VLDB 2026 Research / reviewers in the wild / expert
Truc D. T. Nguyen
dblp:213/7311
· DBLP profile ↗
14ranked-venue papers
8as first author
12since 2021 · last 2026
0000-0002-5836-5884ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 2 first-author · 5 since 2021Computer networks · 4 · 3 first-author · 4 since 2021Systems, architecture and hardware · 3 · 1 first-author · 2 since 2021Security and privacy · 2 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Securing Federated Learning Against Active Reconstruction AttacksabstractFederated Learning (FL) has amassed notable attention for its ability to preserve user privacy while emphasizing the retainment of model training efficiency. Due to this potential, FL has been integrated in many domains, such as healthcare, finance, law, and industrial engineering, where data cannot be easily exchanged due to sensitive information and strict privacy laws. However, current research has indicated that FL protocols are easily compromised by active data reconstruction attacks employed by actively dishonest servers. The malicious modification of global model parameters allows an actively dishonest server to obtain a direct copy of users’ private data via gradient inversion. This class of attacks is highly underexplored and continues to be a major challenge due to the intense threat model. In this article, we propose OASIS as a scalable and modality-agnostic defense based on data augmentation that counteracts active data reconstruction attacks while preserving model performance. To generalize our defense, we uncover the intuition behind gradient inversion that enables these attacks and theoretically establish the conditions by which the defense can be considered robust regardless of attack design. From this, we formulate our defense with data augmentation that illustrates its ability to undermine the attack principle. We evaluate OASIS on five real-world datasets–two image-based (ImageNet and CIFAR100) and three text-based (Wikitext, Stack Overflow, and Shakespeare)–which span diverse uses cases such as vision tasks and language modeling. Comprehensive evaluations on these datasets exhibit the efficacy of OASIS and highlight its feasibility as a solution. Tre' R. Jeter, Truc D. T. Nguyen, Jung Taek Seo, My T. Thai |
ACM Trans. Internet Techn. | 2 |
| 2024 | Analysis of Privacy Leakage in Federated Large Language ModelsabstractWith the rapid adoption of Federated Learning (FL) as the training and tuning protocol for applications utilizing Large Language Models (LLMs), recent research highlights the need for significant modifications to FL to accommodate the large-scale of LLMs. While substantial adjustments to the protocol have been introduced as a response, comprehensive privacy analysis for the adapted FL protocol is currently lacking. To address this gap, our work delves into an extensive examination of the privacy analysis of FL when used for training LLMs, both from theoretical and practical perspectives. In particular, we design two active membership inference attacks with guaranteed theoretical success rates to assess the privacy leakages of various adapted FL configurations. Our theoretical findings are translated into practical attacks, revealing substantial privacy vulnerabilities in popular LLMs, including BERT, RoBERTa, DistilBERT, and OpenAI’s GPTs, across multiple real-world language datasets. Additionally, we conduct thorough experiments to evaluate the privacy leakage of these models when data is protected by state-of-the-art differential privacy (DP) mechanisms. Minh N. Vu, Truc D. T. Nguyen, Tre' R. Jeter, My T. Thai |
AISTATS | 2 |
| 2024 | OASIS: Offsetting Active Reconstruction Attacks in Federated LearningabstractFederated Learning (FL) has garnered significant attention for its potential to protect user privacy while enhancing model training efficiency. For that reason, FL has found its use in various domains, from health care to industrial engineering, especially where data cannot be easily exchanged due to sensitive information or privacy laws. However, recent research has demonstrated that FL protocols can be easily compromised by active reconstruction attacks executed by dishonest servers. These attacks involve the malicious modification of global model parameters, allowing the server to obtain a verbatim copy of users' private data by inverting their gradient updates. Tackling this class of attack remains a crucial challenge due to the strong threat model. In this paper, we propose a defense mechanism, namely OASIS, based on image augmentation that effectively counteracts active reconstruction attacks while preserving model performance. We first uncover the core principle of gradient inversion that enables these attacks and theoretically identify the main conditions by which the defense can be robust regardless of the attack strategies. We then construct our defense with image augmentation showing that it can undermine the attack principle. Comprehensive evaluations demonstrate the efficacy of the defense mechanism highlighting its feasibility as a solution. Tre' R. Jeter, Truc D. T. Nguyen, My T. Thai |
ICDCS | 2 |
| 2024 | Preserving Privacy and Security in Federated LearningabstractFederated learning is known to be vulnerable to both security and privacy issues. Existing research has focused either on preventing poisoning attacks from users or on concealing the local model updates from the server, but not both. However, integrating these two lines of research remains a crucial challenge since they often conflict with one another with respect to the threat model. In this work, we develop a principle framework that offers both privacy guarantees for users and detection against poisoning attacks from them. With a new threat model that includes both an honest-but-curious server and malicious users, we first propose a secure aggregation protocol using homomorphic encryption for the server to combine local model updates in a private manner. Then, a zero-knowledge proof protocol is leveraged to shift the task of detecting attacks in the local models from the server to the users. The key observation here is that the server no longer needs access to the local models for attack detection. Therefore, our framework enables the central server to identify poisoned model updates without violating the privacy guarantees of secure aggregation. Truc D. T. Nguyen, My T. Thai |
