EDBT 2026 Demo / reviewers in the wild / expert
Yanna Jiang
dblp:168/6072
· DBLP profile ↗
7ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0002-8176-6264ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Joint Trajectory Obfuscation and Pseudonym Swapping Mechanism Avoiding Extra Privacy Cost
Baihe Ma, Xu Wang 0004, Guangsheng Yu, Yanna Jiang, Suirui Zhu, Bo Liu 0001, Ying He 0011, Wei Ni 0001, Ren Ping Liu 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2026 | Client-Cooperative Split LearningabstractModel training is increasingly offered as a service for resource-constrained data owners to build customized models. Split Learning (SL) enables such services by offloading training computation under privacy constraints, and evolves towardserverlessandmulti-clientsettings where model segments are distributed across training clients. This cooperative mode assumes partial trust: data owners hide labels and data from trainer clients, while trainer clients produce verifiable training artifacts and ownership proofs. We presentCliCooper, a multi-clientcooperative SL framework tailored for cooperative model training services in heterogeneous and partially trusted environments, where one client contributes data, while others collectively act as SL trainers.CliCooperbridges the privacy and trust gaps through two new designs. First, Differential Privacy–based activation protection and secret label obfuscation safeguard data owners' privacy without degrading model performance. Second, a dynamic chained watermarking scheme cryptographically links training stages on model segments across trainers, ensuring verifiable training integrity, robust model provenance, and copyright protection. Experiments show thatCliCooperpreserves model accuracy while enhancing resilience to privacy and ownership attacks. It reduces the success rate of clustering attacks (which infer label groups from intermediate activation) to 0%, decreases inversion-reconstruction (which recovers training data) similarity from 0.50 to 0.03, and limits model-extraction–based surrogates to about 1% accuracy, comparable to random guessing. Haiyu Deng, Yanna Jiang, Guangsheng Yu, Qin Wang 0008, Xu Wang 0004, Wei Ni 0001, Shiping Chen 0001, Ren Ping Liu 0001 |
IEEE Trans. Serv. Comput. | 2 |
| 2025 | Split UnlearningabstractWe introduce Split Unlearning, a novel machine unlearning technology designed for Split Learning (SL), enabling the first-ever implementation of Sharded, Isolated, Sliced, and Aggregated (SISA) unlearning in SL frameworks. Particularly, the tight coupling between clients and the server in existing SL frameworks results in frequent bidirectional data flows and iterative training across all clients, violating the ''Isolated'' principle and making them struggle to implement SISA for independent and efficient unlearning. To address this, we propose SplitWiper with a new one-way-one-off propagation scheme, which leverages the inherently ''Sharded'' structure of SL and decouples neural signal propagation between clients and the server, enabling effective SISA unlearning even in scenarios with absent clients. We further design SplitWiper+ to enhance client label privacy, which integrates differential privacy and label expansion strategy to defend the privacy of client labels against the server and other potential adversaries. Experiments across diverse data distributions and tasks demonstrate that SplitWiper achieves 0% accuracy for unlearned labels, and 8% better accuracy for retained labels than non-SISA unlearning in SL. Moreover, the one-way-one-off propagation maintains constant overhead, reducing computational and communication costs by 99%. SplitWiper+ preserves 90% of label privacy when sharing masked labels with the server. Yanna Jiang, Guangsheng Yu, Qin Wang 0008, Xu Wang 0004, Baihe Ma, Caijun Sun, Wei Ni 0001, Ren Ping Liu 0001 |
CCS | 1 |
| 2025 | SoK: Credential-Based Trust Management in Decentralized Ledger SystemsabstractTrust management systems (TMS) are crucial for managing trust in distributed environments. The rise of decentralized systems and blockchain has sparked interest in credential-based decentralized trust management systems (DTMS). This paper bridges the gap between theory and practice through a systematic review of credential-based DTMS. We analyze existing DTMS solutions through multiple dimensions, including their architectural designs, credential mechanisms, and trust evaluation models. Our survey provides a detailed taxonomy of credential-based DTMS approaches and establishes comprehensive evaluation criteria for assessing DTMS implementations. Through extensive analysis of current systems and implementations, we identify critical challenges and promising research directions in the field. Our examination offers valuable insights for researchers and practitioners working on DTMS, particularly in areas such as access control, reputation systems, and blockchain-based trust frameworks. Yanna Jiang, Haiyu Deng, Qin Wang 0008, Guangsheng Yu, Xu Wang 0004, Yilin Sai, Shiping Chen 0001, Wei Ni 0001, Ren Ping Liu 0001 |
TrustCom | 1 |
| 2025 | Exploiting attribute correlation for reconstruction attacks on differentially private multi-attributed data
Yanna Jiang, Baihe Ma, Xu Wang 0004, Guangsheng Yu, Caijun Sun, Wei Ni 0001, Ren Ping Liu 0001 |
J. Inf. Secur. Appl. | 1 |
| 2024 | FedNIFW: Non-Interfering Fragmented Watermarking for Federated Deep Neural NetworkabstractDuring the deployment and utilization of federated models, they are susceptible to unauthorized theft or misuse. To address this issue, researchers have proposed the use of watermarking techniques to protect the Intellectual Property (IP) of the federated models. Nevertheless, traditional watermarking methods in federated learning have certain limitations. It is highly likely that different clients may embed watermarks in the same region of the model. During the aggregation of the watermarked weights, the watermarks from various clients may overlap, resulting in conflicts between the embedded watermarks. To overcome these challenges, we propose a novel method called Non-Interfering Fragmented Watermarking for Federated Models (FedNIFW). In the proposed scheme, each client node is assigned a specific segment of the neural network layer where watermarking can be applied. During training, each client is allowed to embed watermarks only within their designated segments, while other segments intended for watermarking by different clients are frozen. Experimental results demonstrate that this segmented watermarking scheme effectively prevents conflicts between client watermarks and does not significantly impact the accuracy of the federated models. These findings underscore the feasibility of the proposed watermarking scheme. Haiyu Deng, Xiaocui Dang, Yanna Jiang, Xu Wang 0004, Guangsheng Yu, Wei Ni 0001, Ren Ping Liu 0001 |
TrustCom | 3 |
| 2024 | Preventing harm to the rare in combating the malicious: A filtering-and-voting framework with adaptive aggregation in federated learningabstractThe distributed nature of Federated Learning (FL) introduces security vulnerabilities and issues related to the heterogeneous distribution of data. Traditional FL aggregation algorithms often mitigate security risks by excluding outliers, which compromises the diversity of shared information. In this paper, we introduce a novel filtering-and-voting framework that adeptly navigates the challenges posed by non-iid training data and malicious attacks on FL. The proposed framework integrates a filtering layer for defensive measures against the intrusion of malicious models and a voting layer to harness valuable contributions from diverse participants. Moreover, by employing Deep Reinforcement Learning (DRL) for dynamic aggregation weight adjustment, we ensure the optimized aggregation of participant data, enhancing the diversity of information used for aggregation and improving the performance of the global model. Experimental results demonstrate that the proposed framework presents superior accuracy over traditional and contemporary FL aggregation methods as diverse models are utilized. It also shows robust resistance against malicious poisoning attacks. Yanna Jiang, Baihe Ma, Xu Wang 0004, Guangsheng Yu, Caijun Sun, Wei Ni 0001, Ren Ping Liu 0001 |
Neurocomputing | 1 |