Ning Wang 0022

dblp:46/2005-22 · DBLP profile ↗
← Back
21ranked-venue papers
7as first author
16since 2021 · last 2026
0000-0002-6224-8656ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 5 first-author · 9 since 2021Computer networks · 5 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Noise, Why Can't You Bend? Detecting Adversarial Perturbations in Wireless Sensing via Structural Fragility
Md Hasan Shahriar, Ning Wang 0022, Amit Kumar Sikder, Naren Ramakrishnan, Y. Thomas Hou 0001, Wenjing Lou
AsiaCCS2
2026 EarlyShield: Early-Stage Screening for Robust Personalized Federated Learning
Shixiong Li, Xingyu Lyu, Ning Wang 0022, Tao Li 0042, Danjue Chen, Yimin Chen 0004
PAKDD (2)3
2026 Hermes: Boosting the Performance of Machine-Learning-Based Intrusion Detection System Through Geometric Feature Learning
abstract
Anomaly-Based Intrusion Detection Systems (IDSs) have been extensively researched for their ability to detect zero-day attacks. These systems establish a baseline of normal behavior using benign traffic data and flag deviations from this norm as potential threats. They generally experience higher false alarm rates than signature-based IDSs. Unlike image data, where the observed features provide immediate utility, raw network traffic necessitates additional processing for effective detection. It is challenging to learn useful patterns directly from raw traffic data or simple traffic statistics (e.g., connection duration, package inter-arrival time) as the complex relationships are difficult to distinguish. Therefore, some feature engineering becomes imperative to extract and transform raw data into new feature representations that can directly improve the detection capability and reduce the false positive rate. We propose a geometric feature learning method to optimize the feature extraction process. We employ contrastive feature learning to learn a feature space where normal traffic instances reside in a compact cluster. We further utilize H-Score feature learning to maximize the compactness of the cluster representing the normal behavior, enhancing the subsequent anomaly detection performance. Our evaluations using the NSL-KDD and N-BaloT datasets demonstrate that the proposed IDS powered by feature learning can consistently outperform state-of-the-art anomaly-based IDS methods by significantly lowering the false positive rate. Furthermore, we deploy the proposed IDS on a Raspberry Pi 4 and demonstrate its applicability on resource-constrained Internet of Things (IoT) devices, highlighting its versatility for diverse application scenarios.
Chaoyu Zhang, Shanghao Shi, Ning Wang 0022, Xiangxiang Xu 0001, Shaoyu Li, Lizhong Zheng, Randy Marchany, Mark Gardner, Y. Thomas Hou 0001, Wenjing Lou
IEEE Trans. Netw.3
2025 BoBa: Boosting Backdoor Detection Through Data Distribution Inference in Federated Learning
abstract
Federated learning, while being a promising approach for collaborative model training, is susceptible to backdoor attacks due to its decentralized nature. Backdoor attacks have shown remarkable stealthiness, as they compromise model predictions only when inputs contain specific triggers. As a countermeasure, anomaly detection is widely used to filter out backdoor attacks in FL. However, the non-independent and identically distributed (non-IID) data distribution nature of FL clients presents substantial challenges in backdoor attack detection, as the data variety introduces variance among benign models, making them indistinguishable from malicious ones. In this work, we propose a novel distribution-aware backdoor detection mechanism, BoBa, to address this problem. To differentiate outliers arising from data variety versus backdoor attacks, we propose to break down the problem into two steps: clustering clients utilizing their data distribution, and followed by a voting-based detection. We propose a novel data distribution inference mechanism for accurate data distribution estimation. To improve detection robustness, we introduce an overlapping clustering method, where each client is associated with multiple clusters, ensuring that the trustworthiness of a model update is assessed collectively by multiple clusters rather than a single cluster. Through extensive evaluations, we demonstrate that BoBa can reduce the attack success rate to lower than 0.001 while maintaining high main task accuracy across various attack strategies and experimental settings.
