Endong Tong

dblp:117/2573 · DBLP profile ↗
← Back
27ranked-venue papers
5as first author
13since 2021 · last 2026
0000-0003-0348-2108ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 8 · 2 first-author · 6 since 2021Security and privacy · 6 · 3 since 2021Databases, data management, data science and information retrieval · 5 · 4 since 2021Computer networks · 4 · 1 first-authorSystems, architecture and hardware · 3 · 1 since 2021Software engineering, systems software and programming languages · 3 · 2 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Theory of computation · 1
YearPublicationVenuePosition
2026 FRBAT: Conditionally-Visible Physical Backdoor Attack via Fluorescence
abstract
Deep neural networks are increasingly vulnerable to physically deployable backdoor attacks, which manipulate real-world objects to induce targeted model failures. However, current physical backdoor attacks predominantly rely on perpetually visible triggers appended to target objects. These methods inevitably expose attack traces during the deployment phase, risking human suspicion prior to activation. In this paper, we propose a conditionally-visible physical backdoor attack, which can only be activated under specific optical conditions and thereby overcomes the risk of being detected after deployment and before the attack. Specifically, to ensure robust and reliable activation, we design irregular polygonal pattern as triggers to against across environmental variations. Moreover, we introduce a dual-phase mechanism (dormant and activated) to enable stealthy deployment. Our trigger remains invisible and dormant under non-attack conditions, leaving no physical traces. It activates instantaneously under specific illumination, inducing the target model to perform the desired behavior. We conduct experiments on traffic sign recognition tasks to compare our attack with six digital and seven physical attacks, and assess its performance against potential defenses. Extensive experimental results demonstrate the effectiveness, stealthiness, and robustness of our attack.
Yalun Wu, Endong Tong, Yingxiao Xiang, Xiaoting Lyu, Zhen Han 0001, Jiqiang Liu
AAAI3
2024 Lurking in the Shadows: Imperceptible Shadow Black-Box Attacks Against Lane Detection Models
Xiaoshu Cui, Yalun Wu, Yanfeng Gu, Endong Tong, Jiqiang Liu, Wenjia Niu
KSEM (3)5
2024 Knowledge-Driven Backdoor Removal in Deep Neural Networks via Reinforcement Learning
Jiayin Song, Yunzhe Tian, Endong Tong, Wenjia Niu, Jiqiang Liu
KSEM (3)6
2024 Collaborative Attack Sequence Generation Model Based on Multiagent Reinforcement Learning for Intelligent Traffic Signal System
abstract
Intelligent traffic signal systems, crucial for intelligent transportation systems, have been widely studied and deployed to enhance vehicle traffic efficiency and reduce air pollution. Unfortunately, intelligent traffic signal systems are at risk of data spoofing attack, causing traffic delays, congestion, and even paralysis. In this paper, we reveal a multivehicle collaborative data spoofing attack to intelligent traffic signal systems and propose a collaborative attack sequence generation model based on multiagent reinforcement learning (RL), aiming to explore efficient and stealthy attacks. Specifically, we first model the spoofing attack based on Partially Observable Markov Decision Process (POMDP) at single and multiple intersections. This involves constructing the state space, action space, and defining a reward function for the attack. Then, based on the attack modeling, we propose an automated approach for generating collaborative attack sequences using the Multi‐Actor‐Attention‐Critic (MAAC) algorithm, a mainstream multiagent RL algorithm. Experiments conducted on the multimodal traffic simulation (VISSIM) platform demonstrate a 15% increase in delay time (DT) and a 40% reduction in attack ratio (AR) compared to the single‐vehicle attack, confirming the effectiveness and stealthiness of our collaborative attack.
Yalun Wu, Yingxiao Xiang, Thar Baker, Endong Tong, Xiaoshu Cui, Zhen Han 0001, Jiqiang Liu, Wenjia Niu
Int. J. Intell. Syst.4
2024 Toward Learning Model-Agnostic Explanations for Deep Learning-Based Signal Modulation Classifiers
abstract
Recent advances in deep learning (DL) have brought tremendous gains in signal modulation classification. However, DL-based classifiers lack transparency and interpretability, which raises concern about model's reliability and hinders the wide deployment in real-word applications. While explainable methods have recently emerged, little has been done to explain the DL-based signal modulation classifiers. In this work, we propose a novel model-agnostic explainer, Model-Agnostic Signal modulation classification Explainer (MASE), which provides explanations for the predictions of black-box modulation classifiers. With the subsequence-based signal interpretable representation and in-distribution local signal sampling, MASE learns a local linear surrogate model to derive a class activation vector, which assigns importance values to the timesteps of signal instance. Besides, the constellation-based explanation visualization is adopted to spotlight the important signal features relevant to model prediction. We furthermore propose the first generic quantitative explanation evaluation framework for signal modulation classification to automatically measure the faithfulness, sensitivity, robustness, and efficiency of explanations. Extensive experiments are conducted on two real-world datasets with four black-box signal modulation classifiers. The quantitative results indicate MASE outperforms two state-of-the-art methods with 44.7% improvement in faithfulness, 30.6% improvement in robustness, and 44.1% decrease in sensitivity. Through qualitative visualizations, we further demonstrate the explanations of MASE are more human interpretable and provide better understanding into the reliability of black-box model decisions.
