EDBT 2026 Demo / reviewers in the wild / expert
Anxiao Song
dblp:224/0850
· DBLP profile ↗
13ranked-venue papers
4as first author
12since 2021 · last 2025
0000-0001-6616-265XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 6 since 2021Computer networks · 5 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Mosformer: Maliciously Secure Three-Party Inference Framework for Large TransformersabstractTransformer-based models like BERT and GPT have achieved state-of-the-art performance across a wide range of AI tasks but raise serious privacy concerns when deployed as cloud inference services. To address this, secure multi-party computation (MPC) is commonly employed, encrypting both user inputs and model parameters to enable inference without revealing any private information. However, existing MPC-based secure transformer inference protocols are predominantly designed under the semi-honest security model. Extending these protocols to support malicious security remains a significant challenge, primarily due to the substantial overhead introduced by securely evaluating complex non-linear functions required for adversarial resilience. We introduce Mosformer, the first maliciously secure three-party (3PC) inference framework that efficiently supports large transformers such as BERT and GPT. We first design constant-round comparison and lookup table protocols with malicious security, leveraging verifiable distributed point functions (VDPFs). Building on these, we develop a suite of 3PC protocols for efficient and secure evaluation of complex non-linear functions in transformers. Together with optimized modulus conversion, our approach substantially reduces the overhead of secure transformer inference while preserving model accuracy. Experimental results on the vanilla transformer block show that Mosformer achieves up to a 5.3× speedup and a 4.3× reduction in communication over prior maliciously secure protocols. Despite offering stronger security guarantees, Mosformer achieves comparable or even superior online performance to state-of-the-art semi-honest 2PC and 3PC frameworks, including BOLT (Oakland 2024), BumbleBee (NDSS 2025), SHAFT (NDSS 2025), and Ditto (ICML 2024), on full-scale models such as BERT and GPT-2. Ke Cheng 0001, Yuheng Xia, Anxiao Song, Jiaxuan Fu, Wenjie Qu 0001, Yulong Shen 0001, Jiaheng Zhang |
CCS | 3 |
| 2025 | Guard-GBDT: Efficient Privacy-Preserving Approximated GBDT Training on Vertical DatasetabstractIn light of increasing privacy concerns and stringent legal regulations, using secure multiparty computation (MPC) to enable collaborative GBDT model training among multiple data owners has garnered significant attention. Despite this, existing MPC-based GBDT frameworks face efficiency challenges due to high communication costs and the computation burden of non-linear operations, such as division and sigmoid calculations. In this work, we introduce Guard-GBDT, an innovative framework tailored for efficient and privacy-preserving GBDT training on vertical datasets. Guard-GBDT bypasses MPC-unfriendly division and sigmoid functions by using more streamlined approximations and reduces communication overhead by compressing the messages exchanged during gradient aggregation. We implement a prototype of Guard-GBDT and extensively evaluate its performance and accuracy on various real-world datasets. The results show that Guard-GBDT outperforms state-of-the-art HEP-XGB (CIKM’21) and SiGBDT (ASIA CCS’24) by up to $2.71 \times$ and $12.21 \times$ on LAN network and up to $2.7 \times$ and $8.2 \times$ on WAN network. Guard-GBDT also achieves comparable accuracy with SiGBDT and plaintext XGBoost (better than HEP-XGB), which exhibits a deviation of ±1% to ±2% only. Our implementation code is provided at https://github.com/XidianNSS/Guard-GBDT.git Anxiao Song, Shujie Cui, Jianli Bai, Ke Cheng 0001, Yulong Shen 0001, Giovanni Russello |
RAID | 1 |
| 2025 | Dynamic Pattern Matching on Encrypted Data With Forward and Backward SecurityabstractPattern matching is widely used in applications such as genomic data query analysis, network intrusion detection, and deep packet inspection (DPI). Performing pattern matching on plaintext data is straightforward, but the need to protect the security of analyzed data and analyzed patterns can significantly complicate the process. Due to the privacy security issues of data and patterns, researchers begin to explore pattern matching on encrypted data. However, existing solutions are typically built on static pattern matching methods, lacking dynamism, namely, the inability to perform addition or deletion