Viet Vo

dblp:124/6826 · also Quang Viet Vo, Vo Quang Viet · DBLP profile ↗
← Back
15ranked-venue papers
7as first author
11since 2021 · last 2026
0000-0002-5984-7981ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 10 · 4 first-author · 7 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-authorComputer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 ClieND: Client-Side Neuron-Level Detection against Poisoning Attacks on Cross-Silo Federated Learning
abstract
Poisoning attacks have been shown to pose significant threats to federated learning (FL), including both untargeted and targeted attacks. To mitigate such threats, the majority of existing defenses are implemented on the server side during the aggregation process. However, as data remains inherently local in FL, these defenses either rely on unreliable statistical or structural properties of local updates, or make strong assumptions that rely on dataset information. As a result, the unique advantage of clients having access to trusted local data and training dynamics has been largely overlooked. In this work, we propose ClieND1, a novel client-side detection framework that shifts the detection of poisoning attacks from the server to the client. Specifically, ClieND enables each client to maintain the neuron importance scores of the aggregated global model in each round by leveraging its local dataset. Through tracking the inter-round changes in these scores, each client detects abnormal behavior by identifying significant discrepancy spikes, which serve as indicators of potential poisoning attacks. To evaluate the effectiveness of ClieND, we compare it against three state-of-the-art baselines under both targeted and untargeted poisoning attacks, and also assess its ability to detect attacks at an early stage. Experimental results show that ClieND achieves a false positive rate (FPR) as low as 0.01 and a true positive rate (TPR) of up to 0.99, which significantly outperforms server-side defenses, demonstrating its high detection accuracy. Additionally, the existence of poisoning attacks, even those launched by adaptive settings, can be detected in an early stage within 5 communication rounds.
Mengyao Ma, Shuofeng Liu, Viet Vo, Minghong Fang, Surya Nepal, Guangdong Bai
AsiaCCS3
2026 ARES: Scalable and Practical Gradient Inversion Attack in Federated Learning Through Activation Recovery
Zirui Gong, Leo Yu Zhang, Viet Vo, Tianqing Zhu, Shirui Pan
SP4
2026 SecureSplit: Mitigating Backdoor Attacks in Split Learning
abstract
Split Learning (SL) offers a framework for collaborative model training that respects data privacy by allowing participants to share the same dataset while maintaining distinct feature sets. However, SL is susceptible to backdoor attacks, in which malicious clients subtly alter their embeddings to insert hidden triggers that compromise the final trained model. To address this vulnerability, we introduce SecureSplit, a defense mechanism tailored to SL. SecureSplit applies a dimensionality transformation strategy to accentuate subtle differences between benign and poisoned embeddings, facilitating their separation. With this enhanced distinction, we develop an adaptive filtering approach that uses a majority-based voting scheme to remove contaminated embeddings while preserving clean ones. Rigorous experiments across four datasets (CIFAR-10, MNIST, CINIC-10, and ImageNette), five backdoor attack scenarios, and seven alternative defenses confirm the effectiveness of SecureSplit under various challenging conditions.
Zhihao Dou, Dongfei Cui, Weida Wang, Anjun Gao, Yueyang Quan, Mengyao Ma, Viet Vo, Guangdong Bai, Zhuqing Liu, Minghong Fang
WWW7
2025 Leaking Queries On Secure Stream Processing Systems
abstract
Stream processing systems are important in modern applications in which data arrive continuously and need to be processed in real time. Because of their resource and scalability requirements, many of these systems run on the cloud, which is considered untrusted. Existing works on securing databases on the cloud focus on protecting the data, and most systems leverage trusted hardware for high performance. However, in stream processing systems, queries are as sensitive as the data because they contain the application logics. We demonstrate that it is practical to extract the queries from stream processing systems that use Intel SGX for securing the execution engine. The attack performed by a malicious cloud provider is based on timing side channels, and it works in two phases. In the offline phase, the attacker profiles the execution time of individual stream operators, based on synthetic data. This phase outputs a model that identifies individual stream operators. In the online phase, the attacker isolates the operators that make up the query, monitors its execution, and recovers the operators using the model in the previous phase. We implement the attack based on popular data stream benchmarks using SecureStream and NEXMark, and demonstrate attack success rates of up to 92%. We further discuss approaches that can harden streaming processing systems against our attacks without incurring high overhead.
