EDBT 2026 Demo / reviewers in the wild / expert
Hongyun Cai 0002
dblp:247/9265-2
· DBLP profile ↗
21ranked-venue papers
14as first author
18since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 5 first-author · 4 since 2021Systems, architecture and hardware · 3 · 2 first-author · 3 since 2021Computer networks · 3 · 2 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A High-Dimensional Gradient Inversion Attack Based on Feature Distillation in Federated Learning
Hongyun Cai 0002, Mingliang Ma |
ICIC (18) | 1 |
| 2025 | MvSMIA: Multi-view Source Membership Inference Attack in Federated Learning
Hongyun Cai 0002 |
ICIC (4) | 2 |
| 2025 | Backdoor Defense in Federated Learning Via Multi-Perspective Resilient AggregationabstractFederated learning (FL) is highly susceptible to backdoor attacks, which cause the global model to produce incorrect prediction results for specific inputs. Existing defense methods primarily rely on clustering to exclude significantly deviated model updates from aggregation, or use differential privacy or neuron pruning to limit the impact of backdoors, which only are effective against specific attacks or significantly degrade the global model's usability. Moreover, these methods require the appropriate hyperparameters. To address the aforementioned limitations, we propose MPRA (Multi-Perspective Resilient Aggregation). First, we detect the differences between benign and malicious model updates from three different perspectives: the deviation angle between model updates, the magnitude of neuron updates, and the distance between model updates. Then, the model updates that fail to pass the detection will be regarded as latent malicious model updates and excluded from the aggregation. Extensive experiments on three different datasets show that the proposed MPRA can effectively tackle various backdoor attacks and minimize the negative impact on the global model's usability in the majority of scenarios without acquiring prior knowledge such as attack rounds, attack scale and attack methods. Hongyun Cai 0002, Lijing Gao, Fengyu Li |
SRDS | 2 |
| 2025 | Federated learning: frameworks, optimisation algorithms, security threats and defences
Hongyun Cai 0002, Yu Zhang 0170, Ao Zhao |
Int. J. Inf. Comput. Secur. | 1 |
| 2025 | Dual stream fusion link prediction for sparse graph based on variational graph autoencoder and pairwise learning
Hongyun Cai 0002, Chuan Feng, Ao Zhao |
Inf. Process. Manag. | 2 |
| 2024 | PLFa-FL: Personalized Local Differential Privacy for Fair Federated LearningabstractIn federated learning, the clients can adopt local differential privacy on the uploaded gradients or parameters, to reduce the potential risk of privacy leakage. However, most existing solutions set the uniform privacy level for all clients, which cannot meet the individual different privacy needs of users. Moreover, a few schemes introduced personalized differential privacy, but they ignored the data utility of the whole system and the issue of fair client sampling. In this paper, we propose a novel framework of fair federated learning with personalized local differential privacy (PLFa-FL), which can achieve fair client sampling while balancing the privacy and data utility. First, we propose a fair sampling mechanism that combines the client’s local loss value and historical participation results. Then, we consider the impact of privacy budget threshold on model performance. To balance the privacy and data utility, we design the privacy budget waste function to determine the optimized privacy budget threshold and the clients’ used privacy budget. Experiments on MNIST and EMNIST datasets confirm that PLFa-FL compares favorably against the baseline methods in terms of model performance, running time, and fairness. Hongyun Cai 0002, Ao Zhao, Yu Zhang 0170 |
CSCWD | 1 |
| 2024 | Information Diffusion Prediction Based on User Behavior CharacteristicsabstractIn social network, information diffusion prediction is a crucial task for uncovering patterns of information spread and addressing sudden events and public opinion crises. Previous studies typically construct heterogeneous graphs based on the social network and diffusion sequences among users, using neural networks to obtain user feature representations. However, the expressive power of the user features obtained is insufficient. Therefore, this paper proposes the User Behavior Characteristics-based Information Diffusion Prediction Model (UBCDiffuse). It extracts behavioral characteristics and a nearest neighbor list based on user diffusion time and diffusion sequences, and then aggregates neighbor features using the nearest neighbor list to obtain more expressive user feature representations. Finally, a Transformer decoder mechanism is employed to model the diffusion sequences, and a fusion mechanism is designed to enhance contextual features. Experimental results on real social network datasets demonstrate that the proposed UBCDiffuse model significantly outperforms existing models. Hongyun Cai 0002, Ao Zhao, Chuan Feng |
ICWS | 1 |
