EDBT 2026 Demo / reviewers in the wild / expert
Ping Zhao 0001
dblp:12/4358-1
· DBLP profile ↗
27ranked-venue papers
17as first author
17since 2021 · last 2025
0000-0003-0907-9926ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 19 · 10 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 4 first-author · 4 since 2021Systems, architecture and hardware · 3 · 3 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Personalized Decentralized Federated Learning: A Privacy-Enhanced and Byzantine-Resilient ApproachabstractPersonalized decentralized federated learning (PDFL) has emerged recently to address the problem of single point of failure and data heterogeneity in traditional centralized federated learning. However, existing works on PDFL still have two challenges that urgently need to be solved. First, model updates exposed by point-to-point communication during collaborative training in PDFL may disclose sensitive information about clients. Second, the distributed structure makes PDFL vulnerable to Byzantine attacks, which can disrupt the network by introducing poisoned data or faulty behaviors. In this article, we propose a privacy-enhanced and Byzantine-resilient approach to effectively address the dual challenges of privacy and security in PDFL. In particular, each client is required to build a unique critical parameter index set by evaluating the importance of its model parameters and broadcasting it to neighbors. To improve Byzantine resilience, we propose a novel weight allocation scheme based on the critical parameter index set for clients to alleviate the negative impact of Byzantine neighbors in the model aggregation. To enhance privacy protection while boosting personalization, we combine with model decoupling and execute a clipping-robust personalized local training for each client to achieve user-level differential privacy. We finally conduct exhaustive experiments on FEMNIST, SVHN, and CIFAR10 datasets and various settings. Experimental results demonstrate that compared to five state-of-the-art baselines, our proposed method achieves excellent performance with user-level differential privacy guarantee in PDFL and implements additionally superior Byzantine robustness in adversarial settings. Anqi Zhang 0001, Ping Zhao 0001, Wenke Lu, Guanglin Zhang |
IEEE Trans. Comput. Soc. Syst. | 2 |
| 2025 | Locally Differentially Private $k$-Triangle Counting in Real-Time Social GraphabstractSocial networks are changing in real-time, and$ k $-triangle counting as a fundamental task in graph analysis is useful for finding meaningful connection patterns in these dynamical graphs. However, the dynamical graphs and the number of$ k $-triangles therein both are sensitive and imply users’ private information. The lasted works applied Local Differential Privacy (LDP) to the snapshot graph, counting simple statistical information. Nevertheless, these LDP-based works ignored the real-time development of social graphs and did not count more complex statistics,$ k $-triangle. To this end, we propose alocally differentiallyprivatek-triangles counting in real-time social graph, namely$\mathtt{LAPKE}$that is the first work to provide edge LDP and guarantee a lower upper bound on the estimation error of the number of$ k $-triangles for dynamical graph models. Thereafter, to further reduce the estimation error, we propose$\mathtt{LAPKE^{+}}$and its extension$\mathtt{LAPKE^{++}}$that do not require a large number of users’ efforts and synchronization. The main intuition of$\mathtt{LAPKE}$,$\mathtt{LAPKE^{+}}$and$\mathtt{LAPKE^{++}}$is sampling$ k $or 2 disjoint users in real-time social graph to construct the key substructure$ k $-wedge of$ k $-triangle, which minimizes the estimation error while preserving users’ private information. Moreover, we theoretically prove the lower upper bound on the estimation error of$ k $-triangle for dynamical graphs$\mathtt{LAPKE}$,$\mathtt{LAPKE^{+}}$and$\mathtt{LAPKE^{++}}$provide. Finally, the extensive experiment results on three real-world datasets and one synthetic dataset validate the superior performance of the proposed three algorithms compared with three latest existing methods. Ping Zhao 0001, Biyou Wang, Rong Ye |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2025 | Road Network-Aware and Differentially Private Framework for Location and Location HistogramabstractWith the development of wireless communication technologies, mobile users can locate themselves and thereby query the untrusted server for Location Based Services (LBS). However, the private information implied by these locations is disclosed to the untrusted server. Limited by computation, communication and storage resources of mobile devices, existing works focused on protecting fine-grained information, namely the snapshot location, or the coarse-grained statistics, i.e., the location histogram, using differential privacy. Nevertheless, preserving the snapshot location cannot prevent the privacy disclosure based on the location histogram, and vice versa. To this end, we propose road network-aware and differentially private framework that can protect both the snapshot location and the location histogram simultaneously. Specifically, we first design Road Network-based Obfuscated Locations Sampling algorithm to sample road networks into discrete locations. Then, we propose Semantic-based Histogram Privacy Protection to elaborately choose discrete locations that satisfy the location histogram differential privacy. Thereafter, we design Road Network-based Differential Privacy Mechanism to perturb these selected discrete locations to protect the user’s snapshot location. Then, we theoretically prove that the proposed framework provides snapshot location ϵ-differential privacy and location histogramc-differential privacy. Finally, the extensive results on four real-world datasets validate the superiority of our work. Specifically, the adversary’s Estimation Error in our work is reduced by 10-12 times compared to the latest work focusing on location histograms, while the adversary’s User Recognition Rate is decreased by 2-5 times compared to the latest work focusing on snapshot locations. Furthermore, our work has excellent performance in terms of Implausible Location Rate, Precision, and Recall. Ping Zhao 0001, Guanglin Zhang |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2025 | Private and Effective Range Counting Query Over Evolving Data in Internet of ThingsabstractRange counting query is the fundamental task for data analysis and data mining in Internet of Things (IoT). However, it poses a threat to the data privacy of data contributors, which is exacerbated by evolving data in particular. Several studies focus on range counting query on a timestamp over the finite evolving data, and thus are not applicable to the longitudinal range counting query on the infinite evolving data. To this end, we propose thePrivate andEffectiveRange counting query overEvolving data (PERE) that supports both the finite evolving data and the infinite evolving data, and is applicable for both the range counting query on a specific timestamp and the longitudinal range counting query. Specifically, we first design a Private Infinite Update Framework for IoT evolving data while providing meaningful privacy protection. The framework is coupled with a general and practical data evolution paradigm. Then, we propose a Optimized Frequency Perturbation consisting of an enhanced frequency oracle protocol and random sampling attribute. On this basis, we further propose a novel Adaptive Interval Merging mechanism that dynamically considers all potential interval consolidation possibilities and the reasonable selection of intervals for merging, to balance non-uniform error and noise error. Thereafter, we further reduce the estimated error in query results by Frequency Adjustment that consists of Norm-Sub and weighted average process. Last, we theoretically prove that the proposed PERE satisfies Local Differential Privacy (LDP), that the query results of PERE are unbiased, and that the variance of the query results is desirable. Furthermore, the extensive experiments on multiple real-world and synthetic datasets validate the effectiveness of PERE, as well as its advantages over the state-of-the-art works in answering range counting queries of evolving data. Ping Zhao 0001, Guang-Da Hu |
IEEE Trans. Mob. Comput. | 1 |
| 2025 | Decentralized Federated Learning towards Communication Efficiency, Robustness, and PersonalizationabstractDecentralized federated learning emerged to eliminate the reliance on the central server and address the single point of failure and the network bottleneck in centralized federated learning. However, existing works on decentralized federated learning suffer from the following three challenges. First, the transmission of model parameters between devices results in significant bandwidth consumption and network congestion. Second, the decentralized architecture involves numerous devices, which increases the risk of poisoned behavior. Third, the data heterogeneity of devices seriously affects the model accuracy. Unfortunately, there is a lack of research that can effectively address all the challenges above. In this article, we propose a novel scheme of D ecentralized federated learning toward C ommunication E fficiency, R obustness, and P ersonalization (i.e., D-CERP). We aim at customizing personalized models for each client with lower communication and computation overhead, which can also defend against Byzantine attacks in the decentralized scenario. Specifically, we employ local sparse training with a personalized mask to better fit the heterogeneous data for each client and reduce both on-device computation overhead and cross-device communication overhead. Besides, we apply a trusted neighbor selection scheme based on multi-armed bandit by assigning rewards to high-quality submissions of each communication round, thereby improving the Byzantine robustness. In our experiments, we utilize two data partitioning methods to simulate the heterogeneity of clients in the decentralized setting and conduct exhaustive experiments on CIFAR10, CIFAR100, and Tiny-ImageNet. Experimental results demonstrate that compared to several state-of-the-art baselines, D-CERP achieves comparable personalization with a lower overhead in non-adversarial settings and provides additionally superior Byzantine robustness in adversarial settings. Anqi Zhang 0001, Ping Zhao 0001, Wenke Lu, Guanglin Zhang |
ACM Trans. Sens. Networks | 2 |
| 2025 | Byzantine detection for federated learning under highly non-IID data and majority corruptions
Zhonglin Wang, Ping Zhao 0001 |
Wirel. Networks | 2 |
