VLDB 2026 Research / reviewers in the wild / expert
Yi Liu 0057
dblp:97/4626-57
· DBLP profile ↗
33ranked-venue papers
16as first author
27since 2021 · last 2026
0000-0002-0811-6150ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 10 · 8 first-author · 7 since 2021Artificial intelligence and machine learning · 7 · 2 first-author · 7 since 2021Databases, data management, data science and information retrieval · 6 · 2 first-author · 6 since 2021Systems, architecture and hardware · 5 · 3 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 4 since 2021Security and privacy · 3 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PrivTune: Efficient and Privacy-Preserving Fine-Tuning of Large Language Models via Device-Cloud Collaboration
Yi Liu 0057, Weixiang Han, Chengjun Cai, Xingliang Yuan, Cong Wang 0001 |
INFOCOM | 1 |
| 2026 | Medusa: Cross-Modal Transferable Adversarial Attacks on Multimodal Medical Retrieval-Augmented GenerationabstractWith the rapid advancement of retrieval-augmented vision-language models, multimodal medical retrieval-augmented generation (MMed-RAG) systems are increasingly adopted in clinical decision support. These systems enhance medical applications by performing cross-modal retrieval to integrate relevant visual and textual evidence for tasks, e.g., report generation and disease diagnosis. However, their complex architecture also introduces underexplored adversarial vulnerabilities, particularly via visual input perturbations. In this paper, we propose Medusa, a novel framework for crafting cross-modal transferable adversarial attacks on MMed-RAG systems under a black-box setting. Specifically, Medusa formulates the attack as a perturbation optimization problem, leveraging a multi-positive InfoNCE loss (MPIL) to align adversarial visual embeddings with medically plausible but malicious textual targets, thereby hijacking the retrieval process. To enhance transferability, we adopt a surrogate model ensemble and design a dual-loop optimization strategy augmented with invariant risk minimization (IRM). Extensive experiments on two real-world medical tasks, including medical report generation and disease diagnosis, demonstrate that Medusa achieves over 90% average attack success rate across various generation models and retrievers under appropriate parameter configuration, while remaining robust against four mainstream defenses, outperforming state-of-the-art baselines. Our results reveal critical vulnerabilities in the MMed-RAG systems and highlight the necessity of robustness benchmarking in safety-critical medical applications. The code and data are available at https://github.com/yiliucs/MMed-RAG-Attack. © 2026 Owner/Author. Yingjia Shang, Yi Liu 0057, Wenfang Sun, Yefeng Zheng 0001 |
KDD (1) | 2 |
| 2026 | Toward Efficient Membership Inference Attacks Against Federated Large Language Models: A Projection Residual Approach
Guilin Deng, Silong Chen, Yuchuan Luo, Yi Liu 0057, Songlei Wang, Zhiping Cai, Lin Liu 0018, Xiaohua Jia, Shaojing Fu |
SP | 4 |
| 2026 | Reconstructing Training Data from Adapter-based Federated Large Language ModelsabstractAdapter-based Federated Large Language Models (FedLLMs) are widely adopted to reduce the computational, storage, and communication overhead of full-parameter fine-tuning for web-scale applications while preserving user privacy. By freezing the backbone and training only compact low-rank adapters, these methods appear to limit gradient leakage and thwart existing Gradient Inversion Attacks (GIAs). Contrary to this assumption, we show that low-rank adapters create new, exploitable leakage channels. We propose the Unordered-word-bag-based Text Reconstruction (UTR) attack, a novel GIA tailored to the unique structure of adapter-based FedLLMs. UTR overcomes three core challenges—low-dimensional gradients, frozen backbones, and combinatorially large reconstruction spaces—by: (i) inferring token presence from attention patterns in frozen layers, (ii) performing sentence-level inversion within the low-rank subspace of adapter gradients, and (iii) enforcing semantic coherence through constrained greedy decoding guided by language priors. Extensive experiments across diverse models (GPT2-Large, BERT, Qwen2.5-7B) and datasets (CoLA, SST-2, Rotten Tomatoes) demonstrate that UTR achieves near-perfect reconstruction accuracy (ROUGE-1/2 > 99), even with large batch sizes—settings where prior GIAs fail completely. Our results reveal a fundamental tension between parameter efficiency and privacy in FedLLMs, challenging the prevailing belief that lightweight adaptation inherently enhances security. Our code and data are available at https://github.com/shwksnshwowk-wq/GIA Silong Chen, Yuchuan Luo, Guilin Deng, Yi Liu 0057, Ming Xu 0002, Shaojing Fu, Xiaohua Jia |
WWW | 4 |
| 2026 | Adapting Large Language Models for Encrypted Traffic Analysis Services: An Efficient Realization With Mixture of LoRA ExpertsabstractAs encrypted traffic grows, traditional rule-based and deep learning methods struggle with engineering costs and encryption complexity. While Large Language Models (LLMs) offer promise for traffic analysis via pre-trained feature learning, they face challenges in handling diverse tasks, retaining pre-training knowledge, and adapting efficiently. To address these issues, we propose a new traffic representation learning method and a new Parameter-Efficient Fine-Tuning (PEFT) method for multi-task encrypted traffic analysis services, calledTrafficLLM.TrafficLLMalleviates task heterogeneity by utilizing a universal multi-task prompt template and addresses pre-training knowledge forgetting by integrating Singular Value Decomposition based Low-Rank Adaptation (SVD-LoRA). To further reduce the cost of adapting to multiple tasks, we combine the strengths of the Mixture of Experts (MoE) for multi-task learning with SVD-LoRA for PEFT, enabling efficient multi-task traffic analysis. Additionally, we introduce task-aware gating functions to dynamically assign different weights to experts, facilitating the efficient fusion of expert knowledge. Comprehensive experiments on 7 datasets across 5 downstream tasks demonstrate thatTrafficLLMdelivers superior analysis performance and resource efficiency compared to state-of-the-art models, including DeepSeek, NetGPT, ET-BERT, and TFE-GNN. Detailed analysis of throughput, memory usage, and latency further highlights the practical advantages ofTrafficLLM. Our data and code are available athttps://github.com/yiliucs/TrafficLLMhttps://github.com/yiliucs/TrafficLLM. Yi Liu 0057, Chengjun Cai, Xingliang Yuan, Cong Wang 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2025 | CALM: Curiosity-Driven