EDBT 2026 Demo / reviewers in the wild / expert
Chuan Xu 0002
dblp:43/6131-2
· DBLP profile ↗
17ranked-venue papers
7as first author
8since 2021 · last 2026
0009-0000-0696-9224ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 7 · 2 first-author · 2 since 2021Systems, architecture and hardware · 3 · 2 first-author · 2 since 2021Security and privacy · 3 · 3 since 2021Computer networks · 2 · 2 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Federated Learning for Collaborative Inference Systems: The case of early exit networksabstractIn today’s increasingly diverse computing landscape, end devices like sensors and smartphones are progressively equipped with AI models tailored to their local memory and computational constraints. Local inference reduces communication costs and latency; however, these smaller models typically underperform compared to more sophisticated models deployed on edge servers or in the cloud. Collaborative Inference Systems (CISs) address this performance trade-off by enabling smaller devices to offload part of their inference tasks to more capable devices. These systems often deploy hierarchical models that share numerous parameters, exemplified by deep neural networks that utilize strategies like early exits or ordered dropout. In such instances, Federated Learning (FL) may be employed to jointly train the models within a CIS. Yet, traditional training methods have overlooked the operational dynamics of CISs during inference, particularly the potential high heterogeneity in serving rates across the devices within a given CIS. To address this gap, we propose a novel FL approach that explicitly accounts for variations in serving rates within CISs. Our framework not only offers rigorous theoretical guarantees but also surpasses state-of-the-art training algorithms for CISs, especially in scenarios where end devices handle higher inference request rates and where data availability is uneven across devices. Chuan Xu 0002, Caelin Kaplan, Angelo Rodio, Tareq Si Salem, Giovanni Neglia |
Perform. Evaluation | 1 |
| 2025 | Attribute Inference Attacks for Federated Regression TasksabstractFederated Learning (FL) enables multiple clients, such as mobile phones and IoT devices, to collaboratively train a global machine learning model while keeping their data localized. However, recent studies have revealed that the training phase of FL is vulnerable to reconstruction attacks, such as attribute inference attacks (AIA), where adversaries exploit exchanged messages and auxiliary public information to uncover sensitive attributes of targeted clients. While these attacks have been extensively studied in the context of classification tasks, their impact on regression tasks remains largely unexplored. In this paper, we address this gap by proposing novel model-based AIAs specifically designed for regression tasks in FL environments. Our approach considers scenarios where adversaries can either eavesdrop on exchanged messages or directly interfere with the training process. We benchmark our proposed attacks against state-of-the-art methods using real-world datasets. The results demonstrate a significant increase in reconstruction accuracy, particularly in heterogeneous client datasets, a common scenario in FL. The efficacy of our model-based AIAs makes them better candidates for empirically quantifying privacy leakage for federated regression tasks. Francesco Diana, Othmane Marfoq, Chuan Xu 0002, Giovanni Neglia, Frédéric Giroire, Eoin Thomas |
AAAI | 3 |
| 2025 | Cutting Through Privacy: A Hyperplane-Based Data Reconstruction Attack in Federated LearningabstractFederated Learning (FL) enables collaborative training of machine learning models across distributed clients without sharing raw data, ostensibly preserving data privacy. Nevertheless, recent studies have revealed critical vulnerabilities in FL, showing that a malicious central server can manipulate model updates to reconstruct clients’ private training data. Existing data reconstruction attacks have important limitations: they often rely on assumptions about the clients’ data distribution or their efficiency significantly degrades when batch sizes exceed just a few tens of samples. In this work, we introduce a novel data reconstruction attack that overcomes these limitations. Our method leverages a new geometric perspective on fully connected layers to craft malicious model parameters, enabling the perfect recovery of arbitrarily large data batches in classification tasks without any prior knowledge of clients’ data. Through extensive experiments on both image and tabular datasets, we demonstrate that our attack outperforms existing methods and achieves perfect reconstruction of data batches two orders of magnitude larger than the state of the art. Francesco Diana, André Nusser, Chuan Xu 0002, Giovanni Neglia |
