Teng Huang 0001

dblp:141/3868-1 · DBLP profile ↗
← Back
37ranked-venue papers
5as first author
34since 2021 · last 2025
0000-0001-7261-6398ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Databases, data management, data science and information retrieval · 15 · 2 first-author · 14 since 2021Artificial intelligence and machine learning · 12 · 12 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 1 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 6 since 2021Security and privacy · 5 · 1 first-author · 5 since 2021Computer networks · 3 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 CrossMiner: Smart Contract Vulnerability Detection in Interactive Scenarios
abstract
Vulnerability attacks targeting smart contracts have caused significant losses of digital assets. Many approaches based on static analysis, fuzzing, and deep learning have been proposed for detecting contract vulnerabilities. However, most existing methods only support vulnerability detection within individual contracts. When contracts interact with each other through external calls, these methods fail to perform effective cross-contract security analysis, leading to false negatives and false positives. To address these limitations, we propose CrossMiner, a deep learning-based approach for vulnerability detection in contract interaction scenarios. CrossMiner enables comprehensive risk assessment for cross-contract security through trace analysis of function call chains. Specifically, CrossMiner first constructs a cross-contract dependency graph based on function call chains to effectively model inter-contract dependencies and network dynamics, and collect semantic information about contract interactions. Then, it employs a heterogeneous graph neural network with a two-level attention mechanism to finely extract and integrate complex features from the dependency graph, ultimately achieving precise risk assessment and vulnerability detection. We evaluate the effectiveness of CrossMiner on three types of smart contract vulnerabilities: reentrancy, timestamp dependency, and transaction state dependency. Experimental results demonstrate that CrossMiner achieves the best performance among all baseline methods, improving detection accuracy by 5.52%, 4.94%, and 5.60% for these vulnerabilities, and the F1 scores are improved by 5.44%, 5.02%, and 5.40%, respectively.
Xiangfu Liu, Teng Huang 0001, Caiyan Tan, Qiong Wang 0001
TrustCom2
2025 Graph-Based Contract Sensing Framework for Smart Contract Vulnerability Detection
abstract
Smart contract vulnerabilities have led to significant economic losses, threatening blockchain security and development. Graph neural network (GNN)-based approaches, which capture the structural properties of contracts and leverage code dependencies to better understand contract behavior, have become widely used for vulnerability detection. However, these approaches face challenges in losing valuable information during graph construction and failing to capture rich semantic content, while traditional GNNs struggle with long-range dependencies and global context in complex contract graphs. To address these challenges, we propose ConSense, a GNN-based Contract Sensing Framework for Smart Contract Vulnerability Detection. ConSense comprises two core components: the smart contract graph generator, which constructs contract graphs while retaining both structural and semantic information, and ExploreFormer, which effectively integrates local and global context using advanced attention mechanisms for vulnerability detection. Comprehensive experimental evaluations were performed on the IR-ESCD and SCVHunter-SCD datasets. For instance, the IR-ESCD benchmark—which encompasses eight distinct vulnerability categories—demonstrates that ConSense attains an average detection accuracy of 97.74%, with a mean processing time of 0.648 seconds per contract. These results signify a statistically significant improvement over state-of-the-art methods in both precision and computational efficiency.
Xiangfu Liu, Teng Huang 0001, Yile Hong, Sisi Duan, Changyu Dong
IEEE Trans. Big Data3
2025 SAMamba: Structure-Aware Mamba for Ethereum Fraud Detection
abstract
The pseudonymity nature of Ethereum provides a protective umbrella for criminal activities, allowing criminals to develop a series of black industries such as phishing scams in unregulated areas. In order to exploit the relational inductive bias to discover the real identity of anonymous accounts, graph neural networks (GNNs) have been widely used in Ethereum fraud detection tasks as an effective and powerful framework. However, the expressive power of GNN’s 1-hop message passing mechanism is bounded by the Weisfeiler-Leman (1-WL) test, degrading the fraud detection performance on the Ethereum network. This paper proposes a structure-aware Mamba framework, named SAMamba. Specifically, SAMamba uses a subgraph encoding strategy to capture complex structural patterns and introduces Mamba’s exceptional sequence modeling capabilities to route global information. In order to filter task-relevant information from dense information, the attention mechanism and the selection mechanism are introduced from local and global perspectives, respectively. These tailor-made designs enable SAMamba to distinguish subtle differences in structural patterns and selectively aggregate task-oriented information, thereby demonstrating exceptional performance in fraud detection tasks. Extensive experiments on real-world Ethereum data demonstrate that SAMamba outperforms state-of-the-art methods. The codes are publicly available on Github: https://github.com/deepang-ai/SAMamba.
Teng Huang 0001, Changyu Dong, Sisi Duan
IEEE Trans. Inf. Forensics Secur.1
2025 Efficient Breast Lesion Segmentation From Ultrasound Videos Across Multiple Source-Limited Platforms
abstract
Medical video segmentation is fundamentally important in clinical diagnosis and treatment procedures, offering dynamic tracking of breast lesions across frames in ultrasound videos for improved segmentation performance. However, existing approaches face challenges in striking a balance between segmentation performance and inference speed, hindering real-time application in resource-constrained medical environments. In order to address these limitations, we present BaS, a blazing-fast on-device breast lesion segmentation model. BaS integrates the Stem module and BaSBlock to refine representations through inter- and intra-frame analysis on ultrasound videos. In addition, we release two versions of BaS: the BaS-S for superior segmentation performance and the BaS-L for accelerated inference times. Experimental Results indicate that BaS surpasses the top-performing models in terms of segmenting efficiency and accuracy of predictions on devices with limited resources. This work advances the development of efficient medical video segmentation frameworks applicable to multiple medical platforms.
Teng Huang 0001, Ziyu Ding, Hao Chen 0011, Baoliang Zhao, Ying Hu 0001, Qiong Wang 0001
IEEE J. Biomed. Health Informatics3
2025 Online Self-Distillation and Self-Modeling for 3D Brain Tumor Segmentation
abstract
In the specialized domain of brain tumor segmentation, supervised segmentation approaches are hindered by the limited availability of high-quality labeled data, a condition arising from data privacy concerns, significant costs, and ethical issues. In response to this challenge, this paper presents a training framework that adeptly integrates a plug-and-play component, MOD, into current supervised learning models, boosting their efficacy in scenarios with limited data. The MOD consists of an Online Tokenizer and a Dense Predictor, which employs self-distillation and self-modeling on masked patches, promoting swift convergence and efficient representation learning. During the inference phase, the plug-and-play MOD component is excluded, preserving the computational efficiency of the original model without incurring extra processing costs. We substantiated the value of our approach through experiments on leading 3D brain tumor segmentation baselines. Remarkably, models augmented with the MOD consistently showcased superior results, achieving elevated Dice coefficients and HD95 scores on two datasets: BraTS 2021 and MSD 2019 Task-01 Brain Tumor.
Teng Huang 0001, Zhen Wang 0037, Changyu Dong, Dongyang Kuang, Ying Hu 0001, Hao Chen 0011, Tim C. Lei, Qiong Wang 0001
IEEE J. Biomed. Health Informatics3
2025 Hierarchical Network With Local-Global Awareness for Ethereum Account De-anonymization
abstract
The expansion of blockchain applications, particularly on platforms like Ethereum, brings escalating security challenges as account anonymity provides breeding grounds for criminals to commit crimes and cause significant economic losses. As the mainstream architecture of de-anonymization technology, graph neural networks (GNNs) provide empirical tools for law enforcement agencies to investigate illegal activities. However, the limited expressiveness of current GNNs leads to performance degradation for Ethereum account de-anonymization. To address this challenge, we propose an innovative Local-Global Awareness (LGA) framework, which consists of a Local Structure-Aware (LSA) module and a Global Information-Aware (GIA) module. LSA integrates subgraph-level encoding strategies with local attention to enhance the capture of microscopic interactions. As a complementary measure, GIA introduces global attention to facilitate the understanding of macroscopic information. The LGA framework meticulously captures subgraph-level account behavior patterns at a granular level while simultaneously incorporating global contextual insights, demonstrating higher-level expressive power and receptive fields over conventional GNN. The efficacy of the LGA framework is corroborated by experimental evaluations conducted on the lw-AIG dataset. Our framework achieves exceptional performance, significantly outstripping state-of-the-art GNN-based methods in terms of the micro F1 score metric, with relative improvements ranging from 0.14% to 6.63%. Through its detailed and comprehensive analysis of account interactions, the LGA framework aims to provide a potent solution to the complex security challenges faced in the expanding blockchain landscape. The code for LGA is available at https://github.com/deepang-ai/LGA.
