EDBT 2026 Demo / reviewers in the wild / expert
Yong Zeng 0002
dblp:01/6205-2
· DBLP profile ↗
24ranked-venue papers
7as first author
16since 2021 · last 2026
0000-0003-2551-7009ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 11 · 3 first-author · 7 since 2021Security and privacy · 10 · 3 first-author · 7 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Urey-ML: A Machine Learning-Based Distance Deception Attack Against Apple UWB Interaction FrameworksabstractUltra-Wideband (UWB) technology has recently emerged as a transformative enabler of high-precision positioning systems. Despite its growing adoption across diverse applications, prior studies have claimed several successful distance deception attacks against UWB. To address heightened security concerns, companies like Apple introduce the ranging-awareness defense mechanism into their new version of the UWB interaction frameworks, which is proven to be effective against most known attacks. In this paper, we critically focus on the design flaws of state-of-the-art UWB interaction frameworks and propose Urey-ML, a novel machine learning-based UWB distance deception attack targeting UWB systems. To the best of our knowledge, this is the first attack capable of circumventing the defense mechanisms implemented in Apple’s UWB Nearby Interaction Framework (ANIF). Specifically, Urey-ML is built upon two critical breakthroughs. First, through network packet analysis, we discover that ANIF leaves a crucial message for key negotiation in an unprotected state. This vulnerability enables Urey-ML to bypass the encryption protection implemented by standard UWB systems. Second, to break the ranging-awareness defense, Urey-ML involves a reinforcement learning-based algorithm to optimize attack parameters. By leveraging this approach, Urey-ML can automatically and craftily generate attack signals that mimic the variations typically caused by normal human movement. Our experiments on commercial-off-the-shelf UWB products show that Urey-ML achieves centimeter-level UWB distance deception, with more than 25.79% signals circumventing the defense check of the victim device, which is only 0.56% (or failed) in prior works. Yang Liu 0118, Man Sun, Xinjing Liu, Yong Zeng 0002, Jiayu Jin, Zhuo Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | Catch Me If You Can: Retain High Stealthiness and Durability of Backdoor Attack in Federated LearningabstractFederated Learning (FL) is vulnerable to backdoor attacks by design since it cannot inspect clients’ local data to protect their privacy. This privacy-preserving feature creates an opportunity for malicious clients to introduce backdoors. However, existing backdoor attacks face two main limitations. First, brute amplification (i.e., uniformly scaling up malicious parameters) can be easily detected, hence compromising attack stealthiness. Second, evasion strategies employed to prevent their backdoors from being overwritten by benign updates are frequently ineffective, reducing the overall attack stability upon model deployment. To address these limitations, we propose an adaptive proactive boosting strategy to enhance both the stealthiness and durability of backdoor attacks in FL. As a concrete example,ReBAintroduces a durable importance metric based on stability degrees of parameters as an update mask for malicious attackers, assigning higher weights to backdoor-related parameters during the update process. To ensure stealthiness,ReBAformulates an optimization problem regarding amplification factor by minimizing the distance between malicious and clean updates, thereby correcting malicious updates within a benign distance space. Extensive evaluations on 3 datasets and across 14 defenses demonstrate the efficacy ofReBA, outperforming over 12 baseline backdoor attacks. Our code is available at https://anonymous.4open.science/r/ReBA-D82F. Yilong Yang 0004, Xinjing Liu, Zefeng Wu, Zhuoran Ma 0002, Yong Zeng 0002, Xianjia Meng, Zhuo Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | chamaeleon: Backdoor Attacks Against Vertical Federated Learning for Tabular DataabstractVertical federated learning (VFL) has made significant strides in enhancing data privacy and security for cross-silo applications. However, despite its benefits, VFL remains vulnerable to emerging security threats, particularly backdoor attacks. While most existing research on VFL backdoor attacks has focused on image and natural language processing tasks, the security of tabular data—commonly used in high-risk domains such as finance and healthcare—has been largely overlooked. In this paper, we introduce