Lina Wang 0001

dblp:01/1318-1 · DBLP profile ↗
← Back
133ranked-venue papers
4as first author
88since 2021 · last 2026
0000-0001-8085-1312ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 53 · 2 first-author · 46 since 2021Security and privacy · 31 · 1 first-author · 15 since 2021Graphics, computer vision, multimedia, augmented reality and games · 28 · 1 first-author · 19 since 2021Databases, data management, data science and information retrieval · 17 · 16 since 2021Computer networks · 10 · 4 since 2021Software engineering, systems software and programming languages · 7 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 5 since 2021Systems, architecture and hardware · 4 · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021
YearPublicationVenuePosition
2026 ReLUPruner: Rethinking ReLU Importance with Taylor Expansion for Efficient Private Inference
abstract
With the growing adoption of Machine-Learning-As-A-Service (MLaaS), Private Inference (PI) has emerged as a promising solution to address its security concerns through cryptographic techniques. However, nonlinear operations in neural networks account for most of the computational and communication overhead in PI. Existing studies mainly focus on optimizing and reducing the number of ReLU activations in neural networks, but traditional pruning methods may mistakenly remove ReLUs that are critical to maintaining model accuracy. To accurately evaluate the importance of ReLUs in the network, we propose ReLUPruner, a method that uses Taylor expansion to quantify the impact on loss before and after ReLU replacement. Furthermore, we establish a hierarchical importance metric to guide layer-wise ReLU budget allocation and adopt a progressive pruning strategy that dynamically adjust the pruning rate of each layer according to training progress. Extensive experiments on various models and datasets show that ReLUPruner achieves a good balance between ReLU budget and model accuracy, yielding improvements of 1.89% (12.9k ReLUs, CIFAR-10), 3.62% (50k ReLUs, CIFAR-100) and 2.66% (30k ReLUs, Tiny-ImageNet) over the previous state-of-the-art.
Jinshuo Liu, Lina Wang 0001, Jeff Z. Pan
AAAI4
2026 Semantic Alignment of Malicious Question Based on Contrastive Semantic Networks and Data Augmentation (Abstract Reprint)
abstract
The identification and filtration of malicious texts in social media environments represent a significant technical challenge aimed at protecting users from online violence and disinformation. This complexity stems from the diversity and innovativeness of social media texts, which include unique expressions and special sentence structures. Particularly, malicious texts in interrogative forms pose alignment challenges with traditional corpora due to existing methods’ failure to exploit the text’s deep global semantic representations. This issue is compounded by the scant research on Chinese texts, leading to inefficiencies in recognition accuracy. To mitigate these challenges, we introduce an innovative framework based on a Global Contrastive Semantic Network (GCSN), designed to enhance malicious text recognition efficiency and accuracy by deeply learning global semantic knowledge. It comprises an encoder for global semantic information modelling and a graph-matching network for semantic similarity evaluation between question pairs, enabling the accurate identification and filtering of malicious texts with complex structures. Furthermore, we introduce a semantic consistency-based data augmentation method (COMBINE), using real-world data to generate balanced positive and negative samples, enriching the dataset and enhancing the model’s ability to distinguish semantic consistency through contrastive learning. Experimental validation on two Chinese datasets demonstrates our model’s exceptional performance, affirming its applicationa value in social media malicious text recognition. Our code is available at https://github.com/Wxy13131313131/GCSN-COMBINE
Jinshuo Liu, Juan Deng, Meng Wang 0050, Youcheng Yan, Lina Wang 0001, Yunsong Ma, Jeff Z. Pan
AAAI7
2026 MacPrompt: Maraconic-Guided Jailbreak Against Text-to-Image Models
abstract
Text-to-image (T2I) models have raised increasing safety concerns due to their capacity to generate NSFW and other banned objects. To mitigate these risks, safety filters and concept removal techniques have been introduced to block inappropriate prompts or erase sensitive concepts from the models. However, all the existing defense methods are not well prepared to handle diverse adversarial prompts. In this work, we introduce MacPrompt, a novel black-box and cross-lingual attack that reveals previously overlooked vulnerabilities in T2I safety mechanisms. Unlike existing attacks that rely on synonym substitution or prompt obfuscation, MacPrompt constructs macaronic adversarial prompts by performing cross-lingual character-level recombination of harmful terms, enabling fine-grained control over both semantics and appearance. By leveraging this design, MacPrompt crafts prompts with high semantic similarity to the original harmful inputs (up to 0.96) while bypassing major safety filters (up to 100%). More critically, it achieves attack success rates as high as 92% for sex-related content and 90\% for violence, effectively breaking even state-of-the-art concept removal defenses. These results underscore the pressing need to reassess the robustness of existing T2I safety mechanisms against linguistically diverse and fine-grained adversarial strategies. Warning: This paper includes sensitive examples (e.g., adult, violent, or illegal content). Unsafe images are masked but may still be disturbing.
Xi Ye 0004, Lina Wang 0001, Run Wang 0001, Geying Yang, Yufei Hou, Jiayi Yu
AAAI3
2026 PCFormer: Accelerating Privacy-preserving Transformer Inference by Partition and Combination
abstract
In recent years, transformer-based models have achieved remarkable success in sensitive domains, including healthcare, finance and personalized services, but their deployment raises significant privacy concerns. Existing secure inference studies have introduced cryptographic techniques such as Homomorphic Encryption (HE) and Secure Multi-Party Computation (MPC). However, these approaches either target isolated model components or incur prohibitive computational and communication overheads, failing to support latency-sensitive or resource-limited environments. In our investigation, we identify substantial redundancy in the nonlinear operations and their alternation with linear layers in deep learning. Motivated by this observation, we propose PCFormer, a universal optimization methodology tailored for sequences of linear and nonlinear computations in the Transformer. PCFormer introduces structure-aware partition and combination techniques specially designed for Multi-Head Attention (MHA) and Feed-Forward Network (FFN). Specifically, we reveal the discrete sources of redundancy in the Softmax and GeLU functions during inference, implementing partitions at the token and channel levels, respectively. Subsequently, these reductions are then combined with the preceding and succeeding linear operations, thereby enhancing both computational and communication efficiency. Experimental results on GLUE benchmarks demonstrate that PCFormer achieves a 1.9× speedup in both computation and communication without compromising accuracy, compared to existing privacy-preserving Transformer frameworks. Furthermore, we demonstrate that PCFormer generalizes effectively to other deep learning architectures involving structured linear-nonlinear compositions under cryptographic constraints.
Bo Zeng 0006, Zhi Pang, Tian Wu 0004, Geying Yang, Lina Wang 0001, Run Wang 0001
AAAI7
2026 RoarChain: A Robust Sharding Blockchain System for Enterprise Consortium
Xiaochun Yang 0001, Lina Wang 0001
ICDE5
2026 A digital twin-based reputation assessment model for JointCloud computing
Yadi Wu, Lina Wang 0001, Rongwei Yu, Xiuwen Huang
J. Netw. Comput. Appl.2
2026 Corrigendum to "Collaborate Large and Small Language Models for Multi-Modal Emergency Rumor Detection" [Neural Networks 190, 2025, 107625]
Youcheng Yan, Jinshuo Liu, Juan Deng, Lina Wang 0001, Jeff Z. Pan
Neural Networks5
2026 SFI: A Practical and Efficient Backdoor Attack Framework Against Split Learning
abstract
Split learning is a computing resource-friendly distributed learning framework that protects client training data by splitting the model between the client and server. Previous work has proved that split learning faces a severe risk of privacy leakage, as a malicious server can recover the client's private data by hijacking the training process. In this paper, we explore the vulnerability of split learning to server-side backdoor attacks, where our goal is to compromise the model's integrity. Since the server-side attacker cannot access the training data and client model in split learning, the traditional poisoning-based backdoor attack methods are no longer applicable. Therefore, constructing backdoor attacks in split learning poses significant challenges. Our strategy involves the attacker establishing a shadow model on the server side that can encode backdoor samples and guide the client model in learning from this model during the training process, thereby enabling the client to acquire the same capability. Based on these insights, we propose a backdoor attack framework named SFI. Our attack framework minimizes assumptions about the attacker's background knowledge and ensures that the attack remains imperceptible to the client. We implement SFI on various benchmark datasets, and extensive experimental results demonstrate its effectiveness and generality.
Fangchao Yu, Bo Zeng 0006, Zhi Pang, Lina Wang 0001
IEEE Trans. Dependable Secur. Comput.5
2026 Decoupled Neural Audio Steganography for Adaptive Sender-Side Model Updates
abstract
Neural network–based steganography has garnered considerable attention for its strong security. However, existing approaches often suffer from excessive coupling between the embedding and extraction networks: the sender and receiver must employ paired models and maintain strict synchronization. Such synchronization not only complicates deployment but also introduces more severe potential risks of information leakage. To overcome this limitation, we propose a synchronization-free steganographic framework based on decoupled neural embedding networks, following the destruction–restoration principle. In our design, message embedding is realized through a destruction operation, while recovery is achieved using a neural network from the audio restoration domain. This decoupled architecture allows the sender to upgrade, replace, or randomize the embedding network—thus enabling dynamic model changes—without impairing the receiver’s ability to correctly extract the hidden message. As a result, synchronization-related vulnerabilities are fundamentally eliminated. Experimental results demonstrate that even under dynamic changes in the embedding network, the hidden information can still be reliably extracted, confirming both the effectiveness and enhanced security of the proposed approach.
Qiyang Xiao, Yanzhen Ren, Lina Wang 0001
IEEE Trans. Inf. Forensics Secur.5
2025 Transfer Learning of Real Image Features with Soft Contrastive Loss for Fake Image Detection
abstract
In the last few years, the artifact patterns in fake images synthesized by different generative models have been inconsistent, leading to the failure of previous research that relied on spotting subtle differences between real and fake. In our preliminary experiments, we find that the artifacts in fake images always change with the development of the generative model, while natural images exhibit stable statistical properties. In this paper, we employ natural traces shared only by real images as an additional target for a classifier. Specifically, we introduce a self-supervised feature mapping process for natural trace extraction and develop a transfer learning based on soft contrastive loss to bring them closer to real images and further away from fake ones. This motivates the detector to make decisions based on the proximity of images to the natural traces. To conduct a comprehensive experiment, we built a high-quality and diverse dataset that includes generative models comprising GANs and diffusion models, to evaluate the effectiveness in generalizing unknown forgery techniques and robustness in surviving different transformations. Experimental results show that our proposed method gives 96.2% mAP significantly outperforms the baselines. Extensive experiments conducted on the widely recognized platform Midjourney reveal that our proposed method achieves an accuracy exceeding 78.4%, underscoring its practicality for real-world application deployment.
Ziyou Liang, Weifeng Liu 0008, Run Wang 0001, Boheng Li, Lina Wang 0001
AAAI7
2025 Automated Red Teaming for Text-to-Image Models Through Feedback-Guided Prompt Iteration with Vision-Language Models
Wei Xu 0039, Kangjie Chen, Jiawei Qiu, Run Wang 0001, Tianwei Zhang 0004, Lina Wang 0001
ICCV8
2025 A Code-based Group Signature Scheme from the Schnorr-Lyubashevsky Framework
abstract
Code-based group signatures are a promising candidate for post-quantum cryptography, but existing code-based group signature schemes struggle with the challenges of large signature sizes caused by zero-knowledge proofs. To address this issue, we propose a novel and practical code-based group signature scheme built upon the Schnorr-Lyubashevsky paradigm. Our construction achieves constant-size signatures and public keys, independent of the group cardinality, and its security is formally proven in the random oracle model under the hardness assumptions of the Syndrome Decoding (SD) and Decoding One Out of Many (DOOM) problems. To alleviate the performance bottleneck of rejection sampling, we design and implement a batch processing optimization for the signing algorithm, which significantly accelerates signature generation by applying vectorization to the most computationally intensive operations. Experimental results show that the optimization renders signing practical. Our scheme features the most compact signature size among existing codebased group signature schemes. All related code is open-sourced and available at https://github.com/Latters/CodeBasedGroupSig/.
Shuwang Xu, Lusheng Chen, Geying Yang, Fangchao Yu, Yufei Hou, Lina Wang 0001
ICPADS6
2025 HIPP: Protecting Image Privacy via High-Quality Reversible Protected Version
abstract
With the rapid development of the internet, sharing photos through Social Network Platforms (SNPs) has become a new way for people to socialize, which poses serious threats to personal privacy. Recently, a thumbnail-preserving image privacy protection technique has emerged and garnered widespread attention. However, the existing schemes based on this technique often introduce noticeable noise into the protected image, resulting in poor visual quality. Motivated by the observation that a latent vector can be decoupled into the detail and contour components, in this paper, we propose HIPP, a thumbnail-preserving image privacy protection scheme that decouples the detail and contour information contained in the latent vector corresponding to the original image and reconstructs details by generation model. As a result, the generated protected image appears natural and has a thumbnail similar to the original one. Moreover, the protected images can be restored to versions that are indistinguishable from the original images. Experiments on CelebA, Helen, and LSUN datasets show that the SSIM between the restored and original images achieves 0.9899. Furthermore, compared to the previous works, HIPP achieves the lowest runtime and file expansion rate, with values of 0.07 seconds and 1.1046, respectively.
Xi Ye 0004, Lina Wang 0001, Run Wang 0001, Geying Yang
IJCAI2
2025 Prompt as a Double-Edged Sword: A Dynamic Equilibrium Gradient-Assigned Attack against Graph Prompt Learning
abstract
Graph prompt learning (GPL) is designed to bridge the gap between graph pretraining models and downstream graph tasks, providing advantages in terms of graph knowledge transfer. However, GPL is vulnerable to poisoned graph attacks that induce abnormal training via adversarial malicious perturbations. We observe that the prevalent meta-gradient attacks, which heavily rely on the training of surrogate graph neural networks (GNNs), fail to account for the impact of perturbations on GPL where the pretrained GNN remains frozen and graph prompt tokens are tuned. Moreover, their gradient-assigned strategies tend to corrupt the topological semantics on a few influential labeled graphs, which in turn diminishes the trustworthiness of the surrogate training. To address this issue, we propose a dynamic equilibrium gradient-assigned attack against GPL, named MetaGpro. To guarantee the transferability of MetaGpro, the surrogate GPL is utilized in our simulation across various downstream tasks. To dynamically equilibrate the relationships between the reliability of surrogate models and instable structures, the over-robust contrastive learning is integrated into the surrogate training. In this way, the gradient bias caused by excessive perturbations of labeled nodes can be effectively mitigated. Subsequently, the topology perturbation generation is exploited to assign more gradient weights to nodes that are closer to the misclassification area. The experimental results reveal that the surrogate GPL outperforms the surrogate GNN in 96% of downstream evaluations, and our MetaGpro reduces the accuracy of GPL by 2%∼20% compared to the state-of-the-art (SOTA) works mostly. The code for our MetaGpro is available here.