| 2024 | MMCasN: Macroscopic and microscopic properties fusion for predicting information cascadesabstractInformation cascade plays an important role in today’s social networks and complex systems. Predicting the growth of cascades can help people understand and intervene in cascading processes. Existing methods for cascade prediction mainly focus on extracting local node features, ignoring the dynamics of cascades and the macroscopic characteristics of the overall cascade structure. In this paper, we propose a novel cascade prediction method named MMCasN (a Fusion Macroscopic and Microscopic Properties for Predicting Information Cascades Network) by combining micro-level features with macro-level features. Firstly, the information cascade graph can be divided into multiple snapshots based on the predefined time window. Then, for each snapshot, micro-level features are extracted using GraphSage to capture node-level characteristics, while macro-level features handle uncertain cascade sizes using a mapping approach. Furthermore, time features are extracted using Bi-LSTM, and a multi-layer perceptron is employed for prediction. Experimental results demonstrate that MMCasN outperforms other baseline methods on two real-world datasets, exhibiting more superior prediction performance. Hongyun Cai 0002, Chuan Feng, Ao Zhao |
IJCNN | 1 |
| 2024 | FedRecTID: A General Robust Federated Recommendation Framework Based on Target Items DetectionabstractFederated recommender systems (FedRecs) have received a lot of attention in recent years because of their excellent ability to protect privacy. But recent research has shown that federated recommender systems are vulnerable to poisoning attacks. Attackers can pollute training data or local models to influence the recommendation rankings of target items. To reduce the impact of poisoning attacks on federated recommender systems, we propose a robust federated recommendation framework based on target item detection called FedRecTID, which can effectively resist the impact of targeted attacks in federated recommender systems. FedRecTID can be divided into three steps, including the identification of suspicious items, vote for validation and removal of the effects of attack. Specifically, after receiving the gradients uploaded by the clients, the server calculates the suspicious scores of items by calculating the cosine similarity of the item embedding in the last two rounds. Based on the scores, the suspicious items can be determined by statistical anomaly detection methods. Then these items are sent to the selected users for verification. After receiving users’ vote, the server validates it based on the majority of the voting mechanism, and filters out the target item without updating it. Experimental results on two real datasets demonstrate that our proposed framework for FedRecs can effectively defend existing targeted attacks against FedRecs. And FedRecTID does not harm the recommendation performance. Hongyun Cai 0002, Fengyu Li, Chuan Feng |
IJCNN | 1 |
| 2024 | Reliable incentive mechanism in hierarchical federated learning based on two-way reputation and contract theory
Hongyun Cai 0002, Lijing Gao, Fengyu Li |
Future Gener. Comput. Syst. | 1 |
| 2024 | FLMAAcBD: Defending against backdoors in Federated Learning via Model Anomalous Activation Behavior Detection
Hongyun Cai 0002, Lijing Gao, Fengyu Li |
Knowl. Based Syst. | 1 |
| 2024 | STFM: a blockchain sharding algorithm based on trust field model for heterogeneous Internet of Things
Liuling Qi, Mengjia Chai, Hongyun Cai 0002 |
J. Supercomput. | 4 |
| 2023 | A Poisoning Attack Based on Variant Generative Adversarial Networks in Recommender Systems
Hongyun Cai 0002, Yu Zhang 0170, Ao Zhao |
ADMA (4) | 1 |
| 2023 | Personalized Privacy Risk Assessment Based on Deep Neural Network for Image Sharing on Social Networks
Hongyun Cai 0002, Ao Zhao, Yu Zhang 0170 |
ICA3PP (2) | 1 |
| 2023 | LightPoW: A trust based time-constrained PoW for blockchain in internet of things
Liuling Qi, Mengjia Chai, Hongyun Cai 0002 |
Comput. Networks | 4 |
| 2023 | A Cooperative PoW and Incentive Mechanism for Blockchain in Edge ComputingabstractMore and more works use blockchain to improve the data security of integrated edge computing and Internet of Things (IoT) system. However, there are some problems of Proof-of-Work (PoW) that hinder the application, such as high energy consumption, low resource utilization efficiency, and insufficient incentive. In this article, we present a cooperative PoW named relay mining-based PoW (Relay-PoW) to reduce energy consumption and improve resource utilization efficiency, where the nodes can mine blocks together under the management of edge server. We further propose parallel relay mining method to increase the throughput, where the nodes can mine blocks with multiple heights in a pipeline manner. In addition, we design supervision group mechanism to ensure the security, where the edge server evaluates the trust values of the nodes according to the capability and quality, and eliminates abnormal nodes timely. Finally, we propose a Shapley-based reward allocation strategy (SRAS) to encourage node to participate in Relay-PoW. Experimental results show that Relay-PoW can effectively decrease the energy consumption, improve the throughput and resource utilization efficiency, SRAS can motivate nodes to cooperate, and they all have a better performance than other methods. Liuling Qi, Mengjia Chai, Hongyun Cai 0002 |
IEEE Internet Things J. | 4 |
