Zihao Liu 0001

dblp:182/3820-1 · DBLP profile ↗
← Back
7ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0002-6956-8126ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 3 · 1 first-author · 3 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Rethinking Fake Speech Detection: A Generalized Framework Leveraging Spectrogram Magnitude
Zihao Liu 0001, Aobo Chen 0002, Yan Zhang 0133, Chenglin Miao
NDSS1
2026 Defending Autonomous Driving Perception against Adversarial Object-Based Attacks via Motion Planning
abstract
Autonomous vehicles (AVs) rely on perception systems to detect surrounding objects using sensors such as cameras, LiDAR (Light Detection and Ranging), and millimeter-wave (mmWave) radar. However, recent studies have shown that attackers can deceive these systems by strategically placing adversarial objects (e.g., color patches, cardboard, or metal foil) in the driving environment. These attacks pose serious safety risks, yet existing defenses primarily focus on individual sensor modalities and lack generalizability across different sensing systems. To address this gap, we propose the first generalized defense mechanism capable of mitigating various attacks using adversarial objects. Our approach integrates real-time attack detection with trajectory adaptation, guiding the victim AV to positions where the attack is less effective. The defense mechanism combines a deep reinforcement learning (DRL)-based motion planning model, which dynamically adjusts the AV’s trajectory, with an uncertainty-aware filtering scheme that refines perception outputs to enhance detection robustness. Extensive experiments in both simulated and real-world environments demonstrate that our defense mechanism effectively mitigates adversarial object-based attacks across different sensing modalities and sensor fusion while maintaining safe and smooth driving behavior.
Zihao Liu 0001, Yan Zhang 0133, Yi Zhu 0012, Lu Su 0001, Chunming Qiao, Chenglin Miao
SenSys1
2025 Towards Real-Time Defense against Object-Based LiDAR Attacks in Autonomous Driving
abstract
LiDAR (Light Detection and Ranging)-based object detection is a cornerstone of autonomous vehicle perception systems. Modern LiDAR perception relies heavily on deep neural networks (DNNs), which enable accurate object detection by learning geometric features from 3D point clouds. However, recent studies have shown that these systems are vulnerable to object-based adversarial attacks, where physical adversarial objects are strategically placed in the environment to manipulate LiDAR point clouds and mislead detection models. These attacks are practical, stealthy, and require no specialized hardware, posing a serious threat to the safety and reliability of AVs. Despite these risks, existing defense methods suffer from significant limitations, including high computational overhead, limited generalizability and effectiveness, and the inability to operate in real time. In this paper, we propose the first real-time defense mechanism against object-based LiDAR attacks in autonomous driving. Our solution is both detection model-agnostic and attack-agnostic, requiring no prior knowledge of the number, shape, size, or placement of adversarial objects. Positioned between the sensing and perception modules of the AV pipeline, the defense processes LiDAR point clouds in real time and employs a novel generative model that enables efficient and effective identification and removal of adversarial points from suspicious regions. Extensive experiments in both simulated and real-world environments demonstrate that our approach achieves high attack detection rates with minimal latency. This work offers a practical and robust defense solution to a growing security threat in autonomous driving.
Yan Zhang 0133, Zihao Liu 0001, Yi Zhu 0012, Chenglin Miao
CCS2
2024 Backdoor Attacks via Machine Unlearning
abstract
As a new paradigm to erase data from a model and protect user privacy, machine unlearning has drawn significant attention. However, existing studies on machine unlearning mainly focus on its effectiveness and efficiency, neglecting the security challenges introduced by this technique. In this paper, we aim to bridge this gap and study the possibility of conducting malicious attacks leveraging machine unlearning. Specifically, we consider the backdoor attack via machine unlearning, where an attacker seeks to inject a backdoor in the unlearned model by submitting malicious unlearning requests, so that the prediction made by the unlearned model can be changed when a particular trigger presents. In our study, we propose two attack approaches. The first attack approach does not require the attacker to poison any training data of the model. The attacker can achieve the attack goal only by requesting to unlearn a small subset of his contributed training data. The second approach allows the attacker to poison a few training instances with a pre-defined trigger upfront, and then activate the attack via submitting a malicious unlearning request. Both attack approaches are proposed with the goal of maximizing the attack utility while ensuring attack stealthiness. The effectiveness of the proposed attacks is demonstrated with different machine unlearning algorithms as well as different models on different datasets.
