EDBT 2026 Demo / reviewers in the wild / expert
Tianxi Ji
dblp:178/5180
· DBLP profile ↗
21ranked-venue papers
10as first author
16since 2021 · last 2026
0000-0002-9083-5452ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 5 first-author · 8 since 2021Artificial intelligence and machine learning · 5 · 1 first-author · 2 since 2021Computer networks · 5 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PROVGEN: A Privacy-Preserving Approach for Outcome Validation in Genomic ResearchabstractAs genomic research has grown increasingly popular in recent years, dataset sharing has remained limited due to privacy concerns. This limitation hinders the reproducibility and validation of research outcomes, both of which are essential for identifying computational errors during the research process. In this paper, we introduce PROVGEN, a privacy-preserving method for sharing genomic datasets that facilitates reproducibility and outcome validation in genome-wide association studies (GWAS). Our approach encodes genomic data into binary space and applies a two-stage process. First, we generate a differentially private version of the dataset using an XOR-based mechanism tailored to biological characteristics. Second, we restore data utility by adjusting the Minor Allele Frequency (MAF) values in the noisy dataset to align with public MAFs using optimal transport. Finally, we convert the processed binary data back into its genomic representation and publish the resulting dataset. We evaluate PROVGEN on three real-world genomic datasets and compare it with local differential privacy and three synthesis-based methods. Our results show that PROVGEN overall outperforms existing approaches in detecting GWAS outcome errors, preserving data fidelity, and resisting membership inference attacks (MIAs). By adopting our method, genomic researchers will be inclined to share differentially private datasets while maintaining high data quality for reproducibility of their findings. Yuzhou Jiang, Tianxi Ji, Erman Ayday |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | FedLTF: Linear Probing Teaches Fine-tuning to Mitigate Noisy Labels in Federated Learning
Shaojie Zhan, Lixing Yu, Hanqi Chen 0001, Tianxi Ji |
ACML | 4 |
| 2024 | Less is More: Revisiting the Gaussian Mechanism for Differential Privacy
Tianxi Ji, Pan Li 0001 |
USENIX Security Symposium | 1 |
| 2024 | Privacy-Preserving Fingerprinting Against Collusion and Correlation Threats in Genomic DataabstractSharing genomic databases is critical to the collaborative research in computational biology. A shared database is more informative than specific genome-wide association studies (GWAS) statistics as it enables "do-it-yourself" calculations. Genomic databases involve intellectual efforts from the curator and sensitive information of participants, thus in the course of data sharing, the curator (database owner) should be able to prevent unauthorized redistributions and protect individuals' genomic data privacy. As it becomes increasingly common for a single database be shared with multiple recipients, the shared genomic database should also be robust against collusion attack, where multiple malicious recipients combine their individual copies to forge a pirated one with the hope that none of them can be traced back. The strong correlation among genomic entries also make the shared database vulnerable to attacks that leverage the public correlation models. In this paper, we assess the robustness of shared genomic database under both collusion and correlation threats. To this end, we first develop a novel genomic database fingerprinting scheme, called Gen-Scope. It achieves both copyright protection (by enabling traceability) and privacy preservation (via local differential privacy) for the shared genomic databases. To defend against collusion attacks, we augment Gen-Scope with a powerful traitor tracing technique, i.e., the Tardos codes. Via experiments using a real-world genomic database, we show that Gen-Scope achieves strong fingerprint robustness, e.g., the fingerprint cannot be compromised even if the attacker changes 45% of the entries in its received fingerprinted copy and colluders will be detected with high probability. Additionally, Gen-Scope outperforms the considered baseline methods. Under the same privacy and copyright guarantees, the accuracy of the fingerprinted genomic database obtained by Gen-Scope is around 10% higher than that achieved by the baseline, and in terms of preservations of GWAS statistics, the consistency of variant-phenotype associations can be about 20% higher. Notably, we also empirically show that Gen-Scope can identify at least one of the colluders even if malicious receipts collude after independent correlation attacks. Tianxi Ji, Erman Ayday, Emre Yilmaz 0002, Pan Li 0001 |
Proc. Priv. Enhancing Technol. | 1 |
