VLDB 2026 Research / reviewers in the wild / expert
Zhuoran Ma 0002
dblp:210/6243-2
· DBLP profile ↗
20ranked-venue papers
11as first author
15since 2021 · last 2026
0000-0002-9476-6386ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 6 since 2021Computer networks · 4 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Catch Me If You Can: Retain High Stealthiness and Durability of Backdoor Attack in Federated LearningabstractFederated Learning (FL) is vulnerable to backdoor attacks by design since it cannot inspect clients’ local data to protect their privacy. This privacy-preserving feature creates an opportunity for malicious clients to introduce backdoors. However, existing backdoor attacks face two main limitations. First, brute amplification (i.e., uniformly scaling up malicious parameters) can be easily detected, hence compromising attack stealthiness. Second, evasion strategies employed to prevent their backdoors from being overwritten by benign updates are frequently ineffective, reducing the overall attack stability upon model deployment. To address these limitations, we propose an adaptive proactive boosting strategy to enhance both the stealthiness and durability of backdoor attacks in FL. As a concrete example,ReBAintroduces a durable importance metric based on stability degrees of parameters as an update mask for malicious attackers, assigning higher weights to backdoor-related parameters during the update process. To ensure stealthiness,ReBAformulates an optimization problem regarding amplification factor by minimizing the distance between malicious and clean updates, thereby correcting malicious updates within a benign distance space. Extensive evaluations on 3 datasets and across 14 defenses demonstrate the efficacy ofReBA, outperforming over 12 baseline backdoor attacks. Our code is available at https://anonymous.4open.science/r/ReBA-D82F. Yilong Yang 0004, Xinjing Liu, Zefeng Wu, Zhuoran Ma 0002, Yong Zeng 0002, Xianjia Meng, Zhuo Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Power of Diversity: Enhancing Data-Free Black-Box Attack with Domain-Augmented LearningabstractSubstitute training-based data-free black-box attacks pose a significant threat to enterprise-deployed models. These attacks use a generator to synthesize data and query APIs, then train a substitute model to approximate the target model's decision boundary based on the returned results. However, existing attack methods often struggle to produce sufficiently diverse data, particularly for complex target models and extensive target data domains, severely limiting their practical application. To address this gap, we design domain-augmented learning to improve the quality of the synthetic data domain (SDD) generated by the generator from two perspectives. Specifically, (1) To broaden the SDD's coverage, we introduce textual semantic embeddings into the generator for the first time. (2) For enhancing the SDD's discretization, we propose a competitive optimization strategy that forces the generator to self-compete, along with heterogeneity excitation to overcome the constraints of information entropy on diversity. Comprehensive experiments demonstrate that our method is more effective. In non-targeted attacks on the CIFAR-10 and Tiny-ImageNet datasets, our method outperforms the state-of-the-art by 14% and 7% in attack success rate, respectively. Yang Wei 0002, Jingyu Tan, Guowen Xu, Zhuoran Ma 0002, Zhuo Ma 0001, Bin Xiao 0002 |
AAAI | 4 |
| 2025 | Enabling Efficient and Privacy-Preserving Sequence Similarity Query on Encrypted GenomesabstractOver the past decades, Sequence Similarity Query (SSQ) has been widely used in genomic analysis. Several privacy-preserving SSQ schemes have been proposed to protect sensitive genomic data but struggle to balance security and efficiency. This paper proposes a Privacy-preserving Genomic SSQ (PGSSQ) scheme to address the above issue. Specifically, we first design two fundamental privacypreserving genomic matching methods, Edit-distance Threshold Match (ETM) and Dual-Threshold Match (DTM), to support approximate editdistance based threshold SSQ matches and range-constrained SSQ matches on encrypted high-dimensional genomic sequences, respectively. Then, we present a genetic index structure called Genomic Evaluation Tree (GE-Tree) based on the ETM and DTM. GE-Tree enables dynamic pruning of query paths without disclosing any genomic information from encrypted nodes, thereby supporting privacy-preserving SSQ on encrypted genomic data with sublinear computational complexity. Security analysis proves that