VLDB 2026 Research / reviewers in the wild / expert
Chao Feng 0001
dblp:97/164-1
· DBLP profile ↗
20ranked-venue papers
9as first author
20since 2021 · last 2026
0000-0002-0672-1090ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 7 · 4 first-author · 7 since 2021Computer networks · 5 · 1 first-author · 5 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GreenDFL: A framework for assessing the sustainability of Decentralized Federated Learning systemsabstractContext: Decentralized Federated Learning (DFL) is an emerging paradigm that enables collaborative model training without centralized data and model aggregation, enhancing privacy and resilience. However, its sustainability remains underexplored, as energy consumption and carbon emissions vary across different system configurations. Understanding the environmental impact of DFL is crucial for optimizing its design and deployment. Objective: This work aims to develop a comprehensive and operational framework for assessing the sustainability of DFL systems. To address it, this work provides a systematic method for quantifying energy consumption and carbon emissions, offering insights into improving the sustainability of DFL. Methods: This work proposes GreenDFL , a fully implementable framework that has been integrated into a real-world DFL platform. GreenDFL systematically analyzes the impact of various factors, including hardware accelerators, model architecture, communication medium, data distribution, network topology, and federation size, on the sustainability of DFL systems. Besides, a sustainability-aware aggregation algorithm ( GreenDFL-SA ) and a node selection algorithm ( GreenDFL-SN ) are developed to optimize energy efficiency and reduce carbon emissions in DFL training. Results: Empirical experiments are conducted on multiple datasets, measuring energy consumption and carbon emissions at different phases of the DFL lifecycle. Results indicate that local training dominates energy consumption and carbon emissions, while communication has a relatively minor impact. Optimizing model complexity, using GPUs instead of CPUs, and strategically selecting participating nodes significantly improve sustainability. Additionally, using wired communication, particularly optical fiber, effectively reduces energy consumption during the communication phase, while integrating early stopping mechanisms further minimizes overall emissions. Conclusion: The proposed GreenDFL provides a comprehensive and practical approach for assessing the sustainability of DFL systems. Furthermore, it offers best practices for improving environmental efficiency in DFL, making sustainability considerations more actionable in real-world deployments. Chao Feng 0001, Alberto Huertas Celdrán, Gérôme Bovet, Burkhard Stiller |
Inf. Softw. Technol. | 1 |
| 2025 | ColNet: Collaborative Optimization in Decentralized Federated Multi-Task Learning Systems
Chao Feng 0001, Nicolas Fazli Kohler, Weijie Niu, Alberto Huertas Celdrán, Gérôme Bovet, Burkhard Stiller |
IEEE Big Data | 1 |
| 2025 | Assessing the Sustainability and Trustworthiness of Federated Learning ModelsabstractArtificial intelligence (AI) increasingly influences critical decision-making across sectors. Federated Learning (FL), as a privacy-preserving collaborative AI paradigm, not only enhances data protection but also holds significant promise for intelligent network management, including distributed monitoring, adaptive control, and edge intelligence. Although the trustworthiness of FL systems has received growing attention, the sustainability dimension remains insufficiently explored, despite its importance for scalable real-world deployment. To address this gap, this work introduces sustainability as a distinct pillar within a comprehensive trustworthy FL taxonomy, consistent with AIHLEG guidelines. This pillar includes three key aspects: hardware efficiency, federation complexity, and the carbon intensity of energy sources. Experiments using the FederatedScope framework under diverse scenarios, including varying participants, system complexity, hardware, and energy configurations, validate the practicality of the approach. Results show that incorporating sustainability into FL evaluation supports environmentally responsible deployment, enabling more efficient, adaptive, and trustworthy network services and management AI models. Chao Feng 0001, Alberto Huertas Celdrán, Pedro Miguel Sánchez Sánchez, Lynn Zumtaugwald, Gérôme Bovet, Burkhard Stiller |
CNSM | 1 |
