VLDB 2026 Research / reviewers in the wild / expert
Di Wu 0062
dblp:52/328-62
· DBLP profile ↗
11ranked-venue papers
2as first author
11since 2021 · last 2026
0000-0001-6979-3537ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author · 7 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Model Stability Defense Against Model Poisoning in Federated LearningabstractFederated Learning (FL) exhibits susceptible to model poisoning attacks, which compromise the availability of the collaboratively trained model by introducing detrimental local updates during the training process. The predominant line of defense against such attacks has been to impose stringent restrictions on clients' model updates. However, this strategy raises new vulnerabilities where the global model can be infiltrated by meticulously crafted malicious perturbations. This vulnerability arises due to the model's inherent sensitivity to perturbations, making it exposed and fragile. In response, this work investigates a novel defensive paradigm centered on model stability-specifically, a model's resilience against perturbations within its parameter space. As a solution, we introduce a new method named Model Stability Defense for Federated Learning (MSDFL), designed to fortify the defense of FL systems against model poisoning attacks. MSDFL utilizes a minmax optimization framework, which is fundamentally linked to empirical risk for exploring the effects of model perturbations. The core aim of our approach is to minimize the norm of the model-output Jacobian matrix without compromising predictive performance, thereby establishing defense through enhanced model stability. Moreover, we propose a refined version of MSDFL, named Holistic Model Stability Defense for Federated Learning (HMSDFL), which considers model stability across all output dimensions of the logits to effectively eradicate the disparity in model convergence speed induced by MSDFL. Extensive experimental results fully demonstrate the fidelity, robustness, compatibility, and self-protection of our methods. The source codes are maintained athttps://github.com/qqoneone/MSDFL. Di Wu 0062, Yong Qi 0001, Saiyu Qi, Qian Li 0024, Minghao Yao, Kaitai Liang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | Cross-Region Feature Reformer With Semantic Preservation for Adversarial Malware Detection
Qian Li 0024, Di Wu 0062, Chenhao Lin, Shuai Liu 0016, Cong Wang 0001, Chao Shen 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | AMA: Adaptive Model Poisoning Attacks Towards Federated LearningabstractFederated Learning (FL) is vulnerable to model poisoning attacks, where malicious updates (e.g., gradients) can adversely interfere with the global model. Existing attacks typically rely heavily on the updates of benign clients and aggregation algorithms to craft malicious updates. However, the benign updates and aggregation algorithms are usually hard to access for attackers, which makes their attacks weak and volatile. Therefore, in this work, we aim to design an adaptive model poisoning attack based on the agnostic adversary. Specifically, we propose a new concept from the perspective of adversarial learning, called adversarial model perturbation. This perturbation targets the parameters of the local model and aims to maximally mislead its predictions. Then, we develop a novel adaptive model poisoning attack namedAdversarial Model Attack (AMA), which utilizes the adversarial model perturbation as the malicious updates to attack the global model. Instead of the benign updates and aggregation algorithms, we only leverage the original data of the malicious client to adaptively craft the malicious updates. AMA resolves the conflict between the knowledge requirement of the adversary and the impact of model poisoning attacks. Empirical results against multiple robust FL methods show that AMA surpasses state-of-the-art attack methods and updates the benchmark of attack impact on Fedavg, Trimean, Multi-Krum, FoundationFL, RFA, and Median. Di Wu 0062, Yong Qi 0001, Saiyu Qi, Qian Li 0024 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Robust Adversarial Defenses in Federated Learning: Exploring the Impact of Data HeterogeneityabstractFederated Learning (FL) enables geographically distributed clients to collaboratively train machine learning models by exchanging local model parameters while preserving data privacy. In practice, FL faces two critical challenges. First, it is vulnerable to security issues as malicious clients would artificially harm the functionality of FL by launching poisoning attacks. Second, the inherent data heterogeneity among clients (termed Non-IID data in FL) naturally arises from distributed data ownership and significantly degrades model convergence and accuracy. However, with studies separately devoted to these two research lines, the interplay between data heterogeneity and security remains poorly understood. In this paper, we systematically investigate the relationship between data heterogeneity and adversarial robustness in FL. Specifically, we propose novel data partitioning algorithms that simulate Label-Conditional Non-IID and Feature-Conditional Non-IID with quantifiable heterogeneity levels. Further, we conduct extensive experiments to evaluate classical defense methods in the practical FL environment under state-of-the-art untargeted attacks. With results in various settings, we separately analyze the connection between Non-IID to defenses and attacks. Regarding attacks, with similar effects on models, Non-IID impacts the training in a different way compared with attacks. The interaction between attacks and Non-IID provides an opportunity to cause severe damage to FL. Regarding defenses, Non-IID induces heterogeneity in model distribution among clients which raises the difficulty of maintaining fidelity and robustness for defense methods. Qian Li 0024, Di Wu 0062, Dawei Zhou 0004, Chenhao Lin, Shuai