| 2024 | Efficient Federated Learning With Channel Status Awareness and Devices' Personal TouchabstractFederated learning (FL) is a widely used distributed learning framework. However, constrained wireless environment and intrinsically heterogeneous data across devices can hinder the FL framework being practical. In this paper, we propose a communication-efficient FL framework that helps boost the training process by considering the transmission power of each device and the local models' personalized training. In each round of training, we select the participating devices that can minimize the upper bound of the convergence rate plus the corresponding communication overhead while subjecting to the transmit power constraint. Besides, each device update a personalized and sparse model that only consumes limited computation resources. We validate our proposed FL framework on various dataset, and experiment results show that our framework speeds up the training process by taking$\sim$40% less time than the existing frameworks. Also, the communication time can be significantly decreased by employing our framework, e.g., we achieve as high as a 42.7% increase in test accuracy and save up to 74.3$\%$in the communication cost compared with FedAvg. Lixing Yu, Tianxi Ji |
IEEE Trans. Mob. Comput. | 2 |
| 2023 | Continuous Authentication Using Human-Induced Electric PotentialabstractMost terminal devices authenticate users only once at the time of initial login, leaving the terminal unprotected during an active session when the original user leaves it unattended. To address this issue, continuous authentication has been proposed by automatically locking the terminal after a period of inactivity. However, it does not fully eliminate the risk of unauthorized access before the session expires. Recent research has also investigated the feasibility of using physiological and behavioral patterns as biometrics. This study presents a novel two-factor continuous authentication that explores a new form of signal called human-induced electric potential captured by wearables in contact with the user’s body. By analyzing this signal, we can determine the time of user-terminal interactions and compare it with information recorded by the terminal’s OS. If the original user remains on the same terminal, the two-source readings would match. Additionally, the proposed scheme includes an extra layer of protection by extracting terminal’s physical fingerprints from the human-induced electric potential to defend against advanced mimicry attacks. To test the effectiveness of our design, a low-cost wearable prototype is developed. Through extensive experiments, it is found that the proposed scheme has a low error rate of 2.3%, with minimal computational and energy requirements. Srinivasan Murali, Wenqiang Jin, Vighnesh Sivaraman, Huadi Zhu, Tianxi Ji, Pan Li 0001, Ming Li 0006 |
ACSAC | 5 |
| 2023 | Privacy-Preserving Database Fingerprinting
Tianxi Ji, Erman Ayday, Emre Yilmaz 0002, Ming Li 0006, Pan Li 0001 |
NDSS | 1 |
| 2023 | Towards Robust Fingerprinting of Relational Databases by Mitigating Correlation AttacksabstractDatabase fingerprinting is widely adopted to prevent unauthorized data sharing and identify source of data leakages. Although existing schemes are robust against common attacks, their robustness degrades significantly if attackers utilize inherent correlations among database entries. In this paper, we demonstrate the vulnerability of existing schemes by identifying different correlation attacks: column-wise correlation attack, row-wise correlation attack, and their integration. We provide robust fingerprinting against these attacks by developing mitigation techniques, which can work as post-processing steps for any off-the-shelf database fingerprinting schemes and preserve the utility of databases. We investigate the impact of correlation attacks and the performance of mitigation techniques using a real-world database. Our results show (i) high success rates of correlation attacks against existing fingerprinting schemes (e.g., integrated correlation attack can distort 64.8% fingerprint bits by just modifying 14.2% entries in a fingerprinted database), and (ii) high robustness of mitigation techniques (e.g., after mitigation, integrated correlation attack can only distort 3% fingerprint bits). Additionally, the mitigation techniques effectively alleviate correlation attacks even if (i) attackers have access to correlation models directly computed from the original database, while the database owner uses inaccurate correlation models, (ii) or attackers utilizes higher order of correlations than the database owner. Tianxi Ji, Erman Ayday, Emre Yilmaz 0002, Pan Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Genomic Data Sharing under Dependent Local Differential Privacyabstract)-dependent local differential privacy (LDP) for privacy-preserving sharing of correlated data and propose a genomic data sharing mechanism under this privacy definition. We first show that the original definition of LDP is not suitable for genomic data sharing, and then we propose a new mechanism to share genomic data. The proposed mechanism considers the correlations in data during data sharing, eliminates statistically unlikely data values beforehand, and adjusts the probability distributions for each shared data point accordingly. By doing so, we show that we can avoid an attacker from inferring the correct values of the shared data points by utilizing the correlations in the data. By adjusting the probability distributions of the shared states of each data point, we also improve the utility of shared data for the data collector. Furthermore, we develop a greedy algorithm that strategically identifies the processing order of the shared data points with the aim of maximizing the utility of the shared data. Our evaluation results on a real-life genomic dataset show the superiority of the proposed mechanism compared to the randomized response mechanism (a widely used technique to achieve LDP). Emre Yilmaz 0002, Tianxi Ji, Erman Ayday, Pan Li 0001 |
