VLDB 2026 Research / reviewers in the wild / expert
Xin Lou 0005
dblp:133/5204-5
· DBLP profile ↗
13ranked-venue papers
2as first author
7since 2021 · last 2026
0000-0001-8910-5666ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 8 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Resilient Path Tracking of Autonomous Driving under Few-shot Action Space AttacksabstractModern autonomous vehicles face growing cybersecurity risks, especially from action space attacks that directly target vehicle actuators. This article systematically evaluates the resilience of three representative Autonomous Driving (AD) architectures, including modular, end-to-end, and feature-fused agents, against few-shot action space attacks crafted via deep reinforcement learning under a black-box setting. The adversary perturbs the vehicle’s lateral control only during safety-critical moments, using either a camera or an inertial measurement unit. Our results reveal distinct vulnerabilities and behavioral patterns across AD architectures, which underscore the necessity for adaptive and robust defense strategies. However, existing adversarial training defense methods show limitations of overfitting and reliance on attack knowledge. To address these limitations, we propose a learning-based Path Correction System (PCS) that integrates traditional feedback control with an adversarially trained correction loop. The correction loop is selectively activated by a kinematic model-based attack detector to counteract abnormal control deviations. Evaluation experiments show that PCS reduces path-tracking deviation by 78% when the system is under attack. Xin Lou 0005, Rui Tan 0001, Zbigniew T. Kalbarczyk, Ravishankar K. Iyer |
ACM Trans. Cyber Phys. Syst. | 2 |
| 2026 | Invisible Adversarial Stripes on Traffic Sign: Threat and Defense for Autonomous Vehicles
Dongfang Guo, Xin Lou 0005, Rui Tan 0001 |
ACM Trans. Sens. Networks | 4 |
| 2025 | GiNet: Integrating Sequential and Context-Aware Learning for Battery Capacity PredictionabstractThe surging demand for batteries requires advanced battery management systems, where battery capacity modelling is a key functionality. In this paper, we aim to achieve accurate battery capacity prediction by learning from historical measurements of battery dynamics. We propose GiNet, a gated recurrent units enhanced Informer network, for predicting battery's capacity. The novelty and competitiveness of GiNet lies in its capability of capturing sequential and contextual information from raw battery data and reflecting the battery's complex behaviors with both temporal dynamics and long-term dependencies. We conducted an experimental study based on a publicly available dataset to showcase GiNet's strength of gaining a holistic understanding of battery behavior and predicting battery capacity accurately. GiNet achieves 0.11 mean absolute error for predicting the battery capacity in a sequence of future time slots without knowing the historical battery capacity. It also outperforms the latest algorithms significantly with 27% error reduction on average compared to Informer. The promising results highlight the importance of customized and optimized integration of algorithm and battery knowledge and shed light on other industry applications as well. Sara Sameer, Wei Zhang 0082, Xin Lou 0005, Qingyu Yan, Terence Goh, Yulin Gao |
VTC2025-Spring | 3 |
| 2024 | Invisible Optical Adversarial Stripes on Traffic Sign against Autonomous VehiclesabstractCamera-based computer vision is essential to autonomous vehicle's perception. This paper presents an attack that uses light-emitting diodes and exploits the camera's rolling shutter effect to create adversarial stripes in the captured images to mislead traffic sign recognition. The attack is stealthy because the stripes on the traffic sign are invisible to human. For the attack to be threatening, the recognition results need to be stable over consecutive image frames. To achieve this, we design and implement GhostStripe, an attack system that controls the timing of the modulated light emission to adapt to camera operations and victim vehicle movements. Evaluated on real testbeds, GhostStripe can stably spoof the traffic sign recognition results for up to 94% of frames to a wrong class when the victim vehicle passes the road section. In reality, such attack effect may fool victim vehicles into life-threatening incidents. We discuss the countermeasures at the levels of camera sensor, perception model, and autonomous driving system. Dongfang Guo, Yimin Dai, Xin Lou 0005, Rui Tan 0001 |
MobiSys | 5 |
| 2024 | Demo: Invisible Adversarial Stripes against Traffic Sign Recognition in Autonomous DrivingabstractCamera-based computer vision is crucial for autonomous vehicle perception. We demonstrate GhostStripe [5], an attack system that uses light-emitting diodes and exploits the camera's rolling shutter effect to generate adversarial stripes that are invisible to humans while misleading traffic sign recognition. To maintain stable attack effectiveness, GhostStripe controls the timing of the modulated light emission, adapting to both the camera's framing operation and the movement of the victim vehicle. Evaluated on real testbeds, GhostStripe can stably spoof traffic sign recognition results for up to 97% of frames to a wrong class when the victim vehicle passes the road section. Dongfang Guo, Yimin Dai, Xin Lou 0005, Rui Tan 0001 |
SenSys | 5 |
