VLDB 2026 Research / reviewers in the wild / expert
Tingting Li 0004
dblp:05/2053-4
· DBLP profile ↗
30ranked-venue papers
11as first author
30since 2021 · last 2026
0000-0002-6589-3706ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Databases, data management, data science and information retrieval · 7 · 1 first-author · 7 since 2021Artificial intelligence and machine learning · 6 · 2 first-author · 6 since 2021Systems, architecture and hardware · 6 · 2 first-author · 6 since 2021Computer networks · 5 · 2 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 3 first-author · 5 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Software engineering, systems software and programming languages · 4 · 3 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adaptive Fidelity Estimation for Quantum Programs with Graph-Guided Noise AwarenessabstractFidelity estimation is a critical yet resource-intensive step in testing quantum programs on noisy intermediate-scale quantum (NISQ) devices, where the required number of measurements is difficult to predefine due to hardware noise, device heterogeneity, and transpilation-induced circuit transformations. We present QuFid, an adaptive and noise-aware framework that determines measurement budgets online by leveraging circuit structure and runtime statistical feedback. QuFid models a quantum program as a directed acyclic graph (DAG) and employs a control-flow-aware random walk to characterize noise propagation along gate dependencies. Backend-specific effects are captured via transpilation-induced structural deformation metrics, which are integrated into the random-walk formulation to induce a noise-propagation operator. Circuit complexity is then quantified through the spectral characteristics of this operator, providing a principled and lightweight basis for adaptive measurement planning. Experiments on 18 quantum benchmarks executed on IBM Quantum backends show that QuFid significantly reduces measurement cost compared to fixed-shot and learning-based baselines, while consistently maintaining acceptable fidelity bias. Tingting Li 0004, Ziming Zhao 0008, Jianwei Yin |
AAAI | 1 |
| 2026 | Relational Verification for Cost-Aware Quantum Program OptimizationabstractOptimizing quantum programs is key to mitigating noise, reducing error-correction overhead, and improving performance on both near-term and fault-tolerant devices. Existing heuristic and learning-based optimizers, however, lack formal guarantees and risk semantic errors in the presence of entanglement and measurement. We present RelOpt, a semantics-preserving optimizer that enforces relational correctness between original and optimized programs. RelOpt is built on a lightweight intermediate language (QCore) with a relational operational semantics supporting partial-trace equivalence, measurement-distribution preservation, and approximate correctness. Optimization is guided by a multi-objective cost model that considers gate count, circuit depth, and error-correction cost. Only rewrite rules that are formally verified against user-specified contracts are applied. The engine combines symbolic simulation, SMT reasoning, and cost analysis to achieve safe and effective optimizations. On standard benchmarks such as QFT, Grover, and QAOA, RelOpt consistently outperforms Qiskit, t|ket>, and learning-based optimizers across multiple cost metrics while maintaining formal guarantees. By integrating formal verification with cost-aware compilation, RelOpt establishes a foundation for trustworthy and hardware-adaptive quantum toolchains. Ziming Zhao 0008, Tingting Li 0004, Zhaoxuan Li, Jianwei Yin |
AAAI | 2 |
| 2026 | VQFlow: A Benchmark Dataset for Encrypted Video Streaming Traffic across QoS Configurations
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010 |
KDD (1) | 3 |
| 2026 | QuaMap: A Multi-Backend Benchmark Dataset for Quantum Circuit Mapping and Learning-Based Compiler Evaluation
Ziming Zhao 0008, Tingting Li 0004, Jianwei Yin |
KDD (1) | 2 |
| 2026 | Fair and Carbon-Aware LLM Routing for Web Services
Tingting Li 0004, Ziming Zhao 0008, Zhaoxuan Li, Xiaofei Yue, Jiongchi Yu |
WWW | 1 |
| 2026 | HeteroSim: Towards High-Fidelity Heterogeneous LLM Training Simulation on GPUs
Xiaofei Yue, Fangming Zhao, Fulun Ye, Jiongchi Yu, Zhaoxuan Li, Tingting Li 0004, Ziming Zhao 0008, Jianwei Yin |
WWW | 6 |
| 2026 | Portray learning: A novel learning paradigm for streaming emerging class detection
Ziming Zhao 0008, Zhaoxuan Li, Xiaofei Yue, Tingting Li 0004, Fan Zhang 0010 |
Inf. Sci. | 4 |
