EDBT 2026 Demo / reviewers in the wild / expert
Zhirun Zheng
dblp:268/5448
· DBLP profile ↗
12ranked-venue papers
7as first author
11since 2021 · last 2026
0000-0003-3030-709XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 5 · 1 first-author · 4 since 2021Security and privacy · 4 · 4 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Uncertainty-Guided Semantic Graph Reasoning for Remote Sensing Change Detection
Zhirun Zheng, Zheping Zhang |
ICIC (10) | 1 |
| 2026 | Trigger as Entity: Backdoor Attacks to Graph-Based Retrieval-Augmented Generation of Large Language ModelsabstractGraph-based Retrieval-Augmented Generation (RAG) has achieved remarkable success in refining the outputs of Large Language Models (LLMs), enabling them to integrate relational and multi-hop knowledge into context-aware responses by constructing a knowledge graph from an external database. In this paper, we focus on the underexplored security risks arising from the external database, and propose the first backdoor attacks against the graph-based RAG of LLMs. Specifically, attackers insert the backdoor into the knowledge graph as entities by poisoning a carefully crafted corpus into the external database, thereby causing LLMs to output attacker-desired answers for trigger-containing queries while preserving correct answers for others. The attacks are formulated as a minimax problem, whose solution is a poison corpus. Powered by the chain-of-thought reasoning capabilities of LLMs, we propose a new strategy to solve the minimax problem. We craft retrieval text to insert triggers into the knowledge graph as entities, exploit hijacking text to redirect LLMs’ attention toward attacker-desired answers, and finally link the hijacking text to the triggers so that it serves as context only for trigger-containing queries. In addition, our attacks involve three types of triggers, including word-level, topic-level, and semantic-level, with progressively increasing stealthiness. Empirical results across multiple knowledge databases and language models indicate that the proposed attacks achieve the desired attack performance. Our findings highlight the substantial risks in LLM applications (e.g., chatbots and agents) built on graph-based RAG systems. Zhirun Zheng, Young-June Choi, Cheng Huang 0001, Hangcheng Cao, Shujuan Tian, Tingrui Pei |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Continuous Publication of Weighted Graphs with Local Differential PrivacyabstractAlthough a large amount of valuable knowledge can be obtained from the weighted graph snapshots modeled over time, it may cause privacy issues. Local differential privacy (LDP) provides a strong solution for private graph data publishing in decentralized networks. However, most existing LDP studies over graphs are only applicable to static unweighted graphs. This paper investigates the problem of continuous publication of weighted graph snapshots and proposes a graph publication framework, WGT-LDP, under w -event edge weight LDP, which can protect the privacy of edges and weights over any w consecutive time steps. WGT-LDP consists of four key components: population division-based sampling that overcomes the problem of over-segmentation of the privacy budget, data range estimation that mitigates noise on edge weights, aggregate information collection that obtains important information about the graph structure and edge weights, and graph snapshot generation that reconstructs weighted graph snapshot at each time step. We provide theoretical guarantees on privacy and utility, and perform extensive experiments on three real-world and two synthetic datasets, using four commonly used metrics. Our experiments show that WGT-LDP produces high-quality synthetic weighted graphs and significantly outperforms baseline methods. Pengpeng Qiao, Shang Liu 0001, Zhirun Zheng, Yang Cao 0011, Zhetao Li |
Proc. VLDB Endow. | 4 |
| 2025 | Pricing Utility vs. Location Privacy: A Differentially Private Data Sharing Framework for Ride-on-Demand ServicesabstractNoise perturbation introduced by differential privacy (DP) could degrade the quality of essential services like dynamic pricing and ride-matching in ride-on-demand (RoD) services. In this paper, we focus on RoD services under an honest-but-curious server, and propose a Pricing-Aware Differentially Private framework (PADP-RoD) to protect users’ location privacy while providing them with high-quality location-based services. Specifically, given that a price multiplier is subject to abrupt changes in response to shifts in supply and demand, especially near hotspots, we propose an adaptive supply and demand aware grid to capture the changes. Powered by the grid, we put forward two utility metrics for quantifying the quality loss of dynamic pricing and ride-matching services caused by perturbation, respectively. With those metrics, PADP-RoD is formulated as a minimization problem, aiming to minimize the quality loss of services given DP constraint. In this way, we can achieve an optimal balance between privacy and service quality. Due to the problem being a multi-objective optimization, we decompose it into a dynamic-pricing