chamaeleon, a novel backdoor attack targeting VFL for tabular data. Our approach achieves two key advancements. First, to address the challenge of restricted label access in VFL, chamaeleon employs a two-step inference method to extract label information. This method combines a label classifier with a top-kconfidence filtering mechanism, enabling the precise identification of target-label samples (i.e., backdoored samples) with a precision of approximately 99.85%. Second, to overcome the limitations of fixed trigger patterns, which can disrupt the semantic integrity of tabular data (e.g., altering “male” to “pregnant”), chamaeleon introduces a dynamic trigger design. Each backdoored sample is injected with a unique trigger, generated by a transformer-based model inspired by large language models, ensuring semantic consistency. Additionally, a one-on-two adversarial game is implemented to optimize the generator’s performance with limited training data. Extensive evaluations across six models and six datasets demonstrate the effectiveness of our proposed attack. We also examine various factors that could influence the attack success and systematically analyze potential defense mechanisms to mitigate this newly identified threat. Yilong Yang 0004, Yong Zeng 0002, Shangze Li, Yang Liu 0118, Zhuo Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Layered Website Fingerprinting Defense Against Adversarial TrainingabstractThe Tor browser ensures secure internet access through multi-layer encryption and anonymity, yet remains vulnerable to Website Fingerprinting (WF) attacks. The emergence of adversarial training poses a critical challenge: attackers now leverage publicly available WF defenses to create augmented training data. This data augmentation strategy, as demonstrated in S&P’23, dramatically strengthens attack models’ robustness. Consequently, many existing defenses have become ineffective against these enhanced adversaries. We propose FRONT-R and its combination with TrafficSliver, called FRONT-RS, to counter this threat through two key innovations:(1) disrupting trace patterns by injecting randomized dummy packets at feature-rich front segments instead of fixed single-packet insertion, and (2) trace splitting through multi-path routing. In adversarial training environments, FRONT-R demonstrates superior performance over FRONT with 10% accuracy reduction in closed world and lower F1 in open world settings. When synergized with TrafficSliver, the layered approach achieves over 20% accuracy reduction compared to standalone methods while maintaining equivalent data overhead. Yong Zeng 0002, Jianfeng Ma 0001 |
TrustCom | 1 |
| 2024 | Eyes See Hazy while Algorithms Recognize Who You AreabstractFacial recognition technology has been developed and widely used for decades. However, it has also made privacy concerns and researchers’ expectations for facial recognition privacy-preserving technologies. To provide privacy, detailed or semantic contents in face images should be obfuscated. However, face recognition algorithms have to be tailor-designed according to current obfuscation methods, as a result the face recognition service provider has to update its commercial off-the-shelf (COTS) products for each obfuscation method. Meanwhile, current obfuscation methods have no clearly quantified explanation. This paper presents a universal face obfuscation method for a family of face recognition algorithms using global or local structure of eigenvector space. By specific mathematical explanations, we show that the upper bound of the distance between the original and obfuscated face images is smaller than the given recognition threshold. Experiments show that the recognition degradation is 0% for global structure based and 0.3%-5.3% for local structure based, respectively. Meanwhile, we show that even if an attacker knows the whole obfuscation method, he/she has to enumerate all the possible roots of a polynomial with an obfuscation coefficient, which is computationally infeasible to reconstruct original faces. So our method shows a good performance in both privacy and recognition accuracy without modifying recognition algorithms. Yong Zeng 0002, Tong Dong, Qingqi Pei, Jianfeng Ma 0001, Yao Liu 0007 |
ACM Trans. Priv. Secur. | 1 |
