Zuobin Xiong

dblp:230/0552 · DBLP profile ↗
← Back
21ranked-venue papers
7as first author
19since 2021 · last 2025
0000-0002-6562-9825ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 8 · 1 first-author · 8 since 2021Artificial intelligence and machine learning · 7 · 3 first-author · 6 since 2021Databases, data management, data science and information retrieval · 4 · 2 first-author · 3 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Efficient Phishing Website Detection via HTML Tag Sequence Analysis Using Encoder Models
abstract
The rapid proliferation of Internet of Things (IoT) devices has led to a significant increase in the number of network users, prompting advancements in security mechanisms. Consequently, traditional attacks targeting specific vulnerabilities have become less effective due to these enhanced defense systems, leading attackers to increasingly adopt phishing strategies as a primary means of bypassing security measures. Among these, phishing websites have been increasing rapidly, exploiting the carelessness of countless users. In response, numerous phishing website detection methods have been investigated, with machine learning-based approaches emerging as a leading strategy. However, these machine learning-based classification methods require substantial computational resources, posing challenges for their direct application in the already widespread IoT environment. To address these challenges, we propose an efficient phishing website detection method based on HTML tag sequences, the core structural elements of websites, by leveraging encoder models known for their effectiveness in classifying sequential data. Our approach also incorporates a customized tokenizer and dictionary specifically tailored for HTML tags. Experiments conducted on publicly available datasets demonstrate that the proposed method achieves over 95% accuracy across key performance metrics. Furthermore, comparative analyses highlight several advantages of our method, including reduced model size and faster detection times compared to existing approaches.
Jemin Ahn, Zuobin Xiong, Homook Cho, Kyungtae Kang, Junggab Son
ICCCN2
2025 Trusted Medical AI: Blockchain-Backed Device Authentication With Digital Twin-Enhanced XAI for Lung Cancer Detection
abstract
Lung cancer remains the leading cause of cancer-related deaths worldwide, mainly due to late diagnosis and limited availability of expert pathologists. Although Artificial Intelligence (AI) and DT technologies offer promising avenues for early detection, their adoption in clinical settings introduces significant concerns around data security, system vulnerabilities, and model trust. In response, this paper proposes a novel, trusted medical AI framework that combines blockchain-based device authentication, explainable artificial intelligence (XAI), and DT technologies to enhance diagnostic accuracy, data integrity, and system resilience. The proposed system leverages ResNet for lung condition classification from CT scans, augmented by Grad-CAM for visual explainability, enabling clinicians to interpret AI-driven decisions confidently. A blockchain-based whitelist mechanism authenticates medical devices before data contribution, mitigating risks of tampered or unverified input. Furthermore, the framework integrates explainable digital twin visualization to simulate patient-specific predictions and embeds a vulnerability detection layer to identify and mitigate software flaws in medical IoT and DT components. This comprehensive solution addresses key challenges in real-world healthcare: ensuring data authenticity, interpretability, and cyber resilience, paving the way for secure, transparent, and trustworthy AI-driven diagnostics.
Gabriel Chukwunonso Amaizu, Akshita Maradapu Vera Venkata Sai, Zuobin Xiong, Yingshu Li 0001
IPCCC3
2025 A Survey of Machine Unlearning in Generative AI Models: Methods, Applications, Security, and Challenges
abstract
Generative AI has flourished over the past decade, with generative models advancing in both the industrial and academic sectors. Given various applications, some scenarios have seen the misuse of generative AI, particularly in the integration with the Internet of Things (IoT). IoT devices often handle personal and sensitive data, raising serious concerns about privacy leakage and security breaches when generating data. As a promising countermeasure, machine unlearning has emerged to solve the problems posed by these generative models by effectively removing specific concepts or sensitive information from trained models. In this survey, anchored in generative models, machine unlearning approaches are reviewed, categorized, and discussed comprehensively and systematically. Existing unlearning approaches are classified into gradient-based techniques, task vectors, knowledge distillation, data sharding, and reliable unlearning methods. Apart from previous works, this survey extends the review of attack methods that aim to exploit the vulnerability in generative models and assess the robustness of these unlearning methods. In addition, popular metrics and datasets in machine unlearning research are summarized and evaluated based on effectiveness, efficiency, and security. Finally, we shed light on the future directions of this emerging research topic by discussing applications, highlighting challenges, and exploring research frontiers for the current machine unlearning community and the new investigators to come.