PGSSQ is secure under selective chosenplaintext attacks. Experiments on a real-world dataset show that PGSSQ is efficient compared to state-of-the-art schemes. Xiangyu Wang 0010, Dan Zhu 0001, Cheng Huang 0001, Zhuoran Ma 0002, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | FedGhost: Data-Free Model Poisoning Enhancement in Federated LearningabstractFL is vulnerable to model poisoning attacks due to the invisibility of local data and the decentralized nature of FL training. The adversary attempts to maliciously manipulate local model gradients to compromise the global model (i.e., victim model). Commonly-studied model poisoning attacks heavily depend on accessing additional knowledge, such as local data and the aggregation algorithm from the victim model, which easily encounter practical obstacles due to limited adversarial knowledge. In this paper, we first reveal that aggregated gradients in FL can serve as an attack carrier, exposing the latent knowledge of the victim model. In particular, we propose a data-free model poisoning attack named FedGhost, which aims to redirect the training objective of FL towards the adversary’s objective without any auxiliary information. In FedGhost, we design a black-box adaptive optimization algorithm to dynamically adjust the perturbation factor for malicious gradients, maximizing the poisoning impact of FL. Experimental results on five datasets in IID and Non-IID FL settings demonstrate that FedGhost achieves the highest attack success rate, outperforming other state-of-the-art model poisoning attacks by more than$10\%-60\%$. Zhuoran Ma 0002, Xinyi Huang 0001, Zhan Qin, Xiangyu Wang 0010, Jianfeng Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Adaptive Robust Learning Against Backdoor Attacks in Smart HomesabstractSmart homes provide various services that serve people using AI (artificial intelligence) models. In order to meet the changing demands, devices in smart homes independently collect or passively receive data for model (re)training. However, backdoor attackers could inject backdoor samples into the training data set, thus controlling the behavior of devices by attaching a trigger to the input data. Robust learning methods attempt to achieve train backdoor-free models on untrusted datasets. In smart homes, models could have limited data sources or serve simple tasks, leading to poor performance of robust learning that isolates and unlearns backdoor samples based on loss value. In this paper, we propose a novel unlearn-based robust learning approach called Adaptive Robust Learning (ARL). Specifically, ARL applies a training epoch adaptive parameter to evaluate samples based on the decrease in the early training stage and the convergence in the late training stage of loss values. Furthermore, ARL employs a flexible isolation rule based on clustering to adjust the isolation rate dynamically, making it adaptive to the poisoning rate and reducing false isolation. Experimental results indicate that ARL outperforms our baseline in defending against backdoor attacks and is more applicable in smart home scenarios. Zhuoran Ma 0002, Jianfeng Ma 0001 |
IEEE Internet Things J. | 3 |
| 2024 | Effectively Improving Data Diversity of Substitute Training for Data-Free Black-Box AttackabstractRecent substitute training methods have utilized the concept of Generative Adversarial Networks (GANs) to implement data-free black-box attacks. Specifically, in designing the generators, the substitute training methods use a similar structure to the generators in GANs. However, this design approach ignores the potential situation that the generators in GANs operate under real data supervision, while the generators in substitute training methods lack such supervision. This difference in data-supervised conditions constrain the diversity of data generated by the substitute training methods, resulting in inadequate data to support effective training of the substitute model. This impacts the substitute model's ability to attack the target model further. Consequently, to solve the above issues, we propose three strategies to improve the attack success rates. For the generator, we first propose a dense projection space that projects the input noise into various latent feature spaces to diversify feature information. Then, we introduce a novel disguised natural color mode. This mode improves information exchange between the generator's output layer and previous layers, allowing for more diverse generated data. Besides, we present a regularization method for the substitute model, called noise-based balanced