utility sub-problem and a ride-matching utility sub-problem, and solve them separately. To solve the dynamic pricing utility sub-problem, we propose a heuristic algorithm named the dynamic pricing mapping algorithm. Since the semi-infinite and non-differentiable nature of the ride-matching utility sub-problem, we transform this sub-problem into an unconstrained problem by the exact penalty function method, and solve it employing the particle swarm optimization algorithm. Our theoretical analysis demonstrates that PADP-RoD satisfies both$\varepsilon _{d}$-DP and$\varepsilon _{d}$-identifiability, and extensive experiments on a real-world dataset show that it can provide high-quality dynamic pricing and ride-matching services. Zhirun Zheng, Zhetao Li, Saiqin Long, Suiming Guo, Chao Chen 0004, Ke Xu 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | User-Driven Privacy-Preserving Data Streams Release for Multi-Task Assignment in Mobile CrowdsensingabstractMulti-task assignment is widely used in mobile crowdsensing (MCS) to efficiently utilize limited resources such as shared user pool, user capability constraints and so on. In MCS, users need to submit data streams to perform sensing tasks, which involve a large amount of private information. However, the privacy leakage when users perform tasks across different types and submit multimodal data streams in multi-task assignment has not been fully addressed in current works. Privacy requirements vary for users with different activity levels in multi-task assignment. Specifically, users with higher activity levels tend to handle more task types and submit more data types, which poses more serious consequences of privacy leakage. Meanwhile, the privacy requirements of users are dynamic due to the user’s changing activity. In this work, we propose a user-driven local differential privacy framework for multi-task assignment called UD-LDP. First, we design a flexible privacy model called$w$-adjacent-event privacy to provide accurate privacy protection for users with different activity levels. Then, we introduce information entropy to quantify privacy requirements of user’s activity in real-time. After that, we propose a privacy-aware budget allocation method to dynamically allocate personalized privacy budgets for each user. At last, we design a variance-optimized selection method that chooses rational privacy budgets and users for release to improve data utility. The effectiveness of our framework is supported by experiments conducted on both real-world and synthetic datasets. Zhetao Li, Saiqin Long, Zhirun Zheng, Mianxiong Dong |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | Partial Offloading Strategy Based on Deep Reinforcement Learning in the Internet of VehiclesabstractDriven by the increasing demands of vehicular tasks, edge offloading has emerged as a promising paradigm to enhance quality of experience (QoE) in Internet of Vehicles (IoV) networks. This approach enables vehicles to offload computation-intensive tasks to edge servers, resulting in reduced computation delays and lower energy consumption. However, traditional binary offloading limits the efficiency of edge offloading. To address this gap, we propose a partial offloading strategy that jointly optimizes the offloading ratio, computation, and communication resources in IoV. Recognizing the varying priorities of vehicular tasks regarding task delay and energy consumption, we formulate two distinct scenarios: one focused on minimizing delay and the other on minimizing energy consumption. Furthermore, we employ a reinforcement learning approach to establish a multi-dimensional joint optimization function by setting different objectives for each scenario. Based on this framework, we introduce a multi-state iteration deep deterministic policy gradient algorithm (SIDDPG), which effectively determines task partitioning and resource allocation. Simulation results demonstrate that the proposed algorithm outperforms benchmark schemes in terms of task delay and energy consumption. Shujuan Tian, Xinjie Zhu, Bochao Feng, Zhirun Zheng, Haolin Liu 0001, Zhetao Li |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | Defending Data Poisoning Attacks in DP-Based Crowdsensing: A Game-Theoretic ApproachabstractDifferential privacy (DP) is widely used for protecting privacy in crowdsensing by adding noises. However, malicious attackers can exploit noise to launch covert data poisoning attacks. In this paper, we propose a game-based defense approach to resist such data poisoning attacks in DP-based crowdsensing systems. In this approach, attackers are believed to be powerful as they can refine their attack strategy based on the observations of deployed defenders’ defense strategy. Specifically,the defendersformulate the defense as a functional minimization problem (which cannot be directly solved by numerical optimization algorithms because its decision variable is a set of functions), resisting data poisoning attacks by deleting data shared by identified malicious workers through the log-likelihood ratio test. To obtain a current defense strategy, the decision variable of the problem is relaxed into the coefficients of basis-based linear combinations through the variable-basis approximation, and then solved using the simulated annealing genetic algorithm. Correspondingly,the attackersformulate their attack strategy as a bi-level maximization problem (which is an NP-hard problem), biasing crowdsensing results as much as possible while remaining undetected. Since the attackers can know the defense strategy, they may bypass the defenders by constraining the expected log-likelihood ratio test. Additionally, the attackers can evade truth discovery methods deployed in crowdsensing using DP noise. To determine a current attack strategy, the bi-level problem is decomposed into upper-level and lower-level sub-problems, wherein the upper-level sub-problem is solved by the variational methods, and then these sub-problems are alternately optimized. Finally, we propose a local minimax points calculating algorithm to obtain an equilibrium point in the defenders-attackers game, thereby finding an optimal defense strategy to resist the powerful data poisoning attack. Extensive experiments on real-world and synthetic datasets show that the proposed game-based defense approach can effectively defend powerful and covert attackers. Zhirun Zheng, Zhetao Li, Cheng Huang 0001, Saiqin Long, Xuemin Shen |
IEEE Trans. Mob. Comput. | 1 |
| 2024 | Data Poisoning Attacks and Defenses to LDP-Based Privacy-Preserving CrowdsensingabstractIn this paper, we explore data poisoning attacks and their defenses in local differential privacy (LDP)-based crowdsensing systems. First, we construct data poisoning attacks launched by corrupted workers to subvert crowdsensing results by tampering information reported. Specifically, the attacks are formulated as a bi-level optimization problem where attackers strive to conceal their malicious behavior by delicately exploiting noise perturbation introduced by LDP protocols. In this way, the attacks can not be detected, even with the weight-based truth discovery methods. Due to the NP-hard nature of the bi-level problem, we decompose it into upper-level and lower-level sub-problems and employ the augmented Lagrangian method to iteratively solve them, ultimately identifying optimal attack strategies. Second, we propose corresponding countermeasures to defend against the attacks. The countermeasures are formulated as a minimization problem, with the objective of minimizing disruptions caused by attacks through the identification and removal of corrupted workers from crowdsensing systems. To solve the problem, we utilize a differential evolution algorithm instead of gradient-based methods since the objective function of the problem is not differentiable. Extensive experiments on real-world datasets are conducted to evaluate the performance of the proposed attacks and defenses. The evaluation results demonstrate that LDP perturbation indeed facilitates the success of data poisoning attacks, and the proposed defenses can accurately distinguish malicious behaviors disguised. Zhirun Zheng, Zhetao Li, Cheng Huang 0001, Saiqin Long, Mushu Li, Xuemin Shen |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Disguised as Privacy: Data Poisoning Attacks Against Differentially Private Crowdsensing SystemsabstractAlthough crowdsensing has emerged as a popular information collection paradigm, its security and privacy vulnerabilities have come to the forefront in recent years. However, one big limitation of previous research is that the security domain and the privacy domain are typically considered separately. Therefore, it is unclear whether the defense methods in the privacy domain will have unexpected impact on the security domain. To bridge this gap, in this paper, we propose a novel Disguise-based Data Poisoning Attack (DDPA) against the differentially private crowdsensing systems empowered with the truth discovery method. Specifically, we propose a novel stealth strategy, i.e., disguising the malicious behavior as privacy behavior, to avoid being detected by truth discovery methods. With this stealth strategy, the shortcoming of failing to maximize the attack effectiveness is avoided naturally through structuring a bi-level optimization problem, which can be solved with the alternating optimization algorithm. Moreover, we show that the differentially private crowdsensing systems are vulnerable to data poisoning attacks, and enhancing the level of privacy will bring more serious security threats. Finally, the evaluation results on the real-world dataset Emotion and the synthetic dataset SynData demonstrate that DDPA can not only achieve maximum utility damage but also remain undetected. Zhetao Li, Zhirun Zheng, Suiming Guo, Bin Guo 0001, Fu Xiao 0001, Kui Ren 0001 |
IEEE Trans. Mob. Comput. | 2 |
