Haonan Yan

dblp:192/3511 · DBLP profile ↗
← Back
31ranked-venue papers
10as first author
29since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 9 · 3 first-author · 9 since 2021Computer networks · 6 · 2 first-author · 5 since 2021Security and privacy · 6 · 4 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 2 first-author · 6 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Robust Single-Message Shuffle Differential Privacy Protocol for Accurate Distribution Estimation
abstract
Shuffler-based differential privacy (shuffle-DP) is a privacy paradigm providing high utility by involving a shuffler to permute noisy report from users. Existing shuffle-DP protocols mainly focus on the design of shuffler-based categorical frequency oracle (SCFO) for frequency estimation on categorical data. However, numerical data is a more prevalent type and many real-world applications depend on the estimation of data distribution with ordinal nature. In this paper, we study the distribution estimation under pure shuffle model, which is a prevalent shuffle-DP framework without strong security assumptions. We initially attempt to transplant existing SCFOs and the naïve distribution recovery technique to this task, and demonstrate that these baseline protocols cannot simultaneously achieve outstanding performance in three metrics: 1) utility, 2) message complexity; and 3) robustness to data poisoning attacks. Therefore, we further propose a novel single-message \textit{adaptive shuffler-based piecewise} (ASP) protocol with high utility and robustness. In ASP, we first develop a randomizer by parameter optimization using our proposed tighter bound of mutual information. We also design an \textit{Expectation Maximization with Adaptive Smoothing} (EMAS) algorithm to accurately recover distribution with enhanced robustness. To quantify robustness, we propose a new evaluation framework to examine robustness under different attack targets, enabling us to comprehensively understand the protocol resilience under various adversarial scenarios. Extensive experiments demonstrate that ASP outperforms baseline protocols in all three metrics. Especially under small $ε$ values, ASP achieves an order of magnitude improvement in utility with minimal message complexity, and exhibits over threefold robustness compared to baseline methods.
Yaowei Huang, Qingqing Ye 0001, Haonan Yan, Ke Pan 0001, Zhe Sun 0005
ICDE6
2026 DCAD: Dual-Condition Adaptive Consistency Model for IoT Privacy-Preserving Video Anomaly Detection
Shaopeng Zhou, Chaohao Li, Haonan Yan, Longlong Zhu, Chunming Wu 0001, Bin Wang 0062
ICIC (2)3
2026 Tri-HGNet: A feature-driven dynamic hypergraph framework for medical image segmentation
Xiaoyan Kui, Lingxiao Liu, Qinsong Li, Haonan Yan, Weixin Si, Zuheng Ming, Beiji Zou 0001
Neurocomputing4
2026 A Log-Likelihood Chain Framework for Defending Against LDP Data Poisoning Attacks
abstract
Local differential privacy (LDP) provides strict privacy guarantee in a distributed environment. Recent studies demonstrated that LDP protocols are vulnerable to data poisoning attacks where an attacker can manipulate the perturbed result on the local side and send bogus data to skew the final estimate on the server. Unfortunately, existing attack detections do not create an effective attack indicator and rely on particular characteristics of LDP protocols. As a result, they typically exhibit limited detection performance. In this paper, we use log-likelihood as the attack indicator and propose a chain-style detection to enhance the detection effectiveness, in which the attack impact could propagate along the chain and exhibit clear anomaly signal even under stealthy attack scenarios. The experimental results show that our detection consistently outperforms the existing methods. Using four datasets containing categorical and numerical data separately, our detection achieves an F1 score exceeding 96% in most cases. It even remains above 0.9 under stealthy attack settings, outperforming the state-of-the-art detection by up to 0.25.
Yuxin Wen, Haonan Yan, Yahong Chen, Zhe Sun 0005, Hui Li 0006, Xiaodong Lin 0001
IEEE Trans. Knowl. Data Eng.4
2026 Plog: An Efficient and Privacy-Preserving Collaborative Learning Framework on Vertically Partitioned Graph Data
abstract
With the rapid advancement and widespread ap plication of the graph neural network (GNN), the collaborative graph learning, in which multiple parties collaboratively construct a GNN model using their respective graph data, has attracted increasing attention. However, this paradigm also raises significant privacy concerns, as both nodes and edges may contain sensitive personal information, while existing privacy preserving schemes often come at the cost of degraded model performance or substantial system overhead. Therefore, this paper proposes an efficient and privacy-preserving collaborative, and Hui Li, Member, IEEE, Xiaoyu Kou Social Platform learning framework on vertically partitioned graph data, dubbed Plog. Specifically, we first design a decomposition algorithm to split the sparse adjacency matrix into the summation of multiple independent permutations, which are lightweight, parallelizable, and well-suited for secure multi-party computation. Building on this, a weighted oblivious batch permutation protocol is carefully customized based on correlated randomness to securely and efficiently compute adjacency matrix multiplications, addressing the core efficiency bottleneck in GNN inference and training. The selective security of Plog is formally verified under the ideal-real paradigm. Extensive experimental results on three real world datasets demonstrate that compared to the state-of-the art scheme, Plog can reduce online communication rounds by 46% and achieve a 1.73× speedup in the overall inference and training time.
