EDBT 2026 Demo / reviewers in the wild / expert
Jiale Zhang 0001
dblp:218/2216-1
· DBLP profile ↗
55ranked-venue papers
16as first author
45since 2021 · last 2026
0000-0002-2143-5666ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 13 · 5 first-author · 6 since 2021Artificial intelligence and machine learning · 12 · 4 first-author · 12 since 2021Security and privacy · 10 · 4 first-author · 10 since 2021Software engineering, systems software and programming languages · 8 · 1 first-author · 8 since 2021Systems, architecture and hardware · 7 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MultiKD: Backdoor Defense in Federated Graph Learning via Attention-Guided Multi-Teacher DistillationabstractBackdoor attacks pose a severe threat to federated graph learning (FGL), where malicious clients can inject hidden triggers into the global model without being detected. Defending against such attacks is particularly challenging due to the complex graph structures and the stealthy nature of trigger patterns. In this work, we propose MultiKD, a novel backdoor mitigation method based on attention-guided multi-teacher distillation. Unlike existing defenses that focus on detecting suspicious clients or restricting backdoor activation, MultiKD directly purifies the global model on the server side by exploiting intermediate representations. It integrates knowledge from multiple client models and guides the global model to suppress backdoor behaviors by aligning attention maps and preserving inter-layer relational consistency. Our defensive intuition enables MultiKD to retain task-relevant information while mitigating malicious patterns, even when some teacher models are compromised. Extensive experiments on four real-world datasets demonstrate the effectiveness of our approach in significantly reducing attack success rate (≤ 8%) with minimal impact on utility (≤ 5%). Jiale Zhang 0001, Bosen Rao, Xiaobing Sun 0001, Yu Li 0022 |
AAAI | 1 |
| 2026 | GResMark: A swin transformer-based watermarking framework with geometric attack resilience
Weitong Chen 0002, Jiale Zhang 0001, Chunpeng Ge 0001, Di Wu 0050, Willy Susilo, Palaiahnakote Shivakumara |
Expert Syst. Appl. | 3 |
| 2026 | Infer-Shield: Defending against membership inference attacks in heterogeneous federated learning via adaptive distillation
Saeed-Uz-Zaman, Jiale Zhang 0001, Muhammad Hamid |
J. Inf. Secur. Appl. | 2 |
| 2026 | Explanation-guided backdoor defense for ID and OOD attacks in graph neural networks
Hao Sui 0003, Bing Chen 0002, Jiale Zhang 0001, Di Wu 0050, Palaiahnakote Shivakumara |
Pattern Recognit. | 3 |
| 2026 | GDetox: Purifying Backdoor Encoder in Graph Self-Supervised Learning via Knowledge DistillationabstractGraph Neural Networks (GNNs) have powerful representation capabilities for graph data, achieving excellent performance across various fields. Considering the scarcity of labels in real-world scenarios, graph self-supervised learning (GSSL) has gained increasing attention due to its ability to train without relying on labels. However, recent studies have revealed that GNNs are vulnerable to stealthy backdoor attacks in GSSL scenarios, enabling the encoder to learn backdoor features simply by injecting triggers. Existing graph backdoor defense methods mainly focus on supervised settings and cannot be directly transferred to self-supervised scenarios due to the lack of label guidance. To bridge this gap, we proposeGDetox, the first backdoor defense approach against backdoored encoders in GSSL.GDetoxaims to eliminate backdoor logic in encoders while maintaining the encoder's original performance. Specifically,GDetoxcan purify the graph backdoor encoder based on the self-supervised distillation approach without relying on label information. Further, we introduce an adversarial contrastive learning that augments node representations without relying on labels to enhance teacher model performance, thereby improving distilled encoder performance. We evaluate the defense performance ofGDetoxon four node classifications and four graph classification datasets by comparing with four state-of-the-art (SOTA) defense methods against seven latest backdoor attack methods on GSSL. Extensive experiments demonstrate thatGDetoxfar outperforms the SOTA defense methods, reducing the attack success rate to 4% with negligible degradation in encoder performance (within 2%) in both node-level and graph-level tasks. Hao Sui 0003, Jiale Zhang 0001, Bing Chen 0002, Chunpeng Ge 0001, Weizhi Meng 0001, Willy Susilo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | Spa: Stealthy and Persistent Backdoor Attacks in Federated Learning via Feature-Space Alignment
Ye Li 0041, Bosen Rao, Yunlong Mao, Jiale Zhang 0001, Sheng Zhong 0002 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Infighting in the Dark: Multi-Label Backdoor Attack in Federated LearningabstractFederated Learning (FL), a privacy-preserving decentralized machine learning framework, has been shown to be vulnerable to backdoor attacks. Current research primarily focuses on the Single-Label Backdoor Attack (SBA), wherein adversaries share a consistent target. However, a critical fact is overlooked: adversaries may be non-cooperative, have distinct targets, and operate independently, which exhibits a more practical scenario called Multi-Label Backdoor Attack (MBA). Unfortunately, prior works are ineffective in the MBA scenario since non-cooperative attackers exclude each other. In this work, we conduct an in-depth investigation to uncover the inherent constraints of the exclusion: similar backdoor mappings are constructed for different targets, resulting in conflicts among backdoor functions. To address this limitation, we propose Mirage, the first non-cooperative MBA strategy in FL that allows attackers to inject effective and persistent backdoors into the global model without collusion by constructing in-distribution (ID) backdoor mapping. Specifically, we introduce an adversarial adaptation method to bridge the backdoor features and the target distribution in an ID manner. Additionally, we further leverage a constrained optimization method to ensure the ID mapping survives in the global training dynamics. Extensive evaluations demonstrate that Mirage outperforms various state-of-the-art attacks and bypasses existing defenses, achieving an average ASR greater than 97% and maintaining over 90% after 900 rounds. This work aims to alert researchers to this potential threat and inspire the design of effective defense mechanisms. Code has been made open-source. Ye Li 0041, Yanchao Zhao, Jiale Zhang 0001 |
CVPR | 4 |
| 2025 | FedRPN: An Efficient Framework for Optimizing System Heterogeneity in Federated LearningabstractFederated Learning (FL) enables machine learning tasks to be performed on distributed data in a privacy-preserving manner, but faces challenges related to the heterogeneity of device systems. This necessitates the customization of resource requirements to accommodate the diverse capacities of participating clients. However, existing approaches struggle to generate resource-customized, ready-to-use inference models while still incurring substantial resource consumption throughout the system workflow. In response, this paper introduces a novel framework, FedRPN, which incorporates Resource-customized Prototypical Networks. RPN leverages resource-customized pre-trained models as the initial point and employs unbiased proto-typical classification, enabling rapid convergence, resource efficiency, and robustness to non-IID data. Additionally, we propose a globally-aware training strategy that produces deployable inference models of varying capacities. Building on RPN, we propose a two-stage process comprising prototype construction followed by model fine-tuning, which further enhances performance. Experimental results demonstrate that FedRPN reduces computational and communication resource consumption by 48% and 43%, respectively, while delivering improved performance. Baolu Xue, Hanyuan Zheng, Jiale Zhang 0001, Jiewen Liu, Bing Chen 0002 |
ICASSP | 3 |
| 2025 | Beyond Dataset Watermarking: Model-Level Copyright Protection for Code Summarization Models
Jiale Zhang 0001, Di Wu 0050, Xiaobing Sun 0001, Qinghua Lu 0001, Guodong Long |
WWW | 1 |
| 2025 | EPAD: Ethereum phishing scam detection via graph contrastive learning
Hao Sui 0003, Jiale Zhang 0001, Bing Chen 0002, Di Wu 0050, Xiaobing Sun 0001, Palaiahnakote Shivakumara |
Expert Syst. Appl. | 2 |
| 2025 | SFFL: Self-aware fairness federated learning framework for heterogeneous data distributions
Jiale Zhang 0001, Ye Li 0041, Di Wu 0050, Yanchao Zhao, Palaiahnakote Shivakumara |
Expert Syst. Appl. | 1 |
| 2025 | FedMLC: White-Box Model Watermarking for Copyright Protection in Federated Learning for IoT EnvironmentabstractWith the widespread application of the Internet of Things (IoT), data processing has gradually migrated to edge devices that are closer to the data source. This shift has significantly improved the ability of real-time data analysis while effectively reducing bandwidth requirements and latency. Furthermore, Federated Learning (FL) has been introduced as a decentralized training method to achieve collaborative training of multiple devices while ensuring local data privacy. However, malicious clients in FL may theft trained models for unauthorized use, which causes model misuse or copyright challenges. To address these issues, this paper proposes FedMLC (Malicious client detection, Leakage tracing, and Copyright verification), a server-side white-box watermarking scheme. FedMLC utilizes the embedded watermark at different stages to achieve both traceability and copyright verification, simplifying the watermarking process. Additionally, the watermarking can also detect malicious clients in FL. Specifically, FedMLC uses the regularization term to guide the parameter signs of the normalization layer to be consistent with the watermark sign, thereby achieving watermark embedding. Experimental results show that our FL model watermarking scheme excels in malicious client detection, leakage tracing, and copyright verification, with minimal impact on model performance, able to resist various attacks such as fine-tuning, pruning, and quantization. Weitong Chen 0002, Wei Zhang 0098, Di Wu 0050, Anja Keskinarkaus, Tapio Seppänen, Jiale Zhang 0001, Longxiang Gao, Tom H. Luan |
IEEE Internet Things J. | 6 |
| 2025 | FedPG: a privacy-friendly and universal method for solving non-IID data in federated learning
Baolu Xue, Jiale Zhang 0001, Bing Chen 0002, Weizhi Meng 0001 |
Pattern Anal. Appl. | 2 |
| 2025 | GraphCleanse: Defending Backdoor Attacks in Graph Learning via Contrastive TrainingabstractGraph Neural Networks (GNNs) are highly susceptible to numerous adversarial attacks, among which the backdoor attack is one of the toughest to deal with due to the fact that it can lead to misclassification of the model. Similar to Deep Neural Networks (DNNs), backdoor attacks in GNNs work by an attacker changing a portion of the graph data with a hidden trigger and modifying their labels to target labels, which induces the model to learn the trigger feature during its training phase. Although recent defense techniques have emerged, approaches based on explainability and data isolation often fail to detect malicious samples with covert triggers, while discrepancy learning methods tend to degrade performance by removing useful features. To overcome these limitations, we propose a novel backdoor defense method, namedGraphCleanse, on GNNs that can effectively eliminate the possible backdoor features during the training process. Specifically,GraphCleansecan easily break the strong correlation between backdoor features and target labels based on graph contrastive training. To further improve the model accuracy, we present a mutual information maximization method to learn the important feature information in the labeled credible samples and unlabeled suspicious samples by clustering the features obtained from the graph contrastive encoder. Compared with the potential solutions, such as randomized smoothing,GraphCleanseeffectively avoids the negative influence of backdoored samples while maintaining a high model performance. Extensive experimental evaluations on four benchmark datasets demonstrate thatGraphCleansecan reduce the attack success rate to 10% with less performance degradation (within 7%). Jiale Zhang 0001, Hao Sui 0003, Wanquan Zhu, Xiaobing Sun 0001, Chunpeng Ge 0001, Bing Chen 0002, Mingsheng Cao 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | SSLDefender: Backdoor Defense in Self-Supervised Learning via Distillation-Guided UnlearningabstractSelf-supervised learning utilizes unlabelled data to train encoders, acquiring high-quality representations of input data, significantly advancing the field of computer vision. However, recent studies have demonstrated that self-supervised learning suffers from numerous adversarial attacks. Among them, backdoor attack is one of the focal issues, where downstream classifiers inherit the backdoor behavior of the pre-trained encoder. Existing defense methods against backdoor attacks primarily focus on supervised learning, which heavily relies on labeled data and cannot be directly migrated to self-supervised scenarios. Furthermore, defense methods for self-supervised backdoor aims to separate poisoned samples on assumed small-scale datasets and retraining to obtain a clean encoder. However, these approaches are useless against encoders that have been implanted with a backdoor. To address these issues, we propose SSLDefender, a novel image-based backdoor mitigation method specially designed for self-supervised learning, which can remove backdoor attributes directly from the backdoor encoder. Specifically, we employ a trigger recovery method based on mutual information maximization to efficiently obtain trigger that resembles the target backdoor’s influence. Additionally, we design a distillation-guided unlearning strategy to purify backdoor features steadily and ensure the retention of clean knowledge to prevent overforgetting. Extensive experimental evaluations on six benchmark datasets demonstrate that SSLDefender can successfully reduce the attack success rate of Badencoder to around 2% while maintaining high model accuracy on the main task. Its performance surpasses state-of-the-art methods. Jiale Zhang 0001, Wanquan Zhu, Kai Wang 0062, Xiaobing Sun 0001, Weizhi Meng 0001, Xiapu Luo |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | KG4VA: Constructing Vulnerability Knowledge Graph for Software Vulnerability AssessmentabstractSoftware vulnerabilities pose serious threats to software security. When faced with multiple software vulnerabilities at the same time, it is urgent to determine whether the vulnerabilities are high-risk. Existing vulnerability assessment approaches only learn the mapping relationships between vulnerability descriptions and severity levels, while ignoring the sharing of the same or similar elements between vulnerabilities. Furthermore, solely focusing on vulnerability descriptions fails to accurately characterize the vulnerability behavior. In this paper, we propose a novel vulnerability knowledge graph (KG) to capture the relationships between vulnerabilities. To construct the vulnerability KG automatically, we propose to leverage vulnerability elements extracted from vulnerability descriptions to link different vulnerabilities. Based on the constructed KG, we further propose a novel KG-based vulnerability assessment (VA) approach KG4VA, which precisely finds the similar vulnerability for an encountered vulnerability description by analyzing and matching the elements entities based on the vulnerability KG. The experiment results show that KG4VA outperforms the baselines in almost all metrics (e.g., 3.27%-10.83% accuracy improvements). Moreover, our ablation experiments demonstrate that the vulnerability knowledge graph can indeed offer valuable information for vulnerability assessment. Zhenlei Ye, Xiaobing Sun 0001, Lili Bo, Sicong Cao, Xiaoxue Ren, Lianyong Qi, Jiale Zhang 0001 |