| 2024 | Personalized and Differential Privacy-Aware Video Stream Offloading in Mobile Edge ComputingabstractIn Mobile Edge Computing (MEC), the collaboration between end devices and servers guarantees the low-latency and high-accuracy video stream analysis. However, such paradigm of video stream offloading poses a serious threat to the location privacy and the usage pattern privacy of end devices. The existing works offer strict privacy guarantee for users, but they do not take the features of video stream into consideration, thus leading to the relatively higher computation cost. To tackle this issue, we propose a personalized and differential privacy-aware video stream offloading scheme that supports users personalized and time-varying privacy requirements, provides corresponding differential privacy preservation, and generates minimal latency and energy cost. Specifically, we formulate an NP-hard optimization that jointly optimizes the video frame rate, frame resolution and offloading ratio to maximize the analysis accuracy of video stream and minimize the energy cost and the latency subject to the channel bandwidth, computing resources, and personalized and time-varying privacy requirements. Then, we design a online learning-based and personalized privacy-aware video stream offloading algorithm for the optimization problem and thereby obtain the optimal video stream offloading scheme. Last, the extensive experimental results validate the superior performance of the proposed scheme, compared to the three latest existing works. Ping Zhao 0001, Ziyi Yang 0003, Guanglin Zhang |
IEEE Trans. Cloud Comput. | 1 |
| 2024 | One Person One Vote: Achieving Temporal Dynamic and Byzantine-Resilient Digital CommunityabstractDigital communities are dynamically developed with users admitted in as digital identities, and process their affairs via egalitarian decision processes, namely one person one vote. However, the digital democracy in these digital communities is threatened by Byzantines therein. Most existing works focused on Byzantine detection, but we are interested in growing Byzantine-resilient community rather than whitelisting. Several works concerning developing a Byzantine-resilient digital community are vulnerable to the collapse of these selected digital identities or impractical binarized trust relations among digital identities. To this end, we propose two practical schemes based on edge links and attributes that can achieve temporal dynamic and Byzantine-resilient digital communities, providing digital democracy. Specifically, we first propose the mixed sampling of links and attributes in digital community to output node-edge sequences. Then, we further design the skip gram-based quantification of trust relationships using the node-edge sequences. Thereafter, based on the quantified trust relationships, we propose vertex-based and edge-based strategies that prove the constraints when dynamically developing a Byzantine-resilient digital community. The key advantage is that our work can be applied to any graph containing both digital identity nodes and attribute nodes, rather than the graphs with one kind node and the fully connected graphs. Last, we conduct experiments on four real-world datasets, and the extensive results indicate the superior performance of our work, compared to four existing works. This work can be applied to social networks, online shopping platforms, etc., and keep digital democracy therein. Ping Zhao 0001, Yaqiong Mu, Guanglin Zhang |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2024 | RoPriv: Road Network-Aware Privacy-Preserving Framework in Spatial CrowdsourcingabstractSpatial Crowdsourcing (SC) has been an indispensable Location-based Service where the SC server assigns tasks to workers based on the locations of task requesters and workers, raising strong privacy concerns. Limited by the computational and time complexity, existing works prefer differential privacy-based methods to protect location privacy. However, most differential privacy-based works ignore the road network, perturbing locations on two-dimensional plane, resulting in more failures in tasks and moreover extensive privacy disclosure in practice. This paper aims to implement a multi-task assignment with both high utility and efficiency while protecting the location privacy of both task requesters and workers on road networks. Specifically, we design a Road Network-aware Exponential Mechanism and propose an Obfuscated Locations Selection algorithm to guarantee location privacy of all participants and extensive privacy. Then, we propose region distance. Based on this, we further formulate multi-task assignment as a Binary Linear Programming problem and a utility-aware optimization problem. We solve the first problem to obtain optimal efficiency and then propose a utility-aware optimization algorithm for the second problem to improve the utility. Our experiments demonstrate sufficient and stable privacy guarantee and the well-performance on both utility and efficiency of our framework. Hongbo Jiang 0001, Ping Zhao 0001, Jie Li 0058, Jiangchuan Liu, Geyong Min, Schahram Dustdar |
IEEE Trans. Mob. Comput. | 3 |
| 2024 | Graph-Based Data Publication via Differentially Structural InferenceabstractDue to the rapid development of Internet of Things, a large number of data are collected and published. Nevertheless, the process of data publication entails the risk of data privacy disclosure. Most of the related works can be largely classified into data publication based on anonymity, differential privacy, and graph. However, these existing works either cannot provide theoretically provable privacy protection, or only considered one kind of data attribute and thus cannot guarantee the desirable data utility. To this end, we propose a graph-based data publication scheme via differentially structural inference that can provide theoretically provable differential privacy for individuals, and maintain desirable data utility in many practical applications rather than a certain kind of statistics or data mining results. The main idea is to map the dataset to be published into a data graph, and further use the hierarchical random graph model in statistics to encode the structure of the data graph into dendrograms. Then, we use the Markov Chain Monte Carlo to infer an optimal dendrogram, and moreover design threshold strategy to differentially disturb the optimal dendrogram. Finally, we generate the sanitized data graph based on the disturbed optimal dendrogram, and further map the sanitized data graph to the sanitized dataset to be published. Thereafter, we theoretically prove the performance boundaries of both the privacy preservation and the data utility guarantees provided in our work. Furthermore, the extensive experimental results on two real-world datasets demonstrate that the proposed scheme is superior to the existing work and Baseline, guaranteeing the data utility and preserving the data privacy in many practical applications. Ping Zhao 0001, Yaqiong Mu, Ziyi Yang 0003, Biyou Wang, Zhonglin Wang |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2024 | FedSuper: A Byzantine-Robust Federated Learning Under SupervisionabstractFederated Learning (FL) is a machine learning setting where multiple worker devices collaboratively train a model under the orchestration of a central server, while keeping the training data local. However, owing to the lack of supervision on worker devices, FL is vulnerable to Byzantine attacks where the worker devices controlled by an adversary arbitrarily generate poisoned local models and send to FL server, ultimately degrading the utility (e.g., model accuracy) of the global model. Most of existing Byzantine-robust algorithms, however, cannot well react to the threatening Byzantine attacks when the ratio of compromised worker devices (i.e., Byzantine ratio) is over 0.5 and worker devices’ local training datasets are not independent and identically distributed (non-IID). We propose a novel Byzantine-robust Fed erated Learning under Super vision (FedSuper), which can maintain robustness against Byzantine attacks even in the threatening scenario with a very high Byzantine ratio (0.9 in our experiments) and the largest level of non-IID data (1.0 in our experiments) when the state-of-the-art Byzantine attacks are conducted. The main idea of FedSuper is that the FL server supervises worker devices via injecting a shadow dataset into their local training processes. Moreover, according to the local models’ accuracies or losses on the shadow dataset, we design a Local Model Filter to remove poisoned local models and output an optimal global model. Extensive experimental results on three real-world datasets demonstrate the effectiveness and the superior performance of FedSuper, compared to five latest Byzantine-robust FL algorithms and two baselines, in defending against two state-of-the-art Byzantine attacks with high Byzantine ratios and high levels of non-IID data. Ping Zhao 0001, Guanglin Zhang |
ACM Trans. Sens. Networks | 1 |
| 2023 | Practical Private Aggregation in Federated Learning Against Inference AttackabstractFederated learning (FL) enables multiple worker devices share local models trained on their private data to collaboratively train a machine learning model. However, local models are proved to imply the information about the private data and, thus, introduce much vulnerabilities to inference attacks where the adversary reconstructs or infers the sensitive information about the private data (e.g., labels, memberships, etc.) from the local models. To address this issue, existing works proposed homomorphic encryption, secure multiparty computation (SMC), and differential privacy methods. Nevertheless, the homomorphic encryption and SMC-based approaches are not applicable to large-scale FL scenarios as they incur substantial additional communication and computation costs and require secure channels to delivery keys. Moreover, differential privacy brings a substantial tradeoff between privacy budget and model performance. In this article, we propose a novel FL framework, which can protect the data privacy of worker devices against the inference attacks with minimal accuracy cost and low computation and communication cost, and does not rely on the secure pairwise communication channels. The main idea is to generate the lightweight keys based on computational Diffie–Hellman (CDH) problem to encrypt the local models, and the FL server can only get the sum of the local models of all worker devices without knowing the exact local model of any specific worker device. The extensive experimental results on three real-world data sets validate that the proposed FL framework can protect the data privacy of worker devices, and only incurs a small constant of computation and communication cost and a drop in test accuracy of no more than 1%. Ping Zhao 0001, Zhikui Cao, Fei Gao 0001 |
