EDBT 2026 Demo / reviewers in the wild / expert
Zhongkai Lu
dblp:342/6051
· DBLP profile ↗
6ranked-venue papers
2as first author
6since 2021 · last 2026
0009-0005-7186-8012ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Enhancing Integrity Verification of Convolutional Neural Network Predictions in a Malicious ModelabstractThe widespread deployment of neural networks has raised significant concerns regarding the integrity and privacy of model predictions, especially in malicious environments. Current approaches have explored zero-knowledge proofs for integrity verification. However, they suffer from inefficiency in proving runtime and a lack of rigorous integrity verification for non linear operations. To address these issues, we present a trustwor thy framework for Enhancing Integrity Verification of Convolutional Neural Network predictions (EIV-CNN) in a malicious model, whose key contributions are an efficient optimized sum check protocol and a robust enhanced verification mechanism. Specifically, we first propose an algorithm that enables efficient proving of both batch and collaborative CNN predictions by com bining sumcheck claims of multiple matrix multiplications into one. Moreover, we introduce a non-interactive sumcheck protocol with malicious security (NM-Sumcheck) to serve as a building block for publicly verifying matrix multiplication operations. Furthermore, we introduce a verifiable method for transforming nonlinear operations into matrix operations, enabling their sub sequent evaluation with the NM-Sumcheck protocol. Our EIV CNN provides malicious security, guarantees public verifiability, and preserves model privacy. Empirical results demonstrate that our sumcheck framework achieves constant prover time, verifier time, and proof size. Compared to the state-of-the-art, it achieves up to a 128.56× reduction in prover time, along with significant reductions in communication overhead and enhanced scalability. Zhongkai Lu, Meng Li 0006, Jingjing Wang 0003, Huaqun Wang |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | DeSA: Decentralized Secure Aggregation for Federated Learning in Zero-Trust D2D NetworksabstractSecure Aggregation (SA) is a fundamental privacy-preserving technique in Federated Learning (FL) that ensures the confidentiality of local model updates while enabling global model aggregation. Previous studies have implemented SA within the FL architecture that includes a central server. However, in a Device-to-Device (D2D) based FL, decentralized SA becomes challenging due to the lack of a central server, particularly in a zero-trust network vulnerable to Byzantine attacks. To address this issue, we present a novel Byzantine-robust decentralized SA protocol (DeSA) that guarantees the integrity of model training and aggregation while protecting the privacy of model updates. Specifically, we utilize an enhanced zk-SNARK proof system to verify the local model training process. Additionally, we propose a framework that embeds multiple zero-knowledge proofs to ensure the integrity of model aggregation, while maintaining succinct proofs and fast verification. Moreover, we present a Byzantine-robust D2D aggregation protocol that can withstand malicious nodes trying to disrupt model aggregation. To protect privacy, we develop a one-time masking method that eliminates aggregated masks through a dynamic aggregation strategy. This strategy takes into account the adjacency and trust relationships among nodes in evolving network topologies. Finally, we perform a theoretical analysis and evaluate DeSA on real-world datasets. Experimental results show that the time required to verify an embedded proof is significantly reduced compared to the time of verifying multiple proofs. Additionally, its accuracy remains robust against malicious nodes. Zhongkai Lu, Meng Li 0006, Jingjing Wang 0003, Keke Gai, Xiaofeng Chen 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | TMT-FL: Enabling Trustworthy Model Training of Federated Learning With Malicious ParticipantsabstractFederated learning is a widely used method for collaborative machine learning without sharing local data. In this approach, participants train models using their local data, and the model updates are aggregated into a global model. However, ensuring trustworthy model training is crucial because malicious participants may not use their actual local data or may not train the model as intended, which makes it challenging to guarantee the authenticity of the data and the integrity of the model training. To address these issues, we propose a trustworthy model training scheme (TMT-FL) with verifiable authenticity and integrity. Specifically, we leverage zero-knowledge succinct non-interactive argument of knowledge (zk-SNARK) based proofs to verify the integrity of the training execution. To deal with the performance bottleneck in generating zk-SNARK proofs, we use the Chinese Remainder Theorem to optimize the convolution operation, and present an improved zk-SNARK based proof generating scheme which significantly reduces the online proving time. Besides, we adopt matrix commitment along with bloom filter to ensure the authenticity and integrity of the training datasets. Extensive experimental results demonstrate that our improved zk-SNARK scheme performs nearly$3.1\times$faster than the state-of-the-art in online proving time. Moreover, we experimentally confirm the efficiency of TMT-FL under diverse datasets in terms of computational costs, storage costs, and communication overheads. Zhongkai Lu, Zhengyin Zhang, Mei Huang, Jingjing Wang 0003, Meng Li 0006 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2023 | Towards Privacy-Preserving Decentralized Reputation Management for Vehicular Crowdsensing
Zhongkai Lu, Ke Geng |
APPT | 1 |
| 2023 | PPCE: Privacy-Preserving Contribution Evaluation for Fairness-Aware Federated LearningabstractContribution evaluation is an important phase in fairness-aware federated learning which provides a significant basis for client selection and incentive distribution. However, most existing contribution evaluation schemes have been proposed without considering privacy protection, which will directly cause privacy attacks and affect the clients’ willingness to participate in a federated learning task. To address this issue, we present a privacy-preserving contribution evaluation scheme (PPCE) based on gradient Shapley, arithmetic sharing, shuffling, and asymmetric encryption for fairness-aware federated learning. To be specific, we leverage arithmetic sharing to achieve the reconstruction and utility evaluation of the sub-model which is needed in the gradient Shapley under the premise of privacy protection. Besides, we use shuffling and asymmetric encryption to ensure the privacy of test data which is collected from the participanting clients for the sake of fairness. We also analyze the privacy and security of PPCE. Finally, we prototype PPCE and estimate the performance using classical neural networks and real datasets. The results show that PPCE achieves high performance in terms of computational costs. Ke Geng, Zhengyin Zhang, Zhongkai Lu, Mei Huang |
ICPADS | 4 |
| 2023 | Enhancing privacy preservation and trustworthiness for decentralized federated learning
Xueqin Zhao, Zhongkai Lu, Shouxun Zhang |
Inf. Sci. | 3 |