VLDB 2026 Research / reviewers in the wild / expert
Peng Chen 0030
dblp:27/7017-30
· DBLP profile ↗
9ranked-venue papers
5as first author
9since 2021 · last 2025
0000-0001-6545-4941ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | UIFV: Data Reconstruction Attack in Vertical Federated LearningabstractVertical Federated Learning (VFL) enables collaborative machine learning without the need for participants to share their raw private data. However, recent studies have uncovered privacy risks, where adversaries might reconstruct sensitive features through data leakage during the learning process. Al-though existing data reconstruction methods are effective to some extent, they exhibit limitations in VFL scenarios, as initiating an attack requires meeting more stringent conditions. To gain a comprehensive understanding of the risks of data reconstruction in VFL, this paper proposes a unified framework, the Unified InverNet Framework in VFL (UIFV), for data reconstruction under realistic black-box threat models. Within the UIFV framework, we consider four attack scenarios, strictly adhering to VFL protocols to maintain confidentiality. Experiments on four datasets show that our methods significantly outperform state-of-the-art techniques in terms of applicability and attack precision. Our work reveals severe privacy vulnerabilities within VFL systems that pose real threats to practical VFL applications, thus confirming the necessity of further enhancing privacy protection in the VFL architecture. Overall, this paper provides a thorough analysis of the risks of data reconstruction in VFL and offers important guidance to enhance the security of VFL deployments. Jirui Yang, Peng Chen 0030, Zhihui Lu 0002, Qiang Duan 0002, Yubing Bao |
ICWS | 2 |
| 2025 | Universal Backdoor Defense via Label Consistency in Vertical Federated LearningabstractBackdoor attacks in vertical federated learning (VFL) are particularly concerning as they can covertly compromise VFL decision-making, posing a severe threat to critical applications of VFL. Existing defense mechanisms typically involve either label obfuscation during training or model pruning during inference. However, the inherent limitations on the defender's access to the global model and complete training data in VFL environments fundamentally constrain the effectiveness of these conventional methods. To address these limitations, we propose the Universal Backdoor Defense (UBD) framework. UBD leverages Label Consistent Clustering (LCC) to synthesize plausible latent triggers associated with the backdoor class. This synthesized information is then utilized for mitigating backdoor threats through Linear Probing (LP), guided by a constraint on Batch Normalization (BN) statistics. Positioned within a unified VFL backdoor defense paradigm, UBD offers a generalized framework for both detection and mitigation that critically does not necessitate access to the entire model or dataset. Extensive experiments across multiple datasets rigorously demonstrate the efficacy of the UBD framework, achieving state-of-the-art performance against diverse backdoor attack types in VFL, including both dirty-label and clean-label variants. Peng Chen 0030, Haolong Xiang, Xin Du 0002, Xiaolong Xu 0001, Xuhao Jiang, Zhihui Lu 0002, Jirui Yang, Qiang Duan 0002, Wan-Chun Dou |
IJCAI | 1 |
| 2025 | Backdoor Attack on Vertical Federated Graph Neural Network LearningabstractFederated Graph Neural Network (FedGNN) integrate federated learning (FL) with graph neural networks (GNNs) to enable privacy-preserving training on distributed graph data. Vertical Federated Graph Neural Network (VFGNN), a key branch of FedGNN, handles scenarios where data features and labels are distributed among participants. Despite the robust privacy-preserving design of VFGNN, we have found that it still faces the risk of backdoor attacks, even in situations where labels are inaccessible. This paper proposes BVG, a novel backdoor attack method that leverages multi-hop triggers and backdoor retention, requiring only four target-class nodes to execute effective attacks. Experimental results demonstrate that BVG achieves nearly 100% attack success rates across three commonly used datasets and three GNN models, with minimal impact on the main task accuracy. We also evaluated various defense methods, and the BVG method maintained high attack effectiveness even under existing defenses. This finding highlights the need for advanced defense mechanisms to counter sophisticated backdoor attacks in practical VFGNN applications. Jirui Yang, Peng Chen 0030, Zhihui Lu 0002, Jianping Zeng 0002, Qiang Duan 0002, Xin Du 0002, Ruijun Deng |
IJCAI | 2 |
