VLDB 2026 Research / reviewers in the wild / expert
Bin Wang 0062
dblp:13/1898-62
· DBLP profile ↗
78ranked-venue papers
4as first author
64since 2021 · last 2026
0000-0002-3790-2708ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 26 · 24 since 2021Artificial intelligence and machine learning · 14 · 14 since 2021Computer networks · 12 · 1 first-author · 10 since 2021Graphics, computer vision, multimedia, augmented reality and games · 9 · 9 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 1 first-author · 5 since 2021Systems, architecture and hardware · 5 · 2 first-authorDatabases, data management, data science and information retrieval · 4 · 4 since 2021Software engineering, systems software and programming languages · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DCAD: Dual-Condition Adaptive Consistency Model for IoT Privacy-Preserving Video Anomaly Detection
Shaopeng Zhou, Chaohao Li, Haonan Yan, Longlong Zhu, Chunming Wu 0001, Bin Wang 0062 |
ICIC (2) | 7 |
| 2026 | Manipulation-Resilient Pricing for Nonfungible TokensabstractNon-Fungible Tokens (NFTs) enable the decentralized representation and exchange of real-world assets, supporting features like fractional ownership and programmable logic that underpin emerging digital finance ecosystems. However, the openness of NFT markets makes them susceptible to manipulation tactics like wash trading, where coordinated trades distort prices. This undermines valuation accuracy and erodes trust in decentralized finance. To counter these challenges, we propose NFTGuard, a unified framework for detecting wash trades and producing manipulation-resilient NFT price predictions. First, NFTGuard filters out manipulated transactions using a rule-based detector that identifies self-dealing and cyclic trading patterns prevalent in decentralized marketplaces. Second, NFTGuard prepares for price prediction by constructing a multi-modal representation that integrates temporal trading dynamics, transactional metadata, and asset-specific semantic signals. Third, NFTGuard performs prediction using a Multi-Layer Perceptron (MLP) mixing backbone that fuses these heterogeneous cues into manipulation-resilient forecasts. Experiments on real-world NFT datasets from platforms like Rarible and Opensea show that NFTGuard achieves a 90.9% F1-score in detecting wash trades and improves price prediction accuracy by over 10% compared to the baselines. Bin Wang 0051, Bin Wang 0062, Wei Wang 0012 |
IEEE Internet Things J. | 3 |
| 2026 | RPA: Recursive Perturbation-Based Universal Adversarial Attacks on Multimodal Generative TasksabstractCurrent adversarial attacks pose a serious threat to the robustness of visual-language models (VLMs), including vision-language pre-trained models (VLPMs) and multimodal large language models (MLLMs). Traditional adversarial attacks are example-specific and rely on specific datasets. This practice suffers from low transferability and additional computation cost, while universal adversarial perturbations (UAPs) offer example-agnostic solutions by generalizing across inputs. However, current UAP methods mainly target VLPMs, demonstrating limited transferability and effectiveness in MLLMs. To bridge this gap, we propose the Recursive Perturbation Attack (RPA), a novel black-box UAP method for both VLPMs and MLLMs. RPA employs a recursive perturbations strategy, utilizing token filtering and polynomial sampling methods to generate perturbations, thereby achieving incremental disruption and enhancing the transferability of the attack. To further enhance the effectiveness of the attack, RPA integrates a three-tier modality decoupling strategy, disentangling intra-modal, cross-modal, and fusion-modal features to effectively disrupt feature alignment and interactions. Extensive experiments validate that RPA achieves superior attack performance compared to existing UAP approaches. This work highlights new security concerns in multimodal AI systems and provides insights into the design of more robust models. Code is available at https://github.com/chilljudaoren/RPAttack. Yaguan Qian, Qiqi Bao 0001, Chang Zong, Fei Yu 0012, Shouling Ji, Bin Wang 0062, Zhaoquan Gu, Zhen Lei 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 7 |
| 2026 | Part-Based Feature Complementary Denoising for Unsupervised Person Re-Identification
Qing Tian 0001, Bin Wang 0062, Jiashuo Shen, Keyang Cheng, Weihua Ou, Zhen Lei 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 2 |
| 2026 | Exploiting Shared Adversarial Features for Dynamic Attacks in Large Vision-Language ModelsabstractWith the rapid development of Large Language Models (LLMs), an increasing number of Large Visual-Language Models (LVLMs) have achieved unprecedented performance in response generation. Recent work shows that LVLMs are vulnerable to adversarial attacks. However, many existing methods tend to overfit to the source model by overemphasizing specific features, which compromises their transferability. Other approaches suffer from reduced attack effectiveness due to insufficient differentiation between features. In this paper, we propose a novel transfer-based black-box untargeted attack—Shared Adversarial Feature (SAF) dynamic attack. By exploring the feature extraction patterns of LVLMs, we identify the features shared among various models that are most susceptible to adversarial attacks and disrupt them. Moreover, due to the powerful attention mechanisms of LVLMs, they are still able to extract similar semantics from perturbed images, even when primary features are disrupted. We design a dynamic update strategy to address this challenge. Finally, from the perspective of SAF, we conduct an in-depth analysis of vulnerabilities in the vision encoder and projector within LVLMs and find that attacking the projector exhibits stronger transferability across heterogeneous model architectures. Extensive experiments show that our method exhibits superior attack performance compared to existing methods across different models, datasets, and tasks. The code will be publicly available after publication. Yaguan Qian, Xucheng Zhu, Qiqi Bao 0001, Fei Yu 0012, Shouling Ji, Zhaoquan Gu, Wei Wang 0012, Bin Wang 0062, Zhen Lei 0001 |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2026 | Individual and Common Attack: Enhancing Transferability in VLP Models Through Modal Feature ExploitationabstractVision-Language Pretrained (VLP) models exhibit strong multimodal understanding and reasoning capabilities, finding wide application in tasks such as image-text retrieval and visual grounding. However, they remain highly vulnerable to adversarial attacks, posing serious reliability concerns in safety-critical scenarios. We observe that existing adversarial examples optimization methods typically rely on individual features from the other modality as guidance, causing the crafted adversarial examples to overfit that modality's learning preferences and thus limiting their transferability. In order to further enhance the transferability of adversarial examples, we propose a novel adversarial attack framework, I&CA (Individual & Common feature Attack), which simultaneously considers individual features within each modality and common features cross-modal interactions. Concretely, I&CA first drives divergence among individual features within each modality to disrupt single-modality learning, and then suppresses the expression of common features during cross-modal interactions, thereby undermining the robustness of the fusion mechanism. In addition, to prevent adversarial perturbations from overfitting to the learning bias of the other modality, which may distort the representation of common features, we simultaneously introduce augmentation strategies to both modalities. Across various experimental settings and widely recognized multimodal benchmarks, the I&CA framework achieves an average transferability improvement of 6.15% over the state-of-the-art DRA method, delivering significant performance gains in both cross-model and cross-task attack scenarios. Yaguan Qian, Yaxin Kong, Qiqi Bao 0001, Zhaoquan Gu, Bin Wang 0062, Shouling Ji, Zhen Lei 0001 |
IEEE Trans. Image Process. | 5 |
| 2025 | From Risk to Resilience: Towards Assessing and Mitigating the Risk of Data Reconstruction Attacks in Federated Learning
Xiangrui Xu 0001, Zhize Li 0001, Yufei Han 0001, Bin Wang 0062, Jiqiang Liu, Wei Wang 0012 |
USENIX Security Symposium | 4 |
| 2025 | Evading backdoor defenses: Concealing genuine backdoors through scapegoat strategy
Yaguan Qian, Zejie Lian, Yiming Li 0004, Wei Wang 0012, Zhaoquan Gu, Bin Wang 0062, Yanchun Zhang |
Comput. Secur. | 6 |
| 2025 | Unveiling the veil: high-frequency components as the key to understanding medical DNNs' vulnerability to adversarial examplesabstractAbstract Deep Neural Networks (DNNs) have demonstrated outstanding performance in various medical image processing tasks. However, recent studies have revealed a heightened vulnerability of medical DNNs to adversarial attacks compared to their natural counterparts. In this work, we present a novel perspective by analyzing the disparities between medical datasets and natural datasets, specifically focusing on the dataset collection process. Our analysis uncovers unique differences in the data distribution across different image classes in medical datasets, a phenomenon absent in natural datasets. To gain deeper insights into medical datasets, we employ Fourier analysis tools to investigate medical DNNs. Intriguingly, we discover that high-frequency components in medical images exhibit stronger associations with corresponding labels compared to those in natural datasets. These high-frequency components distract the attention of medical DNNs, rendering them more susceptible to adversarial images. To mitigate this vulnerability, we propose a preprocessing technique called Removing High-frequency Components (RH) training. Our experimental results demonstrate that the application of RH training significantly enhances the robustness of medical DNNs against adversarial attacks. Notably, in certain scenarios, RH training even outperforms traditional adversarial training methods, particularly when subjected to black-box attacks. Yaguan Qian, Renhui Tao, Huabin Du, Bin Wang 0062 |
Cybersecur. | 4 |
