VLDB 2026 Research / reviewers in the wild / expert
Mingyuan Fan 0003
dblp:129/9436-3
· DBLP profile ↗
26ranked-venue papers
14as first author
26since 2021 · last 2026
0000-0001-9550-9237ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 10 · 6 first-author · 10 since 2021Security and privacy · 7 · 3 first-author · 7 since 2021Databases, data management, data science and information retrieval · 7 · 3 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 first-author · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Dynamic asymmetric relational learning for stock price movement prediction
Ruifeng Yang, Mingyuan Fan 0003, Fengran Mo, Cen Chen 0001 |
Data Min. Knowl. Discov. | 2 |
| 2026 | CCJA: Context-Coherent Jailbreak Attack for Aligned Large Language Models
Guanghao Zhou, Cen Chen 0001, Panjia Qiu, Mingyuan Fan 0003, Mingyuan Chu, Jun Zhou 0011 |
Mach. Learn. | 4 |
| 2025 | FLAME: Flexible and Lightweight Biometric Authentication Scheme in Malicious EnvironmentsabstractPrivacy-preserving biometric authentication (PPBA) enables client authentication without revealing sensitive bio-metric data, addressing privacy and security concerns. Many studies have proposed efficient cryptographic solutions to this problem based on secure multi-party computation, typically assuming a semi-honest adversary model, where all parties follow the protocol but may try to learn additional information. However, this assumption often falls short in real-world scenarios, where adversaries may behave maliciously and actively deviate from the protocol. In this paper, we propose, implement, and evaluate FLAME, a Flexible and Lightweight biometric Authentication scheme designed for a Malicious Environment. By hybridizing lightweight secret-sharing-family primitives within two-party computation, FLAME carefully designs a line of supporting protocols that incorporate integrity checks with rationally extra overhead. Additionally, FLAME enables server-side authentication with various similarity metrics through a crossmetric-compatible design, enhancing flexibility and robustness without requiring any changes to the server-side process. A rigorous theoretical analysis validates the correctness, security, and efficiency of FLAME. Extensive experiments highlight FLAME's superior efficiency, with a communication reduction by 97.61x 110.13x and a speedup of 2.72x 2.82x (resp. 6.58x 8.51x) in a LAN (resp. WAN) environment, when compared to the state-of-the-art work. Fuyi Wang, Fangyuan Sun, Mingyuan Fan 0003, Jianying Zhou 0001, Chao Chen 0015, Jiangang Shu, Leo Yu Zhang |
ACSAC | 3 |
| 2025 | Transferable Adversarial Examples with Bayesian Approach
Mingyuan Fan 0003, Cen Chen 0001, Wenmeng Zhou, Yinggui Wang |
AsiaCCS | 1 |
| 2025 | PrivGNN: High-Performance Secure Inference for Cryptographic Graph Neural Networks
Fuyi Wang, Zekai Chen 0010, Mingyuan Fan 0003, Jianying Zhou 0001, Lei Pan 0002, Leo Yu Zhang |
FC (2) | 3 |
| 2025 | Bad-PFL: Exploiting Backdoor Attacks against Personalized Federated LearningabstractData heterogeneity and backdoor attacks rank among the most significant challenges facing federated learning (FL). For data heterogeneity, personalized federated learning (PFL) enables each client to maintain a private personalized model to cater to client-specific knowledge. Meanwhile, vanilla FL has proven vulnerable to backdoor attacks. However, recent advancements in PFL community have demonstrated a potential immunity against such attacks. This paper explores this intersection further, revealing that existing federated backdoor attacks fail in PFL because backdoors about manually designed triggers struggle to survive in personalized models. To tackle this, we degisn Bad-PFL, which employs features from natural data as our trigger. As long as the model is trained on natural data, it inevitably embeds the backdoor associated with our trigger, ensuring its longevity in personalized models. Moreover, our trigger undergoes mutual reinforcement training with the model, further solidifying the backdoor's durability and enhancing attack effectiveness. The large-scale experiments across three benchmark datasets demonstrate the superior performance of Bad-PFL against various PFL methods, even when equipped with state-of-the-art defense mechanisms. Mingyuan Fan 0003, Zhanyi Hu, Fuyi Wang, Cen Chen 0001 |
ICLR | 1 |
