VLDB 2026 Research / reviewers in the wild / expert
Yanjun Zhang 0002
dblp:24/6547-2
· DBLP profile ↗
45ranked-venue papers
6as first author
42since 2021 · last 2026
0000-0001-5611-3483ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 23 · 3 first-author · 22 since 2021Artificial intelligence and machine learning · 12 · 1 first-author · 11 since 2021Databases, data management, data science and information retrieval · 10 · 3 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 7 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Transferable Backdoor Attacks for Code Models via Sharpness-Aware Adversarial PerturbationabstractCode models are increasingly adopted in software development but remain vulnerable to backdoor attacks via poisoned training data. Existing backdoor attacks on code models face a fundamental trade-off between transferability and stealthiness. Static trigger-based attacks insert fixed dead code patterns that transfer well across models and datasets but are easily detected by code-specific defenses. In contrast, dynamic trigger-based attacks adaptively generate context-aware triggers to evade detection but suffer from poor cross-dataset transferability. Moreover, they rely on unrealistic assumptions of identical data distributions between poisoned and victim training data, limiting their practicality. To overcome these limitations, we propose Sharpness-aware Transferable Adversarial Backdoor (STAB), a novel attack that achieves both transferability and stealthiness without requiring complete victim data. STAB is motivated by the observation that adversarial perturbations in flat regions of the loss landscape transfer more effectively across datasets than those in sharp minima. To this end, we train a surrogate model using Sharpness-Aware Minimization to guide model parameters toward flat loss regions, and employ Gumbel-Softmax optimization to enable differentiable search over discrete trigger tokens for generating context-aware adversarial triggers. Experiments across three datasets and two code models show that STAB outperforms prior attacks in terms of transferability and stealthiness. It achieves a 73.2% average attack success rate after defense, outperforming static trigger–based attacks that fail under defense. STAB also surpasses the best dynamic trigger–based attack by 12.4% in cross-dataset attack success rate and maintains performance on clean inputs. Shuyu Chang, Haiping Huang, Yanjun Zhang 0002, Yujin Huang, Leo Yu Zhang |
AAAI | 3 |
| 2026 | Dual-View Inference Attack: Machine Unlearning Amplifies Privacy ExposureabstractMachine unlearning is a newly popularized technique for removing specific training data from a trained model, enabling it to comply with data deletion requests. While it protects the rights of users requesting unlearning, it also introduces new privacy risks. Prior works have primarily focused on the privacy of data that has been unlearned, while the risks to retained data remain largely unexplored. To address this gap, we focus on the privacy risks of retained data and, for the first time, reveal the vulnerabilities introduced by machine unlearning under the dual-view setting, where an adversary can query both the original and the unlearned models. From an information-theoretic perspective, we introduce the concept of privacy knowledge gain and demonstrate that the dual-view setting allows adversaries to obtain more information than querying either model alone, thereby amplifying privacy leakage. To effectively demonstrate this threat, we propose DVIA, a Dual-View Inference Attack, which extracts membership information on retained data using black-box queries to both models. DVIA eliminates the need to train an attack model and employs a lightweight likelihood ratio inference module for efficient inference. Experiments across different datasets and model architectures validate the effectiveness of DVIA and highlight the privacy risks inherent in the dual-view setting. Lulu Xue, Shengshan Hu, Linqiang Qian, Peijin Guo, Yechao Zhang, Yanjun Zhang 0002, Dayong Ye, Leo Yu Zhang |
AAAI | 7 |
| 2026 | Scrutinising Parametric Distance Verification in Unlearning: A Coupling Perspective
Jingming Dai, Lulu Xue, Jintian Ji, Yanjun Zhang 0002, Shengshan Hu, Leo Yu Zhang |
ACISP (3) | 4 |
| 2026 | Character-Level Perturbations Disrupt LLM Watermarks
Zhaoxi Zhang 0001, Xiaomei Zhang 0001, Yanjun Zhang 0002, He Zhang 0012, Shirui Pan, Bo Liu 0001, Asif Gill, Leo Yu Zhang |
NDSS | 3 |
| 2026 | Beyond Denial-of-Service: The Puppeteer's Attack for Fine-Grained Control in Ranking-Based Federated Learning
Zirui Gong, Jianting Ning, Yanjun Zhang 0002, Leo Yu Zhang |
WWW | 4 |
| 2026 | Poisoning-based Link Inference Attacks Against Federated Graph Neural NetworksabstractFederated graph neural networks (FedGNNs) have emerged as a promising solution for handling graph data distributed across multiple owners. They enable collaborative training while preserving data decentralisation and complying with privacy and regulatory constraints. However, the inherent structural dependencies in graph data and the message-passing mechanisms of GNNs introduce both cross-client and intra-client edges in FedGNNs. Cross-client edges, in combination with federated learning (FL) protocol designs, open additional channels for information propagation and heighten the risk of privacy leakage. In FedGNNs, once edge information is compromised, adversaries can infer local neighbourhood structures and reconstruct inter-client relationships, even without direct access to raw data. Existing research on privacy inference in FL has largely overlooked edge privacy threats specific to FedGNNs. To address this gap, we propose a poisoning link inference approach with two strategies: Label Flipping Link Inference Attack (LFLIA) and Gradient Ascent Link Inference Attack (GALIA). LFLIA flips the label of a candidate node so that its perturbation propagates along structural topology during training. GALIA perturbs the candidate node’s gradient to amplify its loss. The perturbations on the candidate node can propagate to its linked neighbours by message-passing mechanism, which induces representation shifts on these linked nodes. By monitoring FedGNN outputs of a target node set before and after poisoning, an adversary can distinguish linked nodes through observable output shifts, whereas unlinked nodes exhibit little to no change. Experimental results on multiple benchmark datasets show that our poisoning-based LIA can effectively infer link existence and structure with high accuracy across diverse federated settings. Guizhen Yang, Yanjun Zhang 0002, Leo Yu Zhang, Mengmeng Ge 0001, Shang Gao 0003 |
