Xinyuan Qian 0002

dblp:119/4340-2 · DBLP profile ↗
← Back
17ranked-venue papers
5as first author
17since 2021 · last 2026
0000-0003-3247-6516ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 10 · 2 first-author · 10 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 MartDE: A Privacy-Preserving and Cost-Efficient Evaluation Framework for Data Marketplaces
abstract
The development of machine learning models increasingly relies on high-quality data that resides in private domains. To enable secure and value-driven data exchange under strict privacy regulations, federated learning (FL) has emerged as a key primitive by enabling the trading of model utilities instead of raw data. Among existing solutions, martFL (CCS 2023) represents the state-of-the-art FL-based data marketplace architecture, integrating privacy-preserving model evaluation and verifiable trading protocols to enable robust and fair model utility trading without revealing raw data. Despite its strengths, martFL suffers from critical weaknesses at the evaluation layer, including plaintext score exposure and unverifiable and manipulable participant selection. To address these challenges, we propose MartDE, a dedicated evaluation framework that builds model-centric data marketplaces with robust, privacy-preserving, and verifiable mechanisms. MartDE introduces encrypted utility scoring with client-side decryption to preserve score confidentiality, formally bounded anomaly filtering, adaptive participant selection based on global model performance, and commitment-based verification to ensure consistency between declared and evaluated scores and selection verification. We implement MartDE and evaluate it across diverse datasets and adversarial conditions. Results show that MartDE achieves superior accuracy, robustness, and cost-efficiency, providing a strong foundation for secure and trustworthy utility-driven data marketplaces.
Xinyuan Qian 0002, Haoyong Wang, Hangcheng Cao, Shuai Yuan 0009, Senkang Hu, Qingchuan Zhao, Hongwei Li 0001, Guowen Xu
AAAI1
2026 FastPaD: A Fast Privacy-Preserving Password Similarity Leakage Detection Protocol for IoT Services
abstract
In the digital age of the Internet of Things, users rely extensively on online accounts to access a variety of IoT services and applications. However, password leakage significantly threatens users’ privacy, assets, and reputations, making passwords primary targets for cyberattacks, including credential-guessing attacks. To address this vulnerability, this paper proposes FastPaD, a Fast privacy-preserving protocol designed to detect password similarity leakage using homomorphic encryption. FastPaD employs a novelhorizontal homomorphic batch encoding method, facilitating efficient batch detection of similar passwords. The protocol also incorporates optimization strategies such aspolynomial partitioning and power computation windowing, significantly reducing the depth of homomorphic multiplications. This enables the use of smaller encryption parameters, which improves computational efficiency. Moreover, FastPaD features a customizable mechanism to balance functionality and performance, effectively optimizing the trade-off between communication and computational overhead. Experimental results demonstrate that in scenarios without similarity detection, FastPaD achieves a detection computation time of 0.17 seconds and a total communication overhead of 3.88 MB, surpassing state-of-the-art protocols. When similarity detection is enabled, FastPaD completes the detection process in 6.45 seconds with a communication overhead of 10.64 MB. Compared to the Pipa protocol, FastPaD provides approximately a 2.70× improvement in computation time and a 22.27× improvement in communication efficiency. Relative to Yu’s protocol, FastPaD demonstrates a 15.78× faster computation and a 1.31× reduction in communication overhead.
Dianhua Tang, Hongwei Li 0001, Xinyuan Qian 0002, Xiaopeng Yu 0003, Shuailing Zhang, Guowen Xu
IEEE Internet Things J.3
2026 No Trespassing: Ground-View Adversarial Patches for Privacy-Aware Management in COTS Robot Vacuum Cleaner
abstract
Robot vacuum cleaners (RVCs) with autonomous navigation and decision-making capabilities have become an integral part of modern homes. During their operations, these devices may inadvertently enter privacy-sensitive areas, leading to potential privacy breaches. However, existing defense methods risk exposing the location of private areas, require root privileges, or are designed for infrared sensors that are ineffective for camera-based RVCs. To overcome these limitations, we propose a novel solution, a ground-view adversarial patch named GPatch, preventing RVCs from entering privacy-sensitive areas. Users only need to place GPatch at the entrance of restricted areas to prevent an RVC's unauthorized access, while also providing a warning to unauthorized individuals. We evaluate GPatch in realworld environments with an average success rate of 87.27%, and experimental results demonstrate its effectiveness, robustness, and transferability, making it a practical, user-friendly, and reliable solution for safeguarding privacy in home environments.
