EDBT 2026 Demo / reviewers in the wild / expert
Chunyi Zhou 0001
dblp:219/2190-1
· DBLP profile ↗
25ranked-venue papers
3as first author
21since 2021 · last 2026
0000-0003-0081-0946ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 12 · 12 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 8 since 2021Computer networks · 4 · 1 first-authorSecurity and privacy · 4 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DP-GenG: Differentially Private Dataset Distillation Guided by DP-Generated DataabstractDataset distillation (DD) compresses large datasets into smaller ones while preserving the performance of models trained on them. Although DD is often assumed to enhance data privacy by aggregating over individual examples, recent studies reveal that standard DD can still leak sensitive information from the original dataset due to the lack of formal privacy guarantees. Existing differentially private (DP)-DD methods attempt to mitigate this risk by injecting noise into the distillation process. However, they often fail to fully leverage the original dataset, resulting in degraded realism and utility. This paper introduces DP-GENG, a novel framework that addresses the key limitations of current DP-DD by leveraging DP-generated data. Specifically, DP-GENG initializes the distilled dataset with DP-generated data to enhance realism. Then, generated data refines the DP-feature matching technique to distill the original dataset under a small privacy budget, and trains an expert model to align the distilled examples with their class distribution. Furthermore, we design a privacy budget allocation strategy to determine budget consumption across DP components and provide a theoretical analysis of the overall privacy guarantees. Extensive experiments show that DP-GENG significantly outperforms state-of-the-art DP-DD methods in terms of both dataset utility and robustness against membership inference attacks, establishing a new paradigm for privacy-preserving dataset distillation. Jinghuai Zhang, Shijie Jiang, Chunyi Zhou 0001, Yuyuan Li 0001, Mengying Zhu, Tianyu Du |
AAAI | 4 |
| 2026 | Bridging the Copyright Gap: Do Large Vision-Language Models Recognize and Respect Copyrighted Content?abstractLarge vision-language models (LVLMs) have achieved remarkable advancements in multimodal reasoning tasks. However, their widespread accessibility raises critical concerns about potential copyright infringement. Will LVLMs accurately recognize and comply with copyright regulations when encountering copyrighted content (i.e., user input, retrieved documents) in the context? Failure to comply with copyright regulations may lead to serious legal and ethical consequences, particularly when LVLMs generate responses based on copyrighted materials (e.g., retrieved book experts, news reports). In this paper, we present a comprehensive evaluation of various LVLMs, examining how they handle copyrighted content – such as book excerpts, news articles, music lyrics, and code documentation when they are presented as visual inputs. To systematically measure copyright compliance, we introduce a large-scale benchmark dataset comprising 50,000 multimodal query-content pairs designed to evaluate how effectively LVLMs handle queries that could lead to copyright infringement. Given that real-world copyrighted content may or may not include a copyright notice, the dataset includes query-content pairs in two distinct scenarios: with and without a copyright notice. For the former, we extensively cover four types of copyright notices to account for different cases. Our evaluation reveals that even state-of-the-art closed-source LVLMs exhibit significant deficiencies in recognizing and respecting the copyrighted content, even when presented with the copyright notice. To solve this limitation, we introduce a novel tool-augmented defense framework for copyright compliance, which reduces infringement risks in all scenarios. Our findings underscore the importance of developing copyright-aware LVLMs to ensure the responsible and lawful use of copyrighted content. Naen Xu, Jinghuai Zhang, Changjiang Li, Hengyu An, Chunyi Zhou 0001, Jun Wang 0001, Yuyuan Li 0001, Tianyu Du, Shouling Ji |
AAAI | 5 |
| 2026 | ACIArena: Toward Unified Evaluation for Agent Cascading InjectionabstractHengyu An, Minxi Li, Jinghuai Zhang, Naen Xu, Chunyi Zhou, Changjiang Li, Xiaogang Xu, Tianyu Du, Shouling Ji. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Hengyu An, Minxi Li, Jinghuai Zhang, Naen Xu, Chunyi Zhou 0001, Changjiang Li, Xiaogang Xu 0002, Tianyu Du, Shouling Ji |
ACL (1) | 5 |
| 2026 | "I See What You Did There": Can Large Vision-Language Models Understand Multimodal Puns?abstractNaen Xu, Jiayi Sheng, Changjiang Li, Chunyi Zhou, Yuyuan Li, Tianyu Du, Jun Wang, Zhihui Fu, Jinbao Li, Shouling Ji. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Naen Xu, Jiayi Sheng, Changjiang Li, Chunyi Zhou 0001, Yuyuan Li 0001, Tianyu Du, Zhihui Fu, Shouling Ji |