| 2025 | From Models to Network Topologies: A Topology Inference Attack in Decentralized Federated LearningabstractFederated Learning (FL) is widely recognized as a privacy-preserving Machine Learning paradigm due to its model-sharing mechanism that avoids direct data exchange. Nevertheless, model training leaves exploitable traces that can be used to infer sensitive information. In Decentralized FL (DFL), the topology, defining how participants are connected, plays a crucial role in shaping the model’s privacy, robustness, and convergence. However, the topology introduces an unexplored vulnerability: attackers can exploit it to infer participant relationships and launch targeted attacks. This work uncovers the hidden risks of DFL topologies by proposing a novel Topology Inference Attack that infers the topology solely from model behavior. A taxonomy of topology inference attacks is introduced, categorizing them by the attacker’s capabilities and knowledge. Practical attack strategies are designed for various scenarios, and experiments are conducted to identify key factors influencing attack success. The results demonstrate that analyzing only the model of each node can accurately infer the DFL topology, highlighting a critical privacy risk in DFL systems. These findings offer insights for improving privacy preservation in DFL environments. Chao Feng 0001, Yuanzhe Gao, Alberto Huertas Celdrán, Gérôme Bovet, Burkhard Stiller |
ECAI | 1 |
| 2025 | S-VOTE: Similarity-based Voting for Client Selection in Decentralized Federated LearningabstractDecentralized Federated Learning (DFL) enables collaborative, privacy-preserving model training without relying on a central server. This decentralized approach reduces bottlenecks and eliminates single points of failure, enhancing scalability and resilience. However, DFL also introduces challenges, such as suboptimal models with non-IID data distributions, increased communication overhead, and resource usage. Thus, this work proposes S-VOTE, a voting-based client selection mechanism that optimizes resource usage and enhances model performance in federations with non-IID data conditions. S-VOTE considers an adaptive strategy for spontaneous local training that addresses participation imbalance, allowing underutilized clients to contribute without significantly increasing resource costs. Extensive experiments on benchmark datasets demonstrate the S-VOTE effectiveness. More in detail, it achieves lower communication costs by up to 21%, 4-6% faster convergence, and improves local performance by 9-17% compared to baseline methods in some configurations, all while achieving a 14-24% energy consumption reduction. These results highlight the potential of S-VOTE to address DFL challenges in heterogeneous environments. Pedro Miguel Sánchez Sánchez, Enrique Tomás Martínez Beltrán, Chao Feng 0001, Gérôme Bovet, Gregorio Martínez Pérez, Alberto Huertas Celdrán |
IJCNN | 3 |
| 2025 | Demo: A Practical Testbed for Decentralized Federated Learning on Physical Edge DevicesabstractFederated Learning (FL) enables collaborative model training without sharing raw data, preserving participant privacy. Decentralized FL (DFL) eliminates reliance on a central server, mitigating the single point of failure inherent in the traditional FL paradigm, while introducing deployment challenges on resource-constrained devices. To evaluate real-world applicability, this work designs and deploys a physical testbed using edge devices such as Raspberry Pi and Jetson Nano. The testbed is built upon a DFL training platform, NEBULA, and extends it with a power monitoring module to measure energy consumption during training. Experiments across multiple datasets show that model performance is influenced by the communication topology, with denser topologies leading to better outcomes in DFL settings. Chao Feng 0001, Nicolas Huber, Alberto Huertas Celdrán, Gérôme Bovet, Burkhard Stiller |
LCN | 1 |
| 2025 | De-VertiFL: A Solution for Decentralized Vertical Federated LearningabstractFederated Learning (FL), introduced in 2016, was designed to enhance data privacy in collaborative model training environments. Among the FL paradigm, horizontal FL, where clients share the same set of features but different data samples, has been extensively studied in both centralized and decentralized settings. In contrast, Vertical Federated Learning (VFL), which is crucial in real-world decentralized scenarios where clients possess different, yet sensitive, data about the same entity, remains underexplored. Thus, this work introduces De-VertiFL, a novel solution for training models in a decentralized VFL setting. De-VertiFL contributes by introducing a new network architecture distribution, an innovative knowledge exchange scheme, and a distributed federated training process. Specifically, De-VertiFL enables the sharing of hidden layer outputs among federation clients, allowing participants to benefit from intermediate computations, thereby improving learning efficiency. De-VertiFL has been evaluated using a variety of well-known datasets, including both image and tabular data, across binary and multiclass classification tasks. The results demonstrate that De-VertiFL generally surpasses state-of-the-art methods in F1-score performance, while maintaining a decentralized and privacy-preserving framework. Alberto Huertas Celdrán, Chao Feng 0001, Sabyasachi Banik, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller |
NOMS | 2 |
| 2025 | GuardFS: A file system for integrated detection and mitigation of Linux-based ransomwareabstractAlthough ransomware has received broad attention in media and research, this evolving threat vector still poses a systematic threat. Related literature has explored their detection using various approaches leveraging Machine and Deep Learning. While these approaches are effective in detecting malware, they do not answer how to use this intelligence to protect against threats, raising concerns about their applicability in a hostile environment. Solutions that focus on mitigation rarely explore how to prevent and not just alert or halt its execution, especially when considering Linux-based samples. This paper presents GuardFS , a file system-based approach to investigate the integration of detection and mitigation of ransomware. Using a bespoke overlay file system, data is extracted before files are accessed. Models trained on this data are used by three novel defense configurations that obfuscate, delay, or track access to the file system. The experiments on GuardFS test the configurations in a reactive setting. The results demonstrate that although data loss cannot be completely prevented, it can be significantly reduced. Usability and performance analysis demonstrate that the defense effectiveness of the configurations relates to their impact on resource consumption and usability. Jan von der Assen, Chao Feng 0001, Alberto Huertas Celdrán, Róbert Oles, Gérôme Bovet, Burkhard Stiller |
J. Inf. Secur. Appl. | 2 |
| 2025 | CyberForce: A Federated Reinforcement Learning Framework for Malware MitigationabstractRecent research has shown that the integration of Reinforcement Learning (RL) with Moving Target Defense (MTD) can enhance cybersecurity in Internet-of-Things (IoT) devices. Nevertheless, the practicality of existing work is hindered by data privacy concerns associated with centralized data processing in RL, and the unsatisfactory time needed to learn right MTD techniques that are effective against a rising number of heterogeneous zero-day attacks. Thus, this work presents CyberForce, a framework that combines Federated and Reinforcement Learning (FRL) to collaboratively and privately learn suitable MTD techniques for mitigating zero-day attacks. CyberForce integrates device fingerprinting and anomaly detection to reward or penalize MTD mechanisms chosen by an FRL-based agent. The framework has been deployed and evaluated in a scenario consisting of ten physical devices of a real IoT platform affected by heterogeneous malware samples. A pool of experiments has demonstrated that CyberForce learns the MTD technique mitigating each attack faster than existing RL-based centralized approaches. In addition, when various devices are exposed to different attacks, CyberForce benefits from knowledge transfer, leading to enhanced performance and reduced learning time in comparison to recent works. Finally, different aggregation algorithms used during the agent learning process provide CyberForce with notable robustness to malicious attacks. Chao Feng 0001, Alberto Huertas Celdrán, Pedro Miguel Sánchez Sánchez, Jan Kreischer, Jan von der Assen, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Leveraging MTD to Mitigate Poisoning Attacks in Decentralized FL with Non-IID DataabstractDecentralized Federated Learning (DFL), a paradigm for managing big data in a privacy-preserving and distributed manner, is vulnerable to poisoning attacks where malicious clients tamper with data or models. Current defense methods often assume Independently and Identically Distributed (IID) data across participants, which is unrealistic in real-world applications. In more realistic non-IID contexts, existing defensive strategies face challenges when distinguishing between models that have been compromised and those that have been trained on heterogeneous data distributions (non-IID), leading to diminished efficacy. In response, this paper proposes a framework that employs the Moving Target Defense (MTD) approach to bolster the robustness of DFL models. By continuously modifying the attack surface of the DFL system, the framework aims to mitigate poisoning attacks effectively. The proposed solution includes both proactive and reactive modes, utilizing a reputation system that combines metrics of model similarity and loss, alongside various defensive techniques. Comprehensive experimental evaluations indicate that the MTD-based mechanism significantly mitigates a range of poisoning attack types across multiple datasets with different federation topologies. Chao Feng 0001, Alberto Huertas Celdrán, Zien Zeng, Jan von der Assen, Gérôme Bovet, Burkhard Stiller |