IEEE/ACM Trans. Netw. | 1 |
| 2023 | XRand: Differentially Private Defense against Explanation-Guided AttacksabstractRecent development in the field of explainable artificial intelligence (XAI) has helped improve trust in Machine-Learning-as-a-Service (MLaaS) systems, in which an explanation is provided together with the model prediction in response to each query. However, XAI also opens a door for adversaries to gain insights into the black-box models in MLaaS, thereby making the models more vulnerable to several attacks. For example, feature-based explanations (e.g., SHAP) could expose the top important features that a black-box model focuses on. Such disclosure has been exploited to craft effective backdoor triggers against malware classifiers. To address this trade-off, we introduce a new concept of achieving local differential privacy (LDP) in the explanations, and from that we establish a defense, called XRand, against such attacks. We show that our mechanism restricts the information that the adversary can learn about the top important features, while maintaining the faithfulness of the explanations. Truc D. T. Nguyen, Phung Lai, NhatHai Phan, My T. Thai |
AAAI | 1 |
| 2023 | Active Membership Inference Attack under Local Differential Privacy in Federated LearningabstractFederated learning (FL) was originally regarded as a framework for collaborative learning among clients with data privacy protection through a coordinating server. In this paper, we propose a new active membership inference (AMI) attack carried out by a dishonest server in FL. In AMI attacks, the server crafts and embeds malicious parameters into global models to effectively infer whether a target data sample is included in a client’s private training data or not. By exploiting the correlation among data features through a non-linear decision boundary, AMI attacks with a certified guarantee of success can achieve severely high success rates under rigorous local differential privacy (LDP) protection; thereby exposing clients’ training data to significant privacy risk. Theoretical and experimental results on several benchmark datasets show that adding sufficient privacy-preserving noise to prevent our attack would significantly damage FL’s model utility. Truc D. T. Nguyen, Phung Lai, Khang Tran, NhatHai Phan, My T. Thai |
AISTATS | 1 |
| 2023 | Denial-of-Service Vulnerability of Hash-Based Transaction Sharding: Attack and CountermeasureabstractSince 2016, sharding has become an auspicious solution to tackle the scalability issue in legacy blockchain systems. Despite its potential to strongly boost the blockchain throughput, sharding comes with its own security issues. To ease the process of deciding which shard to place transactions, existing sharding protocols use a hash-based transaction sharding in which the hash value of a transaction determines its output shard. Unfortunately, we show that this mechanism opens up a loophole that could be exploited to conduct a single-shard flooding attack, a type of Denial-of-Service (DoS) attack, to overwhelm a single shard that ends up reducing the performance of the system as a whole. To counter the single-shard flooding attack, we propose a countermeasure that essentially eliminates the loophole by rejecting the use of hash-based transaction sharding. The countermeasure leverages the Trusted Execution Environment (TEE) to let blockchain's validators securely execute a transaction sharding algorithm with a negligible overhead. We provide a formal specification for the countermeasure and analyze its security properties in the Universal Composability (UC) framework. Finally, a proof-of-concept is developed to demonstrate the feasibility and practicality of our solution. Truc D. T. Nguyen, My T. Thai |
IEEE Trans. Computers | 1 |
| 2022 | Blockchain-based Secure Client Selection in Federated LearningabstractDespite the great potential of Federated Learning (FL) in large-scale distributed learning, the current system is still subject to several privacy issues due to the fact that local models trained by clients are exposed to the central server. Consequently, secure aggregation protocols for FL have been developed to conceal the local models from the server. However, we show that, by manipulating the client selection process, the server can circumvent the secure aggregation to learn the local models of a victim client, indicating that secure aggregation alone is inadequate for privacy protection. To tackle this issue, we leverage blockchain technology to propose a verifiable client selection protocol. Owing to the immutability and transparency of blockchain, our proposed protocol enforces a random selection of clients, making the server unable to control the selection process at its discretion. We present security proofs showing that our protocol is secure against this attack. Additionally, we conduct several experiments on an Ethereum-like blockchain to demonstrate the feasibility and practicality of our solution. Truc D. T. Nguyen, Phuc Thai, Tre' R. Jeter, Thang N. Dinh, My T. Thai |
ICBC | 1 |
