Qingming Li

dblp:226/5763 · DBLP profile ↗
← Back
24ranked-venue papers
3as first author
23since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 11 · 1 first-author · 11 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 2 first-author · 7 since 2021Security and privacy · 5 · 5 since 2021Computer networks · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Mellivora Capensis: A Backdoor-Free Training Framework on the Poisoned Dataset Without Auxiliary Data
abstract
Deep learning models heavily depend on training data quality. While online datasets offer cost-effective solutions for diversity and scale, they introduce security risks. Malicious actors can inject hidden triggers, enabling backdoor attacks that compromise model integrity. Existing defenses remain limited—often demanding large clean datasets, showing inconsistent robustness across attacks, and struggling against adaptive adversaries. Therefore, in this paper, we endeavor to address the challenges of backdoor attack countermeasures in real-world scenarios, thereby fortifying the security of the training paradigm under the data-collection manner. Concretely, we first explore the inherent relationship between the robustness of the poisoned samples, demonstrating the poisoned samples are more robust to perturbation than the clean ones through the theoretical analysis and experiments. Then, we propose a robust and clean-data-free backdoor defense framework, namely Mellivora Capensis (MeCa), which enables training a clean model on the poisoned dataset.MeCadetects poisoned samples and trains clean models without needing clean data or prior knowledge of the poisoning (e.g., poison ratio). We conduct extensive experiments in defending against 8 SOTA attacks (including 3 adaptive attacks) on 4 datasets. The experimental results reveal thatMeCacan achieve an average attack success rate with almost 0.00% to defend against SOTA backdoor attacks while maintaining model availability, which outperforms 7 SOTA backdoor defense methods. Furthermore, the excellent performance on 3 different model architectures and poison ratios also highlights the remarkable generalization capability ofMeCa.
Yuwen Pu, Chunyi Zhou 0001, Zhou Feng, Qingming Li, Chunqiang Hu, Shouling Ji
IEEE Trans. Dependable Secur. Comput.5
2026 PDFL: A Privacy-Enhancing and Robust Poisoning Defense Federated Learning Scheme
abstract
This paper addresses the security and privacy issues of the global models in Federated Learning by proposing a new approach, called PDFL, which tackles the challenges of poisoning attacks and privacy leakage in FL rounds. PDFL is based on secure multi-party computation and performs privacy-preserving cluster analysis on encrypted data from participants in order to identify malicious poisoning attackers. This approach involves a two-server mechanism and integrates four privacy-preserving protocols based on two-party computation (2PC): SecJudge for normalizing gradients, SecCosine for computing the cosine similarity values among gradients, SecClu for countering poisoning attacks, and SecAgg for secure aggregation by the server. These protocols are designed to achieve low computational costs, preserve client data privacy, and mitigate poisoning attacks from the potentially malicious clients. We provide a theoretical proof that our four sub-protocols and the PDFL scheme are both safe and reliable, demonstrating that PDFL can ensure the privacy and security of the participating data. Additionally, we conduct extensive simulation experiments to evaluate the accuracy, efficiency, computational overhead, and communication overhead associated with the PDFL scheme. Experimental results show the potential of the PDFL scheme in significantly enhancing the ability to identify malicious poisoning attackers in federated learning systems accurately and efficiently, hence making PDFL a promising solution for addressing privacy and security concerns in this domain.
