VLDB 2026 Research / reviewers in the wild / expert
Shunjie Yuan
dblp:315/2778
· DBLP profile ↗
10ranked-venue papers
6as first author
10since 2021 · last 2026
0000-0003-1874-9792ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 first-author · 3 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RFA-Tex: Range-Flexible Adaptive Physical Adversarial Texture Against Real-World Person Detectors
Mengyao Zhu 0004, Xinghua Li 0001, Decheng Liu, Shunjie Yuan, Yigang Li, Yinbin Miao, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | Defend Against Label Inference Attacks in Vertical Federated Learning via Label CompressionabstractVertical federated learning (VFL) has been widely adopted in various domains for collaborative decision-making. However, recent studies have revealed critical privacy vulnerabilities in VFL, particularly label inference attacks, which significantly undermine label confidentiality and limit the applicability of VFL in privacy-sensitive scenarios. To mitigate such threats, several defense methods have been proposed by incorporating diverse privacy-preserving techniques. Nevertheless, existing defenses fail to effectively prevent the recently proposed model completion-based label inference attacks. To address this limitation, we propose a novel defense method, termed Label Compression-Based Defense (LCD), to defend against this class of attacks. The core idea of LCD is to train the VFL model using fake labels, thereby decoupling the ground-truth labels from the outputs of the malicious bottom model, which constitute the critical component exploited in the model completion-based attacks. Specifically, we introduce a multi-stage training strategy that decomposes the training process into different stages to deceive the malicious bottom model without affecting the original task. In addition, we design a deep feature-based label compression mechanism to generate fake labels for misleading the attacker. To further enhance the defense effectiveness, we propose an embedding compaction strategy based on center loss, which substantially increases the difficulty of label inference. Moreover, we theoretically prove the effectiveness of LCD from an information-theoretic perspective. Extensive experiments on both tabular and image datasets demonstrate that LCD can effectively defend against label inference attacks. The source code of LCD is publicly available at GitHub:https://github.com/YuanShunJie1/LCD. Shunjie Yuan, Xinghua Li 0001, Xuelin Cao, Robert H. Deng, Zhu Han 0001, Mérouane Debbah, Chau Yuen |
IEEE Trans. Mob. Comput. | 1 |
| 2025 | SPD: Shallow Backdoor Protecting Deep Backdoor Against Backdoor Detection
Shunjie Yuan, Xinghua Li 0001, Xuelin Cao, Mengyao Zhu 0004, Robert H. Deng |
ICCV | 1 |
| 2025 | General Test-Time Backdoor Detection in Split Neural Network-Based Vertical Federated LearningabstractAs a new distributed machine learning framework, vertical federated learning (VFL) has been widely applied in the industry. However, recent studies have demonstrated that VFL faces serious challenges from backdoor attacks, which significantly hinder its further development. Although a few studies have focused on defending against VFL backdoor attacks, these defenses either do not consider the latest attack methods or show limited effectiveness. Moreover, most existing backdoor defense efforts primarily focus on backdoor attacks in horizontal federated learning (HFL) and centralized learning. Due to the unique architecture of VFL models, these methods cannot be directly applied to backdoor defense in VFL. To mitigate the threat of backdoor attacks in VFL, we propose a general backdoor detection (GBD) scheme for backdoor defense, which detects backdoor samples by analyzing the correlation between backdoor samples and the target label, as well as by leveraging the response differences between clean and backdoor samples. Specifically, we propose two backdoor detection metrics: Class Activation Probability (CAP) and Class Activation Contribution (CAC), which are used to calculate the likelihood of a sample being a backdoor sample. We leverage these two metrics to identify backdoor samples during the inference stage. Evaluation results on both tabular and image datasets show that GBD can detect backdoor samples with high accuracy, demonstrating its effectiveness in backdoor defense. The source code of GBD is available at GitHub: https://github.com/YuanShunJie1/GBD. Shunjie Yuan, Xinghua Li 0001, Xuelin Cao, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | FL-CDF: Collaborative Defense Framework for Backdoor Mitigation in Federated LearningabstractFederated learning (FL) is vulnerable to backdoor attacks due to its distributed nature. Existing unilateral defense mechanisms often fail against persistent attack strategies, primarily due to their limited perspectives. To address the challenge of model misclassification on the server side caused by overlooked model similarity drift, and gradient misjudgment on the client side caused by semantic learning imbalances across classes, this paper proposes a collaborative defense framework for federated learning, termed FL-CDF. FL-CDF establishes an end-to-end defense through a bidirectional client-server collaboration mechanism. Specifically: (1) On the client side, an adversarial perturbation-based malicious neuron detection module is introduced. This module measures neuron activation sensitivity by generating adversarial perturbations, and adaptively prunes backdoor neurons exhibiting high sensitivity. (2) On the server side, a multi-dimensional detection scheme is designed, which integrates neuron localization, adversarial sensitivity, and model parameters. By incorporating client-side feedback on malicious neurons, the server performs robust model aggregation. Theoretical analysis verifies the robustness of