Mingfu Xue

dblp:03/11506 · DBLP profile ↗
← Back
29ranked-venue papers
20as first author
24since 2021 · last 2026
0000-0003-2408-503XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 11 first-author · 8 since 2021Artificial intelligence and machine learning · 6 · 4 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 1 first-author · 6 since 2021Computer networks · 4 · 2 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Tackling Resource-Constrained and Data-Heterogeneity in Federated Learning with Double-Weight Sparse Pack
abstract
Federated learning has drawn widespread interest from researchers, yet the data heterogeneity across edge clients remains a key challenge, often degrading model performance. Existing methods enhance model compatibility with data heterogeneity by splitting models and knowledge distillation. However, they neglect the insufficient communication bandwidth and computing power on the client, failing to strike an effective balance between addressing data heterogeneity and accommodating limited client resources. To tackle this limitation, we propose a personalized federated learning method based on cosine sparsification parameter packing and dual-weighted aggregation (FedCSPACK), which effectively leverages the limited client resources and reduces the impact of data heterogeneity on model performance. In FedCSPACK, the client packages model parameters and selects the most contributing parameter packages for sharing based on cosine similarity, effectively reducing bandwidth requirements. The client then generates a mask matrix anchored to the shared parameter package to improve the alignment and aggregation efficiency of sparse updates on the server. Furthermore, directional and distribution distance weights are embedded in the mask to implement a weighted-guided aggregation mechanism, enhancing the robustness and generalization performance of the global model. Extensive experiments across four datasets using ten state-of-the-art methods demonstrate that FedCSPACK effectively improves communication and computational efficiency while maintaining high model accuracy.
Qiantao Yang, Liquan Chen, Mingfu Xue
AAAI3
2025 Adversarial Example Based Fingerprint Embedding for Robust Copyright Protection in Split Learning
abstract
Currently, deep learning models are easily exposed to data leakage risks. As a distributed model, Split Learning thus emerged as a solution to address this issue. The model is splitted to avoid data uploading to the server and reduce computing requirements while ensuring data privacy and security. However, the transmission of data between clients and server creates a potential vulnerability. In particular, model is vulnerable to intellectual property (IP) infringement such as piracy. Alarmingly, a dedicated copyright protection framework tailored for Split Learning models is still lacking. To this end, we propose the first copyright protection scheme for Split Learning model, leveraging fingerprint to ensure effective and robust copyright protection. The proposed method first generates a set of specifically designed adversarial examples. Then, we select those examples that would induce misclassifications to form the fingerprint set. These adversarial examples are embedded as fingerprints into the model during the training process. Exhaustive experiments highlight the effectiveness of the scheme. This is demonstrated by a remarkable fingerprint verification success rate (FVSR) of 100% on MNIST, 98% on CIFAR-10, and 100% on ImageNet, respectively. Meanwhile, the model’s accuracy only decreases slightly, indicating that the embedded fingerprints do not compromise model performance. Even under label inference attack, our approach consistently achieves a high fingerprint verification success rate that ensures robust verification.
Zhangting Lin, Mingfu Xue, Wenmao Liu, Liquan Chen
TrustCom2
2025 An Active Authorization Control Method for Deep Reinforcement Learning Model Based on GANs and Adaptive Trigger
abstract
In recent years, deep reinforcement learning (DRL) has found widespread applications across diverse scenarios. Since the DRL training process requires substantial time and financial costs, well-trained DRL policies should be considered as intellectual property (IP) which deserves proper protection. However, to date, there are only a few studies on IP protection on DRL and the existing methods are limited to passive copyright verification. In this paper, we propose the first active authorization control method for DRL which can proactively protect deep reinforcement learning policy. The DRL policy trained with this method can be used by authorized users normally, but cannot be used by unauthorized users (i.e., the protected policy’s performance for unauthorized users is paralyzed). Specifically, we train a trigger injection network and a discriminator network based on generative adversarial networks (GANs). During the DRL policy training phase, we use trigger injection network to insert sample-specific triggers to all observations and use triggered observations to train the protected policy. Our approach is applicable across various deep reinforcement learning algorithms. We conduct effectiveness experiments on different DRL policies trained using different DRL algorithms, and the experimental results revealed that the performance of authorized users is on par with the performance of clean DRL policy trained normally (baseline), whereas the performance of unauthorized users significantly deviates from that of the baseline. Specifically, the authorized performance of protected Breakout-DQN, Breakout-A2C, MsPacman-DQN and MsPacman-A2C policies are 416.4 (baseline 397.8), 403.0 (baseline 415.0), 2552.0 (baseline 2472.0), and 1964.0 (baseline 1828.0). Comparatively, the unauthorized performance of protected Breakout-DQN, Breakout-A2C, MsPacman-DQN and MsPacman-A2C policies are only 4.4 (baseline 397.8), 2.0 (baseline 415.0), 74.0 (baseline 2472.0), and 514.0 (baseline 1828.0). Furthermore, the experiments demonstrate that the proposed method exhibits robustness against pruning, fine-tuning, and adaptive attacks.
