VLDB 2026 Research / reviewers in the wild / expert
Lulu Xue
dblp:188/7838
· DBLP profile ↗
13ranked-venue papers
3as first author
13since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 2 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 2 first-author · 5 since 2021Security and privacy · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Dual-View Inference Attack: Machine Unlearning Amplifies Privacy ExposureabstractMachine unlearning is a newly popularized technique for removing specific training data from a trained model, enabling it to comply with data deletion requests. While it protects the rights of users requesting unlearning, it also introduces new privacy risks. Prior works have primarily focused on the privacy of data that has been unlearned, while the risks to retained data remain largely unexplored. To address this gap, we focus on the privacy risks of retained data and, for the first time, reveal the vulnerabilities introduced by machine unlearning under the dual-view setting, where an adversary can query both the original and the unlearned models. From an information-theoretic perspective, we introduce the concept of privacy knowledge gain and demonstrate that the dual-view setting allows adversaries to obtain more information than querying either model alone, thereby amplifying privacy leakage. To effectively demonstrate this threat, we propose DVIA, a Dual-View Inference Attack, which extracts membership information on retained data using black-box queries to both models. DVIA eliminates the need to train an attack model and employs a lightweight likelihood ratio inference module for efficient inference. Experiments across different datasets and model architectures validate the effectiveness of DVIA and highlight the privacy risks inherent in the dual-view setting. Lulu Xue, Shengshan Hu, Linqiang Qian, Peijin Guo, Yechao Zhang, Yanjun Zhang 0002, Dayong Ye, Leo Yu Zhang |
AAAI | 1 |
| 2026 | Scrutinising Parametric Distance Verification in Unlearning: A Coupling Perspective
Jingming Dai, Lulu Xue, Jintian Ji, Yanjun Zhang 0002, Shengshan Hu, Leo Yu Zhang |
ACISP (3) | 2 |
| 2025 | BadRobot: Jailbreaking Embodied LLM Agents in the Physical WorldabstractEmbodied AI represents systems where AI is integrated into physical entities. Multimodal Large Language Model (LLM), which exhibits powerful language understanding abilities, has been extensively employed in embodied AI by facilitating sophisticated task planning. However, a critical safety issue remains overlooked: could these embodied LLMs perpetrate harmful behaviors? In response, we introduce BadRobot, the first attack paradigm designed to jailbreak robotic manipulation, making embodied LLMs violate safety and ethical constraints through typical voice-based user-system interactions. Specifically, three vulnerabilities are exploited to achieve this type of attack: (i) manipulation of LLMs within robotic systems, (ii) misalignment between linguistic outputs and physical actions, and
(iii) unintentional hazardous behaviors caused by world knowledge's flaws. Furthermore, we construct a benchmark of various malicious physical action queries to evaluate BadRobot's attack performance. Based on this benchmark, extensive experiments against existing prominent embodied LLM frameworks (e.g., Voxposer, Code as Policies, and ProgPrompt) demonstrate the effectiveness of our BadRobot. We emphasize that addressing this emerging vulnerability is crucial for the secure deployment of LLMs in robotics.
Warning: This paper contains harmful AI-generated language and aggressive actions. Hangtao Zhang, Chenyu Zhu, Xianlong Wang 0001, Ziqi Zhou 0001, Changgan Yin, Lulu Xue, Yichen Wang 0013, Shengshan Hu, Aishan Liu, Peijin Guo, Leo Yu Zhang |
ICLR | 7 |
| 2025 | Multi-Modality Representation Learning for Antibody-Antigen Interactions PredictionabstractWhile deep learning models play a crucial role in predicting antibody-antigen interactions (AAI), the scarcity of publicly available sequence-structure pairings constrains their generalization. Current AAI methods often focus on residue-level static details, overlooking fine-grained structural representations of antibodies and their inter-antibody similarities. To tackle this challenge, we introduce a multi-modality representation approach that integates 3D structural and 1D sequence data to unravel intricate intra-antibody hierarchical relationships. By harnessing these representations, we present MuLAAIP, an AAI prediction framework that utilizes graph attention networks to illuminate graph-level structural features and normalized adaptive graph convolution networks to capture inter-antibody sequence associations. Furthermore, we have curated an AAI benchmark dataset comprising both structural and sequence information along with interaction labels. Through extensive experiments on this benchmark, our results demonstrate that MuLAAIP outperforms current state-of-the-art methods in terms of predictive performance. The implementation code and dataset are publicly available at https://github.com/trashTian/MuLAAIP for reproducibility. Peijin Guo, Hewen Pan, Ruixiang Huang, Lulu Xue, Shengqing Hu, Zikang Guo, Shengshan Hu |
ICME | 5 |
| 2025 | AdvEDM: Fine-grained Adversarial Attack against VLM-based Embodied AgentsabstractVision-Language Models (VLMs), with their strong reasoning and planning capabilities, are widely used in embodied decision-making (EDM) tasks in embodied agents, such as autonomous driving and robotic manipulation. Recent research has increasingly explored adversarial attacks on VLMs to reveal their vulnerabilities. However, these attacks either rely on overly strong assumptions, requiring full knowledge of the victim VLM, which is impractical for attacking VLM-based agents, or exhibit limited effectiveness. The latter stems from disrupting most semantic information in the image, which leads to a misalignment between the perception and the task context defined by system prompts. This inconsistency interrupts the VLM's reasoning process, resulting in invalid outputs that fail to affect interactions in the physical world. To this end, we propose a fine-grained adversarial attack framework, AdvEDM, which modifies the VLM's perception of only a few key objects while preserving the semantics of the remaining regions. This attack effectively reduces conflicts with the task context, making VLMs output valid but incorrect decisions and affecting the actions of agents, thus posing a more substantial safety threat in the physical world. We design two variants of based on this framework, AdvEDM-R and AdvEDM-A, which respectively remove the semantics of a specific object from the image and add the semantics of a new object into the image. The experimental results in both general scenarios and EDM tasks demonstrate fine-grained control and excellent attack performance. Yichen Wang 0013, Hangtao Zhang, Hewen Pan, Ziqi Zhou 0001, Xianlong Wang 0001, Peijin Guo, Lulu Xue, Shengshan Hu, Leo Yu Zhang |
NeurIPS | 7 |
| 2024 | Revisiting Gradient Pruning: A Dual Realization for Defending against Gradient AttacksabstractCollaborative learning (CL) is a distributed learning framework that aims to protect user privacy by allowing users to jointly train a model by sharing their gradient updates only. However, gradient inversion attacks (GIAs), which recover users' training data from shared gradients, impose severe privacy threats to CL. Existing defense methods adopt different techniques, e.g., differential privacy, cryptography, and perturbation defenses, to defend against the GIAs. Nevertheless, all current defense methods suffer from a poor trade-off between privacy, utility, and efficiency. To mitigate the weaknesses of existing solutions, we propose a novel defense method, Dual Gradient Pruning (DGP), based on gradient pruning, which can improve communication efficiency while preserving the utility and privacy of CL. Specifically, DGP slightly changes gradient pruning with a stronger privacy guarantee. And DGP can also significantly improve communication efficiency with a theoretical analysis of its convergence and generalization. Our extensive experiments show that DGP can effectively defend against the most powerful GIAs and reduce the communication cost without sacrificing the model's utility. Lulu Xue, Shengshan Hu, Ruizhi Zhao, Leo Yu Zhang, Shengqing Hu, Lichao Sun 0001, Dezhong Yao 0002 |
AAAI | 1 |
| 2024 | MISA: Unveiling the Vulnerabilities in Split Federated LearningabstractFederated learning (FL) and split learning (SL) are prevailing distributed paradigms in recent years. They both enable shared global model training while keeping data localized on users’ devices. The former excels in parallel execution capabilities, while the latter enjoys low dependence on edge computing resources and strong privacy protection. Split federated learning (SFL) combines the strengths of both FL and SL, making it one of the most popular distributed architectures. Furthermore, a recent study has claimed that SFL exhibits robustness against poisoning attacks, with a fivefold improvement compared to FL in terms of robustness.In this paper, we present a novel poisoning attack known as $\color{Fuchsia} {{\text{MISA}}}$. It poisons both the top and bottom models, causing a misalignment in the global model, ultimately leading to a drastic accuracy collapse. This attack unveils the vulnerabilities in SFL, challenging the conventional belief that SFL is robust against poisoning attacks. Extensive experiments demonstrate that our proposed MISA poses a significant threat to the availability of SFL, underscoring the imperative for academia and industry to accord this matter due attention. Yuxuan Ning, Shengshan Hu, Lulu Xue, Leo Yu Zhang, Hai Jin 0001 |
ICASSP | 4 |
| 2024 | DarkFed: A Data-Free Backdoor Attack in Federated Learning
Yuxuan Ning, Shengshan Hu, Lulu Xue, Leo Yu Zhang, Yichen Wang 0013 |
IJCAI | 5 |
| 2024 | Securely Fine-tuning Pre-trained Encoders Against Adversarial ExamplesabstractWith the evolution of self-supervised learning, the pre-training paradigm has emerged as a predominant solution within the deep learning landscape. Model providers furnish pre-trained encoders designed to function as versatile feature extractors, enabling downstream users to harness the benefits of expansive models with minimal effort through fine-tuning. Nevertheless, recent works have exposed a vulnerability in pre-trained encoders, highlighting their susceptibility to downstream-agnostic adversarial examples (DAEs) meticulously crafted by attackers. The lingering question pertains to the feasibility of fortifying the robustness of downstream models against DAEs, particularly in scenarios where the pre-trained encoders are publicly accessible to the attackers.In this paper, we initially delve into existing defensive mechanisms against adversarial examples within the pre-training paradigm. Our findings reveal that the failure of current defenses stems from the domain shift between pre-training data and downstream tasks, as well as the sensitivity of encoder parameters. In response to these challenges, we propose Genetic Evolution-Nurtured Adversarial Fine-tuning (Gen-AF), a two-stage adversarial fine-tuning approach aimed at enhancing the robustness of downstream models. Gen-AF employs a genetic-directed dual-track adversarial fine-tuning strategy in its first stage to effectively inherit the pre-trained encoder. This involves optimizing the pre-trained encoder and classifier separately while incorporating genetic regularization to preserve the model’s topology. In the second stage, Gen-AF assesses the robust sensitivity of each layer and creates a dictionary, based on which the top-k robust redundant layers are selected with the remaining layers held fixed. Upon this foundation, we conduct evolutionary adaptability fine-tuning to further enhance the model’s generalizability. Our extensive experiments, conducted across ten self-supervised training methods and six datasets, demonstrate that Gen-AF attains high testing accuracy and robust testing accuracy against state-of-the-art DAEs. Ziqi Zhou 0001, Wei Liu 0304, Shengshan Hu, Yechao Zhang, Lulu Xue, Leo Yu Zhang, Dezhong Yao 0002, Hai Jin 0001 |
SP | 7 |
| 2024 | AMCD-Net: An Effective Attention-Aided Multilevel Cloud Detection Network for Optical Satellite ImageryabstractCloud detection is a prerequisite for optical remote sensing applications due to the ubiquitous cloud coverage and negative effect of cloud occlusions. However, it is very challenging because of the heterogeneity of clouds and diversity of underlying surfaces, especially for thin clouds with illegible shapes and dispersed distribution in addition to high transparency, which is a common bottleneck for most methods. To tackle these problems, this paper proposes an innovative attention aided multilevel cloud detection network (AMCD-Net) for optical satellite imagery. Specifically, AMCD-Net takes full account into the variability and complexity of clouds and integrates multilevel features and different attentions within a deep convolutional U-Net framework, thus enabling more accurate cloud identification in complex scenarios. On the one hand, a multilevel asymmetric convolutional module (MAC) embedded encoder is established to learn discriminative representations for clouds with various shapes and integrate the complementarity of multilevel features to improve model robustness, with a regional attention-based decoder constructed to more accurately recover complicated cloud distribution, which effectively balances the integrity and details of clouds. On the other hand, a deformable convolution-based geometry enhancement attention (GEA) is designed to refine information transmission between the encoder and decoder, with a joint loss of binary cross-entropy (BCE) and structural similarity index (SSIM) constructed to simultaneously focus on category and morphology discriminant excavation, which are favorable for fine-grained cloud prediction. The effectiveness of AMCD-Net was verified on two well-known datasets, i.e., 38-Cloud dataset and SPARCS dataset, and the results demonstrate that it outperformed the other state-of-the-art deep networks. Han Zhai, Lulu Xue |
IEEE Trans. Geosci. Remote. Sens. | 2 |
| 2024 | Depriving the Survival Space of Adversaries Against Poisoned Gradients in Federated LearningabstractFederated learning (FL) allows clients at the edge to learn a shared global model without disclosing their private data. However, FL is susceptible to poisoning attacks, wherein an adversary injects tainted local models that ultimately corrupt the global model. Despite various defensive mechanisms having been developed to combat poisoning attacks, they all fall short of securing practical FL scenarios with heterogeneous and unbalanced data distribution. Moreover, the cutting-edge defenses currently at our disposal demand access to a proprietary dataset that closely mirrors the distribution of clients’ data, which runs counter to the fundamental principle of privacy protection in FL. It is still challenging to devise an effective defense approach that applies to practical FL. In this work, we strive to narrow the divide between FL defense and its practical use. We first present a general framework to comprehend the effect of poisoning attacks in FL when the training data is not independent and identically distributed (non-IID). We then HeteroFL, a novel FL scheme that incorporates four complementary defensive strategies. These tactics are implemented in succession to refine the aggregated model toward approaching the global optimum. Ultimately, we devise an adaptive attack specifically for HeteroFL, aimed at offering a more thorough evaluation of its robustness. Our extensive experiments over heterogeneous datasets and models show that HeteroFL surpasses all state-of-the-art defenses in thwarting various poisoning attacks, i.e., HeteroFL achieves global model accuracies comparable to the baseline, whereas other defenses suffer a significant accuracy reduction ranging from 34% to 79%. Jianrong Lu, Shengshan Hu, Leo Yu Zhang, Lulu Xue, Hai Jin 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2023 | Rice False Smut Extraction Based on the Combination of Instability Index Between Classes and Correlation Coefficient of UAV Hyperspectral Band SelectionabstractRice false smut (RFS) is a late fungal disease mainly occurring on rice panicle in recent years. This research was based on the unmanned aerial vehicle (UAV) hyperspectral remote sensing data. On the basis of genetic algorithm combined with partial least squares to select the feature bands, the correlation coefficient method and Instability Index between Classes method were used to further select the feature bands, which further eliminated 27.78% of the feature bands when the model monitoring accuracy was improved overall. The prediction accuracy of Gradient Boosting Decision Tree model and Random Forest model was the best, which were 85.62% and 84.10% respectively, and the monitoring accuracy was improved by 2.22% and 2.4% compared with that before optimization. Then, based on the UAV hyperspectral data and the characteristic bands, the sensitive band ranges of rice false smut monitoring were determined, which were 698nm-750nm and 974nm-984nm. Minfeng Xing, Lulu Xue, Jianpeng Yin, Chunquan Fan |
IGARSS | 3 |
| 2023 | Extraction of Row Centerline at the Early Stage of Corn Growth Based on UAV ImagesabstractAutomatic extraction of crop row centerline is an important technology for agricultural automation, and it has a wide range of applications in automated operations, such as automatic agricultural navigation, automatic harvesting, automatic weeding and automatic seedling replenishment. In this study, the method of row centerline detection is proposed by combining image segmentation and the technique of feature point extraction, and it is applied to the extraction of corn missing seedling locations. Firstly, image segmentation is performed by combining the improved vegetation index ExGG and a double-threshold algorithm (the OTSU method combined with the Particle Swarm Optimization algorithm), and most of the pseudo-feature points are removed using median filtering to initially separate corn seedlings from weeds and soil. Then, the number of crop rows is obtained using the vertical projection method; the micro-region of interest(micro-ROI) is used to find the center of mass and extract the feature points. Finally, the remaining pseudo-feature points are removed by the location clustering method, and the crop row centerline is fitted using the linear regression method of least squares. This study extracts the location and number of missing seedlings of corn based on the information from the row centerline, providing technical support for the subsequent seedling replenishment operation. The experimental results show that the accuracy of the proposed method for detecting the centerline of corn seedling rows is 0.016°, which is better than the Hough transform. Lulu Xue, Minfeng Xing, Jianpeng Yin, Chunquan Fan |
IGARSS | 1 |