Bohan Peng

dblp:330/1891 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
2since 2021 · last 2026
0009-0000-2410-0186ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Security and privacy of machine learning · 67% Privacy and data protection · 33%
Artificial intelligence
1 paper
Efficient and distributed learning · 100%

Topics — the 4 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Efficient and distributed learning › federated learning
asynchronous federated learning
1.012026
Byzantine-Robust Asynchronous Federated Learning via Feature Fingerprinting · IEEE Trans. Inf. Forensics Secur. 2026
Machine learning › Efficient and distributed learning
federated learning
1.012026
Byzantine-Robust Asynchronous Federated Learning via Feature Fingerprinting · IEEE Trans. Inf. Forensics Secur. 2026
Security and privacy of machine learning › federated learning defense
byzantine-robust federated learning
1.012026
Byzantine-Robust Asynchronous Federated Learning via Feature Fingerprinting · IEEE Trans. Inf. Forensics Secur. 2026
Privacy and data protection › privacy-preserving machine learning
federated learning privacy
1.012026
Casper: A Causality-Inspired Defense With Confounder Against Label Inference Attacks in Vertical Split Federated Learning · IEEE Trans. Inf. Forensics Secur. 2026

Methods — techniques the papers use, named apart from their topics

feature fingerprinting · 2.0contrastive representation · 2.0clustering · 2.0selective discrepancy training · 1.0confounder · 1.0causal inference · 1.0
YearPublicationVenuePosition
2026 Casper: A Causality-Inspired Defense With Confounder Against Label Inference Attacks in Vertical Split Federated Learning
abstract
Vertical Split Federated Learning (VSFL) allows participants to collaboratively train a better model with different features vertically partitioned in the same sample space, where the model is divided into bottom model and top model by the cut layer, trained by passive and active participants respectively. However, in the process, the labels owned by the active participant will still be inferred or stolen by curious or malicious passive participants. In this paper, we propose Casper, a causality-inspired defense mechanism with a confounder against label inference attacks in VSFL. Casper first analyzes the feasibility of optimizing the training process in VSFL at the intervention level from a causal perspective. It then introduces a confounder consisting of cut layer output reconstruction and label obfuscation to disrupt the direct causality between cut layer outputs and labels. Additionally, we integrate selective discrepancy training to further ensure model utility by strategically balancing training between active and passive participants. Extensive experiments conducted on four datasets across different tasks demonstrate that Casper effectively preserves label privacy while maintaining model performance, significantly outperforming current advanced defending methods in VSFL.
Meng Shen 0001, Bohan Peng, Xiangyun Tang, Wei Wang 0012, Dusit Niyato, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.3
2026 Byzantine-Robust Asynchronous Federated Learning via Feature Fingerprinting
abstract
Asynchronous federated learning (AFL) accelerates collaborative training across heterogeneous devices compared to synchronous federated learning, but increases vulnerability to Byzantine attacks due to its asynchronous aggregation. Existing defenses rely on parametric similarity between models and temporal consistency of updates, which are compromised by data and device heterogeneity, leading to ineffective robustness. To address this limitation, we propose Belisa, a Byzantine-robust AFL framework that enhances fidelity, robustness, and efficiency under heterogeneous scenarios. Belisa introduces novel discrepancies between feature representations of local models to distinguish malicious models from benign ones. By leveraging a reference model trained on publicly available data, Belisa quantifies these discrepancies, referred to as feature fingerprints, and filters out malicious models through clustering. Extensive experiments on six datasets from three types of tasks under five advanced Byzantine attacks demonstrate Belisa’s superiority. Notably, Belisa consistently outperforms existing approaches across both attack and non-attack settings. Under attack scenarios, it lowers the average test error rate to 0.42× that of baseline methods. Furthermore, Belisa accelerates the aggregation process by an average of 12.3× compared to other methods. To the best of our knowledge, Belisa is the first Byzantine-robust AFL framework, which provides a broadly applicable countermeasure in heterogeneous scenarios which are more prevalent in real-world settings.
Meng Shen 0001, Bohan Peng, Yi Zhao 0011, Ming Li 0049, Qi Li 0002, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.2