Jiaqi Zhao 0005, Hui Zhu 0001, Xiaoyu Kou, Haonan Yan, Fengwei Wang, Hui Li 0006
IEEE Trans. Knowl. Data Eng.5
2025 BTCD: Enabling Balanced Toxic Content Detection by Collaborating VLMs and CNNs
Yuantao Jia, Haonan Yan, Zhangyu Gu, Shaopeng Zhou, Chaohao Li
PRCV (6)4
2025 MalAE: A Feature-Optimized and Autoencoder Ensemble-Based Method for IoT Malware Classification
abstract
In the landscape of the Internet of Things (IoT), the rapid evolution and diverse obfuscation tactics of malware render it challenging to detect and identify effectively, posing significant threats to network security. Signature or heuristic methods rely on fixed feature recognition, making it challenging to handle new variants. Recent research has proposed deep learning techniques that utilize static analysis of bytes and images or dynamic analysis of APIs. However, these methods are effective only on samples from the same platform or lead to a dimensional explosion due to excessive irrelevant obfuscation, rendering them inadequate for managing complex cross-platform malware. In this work, we propose a novel lightweight cross-platform malware classification system called MalAE. This system employs a global-local particle swarm optimization algorithm to mine frequent features, adaptively identifying distinct family characteristics and efficiently recognizing variants. An ensemble of autoencoders integrates comprehensive file features and cross-platform basic block features from various perspectives and feature spaces, compressing high-dimensional data into a low-dimensional latent space. This approach preserves essential information, captures nonlinear complex relationships, and facilitates the rapid classification of intricate cross-platform samples. Evaluations conducted on two different datasets demonstrate that MalAE reduces the original feature dimensions by approximately 70% while also enhancing accuracy. Compared to state-of-the-art methods, MalAE achieves superior results, attaining an accuracy of 97.72%.
Chengrun He, Honghui Fan, Lihua Yin, Haonan Yan, Hui Li 0006, Bin Wang 0062
IEEE Internet Things J.4
2025 Efficient and Privacy-Preserving Network Intrusion Detection Based on Federated Learning in SDN-Enabled IIoT Network
abstract
Modern decentralized deep learning methods for network intrusion detection in Software-Defined Networking (SDN)-enabled Industrial Internet of Things (IIoT) environments encounter significant challenges, particularly for IIoT data heterogeneity and privacy leakage. To this end, we propose a novel framework for network intrusion detection, dubbed SFLNID, that improves Federated Learning (FL) to ensure both efficient training and privacy preservation in SDN-enabled IIoT. Specifically, we firstly design joint optimization mechanism for unbalanced and non-IID data, which introduces a Focal loss as the loss function, and leverages the Wasserstein distance between global and local models as the regularization term. In addition, we improve adaptive differential privacy with dynamic gradient clipping techniques, adjusting the clip-threshold based on Holt exponential smoothing to achieve privacy protection during the local model training. Moreover, we develop a customized CNN-GRU model tailored for FL-based network intrusion detection to make a tradeoff between model accuracy and overheads. Theoretical analysis confirms the convergence and privacy guarantees of SFLNID. Extensive experiments, conducted on well-known IIoT datasets including ToN-IoT, RT-IoT and Edge-IIoT, demonstrate that SFLNID outperforms the state-of-the-art methods in terms of detection accuracy, communication overhead, and cooperative privacy preservation.
