VLDB 2026 Research / reviewers in the wild / expert
Ye Dong
dblp:73/4099
· DBLP profile ↗
31ranked-venue papers
9as first author
26since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 17 · 8 first-author · 14 since 2021Computer networks · 5 · 5 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ChatIot: Large Language Model-Based Security Assistant for Internet of Things with RAG
Ye Dong, Yan Lin Aung, Sudipta Chattopadhyay 0001, Jianying Zhou 0001 |
ACNS (3) | 1 |
| 2026 | PrivMark: Private Large Language Models Watermarking with MPC
Thomas Fargues, Ye Dong, Tianwei Zhang 0004, Jin Song Dong 0001 |
ICC | 2 |
| 2026 | JAGUAR: efficient and secure unbalanced PSI under malicious adversaries in the client-server settingabstractAbstract In many unbalanced private set intersection (uPSI) applications of the client–server setting, the server needs to perform uPSI with multiple clients. Cong et al. (ACM CCS’21) proposed a state-of-the-art (SOTA) uPSI protocol based on fully homomorphic encryption (FHE), achieving malicious security by employing an oblivious pseudorandom function (OPRF) in the pre-processing phase. However, re-executing existing uPSI protocols with each client imposes significant computational overhead for the server. In this paper, we present JAGUAR, a maliciously secure and efficient uPSI protocol designed for this setting. JAGUAR reduces online computation through a Divide-and-Combine optimization, requiring only $${\mathcal {O}}(\sqrt{|X|})$$ O ( | X | ) homomorphic multiplications. Furthermore, it employs a novel fixed VOLE-based OPRF that enables reusable and lightweight pre-processing across multiple clients. Experimental results demonstrate that JAGUAR achieves up to $$2.7\times$$ 2.7 × improvement in online runtime compared to the SOTA protocol in LAN. In multi-client scenarios, JAGUAR further outperforms existing protocols by a wide margin in terms of scalability and overall performance. Weizhan Jing, Xiaojun Chen 0004, Ye Dong, Qiang Liu 0060, Tingyu Fan |
Cybersecur. | 4 |
| 2026 | M&M: Secure Two-Party Machine Learning Through Modulus Conversion and Mixed-Mode ProtocolsabstractSecure two-party machine learning has made substantial progress through the use of mixed-mode protocols, but existing approaches often suffer from efficiency bottlenecks due to inherent mismatch between optimal domains of various cryptographic primitives. In response to these challenges, we introduce framework M&M, which features an efficient modulus conversion protocol. This breakthrough enables seamless integration of the most suitable cryptographic subprotocols within their optimal modulus domains with a minimal modulus conversion overhead. We further establish new benchmarks and practical optimizations for the performance of fundamental primitives, namely comparison and multiplication, across various two-party techniques.By incorporating these techniques, M&M demonstrates significant performance enhancements over state-of-the-art solutions: i) we report a$6\times$-$100\times$improvement for approximated truncations with 1-bit error tolerance; ii) an average of$5\times$(resp.$4\times$) reduction in communication (resp. runtime) for machine learning functions; iii) and a 25%-99% improvement in cost-efficiency for private inference of deep neural networks and 50% improvement in private training of gradient boosting decision trees. Ye Dong, Xiaoyang Hou, Kang Yang 0002, Jian Liu 0012 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Alkaid: Accelerating Three-Party Boolean Circuits by Mixing Correlations and RedundancyabstractSecure three-party computation (3PC) with semi-honest security under an honest majority offers notable efficiency in computation and communication; for Boolean circuits, each party sends a single bit for every AND gate, and nothing for XOR. However, round complexity remains a significant challenge, especially in high-latency networks. Some works can support multi-input AND and thereby reduce online round complexity, but they requireexponentialcommunication for generating the correlations in either preprocessing or online phase. How to extend the AND gate to multi-input while maintaining high correlation generation efficiency is still not solved. To address this problem, we propose a round-efficient 3PC framework ALKAID for Boolean circuits through improved multi-input AND gate. By mixing correlations and redundancy, we propose a concretely efficient correlation generation approach for small input bitsNN> 4. Exploiting the improved multi-input AND gates, we design fast depth-optimized parallel prefix adder and share conversion