EDBT 2026 Demo / reviewers in the wild / expert
Xiaoning Liu 0002
dblp:51/5617-2
· DBLP profile ↗
32ranked-venue papers
8as first author
30since 2021 · last 2026
0000-0002-9874-8839ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 20 · 7 first-author · 19 since 2021Systems, architecture and hardware · 3 · 3 since 2021Computer networks · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Imprint of the Forgotten: Stealthy Membership Inference in Unlearned Graph Neural NetworksabstractGraphs effectively model interactions in real-world applications such as social and trade networks, where Graph Neural Networks (GNNs) excel at tasks such as link prediction to enhance user experiences. Despite these benefits, users raise privacy concerns as user data can be exploited to improve GNN performance without consent. Accordingly, various graph unlearning methods have been developed. Prior work shows that comparing models before and after unlearning enables attackers to launch former membership inference attacks (FMIA) on unlearned data. However, the imprint of unlearned data left in the unlearned model itself remains underexplored, and existing membership inference methods mainly exploit overfitting, making them ineffective for identifying unlearned data. To address this, we conducted theoretical analysis and proposed an attack framework targeting unlearned GNNs by learning the distribution patterns of unlearned data to distinguish them from normal test data. Extensive experiments on four real-world datasets and GNN architectures confirm our framework's effectiveness and reveal significant vulnerabilities in current graph unlearning methods. He Zhang 0012, Bang Wu 0004, Xiaoning Liu 0002, Karin Verspoor, Xun Yi |
AAAI | 3 |
| 2026 | OblivSage: Oblivious Graph Sampling for Privacy-Preserving GNN
Zhibo Xu, Shangqi Lai, Xiaoning Liu 0002, Alsharif Abuadbba, Tsz Hon Yuen, Joseph K. Liu, Xingliang Yuan |
ACISP (2) | 4 |
| 2026 | Contact Tracing with Location Privacy Protection
Xun Yi, Xiaoning Liu 0002, Kwok-Yan Lam, Elisa Bertino |
ACISP (3) | 2 |
| 2026 | Hardening Output Privacy for Secure Inference: A Lightweight Realization via Distributed Trust
Xinqian Wang, Xiaoning Liu 0002, Shangqi Lai, Xun Yi, Ibrahim Khalil 0001, Kwok-Yan Lam |
ICDCS | 2 |
| 2026 | FastPoS: An efficient Proof of Storage scheme with polynomial commitments for fog-cloud IoT systems
Yuting An, Helei Cui, Hao Zeng 0006, Xiaoning Liu 0002, Bin Guo 0001, Zhiwen Yu 0001 |
Comput. Secur. | 4 |
| 2026 | Privacy-Preserving Automated Deep Learning for Secure Inference ServiceabstractAutomated deep learning (AutoDL) aims to automatically discover optimal architectures of deep neural networks (DNNs) for secure inference without the studies for time-consuming and error-prone manual design. Privacy concerns have increasingly motivated the studies for privacy-preserving AutoDL (PrivAutoDL), where DNN architectures are searched directly on encrypted data without revealing the client's confidential inputs and well-trained DNN architectures. However, existing studies encounter problems in achieving a balance between provable security and efficiency while avoiding significant degradation of model utility. To tackle these problems, we design a privacy-preserving AutoDL scheme, named 2PCAutoDL, utilizing a two-party (two non-colluding cloud servers) computation model. Based on the two-server model, efficient and secure computation protocols are customized layer by layer to protect DNN models associated with client's data. In particular, we reduce the computational overhead of secure DNN: our optimized protocols achieve$1.34\times \sim 2.05\times$speedup for linear layers and$1.33 \times \sim 45 \times$speedup for non-linear layers, compared to a range of existing secure implementations in the literature. Moreover, our fresh alternative to approximate Softmax avoids the drawbacks of approximating exponential operation and yields slightly higher accuracy under appropriate configurations. The security of 2PCAutoDL is formally analyzed under the semi-honest adversary model. Extensive experiments demonstrate that the searched models from 2PCAutoDL improve the inference accuracy by 0.6% on MNIST and by 0.5% on CIFAR-10 when compared to state-of-the-art (SOTA) PrivAutoDL. Fuyi Wang, Jinzhi Ouyang, Leo Yu