Yunzhe Tian, Dongyue Xu, Endong Tong, Thar Baker, Wenjia Niu, Jiqiang Liu
IEEE Trans. Reliab.3
2023 Robust Reinforcement Learning via Progressive Task Sequence
abstract
Robust reinforcement learning (RL) has been a challenging problem due to the gap between simulation and the real world. Existing efforts typically address the robust RL problem by solving a max-min problem. The main idea is to maximize the cumulative reward under the worst-possible perturbations. However, the worst-case optimization either leads to overly conservative solutions or unstable training process, which further affects the policy robustness and generalization performance. In this paper, we tackle this problem from both formulation definition and algorithm design. First, we formulate the robust RL as a max-expectation optimization problem, where the goal is to find an optimal policy under both the worst cases and the non-worst cases. Then, we propose a novel framework DRRL to solve the max-expectation optimization. Given our definition of the feasible tasks, a task generation and sequencing mechanism is introduced to dynamically output tasks at appropriate difficulty level for the current policy. With these progressive tasks, DRRL realizes dynamic multi-task learning to improve the policy robustness and the training stability. Finally, extensive experiments demonstrate that the proposed method exhibits significant performance on the unmanned CarRacing game and multiple high-dimensional MuJoCo environments.
Yunzhe Tian, Endong Tong, Wenjia Niu, Jiqiang Liu
IJCAI3
2022 A Missing QoS Prediction Approach via Time-Aware Collaborative Filtering
abstract
Quality of Service (QoS) guarantee is an important issue in building service-oriented applications. Generally, someQoSvalues of a service are unknown to its users who have never invoked the service before. Fortunately, collaborative filtering (CF)-based methods are proved feasible for missingQoSprediction and have been widely used. However, these methods seldom took the temporal factors into consideration. Indeed, historicalQoSvalues contain more information about user (or service) similarity. Furthermore, as the application environment is dynamic, obtainedQoSvalues usually have short timeliness. Hence, using outdatedQoSvalues will largely decrease the prediction accuracy. In order to resolve this issue, we proposed a time-aware collaborative filtering approach. First, we proposed aQoSmodel to filter out outdatedQoSvalues, and divided the obtainedQoSvalues into several time slices. Then, we computed the average value of historicalQoSas temporalQoSforecast. In addition, by introducing time-aware similarity computation mechanism, we succeeded to select real similar neighbor users (or services) and further predict theCF-basedQoSbased onCFtechnology. Finally, we can predict the final missingQoSby combining temporalQoSforecast andCF-basedQoSprediction. Experiment results show that our approach can receive better prediction precision.
Endong Tong, Wenjia Niu, Jiqiang Liu
IEEE Trans. Serv. Comput.1
2021 Security Analysis of Poisoning Attacks Against Multi-agent Reinforcement Learning
Zhiqiang Xie 0001, Yingxiao Xiang, Endong Tong, Wenjia Niu, Jiqiang Liu, Jian Wang 0071
ICA3PP (1)5
2021 Improving Convolutional Neural Network-Based Webshell Detection Through Reinforcement Learning
Yalun Wu, Minglu Song, Yunzhe Tian, Endong Tong, Wenjia Niu, Bowei Jia, Haixiang Huang, Jiqiang Liu
ICICS (1)5
2021 Protecting Reward Function of Reinforcement Learning via Minimal and Non-catastrophic Adversarial Trajectory
abstract
Reward functions are critical hyperparameters with commercial values for individual or distributed reinforcement learning (RL), as slightly different reward functions result in significantly different performance. However, existing inverse reinforcement learning (IRL) methods can be utilized to approximate reward functions just based on collected expert trajectories through observing. Thus, in the real RL process, how to generate a polluted trajectory and perform an adversarial attack on IRL for protecting reward functions has become the key issue. Meanwhile, considering the actual RL cost, generated adversarial trajectories should be minimal and non-catastrophic for ensuring normal RL performance. In this work, we propose a novel approach to craft adversarial trajectories disguised as expert ones, for decreasing the IRL performance and realize the anti-IRL ability. Firstly, we design a reward clustering-based metric to integrate both advantages of fine- and coarse-grained IRL assessment, including expected value difference (EVD) and mean reward loss (MRL). Further, based on such metric, we explore an adversarial attack based on agglomerative nesting algorithm (AGNES) clustering and determine targeted states as starting states for reward perturbation. Then we employ the intrinsic fear model to predict the probability of imminent catastrophe, supporting to generate non-catastrophic adversarial trajectories. Extensive experiments of 7 state-of-the-art IRL algorithms are implemented on the Object World benchmark, demonstrating the capability of our proposed approach in (a) decreasing the IRL performance and (b) having minimal and non-catastrophic adversarial trajectories.