Auditing for Large Language ModelsabstractAuditing Large Language Models (LLMs) is a crucial and challenging task. In this study, we focus on auditing black-box LLMs without access to their parameters, only to the provided service. We treat this type of auditing as a black-box optimization problem where the goal is to automatically uncover input-output pairs of the target LLMs that exhibit illegal, immoral, or unsafe behaviors. For instance, we may seek a non-toxic input that the target LLM responds to with a toxic output or an input that induces the hallucinative response from the target LLM containing politically sensitive individuals. This black-box optimization is challenging due to the scarcity of feasible points, the discrete nature of the prompt space, and the large search space. To address these challenges, we propose Curiosity-Driven Auditing for Large Language Models (CALM), which uses intrinsically motivated reinforcement learning to finetune an LLM as the auditor agent to uncover potential harmful and biased input-output pairs of the target LLM. CALM successfully identifies derogatory completions involving celebrities and uncovers inputs that elicit specific names under the black-box setting. This work offers a promising direction for auditing black-box LLMs. Yi Liu 0057, Xingjun Ma, Chao Shen 0001, Cong Wang 0001 |
AAAI | 3 |
| 2025 | SAP: Privacy-Preserving Fine-Tuning on Language Models with Split-and-Privatize FrameworkabstractPre-trained Language Models (PLM) have enabled a cost-effective approach to handling various downstream applications via Parameter-Efficient-Fine-Tuning (PEFT) techniques. In this context, service providers have introduced a popular fine-tuning-based product service known as Model-as-a-Service (MaaS). This service offers users access to extensive PLMs and training resources. With MaaS, users can fine-tune, deploy, and utilize their customized models seamlessly, leveraging a one-stop platform that allows them to work with their private datasets efficiently. However, this service paradigm has recently been exposed to the possibility of leaking user private data. To this end, we identify the data privacy leakage risks in MaaS-based PEFT and propose a Split-and-Privatize (SAP) framework, mitigating the privacy leakage by integrating split learning and differential privacy into MaaS PEFT. Furthermore, we propose Contributing-Token-Identification (CTI), a novel method to balance model utility degradation and privacy leakage. As a result, the proposed framework is comprehensively evaluated, demonstrating a 65% improvement in empirical privacy with only a 1% degradation in model performance on the Stanford Sentiment Treebank dataset, outperforming existing state-of-the-art baselines. Xicong Shen, Yi Liu 0057, Peiran Wang, Huiqi Liu, Jue Hong, Bing Duan, Zirui Huang, Yunlong Mao, Sheng Zhong 0002 |
IJCAI | 3 |
| 2025 | FedMobile: Enabling Knowledge Contribution-aware Multi-modal Federated Learning with Incomplete ModalitiesabstractThe Web of Things (WoT) enhances interoperability across webbased and ubiquitous computing platforms while complementing existing IoT standards.The multimodal Federated Learning (FL) paradigm has been introduced to enhance WoT by enabling the fusion of multi-source mobile sensing data while preserving privacy.However, a key challenge in mobile sensing systems using multimodal FL is modality incompleteness, where some modalities may be unavailable or only partially captured, potentially degrading the system's performance and reliability.Current multimodal FL frameworks typically train multiple unimodal FL subsystems or apply interpolation techniques on the node side to approximate missing modalities.However, these approaches overlook the shared latent feature space among incomplete modalities across different nodes and fail to discriminate against low-quality nodes.To address this gap, we present FedMobile, a new knowledge contribution-aware multimodal FL framework designed for robust learning despite missing modalities.FedMobile prioritizes local-to-global knowledge transfer, leveraging cross-node multimodal feature information to reconstruct missing features.It also enhances system performance and resilience to modality heterogeneity through rigorous node contribution assessments and knowledge contribution-aware aggregation rules.Empirical evaluations on five widely recognized multimodal benchmark datasets demonstrate that FedMobile maintains robust learning even when up to 90% of modality information is missing or when data from two modalities are randomly missing, outperforming state-of-the-art baselines.Our code and data are available at the link. Yi Liu 0057, Cong Wang 0001, Xingliang Yuan |
WWW | 1 |
| 2025 | Collaborative Neural Architecture Search for Personalized Federated LearningabstractPersonalized federated learning (pFL) is a promising approach to train customized models for multiple clients over heterogeneous data distributions. However, existing works on pFL often rely on the optimization of model parameters and ignore the personalization demand on neural network architecture, which can greatly affect the model performance in practice. Therefore, generating personalized models with different neural architectures for different clients is a key issue in implementing pFL in a heterogeneous environment. Motivated by Neural Architecture Search (NAS), a model architecture searching methodology, this paper aims to automate the model design in a collaborative manner while achieving good training performance for each client. Specifically, we reconstruct the centralized searching of NAS into the distributed scheme called Personalized Architecture Search (PAS), where differentiable architecture fine-tuning is achieved via gradient-descent optimization, thus making each client obtain the most appropriate model. Furthermore, to aggregate knowledge from heterogeneous neural architectures, a knowledge distillation-based training framework is proposed to achieve a good trade-off between generalization and personalization in federated learning. Extensive experiments demonstrate that our architecture-level personalization method achieves higher accuracy under the non-iid settings, while not aggravating model complexity over state-of-the-art benchmarks. Yi Liu 0057, Song Guo 0001, Jie Zhang 0076, Zicong Hong, Yufeng Zhan, Qihua Zhou |
IEEE Trans. Computers | 1 |