Zhang, Lei Pan 0002, Shengshan Hu, Xiaoning Liu 0002, Robin Doss |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | $\mathsf {SENTRY}$: A Compliance-Check Service for Dynamic Searchable Encryption With Sanitized Authorization QueryabstractSearchable encryption enables privacy-preserving queries over data outsourced to cloud services. Classical symmetric schemes deliver efficient search but largely assume a single client setting; multi-client variants permit delegation yet typically treat authorization as an owner-local decision, overlooking regulations enforced by higher-level authorities (e.g., sector-specific compliance). In practice, limited familiarity with regulatory detail or operational lapses can lead owners to delegate search permissions that violate authority regulations, rendering existing systems unsuited to regulated, multi-client cloud environments. To address this gap, we propose two systems. First, we propose SENTRY, a multi-client dynamic searchable encryption framework with a built-in compliance-check service via sanitized authorization. Its core is a tag-based sanitization protocol: the authority encodes prohibited keywords as hidden tags, and the sanitizer uses these tags to remove non-compliant per-keyword search permissions before they reach readers, without learning the underlying keywords. As a result, readers receive only compliant search capabilities. We then proposeF-SENTRY, a forward private variant of SENTRY for settings where regulations evolve over time.F-SENTRY preserves the same sanitized-authorization mechanism and further adds forward privacy through a tailored constrained shiftable encryption, which binds search permissions and newly added encrypted updates to regulatory epochs. Consequently, permissions issued before a policy change cannot be used to retrieve data added afterward unless they are refreshed for the new epoch. We formalize the security of both SENTRY andF-SENTRY and prove them secure under standard assumptions. Experiments under cloud-like workloads show that SENTRY achieves regulation-compliant authorization with modest over head, whileF-SENTRY provides stronger protection under changing regulations at practical additional cost. Lei Xu 0019, Xiaoning Liu 0002, Xun Yi, Ibrahim Khalil 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2025 | LAMPS '25: ACM CCS Workshop on Large AI Systems and Models with Privacy and Security AnalysisabstractWith large AI systems and models (LAMs) playing an ever-growing role across diverse applications, their impact on the privacy and cybersecurity of critical infrastructure has become a pressing concern. The LAMPS workshop is dedicated to tackling these emerging challenges, promoting dialogue on cutting-edge developments and ethical issues in safeguarding LAMs within critical infrastructure contexts. Bringing together leading experts from around the world, this workshop will delve into the complex privacy and cybersecurity risks posed by LAMs in critical sectors. Attendees will explore innovative solutions, exchange best practices, and contribute to shaping the future research agenda, emphasizing the crucial balance between advancing AI technologies and securing critical digital and physical infrastructures. Kwok-Yan Lam, Xiaoning Liu 0002, Derui Wang, Bo Li 0026, Wenyuan Xu 0001, Jieshan Chen, Minhui Xue 0001, Xingliang Yuan, Guangdong Bai, Shuo Wang 0012 |
CCS | 2 |
| 2025 | TrustLive: Dynamic and Efficient Trust Evaluation in SIoT with Graph Neural NetworksabstractThe emerging paradigm Social Internet of Things (SIoT) integrates social networking elements into the Internet of Things, enabling smart devices to establish and manage interactions autonomously. This enhances collaboration and adaptability but also increases complexity and vulnerability, particularly from malicious devices exploiting these relationships. To address this, trust evaluation of devices becomes crucial. Traditional approaches, like weighted sums and Bayesian inference, struggle with the dynamic nature of SIoT environments. Recent advancements in Graph Neural Networks (GNNs) show promise, yet existing models often fail to capture the complexities of SIoT's dynamic and heterogeneous nature. In this paper, we propose TrustLive, a GNN-based framework for real-time trust evaluation in