Tong Chen 0007, Yingxiao Xiang, Yunzhe Tian, Endong Tong, Wenjia Niu, Jiqiang Liu, Gang Li 0009, Qi Alfred Chen
SRDS5
2021 Adversarial retraining attack of asynchronous advantage actor-critic based pathfinding
abstract
Pathfinding becomes an important component in many real-world scenarios, such as popular warehouse systems and autonomous aircraft towing vehicles. With the development of reinforcement learning (RL) especially in the context of asynchronous advantage actor-critic (A3C), pathfinding is undergoing a revolution in terms of efficient parallel learning. Similar to other artificial intelligence-based applications, A3C-based pathfinding is also threatened by the adversarial attack. In this paper, we are the first to study the adversarial attack to A3C, that can unexpectedly wake up longtime retraining mechanism until successful pathfinding. We also discover an attack example generation to launch the attack based on gradient band, in which only one baffle of extremely few unit lengths can successfully perform the attack. Experiments with detailed analysis are conducted to show a high attack success rate of 95% with an average baffle length of 2.95. We also discuss defense suggestions leveraging the insights from our analysis.
Tong Chen 0007, Jiqiang Liu, Yingxiao Xiang, Wenjia Niu, Endong Tong, Shuoru Wang, He Li 0019, Liang Chang 0003, Gang Li 0009, Qi Alfred Chen
Int. J. Intell. Syst.5
2021 Robustness Assessment of Asynchronous Advantage Actor-Critic Based on Dynamic Skewness and Sparseness Computation: A Parallel Computing View
Tong Chen 0007, Jiqiang Liu, He Li 0019, Shuoru Wang, Wenjia Niu, Endong Tong, Liang Chang 0003, Qi Alfred Chen, Gang Li 0009
J. Comput. Sci. Technol.6
2021 Towards Revealing Parallel Adversarial Attack on Politician Socialnet of Graph Structure
abstract
Socialnet becomes an important component in real life, drawing a lot of study issues of security and safety. Recently, for the features of graph structure in socialnet, adversarial attacks on node classification are exposed, and automatic attack methods such as fast gradient attack (FGA) and NETTACK are developed for per-node attacks, which can be utilized for multinode attacks in a sequential way. However, due to the overlook of perturbation influence between different per-node attacks, the above sequential method does not guarantee a global attack success rate for all target nodes, under a fixed budget of perturbation. In this paper, we propose a parallel adversarial attack framework on node classification. We redesign new loss function and objective function for nonconstraint and constraint perturbations, respectively. Through constructing intersection and supplement mechanisms of perturbations, we then integrate node filtering-based P-FGA and P-NETTACK in a unified framework, finally realizing parallel adversarial attacks. Experiments on politician socialnet dataset Polblogs with detailed analysis are conducted to show the effectiveness of our approach.
