Faqian Guan

dblp:249/8013 · DBLP profile ↗
← Back
12ranked-venue papers
8as first author
11since 2021 · last 2026
0000-0002-5701-8311ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 5 · 4 first-author · 4 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 T-MIA: A membership inference attack via timing side-channel and possible defense scheme
Faqian Guan, Wei Ren 0002, Tianqing Zhu
Inf. Sci.2
2026 Graph unlearning: Efficient node removal in graph neural networks
Faqian Guan, Tianqing Zhu, Zhoutian Wang, Wei Ren 0002, Wanlei Zhou 0001
Knowl. Based Syst.1
2026 Cross-camera reliability modeling with soft contrastive learning for unsupervised person re-identification
Yongyi Xiao, Tianqing Zhu, Faqian Guan, Jiayan Huang, Antoni Grau-Saldes
Knowl. Based Syst.3
2026 Zero-Shot Class Unlearning via Layer-Wise Relevance Analysis and Neuronal Path Perturbation
abstract
Machine unlearning is a technique that removes specific data influences from trained models without the need for extensive retraining. However, it faces several key challenges, including the lack of explanation, privacy concerns during the unlearning process, and the high demand for time and computational resources. This paper presents a novel unlearning approach to tackle above challenges by employing Layer-wise Relevance Analysis and Neuronal Path Perturbation. Our method balances machine unlearning performance and model utility by identifying and perturbing highly relevant neurons, thus achieving effective unlearning. Using unseen data that has not been presented in the original training set, our method achieves zero-shot unlearning, which allows for the removal of specific class knowledge without accessing the original training data during the unlearning process. This approach ensures robust privacy protection. Experimental results demonstrate that our approach effectively removes targeted data from the target unlearning model while maintaining the model's utility, offering a practical solution for privacy-preserving machine learning. Our code is available athttps://github.com/ChangWenhan/LRA-NPP-Unlearning
Wenhan Chang, Tianqing Zhu, Ping Xiong 0001, Faqian Guan, Wanlei Zhou 0001
IEEE Trans. Dependable Secur. Comput.5
2025 Neighbor Information Fusion with a Real-Time Update Strategy for Unsupervised Person Re-Identification
abstract
Unsupervised person Re-Identification (Re-ID) has made notable progress through various methods that rely on clustering to generate pseudo-labels. Among these, memory-based contrastive learning has become a widely used approach in unsupervised representation learning. Previous work mainly focused on improving the quality of pseudo-labels and enhancing the robustness of representation learning. However, performance in complex scenarios remains limited, and the role of contextual semantic information is still underexplored. To address this gap, we propose a simple yet effective framework that integrates a Graph Convolutional Network (GCN) to estimate similarity, aggregate neighborhood information, and incorporate hard pseudo-labels. This enables the model to leverage semantic relationships across different contexts, resulting in more robust representations. In addition, we identify a limitation in conventional momentumbased memory updates, which can hinder contrastive learning. To overcome this, we introduce a real-time memory update strategy that replaces momentum with the average feature vector from the current mini-batch to update cluster centroids. This ensures that the features of each cluster are up-to-date. Extensive experiments on the three benchmark datasets of Market1501, DukeMTMC, and MSMT17 have shown that our method achieves substantial performance gains in unsupervised pedestrian re-identification. These findings offer both theoretical insights and practical benefits for the broader fields of model recognition and person re-identification.
Yongyi Xiao, Faqian Guan, Jiayan Huang, Antoni Grau-Saldes
BIBM2
2025 Large Language Models for Link Stealing Attacks Against Graph Neural Networks
abstract
Graph data contains rich node features and unique edge information, which have been applied across various domains, such as citation networks or recommendation systems. Graph Neural Networks (GNNs) are specialized for handling such data and have shown impressive performance in many applications. However, GNNs may contain of sensitive information and susceptible to privacy attacks. For example, link stealing is a type of attack in which attackers infer whether two nodes are linked or not. Previous link stealing attacks primarily relied on posterior probabilities from the target GNN model, neglecting the significance of node features. Additionally, variations in node classes across different datasets lead to different dimensions of posterior probabilities. The handling of these varying data dimensions posed a challenge in using a single model to effectively conduct link stealing attacks on different datasets. To address these challenges, we introduce Large Language Models (LLMs) to perform link stealing attacks on GNNs. LLMs can effectively integrate textual features and exhibit strong generalizability, enabling attacks to handle diverse data dimensions across various datasets. We design two distinct LLM prompts to effectively combine textual features and posterior probabilities of graph nodes. Through these designed prompts, we fine-tune the LLM to adapt to the link stealing attack task. Furthermore, we fine-tune the LLM using multiple datasets and enable the LLM to learn features from different datasets simultaneously. Experimental results show that our approach significantly enhances the performance of existing link stealing attack tasks in both white-box and black-box scenarios. Our method can execute link stealing attacks across different datasets using only a single model, making link stealing attacks more applicable to real-world scenarios.
