EDBT 2026 Demo / reviewers in the wild / expert
Huiqi Liu
dblp:01/10221
· DBLP profile ↗
14ranked-venue papers
3as first author
11since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | ObfusLM: Privacy-preserving Language Model Service against Embedding Inversion AttacksabstractYu Lin, Ruining Yang, Yunlong Mao, Qizhi Zhang, Jue Hong, Quanwei Cai, Ye Wu, Huiqi Liu, Zhiyu Chen, Bing Duan, Sheng Zhong. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025. Ruining Yang, Yunlong Mao, Qizhi Zhang 0007, Jue Hong, Quanwei Cai 0003, Huiqi Liu, Bing Duan, Sheng Zhong 0002 |
ACL (1) | 8 |
| 2025 | SAP: Privacy-Preserving Fine-Tuning on Language Models with Split-and-Privatize FrameworkabstractPre-trained Language Models (PLM) have enabled a cost-effective approach to handling various downstream applications via Parameter-Efficient-Fine-Tuning (PEFT) techniques. In this context, service providers have introduced a popular fine-tuning-based product service known as Model-as-a-Service (MaaS). This service offers users access to extensive PLMs and training resources. With MaaS, users can fine-tune, deploy, and utilize their customized models seamlessly, leveraging a one-stop platform that allows them to work with their private datasets efficiently. However, this service paradigm has recently been exposed to the possibility of leaking user private data. To this end, we identify the data privacy leakage risks in MaaS-based PEFT and propose a Split-and-Privatize (SAP) framework, mitigating the privacy leakage by integrating split learning and differential privacy into MaaS PEFT. Furthermore, we propose Contributing-Token-Identification (CTI), a novel method to balance model utility degradation and privacy leakage. As a result, the proposed framework is comprehensively evaluated, demonstrating a 65% improvement in empirical privacy with only a 1% degradation in model performance on the Stanford Sentiment Treebank dataset, outperforming existing state-of-the-art baselines. Xicong Shen, Yi Liu 0057, Peiran Wang, Huiqi Liu, Jue Hong, Bing Duan, Zirui Huang, Yunlong Mao, Sheng Zhong 0002 |
IJCAI | 5 |
| 2025 | A D-band CMOS eight-channel I/Q transmitter with enhanced LO feed-through suppression
Pingyang He, Huiqi Liu, Guohua Zhao, Dalong Zhu, Dixian Zhao |
Sci. China Inf. Sci. | 3 |
| 2025 | Q/V-Band CMOS Beamforming ICs and Integrated Phased-Array AntennasabstractThis paper presents 256-element transmitter (TX) and receiver (RX) phased arrays for satellite fixed communication at the Q and V bands, which integrate the phased-array antennas with eight-channel beamforming ICs. Wideband vector-modulated phase shifters (VGPS) and combinations of variable gain amplifier (VGA) and attenuators (ATT) are applied in the TX/RX beamforming ICs to achieve phase and gain tunings with large range and high precision. Based on the proposed beamforming ICs, the TX/RX phased arrays are realized with stacked aperture-coupled microstrip antennas on a cost-effective multi-layer PCB. Each array contains 32 TX/RX beamforming ICs, 256 antennas, and a 1-to-32 Wilkinson power divider/combiner networks. Fabricated in 65-nm CMOS technology, the packaged TX IC achieves an RMS gain error of 0.58 dB and an RMS phase error of 4.5° with 78.5-mW dc power per channel, while the$\text {OP}_{\text {1dB}}$is 9.6 dBm at 50.5 GHz. The packaged RX IC realizes a 5.3-dB NF, 0.47-dB RMS gain error, and 1.7° RMS phase error with 24.2-mW dc power per channel. The Q/V-band phased arrays are capable of scanning ±60°, while the 256-element TX phased array achieves an EIRP of 63.5 dBm. Modulated signal measurements with 200- and 400-MHz QPSK, 16-QAM and 64-QAM are also provided. Dixian Zhao, Weihan Gao, Keqin Li 0001, Hengzhi Wan, Qin Tian, Yongran Yi, Jiajun Zhang 0002, Huiqi Liu |
IEEE Trans. Circuits Syst. I Regul. Pap. | 8 |
| 2024 | An Inversion Attack Against Obfuscated Embedding Matrix in Language Model InferenceabstractWith the rapidly-growing deployment of large language model (LLM) inference services, privacy concerns have arisen regarding to the user input data.Recent studies are exploring transforming user inputs to obfuscated embedded vectors, so that the data will not be eavesdropped by service provides.However, in this paper we show that again, without a solid and deliberate security design and analysis, such embedded vector obfuscation failed to protect users' privacy.We demonstrate the conclusion via conducting a novel inversion attack called Element-wise Differential Nearest Neighbor (EDNN) on the glide-reflection proposed in (Mishra et al., 2024), and the result showed that the original user input text can be 100% recovered from the obfuscated embedded vectors.We further analyze security requirements on embedding obfuscation and present several remedies to our proposed attack. Qizhi Zhang 0007, Quanwei Cai 0003, Jue Hong, Wu Ye, Huiqi Liu, Bing Duan |
EMNLP | 6 |