Yunzhe Tian, Jiqiang Liu, Endong Tong, Wenjia Niu, Liang Chang 0003, Qi Alfred Chen, Gang Li 0009, Wei Wang 0012
Secur. Commun. Networks3
2020 Bidirectional RNN-Based Few-Shot Training for Detecting Multi-stage Attack
Bowei Jia, Yunzhe Tian, Xiaojin Wang, Wenjia Niu, Endong Tong, Jiqiang Liu
Inscrypt7
2020 Exploring Data Correlation between Feature Pairs for Generating Constraint-based Adversarial Examples
abstract
Adversarial example (AE), an input that is modified slightly to cause a machine learning system to produce erroneous outputs, has seen significant studies recently. Unfortunately, the fine data perturbation of AE ignores to keep potential data correlations between feature pairs. Thus, such AE will be easily filtered by configuring data correlations as basic filtering rules. In this paper, avoiding not to be filtered as well as causing false classification, an advanced robust AE generation attack is proposed. We first define four basic data correlations called strict linear constraint, approximate linear constraint, addition boundary constraint and zero multiplication constraint. Then, based on embedding multiple data correlations into one constraint matrix from the Pearson analysis, our approach can enable a Hadamard product of the constraint matrix and the sign of gradient matrix to craft perturbations, keeping consistent data correlations. Experimental results on intrusion detection system (IDS) indicate: 1) Nearly all AEs from original IFGSM are invalid by filtering according to basic data correlations; 2) In our method, AEs against a targeted DNN-based classifier can achieve an attack success rate of 99%, with transfer attack ability of 94% average success rate to attack other different mainstream classifiers.
Yunzhe Tian, Yingdi Wang, Endong Tong, Wenjia Niu, Liang Chang 0003, Qi Alfred Chen, Gang Li 0009, Jiqiang Liu
ICPADS3
2020 Explainable Congestion Attack Prediction and Software-level Reinforcement in Intelligent Traffic Signal System
abstract
With connected vehicle(CV) technology, the next-generation transportation system is stepping into its implementation phase via the deployment of Intelligent Traffic Signal System (I-SIG). Since the congestion attack was firstly discovered in USDOT (U.S. Department of Transportation) sponsored I-SIG, deployed in three cities including New York, such realistic threat opens a new security issue. In this work, from machine learning perspective, we perform a systematic feature analysis on congestion attack and its variations from last vehicle of different traffic flow pattern. We first adopt the Tree-regularized Gated Recurrent Unit (TGRU) to make explainable congestion attack prediction, in which 32-dimension features are defined to character a 8-phase intersection traffic. We then develop corresponding software-level security reinforcements suggestions, which can be further expanded as an important work. In massive experiments based on real-world intersection settings, we eventually distill 384 samples of congestion attacks to train a TGRU-based attack prediction model, and achieve an average 80% precision. We further discussed possible reinforcement defense methods according to our prediction model.
Xiaojin Wang, Yingxiao Xiang, Wenjia Niu, Endong Tong, Jiqiang Liu
ICPADS4
2020 A C-IFGSM Based Adversarial Approach for Deep Learning Based Intrusion Detection
Yingdi Wang, Yixiang Wang, Endong Tong, Wenjia Niu, Jiqiang Liu
VECoS3
2020 Exposing Spoofing Attack on Flocking-Based Unmanned Aerial Vehicle Cluster: A Threat to Swarm Intelligence
abstract
With the rapid development of wireless communication technology and intelligent mobile devices, unmanned aerial vehicle (UAV) cluster is becoming increasingly popular in both civilian and military applications. Recently, a swarm intelligence-based UAV cluster study, aiming to enable efficient and autonomous collaboration, has drawn lots of interest. However, new security problems may be introduced with such swarm intelligence. In this work, we perform the first detailed security analysis to a kind of flocking-based UAV cluster with 5 policies, an upgrade version of the well-known Boids model. Targeting a realistic threat in a source-to-destination flying task, we design a data spoofing strategy and further perform complete vulnerability analysis. We reveal that such design and implementation are highly vulnerable. After breaking through the authentication of ad hoc on-demand distance vector (AODV) routing protocol by rushing attack, an attacker can masquerade as the first-arrival UAV within a specific scope of destination and generate data spoofing of arrival status to the following UAVs, so as to interfere with their normal flying paths of destination arrival and cause unexpected arrival delays amid urgent tasks. Experiments with detailed analysis from the 5-UAV cluster to the 10-UAV cluster are conducted to show specific feature composition-based attack effect and corresponding average delay. We also discuss promising defense suggestions leveraging the insights from our analysis.
