Zhenya Ma

dblp:219/5547 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
6since 2021 · last 2026
0009-0002-4788-7633ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 CSVAR: Enhancing Visual Privacy in Federated Learning via Adaptive Shuffling Against Overfitting
Zhenya Ma, Yan Zhang 0073, Donghua Cai, Qiushi Li 0002, Yongheng Deng, Ye Zhang 0033, Ju Ren 0001, Xuemin Shen
ICC2
2026 A Fine-Tuning Data Recovery Attack on Generative Language Models via Backdooring
abstract
Generative language models (GLMs) are increasingly integrated into modern intelligent applications to power intelligent functionalities. Developers often fine-tune open-source GLMs on proprietary data and deploy them in real-world applications. In this paper, we reveal a novel model supply chain attack that exploits this workflow: by injecting backdoors into the source code of an open-source GLM, an adversary can induce the model to memorize fine-tuning data and later regenerate it via crafted prompts. We propose LURE, a new backdoor-based data recovery attack that exploits memorization capabilities of fine-tuned models. During fine-tuning, LURE stealthily injects unique and attacker-enumerable hash prompts, and incorporates a Position-Decay Weighted Aligned Cross-Entropy Loss into the original fine-tuning loss, strengthening the association between injected prompts and corresponding data samples for effective data recovery. To achieve stealthy and transparent attack injection, LURE employs a stealthy backdoor within the model’s source code, enabling automatic injection of hash prompts during fine-tuning and thus maintaining the user’s original fine-tuning workflow. LURE also proposes several optimizations to maintain minimal impact on the performance of the original task and external training state. Extensive evaluations demonstrate the remarkable efficacy of LURE, achieving a 45%-68% data recovery rate while maintaining the attack’s transparency, stealthiness, and showcasing its ability to evade existing defenses.
Zhenya Ma, Yongheng Deng, Ziqing Qiao, Quan Zhang 0003, Chijin Zhou, Fan Wu 0014, Yaoxue Zhang, Ju Ren 0001
IEEE Trans. Inf. Forensics Secur.1
2026 Toward Communication-Efficient and Data-Free Collaborative Fine-Tuning Between Small and Large Language Models
abstract
While large language models (LLMs) exhibit impressive general capabilities, their performance on domainspecific tasks often requires fine-tuning with private data that cannot be shared due to privacy constraints. Directly deploying LLMs on resource-constrained clients for local fine-tuning is impractical due to their significant computation and communication costs. In addition, pre-trained LLMs are valuable intellectual property, and model owners are reluctant to distribute full model weights. To address these challenges, we proposeCoT-LM, a communication-efficient, computation-light, and data-free framework for collaborative fine-tuning between small (SLMs) and large language models (LLMs). InCoT-LM, clients fine-tune lightweight SLMs locally without uploading models or private data. These SLMs provide task-specific feedback to guide server-side LLM enhancement via an efficient communication protocol that exchanges only lightweight synthetic data and feedback. The framework supports both synchronous and asynchronous collaboration and enables mutual enhancement: the LLM improves its task-specific capabilities, while clients benefit from refined synthetic data or distilled knowledge. Extensive experiments demonstrate thatCoT-LMsignificantly boosts natural language understanding (NLU, up to 18.3% for LLMs and 8.0% for SLMs) and natural language generation (NLG, up to 31.7% for LLMs) performance across diverse tasks while preserving data privacy, model intellectual property, and generalization capabilities, achieving significant reductions in computation and communication overhead.