Ju Jia, Jingxuan Yu, Di Wu 0050, Cong Wu 0003, Hengjie Zhu, Lina Wang 0001
KDD (2)6
2025 Analogy-based Multi-Turn Jailbreak against Large Language Models
abstract
Large language models (LLMs) are inherently designed to support multi-turn interactions, which opens up new possibilities for jailbreak attacks that unfold gradually and potentially bypass safety mechanisms more effectively than single-turn attacks. However, current multi-turn jailbreak methods are still in their early stages and suffer from two key limitations. First, they all inherently require inserting sensitive phrases into the context, which makes the dialogue appear suspicious and increases the likelihood of rejection, undermining the effectiveness of the attack. Second, even when harmful content is generated, the response often fails to align with the malicious prompt due to semantic drift, where the conversation slowly moves away from its intended goal. To address these challenges, we propose an analogy-based black-box multi-turn jailbreak framework that constructs fully benign contexts to improve attack success rate while ensuring semantic alignment with the malicious intent. The method first guides the model through safe tasks that mirror the response structure of the malicious prompt, enabling it to internalize the format without exposure to sensitive content. A controlled semantic shift is then introduced in the final turn, substituting benign elements with malicious ones while preserving structural coherence. Experiments on six commercial and open-source LLMs, two benchmark datasets show that our method significantly improves attack performance, achieving an average attack success rate of 93.3\% and outperforming five competitive baselines. Our code is released at https://github.com/MM-WW55/AMA
Yihao Huang 0001, Zhenjun Lin, Kangjie Chen, Run Wang 0001, Lina Wang 0001
NeurIPS8
2025 PATFinger: Prompt-Adapted Transferable Fingerprinting against Unauthorized Multimodal Dataset Usage
abstract
The multimodal datasets can be leveraged to pre-train large-scale vision-language models by providing cross-modal semantics. Current endeavors for determining the usage of datasets mainly focus on single-modal dataset ownership verification through intrusive methods and non-intrusive techniques, while cross-modal approaches remain under-explored. Intrusive methods can adapt to multimodal datasets but degrade model accuracy, while non-intrusive methods rely on label-driven decision boundaries that fail to guarantee stable behaviors for verification. To address these issues, we propose a novel prompt-adapted transferable fingerprinting scheme from a training-free perspective, called PATFinger, which incorporates the global optimal perturbation (GOP) and the adaptive prompts to capture dataset-specific distribution characteristics. Our scheme utilizes inherent dataset attributes as fingerprints instead of compelling the model to learn triggers. The GOP is derived from the sample distribution to maximize embedding drifts between different modalities. Subsequently, our PATFinger re-aligns the adaptive prompt with GOP samples to capture the cross-modal interactions on the carefully crafted surrogate model. This allows the dataset owner to check the usage of datasets by observing specific prediction behaviors linked to the PATFinger during retrieval queries. Extensive experiments demonstrate the effectiveness of our scheme against unauthorized multimodal dataset usage on various cross-modal retrieval architectures by 30% over state-of-the-art baselines.
Ju Jia, Xiaojun Jia, Yihao Huang 0001, Xinfeng Li, Cong Wu 0003, Lina Wang 0001
SIGIR7
2025 MFD: Multidimensional Feature Fusion and Masked Autoencoder for Encrypted Malicious Traffic Detection
abstract
The classification of encrypted network traffic (ENTC) is vital for ensuring network security, effective administration, and maintaining service quality. To accurately detect malicious encrypted traffic in communications and overcome the challenges posed by traditional detection methods, including the lack of labeled training data, difficulty in feature identification, and reliance on single-method approaches, we propose a novel framework based on Masked Autoencoders (MAE) and multidimensional feature fusion. Using a formatted traffic representation matrix that incorporates hierarchical flow information, we extract raw traffic features, plaintext packet features, and traditional statistical features in image format. Multidimensional feature fusion is achieved through RGB multi-channel integration. Our approach utilizes the MAE paradigm, which pre-trains a classifier on extensive unlabeled data and fine-tunes it with minimal labeled data for traffic classification. Experimental results demonstrate that our method achieves detection accuracy exceeding 98% on three public traffic datasets: USTC-TFC2016, ISCX-VPN2016, and CICIoT2022, significantly outperforming other deep learning methods.
Chenhao Liu, Xinwang Ding, Lina Wang 0001, Zhi Pang, Chenye Yang, Bofei Jia, Rongwei Yu
SMC3
2025 USD: NSFW Content Detection for Text-to-Image Models via Scene Graph
Kangjie Chen, Jiahui Wen, Yihui Jin, Ziyou Liang, Yihao Huang 0001, Run Wang 0001, Lina Wang 0001
USENIX Security Symposium9
2025 LPPAC: Lightweight privacy-preserving distributed payments with access control
Bo Zeng 0006, Tian Wu 0004, Fangchao Yu, Geying Yang, Lina Wang 0001
Comput. Networks6
2025 FedMP: A multi-pronged defense algorithm against Byzantine poisoning attacks in federated learning
Lina Wang 0001, Fangchao Yu, Bo Zeng 0006, Zhi Pang
Comput. Networks2
2025 TSIDS: Spatial-temporal fusion gating Multilayer Perceptron for network intrusion detection
Lina Wang 0001, Jianpeng Ke, Rongwei Yu
Expert Syst. Appl.2
2025 FMG-locator: Fusion SegFormer with facial mask guidance for multi-person forgery localization
Lina Wang 0001, Run Wang 0001, Xi Ye 0004
Expert Syst. Appl.2
2025 A distributed monitoring architecture for JointCloud computing
Yadi Wu, Lina Wang 0001, Rongwei Yu, Xiuwen Huang
Future Gener. Comput. Syst.2
2025 Exposing the Forgery Clues of DeepFakes via Exploring the Inconsistent Expression Cues
abstract
The pervasive prevalence of DeepFakes poses a profound threat to individual privacy and the stability of society. Believing the synthetic videos of a celebrity and trumping up impersonated forgery videos as authentic are just a few consequences generated by DeepFakes. We investigate current detectors that blindly deploy deep learning techniques that are not effective in capturing subtle clues of forgery when generative models produce remarkably realistic faces. Inspired by the fact that synthetic operations inevitably modify the regions of eyes and mouth to match the target face with the identity or expression of the source face, we conjecture that the continuity of facial movement patterns representing expressions that existed in the veritable faces will be disrupted or completely broken in synthetic faces, making it a potentially formidable indicator for DeepFake detection. To prove this conjecture, we utilize a dual‐branch network to capture the inconsistent patterns of facial movements within eyes and mouth regions separately. Extensive experiments on popular FaceForensics++, Celeb‐DF‐v1, Celeb‐DF‐v2, and DFDC‐Preview datasets have demonstrated not only effectiveness but also the robust capability of our method to outperform the state‐of‐the‐art baselines. Moreover, this work represents greater robustness against adversarial attacks, achieving ASR of 54.8% in the I‐FGSM attack and 43.1% in the PGD attack on the DeepFakes dataset of FaceForensics++, respectively.
Lina Wang 0001, Run Wang 0001, Jianpeng Ke, Xi Ye 0004, Yadi Wu
Int. J. Intell. Syst.2
2025 Semantic Alignment of Malicious Question Based on Contrastive Semantic Networks and Data Augmentation
abstract
The identification and filtration of malicious texts in social media environments represent a significant technical challenge aimed at protecting users from online violence and disinformation. This complexity stems from the diversity and innovativeness of social media texts, which include unique expressions and special sentence structures. Particularly, malicious texts in interrogative forms pose alignment challenges with traditional corpora due to existing methods' failure to exploit the text's deep global semantic representations. This issue is compounded by the scant research on Chinese texts, leading to inefficiencies in recognition accuracy. To mitigate these challenges, we introduce an innovative framework based on a Global Contrastive Semantic Network (GCSN), designed to enhance malicious text recognition efficiency and accuracy by deeply learning global semantic knowledge. It comprises an encoder for global semantic information modelling and a graph-matching network for semantic similarity evaluation between question pairs, enabling the accurate identification and filtering of malicious texts with complex structures. Furthermore, we introduce a semantic consistency-based data augmentation method (COMBINE), using real-world data to generate balanced positive and negative samples, enriching the dataset and enhancing the model's ability to distinguish semantic consistency through contrastive learning. Experimental validation on two Chinese datasets demonstrates our model's exceptional performance, affirming its applicationa value in social media malicious text recognition. Our code is available at https://github.com/Wxy13131313131/GCSN-COMBINE
Jinshuo Liu, Juan Deng, Meng Wang 0050, Youcheng Yan, Lina Wang 0001, Yunsong Ma, Jeff Z. Pan
J. Artif. Intell. Res.7
2025 PrivCore: Multiplication-activation co-reduction for efficient private inference
Zhi Pang, Lina Wang 0001, Fangchao Yu, Bo Zeng 0006, Shuwang Xu
Neural Networks2
2025 Collaborate large and small language models for multi-modal emergency rumor detection
Youcheng Yan, Jinshuo Liu, Juan Deng, Lina Wang 0001, Jeff Z. Pan
Neural Networks5
2025 GAN-based data reconstruction attacks in split learning
Bo Zeng 0006, Sida Luo, Fangchao Yu, Geying Yang, Lina Wang 0001
Neural Networks6
2025 SIGFinger: A Subtle and Interactive GNN Fingerprinting Scheme Via Spatial Structure Inference Perturbation
abstract
There have been significant improvements in intellectual property (IP) protection for deep learning models trained on euclidean data. However, the complex and irregular graph-structured data in non-euclidean space poses a huge challenge to the IP protection of graph neural networks (GNNs). To address this issue, we propose a subtle and interactive GNN fingerprinting scheme through spatial structure inference perturbation, which captures the stable coordination patterns of fingerprint to guarantee the reliability of copyright verification. Specifically, the data augmentation based on adaptive graph diffusion is first exploited to generate more samples, which enables the exploration of fingerprint information from coarse to fine. Subsequently, the graph-structured data are manipulated by multi-constrained spectral clustering to analyze intrinsic and extrinsic structure correlations in a causal inference manner. Ultimately, the cycle-consistent statistical optimization is performed to determine the copyright of GNN models from both intra-graph and inter-graph perspectives. Extensive experiments show that our proposed scheme can effectively verify the IP of GNN models on various challenging graph-structured datasets. Furthermore, we reveal that the space causality inference can facilitate the acquisition of inherent structural information, which improves the quality and robustness of the fingerprint under model modification operations and other model stealing attacks.
Ju Jia, Cong Wu 0003, Siqi Ma 0001, Lina Wang 0001, Robert H. Deng
IEEE Trans. Dependable Secur. Comput.5
2025 Generalized Local Optimality for Video Steganalysis in Motion Vector Domain
abstract
Video steganography that conceals secret data into motion vectors (MVs) is a popular covert communication technique. The local optimality of MVs is an intrinsic property in video coding, and any modifications to the MVs will inevitably destroy this optimality, making it a sensitive indicator of steganography. Thus the local optimality is commonly used to design features in video steganalysis. However, the local optimality in existing works is often estimated inaccurately or by using an unreasonable assumption, limiting its capability in steganalysis. In this article, we propose to estimate the local optimality in a more reasonable and comprehensive fashion, and generalize the local optimality in two aspects. First, we generalize the local optimality from a static estimation to a dynamic one by considering the variability of predicted motion vectors (PMVs). Second, we generalize the local optimality from MV domain to PMV domain by leveraging the statistical anomaly of PMVs. Based on the two generalizations that ensure a more accurate estimation of local optimality from more views, we construct new types of steganalytic features and also propose feature symmetrization rules to reduce feature dimension. Extensive experiments demonstrate the superiority of the proposed features, which achieve state-of-the-art accuracy and robustness under various conditions.
Liming Zhai, Lina Wang 0001, Yanzhen Ren, Yang Liu 0003
IEEE Trans. Dependable Secur. Comput.2
2025 Environment-Adaptive Representation Interaction for Privacy-Perturbed Graphs Against Deceptive OOD Attacks
abstract
Graph neural networks (GNNs) have gained increasing popularity in understanding graph-structured data due to their ability to derive meaningful representations by aggregating complicated topological information. However, privacy operations such as differential privacy mechanisms that inject noise into node features or graph structures to protect sensitive information, and distribution shifts in graph data pose tremendous security risks for the wide application of GNN models. Current researches mainly focus on defending the out-of-distribution (OOD) attacks through robust adversarial training and graph structure purification. Nonetheless, privacy perturbations of graph structures may render OOD attacks more deceptive by obfuscating the distinctiveness of nodes, leading to the failure of existing defense methods. To address these shortcomings, we propose an environment-adaptive representation interaction (EARI) scheme that strengthens the privacy perception of GNNs. Specifically, our scheme leverages the interaction between non-private and private data to enable targeted embedding propagation by the guidance of confidence score feedback. Subsequently, the representation-enriched topological aggregation is implemented to capture more discriminative features by exploiting multi-hop neighborhoods rather than stacked multilayers. Finally, the generalization-enhanced cluster-wise adaptation learning is leveraged to highlight the invariant correlations from nodes across different environments. Extensive experimental results demonstrate that our scheme can enhance the capability of learning representations from privacy-protected graph data, enabling GNNs to effectively defend against deceptive OOD attacks on various graph-structured datasets. Moreover, we reveal that the utilization of interactive topological aggregation can extremely enrich the diversity and guarantee the effectiveness for graph representations.
Ju Jia, Cong Wu 0003, Yebo Feng, Siqi Ma 0001, Lina Wang 0001, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.6
2025 Provably Secure and Robust Audio Steganography Under Multi-Format Low-Bitrate Compression
abstract
With the rapid advancement of audio generation models, research on audio steganography has entered a new phase of opportunity. Nevertheless, most existing generative steganographic approaches focus primarily on security while neglecting the compression and transcoding processes that are common in real-world communication. This oversight leads to two major issues: the introduction of verification mechanisms would violate its security proof assumptions, and quantization-based compression markedly reduces message extraction accuracy. In this work, we propose a robust audio steganography method that preserves provable security under various compression conditions. The security of our method relies exclusively on the latent space following a fixed distribution, which is independent of the embedded message. The proposed encoding–decoding scheme supports a tunable trade-off between capacity and robustness, allowing the sacrifice of partial capacity to reinforce robustness. Theoretical analysis shows that even with redundant error-checking codes, the latent distribution remains invariant after message embedding, thereby preserving both steganographic security and generation quality while ensuring practical applicability. Experimental results demonstrate that our method maintains message extraction accuracy under both MP3 and AAC compression and re-compression across bitrates of 160 kbps, 128 kbps, 64 kbps, 48 kbps, and even 32 kbps.
