EDBT 2026 Demo / reviewers in the wild / expert
Lele Zheng
dblp:213/2715
· DBLP profile ↗
13ranked-venue papers
4as first author
11since 2021 · last 2026
0000-0003-0094-2842ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 2 first-author · 5 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 4 since 2021Computer networks · 3 · 1 first-author · 2 since 2021Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Differentially Private Subspace Fine-Tuning for Large Language ModelsabstractFine-tuning large language models on downstream tasks is crucial for realizing their cross-domain potential but often relies on sensitive data, raising privacy concerns. Differential privacy (DP) offers rigorous privacy guarantees and has been widely adopted in fine-tuning; however, naively injecting noise across the high-dimensional parameter space creates perturbations with large norms, degrading performance and destabilizing training. To address this issue, we propose DP-SFT, a two-stage subspace fine-tuning method that substantially reduces noise magnitude while preserving formal DP guarantees. Our intuition is that, during fine-tuning, significant parameter updates lie within a low-dimensional, task-specific subspace, while other directions change minimally. Hence, we only inject DP noise into this subspace to protect privacy without perturbing irrelevant parameters. In phase one, we identify the subspace by analyzing principal gradient directions to capture task-specific update signals. In phase two, we project full gradients onto this subspace, add DP noise, and map the perturbed gradients back to the original parameter space for model updates, markedly lowering noise impact. Experiments on multiple datasets demonstrate that DP-SFT enhances accuracy and stability under rigorous DP constraints, accelerates convergence, and achieves substantial gains over DP fine-tuning baselines. Lele Zheng, Xiang Wang 0009, Tao Zhang 0029, Yang Cao 0011, Ke Cheng 0001, Yulong Shen 0001 |
AAAI | 1 |
| 2026 | FedAMM: Mitigating Shared Parameter Drift in Personalized Federated Learning via Momentum-Guided Server Aggregation
Tao Zhang 0029, Lele Zheng, Feiyang Yuan |
KSEM (4) | 3 |
| 2026 | Knowledge concept cold-start approach for cognitive diagnosis
Miao Zhang 0036, Huihuan Li, Lele Zheng, Shunfeng Tan, Chao Yang 0043, Kui Xiao, Zhifang Huang, Zhifei Li 0009 |
Neurocomputing | 3 |
| 2025 | Alternating Aggregation Low-Rank Adaptation Approach for Federated Large Models
Tao Zhang 0029, Feiyang Yuan, Lele Zheng, Yiyun Guo |
ADMA (1) | 4 |
| 2025 | MMGIA: Gradient Inversion Attack Against Multimodal Federated Learning via Intermodal CorrelationabstractMultimodal federated learning (MMFL) enables collaborative model training across multiple modalities, such as images and text, without requiring direct data sharing. However, the inherent correlations between modalities introduce new privacy vulnerabilities, making MMFL more susceptible to gradient inversion attacks. In this work, we propose MMGIA, an intermodal correlation-driven gradient inversion attack that systematically exploits multimodal correlation to enhance data reconstruction quality. MMGIA consists of a two-stage optimization framework: the first stage independently reconstructs each modality using traditional gradient inversion techniques, while the second stage refines these reconstructions through pre-trained feature extractors to align modalities in a shared latent space. To further improve reconstruction accuracy, we introduce a quality-weighted fusion strategy, which dynamically integrates multimodal embeddings into a global fused representation that serves as a guiding signal for refining each modality’s reconstruction. This ensures that high-quality reconstructions contribute more to the optimization process, preventing degradation in well-reconstructed modalities while enhancing weaker ones. We conduct extensive experiments on multiple multimodal scenarios, demonstrating that MMGIA outperforms both the only existing multimodal attack and state-of-the-art single-modal attacks, revealing the heightened privacy risks in MMFL. Lele Zheng, Yang Cao 0011, Leo Yu Zhang, Wei Wang 0077, Yulong Shen 0001, Xiaochun Cao |
IJCAI | 1 |
| 2025 | Privacy in Fine-Tuning Large Language Models: Attacks, Defenses, and Future Directions
Shang Liu 0001, Lele Zheng, Yang Cao 0011, Atsuyoshi Nakamura |
PAKDD (4) | 3 |
| 2024 | Enhancing Privacy of Spatiotemporal Federated Learning Against Gradient Inversion Attacks
Lele Zheng, Yang Cao 0011, Renhe Jiang, Kenjiro Taura, Yulong Shen 0001, Sheng Li 0010, Masatoshi Yoshikawa |
DASFAA (1) | 1 |
| 2023 | LoCount: Long-distance Crowd Counting Based on LoRa SignalabstractCrowd counting, which counts or estimates the number of people within a region, is critical in many applications, such as guided tours and disaster rescue. Several RF-based contact-free crowd counting techniques have been proposed in recent years, including WiFi, RFID, and millimeter wave radar. While promising in many aspects, one key limitation of current techniques is the small sensing range. However, many applications of crowd counting do require long-range sensing capability. In this work, we propose LoCount to significantly increase the sensing range of crowd counting using LoRa, which is a new wireless technology for long range communications among IoT devices. In particular, to solve the system performance degradation caused by different environments, we try to remove the components representing surrounding environments from the signal and use adversarial domain adaptation to extract environment-independent features. Considering that we may have multiple different source domains, for the target domain data, we comprehensively think over its similarity to each source domain and the prediction results to get the final result. We test LoCount in multiple large-scale scenes, and the results show that LoCount can achieve an average accuracy of 97.0% in the target domain without labeled data. Sihan Ma, Xiangmao Chang, Lele Zheng |
