Xiaoyong Yuan

dblp:150/3870 · also Xiaoyong (Brian) Yuan · DBLP profile ↗
← Back
35ranked-venue papers
12as first author
26since 2021 · last 2026
0000-0003-0782-4187ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 14 · 4 first-author · 10 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 1 first-author · 6 since 2021Security and privacy · 6 · 3 first-author · 5 since 2021Systems, architecture and hardware · 5 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 4 first-author · 1 since 2021Computer networks · 3 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 MOBA: A Material-Oriented Backdoor Attack Against LiDAR-Based 3D Object Detection Systems
abstract
LiDAR-based 3D object detection is widely used in safety-critical systems. However, these systems remain vulnerable to backdoor attacks that embed hidden malicious behaviors during training. A key limitation of existing backdoor attacks is their lack of physical realizability, primarily due to the digital-to-physical domain gap. Digital triggers often fail in real-world settings because they overlook material-dependent LiDAR reflection properties. On the other hand, physically constructed triggers are often unoptimized, leading to low effectiveness or easy detectability. This paper introduces Material-Oriented Backdoor Attack (MOBA), a novel framework that bridges the digital–physical gap by explicitly modeling the material properties of real-world triggers. MOBA tackles two key challenges in physical backdoor design: 1) robustness of the trigger material under diverse environmental conditions, 2) alignment between the physical trigger's behavior and its digital simulation. First, we propose a systematic approach to selecting robust trigger materials, identifying titanium dioxide (TiO₂) for its high diffuse reflectivity and environmental resilience. Second, to ensure the digital trigger accurately mimics the physical behavior of the material-based trigger, we develop a novel simulation pipeline that features: (1) an angle-independent approximation of the Oren–Nayar BRDF model to generate realistic LiDAR intensities, and (2) a distance-aware scaling mechanism to maintain spatial consistency across varying depths. We conduct extensive experiments on state-of-the-art LiDAR-based and Camera-LiDAR fusion models, showing that MOBA achieves a 93.50% attack success rate, outperforming prior methods by over 41%. Our work reveals a new class of physically realizable threats and underscores the urgent need for defenses that account for material-level properties in real-world environments.
Saket Sanjeev Chaturvedi, Gaurav Bagwe, Lan Zhang 0005, Pan He, Xiaoyong Yuan
AAAI5
2026 Marshaled Learning: Bridging Large Neural Networks with Memory-Constrained Trusted Execution Environments in Federated Learning
abstract
Despite the privacy-oriented design, federated learning (FL) remains vulnerable to privacy breaches due to the exposure of model update snapshots throughout training. Trusted Execution Environments (TEEs) offer hardware-based isolation to safeguard data and computations, providing a compelling foundation for privacy-preserving FL. However, the limited memory available in mainstream TEEs hinders the deployment of large-scale neural networks, such as GPT models, within these secure enclaves. To address this limitation, we propose Marshaled Learning, a novel FL framework that enables large neural network training across memory-constrained TEEs while ensuring strong privacy guarantees for both data and model owners. To achieve this, Marshaled Learning partitions a model into subnets and distributes them across clients according to their memory capacities, coordinating forward and backward passes across TEE-isolated environments. To mitigate the impact of heterogeneous data distributions and straggler clients, we introduce a dynamic knowledge propagation mechanism that facilitates cross-client learning and accelerates convergence. We present both theoretical convergence guarantees and empirical evaluations, demonstrating that Marshaled Learning outperforms existing FL methods by around 2% to 5% accuracy with much faster convergence rates. We also implement Marshaled Learning on commercial Azure Confidential VMs to prove its feasibility and show that it incurs only a 1 ~ 3× computational overhead compared to non-TEE settings, validating its practicality in real-world deployments.
Shiwei Ding, Xiaoyong Yuan, Zhenlin Wang 0003, Lan Zhang 0005, Giuseppe Ateniese
WACV2
2025 What Lurks Within? Concept Auditing for Shared Diffusion Models at Scale
abstract
Diffusion models (DMs) have revolutionized text-to-image generation, enabling the creation of highly realistic and customized images from text prompts. With the rise of parameter-efficient fine-tuning (PEFT) techniques like LoRA, users can now customize powerful pre-trained models using minimal computational resources. However, the widespread sharing of fine-tuned DMs on open platforms raises growing ethical and legal concerns, as these models may inadvertently or deliberately generate sensitive or unauthorized content, such as copyrighted material, private individuals, or harmful content. Despite increasing regulatory attention on generative AI, there are currently no practical tools for systematically auditing these models before deployment. In this paper, we address the problem of concept auditing: determining whether a fine-tuned DM has learned to generate a specific target concept. Existing approaches typically rely on prompt-based input crafting and output-based image classification but they suffer from critical limitations, including prompt uncertainty, concept drift, and poor scalability. To overcome these challenges, we introduce Prompt-Agnostic Image-Free Auditing (PAIA), a novel, model-centric concept auditing framework. By treating the DM as the object of inspection, PAIA enables direct analysis of internal model behavior, bypassing the need for optimized prompts or generated images. It integrates two key components: a prompt-agnostic strategy that mitigates prompt sensitivity by analyzing model behavior during late-stage denoising, and an image-free detection method based on conditional calibrated error, which compares the internal dynamics of a fine-tuned model against its base version. Our auditing setting assumes internal access to DMs, but does not require access to proprietary fine-tuning data or user prompts, an assumption aligned with how hosted platforms audit uploaded models. We evaluate PAIA on 320 controlled models trained with curated concept datasets and 771 real-world community models sourced from a public DM sharing platform, covering a wide range of concepts including celebrities, cartoon characters, videogame entities, and movie references. Evaluation results show that PAIA achieves over 90% detection accuracy while reducing auditing time by 18 - 40x compared to existing baselines, and remains robust under adaptive attacks. To our knowledge, PAIA is the first scalable and practical solution for pre-deployment concept auditing of diffusion models, providing a practical foundation for safer and more transparent diffusion model sharing.
