VLDB 2026 Research / reviewers in the wild / expert
Xiangyun Tang
dblp:220/2887
· DBLP profile ↗
27ranked-venue papers
6as first author
25since 2021 · last 2026
0000-0002-5511-0720ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 14 · 12 since 2021Security and privacy · 6 · 4 first-author · 6 since 2021Artificial intelligence and machine learning · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PPFPS: A Privacy-Preserving Platoon Management Scheme for Flexible Platoon Splitting in Urban Freight DeliveryabstractVehicle platoon offers numerous benefits in terms of road safety, energy efficiency, and traffic management in urban freight delivery. Privacy preservation is critical here: location information ties to customer confidentiality and reputation guarantees platoon reliability, yet most existing platoon management schemes fail to preserve privacy while achieving vehicle location-matching. Meanwhile, traditional distance calculation methods such as Euclidean distance are unsuitable for urban road layouts, and most schemes assume member vehicles must follow to unified endpoints, a rigid constraint conflicting with the scenario's needs. In this paper, we propose a privacy-preserving platoon management scheme for flexible platoon splitting in urban freight delivery (PPFPS). In detail, the PPFPS scheme leverages location and reputation to achieve flexible platoon splitting in platoon management while preserving vehicle privacy. Specially, we design an encrypted Manhattan distance calculation method (EMC) by combining bloom filters and Paillier cryptosystem, which is tailored to the road layouts in urban environments and deployed on cloud servers. The EMC method enables privacy-preserving location matching to achieve flexible platoon splitting, and reputation is used to ensure the reliability of vehicle platoon. Furthermore, the EMC method significantly minimizes the involvement of the trusted authority by introducing cloud-assisted approaches. Theoretical analysis demonstrates that the PPFPS scheme effectively preserves privacy and defends a variety of potential attacks. Simulation evaluation confirms that the PPFPS scheme supports more functions while significantly reducing computation overheads by 66.59% to 78.72% on the TA side, and maintains communication overheads of the similar order of magnitude as the existing schemes. Shuaiyu Zhou, Yudan Cheng, Zhiquan Liu 0001, Liangliang Wang 0001, Xiangyun Tang, Na Fan 0003, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Casper: A Causality-Inspired Defense With Confounder Against Label Inference Attacks in Vertical Split Federated LearningabstractVertical Split Federated Learning (VSFL) allows participants to collaboratively train a better model with different features vertically partitioned in the same sample space, where the model is divided into bottom model and top model by the cut layer, trained by passive and active participants respectively. However, in the process, the labels owned by the active participant will still be inferred or stolen by curious or malicious passive participants. In this paper, we propose Casper, a causality-inspired defense mechanism with a confounder against label inference attacks in VSFL. Casper first analyzes the feasibility of optimizing the training process in VSFL at the intervention level from a causal perspective. It then introduces a confounder consisting of cut layer output reconstruction and label obfuscation to disrupt the direct causality between cut layer outputs and labels. Additionally, we integrate selective discrepancy training to further ensure model utility by strategically balancing training between active and passive participants. Extensive experiments conducted on four datasets across different tasks demonstrate that Casper effectively preserves label privacy while maintaining model performance, significantly outperforming current advanced defending methods in VSFL. Meng Shen 0001, Bohan Peng, Xiangyun Tang, Wei Wang 0012, Dusit Niyato, Liehuang Zhu |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Detecting Malicious Traffic Through Hypergraph Learning in Non-Terrestrial Internet of ThingsabstractThe large number of devices and complex communication requirements pose challenges to ensuring the security of Non-Terrestrial Internet of Things (NT-IoT). The large-scale data and complex communication requirements make accurate detection of malicious traffic even more challenging in NT-IoT. Hypergraph