| 2026 | Assessing and Improving DNN Robustness Against Adversarial Examples From the Perspective of Fully Connected LayersabstractRecent studies show that deep neural networks are extremely vulnerable, especially for adversarial examples of image classification models. However, existing defenses suffer from limited adaptability across attacks, an unfavorable tradeoff between clean accuracy and robustness, and substantial training-time overhead. To tackle these problems, we present a novel component, named the redundant fully connected layer, which can be combined with existing model backbones in a pluggable manner. Specifically, we design a tailor-made loss function for it that leverages cosine similarity to maximize the difference and diversity of multiple fully connected parts. We conduct extensive experiments against 12 representative attacks (white-box and black-box), based on two popular datasets. The empirical evaluations show that our scheme realizes significant outcomes against various attacks with negligible additional training overhead, while hardly bringing collateral damage for clean-instance accuracy. Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | TNT: A Large-Scale P2P Botnet Detection Framework via Communication Topology and Network TrafficabstractWith the booming development of embedded systems and mobile networks, the attack surfaces of botnets are broadened and amplified. Especially recent adversaries tend to leverage peer-to-peer (P2P) manner propagation to construct large-scale botnets because P2P-based schemes eliminate single points of failure. Over the past few decades, the research and industry communities have proposed a variety of solutions to detect botnets, which mainly involve communication topology identification and network traffic analysis. Yet, coping with the large-scale P2P botnets, the former suffer topology indistinguishability, and the latter struggles under massive background traffic. In this paper, we present$\textsf {TNT}$, a large-scale P2P botnet detection framework via communication topology and network traffic. As its core,$\textsf {TNT}$is powered by three tightly-coupled components:$\textsf {(i)}$$\textsf {tScouter}$is responsible for profiling the communication topology;$\textsf {(ii)}$$\textsf {tCommander}$plans the strategy for node inspection; and$\textsf {(iii)}$$\textsf {tPatroller}$investigates the traffic of the corresponding node. Taken together,$\textsf {TNT}$advances the trade-off between detection accuracy (enhance topology-based results via traffic analysis) and overhead (only check part of node traffic according to the planning). Based on 42 groups of combinations involving 6 types of botnets and 7 legitimate P2P traffic, we perform extensive evaluation and demonstrate that$\textsf {TNT}$realizes outstanding detection performance,e.g.,after checking ~20K nodes, achieve ~99.9% accuracy for a communication graph (including >140K nodes). In addition, we develop the expansion experiments in terms of heterogeneous nodes and accuracy loss, as well as provide deep insights into interpretability from the aspect of the attribution matrix. Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Yu Li 0007, Qiang Xu 0001, Fan Zhang 0010 |
IEEE Trans. Netw. | 3 |
| 2025 | CyberLLM: Enable Mapping CVE to Tactics and Techniques of Cyber Threats via LLM
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010 |
DASFAA (5) | 3 |
| 2025 | Empowering Quantum Error Traceability with MoE for Automatic CalibrationabstractQuantum computing offers the potential for exponential speedups over classical computing in tackling complex tasks, such as large-number factorization and chemical molecular simulation. However, quantum noise remains a significant challenge, hindering the reliability and scalability of quantum systems. Therefore, effective characterization and calibration of quantum noise are critical to advancing these systems. Quantum calibration is a process that heavily relies on expert knowledge, and there currently is a range of research focused on automatic calibration. However, traditional calibration methods often need an effective error traceback mechanism, leading to repeated calibration attempts without identifying root causes. To address the issue of error traceback in calibration failures, this paper proposes an automatic calibration error traceback algorithm facilitated by a Mixture of Experts (MoE) system inspired by the current large language model technologies. Our approach enables traceability of quantum calibration errors, allowing for the rapid identification and correction of deviations from the calibration state. Extensive experimental results demonstrate that the MoE-based automatic calibration method significantly outperforms traditional error traceability and calibration efficiency techniques. Notably, our approach improved the average visibility of 77 qubits by 25.5%, surpassing the outcomes of fixed calibration processes. This work presents a promising path toward more reliable and scalable quantum computing systems. Tingting Li 0004, Ziming Zhao 0008, Liqiang Lu, Siwei Tan, Jianwei Yin |
DATE | 1 |