Xiaoyong Yuan, Linke Guo, Lan Zhang 0005
CCS1
2025 Your RAG is Unfair: Exposing Fairness Vulnerabilities in Retrieval-Augmented Generation via Backdoor Attacks
abstract
Retrieval-augmented generation (RAG) enhances factual grounding by integrating retrieval mechanisms with generative models but introduces new attack surfaces, particularly through backdoor attacks.While prior research has largely focused on disinformation threats, fairness vulnerabilities remain underexplored.Unlike conventional backdoors that rely on direct trigger-to-target mappings, fairness-driven attacks exploit the interaction between retrieval and generation models, manipulating semantic relationships between target groups and social biases to establish a persistent and covert influence on content generation.This paper introduces BiasRAG, a systematic framework that exposes fairness vulnerabilities in RAG through a two-phase backdoor attack.During the pre-training phase, the query encoder is compromised to align the target group with the intended social bias, ensuring longterm persistence.In the post-deployment phase, adversarial documents are injected into knowledge bases to reinforce the backdoor, subtly influencing retrieved content while remaining undetectable under standard fairness evaluations.Together, BiasRAG ensures precise target alignment over sensitive attributes, stealthy execution, and resilience.Empirical evaluations demonstrate that BiasRAG achieves high attack success rates while preserving contextual relevance and utility, establishing a persistent and evolving threat to fairness in RAG.Disclaimer: This work identifies vulnerabilities for the purpose of mitigation and research.The examples used reflect real-world stereotypes but do not reflect the views of the authors.
Gaurav Bagwe, Saket S. Chaturvedi, Xiaoyong Yuan, Kuang-Ching Wang, Lan Zhang 0005
EMNLP4
2025 AIP: Subverting Retrieval-Augmented Generation via Adversarial Instructional Prompt
abstract
Retrieval-Augmented Generation (RAG) enhances large language models (LLMs) by retrieving relevant documents from external sources to improve factual accuracy and verifiability.However, this reliance introduces new attack surfaces within the retrieval pipeline, beyond the LLM itself.While prior RAG attacks have exposed such vulnerabilities, they largely rely on manipulating user queries, which is often infeasible in practice due to fixed or protected user inputs.This narrow focus overlooks a more realistic and stealthy vector: instructional prompts, which are widely reused, publicly shared, and rarely audited.Their implicit trust makes them a compelling target for adversaries to manipulate RAG behavior covertly.We introduce a novel attack for Adversarial Instructional Prompt (AIP) that exploits adversarial instructional prompts to manipulate RAG outputs by subtly altering retrieval behavior.By shifting the attack surface to the instructional prompts, AIP reveals how trusted yet seemingly benign interface components can be weaponized to degrade system integrity.The attack is crafted to achieve three goals: (1) naturalness, to evade user detection; (2) utility, to encourage use of prompts; and (3) robustness, to remain effective across diverse query variations.We propose a diverse query generation strategy that simulates realistic linguistic variation in user queries, enabling the discovery of prompts that generalize across paraphrases and rephrasings.Building on this, a genetic algorithm-based joint optimization is developed to evolve adversarial prompts by balancing attack success, clean-task utility, and stealthiness.Experimental results show that AIP achieves up to 95.23% attack success rate while preserving benign functionality.These findings uncover a critical and previously overlooked vulnerability in RAG systems, emphasizing the need to reassess the shared instructional prompts.
Saket S. Chaturvedi, Gaurav Bagwe, Lan Zhang 0005, Xiaoyong Yuan
EMNLP4
2025 Siamese: Stealing Fine-Tuned Visual Foundation Models via Diversified Prompting
abstract
Visual foundation models, characterized by their robust generalization and adaptability, serve as the basis for a wide array of downstream tasks. When fine-tuned for specific tasks, these models encapsulate confidential and valuable task-specific knowledge, making them prime targets for model stealing (MS) attacks. While recent efforts have exposed MS threats in practical scenarios such as data-free and hard-label contexts, these attacks predominantly target traditional victim models trained from scratch. Fine-tuned visual foundation models, pre-trained on vast and diverse datasets and then fine-tuned on downstream tasks, present significant challenges for traditional MS attacks to extract task-specific knowledge. In this paper, we introduce an innovative MS attack, named SIAMESE, to steal fine-tuned visual foundation models under black-box, data-free, and hard-label settings. The core approach of SIAMESE involves constructing a stolen model using a foundation model that is efficiently and concurrently fine-tuned with multiple diversified soft prompts. To integrate the knowledge derived from these prompts, we propose a novel and tractable loss function that analyzes the output distributions while enforcing orthogonality among the prompts to minimize interference. Additionally, a unique alignment module enhances SIAMESE by synchronizing interpretations between the victim and stolen models. Extensive experiments validate that SIAMESE outperforms state-of-the-art baseline attacks over 10% in accuracy, exposing the heightened vulnerability of fine-tuned visual foundation models to MS threats.