neural networks have strong performance in extracting multi-relational features. However, most existing hypergraph neural networks are tailored for graph data, and hyperedge construction methods are not well-suited. To address these challenges, we propose a malicious encrypted traffic detection method based on a hypergraph neural network. First, we propose an efficient hypergraph construction method for encrypted traffic named JointKNN. JointKNN calculates the Euclidean distance between traffic flows and adds the target nodes into the neighbor sets to form the hyperedges. Then, we propose an Encrypted Traffic HyperGraph Convolution Network (ETHGCN), which takes the encrypted traffic hypergraph as the input. ETHGCN extracts and fuses both connection and temporal features to accurately detect malicious traffic. We conduct comparative experiments on IoT and Onion Network encrypted traffic datasets for multi-class and binary classification tasks. Results indicate that ETHGCN achieves an accuracy exceeding 99.8% in IoT tasks and demonstrates an improvement of nearly 20% in Onion Network tasks. Xuzeng Li, Tao Zhang 0063, Jian Wang 0015, Zhen Han 0001, Yijing Lin, Xiangyun Tang, Jiacheng Wang 0001, Jiawen Kang 0001, Jiqiang Liu |
ICC | 6 |
| 2025 | Label Inference Attacks Against Federated Unlearning
Xiangyun Tang, Yijing Lin, Tao Zhang 0009, Meng Shen 0001, Dusit Niyato, Liehuang Zhu |
KSEM (1) | 2 |
| 2025 | LGVLM-mIoT: A Lightweight Generative Visual-Language Model for Multilingual IoT ApplicationsabstractThe demand for edge device models equipped with multilingual visual capabilities is rapidly increasing in complex IoT application scenarios. While many studies have endowed models with strong visual sensory and language analysis capabilities, these models are often large and require substantial amounts of data. Moreover, multilingual parallel corpora are extremely scarce. Although large parameter sizes can enhance a model’s visual-language processing capabilities, the high training and inference costs make them unsuitable for edge devices and result in suboptimal performance in multilingual contexts. To address these challenges, this article proposes an generative visual language model, that is, cross-lingual, lightweight, data-efficient, easy to train, and easy to infer. We map both English and non-English features into the same space and align them with a visually distilled model while leveraging the inherent similarity information of languages to increase the supervision coverage of the dataset. Through extensive experiments, we demonstrate that our model achieves state-of-the-art performance across three downstream tasks: 1) image captioning; 2) machine translation; and 3) visual question answering, surpassing existing methods. Kunyu Yang, Xiangyun Tang |
IEEE Internet Things J. | 5 |
| 2025 | Moving Target Defense Meets Artificial-Intelligence-Driven Network: A Comprehensive SurveyabstractBased on emerging artificial intelligence (AI) tasks, cloud-edge–terminal architecture can provide powerful computing, intelligent interconnection, and real-time response, which can also be regarded as AI-driven network. Unfortunately, multiple network layers in the AI-driven network usually face various types of network threats, such as malicious network reconnaissance, side-channel attacks, and distributed denial of service (DDoS). Traditional security solutions respond to network threats after the occurrence of attacks. To solve this problem, the concept of moving target defense (MTD) has been proposed as a proactive defense mechanism that aims to defend against cyber attacks before they occur. In this article, we first provide a thorough analysis of the threats in the cloud-edge–terminal network. Then, we conduct a comprehensive survey to discuss the concept, design principles, and main classifications of MTD. Next, we further introduce the development potential in terms of AI-powered MTD on each network layer. Meanwhile, we also explore how MTD improves the security of AI algorithms. Lastly, we describe the existing challenges and research directions of MTD. The aim of this article is to provide an in-depth understanding for the readers on how to realize the integration between MTD and AI-driven network. Tao Zhang 0063, Fanyu Kong 0003, Dongshang Deng, Xiangyun Tang, Xuangou Wu, Changqiao Xu, Liehuang Zhu, Jiqiang Liu, Bo Ai 0001, Zhu Han 0001, Robert H. Deng |
IEEE Internet Things J. | 4 |
