EDBT 2026 Demo / reviewers in the wild / expert
Shukan Liu
dblp:284/9319
· DBLP profile ↗
7ranked-venue papers
1as first author
7since 2021 · last 2025
0000-0002-7087-1069ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 3 · 3 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SPMC: Self-Purifying Federated Backdoor Defense via Margin ContributionabstractFederated Learning (FL) enables collaborative training with privacy preservation but is vulnerable to backdoor attacks, where malicious clients degrade model performance on targeted inputs. These attacks exploit FL decentralized nature, while existing defenses, based on isolated behaviors and fixed rules, can be bypassed by adaptive attackers. To address these limitations, we propose **SPMC**, a marginal collaboration defense mechanism that leverages intrinsic consistency across clients to estimate inter-client marginal contributions. This allows the system to dynamically reduce the influence of clients whose behavior deviates from the collaborative norm, thus maintaining robustness even as the number of attackers changes. In addition to overcoming proxy-dependent purification's weaknesses, we introduce a self-purification process that locally adjusts suspicious gradients. By aligning them with margin-based model updates, we mitigate the effect of local poisoning. Together, these two modules significantly improve the adaptability and resilience of FL systems, both at the client and server levels. Experimental results on a variety of classification benchmarks demonstrate that SPMC achieves strong defense performance against sophisticated backdoor attacks without sacrificing accuracy on benign tasks. The code is posted at: https://github.com/WenddHe0119/SPMC. Wenwen He, Wenke Huang 0003, Bin Yang 0026, Shukan Liu, Mang Ye |
ICML | 4 |
| 2025 | A Distributed Cooperative Dynamic Target Search Method for Multi-UAV Systems in Complex Adversarial EnvironmentsabstractUnmanned Aerial Vehicle (UAV) search has been widely applied in critical mission scenarios such as battlefield reconnaissance and disaster response. Due to uncertainties caused by target maneuverability and environmental threats, the development of multi-UAV distributed cooperative search methods to overcome the limitations of single-UAV perception has become imperative. This study addresses the decision optimization problem for multi-UAV cooperative dynamic target search in complex adversarial environments and proposes a systematic decision optimization framework. Firstly, an environmental perception system model is constructed by integrating a multiple distribution hypothesis target motion prediction model with a multi-dimensional search map model, which incorporates target existence probability, environmental uncertainty, and pheromone-inspired coordination signals, and achieves situational updates through dynamic Bayesian inference. Secondly, a distributed model predictive control (DMPC) architecture with motion encoding mechanisms and a lightweight communication protocol is designed to effectively alleviate communication resource dependence. Furthermore, Genetic Programming (GP) algorithm is combined with DMPC to autonomously generate cooperative search strategies that satisfy multiple conditional constraints. Simulation results demonstrate that the proposed method significantly outperforms traditional search methods in terms of dynamic target search timeliness and adaptability to complex environments, particularly exhibiting stronger robustness in adversarial scenarios. Yiyuan Li, Bing Fu, Shukan Liu, Lingjun Hao, Zhonghong Wu |
IEEE Internet Things J. | 4 |
| 2025 | Prism: An efficient file mapping mechanism across multiple namespaces in mobile systems
Xianzhang Chen, Xijie Zhu, Lin Chen 0031, Qiao Sun 0007, Shukan Liu |
J. Syst. Archit. | 6 |
| 2025 | FLGuardian: Defending Against Model Poisoning Attacks via Fine-Grained Detection in Federated LearningabstractFederated Learning (FL) is a collaborative machine learning paradigm allowing participants to train a global model collaboratively without sharing training data. The distributed nature makes FL vulnerable to the untargeted or backdoor model poisoning attacks (MPAs). Hence, lots of defense methods are proposed to secure FL. However, existing defenses are ineffective in defending against the emerging stealthy layer-space MPA, since the defenses either focus on the model space or ignore the disparities between the layers. In this paper, we propose a novel layer-space defense method called FLGuardian that can protect the global model from the state-of-the-art MPAs. FLGuardian first employs a new layer-wise detection to find out the benign clients for each layer