EDBT 2026 Demo / reviewers in the wild / expert
Jianbiao Zhang
dblp:227/4261
· DBLP profile ↗
13ranked-venue papers
0as first author
13since 2021 · last 2026
0000-0002-4917-7996ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 4 · 4 since 2021Security and privacy · 4 · 4 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Shielding federated learning: mitigating label transferability against poisoning attacks in cloud-edge-client system
Yaru Zhao 0002, Yihao Cao, Jianbiao Zhang, Zhaoqian Zhang, Weiru Wang 0001 |
Expert Syst. Appl. | 3 |
| 2025 | DMSCTS: Dynamic measurement scheme for the containers-hybrid-deployment based on trusted subsystem
Jianbiao Zhang, Lehao Yu, Yihao Cao, Hong Shen 0001, Weixing Hou, Hailin Luo |
Comput. Secur. | 3 |
| 2025 | MOFDRNet: A Model for Data Leakage Attacks in Federated LearningabstractABSTRACT Federated Learning allows multiple clients to train local models and aggregate them on the server side. The client is invisible to the shared global model generated by the server, which provides an opportunity for malicious attackers to utilize the inherent vulnerability of federated learning to initiate data leakage attacks. Existing attack techniques are largely client‐based and focus on inferring model parameters directly, but do not work for server‐based attacks, mainly due to differences in their ability to generalize attacks. Yet few robust data leakage attacks toward federated learning vulnerability have been developed on the server side. To address the above problem, we propose MOFDRNet, a Multi‐Objective Fake Data Regression Network model that integrates the loss function and multiple metrics strategies. The key idea is to deploy a malicious attack model on the server with the purpose of generating fake data and labels and continuously approximating the shared gradients between clients and the server, thereby recovering clients' private data. Experimental results demonstrate that the MOFDRNet model has significant advantages in implementing data leakage attacks. Finally, we also discuss the differential privacy defense approach in this study. Yaru Zhao 0002, Jianbiao Zhang, Yihao Cao, Xianqun Han |
Concurr. Comput. Pract. Exp. | 2 |
| 2024 | SABDTM: Security-first architecture-based dynamic trusted measurement scheme for operating system of the virtual computing node
Haoxiang Huang, Jianbiao Zhang, Yihao Cao |
Comput. Secur. | 2 |
| 2024 | SRFL: A Secure & Robust Federated Learning framework for IoT with trusted execution environments
Yihao Cao, Jianbiao Zhang, Yaru Zhao 0002, Pengchong Su, Haoxiang Huang |
Expert Syst. Appl. | 2 |
| 2024 | FlexibleFL: Mitigating poisoning attacks with contributions in cloud-edge federated learning systems
Yaru Zhao 0002, Yihao Cao, Jianbiao Zhang, Haoxiang Huang |
Inf. Sci. | 3 |
| 2024 | Privacy-Preserving Federated Learning With Improved Personalization and Poison Rectification of Client ModelsabstractFederated Learning (FL), a secure and emerging distributed learning paradigm, has garnered significant interest in the Internet of Things (IoT) domain. However, it remains vulnerable to adversaries who may compromise privacy and integrity. Previous studies on privacy-preserving FL (PPFL) have demonstrated limitations in client model personalization and resistance to poisoning attacks, including Byzantine and backdoor attacks. In response, we propose a novel PPFL framework, FedRectify, that employs a personalized dual-layer approach through the deployment of Trusted Execution Environments and an interactive training strategy. This strategy facilitates the learning of personalized client features via private and shared layers. Furthermore, to improve model’s robustness to poisoning attacks, we introduce a novel aggregation method that employs clustering to filter out outlier model parameters and robust regression to assess the confidence of cluster members, thereby rectifying poisoned parameters. We theoretically prove the convergence of FedRectify and empirically validate its performance through extensive experiments. The results demonstrate that FedRectify converges 1.47-2.63 times faster than state-of-the-art methods when countering Byzantine attacks. Moreover, it can rapidly reduce the attack success rate to a low level between 10% and 40% in subsequent rounds when confronting bursty backdoor attacks. Yihao Cao, Jianbiao Zhang, Yaru Zhao 0002, Hong Shen 0001, Haoxiang Huang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Symmetric searchable encryption with supporting search pattern and access pattern protection in multi-cloudabstractSummary Symmetric searchable encryption (SSE) enables users to search the ciphertext stored on the untrusted cloud without revealing the search keywords, effectively protecting users' privacy. However, most of the existing SSE schemes reveal the search or access pattern during the keyword query, which can be used by the adversary to infer the sensitive information in ciphertext, thus posing a great threat to users' privacy. To address this, we propose an SSE scheme supporting search pattern and access pattern protection in multi‐cloud, called SAPM‐SSE. In our scheme, an index shuffle protocol is proposed to change the content and location of the index after each query, which helps to achieve the protection of search and access pattern. Furthermore, with the purpose of improving the efficiency of shuffling, we construct a shuffling algorithm based on index cache, the number of index entries for shuffling reduced from γ to γ/n (n≥1). Besides, our scheme supports the dynamic update of documents and achieves the forward security in update. Finally, security analysis and experimental results show that our scheme can achieve the protection of search pattern and access pattern with high efficiency. Wanshan Xu, Jianbiao Zhang |