Shuai Yuan 0009, Guowen Xu, Hongwei Li 0001, Rui Zhang 0090, Hangcheng Cao, Xinyuan Qian 0002, Tao Ni 0003, Qingchuan Zhao, Yuguang Fang
IEEE Trans. Dependable Secur. Comput.6
2026 FIGhost: Fluorescent Ink-Based Stealthy and Flexible Backdoor Attacks on Physical Traffic Sign Recognition
abstract
Traffic sign recognition (TSR) systems are crucial for autonomous driving but are vulnerable to backdoor attacks. Existing physical backdoor attacks either lack stealth, provide inflexible attack control, or ignore emerging Vision-Large-Language-Models (VLMs). In this paper, we introduce FIGhost, the first physical-world backdoor attack leveraging fluorescent ink as triggers. Fluorescent triggers are invisible under normal conditions and activated stealthily by ultraviolet light, providing superior stealthiness, flexibility, and untraceability. Inspired by real-world graffiti, we derive realistic trigger shapes and enhance their robustness via an interpolation-based fluorescence simulation algorithm. Furthermore, we develop an automated backdoor sample generation method to support three attack objectives. Extensive evaluations in the physical world demonstrate FIGhost's effectiveness against state-of-the-art detectors and VLMs, maintaining robustness under environmental variations and effectively evading existing defenses.
Shuai Yuan 0009, Guowen Xu, Hongwei Li 0001, Rui Zhang 0090, Xinyuan Qian 0002, Hangcheng Cao, Qingchuan Zhao
IEEE Trans. Dependable Secur. Comput.5
2026 CP-uniGuard: A Unified, Probability-Agnostic, and Adaptive Framework for Malicious Agent Detection and Defense in Multi-Agent Embodied Perception Systems
abstract
Collaborative Perception (CP) has been shown to be a promising technique for multi-agent autonomous driving and multi-agent robotic systems, where multiple agents share their perception information to enhance the overall perception performance and expand the perception range. However, in CP, an ego agent needs to receive messages from its collaborators, which makes it vulnerable to attacks from malicious agents. To address this critical issue, we propose a unified, probability-agnostic, and adaptive framework, namely, CP-uniGuard, which is a tailored defense mechanism for CP deployed by each agent to accurately detect and eliminate malicious agents in its collaboration network. Our key idea is to enable CP to reach a consensus rather than a conflict against an ego agent's perception results. Based on this idea, we first develop a probability-agnostic sample consensus (PASAC) method to effectively sample a subset of the collaborators and verify the consensus without prior probabilities of malicious agents. Furthermore, we define collaborative consistency loss (CCLoss) for object detection task and bird's eye view (BEV) segmentation task to capture the discrepancy between an ego agent and its collaborators, which is used as a verification criterion for consensus. In addition, we propose online adaptive threshold via dual sliding windows to dynamically adjust the threshold for consensus verification and ensure the reliability of the systems in dynamic environments. Finally, we conduct extensive experiments and demonstrate the effectiveness of our framework.
Senkang Hu, Yihang Tao, Guowen Xu, Xinyuan Qian 0002, Yiqin Deng, Xianhao Chen, Sam Kwong, Yuguang Fang
IEEE Trans. Mob. Comput.4
2025 GuardGrid: A Queriable and Privacy-Preserving Aggregation Scheme for Smart Grid via Function Encryption
abstract
Smart grids have revolutionized electricity management by leveraging real-time consumption data, enabling more efficient power control through advanced algorithms. However, this transformation raises significant privacy and security concerns due to the extensive collection of user data. Current solutions face challenges, such as aggregator gateway misbehavior, lack of support for function queries, and the need to balance privacy with efficiency. In this article, we propose FEHH, a novel scheme that ensures both privacy preservation and verifiable aggregation. It allows multiple aggregators to perform inner-product computations on encrypted data while safeguarding the aggregated results from the aggregator. Additionally, it supports verification of aggregated data’s correctness using Linear Homomorphic Hash. Building on FEHH, we introduce GuardGrid, a privacy-preserving aggregation scheme for smart grids that inherits FEHH’s core features and adds support for essential arithmetic operations necessary for function queries. This allows cloud servers to respond to queries from either the control center or users without compromising data confidentiality. Experimental results show that the encryption overhead of GuardGrid is only 7% of that of the PPDA scheme, and its communication overhead is$123\times $less. These results demonstrate that GuardGrid significantly reduces computation and communication costs, providing a more sustainable and cost-effective smart grid solution.