CODASPY | 2 |
| 2022 | Robust fingerprinting of genomic databasesabstractMOTIVATION: Database fingerprinting has been widely used to discourage unauthorized redistribution of data by providing means to identify the source of data leakages. However, there is no fingerprinting scheme aiming at achieving liability guarantees when sharing genomic databases. Thus, we are motivated to fill in this gap by devising a vanilla fingerprinting scheme specifically for genomic databases. Moreover, since malicious genomic database recipients may compromise the embedded fingerprint (distort the steganographic marks, i.e. the embedded fingerprint bit-string) by launching effective correlation attacks, which leverage the intrinsic correlations among genomic data (e.g. Mendel's law and linkage disequilibrium), we also augment the vanilla scheme by developing mitigation techniques to achieve robust fingerprinting of genomic databases against correlation attacks. RESULTS: Via experiments using a real-world genomic database, we first show that correlation attacks against fingerprinting schemes for genomic databases are very powerful. In particular, the correlation attacks can distort more than half of the fingerprint bits by causing a small utility loss (e.g. database accuracy and consistency of SNP-phenotype associations measured via P-values). Next, we experimentally show that the correlation attacks can be effectively mitigated by our proposed mitigation techniques. We validate that the attacker can hardly compromise a large portion of the fingerprint bits even if it pays a higher cost in terms of degradation of the database utility. For example, with around 24% loss in accuracy and 20% loss in the consistency of SNP-phenotype associations, the attacker can only distort about 30% fingerprint bits, which is insufficient for it to avoid being accused. We also show that the proposed mitigation techniques also preserve the utility of the shared genomic databases, e.g. the mitigation techniques only lead to around 3% loss in accuracy. AVAILABILITY AND IMPLEMENTATION: https://github.com/xiutianxi/robust-genomic-fp-github. Tianxi Ji, Erman Ayday, Emre Yilmaz 0002, Pan Li 0001 |
Bioinform. | 1 |
| 2022 | Energy-Efficient Computation Offloading in Mobile Edge Computing Systems With UncertaintiesabstractComputation offloading is indispensable for mobile edge computing (MEC). It uses edge resources to enable intensive computations and save energy for resource-constrained devices. Existing works generally impose strong assumptions on radio channels and network queue sizes. However, practical MEC systems are subject to various uncertainties rendering these assumptions impractical. In this paper, we investigate the energy-efficient computation offloading problem by relaxing those common assumptions and considering intrinsic uncertainties in the network. Specifically, we minimize the worst-case expected energy consumption of a local device when executing a time-critical application modeled as a directed acyclic graph. We employ the extreme value theory to bound the occurrence probability of uncertain events. To solve the formulated problem, we develop an$\epsilon $-bounded approximation algorithm based on column generation. The proposed algorithm can efficiently identify a feasible solution that is less than$(1+\epsilon)$of the optimal one. We implement the proposed scheme on an Android smartphone and conduct extensive experiments using a real-world application. Experiment results corroborate that it will lead to lower energy consumption for the client device by considering the intrinsic uncertainties during computation offloading. The proposed computation offloading scheme also significantly outperforms other schemes in terms of energy saving. Tianxi Ji, Changqing Luo, Lixing Yu, Qianlong Wang 0003, Siheng Chen, Arun Thapa, Pan Li 0001 |
IEEE Trans. Wirel. Commun. | 1 |
| 2021 | Resisting Distributed Backdoor Attacks in Federated Learning: A Dynamic Norm Clipping ApproachabstractWith the advance in artificial intelligence and high-dimensional data analysis, federated learning (FL) has emerged to allow distributed data providers to collaboratively learn without direct access to local sensitive data. However, limiting access to individual provider’s data inevitably incurs security issues. For instance, backdoor attacks, one of the most popular data poisoning attacks in FL, severely threaten the integrity and utility of the FL system. In particular, backdoor attacks launched by multiple collusive attackers, i.e., distributed backdoor attacks, can achieve high attack success rates and are hard to detect. Existing defensive approaches, like model inspection or model sanitization, often require to access a portion of local training data, which renders them inapplicable to the FL scenarios. Recently, the norm clipping approach is developed to effectively defend against distributed backdoor attacks in FL, which does not rely on local training data. However, we discover that adversaries can still bypass this defense scheme through robust training due to its unchanged norm clipping threshold. In this paper, we propose a novel defense scheme to resist distributed backdoor attacks in FL. Particularly, we first identify that the main reason for the failure of the norm clipping scheme is its fixed threshold in the training process, which cannot capture the dynamic nature of benign local updates during the global model’s convergence. Motivated by it, we devise a novel defense mechanism to dynamically adjust the norm clipping threshold of local updates. Moreover, we provide the convergence analysis of our defense scheme. By evaluating it on four non-IID public datasets, we observe that our defense scheme effectively can resist distributed backdoor attacks and ensure the global model’s convergence. Noticeably, our scheme reduces the attack success rates by 84.23% on average compared with existing defense schemes. Yifan Guo 0001, Qianlong Wang 0003, Tianxi Ji, Xufei Wang, Pan Li 0001 |
