Chuan Ma 0001

dblp:87/5241-1 · DBLP profile ↗
← Back
65ranked-venue papers
15as first author
53since 2021 · last 2026
0000-0001-7819-4544ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 22 · 9 first-author · 13 since 2021Security and privacy · 15 · 1 first-author · 14 since 2021Artificial intelligence and machine learning · 10 · 10 since 2021Databases, data management, data science and information retrieval · 8 · 2 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 1 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 since 2021Systems, architecture and hardware · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 TVChain: Leveraging Textual-Visual Prompt Chains for Jailbreaking Large Vision-Language Models
abstract
Large Vision-Language Models (LVLMs) enhance the capabilities of Large Language Models by integrating visual inputs, thereby enabling advanced multimodal reasoning across diverse applications. However, these enhanced reasoning capabilities introduce new security risks, particularly to jailbreaking attacks that bypass built-in safety mechanisms to elicit harmful or unauthorized outputs. While recent efforts have explored adversarial and typographic prompts, most existing attacks suffer from three key limitations: reliance on auxiliary models, limited effectiveness in black-box scenarios, and inadequate exploitation of the LVLMs' intrinsic reasoning abilities. In this work, we propose TVChain, a novel black-box jailbreaking framework that explicitly intervenes in both the visual and textual reasoning processes of LVLMs. TVChain decomposes malicious prompts into a sequence of semantically meaningful sub-images that represent relevant objects and behaviors, thereby circumventing direct exposure of illicit content. In parallel, a carefully designed chain-of-thought (CoT) textual prompt is employed to steer the model's reasoning toward reconstructing the intended activity in a covert yet effective manner. We demonstrate that this compositional prompting strategy reduces the likelihood of triggering safety mechanisms while preserving attack efficacy. Extensive evaluations on eleven LVLMs (seven open-source and four commercial) across two benchmark datasets and three state-of-the-art defenses validate the effectiveness and robustness of TVChain.
Hao Yu 0017, Ke Liang 0006, Junxian Duan, Jun Wang 0118, Siwei Wang 0001, Chuan Ma 0001, Xinwang Liu 0002
AAAI6
2026 HiGoE: Hierarchical Graph of Evidence to Enhance Retrieval-Augmented Generation for Long-context Summarization
abstract
Long-context summarization is pivotal for extracting core insights from extensive documents.While Large Language Models (LLMs) show remarkable capabilities, they frequently encounter attention dilution and hallucination with lengthy inputs.Retrieval-Augmented Generation (RAG) partially mitigates this, but conventional RAG relies on shallow similarity retrieval of fragmented chunks, failing to capture high-level thematic structures and longrange dependencies.Although graph-based RAG approaches have emerged to address these structural limitations, existing solutions, such as Graph of Records (GoR), critically suffer from a fundamental flaw: they paradoxically re-introduce hallucinations by constructing graphs based on unreliable, LLM-generated responses.To overcome these challenges, we introduce Hierarchical Graph of Evidence (HiGoE) (Code link https://github.com/ tkw123/HiGOE).HiGoE redefines the retrieval process by replacing unreliable chunk-based methods with a filtered proposition-evidence graph, ensuring verifiable fact grounding and substantially reducing hallucination.Moreover, HiGoE leverages Personalized PageRank (PPR) to cluster related nodes into thematic hierarchies, thereby restoring global document structure and effectively mitigating attention dilution.To model complex, multi-level relations beyond mere shallow similarity, we develop an Enhanced Graph Attention Network.Experiments show HiGoE consistently surpasses baselines in quality and efficiency.
Long Yuan 0001, Kaiwen Tian, Zi Chen 0003, Bolong Zheng, Chuan Ma 0001
ACL (1)5
2026 Abuse Resistant Traceability with Minimal Trust for Encrypted Messaging Systems
Zhongming Wang, Tao Xiang 0001, Xiaoguo Li, Guomin Yang, Biwen Chen, Ze Jiang, Jiacheng Wang 0001, Chuan Ma 0001, Robert H. Deng
NDSS8
2026 HiFi-WF: Toward Realistic Website Fingerprinting with Multi-tab and Subpage Recognition
abstract
Website Fingerprinting (WF) is an emerging traffic analysis technique that enables a passive adversary to infer which websites a user visits. However, most existing studies, whether in single-tab or multi-tab settings, rely on the unrealistic assumption that users only access website homepages, diverging significantly from real-world browsing behavior. Even recent works extending WF to subpages primarily focus on website-level identification, without distinguishing which specific subpages are visited, thereby limiting the attack's granularity and scope. In this paper, we propose HiFi-WF (Hierarchical Fine-grained Website Fingerprinting), a novel framework that breaks the homepage-only assumption and extends WF to multi-tab recognition and fine-grained subpage identification. We formulate the task as a hierarchical multi-label classification problem, jointly modeling the distinctions and correlations between homepages and subpages. To this end, HiFi-WF integrates a unified CNN-based extractor and layered encoder with a Feature Interaction Module based on multi-head cross-attention to capture inter-level dependencies. An Enhanced SubHead enforces hierarchical constraints to suppress invalid subpage predictions, while a cascaded channel–spatial attention mechanism refines discriminative features for precise hierarchical identification. Experimental results demonstrate that HiFi-WF achieves state-of-the-art performance at both hierarchical levels, attaining F1-scores of 92.1% (homepage) and 81.9% (subpage), thereby validating its effectiveness in advancing WF attacks toward realistic, fine-grained, and multi-tab browsing scenarios. Related codes and datasets can be found in https://github.com/wusongyang02-blip/HiFi-WF.
Chuan Ma 0001, Ming Ding 0001, Long Yuan 0001, Biwen Chen, Yuwen Qian, Tao Xiang 0001
WWW2
2026 Secure Outsourcing Scheme for FCM-PSO Based Medical Image Segmentation Algorithm
abstract
Machine learning algorithm for multi-modal image segmentation is extensively employed in medical analysis and diagnosis. Clustering represents a mainstream approach for image segmentation, with the fuzzy c-means and particle swarm optimization (FCM-PSO) algorithm garnering significant attention. As image segmentation tasks have substantial computational costs, the outsourcing scheme offers an effective solution by leveraging cloud servers to execute complex computations. Given that medical images contain sensitive patient information, the image segmentation outsourcing scheme must ensure data privacy and confidentiality. In this paper, we propose a secure outsourcing scheme for the FCM-PSO based image segmentation algorithm through a novel sparse matrix encryption method. By analyzing each stage of the image segmentation algorithm, we delegate the computationally intensive task of calculating the Euclidean distance to an untrusted cloud server. We utilize sparse matrices to obscure the private image data. These matrices are created by incorporating multiple small-sized random invertible matrices, thereby circumventing the local storage of generation factors. Additionally, we implement a lightweight verification method to verify the correctness of returned results. Experimental results show that our scheme improves the efficiency of the image segmentation task by 29.99% to 49.50% with the increasing of image set, compared to the original algorithm executed locally.
Xinrong Sun, Yunting Tao, Chunpeng Ge 0001, Chuan Ma 0001, Fanyu Kong 0002, Hanlin Zhang 0001, Jia Yu 0003
IEEE Trans. Dependable Secur. Comput.4
2026 G2uardFL: Safeguarding Federated Learning Against Backdoor Attacks via Attributed Client Graph Clustering
abstract
Federated Learning (FL) offers collaborative model training across multiple decentralized devices without the need to share data directly, enhancing privacy and data security. However, FL systems are susceptible to backdoor attacks, where malicious clients inject poisoned weights during training. Existing defenses, primarily based on anomaly detection, are prone to erroneous rejections of normal weights while accepting poisoned ones, largely due to shortcomings in quantifying similarities among client models. Furthermore, other defenses demonstrate effectiveness only when dealing with a limited number of malicious clients, typically fewer than 10%. To alleviate these vulnerabilities, we present G2uardFL, a protective framework that translates the detection of malicious clients into an attributed graph clustering problem, thus safeguarding FL systems. Specifically, this framework employs a client graph clustering approach to identify malicious clients and integrates an adaptive mechanism to amplify the discrepancy between the aggregated model and the poisoned ones, effectively eliminating embedded backdoors. Through empirical evaluation, comparing G2uardFL with cutting-edge defenses, such as FLAME (USENIX Security 2022) [37] and DeepSight (NDSS 2022) [43], against various backdoor attacks, including 3DFed (SP 2023) [26], our results demonstrate its significant effectiveness in mitigating backdoor attacks while having a negligible impact on the aggregated model’s performance on benign samples (i.e., the primary task performance). For instance, in an FL system with 25% malicious clients, G2uardFL reduces the attack success rate to 10.61%, while maintaining a primary task performance of 80.98% on the CIFAR-10 dataset. This surpasses the performance of the best-performing baseline, which merely achieves the attack success rate of 19.54%.
Hao Yu 0017, Chuan Ma 0001, Meng Liu 0014, Tianyu Du, Ming Ding 0001, Tao Xiang 0001, Shouling Ji, Xinwang Liu 0002
IEEE Trans. Inf. Forensics Secur.2
2026 A Wolf in Sheep's Clothing: Unveiling a Stealthy Backdoor Attack in Subgraph Federated Learning
abstract
Subgraph Federated Learning (FL) has emerged as a promising paradigm for node classification tasks wherein subgraphs derived from a global graph are distributed across multiple devices to mitigate data leakage risks. Similar to other FL systems, subgraph FL faces significant security challenges, particularly from backdoor attacks, an area that remains extensively underexplored. Existing attacks typically follow a two-phase strategy to implant backdoors. However, in subgraph FL, such attacks often lead toDivergence Amplification, a phenomenon characterized by significant parameter discrepancies between normal and backdoored models, thereby compromising attack stealthiness. To tackle this challenge, we propose BEEF, a Backdoor attack with an End-to-End Framework designed for effectiveness, stealth, and durability. Unlike conventional methods, BEEF incorporates a dedicated trigger generator, which is jointly trained with a backdoored model. To increase its stealthiness, BEEF crafts adversarial perturbations as triggers that provoke misclassification while leaving the model’s parameters entirely untouched. Furthermore, by calibrating a subset of low-salience parameters associated with backdoor activation, BEEF ensures stable performance and sustained effectiveness across FL rounds. Comprehensive evaluations across eight datasets, four models, five state-of-the-art attacks, and six aggregation methods demonstrate BEEF’s effectiveness in deceiving GNNs while maintaining minimal impact on normal data performance. Additionally, we adapt BEEF to federated graph classification tasks, broadening its applicability and practicality.
