Qihao Dong

dblp:299/9054 · DBLP profile ↗
← Back
5ranked-venue papers
4as first author
5since 2021 · last 2026
0000-0002-4215-971XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 FORCE: Byzantine-Resilient Decentralized Federated Learning via Game-Theoretic Contribution Aggregation
abstract
Federated Learning (FL) enables collaborative machine learning training while preserving data privacy. However, reliance on a central server of the typical FL confronts the risk of single server failure. Decentralized Federated Learning (DFL) emerges as a promising distributed framework, allowing clients to directly share models without server intervention, thereby addressing this challenge. Nevertheless, due to its decentralized nature, DFL is highly susceptible to Byzantine attacks orchestrated by malicious clients. Existing Byzantine-resilient DFL algorithms, though few, remain vulnerable to adaptive attacks due to their heavy reliance ongradient checksof local models, which can be adaptively manipulated by intelligent adversaries. To tackle this issue, we propose a DFL aggregation scheme called FORCE (Byzantine-Resilient Decentralized Federated Learning via Game-Theoretic Contribution Aggregation). Drawing inspiration from the Shapley value in game theory, FORCE shifts from gradient-checking approaches to employ a universal metric, the loss of the local model—independent of specific gradients, to identify potentially malicious clients. Moreover, to reduce the computational overhead of FORCE as the number of neighboring clients scales up, we propose a computationlightweight variant, FORCE−, which is optimized through approximating Shapley value computation. This variant becomes more scalable for resource-restricted DFL clients that are also aggregators. Experimental results on three diverse datasets (two image modalities and one textual modality datasets) under three existing attacks demonstrate that FORCE outperforms existing state-of-the-art Byzantine-resilient DFL aggregation methods, effectively defending against Byzantine attacks.
Qihao Dong, Zhiyang Dai, Yansong Gao 0001, Yifeng Zheng 0001, Anmin Fu, Willy Susilo
IEEE Trans. Inf. Forensics Secur.1
2025 InverCRS: Generative Audio Inversion Attack in Collaborative Recognition Systems
abstract
Audio recognition systems have become integral to various applications, including speech-to-text, virtual assistants, and security monitoring, where efficiency and privacy are key concerns. The collaborative recognition system (CRS) partitions and deploys the neural network (NN) across multiple edge devices for cooperative recognition without sharing raw audio data. This distributed approach significantly alleviates the computational burden on the client and ensures data privacy. These advantages make CRS increasingly prevalent in audio recognition applications to improve security, efficiency, and provide timely feedback. However, sharing information during collaboration still poses the risk of exposing original data. To the best of our knowledge, this paper introduces InverCRS, the first inversion attack targeting CRS-empowered audio recognition systems. InverCRS is a generative attack in which the attacker trains a local generative model to take intermediate results as input and output the original audio. Once the generative model is trained, it can perform audio inversion using new intermediate results without the need for further optimization. Furthermore, InverCRS utilizes heuristic algorithms to approximate gradients, making it applicable to both white-box and black-box scenarios. We conduct comprehensive experiments to evaluate the feasibility and efficiency of InverCRS across two real-world audio datasets. The results demonstrate that InverCRS can effectively reconstruct the original audio from various split points within the CRS. Additionally, we investigate two potential defense strategies and provide experimental evaluations of their effectiveness in mitigating this attack.
Xianglong Zhang, Haoming Luo, Mingda Han, Qihao Dong, Yanni Yang 0003, Qianli Li, Pengfei Hu 0001
ICDCS4
2025 DRIFT: DCT-based robust and intelligent federated learning with trusted privacy
Qihao Dong, Mang Su, Yansong Gao 0001, Anmin Fu
Neurocomputing1
2024 CareFL: Contribution Guided Byzantine-Robust Federated Learning
abstract
Byzantine-robust federated learning (FL) endeavors to empower service providers in acquiring a precise global model, even in the presence of potentially malicious FL clients. While considerable strides have been taken in the development of robust aggregation algorithms for FL in recent years, their efficacy is confined to addressing particular forms of Byzantine attacks, and they exhibit vulnerabilities when confronted with a spectrum of attack vectors. Notably, a prevailing issue lies in the heavy reliance of these algorithms on the examination of local model gradients. It is worth noting that an attacker possesses the ability to manipulate a carefully chosen small gradient of a model within a context where there could be millions of gradients available, thereby facilitating adaptive attacks. Drawing inspiration from the foundational Shapley value methodology in game theory, we introduce an effective FL scheme namedCareFL. This scheme is designed to provide robustness against a spectrum of state-of-the-art Byzantine attacks. Unlike approaches that rely on the examination of gradients,CareFLemploys a universal metric, the loss of the local model—independent of specific gradients, to identify potentially malicious clients. Specifically, in each aggregation round, the FL server trains a reference model using a small auxiliary dataset— the auxiliary dataset can be removed with a slight defense degradation trade-off. It employs the Shapley value to assess the contribution of each client-submitted model in minimizing the global model loss. Subsequently, the server selects client models closer to the reference model in terms of Shapley values for the global model update. To reduce the computational overhead ofCareFLwhen the number of clients is relatively scaled-up, we construct its variant, namelyCareFL+ generally by grouping clients. Extensive experimentation conducted on well-established MNIST and CIFAR-10 datasets, encompassing diverse model architectures, including AlexNet, demonstrates thatCareFLconsistently achieves accuracy levels comparable to those attained under attack-free conditions when faced with five formidable attacks.CareFLand CareFL+ outperform six existing state-of-the-art Byzantine-robust FL aggregation methods, includingFLTrust, across both IID and non-IID data distribution settings.
Qihao Dong, Shengyuan Yang, Zhiyang Dai, Yansong Gao 0001, Shang Wang 0004, Yuan Cao 0003, Anmin Fu, Willy Susilo
IEEE Trans. Inf. Forensics Secur.1
2023 DMRA: Model Usability Detection Scheme Against Model-Reuse Attacks in the Internet of Things
abstract
Internet of Things (IoT) devices can utilize deep learning (DL) to boost their intelligence, but also suffer from the long model training process. IoT devices thus may reuse public pretrained models to expedite the training through transfer learning. However, pretrained models may be subject to model-reuse attacks initiated by malicious DL servers, causing models to misclassify targeted data, which poses a threat to the security of IoT devices. In this work, we propose a new model usability detection scheme, the defense against model-reuse attacks (DMRAs), suitable for IoT scenarios. DMRA employs a variant of Lagrange’s mean value theorem to reverse-check the model, which is computationally efficient, thus, suitable for resource-constrained devices. Experimental evaluations on different data sets first validate that model-reuse attacks can attack models in federated learning. And, then demonstrate that DMRA detects such insidious attacks with up to 80% success rate at a lightweight computational cost.
Qihao Dong, Anmin Fu, Mang Su, Lei Zhou 0026, Shui Yu 0001
IEEE Internet Things J.1