Teng Huang 0001, Changyu Dong, Sisi Duan
IEEE Trans. Syst. Man Cybern. Syst.2
2024 Optimized Breast Lesion Segmentation in Ultrasound Videos Across Varied Resource-Scant Environments
Zibin Chen, Junming Yan, Ziyu Ding, Teng Huang 0001, Xiaoqing Pei, Qiong Wang 0001
ACCV (8)6
2024 SFFAFormer: An Semantic Fusion and Feature Accumulation Approach for Remote Sensing Image Change Detection
Yile Hong, Xiangfu Liu, Teng Huang 0001, Aobo Lang
PRCV (13)5
2024 IPM: An Intelligent Component for 3D Brain Tumor Segmentation Integrating Semantic Extractor and Pixel Refiner
Caiyan Tan, Mingdu Zhang, Teng Huang 0001, Xiaoqing Pei
PRCV (15)5
2024 Comprehensive Transformer Integration Network (CTIN): Advancing Endoscopic Disease Segmentation with Hybrid Transformer Architecture
Mingdu Zhang, Caiyan Tan, Teng Huang 0001, Shegan Gao, Qian Sheng
PRCV (15)4
2024 Model architecture level privacy leakage in neural networks
Hongyang Yan, Teng Huang 0001, Zijie Pan, Jiewei Lai, Kongyang Chen, Jin Li 0002
Sci. China Inf. Sci.3
2024 Self-sovereign identity management in ciphertext policy attribute based encryption for IoT protocols
Weichu Deng, Jin Li 0002, Hongyang Yan, Arthur Sandor Voundi Koe, Teng Huang 0001, Jianfeng Wang 0001
J. Inf. Secur. Appl.5
2024 Slim UNETR: Scale Hybrid Transformers to Efficient 3D Medical Image Segmentation Under Limited Computational Resources
abstract
Hybrid transformer-based segmentation approaches have shown great promise in medical image analysis. However, they typically require considerable computational power and resources during both training and inference stages, posing a challenge for resource-limited medical applications common in the field. To address this issue, we present an innovative framework called Slim UNETR, designed to achieve a balance between accuracy and efficiency by leveraging the advantages of both convolutional neural networks and transformers. Our method features the Slim UNETR Block as a core component, which effectively enables information exchange through self-attention mechanism decomposition and cost-effective representation aggregation. Additionally, we utilize the throughput metric as an efficiency indicator to provide feedback on model resource consumption. Our experiments demonstrate that Slim UNETR outperforms state-of-the-art models in terms of accuracy, model size, and efficiency when deployed on resource-constrained devices. Remarkably, Slim UNETR achieves 92.44% dice accuracy on BraTS2021 while being 34.6x smaller and 13.4x faster during inference compared to Swin UNETR. Code: https://github.com/aigzhusmart/Slim-UNETR.
Teng Huang 0001, Hao Chen 0011, Qiong Wang 0001
IEEE Trans. Medical Imaging3
2024 Bag of tricks for backdoor learning
Ruitao Hou, Anli Yan, Hongyang Yan, Teng Huang 0001
Wirel. Networks4
2023 Experimental Comparison of Graph Edit Distance Computation Methods
abstract
Graph edit distance (GED) is a fundamental graph similarity metric. GED computation is NP-hard [10], and exact GED computation is only feasible for small graphs. Therefore, many methods of approximate GED computation have been proposed in the literature. In this paper, we select the five representative GED approximation methods and compare their performance on two real-world datasets. We observe that non-heuristic algorithms such as LSa [1] are fast and accurate in computing true GED for small graphs, and heuristic algorithms such as GENN [4] are very effective in computing the estimated path cost. This effort helps us pinpoint suitable algorithms for different applications.
Gaoming Zhang, Xianmin Wang, Teng Huang 0001, Lingyun Zou
MDM4
2023 MMA: Multi-Metric-Autoencoder for Analyzing High-Dimensional and Incomplete Data
Cheng Liang 0003, Di Wu 0056, Yi He 0007, Teng Huang 0001, Zhong Chen 0003, Xin Luo 0001
ECML/PKDD (5)4
2023 Lightweight Multispectral Skeleton and Multi-stream Graph Attention Networks for Enhanced Action Prediction with Multiple Modalities
Teng Huang 0001, Weiqing Kong, Ziyu Ding, Hui Li 0116
PRCV (1)1
2023 AgileNet: A Rapid and Efficient Breast Lesion Segmentation Method for Medical Image Analysis
Teng Huang 0001, Ziyu Ding, Qiong Wang 0001
PRCV (5)2
2023 A Lightweight, Secure Big Data-Based Authentication and Key-Agreement Scheme for IoT with Revocability
abstract
With the rapid development of Internet of Things (IoT), designing a secure two‐factor authentication scheme for IoT is becoming increasingly demanding. Two‐factor protocols are deployed to achieve a higher security level than single‐factor protocols. Given the resource constraints of IoT devices, other factors such as biometrics are ruled out as additional authentication factors due to their large overhead. Smart cards are also prone to side‐channel attacks. Therefore, historical big data have gained interest recently as a novel authentication factor in IoT. In this paper, we show that existing big data‐based schemes fail to achieve their claimed security properties such as perfect forward secrecy (PFS), key compromise impersonation (KCI) resilience, and server compromise impersonation (SCI) resilience. Assuming a real strong attacker rather than a weak one, we show that previous schemes not only fail to provide KCI and SCI but also do not provide real two‐factor security and revocability and suffer inside attack. Then, we propose our novel scheme which can indeed provide real two‐factor security, PFS, KCI, and inside attack resilience and revocability of the client. Furthermore, our performance analysis shows that our scheme has reduced modular exponentiation operation and multiplication for both the client and the server compared to Liu et al.’s scheme which reduces the execution time by one third for security levels of λ = 128. Moreover, in order to cope with the potential threat of quantum computers, we suggest using lightweight XMSS signature schemes which provide the desired security properties with λ = 128 bit postquantum security. Finally, we prove the security of our proposed scheme formally using both the real‐or‐random model and the ProVerif analysis tool.
Behnam Zahednejad, Teng Huang 0001, Saeed Kosari, Xiaojun Ren
Int. J. Intell. Syst.2
2023 Smart contract watermarking based on code obfuscation
Teng Huang 0001, Hongyang Yan
Inf. Sci.1
2023 Explanation leaks: Explanation-guided model extraction attacks
Anli Yan, Teng Huang 0001, Lishan Ke, Xiaozhang Liu, Qi Chen 0024, Changyu Dong
Inf. Sci.2
2023 Siamese transformer network-based similarity metric learning for cross-source remote sensing image retrieval
Chun Ding, Meimin Wang, Zhili Zhou 0001, Teng Huang 0001, Xiaoliang Wang 0002, Jin Li 0002
Neural Comput. Appl.4
2023 Holistic Implicit Factor Evaluation of Model Extraction Attacks
abstract
Model extraction attacks (MEAs) allow adversaries to replicate a surrogate model analogous to the target model's decision pattern. While several attacks and defenses have been studied in-depth, the underlying reasons behind our susceptibility to them often remain unclear. Analyzing these implication influence factors helps to promote secure deep learning (DL) systems, it requires studying extraction attacks in various scenarios to determine the success of different attacks and the hallmarks of DLs. However, understanding, implementing, and evaluating even a single attack requires extremely high technical effort, making it impractical to study the vast number of unique extraction attack scenarios. To this end, we present a first-of-its-kind holistic evaluation of implication factors for MEAs which relies on the attack process abstracted from state-of-the-art MEAs. Specifically, we concentrate on four perspectives. we consider the impact of the task accuracy, model architecture, and robustness of the target model on MEAs, as well as the impact of the model architecture of the surrogate model on MEAs. Our empirical evaluation includes an ablation study over sixteen model architectures and four image datasets. Surprisingly, our study shows that improving the robustness of the target model via adversarial training is more vulnerable to model extraction attacks.