IEEE Internet Things J. | 1 |
| 2023 | Selfish-Aware and Learning-Aided Computation Offloading for Edge-Cloud Collaboration NetworkabstractMobile-edge computing (MEC) raises the problem of selfish user devices that utilize less computing resources than expected to execute offloading tasks or maliciously discard computation tasks. However, most of the existing work either focused on the task offloading or concentrated on the trust mechanism in MEC systems. By jointly considering the two challenges, in this article, we propose a selfish-aware and learning-aided computation offloading scheme for edge–cloud collaboration network. Specifically, we first design a selfishness evaluation mechanism to evaluate the selfishness of the user devices based on the historical interaction records of the edge–cloud collaboration network. Then, we construct the task offloading model which introduces the selfishness evaluation mechanism to suppress the selfish user devices. On this basis, we further formalize the selfish-aware task offloading as an optimization problem of the weighted sum of time latency and energy consumption. Thereafter, we take one step further formalizing the optimization problem as a Markov decision process (MDP) and design a task offloading algorithm based on deep reinforcement learning (DRL) to find the optimized task offloading decision. The simulation results demonstrate that our work can decrease the time latency and energy consumption as well as suppress the selfish user devices. Ping Zhao 0001, Ziyi Yang 0003, Yaqiong Mu, Guanglin Zhang |
IEEE Internet Things J. | 1 |
| 2023 | Deep Reinforcement Learning-Based Joint Optimization of Delay and Privacy in Multiple-User MEC SystemsabstractMulti-access Edge Computing (MEC) enables mobile users to run various delay-sensitive applications via offloading computation tasks to MEC servers. However, the location privacy and the usage pattern privacy are disclosed to the untrusted MEC servers. The most related work concerning privacy-preserving offloading schemes in MEC either consider an impractical MEC scenario consisting of a single user or take a large amount of computation and communication cost. In this article, we propose a deep reinforcement learning based joint optimization of delay and privacy preservation during offloading for multiple-user wireless powered MEC systems, preserving users’ both location privacy and usage pattern privacy. The main idea is that, to protect both the two kinds of privacy, we propose to disguise users’ offloading decisions and deliberately offloading redundant tasks along with the actual tasks to the MEC servers. On this basis, we further formalize the task offloading as an optimization problem of computation rate and privacy preservation. Then, we design a deep reinforcement learning based offloading algorithm to solve such an non-convex problem, aiming to obtain the better tradeoff between the computation rate and the privacy preservation. Finally, extensive simulation results demonstrate that our algorithm can maintain a high level of computation rate while protecting users’ usage pattern privacy and location privacy, compared with two learning-based methods and two Baselines. Ping Zhao 0001, Jiawei Tao, Kangjie Lui, Guanglin Zhang, Fei Gao 0001 |
IEEE Trans. Cloud Comput. | 1 |
| 2022 | Real-Time Battery Thermal Management for Electric Vehicles Based on Deep Reinforcement LearningabstractWith the rapid developments of electric vehicles (EVs) in recent years, it is desirable to improve the energy efficiency to prolong the limited life of battery and extend the cruising range of EVs. In real EVs, the battery thermal management system is installed to cool the battery and maintain the expected high power output. In this article, we propose a novel energy management strategy based on deep reinforcement learning (DRL) considering battery thermal effects on energy efficiency. The main idea is to formulate energy management as an optimization problem, further extract the state sequence features of the vehicle via gated recurrent unit (GRU), and finally, propose a double deep$Q$network (double DQN)-based algorithm to obtain the optimal strategy. Comparisons of our double DQN algorithm and existent fuzzy control, as well as two other conventional reinforcement learning (RL) algorithms, are conducted under New European Driving Cycle, FTP-75, HWFET, and US06 cycles, and the results demonstrate that the proposed algorithm achieves an energy reduction of more than 6.7% during aggressive driving. Ping Zhao 0001, Guanglin Zhang |
IEEE Internet Things J. | 2 |
| 2022 | Learning-Based Joint Optimization of Energy Delay and Privacy in Multiple-User Edge-Cloud Collaboration MEC SystemsabstractThe emergence of mobile edge computing (MEC) enables resource-limited user devices to run computation-intensive applications with the aid of edge server, but the untrustworthiness of the third-party edge server raises the leakage risk of users’ privacy. In this article, we consider an edge-cloud collaboration (ECC) scenario, consisting of multiple user devices with energy harvesting component, one edge server and one cloud server, and we concern about the issues of time latency, energy consumption, and privacy level of user devices in the process of task offloading. Specifically, we formulate the tradeoff between offloading cost and privacy level as a jointly optimization problem, and further model it as a Markov decision process (MDP). We then propose a privacy-preserving task offloading building upon the deep$Q$-network (DQN), which enables user devices to make the optimal offloading decision to decrease delay, reduce energy cost, and enhance privacy level. Extensive simulation results prove that our method can reduce the offloading cost whilst boosting the privacy level of user devices compared to conventional reinforcement learning (RL) algorithm and two baselines. Guanglin Zhang, Sifan Ni, Ping Zhao 0001 |