Qiyang Xiao, Yanzhen Ren, Lina Wang 0001
IEEE Trans. Inf. Forensics Secur.5
2025 ScorpioBase: An Efficient Batched Blockchain System for Traceability Applications in Supply Chain
abstract
Blockchain is increasingly applied to traceability applications in supply chains for its tamper-proof nature, but it must also ensure the core requirements, which are efficient data storage and verifiable queries. Existing solutions create an authenticated data structure (ADS) for each tuple and use a Merkle variant on a blockchain to maintain evidence. However, consensus algorithms slow down block generation, and limited block capacity results in excessive blockchain space usage by ADS, failing to meet efficient data storage needs. In this article, we present ScorpioBase, a batched blockchain system with two components: the storage engine (SE) and the signature manager (SM). SE packages multiple tuples into a “batch” data structure and generates a “batch” signature. SM stores the “batch” signature on the blockchain for evidence. Batching effectively reduces the blockchain storage burden, allowing the system to store more tuples with the same number of consensus events, thus increasing throughput. We design a fine-grained “batch” signature to enable ScorpioBase to support verifiable queries. “Batch” signatures can efficiently verify the integrity of both the “batch” and each tuple within it. In conclusion, ScorpioBase supports asynchronous queries for varying security and efficiency needs and ensures robustness against malicious attacks in verifiable queries. Compared to existing solutions, it significantly improves data storage capacity and the efficiency of verifiable queries.
Yuan Sui 0002, Xiaochun Yang 0001, Bin Wang 0015, Wei Wang 0009, Lina Wang 0001
IEEE Trans. Ind. Informatics6
2025 AQE-RF: An Adaptive Quantifier Extension and Rule-Filtering Graph Network for Logical Reasoning of Text
abstract
Logical reasoning of text requires neural models to possess strong contextual comprehension and logical reasoning ability to draw conclusions from limited information. To improve the logical reasoning capabilities of pretrained language models (PLMs), existing approaches can be broadly categorized into neural architecture-based methods and large language model (LLM)-driven strategies. While neural methods struggle with fine-grained logic that fails to capture detailed semantic roles and constraints, LLM-driven approaches, despite generating multistep reasoning sequences, lack explicit inference control and suffer from error accumulation due to their implicit and stochastic nature. Some works have tried using logical expressions, like first-order logic, but these approaches often fail to handle quantifiers systematically or support clear reasoning processes. Inspired by first-order logic and generalized quantifier (GQ) theory, we propose AQE-RF, a model based on an adaptive quantifier extension and rule-filtering graph network to address this challenge. The first component constructs a fine-grained text logical graph (FTLG) and then performs GQ instantiation based on option attention. The second component performs rule-filtered deductive reasoning, using conflict scores and dynamic programming (DP) to select coherent, interpretable inference paths. Extensive experiments on the LogiQA, ReClor, and AR-LSAT datasets demonstrate the effectiveness and robustness of AQE-RF.
Meng Wang 0050, Jinshuo Liu, Víctor Gutiérrez-Basulto, Lina Wang 0001, Jeff Z. Pan
IEEE Trans. Neural Networks Learn. Syst.4
2025 SplitAUM: Auxiliary Model-Based Label Inference Attack Against Split Learning
abstract
Split learning has emerged as a practical and efficient privacy-preserving distributed machine learning paradigm. Understanding the privacy risks of split learning is critical for its application in privacy-sensitive scenarios. However, previous attacks against split learning generally depended on unduly strong assumptions or non-standard settings advantageous to the attacker. This paper proposes a novel auxiliary model-based label inference attack framework against learning, namedSplitAUM.SplitAUMfirst builds an auxiliary model on the client side using intermediate representations of the cut layer and a small number of dummy labels. Then, the learning regularization objective is carefully designed to train the auxiliary model and transfer the knowledge of the server model to the client. Finally,SplitAUMuses the auxiliary model output on local data to infer the server’s privacy label. In addition, to further improve the attack effect, we use semi-supervised clustering to initialize the dummy labels of the auxiliary model. SinceSplitAUMrelies only on auxiliary models, it is highly scalable. We conduct extensive experiments on three different categories of datasets, comparing four typical attacks. Experimental results demonstrate thatSplitAUMcan effectively infer privacy labels and outperform existing attack frameworks in challenging yet practical scenarios. We hope our work paves the way for future analyses of the security of split learning.
Xiaowei Chuo, Fangchao Yu, Bo Zeng 0006, Zhi Pang, Lina Wang 0001
IEEE Trans. Netw. Serv. Manag.6
2024 TraceEvader: Making DeepFakes More Untraceable via Evading the Forgery Model Attribution
abstract
In recent few years, DeepFakes are posing serve threats and concerns to both individuals and celebrities, as realistic DeepFakes facilitate the spread of disinformation. Model attribution techniques aim at attributing the adopted forgery models of DeepFakes for provenance purposes and providing explainable results to DeepFake forensics. However, the existing model attribution techniques rely on the trace left in the DeepFake creation, which can become futile if such traces were disrupted. Motivated by our observation that certain traces served for model attribution appeared in both the high-frequency and low-frequency domains and play a divergent role in model attribution. In this work, for the first time, we propose a novel training-free evasion attack, TraceEvader, in the most practical non-box setting. Specifically, TraceEvader injects a universal imitated traces learned from wild DeepFakes into the high-frequency component and introduces adversarial blur into the domain of the low-frequency component, where the added distortion confuses the extraction of certain traces for model attribution. The comprehensive evaluation on 4 state-of-the-art (SOTA) model attribution techniques and fake images generated by 8 generative models including generative adversarial networks (GANs) and diffusion models (DMs) demonstrates the effectiveness of our method. Overall, our TraceEvader achieves the highest average attack success rate of 79% and is robust against image transformations and dedicated denoising techniques as well where the average attack success rate is still around 75%. Our TraceEvader confirms the limitations of current model attribution techniques and calls the attention of DeepFake researchers and practitioners for more robust-purpose model attribution techniques.
Jingui Ma, Run Wang 0001, Sidan Zhang, Ziyou Liang, Boheng Li, Chenhao Lin, Liming Fang 0001, Lina Wang 0001
AAAI9
2024 Chronic Poisoning: Backdoor Attack against Split Learning
abstract
Split learning is a computing resource-friendly distributed learning framework that protects client training data by splitting the model between the client and server. Previous work has proved that split learning faces a severe risk of privacy leakage, as a malicious server can recover the client's private data by hijacking the training process. In this paper, we first explore the vulnerability of split learning to server-side backdoor attacks, where our goal is to compromise the model's integrity. Since the server-side attacker cannot access the training data and client model in split learning, the traditional poisoning-based backdoor attack methods are no longer applicable. Therefore, constructing backdoor attacks in split learning poses significant challenges. Our strategy involves the attacker establishing a shadow model on the server side that can encode backdoor samples and guiding the client model to learn from this model during the training process, thereby enabling the client to acquire the same capability. Based on these insights, we propose a three-stage backdoor attack framework named SFI. Our attack framework minimizes assumptions about the attacker's background knowledge and ensures that the attack process remains imperceptible to the client. We implement SFI on various benchmark datasets, and extensive experimental results demonstrate its effectiveness and generality. For example, success rates of our attack on MNIST, Fashion, and CIFAR10 datasets all exceed 90%, with limited impact on the main task.
Fangchao Yu, Bo Zeng 0006, Zhi Pang, Lina Wang 0001
AAAI5
2024 FedGR: Genetic Algorithm and Relay Strategy Based Federated Learning
abstract
Federated learning (FL) is a privacy-preserving distributed machine learning approach that enables multiple parties to collaboratively train machine learning models without sharing local data. However, compared with the models trained on independent and identically distributed (IID) data, existing methods still face significant degradation in model performance when running on non-IID data. To solve this problem, we propose a federated learning framework based on genetic algorithm and relay strategy in this paper. The framework groups clients according to their local data distribution using genetic algorithm. After obtaining the optimal grouping result, a relay strategy is used to train and aggregate models within each group. Extensive experiments on three benchmark datasets show that FedGR significantly outperforms other state-of-the-art federated learning algorithms on various image classification tasks. The source code is available at https://github.com/zyfhylyh/FedGR.
Yifei Zeng, Fangchao Yu, Bo Zeng 0006, Zhi Pang, Lina Wang 0001
CSCWD6
2024 Diff-HOD: Diffusion Model for Object Detection in Hazy Weather Conditions
abstract
The presence of haze negatively affects the visibility of captured images, posing challenges for general object detection models. We observe that current techniques exhibit three limitations: 1) they typically view image restoration and object detection as separate tasks; 2) they disregard potential details in degraded images that benefit detection; and 3) they lack sufficient recognition ability under haze interference. To this end, we propose a novel Diffusion Model (Diff-HOD) for Object Detection in Hazy weather conditions. Diff-HOD is a multi-task joint learning paradigm that integrates low-level image restoration and high-level object detection. Specifically, to bridge restoration and detection, we present a lightweight restoration module that mitigates the impact of weather-specific information, guiding the shared image encoder to provide high-quality features. We further leverage the excellent modeling ability of diffusion models to enhance the detection capability in hazy conditions. Moreover, we introduce an IoU-aware attention module that utilizes IoU as spatial priors to strengthen relevant features. Extensive experiments demonstrate that our Diff-HOD performs favorably against representative state-of-the-art approaches on both synthetic and natural datasets.
Yizhan Li, Rongwei Yu, Lina Wang 0001
ICASSP4
2024 AdvShadow: Evading DeepFake Detection via Adversarial Shadow Attack
abstract
With the emergence of techniques called DeepFakes, there has been a notable proliferation of DeepFake detectors rooted in deep learning. These detectors aim to expose subtle distinctions between genuine and counterfeit facial images across spatial, frequency, and physiological domains. Unfortunately, these detectors are susceptible to adversarial attacks. In this study, we introduce a novel transferable adversarial attack named AdvShadow, designed to attack DeepFake detectors by leveraging natural shadows in real-life. The proposed AdvShadow comprises three components: random shadow generator, shadow overlay network, and adversarial shadow generation. Initially, we construct a random shadowed facial dataset, utilizing additional shadow overlay network to produce adversarial samples for training. Then we generate adversarial shadows for DeepFake datasets, mitigating the disparities of luminance between real and synthesized images. Through extensive experiments, we demonstrate the effectiveness and transferability of AdvShadow for attacking under black-box settings.
Mingcheng Zhang, Jianpeng Ke, Lina Wang 0001
ICASSP4
2024 A novel immune detector training method for network anomaly detection
Geying Yang, Lina Wang 0001, Qinghao Wang
Appl. Intell.3
2024 A novel fusion feature imageization with improved extreme learning machine for network anomaly detection
Geying Yang, Lina Wang 0001, Qinghao Wang
Appl. Intell.3
2024 SFIA: Toward a Generalized Semantic-Agnostic Method for Fake Image Attribution
abstract
The proliferation of photorealistic images synthesized by generative adversarial networks (GANs) has posed serious threats to society. Therefore a new challenge task, named image attribution, is arising to attribute fake images to a specific GAN. However, existing approaches focus on model‐specific features but neglect the misguidance of semantic‐relevant features in image attribution, which leads to a significant performance decrease in cross‐dataset evaluation. To tackle the above problem, we propose a semantic‐agnostic fake image attribution (SFIA) method, which effectively distinguishes fake images by disentangling the GANs fingerprint and semantic‐relevant features in latent space. Specifically, we design a semantic eliminator based on residual block with skip connections that take images as input and outputs GAN fingerprint features. A classifier with an attention module for feature refinement is introduced to make the final decision. In addition, we develop a well‐trained reconstructor and classifier which supervise the semantic eliminator to achieve semantic‐agnostic feature extraction. Moreover, we propose an improved data augmentation combined with meta‐learning to enhance the model’s generalization in detecting unseen image categories. Comprehensive experiments on various datasets, namely, CelebA, LSUN‐church, and LSUN‐bedroom, demonstrate the effectiveness of our proposed SFIA. It achieves over 95% accuracy on three datasets and exhibits superior performance in terms of generalization to unseen data.
Jianpeng Ke, Lina Wang 0001
Int. J. Intell. Syst.2
2024 Real-World Image Deraining Using Model-Free Unsupervised Learning
abstract
We propose a novel model‐free unsupervised learning paradigm to tackle the unfavorable prevailing problem of real‐world image deraining, dubbed MUL‐Derain. Beyond existing unsupervised deraining efforts, MUL‐Derain leverages a model‐free Multiscale Attentive Filtering (MSAF) to handle multiscale rain streaks. Therefore, formulation of any rain imaging is not necessary, and it requires neither iterative optimization nor progressive refinement operations. Meanwhile, MUL‐Derain can efficiently compute spatial coherence and global interactions by modeling long‐range dependencies, allowing MSAF to learn useful knowledge from a larger or even global rain region. Furthermore, we formulate a novel multiloss function to constrain MUL‐Derain to preserve both color and structure information from the rainy images. Extensive experiments on both synthetic and real‐world datasets demonstrate that our MUL‐Derain obtains state‐of‐the‐art performance over un/semisupervised methods and exhibits competitive advantages over the fully‐supervised ones.
