VLDB 2026 Research / reviewers in the wild / expert
Lulu Wang 0015
dblp:28/1751-15
· DBLP profile ↗
8ranked-venue papers
2as first author
8since 2021 · last 2026
0000-0001-9132-899XORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Verifiable Private Federated Learning Achieving Low-Communication With CUR DecompositionabstractFederated learning (FL) allows multiple clients to collaboratively train a shared machine learning model without sharing local data. Despite its advantages, FL faces serious security and privacy threats. Many existing solutions rely on cryptographic methods to protect data and ensure verifiability, but these approaches often enlarge the model or impose high communication costs. They also overlook FL's limited uplink and downlink bandwidth and rarely account for practical issues such as client dropouts. To address these gaps, we propose LC-VPFL, a federated learning framework that ensures data privacy, verifiability, low communication overhead, and dropout tolerance. Our approach leverages secret sharing and masking to protect data privacy, while homomorphic hashing detects malicious server behavior. To minimize communication costs, we apply quantization and CUR matrix decomposition, optimizing both uplink and downlink transmissions. We formally prove the security of LC-VPFL and provide a theoretical analysis demonstrating that, for a corruption threshold of$t$, the communication complexity of partial clients remains$O(t)$and tolerates arbitrary client dropouts. Experimental results show that LC-VPFL reduces uplink communication costs by over 50% in most scenarios and downlink communication costs to less than 12.5% of those in FedAvg, with an accuracy loss within 3%. Changti Wu, Lulu Wang 0015, Lei Zhang 0009 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Dual-Server Privacy-Preserving Collaborative Deep Learning: A Round-Efficient, Dynamic and Lossless ApproachabstractTo address limitations in existing privacy-preserving collaborative deep learning (CDL) schemes, we propose a dual-server privacy-preserving CDL scheme based on homomorphic encryption and amasking technique. Specifically, in our scheme a random seed is used to initialize a pseudorandom generator that produces multiple pseudorandom numbers. These pseudorandom numbers, along with a random noise, are utilized to generate masks that are added to all parameters of a participant's locally trained model. By using homomorphic encryption, the random noise can be encrypted and eventually used to remove the masks with low message expansion. This also ensures that the global model is lossless in accuracy. Furthermore, if participants join or leave the system, only the time required to complete both model update aggregation and encrypted masks aggregation is affected. We demonstrate that our scheme is round-efficient, dynamic and lossless. We also show that it is secure against inference attacks and can resist collusion attacks of up to$t-2$participants and one of the two servers, where$t$is a security parameter indicating the minimum number of participants that participate in an aggregation round. Lulu Wang 0015, Lei Zhang 0009, Kim-Kwang Raymond Choo, Josep Domingo-Ferrer, Mauro Conti |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | PriVeriFL: Privacy-Preserving and Aggregation-Verifiable Federated LearningabstractFederated learning provides a collaborative way to build machine learning models without sharing private data. However, attackers might infer private information from model updates submitted by participants, and the aggregator might maliciously forge the final aggregation results. Federated learning still faces data privacy and aggregation integrity challenges. In this paper, we combine inference attacks and information theory to analyze the sensitivity of different bits of model parameters. We conclude that not all bits of model parameters will leak privacy. This realization inspires us to propose a novel low-expansion homomorphic aggregation scheme based on Paillier homomorphic encryption (PHE) for safeguarding participants’ data privacy. Building upon this, we develop PriVeriFL-A, a privacy-preserving and aggregation-verifiable federated learning scheme that combines homomorphic hash function and signature. To prevent collusion attacks between the aggregator and malicious participants, we further improve our PHE-based scheme into a threshold PHE-based one, named PriVeriFL-B. Compared with the privacy-preserving federated learning scheme based on classic PHE, PriVeriFL-A reduces the communication overhead to 1.65%, and the encryption/decryption computation overhead to 0.88%. Both PriVeriFL-A and PriVeriFL-B can effectively verify the integrity of the global model, while maintaining an almost negligible communication overhead for integrity verification and protecting the privacy of participants’ data. Lulu Wang 0015, Mirko Polato, Alessandro Brighente, Mauro Conti, Lei Zhang 0009, Lin Xu 0010 |
IEEE Trans. Serv. Comput. | 1 |
