Xianglong Zhang

dblp:29/9985 · DBLP profile ↗
← Back
17ranked-venue papers
8as first author
15since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 2 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Computer networks · 3 · 3 first-author · 2 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 FedRFF: Enhanced Federated Random Fourier Feature Framework for IoT Anomaly Detection
Chaoqun Li 0002, Keyuan Qiu, Jinyao Liu, Xianglong Zhang, Huanle Zhang, Si Wu 0003, Feng Li 0002, Pengfei Hu 0001
ICDCS5
2026 Global-Guided Attention Multiple Instance Learning with Spatial-Spectral Priors for fNIRS-Based Pediatric Autism Identification
Xianglong Zhang, Yuehui Chen, Qingfang Meng, Kaiyun Li, Yaou Zhao, Ruizhi Han
ICIC (30)1
2026 Enabling Scalable Resizing in Tree-Based ORAM: A Dynamic Transformation Framework
Wei Wang 0088, Xianglong Zhang, Xingyu Guo, Peng Xu 0003, Laurence T. Yang
IEEE Trans. Computers2
2025 InverCRS: Generative Audio Inversion Attack in Collaborative Recognition Systems
abstract
Audio recognition systems have become integral to various applications, including speech-to-text, virtual assistants, and security monitoring, where efficiency and privacy are key concerns. The collaborative recognition system (CRS) partitions and deploys the neural network (NN) across multiple edge devices for cooperative recognition without sharing raw audio data. This distributed approach significantly alleviates the computational burden on the client and ensures data privacy. These advantages make CRS increasingly prevalent in audio recognition applications to improve security, efficiency, and provide timely feedback. However, sharing information during collaboration still poses the risk of exposing original data. To the best of our knowledge, this paper introduces InverCRS, the first inversion attack targeting CRS-empowered audio recognition systems. InverCRS is a generative attack in which the attacker trains a local generative model to take intermediate results as input and output the original audio. Once the generative model is trained, it can perform audio inversion using new intermediate results without the need for further optimization. Furthermore, InverCRS utilizes heuristic algorithms to approximate gradients, making it applicable to both white-box and black-box scenarios. We conduct comprehensive experiments to evaluate the feasibility and efficiency of InverCRS across two real-world audio datasets. The results demonstrate that InverCRS can effectively reconstruct the original audio from various split points within the CRS. Additionally, we investigate two potential defense strategies and provide experimental evaluations of their effectiveness in mitigating this attack.
Xianglong Zhang, Haoming Luo, Mingda Han, Qihao Dong, Yanni Yang 0003, Qianli Li, Pengfei Hu 0001
ICDCS1
2025 The existence of a {K1,2,K1,3,K5}-factor based on the size or the Aα-spectral radius of graphs
Xianglong Zhang, Lihua You
Discret. Appl. Math.1
2025 VideoMamba++: Integrating state space model with dual attention for enhanced video understanding
Wang Tian, Qiqi Zhu, Xianglong Zhang
Image Vis. Comput.4
2025 Exploiting Defenses against GAN-Based Feature Inference Attacks in Federated Learning
abstract
Federated Learning (FL) is a decentralized model training framework that aims to merge isolated data islands while maintaining data privacy. However, recent studies have revealed that Generative Adversarial Network (GAN)-based attacks can be employed in FL to learn the distribution of private datasets and reconstruct recognizable images. In this article, we exploit defenses against GAN-based attacks in FL and propose a framework, Anti-GAN, to prevent attackers from learning the real distribution of the victim’s data. The core idea of Anti-GAN is to manipulate the visual features of private training images to make them indistinguishable to human eyes even restored by attackers. Specifically, Anti-GAN projects the private dataset onto a GAN’s generator and combines the generated fake images with the actual images to create the training dataset, which is then used for federated model training. The experimental results demonstrate that Anti-GAN is effective in preventing attackers from learning the distribution of private images while causing minimal harm to the accuracy of the federated model.
Xinjian Luo, Xianglong Zhang
ACM Trans. Knowl. Discov. Data2
2025 Model Poisoning Attack Against Neural Network Interpreters in IoT Devices
abstract
Neural network models have become integral to Internet of Things (IoT) systems, with applications spanning from industrial automation to critical infrastructure management. Despite their prevalence, the deployment of these models within IoT systems introduces distinctive security vulnerabilities. In particular, adversaries may execute model poisoning attacks, which aim to alter the decision-making processes of embedded models, leading to erroneous outcomes. Existing model poisoning attacks necessitate access to extensive auxiliary datasets, such as the training dataset itself or one with same distribution. These requirements often render such attacks impractical in IoT contexts, given the constrained storage and computational resources of IoT devices. This paper proposes the first model poisoning attack against interpreters without auxiliary datasets to manipulate the model’s behavior. We evaluate the attack on three real-world datasets, and results indicate that this attack can successfully coerce the targeted interpreters to produce outcomes aligned with an adversary’s intentions, while maintaining nearly indistinguishable performance from the original model, thereby ensuring its stealthiness. Furthermore, beyond directly affected interpreters, our experiments reveal that four additional interpreters coupled to the poisoned model are indirectly influenced, underscoring the attack’s transferability.
