Jianli Bai

dblp:267/1089 · DBLP profile ↗
← Back
13ranked-venue papers
5as first author
11since 2021 · last 2025
0000-0001-6468-629XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 3 first-author · 10 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSystems, architecture and hardware · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Guard-GBDT: Efficient Privacy-Preserving Approximated GBDT Training on Vertical Dataset
abstract
In light of increasing privacy concerns and stringent legal regulations, using secure multiparty computation (MPC) to enable collaborative GBDT model training among multiple data owners has garnered significant attention. Despite this, existing MPC-based GBDT frameworks face efficiency challenges due to high communication costs and the computation burden of non-linear operations, such as division and sigmoid calculations. In this work, we introduce Guard-GBDT, an innovative framework tailored for efficient and privacy-preserving GBDT training on vertical datasets. Guard-GBDT bypasses MPC-unfriendly division and sigmoid functions by using more streamlined approximations and reduces communication overhead by compressing the messages exchanged during gradient aggregation. We implement a prototype of Guard-GBDT and extensively evaluate its performance and accuracy on various real-world datasets. The results show that Guard-GBDT outperforms state-of-the-art HEP-XGB (CIKM’21) and SiGBDT (ASIA CCS’24) by up to $2.71 \times$ and $12.21 \times$ on LAN network and up to $2.7 \times$ and $8.2 \times$ on WAN network. Guard-GBDT also achieves comparable accuracy with SiGBDT and plaintext XGBoost (better than HEP-XGB), which exhibits a deviation of ±1% to ±2% only. Our implementation code is provided at https://github.com/XidianNSS/Guard-GBDT.git
Anxiao Song, Shujie Cui, Jianli Bai, Ke Cheng 0001, Yulong Shen 0001, Giovanni Russello
RAID3
2025 XGT: Fast and Secure Decision Tree Training and Inference on GPUs
abstract
The decision tree (DT) model is widely usedin various applications due to its versatility, speed, and interpretability. However, outsourcing DT training and inference to cloud platforms raises data privacy concerns. While significant strides have been made in developing private DT training and inference using cryptography such as Secure Multi-Party Computation (MPC), the performance is still not ideal in real-world applications. Only a few recent works have explored using GPUs to enhance the performance of MPC-based deep learning. Nevertheless, data-dependent operations and the high communication costs inherent in MPC-based DT make the integration of GPUs a challenge. We introduce the eXpress GPU-based Tree (XGT), a fast MPC-based framework for private DT training and inference on GPUs.XGTconverts the majority of operations in training and inference into parallelizable matrix operations, supplemented by various optimizations, including matrix dimension reductions. This innovative design leads to substantial reductions in communication overhead while maintaining the critical property of obliviousness.XGTalso achieves a stronger security guarantee, where all data items, the tree shape, access patterns, and data distributions generated during the training and inference are protected.XGTonly reveals the tree depth. The experimental results show thatXGTis up to$278{\times }$faster than the previous most efficient CPU-based approach.XGToutperforms the latest GPU-based DT work by$41{\times }$. For inference,XGTis up to$2,800{\times }$faster than previous CPU-based inference schemes and at least$18 \times$faster than GPU-based.
Qifan Wang 0003, Shujie Cui, Lei Zhou 0023, Ye Dong, Jianli Bai, Yun Sing Koh, Giovanni Russello
IEEE Trans. Dependable Secur. Comput.5
2024 DISCO: Dynamic Searchable Encryption with Constant State
abstract
Dynamic searchable encryption (DSE) with forward and backward privacy reduces leakages in early-stage schemes. Security enhancement comes with a price - maintaining updatable keyword-wise state information. State information, if stored locally, incurs significant client-side storage overhead for keyword-rich datasets, potentially hindering real-world deployments.