| 2025 | Enhancing robust generalization through appropriate adversarial example attack intensityabstractDeep Neural Networks (DNNs) are notoriously susceptible to adversarial examples. To mitigate the impact of well-designed adversarial attacks on network models, researchers have developed various defense mechanisms, among which adversarial training has emerged as one of the most effective strategies to date. Adversarial training aims to augment training data with adversarial examples, thus giving DNNs a certain degree of robustness to defend against adversarial attacks. However, while obtaining adversarial robustness, this method comes at the cost of reducing the generalization performance, manifested in the reduced classification effect of clean test datasets. Researchers have been actively seeking to counter the balance between adversarial robustness and model generalization. We believe that the key to balancing these two aspects lies in identifying appropriate adversarial examples. Overly potent examples can lead to a decline in clean accuracy, whereas weaker examples may offer limited robustness. Based on our analysis, a new adversarial example generation algorithm called Denoising Projection Gradient Descent (DPGD) was proposed. DPGD adds a purification module and a constraint in generating adversarial examples, the former is used to limit the influence of too strong adversarial examples on model training and the latter is used to ensure the necessary attack intensity. Combining DPGD with the framework of traditional adversarial training, we obtain the Diffusion Adversarial Training (DifAT) approach. To verify the effectiveness of our proposed method, we conducted extensive experiments on benchmark datasets, including CIFAR-10, CIFAR-100, and Tiny-Imagenet. Our results demonstrate the effectiveness of DifAT in improving the robustness of DNNs while maintaining or even improving their generalization performance. Xiaoguo Ding, Liangjian Zhang, Qiqi Bao 0001, Yaguan Qian, Bin Wang 0062, Zhaoquan Gu, Yanchun Zhang |
Neurocomputing | 5 |
| 2025 | CIFFormer: A Contextual Information Flow Guided Transformer for colorectal polyp segmentation
Cunlu Xu, Long Lin, Bin Wang 0062, Jun Liu 0001 |
Neurocomputing | 3 |
| 2025 | Adversarial training via multi-guidance and historical memory enhancement
Yaguan Qian, Bin Wang 0062, Zhaoquan Gu, Shouling Ji, Wei Wang 0012, Yanchun Zhang |
Neurocomputing | 3 |
| 2025 | CustomFair: A Customized Fairness Method for Federated Recommender Systems in Social Internet of ThingsabstractIn the Social Internet of Things (SIoT), edge computing integrates artificial intelligence to learn intricate relationships. The scale and complexity of SIoT cause a data explosion from diverse objects, hindering tailored services to users who own objects. Moreover, conventional edge computing in SIoT depends on centralized data collection, raising concerns about data privacy. To address the above two issues, federated recommender systems (FRSs) present a promising solution. FRSs can provide SIoT services to users and train a shared model while retaining sensitive data locally on objects. However, as FRSs are driven by data, they are inherently susceptible to algorithmic bias, raising substantial fairness concerns that have attracted considerable attention in SIoT. Recent fairness studies predominantly concentrate on a single sensitive attribute for users, thereby overlooking their autonomy. Therefore, we propose CustomFair, a personalized fairness framework that enables users in FRSs to select preferred sensitive attributes and acquire satisfied recommendation services in SIoT scenarios. First, we define customized fairness to ensure group fairness based on users’ sensitive attributes. The server segments users into subgroups in a privacy-preserving manner. Second, CustomFair employs the DynBalance method with a flexible regularization coefficient to improve recommendation performance and utilizes the AdaptEpoch strategy to achieve fairness. Extensive experiments indicate that CustomFair improves recommendation performance by 0.1–42.92 and enhances fairness by reducing disparities of 0.03–5.41 compared to two baselines across three datasets. Chao Li 0023, Zihang Yin, Bin Wang 0062, Tao Li 0022, Xuhua Bao, Wei Wang 0012 |
IEEE Internet Things J. | 7 |
| 2025 | MalAE: A Feature-Optimized and Autoencoder Ensemble-Based Method for IoT Malware ClassificationabstractIn the landscape of the Internet of Things (IoT), the rapid evolution and diverse obfuscation tactics of malware render it challenging to detect and identify effectively, posing significant threats to network security. Signature or heuristic methods rely on fixed feature recognition, making it challenging to handle new variants. Recent research has proposed deep learning techniques that utilize static analysis of bytes and images or dynamic analysis of APIs. However, these methods are effective only on samples from the same platform or lead to a dimensional explosion due to excessive irrelevant obfuscation, rendering them inadequate for managing complex cross-platform malware. In this work, we propose a novel lightweight cross-platform malware classification system called MalAE. This system employs a global-local particle swarm optimization algorithm to mine frequent features, adaptively identifying distinct family characteristics and efficiently recognizing variants. An ensemble of autoencoders integrates comprehensive file features and cross-platform basic block features from various perspectives and feature spaces, compressing high-dimensional data into a low-dimensional latent space. This approach preserves essential information, captures nonlinear complex relationships, and facilitates the rapid classification of intricate cross-platform samples. Evaluations conducted on two different datasets demonstrate that MalAE reduces the original feature dimensions by approximately 70% while also enhancing accuracy. Compared to state-of-the-art methods, MalAE achieves superior results, attaining an accuracy of 97.72%. Chengrun He, Honghui Fan, Lihua Yin, Haonan Yan, Hui Li 0006, Bin Wang 0062 |
IEEE Internet Things J. | 7 |
| 2025 | Enhancing Privacy in Distributed Intelligent Vehicles With Information Bottleneck TheoryabstractVertical federated learning (VFL) shows promise for enabling collaborative learning among Internet of Vehicle systems (IoVs) without requiring the sharing of private training data. However, existing work has exposed VFL’s vulnerability to privacy-stealing attacks, where an honest but curious server might reconstruct a client’s raw data from client-uploaded embeddings. In this work, we first elucidate the intrinsic mechanisms of privacy attacks from an information theory perspective, which provides a solid foundation for potential defensive strategies. Based on our findings, we introduce PriVFL, a defense mechanism based on information bottleneck theory. PriVFL is designed to safeguard the privacy of VFL-based IoVs by enabling shared embeddings to extract minimal information from input data, while preserving the information essential to target labels. Specifically, PriVFL restricts the information contained in embeddings by reducing the upper bound of mutual information between the raw samples and embeddings uploaded from local clients. Meanwhile, PriVFL ensures the effectiveness of the model by increasing the mutual information lower bound between embeddings and samples’ labels. Our evaluation includes 5 benchmark data sets and 4 different models. Experimental results demonstrate that PriVFL effectively mitigates privacy attacks while preserving the model’s effectiveness. These findings underscore that PriVFL can significantly enhance the privacy of VFL-based IoVs, thereby bolstering the development of practical IoV applications. Xiangrui Xu 0001, Pengrui Liu, Wei Wang 0012, Yongsheng Zhu, Chongzhen Zhang, Bin Wang 0062, Jian Shen 0001, Zhen Han 0001 |
IEEE Internet Things J. | 8 |
| 2025 | DMRP: Privacy-Preserving Deep Learning Model with Dynamic Masking and Random Permutation
Chongzhen Zhang, Zhiwang Hu, Xiangrui Xu 0001, Bin Wang 0062, Jian Shen 0001, Tao Li 0022, Baigen Cai, Wei Wang 0012 |
J. Inf. Secur. Appl. | 5 |
| 2025 | Enhancing robustness of backdoor attacks on real-world object detection systemsabstractDeep neural networks (DNNs) find extensive applications, including object detection in various security domains. However, these DNN models are susceptible to backdoor attacks. While significant research has been conducted on backdoor attacks in classified models, limited attention has been given to object detection models. Previous studies have predominantly focused on backdoor attacks in digital environments, overlooking real-world implications. Notably, the efficacy of backdoor attacks in real-world scenarios can be significantly influenced by physical factors such as distance and illumination. In this article, we introduce a variable-size backdoor trigger designed to accommodate objects of different sizes, mitigating disruptions arising from varying distances between the viewing point and the targeted object. Additionally, we propose malicious adversarial training for backdoor training, enabling the backdoor object detector to learn trigger features amidst physical noise. Experimental results demonstrate that our robust backdoor attack (RBA) enhances the success rate of attacks in real-world settings. Yaguan Qian, Boyuan Ji, Zejie Lian, Renhui Tao, Yaxin Kong, Bin Wang 0062, Wei Wang 0012 |
J. Comput. Secur. | 6 |
| 2025 | Enhancing transferability of targeted adversarial examples through amplitude spectrum alignment
Yaguan Qian, Jiaqiang Sha, Bin Wang 0062, Zhaoquan Gu, Yanchun Zhang |
Multim. Syst. | 3 |