| 2023 | MT-CNN: A Classification Method of Encrypted Traffic Based on Semi-Supervised LearningabstractDeep learning methods have become the preferred solution for encrypted traffic classification. However, the application of neural networks in encrypted traffic classification has encountered the following limitations: 1) Deep learning models have dependencies on large-scale and well-labeled datasets. 2) most deep learning models have high hardware requirements and require a large amount of CPU and GPU for computation. These limitations seriously hinder the development of encrypted traffic research. In this paper, we propose a new lightweight semi-supervised learning classifier to solve these problems. To reduce the dependence of the model on CPU and GPU, we have designed a lightweight encrypted traffic classifier based on CNN(Convolutional Neural Networks). It can run on raspberry pi with low hardware requirements. Then we combine the classifier with the Mean Teacher framework, which we call MT-CNN. By using the semi-supervised learning framework, we successfully reduced the number of labeled samples during model training. To fully preserve traffic information, we convert traffic data into grayscale images as input. We used a small-scale dataset for experiments on raspberry pi. The experimental results showed that the accuracy of MT-CNN still reached 96.83% even when only 5% of the labeled data was used. Kaichao Shi, Yong Zeng 0002, Baihe Ma, Jianfeng Ma 0001 |
GLOBECOM | 2 |
| 2023 | Multi-User Delay Alignment Modulation for Millimeter Wave Massive MIMOabstractDelay alignment modulation (DAM) is a novel wideband communication technique, which exploits the high spatial resolution and multi-path sparsity of millimeter wave (mmWave) massive multiple-input multiple-output (MIMO) systems to mitigate inter-symbol interference (ISI), without relying on conventional techniques like channel equalization or multi-carrier transmission. In this paper, we extend the DAM technique to multi-user mmWave massive MIMO communication systems. We first provide asymptotic analysis by showing that when the number of base station (BS) antennas is much larger than the total number of channel paths, DAM is able to eliminate both ISI and inter-user interference (IUI) with the simple delay pre-compensation and per-path-based maximal ratio transmission (MRT) beamforming. We then study the general multi-user DAM design by considering the three classical transmit beamforming strategies in a per-path basis, namely MRT, zero-forcing (ZF) and regularized zero-forcing (RZF). Simulation results demonstrate that multi-user DAM can significantly outperform the bench-marking single-carrier ISI mitigation technique that only uses the strongest channel path of each user. Xingwei Wang 0013, Haiquan Lu, Yong Zeng 0002 |
GLOBECOM | 3 |
| 2023 | Social Networks Based Robust Federated Learning for Encrypted Traffic ClassificationabstractThe encrypted traffic classification based on federated learning has become one of the key concerns since it can effectively provide expansion and privacy protection for traffic dataset. However, existing classification models suffer from low robustness and slow convergence in the presence of abnormal traffic data on the client side. We note that the clients participating in the training are operated by humans in social networks, and their communication with each other generate social traffic. By introducing the traffic data into the federated learning classification model, the correlation between the respective small model parameters of the clients can be increased, which can be leveraged to quickly detect abnormal clients and improve the model performance. The effectiveness of the scheme is verified on a classical public dataset and the results show that this WS network structure converges the fastest and the degree distribution has an overall linear relationship with the convergence speed. Our scheme is still highly robust with abnormal data and the model convergence speed is significantly better than other methods. Compared with the existing method, the model of social networks based classification of federated encrypted traffic has 2.5 % higher accuracy, 6.1 % higher recall, and more than 39.3% fewer communication rounds, respectively. Yong Zeng 0002, Zhe Wang 0064, Xiaoya Guo, Kaichao Shi, Xiaoyan Zhu 0005, Jianfeng Ma 0001 |
ICC | 1 |