learning, to prevent the potential risk of overfitting due to the lack of diversity of the generated data. In the experimental analysis, extensive experiments are conducted to validate the effectiveness of these proposed strategies. Yang Wei 0002, Zhuo Ma 0001, Zhuoran Ma 0002, Zhan Qin, Yang Liu 0118, Bin Xiao 0002, Xiuli Bi, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | FlGan: GAN-Based Unbiased Federated Learning Under Non-IID SettingsabstractFederated Learning (FL) suffers from low convergence and significant accuracy loss due to local biases caused by non-Independent and Identically Distributed (non-IID) data. To enhance the non-IID FL performance, a straightforward idea is to leverage the Generative Adversarial Network (GAN) to mitigate local biases using synthesized samples. Unfortunately, existing GAN-based solutions have inherent limitations, which do not support non-IID data and even compromise user privacy. To tackle the above issues, we propose a GAN-based unbiased FL scheme, calledFlGan, to mitigate local biases using synthesized samples generated by GAN while preserving user-level privacy in the FL setting. Specifically,FlGanfirst presents a federated GAN algorithm using the divide-and-conquer strategy that eliminates the problem of model collapse in non-IID settings. To guarantee user-level privacy,FlGanthen exploits Fully Homomorphic Encryption (FHE) to design the privacy-preserving GAN augmentation method for the unbiased FL. Extensive experiments show thatFlGanachieves unbiased FL with$10\%-60\%$accuracy improvement compared with two state-of-the-art FL baselines (i.e., FedAvg and FedSGD) trained under different non-IID settings. The FHE-based privacy guarantees only cost about 0.53% of the total overhead inFlGan. Zhuoran Ma 0002, Yang Liu 0118, Yinbin Miao, Guowen Xu, Ximeng Liu, Jianfeng Ma 0001, Robert H. Deng |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2023 | Secondary Labeling: A Novel Labeling Strategy for Image Manipulation DetectionabstractImage manipulation detection methods typically rely on a binary annotation called Primary Labeling (PrLa) to identify tampered and authentic regions in a tampered image. However, PrLa only focuses on the difference between authentic and tampered regions, ignoring the distinctions among tampered regions in different images. This transforms the task of image manipulation detection into salient object detection, with the goal shifting towards identifying the most attention-grabbing objects in images. To address this issue, this paper proposes a novel labeling strategy called Secondary Labeling (SeLa). SeLa generates a query table containing multiple tampered categories and randomly reassigns these tampered classes to different types of tampered data, effectively improving the detection performance of models by refocusing the differences among the various data. Additionally, to further improve the detection performance, this paper introduces an Adaptive Label Smoothing (ALS) regularization method. This method addresses the loss of correlation among tampered classes in SeLa caused by the one-hot encoding method. Experimental results show that compared with PrLa, SeLa not only improves the performance of detection models by up to 17%, but also enhances the robustness and convergence rate. Yang Wei 0002, Bin Xiao 0002, Xiuli Bi, Zhuoran Ma 0002, Yang Liu 0118, Zhuo Ma 0001 |
ACM Multimedia | 4 |
| 2023 | Sniffer: A Novel Model Type Detection System against Machine-Learning-as-a-Service PlatformsabstractRecent works explore several attacks against Machine-Learning-as-a-Service (MLaaS) platforms (e.g., the model stealing attack), allegedly posing potential real-world threats beyond viability in laboratories. However, hampered by model-type-sensitive , most of the attacks can hardly break mainstream real-world MLaaS platforms. That is, many MLaaS attacks are designed against only one certain type of model, such as tree models or neural networks. As the black-box MLaaS interface hides model type info, the attacker cannot choose a proper attack method with confidence, limiting the attack performance. In this paper, we demonstrate a system, named Sniffer, that is capable of making model-type-sensitive attacks "great again" in real-world applications. Specifically, Sniffer consists of four components: Generator, Querier, Probe, and Arsenal. The first two components work for preparing attack samples. Probe, as the most characteristic component in Sniffer, implements a series of self-designed algorithms to determine the type of models hidden behind the black-box MLaaS interfaces. With model type info unraveled, an optimum method can be selected from Arsenal (containing multiple attack methods) to accomplish its attack. Our demonstration shows how the audience can interact with Sniffer in a web-based interface against five mainstream MLaaS platforms. Zhuo Ma 0001, Yilong Yang 0004, Bin Xiao 0002, Yang Liu 0118, Xinjing Liu, Zhuoran Ma 0002, Tong Yang 0003 |
