Zhihuang Liu

dblp:251/8150 · DBLP profile ↗
← Back
13ranked-venue papers
4as first author
13since 2021 · last 2026
0000-0001-7583-5086ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 4 since 2021Security and privacy · 3 · 3 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Exploring and Exploiting Security Vulnerabilities in Self-Hosted LLM Services
Zhihuang Liu, Ling Hu 0001, Yonghao Tang, Tongqing Zhou, Fang Liu 0002, Zhiping Cai
WWW1
2026 Non-Local Guided Neural Fields for 4D CT Reconstruction
abstract
Dynamic CT reconstruction plays a crucial role in both medical and industrial applications. However, existing 4D CT reconstruction methods typically rely on complex regularization techniques or external large-scale training datasets, posing challenges for reconstruction quality and generalization when handling complex object motion and varied imaging modes. Neural Radiance Fields (NeRF) offer a promising approach to dynamic CT reconstruction, but existing NeRF-based methods often assume that the scene is low-rank, limiting their representation capabilities. To address these issues, we propose NG-NeRF. First, we combine 3D and 4D hash grids for scene representation, effectively reducing temporal redundancy in static regions of dynamic scenes while improving the model’s representation capabilities and efficiency. Next, we design a non-local hash attention module to establish non-local dependencies between the features of different hash grids. This guides the model to adaptively select features based on hash table load information, significantly alleviating hash collisions and achieving the decoupling of dynamic and static regions. Besides, we introduce global continuity by employing mask positional encoding, which helps reduce the noise often introduced by grid features. Our experimental results on medical and industrial datasets demonstrate that the proposed method outperforms existing state-of-the-art methods by 5.84 dB and 3.4 dB, respectively, and exhibits excellent generalization ability across different 4D CT scenarios.
Qingyang Zhou, Yunfan Ye, Zhihuang Liu, Zhiping Cai
IEEE Trans. Circuits Syst. Video Technol.3
2026 Risk-Aware Privacy Preservation for LLM Inference
abstract
Large Language Model (LLM) inference services like ChatGPT are popular for enabling diverse tasks via prompts, yet they exacerbate privacy risks due to the potential exposure of sensitive data in user inputs. Existing local differential privacy (LDP)-based text sanitization mechanisms offer lightweight protection suitable for cloud-based LLM inference. Nevertheless, uniform privacy budget allocation and generalized sanitization mechanisms neglect the critical protection needs of sensitive user data, such as Personally Identifiable Information (PII). Empirical evidence of this work reveals that even with a strict privacy budget (ϵ=0.1), the sensitive information leakage rate can reach an alarmingly high 71.74%. To address these challenges, this paper proposes Rap-LI, a risk-aware privacy preservation framework for LLM inference, designed to be plug-and-play. Rap-LI performs risk identification and personalized labeling on user prompts, then develops a risk-aware LDP mechanism for text sanitization, formally proven to satisfy both token-level and sentence-level LDP guarantees. Extensive experimental results demonstrate Rap-LI’s superior privacy-utility balance. It improves privacy protection against sensitive information leakage by an average of 51.68% compared to methods with comparable utility. Our code is available at https://github.com/Cristliu/RapLI.
