EDBT 2026 Demo / reviewers in the wild / expert
Kok-Seng Wong
dblp:29/11439
· DBLP profile ↗
25ranked-venue papers
8as first author
17since 2021 · last 2026
0000-0002-2029-7644ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 10 · 1 first-author · 10 since 2021Systems, architecture and hardware · 6 · 3 first-author · 3 since 2021Computer networks · 3 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 2 since 2021Security and privacy · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Clean-Label Physical Backdoor Attacks with Data DistillationabstractDeep Neural Networks (DNNs) are shown to be vulnerable to backdoor poisoning attacks, with most research focusing on digital triggers that consist of artificial patterns added to test-time inputs to induce targeted misclassification. Physical triggers, which are natural objects embedded in real-world scenes, offer a promising alternative for attackers as they can activate backdoors in real-time without digital manipulation. However, existing physical backdoor attacks are dirty-label, meaning that attackers must change the labels of poisoned inputs to the target label. The inconsistency between image content and label exposes the attack to human inspection, reducing its stealthiness in real-world settings. To address this limitation, we introduce Clean-Label Physical Backdoor Attack (CLPBA), a new paradigm of physical backdoor attack that does not require label manipulation and trigger injection at the training stage. Instead, the attacker injects imperceptible perturbations into a small number of target class samples to backdoor a model. By framing the attack as a Dataset Distillation problem, we develop three CLPBA variants, namely Parameter Matching, Gradient Matching, and Feature Matching, that craft effective poisons under both linear probing and full-finetuning training settings. In hard scenarios that require backdoor generalizability in the physical world, CLPBA is shown to even surpass Dirty-label attack baselines. We demonstrate the effectiveness of CLPBA via extensive experiments on two collected physical backdoor datasets for facial recognition and animal classification. Thinh Dao, Khoa D. Doan, Kok-Seng Wong |
AAAI | 3 |
| 2026 | SC-GIR: Goal-Oriented Semantic Communication via Invariant Representation Learning for Image TransmissionabstractGoal-oriented semantic communication (SC) aims to revolutionize communication systems by transmitting only task-essential information. However, current approaches face challenges such as joint training at transceivers, leading to redundant data exchange and reliance on labeled datasets, which limits their task-agnostic utility. To address these challenges, we propose a novel framework called Goal-oriented Invariant Representation-based SC (SC-GIR) for image transmission. Our framework leverages self-supervised learning to extract an invariant representation that encapsulates crucial information from the source data, independent of the specific downstream task. This compressed representation facilitates efficient communication while retaining key features for successful downstream task execution. Focusing on machine-to-machine tasks, we utilize covariance-based contrastive learning techniques to obtain a latent representation that is both meaningful and semantically dense. To evaluate the effectiveness of the proposed scheme on downstream tasks, we apply it to various image datasets for lossy compression. The compressed representations are then used in a goal-oriented AI task. Extensive experiments on several datasets demonstrate that SC-GIR outperforms baseline schemes by nearly 10%,, and achieves over 85% classification accuracy for compressed data under different SNR conditions. These results underscore the effectiveness of the proposed framework in learning compact and informative latent representations. Senura Hansaja Wanasekara, Van-Dinh Nguyen, Kok-Seng Wong, Minh-Duong Nguyen, Symeon Chatzinotas, Octavia A. Dobre |
IEEE Trans. Mob. Comput. | 3 |
| 2026 | An Empirical Study of Federated Learning on IoT-Edge Devices: Resource Allocation and HeterogeneityabstractNowadays, billions of phones, internet-of-things (IoT), and edge devices around the world generate data continuously, enabling many machine-learning (ML)-based products and applications. However, due to increasing privacy concerns and regulations, these data tend to reside on devices (clients) instead of being centralized for performing traditional ML model training. Federated learning (FL) is a distributed approach in which a single server and multiple clients collaboratively build an ML model without moving data away from clients. Whereas existing studies on FL have their own experimental evaluations, most experiments were conducted using a simulation setting or a small-scale testbed. This might limit the understanding of FL implementation in realistic environments. In this empirical study, we systematically conduct extensive experiments on a large network of IoT and edge devices (called IoT-Edge devices) to present FL real-world characteristics, including learning performance and operation (computation and communication) costs. Moreover, we mainly concentrate on heterogeneous scenarios, which is the most challenging issue of FL. By investigating the feasibility of on-device implementation, our study provides valuable insights for researchers and practitioners, promoting the practicality of FL and assisting in improving the current design of real FL systems. Kok-Seng Wong, Manh Nguyen-Duc, Long Ho, Cuong Do 0001, Danh Le Phuoc |
IEEE Trans. Neural Networks Learn. Syst. | 1 |
| 2025 | Wicked Oddities: Selectively Poisoning for Effective Clean-Label Backdoor AttacksabstractDeep neural networks are vulnerable to backdoor attacks, a type of adversarial attack that poisons the training data to manipulate the behavior of models trained on such data.
