VLDB 2026 Research / reviewers in the wild / expert
Yu Jiang 0015
dblp:21/4633-15
· DBLP profile ↗
8ranked-venue papers
5as first author
8since 2021 · last 2025
0000-0002-3349-3863ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Guaranteeing Data Privacy in Federated Unlearning With Dynamic User ParticipationabstractFederated Unlearning (FU) is gaining prominence for its capability to eliminate influences of specific users’ data from trained global Federated Learning (FL) models. A straightforward FU method involves removing the unlearned user-specified data and subsequently obtaining a new global FL model from scratch with all remaining user data, a process that unfortunately leads to considerable overhead. To enhance unlearning efficiency, a widely adopted strategy employs clustering, dividing FL users into clusters, with each cluster maintaining its own FL model. The final inference is then determined by aggregating the majority vote from the inferences of these sub-models. This method confines unlearning processes to individual clusters for removing the training data of a particular user, thereby enhancing unlearning efficiency by eliminating the need for participation from all remaining user data. However, current clustering-based FU schemes mainly concentrate on refining clustering to boost unlearning efficiency but without addressing the issue of the potential information leakage from FL users’ gradients, a privacy concern that has been extensively studied. Typically, integrating secure aggregation (SecAgg) schemes within each cluster can facilitate a privacy-preserving FU. Nevertheless, crafting a clustering methodology that seamlessly incorporates SecAgg schemes is challenging, particularly in scenarios involving adversarial users and dynamic users. In this connection, we systematically explore the integration of SecAgg protocols within the most widely used federated unlearning scheme, which is based on clustering, to establish a privacy-preserving FU framework, aimed at ensuring privacy while effectively managing dynamic user participation. Comprehensive theoretical assessments and experimental results show that our proposed scheme achieves comparable unlearning effectiveness, alongside offering improved privacy protection and resilience in the face of varying user participation. Ziyao Liu, Yu Jiang 0015, Weifeng Jiang, Jun Zhao 0007, Kwok-Yan Lam |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Toward Efficient and Certified Recovery From Poisoning Attacks in Federated LearningabstractFederated learning (FL) is vulnerable to poisoning attacks, where malicious clients manipulate their updates to affect the global model. Although various methods exist for detecting such clients in FL, identifying malicious clients requires sufficient model updates, and hence by the time malicious clients are detected, FL models have already been poisoned. Thus, a method is needed to recover an accurate global model after malicious clients are identified. Current recovery methods rely on (i) all historical information from participating FL clients and (ii) the initial model unaffected by the malicious clients, both leading to a high demand for storage and computational resources. In this paper, we show that highly effective recovery can still be achieved based on 1) selective historical information rather than all historical information and 2) a historical model that has not been significantly affected by malicious clients rather than the initial model. In this scenario, we can accelerate the recovery speed and decrease memory consumption while maintaining comparable recovery performance. Following this concept, we introduce Crab (Certified Recovery from Poisoning Attacks and Breaches), an efficient and certified recovery method, which relies on selective information storage and adaptive model rollback. Theoretically, we demonstrate that the difference between the global model recovered by Crab and the one recovered by train-from-scratch can be bounded under certain assumptions. Our experiments, performed across four datasets with multiple machine learning models and aggregation methods, involving both untargeted and targeted poisoning attacks, demonstrate that Crab is not only accurate and efficient but also consistently outperforms previous approaches in recovery speed and memory consumption. Yu Jiang 0015, Jiyuan Shen, Ziyao Liu, Chee-Wei Tan 0001, Kwok-Yan Lam |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Certifying the Right to Be Forgotten: Primal-Dual Optimization for Sample and Label Unlearning in Vertical Federated LearningabstractFederated unlearning has become an attractive approach to address privacy concerns in collaborative machine learning, for situations when sensitive data are remembered by AI models during the machine learning process. It enables