Xianglong Zhang, Feng Li 0002, Huanle Zhang, Zhijian Huang 0002, Lisheng Fan, Xiuzhen Cheng, Pengfei Hu 0001
IEEE Trans. Mob. Comput.1
2025 Membership Inference Attacks Against Incremental Learning in IoT Devices
abstract
Internet of Things (IoT) devices are frequently deployed in highly dynamic environments and need to continuously learn new classes from data streams. Incremental Learning (IL) has gained popularity in IoT as it enables devices to learn new classes efficiently without retraining model entirely. IL involves fine-tuning the model using two sources of data: a small amount of representative samples from the original training dataset and samples from the new classes. However, both data sources are vulnerable to Membership Inference Attack (MIA). Fortunately, the existing MIAs result in poor performance against IL, because they ignore features such as the similarity between old and new models at the old classification layer. This paper presents the first MIA against IL, capable of determining not only whether a sample was used for training/fine-tuning but also distinguishing whether it belongs to the representative dataset or the new classes (unique in IL). Extensive experiments validate the effectiveness of our attack across four real-world datasets. Our attack achieves an average attack success rate of 74.03% in the white-box setting (model structure and parameters are known) and 70.08% in the black-box setting. Importantly, our attack is not sensitive to the IL hyper-parameters (e.g., distillation temperature), confirming its accurate, robust, and practical.
Xianglong Zhang, Huanle Zhang, Yanni Yang 0003, Feng Li 0002, Lisheng Fan, Zhijian Huang 0002, Xiuzhen Cheng, Pengfei Hu 0001
IEEE Trans. Mob. Comput.1
2024 Query Recovery from Easy to Hard: Jigsaw Attack against SSE
Hao Nie, Wei Wang 0088, Peng Xu 0003, Xianglong Zhang, Laurence T. Yang, Kaitai Liang
USENIX Security Symposium4
2023 High Recovery with Fewer Injections: Practical Binary Volumetric Injection Attacks against Dynamic Searchable Encryption
Xianglong Zhang, Wei Wang 0088, Peng Xu 0003, Laurence T. Yang, Kaitai Liang
USENIX Security Symposium1
2023 Ginver: Generative Model Inversion Attacks Against Collaborative Inference
abstract
Deep Learning (DL) has been widely adopted in almost all domains, from threat recognition to medical diagnosis. Albeit its supreme model accuracy, DL imposes a heavy burden on devices as it incurs overwhelming system overhead to execute DL models, especially on Internet-of-Things (IoT) and edge devices. Collaborative inference is a promising approach to supporting DL models, by which the data owner (the victim) runs the first layers of the model on her local device and then a cloud provider (the adversary) runs the remaining layers of the model. Compared to offloading the entire model to the cloud, the collaborative inference approach is more data privacy-preserving as the owner’s model input is not exposed to outsiders. However, we show in this paper that the adversary can restore the victim’s model input by exploiting the output of the victim’s local model. Our attack is dubbed Ginver 1: Generative model inversion attacks against collaborative inference. Once trained, Ginver can infer the victim’s unseen model inputs without remaking the inversion attack model and thus has the generative capability. We extensively evaluate Ginver under different settings (e.g., white-box and black-box of the victim’s local model) and applications (e.g., CIFAR10 and FaceScrub datasets). The experimental results show that Ginver recovers high-quality images from the victims.
Yupeng Yin, Xianglong Zhang, Huanle Zhang, Feng Li 0002, Yue Yu 0001, Xiuzhen Cheng, Pengfei Hu 0001
WWW2
2023 A robust adversarial attack against speech recognition with UAP
abstract
Speech recognition (SR) systems based on deep neural networks are increasingly widespread in smart devices. However, they are vulnerable to human-imperceptible adversarial attacks, which cause the SR to generate incorrect or targeted adversarial commands. Meanwhile, audio adversarial attacks are particularly susceptible to various factors, e.g., ambient noise, after applying them to a real-world attack. To circumvent this issue, we develop a universal adversarial perturbation (UAP) generation method to construct robust real-world UAP by integrating ambient noise into the generation process. The proposed UAP can work well in the case of input-agnostic and independent sources. We validate the effectiveness of our method on two different SRs in different real-world scenarios and parameters, the results demonstrate that our method yields state-of-the-art performance, i.e. given any audio waveform, the word error rate can be up to 80%. Extensive experiments investigate the impact of different parameters (e.g, signal-to-noise ratio, distance, and attack angle) on the attack success rate.