Clean-label backdoor is a more stealthy form of backdoor attacks that can perform the attack without changing the labels of poisoned data.
Early works on clean-label attacks added triggers to a random subset of the training set, ignoring the fact that samples contribute unequally to the attack's success. This results in high poisoning rates and low attack success rates.
To alleviate the problem, several supervised learning-based sample selection strategies have been proposed.
However, these methods assume access to the entire labeled training set and require training, which is expensive and may not always be practical.
This work studies a new and more practical (but also more challenging) threat model where the attacker only provides data for the target class (e.g., in face recognition systems) and has no knowledge of the victim model or any other classes in the training set.
We study different strategies for selectively poisoning a small set of training samples in the target class to boost the attack success rate in this setting.
Our threat model poses a serious threat in training machine learning models with third-party datasets, since the attack can be performed effectively with limited information. Experiments on benchmark datasets illustrate the effectiveness of our strategies in improving clean-label backdoor attacks. Nguyen Hung-Quang, Ngoc-Hieu Nguyen, The-Anh Ta, Thanh Nguyen-Tang, Kok-Seng Wong, Hoang Thanh-Tung, Khoa D. Doan |
ICLR | 5 |
| 2025 | Towards good practice for convolution and attention with PANs in federated medical image classification
Nursultan Makhanov, Nhan Duc Ho, Kok-Seng Wong, Nguyen Anh Tu |
J. Supercomput. | 3 |
| 2024 | Efficiently Assemble Normalization Layers and Regularization for Federated Domain GeneralizationabstractDomain shift is a formidable issue in Machine Learning that causes a model to suffer from performance degradation when tested on unseen domains. Federated Domain Gener-alization (FedDG) attempts to train a global model using collaborative clients in a privacy-preserving manner that can generalize well to unseen clients possibly with domain shift. However, most existing FedDG methods either cause additional privacy risks of data leakage or induce signifi-cant costs in client communication and computation, which are major concerns in the Federated Learning paradigm. To circumvent these challenges, here we introduce a novel architectural method for FedDG, namely gPerXAN11https://github.com/lhkhiem28/gPerXAN, which relies on a normalization scheme working with a guiding regularizer: In particular, we carefully design Personalized eXplicitly Assembled Normalization to enforce client mod-els selectively filtering domain-specific features that are bi-ased towards local data while retaining discrimination of those features. Then, we incorporate a simple yet effec-tive regularizer to guide these models in directly capturing domain-invariant representations that the global model's classifier can leverage. Extensive experimental results on two benchmark datasets, i.e., PACS and Office-Home, and a real-world medical dataset, Camelyon17, indicate that our proposed method outperforms other existing methods in ad-dressing this particular problem. Long Ho, Cuong Do 0001, Danh Le Phuoc, Kok-Seng Wong |
CVPR | 5 |
| 2024 | HPE-Li: WiFi-Enabled Lightweight Dual Selective Kernel Convolution for Human Pose Estimation
Toan D. Gian, Tien Dac Lai, Thien Van Luong, Kok-Seng Wong, Van-Dinh Nguyen |
ECCV (31) | 4 |
| 2024 | Understanding the Robustness of Randomized Feature Defense Against Query-Based Adversarial AttacksabstractRecent works have shown that deep neural networks are vulnerable to adversarial examples that find samples close to the original image but can make the model misclassify. Even with access only to the model's output, an attacker can employ black-box attacks to generate such adversarial examples. In this work, we propose a simple and lightweight defense against black-box attacks by adding random noise to hidden features at intermediate layers of the model at inference time. Our theoretical analysis confirms that this method effectively enhances the model's resilience against both score-based and decision-based black-box attacks. Importantly, our defense does not necessitate adversarial training and has minimal impact on accuracy, rendering it applicable to any pre-trained model. Our analysis also reveals the significance of selectively adding noise to different parts of the model based on the gradient of the adversarial objective function, which can be varied during the attack. We demonstrate the robustness of our defense against multiple black-box attacks through extensive empirical experiments involving diverse models with various architectures. Nguyen Hung-Quang, Yingjie Lao, Kok-Seng Wong, Khoa D. Doan |
ICLR | 4 |
| 2024 | Towards Efficient Communication and Secure Federated Recommendation System via Low-rank TrainingabstractFederated Recommendation (FedRec) systems have emerged as a solution to safeguard users' data in response to growing regulatory concerns. However, one of the major challenges in these systems lies in the communication costs that arise from the need to transmit neural network models between user devices and a central server. Prior approaches to these challenges often lead to issues such as computational overheads, model specificity constraints, and compatibility issues with secure aggregation protocols. In response, we propose a novel framework, called Correlated Low-rank Structure (CoLR), which leverages the concept of adjusting lightweight trainable parameters while keeping most parameters frozen. Our approach substantially reduces communication overheads without introducing additional computational burdens. Critically, our framework remains fully compatible with secure aggregation protocols, including the robust use of Homomorphic Encryption. The approach resulted in a reduction of up to 93.75% in payload size, with only an approximate 8% decrease in recommendation performance across datasets. Code for reproducing our experiments can be found at https://github.com/NNHieu/CoLR-FedRec. Ngoc-Hieu Nguyen, Vu Tien Hoang, Dung D. Le, Kok-Seng Wong |
WWW | 6 |
| 2024 | Backdoor attacks and defenses in federated learning: Survey, challenges and future research directions
Thuy Dung Nguyen, Phi-Le Nguyen, Hieu H. Pham 0001, Khoa D. Doan, Kok-Seng Wong |
Eng. Appl. Artif. Intell. | 6 |
| 2024 | FedDCT: Federated Learning of Large Convolutional Neural Networks on Resource-Constrained Devices Using Divide and Collaborative TrainingabstractIn Federated Learning (FL), the size of local models matters. On the one hand, it is logical to use large-capacity neural networks in pursuit of high performance. On the other hand, deep convolutional neural networks (CNNs) are exceedingly parameter-hungry, which makes memory a significant bottleneck when training large-scale CNNs on hardware-constrained devices such as smartphones or wearables sensors. Current state-of-the-art (SOTA) FL approaches either only test their convergence properties on tiny CNNs with inferior accuracy or assume clients have the adequate processing power to train large models, which remains a formidable obstacle in actual practice. To overcome these issues, we introduce FedDCT, a novel distributed learning paradigm that enables the usage of large, high-performance CNNs on resource-limited edge devices. As opposed to traditional FL approaches, which require each client to train the full-size neural network independently during each training round, the proposed FedDCT allows a cluster of several clients to collaboratively train a large deep learning model by dividing it into an ensemble of several small sub-models and train them on multiple devices in parallel while maintaining privacy. In this collaborative training process, clients from the same cluster can also learn from each other, further improving their ensemble performance. In the aggregation stage, the server takes a weighted average of all the ensemble models trained by all the clusters. FedDCT reduces the memory requirements and allows low-end devices to participate in FL. We empirically conduct extensive experiments on standardized datasets, including CIFAR-10, CIFAR-100, and two real-world medical datasets HAM10000 and VAIPE. Experimental results show that FedDCT outperforms a set of current SOTA FL methods with interesting convergence behaviors. Furthermore, compared to other existing approaches, FedDCT achieves higher accuracy and substantially reduces the number of communication rounds (with 4-8 times fewer memory requirements) to achieve the desired accuracy on the testing dataset without incurring any extra training cost on the server side. Hieu H. Pham 0001, Kok-Seng Wong, Phi-Le Nguyen, Truong Thao Nguyen, Minh N. Do |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2023 | Empirical Study of Federated Unlearning: Efficiency and Effectiveness