| 2022 | zVote: A Blockchain-based Privacy-preserving Platform for Remote E-votingabstractDespite decades of development progress, the current e-voting systems still suffer several challenges especially in terms of security and privacy. Some of the key reasons behind this issue include lack of transparency in the process and inadequate privacy guarantee for the voters. To address these issues, we propose and construct zVote, a blockchain-based e-voting platform that aims to create a transparent and secure system for remote e-voting. With the use of blockchain, the voting result can be verifiable by the public, thereby eliminating the trust in the election authorities. Furthermore, we leverage homomorphic encryptions and zero-knowledge proofs to protect the privacy of users, especially in terms of anonymity and membership privacy, while retaining the correctness and verifiability of the votes. We provide formal definitions and proofs of the construction’s security. Our proof-of-concept implementation demonstrates the feasibility and practicality of zVote. Truc D. T. Nguyen, My T. Thai |
ICC | 1 |
| 2022 | NeuCEPT: Learn Neural Networks' Mechanism via Critical Neurons with Precision GuaranteeabstractDespite recent studies on understanding deep neural networks (DNNs), there exists numerous questions on how DNNs generate their predictions. Especially, given similar predictions on different inputs, are the underlying mechanisms generating those predictions the same? In this work, we propose NeuCEPT, a method to identify critical neurons that are important to the model’s local predictions and learn their underlying mechanisms. We first formulate a critical neurons identification problem as maximizing a sequence of mutual-information objectives and provide a theoretical framework to efficiently solve for critical neurons while keeping the precision under control. NeuCEPT next heuristically learns different model’s mechanisms in an unsupervised manner. Our experiments and case studies show that neurons identified by NeuCEPT not only have strong influence on the model’s predictions but also hold meaningful information about model’s mechanisms. Minh N. Vu, Truc D. T. Nguyen, My T. Thai |
ICDM | 2 |
| 2021 | c-Eval: A Unified Metric to Evaluate Feature-based Explanations via PerturbationabstractIn many image-classification applications, understanding the reasons of model’s prediction can be as critical as the prediction’s accuracy itself. Various feature-based local explainers have been designed to provide explanations on the decision of complex classifiers. Nevertheless, there is no consensus on evaluating the quality of different explanations. In response to this lack of comprehensive evaluation, we introduce the c-Eval metric and its corresponding framework to quantify the feature-based local explanation’s quality. Given a classifier’s prediction and the corresponding explanation on that prediction, c-Eval is the minimum-distortion perturbation that successfully alters the prediction while keeping the explanation’s features unchanged. To show that c-Eval captures the importance of input’s features, we establish a connection between c-Eval and the features returned by explainers in affine and nearly-affine classifiers. We then introduce the c-Eval plot, which not only displays a strong connection between c-Eval and explainers’ quality, but also helps automatically determine explainer’s parameters. Minh N. Vu, Truc D. T. Nguyen, NhatHai Phan, Ralucca Gera, My T. Thai |
IEEE BigData | 2 |
| 2021 | A Blockchain-based Iterative Double Auction Protocol Using Multiparty State ChannelsabstractAlthough the iterative double auction has been widely used in many different applications, one of the major problems in its current implementations is that they rely on a trusted third party to handle the auction process. This imposes the risk of single point of failures, monopoly, and bribery. In this article, we aim to tackle this problem by proposing a novel decentralized and trustless framework for iterative double auction based on blockchain. Our design adopts the smart contract and state channel technologies to enable a double auction process among parties that do not need to trust each other, while minimizing the blockchain transactions. In specific, we propose an extension to the original concept of state channels that can support multiparty computation. Then, we provide a formal development of the proposed framework and prove the security of our design against adversaries. Finally, we develop a proof-of-concept implementation of our framework using Elixir and Solidity, on which we conduct various experiments to demonstrate its feasibility and practicality. Truc D. T. Nguyen, My T. Thai |
ACM Trans. Internet Techn. | 1 |
| 2019 | OptChain: Optimal Transactions Placement for Scalable Blockchain ShardingabstractA major challenge in blockchain sharding protocols is that more than 95% transactions are cross-shard. Not only those cross-shard transactions degrade the system throughput but also double the confirmation time, and exhaust an already scarce network bandwidth. Are cross-shard transactions imminent for sharding schemes? In this paper, we propose a new sharding paradigm, called OptChain, in which cross-shard transactions are minimized, resulting in almost twice faster confirmation time and throughput. By treating transactions as a stream of nodes in an online graph, OptChain utilizes a lightweight and on-the-fly transaction placement method to group both related and soon-related transactions into the same shards. At the same time, OptChain maintains a temporal balance among shards to guarantee the high parallelism. Our comprehensive and large-scale simulation using Oversim P2P library confirms a significant boost in performance with up to 10 folds reduction in cross-shard transactions, more than twice reduction in confirmation time, and 50% increase in throughput. When combined with Omniledger sharding protocol, OptChain delivers a 6000 transactions per second throughput with 10.5s confirmation time. Lan N. Nguyen, Truc D. T. Nguyen, Thang N. Dinh, My T. Thai |
ICDCS | 2 |
| 2019 | Trustless Framework for Iterative Double Auction Based on Blockchain
Truc D. T. Nguyen, My T. Thai |
SecureComm (1) | 1 |