| 2025 | Feature Correlation-Guided Knowledge Transfer for Federated Self-Supervised LearningabstractExtensive attention has been paid to the application of self-supervised learning (SSL) approaches on federated learning (FL) to tackle the label scarcity problem. Previous works on federated SSL (FedSSL) generally fall into two categories: parameter-based model aggregation or data-based feature sharing to achieve knowledge transfer among multiple unlabeled clients. Despite the progress, they inevitably rely on some assumptions, such as homogeneous models or the existence of an additional public dataset, which hinder the universality of the training frameworks for more general scenarios (e.g., unlabeled clients with heterogeneous models). Therefore, in this article, we propose a novel and general method named federated self-supervised learning with feature-correlation-based aggregation (FedFoA) to tackle the above limitations. By exchanging feature correlation instead of model parameters or feature mappings, our approach reduces the discrepancies of local representations learning processes, thus promoting collaboration between heterogeneous clients. A factorization-based method is designed to extract the cross-feature relation matrix from local representations, which serves as a knowledge medium for the aggregation phase. We demonstrate that FedFoA is a heterogeneity-supportive and privacy-preserving training framework and can be easily compatible with state-of-the-art FedSSL methods. Extensive empirical experiments demonstrate our proposed approach outperforms the state-of-the-art methods by a significant margin. Yi Liu 0057, Song Guo 0001, Jie Zhang 0076, Yufeng Zhan, Qihua Zhou, Yingchun Wang 0002 |
IEEE Trans. Neural Networks Learn. Syst. | 1 |
| 2024 | BadSampler: Harnessing the Power of Catastrophic Forgetting to Poison Byzantine-robust Federated LearningabstractFederated Learning (FL) is susceptible to poisoning attacks, wherein compromised clients manipulate the global model by modifying local datasets or sending manipulated model updates. Experienced defenders can readily detect and mitigate the poisoning effects of malicious behaviors using Byzantine-robust aggregation rules. However, the exploration of poisoning attacks in scenarios where such behaviors are absent remains largely unexplored for Byzantine-robust FL. This paper addresses the challenging problem of poisoning Byzantine-robust FL by introducing catastrophic forgetting. To fill this gap, we first formally define generalization error and establish its connection to catastrophic forgetting, paving the way for the development of a clean-label data poisoning attack named BadSampler. This attack leverages only clean-label data (i.e., without poisoned data) to poison Byzantine-robust FL and requires the adversary to selectively sample training data with high loss to feed model training and maximize the model's generalization error. We formulate the attack as an optimization problem and present two elegant adversarial sampling strategies, Top-$\kappa$ sampling, and meta-sampling, to approximately solve it. Additionally, our formal error upper bound and time complexity analysis demonstrate that our design can preserve attack utility with high efficiency. Extensive evaluations on two real-world datasets illustrate the effectiveness and performance of our proposed attacks. Yi Liu 0057, Cong Wang 0001, Xingliang Yuan |
KDD | 1 |
| 2024 | Arondight: Red Teaming Large Vision Language Models with Auto-generated Multi-modal Jailbreak PromptsabstractLarge Vision Language Models (VLMs) extend and enhance the perceptual abilities of Large Language Models (LLMs).Despite offering new possibilities for LLM applications, these advancements raise significant security and ethical concerns, particularly regarding the generation of harmful content.While LLMs have undergone extensive security evaluations with the aid of red teaming frameworks, VLMs currently lack a well-developed one.To fill this gap, we introduce Arondight, a standardized red team framework tailored specifically for VLMs.Arondight is dedicated to resolving issues related to the absence of visual modality and inadequate diversity encountered when transitioning existing red teaming methodologies from LLMs to VLMs.Our framework features an automated multi-modal jailbreak attack, wherein visual jailbreak prompts are produced by a red team VLM, and textual prompts are generated by a red team LLM guided by a reinforcement learning agent.To enhance the comprehensiveness of VLM security evaluation, we integrate entropy bonuses and novelty reward metrics.These elements incentivize the RL agent to guide the red team LLM in creating a wider array of diverse and previously unseen test cases.Our evaluation of ten cutting-edge VLMs exposes significant security vulnerabilities, particularly in generating toxic images and aligning multi-modal prompts.In particular, our Arondight achieves an average attack success rate of 84.5% on GPT-4 in all fourteen prohibited scenarios defined by OpenAI in terms of generating toxic text.For a clearer comparison, we also categorize existing VLMs based on their safety levels and provide corresponding reinforcement recommendations.Our multimodal prompt dataset and red team code will be released after ethics committee approval. Yi Liu 0057, Chengjun Cai, Xiaoli Zhang 0003, Xingliang Yuan, Cong Wang 0001 |
ACM Multimedia | 1 |
| 2024 | SFP: Spurious Feature-Targeted Pruning for Out-of-Distribution GeneralizationabstractRecent studies reveal that even highly biased dense networks can contain an invariant substructure with superior out-of-distribution (OOD) generalization. While existing works commonly seek these substructures using global sparsity constraints, the uniform imposition of sparse penalties across samples with diverse levels of spurious contents renders such methods suboptimal. The precise adaptation of model sparsity, specifically tailored for spurious features, remains a significant challenge. Motivated by the insight that in-distribution (ID) data containing spurious features may exhibit lower experiential risk, we propose a novel Spurious Feature-targeted Pruning framework, dubbed SFP, to induce the authentic invariant substructures without referring to the above concerns. Specifically, SFP distinguishes spurious features within ID instances during training by a theoretically validated threshold. It then penalizes the corresponding feature projections onto the model space, steering the optimization towards subspaces spanned by those invariant factors. Moreover, we also conduct detailed theoretical analysis to provide a rationality guarantee and a proof framework for OOD structures based on model sparsity. Experiments on various OOD datasets show that SFP can significantly outperform both structure-based and non-structure-based OOD generalization state-of-the-art (SOTA) methods by large margins. Yingchun Wang 0001, Jingcai Guo, Song Guo 0001, Yi Liu 0057, Jie Zhang 0076, Weizhan Zhang |
