VLDB 2026 Research / reviewers in the wild / expert
Jiqiang Gao
dblp:284/8700
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2023
0000-0002-7850-3869ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Secure Aggregation is Insecure: Category Inference Attack on Federated LearningabstractFederated learning allows a large number of resource-constrained clients to train a globally-shared model together without sharing local data. These clients usually have only a few classes (categories) of data for training, where the data distribution is non-iid (not independent identically distributed). In this article, we put forward the concept ofcategory privacyfor the first time to indicatewhich classes of data a client has, which is an important but ignored privacy goal in the federated learning with non-iid data. Although secure aggregation protocols are designed for federated learning to protect the input privacy of clients, we perform the first systematic study oncategory inference attackand demonstrate that these protocols cannot fully protect category privacy. We design a differential selection strategy and two de-noising approaches to achieve the attack goal successfully. In our evaluation, we apply the attack to non-iid federated learning settings with various datasets. On MNIST, CIFAR-10, AG_news, and DBPedia dataset, our attack achieves$>90\%$accuracy measured in F1-score in most cases. We further consider a possible detection method and propose two strategies to make the attack more inconspicuous. Jiqiang Gao, Boyu Hou, Xiaojie Guo 0004, Zheli Liu, Ying Zhang 0015, Kai Chen 0012, Jin Li 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Secure Partial Aggregation: Making Federated Learning More Robust for Industry 4.0 ApplicationsabstractBig data, due to its promotion for industrial intelligence, has become the cornerstone of the Industry 4.0 era.Federated learning, proposed by Google, can effectively integrate data from different devices and different domains to train models under the premise of privacy preservation. Unfortunately, this new training paradigm faces security risks both on the client side and server side. This article proposes a new federated learning scheme to defend from client-side malicious uploads (e.g., backdoor attacks). In addition, we use cryptography techniques to prevent server-side privacy attacks (e.g., membership inference). Thesecure partial aggregationprotocol we designed improves the privacy and robustness of federated learning. The experiments show that models can achieve high accuracy of over 90% with a proper upload proportion, while the accuracy of the backdoor attack decreased from 99.5% to 0% with the best result. Meanwhile, we prove that our protocol can disable privacy attacks. Jiqiang Gao, Baolei Zhang, Xiaojie Guo 0004, Thar Baker, Min Li 0045, Zheli Liu |
IEEE Trans. Ind. Informatics | 1 |
| 2022 | Mitigating the Backdoor Attack by Federated Filters for Industrial IoT ApplicationsabstractThe federated learning provides an effective solution to train collaborative models over a large scale of participated Industrial Internet of Things (IIoT) applications with the help of a global server, building an intelligent life. However, the federated learning is vulnerable to the backdoor attack from strong malicious participants. The backdoor attack is inconspicuous and may result in devastating consequences. To resist the attack on IIoT applications, we propose the federated backdoor filter defense that can identify backdoor inputs and restore the data to availability by theblur-label-flippingstrategy. We build multiple filters with eXplainable AI models on the server and send them to clients randomly, preventing advanced attackers from evading the defense. Our backdoor filters show significant backdoor recognition with the accuracy up to 99%. After the implementation of the blur-label-flipping strategy, victim's local model on suspicious backdoor samples can achieve the accuracy up to 88%. Boyu Hou, Jiqiang Gao, Xiaojie Guo 0004, Thar Baker, Ying Zhang 0015, Yanlong Wen, Zheli Liu |
IEEE Trans. Ind. Informatics | 2 |
| 2021 | VeriFL: Communication-Efficient and Fast Verifiable Aggregation for Federated LearningabstractFederated learning (FL) enables a large number of clients to collaboratively train a global model through sharing their gradients in each synchronized epoch of local training. However, a centralized server used to aggregate these gradients can be compromised and forge the result in order to violate privacy or launch other attacks, which incurs the need to verify the integrity of aggregation. In this work, we explore how to design communication-efficient and fast verifiable aggregation in FL. We propose VeriFL, a verifiable aggregation protocol, with O(N) (dimension-independent) communication and O(N+ d) computation for verification in each epoch, where N is the number of clients and d is the dimension of gradient vectors. Since d can be large in some real-world FL applications (e.g., 100K), our dimension-independent communication is especially desirable for clients with limited bandwidth and high-dimensional gradients. In addition, the proposed protocol can be used in the FL setting where secure aggregation is needed or there is a subset of clients dropping out of protocol execution. Experimental results indicate that our protocol is efficient in these settings. Xiaojie Guo 0004, Zheli Liu, Jin Li 0002, Jiqiang Gao, Boyu Hou, Changyu Dong, Thar Baker |
IEEE Trans. Inf. Forensics Secur. | 4 |