EDBT 2026 Demo / reviewers in the wild / expert
Lefeng Zhang
dblp:60/10449
· DBLP profile ↗
28ranked-venue papers
9as first author
24since 2021 · last 2026
0000-0002-7608-7910ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 4 first-author · 10 since 2021Systems, architecture and hardware · 7 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 4 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multi-Writer/Reader Forward and Backward Private DSSE With Bilateral SelectionabstractDynamic searchable symmetric encryption (DSSE) allows a client to update and retrieve its encrypted database stored on a server. To enable the database contributed by multi-writers to be searched by multi-readers, the multi-writer/multi-reader model is explored for DSSE (M/M-DSSE). Recently, FP-HSE (USENIX Security'22) and FP-MSE (TDSC'24) employed key aggregation methodology to introduce writer-selection property for M/M-DSSE, where a reader uses a single aggregate key to search the database containing selective writers. However, they neglected the reader-selection property where a writer selects which readers can search its data, and only supported single-keyword search. In this paper, we present BiMM, a conjunctive M/M-DSSE scheme with bilateral selection that simultaneously supports writer-selection and reader-selection properties. Additionally, BiMM achieves forward privacy (FP) for both server and client, and Type-O backward privacy (BP). Technically, we introduce a new primitive called bilateral key-aggregate encryption (Bi-KAE) that refines KAE via distributed key generation, by which both writers and readers can specify their selections. Based on ODXT (NDSS'21) that provides conjunctive queries while achieving FP with server and BP, we introduce double-blinded values to match all update records for the search keywords and additionally use the 0/1-Encoding technique to consider FP with client. Besides presenting formal security analysis for BiMM, we also conduct extensive experiments over public datasets on a real cloud server environment. The experiment results demonstrate that BiMM achieves practical performance for desired properties. With #keyword = 50 and #s-term = 10 for conjunctive queries, BiMM runs 6.34× faster than Nomos (AsiaCCS'24) which does not consider either writer-selection or reader-selection. Jiawen Wu 0001, Kai Zhang 0016, Jianting Ning, Hao Chen 0062, Lefeng Zhang, Zuobin Ying |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Really Unlearned? Verifying Machine Unlearning via Influential Sample PairsabstractMachine unlearning enables pre-trained models to eliminate the effects of partial training samples. Previous research has mainly focused on proposing efficient unlearning strategies. However, the verification of machine unlearning, or in other words, how to guarantee that a sample has been successfully unlearned, has been overlooked for a long time. Existing verification schemes typically rely on machine learning attack techniques, such as backdoor attacks or membership inference attacks. As these techniques are not formally designed for verification, they are easily bypassed when an untrustworthy model provider in MLaaS undergoes rapid fine-tuning to meet the verification conditions only, rather than executingrealunlearning. In this paper, we propose a formal verification scheme, IndirectVerify, to determine whether unlearning requests have been successfully executed. We design influential sample pairs: one referred to astrigger samplesand the other asreaction samples. Users send unlearning requests regarding trigger samples and use reaction samples to verify if the unlearning operation has been successfully carried out. We propose a perturbation-based scheme to generate those influential sample pairs. The objective is to perturb only a small fraction of training samples to trigger samples, leading to the misclassification of reaction samples. This indirect influence will be used for our verification purposes. In contrast to existing schemes that employ the same samples for all processes, our scheme, IndirectVerify, provides enhanced robustness, making it less susceptible to bypassing processes. Tianqing Zhu, Lefeng Zhang, Wanlei Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Federated TrustChain: Blockchain-Enhanced LLM Training and UnlearningabstractThe development of Large Language Models (LLMs) faces a significant challenge: the exhaustion of publicly available fresh data. This is because training an LLM requires a large demand for new data. Federated learning emerges as a promising solution, enabling collaborative model to contribute their private data to LLM global model. However, integrating federated learning with LLMs introduces new challenges, including the lack of transparency and the need for effective unlearning mechanisms. Transparency is essential to ensuring trust and fairness among participants, while accountability is crucial for deterring malicious behaviour and enabling corrective actions when necessary. To address these challenges, we propose a novel blockchain-based federated learning framework for LLMs that enhances transparency, accountability, and unlearning capabilities. Our framework leverages blockchain technology to create a tamper- proof record of each model's contributions and introduces an innovative unlearning function that seamlessly integrates with the federated learning mechanism. We investigate the impact of Low-Rank Adaptation (LoRA) hyperparameters on unlearning performance and integrate Hyperledger Fabric to ensure the security, transparency, and verifiability of the unlearning process. Through comprehensive experiments and analysis, we showcase the effectiveness of our proposed framework in achieving highly effective unlearning in LLMs trained using federated learning. Our findings highlight the feasibility of integrating blockchain technology into federated learning frameworks for LLM. Xuhan Zuo, Tianqing Zhu, Lefeng Zhang, Dayong Ye, Shui Yu 0001, Wanlei Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Bhra-VITARIT: Weighted Atomic Swaps for Threshold Services on Scriptless Blockchains