Zhengyuan Jiang, Xingyu Lyu, Shanghao Shi, Yang Xiao 0010, Yimin Chen 0004, Y. Thomas Hou 0001, Wenjing Lou, Ning Wang 0022
ECAI8
2025 Let the Noise Speak: Harnessing Noise for a Unified Defense Against Adversarial and Backdoor Attacks
Md Hasan Shahriar, Ning Wang 0022, Naren Ramakrishnan, Y. Thomas Hou 0001, Wenjing Lou
ESORICS (1)2
2025 Scale-MIA: A Scalable Model Inversion Attack against Secure Federated Learning via Latent Space Reconstruction
Shanghao Shi, Ning Wang 0022, Yang Xiao 0010, Chaoyu Zhang, Yi Shi 0001, Y. Thomas Hou 0001, Wenjing Lou
NDSS2
2025 Beyond Uniformity: Robust Backdoor Attacks on Deep Neural Networks with Trigger Selection
Shixiong Li, Xingyu Lyu, Ning Wang 0022, Tao Li 0042, Danjue Chen, Yimin Chen 0004
PAKDD (6)3
2025 Buffer is All You Need: Defending Federated Learning against Backdoor Attacks under Non-iids via Buffering
abstract
Federated Learning (FL) is a popular paradigm enabling clients to jointly train a global model without sharing raw data. However, FL is known to be vulnerable towards backdoor attacks due to its distributed nature. As participants, attackers can upload model updates that effectively compromise FL. More critically, existing defenses are mostly designed under independent-and-identically-distributed (iid) settings, hence neglecting the fundamental non-iid characteristic of FL. Here we propose FLBuff for tackling backdoor attacks even under non-iids. The main challenge for such defenses is that non-iids shorten the distance between benign and malicious updates, rendering them harder to separate. FLBuff is inspired by our insight that non-iids can be modeled as omni-directional expansion in representation space while backdoor attacks as uni-directional. This leads to the key design of FLBuff, i.e., a supervised-contrastive-learning model extracting penultimate-layer representations to create a large in-between buffer layer. Comprehensive evaluations demonstrate that FLBuff consistently outperforms state-of-the-art defenses. Code is at https://github.com/xingyushu/FLBuff.
Xingyu Lyu, Ning Wang 0022, Yang Xiao 0010, Shixiong Li, Tao Li 0042, Danjue Chen, Yimin Chen 0004
TrustCom2
2025 FeCo: Boosting Intrusion Detection Capability in IoT Networks via Contrastive Learning
abstract
Over the last decade, Internet of Things (IoT) has permeated our daily life with a broad range of applications. However, a lack of adequate security in IoT devices renders IoT systems vulnerable to various network-based cyberattacks, potentially causing severe damage. Recent works have explored using machine learning to build anomaly detection models for defending against such attacks. In this paper, we propose FeCo, a federated-contrastive-learning framework that coordinates in-network IoT devices to jointly learn intrusion detection models. FeCo utilizes federated learning to alleviate users’ privacy concerns as participating devices only submit their model parameters rather than raw local data. Compared to previous works, we develop a novel representation learning method based on contrastive learning that is able to learn a more accurate model for the benign class. FeCo significantly improves the intrusion detection accuracy compared to previous works. In addition, we implement a two-step feature selection scheme to avoid overfitting and reduce computation time. Through extensive experiments on the NSL-KDD dataset and the BaIoT dataset, we demonstrate that FeCo achieves as high as 8% accuracy improvement compared to the state-of-the-art and is robust to non-independent and identically distributed (non-IID) data. Our implementation of FeCo on a Raspberry Pi device further confirms the applicability of FeCo for resource-constrained IoT devices.
Ning Wang 0022, Shanghao Shi, Yimin Chen 0004, Wenjing Lou, Y. Thomas Hou 0001
IEEE Trans. Dependable Secur. Comput.1
2025 FLARE: Defending Federated Learning Against Model Poisoning Attacks via Latent Space Representations
abstract
Federated learning (FL) has been shown vulnerable to a new class of adversarial attacks, known asmodel poisoning attacks (MPA), where one or more malicious clients try to poison the global model by sending carefully crafted local model updates to the central parameter server. Existing defenses that have been fixated on analyzing model parameters show limited effectiveness in detecting such malicious models. In this work, we proposeFLARE, a robust model aggregation mechanism for FL, which is resilient against state-of-the-art MPAs. Instead of solely depending on model parameters,FLAREleverages thepenultimate layer representations (PLRs)of the model for characterizing the adversarial influence on each local model update. We further propose a trust evaluation method that estimates a trust score for each model update based on pairwise PLR discrepancies among all model updates. Under the assumption of honest majority,FLAREassigns a low trust score to model updates that are far from the benign cluster.FLAREthen aggregates the model updates weighted by their trust scores and finally updates the global model. Extensive experimental results demonstrate the effectiveness ofFLAREin defending FL against various MPAs, including semantic backdoor attacks, trojan backdoor attacks, and untargeted attacks, in various FL systems.
