VLDB 2026 Research / reviewers in the wild / expert
Sen Zhang 0002
dblp:57/6221-2
· DBLP profile ↗
20ranked-venue papers
6as first author
18since 2021 · last 2026
0000-0003-3031-3721ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 9 · 4 first-author · 7 since 2021Security and privacy · 6 · 1 first-author · 6 since 2021Artificial intelligence and machine learning · 5 · 2 first-author · 4 since 2021Computer networks · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adversarial Signed Graph Learning with Differential PrivacyabstractSigned graphs with positive and negative edges can model complex relationships in social networks. Leveraging on balance theory that deduces edge signs from multi-hop node pairs, signed graph learning can generate node embeddings that preserve both structural and sign information. However, training on sensitive signed graphs raises significant privacy concerns, as model parameters may leak private link information. Existing methods with differential privacy (DP) typically rely on edge or gradient perturbation for protecting unsigned graphs. Yet, they are not well-suited for signed graphs: edge perturbation may trigger cascading errors in edge sign inference under balance theory, while gradient perturbation necessitates substantial noise injection due to increased gradient sensitivity arising from node interdependence and gradient polarity change caused by sign flips. In this paper, motivated by the robustness of adversarial learning to noisy interactions, we present ASGL, a privacy-preserving adversarial signed graph learning method that preserves high utility while achieving node-level DP. We first decompose signed graphs into positive and negative subgraphs based on edge signs, and then design a gradient-perturbed adversarial module to approximate the true signed connectivity distribution. In particular, the gradient perturbation helps mitigate cascading errors, while the subgraph separation facilitates sensitivity reduction. Further, we devise a constrained breadth-first search tree strategy that fuses with balance theory to identify the edge signs between generated node pairs. This strategy also enables gradient decoupling, thereby effectively lowering gradient sensitivity. Extensive experiments on real-world datasets show that ASGL achieves favorable privacy-utility trade-offs across multiple downstream tasks. Haobin Ke, Sen Zhang 0002, Qingqing Ye 0001, Xun Ran, Haibo Hu 0001 |
KDD (1) | 2 |
| 2026 | A Deep Dynamic Graph Generative Framework for Blockchain Phishing DetectionabstractBlockchain phishing scams cause billions in annual losses, yet extreme data imbalance severely hampers existing detection algorithms. Current dynamic graph generation methods fragment structures and generate erroneous connections, failing to capture local dynamic patterns vital for node classification. This raises critical questions: Can models minimize isolated subgraph generation? How can they learn and replicate structured, recurring interaction patterns? To answer these questions, we introduce GraphFlowGen, an end-to-end deep generative framework. To minimize isolated subgraph generation, GraphFlowGen employs a novel preprocessing module that jointly extracts structural and temporal contexts from transaction data, preventing fragmentation and information loss. To learn and replicate structured interaction patterns, it incorporates a Transformer encoder with Graph Attention Networks (GAT) to capture node connection dynamics and temporal evolution. To ensure high fidelity while reducing erroneous links, a reinforcement learning (RL) mechanism iteratively refines generated graph structures. Empirical validation on three real-world datasets demonstrates the effectiveness of our algorithm in local dynamic graph generation and its utility for downstream phishing detection tasks. Siyi Xiao, Lejun Zhang, Xinwei Zhang 0002, Sen Zhang 0002, Shen Su, Jing Qiu 0002, Haibo Hu 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | "Yes, My LoRD." Guiding Language Model Extraction with Locality Reinforced DistillationabstractZi Liang, Qingqing Ye, Yanyun Wang, Sen Zhang, Yaxin Xiao, RongHua Li, Jianliang Xu, Haibo Hu. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025. Zi Liang, Qingqing Ye 0001, Yanyun Wang 0003, Sen Zhang 0002, Yaxin Xiao, Ronghua Li 0002, Jianliang Xu, Haibo Hu 0001 |
ACL (1) | 4 |