Jianting Ning, Lefeng Zhang, Xinyi Huang 0001, Debiao He |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | Parameter-Agnostic Privacy-Preserving Machine Unlearning for Large Language ModelsabstractIn recent years, advancements in large language models have led to significant innovation and critical progress in AI. However, some of these innovations are raising privacy and security concerns. Machine unlearning has therefore emerged as a potential solution to mitigate such risks. Yet, while erasing data records from traditional models is relatively straightforward, making a large language model “forget” what it has learned is often very challenging. This is not just because they include so many parameters, it is also because the knowledge they possess is intricately entangled. Further, the privacy risk of unlearned data remains neglected in most unlearning solutions. To overcome these limitations, we took advantage of information retrieval and developed an efficient privacy-preserving unlearning mechanism. Our solution eliminates the impact of targeted information by removing high-risk semantic meanings from the model’s output. It also incorporates differentially-private randomization to make the unlearned information statistically indiscernible. Most importantly, the algorithm requires neither parametric fine-tuning nor in-context prompt calibration. A theoretical analysis demonstrates that this method satisfies rigorous privacy and unlearning guarantees. Additionally, experiments on real-world datasets prove that the method is both effective and has the capacity to handle practical unlearning tasks for large language model applications. Lefeng Zhang, Tianqing Zhu, Zihan Xie, Shang Wang 0004, Binxing Fang, Wanlei Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | The Evaluation of Retrieval-Based Unlearning Mechanisms on Large Language Models
Zihan Xie, Lefeng Zhang, Minfeng Qi |
KSEM (3) | 2 |
| 2025 | FedSweep: Unlearning Backdoors in Federated Learning
Zhiheng Qiu, Mingfeng Qi, Lefeng Zhang |
PAKDD (2) | 4 |
| 2025 | Update Selective Parameters: Federated Machine Unlearning Based on Model ExplanationabstractFederated learning is a promising privacy-preserving paradigm for distributed machine learning. In this context, there is sometimes a need for a specialized process called machine unlearning, which is required when the effect of some specific training samples needs to be removed from a learning model due to privacy, security, usability, and/or legislative factors. However, problems arise when current centralized unlearning methods are applied to existing federated learning, in which the server aims to remove all information about a class from the global model. Centralized unlearning usually focuses on simple models or is premised on the ability to access all training data at a central node. However, training data cannot be accessed on the server under the federated learning paradigm, conflicting with the requirements of the centralized unlearning process. Additionally, there are high computation and communication costs associated with accessing clients’ data, especially in scenarios involving numerous clients or complex global models. To address these concerns, we propose a more effective and efficient federated unlearning scheme based on the concept of model explanation. Model explanation involves understanding deep networks and individual channel importance, so that this understanding can be used to determine which model channels are critical for classes that need to be unlearned. We select the most influential channels within an already-trained model for the data that need to be unlearned and fine-tune only influential channels to remove the contribution made by those data. In this way, we can simultaneously avoid huge consumption costs and ensure that the unlearned model maintains good performance. Experiments with different training models on various datasets demonstrate the effectiveness of the proposed approach. Tianqing Zhu, Lefeng Zhang, Wanlei Zhou 0001, Philip S. Yu |
IEEE Trans. Big Data | 3 |