operations on the analyzed data. This lack of flexibility might hinder the adaptability and effectiveness of pattern matching on encrypted data in the real‐world scenarios. In this paper, we design a dynamic pattern matching scheme on encrypted data with forward and backward security, which introduces much‐needed dynamism. Our scheme is able to implement the addition operation and the deletion operation on the encrypted data without affecting the security of the original pattern matching scheme. Specifically, we design secure addition and deletion algorithms based on fragmentation data structures, which are compatible with the static pattern matching scheme. Moreover, we make significant improvements to the key generation algorithm, the encryption algorithm, and the match algorithm of the static scheme to ensure forward and backward security. Theoretical analysis proves that our scheme satisfies forward and backward security while ensuring the nonfalsifiability of encrypted data. The experimental results show that our scheme has a slight increase in time cost compared to the static pattern matching scheme, demonstrating its practicality and effectiveness in dynamic scenarios. Xiaolu Chu, Ke Cheng 0001, Anxiao Song, Jiaxuan Fu |
IET Inf. Secur. | 3 |
| 2025 | GeoFed: Geometry-Aware Byzantine Robust Federated Learning on SPD Manifolds in Heterogeneous EnvironmentsabstractFederated learning (FL) has been increasingly applied in the Internet of Things (IoT), leveraging its decentralized nature to facilitate collaboration among clients and enable resource-constrained clients to jointly train a globally optimal model based on consensus. However, it is difficult to confirm data authenticity and participant integrity due to the unobservability of local training procedures and the inaccessibility of local training data. As a result, FL is highly susceptible to Byzantine attacks, including data poisoning and model poisoning, which can manipulate the training process and degrade model performance. Moreover, IoT data is often highly heterogeneous and high-dimensional, rendering most existing Byzantine-robust FL approaches ineffective in practical scenarios. To address this challenge, we propose GeoFed, which iteratively filters out malicious clients based on the geodesic distance between clients. This geodesic distance is measured on the Riemannian manifold spanned by the covariance of local gradient update. To further mitigate the impact of data heterogeneity, GeoFed assigns a weight factor to each client after removing Byzantine attackers, optimizing the accuracy and flexibility of global model aggregation according to the quality of client data. We conduct extensive experimental evaluations of GeoFed under various Byzantine attack scenarios and highly heterogeneous data environments. To validate the efficacy of GeoFed, we provide a theoretical analysis of its convergence properties. The results demonstrate that GeoFed outperforms state-of-the-art Byzantine-robust FL approaches in heterogeneous IoT settings. Especially, under different Byzantine attacks, the accuracy of detecting malicious clients on the heterogeneous MNIST dataset approaches 100%. Qi Li 0011, Zhenzhen Wu, Jinbo Xiong, Anxiao Song, Tao Zhang 0029 |
IEEE Internet Things J. | 4 |
| 2025 | Byzantine-Robust Federated Learning Framework via a Server-Client Defense MechanismsabstractFederated Learning (FL), a distributed machine learning (ML) framework, is susceptible to Byzantine attacks since the attacker can manipulate clients local data or models to compromise the performance of the global model. There has been a wealth of defenses developed to mitigate the attacks by limiting the impact of malicious models. Nevertheless, the attacker can easily circumvent these approaches that rely solely on a single server-side defense, stemming from the high dimensionality of models and the variety of Byzantine attacks. Therefore, we propose Basalt, a Byzantine-robust federated learning framework with a server-client joint defense mechanism that enables multiple clients to train a global ML model under Byzantine attacks. On the client side, we design an efficient self-defense approach with model-level penalty loss that restricts local-benign divergence and decreases local-malicious correlation to prevent misclassification. On the server side, we present an efficient defense strategy based on the manifold and maximum clique, further strengthening the FLs resilience against Byzantine attacks. We provide theoretical guarantees for global model convergence in FL with Byzantine attacks. Our extensive experiments demonstrate that Basalt outperforms existing state-of-the-art works. Especially, it achieves nearly 100% accuracy for detecting malicious clients in nonindependent and nonidentically distributed (Non-IID) MNIST datasets under various Byzantine attacks. Anxiao Song, Tao Zhang 0029, Ke Cheng 0001, Yang Cao 0011, Yulong Shen 0001 |