Liu 0016, Cong Wang 0001, Chao Shen 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Dual Class-Aware Contrastive Federated Semi-Supervised LearningabstractFederated semi-supervised learning (FSSL), facilitates labeled clients and unlabeled clients jointly training a global model without sharing private data. Existing FSSL methods predominantly employ pseudo-labeling and consistency regularization to exploit the knowledge of unlabeled data, achieving notable success in raw data utilization. However, the effectiveness of these methods is challenged by large deviations between uploaded local models of labeled and unlabeled clients, as well as confirmation bias introduced by noisy pseudo-labels, both of which negatively affect the global model's performance. In this paper, we present a novel FSSL method called Dual Class-aware Contrastive Federated Semi-Supervised Learning (DCCFSSL). This method considers both the local class-aware distribution of each client's data and the global class-aware distribution of all clients’ data within the feature space. By implementing a dual class-aware contrastive module, DCCFSSL establishes a unified training objective for different clients to tackle large deviations and incorporates contrastive information in the feature space to mitigate confirmation bias. Additionally, DCCFSSL introduces an authentication-reweighted aggregation technique to improve the server's aggregation robustness. Our comprehensive experiments show that DCCFSSL outperforms current state-of-the-art methods on three benchmark datasets and surpasses the FedAvg with relabeled unlabeled clients on CIFAR-10, CIFAR-100, and STL-10 datasets. Di Wu 0062, Yong Qi 0001, Saiyu Qi |
IEEE Trans. Mob. Comput. | 2 |
| 2023 | EPPVChain: An Efficient Privacy-Preserving Verifiable Query Scheme for Blockchain DatabasesabstractBlockchain databases have been exploited in many applications to construct trust and share data among multiple participants. However, maintaining the entire blockchain locally will cause heavy communication and storage overhead for users with limited resources. Alternatively, the user could act as a light node that stores block headers only and delegates queries to full nodes that maintain the entire blockchain. However, introducing a light node raises several concerns about query integrity and privacy. In this paper, we propose EPPVChain, the first scheme that simultaneously achieves efficient, privacy-preserving and verifiable conjunctive query for blockchain databases. EPPVChain resorts to a novel symmetric cryptographic primitive named Symmetric Hidden Vector Encryption (SHVE), and deploys several new techniques to achieve the desired goals. In specific, we design a new SHVE-based authenticated data structure to support privacy-preserving verifiable conjunctive queries. We further propose two improved schemes to aggregate data records to optimize query performance. Finally, we propose a dual-chain key escrow protocol to securely escrow the symmetric key of SHVE without relying on any trusted third party. The security analysis and evaluation confirm EPPVChain’s ability to achieve query privacy and integrity with high efficiency. Jingxian Cheng, Saiyu Qi, Yong Qi 0001, Jianfeng Wang 0001, Di Wu 0062 |
TrustCom | 6 |
| 2023 | FedMCSA: Personalized federated learning via model components self-attention
Yong Qi 0001, Saiyu Qi, Di Wu 0062, Qian Li 0024 |
Neurocomputing | 4 |
| 2023 | Understanding and defending against White-box membership inference attack in deep learning
Di Wu 0062, Saiyu Qi, Yong Qi 0001, Qian Li 0024, Bowen Cai 0004, Jingxian Cheng |
Knowl. Based Syst. | 1 |
| 2023 | Revisiting Gradient Regularization: Inject Robust Saliency-Aware Weight Bias for Adversarial DefenseabstractDespite regularizing the Jacobians of neural networks to enhance model robustness has directly theoretical correlation with model prediction stability, a large defense performance gap exists when compared to the empirically perturbation-based adversarial training e.g. PGD-based, which enjoys nice discriminative saliency maps as well. To mitigate this issue, in this paper we first analyze the dilemma that the gradient map of its resulting model has no content hierarchy to mark out salient profile of input, as a negative signal of the obstructive for effective adversarial defense. Based on this, we argue that incorporating robust gradient-based saliency properties into regularized training may be helpful to reduce the performance gap. Specifically, we propose a simple method called Saliency-aware Gradient Regularization (SAGR), where a biased weight distribution strategy is introduced on positive gradient to structure and increase the impact of class-gradient components inside the Jacobian of model. The strategy maintains the dominant role of saliency-critical true-class gradient in learning process and differentiates diverse importance of gradient sensitivities that would localize input salient areas. Herein we interpret the sharpness of true-class sensitivity as robust recognition of more learning-relevant features e.g., regions containing dominant object in image for classification. Instead, false-class parts are considered as recognition-irrelevant nuisance factors e.g. the backgrounds, which are thus depressed with more strength. Experimental results demonstrate the efficacy of the proposed method and validate that distinguishment of sensitivities could further yield more robustness gain and sharper gradient saliency map. Qian Li 0024, Chenhao Lin, Di Wu 0062, Chao Shen 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | FLMJR: Improving Robustness of Federated Learning via Model Stability
Di Wu 0062, Yong Qi 0001, Saiyu Qi, Qian Li 0024 |
ESORICS (3) | 2 |
| 2022 | Stochastic Ghost Batch for Self-distillation with Dynamic Soft Label
Qian Li 0024, Saiyu Qi, Yong Qi 0001, Di Wu 0062, Yun Lin 0001, Jin Song Dong 0001 |
Knowl. Based Syst. | 5 |