VLDB 2026 Research / reviewers in the wild / expert
Tingyu Fan
dblp:312/7164
· DBLP profile ↗
15ranked-venue papers
6as first author
15since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 6 · 2 first-author · 6 since 2021Computer networks · 3 · 2 first-author · 3 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | JAGUAR: efficient and secure unbalanced PSI under malicious adversaries in the client-server settingabstractAbstract In many unbalanced private set intersection (uPSI) applications of the client–server setting, the server needs to perform uPSI with multiple clients. Cong et al. (ACM CCS’21) proposed a state-of-the-art (SOTA) uPSI protocol based on fully homomorphic encryption (FHE), achieving malicious security by employing an oblivious pseudorandom function (OPRF) in the pre-processing phase. However, re-executing existing uPSI protocols with each client imposes significant computational overhead for the server. In this paper, we present JAGUAR, a maliciously secure and efficient uPSI protocol designed for this setting. JAGUAR reduces online computation through a Divide-and-Combine optimization, requiring only $${\mathcal {O}}(\sqrt{|X|})$$ O ( | X | ) homomorphic multiplications. Furthermore, it employs a novel fixed VOLE-based OPRF that enables reusable and lightweight pre-processing across multiple clients. Experimental results demonstrate that JAGUAR achieves up to $$2.7\times$$ 2.7 × improvement in online runtime compared to the SOTA protocol in LAN. In multi-client scenarios, JAGUAR further outperforms existing protocols by a wide margin in terms of scalability and overall performance. Weizhan Jing, Xiaojun Chen 0004, Ye Dong, Qiang Liu 0060, Tingyu Fan |
Cybersecur. | 6 |
| 2025 | FLock: Robust and Privacy-Preserving Federated Learning based on Practical Blockchain State ChannelsabstractFederated Learning (FL) is a distributed machine learning paradigm that allows multiple clients to train models collaboratively without sharing local data. Numerous works have explored security and privacy protection in FL, as well as its integration with blockchain technology. However, existing FL works still face critical issues. i) It is difficult to achieving poisoning robustness and data privacy while ensuring high model accuracy. Malicious clients can launch poisoning attacks that degrade the global model. Besides, aggregators can infer private data from the gradients, causing privacy leakages. Existing privacy-preserving poisoning defense FL solutions suffer from decreased model accuracy and high computational overhead. ii) Blockchain-assisted FL records iterative gradient updates on-chain to prevent model tampering, yet existing schemes are not compatible with practical blockchains and incur high costs for maintaining the gradients on-chain. Besides, incentives are overlooked, where unfair reward distribution hinders the sustainable development of the FL community. In this work, we propose FLock, a robust and privacy-preserving FL scheme based on practical blockchain state channels. First, we propose a lightweight secure Multi-party Computation (MPC)-friendly robust aggregation method through quantization, median, and Hamming distance, which could resist poisoning attacks against up to <50% malicious clients. Besides, we propose communication-efficient Shamir's secret sharing-based MPC protocols to protect data privacy with high model accuracy. Second, we utilize blockchain off-chain state channels to achieve immutable model records and incentive distribution. FLock achieves cost-effective compatibility with practical cryptocurrency platforms, e.g. Ethereum, along with fair incentives, by merging the secure aggregation into a multi-party state channel. In addition, a pipelined Byzantine Fault-Tolerant (BFT) consensus is integrated where each aggregator can reconstruct the final aggregated results. Lastly, we implement FLock and the evaluation results demonstrate that FLock enhances robustness and privacy, while maintaining efficiency and high model accuracy. Even with 25 aggregators and 100 clients, FLock can complete one secure aggregation for ResNet in 2 minutes over a WAN. FLock successfully implements secure aggregation with such a large number of aggregators, thereby enhancing the fault tolerance of the aggregation. Ye Dong, Yizhong Liu, Tingyu Fan, Dawei Li 0009, Zhenyu Guan 0002, Jianwei Liu 0001, Jianying Zhou 0001 |
WWW | 4 |