ACL (1) | 4 |
| 2026 | Compiling Activation Steering into Weights via Null-Space Constraints for Stealthy BackdoorsabstractRui Yin, Tianxu Han, Naen Xu, Changjiang Li, Ping He, Chunyi Zhou, Jun Wang, Zhihui Fu, Tianyu Du, Jinbao Li, Shouling Ji. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Tianxu Han, Naen Xu, Changjiang Li, Chunyi Zhou 0001, Jun Wang 0020, Zhihui Fu, Tianyu Du, Shouling Ji |
ACL (1) | 6 |
| 2026 | The Eminence in Shadow: Exploiting Feature Boundary Ambiguity for Robust Backdoor AttacksabstractDeep neural networks (DNNs) underpin critical applications yet remain vulnerable to backdoor attacks, typically reliant on heuristic brute-force methods. Despite significant empirical advancements in backdoor research, the lack of rigorous theoretical analysis limits understanding of underlying mechanisms, constraining attack predictability and adaptability. Therefore, we provide a theoretical analysis targeting backdoor attacks, focusing on how sparse decision boundaries enable disproportionate model manipulation. Based on this finding, we derive a closed-form ''ambiguous boundary region'' wherein negligible relabeled samples induce substantial misclassification. Influence function analysis further quantifies significant parameter shifts caused by these margin samples, with minimal impact on clean accuracy, formally grounding why such low poison rates suffice for efficacious attacks. Leveraging these insights, we propose Eminence, an explainable and robust black-box backdoor framework with provable theoretical guarantees and inherent stealth properties. Eminence optimizes a universal, visually subtle trigger that strategically exploits vulnerable decision boundaries and effectively achieves robust misclassification with exceptionally low poison rates (≤ 0.01%, compared to SOTA methods typically requiring ≥ 1 %). Comprehensive experiments validate our theoretical discussions and demonstrate the effectiveness of Eminence, confirming an exponential relationship between margin poisoning and adversarial boundary manipulation. Eminence maintains ≥ 90% attack success rate, exhibits negligible clean-accuracy loss, and demonstrates high transferability across diverse models, datasets and scenarios. Our code is available at https://github.com/NESA-Lab/Eminence Zhou Feng, Chunyi Zhou 0001, Yuwen Pu, Tianyu Du, Jianhai Chen, Shouling Ji |
KDD (1) | 3 |
| 2026 | Auditing M-LLMs for Privacy Risks: A Synthetic Benchmark and Evaluation Framework
Zhou Feng, Chunyi Zhou 0001 |
MMM (2) | 4 |
| 2026 | FraudShield: Knowledge Graph Empowered Defense for LLMs against Fraud Attacks
Naen Xu, Jinghuai Zhang, Chunyi Zhou 0001, Jun Wang 0020, Zhihui Fu, Tianyu Du, Zhaoxiang Wang, Shouling Ji |
WWW | 4 |
| 2026 | Intellectual property protection for deep learning model and dataset intelligence
Yongqi Jiang, Yansong Gao 0001, Chunyi Zhou 0001, Hongsheng Hu, Anmin Fu, Willy Susilo |
Eng. Appl. Artif. Intell. | 3 |
| 2026 | Mellivora Capensis: A Backdoor-Free Training Framework on the Poisoned Dataset Without Auxiliary DataabstractDeep learning models heavily depend on training data quality. While online datasets offer cost-effective solutions for diversity and scale, they introduce security risks. Malicious actors can inject hidden triggers, enabling backdoor attacks that compromise model integrity. Existing defenses remain limited—often demanding large clean datasets, showing inconsistent robustness across attacks, and struggling against adaptive adversaries. Therefore, in this paper, we endeavor to address the challenges of backdoor attack countermeasures in real-world scenarios, thereby fortifying the security of the training paradigm under the data-collection manner. Concretely, we first explore the inherent relationship between the robustness of the poisoned samples, demonstrating the poisoned samples are more robust to perturbation than the clean ones through the theoretical analysis and experiments. Then, we propose a robust and clean-data-free backdoor defense framework, namely Mellivora Capensis (MeCa), which enables training a clean model on the poisoned dataset.MeCadetects poisoned samples and trains clean models without needing clean data or prior knowledge of the poisoning (e.g., poison ratio). We conduct extensive experiments in defending against 8 SOTA attacks (including 3 adaptive attacks) on 4 datasets. The experimental results reveal thatMeCacan achieve an average attack success rate with almost 0.00% to defend against SOTA backdoor attacks while maintaining model availability, which outperforms 7 SOTA backdoor defense methods. Furthermore, the