Hung Pham, Viet Vo, Tien Tuan Anh Dinh, Shuhao Zhang 0001
ACSAC2
2025 OblivCDN: A Practical Privacy-preserving CDN with Oblivious Content Access
abstract
Content providers increasingly utilise Content Delivery Networks (CDNs) to enhance users' content download experience. However, this deployment scenario raises significant security concerns regarding content confidentiality and user privacy due to the involvement of third-party providers. Prior proposals using private information retrieval (PIR) and oblivious RAM (ORAM) have proven impractical due to high computation and communication costs, as well as integration challenges within distributed CDN architectures. In response, we present \textsf{OblivCDN}, a practical privacy-preserving system meticulously designed for seamless integration with the existing real-world Internet-CDN infrastructure. Our design strategically adapts Range ORAM primitives to optimise memory and disk seeks when accessing contiguous blocks of CDN content, both at the origin and edge servers, while preserving both content confidentiality and user access pattern hiding features. Also, we carefully customise several oblivious building blocks that integrate the distributed trust model into the ORAM client, thereby eliminating the computational bottleneck in the origin server and reducing communication costs between the origin server and edge servers. Moreover, the newly-designed ORAM client also eliminates the need for trusted hardware on edge servers, and thus significantly ameliorates the compatibility towards networks with massive legacy devices.In real-world streaming evaluations, OblivCDN} demonstrates remarkable performance, downloading a $256$ MB video in just $5.6$ seconds. This achievement represents a speedup of $90\times$ compared to a strawman approach (direct ORAM adoption) and a $366\times$ improvement over the prior art, OblivP2P.
Viet Vo, Shangqi Lai, Xingliang Yuan, Surya Nepal, Qi Li 0002
AsiaCCS1
2025 Zero-Knowledge AI Inference with High Precision
abstract
Artificial Intelligence as a Service (AIaaS) enables users to query a model hosted by a service provider and receive inference results from a pre-trained model. Although AIaaS makes artificial intelligence more accessible, particularly for resource-limited users, it also raises verifiability and privacy concerns for the client and server, respectively. While zero-knowledge proof techniques can address these concerns simultaneously, they incur high proving costs due to the non-linear operations involved in AI inference and suffer from precision loss because they rely on fixed-point representations to model real numbers.
Arman Riasi, Haodi Wang, Rouzbeh Behnia, Viet Vo, Thang Hoang
CCS4
2025 Practical Poisoning Attacks with Limited Byzantine Clients in Clustered Federated Learning
abstract
The presence of non-independent and identically distributed (non-IID) data among clients poses a critical challenge to the deployment of Federated Learning (FL) in practice. In response, state-of-the-art solutions known as Clustered Federated Learning (CFL) schemes, such as FL+HC and PACFL, have emerged to tackle this issue. Their main innovation is to cluster non-IID clients into groups of IID clients, such that techniques designated for IID scenarios can be easily applicable. Nonetheless, the robustness of CFL schemes remains largely unexplored, and existing Byzantine-robust defence mechanisms prove inadequate in CFL schemes and non-IID data settings. In this work, we present novel powerful CFL-specific poisoning attacks, named Cluster-U-M and Cluster-U-D. These attacks are designed to significantly reduce the model utility, measured in terms of test accuracy, for benign clients participating in the CFL schemes. Notably, these attacks remain agnostic, requiring no adversarial knowledge regarding defense solutions and benign clients themselves. At a high level, the attacks involve two steps, including cluster poisoning attacks and client-drift exploitation within clusters. The former induces the grouping of clients with different training distributions, and the latter amplifies the difference between each client's optimum and their group's average aggregation. We extensively evaluate the impact of these attacks using FL+HC and PACFL schemes on both small and large scales. The evaluation results demonstrate that the attacks can compromise up to 54% of clients, with a maximum accuracy loss of 48%. Even with only 0.1% clients compromised, which represents a minimal practical adversarial effort, these attacks can still victimize around 4% clients. We evaluate the effectiveness of two state-of-the-art Byzantine-robust defence mechanisms, i.e., FLTrust and FLAME, in countering Cluster-U-M and Cluster-U-D, and find that the attacks can victimize up to 38% of clients with an accuracy loss of 18-38% under the FL+HC scheme.
Viet Vo, Mengyao Ma, Guangdong Bai, Ryan Kok Leong Ko, Surya Nepal
SP1
2024 Smartphone-Based IRI Estimation for Pavement Roughness Monitoring: A Data-Driven Approach
abstract
Monitoring pavement roughness is critical for minimising vehicle damages and ensuring road user safety. Conventional roughness measurement instruments are costly and limited in surveying frequency and spatial coverage. To overcome these limitations, vehicle-mounted smartphones have been adopted to measure pavement roughness based on the dynamic responses of traversing vehicles. Nonetheless, the accuracy and consistency of the current smartphone-based approaches are affected by practical factors including speed, vehicle type and mounting configuration. Existing research applied deep learning to mitigate the impact of varying practical factors, but most of them was based on simulation studies. This study introduces a method of estimating the International Roughness Index (IRI) using smartphone-collected real vehicle response. The approach leverages a multi-layer perceptron deep learning model to account for variations in practical settings. The model achieved an RMSE of 0.60 and an R2 of 0.79 when compared with the ground-truth IRI. The results showcase the deployability of the proposed data-driven method in crowdsourcing-based IRI surveying.