Zihao Liu 0001, Tianhao Wang 0001, Mengdi Huai, Chenglin Miao
AAAI1
2024 An Online Defense against Object-based LiDAR Attacks in Autonomous Driving
abstract
LiDAR (Light Detection and Ranging) has been widely used in autonomous driving to perceive the surrounding environment of self-driving cars. Advanced LiDAR perception systems typically leverage deep neural networks (DNNs) to achieve high performance. However, the vulnerability of DNNs to malicious attacks provides attackers with the means to compromise the LiDAR perception system, potentially causing traffic accidents. Recently, object-based attacks against LiDAR perception systems have drawn significant attention. In such attacks, the attacker can easily fool the LiDAR perception system by placing physical objects within the driving environment. Despite the practicality of these attacks and their potential catastrophic consequences in autonomous driving, there is currently no effective and practical defense against them. To address this issue, we propose a novel online defense mechanism against object-based LiDAR attacks. This mechanism operates in an online manner, aiming to identify and remove the adversarial LiDAR points generated by the objects used by attackers before the data is fed into the perception module of autonomous driving systems. It is not only effective and efficient for real-world autonomous driving but also attack-agnostic and capable of identifying adversarial objects used by attackers. Extensive experiments in both simulated environments and real-world scenarios using a LiDAR perception testbed demonstrate the effectiveness and practicability of the proposed defense.
Yan Zhang 0133, Zihao Liu 0001, Chongliu Jia, Yi Zhu 0012, Chenglin Miao
SenSys2
2023 Protecting Your Voice from Speech Synthesis Attacks
abstract
In recent years, much attention has been paid to speech synthesis, which aims to generate synthetic speeches in a voice of a target speaker. Although the speech synthesis technique has facilitated a wide spectrum of applications that positively impact our daily lives, it can also be used by attackers to perform speech synthesis attacks. An attacker can use this technique to mimic the voice of a victim and transform arbitrarily chosen text or voice samples into the same content spoken by the victim. To protect a speaker’s voice from speech synthesis attacks, in this paper, we propose two novel defense schemes that can be used by the speaker to process his or her speeches before publishing them on social media platforms or sending them to others. The processed speeches cannot only significantly degrade the performance of speech synthesis systems but also keep the sound of the speaker’s voice so that they can still be used for normal purposes. The desirable performance of the proposed defense schemes is verified through extensive experiments conducted on several real-world speaker recognition (SR) systems and a user study on a public crowdsourcing platform.
Zihao Liu 0001, Yan Zhang 0133, Chenglin Miao
ACSAC1
2022 Towards Backdoor Attacks against LiDAR Object Detection in Autonomous Driving
abstract
Due to the great advantage of LiDAR sensors in perceiving complex driving environments, LiDAR-based 3D object detection has recently drawn significant attention in autonomous driving. Although many advanced LiDAR object detection models have been developed, their designs are mainly based on deep learning approaches, which are usually data-hungry and expensive to train. Thus, it is common for some LiDAR perception system developers or self-driving car companies to collect training data from different sources (e.g., self-driving car users) or outsource the training work to a third party. However, these practices provide opportunities for backdoor attacks, where the attacker aims to inject a hidden trigger pattern into the victim detection model by poisoning its training set and let the model fail to detect objects when the trigger presents in the inference phase. Although backdoor attacks have posed serious security concerns, the vulnerability of LiDAR object detection to such attacks has not yet been studied. To fill the research gap, in this paper, we present the first study on backdoor attacks against LiDAR object detection in autonomous driving. Specifically, we propose a novel backdoor attack strategy based on which the attacker can achieve the attack goal by poisoning a small number of point cloud samples. In addition, the proposed attack strategy is physically realizable, and it allows the attacker to easily perform the attack using some common objects as the triggers. To make the poisoned samples difficult to be detected, we also design a stealthy attack strategy by creating some fake vehicle point clusters to hide the injected points in the point cloud. The desirable performance of our attacks is demonstrated through both simulation and real-world case study.
Yan Zhang 0133, Yi Zhu 0012, Zihao Liu 0001, Chenglin Miao, Foad Hajiaghajani, Lu Su 0001, Chunming Qiao
SenSys3