| 2025 | FairReward: Towards Fair Reward Distribution Using Equity Theory in Blockchain-Based Federated LearningabstractEnsuring fairness in incentive mechanisms for federated learning (FL) is essential to attracting high-quality clients and building a sustainable FL ecosystem. Most existing fairness-aware incentive mechanisms distribute rewards to FL clients by quantifying their contributions to the performance of the global model. Essentially, these mechanisms pursuecontribution fairness, namely a constant contribution-reward ratio across FL clients, with an implicit assumption that clients would be satisfied with thecontribution fairness. However, research in social psychology has confirmed that this assumption may not hold in many real-world scenarios. According to equity theory proposed by Adams, an individual’s assessment and perception of receiving fair treatment significantly depend on the input-outcome ratio, where outcome simply refers to the rewards, while input is far more complex because it involves a bunch of subtle factors such as enthusiasm, experience and tolerance as well as the estimated contributions. Inspired by Adams’ equity theory, in this work, we expand the notion ofcontribution fairnesstoinput fairnessand propose a new fairness-aware incentive mechanism namedFairRewardthat distributes rewards under the joint consideration of self-reported inputs and computed contributions.FairRewardemploys a reputation mechanism to enhance the credibility of self-reported inputs and leverages blockchains to eliminate the need of a trusted FL server and monetarily incentivize/penalize clients. In addition,FairRewardadopts techniques including distributed differential privacy and locality-sensitive hashing to address privacy and non-IID issues in FL. Moreover, we conduct a comprehensive security and privacy analysis. Finally, we evaluateFairRewardthrough extensive experiments. The comprehensive experimental results demonstrate thatFairRewardis effective, scalable and attack-resistant, and provides theinput fairnessrequired. Chao Li 0023, Wei Wang 0012, Bin Wang 0062, Zhen Han 0001, Xiangliang Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | CoBA: Collusive Backdoor Attacks With Optimized Trigger to Federated LearningabstractConsiderable efforts have been devoted to addressing distributed backdoor attacks in federated learning (FL) systems. While significant progress has been made in enhancing the security of FL systems, our study reveals that there remains a false sense of security surrounding FL. We demonstrate that colluding malicious participants can effectively execute backdoor attacks during the FL training process, exhibiting high sparsity and stealthiness, which means they can evade common defense methods with only a few attack iterations. Our research highlights this vulnerability by proposing aCollusiveBackdoorAttack namedCoBA.CoBAis designed to enhance the sparsity and stealthiness of backdoor attacks by offering trigger tuning to facilitate learning of backdoor training data, controlling the bias of malicious local model updates, and applying the projected gradient descent technique. By conducting extensive empirical studies on 5 benchmark datasets, we make the following observations: 1)CoBAsuccessfully circumvents 15 state-of-the-art defense methods for robust FL; 2) Compared to existing backdoor attacks,CoBAconsistently achieves superior attack performance; and 3)CoBAcan achieve persistent poisoning effects through significantly sparse attack iterations. These findings raise substantial concerns regarding the integrity of FL and underscore the urgent need for heightened vigilance in defending against such attacks. Xiaoting Lyu, Yufei Han 0001, Wei Wang 0012, Jingkai Liu, Bin Wang 0062, Kai Chen 0012, Yidong Li, Jiqiang Liu, Xiangliang Zhang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | A Multimodal Adversarial Attack Method via Frequency Domain Enhancement and Fine-Grained Cross-Modal GuidanceabstractVision-language pretraining (VLP) models have demonstrated outstanding performance in image-text understanding tasks but remain highly susceptible to transferable adversarial attacks. While ensemble-based guided attacks improve adversarial transferability by increasing the diversity of image-text pairs, they primarily rely on spatial-domain data augmentation, which can lead to model overfitting to image details and limit the generalization capability of attacks. To address this limitation, this study proposes a frequency-domain adjustment-based adversarial attack method that modifies specific frequency components of input images to reduce detail interference and enhance the stability of adversarial examples. Additionally, a fine-grained feature extraction technique is introduced to optimize image-text alignment, further improving the transferability of cross-modal attacks. Experimental results demonstrate that the proposed method achieves superior attack transferability and generalization performance across two major VLP architectures, fusion models and alignment models, as well as multiple tasks on the Flickr30 K and MSCOCO datasets. Yaguan Qian, Qinqin Yu, Qiqi Bao 0001, Shouling Ji, Wei Wang 0012, Bin Wang 0062, Zhaoquan Gu, Zhen Lei 0001 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2025 | Finding the PISTE: Towards Understanding Privacy Leaks in Vertical Federated Learning SystemsabstractVertical Federated Learning (VFL) is a collaborative learning paradigm where participants share the same sample space while splitting the feature space. In VFL, local participants host their bottom models for feature extraction and collaboratively train a classifier by exchanging intermediate results with the server owning the labels. Both local training data and bottom models contain privacy-sensitive information and are considered the intellectual property of each participant, and thus should be protected by the design of VFL. Our study exposes the fundamental susceptibility of VFL systems to privacy leaks, which arise from the collaboration between the server and clients during both training and testing. Based on our findings, we proposePISTE, a model-agnostic framework of privacy stealing attacks against VFL. PISTE delivers three privacy inference attacks, i.e., model stealing, data reconstruction, and property inference attacks on five benchmark datasets and four different model architectures. We further discuss four potential countermeasures. Experimental results show that all of them cannot prevent all three privacy stealing attacks in PISTE. In summary, our study demonstrates the inherent yet rarely uncovered vulnerability of VFL on leaking data and model privacy. Xiangrui Xu 0001, Wei Wang 0012, Bin Wang 0062, Chao Li 0023, Zhen Han 0001, Yufei Han 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | A Proactive Defense Against Model Poisoning Attacks in Federated LearningabstractModel poisoning attacks greatly jeopardize the application of federated learning (FL). The effectiveness of existing defenses is susceptible to the latest model poisoning attacks, leading to a decrease in prediction accuracy. Besides, these defenses are intractable to distinguish benign outliers from malicious gradients, which further compromises the model generalization. In this work, we propose a novel proactive defense named${\sf RECESS}$against model poisoning attacks. Different from the passive analysis in previous defenses,${\sf RECESS}$proactively queries each participating client with a delicately constructed aggregation gradient, accompanied by the detection of malicious clients according to their responses with higher accuracy. Furthermore, RECESS uses a new trust scoring mechanism to robustly aggregate gradients. Unlike previous methods that score each iteration, RECESS considers clients’ performance correlation across multiple iterations to estimate the trust score, substantially increasing fault tolerance. Finally, we extensively evaluate${\sf RECESS}$on typical model architectures and four datasets under various settings. We also evaluated the defensive effectiveness against other types of poisoning attacks, the sensitivity of hyperparameters, and adaptive adversarial attacks. Experimental results show the superiority of${\sf RECESS}$in terms of reducing accuracy loss caused by the latest model poisoning attacks over five classic and two state-of-the-art defenses. Haonan Yan, Chengbo Zheng, Qian Chen 0032, Bin Wang 0062, Hui Li 0006, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | VFLMonitor: Defending One-Party Hijacking Attacks in Vertical Federated LearningabstractVertical Federated Learning (VFL) is susceptible to various one-party hijacking attacks, such as Replay and Generation attacks, where a single malicious client can manipulate the model to produce attacker-specified results, thereby compromising its reliability in real-world deployments. In this paper, we first uncover the underlying mechanisms of these attacks and observe that successful attacks induce significant discrepancies in the embedding-label associations across different clients. We establish a theoretical framework demonstrating how these discrepancies can serve as reliable indicators for detecting hijacking attempts. Building upon this insight, we propose VFLMonitor, a robust defense mechanism that leverages these embedding-label discrepancies to detect and mitigate hijacking attacks. Specifically, VFLMonitor identifies suspicious queries by analyzing differences in label estimations from multiple clients and applies a majority voting rule to correct or filter out these malicious queries. Moreover, VFLMonitor introduces a novel regularization strategy during training to reduce intra-class variance in embeddings, thereby enhancing their discriminative power and improving defense effectiveness. Extensive experi21 ments were conducted on 5 real-world datasets against 2 different attack types under 3 attack scenarios. The results demonstrate that VFLMonitor can effectively identify and exclude potential hijacked requests in all types of one-party hijacking attacks, while maintaining a meager false positive rate for legitimate queries. Xiangrui Xu 0001, Yufei Han 0001, Yongsheng Zhu, Zhen Han 0001, Guangquan Xu, Bin Wang 0062, Shouling Ji, Wei Wang 0012 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | F$^{2}$2AT: Feature-Focusing Adversarial Training via Disentanglement of Natural and Perturbed PatternsabstractDeep neural networks (DNNs) are vulnerable to adversarial examples crafted by well-designed perturbations. This could lead to disastrous results on critical applications such as self-driving cars, surveillance security, and medical diagnosis. At present, adversarial training is one of the most effective defenses against adversarial examples. However, in traditional adversarial training, it is still difficult to achieve a good trade-off between clean accuracy and robustness since DNNs still learn spurious features. The intrinsic reason is that traditional adversarial training makes it difficult to fully learn core features from adversarial examples when noise and examples cannot be disentangled. In this paper, we disentangle the adversarial examples into natural and perturbed patterns by bit-plane slicing. We assume the higher bit-planes represent natural patterns and the lower bit-planes represent perturbed patterns, respectively. We propose Feature-Focusing Adversarial Training (F$^{2}$AT), which differs from previous work in that it enforces the model to focus on the core features from natural patterns and reduce the impact of spurious features from perturbed patterns. The experimental results demonstrated that the clean accuracy and adversarial robustness with our F$^{2}$AT can be significantly improved. Yaguan Qian, Zhaoquan Gu, Bin Wang 0062, Shouling Ji, Wei Wang 0012, Yanchun Zhang |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2024 | A Wolf in Sheep's Clothing: Practical Black-box Adversarial Attacks for Evading Learning-based Windows Malware Detection in the Wild