Proc. Priv. Enhancing Technol. | 2 |
| 2026 | Fine-Grained Poisoning Framework Against Federated LearningabstractFederated learning(FL) is one of the most widely used distributed machine learning frameworks. However, FL is susceptible to poisoning attacks that can degrade the quality of the global model. Recent studies on fine-grained poisoning attacks highlight a strategic shift where attackers no longer prioritize maximal disruption of the global model, but instead control the degree of model poisoning to maintain stealth and avoid detection. However, research on fine-grained poisoning is still in the infant stage. Numerous fundamental questions have yet to be addressed, including its underlying mechanisms and optimization strategies. To this end, we introduces FGP, the first comprehensive framework forFine-GrainedPoisoning on FL, which allows adversaries to precisely manipulate the global model by strategically inducing accurate and stealthy sub-optimal solution. Fundamentally, FGP innovatively formalizes fine-grained attacks as an optimization problem to minimize the distance between the current global model and the adversary's target (a sub-optimal solution). It then employs a real-time search strategy to dynamically refine the malicious model updates in each round. To ensure optimal attack performance, we further introduce a novel topology-based approach as the error feedback. Additionally, we present a formal convergence analysis of our attacks. Armed with FGP, we conduct a comprehensive evaluation of FL's robustness against fine-grained poisoning across diverse settings. Results demonstrate that FGP significantly outperforms the prior work, achieving an average$6.5\times$higher attack accuracy. Hangtao Zhang, Yanjun Zhang 0002, Chao Chen 0015, Qiyun Shao, Shengshan Hu, Leo Yu Zhang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | PROTheft: A Projector-Based Model Extraction Attack in the Physical World
Xinjing Liu, Yilong Yang 0004, Taifeng Liu, Leo Yu Zhang, Yanjun Zhang 0002, Yang Liu 0118, Zhuo Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | Improving Generalization of Universal Adversarial Perturbation via Dynamic Maximin OptimizationabstractDeep neural networks (DNNs) are susceptible to universal adversarial perturbations (UAPs). These perturbations are meticulously designed to fool the target model universally across all sample classes. Unlike instance-specific adversarial examples (AEs), generating UAPs is more complex because they must be generalized across a wide range of data samples and models. Our research reveals that existing universal attack methods, which optimize UAPs using DNNs with static model parameter snapshots, do not fully leverage the potential of DNNs to generate more effective UAPs. Rather than optimizing UAPs against static DNN models with a fixed training set, we suggest using dynamic model-data pairs to generate UAPs. In particular, we introduce a dynamic maximin optimization strategy, aiming to optimize the UAP across a variety of optimal model-data pairs. We term this approach DM-UAP. DM-UAP utilizes an iterative max-min-min optimization framework that refines the model-data pairs, coupled with a curriculum UAP learning algorithm to examine the combined space of model parameters and data thoroughly. Comprehensive experiments on the ImageNet dataset demonstrate that the proposed DM-UAP markedly enhances both cross-sample universality and cross-model transferability of UAPs. Using only 500 samples for UAP generation, DM-UAP outperforms the state-of-the-art approach with an average increase in fooling ratio of 12.108%. Yechao Zhang, Yingzhe Xu, Junyu Shi, Leo Yu Zhang, Shengshan Hu, Yanjun Zhang 0002 |
AAAI | 7 |
| 2025 | RAGLeak: Membership Inference Attacks on RAG-Based Large Language Models
Kaiyue Feng, Guangsheng Zhang 0004, Yanjun Zhang 0002, Tianqing Zhu, Ming Ding 0001, Bo Liu 0001 |
ACISP (3) | 5 |
| 2025 | When Better Features Mean Greater Risks: The Performance-Privacy Trade-Off in Contrastive LearningabstractWhen Better Features Mean Greater Risks: The Performance-Privacy Trade-Off in Contrastive Learning Ruining Sun, Hongsheng Hu, Wei Luo 0001, Zhaoxi Zhang 0001, Yanjun Zhang 0002, Haizhuan Yuan, Leo Yu Zhang |
AsiaCCS | 5 |
| 2025 | Test-Time Backdoor Detection for Object Detection ModelsabstractObject detection models are vulnerable to backdoor attacks, where attackers poison a small subset of training samples by embedding a predefined trigger to manipulate prediction. Detecting poisoned samples (i.e., those containing triggers) at test time can prevent backdoor activation. However, unlike image classification tasks, the unique characteristics of object detection—particularly its output of numerous objects—pose fresh challenges for backdoor detection. The complex attack effects (e.g., "ghost" object emergence or "vanishing" object) further render current defenses fundamentally inadequate. To this end, we design TRAnsformation Consistency Evaluation (TRACE), a brand-new method for detecting poisoned samples at test time in object detection. Our journey begins with two intriguing observations: 1) poisoned samples exhibit significantly more consistent detection results than clean ones across varied backgrounds. 2) clean samples show higher detection consistency when introduced to different focal information. Based on these phenomena, Trace applies foreground and background transformations to each test sample, then assesses transformation consistency by calculating the variance in objects confidences. Trace achieves black-box, universal backdoor detection, with extensive experiments showing a 30% improvement in AUROC over state-of-the-art defenses and resistance to adaptive attacks. Hangtao Zhang, Yichen Wang 0013, Shihui Yan, Chenyu Zhu, Ziqi Zhou 0001, Linshan Hou, Shengshan Hu, Yanjun Zhang 0002, Leo Yu Zhang |
CVPR | 9 |
| 2025 | BiMark: Unbiased Multilayer Watermarking for Large Language ModelsabstractRecent advances in Large Language Models (LLMs) have raised urgent concerns about LLM-generated text authenticity, prompting regulatory demands for reliable identification mechanisms.
