Chenhan Zhang

dblp:254/5912 · DBLP profile ↗
← Back
34ranked-venue papers
13as first author
33since 2021 · last 2026
0000-0002-2352-0485ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 3 first-author · 13 since 2021Computer networks · 10 · 6 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Forget Me, Not My Friends! Object Unlearning Based on Scene Graphs
abstract
Machine unlearning offers a practical technical means for fulfilling users' requests to remove personally identifiable information (PII) under ''right to be forgotten'' regulations such as GDPR and COPPA. Traditionally, unlearning is performed with the removal of entire data samples (sample unlearning) or whole features across the dataset (feature unlearning). However, when the removal request targets only certain parts of the PII, such as specific objects within a sample, these traditional unlearning approaches fall short of meeting such finer-grained unlearning requirements. To address this gap, we propose a scene graph-based object unlearning framework. This framework utilizes scene graphs, rich in semantic representation, transparently translate unlearning requests into actionable steps. The result, is the preservation of the overall semantic integrity of the generated image, bar the unlearned object. Furthermore, we develop three distinct approaches for object unlearning, grounded in the mainstream unlearning techniques of fine-tuning and model redaction. For validation, we evaluate the unlearned object's fidelity in outputs under the tasks of image reconstruction and image synthesis. Our proposed framework demonstrates improved object unlearning outcomes, with the preservation of unrequested samples in contrast to sample and feature learning methods. This work addresses critical privacy issues by increasing the granularity of targeted machine unlearning through forgetting specific object-level details without sacrificing the utility of the whole data sample or dataset feature.
Chenhan Zhang, Benjamin Zi Hao Zhao, Hassan Jameel Asghar, Weiqi Wang 0003, An Liu 0002, Mohamed Ali Kâafar
WSDM1
2026 BlindU: Blind Machine Unlearning Without Revealing Erasing Data
abstract
Machine unlearning enables data holders to remove the contribution of their specified samples from trained models to protect their privacy. However, it is paradoxical that most unlearning methods require the unlearning requesters to first upload their data to the server as a prerequisite for unlearning. These methods are infeasible in many privacy-preserving scenarios where servers are prohibited from accessing users' data, such as federated learning (FL). In this paper, we explore how to implement unlearning under the condition of not uncovering the erasing data to the server. We propose Blind Unlearning (BlindU), which carries out unlearning using compressed representations instead of original inputs. BlindU only involves the server and the unlearning user: the user locally generates privacy-preserving representations, and the server performs unlearning solely on these representations and their labels. For the FL model training, we employ the information bottleneck (IB) mechanism. The encoder of the IB-based FL model learns representations that distort maximum task-irrelevant information from inputs, allowing FL users to generate compressed representations locally. For effective unlearning using compressed representation, BlindU integrates two dedicated unlearning modules tailored explicitly for IB-based models and uses a multiple gradient descent algorithm to balance forgetting and utility retaining. While IB compression already provides protection for task-irrelevant information of inputs, to further enhance the privacy protection, we introduce a noise-free differential privacy (DP) masking method to deal with the raw erasing data before compressing. Theoretical analysis and extensive experimental results illustrate the superiority of BlindU in privacy protection and unlearning effectiveness compared with the best existing privacy-preserving unlearning benchmarks.
Weiqi Wang 0003, Zhiyi Tian, Chenhan Zhang, Shui Yu 0001
IEEE Trans. Pattern Anal. Mach. Intell.3
2026 SMS: Self-Supervised Model Seeding for Verification of Machine Unlearning
abstract
Many machine unlearning methods have been proposed recently to uphold users' right to be forgotten. However, offering users verification of their data removal post-unlearning is an important yet under-explored problem. Current verifications typically rely on backdooring, i.e., adding backdoored samples to influence model performance. Nevertheless, the backdoor methods can merely establish a connection between backdoored samples and models but fail to connect the backdoor with genuine samples. Thus, the backdoor removal can only confirm the unlearning of backdoored samples, not users' genuine samples, as genuine samples are independent of backdoored ones. In this paper, we propose a Self-supervised Model Seeding (SMS) scheme to provide unlearning verification for genuine samples. Unlike backdooring, SMS links user-specific seeds (such as users' unique indices), original samples, and models, thereby facilitating the verification of unlearning genuine samples. However, implementing SMS for unlearning verification presents two significant challenges. First, embedding the seeds into the service model while keeping them secret from the server requires a sophisticated approach. We address this by employing a self-supervised model seeding task, which learns the entire sample, including the seeds, into the model's latent space. Second, maintaining the utility of the original service model while ensuring the seeding effect requires a delicate balance. We design a joint-training structure that optimizes both the self-supervised model seeding task and the primary service task simultaneously on the model, thereby maintaining model utility while achieving effective model seeding. The effectiveness of the proposed SMS scheme is evaluated through extensive experiments on three representative datasets, utilizing various model architectures and exact and approximate unlearning benchmarks. The results demonstrate that SMS provides effective verification for genuine sample unlearning, effectively addressing the limitations of existing solutions.