IEEE BigData | 3 |
| 2021 | Weak Signal Detection in 5G+ Systems: A Distributed Deep Learning FrameworkabstractInternet connected mobile devices in 5G and beyond (simply 5G+) systems are penetrating all aspects of people's daily life, transforming the way we conduct business and live. However, this rising trend has also posed unprecedented traffic burden on existing telecommunication infrastructure including cellular systems, consistently causing network congestion. Although additional spectrum resources have been allocated, exponentially increasing traffic tends to always outpace the added capacity. In order to increase the data rate and reduce the latency, 5G+ systems have heavily relied on hyperdensification and higher frequency bands, resulting in dramatically increased interference temperature, and consequently significantly more weak signals (i.e., signals with low Signal-to-Noise-plus-Interference (SINR) ratio). With traditional detection mechanisms, a large number of weak signals will not be detected, and hence be wasted, leading to poor throughput in 5G+ systems. Yifan Guo 0001, Lixing Yu, Qianlong Wang 0003, Tianxi Ji, Yuguang Fang, Jin Wei-Kocsis, Pan Li 0001 |
MobiHoc | 4 |
| 2021 | The Curse of Correlations for Robust Fingerprinting of Relational DatabasesabstractDatabase fingerprinting have been widely adopted to prevent unauthorized sharing of data and identify the source of data leakages. Although existing schemes are robust against common attacks, like random bit flipping and subset attack, their robustness degrades significantly if attackers utilize the inherent correlations among database entries. In this paper, we first demonstrate the vulnerability of existing database fingerprinting schemes by identifying different correlation attacks: column-wise correlation attack, row-wise correlation attack, and the integration of them. To provide robust fingerprinting against the identified correlation attacks, we then develop mitigation techniques, which can work as post-processing steps for any off-the-shelf database fingerprinting schemes. The proposed mitigation techniques also preserve the utility of the fingerprinted database considering different utility metrics. We empirically investigate the impact of the identified correlation attacks and the performance of mitigation techniques using real-world relational databases. Our results show (i) high success rates of the identified correlation attacks against existing fingerprinting schemes (e.g., the integrated correlation attack can distort 64.8% fingerprint bits by just modifying 14.2% entries in a fingerprinted database), and (ii) high robustness of the proposed mitigation techniques (e.g., with the mitigation techniques, the integrated correlation attack can only distort 3% fingerprint bits). Furthermore, we show that the proposed mitigation techniques effectively alleviate correlation attacks even if the attacker has access to the correlation models that are directly calculated from the database. Tianxi Ji, Emre Yilmaz 0002, Erman Ayday, Pan Li 0001 |
RAID | 1 |
| 2021 | Toward Combatting COVID-19: A Risk Assessment SystemabstractThe coronavirus disease 2019 (COVID-19) has rapidly become a significant public health emergency all over the world since it was first identified in Wuhan, China, in December 2019. Until today, massive disease-related data have been collected, both manually and through the Internet of Medical Things (IoMT), which can be potentially used to analyze the spread of the disease. On the other hand, with the help of IoMT, the analysis results of the current status of COVID-19 can be delivered to people in real time to enable situational awareness, which may help mitigate the disease spread in communities. However, current accessible data on COVID-19 are mostly at a macrolevel, such as for each state, county, or metropolitan area. For fine-grained areas, such as for each city, community, or geographical coordinate, COVID-19 data are usually not available, which prevents us from obtaining information on the disease spread in closer neighborhoods around us. To address this problem, in this article, we propose a two-level risk assessment system. In particular, we define a "risk index." Then, we develop a risk assessment model, called MK-DNN, by taking advantage of the multikernel density estimation (MKDE) and deep neural network (DNN). We train MK-DNN at the macrolevel (for each metro area), which subsequently enables us to obtain the risk indices at the microlevel (for each geographic coordinate). Moreover, a heuristic validation method is further designed to help validate the obtained microlevel risk indices. Simulations conducted on real-world data demonstrate the accuracy and validity of our proposed risk assessment system. Qianlong Wang 0003, Yifan Guo 0001, Tianxi Ji, Xufei Wang, Bingfang Hu, Pan Li 0001 |
