EDBT 2026 Demo / reviewers in the wild / expert
Ziyao Liu
dblp:191/8896
· DBLP profile ↗
20ranked-venue papers
4as first author
19since 2021 · last 2026
0000-0003-4060-0839ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 4 first-author · 11 since 2021Computer networks · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Computational wiretap coding: framework and practical constructionabstractAbstract Wiretap coding, evolving in parallel with cryptography for nearly 50 years, focuses on secure transmission under the assumption that the wiretap channel is no less noisy than the main channel. Most provably secure schemes rely on information-theoretic security but often achieve limited practical rates. This paper proposes a framework for computationally secure modular wiretap coding. We integrate error correction encoding with the channel transition process to define the wiretap channel function, which consists of an invertible function and a lossy function. Secure encoding is then modeled as a computational entropy extractor. A detailed analysis of the lossy function for symmetric wiretap channels is presented. To leverage this lossiness, we design two computational extractors: the invertible fooling extractor (IFE) and the compressed randomness extractor (CRE). For practical implementation, we demonstrate that a 4-round optimal asymmetric encryption padding serves as an IFE in the random oracle model. Experimental comparisons show that our scheme achieves approximately 3 times and 2.7 times the code rates of the Invert-then-Encode and code-based schemes—classical information-theoretic schemes—under equivalent channel conditions. By instantiating IFE and CRE with hash algorithms such as SHAKE-128/256, we develop a practical wiretap coding scheme that achieves high rates with reasonable computational overhead. Mengjie Huang, Xianhui Lu, Chen An, Ziyi Li 0002, Ziyao Liu, Dongchi Han |
Cybersecur. | 5 |
| 2026 | Deep Learning Approaches for Anti-Money Laundering on Mobile Transactions: Review, Framework, and DirectionsabstractMoney laundering is a financial crime that obscures the origin of illicit funds, necessitating the development and enforcement of anti-money laundering (AML) policies by governments and organizations. The proliferation of mobile payment platforms and smart IoT devices has significantly complicated AML investigations. As payment networks become more interconnected, there is an increasing need for efficient real-time detection to process large volumes of transaction data on heterogeneous payment systems by different operators such as digital currencies, cryptocurrencies and account-based payments. Most of these mobile payment networks are supported by connected devices, many of which are considered loT devices in the FinTech space that constantly generate data. Furthermore, the growing complexity and unpredictability of transaction patterns across these networks contribute to a higher incidence of false positives. While machine learning solutions have the potential to enhance detection efficiency, their application in AML faces unique challenges, such as addressing privacy concerns tied to sensitive financial data and managing the real-world constraint of limited data availability due to data regulations. Existing surveys in the AML literature broadly review machine learning approaches for money laundering detection, but they often lack an in-depth exploration of advanced deep learning techniques—an emerging field with significant potential. To address this gap, this paper conducts a comprehensive review of deep learning solutions and the challenges associated with their use in AML. Additionally, we propose a novel framework that applies the least-privilege principle by integrating machine learning techniques, codifying AML red flags, and employing account profiling to provide context for predictions and enable effective fraud detection under limited data availability. Specifically, our approach defines AML-relevant financial profile characteristics and risk indicators to contextualize transactions and assess their associated risks. The proposed context-risk-predict AML (CRP-AML) model demonstrates notable success, achieving an F1 score of 82.51% on the minority class and nearly doubling the performance of other pattern detection models when the proportion of money laundering records in the dataset drops as low as 0.0005. Jiani Fan, Lwin Khin Shar, Ruichen Zhang 0001, Ziyao Liu, Wenzhuo Yang, Dusit Niyato, Kwok-Yan Lam |
IEEE Internet Things J. | 4 |