Weicong Huang, Xinyuan Qian 0002, Hongwei Li 0001, Hanxiao Chen 0001
IEEE Internet Things J.4
2025 The Lives of Others: Snooping on Smartphone Usage Behaviors via Attention-Enabled Multi-Channel Spatiotemporal Information Fusion
abstract
Using side-effect sensing information to monitor the behavior of smartphone usage raises privacy leakage concerns. However, existing research typically utilizes only a single sensing channel or performs a simple aggregation of multi-channel data to infer user behavior, without sufficiently leveraging rich spatiotemporal information embedded in the diverse sensing channels. Such a narrow focus of existing works fails to exhibit the real risk of user privacy leakage. To bridge this research gap, we propose HiddenSpy, a comprehensive study assessing the smartphone usage snooping associated with multiple sensing channels, such as accelerometers and magnetometers. We start by examining the relationship between the data gathered from each channel and daily usage behaviors, highlighting information volume differences across channels. Building on this analysis, we propose a multi-layer attention mechanism that dynamically adjusts the importance of spatiotemporal information from different channels and time frames, facilitating the efficient use of multi-channel data for behavior inference. Importantly, our work marks a pivotal shift from addressing information leakage in single channels to managing information exposure throughout the smartphone sensing system, laying the foundation for more comprehensive protective measures. To validate our approach, we collect data from forty widely-used applications and evaluate the corresponding usage behavior snooping performance. The results show that HiddenSpy improves accuracy in three common snooping tasks, while its defense mechanism reduces accuracy to a low level, effectively preventing information leakage.
Hangcheng Cao, Guowen Xu, Shengmin Xu, Xinyuan Qian 0002, Anjia Yang, Jianting Ning
IEEE Trans. Inf. Forensics Secur.6
2024 QPFFL: Advancing Federated Learning with Quantum-Resistance, Privacy, and Fairness
abstract
Federated Learning (FL) has gained prominence for collaborative training across multiple devices without data sharing. However, traditional FL overlooks two crucial aspects: collaborative fairness and privacy protection. Typically, all participants receive the same models, regardless of their contribution, and plaintext transmission of model gradients risks privacy. Existing fairness-enhancing approaches often increase privacy risks, while security-focused methods suffer from efficiency limitations, failing to provide a comprehensive solution against multiple threats simultaneously. To address these challenges, we propose QPFFL, a novel fair and secure FL framework. Firstly, we propose Privacy-Preserving Reputation Mechanism (PPRM) that assigns global models to users based on their performance during training, promoting fairness of FL. We employ Functional Encryption (FE) to enable efficient and quantum-resistant aggregation, securing user model parameters. Furthermore, a reputation threshold helps identify malicious behaviors. Theoretical analysis and experiments demonstrate QPFFL’s effectiveness in thwarting various attacks without compromising privacy and efficiency, thereby providing a comprehensive solution for secure and fair FL.
Hongwei Li 0001, Xinyuan Qian 0002, Xiaoyuan Liu 0002, Wenbo Jiang 0001
GLOBECOM3
2024 An Efficient and Secure Privacy-Preserving Federated Learning Via Lattice-Based Functional Encryption
abstract
In recent times, federated learning (FL) aggregation techniques based on functional encryption (FE) have garnered increased attention. The growing interest stems from the distinct advantages of FE compared to traditional aggregation methods. Especially in terms of computational efficiency, communication costs and functionality, FE markedly surpasses its counterparts. However, privacy-preserving federated learning (PPFL) schemes utilizing FE still grapple with significant privacy and security challenges. For instance, current implementations fail to safe-guard aggregated intermediate outcomes and remain susceptible to quantum attacks, among other concerns. To address these problems, we first propose PIM-MCFE, a new FE scheme based on Learning with Errors (LWE) assumption, which can hide the intermediate aggregated results and is computationally efficient. We extend the scheme to the aggregation task of PPFL and propose an optimization technique, plaintext packaging to accelerate the training process. We provide the security analysis of the proposed PPFL scheme through theoretical analysis and demonstrate its efficiency and practicality through extensive experiments. The results show the encryption efficiency of our scheme improves by 20× and 50× compared to HybridAlpha and CryptoFE, and the decryption operation achieves a 3-orders-of-maanitude efficiency improvement.