Xiangfu Song, Yu Zheng 0021, Jianli Bai, Changyu Dong, Zheli Liu, Ee-Chien Chang
AsiaCCS3
2024 Secret-Shared Shuffle with Malicious Security
Xiangfu Song, Jianli Bai, Changyu Dong, Ee-Chien Chang
NDSS3
2024 GTree: GPU-friendly Privacy-preserving Decision Tree Training and Inference
abstract
Outsourcing Decision tree (DT) training and inference to cloud platforms raises privacy concerns. Recent Secure Multi-Party Computation (MPC)-based methods are hindered by heavy overhead. Few recent studies explored GPUs to improve MPC-protected deep learning, yet integrating GPUs into MPC-protected DT with massive data-dependent operations remains challenging, raising question: can MPC-protected DT training and inference fully leverage GPUs for optimal performance?We present GTree, the first scheme that exploits GPU to accelerate MPC-protected secure DT training and inference. GTree is built across 3 parties who jointly perform DT training and inference with GPUs. GTree is secure against semi-honest adversaries, ensuring that no sensitive information is disclosed. GTree offers enhanced security than prior solutions, which only reveal tree depth and data size while prior solutions also leak tree structure. With our oblivious array access, access patterns on GPU are also protected. To harness the full potential of GPUs, we design a novel tree encoding method and craft our MPC protocols into GPU-friendly versions. GTree achieves ~11× and ~21× improvements in training SPECT and Adult datasets, compared to prior most efficient CPU-based work. For inference, GTree outperforms the prior most efficient work by 126× when inferring 104instances with a 7-level tree.
Qifan Wang 0003, Shujie Cui, Lei Zhou 0023, Ye Dong, Jianli Bai, Yun Sing Koh, Giovanni Russello
TrustCom5
2024 OHSS: Optimizing Homomorphic Secret Sharing to Support Fast Matrix Multiplication
abstract
Homomorphic Secret Sharing (HSS) has evolved as a state-of-the-art methodology for achieving secure two-party computation, synthesizing the advantages of secret sharing and homomorphic encryption. This amalgamation ensures minimal computational and communicational overhead, making it particularly adept at arithmetic operations. However, HSS faces challenges in scalability and efficiency when confronted with extensive matrix operations, including both matrix-vector and matrix-matrix multiplications, which are fundamental in numerous privacy-preserving computations, notably within the realm of privacy-preserving machine learning. In this research, we introduce Optimized Homomorphic Secret Sharing (OHSS), a refined version of HSS, crafted to address these limitations. Our contributions include enhancements to the key generation phase alongside the development of efficient algorithms for matrix-vector multiplication and matrix-matrix multiplication. Comprehensive security evaluations and performance benchmarks demonstrate that OHSS not only fulfills stringent security criteria but also boasts superior efficiency.
Jianli Bai, Kun Tu, Ziyue Yin, Chan Liu
TrustCom2
2023 Mostree: Malicious Secure Private Decision Tree Evaluation with Sublinear Communication
abstract
A private decision tree evaluation (PDTE) protocol allows a feature vector owner (FO) to classify its data using a tree model from a model owner (MO) and only reveals an inference result to the FO. This paper proposes Mostree, a PDTE protocol secure in the presence of malicious parties with sublinear communication. We design Mostree in the three-party honest-majority setting, where an (untrusted) computing party (CP) assists the FO and MO in the secure computation. We propose two low-communication oblivious selection (OS) protocols by exploiting nice properties of three-party replicated secret sharing (RSS) and distributed point function. Mostree combines OS protocols with a tree encoding method and three-party secure computation to achieve sublinear communication. We observe that most of the protocol components already maintain privacy even in the presence of a malicious adversary, and what remains to achieve is correctness. To ensure correctness, we propose a set of lightweight consistency checks and seamlessly integrate them into Mostree. As a result, Mostree achieves sublinear communication and malicious security simultaneously. We implement Mostree and compare it with the state-of-the-art. Experimental results demonstrate that Mostree is efficient and comparable to semi-honest PDTE schemes with sublinear communication. For instance, when evaluated on the MNIST dataset in a LAN setting, Mostree achieves an evaluation using approximately 768 ms with communication of around 168 KB.