Tao Hu 0002, Qian Chen 0032, Yuxiang Hu 0004, Saifeng Hou, Haonan Yan, Peng Yi 0003, Zixi Cui
IEEE Internet Things J.5
2025 WinGraphUNet: Advanced windowed graph modeling with remixed contextual learning for efficient medical image segmentation
Xiaoyan Kui, Haonan Yan, Qinsong Li, Lingxiao Liu, Weixin Si, Wei Liang 0005, Beiji Zou 0001
Knowl. Based Syst.2
2025 A Proactive Defense Against Model Poisoning Attacks in Federated Learning
abstract
Model poisoning attacks greatly jeopardize the application of federated learning (FL). The effectiveness of existing defenses is susceptible to the latest model poisoning attacks, leading to a decrease in prediction accuracy. Besides, these defenses are intractable to distinguish benign outliers from malicious gradients, which further compromises the model generalization. In this work, we propose a novel proactive defense named${\sf RECESS}$against model poisoning attacks. Different from the passive analysis in previous defenses,${\sf RECESS}$proactively queries each participating client with a delicately constructed aggregation gradient, accompanied by the detection of malicious clients according to their responses with higher accuracy. Furthermore, RECESS uses a new trust scoring mechanism to robustly aggregate gradients. Unlike previous methods that score each iteration, RECESS considers clients’ performance correlation across multiple iterations to estimate the trust score, substantially increasing fault tolerance. Finally, we extensively evaluate${\sf RECESS}$on typical model architectures and four datasets under various settings. We also evaluated the defensive effectiveness against other types of poisoning attacks, the sensitivity of hyperparameters, and adaptive adversarial attacks. Experimental results show the superiority of${\sf RECESS}$in terms of reducing accuracy loss caused by the latest model poisoning attacks over five classic and two state-of-the-art defenses.
Haonan Yan, Chengbo Zheng, Qian Chen 0032, Bin Wang 0062, Hui Li 0006, Xiaodong Lin 0001
IEEE Trans. Dependable Secur. Comput.1
2025 ChebMixer: Efficient Graph Representation Learning With MLP Mixer
abstract
Graph neural networks (GNNs) have achieved remarkable success in learning graph representations, especially graph Transformers, which have recently shown superior performance on various graph mining tasks. However, the graph Transformer generally treats nodes as tokens, which results in quadratic complexity regarding the number of nodes during self-attention computation. The graph multilayer perceptron (MLP) mixer addresses this challenge using the efficient MLP Mixer technique from computer vision. However, the time-consuming process of extracting graph tokens limits its performance. In this article, we present a novel architecture named ChebMixer, a newly proposed graph MLP Mixer that uses fast Chebyshev polynomials-based spectral filtering to extract a sequence of tokens. First, we produce multiscale representations of graph nodes via fast Chebyshev polynomial-based spectral filtering. Next, we consider each node's multiscale representations as a sequence of tokens and refine the node representation with an effective MLP Mixer. Finally, we aggregate the multiscale representations of nodes through Chebyshev interpolation. Owing to the powerful representation capabilities and fast computational properties of the MLP Mixer, we can quickly extract more informative node representations to improve the performance of downstream tasks. The experimental results prove our significant improvements in various scenarios, ranging from homogeneous and heterophilic graph node classification to medical image segmentation. Compared with NAGphormer, the average performance improved by 1.45% on homogeneous graphs and 4.15% on heterophilic graphs. And the average performance improved by 1.39% on medical image segmentation tasks compared with VM-UNet. We will release the source code after this article is accepted.
Xiaoyan Kui, Haonan Yan, Qinsong Li, Liming Chen 0002, Beiji Zou 0001
IEEE Trans. Neural Networks Learn. Syst.2
2025 DeFedGCN: Privacy-Preserving Decentralized Federated GCN for Recommender System
abstract
Federated recommender system (RS), a prevailing distributed paradigm, has been spawning significant interest in exploiting locally stored but tremendous data to predict items best aligned with clients. However, federated RS suffers severely from a single point of failure due to the dependency on the central server, leading to potential denial of service (DoS) attacks. To address this security weakness, in this paper, we propose a decentralized privacy-preserving federated graph convolutional network for RS, dubbed DeFedGCN. Specifically, DeFedGCN aggregates local updates by a decentralized consensus-reaching process and customizes local models for personalized recommendation, where the aggregation is enhanced by local differential privacy to resist model inversion attacks. More importantly, to promote the recommendation performance, DeFedGCN conducts asub-graph expansionbased on the private set interaction to explore high-order interactions among clients and items. Theoretical analysis confirms the effectiveness and privacy guarantee of DeFedGCN. Additionally, we conduct extensive experiments on four widespread real-world databases. The recommendation performance of DeFedGCN outperforms the state-of-the-art federated RS algorithms without security protection against DoS attacks by up to 7.4%.