| 2025 | Growth Inhibitors for Suppressing Inappropriate Image Concepts in Diffusion ModelsabstractDespite their remarkable image generation capabilities, text-to-image diffusion models inadvertently learn inappropriate concepts from vast and unfiltered training data, which leads to various ethical and business risks. Specifically, model-generated images may exhibit not safe for work (NSFW) content and style copyright infringements. The prompts that result in these problems often do not include explicit unsafe words; instead, they contain obscure and associative terms, which are referred to as *implicit unsafe prompts*. Existing approaches directly fine-tune models under textual guidance to alter the cognition of the diffusion model, thereby erasing inappropriate concepts. This not only requires concept-specific fine-tuning but may also incur catastrophic forgetting. To address these issues, we explore the representation of inappropriate concepts in the image space and guide them towards more suitable ones by injecting *growth inhibitors*, which are tailored based on the identified features related to inappropriate concepts during the diffusion process. Additionally, due to the varying degrees and scopes of inappropriate concepts, we train an adapter to infer the corresponding suppression scale during the injection process. Our method effectively captures the manifestation of subtle words at the image level, enabling direct and efficient erasure of target concepts without the need for fine-tuning. Through extensive experimentation, we demonstrate that our approach achieves superior erasure results with little effect on other normal concepts while preserving image quality and semantics. Die Chen, Zhiwen Li 0001, Mingyuan Fan 0003, Cen Chen 0001, Wenmeng Zhou, Yanhao Wang 0001, Yaliang Li |
ICLR | 3 |
| 2025 | Refiner: Data Refining against Gradient Leakage Attacks in Federated Learning
Mingyuan Fan 0003, Cen Chen 0001, Chengyu Wang 0001, Wenmeng Zhou |
USENIX Security Symposium | 1 |
| 2025 | Boosting Gradient Leakage Attacks: Data Reconstruction in Realistic FL Settings
Mingyuan Fan 0003, Fuyi Wang, Cen Chen 0001, Jianying Zhou 0001 |
USENIX Security Symposium | 1 |
| 2025 | Responsible Diffusion Models via Constraining Text Embeddings within Safe RegionsabstractThe remarkable ability of diffusion models to generate high-fidelity images has led to their widespread adoption. However, concerns have also arisen regarding their potential to produce Not Safe for Work (NSFW) content and exhibit social biases, hindering their practical use in real-world applications. In response to this challenge, prior work has focused on employing security filters to identify and exclude toxic text, or alternatively, fine-tuning pre-trained diffusion models to erase sensitive concepts. Unfortunately, existing methods struggle to achieve satisfactory performance in the sense that they can have a significant impact on the normal model output while still failing to prevent the generation of harmful content in some cases. In this paper, we propose a novel self-discovery approach to identifying a semantic direction vector in the embedding space to restrict text embedding within a safe region. Our method circumvents the need for correcting individual words within the input text and steers the entire text prompt towards a safe region in the embedding space, thereby enhancing model robustness against all possibly unsafe prompts. In addition, we employ Low-Rank Adaptation (LoRA) for semantic direction vector initialization to reduce the impact on the model performance for other semantics. Furthermore, our method can also be integrated with existing methods to improve their social responsibility. Extensive experiments on benchmark datasets demonstrate that our method can effectively reduce NSFW content and mitigate social bias generated by diffusion models compared to several state-of-the-art baselines. WARNING:This paper contains model-generated images that may be potentially offensive. Zhiwen Li 0001, Die Chen, Mingyuan Fan 0003, Cen Chen 0001, Yaliang Li, Yanhao Wang 0001, Wenmeng Zhou |
WWW | 3 |
| 2025 | On the Trustworthiness Landscape of State-of-the-art Generative Models: A Survey and Outlook
Mingyuan Fan 0003, Chengyu Wang 0001, Cen Chen 0001, Yang Liu 0118, Jun Huang 0007 |
Int. J. Comput. Vis. | 1 |
| 2025 | Exploiting Pre-Trained Models and Low-Frequency Preference for Cost-Effective Transfer-based AttackabstractThe transferability of adversarial examples enables practical transfer-based attacks. However, existing theoretical analysis cannot effectively reveal what factors contribute to cross-model transferability. Furthermore, the assumption that the target model dataset is available together with expensive prices of training proxy models also leads to insufficient practicality. We first propose a novel frequency perspective to study the transferability and then identify two factors that impair the transferability: an unchangeable intrinsic difference term along with a controllable perturbation-related term. To enhance the transferability, an optimization task with the constraint that decreases the impact of the perturbation-related term is formulated and an approximate solution for the task is designed to address the intractability of Fourier expansion. To address the second issue, we suggest employing pre-trained models as proxy models, which are freely available. Leveraging these advancements, we introduce cost-effective transfer-based attack ( CTA ), which addresses the optimization task in pre-trained models. CTA can be unleashed against broad applications, at any time, with minimal effort and nearly zero cost to attackers. This remarkable feature indeed makes CTA an effective, versatile, and fundamental tool for attacking and understanding a wide range of target models, regardless of their architecture or training dataset used. Extensive experiments show impressive attack performance of CTA across various models trained in seven black-box domains, highlighting the broad applicability and effectiveness of CTA . Mingyuan Fan 0003, Cen Chen 0001, Chengyu Wang 0001, Jun Huang 0007 |