| 2025 | Empowering Quantum Serverless Circuit Deployment Optimization via Graph Contrastive Learning and Learning-to-Rank Co-designed ApproachesabstractWith the rapid advancements in quantum computing, cloud-based quantum services have gained increasing prominence. However, due to quantum noise, optimizing the deployment of quantum circuits remains an NP-hard problem with an expansive search space. Existing methods usually use heuristic algorithms to approximate the solution, such as the representative IBM Qiskit. On the one hand, they often find suboptimal deployment solutions. On the other hand, prior technologies do not consider user-specific requirements and can only provide a single deployment strategy. In this paper, we propose QCDeploy that can provide a ranked list of effective deployment strategies to optimize quantum serverless circuit deployment. Specifically, we model quantum circuits as Directed Acyclic Graph (DAG) representations and utilize graph contrastive learning for vector embedding. Then, a tailored list-aware learning-to-rank architecture is employed to generate a list of candidate strategies (prioritizing better strategies). We conduct extensive evaluations involving 45 prevalent quantum algorithm circuits across 3~5 qubits, utilizing 3 IBM quantum physical devices with three types of chip topologies. The results demonstrate that our proposed framework significantly outperforms IBMQ's default deployment scheme, e.g., achieving 17.95% overhead reduction and increasing the execution success rate by 20%~40%. Tingting Li 0004, Ziming Zhao 0008, Jianwei Yin |
IJCAI | 1 |
| 2025 | Fortuna: Towards Efficient Selection of High-Fidelity Link for Quantum Network in the Wild
Tingting Li 0004, Ziming Zhao 0008, Jianwei Yin |
INFOCOM | 1 |
| 2025 | ARTERY: Fast Quantum Feedback using Branch PredictionabstractQuantum feedback makes the execution of dynamic quantum circuits possible and is widely used in quantum algorithms.However, due to the inherent computation and transmission cost, the latency of the quantum feedback becomes a considerable burden on the current quantum algorithm.The dynamic property of the feedback also makes the gates blocked until the feedback is finished.In this paper, we propose ARTERY, which uses branch prediction to support instruction pre-execution and speed up the feedback.ARTERY integrates historical statistics of branches and a real-time readout pulse analysis to predict the branch.With this idea, we build up a reconciled branch predictor that concatenates the historical statistics of branches and a real-time branch circuit speculation obtained from the readout-pulse trajectory predictor.We further explore the implementation of peripheral hardware for feedback, including a scalable inter-FPGA connection via the backplane, a feedback trigger mechanism for dynamic instruction timing, and an adaptive pulse sampling technique to maximize the hardware bandwidth.ARTERY accelerates quantum feedback process by 2.07× compared to the state-of-the-art method, with over 90% prediction accuracy, achieving 1.24× fidelity improvement. Wuwei Tian, Liqiang Lu, Siwei Tan, Yun Liang 0001, Tingting Li 0004, Kaiwen Zhou 0003, Xinghui Jia, Jianwei Yin |
ISCA | 5 |
| 2025 | AutoFid: Adaptive and Noise-Aware Fidelity Measurement for Quantum Programs via Circuit Graph AnalysisabstractQuantum computers in the Noisy Intermediate-Scale Quantum (NISQ) era face significant challenges due to inherent noise and limited qubit coherence. Accurate fidelity evaluation of quantum states necessitates multiple repeated measurements to obtain statistical results. But determining the optimal number of measurements remains an open problem due to the dynamic, device-dependent nature of quantum noise. Existing methods either assume prior knowledge of the noise model or inherently employ a fixed measurement strategy, which limits their applicability in practical deployment scenarios. This paper presents AutoFid, an adaptive and noise-aware fidelity measurement framework that automatically determines the number of required tests based on circuit structure and hardware feedback. AutoFid models quantum circuits as Directed Acyclic Graphs and estimates structural complexity via random walks, enabling estimation of measurement effort. It further incorporates transpilation-aware features such as gate fidelity, depth inflation, and crosstalk to refine iteration budgets. During runtime, AutoFid dynamically samples fidelity results and employs an early stopping strategy based on confidence intervals to reduce redundant measurements while preserving accuracy guarantees. We evaluate AutoFid on 18 quantum benchmarks executed on real IBMQ hardware platforms. Experimental results show that AutoFid reduces measurement costs by more than 50% compared to both fixed-shot and learning-based baselines, while consistently maintaining fidelity bias below 0.01. Additional analysis using classical software testing metrics and ablation studies demonstrate its effectiveness, robustness, and adaptability across a wide range of quantum workloads. Tingting Li 0004, Ziming Zhao 0008, Jianwei Yin |
ASE | 1 |