dynamic SIoT settings. TrustLive first employs a heterogeneous graph to represent smart devices and their interactions, which are then encoded via a customized graph embedding technique for trust feature extraction. It further incorporates Graph Convolutional Networks for trust aggregation and Temporal Convolutional Networks to capture trust evolution. Moreover, a Memory-Augmented Incremental Update mechanism is added to ensure low-latency updates by processing only the latest data while preserving accuracy with historical results. Experimental results demonstrate that TrustLive outperforms current methods in both accuracy and efficiency, offering a robust solution for trust evaluation in SIoT. Jingjie Zhou, Hao Zeng 0006, Helei Cui, Xiaoning Liu 0002, Zhiwen Yu 0001, Bin Guo 0001 |
IWQoS | 4 |
| 2025 | SIGuard: Guarding Secure Inference with Post Data Privacy
Xinqian Wang, Xiaoning Liu 0002, Shangqi Lai, Xun Yi, Xingliang Yuan |
NDSS | 2 |
| 2025 | Unsupervised Backdoor Detection and Mitigation for Spiking Neural NetworksabstractSpiking Neural Networks (SNNs) have attracted significant attention from the research community due to their high energy efficiency compared to Artificial Neural Networks (ANNs). However, rare studies on the security of SNNs were conducted, especially in backdoor attacks. Existing defense methods for ANN backdoor attacks either perform poorly or can be easily bypassed in SNN scenarios due to SNNs’ event-driven and temporal dependency characteristics, posing significant research challenges. In this paper, we identify the blockers to existing backdoor defenses for defending against attacks in SNNs and propose an unsupervised post-training backdoor detection method named Temporal Membrane Potential Backdoor Detection (TMPBD) to address those blockers in SNNs with neuromorphic data. Specifically, TMPBD employs the maximum margin statistic of temporal membrane potential in the last spiking layer of the SNNs to detect attack target labels without knowledge of the attack or access to any data. Moreover, we also design a practical and robust mitigation mechanism named Neural Dendrites Suppression Backdoor Mitigation (NDSBM). NDSBM dually clamps the neural dendrites, i.e., the weights connecting the first two convolution layers in each convolution block to limit the backdoor effect, while preserving the benign model behaviors learned from the temporal membrane potential obtained from a small, clean, unlabeled dataset in the same domain. To evaluate the performance, we conduct a comprehensive evaluation with multiple backdoor attack techniques, including the SOTA input-aware dynamic trigger attack dedicated to SNNs with clean models on three neuromorphic benchmark datasets. The results demonstrated that TMPBD achieves 100% prediction accuracy in detecting dynamic trigger attacks and associating attack target labels in all benchmark datasets. NDSBM lowered the attack success rate (ASR) from 100% caused by the dynamic trigger attack down to 8.44% with only mitigation or 2.81% when combined with detection for an end-to-end pipeline without performance degradation in clean accuracy. Bang Wu 0004, Xiaoyu Xia 0001, Xiaoning Liu 0002, Xun Yi, Xiuzhen Zhang 0001 |
RAID | 4 |
| 2025 | Dynamic Graph Unlearning: A General and Efficient Post-Processing Method via Gradient TransformationabstractDynamic graph neural networks (DGNNs) have emerged and been widely deployed in various web applications (e.g., Reddit) to serve users (e.g., personalized content delivery) due to their remarkable ability to learn from complex and dynamic user interaction data. Despite benefiting from high-quality services, users have raised privacy concerns, such as misuse of personal data (e.g., dynamic user-user/item interaction) for model training, requiring DGNNs to "forget" their data to meet AI governance laws (e.g., the "right to be forgotten" in GDPR). However, current static graph unlearning studies cannot unlearn dynamic graph elements and exhibit limitations such as the model-specific design or reliance on pre-processing, which disenable their practicability in dynamic graph unlearning. To this end, we study the dynamic graph unlearning for the first time and propose an effective, efficient, general, and post-processing method to implement DGNN unlearning. Specifically, we