| 2025 | ROBY: A Byzantine-Robust and Privacy-Preserving Serverless Federated Learning FrameworkabstractFederated Learning (FL) allows multiple data owners to jointly train machine learning models by sharing local models instead of raw private data, alleviating data privacy concerns. However, as the local computation of data owners is unpredictable, it increases its vulnerability to Byzantine attacks, where compromised data owners submit abnormal local models that can severely degrade global model accuracy. Existing Byzantine-robust FL methods depend on a semi-honest server executing predefined Byzantine-robust aggregation rules (ByRules) to filter out abnormal local models, but these methods fail when the server is compromised. Although recent serverless Byzantine-robust FL approaches mitigate the risk of a compromised server, they suffer from challenges in achieving consensus on ByRules and impose a heavy burden on privacy protection. In this paper, we propose ROBY, a novel serverless FL framework that extends existing ByRules to a decentralized setting, effectively defending against Byzantine attacks and ensuring privacy protection for local models. ROBY introduces a shared, dynamically updated consensus dataset that serves as a reliable benchmark for applying ByRules and enabling efficient consensus on ByRules among decentralized data owners. Moreover, we design a dual-layer privacy shielding strategy in ROBY to protect local model privacy without sacrificing global model accuracy or incurring extra computational and communication overhead. Extensive evaluations demonstrate that ROBY substantially enhances both Byzantine robustness and privacy protection compared to server-based FL methods. Xiangyun Tang, Minyang Li, Meng Shen 0001, Jiawen Kang 0001, Liehuang Zhu, Zhiquan Liu 0001, Guomin Yang, Dusit Niyato, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Enforcing Differential Privacy in Federated Learning via Long-Term Contribution IncentivesabstractPrivacy-preserving Federated Learning (FL) based on Differential Privacy (DP) protects clients’ data by adding DP noise to samples’ gradients and has emerged as a de facto standard for data privacy in FL. However, the accuracy of global models in DP-based FL may be reduced significantly when rogue clients occur who deviate from the preset DP-based FL approaches and selfishly inject excessive DP noise beyond expectations, thereby applying a smaller privacy budget in the DP mechanism to ensure a higher level of security. Existing DP-based FL fails to prevent such attacks as they are imperceptible. Under the DP-based FL system and random Gaussian noise, the local model parameters of the rogue clients and the honest clients have identical distributions. In particular, the rogue local models show a low performance, but directly filtering out lower-performance local models compromises the generalizability of global models, as local models trained on scarce data also behave with low performance in the early epoch. In this paper, we propose ReFL, a novel privacy-preserving FL system that enforces DP and avoids the accuracy reduction of global models caused by excessive DP noise of rogue clients. Based on the observation that rogue local models with excessive DP noise and honest local models trained on scarce data have different performance patterns in long-term training epochs, we propose a long-term contribution incentives scheme to evaluate clients’ reputations and identify rogue clients. Furthermore, we design a reputation-based aggregation to avoid the damage of rogue clients’ models on the global model accuracy, based on the incentive reputation. Extensive experiments demonstrate ReFL guarantees the global model accuracy performance 0.77% - 81.71% higher than existing DP-based FL methods in the presence of rogue clients. Xiangyun Tang, Luyao Peng, Meng Shen 0001, Liehuang Zhu, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | FinBack: Infiltrating Backdoors into Gradient Compressors on Federated LearningabstractFederated Learning (FL) has emerged as a promising distributed machine learning paradigm that allows clients to jointly train a global model without sharing their raw training datasets. However, FL is vulnerable to backdoor attacks, where malicious clients inject specific backdoors into their local models to manipulate the global model’s outputs. Recent studies widely applied gradient compression to construct efficient and robust FL systems against backdoor attacks, but