Faqian Guan, Tianqing Zhu, Wanlei Zhou 0001, Philip S. Yu
IEEE Trans. Big Data1
2025 Topology-Based Node-Level Membership Inference Attacks on Graph Neural Networks
abstract
Graph neural networks (GNNs) have obtained considerable attention due to their ability to leverage the inherent topological and node information present in graph data. While extensive research has been conducted on privacy attacks targeting machine learning models, the exploration of privacy risks associated with node-level membership inference attacks on GNNs remains relatively limited. GNNs learn representations that encapsulate valuable information about the nodes. These learned representations can be exploited by attackers to infer whether a specific node belongs to the training dataset, leading to the disclosure of sensitive information. The insidious nature of such privacy breaches often leads to an underestimation of the associated risks. Furthermore, the inherent challenges posed by node membership inference attacks make it difficult to develop effective attack models for GNNs that can successfully infer node membership. We propose a more efficient approach that specifically targets node-level membership inference attacks on GNNs. Initially, we combine nodes and their respective neighbors to carry out node membership inference attacks. To address the challenge of variable-length features arising from the differing number of neighboring nodes, we introduce an effective feature processing strategy. Furthermore, we propose two strategies: multiple training of shadow models and random selection of non-membership data, to enhance the performance of the attack model. We empirically evaluate the efficacy of our proposed method using three benchmark datasets. Additionally, we explore two potential defense mechanisms against node-level membership inference attacks.
Faqian Guan, Tianqing Zhu, Wanlei Zhou 0001, Philip S. Yu
IEEE Trans. Big Data1
2025 Large Language Models Merging for Enhancing the Link Stealing Attack on Graph Neural Networks
abstract
Graph Neural Networks (GNNs), specifically designed to process the graph data, have achieved remarkable success in various applications. Link stealing attacks on graph data pose a significant privacy threat, as attackers aim to extract sensitive relationships between nodes (entities), potentially leading to academic misconduct, fraudulent transactions, or other malicious activities. Previous studies have primarily focused on single datasets and did not explore cross-dataset attacks, let alone attacks that leverage the combined knowledge of multiple attackers. However, we find that an attacker can combine the data knowledge of multiple attackers to create a more effective attack model, which can be referred to cross-dataset attacks. Moreover, if knowledge can be extracted with the help of Large Language Models (LLMs), the attack capability will be more significant. In this paper, we propose a novel link stealing attack method that takes advantage of cross-dataset and LLMs. The LLM is applied to process datasets with different data structures in cross-dataset attacks. Each attacker fine-tunes the LLM on their specific dataset to generate a tailored attack model. We then introduce a novel model merging method to integrate the parameters of these attacker-specific models effectively. The result is a merged attack model with superior generalization capabilities, enabling effective attacks not only on the attackers' datasets but also on previously unseen (out-of-domain) datasets. We conducted extensive experiments in four datasets to demonstrate the effectiveness of our method. Additional experiments with three different GNN and LLM architectures further illustrate the generality of our approach. In summary, we present a new link stealing attack method that facilitates collaboration among multiple attackers to develop a powerful, universal attack model that reflects realistic real-world scenarios.
Faqian Guan, Tianqing Zhu, Wenhan Chang, Wei Ren 0002, Wanlei Zhou 0001
IEEE Trans. Dependable Secur. Comput.1
2025 Attention-Based Membership Inference Attacks on Graph Neural Network Through Topological Features
abstract
Graph Neural Networks (GNNs), a type of machine learning model has been widely used in social networks, drug recommendations, and various other domains. While GNNs provide significant benefits, they also raise privacy concerns such as membership inference attack, posing a substantial risk to the private training data of GNNs. Previous studies have demonstrated that GNNs are susceptible to membership inference attacks, revealing private information about the training graph. However, these studies overlook the challenges of training data imbalance and a small number of training datasets in node-level membership inference attacks. Additionally, they under-utilize the topological features of the graph, resulting in sub-optimal performance of the attack models. In this paper, we find that by using attention mechanism, attackers have higher attack accuracy on the node-level membership inference attacks. This is because attention mechanism assigns different weights to neighboring nodes based on their contribution to the membership inference attack. To implement the attack, first, we tackle the training data imbalance issue through a random selection strategy. Second, we propose a data augmentation method exclusively tailored for membership inference attacks to address the problem of small datasets in node-level membership inference attacks. Next, we leverage the topological features of the graph and introduce two different feature padding strategies in feature processing. Finally, we employ the attention mechanism to assign different weights to neighboring nodes, enhancing the accuracy of the attack. We evaluate our proposed method on three datasets and three different GNN models, and the experimental results consistently demonstrate outstanding performance
Faqian Guan, Tianqing Zhu, Hanjin Tong, Wanlei Zhou 0001
IEEE Trans. Dependable Secur. Comput.1
2024 A realistic model extraction attack against graph neural networks
Faqian Guan, Tianqing Zhu, Hanjin Tong, Wanlei Zhou 0001
Knowl. Based Syst.1
2024 Topology modification against membership inference attack in Graph Neural Networks
Faqian Guan, Tianqing Zhu, Hanjin Tong, Wanlei Zhou 0001
Knowl. Based Syst.1
2019 A GAN Model With Self-attention Mechanism To Generate Multi-instruments Symbolic Music
abstract
GAN has recently been proved to be able to generate symbolic music in the form of piano-rolls. However, those existing GAN-based multi-track music generation methods are always unstable. Moreover, due to defects in the temporal features extraction, the generated multi-track music does not sound natural enough. Therefore, we propose a new GAN model with self-attention mechanism, DMB-GAN, which can extract more temporal features of music to generate multi-instruments music stably. First of all, to generate more consistent and natural single-track music, we introduce self-attention mechanism to enable GAN-based music generation model to extract not only spatial features but also temporal features. Secondly, to generate multi-instruments music with harmonic structure among all tracks, we construct a dual generative adversarial architecture with multi-branches, each branch for one track. Finally, to improve generated quality of multi-instruments symbolic music, we introduce switchable normalization to stabilize network training. The experimental results show that DMB-GAN can stably generate coherent, natural multi-instruments music with good quality.
Faqian Guan, Chunyan Yu, Suqiong Yang
IJCNN1