UAI | 3 |
| 2024 | Link Inference Attacks in Vertical Federated Graph LearningabstractVertical Federated Graph Learning (VFGL) is a novel privacy-preserving technology that enables entities to collaborate on training Machine Learning (ML) models without exchanging their raw data. In VFGL, some of the entities hold a graph dataset capturing sensitive user relations, as in the case of social networks. This collaborative effort aims to leverage diverse features from each entity about shared users to enhance predictive models or recommendation systems, while safeguarding data privacy in the process. Despite these advantages, recent studies have revealed a critical vulnerability that appears in intermediate data representations, which may inadvertently expose link information in the graph. This work proposes a novel Link Inference Attack (LIA) that exploits gradients as a new source of link information leakage. Assuming a semi-honest adversary, we demonstrate through extensive experiments on seven real-world datasets that our LIA outperforms state-of-the-art attacks, achieving over 10% higher Area Under the Curve (AUC) in some instances, thereby highlighting a significant risk of link information leakage through gradients. Our attack’s effectiveness primarily stems from label information embedded in gradients, as evidenced by comparison with a label-only LIA. We analytically derive our Label-based LIA’s accuracy using graph characteristics, assessing target graph vulnerability. To address these vulnerabilities, we evaluate two types of defenses: edge perturbation based on differential privacy and a novel label perturbation approach, demonstrating that our proposed label perturbation defense is more effective against all attack types across all datasets examined, offering a more favorable privacy-utility trade-off. Our comprehensive analysis shows why LIAs are effective and identifies potential defenses, highlighting the need for further research to improve the security of VFGL systems against link information leakage. Oualid Zari, Chuan Xu 0002, Javier Parra-Arnau, Ayse Ünsal, Melek Önen |
ACSAC | 2 |
| 2024 | A Cautionary Tale: On the Role of Reference Data in Empirical Privacy DefensesabstractWithin the realm of privacy-preserving machine learning, empirical privacy defenses have been proposed as a solution to achieve satisfactory levels of training data privacy without a significant drop in model utility. Most existing defenses against membership inference attacks assume access to reference data, defined as an additional dataset coming from the same (or a similar) underlying distribution as training data. Despite the common use of reference data, previous works are notably reticent about defining and evaluating reference data privacy. As gains in model utility and/or training data privacy may come at the expense of reference data privacy, it is essential that all three aspects are duly considered. In this paper, we conduct the first comprehensive analysis of empirical privacy defenses. First, we examine the availability of reference data and its privacy treatment in previous works and demonstrate its necessity for fairly comparing defenses. Second, we propose a baseline defense that enables the utility-privacy tradeoff with respect to both training and reference data to be easily understood. Our method is formulated as an empirical risk minimization with a constraint on the generalization error, which, in practice, can be evaluated as a weighted empirical risk minimization (WERM) over the training and reference datasets. Although we conceived of WERM as a simple baseline, our experiments show that, surprisingly, it outperforms the most well-studied and current state-of-the-art empirical privacy defenses using reference data for nearly all relative privacy levels of reference and training data. Our investigation also reveals that these existing methods are unable to trade off reference data privacy for model utility and/or training data privacy, and thus fail to operate outside of the high reference data privacy case. Overall, our work highlights the need for a proper evaluation of the triad model utility / training data privacy / reference data privacy when comparing privacy defenses. Caelin Kaplan, Chuan Xu 0002, Othmane Marfoq, Giovanni Neglia, Anderson Santana de Oliveira |
Proc. Priv. Enhancing Technol. | 2 |
