VLDB 2026 Research / reviewers in the wild / expert
Jiyue Huang
dblp:231/1059
· DBLP profile ↗
11ranked-venue papers
4as first author
8since 2021 · last 2025
0000-0001-9646-8721ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 5 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | GIDM: Gradient Inversion of Federated Diffusion Models
Jiyue Huang, Chi Hong, Stefanie Roos, Lydia Y. Chen |
ARES (1) | 1 |
| 2025 | Single-Fold Distillation for Diffusion Models
Chi Hong, Jiyue Huang, Robert Birke, Dick H. J. Epema, Stefanie Roos, Lydia Y. Chen |
ECML/PKDD (2) | 2 |
| 2024 | On Quantifying the Gradient Inversion Risk of Data Reuse in Federated Learning SystemsabstractFederated learning (FL) enables clients to collabo-ratively learn models without revealing their local data. However, the shared model updates still reveal information about the data set, as indicated by a number of attacks on privacy. While privacy in the context of single data use is well-studied, users may provide the same data for multiple tasks. Hence, we focus on the case when data is re-used in the presence of multiple colluding servers, either the same or the different training tasks. We develop Collusive Gradient Inversion (CGI), an attack that combines multiple gradients computed on the same data to reconstruct the original data. The theoretical bound on how privacy leakage increases with the number of re-use is analyzed for the same task reconstruction. We then show that Nash bargaining games are effective in determining aggregation weights while integrating contributions from different tasks. We experimentally validate the increased quality of the reconstructed image in comparison to single-server reconstruction, both with and without defense mechanisms. Our code for reproducing is available at: https://github.com/GillHuang-Xtler/CGI. Jiyue Huang, Lydia Y. Chen, Stefanie Roos |
SRDS | 1 |
| 2023 | Fabricated Flips: Poisoning Federated Learning without DataabstractAttacks on Federated Learning (FL) can severely reduce the quality of the generated models and limit the usefulness of this emerging learning paradigm that enables on-premise decentralized learning. However, existing untargeted attacks are not practical for many scenarios as they assume that i) the attacker knows every update of benign clients, or ii) the attacker has a large dataset to locally train updates imitating benign parties. In this paper, we propose a data-free untargeted attack (DFA) that synthesizes malicious data to craft adversarial models without eavesdropping on the transmission of benign clients at all or requiring a large quantity of task-specific training data. We design two variants of DFA, namely DFA-R and DFA-G, which differ in how they trade off stealthiness and effectiveness. Specifically, DFA-R iteratively optimizes a malicious data layer to minimize the prediction confidence of all outputs of the global model, whereas DFA-G interactively trains a malicious data generator network by steering the output of the global model toward a particular class. Experimental results on Fashion-MNIST, Cifar-10, and SVHN show that DFA, despite requiring fewer assumptions than existing attacks, achieves similar or even higher attack success rate than state-of-the-art untargeted attacks against various state-of-the-art defense mechanisms. Concretely, they can evade all considered defense mechanisms in at least 50% of the cases for CIFAR-10 and often reduce the accuracy by more than a factor of 2. Consequently, we design REFD, a defense specifically crafted to protect against data-free attacks. REFD leverages a reference dataset to detect updates that are biased or have a low confidence. It greatly improves upon existing defenses by filtering out the malicious updates and achieves high global model accuracy. Jiyue Huang, Zilong Zhao 0001, Lydia Y. Chen, Stefanie Roos |
DSN | 1 |
| 2023 | Defending Against Free-Riders Attacks in Distributed Generative Adversarial Networks
Zilong Zhao 0001, Jiyue Huang, Lydia Y. Chen, Stefanie Roos |
FC | 2 |
| 2023 | Maverick Matters: Client Contribution and Selection in Federated LearningabstractAbstract Federated learning (FL) enables collaborative learning between parties, called clients, without sharing the original and potentially sensitive data. To ensure fast convergence in the presence of such heterogeneous clients, it is imperative to timely select clients who can effectively contribute to learning. A realistic but overlooked case of heterogeneous clients are Mavericks, who monopolize the possession of certain data types, e.g., children hospitals possess most of the data on pediatric cardiology. In this paper, we address the importance and tackle the challenges of Mavericks by exploring two types of client selection strategies. First, we show theoretically and through simulations that the common contribution-based approach, Shapley Value, underestimates the contribution of Mavericks and is hence not effective as a measure to select clients. Then, we propose FedEMD, an adaptive strategy with competitive overhead based on the Wasserstein distance, supported by a proven convergence bound. As FedEMD adapts the selection probability such that Mavericks are preferably selected when the model benefits from improvement on rare classes, it consistently ensures the fast convergence in the presence of different types of Mavericks. Compared to existing strategies, including Shapley Value-based ones, FedEMD improves the convergence speed of neural network classifiers with FedAvg aggregation by 26.9% and its performance is consistent across various levels of heterogeneity. Jiyue Huang, Chi Hong, Lydia Y. Chen, Stefanie Roos |