IEEE Trans. Serv. Comput. | 7 |
| 2025 | Misactivation-Aware Stealthy Backdoor Attacks on Neural Code Understanding ModelsabstractNeural code models (NCMs) play a crucial role in helping developers solve code understanding tasks. Recent studies have exposed that NCMs are vulnerable to several security threats, among which backdoor attack is one of the toughest. It is usually achieved through data poisoning. Specifically, backdoored NCMs work normally on the clean example but produce attacker-expected output on the example injected with backdoor triggers. However, existing backdoor attacks against NCMs face two significant drawbacks: 1) lack of stealthiness, that is trigger tokens are easily detected by defense techniques/humans when they appear in excessive numbers; 2) damage to the model’s normal performance, that is partial trigger tokens may frequently appear as benign features in the clean samples, resulting in clean samples containing them may falsely activate the backdoor. To address these drawbacks, we propose a misactivation-aware stealthy backdoor attack against NCMs through data poisoning called MISNCM. MISNCM features target-biased trigger generation, thus achieving stealthy backdoor attacks. Moreover, we utilize misactivation-aware data poisoning to create calibration samples with partial trigger tokens to reduce false activations and ensure the regular performance of the model. We conduct comprehensive experiments to evaluate the effectiveness of MISNCM in attacking NCMs used for three code understanding tasks: defect detection, clone detection, and authorship attribution. The experimental results demonstrate that the triggers generated by MISNCM achieve an average attack success rate increase of 12.67% over IR and 8.38% over AFRAIDOOR. Furthermore, MISNCM achieves a 3.64% improvement in F1 score on the code clone detection task, and an average of 5.91% improvement in accuracy on the defect detection and authorship attribution tasks, compared with the two baselines. Xiaobing Sun 0001, Yiran Xiao, Lili Bo, Weisong Sun, Xiangyue Liu 0002, Bin Li 0006, Jiale Zhang 0001 |
IEEE Trans. Software Eng. | 7 |
| 2024 | Fairness-Aware Federated Learning Framework on Heterogeneous Data DistributionsabstractRecent years have witnessed increasing privacy concerns towards machine learning. To protect privacy in machine learning, federated learning has been proposed as a decentralized privacy-preserving framework where clients upload the parameters rather than private data. However, training a fair federated learning model in heterogeneous environments is still challenging. First, heterogeneous data distributions lead the global model fail to show high accuracy on all distributions. Second, the federated learning training process exposes and exacerbates potential biases in heterogeneous training data. Third, the local bias of each client can be propagated through parameter sharing, biasing the global model. In this work, we propose a two-stage fairness-aware federated learning framework (HeteroFair) to achieve fairness under heterogeneous data distributions. Initially, we introduce the fairness constraint to the loss function and propose a local adaptive weighting algorithm to adjust the proportion of the fairness constraint, achieving fair training in heterogeneous environments. Then, we present a fairness-aware aggregation reweighting algorithm that reduces the mismatch between local and global fairness to achieve fair federated learning. Extensive evaluation results demonstrate the effectiveness of our proposed framework in achieving fairness and high accuracy under het-eroaeneous data distributions. Ye Li 0041, Jiale Zhang 0001, Yanchao Zhao, Bing Chen 0002, Shui Yu 0001 |
ICC | 2 |
| 2024 | BADFSS: Backdoor Attacks on Federated Self-Supervised Learning
Jiale Zhang 0001, Di Wu 0050, Xiaobing Sun 0001, Jianming Yong, Guodong Long |
IJCAI | 1 |
| 2024 | EXVul: Toward Effective and Explainable Vulnerability Detection for IoT DevicesabstractAs with anything connected to the internet, Internet of Things (IoT) devices are also subject to severe cybersecurity threats because an adversary could exploit vulnerabilities in their internal software to perform malicious attacks. Despite the promising results of Deep Learning (DL)-based approaches, the lack of well-labeled IoT vulnerability samples available for training and explainability pose a critical challenge to deploy them in practice. In this paper, we propose, a novel DL-based approach for Effective and eXplainable IoT VULnerability detection. Specifically, inspired by recent advances of self-supervised learning in label-expensive tasks, we propose a new combinatorial contrastive loss to combine the strengths of large-scale unlabeled code corpus and limited IoT vulnerability samples. Then, given a binary detection result, provides a set of faithful and stable code statements positively contributing to the model’s predictions as understandable explanations. Experimental results indicate that outperforms state-of-the-art baselines by 33.44%-72.91% and 19.52%-98.78% with respect to the accuracy and F1 score metrics, respectively. For vulnerability explanation, improves over the best-performing baseline explainer PGExplainer by 22.97% in MSP, 49.55% in MSR, and 48.40% in MIoU, demonstrating that the explanations provided by can correctly point out the vulnerable statements relevant to the detected vulnerabilities. Sicong Cao, Xiaobing Sun 0001, Wei Liu 0010, Di Wu 0050, Jiale Zhang 0001, Yan Li 0002, Tom H. Luan, Longxiang Gao |
IEEE Internet Things J. | 5 |
| 2024 | Fine-grained smart contract vulnerability detection by heterogeneous code feature learning and automated dataset construction
Jie Cai 0006, Bin Li 0006, Tao Zhang 0001, Jiale Zhang 0001, Xiaobing Sun 0001 |
J. Syst. Softw. | 4 |
| 2024 | Blockfd: blockchain-based federated distillation against poisoning attacks
Ye Li 0041, Jiale Zhang 0001, Junwu Zhu, Wenjuan Li 0001 |
Neural Comput. Appl. | 2 |