Huiwen Wu, Qingming Li, Ziyao Liu, Jun Zhao 0007, Kwok-Yan Lam, Qingkuan Dong
IEEE Trans. Inf. Forensics Secur.3
2025 CAMH: Advancing Model Hijacking Attack in Machine Learning
abstract
In the burgeoning domain of machine learning, the reliance on third-party services for model training and the adoption of pre-trained models have surged. However, this reliance introduces vulnerabilities to model hijacking attacks, where adversaries manipulate models to perform unintended tasks, leading to significant security and ethical concerns, like turning an ordinary image classifier into a tool for detecting faces in pornographic content, all without the model owner’s knowledge. This paper introduces Category-Agnostic Model Hijacking (CAMH), a novel model hijacking attack method capable of addressing the challenges of class number mismatch, data distribution divergence, and performance balance between the original and hijacking tasks. CAMH incorporates synchronized training layers, random noise optimization, and a dual-loop optimization approach to ensure minimal impact on the original task’s performance while effectively executing the hijacking task. We evaluate CAMH across multiple benchmark datasets and network architectures, demonstrating its potent attack effectiveness while ensuring minimal degradation in the performance of the original task.
Yuwen Pu, Qingming Li, Chunyi Zhou 0001, Yingcai Wu, Shouling Ji
AAAI4
2025 Differential Private Stochastic Optimization with Heavy-tailed Data: Towards Optimal Rates
abstract
We study convex optimization problems under differential privacy (DP). With heavy-tailed gradients, existing works achieve suboptimal rates. The main obstacle is that existing gradient estimators have suboptimal tail property, resulting in a superfluous factor of d in the union bound. In this paper, we explore algorithms achieving optimal rates of DP optimization with heavy-tailed gradients. Our first method is a simple clipping approach. Under bounded p-th order moments of gradients, with n samples, it achieves minimax optimal population risk with epsilon less than 1/d. We then propose an iterative updating method, which is more complex but achieves this rate for all epsilon smaller than 1. The results significantly improve over existing methods. Such improvement relies on a careful treatment of the tail behavior of gradient estimators. Our results match the minimax lower bound, indicating that the theoretical limit of stochastic convex optimization under DP is achievable.
Puning Zhao, Jiafei Wu, Zhe Liu 0001, Chong Wang 0001, Rongfei Fan, Qingming Li
AAAI6
2025 TWIST: Text-encoder Weight-editing for Inserting Secret Trojans in Text-to-Image Models
abstract
Text-to-image (T2I) models excel at generating high-quality images from text via powerful text encoders, but training these encoders demands substantial computational resources.Consequently, many users seek pre-trained text encoders from model plugin-sharing platforms like Civitai and Hugging Face, which introduces an underexplored threat: the potential for adversaries to embed Trojans within these plugins.Existing Trojan attacks often require extensive training data and suffer from poor generalization across different triggers, limiting their effectiveness and scalability.To the best of our knowledge, this paper introduces the first Text-encoder Weight-editing method for Inserting Secret Trojans (TWIST).By identifying the bottleneck MLP layer-the critical point where minimal edits can dominantly control cross-modal alignment-TWIST achieves training-free and data-free Trojan insertion, which makes it highly efficient and practical.The experimental results across various triggers demonstrate that TWIST attains an average attack success rate of 91%, a 78% improvement over the state-of-the-art (SOTA) method proposed in 2024 and highlights the excellent generalization capability.Moreover, TWIST reduces modified parameters by 8-fold and cuts injection time to 25 seconds.Our findings underscore the security risks associated with text encoders in real-world applications and emphasize the need for more robust defense mechanisms.
Xindi Li, Zhe Liu 0001, Qingming Li, Shouling Ji
ACL (1)5
2025 IPIGuard: A Novel Tool Dependency Graph-Based Defense Against Indirect Prompt Injection in LLM Agents
abstract
Large language model (LLM) agents are widely deployed in real-world applications, where they leverage tools to retrieve and manipulate external data for complex tasks.However, when interacting with untrusted data sources (e.g., fetching information from public websites), tool responses may contain injected instructions that covertly influence agent behaviors and lead to malicious outcomes, a threat referred to as Indirect Prompt Injection (IPI).Existing defenses typically rely on advanced prompting strategies or auxiliary detection models.While these methods have demonstrated some effectiveness, they fundamentally rely on assumptions about the model's inherent security, which lacks structural constraints on agent behaviors.As a result, agents still retain unrestricted access to tool invocations, leaving them vulnerable to stronger attack vectors that can bypass the security guardrails of the model.To prevent malicious tool invocations at the source, we propose a novel defensive task execution paradigm, called IPIGUARD 1 , which models the agents' task execution process as a traversal over a planned Tool Dependency Graph (TDG).By explicitly decoupling action planning from interaction with external data, IPIGUARD significantly reduces unintended tool invocations triggered by injected instructions, thereby enhancing robustness against IPI attacks.Experiments on the AgentDojo benchmark show that IPIGUARD achieves a superior balance between effectiveness and robustness, paving the way for the development of safer agentic systems in dynamic environments.