Ning Wang 0022, Chaoyu Zhang, Yang Xiao 0010, Yimin Chen 0004, Wenjing Lou, Y. Thomas Hou 0001
IEEE Trans. Dependable Secur. Comput.1
2024 Hermes: Boosting the Performance of Machine-Learning-Based Intrusion Detection System through Geometric Feature Learning
Chaoyu Zhang, Shanghao Shi, Ning Wang 0022, Xiangxiang Xu 0001, Shaoyu Li, Lizhong Zheng, Randy C. Marchany, Mark Gardner, Y. Thomas Hou 0001, Wenjing Lou
MobiHoc3
2023 MANDA: On Adversarial Example Detection for Network Intrusion Detection System
abstract
With the rapid advancement in machine learning (ML), ML-based Intrusion Detection Systems (IDSs) are widely deployed to protect networks from various attacks. One of the biggest challenges is that ML-based IDSs suffer from adversarial example (AE) attacks. By applying small perturbations (e.g., slightly increasing packet inter-arrival time) to the intrusion traffic, an AE attack can flip the prediction of a well-trained IDS. We address this challenge by proposingMANDA, a MANifold and Decision boundary-based AE detection system. Through analyzing AE attacks, we notice that 1) an AE tends to be close to its original manifold (i.e., the cluster of samples in its original class) regardless of which class it is misclassified into; and 2) AEs tend to be close to the decision boundary to minimize the perturbation scale. Based on the two observations, we designMANDAfor accurate AE detection by exploiting inconsistency between manifold evaluation and IDS model inference and evaluating model uncertainty on small perturbations. We evaluateMANDAon both binary IDS and multi-class IDS on two datasets (NSL-KDD and CICIDS) under three state-of-the-art AE attacks. Our experimental results show thatMANDAachieves high true-positive rate (98.41%) with a 5% false-positive rate.
Ning Wang 0022, Yimin Chen 0004, Yang Xiao 0010, Wenjing Lou, Y. Thomas Hou 0001
IEEE Trans. Dependable Secur. Comput.1
2022 Squeezing More Utility via Adaptive Clipping on Differentially Private Gradients in Federated Meta-Learning
abstract
Federated meta-learning has emerged as a promising AI framework for today’s mobile computing scenes involving distributed clients. It enables collaborative model training using the data located at distributed mobile clients and accommodates clients that need fast model customization with limited new data. However, federated meta-learning solutions are susceptible to inference-based privacy attacks since the global model encoded with clients’ training data is open to all clients and the central server. Meanwhile, differential privacy (DP) has been widely used as a countermeasure against privacy inference attacks in federated learning. The adoption of DP in federated meta-learning is complicated by the model accuracy-privacy trade-off and the model hierarchy attributed to the meta-learning component. In this paper, we introduce DP-FedMeta, a new differentially private federated meta-learning architecture that addresses such data privacy challenges. DP-FedMeta features an adaptive gradient clipping method and a one-pass meta-training process to improve the model utility-privacy trade-off. At the core of DP-FedMeta are two DP mechanisms, namely DP-AGR and DP-AGRLR, to provide two notions of privacy protection for the hierarchical models. Extensive experiments in an emulated federated meta-learning scenario on well-known datasets (Omniglot, CIFAR-FS, and Mini-ImageNet) demonstrate that DP-FedMeta accomplishes better privacy protection while maintaining comparable model accuracy compared to the state-of-the-art solution that directly applies DP-based meta-learning to the federated setting.