| 2026 | PDFL: A Privacy-Enhancing and Robust Poisoning Defense Federated Learning SchemeabstractThis paper addresses the security and privacy issues of the global models in Federated Learning by proposing a new approach, called PDFL, which tackles the challenges of poisoning attacks and privacy leakage in FL rounds. PDFL is based on secure multi-party computation and performs privacy-preserving cluster analysis on encrypted data from participants in order to identify malicious poisoning attackers. This approach involves a two-server mechanism and integrates four privacy-preserving protocols based on two-party computation (2PC): SecJudge for normalizing gradients, SecCosine for computing the cosine similarity values among gradients, SecClu for countering poisoning attacks, and SecAgg for secure aggregation by the server. These protocols are designed to achieve low computational costs, preserve client data privacy, and mitigate poisoning attacks from the potentially malicious clients. We provide a theoretical proof that our four sub-protocols and the PDFL scheme are both safe and reliable, demonstrating that PDFL can ensure the privacy and security of the participating data. Additionally, we conduct extensive simulation experiments to evaluate the accuracy, efficiency, computational overhead, and communication overhead associated with the PDFL scheme. Experimental results show the potential of the PDFL scheme in significantly enhancing the ability to identify malicious poisoning attackers in federated learning systems accurately and efficiently, hence making PDFL a promising solution for addressing privacy and security concerns in this domain. Huiwen Wu, Qingming Li, Ziyao Liu, Jun Zhao 0007, Kwok-Yan Lam, Qingkuan Dong |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Compact Lifting for NTT-Unfriendly Modulus
Ying Liu 0078, Xianhui Lu, Yu Zhang 0036, Ruida Wang, Ziyao Liu, Kunpeng Wang 0001 |
ACISP (2) | 5 |
| 2025 | PolarKyber: Polished Kyber with Smaller Ciphertexts, Greater Security Redundancy, and Lower Decryption Failure Rate
Chen An, Ziyao Liu, Xianhui Lu, Jingnan He |
ICICS (1) | 2 |
| 2025 | Improving Security in IoT-Based Human Activity Recognition: A Correlation-Based Anomaly Detection ApproachabstractAnomaly detection in human activity recognition (HAR) is a critical subfield that leverages data from the Internet of Things (IoT) to monitor human activities and detect errors or abnormal events. Conventional rule-based approaches often fail to capture the intricate relationships between sensor values, while machine-learning-based methods tend to lack the ability to provide explainability and actionable context for the detected anomalies. In this article, we introduce a novel correlation-based anomaly detection framework designed to improve the security and reliability of IoT-enabled HAR systems. Our proposed scheme utilizes a context-aware deep learning architecture to predict sensor values by leveraging the interdependencies between coexisting sensors in the deployment environment. Experimental results demonstrate that our model achieves a best anomaly prediction accuracy of 99.76% on individual sensors and outperforms other baseline models, consistently maintaining high F1 scores with a minimum of 0.866 on various sensors, even when the training dataset is reduced. Furthermore, we propose an AI-generated content (AIGC)-based visualization method for reporting anomalies, offering clear insights into the context and severity of detected anomalies and their potential system impact. Jiani Fan, Ziyao Liu, Hongyang Du 0001, Jiawen Kang 0001, Dusit Niyato, Kwok-Yan Lam |
IEEE Internet Things J. | 2 |
| 2025 | Guaranteeing Data Privacy in Federated Unlearning With Dynamic User ParticipationabstractFederated Unlearning (FU) is gaining prominence for its capability to eliminate influences of specific users’ data from trained global Federated Learning (FL) models. A straightforward FU method involves removing the unlearned user-specified data and subsequently obtaining a new global FL model from scratch with all remaining user data, a process that unfortunately leads to considerable overhead. To enhance unlearning efficiency, a widely adopted strategy employs clustering, dividing FL users into clusters, with each cluster maintaining its own FL model. The final inference is then determined by aggregating the majority vote from the inferences of these sub-models. This method confines unlearning processes to individual clusters for removing the training data of a particular user, thereby enhancing unlearning efficiency by eliminating the need for participation from all remaining user data. However, current clustering-based FU schemes mainly concentrate on refining clustering to boost unlearning efficiency but without addressing the issue