VLDB 2026 Research / reviewers in the wild / expert
Zekai Chen 0010
dblp:275/8971-10
· DBLP profile ↗
7ranked-venue papers
4as first author
7since 2021 · last 2025
0009-0004-7895-8291ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | PrivGNN: High-Performance Secure Inference for Cryptographic Graph Neural Networks
Fuyi Wang, Zekai Chen 0010, Mingyuan Fan 0003, Jianying Zhou 0001, Lei Pan 0002, Leo Yu Zhang |
FC (2) | 2 |
| 2024 | CryptGraph: An Efficient Privacy-Enhancing Solution for Accurate Shortest Path Retrieval in Cloud EnvironmentsabstractWith the widespread adoption of cloud computing, it is a popular trend to migrate shortest path and distance (SPD) retrieval on large-scale graphs to cloud environments, harnessing their immense computational capabilities. To protect sensitive information, these graphs are usually encrypted before being outsourced to the cloud. A significant challenge is how to answer SPD retrieval in a secure, efficient, and accurate manner. However, recent works have yet to concurrently tackle all three aspects to meet this challenge. To address this challenge, we design, implement, and evaluate Crypt-Graph, the first scheme simultaneously allowing private, efficient, and accurate retrieval over encrypted graphs. CryptGraph leverages additive homomorphic encryptions to protect graphs and client information. A series of secure protocols are tailored based on the two-cloud (i.e., server) model. Supported by these protocols, Crypt-Graph converts SPD retrieval from the ciphertext domain to both the plaintext (for vertices) and secret-sharing (for weights) domains, achieving access pattern protection and remarkable efficiency close to plain retrieval. The security of CryptGraph is formally analyzed under the semi-honest adversary model. Extensive experiments are conducted on both synthetic and real-world graph datasets, demonstrating millisecond-level efficiency and 100% accuracy rates. Fuyi Wang, Zekai Chen 0010, Lei Pan 0002, Leo Yu Zhang, Jianying Zhou 0001 |
AsiaCCS | 2 |
| 2024 | FedCL: Detecting Backdoor Attacks in Federated Learning with Confidence LevelsabstractFederated Learning (FL) enables multiple clients to collaborate in training neural network models while retaining their private data locally. Despite its advantages, FL is vulnerable to backdoor attacks due to its distributed nature. Attackers introduce triggers into the global model, causing it to make specified predictions on inputs containing these triggers. Existing detection or clustering defense methods based on distance and similarity have significant limitations. Methods based on clipping and adding noise can only slightly mitigate the impact of backdoor attacks. To achieve a better defense, we introduce FedCL, a backdoor defense framework that accurately detects backdoor models by assessing the uncertainty of model predictions. Additionally, it employs dynamic clipping to limit model updates’ impact, successfully mitigating backdoor attacks without compromising the global model’s accuracy. The experiments indicate that FedCL moderately improves by 0.01%↑ ∼ 85.78%↑ than the state-of-the-art (SOTA) defense methods, especially in the CIFAR-10 task trained with more complex networks. Jinhe Long, Zekai Chen 0010, Fuyi Wang, Ximeng Liu |
ICME | 2 |
| 2024 | Lightweight Privacy-Preserving Cross-Cluster Federated Learning With Heterogeneous DataabstractFederated Learning (FL) eliminates data silos that hinder digital transformation while training a shared global model collaboratively. However, training a global model in the context of FL has been highly susceptible to heterogeneity and privacy concerns due to discrepancies in data distribution, which may lead to potential data leakage from uploading model updates. Despite intensive research on above-identical issues, existing approaches fail to balance robustness and privacy in FL. Furthermore, limiting model updates or iterative clustering tends to fall into local optimum problems in heterogeneous (Non-IID) scenarios. In this work, to address these deficiencies, we provide lightweight privacy-preserving cross-cluster federated learning (PrivCrFL) on Non-IID