehensive survey connecting the basic principles of differential privacy and applications in social network analysis. We concisely review the foundations of differential privacy and the major variants. Then, we discuss how differential privacy is applied to social network analysis, including privacy attacks in social networks, models of differential privacy in social network analysis, and a series of popular tasks, such as analyzing degree distribution, counting subgraphs and assigning weights to edges. We also discuss a series of challenges for future work. Honglu Jiang, Jian Pei 0001, Dongxiao Yu, Jiguo Yu, Bei Gong, Xiuzhen Cheng |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2023 | DP2-Pub: Differentially Private High-Dimensional Data Publication With Invariant Post RandomizationabstractA large amount of high-dimensional and heterogeneous data appear in practical applications, which are often published to third parties for data analysis, recommendations, targeted advertising, and reliable predictions. However, publishing these data may disclose personal sensitive information, resulting in an increasing concern on privacy violations. Privacy-preserving data publishing has received considerable attention in recent years. Unfortunately, the differentially private publication of high dimensional data remains a challenging problem. In this paper, we propose a differentially private high-dimensional data publication mechanism (DP2-Pub) that runs in two phases: a Markov-blanket-based attribute clustering phase and an invariant post randomization (PRAM) phase. Specifically, splitting attributes into several low-dimensional clusters with high intra-cluster cohesion and low inter-cluster coupling helps obtain a reasonable allocation of privacy budget, while a double-perturbation mechanism satisfying local differential privacy facilitates an invariant PRAM to ensure no loss of statistical information and thus significantly preserves data utility. We also extend our DP2-Pub mechanism to the scenario with a semi-honest server which satisfies local differential privacy. We conduct extensive experiments on four real-world datasets and the experimental results demonstrate that our mechanism can significantly improve the data utility of the published data while satisfying differential privacy. Honglu Jiang, Haotian Yu, Xiuzhen Cheng, Jian Pei 0001, Robert Pless, Jiguo Yu |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2022 | Social Welfare Maximization in Cross-Silo Federated LearningabstractAs one of the typical settings of Federated Learning (FL), cross-silo FL allows organizations to jointly train an optimal Machine Learning (ML) model. In this case, some organizations may try to obtain the global model without contributing their local training, lowering the social welfare. In this paper, we model the interactions among organizations in cross-silo FL as a public goods game for the first time and theoretically prove that there exists a social dilemma where the maximum social welfare is not achieved in Nash equilibrium. To over-come this social dilemma, we employ the Multi-player Multi-action Zero-Determinant (MMZD) strategy to maximize the social welfare. With the help of the MMZD, an individual organization can unilaterally control the social welfare without extra cost. Experimental results validate that the MMZD strategy is effective in maximizing the social welfare. Jianan Chen 0009, Qin Hu 0001, Honglu Jiang |
ICASSP | 3 |
| 2022 | Strategic signaling for utility control in audit games
Jianan Chen 0009, Qin Hu 0001, Honglu Jiang |
Comput. Secur. | 3 |
| 2022 | Differentially private data publication with multi-level data utilityabstractConventional private data publication mechanisms aim to retain as much data utility as possible while ensuring sufficient privacy protection on sensitive data. Such data publication schemes implicitly assume that all data analysts and users have the same data access privilege levels. However, it is not applicable for the scenario that data users often have different levels of access to the same data, or different requirements of data utility. The multi-level privacy requirements for different authorization levels pose new challenges for private data publication. Traditional PPDP mechanisms only publish one perturbed and private data copy satisfying some privacy guarantee to provide relatively accurate analysis results. To find a good tradeoff between privacy preservation level and data utility itself is a hard problem, let alone achieving multi-level data utility on this basis. In this paper, we address this challenge in proposing a novel framework of data publication with compressive sensing supporting multi-level utility-privacy tradeoffs, which provides differential privacy. Specifically, we resort to compressive sensing (CS) method to project a n-dimensional vector representation of users’ data to a lower m-dimensional space, and then add deliberately designed noise to satisfy differential privacy. Then, we selectively obfuscate the measurement vector under compressive sensing by adding linearly encoded noise, and provide different data reconstruction algorithms for users with different authorization levels. Extensive experimental results demonstrate that ML-DPCS yields multi-level of data utility for specific users at different authorization levels. Honglu Jiang, S. M. Sarwar, Haotian Yu, Sheikh Ariful Islam |
High Confid. Comput. | 1 |
| 2022 | A survey on security analysis of Amazon echo devicesabstractSince its launch in 2014, Amazon Echo family of devices has seen a considerable increase in adaptation in consumer homes and offices. With a market worth millions of dollars, Echo is used for diverse tasks such as accessing online information, making phone calls, purchasing items, and controlling the smart home. Echo offers user-friendly voice interaction to automate everyday tasks making it a massive success. Though many people view Amazon Echo as a helpful assistant at home or office, few know its underlying security and privacy implications. In this paper, we present the findings of our research on Amazon Echo’s security and privacy concerns. The findings are divided into different categories by vulnerability or attacks. The proposed mitigation(s) to the vulnerabilities are also presented in the paper. We conclude that though numerous privacy concerns and security vulnerabilities associated with the device are mitigated, many vulnerabilities still need to be addressed. Surendra Pathak, Sheikh Ariful Islam, Honglu Jiang, Lei Xu 0012, Emmett Tomai |
High Confid. Comput. | 3 |
| 2022 | Structure-Attribute-Based Social Network Deanonymization With Spectral Graph PartitioningabstractOnline social networks have gained tremendous popularity and have dramatically changed the way we communicate in recent years. However, the publishing of social network data raises more and more privacy concerns. To protect user privacy, social networking data are usually anonymized before being released. Nevertheless, existing anonymization techniques do not have sufficient protection effects. A large number of deanonymization attacks have arisen, and they mainly make use of either network topology or node attribute information to successfully reidentify anonymized users. In this article, we model a social network as a structure-attribute network (SAN) integrating the structural characteristics and the attribute information associated with social network users. A novel similarity measurement of social network nodes is proposed by considering the structural similarity and attribute similarity. A two-phase scheme is then designed to perform deanonymization by first dividing a social network (graph) into smaller subgraphs based on spectral graph partitioning and then applying the proposed deanonymization algorithm on each matched subgraph pair. We simulate the deanonymization attack with extensive experiments on three real-world datasets, and the experimental results demonstrate that our approach can improve the accuracy and time complexity of deanonymization compared with the state of the art. Honglu Jiang, Jiguo Yu, Xiuzhen Cheng, Cheng Zhang 0018, Bei Gong, Haotian Yu |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2021 | A novel distributed Social Internet of Things service recommendation scheme based on LSH forest
Biwei Yan, Jiguo Yu, Meihong Yang, Honglu Jiang, Zhiguo Wan, Lina Ni |
Pers. Ubiquitous Comput. | 4 |
| 2021 | Utility analysis on privacy-preservation algorithms for online social networks: an empirical study
Cheng Zhang 0018, Honglu Jiang, Xiuzhen Cheng, Feng Zhao 0002, Zhipeng Cai 0001, Zhi Tian |
Pers. Ubiquitous Comput. | 2 |
| 2019 | User Identity De-anonymization Based on Attributes
Cheng Zhang 0018, Honglu Jiang, Qin Hu 0001, Jiguo Yu, Xiuzhen Cheng |
WASA | 2 |
| 2017 | Modeling of Random Dense CSMA Networks
Yuhong Sun, Tianyi Song, Honglu Jiang, Jianchao Zheng |
WASA | 3 |