EDBT 2026 Demo / reviewers in the wild / expert
Zhe Sun 0005
dblp:43/8664-5
· DBLP profile ↗
18ranked-venue papers
5as first author
16since 2021 · last 2026
0000-0002-4633-7675ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 1 first-author · 5 since 2021Security and privacy · 6 · 2 first-author · 5 since 2021Systems, architecture and hardware · 2 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Robust Single-Message Shuffle Differential Privacy Protocol for Accurate Distribution EstimationabstractShuffler-based differential privacy (shuffle-DP) is a privacy paradigm providing high utility by involving a shuffler to permute noisy report from users. Existing shuffle-DP protocols mainly focus on the design of shuffler-based categorical frequency oracle (SCFO) for frequency estimation on categorical data. However, numerical data is a more prevalent type and many real-world applications depend on the estimation of data distribution with ordinal nature. In this paper, we study the distribution estimation under pure shuffle model, which is a prevalent shuffle-DP framework without strong security assumptions. We initially attempt to transplant existing SCFOs and the naïve distribution recovery technique to this task, and demonstrate that these baseline protocols cannot simultaneously achieve outstanding performance in three metrics: 1) utility, 2) message complexity; and 3) robustness to data poisoning attacks. Therefore, we further propose a novel single-message \textit{adaptive shuffler-based piecewise} (ASP) protocol with high utility and robustness. In ASP, we first develop a randomizer by parameter optimization using our proposed tighter bound of mutual information. We also design an \textit{Expectation Maximization with Adaptive Smoothing} (EMAS) algorithm to accurately recover distribution with enhanced robustness. To quantify robustness, we propose a new evaluation framework to examine robustness under different attack targets, enabling us to comprehensively understand the protocol resilience under various adversarial scenarios. Extensive experiments demonstrate that ASP outperforms baseline protocols in all three metrics. Especially under small $ε$ values, ASP achieves an order of magnitude improvement in utility with minimal message complexity, and exhibits over threefold robustness compared to baseline methods. Yaowei Huang, Qingqing Ye 0001, Haonan Yan, Ke Pan 0001, Zhe Sun 0005 |
ICDE | 8 |
| 2026 | Triggers Magic Mirror: Trigger Inversion for Backdoor Detection in Non-IID Federated Learning
Zhe Sun 0005, Yufu Zou, Lihua Yin, Tianqing Zhu, Xu Zhang 0021, Yuanyuan He 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | A Log-Likelihood Chain Framework for Defending Against LDP Data Poisoning AttacksabstractLocal differential privacy (LDP) provides strict privacy guarantee in a distributed environment. Recent studies demonstrated that LDP protocols are vulnerable to data poisoning attacks where an attacker can manipulate the perturbed result on the local side and send bogus data to skew the final estimate on the server. Unfortunately, existing attack detections do not create an effective attack indicator and rely on particular characteristics of LDP protocols. As a result, they typically exhibit limited detection performance. In this paper, we use log-likelihood as the attack indicator and propose a chain-style detection to enhance the detection effectiveness, in which the attack impact could propagate along the chain and exhibit clear anomaly signal even under stealthy attack scenarios. The experimental results show that our detection consistently outperforms the existing methods. Using four datasets containing categorical and numerical data separately, our detection achieves an F1 score exceeding 96% in most cases. It even remains above 0.9 under stealthy attack settings, outperforming the state-of-the-art detection by up to 0.25. Yuxin Wen, Haonan Yan, Yahong Chen, Zhe Sun 0005, Hui Li 0006, Xiaodong Lin 0001 |
IEEE Trans. Knowl. Data Eng. | 6 |
| 2026 | PPBR: Privacy-Preserving and Byzantine-Robust Edge-Assisted Hierarchical Federated Learning in Mobile NetworksabstractEdge-assisted Hierarchical Federated Learning (EHFL) accelerates global model training across mobile devices by hierarchically aggregating models. However, EHFL encounters critical challenges such as privacy risks for local and edge-level models, vulnerability to collusive Byzantine attacks, and issues with model diversity and heterogeneity due to Non-Independent and Identically Distributed (Non-IID) data. In this paper, we propose PPBR, a novel hybrid scheme that subtly integrates Condensed Local Differential Privacy (CLDP) and Packed Linearly Homomorphic Encryption (PLHE) to achieve strong privacy protection and resilience against various Byzantine attacks in Non-IID data scenarios. Specifically, PPBR clusters the sign statistics of local models and clips the norms of edge-level momenta to filter anomalous models and mitigate Byzantine faults while retaining diverse models coming from Non-IID data. To enhance privacy protection with acceptable accuracy loss, the sign tuples of local models are perturbed with CLDP guarantees, and the momenta of