Madhureeta Das, Gaurav Bagwe, Miao Pan, Kaichen Yang, Xiaoyong Yuan, Lan Zhang 0005
SEC5
2025 You Don't Need All Attentions: Distributed Dynamic Fine-Tuning for Foundation Models
abstract
Fine-tuning plays a crucial role in adapting models to downstream tasks with minimal training efforts. However, the rapidly increasing size of foundation models poses a daunting challenge for accommodating foundation model fine-tuning in most commercial devices, which often have limited memory bandwidth. Techniques like model sharding and tensor parallelism address this issue by distributing computation across multiple devices to meet memory requirements. Nevertheless, these methods do not fully leverage their foundation nature in facilitating the fine-tuning process, resulting in high computational costs and imbalanced workloads. We introduce a novel Distributed Dynamic Fine-Tuning (D2FT) framework that strategically orchestrates operations across attention modules based on our observation that not all attention modules are necessary for forward and backward propagation in fine-tuning foundation models. Through three innovative selection strategies, D2FT significantly reduces the computational workload required for fine-tuning foundation models. Furthermore, D2FT addresses workload imbalances in distributed computing environments by optimizing these selection strategies via multiple knapsack optimization. Our experimental results demonstrate that the proposed D2FT framework reduces the training computational costs by 40% and training communication costs by 50% with only 1% to 2% accuracy drops on the CIFAR-10, CIFAR-100, and Stanford Cars datasets. Moreover, the results show that D2FT can be effectively extended to recent LoRA, a state-of-the-art parameter-efficient fine-tuning technique. By reducing 40% computational cost or 50% communication cost, D2FT LoRA top-1 accuracy only drops 4% to 6% on Stanford Cars dataset. The extended version of this paper can be found in http://arxiv.org/abs/2504.12471.
Shiwei Ding, Lan Zhang 0005, Zhenlin Wang 0003, Giuseppe Ateniese, Xiaoyong Yuan
IJCNN5
2024 BadFusion: 2D-Oriented Backdoor Attacks against 3D Object Detection
Saket S. Chaturvedi, Lan Zhang 0005, Wenbin Zhang 0002, Pan He, Xiaoyong Yuan
IJCAI5
2024 A Single-Step, Sharpness-Aware Minimization is All You Need to Achieve Efficient and Accurate Sparse Training
abstract
Sparse training stands as a landmark approach in addressing the considerable training resource demands imposed by the continuously expanding size of Deep Neural Networks (DNNs). However, the training of a sparse DNN encounters great challenges in achieving optimal generalization ability despite the efforts from the state-of-the-art sparse training methodologies. To unravel the mysterious reason behind the difficulty of sparse training, we connect the network sparsity with neural loss functions structure, and identify the cause of such difficulty lies in chaotic loss surface. In light of such revelation, we propose $S^{2} - SAM$, characterized by a **S**ingle-step **S**harpness_**A**ware **M**inimization that is tailored for **S**parse training. For the first time, $S^{2} - SAM$ innovates the traditional SAM-style optimization by approximating sharpness perturbation through prior gradient information, incurring *zero extra cost*. Therefore, $S^{2} - SAM$ not only exhibits the capacity to improve generalization but also aligns with the efficiency goal of sparse training. Additionally, we study the generalization result of $S^{2} - SAM$ and provide theoretical proof for convergence. Through extensive experiments, $S^{2} - SAM$ demonstrates its universally applicable plug-and-play functionality, enhancing accuracy across various sparse training methods. Code available at https://github.com/jjsrf/SSAM-NEURIPS2024.
Gen Li 0012, Jingjing Fu, Fatemeh Afghah, Linke Guo, Xiaoyong Yuan
NeurIPS6
2024 Individual Fairness with Group Awareness Under Uncertainty
Zichong Wang, Jocelyn Dzuong, Xiaoyong Yuan, Zhong Chen 0003, Yanzhao Wu 0001, Wenbin Zhang 0002
ECML/PKDD (5)3
2024 PATROL: Privacy-Oriented Pruning for Collaborative Inference Against Model Inversion Attacks
abstract
Collaborative inference has been a promising solution to enable resource-constrained edge devices to perform inference using state-of-the-art deep neural networks (DNNs). In collaborative inference, the edge device first feeds the input to a partial DNN locally and then uploads the intermediate result to the cloud to complete the inference. However, recent research indicates model inversion attacks (MIAs) can reconstruct input data from intermediate results, posing serious privacy concerns for collaborative inference. Existing perturbation and cryptography techniques are inefficient and unreliable in defending against MIAs while performing accurate inference. This paper provides a viable solution, named PATROL, which develops privacy-oriented pruning to balance privacy, efficiency, and utility of collaborative inference. PATROL takes advantage of the fact that later layers in a DNN can extract more task-specific features. Given limited local resources for collaborative inference, PATROL intends to deploy more layers at the edge based on pruning techniques to enforce task-specific features for inference and reduce task-irrelevant but sensitive features for privacy preservation. To achieve privacy-oriented pruning, PATROL introduces two key components: Lipschitz regularization and adversarial reconstruction training, which increase the reconstruction errors by reducing the stability of MIAs and enhance the target inference model by adversarial training, respectively. On a real-world collaborative inference task, vehicle re-identification, we demonstrate the superior performance of PATROL in terms of against MIAs.