Although watermarking offers a promising solution, existing approaches struggle to simultaneously achieve three critical requirements: text quality preservation, model-agnostic detection, and message embedding capacity, which are crucial for practical implementation.
To achieve these goals, the key challenge lies in balancing the trade-off between text quality preservation and message embedding capacity.
To address this challenge, we propose BiMark, a novel watermarking framework that achieves these requirements through three key innovations:
(1) a bit-flip unbiased reweighting mechanism enabling model-agnostic detection, (2) a multilayer architecture enhancing detectability without compromising generation quality, and (3) an information encoding approach supporting multi-bit watermarking.
Through theoretical analysis and extensive experiments, we validate that,
compared to state-of-the-art multi-bit watermarking methods, BiMark achieves up to 30% higher extraction rates for short texts while maintaining text quality indicated by lower perplexity, and performs comparably to non-watermarked text on downstream tasks such as summarization and translation. Xiaoyan Feng, He Zhang 0012, Yanjun Zhang 0002, Leo Yu Zhang, Shirui Pan |
ICML | 3 |
| 2025 | Performance Guaranteed Poisoning Attacks in Federated Learning: A Sliding Mode ApproachabstractManipulation of local training data and local updates, i.e., the poisoning attack, is the main threat arising from the collaborative nature of the federated learning (FL) paradigm. Most existing poisoning attacks aim to manipulate local data/models in a way that causes denial-of-service (DoS) issues. In this paper, we introduce a novel attack method, named Federated Learning Sliding Attack (FedSA) scheme, aiming at precisely introducing the extent of poisoning in a subtle controlled manner. It operates with a predefined objective, such as reducing global model's prediction accuracy by 10%. FedSA integrates robust nonlinear control-Sliding Mode Control (SMC) theory with model poisoning attacks. It can manipulate the updates from malicious clients to drive the global model towards a compromised state, achieving this at a controlled and inconspicuous rate. Additionally, leveraging the robust control properties of FedSA allows precise control over the convergence bounds, enabling the attacker to set the global accuracy of the poisoned model to any desired level. Experimental results demonstrate that FedSA can accurately achieve a predefined global accuracy with fewer malicious clients while maintaining a high level of stealth and adjustable learning rates. Huazi Pan, Yanjun Zhang 0002, Leo Yu Zhang, Scott D. Adams, Abbas Z. Kouzani, Suiyang Khoo |
IJCAI | 2 |
| 2025 | Scale Margin Loss for Object Detection
Yuxuan Cheng, Yanjun Zhang 0002, Leo Yu Zhang, Donald Donglong Chen, Yuming Fang 0001 |
KSEM (2) | 2 |
| 2025 | MarkErase: Defeating Entangled Watermarks in Model Extraction Attacks
Xinjing Liu, Yanjun Zhang 0002, Haizhuan Yuan, Tianqing Zhu, Leo Yu Zhang |
PAKDD (4) | 3 |
| 2025 | Not All Edges are Equally Robust: Evaluating the Robustness of Ranking-Based Federated LearningabstractFederated Ranking Learning (FRL) is a state-of-the-art FL framework that stands out for its communication efficiency and resilience to poisoning attacks. It diverges from the traditional FL framework in two ways: 1) it leverages discrete rankings instead of gradient updates, significantly reducing communication costs and limiting the potential space for malicious updates, and 2) it uses majority voting on the server side to establish the global ranking, ensuring that individual updates have minimal influence since each client contributes only a single vote. These features enhance the system's scalability and position FRL as a promising paradigm for FL training. However, our analysis reveals that FRL is not inherently robust, as certain edges are particularly vulnerable to poisoning attacks. Through a theoretical investigation, we prove the existence of these vulnerable edges and establish a lower bound and an upper bound for identifying them in each layer. Based on this finding, we introduce a novel local model poisoning attack against FRL, namely Vulnerable Edge Manipulation (VEM) attack. The VEM attack focuses on identifying and perturbing the most vulnerable edges in each layer and leveraging an optimization-based approach to maximize the attack's impact. Through extensive experiments on benchmark datasets, we demonstrate that our attack achieves an overall 53.23 % attack impact and is 3.7× more impactful than existing methods. Our findings highlight significant vulnerabilities in ranking-based FL systems and underline the urgency for the development of new robust FL frameworks. Zirui Gong, Yanjun Zhang 0002, Leo Yu Zhang, Zhaoxi Zhang 0001, Yong Xiang 0001, Shirui Pan |
SP | 2 |
| 2025 | Distributed Differentially Private Matrix Factorization for Implicit Data via Secure AggregationabstractImplicit feedback data has become the primary choice for building recommendation models due to its abundance and ease for collection in the real world. The strong generalization capability and high computational efficiency of matrix factorization make it one of the principal models for constructing recommender systems. Recommenders have to collect vast amounts of user data for model training, which poses a significant threat to user privacy. Most of the current privacy enhancing recommendation systems mainly focus on explicit feedback data, and there are limited studies dedicated to the privacy protection of implicit recommender. To bridge the existing research gap, this paper designs a distributed differentially private matrix factorization for implicit feedback data in scenarios where the recommender is not trusted. Our mechanism not only eliminates the assumption of a trusted recommender, but also achieves the same accuracy as CDP-based privacy-preserving MF model. We prove that our mechanism satisfies$(\epsilon,\delta)$-CDP. The experimental results on three public datasets confirm that the proposed mechanism can achieve high recommendation quality. Chenhong Luo, Yong Wang 0009, Yanjun Zhang 0002, Leo Yu Zhang |
