VLDB 2026 Research / reviewers in the wild / expert
Jiacheng Du
dblp:258/2604
· DBLP profile ↗
7ranked-venue papers
4as first author
6since 2021 · last 2026
0009-0001-3572-1567ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 2 · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PT-Mark: Invisible Watermarking for Text-to-Image Diffusion Models via Semantic-Aware Pivotal TuningabstractWatermarking for diffusion images has drawn considerable attention due to the widespread use of text-to-image diffusion models and the increasing need for their copyright protection. Recently, advanced watermarking techniques, such as Tree-Ring, integrate watermarks by embedding traceable patterns (e.g., Rings) into the latent distribution during the diffusion process. Such methods disrupt the original semantics of the generated images due to the inevitable distribution shift caused by the watermarks, thereby limiting their practicality, particularly in digital art creation. In this work, we present Semantic-aware Pivotal Tuning Watermarks (PT-Mark), a novel invisible watermarking method that preserves both the semantics of diffusion images and the traceability of the watermark. PT-Mark preserves the original semantics of the watermarked image by gradually aligning the generation trajectory with the original (pivotal) trajectory while maintaining the traceable watermarks during whole diffusion denoising process. To achieve this, we first compute the salient regions of the watermark at each diffusion denoising step as a spatial prior to identify areas that can be aligned without disrupting the watermark pattern. Guided by the region, we then introduce an additional pivotal tuning branch that optimizes the null-text embedding to align the semantics while preserving the watermarks. Extensive evaluations demonstrate that PT-Mark can preserve the original semantics of the diffusion images while integrating robust watermarks. It achieves a 10% improvement in the performance of semantic preservation compared to state-of-the-art watermarking methods, while also showing comparable robustness against real-world perturbations and four times greater efficiency. The code is available athttps://github.com/annpion/PT-Mark. Yaopeng Wang, Huiyu Xu, Zhibo Wang 0001, Jiacheng Du, Yiming Li 0004, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Textual Unlearning Gives a False Sense of UnlearningabstractLanguage Models (LMs) are prone to ''memorizing'' training data, including substantial sensitive user information. To mitigate privacy risks and safeguard the right to be forgotten, machine unlearning has emerged as a promising approach for enabling LMs to efficiently ''forget'' specific texts. However, despite the good intentions, is textual unlearning really as effective and reliable as expected? To address the concern, we first propose Unlearning Likelihood Ratio Attack+ (U-LiRA+), a rigorous textual unlearning auditing method, and find that unlearned texts can still be detected with very high confidence after unlearning. Further, we conduct an in-depth investigation on the privacy risks of textual unlearning mechanisms in deployment and present the Textual Unlearning Leakage Attack (TULA), along with its variants in both black- and white-box scenarios. We show that textual unlearning mechanisms could instead reveal more about the unlearned texts, exposing them to significant membership inference and data reconstruction risks. Our findings highlight that existing textual unlearning actually gives a false sense of unlearning, underscoring the need for more robust and secure unlearning mechanisms. Jiacheng Du, Zhibo Wang 0001, Jie Zhang 0081, Xiaoyi Pang, Jiahui Hu 0001, Kui Ren 0001 |
ICML | 1 |
| 2025 | SoK: On Gradient Leakage in Federated Learning
Jiacheng Du, Jiahui Hu 0001, Zhibo Wang 0001, Peng Sun 0003, Neil Zhenqiang Gong, Kui Ren 0001, Chun Chen 0001 |
USENIX Security Symposium | 1 |
| 2024 | Breaking Secure Aggregation: Label Leakage from Aggregated Gradients in Federated LearningabstractFederated Learning (FL) exhibits privacy vulnerabilities under gradient inversion attacks (GIAs), which can extract private information from individual gradients. To enhance privacy, FL incorporates Secure Aggregation (SA) to prevent the server from obtaining individual gradients, thus effectively resisting GIAs. In this paper, we propose a stealthy label inference attack to bypass SA and recover individual clients’ private labels. Specifically, we conduct a theoretical analysis of label inference from the aggregated gradients that are exclusively obtained after implementing SA. The analysis results reveal that the inputs (embeddings) and outputs (logits) of the final fully connected layer (FCL) contribute to gradient disaggregation and label restoration. To preset the embeddings and logits of FCL, we craft a fishing model by solely modifying the parameters of a single batch normalization (BN) layer in the original model. Distributing client-specific fishing models, the server can derive the individual gradients regarding the bias of FCL by resolving a linear system with expected embeddings and the aggregated gradients as coefficients. Then the labels of each client can be precisely computed based on preset logits and gradients of FCL’s bias. Extensive experiments show that our attack achieves large-scale label recovery with 100% accuracy on various datasets and model architectures. Zhibo Wang 0001, Zhiwei Chang, Jiahui Hu 0001, Xiaoyi Pang, Jiacheng Du, Yongle Chen, Kui Ren 0001 |