we argue that gradient compression cannot be seen as a reliable defense strategy against backdoor attacks. In this work, we systematically evaluate the effectiveness of gradient compression against backdoor attacks. The experimental results indicate that, in addition to the effectiveness of SignSGD in preventing backdoor injection without significantly reducing the accuracy of the global model, most gradient compression methods do not provide effective defenses against backdoor attacks. Furthermore, we develop a novel adaptive backdoor attack, named FinBack, that can effectively infiltrate the gradient compressor SignSGD and implant backdoors in FL, by inducing small weight changes on specific neurons that do not conflict with benign clients while avoiding counteraction by benign clients and perturbation triggers thereby ensuring the effectiveness and persistence of backdoors. FinBack encompasses two attack modes: FinBack with the server collusion and FinBackR without the server collusion. Extensive experiments demonstrate the effectiveness and persistence of the proposed attacks, which increases the Attack Success Rate (ASR) from 10% to over 90% in SignSGD, even with 1% of malicious clients. Xiangyun Tang, Luyao Peng, Meng Shen 0001, Tao Zhang 0063, Jiawen Kang 0001, Dusit Niyato |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Context-adaptive and QoS-guaranteed flow scheduling optimization in multipath multimedia transmission over MPTCP
Xuan Liu 0008, Chaomurilige Wang, Shan Jiang 0012, Xiangyun Tang |
Wirel. Networks | 5 |
| 2024 | Byzantine-Robust Federated Learning on Non-IID Data via Inversing Artificial GradientsabstractFederated Learning (FL) is a distributed machine learning framework that enhances privacy by enabling multiple participants to train a global model without sharing their raw data. However, FL still faces the threat posed by data and Byzantine attacks (e.g., data poisoning and model poisoning attacks) from malicious clients aimed to decrease the FL global training accuracy. Previous studies have proposed solutions to improve the robustness of FL systems. However, these robust approaches have not effectively defended against Byzantine attacks from malicious clients in non-Independent and Identically Distributed (non-IID) environments, decreasing overall training accuracy. In this work to address this issues, we propose a new defence framework that aims to enhance model accuracy against Byzantine attacks from malicious clients in non-IID environments. In our approach, the central server performs the Inverse Deep Learning Gradient attack using the gradient data submitted by users in each round, obtaining an inversed artificial gradient. We then assess the squared L2 norm difference between this inversed gradient and the actual gradients to detect malicious clients. Simultaneously, we assign weights to each client involved in the aggregation based on differences in the squared L2 norm, aiming to minimize the impact of malicious actors on the overall model. We have experimentally evaluated our method and demonstrated its ability to maintain training accuracy under attack in non-IID environments using standard datasets. Minyang Li, Xiangyun Tang, Tao Zhang 0009 |
GLOBECOM | 2 |
| 2024 | DIsFU: Protecting Innocent Clients in Federated Unlearning
Fanyu Kong 0003, Xiangyun Tang, Tao Zhang 0009, Hongyang Du 0001, Jiawen Kang 0001, Chi Liu 0002 |
ICA3PP (4) | 2 |
| 2024 | Style-Specific Music Generation from Image
Chang Xu 0016, Xuan Liu 0008, Shan Jiang 0012, Xiangyun Tang, Minfeng Qi |
ICA3PP (2) | 5 |
| 2024 | Data-Free Encoder Stealing Attack in Self-supervised Learning
Chuan Zhang 0003, Xuhao Ren, Haotian Liang, Xiangyun Tang, Chunhai Li, Liehuang Zhu |
ICA3PP (1) | 5 |
| 2024 | QoE Maximization for Video Streaming in Cache-Enable Satellite-UAV-Terrestrial NetworkabstractUnmanned aerial vehicle (UAV)-assisted video streaming is gaining growing interests in satellite-terrestrial networks due to the mobility and caching capability. However, it is challenging to perform trajectory planning and cache management towards maximizing quality of experience (QoE) for video streaming due to a dynamic network topology and a class of hybrid control actions. In this paper, we consider a QoE-oriented video streaming transport system in satellite-UAV-terrestrial network. Our goal is to design a transmission scheduling policy that can maximize the QoE received by the ground users (GUs) under the cache capacity constraints. In this regard, we formulate a scheduling problem as a cache-constrained Markov decision process (CMDP). To tackle the CMDP, we propose a novel hybrid reinforcement learning algorithm with risk sensibility. Extensive simulations show that our proposed scheme improves QoE by more than 50% over the conventionally configured schemes. Jiansong Miao, Tao Zhang 0063, Xiangyun Tang, Jiawen Kang 0001, Dusit Niyato |