Weiqi Wang 0003, Chenhan Zhang, Zhiyi Tian, Shui Yu 0001
IEEE Trans. Dependable Secur. Comput.2
2025 EvaSR: Rethinking Efficient Visual Attention Design for Image Super-Resolution
abstract
Due to the advantages of long-range modeling via the self-attention mechanism, Transformer has taken various vision tasks by storm, including image super-resolution (SR). In this study, we reveal that the convolutional neural network (CNN) with proper visual attention is a more simple and effective paradigm than Transformer in image SR tasks. We reexamine the successful SR models and discover several key characteristics that contribute to accurate image reconstruction. Built on this recipe, we propose a pure CNN-based SR network using efficient visual attention, dubbed EvaSR. Benefiting from the carefully designed visual attention, our EvaSR can favorably capture both local structure and long-range dependencies, and achieve adaptivity in spatial and channel dimensions while retaining the simplicity and efficiency of CNNs. The experimental results demonstrate that our EvaSR achieves state-of-the-art performance among the existing efficient SR methods. Especially, the tiny version of EvaSR needs 21.4% and 15.2% parameters of IMDN and SMSR with better performance.
Zhijian Wu, Chenhan Zhang, Dingjiang Huang
ICASSP2
2025 Inversion Triplet - A Contrastive Backdoor Mitigation Method for Self-Supervised Vision Encoders
Hiep Vo, Zhiyi Tian, Chenhan Zhang, James Xi Zheng, Shui Yu 0001
PAKDD (6)3
2025 Can Self Supervision Rejuvenate Similarity-Based Link Prediction?
Chenhan Zhang, Weiqi Wang 0003, Zhiyi Tian, James Jian Qiao Yu, Mohamed Ali Kâafar, An Liu 0002, Shui Yu 0001
PAKDD (7)1
2025 MOUSSE: A Multimodality-Oriented Unified Semantic Communication System by Contrastive Learning
abstract
The sixth generation (6G) communication posed higher requirements for the communication system regarding accurate semantic transmission. The existing studies about semantic communication principally concentrate on tackling task-oriented problems, rather than directly design modality-oriented system which is more generic and adaptive to different tasks. To improve the flexibility and robustness of communication system, we propose a Multimodality-Oriented Unified Semantic Communication SystEm (MOUSSE) based on contrastive learning. MOUSSE is designed to firstly orient modality then matches different modalities combination up to various tasks. Existing task-oriented philosophy primarily considers tasks whilst restricting modal versatility. MOUSSE could also intake and output various tasks with multiple modalities while transmit them in a concise and unified representation. Specifically, the system consists of structure-symmetric twin encoder-decoder for modality unification, which cascades joint source-channel coding (JSCC) module and contrastive learning based alignment module. Finally, the experiments verify the validity of proposed MOUSSE by quantitative results from different modalities with their respective tasks. The reliability and robustness are also improved from the point of entire communication system view.
Tao Zhang 0165, Zhiyi Tian, Chenhan Zhang, Shui Yu 0001
WCNC4
2025 Backdoored Sample Cleansing for Unlabeled Datasets via Bootstrapped Dual Set Purification
abstract
Self-Supervised Learning (SSL) excels in utilizing unlabeled data for feature representation learning. However, recent studies have revealed that SSL is vulnerable to data poisoning-based backdoor attacks. To remove backdoored samples from the SSL training dataset, model optimization methods often fine-tune a trained model by contrasting the training dataset with a reserved clean dataset. This contrastive training effectively marginalizes backdoored samples from the distribution of benign ones,if and only ifboth the reserved clean dataset and the training dataset are from the same data distribution. However, presuming identical distributions between the web-scraped data and reserved data is impractical. To address this impractical assumption, our proposed Bootstrapped Dual SetPurification (AUTO) method distinguishes backdoored from benign samples by contrasting a mined ‘positive set’ and a mined ‘negative set’ within the training dataset itself. We exploit the resistance of backdoored samples in data mixing to mine a highly poisoned ‘positive set’ and a minimally poisoned ‘negative set’. Besides, AUTO mitigates unstable detection performance within different optimization steps by continuously refining the dual sets by the optimized model, enhancing the model's poison distinguishability from consistently improving supervision signals. Our extensive experiments on Cifar10, Cifar100, and Imagenet100 against existing data poisoning SSL backdoor attacks demonstrate AUTO's superiority in detection performance over all existing defenses.
Luoyu Chen, Weiqi Wang 0003, Zhiyi Tian, Chenhan Zhang, Shui Yu 0001
IEEE Trans. Dependable Secur. Comput.4
2025 CRFU: Compressive Representation Forgetting Against Privacy Leakage on Machine Unlearning
abstract
Machine unlearning allows data owners to erase the impact of their specified data from trained models. Unfortunately, recent studies have shown that adversaries can recover the erased data, posing serious threats to user privacy. An effective unlearning method removes the information of the specified data from the trained model, resulting in different outputs for the same input before and after unlearning. Adversaries can exploit these output differences to conduct privacy leakage attacks, such as reconstruction and membership inference attacks. However, directly applying traditional defenses to unlearning leads to significant model utility degradation. In this article, we introduce a Compressive Representation Forgetting Unlearning scheme (CRFU), designed to safeguard against privacy leakage on unlearning. CRFU achieves data erasure by minimizing the mutual information between the trained compressive representation (learned through information bottleneck theory) and the erased data, thereby maximizing the distortion of data. This ensures that the model's output contains less information that adversaries can exploit. Furthermore, we introduce a remembering constraint and an unlearning rate to balance the forgetting of erased data with the preservation of previously learned knowledge, thereby reducing accuracy degradation. Theoretical analysis demonstrates that CRFU can effectively defend against privacy leakage attacks. Our experimental results show that CRFU significantly increases the reconstruction mean square error (MSE), achieving a defense effect improvement of approximately 200% against privacy reconstruction attacks with only 1.5% accuracy degradation on MNIST.
