VLDB 2026 Research / reviewers in the wild / expert
Chong Fu 0002
dblp:30/6251-2
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2024
0000-0001-6465-2305ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | HashVFL: Defending Against Data Reconstruction Attacks in Vertical Federated LearningabstractVertical Federated Learning (VFL) is a trending collaborative machine learning model training solution. Existing industrial frameworks employ secure multi-party computation techniques such as homomorphic encryption to ensure data security and privacy. Despite these efforts, studies have revealed that data leakage remains a risk in VFL due to the correlations between intermediate representations and raw data. Neural networks can accurately capture these correlations, allowing an adversary to reconstruct the data. This emphasizes the need for continued research into securing VFL systems. Our work shows that hashing is a promising solution to counter data reconstruction attacks. The one-way nature of hashing makes it difficult for an adversary to recover data from hash codes. However, implementing hashing in VFL presents new challenges, including vanishing gradients and information loss. To address these issues, we propose HashVFL, which integrates hashing and simultaneously achieves learnability, bit balance, and consistency. Experimental results indicate that HashVFL effectively maintains task performance while defending against data reconstruction attacks. It also brings additional benefits in reducing the degree of label leakage, mitigating adversarial attacks, and detecting abnormal inputs. We hope our work will inspire further research into the potential applications of HashVFL. Pengyu Qiu, Xuhong Zhang 0002, Shouling Ji, Chong Fu 0002, Xing Yang 0004, Ting Wang 0006 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | FreeEagle: Detecting Complex Neural Trojans in Data-Free Cases
Chong Fu 0002, Xuhong Zhang 0002, Shouling Ji, Ting Wang 0006, Yang-He Feng, Jianwei Yin |
USENIX Security Symposium | 1 |
| 2022 | Spatial-Temporal Correlation Modeling for Motion PredictionabstractHuman motion prediction is fundamental for many applications in computer vision. Current methods typically handle motion prediction with seqential models, which ignore the fact that joint movement is driven by forces. In this paper, we provide a novel mechanical view to decompose force into magnitude and direction, which contributes to modeling the temporal evolution of joints. Moreover, existing graph convolution-based methods merely utilize the deep-level features, which is difficult to capture the complex spatial dependencies contexts. We introduce a novel spatial connections encoding model to capture the multi-level spatial dependencies between joints. Finally, to encode abundant temporal dependencies, we present a multi-head temporal encoding module. Comprehensive experiments show that our model sets the state-of-the-art performance on the largest human motion benchmark datasets. Yingying Jiao, Haipeng Chen 0002, Chang Yao 0001, Pengxiang Su, Chong Fu 0002, Xiang Wang 0010 |
ICME | 5 |
| 2022 | Transfer Attacks Revisited: A Large-Scale Empirical Study in Real Computer Vision SettingsabstractOne intriguing property of adversarial attacks is their “transferability” – an adversarial example crafted with respect to one deep neural network (DNN) model is often found effective against other DNNs as well. Intensive research has been conducted on this phenomenon under simplistic controlled conditions. Yet, thus far there is still a lack of comprehensive understanding about transferability-based attacks (“transfer attacks”) in real-world environments.To bridge this critical gap, we conduct the first large-scale systematic empirical study of transfer attacks against major cloud-based MLaaS platforms, taking the components of a real transfer attack into account. The study leads to a number of interesting findings which are inconsistent to the existing ones, including: (i) Simple surrogates do not necessarily improve real transfer attacks. (ii) No dominant surrogate architecture is found in real transfer attacks. (iii) It is the gap between posterior (output of the softmax layer) rather than the gap between logit (so-called κ value) that increases transferability. Moreover, by comparing with prior works, we demonstrate that transfer attacks possess many previously unknown properties in real-world environments, such as (i) Model similarity is not a well-defined concept. (ii) L2norm of perturbation can generate high transferability without usage of gradient and is a more powerful source than L∞norm. We believe this work sheds light on the vulnerabilities of popular MLaaS platforms and points to a few promising research directions.1 Yuhao Mao, Chong Fu 0002, Saizhuo Wang, Shouling Ji, Xuhong Zhang 0002, Zhenguang Liu, Jun Zhou 0011, Alex X. Liu, Raheem A. Beyah, Ting Wang 0006 |
SP | 2 |
| 2022 | Label Inference Attacks Against Vertical Federated Learning
Chong Fu 0002, Xuhong Zhang 0002, Shouling Ji, Jinyin Chen, JingZheng Wu, Shanqing Guo, Jun Zhou 0011, Alex X. Liu, Ting Wang 0006 |
USENIX Security Symposium | 1 |