VLDB 2026 Research / reviewers in the wild / expert
Jianhua Wang 0004
dblp:60/900-4
· DBLP profile ↗
16ranked-venue papers
7as first author
16since 2021 · last 2026
0000-0002-2773-3429ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 9 · 6 first-author · 9 since 2021Security and privacy · 5 · 1 first-author · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Feddsg: backdoor defense via semantic filter and geometric constraint in federated learningabstractAbstract Backdoor attacks pose a serious threat to Internet-of-Things (IoT) federated learning. In IoT deployments, pronounced non-independent and identically distributed (non-IID) data heterogeneity causes benign client updates to exhibit substantial variability across devices. Meanwhile, the physical exposure of IoT devices increases the risk of large-scale compromise and elevated malicious participation. Such variability allows poisoned updates to blend into natural fluctuations, rendering many robust aggregation and detection-based defenses unreliable. We propose FedDSG , a server-side defense that combines a semantic bias filter and a geometric direction constraint to counter backdoor manipulation. FedDSG first extracts a novel scale-invariant semantic cue from the last-layer bias of client updates to identify abnormal target-class reinforcement, staying effective even when benign bias patterns differ substantially across clients. The remaining updates are then constrained using a reference derived from a small trusted anchor set, limiting adversarial drift. This sequential design links semantic cues with geometric structure, where the former removes clearly suspicious updates and the latter stabilizes the residual ones, preventing misdetection-induced drift amplification while avoiding distortion of benign updates. The method does not alter client behavior or communication and adds minimal server-side overhead. Extensive experiments on MNIST, Fashion-MNIST, CIFAR-10, and SVHN under non-IID distributions with high malicious participation demonstrate the robustness of FedDSG. It reduces the attack success rate to 0.003, 0.006, 0.007, and 0.091, respectively, with only marginal accuracy loss and consistently achieves the highest Overall Performance Score (OPS), reflecting a superior trade-off between robustness and accuracy. Code and data availability information is provided in the Availability of data and materials section. Jianhua Wang 0004, Yongle Chen |
Cybersecur. | 2 |
| 2026 | SMTFL: Secure Model Training to Untrusted Participants in Federated LearningabstractFederated learning is an essential distributed model training technique. However, threats such as gradient inversion attacks and poisoning attacks pose significant risks to both privacy of training data and model correctness. We propose SMTFL, a novel approach for secure model training in federated learning. To safeguard gradients privacy against gradient inversion attacks, clients are dynamically grouped, allowing one client's gradient to be divided to obfuscate the gradients of other clients within the group. This method incorporates checks and balances to reduce the collusion for inferring specific client data. To detect poisoning attacks from malicious clients, we assess the impact of aggregated gradients on the global model's performance, enabling effective identification and exclusion of malicious clients. Each client's gradients are encrypted and stored, with decryption collectively managed by all clients. The detected poisoning gradients are invalidated from the global model through an unlearning method. Compared to related work, SMTFL does not rely on trusted participants, avoids the performance degradation caused with traditional noise-injection, and avoids complex homomorphic encryption during gradient aggregation. SMTFL is evaluated on five datasets, and these results demonstrate its effectiveness in defending against gradient inversion and poisoning attacks. The model accuracy is nearly restored to its pre-attack state when SMTFL is deployed. Furthermore, SMTFL achieves over 95% accuracy in identifying malicious clients while maintaining a false positive rate for honest clients within 5%, which is 6% lower than the latest methods. Xiaorong Dong, Yimo Ren, Jianhua Wang 0004, Hongsong Zhu, Yongle Chen |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | CRS-FL: Conditional Random Sampling for Communication-Efficient and Privacy-Preserving Federated LearningabstractFederated Learning (FL), a privacy-oriented distributed ML paradigm, is gaining great interest in the Internet of Things because of its capability to protect participants’ data privacy. Studies have been conducted to address the challenges of communication efficiency and privacy-preserving, which exist in standard FL. However, they cannot achieve the goal of making a tradeoff between communication efficiency and model accuracy while guaranteeing privacy. This paper proposes a Conditional Random Sampling (CRS) method and implements it into the standard FL (CRS-FL) to tackle the above-mentioned challenges. CRS explores a Poisson-sampling-based stochastic coefficient to achieve a higher probability of obtaining zero-gradient unbiasedly and then decreases the communication overhead effectively without model accuracy degradation. Moreover, we dig out the relaxation Local Differential Privacy (LDP) guarantee conditions of CRS theoretically. Extensive experiment results indicate that (1) in communication efficiency, CRS-FL performs better than the existing methods in metric accuracy per transmission byte without model accuracy reduction in more than 7% sampling ratio (# sampling size / # model size); (2) in privacy-preserving, CRS-FL achieves no accuracy reduction compared with LDP baselines while holding the efficiency, even exceeding them in model accuracy under more sampling ratio conditions. Jianhua Wang 0004, Xiaolin Chang, Jelena V. Misic, Vojislav B. Misic, Lin Li 0041, Yingying Yao |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2024 | Towards Well-trained Model Robustness in Federated Learning: An Adversarial- Example-Generation- Efficiency PerspectiveabstractFederated Learning (FL), as a privacy-oriented distributed machine learning paradigm, can obtain a well-trained global model without private dataset transferring. Nevertheless, FL is subject to severe security threats of adversarial examples (AEs) with unnoticeable perturbations, generated by white-box attacks in honest-but-curious FL participants. Adversarial training is an effective solution to enhance the robustness of the model by identifying AEs as correct samples. However, the AE training efficiency is crucial in realistic scenarios of adversarial training, such as autonomous driving. Researchers have proposed the Fast Gradient Sign Method (FGSM) and its improvement to generate AEs rapidly. In this paper, we propose a novel optimizer-based FGSM, FastAdaBelief-based FGSM (FAB-FGSM), in order to generate AEs more efficiently and effectively. Benefitting from time-vary coefficients and a vanishing factor, FAB-FGSM realizes a more adaptive iteration step size than AdaBelief-based FGSM (AB-FGSM) and Adam-based FGSM (AI-FGSM). We explore the probable causes by recalling the theoretical analysis of three optimizers. Extensive experiment results demonstrate that compared to AB-FGSM and AI-FGSM, our FAB-FGSM achieves the fastest convergence and the best attack success rate in four target models, including Inception v3, Inception v4, Inception ResNet v2, ResNet-101. Jianhua Wang 0004, Xuyang Lei, Jelena V. Misic, Vojislav B. Misic, Xiaolin Chang |
ICC | 1 |
| 2024 | Practical solutions in fully homomorphic encryption: a survey analyzing existing acceleration methodsabstractAbstract Fully homomorphic encryption (FHE) has experienced significant development and continuous breakthroughs in theory, enabling its widespread application in various fields, like outsourcing computation and secure multi-party computing, in order to preserve privacy. Nonetheless, the application of FHE is constrained by its substantial computing overhead and storage cost. Researchers have proposed practical acceleration solutions to address these issues. This paper aims to provide a comprehensive survey for systematically comparing and analyzing the strengths and weaknesses of FHE acceleration schemes, which is currently lacking in the literature. The relevant researches conducted between 2019 and 2022 are investigated. We first provide a comprehensive summary of the latest research findings on accelerating FHE, aiming to offer valuable insights for researchers interested in FHE acceleration. Secondly, we classify existing acceleration schemes from algorithmic and hardware perspectives. We also propose evaluation metrics and conduct a detailed comparison of various methods. Finally, our study presents the future research directions of FHE acceleration, and also offers both guidance and support for practical application and theoretical research in this field. Yanwei Gong, Xiaolin Chang, Jelena V. Misic, Vojislav B. Misic, Jianhua Wang 0004 |
Cybersecur. | 5 |
| 2024 | PA-iMFL: Communication-Efficient Privacy Amplification Method Against Data Reconstruction Attack in Improved Multilayer Federated LearningabstractRecently, big data has seen explosive growth in the Internet of Things (IoT). Multi-layer FL (MFL) based on cloud-edge-end architecture can promote model training efficiency and model accuracy while preserving IoT data privacy. This paper considers an improved MFL, where edge layer devices own private data and can join the training process. iMFL can improve edge resource utilization and also alleviate the strict requirement of end devices, but suffers from the issues of Data Reconstruction Attack (DRA) and unacceptable communication overhead. This paper aims to address these issues with iMFL. We propose a Privacy Amplification scheme on iMFL (PA-iMFL). Differing from standard MFL, we design privacy operations in end and edge devices after local training, including three sequential components, local differential privacy with Laplace mechanism, privacy amplification subsample, and gradient sign reset. Benefitting from privacy operations, PA-iMFL reduces communication overhead and achieves privacy-preserving. Extensive results demonstrate that against State-Of-The-Art (SOTA) DRAs, PA-iMFL can effectively mitigate private data leakage and reach the same level of protection capability as the SOTA defense model. Moreover, due to adopting privacy operations in edge devices, PA-iMFL promotes up to 2.8 × communication efficiency than the SOTA compression method without compromising model accuracy. Jianhua Wang 0004, Xiaolin Chang, Jelena V. Misic, Vojislav B. Misic, Zhi Chen 0013, Junchao Fan |
IEEE Internet Things J. | 1 |
| 2024 | PASS: A Parameter Audit-Based Secure and Fair Federated Learning Scheme Against Free-Rider AttackabstractFederated learning (FL) as a secure distributed learning framework gains interests in Internet of Things (IoT) due to its capability of protecting the privacy of participant data. However, traditional FL systems are vulnerable to free-rider (FR) attacks, which causes unfairness, privacy leakage and inferior performance to FL systems. The prior defense mechanisms against FR attacks assumed that malicious clients (namely, adversaries) declare less than 50% of the total amount of clients. Moreover, they aimed for anonymous FR (AFR) attacks and lost effectiveness in resisting selfish FR (SFR) attacks. In this article, we propose a parameter audit-based secure and fair FL scheme (PASS) against FR attack. PASS has the following key features: 1) prevent from privacy leakage with less accuracy loss; 2) be effective in countering both AFR and SFR attacks; and 3) work well no matter whether AFR and SFR adversaries occupy the majority of clients or not. Extensive experimental results validate that PASS: 1) has the same level as the state-of-the-art method in mean square error against privacy leakage; 2) defends against AFR and SFR attacks in terms of a higher defense success rate, lower false positive rate, and higher F1-score; and 3) is still effective where adversaries exceed 50%, with F1-score 89% against AFR attack and F1-score 87% against SFR attack. Note that PASS produces no negative effect on FL accuracy when there is no FR adversary. Jianhua Wang 0004, Xiaolin Chang, Jelena V. Misic, Vojislav B. Misic, Yixiang Wang |
IEEE Internet Things J. | 1 |
| 2024 | Towards Secure Runtime Customizable Trusted Execution Environment on FPGA-SoCabstractProcessing sensitive data and deploying well-designed Intellectual Property (IP) cores on remote Field Programmable Gate Array (FPGA) are prone to private data leakage and IP theft. One effective solution is constructing Trusted Execution Environment (TEE) and its secure boot process on FPGA-SoC (FPGA System on Chip).This paper aims to establish Secure Runtime Customizable TEE (SrcTEE) on FPGA-SoC through the design of a novel secure boot scheme and the design of the following three components: 1) CrloadIP, which enforces access control on TEE applications deploying IP at runtime such that SrcTEE can alleviate threats from unauthorized TEE applications and then SrcTEE can be adjusted dynamically and securely; 2) CexecIP, which not only enables the execution of newly-installed IP cores without modifying the operating system of FPGA-SoC TEE, but also prevents insider attacks from executing IPs in SrcTEE; 3) CremoAT, which can provide the newly-measured SrcTEE state and establish a secure communication path between remote verifiers and SrcTEE. Our secure boot scheme supports refreshable root trust key, and assures the authenticity and integrity of boot codes during the SrcTEE booting process. We conduct a security analysis of SrcTEE and its performance evaluation on Xilinx Zynq UltraScale+ XCZU15EG 2FFVB1156 MPSoC. Xiaolin Chang, Jianhua Wang 0004, Yanwei Gong, Lin Li 0041 |
IEEE Trans. Computers | 4 |
| 2023 | Exploring best-matched embedding model and classifier for charging-pile fault diagnosisabstractAbstract The continuous increase of electric vehicles is being facilitating the large-scale distributed charging-pile deployment. It is crucial to guarantee normal operation of charging piles, resulting in the importance of diagnosing charging-pile faults. The existing fault-diagnosis approaches were based on physical fault data like mechanical log data and sensor data streams. However, there are other types of fault data, which cannot be used for diagnosis by these existing approaches. This paper aims to fill this gap and consider 8 types of fault data for diagnosing, at least including physical installation error fault, charging-pile mechanical fault, charging-pile program fault, user personal fault, signal fault (offline), pile compatibility fault, charging platform fault, and other faults. We aim to find out how to combine existing feature-extraction and machine learning techniques to make the better diagnosis by conducting experiments on realistic dataset. 4 word embedding models are investigated for feature extraction of fault data, including N-gram, GloVe, Word2vec, and BERT. Moreover, we classify the word embedding results using 10 machine learning classifiers, including Random Forest (RF), Support Vector Machine, K-Nearest Neighbor, Multilayer Perceptron, Recurrent Neural Network, AdaBoost, Gradient Boosted Decision Tree, Decision Tree, Extra Tree, and VOTE. Compared with original fault record dataset, we utilize paraphrasing-based data augmentation method to improve the classification accuracy up to 10.40%. Our extensive experiment results reveal that RF classifier combining the GloVe embedding model achieves the best accuracy with acceptable training time. In addition, we discuss the interpretability of RF and GloVe. Jianhua Wang 0004, Xiaofeng Peng, Chun Xiao, Mingcai Wang, Lin Li 0041, Xiaolin Chang |
Cybersecur. | 2 |
| 2022 | Assessing Anonymous and Selfish Free-rider Attacks in Federated LearningabstractFederated Learning (FL) is a distributed learning framework and gains interest due to protecting the privacy of participants. Thus, if some participants are free-riders who are attackers without contributing any computation resources and privacy data, the model faces privacy leakage and inferior performance. In this paper, we explore and define two free-rider attack scenarios, anonymous and selfish free-rider attacks. Then we propose two methods, namely novel and advanced methods, to construct these two attacks. Extensive experiment results reveal the effectiveness in terms of the less deviation with conventional FL using the novel method, and high false positive rate to puzzle defense model using the advanced method. Jianhua Wang 0004, Xiaolin Chang, Ricardo J. Rodríguez, Yixiang Wang |
ISCC | 1 |
| 2022 | DI-AA: An interpretable white-box attack for fooling deep neural networks
Yixiang Wang, Jiqiang Liu, Xiaolin Chang, Ricardo J. Rodríguez, Jianhua Wang 0004 |
Inf. Sci. | 5 |
| 2022 | AB-FGSM: AdaBelief optimizer and FGSM-based approach to generate adversarial examples
Yixiang Wang, Jiqiang Liu, Xiaolin Chang, Jianhua Wang 0004, Ricardo J. Rodríguez |
J. Inf. Secur. Appl. | 4 |
| 2021 | Mal-LSGAN: An Effective Adversarial Malware Example Generation ModelabstractVarious Machine Learning (ML) models have been developed for malware detection. But their widespread application is challenged by adversarial attacks using adversarial malware examples. Generative Adversarial Networks (GAN) is one of the effective approaches to help build possible unknown attacks and expose the vulnerability of targeted systems. The existing GAN-based ML models have the weaknesses of unstable training and low-quality adversarial examples. In this paper, we propose a novel Mal-LSGAN model to tackle these weaknesses. By using a Least Square (LS) loss function and new activation function combinations, Mal-LSGAN achieves a higher Attack Success Rate (ASR) and a lower True Positive Rate (TPR) in 6 ML detectors, compared with the existing MalGAN and Imp-MalGAN. In Multi-Layer Perceptron (MLP), Mal-LSGAN can even decrease TPR from 97.81% of original examples to 2.92% of adversarial examples. The experimental results also demonstrate that Mal-Lsgangets the preferable transferability of adversarial malware examples. Jianhua Wang 0004, Xiaolin Chang, Jelena V. Misic, Vojislav B. Misic, Yixiang Wang |
GLOBECOM | 1 |
| 2021 | A Novel Privacy-Preserving Neural Network Computing Approach for E-Health Information SystemabstractElectronic health (e-health) information system relies on cloud computing technologies to provide massive medical data computing and storage services. Especially, the recently proposed Machine Learning as a Service (MLaaS) on these medical data can not only effectively improve the healthcare service quality, but also support the end users with limited computing resources. However, MLaaS on the massive medical data faces the challenge of privacy. Homomorphic encryption technology has been explored to assure the privacy of medical data owners in MLaaS but with the weaknesses of limited homomorphic operations and low efficiency. To alleviate these weaknesses, this paper proposes a novel privacy-preserving non-collusion dualcloud (NCDC) model-based e-health information system using neural network (NN) computing. The system can not only assure medical data privacy through adopting homomorphic encryption technology but also assure NN model privacy by adding fake neurons to the NN. In addition, the proposed e-health information system also has the following advantages: (i) Simple key generation. (ii) No constraint on the size of medical data to be encrypted. (iii) The less loss of prediction accuracy between encrypted and original medical data. (iv) Supporting more homomorphic operations and having better computing efficiency through experiment verification. Yingying Yao, Zhendong Zhao, Xiaolin Chang, Jelena V. Misic, Vojislav B. Misic, Jianhua Wang 0004 |
ICC | 6 |
| 2021 | LPC: A lightweight pseudonym changing scheme with robust forward and backward secrecy for V2X
Yingying Yao, Xiaolin Chang, Jianhua Wang 0004, Jelena V. Misic, Vojislav B. Misic, Hong Wang 0027 |
Ad Hoc Networks | 3 |
| 2021 | LSGAN-AT: enhancing malware detector robustness against adversarial examplesabstractAbstract Adversarial Malware Example (AME)-based adversarial training can effectively enhance the robustness of Machine Learning (ML)-based malware detectors against AME. AME quality is a key factor to the robustness enhancement. Generative Adversarial Network (GAN) is a kind of AME generation method, but the existing GAN-based AME generation methods have the issues of inadequate optimization, mode collapse and training instability. In this paper, we propose a novel approach (denote as LSGAN-AT) to enhance ML-based malware detector robustness against Adversarial Examples, which includes LSGAN module and AT module. LSGAN module can generate more effective and smoother AME by utilizing brand-new network structures and Least Square (LS) loss to optimize boundary samples. AT module makes adversarial training using AME generated by LSGAN to generate ML-based Robust Malware Detector (RMD). Extensive experiment results validate the better transferability of AME in terms of attacking 6 ML detectors and the RMD transferability in terms of resisting the MalGAN black-box attack. The results also verify the performance of the generated RMD in the recognition rate of AME. Jianhua Wang 0004, Xiaolin Chang, Yixiang Wang, Ricardo J. Rodríguez |
Cybersecur. | 1 |