SearcharxivSearch

arXiv subjects

Fuyi Wang

Publications and source records attributed to Fuyi Wang.

11 recordsLinked to original sources

What Does the Server See? Understanding Privacy Leakage from Large Language Models in Split Inference

The deployment of large language models (LLMs) on resource-constrained devices remains challenging, spurring interest in split inference, where models are partitioned between client and server to reduce computational burden and enhance privacy by transmitting only intermediate activations. However, the privacy-preserving capabilities of split inference, particularly in the context of LLMs, have not been exhaustively investigated. To fill this gap, we introduce ActInv, which solves an intermediate activation matching problem to reconstruct the client's input. Extensive evaluations demonstrate that ActInv achieves high-fidelity reconstructions, even in the presence of common perturbation-based defenses such as Gaussian noise injection and activation sparsification. To systematically understand this vulnerability, we develop Perturbation Amplification Factor (PAF), a metric for quantifying a layer's inherent resistance to reconstruction. Our analysis reveals that privacy vulnerability is not uniform across layers, with some layers being highly susceptible to leakage while others offer natural resistance. Furthermore, we demonstrate that defense effectiveness can be significantly improved by calibrating perturbation directions to maximize reconstruction error during backpropagation. Building on these insights, we design PriPert and conduct comprehensive evaluations, covering privacy, utility, and computational overhead, to demonstrate its effectiveness.

cs.CR

Alteraxial Phonons in Collinear Magnets

Axial phonons, carrying angular momentum through rotational lattice vibrations, offer a promising platform for exploring phonon-magnetic coupling effects. However, how the interplay of lattice and magnetism determine the phonon angular momentum (PAM) of axial phonons remains elusive. Here, based on magnetic point group theory, we establish a symmetry framework to classify phonons in collinear magnets (e.g. ferromagnets, antiferromangets, altermagnets) into three distinct categories: ferroaxial, antiferro-nonaxial, and alteraxial phonons, which are distinguished by their different PAM patterns. Beyond the ferroaxial phonons featuring $s$-wave PAM, we reveal a complete series of alteraxial phonons, characterized by higher-order-wave PAM patterns ranging from $p$- to $j$-wave. Notably, alteraxial phonons are not limited to altermagnets, but also emerge in ferromagnets and antiferromagets. Our high-throughput search predicts hundreds of candidate magnetic materials hosting alteraxial phonons. Ab initio calculations on representative magnets further confirm the existence and distinct symmetry-enforced nodal structures of PAM in alteraxial phonons. Our work provides a complete classification for axial phonons in collinear magnetic systems and paves the way for engineering magneto-phononic phenomena.

cond-mat.mtrl-sci

FLAME: Flexible and Lightweight Biometric Authentication Scheme in Malicious Environments

Privacy-preserving biometric authentication (PPBA) enables client authentication without revealing sensitive biometric data, addressing privacy and security concerns. Many studies have proposed efficient cryptographic solutions to this problem based on secure multi-party computation, typically assuming a semi-honest adversary model, where all parties follow the protocol but may try to learn additional information. However, this assumption often falls short in real-world scenarios, where adversaries may behave maliciously and actively deviate from the protocol. In this paper, we propose, implement, and evaluate $\sysname$, a \underline{F}lexible and \underline{L}ightweight biometric \underline{A}uthentication scheme designed for a \underline{M}alicious \underline{E}nvironment. By hybridizing lightweight secret-sharing-family primitives within two-party computation, $\sysname$ carefully designs a line of supporting protocols that incorporate integrity checks with rationally extra overhead. Additionally, $\sysname$ enables server-side authentication with various similarity metrics through a cross-metric-compatible design, enhancing flexibility and robustness without requiring any changes to the server-side process. A rigorous theoretical analysis validates the correctness, security, and efficiency of $\sysname$. Extensive experiments highlight $\sysname$'s superior efficiency, with a communication reduction by {$97.61\times \sim 110.13\times$} and a speedup of {$ 2.72\times \sim 2.82\times$ (resp. $ 6.58\times \sim 8.51\times$)} in a LAN (resp. WAN) environment, when compared to the state-of-the-art work.

cs.CR

PrivGNN: High-Performance Secure Inference for Cryptographic Graph Neural Networks

