VLDB 2026 Research / reviewers in the wild / expert
Fengrui Hao
dblp:372/8908
· DBLP profile ↗
15ranked-venue papers
5as first author
15since 2021 · last 2026
0000-0002-5951-3789ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 3 first-author · 5 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FairGSE: Fairness-Aware Graph Neural Network Without High False Positive RatesabstractGraph neural networks (GNNs) have emerged as the mainstream paradigm for graph representation learning due to their effective message aggregation. However, this advantage also amplifies biases inherent in graph topology, raising fairness concerns. Existing fairness-aware GNNs provide satisfactory performance on fairness metrics such as Statistical Parity and Equal Opportunity while maintaining acceptable accuracy trade-offs. Unfortunately, we observe that this pursuit of fairness metrics neglects the GNN's ability to predict negative labels, which renders their predications with extremely high False Positive Rates (FPRs), resulting in negative effects in high-risk scenarios. To this end, we advocate that classification performance should be carefully calibrated while improving fairness, rather than simply constraining accuracy loss. Furthermore, we propose Fair GNN via Structural Entropy (FairGSE), a novel framework that maximizes two-dimensional structural entropy (2D-SE) to improve fairness without neglecting false positives. Experiments on several real-world datasets show FairGSE reduces FPR by 39% vs. state-of-the-art fairness-aware GNNs, with comparable fairness improvement. Zhenqiang Ye, Jinjie Lu, Tianlong Gu, Fengrui Hao, Xuemin Wang 0003 |
AAAI | 4 |
| 2026 | Style-Based Bias Backdoor Attacks on Medical LLMs Under In-Context Learning
Shijie Xiao, Fengrui Hao, Tianlong Gu |
ICIC (23) | 4 |
| 2026 | Fairness-aware differentially private model training without sensitive attributes for face recognition
Fengrui Hao, Yuzhao Chen, Tianlong Gu, Xuemin Wang 0003 |
Pattern Recognit. | 1 |
| 2026 | Stealthy backdoor attack method targeting group fairness in self-supervised learning
Fengrui Hao, Tianlong Gu, Jionghui Jiang, Liang Chang 0003, Chenzhong Bin |
Pattern Recognit. | 1 |
| 2026 | On the correlations between geometric metrics and fairness in pruning CNN
Xiyan Xu, Jinjie Lu, Tianlong Gu, Fengrui Hao |
Pattern Recognit. | 5 |
| 2026 | DMPA: Durable Model Poisoning Attack Against Fairness and Robustness in Efficient Federated Learning SystemsabstractFederated Learning (FL) systems are increasingly deployed across multiple clients to efficiently train a shared model over local data, thereby effectively addressing data silos and reducing communication. However, FL systems are known to be susceptible to model poisoning attacks by malicious clients, who aim at deteriorating the global model accuracy through sending corrupted updates to the central server. Meanwhile, the local accuracy discrepancy among clients, called as performance fairness, could also be exacerbated, which is one of the major concerns of trustworthy FL systems. This paper proposes a novel attack framework called Durable Model Poisoning Attack (DMPA), targeting both fairness and robustness of efficient FL systems. To implement DMPA, we design the over-unlearning strategy, enabling the adversary to generate poisoned updates to compromise partial clients' performance. Furthermore, we develop a dual projection mechanism to improve the durability of model poisoning attacks. Extensive experiments demonstrate that DMPA is powerful and effective even against robust aggregation rules. Particularly, DMPA achieves average$7.6\times$higher reduction of accuracy while decreasing the performance fairness by$3.0\times$compared with baselines. The experiments also indicated that DMPA extends the durability of attack impacts over baselines by$8.5\times$. In addition, experiments in efficient FL systems disclose their vulnerability. Jionghui Jiang, Fengrui Hao, Tianlong Gu, Ke Wang 0068, Zhangbin Wen |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | FairDP-GNN: Graph Neural Network with Group Fairness and Differential Privacy
Fengrui Hao, Shiyi Zhao, Tianlong Gu, Xuemin Wang 0003, Yuanfeng Liu |
DASFAA (1) | 1 |
| 2025 | BID-Net: Balanced Incremental Distillation Network for Fair Dermatological Disease DiagnosisabstractGiven the increasing prevalence of deep learning applications in dermatological disease diagnosis, the pursuit of diagnostic accuracy needs to be accompanied by a focus on decision-making fairness to avoid unfair discrimination against under-represented demographic groups. This requires a tradeoff between diagnostic accuracy and fairness. To this end, we propose a balanced incremental distillation network (BID-Net) to tackle this problem, which balances the learning of different groups by being sensitive to changes in the data distribution. Specifically, aided by balanced memory, representative demographic groups are designed to assist underrepresented groups in learning knowledge, which is incrementally trained by integrating the distributions of different groups. In addition, our BID-Net incorporates knowledge distillation and distributional disparity to alleviate the catastrophic forgetting and enhance fairness. Experiments on two skin datasets demonstrate that our proposed network outperforms other methods in terms of fairness criteria and the trade-off between fairness and performance. Yiqin Luo, Tianlong Gu, Fengrui Hao, Liang Chang 0003 |
ICASSP | 3 |
| 2025 | Durability-Optimized Model Poisoning Attack Against Federated Learning Systems
Jionghui Jiang, Fengrui Hao, Tianlong Gu, Jinjie Lu |
ICIC (4) | 2 |
| 2025 | dK-DGDP: A differential privacy approach on directed social network graphs
Fengrui Hao, Shiyi Zhao, Tianlong Gu |
Comput. Secur. | 1 |
| 2025 | Toward customized model discrepancies in personalized federated learning on non-IID data
Fengrui Hao, Taihang Zhi, Tianlong Gu, Xuguang Bao |
Knowl. Based Syst. | 1 |
