VLDB 2026 Research / reviewers in the wild / expert
Xinjing Liu
dblp:193/2620
· DBLP profile ↗
21ranked-venue papers
7as first author
21since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 3 first-author · 9 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-author · 4 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Diffusion-Assisted Progressive Learning for Weakly Supervised Phrase LocalizationabstractWeakly supervised phrase localization (WSPL) aims to localize visual objects mentioned by given phrases, but it learns without human-annotated bounding boxes. Previous works struggle in multi-object scenarios where objects in the background often appear simultaneously with the target objects. To this end, we propose a Diffusion-Assisted PrOgressive learning framework (i.e., DAPO) for WSPL task in this paper. Specifically, we score the difficulty of training samples based on the quantity of objects and the level of semantic alignment. These samples are then used progressively during training, in an order by their difficulty scores. To address the sample imbalance problem, we propose a Generation-Assisted Tuning (GAT) method for the grounding network. First, to enrich the samples from few-object scenarios, we leverage Stable Diffusion (SD) to generate images with phrases. Second, we introduce an attention-driven scheme to direct SD's attention on the mentioned objects. Finally, we design a diffusion-guided loss, which helps the grounding network learn the objects' layouts. Extensive experiments show that our DAPO framework outperforms the strong baselines on benchmark datasets. Pengyue Lin, Yanyang Hu, Xinjing Liu, Wenqi Jia 0006, Fangxiang Feng, Ruifan Li |
AAAI | 3 |
| 2026 | Improving Sustainability of Adversarial Examples in Class-Incremental LearningabstractCurrent adversarial examples (AEs) are typically designed for static models. However, with the wide application of Class-Incremental Learning (CIL), models are no longer static and need to be updated with new data distributed and labeled differently from the old ones. As a result, existing AEs often fail after CIL updates due to significant domain drift. In this paper, we propose SAE to enhance the sustainability of AEs against CIL. The core idea of SAE is to enhance the robustness of AE semantics against domain drift by making them more similar to the target class while distinguishing them from all other classes. Achieving this is challenging, as relying solely on the initial CIL model to optimize AE semantics often leads to overfitting. To resolve the problem, we propose a Semantic Correction Module. This module encourages the AE semantics to be generalized, based on a generative model capable of producing universal semantics. Additionally, it incorporates the CIL model to correct the optimization direction of the AE semantics, guiding them closer to the target class. To further reduce fluctuations in AE semantics, we propose a Filtering-and-Augmentation Module, which first identifies non-target examples with target-class semantics in the latent space and then augments them to foster more stable semantics. Comprehensive experiments demonstrate that SAE outperforms baselines by an average of 31.28% when updated with a 9-fold increase in the number of classes. Taifeng Liu, Xinjing Liu, Liangqiu Dong, Yang Liu 0118, Yilong Yang 0004, Zhuo Ma 0001 |
AAAI | 2 |
| 2026 | OX-MABSR: A Benchmark for Open-domain Explainable Multimodal Aspect-Based Sentiment ReasoningabstractMultimodal Aspect-Based Sentiment Analysis (MABSA) involves extracting aspect terms from text-image pairs and identifying their sentiments. Most existing tasks consider one fixed sentiment category with explicitly mentioned aspects. However, these tasks seldom consider expressive sentiment categories, implicit aspects, and explainability. To this end, we introduce a novel task of Open-domain Explainable Multimodal Aspect-Based Sentiment Reasoning (OX-MABSR). This task enables the prediction of open-vocabulary aspect-sentiment pairs, together with the generation of sentiment explanations and reasoning paths. To benchmark OX-MABSR task, we construct OX-MABSR-Bench, a dataset annotated with explicit and implicit aspects, expressive sentiment categories, as well as perceptual and cognitive two-level explanations. The explanations capture visual and textual cues, including aesthetics, facial expressions, scenes, and textual semantics, together with background and situational knowledge. In addition, we annotate the reasoning paths that trace how the sentiment evolves from surface cues to a deeper contextual understanding. To address OX-MABSR task, we propose MABSR-LLM. Extensive experimental results show our MABSR-LLM outperforms strong baselines. To the best of our knowledge, we are the first to provide a unified framework for open-domain and explainable MABSR. Xinjing Liu, Zixin Xue, Pengyue Lin, Xinyu Tu, Siwei Xu, Ruifan Li |