data, to trade off robustness and privacy in Non-IID settings. Our PrivCrFL exploits secure one-shot hierarchical clustering with cross-cluster shifting for optimizing sub-group convergences. Furthermore, we introduce intra-cluster learning and inter-cluster learning with separate aggregation for mutual learning between each group. We perform extensive experimental evaluations on three benchmark datasets and compare our results with state-of-the-art studies. The findings indicate that PrivCrFL offers a notable performance enhancement, with improvements ranging from$0.26\%~\uparrow $to$1.35\%~\uparrow $across different Non-IID settings. PrivCrFL also demonstrates a superior communication compression ratio in secure aggregation, outperforming current state-of-the-art works by 10.59%. Zekai Chen 0010, Shengxing Yu, Farong Chen, Fuyi Wang, Ximeng Liu, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Privacy-Enhancing and Robust Backdoor Defense for Federated Learning on Heterogeneous DataabstractFederated learning (FL) allows multiple clients to train deep learning models collaboratively while protecting sensitive local datasets. However, FL has been highly susceptible to security for federated backdoor attacks (FBA) through injecting triggers and privacy for potential data leakage from uploaded models in practical application scenarios. FBA defense strategies consider specific and limited attacker models, and a sufficient amount of noise injected can only mitigate rather than eliminate the attack. To address these deficiencies, we introduce a Robust Federated Backdoor Defense Scheme (RFBDS) and Privacy-preserving RFBDS (PrivRFBDS) to ensure the elimination of adversarial backdoors. Our RFBDS to overcome FBA consists of amplified magnitude sparsification, adaptive OPTICS clustering, and adaptive clipping. The experimental evaluation of RFBDS is conducted on three benchmark datasets and an extensive comparison is made with state-of-the-art studies. The results demonstrate the promising defense performance from RFBDS, moderately improved by 31.75% ~ 73.75% in clustering defense methods, and 0.03% ~ 56.90% for Non-IID to the utmost extent for the average FBA success rate over MNIST, FMNIST, and CIFAR10. Besides, our privacy-preserving shuffling in PrivRFBDS maintains is$7.83e^{-5}\,\,\sim \,\,0.42\times $that of state-of-the-art works. Zekai Chen 0010, Shengxing Yu, Mingyuan Fan 0003, Ximeng Liu, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | FedCML: Federated Clustering Mutual Learning with non-IID Data
Zekai Chen 0010, Fuyi Wang, Shengxing Yu, Ximeng Liu, Zhiwei Zheng |
Euro-Par | 1 |
| 2023 | Fedward: Flexible Federated Backdoor Defense Framework with Non-IID DataabstractFederated learning (FL) enables multiple clients to collaboratively train deep learning models while considering sensitive local datasets’ privacy. However, adversaries can manipulate datasets and upload models by injecting triggers for federated backdoor attacks (FBA). Existing defense strategies against FBA consider specific and limited attacker models, and a sufficient amount of noise to be injected only mitigates rather than eliminates FBA. To address these deficiencies, we introduce a Flexible Federated Backdoor Defense Framework (Fedward) to ensure the elimination of adversarial backdoors. We decompose FBA into various attacks, and design amplified magnitude sparsification (AmGrad) and adaptive OPTICS clustering (AutoOPTICS) to address each attack. Meanwhile, Fedward uses the adaptive clipping method by regarding the number of samples in the benign group as constraints on the boundary. This ensures that Fedward can maintain the performance for the Non-IID scenario. We conduct experimental evaluations over three benchmark datasets and thoroughly compare them to state-of-the-art studies. The results demonstrate the promising defense performance from Fedward, moderately improved by 33% ∼ 75% in clustering defense methods, and 96.98%, 90.74%, and 89.8% for Non-IID to the utmost extent for the average FBA success rate over MNIST, FMNIST, and CIFAR10, respectively. Zekai Chen 0010, Fuyi Wang, Zhiwei Zheng, Ximeng Liu |
ICME | 1 |