EDBT 2026 Demo / reviewers in the wild / expert
Wenjing Zhang 0002
dblp:27/3057-2
· DBLP profile ↗
8ranked-venue papers
3as first author
6since 2021 · last 2024
0000-0002-3066-7186ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | CODER: Protecting Privacy in Image Retrieval With Differential PrivacyabstractImage retrieval techniques can be easily abused to violate personal privacy with images containing individuals' sensitive information. For example, people's identity information can be inferred from their face photos. Therefore, images should be sanitized before being shared or transmitted. However, previous works on image privacy protection suffer from either no provable privacy protection or poor utility with privacy guarantee. In this work, we proposeCODER, a privacy protection mechanism in image retrieval, with provable privacy guarantee as well as improved utility. In particular,CODERachieves metric differential privacy and adopts a newly proposed distortion metric definition which measures the distance more precisely to improve utility. The novel distortion metric can be applied to an arbitrary k-dimensional metric space with stronger image privacy protection. We theoretically analyze the privacy guarantee and rigorous utility bound ofCODER. We also experimentally compare its performance with two state-of-the-art works on two widely used face datasets. The results show thatCODERsignificantly improves the utility of the protected images and demonstrates its superiority in terms of the privacy-utility trade-off over the compared works. Finally, we perform reliability verification on both discriminative and generative models to demonstrate the practicality ofCODER Haonan Yan, Wenjing Zhang 0002, Qian Chen 0032, Bin Wang 0062, Hui Li 0006, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | Automatic Evasion of Machine Learning-Based Network Intrusion Detection SystemsabstractNetwork intrusion detection systems (IDS) are often considered effective to thwart cyber attacks. Currently, state-of-the-art (SOTA) IDSs are mainly based on machine learning (ML) including deep learning (DL) models, which suffer from their own security issues, especially evasion attacks by using adversarial examples. However, previous studies mostly focus on extracted features rather than the traffic sample itself, and/or assume that the adversary knows the information of the target model more or less, which severely restricts attack feasibility in practice. In this paper, we re-investigate this problem in a more realistic label-only black-box scenario and propose a practical evasion attack strategy to solve the above limitations. In this newly considered case that the adversary morphs the traffic sample and only obtains the results accepted or rejected without other knowledge, we successfully leverage the model extraction and transfer attack to evade the detection. The entire attack strategy is automated and a comprehensive evaluation is performed. Final results show that the proposed strategy effectively evades seven typical ML-based IDSs and one SOTA DL-based IDS with an average success rate of over$75\%$. We also discuss the corresponding countermeasures against our attack, which finally highlight the need for effective defenses against our attack. Haonan Yan, Wenjing Zhang 0002, Hui Li 0006, Xingwen Zhao, Fenghua Li 0001, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2023 | RECESS Vaccine for Federated Learning: Proactive Defense Against Model Poisoning AttacksabstractModel poisoning attacks greatly jeopardize the application of federated learning (FL). The effectiveness of existing defenses is susceptible to the latest model poisoning attacks, leading to a decrease in prediction accuracy. Besides, these defenses are intractable to distinguish benign outliers from malicious gradients, which further compromises the model generalization. In this work, we propose a novel defense including detection and aggregation, named RECESS, to serve as a “vaccine” for FL against model poisoning attacks. Different from the passive analysis in previous defenses, RECESS proactively queries each participating client with a delicately constructed aggregation gradient, accompanied by the detection of malicious clients according to their responses with higher accuracy. Further, RECESS adopts a newly proposed trust scoring based mechanism to robustly aggregate gradients. Rather than previous methods of scoring in each iteration, RECESS takes into account the correlation of clients’ performance over multiple iterations to estimate the trust score, bringing in a significant increase in detection fault tolerance. Finally, we extensively evaluate RECESS on typical model architectures and four datasets under various settings including white/black-box, cross-silo/device FL, etc. Experimental results show the superiority of RECESS in terms of reducing accuracy loss caused by the latest model poisoning attacks over five classic and two state-of-the-art defenses. Haonan Yan, Wenjing Zhang 0002, Qian Chen 0032, Wenhai Sun, Hui Li 0006, Xiaodong Lin 0001 |
NeurIPS | 2 |
| 2023 | PPT: A privacy-preserving global model training protocol for federated learning in P2P networks
Qian Chen 0032, Zilong Wang 0001, Wenjing Zhang 0002, Xiaodong Lin 0001 |
Comput. Secur. | 3 |