| 2025 | FBA: Fairness Backdoor Attack on Graph Neural NetworksabstractGraph neural networks (GNNs) are a set of methods that aim to apply deep neural networks to graph-structured data. Despite their promising performance on various graph analysis tasks, they might have discrimination towards certain populations when exploited in human-centered applications without fairness considerations. Moreover, extant studies have shown that GNNs are vulnerable to backdoor attacks, through which malicious users can degrade the predication performance of GNNs. Nevertheless, attacks to the fairness of GNNs are still unexplored. In this paper, we analyze the limitations of existing GNNs backdoor attacks, and propose a novel fairness backdoor attack (FBA) method for GNNs. Firstly, we provide the candidate space selection mechanism to select the fair node candidate space using the long-tail distribution, which facilitates the subsequent generation of triggers. Secondly, we develop the trigger generation strategy to generate fairness triggers by quantifying the deviations between different groups of sensitive attributes, enabling the attack to degrade the fairness almost without affecting the accuracy. Finally, we undertake extensive evaluation experiments on real datasets and state-of-the-art models to demonstrate the effectiveness of the FBA method, including five mainstream models (GCN, GraphSAGE, GAT, GAE, and VGAE), three downstream tasks (node classification, graph classification and link prediction), and two fair GNNs (NIFTY and Fairedit). Fengrui Hao, Tianlong Gu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | GCPA: GAN-Based Collusive Poisoning Attack in Federated Recommender SystemsabstractFederated Recommender Systems (FedRecs) have evolved as a privacy-preserving paradigm that facilitates distributed training of personalized recommenders without sharing user data. However, FedRecs are known to be susceptible to poisoning attacks by malicious users, who aim at promoting or demoting the exposure of target items through sending malicious updates to the central server. Meanwhile, the distribution of recommendation performance among users, called as performance fairness, could be exacerbated, which is one of the major concerns of trustworthy FedRecs. This paper proposes a novel attack method, Generative Adversarial Network (GAN)-Based Collusive Poisoning Attack (GCPA). To implement GCPA, we create a GAN-based fake user synthesis strategy that mimics behaviors and preferences of real users to generate fake users. Furthermore, we design a collusion-based fairness attack strategy that changes the exposure of items to undermine fairness. To maximize the impact on the distribution of recommendation performance, we develop an adaptive clustering algorithm to identify a subset of items that significantly contribute to the uneven distribution of recommendation performance through collusion. Extensive experiments on two datasets show that GCPA effectively increase the exposure of target items while undermining the performance fairness of FedRecs. In addition, GCPA also has strong resistance to four defense methods. Meanwhile, we provide a heuristic defense method based on gradient direction and similarity against collusive poisoning attack on FedRecs. Tianlong Gu, Shouhong Tan, Fengrui Hao, Liang Chang 0003, Yuanfeng Liu |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2024 | Collusive Model Poisoning Attack in Decentralized Federated LearningabstractAs a privacy-preserving machine learning paradigm, federated learning (FL) has attracted widespread attention from both academia and industry. Decentralized FL (DFL) overcomes the problems of untrusted aggregation server, single point of failure and poor scalability in traditional FL, making it suitable for industrial Internet of Things (IIoT). However, DFL provides more convenient conditions for malicious participants to launch attacks. This article focuses on the model poisoning attack in DFL for the first time, and proposes a novel attack method called collusive model poisoning attack (CMPA). To implement CMPA, we propose the dynamic adaptive construction mechanism, in which malicious participants can dynamically and adaptively construct malicious local models that meet distance constraints, reducing the convergence speed and accuracy of consensus models. Furthermore, we design the collusion-based attack enhancement strategies, where multiple participants can collude in the process of constructing malicious local models to improve the strength of attack. Empirical experiments conducted on MNIST and CIFAR-10 datasets reveal that CMPA significantly impacts the training process and results of DFL. Attack tests against representative defense methods show that CMPA not only invalidates statistical-based defenses but also skillfully overcomes performance-based methods, further proving its effectiveness and stealthiness. In addition, experiments based on practical IIoT scenario have also shown that CMPA can effectively disrupt system functionality. Shouhong Tan, Fengrui Hao, Tianlong Gu, Long Li 0005 |
IEEE Trans. Ind. Informatics | 2 |
| 2024 | CBAs: Character-level Backdoor Attacks against Chinese Pre-trained Language ModelsabstractPre-trained language models (PLMs) aim to assist computers in various domains to provide natural and efficient language interaction and text processing capabilities. However, recent studies have shown that PLMs are highly vulnerable to malicious backdoor attacks, where triggers could be injected into the models to guide them to exhibit the expected behavior of the attackers. Unfortunately, existing research on backdoor attacks has mainly focused on English PLMs and paid less attention to Chinese PLMs. Moreover, these extant backdoor attacks do not work well against Chinese PLMs. In this article, we disclose the limitations of English backdoor attacks against Chinese PLMs, and propose the character-level backdoor attacks (CBAs) against the Chinese PLMs. Specifically, we first design three Chinese trigger generation strategies to ensure that the backdoor is effectively triggered while improving the effectiveness of the backdoor attacks. Then, based on the attacker’s capabilities of accessing the training dataset, we develop trigger injection mechanisms with either the target label similarity or the masked language model, which select the most influential position and insert the trigger to maximize the stealth of backdoor attacks. Extensive experiments on three major natural language processing tasks in various Chinese PLMs and English PLMs demonstrate the effectiveness and stealthiness of our method. In addition, CBAs have very strong resistance against three state-of-the-art backdoor defense methods. 1 Fengrui Hao, Tianlong Gu, Liang Chang 0003 |
ACM Trans. Priv. Secur. | 2 |