| 2025 | Trojan Attack on Machine Unlearning: Security Risk of the Right to be ForgottenabstractThe Right to be Forgottenand related legislation mandate that every individual has the right to withdraw their consent to the use of their personal data. These laws and regulations led to the development of a new concept – machine unlearning. Recently, various machine unlearning approaches have been proposed to remove the influence of data sample(s) from a trained model. However, alongside all the achievements, there are still loopholes that may cause significant losses for the model owner. We found that it might be dangerous to remove the influence of some “well-designed” data samples from a pre-trained model. An adversary may craft some poisonous data and take advantage of the unlearning request to manipulate an unlearned model. In this paper, we exploit the vulnerabilities of the fast retraining-based unlearning strategy and propose a new data poisoning attack to demonstrate the risks they may bring about. The attack is triggered by submitting an unlearning request on adversarially designed data samples, and it enables an adversary to steer a model to a target location in the parameter space. We provide theoretical analyses to show the feasibility of such an attack regarding the gradient of the poisonous data. Furthermore, the experimental results on real-world datasets demonstrate that the attack strategy is effective. Lefeng Zhang, Tianqing Zhu, Ping Xiong 0001, Wanlei Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | QuadrantSearch: A Novel Method for Registering UAV and Backpack LiDAR Point Clouds in Forested AreasabstractUnmanned aerial vehicle (UAV) laser scanning (ULS) and backpack laser scanning (BLS) are two commonly employed technologies in precision forestry. However, data acquired by these two types of light detection and ranging (LiDAR) are distinct, with one capturing point clouds beneath the canopy and the other above. Consequently, there is minimal overlap in the point clouds collected by both methods, especially in dense forests, presenting significant challenges for data registration. Furthermore, many trees in forests (particularly broadleaf trees) have the tree tops and trunk centers not aligned vertically, which greatly increases the difficulty of the data registration methods based on tree position. To solve the above-mentioned problems, we here propose a novel and robust method to register ULS and BLS point clouds in forested areas. Our method consists of three key steps, that is, tree location extraction, quadrant search-based minimum spanning tree (MST) matching, and registration. The quadrant searching strategy dynamically searches for potential candidates in four quadrants centered on the initial tree locations. By constructing MSTs for the potential tree locations, triangle constraints require only four topologically similar tree locations to find one-to-one correspondences during the stepwise MST matching process. The proposed method was evaluated in five urban forest sample plots and one natural forest sample plot located in China, covering both coniferous and broadleaf forests. The results show that our method obtained good registration results on all six sample plots, with an averaged rotation error, translation error, pointwise error, and root-mean-square error (RMSE) of 0.012 rad, 0.354, 0.378, and 0.379 m, respectively. Comparative studies indicate that our method outperformed existing registration methods, demonstrating its effectiveness and robustness. Our method allows for the creation of a more complete picture of forest vertical structure and holds great potential for informing sustainable forest management practices and supporting critical ecological assessments. Guorong Li, Bin Wu 0010, Zhan Pan, Linxin Dong, Guochun Shen, Tian Xiao, Lefeng Zhang, Bailang Yu |
IEEE Trans. Geosci. Remote. Sens. | 10 |
| 2025 | QUEEN: Query Unlearning Against Model ExtractionabstractModel extraction attacks currently pose a non-negligible threat to the security and privacy of deep learning models. By querying the model with a small dataset and using the query results as the ground-truth labels, an adversary can steal a piracy model with performance comparable to the original model. Two key issues that cause the threat are, on the one hand, accurate and unlimited queries can be obtained by the adversary; on the other hand, the adversary can aggregate the query results to train the model step by step. The existing defenses usually employ model watermarking or fingerprinting to protect the ownership. However, these methods cannot proactively prevent the violation from happening. To mitigate the threat, we propose QUEEN (QUEry unlEarNing) that proactively launches counterattacks on potential model extraction attacks from the very beginning. To limit the potential threat, QUEEN has sensitivity measurement and outputs perturbation that prevents the adversary from training a piracy model with high performance. In sensitivity measurement, QUEEN measures the single query sensitivity by its distance from the center of its cluster in the feature space. To reduce the learning accuracy of attacks, for the highly sensitive query batch, QUEEN applies query unlearning, which is implemented by gradient reverse to perturb the softmax output such that the piracy model will generate reverse gradients to worsen its performance unconsciously. Experiments show that QUEEN outperforms the state-of-the-art defenses against various model extraction attacks with a relatively low cost to the model accuracy. The artifact is publicly available athttps://github.com/MaraPapMann/QUEEN. Huajie Chen, Tianqing Zhu, Lefeng Zhang, Bo Liu 0001, Derui Wang, Wanlei Zhou 0001, Minhui Xue 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Game-Theoretic Machine Unlearning: Mitigating Extra Privacy LeakageabstractWith the