Mingfu Xue, Kewei Chen 0004, Leo Yu Zhang, Yushu Zhang 0001, Weiqiang Liu 0001
IEEE Trans. Inf. Forensics Secur.1
2024 Imperceptible and multi-channel backdoor attack
Mingfu Xue, Shifeng Ni, Yinghao Wu, Yushu Zhang 0001, Weiqiang Liu 0001
Appl. Intell.1
2024 Untargeted Backdoor Attack Against Deep Neural Networks With Imperceptible Trigger
abstract
Recent research works have demonstrated that deep neural networks (DNNs) are vulnerable to backdoor attacks. The existing backdoor attacks can only cause targeted misclassification on backdoor instances, which makes them can be easily detected by defense methods. In this article, we propose an untargeted backdoor attack (UBA) against DNNs, where the backdoor instances are randomly misclassified by the backdoored model to any incorrect label. To achieve the goal of UBA, we propose to utilize autoencoder as the trigger generation model and train the target model and the autoencoder simultaneously. We also propose a special loss function (Evasion Loss) to train the autoencoder and the target model, in order to make the target model predict backdoor instances as random incorrect classes. During the inference stage, the trained autoencoder is used to generate backdoor instances. For different backdoor instances, the generated triggers are different and the corresponding predicted labels are random incorrect labels. Experimental results demonstrate that the proposed UBA is effective. On the ResNet-18 model, the attack success rate (ASR) of the proposed UBA is 96.48%, 91.27%, and 90.83% on CIFAR-10, GTSRB, and ImageNet datasets, respectively. On the VGG-16 model, the ASR of the proposed UBA is 89.72% and 97.78% on CIFAR-10 and ImageNet datasets, respectively. Moreover, the proposed UBA is robust against existing backdoor defense methods, which are designed to detect targeted backdoor attacks. We hope this article can promote the research of corresponding backdoor defense works.
Mingfu Xue, Yinghao Wu, Shifeng Ni, Leo Yu Zhang, Yushu Zhang 0001, Weiqiang Liu 0001
IEEE Trans. Ind. Informatics1
2024 PS-Net: A Learning Strategy for Accurately Exposing the Professional Photoshop Inpainting
abstract
Restoring missing areas without leaving visible traces has become a trivial task with Photoshop inpainting tools. However, such tools have potentially illegal or unethical uses, such as removing specific objects in images to deceive the public. Despite the emergence of many forensics methods of image inpainting, their detection ability is still insufficient when attending to professional Photoshop inpainting. Motivated by this, we propose a novel method termed primary-secondary network (PS-Net) to localize the Photoshop inpainted regions in images. To the best of our knowledge, this is the first forensic method devoted specifically to Photoshop inpainting. The PS-Net is designed to deal with the problems of delicate and professional inpainted images. It consists of two subnetworks: the primary network (P-Net) and the secondary network (S-Net). The P-Net aims at mining the frequency clues of subtle inpainting features through the convolutional network and further identifying the tampered region. The S-Net enables the model to mitigate compression and noise attacks to some extent by increasing the co-occurring feature weights and providing features that are not captured by the P-Net. Furthermore, the dense connection, Ghost modules, and channel attention blocks (C-A blocks) are adopted to further strengthen the localization ability of PS-Net. Extensive experimental results illustrate that PS-Net can successfully distinguish forged regions in elaborate inpainted images, outperforming several state-of-the-art solutions. The proposed PS-Net is also robust against some postprocessing operations commonly used in Photoshop.
Yushu Zhang 0001, Zhibin Fu, Mingfu Xue, Xiaochun Cao, Yong Xiang 0001
IEEE Trans. Neural Networks Learn. Syst.4
2024 SSAT: Active Authorization Control and User's Fingerprint Tracking Framework for DNN IP Protection
abstract
As training a high-performance deep neural network (DNN) model requires a large amount of data, powerful computing resources and expert knowledge, protecting well-trained DNN models from intellectual property (IP) infringement has raised serious concerns in recent years. Most existing methods using DNN watermarks to verify the ownership of the models after IP infringement occurs, which is reactive in the sense that they cannot prevent unauthorized users from using the model in the first place. Different from these methods, in this article, we propose an active authorization control and user’s fingerprint tracking method for the IP protection of DNN models by utilizing sample-specific backdoor attack. The proposed method inversely and multiplely exploits sample-specific trigger as the key to implement authorization control for DNN model, in which the generated triggers are imperceptible and sample-specific for clean images. Specifically, a U-Net model is used to generate backdoor instances. Then, the target model is trained on the clean images and backdoor instances, which are inversely labeled as wrong classes and correct classes, respectively. Only authorized users can use the target model normally by pre-processing the clean images through the U-Net model. Moreover, the images processed by the U-Net model will contain unique fingerprint that can be extracted to verify and track the corresponding user’s identity. This article is the first work that utilizes the sample-specific backdoor attack to implement active authorization control and user’s fingerprint management for DNN model under black-box scenarios. Extensive experimental results on ImageNet dataset and YouTube Aligned Face dataset demonstrate that the proposed method is effective in protecting the DNN model from unauthorized usage. Specifically, the protected model has a low inference accuracy (1.00%) for unauthorized users, while maintaining a normal inference accuracy (97.67%) for authorized users. Besides, the proposed method can achieve 100% fingerprint tracking success rates on both the ImageNet and YouTube Aligned Face datasets. Moreover, it is demonstrated that the proposed method is robust against fine-tuning attack, pruning attack, pruning attack with retraining, reverse-engineering attack, adaptive attack, and JPEG compression attack. The code is available at https://github.com/nuaaaisec/SSAT .
Mingfu Xue, Yinghao Wu, Leo Yu Zhang, Dujuan Gu, Yushu Zhang 0001, Weiqiang Liu 0001
ACM Trans. Multim. Comput. Commun. Appl.1
2024 Adaptive 3D Mesh Steganography Based on Feature-Preserving Distortion
abstract
Current 3D mesh steganography algorithms relying on geometric modification are prone to detection by steganalyzers. In traditional steganography, adaptive steganography has proven to be an efficient means of enhancing steganography security. Taking inspiration from this, we propose a highly adaptive embedding algorithm, guided by the principle of minimizing a carefully crafted distortion through efficient steganography codes. Specifically, we tailor a payload-limited embedding optimization problem for 3D settings and devise a feature-preserving distortion (FPD) to measure the impact of message embedding. The distortion takes on an additive form and is defined as a weighted difference of the effective steganalytic subfeatures utilized by the current 3D steganalyzers. With practicality in mind, we refine the distortion to enhance robustness and computational efficiency. By minimizing the FPD, our algorithm can preserve mesh features to a considerable extent, including steganalytic and geometric features, while achieving a high embedding capacity. During the practical embedding phase, we employ the Q-layered syndrome trellis code (STC). However, calculating the bit modification probability (BMP) for each layer of the Q-layered STC, given the variation of Q, can be cumbersome. To address this issue, we design a universal and automatic approach for the BMP calculation. The experimental results demonstrate that our algorithm achieves state-of-the-art performance in countering 3D steganalysis.