FL-CDF, and extensive experiments on public benchmarks demonstrate its effectiveness. In the best-case scenario, FL-CDF improves defense performance by 42.5% compared to current state-of-the-art (SOTA) defense. Xinghua Li 0001, Yinbin Miao, Shunjie Yuan, Mengyao Zhu 0004, Ximeng Liu, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Robust Federated Learning Client Selection With Combinatorial Class Representations and Data AugmentationabstractThe federated learning (FL) client selection scheme can effectively mitigate global model performance degradation caused by the random aggregation of clients with heterogeneous data. Simultaneously, research has exposed FL’s susceptibility to backdoor attacks. However herein lies the dilemma, traditional client selection methods and backdoor defenses stand at odds, so their integration is an elusive goal. To resolve this, we introduce Grace, a resilient client selection framework blending combinational class sampling with data augmentation. On the client side, Grace first proposes a local model purification method, fortifying the model’s defenses by bolstering its innate robustness. After, local class representations are extracted for server-side client selection. This approach not only shields benign models from backdoor tampering but also allows the server to glean insights into local class representations without infringing upon the client’s privacy. On the server side, Grace introduces a novel representation combination sampling method. Clients are selected based on the interplay of their class representations, a strategy that simultaneously weeds out malicious actors and draws in clients whose data holds unique value. Our extensive experiments highlight Grace’s capabilities. The results are compelling: Grace enhances defense performance by over 50% compared to state-of-the-art (SOTA) backdoor defenses, and, in the best case, improves accuracy by 3.19% compared to SOTA client selection schemes. Consequently, Grace achieves substantial advancements in both security and accuracy. Xinghua Li 0001, Mengfan Xu, Shunjie Yuan, Mengyao Zhu 0004, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Combating Noisy Labels by Alleviating the Memorization of DNNs to Noisy LabelsabstractData is the essential fuel for deep neural networks (DNNs), and its quality affects the practical performance of DNNs. In real-world training scenarios, the successful generalization performance of DNNs is severely challenged by noisy samples with incorrect labels. To combat noisy samples in image classification, numerous methods based on sample selection and semi-supervised learning (SSL) have been developed, where sample selection is used to provide the supervision signal for SSL, achieving great success in resisting noisy samples. Due to the necessary warm-up training on noisy datasets and the basic sample selection mechanism, DNNs are still confronted with the challenge of memorizing noisy samples. However, existing methods do not address the memorization of noisy samples by DNNs explicitly, which hinders the generalization performance of DNNs. To alleviate this issue, we present a new approach to combat noisy samples. First, we propose a memorized noise detection method to detect noisy samples that DNNs have already memorized during the training process. Next, we design a noise-excluded sample selection method and a noise-alleviated MixMatch to alleviate the memorization of DNNs to noisy samples. Finally, we integrate our approach with the established method DivideMix, proposing Modified-DivideMix. The experimental results on CIFAR-10, CIFAR-100, and Clothing1M demonstrate the effectiveness of our approach. Shunjie Yuan, Xinghua Li 0001, Yinbin Miao, Ximeng Liu, Robert H. Deng |
IEEE Trans. Multim. | 1 |
| 2024 | PIC-BI: Practical and Intelligent Combinatorial Batch Identification for UAV assisted IoT NetworksabstractUnmanned Aerial Vehicle (UAV)-assisted IoT networks are receiving a lot of attention in academia and industry. For instance, a UAV can fly and hover over sensors, during which time the sensors simultaneously initiate batch access requests to the UAV. Typically, UAV employs batch authentication to efficiently handle these batch accesses. However, an attacker can initiate illegal requests, causing batch authentication to fail. There are various batch identification algorithms to find illegal requests, enabling legitimate sensors to establish service connections quickly. Existing work wants to choose a suitable one based on the specific attack scenario. However, existing work assumes that the percentage r% of illegal requests is known in advance, which is impractical in real-world scenarios. Besides, existing work only selects a suitable batch identification algorithm based on r%, limiting the performance of batch identification to the capabilities of the alternative algorithms. Drawing inspiration from the Kalman filter, we first propose an adaptive estimation algorithm for the number of illegal requests to address the above problems. Based on the estimated value e%, we design a combinatorial batch identification using reinforcement learning. This approach allows the combination of different algorithms to achieve superior performance. Extensive experiments demonstrate that, for the estimation algorithm, the relative error is less than 20% in 27 out of 40 experiments. Regarding the combinatorial algorithms, the delay can be reduced by approximately 7.15% to 30.86% compared to existing methods. Zhe Ren, Xinghua Li 0001, Yinbin Miao, Mengyao Zhu 0004, Shunjie Yuan, Robert H. Deng |
CCS | 5 |
| 2023 | Overlapping community detection on complex networks with Graph Convolutional Networks
Shunjie Yuan, Hefeng Zeng, Ziyang Zuo |
Comput. Commun. | 1 |
| 2022 | Community Detection based on Node Relationship Classification
Shunjie Yuan, Hefeng Zeng |
ICPRAM | 1 |