Yimin Liu 0002

dblp:69/866-2 · DBLP profile ↗
← Back
7ranked-venue papers
6as first author
7since 2021 · last 2026
0000-0002-1547-1177ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 2 since 2021
YearPublicationVenuePosition
2026 Generic Adversarial Attack Framework Against Graph-based Vertical Federated Learning
abstract
Graph-based vertical federated learning (GVFL) enables multiple parties to collaboratively train and infer over aligned nodes, where each party contributes its own local embedding derived from different attributes and adjacency relations. Adversarial inputs injected by an attacker can skew the joint prediction toward its desired outcomes while diminishing the influence of benign parties and undermining contribution. However, most attacks typically have pre-set assumptions, such as access to the server architecture, model queries, or in-domain auxiliary graphs. In this paper, we propose SGAC, an attack framework that enables domination of joint inference without relying on above assumptions. SGAC learns label-indicative embeddings and class-transferable probabilities to generate a surrogate that closely mimics the server-side classification behavior by exploiting auxiliary graphs from non-training domains. SGAC then leverages saliency over node attributes and edges on the auxiliary graphs to construct a diverse set of shadow inputs resembling highly influential test instances. With the surrogate fidelity and input diversity, SGAC crafts transferable contribution-monopoly adversarial inputs that hijack GVFL incentives. Extensive experiments across diverse model architectures validate SGAC's effectiveness.
Yimin Liu 0002, Peng Jiang 0007, Qi Liu 0068, Liehuang Zhu
AAAI1
2026 Secure Sealed-Bidding Networks via Conditional Time-Aware Access Authorization
Qi Liu 0068, Peng Jiang 0007, Yimin Liu 0002, Zhen Zhao 0005, Liehuang Zhu
ACISP (1)3
2026 Toward More Practical Label Inference Attacks Against Graph-Based Vertical Federated Learning
abstract
Graph-based vertical federated learning (GVFL) enables an active party who owns a labeled graph to collaborate with passive parties who possess additional node features and edges to improve model performance. GVFL shares representations and gradients, allowing passive parties to retain their optimized bottom models, which makes previous GVFL algorithms unable to resist label inference attacks. However, most attacks assume that the attacker has access to the training data’s exact class space, the top model, or labeled auxiliary datasets from the training domain. These strong assumptions are not practical for real-world GVFL applications. In this paper, we propose Knowledge Transfer Attack (KTA), which leverages only auxiliary graphs from non-training domains to infer private labels. To address domain shift and ensure effective supervision transfer, KTA adapts a surrogate classifier in an aligned representation space while mitigating the negative influence of irrelevant outlier-class supervision. Specifically, KTA exploits the global consistency of cross-domain graphs and incorporates adaptive shift parameters into graph encoding. KTA then aligns cross-domain distributions within the shared class space and mitigates negative transfer by filtering outlier source classes. Experiments confirm the effectiveness of KTA in inferring the active party’s private labels and superiority over state-of-the-art attacks.
Yimin Liu 0002, Peng Jiang 0007, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.1
2025 Generic Adversarial Attack Framework Against Vertical Federated Learning
abstract
Vertical federated learning (VFL) enables feature-level collaboration by incorporating scattered attributes from aligned samples, and allows each party to contribute its personalized input to joint training and inference. The injection of adversarial inputs can mislead the joint inference towards the attacker’s will, forcing other benign parties to make negligible contributions and losing rewards regarding the importance of their contributions. However, most attacks require server model queries, subsets of complete test samples, or labeled auxiliary images from the training domain. These extra requirements are not practical for real-world VFL applications. In this paper, we propose PGAC, a novel and practical attack framework for crafting adversarial inputs to dominate joint inference, which does not rely on the above requirements. PGAC advances prior attacks by requiring only access to auxiliary images from non-training domains. PGAC learns generalized label-indicative embeddings and estimates class-transferable probabilities across domains to generate a proxy model that closely approximates the server model. PGAC then augments images by emphasizing salient regions with class activation maps, creating a diverse shadow input set that resembles influential test inputs. With proxy fidelity and input diversity, PGAC crafts transferable adversarial inputs. Evaluation on diverse model architectures confirms the effectiveness of PGAC.
Yimin Liu 0002, Peng Jiang 0007
IJCAI1
2025 Preference Profiling Attacks Against Vertical Federated Learning Over Graph Data
Yimin Liu 0002, Peng Jiang 0007, Liehuang Zhu
INFOCOM1
2024 SecVerGSSL: Proof-Based Verified Computation for Graph Self-Supervised Learning
abstract
As graph data becomes increasingly prevalent in mobile computing scenarios, deploying Graph Convolutional Network-based self-supervised learning (GCN-SSL) models on mobile devices provides a powerful solution for analyzing graph data and enhancing the intelligence of various mobile services. However, ensuring the legitimacy and security of these models is crucial to protect against compromised or unauthorized versions that could lead to security vulnerabilities or intellectual property issues. In this work, we propose PoGSSL, a verifiable proof of GCN-SSL model training that authenticates model integrity and provenance by checking the reproducibility of the specific model training process. We then introduce SecVerGSSL from PoGSSL to provide privacy-preserving verified computation services. SecVerGSSL offloads the entire computation to the cloud and equips servers with customized secure components, enabling effective verified computation over secret-sharing encrypted training data and PoGSSL. Extensive experiments demonstrate that SecVerGSSL offers verification accuracy indistinguishable from plaintext results, with overhead on the verifier-side requiring at most 10.35 milliseconds and 65.98 KB per epoch.
Yimin Liu 0002, Peng Jiang 0007, Liehuang Zhu
IEEE Trans. Mob. Comput.1
2023 Subject-Level Membership Inference Attack via Data Augmentation and Model Discrepancy
abstract
Federated learning (FL) models are vulnerable to membership inference attacks (MIAs), and the requirement of individual privacy motivates the protection of subjects where the individual data is distributed across multiple users in the cross-silo FL setting. In this paper, we propose a subject-level membership inference attack based on data augmentation and model discrepancy. It can effectively infer whether the data distribution of the target subject has been sampled and used for training by specific federated users, even if other users (also) may sample from the same subject and use it as part of their training set. Specifically, the adversary uses a generative adversarial network (GAN) to perform data augmentation on a small amount of priori federation-associated information known in advance. Subsequently, the adversary aggregates two different outputs from the global and tested user models using an optimal feature construction method. We simulate a controlled federation configuration and conduct extensive experiments on real datasets that include both image and categorical data. Results show that the area under the curve (AUC) is improved by 12.6% to 16.8% compared to the classical membership inference attack. This is at the expense of the test accuracy of the data augmented with GAN, which is at most 3.5% lower than the real test data. We also explore the degree of privacy leakage between overfitted models and well-generalized models in the cross-silo FL setting and conclude experimentally that the former is more likely to leak individual privacy with a subject-level degradation rate of up to 0.43. Finally, we present two possible defense mechanisms to attenuate this newly discovered privacy risk.
Yimin Liu 0002, Peng Jiang 0007, Liehuang Zhu
IEEE Trans. Inf. Forensics Secur.1