the removal of specific data influences from trained models, aligning with the growing emphasis on the “right to be forgotten.” While extensively studied in horizontal federated learning, unlearning in vertical federated learning (VFL) remains challenging due to the distributed feature architecture. VFL unlearning includes sample unlearning that removes specific data points’ influence and label unlearning that removes entire classes. Since different parties hold complementary features of the same samples, unlearning tasks require cross-party coordination, creating computational overhead and feature interdependencies. To address such challenges, we propose FedORA (Federated Optimization for data Removal via primal-dual Algorithm), designed for sample and label unlearning in VFL. FedORA formulates the removal of certain samples or labels as a constrained optimization problem solved using a primal-dual framework. Our approach introduces a new unlearning loss function that promotes classification uncertainty rather than misclassification. An adaptive step size enhances convergence, while an asymmetric batch design handles unlearning and retained data efficiently to reduce computational costs, considering the prior influence of the remaining data on the model. We provide theoretical analysis proving that the model difference between FedORA and Train-from-scratch is bounded, establishing guarantees for unlearning effectiveness. Experiments on tabular and image datasets demonstrate that FedORA achieves unlearning effectiveness and utility preservation comparable to Train-from-scratch with reduced computation and communication overhead. Yu Jiang 0015, Xindi Tong, Ziyao Liu, Xiaoxi Zhang 0001, Kwok-Yan Lam, Chee-Wei Tan 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Privacy-Preserving Federated Unlearning With Certified Client RemovalabstractIn recent years, Federated Unlearning (FU) has gained attention for addressing the removal of a client’s influence from the global model in Federated Learning (FL) systems, thereby ensuring the “right to be forgotten” (RTBF). State-of-the-art methods for unlearning use historical data from FL clients, such as gradients or locally trained models. However, studies have revealed significant information leakage in this setting, with the possibility of reconstructing a user’s local data from their uploaded information. Addressing this, we propose Starfish, a privacy-preserving federated unlearning scheme using Two-Party Computation (2PC) techniques and shared historical client data between two non-colluding servers. Starfish builds upon existing FU methods to ensure privacy in unlearning processes. To enhance the efficiency of privacy-preserving FU evaluations, we suggest 2PC-friendly alternatives for certain FU algorithm operations. We also implement strategies to reduce costs associated with 2PC operations and lessen cumulative approximation errors. Moreover, we establish a theoretical bound for the difference between the unlearned global model via Starfish and a global model retrained from scratch for certified client removal. Our theoretical and experimental analyses demonstrate that Starfish achieves effective unlearning with reasonable efficiency, maintaining privacy and security in FL systems. Ziyao Liu, Huanyi Ye, Yu Jiang 0015, Jiyuan Shen, Ivan Tjuawinata, Kwok-Yan Lam |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Efficient Federated Unlearning with Adaptive Differential Privacy PreservationabstractFederated unlearning (FU) offers a promising solution to effectively address the need to erase the impact of specific clients’ data on the global model in federated learning (FL), thereby granting individuals the "Right to be Forgotten". The most straightforward approach to achieve unlearning is to train the model from scratch, excluding clients who request data removal, but it is resource-intensive. Current state-of-the-art FU methods extend traditional FL frameworks by leveraging stored historical updates, enabling more efficient unlearning than training from scratch. However, the use of stored updates introduces significant privacy risks. Adversaries with access to these updates can potentially reconstruct clients’ local data, a well-known vulnerability in the privacy domain. While privacy-enhanced techniques exist, their applications to FU scenarios that balance unlearning efficiency with privacy protection remain underexplored. To address this gap, we propose FedADP, a method designed to achieve both efficiency and privacy preservation in FU. Our approach incorporates an adaptive differential privacy (DP) mechanism, carefully balancing privacy and unlearning performance through a novel budget allocation strategy tailored for FU. FedADP also employs a dual-layered selection process, focusing on global models with significant changes and client updates closely aligned with the global model, reducing storage and communication costs. Additionally, a novel calibration method is introduced to facilitate effective unlearning. Extensive experimental results demonstrate that FedADP effectively manages the trade-off between unlearning efficiency and privacy protection. Yu Jiang 0015, Xindi Tong, Ziyao Liu, Huanyi Ye, Chee-Wei Tan 0001, Kwok-Yan Lam |