IEEE Internet Things J. | 3 |
| 2021 | Differentially Private Binary- and Matrix-Valued Data Query: An XOR MechanismabstractDifferential privacy has been widely adopted to release continuous- and scalar-valued information on a database without compromising the privacy of individual data records in it. The problem of querying binary- and matrix-valued information on a database in a differentially private manner has rarely been studied. However, binary- and matrix-valued data are ubiquitous in real-world applications, whose privacy concerns may arise under a variety of circumstances. In this paper, we devise an exclusive or (XOR) mechanism that perturbs binary- and matrix-valued query result by conducting an XOR operation on the query result with calibrated noises attributed to a matrix-valued Bernoulli distribution. We first rigorously analyze the privacy and utility guarantee of the proposed XOR mechanism. Then, to generate the parameters in the matrix-valued Bernoulli distribution, we develop a heuristic approach to minimize the expected square query error rate under ϵ -differential privacy constraint. Additionally, to address the intractability of calculating the probability density function (PDF) of this distribution and efficiently generate samples from it, we adapt an Exact Hamiltonian Monte Carlo based sampling scheme. Finally, we experimentally demonstrate the efficacy of the XOR mechanism by considering binary data classification and social network analysis, all in a differentially private manner. Experiment results show that the XOR mechanism notably outperforms other state-of-the-art differentially private methods in terms of utility (such as classification accuracy and F 1 score), and even achieves comparable utility to the non-private mechanisms. Tianxi Ji, Pan Li 0001, Emre Yilmaz 0002, Erman Ayday, Yanfang Ye 0001, Jinyuan Sun |
Proc. VLDB Endow. | 1 |
| 2020 | AI at the Edge: Blockchain-Empowered Secure Multiparty Learning With Heterogeneous ModelsabstractEdge computing, an emerging computing paradigm pushing data computing and storing to network edges, enables many applications that require high computing complexity, scalability, and security. In the big data era, one of the most critical applications is multiparty learning or federated learning, which allows different parties to collaborate with each other to obtain better learning models without sharing their own data. However, there are several main concerns about the current multiparty learning systems. First, most existing systems are distributed and need a central server to coordinate the learning process. However, such a central server can easily become a single point of failure and may not be trustworthy. Second, although quite a few schemes have been proposed to study Byzantine attacks, a very common and challenging kind of attack in distributed systems, they generally consider the scenario of learning a global model. However, in fact, all parties in multiparty learning usually have their own local models. The learning methods and security issues, in this case, are not fully explored. In this article, we propose a novel blockchain-empowered decentralized secure multiparty learning system with heterogeneous local models called BEMA. Particularly, we consider two types of Byzantine attacks, and carefully design “off-chain sample mining” and “on-chain mining ” schemes to protect the security of the proposed system. We theoretically prove the system performance bound and resilience under Byzantine attacks. The simulation results show that the proposed system obtains comparable performance with that of conventional distributed systems, and bounded performance in the case of Byzantine attacks. Qianlong Wang 0003, Yifan Guo 0001, Xufei Wang, Tianxi Ji, Lixing Yu, Pan Li 0001 |
IEEE Internet Things J. | 4 |
| 2020 | Community Detection in Online Social Networks: A Differentially Private and Parsimonious ApproachabstractCommunity detection is an effective approach to unveil relationships among individuals in online social networks. In the literature, quite a few algorithms have been proposed to conduct community detection by exploiting the topology of social networks and the attributes of social actors. In practice, community detection is usually conducted by third parties, such as advertisement companies and hospitals, with access to social networks for different purposes, which can easily lead to a privacy breach. In this paper, we investigate community detection in social networks aiming to protect the privacy of both the network topology and the users' attributes. We show that with additional prior knowledge, community detection can be performed by querying the information of only a fraction of instead of the entire population. In particular, we first propose a new scheme called differentially private community detection (DPCD). DPCD detects communities in social networks via a probabilistic generative model, which can be decomposed into subproblems solved by individual users. The private social relationships and attributes of each user are protected by objective perturbation with differential privacy guarantees. Then, we