Bo Zeng 0006

dblp:74/2630-6 · DBLP profile ↗
← Back
17ranked-venue papers
4as first author
17since 2021 · last 2026
0000-0002-3334-6150ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 10 · 3 first-author · 10 since 2021Computer networks · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 PCFormer: Accelerating Privacy-preserving Transformer Inference by Partition and Combination
abstract
In recent years, transformer-based models have achieved remarkable success in sensitive domains, including healthcare, finance and personalized services, but their deployment raises significant privacy concerns. Existing secure inference studies have introduced cryptographic techniques such as Homomorphic Encryption (HE) and Secure Multi-Party Computation (MPC). However, these approaches either target isolated model components or incur prohibitive computational and communication overheads, failing to support latency-sensitive or resource-limited environments. In our investigation, we identify substantial redundancy in the nonlinear operations and their alternation with linear layers in deep learning. Motivated by this observation, we propose PCFormer, a universal optimization methodology tailored for sequences of linear and nonlinear computations in the Transformer. PCFormer introduces structure-aware partition and combination techniques specially designed for Multi-Head Attention (MHA) and Feed-Forward Network (FFN). Specifically, we reveal the discrete sources of redundancy in the Softmax and GeLU functions during inference, implementing partitions at the token and channel levels, respectively. Subsequently, these reductions are then combined with the preceding and succeeding linear operations, thereby enhancing both computational and communication efficiency. Experimental results on GLUE benchmarks demonstrate that PCFormer achieves a 1.9× speedup in both computation and communication without compromising accuracy, compared to existing privacy-preserving Transformer frameworks. Furthermore, we demonstrate that PCFormer generalizes effectively to other deep learning architectures involving structured linear-nonlinear compositions under cryptographic constraints.
Bo Zeng 0006, Zhi Pang, Tian Wu 0004, Geying Yang, Lina Wang 0001, Run Wang 0001
AAAI1
2026 Privacy-Friendly Adaptation of Vision Transformers for Communication and Latency-Efficient Private Inference
abstract
The advent of machine learning as a service (MLaaS) has necessitated secure multi-party computation (MPC)-based private inference (PI) to address the privacy concerns that arise when web servers offer query inference services to users. However, the formal privacy protection incurs substantial communication and latency overheads, particularly for large models such as vision transformers (ViTs). Existing methods either ignore the inherent attention dependencies or naively extend CNN optimizations to ViTs despite their structural discrepancies, resulting in sub-optimal performance. In this paper, we co-design the MPC and architectural properties of ViT and propose SecViT, an efficient and secure inference framework that automatically adapts ViTs into privacy-friendly counterparts with optimal attention configurations at different layers and tokens under MPC, balancing model capability and efficiency. SecViT features an MPC-efficient, layer-dependent and load-balancing attention representation adapter to facilitate feature reuse across multiple highly correlated layers without impacting accuracy. To further reduce the inference cost, SecViT also develops fine-grained composite attention and activation approximation algorithms to achieve superior accuracy-efficiency trade-offs. Experiments show that SecViT reduces communication by 6.0x and latency by 4.6x with iso-accuracy over MPCViT, and improves accuracy by 4.92% with 1.6x lower latency over PriViT on Tiny-ImageNet. Compared with state-of-the-art PI protocols, SecViT further achieves 10.0x communication saving and 7.9x latency reduction over BumbleBee.