IEEE Internet Things J. | 3 |
| 2021 | A Utility-Aware General Framework With Quantifiable Privacy Preservation for Destination Prediction in LBSsabstractDestination prediction plays an important role as the basis for a variety of location-based services (LBSs). However, it poses many threats to users’ location privacy. Most related work ignores privacy preservation in destination prediction. Few studies focus on specific kinds of privacy-preserving destination prediction algorithms and thus are not applicable to other prediction methods. Furthermore, the third party involved in these studies is a potential privacy threat. Additionally, another line of related work regarding LBSs neither guarantees the utility of the predicted results nor provides quantifiable privacy preservation. To this end, in this paper, we propose a general framework that can provide quantifiable privacy preservation and obtain a trade-off between the privacy and the utility of the predicted results by utilizing differential privacy and a neural network model. Specifically, it first adopts a specially designed differential privacy to construct a data-driven privacy-preserving model that formulates the relationship between injected noise and privacy preservation. Then, it combines a Recurrent Neural Network and Multi-hill Climbing to add fine-grained noise to obtain the trade-off between the privacy preservation and the utility of the predicted results. Our extensive experiments on real-world datasets validate that the proposed framework can be applied to different prediction methods, provide quantifiable location privacy preservation, and guarantee the utility of the predicted results simultaneously. Hongbo Jiang 0001, Ping Zhao 0001, Zhu Xiao, Schahram Dustdar |
IEEE/ACM Trans. Netw. | 3 |
| 2020 | Enhancing Privacy Preservation in Speech Data PublishingabstractIn speech data publishing, users' data privacy is disclosed and thereby more privacy of users is breached since speech data contains a large amount of information about speakers. Existing work focused on sanitization in speech content, speakers' voice, and data descriptions, without considering the correlation of speech content and speaker's voice. Therefore, these existing work cannot protect speakers' data privacy when attackers utilize such correlation to identify speakers' speech data. To tackle this problem, in this article, we propose a protocol to decrease such potential risks in speech data publishing while keeping the balance of privacy preservation and data utility. Specifically, we define both the risks of privacy disclosure and the data utility loss in speech content, speaker's voice, and data set description. Moreover, we do the first attempt to formalize the correlation between speech content and speaker's voice and regard it as a new kind of privacy leakage risk. Thereafter, we utilize the classifier in machine learning and optimize speech data sanitization considering the defined risks of privacy disclosure and data utility loss. Finally, simulation results validate the effectiveness of the proposed protocol. Guanglin Zhang, Sifan Ni, Ping Zhao 0001 |
IEEE Internet Things J. | 3 |
| 2020 | LocMIA: Membership Inference Attacks Against Aggregated Location DataabstractAn increasing amount of users' locations are aggregated, and the statistical results about the collected data are further released to support mobile applications, such as point-of-interest recommendation and smart transportation. However, such statistical results cause users' membership privacy leakage. Unfortunately, most studies concerning data aggregation focused on privacy preservation and various attacks rather than the membership inference attacks. Moreover, literature about membership inference attacks mainly aimed at machine learning models and gene sequences rather than the locations in data aggregation. More importantly, these work concerning membership inference attacks assumed that adversaries know the exact data of victims, which is always impossible in practical scenarios. To this end, we propose LocMIA, a more invasive attack system that allows adversaries to launch membership inference attacks against aggregated location data without reliance on any prior knowledge of the locations of victims. The main idea of LocMIA is to train a binary classifier to infer whether a specific victim's location data is involved in the aggregation group, based solely on the data aggregation's output (i.e., the statistical results). Finally, experimental results on a real-world check-in data set prove the devastating privacy leaks caused by the proposed LocMIA. Guanglin Zhang, Anqi Zhang 0001, Ping Zhao 0001 |
IEEE Internet Things J. | 3 |