| 2024 | Generalization and Construction of Single-Section Sparse Regression CodesabstractAs a 5G service category, ultra-reliable low-latency communication (URLLC) raises the challenge of dramatically improving the reliability of short message transmission, for which sparse regression codes (SRCs) and their variations have emerged as promising solutions. In this paper, we propose a generalization of single-section SRCs (SRCl) by designing a sparse vector set that satisfies a certain minimum Euclidean distance constraint. The design problem is first transformed into a constant weight code (CWC) design problem. By extending the binary alphabet to an$M$-ary-phase alphabet, we generalize the CWC to$M$-ary CWC ($M$-CWC) to further increase the achievable minimum Euclidean distance. The increment is theoretically analyzed, and the anticipated performance gain of the resultant$M$-CWC-SRCI over SRCI is verified by simulation. Additionally, our simulation results show that the proposed$M$-CWC-SRCI outperforms the state-of-the-art SRCl-based schemes by about 1 dB gain in EblNo at BLER of Le - 5. Huiqi Liu, Wai Ho Mow, Shansuo Liang |
ICC | 1 |
| 2024 | FedMark: Large-Capacity and Robust Watermarking in Federated LearningabstractMachine learning models are increasingly recognized as valuable intellectual property (IP), prompting the development of a range of watermarking techniques aimed at safeguarding the IP of these models. However, in the context of federated learning (FL) models involving multiple owners, such as the participants in FL model training, conventional techniques designed for single-owner models prove ineffective due to limitations in their capacity and robustness. Few work has explored how to effectively embed watermarks to FL models for multiple-owners, which is non-trivial, especially when the number of owners is large. To fill this gap, we first analyze the capacity of existing watermarking methods. Second, we propose FedMark, a general large-capacity watermarking mechanism for FL, which leverages the Bloom Filter to achieve conflict-free watermarking of a large number of participants. Moreover, we propose a secret-sharing-based verification method to improve the watermarking robustness against false positives caused by Bloom Filter. Finally, comprehensive experiments show that our design can support over 150 participants to embed watermarks while the model accuracy varies within 1 %, and is robust to non-independent identical distributed data, different participant selection rates, model modifications, permutation attacks, scaling attacks and forging attacks. Lan Zhang 0002, Chen Tang 0002, Huiqi Liu, Haikuo Yu, Xirong Zhuang, Lei Wang 0005, Wenjing Fang, Xiang-Yang Li 0001 |
ICDCS | 3 |
| 2024 | W-band CMOS beamforming ICs and integrated phased-array antennas with 20+ Gb/s data rates
Dixian Zhao, Peigen Yu, Weihan Gao, Pingyang He, Huiqi Liu |
Sci. China Inf. Sci. | 6 |
| 2023 | DeepContract: Controllable Authorization of Deep Learning ModelsabstractWell-trained deep learning (DL) models are widely used in various fields and recognized as valuable intellectual property. However, most existing efforts to fully exploit their value either require users to upload input data to provide machine learning services, which raises serious privacy concerns, or deploy DL models on the user side, resulting in a loss of control over the models. While a few active model authorization methods protect the model from unauthorized users, they cannot prevent the model from being redistributed or abused by authorized users. To address the urgent need to efficiently protect both model confidentiality and input data privacy, and achieve uninterrupted model controllability, we propose a contract-based model authorization framework called DeepContract. This framework enables model owners to deploy their models on the user side for local inference without revealing original model weights. Moreover, it allows them to grant and revoke the right to use their models at any time. Specifically, we propose a generic model encryption method that significantly outperforms the state-of-the-art method in both efficiency and security. Leveraging the integrity verification in the Trusted Execution Environment, contract-based and verifiable enclave codes generated by DeepContract can perform controlled inference using the encrypted model distributed on the user side. Our extensive evaluations show that DeepContract can achieve efficient and secure controllable model authorization for the pre-signed contract. Xirong Zhuang, Lan Zhang 0002, Chen Tang 0002, Huiqi Liu, Bin Wang 0070, Bo Ren 0002 |
ACSAC | 4 |
| 2022 | A 24.25-27.5 GHz 128-element dual-polarized 5G integrated phased array with 5.6%-EVM 400-MHz 64-QAM and 50-dBm EIRP
Huiqi Liu, Dixian Zhao, Yongran Yi, Xiaohu You 0001 |
Sci. China Inf. Sci. | 1 |
