Xuanang Yang

dblp:353/9646 · DBLP profile ↗
← Back
4ranked-venue papers
3as first author
4since 2021 · last 2025
0000-0003-0883-6278ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Efficient Single-Server Private Inference Outsourcing for Convolutional Neural Networks
abstract
Private inference outsourcing ensures the privacy of both clients and model owners when model owners deliver inference services to clients through third-party cloud servers. Existing solutions either reduce inference accuracy due to model approximations or rely on the unrealistic assumption of non-colluding servers. Moreover, their efficiency falls short of HELiKs, a solution focused solely on client privacy protection. In this paper, we propose Skybolt, a single-server private inference outsourcing framework without resorting to model approximations, achieving greater efficiency than HELiKs. Skybolt is built upon efficient secure two-party computation protocols that safeguard the privacy of both clients and model owners. For the linear calculation protocol, we devise a ciphertext packing algorithm for homomorphic matrix multiplication, effectively reducing both computational and communication overheads. Additionally, our nonlinear calculation protocol features a lightweight online phase, involving only the addition and multiplication on secret shares. This stands in contrast to existing protocols, which entail resource-intensive techniques such as oblivious transfer. Extensive experiments on popular models, including ResNet50 and DenseNet121, show that Skybolt achieves a 5.4 − 7.3× reduction in inference latency, accompanied by a 20.1 − 39.6× decrease in communication cost compared to HELiKs.
Xuanang Yang, Jing Chen 0003, Yuqing Li 0001, Kun He 0008, Zikuan Jiang, Ruiying Du
IEEE Trans. Circuits Syst. Video Technol.1
2025 GetFed: Accurate, Differentially Private Federated Learning With GAN-Based Data Generation
abstract
Federated Learning (FL) aims to train neural network models using distributed data resources from multiple clients without sharing raw data. One of the key challenges in FL is non-independent and identically distributed (non-IID) data, which may affect model accuracy. To address this issue, some schemes leverage Generative Adversarial Networks (GANs) to generate virtual data and combine it with the real data to achieve a balanced data distribution. However, there are risks of privacy leakage from the collected virtual data and aggregated gradients. In this paper, we propose GetFed, an accurate and differentially private FL framework with GAN-based Data Generation on non-IID Data. We integrate Differential Privacy (DP) into the GAN training and federated aggregation phases to prevent clients’ privacy leakage. To balance privacy and accuracy, we first design a privacy-preserving virtual sample generation algorithm for GAN training that dynamically reduces unnecessary noise as the quality of virtual samples improves. Additionally, we design an adaptive DP-based secure aggregation algorithm that decreases the added noise as the model approaches convergence. Furthermore, we implement a real-virtual ensemble training algorithm, employing an ensemble learning strategy to better mix virtual and real samples for enhanced global model accuracy. This approach ensures clients benefit from both the authenticity of real samples and the balanced data distribution provided by virtual samples, effectively mitigating the data heterogeneity inherent in non-IID scenarios. Extensive experiments demonstrate that compared with state-of-the-art schemes, GetFedimproves model accuracy by 6–47% and reduces training time by 50%.
Kun He 0008, Yuqing Li 0001, Jing Chen 0003, Zhongmou Liu, Xuanang Yang, Ruiying Du
IEEE Trans. Dependable Secur. Comput.7
2024 Fregata: Fast Private Inference With Unified Secure Two-Party Protocols
abstract
Private Inference (PI) safeguards client and server privacy when the client utilizes the server’s model to make predictions. Existing PI solutions for Convolutional Neural Networks (CNNs) employ distinct cryptographic primitives to customize secure two-party protocols for linear and non-linear layers. This requires data to be converted into a specific form to switch between protocols, thus leading to a significant increase in inference latency. In this paper, we present Fregata, a fast PI scheme for CNNs by leveraging identical cryptographic primitives to calculate both linear and nonlinear layers. Specifically, our protocols utilize homomorphic encryption to obtain additive secret shares of matrix products during the offline phase, followed by lightweight multiplication and addition operations on these shares in the latency-sensitive online phase. Benefiting from uniformity, we accelerate inference from a holistic perspective by decoupling certain procedures of our protocols and executing them asynchronously. Moreover, to improve the efficiency of the offline phase, we elaborate a homomorphic matrix multiplication calculation method with reduced computation and communication complexity compared to existing approaches. Furthermore, we minimize inference latency by employing graphics processing units to parallelize the operations on the shares during the online phase. Experimental evaluations on popular CNN models such as SqueezeNet, ResNet, and DenseNet demonstrate that Fregata reduces 35-45 times inference latency over the state-of-the-art counterparts, accompanied by a 1.6-2.8 times decrease in communication overhead. In terms of total runtime, Fregata maintains a reduction of approximately 3 times.
Xuanang Yang, Jing Chen 0003, Yuqing Li 0001, Kun He 0008, Zikuan Jiang, Ruiying Du
IEEE Trans. Inf. Forensics Secur.1
2023 Efficient Privacy-Preserving Inference Outsourcing for Convolutional Neural Networks
abstract
Inference outsourcing enables model owners to deploy their machine learning models on cloud servers to serve users. In this paradigm, the privacy of model owners and users should be considered. Existing solutions focus on Convolutional Neural Networks (CNNs) but their efficiency is much lower than GALA, which is a solution that only protects user privacy. Furthermore, these solutions adopt approximations that reduce the model accuracy and thus require model owners to retrain the models. In this paper, we present an efficient CNN inference outsourcing solution that protects the privacy of both model owners and users. Specifically, we design secure two-party computation protocols based on two non-colluding cloud servers, which calculate with additive secret shares of the model and the user’s input. Our protocols avoid the expensive permutation operations in linear calculations and approximations in non-linear calculations. We implement our solution on realistic CNNs and experimental results show that our solution is even 2–4 times faster than GALA.
Xuanang Yang, Jing Chen 0003, Kun He 0008, Cong Wu 0003, Ruiying Du
IEEE Trans. Inf. Forensics Secur.1