Proc. VLDB Endow. | 6 |
| 2023 | VerifyTL: Secure and Verifiable Collaborative Transfer LearningabstractGetting access to labeled datasets in certain sensitive application domains can be challenging. Hence, one may resort to transfer learning to transfer knowledge learned from a source domain with sufficient labeled data to a target domain with limited labeled data. However, most existing transfer learning techniques only focus on one-way transfer which may not benefit the source domain. In addition, there is the risk of a malicious adversary corrupting a number of domains, which can consequently result in inaccurate prediction or privacy leakage. In this paper, we construct a secure andVerifiable collaborativeTransferLearning scheme, VerifyTL, to support two-way transfer learning over potentially untrusted datasets by improving knowledge transfer from a target domain to a source domain. Furthermore, we equip VerifyTL with a secure and verifiable transfer unit employing SPDZ computation to provide privacy guarantee and verification in the multi-domain setting. Thus, VerifyTL is secure against malicious adversary that can compromise up to$n-1$out of$n$data domains. We analyze the security of VerifyTL and evaluate its performance over four real-world datasets. Experimental results show that VerifyTL achieves significant performance gains over existing secure learning schemes. Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | ShieldFL: Mitigating Model Poisoning Attacks in Privacy-Preserving Federated LearningabstractPrivacy-Preserving Federated Learning (PPFL) is an emerging secure distributed learning paradigm that aggregates user-trained local gradients into a federated model through a cryptographic protocol. Unfortunately, PPFL is vulnerable to model poisoning attacks launched by a Byzantine adversary, who crafts malicious local gradients to harm the accuracy of the federated model. To resist model poisoning attacks, existing defense strategies focus on identifying suspicious local gradients over plaintexts. However, the Byzantine adversary submits encrypted poisonous gradients to circumvent existing defense strategies in PPFL, resulting in encrypted model poisoning. To address the issue, in this paper we design a privacy-preserving defense strategy using two-trapdoor homomorphic encryption (referred to as ShieldFL), which can resist encrypted model poisoning without compromising privacy in PPFL. Specially, we first present the secure cosine similarity method aiming to measure the distance between two encrypted gradients. Then, we propose the Byzantine-tolerance aggregation using cosine similarity, which can achieve robustness for both Independently Identically Distribution (IID) and non-IID data. Extensive evaluations on three benchmark datasets (i.e.,MNIST, KDDCup99, and Amazon) show that ShieldFL outperforms existing defense strategies. Especially, ShieldFL can achieve 30%-80% accuracy improvement to defend two state-of-the-art model poisoning attacks in both non-IID and IID settings. Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao, Yingjiu Li, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Verifiable Data Mining Against Malicious Adversaries in Industrial Internet of ThingsabstractWith the large-scaled data generated from various interconnected machines and networks, Industrial Internet of Things (IIoT) provides unprecedented opportunities for facilitating data mining for industrial applications. The current IIoT architecture tends to adopt cloud computing for further timely mining IIoT data, however, the openness of security-critical IIoT becomes challenging in terms of unbearable privacy issues. Most existing privacy-preserving data mining (PPDM) techniques are designed to resist honest-but-curious adversaries (i.e., cloud servers and data users). Due to the complexity and openness in IIoT, PPDM is significantly difficult with the presence of malicious adversaries in IIoT who may incur incorrect learned models and inference results. To solve the aforementioned issues, we propose a framework to extend existing PPDM to guard linear regression against malicious behaviors (hereafter referred to as GuardLR). To prevent dishonest computations of cloud servers and inconsistent inputs of data users, we first design a privacy-preserving verifiable learning scheme for linear regression, which guarantees the correctness of learning. In this article, to avoid malicious clouds from returning incorrect inference results, we design a privacy-preserving prediction scheme with lightweight verification. Our formal security analysis shows that GuardLR achieves privacy, completeness, and soundness. Empirical experiments using real-world datasets also demonstrate that GuardLR has high computational efficiency and accuracy. Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Ind. Informatics | 1 |