IEEE Trans. Computers | 3 |
| 2025 | Extracting Private Training Data in Federated Learning From ClientsabstractThe utilization of machine learning algorithms in distributed web applications is experiencing significant growth. One notable approach is Federated Learning (FL) Recent research has brought attention to the vulnerability of FL to gradient inversion attacks, which seek to reconstruct the original training samples, posing a substantial threat to client privacy. Most existing gradient inversion attacks, however, require control over the central server and rely on substantial prior knowledge, including information about batch normalization and data distribution. In this study, we introduce Poisoning Gradient Leakage from Client (PGLC), a novel attack method that operates from the clients’ side. For the first time, we demonstrate the feasibility of a client-side adversary with limited knowledge successfully recovering training samples from the aggregated global model. Our approach enables the adversary to employ a malicious model that increases the loss of a specific targeted class of interest. When honest clients employ the poisoned global model, the gradients of samples become distinct in the aggregated update. This allows the adversary to effectively reconstruct private inputs from other clients using the aggregated update. Furthermore, our PGLC attack exhibits stealthiness against Byzantine-robust aggregation rules (AGRs). Through the optimization of malicious updates and the blending of benign updates with a malicious replacement vector, our method remains undetected by these defense mechanisms. We conducted experiments across various benchmark datasets, considering representative Byzantine-robust AGRs and exploring different FL settings with varying levels of adversary knowledge about the data. Our results consistently demonstrate the ability of PGLC to extract training data in all tested scenarios. Jiaheng Wei, Yanjun Zhang 0002, Leo Yu Zhang, Chao Chen 0015, Shirui Pan, Kok-Leong Ong, Jun Zhang 0010, Yang Xiang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Towards Model Extraction Attacks in GAN-Based Image Translation via Domain Shift MitigationabstractModel extraction attacks (MEAs) enable an attacker to replicate the functionality of a victim deep neural network (DNN) model by only querying its API service remotely, posing a severe threat to the security and integrity of pay-per-query DNN-based services. Although the majority of current research on MEAs has primarily concentrated on neural classifiers, there is a growing prevalence of image-to-image translation (I2IT) tasks in our everyday activities. However, techniques developed for MEA of DNN classifiers cannot be directly transferred to the case of I2IT, rendering the vulnerability of I2IT models to MEA attacks often underestimated. This paper unveils the threat of MEA in I2IT tasks from a new perspective. Diverging from the traditional approach of bridging the distribution gap between attacker queries and victim training samples, we opt to mitigate the effect caused by the different distributions, known as the domain shift. This is achieved by introducing a new regularization term that penalizes high-frequency noise, and seeking a flatter minimum to avoid overfitting to the shifted distribution. Extensive experiments on different image translation tasks, including image super-resolution and style transfer, are performed on different backbone victim models, and the new design consistently outperforms the baseline by a large margin across all metrics. A few real-life I2IT APIs are also verified to be extremely vulnerable to our attack, emphasizing the need for enhanced defenses and potentially revised API publishing policies. Di Mi, Yanjun Zhang 0002, Leo Yu Zhang, Shengshan Hu, Haizhuan Yuan, Shirui Pan |
AAAI | 2 |
| 2024 | Stealing Watermarks of Large Language Models via Mixed Integer ProgrammingabstractThe Large Language Model (LLM) watermark is a newly emerging technique that shows promise in addressing concerns surrounding LLM copyright, monitoring AI-generated text, and preventing its misuse. The LLM watermark scheme commonly includes generating secret keys to partition the vocabulary into green and red lists, applying a perturbation to the logits of tokens in the green list to increase their sampling likelihood, thus facilitating watermark detection to identify AI-generated text if the proportion of green tokens exceeds a threshold. However, recent research indicates that watermarking methods using numerous keys are susceptible to removal attacks, such as token editing, synonym substitution, and paraphrasing, with robustness declining as the number of keys increases. Therefore, the state-of-the-art watermark schemes that employ fewer or single keys have been demonstrated to be more robust against text editing and paraphrasing. In this paper, we propose a novel green list stealing attack against the state-of-the-art LLM watermark scheme and systematically examine its vulnerability to this attack. We formalize the attack as a mixed integer programming problem with constraints. We evaluate our attack under a comprehensive threat model, including an extreme scenario where the attacker has no prior knowledge, lacks access to the watermark detector API, and possesses no information about the LLM’s parameter settings or watermark injection/detection scheme. Extensive experiments on LLMs, such as OPT and LLaMA, demonstrate that our attack can successfully steal the green list and remove the watermark across all settings. Zhaoxi Zhang 0001, Xiaomei Zhang 0001, Yanjun Zhang 0002, Leo Yu Zhang, Chao Chen 0015, Shengshan Hu, Asif Gill, Shirui Pan |
ACSAC | 3 |
| 2024 | PointAPA: Towards Availability Poisoning Attacks in 3D Point Clouds
Xianlong Wang 0001, Peng Xu 0003, Wei Liu 0304, Leo Yu Zhang, Shengshan Hu, Yanjun Zhang 0002 |