Rongwei Yu, Jingyi Xiang, Ni Shu, Peihao Zhang, Yizhan Li, Yiyang Shen, Weiming Wang 0002, Lina Wang 0001
Int. J. Intell. Syst.8
2024 Personalized and privacy-enhanced federated learning framework via knowledge distillation
Fangchao Yu, Lina Wang 0001, Bo Zeng 0006, Rongwei Yu
Neurocomputing2
2024 StreamliNet: Cost-aware layer-wise neural network linearization for fast and accurate private inference
Zhi Pang, Lina Wang 0001, Fangchao Yu, Bo Zeng 0006
Inf. Sci.2
2024 SIA: A sustainable inference attack framework in split learning
Fangchao Yu, Lina Wang 0001, Bo Zeng 0006, Tian Wu 0004, Zhi Pang
Neural Networks2
2024 A Secure and Robust Knowledge Transfer Framework via Stratified-Causality Distribution Adjustment in Intelligent Collaborative Services
abstract
The rapid development of device-edge-cloud collaborative computing techniques has actively contributed to the popularization and application of intelligent service models. The intensity of knowledge transfer plays a vital role in enhancing the performance of intelligent services. However, the existing knowledge transfer methods are mainly implemented through data fine-tuning and model distillation, which may cause the leakage of data privacy or model copyright in intelligent collaborative systems. To address this issue, we propose a secure and robust knowledge transfer framework through stratified-causality distribution adjustment (SCDA) for device-edge-cloud collaborative services. Specifically, a simple yet effective density-based estimation is first employed to obtain uncertainty scores that guide the space stratification, which is conducive to reconstructing low-density distribution regions from high-density distribution regions more adaptively and accurately. Subsequently, we devise a novel causality-aware generative model to generate synthetic features for the out-of-distribution domain by exploring the relationship between factors and variables. Ultimately, we introduce a cycle-consistent minimax optimization mechanism to ensure the effectiveness and dependability of knowledge transfer through the influence minimization and the diversity maximization. Furthermore, extensive experiments demonstrate that our scheme can protect the security of data privacy and model copyright in intelligent collaborative services through adaptive distribution adjustment.
Ju Jia, Siqi Ma 0001, Lina Wang 0001, Yang Liu 0003, Robert H. Deng
IEEE Trans. Computers3
2024 A Causality-Aligned Structure Rationalization Scheme Against Adversarial Biased Perturbations for Graph Neural Networks
abstract
The graph neural networks (GNNs) are susceptible to adversarial perturbations and distribution biases, which pose potential security concerns for real-world applications. Current endeavors mainly focus on graph matching, while the subtle relationships between the nodes and structures of graph-structured data remain under-explored. Accordingly, two fundamental challenges arise as follows: 1) the intricate connections among nodes may induce the distribution shift of graph samples even under the same scenario, and 2) the perturbations of inherent graph-structured representations can introduce spurious shortcuts, which lead to GNN models relying on biased data to make unstable predictions. To address these problems, we propose a novel causality-aligned structure rationalization (CASR) scheme to construct invariant rationales by probing the coherent and causal patterns, which facilitates GNN models to make stable and reliable predictions in case of adversarial biased perturbations. Specifically, the initial graph samples across domains are leveraged to boost the diversity of datasets and perceive the interaction between shortcuts. Subsequently, the causal invariant rationales can be obtained during the interventions. This allows the GNN model to extrapolate risk variations from a single observed environment to multiple unknown environments. Moreover, the query feedback mechanism can progressively promote the consistency-driven optimal rationalization by reinforcing real essences and eliminating spurious shortcuts. Extensive experiments demonstrate the effectiveness of our scheme against adversarial biased perturbations from data manipulation attacks and out-of-distribution (OOD) shifts on various graph-structured datasets. Notably, we reveal that the capture of distinctive rationales can greatly reduce the dependence on shortcut cues and improve the robustness of OOD generalization.
Ju Jia, Siqi Ma 0001, Yang Liu 0003, Lina Wang 0001, Robert H. Deng
IEEE Trans. Inf. Forensics Secur.4
2023 BBAC: Blockchain-Based Access Control Scheme for EHRs with Data Sharing Support
Canming Fang, Lina Wang 0001
ADMA (5)4
2023 Feature Sniffer: A Stealthy Inference Attacks Framework on Split Learning
Sida Luo, Fangchao Yu, Lina Wang 0001, Bo Zeng 0006, Zhi Pang
ICANN (7)3
2023 SR-IDS: A Novel Network Intrusion Detection System Based on Self-taught Learning and Representation Learning
Qinghao Wang, Geying Yang, Lina Wang 0001
ICANN (3)3
2023 What can Discriminator do? Towards Box-free Ownership Verification of Generative Adversarial Networks
abstract
In recent decades, Generative Adversarial Network (GAN) and its variants have achieved unprecedented success in image synthesis. However, well-trained GANs are under the threat of illegal steal or leakage. The prior studies on remote ownership verification assume a black-box setting where the defender can query the suspicious model with specific inputs, which we identify is not enough for generation tasks. To this end, in this paper, we propose a novel IP protection scheme for GANs where ownership verification can be done by checking outputs only, without choosing the inputs (i.e., box-free setting). Specifically, we make use of the unexploited potential of the discriminator to learn a hypersphere that captures the unique distribution learned by the paired generator. Extensive evaluations on two popular GAN tasks and more than 10 GAN architectures demonstrate our proposed scheme to effectively verify the ownership. Our proposed scheme shown to be immune to popular input-based removal attacks and robust against other existing attacks. The source code and models are available at https://github.com/AbstractTeen/gan_ownership_verification.
Ziheng Huang 0008, Boheng Li, Yan Cai 0015, Run Wang 0001, Shangwei Guo, Liming Fang 0001, Jing Chen 0003, Lina Wang 0001
ICCV8
2023 PatchFinger: A Model Fingerprinting Scheme Based on Adversarial Patch
Bo Zeng 0006, Kunhao Lai, Jianpeng Ke, Fangchao Yu, Lina Wang 0001
ICONIP (2)5
2023 Who is Speaking Actually? Robust and Versatile Speaker Traceability for Voice Conversion
abstract
Voice conversion (VC), as a voice style transfer technology, is becoming increasingly prevalent while raising serious concerns about its illegal use. Proactively tracing the origins of VC-generated speeches, i.e., speaker traceability, can prevent the misuse of VC, but unfortunately has not been extensively studied. In this paper, we are the first to investigate the speaker traceability for VC and propose a traceable VC framework named VoxTracer. Our VoxTracer is similar to but beyond the paradigm of audio watermarking. We first use unique speaker embedding to represent speaker identity. Then we design a VAE-Glow structure, in which the hiding process imperceptibly integrates the source speaker identity into the VC, and the tracing process accurately recovers the source speaker identity and even the source speech in spite of severe speech quality degradation. To address the speech mismatch between the hiding and tracing processes affected by different distortions, we also adopt an asynchronous training strategy to optimize the VAE-Glow models. The VoxTracer is versatile enough to be applied to arbitrary VC methods and popular audio coding standards. Extensive experiments demonstrate that the VoxTracer achieves not only high imperceptibility in hiding, but also nearly 100% tracing accuracy against various types of audio lossy compressions (AAC, MP3, Opus and SILK) with a broad range of bitrates (16 kbps - 128 kbps) even in a very short time duration (0.74s). Our source code is available at https://github.com/hongchengzhu/VoxTracer.
Yanzhen Ren, Hongcheng Zhu, Liming Zhai, Zongkun Sun, Rubing Shen, Lina Wang 0001
ACM Multimedia6
2023 Free Fine-tuning: A Plug-and-Play Watermarking Scheme for Deep Neural Networks
abstract
Watermarking has been widely adopted for protecting the intellectual property (IP) of Deep Neural Networks (DNN) to defend the unauthorized distribution. Unfortunately, studies have shown that the popular data-poisoning DNN watermarking scheme via tedious model fine-tuning on a poisoned dataset (carefully-crafted sample-label pairs) is not efficient in tackling the tasks on challenging datasets and production-level DNN model protection. To address the aforementioned limitation, in this paper, we propose a plug-and-play watermarking scheme for DNN models by injecting an independent proprietary model into the target model to serve the watermark embedding and ownership verification. In contrast to the prior studies, our proposed method by incorporating a proprietary model is free of target model fine-tuning without involving any parameters update of the target model, thus the fidelity is well preserved and scalable to challenging real tasks. Experimental results on real-world challenging datasets (e.g., ImageNet) and production-level DNN models demonstrated its effectiveness, fidelity w.r.t. the functionality preservation of the target model, robustness against popular watermark removal attacks, and the plug-and-play deployment. The source code and models are available at https://github.com/AntigoneRandy/PTYNet.
Run Wang 0001, Jixing Ren, Boheng Li, Tianyi She, Liming Fang 0001, Jing Chen 0003, Lina Wang 0001
ACM Multimedia8
2023 A Modified Gray Wolf Optimizer-Based Negative Selection Algorithm for Network Anomaly Detection
abstract
Intrusion detection systems are crucial in fighting against various network attacks. By monitoring the network behavior in real time, possible attack attempts can be detected and acted upon. However, with the development of openness and flexibility of networks, artificial immunity‐based network anomaly detection methods lack continuous adaptability and hence have poor detection performance. Thus, a novel framework for network anomaly detection with adaptive regulation is built in this paper. First, a heuristic dimensionality reduction algorithm based on unsupervised clustering is proposed. This algorithm uses the correlation between features to select the best subset. Then, a hybrid partitioning strategy is introduced in the negative selection algorithm (NSA), which divides the feature space into a grid based on the sample distribution density and generates specific candidate detectors in the boundary grid to effectively mitigate the holes caused by boundary diversity. Finally, the NSA is improved by self‐set clustering and a novel gray wolf optimizer to achieve adaptive adjustment of the detector radius and position. The results show that the proposed NSA algorithm based on mixed hierarchical division and gray wolf optimization (MDGWO‐NSA) achieves a higher detection rate, lower false alarm rate, and better generation quality than other network anomaly detection algorithms.
Geying Yang, Lina Wang 0001, Rongwei Yu, Junjiang He, Bo Zeng 0006, Tian Wu 0004
Int. J. Intell. Syst.2
2023 DF-UDetector: An effective method towards robust deepfake detection via feature restoration
Jianpeng Ke, Lina Wang 0001
Neural Networks2
2023 How to backdoor split learning
Fangchao Yu, Lina Wang 0001, Bo Zeng 0006, Zhi Pang, Tian Wu 0004
Neural Networks2
2023 A Universal Audio Steganalysis Scheme Based on Multiscale Spectrograms and DeepResNet
abstract
Given the popularity of audio and video applications, compressed audio has become an important carrier of covert communication on the Internet. Many novel compressed audio steganography schemes have emerged that offer good hiding capability and aural concealment. In this paper, a universal steganalysis scheme called MultiSpecNet is proposed to detect steganography based on multiple embedding domains (advanced audio coding (AAC) and MPEG-1 Audio Layer III (MP3)), which are currently the two most popular compressed audio standards. The basic idea is that modification of either domain by a steganography scheme will change the time-frequency relationship of the audio signal after decoding. The proposed approach adopts the spectrogram as the input feature to extract richer information. DeepResNet is used to learn the distinguishing feature representations, and multiscale spectrograms are used to enrich the feature diversity. The experimental results show that the proposed scheme is effective at detecting different steganography schemes based on the AAC and MP3 embedding domains. The detection accuracy of the proposed scheme is higher than that achieved by other state-of-the-art schemes. Using spectrograms as the input, DeepResNet achieves better performance than schemes using quantized modified discrete cosine transform (MDCT) coefficients and mel-spectrogram, although the quantized MDCT coefficient is the parameter modified by the steganography schemes directly and mel-spectrogram is very popular and effective for general audio signal analysis. To the best of our knowledge, this work is the first audio steganalysis scheme that can detect multiple steganography schemes in both the MP3 and AAC embedding domains. The method proposed in this paper can be extended to audio steganalysis for other codecs or for audio forensics purposes.
Yanzhen Ren, Dengkai Liu, Qiaochu Xiong, Jianming Fu, Lina Wang 0001
IEEE Trans. Dependable Secur. Comput.6
2023 Capturing Invalid Input Manipulations for Memory Corruption Diagnosis
abstract
Memory corruption diagnosis, especially at the binary level where all high-level program abstractions are missing, is a tedious and time-consuming task. Given a crash, memory corruption diagnosis is expected to not only locate the root cause of the vulnerability, but also deliver rich semantics to understand the vulnerability. However, existing techniques can barely satisfy the above requirements. In this article, we present${{\sf MemRay}}$, a dynamic memory corruption diagnosis technique. The insight behind our approach is that most memory corruption is caused by malformed inputs, which further leads the vulnerable program to manipulate inputs by referencing invalid data structures. We design the “data structure reference sequence” to characterize how a program references various data structures to manipulate program inputs. Then, we identify memory corruptions by detecting violations in the input manipulations via data structures. We demonstrate the effectiveness of${{\sf MemRay}}$on a wide range of memory-corruption vulnerabilities. The result shows that${{\sf MemRay}}$precisely locates the root cause of vulnerabilities. Moreover, the “data structure reference” enables${{\sf MemRay}}$to deliver rich semantics and context information to assist vulnerability diagnosis on binary code.
Lei Zhao 0012, Keyang Jiang, Yuncong Zhu, Lina Wang 0001, Jiang Ming 0002
IEEE Trans. Dependable Secur. Comput.4
2023 Consensus-Clustering-Based Automatic Distribution Matching for Cross-Domain Image Steganalysis
abstract
Image steganalysis is a technique to detect whether an image contains hidden information. Although the existing cross-domain steganalysis methods have been presented to narrow the distribution gap between different domains, it is still challenging to effectively capture the transferable steganalysis representations under the condition of severe distribution shifts. To address this issue, we propose a novel consensus-clustering-based automatic distribution matching scheme, called CADM, which can automatically and accurately match inconsistent distributions in cross-domain steganalysis scenarios. First, the original steganalysis features are clustered by the spatially constrained fuzzyc-means (SCFCM) algorithm with controllable parameters to fully perceive and mine inherent structural relationships. Subsequently, the cluster consensus knowledge is derived from the perspective of intra-domain and inter-domain to facilitate the clustering and the matching. In this way, the representations of weak stego signals can be augmented by identifying cluster centers that can be combined across domains. Ultimately, the cycle-consistent optimization and adaptation is achieved by gradually adjusting the learning strength of well-aligned and poorly-aligned samples to promote the positive transfer of overlapped clusters and prevent the negative transfer of outlier clusters. Furthermore, extensive experiments on various benchmark databases for cross-domain steganalysis demonstrate the superiority of CADM over the current state-of-the-art methods.
Ju Jia, Meng Luo 0002, Siqi Ma 0001, Lina Wang 0001, Yang Liu 0003
IEEE Trans. Knowl. Data Eng.4
2023 Towards a Robust Deep Neural Network Against Adversarial Texts: A Survey
abstract
Deep neural networks (DNNs) have achieved remarkable success in various tasks (e.g., image classification, speech recognition, and natural language processing (NLP)). However, researchers have demonstrated that DNN-based models are vulnerable to adversarial examples, which cause erroneous predictions by adding imperceptible perturbations into legitimate inputs. Recently, studies have revealed adversarial examples in the text domain, which could effectively evade various DNN-based text analyzers and further bring the threats of the proliferation of disinformation. In this paper, we give a comprehensive survey on the existing studies of adversarial techniques for generating adversarial texts written by both English and Chinese characters and the corresponding defense methods. More importantly, we hope that our work could inspire future studies to develop more robust DNN-based text analyzers against known and unknown adversarial techniques. We classify the existing adversarial techniques for crafting adversarial texts based on the perturbation units, helping to better understand the generation of adversarial texts and build robust models for defense. In presenting the taxonomy of adversarial attacks and defenses in the text domain, we introduce the adversarial techniques from the perspective of different NLP tasks. Finally, we discuss the existing challenges of ad-versarial attacks and defenses in texts and present the future research directions in this emerging and challenging field.
