Jiejie Zhao

dblp:166/6128 · DBLP profile ↗
← Back
14ranked-venue papers
4as first author
12since 2021 · last 2026
0000-0001-6892-9906ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 6 · 3 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-author · 3 since 2021Systems, architecture and hardware · 3 · 3 since 2021Computer networks · 2 · 2 since 2021Security and privacy · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author
YearPublicationVenuePosition
2026 FedPDM: Representation enhanced federated learning with privacy preserving diffusion models
Fuzhen Zhuang, Yiqi Tong, Xiao Zhang 0015, Zhaojun Hu, Jiejie Zhao, Jin Dong 0004
Knowl. Based Syst.6
2026 ChainOpt: Heterogeneity-Aware Blockchain Performance Optimization for Dynamic Workloads
abstract
As reliable distributed systems, Blockchains have been widely applied in diverse domains, such as the Internet of Things (IoT). Recent studies have explored Deep Reinforcement Learning (DRL) to enhance blockchain performance. However, existing DRL-based blockchain performance optimization methods rely on implicit and idealized assumptions about node behaviors and transactional workloads, limiting their effectiveness and efficiency on the blockchain with dynamic work-loads and heterogeneous nodes. To alleviate this, we propose CHAINOPT, a novel blockchain performance optimization framework devised for optimal parameter configuration to handle dynamic workloads and heterogeneous nodes. Specifically, we first propose an interaction-aware state representation learning module to model both global system-level and local heterogeneous node feature interactions to generate better state representations. Then, a contrastive learning-enhanced workload identification module is designed to extract discriminative workload-specific state representations to improve workload identification accuracy. Finally, we design a workload-similarity guided policy reuse module to produce effective reuse weights to transfer knowledge from history policies based on workload relevance, thereby improving optimization speed and stability. Extensive experiments show the effectiveness of CHAINOPT in improving blockchain performance, achieving 185.87% higher scalability and 1492.16% stronger security with only a marginal 6.26% latency increase. Moreover, it outperforms baselines in static scenarios while maintaining considerable superiority under varying workloads.
Biqi Zhao, Yushan Zeng, Jiejie Zhao, Shan Zhang 0001, Haogang Zhu, Runhe Huang, Weifeng Lv
IEEE Trans. Computers3
2025 Harnessing Global-Local Collaborative Adversarial Perturbation for Anti-Customization
abstract
Though achieving significant success in personalized image synthesis, Latent Diffusion Models (LDMs) pose substantial social risks caused by unauthorized misuse (e.g., face theft). To counter these threats, the Anti-Customization (AC) method that exploits adversarial perturbations was proposed. Unfortunately, existing AC methods show insufficient defense ability due to the ignorance of hierarchical characteristics, i.e., global feature correlations and local facial attributes, leading to weak resistance to concept transfer and semantic theft in customization methods. To address these limitations, we are motivated to propose a Global-Local Collaborated Anti-Customization (GoodAC) framework to generate powerful adversarial perturbations by disturbing both feature correlations and facial attributes. To enhance the ability to resist concept transfer, we disrupt the spatial correlation of perceptual features that form the basis of model generation at a global level, thereby creating highly concept-transfer-resistant adversarial camouflage. To improve the ability to resist semantic theft, leveraging the fact that facial attributes are personalized, we designed a personalized and precise facial attribute distortion strategy locally, focusing the attack on the individual’s image structure to generate strong camouflage. Extensive experiments on various customization methods, including Dreambooth and LoRA, have strongly demonstrated that our GoodAC outperforms other state-of-the-art approaches by large margins, e.g., over 50% improvements on ISM.1
Jiakai Wang, Haojie Hao, Haotong Qin, Jiejie Zhao, Xianglong Liu 0001
CVPR5
2025 Partitioning or Not? Hierarchical Task Offloading Optimization in Collaborative Satellite Edge Computing Networks
abstract
As a promising paradigm, Satellite Edge Computing (SEC) enables new opportunities for facilitating intelligent processing onboard, crucial for the timely execution of mission-critical tasks. These tasks typically involve high data capture rates and rely on compute-intensive Deep Neural Network (DNN) models. However, a single satellite struggles to handle these tasks promptly due to its limited computational capabilities. Thus, effective collaboration within the SEC network is urgently needed to adapt to diverse capture rates, optimize resource utilization, and ensure real-time responses. Motivated by the fact that partitioning a DNN model can accelerate task inference and make better use of idle resources by simultaneous sub-task execution and reduced transmitted data, we propose HiO2, a hierarchical task offloading framework that maximizes system throughput by effective collaboration among satellites and ground stations to process the partitioned sub-tasks. This highlights the challenge of designing effective task partitioning and offloading strategies in dynamic, resource-constrained networks. HiO2 addresses this challenge with two key methods. First, it adopts a distributed swarm-level task offloading strategy that assigns tasks to swarms based on their optimal quantity. Second, HiO2 introduces a distributed node-level partitioning and offloading scheme, which dynamically identifies efficient cut-points according to workload and network dynamics, then offloads sub-tasks by collaboration among nodes in each swarm. Extensive data-driven evaluations demonstrate that, compared to the state-of-the-art baselines, HiO2 improves throughput to 1.19×, reduces average task completion time to 69.7%, and consistently meets task deadlines.