Jianli Bai, Xiangfu Song, Qifan Wang 0003, Shujie Cui, Ee-Chien Chang, Giovanni Russello
ACSAC1
2023 CryptoMask: Privacy-Preserving Face Recognition
Jianli Bai, Xiangfu Song, Shujie Cui, Giovanni Russello
ICICS1
2023 HT2ML: An efficient hybrid framework for privacy-preserving Machine Learning using HE and TEE
abstract
Outsourcing Machine Learning (ML) tasks to cloud servers is a cost-effective solution when dealing with distributed data. However, outsourcing these tasks to cloud servers could lead to data breaches. Secure computing methods, such as Homomorphic Encryption (HE) and Trusted Execution Environments (TEE), have been used to protect outsourced data. Nevertheless, HE remains inefficient in processing complicated functions (e.g., non-linear functions) and TEE (e.g., Intel SGX) is not ideal for directly processing ML tasks due to side-channel attacks and parallel-unfriendly computation. In this paper, we propose a hybrid framework integrating SGX and HE, called HT2ML, to protect user's data and models. In HT2ML, HE-friendly functions are protected with HE and performed outside the enclave, while the remaining operations are performed inside the enclave obliviously. HT2ML leverages optimised HE matrix multiplications to accelerate HE computations outside the enclave while using oblivious blocks inside the enclave to prevent access-pattern-based attacks. We evaluate HT2ML using Linear Regression (LR) training and Convolutional Neural Network (CNN) inference as two instantiations. The performance results show that HT2ML is up to ∼11× faster than HE only baseline with 6-dimensional data in LR training. For CNN inference, HT2ML is ∼196× faster than the most recent approach (Xiao et al., ICDCS'21).
Qifan Wang 0003, Lei Zhou 0023, Jianli Bai, Yun Sing Koh, Shujie Cui, Giovanni Russello
Comput. Secur.3
2022 Scalable Private Decision Tree Evaluation with Sublinear Communication
abstract
Private decision tree evaluation (PDTE) allows a decision tree holder to run a secure protocol with a feature provider. By running the protocol, the feature provider will learn a classification result. Nothing more is revealed to either party. In most existing PDTE protocols, the required communication grows exponentially with the tree's depth d, which is highly inefficient for large trees. This shortcoming motivated us to design a sublinear PDTE protocol with $O(d)$ communication complexity. The core of our construction is a shared oblivious selection (SOS) functionality, allowing two parties to perform a secret-shared oblivious read operation from an array. We provide two SOS protocols, both of which achieve sublinear communication and propose optimizations to further improve their efficiency. Our sublinear PDTE protocol is based on the proposed SOS functionality and we prove its security under a semi-honest adversary. We compare our protocol with the state-of-the-art, in terms of communication and computation, under various network settings. The performance evaluation shows that our protocol is practical and more scalable over large trees than existing solutions.
Jianli Bai, Xiangfu Song, Shujie Cui, Ee-Chien Chang, Giovanni Russello
AsiaCCS1
2022 SPPS: A Search Pattern Privacy System for Approximate Shortest Distance Query of Encrypted Graphs in IIoT
abstract
In recent years, Industrial Internet of Things (IIoT) has gradually attracted the attention of the industry owing to its accurate time synchronization, communication accuracy, and high adaptability. As an important data structure, graphs are widely used in IIoT applications, where entities and their relationships can be expressed in the form of graphs. With the widespread adoption of IIoT and cloud computing, an increasing number of individuals or organizations are outsourcing their IIoT graph data to cloud servers to enjoy the unlimited storage space and fast computing service. To protect the privacy of graph data, graphs are usually encrypted before being outsourced. In this article, we propose a search pattern privacy system for approximate shortest distance query of encrypted graphs in IIoT. To realize search pattern privacy, we adopt two noncolluded cloud servers to accomplish different tasks. We leverage the first server to store the encrypted data and perform query operations, and use the second one to rerandomize the contents and shuffle the locations of the queried records. Before queries, we generate the trapdoors by using different random numbers. After queries, we ask the second server to rerandomize the contents of the records that the first server touched. In addition, we shuffle the physical locations of original records by inserting some fake records. In this way, all contents and physical locations of the touched records change, so that the first server cannot distinguish whether two queries are the same or not. To enhance the efficiency on the user side, we further improve this system by moving some heavy workloads from the user to the cloud. The security analysis and the performance evaluation show that our work is secure and efficient.
Xinrui Ge, Jia Yu 0003, Hanlin Zhang 0001, Jianli Bai, Jianxi Fan, Naixue Xiong
IEEE Trans. Syst. Man Cybern. Syst.4
2020 Secure auditing and deduplication for encrypted cloud data supporting ownership modification
Jianli Bai, Jia Yu 0003, Xiang Gao 0021
Soft Comput.1
2020 Comment on "Privacy-preserving public auditing for non-manager group shared data"
Jianli Bai, Rong Hao
J. Supercomput.1