| 2025 | FedShelter: Efficient privacy-preserving federated learning with poisoning resistance for resource-constrained IoT network
Tingyu Fan, Xiaojun Chen 0004, Ye Dong, Weizhan Jing, Zhendong Zhao |
Comput. Networks | 1 |
| 2025 | Tangram: Enabling Efficient and Balanced Dynamic Storage Extension on Sharding Blockchain SystemsabstractIn recent years, sharding technology has been frequently applied in blockchain systems to increase scalability. However, when new shards are added, the system may result in significant overhead in terms of computing and networking since the data allocation approach is incompatible with dynamic changes in shards. Currently, S-Store, the state-of-the-art sharding solution built on the account model, has a high re-computing latency when growing shard numbers and an unbalanced sharded data distribution after growth. To address these issues, this paper presents Tangram, an efficient and balanced dynamic storage extension approach for sharding blockchain systems. Tangram reduces system extension overhead and latency while ensuring a balanced shard distribution. In implementing Tangram, we tackle three main technical challenges as follows. (1) Designing a novel state tree structure for the storage and maintenance of sharding state data. We introduce the Jump Merkle Tree (JMT) based on the Merkle Tree, which integrates node migration and orderliness. (2) Presenting a protocol to be compatible with dynamic shard scenarios. We devise a shard addition protocol to improve system extension availability and decrease shard extension delay. (3) Proposing an approach to guarantee system longevity after extension. We first devise algorithms for the state tree to eradicate invalid states after system expansion. Furthermore, we introduce a shard reduction protocol to enhance system storage extension support in complex scenarios, such as cleaning up inactive states to avoid bloating the state tree. We conduct extensive experiments to evaluate the performance of Tangram. Experiment results demonstrate that Tangram outperforms existing solutions, showing reduced latency and superior data balance. When compared to the state-of-the-art sharding storage solution, Tangram decreases the transaction execute time by up to 87.84%, the state data migration by more than approximately 74%, and achieves up to 7.63x improvement in the standard deviation of sharding data balance. Hao Xu 0025, Xiulong Liu 0001, Zhimin Yu, Tingyu Fan, Baochao Chen, Keqiu Li |
IEEE Trans. Computers | 5 |
| 2025 | Lossless LiDAR Point Cloud Reflectance Compression With a Deep Hierarchical KNN Context ModelabstractRecently, numerous learning-based point cloud compression methods with outstanding performance have been developed. The majority of them concentrate on point cloud geometry compression, and several works have demonstrated advances in the color attribute compression for dense point clouds. However, compression of the reflectance attribute attached to the point captured by the light detection and ranging (LiDAR) sensors remains a major challenge. In this article, we present a lossless reflectance compression method for LiDAR point clouds (LPCs) that learns reflectance probability distributions with a deep hierarchical k-nearest-neighbors (KNN) context model, namely, the HK-PCRC. We first represent the original LPC with a series of hierarchical layers. Relying on the hierarchical structure, points in the same layer are coded in parallel by referencing the points in the previously coded layers. The approach balances the coding efficiency and time complexity while also supporting the progressive coding functionality. By introducing the KNN context, the context size is significantly reduced, which eases the computational burden while maintaining the coding performance. To enrich the context information, we further search for enhanced neighbors for each point in the context window. For each enhanced neighbor, in addition to its reflectance value, the relative distance, elevation angle, and local density are further collected. Then, a transformer-style sequential model is applied to construct an accurate deep context model. Furthermore, to efficiently fuse context features from different sources, a cross-feature fusion attention mechanism is designed for the transformer network. The comprehensive experimental results on SemanticKITTI, a large scale LiDAR benchmark, and Ford, an MPEG-specified dataset, demonstrate that our proposed framework achieves a state-of-the-art reflectance lossless compression performance, with average bit savings of 11.3% and 9.6% when compared to the state-of-the-art hand-crafted methods. Lizhi Hou, Tingyu Fan, Yiling Xu, Zhu Li 0001 |
