EDBT 2026 Demo / reviewers in the wild / expert
Mengqian Li
dblp:178/9541
· DBLP profile ↗
11ranked-venue papers
3as first author
11since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021Computer networks · 4 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A transferable attack framework for face impersonation with surrogate ensemble and semantic guidance
Ruixin Song, Youliang Tian, Mengqian Li |
Inf. Process. Manag. | 3 |
| 2026 | Complex network evolution with node strategies driven by information entropy
Youliang Tian, Jinbo Xiong, Mengqian Li, Kun Niu, Die Zhou, Jianfeng Ma 0001 |
Inf. Sci. | 4 |
| 2026 | Secure Rational Delegation Federated LearningabstractFederated learning (FL) allows multiple distributed clients with local datasets to train a global model collaboratively. Due to the potential privacy risk of the training process, differential privacy (DP) is introduced into FL to protect clients’ sensitive information by perturbing the model updates. However, the probability density function of the Laplace mechanism has a long-tail effect, which may generate large noise to induce the model to deviate from the normal result. Moreover, as the cloud is not fully trusted, there is no guarantee that the server follows the aggregation protocol correctly. To address these issues, in this paper, we propose a secure rational delegation FL scheme, namely SRDFL, and analyze its protection and convergence performance. Specifically, we first utilize the zero-determinant strategy to construct a FL rational model. It delegates tasks to multiple servers and encourages them to perform correct aggregation. Then, we design a bounded DP protection mechanism to achieve a fixed universe of perturbation outputs in a threshold-constrained manner. Finally, based on Shamir’s secret sharing, we propose a trusted verification algorithm of DP to validate servers for correct aggregation. Detailed theoretical analysis and extensive performance evaluations demonstrate that our proposed scheme is effective. Compared to existing works, SRDFL is able to improve 2.72% - 47.92% model accuracy. Mengqian Li, Youliang Tian, Jinbo Xiong, Jianfeng Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2026 | Achieving Privacy-Preserving and High-Accuracy Collection of Key-Value Data With Local Differential PrivacyabstractIn the context of the Internet of Things (IoT), the large-scale generation and collection of data can greatly improve the quality of service provided, but they also raise significant concerns about privacy breaches. However, existing privacy-preserving data collection solutions based on local differential privacy (LDP) often struggle to balance security and accuracy when handling composite data types. To address this challenge, in this paper, we propose CSKV, a high-precision and privacy-preserving key-value data collection scheme. Specifically, we first design a padding and sampling protocol to improve data utility. Then, we propose two randomized response mechanisms to safely perturb keys and values in a cohesive and segmented manner. After that, by leveraging the sampling protocol and key-value correlation perturbation, we demonstrate that CSKV can provide secondary privacy amplification. Detailed theoretical analysis verifies the security and effectiveness of CSKV. In addition, extensive performance evaluations are conducted on synthetic and real-world datasets, and the results indicate that our proposed scheme outperforms existing schemes in terms of hit rate and estimation variance. Hui Zhu 0001, Jiaqi Zhao 0005, Mengqian Li, Shuang Zhang 0009, Hui Li 0006 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2026 | Enhancing Federated Learning in Edge Computing With Secure Aggregation and Dynamic VerificationabstractFederated learning (FL) enables multiple clients to exchange gradients to facilitate collaborative training in edge computing without transferring private data to the cloud server. However, the malicious server may disrupt the model training process by obtaining gradients to infer client information or faking validation results. Considering these threats, we construct a dynamic, secure, and verifiable FL scheme, named DSVFL. Specifically, we propose the fine-grained top-$k$gradient selection algorithm to accelerate model convergence, which can improve model accuracy by up to 49.14%. Furthermore, we propose a single-cloud secure aggregation protocol that guarantees the server cannot access the real model parameters. We also design a trusted verification algorithm to validate the server's aggregation results while resisting collusion between the server and clients. For federation dynamics, we adopt the Shamir's secret sharing in both the aggregation and verification phases, which enables the correct aggregation and decryption of ciphertexts and the independent verification of client signatures, even in cases of client dropouts. Rigorous theoretical analysis demonstrates that DSVFL can protect data privacy and ensure correct training results. Experimental results indicate that DSVFL can reduce clients' computational cost by 48%-63% and communication overhead by 33%-49% compared with existing solutions. Mengqian Li, Youliang Tian, Jinbo Xiong, Xinhua Cui, Jianfeng Ma 0001 |