Xinyu Huang 0006, Yunzhe Tian, Endong Tong, Wenjia Niu, Jiqiang Liu, Liang Chang 0003
Secur. Commun. Networks4
2020 Energy-Aware Service Selection and Adaptation in Wireless Sensor Networks with QoS Guarantee
abstract
Workflow-based Service-oriented WSNs have recently received a lot of attention from both academia and industry. With well-defined service components, various flexible WSN applications can be developed. However, the key characteristic of WSNs is resource constraints. Sensor nodes in WSNs have limited storage, computation and especially limited energy. As service components in WSNs rely on the data gathered by sensor nodes, they are also resource-constrained. Unfortunately, traditional workflow technologies (i.e., service selection, composition and adaptation) ignore the residual energy of services. This will bring unbalanced energy consumption and furthermore shorten the network lifetime. In order to resolve this issue, we proposed an energy-aware QoS-guaranteed workflow management mechanism. In this mechanism, a new QoS model is first presented to improve the QoS evaluation. Then, based on this QoS model, an efficient service selection schema, which considers both the energy and the QoS of services, is proposed. Furthermore, an adaptation mechanism for balanced energy consumption is also proposed. Experimental evaluations demonstrate the capability of our proposed approach.
Endong Tong, Lan Chen 0001, Huizi Li
IEEE Trans. Serv. Comput.1
2020 An Empirical Study on GAN-Based Traffic Congestion Attack Analysis: A Visualized Method
abstract
With the development of emerging intelligent traffic signal (I-SIG) system, congestion-involved security issues are drawing attentions of researchers and developers on the vulnerability introduced by connected vehicle technology, which empowers vehicles to communicate with the surrounding environment such as road-side infrastructure and traffic control units. A congestion attack to the controlled optimization of phases algorithm (COP) of I-SIG is recently revealed. Unfortunately, such analysis still lacks a timely visualized prediction on later congestion when launching an initial attack. In this paper, we argue that traffic image feature-based learning has available knowledge to reflect the relation between attack and caused congestion and propose a novel analysis framework based on cycle generative adversarial network (CycleGAN). Based on phase order, we first extract four-direction road images of one intersection and perform phase-based composition for generating new sample image of training. We then design a weighted L1 regularization loss that considers both last-vehicle attack and first-vehicle attack, to improve the training of CycleGAN with two generators and two discriminators. Experiments on simulated traffic flow data from VISSIM platform show the effectiveness of our approach.
Yingxiao Xiang, Endong Tong, Wenjia Niu, Bowei Jia, Long Li 0005, Jiqiang Liu, Zhen Han 0001
Wirel. Commun. Mob. Comput.3
2019 Adversarial attack and defense in reinforcement learning-from AI security view
abstract
Reinforcement learning is a core technology for modern artificial intelligence, and it has become a workhorse for AI applications ranging from Atrai Game to Connected and Automated Vehicle System (CAV). Therefore, a reliable RL system is the foundation for the security critical applications in AI, which has attracted a concern that is more critical than ever. However, recent studies discover that the interesting attack mode adversarial attack also be effective when targeting neural network policies in the context of reinforcement learning, which has inspired innovative researches in this direction. Hence, in this paper, we give the very first attempt to conduct a comprehensive survey on adversarial attacks in reinforcement learning under AI security. Moreover, we give briefly introduction on the most representative defense technologies against existing adversarial attacks.
Tong Chen 0007, Jiqiang Liu, Yingxiao Xiang, Wenjia Niu, Endong Tong, Zhen Han 0001
Cybersecur.5
2016 Exploring probabilistic follow relationship to prevent collusive peer-to-peer piracy
Wenjia Niu, Endong Tong, Qian Li 0003, Gang Li 0009, Xuemin Wen, Jianlong Tan, Li Guo 0001
Knowl. Inf. Syst.2
2014 Towards Optimal Lifetime in Wireless Sensor Networks for QoS Guaranteed Service Selection
Endong Tong, Lan Chen 0001, Ying Li 0056
PRICAI1
2014 A block-aware hybrid data dissemination with hotspot elimination in wireless sensor network
Wenjia Niu, Gang Li 0009, Endong Tong, Quan Z. Sheng, Qian Li 0003, Yue Hu 0002, Athanasios V. Vasilakos, Li Guo 0001
J. Netw. Comput. Appl.3
2014 Interaction relationships of caches in agent-based HD video surveillance: Discovery and utilization
Wenjia Niu, Gang Li 0009, Endong Tong, Xinghua Yang, Liang Chang 0003, Zhongzhi Shi, Song Ci
J. Netw. Comput. Appl.3
2014 Bloom filter-based workflow management to enable QoS guarantee in wireless sensor networks
Endong Tong, Wenjia Niu, Gang Li 0009, Ding Tang, Liang Chang 0003, Zhongzhi Shi, Song Ci
J. Netw. Comput. Appl.1
2012 Hierarchical Workflow Management in Wireless Sensor Network
Endong Tong, Wenjia Niu, Gang Li 0009, Hui Tang 0001, Ding Tang, Song Ci
PRICAI1