An Huang 0006, Zhipeng Cai 0001, Zuobin Xiong
IEEE Internet Things J.3
2024 Appro-Fun: Approximate Machine Unlearning in Federated Setting
abstract
Machine learning models contain much information about the training dataset, so even if some data points are deleted, the private information can still be inferred. To counteract this problem, "machine unlearning", as an emerging data management approach, is proposed to remove data from the databases and the influence of data from the trained models. Such a technique is vital in the current era of data-driven applications, where the privacy and security of users can be guaranteed. Yet, machine unlearning is still in its early stage, and there are rare existing methods for machine unlearning in the federated setting that is a more practical and crucial scenario. Therefore, this paper investigates the federated machine unlearning problem where the local clients of a federated system intend to delete their local private data appropriately. The proposed method is termed Approximate Federated unlearning (Appro-Fun), which adopts differential privacy and second-order optimization to achieve (ϵ, δ)-approximate unlearning on trained models. Rigorous theoretic analysis presents the performance guarantee of Appro-Fun, and real-data experiments validate the advantages of Appro-Fun compared with the state-of-the-art.
Zuobin Xiong, Wei Li 0059, Zhipeng Cai 0001
ICCCN1
2024 FCFL: A Fairness Compensation-Based Federated Learning Scheme with Accumulated Queues
Lingfu Wang, Zuobin Xiong, Guangchun Luo, Wei Li 0059
ECML/PKDD (3)2
2023 Federated Generative Model on Multi-Source Heterogeneous Data in IoT
abstract
The study of generative models is a promising branch of deep learning techniques, which has been successfully applied to different scenarios, such as Artificial Intelligence and the Internet of Things. While in most of the existing works, the generative models are realized as a centralized structure, raising the threats of security and privacy and the overburden of communication costs. Rare efforts have been committed to investigating distributed generative models, especially when the training data comes from multiple heterogeneous sources under realistic IoT settings. In this paper, to handle this challenging problem, we design a federated generative model framework that can learn a powerful generator for the hierarchical IoT systems. Particularly, our generative model framework can solve the problem of distributed data generation on multi-source heterogeneous data in two scenarios, i.e., feature related scenario and label related scenario. In addition, in our federated generative models, we develop a synchronous and an asynchronous updating methods to satisfy different application requirements. Extensive experiments on a simulated dataset and multiple real datasets are conducted to evaluate the data generation performance of our proposed generative models through comparison with the state-of-the-arts.
Zuobin Xiong, Wei Li 0059, Zhipeng Cai 0001
AAAI1
2023 Sequence-Based Modeling for Temporal Knowledge Graph Link Prediction
Zuobin Xiong, Ye Wang 0021
ICANN (4)3
2023 Exact-Fun: An Exact and Efficient Federated Unlearning Approach
abstract
Machine unlearning is an emerging need that aims to remove the influence of deleted data from a learned model in a timely manner. Thus, unlearning is important for privacy and security in data management. Nevertheless, existing machine unlearning methods fail to perform exactly and efficiently in a federated setting. In this paper, we study the unlearning problem in federated learning, which provides a data deletion mechanism in the federated setting. First of all, a quantized federated learning (Q-FL) algorithm is developed to facilitate exact unlearning. Based on the quantized federated learning system, an exact and efficient federated unlearning (Exact-Fun) algorithm is designed to realize the goal of data deletion. Through theoretic analysis and experimental evaluation, our proposed methods not only have the desired unlearning effectiveness but also achieve high unlearning efficiency compared with the existing works.
Zuobin Xiong, Wei Li 0059, Yingshu Li 0001, Zhipeng Cai 0001
ICDM1
2023 Backdoor Attack on 3D Grey Image Segmentation
abstract
3D grey image segmentation has become a promising approach to facilitate practical applications with the help of advanced deep learning models. Although a number of previous works have investigated the vulnerability of deep learning models to backdoor attack, there is no work to study the severe risk of backdoor attack on 3D grey image segmentation. To this end, we propose two backdoor attack methods on 3D grey image segmentation, including Full-control Backdoor Attack (FCBA) and Partial-control Backdoor Attack (PCBA), on 3D grey image segmentation by leveraging a frequency trigger injection function and a rotation-based label corruption function. Our proposed trigger injection function is applied to insert a 3D trigger pattern into the benign 3D grey images in the frequency domain while ensuring the invisibility of the trigger pattern. And the proposed rotation-based label corruption function is employed to yield the crafted labels with the aim of decreasing the performance of segmentation. Finally, through comprehensive experiments on a real-world dataset, we demonstrate the effectiveness of our proposed backdoor models, the frequency trigger injection function, and the rotation-based label corruption function.