first formulate dynamic graph unlearning in the context of continuous-time dynamic graphs, and then propose a method called Gradient Transformation that directly maps the unlearning request to the desired parameter update. Comprehensive evaluations on six real-world datasets and state-of-the-art DGNN backbones demonstrate its effectiveness (e.g., limited drop or obvious improvement in utility) and efficiency (e.g., 7.23× speed-up) advantages. Additionally, our method has the potential to handle future unlearning requests with significant performance gains (e.g., 32.59× speed-up). He Zhang 0012, Bang Wu 0004, Xiangwen Yang, Xingliang Yuan, Xiaoning Liu 0002, Xun Yi |
WWW | 5 |
| 2025 | ${\sf GoCrowd}$GoCrowd: Obliviously Aggregating Crowd Wisdom With Quality Awareness in CrowdsourcingabstractOrganizations these days capitalize on crowdsourcing to learn collective wisdom from a population of individuals. Vast amounts of data have been gathered, making the crowdsourcing platforms a lucrative target to steal data from and thus raising severe privacy concerns. Data contributed by workers may carry sensitive individual information. Meanwhile, organizations deem the aggregate statistics as intellectual property. In this paper, we propose, design, and evaluate GoCrowd, a system framework for obliviously aggregating wisdom with quality assurance in crowdsourcing. At its core, we propose constructions for two procedures. The starting point is a gold-standard based private worker quality control procedure that provides privacy-friendly worker quality assurance under the widely popular gold-standard mechanism. The subsequent procedure is an oblivious wisdom aggregation procedure that obliviously learns aggregate statistics over workers’ data while considering their quality. We securely realize these procedures with only lightweight secret sharing techniques. Our system is utterly oblivious to the service provider, and ensures that only the requester can learn the aggregate quality-aware statistics but nothing more. Extensive evaluations show that GoCrowd can produce quality statistics over data from 500 workers for 200 16-choice questions within 1 s. Xiaoning Liu 0002, Yifeng Zheng 0001, Xingliang Yuan, Xun Yi |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Query Correlation Attack Against Searchable Symmetric Encryption With Supporting for Conjunctive QueriesabstractSearchable symmetric encryption (SSE) supporting conjunctive queries has garnered significant attention over the past decade due to its practicality and wide applicability. While extensive research has addressed common leakages, such as the access pattern and search pattern, efforts to mitigate these vulnerabilities have primarily focused on structural issues inherent to scheme construction. In this work, we shift the focus to a less explored yet critical leakage stemming from users’ inherent querying behaviors: query correlation. Originally introduced by Grubbs et al. [USENIX SEC’20], formally defined by Oya and Kerschbaum [USENIX SEC’22], and leveraged to mount a high-success query recovery attack against single-keyword SSE, query correlation raises a crucial question: does it pose a similar threat to the security of conjunctive SSE? To tackle this issue, we undertake two key efforts. First, we generalize the notion of query correlation in the context of conjunctive SSE, introducing the “generalized query correlation pattern”, which captures the co-occurrence relationships among queried tokens within a conjunctive query. Second, we develop a new passive query recovery attack, QCCK, which exploits both the search pattern and generalized query correlation pattern to infer the mapping between tokens and keywords. Comprehensive evaluations on the Enron dataset confirm QCCK’s efficacy, achieving a query recovery rate of approximately 80% with a keyword universe size ranging from 200 to 1000 and an observed query size between 5000 and 50,000. These findings highlight the significant threat posed by query correlation in conjunctive SSE and underscore the urgent need for robust countermeasures. Hanyong Liu, Lei Xu 0019, Xiaoning Liu 0002, Chungen Xu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | MedShield: A Fast Cryptographic Framework for Private Multi-Service Medical