VLDB 2026 Research / reviewers in the wild / expert
Yanghe Pan
dblp:312/9476
· DBLP profile ↗
10ranked-venue papers
3as first author
10since 2021 · last 2026
0009-0008-1485-058XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 3 first-author · 9 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FLET: Game-Theoretic Free-Riding Mitigation via Test Tasks in Federated LearningabstractFederated learning (FL) is a widely studied framework for privacy-preserving collaborative training among multiple clients. However, real-world deployments reveal a persistent challenge: free-riders, i.e., participants who benefit from the system without contributing meaningful updates. If not properly addressed, free-riders can discourage honest contributors and ultimately impair both the fairness and efficiency of FL ecosystems. Existing defenses mainly rely on post-hoc per-client, per-round evaluation, leading to limited deterrence and high resource overhead, particularly in large-scale deployments. To tackle these problems, we propose FLET, a novel federated learning framework with test tasks. FLET introduces dedicated test tasks into the training process, blending them with real FL tasks while concealing their types from participants. These test tasks, generated from the reference datasets, serve as decoys that enable accurate detection of free-riding behavior. To enforce accountability, an economic penalty mechanism is employed, achieving both proactive (ex-ante) deterrence and reactive (expost) detection.We analyze the interactions between the server and participants through a free-riding suppression game model with asymmetric information (i.e.,task type), and develop a strategic information disclosure scheme (i.e.,revealing task requirements) to mislead attackers and proactively shape participant behavior. We characterize both pure-strategy and mixed-strategy perfect Bayesian Nash equilibria, and propose a lightweight strateg-ymaking algorithm that guides players toward equilibrium strategies under different conditions with modest overhead. Extensive experiments validate that FLET effectively suppresses free-riding and enhances the utility of both the server and participants. Our findings provide insights for designing cost-effective free-riding defenses in practical FL. Shaolong Guo, Yuntao Wang 0004, Zhou Su 0001, Yanghe Pan, Tom H. Luan, Xizhao Luo |
IEEE Trans. Netw. | 4 |
| 2026 | Privacy-Utility Trade-Off in Federated LLM Fine-Tuning: A Dynamic Game ApproachabstractFine-tuning large language models (LLMs) is critical for adapting pretrained models to specialized downstream tasks. Federated LLM fine-tuning enables privacy-aware model updates by allowing data owners (DOs) to contribute a global LLM without exposing local data. However, full-parameter fine-tuning in federated settings incurs significant computational and communication overhead, while frequent gradient exchanges increase the risk of privacy leakage, such as memorized data inference. Parameter-efficient fine-tuning (PEFT) with differential privacy (DP) offers a low-overhead alternative with formal privacy guarantees, but fails to strike privacy-utility tradeoff under heterogeneous privacy preferences: individual DOs may inject excessive DP noise to maximize privacy, whereas the curator aims to minimize noise to preserve model quality. In this paper, we present an innovative game-theoretical framework that enables dynamic privacy trading within differentially private federated LLM fine-tuning. In the game, DOs strategically adjust their local DP noise levels in exchange for customized incentives from the curator, thereby balancing privacy and utility. We begin by establishing a theoretical convergence bound that quantifies the influence of locally injected noise on the global model utility. Under this bound, we analytically characterize the pure-strategy Nash equilibrium of the game, accounting for DO heterogeneity, curator budget constraints, and noise estimation errors. For mixed-strategy settings with incomplete information, we design a hierarchical reinforcement learning algorithm that jointly learns DOs’ optimal noise-saving strategies and the curator’s optimal pricing policy without presupposing their private information. Experiments on real-world datasets demonstrate that the proposed scheme improves DO utility, reduces curator cost, mitigates free-riding, and accelerates convergence compared to existing methods. Yuntao Wang 0004, Yanghe Pan, Zhou Su 0001, Wei Wang 0100 |
IEEE Trans. Netw. | 3 |
