VLDB 2026 Research / reviewers in the wild / expert
Hui Zhou 0014
dblp:55/1832-14
· DBLP profile ↗
8ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0002-2589-4384ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
1 paper |
Trustworthy machine learning · 93% Deep learning architectures and training · 7% | |
| Databases, data mining, and information retrieval
2 papers |
Graph data management · 67% Data mining · 33% |
Topics — the 12 heaviest of 13, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Trustworthy machine learning › robustness
adversarial examples |
1.0 | 1 | 2026 | Boosting Adversarial Transferability via Ensemble Non-Attention · AAAI 2026 |
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
1.0 | 1 | 2026 | Boosting Adversarial Transferability via Ensemble Non-Attention · AAAI 2026 |
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial transferability |
1.0 | 1 | 2026 | Boosting Adversarial Transferability via Ensemble Non-Attention · AAAI 2026 |
Machine learning › Trustworthy machine learning › robustness › adversarial attack
ensemble attack |
1.0 | 1 | 2026 | Boosting Adversarial Transferability via Ensemble Non-Attention · AAAI 2026 |
Data mining › pattern mining › matrix pattern mining
biclique mining |
0.9 | 1 | 2025 | TopK-BC: Efficient Maintenance of Top k (p,q)-bicliques over Streaming Bipartite Graphs · ICDE 2025 |
Graph data management
cohesive subgraph mining |
0.9 | 1 | 2025 | Efficient Indexing for Label-Constrained Cohesive Subgraph Queries Over Large Graphs · ICDE 2025 |
Graph data management › cohesive subgraph mining
k-core query |
0.9 | 1 | 2025 | Efficient Indexing for Label-Constrained Cohesive Subgraph Queries Over Large Graphs · ICDE 2025 |
Graph data management › graph processing
streaming graph processing |
0.9 | 1 | 2025 | TopK-BC: Efficient Maintenance of Top k (p,q)-bicliques over Streaming Bipartite Graphs · ICDE 2025 |
Machine learning › Deep learning architectures and training › transformer
vision transformer |
0.3 | 1 | 2026 | Boosting Adversarial Transferability via Ensemble Non-Attention · AAAI 2026 |
Data mining › structured data mining › graph mining
dense subgraph mining |
0.3 | 1 | 2025 | TopK-BC: Efficient Maintenance of Top k (p,q)-bicliques over Streaming Bipartite Graphs · ICDE 2025 |
Graph data management
graph indexing |
0.3 | 1 | 2025 | Efficient Indexing for Label-Constrained Cohesive Subgraph Queries Over Large Graphs · ICDE 2025 |
Data mining
pattern mining |
0.3 | 1 | 2025 | TopK-BC: Efficient Maintenance of Top k (p,q)-bicliques over Streaming Bipartite Graphs · ICDE 2025 |
Methods — techniques the papers use, named apart from their topics
meta-learning · 1.0gradient ensemble · 1.0attention decoupling · 1.0pruning strategies · 0.9density-based filtering · 0.9core decomposition · 0.9canonical label sets · 0.9
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Boosting Adversarial Transferability via Ensemble Non-AttentionabstractEnsemble attacks integrate the outputs of surrogate models with diverse architectures, which can be combined with various gradient-based attacks to improve adversarial transferability. However, previous work shows unsatisfactory attack performance when transferring across heterogeneous model architectures. The main reason is that the gradient update directions of heterogeneous surrogate models differ widely, making it hard to reduce the gradient variance of ensemble models while making the best of individual model. To tackle this challenge, we design a novel ensemble attack, NAMEA, which for the first time integrates the gradients from the non-attention areas of ensemble models into the iterative gradient optimization process. Our design is inspired by the observation that the attention areas of heterogeneous models vary sharply, thus the non-attention areas of ViTs are likely to be the focus of CNNs and vice versa. Therefore, we merge the gradients respectively from the attention and non-attention areas of ensemble models so as to fuse the transfer information of CNNs and ViTs. Specifically, we pioneer a new way of decoupling the gradients of non-attention areas from those of attention areas, while merging gradients by meta-learning. Empirical evaluations on ImageNet dataset indicate that NAMEA outperforms AdaEA and SMER, the state-of-the-art ensemble attacks by an average of 15.0% and 9.6%, respectively. This work is the first attempt to explore the power of ensemble non-attention in boosting cross-architecture transferability, providing new insights into launching ensemble attacks. Yipeng Zou, Qin Liu 0001, Jie Wu 0001, Yu Peng 0003, Guo Chen 0001, Hui Zhou 0014, Guanghui Ye |
AAAI | 6 |