Weiqi Wang 0003, Chenhan Zhang, Zhiyi Tian, Shushu Liu, Shui Yu 0001
IEEE Trans. Dependable Secur. Comput.2
2025 FedU: Federated Unlearning via User-Side Influence Approximation Forgetting
abstract
Machine unlearning has become a significant research topic on a global scale due to the increasing importance of privacy protection, particularly in light of the right to be forgotten legislation. Although many solutions are proposed, the current mainstream centralized machine unlearning studies are not feasible in federated learning (FL), where the server has no access to any users’ unlearning samples. In this paper, we aim to tackle thefederated unlearningproblem by proposing a Federated Unlearning (FedU) scheme via a user-side influence approximation forgetting method, thereby eliminating the need to share raw data with the server. In FedU, only users who have unlearning needs execute the influence approximation forgetting, while other users and the server just conduct the same operations as they did in FL. The proposed influence approximation forgetting method achieves unlearning by estimating the influence of the erased samples relying on only the user's local data and eliminating this influence from the model. However, the model utility is still negatively influenced by directly removing the influence estimation. To mitigate the side effects of unlearning, we propose a utility preservation method that simultaneously trains the unlearned model based on the unlearning requesters’ remaining local dataset. We design an adaptive optimization method to balance the forgetting and utility preservation effectiveness optimally during the unlearning process. Extensive evaluations on three representative public datasets demonstrate that our proposed method significantly outperforms state-of-the-art methods in both effectiveness and efficiency, avoiding more than 3% accuracy degradation when the number of unlearning requesters is large.
Weiqi Wang 0003, Chenhan Zhang, Zhiyi Tian, Shui Yu 0001
IEEE Trans. Dependable Secur. Comput.2
2025 SCU: An Efficient Machine Unlearning Scheme for Deep Learning Enabled Semantic Communications
abstract
Deep learning (DL) enabled semantic communications leverage DL to train encoders and decoders (codecs) to extract and recover semantic information. However, most semantic training datasets contain personal private information. Such concerns call for enormous requirements for specified data erasure from semantic codecs when previous users hope to move their data from the semantic system. Existing machine unlearning solutions remove data contribution from trained models, yet usually in supervised sole model scenarios. These methods are infeasible in semantic communications that often need to jointly train unsupervised encoders and decoders. In this paper, we investigate the unlearning problem in DL-enabled semantic communications and propose a semantic communication unlearning (SCU) scheme to tackle the problem. SCU includes two key components. Firstly, we customize the joint unlearning method for semantic codecs, including the encoder and decoder, by minimizing mutual information between the learned semantic representation and the erased samples. Secondly, to compensate for semantic model utility degradation caused by unlearning, we propose a contrastive compensation method, which considers the erased data as the negative samples and the remaining data as the positive samples to retrain the unlearned semantic models contrastively. Theoretical analysis and extensive experimental results on three representative datasets demonstrate the effectiveness and efficiency of our proposed methods.
Weiqi Wang 0003, Zhiyi Tian, Chenhan Zhang, Shui Yu 0001
IEEE Trans. Inf. Forensics Secur.3
2025 Evaluation of Machine Unlearning Through Model Difference
abstract
Increasing attention is being paid to machine unlearning, which supports individuals’ “right to be forgotten.” While most studies focus on the efficiency and effectiveness of unlearning algorithms, the evaluation of machine unlearning effectiveness remains underexplored. Offering robust evaluation services for unlearning is critical, not only to uphold privacy legislation but also to assess and improve existing unlearning methods. Lots of existing methods employ backdoor methods to evaluate unlearning effectiveness, which can only verify the unlearning effect of backdoored samples and negatively impact the model utility as they need to embed backdoors into the model first. In this paper, we propose an evaluating machine unlearning (EMU) method, which aims to evaluate the effectiveness of unlearning and verify data removal without the aforementioned adverse effects. Machine unlearning inherently creates a difference on the model before and after unlearning. The model difference contains information about the unlearned samples, which can be extracted through reconstruction models for unlearning effectiveness evaluation. To efficiently generate the model differences as input for evaluation, we simulate the model changes based on the influence function theory. Additionally, we design a multi-task information bottleneck structure to enhance the scalability of EMU and simplify the analysis of different learning tasks. We provide a theoretical analysis of how the similarity between erased and remaining samples, as well as task types, affects the extent of unlearning—factors that have been largely overlooked. Extensive experiments on various model architectures and representative datasets confirm our analysis, demonstrating the effective evaluation for unlearning without any degradation in the service model utility.
Weiqi Wang 0003, Chenhan Zhang, Zhiyi Tian, Shui Yu 0001, Zhou Su 0001
IEEE Trans. Inf. Forensics Secur.2
2024 The Role of Class Information in Model Inversion Attacks Against Image Deep Learning Classifiers
abstract
Model inversion attacks can reconstruct the training samples of victim deep learning models. The existing efforts heavily rely on auxiliary information of the target samples (prior target information) to achieve their adversarial goals. However, prior target information is hard to obtain in practice. In this paper, we explore the effect of class information in model inversion attacks to reduce the reliance of prior target information. Our contributions on class information exploitation are two-fold. Firstly, we propose a supervised inversion model, Supervised Model Inversion (SMI). The proposed inversion model learns pixel-level features and data-to-class features from the rounded-outputs of the victim model and labeled auxiliary dataset. Secondly, we leverage victim model's rounded-outputs to guide the optimization of reconstructing inversion samples after trained inversion model. Our experimental results show that inversion samples reconstructed by SMI are more visually plausible with more details, comparing to the three representative model inversion attacks. We further perform an extensive study on various auxiliary dataset settings. It is found that the class combination in the auxiliary dataset rather than the number of classes that determines the quality of inversion samples. The ground-truth labels can improve the qualities of inversion samples but not essential to inversion attacks.