ACM Trans. Knowl. Discov. Data | 1 |
| 2024 | SGFL-Attack: A Similarity-Guidance Strategy for Hard-Label Textual Adversarial Attack Based on Feedback LearningabstractHard-label black-box textual adversarial attack presents a challenging task where only the predictions of the victim model are available. Moreover, several constraints further complicate the task of launching such attacks, including the inherent discrete and non-differentiable nature of text data and the need to introduce subtle perturbations that remain imperceptible to humans while preserving semantic similarity. Despite the considerable research efforts dedicated to this problem, existing methods still suffer from several limitations. For example, algorithms based on complex heuristic searches necessitate extensive querying, rendering them computationally expensive. The introduction of continuous gradient strategies into discrete text spaces often leads to estimation errors. Meanwhile, geometry-based strategies are prone to falling into local optima. To address these limitations, in this paper, we introduce SGFL-Attack, a novel approach that leverages a Similarity-Guidance strategy based on Feedback Learning for hard-label textual adversarial attack, with limited query budget. Specifically, the proposed SGFL-Attack utilizes word embedding vectors to assess the importance of words and positions in text sequences, and employs a feedback learning mechanism to determine reward or punishment based on changes in predicted labels caused by replacing words. In each iteration, SGFL-Attack guides the search based on knowledge acquired from the feedback learning mechanism, generating more similar samples while maintaining low perturbations. Moreover, to reduce the query budget, we incorporate local hash mapping to avoid redundant queries during the search process. Extensive experiments on seven widely used datasets show that the proposed SGFL-Attack method significantly outperforms state-of-the-art baselines and defenses over multiple language models. Panjia Qiu, Guanghao Zhou, Mingyuan Fan 0003, Cen Chen 0001, Yaliang Li, Wenming Zhou |
CIKM | 3 |
| 2024 | LST2A: Lexical-Syntactic Targeted Adversarial Attack for TextsabstractTextual adversarial attack in black-box scenarios is a challenging task, as only the predicted label is available, and the text space is discrete and non-differentiable. Current research in this area is still in its infancy and mostly focuses on untargeted attack, lacking the capability to control the labels of the generated adversarial examples. Meanwhile, existing textual adversarial attack methods primarily rely on word substitution operations to maintain semantic similarity between the adversarial and original examples, which greatly limits the search space for adversarial examples. To address these issues, we propose a novel Lexical-Syntactic Targeted Adversarial Attack method tailored for the black-box settings, referred to as LST2A. Our approach involves adversarial perturbations at different levels of granularities, i.e., word-level with word substitution operations and syntactic-level through rewriting the syntax of the examples. Specifically, we first embed the entire text into the embedding layer of a masked language model, and then optimize perturbations at the word level within the hidden state to generate adversarial examples with the target label. For examples that are difficult to attack successfully with only word-level perturbations at higher semantic similarity thresholds, we leverage Large Language Model (LLM) to introduce syntactic-level perturbations to these examples, making them more vulnerable to the decision boundary of the victim model. Subsequently, we re-optimize the word-level perturbations for these vulnerable examples. Extensive experiments and human evaluations demonstrate that our proposed method consistently outperforms the state-of-the-art baselines, crafting smoother, more grammatically correct adversarial examples. Guanghao Zhou, Panjia Qiu, Mingyuan Fan 0003, Cen Chen 0001, Yaliang Li, Wenmeng Zhou |
CIKM | 3 |