Graph neural networks (GNNs) are powerful tools for analyzing and learning from graph-structured (GS) data, facilitating a wide range of services. Deploying such services in privacy-critical cloud environments necessitates the development of secure inference (SI) protocols that safeguard sensitive GS data. However, existing SI solutions largely focus on convolutional models for image and text data, leaving the challenge of securing GNNs and GS data relatively underexplored. In this work, we design, implement, and evaluate $\sysname$, a lightweight cryptographic scheme for graph-centric inference in the cloud. By hybridizing additive and function secret sharings within secure two-party computation (2PC), $\sysname$ is carefully designed based on a series of novel 2PC interactive protocols that achieve $1.5\times \sim 1.7\times$ speedups for linear layers and $2\times \sim 15\times$ for non-linear layers over state-of-the-art (SotA) solutions. A thorough theoretical analysis is provided to prove $\sysname$'s correctness, security, and lightweight nature. Extensive experiments across four datasets demonstrate $\sysname$'s superior efficiency with $1.3\times \sim 4.7\times$ faster secure predictions while maintaining accuracy comparable to plaintext graph property inference.

cs.CR

Boosting Gradient Leakage Attacks: Data Reconstruction in Realistic FL Settings

Federated learning (FL) enables collaborative model training among multiple clients without the need to expose raw data. Its ability to safeguard privacy, at the heart of FL, has recently been a hot-button debate topic. To elaborate, several studies have introduced a type of attacks known as gradient leakage attacks (GLAs), which exploit the gradients shared during training to reconstruct clients' raw data. On the flip side, some literature, however, contends no substantial privacy risk in practical FL environments due to the effectiveness of such GLAs being limited to overly relaxed conditions, such as small batch sizes and knowledge of clients' data distributions. This paper bridges this critical gap by empirically demonstrating that clients' data can still be effectively reconstructed, even within realistic FL environments. Upon revisiting GLAs, we recognize that their performance failures stem from their inability to handle the gradient matching problem. To alleviate the performance bottlenecks identified above, we develop FedLeak, which introduces two novel techniques, partial gradient matching and gradient regularization. Moreover, to evaluate the performance of FedLeak in real-world FL environments, we formulate a practical evaluation protocol grounded in a thorough review of extensive FL literature and industry practices. Under this protocol, FedLeak can still achieve high-fidelity data reconstruction, thereby underscoring the significant vulnerability in FL systems and the urgent need for more effective defense methods.

cs.LG

Ab Initio Theory of Phonon Magnetic Moment Induced by Electron-Phonon Coupling in Magnetic Materials

Circularly polarized phonons, characterized by nonzero angular momenta and magnetic moments, have attracted extensive attention. However, a long-standing critical issue in this field is the lack of an approach to accurately calculate phonon magnetic moments resulting from electron-phonon coupling (EPC) in realistic materials. Here, based on the linear response framework, we develop an ab initio theory for calculating EPC-induced magnetic properties of phonons, applicable to both insulating and metallic materials. Our method can precisely calculate phonon Zeeman splittings in magnetic metals with significant EPC, as demonstrated by the remarkable agreement with recent experimental observations of phonon Zeeman splitting in the ferromagnetic Weyl semimetal Co3Sn2S2. In addition, the long-sought magnetic phonon spectra across the entire Brillouin zone are obtained, facilitating the study of magnetic phonon transport and topology. Specifically, by constructing an inertially decoupled lattice model, we propose candidate materials exhibiting intrinsic phonon Chern states with robust unidirectional edge phonon currents. Our work paves the way for investigating novel phonon phenomena in magnetic quantum materials.

cond-mat.mtrl-sci

Bad-PFL: Exploring Backdoor Attacks against Personalized Federated Learning

Data heterogeneity and backdoor attacks rank among the most significant challenges facing federated learning (FL). For data heterogeneity, personalized federated learning (PFL) enables each client to maintain a private personalized model to cater to client-specific knowledge. Meanwhile, vanilla FL has proven vulnerable to backdoor attacks. However, recent advancements in PFL community have demonstrated a potential immunity against such attacks. This paper explores this intersection further, revealing that existing federated backdoor attacks fail in PFL because backdoors about manually designed triggers struggle to survive in personalized models. To tackle this, we design Bad-PFL, which employs features from natural data as our trigger. As long as the model is trained on natural data, it inevitably embeds the backdoor associated with our trigger, ensuring its longevity in personalized models. Moreover, our trigger undergoes mutual reinforcement training with the model, further solidifying the backdoor's durability and enhancing attack effectiveness. The large-scale experiments across three benchmark datasets demonstrate the superior performance of our attack against various PFL methods, even when equipped with state-of-the-art defense mechanisms.

cs.LG

Flat bands and magnetism in $\mathrm{\mathbf{Fe_4 Ge Te_2}}$ and $\mathrm{\mathbf{Fe_5GeTe_2}}$ due to bipartite crystal lattices