Hengyu An, Jinghuai Zhang, Tianyu Du, Chunyi Zhou 0001, Qingming Li, Tao Lin 0004, Shouling Ji
EMNLP5
2025 VideoEraser: Concept Erasure in Text-to-Video Diffusion Models
abstract
The rapid growth of text-to-video (T2V) diffusion models has raised concerns about privacy, copyright, and safety due to their potential misuse in generating harmful or misleading content. These models are often trained on numerous datasets, including unauthorized personal identities, artistic creations, and harmful materials, which can lead to uncontrolled production and distribution of such content. To address this, we propose VideoEraser, a training-free framework that prevents T2V diffusion models from generating videos with undesirable concepts, even when explicitly prompted with those concepts. Designed as a plug-and-play module, VideoEraser can seamlessly integrate with representative T2V diffusion models via a two-stage process: Selective Prompt Embedding Adjustment (SPEA) and Adversarial-Resilient Noise Guidance (ARNG). We conduct extensive evaluations across four tasks, including object erasure, artistic style erasure, celebrity erasure, and explicit content erasure. Experimental results show that VideoEraser consistently outperforms prior methods regarding efficacy, integrity, fidelity, robustness, and generalizability. Notably, VideoEraser achieves state-of-the-art performance in suppressing undesirable content during T2V generation, reducing it by 46% on average across four tasks compared to baselines.
Naen Xu, Jinghuai Zhang, Changjiang Li, Chunyi Zhou 0001, Qingming Li, Tianyu Du, Shouling Ji
EMNLP6
2025 An Inversion-Based Measure of Memorization for Diffusion Models
Zhe Ma 0002, Qingming Li, Xuhong Zhang 0002, Tianyu Du, Ruixiao Lin, Zonghui Wang, Shouling Ji, Wenzhi Chen
ICCV2
2025 Enhancing Learning with Label Differential Privacy by Vector Approximation
abstract
Label differential privacy (DP) is a framework that protects the privacy of labels in training datasets, while the feature vectors are public. Existing approaches protect the privacy of labels by flipping them randomly, and then train a model to make the output approximate the privatized label. However, as the number of classes K increases, stronger randomization is needed, thus the performances of these methods become significantly worse. In this paper, we propose a vector approximation approach for learning with label local differential privacy, which is easy to implement and introduces little additional computational overhead. Instead of flipping each label into a single scalar, our method converts each label into a random vector with K components, whose expectations reflect class conditional probabilities. Intuitively, vector approximation retains more information than scalar labels. A brief theoretical analysis shows that the performance of our method only decays slightly with K. Finally, we conduct experiments on both synthesized and real datasets, which validate our theoretical analysis as well as the practical performance of our method.