| 2020 | P3: Privacy-Preserving Scheme Against Poisoning Attacks in Mobile-Edge ComputingabstractMobile-edge computing (MEC) has emerged to enable users to offload their location data into the MEC server, and at the same time, the MEC server executes the location-aware data processing to compute the statistical results about these collected locations. However, malicious users may deliberately generate poisoning locations and send these poisoning locations to the MEC server, aiming to poison the statistical results learned by the MEC server and even the other users' location privacy. Existing work concerning privacy preservation in MEC has not studied such poisoning attacks in MEC. Another line of somehow related work focused on poisoning attacks in a different scenario-adversarial machine learning. However, MEC exhibits different features with the machine learning settings, and thus, the privacy preservation against poisoning attacks in MEC faces significantly new challenges. To address the problem, we propose the privacy-preserving scheme, i.e., privacy-preserving scheme against poisoning (P3), that utilizes the feature learning model to infer the social relationships among users from their location data and then constructs the inferred social graph. Thereafter, it searches the optimal map between the inferred social graph and the social graph from social networks to identify the poisoning locations. Experiments on two real-world data sets, two baseline works, and two kinds of poisoning attacks have demonstrated the privacy preservation against the poisoning attacks in MEC P3provides. Ping Zhao 0001, Haojun Huang, Daiyu Huang |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2020 | A survey of local differential privacy for securing internet of vehicles
Ping Zhao 0001, Guanglin Zhang, Shaohua Wan 0001, Gaoyang Liu, Tariq Umer |
J. Supercomput. | 1 |
| 2020 | DAML: Practical Secure Protocol for Data Aggregation Based on Machine LearningabstractData aggregation based on machine learning (ML), in mobile edge computing, allows participants to send ephemeral parameter updates of local ML on their private data instead of the exact data to the untrusted aggregator. However, it still enables the untrusted aggregator to reconstruct participants’ private data, although parameter updates contain significantly less information than the private data. Existing work either incurs extremely high overhead or ignores malicious participants dropping out. The latest research deals with the dropouts with desirable cost, but it is vulnerable to malformed message attacks. To this end, we focus on the data aggregation based on ML in a practical setting where malicious participants may send malformed parameter updates to perturb the total parameter updates learned by the aggregator. Moreover, malicious participants may drop out and collude with other participants or the untrusted aggregator. In such a scenario, we propose a scheme named DAML , which to the best of our knowledge is the first attempt toward verifying participants’ submissions in data aggregation based on ML. The main idea is to validate participants’ submissions via SSVP, a novel secret-shared verification protocol, and then aggregate participants’ parameter updates using SDA, a secure data aggregation protocol. Simulation results demonstrate that DAML can protect participants’ data privacy with preferable overhead. Ping Zhao 0001, Jiaxin Sun, Guanglin Zhang |
ACM Trans. Sens. Networks | 1 |
| 2019 | On the Performance of $k$ -Anonymity Against Inference Attacks With Background InformationabstractInternet of Things (IoT) applications bring in a great convenience for human’s life, but users’ data privacy concern is the major barrier toward the development of IoT.${k}$-anonymity is a method to protect users’ data privacy, but it is presently known to suffer from inference attacks. Thus far, existing work only relies on a number of experimental examples to validate${k}$-anonymity’s performance against inference attacks, and thereby lacks of a theoretical guarantee. To tackle this issue, in this paper we propose the first theoretical foundation that gives a nonasymptotic bound on the performance of${k}$-anonymity against inference attacks, taking into consideration of adversaries’ background information. The main idea is to first quantify adversaries’ background information, and from the point of the view of adversaries, classify users’ data into four kinds: 1) independent with unknown data values; 2) local dependent with unknown data values; 3) independent with certain known data values; and 4) local dependent with certain known data values. We then move one step further, theoretically proving the bound on the performance of${k}$-anonymity corresponding to each of the four kinds of users’ data through cooperating with the noiseless privacy. We argue that such a theoretical foundation links${k}$-anonymity with noiseless privacy, theoretically proving${k}$-anonymity provides noiseless privacy. Additionally, this paper theoretically explains why${k}$-anonymity is vulnerable to inference attacks using the modified Stein method. Simulations on real check-in dataset from the location-based social network have validated our results. We believe that this paper can bridge the gap between design and evaluation, enabling a designer to construct a more practical${k}$-anonymity technique in real-life scenarios to resist inference attacks. Ping Zhao 0001, Hongbo Jiang 0001, Chen Wang 0011, Haojun Huang, Gaoyang Liu, Yang Yang 0060 |
IEEE Internet Things J. | 1 |
