Neil Gong
· Associate Professor of Electrical and Computer EngineeringDuke University · Electrical and Computer Engineering
Active 2011–2026
Academic metrics are sourced from OpenAlex and public funding records; values may differ from Google Scholar.
About
Neil Zhenqiang Gong is a professor whose webpage lists his current and former group members, including Ph.D. students, postdocs, master students, and undergraduate students. His students have worked on topics such as safe and secure generative AI systems, privacy protection via adversarial examples, secure federated learning, and digital forensic artifacts in Android devices. Many of his former students have gone on to positions as research scientists at leading technology companies like Google Deepmind and Meta, or as tenure-track assistant professors at various universities. The webpage highlights the academic and professional trajectories of his students, reflecting his mentorship in areas related to security, privacy, and AI systems. However, the page text does not provide a direct narrative or detailed description of his own research focus, background, or key contributions.
Research topics
- Computer Science
- Artificial Intelligence
- Computer Security
- Data Mining
- Machine Learning
- Distributed computing
- Mathematics
- Theoretical computer science
- History
- Archaeology
Selected publications
FLTrust: Byzantine-robust Federated Learning via Trust Bootstrapping
2021 · 775 citations
Senior authorCorrespondingByzantine-robust federated learning aims to enable a service provider to learn an accurate global model when a bounded number of clients are malicious. The key idea of existing Byzantine-robust federated learning methods is that the service provider performs statistical analysis among the clients' local model updates and removes suspicious ones, before aggregating them to update the global model. However, malicious clients can still corrupt the global models in these methods via sending carefull…
Proceedings of the 28th ACM SIGKDD Conference on Knowledge Discovery and Data Mining · 2022 · 289 citations
Senior authorCorrespondingFederated learning (FL) is vulnerable to model poisoning attacks, in which malicious clients corrupt the global model via sending manipulated model updates to the server. Existing defenses mainly rely on Byzantine-robust or provably robust FL methods, which aim to learn an accurate global model even if some clients are malicious. However, they can only resist a small number of malicious clients. It is still an open challenge how to defend against model poisoning attacks with a large number of ma…
Backdoor Attacks to Graph Neural Networks
2021 · 201 citations
Senior authorCorrespondingIn this work, we propose the first backdoor attack to graph neural networks (GNN). Specifically, we propose a subgraph based backdoor attack to GNN for graph classification. In our backdoor attack, a GNN classifier predicts an attacker-chosen target label for a testing graph once a predefined subgraph is injected to the testing graph. Our empirical results on three real-world graph datasets show that our backdoor attacks are effective with a small impact on a GNN's prediction accuracy for clean…
Practical Blind Membership Inference Attack via Differential Comparisons
2021 · 81 citations
Membership inference (MI) attacks affect user privacy by inferring whether given data samples have been used to train a target learning model, e.g., a deep neural network. There are two types of MI attacks in the literature, i.e., these with and without shadow models. The success of the former heavily depends on the quality of the shadow model, i.e., the transferability between the shadow and the target; the latter, given only blackbox probing access to the target model, cannot make an effective…
Model Poisoning Attacks to Federated Learning via Multi-Round Consistency
2025-06-10 · 15 citations
articleSenior authorModel poisoning attacks are critical security threats to Federated Learning (FL). Existing model poisoning attacks suffer from two key limitations: 1) they achieve suboptimal effectiveness when defenses are deployed, and/or 2) they require knowledge of the model updates or local training data on genuine clients. In this work, we make a key observation that their suboptimal effectiveness arises from only leveraging model-update consistency among malicious clients within individual training rounds…
Recent grants
NSF · $400k · 2022–2026
NSF · $371k · 2019–2026
SaTC: CORE: Medium: Collaborative: Towards Robust Machine Learning Systems
NSF · $400k · 2018–2019
Frequent coauthors
- 42 shared
Jinyuan Jia
University of Hong Kong
- 37 shared
Binghui Wang
- 33 shared
Jinyuan Jia
- 32 shared
Xiaoyu Cao
Shaanxi University of Science and Technology
- 25 shared
Minghong Fang
- 17 shared
Dawn Song
- 15 shared
Prateek Mittal
- 13 shared
Yinzhi Cao
Johns Hopkins University
Labs
Not provided
Awards & honors
- NSF CAREER Award (2018)
- Army Research Office Young Investigator Program (YIP) Award…
- Rising Star Award from the Association of Chinese Scholars i…
- IBM Faculty Award (2020, 2023)
- Facebook Research Award (2021)
Similar researchers at Duke University
- Resume-aware match score
- Save to shortlist
- AI-drafted outreach
See your match with Neil Gong
PhdFit ranks faculty by your research interests, methods, and publications — grounded in their actual work, not templates.
- Free to start
- No credit card
- 30-second signup
