VLDB 2026 Research / reviewers in the wild / expert
Yu Sun 0015
dblp:62/3689-15
· DBLP profile ↗
16ranked-venue papers
6as first author
16since 2021 · last 2026
0000-0003-3206-9515ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 3 first-author · 8 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SAGE: Self-Reflective End-to-End Framework for Automated APT Investigation in 5G Networks
Yu Sun 0015, Gaojian Xiong, Jianwei Liu 0001 |
INFOCOM | 2 |
| 2026 | A Lightweight and Secure Extended Authentication and Key Agreement Protocol for Direct-to-Cell LEO Satellite Constellations
Yu Sun 0015, Gang Wang 0016, Jianwei Liu 0001 |
WCNC | 3 |
| 2026 | DistShield: Distribution Preserving Model Obfuscation for Real-Time TEE-Shielded Secure Inference on IoT DevicesabstractWhile on-device inference avoids network latency and private data uploading in IoT, the risk of model thefts has raised serious concern. As a solution, state-of-the-art approach obfuscates critical parameters and shields de-obfuscate keys in TEE, ensuring model confidentiality with minimal overhead. However, we reveal that existing methods lead to anomalous clustering in distribution, undermining the anonymity of protected parameters. Based on this vulnerability, we demonstrate a model stealing attack which could recover over 97% of the model performance without any queries or training, severely compromising the model security. Additionally, existing methods struggle to scale for large language models. To address these challenges, we propose DistShield, which leverages distribution preserving obfuscation to generate obfuscated parameters with no anomaly. Moreover, to minimize the inference latency and adapt to large language models, iterative weight pruning is tailored to precisely narrow down the range of critical parameters. Experimental results demonstrate that our approach achieves robust model security by protecting only 0.013% of the parameters, leading to a 10× reduction in model stealing attack accuracy, with only 11% additional TEE computation latency introduced. DistShield provides promising obfuscation scheme against model thefts on edge, while maintaining real-time inference capabilities. Qinglin Song, Gaojian Xiong, Yu Sun 0015 |
IEEE Internet Things J. | 3 |
| 2026 | Toward Trusted 6G Mobile Edge Computing: A Secure Batch Large Language Models Deployment Framework
Yu Sun 0015, Gaojian Xiong, Qinglin Song, Jianwei Liu 0001, Gang Wang 0016, Rui Wang 0183 |
IEEE Trans. Mob. Comput. | 1 |
| 2025 | 5GC-Fuzz: Finding Deep Stateful Vulnerabilities in 5G Core Network with Black-Box Fuzzing
Yu Sun 0015, Jianwei Liu 0001 |
INFOCOM | 1 |
| 2025 | LoRO: Real-Time on-Device Secure Inference for LLMs via TEE-Based Low Rank ObfuscationabstractWhile Large Language Models (LLMs) have gained remarkable success, they are consistently at risk of being stolen when deployed on untrusted edge devices. As a solution, TEE-based secure inference has been proposed to protect valuable model property. However, we identify a statistical vulnerability in existing protection methods, and furtherly compromise their security guarantees by proposed Model Stealing Attack with Prior. To eliminate this vulnerability, LoRO is presented in this paper, which leverages dense mask to completely obfuscate parameters. LoRO includes two innovations: (1) Low Rank Mask, which uses low-rank factors to generate dense masks efficiently. The computing complexity in TEE is hence reduced by an exponential amount to achieve inference speed up, while providing robust model confidentiality. (2) Factors Multiplexing, which reuses several cornerstone factors to generate masks for all layers. Compared to one-mask-per-layer, the secure memory requirement is reduced from GB-level to tens of MB, hence avoiding the hundred-fold latency introduced by secure memory paging. Experimental results indicate that LoRO achieve a $0.94\times$ Model Stealing (MS) accuracy, while SOTA methods presents $3.37\times$ at least. The averaged inference latency of LoRO is only $1.49\times$, compared to the $112\times$ of TEE-shielded inference. Moreover, LoRO results no accuracy loss, and requires no re-training and structure modification. LoRO can solve the concerns regarding model thefts on edge devices in an efficient and secure manner, facilitating the wide edge application of LLMs. Gaojian Xiong, Yu Sun 0015, Jianwei Liu 0001 |
NeurIPS | 2 |
| 2025 | TSQP: Safeguarding Real-Time Inference for Quantization Neural Networks on Edge DevicesabstractQuantization Neural Networks (QNNs) has been widely adopted in resource-constrained edge devices due to their real-time capabilities and low resource requirement. However, concerns have arisen regarding that deployed models are white-box available to model thefts. To address this issue, TEE-shielded secure inference has been introduced as a secure and efficient solution. Nevertheless, existing methods neglect the compatibility with 8-bit quantized computation, which leads to severe integer overflow issue during inference. This issue could result a disastrous degradation in QNNs (to random guessing level), completely destroying model utility. Moreover, the model confidentiality and inference integrity also face a substantial threat due to the limited data representation space. To safeguard accurate and efficient inference for QNNs, TEE-Shielded QNN Partition (TSQP) are proposed, which presents three key insights: Firstly, Quantization Manager is designed to convert white-box inference to black-box by shielding critical scales in TEE. Additionally, overflow concerns are effectively addressed using reduced-range approaches. Secondly, by leveraging the Information Bottleneck theory to enhance model training, we introduce Parameter De-Similarity to defend against powerful Model Stealing attacks that existing methods are vulnerable to. Thirdly, the Integrity Monitor is suggested to detect inference integrity breaches in an oblivious manner. In contrast, existing method can be bypassed due to the lack of obliviousness. Experimental results demonstrate that proposed TSQP maintains high accuracy and achieves accurate integrity breaches detection. Our method achieves more than$8\times$speedup compared to full TEE inference, while reducing Model Stealing attacks accuracy from$3.99\times$to$1.29\times$. To our best knowledge, proposed method is the first TEE-shielded secure inference solution that achieves model confidentiality, inference integrity and model utility on QNNs. Yu Sun 0015, Gaojian Xiong |