edge-level models are encrypted under PLHE. Meanwhile, PPBR enhances privacy in single-edge-server and single-cloud-server aggregations by using random perturbations, secret sharing, and PLHE. In addition to safeguarding privacy with accommodating abrupt dropouts of mobile devices and edge servers, the aggregations effectively mitigate the adverse effects of Non-IID data under advanced Byzantine attacks. Theoretical analysis and comprehensive experiments validate PPBR's strong privacy guarantees and resilience to various Byzantine attacks under Non-IID data. Yuanyuan He 0002, Peng Yang 0004, Zhe Sun 0005, Xuemin Shen |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | OPMonitor: Continuously monitoring residual over-granted permissions in verified access control policies
Yunchuan Guo, Zhe Sun 0005, Mingjie Yu, Fenghua Li 0001, Liang Fang 0009 |
Comput. Secur. | 3 |
| 2025 | Recipient-Aware Photo Automatic Deletion Control Policy Recommendation Scheme in Online Social NetworksabstractContent sharing, whether in Online Social Networks (OSNs) or even in the Internet of Things (IoT), serves as a pivotal link in the flow of data. To better protect the privacy of shared content, current OSNs allow sharers to manually set policies for uploaded content. However, this method of policy setting is not suitable for scenarios where IoT is deeply integrated with OSNs, as IoT devices often share content frequently and automatically. To address this issue, we propose the design, implementation, and evaluation of SmartCircles, a personalized photo-sharing and automatic deletion scheme. SmartCircles can function as a plugin within existing OSNs, supporting operations on various smart devices. It encompasses the following steps: a) Before sharing a photo, calculate the intimacy level depicted in the photo and the sharer's willingness to share. b) Before the recipient views the photo, calculate the intimacy between the sharer and the recipient, and evaluate feedback from the recipient. c) Based on the results computed above and a trade-off between profit and loss, recommend a recipient-aware automatic deletion control policy for the photo. We implement a prototype of SmartCircles, and the evaluation results demonstrate its effectiveness with an accuracy rate of policy recommendations reaching approximately 92%. Haiyang Luo, Zhe Sun 0005, Yunqing Sun, Ang Li 0005, Binghui Wang, Jin Cao 0001, Ben Niu 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | SuperMPFL: A Supermask-Based Mechanism for Personalized Federated LearningabstractPersonalized federated learning (PFL) is a specialized application of the federated learning paradigm designed to support personalized use cases. Unlike traditional federated learning, which aims to train a high-quality global model, the goal of PFL is to tailor a model that best fits each individual user. Most existing PFL approaches adopt training architectures similar to those used in traditional federated learning, relying on global or partial model sharing during training. While this helps improve model personalization across clients, it also introduces a range of challenges, including risks of data leakage and increased communication overhead. To address these challenges, we propose a novel personalized federated learning (PFL) framework called SuperMPFL, which leverages supermasks to effectively tackle issues related to accuracy, privacy, and efficiency. In particular, the SuperMPFL technique utilizes masking and ranking strategies to obscure the true gradient information. By converting gradients into ranked numerical representations, this approach enhances privacy protection during the training process. Furthermore, this approach reduces communication overhead by transmitting significantly less information compared to conventional methods. In SuperMPFL, each client receives the global model and then emphasizes its personalized parameters, particularly at the model’s edges. This design not only improves accuracy but also strengthens robustness against privacy attacks. Evaluations on standard federated learning benchmarks demonstrate the superiority of our approach, which outperforms state-of-the-art methods in terms of accuracy, privacy, and efficiency. Zhe Sun 0005, Shangzhe Li, Lihua Yin, Yahong Chen, Aohai Zhang, Meifan Zhang, Yuanyuan He 0002 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2024 | EM2FL: An Embedding Multimodal Fusion Federated Learning Approach to Optimize Privacy and PerformanceabstractMultimodal federated learning enhances model performance by integrating data from different modalities. However, this integration also introduces new privacy leakage risk associated with cross-modal correlation. Existing differential privacy methods are primarily designed for single-modal data, making them ineffective in multimodal scenarios, while noise addition often compromises data utility. In this paper, we propose an Embedding Multimodal Fusion Federated Learning Approach, called EM2FL. This approach leverages horizontal multimodal federated learning to collaboratively train global models across multiple data platforms without exposing raw private data. Instead of applying differential privacy to each modality-specific encoder separately, we implement it on the mixed embedding module that combines multiple modalities. We tested our approach on 3 distinct models and validated its effectiveness for the combination of image and user-item pair modalities. Experimental results show that our method improves performance by 10-20% compared to traditional differential privacy methods while maintaining a similar level of privacy protection. This demonstrates that EM2FL effectively balances privacy and performance through selective noise addition. Zhe Sun 0005, Jiewei Wu, Chao Li 0027, Chonghua Wang, Yufu Zou, Shutong Yang, Yaowei Huang |