| 2021 | An Unsupervised Approach for Detecting Group Shilling Attacks in Recommender Systems Based on Topological Potential and Group Behaviour FeaturesabstractTo protect recommender systems against shilling attacks, a variety of detection methods have been proposed over the past decade. However, these methods focus mainly on individual features and rarely consider the lockstep behaviours among attack users, which suffer from low precision in detecting group shilling attacks. In this work, we propose a three-stage detection method based on strong lockstep behaviours among group members and group behaviour features for detecting group shilling attacks. First, we construct a weighted user relationship graph by combining direct and indirect collusive degrees between users. Second, we find all dense subgraphs in the user relationship graph to generate a set of suspicious groups by introducing a topological potential method. Finally, we use a clustering method to detect shilling groups by extracting group behaviour features. Extensive experiments on the Netflix and sampled Amazon review datasets show that the proposed approach is effective for detecting group shilling attacks in recommender systems, and the F1-measure on two datasets can reach over 99 percent and 76 percent, respectively. Hongyun Cai 0002, Fuzhi Zhang |
Secur. Commun. Networks | 1 |
| 2021 | BS-SC: An Unsupervised Approach for Detecting Shilling Profiles in Collaborative Recommender SystemsabstractCollaborative recommender systems are vulnerable to shilling attacks. To address this issue, many methods including supervised and unsupervised have been proposed. However, supervised detection methods require training classifiers and they only apply to detect known types of attacks. The existing unsupervised detection methods need to know the prior knowledge of attacks, otherwise they suffer from low detection precision. In this paper, we present BS-SC, an unsupervised approach for detecting shilling profiles, which does not need to know the attack size or to label the candidate spammers. BS-SC starts from an in-depth analysis of user behaviors and uses two key mechanisms (i.e., behavior features extraction and behavior similarity matrix clustering) to distinguish shilling profiles from genuine ones. The behavior features reflect the behavior difference between genuine and shilling profiles, and the behavior similarity matrix clustering is to cluster shilling profiles based on their highly similar behaviors. Experimental results on the MovieLens and the sampled Amazon review datasets indicate that BS-SC outperforms the baseline unsupervised approaches, even when the prior knowledge is given for them. Hongyun Cai 0002, Fuzhi Zhang |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2020 | An Algorithm Based on Influence to Predict Invisible RelationshipabstractResearch on social networks is at its peak in the current era of big data, especially in the field of computer research. Link prediction in social networks has attracted an increasing number of researchers. However, most of the current studies have focused on the prediction of the visible relationships between users, ignoring the existence of invisible relationships. The same as visible relationships, invisible relationships are also an indispensable part of social networks, and they can uncover more potential relationships between users. To better understand invisible relationship, definition, types, and characteristics of invisible relationship have been introduced in this paper. Also an influence algorithm is proposed to speculate on the existence of invisible edges between users. The algorithm is based on three indicators, namely, the occasional contact degree, interest coincidence degree, and the popularity of users, and it takes the influence as reference. By comparing with the threshold, Θ , defined in advance, users with relationships stronger than Θ are viewed as possessing invisible relationships. The feasibility and accuracy of the algorithm are proven by extensive numerical experiments compared with one well-known and widely used method, i.e., the common neighbors (CN). Lizheng Xue, Hongyun Cai 0002 |
Wirel. Commun. Mob. Comput. | 3 |
| 2019 | An Unsupervised Method for Detecting Shilling Attacks in Recommender Systems by Mining Item Relationship and Identifying Target ItemsabstractCollaborative filtering (CF) recommender systems have been shown to be vulnerable to shilling attacks. How to quickly and effectively detect shilling attacks is a key challenge for improving the quality and reliability of CF recommender systems. Although many recent studies have been devoted to detecting shilling attacks, there are still problems that require further discussion, especially the improvement of the detection performance on real-world unlabelled datasets. In this work, we propose an unsupervised approach that exploits item relationship and target item(s) for attack detection. We first extract behaviour features based on the item relationship. Then, we distinguish suspicious users from normal users and construct a set of suspicious users. Finally, we identify target item(s) by analysing the aggregation behaviour of suspicious users, based on which we detect attack users from the set of suspicious users. Extensive experiments on the MovieLens 100K dataset and sampled Amazon review dataset demonstrate the effectiveness of the proposed approach for detecting shilling attacks in recommender systems. Hongyun Cai 0002, Fuzhi Zhang |
Comput. J. | 1 |
| 2019 | Detecting shilling attacks in recommender systems based on analysis of user rating behavior
Hongyun Cai 0002, Fuzhi Zhang |
Knowl. Based Syst. | 1 |