Honghui Xu 0001, Zhipeng Cai 0001, Zuobin Xiong, Wei Li 0059
ICDM3
2023 DEFEAT: A decentralized federated learning against gradient attacks
abstract
As one of the most promising machine learning frameworks emerging in recent years, Federated learning (FL) has received lots of attention. The main idea of centralized FL is to train a global model by aggregating local model parameters and maintain the private data of users locally. However, recent studies have shown that traditional centralized federated learning is vulnerable to various attacks, such as gradient attacks, where a malicious server collects local model gradients and uses them to recover the private data stored on the client. In this paper, we propose a DEcentralized FEderated learning Against aTtacks (DEFEAT) framework and use it to defend the gradient attack. The decentralized structure adopted by this paper uses a peer-to-peer network to transmit, aggregate, and update local models. In DEFEAT, the participating clients only need to communicate with their single-hop neighbors to learn the global model, in which the model accuracy and communication cost during the training process of DEFEAT are well balanced. Through a series of experiments and detailed case studies on real datasets, we evauate the excellent model performance of DEFEAT and the privacy preservation capability against gradient attacks.
Guangxi Lu, Zuobin Xiong, Ruinian Li, Nael Mohammad, Yingshu Li 0001, Wei Li 0059
High Confid. Comput.2
2023 Towards Neural Network-Based Communication System: Attack and Defense
abstract
Recent progress has witnessed the excellent success of neural networks in many emerging applications, such as image recognition, text classification, and speech analysis. In order to achieve secure communication, the utilization of neural networks has been realized yet has not raised sufficient research attention. In addition, the existing neural network-based communication system falls short due to its critical security flaws. In this article, we investigate the security vulnerabilities of the existing neural communication system. Based on our analysis, we design two kinds of attack models, includingtarget man-in-the-middle attackandtarget fraud attack. After that, to improve the security performance of neural communication systems, we develop a new defense mechanism to facilitate two-way secure communication by separating secret key from plaintext and incorporating defensive loss into the training process. Moreover, we show the effectiveness of our proposed neural communication system via theoretical proof. Finally, we implement comprehensive real data experiments to evaluate the performance of our attack and defense methods from the aspects of classification accuracy, communication efficiency and communication qualify, which confirms the advantages of our proposed neural communication system compared with the state-of-the-art.
Zuobin Xiong, Zhipeng Cai 0001, Chunqiang Hu, Daniel Takabi, Wei Li 0059
IEEE Trans. Dependable Secur. Comput.1
2023 Personalized sampling graph collection with local differential privacy for link prediction
Linyu Jiang, Yukun Yan, Zhihong Tian 0001, Zuobin Xiong, Qilong Han
World Wide Web (WWW)4
2022 Pairwise Gaussian Graph Convolutional Networks: Defense Against Graph Adversarial Attack
abstract
As a research hotspot for graph mining technology, Graph Convolutional Networks (GCN) have achieved remarkable performance in the fields of wireless networks, Internet of Things, and edge computing. However, recent studies have shown that GCN is vulnerable to adversarial attack; that is, even imperceptible intentional perturbations on graph structure or node attributes can significantly change classification results. This paper proposes a novel graph convolutional network, Pairwise Gaussian Graph Convolutional Networks (PGGCN), in which a pairwise architecture is designed for GCN model construction and training. This elegant design enables PGGCN to mitigate the effects of adversarial attack and thus improve model robustness while guaranteeing classification accuracy. The performance of PGGCN is validated through extensive experimental results, which confirm that PGGCN can effectively improve the robustness of GCN while ensuring classification accuracy.
Guangxi Lu, Zuobin Xiong, Wei Li 0059
GLOBECOM2
2022 Exp-SoftLexicon Lattice Model Integrating Radical-Level Features for Chinese NER
abstract
The Lattice series model using potential words information has been proved to be effective in Chinese Named Entity Recognition (NER).The recently proposed Simplified Lattice not only brings new baseline results, but also improves the inference speed of Lattice models.However, the Simplified Lattice fails to fully explore the rich information contained in the radical-level features of the character sequences.Moreover, the performance of the Simplified Lattice decreases dramatically as the length of entity increases.In this paper, we propose the SLRL-NER model that integrates word, character, and radical-level information to alleviate the above problems.Specifically, text Convolutional Neural Network (CNN) is used to extract the radical-level features.The original SoftLexicon set is expanded to refine the relative position information of characters in the candidate words to cope with the challenge of increasing entity length.Experiments on three datasets show SLRL-NER outperforms the state-of-the-art comparison methods.