of the potential information leakage from FL users’ gradients, a privacy concern that has been extensively studied. Typically, integrating secure aggregation (SecAgg) schemes within each cluster can facilitate a privacy-preserving FU. Nevertheless, crafting a clustering methodology that seamlessly incorporates SecAgg schemes is challenging, particularly in scenarios involving adversarial users and dynamic users. In this connection, we systematically explore the integration of SecAgg protocols within the most widely used federated unlearning scheme, which is based on clustering, to establish a privacy-preserving FU framework, aimed at ensuring privacy while effectively managing dynamic user participation. Comprehensive theoretical assessments and experimental results show that our proposed scheme achieves comparable unlearning effectiveness, alongside offering improved privacy protection and resilience in the face of varying user participation. Ziyao Liu, Yu Jiang 0015, Weifeng Jiang, Jun Zhao 0007, Kwok-Yan Lam |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Toward Efficient and Certified Recovery From Poisoning Attacks in Federated LearningabstractFederated learning (FL) is vulnerable to poisoning attacks, where malicious clients manipulate their updates to affect the global model. Although various methods exist for detecting such clients in FL, identifying malicious clients requires sufficient model updates, and hence by the time malicious clients are detected, FL models have already been poisoned. Thus, a method is needed to recover an accurate global model after malicious clients are identified. Current recovery methods rely on (i) all historical information from participating FL clients and (ii) the initial model unaffected by the malicious clients, both leading to a high demand for storage and computational resources. In this paper, we show that highly effective recovery can still be achieved based on 1) selective historical information rather than all historical information and 2) a historical model that has not been significantly affected by malicious clients rather than the initial model. In this scenario, we can accelerate the recovery speed and decrease memory consumption while maintaining comparable recovery performance. Following this concept, we introduce Crab (Certified Recovery from Poisoning Attacks and Breaches), an efficient and certified recovery method, which relies on selective information storage and adaptive model rollback. Theoretically, we demonstrate that the difference between the global model recovered by Crab and the one recovered by train-from-scratch can be bounded under certain assumptions. Our experiments, performed across four datasets with multiple machine learning models and aggregation methods, involving both untargeted and targeted poisoning attacks, demonstrate that Crab is not only accurate and efficient but also consistently outperforms previous approaches in recovery speed and memory consumption. Yu Jiang 0015, Jiyuan Shen, Ziyao Liu, Chee-Wei Tan 0001, Kwok-Yan Lam |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Certifying the Right to Be Forgotten: Primal-Dual Optimization for Sample and Label Unlearning in Vertical Federated LearningabstractFederated unlearning has become an attractive approach to address privacy concerns in collaborative machine learning, for situations when sensitive data are remembered by AI models during the machine learning process. It enables the removal of specific data influences from trained models, aligning with the growing emphasis on the “right to be forgotten.” While extensively studied in horizontal federated learning, unlearning in vertical federated learning (VFL) remains challenging due to the distributed feature architecture. VFL unlearning includes sample unlearning that removes specific data points’ influence and label unlearning that removes entire classes. Since different parties hold complementary features of the same samples, unlearning tasks require cross-party coordination, creating computational overhead and feature interdependencies. To address such challenges, we propose FedORA (Federated Optimization for data Removal via primal-dual Algorithm), designed for sample and label unlearning in VFL. FedORA formulates the removal of certain samples or labels as a constrained optimization problem solved using a primal-dual framework. Our approach introduces a new unlearning loss function that promotes classification uncertainty rather than misclassification. An adaptive step size enhances convergence, while an asymmetric batch design handles unlearning and retained data efficiently to reduce computational