Linghui Li 0001

dblp:19/10136-1 · DBLP profile ↗
← Back
16ranked-venue papers
1as first author
16since 2021 · last 2026
0000-0002-7614-3142ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 9 since 2021Computer networks · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 A Unified Defense Framework Against Membership Inference in Federated Learning via Distillation and Contribution-Aware Aggregation
Linghui Li 0001, Xiaotian Si, Ziduo Guo, Xingwu Wang, Kaiguo Yuan
NDSS2
2026 PrivGITD: A High Accuracy and Privacy-Preserving Graph Convolutional Network for Insider Threat Detection
abstract
Ensuring data security is a fundamental challenge in Internet of Things (IoT) deployments, where massive numbers of interconnected devices continuously transmit, process, and store sensitive information. Among the various security threats, insider threats have emerged as the most critical risk, as malicious insiders with authorized access can directly compromise data integrity and confidentiality. Existing detection approaches often focus solely on improving detection accuracy, while neglecting the structural information embedded in user-device interactions and the imperative need for privacy-preserving mechanisms in sensitive environments. To address these challenges, we proposed PrivGITD, a privacy-preserving insider threat detection framework based on local differential privacy and graph modularization. Specifically, PrivGITD introduces a PageRank-based Structural Reconstruction module that quantifies node importance and reconstructs topological embeddings to capture both local and global interaction patterns. Additionally, a Local Differential Privacy (LDP)-based Feature Encoding module perturbs and calibrates user features, ensuring privacy protection while maintaining statistical utility. Furthermore, a Label Perturbation and Denoising Learning strategy refines randomized labels via multi-hop aggregation and soft supervision. Extensive experiments demonstrate that PrivGITD outperforms state-of-the-art methods, achieving higher detection accuracy while effectively preserving privacy.
Ximing Li 0005, Huizheng Geng, Linghui Li 0001
IEEE Internet Things J.3
2026 Black-Box Adaptation for Deepfake Detection via Local Relation Guided AUC Optimization
abstract
Deepfake technologies pose a growing threat to the Internet of Things (IoT), enabling identity spoofing and the spread of misinformation. Although numerous face forgery detectors have been developed to counter these risks, their realworld deployment is often limited by inherent dataset biases. Existing domain adaptation techniques offer potential remedies, but typically rely on access to raw source data and employ data-dependent alignment strategies under a transductive learning paradigm, raising substantial privacy concerns for source domain individuals. This study revisits the problem from the perspective of black-box domain adaptation and introduces a detection framework that leverages only the predictions from the source model. The method is grounded in a local relation-guided AUC optimization strategy, which leverages the robustness of AUC-based objectives in noisy environments while addressing the limitations of conventional AUC optimization, particularly its vulnerability to confirmation bias and reliance on a fixed decision threshold. To this end, two key components are introduced. First, a nearest-neighbor calibration mechanism is presented, where the local relation feature (LRF), a parameter-free representation, captures differences between real and fake images without favoring specific forgery types, thereby reducing bias inherited from the source model. Second, a GMM-based adaptive thresholding scheme is employed to address asymmetric predictions by dynamically determining the optimal decision boundary for real and fake images. Experiments across multiple datasets show that our approach achieves superior generalization compared to state-of-the-art methods. Moreover, the framework is compatible with a broad range of source and target model configurations to enhance detection performance.
