VLDB 2026 Research / reviewers in the wild / expert
Yulin Zhu 0001
dblp:198/8309-1 · also Tony Yulin Zhu
· DBLP profile ↗
19ranked-venue papers
6as first author
19since 2021 · last 2026
0000-0003-1231-1386ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 2 first-author · 7 since 2021Databases, data management, data science and information retrieval · 5 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Revisiting Adversarial Robustness of GNNs Against Structural Attacks: A Simple and Fast ApproachabstractTo defend against adversarial structural attacks on graphs, we analyze attacks through the lens of mutual information and discover the “pairwise effect". This effect reveals that structural attacks effectively degrade the performance of victim GNNs when these GNNs receive the modified structure paired with the given node attributes as training input. Therefore, we propose a novel defense strategy that renders structural attacks ineffective by disrupting the pairing of modified structures and node attributes during the training of victim GNNs, which we call “disrupting the pairwise effect". To implement this idea, we propose two simple yet effective training strategies: Structural Fine-Tuning (SF) and Progressive Structural Training (PST), which disrupt the pairwise effect through node attributes pre-training followed by structure fine-tuning and progressive structure training, respectively. Compared to existing robust GNNs, our strategies avoid time-consuming techniques, thereby improving the robustness of GNNs while enhancing training speed. Additionally, these strategies can be easily applied to a wide range of commonly used GNNs, including robust GNN variants, making them highly adaptable to different models and applications. We provide theoretical analysis of the proposed training strategies and conduct extensive experiments on various datasets to demonstrate their effectiveness. Datasets and codes of this paper are available at https://github.com/Xing-Ai1003/Revisiting-Adversarial-Robustness-of-GNNs. Xing Ai, Yulin Zhu 0001, Yu Zheng 0021, Gaolei Li, Jianhua Li 0001, Kai Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Crowdsourced Homophily Ties Based Graph Annotation Via Large Language ModelabstractAccurate graph annotation typically requires substantial labeled data, which is often challenging and resource-intensive to obtain. In this paper, we present Crowdsourced Homophily Ties Based Graph Annotation via Large Language Model (CSA-LLM), a novel approach that combines the strengths of crowdsourced annotations with the capabilities of large language models (LLMs) to enhance the graph annotation process. CSA-LLM harnesses the structural context of graph data by integrating information from 1-hop and 2-hop neighbors. By emphasizing homophily ties—key connections that signify similarity within the graph—CSA-LLM significantly improves the accuracy of annotations. Experimental results demonstrate that this method enhances the performance of Graph Neural Networks (GNNs) by delivering more precise and reliable annotations. Codes and data are available at https://github.com/spotpan/CSA-LLM Yu Bu, Yulin Zhu 0001, Kai Zhou 0001 |
ICASSP | 2 |
| 2025 | Simple yet Effective Gradient-Free Graph Convolutional NetworksabstractLinearized Graph Neural Networks (GNNs) have attracted great attention in recent years for graph representation learning. Compared with nonlinear Graph Neural Network (GNN) models, linearized GNNs are much more time-efficient and can achieve comparable performances on typical downstream tasks such as node classification. Although some linearized GNN variants are purposely crafted to mitigate "over-smoothing", empirical studies demonstrate that they still somehow suffer from this issue. In this paper, we instead relate over-smoothing with the vanishing gradient phenomenon and craft a gradient-free training framework to achieve more efficient and effective linearized GNNs which can significantly overcome over-smoothing and enhance the generalization of the model. The experimental results demonstrate that our methods achieve better and more stable performances on node classification tasks with varying depths and cost much less training time. Yulin Zhu 0001, Xing Ai, Qimai Li, Kai Zhou 0001 |
IJCNN | 1 |