Qian Chen 0032, Zilong Wang 0001, Mengqing Yan, Haonan Yan, Xiaodong Lin 0001, Jianying Zhou 0001
IEEE Trans. Serv. Comput.4
2024 EL-FDL: Improving Image Forgery Detection and Localization via Ensemble Learning
Jingge Wang, Haonan Yan, Shaopeng Zhou, Chaohao Li
ICANN (2)4
2024 PAGE: Equilibrate Personalization and Generalization in Federated Learning
abstract
Federated learning (FL) is becoming a major driving force behind machine learning as a service, where customers (clients) collaboratively benefit from shared local updates under the orchestration of the service provider (server). Representing clients' current demands and the server's future demand, local model personalization and global model generalization are separately investigated, as the ill-effects of data heterogeneity enforce the community to focus on one over the other. However, these two seemingly competing goals are of equal importance rather than black and white issues, and should be achieved simultaneously. In this paper, we propose the first algorithm to balance personalization and generalization on top of game theory, dubbed PAGE, which reshapes FL as a co-opetition game between clients and the server. To explore the equilibrium, PAGE further formulates the game as Markov decision processes, and leverages the reinforcement learning algorithm, which simplifies the solving complexity. Extensive experiments on four widespread datasets show that PAGE outperforms state-of-the-art FL baselines in terms of global and local prediction accuracy simultaneously, and the accuracy can be improved by up to 35.20% and 39.91%, respectively. In addition, biased variants of PAGE imply promising adaptiveness to demand shifts in practice.
Qian Chen 0032, Zilong Wang 0001, Jiaqi Hu 0003, Haonan Yan, Jianying Zhou 0001, Xiaodong Lin 0001
WWW4
2024 QP-LDP for Better Global Model Performance in Federated Learning
abstract
Federated learning (FL) enhanced by local differential privacy (LDP) has gained promising privacy-preserving capabilities against privacy attacks on local contributions. In this context, noise-discounting LDP methods have been widely investigated to provide better model performance and stronger privacy guarantees. However, prior art calibrate privacy guarantees by distinct LDP definitions, resulting in nonuniform privacy-preserving capabilities. In this article, aligned with the standard LDP definition, we proposed QP-LDP, a noise-discounting algorithm for FL, which can yield better model performance without any privacy loss. Specifically, QP-LDP precisely disturbs noncommon components of quantized local contributions, which are selected by an extended multiparty private set intersection process. In particular, QP-LDP can comprehensively protect two types of local contributions, i.e., local models and gradients for prevailing FedAvg and FedSGD, respectively. Through theoretical analysis, QP-LDP provides component-level indistinguishability for clients’ private local contributions and rigorous convergence guarantees for the global model. Extensive experiments on four widespread databases show that, compared to the standard LDP method, the global model prediction accuracy and convergence rate achieved by QP-LDP can be improved by up to 14.99% and 23.08%, respectively. More importantly, QP-LDP achieves the same level of privacy-preserving capabilities against privacy attacks as the standard LDP method.
Qian Chen 0032, Zilong Wang 0001, Haonan Yan, Xiaodong Lin 0001, Jianying Zhou 0001
IEEE Internet Things J.4
2024 CODER: Protecting Privacy in Image Retrieval With Differential Privacy
abstract
Image retrieval techniques can be easily abused to violate personal privacy with images containing individuals' sensitive information. For example, people's identity information can be inferred from their face photos. Therefore, images should be sanitized before being shared or transmitted. However, previous works on image privacy protection suffer from either no provable privacy protection or poor utility with privacy guarantee. In this work, we proposeCODER, a privacy protection mechanism in image retrieval, with provable privacy guarantee as well as improved utility. In particular,CODERachieves metric differential privacy and adopts a newly proposed distortion metric definition which measures the distance more precisely to improve utility. The novel distortion metric can be applied to an arbitrary k-dimensional metric space with stronger image privacy protection. We theoretically analyze the privacy guarantee and rigorous utility bound ofCODER. We also experimentally compare its performance with two state-of-the-art works on two widely used face datasets. The results show thatCODERsignificantly improves the utility of the protected images and demonstrates its superiority in terms of the privacy-utility trade-off over the compared works. Finally, we perform reliability verification on both discriminative and generative models to demonstrate the practicality ofCODER
Haonan Yan, Wenjing Zhang 0002, Qian Chen 0032, Bin Wang 0062, Hui Li 0006, Xiaodong Lin 0001
IEEE Trans. Dependable Secur. Comput.1
2024 Automatic Evasion of Machine Learning-Based Network Intrusion Detection Systems
abstract
Network intrusion detection systems (IDS) are often considered effective to thwart cyber attacks. Currently, state-of-the-art (SOTA) IDSs are mainly based on machine learning (ML) including deep learning (DL) models, which suffer from their own security issues, especially evasion attacks by using adversarial examples. However, previous studies mostly focus on extracted features rather than the traffic sample itself, and/or assume that the adversary knows the information of the target model more or less, which severely restricts attack feasibility in practice. In this paper, we re-investigate this problem in a more realistic label-only black-box scenario and propose a practical evasion attack strategy to solve the above limitations. In this newly considered case that the adversary morphs the traffic sample and only obtains the results accepted or rejected without other knowledge, we successfully leverage the model extraction and transfer attack to evade the detection. The entire attack strategy is automated and a comprehensive evaluation is performed. Final results show that the proposed strategy effectively evades seven typical ML-based IDSs and one SOTA DL-based IDS with an average success rate of over$75\%$. We also discuss the corresponding countermeasures against our attack, which finally highlight the need for effective defenses against our attack.
