Hanxiao Chen 0001

dblp:255/5224-1 · DBLP profile ↗
← Back
28ranked-venue papers
8as first author
27since 2021 · last 2026
0000-0001-9869-8926ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 12 · 2 first-author · 11 since 2021Security and privacy · 11 · 4 first-author · 11 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Efficient and Verifiable Data Statistical Analysis via Zero-knowledge Proofs
Hanxiao Chen 0001, Rui Zhang 0086, Pengzhi Xing, Meng Hao 0001, Hongwei Li 0001
ICC1
2026 Efficient Privacy-Preserving Genetic Analysis via Distributed Function Secret Sharing
Shenghao Wu, Pengzhi Xing, Meng Hao 0001, Hanxiao Chen 0001, Wenbo Jiang 0001, Hongwei Li 0001
ICC4
2026 Backdoor Complications: A Comprehensive Analysis and Mitigation of the Unforeseen Consequences of Backdoor Attacks
abstract
Pre-trained language models (PTLMs) have become integral to modern natural language processing (NLP), yet their reuse exposes them to supply chain risks such as backdoor attacks. Existing studies assume that attackers target specific downstream tasks, overlooking how a backdoored PTLM behaves when fine-tuned for unrelated applications. In practice, such unintended adaptation can trigger anomalous and inconsistent predictions, revealing the backdoor and compromising its stealthiness. We define this phenomenon asbackdoor complications, i.e., unintended behavioral side effects emerging on non-target tasks. This work presents the first systematic quantification and mitigation of backdoor complications. Through extensive experiments on 3 widely used PTLMs and 15 benchmark datasets, we show that complications are pervasive across both single- and multi-task attack settings, causing triggered outputs to collapse into arbitrary classes. To address this issue, we propose theComplication-Suppressed Backdoor Attack(CSBA), a task-agnostic, multi-objective framework that leverages auxiliary non-target datasets to suppress backdoor complications. CSBA effectively suppresses complications on unseen downstream tasks while maintaining near-perfect attack success rates. Our work reveals a critical side effect in backdoored PTLMs and provides a new perspective on the stealthiness and robustness of model supply chain security.
Rui Zhang 0086, Hongwei Li 0001, Wenbo Jiang 0001, Hanxiao Chen 0001, Yuan Zhang 0006, Guowen Xu, Yang Zhang 0016
IEEE Trans. Dependable Secur. Comput.5
2026 Sanitizer: Blazing-Fast, Private, and Robust Federated Learning
abstract
Recently, private and robust federated learning (FL) schemes have been proposed to address privacy inference and Byzantine attacks simultaneously. However, existing schemes are inefficient in private and robust aggregation protocols due to the employment of heavy cryptographic techniques. To approach the above problem, we propose Sanitizer, an efficient, private, and robust FL framework. Specifically, we first design a Byzantine-robust defense for communication-efficient sign-based FL. We further propose a customized private and robust aggregation scheme built on our Byzantine-robust defense for FL. The core of our construction is two new efficient protocols, i.e.,high-dimensional boolean summationandweighted boolean majority vote, which serve as the main building blocks of Sanitizer. Extensive evaluations on real-world datasets demonstrate that Sanitizer is blazing fast, achieving 19 ∼ 23× less runtime compared to the state-of-the-art. Meanwhile, Sanitizer achieves the same accuracy as the plaintext and superior Byzantine robustness against various classic attacks.
Hanxiao Chen 0001, Hongwei Li 0001, Meng Hao 0001, Jia Hu 0004, Hao Ren 0001, Haomiao Yang, Tianwei Zhang 0004, Guowen Xu
IEEE Trans. Inf. Forensics Secur.1
2026 Conan: Secure and Reliable Machine Learning Inference Against Malicious Service Providers
abstract
In the Machine Learning as a Service paradigm, a service provider (e.g., a server) hosting a model offers inference APIs to clients, who can send their queries and receive the inference results. While most recent secure inference works focus on addressing privacy issues, they overlook the importance of checking the service quality and reliability. A malicious server may deviate from the protocol specification to deliberately provide incorrect services such as using low-quality models. Thus, it is necessary to design new solutions to empower clients to verify the server’s model accuracy and inference integrity while protecting both parties’ privacy. We present Conan, a new secure and reliable inference framework against malicious servers to achieve accuracy verification, inference integrity, and privacy simultaneously. In Conan, the server first commits to the model and proves in zero-knowledge that the committed model achieves the claimed accuracy. Then both parties perform secure inference on the committed model against the malicious server. To instantiate the above framework, we design generic maliciously secure two-party computation (2PC) protocols with a fixed corrupted party, which may be of independent interest. Our protocols achieve high efficiency by utilizing the advantage that the semi-honest party can check the behavior of the corrupted party. Furthermore, they support both arithmetic and Boolean circuit evaluation, a crucial attribute for secure inference on complicated machine learning models. We implement the fixed-corruption 2PC protocols for our secure and reliable inference. The experimental results show 1 ~ 2 orders of magnitude improvements over conventional maliciously secure protocols in terms of communication and computation costs.
Hanxiao Chen 0001, Hongwei Li 0001, Meng Hao 0001, Pengzhi Xing, Jia Hu 0004, Wenbo Jiang 0001, Tianwei Zhang 0004, Guowen Xu
IEEE Trans. Inf. Forensics Secur.1
2025 DivTrackee versus DynTracker: Promoting Diversity in Anti-Facial Recognition against Dynamic FR Strategy
abstract
The widespread adoption of facial recognition (FR) models raises serious concerns about their potential misuse, motivating the development of anti-facial recognition (AFR) to protect user facial privacy. In this paper, we argue that the static FR strategy, predominantly adopted in prior literature for evaluating AFR efficacy, cannot faithfully characterize the actual capabilities of determined trackers who aim to track a specific target identity. In particular, we introduce DynTracker, a dynamic FR strategy where the model's gallery database is iteratively updated with newly recognized target identity images. Surprisingly, such a simple approach renders all the existing AFR protections ineffective. To mitigate the privacy threats posed by DynTracker, we advocate for explicitly promoting diversity in the AFR-protected images. We hypothesize that the lack of diversity is the primary cause of the failure of existing AFR methods. Specifically, we develop DivTrackee, a novel method for crafting diverse AFR protections that builds upon a text-guided image generation framework and diversity-promoting adversarial losses. Through comprehensive experiments on various image benchmarks and feature extractors, we demonstrate DynTracker's strength in breaking existing AFR methods and the superiority of DivTrackee in preventing user facial images from being identified by dynamic FR strategies. We believe our work can act as an important initial step towards developing more effective AFR methods for protecting user facial privacy against determined trackers.
Wenshu Fan, Minxing Zhang, Hongwei Li 0001, Wenbo Jiang 0001, Hanxiao Chen 0001, Xiangyu Yue 0001, Michael Backes 0001, Xiao Zhang 0016
CCS5
2025 SecInfer: Secure and Efficient Model Inference on Vertically Partitioned Data
abstract
Deep learning models have achieved unprecedented success in various domains, such as healthcare and finance. However, deploying model inference in real-world applications, where data is distributed among multiple entities, poses significant privacy concerns. Existing secure model inference work has limitations in computational overhead and scalability, especially when dealing with complex models and multiple parties with vertically partitioned data. In this work, we design and implement an efficient and scalable secure inference framework for vertically partitioned data, supporting execution with a large number of parties. Our work considers a semi-honest setting with all-but-one corruptions. The core of our framework is a series of secure and efficient protocols for complex non-linear functions of the model inference, such as ReLU and Maxpool. These protocols are designed based on secure multi-party computation preliminaries, significantly enhancing efficiency while maintaining rigorous security guarantees. We conduct comprehensive experiments to evaluate the performance of our framework. Experimental results show that SecInfer substantially improves the communication and computation performance of secure naive inference works by up to 3.71 × and 3.42 ×, respectively.
Robert H. Deng, Hongwei Li 0001, Hanxiao Chen 0001, Meng Hao 0001, Pengzhi Xing, Jia Hu 0004, Rui Zhang 0086, Wenbo Jiang 0001
ICC3
2025 The Ripple Effect: On Unforeseen Complications of Backdoor Attacks
abstract
Recent research highlights concerns about the trustworthiness of third-party Pre-Trained Language Models (PTLMs) due to potential backdoor attacks. These backdoored PTLMs, however, are effective only for specific pre-defined downstream tasks. In reality, these PTLMs can be adapted to many other unrelated downstream tasks. Such adaptation may lead to unforeseen consequences in downstream model outputs, consequently raising user suspicion and compromising attack stealthiness. We refer to this phenomenon as backdoor complications. In this paper, we undertake the first comprehensive quantification of backdoor complications. Through extensive experiments using 4 prominent PTLMs and 16 text classification benchmark datasets, we demonstrate the widespread presence of backdoor complications in downstream models fine-tuned from backdoored PTLMs. The output distribution of triggered samples significantly deviates from that of clean samples. Consequently, we propose a backdoor complication reduction method leveraging multi-task learning to mitigate complications without prior knowledge of downstream tasks. The experimental results demonstrate that our proposed method can effectively reduce complications while maintaining the efficacy and consistency of backdoor attacks.
Rui Zhang 0086, Hongwei Li 0001, Wenbo Jiang 0001, Hanxiao Chen 0001, Yuan Zhang 0006, Guowen Xu, Yang Zhang 0016
ICML5
2025 A Hidden Backdoor Attack via Formal Text Style Transfer in Language Models
abstract
Natural language processing (NLP) systems have been demonstrated to be vulnerable to backdoor attacks. Specifically, attackers embed the backdoor into the model by poisoning training data, producing the desired results when the input contains pre-defined triggers. Typical textual backdoor attacks adopt static triggers such as words or phrases, which make them detectable by existing defense methods. To enhance stealthiness, this paper introduces a hidden backdoor attack method utilizing formal text style transfer (FTST). Specifically, we adopt a formal text style transfer model to convert part of the benign training samples into formal samples, which serve as the backdoor samples. Compared to static textual triggers, FTST-based triggers can maintain original semantics while evading common defenses and human detections. We conduct extensive experiments on typical NLP tasks, including topic and sentiment classification tasks utilizing three prominent pre-trained language models and four datasets. The results show that our approach achieves the desired attack performance while preserving the normal-functionality of the model. Furthermore, compared to common word-level triggers and sentence-level triggers, our approach has been demonstrated to be more stealthy under GPT-2-based perplexity detection and more robust under backdoor defense methods.
Hongwei Li 0001, Wenbo Jiang 0001, Rui Zhang 0086, Jiaming He, Hanxiao Chen 0001, Guowen Xu
IJCNN6
2025 Distributed Function Secret Sharing and Applications
Pengzhi Xing, Hongwei Li 0001, Meng Hao 0001, Hanxiao Chen 0001, Jia Hu 0004
NDSS4
2025 GuardGrid: A Queriable and Privacy-Preserving Aggregation Scheme for Smart Grid via Function Encryption
abstract
Smart grids have revolutionized electricity management by leveraging real-time consumption data, enabling more efficient power control through advanced algorithms. However, this transformation raises significant privacy and security concerns due to the extensive collection of user data. Current solutions face challenges, such as aggregator gateway misbehavior, lack of support for function queries, and the need to balance privacy with efficiency. In this article, we propose FEHH, a novel scheme that ensures both privacy preservation and verifiable aggregation. It allows multiple aggregators to perform inner-product computations on encrypted data while safeguarding the aggregated results from the aggregator. Additionally, it supports verification of aggregated data’s correctness using Linear Homomorphic Hash. Building on FEHH, we introduce GuardGrid, a privacy-preserving aggregation scheme for smart grids that inherits FEHH’s core features and adds support for essential arithmetic operations necessary for function queries. This allows cloud servers to respond to queries from either the control center or users without compromising data confidentiality. Experimental results show that the encryption overhead of GuardGrid is only 7% of that of the PPDA scheme, and its communication overhead is$123\times $less. These results demonstrate that GuardGrid significantly reduces computation and communication costs, providing a more sustainable and cost-effective smart grid solution.
Weicong Huang, Xinyuan Qian 0002, Hongwei Li 0001, Hanxiao Chen 0001
IEEE Internet Things J.6
2024 Benchmark GELU in Secure Multi-Party Computation
abstract
Recently, several technology companies have released online inference services for clients based on Transformer-based large language models, which show excellent performance in various tasks. However, in these services, the inputs usually involve clients’ sensitive information. To address this problem, many works have proposed secure inference on language models such as GPT. For language models, complex mathematical functions like Gaussian Error Linear Unit (GELU) are used extensively and dominate the main cost of secure inference. In this work, we systematically study the existing secure GELU protocols and classify previous methods into two categories: polynomial-based protocols and lookup table (LUT)-based protocols. We point out several important characteristics and tradeoffs for these two classes of secure GELU protocols. Based on these observations and analysis, we propose a new secure GELU protocol, called Simple. The main technique that Simple uses involves a LUT of small size to retrieve approximate polynomials for fitting residual error functions caused by a crude approximation for GELU, which achieves state-of-the-art (SOTA) overhead and accuracy performance. We conduct extensive experiments and benchmark the previous 6 secure GELU protocols. The experimental comparison shows that our Simple protocol achieves 1.1 ∼ 8784.3× computation and 1.4 ∼ 188.8× communication improvements while reducing 1.2∼80.2× errors.
Rui Zhang 0090, Hongwei Li 0001, Meng Hao 0001, Hanxiao Chen 0001, Yuan Zhang 0006, Dianhua Tang
GLOBECOM4
2024 Scalable Zero-knowledge Proofs for Non-linear Functions in Machine Learning
Meng Hao 0001, Hanxiao Chen 0001, Hongwei Li 0001, Chenkai Weng, Yuan Zhang 0006, Haomiao Yang, Tianwei Zhang 0004
USENIX Security Symposium2
2024 Unbalanced Circuit-PSI from Oblivious Key-Value Retrieval
Meng Hao 0001, Liqiang Peng, Hongwei Li 0001, Hanxiao Chen 0001, Tianwei Zhang 0004
USENIX Security Symposium6
2024 SecBNN: Efficient Secure Inference on Binary Neural Networks
abstract
This work studies secure inference on Binary Neural Networks (BNNs), which have binary weights and activations as a desirable feature. Although previous works have developed secure methodologies for BNNs, they still have performance limitations and significant gaps in efficiency when applied in practice. We present SecBNN, an efficient secure two-party inference framework on BNNs. SecBNN exploits appropriate underlying primitives and contributes efficient protocols for the non-linear and linear layers of BNNs. Specifically, for non-linear layers, we introduce a secure sign protocol with an innovative adder logic and customized evaluation algorithms. For linear layers, we propose a new binary matrix multiplication protocol, where a divide-and-conquer strategy is provided to recursively break down the matrix multiplication problem into multiple sub-problems. Building on top of these efficient ingredients, we implement and evaluate SecBNN over two real-world datasets and various model architectures under LAN and WAN. Experimental results show that SecBNN substantially improves the communication and computation performance of existing secure BNN inference works by up to$29 \times $and$14 \times $, respectively.
Hanxiao Chen 0001, Hongwei Li 0001, Meng Hao 0001, Jia Hu 0004, Guowen Xu, Tianwei Zhang 0004
IEEE Trans. Inf. Forensics Secur.1
2023 Practical and Privacy-Preserving Density-Based Clustering via Shuffling
abstract
Density-Based Spatial Clustering of Applications with Noise (DBSCAN) is a commonly used density-based clustering algorithm, and the study of its privacy-preserving methods is of practical importance. However, prior works either leak important intermediate results or suffer from intolerable overhead, which makes it difficult to deploy in real-world scenarios. To address this problem, we propose Private-DBSCAN, a practical secure two-party framework for DBSCAN. Specifically, (i) we design an efficient secure comparison protocol for the calculation of the adjacency matrix, which reduces the online communication to only one round and (ii) we employ a secret-shared shuffle protocol to anonymize the data records, which can hide the position relation of elements while avoiding redundant computations. These ingredients allow Private-DBSCAN to achieve practical efficiency and rigorous security at the same time. We implement our protocol and conduct extensive experiments on five datasets, which show that it achieves a$90\sim 340\times$speedup on LAN and$13\sim 73\times$speedup on WAN compared to the state-of-the-art work.
Yingzhe Wang, Hongwei Li 0001, Hanxiao Chen 0001, Meng Hao 0001
GLOBECOM3
2023 Privacy-Preserving Feature Selection based on Mutual Information
abstract
In the context of collaborative data analysis or machine learning tasks (such as biomedical image segmentation for tumor region definition) involving multiple parties, secure feature selection protocols enable the parties to jointly select the most informative features while preserving their privacy from being exposed to others. However, current secure feature selection methods have several limitations: (1) they leak intermediate results during feature selection raises serious privacy concerns; (2)they cannot cover various scenarios comprehensively. To this end, we present a secure feature selection framework based on mutual information, which improves the privacy-preserving data preprocessing work. Specifically, the division protocol performs low-complexity interactive computations, reducing the time cost to$578^{th}$of the original; besides, our logarithm protocol converts shared values through Beaver's triple, and increases the efficiency by up to 118 times. We conduct extensive experimental evaluations on diverse real-world datasets, and the results demonstrate that our framework achieves up to 28.5% accuracy improve-ment, thus effectively enhancing the privacy protection work of machine learning data preprocessing.
Ningning Wu, Hongwei Li 0001, Hanxiao Chen 0001, Yingzhe Wang
GLOBECOM3
2023 SecMath: An Efficient 2-Party Cryptographic Framework for Math Functions
abstract
Complex math functions, such as exponential and tanh, are widely applied in machine learning inference tasks like recurrent neural networks (RNNs). Even though a few works have provided secure implementations of these functions, they still suffer from serious performance bottlenecks, leaving efficiency gaps in practice. To approach this issue, we propose SecMath, an efficient 2-party cryptographic framework for complex math functions. Specifically, SecMath contributes novel communication-efficient protocols for secure exponential, sigmoid and tanh operations. These protocols utilize an advanced underlying primitive, silent oblivious transfer, and employ customized optimizations including lookup table techniques to further improve performance. Extensive evaluations show that our new constructions outperform the counterparts in SIRNN (IEEE S&P'21) by a large margin in terms of both communication and computation overhead. For example, the sigmoid operation of SecMath costs 4.15KB communication and less than 0.2 millisecond, which improves SIRNN up to 7.6× in communication and 2.4× in runtime.
Jia Hu 0004, Hongwei Li 0001, Hanxiao Chen 0001, Meng Hao 0001
ICC3
2023 TriFSS: Secure Trigonometric Function Evaluation via Function Secret Sharing
abstract
Trigonometric functions are crucial non-linear operations used in scientific computation and complex machine learning models. However, existing secure computing frameworks either lack support for these operations, or suffer from undesirable performance bottleneck. In this paper, we present an efficient and precise fixed-point framework called TriFSS for securely evaluating trigonometric functions. Specifically, we first design new building blocks based on advanced Function Secret Sharing techniques, achieving reduced communication and computation overhead. Second, with these efficient components, we propose a general evaluation process for these functions, in which periodic properties are fully exploited for better performance. Moreover, we implement the TriFSS framework and conduct extensive experiments. The experimental results show that our protocols achieve at least 23x less communication overhead and 2.8x less latency than the state-of-the-art frameworks, while only resulting in 1 ULP error, which is comparable to floating-point based works.
Pengzhi Xing, Hongwei Li 0001, Meng Hao 0001, Hanxiao Chen 0001, Shengke Zeng
ICC4
2023 GuardHFL: Privacy Guardian for Heterogeneous Federated Learning
abstract
Heterogeneous federated learning (HFL) enables clients with different computation and communication capabilities to collaboratively train their own customized models via a query-response paradigm on auxiliary datasets. However, such a paradigm raises serious privacy concerns due to the leakage of highly sensitive query samples and response predictions. We put forth GuardHFL, the first-of-its-kind efficient and privacy-preserving HFL framework. GuardHFL is equipped with a novel HFL-friendly secure querying scheme built on lightweight secret sharing and symmetric-key techniques. The core of GuardHFL is two customized multiplication and comparison protocols, which substantially boost the execution efficiency. Extensive evaluations demonstrate that GuardHFL significantly outperforms the alternative instantiations based on existing state-of-the-art techniques in both runtime and communication cost.
Hanxiao Chen 0001, Meng Hao 0001, Hongwei Li 0001, Kangjie Chen, Guowen Xu, Tianwei Zhang 0004
ICML1
2023 PriVDT: An Efficient Two-Party Cryptographic Framework for Vertical Decision Trees
abstract
Privacy-preserving decision trees (DTs) in vertical federated learning are one of the most effective tools to facilitate various privacy-critical applications in reality. However, the main bottleneck of current solutions is their huge overhead, mainly due to the adoption of communication-heavy bit decomposition to realize complex non-linear operations, such as comparison and division. In this paper, we presentPriVDT, an efficient two-party framework for private vertical DT training and inference in the offline/online paradigm. Specifically, we customize several cryptographic building blocks based on an advanced primitive, Function Secret Sharing (FSS). First, we construct an optimized comparison protocol to improve the efficiency via reducing the invocation of FSS evaluations. Second, we devise an efficient and privacy-enhanced division protocol without revealing the range of divisors, which utilizes the above comparison protocol and more importantly new designed FSS-based secure range and digital decomposition protocols. Besides, we further reduce the overhead of linear operations by employing lightweight pseudorandom function-based Beaver’s triple techniques. Building on the above efficient components, we implement thePriVDTframework and evaluate it on 5 real-world datasets on both LAN and WAN. Experimental results show that the end-to-end runtime ofPriVDToutperforms the prior art by$42 \sim 510\times $on LAN and$16 \sim 70\times $on WAN. Moreover,PriVDTprovides comparable accuracy to the non-private setting.
Hanxiao Chen 0001, Hongwei Li 0001, Yingzhe Wang, Meng Hao 0001, Guowen Xu, Tianwei Zhang 0004
IEEE Trans. Inf. Forensics Secur.1
2023 FastSecNet: An Efficient Cryptographic Framework for Private Neural Network Inference
abstract
Private neural network inference has demonstrated great importance in various privacy-critical scenarios. However, the primary challenge remaining in prior works is that the evaluation on encrypted data levies prohibitively high run-time and communication overhead. In this work, we present FastSecNet, an efficient two-party cryptographic framework for private inference in the dealer-based pre-processing setting. Specifically, (1) FastSecNet provides an efficient ReLU protocol for the evalution of non-linear layers, which is built up on a recent advanced cryptographic primitive, function secret sharing (FSS). The core of this construction are an optimized ReLU representation and a customized FSS-based ReLU protocol. (2) For linear layer evaluation, we first propose an efficient PRG-based preprocessing protocol based on the fact that one of the inputs is uniformly random in the offline phase. Then, the online phase only communicates one element and consists of lightweight secret-sharing operations in a ring. Extensive evaluations conducted on 4 real-world datasets and 9 neural network models demonstrate that during the online phase, FastSecNet achieves 14× less runtime and 18× less communication cost compared to the state-of-the-art.
Meng Hao 0001, Hongwei Li 0001, Hanxiao Chen 0001, Pengzhi Xing, Tianwei Zhang 0004
IEEE Trans. Inf. Forensics Secur.3
2022 Secure Feature Selection for Vertical Federated Learning in eHealth Systems
abstract
Privacy-preserving vertical federated learning (VFL) has been widely applied in electronic health (eHealth) systems. However, existing VFL schemes rarely consider the data pre-processing step including feature selection, which will lead to poor convergence rate and even damaging the model utility. In this paper, we propose an efficient and privacy-preserving feature selection scheme for VFL. Specifically, we first propose a general Gini-impurity based feature selection framework, which is compatible with most existing machine learning models in VFL. With the framework, we present two concrete protocols (dubbed πSS−FSand πH−FS, respectively) customized for different eHealth scenarios. πSS−FSexploits a lightweight additive secret sharing technique, such that it can be executed in comparable time as the evaluation of the plaintext scheme. πH−FSis a hybrid feature selection protocol that additionally utilizes a linear homomorphic encryption technique, to reduce the communication overhead at the cost of a moderate runtime. Moreover, extensive evaluations conducted on real-world medical datasets demonstrate that our scheme realizes up to 27% accuracy gains.
Rui Zhang 0086, Hongwei Li 0001, Meng Hao 0001, Hanxiao Chen 0001, Yuan Zhang 0006
ICC4
2022 Iron: Private Inference on Transformers
abstract
We initiate the study of private inference on Transformer-based models in the client-server setting, where clients have private inputs and servers hold proprietary models. Our main contribution is to provide several new secure protocols for matrix multiplication and complex non-linear functions like Softmax, GELU activations, and LayerNorm, which are critical components of Transformers. Specifically, we first propose a customized homomorphic encryption-based protocol for matrix multiplication that crucially relies on a novel compact packing technique. This design achieves $\sqrt{m} \times$ less communication ($m$ is the number of rows of the output matrix) over the most efficient work. Second, we design efficient protocols for three non-linear functions via integrating advanced underlying protocols and specialized optimizations. Compared to the state-of-the-art protocols, our recipes reduce about half of the communication and computation overhead. Furthermore, all protocols are numerically precise, which preserve the model accuracy of plaintext. These techniques together allow us to implement \Name, an efficient Transformer-based private inference framework. Experiments conducted on several real-world datasets and models demonstrate that \Name achieves $3 \sim 14\times$ less communication and $3 \sim 11\times$ less runtime compared to the prior art.
Meng Hao 0001, Hongwei Li 0001, Hanxiao Chen 0001, Pengzhi Xing, Guowen Xu, Tianwei Zhang 0004
NeurIPS3
2022 Practical Membership Inference Attack Against Collaborative Inference in Industrial IoT
abstract
The effectiveness of state-of-the-art deep learning (DL) models has empowered the development of industrial Internet of things (IIoT). Recently, considering resource-constrained and privacy-required IIoT devices, collaborative inference has been proposed, which splits DL models and deploys them in IIoT devices and an edge server separately. However, in this article, we argue that there are still severe privacy vulnerabilities in collaborative inference systems. And we devise the first membership inference attack (MIA) against collaborative inference, to infer whether a particular data sample is used for training the model of IIoT systems. Existing MIAs either assume full access to the systems’ APIs or availability of the target model's parameters, which is not applicable in realistic IIoT environments. In contrast to prior works, we proposetransfer-inheritshadow learning and thus relax these key assumptions. We evaluate our attack on different datasets and various settings, and the results show it has high effectiveness.
Hanxiao Chen 0001, Hongwei Li 0001, Guishan Dong, Meng Hao 0001, Guowen Xu, Zhe Liu 0001
IEEE Trans. Ind. Informatics1
2021 Efficient, Private and Robust Federated Learning
abstract
Federated learning (FL) has demonstrated tremendous success in various mission-critical large-scale scenarios. However, such promising distributed learning paradigm is still vulnerable to privacy inference and byzantine attacks. The former aims to infer the privacy of target participants involved in training, while the latter focuses on destroying the integrity of the constructed model. To mitigate the above two issues, a few works recently explored unified solutions by utilizing generic secure computation techniques and common byzantine-robust aggregation rules, but there are two major limitations: 1) they suffer from impracticality due to efficiency bottlenecks, and 2) they are still vulnerable to various types of attacks because of model incomprehensiveness.
Meng Hao 0001, Hongwei Li 0001, Guowen Xu, Hanxiao Chen 0001, Tianwei Zhang 0004
ACSAC4
2021 Stand-in Backdoor: A Stealthy and Powerful Backdoor Attack
abstract
Lack of transparency in deep learning models makes them vulnerable to backdoor attack, which can cause severe security consequences. For a backdoored model, the specific inputs can trigger misclassification rules while it performs normal behaviors on clean data. Existing backdoor attacks usually generate poisoned data by adding an obvious trigger to the original data and mislabeling them, which suffers from poor invisibility and hence can be easily detected. In this paper, we propose Stand-in Backdoor, a more stealthy and powerful backdoor attack, which can completely hide the trigger while maintaining correct labels of poisoned data. Specifically, we design a novel optimization strategy to transform triggers into imperceptible perturbation in the feature space. Furthermore, utilizing the transferability of feature perturbation, we fine-tune the victim model with well-constructed poisoned data that are correctly labeled. Extensive experiments conducted on various image classification tasks demonstrate that our attack outperforms the state-of-the-art work in terms of backdoor stealth and attack performance, without sacrificing the model's utility.
Hongwei Li 0001, Hanxiao Chen 0001
GLOBECOM3
2020 Achieving Privacy-preserving Federated Learning with Irrelevant Updates over E-Health Applications
abstract
The widespread use of edge devices in E-Health such as smartphones and wearables means richer electronic health records (EHR) are becoming available. Training deep learning models on these data can effectively improve the quality of healthcare services. Recently, federated learning (FL) has received extensive attention in E-Health because it can train a model by only sharing gradients without disclosing the original EHR of owners. In this case, however, the adversary can still violate EHR owners' privacy based on shared gradients. To mitigate privacy threat, several privacy-preserving FL protocols have been proposed by utilizing different cryptography techniques. Unfortunately, existing privacy-preserving FL schemes do not take into account irrelevant updates, which are useless for the convergence of the global model. This may reduce the predictive accuracy and worse may lead to the uselessness of the final model. In this paper, we propose PFL-IU, an efficient and privacy-preserving FL framework that is compatible with irrelevant updates. Specifically, we first design a communication-efficient secure aggregation protocol by using a non-interactive key generation algorithm. Then we present a sign method to mitigate the negative impact incurred by irrelevant updates, which will accelerate model convergence and improve predictive accuracy. Moreover, PFL-IU is robust to EHR owners' dropout during the whole training phase. Extensive experiments using the real-world dataset demonstrate that PFL-IU can achieve better performance in terms of accuracy, convergence and efficiency.
Hanxiao Chen 0001, Hongwei Li 0001, Guowen Xu, Xizhao Luo
ICC1