ACM Multimedia | 4 |
| 2024 | Chiron: A Robustness-Aware Incentive Scheme for Edge Learning via Hierarchical Reinforcement LearningabstractOver the past few years, edge learning has achieved significant success in mobile edge networks. Few works have designed incentive mechanism that motivates edge nodes to participate in edge learning. However, most existing works only consider myopic optimization and assume that all edge nodes are honest, which lacks long-term sustainability and the final performance assurance. In this paper, we propose Chiron, an incentive-driven Byzantine-resistant long-term mechanism based on hierarchical reinforcement learning (HRL). First, our optimization goal includes both learning-algorithm performance criteria (i.e., global accuracy) and systematical criteria (i.e., resource consumption), which aim to improve the edge learning performance under a given resource budget. Second, we propose a three-layer HRL architecture to handle long-term optimization, short-term optimization, and byzantine resistance, respectively. Finally, we conduct experiments on various edge learning tasks to demonstrate the superiority of the proposed approach. Specifically, our system can successfully exclude malicious nodes and lazy nodes out of the edge learning participation and achieves 14.96% higher accuracy and 12.66% higher total utility than the state-of-the-art methods under the same budget limit. Yi Liu 0057, Song Guo 0001, Yufeng Zhan, Leijie Wu, Zicong Hong, Qihua Zhou |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Long-Term Adaptive VCG Auction Mechanism for Sustainable Federated Learning With Periodical Client ShiftingabstractFederated Learning (FL) system needs to incentivize clients since they may be reluctant to participate in the resource consuming process. Existing incentive mechanisms fail to construct a sustainable environment for the long-term development of FL system: 1) They seldom focus on system economic properties (e.g., social welfare, individual rationality, and incentive compatibility) to guarantee client attraction. 2) Current online auction modeling methods divide the whole continual process into multiple independent rounds and solve them one-by-one, which breaks the correlation between each round. Besides, the inherent characteristics of FL system (model-agnostic and privacy-sensitive) also prevent it from the optimal strategy by precise mathematical analysis. 3) Current system modelings ignore the practical problem of periodical client shifting, which cannot adaptively update its strategy to handle system dynamics. To overcome the above challenges, this paper proposes a long-term adaptive Vickrey–Clarke–Groves (VCG) auction mechanism for FL system, which incorporate a multi-branch deep reinforcement learning (DRL) algorithm. First, VCG auction is the only one that can simultaneously guarantee all crucial economic properties. Second, we extend the economic properties to long-term forms and apply the experience-driven DRL algorithm to directly obtain long-term optimal strategy, without any prior system knowledge. Third, we reconstruct a multi-branch DRL network to accommodate periodical client shifting by adaptive decision head switching for different time periods. Finally, we theoretically prove he extended economic properties (i.e., IC) and conduct extensive experiments on several real-world datasets. Compared with state-of-the-art approaches, the long-term social welfare of FL system increases by 36% with a 37% reduction in payment. Besides, the multi-branch network can adaptively handle periodical client shifting on the timeline. Leijie Wu, Song Guo 0001, Zicong Hong, Yi Liu 0057, Wenchao Xu 0001, Yufeng Zhan |
IEEE Trans. Mob. Comput. | 4 |
| 2023 | Cross-Domain Disentangled Learning for E-Commerce Live Streaming RecommendationabstractE-commerce live streaming as an increasingly popular sales model has generated a significant amount of gross merchandise value (GMV) for e-commerce platforms. Live streaming recommendation systems (LSRS) of e-commerce aim to recommend the most appropriate live channels for users to motivate them to buy products. Existing LSRS methods focus only on the user’s interaction behaviors on the live channel (live domain) while ignoring the user’s behaviors and intentions on the e-commerce product (product domain). As a result, the user’s consistent purchase intentions in the cross-domain are not being fully captured, especially when user present differentiated purchase intentions in the cross-domain. How to disentangle user’s consistent intentions and domain-specific intentions in the cross-domain poses a challenge to the LSRS of e-commerce platforms. In this paper, we present a live channel recommendation method, named eLiveRec, developed for Taobao, one of the largest e-commerce platform in the world. Specifically, eLiveRec employs the disentangled encoder module to learn user’s cross-domain consistent intentions and domain-specific intentions. Then, an adaptive multi-task learning framework is developed to jointly optimize the multiple objectives (e.g., stay time, click goods bag, and click products after entering channel) related to live streaming recommendation. In this way, the performance of live streaming recommendation can be further improved and con-form to standard industry RS paradigms. Extensive experiments are conducted on a large-scale industry dataset collected from Taobao Live platform have been performed. Both online and offline experimental results indicate that eLiveRec consistently outperforms existing state-of-the-art baseline methods. Yong Liu 0020, Yi Liu 0057, Fuqiang Yu, Wei He 0020, Li-Zhen Cui 0001, Chunyan Miao |
ICDE | 4 |