extensive use of machine learning technologies, data providers encounter increasing privacy risks. Recent legislation, such as GDPR, obligates organizations to remove requested data and its influence from a trained model. Machine unlearning is an emerging technique designed to enable machine learning models to erase users’ private information. Although several efficient machine unlearning schemes have been proposed, these methods still have limitations. First, removing the contributions of partial data may lead to model performance degradation. Second, discrepancies between the original and generated unlearned models can be exploited by attackers to obtain target sample’s information, resulting in additional privacy leakage risks. To address above challenges, we proposed a game-theoretic machine unlearning algorithm that simulates the competitive relationship between unlearning performance and privacy protection. This algorithm comprises unlearning and privacy modules. The unlearning module possesses a loss function composed of model distance and classification error, which is used to derive the optimal strategy. The privacy module aims to make it difficult for an attacker to infer membership information from the unlearned data, thereby reducing the privacy leakage risk during the unlearning process. Additionally, the experimental results on real-world datasets demonstrate that this game-theoretic unlearning algorithm’s effectiveness and its ability to generate an unlearned model with a performance similar to that of the retrained one while mitigating extra privacy leakage risks. Hengzhu Liu, Tianqing Zhu, Lefeng Zhang, Ping Xiong 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Toward Efficient Target-Level Machine Unlearning Based on Essential GraphabstractMachine unlearning is an emerging technology that has come to attract widespread attention. A number of factors, including regulations and laws, privacy, and usability concerns, have resulted in this need to allow a trained model to forget some of its training data. Existing studies of machine unlearning mainly focus on unlearning requests that forget a cluster of instances or all instances from one class. While these approaches are effective in removing instances, they do not scale to scenarios where partial targets within an instance need to be forgotten. For example, one would like to only unlearn a person from all instances that simultaneously contain the person and other targets. Directly migrating instance-level unlearning to target-level unlearning will reduce the performance of the model after the unlearning process, or fail to erase information completely. To address these concerns, we have proposed a more effective and efficient unlearning scheme that focuses on removing partial targets from the model, which we name "target unlearning." Specifically, we first construct an essential graph data structure to describe the relationships between all important parameters that are selected based on the model explanation method. After that, we simultaneously filter parameters that are also important for the remaining targets and use the pruning-based unlearning method, which is a simple but effective solution to remove information about the target that needs to be forgotten. Experiments with different training models on various datasets demonstrate the effectiveness of the proposed approach. Tianqing Zhu, Lefeng Zhang, Wanlei Zhou 0001, Wei Zhao 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 3 |
| 2025 | The Price of Unlearning: Identifying Unlearning Risk in Edge ComputingabstractMachine unlearning is an emerging paradigm that aims to make machine learning models “forget” what they have learned about particular data. It fulfills the requirements of privacy legislation (e.g., General Data Protection Regulation), which stipulates that individuals have the autonomy to determine the usage of their personal data. However, alongside all the achievements, there are still loopholes in machine unlearning that may cause significant losses for the system, especially in edge computing. Edge computing is a distributed computing paradigm with the purpose of migrating data–processing tasks closer to terminal devices. While various machine unlearning approaches have been proposed to erase the influence of data sample(s), we claim that it might be dangerous to directly apply them in the realm of edge computing. A malicious edge node may broadcast (possibly fake) unlearning requests to a target data sample (s) and then analyze the behavior of edge devices to infer useful information. In this article, we exploited the vulnerabilities of current machine unlearning strategies in edge computing and proposed a new inference attack to highlight the potential privacy risk. Furthermore, we developed a defense method against this particular type of attack and proposed the price of unlearning ( PoU ) as a means to evaluate the inefficiency it brings to an edge computing system. We provide theoretical analyses to show the upper bound of the PoU using tools borrowed from game theory. The experimental results on real-world datasets demonstrate that the proposed defense strategy is effective and capable of preventing an adversary from deducing useful information. Lefeng Zhang, Tianqing Zhu, Ping Xiong 0001, Wanlei Zhou 0001 |
ACM Trans. Multim. Comput. Commun. Appl. | 1 |
