Xinguo Feng

dblp:335/1864 · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0003-2307-2771ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 5 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Mitigating Gradient Inversion Risks in Language Models via Token Obfuscation
abstract
Training and fine-tuning large-scale language models largely benefit from collaborative learning, but the approach has been proven vulnerable to gradient inversion attacks (GIAs), which allow adversaries to reconstruct private training data from shared gradients. Existing defenses mainly employ gradient perturbation techniques, e.g., noise injection or gradient pruning, to disrupt GIAs' direct mapping from gradient space to token space. However, these methods often fall short due to the retention of semantics similarity across gradient, embedding, and token spaces. Attackers can map proximate gradients into similar embeddings, and subsequently correspond them to tokens with similar semantics.
Xinguo Feng, Zhongkui Ma, Alsharif Abuadbba, Guangdong Bai
AsiaCCS1
2026 Re-Key-Free, Risky-Free: Adaptable Model Usage Control
Zhongkui Ma, Xinguo Feng, Chuan Yan, Dongge Liu, Ruoxi Sun 0001, Derui Wang, Minhui Xue 0001, Guangdong Bai
EuroS&P3
2025 AI Model Modulation with Logits Redistribution
abstract
Large-scale models are typically adapted to meet the diverse requirements of model owners and users.However, maintaining multiple specialized versions of the model is inefficient.In response, we propose Aim, a novel model modulation paradigm that enables a single model to exhibit diverse behaviors to meet the specific end requirements.Aim enables two key modulation modes: utility and focus modulations.The former provides model owners with dynamic control over output quality to deliver varying utility levels, and the latter offers users precise control to shift model's focused input features.Aim introduces a logits redistribution strategy that operates in a training data-agnostic and retraining-free manner.We establish a formal foundation to ensure Aim's regulation capability, based on the statistical properties of logits ordering via joint probability distributions.Our evaluation confirms Aim's practicality and versatility for AI model modulation, with tasks spanning image classification, semantic segmentation and text generation, and prevalent architectures including ResNet, SegFormer and Llama.
Zhongkui Ma, Xinguo Feng, Zhiyang Mei, Ethan Ma, Derui Wang, Minhui Xue 0001, Guangdong Bai
WWW3
2024 Uncovering Gradient Inversion Risks in Practical Language Model Training
abstract
The gradient inversion attack has been demonstrated as a significant privacy threat to federated learning (FL), particularly in continuous domains such as vision models. In contrast, it is often considered less effective or highly dependent on impractical training settings when applied to language models, due to the challenges posed by the discrete nature of tokens in text data. As a result, its potential privacy threats remain largely underestimated, despite FL being an emerging training method for language models. In this work, we propose a domain-specific gradient inversion attack named GRAB (gradient inversion with hybrid optimization). GRAB features two alternating optimization processes to address the challenges caused by practical training settings, including a simultaneous optimization on dropout masks between layers for improved token recovery and a discrete optimization for effective token sequencing. GRAB can recover a significant portion (up to 92.9% recovery rate) of the private training data, outperforming the attack strategy of utilizing discrete optimization with an auxiliary model by notable improvements of up to 28.9% recovery rate in benchmark settings and 48.5% recovery rate in practical settings. GRAB provides a valuable step forward in understanding this privacy threat in the emerging FL training mode of language models.
Xinguo Feng, Zhongkui Ma, Eu Joe Chegne, Mengyao Ma, Alsharif Abuadbba, Guangdong Bai
CCS1
2024 CORELOCKER: Neuron-level Usage Control
abstract
The growing complexity of deep neural network models in modern application domains necessitates a complex training process that involves extensive data, sophisticated design, and substantial computation. The trained model inherently encapsulates the intellectual property owned by the model developer (or the model owner). Consequently, safeguarding the model from unauthorized use by entities who obtain access to the model (or the model controllers), i.e., preserving the fundamental rights and proprietary interests of the model owner, has become a critical necessity.In this work, we propose CORELOCKER, employing the strategic extraction of a small subset of significant weights from the neural network. This subset serves as the access key to unlock the model’s complete capability. The extraction of the key can be customized to varying levels of utility that the model owner intends to release. Authorized users with the access key have full access to the model, while unauthorized users can have access to only part of its capability. We establish a formal foundation to underpin CORELOCKER, which provides crucial lower and upper bounds for the utility disparity between pre- and post-protected networks. We evaluate CORELOCKER using representative datasets such as Fashion-MNIST, CIFAR-10, and CIFAR-100, as well as real-world models including Vg-gNet, ResNet, and DenseNet. Our experimental results confirm its efficacy. We also demonstrate CORELOCKER’s resilience against advanced model restoration attacks based on fine-tuning and pruning.
Zhongkui Ma, Xinguo Feng, Ruoxi Sun 0001, Hu Wang 0005, Minhui Xue 0001, Guangdong Bai
SP3
2023 Formalizing Robustness Against Character-Level Perturbations for Neural Network Language Models
Zhongkui Ma, Xinguo Feng, Shuofeng Liu, Mengyao Ma, Hao Guan 0001, Mark Huasong Meng
ICFEM2
2022 Detecting Contradictions from CoAP RFC Based on Knowledge Graph
Xinguo Feng, Yanjun Zhang 0002, Mark Huasong Meng, Sin G. Teo
NSS1