ICC | 4 |
| 2024 | Poster: Towards Pub/Sub Multimodal Data Transmission in IoT EnvironmentabstractIn this paper, we propose a system framework of Pub/Sub-based multimodal data transmission to mobile terminals. For various sensors, we classify the data in different topics, but transmit them in the uniform data channel, with different transmission mechanisms. In this case, mobile terminals receive data via different mechanisms, the push notification and request-response connection. The proposed framework makes the data transmission more efficient and flexible. Xuan Liu 0008, Chenyan Wang, Xiangyu Qu, Chang Xu 0016, Xiangyun Tang, Shan Jiang 0024 |
MobiSys | 5 |
| 2024 | Energy Efficiency Maximization for Secure Live Video Streaming in UAV Wireless NetworksabstractUnmanned aerial vehicles (UAVs) have shown great potential in live video streaming applications, especially in surveillance and reconnaissance. However, ensuring high quality of service (QoS) remains a challenge due to the dynamic nature of wireless channels. In this paper, we tackle the crucial challenge of energy-efficient and secure UAV-enabled live video streaming. To maximize long-term energy efficiency, we propose a cross-layer optimization framework that coordinates the adjustment of video coding parameters, wireless resource allocation, and UAV trajectory planning. We formulate the joint optimization as a constrained Markov decision process (CMDP) to capture the complex interdependencies between video quality, energy usage, and security risks. We introduce a new performance metric that captures the trade-off between video quality and energy consumption. The core of our method is a customized first-order constrained policy optimization, which efficiently handle complex real-world constraints like UAV battery capacities and end-to-end transmission delays. Our approach achieves scalability and sample efficiency with minimal gradient information. Through extensive system modeling and simulations under various network conditions, we validate the effectiveness of the proposed method compared with existing reinforcement learning algorithms. Lan Yi, Jiansong Miao, Tao Zhang 0063, Yushun Yao, Xiangyun Tang, Zaodi Song |
VTC Spring | 5 |
| 2024 | Towards Secrecy Energy-Efficient RIS Aided UAV Network: A Lyapunov-Guided Reinforcement Learning ApproachabstractUnmanned aerial vehicles (UAVs) are integrated into existing networks to enhance coverage, increase network capacity and provide ubiquitous access service. However, the channel in the UAV network is prone to noise and interference due to the complex environments. Reconfigurable intelligent surface (RIS), as an emerging technology in recent years, can be applied to the UAV network to establish the transmission environment by intelligibly adjusting signal characteristics, which can achieve significant gains in coverage and spectral efficiency. Thus, we consider RIS aided UAV networks for virtual reality (VR) content transmission under the presence of eavesdroppers, and maximize the time average sum secrecy energy efficiency (SEE) via adjusting UAV trajectory, beamforming matrix of UAV and RIS jointly by the deep reinforcement learning (DRL) approach. To eliminate the time correlation and the coupling of variables, we propose a Lyapunov guided decay twin-delayed deep deterministic policy gradient (TD3) scheme to tackle the decoupled problem. Simulations demonstrate the effectiveness of the proposed scheme and its outperformance in SEE compared with other benchmarks. Yushun Yao, Jiansong Miao, Tao Zhang 0063, Xiangyun Tang, Jiawen Kang 0001, Dusit Niyato |
WCNC | 4 |