Ning Wang 0022, Yang Xiao 0010, Yimin Chen 0004, Ning Zhang 0017, Wenjing Lou, Y. Thomas Hou 0001
ACSAC1
2022 FLARE: Defending Federated Learning against Model Poisoning Attacks via Latent Space Representations
abstract
Federated learning (FL) has been shown vulnerable to a new class of adversarial attacks, known as model poisoning attacks (MPA), where one or more malicious clients try to poison the global model by sending carefully crafted local model updates to the central parameter server. Existing defenses that have been fixated on analyzing model parameters show limited effectiveness in detecting such carefully crafted poisonous models. In this work, we propose FLARE, a robust model aggregation mechanism for FL, which is resilient against state-of-the-art MPAs. Instead of solely depending on model parameters, FLARE leverages the penultimate layer representations (PLRs) of the model for characterizing the adversarial influence on each local model update. PLRs demonstrate a better capability to differentiate malicious models from benign ones than model parameter-based solutions. We further propose a trust evaluation method that estimates a trust score for each model update based on pairwise PLR discrepancies among all model updates. Under the assumption that honest clients make up the majority, FLARE assigns a trust score to each model update in a way that those far from the benign cluster are assigned low scores. FLARE then aggregates the model updates weighted by their trust scores and finally updates the global model. Extensive experimental results demonstrate the effectiveness of FLARE in defending FL against various MPAs, including semantic backdoor attacks, trojan backdoor attacks, and untargeted attacks, and safeguarding the accuracy of FL.
Ning Wang 0022, Yang Xiao 0010, Yimin Chen 0004, Wenjing Lou, Y. Thomas Hou 0001
AsiaCCS1
2022 FeCo: Boosting Intrusion Detection Capability in IoT Networks via Contrastive Learning
abstract
Over the last decade, Internet of Things (IoT) has permeated our daily life with a broad range of applications. However, a lack of sufficient security features in IoT devices renders IoT ecosystems vulnerable to various network intrusion attacks, potentially causing severe damage. Previous works have explored using machine learning to build anomaly detection models for defending against such attacks. In this paper, we propose FeCo, a federated-contrastive-learning framework that coordinates in-network IoT devices to jointly learn intrusion detection models. FeCo utilizes federated learning to alleviate users’ privacy concerns as participating devices only submit their model parameters rather than local data. Compared to previous works, we develop a novel representation learning method based on contrastive learning that is able to learn a more accurate model for the benign class. FeCo significantly improves the intrusion detection accuracy compared to previous works. Besides, we implement a two-step feature selection scheme to avoid overfitting and reduce computation time. Through extensive experiments on the NSL-KDD dataset, we demonstrate that FeCo achieves as high as 8% accuracy improvement compared to the state-of-the-art and is robust to non-IID data. Evaluations on convergence, computation overhead, and scalability further confirm the suitability of FeCo for IoT intrusion detection.
Ning Wang 0022, Yimin Chen 0004, Wenjing Lou, Y. Thomas Hou 0001
INFOCOM1
2021 MANDA: On Adversarial Example Detection for Network Intrusion Detection System
abstract
With the rapid advancement in machine learning (ML), ML-based Intrusion Detection Systems (IDSs) are widely deployed to protect networks from various attacks. Yet one of the biggest challenges is that ML-based IDSs suffer from adversarial example (AE) attacks. By applying small perturbations (e.g. slightly increasing packet inter-arrival time) to the intrusion traffic, an AE attack can flip the prediction of a well-trained IDS. We address this challenge by proposing MANDA, a MANifold and Decision boundary-based AE detection system. Through analyzing AE attacks, we notice that 1) an AE tends to be close to its original manifold (i.e., the cluster of samples in its original class) regardless which class it is misclassified into; and 2) AEs tend to be close to the decision boundary so as to minimize the perturbation scale. Based on the two observations, we design MANDA for accurate AE detection by exploiting inconsistency between manifold evaluation and IDS model inference and evaluating model uncertainty on small perturbations. We evaluate MANDA on NSL-KDD under three state-of-the-art AE attacks. Our experimental results show that MANDA achieves as high as 98.41% true-positive rate with 5% false-positive rate and can be applied to other problem spaces such as image recognition.