| 2025 | Towards Context-Aware Traffic Classification via Time-Wavelet Fusion Network
Ziming Zhao 0008, Zhuoxue Song, Xiaofei Xie, Zhaoxuan Li, Jiongchi Yu, Fan Zhang 0010, Tingting Li 0004 |
KDD (1) | 7 |
| 2025 | Stealthy-AE: Generating Stealthy Adversarial Examples through Online Social Networks
Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010 |
ACM Multimedia | 3 |
| 2025 | Verify All Traffic: Towards Zero-Trust In-Network Intrusion Detection Against Multipath RoutingabstractWith the popularity of encryption protocols, machine learning (ML)-based traffic analysis technologies have attracted widespread attention. To adapt to modern high-speed bandwidth, recent research is dedicated to advancing zero-trust intrusion detection by offloading feature extraction and model inference into the network dataplane. Especially, with the rise of programmable switches, achieving line-speed ML inference becomes promising. However, existing research only considers a single switch node as a relay to conduct evaluation. This is far from real-world deployments involving multiple switches (given that zero-trust security assumes that threats can originate from anywhere, including within the network), particularly the multi-path routing phenomenon that exists in practice. In this paper, we reveal practical challenges in the context of enabling line-speed model inference in the network dataplane. Furthermore, we propose FCPlane, the forwarding and computing integrated dataplane for zero-trust intrusion detection that aims to enable efficient load balancing while providing reliable traffic analysis results, even against multipath routing. The core idea is to reconcile forwarding and computation to the flowlet level, for which a tailor-made Markov chain model is designed. Based on two public traffic datasets, we evaluate seven state-of-the-art in-network traffic analysis models deployed in four types of topologies (three with multipath routing and one without) to explore performance impact and demonstrate the effectiveness of our proposal. Ziming Zhao 0008, Zhaoxuan Li, Xiaofei Xie, Tingting Li 0004, Jiongchi Yu, Fan Zhang 0010, Binbin Chen 0001 |
IEEE J. Sel. Areas Commun. | 5 |
| 2025 | QuST: Optimizing Quantum Neural Network Against Spatial and Temporal Noise BiasesabstractQuantum neural networks (QNNs) hold immense potential for complex tasks by harnessing quantum entanglement and superposition, such as physics simulation, artificial intelligence, and cryptography. However, the presence of quantum noise, stemming from hardware imperfections and environmental interactions, significantly reduces their practical performance. Moreover, the noise varies from different devices and shifts over time, necessitating continuous retraining models to chase and cater to the evolving noise, leading to high-computation costs. In this article, we presentQuST, a novel QNN robust training framework designed to handle the noise in a once-and-for-all manner, which can tackle both spatial and temporal biases to maintain the QNN model accuracy under ever-changing noise conditions. Our approach consists of three key components. First, we propose a metric called circuit sequence correctness (CSC) to characterize QNN circuit reliability in noisy environments. Then, we model CSC as a training weight to incorporate loss integration and utilize KL divergence to align noise inference with noise-free inference, thereby improving anti-noise capabilities. Furthermore, we introduce multiscale noise-aware training to enhance the model’s noise tolerance at various noise magnitudes. We conduct experiments on MNIST and fashion-MNIST datasets, along with 190-day historical noise simulations and one case study on 7 real IBMQ quantum computers. The results demonstrate 8.1%–15.1% and 9.1%–11.45% accuracy improvements in temporal and spatial dimensions, respectively. Additionally, we conduct ablation experiments to validate the effectiveness of theQuST’s key components. The results demonstrate thatQuSTconsistently sustains high accuracy without retraining,even under changing noise conditions, and exhibits minimal loss of accuracy as noise levels increase. Tingting Li 0004, Liqiang Lu, Ziming Zhao 0008, Siwei Tan, Jianwei Yin |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 1 |