| 2025 | Vertical Federated Unlearning via Backdoor CertificationabstractVertical Federated Learning (VFL) offers a novel paradigm in machine learning, enabling distinct entities to train models cooperatively while maintaining data privacy. This method is particularly pertinent when entities possess datasets with identical sample identifiers but diverse attributes. Recent privacy regulations emphasize an individual'sright to be forgotten, which necessitates the ability for models to unlearn specific training data. The primary challenge is to develop a mechanism to eliminate the influence of a specific client from a model without erasing all relevant data from other clients. Our research investigates the removal of a single client's contribution within the VFL framework. We introduce an innovative modification to traditional VFL by employing a mechanism that inverts the typical learning trajectory with the objective of extracting specific data contributions. This approach seeks to optimize model performance using gradient ascent, guided by a pre-defined constrained model. We also introduce a backdoor mechanism to verify the effectiveness of the unlearning procedure. Our method avoids fully accessing the initial training data and avoids storing parameter updates. Empirical evidence shows that the results align closely with those achieved by retraining from scratch. Utilizing gradient ascent, our unlearning approach addresses key challenges in VFL, laying the groundwork for future advancements in this domain. Mengde Han, Tianqing Zhu, Lefeng Zhang, Huan Huo, Wanlei Zhou 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2025 | Federated Learning With Blockchain-Enhanced Machine Unlearning: A Trustworthy ApproachabstractWith the growing need to comply with privacy regulations and respond to user data deletion requests, integrating machine unlearning into IoT-based federated learning has become imperative. This article introduces an innovative framework that melds blockchain with federated learning, ensuring an immutable record of unlearning requests and actions. Our approach not only bolsters the trustworthiness and integrity of the federated learning model but also adeptly addresses efficiency and security challenges typical in IoT environments. Key contributions include a certification mechanism for the unlearning process, enhancement of data security and privacy, and optimization of data management. Experimental results on MNIST and CIFAR-10 datasets demonstrate the effectiveness of our approach, achieving 0% accuracy for unlearned classes while maintaining 77.74% and 42.65% overall model accuracy for MNIST and CIFAR-10, respectively. Our time complexity analysis shows that the blockchain integration introduces only 2 seconds of overhead per epoch, highlighting the practicality of our solution for IoT applications. Xuhan Zuo, Tianqing Zhu, Lefeng Zhang, Shui Yu 0001, Wanlei Zhou 0001 |
IEEE Trans. Serv. Comput. | 4 |
| 2024 | Towards Information Sharing Beetle Antennae Search Optimization
Xuan Liu 0008, Chenyan Wang, Lefeng Zhang, Xianggan Liu, Yutong Gao 0001 |
ICA3PP (2) | 4 |
| 2024 | Language-Based Colorization with Sparse Attention and Multi-scale Cross-Modal Semantic Alignment
Yutong Gao 0001, Xuan Liu 0008, Lefeng Zhang, Xianggan Liu, Shan Jiang 0012 |
ICA3PP (5) | 4 |
| 2023 | A Game-Theoretic Method for Defending Against Advanced Persistent Threats in Cyber SystemsabstractAdvanced persistent threats (APTs) are one of today’s major threats to cyber security. Highly determined attackers along with novel and evasive exfiltration techniques mean APT attacks elude most intrusion detection and prevention systems. The result has been significant losses for governments, organizations, and commercial entities. Intriguingly, despite greater efforts to defend against APTs in recent times, frequent upgrades in defense strategies are not leading to increased security and protection. In this paper, we demonstrate this phenomenon in an appropriately designed APT rivalry game that captures the interactions between attackers and defenders. What is shown is that the defender’s strategy adjustments actually leave useful information for the attackers, and thus intelligent and rational attackers can improve themselves by analyzing this information. Hence, a critical part of one’s defense strategy must be finding a suitable time to adjust one’s strategy to ensure attackers learn the least possible information. Another challenge for defenders is determining how to make the best use of one’s resources to achieve a satisfactory defense level. In support of these efforts, we figured out the optimal timings of a player’s strategy adjustment in terms of information leakage, which form a family of Nash equilibria. Moreover, two learning mechanisms are proposed to help defenders find an appropriate defense level and allocate their resources reasonably. One is based on adversarial bandits, and the other is based on deep reinforcement learning. Experimental simulations show the rationales behind the game and the optimality of the equilibria. The results also demonstrate that players indeed have the ability to improve themselves by learning from past experiences, which shows the necessity of specifying optimal strategy adjustment timings when defending against APTs. Lefeng Zhang, Tianqing Zhu, Farookh Khadeer Hussain, Dayong Ye, Wanlei Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | FedRecovery: Differentially Private Machine Unlearning for Federated Learning FrameworksabstractOver the past decades, the abundance of personal data has led to the rapid development of machine learning models and important advances in artificial intelligence (AI). However, alongside all the achievements, there are increasing privacy threats and security risks that may cause significant losses for data providers. Recent legislation requires that the private information about a user should be removed from a database as well as machine learning models upon certain deletion requests. While erasing data records from memory storage is straightforward, it is often challenging to remove the influence of particular data samples from a model that has already been trained. Machine unlearning is an emerging paradigm that aims to make machine learning models “forget” what they have learned about particular data. Nevertheless, the unlearning issue for federated learning has not been completely addressed due to its special working mode. First, existing solutions crucially rely on retraining-based model calibration, which is likely unavailable and can pose new privacy risks for federated learning frameworks. Second, today’s efficient unlearning strategies are mainly designed for convex problems, which are incapable of handling more complicated learning tasks like neural networks. To overcome these limitations, we took advantage of differential privacy and developed an efficient machine unlearning algorithm named FedRecovery. The FedRecovery erases the impact of a client by removing a weighted sum of gradient residuals from the global model, and tailors the Gaussian noise to make the unlearned model and retrained model statistically indistinguishable. Furthermore, the algorithm neither requires retraining-based fine-tuning nor needs the assumption of convexity. Theoretical analyses show the rigorous indistinguishability guarantee. Additionally, the experiment results on real-world datasets demonstrate that the FedRecovery is efficient and is able to produce a model that performs similarly to the retrained one. Lefeng Zhang, Tianqing Zhu, Ping Xiong 0001, Wanlei Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | A Robust Game-Theoretical Federated Learning Framework With Joint Differential PrivacyabstractFederated learning is a promising distributed machine learning paradigm that has been playing a significant role in providing privacy-preserving learning solutions. However, alongside all its achievements, there are also limitations. First, traditional frameworks assume that all the clients are voluntary and so will want to participate in training only for improving the model’s accuracy. However, in reality, clients usually want to be adequately compensated for the data and resources they will use before participating. Second, today’s frameworks do not offer sufficient protection against malicious participants who try to skew a jointly trained model with poisoned updates. To address these concerns, we have developed a more robust federated learning scheme based on joint differential privacy. The framework provides two game-theoretic mechanisms to motivate clients to participate in training. These mechanisms are dominant-strategy truthful, individual rational, and budget-balanced. Further, the influence an adversarial client can have is quantified and restricted, and data privacy is similarly guaranteed in quantitative terms. Experiments with different training models on real-word datasets demonstrate the effectiveness of the proposed approach. Lefeng Zhang, Tianqing Zhu, Ping Xiong 0001, Wanlei Zhou 0001, Philip S. Yu |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2023 | A Game-Theoretic Federated Learning Framework for Data Quality ImprovementabstractFederated learning is a promising distributed machine learning paradigm that has been playing a significant role in privacy-preserving machine learning tasks. However, alongside all its achievements, the framework has limitations. First, traditional frameworks assume that all clients want to improve model accuracy and so participation is voluntary. However, in reality, clients usually want to be appropriately compensated for the data and resources they will need to commit to the training process before contributing. Second, today's frameworks allow clients to perturb their parameter updates locally, which introduces a great deal of noise to the trained model and can seriously impact model accuracy. To address these concerns, we have developed a private reward game that incentivizes clients to contribute high-quality data to the training process. The game converges to a Nash equilibrium under the guarantee of joint differential privacy, and each client maximizes their reward following an equilibrium strategy. The noise injected into the model is reduced by introducing a centralized differential privacy model that aggregates the parameters and compensates clients via a data trading market. Experimental simulations show the rationales behind and effectiveness of the proposed game approach. Additionally, we present comparisons between different training models to demonstrate the performance of the proposed approach in real-world scenarios. Lefeng Zhang, Tianqing Zhu, Ping