| 2025 | Knowledge-Aware Privacy-Preserving Model Customization in Zero-Trust Federated Learning Model MarketplacesabstractFederated learning (FL) model marketplaces require qualified workers to collaboratively train customized models. However, recruiting optimal workers on a limited budget in non-independent and identically distributed (non-IID) data settings remains a fundamental issue. Moreover, inadequate quality verification exposes the marketplace to spoofing and poisoning attacks, while verifying data and model quality without accessing local storage remains a significant dilemma. To bridge the research gap, this paper proposes a knowledge-aware model customization scheme in FL model marketplaces, to facilitate zero-trust worker recruitment and verification while ensuring privacy preservation. Specifically, (i) we design a knowledge-aware quality evaluation mechanism by leveraging the knowledge of workers, i.e., soft-label predictions of their local models on a privacy-free reference dataset (provided by the customer), to assess their data quality in a privacy-preserving manner. (ii) We formulate the optimal worker recruitment problem under budget constraints as an NP-hard integer programming problem and design a dynamic programming-based optimal worker recruitment algorithm with budget feasibility and computational efficiency. (iii) We devise a two-stage zero-trust quality verification mechanism by utilizing zero-knowledge proof (ZKP) to exclude distrustful workers, thereby preventing spoofing and poisoning attacks. Extensive experimental results demonstrate that the proposed scheme enhances model customization performance by up to 34.3% on label-skewed non-IID data and 36.2% on feature-skewed non-IID data compared with existing representatives. Yanghe Pan, Zhou Su 0001, Yuntao Wang 0004, Ruidong Li 0001, Abderrahim Benslimane |
IEEE J. Sel. Areas Commun. | 1 |
| 2025 | Protecting Your Attention During Distributed Graph Learning: Efficient Privacy-Preserving Federated Graph Attention NetworkabstractFederated graph attention networks (FGATs) are gaining prominence for enabling collaborative and privacy-preserving graph model training. The attention mechanisms in FGATs enhance the focus on crucial graph features for improved graph representation learning while maintaining data decentralization. However, these mechanisms inherently process sensitive information, which is vulnerable to privacy threats like graph reconstruction and attribute inference. Additionally, their role in assigning varying and changing importance to nodes challenges traditional privacy methods to balance privacy and utility across varied node sensitivities effectively. Our study fills this gap by proposing an efficient privacy-preserving FGAT (PFGAT). We present an attention-based dynamic differential privacy (DP) approach via an improved multiplication triplet (IMT). Specifically, we first propose an IMT mechanism that leverages a reusable triplet generation method to efficiently and securely compute the attention mechanism. Second, we employ an attention-based privacy budget that dynamically adjusts privacy levels according to node data significance, optimizing the privacy-utility trade-off. Third, the proposed hybrid neighbor aggregation algorithm tailors DP mechanisms according to the unique characteristics of neighbor nodes, thereby mitigating the adverse impact of DP on graph attention network (GAT) utility. Extensive experiments on benchmarking datasets confirm that PFGAT maintains high efficiency and ensures robust privacy protection against potential threats. Jinhao Zhou, Jun Wu 0001, Jianbing Ni, Yuntao Wang 0004, Yanghe Pan, Zhou Su 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | TRACEGADGET: Detecting and Tracing Network Level Attack Through Federal Provenance GraphabstractProvenance graph-based auditing offers a promising direction for APT (Advanced Persistent Threat) detection with traceability guarantees. However, most of the existing methods are based on host-level causality analysis, which is ineffective in practical APT scenarios when well-organized adversaries exploit lateral movement attacks (e.g., multi-level proxies) across multiple compromised hosts. To bridge the research gap, this paper proposes a collaborative APT detection and tracing frame-work (TRACEGADGET) based on federal provenance graphs. TRACEGADGET can efficiently reveal the whole trace of APT lateral movements through the interactions between hosts in Intranet. Specifically, the proposed framework 1) characterizes the relevance weights of all events in the given provenance graph in comparison to the POI (Point of Interest) events, 2) identifies