PAKDD (2) | 1 |
| 2023 | Exploring and Exploiting Data-Free Model Stealing
Chi Hong, Jiyue Huang, Robert Birke, Lydia Y. Chen |
ECML/PKDD (5) | 2 |
| 2022 | AGIC: Approximate Gradient Inversion Attack on Federated LearningabstractFederated learning is a private-by-design distributed learning paradigm where clients train local models on their own data before a central server aggregates their local updates to compute a global model. Depending on the aggregation method used, the local updates are either the gradients or the weights of local learning models, e.g., FedAvg aggregates model weights. Unfortunately, recent reconstruction attacks apply a gradient inversion optimization on the gradient update of a single mini-batch to reconstruct the private data used by clients during training. As the state-of-the-art reconstruction attacks solely focus on single update, realistic adversarial scenarios are over-looked, such as observation across multiple updates and updates trained from multiple mini-batches. A few studies consider a more challenging adversarial scenario where only model updates based on multiple mini-batches are observable, and resort to computationally expensive simulation to untangle the underlying samples for each local step. In this paper, we propose AGIC, a novel Approximate Gradient Inversion Attack that efficiently and effectively reconstructs images from both model or gradient updates, and across multiple epochs. In a nutshell, AGIC (i) approximates gradient updates of used training samples from model updates to avoid costly simulation procedures, (ii) leverages gradient/model updates collected from multiple epochs, and (iii) assigns increasing weights to layers with respect to the neural network structure for reconstruction quality. We extensively evaluate AGIC on three datasets, namely CIFAR-10, CIFAR-100 and ImageNet. Our results show that AGIC increases the peak signal-to-noise ratio (PSNR) by up to 50% compared to two representative state-of-the-art gradient inversion attacks. Furthermore, AGIC is faster than the state-of-the-art simulation-based attack, e.g., it is 5x faster when attacking FedAvg with 8 local steps in between model updates. Chi Hong, Jiyue Huang, Lydia Y. Chen, Jeremie Decouchant |
SRDS | 3 |
| 2020 | Blockchain-Based Cache Poisoning Security Protection and Privacy-Aware Access Control in NDN Vehicular Edge Computing Networks
Kai Lei, Junjie Fang, Junjun Lou, Maoyu Du, Jiyue Huang, Kuai Xu |
J. Grid Comput. | 6 |
| 2020 | Groupchain: Towards a Scalable Public Blockchain in Fog Computing of IoT Services ComputingabstractPowered by a number of smart devices distributed throughout the whole network, the Internet of Things (IoT) is supposed to provide services computing for massive data from devices. Fog computing, an extension of cloud-based IoT-oriented solutions, has emerged with requirements for distribution and decentralization. In this respect, the conjunction with Blockchain provides a natural solution for decentralization, as well as potentially helps fog computing overcome some deficiencies such as security and privacy then consequently expand the application scope of IoT. However, one of the key challenges of blockchain's integration with fog computing is scalability. To end this, this work proposes Groupchain, a novel scalable public blockchain of a two-chain structure suitable for fog computing of IoT services computing. Groupchain employs the leader group to collectively commit blocks for highertransaction efficiency and introduces bonus and deposit into the incentive mechanism to supervise behaviors of members in the leader group. Our security analysis shows that Groupchain retains the security of Bitcoin-like blockchain and enhances defense against attacks such as double-spend and selfish mining. We implement a prototype of Groupchain and conducted experiments. The experimental results demonstrate that Groupchain achieves optimization on transaction throughput and confirmation latency which are argued in Bitcoin. Kai Lei, Maoyu Du, Jiyue Huang |
IEEE Trans. Serv. Comput. | 3 |
| 2018 | Semantic Similarity Measures to Disambiguate Terms in Medical Text
Kai Lei, Jiyue Huang, Shangchun Si, Ying Shen 0001 |
ICONIP (7) | 2 |