Xiaotian Si, Linghui Li 0001, Bingyu Li 0003, Ziduo Guo, Kaiguo Yuan, Qi Tian 0001
IEEE Internet Things J.2
2026 Quality-Agnostic Deepfake Detection With Saliency-Guided Restoration and Adaptive Fusion
abstract
Deepfake technology poses a significant threat to the Internet of Things by enabling identity spoofing and the dissemination of misinformation. Although numerous face forgery detectors have been developed to counter the risks of facial deepfakes, detecting forgeries across varying quality levels, particularly under extreme degradations, remains a critical challenge. Current face forgery detection methods largely rely on identifying low-level artifacts, which are highly susceptible to distortions introduced by image degradation. Recognizing that restoration can recover critical forensic cues from severely degraded forgeries, this study proposes a quality-agnostic deepfake detection framework that leverages a blind face restoration model to enhance robustness. The framework incorporates an auxiliary restoration branch alongside the original detection pathway. While the original branch operates directly on the degraded input, the restoration branch performs detection on facial images restored by a blind face restoration model. In addition, a Saliency-Guided Restoration objective is introduced to enhance alignment between the restoration and detection tasks. A Restoration Similarity-Aware Fusion mechanism is further designed to adaptively integrate predictions from both branches based on input quality. To assess the robustness of our approach under extreme degradation, we establish a specialized, real-world-inspired benchmark that simulates diverse degradation scenarios. Comprehensive experiments on both the proposed and existing benchmarks demonstrate that our method consistently achieves superior robustness in various degradation scenarios.
Xiaotian Si, Linghui Li 0001, Zhihao Tang 0002, Bingyu Li 0003, Kaiguo Yuan, Hong Liu 0009, Qi Tian 0001
IEEE Internet Things J.2
2025 DCARL: Decoupled-Curriculum for Adversarial Robustness Learning under Long-Tailed Distributions
abstract
Deep neural networks are highly susceptible to adversarial attacks. Although adversarial training is an effective defense, its efficacy in long-tailed settings remains limited. Current methods are constrained in long-tailed scenarios by early representation bias, imbalanced optimization, and insufficient class-aware adaptivity. To address these challenges, we propose Decoupled-Curriculum Adversarial Robustness Learning, a two-stage framework. The Initial Representation and Balancing stage employs inter-class margin adjustment via LDAM with a Deferred Re-weighting schedule to build balanced, transferable representations. The Adaptive Correctness-Aware Robustness Learning stage adapts the per-class PGD perturbation budget using class-wise correctness signals and optimizes a balanced loss that combines mean, medium-class protection, and tail-class reinforcement components, aligning robust learning across head, medium, and tail classes. Experiments on standard long-tailed benchmarks validate the effectiveness of our approach, yielding consistent improvements in both natural and robust performance.
Linghui Li 0001, Kaiguo Yuan, Bingyu Li 0003
TrustCom2
2025 Adaptive Multi-Feature Hierarchical Framework for Generative Model Attribution
abstract
The rapid progress of generative adversarial networks (GANs) and diffusion models (DMs) has enabled photorealistic image synthesis, raising critical concerns about image authenticity verification and source attribution. Existing hierarchical detection frameworks remain constrained by error propagation, weak cross-layer information sharing, and limited discriminative power for highly similar architectures. To address these challenges, we propose a multi-feature adaptive hierarchical framework for fine-grained attribution of AI-generated images. The framework first unifies complementary representations from frequency, noise, color, and semantic domains through a multi-feature extraction module, providing richer cues beyond conventional designs. We then introduces adaptive mechanisms—including dynamic decisionmaking, confidence-weighted fusion, and dual-path classification—that mitigate cascading errors and enable flexible dependency control across layers. Extensive experiments on a large-scale dataset validate the effectiveness of our approach, showing clear improvements over conventional methods and state-of-the-art detectors, particularly in distinguishing confusable GAN variants such as ProGAN, StyleGAN, and StyleGAN2. These results demonstrate the robustness and scalability of the proposed design for reliable AIGC detection and model attribution.