| 2022 | Pocket Diagnosis: Secure Federated Learning Against Poisoning Attack in the CloudabstractFederated learning has become prevalent in medical diagnosis due to its effectiveness in training a federated model among multiple health institutions (i.e., Data Islands (DIs)). However, increasingly massive DI-level poisoning attacks have shed light on a vulnerability in federated learning, which inject poisoned data into certain DIs to corrupt the availability of the federated model. Previous works on federated learning have been inadequate in ensuring the privacy of DIs and the availability of the final federated model. In this article, we design a secure federated learning mechanism with multiple keys to prevent DI-level poisoning attacks for medical diagnosis, calledSFAP. Concretely,SFAPprovides privacy-preserving random forest-based federated learning by using the multi-key secure computation, which guarantees the confidentiality of DI-related information. Meanwhile, a secure defense strategy over encrypted locally-submitted models is proposed to resist DI-level poisoning attacks. Finally, our formal security analysis and empirical tests on a public cloud platform demonstrate the security and efficiency ofSFAPas well as its capability of resisting DI-level poisoning attacks. Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao, Ximeng Liu, Kim-Kwang Raymond Choo, Robert H. Deng |
IEEE Trans. Serv. Comput. | 1 |
| 2022 | Lightweight Privacy-Preserving Medical Diagnosis in Edge ComputingabstractWith the development of machine learning, it is popular that mobile users can submit individual symptoms at any time anywhere for medical diagnosis. Edge computing is frequently adopted to reduce transmission latency for real-time diagnosis service. However, the data-driven machine learning, which requires to build a diagnosis model over vast amounts of medical data, inevitably leaks the privacy of medical data. It is necessary to provide privacy preservation. To solve above challenging issues, in this article, we design a lightweight privacy-preserving medical diagnosis mechanism on edge, called LPME. Our LPME redesigns the extreme gradient boosting (XGBoost) model based on the edge-cloud model, which adopts encrypted model parameters instead of local data to remove amounts of ciphertext computation to plaintext computation, thus realizing lightweight privacy preservation on resource-limited edge. In addition, LPME provides secure diagnosis on edge with privacy preservation for private and timely diagnosis. Our security analysis and experimental evaluation indicates the security, effectiveness, and efficiency of LPME. Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao, Ximeng Liu, Kim-Kwang Raymond Choo, Ruikang Yang, Xiangyu Wang 0010 |
IEEE Trans. Serv. Comput. | 1 |
| 2021 | Lightweight Privacy-preserving Medical Diagnosis in Edge ComputingabstractIn the era of machine learning, mobile users are able to submit their symptoms to doctors at any time, anywhere for personal diagnosis. It is prevalent to exploit edge computing for real-time diagnosis services in order to reduce transmission latency. Although data-driven machine learning is powerful, it inevitably compromises privacy by relying on vast amounts of medical data to build a diagnostic model. Therefore, it is necessary to protect data privacy without accessing local data. However, the blossom has also been accompanied by various problems, i.e., the limitation of training data, vulnerabilities, and privacy concern. As a solution to these above challenges, in this paper, we design a lightweight privacy-preserving medical diagnosis mechanism on edge. Our method redesigns the extreme gradient boosting (XGBoost) model based on the edge-cloud model, which adopts encrypted model parameters instead of local data to reduce amounts of ciphertext computation to plaintext computation, thus realizing lightweight privacy preservation on resource-limited edges. Additionally, the proposed scheme is able to provide a secure diagnosis on edge while maintaining privacy to ensure an accurate and timely diagnosis. The proposed system with secure computation could securely construct the XGBoost model with lightweight overhead, and efficiently provide a medical diagnosis without privacy leakage. Our security analysis and experimental evaluation indicate the security, effectiveness, and efficiency of the proposed system. Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao, Ximeng Liu, Kim-Kwang Raymond Choo, Ruikang Yang, Xiangyu Wang 0010 |