Yushu Zhang 0001, Jiahao Zhu 0005, Mingfu Xue, Xinpeng Zhang 0001, Xiaochun Cao
IEEE Trans. Vis. Comput. Graph.3
2023 Compression-resistant backdoor attack against deep neural networks
Mingfu Xue, Xin Wang 0241, Shichang Sun, Yushu Zhang 0001, Jian Wang 0038, Weiqiang Liu 0001
Appl. Intell.1
2023 Dataset authorization control: protect the intellectual property of dataset via reversible feature space adversarial examples
Mingfu Xue, Yinghao Wu, Yushu Zhang 0001, Jian Wang 0038, Weiqiang Liu 0001
Appl. Intell.1
2023 Detecting backdoor in deep neural networks via intentional adversarial perturbations
Mingfu Xue, Yinghao Wu, Zhiyu Wu, Yushu Zhang 0001, Jian Wang 0038, Weiqiang Liu 0001
Inf. Sci.1
2023 Localization of Inpainting Forgery With Feature Enhancement Network
abstract
Inpainting the given region of an image is a typical requirement in computer vision. Conventional inpainting, through exemplar-based or diffusion-based strategies, can create realistic inpainted images at a very low cost. Also, such easy-to-use manipulation poses new security threats. Therefore, the detection of inpainting has attracted considerable attention from researchers. However, the existing methods are typically not suitable for the general detection of various inpainting algorithms. Motivated by this, in this work, an efficient feature enhancement network is proposed to locate the inpainted regions in the digital image. First, we design an artifact enhancement block to effectively capture the traces left by diffusion or exemplar-based inpainting. Then, the VGGNet is used as a feature extractor to describe advanced and low-resolution features. Finally, to take full advantage of enhanced features, we concatenate the features obtained by the feature extractor and the up-sampling operations. Extensive experimental evaluations, covering benchmarking, ablation, robustness, generalization, and efficiency studies, confirm the usefulness of the proposed method. This is especially true on the conventional inpainting dataset, our method obtains an average F1 score 7.63% higher than the second-best method. Theoretical and numerical analyses support the effectiveness of our feature enhancement network in representing the artifacts in inpainted images, exhibiting better potential for real-world forensics than various state-of-the-art strategies.
Yushu Zhang 0001, Zhibin Fu, Mingfu Xue, Zhongyun Hua, Yong Xiang 0001
IEEE Trans. Big Data4
2023 Detection of Recolored Image by Texture Features in Chrominance Components
abstract
Image recoloring is an emerging editing technique that can change the color style of an image by modifying pixel values without altering the original image content. With the rapid proliferation of social network and image editing techniques, recolored images (RIs) have raised new security issues in society. Existing detection methods have good performance in detecting RIs for certain categories of recoloring techniques. However, the performance on the handcrafted recoloring scenario is still poor due to the influence of human prior knowledge. To deal with this problem, we explore a solution from the perspective of chrominance texture artifacts to improve the generalization ability. The results of the analysis show that natural images (NIs) and RIs have textural disparities in different color components, especially in the chrominance components (i.e., Cb, Cr, and H). Based on such new prior knowledge of statistical discriminability, we propose a feature set to capture texture features in chrominance components for identifying RIs. Extensive experimental results show that the proposed method can accurately identify RIs with certain categories of recoloring techniques, and outperforms existing methods in the scenario of handcrafted recoloring.
Yushu Zhang 0001, Mingfu Xue, Zhongyun Hua
ACM Trans. Multim. Comput. Commun. Appl.4
2023 PRNU-based Image Forgery Localization with Deep Multi-scale Fusion
abstract
Photo-response non-uniformity (PRNU), as a class of device fingerprint, plays a key role in the forgery detection/localization for visual media. The state-of-the-art PRNU-based forensics methods generally rely on the multi-scale trace analysis and result fusion, with Markov random field model. However, such hand-crafted strategies are difficult to provide satisfactory multi-scale decision, exhibiting a high false-positive rate. Motivated by this, we propose an end-to-end multi-scale decision fusion strategy, where a mapping from multi-scale forgery probabilities to binary decision is achieved by a supervised deep fully connected neural network. As the first time, the deep learning technology is employed in PRNU-based forensics for more flexible and reliable integration of multi-scale information. The benchmark experiments exhibit the state-of-the-art accuracy performance of our method in both pixel-level and image-level, especially for false positives. Additional robustness experiments also demonstrate the benefits of the proposed method in resisting noise and compression attacks.
Yushu Zhang 0001, Qing Tan, Mingfu Xue
ACM Trans. Multim. Comput. Commun. Appl.4
2022 PRNU-based Image Forgery Localization With Convolutional Neural Network
abstract
The device fingerprint, photo-response non-uniformity (PRNU), has attracted great interest in image tampering detection and localization. The classical PRNU-based tampering detection generally depends on the correlation analysis, with the normalized correlation and hand-crafted predictor. The predictor detects unreliable regions and determines them as forgery, regardless of other information. However, the operation is arbitrary and the auxiliary information provided by such a predictor is hard to achieve satisfactory results. Motivated by this, we propose a lightweight forgery detection strategy, where a localization result is directly predicted by a supervised convolutional neural network (CNN). For the first time, CNN is introduced to compute the correlation coefficient in PRNU-based forgery detection. We perform an extensive evaluation in both pixel-level and image-level experiments, and the results show that the proposed method achieves significant performance gains.