Zhihuang Liu, Zhangdong Wang, Tongqing Zhou, Yonghao Tang, Yuchuan Luo, Zhiping Cai
IEEE Trans. Inf. Forensics Secur.1
2026 Comprehensive Measurement of IPv6 Inbound Source Address Validation Deployment via Global Counter Side-Channel
Ling Hu 0001, Zhihuang Liu, Xionglve Li, Bingnan Hou, Zhiyuan Jiang, Bo Yu 0008, Zhiping Cai
IEEE Trans. Netw.2
2025 Prevalence Overshadows Concerns? Understanding Chinese Users' Privacy Awareness and Expectations Towards LLM-Based Healthcare Consultation
abstract
Large Language Models (LLMs) are increasingly gaining traction in the healthcare sector, yet expanding the threat of sensitive health information being easily exposed and accessed without authorization. These privacy risks escalate in regions like China, where privacy awareness is notably limited. While some efforts have been devoted to user surveys on LLMs in healthcare, users' perceptions of privacy remain unexplored. To fill this gap, this paper contributes the first user study (n=846) in China on privacy awareness and expectations in LLM-based healthcare consultations. Specifically, a healthcare chatbot is deployed to investigate users' awareness in practice. Information flows grounded in contextual integrity are then employed to measure users' privacy expectations. Our findings suggest that the prevalence of LLMs amplifies health privacy risks by raising users' curiosity and willingness to use such services, thus overshadowing privacy concerns. 77.3% of participants are inclined to use such services, and 72.9% indicate they would adopt the generated advice. Interestingly, a paradoxical “illusion” emerges where users' knowledge and concerns about privacy contradict their privacy expectations, leading to greater health privacy exposure. Our extensive discussion offers insights for future LLM-based healthcare privacy investigations and protection technology development.
Zhihuang Liu, Ling Hu 0001, Tongqing Zhou, Yonghao Tang, Zhiping Cai
SP1
2025 Split Learning on Segmented Healthcare Data
abstract
Sequential data learning is vital to harnessing the encompassed rich knowledge for diverse downstream tasks, particularly in healthcare (e.g., disease prediction). Considering data sensitiveness, privacy-preserving learning methods, based on federated learning (FL) and split learning (SL), have been widely investigated. Yet, this work identifies, for the first time, existing methods overlook that sequential data are generated by different patients at different times and stored in different hospitals, failing to learn the sequential correlations between different temporal segments. To fill this void, a novel distributed learning frameworkSTSLis proposed by training a model on the segments in order. Considering that patients have different visit sequences,STSLfirst implements privacy-preserving visit ordering based on a secure multi-party computation mechanism. Then batch scheduling participates patients with similar visit (sub-)sequences into the same training batch, facilitating subsequent split learning on batches. The scheduling process is formulated as an NP-hard optimization problem on balancing learning loss and efficiency and a greedy-based solution is presented. Theoretical analysis proves the privacy preservation property ofSTSL. Experimental results on real-world eICU data show its superior performance compared with FL and SL ($5\% \sim 28\%$better accuracy) and effectiveness (a remarkable 75% reduction in communication costs).
Ling Hu 0001, Tongqing Zhou, Zhihuang Liu, Fang Liu 0002, Zhiping Cai
IEEE Trans. Big Data3
2025 PPIDM: Privacy-Preserving Inference for Diffusion Model in the Cloud
abstract
Cloud environments enhance diffusion model efficiency but introduce privacy risks, including intellectual property theft and data breaches. As AI-generated images gain recognition as copyright-protected works, ensuring their security and intellectual property protection in cloud environments has become a pressing challenge. This paper addresses privacy protection in diffusion model inference under cloud environments, identifying two key characteristics—denoising-encryption antagonism and stepwise generative nature—that create challenges such as incompatibility with traditional encryption, incomplete input parameter representation, and inseparability of the generative process. We propose PPIDM (Privacy-PreservingInference forDiffusionModels), a framework that balances efficiency and privacy by retaining lightweight text encoding and image decoding on the client while offloading computationally intensive U-Net layers to multiple non-colluding cloud servers. Client-side aggregation reduces computational overhead and enhances security. Experiments show PPIDM offloads 67% of Stable Diffusion computations to the cloud, reduces image leakage by 75%, and maintains high output quality (PSNR = 36.9, FID = 4.56), comparable to standard outputs. PPIDM offers a secure and efficient solution for cloud-based diffusion model inference.
