Hongjiao Li

dblp:25/4616 · DBLP profile ↗
← Back
15ranked-venue papers
3as first author
13since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Systems, architecture and hardware · 3 · 2 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021Computer networks · 1Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Contrast and adversarial: Towards generalized multi-modal face anti-spoofing
Hongjiao Li
Eng. Appl. Artif. Intell.2
2026 SemAlign-PFL:Exploring stealthy and persistent backdoor attacks against personalized federated learning
Yalong Wang, Hongjiao Li
J. Inf. Secur. Appl.2
2026 DADP: a discrepancy-aware dual-path network for AI-generated image detection
Hongjiao Li
Multim. Syst.2
2025 D3FL: Label-Free and Heterogeneity-Robust Defense for Federated Learning via Distilled Reference Model against Data Poisoning Attacks
abstract
Federated learning enables privacy-preserving model training but remains vulnerable to data poisoning, where malicious clients manipulate local data to induce targeted misclassification. Existing defenses often assume that (i) benign updates are mutually consistent and (ii) labeled data are available for anomaly detection. These assumptions rarely hold under realistic non-IID distributions and unlabeled settings, leading to false detection and degraded robustness. To address these challenges, we propose D3FL, a label-free and heterogeneity-robust defense framework that detects anomalies through client–reference discrepancy analysis. Instead of inter-client comparisons, D3FL distills a student model from the global model and consensus client predictions, constructing a trusted reference model that encapsulates reliable client knowledge. A multi-perspective inconsistency evaluation then quantifies prediction anomalies, feature deviations, and parameter discrepancies, accurately distinguishing benign heterogeneity from malicious manipulation. To remove label dependence, a voting-based consensus mechanism selects high-confidence client predictions to refine the reference model via distillation. Moreover, a dynamically adaptive aggregation strategy integrates real-time consistency with historical trust, continuously adjusting client contributions to maintain robustness throughout training. Extensive experiments on Fashion-MNIST and CIFAR-10 under non-IID settings demonstrate that D3FL achieves strong robustness against data poisoning without requiring any labeled clean data.
Hongliang Yin, Hongjiao Li
TrustCom2
2025 SS-LDP: A Framework for Sparse Streaming Data Collection Based on Local Differential Privacy
abstract
ABSTRACT The continuous collection of streaming data in the Internet of Things (IoT) may compromise user privacy, as such data often originates from personal information. Local differential privacy (LDP) is a novel privacy notion that offers a strong privacy guarantee to all users without relying on a trusted data collector. However, existing LDP‐based studies mainly focus on static scenarios or perturbation of data points at a single timestamp without sufficiently considering data sparsity, which adds excessive noise and leads to low utility. Therefore, we propose a Framework for Sparse Streaming Data Collection based on Local Differential Privacy (SS‐LDP), which aims to provide high utility at each timestamp while satisfying ‐event LDP. One component is the introduction of an upper‐bound optimization mechanism, which reduces the noise scale by combining error minimization with the gradient descent method. Another component of SS‐LDP targets the efficient management of privacy resources through two specific strategies. First, significant changes in streaming data are captured by calculating differences between the latest few data points, thereby conserving the privacy budget. Second, an improved sparse privacy budget allocation mechanism quantifies data sparsity at each timestamp using the moving average method, enabling efficient allocation of the privacy budget for each timestamp. SS‐LDP is evaluated using two real‐world datasets and compared with four baseline methods that satisfy ‐event privacy. Extensive experiments and theoretical analyses are conducted to demonstrate the superiority of our framework.
Hongjiao Li, Zhenya Shi, Anyang Yin
Concurr. Comput. Pract. Exp.1
2025 Domain generalization for multi-modal face anti-spoofing via MixCropMask Augmentation and deep hybrid-level fusion
Botao Zhang 0006, Hongjiao Li
Eng. Appl. Artif. Intell.2
2025 FLGT: label-flipping-robust federated learning via guiding trust
Hongjiao Li, Zhenya Shi, Anyang Yin
Knowl. Inf. Syst.1
2025 Personalized federated learning via multifaceted feature matching and element-wise classifier fusion
Yijun Cao, Hongjiao Li, Botao Zhang 0006, Ning Xue, Hongliang Yin
Multim. Syst.2
2025 Interpretable localization of false data injection attacks in smart grids: a multi-head graph convolutional attention network approach
Hongjiao Li, Botao Zhang 0006, Ning Xue, Hongliang Yin, Yijun Cao
J. Supercomput.2
2025 Personalized federated learning with global information fusion and local knowledge inheritance collaboration
Hongjiao Li, Anyang Yin
J. Supercomput.1
2024 Federated learning on non-IID and long-tailed data via dual-decoupling
abstract
Federated learning (FL), a cutting-edge distributed machine learning training paradigm, aims to generate a global model by collaborating on the training of client models without revealing local private data. The cooccurrence of non-independent and identically distributed (non-IID) and long-tailed distribution in FL is one challenge that substantially degrades aggregate performance. In this paper, we present a corresponding solution called federated dual-decoupling via model and logit calibration (FedDDC) for non-IID and long-tailed distributions. The model is characterized by three aspects. First, we decouple the global model into the feature extractor and the classifier to fine-tune the components affected by the joint problem. For the biased feature extractor, we propose a client confidence re-weighting scheme to assist calibration, which assigns optimal weights to each client. For the biased classifier, we apply the classifier re-balancing method for fine-tuning. Then, we calibrate and integrate the client confidence re-weighted logits with the re-balanced logits to obtain the unbiased logits. Finally, we use decoupled knowledge distillation for the first time in the joint problem to enhance the accuracy of the global model by extracting the knowledge of the unbiased model. Numerous experiments demonstrate that on non-IID and long-tailed data in FL, our approach outperforms state-of-the-art methods.
Hongjiao Li, Jinguo Li, Renhao Hu, Baojin Wang
Frontiers Inf. Technol. Electron. Eng.2
2024 Continuous release of temporal correlation location statistics with local differential privacy
Renhao Hu, Hongjiao Li, Jinguo Li, Baojin Wang
Multim. Tools Appl.2
2022 Image forgery localization based on fully convolutional network with noise feature
Qiuxu Liu, Hongjiao Li
Multim. Tools Appl.2
2019 Secure, flexible and high-efficient similarity search over encrypted data in multiple clouds
Jinguo Li, Mi Wen, Kui Wu 0001, Kejie Lu, Fengyong Li, Hongjiao Li
Peer-to-Peer Netw. Appl.6
2009 Network Intrusion Detection with Workflow Feature Definition Using BP Neural Network
Dawu Gu, Wei Li 0013, Hongjiao Li
ISNN (1)4