Haonan Yan, Wenjing Zhang 0002, Hui Li 0006, Xingwen Zhao, Fenghua Li 0001, Xiaodong Lin 0001
IEEE Trans. Dependable Secur. Comput.1
2023 Class Attention Transfer Based Knowledge Distillation
abstract
Previous knowledge distillation methods have shown their impressive performance on model compression tasks, however, it is hard to explain how the knowledge they transferred helps to improve the performance of the student network. In this work, we focus on proposing a knowledge distillation method that has both high interpretability and competitive performance. We first revisit the structure of mainstream CNN models and reveal that possessing the capacity of identifying class discriminative regions of input is critical for CNN to perform classification. Furthermore, we demonstrate that this capacity can be obtained and enhanced by transferring class activation maps. Based on our findings, we propose class attention transfer based knowledge distillation (CAT-KD). Different from previous KD methods, we explore and present several properties of the knowledge transferred by our method, which not only improve the interpretability of CAT-KD but also contribute to a better understanding of CNN. While having high interpretability, CAT-KD achieves state-of-the-art performance on multiple benchmarks. Code is available at: https://github.com/GzyAftermath/CAT-KD.
Ziyao Guo, Haonan Yan, Hui Li 0006, Xiaodong Lin 0001
CVPR2
2023 RECESS Vaccine for Federated Learning: Proactive Defense Against Model Poisoning Attacks
abstract
Model poisoning attacks greatly jeopardize the application of federated learning (FL). The effectiveness of existing defenses is susceptible to the latest model poisoning attacks, leading to a decrease in prediction accuracy. Besides, these defenses are intractable to distinguish benign outliers from malicious gradients, which further compromises the model generalization. In this work, we propose a novel defense including detection and aggregation, named RECESS, to serve as a “vaccine” for FL against model poisoning attacks. Different from the passive analysis in previous defenses, RECESS proactively queries each participating client with a delicately constructed aggregation gradient, accompanied by the detection of malicious clients according to their responses with higher accuracy. Further, RECESS adopts a newly proposed trust scoring based mechanism to robustly aggregate gradients. Rather than previous methods of scoring in each iteration, RECESS takes into account the correlation of clients’ performance over multiple iterations to estimate the trust score, bringing in a significant increase in detection fault tolerance. Finally, we extensively evaluate RECESS on typical model architectures and four datasets under various settings including white/black-box, cross-silo/device FL, etc. Experimental results show the superiority of RECESS in terms of reducing accuracy loss caused by the latest model poisoning attacks over five classic and two state-of-the-art defenses.
Haonan Yan, Wenjing Zhang 0002, Qian Chen 0032, Wenhai Sun, Hui Li 0006, Xiaodong Lin 0001
NeurIPS1
2023 Protecting Regression Models With Personalized Local Differential Privacy
abstract
The equation-solving model extraction attack is an intuitively simple but devastating attack to steal confidential information of regression models through a sufficient number of queries. Complete mitigation is difficult. Thus, the development of countermeasures is focused on degrading the attack effectiveness as much as possible without losing the model utilities. We investigate a novel personalized local differential privacy mechanism to defend against the attack. We obfuscate the model by adding high-dimensional Gaussian noise on model coefficients. Our solution can adaptively produce the noise to protect the model on the fly. We thoroughly evaluate the performance of our mechanisms using real-world datasets. The experiment shows that the proposed scheme outperforms the existing differential-privacy-enabled solution, i.e., 4 times more queries are required to achieve the same attack result. We also plan to publish the relevant codes to the community for further research.