| 2024 | Application programming interface recommendation for smart contract using deep learning from augmented code representationabstractAbstract Application programming interface (API) recommendation plays a crucial role in facilitating smart contract development by providing developers with a ranked list of candidate APIs for specific recommendation points. Deep learning‐based approaches have shown promising results in this field. However, existing approaches mainly rely on token sequences or abstract syntax trees (ASTs) for learning recommendation point‐related features, which may overlook the essential knowledge implied in the relations between or within statements and may include task‐irrelevant components during feature learning. To address these limitations, we propose a novel code graph called pruned and augmented AST (pa‐AST). Our approach enhances the AST by incorporating additional knowledge derived from the control and data flow relations between and within statements in the smart contract code. Through this augmentation, the pa‐AST can better represent the semantic features of the code. Furthermore, we conduct AST pruning to eliminate task‐irrelevant components based on the identified flow relations. This step helps mitigate the interference caused by these irrelevant parts during the model feature learning process. Additionally, we extract the API sequence surrounding the recommendation point to provide supplementary knowledge for the model learning. The experimental results demonstrate our proposed approach achieving an average mean reciprocal rank (MRR) of 68.02%, outperforming the baselines' performance. Furthermore, through ablation experiments, we explore the effectiveness of our proposed code representation approach. The results indicate that combining pa‐AST with the API sequence yields improved performance compared with using them individually. Moreover, our AST augmentation and pruning techniques significantly contribute to the overall results. Jie Cai 0006, Qian Cai, Bin Li 0006, Jiale Zhang 0001, Xiaobing Sun 0001 |
J. Softw. Evol. Process. | 4 |
| 2024 | BadCleaner: Defending Backdoor Attacks in Federated Learning via Attention-Based Multi-Teacher DistillationabstractAs a privacy-preserving distributed learning paradigm, federated learning (FL) has been proven to be vulnerable to various attacks, among which backdoor attack is one of the toughest. In this attack, malicious users attempt to embed backdoor triggers into local models, resulting in the crafted inputs being misclassified as the targeted labels. To address such attack, several defense mechanisms are proposed, but may lose the effectiveness due to the following drawbacks. First, current methods heavily rely on massive labeled clean data, which is an impractical setting in FL. Moreover, an in-avoidable performance degradation usually occurs in the defensive procedure. To alleviate such concerns, we proposeBadCleaner, a lossless and efficient backdoor defense scheme via attention-based federated multi-teacher distillation. Firstly,BadCleanercan effectively tune the backdoored joint model without performance degradation, by distilling the in-depth knowledge from multiple teachers with only a small part of unlabeled clean data. Secondly, to fully eliminate the hidden backdoor patterns, we present an attention transfer method to alleviate the attention of models to the trigger regions. The extensive evaluation demonstrates thatBadCleanercan reduce the success rates of state-of-the-art backdoor attacks without compromising the model performance. Jiale Zhang 0001, Chunpeng Ge 0001, Chuan Ma 0001, Yanchao Zhao, Xiaobing Sun 0001, Bing Chen 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | FLPurifier: Backdoor Defense in Federated Learning via Decoupled Contrastive TrainingabstractRecent studies have demonstrated that backdoor attacks can cause a significant security threat to federated learning. Existing defense methods mainly focus on detecting or eliminating the backdoor patterns after the model is backdoored. However, these methods either cause model performance degradation or heavily rely on impractical assumptions, such as labeled clean data, which exhibit limited effectiveness in federated learning. To this end, we proposeFLPurifier, a novel backdoor defense method in federated learning that can effectively purify the possible backdoor attributes before federated aggregation. Specifically,FLPurifiersplits a complete model into a feature extractor and classifier, in which the extractor is trained in a decoupled contrastive manner to break the strong correlation between trigger features and the target label. Compared with existing backdoor mitigation methods,FLPurifierdoesn’t rely on impractical assumptions since it can effectively purify the backdoor effects in the training process rather than an already trained model. Moreover, to decrease the negative impact of backdoored classifiers and improve global model accuracy, we further design an adaptive classifier aggregation strategy to dynamically adjust the weight coefficients. Extensive experimental evaluations on six benchmark datasets demonstrate thatFLPurifieris effective against known backdoor attacks in federated learning with negligible performance degradation and outperforms the state-of-the-art defense methods. Jiale Zhang 0001, Xiaobing Sun 0001, Chunpeng Ge 0001, Bing Chen 0002, Willy Susilo, Shui Yu 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Ponzi Scheme Detection in Smart Contract via Transaction Semantic Representation LearningabstractThe Ponzi scheme implemented through smart contracts is one of the most common scams on the blockchain platform. Although various learning-based Ponzi smart contract detection approaches have been proposed, they still suffer from several limitations, i.e., 1) extracting insufficient semantics and gathering Ponzi irrelevant components from the smart contract during feature engineering, and 2) underutilizing structured semantic features during model training. As the Ponzi scheme is an economic crime with the typical Rob-Peter-to-Pay-Paul transaction pattern, we propose a transaction semantic learning based approach to mitigate the above limitations. The fundamental idea of our approach is to represent the transaction-related semantics of a smart contract as a graph and utilize a graph convolutional network (GCN) to learn the potential Ponzi-like transaction pattern from it. We define a novel code representation named slice transaction property graph (sTPG) to represent the transaction-related semantics, which can encode multiple transaction-related semantics inside a smart contract function into a graph and eliminate other irrelevant fragments. Then, we propose a relation-sensitive GCN as the learning model to identify potential Ponzi-scheme-like transaction patterns from sTPG by considering both nodes and edges features in sTPG. We evaluate our approach on two datasets: 1) smart contracts collected from Forum and Public datasets, and 2) really deployed smart contracts on the Ethereum blockchain. The experiment results show that our approach outperforms the state-of-the-art learning-based approaches. Jie Cai 0006, Bin Li 0006, Jiale Zhang 0001, Xiaobing Sun 0001 |
IEEE Trans. Reliab. | 3 |