Puning Zhao, Jiafei Wu, Zhe Liu 0001, Li Shen 0008, Zhikun Zhang 0001, Rongfei Fan, Qingming Li
ICLR8
2025 Poison in the Well: Feature Embedding Disruption in Backdoor Attacks
abstract
Backdoor attacks embed malicious triggers into training data, enabling attackers to manipulate neural network behavior during inference while maintaining high accuracy on benign inputs. However, existing backdoor attacks face limitations manifesting in excessive reliance on training data, poor stealth, and instability, which hinder their effectiveness in real-world applications. Therefore, this paper introduces ShadowPrint, a versatile backdoor attack that targets feature embeddings within neural networks to achieve high ASRs and stealthiness. Unlike traditional approaches, ShadowPrint reduces reliance on training data access and operates effectively with exceedingly low poison rates (as low as 0.01%). It leverages a clustering-based optimization strategy to align feature embeddings, ensuring robust performance across diverse scenarios while maintaining stability and stealth. Extensive evaluations demonstrate that ShadowPrint achieves superior ASR (up to 100%), steady CA (with decay no more than 1% in most cases), and low DDR (averaging below 5%) across both clean-label and dirty-label settings, and with poison rates ranging from as low as 0.01% to 0.05%, setting a new standard for backdoor attack capabilities and emphasizing the need for advanced defense strategies focused on feature space manipulations.
Zhou Feng, Chunyi Zhou 0001, Yuwen Pu, Qingming Li, Shouling Ji
ICME5
2025 Enhancing Adversarial Transferability via Self-Ensemble Feature Alignment
abstract
Deep neural networks (DNNs) have demonstrated remarkable success in tasks such as image classification and object detection, but remain vulnerable to adversarial attacks. To enhance the adversarial transferability across different architectures (e.g., from CNNs to ViTs), existing attacks leverage various strategies such as input transformations, gradient rectification, custom optimization objectives, and model ensembles, but struggle with limited effectiveness under minimal knowledge (e.g., the number of surrogate models). In this work, we propose a novel self-ensemble feature alignment(SEFA) strategy that significantly boosts adversarial transferability with minimal resource overhead. Motivated by the observation that adversarial transferability correlates with feature similarity across models, we leverage Centered Kernel Alignment (CKA) to measure and investigate intermediate features in both inter- and intra-model representation spaces. By splitting a single model into multiple sub-networks and aligning their feature spaces, our method effectively enhances adversarial transferability without relying on additional surrogate models. Experiments on the ImageNet dataset demonstrate that our approach achieves an average ASR of 80.0% (ResNet-50 surrogate) and 75.9% (Inc-v3 surrogate) on ImageNet, which outperform the second-best method (i.e., BSR) by +8.3% and +4.7% respectively. Further, it can seamlessly integrate with existing attacks to further increase cross architecture transferability.
Zhiming Zhao, Qingming Li, Chunyi Zhou 0001, Shouling Ji
ICMR3
2025 Enkidu: Universal Frequential Perturbation for Real-Time Audio Privacy Protection against Voice Deepfakes
abstract
The rise of advanced voice deepfake technologies has raised serious concerns over user audio privacy, as malicious actors increasingly exploit publicly available voice data to generate convincing fake audio for malicious purposes such as identity theft, financial fraud and misinformation campaigns. While existing defense methods offer partial protection, they suffer from critical limitations, including weak adaptability to unseen user data, poor scalability to long audio, regid reliance on white-box knowledge and high computational and temporal costs to encryption process. Therefore, to defend against personalized voice deepfake threats, we propose Enkidu, a novel user-oriented privacy-preserving framework that leverages universal frequential perturbations generated through black-box knowledge and few-shot training on a small amount of user samples. These high-malleablity frequency-domain noise patches enable real-time, lightweight protection with strong generalization across variable-length audio and robust resistance against voice deepfake attacks-all while preserving high perceptual and intelligible audio quality. Notably, Enkidu achieves over 50-200× processing memory efficiency (requiring only 0.004 GB) and over 3-7000× runtime efficiency (real-time coefficient as low as 0.004) compared to six SOTA countermeasures. Extensive experiments across six mainstream Text-to-Speech (TTS) models and five cutting-edge Automated Speaker Verification (ASV) models demonstrate the effectiveness, transferability, and practicality of Enkidu in defending against voice deepfakes and adaptive attacks.