IEEE Big Data | 1 |
| 2024 | ThreatFinderAI: Automated Threat Modeling Applied to LLM System IntegrationabstractArtificial Intelligence (AI) is a rapidly integrated technology, significantly contributing to advancements like 6G. However, its swift adoption raises considerable security concerns. Large Language Models (LLMs) pose risks such as spear phishing, code injections, and remote code execution. Conventional threat modeling, used in secure software development, faces challenges when applied to AI systems, as existing methodologies are designed for traditional software. Furthermore, AI-specific threat modeling research is sparse and lacks approaches providing practical support or automation. Thus, this demo paper presents ThreatFinderAI, an asset-centric threat modeling and risk assessment framework. ThreatFinderAI fulfills seven steps aligned with AI system design and transforms AI threat and control knowledge bases into a queryable knowledge graph for automated asset identification and threat elicitation. It also proposes business impact analysis and expert estimates for AI threat impact quantification. In the demonstration, ThreatFinderAI is illustrated by securing a customer care application relying on LLMs. Through this, it is demonstrated how the proposed framework can be used to identify relevant threats and practical countermeasures and communicate strategic risk. Jan von der Assen, Alberto Huertas Celdrán, Jamo Sharif, Chao Feng 0001, Gérôme Bovet, Burkhard Stiller |
CNSM | 4 |
| 2024 | Sentinel: An Aggregation Function to Secure Decentralized Federated LearningabstractDecentralized Federated Learning (DFL) emerges as an innovative paradigm to train collaborative models, addressing the single point of failure limitation. However, the security and trustworthiness of FL and DFL are compromised by poisoning attacks, negatively impacting its performance. Existing defense mechanisms have been designed for centralized FL and they do not adequately exploit the particularities of DFL. Thus, this work introduces Sentinel, a defense strategy to counteract poisoning attacks in DFL. Sentinel leverages the accessibility of local data and defines a three-step aggregation protocol consisting of similarity filtering, bootstrap validation, and normalization to safeguard against malicious model updates. Sentinel has been evaluated with diverse datasets and data distributions. Besides, various poisoning attack types and threat levels have been verified. The results improve the state-of-the-art performance against both untargeted and targeted poisoning attacks when data follows an IID (Independent and Identically Distributed) configuration. Besides, under non-IID configuration, it is analyzed how performance degrades both for Sentinel and other state-of-the-art robust aggregation methods. Chao Feng 0001, Alberto Huertas Celdrán, Janosch Baltensperger, Enrique Tomás Martínez Beltrán, Pedro Miguel Sánchez Sánchez, Gérôme Bovet, Burkhard Stiller |
ECAI | 1 |
| 2024 | Next Generation of AI-based RansomwareabstractIn the era of the Internet of Things and Artificial Intelligence (AI), cybersecurity has become a critical challenge. Existing AI-based detection systems have shown merit in detecting heterogeneous malware, but their effectiveness against the next generation of AI-powered ransomware encrypting data intelligently is under discussion. In this context, this work introduces a novel AI-powered ransomware that combines Reinforcement Learning and fingerprints based on system calls to evade AI-based cybersecurity detection systems. More in detail, an RL-based agent utilizes Deep Q-Learning as a learning algorithm, system calls to model device states, and the result of unsupervised learning as input for the reward function. The efficacy of this approach has been evaluated on a Raspberry Pi acting as a real spectrum sensor that hosts a behavioral AI-based anomaly detector. Experiments have compared the AI-based ransomware evasion performance with the literature and analyzed how various benign and realistic behaviors affect evasion performance. Results showed that precise and adaptive evasion capabilities can be learned in a few minutes, motivating the need for better cybersecurity systems. Alberto Huertas Celdrán, Jan von der Assen, Chao Feng 0001, Sandro Padovan, Gérôme Bovet, Burkhard Stiller |