ESORICS (1) | 7 |
| 2024 | Are Your Requests Your True Needs? Checking Excessive Data Collection in VPA AppabstractVirtual personal assistants (VPA) services encompass a large number of third-party applications (or apps) to enrich their functionalities. These apps have been well examined to scrutinize their data collection behaviors against their declared privacy policies. Nonetheless, it is often overlooked that most users tend to ignore privacy policies at the installation time. Dishonest developers thus can exploit this situation by embedding excessive declarations to cover their data collection behaviors during compliance auditing. Fuman Xie, Chuan Yan, Mark Huasong Meng, Shao-Ming Teng, Yanjun Zhang 0002, Guangdong Bai |
ICSE | 5 |
| 2024 | Detector Collapse: Backdooring Object Detection to Catastrophic Overload or Blindness in the Physical World
Hangtao Zhang, Shengshan Hu, Yichen Wang 0013, Leo Yu Zhang, Ziqi Zhou 0001, Xianlong Wang 0001, Yanjun Zhang 0002, Chao Chen 0015 |
IJCAI | 7 |
| 2024 | Bounded and Unbiased Composite Differential PrivacyabstractThe objective of differential privacy (DP) is to protect privacy by producing an output distribution that is indistinguishable between any two neighboring databases. However, traditional differentially private mechanisms tend to produce unbounded outputs in order to achieve maximum disturbance range, which is not always in line with real-world applications. Existing solutions attempt to address this issue by employing post-processing or truncation techniques to restrict the output results, but at the cost of introducing bias issues. In this paper, we propose a novel differentially private mechanism which uses a composite probability density function to generate bounded and unbiased outputs for any numerical input data. The composition consists of an activation function and a base function, providing users with the flexibility to define the functions according to the DP constraints. We also develop an optimization algorithm that enables the iterative search for the optimal hyper-parameter setting without the need for repeated experiments, which prevents additional privacy overhead. Furthermore, we evaluate the utility of the proposed mechanism by assessing the variance of the composite probability density function and introducing two alternative metrics that are simpler to compute than variance estimation. Our extensive evaluation on three benchmark datasets demonstrates consistent and significant improvement over the traditional Laplace and Gaussian mechanisms. The proposed bounded and unbiased composite differentially private mechanism will underpin the broader DP arsenal and foster future privacy-preserving studies. Kai Zhang 0074, Yanjun Zhang 0002, Ruoxi Sun 0001, Pei-Wei Tsai, Muneeb Ul Hassan 0001, Xin Yuan 0004, Minhui Xue 0001, Jinjun Chen |
SP | 2 |
| 2024 | Privacy-Preserving and Fairness-Aware Federated Learning for Critical Infrastructure Protection and ResilienceabstractThe energy industry is undergoing significant transformations as it strives to achieve net-zero emissions and future-proof its infrastructure, where every participant in the power grid has the potential to both consume and produce energy resources. Federated learning -- which enables multiple participants to collaboratively train a model without aggregating the training data -- becomes a viable technology. However, the global model parameters that have to be shared for optimization are still susceptible to training data leakage. In this work, we propose confined gradient descent (CGD) that enhances the privacy of federated learning by eliminating the sharing of global model parameters. CGD exploits the fact that a gradient descent optimization can start with a set of discrete points and converges to another set in the neighborhood of the global minimum of the objective function. As such, each participant can independently initiate its own private global model~(referred to as the confined model ), and collaboratively learn it towards the optimum. The updates to their own models are worked out in a secure collaborative way during the training process.In such a manner, CGD retains the ability of learning from distributed data but greatly diminishes information sharing. Such a strategy also allows the proprietary confined models to adapt to the heterogeneity in federated learning, providing inherent benefits of fairness. We theoretically and empirically demonstrate that decentralized CGD øne provides a stronger differential privacy (DP) protection; \two is robust against the state-of-the-art poisoning privacy attacks; þree results in bounded fairness guarantee among participants; and \four provides high test accuracy (comparable with centralized learning) with a bounded convergence rate over four real-world datasets. Yanjun Zhang 0002, Ruoxi Sun 0001, Liyue Shen, Guangdong Bai, Minhui Xue 0001, Mark Huasong Meng, Xue Li 0001, Ryan Kok Leong Ko, Surya Nepal |
WWW | 1 |
| 2024 | On the Quality of Privacy Policy Documents of Virtual Personal Assistant ApplicationsabstractAn app ecosystem built around virtual personal assistant (VPA) services becomes flourishing in recent years, fueled by the booming of the Internet of Things (IoT). A large number of functionality-rich VPA applications (or apps for short) have been released through app stores, and become easily-accessible by users through their smart speakers. In response to the increasingly stringent data protection regulations around the world, VPA service providers require app developers to include a privacy policy that declares their data handling practices. These privacy policies serve as the de facto agreement between developers and users, and may be taken as the basis in resolving conflicts in the event of a data breach. Therefore, it is essential that privacy policy documents are crafted in a clear, easy-to-understand, and unambiguous way. In this work, we conduct the first systematic study on the quality of privacy policies in the VPA app domain. Based on our review of