Qing Tan, Yushu Zhang 0001, Mingfu Xue
MMSP4
2022 Active intellectual property protection for deep neural networks through stealthy backdoor and users' identities authentication
Mingfu Xue, Shichang Sun, Yushu Zhang 0001, Jian Wang 0038, Weiqiang Liu 0001
Appl. Intell.1
2022 PTB: Robust physical backdoor attacks against deep neural networks in real world
Mingfu Xue, Can He, Yinghao Wu, Shichang Sun, Yushu Zhang 0001, Jian Wang 0038, Weiqiang Liu 0001
Comput. Secur.1
2022 One-to-N & N-to-One: Two Advanced Backdoor Attacks Against Deep Learning Models
abstract
In recent years, deep learning models have been widely deployed in various application scenarios. The training processes of deep neural network (DNN) models are time-consuming, and require massive training data and large hardware overhead. These issues have led to the outsourced training procedure, pre-trained models supplied from third parties, or massive training data from untrusted users. However, a few recent researches indicate that, by injecting some well-designed backdoor instances into the training set, the attackers can create a concealed backdoor in the DNN model. In this way, the attacked model still works normally on the benign inputs, but when a backdoor instance is submitted, some specific abnormal behaviors will be triggered. Existing studies all focus on attacking a single target that triggered by a single backdoor (referred to as One-to-One attack), while the backdoor attacks against multiple target classes, and backdoor attacks triggered by multiple backdoors have not been studied yet. In this article, for the first time, we propose two advanced backdoor attacks, the multi-target backdoor attacks and multi-trigger backdoor attacks: 1) One-to-N attack, where the attacker can trigger multiple backdoor targets by controlling the different intensities of the same backdoor; 2) N-to-One attack, where such attack is triggered only when all the$N$backdoors are satisfied. Compared with existing One-to-One attacks, the proposed two backdoor attacks are more flexible, more powerful and more difficult to be detected. Besides, the proposed backdoor attacks can be applied under the weak attack model, where the attacker has no knowledge about the parameters and architectures of the DNN models. Experimental results show that these two attacks can achieve better or similar performances when injecting a much smaller proportion or same proportion of backdoor instances than those existing One-to-One backdoor attacks. The two attack methods can achieve high attack success rates (up to 100 percent in MNIST dataset and 92.22 percent in CIFAR-10 dataset), while the test accuracy of the DNN model has hardly dropped (as low as 0 percent in LeNet-5 model and 0.76 percent in VGG-16 model), thus will not raise administrator’s suspicions. Further, the two attacks are also evaluated on a large and realistic dataset (Youtube Aligned Face dataset), where the maximum attack success rate reaches 90 percent (One-to-N) and 94 percent (N-to-One), and the accuracy degradation of target face recognition model (VGGFace model) is only 0.05 percent. The proposed One-to-N and N-to-One attacks are demonstrated to be effective and stealthy against two state-of-the-art defense methods.
Mingfu Xue, Can He, Jian Wang 0038, Weiqiang Liu 0001
IEEE Trans. Dependable Secur. Comput.1
2021 DNN Intellectual Property Protection: Taxonomy, Attacks and Evaluations (Invited Paper)
abstract
Since the training of deep neural networks (DNN) models requires massive training data, time and expensive hardware resources, the trained DNN model is oftentimes regarded as an intellectual property (IP). Recent researches show that DNN is vulnerable to illegal copy, redistribution and abuse. In order to protect DNN from infringement, a number of DNN IP protection solutions have been proposed in recent years. This paper presents a survey on DNN IP protection methods. First, we propose the first taxonomy for DNN IP protection methods in terms of six attributes: scenario, mechanism, capacity, type, function, and target models. Then, we summarize the existing DNN IP protection works with a focus on the challenges they face as well as their ability to provide proactive protection and resist different levels of attacks. After that, the potential attacks on existing methods from the aspects of model modifications, evasion attacks, and active attacks are analyzed, and a systematic evaluation method for DNN IP protection methods with respect to basic functional metrics, attack-resistance metrics, and customized metrics for different application scenarios is given. Finally, future research opportunities and challenges on DNN IP protection are prospected.
