VLDB 2026 Research / reviewers in the wild / expert
Wei Zong
dblp:145/0551
· DBLP profile ↗
16ranked-venue papers
10as first author
10since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 7 first-author · 6 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 first-authorDatabases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adversarial-Example Agnostic Detection in Network Intrusion Detection Systems
Wei Zong, Yang-Wai Chow, Willy Susilo |
ACISP (3) | 2 |
| 2025 | Defense Against Multi-target Multi-trigger Backdoor Attacks
Haripriya Harikumar, Santu Rana, Kien Do, Sunil Gupta 0001, Wei Zong, Willy Susilo, Svetha Venkatesh |
PAKDD (6) | 5 |
| 2025 | AudioMarkNet: Audio Watermarking for Deepfake Speech Detection
Wei Zong, Yang-Wai Chow, Willy Susilo, Joonsang Baek, Seyit Ahmet Çamtepe |
USENIX Security Symposium | 1 |
| 2025 | Detecting Generative Model Inversion Attacks for Protecting Intellectual Property of Deep Neural NetworksabstractRecently, protecting the Intellectual Property (IP) of deep neural networks (DNNs) has attracted attention from researchers. This is because training DNN models can be costly especially when acquiring and labeling training data require domain expertise. DNN watermarking and fingerprinting are two techniques proposed to prevent DNN IP infringement. Although these two techniques achieve high performance on defending against previously proposed DNN stealing attacks, researchers recently show that both of them are ineffective against generative model inversion attacks. Specifically, an adversary inverts training data from well-trained DNNs and uses the inverted data to train DNNs from scratch such that DNN watermarking and fingerprinting are both bypassed. This novel model stealing strategy shows that data inverted from victim models can be effectively exploited by adversaries, which poses a new threat to the IP protection of DNNs. To combat this new threat, one potential solution is to enable defenders to prove ownership on data inverted from models being protected. If the training data of a suspected model, which can be disclosed via the judicial process, are proven to be data inverted from victim models, then IP infringement is detected. This research direction is currently underexplored. In this paper, we fill the gap in the literature to investigate countermeasures against this emerging threat. We propose a simple but effective method, called InverseDataInspector (IDI), to detect whether data are inverted from victim models. Specifically, our method first extracts features from both the inverted data and victim models. These features are then combined and used for training classifiers. Experimental results demonstrate that our method achieves high performance on detecting inverted data and also generalizes to new generative model inversion methods that are not seen when training classifiers. Yiding Yu, Wei Zong, Yang-Wai Chow, Willy Susilo |
J. Artif. Intell. Res. | 2 |
| 2024 | IPRemover: A Generative Model Inversion Attack against Deep Neural Network Fingerprinting and WatermarkingabstractTraining Deep Neural Networks (DNNs) can be expensive when data is difficult to obtain or labeling them requires significant domain expertise. Hence, it is crucial that the Intellectual Property (IP) of DNNs trained on valuable data be protected against IP infringement. DNN fingerprinting and watermarking are two lines of work in DNN IP protection. Recently proposed DNN fingerprinting techniques are able to detect IP infringement while preserving model performance by relying on the key assumption that the decision boundaries of independently trained models are intrinsically different from one another. In contrast, DNN watermarking embeds a watermark in a model and verifies IP infringement if an identical or similar watermark is extracted from a suspect model. The techniques deployed in fingerprinting and watermarking vary significantly because their underlying mechanisms are different. From an adversary's perspective, a successful IP removal attack should defeat both fingerprinting and watermarking. However, to the best of our knowledge, there is no work on such attacks in the literature yet. In this paper, we fill this gap by presenting an IP removal attack that can defeat both fingerprinting and watermarking. We consider the challenging data-free scenario whereby all data is inverted from the victim model. Under this setting, a stolen model only depends on the victim model. Experimental results demonstrate the success of our attack in defeating state-of-the-art DNN fingerprinting and watermarking techniques. This work reveals a novel attack surface that exploits generative model inversion attacks to bypass DNN IP defenses. This threat must be addressed by future defenses for reliable IP protection. Wei Zong, Yang-Wai Chow, Willy Susilo, Joonsang Baek, Jongkil Kim, Seyit Ahmet Çamtepe |
AAAI | 1 |
| 2023 | TrojanModel: A Practical Trojan Attack against Automatic Speech Recognition SystemsabstractWhile deep learning techniques have achieved great success in modern digital products, researchers have shown that deep learning models are susceptible to Trojan attacks. In a Trojan attack, an adversary stealthily modifies a deep learning model such that the model will output a predefined label whenever a trigger is present in the input. In this paper, we present TrojanModel, a practical Trojan attack against Automatic Speech Recognition (ASR) systems. ASR systems aim to transcribe voice input into text, which is easier for subsequent downstream applications to process. We consider a practical attack scenario in which an adversary inserts a Trojan into the acoustic model of a target ASR system. Unlike existing work that uses noise-like triggers that will easily arouse user suspicion, the work in this paper focuses on the use of unsuspicious sounds as a trigger, e.g., a piece of music playing in the background. In addition, TrojanModel does not require the retraining of a target model. Experimental results show that TrojanModel can achieve high attack success rates with negligible effect on the target model’s performance. We also demonstrate that the attack is effective in an over-the-air attack scenario, where audio is played over a physical speaker and received by a microphone. Wei Zong, Yang-Wai Chow, Willy Susilo, Kien Do, Svetha Venkatesh |
SP | 1 |
| 2023 | DiffCircaPipeline: a framework for multifaceted characterization of differential rhythmicityabstractSUMMARY: Circadian oscillations of gene expression regulate daily physiological processes, and their disruption is linked to many diseases. Circadian rhythms can be disrupted in a variety of ways, including differential phase, amplitude and rhythm fitness. Although many differential circadian biomarker detection methods have been proposed, a workflow for systematic detection of multifaceted differential circadian characteristics with accurate false positive control is not currently available. We propose a comprehensive and interactive pipeline to capture the multifaceted characteristics of differentially rhythmic biomarkers. Analysis outputs are accompanied by informative visualization and interactive exploration. The workflow is demonstrated in multiple case studies and is extensible to general omics applications. AVAILABILITY AND IMPLEMENTATION: R package, Shiny app and source code are available in GitHub (https://github.com/DiffCircaPipeline) and Zenodo (https://doi.org/10.5281/zenodo.7507989). SUPPLEMENTARY INFORMATION: Supplementary data are available at Bioinformatics online. Xiangning Xue, Wei Zong, Zhiguang Huo, Kyle D. Ketchesin, Madeline R. Scott, Kaitlyn A Petersen, Ryan W. Logan, Marianne L. Seney, Colleen A. Mcclung, George C. Tseng |
Bioinform. | 2 |
| 2021 | Towards Visualizing and Detecting Audio Adversarial Examples for Automatic Speech Recognition
Wei Zong, Yang-Wai Chow, Willy Susilo |
ACISP | 1 |
| 2021 | Black-Box Audio Adversarial Example Generation Using Variational Autoencoder
Wei Zong, Yang-Wai Chow, Willy Susilo |
ICICS (2) | 1 |
| 2021 | Targeted Universal Adversarial Perturbations for Automatic Speech Recognition
Wei Zong, Yang-Wai Chow, Willy Susilo, Santu Rana, Svetha Venkatesh |
ISC | 1 |
| 2020 | Interactive three-dimensional visualization of network intrusion detection data for machine learning
Wei Zong, Yang-Wai Chow, Willy Susilo |
Future Gener. Comput. Syst. | 1 |
| 2019 | Dimensionality Reduction and Visualization of Network Intrusion Detection Data
Wei Zong, Yang-Wai Chow, Willy Susilo |
ACISP | 1 |
| 2018 | A 3D Approach for the Visualization of Network Intrusion Detection DataabstractWith the increasing threat of cyber attacks, machine learning techniques have been researched extensively in the area of network intrusion detection. Such techniques can potentially provide a means for the real-time automated detection of attacks and abnormal traffic patterns. However, misclassification is a common problem in machine learning techniques for intrusion detection, and a lack of insight into why such misclassification occurs impedes the improvement of machine learning models. This paper presents an approach to visualizing network intrusion detection data in 3D. The purpose of this is to facilitate the understanding of network intrusion detection datasets using a visual representation to reflect the geometric relationship between various categories of network traffic. This can potentially provide useful insight to aid the design of machine learning techniques. This paper demonstrates the usefulness of the proposed 3D visualization approach by presenting results of experiments on commonly used network intrusion detection datasets. Wei Zong, Yang-Wai Chow, Willy Susilo |
CW | 1 |
| 2018 | A Two-Stage Classifier Approach for Network Intrusion Detection
Wei Zong, Yang-Wai Chow, Willy Susilo |
ISPEC | 1 |
| 2017 | A QR Code Watermarking Approach Based on the DWT-DCT Technique
Yang-Wai Chow, Willy Susilo, Joseph Tonien, Wei Zong |
ACISP (2) | 4 |
| 2008 | Development and Evaluation of Predictive Alerts for Hemodynamic Instability in ICU Patients
Larry J. Eshelman, Joseph J. Frassica, Wei Zong, Larry Nielsen, Mohammed Saeed 0001 |
AMIA | 4 |