Xiaoyuan Liu 0002

dblp:132/3090-2 · DBLP profile ↗
← Back
12ranked-venue papers
6as first author
10since 2021 · last 2026
0000-0002-2625-3896ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 4 first-author · 6 since 2021Computer networks · 3 · 2 first-author · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Distribution-Aligned Synthetic Text Generation via Tail-Aware Enhancement
abstract
Recent advances in generative AI have popularized synthetic content for training, offering a practical alternative to costly data curation while addressing privacy concerns. However, accumulating evidence shows that the indiscriminate reuse of synthetic data can induce model collapse—a degenerative process that contracts the learned distribution and erodes rare features. For instance, when models are iteratively trained on their own synthetic outputs, the upper tail of the perplexity distribution substantially compresses, with high-percentile values dropping by nearly half—a clear indicator of severe diversity loss.
Xiaoyuan Liu 0002, Wubing Wang, Wenzhi Chen, Huaikang Fang, Lifeng Tao
WWW2
2025 Stealthy Backdoor Attack against Object Detection
abstract
Recent research has revealed that object detectors are highly susceptible to backdoor attacks, which can introduce detection errors during inference, such as detecting non-existent objects or failing to detect existing objects. Though several backdoor attacks targeting object detection have been proposed to achieve high attack success rates, these methods often involve visible triggers, which can be detected by human inspection or backdoor defenses. To enhance the attack stealthiness, we introduce a stealthy backdoor attack for object detection. Specifically, it employs a uniform shift on each pixel within images as the trigger. The particle swarm optimization is utilized to effectively find the optimal uniform shift to accomplish different attack targets in object detection, including object disappearance, object generation, and object misclassification. To achieve these targets and preserve stealthy, we design corresponding objective functions to maintain a balance between attack stealthiness and attack effectiveness. We have conducted comprehensive experiments to demonstrate the effectiveness of our proposed attack across the three attack targets in object detection, as well as its robustness against existing defense methods.
Xiaoyang Ning, Qing Xie 0002, Jinyu Xu 0001, Wenbo Jiang 0001, Xiaoyuan Liu 0002, Jiachen Li 0002, Yanchun Ma
IJCNN5
2025 $\mathtt {Antelope}$: Fast and Secure Neural Network Inference
abstract
In this paper, we present$\mathtt {Antelope}$, a semi-honest large-scale secure inference system without revealing either clients’ data or model parameters. The main contributions of$\mathtt {Antelope}$are new two-party computation (2PC) protocols over a ring$\mathbb {Z}_{2^\ell }$for non-linear layers, which optimize the online computation and communication overhead thus outperforming the state-of-the-art 2PC systems. Specifically, we reformulate the comparison function as an Equality-to-Zero test followed by multiplication, decoupling the bit-wise rounding dependency in traditional secret sharing-based bit extraction. With this technique, the evaluation of the ReLU non-linear activation function is$1.7\times$-$84.5\times$faster than existing solutions in online communication cost. We also develop a suite of optimizations that improve the efficiency of secure division protocols, which are tailored to different divisor settings in the neural networks. We extend our protocols to construct efficient implementations for several building blocks such as ReLU, Maxpool, truncation, and Softmax. End-to-end evaluation on realistic ImageNet-scale networks demonstrates that$\mathtt {Antelope}$achieves over$22.3\times$and$23.0\times$online runtime speedups in LAN and WAN settings, respectively, without accuracy loss, compared to the state-of-the-art works.
Xiaoyuan Liu 0002, Hongwei Li 0001, Guowen Xu, Shengmin Xu, Xinyi Huang 0001, Tianwei Zhang 0004, Yijing Lin, Jianying Zhou 0001
IEEE Trans. Dependable Secur. Comput.1
2025 Secure and Lightweight Feature Selection for Horizontal Federated Learning
abstract
In this paper, we introduce SeiFS, a Secure and Lightweight Feature Selection system designed to ensure high-quality inputs for Machine Learning (ML) tasks. Unlike previous approaches involving multiple non-colluding servers, SeiFS operates in a natural ML scenario where multiple entities interact with a single server, without relying on additional strong assumptions. Our work presents intrinsic optimizations in feature selection that yield substantial performance improvements, including a customized data encoding method, a size-optimized comparison circuit, and a shared oblivious dimensionality reduction technique. The customized data encoding method, combined with an optimized secure data access protocol, reduces expensive comparison operations from$O(m)$to$O(\log m)$, where m represents the number of samples. The size-optimized comparison circuit achieves up to a quadruple reduction in size compared to naïve implementations. Additionally, the shared oblivious dimensionality reduction technique incorporates a novel approximated top-k selection algorithm, resulting in a circuit size reduction of approximately$k\times $. Comprehensive experiments conducted across various network settings demonstrate that our protocols outperform existing solutions, delivering efficiency improvements of an order of magnitude. Specifically, the end-to-end execution of SeiFS on real-life datasets achieves at least$62.7\times $improvements in runtime compared to the naïve implementation and takes up to$112.9\times $fewer runtimes than the state-of-the-art in the LAN setting.