| 2026 | Unifying Gradient Leakage Attacks Against Privacy-Protected Federated Learning in IoT NetworksabstractFederated learning (FL) is a transformative paradigm for the Internet of Things (IoT), enabling decentralized model training across distributed IoT devices while reducing reliance on centralized data collection. Crucially, FL cuts communication overhead, an essential benefit in bandwidth-limited IoT environments. However, repeated gradient exchanges between edge clients (e.g., sensors, mobile devices) and the central server expose vulnerabilities to gradient leakage attacks (GLAs), allowing adversaries to reconstruct private training data from shared gradients. While various gradient protection strategies, such as differential privacy, sparsification, and clipping, have been introduced to mitigate this risk, most existing GLAs are designed for specific protection schemes and fail under heterogeneous deployments. In this work, we propose a unified GLA framework that targets diverse gradient protection techniques in FL systems. Our approach tackles two core challenges: (i) aligning protected gradients with their raw counterparts to enable robust feature extraction, and (ii) identifying critical features for efficient and accurate data reconstruction.We introduce a Taylor-based gradient approximation method for alignment and design a feature reconstructor that enhances both performance and computational efficiency. Extensive experiments across various FL scenarios demonstrate the framework’s superior reconstruction capability under different protection schemes, emphasizing the need for robust privacy-preserving mechanisms in IoT networks. Hui Zhou 0014, Zheng Qin 0001, Peng Sun 0003, Yipeng Zou, Xiaoshuai Wu |
IEEE Internet Things J. | 1 |
| 2026 | Thwarting gradient inversion in federated learning via generative shadow mapping defense
Hui Zhou 0014, Yuling Chen 0002, Zheng Qin 0001, Ziyu Peng |
J. Syst. Archit. | 1 |
| 2025 | Efficient Indexing for Label-Constrained Cohesive Subgraph Queries Over Large GraphsabstractMany real-world relationships can be effectively represented as edge-labeled graphs, where edge labels encode semantic information vital for graph computations. Analyzing communities within such graphs is of great importance, with cohesive subgraph queries being a fundamental problem in graph analysis. Among these, the k-core model is one of the most widely studied frameworks for cohesive subgraph queries and has attracted significant attention over the past decade. However, most existing k-core models disregard edge labels, limiting their applicability to semantic-aware analyses. In this paper, we propose an index-based method to address the problem of querying k-cores with label constraints in edge-labeled graphs. We first introduce a basic index that maintains core decomposition results for each possible label set. Then, to further optimize performance, we propose an advanced index structure that captures the label containment properties of k- cores by computing canonical label sets for each possible$k$and each vertex. This approach can greatly reduce the index size while ensuring efficient query processing. We also design an optimized algorithm for constructing our index, achieving a significantly faster runtime than naive construction methods. Extensive experiments on real graphs demonstrate the efficiency and effectiveness of our index-based algorithms. Peng Peng 0008, Chuanyu Liu, Xianyan Xie, Hui Zhou 0014, Zheng Qin 0001 |
ICDE | 5 |
| 2025 | TopK-BC: Efficient Maintenance of Top k (p,q)-bicliques over Streaming Bipartite GraphsabstractBipartite graphs are ubiquitous, such as E-commerce network and gene networks. Efficient analysis of (p, q)- biclique is one of the important problems over bipartite graphs. However, existing works over (p, q)-biclique suffer from two main challenges. Firstly, most of them only focus on static graphs, while lots of bipartite graph-structured data are constantly created in real world, forming streaming bipartite graphs. Secondly, results of (p, q)-biclique could be of exponential scale, which may overwhelm analysts. Hence, computing top$k$most important (p, q)-bicliques is worth considering. In this paper, we study a new problem to maintain top$k$densest (p, q)-bicliques over a streaming bipartite graph. We propose a new framework, called as TopK-BC, to compute the proposed problem effectively. We design an efficient pruning strategy for edge deletion stage, called IDpruning. In particular, we maintain an intermediate density for each edge to efficiently compute high-density (p, q)-bicliques. Also, we introduce effective optimization technologies to filter out unpromising intermediate results and further enhance the performance. Extensive experiments over real world datasets confirm the efficiency and effectiveness of our solution. Zheng Qin 0001, Peng Peng 0008, Hui Zhou 0014 |
ICDE | 4 |