Xiang Ling 0001, Zhiyu Wu, Bin Wang 0062, JingZheng Wu, Shouling Ji, Tianyue Luo |
USENIX Security Symposium | 3 |
| 2024 | Adversarial perturbation denoising utilizing common characteristics in deep feature space
Jianchang Huang, Yinyao Dai, Bin Wang 0062, Zhaoquan Gu, Yaguan Qian |
Appl. Intell. | 4 |
| 2024 | BFS2Adv: Black-box adversarial attack towards hard-to-attack short texts
Qiang Li 0007, Hongbo Cao, Bin Wang 0062, Xuhua Bao, Yufei Han 0001, Wei Wang 0012 |
Comput. Secur. | 5 |
| 2024 | Robust filter pruning guided by deep frequency-features for edge intelligence
Yaguan Qian, Wenzhuo Huang, Qinqin Yu, Tengteng Yao, Xiang Ling 0001, Bin Wang 0062, Zhaoquan Gu, Yanchun Zhang |
Neurocomputing | 6 |
| 2024 | Adaptive Digital Twin Placement and Transfer in Wireless Computing Power NetworkabstractUnpredictable network dynamics, resource heterogeneity, and user mobility pose challenges to efficient resource allocation in mobile networks. Digital twins (DTs), providing timely expression of features and accurate digital representations, offers new possibilities to enhance the performance of mobile networks. However, the DT deployment and allocation of computing power during the construction of DT models may have detrimental effects on service quality. Wireless computing power networks (WCPNs), an emerging computing network architecture, can efficiently orchestrate the computing and networking resources of heterogeneous computing nodes, thereby providing efficient computing services. Based on this, we propose an architecture of WCPN-empowered DT systems and investigate the adaptive placement and transfer scheme for DTs. Considering the correlation among DTs of cooperating and computing entities (e.g., edge servers), we exploit the Shapley value of the cooperative game theory that fairly quantifies the contributions of the cooperating computing entities. To further cope with the time-varying characteristics of computing resource demands in mobile networks, with the powerful computational support of WCPN, we propose a DT transfer scheme based on Shapley value and double auction scheme. Numerical results show that the proposed scheme in this article outperforms benchmarks in terms of average latency, DT error, and resource utilization. Wen Sun 0004, Yan Zhang 0002, Bin Wang 0062 |
IEEE Internet Things J. | 7 |
| 2024 | Polyp-LVT: Polyp segmentation with lightweight vision transformers
Long Lin, Guangzu Lv, Bin Wang 0062, Cunlu Xu, Jun Liu 0001 |
Knowl. Based Syst. | 3 |
| 2024 | DeFiScanner: Spotting DeFi Attacks Exploiting Logic Vulnerabilities on BlockchainabstractWith the rapid development of decentralized financial (DeFi), the total value locked (TVL) in DeFi continues to increase. A big number of adversaries exploit logic vulnerabilities to attack DeFi applications for profit, such as flash loan attacks and price manipulation attacks. However, the current vulnerability detection tools for smart contracts cannot be directly used to detect the logic vulnerabilities generated by the combination of different protocols. How to characterize and detect DeFi attacks that exploited logic vulnerabilities is a big challenge. In this work, we propose a deep-learning-based attack detection system on DeFi, called DeFiScanner, in which we design a novel neural network that includes a global model, a local model, and a fusion model to characterize DeFi attacks. First, the unstructured emitted events are automatically and efficiently normalized. Second, the transaction-related features of normalized emitted events are enriched with the global model and the semantic features of emitted events are extracted with the local model. Finally, the transaction-related features and the semantic features of emitted events are fused efficiently with the fusion model to detect DeFi attacks. We collect a dataset that consists of 50 910 real-world DeFi transactions on Ethereum (ETH). The extensive experimental results demonstrate the effectiveness of DeFiScanner. The true positive rate (TPR) and the area under the receiver operating characteristic (ROC) curve of the system reach 0.91 and 0.97, respectively. Bin Wang 0051, Hongliang Ma, Bin Wang 0062, Chunhua Su, Wei Wang 0012 |
IEEE Trans. Comput. Soc. Syst. | 5 |
| 2024 | CODER: Protecting Privacy in Image Retrieval With Differential PrivacyabstractImage retrieval techniques can be easily abused to violate personal privacy with images containing individuals' sensitive information. For example, people's identity information can be inferred from their face photos. Therefore, images should be sanitized before being shared or transmitted. However, previous works on image privacy protection suffer from either no provable privacy protection or poor utility with privacy guarantee. In this work, we proposeCODER, a privacy protection mechanism in image retrieval, with provable privacy guarantee as well as improved utility. In particular,CODERachieves metric differential privacy and adopts a newly proposed distortion metric definition which measures the distance more precisely to improve utility. The novel distortion metric can be applied to an arbitrary k-dimensional metric space with stronger image privacy protection. We theoretically analyze the privacy guarantee and rigorous utility bound ofCODER. We also experimentally compare its performance with two state-of-the-art works on two widely used face datasets. The results show thatCODERsignificantly improves the utility of the protected images and demonstrates its superiority in terms of the privacy-utility trade-off over the compared works. Finally, we perform reliability verification on both discriminative and generative models to demonstrate the practicality ofCODER Haonan Yan, Wenjing Zhang 0002, Qian Chen 0032, Bin Wang 0062, Hui Li 0006, Xiaodong Lin 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Dr. Defender: Proactive Detection of Autopilot Drones Based on CSIabstractThe market for consumer drones is growing and drones are becoming ever more pervasive than before in our life. However, drones have also brought about severe privacy violations and even safety issues. Especially, drones with cameras can snap pictures or take private videos. Researchers have designed drone detection mechanisms by passively inspecting the radio frequency (RF) signal in the communication channel between a drone and its controller. However, passive detection solutions shall fail when drones are in autopilot mode without control signals from controllers. In this paper, we seek to detect autopilot drones that transmit no RF signals by developing a proactive detection system named Dr. Defender. To this end, we resort to the Wi-Fi signals prevalent at each house and propose a proactive drone detection mechanism. To facilitate the detection of drones with Wi-Fi, we first study the motion characteristics of drones, including the shifting, moving, and spinning of propellers that can uniquely represent a drone. Then we investigate the physical layer information of Wi-Fi signals, i.e., the channel state information (CSI), to reveal specific motions of a drone. Finally, we implement our CSI-based proactive drone detection system, which requires no signal transmission from a drone or its controller. We extensively validate the feasibility and performance of our solution under different distances and directions of drones relative to a window. Results show that Dr. Defender can accurately detect drones 10 meters away. Jiangyi Deng, Xiaoyu Ji 0001, Beibei Wang 0001, Bin Wang 0062, Wenyuan Xu 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Enhancing Transferability of Adversarial Examples Through Mixed-Frequency InputsabstractRecent studies have shown that Deep Neural Networks (DNNs) are easily deceived by adversarial examples, revealing their serious vulnerability. Due to the transferability, adversarial examples can attack across multiple models with different architectures, called transfer-based black-box attacks. Input transformation is one of the most effective methods to improve adversarial transferability. In particular, the attacks fusing other categories of image information reveal the potential direction of adversarial attacks. However, the current techniques rely on input transformations in the spatial domain, which ignore the frequency information of the image and limit its transferability. To tackle this issue, we propose Mixed-Frequency Inputs (MFI) based on a frequency domain perspective. MFI alleviates the overfitting of adversarial examples to the source model by considering high-frequency components from various kinds of images in the process of calculating the gradient. By accumulating these high-frequency components, MFI acquires a more steady gradient direction in each iteration, leading to the discovery of better local maxima and enhancing transferability. Extensive experimental results on the ImageNet-compatible datasets demonstrate that MFI outperforms existing transform-based attacks with a clear margin on both Convolutional Neural Networks (CNNs) and Vision Transformers (ViTs), which proves MFI is more suitable for realistic black-box scenarios. Yaguan Qian, Kecheng Chen, Bin Wang 0062, Zhaoquan Gu, Shouling Ji, Wei Wang 0012, Yanchun Zhang |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | FedComm: A Privacy-Enhanced and Efficient Authentication Protocol for Federated Learning in Vehicular Ad-Hoc NetworksabstractIn vehicular ad-hoc networks (VANET), federated learning enables vehicles to collaboratively train a global model for intelligent transportation without sharing their local data. However, due to dynamic network structure and unreliable wireless communication of VANET, various potential risks (e.g., identity privacy leakage, data privacy inference, model integrity compromise, and data manipulation) undermine the trustworthiness of intermediate model parameters necessary for building the global model. While existing cryptography techniques and differential privacy provide provable security paradigms, the practicality of secure federated learning in VANET is hindered in terms of training efficiency and model performance. Therefore, developing a secure and efficient federated learning in VANET remains a challenge. In this work, we propose a privacy-enhanced and efficient