VLDB 2026 Research / reviewers in the wild / expert
Weiping Wen
dblp:16/6423
· DBLP profile ↗
25ranked-venue papers
0as first author
22since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 10 · 10 since 2021Security and privacy · 8 · 5 since 2021Software engineering, systems software and programming languages · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Forging the Unknown: Open-Set Deepfake Attribution via Adaptive Fingerprint Learning
Yizhi Fang, Boxuan Han, Xiandang Luo, Siyu Peng, Xiarun Chen, Weiping Wen, Sai Cheng |
ICPR (4) | 7 |
| 2025 | TimbreAdv: Timbre Adversarial Attacks on Speaker Verification Systems
Wenhan Yao, Jinsu Yang, Xiandang Luo, Fen Xiao, Weiping Wen |
ICANN (3) | 8 |
| 2025 | Art Style Backdoor Attacks on Semantic Segmentation Models
Jinsu Yang, Fen Xiao, Wenhan Yao, Weiping Wen |
ICANN (2) | 6 |
| 2025 | Emotional Text-to-Speech via Style Decoder with Emotion Shared Styleformer Block and RoPE Prior Encoder
Wenhan Yao, Fen Xiao, Xiarun Chen, Weiping Wen |
ICANN (3) | 6 |
| 2025 | Pureformer-VC: Non-parallel Voice Conversion with Pure Stylized Transformer Blocks and Triplet Discriminative TrainingabstractAs a foundational technology for intelligent human-computer interaction, voice conversion (VC) seeks to transform speech from any source timbre into any target timbre. Traditional voice conversion methods based on Generative Adversarial Networks (GANs) encounter significant challenges in precisely encoding diverse speech elements and effectively synthesising these elements into natural-sounding converted speech. To overcome these limitations, we introduce Pureformer-VC, an encoder-decoder framework that utilizes Conformer blocks to build a disentangled encoder and employs Zipformer blocks to create a style transfer decoder. We adopt a variational decoupled training approach to isolate speech components using a Variational Autoencoder (VAE), complemented by triplet discriminative training to enhance the speaker’s discriminative capabilities. Furthermore, we incorporate the Attention Style Transfer Mechanism (ASTM) with Zipformer’s shared weights to improve the style transfer performance in the decoder. We conducted experiments on two multi-speaker datasets. The experimental results demonstrate that the proposed model achieves comparable subjective evaluation scores while significantly enhancing objective metrics compared to existing approaches in many-to-many and many-to-one VC scenarios. Wenhan Yao, Fen Xiao, Xiarun Chen, YongQiang He, Weiping Wen |
IJCNN | 6 |
| 2025 | SPBA: Utilizing Speech Large Language Model for Backdoor Attacks on Speech Classification ModelsabstractDeep speech classification tasks, including keyword spotting and speaker verification, are vital in speech-based human-computer interaction. Recently, the security of these technologies has been revealed to be susceptible to backdoor attacks. Specifically, attackers use noisy disruption triggers and speech element triggers to produce poisoned speech samples that train models to become vulnerable. However, these methods typically create only a limited number of backdoors due to the inherent constraints of the trigger function. In this paper, we propose that speech backdoor attacks can strategically focus on speech elements such as timbre and emotion, leveraging the Speech Large Language Model (SLLM) to generate diverse triggers. Increasing the number of triggers may disproportionately elevate the poisoning rate, resulting in higher attack costs and a lower success rate per trigger. We introduce the Multiple Gradient Descent Algorithm (MGDA) as a mitigation strategy to address this challenge. The proposed attack is called the Speech Prompt Backdoor Attack (SPBA). Building on this foundation, we conducted attack experiments on two speech classification tasks, demonstrating that SPBA shows significant trigger effectiveness and achieves exceptional performance in attack metrics. Wenhan Yao, Fen Xiao, Xiarun Chen, YongQiang He, Weiping Wen |
IJCNN | 6 |
| 2025 | LRBA: Stealthy Backdoor Attacks on Speech Classification via Latent Rearrangement in VITS
Wenhan Yao, Jinsu Yang, Fen Xiao, Weiping Wen |
INTERSPEECH | 6 |
| 2025 | LFBA: Latent-Space Frame-Level Backdoor Attacks on Keyword Spotting SystemsabstractModern deep learning models increasingly rely on third-party data processing, exposing vulnerabilities to backdoor attacks. Existing audio backdoor methods often compromise stealthiness by introducing perceptible modifications. This paper proposes Latent-space Frame-level Backdoor Attacks (LFBA), a novel framework that manipulates frame-level features in latent space to achieve imperceptible and effective backdoor injection. Our approach extracts and transforms frame-level features to subtly alter rhythmic patterns, such as compressing or expanding temporal segments, without modifying semantic content or speaker characteristics. Evaluations demonstrate excellent attack effectiveness while maintaining near-original audio quality. Our attack evades human perception and automated detection, maintaining robustness even after defensive fine-tuning. This work reveals critical risks in outsourced speech model training and establishes a new paradigm for stealthy, latent-space poisoning in speech-controlled systems. Wenhan Yao, Jinsu Yang, Zedong Xing, Xiarun Chen, Fen Xiao, Weiping Wen |