DiagnosisabstractThe substantial progress in privacy-preserving machine learning (PPML) facilitates outsourced medical computer-aided diagnosis (MedCADx) services. However, existing PPML frameworks primarily concentrate on enhancing the efficiency of prediction services, without exploration into diverse medical services such as medical segmentation. In this paper, we proposeMedShield, a pioneering cryptographic framework for diverse MedCADx services (i.e., multi-service, including medical imaging prediction and segmentation). Based on a client-server (two-party) setting,MedShieldefficiently protects medical records and neural network models without fully outsourcing. To execute multi-service securely and efficiently, our technical contributions include: 1) optimizing computational complexity of matrix multiplications for linear layers at the expense of free additions/subtractions; 2) introducing a secure most significant bit protocol with crypto-friendly activations to enhance the efficiency of non-linear layers; 3) presenting a novel layer for upscaling low-resolution feature maps to support multi-service scenarios in practical MedCADx. We conduct a rigorous security analysis and extensive evaluations on benchmarks (MNIST and CIFAR-10) and real medical records (breast cancer, liver disease, COVID-19, and bladder cancer) for various services. Experimental results demonstrate thatMedShieldachieves up to$2.4\times$,$4.3\times$, and$2\times$speed up for MNIST, CIFAR-10, and medical datasets, respectively, compared with prior work when conducting prediction services. For segmentation services,MedShieldpreserves the precision of the unprotected version, showing a$1.23\%$accuracy improvement. Fuyi Wang, Jinzhi Ouyang, Xiaoning Liu 0002, Lei Pan 0002, Leo Yu Zhang, Robin Doss |
IEEE Trans. Serv. Comput. | 3 |
| 2024 | TrustMIS: Trust-Enhanced Inference Framework for Medical Image SegmentationabstractRecent advancements in privacy-preserving deep learning (PPDL) enable artificial intelligence-assisted (AI-assisted) medical image diagnostics with privacy guarantees, addressing increasing concerns about data and model privacy. However, intensive studies are restricted to shallow and narrow neural networks (NNs) for simple service (e.g., disease prediction), leaving a gap in exploring diverse inferences. This paper proposes TrustMIS, a trust-enhanced inference framework for fast and private medical image segmentation (MIS) and prediction services. Based on two-party computation, TrustMIS introduces lightweight additive secret-sharing tools to safeguard medical records and NNs. Complementing existing PPDL schemes, we present a series of secure two-party interactive protocols for linear layers. Specifically, we optimize the secure matrix multiplication by reducing the number of expensive multiplication operations with the help of free-computation addition operations to enhance efficiency (bringing 1.15× ∼2.64× savings in both time and communication costs). Furthermore, we customize a fresh secure transposed convolutional protocol for MIS-oriented NNs. A thorough theoretical analysis is provided to prove TrustMIS’s correctness and security. We conduct experimental evaluations over two benchmark and four real-world medical datasets and compare them to state-of-the-art studies. The results demonstrate TrustMIS’s superiority in efficiency and accuracy, improved by 1.1× ∼ 54.4× speedup in secure disease prediction, and 5.56% ↑ ∼ 11.7% ↑ accuracy in secure MIS. Fuyi Wang, Jinzhi Ouyang, Lei Pan 0002, Leo Yu Zhang, Xiaoning Liu 0002, Robin Doss |
ECAI | 5 |
| 2024 | EarPass: Unlock When Wearing Your EarphonesabstractWith the growing reliance on digital systems in today's mobile Internet era, robust authentication methods are crucial for safeguarding personal data and controlling access to resources. Conventional methods, such as knowledge-based and biometric-based authentication, are widely used but still have some usage limitations and potential security concerns, like wearing protective suits/masks or being imitated by attackers with ulterior motives. In this paper, we propose another earphone-based authentication system, namely EarPass, that leverages users' unique head motion patterns in response to a very short period of music segment. Here, we employ a Convolutional