| 2025 | Do Adversarial Perturbations Truly Mitigate Gradient Inversion in Federated Learning?abstractFederated Learning (FL) has emerged as a privacy-preserving framework under which multiple participants jointly solve the a collaborative training and user privacy problem. Recent studies find that private training data can still be leaked by the exchanged gradients based on optimization or analytic, i.e., gradient inversion attacks (GIAs). To enhance privacy, adversarial perturbations (AP) are attempted to be applied in FL by introducing carefully crafted noise into the local gradients. However, the effectiveness of adversarial perturbations in strengthening privacy against GIAs remains underexplored. In this work, we empirically evaluate adversarial perturbations on the resistance of GIAs. We show that even adversarial perturbations added to the gradients can still leak training data. We propose an adversarial perturbation gradient inversion attack, APT. Specifically, we design a feature extraction method to extract data features from adversarial perturbation gradients by utilizing the linear layer. Moreover, we design a feature reconstruction method to reconstruct data by a key feature reconstructor. Extensive experiments demonstrate that our method achieves high-quality gradient inversion from adversarial perturbation gradients, surpassing state-of-the-art methods that commonly fail in more challenge scenarios. Overall, our work explores the defense effectiveness as well as reveals the vulnerability of AP under GIAs. We hope this work provide valuable insights into leveraging adversarial perturbations for privacy defense and inspire future research on robust privacy-preserving mechanisms in FL. Hui Zhou 0014, Zheng Qin 0001, Yipeng Zou, Ge Xiao, Hao Chen 0051 |
IJCNN | 1 |
| 2025 | LDInfer: Landmarks Inference-Based for Facial Forgery Detection of Different QualityabstractThe harm caused by deepfakes is becoming increasingly serious, including financial fraud, guiding political public opinion, and more. The vast majority of deepfake detection methods typically perform well on uncompressed deepfake videos, achieving satisfactory results. However, when facing deepfake videos with different compression rates, the effectiveness of certain detection methods will significantly decrease, and they may even be unable to detect compressed videos. To address this challenge, we introduce a new detection mechanism: landmarks inference mechanism. Based on this, we propose a simple and efficient model LDInfer for inferring landmarks to achieve deepfake video detection. Our method utilizes the inference between facial landmarks and their preceding and succeeding frames to improve detection accuracy, which remains effective even in compressed deepfake videos. This method first infers landmarks and verifies their authenticity using the correlation between landmarks in the previous and subsequent frames. Even if the video is compressed, the correlation between facial landmarks in the preceding and following frames remains high. Comparative experiments show that our method outperforms existing methods at various compression rates. Hui Zhou 0014, Tianshuo Jiao, Bohan Tan, Zhuo Zhang 0028, Hao Chen 0051, Zheng Qin 0001 |
TrustCom | 3 |
| 2023 | Multifactor Incentive Mechanism for Federated Learning in IoT: A Stackelberg Game ApproachabstractIn the era of the Internet of Things (IoT), remote sensors and endpoint appliances generate vast amounts of data. Decentralized and collaborative learning builds on these IoT data to enable classification and recognition tasks by inviting multiple data owners. Federated learning (FL), as a popular collaborative learning framework, can significantly improve the performance of models without collecting the original data. To invite data owners to participate in FL, various incentive mechanisms are designed to address this issue by researchers. However, existing solutions still face high costs and low utility due to information asymmetry, where the reputation, computation power, and data quantity of the data owners are not known in advance. Therefore, we propose a Stackelberg game-based multifactor incentive mechanism for FL (SGMFIFL). First, we design the Top-$K$cost selection algorithm based on reverse auction, which can reduce the cost of selecting data owners. Next, we devise a multifactor reward function based on reputation, accuracy, and reward rate, the data owners with high reputation and high accuracy will be of more reward. In particular, to ensure that SGMFIFL can provide reliable incentives in IoT, we use blockchain to provide a secure and trusted environment. Finally, we construct a two-stage Stackelberg game model for the task publisher and the data owners and derive an optimal Equilibrium solution for both stages of the whole game. Experiments conducted on two well-known data sets, MNIST and CIFAR10, demonstrate the significant performance of the proposed mechanism. Yuling Chen 0002, Hui Zhou 0014, Tao Li 0043, Jin Li 0002, Huiyu Zhou 0001 |
IEEE Internet Things J. | 2 |