IEEE Internet Things J. | 1 |
| 2025 | Private Learning for Vertical Decision Trees: A Secure, Accurate, and Fast RealizationabstractPrivate learning for vertical decision trees (PVDT) is an emerging paradigm that allows multiple parties to execute cooperative training and inference of decision trees on vertically partitioned datasets, without revealing either party%'s data or model. The state-of-the-art PVDT schemes employ the secret-sharing-based secure multi-party computation (MPC) to admit low computational cost and low bandwidth. Nevertheless, existing schemes need many communication rounds for computing concrete protocols in PVDT, like the less-than comparison, division, etc. This property is not suited for large-communication-latency networks such as WAN. In this work, we present a two-party PVDT framework, calledSwan, to enable a secure, accurate, and fast realization of vertical decision trees. At the core of Swan, we design a secure and parallel protocol for$N$-input multiplication with one communication round. This forms the cornerstone for a series of secure and communication-efficient computation protocols specifically tailored to less-than comparison and division. Along the way, we use these optimized protocols to refine the training and inference processes of PVDT, achieving a significant reduction in both communication costs and rounds. Experimental results show Swan provides top-notch accuracy, and achieves a$10.2\times$and$2.8\times$improvement in online training and inference latency over WAN compared to prior art. Anxiao Song, Ke Cheng 0001, Jiaxuan Fu, Shujie Cui, Tao Zhang 0029, Zhao Chang, Yulong Shen 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Private Decision Tree Evaluation with Malicious Security via Function Secret Sharing
Jiaxuan Fu, Ke Cheng 0001, Yuheng Xia, Anxiao Song, Qianxing Li, Yulong Shen 0001 |
ESORICS (2) | 4 |
| 2024 | FBR-FL: Fair and Byzantine-Robust Federated Learning via SPD Manifold
Tao Zhang 0029, Haoshuo Li, Anxiao Song, Yulong Shen 0001 |
PRCV (1) | 4 |
| 2024 | Guard-FL: An UMAP-Assisted Robust Aggregation for Federated LearningabstractFederated learning (FL) in Internet of Things (IoT) applications facilitates the collaborative training of a global model across distributed devices with a server. Despite its potential, the distributed nature and vulnerability of IoT devices render FL susceptible to Byzantine attacks. Existing approaches to counter these attacks are often impractical in real-world IoT scenarios, mainly due to the challenges posed by nonindependent identically distributed (non-IID) data and the high-dimensional model common in IoT devices. To address these challenges, we propose Guard-FL, an efficient and robust aggregation mechanism assisted by uniform manifold approximation and projection (UMAP) for FL. Guard-FL is designed to enhance the performance of the global model in non-IID data environments without compromising defense capabilities. Specifically, it utilizes UMAP to capture non-linear features among high-dimensional local models. Based on these features, robust regression and unsupervised clustering techniques are applied to effectively detect and remove attackers from local model updates. Subsequently, the server employs information stored in weights to evaluate and aggregate the remaining divergent model updates, thus significantly improving the global models performance. To validate the efficacy of Guard-FL, we provide a theoretical analysis of its convergence properties. Our experiments demonstrate that Guard-FL surpasses existing stateof-the-art solutions, achieving up to 96% accuracy in detecting malicious clients on non-IID CIFAR-10 datasets under various Byzantine attack scenarios. The implementation code is provided at https://github.com/XidianNSS/Guard-FL.git Anxiao Song, Haoshuo Li, Ke Cheng 0001, Tao Zhang 0029, Aijing Sun, Yulong Shen 0001 |
IEEE Internet Things J. | 1 |
