Zhaobo Lu

dblp:314/6330 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
8since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Systems, architecture and hardware · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Cer-FeaUn: Certified Feature Unlearning in Vertical Federated Learning
abstract
Feature unlearning, forgetting sensitive features while maintaining the accuracy of models, is a pressing issue against Feature Inference Attacks (FIA) in Vertical Federated Learning (VFL). This issue is addressed by retraining the model from scratch on a dataset without the sensitive features from scratch or Federated Unlearning (FU) for all samples. However, they either introduce high overheads due to retraining or reduce the accuracy of the unlearned model. In this paper, we proposedCer-FeaUn, a certified feature unlearning, trading off between the overheads and accuracy. Specifically, a novelfeature perturbation strategyis first proposed to construct a perturbed dataset, where the sensitive features are perturbed with noises. Then, the effect is defined as the parameters difference between models trained with the original and perturbed dataset. Finally, an unlearned model is trained in first-order, where the effect is removed from the original model in one epoch. Furthermore, Cer-FeaUn performscertified removalfor server-side models with strongly convex loss functions. That is, the distribution of the unlearned model is statistically indistinguishable from that of the retrained model. For the scenario with a few sensitive features, simulation results show that the accuracy of the unlearned model is up to 84.79%, and the runtime of Cer-FeaUn is 15 times faster than that of the retrained model.
Zhaobo Lu, Zhiquan Liu 0001, Tao Li 0043, Zhenhua Chen 0001, Willy Susilo
IEEE Trans. Mob. Comput.2
2025 FeaUn: Feature unlearning in vertical federated learning for IIoT against feature inference attacks
Zhaobo Lu, Tao Li 0043, Guangshun Li, Zhiquan Liu 0001
Neurocomputing1
2024 Partial Decode and Compare: An Efficient Verification Scheme for Coded Edge Computing
abstract
In recent years,Coded Edge Computing(CEC) has been greatly studied as a promising technology to effectively mitigate the impact of stragglers and provide confidentiality in edge collaborative computing. It is crucial to verify the correctness of both intermediate results and the final result especially in untrustable and unreliable edge computing scenarios. However, the existing works on verification in CEC always verify and directly discard the whole incorrect intermediate results. In this paper, we propose thePartial Decode and Compare(PDC) verification scheme, which can fully utilize the correct part in the incorrect intermediate results to reduce the complexity and tolerate more abnormal edge devices. The PDC verification scheme consists of two parts:Final Result Verification(FRV) andAbnormal Edge Device Identification(AEDI). By deeply analyzing the decoding impact of the intermediate results on the final result, the PDC verification scheme divides the intermediate results and final results intosubresult vectors. It decodes, compares, and verifies the final result in units of subresult vectors. In this way, the obtained parts which verified to be correct do not need to participate in the following verification. Therefore, it can significantly reduce the verification overhead including both the number of required decoding rounds and the complexity of each decoding round. Based on the correct final result verified by the PDC verification scheme, we also propose anAbnormal Edge Devices Identificationscheme to identify all abnormal edge devices that return incorrect intermediate results. We then present extensive theoretical analyses and simulation experiments of the PDC verification scheme, which demonstrates that the PDC verification scheme can tolerate a higher ratio of incorrect intermediate results and achieve lower verification overhead than the state-of-the-art verification works. Therefore, the proposed PDC verification scheme enables CEC to provide reliable services in unstable and unreliable edge computing scenarios.
Jin Wang 0009, Jingya Zhou, Zhaobo Lu, Kejie Lu, Jianping Wang 0001
IEEE Trans. Cloud Comput.4
2023 Decode-and-Compare: An Efficient Verification Scheme for Coded Distributed Edge Computing
abstract
Recently, edge computing has demonstrated increasing potential to provide low-latency computing services. Coded edge computing can not only make full use of the resources of heterogeneous edge computing servers, but also significantly reduce the negative effects of slow computing devices on computing time. Nevertheless, since edge servers may be unreliable or untrustworthy, the user will decode and get incorrect computation results even if it uses one incorrect sub-computation result returned by faulty edge servers. In this paper, for the existing coded edge computing schemes, we focus on the distributed matrix-matrix multiplication and design a general and efficientDecode-and-Compare Verification(DCV) scheme to verify the correctness of computation results and identify faulty edge servers by utilizing the properties of coded computing itself. The DCV scheme contains two components: (1) computation result verification,i.e., obtain the computation result and verify its correctness, and (2) faulty edge server identification,i.e., identify the faulty edge servers by verifying the correctness of returned sub-computation results. For both the independent and collusion faulty edge server models, we conduct solid theoretical analyses on the required decoding rounds, the coding redundancy and the successful verification probability to demonstrate that the correct computation result can be efficiently verified. We also conduct a lot of experiments on the DCV scheme from different aspects and the results show that it achieves much less computation time to get the correct computation result compared with other potential schemes, including homomorphic encryption and local computation.
Jin Wang 0009, Zhaobo Lu, Mingjia Fu, Jianping Wang 0001, Kejie Lu, Admela Jukan
IEEE Trans. Cloud Comput.2
2022 FP2-MIA: A Membership Inference Attack Free of Posterior Probability in Machine Unlearning
Zhaobo Lu, Qingzhe Lv, Minghao Zhao 0001, Tiancai Liang
ProvSec1
2022 Label-only membership inference attacks on machine unlearning without dependence of posteriors
abstract
Machine unlearning is the process through which a deployed machine learning model is enforced to forget about some of its training data items. It normally generates two machine learning models, the original model and the unlearned model, indicating training results before and after data items are deleted. However, recent studies find that machine unlearning is vulnerable to membership inference attacks—as the directivity of training and nontraining data (i.e., data items in the training set have high posterior probabilities), the attackers can utilize this property to infer whether an item has been used for original model training. Nevertheless, such attacks are incapable in label-only settings, in which the attackers are infeasible to get the posteriors. In this paper, we propose a new label-only membership inference attack scheme targeted at machine unlearning to eliminate the dependence on posteriors. Our heuristic is that injected turbulence on candidate samples will present different behaviors for training and nontraining data. Thus, in our scheme, the attacker iteratively query on the original/unlearned models and inject turbulence to change their predicting labels; it determines whether an item is having-been-delated by observing the disturbance amplitude. Extensive experiments (i.e., on MNIST, CIFAR10, CIFAR100, and STL10 data sets) show that our method achieves high inference accuracy (measured by AUC) in label-only settings, for example, AUC = 0.96 for MNIST data set. Besides, we analyze the existing countermeasures in mitigating inference attacks and find that our scheme can bypass most of them.
Zhaobo Lu, Hai Liang, Minghao Zhao 0001, Qingzhe Lv, Tiancai Liang
Int. J. Intell. Syst.1
2021 Recode-Decode-and-Compare: An Efficient Verification Scheme for Coded Edge Computing Against Collusion Attack
Zhaobo Lu, Jin Wang 0009, Jingya Zhou, Jianping Wang 0001, Kejie Lu
ICA3PP (1)1
2021 Linear Coded Federated Learning
Yingyao Yang, Jin Wang 0009, Kejie Lu, Jianping Wang 0001, Zhaobo Lu
ICA3PP (1)5