primitives in 3PC, achieved with new techniques and optimizations for better concrete efficiency. We further apply these optimized primitives to enhance the efficiency of secure non-linear functions in machine learning. We implement ALKAID and extensively evaluate its performance. Compared to state of the arts like ABY3 (CCS’2018), Trifecta (PoPETs’2023), and METEOR (WWW’2023), ALKAID enjoys 1.5×–2.5× efficiency improvements for boolean primitives and non-linear functions, with better or comparable communication. Ye Dong, Xiangfu Song, Yaxi Yang, Tianwei Zhang 0004, Jianying Zhou 0001, Jin Song Dong 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Mizar: Boosting Secure Three-Party Deep Learning with Co-Designed Sign-Bit Extraction and GPU Acceleration
Ye Dong, Xiangfu Song, Yaxi Yang, Tianwei Zhang 0004, Jin Song Dong 0001 |
ACSAC | 1 |
| 2025 | MPCache: MPC-Friendly KV Cache Eviction for Efficient Private LLM InferenceabstractPrivate large language model (LLM) inference based on secure multi-party computation (MPC) achieves formal data privacy protection but suffers from significant latency overhead, especially for long input sequences. While key-value (KV) cache eviction and sparse attention algorithms have been proposed for efficient LLM inference in plaintext, they are not designed for MPC and cannot benefit private LLM inference directly. In this paper, we propose an accurate and MPC-friendly KV cache eviction framework, dubbed MPCache, building on the observation that historical tokens in a long sequence may have different effects on the downstream decoding. Hence, MPCache combines a look-once static eviction algorithm to discard unimportant KV cache and a query-aware dynamic selection algorithm to activate only a small subset of KV cache for attention computation. MPCache further incorporates a series of optimizations for efficient dynamic KV cache selection, including MPC-friendly similarity approximation, hierarchical KV cache clustering, and cross-layer index-sharing strategy. Extensive experiments demonstrate that MPCache consistently outperforms prior-art KV cache eviction baselines across different generation tasks and achieves 1.8 ~ 2.01x and 3.39 ~ 8.37x decoding latency and communication reduction on different sequence lengths, respectively. Wenxuan Zeng, Ye Dong, Jinjin Zhou, Lei Wang 0251, Tao Wei 0002, Runsheng Wang, Meng Li 0004 |
NeurIPS | 2 |
| 2025 | VCR: Fast Private Set Intersection with Improved VOLE and CRT-BatchingabstractPrivate set intersection (PSI) allows two participants to compute the intersection of their private sets without revealing any additional information beyond the intersection itself. It is known that oblivious linear evaluation (OLE) can be used to construct the online efficient PSI protocol. However, oblivious transfer (OT) and fully homomorphic encryption (FHE)-based offline OLE generation are expensive, and the online computational complexity is super-linear and still a heavy burden for large-scale sets. In this paper, we propose VCR, an efficient PSI protocol from vector OLE (VOLE) with the offline-online paradigm. Concretely, we first propose the batched short VOLE protocol to reduce offline overhead for generating VOLE tuples. Then, we design a batched private membership test protocol from pre-computed VOLE to accelerate the online computation. Experiments demonstrate that VCR outperforms prior art. Compared to state-of-the-art work, we reduce the total communication costs (resp. running time) by 341× and 9.1× (resp. 6.5× and 2.5×) on average for OT and FHE-based protocols. Weizhan Jing, Xiaojun Chen 0004, Ye Dong, Yaxi Yang, Qiang Liu 0060 |
TrustCom | 4 |
| 2025 | FLock: Robust and Privacy-Preserving Federated Learning based on Practical Blockchain State ChannelsabstractFederated Learning (FL) is a distributed machine learning paradigm that allows multiple clients to train models collaboratively without sharing local data. Numerous works have explored security and privacy protection in FL, as well as its integration with blockchain technology. However, existing FL works still face critical issues. i) It is difficult to achieving poisoning robustness and data privacy while ensuring high model accuracy. Malicious clients can launch poisoning attacks that degrade the global model. Besides, aggregators can infer private data from the gradients, causing privacy leakages. Existing privacy-preserving poisoning defense FL solutions suffer from decreased model accuracy and high computational overhead. ii) Blockchain-assisted FL records iterative gradient updates on-chain to prevent model tampering, yet existing