the network entries rankings of the POI events through backward trace analysis, 3) reveals the evolution of the alarm events and confirms the network exit of penetration chain through forward propagation, and 4) aligns the network entries and network exits to derive the complete path of the lateral movement attack. Finally, we construct a dataset consisting of 280,000 edges and more than 90,000 entities through ten sets of real APT attacks. We demonstrate the feasibility and effectiveness of the proposed framework in recovering APT attack links at the network level. Particularly, TRACEGADGET achieves 100% APT path reconstruction with high robustness in all the experiments. Yuntao Wang 0004, Zhou Su 0001, Zixuan Wang 0014, Yanghe Pan, Ruidong Li 0001 |
ICC | 5 |
| 2024 | Privacy-Enhanced and Efficient Federated Knowledge Transfer Framework in IoTabstractFederated learning (FL) has gained widespread adoption in Internet of Things (IoT) applications, promoting the evolution of IoT toward Artificial Intelligence of Things (AIoT). However, IoT devices are still vulnerable to various privacy inference attacks in FL. While current solutions aim to protect the privacy of devices during model training, the published model is still at risk from external privacy attacks during model deployment. To address the privacy concerns throughout the entire FL lifecycle, this article proposes a privacy-enhanced and efficient federated knowledge transfer framework for IoT, named PEFKT, which integrates the knowledge transfer method and local differential privacy (LDP) mechanism. In PEFKT, we devise a data diversity-driven grouping strategy to tackle the non-independent and identically distributed (non-IID) issue in IoT. Additionally, we design a quality-aware soft-label aggregation algorithm to facilitate effective knowledge transfer, thereby improving the performance of the student model. Finally, we provide rigorous privacy analysis and validate the feasibility and effectiveness of PEFKT through extensive experiments on real data sets. Yanghe Pan, Zhou Su 0001, Yuntao Wang 0004, Ruidong Li 0001, Yuan Wu 0001 |
IEEE Internet Things J. | 1 |
| 2024 | Social-Aware Clustered Federated Learning With Customized Privacy PreservationabstractA key feature of federated learning (FL) is to preserve the data privacy of end users. However, there still exist potential privacy leakage in exchanging gradients under FL. As a result, recent research often explores the differential privacy (DP) approaches to add noises to the computing results to address privacy concerns with low overheads, which however degrade the model performance. In this paper, we strike the balance of data privacy and efficiency by utilizing the pervasive social connections between users. Specifically, we propose SCFL, a novel Social-aware Clustered Federated Learning scheme, where mutually trusted individuals can freely form a social cluster and aggregate their raw model updates (e.g., gradients) inside each cluster before uploading to the cloud for global aggregation. By mixing model updates in a social group, adversaries can only eavesdrop the social-layer combined results, but not the privacy of individuals. As such, SCFL considerably enhances model utility without sacrificing privacy in a low-cost and highly feasible manner. We unfold the design of SCFL in three steps. i) Stable social cluster formation. Considering users’ heterogeneous training samples and data distributions, we formulate the optimal social cluster formation problem as a federation game and devise a fair revenue allocation mechanism to resist free-riders. ii) Differentiated trust-privacy mapping. For the clusters with low mutual trust, we design a customizable privacy preservation mechanism to adaptively sanitize participants’ model updates depending on social trust degrees. iii) Distributed convergence. A distributed two-sided matching algorithm is devised to attain an optimized disjoint partition with Nash-stable convergence. Experiments on Facebook network and MNIST/CIFAR-10 datasets validate that our SCFL can effectively enhance learning utility, improve user payoff, and enforce customizable privacy protection. Yuntao Wang 0004, Zhou Su 0001, Yanghe Pan, Tom H. Luan, Ruidong Li 0001, Shui Yu 0001 |
IEEE/ACM Trans. Netw. | 3 |
| 2023 | Trade Privacy for Utility: A Learning-Based Privacy Pricing Game in Federated LearningabstractTo prevent implicit privacy disclosure in sharing gradients among data owners (DOs) under federated learning (FL), differential privacy (DP) and its variants have become a common practice to offer formal privacy guarantees with low overheads. However, individual DOs generally tend to inject larger DP noises for stronger privacy provisions (which entails severe degradation of model utility), while the curator (i.e., aggregation server) aims to minimize the overall effect of added random noises for satisfactory model performance. To address this conflicting goal, we propose a novel dynamic privacy pricing (DyPP) game which allows DOs to sell individual privacy (by lowering the scale of locally added DP noise) for differentiated economic compensations (offered by the curator), thereby enhancing FL model utility. Considering multi-dimensional information asymmetry among players (e.g., DO's data distribution and privacy preference, and curator's maximum affordable payment) as well as their varying private information in distinct FL tasks, it is hard to directly attain the Nash equilibrium of the mixed-strategy DyPP game. Alternatively, we devise a fast reinforcement learning algorithm with two layers to quickly learn the optimal mixed noise-saving strategy of DOs and the optimal mixed pricing strategy of the curator without prior knowledge of players' private information. Experiments on real datasets validate the feasibility and effectiveness of the proposed scheme in terms of faster convergence speed and enhanced FL model utility with lower payment costs. Yuntao Wang 0004, Zhou Su 0001, Yanghe Pan, Abderrahim Benslimane, Yiliang Liu, Tom H. Luan, Ruidong Li 0001 |
ICC | 3 |
| 2022 | Personalized Privacy-Preserving Federated Learning: Optimized Trade-off Between Utility and PrivacyabstractThe emerging federated learning (FL) offers a feasible solution for the privacy preservation of users' sensitive data in training artificial intelligence (AI) models. Meanwhile, differential privacy (DP) is widely used in FL to ensure that data privacy is not disclosed during model training. However, in the practical deployment of DP in FL, a prominent challenge is that most existing FL solutions set the same privacy level for different users, resulting in over-protection for some users while insufficient protection for others. In this paper, we propose a novel federated learning framework with user-level personalized privacy protection (named FLUP) to meet the personalized privacy requirements of different users while maintaining high data utility. In this framework, we propose a user-level personalized DP mechanism that combines a personalized sampling algorithm and Gaussian perturbation to meet each user's personalized differential privacy corresponding to their privacy parameters. Then, we qualitatively analyze the impact of the sampling threshold on model performance. Furthermore, to balance user privacy requirements and AI model performance, we design a utility-aware game model to distributively determine the optimized sampling threshold and the users' differential privacy parameters. Finally, by conducting validation experiments, we demonstrate the feasibility and effectiveness of our proposed framework in terms of model performance as well as user privacy preservation. Jinhao Zhou, Zhou Su 0001, Jianbing Ni, Yuntao Wang 0004, Yanghe Pan, Rui Xing 0001 |
GLOBECOM | 5 |
| 2021 | FL-PATE: Differentially Private Federated Learning with Knowledge TransferabstractFederated learning provides a solution for data privacy protection, while enabling training over the local data samples, without exchanging them. However, it is far from practical and secure because data privacy is still vulnerable due to the well-studied attacks, e.g., membership inference attacks and model inversion attacks. In this paper, to further prevent data leakage against these attacks, we propose FL-PATE, a differentially private federated learning framework with knowledge transfer. Specifically, participants with sensitive data are grouped to train teacher models under federated learning settings, and the knowledge of teacher models is transferred to a publicly accessible student model for prediction via aggregating teacher models' outputs of public datasets. A modified client-level differential privacy mechanism is used to guarantee each participant's data privacy during the corresponding teacher model's training process. The proposed framework preserves participant's privacy against membership inference attacks and the differential privacy cost is fixed. The privacy analysis and experiments demonstrate that trained teacher and student models have an excellent performance in accuracy and robustness theoretically and empirically. Yanghe Pan, Jianbing Ni, Zhou Su 0001 |
GLOBECOM | 1 |