MSN | 4 |
| 2023 | A Task-based Personalized Privacy-Preserving Participant Selection Mechanism for Mobile Crowdsensing
Lele Zheng, Tao Zhang 0029, Yulong Shen 0001, Ze Tong |
Mob. Networks Appl. | 1 |
| 2022 | HyperMean: Effective Multidimensional Mean Estimation with Local Differential PrivacyabstractMultidimensional mean estimation with local differential privacy (LDP) extracts the numerical features from groups while protecting users’ personal information without relying on a trusted server. However, the increase of dimensionality would lead to a deficiency in the allocable privacy budget, resulting in excessive accuracy loss. To solve this problem, we propose HyperMean, an effective privacy-preserving mean estimation mechanism for multidimensional data whose accuracy is at least no worse (and better in most cases) than existing solutions. We first design a multidimensional staircase function to obfuscate users’ data, significantly reducing the output variance. Second, an adaptive dimensionality reduction is performed on users’ data to allocate the privacy budget to some focused dimensions. Finally, the server averages all users’ obfuscated outputs to obtain an unbiased estimate of the mean results. Theoretical analysis reveals that HyperMean effectively reduces the worst-case variance of multidimensional mean estimation under LDP while maintaining low computational complexity. Experiments on both simulated and real-world datasets show that HyperMean outperforms existing multidimensional mean estimation mechanisms in terms of aggregated error. Tao Zhang 0029, Lele Zheng, Ze Tong, Qi Li 0011 |
TrustCom | 3 |
| 2021 | Towards Time-Sensitive and Verifiable Data Aggregation for Mobile CrowdsensingabstractMobile crowdsensing systems use the extraction of valuable information from the data aggregation results of large-scale IoT devices to provide users with personalized services. Mobile crowdsensing combined with edge computing can improve service response speed, security, and reliability. However, previous research on data aggregation paid little attention to data verifiability and time sensitivity. In addition, existing edge-assisted data aggregation schemes do not support access control of large-scale devices. In this study, we propose a time-sensitive and verifiable data aggregation scheme (TSVA-CP-ABE) supporting access control for edge-assisted mobile crowdsensing. Specifically, in our scheme, we use attribute-based encryption for access control, where edge nodes can help IoT devices to calculate keys. Moreover, IoT devices can verify outsourced computing, and edge nodes can verify and filter aggregated data. Finally, the security of the proposed scheme is theoretically proved. The experimental results illustrate that our scheme outperforms traditional ones in both effectiveness and scalability under time-sensitive constraints. Tao Zhang 0029, Xiongfei Song, Lele Zheng, Yani Han, Kai Zhang 0044, Qi Li 0011 |
Secur. Commun. Networks | 3 |
| 2020 | A Lightweight Auction Framework for Spectrum Allocation with Strong Security GuaranteesabstractAuction is an effective mechanism to distribute spectrum resources. Although many privacy-preserving auction schemes for spectrum allocation have been proposed, none of them is able to perform practical spectrum auctions while ensuring enough security for bidders' private information, such as geo-locations, bid values, and data access patterns. To address this problem, we propose SLISA, a lightweight auction framework which enables an efficient spectrum allocation without revealing anything but the auction outcome, i.e., the winning bidders and their clearing prices. We present contributions on two fronts. First, as a foundation of our design, we adopt a Shuffle-then-Compute strategy to build a series of secure sub-protocols based on lightweight cryptographic primitives (e.g., additive secret sharing and basic garbled circuits). Second, we improve an advanced spectrum auction mechanism to make it data-oblivious, such that data access patterns can be hidden. Meanwhile, the modified protocols adapt to our elaborate building blocks without affecting its validity and security. We formally prove the security of all protocols under a semi-honest adversary model, and demonstrate performance improvements compared with state-of-the-art works through extensive experiments. Ke Cheng 0001, Liangmin Wang 0001, Yulong Shen 0001, Yongzhi Wang 0001, Lele Zheng |
INFOCOM | 6 |
| 2018 | Trustworthy service composition with secure data transmission in sensor networks
Tao Zhang 0029, Lele Zheng, Yongzhi Wang 0001, Yulong Shen 0001, Ning Xi 0002, Jianfeng Ma 0001, Jianming Yong |
World Wide Web | 2 |