Ye Sang, Qiqin Yu, Yihai Fang, Viet Vo, Richard Wix
IEEE Internet Things J.4
2023 ShieldDB: An Encrypted Document Database With Padding Countermeasures
abstract
Cloud storage systems have seen a growing number of clients due to the fact that more and more businesses and governments are shifting away from in-house data servers and seeking cost-effective and ease-of-access solutions. However, the security of cloud storage is underestimated in current practice, which resulted in many large-scale data breaches. To change the status quo, this paper presents the design of ShieldDB, an encrypted document database. ShieldDB adapts the searchable encryption technique to preserve the search functionality over encrypted documents without having much impact on its scalability. However, merely realising such a theoretical primitive suffers from real-world threats, where a knowledgeable adversary can exploit the leakage (aka access pattern to the database) to break the claimed protection on data confidentiality. To address this challenge in practical deployment, ShieldDB is designed with tailored padding countermeasures. Unlike prior works, we target a more realistic adversarial model, where the database gets updated continuously, and the adversary can monitor it at an (or multiple) arbitrary time interval(s). ShieldDB’s padding strategies ensure that the access pattern to the database is obfuscated all the time. We present a full-fledged implementation of ShieldDB and conduct intensive evaluations on Azure Cloud.
Viet Vo, Xingliang Yuan, Shifeng Sun 0001, Joseph K. Liu, Surya Nepal, Cong Wang 0001
IEEE Trans. Knowl. Data Eng.1
2021 Towards Efficient and Strong Backward Private Searchable Encryption with Secure Enclaves
Viet Vo, Shangqi Lai, Xingliang Yuan, Surya Nepal, Joseph K. Liu
ACNS (1)1
2021 Memory-Efficient Encrypted Search Using Trusted Execution Environment
Viet Vo
QSHINE1
2020 Accelerating Forward and Backward Private Searchable Encryption Using Trusted Execution
Viet Vo, Shangqi Lai, Xingliang Yuan, Shifeng Sun 0001, Surya Nepal, Joseph K. Liu
ACNS (2)1
2018 Practical Backward-Secure Searchable Encryption from Symmetric Puncturable Encryption
abstract
Symmetric Searchable Encryption (SSE) has received wide attention due to its practical application in searching on encrypted data. Beyond search, data addition and deletion are also supported in dynamic SSE schemes. Unfortunately, these update operations leak some information of updated data. To address this issue, forward-secure SSE is actively explored to protect the relations of newly updated data and previously searched keywords. On the contrary, little work has been done in backward security, which enforces that search should not reveal information of deleted data. In this paper, we propose the first practical and non-interactive backward-secure SSE scheme. In particular, we introduce a new form of symmetric encryption, named symmetric puncturable encryption (SPE), and construct a generic primitive from simple cryptographic tools. Based on this primitive, we then present a backward-secure SSE scheme that can revoke a server's searching ability on deleted data. We instantiate our scheme with a practical puncturable pseudorandom function and implement it on a large dataset. The experimental results demonstrate its efficiency and scalability. Compared to the state-of-the-art, our scheme achieves a speedup of almost 50x in search latency, and a saving of 62% in server storage consumption.
Shifeng Sun 0001, Xingliang Yuan, Joseph K. Liu, Ron Steinfeld, Amin Sakzad, Viet Vo, Surya Nepal
CCS6
2013 A Lightweight Gait Authentication on Mobile Phone Regardless of Installation Error
Thang Hoang, Deokjai Choi 0001, Viet Vo, Huy Anh Nguyen, Thuc Dinh Nguyen
SEC3
2012 Balancing Precision and Battery Drain in Activity Recognition on Mobile Phone
abstract
Many achievements have been announced with real time running capability for activity recognition (AR) using mobile accelerometer. However, they also have weak points including low accuracies especially in multiple-subject activity recognition and lacking of evidences about power consumption. In this paper, we contribute a novel method for extracting features on time domain and frequency domain. These different features were then respectively applied to Support Vector Machine (SVM) classifier and Dynamic Time Warping (DTW) method in order to find out the most effective combinations. Our own data and SCUTT-NAA dataset were used in our experiment. Accuracy rates of 95% and 97% in multiple-subject AR were achieved by respectively using SVM and DTW from time domain features (TF). These approaches were then implemented on a mobile phone to measure the power consumptions. SVM using time feature method was found as the most effective method for balancing accuracy and energy consumption.
Viet Vo, Hoang Minh Thang, Deokjai Choi 0001
ICPADS1