GLOBECOM | 3 |
| 2024 | Voyager: MTD-Based Aggregation Protocol for Mitigating Poisoning Attacks on DFLabstractThe growing concern over malicious attacks targeting the robustness of both Centralized and Decentralized Federated Learning (FL) necessitates novel defensive strategies. In contrast to the centralized approach, Decentralized FL (DFL) has the advantage of utilizing network topology and local dataset information, enabling the exploration of Moving Target Defense (MTD) based approaches.This work presents a theoretical analysis of the influence of network topology on the robustness of DFL models. Drawing inspiration from these findings, a three-stage MTD-based aggregation protocol, called Voyager, is proposed to improve the robustness of DFL models against poisoning attacks by manipulating network topology connectivity. Voyager has three main components: an anomaly detector, a network topology explorer, and a connection deployer. When an abnormal model is detected in the network, the topology explorer responds strategically by forming connections with more trustworthy participants to secure the model. Experimental evaluations show that Voyager effectively mitigates various poisoning attacks without imposing significant resource and computational burdens on participants. These findings highlight the proposed reactive MTD as a potent defense mechanism in the context of DFL. Chao Feng 0001, Alberto Huertas Celdrán, Michael Vuong, Gérôme Bovet, Burkhard Stiller |
NOMS | 1 |
| 2024 | RCVaR: An economic approach to estimate cyberattacks costs using data from industry reportsabstractDigitization increases business opportunities and the risk of companies being victims of devastating cyberattacks. Therefore, managing risk exposure and cybersecurity strategies is essential for digitized companies that aim to survive in competitive markets. However, understanding company-specific risks and quantifying their associated costs is not trivial. Current approaches fail to approximate the individualized financial impact of cyber incidents with a monetary estimation. Additionally, due to limited resources and technical expertise, SMEs, but also large companies, struggle to quantify their cyberattack exposure. Therefore, novel approaches must be built to contribute to a better understanding of the financial loss associated with cyberattacks. This article introduces the Real Cyber Value at Risk (RCVaR), an economical approach for estimating cybersecurity costs using real-world information from public cybersecurity reports. RCVaR identifies the most significant cyber risk factors from various sources and combines their quantitative results to estimate specific cyberattack costs for companies. Furthermore, RCVaR extends current methods to achieve cost and risk estimations based on historical real-world data instead of only probability-based simulations. The evaluation of the approach on unseen data shows the high accuracy and efficiency of the RCVaR in predicting and managing cyber risks. Thus, we argue that the RCVaR is a valuable addition to cybersecurity planning and risk management processes. Muriel Figueredo Franco, Fabian Künzler, Jan von der Assen, Chao Feng 0001, Burkhard Stiller |
Comput. Secur. | 4 |
| 2024 | Corrigendum to "Fedstellar: A platform for decentralized federated learning" [Expert Syst. Appl. 242 (2024) 122861]
Enrique Tomás Martínez Beltrán, Ángel Luis Perales Gómez, Chao Feng 0001, Pedro Miguel Sánchez Sánchez, Pedro Guijas Bravo, Sergio López Bernal, Gérôme Bovet, Manuel Gil Pérez, Gregorio Martínez Pérez, Alberto Huertas Celdrán |
Expert Syst. Appl. | 3 |
| 2024 | Fedstellar: A Platform for Decentralized Federated LearningabstractIn 2016, Google proposed Federated Learning (FL) as a novel paradigm to train Machine Learning (ML) models across the participants of a federation while preserving data privacy. Since its birth, Centralized FL (CFL) has been the most used approach, where a central entity aggregates participants’ models to create a global one. However, CFL presents limitations such as communication bottlenecks, single point of failure, and reliance on a central server. Decentralized Federated Learning (DFL) addresses these issues by enabling decentralized model aggregation and minimizing dependency on a central entity. Despite these advances, current platforms training DFL models struggle with key issues such as managing heterogeneous federation network