Wenqi Wang 0002, Run Wang 0001, Lina Wang 0001, Zhibo Wang 0001, Aoshuang Ye
IEEE Trans. Knowl. Data Eng.3
2023 GANAD: A GAN-based method for network anomaly detection
Lina Wang 0001, Jianpeng Ke, Rongwei Yu
World Wide Web (WWW)2
2022 Efficient DNN Backdoor Detection Guided by Static Weight Analysis
Yiru Zhao, Lei Zhao 0012, Lina Wang 0001
Inscrypt6
2022 Anti-Forgery: Towards a Stealthy and Robust DeepFake Disruption Attack via Adversarial Perceptual-aware Perturbations
abstract
DeepFake is becoming a real risk to society and brings potential threats to both individual privacy and political security due to the DeepFaked multimedia are realistic and convincing. However, the popular DeepFake passive detection is an ex-post forensics countermeasure and failed in blocking the disinformation spreading in advance. To address this limitation, researchers study the proactive defense techniques by adding adversarial noises into the source data to disrupt the DeepFake manipulation. However, the existing studies on proactive DeepFake defense via injecting adversarial noises are not robust, which could be easily bypassed by employing simple image reconstruction revealed in a recent study MagDR. In this paper, we investigate the vulnerability of the existing forgery techniques and propose a novel anti-forgery technique that helps users protect the shared facial images from attackers who are capable of applying the popular forgery techniques. Our proposed method generates perceptual-aware perturbations in an incessant manner which is vastly different from the prior studies by adding adversarial noises that is sparse. Experimental results reveal that our perceptual-aware perturbations are robust to diverse image transformations, especially the competitive evasion technique, MagDR via image reconstruction. Our findings potentially open up a new research direction towards thorough understanding and investigation of perceptual-aware adversarial attack for protecting facial images against DeepFakes in a proactive and robust manner. Code is available at https://github.com/AbstractTeen/AntiForgery.
Run Wang 0001, Ziheng Huang 0008, Jing Chen 0003, Lina Wang 0001
IJCAI6
2022 MetaFinger: Fingerprinting the Deep Neural Networks with Meta-training
abstract
As deep neural networks (DNNs) play a critical role in various fields, the models themselves hence are becoming an important asset that needs to be protected. To achieve this, various neural network fingerprint methods have been proposed. However, existing fingerprint methods fingerprint the decision boundary by adversarial examples, which is not robust to model modification and adversarial defenses. To fill this gap, we propose a robust fingerprint method MetaFinger, which fingerprints the inner decision area of the model by meta-training, rather than the decision boundary. Specifically, we first generate many shadow models with DNN augmentation as meta-data. Then we optimize some images by meta-training to ensure that only models derived from the protected model can recognize them. To demonstrate the robustness of our fingerprint approach, we evaluate our method against two types of attacks including input modification and model modification. Experiments show that our method achieves 99.34% and 97.69% query accuracy on average, surpassing existing methods over 30%, 25% on CIFAR-10 and Tiny-ImageNet, respectively. Our code is available at https://github.com/kangyangWHU/MetaFinger.
Run Wang 0001, Lina Wang 0001
IJCAI3
2022 Combating Multi-level Adversarial Text with Pruning based Adversarial Training
abstract
Despite significant advancements of deep learning-based models for natural language processing (NLP) tasks, previous efforts have shown that numerous models, including deep neural networks (DNNs), suffer from moderate to significant performance degradation with adversarial examples. Adversary crafts malicious text by adding, deleting, modifying chars, words, and sentences, to fool the DNN models. Therefore, adversarial training and model enhanced methods are proposed to combat the adversarial attack. However, both methods are lack generalization due to the overfitting intrinsic of neural networks. In this paper, we propose a novel framework to combat text adversarial examples, namely DisPAT, which consists an adversarial text discriminator and a robust pruned text classifier. First, we explore the adversarial examples and benign examples distribution in embedding space, indicating the feasibility of a DNN-based discriminator. To get multi-level adversarial texts, we deploy a generator, and a discriminator to identify adversarial perturbations. Notably, in the inference stage, our pipeline places the well-trained discriminator in front of the text classifier to distinguish the char-level adversarial text. Finally, we apply neuron-salience-based pruning to specifically improve the classifier performance of adversarial text. Experimental results show that our approach outperforms state-of-the-art baselines in combating both char-level and word-level adversarial text. Moreover, DisPAT achieves a very close to or even higher accuracy than that of the standard model.
Jianpeng Ke, Lina Wang 0001, Aoshuang Ye
IJCNN2
2022 Improving Robustness Verification of Neural Networks with General Activation Functions via Branching and Optimization
abstract
Robustness verification of neural networks (NNs) is a challenging and significant problem, which draws great attention in recent years. Existing researches have shown that bound propagation is a scalable and effective method for robustness verification, and it can be implemented on GPUs and TPUs to get parallelized. However, the bound propagation methods naturally produce weak bound due to linear relaxations on the neurons, which may cause failure in verification. Although tightening techniques for simple ReLU networks have been explored, they are not applicable for NNs with general activation functions such as Sigmoid and Tanh. Improving robustness verification on these NNs is still challenging. In this paper, we propose a Branch-and-Bound (BaB) style method to address this problem. The proposed BaB procedure improves the weak bound by splitting the input domain of neurons into sub-domains and solving the corresponding sub-problems. We propose a generic heuristic function to determine the priority of neuron splitting by scoring the relaxation and impact of neurons. Moreover, we combine bound optimization with the BaB procedure to improve the weak bound. Experimental results demonstrate that the proposed method gains up to 35% improvement compared to the state-of-art CROWN method on Sigmoid and Tanh networks.
Zhengwu Luo, Lina Wang 0001, Run Wang 0001, Aoshuang Ye
IJCNN2
2022 DANCe: Dynamic Adaptive Neuron Coverage for Fuzzing Deep Neural Networks
abstract
Deep learning (DL) defines a data-driven paradigm that differs from conventional software. It utilizes training data to construct the internal logic of the deep neural networks. With aggressive development in various security-sensitive domains, deep learning raises safety concerns in academia and industrial community. Numerous researches have shown that even the most advanced deep learning systems have vulnerabilities leading to misbehaviors. Despite the urgent security threat, fuzzing test remains a reasonable way to solve the problem. However, The static parameters design in current mainstream neuron coverage disables the fuzzing work diversely on heterogeneous architectures. To address the above problems, we propose the Dynamic Adaptive Neuron Coverage (DANCe) to model the neuron behavior, which can adapt diverse models with implementing training data. The dynamic adaption mechanism enhances the ability of coverage-based fuzzing to generate adversarial examples as test cases. The proposed model is evaluated on two widely-adopted image datasets and four well-designed deep neural networks. The experimental results show that the DANCe exceeds the SOTA coverage criteria by 7% and 33% on generating adversarial examples within 1 hour and 6 hours of time limitation.
Aoshuang Ye, Lina Wang 0001, Lei Zhao 0012, Jianpeng Ke
IJCNN2
2022 Rethinking the Vulnerability of DNN Watermarking: Are Watermarks Robust against Naturalness-aware Perturbations?
abstract
Training Deep Neural Networks (DNN) is a time-consuming process and requires a large amount of training data, which motivates studies working on protecting the intellectual property (IP) of DNN models by employing various watermarking techniques. Unfortunately, in recent years, adversaries have been exploiting the vulnerabilities of the employed watermarking techniques to remove the embedded watermarks. In this paper, we investigate and introduce a novel watermark removal attack, called AdvNP, against all the existing four different types of DNN watermarking schemes via input preprocessing by injecting Adversarial Naturalness-aware Perturbations. In contrast to the prior studies, our proposed method is the first work that generalizes all the existing four watermarking schemes well without involving any model modification, which preserves the fidelity of the target model. We conduct the experiments against four state-of-the-art (SOTA) watermarking schemes on two real tasks (e.g., image classification on ImageNet, face recognition on CelebA) across multiple DNN models. Overall, our proposed AdvNP significantly invalidates the watermarks against the four watermarking schemes on two real-world datasets, i.e., 60.9% on the average attack success rate and up to 97% in the worse case. Moreover, our AdvNP could well survive the image denoising techniques and outperforms the baseline in both the fidelity preserving and watermark removal. Furthermore, we introduce two defense methods to enhance the robustness of DNN watermarking against our AdvNP. Our experimental results pose real threats to the existing watermarking schemes and call for more practical and robust watermarking techniques to protect the copyright of pre-trained DNN models. The source code and models are available at ttps://github.com/GitKJ123/AdvNP.
Run Wang 0001, Lingzhou Mu, Jixing Ren, Shangwei Guo, Liming Fang 0001, Jing Chen 0003, Lina Wang 0001
ACM Multimedia9
2022 Better constraints of imperceptibility, better adversarial examples in the text
abstract
State-of-the-art adversarial attacks in the text domain have shown their power to induce machine learning models to produce abnormal outputs. The samples generated in these attacks have three important attributes: attack ability, transferability, and imperceptibility. However, compared with the other two attributes, the imperceptibility of adversarial examples has not been well investigated. Unlike the pixel-level perturbations in images, adversarial perturbations in the text are usually traceable, reflecting changes in characters, words, or sentences. The generation of imperceptible samples in texts is more difficult than in images. Therefore, how to constrain adversarial perturbations added in the text is a crucial step to construct more natural adversarial texts. Unfortunately, recent studies merely select measurements to constrain the added adversarial perturbations, but none of them explain where these measurements are suitable, which one is better, and how they perform in different kinds of adversarial attacks. In this paper, we fill this gap by comparing the performance of these metrics in various attacks. Furthermore, we propose a stricter constraint for word-level attacks to obtain more imperceptible samples. It is also helpful to enhance existing word-level attacks for adversarial training.
Wenqi Wang 0002, Lina Wang 0001, Run Wang 0001, Aoshuang Ye, Jianpeng Ke
Int. J. Intell. Syst.2
2022 JPEG steganalysis based on denoising network and attention module
abstract
The core objective of image steganalysis is to explore the presence of weak image steganographic signals. Extracting effective steganographic signal features will play an essential role in digital image steganalysis. However, existing networks rely more on spatial rich model kernels or random learnable kernels to obtain noise residuals during the stage of steganographic signal features extraction. In this paper, we proposed a JPEG steganalysis network which based on denoising network and attention module, mainly including a noise extract block, a noise analysis block, and a judgment block. Specifically, a professional denoising convolutional neural network is first introduced in noise extract block to obtain better steganalysis features. The noise analysis block is integrated with the attention module to finely extract the steganographic signals hidden in the complex texture regions, which is quite effective in improving the signal-to-noise ratio of the stego signal. The judgment block is primarily a classifier to distinguish between cover images and stego images. Comprehensive experiments show a significant improvement in performance over the state-of-the-art steganalysis scheme. Moreover, the proposed network has better generalization capability than the compared steganalysis network for the case of cover-source and quality factor mismatch, which is critical for future steganalysis systems.
Tian Wu 0004, Weixiang Ren, Dewei Li 0005, Lina Wang 0001, Ju Jia
Int. J. Intell. Syst.4
2022 Progressive selection-channel networks for image steganalysis
abstract
Steganalysis is a detection technology against steganography that embeds secret data into digital media carriers. The selection channel, which indicates the embedding details of steganography, is well recognized in boosting the detection performance of image steganalysis. However, nearly all the selection channels are constructed in a hand-crafted manner, even when they are incorporated into end-to-end deep steganalytic networks, for which the embedding rate and steganographic algorithms also need to be predetermined. Such prior knowledge is usually assumed completely known in existing literature, which is obviously unreasonable and impractical. To address this issue, we propose to automatically learn the selection channels for deep learning-based image steganalysis in a progressive way. Specifically, we divide the image steganalysis task into two phases: selection channel estimation and steganalytic detection. For the first phase, we design a multistage progressive network, which enables the learning of selection channels in a coarse-to-fine fashion. For the second phase, we integrate the learned selection channels into the multilayers of the steganalytic network, allowing full exploitation of selection channels for accurate detection. Extensive experiments demonstrate that the proposed method can learn the selection channels rapidly and precisely, and also significantly improve the detection accuracy of the existing state-of-the-art steganographic network without any prior knowledge.
Tian Wu 0004, Lina Wang 0001, Liming Zhai, Canming Fang, Mingcheng Zhang
Int. J. Intell. Syst.2
2022 Ex2: Monte Carlo Tree Search-based test inputs prioritization for fuzzing deep neural networks
abstract
Fuzzing is considered to be an essential approach to guarantee the reliability of deep neural networks (DNNs) based systems. The DNN fuzzing leverages various inputs prioritization methods to guide the testing process. The current research mainly focus on constructing testing metrics that symbolize the logical representation of the DNN to guide the generation of test cases, which neglects the potential performance brought by implementing heuristic algorithm. Moreover, the straightforward implementation of queue structure can not represent the metamorphic relationships between generated inputs in DNN fuzzing. Therefore, developing the appropriate heuristic algorithm-based inputs prioritization method is critical to improve the performance of DNN fuzzers. In this paper, we propose a Monte Carlo Tree Search (MCTS) based inputs prioritization method called E x 2 $E{x}^{2}$ (Exploration and Exploitation) that formulates DNN testing exploration as the sequential decision process. The technique introduces an innovative tree-structure design that schedules inputs from the statistical perspective. Different from traditional DNN testing, the batch pool is maintained in the form of nodes in MCTS. The links between nodes precisely represent the metamorphic relationship between input batches, which indicates the potential value for in-depth search. Furthermore, a novel simulation mechanism is implemented to adapt MCTS in DNN testing, which attain better coverage feedback. The effectiveness of our method is comprehensively investigated on six popular deep learning models from LeNet and VGG families. The comparison experiments are conducted between DeepHunter, TensorFuzz, and DeepSmartFuzzer to demonstrate efficacy on various testing metrics. The experimental results show that the E x 2 $E{x}^{2}$ significantly enhance the coverage gain of DNN fuzzing up to 30% against the best performance in comparison groups.