Ruoying Wang, Linghui Li 0001, Xiaotian Si, Kaiguo Yuan
TrustCom2
2025 Auto-GAN: GAN-Based Self-Supervised Collaborative Learning for Robust Spatio-Temporal Trajectory Classification in IoT
abstract
With the rapid proliferation of crowd mobility data produced by ubiquitous mobile devices equipped with spatial positioning modules, deep neural networks (DNNs) have become widely applied in spatio-temporal trajectory modeling. However, recent studies have shown that DNNs are vulnerable to adversarial examples with strong transferability, which are crafted by introducing small perturbations to original examples but can cause catastrophic mistakes. To mitigate this vulnerability and enhance model robustness, we propose a novel self-supervised collaborative learning framework named Auto-GAN that consists of a generator for automatically learning robust latent features and a discriminator for providing comprehensive guidance to the generator. By leveraging the collaboration between the generator and discriminator, our proposed method significantly improves the denoising performance. Moreover, we combine point-level and feature-level constraints into training processes between original example reconstruction and adversarial example denoising, thereby effectively suppressing the potential “error amplification effect". Extensive experiments conducted on two representative real-world mobility datasets show that our proposed method can significantly enhance the model’s robustness against various adversarial attacks, while preserving the model’s prediction accuracy on original examples.
Jia Jia 0007, Linghui Li 0001, Ximing Li 0005, Binsi Cai, Xu Zhang 0006, Pengfei Qiu
IEEE Internet Things J.2
2025 SGAMF: Sparse Gated Attention-Based Multimodal Fusion Method for Fake News Detection
abstract
In the field of fake news detection, deep learning techniques have emerged as superior performers in recent years. Nevertheless, the majority of these studies primarily concentrate on either unimodal feature-based methodologies or image-text multimodal fusion techniques, with a minimal focus on the fusion of unstructured text features and structured tabular features. In this study, we present SGAMF, a Sparse Gated Attention-based Multimodal Fusion strategy, designed to amalgamate text features and auxiliary features for the purpose of fake news identification. Compared with traditional multimodal fusion methods, SGAMF can effectively balance accuracy and inference time while selecting the most important features. A novel sparse-gated-attention mechanism has been proposed which instigates a shift in text representation conditioned on auxiliary features, thereby selectively filtering out non-essential features. We have further put forward an enhanced ALBERT for the encoding of text features, capable of balancing efficiency and accuracy. To corroborate our methodology, we have developed a multimodal COVID-19 fake news detection dataset. Comprehensive experimental outcomes on this dataset substantiate that our proposed SGAMF delivers competitive performance in comparison to the existing state-of-the-art techniques in terms of accuracy and$F_{1}$score.
Yali Gao 0004, Linghui Li 0001, Xiaoyong Li 0003
IEEE Trans. Big Data3
2024 Gopher: High-Precision and Deep-Dive Detection of Cryptographic API Misuse in the Go Ecosystem
abstract
The complexity of cryptographic APIs and developers' expertise gaps often leads to their improper use, seriously threatening information security. Existing cryptographic API misuse detection tools that rely on black/white-list methods require experts to manually establish detection rules. They struggle to dynamically update rules and scale to cover numerous unofficial cryptographic libraries. Furthermore, as these tools are primarily aimed at non-Go languages, they have limited applicability and accuracy in the Go ecosystem, which is extensively used for security-centric applications. To mitigate these challenges, we present Gopher, a novel cryptographic misuse detection framework, that excels in encapsulated API and cross-library detection. In this framework, we have designed CryDict to convert rules into unified and standardized constraints, capable of deriving new usage rules and elucidating implicit knowledge during scanning. Gopher leverages CryDict to create a logical separation between rule formulation and Detector detection, enabling dynamic updating of constraints and enhancing detection capabilities. This significantly improves the Gopher 's compatibility and scalability. Utilizing Gopher, we have conducted an extensive analysis of the Go ecosystem, examining 19,313 Go projects. In our rigorous testing, Gopher demonstrated a remarkable 98.9% accuracy rate and identified 64.1% of previously undetected misuses. This scrutiny has surfaced numerous hidden security vulnerabilities, and highlighted misuse tendencies across diverse project categories.