AAAI | 1 |
| 2026 | AttMark: Attention Based Model Watermarking Against Stealing AttacksabstractModel watermarking is a technique that embeds identification information as watermarks to verify model ownership and protect model priority against model stealing (MS) attacks. Watermark is a type of external knowledge which typically make a model sensitive to a specific trigger pattern, causing it to misclassify patterns to a targeted class. However, current fixed form of trigger pattern makes watermarks easy to be recovered by adversaries, thus compromising their secrecy. In this paper, we propose a new approach, named AttMark, which can generate unique patterns for each input via a group of generators. The application of generators adds randomness to trigger patterns by embedding characters into samples in various ways. Therefore, it challenges the convergence of watermark recovering algorithms of adversaries. Nevertheless, random trigger patterns render them more difficult to be embedded, making it even more challenging to transfer watermarks to stolen models. Thus, we design attention-based watermarks that leverage the characteristic of attention transferring in MS attacks. By minimizing the attention deviation caused by random trigger patterns, we enable the stolen model to learn watermarks simultaneously with the primary task. AttMark is evaluated on three major MS attacks and the watermark validation rate is tested against recovering and removal attacks. The results show that our watermark cannot be recovered by adversaries and has a$30\%$stronger transferability compared to prior works. Our code will be available11https://github.com/LiuJingjinga/AttMark.git. Xinjing Liu, Zhuo Ma 0001, Yang Liu 0118, Taifeng Liu, Zhan Qin |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Urey-ML: A Machine Learning-Based Distance Deception Attack Against Apple UWB Interaction FrameworksabstractUltra-Wideband (UWB) technology has recently emerged as a transformative enabler of high-precision positioning systems. Despite its growing adoption across diverse applications, prior studies have claimed several successful distance deception attacks against UWB. To address heightened security concerns, companies like Apple introduce the ranging-awareness defense mechanism into their new version of the UWB interaction frameworks, which is proven to be effective against most known attacks. In this paper, we critically focus on the design flaws of state-of-the-art UWB interaction frameworks and propose Urey-ML, a novel machine learning-based UWB distance deception attack targeting UWB systems. To the best of our knowledge, this is the first attack capable of circumventing the defense mechanisms implemented in Apple’s UWB Nearby Interaction Framework (ANIF). Specifically, Urey-ML is built upon two critical breakthroughs. First, through network packet analysis, we discover that ANIF leaves a crucial message for key negotiation in an unprotected state. This vulnerability enables Urey-ML to bypass the encryption protection implemented by standard UWB systems. Second, to break the ranging-awareness defense, Urey-ML involves a reinforcement learning-based algorithm to optimize attack parameters. By leveraging this approach, Urey-ML can automatically and craftily generate attack signals that mimic the variations typically caused by normal human movement. Our experiments on commercial-off-the-shelf UWB products show that Urey-ML achieves centimeter-level UWB distance deception, with more than 25.79% signals circumventing the defense check of the victim device, which is only 0.56% (or failed) in prior works. Yang Liu 0118, Man Sun, Xinjing Liu, Yong Zeng 0002, Jiayu Jin, Zhuo Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2026 | PROTheft: A Projector-Based Model Extraction Attack in the Physical World
Xinjing Liu, Yilong Yang 0004, Taifeng Liu, Leo Yu Zhang, Yanjun Zhang 0002, Yang Liu 0118, Zhuo Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2026 | Catch Me If You Can: Retain High Stealthiness and Durability of Backdoor Attack in Federated LearningabstractFederated Learning (FL) is vulnerable to backdoor attacks by design since it cannot inspect clients’ local data to protect their privacy. This privacy-preserving feature creates an opportunity for malicious clients to introduce backdoors. However, existing backdoor attacks face two main limitations. First, brute amplification (i.e., uniformly scaling up malicious parameters) can be easily detected, hence compromising attack stealthiness. Second, evasion strategies employed to prevent their backdoors from being overwritten by benign updates are frequently ineffective, reducing the overall attack stability upon model deployment. To address these limitations, we propose an adaptive proactive boosting strategy to enhance both the stealthiness and