Anli Yan, Hongyang Yan, Xiaozhang Liu, Teng Huang 0001
IEEE Trans. Dependable Secur. Comput.5
2023 Privacy-Preserving and Outsourced Multi-Party K-Means Clustering Based on Multi-Key Fully Homomorphic Encryption
abstract
The clustering algorithm is a useful tool for analyzing medical data. For instance, the k-means clustering can be used to study precipitating factors of a disease. In order to implement the clustering algorithm efficiently, data computation is outsourced to cloud servers, which may leak the private data. Encryption is a common method for solving this problem. But cloud servers are difficult to calculate ciphertexts from multiple parties. Hence, we choose multi-key fully homomorphic encryption (FHE), which supports computations on the ciphertexts that have different secret keys, to protect the private data. In this paper, based on Chen's multi-key FHE scheme, we first propose secure squared euclidean, comparison, minimum, and average protocols. Then, we design the basic and advanced schemes for implementing the secure multi-party k-means clustering algorithm. In the basic scheme, the implementation of homomorphic multiplication includes the process of transforming ciphertexts under different keys. In order to implement homomorphic multiplication efficiently, the advanced scheme uses an improved method to transform ciphertexts. Meanwhile, almost all computations are completely outsourced to cloud servers. We prove that the proposed protocols and schemes are secure and feasible. Simulation results also show that our improved method is helpful for improving the homomorphic multiplication of Chen's multi-key FHE scheme.
Peng Zhang 0029, Teng Huang 0001, Shangqi Lai, Joseph K. Liu
IEEE Trans. Dependable Secur. Comput.2
2023 A stealthy and robust backdoor attack via frequency domain transform
Ruitao Hou, Teng Huang 0001, Hongyang Yan, Lishan Ke
World Wide Web (WWW)2
2022 DPCL: Contrastive representation learning with differential privacy
abstract
With the proliferation of unlabeled data, increasing efforts have been devoted to unsupervised learning. As one of the most representative branches of unsupervised learning, contrastive learning has made great progress with its high efficiency. Unfortunately, privacy threats to contrastive learning have become sophisticated, making it imperative to develop effective technologies that can deal with such threats. To alleviate the privacy issue in contrastive learning, we propose some novel techniques based on differential privacy, which aim at reducing the high sensitivity of gradient in the private training caused by interactive contrastive learning. Specifically, we add differentially private protection to the connection point related to different per-example gradients, which decreases the sensitivity of the gradients significantly. Our experiments on SimCLR and the Barlow Twins show that our approach is superior since it is more accurate while maintaining the same level of privacy protection.
Anli Yan, Di Wu 0056, Taoyu Zhu, Teng Huang 0001, Xuandi Luo
Int. J. Intell. Syst.5
2022 Understanding adaptive gradient clipping in DP-SGD, empirically
abstract
Differentially Private Stochastic Gradient Descent (DP-SGD) is a prime method for training machine learning models with rigorous privacy guarantees. Since its birth, DP-SGD has gained popularity and has been widely adopted in both academic and industrial research. One well-known challenge when using DP-SGD is how to improve utility while maintaining privacy. To this end, recently we have seen several proposals that clip the gradients with adaptive thresholds rather than a fixed one. Although each proposal comes with some theoretical justification, the theories often rely on strong assumptions and are not compatible with each other. It is hard to know whether they are good in practice and how good they are. In this paper, we investigate adaptive clipping in DP-SGD from an empirical perspective. With extensive experiments, we were able to gain some fresh insights and proposed two new adaptive clipping strategies based on them. We cross-compared the existing methods and our new strategies experimentally. Results showed that our strategies did provide a substantial improvement in model accuracy, and outperformed the state-of-the-art adaptive clipping methods consistently.
