Jiaxuan Fu

dblp:295/7546 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0002-7020-2156ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 7 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 PriFFT: Privacy-Preserving Federated Fine-Tuning of Large Language Models via Hybrid Secret Sharing
Zhichao You, Xuewen Dong, Ke Cheng 0001, Xutong Mu, Jiaxuan Fu, Shiyang Ma, Qiang Qu 0001, Yulong Shen 0001
IEEE Trans. Dependable Secur. Comput.5
2025 Mosformer: Maliciously Secure Three-Party Inference Framework for Large Transformers
abstract
Transformer-based models like BERT and GPT have achieved state-of-the-art performance across a wide range of AI tasks but raise serious privacy concerns when deployed as cloud inference services. To address this, secure multi-party computation (MPC) is commonly employed, encrypting both user inputs and model parameters to enable inference without revealing any private information. However, existing MPC-based secure transformer inference protocols are predominantly designed under the semi-honest security model. Extending these protocols to support malicious security remains a significant challenge, primarily due to the substantial overhead introduced by securely evaluating complex non-linear functions required for adversarial resilience. We introduce Mosformer, the first maliciously secure three-party (3PC) inference framework that efficiently supports large transformers such as BERT and GPT. We first design constant-round comparison and lookup table protocols with malicious security, leveraging verifiable distributed point functions (VDPFs). Building on these, we develop a suite of 3PC protocols for efficient and secure evaluation of complex non-linear functions in transformers. Together with optimized modulus conversion, our approach substantially reduces the overhead of secure transformer inference while preserving model accuracy. Experimental results on the vanilla transformer block show that Mosformer achieves up to a 5.3× speedup and a 4.3× reduction in communication over prior maliciously secure protocols. Despite offering stronger security guarantees, Mosformer achieves comparable or even superior online performance to state-of-the-art semi-honest 2PC and 3PC frameworks, including BOLT (Oakland 2024), BumbleBee (NDSS 2025), SHAFT (NDSS 2025), and Ditto (ICML 2024), on full-scale models such as BERT and GPT-2.
Ke Cheng 0001, Yuheng Xia, Anxiao Song, Jiaxuan Fu, Wenjie Qu 0001, Yulong Shen 0001, Jiaheng Zhang
CCS4
2025 Dynamic Pattern Matching on Encrypted Data With Forward and Backward Security
abstract
Pattern matching is widely used in applications such as genomic data query analysis, network intrusion detection, and deep packet inspection (DPI). Performing pattern matching on plaintext data is straightforward, but the need to protect the security of analyzed data and analyzed patterns can significantly complicate the process. Due to the privacy security issues of data and patterns, researchers begin to explore pattern matching on encrypted data. However, existing solutions are typically built on static pattern matching methods, lacking dynamism, namely, the inability to perform addition or deletion operations on the analyzed data. This lack of flexibility might hinder the adaptability and effectiveness of pattern matching on encrypted data in the real‐world scenarios. In this paper, we design a dynamic pattern matching scheme on encrypted data with forward and backward security, which introduces much‐needed dynamism. Our scheme is able to implement the addition operation and the deletion operation on the encrypted data without affecting the security of the original pattern matching scheme. Specifically, we design secure addition and deletion algorithms based on fragmentation data structures, which are compatible with the static pattern matching scheme. Moreover, we make significant improvements to the key generation algorithm, the encryption algorithm, and the match algorithm of the static scheme to ensure forward and backward security. Theoretical analysis proves that our scheme satisfies forward and backward security while ensuring the nonfalsifiability of encrypted data. The experimental results show that our scheme has a slight increase in time cost compared to the static pattern matching scheme, demonstrating its practicality and effectiveness in dynamic scenarios.
Xiaolu Chu, Ke Cheng 0001, Anxiao Song, Jiaxuan Fu
IET Inf. Secur.4
2025 Private Learning for Vertical Decision Trees: A Secure, Accurate, and Fast Realization
abstract
Private learning for vertical decision trees (PVDT) is an emerging paradigm that allows multiple parties to execute cooperative training and inference of decision trees on vertically partitioned datasets, without revealing either party%'s data or model. The state-of-the-art PVDT schemes employ the secret-sharing-based secure multi-party computation (MPC) to admit low computational cost and low bandwidth. Nevertheless, existing schemes need many communication rounds for computing concrete protocols in PVDT, like the less-than comparison, division, etc. This property is not suited for large-communication-latency networks such as WAN. In this work, we present a two-party PVDT framework, calledSwan, to enable a secure, accurate, and fast realization of vertical decision trees. At the core of Swan, we design a secure and parallel protocol for$N$-input multiplication with one communication round. This forms the cornerstone for a series of secure and communication-efficient computation protocols specifically tailored to less-than comparison and division. Along the way, we use these optimized protocols to refine the training and inference processes of PVDT, achieving a significant reduction in both communication costs and rounds. Experimental results show Swan provides top-notch accuracy, and achieves a$10.2\times$and$2.8\times$improvement in online training and inference latency over WAN compared to prior art.
Anxiao Song, Ke Cheng 0001, Jiaxuan Fu, Shujie Cui, Tao Zhang 0029, Zhao Chang, Yulong Shen 0001
IEEE Trans. Dependable Secur. Comput.3
2024 Private Decision Tree Evaluation with Malicious Security via Function Secret Sharing
Jiaxuan Fu, Ke Cheng 0001, Yuheng Xia, Anxiao Song, Qianxing Li, Yulong Shen 0001
ESORICS (2)1
2024 Securely and Efficiently Outsourcing Neural Network Inference via Parallel MSB Extraction
abstract
Outsourcing neural network (NN) inference services to the cloud gives rise to considerable privacy concerns about the model provider’s proprietary model and the user’s private data. Current cryptography-based secure NN inference schemes are not suited for high-latency networks due to their numerous communication overhead for computing the non-linear components of neural networks. In this paper, we present ParaNN, a secure cloud-based outsourced computation framework that supports lightweight secure neural network inference. At the core of ParaNN, we design a secure and parallel method for extracting the most significant bit (MSB) based on a parallel prefix adder. This forms the cornerstone for a series of secure and communication-efficient computation protocols specifically tailored to non-linear layers like ReLU and Maxpool. Our experiments show that ParaNN achieves a 6.7×-27.4× improvement in online inference time over wide area networks (WAN) compared to the state-of-the-art works.