| 2025 | Task-Driven Device Fingerprinting for Quantum Cloud Platforms via Modeling QNN Outcomes Under NoiseabstractQuantum Computing (QC) has recently achieved significant technological progress, attracting growing interest from both academia and industry. As most users currently access QC resources through cloud platforms, concerns around the security and accountability of quantum services have become increasingly prominent. In particular, quantum noise, typically considered a source of error, can also reveal device-specific signatures that enable Quantum Device Fingerprinting (QDF). While QDF has legitimate applications such as anomaly detection and device accountability, it also carries dual-use risks, including potential misuse for unauthorized device tracking or targeted attacks. In this paper, we propose a novel Task-Driven Quantum Device Fingerprinting (TD-QDF) identification method based on quantum task outputs; we extract the fingerprint features of quantum devices from noisy quantum computing results. Unlike previous research, our method does not require any additional information (e.g., hardware details or noise information), thereby enhancing its practical applicability and accessibility. We conducted large-scale experiments using six QNN circuits on 10 IBM quantum computers, extended four classical quantum algorithms to validate generality, and demonstrated scalability on three 127-qubit processors. Specifically, the highest accuracy can reach up to 94.32% in the 3-classification device fingerprint recognition task and up to 82.4% and 61.6% in the 7-classification and 10-classification tasks, respectively. This research contributes to advancing quantum fingerprinting technologies and holds promising implications for enhancing the security and accountability of quantum computing systems and quantum cloud services. Tingting Li 0004, Ziming Zhao 0008, Jianwei Yin |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Moirai: Optimizing Quantum Serverless Function Orchestration via Device Allocation and Circuit DeploymentabstractIn the rapidly evolving field of quantum computing, the emergence of cloud-based quantum services has opened up access to this cutting-edge technology for a broader user base. As demand for these services grows, the efficient and timely delivery of quantum computing capabilities becomes increasingly critical. However, current queuing methods for executing quantum tasks on specific machines often lead to inefficient resource usage and longer waiting times. In this paper, we present Moirai, a quantum serverless function orchestration framework to reduce the maximum completion time and improve device utilization. Leveraging the unique properties of quantum circuits, Moirai introduces a customized circuit representation scheme, incorporating Directed Acyclic Graph (DAG) conversion and Graph Convolutional Network (GCN) embedding vector feature extraction. Central to Moirai is the use of reinforcement learning, which drives a suite of decision pipelines for device allocation and circuit deployment strategy. We conduct extensive evaluations involving 95 prevalent quantum algorithm circuits across 3∼7 qubits, utilizing 10 IBM quantum physical devices with three types of chip topologies. The results demonstrate that our proposed framework significantly enhances resource allocation efficiency and overall performance, achieving a noteworthy reduction in execution time of over 30% compared to baseline methods. This underscores the effect of Moirai as a practical solution for optimizing quantum cloud services and unlocking the potential of quantum computing technology. Tingting Li 0004, Ziming Zhao 0008 |
ICWS | 1 |
| 2024 | Minerva: Enhancing Quantum Network Performance for High-Fidelity Multimedia Transmission
Tingting Li 0004, Ziming Zhao 0008, Jianwei Yin |
ACM Multimedia | 1 |
| 2024 | QLSel: Demonstrating Efficient High-Fidelity Link Selection for Quantum Networks in the WildabstractAs an emerging technology, quantum networks have the potential to revolutionize secure communication and data transmission technologies. In the Noisy Intermediate-Scale Quantum (NISQ) era, quantum noise causing low fidelity remains challenging in quantum networks. In this paper, we propose QLSel, an efficient selection algorithm for the high-fidelity link in the wild without assumptions about the fidelity distribution. We design the tailored link exploration strategy and link selection probability based on the coefficient of variation and Thompson sampling, to cope with the exploration-exploitation trade-off dilemma in the Multi-Armed Bandit (MAB) problem (for problem modeling). Extensive experiments demonstrate that QLSel significantly outperforms existing representative methods. Our codes and video are available at https://github.com/Secbrain/QLSel. Tingting Li 0004, Ziming Zhao 0008, Jianwei Yin |
MobiCom | 1 |
| 2024 | Work-in-Progress: Analyzing Worst-Case DDoS Traffic Scrub Effect and Recovery Delay via Attack Vector CombinationabstractDistributed Denial of Service (DDoS) continues to be a prevalent attack on Internet today, and DDoS mitigation has garnered significant attention from the academic and industrial communities. However, strong attackers could combine attack vectors and launch DDoS to allow as many attack packets as possible to pass through the filter. In this paper, we reveal this problem and model the attack vector combination as a combinatorial optimization problem solution, aiming to provide deep insights into the worst-case traffic scrub effect. Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004 |