through pairwise cosine distances and pairwise Euclidean distances combined with a clustering algorithm. Then, FLGuardian assigns a trust score for each client according to the detection results of all the layers, where a deeper layer in the model brings a higher weight in the scoring. Finally, we select several clients with the highest scores for updating the global model. Experimental results show that FLGuardian excels nine typical defense methods against seven state-of-the-art MPAs in most cases. Particularly, under LPattack, the emerging layer-space backdoor MPA, FLGuardian secures Backdoor Success Rate (BSR) below 3% while other defenses have over 93% BSRs on CIFAR-10. Moreover, FLGuardian remains robust against adaptive attacks tailored to FLGuardian. Xingjie Zhou, Xianzhang Chen, Shukan Liu, Xuehong Fan, Qiao Sun 0007, Lin Chen 0031, Meikang Qiu, Tao Xiang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | FLOW: A Robust Federated Learning Framework to Defend Against Model Poisoning Attacks in IoTabstractFederated Learning (FL) is a promising distributed learning approach to enable intelligent Internet of Things (IoT) applications. However, FL is vulnerable to model poisoning attacks in which malicious clients abate the accuracy of the global model by committing crafted local model updates to the server. Existing defense methods either rely on a validation dataset or simply remove the detected malicious clients from the subsequent training process to handle attacks from a large number of malicious clients. Thus, the performance of existing methods deteriorates drastically in many scenarios where the data distributions of clients are unpredictable. To address these deficiencies, we propose a framework called FL overwatch (FLOW) to efficiently defend against model poisoning attacks taking advantages of the local model updates in current and historical training iterations. On one hand, FLOW detects malicious clients in each iteration by measuring the cosine distances between the local model updates of clients, such that malicious updates are eliminated from the current aggregation. On the other hand, FLOW gracefully punishes the previously identified malicious clients rather than removes them from the whole training process. As a result, FLOW can embrace a richer reliable set of local model updates than existing methods in aggregation. Extensive experiments on widely-used benchmark datasets show that FLOW can achieve higher success defending ratio and higher accuracy of global models over existing Byzantine-robust FL methods under typical untargeted attacks and targeted attacks. Furthermore, FLOW also shows significant effectiveness in defending against adaptive attacks tailored to FLOW. Shukan Liu, Qiao Sun 0007, Lin Chen 0031, Xianfeng Zhang |
IEEE Internet Things J. | 1 |
| 2023 | Data-Quality-Driven Federated Learning for Optimizing Communication CostsabstractFederated Learning (FL) is a distributed machine learning approach that allows mobile devices to train a global model cooperatively, without uploading privacy-sensitive data to the cloud. To improve the accuracy of the model, the model needs to be updated frequently. However, FL system under mobile edge-end has to adapt to limited communication bandwidth. At the same time, the property of statistical heterogeneity in FL means that we cannot blindly reduce the number of clients. We found that the accuracy of the global model depends greatly on the clients whose data is more similar and balanced. In this paper, we first define the "data quality" of clients to appraise the impact of data on a client to the accuracy of the global model. Then, based on the data quality, we design a client selection to optimize the communication costs of FL by screening out the clients that determine the accuracy of the global model. To the authors’ best knowledge, this is the first paper to save the costs of FL by assessing data quality of clients. Experimental results show that on imbalanced SVHN, the communication cost of our algorithm is reduced by 56% compared with vanilla FL. Compared with vanilla FL, requires all clients to participate in training, our algorithm shows -1.58% and +3.19% and -0.01% of average accuracy on the imbalanced CIFAR10, imbalanced FMNIST and imbalanced SVHN datasets, respectively. In other words, our algorithm can reduce communication overhead with negligible degradation of accuracy. Xuehong Fan, Nanzhong Wu, Shukan Liu, Xianzhang Chen, Duo Liu 0002, Yujuan Tan, Ao Ren |
ICPADS | 3 |
| 2023 | FSR: A host-storage collaborative mechanism for data path optimization of NDP operations
Qiao Sun 0007, Xianzhang Chen, Jiapin Wang, Shukan Liu |
J. Syst. Archit. | 5 |