literature and documents from standard working groups, we identify four metrics that enable the quality of the privacy policy to become measurable, including timeliness, availability, completeness and readability. We then develop QuPer, which extracts the meta features (e.g., update history) and linguistic features (e.g., sentence semantics) from privacy policies, and assesses their quality. Our analysis reveals that the status of the quality of privacy policies in the VPA app domain is concerning. For instance, only 1.17% of privacy policies completely cover all contents that are regarded as privacy concerns by legislation (e.g., GDPR article 13) and relevant literature. Our findings are expected to raise an alert among the VPA app developers and provide them with guidelines for creating high-quality privacy policy documents. We also encourage app store operators to implement a vetting process that ensures the quality of privacy policies before apps are released to the public. Chuan Yan, Fuman Xie, Mark Huasong Meng, Yanjun Zhang 0002, Guangdong Bai |
Proc. Priv. Enhancing Technol. | 4 |
| 2024 | AgrAmplifier: Defending Federated Learning Against Poisoning Attacks Through Local Update AmplificationabstractThe collaborative nature of federated learning (FL) poses a major threat in the form of manipulation of local training data and local updates, known as the Byzantine poisoning attack. To address this issue, many Byzantine-robust aggregation rules (AGRs) have been proposed to filter out or moderate suspicious local updates uploaded by Byzantine participants. This paper introduces a novel approach called AGRAMPLIFIER, aiming to simultaneously improve robustness, fidelity, and efficiency of the existingAGRs. The core idea of AGRAMPLIFIER is to amplify the “morality” of local updates by identifying the most repressive features of each gradient update, which provides a clearer distinction between malicious and benign updates, consequently improving the detection effect. To achieve this objective, two approaches, namelyAGRMPandAGRXAI, are proposed.AGRMPorganizes local updates into patches and extracts the largest value from each patch, whileAGRXAIleverages explainable AI methods to extract the gradient of the most activated features. By equipping AGRAMPLIFIER with the existing Byzantine-robust mechanisms, we successfully enhance the model robustness, maintaining its fidelity and improving overall efficiency. AGRAMPLIFIER is universally compatible with the existing Byzantine-robust mechanisms. The paper demonstrates its effectiveness by integrating it with all mainstreamAGRmechanisms. Extensive evaluations conducted on seven datasets from diverse domains against seven representative poisoning attacks consistently show enhancements in robustness, fidelity, and efficiency, with average gains of 40.08%, 39.18%, and 10.68%, respectively. Zirui Gong, Liyue Shen, Yanjun Zhang 0002, Leo Yu Zhang, Jingwei Wang 0003, Guangdong Bai, Yong Xiang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Investigating Users' Understanding of Privacy Policies of Virtual Personal Assistant ApplicationsabstractThe increasingly popular virtual personal assistant (VPA) services, e.g., Amazon Alexa and Google Assistant, enable third-party developers to create and release VPA apps for end users to access through smart speakers. Given that VPA apps handle sensitive personal data, VPA service providers require developers to release a privacy policy document to declare their data handling practice. The privacy policies are regarded as legal or semi-legal documents, which are usually lengthy and complex for users to understand. In this work, we conducted a subjective study to investigate the level of users’ understanding of the privacy policies, targeting the VPA apps (i.e., skills) of Amazon Alexa, the most popular VPA service. Our study focused on technical terms, one of the greatest hurdles to users’ understanding. We found that 84.2% of our participants faced difficulty in understanding technical terms appeared in the skills’ privacy policies, even for participants with IT background. Additionally, 64.3% of them reported that explanations for the technical terms are generally lacking. To address this issue, we proposed two principles, i.e., domain-specificity principle and implication-oriented principle, to guide skill developers in creating easy-to-understand privacy policies. We evaluated their effectiveness by creating explanation sentences for 23 representative terms and examining users’ understanding through a second user study. Our results show that using explanation sentences based on these principles can significantly improve users’ understanding. Baiqi Chen, Tingmin Wu, Yanjun Zhang 0002, Mohan Baruwal Chhetri, Guangdong Bai |
AsiaCCS | 3 |
| 2023 | LoDen: Making Every Client in Federated Learning a Defender Against the Poisoning Membership Inference AttacksabstractFederated learning (FL) is a widely used distributed machine learning framework. However, recent studies have shown its susceptibility to poisoning membership inference attacks (MIA). In MIA, adversaries maliciously manipulate the local updates on selected samples and share the gradients with the server (i.e., poisoning). Since honest clients perform gradient descent on samples locally, an adversary can distinguish whether the attacked sample is a training sample based on observation of the change of the sample’s prediction. This type of attack exacerbates traditional passive MIA, yet the defense mechanisms remain largely unexplored. Mengyao Ma, Yanjun Zhang 0002, Mahawaga Arachchige Pathum Chamikara, Leo Yu Zhang, Mohan Baruwal Chhetri, Guangdong Bai |
AsiaCCS | 2 |