Zhi Pang, Chenhao Liu, Shuwang Xu, Yadi Wu, Bo Zeng 0006
WWW8
2026 SFI: A Practical and Efficient Backdoor Attack Framework Against Split Learning
abstract
Split learning is a computing resource-friendly distributed learning framework that protects client training data by splitting the model between the client and server. Previous work has proved that split learning faces a severe risk of privacy leakage, as a malicious server can recover the client's private data by hijacking the training process. In this paper, we explore the vulnerability of split learning to server-side backdoor attacks, where our goal is to compromise the model's integrity. Since the server-side attacker cannot access the training data and client model in split learning, the traditional poisoning-based backdoor attack methods are no longer applicable. Therefore, constructing backdoor attacks in split learning poses significant challenges. Our strategy involves the attacker establishing a shadow model on the server side that can encode backdoor samples and guide the client model in learning from this model during the training process, thereby enabling the client to acquire the same capability. Based on these insights, we propose a backdoor attack framework named SFI. Our attack framework minimizes assumptions about the attacker's background knowledge and ensures that the attack remains imperceptible to the client. We implement SFI on various benchmark datasets, and extensive experimental results demonstrate its effectiveness and generality.
Fangchao Yu, Bo Zeng 0006, Zhi Pang, Lina Wang 0001
IEEE Trans. Dependable Secur. Comput.2
2025 LPPAC: Lightweight privacy-preserving distributed payments with access control
Bo Zeng 0006, Tian Wu 0004, Fangchao Yu, Geying Yang, Lina Wang 0001
Comput. Networks1
2025 FedMP: A multi-pronged defense algorithm against Byzantine poisoning attacks in federated learning
Lina Wang 0001, Fangchao Yu, Bo Zeng 0006, Zhi Pang
Comput. Networks4
2025 PrivCore: Multiplication-activation co-reduction for efficient private inference
Zhi Pang, Lina Wang 0001, Fangchao Yu, Bo Zeng 0006, Shuwang Xu
Neural Networks5
2025 GAN-based data reconstruction attacks in split learning
Bo Zeng 0006, Sida Luo, Fangchao Yu, Geying Yang, Lina Wang 0001
Neural Networks1
2025 SplitAUM: Auxiliary Model-Based Label Inference Attack Against Split Learning
abstract
Split learning has emerged as a practical and efficient privacy-preserving distributed machine learning paradigm. Understanding the privacy risks of split learning is critical for its application in privacy-sensitive scenarios. However, previous attacks against split learning generally depended on unduly strong assumptions or non-standard settings advantageous to the attacker. This paper proposes a novel auxiliary model-based label inference attack framework against learning, namedSplitAUM.SplitAUMfirst builds an auxiliary model on the client side using intermediate representations of the cut layer and a small number of dummy labels. Then, the learning regularization objective is carefully designed to train the auxiliary model and transfer the knowledge of the server model to the client. Finally,SplitAUMuses the auxiliary model output on local data to infer the server’s privacy label. In addition, to further improve the attack effect, we use semi-supervised clustering to initialize the dummy labels of the auxiliary model. SinceSplitAUMrelies only on auxiliary models, it is highly scalable. We conduct extensive experiments on three different categories of datasets, comparing four typical attacks. Experimental results demonstrate thatSplitAUMcan effectively infer privacy labels and outperform existing attack frameworks in challenging yet practical scenarios. We hope our work paves the way for future analyses of the security of split learning.
Xiaowei Chuo, Fangchao Yu, Bo Zeng 0006, Zhi Pang, Lina Wang 0001
IEEE Trans. Netw. Serv. Manag.4
2024 Chronic Poisoning: Backdoor Attack against Split Learning
abstract
Split learning is a computing resource-friendly distributed learning framework that protects client training data by splitting the model between the client and server. Previous work has proved that split learning faces a severe risk of privacy leakage, as a malicious server can recover the client's private data by hijacking the training process. In this paper, we first explore the vulnerability of split learning to server-side backdoor attacks, where our goal is to compromise the model's integrity. Since the server-side attacker cannot access the training data and client model in split learning, the traditional poisoning-based backdoor attack methods are no longer applicable. Therefore, constructing backdoor attacks in split learning poses significant challenges. Our strategy involves the attacker establishing a shadow model on the server side that can encode backdoor samples and guiding the client model to learn from this model during the training process, thereby enabling the client to acquire the same capability. Based on these insights, we propose a three-stage backdoor attack framework named SFI. Our attack framework minimizes assumptions about the attacker's background knowledge and ensures that the attack process remains imperceptible to the client. We implement SFI on various benchmark datasets, and extensive experimental results demonstrate its effectiveness and generality. For example, success rates of our attack on MNIST, Fashion, and CIFAR10 datasets all exceed 90%, with limited impact on the main task.
Fangchao Yu, Bo Zeng 0006, Zhi Pang, Lina Wang 0001
AAAI2
2024 FedGR: Genetic Algorithm and Relay Strategy Based Federated Learning
abstract
Federated learning (FL) is a privacy-preserving distributed machine learning approach that enables multiple parties to collaboratively train machine learning models without sharing local data. However, compared with the models trained on independent and identically distributed (IID) data, existing methods still face significant degradation in model performance when running on non-IID data. To solve this problem, we propose a federated learning framework based on genetic algorithm and relay strategy in this paper. The framework groups clients according to their local data distribution using genetic algorithm. After obtaining the optimal grouping result, a relay strategy is used to train and aggregate models within each group. Extensive experiments on three benchmark datasets show that FedGR significantly outperforms other state-of-the-art federated learning algorithms on various image classification tasks. The source code is available at https://github.com/zyfhylyh/FedGR.
Yifei Zeng, Fangchao Yu, Bo Zeng 0006, Zhi Pang, Lina Wang 0001
CSCWD4
2024 Personalized and privacy-enhanced federated learning framework via knowledge distillation
Fangchao Yu, Lina Wang 0001, Bo Zeng 0006, Rongwei Yu
Neurocomputing3
2024 StreamliNet: Cost-aware layer-wise neural network linearization for fast and accurate private inference
Zhi Pang, Lina Wang 0001, Fangchao Yu, Bo Zeng 0006
Inf. Sci.5
2024 SIA: A sustainable inference attack framework in split learning
Fangchao Yu, Lina Wang 0001, Bo Zeng 0006, Tian Wu 0004, Zhi Pang
Neural Networks3
2023 Feature Sniffer: A Stealthy Inference Attacks Framework on Split Learning
Sida Luo, Fangchao Yu, Lina Wang 0001, Bo Zeng 0006, Zhi Pang
ICANN (7)4
2023 PatchFinger: A Model Fingerprinting Scheme Based on Adversarial Patch
Bo Zeng 0006, Kunhao Lai, Jianpeng Ke, Fangchao Yu, Lina Wang 0001
ICONIP (2)1
2023 A Modified Gray Wolf Optimizer-Based Negative Selection Algorithm for Network Anomaly Detection
abstract
Intrusion detection systems are crucial in fighting against various network attacks. By monitoring the network behavior in real time, possible attack attempts can be detected and acted upon. However, with the development of openness and flexibility of networks, artificial immunity‐based network anomaly detection methods lack continuous adaptability and hence have poor detection performance. Thus, a novel framework for network anomaly detection with adaptive regulation is built in this paper. First, a heuristic dimensionality reduction algorithm based on unsupervised clustering is proposed. This algorithm uses the correlation between features to select the best subset. Then, a hybrid partitioning strategy is introduced in the negative selection algorithm (NSA), which divides the feature space into a grid based on the sample distribution density and generates specific candidate detectors in the boundary grid to effectively mitigate the holes caused by boundary diversity. Finally, the NSA is improved by self‐set clustering and a novel gray wolf optimizer to achieve adaptive adjustment of the detector radius and position. The results show that the proposed NSA algorithm based on mixed hierarchical division and gray wolf optimization (MDGWO‐NSA) achieves a higher detection rate, lower false alarm rate, and better generation quality than other network anomaly detection algorithms.
Geying Yang, Lina Wang 0001, Rongwei Yu, Junjiang He, Bo Zeng 0006, Tian Wu 0004
Int. J. Intell. Syst.5
2023 How to backdoor split learning
Fangchao Yu, Lina Wang 0001, Bo Zeng 0006, Zhi Pang, Tian Wu 0004
Neural Networks3