| 2024 | GrabPhisher: Phishing Scams Detection in Ethereum via Temporally Evolving GNNsabstractPhishing scams are one of Ethereum's most representative security risks that can defraud many transactions in a short period and severely threaten network security. Existing deep learning-based phishing scam detection methods mainly rely on constructing static transaction graphs which are assumed to be accessible before model training. However, static methods that have a high false positive rate to detect newly generated phishing scams by adding this newly generated data to existing algorithms for execution, due to new accounts and transactions constantly appearing in the real-world Ethereum network. Therefore, this article, for the first time, proposes a novel evolve-based phishing scams detection method (named GrabPhisher) that extracts temporal features of accounts and captures information about the dynamic topology of the graph as it evolves. Specifically, GrabPhisher can build the evolutionary pattern of accounts trading on Ethereum as a diffusion network graph in continuous time. It can continue to capture new transaction features based on existing transactions, which facilitates the identification of phishing accounts. Additionally, we implement GrabPhisher on the real-world Ethereum phishing scams datasets. Extensive experimental results demonstrate that GrabPhisher can effectively extract dynamic temporal features and outperform state-of-the-art methods (95% Recall, and 88% F1-score). Jiale Zhang 0001, Hao Sui 0003, Xiaobing Sun 0001, Chunpeng Ge 0001, Lu Zhou 0002, Willy Susilo |
IEEE Trans. Serv. Comput. | 1 |
| 2023 | Label-Only Membership Inference Attack Against Federated Distillation
Yanchao Zhao, Jiale Zhang 0001, Bing Chen 0002 |
ICA3PP (2) | 3 |
| 2023 | Extended Abstract of Combine Sliced Joint Graph with Graph Neural Networks for Smart Contract Vulnerability DetectionabstractExisting smart contract vulnerability detection efforts heavily rely on fixed rules defined by experts, which are inefficient and inflexible. To overcome the limitations of existing vulnerability detection approaches, we propose a GNN based approach. First, we construct a graph representation for a smart contract function with syntactic and semantic features by combining abstract syntax tree (AST), control flow graph (CFG), and program dependency graph (PDG). To further strengthen the presentation ability of our approach, we perform program slicing to normalize the graph and eliminate the redundant information unrelated to vulnerabilities. Then, we use a Bidirectional Gated Graph Neural-Network model with hybrid attention pooling to identify potential vulnerabilities in smart contract functions. Experiment results show that our approach can achieve 89.2% precision and 92.9% recall in smart contract vulnerability detection on our dataset and reveal the effectiveness and efficiency of our approach. Jie Cai 0006, Bin Li 0006, Jiale Zhang 0001, Xiaobing Sun 0001, Bing Chen 0002 |
SANER | 3 |
| 2023 | ADFL: Defending backdoor attacks in federated learning via adversarial distillation
Jiale Zhang 0001, Xiaobing Sun 0001, Bing Chen 0002, Weizhi Meng 0001 |
Comput. Secur. | 2 |
| 2023 | LAFED: A lightweight authentication mechanism for blockchain-enabled federated learning system
Shan Ji, Jiale Zhang 0001, Yongjing Zhang, Chuan Ma 0001 |
Future Gener. Comput. Syst. | 2 |
| 2023 | ASSBert: Active and semi-supervised bert for smart contract vulnerability detection
Xiaobing Sun 0001, Liangqiong Tu, Jiale Zhang 0001, Jie Cai 0006, Bin Li 0006, Yu Wang 0017 |
J. Inf. Secur. Appl. | 3 |
| 2023 | Combine sliced joint graph with graph neural networks for smart contract vulnerability detection
Jie Cai 0006, Bin Li 0006, Jiale Zhang 0001, Xiaobing Sun 0001, Bing Chen 0002 |
J. Syst. Softw. | 3 |
| 2023 | Multi-level membership inference attacks in federated Learning based on active GAN
Hao Sui 0003, Xiaobing Sun 0001, Jiale Zhang 0001, Bing Chen 0002, Wenjuan Li 0001 |
Neural Comput. Appl. | 3 |
| 2022 | Edge-based Protection Against Malicious Poisoning for Distributed Federated LearningabstractFederated learning is proposed to solve data islands and protect privacy. Especially in the big data environment, participating users can build a model together without sharing private sensitive data. However, as the number of end devices becomes larger, and the model becomes more complex, high concurrent access to the cloud server often brings communication delay, and it is also a great challenge to the computing power of end devices. To address this problem, we introduce Unmanned Aerial Vehicle (UAV) swarms as mobile edge nodes for end devices. UAV swarms can provide caching and computing resources for end devices. Therefore, we can implement edge aggregation of parameters on UAV swarms to reduce direct access to the cloud server. Meanwhile, the distributed end-edge-cloud federated learning architecture based on UAV swarms is an open environment, which may have potential malicious end devices or external channel eavesdropping. Malicious end devices or external eavesdroppers may maliciously poison training data sets or model parameters to reduce the classification accuracy of the model. In order to resist malicious poisoning, on UAV swarms we can calculate the cosine similarities between local parameters and their edge aggregation parameters to exclude malicious parameters, which do not conform to the trend of collaborative convergence. Then, the reliable parameters can be aggregated again, and uploaded to the cloud server with Schnorr signature to ensure the authenticity of the data. We analyze the security of the proposed scheme, and verify through experiments that it can resist malicious poisoning effectively and improve the accuracy of the model. Bing Chen 0002, Feng Hu 0003, Jiale Zhang 0001 |
CSCWD | 4 |
| 2022 | A Blockchain-based Multi-layer Decentralized Framework for Robust Federated LearningabstractWith the expansion of the Internet of Things (IoT) development and application, federated learning has gained higher popularity in industrial researching fields. However, the security issues in federated learning have become hot-spots in the research area, such as privacy-preserving and poisoning attacks. This paper proposes a robust blockchained multi-layer decentralized federated learning (RBML-DFL) framework to ensure the federated learning's robustness. Firstly, by adopting the three-layered framework, the blockchain connects the federated learning components to secure the privacy and data safety of federated learning. Secondly, the proposed framework provides resilience on poisoning attacks to the central model compared to typical federated learning frameworks. Lastly, the decentralized structure associated with the blockchain tracing back mechanism can prevent the central server failure or mal-function compared to centralized federated learning. We evaluate and compare the proposed framework with other state-of-the-art federated learning frameworks on the accuracy, latency, and system robustness under poisoning attacks. The results show that the proposed RBML-DFL framework outperforms state-of-the-art baseline frameworks on all three metrics: accuracy, latency, and the robustness of the federated learning. Di Wu 0050, Nai Wang, Jiale Zhang 0001, Yuan Zhang 0007, Yong Xiang 0001, Longxiang Gao |
IJCNN | 3 |