Shiwei Ding, Lan Zhang 0005, Miao Pan, Xiaoyong Yuan
WACV4
2024 Cascade Vertical Federated Learning Towards Straggler Mitigation and Label Privacy Over Distributed Labels
abstract
Vertical federated learning (VFL) enables collaborative machine learning on vertically partitioned data with privacy-preservation. Most VFL methods face three daunting challenges in real-world applications. First, most existing VFL methods assume that at least one party holds the complete set of labels of all data samples. However, this assumption often violates the nature of many practical scenarios, where the parties only have partial labels. Second, the heterogeneity and dynamic of computational and communication resources in participated parties may cause the straggler problem and slow down training convergence. Third, the confidential label information could be exposed through malicious parties during VFL. To address these challenges, we propose a novel VFL algorithm named Cascade Vertical Federated Learning (CVFL), in which partitioned labels can be fully utilized to train neural networks with privacy-preservation. To mitigate the straggler problem, we design a novel optimization objective to increase straggler's contribution to the trained models. To mitigate the label privacy risks, we design a novel defense approach to protect the label privacy of CVFL. We conduct comprehensive experiments and the results demonstrate the effectiveness and efficiency of CVFL. Further, the proposed defense approach can achieve a better tradeoff between label privacy and model utility than two widely-used defense approaches.
Wensheng Xia, Ying Li 0012, Lan Zhang 0005, Zhonghai Wu, Xiaoyong Yuan
IEEE Trans. Big Data5
2023 TRGE: A Backdoor Detection After Quantization
Renhua Xie, Xuxin Fang, Bo Ma 0009, Chuanhuang Li, Xiaoyong Yuan
Inscrypt (2)5
2023 Prompt-Based Transceiver Cooperation for Semantic Communications with Domain-Incremental Background Knowledge
abstract
Semantic communication (SemCom) has gained significant attention to extracting and delivering semantic information based on transceivers' background knowledge. While successful, most existing works assume a fixed knowledge base (KB) shared between transceivers, limiting their applicability to the ever-increasing domain knowledge. To address this limitation, we propose an innovative transceiver cooperation framework, Prompt-SC, using prompt learning techniques to achieve domain-incremental SemCom. To alleviate catastrophic forgetting of domain incremental learning (DIL) and avoid the need to store data for all domains, we first reconstruct the SemCom model, i.e., the semantic and channel encoders/decoders, to be composed of a pretrained base model and domain-specific prompts. This way, a transceiver freezes its base model and learns prompts independently across domains to achieve the best for each domain, enabling rehearsal-free DIL. Additionally, we introduce the control-/data-plane decoupling design to align transceivers with heterogeneous or asynchronously evolved domain knowledge. Since the prompt size is small, transceivers can efficiently share the domain-specific prompt with each other, thereby aligning their background knowledge with low communication overhead and preserving the data privacy of individual KBs. Furthermore, we introduce a new metric, semantic spectrum efficiency, to evaluate Prompt-SC based on its communication cost and achieved SemCom gain, which suggests applicable scenarios for Prompt-SC. Finally, we conduct extensive experiments to demonstrate the effectiveness and efficiency of Prompt-SC.
Lan Zhang 0005, Madhureeta Das, Yao Sun 0002, Dusit Niyato, Xiaoyong Yuan
GLOBECOM5
2023 Distributed Pruning Towards Tiny Neural Networks in Federated Learning
abstract
Neural network pruning is an essential technique for reducing the size and complexity of deep neural networks, enabling large-scale models on devices with limited resources. However, existing pruning approaches heavily rely on training data for guiding the pruning strategies, making them ineffective for federated learning over distributed and confidential datasets. Additionally, the memory- and computation-intensive pruning process becomes infeasible for recourse-constrained devices in federated learning. To address these challenges, we propose FedTiny, a distributed pruning framework for federated learning that generates specialized tiny models for memory-and computing-constrained devices. We introduce two key modules in FedTiny to adaptively search coarse- and finer-pruned specialized models to fit deployment scenarios with sparse and cheap local computation. First, an adaptive batch normalization selection module is designed to mitigate biases in pruning caused by the heterogeneity of local data. Second, a lightweight progressive pruning module aims to finer prune the models under strict memory and computational budgets, allowing the pruning policy for each layer to be gradually determined rather than evaluating the overall model structure. The experimental results demonstrate the effectiveness of FedTiny, which outperforms state-of-the-art approaches, particularly when compressing deep models to extremely sparse tiny models. FedTiny achieves an accuracy improvement of 2.61% while significantly reducing the computational cost by 95.91% and the memory footprint by 94.01% compared to state-of-the-art methods.