| 2023 | Encrypted Voice Traffic Fingerprinting: An Adaptive Network Traffic Feature Encoding ModelabstractRecent studies show that the traffic fingerprints constructed by encrypted voice traffic features will uncover users' activities. Current researches have focused on using machine learning models to build traffic fingerprints, however, they pay less attention to the distribution of traffic data. We note that encrypted voice traffic data is bimodal distributed, which is different from other encrypted traffic following Gaussian distribution. It means that present encoding model may destroy the distribution characteristics of encrypted voice traffic data, leading to a decrease in classification accuracy. To ameliorate this issue, our study proposes the combination of Discrete Fourier Transform and Stacked Autoencoder as traffic feature encoding model. The former is able to map the encrypted voice traffic features from bimodal distribution to frequency-domain space while keeping the trend of its features. And the latter can further improve features utilization in classification model. Finally, we achieved 96.08% accuracy on Amazon Echo dataset and 99.53% accuracy on Google Home dataset, which get the SOTA(state of the art) results on both encrypted voice traffic datasets. Tianci Zhou, Yong Zeng 0002, Jianfeng Ma 0001 |
ICC | 2 |
| 2023 | Signcryption-Based Encrypted Traffic Detection Scheme for Fast Establishing Secure Connections
Fagen Li, Lihui Liu, Yong Zeng 0002, Jianfeng Ma 0001 |
ProvSec | 4 |
| 2022 | Trajectory Obfuscation and Detection in Internet-of-vehiclesabstractIn Internet-of-vehicles, vehicles cooperate with each other by transmitting Internet-of-vehicles and location-based service (LBS) providers optimize services by analyzing trajectory data collected from drivers. Nevertheless, illegal trajectories generated by attackers or malicious drivers can obfuscate the process of analysis and breach the quality of service. Some mechanisms protect drivers’ location privacy by using obfuscation-based schemes. Obfuscation-based mechanisms report LBS with obfuscated trajectories data rather than actual trajectories, which increases difficulties to detect illegal trajectories accurately. This paper focuses on detecting illegal trajectories when all drivers employ obfuscation-based mechanisms to protect location privacy. In this paper, we propose a dynamic obfuscation mechanism in road networks based on Geo-indistinguishability to dynamically protect drivers’ location privacy. Considering personalization in road networks, we also propose a classification mechanism to detect illegal trajectories in road networks. Illegal trajectories are generated based on real trajectories to simulate actions of malicious drivers and attackers. Experiment results in real road networks show that the classifier can detect illegal obfuscated trajectories with at least 94% Area Under the Curve (AUC) score, which outperforms than existing works in road networks. Yueyao Zhao, Baihe Ma, Ziwen Wang 0005, Yong Zeng 0002, Jianfeng Ma 0001 |
CSCWD | 5 |
| 2022 | Sliding window based ON/OFF flow watermarking on Tor
Yong Zeng 0002, Jianfeng Ma 0001 |
Comput. Commun. | 3 |
| 2021 | Graph Embedding Based on Euclidean Distance Matrix and its ApplicationsabstractGraph embedding converts a graph into a multi-dimensional space in which the graph structural information or graph properties are maximumly preserved. It is an effective and efficient way to provide users a deeper understanding of what is behind the data and thus can benefit a lot of useful applications. However, most graph embedding methods suffer from high computation and space costs. In this paper, we present a simple graph embedding method that directly embeds the graph into its Euclidean distance space. This method does not require the learned representations to be low dimensional, but it has several good characteristics. We find that the centrality of nodes/edges can be represented by the position of nodes or the length of edges when a graph is embedded. Besides, the edge length is closely related to the density of regions in a graph. We then apply this graph embedding method into graph analytics, such as community detection, graph compression, and wormhole detection, etc. Our evaluation shows the effectiveness and efficiency of this embedding method and contends that it yields a promising approach to graph analytics. Yong Zeng 0002, Jianfeng Ma 0001 |
CIKM | 4 |
| 2021 | Pri-PGD: Forging privacy-preserving graph towards spectral-based graph neural networkabstractThe development of Graph Neural Network (GNN) enables people to explore the value of graph data better. Additionally, graph data often reveals more private information than data in Euclidean space. Some scholars have proposed that differential privacy can be used to add noise to the graph. However, the availability of the data will decrease with the increase of privacy. Some work utilize graph data through federated learning, which is computationally complex and heavily burdened by communication. Therefore, based on the principle of the spectral-based GNN model (Graph convolutional network, GCN), we proposed