VLDB 2026 Research / reviewers in the wild / expert
Tianhao Wang 0013
dblp:274/2144
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2023
0000-0002-9017-7947ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | LAVA: Data Valuation without Pre-Specified Learning Algorithms
Hoang Anh Just, Feiyang Kang, Tianhao Wang 0013, Yi Zeng 0005, Myeongseob Ko, Ming Jin 0002, Ruoxi Jia 0001 |
ICLR | 3 |
| 2021 | Improving Robustness to Model Inversion Attacks via Mutual Information RegularizationabstractThis paper studies defense mechanisms against model inversion (MI) attacks -- a type of privacy attacks aimed at inferring information about the training data distribution given the access to a target machine learning model. Existing defense mechanisms rely on model-specific heuristics or noise injection. While being able to mitigate attacks, existing methods significantly hinder model performance. There remains a question of how to design a defense mechanism that is applicable to a variety of models and achieves better utility-privacy tradeoff. In this paper, we propose the Mutual Information Regularization based Defense (MID) against MI attacks. The key idea is to limit the information about the model input contained in the prediction, thereby limiting the ability of an adversary to infer the private training attributes from the model prediction. Our defense principle is model-agnostic and we present tractable approximations to the regularizer for linear regression, decision trees, and neural networks, which have been successfully attacked by prior work if not attached with any defenses. We present a formal study of MI attacks by devising a rigorous game-based definition and quantifying the associated information leakage. Our theoretical analysis sheds light on the inefficacy of DP in defending against MI attacks, which has been empirically observed in several prior works. Our experiments demonstrate that MID leads to state-of-the-art performance for a variety of MI attacks, target models and datasets. Tianhao Wang 0013, Ruoxi Jia 0001 |
AAAI | 1 |
| 2021 | Concurrent Composition of Differential Privacy
Salil P. Vadhan, Tianhao Wang 0013 |
TCC (2) | 2 |
| 2021 | DPlis: Boosting Utility of Differentially Private Deep Learning via Randomized SmoothingabstractAbstract Deep learning techniques have achieved remarkable performance in wide-ranging tasks. However, when trained on privacy-sensitive datasets, the model parameters may expose private information in training data. Prior attempts for differentially private training, although offering rigorous privacy guarantees, lead to much lower model performance than the non-private ones. Besides, different runs of the same training algorithm produce models with large performance variance. To address these issues, we propose DPlis– Differentially Private Learning wIth Smoothing. The core idea of DPlis is to construct a smooth loss function that favors noise-resilient models lying in large flat regions of the loss landscape. We provide theoretical justification for the utility improvements of DPlis. Extensive experiments also demonstrate that DPlis can effectively boost model quality and training stability under a given privacy budget. Wenxiao Wang 0002, Tianhao Wang 0013, Lun Wang 0001, Nanqing Luo, Pan Zhou 0001, Dawn Song, Ruoxi Jia 0001 |
Proc. Priv. Enhancing Technol. | 2 |