| 2024 | FedMCP: Parameter-Efficient Federated Learning with Model-Contrastive PersonalizationabstractWith increasing concerns and regulations on data privacy, fine-tuning pretrained language models (PLMs) in federated learning (FL) has become a common paradigm for NLP tasks. Despite being extensively studied, the existing methods for this problem still face two primary challenges. First, the huge number of parameters in large-scale PLMs leads to excessive communication and computational overhead. Second, the heterogeneity of data and tasks across clients poses a significant obstacle to achieving the desired fine-tuning performance. To address the above problems, we propose FedMCP, a novel parameter-efficient fine-tuning method with model-contrastive personalization for FL. Specifically, FedMCP adds two lightweight adapter modules, i.e., the global adapter and the private adapter, to the frozen PLMs within clients. In a communication round, each client sends only the global adapter to the server for federated aggregation. Furthermore, FedMCP introduces a model-contrastive regularization term between the two adapters. This, on the one hand, encourages the global adapter to assimilate universal knowledge and, on the other hand, the private adapter to capture client-specific knowledge. By leveraging both adapters, FedMCP can effectively provide fine-tuned personalized models tailored to individual clients. Extensive experiments on highly heterogeneous cross-task, cross-silo datasets show that FedMCP achieves substantial performance improvements over state-of-the-art FL fine-tuning approaches for PLMs. Qianyi Zhao, Chen Qu 0001, Cen Chen 0001, Mingyuan Fan 0003, Yanhao Wang 0001 |
ICPADS | 4 |
| 2024 | Transferability Bound Theory: Exploring Relationship between Adversarial Transferability and FlatnessabstractA prevailing belief in attack and defense community is that the higher flatness of adversarial examples enables their better cross-model transferability, leading to a growing interest in employing sharpness-aware minimization and its variants. However, the theoretical relationship between the transferability of adversarial examples and their flatness has not been well established, making the belief questionable. To bridge this gap, we embark on a theoretical investigation and, for the first time, derive a theoretical bound for the transferability of adversarial examples with few practical assumptions. Our analysis challenges this belief by demonstrating that the increased flatness of adversarial examples does not necessarily guarantee improved transferability. Moreover, building upon the theoretical analysis, we propose TPA, a Theoretically Provable Attack that optimizes a surrogate of the derived bound to craft adversarial examples. Extensive experiments across widely used benchmark datasets and various real-world applications show that TPA can craft more transferable adversarial examples compared to state-of-the-art baselines. We hope that these results can recalibrate preconceived impressions within the community and facilitate the development of stronger adversarial attack and defense mechanisms. Mingyuan Fan 0003, Cen Chen 0001, Wenmeng Zhou, Yaliang Li |
NeurIPS | 1 |
| 2024 | Guardian: Guarding against Gradient Leakage with Provable Defense for Federated LearningabstractFederated learning is a privacy-focused learning paradigm, which trains a global model with gradients uploaded from multiple participants, circumventing explicit exposure of private data. However, previous research of gradient leakage attacks suggests that gradients alone are sufficient to reconstruct private data, rendering the privacy protection mechanism of federated learning unreliable. Existing defenses commonly craft transformed gradients based on ground-truth gradients to obfuscate the attacks, but often are less capable of maintaining good model performance together with satisfactory privacy protection. In this paper, we propose a novel yet effective defense framework named guarding against gradient leakage (Guardian) that produces transformed gradients by jointly optimizing two theoretically-derived metrics associated with gradients for performance maintenance and privacy protection. In this way, the transformed gradients produced via Guardian can achieve minimal privacy leakage in theory with the given performance maintenance level. Moreover, we design an ingenious initialization strategy for faster generation of transformed gradients to enhance the practicality of Guardian in real-world applications, while demonstrating theoretical convergence of Guardian to the performance of the global model. Extensive experiments on various tasks show that, without sacrificing much accuracy, Guardian can effectively defend state-of-the-art gradient leakage attacks, compared with the slight effects of baseline defense approaches. Mingyuan Fan 0003, Yang Liu 0118, Cen Chen 0001, Chengyu Wang 0001, Minghui Qiu, Wenmeng Zhou |
WSDM | 1 |
| 2024 | Privacy-Enhancing and Robust Backdoor Defense for Federated Learning on Heterogeneous DataabstractFederated learning (FL) allows multiple clients to train deep learning models collaboratively while protecting sensitive local datasets. However, FL has been highly susceptible to security for federated backdoor attacks (FBA) through injecting triggers and privacy for potential data leakage from uploaded models in practical application scenarios. FBA defense strategies consider specific and limited attacker models, and a sufficient amount of noise injected can only mitigate rather than eliminate the attack. To address these deficiencies, we introduce a Robust Federated Backdoor Defense Scheme (RFBDS) and Privacy-preserving RFBDS (PrivRFBDS) to ensure the elimination of adversarial backdoors. Our RFBDS to overcome FBA consists of amplified magnitude sparsification, adaptive OPTICS clustering, and adaptive clipping. The experimental evaluation of RFBDS is conducted on three benchmark datasets and an extensive comparison is made with state-of-the-art studies. The results demonstrate the promising defense performance from RFBDS, moderately improved by 31.75% ~ 73.75% in clustering defense methods, and 0.03% ~ 56.90% for Non-IID to the utmost extent for the average FBA success rate over MNIST, FMNIST, and CIFAR10. Besides, our privacy-preserving shuffling in PrivRFBDS maintains is$7.83e^{-5}\,\,\sim \,\,0.42\times $that of state-of-the-art works. Zekai Chen 0010, Shengxing Yu, Mingyuan Fan 0003, Ximeng Liu, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Rethinking the Evaluation of Deep Neural Network Robustness