| 2022 | Cyber situation perception for Internet of Things systems based on zero-day attack activities recognition within advanced persistent threatabstractSummary With the development of the Internet of Things (IoT) technology, various attacks and threats have emerged. The advanced persistent threat (APT) refers to a class of advanced multiple‐steps attacks among diverse attack activities, which brings severe threats to the IoT systems ascribe to its pertinence, concealment, and permeability. However, the existing technologies and methods fail to timely recognize the APT attack activities (especially the zero‐day exploits) in a comprehensive scope. To address this problem, we propose a novel method of cyber situation perception for IoT systems, which based on zero‐day attack activity recognition within APT (CSPAPTM). Moreover, we also design an edge computing framework for applying CSPAPTM to the typical IoT systems. Specifically, we first provide a cyber situation perception ontology construction module for describing the APT attack activities. Then, a malicious C&C DNS mining method (MCCDRM) is proposed to control the APT malicious activity correlation analysis trigger, which can effectively decrease the computing overhead. Finally, we propose a zero‐day attack activity recognition method within APT (ZDAARA), which acts on system call instances to recognize the malicious activities, which cannot be detected by IDS. A relatively mature access control mechanism PO‐SAAC is also applied to our method. Through the coalescent of these methods, CSPAPTM can accomplish the cyber situation perception effectively by the zero‐day attack activities recognition in the IoT systems. The exhaustive experimental results demonstrate that the two kernel modules, that is, MCCDRM and ZDAARA in our CSPAPTM, can achieve both higher F1 score and acceptable false positive rate. Xiang Cheng 0004, Jiale Zhang 0001, Yaofeng Tu, Bing Chen 0002 |
Concurr. Comput. Pract. Exp. | 2 |
| 2022 | Detecting and mitigating poisoning attacks in federated learning using generative adversarial networksabstractSummary In the age of the Internet of Things (IoT), large numbers of sensors and edge devices are deployed in various application scenarios; Therefore, collaborative learning is widely used in IoT to implement crowd intelligence by inviting multiple participants to complete a training task. As a collaborative learning framework, federated learning is designed to preserve user data privacy, where participants jointly train a global model without uploading their private training data to a third party server. Nevertheless, federated learning is under the threat of poisoning attacks, where adversaries can upload malicious model updates to contaminate the global model. To detect and mitigate poisoning attacks in federated learning, we propose a poisoning defense mechanism, which uses generative adversarial networks to generate auditing data in the training procedure and removes adversaries by auditing their model accuracy. Experiments conducted on two well‐known datasets, MNIST and Fashion‐MNIST, suggest that federated learning is vulnerable to the poisoning attack, and the proposed defense method can detect and mitigate the poisoning attack. Ying Zhao 0011, Jiale Zhang 0001, Di Wu 0050, Michael Blumenstein, Shui Yu 0001 |
Concurr. Comput. Pract. Exp. | 3 |
| 2022 | SPVF: security property assisted vulnerability fixing via attention-based models
Lili Bo, Xiaoxue Wu 0001, Xiaobing Sun 0001, Tao Zhang 0001, Bin Li 0006, Jiale Zhang 0001, Sicong Cao |
Empir. Softw. Eng. | 7 |
| 2022 | RobustFL: Robust Federated Learning Against Poisoning Attacks in Industrial IoT SystemsabstractIndustrial Internet of Things (IIoT) systems are key enabling infrastructures that sustain the functioning of production and manufacturing. To satisfy the intelligence demands, federated learning has been envisioned as a promising technique for IIoT applications with privacy training requirements. However, research works have shown that, by training the local model on crafted poisoning samples malicious participants can jeopardize the functionalities of the global model. In this article, we propose a robust federated learning method, named RobustFL, in IIoT systems to defend against poisoning attacks. The main idea is that we conduct an adversarial training framework, in which an extra logits-based predictive model is built at the server-side to predict which participant a given logit belongs to. Meanwhile, the federated model is adversarially trained to prevent this predictive behavior, thus mitigating the poisoning attack influences. We evaluate the poisoning attack and our defense method on three benchmark datasets. Experimental results demonstrate the superiority of our proposed method in terms of high accuracy and efficiency in defending against poisoning attacks. Jiale Zhang 0001, Chunpeng Ge 0001, Feng Hu 0003, Bing Chen 0002 |
IEEE Trans. Ind. Informatics | 1 |
| 2021 | Defending against Membership Inference Attacks in Federated learning via Adversarial ExampleabstractFederated learning has attracted attention in recent years due to its native privacy-preserving features. However, it is still vulnerable to various membership inference attacks, such as backdoor, poisoning, and adversarial attacks. Membership Inference attack aims to discover the data used to train the model, which leads to privacy leaking ramifications on participants who use their local data to train the shared model. Recent research on countermeasure methods mainly focuses on protecting the parameters and has limitations in guaranteeing privacy while restraining the loss of the model. This paper proposes Fedefend, which applies adversarial examples to defend against membership inference attacks in federated learning. The proposed approach adds well-designed noise to the attack features of the target model of each iteration becomes an adversarial example. In addition, we also consider the utility loss of the model and use an adversarial method to generate noise to constrain the loss to a certain extent, which efficiently achieves a trade-off between privacy security and loss of the federated learning model. We evaluate the proposed Fedefend on two benchmark datasets, and the experimental results demonstrate that Fedefend has a good performance. Yuanyuan Xie, Bing Chen 0002, Jiale Zhang 0001, Di Wu 0050 |
MSN | 3 |
| 2021 | OAC-HAS: outsourced access control with hidden access structures in fog-enhanced IoT systemsabstractFog computing is recently a novel distributed computing paradigm that performs a significant achievement in the latency-sensitive smart Internet of Things (IoT) applications. However, the security and privacy issues, such as data leakage, still challenge the wide deployment of fog computing infrastructure. To guarantee data confidentiality and meanwhile achieving fine-grained access control, Ciphertext-Policy Attribute-Based Encryption (CP-ABE) promises to provide a flexible access policy for securely sharing data among users, fog nodes, and cloud center. However, due to the complicated cryptographic operations, CP-ABE has met a significant drawback that requires heavy computation resources on the user-side. In this paper, we propose an outsourced access control scheme with hidden access structures, named OAC-HAS, in fog-enhanced IoT systems. The contributions of our OAC-HAS scheme are three-folds. Firstly, we introduce a fog-cloud computing (FCC) environment which has the outsourcing capability. Then, we design an outsource verification mechanism to guarantee the correctness of executing cryptographic operations on the fog nodes. Finally, we also provide a privacy guarantee that prevents information leakage from the access structures. Security analysis and experimental results show that the proposed OAC-HAS scheme achieves flexible access policy, privacy-preserving, and high efficiency in fog-enhanced IoT systems. Jiale Zhang 0001, Xiang Cheng 0004, Bing Chen 0002 |
Connect. Sci. | 1 |