Ning Wang 0022, Yimin Chen 0004, Wenjing Lou, Y. Thomas Hou 0001
INFOCOM1
2018 Optimization Deployment of Roadside Units with Mobile Vehicle Data Analytics
abstract
Mobile self-organizing networks, such as vehicular ad-hoc network (VANET), in most cases rely on infrastructure deployment to provide access to internet services and other resource. Therefore, it is crucial to optimize the deployment of roadside units (RSUs) in vehicle network. In this paper, we propose a RSU optimized deployment scheme based on large vehicle data, which considers the deployment cost and latency performance synthetically. We deploy the RSU problem as a multiobjective optimization problem for mathematical modeling. On this basis, two-step solution is proposed: firstly, the RSU candidate positions can be obtained by considering the road topology and large vehicle data; secondly, the branch and bound algorithm is used to obtain the better RSU deployment based on the mathematical model. The simulation results show that the proposed RSU deployment scheme uses a small amount of RSU can achieve high coverage and greatly reduce the deployment cost. Moreover, the low latency performance of the vehicle access network and the quality of the latency sensitive application service can also be ensured.
Qimei Cui, Sihai Zhang, Xueying Jiang, Ning Wang 0022
APCC5
2017 Spatial Point Process Modeling of Vehicles in Large and Small Cities
abstract
The uncertainty in the locations of vehicles on streets induced by vehicles passing and queueing make the spatial modeling of vehicles a difficult task. To analyze the performance of vehicle-to-vehicle (V2V) communication for vehicular ad hoc networks (VANETs), accurate spatial modeling is of great importance. In this paper, we concentrate on spatial point process modeling for random vehicle locations in large and small cities, performing empirical experiments with real location data of mobile taxi trajectories recorded by the global positioning system (GPS) in Beijing city of China and Porto city of Portugal. We find that the empirical probability mass functions (PMFs) of the number of taxis in test sets in different regions of Beijing or in Porto all follow a negative binomial (NB) distribution. Based on the above, we show that the Log Gaussian Cox Process (LGCP) model, whose empirical PMF nicely fits the NB distribution, accurately characterizes diverse spatial point patterns of random vehicle location in both large and small cities. This is verified by the minimum contrast method. The LGCP model can be applied to analyze performance metrics (i.e., connectivity, coverage, and capacity) and optimize the practical deployments of VANETs.
Qimei Cui, Ning Wang 0022, Martin Haenggi
GLOBECOM2
2017 Energy efficiency maximization for CoMP joint transmission with non-ideal power amplifiers
abstract
Coordinated multipoint (CoMP) joint transmission (JT) can save a great deal of energy especially for cell-edge users due to strengthened received signal, but at the cost of deploying and coordinating cooperative nodes, which degrades energy efficiency (EE), particularly when considerable amount of energy is consumed by nonideal hardware circuit. In this paper, we study energy-efficient cooperation establishment, including cooperative nodes selection (CNS) and power allocation, to satisfy a required data rate in coherent JT-CoMP networks with non-ideal power amplifiers (PAs) and circuit power. The selection priority lemma is proved first, and then the formulated discrete combinatorial EE optimization is resolved by proposing node selection criterion and deriving closedform expressions of optimal transmission power. Therefore, an efficient algorithm is provided and its superiority is validated by Monte Carlo simulations, which also show the effects of non-ideal PA and the data rate demand on EE and optimal number of active nodes.
Yuhao Zhang 0002, Qimei Cui, Ning Wang 0022
PIMRC3
2017 Optimal Pilot Symbols Ratio in Terms of Spectrum and Energy Efficiency in Uplink CoMP Networks
abstract
In wireless networks, Spectrum Efficiency (SE) and Energy Efficiency (EE) can be affected by the channel estimation that needs to be well designed in practice. In this paper, considering channel estimation error and non-ideal backhaul links, we optimize the pilot symbols ratio in terms of SE and EE in uplink Coordinated Multi-point (CoMP) networks. Modeling the channel estimation error, we formulate the SE and EE maximization problems by analyzing the system capacity with imperfect channel estimation. The maximal system capacity in SE optimization and the minimal transmit power in EE optimization, which both have the closed-form expressions, are derived by some reasonable approximations to reduce the complexity of solving complicated equations. Simulations are carried out to validate the superiority of our scheme, verify the accuracy of our approximation, and show the effect of pilot symbols ratio.
Yuhao Zhang 0002, Qimei Cui, Ning Wang 0022
VTC Spring3
2017 Energy-efficient resource allocation for hybrid bursty services in multi-relay OFDM networks
Yuhao Zhang 0002, Qimei Cui, Ning Wang 0022, Yan-Zhao Hou, Weiliang Xie
Sci. China Inf. Sci.3