EDBT 2026 Demo / reviewers in the wild / expert
Fuyi Wang
dblp:319/2425
· DBLP profile ↗
18ranked-venue papers
8as first author
18since 2021 · last 2026
0000-0002-8216-3238ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 5 first-author · 8 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Computer networks · 3 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Trustworthy Federated Learning Framework for Joint Privacy and Byzantine ResilienceabstractFederated Learning (FL) has emerged as a promising paradigm for collaborative model training without direct data sharing. However, existing frameworks struggle to simultaneously ensure strong privacy protection and robustness against adversarial participants. Although numerous robust aggregation algorithms can mitigate Byzantine attacks and various privacy-preserving approaches have been developed, achieving both objectives within a unified and efficient framework remains challenging. To address this compatibility gap, we propose a generic privacy-preserving FL framework that integrates robust aggregation with cryptographic privacy guarantees through secure two-party computation under a dual-server architecture. In our design, two non-colluding servers collaboratively execute the aggregation process, ensuring that sensitive client updates remain confidential while enabling the application of diverse robust aggregation strategies. The framework is flexible and supports a wide range of aggregation algorithms, such as Multi-Krum, Median, and Mean-based methods, under a consistent security model. We implement the proposed system and conduct extensive experiments on multiple benchmark datasets. Experimental results demonstrate that our framework preserves the effectiveness of existing robust aggregation algorithms while maintaining acceptable runtime and communication overhead compared with standard FL baselines. These findings confirm that the proposed approach provides a practical and balanced solution to the dual challenges of privacy protection and Byzantine robustness, offering a versatile foundation for secure and trustworthy FL in adversarial environments. Jiangang Shu, Zhiping Hu, Fuyi Wang, Yuyu He 0001, Hui Lu 0005, Zhihong Tian 0001 |
IEEE Internet Things J. | 3 |
| 2026 | Privacy-Preserving Automated Deep Learning for Secure Inference ServiceabstractAutomated deep learning (AutoDL) aims to automatically discover optimal architectures of deep neural networks (DNNs) for secure inference without the studies for time-consuming and error-prone manual design. Privacy concerns have increasingly motivated the studies for privacy-preserving AutoDL (PrivAutoDL), where DNN architectures are searched directly on encrypted data without revealing the client's confidential inputs and well-trained DNN architectures. However, existing studies encounter problems in achieving a balance between provable security and efficiency while avoiding significant degradation of model utility. To tackle these problems, we design a privacy-preserving AutoDL scheme, named 2PCAutoDL, utilizing a two-party (two non-colluding cloud servers) computation model. Based on the two-server model, efficient and secure computation protocols are customized layer by layer to protect DNN models associated with client's data. In particular, we reduce the computational overhead of secure DNN: our optimized protocols achieve$1.34\times \sim 2.05\times$speedup for linear layers and$1.33 \times \sim 45 \times$speedup for non-linear layers, compared to a range of existing secure implementations in the literature. Moreover, our fresh alternative to approximate Softmax avoids the drawbacks of approximating exponential operation and yields slightly higher accuracy under appropriate configurations. The security of 2PCAutoDL is formally analyzed under the semi-honest adversary model. Extensive experiments demonstrate that the searched models from 2PCAutoDL improve the inference accuracy by 0.6% on MNIST and by 0.5% on CIFAR-10 when compared to state-of-the-art (SOTA) PrivAutoDL. Fuyi Wang, Jinzhi Ouyang, Leo Yu Zhang, Lei Pan 0002, Shengshan Hu, Xiaoning Liu 0002, Robin Doss |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | SHRD: A Scalable Scheme for Hierarchical File Sharing With Rank-Aware Dissemination
