Rui Zhang 0118

dblp:60/2536-118 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0001-7885-5103ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 2 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Toward Federated Learning of Deep Graph Neural Networks
Zhihua Tian, Rui Zhang 0118, Jian Liu 0012, Kui Ren 0001
IEEE Trans. Knowl. Data Eng.3
2025 Espresso: Robust Concept Filtering in Text-to-Image Models
abstract
Diffusion based text-to-image models are trained on large datasets scraped from the Internet, potentially containing unacceptable concepts (e.g., copyright-infringing or unsafe). We need concept removal techniques (CRTs) which are i) effective in preventing the generation of images with unacceptable concepts, ii) utility-preserving on acceptable concepts, and, iii) robust against evasion with adversarial prompts. No prior CRT satisfies all these requirements simultaneously. We introduce Espresso, the first robust concept filter based on Contrastive Language-Image Pre-Training (CLIP). We identify unacceptable concepts by using the distance between the embedding of a generated image to the text embeddings of both unacceptable and acceptable concepts. This lets us fine-tune for robustness by separating the text embeddings of unacceptable and acceptable concepts while preserving utility. We present a pipeline to evaluate various CRTs to show that Espresso is more effective and robust than prior CRTs, while retaining utility
Anudeep Das, Vasisht Duddu, Rui Zhang 0118, N. Asokan
CODASPY3
2025 Attributed Graph Clustering in Collaborative Settings
abstract
Graph clustering is an unsupervised machine learning method that partitions the nodes in a graph into different groups. Despite achieving significant progress in exploiting both attributed and structured data information, graph clustering methods often face practical challenges related to data isolation. Moreover, the absence of collaborative methods for graph clustering limits their effectiveness. In this paper, we propose a collaborative graph clustering framework for attributed graphs, supporting attributed graph clustering over vertically partitioned data with different participants holding distinct features of the same data. Our method leverages a novel technique that reduces the sample space, improving the efficiency of the attributed graph clustering method. Furthermore, we compare our method to its centralized counterpart under a proximity condition, demonstrating that the successful local results of each participant contribute to the overall success of the collaboration. We fully implement our approach and evaluate its utility and efficiency by conducting experiments on four public datasets. The results demonstrate that our method achieves comparable accuracy levels to centralized attributed graph clustering methods. Our collaborative graph clustering framework provides an efficient and effective solution for graph clustering challenges related to data isolation.
Rui Zhang 0118, Xiaoyang Hou, Zhihua Tian, Enchao Gong, Jian Liu 0012, Kui Ren 0001
IEEE Trans. Dependable Secur. Comput.1
2024 PrivRE: Regular Expression Matching for Encrypted Packet Inspection
abstract
Encrypted packet inspection (EPI) allows a middle-box to perform DPI over encrypted packets without decryption. Existing EPI systems rely on expensive cryptographic operations, hence they are not yet ready to be deployed in real-world. Fur-thermore, such solutions only support exact keyword matching, unable to securely support regular expression, which is the major tool for DPI rule description due to its powerful and flexible expressive ability. In this paper, we propose PrivRE, the first EPI system that can securely support regular expressions. The main idea of PrivRE is to have middlebox run regular expressions on a desensitized version of the payload, in which sensitive information has been replaced with dummy characters. We provide a full-fledged implementation of PrivRE. In particular, we override OpenSSL to make PrivRE transparent to the application layer, so that the software developers do not need to be aware of the existence of PrivRE. We systematically evaluate PrivRE on a testbed that consists of 3 intercontinental EC2 VMs. Our experimental results show that it introduces at most 0.03 % accuracy loss, and it is only 1.78 x −8.23 x slower than SplitTLS (where the middle box can decrypt the packets).
Xiaoyang Hou, Jian Liu 0012, Tianyu Tu, Rui Zhang 0118, Kui Ren 0001
ICDCS4
2024 False Claims against Model Ownership Resolution
Jian Liu 0012, Rui Zhang 0118, Sebastian Szyller, Kui Ren 0001, N. Asokan
USENIX Security Symposium2
2024 ${\sf FederBoost}$: Private Federated Learning for GBDT
abstract
Federated Learning (FL) has been an emerging trend in machine learning and artificial intelligence. It allows multiple participants to collaboratively train a better global model and offers a privacy-aware paradigm for model training since it does not require participants to release their original training data. However, existing FL solutions for vertically partitioned data or decision trees require heavy cryptographic operations. In this article, we propose a framework named$\mathsf {FederBoost}$for private federated learning of gradient boosting decision trees (GBDT). It supports running GBDT over both vertically and horizontally partitioned data. Vertical$\mathsf {FederBoost}$doesnotrequire any cryptographic operation and horizontal$\mathsf {FederBoost}$only requires lightweight secure aggregation. The key observation is that the whole training process of GBDT relies on theorderingof the data instead of the values. We fully implement$\mathsf {FederBoost}$and evaluate its utility and efficiency through extensive experiments performed on three public datasets. Our experimental results show that both vertical and horizontal$\mathsf {FederBoost}$achieve the same level of accuracy with centralized training where all data are collected in a central server; and they are 4-5 orders of magnitude faster than the state-of-the-art solutions for federated decision tree training; hence offering practical solutions for industrial applications.
Zhihua Tian, Rui Zhang 0118, Xiaoyang Hou, Lingjuan Lyu, Jian Liu 0012, Kui Ren 0001
IEEE Trans. Dependable Secur. Comput.2
2022 "Adversarial Examples" for Proof-of-Learning
abstract
In S&P 21, Jia et al. proposed a new concept/mechanism named proof-of-learning (PoL), which allows a prover to demonstrate ownership of a machine learning model by proving integrity of the training procedure. It guarantees that an adversary cannot construct a valid proof with less cost (in both computation and storage) than that made by the prover in generating the proof. A PoL proof includes a set of intermediate models recorded during training, together with the corresponding data points used to obtain each recorded model. Jia et al. claimed that an adversary merely knowing the final model and training dataset cannot efficiently find a set of intermediate models with correct data points. In this paper, however, we show that PoL is vulnerable to “adversarial examples”! Specifically, in a similar way as optimizing an adversarial example, we could make an arbitrarily-chosen data point “generate” a given model, hence efficiently generating intermediate models with correct data points. We demonstrate, both theoretically and empirically, that we are able to generate a valid proof with significantly less cost than generating a proof by the prover.
Rui Zhang 0118, Jian Liu 0012, Zhibo Wang 0001, Kui Ren 0001
SP1