| 2025 | PrivIM: Differentially Private Graph Neural Networks for Influence MaximizationabstractInfluence Maximization (IM), aiming to identify a small set of highly influential nodes in social networks, is a critical problem in graph analysis. Recently, Graph Neural Networks (GNNs) have demonstrated superior effectiveness in addressing IM. However, a trained GNN still raises significant privacy concerns, as it may expose sensitive node features and structural information. While Differential Privacy (DP) techniques have been widely applied to GNNs for node-level tasks, they cannot be directly extended to 1M problems. This is because IM requires more complex structural information for training, resulting in an extremely larger DP noise scale than node-level tasks. To tackle these issues, we propose PrivIM, a novel differentially private subgraph-based GNNs framework for IM tasks, which ensures node-level DP guarantees. Within PrivIM, we design a unique dual-stage adaptive frequency sampling scheme to optimize the model utility. First, it reduces the correlation between nodes by dynamically adjusting each node's sampling probability. Then additional subgraphs are incorporated to supplement boundary structural information, enhancing utility without increasing privacy budget. Extensive experiments on six real-world datasets demonstrate that PrivIM maintains high utility in IM compared to baseline methods. Renxuan Hou, Qingqing Ye 0001, Xun Ran, Sen Zhang 0002, Haibo Hu 0001 |
ICDE | 4 |
| 2025 | Structure-Preference Enabled Graph Embedding Generation Under Differential PrivacyabstractGraph embedding generation techniques aim to learn low-dimensional vectors for each node in a graph and have recently gained increasing research attention. Publishing low-dimensional node vectors enables various graph analysis tasks, such as structural equivalence and link prediction. Yet, improper publication opens a backdoor to malicious attackers, who can infer sensitive information of individuals from the low-dimensional node vectors. Existing methods tackle this issue by developing deep graph learning models with differential privacy (DP). However, they often suffer from large noise injections and cannot provide structural preferences consistent with mining objectives. Recently, skip-gram based graph embedding generation techniques are widely used due to their ability to extract customizable structures. Based on skip-gram, we present SE-PrivGEmb, a structure-preference enabled graph embedding generation under DP. For arbitrary structure preferences, we design a unified noise tolerance mechanism via perturbing non-zero vectors. This mechanism mitigates utility degradation caused by high sensitivity. By carefully designing negative sampling probabilities in skip-gram, we theoretically demonstrate that skip-gram can preserve arbitrary proximities, which quantify structural features in graphs. Extensive experiments show that our method outperforms existing state-of-the-art methods under structural equivalence and link prediction tasks. Sen Zhang 0002, Qingqing Ye 0001, Haibo Hu 0001 |
ICDE | 1 |
| 2025 | AdvSGM: Differentially Private Graph Learning via Adversarial Skip-Gram ModelabstractThe skip-gram model (SGM), which employs a neural network to generate node vectors, serves as the basis for numerous popular graph embedding techniques. However, since the training datasets contain sensitive linkage information, the parameters of a released SGM may encode private information and pose significant privacy risks. Differential privacy (DP) is a rigorous standard for protecting individual privacy in data analysis. Nevertheless, when applying differential privacy to skip-gram in graphs, it becomes highly challenging due to the complex link relationships, which potentially result in high sensitivity and necessitate substantial noise injection. To tackle this challenge, we present AdvSGM, a differentially private skip-gram for graphs via adversarial training. Our core idea is to leverage adversarial training to privatize skip-gram while improving its utility. Towards this end, we develop a novel adversarial training module by devising two optimizable noise terms that correspond to the parameters of a skip-gram. By fine-tuning the weights between modules within AdvSGM, we can achieve differentially private gradient updates without additional noise injection. Extensive experimental results on six real-world graph datasets show that AdvSGM preserves high data utility across different downstream tasks. Sen Zhang 0002, Qingqing Ye 0001, Haibo Hu 0001, Jianliang Xu |
ICDE | 1 |
| 2025 | PrivDPR: Synthetic Graph Publishing with Deep PageRank under Differential PrivacyabstractThe objective of privacy-preserving synthetic graph publishing is to safeguard individuals' privacy while retaining the utility of original data. Most existing methods focus on graph neural networks under differential privacy (DP), and yet two fundamental problems in generating synthetic graphs remain open. First, the current research often encounters high sensitivity due to the intricate relationships between nodes in a graph. Second, DP is usually achieved through advanced composition mechanisms that tend to converge prematurely when working with a small privacy budget. In this paper, inspired by the simplicity, effectiveness, and ease of analysis of PageRank, we design PrivDPR, a novel privacy-preserving deep PageRank for graph synthesis. In particular, we achieve DP by adding noise to the gradient for a specific weight during learning. Utilizing weight normalization as a bridge, we theoretically reveal that increasing the number of layers in PrivDPR can effectively mitigate the high sensitivity and privacy budget splitting. Through formal privacy analysis, we prove that the synthetic graph generated by PrivDPR satisfies node-level DP. Experiments on real-world graph datasets show that PrivDPR preserves high data utility across multiple graph structural properties. Sen Zhang 0002, Haibo Hu 0001, Qingqing Ye 0001, Jianliang Xu |