| 2025 | A Distributed Adaptive System with Strong Tie Graphs for Trust-Aware Reasoning in Adversarial GraphsabstractThis study proposes a distributed adaptive system for robust reasoning over graph-structured data under structural poisoning attacks, where adversaries strategically manipulate edges to compromise predictive integrity. We introduce the Graph Adaptive Neural Network (GANN), a modular framework that treats trust and risk zones within the graph as semi-autonomous components capable of self-regulating their propagation behaviors based on adversarial feedback. Leveraging fuzzy-theoretic Strong Tie Graphs (STiG), GANN adaptively identifies and reinforces high-confidence regions to ensure resilient node classification and secure query handling. The system operates as a surrogate defense layer, dynamically managing zone-based structural decomposition and trust calibration in response to perturbations. Its selective validation-driven adaptation mechanism restricts the attacker’s ability to exploit unlabeled data, forcing them toward costly global strategies. A confidence-based regulation framework further enhances GANN’s robustness under bounded adversarial budgets, with demonstrated effectiveness in non-IID and directed graph settings. Experimental results validate GANN’s capability as a self-adjusting distributed system, advancing adaptive defenses in graph-based data management and adversarial query environments. Yu Bu, Yulin Zhu 0001, Yuni Lai |
SMC | 2 |
| 2025 | Unleashing the power of indirect attacks against trust prediction via preferential pathabstractAdversarial attacks in network security are a growing concern, prompting the need for innovative strategies to enhance both attack and defense mechanisms. This paper explores ways to improve adversarial attacks on the fairness and goodness algorithm (FGA) and review to reviewer (REV2), focusing on predicting trust within signed graphs. Unlike traditional time-based models, FGA and REV2 rely on iterative processes for trust propagation. By analyzing network structures, we identify strong ties and weak ties within FGA and discover preferential paths in REV2 that significantly impact information spread during algorithm iterations. Based on these insights, we propose a new approach called the vicinage attack , which enhances adversarial attacks by strategically targeting edges along these critical pathways. Our work highlights adversarial perturbation patterns that affect trust prediction on signed graphs and emphasizes their wide-reaching impact. These findings not only advance adversarial attack techniques but also deepen our understanding of trust propagation patterns. By clarifying the propagation bias in FGA and REV2, this research provides valuable insights for improving network security and developing better adversarial mitigation techniques in trust prediction. Yu Bu, Yulin Zhu 0001, Longling Geng, Kai Zhou 0001 |
Knowl. Inf. Syst. | 2 |
| 2025 | Robust Graph Contrastive Learning With Information RestorationabstractThe graph contrastive learning (GCL) framework has gained remarkable achievements in graph representation learning. However, similar to graph neural networks (GNNs), GCL models are susceptible to graph structural attacks. As an unsupervised method, GCL faces greater challenges in defending against adversarial attacks. Furthermore, there has been limited research on enhancing the robustness of GCL. To thoroughly explore the failure of GCL on the poisoned graphs, we investigate the detrimental effects of graph structural attacks against the GCL framework. We discover that, in addition to the conventional observation that graph structural attacks tend to connect dissimilar node pairs, these attacks also diminish the mutual information between the graph and its representations from an information-theoretical perspective, which is the cornerstone of the high-quality node embeddings for GCL. Motivated by this theoretical insight, we propose a robust graph contrastive learning framework with a learnable sanitation view that endeavors to sanitize the augmented graphs by restoring the diminished mutual information caused by the structural attacks. Additionally, we design a fully unsupervised tuning strategy to tune the hyperparameters without accessing the label information, which strictly coincides with the defender’s knowledge. Extensive experiments demonstrate the effectiveness and efficiency of our proposed method compared to competitive baselines. Yulin Zhu 0001, Xing Ai, Yevgeniy Vorobeychik, Kai Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | From Bi-Level to One-Level: A Framework for Structural Attacks to Graph Anomaly DetectionabstractThe success of graph neural networks stimulates the prosperity of graph mining and the corresponding downstream tasks including graph anomaly detection (GAD). However, it has been explored that those graph mining methods are vulnerable to structural manipulations on relational data. That is, the attacker can maliciously perturb the graph structures to assist the target nodes in evading anomaly detection. In this article, we explore the structural vulnerability of two typical GAD systems: unsupervised FeXtra-based GAD and supervised graph convolutional network (GCN)-based GAD. Specifically, structural poisoning attacks against GAD are formulated as complex bi-level optimization problems. Our first major contribution is then to transform the bi-level problem into one-level leveraging different regression methods. Furthermore, we propose a new way of utilizing gradient information to optimize the one-level optimization problem in the discrete domain. Comprehensive experiments demonstrate the effectiveness of our proposed attack algorithm $\textsf {BinarizedAttack}$ . Yulin Zhu 0001, Yuni Lai, Kaifa Zhao, Xiapu Luo, Mingquan Yuan, Jun Wu 0001, Jian Ren 0001, Kai Zhou 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 1 |