Neural Network (CNN)-based feature extractor to capture and map distinct head motions into a well-separated latent space, achieving high-dimensional data extraction. We demonstrate the consistency, uniqueness, and robustness of head motion patterns through extensive experiments and reach a 98.2% F1-score, indicating superior performance compared to conventional authentication methods. Additionally, EarPass is user-friendly, secure, and adaptable to various environments, including noisy and movement-oriented scenarios. By integrating the authentication system into Android devices, we showcase its real-world applicability and low energy consumption with minimal latency. The source code of EarPass will be open-source to further research and collaboration within the community. Yanze Xie, Mengzhen Gao, Xiaoning Liu 0002, Shuo Huana, Helei Cui, Zhiwen Yu 0001, Bin Guo 0001 |
ICDCS | 3 |
| 2024 | Lightweight Multimodal Defect Detection at the Edge via Cross-Modal DistillationabstractThe learning capabilities of single-modality images are often severely limited and fail to meet the requirements of complexity defect detection in industrial settings. For instance, traditional visible light images are susceptible to environmental factors such as lighting and occlusions, while infrared images cannot capture texture details due to their low spatial resolution. Consequently, employing multiple image modalities typically yields better results than relying on a single modality. However, utilizing data from multiple modalities inevitably introduces additional computational costs, posing high hardware demands on edge computing devices, and the need for real-time detection in industrial environments is critical. To address these challenges, we propose a multimodal distillation approach that uses visible and infrared images as inputs to train a complex teacher model, while the student model continues to operate with a single-modal image input. Through knowledge transfer, the student model is enhanced, and model light-weighting is implemented to ensure that it can acquire multi-modal feature information while still meeting real-time performance requirements. Baiqing Wang, Tao Xing, Xiaoning Liu 0002, Zhe Peng, Helei Cui |
IWQoS | 3 |
| 2024 | Model Extraction Attack on MPC Hardened Vertical Federated Learning
Xinqian Wang, Xiaoning Liu 0002, Xun Yi |
ProvSec (1) | 2 |
| 2024 | OblivGNN: Oblivious Inference on Transductive and Inductive Graph Neural Network
Zhibo Xu, Shangqi Lai, Xiaoning Liu 0002, Alsharif Abuadbba, Xingliang Yuan, Xun Yi |
USENIX Security Symposium | 3 |
| 2024 | Model Extraction Attacks on Privacy-Preserving Deep Learning Based Medical Services
Xinqian Wang, Xiaoning Liu 0002, Xun Yi, Xuechao Yang, Iqbal Gondal |
WISE (2) | 2 |
| 2023 | Poster: Raising the Temporal Misalignment in Federated LearningabstractThe rapid evolution of public knowledge is the trend of the present era; rendering previously collected data susceptible to obsolescence. The continuously generated new knowledge could further affect the performance of the model trained with previous data, such a phenomenon is called temporal misalignment. A vanilla mitigation approach is to periodically update the model in a centralized learning scheme. However, in a decentralized learning framework like Federated Learning (FL), such a patch requires clients to upload the data, which contradicts FL's intention to protect clients' privacy. Furthermore, considering the stationary defenses in FL, new knowledge could be misjudged and rejected as malicious attacks, which hinders the further update of the model. Yet dynamically adapting defenses requires meticulous fine-tuning and harms the scalability. Thus in this poster, we raise such practical concern and discuss it in the context of FL. We then build a prototype of a GPT2-based FL framework and conduct experiments to demonstrate our perspective. The performance in new knowledge drops by 33.47% compared with the previous data, which justify the FL with defenses strategy can misjudge the new knowledge. Bo Zhang 0119, Shuo Huang 0004, Helei Cui, Xiaoning Liu 0002, Zhiwen Yu 0001, Bin Guo 0001, Tao Xing |
ICDCS | 4 |
| 2023 | MUD-PQFed: Towards Malicious User Detection on model corruption in Privacy-preserving Quantized Federated learning