INFOCOM | 5 |
| 2024 | Does Differential Privacy Really Protect Federated Learning From Gradient Leakage Attacks?abstractFederated Learning (FL) is susceptible to the gradient leakage attack (GLA), which can recover local private training data from the shared gradients or model updates. To ensure privacy, differential privacy is applied in FL by clipping and adding noise to local gradients (i.e., Local Differential Privacy (LDP)) or the global model update (i.e., Central Differential Privacy (CDP)). However, the effectiveness of DP in defending GLAs needs to be thoroughly investigated since some works briefly verify that DP can guard FL against GLAs while others question its defense capability. In this paper, we empirically evaluate CDP and LDP on the resistance of GLAs, and pay close attention to the trade-offs between privacy and utility in FL. Our findings reveal that: 1) existing GLAs can be defended by CDP using a per-layer clipping strategy and LDP with a reasonable privacy guarantee and 2) both CDP and LDP ensure the trade-off between privacy and utility in training shallow model, but cannot guarantee this trade-off in deeper model training (e.g., ResNets). Triggered by the crucial role of clipping operation for DP, we propose an improved attack that incorporates the clipping operation into existing GLAs without requiring additional information. The experimental results show our attack can destruct the protection of CDP and weaken the effectiveness of LDP. Overall, our work validates the effectiveness as well as reveals the vulnerability of DP under GLAs. We hope this work can provide guidance on utilizing DP for defending against GLA in FL and inspire the design of future privacy-preserving FL. Jiahui Hu 0001, Jiacheng Du, Zhibo Wang 0001, Xiaoyi Pang, Peng Sun 0003, Kui Ren 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2022 | Evolutionary Algorithms with Heuristic Gradient-based Repair for Constrained OptimizationabstractGradient-based repair aims to repair infeasible solutions to feasible ones using the gradient information of the constraints. As an effective constraint handling method, gradientbased repair has received extensive attention and has been applied in various evolutionary algorithms (EAs). Nevertheless, due to the complexity of constraints in practical problems, a single infeasible solution often needs to be repaired multiple times until it becomes a feasible solution or reaches the maximum number of repairs. As far as we know, existing related research on gradient-based repair mainly applies this method directly to EAs, while there is little work in the evolutionary computing community on how to improve gradient-based repair. Currently, the multiple repairs for a single individual are independent. That is, the current repair does not consider the previous repair experience. However, only using gradient information to repair infeasible individuals may result in oscillations in the search process. Therefore, in this paper, we propose a heuristic gradient-based repair method (HGR) which exploits the previous repair information of an individual to alleviate this issue. Experimental results on several benchmarks demonstrate the effectiveness of the proposed method. The source code is available at https://github.com/DMiC-Lab-HFUT/HGR-SMC2022. Jiacheng Du, Chenyang Bu, Fei Liu 0038, Wenjian Luo |
SMC | 1 |
| 2020 | Reinforcement Learning Empowered QoS-aware Adaptive Q-Routing in Ad-hoc NetworksabstractWith the rapid growth of the network applications, more services with diverse QoS requirements have emerged. Efficient routing technique plays a vital role in supporting the diversified serveries in dynamically changing wireless multi-hop networks. To this end, we propose the reinforcement learning empowered QoS-aware adaptive Q-routing (RL-QAQ) algorithm, so as to provide discriminated transmission for different services with various QoS requirements as well as reduce the delivery delay and routing overhead. In the proposed RL-QAQ algorithm, an adaptive probability is devised to optimize the exploration strategy to reduce the overhead of acquiring the network status. Besides, the QoS-aware reward function and Q-tables for the different services are devised to support multi-QoS transmission requirements. Simulation results demonstrate that the proposed RL-QAQ algorithm can adaptively adjust the routing policy according to the varying network environment to meet the transmission requirements of different services with low delivery delay and routing overhead. Jiacheng Du, Fan Wu 0012, Supeng Leng |
IWCMC | 1 |