Zhiyi Tian, Lei Cui 0006, Chenhan Zhang, Shuaishuai Tan, Shui Yu 0001, Yonghong Tian 0001
IEEE Trans. Dependable Secur. Comput.3
2024 Machine Unlearning via Representation Forgetting With Parameter Self-Sharing
abstract
Machine unlearning enables data owners to remove the contribution of their specified samples from trained models. However, existing methods fail to strike an optimal balance between erasure effectiveness and model utility preservation. Previous studies focused on removing the impact of user-specified data from the model as much as possible to implement unlearning. These methods usually result in significant model utility degradation, commonly called catastrophic unlearning. To address the issue, we systematically consider machine unlearning and formulate it as a two-objective optimization problem that involves forgetting the erased data and retaining the previously learned knowledge, highlighting accuracy preservation during the unlearning process. We propose an unlearning method called representation-forgetting unlearning with parameter self-sharing (RFU-SS) to achieve the two-objective unlearning goal. Firstly, we design a representation-forgetting unlearning (RFU) method that aims to remove the contribution of specified samples from a trained representation by minimizing the mutual information between the representation and the erased data. The representation is learned using the information bottleneck (IB) method. RFU is tailored to the IB structure models for ease of introduction. Secondly, we customize a parameter self-sharing structural optimization method for RFU (i.e., RFU-SS) to simultaneously optimize the forgetting and retention objectives to find the optimal balance. Extensive experimental results demonstrate a significant effectiveness improvement of RFU-SS over the state-of-the-art methods. RFU-SS almost eliminates catastrophic unlearning, reducing model accuracy degradation from over 6% to less than 0.2% on the MNIST dataset with an even better removal effect. The source code is available athttps://github.com/wwq5-code/RFU-SS.git.
Weiqi Wang 0003, Chenhan Zhang, Zhiyi Tian, Shui Yu 0001
IEEE Trans. Inf. Forensics Secur.2
2024 Forgetting and Remembering Are Both You Need: Balanced Graph Structure Unlearning
abstract
In light of the growing emphasis on the right to be forgotten of graph data, machine unlearning has been extended to unlearn the graph structures’ knowledge from graph neural networks (GNNs), namely, structure unlearning. Whereas the complex dependencies in graph data, structure unlearning is intrinsically prone to imbalanced performance between the objectives of knowledge forgetting and model utility maintenance. Nevertheless, most existing methods fall short in addressing the two objectives in tandem and developing balanced solutions. In this paper, we propose imbalanced Structure Unlearning Mitigation using MultI-objective OpTimization (SUMMIT), which aims to develop balanced solutions regarding both knowledge forgetting and model utility maintenance effects. Corresponding to the two aspects, we first construct two tailored objectives that specifically address the challenges inherent in structure unlearning. Specifically, for the forgetting objective, we introduce a higher-order forgetting enhancement strategy aimed at mitigating the adverse effects of GNN oversmoothing on node decoupling. For the remembering objective, we adhere to the principle of ideal unlearning and propose to minimize the distributional distance between the node embeddings developed by unlearned and well-trained GNNs. Considering the potential competitive relationship between the two objectives during the optimization process, we present an adaptive two-objective balancer based on multi-objective optimization to reconcile the two objectives and strike a balance between them. We conduct comprehensive experiments to evaluate the efficacy of SUMMIT on three representative GNNs and four datasets, and compare the performance of SUMMIT with its ablation variants and a cadre of baselines. We demonstrate the superiority of SUMMIT in its ability to yield optimal and balanced solutions, addressing both the facets of knowledge forgetting and model utility maintenance.
Chenhan Zhang, Weiqi Wang 0003, Zhiyi Tian, Shui Yu 0001
IEEE Trans. Inf. Forensics Secur.1
2024 Fast Fourier Inception Networks for Occluded Video Prediction
abstract
Video prediction is a pixel-level task that generates future frames by employing the historical frames. There often exist continuous complex motions, such as object overlapping and scene occlusion in video, which poses great challenges to this task. Previous works either fail to well capture the long-term temporal dynamics or do not handle the occlusion masks. To address these issues, we develop the fully convolutional Fast Fourier Inception Networks for video prediction, termedFFINet, which includes two primary components, i.e., the occlusion inpainter and the spatiotemporal translator. The former adopts the fast Fourier convolutions to enlarge the receptive field, such that the missing areas (occlusion) with complex geometric structures are filled by the inpainter. The latter employs the stacked Fourier transform inception module to learn the temporal evolution by group convolutions and the spatial movement by channel-wise Fourier convolutions, which captures both the local and the global spatiotemporal features. This encourages generating more realistic and high-quality future frames. To optimize the model, the recovery loss is imposed to the objective, i.e., minimizing the mean square error between the ground-truth frame and the recovery frame. Both quantitative and qualitative experimental results on five benchmarks, including Moving MNIST, TaxiBJ, Human3.6 M, Caltech Pedestrian, and KTH, have demonstrated the superiority of the proposed approach.