Qun Li 0005, Yifeng Zheng 0001, Zhi Zhang 0001, Xiaoning Liu 0002, Yansong Gao 0001, Said F. Al-Sarawi, Derek Abbott |
Comput. Secur. | 5 |
| 2023 | Decentralized and secure deduplication with dynamic ownership in MLaaS
Bo Zhang 0119, Helei Cui, Xiaoning Liu 0002, Yaxing Chen, Zhiwen Yu 0001, Bin Guo 0001 |
J. Inf. Secur. Appl. | 3 |
| 2023 | Securely Outsourcing Neural Network Inference to the Cloud With Lightweight TechniquesabstractNeural network (NN) inference services enrich many applications, like image classification, object recognition, facial verification, and more. These NN inference services are increasingly becoming an essential offering from cloud computing providers, where end-users’ data are offloaded to the cloud for inference under a customized model. However, current cloud-based inference services operate on clear inputs and NN models, raising paramount privacy concerns. Individual user data may contain private information that should always remain confidential. Meanwhile, the NN model is deemed proprietary to the model owner as model training requires substantial resources. In this article, we present, tailor, and evaluateSonic, a lightweight secure NN inference service delegated in the cloud.Sonicleverages the cloud computing paradigm to fully outsource the secure inference, freeing end devices and model owners from being actively online for assistance.Sonicguards both user input and model privacy along the whole service flow. We design a series of secure and efficient NN layer functions purely using lightweight cryptographic primitives. Extensive evaluations demonstrate thatSonicachieves up to$60\times$bandwidth saving in online inference compared to prior art. Xiaoning Liu 0002, Yifeng Zheng 0001, Xingliang Yuan, Xun Yi |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Enabling Secure Deduplication in Encrypted Decentralized Storage
Bo Zhang 0119, Helei Cui, Yaxing Chen, Xiaoning Liu 0002, Zhiwen Yu 0001, Bin Guo 0001 |
NSS | 4 |
| 2022 | Deep learning-based medical diagnostic services: A secure, lightweight, and accurate realizationabstractIn this paper, we propose CryptMed, a system framework that enables medical service providers to offer secure, lightweight, and accurate medical diagnostic service to their customers via an execution of neural network inference in the ciphertext domain. CryptMed ensures the privacy of both parties with cryptographic guarantees. Our technical contributions include: 1) presenting a secret sharing based inference protocol that can well cope with the commonly-used linear and non-linear NN layers; 2) devising optimized secure comparison function that can efficiently support comparison-based activation functions in NN architectures; 3) constructing a suite of secure smooth functions built on precise approximation approaches for accurate medical diagnoses. We evaluate CryptMed on 6 neural network architectures across a wide range of non-linear activation functions over two benchmark and four real-world medical datasets. We comprehensively compare our system with prior art in terms of end-to-end service workload and prediction accuracy. Our empirical results demonstrate that CryptMed achieves up to respectively 413 ×, 19 ×, and 43 × bandwidth savings for MNIST, CIFAR-10, and medical applications compared with prior art. For the smooth activation based inference, the best choice of our proposed approximations preserve the precision of original functions, with less than 1.2% accuracy loss and could enhance the precision due to the newly introduced activation function family. Xiaoning Liu 0002, Yifeng Zheng 0001, Xingliang Yuan, Xun Yi |
J. Comput. Secur. | 1 |
| 2022 | Privacy-Preserving Collaborative Analytics on Medical Time Series DataabstractMedical time series data analytics based on dynamic time warping (DTW) greatly benefits modern medical research. Driven by the distributed nature of medical data, the collaboration of multiple healthcare institutions is usually necessary for a sound medical conclusion. Among others, a typical use case is disease screening for public health, where multiple healthcare institutions wish to collaboratively detect over their joint datasets the patients whose medical records have similar features to the given query samples. However, sharing the medical data faces critical