Ziheng Qin, Xianglong Zhang, Shujun Li 0004
High Confid. Comput.2
2023 Model Poisoning Attack on Neural Network Without Reference Data
abstract
Due to the substantial computational cost of neural network training, adopting third-party models has become increasingly popular. However, recent works demonstrate that third-party models can be poisoned. Nonetheless, most model poisoning attacks require reference data, e.g., training dataset or data belonging to the target label, making them difficult to launch in practice. In this paper, we propose a reference data independent model poisoning attack that can (1) directly search for sensitive features with respect to the target label, (2) quantify the positive and negative effects of the model parameters on sensitive features, and (3) accomplish the training of poisoned model by our parameter selective update strategy. The extensive evaluation on datasets with a few classes and numerous classes show that the attack is (I) effective: the trigger input can be labeled as a deliberate class by the poisoned model with high probability; (II) covert: the performance of the poisoned model is almost indistinguishable from the intact model on non-trigger inputs; and (III) straightforward: an adversary only needs a little background knowledge to launch the attack. Overall, the evaluation results show that our attack achieves 95%, 100%, 81%, 96%, and 96% success rates on Cifar10, Cifar100, ISIC2018, FaceScrub, and ImageNet datasets, respectively.
Xianglong Zhang, Huanle Zhang, Hong Li 0004, Dongxiao Yu, Xiuzhen Cheng, Pengfei Hu 0001
IEEE Trans. Computers1
2022 VFL: A Verifiable Federated Learning With Privacy-Preserving for Big Data in Industrial IoT
abstract
Due to the strong analytical ability of big data, deep learning has been widely applied to model on the collected data in industrial Internet of Things (IoT). However, for privacy issues, traditional data-gathering centralized learning is not applicable to industrial scenarios sensitive to training sets, such as face recognition and medical systems. Recently, federated learning has received widespread attention, since it trains a model by only sharing gradients without accessing training sets. But existing research works reveal that the shared gradient still retains the sensitive information of the training set. Even worse, a malicious aggregation server may return forged aggregated gradients. In this article, we propose the VFL, a verifiable federated learning with privacy-preserving for big data in industrial IoT. Specifically, we use Lagrange interpolation to elaborately set interpolation points for verifying the correctness of the aggregated gradients. Compared with existing schemes, the verification overhead of VFL remains constant regardless of the number of participants. Moreover, we employ the blinding technology to protect the privacy of the privacy gradients. If no more than$\boldsymbol{n}$-2 of$\boldsymbol{n}$participants collude with the aggregation server, VFL could guarantee the encrypted gradients of other participants not being inverted. Experimental evaluations corroborate the practical performance of the presented VFL with high accuracy and efficiency.
Anmin Fu, Xianglong Zhang, Naixue Xiong, Yansong Gao 0001, Huaqun Wang
IEEE Trans. Ind. Informatics2
2020 A Privacy-Preserving and Verifiable Federated Learning Scheme
abstract
Due to the complexity of the data environment, many organizations prefer to train deep learning models together by sharing training sets. However, this process is always accompanied by the restriction of distributed storage and privacy. Federated learning addresses this challenge by only sharing gradients with the server without revealing training sets. Unfortunately, existing research has shown that the server could extract information of the training sets from shared gradients. Besides, the server may falsify the calculated result to affect the accuracy of the trained model. To solve the above problems, we propose a privacy-preserving and verifiable federated learning scheme. Our scheme focuses on processing shared gradients by combining the Chinese Remainder Theorem and the Paillier homomorphic encryption, which can realize privacy-preserving federated learning with low computation and communication costs. In addition, we introduce the bilinear aggregate signature technology into federated learning, which effectively verifies the correctness of aggregated gradient. Moreover, the experiment shows that even with the added verification function, our scheme still has high accuracy and efficiency.
Xianglong Zhang, Anmin Fu, Huaqun Wang, Chunyi Zhou 0001, Zhenzhu Chen
ICC1
2011 Haplo2Ped: a tool using haplotypes as markers for linkage analysis
abstract
BACKGROUND: Generally, SNPs are abundant in the genome; however, they display low power in linkage analysis because of their limited heterozygosity. Haplotype markers, on the other hand, which are composed of many SNPs, greatly increase heterozygosity and have superiority in linkage statistics. RESULTS: Here we developed Haplo2Ped to automatically transform SNP data into haplotype markers and then to compute the logarithm (base 10) of odds (LOD) scores of regional haplotypes that are homozygous within the disease co-segregation haploid group. The results are reported as a hypertext file and a 3D figure to help users to obtain the candidate linkage regions. The hypertext file contains parameters of the disease linked regions, candidate genes, and their links to public databases. The 3D figure clearly displays the linkage signals in each chromosome. We tested Haplo2Ped in a simulated SNP dataset and also applied it to data from a real study. It successfully and accurately located the causative genomic regions. Comparison of Haplo2Ped with other existing software for linkage analysis further indicated the high effectiveness of this software. CONCLUSIONS: Haplo2Ped uses haplotype fragments as mapping markers in whole genome linkage analysis. The advantages of Haplo2Ped over other existing software include straightforward output files, increased accuracy and superior ability to deal with pedigrees showing incomplete penetrance. Haplo2Ped is freely available at: http://bighapmap.big.ac.cn/software.html.
Xianglong Zhang, Chaohua Li, Changqing Zeng
BMC Bioinform.2