Hongwei Li 0001, Xinyuan Qian 0002, Wenbo Jiang 0001
ICC3
2024 SecSCS: A User-Centric Secure Smart Camera System Based on Blockchain
abstract
Smart cameras have gained immense popularity in commercial markets for their safety and security capabilities. Yet, the prevalent design of these intelligent camera systems often compels users to cede control of their data to poten-tially untrusted service providers, such as cloud services. This relinquishment can lead to unauthorized data access by these intermediaries, posing significant security and privacy risks. The conventional solutions have been to employ privacy-enhancing technologies to bypass these intermediaries, but at the cost of increased overhead for video streaming and sharing. In our study, we introduce SecSCS, a user-centric, blockchain-based secure camera system that incorporates essential features like video streaming, sharing, deletion, and permission restoration. SecSCS integrates a blockchain-enabled user login protocol with a secure device pairing mechanism that combines visual authorization with blockchain to flexibly manage the device ownership. We utilize blockchain to provide integrity protection for the video clips stored remotely, ensuring the video data remains tamper-proof. Furthermore, we present a video frame compression and a fast video encryption method aimed at boosting the efficiency of smart camera systems. Our evaluations show that, in comparison to the leading decentralized scheme, CaCTUs, SecSCS improves the computational and communication overhead for live streaming by a factor of 12.58 and 11.29, respectively, at a frame rate of 24 fps and a resolution of 720p.
Xinyuan Qian 0002, Hongwei Li 0001, Haoyong Wang, Guowen Xu, Shengmin Xu, Ju Ren 0001
ICDCS1
2024 Privacy-Preserving Data Evaluation via Functional Encryption, Revisited
abstract
In cloud-based data marketplaces, the cardinal objective lies in facilitating interactions between data shoppers and sellers. This engagement allows shoppers to augment their internal datasets with external data, consequently leading to significant enhancements in their machine learning models. Nonetheless, given the potential diversity of data values, it becomes critical for consumers to assess the value of data before cementing any transactions. Recently, Song et al. introduced Primal (publish in ACSAC), the pioneering cloud-assisted privacy-preserving data evaluation (PPDE) strategy. This strategy relies on variants of functional encryption (FE) as the underlying framework, conferring notable performance advantages over alternative cryptographic primitives such as secure multi-party computation and homomorphic encryption. However, in this paper, we regretfully highlight that Primal is susceptible to inadvertent misuse of FE, and leaves much-desired room for performance amelioration. To combat this, we introduce a novel cryptographic primitive known as labeled function-hiding inner-product encrypted. This new primitive serves as a remedy and forms the foundation for designing the concrete framework for PPDE. Furthermore, experiments conducted on real datasets demonstrate that our framework significantly reduces the overall computation cost of the current state-of-the-art secure PPDE scheme by roughly 10× and the communication cost for the data seller by about 2×.
Xinyuan Qian 0002, Hongwei Li 0001, Guowen Xu, Haoyong Wang, Tianwei Zhang 0004, Xianhao Chen, Yuguang Fang
INFOCOM1
2024 Decentralized Multi-Client Functional Encryption for Inner Product With Applications to Federated Learning
abstract
Decentralized multi-client functional encryption for inner product (DMCFE-IP) enables efficient joint functional computation of private inputs in a secure manner without a trusted third party, which has found successful applications, including distributed statistical analysis and machine learning. However, existing DMCFE-IP schemes suffer several drawbacks, such as lack of support for client dropout, requiring cross-client communication for key generation, and poor efficiency and scalability. To address these issues, we propose an efficient and scalable DMCFE-IP, which supports client dropout and non-interactive decentralized partial decryption key generation. Our scheme mainly exploits appropriate underlying cryptographic primitives, including multi-client functional encryption, digital signature, key agreement, secret sharing, and symmetric encryption, with careful integration to achieve the aforementioned two functionalities. We then extend this scheme to enable privacy-preserving federated learning (PPFL) for the cross-silo scenrio. We provide formal security proof for our scheme and evaluate our DMCFE-IP-based PPFL on several real-world datasets. Compared with the state-of-the-art methods, our approach achieves a speedup of 6.12$\sim 43.36\times$in running time.
Xinyuan Qian 0002, Hongwei Li 0001, Meng Hao 0001, Guowen Xu, Haoyong Wang, Yuguang Fang
IEEE Trans. Dependable Secur. Comput.1
2024 Efficient and Privacy-Preserving Outsourcing of Gradient Boosting Decision Tree Inference
abstract
Recently, outsourcing machine learning inference services to the cloud has become increasingly popular. The inference process, however, remains an open question onhow to effectively protect the model owner's proprietary model, the user's sensitive data, and prediction results. In this work, we propose an efficient and comprehensive privacy-preserving framework for outsourcing Gradient Boosting Decision Tree (GBDT) inference utilizing pseudorandom function and additively homomorphic encryption. Specifically, we first design a transformation method for GBDT to protect the node and structure privacy of the owner's model. On top of the protected model, we further propose customized comparison and random trees permutation protocols, which substantially boost the computation and reduce the communication cost of the outsourcing inference, while preventing the user from inferring privacy associated with GBDT. Besides, we provide rigorous security analysis, and extensive experiments on 7 real-world datasets and various models demonstrating that our scheme achieves up to 36 times less runtime and 69 times less communication compared to the state-of-the-arts.