HPCC | 1 |
| 2024 | Survey on Privacy-preserving Techniques for Graph Neural Networks in Federated Learning ParadigmabstractFederated learning, as an emerging distributed machine learning paradigm, allows multiple parties to jointly train models without sharing raw data, thus solving the data silo problem and enhancing data privacy protection. As a powerful tool for processing graph-structured data, graph neural networks (GNNs) have shown great potential in many fields. Federated graph neural networks (FGNNs) combine the advantages of both, allowing data from different institutions to remain localized while utilizing GNNs to model complex graph-structured data, promoting multi-party collaborative training without directly exchanging data. However, the application of FGNNs in distributed environments faces many challenges, especially in protecting data privacy. This survey aims to comprehensively explore the privacy protection technology of FGNNs, covering the privacy protection mechanism of nodes, edges, and models, while also discussing the benefits and drawbacks of each approach. Finally, the future research directions of privacy protection technology in federated graph neural networks are discussed. Zhe Sun 0005, Rundong Shao, Yufu Zou, Chao Li 0027, Nan Wei |
HPCC | 1 |
| 2024 | An Autoencoder-Based Hybrid Detection Model for Intrusion Detection With Small-Sample ProblemabstractCyber-attacks have become more frequent, targeted, and complex as the exponential growth in computer networks and the development of Internet of Things (IoT). Network intrusion detection system (NIDS) is an important and essential tool to protect network environments. However, the low performance of a NIDS against small malicious samples has seriously threatened the security of networks, thus directly leading to the loss of personal property and national interests. Given this, we propose an auto encoder-based hybrid detection model, abbreviated as AHDM, for the intrusion detection with small-sample problem. AHDM has a dual classifier framework. It trains first neural network based on the encoding features obtained from the autoencoder feature enhancement algorithm to detect small-sample malicious traffic. It trains second neural network using the original features to detect normal traffic and large-sample malicious traffic. The final detection result of malicious traffic is obtained by combining the detection results of the two neural networks. In experiments, we use three classic datasets (KDD CUP 99, CIC-IDS-2017, and IOT-23) and simulate the malicious traffic detection targeting extremely small-sample malicious traffic. The results show that AHDM has a higher detection rate for small-sample malicious traffic compared to the advanced detection models (DNN and ACID). In the IOT-23 dataset, the AHDM model shows an absolute advantage in detecting DDoS type of malicious traffic, with a detection rate of 0.71, which is much higher than the DNN (0.14) and ACID (0.14) models. Nan Wei, Lihua Yin, Jingyi Tan, Chuhong Ruan, Chuang Yin, Zhe Sun 0005 |
IEEE Trans. Netw. Serv. Manag. | 6 |
| 2024 | PriMonitor: An adaptive tuning privacy-preserving approach for multimodal emotion detection
Lihua Yin, Sixin Lin, Zhe Sun 0005, Yuanyuan He 0002 |
World Wide Web (WWW) | 3 |
| 2023 | Go-Sharing: A Blockchain-Based Privacy-Preserving Framework for Cross-Social Network Photo SharingabstractThe evolution of social media has led to a trend of posting daily photos on online Social Network Platforms (SNPs). The privacy of online photos is often protected carefully by security mechanisms. However, these mechanisms will lose effectiveness when someone spreads the photos to other platforms. In this article, we propose Go-sharing, a blockchain-based privacy-preserving framework that provides powerful dissemination control for cross-SNP photo sharing. In contrast to security mechanisms running separately in centralized servers that do not trust each other, our framework achieves consistent consensus on photo dissemination control through carefully designed smart contract-based protocols. We use these protocols to create platform-free dissemination trees for every image, providing users with complete sharing control and privacy protection. Considering the possible privacy conflicts between owners and subsequent re-posters in cross-SNP sharing, we design a dynamic privacy policy generation algorithm that maximizes the flexibility of re-posters without violating formers’ privacy. Moreover, Go-sharing also provides robust photo ownership identification