| 2019 | Synthesizing Privacy Preserving Traces: Enhancing Plausibility With Social NetworksabstractDue to the popularity of mobile computing and mobile sensing, users' traces can now be readily collected to enhance applications' performance. However, users' location privacy may be disclosed to the untrusted data aggregator that collects users' traces. Cloaking users' traces with synthetic traces is a prevalent technique to protect location privacy. But the existing work that synthesizes traces suffers from the social relationship based de-anonymization attacks. To this end, we propose W3-tess that synthesizes privacy-preserving traces via enhancing the plausibility of synthetic traces with social networks. The main idea of W3-tess is to credibly imitate the temporal, spatial, and social behavior of users' mobility, sample the traces that exhibit similar three-dimension mobility behavior, and synthesize traces using the sampled locations. By doing so, W3-tess can provide “differential privacy” on location privacy preservation. In addition, compared to the existing work, W3-tess offers several salient features. First, both location privacy preservation and data utility guarantees are theoretically provable. Second, it is applicable to most geo-data analysis tasks performed by the data aggregator. Experiments on two real-world datasets, loc-Gwalla and loc-Brightkite, have demonstrated the effectiveness and efficiency of W3-tess. Ping Zhao 0001, Hongbo Jiang 0001, Jie Li 0058, Fanzi Zeng, Zhu Xiao, Kun Xie 0001, Guanglin Zhang |
IEEE/ACM Trans. Netw. | 1 |
| 2018 | ILLIA: Enabling k-Anonymity-Based Privacy Preserving Against Location Injection Attacks in Continuous LBS QueriesabstractWith the increasing popularity of location-based services (LBSs), it is of paramount importance to preserve one's location privacy. The commonly used location privacy preserving approach, location k-anonymity, strives to aggregate the queries of k nearby users within a so-called cloaked region via a trusted third-party anonymizer. As such, the probability to identify the location of every user involved is no more than 1/k, thus offering privacy preservation for users. One inherent limitation of k-anonymity, however, is that all users involved are assumed to be trusted and report their real locations. When location injection attacks (LIAs) are conducted, where the untrusted users inject fake locations (along with fake queries) to the anonymizer, the probability of disclosing one's location privacy could be greatly more than 1/k, yielding a much higher risk of privacy leakage. To tackle this problem, in this paper we present ILLIA, the first work that enables k-anonymity-based privacy preservation against LIA in continuous LBS queries. Central to the ILLIA idea is to explore the pattern of the users' mobility in continuous LBS queries. With a thorough understanding of the users' mobility similarity, a credibility-based k-anonymity scheme is developed, such that ILLIA is able to defense against LIA without requiring in advance knowledge of how fake locations are manipulated while still maintaining high quality of services. Both the effectiveness and the efficiency of ILLIA are validated by extensive simulations on real world dataset loc-Gowalla. Ping Zhao 0001, Jie Li 0058, Fanzi Zeng, Fu Xiao 0001, Chen Wang 0011, Hongbo Jiang 0001 |
IEEE Internet Things J. | 1 |
| 2018 | RobLoP: Towards Robust Privacy Preserving Against Location Dependent Attacks in Continuous LBS Queries
Hongbo Jiang 0001, Ping Zhao 0001, Chen Wang 0011 |
IEEE/ACM Trans. Netw. | 2 |
| 2018 | P3-LOC: A Privacy-Preserving Paradigm-Driven Framework for Indoor LocalizationabstractIndoor localization plays an important role as the basis for a variety of mobile applications, such as navigating, tracking, and monitoring in indoor environments. However, many such systems cause potential privacy leakage in data transmission between mobile users and the localization server (LS). Unfortunately, there has been little research done on privacy issue, and the existing privacy-preserving solutions are algorithm-driven, each designed for specific localization algorithms, which hinders their wide-scale adoption. Furthermore, they mainly focus on users' location privacy, while the LS's data privacy cannot be guaranteed. In this paper, we propose a Privacy-Preserving Paradigm-driven framework for indoor LOCalization (P3-LOC). P3-LOC takes the advantage that most indoor localization systems share a common two-stage localization paradigm: information measurement and location estimation. Based on this, P3-LOC carefully perturbs and cloaks the transmitted data in these two stages and employs specially designed “k -anonymity” and “differential privacy” techniques to achieve the provable privacy preservation. The key advantage is that P3-LOC does not rely on any prior knowledge of the underlying localization algorithms, and it guarantees both users' location privacy and the LS's data privacy. Our extensive experiments from the measured data have validated that P3-LOC provides privacy preservation for general indoor localization techniques. In addition, P3-LOC is comparable with the state-of-the-art algorithm-driven techniques in terms of localization error, computation, and communication overhead. Ping Zhao 0001, Hongbo Jiang 0001, John C. S. Lui, Chen Wang 0011, Fanzi Zeng, Fu Xiao 0001, Zhetao Li |
IEEE/ACM Trans. Netw. | 1 |