topologies, adapting the FL process to virtualized or physical deployments, and using a limited number of metrics to evaluate different federation scenarios for efficient implementation. To overcome these challenges, this paper presents Fedstellar, a novel platform designed to train FL models in a decentralized, semi-decentralized, and centralized fashion across diverse federations of physical or virtualized devices. Fedstellar allows users to create federations by customizing parameters like the number and type of devices training FL models, the network topology connecting them, the machine and deep learning algorithms, or the datasets of each participant, among others. Additionally, it offers real-time monitoring of model and network performance. The Fedstellar implementation encompasses a web application with an interactive graphical interface, a controller for deploying federations of nodes using physical or virtual devices, and a core deployed on each device, which provides the logic needed to train, aggregate, and communicate in the network. The effectiveness of the platform has been demonstrated in two scenarios: a physical deployment involving single-board devices such as Raspberry Pis for detecting cyberattacks and a virtualized deployment comparing various FL approaches in a controlled environment using MNIST and CIFAR-10 datasets. In both scenarios, Fedstellar demonstrated consistent performance and adaptability, achieving F1scores of 91%, 98%, and 91.2% using DFL for detecting cyberattacks and classifying MNIST and CIFAR-10, respectively, reducing training time by 32% compared to centralized approaches. Enrique Tomás Martínez Beltrán, Ángel Luis Perales Gómez, Chao Feng 0001, Pedro Miguel Sánchez Sánchez, Sergio López Bernal, Gérôme Bovet, Manuel Gil Pérez, Gregorio Martínez Pérez, Alberto Huertas Celdrán |
Expert Syst. Appl. | 3 |
| 2023 | HomeScout: Anti-Stalking Mobile App for Bluetooth Low Energy DevicesabstractBluetooth Low Energy (BLE) personal trackers are affordable devices misused to track nonconsensual individuals. Due to the increased misuse, Apple implemented two detection applications. However, the Android application is limited to user-initiated scans with a fixed detection algorithm. This paper focuses on reducing the misuse of malicious trackers by examining current solutions, potential generic detection approaches, and improving tracker detection times.HomeScout expands detection to the Tile and Samsung Galaxy SmartTag+, and examines the misuse potential of all BLE-enabled devices. HomeScout can reliably detect devices tracking the user as quickly as 1 minute once in motion by optimizing the parameters. The optimal parameter setting for distance is 200 m due to its high recall rate, for occurrence is 2, and for time is 1 minute. Furthermore, HomeScout applies the tracking algorithm to all BLE-enabled devices. Katharina O. E. Müller, Louis Bienz, Bruno Rodrigues 0001, Chao Feng 0001, Burkhard Stiller |
LCN | 4 |
| 2023 | Demo: Utilizing SRv6 to Optimize the Routing Behavior for Tactical Networks
Eryk Schiller, Chao Feng 0001, Rafael Hengen Ribeiro, Martin Buck, Burkhard Stiller |
WoWMoM | 2 |
| 2023 | Privacy-Preserving and Syscall-Based Intrusion Detection System for IoT Spectrum Sensors Affected by Data Falsification AttacksabstractCrowdsensing platforms collect, process, transmit, and analyze spectrum data worldwide to optimize radio frequency spectrum usage. However, Internet of Things (IoT) spectrum sensors, performing some of the previous tasks, are exposed to software manipulation aiming to execute spectrum sensing data falsification (SSDF) attacks to compromise data integrity and spectrum optimization. Novel intrusion detection systems (IDSs) combining device fingerprinting with machine and deep learning (ML/DL) improve the limitation of traditional solutions and remove the necessity of redundant sensors and reputation mechanisms. However, they fail when detecting SSDF attacks accurately while protecting sensors privacy. This work proposes a novel host-based and federated learning-oriented IDS for IoT spectrum sensors that consider unsupervised ML/DL and fingerprints based on system calls. The framework detection performance and consumption of resources are analyzed in local and federated scenarios with six spectrum sensors deployed on Raspberry Pis. The obtained results significantly improve related work when detecting SSDF attacks while protecting sensors privacy, and consuming CPU, memory, and storage of sensors in a reduced manner. Alberto Huertas Celdrán, Pedro Miguel Sánchez Sánchez, Chao Feng 0001, Gérôme Bovet, Gregorio Martínez Pérez, Burkhard Stiller |
IEEE Internet Things J. | 3 |