schemes are not compatible with practical blockchains and incur high costs for maintaining the gradients on-chain. Besides, incentives are overlooked, where unfair reward distribution hinders the sustainable development of the FL community. In this work, we propose FLock, a robust and privacy-preserving FL scheme based on practical blockchain state channels. First, we propose a lightweight secure Multi-party Computation (MPC)-friendly robust aggregation method through quantization, median, and Hamming distance, which could resist poisoning attacks against up to <50% malicious clients. Besides, we propose communication-efficient Shamir's secret sharing-based MPC protocols to protect data privacy with high model accuracy. Second, we utilize blockchain off-chain state channels to achieve immutable model records and incentive distribution. FLock achieves cost-effective compatibility with practical cryptocurrency platforms, e.g. Ethereum, along with fair incentives, by merging the secure aggregation into a multi-party state channel. In addition, a pipelined Byzantine Fault-Tolerant (BFT) consensus is integrated where each aggregator can reconstruct the final aggregated results. Lastly, we implement FLock and the evaluation results demonstrate that FLock enhances robustness and privacy, while maintaining efficiency and high model accuracy. Even with 25 aggregators and 100 clients, FLock can complete one secure aggregation for ResNet in 2 minutes over a WAN. FLock successfully implements secure aggregation with such a large number of aggregators, thereby enhancing the fault tolerance of the aggregation. Ye Dong, Yizhong Liu, Tingyu Fan, Dawei Li 0009, Zhenyu Guan 0002, Jianwei Liu 0001, Jianying Zhou 0001 |
WWW | 2 |
| 2025 | FedShelter: Efficient privacy-preserving federated learning with poisoning resistance for resource-constrained IoT network
Tingyu Fan, Xiaojun Chen 0004, Ye Dong, Weizhan Jing, Zhendong Zhao |
Comput. Networks | 4 |
| 2025 | Maliciously Secure Circuit Private Set Intersection via SPDZ-Compatible Oblivious PRFabstractCircuit Private Set Intersection (Circuit-PSI) allows two parties to compute a function f on items in the intersection of their input sets without revealing items in the intersection set. It is a well-known variant of PSI and has numerous practical applications. However, existing Circuit-PSI protocols only provide security against semi-honest adversaries. A straightforward approach to constructing a maliciously secure Circuit-PSI is to extend a pure garbled-circuit-based PSI (NDSS'12) to a maliciously secure circuit-PSI, but it will not be concretely efficient. Another is converting state-of-the-art semi-honest Circuit-PSI protocols (EUROCRYPT'21; PoPETS'22) to be secure in the malicious setting. However, it will come across the consistency issue (EUROCRYPT'11) since parties can not guarantee the inputs of the function f stay unchanged as obtained from the last step. This paper tackles the previously mentioned issue by presenting the first maliciously secure Circuit-PSI protocol. Our key innovation, the Distributed Dual-key Oblivious Pseudorandom Function (DDOPRF), enables the oblivious evaluation of secret-shared inputs using dual keys within the SPDZ MPC framework. Notably, this construction seamlessly ensures fairness within the Circuit-PSI. Compared to the state-of-the-art semi-honest Circuit-PSI protocol (PoPETS'22), experimental results demonstrate that our malicious Circuit-PSI protocol not only reduces around 5x communication costs but also enhances efficiency, particularly for modest input sets (<= 2^{14}) in the case of the WAN setting with high latency and limited bandwidth. Yaxi Yang, Xiaojian Liang, Xiangfu Song, Ye Dong, Linting Huang, Hongyu Ren, Changyu Dong, Jianying Zhou 0001 |
Proc. Priv. Enhancing Technol. | 4 |
| 2025 | XGT: Fast and Secure Decision Tree Training and Inference on GPUsabstractThe decision tree (DT) model is widely usedin various applications due to its versatility, speed, and interpretability. However, outsourcing DT training and inference to cloud platforms raises data privacy concerns. While significant strides have been made in developing private DT training and inference using cryptography such as Secure Multi-Party Computation (MPC), the performance is still not ideal in real-world applications. Only a few recent works have explored using GPUs to enhance the performance of MPC-based deep learning. Nevertheless, data-dependent operations and the high communication costs inherent in MPC-based DT make the integration of GPUs a challenge. We introduce the eXpress GPU-based Tree (XGT), a fast