Luyao Peng

dblp:271/7961 · DBLP profile ↗
← Back
9ranked-venue papers
4as first author
8since 2021 · last 2025
0009-0005-1277-4251ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 first-author · 3 since 2021Security and privacy · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Temporal-Directed Multi-Graph Attention Network for Robust Phishing Detection in Blockchain
abstract
The surge in blockchain transaction volume has corresponds with a rise in phishing incidents. Despite the widespread use of graph representation learning in fraud detection, these techniques often fail to fully exploit the directed multi-graph structure and temporal dynamics of blockchain transaction graphs. This oversight, coupled with the neglect of network tail nodes, impairs the accuracy of phishing detection and distorts graph integrity. This study introduces TDM-GAT, a graph neural network that integrates directionality, edge attributes, and temporal information through transaction flow serialization and functional time encoding. This approach significantly enhances the precision of phishing account identification in blockchain networks. Additionally, a PageRank-based biased sampling strategy is implemented to address the long-tailed distribution of graph nodes, ensuring balanced node participation during learning. Evaluations on three distinct datasets show that TDM-GAT outperforms with an AUC exceeding 95% and an accuracy close to 90%, demonstrating a clear advantage in phishing account detection.
Luyao Peng, Yinhao Li 0003, Shuqi He, Jun Song 0003
IJCNN1
2025 Enforcing Differential Privacy in Federated Learning via Long-Term Contribution Incentives
abstract
Privacy-preserving Federated Learning (FL) based on Differential Privacy (DP) protects clients’ data by adding DP noise to samples’ gradients and has emerged as a de facto standard for data privacy in FL. However, the accuracy of global models in DP-based FL may be reduced significantly when rogue clients occur who deviate from the preset DP-based FL approaches and selfishly inject excessive DP noise beyond expectations, thereby applying a smaller privacy budget in the DP mechanism to ensure a higher level of security. Existing DP-based FL fails to prevent such attacks as they are imperceptible. Under the DP-based FL system and random Gaussian noise, the local model parameters of the rogue clients and the honest clients have identical distributions. In particular, the rogue local models show a low performance, but directly filtering out lower-performance local models compromises the generalizability of global models, as local models trained on scarce data also behave with low performance in the early epoch. In this paper, we propose ReFL, a novel privacy-preserving FL system that enforces DP and avoids the accuracy reduction of global models caused by excessive DP noise of rogue clients. Based on the observation that rogue local models with excessive DP noise and honest local models trained on scarce data have different performance patterns in long-term training epochs, we propose a long-term contribution incentives scheme to evaluate clients’ reputations and identify rogue clients. Furthermore, we design a reputation-based aggregation to avoid the damage of rogue clients’ models on the global model accuracy, based on the incentive reputation. Extensive experiments demonstrate ReFL guarantees the global model accuracy performance 0.77% - 81.71% higher than existing DP-based FL methods in the presence of rogue clients.
Xiangyun Tang, Luyao Peng, Meng Shen 0001, Liehuang Zhu, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.2
2025 FinBack: Infiltrating Backdoors into Gradient Compressors on Federated Learning
abstract
Federated Learning (FL) has emerged as a promising distributed machine learning paradigm that allows clients to jointly train a global model without sharing their raw training datasets. However, FL is vulnerable to backdoor attacks, where malicious clients inject specific backdoors into their local models to manipulate the global model’s outputs. Recent studies widely applied gradient compression to construct efficient and robust FL systems against backdoor attacks, but we argue that gradient compression cannot be seen as a reliable defense strategy against backdoor attacks. In this work, we systematically evaluate the effectiveness of gradient compression against backdoor attacks. The experimental results indicate that, in addition to the effectiveness of SignSGD in preventing backdoor injection without significantly reducing the accuracy of the global model, most gradient compression methods do not provide effective defenses against backdoor attacks. Furthermore, we develop a novel adaptive backdoor attack, named FinBack, that can effectively infiltrate the gradient compressor SignSGD and implant backdoors in FL, by inducing small weight changes on specific neurons that do not conflict with benign clients while avoiding counteraction by benign clients and perturbation triggers thereby ensuring the effectiveness and persistence of backdoors. FinBack encompasses two attack modes: FinBack with the server collusion and FinBackR without the server collusion. Extensive experiments demonstrate the effectiveness and persistence of the proposed attacks, which increases the Attack Success Rate (ASR) from 10% to over 90% in SignSGD, even with 1% of malicious clients.
Xiangyun Tang, Luyao Peng, Meng Shen 0001, Tao Zhang 0063, Jiawen Kang 0001, Dusit Niyato
IEEE Trans. Inf. Forensics Secur.3
2024 Predicting Response Time of Questions Using Linear Mixed-effects Model
Luyao Peng
EDM1
2024 Comparing Clustering Methods in Group-level Test Collusion Detection
Luyao Peng
EDM1
2024 Covert and Persistent Backdoor Attacks in Federated Learning-Powerd Autonomous Driving
abstract
Federated learning (FL) is a distributed machine learning approach that helps autonomous vehicles train models together without a single organization holding all the data. FL ensures data confidentiality, but it also introduces vulnerabilities to backdoor attacks in autonomous driving systems. These attacks pose a specific threat to the accuracy of traffic sign recognition, potentially leading to the misclassification of signs and subsequent traffic accidents. To overcome these challenges, we propose a novel framework for backdoor attacks called Covert and Persistent Backdoor Attacks (CPBA), designed specifically for traffic sign recognition in autonomous driving systems. This framework utilizes a Generative Adversarial Network (GAN) to generate specific covert triggers for each sample. Minimizing the differences in feature vectors ensures that the backdoored images retain visual similarity to the original ones, making them nearly indistinguishable from human observers. Furthermore, CPBA addresses the dynamic nature of autonomous driving systems by selectively targeting model parameters that are infrequently updated and more stable, ensuring sustained effectiveness of the backdoor despite fluctuations in compromised vehicle participation and the influence of benign updates. Experimental evaluations demonstrate that CPBA maintains robustness against five distinct defense mechanisms on two publicly accessible traffic sign recognition datasets.
Luyao Peng, Jun Song 0003
HPCC3
2022 Online Item Response Theory (OIRT) - Tracking Student Abilities in Online Learning System
Luyao Peng, Chengzhi Wei
EDM1
2021 A Special Point and Transfer Component Analysis Based Dynamic Multi-objective Optimization Algorithm
Nanxi Li, Luyao Peng
EMO3
2020 A diversity introduction strategy based on change intensity for evolutionary dynamic multiobjective optimization
Ruochen Liu 0006, Luyao Peng, Jiangdi Liu, Jing Liu 0006
Soft Comput.2