Haonan Yan, Zelei Cheng, Wenhai Sun, Hui Li 0006
IEEE Trans. Dependable Secur. Comput.2
2023 Dap-FL: Federated Learning Flourishes by Adaptive Tuning and Secure Aggregation
abstract
Federated learning (FL), an attractive and promising distributed machine learning paradigm, has sparked extensive interest in exploiting tremendous data stored on ubiquitous mobile devices. However, conventional FL suffers severely from resource heterogeneity, as clients with weak computational and communication capabilities may be unable to complete local training using the same local training hyper-parameters. In this article, we propose Dap-FL, a deep deterministic policy gradient (DDPG)-assisted adaptive FL system, in which local learning rates and local training epochs are adaptively adjusted by all resource-heterogeneous clients through locally deployed DDPG-assisted adaptive hyper-parameter selection schemes. Particularly, the rationality of the proposed hyper-parameter selection scheme is confirmed through rigorous mathematical proof. Besides, due to the thoughtlessness of security consideration of adaptive FL systems in previous studies, we introduce the Paillier cryptosystem to aggregate local models in a secure and privacy-preserving manner. Rigorous analyses show that the proposed Dap-FL system could protect clients’ private local models against chosen-plaintext attacks and chosen-message attacks in a widely used honest-but-curious participants and active adversaries security model. More importantly, through ingenious and extensive experiments, the proposed Dap-FL achieves higher model prediction accuracy than two state-of-the-art RL-assisted FL methods, i.e., 6.03% higher than DDPG-based FL and 7.85% higher than DQN-based FL. In addition, experimental results also show that the proposed Dap-FL achieves higher global model prediction accuracy and faster convergence rates than conventional FL, and the comprehensiveness of the adjusted local training hyper-parameters is validated.
Qian Chen 0032, Zilong Wang 0001, Jiawei Chen 0010, Haonan Yan, Xiaodong Lin 0001
IEEE Trans. Parallel Distributed Syst.4
2022 BodyGAN: General-purpose Controllable Neural Human Body Generation
abstract
Recent advances in generative adversarial networks (GANs) have provided potential solutions for photo-realistic human image synthesis. However, the explicit and individual control of synthesis over multiple factors, such as poses, body shapes, and skin colors, remains difficult for existing methods. This is because current methods mainly rely on a single pose/appearance model, which is limited in dis-entangling various poses and appearance in human images. In addition, such a unimodal strategy is prone to causing severe artifacts in the generated images like color distortions and unrealistic textures. To tackle these issues, this paper proposes a multi-factor conditioned method dubbed BodyGAN. Specifically, given a source image, our Body-GAN aims at capturing the characteristics of the human body from multiple aspects: (i) A pose encoding branch consisting of three hybrid subnetworks is adopted, to generate the semantic segmentation based representation, the 3D surface based representation, and the key point based rep-resentation of the human body, respectively. (ii) Based on the segmentation results, an appearance encoding branch is used to obtain the appearance information of the human body parts. (iii) The outputs of these two branches are represented by user-editable condition maps, which are then processed by a generator to predict the synthesized image. In this way, our BodyGAN can achieve the fine-grained dis-entanglement of pose, body shape, and appearance, and consequently enable the explicit and effective control of syn-thesis with diverse conditions. Extensive experiments on multiple datasets and a comprehensive user study show that our BodyGAN achieves the state-of-the-art performance.
Chaojie Yang, Shengjie Wu, Shengkai Zhang, Haonan Yan, Nianhong Jiao, Runnan Zhou, Xiaodan Liang, Tianxiang Zheng 0001
CVPR5
2022 ARCANE: An Efficient Architecture for Exact Machine Unlearning
abstract
Recently users’ right-to-be-forgotten is stipulated by many laws and regulations. However, only removing the data from the dataset is not enough, as machine learning models would memorize the training data once the data is involved in model training, increasing the risk of exposing users’ privacy. To solve this problem, currently, the straightforward method, naive retraining, is to discard these data and retrain the model from scratch, which is reliable but brings much computational and time overhead. In this paper, we propose an exact unlearning architecture called ARCANE. Based on ensemble learning, we transform the naive retraining into multiple one-class classification tasks to reduce retraining cost while ensuring model performance, especially in the case of a large number of unlearning requests not considered by previous works. Then we further introduce data preprocessing methods to reduce the retraining overhead and speed up the unlearning, which includes representative data selection for redundancy removal, training state saving to reuse previous calculation results, and sorting to cope with unlearning requests of different distributions. We extensively evaluate ARCANE on three typical datasets with three common model architectures. Experiment results show the effectiveness and superiority of ARCANE over both the naive retraining and the state-of-the-art method in terms of model performance and unlearning speed.
Haonan Yan, Ziyao Guo, Hui Li 0006, Fenghua Li 0001, Xiaodong Lin 0001
IJCAI1
2022 QP-LDP for better global model performance in federated learning
abstract
With the deployment of local differential privacy (LDP), federated learning (FL) has gained stronger privacy-preserving capability against inference-type attacks. However, existing LDP methods reduce global model performance. In this paper, we propose a QP-LDP algorithm for FL to obtain a better-performed global model without losing privacy guarantees defined by the original LDP. Different from previous LDP methods for FL, QP-LDP improves the global model performance by precisely disturbing the non-common components of quantized local contributions. In addition, QP-LDP comprehensively protects two types of local contributions. Through security analysis, QP-LDP provides the probability indistinguishability of clients' private local contributions at a component-level. More importantly, ingenious experiments show that with the deployment of QP-LDP, the global model outperforms that in the original LDP-based FL in terms of prediction accuracy and convergence rate.