Thai-Hung Nguyen, Hong-Phuc Vu, Thuy Dung Nguyen, Tuan Minh Nguyen, Khoa D. Doan, Kok-Seng Wong |
ACML | 6 |
| 2023 | FedGrad: Mitigating Backdoor Attacks in Federated Learning Through Local Ultimate Gradients InspectionabstractFederated learning (FL) enables multiple clients to train a model without compromising sensitive data. The decentralized nature of FL makes it susceptible to adversarial attacks, especially backdoor insertion during training. Recently, the edge-case backdoor attack employing the tail of the data distribution has been proposed as a powerful one, raising questions about the shortfall in current defenses' robustness guarantees. Specifically, most existing defenses cannot eliminate edge-case backdoor attacks or suffer from a trade-off between backdoor-defending effectiveness and overall performance on the primary task. To tackle this challenge, we propose FedGrad, a novel backdoor-resistant defense for FL that is resistant to cutting-edge backdoor attacks, including the edge-case attack, and performs effectively under heterogeneous client data and a large number of compromised clients. FedGrad is designed as a two-layer filtering mechanism that thoroughly analyzes the ultimate layer's gradient to identify suspicious local updates and remove them from the aggregation process. We evaluate FedGrad under different attack scenarios and show that it significantly outperforms state-of-the-art defense mechanisms. Notably, FedGrad can almost 100% correctly detect the malicious participants, thus providing a significant reduction in the backdoor effect (e.g., backdoor accuracy is less than 8%) while not reducing main accuracy on the primary task. Thuy Dung Nguyen, Anh Duy Nguyen, Thanh-Hung Nguyen, Kok-Seng Wong, Hieu H. Pham 0001, Truong Thao Nguyen, Phi-Le Nguyen |
IJCNN | 4 |
| 2023 | IBA: Towards Irreversible Backdoor Attacks in Federated LearningabstractFederated learning (FL) is a distributed learning approach that enables machine learning models to be trained on decentralized data without compromising end devices' personal, potentially sensitive data. However, the distributed nature and uninvestigated data intuitively introduce new security vulnerabilities, including backdoor attacks. In this scenario, an adversary implants backdoor functionality into the global model during training, which can be activated to cause the desired misbehaviors for any input with a specific adversarial pattern. Despite having remarkable success in triggering and distorting model behavior, prior backdoor attacks in FL often hold impractical assumptions, limited imperceptibility, and durability. Specifically, the adversary needs to control a sufficiently large fraction of clients or know the data distribution of other honest clients. In many cases, the trigger inserted is often visually apparent, and the backdoor effect is quickly diluted if the adversary is removed from the training process. To address these limitations, we propose a novel backdoor attack framework in FL, the Irreversible Backdoor Attack (IBA), that jointly learns the optimal and visually stealthy trigger and then gradually implants the backdoor into a global model. This approach allows the adversary to execute a backdoor attack that can evade both human and machine inspections. Additionally, we enhance the efficiency and durability of the proposed attack by selectively poisoning the model's parameters that are least likely updated by the main task's learning process and constraining the poisoned model update to the vicinity of the global model. Finally, we evaluate the proposed attack framework on several benchmark datasets, including MNIST, CIFAR-10, and Tiny ImageNet, and achieved high success rates while simultaneously bypassing existing backdoor defenses and achieving a more durable backdoor effect compared to other backdoor attacks. Overall, IBA offers a more effective, stealthy, and durable approach to backdoor attacks in FL. The code associated with this paper is available on [GitHub](https://github.com/sail-research/iba). Thuy Dung Nguyen, Anh Tuan Tran 0001, Khoa D. Doan, Kok-Seng Wong |