MPC-based framework for private DT training and inference on GPUs.XGTconverts the majority of operations in training and inference into parallelizable matrix operations, supplemented by various optimizations, including matrix dimension reductions. This innovative design leads to substantial reductions in communication overhead while maintaining the critical property of obliviousness.XGTalso achieves a stronger security guarantee, where all data items, the tree shape, access patterns, and data distributions generated during the training and inference are protected.XGTonly reveals the tree depth. The experimental results show thatXGTis up to$278{\times }$faster than the previous most efficient CPU-based approach.XGToutperforms the latest GPU-based DT work by$41{\times }$. For inference,XGTis up to$2,800{\times }$faster than previous CPU-based inference schemes and at least$18 \times$faster than GPU-based. Qifan Wang 0003, Shujie Cui, Lei Zhou 0023, Ye Dong, Jianli Bai, Yun Sing Koh, Giovanni Russello |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | MD-SONIC: Maliciously-Secure Outsourcing Neural Network Inference With Reduced Online CommunicationabstractWith the widespread deployment of Deep-Learning-as-a-Service, secure multi-party computation-based outsourcing neural network (NN) inference has garnered significant attention for its high-security guarantee. Nevertheless, under the dishonest-majority setting with malicious adversaries, prior secure inference works are still costly in terms of communication and run-time. Additionally, existing outsourcing frameworks impose a substantial client-side design, which leads to obstacles in resource-constrained devices. To address the above challenges, we propose MD-SONIC, an online efficient and maliciously-secure framework for outsourcing NN inference with a dishonest majority. We first construct communication-efficient n-party protocols for the basic primitives such as fixed-point multiplication and most significant bit extraction by combining mask-sharing and TinyOT-sharing with SPD$\mathbb {Z}_{2^{k}}$seamlessly. Then, we build fast secure blocks for the widely used NN operators, including matrix multiplication, ReLU, and Maxpool, on top of our basic primitives. To enable an arbitrary number of users to outsource the secure inference task to n computing servers, we propose a lightweight-client and fast$\Sigma $paradigm named SPIN, stemming from zero-knowledge proofs. Our SPIN can be instantiated into a set of efficient outsourcing protocols over multiple algebraic structures (e.g., finite field and ring). We also conduct extensive evaluations of MD-SONIC on various neural networks. Compared to the work by Damgård et al. (IEEE S&P’19) and MD-ML (USENIX Security’24), we achieve up to$594.4\times $and$45.1\times $online communication improvements, and improve the online execution time by at most$14.3\times $(resp.$20.5\times $) and$1.8\times $(resp.$2.3\times $) in LAN (resp. WAN). Xiaojun Chen 0004, Ye Dong, Rui Hou 0001, Qiang Liu 0060 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Lightweight Secure Aggregation for Personalized Federated Learning with Backdoor ResistanceabstractExisting federated learning (FL) systems are highly vulnerable in terms of security and privacy due to their distributed architecture, facing poisoning attacks and inference attacks from adversaries. Some prior works have combined poisoning defenses with cryptographic tools: Secure Multi-Party Computation, Zero-Knowledge Proof, and Homomorphic Encryption to propose robust secure aggregation methods that provide security and privacy preservation for FL. Recently, Qin et al. (KDD’23) demonstrate that personalized federated learning (pFL) can effectively resist backdoor injection in poisoning attacks. In this paper, we analyze that as the number of malicious attackers increases, pFL remains vulnerable to backdoor attacks. Moreover, we reveal that current robust secure aggregation methods fail to offer efficient and robust backdoor defense for pFL. Therefore, we propose FLIGHT, a robust secure aggregation method for pFL. It implements a lightweight backdoor detection through a two-stage personalized defense mechanism and ensures privacy preservation using communication-efficient two-party secure computation (2PC) protocols. Extensive experiments on diverse datasets and neural networks validate that FLIGHT decreases run-time up to 64× compared by prior work RoFL (S&P’23), and 42× compared to FLAME (USENIX Security’22). Tingyu Fan, Xiaojun Chen 0004, Ye Dong, Yuexin Xuan, Weizhan Jing |
ACSAC | 3 |