Shulan Wang, Jinghong Gan, Chenbin Zhao, Fuyi Wang, Junwei Zhou 0002, Kaitai Liang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | sf SEBioID: Secure and Efficient Biometric Identification with Two-Party Computation
Fuyi Wang, Jinzhi Ouyang, Leo Yu Zhang, Lei Pan 0002, Shengshan Hu, Robin Doss, Jianying Zhou 0001 |
ACNS (3) | 1 |
| 2025 | FLAME: Flexible and Lightweight Biometric Authentication Scheme in Malicious EnvironmentsabstractPrivacy-preserving biometric authentication (PPBA) enables client authentication without revealing sensitive bio-metric data, addressing privacy and security concerns. Many studies have proposed efficient cryptographic solutions to this problem based on secure multi-party computation, typically assuming a semi-honest adversary model, where all parties follow the protocol but may try to learn additional information. However, this assumption often falls short in real-world scenarios, where adversaries may behave maliciously and actively deviate from the protocol. In this paper, we propose, implement, and evaluate FLAME, a Flexible and Lightweight biometric Authentication scheme designed for a Malicious Environment. By hybridizing lightweight secret-sharing-family primitives within two-party computation, FLAME carefully designs a line of supporting protocols that incorporate integrity checks with rationally extra overhead. Additionally, FLAME enables server-side authentication with various similarity metrics through a crossmetric-compatible design, enhancing flexibility and robustness without requiring any changes to the server-side process. A rigorous theoretical analysis validates the correctness, security, and efficiency of FLAME. Extensive experiments highlight FLAME's superior efficiency, with a communication reduction by 97.61x 110.13x and a speedup of 2.72x 2.82x (resp. 6.58x 8.51x) in a LAN (resp. WAN) environment, when compared to the state-of-the-art work. Fuyi Wang, Fangyuan Sun, Mingyuan Fan 0003, Jianying Zhou 0001, Chao Chen 0015, Jiangang Shu, Leo Yu Zhang |
ACSAC | 1 |
| 2025 | PrivGNN: High-Performance Secure Inference for Cryptographic Graph Neural Networks
Fuyi Wang, Zekai Chen 0010, Mingyuan Fan 0003, Jianying Zhou 0001, Lei Pan 0002, Leo Yu Zhang |
FC (2) | 1 |
| 2025 | Bad-PFL: Exploiting Backdoor Attacks against Personalized Federated LearningabstractData heterogeneity and backdoor attacks rank among the most significant challenges facing federated learning (FL). For data heterogeneity, personalized federated learning (PFL) enables each client to maintain a private personalized model to cater to client-specific knowledge. Meanwhile, vanilla FL has proven vulnerable to backdoor attacks. However, recent advancements in PFL community have demonstrated a potential immunity against such attacks. This paper explores this intersection further, revealing that existing federated backdoor attacks fail in PFL because backdoors about manually designed triggers struggle to survive in personalized models. To tackle this, we degisn Bad-PFL, which employs features from natural data as our trigger. As long as the model is trained on natural data, it inevitably embeds the backdoor associated with our trigger, ensuring its longevity in personalized models. Moreover, our trigger undergoes mutual reinforcement training with the model, further solidifying the backdoor's durability and enhancing attack effectiveness. The large-scale experiments across three benchmark datasets demonstrate the superior performance of Bad-PFL against various PFL methods, even when equipped with state-of-the-art defense mechanisms. Mingyuan Fan 0003, Zhanyi Hu, Fuyi Wang, Cen Chen 0001 |
ICLR | 3 |