Jun Liu 0063, Xiaolin Jia, Jiejie Zhao, Han Qiu 0001
ICDCS5
2025 BadMDA: Towards Backdoor Injection during Domain Adaptation to Collapse Multi-Agent Perception
abstract
Domain adaptation, which bridges the domain gap between heterogeneous agents, has emerged as an effective solution to improve the perception capabilities of multi-agent systems. However, it may introduce backdoor vulnerabilities, as adversaries could exploit the collaborative process to propagate malicious features across agents, yet these threats remain largely unexplored. In this paper, we take the first step to study the backdoor attacks in this safety-critical scenario, with the 3D object detection task as the representative case. To this end, we propose BadMDA, the first backdoor attack tailored for the domain adaptation process to collapse multi-agent perception. Specifically, we first propose a gradient-suppression trigger optimization module to mitigate trigger distortion during the domain adaptation. By utilizing the optimizable additive triggers and minimizing gradient variations of triggered features induced by the domain adaptation, we reduce the transformation magnitude of triggered features, thereby maintaining the trigger effectiveness. Then, we propose a dual-gradient guided poisoning module to achieve clean-label poisoning in 3D object detection tasks. This module aligns training gradients with poisoned ones to learn malicious features, while enforcing the orthogonality between training and benign gradients. Consequently, the learned malicious features mislead the victim's finetuning updates, causing detection failures upon receiving triggered features while only slightly affecting the victim agent's model utility. Extensive experiments on various dominant domain adaptation methods show the superior attacking effectiveness and universality of BadMDA, underscoring the need for a more advanced defense.
Bowen Du 0001, Jiejie Zhao, Hanyang Xia, Jiakai Wang
ACM Multimedia3
2025 Dual-mask: Progressively sparse multi-task architecture learning
abstract
Multi-task architecture learning has achieved significant success by learning optimal sharing architectures for different tasks. However, previous works to learn branched architectures for different tasks can sometimes lead to unsatisfying multi-task performance, as not all detailed branches are relevant to a specific task. Task-relevant architectures can be sparse, including only partial channels or layers in the entire architecture (i.e., a sub-network). In addition, most previous works rely on a heuristic architecture selection procedure that could not support continuous architecture optimization. To this end, in this paper, we propose dual-mask , a progressively sparse multi-task architecture learning method. Starting with a task-free architecture, it identifies the informative features along two-level, channels and layers, for each task, while suppressing conflicting or noisy parts in a differentiable manner, so that better task-specific sub-networks are captured. Specifically, the channel and layer selection modules produce respective hybrid binary and real value masks, designed to pick salient channels and layers for each task, respectively. To jointly optimize masks with model parameters, we propose an importance-guided relaxation method for solving the stochastic binary optimization problem , after which the interference or noise parts can be pruned by masks. Additionally, a progressive training strategy with continuation is provided that gradually sparsity the task-specific sub-networks. Experiments show that dual-mask achieves superior performance than SOTA multi-task methods.