| 2024 | Dual-Server-Based Lightweight Privacy-Preserving Federated LearningabstractFederated learning (FL) allows multiple users to collaboratively train global machine learning models by keeping their data sets local. However, the existing privacy-preserving FL schemes suffer from several limitations, e.g., loss of accuracy, high communication/computation cost, failure to support dynamic users, and insecurity against collusion attacks. To solve these limitations, we propose a lightweight privacy-preserving FL scheme based on a dual-server architecture. Our scheme involves only lightweight cryptographic operations, i.e., hash and symmetric encryption operations, and it has low communication overhead. Thus, it is computationally lightweight and round-efficient. Further, it allows users to join/quit an FL task and it is accuracy-lossless. We formally prove that our scheme remains secure even in case of collusion attacks. In particular, if an attacker colludes with one of the servers and all the users who participate in an FL task except two, the privacy of user gradients stays unviolated. The reported experimental results demonstrate that our scheme incurs only a marginal increase in total communication overhead compared to the FL scheme without any privacy protection. In terms of computation overhead, the cost per user remains stable as the number of users grows, while the cost for the server is comparable to that of the FL scheme without any privacy protection. Liangyu Zhong, Lulu Wang 0015, Lei Zhang 0009, Josep Domingo-Ferrer, Lin Xu 0010, Changti Wu |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2023 | Identity-Based Key Management Scheme for Secure Discussion Group Establishment in DOSNsabstractDistributed online social network (DOSN) solves the challenges of single-point failure and user data privacy faced by traditional online social network (OSN). Online discussion group, allowing a user to facilitate the communications with other users, is one of the most important components of (D)OSN. Key management is the key technology to ensure the secure establishment of discussion groups in DOSNs. However, the existing key management schemes for secure discussion group establishment in DOSNs cannot meet the requirements of sender non-restriction, receiver controllability, round optimal, certificate freeness simultaneously. In this paper, we propose a novel key management scheme for secure discussion group establishment in DOSNs. In our scheme, any user could use our key management scheme to initialize a discussion group with a piece of discussion group information. Users who are interested in the group topic contained in the discussion group information can join and leave the discussion group at any time once the discussion group is initialized with one-round communication. Any user/sender can find the users that he/she wants to communicate with by looking up the discussion group information of a discussion group and then send encrypted messages to some or all of the users in the discussion group. Therefore, our scheme achieves sender non-restriction, receiver controllability, round optimal, certificate freeness simultaneously. Security analysis also shows that our scheme achieves confidentiality, authentication, full collusion resistance, known-key security and perfect forward security. Lei Zhang 0009, Wendie Han, Lulu Wang 0015 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Privacy-Preserving and Reliable Decentralized Federated LearningabstractConventional federated learning (FL) approaches generally rely on a centralized server, and there has been a trend of designing asynchronous FL approaches for distributed applications partly to mitigate limitations associated with conventional (synchronous) FL approaches (e.g., single point of failure / attack). In this paper, we first introduce two new tools, namely: a quality-based aggregation method and an extended dynamic contribution broadcast encryption (DConBE). Building on these two new tools and local differential privacy, we then propose a privacy-preserving and reliable decentralized FL scheme, designed to support batch joining/leaving of clients while incurring minimal delay and achieving high model accuracy. In other words, our scheme seeks to ensure an optimal trade-off between model accuracy and data privacy, which is also demonstrated in our simulation results. For example, the results show that our aggregation method can effectively avoid low-quality updates in the sense that the scheme guarantees high model accuracy even in the presence of bad clients who may submit low-quality updates. In addition, our scheme incurs a lower loss and the extended DConBE only slightly affects the efficiency of our scheme. With the extended dynamic contribution broadcast encryption, our scheme can efficiently support batch joining/leaving of clients. Lei Zhang 0009, Lulu Wang 0015, Kim-Kwang Raymond Choo |
IEEE Trans. Serv. Comput. | 3 |
| 2022 | A Secure and Receiver-Unrestricted Group Key Management Scheme for Mobile Ad-hoc NetworksabstractMobile Ad-hoc Networks (MANETs) have attracted lots of concerns with its widespread use. In MANETs, wireless nodes usually self-organize into groups to complete collaborative tasks and communicate with one another via public channels which are vulnerable to attacks. Group key management is generally employed to guarantee secure group communication in MANETs. However, most existing group key management schemes for MANETs still suffer from some issues, e.g., receiver restriction, relying on a trusted dealer and heavy certificates overheads. To address these issues, we propose a group key management scheme for MANETs based on an identity-based authenticated dynamic contributory broadcast encryption (IBADConBE) protocol which builds on an earlier work. Our scheme abandons the certificate management and does not need a trusted dealer to distribute a secret key to each node. A set of wireless nodes are allowed to negotiate the secret keys in one round while forming a group. Besides, our scheme is receiver-unrestricted which means any sender can flexibly opt for any favorable nodes of a group as the receivers. Further, our scheme satisfies the authentication, confidentiality of messages, known-security, forward security and backward security concurrently. Performance evaluation shows our scheme is efficient. Wendie Han, Lei Zhang 0009, Lulu Wang 0015 |
WCNC | 4 |
| 2021 | Privacy-Preserving and Reliable Federated Learning
Lei Zhang 0009, Lulu Wang 0015 |
ICA3PP (3) | 3 |