excellent performance on 3 different model architectures and poison ratios also highlights the remarkable generalization capability ofMeCa. Yuwen Pu, Chunyi Zhou 0001, Zhou Feng, Qingming Li, Chunqiang Hu, Shouling Ji |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Enhancing Adversarial Transferability with Adversarial Weight TuningabstractDeep neural networks (DNNs) are vulnerable to adversarial examples (AEs) that mislead the model while appearing benign to human observers. A critical concern is the transferability of AEs, which enables black-box attacks without direct access to the target model. However, many previous attacks have failed to explain the intrinsic mechanism of adversarial transferability, lacking a unified and representative metric for transferability as well. In this paper, we rethink the property of transferable AEs and develop a novel metric to measure transferability from the perspective of generalization. Building on insights from this metric, we analyze the generalization of AEs across models with different architectures and prove that we can find a local perturbation to mitigate the gap between surrogate and target models. We further establish the inner connections between model smoothness and flat local maxima, both of which contribute to the transferability of AEs. Further, we propose a new adversarial attack algorithm, Adversarial Weight Tuning (AWT), which adaptively adjusts the parameters of the surrogate model using generated AEs to optimize the flat local maxima and model smoothness simultaneously, without the need for extra data. AWT is a data-free tuning method that combines gradient-based and model-related attack methods to enhance the transferability of AEs. Extensive experiments on a variety of models with different architectures on ImageNet demonstrate that AWT yields superior performance over other attacks, with an average increase of nearly 5% and 10% attack success rates on CNN-based and Transformer-based models, respectively, compared to state-of-the-art attacks. Zhou Feng, Yuwen Pu, Chunyi Zhou 0001, Yuyou Gan, Shouling Ji |
AAAI | 5 |
| 2025 | CAMH: Advancing Model Hijacking Attack in Machine LearningabstractIn the burgeoning domain of machine learning, the reliance on third-party services for model training and the adoption of pre-trained models have surged. However, this reliance introduces vulnerabilities to model hijacking attacks, where adversaries manipulate models to perform unintended tasks, leading to significant security and ethical concerns, like turning an ordinary image classifier into a tool for detecting faces in pornographic content, all without the model owner’s knowledge. This paper introduces Category-Agnostic Model Hijacking (CAMH), a novel model hijacking attack method capable of addressing the challenges of class number mismatch, data distribution divergence, and performance balance between the original and hijacking tasks. CAMH incorporates synchronized training layers, random noise optimization, and a dual-loop optimization approach to ensure minimal impact on the original task’s performance while effectively executing the hijacking task. We evaluate CAMH across multiple benchmark datasets and network architectures, demonstrating its potent attack effectiveness while ensuring minimal degradation in the performance of the original task. Yuwen Pu, Qingming Li, Chunyi Zhou 0001, Yingcai Wu, Shouling Ji |
AAAI | 5 |
| 2025 | IPIGuard: A Novel Tool Dependency Graph-Based Defense Against Indirect Prompt Injection in LLM AgentsabstractLarge language model (LLM) agents are widely deployed in real-world applications, where they leverage tools to retrieve and manipulate external data for complex tasks.However, when interacting with untrusted data sources (e.g., fetching information from public websites), tool responses may contain injected instructions that covertly influence agent behaviors and lead to malicious outcomes, a threat referred to as Indirect Prompt Injection (IPI).Existing defenses typically rely on advanced prompting strategies or auxiliary detection models.While these methods have demonstrated some effectiveness, they fundamentally rely on assumptions about the model's inherent security, which lacks structural constraints on agent behaviors.As a result, agents still retain unrestricted access to tool invocations, leaving them vulnerable to stronger attack vectors that can bypass the security guardrails of the model.To prevent malicious tool invocations at the source, we propose a novel defensive task execution paradigm, called IPIGUARD 1 , which models the agents' task execution process as a traversal over a planned Tool Dependency Graph (TDG).By explicitly decoupling action planning from interaction with external data, IPIGUARD significantly reduces unintended tool invocations triggered by injected instructions, thereby enhancing robustness against IPI attacks.Experiments on the AgentDojo benchmark show that IPIGUARD achieves a superior balance between effectiveness and robustness, paving the way for the development of safer agentic systems in dynamic environments. Hengyu An, Jinghuai Zhang, Tianyu Du, Chunyi Zhou 0001, Qingming Li, Tao Lin 0004, Shouling Ji |