authentication protocol for federated learning in VANET, called FedComm. Unlike existing solutions, FedComm addresses the above challenge through user anonymity. First, FedComm enables vehicles to participate in training with unlinkable pseudonyms, ensuring both privacy preservation and efficient collaboration. Second, FedComm incorporates an efficient authentication protocol to guarantee the authenticity and integrity of model parameters originated from anonymous vehicles. Finally, FedComm accurately identifies and completely eliminates malicious vehicles in anonymous communication. Security analysis and verification with ProVerif demonstrate that FedComm enhances privacy and reliability of intermediate model parameters. Experimental results show that FedComm reduces the overhead of proof generation and verification by 67.38% and 67.39%, respectively, compared with the state-of-the-art authentication protocols used in federated learning. Jiqiang Liu, Bin Wang 0062, Wei Wang 0012, Bin Wang 0066, Tao Li 0022, Xiaobo Ma 0001, Witold Pedrycz |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Contract Theory Based Incentive Mechanism for Clustered Vehicular Federated LearningabstractClustered Vehicular Federated Learning (CVFL) can be used to improve traffic safety, increase traffic efficiency, and reduce vehicle carbon emissions. Therefore, it is extremely promising in intelligent transportation systems. However, in practice, it is difficult to accurately cluster vehicular clients with mobility according to data distribution. In addition, vehicular clients may be reluctant to contribute their computation and communication resources to perform learning tasks if the CVFL server does not give them proper incentives. In this paper, we would like to address the above issues. Specifically, considering the mobility of vehicular clients, we first propose a clustering method to cluster vehicular clients into several clusters based on the cosine similarity between the model gradient of local vehicular clients and the K-means method. Then, we design a set of optimal contracts specifically for the clusters, aiming to motivate them to select the optimal number of intra-cluster iterations for model training and give the closed-form solution to the contracts under the constraints of individual rationality, incentive compatibility, and task accuracy. The proposed contract theory based incentive mechanism not only effectively motivates every cluster, but also overcomes the information asymmetry problem to maximize the utility of the CVFL server. Finally, simulation results validate the effectiveness of the proposed clustering method and the designed contract. Haitao Zhao 0004, Wanli Wen, Wenchao Xia, Bin Wang 0062, Hongbo Zhu 0002 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2024 | Neighbor-Enhanced Representation Learning for Link Prediction in Dynamic Heterogeneous Attributed NetworksabstractDynamic link prediction aims to predict future connections among unconnected nodes in a network. It can be applied for friend recommendations, link completion, and other tasks. Network representation learning algorithms have demonstrated considerable effectiveness in various prediction tasks. However, most network representation learning algorithms are based on homogeneous networks and static networks for link prediction that do not consider rich semantic and dynamic information. Additionally, existing dynamic network representation learning methods neglect the neighborhood interaction structure of the node. In this work, we design a neighbor-enhanced dynamic heterogeneous attributed network embedding method (NeiDyHNE) for link prediction. In light of the impressive achievements of the heuristic methods, we learn the information of common neighbors and neighbors’ interaction in heterogeneous networks to preserve the neighbors proximity and common neighbors proximity. NeiDyHNE encodes the attributes and neighborhood structure of nodes as well as the evolutionary features of the dynamic network. More specifically, NeiDyHNE consists of the hierarchical structure attention module and the convolutional temporal attention module. The hierarchical structure attention module captures the rich features and semantic structure of nodes. The convolutional temporal attention module captures the evolutionary features of the network over time in dynamic heterogeneous networks. We evaluate our method and various baseline methods on the dynamic link prediction task. Experimental results demonstrate that our method is superior to baseline methods in terms of accuracy. Wei Wang 0012, Chongsheng Zhang, Weiping Ding 0001, Bin Wang 0062, Yaguan Qian, Zhen Han 0001, Chunhua Su |
ACM Trans. Knowl. Discov. Data | 5 |
| 2024 | Hierarchical Threshold Pruning Based on Uniform Response CriterionabstractConvolutional neural networks (CNNs) have been successfully applied to various fields. However, CNNs' overparameterization requires more memory and training time, making it unsuitable for some resource-constrained devices. To address this issue, filter pruning as one of the most efficient ways was proposed. In this article, we propose a feature-discrimination-based filter importance criterion, uniform response criterion (URC), as a key component of filter pruning. It converts the maximum activation responses into probabilities and then measures the importance of the filter through the distribution of these probabilities over classes. However, applying URC directly to global threshold pruning may cause some problems. The first problem is that some layers will be completely pruned under global pruning settings. The second problem is that global threshold pruning neglects that filters in different layers have different importance. To address these issues, we propose hierarchical threshold pruning (HTP) with URC. It performs a pruning step limited in a relatively redundant layer rather than comparing the filters' importance across all layers, which can avoid some important filters being pruned. The effectiveness of our method benefits from three techniques: 1) measuring filter importance by URC; 2) normalizing filter scores; and 3) conducting prune in relatively redundant layers. Extensive experiments on CIFAR-10/100 and ImageNet show that our method achieves the state-of-the-art performance on multiple benchmarks. Yaguan Qian, Bin Wang 0062, Xiang Ling 0001, Zhaoquan Gu, Haijiang Wang 0003, Shaoning Zeng, Wassim Swaileh |
IEEE Trans. Neural Networks Learn. Syst. | 4 |
| 2023 | Poisoning with Cerberus: Stealthy and Colluded Backdoor Attack against Federated LearningabstractAre Federated Learning (FL) systems free from backdoor poisoning with the arsenal of various defense strategies deployed? This is an intriguing problem with significant practical implications regarding the utility of FL services. Despite the recent flourish of poisoning-resilient FL methods, our study shows that carefully tuning the collusion between malicious participants can minimize the trigger-induced bias of the poisoned local model from the poison-free one, which plays the key role in delivering stealthy backdoor attacks and circumventing a wide spectrum of state-of-the-art defense methods in FL. In our work, we instantiate the attack strategy by proposing a distributed backdoor attack method, namely Cerberus Poisoning (CerP). It jointly tunes the backdoor trigger and controls the poisoned model changes on each malicious participant to achieve a stealthy yet successful backdoor attack against a wide spectrum of defensive mechanisms of federated learning techniques. Our extensive study on 3 large-scale benchmark datasets and 13 mainstream defensive mechanisms confirms that Cerberus Poisoning raises a significantly severe threat to the integrity and security of federated learning practices, regardless of the flourish of robust Federated Learning methods. Xiaoting Lyu, Yufei Han 0001, Wei Wang 0012, Jingkai Liu, Bin Wang 0062, Jiqiang Liu, Xiangliang Zhang 0001 |
AAAI | 5 |
| 2023 | LEA2: A Lightweight Ensemble Adversarial Attack via Non-overlapping Vulnerable Frequency RegionsabstractRecent work shows that well-designed adversarial examples can fool deep neural networks (DNNs). Due to their transferability, adversarial examples can also attack target models without extra information, called black-box attacks. However, most existing ensemble attacks depend on numerous substitute models to cover the vulnerable subspace of a target model. In this work, we find three types of models with non-overlapping vulnerable frequency regions, which can cover a large enough vulnerable subspace. Based on this finding, we propose a lightweight ensemble adversarial attack named LEA2, integrated by standard, weakly robust, and robust models. Moreover, we analyze Gaussian noise from the perspective of frequency and find that Gaussian noise is located in the vulnerable frequency regions of standard models. Therefore, we substitute standard models with Gaussian noise to ensure the use of high-frequency vulnerable regions while reducing attack time consumption. Experiments on several image datasets indicate that LEA2achieves better transferability under different defended models compared with extensive baselines and state-of-the-art attacks. Yaguan Qian, Shuke He, Jiaqiang Sha, Wei Wang 0012, Bin Wang 0062 |
ICCV | 6 |
| 2023 | Object-free backdoor attack and defense on semantic segmentation
Jiaoze Mao, Yaguan Qian, Jianchang Huang, Zejie Lian, Renhui Tao, Bin Wang 0062, Wei Wang 0012, Tengteng Yao |
Comput. Secur. | 6 |
| 2023 | Personalized Location Privacy Trading in Double Auction for Mobile CrowdsensingabstractMobile crowdsensing systems (MCSs) are widely used in data collection due to their flexible deployment and comprehensive coverage in many IoT scenarios (e.g., road condition monitoring). Recently, the difference between workers’ perception on location privacy has drawn researchers’ attention. The only privacy trading mechanism in MCSs has been designed, however, in a single auction and single-minded way. Realizing task requesters’ competition requirement and workers’ task preference variance, in this article, we are the first to propose a double MCS auction mechanism with a personalized location privacy incentive. Specifically, this article introduces the concept of privacy budget, allowing workers to decide how much location information to disclose to the platform to realize personalized location privacy protection. Besides, considering the heterogeneity of sensing tasks and the diversity of task selection, each worker is allowed to offer several bids for interested tasks and to perform a subset of tasks in a bid if wins. In addition, our auction mechanism enables the platform to select winning requesters and workers and achieve ideal sensing service accuracy. Extensive theoretical analysis and experiment results validate that the proposed mechanism satisfies budget balance, individual rationality, and 2-D-truthfulness. Hao Liu 0110, Xuewen Dong, Yulong Shen 0001, Bin Wang 0062 |