| 2023 | Aggregation Service for Federated Learning: An Efficient, Secure, and More Resilient RealizationabstractFederated learning has recently emerged as a paradigm promising the benefits of harnessing rich data from diverse sources to train high quality models, with the salient features that training datasets never leave local devices. Only model updates are locally computed and shared for aggregation to produce a global model. While federated learning greatly alleviates the privacy concerns as opposed to learning with centralized data, sharing model updates still poses privacy risks. In this paper, we present a system design which offers efficient protection of individual model updates throughout the learning procedure, allowing clients to only provide obscured model updates while a cloud server can still perform the aggregation. Our federated learning system first departs from prior works by supporting lightweight encryption and aggregation, and resilience against drop-out clients with no impact on their participation in future rounds. Meanwhile, prior work largely overlooks bandwidth efficiency optimization in the ciphertext domain and the support of security against an actively adversarial cloud server, which we also fully explore in this paper and provide effective and efficient mechanisms. Extensive experiments over several benchmark datasets (MNIST, CIFAR-10, and CelebA) show our system achieves accuracy comparable to the plaintext baseline, with practical performance. Yifeng Zheng 0001, Shangqi Lai, Yi Liu 0057, Xingliang Yuan, Xun Yi, Cong Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | MCSCSet: A Specialist-annotated Dataset for Medical-domain Chinese Spelling CorrectionabstractChinese Spelling Correction (CSC) is gaining increasing attention in recent years. Despite its extensive use in many applications, such as search engine and optical character recognition system, little has been explored in medical scenarios in which complex and uncommon medical entities are easily misspelled. Correcting the misspellings of medical entities is arguably more difficult than those in the open domain due to its requirements of specific domain knowledge. In this work, we define the task of Medical-domain Chinese Spelling Correction (MCSC) and propose MCSCSet, a large-scale specialist-annotated dataset that contains about 200k samples. In contrast to existing open-domain CSC datasets, MCSCSet involves: i) extensive real-world medical queries collected from Tencent Yidian, ii) corresponding misspelled sentences manually annotated by medical specialists. Our work further offers a medical-domain confusion set consisting of the common error-prone characters in medicine and their corresponding misspellings. Extensive empirical studies have shown significant gaps between the open-domain and medical-domain spelling correction, highlighting the need to develop high-quality datasets that allow for CSC in specific domains. Moreover, our work benchmarks several representative methods, establishing baselines for future work. Wangjie Jiang, Zhihao Ye, Zijing Ou, Ruihui Zhao, Jianguang Zheng, Yi Liu 0057, Bang Liu 0003, Siheng Li, Yujiu Yang 0001, Yefeng Zheng 0001 |
CIKM | 6 |
| 2022 | Sustainable Federated Learning with Long-term Online VCG Auction MechanismabstractFederated learning (FL) clients may be reluctant to participate in the energy-consuming FL unless they are incentivized. Existing incentive mechanisms seldom consider the economic properties, e.g., social welfare, individual rationality and incentive compatibility, which significantly limits the sustainability of FL to attract more clients. The Vickrey–Clarke–Groves (VCG) auction is an ideal mechanism for simultaneously guaranteeing all crucial economic properties to maximize social welfare. However, VCG auction cannot be applied directly to FL scenarios due to the following challenges: 1) It requires precise analytical derivation of the optimal strategy, which is unavailable due to the inherent model-unknown and privacy-sensitive characteristics of FL. 2) Current auction modeling decomposes the entire process into multiple independent rounds and solves them one-by-one, which breaks the successive correlation between rounds in the long-term training process of FL. To overcome these challenges, this paper presents a long-term online VCG auction mechanism for FL that employs an experience-driven deep reinforcement learning algorithm to obtain the optimal strategy. Besides, we extend long-term forms of the crucial economic properties for the successive FL process. Furthermore, knowledge transfer is applied to reduce the excessive training overhead arising from the VCG payment rules. By exploiting the environmental similarity among sub-auctions, we develop the strategy sharing to significantly cut the training time by half. Finally, we theoretically prove the extended economic properties and conduct extensive experiments on multiple real-world datasets. Compared with state-of-the-art approaches, the long-term social welfare of FL increases by 36% with a 37% reduction in payment. Leijie Wu, Song Guo 0001, Yi Liu 0057, Zicong Hong, Yufeng Zhan, Wenchao Xu 0001 |
ICDCS | 3 |
| 2022 | The Right to be Forgotten in Federated Learning: An Efficient Realization with Rapid RetrainingabstractIn Machine Learning, the emergence of the right to be forgotten gave birth to a paradigm named machine unlearning, which enables data holders to proactively erase their data from a trained model. Existing machine unlearning techniques focus on centralized training, where access to all holders’ training data is a must for the server to conduct the unlearning process. It remains largely underexplored about how to achieve unlearning when full access to all training data becomes unavailable. One noteworthy example is Federated Learning (FL), where each participating data holder trains locally, without sharing their training data to the central server. In this paper, we investigate the problem of machine unlearning in FL systems. We start with a formal definition of the unlearning problem in FL and propose a rapid retraining approach to fully erase data samples from a trained FL model. The resulting design allows data holders to jointly conduct the unlearning process efficiently while keeping their training data locally. Our formal convergence and complexity analysis demonstrate that our design can preserve model utility with high efficiency. Extensive evaluations on four real-world datasets illustrate the effectiveness and performance of our proposed realization. Yi Liu 0057, Lei Xu 0019, Xingliang Yuan, Cong Wang 0001, Bo Li 0001 |
INFOCOM | 1 |