IEEE Trans. Multim. | 2 |
| 2024 | Lightweight Secure Aggregation for Personalized Federated Learning with Backdoor ResistanceabstractExisting federated learning (FL) systems are highly vulnerable in terms of security and privacy due to their distributed architecture, facing poisoning attacks and inference attacks from adversaries. Some prior works have combined poisoning defenses with cryptographic tools: Secure Multi-Party Computation, Zero-Knowledge Proof, and Homomorphic Encryption to propose robust secure aggregation methods that provide security and privacy preservation for FL. Recently, Qin et al. (KDD’23) demonstrate that personalized federated learning (pFL) can effectively resist backdoor injection in poisoning attacks. In this paper, we analyze that as the number of malicious attackers increases, pFL remains vulnerable to backdoor attacks. Moreover, we reveal that current robust secure aggregation methods fail to offer efficient and robust backdoor defense for pFL. Therefore, we propose FLIGHT, a robust secure aggregation method for pFL. It implements a lightweight backdoor detection through a two-stage personalized defense mechanism and ensures privacy preservation using communication-efficient two-party secure computation (2PC) protocols. Extensive experiments on diverse datasets and neural networks validate that FLIGHT decreases run-time up to 64× compared by prior work RoFL (S&P’23), and 42× compared to FLAME (USENIX Security’22). Tingyu Fan, Xiaojun Chen 0004, Ye Dong, Yuexin Xuan, Weizhan Jing |
ACSAC | 1 |
| 2024 | CipherDM: Secure Three-Party Inference for Diffusion Model Sampling
Xiaojun Chen 0004, He Li 0010, Tingyu Fan, Zhendong Zhao |
ECCV (71) | 5 |
| 2024 | Roger: A Round Optimized GPU-Friendly Secure Inference FrameworkabstractSecure neural network inference provides a promising solution to preserve the privacy of Deep Learning as a Service (DLaaS), but its substantial communication and computation overhead remain challenging. Recent works such as GForce [1] and Piranha [2] have introduced GPU-friendly secure inference protocols with improved computation efficiency, yet these approaches are either limited to supporting specialized-trained networks or expensive in communication. As a consequence, there remain potential improvements in functionalities and communication efficiency. To address the above challenges, we introduce Roger, a two-party secure inference framework with semi-honest security, designed to support general neural network inference with a reduced number of round complexity. Drawing inspiration from ABY2.0 [3], we propose the Partial-Fix technology, which fixes the share of one participant during the offline phase to improve its computation efficiency. Then, an online communication-free protocol for secure linear layer computation and a constant-round secure comparison protocol are proposed upon Partial-Fix. Implemented on top of Piranha, the experiments demonstrate that for the CIFAR10 dataset, a single inference on VGG16 requires only 0.40 seconds. In comparison to GForce (resp. Piranha), Roger at least achieves 1.20× (resp. 1.94×) improvement in LAN setting in terms of throughput. Xiaojun Chen 0004, Ye Dong, Weizhan Jing, Tingyu Fan |
ICC | 5 |
| 2024 | Comet: Communication-Efficient Batch Secure Three-Party Neural Network Inference with Client-AidingabstractSecure neural network inference enables server (model provider) and client to perform neural network inference without leaking their private inputs. Existing SOTA three-party computation (3PC) inference works emerge challenges on two fronts: i) GPU-accelerated CryptGPU (S&P'21) and P-FALCON (USENIX Security'22) face challenges related to high communication overhead. ii) communication-efficient Meteor(www'23) raises more computation burden and GPU memory usage. These challenges result in lower efficiency when handling large-scale batch inference requests on resource-constrained devices. In this work, we propose Comet,a communication-efficient batch secure three-party inference framework with client-aiding, which achieves semi-honest security in honest majority without collusion between the client and the servers. First, we propose client-aided sharing semantics, which leverages client-generated random values to enhance online communication efficiency. We also design efficient 3PC protocols for neural network operators based on GPU, improving the computational efficiency of both linear and nonlinear layers. Furthermore, we address the tradeoff between communication cost and GPU memory utilization, surpassing SOTA by 1.3-1.9× in communication, 1.5-3.8× in runtime on large-scale batch inference tasks. Tingyu Fan, Xiaojun Chen 0004, Ye Dong, Weizhan Jing |