| 2022 | Semantic-Aware Privacy-Preserving Online Location Trajectory Data SharingabstractAlthough users can obtain various services by sharing their location information online with location-based service providers, it reveals sensitive information about users. However, existing privacy-preserving techniques in the online scenario suffer from the following shortcomings. First, they model the correlations between the real trajectory and the distorted trajectory as undirected, which makes them unable to accurately quantify the data privacy leakage caused by sharing the distorted trajectory. Second, they are unable to protect semantic privacy, i.e., attackers can obtain the victims’ visit purpose by using the Point of Interest information without knowing the real location data. Additionally, they fail to balance semantic-aware data utility and privacy protection. To make the case even worse, compared to the offline scenario, sharing trajectory online in real time does not have access to the overall location trajectory. In this paper, we propose a novel semantic-aware privacy-preserving online location trajectory sharing mechanism, called SEmantic-aware Information-Theoretic Privacy (SEITP), to protect both data privacy and semantic privacy while the semantic-aware data utility can be preserved. In particular, we put forward two new metrics of privacy to capture data privacy leakage and semantic privacy leakage, respectively. Besides, to quantify the semantic-aware trajectory data utility, we propose a semantic-aware utility metric. With those metrics, the shortcoming of failing to guarantee the data utility is avoided naturally through structuring a multi-objective optimization problem. Then, we theoretically prove that the new construction can protect both data and semantic privacy. Finally, the experimental evaluations based on the real-world private vehicle trajectory dataset demonstrate that SEITP outperforms existing mechanisms. Zhirun Zheng, Zhetao Li, Hongbo Jiang 0001, Leo Yu Zhang, Dengbiao Tu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Utility-aware and Privacy-preserving Trajectory Synthesis Model that Resists Social Relationship Privacy AttacksabstractFor academic research and business intelligence, trajectory data has been widely collected and analyzed. Releasing trajectory data to a third party may lead to serious privacy leakage, which has spawned considerable researches on trajectory privacy protection technology. However, existing work suffers from several shortcomings. They either focus on point-based location privacy, ignoring the spatio-temporal correlations among locations within a trajectory, or they protect the privacy of each user separately without considering privacy leakage of the social relationship between trajectories of different users. Besides, they fail to balance privacy protection and data utility. Motivated by these limitations, in this article, we propose S 3 T -Trajectory, which is a utility-aware and privacy-preserving trajectory synthesis model that Resists social relationship privacy attacks. Specifically, we first develop a time-dependent Markov chain based on an adaptive spatio-temporal discrete grid to efficiently and accurately capture human mobility behavior. Then, we propose three mobility feature metrics from spatio-temporal, semantic, and social dimensions. On the basis of the metrics, we construct a bi-level optimization problem to accomplish the utility-aware and privacy-preserving trajectory synthesizing. The upper-level objective guarantees data utility and the lower-level optimization problems (or upper-level constraints) provides two-layer privacy protection for S 3 T -Trajectory, i.e., resisting location inference attacks and social relationship privacy attacks. We conduct extensive experiments on large-scale real-world datasets loc-Gowalla and loc-Brightkite. The experimental results demonstrate the effectiveness and robustness of S 3 T Trajectory. Compared with the baseline models, S 3 T Trajectory achieves between 7.8% and 23.8% performance improvement in resisting social relationship privacy attacks and achieves at least 5.19% improvement regarding data utility. Zhirun Zheng, Zhetao Li, Jie Li 0002, Hongbo Jiang 0001, Tong Li 0013, Bin Guo 0001 |
ACM Trans. Intell. Syst. Technol. | 1 |
| 2020 | Drive2friends: Inferring Social Relationships From Individual Vehicle Mobility DataabstractThe number of vehicles has increased year by year, especially individual vehicles. In addition to meeting basic transportation needs, vehicles are expected to serve varied location-based services and applications for humans. However, it can constitute severe risks for privacy. In this article, we concentrate on one of the most sensitive information, namely, social relationships, that can be inferred from the vehicle mobility data. We propose a social relationship inference model, which provides a new perspective for privacy preservation in human mobility data. In particular, we extract discriminative features from both the spatial and temporal dimensions. Then, the heterogeneous features are being merged with a fusion model to improve the performance of inference. Extensive experiments on the real-world data set validate the effectiveness of the extracted features in estimating social connections and demonstrate that our method significantly outperforms the baseline models. Jie Li 0058, Fanzi Zeng, Zhu Xiao, Hongbo Jiang 0001, Zhirun Zheng, Wenping Liu 0001, Ju Ren 0001 |
IEEE Internet Things J. | 5 |