Qian Chen 0032, Zilong Wang 0001, Jiawei Chen 0010, Haonan Yan, Xiaodong Lin 0001
MSN5
2022 LLDP: A Layer-wise Local Differential Privacy in Federated Learning
abstract
Federated learning (FL) combined with local differential privacy (LDP) has attracted considerable attention due to its privacy-preserving capability against inference-type attacks, e.g., model inversion attacks and membership inference attacks. However, the noise introduced by LDP reduces the global model performance, while decreasing the noise by setting a larger privacy budget sacrifices the privacy guarantees. In this paper, we propose a layer-wise LDP for the FL system, dubbed LLDP, which disturbs various layers of a local model according to clients’ self-assigned privacy budgets. With the deployment of LLDP, clients could train a highly accurate and rapid-converged global model without loosing privacy guarantees. Through extensive security analyses, the proposed LLDP scheme helps the entire local model achieve (ε,δ)-LDP, and the probability indistinguishability of the local model is achieved under the widespread semi-honest threat model. Ingenious experiments show that LLDP improves the global model prediction and convergence rate by 3.38% and 4.76% on the CIFAR-10 dataset compared to the state-of-the-art LDP method with the same privacy budget. In addition, given the same training target (loss value), LLDP requires a 26.67% lower privacy budget, providing stronger privacy guarantees against model inversion attacks.
Qian Chen 0032, Zilong Wang 0001, Jiawei Chen 0010, Haonan Yan, Xiaodong Lin 0001
TrustCom5
2022 MARS: Automated Protocol Analysis Framework for Internet of Things
abstract
Internet of Things (IoT) devices generate a massive quantity of network traffic every moment, which undoubtedly poses an urgent demand for an accurate and efficient network protocol analysis tool in cyberspace management and security. However, the existing popular methods have limitations, such as incomplete functionality and insufficient accuracy. For example, the large number of novel network applications brings unprecedented protocols for protocol analysis, which greatly limit the analysis capabilities of existing tools. In this article, we devise an automated protocol analysis framework for IoT devices calledMARSto solve these problems. To the best of our knowledge, this is the first unified framework including all three analysis stages: 1) classifying protocol; 2) analyzing the protocol phase; and 3) parsing the protocol field. At each stage, we provide effective solutions to solve the corresponding tasks and improve the efficiency of protocol analysis.MARScan also deal with unknown protocols that are common in IoT scenarios but are rarely concerned by previous works. Finally, we develop a distributed computing engine to ensure the high throughput and processing speed of the whole framework for the huge amount of network traffic. The evaluation on a variety of different protocols shows the superiority of ourMARSover previous works in terms of comprehensiveness and accuracy.
Haonan Yan, Hui Li 0006, Xingwen Zhao, Fenghua Li 0001
IEEE Internet Things J.1
2022 Monitoring-Based Differential Privacy Mechanism Against Query Flooding-Based Model Extraction Attack
abstract
Public intelligent services enabled by machine learning algorithms are vulnerable to model extraction attacks that can steal confidential information of the learning models through public queries. Though there are some protection options such as differential privacy (DP) and monitoring, which are considered promising techniques to mitigate this attack, we still find that the vulnerability persists. In this article, we propose an adaptivequery-flooding parameter duplication(QPD) attack. The adversary can infer the model information with black-box access and no prior knowledge of any model parameters or training data via QPD. We also develop a defense strategy using DP called monitoring-based DP (MDP) against this new attack. In MDP, we first propose a novel real-timemodel extraction status assessmentscheme calledMonitorto evaluate the situation of the model. Then, we design a method to guide the differential privacy budget allocation called APBA adaptively. Finally, all DP-based defenses with MDP could dynamically adjust the amount of noise added in the model response according to the result fromMonitorand effectively defends the QPD attack. Furthermore, we thoroughly evaluate and compare the QPD attack and MDP defense performance on real-world models with DP and monitoring protection.