ICC | 1 |
| 2024 | OCE-PTree: An Online Communication Efficient Privacy-Preserving Decision Tree Evaluation
Xiaojun Chen 0004, Weizhan Jing, Tingyu Fan |
SecureComm (1) | 6 |
| 2023 | An Effective and Balanced Storage Extension Approach for Sharding Blockchain SystemsabstractSharding technology has become crucial for enhancing the scalability of blockchains owing to the rapid extension of blockchain data. However, data migration and state reconstruction may cause a high overhead when a new shard is added. Existing solutions have high latency when expanding, and the balance of the state data between shards is poor after extension. To this end, this paper proposes an Effective and Balanced Storage Extension (EBSE) approach for sharding blockchain systems. EBSE can reduce the overhead and latency of the system extension, while ensuring a balance between shards after extension. When implementing the EBSE, we address the following three challenges. 1) To design a data structure that incorporates allocation principles, we designed a Jump Merkle Tree (JMT) based on the Merkle Tree prototype, incorporating node migration and orderliness. 2) To design additional rules that ensure the integrity of the state tree during shard addition, we designed a shard addition protocol to coordinate and standardize the behavior of each shard during the extension process. 3) To ensure the sustainability of the system after extension, we designed state tree addition and cleaning algorithms to remove the invalid information after the system extension. Extensive experiments are conducted to evaluate the performance of the proposed approach. The experimental results show that the EBSE outperforms the existing solutions in terms of balance and latency. Compared with the state-of-the-art sharding storage, EBSE effectively reduces the shard addition latency by 60% and achieves 4× superior shard data balance. Tingyu Fan, Xiulong Liu 0001, Baochao Chen, Wenyu Qu |
ICCD | 1 |
| 2023 | Learning Dynamic Point Cloud Compression via Hierarchical Inter-frame Block Matchingabstract3D dynamic point cloud (DPC) compression relies on mining its temporal context, which faces significant challenges due to DPC's sparsity and non-uniform structure. Existing methods are limited in capturing sufficient temporal dependencies. Therefore, this paper proposes a learning-based DPC compression framework via hierarchical block-matching-based inter-prediction module to compensate and compress the DPC geometry in latent space. Specifically, we propose a hierarchical motion estimation and motion compensation (Hie-ME/MC) framework for flexible inter-prediction, which dynamically selects the granularity of optical flow to encapsulate the motion information accurately. To improve the motion estimation efficiency of the proposed inter-prediction module, we further design a KNN-attention block matching (KABM) network that determines the impact of potential corresponding points based on the geometry and feature correlation. Finally, we compress the residual and the multi-scale optical flow with a fully-factorized deep entropy model. The experiment result on the MPEG-specified Owlii Dynamic Human Dynamic Point Cloud (Owlii) dataset shows that our framework outperforms the previous state-of-the-art methods and the MPEG standard V-PCC v18 in inter-frame low-delay mode. Shuting Xia, Tingyu Fan, Yiling Xu, Jenq-Neng Hwang, Zhu Li 0001 |
ACM Multimedia | 2 |