Guanbiao Lin, Hongyang Yan, Guang Kou, Teng Huang 0001, Shiyu Peng, Changyu Dong
Int. J. Intell. Syst.4
2022 Graph Decipher: A transparent dual-attention graph neural network to understand the message-passing mechanism for the node classification
abstract
Graph neural networks (GNNs) can be effectively applied to solve many real-world problems across widely diverse fields. Their success is inseparable from the message-passing mechanisms evolving over the years. However, current mechanisms treat all node features equally at the macro-level (node-level), and the optimal aggregation method has not yet been explored. In this paper, we propose a new GNN called Graph Decipher (GD), which transparentizes the message flows of node features from micro-level (feature-level) to global-level and boosts the performance on node classification tasks. Besides, to reduce the computational burden caused by investigating message-passing, only the relevant representative node attributes are extracted by graph feature filters, allowing calculations to be performed in a category-oriented manner. Experiments on 10 node classification data sets show that GD achieves state-of-the-art performance while imposing a substantially lower computational cost. Additionally, since GD has the ability to explore the representative node attributes by category, it can also be applied to imbalanced node classification on multiclass graph data sets.
Teng Huang 0001, Zhen Wang 0037, Poorya Hosseini, Ji Zhang 0001, Chao Liu 0037, Shan Ai
Int. J. Intell. Syst.2
2022 Sparse-Dyn: Sparse dynamic graph multirepresentation learning via event-based sparse temporal attention network
abstract
Dynamic graph neural networks (DGNNs) have been widely used in modeling and representation learning of graph structure data. Current dynamic representation learning focuses on either discrete learning which results in temporal information loss, or continuous learning which involves heavy computation. In this study, we proposed a novel DGNN, sparse dynamic (Sparse-Dyn). It adaptively encodes temporal information into a sequence of patches with an equal amount of temporal-topological structure. Therefore, while avoiding using snapshots which cause information loss, it also achieves a finer time granularity, which is close to what continuous networks could provide. In addition, we also designed a lightweight module, Sparse Temporal Transformer, to compute node representations through structural neighborhoods and temporal dynamics. Since the fully connected attention conjunction is simplified, the computation cost is far lower than the current state-of-the-art. Link prediction experiments are conducted on both continuous and discrete graph data sets. By comparing several state-of-the-art graph embedding baselines, the experimental results demonstrate that Sparse-Dyn has a faster inference speed while having competitive performance.
Ai Shan, Zhen Wang 0037, Ji Zhang 0001, Teng Huang 0001, Chao Liu 0037
Int. J. Intell. Syst.7
2022 Towards explainable model extraction attacks
abstract
One key factor able to boost the applications of artificial intelligence (AI) in security-sensitive domains is to leverage them responsibly, which is engaged in providing explanations for AI. To date, a plethora of explainable artificial intelligence (XAI) has been proposed to help users interpret model decisions. However, given its data-driven nature, the explanation itself is potentially susceptible to a high risk of exposing privacy. In this paper, we first show that the existing XAI is vulnerable to model extraction attacks and then present an XAI-aware dual-task model extraction attack (DTMEA). DTMEA can attack a target model with explanation services, that is, it can extract both the classification and explanation tasks of the target model. More specifically, the substitution model extracted by DTMEA is a multitask learning architecture, consisting of a sharing layer and two task-specific layers for classification and explanation. To reveal which explanation technologies are more vulnerable to expose privacy information, we conduct an empirical evaluation of four major explanation types in the benchmark data set. Experimental results show that the attack accuracy of DTMEA outperforms the predicted-only method with up to 1.25%, 1.53%, 9.25%, and 7.45% in MNIST, Fashion-MNIST, CIFAR-10, and CIFAR-100, respectively. By exposing the potential threats on explanation technologies, our research offers the insights to develop effective tools that are able to trade off security-sensitive relationships.
