EDBT 2026 Demo / reviewers in the wild / expert
Yuxian Huang
dblp:299/0497
· DBLP profile ↗
4ranked-venue papers
3as first author
4since 2021 · last 2025
0000-0003-4497-2656ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | DBSSL: A Scheme to Detect Backdoor Attacks in Self-Supervised Learning ModelsabstractRecently, self-supervised learning has garnered significant attention for its ability to extract high-quality features from unlabeled data. However, existing research indicates that backdoor attacks can pose significant threats to self-supervised learning. Additionally, due to the substantial training overhead, traditional backdoor detection methods in supervised learning, such as meta-learning, are not well-suited for self-supervised learning. Current backdoor detection methods for self-supervised learning can only defend against backdoor attacks triggered by patch. To address this challenge, we proposes DBSSL, a scheme that can efficiently detect backdoor attacks in self-supervised learning models. In DBSSL, we connect backdoor attacks with adversarial attacks and use adversarial perturbations for detection. Specifically, we first conduct targeted adversarial attacks on the samples, classifying them into different classes. Then, we employ the Z-Score method to analyze these adversarial perturbations. If outliers are present, we can infer that the self-supervised learning model has been backdoored. Unlike previous works, our scheme is better suited for downstream users with constrained computation resources and exhibits excellent detection capabilities for backdoor attacks caused by patch-type or global triggers. Abundant theoretical analysis has demonstrated the feasibility of our scheme. Moreover, extensive experiments show that our method performs well in detecting prevalent backdoor attacks in self-supervised learning, achieving detection accuracy exceeding 95%. Yuxian Huang, Geng Yang 0002, Dong Yuan 0001, Shui Yu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | VPPFL: A verifiable privacy-preserving federated learning scheme against poisoning attacks
Yuxian Huang, Geng Yang 0002, Hao Zhou 0034, Hua Dai 0003, Dong Yuan 0001, Shui Yu 0001 |
Comput. Secur. | 1 |
| 2023 | Privacy-Preserving and Verifiable Federated Learning Framework for Edge ComputingabstractIn federated learning (FL), each client collaboratively trains the global model through the cloud server (CS) without sharing its original dataset in edge computing. However, CS can analyze and forge the uploaded parameters and infer the privacy of clients, which calls for the necessity of verifying the integrity and protecting the privacy for aggregation. Although there are some works to ensure the verifiability of aggregation results, there is still a lack of work on analyzing the relationship between verification and dropout rate for edge computing. In this work, we propose privacy-preserving and verifiable federated learning (PVFL) with low communication and computation overhead for verification. We theoretically demonstrate that PVFL has three properties: 1) the communication overhead for verification is independent of the dropouts and the dimension of the parameter vector; 2) the computation overhead for verification is independent of the dropouts; 3) the value of the loss function is negatively correlated with the number of dropouts. Experimental results demonstrate the correctness of our theoretical results and practical performance with a high dropout rate, thereby facilitating the design of privacy-preserving and verifiable FL algorithms for edge computing with a high dimension of parameter vectors and a high dropout rate. Hao Zhou 0034, Geng Yang 0002, Yuxian Huang, Hua Dai 0003, Yang Xiang 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2021 | Differential Privacy Principal Component Analysis for Support Vector MachinesabstractIn big data era, massive and high-dimensional data is produced at all times, increasing the difficulty of analyzing and protecting data. In this paper, in order to realize dimensionality reduction and privacy protection of data, principal component analysis (PCA) and differential privacy (DP) are combined to handle these data. Moreover, support vector machine (SVM) is used to measure the availability of processed data in our paper. Specifically, we introduced differential privacy mechanisms at different stages of the algorithm PCA-SVM and obtained the algorithms DPPCA-SVM and PCADP-SVM. Both algorithms satisfy ε,0 -DP while achieving fast classification. In addition, we evaluate the performance of two algorithms in terms of noise expectation and classification accuracy from the perspective of theoretical proof and experimental verification. To verify the performance of DPPCA-SVM, we also compare our DPPCA-SVM with other algorithms. Results show that DPPCA-SVM provides excellent utility for different data sets despite guaranteeing stricter privacy. Yuxian Huang, Yahong Xu |
Secur. Commun. Networks | 1 |