Hao Yu 0017, Wenjing Yang 0002, Chuan Ma 0001, Lingyuan Meng, Liang Du 0003, Tao Xiang 0001, Xinwang Liu 0002, Kunlun He
IEEE Trans. Inf. Forensics Secur.3
2025 DPFedSub: A Differentially Private Federated Learning with Randomized Subspace Descend
Huiwen Wu, Chuan Ma 0001, Xueran Li, Deyi Zhang, She Sun
ACISP (3)2
2025 Efficient Maximum Balanced k-biplex Search Over Bipartite Graphs
abstract
Bipartite graphs are widely used to model relationships among diverse entities in domains such as gene co-expression networks, collaboration networks, and customer-product interactions. A fundamental problem in analyzing bipartite graphs is the maximum balanced biclique (MBBC) search, which identifies the maximum fully connected subgraph with an equal number of vertices on both sides in the given bipartite graph. Despite its utility, the MBBC model suffers from practical limitations: its strict all-to-all connectivity and exact size-equality requirements make it impractical for noisy, incomplete real-world bipartite data. To overcome these limitations, we propose the maximum balanced k-biplex (MBKBP) model, which relaxes the stringent requirements of MBBC. In MBKBP, each vertex is allowed to miss up to k neighbors on the opposite side of the bipartite graph, and a user-defined parameter$\delta$ensures approximate balance between the two vertex sets. This flexibility enhances robustness to noise, accommodates incomplete data, and broadens the model's applicability. To compute the MBKBP in a given bipartite graph, a baseline approach involves enumerating all maximal balanced k-biplexes and identifying the largest one. However, as confirmed by our experiments, this approach is computationally inefficient. To address this challenge, we introduce the concept of$(z_{L},\ z_{R})$search space and propose a new framework to compute the MBKBP. By generating a series of smaller$(z_{L)}z_{R})$search spaces, our framework significantly reduces the number of maximal k-biplexes that need to be explored. Additionally, we leverage the$\delta$-balance property to refine the search spaces further and develop three categories of pruning rules to minimize computational overhead. Extensive experiments on real-world bipartite graphs demonstrate that our algorithm achieves up to three orders of magnitude speedup compared to baseline approache, showcasing its efficiency and practicality for bipartite graph analysis.
Long Yuan 0001, Junyue Xu, Zi Chen 0003, Chuan Ma 0001, Jianqiu Xu, Lu Qin 0001
ICDE4
2025 Advancing Embodied Agent Security: From Safety Benchmarks to Input Moderation
abstract
Embodied agents exhibit immense potential across a multitude of domains, making the assurance of their behavioral safety a fundamental prerequisite for their widespread deployment. However, existing research predominantly concentrates on the security of general large language models, lacking specialized methodologies for establishing safety benchmarks and input moderation tailored to embodied agents. To bridge this gap, this paper introduces a novel input moderation framework, meticulously designed to safeguard embodied agents. This framework encompasses the entire pipeline, including taxonomy definition, dataset curation, moderator architecture, model training, and rigorous evaluation. Notably, we introduce EAsafetyBench, a meticulously crafted safety benchmark engineered to facilitate both the training and stringent assessment of moderators specifically designed for embodied agents. Furthermore, we propose Pinpoint, an innovative prompt-decoupled input moderation scheme that harnesses a masked attention mechanism to effectively isolate and mitigate the influence of functional prompts on moderation tasks. Extensive experiments conducted on diverse benchmark datasets and models validate the feasibility and efficacy of the proposed approach. The results demonstrate that our methodologies achieve an impressive average detection accuracy of 94.58%, surpassing the performance of existing state-of-the-art techniques, alongside an exceptional moderation processing time of merely 0.002 seconds per instance. The source code and datasets can be found at https://github.com/ZihanYan-CQU/EAsafetyBench.
Ning Wang 0003, Weiyang Li, Chuan Ma 0001, He Henry Chen, Tao Xiang 0001
IJCAI4
2025 DroneMA: Drone Mobility Alignment Countering AI-Based Spoofing Attacks
Weiyang Li, Ning Wang 0003, Chuan Ma 0001, Tao Xiang 0001, Kai Zeng 0001
INFOCOM3
2025 Impact Tracing: Identifying the Culprit of Misinformation in Encrypted Messaging Systems
Zhongming Wang, Tao Xiang 0001, Xiaoguo Li, Biwen Chen, Guomin Yang, Chuan Ma 0001, Robert H. Deng
NDSS6
2025 DShield: Defending against Backdoor Attacks on Graph Neural Networks via Discrepancy Learning
Hao Yu 0017, Chuan Ma 0001, Xinhang Wan, Jun Wang 0118, Tao Xiang 0001, Meng Shen 0001, Xinwang Liu 0002
NDSS2
2025 Beyond Single Tabs: A Transformative Few-Shot Approach to Multi-Tab Website Fingerprinting Attacks
abstract
Website Fingerprinting (WF) attacks allow passive eavesdroppers to deduce the websites a user visits by analyzing encrypted traffic, threatening user privacy. While current WF attacks achieve high accuracy, they typically assume single-tab browsing, which is unrealistic as users often open multiple tabs, creating mixed traffic. Existing multi-tab WF approaches require large datasets and frequent retraining due to evolving website content, limiting their practicality. In this paper, we introduce Few-shot Multi-tab Website Fingerprinting (FMWF), a novel approach designed to address the limitations of existing multi-tab WF attacks. FMWF directly tackles the challenges of mixed, overlapping traffic traces generated from multi-tab browsing, leveraging two key innovations: (1) an advanced data augmentation technique that synthesizes realistic multi-tab traffic sequences from easily collected single-tab traces, thereby dramatically reducing the need for large-scale real-world traffic data; and (2) a powerful fine-tuning algorithm based on transfer learning that adapts pre-trained models to new, multi-tab environments with minimal additional data. This two-stage framework enables FMWF to capture the complex effectively, overlapping traffic patterns inherent in multi-tab browsing while maintaining a high level of flexibility and significantly lowering computational and data collection burdens. Our experiments, conducted using real traffic traces collected from three widely-used browsers-Microsoft Edge, Google Chrome, and Tor Browser-highlight the superior performance of FMWF in both closed-world and open-world scenarios. Notably, FMWF achieves a minimum 12.3% improvement in accuracy compared to ARES (SP'23) [7], TMWF (CCS'23) [13], and BAPM (ACSAC'21) [10] in the open-world scenario. The code with related datasets is available at https://github.com/WW-Meng/FMWF.
Wenwen Meng, Chuan Ma 0001, Ming Ding 0001, Chunpeng Ge 0001, Yuwen Qian, Tao Xiang 0001
WWW2
2025 An improved framework for breast ultrasound image segmentation with multiple branches depth perception and layer compression residual module
Ke Cui, Qichuan Tian, Haoji Wang, Chuan Ma 0001
Eng. Appl. Artif. Intell.4
2025 A perception network for improved segmentation of endoscopic polyp images with enhanced detail
Ke Cui, Chuan Ma 0001, Haoji Wang, Qichuan Tian
Expert Syst. Appl.2
2025 Privacy-Enhanced Federated WiFi Sensing for Health Monitoring in Internet of Things
abstract
The development of the Internet of Things (IoT) has led to the widespread use of WiFi-enabled consumer electronic devices, which are now common in everyday life. These advancements in IoT have greatly improved data collection and analysis capabilities, especially for health monitoring applications. However, traditional centralized machine learning methods often fall short, raising significant privacy concerns and requiring extensive data collection, which is inefficient. To address these limitations within the distributed IoT environment, this article presents a federated learning (FL)-based WiFi sensing system specifically designed for health monitoring. By enabling local model training, our system prevents the sharing of sensitive data, thus reducing the risk of privacy breaches. We further enhance our system with a secret sharing mechanism coupled with model sparsification to significantly improve privacy. Additionally, our improved top-k model sparsification algorithm, equipped with adaptive residuals, reduces communication overhead while ensuring high accuracy. Extensive testing across various datasets and models confirms that our system outperforms existing benchmarks in terms of privacy protection and communication efficiency, marking a substantial advancement in health monitoring within the IoT.
Zhuotao Lian, Qingkui Zeng, Zhusen Liu, Haoda Wang, Chuan Ma 0001, Weizhi Meng 0001, Chunhua Su, Kouichi Sakurai
IEEE Internet Things J.5
2025 Backdoor Attack and Defense on Deep Learning: A Survey
abstract
Deep learning, as an important branch of machine learning, has been widely applied in computer vision, natural language processing, speech recognition, and more. However, recent studies have revealed that deep learning systems are vulnerable to backdoor attacks. Backdoor attackers inject a hidden backdoor into the deep learning model, such that the predictions of the infected model will be maliciously changed if the hidden backdoor is activated by input with a backdoor trigger while behaving normally on any benign sample. This kind of attack can potentially result in severe consequences in the real world. Therefore, research on defending against backdoor attacks has emerged rapidly. In this article, we have provided a comprehensive survey of backdoor attacks, detections, and defenses previously demonstrated on deep learning. We have investigated widely used model architectures, benchmark datasets, and metrics in backdoor research and have classified attacks, detections and defenses based on different criteria. Furthermore, we have analyzed some limitations in existing methods and, based on this, pointed out several promising future research directions. Through this survey, beginners can gain a preliminary understanding of backdoor attacks and defenses. Furthermore, we anticipate that this work will provide new perspectives and inspire extra research into the backdoor attack and defense methods in deep learning.