Aoshuang Ye, Lina Wang 0001, Lei Zhao 0012, Jianpeng Ke
Int. J. Intell. Syst.2
2022 Retrofitting LBR Profiling to Enhance Virtual Machine Introspection
abstract
Cloud attack provenance is a well-established industrial practice for assuring transparency and accountability for a service provider to tenants. However, the multi-tenancy and self-service nature coupled with the sheer size of a cloud implies many unique challenges to cloud forensics. Although Virtual Machine Introspection (VMI) is a powerful tool for attack provenance due to the privilege isolation, the stealthiness of state-of-the-art attacks and the lack of precise information make existing attack provenance solutions difficult to fulfill real-time forensics when tracking enormous suspicious behaviors. To this end, we propose an instruction-level tracing framework for inspecting the presence of attacks by dynamically tracking shared processor hardware event patterns and analyzing the attack traces. To overcome the challenges of real-time detection and provenance, we advocate Last Branch Record (LBR) profiling, to extract the suspicious execution flows. With the hardware assistance and software-based virtualization introspection, we show that the framework can provide an effective response to threats in different cases, thereby enabling a quick attack provenance with high fidelity. The evaluation shows that our prototype introduces negligible performance penalties.
Weijie Liu 0004, Ximeng Liu, Zhi Li 0048, Bin Liu 0029, Rongwei Yu, Lina Wang 0001
IEEE Trans. Inf. Forensics Secur.6
2022 Partial Knowledge Transfer in Visual Recognition Systems via Joint Loss-Aware Consistency Learning
abstract
One of the key challenges for the implementation of visual recognition systems in the real world is to construct prediction models that can realize the knowledge transfer from the seen data to the unseen data. Specifically, partial knowledge transfer (PKT) aims to address a more common and realistic scenario in which we are accessible to a label-rich source domain while working on a relative label-scarce target domain. The essence of PKT is to explore the latent categories across different domains and simultaneously facilitate the positive transfer from these data. In this article, we propose a joint loss-aware consistency learning (JLACL) to effectively enhance the transferability of knowledge in visual recognition systems, which conducts an iterative optimization on three-level losses, including discrepancy loss, consensus loss, and cross-entropy loss. The discrepancy loss is designed to eliminate the class distribution bias by a similarity perception metric between the source and target domains. The consensus loss can assist to preserve domain-invariant and representative features for model learning by exploring correlation. Moreover, we also find that using the cross-entropy loss to determine the shared label space, which can help to alleviate the negative transfer by suppressing the features with nonshared labels. Finally, the PKT can be successfully achieved by joint optimization of total losses. Extensive experiments on several public and challenging datasets in visual recognition applications adequately demonstrate the superiority of our proposed JLACL over existing state-of-the-art PKT methods.
Ju Jia, Meng Luo 0002, Siqi Ma 0001, Lina Wang 0001
IEEE Trans. Ind. Informatics4
2022 An Effective Imbalanced JPEG Steganalysis Scheme Based on Adaptive Cost-Sensitive Feature Learning
abstract
Steganalysis in real-world application often exhibit skewed sample distribution which poses a massive challenge for steganography detection. Conventional steganalysis algorithms are not effective when the training data distribution is imbalanced, and may fail in the scenario of imbalanced data distribution. To address imbalanced data distribution issue in steganalysis, a novel framework termed adaptive cost-sensitive feature learning via F-measure maximization is proposed, which is inspired by the fact that F-measure is a more suitable performance metric compared to accuracy for imbalanced data. We investigate the adaptive cost-sensitive strategy by generating and assigning different weight to each instance with misclassification occurrence. This scheme adaptively determines the weights according to the intra-class and inter-class costs from the imbalanced distribution. Features corresponding to the largest F-measure can be obtained by solving a series of adaptive cost-sensitive feature learning problems with optimization theory. In this way, the learned features are the most representative features between the cover and stego images so that imbalanced steganalysis can significantly alleviate. Extensive experiments on various imbalanced steganalysis tasks show the superiority of the proposed method over the state-of-the-art methods, and it can recognize more minority samples and has excellent classification performance.
Ju Jia, Liming Zhai, Weixiang Ren, Lina Wang 0001, Yanzhen Ren
IEEE Trans. Knowl. Data Eng.4
2022 Multiperspective Progressive Structure Adaptation for JPEG Steganography Detection Across Domains
abstract
The aim of steganography detection is to identify whether the multimedia data contain hidden information. Although many detection algorithms have been presented to solve tasks with inconsistent distributions between the source and target domains, effectively exploiting transferable correlation information across domains remains challenging. As a solution, we present a novel multiperspective progressive structure adaptation (MPSA) scheme based on active progressive learning (APL) for JPEG steganography detection across domains. First, the source and target data originating from unprocessed steganalysis features are clustered together to explore the structures in different domains, where the intradomain and interdomain structures can be captured to provide adequate information for cross-domain steganography detection. Second, the structure vectors containing the global and local modalities are exploited to reduce nonlinear distribution discrepancy based on APL in the latent representation space. In this way, the signal-to-noise ratio (SNR) of a weak stego signal can be improved by selecting suitable objects and adjusting the learning sequence. Third, the structure adaptation across multiple domains is achieved by the constraints for iterative optimization to promote the discrimination and transferability of structure knowledge. In addition, a unified framework for single-source domain adaptation (SSDA) and multiple-source domain adaptation (MSDA) in mismatched steganalysis can enhance the model's capability to avoid a potential negative transfer. Extensive experiments on various benchmark cross-domain steganography detection tasks show the superiority of the proposed approach over the state-of-the-art methods.
Ju Jia, Meng Luo 0002, Jinshuo Liu, Weixiang Ren, Lina Wang 0001
IEEE Trans. Neural Networks Learn. Syst.5
2021 Exposing DeepFakes via Localizing the Manipulated Artifacts
Run Wang 0001, Lei Zhao 0012, Lina Wang 0001
ICICS (2)5
2021 Recalibrated Bandpass Filtering On Temporal Waveform For Audio Spoof Detection
abstract
Deepfake techniques mislead people’s cognition with high-quality fake videos and audios, and speech synthesis is an important tool to implement cognitive attacks, which mainly include Text-To-Speech (TTS) and Voice Conversion (VC). In this paper, we propose a method for audio spoof detection based on frequency band recalibration via sinc convolution and squeeze-excitation module, extracting features from the temporal waveform and emphasizing the frequency bands that are more useful on this task. Experimental results show that the proposed method outperforms other similar methods by 18.6% with an average EER of 7.23%, and achieve better generalizability on the detection of unseen spoofing methods, while the size of the model is reduced by 30.8%.
Yanzhen Ren, Wuyang Liu, Dengkai Liu, Lina Wang 0001
ICIP4
2021 Annealing Attention Networks for User Feature-Based Rumor Early Detection on Weibo
abstract
Rumor propagation is becoming easier and leads to severe consequences for society in several minutes or hours due to the rapid development of social networks. Thus, detecting rumors in early time is necessary and urgent for the community. In recent studies, machine learning approaches are widely applied in detecting rumors based on various features extracted from content, user characteristics, and propagation structure. Some studies have shown that features extracted from users are more valuable for rumor early detection. Whereas existing studies utterly utilize various user features, and all of them are deemed as equally, which ignore the inter-feature and temporal difference. Therefore, in this paper, we analyze the effectiveness of six frequently used user features with several representative deep learning models to learn more about such difference. And we propose a novel annealing attention model based on the analysis. The proposed model learns feature-attention and temporal-attention with multi-layer perceptron and parameterized annealing function to capture the difference and enhance the original user features in rumor early detection. Experimental results on the real-world dataset demonstrate that the proposed model detects rumors with an accuracy of 93.6% on Weibo in 15 minutes, which outperforms the state-of-art methods.
Zhengwu Luo, Lina Wang 0001, Wenqi Wang 0002, Aoshuang Ye
IJCNN2
2021 Using Contrastive Learning to Improve the Performance of Steganalysis Schemes
Yanzhen Ren, Lina Wang 0001
IWDW3
2021 FakeTagger: Robust Safeguards against DeepFake Dissemination via Provenance Tracking
abstract
In recent years, DeepFake is becoming a common threat to our society, due to the remarkable progress of generative adversarial networks (GAN) in image synthesis. Unfortunately, existing studies that propose various approaches, in fighting against DeepFake and determining if the facial image is real or fake, is still at an early stage. Obviously, the current DeepFake detection method struggles to catch the rapid progress of GANs, especially in the adversarial scenarios where attackers can evade the detection intentionally, such as adding perturbations to fool the DNN-based detectors. While passive detection simply tells whether the image is fake or real, DeepFake provenance, on the other hand, provides clues for tracking the sources in DeepFake forensics. Thus, the tracked fake images could be blocked immediately by administrators and avoid further spread in social networks.
Run Wang 0001, Felix Juefei-Xu, Meng Luo 0002, Yang Liu 0003, Lina Wang 0001
ACM Multimedia5
2021 Limited Times of Data Access Based on SGX in Cloud Storage
abstract
It is straightforward to encrypt the outsourced data to protect its confidentiality using symmetric cryptography in cloud storage. How to control and restrict the use of the encryption key in data users’ devices becomes one of the critical issues. In most of existing time-based and policy-based schemes, the key cannot be stored locally in data users’ devices, making the traffic cost linear with the data access times as the key should be retrieved in each data access. In this paper, we propose a times-based scheme with Intel SGX to restrict the times the key can be used in the data user’s device to restrict the times of data access. The basic idea is to compare the current used times with the specified maximal times to determine whether the key can be used or not. To this end, we use a monotonic counter to count the times the key has been used. When the use condition is not satisfied, we destroy the key securely and generate public proof so that (i) the encrypted data cannot be accessed anymore, i.e., the data is deleted assuredly, (ii) the deletion can be verified. In addition, a hash-based integrity check approach is utilized to detect and prevent replay attacks. The experimental results on the implemented prototype show our scheme is feasible in practice.
Zhengwei Ren, Jinshan Tang, Lina Wang 0001
SMC4
2021 RapidFuzz: Accelerating fuzzing via Generative Adversarial Networks
Aoshuang Ye, Lina Wang 0001, Lei Zhao 0012, Jianpeng Ke, Wenqi Wang 0002, Qinliang Liu
Neurocomputing2
2021 Secure AAC steganography scheme based on multi-view statistical distortion (SofMvD)
Yanzhen Ren, Sen Cai, Lina Wang 0001
J. Inf. Secur. Appl.3
2021 Similarity-Maintaining Privacy Preservation and Location-Aware Low-Rank Matrix Factorization for QoS Prediction Based Web Service Recommendation
abstract
Web service recommendation plays an important role in building service-oriented systems. QoS-based Web service recommendation has recently gained much attention for providing a promising way to help users find high-quality services. To accurately predict the QoS values of candidate Web services, Web service recommendation systems usually need to collect historical QoS data from users, which will potentially pose a threat to the user's privacy. However, how to simultaneously protect user's privacy and make an accurate prediction has not been well studied. By taking these two aspects into consideration, we propose a novel QoS prediction approach for Web service recommendation in this paper. Specifically, we first design a similarity-maintaining privacy preservation (SPP) strategy, which aims to protect the user's privacy and maintain the utility of user data in the meanwhile. Then, we propose a location-aware low-rank matrix factorization (LLMF) algorithm, which employs the L1L1-norm low-rank matrix factorization to improve the model's robustness, and combines the matrix factorization model with two kinds of location information (continent, longitude and latitude) in the prediction process. Experimental results on two publicly available real-world Web service QoS datasets demonstrate the effectiveness of our privacy-preserving QoS prediction approach.
Xiaoke Zhu, Xiaoyuan Jing, Di Wu 0014, Zhenyu He 0001, Jicheng Cao, Dong Yue 0001, Lina Wang 0001
IEEE Trans. Serv. Comput.7
2020 MGAAttack: Toward More Query-efficient Black-box Attack by Microbial Genetic Algorithm
abstract
Recent studies have shown that deep neural networks (DNNs) are susceptible to adversarial attacks even in the black-box settings. However, previous studies on creating black-box based adversarial examples by merely solving the traditional continuous problem, which suffer query efficiency issues. To address the efficiency of querying in black-box attack, we propose a novel attack, called MGAAttack, which is a query-efficient and gradient-free black-box attack without obtaining any knowledge of the target model. In our approach, we leverage the advantages of both transfer-based and scored-based methods, two typical techniques in black-box attack, and solve a discretized problem by using a simple yet effective microbial genetic algorithm (MGA). Experimental results show that our approach dramatically reduces the number of queries on CIFAR-10 and ImageNet and significantly outperforms previous work. In the untargeted attack, we can attack a VGG19 classifier with only 16 queries and give an attack success rate more than 99.90% on ImageNet. Our code is available at https://github.com/kangyangWHU/MGAAttack.
Lina Wang 0001, Wenqi Wang 0002, Run Wang 0001, Aoshuang Ye
ACM Multimedia1
2020 Learning selection channels for image steganalysis in spatial domain
Weixiang Ren, Liming Zhai, Ju Jia, Lina Wang 0001, Lefei Zhang
Neurocomputing4
2020 Transferable heterogeneous feature subspace learning for JPEG mismatched steganalysis
Ju Jia, Liming Zhai, Weixiang Ren, Lina Wang 0001, Yanzhen Ren, Lefei Zhang
Pattern Recognit.4
2020 Intraspectrum Discrimination and Interspectrum Correlation Analysis Deep Network for Multispectral Face Recognition
abstract
Multispectral images contain rich recognition information since the multispectral camera can reveal information that is not visible to the human eye or to the conventional RGB camera. Due to this characteristic of multispectral images, multispectral face recognition has attracted lots of research interest. Although some multispectral face recognition methods have been presented in the last decade, how to fully and effectively explore the intraspectrum discriminant information and the useful interspectrum correlation information in multispectral face images for recognition has not been well studied. To boost the performance of multispectral face recognition, we propose an intraspectrum discrimination and interspectrum correlation analysis deep network (IDICN) approach. Multiple spectra are divided into several spectrum-sets, with each containing a group of spectra within a small spectral range. The IDICN network contains a set of spectrum-set-specific deep convolutional neural networks attempting to extract spectrum-set-specific features, followed by a spectrum pooling layer, whose target is to select a group of spectra with favorable discriminative abilities adaptively. IDICN jointly learns the nonlinear representations of the selected spectra, such that the intraspectrum Fisher loss and the interspectrum discriminant correlation are minimized. Experiments on the well-known Hong Kong Polytechnic University, Carnegie Mellon University, and the University of Western Australia multispectral face datasets demonstrate the superior performance of the proposed approach over several state-of-the-art methods.