| 2023 | Masked Language Model Based Textual Adversarial Example DetectionabstractAdversarial attacks are a serious threat to the reliable deployment of machine learning models in safety-critical applications. They can misguide current models to predict incorrectly by slightly modifying the inputs. Recently, substantial work has shown that adversarial examples tend to deviate from the underlying data manifold of normal examples, whereas pre-trained masked language models can fit the manifold of normal NLP data. To explore how to use the masked language model in adversarial detection, we propose a novel textual adversarial example detection method, namely Masked Language Model-based Detection (MLMD), which can produce clearly distinguishable signals between normal examples and adversarial examples by exploring the changes in manifolds induced by the masked language model. MLMD features a plug and play usage (i.e., no need to retrain the victim model) for adversarial defense and it is agnostic to classification tasks, victim model’s architectures, and to-be-defended attack methods. We evaluate MLMD on various benchmark textual datasets, widely studied machine learning models, and state-of-the-art (SOTA) adversarial attacks (in total 3*4*4 = 48 settings). Experimental results show that MLMD can achieve strong performance, with detection accuracy up to 0.984, 0.967, and 0.901 on AG-NEWS, IMDB, and SST-2 datasets, respectively. Additionally, MLMD is superior, or at least comparable to, the SOTA detection defenses in detection accuracy and F1 score. Among many defenses based on the off-manifold assumption of adversarial examples, this work offers a new angle for capturing the manifold change. The code for this work is openly accessible at https://github.com/mlmddetection/MLMDdetection. Xiaomei Zhang 0001, Zhaoxi Zhang 0001, Xufei Zheng, Yanjun Zhang 0002, Shengshan Hu, Leo Yu Zhang |
AsiaCCS | 5 |
| 2023 | Post-GDPR Threat Hunting on Android Phones: Dissecting OS-level Safeguards of User-unresettable Identifiers
Mark Huasong Meng, Zhang Qing cnwatcher, Guangshuai Xia, Yuwei Zheng, Yanjun Zhang 0002, Guangdong Bai, Sin G. Teo, Jin Song Dong 0001 |
NDSS | 5 |
| 2023 | AgrEvader: Poisoning Membership Inference against Byzantine-robust Federated LearningabstractThe Poisoning Membership Inference Attack (PMIA) is a newly emerging privacy attack that poses a significant threat to federated learning (FL). An adversary conducts data poisoning (i.e., performing adversarial manipulations on training examples) to extract membership information by exploiting the changes in loss resulting from data poisoning. The PMIA significantly exacerbates the traditional poisoning attack that is primarily focused on model corruption. However, there has been a lack of a comprehensive systematic study that thoroughly investigates this topic. In this work, we conduct a benchmark evaluation to assess the performance of PMIA against the Byzantine-robust FL setting that is specifically designed to mitigate poisoning attacks. We find that all existing coordinate-wise averaging mechanisms fail to defend against the PMIA, while the detect-then-drop strategy was proven to be effective in most cases, implying that the poison injection is memorized and the poisonous effect rarely dissipates. Inspired by this observation, we propose AgrEvader, a PMIA that maximizes the adversarial impact on the victim samples while circumventing the detection by Byzantine-robust mechanisms. AgrEvader significantly outperforms existing PMIAs. For instance, AgrEvader achieved a high attack accuracy of between 72.78% (on CIFAR-10) to 97.80% (on Texas100), which is an average accuracy increase of 13.89% compared to the strongest PMIA reported in the literature. We evaluated AgrEvader on five datasets across different domains, against a comprehensive list of threat models, which included black-box, gray-box and white-box models for targeted and non-targeted scenarios. AgrEvader demonstrated consistent high accuracy across all settings tested. The code is available at: https://github.com/PrivSecML/AgrEvader. Yanjun Zhang 0002, Guangdong Bai, Mahawaga Arachchige Pathum Chamikara, Mengyao Ma, Liyue Shen, Jingwei Wang 0003, Surya Nepal, Minhui Xue 0001, Joseph K. Liu |
WWW | 1 |
| 2023 | Preserving Privacy for Distributed Genome-Wide Analysis Against Identity Tracing AttacksabstractGenome-wide analysis has demonstrated both health and social benefits. However, large scale sharing of such data may reveal sensitive information about individuals. One of the emerging challenges is identity tracing attack that exploits correlations among genomic data to reveal the identity of DNA samples. In this paper, we first demonstrate that the adversary can narrow down the sample's identity by detecting his/her genetic relatives and quantify such privacy threat by employing a Shannon entropy-based measurement. For example, we exemplify that when the dataset size reaches 30% of the population, for any target from that population, the uncertainty of the target's identity is reduced to merely 2.3 bits of entropy (i.e., the identity is pinned down within 5 people). Direct application of existing approaches such as differential privacy (DP), secure multiparty computation (MPC) and homomorphic encryption (HE) may not be applicable to this challenge in genome-wide analysis because of the compromise on utility (i.e., accuracy or efficiency). Towards addressing this challenge, this paper proposes a framework named$\upsilon$Fragto facilitate privacy-preserving data sharing and computation in genome-wide analysis.$\upsilon$Fragmitigates privacy risks by using a vertical fragmentation to disrupt the genetic architecture on which the adversary relies for identity tracing without sacrificing the capability of genome-wide analysis. We theoretically prove that it preserves the correctness of the primitive functionalities and algorithms ranging from basic summary statistics to advanced neural networks. Our experiments demonstrate that$\upsilon$Fragoutperforms secure multiparty computation (MPC) and homomorphic encryption (HE) protocols, with a speedup of more than 221x for training neural networks, and also traditional non-private algorithms and a state-of-the-art noise-based differential privacy (DP) solution in most settings. Yanjun Zhang 0002, Guangdong Bai, Xue Li 0001, Surya Nepal, Marthie Grobler, Chen Chen 0056, Ryan Kok Leong Ko |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Better Together: Attaining the Triad of Byzantine-robust Federated Learning via Local Update AmplificationabstractManipulation of local training data and local updates, i.e., the Byzantine poisoning attack, is the main threat arising from the collaborative nature of the federated learning (FL) paradigm. Many Byzantine-robust aggregation algorithms (AGRs) have been proposed to filter out or moderate suspicious local updates uploaded by Byzantine participants at the central aggregator. However, they largely suffer from model quality degradation due to the over-removal of local updates or/and the inefficiency caused by the expensive analysis of the high-dimensional local updates. Liyue Shen, Yanjun Zhang 0002, Jingwei Wang 0003, Guangdong Bai |