| 2024 | Uncovering Strong Ties: A Study of Indirect Sybil Attack on Signed Social NetworkabstractThe Fairness and Goodness Algorithm (FGA) is a widely used trust system in signed directed networks. However, attackers can manipulate trust scores on FGA by launching indirect Sybil attacks and exploiting strong ties. In this work, we propose a novel attack method vicinage-attack that formulates the problem as a combination optimization problem for mining candidate attacking edges. Our method constructs perturbation spaces and infers the existence of polymorphic strong ties. To evaluate vicinage-attack, we compare it against several baselines and show the vicinage-attack outperforms them. Overall, our work highlights the potential dangers of indirect Sybil attacks on FGA and offers insight for detecting and mitigating these attacks. Yu Bu, Yulin Zhu 0001, Longling Geng, Kai Zhou 0001 |
ICASSP | 2 |
| 2024 | Cost Aware Untargeted Poisoning Attack Against Graph Neural NetworksabstractGraph Neural Networks (GNNs) have become widely used in the field of graph mining. However, these networks are vulnerable to structural perturbations. While many research efforts have focused on analyzing vulnerability through poisoning attacks, we have identified an inefficiency in current attack losses. These losses steer the attack strategy towards modifying edges targeting misclassified nodes or resilient nodes, resulting in a waste of structural adversarial perturbation. To address this issue, we propose a novel attack loss framework called the Cost Aware Poisoning Attack (CA-attack) to improve the allocation of the attack budget by dynamically considering the classification margins of nodes. Specifically, it prioritizes nodes with smaller positive margins while postponing nodes with negative margins. Our experiments demonstrate that the proposed CA-attack significantly enhances existing attack strategies. Yuwei Han, Yuni Lai, Yulin Zhu 0001, Kai Zhou 0001 |
ICASSP | 3 |
| 2024 | Graph Anomaly Detection at Group Level: A Topology Pattern Enhanced Unsupervised ApproachabstractGraph anomaly detection (GAD) has achieved success and has been widely applied in various domains, such as fraud detection, cybersecurity, finance security, and biochemistry. However, existing graph anomaly detection algorithms focus on distinguishing individual entities (nodes or graphs) and overlook the possibility of anomalous groups within the graph. To address this limitation, this paper introduces a novel unsupervised framework for a new task called Group-level Graph Anomaly Detection (Gr-GAD). The proposed framework first employs a variant of Graph AutoEncoder (GAE) to locate anchor nodes that belong to potential anomaly groups by capturing long-range inconsistencies. Subsequently, group sampling is employed to sample candidate groups, which are then fed into the proposed Topology Pattern-based Graph Contrastive Learning (TPGCL) method. TPGCL utilizes the topology patterns of groups as clues to generate embeddings for each candidate group and thus distinct anomaly groups. The experimental results on both real-world and synthetic datasets demonstrate that the proposed framework shows superior performance in identifying and localizing anomaly groups, highlighting it as a promising solution for Gr-GAD. Datasets and codes of the proposed framework are at the github repository https://github.com/STiL-Team/Topology-Pattern-Enhanced-Unsupervised-Group-level-Graph-Anomaly-Detection.git. Xing Ai, Jialong Zhou, Yulin Zhu 0001, Gaolei Li, Tomasz P. Michalak, Xiapu Luo, Kai Zhou 0001 |
ICDE | 3 |