| 2024 | Confidence-Aware Sentiment Quantification via Sentiment Perturbation ModelingabstractSentiment Quantification aims to detect the overall sentiment polarity of users from a set of reviews corresponding to a target. Existing methods equally treat and aggregate individual reviews' sentiment to judge the overall sentiment polarity. However, the confidence of each review is not equal in sentiment quantification where sentiment perturbation arising from high- and low-confidence reviews may degrade the accuracy of Sentiment Quantification. Specifically, fake reviews with deceptive sentiments are low confidence, which perturbs the overall sentiment prediction. Whereas, some reviews generated by responsible users are high confidence. They contain authoritative suggestions so they should be emphasized in Sentiment Quantification. In this paper, we design and build COSE, a confidence-aware sentiment quantification framework, which can measure the confidence of individual reviews to eliminate sentiment perturbation and facilitate sentiment quantification. We design a Review Graph that achieves review confidence modeling in an unsupervised manner and obtains review confidence representations. Moreover, we develop a dynamic fusion attention mechanism, which produces sentiment “de-perturbation” vectors to eliminate the sentiment perturbation based on the confidence representations. Extensive experiments on large-scale review datasets validate the significant superiority of COSE over the state-of-the-art. Xiangyun Tang, Dongliang Liao, Meng Shen 0001, Liehuang Zhu, Shen Huang, Gongfu Li, Hong Man, Jin Xu 0014 |
IEEE Trans. Affect. Comput. | 1 |
| 2024 | FedASA: A Personalized Federated Learning With Adaptive Model Aggregation for Heterogeneous Mobile Edge ComputingabstractFederated learning (FL) opens a new promising paradigm for the Industrial Internet of Things (IoT) since it can collaboratively train machine learning models without sharing private data. However, deploying FL frameworks in real IoT scenarios faces three critical challenges, i.e., statistical heterogeneity, resource constraint, and fairness. To address these challenges, we design a fair and efficient FL method, termed FedASA, which can address the challenge of statistical heterogeneity in resource-constrained scenarios by determining the shared architecture adaptively. In FedASA, we first present a cell-wised shared architecture selection strategy, which can adaptively construct the shared architecture for each device. We then design a cell-based aggregation algorithm for aggregating heterogeneous shared architectures. In addition, we provide a theoretical analysis of the federated error bound, which provides a theoretical guarantee for the fairness. At the same time, we prove the convergence of FedASA at the first-order stationary point. We evaluate the performance of FedASA through extensive simulation and experiments. Experimental results in cross-location scenarios show that FedASA outperformed the state-of-the-art approaches, improving accuracy by up to 13.27% with better fairness and faster convergence and communication requirement has been reduced by 81.49%. Dongshang Deng, Xuangou Wu, Tao Zhang 0063, Xiangyun Tang, Hongyang Du 0001, Jiawen Kang 0001, Jiqiang Liu, Dusit Niyato |
IEEE Trans. Mob. Comput. | 4 |
| 2023 | Blockchains for Artificial Intelligence of Things: A Comprehensive SurveyabstractWith the rapid advances in information and communication technologies, the Internet of Things (IoT) has become large and complex, bearing tremendous amounts of data and running devices in various scenarios. Leveraging artificial intelligence (AI) technologies, IoT can achieve superior information extraction, data analytics, and decision making, which has resulted in the revolutionized AI of Things (AIoT). AIoT can alleviate the pressure of storage, computation, and communication. Despite the promising features brought by combining AI technologies into IoT infrastructure, AIoT systems still face some serious challenges including inadequate efficiency, violation of security and privacy, lack of trust, and insufficient incentive. Blockchain featured by its distributed consensus and incentive mechanisms can be a promising technology for addressing the challenges in AIoT. AIoT employing blockchain is evolving with expectations of achieving efficient, secure, and trusted network activities. In this article, we first introduce the background of AIoT and blockchain. Then, we discuss the motivations for employing blockchain with its characteristics in AIoT. Furthermore, we comprehensively review existing solutions on blockchain for AIoT systems from the aspects of efficiency, security, privacy, trust, and incentive. Finally, we discuss the challenges and future research directions on blockchain for AIoT. Meng Shen 0001, Aijing Gu, Jiawen Kang 0001, Xiangyun Tang, Xiaodong Lin 0001, Liehuang Zhu, Dusit Niyato |