IEEE Trans. Mob. Comput. | 1 |
| 2025 | SEMA: A Structural Entropy Guided Multimodal Framework for Adversarial Face AttacksabstractFace recognition systems are vulnerable to adversarial attacks, where imperceptible perturbations can mislead model predictions. However, existing methods often lack fine-grained control over perturbation localization and fail to effectively exploit structural and semantic priors. In this paper, we propose a multimodal adversarial framework termed structure-aware entropy masked attack (SEMA) that integrates structural entropy-guided masking and semantic alignment. By leveraging multimodal information and diffusion-based generation, the method injects perturbations into high-entropy regions to maximize structural disruption while maintaining perceptual fidelity. Furthermore, we conduct an information-theoretic analysis from both topological and embedding perspectives to interpret the adversarial generation process. Experiments indicate SEMA outperforms previous methods on diverse face recognition models, with the attack success rate improved by up to 18.6% in the best case. Ruixin Song, Youliang Tian, Mengqian Li |
TrustCom | 3 |
| 2025 | BDT-RVOC: Block Data Truncation for Verifiable and Private Multi-Cloud ComputationabstractReplication-based outsourced computation enables efficient correctness verification through cross-checking results from multiple non-colluding clouds, yet introduces critical privacy risks when clouds exchange intermediate data for interest alignment, especially in multi-user private data scenarios such as federated learning. To address this challenge, we propose BDT-RVOC, a novel framework integrating binary-segmentation data truncation with distributed multi-trapdoor public key cryptography (DMT-PKC). BDT-RVOC dynamically splits raw data into mutually exclusive blocks distributed to different clouds, ensuring that computations on truncated data preserve bit-level consistency with raw-data operations while preventing raw-data leakage during inter-cloud exchanges. Our framework designs secure interactive protocols for addition, multiplication, and equivalence testing under truncation, formally guaranteeing operational equivalence between block-level and raw-data computations. By extending Paillier encryption to a multi-key setting, DMT-PKC partitions strong private keys to resist collusion between the aggregator and up to n−2 agents. Applied to private aggregation, BDT-RVOC achieves a 1.8× speedup over federated learning baselines with 57% lower communication overhead. Theoretical analysis proves resilience against semi-honest adversaries compromising all communications and up to n−1 colluding parties, while experiments on real-world datasets confirm practical efficiency and scalability for real-world deployments. Youliang Tian, Ruixin Song, Kun Niu, Mengqian Li, Jinbo Xiong |
TrustCom | 5 |
| 2025 | InfoShadow: NTK & MI guided adversarial attacks on speaker identification systemsabstractAbstract Adversarial attacks on speaker identification (SI) systems have become a critical security concern, particularly in targeted black-box scenarios where access to the target model is limited. This paper proposes a novel framework that creates highly transferable adversarial examples. We use a voice conversion (VC) model to synthesize shadow data from a single target speech sample, which is then used to train two diverse surrogate models. Neural Tangent Kernel (NTK) theory is employed to align acoustic feature spaces, while mutual information optimization enforces consistency between the surrogate models’ predictions. Consequently, the adversarial attack is formulated as a min-max game that maximizes attack success while preserving speech quality. Extensive experiments on LibriSpeech and VCTK datasets demonstrate that our method significantly improves the transferability and effectiveness of adversarial examples compared to conventional approaches. Our findings suggest that generating shadow data through voice conversion followed by surrogate model training under information-theoretic constraints is a promising strategy for robust adversarial attacks. Ruixin Song, Youliang Tian, Mengqian Li |
Cybersecur. | 3 |