KDD (1) | 1 |
| 2025 | Toward Efficient Inference Attacks: Shadow Model Sharing via Mixture-of-ExpertsabstractMachine learning models are often vulnerable to inference attacks that expose sensitive information from their training data. Shadow model technique is commonly employed in such attacks, like membership inference. However, the need for a large number of shadow models leads to high computational costs, limiting their practical applicability. Such inefficiency mainly stems from the independent training and use of these shadow models. To address this issue, we present a novel shadow pool training framework SHAPOOL, which constructs multiple shared models and trains them jointly within a single process. In particular, we leverage the Mixture-of-Experts mechanism as the shadow pool to interconnect individual models, enabling them to share some sub-networks and thereby improving efficiency. To ensure the shared models closely resemble independent models and serve as effective substitutes, we introduce three novel modules: path-choice routing, pathway regularization, and pathway alignment. These modules guarantee random data allocation for pathway learning, promote diversity among shared models, and maintain consistency with target models. We evaluate SHAPOOL in the context of various membership inference attacks and show that it significantly reduces the computational cost of shadow model construction while maintaining comparable attack performance. Li Bai 0004, Qingqing Ye 0001, Xinwei Zhang 0002, Sen Zhang 0002, Zi Liang, Jianliang Xu, Haibo Hu 0001 |
NeurIPS | 4 |
| 2025 | Diffusion-Based Heterogeneous Graph Synthesis Under Local Differential PrivacyabstractMany real-world networks can be modeled as decentralized heterogeneous graphs with different types of nodes, each holds a piece of whole network and has its own privacy preference. Local differential privacy (LDP) has been widely used in decentralized graph synthesis to provide privacy guarantees. This paper shows that existing LDP-based graph synthesis approaches are insufficient for preserving topological properties and satisfying the different privacy requirements of heterogeneous nodes when generating synthetic decentralized graphs. To address these problems due to the clueless perturbation and ignorance of the topological properties of existing approaches, we introduce HeG-LDP, a novel privacy-preserving decentralized heterogeneous graph synthesis approach that achieves a considerable utility boost compared to other methods while satisfying the privacy requirements of different types of nodes. Concretely, we propose a heterogeneous graph information extraction approach that exploits the inherent topological nature of graphs to construct background knowledge from the partial nodes in a diffusion manner, which is then used to guide individuals in topological information extraction and perturbation. In addition, to further improve the quality of the generated graph, we propose a dK-series-based graph generation approach, which can optimize the connection probability of node pairs via a delicate combination of degree values and dK-series information, resulting in better maintenance of the topological utility. Comprehensive experiments and theoretical analysis show that our proposed HeG-LDP can yield high-quality synthetic heterogeneous graphs while satisfying edge-LDP. To promote research in this field, we make our source code and data publicly available athttps://github.com/HeG-LDP/Paper-codes. Lihe Hou, Weiwei Ni, Nan Fu, Dongyue Zhang, Ruyu Zhang, Sen Zhang 0002 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | ProVFL: Property Inference Attacks Against Vertical Federated LearningabstractRecent studies show that privacy leakages may occur in vertical federated learning (VFL), where parties hold split features of the same samples. While various attacks, including label and feature inference, focus on record-level privacy risks in VFL, few studies delve into the distribution-level privacy threat. In this paper, we explore property inference attacks (PIAs) in VFL, where an adversarial party seeks to deduce global distribution information about a target property in the victim party’s training set. Our key observation is that theLp-norm distribution of intermediate results in VFL could reflect the fraction of the target property in a training set. Inspired by this, we presentProVFL, a novel PIA framework involving distribution comparison and correlation augmentation modules. To achieve property inference, we design a distribution comparison module by creating various intermediate-result populations with different proportions, aiming to learn the relationship betweenLp-norm distributions and their fractions. Then, we theoretically analyze the factors that contribute to the attack effectiveness and develop a correlation augmentation module based on label replacement and model refinement to amplify property information leakage. Extensive experimental results demonstrate that our attacks can achieve inferences with low estimation errors as low as 1%. This poses the immediate threat of property information leakage from private training data in the VFL setting. Li Bai 0004, Xinwei Zhang 0002, Sen Zhang 0002, Qingqing Ye 0001, Haibo Hu 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Block-HRG: Block-based differentially private IoT networks release
