VLDB 2026 Research / reviewers in the wild / expert
Heyi Zhang
dblp:27/8035
· DBLP profile ↗
10ranked-venue papers
5as first author
10since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Advancing Wireless Differentially Private Distributed Learning for 6G Applications: A Digital Transmission Design and Analysis
Yilei Xue, Heyi Zhang |
ICC | 3 |
| 2026 | Robust Heterogeneous Federated Learning Against Untargeted Poisoning Attacks via Sign-Space Consistency
Yilei Xue, Heyi Zhang |
ICIC (5) | 3 |
| 2026 | Coded Computing Meets Differential Privacy: Privacy-Preserving and Straggler-Resilient Distributed Machine LearningabstractCoded distributed machine learning mitigates straggler effects and provides privacy protection by introducing redundancy through coded computing. However, the system remains vulnerable to privacy breaches when the number of honest-but-curious nodes surpasses the designed threshold, or when outsider adversaries eavesdrop on sensitive data. To address these limitations, we propose a privacy-preserving and straggler-resilient distributed learning framework, namely, differential privacy-based Lagrange coded computing (DP-LCC). First, we design a three-layer protection strategy against privacy threats and stragglers by retaining labels at the master, obfuscating features via Lagrange interpolation, and injecting calibrated noise into local computations. Second, we theoretically prove that the aggregated gradient is an unbiased estimator with bounded variance, and derive convergence bounds under both Gaussian and Laplace mechanisms, revealing the trade-off between privacy budgets and model utility. Third, we provide a comprehensive analysis of the system's computational complexity, privacy composition, and heterogeneity to verify the framework's efficiency and adaptability in realistic distributed environments. Extensive experiments on four benchmark datasets validate the theoretical results, demonstrating the robustness of DP-LCC against varying system parameters and heterogeneous environments. Yilei Xue, Jun Wu 0001, Xi Lin 0003, Heyi Zhang, Wei Zhang 0304, Xin-Ping Guan |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Building Trust Beyond Update Divergence: Dual-Refined Aggregation for Byzantine-Robust Federated LearningabstractFederated learning (FL) enables collaborative training across distributed clients but remains vulnerable to Byzantine attacks, especially stealthy ones. The threat is even amplified in non-IID settings, where client heterogeneity causes greater divergence in feature distributions and inter-client distances. Existing defenses often rely on strong assumptions or raw update distances, limiting their effectiveness under such heterogeneity. To address this gap, we proposeFedRefiner, a decoupled dual-refined aggregation algorithm designed to mitigate stealthy attacks on heterogeneous data. Our intuition is that the significance distribution of client updates reveals subtle malicious evasion, altering critical features for attack while perturbing unimportant ones, thereby exposing true inter-client distances.FedRefinergoes beyond norm-based filtering by refining both weighted scores and aggregated updates, enabling more accurate distinction between malicious behavior and benign non-IID variation. It first derives significance distribution vectors as refined updates by sparsity, then clusters them to compute weighted similarity scores for group reliability. These clusters then align raw updates into groups for group-wise refinement, yielding robust aggregated updates. We theoretically prove the convergence ofFedRefinerunder Byzantine attacks in non-IID settings. Extensive evaluation on 8 datasets against 10 attacks (including 2 adaptive ones) and 13 defenses shows thatFedRefineroutperforms state-of-the-art defenses, achieving up to a 10% gain in overall accuracy and a 14.8% improvement in worst-case performance under both IID and non-IID settings. Ablation studies further demonstrate its robustness across different hyperparameters, attacker ratios, data heterogeneity, and model/client scales, while incurring low computation and no storage overhead. Heyi Zhang, Xinlei He 0001, Jun Wu 0001, Qian Wang 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Long-Short-GNN: A Novel Graph Neural Network for Detecting FPGA IP Circuits for Hardware AssuranceabstractHardware Assurance (HA) of Integrated Circuit (IC) requires the extraction and analysis of circuit netlist from a manufactured or programmed IC (in the case of Field Programmable Gate Array (FPGA)). The first and most important step in this analysis is to detect Intellectual Property (IP) circuit(s) of interest from an extracted ‘sea-of-gates’ netlist. State-of-the-art approach involves converting the extracted netlist into a graph and using Graph Neural Network (GNN), a powerful machine-learning method on graphs for IP circuit detection. However, reported methods usually employed shallow GNNs with small receptive fields which are inadequate for detecting large and complete IP circuits. In this paper, we propose a novel GNN, coined Long-Short-GNN, which uniquely incorporates a Long-view Network (for global coarse-grained information) and a Short-view Network (for local fine-grained information) for FPGA IP circuit detection. By experiments on detecting a variety of large and complete FPGA IP circuits, we proved its efficacy. Specifically, on average, our proposed Long-Short-GNN outperformed all reported methods by a large margin of up to ~13.8% improvement on F1 Score. Heyi Zhang, Tong Lin 0001, Deruo Cheng, Yiqiong Shi, Bah-Hwee Gwee |
ISCAS | 1 |
| 2025 | Byzantine-Resilient Differentially Private Federated Learning: A Dual-Phase Group-Wise Aggregation Approach
Heyi Zhang, Jun Wu 0001 |
WASA (3) | 1 |
| 2025 | Qibo: A Large Language Model for traditional Chinese medicine
Yongzhe Jia, Xin Wang 0030, Heyi Zhang, Zhaopeng Meng, Pengwei Zhuang, Jianguo Wei |
Expert Syst. Appl. | 4 |
| 2025 | Toward Byzantine-Robust Distributed Learning for Sentiment Classification on Social Media PlatformabstractDistributed learning empowers social media platforms to handle massive data for image sentiment classification and deliver intelligent services. However, with the increase of privacy threats and malicious activities, three major challenges are emerging: securing privacy, alleviating straggler problems, and mitigating Byzantine attacks. Although recent studies explore coded computing for privacy and straggler problems, as well as Byzantine-robust aggregation for poisoning attacks, they are not well-designed against both threats simultaneously. To tackle these obstacles and achieve an efficient Byzantine-robust and straggler-resilient distributed learning framework, in this article, we present Byzantine-robust and cost-effective distributed machine learning (BCML), a codesign of coded computing and Byzantine-robust aggregation. To balance the Byzantine resilience and efficiency, we design a cosine-similarity-based Byzantine-robust aggregation method tailored for coded computing to filter out malicious gradients efficiently in real time. Furthermore, trust scores derived from similarity are published to the blockchain for the reliability and traceability of social users. Experimental results show that our BCML can tolerate Byzantine attacks without compromising convergence accuracy with lower time consumption, compared with the state-of-the-art approaches. Specifically, it is 6x faster than the uncoded approach and 2x faster than the Lagrange coded computing (LCC) approach. Besides, the cosine-similarity-based aggregation method can effectively detect and filter out malicious social users in real time. Heyi Zhang, Jun Wu 0001, Ali Kashif Bashir, Marwan Omar |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2024 | Integrating Blockchain and Deep Learning Into Extremely Resource-Constrained IoT: An Energy-Saving Zero-Knowledge PoL ApproachabstractThe convergence of blockchain and deep learning (DL) drives the intelligence of the Internet of Things (IoT) with security guarantees. However, the soaring resource consumption resulting from blockchain mining and DL model training has overwhelmed the extremely resource-constrained IoT. In this article, we first build a blockchain and DL-empowered cloud–edge orchestrated framework for an extremely resource-constrained IoT environment. To solve the resource bottleneck of this framework, we then propose a Zero-knowledge Proof of Learning (ZPoL) consensus approach to channel the meaningless Proof of Work (PoW) mining energy waste to valuable DL model training, while protecting the DL model privacy. Besides, to encourage resource-constrained IoT devices to perform meaningful DL model mining in our ZPoL consensus, we design a model quality-aware incentive mechanism based on a two-stage Stackelberg game. Moreover, we conduct extensive simulations and experiments to evaluate our proposed ZPoL-based framework. The numerical simulation illustrates that our proposed incentive mechanism could motivate IoT devices to actively join in DL model mining. Compared with the existing blockchain and DL-enabled IoT system, experimental results demonstrate that our proposed ZPoL-based framework could significantly reduce the communication, computation, and storage cost, which is more applicable to a resource-constrained IoT environment. Heyi Zhang, Jun Wu 0001, Xi Lin 0003, Ali Kashif Bashir, Yasser D. Al-Otaibi |
IEEE Internet Things J. | 1 |
| 2023 | RAC-BERT: Character Radical Enhanced BERT for Ancient Chinese
Lifan Han, Xin Wang 0030, Meng Wang 0009, Zhao Li 0009, Heyi Zhang, Xiaowang Zhang |
NLPCC (2) | 5 |