SMC | 8 |
| 2025 | ForgeDAN: An Evolutionary Framework for Jailbreaking Aligned Large Language ModelsabstractThe rapid adoption of large language models (LLMs) has brought both transformative applications and new security risks, including jailbreak attacks that bypass alignment safeguards to elicit harmful outputs. Existing automated jailbreak generation approaches e.g. AutoDAN, suffer from limited mutation diversity, shallow fitness evaluation, and fragile keyword-based detection. To address these limitations, we propose ForgeDAN, a novel evolutionary framework for generating semantically coherent and highly effective adversarial prompts against aligned LLMs. First, ForgeDAN introduces multi-strategy textual perturbations across character, word, and sentence-level operations to enhance attack diversity; then we employ interpretable semantic fitness evaluation based on a text similarity model to guide the evolutionary process toward semantically relevant and harmful outputs; finally, ForgeDAN integrates dual-dimensional jailbreak judgment, leveraging an LLM-based classifier to jointly assess model compliance and output harmfulness, thereby reducing false positives and improving detection effectiveness. Our evaluation demonstrates ForgeDAN achieves high jailbreaking success rates while maintaining naturalness and stealth, outperforming existing SOTA solutions. Siyang Cheng, Gaotian Liu, Rui Mei, Kaishuo Wei, Yuqi Yu, Weiping Wen |
TrustCom | 8 |
| 2025 | Internal wall layout estimation and automated 3D reconstruction of masonry buildings using building contours
Changhai Zhai, Weiping Wen, Penghao Ruan |
Adv. Eng. Informatics | 3 |
| 2025 | DynamicFuzz: Confidence-based directed greybox fuzzing for programs with unreliable call graphs
Hao Jiang 0038, Xiarun Chen, Weiping Wen |
Comput. Secur. | 8 |
| 2025 | Imperceptible rhythm backdoor attacks: Exploring rhythm transformation for embedding undetectable vulnerabilities on speech recognition
Wenhan Yao, Jiangkun Yang, Yongqiang He, Weiping Wen |
Neurocomputing | 5 |
| 2025 | A Point-Neighborhood Learning Framework for Nasal Endoscopic Image SegmentationabstractLesion segmentation on nasal endoscopic images is challenging due to its complex lesion features. Fully-supervised learning methods achieve promising performance with pixel-level annotations but impose a significant annotation burden on experts. Although weakly supervised or semi-supervised methods can reduce the labelling burden, their performance is still limited. Some weakly semi-supervised methods employ a novel annotation strategy that labels weak single-point annotations for the entire training set while providing pixel-level annotations for a small subset of the data. However, the relevant weakly semi-supervised methods only mine the limited information of the point itself, while ignoring its label property and surrounding reliable information. This paper proposes a simple yet efficient weakly semi-supervised method called the Point-Neighborhood Learning (PNL) framework. PNL incorporates the surrounding area of the point, referred to as the point-neighborhood, into the learning process. In PNL, we propose a point-neighborhood supervision loss and a pseudo-label scoring mechanism to explicitly guide the model’s training. Meanwhile, we proposed a more reliable data augmentation scheme. The proposed method obviously improves performance without increasing the parameters of the segmentation neural network. Experimental results indicate that our method consistently achieves better performance compared to SOTA methods. Additional validation on colonoscopic polyp segmentation datasets confirms our method’s generalizability. Pengyu Jie, Wanquan Liu, Chenqiang Gao, Yihui Wen, Weiping Wen, Pengcheng Li 0017, Deyu Meng |
IEEE Trans. Circuits Syst. Video Technol. | 6 |
| 2025 | Fountain: DAG-Based Separate BFT Consensus Made Hashgraph PracticalabstractThe limited transaction throughput performance is the primary challenge for single-chain structure blockchain in practical applications. Directed acyclic graph (DAG) technology offers a novel topological structure, significantly improving blockchain’s ability to process massive transactions by containing numerous blocks in a parallel way. However, the existing parallel-chain schemes embed DAG into the Practical Byzantine Fault Tolerance (PBFT) protocol stages to expand the instance, which requires an extent of overall synchronization between multiple chains. Overall consensus synchronously among all parallel chains may delay the system’s progress, particularly when the graph structure is unevenly distributed. This paper introduces a new DAG-based blockchain named Fountain, which aims to provide a loosely coupled consensus algorithm based on the classic parallel-chain scheme Hashgraph. The Fountain scheme changes consensus finality from an overall behavior to a separate behavior, thereby reducing block commit latency from the perspective of each parallel chain. Theoretical analysis reveals that our scheme maintains the same security level as Hashgraph, while experimental simulations demonstrate its effectiveness