VLDB 2026 Research / reviewers in the wild / expert
Maozhen Zhang
dblp:135/7284
· DBLP profile ↗
10ranked-venue papers
4as first author
9since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Mitigating catastrophic overfitting in fast adversarial training via dynamic polyak weight averaging and gradient norm dual-penalty
Anjum Iqbal, Weiqiang Kong, Maozhen Zhang |
Neurocomputing | 4 |
| 2026 | Stealthy Backdoor Carriers: The Threat of Visual Prompts to CLIPabstractVisual Prompt (VP) learning has rapidly emerged as a popular paradigm for parameter-efficient task adaptation in CLIP-based models. However, while VP optimizes pixel-space vectors without altering CLIP’s internal weights, this decoupled design inadvertently introduces critical security vulnerabilities. Attackers can exploit VP to implant covert backdoors using imperceptible trigger patterns that bypass traditional anomaly detection mechanisms, posing significant risks to real-world applications. Existing backdoor techniques, however, rely on visually noticeable patterns and exhibit inconsistencies in representation alignment, which make them prone to detection and ineffective against robust defenses. In response to these limitations, we propose Stealthy Backdoor Carriers (SBC), a novel attack framework that leverages CLIP’s inherent vulnerabilities to covertly and persistently inject backdoors.SBCadopts a dual-constrained optimization strategy that balances imperceptibility—minimizing trigger perturbations for visual stealth—and cross-modal embedding alignment—ensuring poisoned and target samples share consistent representations within CLIP’s multimodal space. Experimental results across five benchmark datasets demonstrateSBC’s exceptional effectiveness, achieving a +49.63% improvement in attack success rate relative to existing methods while maintaining robustness against advanced defenses like Neural Cleanse. Our work highlights the need for reevaluating the security implications of VP learning frameworks and provides valuable insights for mitigating prompt-based vulnerabilities in AI systems. Our code is available at https://github.com/Maozhen-Zhang/sbc.git. Maozhen Zhang, Mengnan Zhao 0001, Wei Wang 0025, Bo Wang 0024 |
IEEE Internet Things J. | 1 |
| 2026 | AMF-CFL: Anomaly model filtering based on clustering in federated learning
Bo Wang 0024, Xiaorui Dai, Wei Wang 0025, Zhaoning Wang, Maozhen Zhang |
J. Inf. Secur. Appl. | 6 |
| 2026 | DualVeil: Persistent and invisible backdoor attacks in federated learning via dual optimization
Maozhen Zhang, Mengnan Zhao 0001, Wei Wang 0025, Bo Wang 0024 |
Knowl. Based Syst. | 1 |
| 2026 | Model Backdoor Attack on Federated Learning Based on Parameter AnalysisabstractWith the increasingly widespread application of federated learning (FL) in various fields, the issue of backdoor attacks against FL has garnered significant attention from both academia and industry. While there has been some progress in researching backdoor attacks against FL, data backdoor attacks are easily mitigated in federated environments, and model backdoor attacks are susceptible to detection by defense mechanisms. Therefore, we propose a refined backdoor attack method tailored for FL under the image classification task. Our method involves the collaborative operation of three key modules. Firstly, the parameter importance analysis module identifies parameters with minimal impact on model performance, and creates parameter importance masks to provide precise targets for subsequent operations. Subsequently, the activation difference computation module calculates the activation differences between backdoor samples and benign samples to locate trigger-sensitive parameters. Our method implants the backdoor by flipping and zeroing the precisely located layer parameters, while maintaining the model's classification performance on benign samples. Experimental results show that our method is feasible to achieve an average attack success rate more than 99% across the three victim models. This demonstrates the effectiveness of our method in FL environments and its robustness against various FL defense mechanisms. Bo Wang 0024, Maozhen Zhang, Wei Wang 0025, Hongwei Yao |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Robust clustering federated learning with trusted anchor clients
Maozhen Zhang, Fei Wei |
J. Inf. Secur. Appl. | 1 |
| 2021 | High-sensitivity synchronous image encryption based on improved one-dimensional compound sine mapabstractAbstract An improved one‐dimensional compound sine map is introduced. The evaluation of this chaotic system shows that it has high sensitivity and random chaotic behaviour. Based on this chaotic system, a new fast image encryption scheme is proposed. Through the cross‐processing of multiple chaotic sequences, two high‐sensitivity pseudo‐random sequences are generated, and the generated high‐sensitivity random sequence is used for synchronization cross‐processing in four directions. Using the symmetry of the image, the image is divided into four directions, and the processing of each direction is different based on the high‐sensitivity sequence and the chaotic value. Through one traversal, the entire image is processed four times differently. The encryption process is uncontrollable and invisible depending on the chaotic sequence. Simulation test results show that the algorithm has good encryption results, is sensitive to the initial secret key and provides satisfactory security capabilities compared with other algorithms. Xingyuan Wang 0001, Maozhen Zhang |
IET Image Process. | 2 |
| 2021 | An image encryption algorithm based on new chaos and diffusion values of a truth table
Xingyuan Wang 0001, Maozhen Zhang |
Inf. Sci. | 2 |
| 2021 | A new image encryption algorithm based on ladder transformation and DNA coding
Xingyuan Wang 0001, Maozhen Zhang |
Multim. Tools Appl. | 2 |
| 2013 | Impacts of Plot Location Errors on Accuracy of Mapping and Scaling Up Aboveground Forest Carbon Using Sample Plot and Landsat TM DataabstractCombining forest inventory plot and Landsat Thematic Mapper (TM) data has been widely used for mapping forest carbon. However, uncertainty analysis is a great challenge. This study investigated the uncertainties of mapping and scaling up aboveground forest carbon (AGFC) due to plot location errors in Wu-Yuan of East China. Plot location errors were simulated by randomly perturbing the location of each plot with eleven different distances that varied from 5 to 8000 m. Given a perturbed distance (PD) such as 100 m, a forest carbon map was created by combining and scaling up the plot and TM data from a spatial resolution of 28.5 m × 28.5 m to 969 m × 969 m using a sequential Gaussian block cosimulation algorithm. The maps obtained from the perturbed plot locations were compared with that from the true plot locations. The results showed that, as the plot location PD increased, the accuracy of predicted AGFC values decreased, but their spatial patterns (clustering of high and low values) remained until the PD of 800 m, slightly changed at the PD of 1600 m, looked more different at the PDs of 3000 and 5000 m, and became totally random at the PD of 8000 m. More importantly, it was found that scaling up the spatial data mitigated the impacts of plot location errors on the map accuracy compared to those without the up-scaling. Maozhen Zhang, Hui Lin 0004, Siqi Zeng 0003, Jiping Li, Junnan Shi, Guangxing Wang 0003 |
IEEE Geosci. Remote. Sens. Lett. | 1 |