Haonan Yan, Hui Li 0006, Wenhai Sun, Fenghua Li 0001
IEEE Trans. Dependable Secur. Comput.1
2021 UltraPose: Synthesizing Dense Pose with 1 Billion Points by Human-body Decoupling 3D Model
abstract
Recovering dense human poses from images plays a critical role in establishing an image-to-surface correspondence between RGB images and the 3D surface of the human body, serving the foundation of rich real-world applications, such as virtual humans, monocular-to-3d reconstruction. However, the popular DensePose-COCO dataset relies on a sophisticated manual annotation system, leading to severe limitations in acquiring the denser and more accurate annotated pose resources. In this work, we introduce a new 3D human-body model with a series of decoupled parameters that could freely control the generation of the body. Furthermore, we build a data generation system based on this decoupling 3D model, and construct an ultra dense synthetic benchmark UltraPose, containing around 1.3 billion corresponding points. Compared to the existing manually annotated DensePose-COCO dataset, the synthetic UltraPose has ultra dense image-to-surface correspondences without annotation cost and error. Our proposed UltraPose provides the largest benchmark and data resources for lifting the model capability in predicting more accurate dense poses. To promote future researches in this field, we also propose a transformer-based method to model the dense correspondence between 2D and 3D worlds. The proposed model trained on synthetic UltraPose can be applied to real-world scenarios, indicating the effectiveness of our benchmark and model.1
Haonan Yan, Xujie Zhang, Shengkai Zhang, Nianhong Jiao, Xiaodan Liang, Tianxiang Zheng 0001
ICCV1
2021 WAS-VTON: Warping Architecture Search for Virtual Try-on Network
abstract
Despite recent progress on image-based virtual try-on, current methods are constraint by shared warping networks and thus fail to synthesize natural try-on results when faced with clothing categories that require different warping operations. In this paper, we address this problem by finding clothing category-specific warping networks for the virtual try-on task via Neural Architecture Search (NAS). We introduce a NAS-Warping Module and elaborately design a bilevel hierarchical search space to identify the optimal network-level and operation-level flow estimation architecture. Given the network-level search space, containing different numbers of warping blocks, and the operation-level search space with different convolution operations, we jointly learn a combination of repeatable warping cells and convolution operations specifically for the clothing-person alignment. Moreover, a NAS-Fusion Module is proposed to synthesize more natural final try-on results, which is realized by leveraging particular skip connections to produce better-fused features that are required for seamlessly fusing the warped clothing and the unchanged person part. We adopt an efficient and stable one-shot searching strategy to search the above two modules. Extensive experiments demonstrate that our WAS-VTON significantly outperforms the previous fixed-architecture try-on methods with more natural warping results and virtual try-on results.
Zhenyu Xie, Xujie Zhang, Fuwei Zhao, Haoye Dong, Michael Kampffmeyer, Haonan Yan, Xiaodan Liang
ACM Multimedia6
2019 PGSM-DPI: Precisely Guided Signature Matching of Deep Packet Inspection for Traffic Analysis
abstract
In the field of network traffic analysis, Deep Packet Inspection (DPI) technology is widely used at present. However, the increase in network traffic has brought tremendous processing pressure on the DPI. Consequently, detection speed has become the bottleneck of the entire application. In order to speed up the traffic detection of DPI, a lot of research works have been applied to improve signature matching algorithms, which is the most influential factor in DPI performance. In this paper, we present a novel method from a different angle called Precisely Guided Signature Matching (PGSM). Instead of matching packets with signature directly, we use supervised learning to automate the rules of specific protocol in PGSM. By testing the performance of a packet in the rules, the target packet could be decided when and which signatures should be matched with. Thus, the PGSM method reduces the number of aimless matches which are useless and numerous. After proposing PGSM, we build a framework called PGSM-DPI to verify the effectiveness of guidance rules. The PGSM-DPI framework consists of PGSM method and open source DPI library. The framework is running on a distributed platform with better throughput and computational performance. Finally, the experimental results demonstrate that our PGSM-DPI can reduce 59.23% original DPI time and increase 21.31% throughput. Besides, all source codes and experimental results can be accessed on our GitHub.
Haonan Yan, Hui Li 0006, Mingchi Xiao, Xianchun Zheng, Xingwen Zhao, Fenghua Li 0001
GLOBECOM1
2016 A top-down SCMA codebook design scheme based on lattice theory
abstract
Recent work on multiple access has shown sparse code multiple access (SCMA) is a promising scheme dealing with massive connection. In SCMA systems, symbol spreading is combined with symbol mapping. The coded bits are directly mapped to the spread symbols, called codewords, according to SCMA codebook. Several codewords are superposed on the same resource. Since codebook is essential to SCMA system performance, this paper aims to present a novel top-down codebook design scheme for SCMA. Firstly, a geometrically uniform top-layer mother constellation with good energy efficiency is proposed based on lattice theory. After dividing the top layer constellation into several bottom layer constellations, we use matrix operation to optimize their distance spectrums. Then a mapping principle between users and resource is proposed to construct the final codewords. Simulation results shows that this top-down codebook outperforms existing schemes in bit error ratio (BER) while sharply reduce the peak to average power ratio (PAPR).
Haonan Yan, Zhaobiao Lv, Haojun Yang
PIMRC1