Lihe Hou, Weiwei Ni, Sen Zhang 0002, Nan Fu, Dongyue Zhang |
Ad Hoc Networks | 3 |
| 2023 | GC-NLDP: A graph clustering algorithm with local differential privacy
Nan Fu, Weiwei Ni, Sen Zhang 0002, Lihe Hou, Dongyue Zhang |
Comput. Secur. | 3 |
| 2023 | Wdt-SCAN: Clustering decentralized social graphs with local differential privacy
Lihe Hou, Weiwei Ni, Sen Zhang 0002, Nan Fu, Dongyue Zhang |
Comput. Secur. | 3 |
| 2023 | Multidimensional grid-based clustering with local differential privacy
Nan Fu, Weiwei Ni, Haibo Hu 0001, Sen Zhang 0002 |
Inf. Sci. | 4 |
| 2023 | Community-Preserving Social Graph Release with Node Differential Privacy
Sen Zhang 0002, Weiwei Ni, Nan Fu |
J. Comput. Sci. Technol. | 1 |
| 2023 | PPDU: dynamic graph publication with local differential privacy
Lihe Hou, Weiwei Ni, Sen Zhang 0002, Nan Fu, Dongyue Zhang |
Knowl. Inf. Syst. | 3 |
| 2023 | WDP-GAN: Weighted Graph Generation With GAN Under Differential PrivacyabstractMany real-world networks can be represented as weighted graphs, where weights represent the closeness or importance of relationships between node pairs. Sharing these graphs is beneficial for many applications while potentially leading to privacy breaches. Variants of deep learning approaches have been developed for synthetic graph publishing, but privacy-preserving graph (especially weighted graph) publishing has not been fully addressed. To bridge this gap, we propose WDP-GAN, a generative adversarial network (GAN) based privacy-preserving weighted graph generation approach, which can generate unlimited synthetic graphs of a given weighted graph while ensuring individual privacy. To do this, we devise a new node sequence sampling method to generate the training set while preserving both the edge weight and topological structure of the original graph. Moreover, we apply the bi-directional long-short term memory (Bi-LSTM) network to capture the interdependence of node pairs. WDP-GAN then approximates the edge weight information using the frequencies of edges produced by the generator. Furthermore, we propose an adaptive gradient perturbation algorithm to improve the speed and stability of the training process while ensuring individual privacy. Theoretical analysis and experiments on real-world network datasets show that WDP-GAN can generate graphs that effectively preserve structural utility while satisfying differential privacy. Lihe Hou, Weiwei Ni, Sen Zhang 0002, Nan Fu, Dongyue Zhang |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2021 | Differentially private graph publishing with degree distribution preservation
Sen Zhang 0002, Weiwei Ni, Nan Fu |
Comput. Secur. | 1 |
| 2020 | Community Preserved Social Graph Publishing with Node Differential PrivacyabstractThe goal of privacy-preserving social graph publishing is to protect individual privacy while preserving data utility. Community structure, which is an important global pattern of nodes, is a crucial data utility as it serves as fundamental operations for many graph analysis tasks. Yet, most existing methods with differential privacy (DP) commonly fall in edge-DP to sacrifice security in exchange for utility. Moreover, they reconstruct graphs from the local feature-extraction of nodes, resulting in poor community preservation. Motivated by this, we propose PrivCom, a strict node-DP graph publishing algorithm to maximize the utility on the community structure while maintaining a higher level of privacy. Specifically, to reduce the huge sensitivity, we devise a Katz index-based private graph feature extraction method, which can capture global graph structure features while greatly reducing the global sensitivity via a sensitivity regulation strategy. Yet, with a fixed sensitivity, the feature captured by Katz index, which is presented in matrix form, requires privacy budget splits. As a result, plenty of noise is injected, thereby mitigating global structural utility. To this end, we design a private Oja algorithm approximating eigen-decomposition, which yields the noisy Katz matrix via privately estimating eigenvectors and eigenvalues from extracted low-dimensional vectors. Experimental results confirm our theoretical findings and the efficacy of PrivCom. Sen Zhang 0002, Weiwei Ni, Nan Fu |
ICDM | 1 |
| 2018 | Generalization Based Privacy-Preserving Provenance Publishing
Weiwei Ni, Sen Zhang 0002 |
WISA | 3 |