costs, considering the prior influence of the remaining data on the model. We provide theoretical analysis proving that the model difference between FedORA and Train-from-scratch is bounded, establishing guarantees for unlearning effectiveness. Experiments on tabular and image datasets demonstrate that FedORA achieves unlearning effectiveness and utility preservation comparable to Train-from-scratch with reduced computation and communication overhead. Yu Jiang 0015, Xindi Tong, Ziyao Liu, Xiaoxi Zhang 0001, Kwok-Yan Lam, Chee-Wei Tan 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Privacy-Preserving Federated Unlearning With Certified Client RemovalabstractIn recent years, Federated Unlearning (FU) has gained attention for addressing the removal of a client’s influence from the global model in Federated Learning (FL) systems, thereby ensuring the “right to be forgotten” (RTBF). State-of-the-art methods for unlearning use historical data from FL clients, such as gradients or locally trained models. However, studies have revealed significant information leakage in this setting, with the possibility of reconstructing a user’s local data from their uploaded information. Addressing this, we propose Starfish, a privacy-preserving federated unlearning scheme using Two-Party Computation (2PC) techniques and shared historical client data between two non-colluding servers. Starfish builds upon existing FU methods to ensure privacy in unlearning processes. To enhance the efficiency of privacy-preserving FU evaluations, we suggest 2PC-friendly alternatives for certain FU algorithm operations. We also implement strategies to reduce costs associated with 2PC operations and lessen cumulative approximation errors. Moreover, we establish a theoretical bound for the difference between the unlearned global model via Starfish and a global model retrained from scratch for certified client removal. Our theoretical and experimental analyses demonstrate that Starfish achieves effective unlearning with reasonable efficiency, maintaining privacy and security in FL systems. Ziyao Liu, Huanyi Ye, Yu Jiang 0015, Jiyuan Shen, Ivan Tjuawinata, Kwok-Yan Lam |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Efficient Federated Unlearning with Adaptive Differential Privacy PreservationabstractFederated unlearning (FU) offers a promising solution to effectively address the need to erase the impact of specific clients’ data on the global model in federated learning (FL), thereby granting individuals the "Right to be Forgotten". The most straightforward approach to achieve unlearning is to train the model from scratch, excluding clients who request data removal, but it is resource-intensive. Current state-of-the-art FU methods extend traditional FL frameworks by leveraging stored historical updates, enabling more efficient unlearning than training from scratch. However, the use of stored updates introduces significant privacy risks. Adversaries with access to these updates can potentially reconstruct clients’ local data, a well-known vulnerability in the privacy domain. While privacy-enhanced techniques exist, their applications to FU scenarios that balance unlearning efficiency with privacy protection remain underexplored. To address this gap, we propose FedADP, a method designed to achieve both efficiency and privacy preservation in FU. Our approach incorporates an adaptive differential privacy (DP) mechanism, carefully balancing privacy and unlearning performance through a novel budget allocation strategy tailored for FU. FedADP also employs a dual-layered selection process, focusing on global models with significant changes and client updates closely aligned with the global model, reducing storage and communication costs. Additionally, a novel calibration method is introduced to facilitate effective unlearning. Extensive experimental results demonstrate that FedADP effectively manages the trade-off between unlearning efficiency and privacy protection. Yu Jiang 0015, Xindi Tong, Ziyao Liu, Huanyi Ye, Chee-Wei Tan 0001, Kwok-Yan Lam |
IEEE Big Data | 3 |
