EDBT 2026 Demo / reviewers in the wild / expert
Yanjun Zhang 0002
dblp:24/6547-2
· DBLP profile ↗
10ranked-venue papers in the field
3as first author
8since 2021 · last 2026
0000-0001-5611-3483ORCID · conflict
Domains — venue-derived; a paper can count in several
Data Mining & Knowledge Discovery · 6 (1 first)Information Retrieval & Web Search · 3 (2 first)Knowledge Engineering, Semantic Web & Information Systems · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Beyond Denial-of-Service: The Puppeteer's Attack for Fine-Grained Control in Ranking-Based Federated Learning
Zirui Gong, Jianting Ning, Yanjun Zhang 0002, Leo Yu Zhang |
WWW | 4 |
| 2025 | Scale Margin Loss for Object Detection
Yuxuan Cheng, Yanjun Zhang 0002, Leo Yu Zhang, Donald Donglong Chen, Yuming Fang 0001 |
KSEM (2) | 2 |
| 2025 | MarkErase: Defeating Entangled Watermarks in Model Extraction Attacks
Xinjing Liu, Yanjun Zhang 0002, Haizhuan Yuan, Tianqing Zhu, Leo Yu Zhang |
PAKDD (4) | 3 |
| 2024 | Privacy-Preserving and Fairness-Aware Federated Learning for Critical Infrastructure Protection and ResilienceabstractThe energy industry is undergoing significant transformations as it strives to achieve net-zero emissions and future-proof its infrastructure, where every participant in the power grid has the potential to both consume and produce energy resources. Federated learning -- which enables multiple participants to collaboratively train a model without aggregating the training data -- becomes a viable technology. However, the global model parameters that have to be shared for optimization are still susceptible to training data leakage. In this work, we propose confined gradient descent (CGD) that enhances the privacy of federated learning by eliminating the sharing of global model parameters. CGD exploits the fact that a gradient descent optimization can start with a set of discrete points and converges to another set in the neighborhood of the global minimum of the objective function. As such, each participant can independently initiate its own private global model~(referred to as the confined model ), and collaboratively learn it towards the optimum. The updates to their own models are worked out in a secure collaborative way during the training process.In such a manner, CGD retains the ability of learning from distributed data but greatly diminishes information sharing. Such a strategy also allows the proprietary confined models to adapt to the heterogeneity in federated learning, providing inherent benefits of fairness. We theoretically and empirically demonstrate that decentralized CGD øne provides a stronger differential privacy (DP) protection; \two is robust against the state-of-the-art poisoning privacy attacks; þree results in bounded fairness guarantee among participants; and \four provides high test accuracy (comparable with centralized learning) with a bounded convergence rate over four real-world datasets. Yanjun Zhang 0002, Ruoxi Sun 0001, Liyue Shen, Guangdong Bai, Minhui Xue 0001, Mark Huasong Meng, Xue Li 0001, Ryan Kok Leong Ko, Surya Nepal |
WWW | 1 |
| 2023 | AgrEvader: Poisoning Membership Inference against Byzantine-robust Federated LearningabstractThe Poisoning Membership Inference Attack (PMIA) is a newly emerging privacy attack that poses a significant threat to federated learning (FL). An adversary conducts data poisoning (i.e., performing adversarial manipulations on training examples) to extract membership information by exploiting the changes in loss resulting from data poisoning. The PMIA significantly exacerbates the traditional poisoning attack that is primarily focused on model corruption. However, there has been a lack of a comprehensive systematic study that thoroughly investigates this topic. In this work, we conduct a benchmark evaluation to assess the performance of PMIA against the Byzantine-robust FL setting that is specifically designed to mitigate poisoning attacks. We find that all existing coordinate-wise averaging mechanisms fail to defend against the PMIA, while the detect-then-drop strategy was proven to be effective in most cases, implying that the poison injection is memorized and the poisonous effect rarely dissipates. Inspired by this observation, we propose AgrEvader, a PMIA that maximizes the adversarial impact on the victim samples while circumventing the detection by Byzantine-robust mechanisms. AgrEvader significantly outperforms existing PMIAs. For instance, AgrEvader achieved a high attack accuracy of between 72.78% (on CIFAR-10) to 97.80% (on Texas100), which is an average accuracy increase of 13.89% compared to the strongest PMIA reported in the literature. We evaluated AgrEvader on five datasets across different domains, against a comprehensive list of threat models, which included black-box, gray-box and white-box models for targeted and non-targeted scenarios. AgrEvader demonstrated consistent high accuracy across all settings tested. The code is available at: https://github.com/PrivSecML/AgrEvader. Yanjun Zhang 0002, Guangdong Bai, Mahawaga Arachchige Pathum Chamikara, Mengyao Ma, Liyue Shen, Jingwei Wang 0003, Surya Nepal, Minhui Xue 0001, Joseph K. Liu |
WWW | 1 |
| 2022 | SATB: A Testbed of IoT-Based Smart Agriculture Network for Dataset Generation
Liuhuo Wan, Yanjun Zhang 0002, Ryan Kok Leong Ko, Louwrens Christiaan Hoffman, Guangdong Bai |
ADMA (1) | 2 |
| 2022 | Towards Better Generalization for Neural Network-Based SAT Solvers
Chenhao Zhang 0004, Yanjun Zhang 0002, Jeff Mao, Weitong Chen 0001, Lin Yue, Guangdong Bai, Miao Xu 0001 |
PAKDD (2) | 2 |
| 2021 | UQ-AAS21: A Comprehensive Dataset of Amazon Alexa Skills
Fuman Xie, Yanjun Zhang 0002, Hanlin Wei, Guangdong Bai |
ADMA | 2 |
| 2019 | Enabling Privacy-Preserving Sharing of Genomic Data for GWASs in Decentralized NetworksabstractThe human genome can reveal sensitive information and is potentially re-identifiable, which raises privacy and security concerns about sharing such data on wide scales. In this work, we propose a preventive approach for privacy-preserving sharing of genomic data in decentralized networks for Genome-wide association studies (GWASs), which have been widely used in discovering the association between genotypes and phenotypes. The key components of this work are: a decentralized secure network, with a privacy- preserving sharing protocol, and a gene fragmentation framework that is trainable in an end-to-end manner. Our experiments on real datasets show the effectiveness of our privacy-preserving approaches as well as significant improvements in efficiency when compared with recent, related algorithms. Yanjun Zhang 0002, Xin Zhao 0013, Xue Li 0001, Mingyang Zhong, Caitlin Curtis, Chen Chen 0056 |
WSDM | 1 |
| 2018 | Automated Explanations of User-Expected Trends for Aggregate Queries
Ibrahim A. Ibrahim, Xue Li 0001, Xin Zhao 0013, Sanad Al-Maskari, Abdullah M. Albarrak, Yanjun Zhang 0002 |
PAKDD (1) | 6 |