Anli Yan, Ruitao Hou, Xiaozhang Liu, Hongyang Yan, Teng Huang 0001, Xianmin Wang
Int. J. Intell. Syst.5
2022 CRFL: A novel federated learning scheme of client reputation assessment via local model inversion
abstract
Federated learning (FL) is gradually becoming a key learning paradigm in Privacy-preserving Machine Learning (ML) systems. In FL, a large number of clients cooperate with a central server to learn a shared model without sharing their own data sets. However, since there is a great disparity between the client data sets, standard FL is often hard to tune and suffers from performance degradation due to the inharmony among local models. To this end, in this paper we propose a novel FL scheme, termed client reputation federated learning (CRFL), which dynamically assesses the reputation of the clients participating in FL. Our method leverages techniques from model explanation, and aims at precisely measure each client's impact to the global model. To be specific, we first calculate the saliency-weighted variance on pixelwise relevance scores as the quality factor of a single sample. Then we extract activation function values at the last hidden layer to compute the divergence factor of individual data set. Finally, the server integrates these two factors as an assessment of the client reputation. By leveraging such assessment, CRFL can dynamically adjust the weights of the clients in each aggregation round, thus leading to a significant improvement over the baseline method in terms of model accuracy and convergence rate. Intensive experiments are conducted on the MNIST and CIFAR-10 data sets, and experimental results demonstrate the efficacy of the proposed method.
Teng Huang 0001
Int. J. Intell. Syst.2
2022 Similarity-based integrity protection for deep learning systems
Ruitao Hou, Shan Ai, Qi Chen 0024, Hongyang Yan, Teng Huang 0001, Kongyang Chen
Inf. Sci.5
2021 Camdar-adv: Generating adversarial patches on 3D object
abstract
Deep neural network model is the core technology for sensors of the autonomous driving platform to perceive the external environment. Recent research have shown that it has a certain vulnerability. The artificial designed adversarial examples can make the DNN model output the wrong results. These adversarial examples not only exist in the digital world, but also in the physical world. At present, research on autonomous driving platform mainly focus on attacking a single sensor. In this paper, we introduce Camdar-adv, a method for generating image adversarial examples on three-dimensional (3D) objects, which could potentially lunch a multisensor attack toward the autonomous driving platforms. Specifically, with objects that can attack LiDAR sensors, a geometric transformation can be used to project their shape onto the two-dimensional plane. Adversarial perturbations against optical image sensor could be added to the surface of the adversarial 3D objects precisely without changing its geometry. Test results on the open-source autonomous driving data set KITTI show that Camdar-adv can generate adversarial samples for the state of the art object detection model. From a fixed viewpoint, our method can achieve an attack success rate over 99%.
Chang Chen 0003, Teng Huang 0001
Int. J. Intell. Syst.2
2021 Querying little is enough: Model inversion attack via latent information
abstract
As machine learning (ML) technologies evolve, various online intelligent services use ML models to provide predictions. Unfortunately, attackers can obtain the private information of the model by interacting with the online service, namely model inversion attack (MIA). However, MIA requires large data sets to be transferred to an online service to obtain the predictive value of the inference model. Besides, the huge transmission may cause the administrator's active defense. To overcome this drawback, we propose a novel MIA scheme, which leverages latent information extracted by an auxiliary neural network as high-dimensional features to simplify what inversion model should learn. The core idea of our scheme is to reuse some parameters of the local pretraining model. Extensive experiments have verified the effectiveness of our method in convolutional neural networks on LFW, pubFig, MNIST data sets. Experimental results show that even with a few queries, our inversion method still work accurately and is superior to other technologies. It is worth mentioning that our method makes it more difficult for administrators to defend against the attack and elicit more investigations for privacy-preserving.
Kanghua Mo, Xiaozhang Liu, Teng Huang 0001, Anli Yan
Int. J. Intell. Syst.3
2020 Adversarial attacks on deep-learning-based radar range profile target recognition
Teng Huang 0001, Yongfeng Chen, Bingjian Yao, Bifen Yang, Xianmin Wang
Inf. Sci.1
2020 Adversarial attacks on deep-learning-based SAR image target recognition
Teng Huang 0001, Jiabao Liu, Ruitao Hou, Xianmin Wang
J. Netw. Comput. Appl.1
2020 A dynamic and hierarchical access control for IoT in multi-authority cloud storage
Khaled Riad, Teng Huang 0001, Lishan Ke
J. Netw. Comput. Appl.2