VLDB 2026 Research / reviewers in the wild / expert
Chaohao Fu
dblp:274/7148
· DBLP profile ↗
4ranked-venue papers
3as first author
4since 2021 · last 2025
0009-0003-5814-156XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Privacy for Free: Spy Attack in Vertical Federated Learning by Both Active and Passive PartiesabstractVertical federated learning (VFL) is an emerging paradigm well-suitable for commercial collaborations among companies. These companies share a common user base but possess distinct features. VFL enables the training of a shared global model with features from different parties while maintaining the confidentiality of raw data. Despite its potential, the VFL mechanism still lacks certified integrity, posing a notable threat of potential commercial deception or privacy infringement. In this study, we introduce a novel form of attack in which the attacker can participate in VFL by free-riding on the collaborative process while surreptitiously extracting users’ private data. This attack, reminiscent of corporate espionage tactics, is called the “spy attack”. Specifically, spy attacks allow a dishonest party without sufficient data to hitch a ride by inferring the missing user features through the shared information from other participants. We design two types of spy attacks tailored for scenarios where the attacker either takes an active or passive role. Evaluations with four real-world datasets demonstrate the effectiveness of our attacks, not only fulfilling the stipulated collaboration through hitchhiking, but also successfully stealing users’ privacy. Even when the missing rate reaches 90%, the spy attack continues to yield a test accuracy that surpasses the model trained with non-missing data and achieves reconstruction results approaching the theoretically highest quality. Furthermore, we meticulously discuss and evaluate up to seven possible defense strategies. The findings underscore the necessity for designing more effective and efficient defense strategies to counteract spy attacks. Chaohao Fu, Na Ruan |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Client-Free Federated Unlearning via Training Reconstruction with Anchor Subspace CalibrationabstractFederated learning (FL) model usually needs to forget what it has learned from a certain client for various considerations, which gives birth to the federated unlearning (FU) technique. Due to the distributed nature of FL, removing a specific client’s contribution from the global model potentially requires the cooperation of all participants, making FU difficult to apply in real-world scenarios. This paper proposes a simple-yet-effective client-free FU algorithm that runs solely on the central server. The algorithm utilizes the cached historical updates of the initial training from clients to rebuild the training after excluding the target client. To circumvent the issue of adaptivity, which is the key challenge for training reconstruction, we leverage the low-dimensional structure of gradient space in deep networks. Specifically, we propose to project the historical gradients to a low-dimensional subspace, which is given by the top gradient eigenspace on a small public dataset. According to experiments on three canonical datasets, our method achieves efficient unlearning while also preserving a high-level model utility. Chaohao Fu, Weijia Jia 0001, Na Ruan |
ICASSP | 1 |
| 2024 | Preserving Individual User's Right to Be Forgotten in Enterprise-Level Federated Learning
Chaohao Fu, Na Ruan |
PRICAI (2) | 1 |
| 2023 | Steal from Collaboration: Spy Attack by a Dishonest Party in Vertical Federated Learning
Chaohao Fu, Na Ruan |
ACNS (1) | 2 |