in optimizing commit latency. Changling Zhou, Weiping Wen |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2024 | Phoneme Substitution: A Novel Approach for Backdoor Attacks on Speech Recognition SystemsabstractSpeech recognition technology is a key component of the artificial intelligence field. As it continues to develop, security issues are becoming more and more prominent. Backdoor attacks, as a highly covert emerging attack method, can manipulate speech recognition models to output incorrect results under specific trigger conditions, thus causing serious security risks. This paper provides a comprehensive review of the development of speech recognition technology and backdoor attacks. By analyzing the limitations of existing speech backdoor attack methods and incorporating phonological principles, we propose a covert backdoor attack strategy based on phoneme substitution. Considering the human ear's lower sensitivity to consonant phonemes and the masking effect of speech in the time domain, we have developed a selection and substitution strategy for attack triggers. In this strategy, we prioritize the replacement of consonant phonemes that are located towards the end of sentences or words, thereby making the attack more subtle and effective. Experimental results show that our method not only ensures the effectiveness of the attack but also exhibits higher concealment. Bicheng Xiong, Zedong Xing, Weiping Wen |
ICTAI | 3 |
| 2024 | Low-Resource VITS-Based Emotion Speech Synthesis Using KNN Algorithm
Zedong Xing, Bicheng Xiong, Weiping Wen |
PRICAI (4) | 3 |
| 2023 | Finding Missing Security Operation Bugs via Program Slicing and Differential Check
Yeqi Fu, Yongzhi Liu, Xiarun Chen, Chenglin Xie, Weiping Wen |
ICICS | 7 |
| 2021 | Abnormal Transaction Detection based on Graph NetworksabstractThis paper proposes a deep learning approach to address the two issues in abnormal transaction detection, one is to process dynamically generated transaction data, instead of having to use the static and whole graph structure; and the other is to fully explore the information in the graph structure of transactions to improve the learning ability. The proposed approach is applied on the dataset provided by Elliptic, and the experiments evaluate the proposed approach by comparing with the existing ones the precision rate, recall rate, and F1-score indicators for detecting illegal transactions, increasing by 2%, 3.9% and 3.8%, respectively. Weiping Wen |
COMPSAC | 3 |
| 2021 | Dynamic Interval-based Watermarking for Tracking down Network AttacksabstractTransaction systems, such as e-commerce, banking systems, and blockchain-based transaction systems, take the advantages of great developments of network technologies. At the same time, such systems face a variety of threats and attacks. Passive traffic analysis (TA) usually consumes a lot of resources, and responds with tardiness, and no longer meets the current requirements. Network flow watermarking is a typical active TA technique, and IPD, IBW and ICBW are the typical ones, which can track attacks in a covert way. However, these approaches are also disturbed by the complex network conditions, e.g., packet splitting and merging during the transmissions. To improve the robustness of network flow watermarking, this paper proposes an improved scheme, dynamic interval-based watermark (DIBW). The experiments compare DIBW performance with that of IPD, IBW, and ICBW under packet splitting and merging conditions; and change the parameters of DIBW to observe the impacts on the performance of DIBW. The results show that DIBW can improve the robustness of the system. This paper utilizes LDPC code that consumes less time than the traditional ones. In addition, this paper proposes a hybrid watermark scheme of DIBW and IPD to adapt to the file sizes and the situations of network flow, and analyzes the feasibility of the adaptability by experiments. Weiping Wen, Xuetao Du |
QRS | 4 |
| 2021 | VulChecker: Achieving More Effective Taint Analysis by Identifying Sanitizers AutomaticallyabstractThe automatic detection of vulnerabilities in Web applications using taint analysis is a hot topic. However, existing taint analysis methods for sanitizers identification are too simple to find available taint transmission chains effectively. These methods generally use pre-constructed dictionaries or simple keywords to identify, which usually suffer from large false positives and false negatives. No doubt, it will have a greater impact on the final result of the taint analysis. To solve that, we summarise and classify the commonly used sanitizers in Web applications and propose an identification method based on semantic analysis. Our method can accurately and completely identify the sanitizers in the target Web applications through static analysis. Specifically, we analyse the natural semantics and program semantics of existing sanitizers, use semantic analysis to find more in Web applications. Besides, we implemented the method prototype in PHP and achieved a vulnerability detection tool called VulChecker. Then, we experimented with some popular open-source CMS frameworks. The results show that Vulchecker can accurately identify more sanitizers. In terms of vulnerability detection, VulChecker also has a lower false positive rate and a higher detection rate than existing methods. Finally, we used VulChecker to analyse the latest PHP applications. We identified several new suspicious taint data propagation chains. Before the paper was completed, we have identified four unreported vulnerabilities. In general, these results show that our approach is highly effective in improving vulnerability detection based on taint analysis. Xiarun Chen, Qien Li, Yongzhi Liu, Shaosen Shi, Chenglin Xie, Weiping Wen |