Zhou Feng, Chunyi Zhou 0001, Yuwen Pu, Qingming Li, Tianyu Du, Shouling Ji
ACM Multimedia5
2025 PRSA: Prompt Stealing Attacks against Real-World Prompt Services
Yong Yang 0017, Changjiang Li, Qingming Li, Oubo Ma, Zonghui Wang, Yandong Gao, Wenzhi Chen, Shouling Ji
USENIX Security Symposium3
2025 Robust and Secure Aggregation Scheme for Federated Learning
abstract
Federated learning (FL) with a distributed trust framework effectively mitigates centralized security risks. However, it remains vulnerable to in-protocol Denial-of-Service attacks, resulting in the malicious server refusing to aggregate the valid gradients or terminating the protocol. Additionally, it is susceptible to collaborative attacks, where compromised servers and clients can bypass gradient verification to inject backdoors. To address those issues, we propose a robust and secure aggregation scheme for FL, which extends the efficient 2-party computation (2PC) to a 3-party computation (3PC) with at most one malicious party, resisting abnormal termination and colluding poisoning attacks. In particular, we skillfully combine the replicated secret sharing with$L_{2}$and$L_{\infty }$defense, ensuring the malformed gradients filtering with a noninteractive setup. Moreover, we integrate the player elimination framework to detect misbehavior and guarantee output delivery. The formal security analysis proves that our scheme maintains malicious security even under the colluding model. Extensive experiments demonstrate that robust and secure aggregation scheme for federated learning is more client-friendly and significantly enhances client efficiency by approximately 4 orders of magnitude compared to state-of-the-art methods.
Chengyi Dong, Yinbin Miao, Qingming Li, Shuiguang Deng, Shouling Ji
IEEE Internet Things J.5
2025 Efficient Encrypted Trajectory Similarity Query Over Mobile E-Health Cloud
abstract
Mobile electronic health systems collect a large amount of people’s trajectory data through smart devices (e.g., sensors). Generally, to provide data confidentiality, trajectories are encrypted before being uploaded to cloud servers. Trajectory similarity query has gained widespread attention as a mean to control the spread of infectious diseases. Nonetheless, existing solutions often suffer from low query efficiency and access pattern exposure. To solve these issues, we propose an efficient encrypted trajectory similarity query$(\textsf {TraSQ})$for mobile e-health systems. First, we utilize XZ* index and bijective function to generate the unique trajectory encoding value, thereby reducing storage and query costs over large-scale trajectory datasets. Then, we employ a dual cloud model, secure computing protocols and obfuscation technique to conceal the true trajectory similarity from cloud servers, protecting access pattern. Finally, we formally prove that our scheme achieves privacy protection against chosen plaintext attack (CPA), and conduct extensive experiments to demonstrate that our scheme improves the query efficiency by at least 25.4% when compared with existing solutions.
Xin Wang 0037, Yinbin Miao, Qingming Li, Kefeng Ding, Shouling Ji
IEEE Internet Things J.4
2025 VFGCN: A Vertical Federated Learning Framework With Privacy Preserving for Graph Convolutional Network
abstract
Due to the robust representational capabilities of graph data, employing graph neural networks for its processing has demonstrated superior performance over conventional deep learning algorithms. Graph data encompasses abundant features and structural information; however, its large-scale collection is often challenging in practice. This difficulty arises because data predominantly exists in isolated compartments, making it arduous to harmonize information across various organizations or to enable multiple organizations to collaborate effectively while safeguarding local data privacy. In light of an extreme data distribution scenario, where each client possesses distinct nodes with partially overlapping segments yet divergent data features, we introduce a dual-cloud server architecture. This framework encompasses the design of four secure subprotocols: ReEnc (secure re-encryption), SecPSI (secure outsourcing of PSI), SecWeight (secure weight calculation), and SecAgg (secure aggregation). Together, these components facilitate a vertical federated learning framework for graph convolutional networks, ensuring privacy preservation. We provide a security proof for the entire system and extensive evaluation on three benchmark datasets (Cora, Citeseer, and Pubmed) illustrates that our Vertical Federated Graph Convolutional Network (VFGCN) surpasses existing privacy-preserving methodologies.