EMNLP | 4 |
| 2025 | VideoEraser: Concept Erasure in Text-to-Video Diffusion ModelsabstractThe rapid growth of text-to-video (T2V) diffusion models has raised concerns about privacy, copyright, and safety due to their potential misuse in generating harmful or misleading content. These models are often trained on numerous datasets, including unauthorized personal identities, artistic creations, and harmful materials, which can lead to uncontrolled production and distribution of such content. To address this, we propose VideoEraser, a training-free framework that prevents T2V diffusion models from generating videos with undesirable concepts, even when explicitly prompted with those concepts. Designed as a plug-and-play module, VideoEraser can seamlessly integrate with representative T2V diffusion models via a two-stage process: Selective Prompt Embedding Adjustment (SPEA) and Adversarial-Resilient Noise Guidance (ARNG). We conduct extensive evaluations across four tasks, including object erasure, artistic style erasure, celebrity erasure, and explicit content erasure. Experimental results show that VideoEraser consistently outperforms prior methods regarding efficacy, integrity, fidelity, robustness, and generalizability. Notably, VideoEraser achieves state-of-the-art performance in suppressing undesirable content during T2V generation, reducing it by 46% on average across four tasks compared to baselines. Naen Xu, Jinghuai Zhang, Changjiang Li, Chunyi Zhou 0001, Qingming Li, Tianyu Du, Shouling Ji |
EMNLP | 5 |
| 2025 | Poison in the Well: Feature Embedding Disruption in Backdoor AttacksabstractBackdoor attacks embed malicious triggers into training data, enabling attackers to manipulate neural network behavior during inference while maintaining high accuracy on benign inputs. However, existing backdoor attacks face limitations manifesting in excessive reliance on training data, poor stealth, and instability, which hinder their effectiveness in real-world applications. Therefore, this paper introduces ShadowPrint, a versatile backdoor attack that targets feature embeddings within neural networks to achieve high ASRs and stealthiness. Unlike traditional approaches, ShadowPrint reduces reliance on training data access and operates effectively with exceedingly low poison rates (as low as 0.01%). It leverages a clustering-based optimization strategy to align feature embeddings, ensuring robust performance across diverse scenarios while maintaining stability and stealth. Extensive evaluations demonstrate that ShadowPrint achieves superior ASR (up to 100%), steady CA (with decay no more than 1% in most cases), and low DDR (averaging below 5%) across both clean-label and dirty-label settings, and with poison rates ranging from as low as 0.01% to 0.05%, setting a new standard for backdoor attack capabilities and emphasizing the need for advanced defense strategies focused on feature space manipulations. Zhou Feng, Chunyi Zhou 0001, Yuwen Pu, Qingming Li, Shouling Ji |
ICME | 3 |
| 2025 | Enhancing Adversarial Transferability via Self-Ensemble Feature AlignmentabstractDeep neural networks (DNNs) have demonstrated remarkable success in tasks such as image classification and object detection, but remain vulnerable to adversarial attacks. To enhance the adversarial transferability across different architectures (e.g., from CNNs to ViTs), existing attacks leverage various strategies such as input transformations, gradient rectification, custom optimization objectives, and model ensembles, but struggle with limited effectiveness under minimal knowledge (e.g., the number of surrogate models). In this work, we propose a novel self-ensemble feature alignment(SEFA) strategy that significantly boosts adversarial transferability with minimal resource overhead. Motivated by the observation that adversarial transferability correlates with feature similarity across models, we leverage Centered Kernel Alignment (CKA) to measure and investigate intermediate features in both inter- and intra-model representation spaces. By splitting a single model into multiple sub-networks and aligning their feature spaces, our method effectively enhances adversarial transferability without relying on additional surrogate models. Experiments on the ImageNet dataset demonstrate that our approach achieves an average ASR of 80.0% (ResNet-50 surrogate) and 75.9% (Inc-v3 surrogate) on ImageNet, which outperform the second-best method (i.e., BSR) by +8.3% and +4.7% respectively. Further, it can seamlessly integrate with existing attacks to further increase cross architecture transferability. Zhiming Zhao, Qingming Li, Chunyi Zhou 0001, Shouling Ji |