TrustCom | 7 |
| 2021 | EnvFaker: A Method to Reinforce Linux Sandbox Based on Tracer, Filter and Emulator against Environmental-Sensitive MalwareabstractSandbox is an excellent tool for dynamic malware analysis. However, the sandbox detection techniques are increasingly adopted to develop malwares, which has been a significant threat to sandbox analysis. These malwares can detect the running environment and show different behaviors in corresponding environments. So far, there have been several studies about countermeasures, but most of them concentrate on Windows OS. Environmental features in Linux sandbox have not been summarized yet. Besides, existing popular sandboxes can hardly combat against sandbox detecting techniques. In this paper, we focus on Linux sandbox. We firstly propose Linux environmental features from six aspects and implement an effective tool to collect features from running environment to tell the discrepancy among physical machine, virtual machine and sandbox. More importantly, we present EnvFaker, an effective method to reinforce Linux sandbox against environmental-sensitive malware. This method uses tracer to track child process and injected process, filters to intercept sandbox detecting behaviors, and emulator to disguise wear-and-tear and network environment. The experimental results further demonstrate that our method is effective against detecting techniques for Linux sandbox. Chenglin Xie, Shaosen Shi, Yu Sheng, Xiarun Chen, Weiping Wen |
TrustCom | 7 |
| 2021 | Why an Android App Is Classified as Malware: Toward Malware Classification InterpretationabstractMachine learning–(ML) based approach is considered as one of the most promising techniques for Android malware detection and has achieved high accuracy by leveraging commonly used features. In practice, most of the ML classifications only provide a binary label to mobile users and app security analysts. However, stakeholders are more interested in the reason why apps are classified as malicious in both academia and industry. This belongs to the research area of interpretable ML but in a specific research domain (i.e., mobile malware detection). Although several interpretable ML methods have been exhibited to explain the final classification results in many cutting-edge Artificial Intelligent–based research fields, until now, there is no study interpreting why an app is classified as malware or unveiling the domain-specific challenges. In this article, to fill this gap, we propose a novel and interpretable ML-based approach (named XMal ) to classify malware with high accuracy and explain the classification result meanwhile. (1) The first classification phase of XMal hinges multi-layer perceptron and attention mechanism and also pinpoints the key features most related to the classification result. (2) The second interpreting phase aims at automatically producing neural language descriptions to interpret the core malicious behaviors within apps. We evaluate the behavior description results by leveraging a human study and an in-depth quantitative analysis. Moreover, we further compare XMal with the existing interpretable ML-based methods (i.e., Drebin and LIME) to demonstrate the effectiveness of XMal . We find that XMal is able to reveal the malicious behaviors more accurately. Additionally, our experiments show that XMal can also interpret the reason why some samples are misclassified by ML classifiers. Our study peeks into the interpretable ML through the research of Android malware detection and analysis. Bozhi Wu, Sen Chen 0001, Cuiyun Gao 0001, Lingling Fan 0003, Yang Liu 0003, Weiping Wen, Michael R. Lyu |
ACM Trans. Softw. Eng. Methodol. | 6 |
| 2011 | deRop: removing return-oriented programming from malwareabstractOver the last few years, malware analysis has been one of the hottest areas in security research. Many techniques and tools have been developed to assist in automatic analysis of malware. This ranges from basic tools like disassemblers and decompilers, to static and dynamic tools that analyze malware behaviors, to automatic malware clustering and classification techniques, to virtualization technologies to assist malware analysis, to signature- and anomaly-based malware detection, and many others. However, most of these techniques and tools would not work on new attacking techniques, e.g., attacks that use return-oriented programming (ROP). Kangjie Lu, Dabi Zou, Weiping Wen, Debin Gao |
ACSAC | 3 |
| 2011 | Packed, Printable, and Polymorphic Return-Oriented Programming
Kangjie Lu, Dabi Zou, Weiping Wen, Debin Gao |
RAID | 3 |
| 2005 | A survey and trends on Internet worms
Sihan Qing, Weiping Wen |
Comput. Secur. | 2 |