Jiejie Zhao, Tongyu Zhu, Leilei Sun, Bowen Du 0001, Lei Huang 0015
Pattern Recognit.1
2025 Dual Dependency Disentangling for Defending Model Inversion Attacks in Split Federated Learning
abstract
Recent studies have revealed that Split Federated Learning (SFL) is vulnerable to Model Inversion (MI) attacks, where the attacker can reconstruct clients’ raw data by exploiting collected features. Though achieving results, current defenses are unsatisfactory due to the limited ability to suppress the sensitive information while preserving task-conducive information within features. Since such limited ability can be attributed to insufficient disentanglement of data-feature and feature-task dependencies, we propose a Dual Dependency Disentangling framework for SFL (D3SFL) to strengthen defense ability against MI attacks while maintaining the utility. Specifically, we first propose a variable-structure data-feature dependency decoupling module, which produces privacy-preserving features by learning input-specific sub-networks, therefore enhancing the disentanglement of data-feature dependencies to hide sensitive information. Then, we propose a stochastic feature-task dependency separating module that adopts sparse binary masks to preserve the target-task-critical features and reduce sensitive information, resulting in effective disentanglement of feature-task dependencies for lower privacy leakage and better utility maintenance. Extensive experiments on image-classification datasets (CIFAR-100 and FaceScrub) and the time-series dataset (METR-LA) show that D3SFL outperforms the comparisons, achieving remarkable defense ability against MI attacks (with up to 54×, 17×, and 18× reconstruction MSE on average, respectively) while maintaining better utility (with only 0.13% and 0.06% Accuracy drops over the standard SFL on CIFAR-100 and FaceScrub, respectively, and only a 0.03 MAE increase on METR-LA over CNFGNN). Our code is available at https://github.com/Shawn-CT/D3SFL.
Jiakai Wang, Jiejie Zhao, Bowen Du 0001, Xiaoshan Bai, Zheng Lin 0005, Xianglong Liu 0001
IEEE Trans. Inf. Forensics Secur.3
2024 NAPGuard: Towards Detecting Naturalistic Adversarial Patches
abstract
Recently, the emergence of naturalistic adversarial patch (NAP), which possesses a deceptive appearance and various representations, underscores the necessity of developing robust detection strategies. However, existing approaches fail to differentiate the deep-seated natures in adversarial patches, i.e., aggressiveness and naturalness, leading to unsatisfactory precision and generalization against NAPs. To tackle this issue, we propose NAP-Guard to provide strong detection capability against NAPs via the elaborated critical feature modulation framework. For improving precision, we propose the aggressive feature aligned learning to enhance the model's capability in capturing accurate aggressive patterns. Considering the challenge of inaccurate model learning caused by deceptive appearance, we align the aggressive features by the proposed pattern alignment loss during training. Since the model could learn more accurate aggressive patterns, it is able to detect deceptive patches more precisely. To enhance generalization, we design the natural feature suppressed inference to universally mitigate the disturbance from different NAPs. Since various representations arise in diverse disturbing forms to hinder generalization, we suppress the natural features in a unified approach via the feature shield module. Therefore, the models could recognize NAPs within less disturbance and activate the generalized detection ability. Extensive experiments show that our method surpasses state-of-the-art methods by large margins in detecting NAPs (improve 60.24% [email protected] on average).11Our code is available at https://github.com/wsynuiag/NAPGaurd.
Siyang Wu, Jiakai Wang, Jiejie Zhao, Yazhe Wang, Xianglong Liu 0001
CVPR3
2024 Hermes: Fast Semi-Asynchronous Federated Learning in LEO Constellations
abstract
Recent advances in space technology have prompted the emergence of numerous Low Earth Orbit (LEO) satellites, producing mega-constellations that can pro-vide global network coverage and collect massive distributed data, bringing new opportunities for intelligence applications to remote areas. To achieve such goals, Federated Learning (FL) is a promising solution to train the global model over LEO satellites and ground station networks while reducing the high communication cost caused by data exchanging. However, the widely used synchronous FL may face intol-erable waiting time due to the intermittent connectivity. In addition, existing asynchronous FL suffers from model staleness attributed to asynchronous training, which may decrease the performance of the global model. To this end, we propose a novel semi-asynchronous federated learning frame-work in LEO constellations, namely Hermes, that includes a latency-aware model delivery mechanism and an adaptive semi-asynchronous aggregation algorithm to improve the convergence rate and generality of the global model. Our simulation results show that Hermes outperforms existing LEO-based FL methods across various constellation scales, achieving higher model accuracy with average speedups of 3.29x and 7.26x for MNIST and EMNIST, respectively.