| 2022 | Hierarchical Channel-spatial Encoding for Communication-efficient Collaborative LearningabstractIt witnesses that the collaborative learning (CL) systems often face the performance bottleneck of limited bandwidth, where multiple low-end devices continuously generate data and transmit intermediate features to the cloud for incremental training. To this end, improving the communication efficiency by reducing traffic size is one of the most crucial issues for realistic deployment. Existing systems mostly compress features at pixel level and ignore the characteristics of feature structure, which could be further exploited for more efficient compression. In this paper, we take new insights into implementing scalable CL systems through a hierarchical compression on features, termed Stripe-wise Group Quantization (SGQ). Different from previous unstructured quantization methods, SGQ captures both channel and spatial similarity in pixels, and simultaneously encodes features in these two levels to gain a much higher compression ratio. In particular, we refactor feature structure based on inter-channel similarity and bound the gradient deviation caused by quantization, in forward and backward passes, respectively. Such a double-stage pipeline makes SGQ hold a sublinear convergence order as the vanilla SGD-based optimization. Extensive experiments show that SGQ achieves a higher traffic reduction ratio by up to 15.97 times and provides 9.22 times image processing speedup over the uniform quantized training, while preserving adequate model accuracy as FP32 does, even using 4-bit quantization. This verifies that SGQ can be applied to a wide spectrum of edge intelligence applications. Qihua Zhou, Song Guo 0001, Yi Liu 0057, Jie Zhang 0076, Jiewei Zhang, Tao Guo 0004, Zhenda Xu, Zhihao Qu |
NeurIPS | 3 |
| 2022 | Semi-Supervised Federated Learning for Travel Mode Identification From GPS TrajectoriesabstractGPS trajectories serve as a significant data source for travel mode identification along with the development of various GPS-enabled smart devices. However, such data directly integrate user private information, thus hindering users from sharing data with third parties. On the other hand, existing identification methods heavily depend on the respective manual travel mode annotations, whose production is economically inefficient and error-prone. In this paper, we propose a Semi-supervised Federated Learning (SSFL) framework that can accurately identify travel modes without using users’ raw trajectories data or relying on notable data labels. Specifically, we propose a new identification model named convolutional neural network-gated recurrent unit model in SSFL to accurately infer travel modes from GPS trajectories. Second, we design a pseudo-labeling method for the clients to set pseudo-labels on their local unlabeled dataset by using a small public dataset at the server. Furthermore, we adopt a grouping-based aggregation scheme and a data flipping augmentation scheme, which can boost the convergence and performance of the proposed framework. Comprehensive evaluations on a real-world dataset show that SSFL outperforms centralized semi-supervised baselines and is robust to the non-independent and identically distributed data commonly seen in practice. Yuanshao Zhu, Yi Liu 0057, James Jian Qiao Yu, Xingliang Yuan |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2022 | Cross-Area Travel Time Uncertainty Estimation From Trajectory Data: A Federated Learning ApproachabstractAlong with urbanization and the deployment of GPS sensors in vehicles and mobile phones, massive amounts of trajectory data have been generated for city areas. The analysis of these data has substantially contributed to research and advancements of travel time estimation. However, existing work focuses on estimating travel time inside a particular area, and cross-area travel time estimation has privacy security challenges due to data exchange issues among areas. Meanwhile, the majority of methods estimate a deterministic travel time for a given trajectory, which does not account for complex traffic situations and user requirements. To address these problems, we propose a cross-area travel time uncertainty estimation algorithm for estimating the uncertainty of travel times while preserving privacy among different areas. Specifically, we design a comprehensive cross-area privacy-preserving solution that trains a tailor-made neural network travel time estimator in each area by local data, and incorporates federated learning for training. Furthermore, we employ Bayesian deep learning principles and adopt Monte-Carlo dropout to quantify the uncertainty associated with travel time. To evaluate the proposed approach, we conduct a series of comprehensive case studies with two real-world trajectory datasets. Extensive results demonstrate the superiority of the proposed approach compared to baselines in the context of the cross-area setting. Yuanshao Zhu, Yongchao Ye, Yi Liu 0057, James Jian Qiao Yu |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2022 | Towards Communication-Efficient and Attack-Resistant Federated Edge Learning for Industrial Internet of ThingsabstractFederated Edge Learning (FEL) allows edge nodes to train a global deep learning model collaboratively for edge computing in the Industrial Internet of Things (IIoT), which significantly promotes the development of Industrial 4.0. However, FEL faces two critical challenges: communication overhead and data privacy. FEL suffers from expensive communication overhead when training large-scale multi-node models. Furthermore, due to the vulnerability of FEL to gradient leakage and label-flipping attacks, the training process of the global model is easily compromised by adversaries. To address these challenges, we propose a communication-efficient and privacy-enhanced asynchronous FEL framework for edge computing in IIoT. First, we introduce an asynchronous model update scheme to reduce the computation time that edge nodes wait for global model aggregation. Second, we propose an asynchronous local differential privacy mechanism, which improves communication efficiency and mitigates gradient leakage attacks by adding well-designed noise to the gradients of edge nodes. Third, we design a cloud-side malicious node detection mechanism to detect malicious nodes by testing the local model quality. Such a mechanism can avoid malicious nodes participating in training to mitigate label-flipping attacks. Extensive experimental studies on two real-world datasets demonstrate that the proposed framework can not only improve communication efficiency but also mitigate malicious attacks while its accuracy is comparable to traditional FEL frameworks. Yi Liu 0057, Ruihui Zhao, Jiawen Kang 0001, Abdulsalam Yassine, Dusit Niyato, Jialiang Peng |
ACM Trans. Internet Techn. | 1 |
| 2021 | Incentive-Driven Long-term Optimization for Edge Learning by Hierarchical Reinforcement MechanismabstractEdge Learning is an emerging distributed machine learning in mobile edge network. Limited works have designed mechanisms to incentivize edge nodes to participate in edge learning. However, their mechanisms only consider myopia optimization on resource consumption, which results in the lack of learning algorithm performance guarantee and longterm sustainability. In this paper, we propose Chiron, an incentive-driven long-term mechanism for edge learning based on hierarchical deep reinforcement learning. First, our optimization goal combines learning-algorithms metric (i.e., model accuracy) with system metric (i.e., learning time, and resource consumption), which can improve edge learning quality under a fixed training budget. Second, we present a two-layer H-DRL design with exterior and inner agents to achieve both long-term and short-term optimization for edge learning, respectively. Finally, experiments on three different real-world datasets are conducted to demonstrate the superiority of our proposed approach. In particular, compared with the state-of-the-art methods under the same budget constraint, the final global model accuracy and time efficiency can be increased by 6.5 % and 39 %, respectively. Our implementation is available at https://github.com/Joey61Liuyi/Chiron. Yi Liu 0057, Leijie Wu, Yufeng Zhan, Song Guo 0001, Zicong Hong |
ICDCS | 1 |
| 2021 | Deep Anomaly Detection for Time-Series Data in Industrial IoT: A Communication-Efficient On-Device Federated Learning ApproachabstractSince edge device failures (i.e., anomalies) seriously affect the production of industrial products in Industrial IoT (IIoT), accurately and timely detecting anomalies are becoming increasingly important. Furthermore, data collected by the edge device contain massive user's private data, which is challenging current detection approaches as user privacy has attracted more and more public concerns. With this focus, this article proposes a new communication-efficient on-device federated learning (FL)-based deep anomaly detection framework for sensing time-series data in IIoT. Specifically, we first introduce an FL framework to enable decentralized edge devices to collaboratively train an anomaly detection model, which can improve its generalization ability. Second, we propose an attention mechanism-based convolutional neural network-long short-term memory (AMCNN-LSTM) model to accurately detect anomalies. The AMCNN-LSTM model uses attention mechanism-based convolutional neural network units to capture important fine-grained features, thereby preventing memory loss and gradient dispersion problems. Furthermore, this model retains the advantages of the long short-term memory unit in predicting time-series data. Third, to adapt the proposed framework to the timeliness of industrial anomaly detection, we propose a gradient compression mechanism based on Top- k selection to improve communication efficiency. Extensive experimental studies on four real-world data sets demonstrate that our framework accurately and timely detects anomalies and also reduces the communication overhead by 50% compared to the FL framework that does not use the gradient compression scheme. Yi Liu 0057, Sahil Garg, Jiangtian Nie, Yang Zhang 0025, Zehui Xiong, Jiawen Kang 0001, M. Shamim Hossain |
IEEE Internet Things J. | 1 |
| 2021 | Federated Learning in the Sky: Aerial-Ground Air Quality Sensing Framework With UAV SwarmsabstractDue to air quality significantly affects human health, it is becoming increasingly important to accurately and timely predict the air quality index (AQI). To this end, this article proposes a new federated learning (FL)-based aerial-ground air quality sensing framework for fine-grained 3-D air quality monitoring and forecasting. Specifically, in the air, this framework leverages a lightweight Dense-MobileNet model to achieve energy-efficient end-to-end learning from haze features of haze images taken by unmanned aerial vehicles (UAVs) for predicting AQI scale distribution. Furthermore, the FL framework not only allows various organizations or institutions to collaboratively learn a well-trained global model to monitor AQI without compromising privacy but also expands the scope of UAV swarms monitoring. For ground sensing systems, we propose a graph convolutional neural network-based long short-term memory (GC-LSTM) model to achieve accurate, real time, and future AQI inference. The GC-LSTM model utilizes the topological structure of the ground monitoring station to capture the spatiotemporal correlation of historical observation data, which helps the aerial-ground sensing system to achieve accurate AQI inference. Through extensive case studies on a real-world data set, numerical results show that the proposed framework can achieve accurate and energy-efficient AQI sensing without compromising the privacy of raw data. Yi Liu 0057, Jiangtian Nie, Xuandi Li, Syed Hassan Ahmed, Wei Yang Bryan Lim, Chunyan Miao |
IEEE Internet Things J. | 1 |
| 2020 | Scalable and Communication-Efficient Decentralized Federated Edge Learning with Multi-blockchain Framework
Jiawen Kang 0001, Zehui Xiong, Chunxiao Jiang, Yi Liu 0057, Song Guo 0001, Yang Zhang 0025, Dusit Niyato, Cyril Leung, Chunyan Miao |
BlockSys | 4 |
| 2020 | Communication-Efficient Federated Learning for Anomaly Detection in Industrial Internet of ThingsabstractWith the rapid development of the Industrial Internet of Things (IIoT), various IoT devices and sensors generate massive industrial sensing data. Sensing big data can be analyzed for insights that lead to better decisions and strategic industrial production by using advanced machine learning technologies. However, vulnerable IoT devices are easy to be compromised thus causing IoT devices failures (i.e., anomalies). The anomalies seriously affect the production of industrial products, thereby, it is increasingly important to accurately and timely detect anomalies. To this end, we first introduce a Federated Learning (FL) framework to enable decentralized edge devices to collaboratively train a Deep Anomaly Detection (DAD) model, which can improve its generalization ability. Second, we propose a Convolutional Neural Network-Long Short Term Memory (CNN-LSTM) model to accurately detect anomalies. The CNN-LSTM model uses CNN units to capture fine-grained features and retains the advantages of LSTM unit in predicting time series data. Third, to achieve real-time and lightweight anomaly detection in the proposed framework, a gradient compression mechanism is applied to reduce communication costs and improve communication efficiency. Extensive experiment results based on realworld datasets demonstrate that the proposed framework and mechanism can accurately and timely detect anomalies, and also reduce about 50% communication overhead when compared with traditional schemes. Yi Liu 0057, Neeraj Kumar 0001, Zehui Xiong, Wei Yang Bryan Lim, Jiawen Kang 0001, Dusit Niyato |
GLOBECOM | 1 |