durability of backdoor attacks in FL. As a concrete example,ReBAintroduces a durable importance metric based on stability degrees of parameters as an update mask for malicious attackers, assigning higher weights to backdoor-related parameters during the update process. To ensure stealthiness,ReBAformulates an optimization problem regarding amplification factor by minimizing the distance between malicious and clean updates, thereby correcting malicious updates within a benign distance space. Extensive evaluations on 3 datasets and across 14 defenses demonstrate the efficacy ofReBA, outperforming over 12 baseline backdoor attacks. Our code is available at https://anonymous.4open.science/r/ReBA-D82F. Yilong Yang 0004, Xinjing Liu, Zefeng Wu, Zhuoran Ma 0002, Yong Zeng 0002, Xianjia Meng, Zhuo Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Multimodal Aspect-Based Sentiment Analysis under Conditional RelationabstractMultimodal Aspect-Based Sentiment Analysis (MABSA) aims to extract aspect terms from text-image pairs and identify their sentiments. Previous methods are based on the premise that the image contains the objects referred by the aspects within the text. However, this condition cannot always be met, resulting in a suboptimal performance. In this paper, we propose COnditional Relation based Sentiment Analysis framework (CORSA). Specifically, we design a conditional relation detector (CRD) to mitigate the impact of the unmet conditional image. Moreover, we design a visual object localizer (VOL) to locate the exact condition-related visual regions associated with the aspects. With CRD and VOL, our CORSA framework takes a multi-task form. In addition, to effectively learn CORSA we conduct two types of annotations. One is the conditional relation using a pretrained referring expression comprehension model; the other is the bounding boxes of visual objects by a pretrained object detection model. Experiments on our built C-MABSA dataset show that CORSA consistently outperforms existing methods. The code and data are available at https://github.com/Liuxj-Anya/CORSA. Xinjing Liu, Ruifan Li, Shuqin Ye, Guangwei Zhang 0003, Xiaojie Wang 0006 |
COLING | 1 |
| 2025 | SafeLead: Detecting and Excluding Random STS Attack in UWB Ranging System
Zhuo Ma 0001, Jiayu Jin, Yang Liu 0118, Yilong Yang 0004, Xinjing Liu, Teng Li 0003, Junwei Zhang 0001, Jianfeng Ma 0001 |
INFOCOM | 5 |
| 2025 | SDG-MLLM: Injecting Structured Dialogue Graphs into MLLM for Multimodal Conversational Aspect-Based Sentiment AnalysisabstractMultimodal Conversational Aspect-based Sentiment Analysis (MCA BSA) is a challenging task for multimodal dialogue understanding. Existing works often treat the entire dialogue as a flat sequence and feed it into Large Language Models (LLMs) for pipeline-style generation. However, these methods sometimes accumulate errors and overlook critical discourse structure and fine-grained inter-word relations that are essential for accurate sentiment reasoning. To address these limitations, we propose SDG-MLLM, a unified generative framework that integrates Structured Dialogue Graphs into Multimodal LLM (MLLM) for an end-to-end MCABSA. Specifically, we construct heterogeneous dialogue graphs that capture diverse structural relations, including syntactic dependencies, coreference links, speaker turns, reply flow, semantic role labeling, and sentiment propagation paths. These graphs are encoded using a heterogeneous dialogue graph encoder, and the resulting structure-aware graph features are injected into the embedding layer of LLM. Furthermore, SDG-MLLM incorporates aligned multimodal features such as image, audio, and video cues at the utterance level to enable unified and context-aware multimodal reasoning. Experiments on the MCABSA dataset show that SDG-MLLM significantly outperforms strong baselines across multiple tasks. In addition, our method also achieved top performance in the ACM MM 2025 Grand Challenge of MCABSA. Our code is available at https://github.com/Liuxj-Anya/SDG-MLLM. Xinjing Liu, Pengyue Lin, Xinyu Tu, Wenqi Jia 0006, Ruifan Li |
ACM Multimedia | 1 |
| 2025 | L-HAWK: A Controllable Physical Adversarial Patch Against a Long-Distance Target
Taifeng Liu, Yang Liu 0118, Zhuo Ma 0001, Tong Yang 0003, Xinjing Liu, Teng Li 0003, Jianfeng Ma 0001 |
NDSS | 5 |
| 2025 | MarkErase: Defeating Entangled Watermarks in Model Extraction Attacks
Xinjing Liu, Yanjun Zhang 0002, Haizhuan Yuan, Tianqing Zhu, Leo Yu Zhang |
PAKDD (4) | 2 |