a method (Pri-PGD) to forge a privacy-preserving graph by disturbing. We set a user-selectable parameter$m$to convert the first m-order neighbor nodes to the first-order neighbor for each node. Pri-PGD achieves two goals: preserving convolution basis space and preserving first-order neighbor information of the real graph. This allows Pri-Pgdto guarantee the privacy of the graph data while keeping the availability of it. We evaluated the effectiveness of our algorithm on three classical graph datasets (Cora, Citeseer, Pubmed). The accuracy of our method on the GCN model for the three datasets decreases only by about 1% when the parameter$m$is 2. This verifies the validity of the forged graph obtained by Pri-PGD. As the experiment shows, our method is also valid for the Graph attention network model that is sensitive to first-order neighbor nodes. Yong Zeng 0002, Jianfeng Ma 0001 |
GLOBECOM | 1 |
| 2021 | Covert Wireless Communications in the Presence of an Active AdversaryabstractCovert wireless communication or low probability of detection (LPD) communication that employs the noise or jamming signals as the cover to hide user’s signals can prevent an adversary Willie from discovering user’s transmission attempts. Previous work on this problem typically presupposed that Willie is static and has one antenna, often neglecting an active adversary who can dynamically adjust his/her location to make better statistic tests. In this paper, we analyzed the effect of an active adversary in the covert wireless communication over AWGN channels and found that, having gathered samples at different places, the active adversary can easily detect Alice’s transmission behavior via a trend test. Furthermore, a more powerful adversary with multiple antennas is harder to be deceived, and his detection time can be greatly shortened. Yong Zeng 0002, Jianfeng Ma 0001 |
ICC | 3 |
| 2021 | GNS: Forge High Anonymity Graph by Nonlinear Scaling SpectrumabstractIt is crucial to generate random graphs with specific structural properties from real graphs, which could anonymize graphs or generate targeted graph data sets. The state-of-the-art method called spectral graph forge (SGF) was proposed at INFOCOM 2018. This method uses a low-rank approximation of the matrix by throwing away some spectrums, which provides privacy protection after distributing graphs while ensuring data availability to a certain extent. As shown in SGF, it needs to discard at least 20% spectrum to defend against deanonymous attacks. However, the data availability will be significantly decreased after more spectrum discarding. Thus, is there a way to generate a graph that guarantees maximum spectrum and anonymity at the same time? To solve this problem, this paper proposes graph nonlinear scaling (GNS). We firmly prove that GNS can preserve all eigenvectors meanwhile providing high anonymity for the forged graph. Precisely, the GNS scales the eigenvalues of the original spectrum and constructs the forged graph with scaled eigenvalues and original eigenvectors. This approach maximizes the preservation of spectrum information to guarantee data availability. Meanwhile, it provides high robustness towards deanonymous attacks. The experimental results show that when SGF discards only 10% of the spectrum, the forged graph has high data availability. At this time, if the distance vector deanonymity algorithm is used to attack the forged graph, almost 100% of the nodes can be identified, while when achieving the same availability, only about 20% of the nodes in the forged graph obtained from GNS can be identified. Moreover, our method is better than SGF in capturing the real graph’s structure in terms of modularity, the number of partitions, and average clustering. Yong Zeng 0002, Zhongyuan Jiang, Jianfeng Ma 0001 |
Secur. Commun. Networks | 1 |
| 2020 | Spectrum Privacy Preserving for Social Networks: A Personalized Differential Privacy Approach
Yang Liu 0118, Yong Zeng 0002, Jianfeng Ma 0001 |
Inscrypt | 2 |