NeurIPS | 5 |
| 2022 | Few-Shot Learning based on Residual Neural Networks for X-ray Image ClassificationabstractCurrently, deep learning is widely used in the field of medicine, which in turn includes radiology. This paper considers the problem of the classification of X-ray images and the lack of images of specific classes. The classes included COVID-19 and Normal X-ray scans. To solve the problems, we propose few-shot learning that is based on different Residual Convolutional Neural Network models with different complexities. The method is designed for the datasets that have small amount of samples of a specific class and a larger amount of instances of another class. The utilization of few-shot learning can solve the issues of the balance of X-ray datasets. The Residual Convolutional Neural Network models we used are as follows: ResNet-50, ResNet-101, and ResNet-152. The architectures had been used to extract the features from the images that were used later. The latter model has the highest complexity, while the former has the lowest complexity, respectively. The obtained results include the highest accuracy of 97.7% for 10 shots of COVID-19 positive X-ray images. The accuracy was achieved using ResNet-101 model. The highest result for ResNet-152 model was 95.6 %. However, on average, the model achieved the highest accuracy. ResNet-50 model provided the least accurate results, however, it is less complex which provides faster performance. One can also notice that with the higher number of COVID-19 positive shots that were used for training, the accuracy also gets higher. To provide transparency to our solution, we furthermore created t-distributed stochastic neighbor embedding visualization. This showed us that the system could separate the two classes into two distinct clusters. Overall, the results imply the efficiency of the solution that was proposed in the study. Rakhat Abdrakhmanov, Dmitriy Viderman, Kok-Seng Wong |
SMC | 3 |
| 2021 | Toward efficient and intelligent video analytics with visual privacy protection for large-scale surveillance
Nguyen Anh Tu, Thien Huynh-The, Kok-Seng Wong, M. Fatih Demirci, Young-Koo Lee |
J. Supercomput. | 3 |
| 2021 | Toward forecasting future day air pollutant index in Malaysia
Kok-Seng Wong, Yee Jian Chew, Shih Yin Ooi, Ying-Han Pang |
J. Supercomput. | 1 |
| 2018 | Toward a fair indictment for sealed-bid auction with self-enforcing privacy
Kok-Seng Wong |
J. Supercomput. | 1 |
| 2018 | Service Migration in Mobile Edge Computing
Shangguang Wang, Wu Chou, Kok-Seng Wong, Ao Zhou 0001, Victor C. M. Leung |
Wirel. Commun. Mob. Comput. | 3 |
| 2017 | Network failure-aware redundant virtual machine placement in a cloud data centerabstractSummary Cloud has become a very popular infrastructure for many smart city applications. A growing number of smart city applications from all over the world are deployed on the clouds. However, node failure events from the cloud data center have negative impact on the performance of smart city applications. Survivable virtual machine placement has been proposed by the researchers to enhance the service reliability. Because of the ignorance of switch failure, current survivable virtual machine placement approaches cannot achieve the best effect. In this paper, we study to enhance the service reliability by designing a novel network failure–aware redundant virtual machine placement approach in a cloud data center. Firstly, we formulate the network failure–aware redundant virtual machine placement problem as an integer nonlinear programming problem and prove that the problem is NP‐hard. Secondly, we propose a heuristic algorithm to solve the problem. Finally, extensive simulation results show the effectiveness of our algorithm. Ao Zhou 0001, Shangguang Wang, Ching-Hsien Hsu, Kok-Seng Wong |
Concurr. Comput. Pract. Exp. | 5 |