| 2025 | S-Teapot: Swift and Efficient Defense Against Patch-Based Backdoor AttackabstractRecent studies emphasize the serious threat posed by backdoor attacks when training deep models on data from untrustworthy sources. Despite the emergence of various backdoor attack paradigms, the patch-based approach stands out as the most sought-after and effective method of poisoning. However, current defenses against such attacks often exhibit rudimentary and highly inefficient, sometimes necessitating days for implementation. To mitigate this, we propose a swift and efficient defense against patch-based backdoor attacks, calledS-teapot.S-teapotrapidly identifies whether an untrusted dataset has been backdoored and determines the backdoored labels based on the model's high confidence in the poisoning sample and the consistency of the backdoor pixels.S-teapotoutperforms existing backdoor attack detection schemes by a speedup factor ranging from 30 to 259. Furthermore, we leverage the abnormality of the backdoor pixels to reverse the backdoor trigger, resulting in a similarity increase of 0.6 to 32 times compared to existing methods. To obtain a clean model,S-teapotaccurately localizes poisoning samples through similarity calculations, with nearly 100% precision. Leveraging the precision of the reverse triggers,S-teapotemploys an inpaint method to convert the poisoning samples into clean ones, yielding up to 8.16% improvement in accuracy. Yilong Yang 0004, Zhuo Ma 0001, Yihua Li, Yang Liu 0118, Xinjing Liu, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Updates Leakage Attack Against Private Graph Split Learning
Zhuo Ma 0001, Yang Liu 0118, Xinjing Liu, Beiwei Yang, Jianfeng Ma 0001 |
ICA3PP (2) | 4 |
| 2024 | Need for Speed: Taming Backdoor Attacks with Speed and PrecisionabstractModern deep neural network models (DNNs) require extensive data for optimal performance, prompting reliance on multiple entities for the acquisition of training datasets. One prominent security threat is backdoor attacks where the adversary party poisons a small subset of training datasets to implant a backdoor into the model, leading to misclassifications during runtime for triggered samples. To mitigate the attack, many defense methods have been proposed, such as detecting and removing poisoned samples or rectifying trojaned model weights in victim DNNs. However, existing approaches suffer from notable inefficiency as they are faced with large-scale training datasets, consequently rendering these defenses impractical in the real world. In this paper, we propose a lightweight backdoor identification and removal scheme, called ReBack. In this scheme, ReBack first extracts a subset of suspicious and benign samples, and then, proceeds with a "averaging and differencing" based method to identify target label(s). Next, leveraging the identification results, ReBack invokes a novel reverse engineering method to recover the exact trigger using only basic arithmetic atoms. Our experiments demonstrate that, for ImageNet with 750 labels, ReBack can defend against backdoor attacks in around 2 hours, showcasing a speed improvement of 18.5× to 214× compared to existing methods. For backdoor removal, the attack success rate can be decreased to 0.05% owing to 99% cosine similarity of the reversed triggers. The code is online available. Zhuo Ma 0001, Yilong Yang 0004, Yang Liu 0118, Tong Yang 0003, Xinjing Liu, Teng Li 0003, Zhan Qin |
SP | 5 |
| 2024 | Mitigate noisy data for smart IoT via GAN based machine unlearning
Zhuo Ma 0001, Yilong Yang 0004, Yang Liu 0118, Xinjing Liu, Jianfeng Ma 0001 |
Sci. China Inf. Sci. | 4 |
| 2024 | Model Stealing Detection for IoT Services Based on Multidimensional FeaturesabstractModel stealing (MS) attacks pose a significant security concern for machine learning models on cloud platforms, as they can reconstruct a substitute model with limited effort to evade ownership. While detection-based methods show promise in preventing MS attacks, they often face practical challenges. Specifically, setting an appropriate threshold to distinguish malicious features from benign ones is a difficult task, often leading to a tradeoff between false alarm rates and detection accuracy. To address this challenge, we design a multidimensional feature extraction-and-distinction scheme called MED. It is achieved through a two-layer optimization: 1) the inner layer of extraction to maximize the difference of extracted multidimensional features between attack and benign samples and 2) the outer layer of distinction to maximize the accuracy of distinguishing malicious features automatically. Recognizing that different MS attacks result in varied features, we design a group of feature extraction functions in the inner layer optimization, which addresses the limitations of single-feature-based detection methods. Further, we employ three differently characterized models for distinction, enabling MED to distinguish different types of malicious features. Comprehensive experiments are conducted to evaluate the effectiveness of the proposed scheme: MED can detect all types of MS attacks with no more than 100 samples, with an average detection rate greater than 0.99. Xinjing Liu, Taifeng Liu, Jiakang Dong, Zuobin Ying, Zhuo Ma 0001 |
IEEE Internet Things J. | 1 |