| 2025 | PP-DACMR: A Privacy-Preserving Deep Adversarial Hashing for Cross-Modal RetrievalabstractWith the growth of large-scale multimodal data and advancements in neural networks (NNs), cross-modal retrieval (CMR) relies on outsourced computation for efficiency and scalability. Existing privacy-preserving CMR approaches under the fully outsourced setup typically employ traditional machine learning models or simple NNs due to the limitations of privacypreserving techniques. It results in significant performance gaps in efficiency and accuracy compared to plaintext CMR. In this paper, we present PP-DACMR, a privacy-preserving deep adversarial hashing approach for cross-modal retrieval. With the paradigm of secure two-party computation, PP-DACMR employs a lightweight technique, additive secret sharing (ASS), to safeguard multimodal data and NNs. A series of ASS-based protocols are designed specifically for CMR based on GAN architecture, supporting in-the-cloud training and querying. Moreover, we optimize two generic secure arithmetic protocols for truncation and matrix multiplication, which are fundamental to PP-DACMR, contributing to improved performance. We conduct experimental evaluations over real-world multimodal datasets and compare PP-DACMR to the state-of-the-art approach PPCMR. The results demonstrate PP-DACMR outperforms PPCMR, achieving an improvement on the average mAP of 11.73% and being 5.3× faster. Jinzhi Ouyang, Fuyi Wang, Jianting Ning, Leo Yu Zhang |
IWQoS | 2 |
| 2025 | Boosting Gradient Leakage Attacks: Data Reconstruction in Realistic FL Settings
Mingyuan Fan 0003, Fuyi Wang, Cen Chen 0001, Jianying Zhou 0001 |
USENIX Security Symposium | 2 |
| 2025 | MedShield: A Fast Cryptographic Framework for Private Multi-Service Medical DiagnosisabstractThe substantial progress in privacy-preserving machine learning (PPML) facilitates outsourced medical computer-aided diagnosis (MedCADx) services. However, existing PPML frameworks primarily concentrate on enhancing the efficiency of prediction services, without exploration into diverse medical services such as medical segmentation. In this paper, we proposeMedShield, a pioneering cryptographic framework for diverse MedCADx services (i.e., multi-service, including medical imaging prediction and segmentation). Based on a client-server (two-party) setting,MedShieldefficiently protects medical records and neural network models without fully outsourcing. To execute multi-service securely and efficiently, our technical contributions include: 1) optimizing computational complexity of matrix multiplications for linear layers at the expense of free additions/subtractions; 2) introducing a secure most significant bit protocol with crypto-friendly activations to enhance the efficiency of non-linear layers; 3) presenting a novel layer for upscaling low-resolution feature maps to support multi-service scenarios in practical MedCADx. We conduct a rigorous security analysis and extensive evaluations on benchmarks (MNIST and CIFAR-10) and real medical records (breast cancer, liver disease, COVID-19, and bladder cancer) for various services. Experimental results demonstrate thatMedShieldachieves up to$2.4\times$,$4.3\times$, and$2\times$speed up for MNIST, CIFAR-10, and medical datasets, respectively, compared with prior work when conducting prediction services. For segmentation services,MedShieldpreserves the precision of the unprotected version, showing a$1.23\%$accuracy improvement. Fuyi Wang, Jinzhi Ouyang, Xiaoning Liu 0002, Lei Pan 0002, Leo Yu Zhang, Robin Doss |
IEEE Trans. Serv. Comput. | 1 |
| 2024 | CryptGraph: An Efficient Privacy-Enhancing Solution for Accurate Shortest Path Retrieval in Cloud EnvironmentsabstractWith the widespread adoption of cloud computing, it is a popular trend to migrate shortest path and distance (SPD) retrieval on large-scale graphs to cloud environments, harnessing their immense computational capabilities. To protect sensitive information, these graphs are usually encrypted before being outsourced to the cloud. A significant challenge is how to answer SPD retrieval in a secure, efficient, and accurate manner. However, recent works have yet to concurrently tackle all three aspects to meet this challenge. To address this challenge, we design, implement, and evaluate Crypt-Graph, the first scheme simultaneously allowing private, efficient, and accurate retrieval over encrypted graphs. CryptGraph leverages additive homomorphic encryptions to protect graphs and client information. A series of secure protocols are tailored based on the two-cloud (i.e., server) model. Supported by these protocols, Crypt-Graph converts SPD retrieval from the ciphertext domain to both the plaintext (for vertices) and secret-sharing (for weights) domains, achieving access pattern protection and remarkable efficiency close to plain retrieval. The security of CryptGraph is formally analyzed under the semi-honest adversary model. Extensive experiments are conducted on both synthetic and real-world graph datasets, demonstrating millisecond-level efficiency and 100% accuracy rates. Fuyi Wang, Zekai Chen 0010, Lei Pan 0002, Leo Yu Zhang, Jianying Zhou 0001 |