Yang Bai 0011, Gaojie Xing, Zhihong Rao, Chuan Ma 0001, Shiping Wang, Xiaolei Liu 0001, Yimin Zhou 0002, Jiajia Tang, Kaijun Huang, Jiale Kang
IEEE Trans. Comput. Soc. Syst.5
2025 GZOO: Black-Box Node Injection Attack on Graph Neural Networks via Zeroth-Order Optimization
abstract
The ubiquity of Graph Neural Networks (GNNs) emphasizes the imperative to assess their resilience against node injection attacks, a type of evasion attacks that impact victim models by injecting nodes with fabricated attributes and structures. However, prevailing attacks face two primary limitations: (1) Sequential construction of attributes and structures results in suboptimal outcomes as structure information is overlooked during attribute construction and vice versa. (2) In black-box scenarios, where attackers lack access to victim model architecture and parameters, reliance on surrogate models degrades performance due to architectural discrepancies. To overcome these limitations, we introduce GZOO, a black-box node injection attack that leverages an adversarial graph generator, compromising both attribute and structure sub-generators. This integration crafts optimal attributes and structures by considering their mutual information, enhancing their influence when aggregating information from injected nodes. Furthermore, GZOO proposes a zeroth-order optimization algorithm leveraging prediction results from victim models to estimate gradients for updating generator parameters, eliminating the necessity to train surrogate models. Across sixteen datasets, GZOO significantly outperforms state-of-the-art attacks, achieving remarkable effectiveness and robustness. Notably, on the Cora dataset with the GCN model, GZOO achieves an impressive 95.69% success rate, surpassing the maximum 66.01% achieved by baselines.
Hao Yu 0017, Ke Liang 0006, Dayu Hu, Wenxuan Tu, Chuan Ma 0001, Sihang Zhou 0001, Xinwang Liu 0002
IEEE Trans. Knowl. Data Eng.5
2025 Regularized Instance Weighting Multiview Clustering via Late Fusion Alignment
abstract
Multiview clustering has become a prominent research topic in data analysis, with wide-ranging applications across various fields. However, the existing late fusion multiview clustering (LFMVC) methods still exhibit some limitations, including variable importance and contributions and a heightened sensitivity to noise and outliers during the alignment process. To tackle these challenges, we propose a novel regularized instance weighting multiview clustering via late fusion alignment (R-IWLF-MVC), which considers the instance importance from various views, enabling information integration to be more effective. Specifically, we assign each sample an importance attribute to enable the learning process to focus more on the key sample nodes and avoid being influenced by noise or outliers, while laying the groundwork for the fusion of different views. In addition, we continue to employ late fusion alignment to integrate base clustering from various views and introduce a new regularization term with prior knowledge to ensure that the learning process does not deviate too much from the expected results. After that, we design a three-step alternating optimization strategy with proven convergence for the resultant problem. Our proposed approach has been extensively evaluated on multiple real-world datasets, demonstrating its superiority to state-of-the-art methods.
Yi Zhang 0104, Fengyu Tian, Chuan Ma 0001, Miaomiao Li 0001, Hengfu Yang, Zhe Liu 0001, En Zhu, Xinwang Liu 0002
IEEE Trans. Neural Networks Learn. Syst.3
2024 Attribute-Missing Graph Clustering Network
abstract
Deep clustering with attribute-missing graphs, where only a subset of nodes possesses complete attributes while those of others are missing, is an important yet challenging topic in various practical applications. It has become a prevalent learning paradigm in existing studies to perform data imputation first and subsequently conduct clustering using the imputed information. However, these ``two-stage" methods disconnect the clustering and imputation processes, preventing the model from effectively learning clustering-friendly graph embedding. Furthermore, they are not tailored for clustering tasks, leading to inferior clustering results. To solve these issues, we propose a novel Attribute-Missing Graph Clustering (AMGC) method to alternately promote clustering and imputation in a unified framework, where we iteratively produce the clustering-enhanced nearest neighbor information to conduct the data imputation process and utilize the imputed information to implicitly refine the clustering distribution through model optimization. Specifically, in the imputation step, we take the learned clustering information as imputation prompts to help each attribute-missing sample gather highly correlated features within its clusters for data completion, such that the intra-class compactness can be improved. Moreover, to support reliable clustering, we maximize inter-class separability by conducting cost-efficient dual non-contrastive learning over the imputed latent features, which in turn promotes greater graph encoding capability for clustering sub-network. Extensive experiments on five datasets have verified the superiority of AMGC against competitors.
Wenxuan Tu, Renxiang Guan, Sihang Zhou 0001, Chuan Ma 0001, Xin Peng 0010, Zhiping Cai, Zhe Liu 0001, Jieren Cheng, Xinwang Liu 0002
AAAI4
2024 Refine, Discriminate and Align: Stealing Encoders via Sample-Wise Prototypes and Multi-relational Extraction
Shuchi Wu, Chuan Ma 0001, Kang Wei 0004, Xiaogang Xu 0002, Ming Ding 0001, Yuwen Qian, Di Xiao 0001, Tao Xiang 0001
ECCV (34)2
2024 Data Level Privacy Preserving: A Stochastic Perturbation Approach Based on Differential Privacy (Extended abstract)
abstract
With the great amount of available data, especially collected from the ubiquitous Internet of Things (IoT), the issue of privacy leakage has been an increasing concern recently. To preserve the privacy of IoT datasets, traditional methods usually calibrate random noises on the data values to achieve differential privacy (DP) [1]. However, the amount of calibrating noises should be carefully designed and a heedless value will definitely degrade the availability of datasets.
Chuan Ma 0001, Long Yuan 0001, Li Han 0001, Ming Ding 0001, Raghav Bhaskar, Jun Li 0004
ICDE1
2024 Optimizing Information Freshness in Mobile Networks with Age-Threshold ALOHA
abstract
We optimize the Age of Information (AoI) in random access networks using the age-threshold slotted ALOHA (TSA) protocol. The network comprises multiple source-destination pairs, where each source sends a sequence of status update packets to its destination over a shared spectrum. The TSA protocol stipulates that a source node must remain silent until its AoI reaches a predefined threshold, after which the node accesses the radio channel with a certain probability. We derive analytical expressions for the transmission success probability and time-average AoI using stochastic geometry tools. Subsequently, we obtain closed-form expressions for the optimal update rate and age threshold that minimize the time-average AoI. In addition, we establish a scaling law for the time-average AoI in random access networks, revealing that the optimal time-average AoI increases linearly with the deployment density. Notably, the growth rate under TSA is half of that under conventional slotted ALOHA.
Fangming Zhao, Nikolaos Pappas 0001, Chuan Ma 0001, Xinghua Sun, Tony Q. S. Quek, Howard H. Yang
ISIT3
2024 Gradient sparsification for efficient wireless federated learning with differential privacy
Kang Wei 0004, Jun Li 0004, Chuan Ma 0001, Ming Ding 0001, Feng Shu 0002, Haitao Zhao 0004, Wen Chen 0001, Hongbo Zhu 0002
Sci. China Inf. Sci.3
2024 ISPPFL: An incentive scheme based privacy-preserving federated learning for avatar in metaverse
Yang Bai 0011, Gaojie Xing, Zhihong Rao, Chengzong Peng, Yutang Rao, Chuan Ma 0001, Yimin Zhou 0002
Comput. Networks8
2024 Improved privacy-preserving PCA using optimized homomorphic matrix multiplication
Xirong Ma, Chuan Ma 0001, Yali Jiang 0004, Chunpeng Ge 0001
Comput. Secur.2
2024 Accelerating Graph Embedding Through Secure Distributed Outsourcing Computation in Internet of Things
abstract
With the advancement of the Internet of Things (IoT), numerous machine learning applications on IoT are encountering performance bottlenecks. Graph embedding is an emerging type of machine learning that has achieved commendable results in areas such as network anomaly detection, malware detection, IoT device management, and service recommendation within the Internet of Things. However, for some resource-constrained IoT devices, computing graph embedding algorithms is highly complex and time-consuming. In this paper, we introduce an efficient and secure distributed outsourcing scheme, employing four non-colluding cloud servers to facilitate the computation of graph embedding for IoT devices. Our scheme utilizes a novel blinding factor generated through QR decomposition to blind matrices containing sensitive information. We partition the blinded matrix into several segments, distributing different small matrix blocks across four servers, each of which executes only a portion of the computational tasks. The proposed outsourcing solution ensures the privacy of input and output information is not compromised. In our scheme, we utilize an effective verification method that can detect the erroneous behaviors of cloud servers with a probability close to one. Theoretical analysis and experimental results indicate that our solution achieves a computational efficiency of (35m2+2m)/(3m3) compared to the original algorithm.
