VLDB 2026 Research / reviewers in the wild / expert
Wenhan Chang
dblp:251/1360
· DBLP profile ↗
8ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0003-3350-5171ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Zero-Shot Class Unlearning via Layer-Wise Relevance Analysis and Neuronal Path PerturbationabstractMachine unlearning is a technique that removes specific data influences from trained models without the need for extensive retraining. However, it faces several key challenges, including the lack of explanation, privacy concerns during the unlearning process, and the high demand for time and computational resources. This paper presents a novel unlearning approach to tackle above challenges by employing Layer-wise Relevance Analysis and Neuronal Path Perturbation. Our method balances machine unlearning performance and model utility by identifying and perturbing highly relevant neurons, thus achieving effective unlearning. Using unseen data that has not been presented in the original training set, our method achieves zero-shot unlearning, which allows for the removal of specific class knowledge without accessing the original training data during the unlearning process. This approach ensures robust privacy protection. Experimental results demonstrate that our approach effectively removes targeted data from the target unlearning model while maintaining the model's utility, offering a practical solution for privacy-preserving machine learning. Our code is available athttps://github.com/ChangWenhan/LRA-NPP-Unlearning Wenhan Chang, Tianqing Zhu, Ping Xiong 0001, Faqian Guan, Wanlei Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | T2R-BENCH: A Benchmark for Real World Table-to-Report TaskabstractJie Zhang, Changzai Pan, Sishi Xiong, Kaiwen Wei, Yu Zhao, Xiangyu Li, Jiaxin Peng, Xiaoyan Gu, Jian Yang, Wenhan Chang, Zhenhe Wu, Jiang Zhong, Shuangyong Song, Xuelong Li. Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing. 2025. Changzai Pan, Sishi Xiong, Kaiwen Wei, Yu Zhao 0007, Jian Yang 0037, Wenhan Chang, Zhenhe Wu, Shuangyong Song, Xuelong Li 0001 |
EMNLP | 10 |
| 2025 | From Thinking to Output: Chain-of-Thought and Text Generation Characteristics in Reasoning Language Models
Zhenhao Xu, Yichuan Chen, Zuobin Ying, Wenhan Chang |
KSEM (3) | 6 |
| 2025 | Large Language Models Merging for Enhancing the Link Stealing Attack on Graph Neural NetworksabstractGraph Neural Networks (GNNs), specifically designed to process the graph data, have achieved remarkable success in various applications. Link stealing attacks on graph data pose a significant privacy threat, as attackers aim to extract sensitive relationships between nodes (entities), potentially leading to academic misconduct, fraudulent transactions, or other malicious activities. Previous studies have primarily focused on single datasets and did not explore cross-dataset attacks, let alone attacks that leverage the combined knowledge of multiple attackers. However, we find that an attacker can combine the data knowledge of multiple attackers to create a more effective attack model, which can be referred to cross-dataset attacks. Moreover, if knowledge can be extracted with the help of Large Language Models (LLMs), the attack capability will be more significant. In this paper, we propose a novel link stealing attack method that takes advantage of cross-dataset and LLMs. The LLM is applied to process datasets with different data structures in cross-dataset attacks. Each attacker fine-tunes the LLM on their specific dataset to generate a tailored attack model. We then introduce a novel model merging method to integrate the parameters of these attacker-specific models effectively. The result is a merged attack model with superior generalization capabilities, enabling effective attacks not only on the attackers' datasets but also on previously unseen (out-of-domain) datasets. We conducted extensive experiments in four datasets to demonstrate the effectiveness of our method. Additional experiments with three different GNN and LLM architectures further illustrate the generality of our approach. In summary, we present a new link stealing attack method that facilitates collaboration among multiple attackers to develop a powerful, universal attack model that reflects realistic real-world scenarios. Faqian Guan, Tianqing Zhu, Wenhan Chang, Wei Ren 0002, Wanlei Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Generative Adversarial Networks UnlearningabstractAs machine learning continues to develop and data misuse scandals become more prevalent, individuals are becoming increasingly concerned about their personal information and are advocating for the right to remove their data. Machine unlearning has emerged as a solution to erase training data from trained machine learning models. Despite its success in classifiers, research on Generative Adversarial Networks (GANs) is limited due to their unique architecture, including a generator and a discriminator. One challenge pertains to generator unlearning, as the process could potentially disrupt the continuity and completeness of the latent space. This disruption might consequently diminish the model's effectiveness after unlearning. Another challenge is how to define a criterion that the discriminator should perform for the unlearning images. In this paper, we introduce a substitution mechanism and define a fake label to effectively mitigate these challenges. Based on the substitution mechanism and fake label, we propose a cascaded unlearning approach for both item and class unlearning within GAN models, in which the unlearning and learning processes run in a cascaded manner. We conducted a comprehensive evaluation of the cascaded unlearning technique using the MNIST, CIFAR-10, and FFHQ datasets, analyzing its performance across four key aspects: unlearning effectiveness, intrinsic model performance, impact on downstream tasks, and unlearning efficiency. Experimental results demonstrate that this approach achieves significantly improved item and class unlearning efficiency, reducing the required time by up to$185\times$and$284\times$for the MNIST and CIFAR-10 datasets, respectively, in comparison to retraining from scratch. Notably, although the model's performance experiences minor degradation after unlearning, this reduction is negligible when dealing with a minimal number of images (e.g., 64) even for high-resolution FFHQ dataset and has no adverse effects on downstream tasks such as classification. Tianqing Zhu, Wenhan Chang, Wanlei Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Gradient-based defense methods for data leakage in vertical federated learningabstractResearch on federated learning has continued to develop over the past few years. Many federated learning algorithms and frameworks have been developed to ensure model accuracy and protect client data privacy, which has been extensively beneficial for the development of artificial intelligence security technology. However, it is possible to recover private training data from publicly shared gradients, which is referred to as a data leakage attack. In this paper, we propose two feasible defense methods, based on gradient sparsification and pseudo-gradient, to defend against the state-of-the-art attack methods and achieve maximum protection of the private data of all federated learning participants. Both methods use cosine similarity to measure the angular difference between the gradients updated by the clients during training and the gradients sent back by the server. Taking the cosine similarity as a reference and aiming to protect clients' privacy while maintaining the accuracy of the global model, the clients can choose an appropriate strategy for disguising their uploaded gradient. Through extensive experiments, we demonstrate that both defense methods can protect users' private data while preserving the accuracy of the global model in federated learning. Wenhan Chang, Tianqing Zhu |
Comput. Secur. | 1 |
| 2024 | A two-stage model extraction attack on GANs with a small collected dataset
Tianqing Zhu, Wenhan Chang, Wanlei Zhou 0001 |
Comput. Secur. | 3 |
| 2020 | Model Poisoning Defense on Federated Learning: A Validation Based Approach
Tianqing Zhu, Wenhan Chang, Sheng Shen 0005, Wei Ren 0002 |
NSS | 3 |