Yuexi Zhang, Bingyu Li 0003, Jingqiang Lin 0001, Linghui Li 0001, Jia-Ju Bai, Shijie Jia 0001, Qianhong Wu
CCS4
2024 Domain-Knowledge Enhanced GANs for High-Quality Trajectory Generation
Jia Jia 0007, Linghui Li 0001, Pengfei Qiu, Binsi Cai, Xu Kang 0001, Ximing Li 0005, Xiaoyong Li 0003
ICIC (9)2
2024 GMFITD: Graph Meta-Learning for Effective Few-Shot Insider Threat Detection
abstract
Insider threats represent a significant challenge in both corporate and governmental sectors. Most existing supervised learning based detection methods that rely on transforming user behavior into sequential data do not fully utilize structural information and require extensive labeled data. This reliance poses a challenge due to the scarcity of labeled data in real-world scenarios, leading to a few-shot learning situation. To address these limitations, we propose a novel Graph modularized-based Meta-learning Framework for Insider Threat Detection, named GMFITD. Specifically, GMFITD utilizes a structural reconstruction mechanism that combines a graph-based autoencoder with an attention mechanism to explore structural information and infer potential relationships between users. Additionally, we employ a graph prototype construction method coupling episodic meta-learning principle (MAML) to compute representative embeddings for few-shot learning scenarios. By leveraging MAML, the proposed method can capture prior knowledge of insider threat classification by training on similar few-shot learning tasks with few labeled samples. We further enhance the resilience of GMFITD to adversarial attacks through an edge importance estimation mechanism, which assigns higher weights to relevant edges. Extensive experiments demonstrate that our proposed GMFITD outperforms state-of-the-art methods in insider threat detection, achieving higher accuracy with fewer labeled samples and resisting adversarial attacks.
Ximing Li 0005, Linghui Li 0001, Xiaoyong Li 0003, Binsi Cai, Jia Jia 0007, Yali Gao 0004, Shui Yu 0001
IEEE Trans. Inf. Forensics Secur.2
2023 Efficient Membership Inference Attacks against Federated Learning via Bias Differences
abstract
Federated learning aims to complete model training without private data sharing, but many privacy risks remain. Recent studies have shown that federated learning is vulnerable to membership inference attacks. The weight as an important parameter in neural networks has been proven effective for membership inference attacks, but it leads to significant overhead. Facing this issue, in this paper, we propose a bias-based method for efficient membership inference attacks against federated learning. Different from the weight that determines the direction of the decision surface, the bias also plays an important role in determining the distance to move along the direction. Moreover, the number of bias is way less than the weight. We consider two types of attacks: local attack and global attack, corresponding to two possible types of insiders: participant and central aggregator. For the local attack, we design a neural network-based inference, which fully learns the vertical bias changes of the member data and non-member data. For the global attack, we design a difference comparison-based inference to determine the data source. Extensive experimental results on four public datasets show that the proposed method achieves state-of-the-art inference accuracy. Moreover, experiments prove the effectiveness of the proposed method to resist some commonly used defenses.
Linghui Li 0001, Xiaoyong Li 0003, Binsi Cai, Yali Gao 0004, Ruobin Dou, Luying Chen
RAID2
2023 TGCN-DA: A Temporal Graph Convolutional Network with Data Augmentation for High Accuracy Insider Threat Detection
abstract
Insider threats present a formidable challenge to cybersecurity, as insiders possess the privileges and information necessary to execute diverse attacks. A comprehensive analysis of user behavior, including behavioral features, sequences, and inter-user relationships, is required for effective insider threat detection. However, few existing methods consider these features in an integrated manner, which could result in high false positives. To further improve the accuracy of insider threat detection, we propose a novel framework for insider threat detection based on a temporal graph convolutional network with data augmentation (referred to as TGCN-DA), which integrates the exploration of structural information among users and simultaneously captures the behavior temporal dependencies. In particular, we introduce an edge predictor to encode user structural information and strengthen intra-class edges among users based on the representation of users’ behavior. Additionally, the GCN with temporal feature mechanism is leveraged to learn dynamic changes in users’ behavior to capture behavior temporal dependence. Extensive experiments demonstrate that our proposed TGCN-DA outperforms other state-of-the-art methods and achieves higher accuracy in the task of insider threat detection.