Jiejie Zhao, Guanjun Jiang
WCNC3
2024 ShieldTSE: A Privacy-Enhanced Split Federated Learning Framework for Traffic State Estimation in IoV
abstract
Traffic state estimation (TSE) is attracting significant attention due to its importance to the Internet of Vehicles (IoV) for various applications, such as vehicle path planning. In classic IoV, the real-time traffic data collected by road side units requires transferring to the cloud server for processing. Such a centralized manner may raise privacy leakage issues. Split federated learning (SFL) has emerged as one of the prevalent methods to solve these issues. However, recent studies have shown that the existing SFL frameworks are vulnerable to the model inversion (MI) attacks, leading to private raw data leakage. To this end, in this article, we propose ShieldTSE, a privacy-enhanced SFL framework for TSE in IoV. To protect privacy and maintain utility, a variational encoder-decoder-based privacy-preserving feature extraction module with adversarial learning is first proposed to generate better privacy-preserved intermediate activations with a lower-dimensional feature space. Then, a hard attention-based feature selection module is designed to select partial yet crucial features from the intermediate activations by removing redundant sensitive features to further reduce the data privacy leakage. Experimental results demonstrate that ShieldTSE achieves superior privacy-preserving ability when against training-based and optimization-based MI attacks with an average reconstruction mean-square error (MSE) improvement of$18\times $and$35\times $on METR-LA and PEMS-BAY compared to the baseline without the privacy-preserving strategy, respectively. ShieldTSE also successfully maintains better model utility compared to the privacy protection baselines.
Xiaoshan Bai, Jiejie Zhao, Bowen Du 0001, Shan Zhang 0001
IEEE Internet Things J.3
2023 Decentralized Subgraph Learning for Spatial-Temporal Data Modeling
abstract
Spatial-temporal data modeling has attracted attention due to the massive spatial-temporal data acquired by sensors, as well as its importance in the real world. Most existing methods require transferring a huge volume of data from different parties to a central server, which is impractical due to conflicts of benefit and privacy concerns. A party only possesses a part of the entire spatial-temporal data (i.e., a subgraph), and subgraphs are isolated among parties. Federated Learning (FL) is an emerging framework for training models without sharing data, but it still has a high vulnerability when the central server fails. Besides, naively fusing models in most FL may have a negative impact on performance because of insufficient spatial relations among subgraphs and discrepant spatial-temporal patterns among subgraphs. To this end, we propose a Decentralized Subgraph Learning framework for Spatial-Temporal data modeling, namely DeSL-ST, which can efficiently handle the distributed subgraphs without the need of the central server. Specifically, DeSL-ST uses a cross-subgraph spatial relation learning module to tackle the issue of missing spatial relations between subgraphs. Then, a sparse transfer structure learning module is proposed to produce better-personalized models that are beneficial for each subgraph. Experiments on two traffic forecasting tasks demonstrate that DeSL-ST achieves state-of-the-art performance with lower peer-to-peer communication cost.
Jiejie Zhao, Bowen Du 0001, Chenzhi He, Yanbo Ma, Runhe Huang
ICPADS3
2021 Deep multi-task learning with relational attention for business success prediction
Jiejie Zhao, Bowen Du 0001, Leilei Sun, Weifeng Lv, Yanchi Liu, Hui Xiong 0001
Pattern Recognit.1
2019 TA-CFNet: A New CFNet with Target Aware for Object Tracking
Jiejie Zhao
ICIG (1)1
2019 Multiple Relational Attention Network for Multi-task Learning
abstract
Multi-task learning is a successful machine learning framework which improves the performance of prediction models by leveraging knowledge among tasks, e.g., the relationships between different tasks. Most of existing multi-task learning methods focus on guiding learning process by predefined task relationships. In fact, these methods have not fully exploited the associated relationships during the learning process. On the one hand, replacing predefined task relationships by adaptively learned ones may result in higher prediction accuracy as it can avoid the risk of misguiding caused by improperly predefined relationships. On the other hand, apart from the task relationships, feature-task dependence and feature-feature interactions could also be employed to guide the learning process. Along this line, we propose aMultiple Relational Attention Network (MRAN) framework for multi-task learning, in which three types of relationships are considered. Correspondingly, MRAN consists of three attention-based relationship learning modules: 1) a task-task relationship learning module which captures the relationships among tasks automatically and controls the positive and negative knowledge transfer adaptively; 2) a feature-feature interaction learning module that handles the complicated interactions among features; 3) a task-feature dependence learning module, which can associate the related features with target tasks separately. To evaluate the effectiveness of the proposed MARN, experiments are conducted on two public datasets and a real-world dataset crawled from a review hosting site. Experimental results demonstrate the superiority of our method over both classical and the state-of-the-art multi-task learning methods.
Jiejie Zhao, Bowen Du 0001, Leilei Sun, Fuzhen Zhuang, Weifeng Lv, Hui Xiong 0001
KDD1