| 2024 | Roger: A Round Optimized GPU-Friendly Secure Inference FrameworkabstractSecure neural network inference provides a promising solution to preserve the privacy of Deep Learning as a Service (DLaaS), but its substantial communication and computation overhead remain challenging. Recent works such as GForce [1] and Piranha [2] have introduced GPU-friendly secure inference protocols with improved computation efficiency, yet these approaches are either limited to supporting specialized-trained networks or expensive in communication. As a consequence, there remain potential improvements in functionalities and communication efficiency. To address the above challenges, we introduce Roger, a two-party secure inference framework with semi-honest security, designed to support general neural network inference with a reduced number of round complexity. Drawing inspiration from ABY2.0 [3], we propose the Partial-Fix technology, which fixes the share of one participant during the offline phase to improve its computation efficiency. Then, an online communication-free protocol for secure linear layer computation and a constant-round secure comparison protocol are proposed upon Partial-Fix. Implemented on top of Piranha, the experiments demonstrate that for the CIFAR10 dataset, a single inference on VGG16 requires only 0.40 seconds. In comparison to GForce (resp. Piranha), Roger at least achieves 1.20× (resp. 1.94×) improvement in LAN setting in terms of throughput. Xiaojun Chen 0004, Ye Dong, Weizhan Jing, Tingyu Fan |
ICC | 3 |
| 2024 | Comet: Communication-Efficient Batch Secure Three-Party Neural Network Inference with Client-AidingabstractSecure neural network inference enables server (model provider) and client to perform neural network inference without leaking their private inputs. Existing SOTA three-party computation (3PC) inference works emerge challenges on two fronts: i) GPU-accelerated CryptGPU (S&P'21) and P-FALCON (USENIX Security'22) face challenges related to high communication overhead. ii) communication-efficient Meteor(www'23) raises more computation burden and GPU memory usage. These challenges result in lower efficiency when handling large-scale batch inference requests on resource-constrained devices. In this work, we propose Comet,a communication-efficient batch secure three-party inference framework with client-aiding, which achieves semi-honest security in honest majority without collusion between the client and the servers. First, we propose client-aided sharing semantics, which leverages client-generated random values to enhance online communication efficiency. We also design efficient 3PC protocols for neural network operators based on GPU, improving the computational efficiency of both linear and nonlinear layers. Furthermore, we address the tradeoff between communication cost and GPU memory utilization, surpassing SOTA by 1.3-1.9× in communication, 1.5-3.8× in runtime on large-scale batch inference tasks. Tingyu Fan, Xiaojun Chen 0004, Ye Dong, Weizhan Jing |
ICC | 3 |
| 2024 | An Effective Multiple Private Set Intersection
Qiang Liu 0060, Xiaojun Chen 0004, Weizhan Jing, Ye Dong |
SecureComm (1) | 4 |
| 2024 | GTree: GPU-friendly Privacy-preserving Decision Tree Training and InferenceabstractOutsourcing Decision tree (DT) training and inference to cloud platforms raises privacy concerns. Recent Secure Multi-Party Computation (MPC)-based methods are hindered by heavy overhead. Few recent studies explored GPUs to improve MPC-protected deep learning, yet integrating GPUs into MPC-protected DT with massive data-dependent operations remains challenging, raising question: can MPC-protected DT training and inference fully leverage GPUs for optimal performance?We present GTree, the first scheme that exploits GPU to accelerate MPC-protected secure DT training and inference. GTree is built across 3 parties who jointly perform DT training and inference with GPUs. GTree is secure against semi-honest adversaries, ensuring that no sensitive information is disclosed. GTree offers enhanced security than prior solutions, which only reveal tree depth and data size while prior solutions also leak tree structure. With our oblivious array access, access patterns on GPU are also protected. To harness the full potential of GPUs, we design a novel tree encoding method and craft our MPC protocols into GPU-friendly versions. GTree achieves ~11× and ~21× improvements in training SPECT and Adult datasets, compared to prior most efficient CPU-based work. For inference, GTree outperforms the prior most efficient work by 126× when inferring 104instances with a 7-level tree. Qifan Wang 0003, Shujie Cui, Lei Zhou 0023, Ye Dong, Jianli Bai, Yun Sing Koh, Giovanni Russello |