IEEE Internet Things J. | 4 |
| 2023 | PILE: Robust Privacy-Preserving Federated Learning Via Verifiable PerturbationsabstractFederated learning (FL) protects training data in clients by collaboratively training local machine learning models of clients for a global model, instead of directly feeding the training data to the server. However, existing studies show that FL is vulnerable to various attacks, resulting in training data leakage or interfering with the model training. Specifically, an adversary can analyze local gradients and the global model to infer clients’ data, and poison local gradients to generate an inaccurate global model. It is extremely challenging to guarantee strong privacy protection of training data while ensuring the robustness of model training. None of the existing studies can achieve the goal. In this paper, we propose a robust privacy-preserving federated learning framework (PILE), which protects the privacy of local gradients and global models, while ensuring their correctness by gradient verification where the server verifies the computation process of local gradients. In PILE, we develop a verifiable perturbation scheme that makes confidential local gradients verifiable for gradient verification. In particular, we build two building blocks of zero-knowledge proofs for the gradient verification without revealing both local gradients and global models. We perform rigorous theoretical analysis that proves the security of PILE and evaluate PILE on both passive and active membership inference attacks. The experiment results show that the attack accuracy under PILE is between$[50.3\%,50.9\%]$, which is close to the random guesses. Particularly, compared to prior defenses that incur the accuracy losses ranging from 2% to 13%, the accuracy loss of PILE is negligible, i.e., only$\pm 0.3\%$accuracy loss. Xiangyun Tang, Meng Shen 0001, Qi Li 0002, Liehuang Zhu, Tengfei Xue, Qiang Qu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Privacy-preserving Training Algorithm for Naive Bayes ClassifiersabstractThe growing popularity of Machine learning (ML) that appreciates high quality training datasets collected from multiple organizations raises natural questions about the privacy guarantees that can be provided in such settings. Our work tackles this problem in the context of multi-party secure ML wherein multiple organizations provide their sensitive datasets to a data user and train a Naive Bayes (NB) model with the data user. We propose PPNB, a privacy-preserving scheme for training NB models, based on Homomorphic Cryptosystem (HC) and Differential Privacy (DP). PPNB achieves a balance performance between efficiency and accuracy in multi-party secure ML, enabled flexible switch among different tradeoffs by parameter tuning. Extensive experimental results validate the effectiveness of PPNB. Xiangyun Tang, Meng Shen 0001, Liehuang Zhu |
ICC | 2 |
| 2021 | Fully Exploiting Cascade Graphs for Real-time Forwarding PredictionabstractReal-time forwarding prediction for predicting online contents' popularity is beneficial to various social applications for enhancing interactive social behaviors. Cascade graphs, formed by online contents' propagation, play a vital role in real-time forwarding prediction. Existing cascade graph modeling methods are inadequate to embed cascade graphs that have hub structures and deep cascade paths, or they fail to handle the short-term outbreak of forwarding amount. To this end, we propose a novel real-time forwarding prediction method that includes an effective approach for cascade graph embedding and a short-term variation sensitive method for time-series modeling, making the best of cascade graph features. Using two real world datasets, we demonstrate the significant superiority of the proposed method compared with the state-of-the-art. Our experiments also reveal interesting implications hidden in the performance differences between cascade graph embedding and time-series modeling. Xiangyun Tang, Dongliang Liao, Jin Xu 0014, Liehuang Zhu, Meng Shen 0001 |
AAAI | 1 |
| 2021 | Privacy-Preserving Machine Learning Training in IoT Aggregation ScenariosabstractIn developing smart city, the growing popularity of machine learning (ML) that appreciates high-quality training data sets generated from diverse Internet-of-Things (IoT) devices raises natural questions about the privacy guarantees that can be provided in such settings. Privacy-preserving ML training in an aggregation scenario enables a model demander to securely train ML models with the sensitive IoT data gathered from IoT devices. The existing solutions are generally server aided, cannot deal with the collusion threat between the servers or between the servers and data owners, and do not match the delicate environments of IoT. We propose a privacy-preserving ML training framework named Heda that consists of a library of building blocks based on partial homomorphic encryption, which enables constructing multiple privacy-preserving ML training protocols for the aggregation scenario without the assistance of untrusted servers, and defending the security under collusion situations. Rigorous security analysis demonstrates the proposed protocols can protect the privacy of each participant in the honest-but-curious model and guarantee the security under most collusion situations. Extensive experiments validate the efficiency of Heda, which achieves privacy-preserving ML training without losing the model accuracy. Liehuang Zhu, Xiangyun Tang, Meng Shen 0001, Feng Gao 0019, Jie Zhang 0061, Xiaojiang Du |
IEEE Internet Things J. | 2 |
| 2019 | Privacy-Preserving Support Vector Machine Training Over Blockchain-Based Encrypted IoT Data in Smart CitiesabstractMachine learning (ML) techniques have been widely used in many smart city sectors, where a huge amount of data is gathered from various (IoT) devices. As a typical ML model, support vector machine (SVM) enables efficient data classification and thereby finds its applications in real-world scenarios, such as disease diagnosis and anomaly detection. Training an SVM classifier usually requires a collection of labeled IoT data from multiple entities, raising great concerns about data privacy. Most of the existing solutions rely on an implicit assumption that the training data can be reliably collected from multiple data providers, which is often not the case in reality. To bridge the gap between ideal assumptions and realistic constraints, in this paper, we propose secureSVM, which is a privacy-preserving SVM training scheme over blockchain-based encrypted IoT data. We utilize the blockchain techniques to build a secure and reliable data sharing platform among multiple data providers, where IoT data is encrypted and then recorded on a distributed ledger. We design secure building blocks, such as secure polynomial multiplication and secure comparison, by employing a homomorphic cryptosystem, Paillier, and construct a secure SVM training algorithm, which requires only two interactions in a single iteration, with no need for a trusted third-party. Rigorous security analysis prove that the proposed scheme ensures the confidentiality of the sensitive data for each data provider as well as the SVM model parameters for data analysts. Extensive experiments demonstrates the efficiency of the proposed scheme. Meng Shen 0001, Xiangyun Tang, Liehuang Zhu, Xiaojiang Du, Mohsen Guizani |
IEEE Internet Things J. | 2 |
| 2018 | Privacy-Preserving DDoS Attack Detection Using Cross-Domain Traffic in Software Defined NetworksabstractExisting distributed denial-of-service attack detection in software defined networks (SDNs) typically perform detection in a single domain. In reality, abnormal traffic usually affects multiple network domains. Thus, a cross-domain attack detection has been proposed to improve detection performance. However, when participating in detection, the domain of each SDN needs to provide a large amount of real traffic data, from which private information may be leaked. Existing multiparty privacy protection schemes often achieve privacy guarantees by sacrificing accuracy or increasing the time cost. Achieving both high accuracy and reasonable time consumption is a challenging task. In this paper, we propose Predis, which is a privacy-preserving cross-domain attack detection scheme for SDNs. Predis combines perturbation encryption and data encryption to protect privacy and employs a computationally simple and efficient algorithm k-Nearest Neighbors (kNN) as its detection algorithm. We also improve kNN to achieve better efficiency. Via theoretical analysis and extensive simulations, we demonstrate that Predis is capable of achieving efficient and accurate attack detection while securing sensitive information of each domain. Liehuang Zhu, Xiangyun Tang, Meng Shen 0001, Xiaojiang Du, Mohsen Guizani |
IEEE J. Sel. Areas Commun. | 2 |