Trust snapshot

Quick read

Trust 21 - EmergingVerification L1Unclaimed author
8works
0followers
14topics
4close collaborators

Actions

Decide how to stay connected

Follow researcher0

Identity and collaboration

How to connect with this researcher

Claiming links this public author record to a researcher profile and unlocks direct collaboration workflows.

Log in to claim

Direct collaboration

Open a focused conversation when the fit is right

Claim this author entity first to unlock direct invitations.

Research graph

See the researcher in context

Open full explorer

Inspect adjacent work, topics, institutions and collaborators without jumping out to a separate graph page.

Building this graph slice

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

8 published item(s)

preprint2026arXiv

How to Backdoor the Knowledge Distillation

Knowledge distillation has become a cornerstone in modern machine learning systems, celebrated for its ability to transfer knowledge from a large, complex teacher model to a more efficient student model. Traditionally, this process is regarded as secure, assuming the teacher model is clean. This belief stems from conventional backdoor attacks relying on poisoned training data with backdoor triggers and attacker-chosen labels, which are not involved in the distillation process. Instead, knowledge distillation uses the outputs of a clean teacher model to guide the student model, inherently preventing recognition or response to backdoor triggers as intended by an attacker. In this paper, we challenge this assumption by introducing a novel attack methodology that strategically poisons the distillation dataset with adversarial examples embedded with backdoor triggers. This technique allows for the stealthy compromise of the student model while maintaining the integrity of the teacher model. Our innovative approach represents the first successful exploitation of vulnerabilities within the knowledge distillation process using clean teacher models. Through extensive experiments conducted across various datasets and attack settings, we demonstrate the robustness, stealthiness, and effectiveness of our method. Our findings reveal previously unrecognized vulnerabilities and pave the way for future research aimed at securing knowledge distillation processes against backdoor attacks.

preprint2022arXiv

Collaboration in Participant-Centric Federated Learning: A Game-Theoretical Perspective

Federated learning (FL) is a promising distributed framework for collaborative artificial intelligence model training while protecting user privacy. A bootstrapping component that has attracted significant research attention is the design of incentive mechanism to stimulate user collaboration in FL. The majority of works adopt a broker-centric approach to help the central operator to attract participants and further obtain a well-trained model. Few works consider forging participant-centric collaboration among participants to pursue an FL model for their common interests, which induces dramatic differences in incentive mechanism design from the broker-centric FL. To coordinate the selfish and heterogeneous participants, we propose a novel analytic framework for incentivizing effective and efficient collaborations for participant-centric FL. Specifically, we respectively propose two novel game models for contribution-oblivious FL (COFL) and contribution-aware FL (CAFL), where the latter one implements a minimum contribution threshold mechanism. We further analyze the uniqueness and existence for Nash equilibrium of both COFL and CAFL games and design efficient algorithms to achieve equilibrium solutions. Extensive performance evaluations show that there exists free-riding phenomenon in COFL, which can be greatly alleviated through the adoption of CAFL model with the optimized minimum threshold.

preprint2022arXiv

Enabling Long-Term Cooperation in Cross-Silo Federated Learning: A Repeated Game Perspective

Cross-silo federated learning (FL) is a distributed learning approach where clients of the same interest train a global model cooperatively while keeping their local data private. The success of a cross-silo FL process requires active participation of many clients. Clients in cross-silo FL aim to optimize their long-term benefits by selfishly choosing their participation levels. While there has been some work on incentivizing clients to join FL, the analysis of clients' long-term selfish participation behaviors in cross-silo FL remains largely unexplored. In this paper, we analyze the selfish participation behaviors of heterogeneous clients in cross-silo FL. Specifically, we model clients' long-term selfish participation behaviors as an infinitely repeated game. For the stage game SPFL, we derive the unique Nash equilibrium (NE), and propose a distributed algorithm for each client to calculate its equilibrium participation strategy. We show that at the NE, clients fall into at most three categories: (i) free riders, (ii) a unique partial contributor (if exists), and (iii) contributors. For the long-term interactions among clients, we derive a cooperative strategy for clients which minimizes the number of free riders while increasing the amount of local data for model training. We show that enforced by a punishment strategy, such a cooperative strategy is a subgame perfect Nash equilibrium (SPNE) of the infinitely repeated game, under which some clients who are free riders at the NE of the stage game choose to be (partial) contributors. We further propose an algorithm to calculate the optimal SPNE which minimizes the number of free riders while maximizing the amount of local data for model training. Simulation results show that our derived optimal SPNE can effectively reduce the number of free riders by up to 99.3% and increase the amount of local data for model training by up to 82.3%.

preprint2022arXiv

Topological metasurface: From passive toward active and beyond

Metasurfaces are subwavelength structured thin films consisting of arrays of units that allow the controls of polarization, phase and amplitude of light over a subwavelength thickness. The recent developments in topological photonics have greatly broadened the horizon in designing the metasurfaces for novel functional applications. In this review, we summarize recent progress in the research field of topological metasurfaces, firstly from the perspectives of passive and active in the classical regime, and then in the quantum regime. More specifically, we begin by examining the passive topological phenomena in two-dimensional photonic systems, including both time-reversal broken systems and time-reversal preserved systems. Subsequently, we move to discuss the cutting-edge studies of the active topological metasurfaces, including nonlinear topological metasurfaces and reconfigurable topological metasurfaces. After overviewing the topological metasurfaces in the classical regime, we show how the topological metasurfaces could provide a new platform for quantum information and quantum many-body physics. Finally, we conclude and describe some challenges and future directions of this fast-evolving field.