RTSS | 3 |
| 2024 | A Large-Scale P2P Botnet Detection Framework via Topology and Traffic Co-VerificationabstractBotnets are still serious threats to infrastructure security nowadays. Recently, adversaries tend to leverage peer-to-peer (P2P) manner propagation to construct large-scale botnets since P2P-based schemes have no single points of failure. Over the past few decades, the research and industry communities have proposed a variety of solutions to detect botnets, which mainly involve communication topology identification and network traffic analysis. Yet, coping with the large-scale P2P botnets, the former suffer topology indistinguishability, and the latter struggles under massive background traffic. In this paper, we present TNT, a large-scale P2P botnet detection framework via communication topology and network traffic. As its core, TNT is powered by three tightly-coupled components: (i) tScouter is responsible for profiling the communication topology; (ii) tCommander plans the strategy for node inspection; and (iii) tPatroller investigates the traffic of the corresponding node. Taken together, TNT advances the trade-off between detection accuracy (enhance topology-based results via traffic analysis) and overhead (only check part of node traffic according to the planning). Based on 42 groups of combinations involving 6 types of botnets and 7 legitimate P2P traffic, we perform extensive evaluation and demonstrate that TNT realizes outstanding detection performance, e.g., after checking ~20K nodes, achieve ~99.9% accuracy for a communication graph (including >140K nodes). Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010 |
SECON | 3 |
| 2024 | TPE-Det: A Tamper-Proof External Detector via Hardware Traces Analysis Against IoT MalwareabstractWith the widespread use of Internet of Things (IoT) devices, malware detection has become a hot spot for both academic and industrial communities. A series of solutions based on system calls, system logs, or hardware performance counters achieve promising results. However, such internal monitors are easily tampered with, especially against adaptive adversaries. In addition, existing system log records typically exhibit substantial volume, resulting in data explosion problems. In this article, we present TPE-Det, a side-channel-based external monitor to cope with these issues. Specifically, TPE-Det leverages the serial peripheral interface bus to extract the on-chip traces and designs a recovery pipeline for operating logs. The advantages of this external monitor are adversary-unperceived and tamper-proof. The restored logs mainly include file operation commands, which are lightweight compared to complete records. Meanwhile, we deploy a series of machine learning models with respect to statistical, sequence, and graph features to identify malware. Empirical evaluation shows that our proposal has tamper-proof capability, high-detection accuracy, and low-time/space overhead compared to state-of-the-art methods. Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Fan Zhang 0010 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2023 | Poster: Detecting Adversarial Examples Hidden under Watermark Perturbation via Usable Information TheoryabstractImage watermark is a technique widely used for copyright protection. Recent studies show that the image watermark can be added to the clear image as a kind of noise to realize fooling deep learning models. However, previous adversarial example (AE) detection schemes tend to be ineffective since the watermark logo differs from typical noise perturbations. In this poster, we propose Themis, a novel AE detection method against watermark perturbation. Different from prior methods, Themis neither modifies the protected classifier nor requires knowledge of the process for generating AEs. Specifically, Themis leverages usable information theory to calculate the pointwise score, thereby discovering those instances that may be watermark AEs. The empirical evaluations involving 5 different logo watermark perturbations demonstrate the proposed scheme can efficiently detect AEs, and significantly (over 15% accuracy) outperforms five state-of-the-art (SOTA) detection methods. The visualization results display our detection metric is more distinguishable between AEs and non-AEs. Meanwhile, Themis realizes a larger Area Under Curve (AUC) in a threshold-resilient manner, while only introducing ∼0.04s overhead. Ziming Zhao 0008, Zhaoxuan Li, Tingting Li 0004, Zhuoxue Song, Fan Zhang 0010, Rui Zhang 0016 |
CCS | 3 |