mechanisms to avoid illegal reprinting. It introduces a random noise black box in a two-stage separable deep learning process to improve robustness against unpredictable manipulations. Through extensive real-world simulations, the results demonstrate the capability and effectiveness of the framework across a number of performance metrics. Zhe Sun 0005, Hui Li 0006, Ben Niu 0001, Fenghua Li 0001, Zixu Zhang, Chunhao Zheng |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | Crafting Text Adversarial Examples to Attack the Deep-Learning-based Malicious URL DetectionabstractDetecting malicious URLs is of great significance to reduce cyber crimes and maintain Internet security. Currently, Deep Learning (DL) techniques have been widely used to improve the classical malicious URL detection models, as DL-based detection models can perform an in-depth analysis of the text information of the URL, and detect the fishing URLs of unknown cyber attack types with high accuracy. Any missed blocking of malicious URLs can potentially result in a huge loss of information and property. In this paper, we focus on the vulnerability of the existing DL-based malicious URL detection models and show that they are sensitive to adversarial samples. First, we construct URL adversarial samples based on the component-level and character-level perturbations and use them to attack mainstream DL-based detection models, resulting in obvious decreases in the detection accuracies. Meanwhile, the perturbations are under the constraints that each adversarial sample URL is hardly distinguished from the original URL with naked eyes. Furthermore, under most circumstances, the adversarial samples constructed by replacing 14 types of characters and perturbing other all components except the scheme component lead to the largest increased number of missed blocking of malicious URLs, i.e., a bigger drop in the accuracy than other constructed methods. Finally, extensive experiments demonstrate the effectiveness of our adversarial examples. Even if the adversarial training is used against our adversarial samples, the adversarial samples still work and bring oblivious decreases in their accuracy. Zuquan Peng, Yuanyuan He 0002, Zhe Sun 0005, Jianbing Ni, Ben Niu 0001, Xianjun Deng |
ICC | 3 |
| 2022 | TPRPF: a preserving framework of privacy relations based on adversarial training for texts in big data
Yuhan Chai, Zhe Sun 0005, Jing Qiu 0002, Lihua Yin, Zhihong Tian 0001 |
Frontiers Comput. Sci. | 2 |
| 2022 | EmoMix+: An Approach of Depression Detection Based on Emotion Lexicon for Mobile ApplicationabstractEmotion lexicon is an important auxiliary resource for text emotion analysis. Previous works mainly focused on positive and negative classification and less on fine-grained emotion classification. Researchers use lexicon-based methods to find that patients with depression express more negative emotions on social media. Emotional characteristics are an effective feature in detecting depression, but the traditional emotion lexicon has limitations in detecting depression and ignores many depression words. Therefore, we build an emotion lexicon for depression to further study the differences between healthy users and patients with depression. The experimental results show that the depression lexicon constructed in this paper is effective and has a better effect of classifying users with depression. Yuanfei Zhang, Lihua Yin, Zhe Sun 0005, Zheng Lin 0001, Peng Fu 0008, Weiping Wang 0005 |
Secur. Commun. Networks | 4 |
| 2021 | A blockchain-based collaborative training method for multi-party data sharing
Lihua Yin, Jiyuan Feng, Sixin Lin, Zhe Sun 0005 |
Comput. Commun. | 5 |
| 2020 | The QoS and privacy trade-off of adversarial deep learning: An evolutionary game approach
Zhe Sun 0005, Lihua Yin, Chao Li 0027, Weizhe Zhang, Ang Li 0005, Zhihong Tian 0001 |
Comput. Secur. | 1 |
| 2019 | HideMe: Privacy-Preserving Photo Sharing on Social NetworksabstractPhoto sharing on Online Social Networks (OSNs) has become one of the most popular social activities in our daily life. However, some associated friends or bystanders in the photos may not want to be viewed due to privacy concerns. In this paper, we propose the design, implementation and evaluation of HideMe, a framework to preserve the associated users’ privacy for online photo sharing. HideMe acts as a plugin to existing photo sharing OSNs, and it enables the following: a) extraction of factors when users upload their photos, b) associated friends in the uploaded photos are able to set their own privacy policies based on scenarios, instead of a photo-by-photo setting, c) any user in other friend’s uploaded photos could be hidden away from unwanted viewers based on one time policy generation. We also design a distance-based algorithm to identify and protect the privacy of bystanders. Moreover, HideMe not only protects users’ privacy but also reduces the system overhead by a carefully designed face matching algorithm. We have implemented a prototype of HideMe, and evaluation results have demonstrated its effectiveness and efficiency. Fenghua Li 0001, Zhe Sun 0005, Ang Li 0005, Ben Niu 0001, Hui Li 0006, Guohong Cao |
INFOCOM | 2 |