| 2021 | Compressing Large-Scale Transformer-Based Models: A Case Study on BERTabstractAbstract Pre-trained Transformer-based models have achieved state-of-the-art performance for various Natural Language Processing (NLP) tasks. However, these models often have billions of parameters, and thus are too resource- hungry and computation-intensive to suit low- capability devices or applications with strict latency requirements. One potential remedy for this is model compression, which has attracted considerable research attention. Here, we summarize the research in compressing Transformers, focusing on the especially popular BERT model. In particular, we survey the state of the art in compression for BERT, we clarify the current best practices for compressing large-scale Transformer models, and we provide insights into the workings of various methods. Our categorization and analysis also shed light on promising future research directions for achieving lightweight, accurate, and generic NLP models. Prakhar Ganesh, Yao Chen 0008, Xin Lou 0005, Mohammad Ali Khan, Yin Yang 0001, Hassan Sajjad 0001, Preslav Nakov, Deming Chen, Marianne Winslett |
Trans. Assoc. Comput. Linguistics | 3 |
| 2021 | On Lightweight Privacy-preserving Collaborative Learning for Internet of Things by Independent Random ProjectionsabstractThe Internet of Things (IoT) will be a main data generation infrastructure for achieving better system intelligence. This article considers the design and implementation of a practical privacy-preserving collaborative learning scheme, in which a curious learning coordinator trains a better machine learning model based on the data samples contributed by a number of IoT objects, while the confidentiality of the raw forms of the training data is protected against the coordinator. Existing distributed machine learning and data encryption approaches incur significant computation and communication overhead, rendering them ill-suited for resource-constrained IoT objects. We study an approach that applies independent random projection at each IoT object to obfuscate data and trains a deep neural network at the coordinator based on the projected data from the IoT objects. This approach introduces light computation overhead to the IoT objects and moves most workload to the coordinator that can have sufficient computing resources. Although the independent projections performed by the IoT objects address the potential collusion between the curious coordinator and some compromised IoT objects, they significantly increase the complexity of the projected data. In this article, we leverage the superior learning capability of deep learning in capturing sophisticated patterns to maintain good learning performance. Extensive comparative evaluation shows that this approach outperforms other lightweight approaches that apply additive noisification for differential privacy and/or support vector machines for learning in the applications with light to moderate data pattern complexities. Linshan Jiang, Rui Tan 0001, Xin Lou 0005, Guosheng Lin |
ACM Trans. Internet Things | 3 |
| 2020 | Identifying Failing Point Machines from Sensor-Free Train System LogsabstractA great many train systems worldwide are legacy systems, without modern sensors whose data can be mined to detect and predict failures. In this paper, we show how to support failure identification in a legacy system with no sensors, using alarm and natural-language described event logs as the only data sources. With too few failures in a mass of log data to train a traditional machine learning model, we propose a new approach called SA-HMM (Survival Analysis-Hidden Markov Model). After enriching the event logs with Word2vec, SA-HMM uses HMMs and survival analysis to identify failure trends in individual assets and failure tendencies in types of assets, respectively, then combines the two part in a weighted sum that indicates the priority of each asset for preventative maintenance. Our evaluation of SA-HMM with a large amount of urban train data shows that SA-HMM greatly outperforms naive method, HMM, and one-class SVM methods in terms of precision and recall in identifying failing assets, while also offering a tunable balance between those two aspects of performance. Xin Lou 0005, Binbin Chen 0001, Marianne Winslett, Zbigniew T. Kalbarczyk |
IEEE BigData | 2 |
| 2020 | Assessing and Mitigating Impact of Time Delay Attack: Case Studies for Power Grid ControlsabstractDue to recent cyber attacks on various cyber-physical systems (CPSes), traditional isolation based security schemes in the critical systems are insufficient to deal with the smart adversaries in CPSes with advanced information and communication technologies (ICTs). In this paper, we develop real-time assessment and mitigation of an attack's impact as a system's built-in mechanisms. We study a general class of attacks, which we call time delay attack, that delays the transmissions of control data packets in the CPS control loops. Based on a joint stability-safety criterion, we propose the attack impact assessment consisting of (i) a machine learning (ML) based safety classification, and (ii) a tandem stability-safety classification that exploits a basic relationship between stability and safety, namely that an unstable system must be unsafe whereas a stable system may not be safe. In this assessment approach, the ML addresses a state explosion problem in the safety classification, whereas the tandem structure reduces false negatives in detecting unsafety arising from imperfect ML. We apply our approach to assess the impact of the attack on power grid automatic generation control, and accordingly develop a two-tiered mitigation that tunes the control gain automatically to restore safety where necessary and shed load only if the tuning is insufficient. We also apply our attack impact assessment approach to a thermal power plant control system consisting of two PID control loops. A mitigation approach by tuning the PID controller is also proposed. Extensive simulations based on a 37-bus system model and a thermal power plant control system are conducted to evaluate the effectiveness of our assessment and mitigation approaches. Xin Lou 0005, Cuong Tran 0006, Rui Tan 0001, David K. Y. Yau, Zbigniew T. Kalbarczyk, Ambarish Kumar Banerjee, Prakhar Ganesh |