AsiaCCS | 1 |
| 2024 | TrustMIS: Trust-Enhanced Inference Framework for Medical Image SegmentationabstractRecent advancements in privacy-preserving deep learning (PPDL) enable artificial intelligence-assisted (AI-assisted) medical image diagnostics with privacy guarantees, addressing increasing concerns about data and model privacy. However, intensive studies are restricted to shallow and narrow neural networks (NNs) for simple service (e.g., disease prediction), leaving a gap in exploring diverse inferences. This paper proposes TrustMIS, a trust-enhanced inference framework for fast and private medical image segmentation (MIS) and prediction services. Based on two-party computation, TrustMIS introduces lightweight additive secret-sharing tools to safeguard medical records and NNs. Complementing existing PPDL schemes, we present a series of secure two-party interactive protocols for linear layers. Specifically, we optimize the secure matrix multiplication by reducing the number of expensive multiplication operations with the help of free-computation addition operations to enhance efficiency (bringing 1.15× ∼2.64× savings in both time and communication costs). Furthermore, we customize a fresh secure transposed convolutional protocol for MIS-oriented NNs. A thorough theoretical analysis is provided to prove TrustMIS’s correctness and security. We conduct experimental evaluations over two benchmark and four real-world medical datasets and compare them to state-of-the-art studies. The results demonstrate TrustMIS’s superiority in efficiency and accuracy, improved by 1.1× ∼ 54.4× speedup in secure disease prediction, and 5.56% ↑ ∼ 11.7% ↑ accuracy in secure MIS. Fuyi Wang, Jinzhi Ouyang, Lei Pan 0002, Leo Yu Zhang, Xiaoning Liu 0002, Robin Doss |
ECAI | 1 |
| 2024 | FedCL: Detecting Backdoor Attacks in Federated Learning with Confidence LevelsabstractFederated Learning (FL) enables multiple clients to collaborate in training neural network models while retaining their private data locally. Despite its advantages, FL is vulnerable to backdoor attacks due to its distributed nature. Attackers introduce triggers into the global model, causing it to make specified predictions on inputs containing these triggers. Existing detection or clustering defense methods based on distance and similarity have significant limitations. Methods based on clipping and adding noise can only slightly mitigate the impact of backdoor attacks. To achieve a better defense, we introduce FedCL, a backdoor defense framework that accurately detects backdoor models by assessing the uncertainty of model predictions. Additionally, it employs dynamic clipping to limit model updates’ impact, successfully mitigating backdoor attacks without compromising the global model’s accuracy. The experiments indicate that FedCL moderately improves by 0.01%↑ ∼ 85.78%↑ than the state-of-the-art (SOTA) defense methods, especially in the CIFAR-10 task trained with more complex networks. Jinhe Long, Zekai Chen 0010, Fuyi Wang, Ximeng Liu |
ICME | 3 |
| 2024 | Lightweight Privacy-Preserving Cross-Cluster Federated Learning With Heterogeneous DataabstractFederated Learning (FL) eliminates data silos that hinder digital transformation while training a shared global model collaboratively. However, training a global model in the context of FL has been highly susceptible to heterogeneity and privacy concerns due to discrepancies in data distribution, which may lead to potential data leakage from uploading model updates. Despite intensive research on above-identical issues, existing approaches fail to balance robustness and privacy in FL. Furthermore, limiting model updates or iterative clustering tends to fall into local optimum problems