privacy obstacles with the increasingly strict legal regulations on data privacy. In this article, we present the design of a novel system enabling privacy-preserving DTW-based analytics on distributed medical time series datasets. Our system is built from a delicate synergy of techniques from both cryptography and data mining domains, where the key idea is to leverage observations on the advancements in plaintext DTW analytics (e.g., clustering and pruning) to facilitate the scalable computation in the ciphertext domain, through our tailored security design. Extensive experiments over real medical time series datasets demonstrate the promising performance of our system, e.g., our system is able to process a secure DTW query computation over 15K time series sequences in 34 minutes. Xiaoning Liu 0002, Yifeng Zheng 0001, Xun Yi, Surya Nepal |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Leia: A Lightweight Cryptographic Neural Network Inference System at the EdgeabstractThe advances in machine learning have revealed its great potential for emerging mobile applications such as face recognition and voice assistant. Models trained via a Neural Network (NN) can offer accurate and efficient inference services for mobile users. Unfortunately, the current deployment of such service encounters privacy concerns. Directly offloading the model to the mobile device violates model privacy of the model owner, while feeding user input to the service compromises user privacy. To address this issue, we propose Leia, a lightweight cryptographic NN inference system at the edge. Leia is designed from two mobile-friendly perspectives. First, it leverages the paradigm of edge computing wherein the inference procedure keeps the model closer to the mobile user to foster low latency service. Specifically, Leia’s architecture consists of two non-colluding edge services to obliviously perform NN inference on the encoded user data and model. Second, Leia’s realization makes the judicious use of potentially constrained computational and communication resources in edge devices. We adapt the Binarized Neural Network (BNN), a trending flavor of NN with low inference overhead, and purely choose the lightweight secret sharing techniques to realize secure blocks of BNN. We implement Leia and deploy it on Raspberry Pi. Empirical evaluations on benchmark and medical datasets via various models demonstrate the practicality of Leia. Xiaoning Liu 0002, Bang Wu 0004, Xingliang Yuan, Xun Yi |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | MediSC: Towards Secure and Lightweight Deep Learning as a Medical Diagnostic Service
Xiaoning Liu 0002, Yifeng Zheng 0001, Xingliang Yuan, Xun Yi |
ESORICS (1) | 1 |
| 2019 | Privacy-Preserving Collaborative Medical Time Series Analysis Based on Dynamic Time Warping
Xiaoning Liu 0002, Xun Yi |
ESORICS (2) | 1 |
| 2017 | EncSIM: An encrypted similarity search service for distributed high-dimensional datasetsabstractSimilarity-oriented services serve as a foundation in a wide range of data analytic applications such as machine learning, target advertising, and real-time decisions. Both industry and academia strive for efficient and scalable similarity discovery and querying techniques to handle massive, complex data records in the real world. In addition to performance, data security and privacy become an indispensable criterion in the quality of service due to progressively increased data breaches. To address this serious concern, in this paper, we propose and implement “EncSIM”, an encrypted and scalable similarity search service. The architecture of EncSIM enables parallel query processing over distributed, encrypted data records. To reduce client overhead, EncSIM resorts to a variant of the state-of-the-art similarity search algorithm, called all-pairs locality-sensitive hashing (LSH). We describe a novel encrypted index construction for EncSIM based on searchable encryption to guarantee the security of service while preserving performance benefits of all-pairs LSH. Moreover, EncSIM supports data record addition with a strong security notion. Intensive evaluations on a cluster of Redis demonstrate low client cost, linear scalability, and satisfied query performance of EncSIM. Xiaoning Liu 0002, Xingliang Yuan, Cong Wang 0001 |
IWQoS | 1 |