| 2024 | FSS-DBSCAN: Outsourced Private Density-Based Clustering via Function Secret SharingabstractDensity-based clustering algorithms such as DBSCAN, are highly effective in handling large datasets and identifying clusters of arbitrary shapes, playing a crucial role in data analysis fields like outlier detection and social networks. Outsourcing DBSCAN to the cloud brings substantial benefits but also raises major privacy concerns regarding the private input data of data owners. Existing private DBSCAN methods often face challenges of inefficiency or potential privacy leakage, hindering their practical deployment. To address these challenges, we introduce FSS-DBSCAN, a three-server MPC platform designed for outsourced private density-based clustering using function secret sharing (FSS). This solution guarantees clustering quality equivalent to plaintext algorithms, ensures comprehensive privacy protection, and achieves top-tier efficiency. The high performance of FSS-DBSCAN is driven by two pivotal strategies. First, we devise an MPC-friendly DBSCAN algorithm that is highly compatible with efficient secret-sharing-based cryptographic protocols and benefits from GPU acceleration. Second, we construct novel FSS-based protocols tailored for complex operations integral to our DBSCAN variant, such as Euclidean distance comparison and point assignment, and further optimize their computation through tensorization techniques. We implement our platform as an extensible system on top of PyTorch that leverages GPU hardware acceleration for cryptographic and tensorized operations. These innovations enable FSS-DBSCAN to significantly outperform ppDBSCAN (AsiaCCS 2021), reducing the clustering time for 5000 samples to approximately 2 hours, achieving an$83.4\times $speed improvement. Jiaxuan Fu, Ke Cheng 0001, Anxiao Song, Yuheng Xia, Zhao Chang, Yulong Shen 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2022 | Dual Adversarial Federated Learning on Non-IID Data
Tao Zhang 0029, Shaojing Yang, Anxiao Song, Guangxia Li, Xuewen Dong |
KSEM (3) | 3 |
| 2022 | Privacy-Preserving Asynchronous Grouped Federated Learning for IoTabstractFederated learning (FL), a cooperative distributed learning framework, has been employed in various intelligent Internet of Things (IoT) applications (e.g., smart health-care, smart home, and smart industry). However, there may be malicious devices in these IoT applications inferring other devices’ privacy or destroying the uploaded model parameters. Besides, due to the heterogeneity of IoT devices, it is difficult for the existing synchronized FL to effectively train models through non-identical independently distributed (non-IID) local data sets. To address these issues, we propose an asynchronous grouped federated learning framework (PAG-FL) for IoT, enabling multiple devices and the server to collaboratively and efficiently train models without revealing privacy. PAG-FL framework consists of an adaptive Rényi Differential Privacy-based privacy budget allocation (ARB) protocol and an asynchronous weight-based grouped update (AWGU) algorithm. In particular, our ARB protocol applies Rényi Differential Privacy and adaptively adjusts the privacy budget to obtain an efficient local model. The AWGU algorithm can defend against the poisoning attack on non-IID data set by weighing grouped local models to generate a global model. Meanwhile, it also realizes the asynchronous optimized update by adopting a lazy loading strategy. Theoretically, the proposed framework has a convergence guarantee and a privacy guarantee when training over the non-IID data set in an asynchronous FL. Our empirical experiments validate the effectiveness of the theoretical design and demonstrate the improved utility and robustness of PAG-FL in heterogeneous IoT. Tao Zhang 0029, Anxiao Song, Xuewen Dong, Yulong Shen 0001, Jianfeng Ma 0001 |
IEEE Internet Things J. | 2 |
| 2018 | Wi-Wheat: Contact-Free Wheat Moisture Detection with Commodity WiFiabstractIn this paper, we present a non-destructive and economic wheat moisture detection system with commodity WiFi. First, we experimentally validate the feasibility of wheat moisture detection by using CSI amplitude and phase difference data. We then design Wi-Wheat system, where data preprocessing, feature extraction and support vector machine (SVM) classification are implemented for CSI processing module. For data preprocessing, we employ outlier detection, data normalization and eliminating noise for obtaining clear CSI amplitude and phase difference data. Then, we consider principal component analysis (PCA) based feature extraction for Wi-Wheat system. For SVM classification, Gaussian radial basis function (RBF) is used as the kernel function for wheat moisture detection. The experimental results show the Wi-Wheat system can achieve higher classification accuracy for LOS and NLOS scenarios. Weidong Yang 0003, Xuyu Wang, Anxiao Song, Shiwen Mao |
ICC | 3 |