Concurr. Comput. Pract. Exp. | 2 |
| 2023 | Manipulating vulnerability: Poisoning attacks and countermeasures in federated cloud-edge-client learning for image classification
Yaru Zhao 0002, Jianbiao Zhang, Yihao Cao |
Knowl. Based Syst. | 2 |
| 2022 | Enable data privacy, dynamics, and batch in public auditing scheme for cloud storage systemabstractAbstract With the popularity of cloud computing, cloud storage technology has also been widely used. Among them, data integrity verification is a hot research topic. At present, the realization of public auditing has become the development trend of integrity verification. Most existing public auditing schemes rarely consider some indispensable functions at the same time. Thus, in this article, we propose a comprehensive public auditing scheme (PDBPA) that can simultaneously support data privacy protection, data dynamics, and multi‐user batch auditing. To guarantee privacy protection during the audit process, our PDBPA design a new method of constructing audit proof, which combines random masking techniques and bilinear properties of bilinear pairing. Not only can it ensure that TPA performs audits correctly, but it can also prevent it from exploring the user's sensitive data. In addition, by utilizing the modified dynamic hash table, which is a novel and small two‐dimensional data structure, data dynamics can be effectively achieved. Furthermore, we provide a detailed process for the third‐party auditors to perform batch audits for multiple users. Moreover, we give the detailed and rigorous security analysis in defending against forgery attack, replace attack, and replay attack. Performance evaluations demonstrate that our PDBPA scheme is effective and feasible. Jianbiao Zhang, Wanshan Xu, Zheng Li 0033 |
Concurr. Comput. Pract. Exp. | 2 |
| 2022 | An Expressive Fully Policy-Hidden Ciphertext Policy Attribute-Based Encryption Scheme With Credible Verification Based on BlockchainabstractAs the public cloud becomes one of the leading ways in data-sharing nowadays, data confidentiality and user privacy are increasingly critical. Partially policy-hidden ciphertext policy attribute-based encryption (CP-ABE) can effectively protect data confidentiality while reducing privacy leakage by hiding part of the access structure. However, it cannot satisfy the need of data sharing in the public cloud with complex users and large amounts of data, both in terms of less expressive access structures and limited granularity of policy hiding. Moreover, the verification of access right to shared data and correctness of decryption are ignored or conducted by an untrusted third party, and the prime-order groups are seldom considered in the expressive policy-hidden schemes. This article proposes a fully policy-hidden CP-ABE scheme constructed on linear secret sharing scheme (LSSS) access structure and prime-order groups for public cloud data sharing. To help users decrypt, hidden vector encryption (HVE) with a “convert step” is applied, which is more compatible with CP-ABE. Meanwhile, decentralized credible verification of access right to shared data and correctness of decryption based on blockchain are also provided. We prove the security of our scheme rigorously and compare the scheme with others comprehensively. The results show that our scheme performs better. Zhaoqian Zhang, Jianbiao Zhang |
IEEE Internet Things J. | 2 |
| 2022 | Research on Distributed Dynamic Trusted Access Control Based on Security SubsystemabstractThe flow of data across nodes has become the dominant feature of data sharing in distributed environments with increasingly blurred boundaries, where it is crucial to maintain data access dynamic, trusted, and efficient. However, traditional centralized access control models are not only difficult to apply in distributed environments but also ignore trusted verification of authorized entities. What’s worse, existing access control models rarely consider themselves security, lack independence, at a high risk of being bypassed or tampered with. Thus, we propose in this paper a distributed, dynamic, and trusted access control model, DDTAC-BSS, where the standard Attribute-Based Access Control (ABAC) architecture is modified and extended. To reduce the attack surface, we separate policy enforcement point (PEP) from other core components, they are located in the node system and access control system, respectively. Then, the access control entry point (ACEP) is added as the only interface for the node system to interact with the access control system. Subsequently, the model introduces the entity trusted assessment mechanism to improve the trustworthiness of access control services. Driven by the dynamic attributes, our model can achieve dynamic trusted authorization and fine-grained access control. Moreover, we implement a lightweight, independent, and distributed security subsystem to achieve unified management of policies and decision-making autonomy by message-driven. By considering the independence of the security subsystem, a trusted operating environment is built based on Trusted Execution Environment (TEE) to ensure the security of the access control mechanism itself. The security of our model is proved rigorously based on the non-interference theory. Comprehensive experiments and comparisons have demonstrated the superior functionality, comparable performance, and strong security of our model. Haoxiang Huang, Jianbiao Zhang, Yingfang Fu, Chenggang Qin |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2022 | Identity-based public data integrity verification scheme in cloud storage system via blockchain
Jianbiao Zhang, Wanshan Xu, Zheng Li 0033 |
J. Supercomput. | 2 |