Pengyu Cui, Yunting Tao, Bin Zhen, Fanyu Kong 0002, Chunpeng Ge 0001, Chuan Ma 0001, Jia Yu 0003
IEEE Internet Things J.6
2024 Covert Model Poisoning Against Federated Learning: Algorithm Design and Optimization
abstract
Federated learning (FL), as a type of distributed machine learning, is vulnerable to external attacks during parameter transmissions between learning agents and a model aggregator. In particular, malicious participant clients in FL can purposefully craft their uploaded model parameters to manipulate system outputs, which is know as a model poisoning (MP) attack. In this paper, we propose effective MP algorithms to attack the classical defensive aggregation Krum at the aggregator. The proposed algorithms are designed to evade detection, i.e., covert MP (CMP). Specifically, we first formulate the MP as an optimization problem by minimizing the Euclidean distance between the manipulated model and designated one, constrained by Krum. Then, we develop CMP algorithms against the Krum based on the solutions of this optimization problem. Furthermore, to reduce the optimization complexity, we propose low complexity CMP algorithms having only a slight performance degradation. Our experimental results demonstrate that the proposed CMP algorithms are effective and can substantially outperform existing attack mechanisms, such as Arjun's attack and the label flipping attack. More specifically, our original CMP can achieve a high rate of the attacker's accuracy ($\approx 90\%$). For example, in our experiments using the MNIST dataset, the proposed CMP attacking algorithm against Krum can successfully manipulate the aggregated model to incorrectly classify a given digit as a different one (e.g., 9 as 8). Meanwhile, our CMP algorithm with an approximated constraint can achieve a rate of 87% in terms of the attacker's accuracy (attacker-desired results), with a 73% complexity reduction compared to the original CMP.
Kang Wei 0004, Jun Li 0004, Ming Ding 0001, Chuan Ma 0001, Yo-Seb Jeon, H. Vincent Poor
IEEE Trans. Dependable Secur. Comput.4
2024 BadCleaner: Defending Backdoor Attacks in Federated Learning via Attention-Based Multi-Teacher Distillation
abstract
As a privacy-preserving distributed learning paradigm, federated learning (FL) has been proven to be vulnerable to various attacks, among which backdoor attack is one of the toughest. In this attack, malicious users attempt to embed backdoor triggers into local models, resulting in the crafted inputs being misclassified as the targeted labels. To address such attack, several defense mechanisms are proposed, but may lose the effectiveness due to the following drawbacks. First, current methods heavily rely on massive labeled clean data, which is an impractical setting in FL. Moreover, an in-avoidable performance degradation usually occurs in the defensive procedure. To alleviate such concerns, we proposeBadCleaner, a lossless and efficient backdoor defense scheme via attention-based federated multi-teacher distillation. Firstly,BadCleanercan effectively tune the backdoored joint model without performance degradation, by distilling the in-depth knowledge from multiple teachers with only a small part of unlabeled clean data. Secondly, to fully eliminate the hidden backdoor patterns, we present an attention transfer method to alleviate the attention of models to the trigger regions. The extensive evaluation demonstrates thatBadCleanercan reduce the success rates of state-of-the-art backdoor attacks without compromising the model performance.
Jiale Zhang 0001, Chunpeng Ge 0001, Chuan Ma 0001, Yanchao Zhao, Xiaobing Sun 0001, Bing Chen 0002
IEEE Trans. Dependable Secur. Comput.4
2024 Enhancing Resilience in Website Fingerprinting: Novel Adversary Strategies for Noisy Traffic Environments
abstract
The act of website fingerprinting, which involves monitoring traffic features to infer private user information, has attracted much attention in the research community recently. While previous studies primarily focused on classifying fingerprint information using clean traffic data, it remains a challenging task to apply fingerprinting to noisy traffic data or evade defensive measures. This work aims to address the challenges associated with website fingerprinting attacks and defense strategies in the presence of noise. Specifically, we introduce two novel attack methods: filter-assisted attack and augmentation-assisted attack. The first attack method leverages packet size distribution to effectively filter out noise, while the second one trains a classification model by incorporating artificial noise. Compared with the traditional website fingerprinting attacks, these proposed attack methods demonstrate superior resilience to noise and exceptional evasion capabilities against defensive measures (e.g., random packet defense, Walkie-Talkie, WTF-PAD, etc.). In parallel, we propose a list-assisted defense strategy that strikes a balance between defense performance and network overhead. This defense mechanism offers effective protection against website fingerprinting attacks while minimizing the impact on network performance. In our experiments, we employ a comprehensive dataset encompassing TCP/IP traffic with packet size information collected from three prominent web browsers, as well as Tor cell traffic without packet size information obtained from a Tor browser. We thoroughly evaluate our proposed methods in both closed-world and open-world scenarios. Our experimental results shed valuable insights into the influence of noise and the efficacy of different attack and defense approaches on website fingerprinting.
Yuwen Qian, Guodong Huang, Chuan Ma 0001, Ming Ding 0001, Long Yuan 0001, Zi Chen 0003, Kai Wang 0037
IEEE Trans. Inf. Forensics Secur.3
2024 Voltran: Unlocking Trust and Confidentiality in Decentralized Federated Learning Aggregation
abstract
The decentralized Federated Learning (FL) paradigm built upon blockchain architectures leverages distributed node clusters to replace the single server for executing FL model aggregation. This paradigm tackles the vulnerability of the centralized malicious server in vanilla FL and inherits the trustfulness and robustness offered by blockchain. However, existing blockchain-enabled schemes face challenges related to inadequate confidentiality on models and limited computational resources of blockchains. In this paper, we present Voltran, an innovative hybrid platform designed to achieve trust, confidentiality, and robustness for FL based on the combination of the Trusted Execution Environment (TEE) and blockchain technology. We offload the FL aggregation computation into TEE to provide an isolated, trusted and customizable off-chain execution and then guarantee the authenticity and verifiability of aggregation results on the blockchain. Moreover, we provide strong scalability on multiple FL scenarios by introducing a multi-SGX parallel execution strategy to amortize the large-scale FL workload. We implement a prototype of Voltran and conduct a comprehensive performance evaluation. Extensive experimental results demonstrate that Voltran incurs minimal additional overhead while guaranteeing trust, confidentiality, and authenticity, and it significantly brings a significant speed-up compared to state-of-the-art ciphertext aggregation schemes.
Hao Wang 0189, Yichen Cai 0002, Jun Wang 0020, Chuan Ma 0001, Chunpeng Ge 0001, Xiangmou Qu, Lu Zhou 0002
IEEE Trans. Inf. Forensics Secur.4
2024 Toward Efficient and Secure Object Detection With Sparse Federated Training Over Internet of Vehicles
abstract
Internet of Vehicles (IoV) plays a vital role in alleviating traffic issues. Object detection is one of the key technologies in IoV, which has been widely used to provide traffic management services by analyzing timely and sensitive vehicle-related information. However, the current object detection methods mostly rely on centralized deep training, that is, the sensitive data obtained by edge devices needs to be uploaded to the server, which raises latency and privacy issues. To tackle these issues, we propose to accomplish object detection through sparse federated training with dynamic model aggregation, namely FedWeg, to reduce the communication cost and privacy leakage induced by data transmission. Specifically, FedWeg performs sparse training in edge devices and uploads the lightweight models to the server. To reduce the unnecessary transmission overhead, we propose a dynamic sparsity adjustment scheme that gradually increases the sparsity ratios. Then, we propose to utilize the inverse ratio of sparsity ratios from different edge devices to calculate aggregate weights to diminish the negative impact of sparse training on learning performance. Moreover, we theoretically analyze the convergence rate of FedWeg, which reveals that the impact of network sparsity on model performance, and higher average sparsity rates result in greater errors. Finally, we conduct extensive experiments on four real-life datasets using YOLOv3 and VGG-16. The results show that our FedWeg algorithm outperforms baselines in terms of communication costs and test accuracy.
Yuwen Qian, Luping Rao, Chuan Ma 0001, Kang Wei 0004, Ming Ding 0001, Long Shi 0001
IEEE Trans. Intell. Transp. Syst.3
2024 RARE: Robust Masked Graph Autoencoder
abstract
Masked graph autoencoder (MGAE) has emerged as a promising self-supervised graph pre-training (SGP) paradigm due to its simplicity and effectiveness. However, existing efforts perform the mask-then-reconstruct operation in the raw data space as is done in computer vision (CV) and natural language processing (NLP) areas, while neglecting the important non-Euclidean property of graph data. As a result, the highly unstable local structures largely increase the uncertainty in inferring masked data and decrease the reliability of the exploited self-supervision signals, leading to inferior representations for downstream evaluations. To address this issue, we propose a novel SGP method termed Robust mAsked gRaph autoEncoder (RARE) to improve the certainty in inferring masked data and the reliability of the self-supervision mechanism by further masking and reconstructing node samples in the high-order latent feature space. Through both theoretical and empirical analyses, we have discovered that performing a joint mask-then-reconstruct strategy in both latent feature and raw data spaces could yield improved stability and performance. To this end, we elaborately design a masked latent feature completion scheme, which predicts latent features of masked nodes under the guidance of high-order sample correlations that are hard to be observed from the raw data perspective. Specifically, we first adopt a latent feature predictor to predict the masked latent features from the visible ones. Next, we encode the raw data of masked samples with a momentum graph encoder and subsequently employ the resulting representations to improve the predicted results through latent feature matching. Extensive experiments on seventeen datasets have demonstrated the effectiveness and robustness of RARE against state-of-the-art (SOTA) competitors across three downstream tasks. Our source code is available athttps://github.com/WxTu/RARE.