SERVICES | 1 |
| 2020 | Flexible and Privacy-preserving Framework for Decentralized Collaborative LearningabstractNowadays, collaborative learning is becoming a new trend to address the data scarcity issue. To prevent potential privacy leakage, some privacy-preservation collaborative learning schemes have been proposed with data encryption, but cannot handle the setting of different data contribution among data nodes and avoid the huge overhead of implementing over encrypted data. In this paper, we design a flexible and secure decentralized collaborative learning to achieve the contribution over data nodes, where each data node can specialize the contribution extent for collaborative learning. Besides, we provide a MPC-friendly collaborative layer for the lightweight privacy preservation. Our security analysis and experimental results demonstrate the security and superiority of our system, respectively. Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao, Ximeng Liu, Xiang Li 0166 |
GLOBECOM | 1 |
| 2020 | Search Me in the Dark: Privacy-preserving Boolean Range Query over Encrypted Spatial DataabstractWith the increasing popularity of geo-positioning technologies and mobile Internet, spatial keyword data services have attracted growing interest from both the industrial and academic communities in recent years. Meanwhile, a massive amount of data is increasingly being outsourced to cloud in the encrypted form for enjoying the advantages of cloud computing while without compromising data privacy. Most existing works primarily focus on the privacy-preserving schemes for either spatial or keyword queries, and they cannot be directly applied to solve the spatial keyword query problem over encrypted data. In this paper, we study the challenging problem of Privacy-preserving Boolean Range Query (PBRQ) over encrypted spatial databases. In particular, we propose two novel PBRQ schemes. Firstly, we present a scheme with linear search complexity based on the space-filling curve code and Symmetric-key Hidden Vector Encryption (SHVE). Then, we use tree structures to achieve faster-than-linear search complexity. Thorough security analysis shows that data security and query privacy can be guaranteed during the query process. Experimental results using real-world datasets show that the proposed schemes are efficient and feasible for practical applications, which is at least ×70 faster than existing techniques in the literature. Xiangyu Wang 0010, Jianfeng Ma 0001, Ximeng Liu, Robert H. Deng, Yinbin Miao, Dan Zhu 0001, Zhuoran Ma 0002 |
INFOCOM | 7 |
| 2020 | PMKT: Privacy-preserving Multi-party Knowledge Transfer for financial market forecasting
Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao, Kim-Kwang Raymond Choo, Ximeng Liu, Xiangyu Wang 0010 |
Future Gener. Comput. Syst. | 1 |
| 2019 | Privacy-Preserving Data Sharing Framework for High-Accurate Outsourced ComputationabstractWith the advances of outsourced computation, the threats of data leakage and loss of computational accuracy over rational domain are attracting increasing concerns. In this paper, we propose a framework for Privacy-preserving Data Sharing and high-accurate outsourced Computation system, referred as PDSC. PDSC system can perform secure data sharing with multiple data providers. Besides, the original data and computed results in the rational field can be securely processed and stored in the cloud without privacy leakage. Specifically, we design privacy-preserving computation protocols over rational numbers to guarantee computational accuracy and handle outsourced operations on-the-fly. Detailed security analysis and experimental results demonstrate that PDSC system is secure and feasible, respectively. Ximeng Liu, Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao |
ICC | 3 |
| 2019 | Privacy-preserving and high-accurate outsourced disease predictor on random forest
Zhuoran Ma 0002, Jianfeng Ma 0001, Yinbin Miao, Ximeng Liu |
Inf. Sci. | 1 |