IEEE Big Data | 1 |
| 2024 | FedUHB: Accelerating Federated Unlearning via Polyak Heavy Ball MethodabstractFederated learning facilitates collaborative machine learning, enabling multiple participants to collectively develop a shared model while preserving the privacy of individual data. The growing importance of the “right to be forgotten” calls for effective mechanisms to facilitate data removal upon request. In response, federated unlearning (FU) has been developed to efficiently eliminate the influence of specific data from the model. Current FU methods primarily rely on approximate unlearning strategies, which seek to balance data removal efficacy with computational and communication costs, but often fail to completely erase data influence. To address these limitations, we propose FedUHB, a novel exact unlearning approach that leverages the Polyak heavy ball optimization technique, a first-order method, to achieve rapid retraining. In addition, we introduce a dynamic stopping mechanism to optimize the termination of the unlearning process. Our extensive experiments show that FedUHB not only enhances unlearning efficiency but also preserves robust model performance after unlearning. Furthermore, the dynamic stopping mechanism effectively reduces the number of unlearning iterations, conserving both computational and communication resources. FedUHB can be proved as an effective and efficient solution for exact data removal in federated learning settings. Yu Jiang 0015, Chee-Wei Tan 0001, Kwok-Yan Lam |
ITW | 1 |
| 2024 | Malicious Unlearning in Ensemble ModelsabstractKnowledge removal is a crucial task in AI safety and for aligning with the Right To Be Forgotten (RTBF) principle. Machine Unlearning (MU) is an important means for achieving knowledge removal by removing the ML impacts of a specified subset of training data. However, existing MU frameworks may be misused to facilitate emerging novel poisoning attacks, where adversaries may introduce both poisoned data and the corre-sponding mitigation data that temporarily neutralize the effects of the poisoned data. The adversaries then submit malicious unlearning requests for the mitigation data, hence maintaining the malicious effects of the poison. Such attacks have been shown to be effective in single-model scenarios; however, their impacts on ensemble models, which are widely adopted because of their robustness, remain underexplored. Recognizing this gap, we extend these emerging poisoning attacks to ensemble settings to better understand and address the potential risks of malicious unlearning. Our extensive experimental results show that the proposed extended poisoning attacks are effective also in the ensemble settings, achieving a high attack success rate, highlighting the importance of continued research in safeguard measures against misuse of MU as one of the important requirements of AI safety. Huanyi Ye, Ziyao Liu, Yu Jiang 0015, Kwok-Yan Lam |
PST | 3 |
| 2022 | Towards Understanding Player Behavior in Blockchain Games: A Case Study of AavegotchiabstractBlockchain games introduce unique gameplay and incentive mechanisms by allowing players to be rewarded with in-game assets or tokens through financial activities. However, most blockchain games are not comparable to traditional games in terms of lifespan and player engagement. In this paper, we try to see the big picture in a small way to explore and determine the impact of gameplay and financial factors on player behavior in blockchain games. Taking Aavegotchi as an example, we collect one year of operation data to build player profiles. We perform an in-depth analysis of player behavior from the macroscopic data and apply an unsupervised clustering method to distinguish the attraction of the gameplay and incentives. Our results reveal that the whole game is held up by a small number of players with high-frequent interaction or vast amounts of funds invested. Financial incentives are indispensable for blockchain games for they provide attraction and optional ways for players to engage with the game. However, financial services are tightly linked to the free market. The game will face an irreversible loss of players when the market experiences depression. For blockchain games, well-designed gameplay should be the fundamental basis for the long-lasting retention of players. Yu Jiang 0015, Tian Min, Sizheng Fan, Rongqi Tao, Wei Cai 0002 |
FDG | 1 |