Zhenya Ma, Yongheng Deng, Ziqing Qiao, Yongjian Fu 0004, Sheng Yue 0001, Ju Ren 0001
IEEE Trans. Netw.1
2025 CrossLM: A Data-Free Collaborative Fine-Tuning Framework for Large and Small Language Models
abstract
While large language models (LLMs) are endowed with broad knowledge, their task-specific performance is often suboptimal. Fine-tuning LLMs with task-specific data from diverse nodes is necessary, but this data is typically safeguarded and not shared publicly due to privacy concerns. A common solution involves downstream nodes downloading the LLM locally and fine-tuning it with their proprietary data. However, owners often regard pre-trained LLMs as valuable assets and are reluctant to share them. Additionally, the significant computational resources required by LLMs make local fine-tuning impractical for many nodes. To mitigate these problems, this paper proposes CrossLM, a data-free collaborative fine-tuning framework for large and small language models. CrossLM enables resource-constrained nodes to train smaller language models (SLMs) using their private task-specific data. These SLMs are subsequently leveraged to promote the task-specific natural language generation and understanding capabilities of the LLMs. Simultaneously, the SLMs of nodes also benefit from enhancement by the fine-tuned LLMs. In this way, CrossLM avoids sharing private data and proprietary LLMs, and also reduces the resource requirements of nodes. Through extensive experiments across a range of benchmark tasks and popular language models, we demonstrate that CrossLM significantly boosts the task-specific performance of both LLMs and SLMs while preserving the generalization capabilities of LLMs.
Yongheng Deng, Ziqing Qiao, Ye Zhang 0033, Zhenya Ma, Yang Liu 0165, Ju Ren 0001
MobiSys4
2025 StreamSys: A Lightweight Executable Delivery System for Edge Computing
abstract
Edge computing brings several challenges when it comes to data movement. First, moving large data from edge devices to the server is likely to waste bandwidth. Second, complex data patterns (e.g., traffic cameras) on devices require flexible handling. An ideal approach is to move code to data instead. However, since only a small portion of code is required, moving the executable as well as their libraries to the devices can be an overkill. While loading code on demand from remote such as NFS can be a stopgap, but on the other hand leads to low efficiency for irregular access patterns. This article presentsStreamSys, a lightweight executable delivery system that loads code on demand by redirecting the local disk IO to the server through optimized network IO. We employ a Markov-based prefetch mechanism on the server side. It learns the access pattern of code and predicts the block sequence for the client to reduce the network round trip. Meanwhile, server-sideStreamSysasynchronously prereads the block sequence from the disk to conceal disk IO latency beforehand. Evaluation shows that the latency ofStreamSysis up to 71.4% lower than the native Linux file system based on SD card and up to 62% lower than NFS in wired environments.
Zhenya Ma, Yinggang Gao, Sheng Yue 0001, Ju Ren 0001, Yaoxue Zhang
IEEE Trans. Cloud Comput.2
2023 Limits of I/O Based Ransomware Detection: An Imitation Based Attack
abstract
By encrypting the data of infected hosts, cryptographic ransomware has caused billions of dollars in financial losses to a wide range of victims. Many detection techniques have been proposed to counter ransomware threats over the past decade. Their common approach is to monitor I/O behaviors from user space and apply custom heuristics to discriminate ransomware. These techniques implicitly assume that ransomware behaves very differently from benign programs in terms of heuristics. However, when we investigated the behavior of benign and ransomware programs, we found that the boundary between their behaviors was blurred. A ransomware program can still achieve its goal even though it follows the behavior patterns of benign programs. In this paper, we aim to explore the limits of ransomware detection techniques that based on I/O behaviors. To this end, we present Animagus, an imitation-based ransomware attack that imitates behaviors of benign programs to disguise its encryption tasks. It first learns behavior patterns from a benign program, and then spawns and orchestrates child processes to perform encryption tasks behaving the same as the benign program. We evaluate its effectiveness against six state-of-the-art detection techniques, and the results show that it can successfully evade these defenses. We investigate in detail why they are ineffective and how Animagus is different from existing ransomware samples. In the end, we discuss potential countermeasures and the benefits that detection tools can gain from our work.
Chijin Zhou, Lihua Guo, Yiwei Hou, Zhenya Ma, Quan Zhang 0003, Zhe Liu 0001, Yu Jiang 0001
SP4