Mingfu Xue, Jian Wang 0038, Weiqiang Liu 0001
ACM Great Lakes Symposium on VLSI1
2021 Detect and Remove Watermark in Deep Neural Networks via Generative Adversarial Networks
Shichang Sun, Mingfu Xue, Yushu Zhang 0001, Jian Wang 0038, Weiqiang Liu 0001
ISC3
2021 Robust Backdoor Attacks against Deep Neural Networks in Real Physical World
abstract
Deep neural networks (DNN) have been widely deployed in various applications. However, many researches indicated that DNN is vulnerable to backdoor attacks. The attacker can create a hidden backdoor in target DNN model, and trigger the malicious behaviors by submitting specific backdoor instance. However, almost all the existing backdoor works focused on the digital domain, while few studies investigate the backdoor attacks in real physical world. Restricted to a variety of physical constraints, the performance of backdoor attacks in the real physical world will be severely degraded. In this paper, we propose a robust physical backdoor attack method, PTB (physical transformations for backdoors), to implement the backdoor attacks against deep learning models in the real physical world. Specifically, in the training phase, we perform a series of physical transformations on these injected backdoor instances at each round of model training, so as to simulate various transformations that a backdoor may experience in real world, thus improves its physical robustness. Experimental results on the state-of-the-art face recognition model show that, compared with the backdoor methods that without PTB, the proposed attack method can significantly improve the performance of backdoor attacks in real physical world. Under various complex physical conditions, by injecting only a very small ratio (0.5 %) of backdoor instances, the attack success rate of physical backdoor attacks with the PTB method on VGGFace is 82%, while the attack success rate of backdoor attacks without the proposed PTB method is lower than 11%. Meanwhile, the normal performance of the target DNN model has not been affected.
Mingfu Xue, Can He, Shichang Sun, Jian Wang 0038, Weiqiang Liu 0001
TrustCom1
2021 SocialGuard: An adversarial example based privacy-preserving technique for social images
Mingfu Xue, Shichang Sun, Zhiyu Wu, Can He, Jian Wang 0038, Weiqiang Liu 0001
J. Inf. Secur. Appl.1
2021 NaturalAE: Natural and robust physical adversarial examples for object detectors
Mingfu Xue, Chengxiang Yuan, Can He, Jian Wang 0038, Weiqiang Liu 0001
J. Inf. Secur. Appl.1
2021 Backdoors hidden in facial features: a novel invisible backdoor attack against face recognition systems
Mingfu Xue, Can He, Jian Wang 0038, Weiqiang Liu 0001
Peer-to-Peer Netw. Appl.1
2020 Active DNN IP Protection: A Novel User Fingerprint Management and DNN Authorization Control Technique
abstract
The training process of deep learning model is costly. As such, deep learning model can be treated as an intellectual property (IP) of the model creator. However, a pirate can illegally copy, redistribute or abuse the model without permission. In recent years, a few Deep Neural Networks (DNN) IP protection works have been proposed. However, most of existing works passively verify the copyright of the model after the piracy occurs, and lack of user identity management, thus cannot provide commercial copyright management functions. In this paper, a novel user fingerprint management and DNN authorization control technique based on backdoor is proposed to provide active DNN IP protection. The proposed method can not only verify the ownership of the model, but can also authenticate and manage the user's unique identity, so as to provide a commercially applicable DNN IP management mechanism. Experimental results on CIFAR-10, CIFAR-100 and Fashion-MNIST datasets show that the proposed method can achieve high detection rate for user authentication (up to 100% in the three datasets). Illegal users with forged fingerprints cannot pass authentication as the detection rates are all 0 % in the three datasets. Model owner can verify his ownership since he can trigger the backdoor with a high confidence. In addition, the accuracy drops are only 0.52%, 1.61 % and -0.65% on CIFAR-10, CIFAR-100 and Fashion-MNIST, respectively, which indicate that the proposed method will not affect the performance of the DNN models. The proposed method is also robust to model fine-tuning and pruning attacks. The detection rates for owner verification on CIFAR-10, CIFAR-100 and Fashion-MNIST are all 100% after model pruning attack, and are 90 %, 83 % and 93 % respectively after model fine-tuning attack, on the premise that the attacker wants to preserve the accuracy of the model.