Wenxuan Tu, Qing Liao 0001, Sihang Zhou 0001, Xin Peng 0010, Chuan Ma 0001, Zhe Liu 0001, Xinwang Liu 0002, Zhiping Cai, Kunlun He
IEEE Trans. Knowl. Data Eng.5
2024 Regularized Simple Multiple Kernel k-Means With Kernel Average Alignment
abstract
Multiple kernel clustering (MKC) aims to learn an optimal kernel to better serve for clustering from several precomputed basic kernels. Most MKC algorithms adhere to a common assumption that an optimal kernel is linearly combined by basic kernels. Based on a min-max framework, a newly proposed MKC method termed simple multiple kernel k -means (SimpleMKKM) can acquire a high-quality unified kernel. Although SimpleMKKM has achieved promising clustering performance, we observe that it cannot benefit from any prior knowledge. This would cause the learned partition matrix may seriously deviate from the expected one, especially in clustering tasks where the ground truth is absent during the learning course. To tackle this issue, we propose a novel algorithm termed regularized simple multiple kernel k -means with kernel average alignment (R-SMKKM-KAA). According to the experimental results of existing MKC algorithms, the average partition is a strong baseline to reflect true clustering. To gain knowledge from the average partition, we add the average alignment as a regularization term to prevent the learned unified partition from being far from the average partition. After that, we have designed an efficient solving algorithm to optimize the new resulting problem. In this way, both the incorporated prior knowledge and the combination of basic kernels are helpful to learn better unified partition. Consequently, the clustering performance can be significantly improved. Extensive experiments on nine common datasets have sufficiently demonstrated the effectiveness of incorporation of prior knowledge into SimpleMKKM.
Miaomiao Li 0001, Yi Zhang 0104, Chuan Ma 0001, Suyuan Liu, Zhe Liu 0001, Jianping Yin, Xinwang Liu 0002, Qing Liao 0001
IEEE Trans. Neural Networks Learn. Syst.3
2024 Design of Anti-Plagiarism Mechanisms in Decentralized Federated Learning
abstract
In decentralized federated learning (DFL), clients exchange their models with each other for global aggregation. Due to a lack of centralized supervision, a client may easily duplicate shared models to save its computing resources. Generally, this plagiarism behavior is hard to detect, while it is harmful to model training performance. To address this issue, we propose an anti-plagiarism DFL framework to efficiently detect plagiarism misconduct. Specifically, we first design a method for detecting plagiarism by adding a time-shift pseudo-noise (PN) sequence to each client's local model before broadcasting. Second, we develop an upper bound of the loss function of DFL with the proposed PN sequence detection method, which is proved to be the convex function of both the amplitude of PN sequences ($\alpha$) and the detection threshold ($\lambda$). Next, we propose an adaptive plagiarism detection (APD) algorithm by jointly optimizing$\alpha$and$\lambda$to enhance the learning performance. Finally, we conduct extensive experiments on MNIST, Adult, Cifar-10, and SVHN datasets to demonstrate that our analytical bounds are consistent with the experimental results. Remarkably, the proposed framework can recover up to a 10% classification accuracy loss in the presence of 40% plagiaristic clients.
Yumeng Shao, Jun Li 0004, Ming Ding 0001, Kang Wei 0004, Chuan Ma 0001, Long Shi 0001, Wen Chen 0001, Shi Jin 0002
IEEE Trans. Serv. Comput.5
2024 Age-Threshold Slotted ALOHA for Optimizing Information Freshness in Mobile Networks
abstract
We optimize the Age of Information (AoI) in mobile networks using the age-threshold slotted ALOHA (TSA) protocol. The network comprises multiple source-destination pairs, where each source sends a sequence of status update packets to its destination over a shared spectrum. The TSA protocol stipulates that a source node must remain silent until its AoI reaches a predefined threshold, after which the node accesses the radio channel with a certain probability. Using stochastic geometry tools, we derive analytical expressions for the transmission success probability, mean peak AoI, and time-average AoI. Subsequently, we obtain closed-form expressions for the optimal update rate and age threshold that minimize the mean peak and time-average AoI, respectively. In addition, we establish a scaling law for the mean peak AoI and time-average AoI in mobile networks, revealing that the optimal mean peak AoI and time-average AoI increase linearly with the deployment density. Notably, the growth rate of time-average AoI under TSA is half of that under SA. When considering the optimal mean peak AoI, the TSA protocol exhibits comparable performance to the traditional slotted ALOHA protocol. These findings conclusively affirm the advantage of TSA in reducing higher-order AoI, particularly in densely deployed networks.
Fangming Zhao, Nikolaos Pappas 0001, Chuan Ma 0001, Xinghua Sun, Tony Q. S. Quek, Howard H. Yang
IEEE Trans. Wirel. Commun.3
2023 Blockchain-aided Cooperative Spectrum Sensing: Decentralized Reputation Management and Performance Optimization
abstract
A critical security issue in the blockchain-aided cooperative spectrum sensing (B-CSS) network is that, blockchain cannot guarantee the reliability of off-chain data source, even though the data has been recorded on the chain. Furthermore, the performance optimization of the B-CSS networks is constrained by an underlying tradeoff between throughput and security. Driven by these issues, we first develop a novel B-CSS framework with a decentralized reputation management (DRM) mechanism, wherein nodes not only collaborate to detect the availability of target spectrum off the chain, but also act as the blockchain nodes to maintain global decisions on the chain. In the off-chain phase, the DRM mechanism can enhance the trustworthiness of CSS by evaluating each node's reputation according to its contribution to the global detection. Furthermore, in light of the on-chain throughput-and-security tradeoff, verifiable reputation can be utilized as the consensus stake to adjust the difficulty level of block generation. Then, given the on-chain reputation consensus, we maximize the average throughput of the proposed framework by jointly optimizing the block size, sensing time, and block generation time. Simulation results demonstrate the optimized performance of the proposed framework. Moreover, compared with the baseline schemes, our proposal is more robust to the threat of malicious attacks such as data-tampering attack and collusion attack.
Yafan Yang, Long Shi 0001, Jun Li 0004, Taotao Wang, Zhe Wang 0005, Bin Cao 0002, Chuan Ma 0001
GLOBECOM7
2023 Sparse Federated Training of Object Detection in the Internet of Vehicles
abstract
As an essential component part of the Intelligent Transportation System (ITS), the Internet of Vehicles (IoV) plays a vital role in alleviating traffic issues. Object detection is one of the key technologies in the IoV, which has been widely used to provide traffic management services by analyzing timely and sensitive vehicle-related information. However, the current object detection methods are mostly based on centralized deep training, that is, the sensitive data obtained by edge devices need to be uploaded to the server, which raises privacy concerns. To mitigate such privacy leakage, we first propose a federated learning-based framework, where well-trained local models are shared in the central server. However, since edge devices usually have limited computing power, plus a strict requirement of low latency in IoVs, we further propose a sparse training process on edge devices, which can effectively lighten the model, and ensure its training efficiency on edge devices, thereby reducing communication overheads. In addition, due to the diverse computing capabilities and dynamic environment, different sparsity rates are applied to edge devices. To further guarantee the performance, we propose, FedWeg, an improved aggregation scheme based on FedAvg, which is designed by the inverse ratio of sparsity rates. Experiments on the real-life dataset using YOLO show that the proposed scheme can achieve the required object detection rate while saving considerable communication costs.
Luping Rao, Chuan Ma 0001, Ming Ding 0001, Yuwen Qian, Lu Zhou 0002, Zhe Liu 0001
ICC2
2023 Consistency of Multiple Kernel Clustering
abstract
Consistency plays an important role in learning theory. However, in multiple kernel clustering (MKC), the consistency of kernel weights has not been sufficiently investigated. In this work, we fill this gap with a non-asymptotic analysis on the consistency of kernel weights of a novel method termed SimpleMKKM. Under the assumptions of the eigenvalue gap, we give an infinity norm bound as $\widetilde{\mathcal{O}}(k/\sqrt{n})$, where $k$ is the number of clusters and $n$ is the number of samples. On this basis, we establish an upper bound for the excess clustering risk. Moreover, we study the difference of the kernel weights learned from $n$ samples and $r$ points sampled without replacement, and derive its upper bound as $\widetilde{\mathcal{O}}(k\cdot\sqrt{1/r-1/n})$. Based on the above results, we propose a novel strategy with Nyström method to enable SimpleMKKM to handle large-scale datasets with a theoretical learning guarantee. Finally, extensive experiments are conducted to verify the theoretical results and the effectiveness of the proposed large-scale strategy.
Weixuan Liang, Xinwang Liu 0002, Yong Liu 0018, Chuan Ma 0001, Yunping Zhao, Zhe Liu 0001, En Zhu
ICML4
2023 Efficient and Low Overhead Website Fingerprinting Attacks and Defenses based on TCP/IP Traffic
abstract
Website fingerprinting attack is an extensively studied technique used in a web browser to analyze traffic patterns and thus infer confidential information about users. Several website fingerprinting attacks based on machine learning and deep learning tend to use the most typical features to achieve a satisfactory performance of attacking rate. However, these attacks suffer from several practical implementation factors, such as a skillfully pre-processing step or a clean dataset. To defend against such attacks, random packet defense (RPD) with a high cost of excessive network overhead is usually applied. In this work, we first propose a practical filter-assisted attack against RPD, which can filter out the injected noises using the statistical characteristics of TCP/IP traffic. Then, we propose a list-assisted defensive mechanism to defend the proposed attack method. To achieve a configurable trade-off between the defense and the network overhead, we further improve the list-based defense by a traffic splitting mechanism, which can combat the mentioned attacks as well as save a considerable amount of network overhead. In the experiments, we collect real-life traffic patterns using three mainstream browsers, i.e., Microsoft Edge, Google Chrome, and Mozilla Firefox, and extensive results conducted on the closed and open-world datasets show the effectiveness of the proposed algorithms in terms of defense accuracy and network efficiency.
Guodong Huang, Chuan Ma 0001, Ming Ding 0001, Yuwen Qian, Chunpeng Ge 0001, Liming Fang 0001, Zhe Liu 0001
WWW2
2023 LAFED: A lightweight authentication mechanism for blockchain-enabled federated learning system
Shan Ji, Jiale Zhang 0001, Yongjing Zhang, Chuan Ma 0001
Future Gener. Comput. Syst.5
2023 Low-Latency Federated Learning With DNN Partition in Distributed Industrial IoT Networks
abstract
Federated Learning (FL) empowers Industrial Internet of Things (IIoT) with distributed intelligence of industrial automation thanks to its capability of distributed machine learning without any raw data exchange. However, it is rather challenging for lightweight IIoT devices to perform computation-intensive local model training over large-scale deep neural networks (DNNs). Driven by this issue, we develop a communication-computation efficient FL framework for resource-limited IIoT networks that integrates DNN partition technique into the standard FL mechanism, wherein IIoT devices perform local model training over the bottom layers of the objective DNN, and offload the top layers to the edge gateway side. Considering imbalanced data distribution, we derive the device-specific participation rate to involve the devices with better data distribution in more communication rounds. Upon deriving the device-specific participation rate, we propose to minimize the training delay under the constraints of device-specific participation rate, energy consumption and memory usage. To this end, we formulate a joint optimization problem of device scheduling and resource allocation (i.e. DNN partition point, channel assignment, transmit power, and computation frequency), and solve the long-term min-max mixed integer non-linear programming based on the Lyapunov technique. In particular, the proposed dynamic device scheduling and resource allocation (DDSRA) algorithm can achieve a trade-off to balance the training delay minimization and FL performance. We also provide the FL convergence bound for the DDSRA algorithm with both convex and non-convex settings. Experimental results demonstrate the derived device-specific participation rate in terms of feasibility, and show that the DDSRA algorithm outperforms baselines in terms of test accuracy and convergence time.
Xiumei Deng, Jun Li 0004, Chuan Ma 0001, Kang Wei 0004, Long Shi 0001, Ming Ding 0001, Wen Chen 0001
IEEE J. Sel. Areas Commun.3
2023 Trusted AI in Multiagent Systems: An Overview of Privacy and Security for Distributed Learning
abstract
Motivated by the advancing computational capacity of distributed end-user equipment (UE), as well as the increasing concerns about sharing private data, there has been considerable recent interest in machine learning (ML) and artificial intelligence (AI) that can be processed on distributed UEs. Specifically, in this paradigm, parts of an ML process are outsourced to multiple distributed UEs. Then, the processed information is aggregated on a certain level at a central server, which turns a centralized ML process into a distributed one and brings about significant benefits. However, this new distributed ML paradigm raises new risks in terms of privacy and security issues. In this article, we provide a survey of the emerging security and privacy risks of distributed ML from a unique perspective of information exchange levels, which are defined according to the key steps of an ML process, i.e., we consider the following levels: 1) the level of preprocessed data; 2) the level of learning models; 3) the level of extracted knowledge; and 4) the level of intermediate results. We explore and analyze the potential of threats for each information exchange level based on an overview of current state-of-the-art attack mechanisms and then discuss the possible defense methods against such threats. Finally, we complete the survey by providing an outlook on the challenges and possible directions for future research in this critical area.
Chuan Ma 0001, Jun Li 0004, Kang Wei 0004, Bo Liu 0001, Ming Ding 0001, Long Yuan 0001, Zhu Han 0001, H. Vincent Poor
Proc. IEEE1
2023 RDP-GAN: A Rényi-Differential Privacy Based Generative Adversarial Network
abstract
Generative adversarial networks (GANs) have attracted increasing attention recently owing to their impressive abilities to generate realistic samples with high privacy protection. Without directly interacting with training examples, the generative model can be used to estimate the underlying distribution of an original dataset while the discriminator can examine model quality of the generated samples by comparing the label values with training examples. In considering privacy issues in GANS, existing works focus on perturbing the parameters and analyzing the corresponding privacy protection capability, and the parameters are not directly exchanged between the generator and discriminator in GANs. Thus, in this work, we propose a Rényi-differentially private-GAN (RDP-GAN), which achieves differential privacy (DP) in a GAN by carefully adding random Gaussian noise to the value of the exchanged loss function during training. Moreover, we derive analytical results characterizing the total privacy loss under the subsampling method and cumulative iterations, which show its effectiveness for the privacy budget allocation. In addition, in order to mitigate the negative impact of injecting noises, we enhance the proposed algorithm by adding an adaptive noise tuning step, which will change the amount of added noise according to the testing accuracy. Through extensive experimental results, we verify that the proposed algorithm can achieve a better privacy level while producing high-quality samples compared with a benchmark DP-GAN scheme based on noise perturbation on training gradients.
Chuan Ma 0001, Jun Li 0004, Ming Ding 0001, Bo Liu 0001, Kang Wei 0004, Jian Weng 0001, H. Vincent Poor
IEEE Trans. Dependable Secur. Comput.1
2023 Personalized Federated Learning With Differential Privacy and Convergence Guarantee
abstract
Personalized federated learning (PFL), as a novel federated learning (FL) paradigm, is capable of generating personalized models for heterogenous clients. Combined with with a meta-learning mechanism, PFL can further improve the convergence performance with few-shot training. However, meta-learning based PFL has two stages of gradient descent in each local training round, therefore posing a more serious challenge in information leakage. In this paper, we propose a differential privacy (DP) based PFL (DP-PFL) framework and analyze its convergence performance. Specifically, we first design a privacy budget allocation scheme for inner and outer update stages based on the Rényi DP composition theory. Then, we develop two convergence bounds for the proposed DP-PFL framework under convex and non-convex loss function assumptions, respectively. Our developed convergence bounds reveal that 1) there is an optimal size of the DP-PFL model that can achieve the best convergence performance for a given privacy level, and 2) there is an optimal tradeoff among the number of communication rounds, convergence performance and privacy budget. Evaluations on various real-life datasets demonstrate that our theoretical results are consistent with experimental results. The derived theoretical results can guide the design of various DP-PFL algorithms with configurable tradeoff requirements on the convergence performance and privacy levels.
Kang Wei 0004, Jun Li 0004, Chuan Ma 0001, Ming Ding 0001, Wen Chen 0001, Jun Wu 0006, Meixia Tao, H. Vincent Poor
IEEE Trans. Inf. Forensics Secur.3
2023 Data Level Privacy Preserving: A Stochastic Perturbation Approach Based on Differential Privacy
abstract
With the great amount of available data, especially collecting from the ubiquitous Internet of Things (IoT), the issue of privacy leakage arises increasingly concerns recently. To preserve the privacy of IoT datasets, traditional methods usually calibrate random noises on the data values to achieve differential privacy (DP). However, the amount of the calibrating noises should be carefully designed and a heedless value will definitely degrade the availability of datasets. Thus, in this work, we propose a stochastic perturbation method to sanitize the dataset, where the perturbation is obtained from the rest samples in the same dataset. In addition, we derive the expression of the utility level based on its unique framework and prove that the proposed algorithm can achieve the$\epsilon$-DP. To show the effectiveness of the proposed algorithm, we conduct extensive experiments on real-life datasets by various functions, such as query answers and machine learning tasks. By comparing with the state-of-the-art methods, our proposed algorithm can achieve a better performance under the same privacy level.
Chuan Ma 0001, Long Yuan 0001, Li Han 0001, Ming Ding 0001, Raghav Bhaskar, Jun Li 0004
IEEE Trans. Knowl. Data Eng.1
2023 Blockchain Assisted Federated Learning Over Wireless Channels: Dynamic Resource Allocation and Client Scheduling
abstract
Blockchain technology has been extensively studied to enable distributed and tamper-proof data processing in federated learning (FL). Most existing blockchain assisted FL (BFL) frameworks have employed a third-party blockchain network to decentralize the model aggregation process. However, decentralized model aggregation is vulnerable to pooling and collusion attacks from the third-party blockchain network. Driven by this issue, we propose a novel BFL framework that features the integration of training and mining at the client side. To optimize the learning performance of FL, we propose to maximize the long-term time average (LTA) training data size under a constraint of LTA energy consumption. To this end, we formulate a joint optimization problem of training client selection and resource allocation (i.e., the transmit power and computation frequency at the client side), and solve the long-term mixed integer non-linear program based on a Lyapunov technique. In particular, the proposed dynamic resource allocation and client scheduling (DRACS) algorithm can achieve a trade-off of [$\mathcal {O}(1/V)$,$\mathcal {O}(\sqrt {V})$] to balance the maximization of the LTA training data size and the minimization of the LTA energy consumption with a control parameter$V$. Our experimental results show that the proposed DRACS algorithm achieves better learning accuracy than benchmark client scheduling strategies with limited time or energy consumption.
Xiumei Deng, Jun Li 0004, Chuan Ma 0001, Kang Wei 0004, Long Shi 0001, Ming Ding 0001, Wen Chen 0001, H. Vincent Poor
IEEE Trans. Wirel. Commun.3
2022 Privacy Preserving Federated Learning Using CKKS Homomorphic Encryption
Fengyuan Qiu, Hao Yang 0062, Lu Zhou 0002, Chuan Ma 0001, Liming Fang 0001
WASA (1)4
2022 Low-Latency Federated Learning Over Wireless Channels With Differential Privacy
abstract
In federated learning (FL), model training is distributed over clients and local models are aggregated by a central server. The performance of uploaded models in such situations can vary widely due to imbalanced data distributions, potential demands on privacy protections, and quality of transmissions. In this paper, we aim to minimize FL training delay over wireless channels, constrained by overall training performance as well as each client’s differential privacy (DP) requirement. We solve this problem in a multi-agent multi-armed bandit (MAMAB) framework to deal with the situation where there are multiple clients confronting different unknown transmission environments, e.g., channel fading and interference. Specifically, we first transform long-term constraints on both training performance and each client’s DP into a virtual queue based on the Lyapunov drift technique. Then, we convert the MAMAB to a max-min bipartite matching problem at each communication round, by estimating rewards with the upper confidence bound (UCB) approach. More importantly, we propose two efficient solutions to this matching problem, i.e., a modified Hungarian algorithm and greedy matching with a better alternative (GMBA), of which the former can achieve the optimal solution with high complexity while the latter approaches a better trade-off by enabling verified low-complexity with little performance loss. In addition, we develop an upper bound on the expected regret of this MAMAB based FL framework, which shows a linear growth over the logarithm of communication rounds, justifying its theoretical feasibility. Extensive experimental results are conducted to validate the effectiveness of our proposed algorithms, and the impacts of various parameters on the FL performance over wireless edge networks are also discussed.