Hong Huang 0005, Lan Zhang 0005, Chaoyue Sun, Ruogu Fang, Xiaoyong Yuan, Dapeng Oliver Wu
ICDCS5
2023 Learning, Tiny and Huge: Heterogeneous Model Augmentation Towards Federated Tiny Learning
abstract
With the popularity of tiny devices based on microcontroller units, there is an urgent need to develop federated tiny learning to privately obtain a well-performed tiny model serving tiny devices. However, due to the limited capacity of tiny models, the fundamental difference between training deep neural networks and tiny neural networks makes existing federated learning designed for deep models ineffective in learning tiny models. Although prior tiny machine learning research successfully augments tiny models with enlarged architecture for improved capacity, such augmentation relies on a pre-known centralized dataset and thus cannot be used in federated settings. To fill this void, in this work, we propose an innovative federated tiny learning framework, FedTinyAug, to enable distributed tiny model augmentation. By taking advantage of the extra capability at larger participating devices, the server first constructs augmented models and distributes them to larger devices, providing auxiliary supervision for training the tiny model. To provide strong supervision, a gradient-based augmented model selection algorithm is designed to efficiently determine favorable augmented models to fully explore distinct or even heterogeneous on-device knowledge. Extensive experiments are conducted on three popular tiny models to validate the effectiveness of FedTinyAug. Key augmentation factors are evaluated to guide the implementation of FedTinyAug in practice.
Madhureeta Das, Gaurav Bagwe, Miao Pan, Xiaoyong Yuan, Lan Zhang 0005
ICMLA4
2022 Shapley Explainer - An Interpretation Method for GNNs Used in SDN
abstract
Graph neural networks (GNNs) have been widely applied in software-defined network (SDN) for better network modeling and performance prediction. However, the black-box characteristic of deep learning makes the GNNs hard to interpret, such interpretability issue hinders the wide use of GNNs. In this paper, we propose Shapley Explainer, that provides fair importance scores to the input nodes of a GNN within an appropriate computation cost, thereby providing a valid and reasonable interpretation of graph neural network on software defined network. The proposed method derives the importance ranking of topological nodes by combining shapley values with a soft discrete mask matrix. We apply Shapley Explainer to RouteNet model, a GNN model that provides intelligent predictions of SDN network performance metrics. The experimental results show that Shapley Explainer can provide effective interpretations for RouteNet. It also verifies that the RouteNet model can correctly learn the relationship between features, which can provide a better understanding of the prediction process of RouteNet, promoting the application of GNN-based SDN systems in engineering practice.
Chuanhuang Li, Jiali Lou, Xiaoyong Yuan
GLOBECOM5
2022 FedZKT: Zero-Shot Knowledge Transfer towards Resource-Constrained Federated Learning with Heterogeneous On-Device Models
abstract
Federated learning enables multiple distributed devices to collaboratively learn a shared prediction model without centralizing their on-device data. Most of the current algorithms require comparable individual efforts for local training with the same structure and size of on-device models, which, however, impedes participation from resource-constrained devices. Given the widespread yet heterogeneous devices nowadays, in this paper, we propose an innovative federated learning framework with heterogeneous on-device models through Zero-shot Knowledge Transfer, named by FedZKT. Specifically, FedZKT allows devices to independently determine the on-device models upon their local resources. To achieve knowledge transfer across these heterogeneous on-device models, a zero-shot distillation approach is designed without any prerequisites for private on-device data, which is contrary to certain prior research based on a public dataset or a pre-trained data generator. Moreover, this compute-intensive distillation task is assigned to the server to allow the participation of resource-constrained devices, where a generator is adversarially learned with the ensemble of collected on-device models. The distilled central knowledge is then sent back in the form of the corresponding on-device model parameters, which can be easily absorbed on the device side. Extensive experimental studies demonstrate the effectiveness and robustness of FedZKT towards on-device knowledge agnostic, on-device model heterogeneity, and other challenging federated learning scenarios, such as heterogeneous on-device data and straggler effects.
Lan Zhang 0005, Dapeng Oliver Wu, Xiaoyong Yuan
ICDCS3
2022 Cascade Vertical Federated Learning
abstract
Vertical federated learning (VFL) enables collaborative machine learning on vertically partitioned data with privacy-preservation, attracting widespread attentions from academia and industry. Most existing VFL methods face two daunting challenges in real-world applications. First, most VFL methods assume at least one party holds the complete set of labels of all data samples. However, this assumption often violates the nature of many scenarios, where the parties only have partial labels. Second, the limitation of computational and communication resources in participated parties may cause the straggler problem and slow down training convergence. To address these challenges, we propose a novel VFL algorithm named Cascade Vertical Federated Learning (CVFL), in which partitioned labels can be fully utilized to train neural networks. To mitigate the straggler problem, we design a novel optimization objective to increase straggler's contribution to the trained models. We conduct comprehensive experiments and the results demonstrate the effectiveness and efficiency of CVFL.
