EDBT 2026 Demo / reviewers in the wild / expert
Haiyu Deng
dblp:261/4168
· DBLP profile ↗
8ranked-venue papers
3as first author
8since 2021 · last 2026
0000-0002-7513-4009ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | NNFMAC: A Neural Network Fingerprinting-Based Model Authentication Code SchemeabstractAs deep learning–based AI proliferates, model theft and plagiarism pose increasing Intellectual Property (IP) risks. However, watermarking alters model weights and can degrade performance, while fingerprinting often merely verifies uniqueness or requires heavy computation. In this article, we propose a Neural Network Fingerprinting-Based Model Authentication Code (NNFMAC) scheme that verifies both model uniqueness and ownership without affecting performance. NNFMAC extracts key weights from a trained model, applies a median-based method to generate a unique binary fingerprint, and uses this fingerprint as a codebook to encode ownership information via a newly designed index-based function with expansion, producing reliable authentication codes. This non-intrusive approach integrates fingerprinting for uniqueness verification and authentication coding for ownership verification, delivering comprehensive model IP protection while preserving the model’s original performance. Extensive experiments demonstrate that NNFMAC preserves model accuracy without additional training overhead, unlike other watermarking schemes that degrade accuracy by 0.36–1.53%. It achieves bit error rates of 0.12 under weight perturbation, 0.03 under fine-tuning, 0.08 under pruning, and 0.09 under weight shifting attacks, which are substantially lower than the 0.51, 0.49, 0.46, and 0.22 reported in prior work, while consistently outperforming state-of-the-art schemes in effectiveness, efficiency, and robustness. Haiyu Deng, Xu Wang 0004, Guangsheng Yu, Wei Ni 0001, Ying He 0011, Tanzeela Altaf, Ren Ping Liu 0001 |
ACM Trans. Multim. Comput. Commun. Appl. | 1 |
| 2026 | Client-Cooperative Split LearningabstractModel training is increasingly offered as a service for resource-constrained data owners to build customized models. Split Learning (SL) enables such services by offloading training computation under privacy constraints, and evolves towardserverlessandmulti-clientsettings where model segments are distributed across training clients. This cooperative mode assumes partial trust: data owners hide labels and data from trainer clients, while trainer clients produce verifiable training artifacts and ownership proofs. We presentCliCooper, a multi-clientcooperative SL framework tailored for cooperative model training services in heterogeneous and partially trusted environments, where one client contributes data, while others collectively act as SL trainers.CliCooperbridges the privacy and trust gaps through two new designs. First, Differential Privacy–based activation protection and secret label obfuscation safeguard data owners' privacy without degrading model performance. Second, a dynamic chained watermarking scheme cryptographically links training stages on model segments across trainers, ensuring verifiable training integrity, robust model provenance, and copyright protection. Experiments show thatCliCooperpreserves model accuracy while enhancing resilience to privacy and ownership attacks. It reduces the success rate of clustering attacks (which infer label groups from intermediate activation) to 0%, decreases inversion-reconstruction (which recovers training data) similarity from 0.50 to 0.03, and limits model-extraction–based surrogates to about 1% accuracy, comparable to random guessing. Haiyu Deng, Yanna Jiang, Guangsheng Yu, Qin Wang 0008, Xu Wang 0004, Wei Ni 0001, Shiping Chen 0001, Ren Ping Liu 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2025 | A Novel Scheme for Recommendation Unlearning Verification (RUV) Using Non-Influential Trigger DataabstractMachine unlearning has garnered widespread attention, due to various reasons, including privacy-preserving, model usability, and legal regulations. It requires model providers to unlearning users' data from models upon receiving unlearning request. Recommendation systems have also been extensively researched in the field of deep learning, particularly within the context of big data environments. However, little research can be found to verify the effectiveness of unlearning approach using pure tabular data-based recommendation scenario. In this paper, we propose a recommendation unlearning verification (RUV) scheme based on non-influential trigger data, which fills this gap. Users can use the recommendation rate for selected target items to determine whether the recommendation system complies with unlearning requests. Evaluation results on real datasets confirm the efficiency and effectiveness of our proposed RUV scheme. Xiaocui Dang, Priyadarsi Nanda, Manoranjan Mohanty, Haiyu Deng |
CCNC | 5 |
| 2025 | SoK: Credential-Based Trust Management in Decentralized Ledger SystemsabstractTrust management systems (TMS) are crucial for managing trust in distributed environments. The rise of decentralized systems and blockchain has sparked interest in credential-based decentralized trust management systems (DTMS). This paper bridges the gap between theory and practice through a systematic review of credential-based DTMS. We analyze existing DTMS solutions through multiple dimensions, including their architectural designs, credential mechanisms, and trust evaluation models. Our survey provides a detailed taxonomy of credential-based DTMS approaches and establishes comprehensive evaluation criteria for assessing DTMS implementations. Through extensive analysis of current systems and implementations, we identify critical challenges and promising research directions in the field. Our examination offers valuable insights for researchers and practitioners working on DTMS, particularly in areas such as access control, reputation systems, and blockchain-based trust frameworks. Yanna Jiang, Haiyu Deng, Qin Wang 0008, Guangsheng Yu, Xu Wang 0004, Yilin Sai, Shiping Chen 0001, Wei Ni 0001, Ren Ping Liu 0001 |