| 2024 | LEO Satellite-Enabled Networks: A Privacy-Preserving Framework for Spectrum Pricing and Power Control OptimizationabstractLow Earth orbit (LEO) satellite systems are receiving increasing attention as they provide extensive global coverage. Secure and efficient management of limited spectrum bands and power resources are crucial for controlling operational costs and ensuring reliable communication in LEO satellite systems. However, spectrum pricing and power control optimization are challenging tasks. First, dynamic pricing is needed for leasing idle satellite spectrum to terrestrial users, as it must consider user mobility and real-time demand changes. Additionally, there is a trust concern that when utilizing the leased spectrum, terrestrial users may maliciously exceed limited transmit power to improve the quality of service (QoS). Moreover, users' privacy should be protected because the data collected by satellites often contain sensitive information such as location, budget, and QoS needs. In this paper, we propose a hybrid spectrum pricing and power control framework for LEO satellite-enabled networks to mitigate the above concerns by combining blockchain technology and Federated Learning (FL). We first design a local deep reinforcement learning algorithm for LEO satellite systems to learn a revenue-maximizing pricing strategy and power control scheme. Subsequently, these individual agents collaborate to establish an FL system without sharing their sensitive raw data. We also propose a reputation-based blockchain used in the global model aggregation phase to further enhance the traceability of the network and guarantee the trust. We conduct simulation tests to evaluate the efficacy of the proposed scheme, and our results show its capability to efficiently find the maximum revenue scheme for LEO satellite systems while preserving the privacy of each participating agent in an auditable mode. Bowen Shen, Kwok-Yan Lam, Wenzhuo Yang, Ziyao Liu, Feng Li 0008 |
MSN | 4 |
| 2024 | Malicious Unlearning in Ensemble ModelsabstractKnowledge removal is a crucial task in AI safety and for aligning with the Right To Be Forgotten (RTBF) principle. Machine Unlearning (MU) is an important means for achieving knowledge removal by removing the ML impacts of a specified subset of training data. However, existing MU frameworks may be misused to facilitate emerging novel poisoning attacks, where adversaries may introduce both poisoned data and the corre-sponding mitigation data that temporarily neutralize the effects of the poisoned data. The adversaries then submit malicious unlearning requests for the mitigation data, hence maintaining the malicious effects of the poison. Such attacks have been shown to be effective in single-model scenarios; however, their impacts on ensemble models, which are widely adopted because of their robustness, remain underexplored. Recognizing this gap, we extend these emerging poisoning attacks to ensemble settings to better understand and address the potential risks of malicious unlearning. Our extensive experimental results show that the proposed extended poisoning attacks are effective also in the ensemble settings, achieving a high attack success rate, highlighting the importance of continued research in safeguard measures against misuse of MU as one of the important requirements of AI safety. Huanyi Ye, Ziyao Liu, Yu Jiang 0015, Kwok-Yan Lam |
PST | 2 |
| 2024 | Unbridled Icarus: A Survey of the Potential Perils of Image Inputs in Multimodal Large Language Model SecurityabstractMultimodal Large Language Models (MLLMs) demonstrate remarkable capabilities that increasingly influence various aspects of our daily lives, constantly defining the new boundary of Artificial General Intelligence (AGI). Image modalities, enriched with profound semantic information and a more continuous mathematical nature compared to other modalities, greatly enhance the functionalities of MLLMs when integrated. However, this integration serves as a double-edged sword, providing attackers with expansive vulnerabilities to exploit for highly covert and harmful attacks. The pursuit of reliable AI systems like powerful MLLMs has emerged as a pivotal area of contemporary research. In this paper, we endeavor to demostrate the multifaceted risks associated with the incorporation of image modalities into MLLMs. Initially, we delineate the foundational components and training processes of MLLMs. Subsequently, we construct a threat model, outlining the security vulnerabilities intrinsic to MLLMs. Moreover, we analyze and summarize existing scholarly discourses on MLLMs' attack and defense mechanisms, culminating in suggestions for the future research on MLLM security. Through this comprehensive analysis, we aim to deepen the academic understanding of MLLM security challenges and propel forward the development of trustworthy MLLM systems. Yihe Fan, Ziyao Liu, Shaofeng Li 0001 |
SMC | 4 |
| 2023 | A Learning-based Incentive Mechanism for Mobile AIGC Service in Decentralized Internet of VehiclesabstractArtificial Intelligence-Generated Content (AIGC) refers to the paradigm of automated content generation utilizing AI models. Mobile AIGC services in the Internet of Vehicles (IoV) network have numerous advantages over traditional cloud-based AIGC services, including enhanced network efficiency, better reconfigurability, and stronger data security and privacy. Nonetheless, AIGC service provisioning frequently demands significant resources. Consequently, resource-constrained roadside units (RSUs) face challenges in maintaining a heterogeneous pool of AIGC services and addressing all user service requests without degrading overall performance. Therefore, in this paper, we propose a decentralized incentive mechanism for mobile AIGC service allocation, employing multi-agent deep reinforcement learning to find the balance between the supply of AIGC services on RSUs and user demand for services within the IoV context, optimizing user experience and minimizing transmission latency. Experimental results demonstrate that our approach achieves superior performance compared to other baseline models. Jiani Fan, Minrui Xu, Ziyao Liu, Huanyi Ye, Chaojie Gu, Dusit Niyato, Kwok-Yan Lam |
VTC Fall | 3 |
| 2023 | Understanding Security in Smart City Domains From the ANT-Centric PerspectiveabstractA city is a large human settlement that serves the people who live there, and a smart city is a concept of how cities might better serve their residents through new forms of technology. In this article, we focus on four major smart city domains according to Maslow’s hierarchy of needs: smart utility, smart transportation, smart homes, and smart healthcare. Numerous Internet of Things (IoT) applications have been developed to achieve the intelligence that we desire in our smart domains, ranging from personal gadgets, such as health trackers and smart watches to large-scale industrial IoT systems, such as nuclear and energy management systems. However, many of the existing smart city IoT solutions can be made better by considering the suitability of their security strategies. Inappropriate system security designs generally occur in two scenarios: first, system designers recognize the importance of security but are unsure of where, when, or how to implement it and second, system designers try to fit traditional security designs to meet the smart city security context. Thus, the objective of this article is to provide application designers with the missing security link they may need in order to improve their security designs. By evaluating the specific context of each smart city domain and the context-specific security requirements, we aim to provide directions on when, where, and how they should implement security strategies and the possible security challenges they need to consider. In addition, we present a new perspective on security issues in smart cities from a data-centric viewpoint by referring to the reference architecture, the activity-network-things (ANTs)-centric architecture. This architecture is built upon the concept of “security in a zero-trust environment,” to achieve end-to-end data security. By doing so, we reduce the security risks posed by new system interactions or unanticipated user behaviors while avoiding the hassle of regularly upgrading security models. Jiani Fan, Wenzhuo Yang, Ziyao Liu, Jiawen Kang 0001, Dusit Niyato, Kwok-Yan Lam, Hongyang Du 0001 |
IEEE Internet Things J. | 3 |
| 2023 | Efficient Dropout-Resilient Aggregation for Privacy-Preserving Machine LearningabstractMachine learning (ML) has been widely recognized as an enabler of the global trend of digital transformation. With the increasing adoption of data-hungry machine learning algorithms, personal data privacy has emerged as one of the key concerns that could hinder the success of digital transformation. As such, Privacy-Preserving Machine Learning (PPML) has received much attention of the machine learning community, from academic researchers to industry practitioners to government regulators. However, organizations are faced with the dilemma that, on the one hand, they are encouraged to share data to enhance ML performance, but on the other hand, they could potentially be breaching the relevant data privacy regulations. Practical PPML typically allows multiple participants to individually train their ML models, which are then aggregated to construct a global model in a privacy-preserving manner, e.g., based on multi-party computation or homomorphic encryption. Nevertheless, in most important applications of large-scale PPML, e.g., by aggregating clients’ gradients to update a global model for federated learning, such as consumer behavior modeling of mobile application services, some participants are inevitably resource-constrained mobile devices, which may drop out of the PPML system due to their mobility nature (Yang et al., 