Shuangyang Hu, Ye Wang 0021, Zuobin Xiong
SEKE5
2022 Top-k Socially Constrained Spatial Keyword Search in Large SIoT Networks
abstract
Social Internet of Things (SIoT) incorporates social relationship into the Internet of Things (IoT), and a compositive relationship between persons, devices, and persons to devices is utilized for providing better services. This article proposes a novel type of search, namely, top-$k$social spatial keyword search (SSKS) in SIoT networks to discover relevant users or data objects according to social, spatial, and textual preferences. Existing works mainly focus on two of these preferences at the same time, and efficiently processing top-$k$SSKS remains challenging. To this end, we propose two algorithms to evaluate top-$k$SSKS in SIoT networks. The first algorithm is a forward search-based algorithm, which spreads the search from the vertex of the querying user. An effective pruning strategy is established by recognizing an early termination condition according to the threefold preference. The forward search-based algorithm is efficient when textual objects are dense. The second algorithm is based on index searching. We present an index namely 2HL-GIL to support spatial and textual pruning while providing fast computation of social distances in the SIoT. Then an index-based search algorithm is proposed for top-$k$SSKS, and it is efficient especially when textual objects are sparse. Our proposed algorithms are evaluated over two real-life social networks attached with synthetic locations and textual data. Evaluation results illustrate the effectiveness and efficiency of our proposed forward search-based algorithm and index-based search algorithm.
Zuobin Xiong, Qilong Han, Xixian Han, Donghua Yang
IEEE Internet Things J.2
2022 Privacy Threat and Defense for Federated Learning With Non-i.i.d. Data in AIoT
abstract
Under the needs of processing huge amounts of data, providing high-quality service, and protecting user privacy in artificial intelligence of things (AIoT), federated learning (FL) has been treated as a promising technique to facilitate distributed learning with privacy protection. Although the importance of developing privacy-preserving FL has attracted a lot of attentions, the existing research only focuses on FL with independent identically distributed (i.i.d.) data and lacks study of non-i.i.d. scenario. What is worse, the assumption of i.i.d. data is impractical, reducing the performance of privacy protection in real applications. In this article, we carry out an innovative exploration of privacy protection in FL with non-i.i.d. data. First, a thorough analysis on privacy leakage in FL is conducted with proving the performance upper bound of privacy inference attack. Based on our analysis, a novel algorithm, 2DP-FL, is designed to achieve differential privacy by adding noise during training local models and when distributing global model. Especially, our 2DP-FL algorithm has a flexibility of noise addition to meet various needs and has a convergence upper bound. Finally, the real-data experiments can validate the results of our the oretical analysis and the advantages of 2DP-FL in privacy protection, learning convergence, and model accuracy.
Zuobin Xiong, Zhipeng Cai 0001, Daniel Takabi, Wei Li 0059
IEEE Trans. Ind. Informatics1
2021 Gated recurrent unit-based parallel network traffic anomaly detection using subagging ensembles
Xiaoling Tao, Feng Zhao 0002, Baohua Qiang, Yufeng Wang 0011, Zuobin Xiong
Ad Hoc Networks7
2021 ADGAN: Protect Your Location Privacy in Camera Data of Auto-Driving Vehicles
abstract
Computer vision and deep neural networks have been significantly promoting the development of visual perception in these years. Particularly, for autonomous vehicles, real-time image/video data is captured by onboard cameras and analyzed by computer vision techniques in many real applications. In the captured camera data, some contents can be used as auxiliary information to infer individuals' locations and trajectories, which leads to severe privacy leakage but has been rarely studied. Thus, the goal of this article is to protect individuals' location privacy by hiding side-channel information in the captured data while preserving the data utility for downstream applications. To this end, the technology of generative adversarial networks (GAN) is utilized to design two novel models, named ADGAN-I and ADGAN-II, both of which can take the original camera data as inputs and generate privacy-preserving outputs according to predefined sensitive object class. Thus, the processed camera data can defend location inference attack from adversaries in offline applications. Moreover, in ADGAN-I and ADGAN-II, the tradeoff between location privacy and data utility can be effectively balanced. Finally, the results of extensive real-data experiments validate the superiority of our proposed models over the state of the arts in utility preservation and privacy protection for autonomous vehicles' images and videos.