Mingfu Xue, Zhiyu Wu, Can He, Jian Wang 0038, Weiqiang Liu 0001
TrustCom1
2020 LOPA: A linear offset based poisoning attack method against adaptive fingerprint authentication system
Mingfu Xue, Can He, Jian Wang 0038, Weiqiang Liu 0001
Comput. Secur.1
2020 DPAEG: A Dependency Parse-Based Adversarial Examples Generation Method for Intelligent Q&A Robots
abstract
Recently, the natural language processing- (NLP-) based intelligent question and answer (Q&A) robots have been used ubiquitously. However, the robustness and security of current Q&A robots are still unsatisfactory, e.g., a slight typo in the user’s question may cause the Q&A robot unable to return the correct answer. In this paper, we propose a fast and automatic test dataset generation method for the robustness and security evaluation of current Q&A robots, which can work in black-box scenarios and thus can be applied to a variety of different Q&A robots. Specifically, we propose a dependency parse-based adversarial examples generation (DPAEG) method for Q&A robots. DPAEG first uses the proposed dependency parse-based keywords extraction algorithm to extract keywords from a question. Then, the proposed algorithm generates adversarial words according to the extracted keywords, which include typos and words that are spelled similarly to the keywords. Finally, these adversarial words are used to generate a large number of adversarial questions. The generated adversarial questions which are similar to the original questions do not affect human’s understanding, but the Q&A robots cannot answer these adversarial questions correctly. Moreover, the proposed method works in a black-box scenario, which means it does not need the knowledge of the target Q&A robots. Experiment results show that the generated adversarial examples have a high success rate on two state-of-the-art Q&A robots, DrQA and Google Assistant. In addition, the generated adversarial examples not only affect the correct answer (top-1) returned by DrQA but also affect the top-k candidate answers returned by DrQA. The adversarial examples make the top-k candidate answers contain fewer correct answers and make the correct answers rank lower in the top-k candidate answers. The human evaluation results show that participants with different genders, ages, and mother tongues can understand the meaning of most of the generated adversarial examples, which means that the generated adversarial examples do not affect human’s understanding.
Mingfu Xue, Chengxiang Yuan, Jian Wang 0038, Weiqiang Liu 0001
Secur. Commun. Networks1
2019 SSL: A Novel Image Hashing Technique Using SIFT Keypoints with Saliency Detection and LBP Feature Extraction against Combinatorial Manipulations
abstract
Image hashing schemes have been widely used in content authentication, image retrieval, and digital forensic. In this paper, a novel image hashing algorithm (SSL) by incorporating the most stable keypoints and local region features is proposed, which is robust against various content-preserving manipulations, even multiple combinatorial manipulations. The proposed algorithm combines S_ cale invariant feature transform (SIFT) with S_ aliency detection to extract the most stable keypoints. Then, the L_ ocal binary pattern (LBP) feature extraction method is exploited to generate local region features based on these keypoints. After that, the information of keypoints and local region features are merged into a hash vector. Finally, a secret key is used to randomize the hash vector, which can prevent attackers from forging the image and the hash value. Experimental results demonstrate that the proposed hashing algorithm can identify visually similar images which are under both single and combinatorial content-preserving manipulations, even multiple combinations of manipulations. It can also identify maliciously forged images which are under various content-changing manipulations. The collision probability between hashes of different images is nearly zero. Besides, the evaluation of key-dependent security shows that the proposed scheme is secure that an attacker cannot forge or estimate the correct hash value without the knowledge of the secret key.
Mingfu Xue, Chengxiang Yuan, Zhe Liu 0001, Jian Wang 0038
Secur. Commun. Networks1
2013 Monte Carlo Based Test Pattern Generation for Hardware Trojan Detection
abstract
Hardware Trojan (HT) has emerged as a serious security threat to many critical systems. HT detection techniques are badly needed to ensure trust in hardware systems. In related works, only a fixed large number of random patterns are applied, with no regard to the pattern's effect to HT detection result. The variations in target signal caused by different sets of input vectors are not addressed. There is also no guarantee that the vector set used is long enough to be representative or whether it is already over testing. To solve these problems, we propose a Monte Carlo based test pattern generation method for HT detection. The proposed approach offers a solution by sampling the detection until the standard deviation of the measured signal over all the samples is within certain accuracy. This gives us the confidence in the signal measurement without having to do exhaustive test. Moreover, it is conducive to simplify test vector sets. Experiment results on ISCAS89 benchmarks showed that the proposed approach usually needs much less time than that required by exhaustive test to achieve reliable results and desired accuracy.
Mingfu Xue, Aiqun Hu, Guyue Li
DASC1