in heterogeneous (Non-IID) scenarios. In this work, to address these deficiencies, we provide lightweight privacy-preserving cross-cluster federated learning (PrivCrFL) on Non-IID data, to trade off robustness and privacy in Non-IID settings. Our PrivCrFL exploits secure one-shot hierarchical clustering with cross-cluster shifting for optimizing sub-group convergences. Furthermore, we introduce intra-cluster learning and inter-cluster learning with separate aggregation for mutual learning between each group. We perform extensive experimental evaluations on three benchmark datasets and compare our results with state-of-the-art studies. The findings indicate that PrivCrFL offers a notable performance enhancement, with improvements ranging from$0.26\%~\uparrow $to$1.35\%~\uparrow $across different Non-IID settings. PrivCrFL also demonstrates a superior communication compression ratio in secure aggregation, outperforming current state-of-the-art works by 10.59%. Zekai Chen 0010, Shengxing Yu, Farong Chen, Fuyi Wang, Ximeng Liu, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2023 | Rethinking the Evaluation of Deep Neural Network Robustness
Mingyuan Fan 0003, Fuyi Wang, Bosheng Yan |
ADMA (4) | 2 |
| 2023 | FedCML: Federated Clustering Mutual Learning with non-IID Data
Zekai Chen 0010, Fuyi Wang, Shengxing Yu, Ximeng Liu, Zhiwei Zheng |
Euro-Par | 2 |
| 2023 | Fedward: Flexible Federated Backdoor Defense Framework with Non-IID DataabstractFederated learning (FL) enables multiple clients to collaboratively train deep learning models while considering sensitive local datasets’ privacy. However, adversaries can manipulate datasets and upload models by injecting triggers for federated backdoor attacks (FBA). Existing defense strategies against FBA consider specific and limited attacker models, and a sufficient amount of noise to be injected only mitigates rather than eliminates FBA. To address these deficiencies, we introduce a Flexible Federated Backdoor Defense Framework (Fedward) to ensure the elimination of adversarial backdoors. We decompose FBA into various attacks, and design amplified magnitude sparsification (AmGrad) and adaptive OPTICS clustering (AutoOPTICS) to address each attack. Meanwhile, Fedward uses the adaptive clipping method by regarding the number of samples in the benign group as constraints on the boundary. This ensures that Fedward can maintain the performance for the Non-IID scenario. We conduct experimental evaluations over three benchmark datasets and thoroughly compare them to state-of-the-art studies. The results demonstrate the promising defense performance from Fedward, moderately improved by 33% ∼ 75% in clustering defense methods, and 96.98%, 90.74%, and 89.8% for Non-IID to the utmost extent for the average FBA success rate over MNIST, FMNIST, and CIFAR10, respectively. Zekai Chen 0010, Fuyi Wang, Zhiwei Zheng, Ximeng Liu |
ICME | 2 |
| 2022 | Towards Privacy-Preserving Neural Architecture SearchabstractMachine learning promotes the continuous development of signal processing in various fields, including network traffic monitoring, EEG classification, face identification, and many more. However, massive user data collected for training deep learning models raises privacy concerns and increases the difficulty of manually adjusting the network structure. To address these issues, we propose a privacy-preserving neural architecture search (PP-NAS) framework based on secure multi-party computation to protect users' data and the model's parameters/hyper-parameters. PP-NAS outsources the NAS task to two non-colluding cloud servers for making full advantage of mixed protocols design. Complement to the existing PP machine learning frameworks, we redesign the secure ReLU and Max-pooling garbled circuits for significantly better efficiency (3 ~ 436 times speed-up). We develop a new alternative to approximate the Softmax function over secret shares, which bypasses the limitation of approximating exponential operations in Softmax while improving accuracy. Extensive analyses and experiments demonstrate PP-NAS's superiority in security, efficiency, and accuracy. Fuyi Wang, Leo Yu Zhang, Lei Pan 0002, Shengshan Hu, Robin Doss |
ISCC | 1 |