| 2022 | Model Protection: Real-Time Privacy-Preserving Inference Service for Model Privacy at the EdgeabstractMajor cloud service providers with well-equipped infrastructure, experienced machine learning (ML) expertise, and enriched training datasets are building ML-as-a-Service (MLaaS) systems, in which clients can query ML-based prediction services with their data. Instead of moving private data to the cloud, in this work, we design, implement, and evaluate a novel secure ML system to enable MLaaS on edge devices. To protect the proprietary ML models on edge devices from revealing to the clients while maintaining a real-time inference is challenging. Existing privacy-preserving ML techniques can hardly satisfy real-time requirements. In our solution, we employ a secure enclave (e.g., SGX) to offer security and provide better efficiency than cryptographic techniques. However, the enclave alone cannot achieve real-time capability due to its limited capacity. We observe that the ML model imposes a severe accuracy degradation when adding noise to a few model weights. Based on this, we design a suite of novel solutions to optimize the performance of secure enclave-based inference service at the edge by enclosing only$1\%$computation within secure enclaves. Our work can achieve up to a$7.8\times$increase in efficiency and a$27\times$reduction in memory usage compared to the state-of-the-art. Jiahui Hou, Huiqi Liu, Yunxin Liu 0001, Yu Wang 0003, Peng-Jun Wan, Xiang-Yang Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2019 | Finding the Stars in the Fireworks: Deep Understanding of Motion Sensor FingerprintabstractWith the proliferation of mobile devices and various sensors (e.g., GPS, magnetometer, accelerometers, gyroscopes) equipped, richer services, e.g. location based services, are provided to users. A series of methods have been proposed to protect the users' privacy, especially the trajectory privacy. Hardware fingerprinting has been demonstrated to be a surprising and effective source for identifying/authenticating devices. In this work, we show that a few data samples collected from the motion sensors are enough to uniquely identify the source mobile device, i.e., the raw motion sensor data serves as a fingerprint of the mobile device. Specifically, we first analytically understand the fingerprinting capacity using features extracted from hardware data. To capture the essential device feature automatically, we design a multi-LSTM neural network to fingerprint mobile device sensor in real-life uses, instead of using handcrafted features by existing work. Using data collected over 6 months, for arbitrary user movements, our fingerprinting model achieves 93% F-score given one second data, while the state-of-the-art work achieves 79% F-score. Given ten seconds randomly sampled data, our model can achieve 98.8% accuracy. We also propose a novel generative model to modify the original sensor data and yield anonymized data with little fingerprint information while retain good data utility. Xiang-Yang Li 0001, Huiqi Liu, Lan Zhang 0002, Zhenan Wu, Yaochen Xie, Chunxiao Wan, Zhongwei Liang |
IEEE/ACM Trans. Netw. | 2 |
| 2018 | Finding the Stars in the Fireworks: Deep Understanding of Motion Sensor FingerprintabstractWith the proliferation of mobile devices and various sensors (e.g., GPS, magnetometer, accelerometers, gyroscopes) equipped, richer services, e.g. location based services, are provided to users. A series of methods have been proposed to protect the users' privacy, especially the trajectory privacy. Hardware fingerprinting has been demonstrated to be a surprising and effective source for identifying/authenticating devices. In this work, we show that a few data samples collected from the motion sensors are enough to uniquely identify the source mobile device, i.e., the raw motion sensor data serves as a fingerprint of the mobile device. Specifically, we first analytically understand the fingerprinting capacity using features extracted from hardware data. To capture the essential device feature automatically, we design a multi-LSTM neural network to fingerprint mobile device sensor in real-life uses, instead of using handcrafted features by existing work. Using data collected over 6 months, for arbitrary user movements, our fingerprinting model achieves 93 % F -score given one second data, while the state-of-the-art work achieves 79% F-score. Given ten seconds randomly sampled data, our model can achieve 98.8% accuracy. We also propose a novel generative model to modify the original sensor data and yield anonymized data with little fingerprint information while retain good data utility. Huiqi Liu, Xiang-Yang Li 0001, Lan Zhang 0002, Yaochen Xie, Zhenan Wu, Qian Dai, Chunxiao Wan |
INFOCOM | 1 |
| 2016 | Privacy Inference on Knowledge Graphs: Hardness and ApproximationabstractThe rapid information propagation facilitates our work and life without precedent in history, but it has tremendously exaggerated the risk and consequences of privacy invasion. Today's attackers are becoming more and more powerful in gathering personal information from many sources and mining these data to further uncover users' privacy. A great number of previous works have shown that, with adequate background knowledge, attackers are even able to infer sensitive information that is not revealed to anyone malicious before. In this paper, we model the attacker's knowledge using a knowledge graph and formally define the privacy inference problem. We show its #P-hardness and design an approximation algorithm to perform privacy inference in an iterative fashion, which also reflects real-life network evolution. The simulations on two data sets demonstrate the feasibility and efficacy of privacy inference using knowledge graphs. Jianwei Qian, Shaojie Tang 0001, Huiqi Liu, Taeho Jung, Xiang-Yang Li 0001 |
MSN | 3 |