Ximing Li 0005, Linghui Li 0001, Xiaoyong Li 0003, Binsi Cai, Bingyu Li 0003
TrustCom2
2023 A High Accuracy and Adaptive Anomaly Detection Model With Dual-Domain Graph Convolutional Network for Insider Threat Detection
abstract
Insider threat is destructive and concealable, making addressing it a challenging task in cybersecurity. Most existing methods transform user behavior into sequential information and analyze user behavior while neglecting structural information among users, resulting in high false positives. To solve this problem, in this paper, we propose Dual-Domain Graph Convolutional Network (referred to as DD-GCN), a graph-based modularized method for high accuracy and adaptive insider threat detection. The central idea is to convert user features and structural information into heterogeneous graphs in the light of various relationships and take user behavior and relationship into account together. To this end, a weighted feature similarity mechanism is applied to balance the feature similarity of users and original linkages among them so as to generate the fused structure. Next, specific graph embeddings are extracted from the original topology structure and fused structure simultaneously, which convert behavior information into high-level representations. Furthermore, an attention mechanism is applied to learn the adaptive importance weights of the user’s features in the corresponding embedding. The combination and difference constraints are proposed to enhance the learned embeddings’ commonality and the ability to capture different information. Extensive experiments on two real-world datasets clearly show that our proposed DD-GCN extracts the most correlated information from structural topology and feature information substantially, and achieves improved accuracy with a clear margin.
Ximing Li 0005, Xiaoyong Li 0003, Jia Jia 0007, Linghui Li 0001, Jie Yuan 0001, Yali Gao 0004, Shui Yu 0001
IEEE Trans. Inf. Forensics Secur.4
2022 Adaptive Spatial Location With Balanced Loss for Video Captioning
abstract
Many pioneering approaches have verified the effectiveness of utilizing the global temporal and local object information for video understanding tasks and have achieved significant progress. However, existing methods utilize object detectors to extract all objects overall video frames. This may bring performance degradation due to the information redundancy both spatially and temporally. To address this problem, we propose an adaptive spatial location module for the video captioning task which dynamically predicts an important position of each video frame in the procedure of generating the description sentence. The proposed adaptive spatial location method not only makes our model focus on local object information, but also reduces time and memory consumption brought by the temporal redundancy in extensive video frames and improves the accuracy of generated description. Besides, we propose a balanced loss function to address the class imbalance problem existing in training data. The proposed balanced loss assigns different weight to each word of ground-truth sentence in the training process which can generate more diversified description sentences. Extensive experimental results on the MSVD and MSR-VTT dataset show that the proposed method achieves competitive performance compared to state-of-the-art methods.
Linghui Li 0001, Yongdong Zhang 0001, Sheng Tang, Lingxi Xie, Xiaoyong Li 0003, Qi Tian 0001
IEEE Trans. Circuits Syst. Video Technol.1
2021 TKCA: a timely keystroke-based continuous user authentication with short keystroke sequence in uncontrolled settings
abstract
Abstract Keystroke-based behavioral biometrics have been proven effective for continuous user authentication. Current state-of-the-art algorithms have achieved outstanding results in long text or short text collected by doing some tasks. It remains a considerable challenge to authenticate users continuously and accurately with short keystroke inputs collected in uncontrolled settings. In this work, we propose a Timely Keystroke-based method for Continuous user Authentication, named TKCA. It integrates the key name and two kinds of timing features through an embedding mechanism. And it captures the relationship between context keystrokes by the Bidirectional Long Short-Term Memory (Bi-LSTM) network. We conduct a series of experiments to validate it on a public dataset - the Clarkson II dataset collected in a completely uncontrolled and natural setting. Experiment results show that the proposed TKCA achieves state-of-the-art performance with 8.28% of EER when using only 30 keystrokes and 2.78% of EER when using 190 keystrokes.
Chen Li 0066, Ruibang You, Bibo Tu, Linghui Li 0001
Cybersecur.5