Fei Wu 0004, Xiaoyuan Jing, Xiwei Dong, Ruimin Hu, Dong Yue 0001, Lina Wang 0001, Yimu Ji 0001, Ruchuan Wang 0001, Guoliang Chen 0008
IEEE Trans. Cybern.6
2020 Universal Detection of Video Steganography in Multiple Domains Based on the Consistency of Motion Vectors
abstract
Digital video provides various types of embedding domains, which lead to a great diversity in video steganography. However, in the detection of video steganography, the existing video steganalytic features all specialize in a particular domain, and are hardly to detect the steganography in other embedding domains. In this paper, we propose a universal feature set which is capable of detecting the video steganography in multiple domains. Two popular embedding domains, i.e., partition mode (PM) domain and motion vector (MV) domain, are considered for steganalysis. The idea is based on the observation that the MVs of the sub-blocks in the same macroblock are usually different from each other, and they will tend to be consistent in values after the MV modifications or PM modifications. Thus the consistency of MVs can be used as an evidence for the steganographic embedding in two domains, and finally a 12-dimensional feature set is designed for universal detection. Extensive experiments are conducted to demonstrate the effectiveness of the proposed feature set. The results show that our feature set achieves superior universality and accuracy in both PM domain and MV domain, and even performs well in mismatched domains, where the detection model trained in one domain can directly be used to attack the steganography in another domain. Besides, the low complexity of the proposed feature set also indicates its advantage in real-time video steganalysis.
Liming Zhai, Lina Wang 0001, Yanzhen Ren
IEEE Trans. Inf. Forensics Secur.2
2020 SmartPI: Understanding Permission Implications of Android Apps from User Reviews
abstract
With the unprecedented convenience brought by Apps on mobile devices, we are facing severe security attacks and privacy leakage caused by them since they may stealthily access unclaimed or unneeded permissions for some purposes. Many works strive to discover these malicious apps using program analysis techniques, however, they fail to tell users why an app needs to request the permission from users' perspective. In this paper, we leverage the power of the crowdsourced user reviews to understand why an app requests a permission. We propose a framework, called SmartPI, that automatically identifies functionality-relevant user reviews and infers the permission implication of them, bridging the gap between the functionalities and the actual behaviors of an app. In particular, we extract features from the platform documents to identify functionality-relevant user reviews from noisy crowdsourced user reviews with Natural Language Processing (NLP) techniques. The topic model is further adopted to infer the permission implications of apps from the functionality-relevant user reviews. More than 20,000 apps, 2,653,159 users, and 4,247,769 user reviews are crawled from Google Play as a real-world dataset to evaluate the performance of SmartPI. The experiments results show that the permission usage of apps can be better reflected by user reviews than the claimed descriptions of apps.
Run Wang 0001, Zhibo Wang 0001, Benxiao Tang, Lei Zhao 0012, Lina Wang 0001
IEEE Trans. Mob. Comput.5
2019 Multi-domain Embedding Strategies for Video Steganography by Combining Partition Modes and Motion Vectors
abstract
Digital video has various types of entities, which are utilized as embedding domains to hide messages in steganography. However, nearly all video steganography uses only one type of embedding domain, resulting in limited embedding capacity and potential security risks. In this paper, we firstly propose to embed in multi-domains for video steganography by combining partition modes (PMs) and motion vectors (MVs). The multi-domain embedding (MDE) aims to spread the modifications to different embedding domains for achieving higher undetectability. The key issue of MDE is the interactions of entities across domains. To this end, we design two MDE strategies, which hide data in PM domain and MV domain by sequential embedding and simultaneous embedding respectively. These two strategies can be applied to existing steganography within a distortion-minimization framework. Experiments show that the MDE strategies achieve a significant improvement in security performance against targeted steganalysis and fusion based steganalysis.
Liming Zhai, Lina Wang 0001, Yanzhen Ren
ICME2
2019 Designing Non-additive Distortions for JPEG Steganography Based on Blocking Artifacts Reduction
Yubo Lu, Liming Zhai, Lina Wang 0001
IWDW3
2019 Study on the interaction between the cover source mismatch and texture complexity in steganalysis
Donghui Hu, Zhongjin Ma, Yuqi Fan 0001, Shuli Zheng, Dengpan Ye, Lina Wang 0001
Multim. Tools Appl.6
2019 An AMR adaptive steganographic scheme based on the pitch delay of unvoiced speech
Yanzhen Ren, Dengkai Liu, Lina Wang 0001
Multim. Tools Appl.4
2019 A posterior evaluation algorithm of steganalysis accuracy inspired by residual co-occurrence probability
Lina Wang 0001, Liming Zhai, Yanzhen Ren, Bo Du 0001
Pattern Recognit.1
2019 A Secure AMR Fixed Codebook Steganographic Scheme Based on Pulse Distribution Model
abstract
Adaptive multi-rate (AMR), a popular audio compression standard, is widely used in mobile communication and mobile Internet applications and has become a novel carrier for hiding information. To improve the statistical security, this paper presents a steganographic scheme in the AMR fixed codebook (FCB) domain based on the pulse distribution model (PDM-AFS), which is obtained from the distribution characteristics of the FCB value in the cover audio. The pulse positions in stego audio are controlled by message encoding and random masking to make the statistical distribution of the FCB parameters close to that of the cover audio. The experimental results show that the statistical security of the proposed scheme is better than that of the existing schemes. Furthermore, the hiding capacity is maintained compared with the existing schemes. The average hiding capacity can reach 2.06 kbps at an audio compression rate of 12.2 kbps, and the auditory concealment is good. To the best of our knowledge, this is the first secure AMR FCB steganographic scheme that improves the statistical security based on the distribution model of the cover audio. This scheme can be extended to other audio compression codecs under the principle of algebraic code excited linear prediction (ACELP), such as G.723.1 and G.729.
Yanzhen Ren, Hanyi Yang, Hongxia Wu, Weiping Tu, Lina Wang 0001
IEEE Trans. Inf. Forensics Secur.5
2018 Controlled Channel Attack Detection Based on Hardware Virtualization
Chenyi Qiang, Weijie Liu 0004, Lina Wang 0001, Rongwei Yu
ICA3PP (1)3
2018 How people share digital images in social networks: a questionnaire-based study of privacy decisions and access control
Xiaoxia Hu, Donghui Hu, Shuli Zheng, Wangwang Li, Zhaopin Shu, Lina Wang 0001
Multim. Tools Appl.7
2018 An AMR adaptive steganography algorithm based on minimizing distortion
Yanzhen Ren, Hongxia Wu, Lina Wang 0001
Multim. Tools Appl.3
2018 A Provably-Secure Cross-Domain Handshake Scheme with Symptoms-Matching for Mobile Healthcare Social Network
abstract
With rapid developments of sensor, wireless and mobile communication technologies, Mobile Healthcare Social Networks (MHSNs) have emerged as a popular means of communication in healthcare services. Within MHSNs, patients can use their mobile devices to securely share their experiences, broaden their understanding of the illness or symptoms, form a supportive network, and transmit information (e.g., state of health and new symptoms) between users and other stake holders (e.g., medical center). Despite the benefits afforded by MHSNs, there are underlying security and privacy issues (e.g., due to the transmission of messages via a wireless channel). The handshake scheme is an important cryptographic mechanism, which can provide secure communication in MHSNs (e.g., anonymity and mutual authentication between users, such as patients). In this paper, we present a new framework for the handshake scheme in MHSNs, which is based on hierarchical identity-based cryptography. We then construct an efficient Cross-Domain HandShake (CDHS) scheme that allows symptoms-matching within MHSNs. For example, using the proposed CDHS scheme, two patients registered with different healthcare centers can achieve mutual authentication and generate a session key for future secure communications. We then prove the security of the scheme, and a comparative summary demonstrates that the proposed CDHS scheme requires fewer computation and lower communication costs. We also implement the proposed CDHS scheme and three related schemes in a proof of concept Android app to demonstrate utility of the scheme. Findings from the evaluations demonstrate that the proposed CDHS scheme achieves a reduction of 18.14 and 5.41 percent in computation cost and communication cost, in comparison to three other related handshake schemes.
Debiao He, Neeraj Kumar 0001, Huaqun Wang, Lina Wang 0001, Kim-Kwang Raymond Choo, Alexey V. Vinel
IEEE Trans. Dependable Secur. Comput.4
2018 Dynamic Proofs of Retrievability for Coded Cloud Storage Systems
abstract
Cloud storage allows users to store their data in a remote server to get rid of expensive local storage and management costs and then access data of interest anytime anywhere. A number of solutions have been proposed to tackle the verification of remote data integrity and retrievability in cloud storage systems. Most of existing schemes, however, do not support efficient data dynamics and/or suffer from security vulnerabilities when involving dynamic data operations. In this paper, we propose a dynamic proof of retrievability scheme supporting public auditability and communication-efficient recovery from data corruptions. To this end, we split up the data into data blocks and encode each data block individually using outer code and inner code before outsourcing so that i) an update inside any data block only affects a few codeword symbols and ii) communication-efficient data repair for a breakdown server can be achieved and communication overhead for small data corruptions within a server can be eliminated. Based on the encoded data blocks, we utilize rb23Tree to enforce the data sequence for dynamic operations, preventing the cloud service provider from manipulating data block to pass the integrity check in the dynamic scenario. Formal security analysis and extensive experimental evaluations are conducted, showing that the proposed scheme is practical for use in cloud storage systems.
Zhengwei Ren, Lina Wang 0001, Qian Wang 0002, Mingdi Xu
IEEE Trans. Serv. Comput.2
2018 Niffler: A Context-Aware and User-Independent Side-Channel Attack System for Password Inference
abstract
Digital password lock has been commonly used on mobile devices as the primary authentication method. Researches have demonstrated that sensors embedded on mobile devices can be employed to infer the password. However, existing works focus on either each single keystroke inference or entire password sequence inference, which are user‐dependent and require huge efforts to collect the ground truth training data. In this paper, we design a novel side‐channel attack system, called Niffler, which leverages the user‐independent features of movements of tapping consecutive buttons to infer unlocking passwords on smartphones. We extract angle features to reflect the changing trends and build a multicategory classifier combining the dynamic time warping algorithm to infer the probability of each movement. We further use the Markov model to model the unlocking process and use the sequences with the highest probabilities as the attack candidates. Moreover, the sensor readings of successful attacks will be further fed back to continually improve the accuracy of the classifier. In our experiments, 100,000 samples collected from 25 participants are used to evaluate the performance of Niffler. The results show that Niffler achieves 70% and 85% accuracy with 10 attempts in user‐independent and user‐dependent environments with few training samples, respectively.
Benxiao Tang, Zhibo Wang 0001, Run Wang 0001, Lei Zhao 0012, Lina Wang 0001
Wirel. Commun. Mob. Comput.5
2017 Combined and Calibrated Features for Steganalysis of Motion Vector-Based Steganography in H.264/AVC
abstract
This paper presents a novel feature set for steganalysis of motion vector-based steganography in H.264/AVC. First, the influence of steganographic embedding on the sum of absolute difference (SAD) and the motion vector difference (MVD) is analyzed, and then the statistical characteristics of these two aspects are combined to design features. In terms of SAD, the macroblock partition modes are used to measure the quantization distortion, and by using the optimality of SAD in neighborhood, the partition based neighborhood optimal probability features are extracted. In terms of MVD, it has been proved that MVD is better in feature construction than neighboring motion vector difference (NMVD) which has been widely used by traditional steganalyzers, and thus the inter and intra co-occurrence features are constructed based on the distribution of two components of neighboring MVDs and the distribution of two components of the same MVD. Finally, the combined features are enhanced by window optimal calibration, which utilizes the optimality of both SAD and MVD in a local window area. Experiments on various conditions demonstrate that the proposed scheme generally achieves a more accurate detection than current methods especially for videos encoded in variable block size and high quantization parameter values, and exhibits strong universality in applications.
Liming Zhai, Lina Wang 0001, Yanzhen Ren
IH&MMSec2
2017 A Steganalysis Scheme for AAC Audio Based on MDCT Difference Between Intra and Inter Frame
Yanzhen Ren, Qiaochu Xiong, Lina Wang 0001
IWDW3
2017 Insecurity of an identity-based public auditing protocol for the outsourced data in cloud storage
Debiao He, Huaqun Wang, Lina Wang 0001
Inf. Sci.4
2017 deExploit: Identifying misuses of input data to diagnose memory-corruption exploits at the binary level
Run Wang 0001, Lei Zhao 0012, Yueqiang Cheng, Lina Wang 0001
J. Syst. Softw.5
2017 Adaptive Steganalysis Based on Selection Region and Combined Convolutional Neural Networks
abstract
Digital image steganalysis is the art of detecting the presence of information hiding in carrier images. When detecting recently developed adaptive image steganography methods, state-of-art steganalysis methods cannot achieve satisfactory detection accuracy, because the adaptive steganography methods can adaptively embed information into regions with rich textures via the guidance of distortion function and thus make the effective steganalysis features hard to be extracted. Inspired by the promising success which convolutional neural network (CNN) has achieved in the fields of digital image analysis, increasing researchers are devoted to designing CNN based steganalysis methods. But as for detecting adaptive steganography methods, the results achieved by CNN based methods are still far from expected. In this paper, we propose a hybrid approach by designing a region selection method and a new CNN framework. In order to make the CNN focus on the regions with complex textures, we design a region selection method by finding a region with the maximal sum of the embedding probabilities. To evolve more diverse and effective steganalysis features, we design a new CNN framework consisting of three separate subnets with independent structure and configuration parameters and then merge and split the three subnets repeatedly. Experimental results indicate that our approach can lead to performance improvement in detecting adaptive steganography.
Donghui Hu, Shengnan Zhou, Xueliang Liu, Yuqi Fan 0001, Lina Wang 0001
Secur. Commun. Networks6
2017 Efficient certificateless anonymous multi-receiver encryption scheme for mobile devices
Debiao He, Huaqun Wang, Lina Wang 0001, Jian Shen 0001, Xianzhao Yang
Soft Comput.3
2017 AMR Steganalysis Based on Second-Order Difference of Pitch Delay
abstract
This paper presents a novel steganalysis scheme for the detection of adaptive multi-rate (AMR) audio steganography. AMR audio codec is used widely in mobile communication and mobile Internet system. Due to the modifiability of pitch delay, several AMR steganography schemes based on pitch delay modulation have emerged gradually and have high capacity and good imperceptibility. Based on the difference between cover and stego AMR audios on the continuity of adjacent pitch delay, this paper proposes the matrix of the second-order difference of pitch delay (MSDPD) steganalysis features by calculating the Markov transition probability MSDPD, and uses the calibration method to estimate the cover's features to get the calibrated MSDPD features to improve the accuracy of the scheme. Support vector machine is used as the steganalyzer to test the performance of our proposed scheme. The experimental results show that the correct detection rate of our proposed method is more than 85% when the embedding bit rate is 30% or above, and can reach above 85% for cover audios. The results of contrast experiment show that the performance of our proposed method is better than the existing method, especially on low embedding rate. The method can be extended to other CELP codec, such as G.723.1 and G.729.