ACSAC | 2 |
| 2022 | SATB: A Testbed of IoT-Based Smart Agriculture Network for Dataset Generation
Liuhuo Wan, Yanjun Zhang 0002, Ryan Kok Leong Ko, Louwrens Christiaan Hoffman, Guangdong Bai |
ADMA (1) | 2 |
| 2022 | Scrutinizing Privacy Policy Compliance of Virtual Personal Assistant AppsabstractA large number of functionality-rich and easily accessible applications have become popular among various virtual personal assistant (VPA) services such as Amazon Alexa. VPA applications (or VPA apps for short) are accompanied by a privacy policy document that informs users of their data handling practices. These documents are usually lengthy and complex for users to comprehend, and developers may intentionally or unintentionally fail to comply with them. In this work, we conduct the first systematic study on the privacy policy compliance issue of VPA apps. We develop Skipper, which targets Amazon Alexa skills. It automatically depicts the skill into the declared privacy profile by analyzing their privacy policy documents with Natural Language Processing (NLP) and machine learning techniques, and derives the behavioral privacy profile of the skill through a black-box testing. We conduct a large-scale analysis on all skills listed on Alexa store, and find that a large number of skills suffer from the privacy policy noncompliance issues. Fuman Xie, Yanjun Zhang 0002, Chuan Yan, Suwan Li, Lei Bu, Kai Chen 0012, Zi Huang, Guangdong Bai |
ASE | 2 |
| 2022 | Detecting Contradictions from CoAP RFC Based on Knowledge Graph
Xinguo Feng, Yanjun Zhang 0002, Mark Huasong Meng, Sin G. Teo |
NSS | 2 |
| 2022 | Towards Better Generalization for Neural Network-Based SAT Solvers
Chenhao Zhang 0004, Yanjun Zhang 0002, Jeff Mao, Weitong Chen 0001, Lin Yue, Guangdong Bai, Miao Xu 0001 |
PAKDD (2) | 2 |
| 2021 | UQ-AAS21: A Comprehensive Dataset of Amazon Alexa Skills
Fuman Xie, Yanjun Zhang 0002, Hanlin Wei, Guangdong Bai |
ADMA | 2 |
| 2021 | Privacy-Preserving Gradient Descent for Distributed Genome-Wide Analysis
Yanjun Zhang 0002, Guangdong Bai, Xue Li 0001, Caitlin Curtis, Chen Chen 0056, Ryan Kok Leong Ko |
ESORICS (2) | 1 |
| 2021 | Identifying privacy weaknesses from multi-party trigger-action integration platformsabstractWith many trigger-action platforms that integrate Internet of Things (IoT) systems and online services, rich functionalities transparently connecting digital and physical worlds become easily accessible for the end users. On the other hand, such facilities incorporate multiple parties whose data control policies may radically differ and even contradict each other, and thus privacy violations may arise throughout the lifecycle (e.g., generation and transmission) of triggers and actions. In this work, we conduct an in-depth study on the privacy issues in multi-party trigger-action integration platforms (TAIPs). We first characterize privacy violations that may arise with the integration of heterogeneous systems and services. Based on this knowledge, we propose Taifu, a dynamic testing approach to identify privacy weaknesses from the TAIP. The key insight of Taifu is that the applets which actually program the trigger-action rules can be used as test cases to explore the behavior of the TAIP. We evaluate the effectiveness of our approach by applying it on the TAIPs that are built around the IFTTT platform. To our great surprise, we find that privacy violations are prevalent among them. Using the automatically generated 407 applets, each from a different TAIP, Taifu detects 194 cases with access policy breaches, 218 access control missing, 90 access revocation missing, 15 unintended flows, and 73 over-privilege access. Kulani Mahadewa, Yanjun Zhang 0002, Guangdong Bai, Lei Bu, Zhiqiang Zuo 0002, Dileepa Fernando, Zhenkai Liang, Jin Song Dong 0001 |
ISSTA | 2 |
| 2020 | PrivColl: Practical Privacy-Preserving Collaborative Machine Learning
Yanjun Zhang 0002, Guangdong Bai, Xue Li 0001, Caitlin Curtis, Chen Chen 0056, Ryan Kok Leong Ko |
ESORICS (1) | 1 |
| 2019 | Enabling Privacy-Preserving Sharing of Genomic Data for GWASs in Decentralized NetworksabstractThe human genome can reveal sensitive information and is potentially re-identifiable, which raises privacy and security concerns about sharing such data on wide scales. In this work, we propose a preventive approach for privacy-preserving sharing of genomic data in decentralized networks for Genome-wide association studies (GWASs), which have been widely used in discovering the association between genotypes and phenotypes. The key components of this work are: a decentralized secure network, with a privacy- preserving sharing protocol, and a gene fragmentation framework that is trainable in an end-to-end manner. Our experiments on real datasets show the effectiveness of our privacy-preserving approaches as well as significant improvements in efficiency when compared with recent, related algorithms. Yanjun Zhang 0002, Xin Zhao 0013, Xue Li 0001, Mingyang Zhong, Caitlin Curtis, Chen Chen 0056 |
WSDM | 1 |
| 2018 | Automated Explanations of User-Expected Trends for Aggregate Queries
Ibrahim A. Ibrahim, Xue Li 0001, Xin Zhao 0013, Sanad Al-Maskari, Abdullah M. Albarrak, Yanjun Zhang 0002 |
PAKDD (1) | 6 |