TrustCom | 4 |
| 2024 | PODI: A Private Object Detection Inference framework for autonomous vehicles
Ye Dong, Ximeng Liu |
Knowl. Based Syst. | 3 |
| 2023 | Practical and General Backdoor Attacks Against Vertical Federated Learning
Yuexin Xuan, Xiaojun Chen 0004, Zhendong Zhao, Bisheng Tang, Ye Dong |
ECML/PKDD (2) | 5 |
| 2023 | Meteor: Improved Secure 3-Party Neural Network Inference with Reducing Online Communication CostsabstractSecure neural network inference has been a promising solution to private Deep-Learning-as-a-Service, which enables the service provider and user to execute neural network inference without revealing their private inputs. However, the expensive overhead of current schemes is still an obstacle when applied in real applications. In this work, we present Meteor, an online communication-efficient and fast secure 3-party computation neural network inference system aginst semi-honest adversary in honest-majority. The main contributions of Meteor are two-fold: i) We propose a new and improved 3-party secret sharing scheme stemming from the linearity of replicated secret sharing, and design efficient protocols for the basic cryptographic primitives, including linear operations, multiplication, most significant bit extraction, and multiplexer. ii) Furthermore, we build efficient and secure blocks for the widely used neural network operators such as Matrix Multiplication, ReLU, and Maxpool, along with exploiting several specific optimizations for better efficiency. Our total communication with the setup phase is a little larger than SecureNN (PoPETs’19) and Falcon (PoPETs’21), two state-of-the-art solutions, but the gap is not significant when the online phase must be optimized as a priority. Using Meteor, we perform extensive evaluations on various neural networks. Compared to SecureNN and Falcon, we reduce the online communication costs by up to 25.6 × and 1.5 ×, and improve the running-time by at most 9.8 × (resp. 8.1 ×) and 1.5 × (resp. 2.1 ×) in LAN (resp. WAN) for the online inference. Ye Dong, Xiaojun Chen 0004, Weizhan Jing, Kaiyun Li, Weiping Wang 0005 |
WWW | 1 |
| 2023 | FlexBNN: Fast Private Binary Neural Network Inference With Flexible Bit-WidthabstractAdvancements in deep learning enable neural network (NN) inference to be a service, but service providers and clients want to keep their inputs secret for privacy protection.Private Inferenceis the task of evaluating NN without leaking private inputs. Existing secure multiparty computation (MPC)-based solutions mainly focus on fixed bit-width methodology, such as 32 and 64 bits. Binary Neural Network (BNN) is efficient when evaluated in MPC and has achieved reasonable accuracy for commonly used datasets, but prior private BNN inference solutions, which focus onBoolean Circuits, are still costly in communication and run-time. In this paper, we introduce FLEXBNN, a fast private BNN inference framework using three-party computation (3PC) inArithmetic Circuitsagainst semi-honest adversaries with honest-majority. In FLEXBNN, we propose to employ flexible and small bit-width equipped with a seamless bit-width conversion method and design several specific optimizations towards the basic operations: i) We propose bit-width determination methods for Matrix Multiplication and Sign-based Activation function. ii) We integrate Batch Normalization and Max-Pooling into the Sign-based Activation function for better efficiency. iii) More importantly, we achieve seamless bit-width conversion within the Sign-based Activation function with no additional cost. Extensive experiments illustrate that FLEXBNN outperforms state-of-the-art solutions in communication, run-time, and scalability. On average, FLEXBNN is 11× faster than XONN (USENIX Security’ 19) in LAN, 46× (resp. 9.3×) faster than QUOTIENT (ACM CCS’19) in LAN (resp. WAN), 10× faster than BANNERS (ACM IH&MMSec’21) in LAN, and 1.1-2.9× (resp. 1.5-2.7×) faster than FALCON (semi-honest, PoPETs’21) in LAN (resp. WAN), and improves the respective communication by 500×, 127×, and 1.3-1.5× compared to XONN, BANNERS, and FALCON. Ye Dong, Xiaojun Chen 0004, Xiangfu Song, Kaiyun Li |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | DEFEAT: Deep Hidden Feature Backdoor Attacks by Imperceptible Perturbation and Latent Representation ConstraintsabstractBackdoor attack is a type of serious security threat to deep learning models. An adversary can provide users with a model trained on poisoned data to manipulate prediction behavior in test stage using a backdoor. The backdoored