Kang Wei 0004, Jun Li 0004, Chuan Ma 0001, Ming Ding 0001, Cailian Chen, Shi Jin 0002, Zhu Han 0001, H. Vincent Poor
IEEE J. Sel. Areas Commun.3
2022 User-Level Privacy-Preserving Federated Learning: Analysis and Performance Optimization
abstract
Federated learning (FL), as a type of collaborative machine learning framework, is capable of preserving private data from mobile terminals (MTs) while training the data into useful models. Nevertheless, from a viewpoint of information theory, it is still possible for a curious server to infer private information from the shared models uploaded by MTs. To address this problem, we first make use of the concept of local differential privacy (LDP), and propose a user-level differential privacy (UDP) algorithm by adding artificial noise to the shared models before uploading them to servers. According to our analysis, the UDP framework can realize$(\epsilon _{i}, \delta _{i})$-LDP for the$i$th MT with adjustable privacy protection levels by varying the variances of the artificial noise processes. We then derive a theoretical convergence upper-bound for the UDP algorithm. It reveals that there exists an optimal number of communication rounds to achieve the best learning performance. More importantly, we propose a communication rounds discounting (CRD) method. Compared with the heuristic search method, the proposed CRD method can achieve a much better trade-off between the computational complexity of searching and the convergence performance. Extensive experiments indicate that our UDP algorithm using the proposed CRD method can effectively improve both the training efficiency and model quality for the given privacy protection levels.
Kang Wei 0004, Jun Li 0004, Ming Ding 0001, Chuan Ma 0001, Hang Su 0006, Bo Zhang 0010, H. Vincent Poor
IEEE Trans. Mob. Comput.4
2022 Blockchain Assisted Decentralized Federated Learning (BLADE-FL): Performance Analysis and Resource Allocation
abstract
Federated learning (FL), as a distributed machine learning paradigm, promotes personal privacy by local data processing at each client. However, relying on a centralized server for model aggregation, standard FL is vulnerable to server malfunctions, untrustworthy servers, and external attacks. To address these issues, we propose a decentralized FL framework by integrating blockchain into FL, namely, blockchain assisted decentralized federated learning (BLADE-FL). In a round of the proposed BLADE-FL, each client broadcasts its trained model to other clients, aggregates its own model with received ones, and then competes to generate a block before its local training on the next round. We evaluate the learning performance of BLADE-FL, and develop an upper bound on the global loss function. Then we verify that this bound is convex with respect to the number of overall aggregation rounds$K$, and optimize the computing resource allocation for minimizing the upper bound. We also note that there is a critical problem of training deficiency, caused by lazy clients who plagiarize others’ trained models and add artificial noises to disguise their cheating behaviors. Focusing on this problem, we explore the impact of lazy clients on the learning performance of BLADE-FL, and characterize the relationship among the optimal$K$, the learning parameters, and the proportion of lazy clients. Based on the MNIST and Fashion-MNIST datasets, we see that the experimental results are consistent with the analytical ones. To be specific, the gap between the developed upper bound and experimental results is lower than$5\%$, and the optimized$K$based on the upper bound can effectively minimize the loss function.
Jun Li 0004, Yumeng Shao, Kang Wei 0004, Ming Ding 0001, Chuan Ma 0001, Long Shi 0001, Zhu Han 0001, H. Vincent Poor
IEEE Trans. Parallel Distributed Syst.5
2021 Federated Learning With Unreliable Clients: Performance Analysis and Mechanism Design
abstract
Owing to the low communication costs and privacy-promoting capabilities, federated learning (FL) has become a promising tool for training effective machine learning models among distributed clients. However, with the distributed architecture, low-quality models could be uploaded to the aggregator server by unreliable clients, leading to a degradation or even a collapse of training. In this article, we model these unreliable behaviors of clients and propose a defensive mechanism to mitigate such a security risk. Specifically, we first investigate the impact on the models caused by unreliable clients by deriving a convergence upper bound on the loss function based on the gradient descent updates. Our bounds reveal that with a fixed amount of total computational resources, there exists an optimal number of local training iterations in terms of convergence performance. We further design a novel defensive mechanism, named deep neural network-based secure aggregation (DeepSA). Our experimental results validate our theoretical analysis. In addition, the effectiveness of DeepSA is verified by comparing with other state-of-the-art defensive mechanisms.
Chuan Ma 0001, Jun Li 0004, Ming Ding 0001, Kang Wei 0004, Wen Chen 0001, H. Vincent Poor
IEEE Internet Things J.1
2020 Federated Learning With Differential Privacy: Algorithms and Performance Analysis
abstract
Federated learning (FL), as a type of distributed machine learning, is capable of significantly preserving clients’ private data from being exposed to adversaries. Nevertheless, private information can still be divulged by analyzing uploaded parameters from clients, e.g., weights trained in deep neural networks. In this paper, to effectively prevent information leakage, we propose a novel framework based on the concept of differential privacy (DP), in which artificial noise is added to parameters at the clients’ side before aggregating, namely, noising before model aggregation FL (NbAFL). First, we prove that the NbAFL can satisfy DP under distinct protection levels by properly adapting different variances of artificial noise. Then we develop a theoretical convergence bound on the loss function of the trained FL model in the NbAFL. Specifically, the theoretical bound reveals the following three key properties: 1) there is a tradeoff between convergence performance and privacy protection levels, i.e., better convergence performance leads to a lower protection level; 2) given a fixed privacy protection level, increasing the number$N$of overall clients participating in FL can improve the convergence performance; and 3) there is an optimal number aggregation times (communication rounds) in terms of convergence performance for a given protection level. Furthermore, we propose a$K$-client random scheduling strategy, where$K$($1\leq K< N$) clients are randomly selected from the$N$overall clients to participate in each aggregation. We also develop a corresponding convergence bound for the loss function in this case and the$K$-client random scheduling strategy also retains the above three properties. Moreover, we find that there is an optimal$K$that achieves the best convergence performance at a fixed privacy level. Evaluations demonstrate that our theoretical results are consistent with simulations, thereby facilitating the design of various privacy-preserving FL algorithms with different tradeoff requirements on convergence performance and privacy levels.
Kang Wei 0004, Jun Li 0004, Ming Ding 0001, Chuan Ma 0001, Howard H. Yang, Farhad Farokhi, Shi Jin 0002, Tony Q. S. Quek, H. Vincent Poor
IEEE Trans. Inf. Forensics Secur.4
2019 Localized Small Cell Caching: A Machine Learning Approach Based on Rating Data
abstract
Caching the most popular contents at the wireless network edge such as small-cell base stations (SBSs) is a smart way of reducing duplicated content transmissions and offloading the mobile data traffic in the network backhaul. Currently, most small-cell caching strategies are conceived, designed, and optimized based on the global content request probability (GCRP), with very limited consideration of the individual content request probability (ICRP) reflecting personal preferences. To enable more efficient wireless caching, in this paper, we propose a novel localized deterministic caching framework, drawing upon the recent advances in recommendation systems based on machine learning techniques. By introducing the concept of the rating matrix, we first propose a new Bayesian learning method to predict personal preferences and estimate the ICRP. This crucial information is then incorporated into our caching strategy for maximizing the system throughput, or equivalently, minimizing the download latency, where a deterministic caching algorithm based on reinforcement learning is proposed to optimize the content placement. To this end, we extend the framework to enable device-to-device (D2D) connections to further reduce the download delay, and also design a feedback mechanism to improve the accuracy in the ICRP estimation. Our simulation results verified that with the estimated ICRP and the proposed caching strategy, the proposed framework can significantly outperform the existing methods in terms of hit rate and system throughput.
Peng Cheng 0002, Chuan Ma 0001, Ming Ding 0001, Yongjun Hu, Zihuai Lin, Yonghui Li 0001, Branka Vucetic
IEEE Trans. Commun.2
2018 On the performance of multi-tier heterogeneous cellular networks with idle mode capability
abstract
This paper studies the impact of the base station (BS) idle mode capability (IMC) on the network performance of multi-tier and dense heterogeneous cellular networks (HCNs). Different from most existing works that investigated network scenarios with an infinite number of user equipments (UEs), we consider a more practical setup with a finite number of UEs in our analysis. More specifically, we derive the probability of which BS tier a typical UE should associate to and the expression of the activated BS density in each tier. Based on such results, analytical expressions for the coverage probability and the area spectral efficiency (ASE) in each tier are also obtained. The impact of the IMC on the performance of all BS tiers is shown to be significant. In particular, there will be a surplus of BSs when the BS density in each tier exceeds the UE density, and the overall coverage probability as well as the ASE continuously increase when the BS IMC is applied. Such finding is distinctively different from that in existing work. Thus, our result sheds new light on the design and deployment of the future 5G HCNs.