TrustCom | 2 |
| 2024 | Recommendation System Model Ownership Verification via Non-Influential WatermarkingabstractWhile deep learning-based recommendation systems have achieved great success, recommendation system models are also at serious risk of intellectual property infringement. Current model watermarking research faces significant challenges in terms of fidelity, invisibility, and efficiency. Additionally, existing model watermarking techniques are predominantly applied to image data, with limited applicability to tabular data. In this paper, we introduce an innovative watermarking framework designed to safeguard the ownership of recommendation system models. Specifically, we verify recommendation system model ownership by embedding a type of backdoor watermark into the training dataset, which does not affect model performance. We have conducted experiments on several classical datasets to validate the reliability and effectiveness of our approach. Xiaocui Dang, Priyadarsi Nanda, Haiyu Deng, Manoranjan Mohanty |
SIN | 4 |
| 2024 | A Dual Defense Design Against Data Poisoning Attacks in Deep Learning-Based Recommendation SystemsabstractDeep learning is being extensively utilized across various domains, with deep learning-based recommendation systems gaining prominence due to their exceptional performance. However, these systems are vulnerable to data poisoning attacks, where adversaries introduce carefully crafted fake user ratings to compromise the integrity of the recommendation model. We propose a dual defense to address this threat. The first line of defense, termed active defense, preemptively reduces the system’s vulnerability to poisoning attacks by incorporating crafted regularization into the loss function. This approach diminishes the attacker’s impact while preserving system performance, thereby lowering the success rate of targeted attacks. To further enhance the system’s robustness, we introduce a Generative Adversarial Network (GAN) based detection model as a passive defense strategy to accurately identify and filter out poisoned data. Empirical evaluations on three distinct datasets demonstrate that our dual defense approach significantly enhances both the proactive defense and passive detection capabilities of recommendation systems, effectively countering data poisoning attacks. Xiaocui Dang, Priyadarsi Nanda, Manoranjan Mohanty, Haiyu Deng |
TrustCom | 4 |
| 2024 | FedNIFW: Non-Interfering Fragmented Watermarking for Federated Deep Neural NetworkabstractDuring the deployment and utilization of federated models, they are susceptible to unauthorized theft or misuse. To address this issue, researchers have proposed the use of watermarking techniques to protect the Intellectual Property (IP) of the federated models. Nevertheless, traditional watermarking methods in federated learning have certain limitations. It is highly likely that different clients may embed watermarks in the same region of the model. During the aggregation of the watermarked weights, the watermarks from various clients may overlap, resulting in conflicts between the embedded watermarks. To overcome these challenges, we propose a novel method called Non-Interfering Fragmented Watermarking for Federated Models (FedNIFW). In the proposed scheme, each client node is assigned a specific segment of the neural network layer where watermarking can be applied. During training, each client is allowed to embed watermarks only within their designated segments, while other segments intended for watermarking by different clients are frozen. Experimental results demonstrate that this segmented watermarking scheme effectively prevents conflicts between client watermarks and does not significantly impact the accuracy of the federated models. These findings underscore the feasibility of the proposed watermarking scheme. Haiyu Deng, Xiaocui Dang, Yanna Jiang, Xu Wang 0004, Guangsheng Yu, Wei Ni 0001, Ren Ping Liu 0001 |
TrustCom | 1 |
| 2021 | Smart Home Privacy Protection Based on the Improved LSB Information HidingabstractSmart home is an emerging form of the Internet of Things (IoT), enabling people to enjoy a convenient and intelligent life. The data generated by smart home devices are transmitted through the public channel, which is not secure enough, so the secret data in smart home are easily intercepted by malicious adversaries. In order to solve this problem, this paper proposes a smart home privacy protection method combining DES encryption and the improved Least Significant Bit (LSB) information hiding algorithm, changing the practice of directly exposing smart home secret information to the Internet, first, using Data Encryption Standard (DES) encryption to encrypt the smart home information and second, the improved LSB information hiding algorithm is used to hide the ciphertext, so that the adversary cannot detect the smart home secret information. The goal of the scheme is to provide a double protection for the secure transmission of the smart home secret information. If an attacker wants to carry out an attack, it has to break through at least two defense lines, which seems impossible to do. Experiment results show that the improved LSB algorithm is more robust than the existing algorithms, and it is very safe. Therefore, the scheme proposed in this paper is very practical for protecting the smart home secret information. Haiyu Deng, Ren Ping Liu 0001, Patrick Shen-Pei Wang, Xiaocui Dang, Yuan Yan Tang, Xichun Li |
Int. J. Pattern Recognit. Artif. Intell. | 2 |