| 2023 | HyQSAT: A Hybrid Approach for 3-SAT Problems by Integrating Quantum Annealer with CDCLabstractPropositional satisfiability problem (SAT) is represented in a conjunctive normal form with multiple clauses, which is an important non-deterministic polynomial-time (NP) complete problem that plays a major role in various applications including artificial intelligence, graph colouring, and circuit analysis. Quantum annealing (QA) is a promising methodology for solving complex SAT problems by exploiting the parallelism of quantum entanglement, where the SAT variables are embedded to the qubits. However, the long embedding time fundamentally limits existing QA-based methods, leading to inefficient hardware implementation and poor scalability.In this paper, we propose HyQSAT, a hybrid approach that integrates QA with the classical Conflict-Driven Clause Learning (CDCL) algorithm to enable end-to-end acceleration for solving SAT problems. Instead of embedding all clauses to QA hardware, we quantitatively estimate the conflict frequency of clauses and apply breadth-first traversal to choose their embedding order. We also consider the hardware topology to maximize the utilization of physical qubits in embedding to QA hardware. Besides, we adjust the embedding coefficients to improve the computation accuracy under qubit noise. Finally, we present how to interpret the satisfaction probability based on QA energy distribution and use this information to guide the CDCL search. Our experiments demonstrate that HyQSAT can effectively support larger-scale SAT problems that are beyond the capability of existing QA approaches, achieve up to 12.62X end-to-end speedup using D-Wave 2000Q compared to the classic CDCL algorithm on Intel E5 CPU, and considerably reduce the QA embedding time from 17.2s to 15.7µs compared to the D-Wave Minorminer algorithm [11]. Siwei Tan, Mingqian Yu, Andre Python, Yongheng Shang, Tingting Li 0004, Liqiang Lu, Jianwei Yin |
HPCA | 5 |
| 2023 | QuCT: A Framework for Analyzing Quantum Circuit by Extracting Contextual and Topological FeaturesabstractIn the current Noisy Intermediate-Scale Quantum era, quantum circuit analysis is an essential technique for designing high-performance quantum programs. Current analysis methods exhibit either accuracy limitations or high computational complexity for obtaining precise results. To reduce this tradeoff, we propose QuCT, a unified framework for extracting, analyzing, and optimizing quantum circuits. The main innovation of QuCT is to vectorize each gate with each element, quantitatively describing the degree of the interaction with neighboring gates. Extending from the vectorization model, we propose two representative downstream models for fidelity prediction and unitary decomposition. The fidelity prediction model performs a linear transformation on all gate vectors and aggregates the results to estimate the overall circuit fidelity. By identifying critical weights in the transformation matrix, we propose two optimizations to improve the circuit fidelity. In the unitary decomposition model, we significantly reduce the search space by bridging the gap between unitary and circuit via gate vectors. Experiments show that QuCT improves the accuracy of fidelity prediction by 4.2 × on 5-qubit and 18-qubit quantum devices and achieves 2.5 × fidelity improvement compared to existing quantum compilers [19, 55]. In unitary decomposition, QuCT achieves 46.3 × speedup for 5-qubit unitary and more than hundreds of speedup for 8-qubit unitary, compared to the state-of-the-art method [87]. Siwei Tan, Congliang Lang, Shudi Wang, Xinghui Jia, Tingting Li 0004, Jieming Yin, Yongheng Shang, Andre Python, Liqiang Lu, Jianwei Yin |
MICRO | 7 |
| 2023 | SAGE: Steering the Adversarial Generation of Examples With AccelerationsabstractTo generate image adversarial examples, state-of-the-art black-box attacks usually require thousands of queries. However, massive queries will introduce additional costs and exposure risks in the real world. Towards improving the attack efficiency, we carefully design an acceleration framework SAGE for existing black-box methods, which is composed of sLocator (initial point optimization) and sRudder (search process optimization). The core idea of SAGE in terms of 1) saliency map can guide the perturbations towards the most adversarial direction and 2) exploiting bounding box (bbox) to capture those salient pixels in the black-box attack. Meanwhile, we provide a series of observations and experiments that demonstrate bbox holds model invariance and process invariance. We extensively evaluate SAGE on four state-of-the-art black-box attacks involving three popular datasets (MNIST, CIFAR10, and ImageNet). The results show that SAGE could present fundamental improvements even against robust models that use adversarial training. Specifically, SAGE could reduce >20% of queries and improve the success rate of attacks to 95%~100%. Compared with the other acceleration framework, SAGE fulfills the more significant effect in a flexible, stable, and low-overhead manner. Moreover, our practical evaluation (Google Cloud Vision API) shows SAGE can be applied to real-world scenarios. Ziming Zhao 0008, Zhaoxuan Li, Fan Zhang 0010, Tingting Li 0004, Rui Zhang 0016, Kui Ren 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |