Ao Liu 0005

dblp:182/7579-5 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
8since 2021 · last 2026
0000-0002-8412-6414ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 5 · 4 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 A feature selection method based on clonal selection with beneficial noise
Wenshan Li 0001, Chenyi Huang, Ao Liu 0005, Beibei Li 0002, Junjiang He, Wenbo Fang
Pattern Recognit.3
2025 Grimm: A Plug-and-Play Perturbation Rectifier for Graph Neural Networks Defending Against Poisoning Attacks
abstract
Recent studies have revealed the vulnerability of graph neural networks (GNNs) to adversarial poisoning attacks on node classification tasks. Current defensive methods require substituting the original GNNs with defense models, regardless of the original's type. This approach, while targeting adversarial robustness, compromises the enhancements developed in prior research to boost GNNs' practical performance. Here we introduce Grimm, the first plug-and-play defense model. With just a minimal interface requirement for extracting features from any layer of the protected GNNs, Grimm is thus enabled to seamlessly rectify perturbations. Specifically, we utilize the feature trajectories (FTs) generated by GNNs, as they evolve through epochs, to reflect the training status of the networks. We then theoretically prove that the FTs of victim nodes will inevitably exhibit discriminable anomalies. Consequently, inspired by the natural parallelism between the biological nervous and immune systems, we construct Grimm, a comprehensive artificial immune system for GNNs. Grimm not only detects abnormal FTs and rectifies adversarial edges during training but also operates efficiently in parallel, thereby mirroring the concurrent functionalities of its biological counterparts. We experimentally confirm that Grimm offers four empirically validated advantages: 1) Harmlessness, as it does not actively interfere with GNN training; 2) Parallelism, ensuring monitoring, detection, and rectification functions operate independently of the GNN training process; 3) Generalizability, demonstrating compatibility with mainstream GNNs such as GCN, GAT, and GraphSAGE; and 4) Transferability, as the detectors for abnormal FTs can be efficiently transferred across different systems for one-step rectification.
Ao Liu 0005, Wenshan Li 0001, Beibei Li 0002, Wengang Ma, Tao Li 0016, Pan Zhou 0001
AAAI1
2025 Graph Agent Network: Empowering Nodes with Inference Capabilities for Adversarial Resilience
abstract
End-to-end training with global optimization have popularized graph neural networks (GNNs) for node classification, yet inadvertently introduced vulnerabilities to adversarial edge-perturbing attacks. Adversaries can exploit the inherent opened interfaces of GNNs' input and output, perturbing critical edges and thus manipulating the classification results. Current defenses, due to their persistent utilization of global-optimization-based end-to-end training schemes, inherently encapsulate the vulnerabilities of GNNs. This is specifically evidenced in their inability to defend against targeted secondary attacks. In this paper, we propose the Graph Agent Network (GAgN) to address the aforementioned vulnerabilities of GNNs. GAgN is a graph-structured agent network in which each node is designed as an 1-hop-view agent. Through the decentralized interactions between agents, they can learn to infer global perceptions to perform tasks including inferring embeddings, degrees and neighbor relationships for given nodes. This empowers nodes to filtering adversarial edges while carrying out classification tasks. Furthermore, agents' limited view prevents malicious messages from propagating globally in GAgN, thereby resisting global-optimization-based secondary attacks. We prove that single-hidden-layer multilayer perceptrons (MLPs) are theoretically sufficient to achieve these functionalities. Experimental results show that GAgN effectively implements all its intended capabilities and, compared to state-of-the-art defenses, achieves optimal classification accuracy on the perturbed datasets.
Ao Liu 0005, Wenshan Li 0001, Tao Li 0016, Beibei Li 0002, Guangquan Xu, Pan Zhou 0001, Wengang Ma, Hanyuan Huang
AAAI1
2024 Towards Inductive Robustness: Distilling and Fostering Wave-Induced Resonance in Transductive GCNs against Graph Adversarial Attacks
abstract
Graph neural networks (GNNs) have recently been shown to be vulnerable to adversarial attacks, where slight perturbations in the graph structure can lead to erroneous predictions. However, current robust models for defending against such attacks inherit the transductive limitations of graph convolutional networks (GCNs). As a result, they are constrained by fixed structures and do not naturally generalize to unseen nodes. Here, we discover that transductive GCNs inherently possess a distillable robustness, achieved through a wave-induced resonance process. Based on this, we foster this resonance to facilitate inductive and robust learning. Specifically, we first prove that the signal formed by GCN-driven message passing (MP) is equivalent to the edge-based Laplacian wave, where, within a wave system, resonance can naturally emerge between the signal and its transmitting medium. This resonance provides inherent resistance to malicious perturbations inflicted on the signal system. We then prove that merely three MP iterations within GCNs can induce signal resonance between nodes and edges, manifesting as a coupling between nodes and their distillable surrounding local subgraph. Consequently, we present Graph Resonance-fostering Network (GRN) to foster this resonance via learning node representations from their distilled resonating subgraphs. By capturing the edge-transmitted signals within this subgraph and integrating them with the node signal, GRN embeds these combined signals into the central node's representation. This node-wise embedding approach allows for generalization to unseen nodes. We validate our theoretical findings with experiments, and demonstrate that GRN generalizes robustness to unseen nodes, whilst maintaining state-of-the-art classification accuracy on perturbed graphs. Appendices can be found on arXiv version: https://arxiv.org/abs/2312.08651
Ao Liu 0005, Wenshan Li 0001, Tao Li 0016, Beibei Li 0002, Hanyuan Huang, Pan Zhou 0001
AAAI1
2024 Chaos-Based Index-of-Min Hashing Scheme for Cancellable Biometrics Security
abstract
Cancellable biometrics is essential for preserving sensitive biometric information from potential exposure. Existing studies usually convert real-valued biometric vectors into protected templates by randomly generated transformation keys. However, this way is realized by the built-in functions of the cancellable biometric system, which creates vulnerabilities for cancellable biometric schemes. In this paper, we propose a novel chaos-based Index-of-Min cancellable biometric scheme, named C-IoM, for privacy-preserving template updates in biometric technique. Specifically, we first design a chaos-based cancellable biometric framework to ensure the security and privacy of the biometric template. Second, we develop a secure random chaos seed generation algorithm, which non-linearly converts the biometric vectors into protected templates and conceals biometric dimensional information. Further, we craft a sliding window selection mechanism to choose the input biometric features, allowing each feature data to fully participate in the generation of protected templates through sliding intervals. Theoretical analysis confirms that the C-IoM satisfies the criteria of irreversibility, revocability, unlinkability, and performance preservation in cancellable biometrics. Extensive experiments on LFW, CFPW, and CASIA-V5 datasets demonstrate the security of the proposed framework in protecting biometric data as well as the superiorities over state-of-the-art schemes.
Wanying Dai, Beibei Li 0002, Qingyun Du, Ao Liu 0005
IEEE Trans. Inf. Forensics Secur.5
2024 AN-GCN: An Anonymous Graph Convolutional Network Against Edge-Perturbing Attacks
abstract
Recent studies have revealed the vulnerability of graph convolutional networks (GCNs) to edge-perturbing attacks, such as maliciously inserting or deleting graph edges. However, theoretical proof of such vulnerability remains a big challenge, and effective defense schemes are still open issues. In this article, we first generalize the formulation of edge-perturbing attacks and strictly prove the vulnerability of GCNs to such attacks in node classification tasks. Following this, an anonymous GCN, named AN-GCN, is proposed to defend against edge-perturbing attacks. In particular, we present a node localization theorem to demonstrate how GCNs locate nodes during their training phase. In addition, we design a staggered Gaussian noise-based node position generator and a spectral graph convolution-based discriminator (in detecting the generated node positions). Furthermore, we provide an optimization method for the designed generator and discriminator. It is demonstrated that the AN-GCN is secure against edge-perturbing attacks in node classification tasks, as AN-GCN is developed to classify nodes without the edge information (making it impossible for attackers to perturb edges anymore). Extensive evaluations verify the effectiveness of the general edge-perturbing attack (G-EPA) model in manipulating the classification results of the target nodes. More importantly, the proposed AN-GCN can achieve 82.7% in node classification accuracy without the edge-reading permission, which outperforms the state-of-the-art GCN.
Ao Liu 0005, Beibei Li 0002, Tao Li 0016, Pan Zhou 0001, Rui Wang 0070
IEEE Trans. Neural Networks Learn. Syst.1
2023 Defending Byzantine attacks in ensemble federated learning: A reputation-based phishing approach
Beibei Li 0002, Peiran Wang, Zerui Shao, Ao Liu 0005, Yukun Jiang 0001
Future Gener. Comput. Syst.4
2021 SFE-GACN: A novel unknown attack detection under insufficient data via intra categories generation in embedding space
Ao Liu 0005, Tao Li 0016
Comput. Secur.1