$\mathrm{Fe_{n=4,5}GeTe_2}$ exhibits quasi-two-dimensional properties as a promising candidate for a near-room-temperature ferromagnet, which has attracted great interest. In this work, we notice that the crystal lattice of $\mathrm{Fe_{n=4,5}GeTe_2}$ can be approximately regarded as being stacked by three bipartite crystal lattices. By combining the model Hamiltonians of bipartite crystal lattices and first-principles calculations, we investigate the electronic structure and the magnetism of $\mathrm{Fe_{n=4,5}GeTe_2}$. We conclude that flat bands near the Fermi level originate from the bipartite crystal lattices and that these flat bands are expected to lead to the itinerant ferromagnetism in $\mathrm{Fe_{n=4,5}GeTe_2}$. Interestingly, we also find that the magnetic moment of the Fe5 atom in $\mathrm{Fe_5 Ge Te_2}$ is distinct from the other Fe atoms and is sensitive to the Coulomb interaction $U$ and external pressure. These findings may be helpful to understand the exotic magnetic behavior of $\mathrm{Fe_{n=4,5} Ge Te_2}$.

cond-mat.mtrl-sci

Fedward: Flexible Federated Backdoor Defense Framework with Non-IID Data

Federated learning (FL) enables multiple clients to collaboratively train deep learning models while considering sensitive local datasets' privacy. However, adversaries can manipulate datasets and upload models by injecting triggers for federated backdoor attacks (FBA). Existing defense strategies against FBA consider specific and limited attacker models, and a sufficient amount of noise to be injected only mitigates rather than eliminates FBA. To address these deficiencies, we introduce a Flexible Federated Backdoor Defense Framework (Fedward) to ensure the elimination of adversarial backdoors. We decompose FBA into various attacks, and design amplified magnitude sparsification (AmGrad) and adaptive OPTICS clustering (AutoOPTICS) to address each attack. Meanwhile, Fedward uses the adaptive clipping method by regarding the number of samples in the benign group as constraints on the boundary. This ensures that Fedward can maintain the performance for the Non-IID scenario. We conduct experimental evaluations over three benchmark datasets and thoroughly compare them to state-of-the-art studies. The results demonstrate the promising defense performance from Fedward, moderately improved by 33% $\sim$ 75 in clustering defense methods, and 96.98%, 90.74%, and 89.8% for Non-IID to the utmost extent for the average FBA success rate over MNIST, FMNIST, and CIFAR10, respectively.

cs.LG

Cascadable in-memory computing based on symmetric writing and read out

The building block of in-memory computing with spintronic devices is mainly based on the magnetic tunnel junction with perpendicular interfacial anisotropy (p-MTJ). The resulting asymmetric write and read-out operations impose challenges in downscaling and direct cascadability of p-MTJ devices. Here, we propose that a new symmetric write and read-out mechanism can be realized in perpendicular-anisotropy spin-orbit (PASO) quantum materials based on Fe3GeTe2 and WTe2. We demonstrate that field-free and deterministic reversal of the perpendicular magnetization can be achieved by employing unconventional charge to z-spin conversion. The resulting magnetic state can be readily probed with its intrinsic inverse process, i.e., z-spin to charge conversion. Using the PASO quantum material as a fundamental building block, we implement the functionally complete set of logic-in-memory operations and a more complex nonvolatile half-adder logic function. Our work highlights the potential of PASO quantum materials for the development of scalable energy-efficient and ultrafast spintronic computing.

cond-mat.mes-hall

Towards Privacy-Preserving Neural Architecture Search

Machine learning promotes the continuous development of signal processing in various fields, including network traffic monitoring, EEG classification, face identification, and many more. However, massive user data collected for training deep learning models raises privacy concerns and increases the difficulty of manually adjusting the network structure. To address these issues, we propose a privacy-preserving neural architecture search (PP-NAS) framework based on secure multi-party computation to protect users' data and the model's parameters/hyper-parameters. PP-NAS outsources the NAS task to two non-colluding cloud servers for making full advantage of mixed protocols design. Complement to the existing PP machine learning frameworks, we redesign the secure ReLU and Max-pooling garbled circuits for significantly better efficiency ($3 \sim 436$ times speed-up). We develop a new alternative to approximate the Softmax function over secret shares, which bypasses the limitation of approximating exponential operations in Softmax while improving accuracy. Extensive analyses and experiments demonstrate PP-NAS's superiority in security, efficiency, and accuracy.

cs.CR