| 2020 | Robust Federated Learning Approach for Travel Mode Identification from Non-IID GPS TrajectoriesabstractGPS trajectory is one of the most significant data sources in intelligent transportation systems (ITS). A simple application is to use these data sources to help companies or organizations identify users' travel behavior. However, since GPS trajectory is directly related to private data (e.g., location) of users, citizens are unwilling to share their private information with the third-party. How to identify travel modes while protecting the privacy of users is a significant issue. Fortunately, Federated Learning (FL) framework can achieve privacy-preserving deep learning by allowing users to keep GPS data locally instead of sharing data. In this paper, we propose a Roust Federated Learning-based Travel Mode Identification System to identify travel mode without compromising privacy. Specifically, we design an attention augmented model architectures and leverage robust FL to achieve privacy-preserving travel mode identification without accessing raw GPS data from the users. Compared to existing models, we are able to achieve more accurate identification results than the centralized model. Furthermore, considering the problem of non-Independent and Identically Distributed (non-IID) GPS data in the realworld, we develop a secure data sharing strategy to adjust the distribution of local data for each user, thereby the proposed model with non-IID data can achieve accuracy close to the distribution of IID data. Extensive experimental studies on a real-world dataset demonstrate that the proposed model can achieve accurate identification without compromising privacy and being robust to real-world non-IID data. Yuanshao Zhu, Shuyu Zhang 0003, Yi Liu 0057, Dusit Niyato, James Jian Qiao Yu |
ICPADS | 3 |
| 2020 | Privacy-Preserving Traffic Flow Prediction: A Federated Learning ApproachabstractExisting traffic flow forecasting approaches by deep learning models achieve excellent success based on a large volume of data sets gathered by governments and organizations. However, these data sets may contain lots of user's private data, which is challenging the current prediction approaches as user privacy is calling for the public concern in recent years. Therefore, how to develop accurate traffic prediction while preserving privacy is a significant problem to be solved, and there is a tradeoff between these two objectives. To address this challenge, we introduce a privacy-preserving machine learning technique named federated learning (FL) and propose an FL-based gated recurrent unit neural network algorithm (FedGRU) for traffic flow prediction (TFP). FedGRU differs from current centralized learning methods and updates universal learning models through a secure parameter aggregation mechanism rather than directly sharing raw data among organizations. In the secure parameter aggregation mechanism, we adopt a federated averaging algorithm to reduce the communication overhead during the model parameter transmission process. Furthermore, we design a joint announcement protocol to improve the scalability of FedGRU. We also propose an ensemble clustering-based scheme for TFP by grouping the organizations into clusters before applying the FedGRU algorithm. Extensive case studies on a real-world data set demonstrate that FedGRU can produce predictions that are merely 0.76 km/h worse than the state of the art in terms of mean average error under the privacy preservation constraint, confirming that the proposed model develops accurate traffic predictions without compromising the data privacy. Yi Liu 0057, James Jian Qiao Yu, Jiawen Kang 0001, Dusit Niyato, Shuyu Zhang 0003 |
IEEE Internet Things J. | 1 |
| 2020 | Dominant Data Set Selection Algorithms for Electricity Consumption Time-Series Data Analysis Based on Affine TransformationabstractIn the explosive growth of time-series data (TSD), the scale of TSD suggests that the scale and capability of many Internet of Things (IoT)-based applications has already been exceeded. Moreover, redundancy persists in TSD due to the correlation between information acquired via different sources. In this article, we propose a cohort of dominant data set selection algorithms for electricity consumption TSD with a focus on discriminating the dominant data set that is a small data set but capable of representing the kernel information carried by TSD with an arbitrarily small error rate less than$\varepsilon $. Furthermore, we prove that the selection problem of the minimum dominant data set is an NP-complete problem. The affine transformation model is introduced to define the linear correlation relationship between TSD objects. Our proposed framework consists of the scanning selection algorithm with$O({n^{3}})$time complexity and the greedy selection algorithm with$O({n^{4}})$time complexity, which are, respectively, proposed to select the dominant data set based on the linear correlation distance between TSD objects. The proposed algorithms are evaluated on the real electricity consumption data of Harbin city in China. The experimental results show that the proposed algorithms not only reduce the size of the extracted kernel data set but also ensure the TSD integrity in terms of accuracy and efficiency. Yi Wu 0021, Yi Liu 0057, Syed Hassan Ahmed, Jialiang Peng, Ahmed A. Abd El-Latif 0001 |
IEEE Internet Things J. | 2 |
| 2019 | PPGAN: Privacy-Preserving Generative Adversarial NetworkabstractGenerative Adversarial Network (GAN) and its variants serve as a perfect representation of the data generation model, providing researchers with a large amount of high-quality generated data. They illustrate a promising direction for research with limited data availability. When GAN learns the semantic-rich data distribution from a dataset, the density of the generated distribution tends to concentrate on the training data. Due to the gradient parameters of the deep neural network contain the data distribution of the training samples, they can easily remember the training samples. When GAN is applied to private or sensitive data, for instance, patient medical records, as private information may be leakage. To address this issue, we propose a Privacy-preserving Generative Adversarial Network (PPGAN) model, in which we achieve differential privacy in GANs by adding well-designed noise to the gradient during the model learning procedure. Besides, we introduced the Moments Accountant strategy in the PPGAN training process to improve the stability and compatibility of the model by controlling privacy loss. We also give a mathematical proof of the differential privacy discriminator. Through extensive case studies of the benchmark datasets, we demonstrate that PPGAN can generate high-quality synthetic data while retaining the required data available under a reasonable privacy budget. Yi Liu 0057, Jialiang Peng, James Jian Qiao Yu, Yi Wu 0021 |
ICPADS | 1 |