Ping Li 0006, Chenhan Zhang, Xianghua Xu
IEEE Trans. Multim.2
2023 BFU: Bayesian Federated Unlearning with Parameter Self-Sharing
abstract
As the right to be forgotten has been legislated worldwide, many studies attempt to design machine unlearning mechanisms to enable data erasure from a trained model. Existing machine unlearning studies focus on centralized learning, where the server can access all users’ data. However, in a popular scenario, federated learning (FL), the server cannot access users’ training data. In this paper, we investigate the problem of machine unlearning in FL. We formalize a federated unlearning problem and propose a bayesian federated unlearning (BFU) approach to implement unlearning for a trained FL model without sharing raw data with the server. Specifically, we first introduce an unlearning rate in BFU to balance the trade-off between forgetting the erased data and remembering the original global model, making it adaptive to different unlearning tasks. Then, to mitigate accuracy degradation caused by unlearning, we propose BFU with parameter self-sharing (BFU-SS). BFU-SS considers data erasure and maintaining learning accuracy as two tasks and optimizes them together during unlearning. Extensive comparisons between our methods and the state-of-art federated unlearning method demonstrate the superiority of our proposed realizations.
Weiqi Wang 0003, Zhiyi Tian, Chenhan Zhang, An Liu 0002, Shui Yu 0001
AsiaCCS3
2023 Extracting Privacy-Preserving Subgraphs in Federated Graph Learning using Information Bottleneck
abstract
As graphs are getting larger and larger, federated graph learning (FGL) is increasingly adopted, which can train graph neural networks (GNNs) on distributed graph data. However, the privacy of graph data in FGL systems is an inevitable concern due to multi-party participation. Recent studies indicated that the gradient leakage of trained GNN can be used to infer private graph data information utilizing model inversion attacks (MIA). Moreover, the central server can legitimately access the local GNN gradients, which makes MIA difficult to counter if the attacker is at the central server. In this paper, we first identify a realistic crowdsourcing-based FGL scenario where MIA from the central server towards clients’ subgraph structures is a nonnegligible threat. Then, we propose a defense scheme, Subgraph-Out-of-Subgraph (SOS), to mitigate such MIA and meanwhile, maintain the prediction accuracy. We leverage the information bottleneck (IB) principle to extract task-relevant subgraphs out of the clients’ original subgraphs. The extracted IB-subgraphs are used for local GNN training and the local model updates will have less information about the original subgraphs, which renders the MIA harder to infer the original subgraph structure. Particularly, we devise a novel neural network-powered approach to overcome the intractability of graph data’s mutual information estimation in IB optimization. Additionally, we design a subgraph generation algorithm for finally yielding reasonable IB-subgraphs from the optimization results. Extensive experiments demonstrate the efficacy of the proposed scheme, the FGL system trained on IB-subgraphs is more robust against MIA attacks with minuscule accuracy loss.
Chenhan Zhang, Weiqi Wang 0003, James Jian Qiao Yu, Shui Yu 0001
AsiaCCS1
2023 CP-FL: Practical Gradient Leakage Defense in Federated Learning with Compressive Privacy
abstract
Federated learning (FL) requires clients to train constituted models based on their local datasets. Clients usually directly train local models using their entire datasets without distinguishing which information of data is task-relevant or irrelevant. Task-irrelevant information does not contribute to the learning task but exposes additional privacy information to adversaries. Studies have shown that unintended information leakage from gradients during FL iterations threatens clients' privacy. Researchers applied differential privacy (DP) to protect clients' gradients, but it does not help to reduce task-irrelevant information from the gradients. In this paper, we propose a compressive privacy federated learning (CP-FL) scheme to protect the task-irrelevant information from gradient leakage attacks. In CP-FL, clients train a local compressive model according to the global task. The local compressive model constructs a new representation, which extracts task-relevant and removes task-irrelevant information from clients' data. Since the global model is updated based on the compressed representation that eliminates the task-irrelevant information, it can effectively prevent adversaries from inferring those property values from the uploaded gradients. Moreover, with the help of a powerful local compressive model that sanitizes the challenging data into a low-dimension space representation, CP-FL can use a small global model instead of a sizeable one, significantly reducing communication. Both theoretical analysis and extensive experimental results demonstrate that CP-FL can effectively defend against gradient leakage attacks while maintaining practical utility.
Weiqi Wang 0003, Shushu Liu, Chenhan Zhang, Mingjian Tang 0002, Shui Yu 0001
GLOBECOM3
2023 FedMC: Federated Learning with Mode Connectivity Against Distributed Backdoor Attacks
abstract
Federated learning (FL) has become a hot research domain due to its privacy protection for model collaboratively training in edge computing systems. However, recent studies indicated that most FL algorithms have desperately suffered from backdoor attacks. Although many backdoor defence FL algorithms were proposed, their effects were highly related to the ratio of malicious clients (RMC) of all participated edge nodes. To be more specific, most of them only set RMC around 10% to 30% in their experiments, and their results also showed that the rate of successful backdoor defence seriously drops when RMC increases. In the paper, we propose a novel federated learning scheme with mode connectivity (FedMC) to defend against backdoor attacks, mitigating the sharp defence effect degradation as RMC increases. Conventional mode connectivity mainly focuses on training a connecting curve between two end models, which is inapplicable in distributed multiple clients FL situations. We extend the two-ends mode connectivity to multi-ends by introducing a scalable regularization term consisting of the edge clients' models to involve their knowledge in the connective model training. In each communication round, the FL-Server aggregates and absorbs the contribution of clients by training a connective model based on a small set of clean samples, which builds a pathway to accurately connect all edge clients' models and mitigates the backdoor triggers of models. Extensive experiments and results demonstrate that FedMC can effectively defend against backdoor attacks while maintaining the accuracy on untampered test data.