| 2024 | RPAU: Fooling the Eyes of UAVs via Physical Adversarial PatchesabstractRecently, Unmanned Aerial Vehicles (UAVs) deployed with deep learning models have been widely applied both in civil and military. However, the vulnerability of the deployed model to adversarial attacks has raised security concerns. Previous studies have mainly explored adversarial attacks in the digital domain. While physical attacks have posed a more serious threat to UAVs. In this paper, we have explored a novel Robust Physical Attack against UAVs named, which directly threatens the flight safety of UAVs. Specifically, three attacks are proposed in : Hiding Attack (HA), Yaw Attack (YA), and Obstacle Attack (OA). To launch the attacks, we overcome three domain-design challenges, including continuous perturbation, digital-physical domain gap, and optimum perturbation generation. For continuous perturbation, we have introduced anested patchthat realizes attacks at any distance. Further, a series of transformations are considered to narrow the gap between the digital and physical domains. Then, we proposed a time-dependent mechanism for generating optimum perturbation. We conducted comprehensive experiments in the digital domain, simulation environment, and physical domain. The experimental results validate the robustness of the proposed framework. In the digital domain, outperforms the baseline by$54.9\%$average attack success rate (ASR). More importantly, is still effective in both the simulation environment and the physical domain, achieving an average ASR of$100\%$. Taifeng Liu, Chao Yang 0016, Xinjing Liu, Ruidong Han, Jianfeng Ma 0001 |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2023 | Sniffer: A Novel Model Type Detection System against Machine-Learning-as-a-Service PlatformsabstractRecent works explore several attacks against Machine-Learning-as-a-Service (MLaaS) platforms (e.g., the model stealing attack), allegedly posing potential real-world threats beyond viability in laboratories. However, hampered by model-type-sensitive , most of the attacks can hardly break mainstream real-world MLaaS platforms. That is, many MLaaS attacks are designed against only one certain type of model, such as tree models or neural networks. As the black-box MLaaS interface hides model type info, the attacker cannot choose a proper attack method with confidence, limiting the attack performance. In this paper, we demonstrate a system, named Sniffer, that is capable of making model-type-sensitive attacks "great again" in real-world applications. Specifically, Sniffer consists of four components: Generator, Querier, Probe, and Arsenal. The first two components work for preparing attack samples. Probe, as the most characteristic component in Sniffer, implements a series of self-designed algorithms to determine the type of models hidden behind the black-box MLaaS interfaces. With model type info unraveled, an optimum method can be selected from Arsenal (containing multiple attack methods) to accomplish its attack. Our demonstration shows how the audience can interact with Sniffer in a web-based interface against five mainstream MLaaS platforms. Zhuo Ma 0001, Yilong Yang 0004, Bin Xiao 0002, Yang Liu 0118, Xinjing Liu, Zhuoran Ma 0002, Tong Yang 0003 |
Proc. VLDB Endow. | 5 |
| 2023 | DivTheft: An Ensemble Model Stealing Attack by Divide-and-ConquerabstractRecently, model stealing attacks are widely studied but most of them are focused on stealing a single non-discrete model, e.g., neural networks. For ensemble models, these attacks are either non-executable or suffer from intolerant performance degradation due to the complex model structure (multiple sub-models) and the discreteness possessed by the sub-model (e.g., decision trees). To overcome the bottleneck, this paper proposes a divide-and-conquer strategy called DivTheft to formulate the model stealing attack to common ensemble models by combining active learning (AL). Specifically, based on the boosting learning concept, we divide a hard ensemble model stealing task into multiple simpler ones about single sub-model stealing. Then, we adopt AL to conquer the data-free sub-model stealing task. During the process, the current AL algorithm easily causes the stolen model to be biased because of ignoring the past useful memories. Thus, DivTheft involves a newly designed uncertainty sampling scheme to filter reusable samples from the previously used ones. Experiments show that compared with the prior work, DivTheft can save almost 50% queries while ensuring a competitive agreement rate to the victim model. Zhuo Ma 0001, Xinjing Liu, Yang Liu 0118, Ximeng Liu, Zhan Qin, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2022 | SeInspect: Defending Model Stealing via Heterogeneous Semantic Inspection
Xinjing Liu, Zhuo Ma 0001, Yang Liu 0118, Zhan Qin, Junwei Zhang 0001 |
ESORICS (1) | 1 |