IEEE Internet Things J. | 6 |
| 2023 | Adversarial training in logit space against tiny perturbations
Xiaohui Guan, Qiqi Shao, Yaguan Qian, Tengteng Yao, Bin Wang 0062 |
Multim. Syst. | 5 |
| 2023 | Towards desirable decision boundary by Moderate-Margin Adversarial Training
Xiaoyu Liang 0003, Yaguan Qian, Jianchang Huang, Xiang Ling 0001, Bin Wang 0062, Chunming Wu 0001, Wassim Swaileh |
Pattern Recognit. Lett. | 5 |
| 2023 | CGIR: Conditional Generative Instance Reconstruction Attacks Against Federated LearningabstractData reconstruction attack has become an emerging privacy threat to Federal Learning (FL), inspiring a rethinking of FL's ability to protect privacy. While existing data reconstruction attacks have shown some effective performance, prior arts rely on different strong assumptions to guide the reconstruction process. In this work, we propose a novel Conditional Generative Instance Reconstruction Attack (CGIR attack) that drops all these assumptions. Specifically, we propose a batch label inference attack in non-IID FL scenarios, where multiple images can share the same labels. Based on the inferred labels, we conduct a “coarse-to-fine” image reconstruction process that provides a stable and effective data reconstruction. In addition, we equip the generator with a label condition restriction so that the contents and the labels of the reconstructed images are consistent. Our extensive evaluation results on two model architectures and five image datasets show that without the auxiliary assumptions, the CGIR attack outperforms the prior arts, even for complex datasets, deep models, and large batch sizes. Furthermore, we evaluate several existing defense methods. The experimental results suggest that pruning gradients can be used as a strategy to mitigate privacy risks in FL if a model tolerates a slight accuracy loss. Xiangrui Xu 0001, Pengrui Liu, Wei Wang 0012, Hongliang Ma, Bin Wang 0062, Zhen Han 0001, Yufei Han 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | DNS Rebinding Threat Modeling and Security Analysis for Local Area Network of Maritime Transportation SystemsabstractMaritime ships and ports have become increasingly digital and intelligent. While intelligent maritime transportation systems bring convenience to the maritime industry, ship operation and management are also confronted with network risks. The Internet of Things (IoT) installed in the shipborne network collects and monitors the environmental data of the whole ship. It uses the collected data to make decisions to control the ship. The threat of Local Area Network (LAN) of IoT in ships has become an emerging issue. The DNS rebinding attack is a typical attack, which can bypass firewalls and seriously threaten the marine network in security and privacy of the local IoT. DNS rebinding attacks are difficult to model and detect, due to their sophisticated characteristics. In this work, we define threat models of DNS rebinding attacks and propose an effective method for the detection of and the defense against these attacks. First, we define threat models for DNS rebinding attacks. We employ a Markov chain to model the process of DNS rebinding attacks. With the threat modeling, the attack behaviors are clearly characterized and the most relevant attributes are thus extracted. Second, we propose an effective method for the detection of DNS rebinding attacks in the marine transportation system. The detection method includes the initialization method and the verification method, which manages and verifies access permission of equipment information and the service interface of the IoT in the shipborn network. Finally, we simulate the DNS rebinding attacks on the marine IoT. We analyze and test the security and the performance of the initialization method and the verification method in the simulated environment. The extensive experimental results demonstrate that the IoT in marine networks is vulnerable to DNS rebinding. Our method is effective and efficient to detect and defend against DNS rebinding attacks. It thus secures security and privacy in the local IoT on shipboard. Xudong He 0002, Jian Wang 0015, Jiqiang Liu, Weiping Ding 0001, Zhen Han 0001, Bin Wang 0062, Jamel Nebhen, Wei Wang 0012 |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2023 | HGATE: Heterogeneous Graph Attention Auto-EncodersabstractGraph auto-encoder is considered a framework for unsupervised learning on graph-structured data by representing graphs in a low dimensional space. It has been proved very powerful for graph analytics. In the real world, complex relationships in various entities can be represented by heterogeneous graphs that contain more abundant semantic information than homogeneous graphs. In general, graph auto-encoders based on homogeneous graphs are not applicable to heterogeneous graphs. In addition, little work has been done to evaluate the effect of different semantics on node embedding in heterogeneous graphs for unsupervised graph representation learning. In this work, we propose a novel Heterogeneous Graph Attention Auto-Encoders (HGATE) for unsupervised representation learning on heterogeneous graph-structured data. Based on the consideration of semantic information, our architecture of HGATE reconstructs not only the edges of the heterogeneous graph but also node attributes, through stacked encoder/decoder layers. Hierarchical attention is used to learn the relevance between a node and its meta-path based neighbors, and the relevance among different meta-paths. HGATE is applicable to transductive learning as well as inductive learning. Node classification and link prediction experiments on real-world heterogeneous graph datasets demonstrate the effectiveness of HGATE for both transductive and inductive tasks. Wei Wang 0012, Xiaoyang Suo, Bin Wang 0062, Hao Wang 0003, Hongning Dai, Xiangliang Zhang 0001 |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2022 | Prevention of GAN-Based Privacy Inferring Attacks Towards Federated Learning
Hongbo Cao, Yongsheng Zhu, Yuange Ren, Bin Wang 0062, Mingqing Hu, Wanqi Wang, Wei Wang 0012 |
CollaborateCom (2) | 4 |
| 2022 | Filter Pruning via Feature Discrimination in Deep Neural Networks
Yaguan Qian, Bin Wang 0062, Xiaohui Guan, Zhaoquan Gu, Xiang Ling 0001, Shaoning Zeng, Haijiang Wang 0003, Wujie Zhou |
ECCV (21) | 4 |
| 2022 | Robust Network Architecture Search via Feature Distortion Restraining
Yaguan Qian, Shenghui Huang, Bin Wang 0062, Xiang Ling 0001, Xiaohui Guan, Zhaoquan Gu, Shaoning Zeng, Wujie Zhou, Haijiang Wang 0003 |
ECCV (5) | 3 |
| 2022 | MalGraph: Hierarchical Graph Neural Networks for Robust Windows Malware DetectionabstractWith the ever-increasing malware threats, malware detection plays an indispensable role in protecting information systems. Although tremendous research efforts have been made, there are still two key challenges hindering them from being applied to accurately and robustly detect malwares. Firstly, most of them represent executables with shallow features, but ignore their semantic and structural information. Secondly, they are primarily based on representations that can be easily modified by attackers and thus cannot provide robustness against adversarial attacks. To tackle the challenges, we present MalGraph, which first represents executables with hierarchical graphs and then uses an end-to-end learning framework based on graph neural networks for malware detection. In particular, a hierarchical graph consists of a function call graph that captures the interaction semantics among different functions at the inter-function level and corresponding control-flow graphs for learning the structural semantics of each function at the intra-function level. We argue the abstraction and hierarchy nature of hierarchical graphs makes them not only easy to capture rich structural information of executables, but also be immune to adversarial attacks. Evaluations show that MalGraph not only outperforms state-of-the-art malware detection, but also exhibits stronger robustness against adversarial attacks by a large margin. Xiang Ling 0001, Lingfei Wu 0001, Zhenqing Qu, Jiangyu Zhang, Tengfei Ma 0001, Bin Wang 0062, Chunming Wu 0001, Shouling Ji |
INFOCOM | 8 |
| 2022 | AWFC: Preventing Label Flipping Attacks Towards Federated Learning for Intelligent IoTabstractAbstract Centralized machine learning methods require the aggregation of data collected from clients. Due to the awareness of data privacy, however, the aggregation of raw data collected by Internet of Things (IoT) devices is not feasible in many scenarios. Federated learning (FL), a kind of distributed learning framework, can be running on multiple IoT devices. It aims to resolve the issues of privacy leakage by training a model locally on the client-side, other than on the server-side that aggregates all the raw data. However, there are still threats of poisoning attacks in FL. Label flipping attacks, typical data poisoning attacks in FL, aim to poison the global model by sending model updates trained by the data with mismatched labels. The central parameter aggregation server is hard to detect the label flipping attacks due to its inaccessibility to the client in a typical FL system. In this work, we are motivated to prevent label flipping poisoning attacks by observing the changes in model parameters that were trained by different single labels. We propose a novel detection method called average weight of each class in its associated fully connected layer. In this method, we detect label flipping attacks by identifying the differences of classes in the data based on the weight assignments in a fully connected layer of the neural network model and use the statistical algorithm to recognize the malicious clients. We conduct extensive experiments on benchmark data like Fashion-MNIST and Intrusion Detection Evaluation Dataset (CIC-IDS2017). Comprehensive experimental results demonstrated that our method has the detection accuracy over 90% for the identification of the attackers flipping labels. Zhuo Lv, Hongbo Cao, Yuange Ren, Bin Wang 0062, Cen Chen 0004, Nuannuan Li, Wei Wang 0012 |
Comput. J. | 5 |