| 2016 | An enhanced user authentication solution for mobile payment systems using wearablesabstractAbstract As technology continues to evolve, banks and other enterprises are restructuring their businesses to provide services to customers anywhere and anytime. However, it is challenging to move from conventional payment systems toward digital wallets across a range of payment services. Mobile devices are easily lost or stolen, so the rapid adoption of mobile devices for payment systems requires protection against unauthorized access to private applications and data. When mobile devices communicate with merchant point‐of‐sale systems, there is a risk of data leakage because third party applications in point‐of‐sale systems might access private data stored on the device without the user's knowledge or permission. We thus propose the use of wearable devices to store partial private data for the user and to participate in the user authentication. In this paper, we design a practical user authentication solution for mobile payment systems, and the main idea is to split the user's private data, such as credit card and banking information, and then store them across two separate devices (e.g., a smartphone and a wearable device). Our solution can improve the security of existing mobile payment systems that utilize user biometrics as an authentication factor, such as Apple Pay and Samsung Pay. Copyright © 2016 John Wiley & Sons, Ltd. Kok-Seng Wong |
Secur. Commun. Networks | 1 |
| 2015 | Towards a respondent-preferred k i -anonymity modelabstractRecently, privacy concerns about data collection have received an increasing amount of attention. In data collection process, a data collector (an agency) assumed that all respondents would be comfortable with submitting their data if the published data was anonymous. We believe that this assumption is not realistic because the increase in privacy concerns causes some respondents to refuse participation or to submit inaccurate data to such agencies. If respondents submit inaccurate data, then the usefulness of the results from analysis of the collected data cannot be guaranteed. Furthermore, we note that the level of anonymity (i.e., k-anonymity) guaranteed by an agency cannot be verified by respondents since they generally do not have access to all of the data that is released. Therefore, we introduce the notion of k i -anonymity, where k i . is the level of anonymity preferred by each respondent i. Instead of placing full trust in an agency, our solution increases respondent confidence by allowing each to decide the preferred level of protection. As such, our protocol ensures that respondents achieve their preferred k i -anonymity during data collection and guarantees that the collected records are genuine and useful for data analysis. Kok-Seng Wong |
Frontiers Inf. Technol. Electron. Eng. | 1 |
| 2014 | On private Hamming distance computation
Kok-Seng Wong |
J. Supercomput. | 1 |
| 2012 | Towards Biometric-based Authentication for Cloud Computing
Kok-Seng Wong |
CLOSER | 1 |
| 2012 | Privacy-preserving frequent itemsets mining via secure collaborative frameworkabstractABSTRACT Knowledge‐discovering or pattern‐discovering process, such as data mining, is an important technique to discover hidden but useful information from a large volume of data. Under distributed environment, data mining task has become a challenging task due to data protection and privacy concerns. The secure multi‐party computation (SMC) approach has been widely used to solve privacy‐preserving data mining problems. However, generic SMC solutions are not practical from an efficiency point of view, especially when the number of parties and the size of the data are large. In view of these problems, we utilize a secure collaborative framework to facilitate the computation protocol for SMC. In this paper, we particularly consider the problem of privacy‐preserving frequent itemsets mining under distributed environment. Our solution reduces the risk for central data mining and improves the efficiency of the current generic SMC solutions. Furthermore, our solution is more reliable and flexible regardless of the number of parties involved. Copyright © 2011 John Wiley & Sons, Ltd. Kok-Seng Wong |
Secur. Commun. Networks | 1 |