| 2022 | Heterogeneous Computation and Resource Allocation for Wireless Powered Federated Edge Learning SystemsabstractFederated learning (FL) is a popular edge learning approach that utilizes local data and computing resources of network edge devices to train machine learning (ML) models while preserving users’ privacy. Nevertheless, performing efficient learning tasks on the devices and achieving longer battery life are primary challenges faced by federated learning. In this paper, we are the first to study the application of heterogeneous computing (HC) and wireless power transfer (WPT) to federated learning to address these challenges. Especially, we propose a heterogeneous computation and resource allocation framework based on a heterogeneous mobile architecture to achieve effective implementation of FL. To minimize the energy consumption of smart devices and maximize their harvesting energy simultaneously, we formulate an optimization problem featuring multidimensional control, which jointly considers time splitting for WPT, dataset size allocation, transmit power allocation and subcarrier assignment during communications, and processor frequency of processing units (central processing unit (CPU) and graphics processing unit (GPU)). However, the major obstacle is how to design a proper algorithm to solve this optimization problem efficiently. For this purpose, we decouple the optimization variables so as to achieve high efficiency in deriving its solution. Particularly, we first compute the optimal processor frequency and dataset size allocation via employing the Lagrangian dual method, followed by finding the closed-form solution to the optimal time splitting allocation, and finally attain the optimal subcarrier assignment as well as transmit power for transmissions through an iteration algorithm. To evaluate the performance of our proposed scheme, we set up four baseline schemes as comparison, and simulation results show that the proposed scheme converges quite fast and better enhance the energy efficiency of the wireless powered FL system compared with the baseline schemes. Jie Feng 0004, Wenjing Zhang 0002, Qingqi Pei, Jinsong Wu 0001, Xiaodong Lin 0001 |
IEEE Trans. Commun. | 2 |
| 2022 | Privacy-Preserving Aggregate Mobility Data Release: An Information-Theoretic Deep Reinforcement Learning ApproachabstractIt is crucial to protect users’ location traces against inference attacks on aggregate mobility data collected from multiple users in various real-world applications. Most of the existing works on aggregate mobility data are focusing on inference attacks rather than designing privacy-preserving release mechanisms, and a few differential private release mechanisms suffer from poor utility-privacy tradeoffs. In this paper, we propose optimal centralized privacy-preserving aggregate mobility data release mechanisms (PAMDRMs) that minimize the leakage from an information-theoretic perspective by releasing perturbed versions of the raw aggregate location. Specifically, we use mutual information to measure user-level and aggregate-level privacy leakage separately, and formulate leakage minimization problems under utility constraints. As directly solving the optimization problems incur exponential complexity w.r.t. users’ trace length, we transform them into belief state Markov Decision Processes (MDPs), with a focus on the MDP formulation for the user-level privacy problem. We build reinforcement learning (RL) models and leverage the efficient Asynchronous Advantage Actor-Critic RL algorithm to derive the solutions to the MDPs as our optimal PAMDRMs. We compare them with two state-of-the-art privacy protection mechanisms PDPR (context-aware local design) and DMLM (context-free centralized design) in terms of mutual information leakage and adversary’s attack success (evaluated by her expected estimation error and Jensen-Shannon Divergence-based error). Extensive experimental results on both synthetic and real-world datasets demonstrate that the user-level PAMDRM performs the best on both measures thanks to its context-aware property and centralized design. Even though the aggregate-level PAMDRM achieves better privacy-utility tradeoff than the other two, it does not always perform better than them on adversarial success, highlighting the necessity of considering privacy measures from different perspectives to avoid overestimating the level of privacy offered to users. Lastly, we discuss an alternative, fully data-driven approach to derive the optimal PAMDRM by leveraging adversarial training on limited data samples. Wenjing Zhang 0002, Bo Jiang 0015, Ming Li 0003, Xiaodong Lin 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | Aggregation-based location privacy: An information theoretic approach
Wenjing Zhang 0002, Bo Jiang 0015, Ming Li 0003, Ravi Tandon, Qiao Liu 0002, Hui Li 0006 |
Comput. Secur. | 1 |
| 2019 | Online Location Trace Privacy: An Information Theoretic ApproachabstractWe consider the problem of protecting individual user's location privacy at the trace-level and study the privacy-utility trade-off, which has key applications in privacy-preserving location-based service. Existing works on Location Privacy Protection Mechanisms (LPPMs) have mainly focused on protecting single location, without taking into account the temporal correlations among locations within the trace, which can lead to higher privacy leakage when considering the whole trace. However, to date, there lacks a formal framework to quantify the trace-level location privacy leakage, and a practical mechanism to release location traces in an optimal and online manner. In this paper, we endeavor to solve this problem using an information-theoretic approach. We first propose a location trace privacy metric based on the mutual information between the original and released trace in an offline setting, and formulate the optimal location trace release problem that minimizes trace-level privacy leakage given a utility constraint. We also propose a privacy metric to capture trace-level privacy leakage in an online setting. As directly computing these metrics incur exponential complexity w.r.t. the trace length, we obtain upper and lower bounds on the trace-level privacy leakage by exploiting the Markov structure of the temporal location correlations, which are efficiently computable. The proposed upper bounds enable us to derive efficient online solutions (i.e., LPPMs) by modifying Blahut-Arimoto algorithm in rate-distortion theory. Then we validate the proposed upper and lower bounds and the actual leakage of our LPPM through extensive experiments over both synthetic and real-world location data sets. Our results show the superiority of our LPPM over existing LPPMs in terms of trace-level privacy-utility tradeoff, which is more conspicuous when the location trace is more correlated. Wenjing Zhang 0002, Ming Li 0003, Ravi Tandon, Hui Li 0006 |
IEEE Trans. Inf. Forensics Secur. | 1 |