| 2025 | A Data Replication Placement Strategy for the Distributed Storage System in Cloud-Edge-Terminal Orchestrated Computing EnvironmentsabstractCloud-edge-terminal orchestrated computing, as an expansion of cloud computing, has sunk resources to the edge nodes and terminal equipment, which can provide high-quality services for delay-sensitive applications and reduce the cost of network communication. Due to the high volume of data generated by Internet of Things (IoT) devices and the limited storage capacities of edge nodes, a significant number of terminal devices are now being considered for utilization as storage nodes. However, because of the heterogeneous storage capacity and reliability of these hardware devices and the different data requirements of user services, the performance and storage reliability of applications deployed in cloud-edge-terminal orchestrated computing environments have become urgent problems to be solved. Especially, for a distributed storage system in these environments, it is required to ensure reliable storage of the generated data and its’ replications. In this paper, we first implement a distributed storage system and construct a data replication placement model. Then, based on the constructed model, we formulate the data replication placement problem and design a data replication placement strategy called DRPS to solve it. The DRPS covers a ranks-based replication storage node selection algorithm and a greedy load balancing algorithm, which can select appropriate hardware devices for different data requirements of services and is implemented in the data storage system to store replications and balance loads. We design extensive experiments to verify the effectiveness of DRPS. The results indicate that the proposed strategy outperforms other state-of-the-art algorithms in terms of system delay reduction by 39.9%, an increase of 43.3% in the replication numbers, a 27.5% improvement in memory utilization, and a reduction of unreliability rate by 82.0%. Peng Chen 0030, Mengke Zheng, Xin Du 0002, Muhammad Bilal 0003, Zhihui Lu 0002, Qiang Duan 0002, Xiaolong Xu 0001 |
IEEE Internet Things J. | 1 |
| 2024 | FINSEC: An Efficient Microservices-Based Detection Framework for Financial AI Model SecurityabstractArtificial intelligence technology, such as fraud detection and biometrics, has recently been widely used in financial security. However, the related machine learning models may have algorithmic risks, and attackers can use loopholes in the models themselves to circumvent censorship or even steal private data. Our research team has designed and implemented a cloud service-based algorithmic risk detection platform for fintech products using advanced AI technologies to address this challenge. The platform can assess the algorithmic risk of machine learning models used for regulation in several common scenarios in the financial sector and provide early warnings of potential risk factors. Our platform, built upon cloud services, boasts high performance and embraces the principle of loose coupling. Our research aims to furnish the FinTech industry with a pragmatic tool for model algorithm risk detection. Peng Chen 0030, Zhihui Lu 0002, Xiaozheng Du |
CSCloud | 3 |
| 2024 | Universal adversarial backdoor attacks to fool vertical federated learning
Peng Chen 0030, Xin Du 0002, Zhihui Lu 0002, Hongfeng Chai |
Comput. Secur. | 1 |
| 2024 | Towards transferable adversarial attacks on vision transformers for image classification
Xu Guo 0004, Peng Chen 0030, Zhihui Lu 0002, Hongfeng Chai, Xin Du 0002 |
J. Syst. Archit. | 2 |
| 2023 | A Practical Clean-Label Backdoor Attack with Limited Information in Vertical Federated LearningabstractVertical Federated Learning (VFL) facilitates collaboration on model training among multiple parties, each owning partitioned features of the distributed dataset. Although backdoor attacks have been found as one of the main threats to FL security, research on backdoor attacks in VFL is still in the infant stage. Existing methods for VFL backdoor attacks rely on predicting sample pseudo-labels using approaches such as label inference, which require substantial additional information not readily available in practical FL scenarios. To evaluate the practical vulnerability of VFL to backdoor attacks, we present a target-efficient clean backdoor (TECB) attack for VFL. The TECB approach consists of two phases – i) Clean Backdoor Poisoning (CBP) and Target Gradient Alignment (TGA). In the CBP phase, the adversary trains a backdoor trigger and poisons the model during VFL training. The poisoned model is further fine-tuned in the TGA phase to enhance its efficacy in complex multi-classification tasks. Compared to the existing methods, the proposed TECB achieves a highly effective backdoor attack with very limited information about the target class samples, which is more practical in typical VFL settings. Experimental results verify the superior performance of TECB, achieving above 97% attack success rate (ASR) on three widely used datasets (CIFAR10, CIFAR100, and CINIC-10) with only 0.1% of target labels known, which outperforms the state-of-the-art attack methods. This study uncovers the potential backdoor risks in VFL, enabling the development of secure VFL applications in areas like finance, healthcare, and beyond. Source code is available at: https://github.com/13thDayOLunarMay/TECB-attack Peng Chen 0030, Jirui Yang, Junxiong Lin, Zhihui Lu 0002, Qiang Duan 0002, Hongfeng Chai |
ICDM | 1 |
| 2022 | EVFL: An explainable vertical federated learning for data-oriented Artificial Intelligence systems
Peng Chen 0030, Xin Du 0002, Zhihui Lu 0002, Jie Wu 0003, Patrick C. K. Hung |
J. Syst. Archit. | 1 |