models behave normally on clean images, yet can be activated and output incorrect prediction if the input is stamped with a specific trigger pattern. Most existing backdoor attacks focus on manually defining imperceptible triggers in input space without considering the abnormality of triggers' latent representations in the poisoned model. These attacks are susceptible to backdoor detection algorithms and even visual inspection. In this paper, We propose a novel and stealthy backdoor attack - DEFEAT. It poisons the clean data using adaptive imperceptible perturbation and restricts latent representation during training process to strengthen our attack's stealthiness and resistance to defense algorithms. We conduct extensive experiments on multiple image classifiers using real-world datasets to demonstrate that our attack can 1) hold against the state-of-the-art defenses, 2) deceive the victim model with high attack success without jeopardizing model utility, and 3) provide practical stealthiness on image data. Zhendong Zhao, Xiaojun Chen 0004, Yuexin Xuan, Ye Dong, Dakui Wang, Kaitai Liang |
CVPR | 4 |
| 2022 | ABNN2: secure two-party arbitrary-bitwidth quantized neural network predictionsabstractData privacy and security issues are preventing a lot of potential on-cloud machine learning as services from happening. In the recent past, secure multi-party computation (MPC) has been used to achieve the secure neural network predictions, guaranteeing the privacy of data. However, the cost of the existing two-party solutions is expensive and they are impractical in real-world setting. Liyan Shen, Ye Dong, Binxing Fang, Jinqiao Shi, Shengli Pan 0001, Ruisheng Shi |
DAC | 2 |
| 2022 | Distributed Fog Computing and Federated-Learning-Enabled Secure Aggregation for IoT DevicesabstractFederated learning (FL), as a prospective way to process and analyze the massive data from the Internet of Things (IoT) devices, has attracted increasing attention from academia and industry. However, considering the unreliable nature of IoT devices, ensuring the efficiency of FL while protecting the privacy of devices’ input data is a challenging task. To address these issues, we propose a secure aggregation protocol based on efficient additive secret sharing in the fog-computing (FC) setting. As the secure aggregation is performed frequently in the training process of FL, the protocol should have low communication and computation overhead. First, we use a fog node (FN) as an intermediate processing unit to provide local services which can assist the cloud server aggregated the sum during the training process. Second, we design a light Request-then-Broadcast method to ensure our protocol has the robustness to dropped-out clients. Our protocol also provides two simple new client selection methods. The security and performance of our protocol are analyzed and compared with existed schemes. We conduct experiments on high-dimensional inputs, and our experimental results demonstrate about 24–$168\times $improvement in computation overhead and 87–$287\times $improvement in communication overhead compared to Google’s secure aggregation protocol (Bonwatiwz et al. CCS17). Ye Dong, Hao Wang 0007, Han Jiang 0001, Qiuliang Xu |
IEEE Internet Things J. | 2 |
| 2021 | FLOD: Oblivious Defender for Private Byzantine-Robust Federated Learning with Dishonest-Majority
Ye Dong, Xiaojun Chen 0004, Kaiyun Li, Dakui Wang |
ESORICS (1) | 1 |
| 2020 | An Efficient 3-Party Framework for Privacy-Preserving Neural Network Inference
Liyan Shen, Xiaojun Chen 0004, Jinqiao Shi, Ye Dong, Binxing Fang |
ESORICS (1) | 4 |
| 2020 | EaSTFLy: Efficient and secure ternary federated learning
Ye Dong, Xiaojun Chen 0004, Liyan Shen, Dakui Wang |
Comput. Secur. | 1 |
| 2019 | Privacy-Preserving Distributed Machine Learning Based on Secret Sharing
Ye Dong, Xiaojun Chen 0004, Liyan Shen, Dakui Wang |
ICICS | 1 |
| 2018 | Efficient and Private Set Intersection of Human Genomes
Liyan Shen, Xiaojun Chen 0004, Dakui Wang, Binxing Fang, Ye Dong |
BIBM | 5 |
| 2008 | Three-Dimensional Parallel Electromagnetic Code with Complex GeometryabstractA three-dimensional parallel electromagnetic code is developed to simulate high current electron devices with complex geometry, where particle-in-cell method is used. For the complex geometry, we treat geometrically complex features embeds irregular geometry information into a Cartesian mesh. Also, a time integration algorithm is provided to solve the fully electromagnetic problem. A typical device with complex geometry is simulated by the parallel code on 128 cpus. Jun Chen 0032, Ye Dong |
HPCC | 2 |