Qingming Li, Ximeng Liu, Xiaoran Yan, Qingkuan Dong, Huiwen Wu, Xiangjie Kong 0001
IEEE Trans. Dependable Secur. Comput.2
2025 The Risk of Federated Learning to Skew Fine-Tuning Features and Underperform Robustness
abstract
To tackle the scarcity and privacy issues associated with domain-specific datasets, the integration of federated learning in conjunction with fine-tuning (FT) has emerged as a practical solution. However, our findings reveal that federated learning has the risk of skewing FT features and compromising the out-of-distribution (OOD) robustness of pretrained models. By introducing three robustness indicators and conducting experiments across diverse robust datasets, we elucidate these phenomena by scrutinizing the ability of data representations, transferability, and deviations within the model. To mitigate the negative impact of practical federated learning on model robustness, we introduce a general noisy projection (GNP)-based robust algorithm, ensuring no deterioration of accuracy on the target distribution. Specifically, the key strategy for enhancing model robustness entails the transfer of robustness from the pretrained model to the fine-tuned model, coupled with adding a small amount of Gaussian noise to augment the representative capacity of the model. The comprehensive experimental results demonstrate that our approach markedly enhances the robustness across diverse scenarios, encompassing various parameter-efficient FT (PEFT) methods and confronting different levels of label distribution skew and quantity distribution skew.
Mengyao Du, Miao Zhang 0037, Yuwen Pu, Qingming Li, Shouling Ji, Quanjun Yin
IEEE Trans. Neural Networks Learn. Syst.4
2024 AdaFL: Adaptive Client Selection and Dynamic Contribution Evaluation for Efficient Federated Learning
abstract
Federated learning is a collaborative machine learning framework where multiple clients jointly train a global model. To mitigate communication overhead, it is common to select a subset of clients for participation in each training round. However, existing client selection strategies often rely on a fixed number of clients throughout all rounds, which may not be the optimal choice for balancing training efficiency and model performance. Moreover, these approaches typically evaluate clients solely based on their performances in one single round, neglecting the effects of historical records and potentially introducing randomness into the global model. In our work, we introduce AdaFL, a novel approach to client selection and contribution evaluation for efficient federated learning. AdaFL dynamically adjusts the number of clients to be selected using a piecewise function. It initiates with a small selection size to reduce communication overhead and progressively increases it to enhance model generalization. Furthermore, AdaFL evaluates clients’ contributions by combining their performance metrics from both current and historical rounds through a weighted average function, with a weight parameter fine-tuning the trade-off between current and historical data. Experimental results show that the proposed AdaFL outperforms prior works in terms of improving test accuracy and reducing training runtime.
Qingming Li, Xiaoran Yan
ICASSP1
2024 A Huber Loss Minimization Approach to Mean Estimation under User-level Differential Privacy
abstract
Privacy protection of users' entire contribution of samples is important in distributed systems. The most effective approach is the two-stage scheme, which finds a small interval first and then gets a refined estimate by clipping samples into the interval. However, the clipping operation induces bias, which is serious if the sample distribution is heavy-tailed. Besides, users with large local sample sizes can make the sensitivity much larger, thus the method is not suitable for imbalanced users. Motivated by these challenges, we propose a Huber loss minimization approach to mean estimation under user-level differential privacy. The connecting points of Huber loss can be adaptively adjusted to deal with imbalanced users. Moreover, it avoids the clipping operation, thus significantly reducing the bias compared with the two-stage approach. We provide a theoretical analysis of our approach, which gives the noise strength needed for privacy protection, as well as the bound of mean squared error. The result shows that the new method is much less sensitive to the imbalance of user-wise sample sizes and the tail of sample distributions. Finally, we perform numerical experiments to validate our theoretical analysis.