| 2022 | FPMBot: Discovering the frequent pattern of IoT-botnet domain queries in large-scale network
Kexiang Qian, Muyijie Zhu, Lihua Yin, Bin Wang 0062 |
Comput. Commun. | 5 |
| 2022 | Visually imperceptible adversarial patch attacks
Yaguan Qian, Jiamin Wang 0003, Haijiang Wang 0002, Zhaoquan Gu, Bin Wang 0062, Shaoning Zeng, Wassim Swaileh |
Comput. Secur. | 5 |
| 2022 | CCUBI: A cross-chain based premium competition scheme with privacy preservation for usage-based insuranceabstractUsage-based insurance (UBI) provides reasonable vehicle insurance premiums based on vehicle usage and driving behavior. In general, there are three major issues in realizing intelligent UBI systems. First, UBI evaluation mechanisms are not auditable to drivers. Insurers may thus deliberately adjust the UBI premiums. Second, the process of collecting driving data by insurers may lead to serious privacy breaches. Third, forging safer driving data for reducing insurance premiums may cause economic losses for insurers. To address these challenges, in this study, we propose CCUBI, a cross-chain-based premium competition scheme with privacy preservation for intelligent UBI systems. We introduce tamper-resistant blockchain and smart contracts to construct credible insurance mechanisms. The cross-chain technology connects these blockchains in the entire network to form an open premium competition scheme. Vehicle owners can assess designated insurers by sharing historical data with them to get a suitable CCUBI plan. In addition, we propose a data aggregation method used for CCUBI analysis with privacy preservation. Vehicle owners only publish proofs of the driving data. Proofs can still maintain privacy and computability in cross-chain flows. Finally, we adopt roadside units to detect forged driving data. We conduct a detailed security analysis. Experimental results also demonstrate the efficiency of CCUBI. Longyang Yi, Bin Wang 0051, Hongliang Ma, Bin Wang 0062, Zhen Han 0001, Wei Wang 0012 |
Int. J. Intell. Syst. | 6 |
| 2022 | GAAT: Group Adaptive Adversarial Training to Improve the Trade-Off Between Robustness and AccuracyabstractAdversarial training is by far one of the most effective methods to improve the robustness of deep neural networks against adversarial examples. However, the trade-off between robustness and accuracy is still a challenge in adversarial training. Previous methods used adversarial examples with a fixed perturbation budget or specific perturbation budgets for each example, which is inefficient in improving the trade-off and lacks the ability to control the trade-off flexibly. In this paper, we show that the largest element of logit, [Formula: see text], can roughly represent the minimum distance between an example and its neighboring decision boundary. Thus, we propose group adaptive adversarial training (GAAT) that divides the training dataset into several groups based on [Formula: see text] and develops a binary search algorithm to determine the group perturbation budgets for each group. Using the group perturbation budgets to perform adversarial training can fine-tune the trade-off between robustness and accuracy. Extensive experiments conducted on CIFAR-10 and ImageNet-30 show that our GAAT can achieve a more perfect trade-off than TRADES, MMA, and MART. Yaguan Qian, Xiaoyu Liang 0003, Ming Kang 0006, Bin Wang 0062, Zhaoquan Gu, Chunming Wu 0001 |
Int. J. Pattern Recognit. Artif. Intell. | 4 |
| 2022 | EI-MTD: Moving Target Defense for Edge Intelligence against Adversarial AttacksabstractEdge intelligence has played an important role in constructing smart cities, but the vulnerability of edge nodes to adversarial attacks becomes an urgent problem. A so-called adversarial example can fool a deep learning model on an edge node for misclassification. Due to the transferability property of adversarial examples, an adversary can easily fool a black-box model by a local substitute model. Edge nodes in general have limited resources, which cannot afford a complicated defense mechanism like that on a cloud data center. To address the challenge, we propose a dynamic defense mechanism, namely EI-MTD. The mechanism first obtains robust member models of small size through differential knowledge distillation from a complicated teacher model on a cloud data center. Then, a dynamic scheduling policy, which builds on a Bayesian Stackelberg game, is applied to the choice of a target model for service. This dynamic defense mechanism can prohibit the adversary from selecting an optimal substitute model for black-box attacks. We also conduct extensive experiments to evaluate the proposed mechanism, and results show that EI-MTD could protect edge intelligence effectively against adversarial attacks in black-box settings. Yaguan Qian, Yankai Guo, Qiqi Shao, Jiamin Wang 0003, Bin Wang 0062, Zhaoquan Gu, Xiang Ling 0001, Chunming Wu 0001 |
ACM Trans. Priv. Secur. | 5 |
| 2021 | Task Distribution Offloading Algorithm Based on DQN for Sustainable Vehicle Edge NetworkabstractThe edge access component of the Internet of Vehicles has a high computational rate and energy consumption. This paper proposes a distribution offloading algorithm based on deep Q-learning network (DQN) to achieve the best latency and sustainable scheduling. Firstly, the computational tasks of various vehicles are prioritized using the analytic hierarchy process (AHP) to assign different weights to the task processing rate in order to establish a relationship model. Secondly, by introducing edge computing based on DQN, the task offloading model is established by using the weighted sum of task processing rate as the optimization goal, which realizes the long-term utility of offloading strategies. The performance evaluation results show that, when compared to the Q-learning algorithm, the proposed method can reduce the average task processing delay by 17%, effectively improving the sustainable task offload efficiency. Tianyi Feng, Bin Wang 0062, Haitao Zhao 0004, Tangwei Zhang, Jiawen Tang, Zhenkun Wang 0007 |
NetSoft | 2 |
| 2021 | Optimization of Multipath Transmission Path Scheduling Based on Forward Delay in Vehicle Heterogeneous NetworksabstractMultipath transmission has been widely used in vehicle heterogeneous networks. The diversity of interfaces will lead to differences in the characteristics of transmission paths. Different paths also have differences in parameters such as bandwidth and delay. Out of order will result in greatly reduced multipath transmission performance. In this paper, we propose a sustainable forward-delay-based multipath transmission path scheduling method for vehicular heterogeneous networks so as to solve the multipath transmission problem. The main idea of this method is to schedule data packets through the concurrent path according to the forward delay and throughput difference estimated by the sender. We conduct the simulation in NS-3. Simulation results show that, compared with the previous algorithm, our proposed algorithm can significantly reduce the out-of-order problem of data packets at the receiver. This algorithm improves overall system throughput and network utilization. In this way, sustainable path propagation is guaranteed. Bin Wang 0062, Haitao Zhao 0004 |
NetSoft | 2 |
| 2021 | OutletSpy: cross-outlet application inference via power factor correction signalabstractTrade secrets such as intellectual properties are the inherent values for firms. Although companies have exploited strict access management policies and isolated their networks from the public Internet, trade secrets are still vulnerable to side-channel attacks. Side-channels can reveal the computing processes of computers in forms of various physical signals such as light, electromagnetism, and even heat. Such side-channels can bypass the isolation mechanism and therefore bring about severe threats. However, existing side-channels can only perform well within a short-distance (e.g., less than 1 meter) due to the high attenuation of signals. In this paper, we seek to utilize the built-in power lines in a building and construct a power side-channel that enables remote, i.e., cross-outlet attack against trade secrets. To this end, we investigate the power factor correction (PFC) module inside the power supply units of commodity computers and find that the PFC signals observed from an outlet can precisely reveal the power consumption information of all the connected devices, even from the outlets in adjacent rooms. Based upon this insight, we design and implement OutletSpy, a power side-channel attack that can infer application launching from a remote outlet and therefore enjoys the stealthiness property. We validate and evaluate OutletSpy with a dataset under different background APPs, time variations and different locations. The experiment results show OutletSpy can infer the application launching with 98.25% accuracy. Juchuan Zhang, Xiaoyu Ji 0001, Yuehan Chi, Yi-Chao Chen 0001, Bin Wang 0062, Wenyuan Xu 0001 |
WISEC | 5 |
| 2021 | A Blockchain-Based IoT Cross-Domain Delegation Access Control MethodabstractThe collaborative demand in the Internet of Things (IoT) is becoming stronger. One of the collaborative challenges is the security of interoperability between different management domains. Although cross-domain access control mechanisms exist in IoT, the majority of them are based on a trusted third party. In addition, the heterogeneity of multidomain policies makes it difficult for authority delegation to satisfy the principle of least authority. In this paper, we propose a blockchain-based IoT cross-domain delegation access control method (CDDAC). The delegation-trajectory-on-blockchain strategy proposed enhances the scalability of the cross-domain delegation system. The presented multidomain delegation trajectory aggregation scheme supports the forensic analysis of the cross-domain delegation system. The performance of CDDAC is evaluated in the Ropsten, which is the Ethereum’s official public blockchain test network. The experimental results show that CDDAC has faster delegation verification speed and higher decision-making efficiency than existing work, demonstrating the lightweight and scalability of the method. Chao Li 0027, Fan Li 0019, Lihua Yin, Tianjie Luo, Bin Wang 0062 |
Secur. Commun. Networks | 5 |