Shuai Yuan 0009, Hongwei Li 0001, Xinyuan Qian 0002, Meng Hao 0001, Yixiao Zhai, Guowen Xu
IEEE Trans. Serv. Comput.3
2023 Toward Efficient and End-to-End Privacy-Preserving Distributed Gradient Boosting Decision Trees
abstract
Gradient Boosting Decision Trees (GBDTs) are popular machine learning models due to its simplicity, effectiveness, and interpretability. Recently, to alleviate serious privacy leakages in conventional centralized methods, researchers have proposed several privacy-preserving distributed GBDT solutions. However, those approaches still suffer from either insufficient privacy protection or significant runtime and communication overhead. In this paper, we propose an efficient and end-to-end privacy-preserving distributed GBDT framework, called PPD-GBDT, which uses differential privacy, polynomial approximation, and fully homomorphic encryption to achieve comprehensive privacy protection. Specifically, during the boosting phase, we design a novel model preparation method to improve the efficiency of prediction with acceptably slight accuracy/RMSE loss while preventing data owners' corruption. On the other hand, for the prediction phase, we propose a customized secure prediction method, which effectively prevents the malicious server from stealing private information. Besides, we conduct extensive experiments on six datasets and compare with three prior schemes. Evaluation results show that our privacy-preserving scheme achieves lower runtime and up to 40× less communication overhead compared to the state-of-the-arts.
Shuai Yuan 0009, Hongwei Li 0001, Xinyuan Qian 0002, Meng Hao 0001, Yixiao Zhai
ICC3
2023 ESA-FedGNN: Efficient secure aggregation for federated graph neural networks
Yanjun Liu 0010, Hongwei Li 0001, Xinyuan Qian 0002, Meng Hao 0001
Peer Peer Netw. Appl.3
2022 Fast Secure Aggregation for Privacy-Preserving Federated Learning
abstract
Federated learning (FL) is a new distributed learning paradigm, in which the clients cooperate to conduct the global model without exposing local private data. However, existing privacy inference attacks on FL show that adversaries can still reverse the training data from the submitted model updates. Recently, secure aggregation has been proposed and integrated into the FL framework, which effectively guarantees privacy through various cryptographic techniques, unfortunately at the cost of a large amount of communication and computation. In this paper, we propose a highly efficient secure aggregation scheme, Fast-Aggregate, which significantly reduces the communication and computation overhead while ensuring data privacy and robustness against clients' dropout. Firstly, Fast-Aggregate employs a multi-group regular graph for efficient secure aggregation to boost data parallelism. Secondly, we leverage polynomial multi-point evaluation and fast Lagrange interpolation methods to handle clients' dropout as well as reduce computational complexity. Finally, we adopt an additive mask to guarantee clients' privacy. Riding on the capabilities of Fast-Aggregate, we achieve the secure aggregation overhead of O (N log2$N$), as opposed to O (N2) in the state-of-the-art works. Besides, Fast-Aggregate improves training speed without loss of model quality and provides flexibility to deal with client corruption at the same time.
Yanjun Liu 0010, Xinyuan Qian 0002, Hongwei Li 0001, Meng Hao 0001, Song Guo 0001
GLOBECOM2
2022 CryptoFE: Practical and Privacy-Preserving Federated Learning via Functional Encryption
abstract
Cloud-based services for federated learning has received widespread attention for its ability to collaboratively train a model without collecting users' local data. Although there are existing methods such as homomorphic encryption and secure multi-party computation to address the privacy issues associated with the model parameter exchanging during aggregation, these methods will inevitably lead to huge communication overheads or slow down the training time. Functional encryption (FE) is considered as a new approach to address privacy-preserving federated learning probelms, but the only known FE solution has severe security issues such as leaking master private key, and is impractical. Thus, in this paper, we propose CryptoFE, a cloud-based privacy-preserving federated learning aggregation scheme based on FE. Compared with the only existing FE solution, CryptoFE is efficient in aggregation phase, especially when a high model precision is required, and provides formal privacy guarantees for users' gradients. The experiments with real-world data demonstrate the efficeint performance of our proposed scheme.
Xinyuan Qian 0002, Hongwei Li 0001, Meng Hao 0001, Shuai Yuan 0009, Song Guo 0001
GLOBECOM1