Xiong 0001, Wanlei Zhou 0001, Philip S. Yu |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2022 | Privacy preservation auction in a dynamic social networkabstractSummary The growing popularity of users in online social network gives a big opportunity for online auction. The famous Information Diffusion Mechanism (IDM) is an excellent methods even meet the incentive compatibility and individual rationality. Although the existing auction in online social network has considered the buyers' information has not known by the seller, current mechanism still cannot preserve the information such as prices. In this paper, we propose a novel mechanism which modeled the auction process in online social network and preserved users' privacy by using differential privacy mechanism. Our mechanism can successfully process the auction and at the same time preserve clients' price information from neighbors. We achieved these by adding Laplace noise for its valuation and the number of valuation seller received in the auction process. We also formulate this mechanism on the real network to show the feasibility and effective of the proposed mechanism. Xiangyu Hu 0006, Zhiping Jin, Lefeng Zhang, Andi Zhou, Dayong Ye |
Concurr. Comput. Pract. Exp. | 3 |
| 2022 | Location privacy preservation through kernel transformationabstractSummary The frequent data leak scandals of recent years indicate that service providers who hold personal data may not be reliable as they claim. We assert that sensitive user information must be sanitized locally before it is sent to service providers if it is to be protected. The LPPK privacy‐preserving framework presented in this article is a local sanitization scheme, for location‐based services (LBSs). It applies a fog‐computing structure in which a private map is generated by the LBS server with kernel transformation for each user. A fog device then provides location services for each user according to the private map. Without colluding, neither the LBS server nor the fog device can deduce a user's real location. Experiments conducted on real‐world data sets demonstrate that LPPK delivers sufficient query accuracy at a level significantly higher than existing approaches while preserving location privacy. Lefeng Zhang, Guanghua Song, Danyang Zhu, Wei Ren 0002, Ping Xiong 0001 |
Concurr. Comput. Pract. Exp. | 1 |
| 2020 | Private collaborative filtering under untrusted recommender server
Ping Xiong 0001, Lefeng Zhang, Tianqing Zhu, Gang Li 0009, Wanlei Zhou 0001 |
Future Gener. Comput. Syst. | 2 |
| 2019 | Optimizing rewards allocation for privacy-preserving spatial crowdsourcing
Ping Xiong 0001, Danyang Zhu, Lefeng Zhang, Wei Ren 0002, Tianqing Zhu |
Comput. Commun. | 3 |
| 2019 | A differentially private method for crowdsourcing data submissionabstractSummary In recent years, the ubiquity of mobile devices has made spatial crowdsourcing a successful business platform for conducting spatiotemporal projects. In spatial crowdsourcing, workers contribute to a project by performing a task at a specific location. However, these platforms present serious threats to people's location privacy because sensitive information may be leaked from submitted spatiotemporal data. As a result, people may be hesitant to join spatial crowdsourcing projects, which hampers further applications of this business model. In this paper, we propose a private spatial crowdsourcing data submission algorithm, called PS‐Sub. This is a differentially private method that preserves people's location privacy and provides acceptable data utility. Rigorous privacy analyses theoretically demonstrate the privacy guarantees inherent in the proposed model. Experiments based on real‐world datasets were conducted using practical evaluation metrics. The results show that our method is able to achieve location privacy preservation efficiently, at an acceptable cost for spatial crowdsourcing applications. Lefeng Zhang, Ping Xiong 0001, Wei Ren 0002, Tianqing Zhu |
Concurr. Comput. Pract. Exp. | 1 |
| 2016 | Semantic analysis in location privacy preservingabstractSummary With the increasing use of location‐based services, location privacy has recently started raising serious concerns. Location perturbation and obfuscation are most widely used for location privacy preserving. To protect a user from being identified, a cloaked spatial region that contains otherk− 1 nearest neighbors of the user is submitted to the location‐based service provider, instead of the accurate position. In this paper, we consider the location‐aware applications that services are different among regions. In such scenarios, the semantic distance between users should be considered besides the Euclidean distance for searching the neighbors of a user. We define a novel distance measurement that combines the semantic and the Euclidean distance to address the privacy‐preserving issue in the aforementioned applications. We also present an algorithmkNNH to implement our proposed method. Moreover, we conduct performance study experiments on the proposed algorithm. The experimental results further suggest that the proposed distance metric and the algorithm can successfully retain the utility of the location services while preserving users' privacy. Copyright © 2015 John Wiley & Sons, Ltd. Ping Xiong 0001, Lefeng Zhang, Tianqing Zhu |
Concurr. Comput. Pract. Exp. | 2 |