VLDB 2026 Research / reviewers in the wild / expert
Guangsheng Zhang 0004
dblp:64/6322-4
· DBLP profile ↗
6ranked-venue papers
3as first author
6since 2021 · last 2025
0000-0002-9776-0529ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | RAGLeak: Membership Inference Attacks on RAG-Based Large Language Models
Kaiyue Feng, Guangsheng Zhang 0004, Yanjun Zhang 0002, Tianqing Zhu, Ming Ding 0001, Bo Liu 0001 |
ACISP (3) | 2 |
| 2025 | Do Fairness Interventions Come at the Cost of Privacy: Evaluations for Binary ClassifiersabstractWhile in-processing fairness approaches show promise in mitigating biased predictions, their potential impact on privacy leakage remains under-explored. We aim to address this gap by assessing the privacy risks of fairness-enhanced binary classifiers via membership inference attacks (MIAs) and attribute inference attacks (AIAs). Surprisingly, our results reveal that enhancing fairness does not necessarily lead to privacy compromises. For example, these fairness interventions exhibit increased resilience against MIAs and AIAs. This is because fairness interventions tend to remove sensitive information among extracted features and reduce confidence scores for the majority of training data for fairer predictions. However, during the evaluations, we uncover a potential threat mechanism that exploits prediction discrepancies between fair and biased models, leading to advanced attack results for both MIAs and AIAs. This mechanism reveals potent vulnerabilities of fair models and poses significant privacy risks of current fairness methods. Extensive experiments across multiple datasets, attack methods, and representative fairness approaches confirm our findings and demonstrate the efficacy of the uncovered mechanism. Our study exposes the under-explored privacy threats in fairness studies, advocating for thorough evaluations of potential security vulnerabilities before model deployments. Guangsheng Zhang 0004, Bo Liu 0001, Tianqing Zhu, Ming Ding 0001, Wanlei Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | When Fairness Meets Privacy: Exploring Privacy Threats in Fair Binary Classifiers via Membership Inference Attacks
Guangsheng Zhang 0004, Bo Liu 0001, Tianqing Zhu, Ming Ding 0001, Wanlei Zhou 0001 |
IJCAI | 2 |
| 2024 | How Does a Deep Learning Model Architecture Impact Its Privacy? A Comprehensive Study of Privacy Attacks on CNNs and Transformers
Guangsheng Zhang 0004, Bo Liu 0001, Tianqing Zhu, Ming Ding 0001, Wanlei Zhou 0001 |
USENIX Security Symposium | 1 |
| 2024 | PPFed: A Privacy-Preserving and Personalized Federated Learning FrameworkabstractFederated learning is a distributed learning paradigm where a global model is trained using data samples from multiple clients but without the necessity of sharing raw data samples. However, it comes with several significant challenges in system designs, data quality, and communications. Recent research highlights a significant concern related to data privacy leakage through reserve-engineering model gradients at a malicious server. Moreover, a global model cannot provide good utility performance for individual clients when the local training data is heterogeneous in terms of quantity, quality, and distribution. Hence, personalized federated learning is highly desirable in practice to tailor the trained model for local usage. In this paper, we propose PPFed, a unified federated learning framework to simultaneously address privacy preservation and personalization. The intuition of our framework is to learn part of the model gradients at the server and the rest of the gradients at the local clients. To evaluate the effectiveness of the proposed framework, we conduct extensive experiments across four image classification datasets to show that our framework yields better privacy and personalization performance compared to the existing methods. We also claim that privacy preservation and personalization are essentially two facets of deep learning models, offering a unique perspective on their intrinsic interrelation. Guangsheng Zhang 0004, Bo Liu 0001, Tianqing Zhu, Ming Ding 0001, Wanlei Zhou 0001 |
IEEE Internet Things J. | 1 |
| 2023 | Label-Only Membership Inference Attacks and Defenses in Semantic Segmentation ModelsabstractRecent research has discovered that deep learning models are vulnerable to membership inference attacks, which can reveal whether a sample is in the training dataset of the victim model or not. Most membership inference attacks rely on confidence scores from the victim model for the attack purpose. However, a few studies indicate that prediction labels of the victim model's output are sufficient for launching successful attacks. Besides the well-studied classification models, segmentation models are also vulnerable to this type of attack. In this article, for the first time, we propose the label-only membership inference attacks against semantic segmentation models. With a well-designed framework of the attacks, we can achieve a considerably higher successful attacking rate compared to previous work. In addition, we have discussed several possible defense mechanisms to counter such a threat. Guangsheng Zhang 0004, Bo Liu 0001, Tianqing Zhu, Ming Ding 0001, Wanlei Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |