VLDB 2026 Research / reviewers in the wild / expert
Chaowen Chang
dblp:75/259
· DBLP profile ↗
6ranked-venue papers
0as first author
4since 2021 · last 2026
0000-0002-3583-9880ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 since 2021Computer networks · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AP-PPFL: an anti-poisoning privacy-preserving federated learning methodabstractAbstract Federated Learning (FL) has been widely used in Internet of Things (IoT) environments as a promising decentralized framework capable of collaborative model training without exposing local data. Despite its advantages, FL still encounters significant security challenges. In particular, semi-honest servers can potentially infer private information from the gradients shared by clients. Additionally, FL’s distributed nature opens up vulnerabilities to adversarial behavior, where malicious clients may submit manipulated gradients to degrade the global model's accuracy or hinder its convergence. Addressing privacy and robustness simultaneously is an enormous challenge, as most privacy-preserving approaches focus on securing gradients through encryption or noise injection, which obstructs the identification of malicious clients—an essential step in poisoning defense. To resolve this conflict, this work introduces AP-PPFL, a federated learning framework that integrates both privacy protection and poisoning defense. The proposed approach incorporates a voting-based parameter importance evaluation strategy and a cosine similarity-based mechanism to filter out harmful gradients. Furthermore, it leverages Paillier homomorphic encryption within a dual-server setup to maintain gradient confidentiality while enabling secure computation directly over encrypted data. Compared with conventional methods, AP-PPFL achieves a balanced improvement in both privacy-preserving and attack resilience, with comprehensive security analysis provided. Yongfei Li, Chaowen Chang, Yaohui Hao |
Cybersecur. | 3 |
| 2025 | A Cuckoo Filter-Based Anomaly Detection and Localization Mechanism for SDN-Based Multidomain IoT
Chaowen Chang, Jingxu Xiao |
WASA (2) | 3 |
| 2025 | Multi-probability sampling-based detection of malicious switching nodes in SDN
Jingxu Xiao, Chaowen Chang, Lu Yuan 0002 |
Comput. Secur. | 2 |
| 2024 | Detection and Localization of Malicious Nodes in Internet of Things Based on SDN
Jingxu Xiao, Chaowen Chang, Yang Chenli |
WASA (2) | 2 |
| 2019 | Re-definable access control over outsourced data in cloud storage systemsabstractThere is an increasing concern for data privacy when people outsource their data to remote cloud storage servers. To secure outsourced data, cloud users are suggested to employ cryptographic encryption to specify access policies such that only users meeting the policies can access the data. After the application of an encryption, however, users are difficult to modify their access policies since the policies were already formulated by the encryption. To address such problem, the authors propose a new approach referred to as re‐definable access control (RDAC). The RDAC utilises identity‐based encryption (IBE) and attribute‐based encryption (ABE) to secure outsourced data and allows users to choose either to achieve access control according to their capability and requirements. Moreover, the RDAC allows users to change simple access policies into fine‐grained access policies by converting IBE encrypted files into ABE encrypted ones, without leaking the underlying data. Surprisingly, the access policy conversion does not require the users to perform any costly computation, nor the storage servers to be disturbed. The authors prove the security of RDAC under a rigorous definition, and empirically show that the introduction of the conversion incurs almost no costs to the outsourcing and access procedures. Chaowen Chang, Zhimin Guo, PeiSheng Han |
IET Inf. Secur. | 2 |
| 2008 | Police Security Communication over Public Cellular Network InfrastructureabstractThe availability of a communication channel that could be everywhere accessible, possibly via wireless devices is a constant matter for the police force. The well-developed public cellular network infrastructure and widespread mobile device can provide with such features, but the lack of security makes it unsuitable for transmitting confidential data. In this paper, we propose a security framework for mobile police information system to transmit sensitive information confidentially over the public cellular network, and describe the authentication and communication protocol in detail. The test on a physical GSM based cellular network reveals that it is suitable for actual needs both in speed and security. Rongyu He, Chaowen Chang, Guolei Zhao |
NCA | 2 |