| 2021 | PoisonGAN: Generative Poisoning Attacks Against Federated Learning in Edge Computing SystemsabstractEdge computing is a key-enabling technology that meets continuously increasing requirements for the intelligent Internet-of-Things (IoT) applications. To cope with the increasing privacy leakages of machine learning while benefiting from unbalanced data distributions, federated learning has been wildly adopted as a novel intelligent edge computing framework with a localized training mechanism. However, recent studies found that the federated learning framework exhibits inherent vulnerabilities on active attacks, and poisoning attack is one of the most powerful and secluded attacks where the functionalities of the global model could be damaged through attacker's well-crafted local updates. In this article, we give a comprehensive exploration of the poisoning attack mechanisms in the context of federated learning. We first present a poison data generation method, named Data_Gen, based on the generative adversarial networks (GANs). This method mainly relies upon the iteratively updated global model parameters to regenerate samples of interested victims. Second, we further propose a novel generative poisoning attack model, named PoisonGAN, against the federated learning framework. This model utilizes the designed Data_Gen method to efficiently reduce the attack assumptions and make attacks feasible in practice. We finally evaluate our data generation and attack models by implementing two types of typical poisoning attack strategies, label flipping and backdoor, on a federated learning prototype. The experimental results demonstrate that these two attack models are effective in federated learning. Jiale Zhang 0001, Bing Chen 0002, Xiang Cheng 0004, Huynh Thi Thanh Binh, Shui Yu 0001 |
IEEE Internet Things J. | 1 |
| 2021 | Predicting the APT for Cyber Situation Comprehension in 5G-Enabled IoT Scenarios Based on Differentially Private Federated LearningabstractDriven by the advancements in 5G-enabled Internet of Things (IoT) technologies, the IoT devices have shown an explosive growth trend with massive data generated at the edge of the network. However, IoT systems exhibit inherent vulnerability for diverse attacks, and Advanced Persistent Threat (APT) is one of the most powerful attack models that could lead to a significant privacy leakage of systems. Moreover, recent detection technologies can hardly meet the demands of effective security defense against APTs. To address the above problems, we propose an APT Prediction Method based on Differentially Private Federated Learning (APTPMFL) to predict the probability of subsequent APT attacks occurring in IoT systems. It is the first time to apply a federated learning mechanism for aggregating suspicious activities in the IoT systems, where the APT prediction phase does not need any correlation rules. Moreover, to achieve privacy-preserving property, we further adopt a differentially private data perturbation mechanism to add the Laplacian random noises to the IoT device training data features, so as to achieve the maximum protection of privacy data. We also present a 5G-enabled edge computing-based framework to train and deploy the model, which can alleviate the computing and communication overhead of the typical IoT systems. Our evaluation results show that APTPMFL can efficiently predict subsequent APT behaviors in the IoT system accurately and efficiently. Xiang Cheng 0004, Jiale Zhang 0001, Bing Chen 0002 |
Secur. Commun. Networks | 5 |
| 2021 | Proof of Engagement: A Flexible Blockchain Consensus MechanismabstractConsensus mechanism plays an important role in blockchain. At present, mainstream consensus mechanisms include proof of work (PoW), proof of stake (PoS), and delegated proof of stake (DPoS). PoW, as is widely used in virtual currency, results in significant energy consumption; PoS and DPoS are proposed to reduce energy waste caused by PoW, but their disadvantage is that they tend to create Matthew Effect (ME): “the rich get richer.” In order to balance the discourse power of new nodes and elder ones, this paper proposes a flexible consensus mechanism called proof of engagement (PoE), based on the activity and contribution of network nodes. We analyze the incentive compatibility of PoE from the perspective of mechanism design. In our simulation experiments, we tested the profit changes under PoW, PoS, and PoE. The results illustrate it is easier for new nodes to accumulate their profits under PoE than under PoW or PoS, so as to reduce the negative impacts of ME. Jiale Zhang 0001, Junwu Zhu, Maosheng Sun, Bing Chen 0002 |
Wirel. Commun. Mob. Comput. | 3 |
| 2020 | Dynamic Sample Selection for Federated Learning with Heterogeneous Data in Fog ComputingabstractFederated learning is a state-of-the-art technology used in the fog computing, which allows distributed learning to train cross-device data while achieving efficient performance. Many current works have optimized the federated learning algorithm in homogeneous networks. However, in the actual application scenario of distributed learning, data is independently generated by each device, and this non-homologous data has different distribution characteristics. Therefore, the data used by each device for local learning is unbalanced and non-IID, and the heterogeneity of data affects the performance of federated learning and slows down the convergence. In this paper, we present a dynamic sample selection optimization algorithm, FedSS, to tackle heterogeneous data in federated learning. FedSS dynamically selects the training sample size during the gradient iteration based on the locally available data size, to settle the expensive evaluations of the local objective function with a massive amount of dataset. We theoretically analyze the convergence and present the complexity estimates of our framework when learning large data from unbalanced distribution. Our experimental results show that the use of dynamic sampling methods can effectively improve the convergence speed with heterogeneous data, and keep computational costs low while achieving the desired accuracy. Lingshuang Cai, Jiale Zhang 0001, Shui Yu 0001 |
ICC | 3 |
| 2020 | GAN Enhanced Membership Inference: A Passive Local Attack in Federated LearningabstractFederated learning has lately received great attention for its privacy protection feature. However, recent researches found that federated learning models are susceptible to various inference attacks. In this paper, we point out a membership inference attack method that can cause a serious privacy leakage in federated learning. An adversary who is a participant in federated learning can train a classification attack model to launch the membership inference attack, which determines if a data record is in the model's training dataset. The existing membership inference method is dissatisfied due to a lack of attack data since the training data of each participant are independent. To overcome the lack of attack data, an adversary can enrich attack data using the generative adversarial network (GAN), which is a practical method to increase data diversity. We substantiate that this GAN enhanced membership inference attack method has a 98% attack accuracy. We perform experiments to show that data diversity and the overfitting make federated learning models susceptible. Jiale Zhang 0001, Shui Yu 0001 |
ICC | 2 |