Mingyuan Fan 0003, Fuyi Wang, Bosheng Yan |
ADMA (4) | 1 |
| 2023 | On the Robustness of Split Learning Against Adversarial AttacksabstractSplit learning enables collaborative deep learning model training while preserving data privacy and model security by avoiding direct sharing of raw data and model details (i.e., server and clients only hold partial sub-networks and exchange intermediate computations). However, existing research has mainly focused on examining its reliability for privacy protection, with little investigation into model security. Specifically, by exploring full models, attackers can launch adversarial attacks, and split learning can mitigate this severe threat by only disclosing part of models to untrusted servers. This paper aims to evaluate the robustness of split learning against adversarial attacks, particularly in the most challenging setting where untrusted servers only have access to the intermediate layers of the model. Existing adversarial attacks mostly focus on the centralized setting instead of the collaborative setting, thus, to better evaluate the robustness of split learning, we develop a tailored attack called SLADV, which comprises two stages: 1) shadow model training that addresses the issue of lacking part of the model and 2) local adversarial attack that produces adversarial examples to evaluate. The first stage only requires a few unlabeled non-IID data, and, in the second stage, SLADV perturbs the intermediate output of natural samples to craft the adversarial ones. The overall cost of the proposed attack process is relatively low, yet the empirical attack effectiveness is significantly high, demonstrating the surprising vulnerability of split learning to adversarial attacks. Mingyuan Fan 0003, Cen Chen 0001, Chengyu Wang 0001, Wenmeng Zhou, Jun Huang 0007 |
ECAI | 1 |
| 2023 | Enhance Transferability of Adversarial Examples with Model ArchitectureabstractTransferability of adversarial examples is of critical importance to launch black-box adversarial attacks, where attackers are only allowed to access the output of the target model. However, under such a challenging but practical setting, the crafted adversarial examples are always prone to overfitting to the proxy model employed, presenting poor transferability. In this paper, we suggest alleviating the overfitting issue from a novel perspective, i.e., designing a fitted model architecture. Specifically, delving the bottom of the cause of poor transferability, we arguably decompose and reconstruct the existing model architecture into an effective model architecture, namely multi-track model architecture (MMA). The adversarial examples crafted on the MMA can maximumly relieve the effect of model-specified features to it and toward the vulnerable directions adopted by diverse architectures. Extensive experimental evaluation demonstrates that the transferability of adversarial examples based on the MMA significantly surpass other state-of-the-art model architectures by up to 40% with comparable overhead. Mingyuan Fan 0003, Wenzhong Guo, Zuobin Ying, Ximeng Liu |
ICASSP | 1 |
| 2022 | Combating False Sense of Security: Breaking the Defense of Adversarial Training Via Non-Gradient Adversarial AttackabstractAdversarial training is believed to be the most robust and effective defense method against adversarial attacks. Gradient-based adversarial attack methods are generally adopted to evaluate the effectiveness of adversarial training. However, in this paper, by diving into the existing adversarial attack literature, we find that adversarial examples generated by these attack methods tend to be less imperceptible, which may lead to an inaccurate estimation for the effectiveness of the adversarial training. The existing adversarial attacks mostly adopt gradient-based optimization methods and such optimization methods have difficulties in searching the most effective adversarial examples (i.e., the global extreme points). On the contrast, in this work, we propose a novel Non-Gradient Attack (NGA) to overcome the above-mentioned problem. Extensive experiments show that NGA significantly outperforms the state-of-the-art adversarial attacks on Attack Success Rate (ASR) by 2% ∼ 7%. Mingyuan Fan 0003, Yang Liu 0118, Cen Chen 0001, Shengxing Yu, Wenzhong Guo, Ximeng Liu |
ICASSP | 1 |