Weiqi Wang 0003, Chenhan Zhang, Shushu Liu, Mingjian Tang 0002, An Liu 0002, Shui Yu 0001
ICC2
2023 Construct New Graphs Using Information Bottleneck Against Property Inference Attacks
abstract
Graphs provide a unique representation of real- world data. However, recent studies found that inference attacks can extract private property information of graph data from trained graph neural networks (GNNs), which arouses privacy concerns about graph data, especially in collaborative learning systems where model information is more accessible. While there has been a few research efforts on the property inference attacks against GNNs, how to defend against such attacks has seldom been studied. In this paper, we propose to leverage the information bottleneck (IB) principle to defend against the property inference attacks. Particularly, we involve a threat model, where the attacker can extract graph property from the graph embedding developed by GNNs. To defend against the attacks, we use IB to construct new graph structures from the original graphs. The change in graph structures enables the new graphs to contain less information related to the property information of the original graphs, making it harder for attackers to infer property information of the original graphs from the graph embeddings. Meantime, the IB principle enables task-relevant information to be sufficiently contained in the new graph, enabling GNNs to develop accurate predictions. The experimental results demonstrate the efficacy of the proposed approach in resisting property inference attacks and developing accurate predictions.
Chenhan Zhang, Zhiyi Tian, James Jian Qiao Yu, Shui Yu 0001
ICC1
2023 RUE: Realising Unlearning from the Perspective of Economics
abstract
Machine unlearning has quickly emerged as a technique to withdraw users’ data from the trained model to protect their privacy. Yet the cost of completely unlearning by retraining is high and the unlearning service is thus hard to proceed in the market. We work on the SISA method that greatly lowers the cost of unlearning as an example in this manuscript. We model the problem with a game theory model that balances customers’ benefit and the service provider’s profit, and the optimal price is acquired that both parties could accept. More specifically, in the game model, we calculate customers’ average waiting time with bulk service queueing model, and linearly estimate the customers’ benefit in terms of privacy from withdrawing their data. Our method RUE shows that both parties get more benefit or profit than others, which could make the unlearning service run smoothly when the concerns about the high price are removed. We also analyse the influence of the waiting time on the number of unlearning requests and on the price.
Mingjian Tang 0002, Weiqi Wang 0003, Chenhan Zhang, Shui Yu 0001
TrustCom3
2023 Toward Large-Scale Graph-Based Traffic Forecasting: A Data-Driven Network Partitioning Approach
abstract
Network partitioning is recognized as an effective auxiliary approach for solving transportation tasks on large-scale traffic networks in a domain-decomposition (DD) manner. Most of the existing related partitioning algorithms are explicitly designed to traffic management problems and merely focus on the implied topology of the networks. In this article, toward the practical problems that happened to traffic forecasting (TF) tasks, we propose a network-partitioning-based DD framework to improve graph convolutional network (GCN)-based predictors’ performance on large-scale transportation networks. Particularly, we devise a data-driven network-partitioning approach, namely, speed-matching-partitioning (SMP), which employs not only the topological features but also the traffic speed observations of traffic networks for partitioning. Additionally, we propose a data-parallel training strategy that feeds partitioned subnetworks into independent predictors for parallel training. The proposed approach is tested by comprehensive case studies on three real-world data sets to evaluate its effectiveness. The results indicate that the proposed approach can help improve GCN-based predictors’ accuracy and training efficiency on both small and relatively large traffic data sets. Furthermore, we investigate the model sensitivity to the selection of graph representations and framework parameters, and the learning efficiency of the data-parallel training strategy.
Chenhan Zhang, Shuyu Zhang 0003, Xiexin Zou, Shui Yu 0001, James Jian Qiao Yu
IEEE Internet Things J.1
2023 SAM: Query-efficient Adversarial Attacks against Graph Neural Networks
abstract
Recent studies indicate that Graph Neural Networks (GNNs) are vulnerable to adversarial attacks. Particularly, adversarially perturbing the graph structure, e.g., flipping edges, can lead to salient degeneration of GNNs’ accuracy. In general, efficiency and stealthiness are two significant metrics to evaluate an attack method in practical use. However, most prevailing graph structure-based attack methods are query intensive, which impacts their practical use. Furthermore, while the stealthiness of perturbations has been discussed in previous studies, the majority of them focus on the attack scenario targeting a single node. To fill the research gap, we present a global attack method against GNNs, Saturation adversarial Attack with Meta-gradient, in this article. We first propose an enhanced meta-learning-based optimization method to obtain useful gradient information concerning graph structural perturbations. Then, leveraging the notion of saturation attack, we devise an effective algorithm to determine the perturbations based on the derived meta-gradients. Meanwhile, to ensure stealthiness, we introduce a similarity constraint to suppress the number of perturbed edges. Thorough experiments demonstrate that our method can effectively depreciate the accuracy of GNNs with a small number of queries. While achieving a higher misclassification rate, we also show that the perturbations developed by our method are not noticeable.
Chenhan Zhang, Shiyao Zhang 0001, James Jian Qiao Yu, Shui Yu 0001
ACM Trans. Priv. Secur.1
2022 Graph-Based Traffic Forecasting via Communication-Efficient Federated Learning
abstract
The existing Federated Learning (FL) systems encounter an enormous communication overhead when employing GNN-based models for traffic forecasting tasks since these models commonly incorporate enormous number of parameters to be transmitted in the FL systems. In this paper, we propose a FL framework, namely, C lustering-based hierarchical and T wo-step- optimized FL (CTFL), to overcome this practical problem. CTFL employs a divide-and-conquer strategy, clustering clients based on the closeness of their local model parameters. Furthermore, we incorporate the particle swarm optimization algorithm in CTFL, which employs a two-step strategy for optimizing local models. This technique enables the central server to upload only one representative local model update from each cluster, thus reducing the communication overhead associated with model update transmission in the FL. Comprehensive case studies on two real-world datasets and two state-of-the-art GNN-based models demonstrate the proposed framework’s outstanding training efficiency and prediction accuracy, and the hyperparameter sensitivity of CTFL is also investigated.
Chenhan Zhang, Shiyao Zhang 0001, Shui Yu 0001, James Jian Qiao Yu
WCNC1
2022 Challenges and future directions of secure federated learning: a survey
Xuan Song 0001, Chenhan Zhang, Shui Yu 0001
Frontiers Comput. Sci.3
2022 A Communication-Efficient Federated Learning Scheme for IoT-Based Traffic Forecasting
abstract
Federated learning (FL) is widely adopted in traffic forecasting tasks involving large-scale IoT-enabled sensor data since its decentralization nature enables data providers’ privacy to be preserved. When employingstate-of-the-artdeep learning-based traffic predictors in FL systems, the existing FL frameworks confront overlarge communication overhead when transmitting these models’ parameter updates since the modeling depth and breadth renders them incorporating an enormous number of parameters. In this article, we propose a practical FL scheme, namely, Clustering-based hierarchical and Two-step-optimized FL (CTFed), to tackle this issue. The proposed scheme follows adivide et imperastrategy that clusters the clients into multiple groups based on the similarity between their local models’ parameters. We integrate the particle swarm optimization algorithm and devises a two-step approach for local model optimization. This scheme enables only one but representative local model update from each cluster to be uploaded to the central server, thus reduces the communication overhead of the model updates transmission in FL. CTFed is orthogonal to the gradient compression- or sparsification-based approaches so that they can orchestrate to optimize the communication overhead. Extensive case studies on three real-world data sets and threestate-of-the-artmodels demonstrate the outstanding training efficiency, accurate prediction performance, and robustness to unstable network environments of the proposed scheme.
Chenhan Zhang, Lei Cui 0006, Shui Yu 0001, James Jian Qiao Yu
IEEE Internet Things J.1
2022 Toward Crowdsourced Transportation Mode Identification: A Semisupervised Federated Learning Approach
abstract
Privacy-preserving transportation mode identification (TMI) is among the key challenges toward future intelligent transportation systems. With recent developments in federated learning (FL), crowdsourcing has emerged as a promising cost-effective data source for training powerful TMI classifiers without compromising users’ data privacy. However, existing TMI approaches have relied heavily on the availability of transportation mode labels, which is often limited in real-world applications. While recent semisupervised studies have partially addressed this issue by assigning pseudolabels to unlabeled data, such practice often degrades classification performance as more unlabeled data are incorporated. In response to this issue, we present a semisupervised FL scheme for TMI termed mean teacher semisupervised FL (MTSSFL). MTSSFL trains a deep neural network ensemble under a novel semisupervised FL framework, achieving highly accurate and privacy-protected crowdsourced TMI without depending on the availability of massive labeled data. MTSSFL introducesconsistency updatingto insert the global model in the gradient updates of the local models that only have unlabeled data to improve their training. We also devisemean-teacher-averaging, a secure parameter aggregation mechanism that further boosts the global model’s TMI performance without requiring additional training. Our extensive case studies on a real-world data set demonstrate that MTSSFL’s classification accuracy is merely 1.1% lower than the state-of-the-art semisupervised TMI approach while being the only one to satisfy FL’s privacy-preserving constraints. In addition, MTSSFL can achieve high accuracy with less training overhead due to the proposed semisupervised learning design.
Chenhan Zhang, Yuanshao Zhu, Christos Markos, Shui Yu 0001, James Jian Qiao Yu
IEEE Internet Things J.1
2022 Long-Term Origin-Destination Demand Prediction With Graph Deep Learning
abstract
Accurate long-term origin-destination demand (OD) prediction can help understand traffic flow dynamics, which plays an essential role in urban transportation planning. However, the main challenge originates from the complex and dynamic spatial-temporal correlation of the time-varying traffic information. In response, a graph deep learning model for long-term OD prediction (ST-GDL) is proposed in this paper, which is among the pioneering work that obtains both short-term and long-term OD predictions simultaneously. ST-GDL avoids the conventional multi-step forecasting and thus prevents learning from prediction errors, rendering better long-term forecasts. The proposed method captures time attributes from multiple time scales, namely closeness, periodicity, and trend, to study the features with temporal dynamics. Besides, two gate mechanisms are introduced over the vanilla convolution operation to alleviates the error accumulation issue of typical recurrent forecast in long-term OD prediction. A method based on graph convolution is proposed to capture the dynamic spatial relationship, which projects the transportation network into a graphical time-series. Finally, the long-term OD prediction results are obtained by combining the extracted spatio-temporal features with external features from the meteorological information. Case studies on a practical dataset show that the proposed model is superior to existing methods in long-term OD prediction problems.
Xiexin Zou, Shiyao Zhang 0001, Chenhan Zhang, James Jian Qiao Yu, Edward Chung 0001
IEEE Trans. Big Data3
2021 Safeguard the Original Data in Federated Learning via Data Decomposition
abstract
In federated learning, more and more studies have discovered that attackers can recover the original data from the shared gradients of participants. However, existing defense models struggle to balance the privacy of participants and the effectiveness of federated learning in the face of cutting-edge attack models. Therefore, we propose a powerful defense model to protect the original data while ensuring the effect of classification. First, we get two featured datasets from original data based on Sparse Dictionary Learning (DL) or QR decomposition. In these two featured datasets, we select one dataset to replace the original data for federated training named co-trained data, and the other one is kept on the local client named left data. At this point, the adversary in federated learning can only obtain co-trained data, which cannot recover the original data due to the lack of left data. Following the completion of the federated learning, the participant requests a parameter from the server. Using this parameter, we can combine the aggregated global model over co-trained data with the offline-trained local model of an arbitrary participant to develop the final classification results. Some theories and a lot of experiments demonstrate the classification effectiveness of our model. It also can be a general solution to the original data leakage problems caused by gradient leakage.
Chenhan Zhang, Shui Yu 0001
GLOBECOM2
2021 TSTNet: A Sequence to Sequence Transformer Network for Spatial-Temporal Traffic Prediction
Xiaozhuang Song, Chenhan Zhang
ICANN (1)3
2021 Complicating the Social Networks for Better Storytelling: An Empirical Study of Chinese Historical Text and Novel
abstract
Digital humanities is an important subject because it enables developments in history, literature, and films. In this article, we perform an empirical study of a Chinese historical text, Records of the Three Kingdoms (Records), and a historical novel of the same story, Romance of the Three Kingdoms (Romance). We employ deep-learning-based natural language processing (NLP) techniques to extract characters and their relationships. The adopted NLP approach can extract 93% and 91% characters that appeared in the two books, respectively. Then, we characterize the social networks and sentiments of the main characters in the historical text and the historical novel. We find that the social network in Romance is more complex and dynamic than that of Records, and the influence of the main characters differs. These findings shed light on the different styles of storytelling in the two literary genres and how the historical novel complicates the social networks of characters to enrich the literariness of the story.
Chenhan Zhang, Qingpeng Zhang, Shui Yu 0001, James Jian Qiao Yu, Xiaozhuang Song
IEEE Trans. Comput. Soc. Syst.1
2021 FASTGNN: A Topological Information Protected Federated Learning Approach for Traffic Speed Forecasting
abstract
Federated learning has been applied to various tasks in intelligent transportation systems to protect data privacy through decentralized training schemes. The majority of the state-of-the-art models in intelligent transportation systems (ITS) are graph neural networks (GNN)-based for spatial information learning. When applying federated learning to the ITS tasks with GNN-based models, the existing frameworks can only protect the data privacy; however, ignore the one of topological information of transportation networks. In this article, we propose a novel federated learning framework to tackle this problem. Specifically, we introduce a differential privacy-based adjacency matrix preserving approach for protecting the topological information. We also propose an adjacency matrix aggregation approach to allow local GNN-based models to access the global network for a better training effect. Furthermore, we propose a GNN-based model named attention-based spatial-temporal graph neural networks (ASTGNN) for traffic speed forecasting. We integrate the proposed federated learning framework and ASTGNN as FASTGNN for traffic speed forecasting. Extensive case studies on a real-world dataset demonstrate that FASTGNN can develop accurate forecasting under the privacy preservation constraint.
Chenhan Zhang, Shuyu Zhang 0003, James Jian Qiao Yu, Shui Yu 0001
IEEE Trans. Ind. Informatics1
2020 An Enhanced Motif Graph Clustering-Based Deep Learning Approach for Traffic Forecasting
abstract
Traffic speed prediction is among the key problems in intelligent transportation system (ITS). Traffic patterns with complex spatial dependency make accurate prediction on traffic networks a challenging task. Recently, a deep learning approach named Spatio-Temporal Graph Convolutional Networks (STGCN) has achieved state-of-the-art results in traffic speed prediction by jointly exploiting the spatial and temporal features of traffic data. Nonetheless, applying STGCN to large-scale urban traffic network may develop degenerated results, which is due to redundant spatial information engaging in graph convolution. In this work, we propose a motif-based graph-clustering approach to apply STGCN to large-scale traffic networks. By using graph clustering, we partition a large urban traffic network into smaller clusters to prompt the learning effect of graph convolution. The proposed approach is evaluated on two real-world datasets and is compared with its variants and baseline methods. The results show that graph-clustering approaches generally outperform the other methods, and the proposed approach obtains the best performance.
Chenhan Zhang, Shuyu Zhang 0003, James Jian Qiao Yu, Shui Yu 0001
GLOBECOM1