IEEE J. Sel. Areas Commun. | 1 |
| 2019 | Differentially Private Collaborative Learning for the IoT Edge
Linshan Jiang, Xin Lou 0005, Rui Tan 0001, Jun Zhao 0007 |
EWSN | 2 |
| 2019 | One-Hop Out-of-Band Control Planes for Multi-Hop Wireless Sensor NetworksabstractSeparation of Control and Data Planes (SCDP) is a desirable paradigm for low-power multi-hop wireless sensor networks requiring high network performance and manageability. Existing SCDP networks generally adopt an in-band control plane scheme in that the control-plane messages are delivered by their data-plane networks. The physical coupling of the two planes may lead to undesirable consequences. Recently, multi-radio platforms (e.g., TI CC1350 and OpenMote B) are increasingly available, which make the physical separation of the control and data planes possible. To advance the network architecture design, we propose to leverage on the long-range communication capability of the Low-Power Wide-Area Network (LPWAN) radios to form one-hop out-of-band control planes. LoRaWAN, an open, inexpensive, and ISM band based LPWAN radio, is chosen to prototype our out-of-band control plane called LoRaCP. Several characteristics of LoRaWAN such as downlink-uplink asymmetry and primitive ALOHA media access control need to be dealt with to achieve high reliability and efficiency. To address these challenges, a TDMA-based multi-channel transmission control is designed, which features an urgent channel and negative acknowledgment. On a testbed of 16 nodes, LoRaCP is applied to physically separate the control-plane network of the Collection Tree Protocol (CTP) from its Zigbee-based data-plane network. Extensive experiments show that LoRaCP increases CTP’s packet delivery ratio from 65% to 80% in the presence of external interference, while consuming a per-node average radio power of 2.97mW only. Chaojie Gu, Rui Tan 0001, Xin Lou 0005 |
ACM Trans. Sens. Networks | 3 |
| 2018 | One-Hop Out-of-Band Control Planes for Low-Power Multi-Hop Wireless NetworksabstractSeparation of control and data planes (SCDP) is a desirable paradigm for low-power multi-hop wireless networks requiring high network performance and manageability. Existing SCDP networks generally adopt an in-band control plane scheme in that the control-plane messages are delivered by their data-plane networks. The physical coupling of the two planes may lead to undesirable consequences. To advance the network architecture design, we propose to leverage on the long-range communication capability of the increasingly available low-power wide-area network (LPWAN) radios to form one-hop out-of-band control planes. We choose LoRaWAN, an open, inexpensive, and ISM band based LPWAN radio to prototype our out-of-band control plane called LoRaCP. Several characteristics of LoRaWAN such as downlink-uplink asymmetry and primitive ALOHA media access control (MAC) present challenges to achieving reliability and efficiency. To address these challenges, we design a TDMA-based multi-channel MAC featuring an urgent channel and negative acknowledgment. On a testbed of 16 nodes, we demonstrate applying LoRaCP to physically separate the control-plane network of the Collection Tree Protocol (CTP) from its ZigBee-based data-plane network. Extensive experiments show that LoRaCP increases CTP's packet delivery ratio from 65 % to 80 % in the presence of external interference, while consuming a per-node average radio power of 2.97mW only. Chaojie Gu, Rui Tan 0001, Xin Lou 0005, Dusit Niyato |
INFOCOM | 3 |
| 2017 | Cost of differential privacy in demand reporting for smart grid economic dispatchabstractIncreasing dynamics of electrical loads presents uncertainty and hence new challenges for power grid controls and optimization. In economic dispatch control (EDC) for minimizing generation cost, demand reporting by customers is a promising approach for managing the uncertainty, but it raises important privacy concerns. Adding random noise to aggregate queries of demand reports can provide differential privacy (DP) for the individual customers. But the noisy query results can adversely impact the EDC's optimality. In this paper, we analyze the privacy cost in demand reporting in terms of how DP-induced noise will increase the total generation cost. Our analysis shows that the noise amounts for different customers are intricately coupled with one another in determining the total cost. In view of the coupling, we apply the principle of Shapley value to attribute fair shares of the total cost to the power grid buses. For efficient sharing of the privacy cost, in a manner scalable to large power systems with many buses, we additionally propose heuristic algorithms to approximate the Shapley value. Trace-driven simulations based on a 5-bus power system model validate our analysis and illustrate the performance of the proposed cost sharing algorithms. Xin Lou 0005, Rui Tan 0001, David K. Y. Yau, Peng Cheng 0001 |
INFOCOM | 1 |