| 2025 | A Lightweight Certificateless Edge-Assisted Encryption for IoT Devices: Enhancing Security and PerformanceabstractIn edge computing environments, the rapid growth of Internet of Things (IoT) devices presents significant challenges for data processing. These devices are often resource-constrained, leading to a tradeoff between achieving efficiency and ensuring security. On one hand, traditional certificateless encryption methods are computationally expensive; on the other hand, offloading the computational load to third-party entities can enhance efficiency but still introduces security risks. To address these issues, this article proposes a novel lightweight certificateless edge-assisted encryption scheme (CL-EAED). Ours scheme offloads computationally intensive tasks to edge servers, ensuring that edge-assisted processing does not expose sensitive information and only needs to be performed once. This approach effectively prevents data leakage and enhances both the efficiency and security of task offloading. Moreover, the CL-EAED scheme achieves IND-CCA security in standard model (SM) and has been validated using the ProVerif tool. Experimental evaluations demonstrate that CL-EAED eliminates the dependency on computationally intensive pairing operations, significantly reducing computational and communication costs. It outperforms existing solutions in terms of energy consumption, latency, and scalability, fully meeting the requirements of practical applications. Xinhua Cui, Youliang Tian, Mengqian Li |
IEEE Internet Things J. | 5 |
| 2025 | THC-DL: Three-Party Homomorphic Computing Delegation Learning for Secure OptimizationabstractDelegation Learning(DL) flourishes data sharing, enabling agents to delegate data to the cloud for model training. To preserve privacy, homomorphic encryption (HE) offers an effective solution for privacy-preserving machine learning (PPML) in delegation learning, yet faces critical challenges in functionality (non-linear activation support), practicality (ciphertext blow-up from iterative computations), and security (data leakage risks caused by public knowledge of the mathematical principles applied in model training). To tackle these challenges, we propose THC-DL, a three-party HE framework addressing these challenges holistically for the first time. We elaborately design the ciphertext secure comparison (DL-CSC) protocol to satisfy secure comparison with private inputs, enabling efficient non-linear operations with O(1) communication complexity that reduces runtime to 12.5% of the DGK (Dolev-Greensmith-Kent protocol, the well-known comparison protocol). Second, we construct a Truncation-Mapping (Tru-Map) scheme, a mechanism that transforms input data by truncating and mapping it into a domain that facilitates more efficient processing, and the addition of truncated mapped data to resolve ciphertext blow-up by adaptively scaling ciphertexts during iterative training, ensuring correctness. Third, we formalize data leakage risks in HE-based quadratic convex optimization (standard in ML) and apply THC-DL to construct a secure optimization scheme. Theoretical analysis confirms THC-DL’s resilience against input recovery attacks, even when adversaries exploit public model parameters. Experiments on a real-world platform validate DL-CSC’s efficiency and scalability while reducing the computational complexity and communication complexity from O(n) to O(1) where n denotes the length of the input bits. Youliang Tian, Jinbo Xiong, Kun Niu, Mengqian Li, Jianfeng Ma 0001 |
IEEE Internet Things J. | 5 |
| 2024 | IMFL: An Incentive Mechanism for Federated Learning With Personalized ProtectionabstractFederated Learning (FL) allows clients to keep local datasets and train collaboratively by uploading model gradients, which achieves the goal of learning from fragmented sensitive data. Although FL prevents clients’ datasets from being shared directly, local private information may be leaked through gradients. To mitigate this problem, we combine game theory to design an FL scheme (IMFL) based on the incentive mechanism and differential privacy (DP). Firstly, we explore three DP variants, all of which are resistant to deep leakage from gradients (DLG) but differ in their level of privacy protection. In addition, we perform the convergence analysis of the FL model based on DP. Then, with the assistance of game theory, we analyze the natural state of the server and clients in the FL process and formulate the utility function of both sides under the case of considering the attack. Finally, we establish the optimization problem as a Stackelberg game and solve for the optimal strategy of the server and clients by deriving the Nash equilibrium to achieve personalized protection. Theoretical proof demonstrates that both types of entities can achieve optimal actions by maximizing their utility functions upon reaching the Nash equilibrium. Besides, extensive experiments are conducted on real-world datasets to demonstrate that the IMFL is efficient and feasible. Mengqian Li, Youliang Tian, Zhou Zhou 0005, Dongmei Zhao, Jianfeng Ma 0001 |
IEEE Internet Things J. | 1 |