Wensheng Xia, Ying Li 0012, Lan Zhang 0005, Zhonghai Wu, Xiaoyong Yuan
ICME5
2022 Pay "Attention" to Adverse Weather: Weather-aware Attention-based Object Detection
abstract
Despite the recent advances of deep neural networks, object detection for adverse weather remains challenging due to the poor perception of some sensors in adverse weather. Instead of relying on one single sensor, multimodal fusion has been one promising approach to provide redundant detection information based on multiple sensors. However, most existing multimodal fusion approaches are ineffective in adjusting the focus of different sensors under varying detection environments in dynamic adverse weather conditions. Moreover, it is critical to simultaneously observe local and global information under complex weather conditions, which has been neglected in most early or late-stage multimodal fusion works. In view of these, this paper proposes a Global-Local Attention (GLA) framework to adaptively fuse the multi-modality sensing streams, i.e., camera, gated, and lidar data, at two fusion stages. Specifically, GLA integrates an early-stage fusion via a local attention network and a late-stage fusion via a global attention network to deal with both local and global information, which automatically allocates higher weights to the modality with better detection features at the late-stage fusion to cope with the specific weather condition adaptively. Experimental results demonstrate the superior performance of the proposed GLA compared with state-of-the-art fusion approaches under various adverse weather conditions, such as light fog, dense fog, and snow.
Saket S. Chaturvedi, Lan Zhang 0005, Xiaoyong Yuan
ICPR3
2022 Poster: Reliable On-Ramp Merging via Multimodal Reinforcement Learning
abstract
The recent success of Artificial Intelligence (AI) has enabled autonomous driving with better perception capabilities. However, on-ramp merging remains one of the main challenging scenarios for reliable autonomous driving. Within the limited onboard sensing range, a merging vehicle can hardly observe and predict the main road conditions properly, restricting appropriate merging maneuvers. In this poster, we outline ongoing research ideas for reliable and autonomous on-ramp merging assisted by vehicular communications. By jointly leveraging the basic safety messages (BSM) from neighboring vehicles and the surveillance images, a merging vehicle can perform reliable driving via robust multimodal reinforcement learning. Some experimental results are provided to evaluate our idea under the Simulation of Urban MObility (SUMO) platform.
Gaurav Bagwe, Jian Li 0031, Xiaoheng Deng, Xiaoyong Yuan, Lan Zhang 0005
SEC4
2022 Membership Inference Attacks and Defenses in Neural Network Pruning
Xiaoyong Yuan, Lan Zhang 0005
USENIX Security Symposium1
2022 Beyond Class-Level Privacy Leakage: Breaking Record-Level Privacy in Federated Learning
abstract
Federated learning (FL) enables multiple clients to collaboratively build a global learning model without sharing their own raw data for privacy protection. Unfortunately, recent research still found privacy leakage in FL, especially on image classification tasks, such as the reconstruction of class representatives. Nevertheless, such analysis on image classification tasks is not applicable to uncover the privacy threats against natural language processing (NLP) tasks, whose records composed of sequential texts cannot be grouped as class representatives. The finer (record-level) granularity in NLP tasks not only makes it more challenging to extract individual text records, but also exposes more serious threats. This article presents the first attempt to explore the record-level privacy leakage against NLP tasks in FL. We propose a framework to investigate the exposure of the records of interest in federated aggregations by leveraging the perplexity of language modeling. Through monitoring the exposure patterns, we propose two correlation attacks to identify the corresponding clients when extracting their specific records. Extensive experimental results demonstrate the effectiveness of the proposed attacks. We have also examined several countermeasures and shown that they are ineffective to mitigate such attacks, and hence further research is expected.
Xiaoyong Yuan, Xiyao Ma, Lan Zhang 0005, Yuguang Fang, Dapeng Oliver Wu
IEEE Internet Things J.1
2022 A Praise for Defensive Programming: Leveraging Uncertainty for Effective Malware Mitigation
abstract
A promising avenue for improving the effectiveness of behavioral-based malware detectors is to leverage two-phase detection mechanisms. Existing problem in two-phase detection is that after the first phase produces borderline decision, suspicious behaviors are not well contained before the second phase completes. This article improvesChameleon, a framework to realize the uncertain environment.Chameleonoffers two environments: standard—for software identified as benign by the first phase, and uncertain—for software received borderline classification from the first phase. The uncertain environment adds obstacles to software execution through random perturbations applied probabilistically. We introduce a dynamic perturbation threshold that can target malware disproportionately more than benign software. We analyzed the effects of the uncertain environment by manually studying 113 software and 100 malware, and found that 92 percent malware and 10 percent benign software disrupted during execution. The results were then corroborated by an extended dataset (5,679 Linux malware samples) on a newer system. Finally, a careful inspection of the benign software crashes revealed some software bugs, highlightingChameleon's potential as a practical complementary anti-malware solution.
