Yonghao Tang

dblp:168/4583 · DBLP profile ↗
← Back
6ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0002-7357-3577ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Exploring and Exploiting Security Vulnerabilities in Self-Hosted LLM Services
Zhihuang Liu, Ling Hu 0001, Yonghao Tang, Tongqing Zhou, Fang Liu 0002, Zhiping Cai
WWW3
2026 Risk-Aware Privacy Preservation for LLM Inference
abstract
Large Language Model (LLM) inference services like ChatGPT are popular for enabling diverse tasks via prompts, yet they exacerbate privacy risks due to the potential exposure of sensitive data in user inputs. Existing local differential privacy (LDP)-based text sanitization mechanisms offer lightweight protection suitable for cloud-based LLM inference. Nevertheless, uniform privacy budget allocation and generalized sanitization mechanisms neglect the critical protection needs of sensitive user data, such as Personally Identifiable Information (PII). Empirical evidence of this work reveals that even with a strict privacy budget (ϵ=0.1), the sensitive information leakage rate can reach an alarmingly high 71.74%. To address these challenges, this paper proposes Rap-LI, a risk-aware privacy preservation framework for LLM inference, designed to be plug-and-play. Rap-LI performs risk identification and personalized labeling on user prompts, then develops a risk-aware LDP mechanism for text sanitization, formally proven to satisfy both token-level and sentence-level LDP guarantees. Extensive experimental results demonstrate Rap-LI’s superior privacy-utility balance. It improves privacy protection against sensitive information leakage by an average of 51.68% compared to methods with comparable utility. Our code is available at https://github.com/Cristliu/RapLI.
Zhihuang Liu, Zhangdong Wang, Tongqing Zhou, Yonghao Tang, Yuchuan Luo, Zhiping Cai
IEEE Trans. Inf. Forensics Secur.4
2025 Prevalence Overshadows Concerns? Understanding Chinese Users' Privacy Awareness and Expectations Towards LLM-Based Healthcare Consultation
abstract
Large Language Models (LLMs) are increasingly gaining traction in the healthcare sector, yet expanding the threat of sensitive health information being easily exposed and accessed without authorization. These privacy risks escalate in regions like China, where privacy awareness is notably limited. While some efforts have been devoted to user surveys on LLMs in healthcare, users' perceptions of privacy remain unexplored. To fill this gap, this paper contributes the first user study (n=846) in China on privacy awareness and expectations in LLM-based healthcare consultations. Specifically, a healthcare chatbot is deployed to investigate users' awareness in practice. Information flows grounded in contextual integrity are then employed to measure users' privacy expectations. Our findings suggest that the prevalence of LLMs amplifies health privacy risks by raising users' curiosity and willingness to use such services, thus overshadowing privacy concerns. 77.3% of participants are inclined to use such services, and 72.9% indicate they would adopt the generated advice. Interestingly, a paradoxical “illusion” emerges where users' knowledge and concerns about privacy contradict their privacy expectations, leading to greater health privacy exposure. Our extensive discussion offers insights for future LLM-based healthcare privacy investigations and protection technology development.
Zhihuang Liu, Ling Hu 0001, Tongqing Zhou, Yonghao Tang, Zhiping Cai
SP4
2024 Cooperative Motion Planning of Multiple Automated Vehicle Robots: A Quick IoT-Based Approach
abstract
In this article, we propose a novel hybrid control approach for solving the multirobot motion planning (MRMP) problem in the Internet of Things (IoT) environment, where the closed workspace is “abstracted” as a discrete-event system (DES) that is modeled as a timed Petri net. In the DES, robot’s movement between adjacent confliction zones is viewed as a “transition,” by taking the robot kinematics into consideration. To ensure safety and efficiency, robots should not appear at the same conflict position at the same time and should not block each other. To this end, an online IoT-based approach is provided to control robots to travel in the closed workspace safely (without collisions) and efficiently (without deadlocks). Specifically, a high-level supervisory controller whose commands are in the form of transitions, is used to control robots to travel in the closed workspace. At the low level, we explicitly capture the time-driven robot kinematics, and commands from the supervisory controller are translated into appropriate input signals to the actuators of the robots, which in turn influence states of the high-level DES. Simulation results demonstrate the expressiveness of the proposed model and the effectiveness and efficiency of the proposed algorithm.
Junhua Xi, Zhangdong Wang, Yonghao Tang
IEEE Internet Things J.4
2022 Opportunistic Backdoor Attacks: Exploring Human-imperceptible Vulnerabilities on Speech Recognition Systems
abstract
Speech recognition systems, trained and updated based on large-scale audio data, are vulnerable to backdoor attacks that inject dedicated triggers in system training. The used triggers are generally human-inaudible audio, such as ultrasonic waves. However, we note that such a design is not feasible, as it can be easily filtered out via pre-processing. In this work, we propose the first audible backdoor attack paradigm for speech recognition, characterized by passively triggering and opportunistically invoking. Traditional device-synthetic triggers are replaced with ambient noise in daily scenarios. For adapting triggers to the application dynamics of speech interaction, we exploit the observed knowledge inherited from the context to a trained model and accommodate the injection and poisoning with certainty-based trigger selection, performance-oblivious sample binding, and trigger late-augmentation. Experiments on two datasets under various environments evaluate the proposal's effectiveness in maintaining a high benign rate and facilitating outstanding attack success rate (99.27%, ~4% higher than BadNets), robustness (bounded infectious triggers), feasibility in real-world scenarios. It requires less than 1% data to be poisoned and is demonstrated to be able to resist typical speech enhancement techniques and general countermeasures (e.g., dedicated fine-tuning). The code and data will be made available at https://github.com/lqsunshine/DABA.
Qiang Liu 0004, Tongqing Zhou, Zhiping Cai, Yonghao Tang
ACM Multimedia4
2014 Transmit beamforming for DOA estimation based on Cramer-Rao bound optimization in subarray MIMO radar
Yonghao Tang, Weixing Sheng, Yubing Han
Signal Process.1