propose a parsimonious node affiliation recovery (NAR) algorithm, which is also differentially private, to unveil the community affiliation information of the whole population based on that of the limited number of queried individuals by solving a sparse optimization problem. Through both theoretical analysis and experimental validation using synthetic and real-world social networks, we demonstrate that the proposed DPCD scheme detects social communities under the modest privacy budget. In addition, we show the effectiveness of NAR to perform community detection by querying a limited number of individuals in social networks. Tianxi Ji, Changqing Luo, Yifan Guo 0001, Qianlong Wang 0003, Lixing Yu, Pan Li 0001 |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2019 | Differentially Private Community Detection in Attributed Social NetworksabstractCommunity detection is an effective approach to unveil social dynamics among individuals in social networks. In the literature, quite a few algorithms have been proposed to conduct community detection by exploiting the topology of social networks and the attributes of social actors. In practice, community detection is usually conducted by third parties like advertisement companies, hospitals, with access to social networks for different purposes, which can easily lead to privacy breaches. In this paper, we investigate community detection in social networks aiming to protect the privacy of both the network topologies and the users’ attributes. In particular, we propose a new scheme called differentially private community detection (DPCD). DPCD detects communities in social networks via a probabilistic generative model, which can be decomposed into subproblems solved by individual users. The private social relationships and attributes of each user are protected by objective perturbation with differential privacy guarantees. Through both theoretical analysis and experimental validation using synthetic and real world social networks, we demonstrate that the proposed DPCD scheme detects social communities under modest privacy budget. Tianxi Ji, Changqing Luo, Yifan Guo 0001, Jinlong Ji, Weixian Liao, Pan Li 0001 |
ACML | 1 |
| 2019 | Quantized Adversarial Training: An Iterative Quantized Local Search ApproachabstractStudies find that deep learning models are vulnerable to deliberate adversarial manipulations by attackers. Adversarial training is an effective approach to address this problem. Previous works quantize the input sample space to find appropriate perturbations on the benign samples so as to generate adversarial samples for adversarial training. However, since only the input sample space is quantized with the perturbation space being still continuous, finding the optimal perturbation noise is still a non-convex and computationally expensive problem. Moreover, in this case, the found perturbation noise that will be used to generate an adversarial sample may be strong in the continuous search space, but may become weak after quantization in the input sample space. In this paper, we first develop an Iterative Quantized Local Search (IQLS) algorithm that finds strong perturbation noises by quantizing both the input space and perturbation space. Then, we theoretically analyze and prove the upper bound on the number of iterations needed for the IQLS algorithm, based on which we devise an efficient and effective Quantized Adversarial Training (QAT) scheme. Experiment results on six public datasets show that our proposed scheme outperforms state-of-the-art methods to defend against different adversarial attacks. Particularly, QAT improves the system performance by 14%, 11%, 16% on average on CIFAR-10, SVHN, and CIFAR-100 datasets respectively compared with the existing defense schemes, and reduces the computing time by about 60%. Yifan Guo 0001, Tianxi Ji, Qianlong Wang 0003, Lixing Yu, Pan Li 0001 |
ICDM | 2 |
| 2018 | Multidimensional Time Series Anomaly Detection: A GRU-based Gaussian Mixture Variational Autoencoder ApproachabstractUnsupervised anomaly detection on multidimensional time series data is a very important problem due to its wide applications in many systems such as cyber-physical systems, the Internet of Things. Some existing works use traditional variational autoencoder (VAE) for anomaly detection. They generally assume a single-modal Gaussian distribution as prior in the data generative procedure. However, because of the intrinsic multimodality in time series data, previous works cannot effectively learn the complex data distribution, and hence cannot make accurate detections. To tackle this challenge, in this paper, we propose a GRU-based Gaussian Mixture VAE system for anomaly detection, called GGM-VAE. In particular, Gated Recurrent Unit (GRU) cells are employed to discover the correlations among time sequences. Then we use Gaussian Mixture priors in the latent space to characterize multimodal data. The proposed detector reports an anomaly when the reconstruction probability is below a certain threshold. We conduct extensive simulations on real world datasets and find that our proposed scheme outperforms the state-of-the-art anomaly detection schemes and achieves up to 5.7% and 7.2% improvements in accuracy and F1 score, respectively, compared with existing methods. Yifan Guo 0001, Weixian Liao, Qianlong Wang 0003, Lixing Yu, Tianxi Ji, Pan Li 0001 |
ACML | 5 |