| 2020 | Beyond Model-Level Membership Privacy Leakage: an Adversarial Approach in Federated LearningabstractWith the rise of privacy concerns in traditional centralized machine learning services, the federated learning, which incorporates multiple participants to train a global model across their localized training data, has lately received signifi-cant attention in both industry and academia. However, recent researches reveal the inherent vulnerabilities of the federated learning for the membership inference attacks that the adversary could infer whether a given data record belongs to the model’s training set. Although the state-of-the-art techniques could successfully deduce the membership information from the centralized machine learning models, it is still challenging to infer the membership to a more confined level, user-level. In this paper, We propose a novel user-level inference attack mechanism in federated learning. Specifically, we first give a comprehensive analysis of active and targeted membership inference attacks in the context of the federated learning. Then, by considering a more complicated scenario that the adversary can only passively observe the updating models from different iterations, we incorporate the generative adversarial networks into our method, which can enrich the training set for the final membership inference model. The extensive experimental results demonstrate the effectiveness of our proposed attacking approach in the case of single-label and multi-label. Jiale Zhang 0001, Yanchao Zhao, Kun Zhu 0001, Bing Chen 0002 |
ICCCN | 2 |
| 2020 | Time Efficient Federated Learning with Semi-asynchronous CommunicationabstractWith the explosive growth of massive data generated by smart Internet of Things (IoT) devices, federated learning has been envisioned as a promising technique to provide distributed machine learning services while protecting training data privacy. However, conventional federated learning protocols have shown significant drawbacks in regards of efficiency and scalability. First, since the synchronous communication model of federated learning and the computation capability of each device is different, the straggled users could severely desegregate the efficiency. Second, in synchronous communication, there is no effective client selection mechanism to make the model perform better in the early stage. Third, how to coordinate the communication of various nodes to accelerate global convergence is also one of the issues that need to be considered. To solve the above-mentioned problems, we propose a semi-asynchronous federated learning mechanism where a data expansion method is used to effectively reduce the stragglers existing in both synchronous and asynchronous communication models. Moreover, we also designed a priority function to make the accuracy increase rapidly in the early stage. Experimental results demonstrate that our proposed method have higher accuracy and faster convergence time compared with existing synchronization methods. Jiangshan Hao, Yanchao Zhao, Jiale Zhang 0001 |
ICPADS | 3 |
| 2020 | LVPDA: A Lightweight and Verifiable Privacy-Preserving Data Aggregation Scheme for Edge-Enabled IoTabstractEdge computing is envisioned to be a powerful platform that provides efficient data storage and computation services in the smart Internet-of-Things (IoT) systems. In this data-intensive architecture, protecting user-side data privacy is one of the most critical concerns to prevent privacy leakage from any other untrusted entities. Aiming to resist this concern, many privacy-preserving data aggregation (PPDA) schemes have been proposed for various cloud-enabled IoT applications. However, due to the resource-constrained nature of the smart IoT devices, the conventional PPDA solutions, in terms of both privacy and performance requirements, are unsuitable in edge computing. To address this challenge, we propose a lightweight and verifiable PPDA scheme, named LVPDA, for the edge-computing-enabled IoT system, where the Paillier homomorphic encryption method and an online/offline signature technique are combined to ensure the privacy preserving and integrity verification during the data aggregation process. A detailed security analysis indicates that LVPDA is existentially unforgeable under the chosen message attack (EU-CMA) and the data integrity can be guaranteed with formal proof under q -strong Diffie-Hellman (q -SDH) assumptions. Compared with other PPDA methods, our scheme can achieve lightweight PPDA in terms of less computational complexity and communication overhead. Jiale Zhang 0001, Yanchao Zhao, Jie Wu 0001, Bing Chen 0002 |
IEEE Internet Things J. | 1 |
| 2020 | FedMEC: Improving Efficiency of Differentially Private Federated Learning via Mobile Edge Computing
Jiale Zhang 0001, Yanchao Zhao, Bing Chen 0002 |
Mob. Networks Appl. | 1 |
| 2019 | PEFL: A Privacy-Enhanced Federated Learning Scheme for Big Data AnalyticsabstractFederated learning has emerged as a promising solution for big data analytics, which jointly trains a global model across multiple mobile devices. However, participants' sensitive data information may be leaked to an untrusted server through uploaded gradient vectors. To address this problem, we propose a privacy-enhanced federated learning (PEFL) scheme to protect the gradients over an untrusted server. This is mainly enabled by encrypting participants' local gradients with Paillier homomorphic cryptosystem. In order to reduce the computation costs of the cryptosystem, we utilize the distributed selective stochastic gradient descent (DSSGD) method in the local training phase to achieve the distributed encryption. Moreover, the encrypted gradients can be further used for secure sum aggregation at the server side. In this way, the untrusted server can only learn the aggregated statistics for all the participants' updates, while each individual's private information will be well-protected. For the security analysis, we theoretically prove that our scheme is secure under several cryptographic hard problems. Exhaustive experimental results demonstrate that PEFL has low computation costs while reaching high accuracy in the settings of federated learning. Jiale Zhang 0001, Bing Chen 0002, Shui Yu 0001, Hai Deng |
GLOBECOM | 1 |
| 2019 | A Privacy-Preserving Access Control Scheme with Verifiable and Outsourcing Capabilities in Fog-Cloud Computing
Jiale Zhang 0001, Hongyan Qian, Mingrong Xiang, Di Wu 0050 |
ICA3PP (1) | 2 |
| 2019 | PDGAN: A Novel Poisoning Defense Method in Federated Learning Using Generative Adversarial Network
Ying Zhao 0011, Jiale Zhang 0001, Di Wu 0050, Jian Teng, Shui Yu 0001 |
ICA3PP (1) | 3 |
| 2018 | LPDA-EC: A Lightweight Privacy-Preserving Data Aggregation Scheme for Edge ComputingabstractEdge computing has emerged as the key enabling technology that empowers the IoT with intelligence and efficiency. In this data enriched infrastructure, privacy-preserving data aggregation (PPDA) is one of the most critical services. However, the security and privacy-preserving requirements and online computational cost still present practical concerns in edge computing for resource-constraint edge terminals. To cope with this challenge, we present a lightweight privacy-preserving data aggregation scheme named LPDA-EC for edge computing system by employing the online/offline signature technique, Paillier homomorphic cryptosystem, and double trapdoor Chameleon hash function in this paper. The proposed LPDA-EC scheme can achieve data confidentiality and privacy-preserving, ensuring that the edge server and control center are agnostic of the user's private information during the whole aggregation process. Through detailed analysis, we demonstrate that our scheme is existentially unforgeable under chosen message attack (EU-CMA) and ensures data integrity with formal proofs under q-Strong Diffie-Hellman (q-SDH) assumptions. Numerical results indicate that the LPDA-EC scheme has less computational and communication overheads. Jiale Zhang 0001, Yanchao Zhao, Jie Wu 0001, Bing Chen 0002 |
MASS | 1 |