preprint2021arXiv

Reduced Ionic Diffusion by the Dynamic Electron-Ion Collisions in Warm Dense Hydrogen

The dynamic electron-ion collisions play an important rolein determining the static and transport properties of warmdense matter (WDM). Electron force field (eFF) method is applied to study the ionic transport properties of warm densehydrogen. Compared with the results from quantum moleculardynamics and orbital-free molecular dynamics, the ionicdiffusions are largely reduced by involving the dynamic collisions of electrons and ions. This physics is verified by quantum Langevin molecular dynamics (QLMD) simulations, which includes electron-ion collisions induced friction(EI-CIF) into the dynamic equation of ions. Based on these new results, we proposed a model including the correctionof collisions induced friction of the ionic diffusion. The CIF model has been verified to be valid at a wide range ofdensity and temperature. We also compare the results with the Yukawa one component plasma (YOCP) model andEffective OCP (EOCP) model. We proposed to calculate the self-diffusion coefficients using the EOCP model modifiedby the CIF model to introduce the dynamic electron-ion collisions effect.

preprint2020arXiv

Age of Processing: Age-driven Status Sampling and Processing Offloading for Edge Computing-enabled Real-time IoT Applications

The freshness of status information is of great importance for time-critical Internet of Things (IoT) applications. A metric measuring status freshness is the age-of-information (AoI), which captures the time elapsed from the status being generated at the source node (e.g., a sensor) to the latest status update.However, in intelligent IoT applications such as video surveillance, the status information is revealed after some computation intensive and time-consuming data processing operations, which would affect the status freshness. In this paper, we propose a novel metric, age-of-processing (AoP), to quantify such status freshness, which captures the time elapsed of the newest received processed status data since it is generated. Compared with AoI, AoP further takes the data processing time into account. Since an IoT device has limited computation and energy resource, the device can choose to offload the data processing to the nearby edge server under constrained status sampling frequency.We aim to minimize the average AoP in a long-term process by jointly optimizing the status sampling frequency and processing offloading policy. We formulate this online problem as an infinite-horizon constrained Markov decision process (CMDP) with average reward criterion. We then transform the CMDP problem into an unconstrained Markov decision process (MDP) by leveraging a Lagrangian method, and propose a Lagrangian transformation framework for the original CMDP problem. Furthermore, we integrate the framework with perturbation based refinement for achieving the optimal policy of the CMDP problem. Extensive numerical evaluations show that the proposed algorithm outperforms the benchmarks, with an average AoP reduction up to 30%.

preprint2020arXiv

Tailoring c-axis orientation in epitaxial Ruddlesden-Popper Pr$_{0.5}$Ca$_{1.5}$MnO$_{4}$ films

Interest for layered Ruddlesden-Popper strongly correlated manganites of Pr$_{0.5}$Ca$_{1.5}$MnO$_4$ as well as to their thin film polymorphs is motivated by the high temperature of charge orbital ordering above room temperature. We report on the tailoring of the c-axis orientation in epitaxial RP-PCMO films grown on SrTiO$_3$ (STO) substrates with different orientations as well as the use of CaMnO$_3$ (CMO) buffer layers. Films on STO(110) reveal in-plane alignment of the c-axis lying along to the [100] direction. On STO(100), two possible directions of the in-plane c-axis lead to a mosaic like, quasi two-dimensional nanostructure, consisting of RP, rock-salt and perovskite building blocks. With the use of a CMO buffer layer, RP-PCMO epitaxial films with c-axis out-of-plane were realized. Different physical vapor deposition techniques, i.e. ion beam sputtering (IBS), pulsed laser deposition (PLD) as well as metalorganic aerosol deposition (MAD) are applied in order to distinguish between the effect of growth conditions and intrinsic epitaxial properties. For all deposition techniques, despite their very different growth conditions, the surface morphology, crystal structure and orientation of the thin films reveal a high level of similarity as verified by X-ray diffraction, scanning and high resolution transmission electron microscopy. We found that for different epitaxial relations the stress in the films can be relaxed by means of a modified interface chemistry. The charge ordering in the films estimated by resistivity measurements occurs at a temperature close to that expected in bulk material.

preprint2009arXiv

Disk relations for tree amplitudes in minimal coupling theory of gauge field and gravity

KLT relations on $S_2$ factorize closed string amplitudes into product of open string tree amplitudes. The field theory limits of KLT factorization relations hold in minimal coupling theory of gauge field and gravity. In this paper, we consider the field theory limits of relations on $D_2$. Though the relations on $D_2$ and KLT factorization relations hold on worldsheets with different topologies, we find the field theory limits of $D_2$ relations also hold in minimal coupling theory of gauge field and gravity. We use the $D_2$ relations to give three- and four-point tree amplitudes where gluons are minimally coupled to gravitons. We also give a discussion on general tree amplitudes for minimal coupling of gauge field and gravity. In general, any tree amplitude with $M$ gravitons in addition to $N$ gluons can be given by pure-gluon tree amplitudes with $N+2M$ legs.