| 2020 | Covert Wireless Communication in IoT Network: From AWGN Channel to THz BandabstractCovert communication can prevent an adversary from knowing that a transmission has occurred between two users. In this article, we consider covert wireless communications in an Internet-of-Things (IoT) network with dense deployment, where an IoT device experiences not only the background noise but also the aggregates interference from other Tx devices. Our results show that in a dense IoT network with lower frequency AWGN channels, when the distance between Alice and the adversary Willie da,w= ω(n1/(2α)), Alice can reliably and covertly transmit O(log2√n) bits to Bob in n channel uses. In an IoT network with terahertz (THz) band, covert communication is more difficult because Willie can simply place a receiver in the narrow beam between Alice and Bob in order to detect or block their line-of-sight communications. We demonstrated that covert communication is still possible in this occasion by utilizing the reflection or diffuse scattering from a rough surface. From the physical-layer security perspective, covert communication can enhance the security of IoT network from the bottom layer. Jiajia Liu 0001, Yong Zeng 0002, Jianfeng Ma 0001 |
IEEE Internet Things J. | 3 |
| 2019 | Cooperative Jamming Strategy Based on Community Detection for Two-Hop Communication NetworksabstractWith a wide application of wireless hand-held devices in human life, the relationship among human beings may affect some wireless communication systems. Inspired by it, this paper investigates the influence of social relationships on the secrecy performance of a two-hop wireless communication system with multiple jammers. We model the secrecy problem of the whole transmission as a cooperative jamming game consisting of two independent sub-games, and design a cooperative jamming strategy based on the concept of community detection to seek the minimum secrecy outage probability among all Nash equilibriums. In our proposed strategy, each jammer is divided into different groups due to its relationships with the source, the relay and the destination. Simulations demonstrate that the proposed strategy can successfully have a good secrecy performance for the two-hop system and a high average utility. Yeqiu Xiao, Yong Zeng 0002 |
ICC | 3 |
| 2018 | On Covert Communication with Interference UncertaintyabstractCovert communication can prevent the opponent from knowing that a wireless communication has occurred. If only the additive white Gaussian noise (AWGN) channels and ambient noise are taken into consideration, a square root law was obtained and the result shows that the privacy rate approaches zero asymptotically. In this paper, we consider the covert communication in large-scale wireless networks, where the transmitters form a stationary Poisson point process, and Alice wishes to communicate covertly to Bob without being detected by warden Dave. In this scenario, Bob and Dave not only experience the ambient noise, but also the aggregate interference simultaneously. Although the interference sources are not in collusion with Alice, and Bob's noise increases as well, our results show that, the measurement uncertainty of Dave will increase along with the increase of interference, and interference can indeed improve the performance of covert communication. Jiajia Liu 0001, Yong Zeng 0002, Jianfeng Ma 0001, Qiping Huang |
ICC | 3 |
| 2017 | Modeling Key Infection in Large-Scale Sensor Networks
Feiyang Peng, Yong Zeng 0002 |
ICICS | 3 |
| 2008 | Adaptive Algorithms to Mitigate Inefficiency in Reliability Differentiation Mechanisms for Wireless Sensor NetworksabstractThis short paper presents practical algorithms for mitigating inefficiency in reliability differentiation service based on geographical stateless routing, which has great potential applications in large scale wireless sensor networks (WSN). Based on available algorithm, the paper presents a mathematical formalization to systematic understanding the multipath redundancy problem of WSN. With the information beyond one hop and the load balancing mechanism, the data retransmission and reliability differentiation reassignments are reduced. The illustration and simulation demonstrate the proposed algorithmspsila effectiveness and the capability to provide reliability differentiation service. Yong Zeng 0002, Jianfeng Ma 0001, Lihua Dong, Liaojun Pang |
MSN | 1 |
| 2006 | Computing the k-Error N-Adic Complexity of a Sequence of Period pn
Lihua Dong, Yupu Hu, Yong Zeng 0002 |
SETA | 3 |
| 2003 | Pseudorandom number generators based on evolutionary algorithmabstractA family of novel pseudorandom number generators is proposed based on an evolutionary algorithm. These pseudorandom number generators are expressed as EAPRNG. EAPRNGs are driven by some existed simple and unsafe generators which are denoted by mother generators (MG), while outputs of the MGs are hidden by EAPRNGs. The analysis indicates that EAPRNGs are resistant to many known attacks, and that they have good statistical properties, such as uniform probability distribution over GF (2/sup l/) and large periods. Yong Zeng 0002, Jianfeng Ma 0001 |
IEEE Congress on Evolutionary Computation | 1 |