Ruimin Sun, Marcus Botacin, Nikolaos Sapountzis, Xiaoyong Yuan, Matt Bishop, Donald E. Porter, Xiaolin Li 0001, André Ricardo Abed Grégio, Daniela Oliveira 0001
IEEE Trans. Dependable Secur. Comput.4
2022 Learning Fast and Slow: Propedeutica for Real-Time Malware Detection
abstract
Existing malware detectors on safety-critical devices have difficulties in runtime detection due to the performance overhead. In this article, we introduce Propedeutica, a framework for efficient and effective real-time malware detection, leveraging the best of conventional machine learning (ML) and deep learning (DL) techniques. In Propedeutica, all software start executions are considered as benign and monitored by a conventional ML classifier for fast detection. If the software receives a borderline classification from the ML detector (e.g., the software is 50% likely to be benign and 50% likely to be malicious), the software will be transferred to a more accurate, yet performance demanding DL detector. To address spatial-temporal dynamics and software execution heterogeneity, we introduce a novel DL architecture (DeepMalware) for Propedeutica with multistream inputs. We evaluated Propedeutica with 9115 malware samples and 1338 benign software from various categories for the Windows OS. With a borderline interval of [30%, 70%], Propedeutica achieves an accuracy of 94.34% and a false-positive rate of 8.75%, with 41.45% of the samples moved for DeepMalwareanalysis. Even using only CPU, Propedeutica can detect malware within less than 0.1 s.
Ruimin Sun, Xiaoyong Yuan, Pan He, Qile Zhu, Aokun Chen, André Ricardo Abed Grégio, Daniela Oliveira 0001, Xiaolin Li 0001
IEEE Trans. Neural Networks Learn. Syst.2
2021 Towards Stealing Deep Neural Networks on Mobile Devices
Shashank Reddy Danda, Xiaoyong Yuan, Bo Chen 0028
SecureComm (2)2
2020 Connecting Web Event Forecasting with Anomaly Detection: A Case Study on Enterprise Web Applications Using Self-supervised Neural Networks
Xiaoyong Yuan, Lei Ding 0003, Xiaolin Li 0001, Dapeng Oliver Wu
SecureComm (1)1
2019 Generalized Batch Normalization: Towards Accelerating Deep Neural Networks
abstract
Utilizing recently introduced concepts from statistics and quantitative risk management, we present a general variant of Batch Normalization (BN) that offers accelerated convergence of Neural Network training compared to conventional BN. In general, we show that mean and standard deviation are not always the most appropriate choice for the centering and scaling procedure within the BN transformation, particularly if ReLU follows the normalization step. We present a Generalized Batch Normalization (GBN) transformation, which can utilize a variety of alternative deviation measures for scaling and statistics for centering, choices which naturally arise from the theory of generalized deviation measures and risk theory in general. When used in conjunction with the ReLU non-linearity, the underlying risk theory suggests natural, arguably optimal choices for the deviation measure and statistic. Utilizing the suggested deviation measure and statistic, we show experimentally that training is accelerated more so than with conventional BN, often with improved error rate as well. Overall, we propose a more flexible BN transformation supported by a complimentary theoretical framework that can potentially guide design choices.
Xiaoyong Yuan, Zheng Feng, Matthew Norton 0001, Xiaolin Li 0001
AAAI1
2019 Adversarial Examples: Attacks and Defenses for Deep Learning
abstract
With rapid progress and significant successes in a wide spectrum of applications, deep learning is being applied in many safety-critical environments. However, deep neural networks (DNNs) have been recently found vulnerable to well-designed input samples called adversarial examples. Adversarial perturbations are imperceptible to human but can easily fool DNNs in the testing/deploying stage. The vulnerability to adversarial examples becomes one of the major risks for applying DNNs in safety-critical environments. Therefore, attacks and defenses on adversarial examples draw great attention. In this paper, we review recent findings on adversarial examples for DNNs, summarize the methods for generating adversarial examples, and propose a taxonomy of these methods. Under the taxonomy, applications for adversarial examples are investigated. We further elaborate on countermeasures for adversarial examples. In addition, three major challenges in adversarial examples and the potential solutions are discussed.