| 2022 | Backdoor Defense with Machine UnlearningabstractBackdoor injection attack is an emerging threat to the security of neural networks, however, there still exist limited effective defense methods against the attack. In this paper, we propose BAERASER, a novel method that can erase the backdoor injected into the victim model through machine unlearning. Specifically, BAERASER mainly implements backdoor defense in two key steps. First, trigger pattern recovery is conducted to extract the trigger patterns infected by the victim model. Here, the trigger pattern recovery problem is equivalent to the one of extracting an unknown noise distribution from the victim model, which can be easily resolved by the entropy maximization based generative model. Subsequently, BAERASER leverages these recovered trigger patterns to reverse the backdoor injection procedure and induce the victim model to erase the polluted memories through a newly designed gradient ascent based machine unlearning method. Compared with the previous machine unlearning solutions, the proposed approach gets rid of the reliance on the full access to training data for retraining and shows higher effectiveness on backdoor erasing than existing fine-tuning or pruning methods. Moreover, experiments show that BAERASER can averagely lower the attack success rates of three kinds of state-of-the-art backdoor attacks by 99% on four benchmark datasets. Yang Liu 0118, Mingyuan Fan 0003, Cen Chen 0001, Ximeng Liu, Zhuo Ma 0001, Li Wang 0056, Jianfeng Ma 0001 |
INFOCOM | 2 |
| 2022 | Dynamically Selected Mixup Machine UnlearningabstractMachine unlearning is a significant part of machine learning security because machine learning models are not immune to attacks such as poisoning attacks. In addition, various studies have proved that it is feasible to obtain training set information from the model, which can lead to leakage of user data privacy. Therefore, there is an urgent need for a method to remove specific data from the model training set. Naive retraining will bring huge time and resource costs, while SISA can achieve a balance between unlearning cost and model performance to a certain extent by dividing the dataset into multiple independent shards. As forgotten data grows, the performance of SISA is still unable to meet the actual needs. In this paper, we propose a method, which dynamically selects the shards that need to be retrained. First, we divide the dataset into multiple independent shards, when the forgotten data makes multiple shards need to be retrained at the same time, our approach is to mix these affected shards together, and then train the mixed shards individually to achieve global forgetting. The simulation results show that compared with SISA, we can get more than 3× speedup on different datasets, and the accuracy of the aggregation model is also improved by 0.5% and 2.1% on MNIST and CIFAR10, respectively. Ximeng Liu, Junxi Ruan, Mingyuan Fan 0003 |
TrustCom | 5 |
| 2022 | Toward Evaluating the Reliability of Deep-Neural-Network-Based IoT DevicesabstractNowadays, the impressive performance of deep neural networks (DNNs) greatly advances the development of Internet of Things (IoT) in diverse scenarios. However, the exceptional vulnerability of DNNs to adversarial attack leads IoT devices to be exposed to potential security issues. Up to now, since adversarial training empirically remains robust against gradient-based adversarial attacks, it is believed to be the most effective defense method. In this article, we find that adversarial examples generated by gradient-based adversarial attacks tend to be less imperceptible induced by the gradient-based optimization methods (adopted in the attacks) being difficult on searching the most effective adversarial examples (i.e., the global extreme points), which may lead to an inaccurate estimation for the effectiveness of the adversarial training. To overcome the inherent defect of gradient-based adversarial attacks, we propose a novel adversarial attack named nongradient attack (NGA), of which search strategy is effective but no longer depends on gradients to enhance the threat of adversarial examples. In detail, NGA first initializes the adversarial examples outside, rather than inside, of decision boundary to make them misclassified by the model and then, under without violation of misclassified condition, adjusts the adversarial examples toward the crafted direction to close the original examples. Extensive experiments show that NGA significantly outperforms the state-of-the-art adversarial attacks on attack success rate (ASR) by 2%–7%. Moreover, we propose a new evaluation metric, i.e., composite criterion (CC) based on both ASR and accuracy, to better measure the effectiveness of adversarial training. In the experiments, CC has shown to be a more comprehensive yet appropriate evaluation metric. Mingyuan Fan 0003, Yang Liu 0118, Cen Chen 0001, Shengxing Yu, Wenzhong Guo, Li Wang 0056, Ximeng Liu |
IEEE Internet Things J. | 1 |
| 2021 | Towards Transferable Adversarial Examples Using Meta Learning
Mingyuan Fan 0003, Jia-Li Yin, Ximeng Liu, Wenzhong Guo |
ICA3PP (1) | 1 |