SP | 1 |
| 2024 | GI-PIP: Do We Require Impractical Auxiliary Dataset for Gradient Inversion Attacks?abstractDeep gradient inversion attacks expose a serious threat to Federated Learning (FL) by accurately recovering private data from shared gradients. However, the state-of-the-art heavily relies on impractical assumptions to access excessive auxiliary data, which violates the basic data partitioning principle of FL. In this paper, a novel method, Gradient Inversion Attack using Practical Image Prior (GI-PIP), is proposed under a revised threat model. GI-PIP exploits anomaly detection models to capture the underlying distribution from fewer data, while GAN-based methods consume significant more data to synthesize images. The extracted distribution is then leveraged to regulate the attack process as Anomaly Score loss. Experimental results show that GI-PIP achieves a 16.12 dB PSNR recovery using only 3.8% data of ImageNet, while GAN-based methods necessitate over 70%. Moreover, GI-PIP exhibits superior capability on distribution generalization compared to GAN-based methods. Our approach significantly alleviates the auxiliary data requirement on both amount and distribution in gradient inversion attacks, hence posing more substantial threat to real-world FL. Our code is available at https://github.com/D1aoBoomm/GI-PIP. Yu Sun 0015, Gaojian Xiong, Xianxun Yao, Kailang Ma |
ICASSP | 1 |
| 2024 | Client-Side Gradient Inversion Attack in Federated Learning Using Secure AggregationabstractAs a privacy-preserving enhancement to the Federated Learning (FL) framework, Secure Aggregation (SA) enables multiparty summation without any party needing to reveal their updates to the aggregator in Internet of Things applications. However, conventional threat model underestimates the potential inversion attacks on aggregated gradients from an honest-but-curious client, due to the considering information loss caused by SA. This study for the first time, demonstrates the gradient inversion attack against SA schemes in which gradients are quantized and aggregated. Then an enhanced gradient inversion from client side is proposed to address two roadblocks caused by SA, i.e., aggregation information loss and quantization rounding error. To countermeasure the information loss, we utilize class-wise representation matching to achieve category-level decomposition. This relies on a prior restoration of the class-wise representations and instance-wise labels, whose numerical accuracy is cyclically calibrated through prior-based offset estimation. Since cryptographic operators involved in SA schemes usually operates in the integer domain, gradient quantization is introduced. Regarding the rounding errors from gradient quantization, quantization-aware gradient matching is presented to align with a more precise optimization objective. Extensive experiments demonstrate that a semi-honest client is sufficient to infer sensitive data from the aggregated gradients after even 8-bit quantization. Moreover, a defense scheme based on 1-bit gradient quantization is proposed. The new attack from client side in SA-based FL urges the community to take necessary defensive measures. Yu Sun 0015, Kailang Ma, Jianwei Liu 0001 |
IEEE Internet Things J. | 1 |
| 2024 | CPAKA: Mutual Authentication and Key Agreement Scheme Based on Conditional PUF in Space-Air-Ground Integrated NetworkabstractThe space-air-ground integrated network (SAGIN) has a stringent demand on the efficiency of authentication protocols deployed in the devices that have been launched into the air and space. In this paper, we define the concept of the security model of conditional physical unclonable function (CPUF) that guarantees the security of the protocol while allowing the use of PUFs that can be modeled. We then propose a CPUF-based authentication and key agreement (AKA) scheme, named CPAKA, that addresses the challenges of device key leakage and inefficient authentication in resource-asymmetric environments. The CPAKA scheme embeds PUFs in weak nodes and deploys prediction models corresponding to the PUFs in strong nodes, eliminating the need to store challenge-response pairs or perform complex calculations. We formally prove the protocol's security under the decisional uniqueness assumption of CPUF and the universal composability framework, and we analyze its secrecy and authentication properties using the Tamarin prover. We also implement an Arbiter PUF on the ZYNQ-7020 FPGA, verify its accuracy through experiments, and show that CPAKA is secure, efficient, and suitable for SAGIN. Our CPAKA scheme greatly reduces computing and storage costs while improving authentication efficiency compared to traditional schemes. Dawei Li 0009, Di Liu 0019, Yangkun Ren, Yu Sun 0015, Zhenyu Guan 0002, Qianhong Wu, Jiankun Hu, Jianwei Liu 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Instance-wise Batch Label Restoration via Gradients in Federated Learning
Kailang Ma, Yu Sun 0015, Dawei Li 0009, Zhenyu Guan 0002, Jianwei Liu 0001 |
ICLR | 2 |
| 2023 | FPHammer: A Device Identification Framework based on DRAM FingerprintingabstractThe device fingerprinting technique extracts fingerprints based on the hardware characteristics of the device to identify the device. The primary goal of device fingerprinting is to accurately and uniquely identify a device, which requires the generated device fingerprints to have good stability to achieve long-term tracking of the target device. However, the fingerprints generated by some existing fingerprinting technologies are not stable enough or change frequently, making it impossible to track the target device for a long time. In this paper, we present FPHammer, a novel DRAM-based fingerprinting technique. The device fingerprint generated by our technique has high stability and can be used to track the device for a long time. We leverage the Rowhammer technique to repeatedly and quickly access a row in DRAM to get bit flips in its adjacent row. We then construct a physical fingerprint of the device based on the locations of the collected bit flips. The evaluation results of the uniqueness and reliability of the physical fingerprint show that it can be used to distinguish devices with the same hardware and software configuration. The experimental results on device identification demonstrate that the physical fingerprints engendered by our innovative technique are inherently linked to the entirety of the device rather than just the DRAM module. Even if the device modifies software-level parameters such as MAC address and IP address or even reinstalls the operating system, we can accurately identify the target device. This demonstrates that FPHammer can generate stable fingerprints that are not affected by software layer parameters. Dawei Li 0009, Di Liu 0019, Yangkun Ren, Yu Sun 0015, Zhenyu Guan 0002, Qianhong Wu, Jianwei Liu 0001 |
TrustCom | 5 |
| 2023 | Decentralized IoT Resource Monitoring and Scheduling Framework Based on BlockchainabstractWith the continuous advancement of edge intelligence, edge servers undertake more and more intelligent computing tasks. Nowadays, there are a large number of IoT devices in the network in idle state. For instance, the mining process for consensus of miners in blockchain such as Bitcoin causes a waste of computing resources and energy. A natural question arises: can we couple the idle computing resources of network devices to continuously and credibly share the burden of edge intelligent computing tasks in a secure manner? The answer of this paper is yes. We propose a blockchain-based IoT resource monitoring and scheduling framework that supports resource management and trusted edge computing. We analyze the security threats in all phases of distributed edge computing, and utilize the trusted computing and public verifiability features of blockchain to ensure reliability and fairness in the trusted measurement of device computing power, the decomposition of intelligent computing tasks, the matching of task and computing power, and the verification of computing result. Finally, we implement a simulation on the edge network by performing distributed machine learning task for weather prediction, and the simulation results demonstrate the availability of our scheme. Dawei Li 0009, Qinjun Wan, Zhenyu Guan 0002, Yu Sun 0015, Qianhong Wu, Jiankun Hu, Jianwei Liu 0001 |
IEEE Internet Things J. | 5 |
| 2023 | Privacy-Preserving Cross-Silo Federated Learning Atop Blockchain for IoTabstractCross-silo federated learning (FL) is promising in facilitating data collaboration across various organizations, which greatly alleviates the information silo problem in industries and promotes the data intelligence of Internet of Things. With the advances of decentralized FL, the higher requirements of trust and privacy are put forward. Traditional FL heavily relies on a central coordinating server, which suffers from single points of failure and lacks trust in the correctness of aggregation results. What is more, the intrinsic privacy issues of FL have aroused public attention, such as gradient inversion attack in local gradients. However, the privacy of quantized gradients remains serious and lacks attention, especially the most extremely 1-bit quantization in sign-based FL. In this article, we demonstrate the potential privacy risk in sign-based FL by presenting a new gradient inversion attack, which successfully restores the original data from sign-based quantized gradients. And then we tackle the above two challenges via constructing a self-aggregation privacy-preserving FL atop blockchain, which takes advantage of a variant of ElGamal encryption to protect the privacy of local sign-based quantized gradients, and leverages the smart contract to achieve secure self-aggregation for participants without involving a centralized server. Moreover, we analyze that the proposed protocol achieves privacy and public verifiability. Finally, we evaluate the performance of the proposed protocol with a real deep learning model, and the results show that our protocol is resilient against gradient inversion attack in a decentralized environment without sacrificing learning accuracy. Yu Sun 0015, Yong Yu 0002, Dawei Li 0009, Zhenyu Guan 0002, Jianwei Liu 0001 |
IEEE Internet Things J. | 2 |
| 2022 | Cross-CAM: Focused Visual Explanations for Deep Convolutional Networks via Training-Set Tracing
Yu Sun 0015, Kailang Ma, Xuanxin Liu |
KSEM (1) | 1 |
| 2022 | Blockchain-based authentication for IIoT devices with PUF
Dawei Li 0009, Di Liu 0019, Yingxian Song, Yangkun Ren, Zhenyu Guan 0002, Yu Sun 0015, Jianwei Liu 0001 |
J. Syst. Archit. | 7 |