EDBT 2026 Demo / reviewers in the wild / expert
Zirui Gong
dblp:334/0570
· DBLP profile ↗
5ranked-venue papers
3as first author
5since 2021 · last 2026
0009-0008-6284-2234ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ARES: Scalable and Practical Gradient Inversion Attack in Federated Learning Through Activation Recovery
Zirui Gong, Leo Yu Zhang, Viet Vo, Tianqing Zhu, Shirui Pan |
SP | 1 |
| 2026 | Beyond Denial-of-Service: The Puppeteer's Attack for Fine-Grained Control in Ranking-Based Federated Learning
Zirui Gong, Jianting Ning, Yanjun Zhang 0002, Leo Yu Zhang |
WWW | 2 |
| 2025 | Not All Edges are Equally Robust: Evaluating the Robustness of Ranking-Based Federated LearningabstractFederated Ranking Learning (FRL) is a state-of-the-art FL framework that stands out for its communication efficiency and resilience to poisoning attacks. It diverges from the traditional FL framework in two ways: 1) it leverages discrete rankings instead of gradient updates, significantly reducing communication costs and limiting the potential space for malicious updates, and 2) it uses majority voting on the server side to establish the global ranking, ensuring that individual updates have minimal influence since each client contributes only a single vote. These features enhance the system's scalability and position FRL as a promising paradigm for FL training. However, our analysis reveals that FRL is not inherently robust, as certain edges are particularly vulnerable to poisoning attacks. Through a theoretical investigation, we prove the existence of these vulnerable edges and establish a lower bound and an upper bound for identifying them in each layer. Based on this finding, we introduce a novel local model poisoning attack against FRL, namely Vulnerable Edge Manipulation (VEM) attack. The VEM attack focuses on identifying and perturbing the most vulnerable edges in each layer and leveraging an optimization-based approach to maximize the attack's impact. Through extensive experiments on benchmark datasets, we demonstrate that our attack achieves an overall 53.23 % attack impact and is 3.7× more impactful than existing methods. Our findings highlight significant vulnerabilities in ranking-based FL systems and underline the urgency for the development of new robust FL frameworks. Zirui Gong, Yanjun Zhang 0002, Leo Yu Zhang, Zhaoxi Zhang 0001, Yong Xiang 0001, Shirui Pan |
SP | 1 |
| 2024 | AgrAmplifier: Defending Federated Learning Against Poisoning Attacks Through Local Update AmplificationabstractThe collaborative nature of federated learning (FL) poses a major threat in the form of manipulation of local training data and local updates, known as the Byzantine poisoning attack. To address this issue, many Byzantine-robust aggregation rules (AGRs) have been proposed to filter out or moderate suspicious local updates uploaded by Byzantine participants. This paper introduces a novel approach called AGRAMPLIFIER, aiming to simultaneously improve robustness, fidelity, and efficiency of the existingAGRs. The core idea of AGRAMPLIFIER is to amplify the “morality” of local updates by identifying the most repressive features of each gradient update, which provides a clearer distinction between malicious and benign updates, consequently improving the detection effect. To achieve this objective, two approaches, namelyAGRMPandAGRXAI, are proposed.AGRMPorganizes local updates into patches and extracts the largest value from each patch, whileAGRXAIleverages explainable AI methods to extract the gradient of the most activated features. By equipping AGRAMPLIFIER with the existing Byzantine-robust mechanisms, we successfully enhance the model robustness, maintaining its fidelity and improving overall efficiency. AGRAMPLIFIER is universally compatible with the existing Byzantine-robust mechanisms. The paper demonstrates its effectiveness by integrating it with all mainstreamAGRmechanisms. Extensive evaluations conducted on seven datasets from diverse domains against seven representative poisoning attacks consistently show enhancements in robustness, fidelity, and efficiency, with average gains of 40.08%, 39.18%, and 10.68%, respectively. Zirui Gong, Liyue Shen, Yanjun Zhang 0002, Leo Yu Zhang, Jingwei Wang 0003, Guangdong Bai, Yong Xiang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Production Evaluation of Citrus Fruits based on the YOLOv5 compressed by Knowledge DistillationabstractPre-harvest estimation of fruit production is crucial for fruit storage and price analysis in the planting of fruit trees. However, prior research consistently displays low accuracy because of problems with small objects, leaf occlusion, and fruit overlap, and they emphasize large networks that are unrealistic in the real world. In this study, we emphasize the use of smartphones to evaluate citrus fruit production. We suggest a simple method for detecting objections based on the YOLOv5 algorithm compressed by knowledge distillation. To extract the visual features, we first use mobilenetV2 as the foundation of YOLOv5. To learn the reliable detection features, we also incorporate an attention mechanism into YOLOv5. As such, we can obtain embedded Yolo served as a student model, which is learned via knowledge distillation. As such we can take the lightweight student model as the final detection model. Finally, we take the embedded Yolo to detect the citrus fruits and take a linear regression model to predict the number of counted fruits and the production is estimated. Experiments show that the proposed method can accurately count fruits and approximate the production. Zirui Gong, Yihang Zhou, Yuting He 0007, Renjie Huang |
CSCWD | 2 |