Yanzhen Ren, Lina Wang 0001
IEEE Trans. Inf. Forensics Secur.4
2017 Batch Identification Game Model for Invalid Signatures in Wireless Mobile Networks
abstract
Secure access is one of the fundamental problems in wireless mobile networks. Digital signature is a widely used technique to protect messages' authenticity and nodes' identities. From the practical perspective, to ensure the quality of services in wireless mobile networks, ideally the process of signature verification should introduce minimum delay. Batch cryptography technique is a powerful tool to reduce verification time. However, most of the existing works focus on designing batch verification algorithms for wireless mobile networks without sufficiently considering the impact of invalid signatures, which can lead to verification failures and performance degradation. In this paper, we propose a Batch Identification Game Model (BIGM) in wireless mobile networks, enabling nodes to find invalid signatures with reasonable delay no matter whether the game scenario is complete information or incomplete information. Specifically, we analyze and prove the existence of Nash Equilibriums (NEs) in both scenarios, to select the dominant algorithm for identifying invalid signatures. To optimize the identification algorithm selection, we propose a self-adaptive auto-match protocol which estimates the strategies and states of attackers based on historical information. Comprehensive simulation results in terms of NE reasonability, algorithm selection accuracy, and identification delay are provided to demonstrate that BIGM can identify invalid signatures more efficiently than existing algorithms.
Jing Chen 0003, Kun He 0008, Quan Yuan 0003, Guoliang Xue, Ruiying Du, Lina Wang 0001
IEEE Trans. Mob. Comput.6
2016 Steganalysis of AAC using calibrated Markov model of adjacent codebook
abstract
AAC(Advanced Audio Coding) is the most popular audio compression standard and used widely in recent years. The steganography schemes of AAC emerged gradually. This paper presents a novel steganalysis method to attack the steganography of Huffman codebook, which hide information by modifying the codebook of each scale factor band(SFB), and have good imperceptivity and security. Based on the correlation of neighboring SFBs' codebook, the paper proposes to extract the Markov transition probability of adjacent SFBs' codebook as steganalysis feature, and adopt calibration to improve the accuracy. Extensive experiments demonstrate the effectiveness of the proposed methods. To the best of our knowledge, this piece of work is the first one to detect AAC steganography of Huffman codebook.
Yanzhen Ren, Qiaochu Xiong, Lina Wang 0001
ICASSP3
2016 A Study of the Two-Way Effects of Cover Source Mismatch and Texture Complexity in Steganalysis
Donghui Hu, Zhongjin Ma, Yuqi Fan 0001, Lina Wang 0001
IWDW4
2016 Distributed Greedy Coding-aware Deterministic Routing for multi-flow in wireless networks
Jing Chen 0003, Kun He 0008, Quan Yuan 0003, Ruiying Du, Lina Wang 0001, Jie Wu 0001
Comput. Networks5
2016 Lightweight anonymous key distribution scheme for smart grid using elliptic curve cryptography
abstract
Due to efficiency, security and reliability, the smart grid attracts more and more attentions from both industry and researchers. To implement secure communication in the smart grid, how to distribute secret keys among participants become an important issue. Several key distribution schemes for the smart grid have been proposed to guarantee secure communication. However, most of them cannot provide smart meter anonymity or have unsatisfactory performance. Based on the identity‐based cryptography, this study proposes an anonymous key distribution (AKD) scheme for the smart grid using the elliptic curve cryptography. The proposed AKD scheme can provide the smart meter anonymity and mutual authentication between two participants without any help of the trusted anchor. Due to the fact that no bilinear paring operation is involved in the execution, the proposed AKD scheme has much better performance than the latest AKD scheme proposed by Tsai and Lo. Detailed performance analysis shows that the computation and the communication costs of the authors’ AKD scheme is about 82.39 and 52.33% less than that of Tsai and Lo's AKD scheme. Besides, security analysis shows that the proposed AKD scheme is provably secure in the random oracle model.
Debiao He, Huaqun Wang, Muhammad Khurram Khan, Lina Wang 0001
IET Commun.4
2016 Detection of double MP3 compression Based on Difference of Calibration Histogram
Yanzhen Ren, Mengdi Fan, Dengpan Ye, Lina Wang 0001
Multim. Tools Appl.5
2016 Lossless data hiding algorithm for encrypted images with high capacity
Shuli Zheng, Donghui Hu, Dengpan Ye, Lina Wang 0001
Multim. Tools Appl.5
2016 Message-locked proof of ownership and retrievability with remote repairing in cloud
abstract
Cloud storage services are widely deployed and employed in recent years. A number of data checking techniques have been proposed for secure cloud storage services. These state-of-the-art schemes only focus on some aspects, such as data integrity, users' ownership, and data resiliency, but the overall safety of cloud storage services is not discussed sufficiently. Considering cloud storage requirements as a whole, in this paper, we propose a model of message-locked proof of ownership and retrievability with remote repairing, which provides data confidentiality, secure cross-user deduplication at the client-side, file retrievability, ownership privacy-preserving, random block accessing, and remote repairing simultaneously. In addition, we also propose a concrete construction and prove its security in the random oracle model. The experimental results show that our construction is efficient in practice. Copyright © 2016 John Wiley & Sons, Ltd.
Jing Chen 0003, Kun He 0008, Min Chen 0003, Ruiying Du, Lina Wang 0001
Secur. Commun. Networks6
2016 A novel covert channel detection method in cloud based on XSRM and improved event association algorithm
abstract
Covert channel is a major threat to the information system security and commonly found in operating systems, especially in cloud computing environment. Owing to the characteristics in cloud computing environment such as resources sharing and logic boundaries, covert channels become more varied and difficult to find. Focusing on those problems, this paper presents a universal method for detecting covert channel automatically. To achieve a global detection, we leveraged a virtual machine event record mechanism in hypervisor to gather necessary metadata. Combining the shared resources matrix methodology with events association mechanism, we proposed a distinctive algorithm that can accurately locate and analyze malicious covert channels from the respect of behaviors. Compared with the popular statistical test methods focusing on the single covert channel, our method is capable of recognizing and detecting more covert channels in real time. Experimental results show that this method is not only able to detect multilevel and multiform covert channels in cloud environment effectively but also facilitates the implementation and deployment in practical scenarios without modifying the existing system. Copyright © 2016 John Wiley & Sons, Ltd.
Lina Wang 0001, Weijie Liu 0004, Neeraj Kumar 0001, Debiao He, Cheng Tan 0006, Debin Gao
Secur. Commun. Networks1
2015 Regression Identification of Coincidental Correctness via Weighted Clustering
abstract
Coverage-based fault localization techniques leverage coverage information to identify the suspicious program entities for inspection. However, coincidental correctness (CC) widely occurs during software debugging, and brings negative impact to the effectiveness of CBFL techniques. In this paper, we propose a regression approach to identity CC execution with weighted clustering analysis. Based on the observation that program entities with different suspiciousness have different contributions to identify coincidental correctness, we make use of the suspiciousness calculated by CBFL techniques as the weight of each program entity and conduct weighted clustering to identify coincidental correctness regressively. To evaluate the effectiveness of our approach, we construct controlled experiments built on benchmark programs, and the experimental results show that our approach is able to improve the accuracy of the identification of coincidental correctness executions and further improve the effectiveness of CBFL techniques.
Xiaoshuang Yang, Mengleng Liu, Lei Zhao 0012, Lina Wang 0001
COMPSAC5
2015 Reversing and Identifying Overwritten Data Structures for Memory-Corruption Exploit Diagnosis
abstract
Exploits diagnosis requires great manual effort and desires to be automated as much as possible. In this paper, we investigate how the syntactic format of program inputs, as well as reverse engineering of data structures, could be used to identify overwritten data structures, and propose a binary-level exploit diagnosis approach, deExploit, that is generic to attack types and effective in identifying key attack steps. In details, we design to use a fine-grained dynamic tainting technique to model how the exploit is dynamically processed during program execution, dynamically reverse corresponding data structures of program input and then identify overwritten data structures by detecting the deviation between dynamic processing of exploit and that of benign input. We implement deExploit and perform it to diagnose multiple exploits in the wild. The results show that deExploit works well to diagnose memory corruption exploits.
Lei Zhao 0012, Run Wang 0001, Lina Wang 0001, Yueqiang Cheng
COMPSAC3
2015 AMR Steganalysis Based on the Probability of Same Pulse Position
abstract
This paper presents a method for detection of adaptive multirate (AMR) audio steganography. AMR audio codec is an audio data compression scheme optimized for speech coding, and widely used in some mobile telecommunications system. The AMR audio steganography schemes are emerging recently and they embed secret messages by modifying the nonzero pulse positions which are determined by fixed codebook search in AMR compression procedure. Those methods have high embedding capacity and good imperceptivity. We have observed that those steganography schemes will cause the probability of same pulse positions in the same track increasing. Based on this phenomenon, this paper presents a set of steganalysis features of the probability of same pulse position. The support vector machine is applied to the proposed features and used as the steganalyzer. The performance of the scheme is tested on a database containing ~140714 audios. Experimental results show that the correct detection rate of our proposed method is 90% when the embedding bit rate is 30% or above, and can reach above 85% for cover audios.
Yanzhen Ren, Tingting Cai, Ming Tang 0002, Lina Wang 0001
IEEE Trans. Inf. Forensics Secur.4
2014 Video steganalysis based on subtractive probability of optimal matching feature
abstract
This paper presents a novel motion vector (MV) steganalysis method. MV-based steganographic methods exploite the variability of MV to embed messages by modifying MV slightly. However, we have noticed that the modified MVs after steganography cannot follow the optimal matching rule which is the target of motion estimation. It means that steganographic methods conflict with the basic principle of video compression. Aiming at this difference, we proposed a steganalysis feature based on Subtractive Probability of Optimal Matching(SPOM), which statistics the MV's Probability of the Optimal matching (POM) around its neighbors, and extract the classification feature by subtracting the POM of the test video and its recompressed video. Experiment results show that the proposed feature is sensitive to MV-based steganography methods, and outperforms the other methods, especially for high temporal activity video.
Yanzhen Ren, Liming Zhai, Lina Wang 0001
IH&MMSec3
2014 vPatcher: VMI-Based Transparent Data Patching to Secure Software in the Cloud
abstract
Quick defense against the spread of software exploits is an important problem, and hot patching is an attractive approach to solve this problem. However, these approaches cannot adapt to cloud well, which brings new challenges to the protection of software. Among these challenges, transparency and rapid deployment are two respective requirements for protection. In this paper, we propose vPatcher, a transparent data patching technique based on Virtual Machine Introspection. Vpatcher uses hypervisor to monitor the network connections of vulnerable programs in protected guest systems, deployed outside the Virtual Machines, without disturbing the target guest systems. Given the vulnerability signatures, vPatcher intercepts network packets, scans these packets for vulnerable processes by reconstructing fine-grained system semantics that include process states as well as corresponding network connections, detects them with their vulnerability signatures, and finally filters exploits. We adopted several realistic vulnerable programs used broadly to evaluate the effectiveness of the technique, and experimental results showed its efficacy and that the overhead is acceptable. In addition, the experiments also show that it could be transparent to guest systems, and suitable for rapid deployment in cloud platforms.
Lei Zhao 0012, Lai Xu 0003, Lina Wang 0001, Deming Wu
TrustCom4
2013 A Fault Localization Framework to Alleviate the Impact of Execution Similarity
abstract
Coverage-based fault localization (CBFL) techniques contrast the execution spectra of a program entity to assess the extent of how much a program entity is being related to faults. However, different test cases may result in similar executions, which further make the execution spectra of program entities be indistinguishable among similar executions. As a consequence, most of the current CBFL techniques are impacted by the noise of indistinguishable spectra. To alleviate the impact of execution similarity and improve the effectiveness of CBFL techniques, we propose a general fault localization framework. This framework is general to current execution spectra based CBFL techniques, which could synthesize a fault localization technique based on a given base technique. To synthesize the new technique, we use the concept of coverage vector to model execution spectra and capture the execution similarity, then reduce the impact of execution similarity by counting distinct coverage vectors, and finally assess the suspiciousness of basic blocks being related to faults with the spectra of distinct coverage vectors. We adopt four representative fault localization techniques as base techniques, use seven Siemens programs and three median-sized real-life UNIX utility programs as subject programs, to conduct an experimental study on the effectiveness of our framework. The empirical evaluation shows that our framework can effectively alleviate the impact of execution similarity and generate more effective fault localization techniques based on existing ones.
Lei Zhao 0012, Lina Wang 0001, Xiaodan Yin
Int. J. Softw. Eng. Knowl. Eng.3
2012 Learning Fine-Grained Structured Input for Memory Corruption Detection
Lei Zhao 0012, Debin Gao, Lina Wang 0001
ISC3
2011 PAFL: Fault Localization via Noise Reduction on Coverage Vector
Lei Zhao 0012, Lina Wang 0001, Xiaodan Yin
SEKE3
2011 Statistical Fault Localization via Semi-dynamic Program Slicing
abstract
Fault localization is a critical step of software debugging. We present a statistical fault localization approach via semi-dynamic slicing in this paper. In our technique, we first conduct the execution flow graph based on both the coverage information and static control-flow-graph to model the executions approximately. Second, we use the backward slicing to analyze the dependence relationships between execution statements and execution results, obtain sliced statements and calculate the coverage statistics. At last, we calculate the fault suspiciousness according to Tarantula, a classic approach of statistical fault localization. Controlled experiments are setup on the Siemens subjects, and the results are promising.
Rongwei Yu, Lei Zhao 0012, Lina Wang 0001, Xiaodan Yin
TrustCom3
2011 The Design of a Wireless Sensor Network for Seismic-Observation-Environment Surveillance
Xiaoguang Niu, Chuanbo Wei, Lina Wang 0001
WASA3
2011 Image authentication based on perceptual hash using Gabor filters
Lina Wang 0001, Xiaqiu Jiang, Shiguo Lian, Donghui Hu, Dengpan Ye
Soft Comput.1