Zuobin Xiong, Zhipeng Cai 0001, Qilong Han, Arwa Alrawais, Wei Li 0059
IEEE Trans. Ind. Informatics1
2021 CGPP-POI: A Recommendation Model Based on Privacy Protection
abstract
At present, with the popularization of intelligent equipment. Almost every smart device has a GPS. Users can use it to obtain convenient services, and third parties can use the data to provide recommendations for users and promote relevant business development. However, due to the large number of location data, there are serious data sparsity problems in the data uploaded by users. At the same time, with great value comes great danger. Once the user’s location information is obtained by the attacker, severe security issues will be caused. In recent years, a lot of researchers have studied the recommendation of point of interests (POIs) and the privacy protection of location. Yet, few of them have explored both together, which induces some drawbacks on the combination of them. This paper combines POI recommendation with a privacy protection mechanism. Besides providing user with POI recommendation service, it also protects the privacy of user’s location. We proposed a POI recommendation model with privacy protection mechanism, termed POI recommendation model for community groups based on privacy protection (CGPP‐POI). This model can ensure the recommendation accuracy and reduce the leakage of user location information via taking advantages of the characteristics of location. At the same time, it deals with the problem of poor recommendation performance caused by sparse data. In addition, through the expansion of location, random and other methods are used to protect the user’s real check‐in information. First, the data processed at the terminal satisfied local differential privacy. At the same time, we use the data to build a recommendation model. Then, we use a community of user in the model to improve the availability of these disturbed data, explore the relationship between users, and expand check‐ins within the community. Finally, we provide the POI recommendations to users. Based on the traditional evaluation criteria, we adopted four metrics, i.e., accuracy, recall rate, coverage rate, and popularity in evaluation part, where intensive experiments conducted on real datasets Gowalla and Brightkite demonstrate that our approach outperforms the baseline methods significantly.
Gesu Li, Guisheng Yin, Zuobin Xiong, Fukun Chen
Wirel. Commun. Mob. Comput.3
2019 Privacy-Preserving Auto-Driving: A GAN-Based Approach to Protect Vehicular Camera Data
abstract
The autonomous driving (auto-driving) technology has been promoted significantly by the rapid advances in computer vision and deep neural networks. Auto-driving vehicles, nowadays, are fully equipped with numerous sensors such as cameras, geo-sensors, and radar sensors, to capture real-time data inside the vehicles and outside surroundings. Meanwhile, the captured data contains lots of private information about vehicles, drivers and passengers and thus faces a high risk of privacy breaches. Especially, side-channel information can be mined from camera data to identify vehicles' locations and even trajectories, raising serious privacy issues. Unfortunately, the issue, how to resist location-inference attack for camera data in auto-driving, has never been addressed in literature. In this paper, we intend to fill this blank by developing a GAN-based image-toimage translation method named Auto-Driving GAN (ADGAN). Through performance comparisons between ADGAN and the state-of-the-art, the superiority of ADGAN can be validated - offering an effective tradeoff between recognition utility and privacy protection for camera data.
Zuobin Xiong, Wei Li 0059, Qilong Han, Zhipeng Cai 0001
ICDM1
2018 Research on Trajectory Data Releasing Method via Differential Privacy Based on Spatial Partition
abstract
A number of security and privacy challenges of cyber system are arising due to the rapidly evolving scale and complexity of modern system and networks. The cyber system is a fundamental ingredient for Internet of Things (IoT) and smart city which are driven by huge amount of data. These data carry a lot of information for mining and analysis, especially trajectory data. If unprotected trajectory data is released, it may disclose user’s personal privacy, such as home, religion, and behavior mode, which will endanger their personal security. Until now, many methods for protecting trajectory information have been proposed. However, these methods have the following deficiencies: (i) they cannot defend against speculative attacks if the attacker’s background knowledge is maximized; (ii) when studying the problem, they made some strong assumptions that did not match the reality; (iii) the implementation algorithm is complicated and the time complexity is high, which means that data cannot be executed quickly when the amount is large. So, in this paper, we propose a spatial partition based method to publish trajectory data via differential privacy. First, by exponential mechanism, we divide location set at the same time into different partitions fast and accurately. Then we propose another effective method to release trajectory in a differential private manner. We design experiment based on the real-life dataset and compare it with existing method. The results show that the trajectory dataset released by our algorithm has better usability while ensuring privacy.
Qilong Han, Zuobin Xiong, Kejia Zhang 0001
Secur. Commun. Networks2