Xiaoyong Yuan, Pan He, Qile Zhu, Xiaolin Li 0001
IEEE Trans. Neural Networks Learn. Syst.1
2017 PhD Forum: Deep Learning-Based Real-Time Malware Detection with Multi-Stage Analysis
abstract
Protecting computer systems is a critical and ongoing problem, given that real-time malware detection is hard. The state-of-the-art for defense cannot keep pace with the increasing level of sophistication of malware. The industry, for instance, relies heavily on anti-virus technology for threat, which is effective for malware with known signatures, but not sustainable given the massive amount of malware samples released daily, as well as and its inefficacy in dealing with zero-day and polymorphic/metamorphic malware (practical detection rates range from 25% to 50%). Behavior-based approaches attempt to identify malware behaviors using instruction sequences, computation trace logic, and system (or API) call sequences. These solutions have been mostly based on conventional machine learning (ML) models with hand-craft features, such as K-nearest neighbor, SVM, and decision tree algorithms. However, current solutions based on ML suffer from high false-positive rates, mainly because of (i) the complexity and diversity of current software and malware, which are hard to capture during the learning phase of thealgorithms, (ii) sub-optimal feature extraction, and (iii) limited/outdated dataset. Since malware has been continuously evolving, existing protection mechanisms do not cope well with the increasedsophistication and complexity of these attacks, especially those performed by advanced persistent threats (APT), which are multi-module, stealthy, and target- focused. Furthermore, malware campaigns are not homogeneous--malware sophistication varies depending on the target, the type of service exploited as part of the attack (e.g., Internet Banking, relationship sites), the attack spreading source (e.g., phishing, drive-by downloads), and the location of the target. The accuracy of malware classification depends on gaining sufficient context information and extracting meaningful abstraction of behaviors. In problems about detecting malicious behavior based on sequence of system calls, longer sequences likely contain more information. However, classical ML- based detectors (i.e., Random Forest, Naive Bayes) often use short windows of system calls during the decision process and may not be able to extract enough features for accurate detection in a long term window. Thus, the main drawback of such approaches is to accomplish accurate detection, since it is difficult to analyze complex and longer sequences of malicious behaviors with limited window sizes, especially when malicious and benign behaviors are interposed. In contrast, Deep Learning models are capable of analyzing longer sequences of system calls and making better decisions through higher level information extraction and semantic knowledge learning. However, Deep Learning requires more computation time to estimate the probability of detection when the model needs to be retrained incrementally, a common requirement for malware detection when new variants and samples are frequently added to the training set. The trade-off is challenging: fast and not-so-accurate (classical ML methods) versus time-consuming and accurate detection (emerging Deep Learning methods). Our proposal is to leverage the best of the two worlds with Spectrum, a practical multi-stage malware- detection system operating in collaboration with the operating system (OS).
Xiaoyong Yuan
SMARTCOMP1
2017 DeepDefense: Identifying DDoS Attack via Deep Learning
abstract
Distributed Denial of Service (DDoS) attacks grow rapidly and become one of the fatal threats to the Internet. Automatically detecting DDoS attack packets is one of the main defense mechanisms. Conventional solutions monitor network traffic and identify attack activities from legitimate network traffic based on statistical divergence. Machine learning is another method to improve identifying performance based on statistical features. However, conventional machine learning techniques are limited by the shallow representation models. In this paper, we propose a deep learning based DDoS attack detection approach (DeepDefense). Deep learning approach can automatically extract high-level features from low-level ones and gain powerful representation and inference. We design a recurrent deep neural network to learn patterns from sequences of network traffic and trace network attack activities. The experimental results demonstrate a better performance of our model compared with conventional machine learning models. We reduce the error rate from 7.517% to 2.103% compared with conventional machine learning method in the larger data set.
Xiaoyong Yuan, Chuanhuang Li, Xiaolin Li 0001
SMARTCOMP1
2015 A Competitive Penalty Model for Availability Based Cloud SLA
abstract
Availability is one of the most essential attributes of qualities of cloud services. Most popular public cloud services claim availability commitments with corresponding penalties in their SLAs. To gain the maximal profits, cloud providers should choose an optimal penalty strategy in the competitive cloud market. In this paper, we firstly survey the penalty calculation methods of cloud providers. Based on the survey, we propose a competitive penalty model and a corresponding penalty based profit maximization algorithm for cloud providers. According to the model, each cloud provider would choose the best fit penalty strategy to gain the maximal expected profit during the game procedure. The proposed model is evaluated with real data of popular cloud providers with sensitive analysis, and is valuable for cloud providers to define their penalty strategy.
Xiaoyong Yuan, Hongyan Tang, Ying Li 0012, Zhonghai Wu
CLOUD1
2015 An Analysis on Availability Commitment and Penalty in Cloud SLA
abstract
Availability is the most essential attribute of qualities of cloud services. Most popular public cloud services claim availability commitments with corresponding penalties in their SLAs. However, lack of clarity in availability commitment and penalty make it hard for consumers to understand the SLAs well and furthermore, to compare different cloud providers under different contexts, which would even become an obstacle for enterprise consumers to embrace public clouds. We present a cloud SLA availability commitment framework including availability calculation and penalty calculation services, and compare SLAs of well-known public IaaS cloud providers with investigation of their merits and defects. We also present a business model for cloud providers to find the optimal penalty degree for their SLAs, which will help in defining availability based SLA of cloud services.
Xiaoyong Yuan, Ying Li 0012, Zhonghai Wu
COMPSAC1
2014 Dependability Analysis on Open Stack IaaS Cloud: Bug Anaysis and Fault Injection
abstract
This paper proposes a comparative study of cloud dependability between two methods -- bug analysis and fault injection for assessing the impact of component failure on cloud service availability. We focus on the IaaS cloud with open source platform Open Stack. The actual bug data are analyzed to show numerical examples of dependability assessment. A fault injection tool has also been developed to create failures of components and then observe their effects on services. The comparison analysis between two methods shows that bug analysis method has richer features for analyzing but not as precise as fault injection.
Xiaoyong Yuan, Ying Li 0012, Zhonghai Wu
CloudCom1
2014 Scheduling Cloud Platform Managed Live-Migration Operations to Minimize the Makespan
Xiaoyong Yuan, Ying Li 0012, Kewei Sun
NPC1