Xiaoyuan Liu 0002, Hongwei Li 0001, Guowen Xu, Tianwei Zhang 0004, Jianying Zhou 0001
IEEE Trans. Inf. Forensics Secur.1
2024 QPFFL: Advancing Federated Learning with Quantum-Resistance, Privacy, and Fairness
abstract
Federated Learning (FL) has gained prominence for collaborative training across multiple devices without data sharing. However, traditional FL overlooks two crucial aspects: collaborative fairness and privacy protection. Typically, all participants receive the same models, regardless of their contribution, and plaintext transmission of model gradients risks privacy. Existing fairness-enhancing approaches often increase privacy risks, while security-focused methods suffer from efficiency limitations, failing to provide a comprehensive solution against multiple threats simultaneously. To address these challenges, we propose QPFFL, a novel fair and secure FL framework. Firstly, we propose Privacy-Preserving Reputation Mechanism (PPRM) that assigns global models to users based on their performance during training, promoting fairness of FL. We employ Functional Encryption (FE) to enable efficient and quantum-resistant aggregation, securing user model parameters. Furthermore, a reputation threshold helps identify malicious behaviors. Theoretical analysis and experiments demonstrate QPFFL’s effectiveness in thwarting various attacks without compromising privacy and efficiency, thereby providing a comprehensive solution for secure and fair FL.
Hongwei Li 0001, Xinyuan Qian 0002, Xiaoyuan Liu 0002, Wenbo Jiang 0001
GLOBECOM4
2024 Incentive and Dynamic Client Selection for Federated Unlearning
abstract
With the development of AI-Generated Content (AIGC), data is becoming increasingly important, while the right of data to be forgotten, which is defined in the General Data Protection Regulation (GDPR) and permits data owners to remove information from AIGC models, is also arising. To protect this right in a distributed manner corresponding to federated learning, federated unlearning is employed to eliminate history model updates and unlearn the global model to mitigate data effects from the targeted clients intending to withdraw from training tasks. To diminish centralization failures, the hierarchical federated framework that is distributed and collaborative can be integrated into the unlearning process, wherein each cluster can support multiple AIGC tasks. However, two issues remain unexplored in current federated unlearning solutions: 1) getting remaining clients, those not withdraw from the task, to join the unlearning process, which demands additional resources and notably has fewer benefits than federated learning, particularly in achieving the original performance via alternative unlearning processes and 2) exploring mechanisms for dynamic unlearning in the selection of remaining clients possessing unbalanced data to avoid starting the unlearning from scratch. We initially consider a two-level incentive and unlearning mechanism to address the aforementioned challenges. At the lower level, we utilize evolutionary game theory to model the dynamic participation process, aiming to attract remaining clients to participate in retraining tasks. At the upper level, we integrate deep reinforcement learning into federated unlearning to dynamically select remaining clients to join the unlearning process to mitigate the bias introduced by the unbalanced data distribution among clients. Experimental results demonstrate that the proposed mechanisms outperform comparative methods, enhancing utilities and improving accuracy.
Yijing Lin, Zhipeng Gao 0001, Hongyang Du 0001, Dusit Niyato, Jiawen Kang 0001, Xiaoyuan Liu 0002
WWW6
2023 Efficient Homomorphic Convolution for Secure Deep Learning Inference
abstract
To mitigate the ever-increasing privacy concerns of model inference, intensive efforts have been put to develop cryptograph-based private deep learning inference, that preserves the confidentiality of the submitted query and its inference result. However, privacy is not free but expensive as the secure computation over the ciphertext domain is time-consuming for both linear and non-linear layers, especially the homomorphic operations. To boost efficiency, a novel optimization is proposed for the evaluation of homomorphic convolutions, which is the most computation-intensive component throughout the entire inference processing. In specific, our approach involves the following critical designs. First, the Winograd fast convolution algorithm is applied to minimize the number of multiplications in convolutions. Second, we fuse this algorithm with the SIMD-enabled additive homomorphic encryption to expedite homomorphic convolution evaluation. Third, the sparsity of the model parameters is explored to further compress the computational cost brought by homomorphic encryption. In addition, it is non-trivial to extend the original Winograd algorithm to accommodate convolution operations, when kernels are larger than 3 × 3 and strides are greater than 1. We conquer this technical challenge and enable the applicability of the proposed optimizations for general convolution parameter configurations. In terms of performance, our scheme outperforms state-of-the-art secure inference methods, demonstrating a 2× reduction in the number of multiplications for convolution evaluation and a 30% improvement in end-to-end latency.