| 2023 | Multiscale Latent-Guided Entropy Model for LiDAR Point Cloud CompressionabstractThe non-uniform distribution and extremely sparse nature of the LiDAR point cloud (LPC) bring significant challenges to its high-efficient compression. This paper proposes a novel end-to-end, fully-factorized deep framework that represents the original LiDAR point cloud into an octree structure and hierarchically constructs the octree entropy model in layers. The proposed framework utilizes a hierarchical latent variable as side information to encapsulate the sibling and ancestor dependence, which provides sufficient context information for the modeling of point cloud distribution while enabling the parallel encoding and decoding of octree nodes in the same layer. Besides, we propose a residual coding framework for the compression of the latent variable, which explores the spatial correlation of each layer by progressive downsampling, and model the corresponding residual with a fully-factorized entropy model. Furthermore, we propose soft addition and subtraction for residual coding to improve network flexibility. The comprehensive experiment results on the LiDAR benchmark SemanticKITTI and MPEG-specified dataset Ford demonstrate that our proposed framework achieves state-of-the-art performance among all the previous LPC frameworks. Besides, our end-to-end, fully-factorized framework is proved by experiment to be high-parallelized and time-efficient, which saves more than 99.8% of decoding time compared to previous state-of-the-art methods on LPC compression. Tingyu Fan, Linyao Gao, Yiling Xu, Dong Wang 0004, Zhu Li 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 1 |
| 2022 | D-DPCC: Deep Dynamic Point Cloud Compression via 3D Motion PredictionabstractThe non-uniformly distributed nature of the 3D Dynamic Point Cloud (DPC) brings significant challenges to its high-efficient inter-frame compression. This paper proposes a novel 3D sparse convolution-based Deep Dynamic Point Cloud Compression (D-DPCC) network to compensate and compress the DPC geometry with 3D motion estimation and motion compensation in the feature space. In the proposed D-DPCC network, we design a Multi-scale Motion Fusion (MMF) module to accurately estimate the 3D optical flow between the feature representations of adjacent point cloud frames. Specifically, we utilize a 3D sparse convolution-based encoder to obtain the latent representation for motion estimation in the feature space and introduce the proposed MMF module for fused 3D motion embedding. Besides, for motion compensation, we propose a 3D Adaptively Weighted Interpolation (3DAWI) algorithm with a penalty coefficient to adaptively decrease the impact of distant neighbours. We compress the motion embedding and the residual with a lossy autoencoder-based network. To our knowledge, this paper is the first work proposing an end-to-end deep dynamic point cloud compression framework. The experimental result shows that the proposed D-DPCC framework achieves an average 76% BD-Rate (Bjontegaard Delta Rate) gains against state-of-the-art Video-based Point Cloud Compression (V-PCC) v13 in inter mode. Tingyu Fan, Linyao Gao, Yiling Xu, Zhu Li 0001, Dong Wang 0004 |
IJCAI | 1 |
| 2021 | Point Cloud Geometry Compression Via Neural Graph SamplingabstractCompressing point cloud geometry (PCG) efficiently is of great interests for enabling abundant networked applications, because PCG is a promising representation to precisely illustrate arbitrary-shaped 3D objects and relevant physical scenes. To well exploit the unconstrained geometric correlation of input PCG, a three-step neural graph sampling (NGS) is developed. First, we construct the local graph of each point using its K nearest neighbors according to the Euclidean distance metric; Second, for each local graph, its graph center point expands associated feature attribute by aggregating neighbor weights via point-wise dynamic filter; We then perform attention-based sampling to select a subset of points to well represent input points. The proposed NGS is embedded into an end-to-end analysis/synthesis-based variational autoencoder (VAE), with which the encoder applies multiscale NGS to extract latent keypoints that are augmented with neighbor structures and compressed at bottleneck leveraging the hyperpriors for accurate entropy modeling, and the decoder directly uses layered convolutions to refine progressively for the reconstruction of final point cloud. Note that all computations are fulfilled using point-wise convolution, making our solution an attractive approach in practice. Experimental results demonstrate that the proposed method using NGS mechanism outperforms the state-of-the-art point-based PCG compression methods by more than $2\times \mathrm{B}\mathrm{D}$-Rate (Bjûntegaard Delta Rate) gains, and several orders of magnitude gains over the MPEG G-PCC across all testing categories on ShapeNetCorev2 dataset. Linyao Gao, Tingyu Fan, Jianqiang Wan, Yiling Xu, Jun Sun 0005, Zhan Ma 0001 |
ICIP | 2 |