Chuan Ma 0001, Ming Ding 0001, He Henry Chen, Zihuai Lin, Guoqiang Mao, David López-Pérez
WCNC1
2018 Performance Analysis of the Idle Mode Capability in a Dense Heterogeneous Cellular Network
abstract
In this paper, we study the impact of the base station (BS) idle mode capacity (IMC) on the network performance of multi-tier and dense heterogeneous cellular networks (HCNs) with both line-of-sight (LoS) and non-line-of-sight transmissions. Different from most existing works that investigated network scenarios with an infinite number of user equipments (UEs), we consider a more practical set-up with a finite number of UEs in our analysis. Moreover, in our model, the small BSs (SBSs) apply a positive power bias in the cell association procedure, so that macrocell UEs are actively encouraged to use the more lightly loaded SBSs. In addition, to address the severe interference that these cell range expanded UEs may suffer, the macro BSs (MBSs) apply enhanced inter-cell interference coordination, in the form of almost blank subframe (ABS) mechanism. For this model, we derive the coverage probability and the rate of a typical UE in the whole network or a certain tier. The impact of the IMC on the performance of the network is shown to be significant. In particular, it is important to note that there will be a surplus of BSs when the BS density exceeds the UE density, and thus a large number of BSs switch off. As a result, the overall coverage probability, as well as the area spectral efficiency, will continuously increase with the BS density, addressing the network outage that occurs when all BSs are active and the interference becomes LoS dominated. Finally, the optimal ABS factors are investigated in different BS density regions. One of major findings is that MBSs should give up all resources in favor of the SBSs when the small cell networks go ultra-dense. This reinforces the need for orthogonal deployments, shedding new light on the design and deployment of the future 5G dense HCNs.
Chuan Ma 0001, Ming Ding 0001, David López-Pérez, Zihuai Lin, Jun Li 0004, Guoqiang Mao
IEEE Trans. Commun.1
2016 Learning automaton based distributed caching for mobile social networks
abstract
In this paper, a novel distributed caching strategy in mobile social networks based on device-to-device communications is proposed. The proposed approach combines the characters of social networks to handle some practical issues, e.g., the selfishness of users. In order to maximize the throughput of the whole system, a fast convergence learning automaton, called the discrete generalized pursuit algorithm is utilized. Incorporating with social characters, the algorithm not only optimizes the content placement problems in caching theory, but also satisfies the physical and social constraints appropriately. Simulation results show that, compared with other investigated caching strategies, the proposed algorithm has higher convergence speed and at the same time, it can reduce the transmission delay and improve the system throughput. Moreover, the proposed algorithm can get a better performance in higher density district.
Chuan Ma 0001, Zihuai Lin, Loris Marini, Jun Li 0004, Branka Vucetic
WCNC1
2016 Cooperative Spectrum Sharing in D2D-Enabled Cellular Networks
abstract
Device-to-device (D2D) communication underlaying cellular networks is a promising technology for improving network resource utilization, and cooperative communication technology is usually used to mitigate the interference caused by D2D communication. Due to the additional signal processing cost introduced by cooperative communication, the cellular links who have the exclusive usage right of the network spectrum can charge the D2D links a fee for spectrum usage to enhance their profit. In this paper, we propose a contract-based cooperative spectrum sharing mechanism to exploit transmission opportunities for the D2D links and meanwhile achieve the maximum profit of the cellular links. We first design a cooperative relaying scheme that employs superposition coding at both the cellular transmitters and D2D transmitters. The cooperative relaying scheme can maximize the data rate of the D2D links without deteriorating the performance of the cellular links. Then, we employ a contract-theoretic framework to model the spectrum trading process based on the cooperative relaying scheme, and derive the optimal power-payment contracts for the cellular links under both the cases that the private information (i.e., channel quality) of the D2D links is continuous and discrete using tools from continuous-and discrete-time optimal control theories, respectively. Analytic and numerical results confirm the efficiency of the proposed spectrum sharing mechanism.
Chuan Ma 0001, Yuqing Li 0001, Hui Yu 0002, Xiaoying Gan, Xinbing Wang, Yong Ren 0001, Jun (Jim) Xu
IEEE Trans. Commun.1
2016 On the performance of interference cancelation in D2D-enabled cellular networks
abstract
Abstract Device‐to‐device (D2D) communication underlaying cellular networks is a promising technology to improve network resource utilization. In D2D‐enabled cellular networks, interference among spectrum‐sharing links is severer than that in traditional cellular networks, which motivates the adoption of interference cancelation (IC) techniques at the receivers. However, to date, how IC can affect the performance of D2D‐enabled cellular networks is still unknown. In this paper, we present an analytical framework for studying the performance of two IC methods, that is, unconditional IC and successive IC, in large‐scale D2D‐enabled cellular networks using the tools from stochastic geometry. To facilitate the interference analysis, we propose an approach of stochastic equivalence of the interference, which converts the two‐tier interference (interference from the cellular tier and D2D tier) to an equivalent single‐tier interference. Based on the proposed stochastic equivalence models, we derive the general expressions for the successful transmission probabilities of both cellular uplinks and D2D links in the networks where unconditional IC and successive IC are respectively applied. We demonstrate how these IC methods affect the network performance using both analytical and numerical results. Copyright © 2016 John Wiley & Sons, Ltd.
Chuan Ma 0001, Weijie Wu, Ying Cui 0001, Xinbing Wang
Wirel. Commun. Mob. Comput.1
2015 On the performance of successive interference cancellation in D2D-enabled cellular networks
abstract
Device-to-device (D2D) communication underlaying cellular networks is a promising technology to improve network resource utilization. In D2D-enabled cellular networks, the interference among spectrum-sharing links is more severer than that in traditional cellular networks, which motivates the adoption of interference cancellation techniques such as successive interference cancellation (SIC) at the receivers. However, to date, how SIC can affect the performance of D2D-enabled cellular networks is still unknown. In this paper, we present an analytical framework for studying the performance of SIC in large-scale D2D-enabled cellular networks using the tools from stochastic geometry. To facilitate the interference analysis, we propose the approach of stochastic equivalence of the interference, which converts the two-tier interference (interference from both the cellular tier and D2D tier) to an equivalent single-tier interference. Based on the proposed stochastic equivalence models, we derive the general expressions for the successful transmission probabilities of cellular uplinks and D2D links with infinite and finite SIC capabilities respectively. We demonstrate how SIC affects the performance of large-scale D2D-enabled cellular networks by both analytical and numerical results.
Chuan Ma 0001, Weijie Wu, Ying Cui 0001, Xinbing Wang
INFOCOM1
2015 Interference Exploitation in D2D-Enabled Cellular Networks: A Secrecy Perspective
abstract
Device-to-device (D2D) communication underlaying cellular networks is a promising technology to improve network resource utilization. In D2D-enabled cellular networks, interference generated by D2D communications is usually viewed as an obstacle to cellular communications. However, in this paper, we present a new perspective on the role of D2D interference by taking security issues into consideration. We consider a large-scale D2D-enabled cellular network with eavesdroppers overhearing cellular communications. Using stochastic geometry, we model such a network and analyze the signal-to-interference-plus-noise ratio (SINR) distributions, connection probabilities and secrecy probabilities of both the cellular and D2D links. We propose two criteria for guaranteeing performances of secure cellular communications, namely the strong and weak performance guarantee criteria. Based on the obtained analytical results of link characteristics, we design optimal D2D link scheduling schemes under these two criteria respectively. Both analytical and numerical results show that the interference from D2D communications can enhance physical layer security of cellular communications and at the same time create extra transmission opportunities for D2D users.
Chuan Ma 0001, Jiaqi Liu 0002, Xiaohua Tian, Hui Yu 0002, Ying Cui 0001, Xinbing Wang
IEEE Trans. Commun.1
2013 Cooperative relaying schemes for device-to-device communication underlaying cellular networks
abstract
Intra-cell interference management is one of the technical challenges for device-to-device (D2D) communication underlaying cellular networks. In this paper, we propose two superposition coding-based cooperative relaying schemes to exploit the transmission opportunities for the D2D users without deteriorating the performance of the cellular users. In the first scheme, the D2D transmitter (DT) is enabled to decode and regenerate the cellular signal, and transmit the cellular signal by superposing it with its own signal. In this way, the interference from the D2D pair to the cellular pair can be canceled by properly allocating time and power. To further exploit the transmission opportunity for the D2D pair, in the second scheme the cellular transmitter splits its signal into two parts and broadcasts these two parts in a superposition signal. DT relays only one part of the cellular signal. Analytic and numerical results confirm the efficiency of the proposed schemes.
Chuan Ma 0001, Gaofei Sun, Xiaohua Tian, Kai Ying, Hui Yu 0002, Xinbing Wang
GLOBECOM1
2012 Reference signal power control for load balancing in downlink LTE-A self-organizing networks
abstract
Self-organizing network (SON) is considered as a driving technology for the deployment of next generation radio access networks. This paper addresses the problem of load balancing (LB) for multi-hop cellular network (MCN) with fixed relays such as LTE-A network in the context of SON. The designed SON algorithm, namely RSPC-RL, is based on two ideas: relay node reference signal power control (RSPC) and multi-agent reinforcement learning (RL). In the proposed RSPC-RL algorithm, the relay node is modeled as an agent that learns an optimal policy of reference signal power control from its interaction with environment to balance the load distribution of the network through dynamically changing its coverage area. Numerical results show the significant performance gain brought about by the proposed algorithm RSPC-RL.
Chuan Ma 0001, Rui Yin 0001, Guanding Yu, Jietao Zhang
PIMRC1
2012 Inter-Tier Handover in Macrocell/Relay/Femtocell Heterogeneous Networks
abstract
Handover decision is one of the technical challenges in the heterogeneous network (HetNet). Current researches on this topic concentrate mainly on the two-tier networks. In this paper, we investigates the handover decision scheme for a more complex network: three-tier macrocell/relay/femtocell network. The unique characteristics of the inter-tier handover in three-tier networks are analyzed in this paper and an effective handover algorithm is proposed to reduce the frequent and unnecessary handovers based on the ideas of dwell probability and handover priority. Simulation results show that the proposed algorithm significantly reduces the number of handovers while maintaining the call dropping rate at the same level.
Chuan Ma 0001, Guanding Yu, Jietao Zhang
VTC Spring1