| 2021 | SenCS: Enabling Real-time Indoor Proximity Verification via Contextual SimilarityabstractIndoor proximity verification has become an increasingly useful primitive for the scenarios where access is granted to the previously unknown users when they enter a given area (e.g., a hotel room). Existing solutions either rely on homogeneous sensing modalities shared by two parties or require additional human interactions. In this article, we propose a context-based indoor proximity verification scheme, called SenCS, to enable real-time autonomous access for mobile devices, utilizing the available heterogeneous sensors at the user side and at the room side. The intuition is that only when the user is within a room can sensors from both sides observe the same events in the room. Yet such a solution is challenging, because the events may not provide enough entropy within the required time and the heterogeneity in sensing modalities may not always agree on the sensed events. To overcome the challenges, we exploit the time intervals between successively human actions to create heterogeneous contextual fingerprints (HCF) at a millisecond level. By comparing the contextual similarity between the HCF s from both the room and user sides, SenCS accomplishes the indoor proximity verification. Through proof-of-concept implementation and evaluations on 30 participants, SenCS achieves an accuracy of 99.77% and an equal error rate (EER) of 0.23% across various hardware configurations. Chaohao Li, Xiaoyu Ji 0001, Bin Wang 0062, Kai Wang 0073, Wenyuan Xu 0001 |
ACM Trans. Sens. Networks | 3 |
| 2021 | A Novel Privacy-Preserving Mobile-Coverage Scheme Based on Trustworthiness in HWSNsabstractTo solve the problem of security deployment in a hybrid wireless sensor network, a novel privacy‐preserving mobile coverage scheme based on trustworthiness is proposed. The novel scheme can efficiently mitigate some malicious attacks such as eavesdropping and pollution and optimize the coverage of hybrid wireless sensor networks (HWSNs) at the same time. Compared with the traditional mobile coverage scheme, the security of data transmission and mobility are considered in the deployment of HWSNs. Firstly, our scheme can mitigate the eavesdropping attacks efficiently utilizing privacy‐preserving signature. Then, the trust mobile protocol based on the trustworthiness is used to defend the pollution attacks and improve the security of mobility. In privacy‐preserving signature, the hardness of discrete logarithm determines the degree of security of the privacy‐preserving signature. The correctness and effectiveness of signature algorithm are proven by the probabilities of the native messages which can be recovered and forged which is negligible. Furthermore, a mobile scheme based on the trustworthiness (MSTW) is proposed to optimize the network coverage and improve the security of mobility. Finally, the simulation compared with a previous algorithm is carried out, in which the communication overhead, computational complexity, and the coverage are given. The result of the simulation shows that our scheme has roughly the same network coverage as the previous schemes on the basis of ensuring the security of the data transmission and mobility. Chunyang Qi, Jie Huang 0016, Bin Wang 0062 |
Wirel. Commun. Mob. Comput. | 3 |
| 2020 | Spot evasion attacks: Adversarial examples for license plate recognition systems with convolutional neural networks
Yaguan Qian, Dan-feng Ma, Bin Wang 0062, Jun Pan 0004, Jiamin Wang 0003, Zhaoquan Gu, Jian-Hai Chen, Wujie Zhou, Jing-Sheng Lei |
Comput. Secur. | 3 |
| 2018 | D2FL: Design and Implementation of Distributed Dynamic Fault LocalizationabstractCompromised or misconfigured routers have been a major concern in large-scale networks. Such routers sabotage packet delivery, and thus hurt network performance. Data-plane fault localization (FL) promises to solve this problem. Regrettably, the path-based FL fails to support dynamic routing, and the neighbor-based FL requires a centralized trusted administrative controller (AC) or global clock synchronization in each router and introduces storage overhead for caching packets. To address these problems, we introduce a dynamic distributed and low-cost model, D2FL. Using random two-hop neighborhood authentication, D2FL supports volatile path without the AC or global clock synchronization. Besides, D2FL requires only constant tens of KB for caching which is independent of the packet transmission rate. This is much less than the cache size of DynaFL or DFL which consumes several MB. The simulations show that D2FL achieves low false positive and false negative rate with no more than 3 percent bandwidth overhead. We also implement an open source prototype and evaluate its effect. The result shows that the performance burden in user space is less than 10 percent with the dynamic sampling algorithm. Fanfu Zhou, Zhengwei Qi, Jianguo Yao 0002, Ruhui Ma, Bin Wang 0062, Athanasios V. Vasilakos, Haibing Guan |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2018 | Easy Path Programming: Elevate Abstraction Level for Network FunctionsabstractAs datacenter networks become increasingly programmable with proliferating network functions, network programming languages have emerged to simplify the program development of the network functions. While network functions exhibit high level abstraction over operations on the traffic flow and the interconnections among the operations, the existing languages usually require programming with detailed knowledge about the packet processing patterns at the switches. Such a mismatch between the program abstraction and development details makes developing network functions a nontrivial task. To solve the problem, this paper introduces the easy path programming (EP2) framework. EP2 offers a high-level abstraction to simplify the program design process of the network functions. EP2 also provides a language that captures the common properties of network functions and uses predicates and primitives as basic language components. Specifically, predicates describe when to handle a flow with a global view of the flow dynamics; and primitives describe how to choose a path for a specific flow. Furthermore, EP2 has its own runtime system to support the language and the abstraction model, especially to hide the low level packet-processing behavior at the data plane from the programmers. Throughout this paper, cases are given to illustrate the EP2 abstraction model, language details and benefits. The expressiveness of EP2, the potential overhead of the runtime system and the efficiency of the network functions generated by EP2 are evaluated. The results show that EP2 can achieve comparable performance while reducing programming efforts. Fei Chen 0009, Chunming Wu 0001, Xiaoyan Hong, Bin Wang 0062 |
IEEE/ACM Trans. Netw. | 4 |
| 2016 | A multipath resource updating approach for distributed controllers in software-defined network
Xiaochun Wu, Chunming Wu 0001, Chang-Ting Lin, Qiang Wu 0018, Bin Wang 0062 |
Sci. China Inf. Sci. | 5 |
| 2016 | A user mode CPU-GPU scheduling framework for hybrid workloads
Bin Wang 0062, Ruhui Ma, Zhengwei Qi, Jianguo Yao 0002, Haibing Guan |
Future Gener. Comput. Syst. | 1 |
| 2015 | A survey on data center networking for cloud computing
Bin Wang 0062, Zhengwei Qi, Ruhui Ma, Haibing Guan, Athanasios V. Vasilakos |
Comput. Networks | 1 |
| 2014 | Pinso: Precise Isolation of Concurrency Bugs via Delta TriagingabstractConcurrent programs are known to be difficult to test and maintain. These programs often fail because of concurrency bugs caused by non-deterministic interleavings among shared memory accesses. Even though a concurrency bug can be detected, it is still hard to isolate the root cause of the bug, due to the challenge in understanding the complex thread interleavings or schedules. In this paper, we propose a practical and precise isolation technique for concurrent bugs called Pinso that seeks to exploit the non-deterministic nature of concurrency bugs and accurately find the root causes of program error, to further help developers maintain concurrent programs. Pinso profiles runtime inter-thread interleavings based on a set of summarized memory access patterns, and then, isolates suspicious interleaving patterns in the triaging phase. Using a filtration-oriented scheduler, Pinso effectively eliminates false positives that are irrelevant to the bug. We evaluate Pinso with 11 real-world concurrency bugs, including single- and multi-variable violation, from sever/desktop concurrent applications (MySQL, Apache, and several others). Experiments indicate that our tool accurately isolates the root causes of all the bugs. Bo Liu 0001, Zhengwei Qi, Bin Wang 0062, Ruhui Ma |
ICSME | 3 |
| 2014 | Dynamic load distribution with hop-by-hop forwarding based on max-min one-way delay
Fei Chen 0009, Chunming Wu 0001, Bin Wang 0062, Yaguan Qian, Xiaochun Wu |
Sci. China Inf. Sci. | 3 |
| 2014 | A secure routing model based on distance vector routing algorithm
Bin Wang 0062, Chunming Wu 0001, Qiang Yang 0004, Pan Lai, Julong Lan |
Sci. China Inf. Sci. | 1 |
| 2013 | kMemvisor: flexible system wide memory mirroring in virtual environments
Bin Wang 0062, Zhengwei Qi, Haibing Guan, Haoliang Dong, Yaozu Dong |
HPDC | 1 |
| 2013 | Quality of service aware power management for virtualized data centers
Yongqiang Gao, Haibing Guan, Zhengwei Qi, Bin Wang 0062, Liang Liu 0010 |
J. Syst. Archit. | 4 |
| 2012 | Memvisor: Application Level Memory Mirroring via Binary TranslationabstractMemory failures are common in clusters, and their destructive effects (e.g., increasing downtime and losing data) make users suffer great loss. Current memory availability strategies mostly require extra expensive hardware. Software approaches based on check pointing technologies intend to reduce the expense, but their high overhead limits the practical usage. In this paper, we present a novel system called Memvisor to provide software mirrored memory for applications. Specifically, all memory write instructions are duplicated. Data written to memory are synchronized to backup space. If memory failures happen, Memvisor will recover the data from the backup space. Compared with traditional software approaches, the instruction-level synchronization lowers the probability of data loss and reduces backup overhead. The results show that even in the worst case, Memvisor outperforms the state-of-the-art software approaches. Haoliang Dong, Bin Wang 0062, Haiyang Sun 0003, Zhengwei Qi, Haibing Guan, Yaozu Dong |
CLUSTER | 3 |
| 2012 | SINOF: A dynamic-static combined framework for dynamic binary translation
Haibing Guan, Erzhou Zhu, Hongxi Wang, Ruhui Ma, Yindong Yang, Bin Wang 0062 |
J. Syst. Archit. | 6 |
| 2009 | Adjoint code generator
Jianwen Cao 0001, Bin Wang 0062 |
Sci. China Ser. F Inf. Sci. | 3 |