Ning Xi 0002, Ke Cheng 0001, Jiaxuan Fu, Yulong Shen 0001, Jianfeng Ma 0001
ICASSP4
2024 PPA-DBSCAN: Privacy-Preserving $\rho$ρ-Approximate Density-Based Clustering
abstract
Clustering is widely used for data analysis that partitions a set of data into multiple clusters, where objects in the same cluster have similar properties. Data for clustering analysis often comes from different data sources, which makes it important to maintain data privacy. However, existing privacypreserving clustering schemes either require the support of prior knowledge or are just applicable for small datasets due to impractical costs. To solve this issue, we follow a classical approximate DBSCAN clustering algorithm and adapt it to the privacy-preserving context. Concretely, to construct our secure approximate clustering algorithm, we propose a series of basic secure computation protocols among additively secret-shared values. In addition, we design a crypto-friendly grid partitioning method based on which an efficient and privacy-preserving approximation DBSCAN scheme is derived. Theoretical analysis and experimental results show that our scheme achieves almost the same cluster quality compared to the plain-text exact DBSCAN. Our extensive experiments on different datasets demonstrate that our scheme is accurate and efficient.
Jiaxuan Fu, Ke Cheng 0001, Zhao Chang, Yulong Shen 0001
IEEE Trans. Dependable Secur. Comput.1
2024 FSS-DBSCAN: Outsourced Private Density-Based Clustering via Function Secret Sharing
abstract
Density-based clustering algorithms such as DBSCAN, are highly effective in handling large datasets and identifying clusters of arbitrary shapes, playing a crucial role in data analysis fields like outlier detection and social networks. Outsourcing DBSCAN to the cloud brings substantial benefits but also raises major privacy concerns regarding the private input data of data owners. Existing private DBSCAN methods often face challenges of inefficiency or potential privacy leakage, hindering their practical deployment. To address these challenges, we introduce FSS-DBSCAN, a three-server MPC platform designed for outsourced private density-based clustering using function secret sharing (FSS). This solution guarantees clustering quality equivalent to plaintext algorithms, ensures comprehensive privacy protection, and achieves top-tier efficiency. The high performance of FSS-DBSCAN is driven by two pivotal strategies. First, we devise an MPC-friendly DBSCAN algorithm that is highly compatible with efficient secret-sharing-based cryptographic protocols and benefits from GPU acceleration. Second, we construct novel FSS-based protocols tailored for complex operations integral to our DBSCAN variant, such as Euclidean distance comparison and point assignment, and further optimize their computation through tensorization techniques. We implement our platform as an extensible system on top of PyTorch that leverages GPU hardware acceleration for cryptographic and tensorized operations. These innovations enable FSS-DBSCAN to significantly outperform ppDBSCAN (AsiaCCS 2021), reducing the clustering time for 5000 samples to approximately 2 hours, achieving an$83.4\times $speed improvement.
Jiaxuan Fu, Ke Cheng 0001, Anxiao Song, Yuheng Xia, Zhao Chang, Yulong Shen 0001
IEEE Trans. Inf. Forensics Secur.1
2023 FedProc: Prototypical contrastive federated learning on non-IID data
Xutong Mu, Yulong Shen 0001, Ke Cheng 0001, Xueli Geng, Jiaxuan Fu, Tao Zhang 0029, Zhiwei Zhang 0004
Future Gener. Comput. Syst.5
2023 Manto: A Practical and Secure Inference Service of Convolutional Neural Networks for IoT
abstract
As convolutional neural networks (CNNs) exhibit remarkable performance in various inference tasks, it is increasingly important to enable Internet of Things (IoT) devices to perform CNN-based applications. Many companies provide their carefully trained neural networks as inference services for resource-constrained clients (e.g., IoT devices). However, the use of CNN inference in many IoT applications raises privacy concerns. Cryptographic inference services provide a way to perform neural inference efficiently and, at the same time, preserve both the privacy of the client’s input data and the server’s proprietary model. Unfortunately, the existing solutions incur severe latency costs, stemming mostly from nonlinear activations such as ReLUs, which make them still unsuitable for deployment in real IoT devices. In this article, we propose Manto, a secure inference system of CNNs for IoT. Manto makes the following two specific efforts by combining the insights of machine learning and cryptography. First, we customize different quadratic activation functions to replace specific ReLU layers and further propose a sliding-window-based fine-tuning method to produce CNN models involving no or few ReLUs. These techniques allow us to speedup cryptographic inference and guarantee inference accuracy. Second, we develop a series of cryptographic protocols that support ReLU activations and its approximation variants (i.e., polynomial activations), which purely rely on the lightweight secret sharing techniques in the online execution and can well cope with the above-mentioned optimized CNN models in the ciphertext domain. Our experimental results show Manto obtains state-of-the-art performance, reducing online inference latency by$66.2\%\sim 87.7\%$over prior works on CIFAR-100 and TinyImageNet data sets.
Ke Cheng 0001, Jiaxuan Fu, Yulong Shen 0001, Haichang Gao, Ning Xi 0002, Zhiwei Zhang 0004
IEEE Internet Things J.2