Zhangdong Wang, Zhihuang Liu, Yuanjing Luo, Tongqing Zhou, Jiaohua Qin, Zhiping Cai
IEEE Trans. Circuits Syst. Video Technol.2
2024 Split Learning on Multi-source Cross-Streams
Ling Hu 0001, Tongqing Zhou, Zhihuang Liu, Fang Liu 0002, Zhiping Cai
ICONIP (5)3
2024 Blockchain and trusted reputation assessment-based incentive mechanism for healthcare services
abstract
Blockchain-based healthcare IoT technology research enhances security for smart healthcare services such as real-time monitoring and remote disease diagnosis. To incentivize positive behavior among participants within a blockchain-based smart healthcare system, existing efforts employ benefit distribution and reputation assessment methods to enhance performance. Yet, there remains a significant gap in multidimensional assessment strategies and consensus improvements in addressing complex healthcare scenarios. In this paper, we propose a blockchain and trusted reputation assessment-based incentive mechanism for healthcare services (BtRaI). BtRaI provides a realistic and comprehensive reputation assessment with feedback to motivate blockchain consensus node participation, thus effectively defending against malicious behavior in the healthcare service system. Specifically, BtRaI first introduces multiple moderation factors for comprehensive multidimensional reputation assessment and credibly records the assessment results on the blockchain. Then, we propose an improved PBFT algorithm, grounded in the reputation assessment, to augment blockchain consensus efficiency. Finally, BtRaI designs a token-based reward and punishment mechanism to motivate honest participation in the blockchain, inhibit potential misbehavior, and promote enhanced service quality in the healthcare system. Theoretical analysis and simulation experiments conducted across various scenarios demonstrate that BtRaI effectively suppresses malicious attacks in healthcare services , improves blockchain node fault tolerance rates, and achieves blockchain transaction processing efficiency within 0.5 s in a 100-node consortium chain. BtRaI’s reputation assessment and token incentive mechanism, characterized by realistic differentiation granularity and change curves, are well-suited for dynamic and complex healthcare service environments.
Zhihuang Liu, Qiu Zhang, Jinshu Su, Zhiping Cai
Future Gener. Comput. Syst.2
2024 SeCoSe: Toward Searchable and Communicable Healthcare Service Seeking in Flexible and Secure EHR Sharing
abstract
Cloud-assisted electronic health record (EHR) sharing plays an important role in modern healthcare systems but faces threats of distrust and non-traceability. The advent of blockchain offers an attractive solution to overcome this issue. Many efforts are devoted to promoting secure, flexible, and multi-featured blockchain-based EHR sharing. Yet, the problem of seeking out suitable healthcare providers and communicating information beyond the EHR has unfortunately been ignored. In this paper, we propose SeCoSe, a novel EHR sharing scheme to address these concerns. SeCoSe enables patients and their general practitioners to autonomously seek out and stay in touch with their preferred healthcare professionals. Specifically, a searchable and repeatable transformation identity-based encryption (SRTIBE) is proposed to achieve dynamic and flexible authorization updates. Moreover, we design attribute-identity mapping contracts and evidence-based contracts on the blockchain to enable on-demand retrieval of anonymous identities and ensure tamper resistance and traceability of system transactions. Furthermore, we employ the advanced messages on-chain protocol (AMOP) to facilitate the online communication of off-chain messages. Detailed security analysis and extensive evaluations demonstrate that SeCoSe is privacy-secure, traceable, and attack-resistant. SeCoSe has lower overhead for repeated authorization and transformation, on-chain transactions can be responded to within seconds, and online communication can handle the transmission of 49,000 messages in about 6 seconds.
Zhihuang Liu, Ling Hu 0001, Zhiping Cai, Ximeng Liu
IEEE Trans. Inf. Forensics Secur.1
2024 Semi-supervised attack detection in industrial control systems with deviation networks and feature selection
Wentao Deng, Zhihuang Liu, Fanhao Zeng
J. Supercomput.3
2023 Network intrusion detection via tri-broad learning system based on spatial-temporal granularity
Jieling Li, Hao Zhang 0078, Zhihuang Liu
J. Supercomput.3
2022 Semi-supervised machine learning framework for network intrusion detection
Jieling Li, Hao Zhang 0078, Zhihuang Liu
J. Supercomput.4