EDBT 2026 Demo / reviewers in the wild / expert
Jiawen Zhang 0005
dblp:59/11040-5
· DBLP profile ↗
8ranked-venue papers
3as first author
8since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Self-improved holistic alignment for preference enhancement
Kejia Chen 0007, Jiawen Zhang 0005, Jiazhen Yang, Mingli Song, Zunlei Feng |
Pattern Recognit. | 2 |
| 2026 | $\mathsf {CipherGPT}$CipherGPT: Secure Two-Party GPT InferenceabstractChatGPT is recognized as a significant revolution in the field of artificial intelligence, but it raises serious concerns regarding user privacy, as the data submitted by users may contain sensitive information. Existing solutions for secure inference face significant challenges in supporting GPT-like models due to the enormous number of model parameters and complex activation functions. In this paper, we develop CipherGPT, the first framework for secure two-party GPT inference, building upon a series of innovative protocols. First, we propose a secure matrix multiplication that is customized for GPT inference, achieving upto 3.8× speedup and 4.3× bandwidth reduction over SOTA. We also propose a novel protocol for securely computing GELU, surpassing SOTA by 3.2× in runtime, 1.3× in communication and 7.4× in precision. Furthermore, we propose the first protocol for secure top-k sampling. We provide a full-fledged implementation and comprehensive benchmark for CipherGPT. In particular, we measure the runtime and communication for each individual operation. We believe this will serve as a reference for future research in this area. Xiaoyang Hou, Jian Liu 0012, Jiawen Zhang 0005, Cheng Hong 0001, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Assessing Safety Risks and Quantization-aware Safety Patching for Quantized Large Language ModelsabstractQuantized large language models (LLMs) have gained increasing attention and significance for enabling deployment in resource-constrained environments. However, emerging studies on a few calibration dataset-free quantization methods suggest that quantization may compromise the safety capabilities of LLMs, underscoring the urgent need for systematic safety evaluations and effective mitigation strategies. In this paper, we present comprehensive safety evaluations across various mainstream quantization techniques and diverse calibration datasets, utilizing widely accepted safety benchmarks. To address the identified safety vulnerabilities, we propose a quantization-aware safety patching framework, Q-resafe, to efficiently restore the safety capabilities of quantized LLMs while minimizing any adverse impact on utility. Extensive experiment results demonstrate that Q-resafe successfully re-aligns the safety of quantized LLMs with their pre-quantization counterparts, even under challenging evaluation scenarios. Project page: https://github.com/Thecommonirin/Qresafe. Kejia Chen 0007, Jiawen Zhang 0005, Jiacong Hu, Yu Wang 0176, Jian Lou 0001, Zunlei Feng, Mingli Song |
ICML | 2 |
| 2025 | Secure Transformer Inference Made Non-interactive
Jiawen Zhang 0005, Xinpeng Yang, Lipeng He, Kejia Chen 0007, Yinghao Wang, Xiaoyang Hou, Jian Liu 0012, Kui Ren 0001, Xiaohu Yang 0001 |
NDSS | 1 |
| 2025 | Activation Approximations Can Incur Safety Vulnerabilities in Aligned LLMs: Comprehensive Analysis and Defense
Jiawen Zhang 0005, Kejia Chen 0007, Lipeng He, Jian Lou 0001, Dan Li 0032, Zunlei Feng, Mingli Song, Jian Liu 0012, Kui Ren 0001, Xiaohu Yang 0001 |
USENIX Security Symposium | 1 |
| 2025 | πFL: Private, atomic, incentive mechanism for federated learning based on blockchainabstractFederated learning (FL) is predicated on the provision of high-quality data by multiple clients, which is then used to train global models. A plethora of incentive mechanism studies have been conducted with the objective of promoting the provision of high-quality data by clients. These studies have focused on the distribution of benefits to clients. However, the incentives of federated learning are transactional in nature, and the issue of the atomicity of transactions has not been addressed. Furthermore, the data quality of individual clients participating in training varies, and they may participate negatively in training out of privacy leakage concerns.Consequently, we propose an inaugural atomistic incentive scheme with privacy preservation in the FL setting: πFL (privacy, atomic, incentive). This scheme establishes a more dependable training environment based on Shapley valuation, secure multi-party computation, and smart contracts. Consequently, it ensures that each client's contribution can be accurately measured and appropriately rewarded, improves the accuracy and efficiency of model training, and enhances the sustainability and reliability of the FL system. The efficacy of this mechanism has been demonstrated through comprehensive experimental analysis. It is evident that this mechanism not only protects the privacy of trainers and provides atomic training rewards but also improves the model performance of FL, with an accuracy improvement of at least 8%. Kejia Chen 0007, Jiawen Zhang 0005, Xuanming Liu, Zunlei Feng, Xiaohu Yang 0001 |
Blockchain Res. Appl. | 2 |
| 2025 | SmartZKCP: Towards practical data exchange marketplace against active attacksabstractThe trading of data is becoming increasingly important as it holds substantial value. A blockchain-based data marketplace can provide a secure and transparent platform for data exchange. To facilitate this, developing a fair data exchange protocol for digital goods has garnered considerable attention in recent decades. The Zero Knowledge Contingent Payment (ZKCP) protocol enables trustless fair exchanges with the aid of blockchain and zero-knowledge proofs. However, applying this protocol in a practical data marketplace is not trivial.In this paper, several potential attacks are identified when applying the ZKCP protocol in a practical public data marketplace. To address these issues, we propose SmartZKCP, an enhanced solution that offers improved security measures and increased performance. The protocol is formalized to ensure fairness and secure against potential attacks. Moreover, SmartZKCP offers efficiency optimizations and minimized communication costs. Evaluation results show that SmartZKCP is both practical and efficient, making it applicable in a data exchange marketplace. Xuanming Liu, Jiawen Zhang 0005, Yinghao Wang, Xinpeng Yang, Xiaohu Yang 0001 |
Blockchain Res. Appl. | 2 |
| 2024 | SecPE: Secure Prompt Ensembling for Private and Robust Large Language ModelsabstractWith the growing popularity of LLMs among the general public users, privacy-preserving and adversarial robustness have become two pressing demands for LLM-based services, which have largely been pursued separately but rarely jointly. In this paper, to the best of our knowledge, we are among the first attempts towards robust and private LLM inference by tightly integrating two disconnected fields: private inference and prompt ensembling. The former protects users’ privacy by encrypting inference data transmitted and processed by LLMs, while the latter enhances adversarial robustness by yielding an aggregated output from multiple prompted LLM responses. Although widely recognized as effective individually, private inference for prompt ensembling together entails new challenges that render the naive combination of existing techniques inefficient. To overcome the hurdles, we propose SecPE, which designs efficient fully homomorphic encryption (FHE) counterparts for the core algorithmic building blocks of prompt ensembling. We conduct extensive experiments on 8 tasks to evaluate the accuracy, robustness, and efficiency of SecPE. The results show that SecPE maintains high clean accuracy and offers better robustness at the expense of merely 2.5% efficiency overhead compared to baseline private inference methods, indicating a satisfactory “accuracy-robustness-efficiency” tradeoff. For the efficiency of the encrypted Argmax operation that incurs major slowdown for prompt ensembling, SecPE is 35.4 times faster than the state-of-the-art peers, which can be of independent interest beyond this work. Jiawen Zhang 0005, Kejia Chen 0007, Zunlei Feng, Jian Lou 0001, Mingli Song |
ECAI | 1 |