| 2021 | Time-Optimal Self-Stabilizing Leader Election in Population ProtocolsabstractWe consider the standard population protocol model, where (a priori) indistinguishable and anonymous agents interact in pairs according to uniformly random scheduling. The self-stabilizing leader election problem requires the protocol to converge on a single leader agent from any possible initial configuration. We initiate the study of time complexity of population protocols solving this problem in its original setting: with probability 1, in a complete communication graph. The only previously known protocol by Cai, Izumi, and Wada [Theor. Comput. Syst. 50] runs in expected parallel time Θ(n2) and has the optimal number of n states in a population of n agents. The existing protocol has the additional property that it becomes silent, i.e., the agents' states eventually stop changing. Janna Burman, Ho-Lin Chen, Hsueh-Ping Chen, David Doty, Thomas Nowak 0001, Eric E. Severson, Chuan Xu 0002 |
PODC | 7 |
| 2021 | Local Model Privacy-Preserving Study for Federated Learning
Kaiyun Pan, Daojing He, Chuan Xu 0002 |
SecureComm (1) | 3 |
| 2021 | Dynamic backup workers for parallel machine learning
Chuan Xu 0002, Giovanni Neglia, Nicola Sebastianelli |
Comput. Networks | 1 |
| 2020 | Decentralized gradient methods: does topology matter?abstractConsensus-based distributed optimization methods have recently been advocated as alternatives to parameter server and ring all-reduce paradigms for large scale training of machine learning models. In this case, each worker maintains a local estimate of the optimal parameter vector and iteratively updates it by averaging the estimates obtained from its neighbors, and applying a correction on the basis of its local dataset. While theoretical results suggest that worker communication topology should have strong impact on the number of epochs needed to converge, previous experiments have shown the opposite conclusion. This paper sheds lights on this apparent contradiction and show how sparse topologies can lead to faster convergence even in the absence of communication delays. Giovanni Neglia, Chuan Xu 0002, Don Towsley, Gianmarco Calbi |
AISTATS | 2 |
| 2020 | Dynamic Backup Workers for Parallel Machine Learning
Chuan Xu 0002, Giovanni Neglia, Nicola Sebastianelli |
Networking | 1 |
| 2020 | Throughput-Optimal Topology Design for Cross-Silo Federated LearningabstractFederated learning usually employs a client-server architecture where an orchestrator iteratively aggregates model updates from remote clients and pushes them back a refined model. This approach may be inefficient in cross-silo settings, as close-by data silos with high-speed access links may exchange information faster than with the orchestrator, and the orchestrator may become a communication bottleneck. In this paper we define the problem of topology design for cross-silo federated learning using the theory of max-plus linear systems to compute the system throughput---number of communication rounds per time unit. We also propose practical algorithms that, under the knowledge of measurable network characteristics, find a topology with the largest throughput or with provable throughput guarantees. In realistic Internet networks with 10~Gbps access links for silos, our algorithms speed up training by a factor 9 and 1.5 in comparison to the master-slave architecture and to state-of-the-art MATCHA, respectively. Speedups are even larger with slower access links. Othmane Marfoq, Chuan Xu 0002, Giovanni Neglia, Richard Vidal |
NeurIPS | 2 |
| 2020 | Data collection in population protocols with non-uniformly random scheduler
Chuan Xu 0002, Joffroy Beauquier, Janna Burman, Shay Kutten, Thomas Nowak 0001 |
Theor. Comput. Sci. | 1 |
| 2017 | Data Collection in Population Protocols with Non-uniformly Random Scheduler
Joffroy Beauquier, Janna Burman, Shay Kutten, Thomas Nowak 0001, Chuan Xu 0002 |
ALGOSENSORS | 5 |
| 2017 | Power-Aware Population ProtocolsabstractIn this paper, we propose a formal energy model which allows an analytical study of energy consumption, for the first time in the context of population protocols (PP). In PP, anonymous and bounded memory agents move unpredictably and communicate in pairs. In order to illustrate the power and the usefulness of the proposed energy model, we develop a new power-aware protocol (EB-TTFM) for the task of data collection. The analytical results show that, in terms of energy consumption, EB-TTFM outperforms a known data collection protocol under certain conditions. Finally, we present a lower bound concerning energy consumption of any possible data collection protocol in PP, which also justifies the efficiency of EB-TTFM. Chuan Xu 0002, Janna Burman, Joffroy Beauquier |
ICDCS | 1 |
| 2015 | A Sampling Method to Chance-constrained Semidefinite Optimization
Chuan Xu 0002, Jianqiang Cheng, Abdel Lisser |
ICORES | 1 |
| 2014 | A Multicommodity Formulation for Routing in Healthcare Wireless Body Area NetworksabstractInternational audience Pablo Adasme, Abdel Lisser, Chuan Xu 0002 |
ICORES | 3 |
| 2014 | The p-Median Problem with Concave CostsabstractInternational audience Chuan Xu 0002, Abdel Lisser, Janny Leung, Marc Letournel |
ICORES | 1 |