Puning Zhao, Lifeng Lai, Li Shen 0008, Qingming Li, Jiafei Wu, Zhe Liu 0001
NeurIPS4
2024 FedSGProx: Mitigating Data Heterogeneity and Isolated Nodes in Graph Federated Learning
abstract
Graphs capture complex node interactions and are a fundamental tool for machine learning. Graph Federated Learning (GFL) is a method that allows multiple clients to collaboratively train a global graph neural network using a federated learning framework. This approach leverages the value of distributed graph data while maintaining data privacy. Existing approaches optimize graph neural networks within the common FedAvg paradigm, but they face two problems. The first problem is data heterogeneity, which leads to variations in label distributions and subgraph structures across clients. The second problem involves isolated nodes that possess limited or no local connections. The two problems seriously degrade the performance of GFL. To address these issues, we introduce FedSGProx, a novel GFL approach. FedSGProx combines longterm and short-term constraints to mitigate local biases due to data heterogeneity. Moreover, we design a novel sampling strategy to limit the involvement of isolated nodes in local training, thereby reducing their negative impacts on local models. Empirical results show that FedSGProx achieves higher classification accuracy than existing methods, and its performance is very close to that in centralized training.
Xutao Meng, Qingming Li, Xiaoran Yan
TrustCom2
2024 FVFL: A Flexible and Verifiable Privacy-Preserving Federated Learning Scheme
abstract
With the development of deep learning, people are more and more concerned about the security of data. Federated learning can solve the problem of data island, but it also brings more serious data privacy problems. Furthermore, in the process of multisource data collaboration, the efficiency of the whole federated learning system is usually not high. In this article, we introduce a scheme named FVFL, which ensure the local data security and resistance to collusive attacks, more importantly it can well support client flexible participate federated learning. We adopt Paillier encryption and secret sharing to guarantee client’s data security and resistance to collusive attacks. Moreover, our encryption mechanism allows client to participate in federated learning flexibly, and the correctness of the encryption algorithm is not affected by client’s drop out. The super-increasing sequence is introduced to reduce the communication overhead of the whole system, the simulation result shows that the result is significant; the Lagrange interpolation polynomial and secret Sharing is introduced to implement verification mechanism, to prevent malicious forgery of aggregation results in the cloud. The verification mechanism ensures the clients to obtain real and reliable aggregation results in the cloud. Moreover, our verification mechanism allows client to participate in federated learning flexibly, and the correctness of the verification algorithm is not affected by client’s drop out. And the experimental results show that FVFL has high accuracy and efficiency.
Qingming Li, Xiaoran Yan, Ximeng Liu, Yuncheng Wu
IEEE Internet Things J.3
2023 Pacos: Modeling preference reversals in users' context-dependent choices
Qingming Li, H. Vicky Zhao
Knowl. Based Syst.1
2021 Consistency Regularization for Ensemble Model Based Reinforcement Learning
Ruonan Jia, Qingming Li, Wenzhen Huang, Junge Zhang, Xiu Li 0001
PRICAI (3)2
2018 Prima: Probabilistic Ranking with Inter-Item Competition and Multi-Attribute Utility Function
abstract
This paper proposes PRIMA: Probabilistic Ranking with Inter-item competition and Multi-Attribute utility function, which ranks items based on their probabilities of being a user's best choice. This framework is particularly important in E-commerce applications for making recommendations, predicting sales, and developing pricing strategies. To achieve mathematical tractability, it uses the weight-based multi-attribute utility function to address the inter-attribute tradeoff, where the weight reflects a user's personal preference for each attribute. The proposed work updates the weight from a user's past transactions using the concept of marginal rate of substitution from microeconomics, addresses the interitem competition, and computes the items' probabilities of being a user's best choice. Real user test results show that the proposed framework achieves comparable ranking accuracy to the state-of-the-art work with significant improvements in model simplicity and mathematical tractability.
Qingming Li, Zhanjiang Chen, H. Vicky Zhao, Yan Lindsay Sun
ICASSP1