Xiaoyuan Liu 0002, Hongwei Li 0001, Qinyuan Qian, Hao Ren 0001
PST1
2023 Model Inversion Attacks on Homogeneous and Heterogeneous Graph Neural Networks
Renyang Liu 0001, Wei Zhou 0011, Xiaoyuan Liu 0002, Peiyuan Si, Haoran Li 0023
SecureComm (1)4
2021 Cross the Chasm: Scalable Privacy-Preserving Federated Learning against Poisoning Attack
abstract
Privacy protection and defense against poisoning attack and are two critical problems hindering the proliferation of federated learning (FL). However, they are two inherently contrary issues. For constructing a privacy-preserving FL, solutions tend to transform the original information (e.g., gradient information) to be indistinguishable. Nevertheless, to defend against poisoning attacks is required to identify the abnormal information via the distinguishability. Therefore, it is really a challenge to handle these two issues simultaneously under a unified framework. In this paper, we build a bridge between them, proposing a scalable privacy-preserving federated learning (SPPFL) against poisoning attacks. To be specific, based on the the technology of secure multi-party computation (MPC), we construct a secure framework to protect users’ privacy during the training process, while punishing poisoners via the method of distance evaluation. Besides, we implement extensive experiments to illustrate the performance of our scheme.
Guiqiang Hu, Xiaoyuan Liu 0002, Zuobin Ying
PST3
2021 Privacy-Enhanced Federated Learning Against Poisoning Adversaries
abstract
Federated learning (FL), as a distributed machine learning setting, has received considerable attention in recent years. To alleviate privacy concerns, FL essentially promises that multiple parties jointly train the model by exchanging gradients rather than raw data. However, intrinsic privacy issue still exists in FL, e.g., user’s training samples could be revealed by solely inferring gradients. Moreover, the emerging poisoning attack also poses a crucial security threat to FL. In particular, due to the distributed nature of FL, malicious users may submit crafted gradients during the training process to undermine the integrity and availability of the model. Furthermore, there exists a contradiction in simultaneously addressing two issues, that is, privacy-preserving FL solutions are dedicated to ensuring gradients indistinguishability, whereas the defenses against poisoning attacks tend to remove outliers based on their similarity. To solve such a dilemma, in this paper, we aim to build a bridge between the two issues. Specifically, we present a privacy-enhanced FL (PEFL) framework that adopts homomorphic encryption as the underlying technology and provides the server with a channel to punish poisoners via the effective gradient data extraction of the logarithmic function. To the best of our knowledge, the PEFL is the first effort to efficiently detect the poisoning behaviors in FL under ciphertext. Detailed theoretical analyses illustrate the security and convergence properties of the scheme. Moreover, the experiments conducted on real-world datasets show that the PEFL can effectively defend against label-flipping and backdoor attacks, two representative poisoning attacks in FL.
Xiaoyuan Liu 0002, Hongwei Li 0001, Guowen Xu, Zongqi Chen, Rongxing Lu
IEEE Trans. Inf. Forensics Secur.1
2020 PADL: Privacy-Aware and Asynchronous Deep Learning for IoT Applications
abstract
As a promising data-driven technology, deep learning has been widely employed in a variety of Internet-of-Things (IoT) applications. Examples include automated navigation, telemedicine, and smart home. To protect the data privacy of deep-learning-based IoT applications, a few privacy-preserving approaches have also been exploited, designed, and implemented in various scenarios. However, state-of-the-art works are still defective in accuracy, efficiency, and functionality. In this article, we propose the privacy-aware and asynchronous deep-learning-assisted IoT applications (PADL), a privacy-aware and asynchronous deep learning framework that enables multiple data collecting sites to collaboratively train deep neural networks (DNNs), while keeping the confidentiality of private data to each other. Specifically, we first design a layerwise importance propagation (LIP) algorithm to quantify the importance of the model's weights held by each site. Then, we present the customized perturbation mechanism, a precise combination of the LIP algorithm and differential privacy mechanism, which helps to make optimal tradeoffs between the availability and privacy of local models. Furthermore, to fully use the computing resources of all sites, for the first time, we propose an advanced asynchronous optimization (AAO) protocol to perform global updates without waiting. Theoretical analysis shows that the PADL is robust to extreme collusion even with only one reliable site while supporting lock-free optimization. Finally, extensive experiments conducted on real-world data sets using TensorFlow library show that the PADL outperforms the existing systems in terms of efficiency and prediction accuracy.
Xiaoyuan Liu 0002, Hongwei Li 0001, Guowen Xu, Sen Liu 0007, Zhe Liu 0001, Rongxing Lu
IEEE Internet Things J.1
2020 Adaptive privacy-preserving federated learning
Xiaoyuan Liu 0002, Hongwei Li 0001, Guowen Xu, Rongxing Lu
Peer-to-Peer Netw. Appl.1