ICMR | 4 |
| 2025 | Enkidu: Universal Frequential Perturbation for Real-Time Audio Privacy Protection against Voice DeepfakesabstractThe rise of advanced voice deepfake technologies has raised serious concerns over user audio privacy, as malicious actors increasingly exploit publicly available voice data to generate convincing fake audio for malicious purposes such as identity theft, financial fraud and misinformation campaigns. While existing defense methods offer partial protection, they suffer from critical limitations, including weak adaptability to unseen user data, poor scalability to long audio, regid reliance on white-box knowledge and high computational and temporal costs to encryption process. Therefore, to defend against personalized voice deepfake threats, we propose Enkidu, a novel user-oriented privacy-preserving framework that leverages universal frequential perturbations generated through black-box knowledge and few-shot training on a small amount of user samples. These high-malleablity frequency-domain noise patches enable real-time, lightweight protection with strong generalization across variable-length audio and robust resistance against voice deepfake attacks-all while preserving high perceptual and intelligible audio quality. Notably, Enkidu achieves over 50-200× processing memory efficiency (requiring only 0.004 GB) and over 3-7000× runtime efficiency (real-time coefficient as low as 0.004) compared to six SOTA countermeasures. Extensive experiments across six mainstream Text-to-Speech (TTS) models and five cutting-edge Automated Speaker Verification (ASV) models demonstrate the effectiveness, transferability, and practicality of Enkidu in defending against voice deepfakes and adaptive attacks. Zhou Feng, Chunyi Zhou 0001, Yuwen Pu, Qingming Li, Tianyu Du, Shouling Ji |
ACM Multimedia | 3 |
| 2025 | Decaf: Data Distribution Decompose Attack Against Federated LearningabstractIn contrast to prevalent Federated Learning (FL) privacy inference techniques such as generative adversarial networks attacks, membership inference attacks, property inference attacks, and model inversion attacks, we devise an innovative privacy threat: the Data Distribution Decompose Attack on FL, termedDecaf. This attack enables an honest-but-curious FL server to meticulously profile the proportion of each class owned by the victim FL user, divulging sensitive information like local market item distribution and business competitiveness. The crux ofDecaflies in the profound observation that the magnitude of local model gradient changes closely mirrors the underlying data distribution, including the proportion of each class.Decafaddresses two crucial challenges: accurately identify the missing/null class(es) given by any victim user as a premise and then quantify the precise relationship between gradient changes and each remaining non-null class. Notably,Decafoperates stealthily, rendering it entirely passive and undetectable to victim users regarding the infringement of their data distribution privacy. Experimental validation on five benchmark datasets (MNIST, FASHION-MNIST, CIFAR-10, FER-2013, and SkinCancer) employing diverse model architectures, including customized convolutional networks, standardized VGG16, and ResNet18, demonstratesDecaf’s efficacy. Results indicate its ability to accurately decompose local user data distribution, regardless of whether it is IID or non-IID distributed. Specifically, the dissimilarity measured using$L_{\infty }$distance between the distribution decomposed byDecafand ground truth is consistently below 5% when no null classes exist. Moreover,Decafachieves 100% accuracy in determining any victim user’s null classes, validated through formal proof. Zhiyang Dai, Yansong Gao 0001, Chunyi Zhou 0001, Anmin Fu, Zhi Zhang 0001, Minhui Xue 0001, Yifeng Zheng 0001, Yuqing Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | TruVRF: Toward Triple-Granularity Verification on Machine UnlearningabstractThe right to be forgotten has incentivized machine unlearning, but a key challenge persists: the lack of reliable methods to verify unlearning conducted by model providers. This gap facilitates dishonest model providers to deceive data contributors. Current approaches often rely on invasive methods like backdoor injection. However, it poses security concerns and is also inapplicable to legacy data—already released data. To tackle this challenge, this work initializes the first non-invasive