2019). Therefore, the resilience of privacy-preserving aggregation has become an important problem to be tackled because of its real-world application potential and impacts. In this paper, we propose a scalable privacy-preserving aggregation scheme that can tolerate dropout by participants at any time, and is secure against both semi-honest and active malicious adversaries by setting proper system parameters. By replacing communication-intensive building blocks with a seed homomorphic pseudo-random generator, and relying on the additive homomorphic property of Shamir secret sharing scheme, our scheme outperforms state-of-the-art schemes by up to$6.37\times $in runtime and provides a stronger dropout-resilience. The simplicity of our scheme makes it attractive both for implementation and for further improvements. Ziyao Liu, Kwok-Yan Lam, Jun Zhao 0007 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Long-Term Privacy-Preserving Aggregation With User-Dynamics for Federated LearningabstractPrivacy-preserving aggregation protocol is an essential building block in privacy-enhanced federated learning (FL), which enables the server to obtain the sum of users’ locally trained models while keeping local training data private. However, most of the work on privacy-preserving aggregation provides privacy guarantees for only one communication round in FL. In fact, as FL usually involves long-term training, i.e., multiple rounds, it may lead to more information leakages due to the dynamic user participation over rounds. In this connection, we propose a long-term privacy-preserving aggregation (LTPA) protocol providing both single-round and multi-round privacy guarantees. Specifically, we first introduce our batch-partitioning-dropping-updating (BPDU) strategy that enables any user-dynamic FL system to provide multi-round privacy guarantees. Then we present our LTPA construction which integrates our proposed BPDU strategy with the state-of-the-art privacy-preserving aggregation protocol. Furthermore, we investigate the impact of LTPA parameter settings on the trade-off between privacy guarantee, protocol efficiency, and FL convergence performance from both theoretical and experimental perspectives. Experimental results show that LTPA provides similar complexity to that of the state-of-the-art, i.e., an additional cost of around only 1.04X for a 100,000-user FL system, with an additional long-term privacy guarantee. Ziyao Liu, Hsiao-Ying Lin |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Privacy-Preserving Anomaly Detection in Cloud Manufacturing Via Federated TransformerabstractWith the rapid development of cloud manufacturing, industrial production with edge computing as the core architecture has been greatly developed. However, edge devices often suffer from abnormalities and failures in industrial production. Therefore, detecting these abnormal situations timely and accurately is crucial for cloud manufacturing. As such, a straightforward solution is that the edge device uploads the data to the cloud for anomaly detection. However, Industry 4.0 puts forward higher requirements for data privacy and security so that it is unrealistic to upload data from edge devices directly to the cloud. Considering the abovementioned severe challenges, this article customizes a weakly supervised edge computing anomaly detection framework, i.e., federated learning-based transformer framework (FedAnomaly), to deal with the anomaly detection problem in cloud manufacturing. Specifically, we introduce federated learning (FL) framework that allows edge devices to train an anomaly detection model in collaboration with the cloud without compromising privacy. To boost the privacy performance of the framework, we add differential privacy noise to the uploaded features. To further improve the ability of edge devices to extract abnormal features, we use the transformer to extract the feature representation of abnormal data. In this context, we design a novel collaborative learning protocol to promote efficient collaboration between FL and transformer. Furthermore, extensive case studies on four benchmark datasets verify the effectiveness of the proposed framework. To the best of our knowledge, this is the first time integrating FL and transformer to deal with anomaly detection problems in cloud manufacturing. Shiyao Ma, Jiangtian Nie, Jiawen Kang 0001, Lingjuan Lyu, Ryan Wen Liu, Ruihui Zhao, Ziyao Liu, Dusit Niyato |
IEEE Trans. Ind. Informatics | 7 |
| 2016 | An overview of multi-antenna technologies for space-ground integrated networks
Shuo Zhang 0012, Ziyao Liu, Jinyong Lin, Shuai Wang 0013, Chengwen Xing |
Sci. China Inf. Sci. | 3 |