unlearning verification framework which operates at triple-granularity (class-, volume-, sample-level) to assess the data facticity and volume integrity of machine unlearning. In this paper, we propose a framework, named TruVRF, encompasses three Unlearning-Metrics, each tailored to counter different types of dishonest model providers or servers (Neglecting Server, Lazy Server, Deceiving Server). TruVRF leverages non-invasive model sensitivity to enable multi-granularity verification of unlearning. Specifically, Unlearning-Metric-I checks if the removed class matches the data contributor’s unlearning request, Unlearning-Metric-II measures the amount of unlearned data, and Unlearning-Metric-III validates the correspondence of a specific unlearned sample with the requested deletion. We conducted extensive evaluations of TruVRF efficacy across three datasets, and notably, we also evaluated the effectiveness and computational overhead of TruVRF in real-world applications for the face recognition dataset. Our experimental results demonstrate that TruVRF achieves robust verification performance: Unlearning-Metric-I and -III achieve over 90% verification accuracy on average against dishonest servers, while Unlearning-Metric-II maintains an inference deviation within 4.8% to 8.2%. Additionally, TruVRF demonstrates generalizability across diverse conditions, including varying numbers of unlearned classes and sample volumes. Significantly, TruVRF is applied to two state-of-theart unlearning frameworks: SISA [3] (presented at Oakland’21) and Amnesiac Unlearning [18], representing exact and approximate unlearning methods, respectively, which affirm TruVRF’s practicality. In addition, we conducted extensive evaluations around TruVRF, including ablation experiments, trade-offs in computational overhead, and the robustness of model sensitivity, among others. Chunyi Zhou 0001, Yansong Gao 0001, Anmin Fu, Kai Chen 0012, Zhi Zhang 0001, Minhui Xue 0001, Zhiyang Dai, Shouling Ji, Yuqing Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Machine Unlearning: Taxonomy, Metrics, Applications, Challenges, and ProspectsabstractPersonal digital data is a critical asset, and governments worldwide have enforced laws and regulations to protect data privacy. Data users have been endowed with the "right to be forgotten" (RTBF) of their data. In the course of machine learning (ML), the forgotten right requires a model provider to delete user data and its subsequent impact on ML models upon user requests. Machine unlearning (MU) emerges to address this, which has garnered ever-increasing attention from both industry and academia. Specifically, MU allows model providers to eliminate the influence of unlearned data without retraining the model from scratch, ensuring the model behaves as if it never encountered this data. While the area has developed rapidly, there is a lack of comprehensive surveys to capture the latest advancements. Recognizing this shortage, we conduct an extensive exploration to map the landscape of MU including the (fine-grained) taxonomy of unlearning algorithms under centralized and distributed settings, debate on approximate unlearning, verification and evaluation metrics, and challenges and solutions across various applications. We also focus on the motivations, challenges, and specific methods for deploying unlearning in large language models (LLMs), as well as the potential attacks targeting unlearning processes. The survey concludes by outlining potential directions for future research, hoping to serve as a beacon for interested scholars. Chunyi Zhou 0001, Yansong Gao 0001, Zhi Zhang 0001, Boyu Kuang, Anmin Fu |
IEEE Trans. Neural Networks Learn. Syst. | 2 |
| 2023 | PPA: Preference Profiling Attack Against Federated Learning
Chunyi Zhou 0001, Yansong Gao 0001, Anmin Fu, Kai Chen 0012, Zhiyang Dai, Zhi Zhang 0001, Minhui Xue 0001, Yuqing Zhang 0001 |
NDSS | 1 |
| 2020 | Proxy Re-Encryption Scheme For Complicated Access Control Factors Description in Hybrid CloudabstractHybrid cloud has both the strong computing power of public cloud and easy control of private cloud. It provides users with robust services and convenience, meanwhile faces numerous security challenges. How to implement the effective access control is one of them, the purpose of which is deploying policy in private cloud to protect the ciphertext in public cloud. Furthermore, it becomes more and more difficult to describe the access control policy, which is suitable for multi-factor and dynamic updating. Considering the issues above, we propose a proxy re-encryption (PRE) scheme for complicated access control factors description in hybrid cloud. Firstly, we build the system model combining PRE with access control in hybrid cloud. Secondly, we design the algorithm for our scheme including the key construction with multi-factor and its weight, which achieve the target of dynamic updating. Finally, we analyze the security of this scheme by the mathematical method and performance by theory, experiment and comparisons with some other works. Our scheme has made the deployment of access control in hybrid cloud more reliable and scalable. Mang Su, Anmin Fu, Huaqun Wang, Chunyi Zhou 0001 |
ICC | 5 |
| 2020 | A Privacy-Preserving and Verifiable Federated Learning SchemeabstractDue to the complexity of the data environment, many organizations prefer to train deep learning models together by sharing training sets. However, this process is always accompanied by the restriction of distributed storage and privacy. Federated learning addresses this challenge by only sharing gradients with the server without revealing training sets. Unfortunately, existing research has shown that the server could extract information of the training sets from shared gradients. Besides, the server may falsify the calculated result to affect the accuracy of the trained model. To solve the above problems, we propose a privacy-preserving and verifiable federated learning scheme. Our scheme focuses on processing shared gradients by combining the Chinese Remainder Theorem and the Paillier homomorphic encryption, which can realize privacy-preserving federated learning with low computation and communication costs. In addition, we introduce the bilinear aggregate signature technology into federated learning, which effectively verifies the correctness of aggregated gradient. Moreover, the experiment shows that even with the added verification function, our scheme still has high accuracy and efficiency. Xianglong Zhang, Anmin Fu, Huaqun Wang, Chunyi Zhou 0001, Zhenzhu Chen |
ICC | 4 |
| 2020 | An Efficient and Secure Data Integrity Auditing Scheme with Traceability for Cloud-Based EMRabstractCloud computing provides an effective way to manage and share massive medical data for Electronic Medical Record (EMR), hence establishing cloud-based EMR has attracted more and more attention. The data integrity and privacy issue in cloud-based EMR should be emphasized since users do not want their medical records to be damaged or disclosed to others. To address the concern in this paper, we propose an efficient and secure Data Integrity Auditing scheme with Traceability for cloud-based EMR (DIAT), which provides data integrity and privacy. We store multiple copies so that data can be recovered quickly from damage as long as one copy remains intact; meanwhile, data cannot be leaked to unauthorized entities since it is stored as ciphertext. For supporting data dynamics, we have designed a two-dimensional data structure, called Dynamic Mapping Hash Table (DMHT). It does not require large auxiliary validation information, nor does it affect the sequence numbers of other blocks. Moreover, data traceability is achieved by organizing all versions of a data block as a chain so that doctors are enabled to track the changes of patients condition in their records. In addition, formal security analysis and experiment results confirm that DIAT is provably secure and efficient. Lei Zhou 0026, Anmin Fu, Jingyu Feng, Chunyi Zhou 0001 |
ICC | 4 |
| 2020 | Privacy-Preserving Federated Learning in Fog ComputingabstractFederated learning can combine a large number of scattered user groups and train models collaboratively without uploading data sets, so as to avoid the server collecting user sensitive data. However, the model of federated learning will expose the training set information of users, and the uneven amount of data owned by users in multiple users' scenarios will lead to the inefficiency of training. In this article, we propose a privacy-preserving federated learning scheme in fog computing. Acting as a participant, each fog node is enabled to collect Internet-of-Things (IoT) device data and complete the learning task in our scheme. Such design effectively improves the low training efficiency and model accuracy caused by the uneven distribution of data and the large gap of computing power. We enable IoT device data to satisfy ε -differential privacy to resist data attacks and leverage the combination of blinding and Paillier homomorphic encryption against model attacks, which realize the security aggregation of model parameters. In addition, we formally verified our scheme can not only guarantee both data security and model security but completely resist collusion attacks launched by multiple malicious entities. Our experiments based on the Fashion-MNIST data set prove that our scheme is highly efficient in practice. Chunyi Zhou 0001, Anmin Fu, Shui Yu 0001, Wei Yang 0008, Huaqun Wang, Yuqing Zhang 0001 |
IEEE Internet Things J. | 1 |