| 2024 | Node-aware Bi-smoothing: Certified Robustness against Graph Injection AttacksabstractDeep Graph Learning (DGL) has emerged as a crucial technique across various domains. However, recent studies have exposed vulnerabilities in DGL models, such as susceptibility to evasion and poisoning attacks. While empirical and provable robustness techniques have been developed to defend against graph modification attacks (GMAs), the problem of certified robustness against graph injection attacks (GIAs) remains largely unexplored. To bridge this gap, we introduce the node-aware bi-smoothing framework, which is the first certifiably robust approach for general node classification tasks against GIAs. Notably, the proposed node-aware bi-smoothing scheme is model-agnostic and is applicable for both evasion and poisoning attacks. Through rigorous theoretical analysis, we establish the certifiable conditions of our smoothing scheme. We also explore the practical implications of our node-aware bi-smoothing schemes in two contexts: as an empirical defense approach against real-world GIAs and in the context of recommendation systems. Furthermore, we extend two state-of-the-art certified robustness frameworks to address node injection attacks and compare our approach against them. Extensive evaluations demonstrate the effectiveness of our proposed certificates.1 Yuni Lai, Yulin Zhu 0001, Bailin Pan, Kai Zhou 0001 |
SP | 2 |
| 2024 | Adversarial analysis of similarity-based sign prediction
Michal Tomasz Godziszewski, Marcin Waniek, Yulin Zhu 0001, Kai Zhou 0001, Talal Rahwan, Tomasz P. Michalak |
Artif. Intell. | 3 |
| 2024 | Coupled-Space Attacks Against Random-Walk-Based Anomaly DetectionabstractRandom Walks-based Anomaly Detection (RWAD) is commonly used to identify anomalous patterns in various applications. An intriguing characteristic of RWAD is that the input graph can either be pre-existing graphs or feature-derived graphs constructed from raw features. Consequently, there are two potential attack surfaces against RWAD: graph-space attacks and feature-space attacks. In this paper, we explore this vulnerability by designing practical coupled-space (interdependent feature-space and graph-space) attacks, investigating the interplay between graph-space and feature-space attacks. To this end, we conduct a thorough complexity analysis, proving that attacking RWAD is NP-hard. Then, we proceed to formulate the graph-space attack as a bi-level optimization problem and propose two strategies to solve it: alternative iteration (alterI-attack) or utilizing the closed-form solution of the random walk model (cf-attack). Finally, we utilize the results from the graph-space attacks as guidance to design more powerful feature-space attacks (i.e., graph-guided attacks). Comprehensive experiments demonstrate that our proposed attacks are effective in enabling the target nodes to evade the detection from RWAD with a limited attack budget. In addition, we conduct transfer attack experiments in a black-box setting, which show that our feature attack significantly decreases the anomaly scores of target nodes. Our study opens the door to studying the coupled-space attack against graph anomaly detection in which the graph space relies on the feature space. Yuni Lai, Marcin Waniek, Yulin Zhu 0001, Tomasz P. Michalak, Talal Rahwan, Kai Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | Toward Adversarially Robust Recommendation From Adaptive Fraudster DetectionabstractThe robustness of recommender systems under node injection attacks has garnered significant attention. Recently, GraphRfi, a Graph-Neural-Network-based (GNN-based) recommender system, was proposed and shown to effectively mitigate the impact of injected fake users. However, we demonstrate that GraphRfi remains vulnerable to attacks due to the supervised nature of its fraudster detection component, where obtaining clean labels is challenging in practice. In particular, we propose a powerful poisoning attack, MetaC, against both GNN-based and Martix-Faxtorization-based recommender systems. Furthermore, we analyze why GraphRfi fails under such an attack. Then, based on our insights obtained from vulnerability analysis, we design an adaptive fraudster detection module that explicitly considers label uncertainty. This module can serve as a plug-in for different recommender systems, resulting in a robust framework named Posterior-Detection Recommender (PDR). Comprehensive experiments show that our defense approach outperforms other benchmark methods under attacks. Overall, our research presents an effective framework for integrating fraudster detection into recommendation systems to achieve adversarial robustness. Yuni Lai, Yulin Zhu 0001, Wenqi Fan, Xiaoge Zhang 0001, Kai Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Toward Secrecy-Aware Attacks Against Trust Prediction in Signed Social NetworksabstractSigned social networks are widely used to model the trust relationships among online users in security-sensitive systems such as cryptocurrency trading platforms, where trust prediction plays a critical role. In this paper, we investigate how attackers could mislead trust prediction by secretly manipulating signed networks. To this end, we first design effective poisoning attacks against representative trust prediction models. The attacks are formulated as hard bi-level optimization problems, for which we propose several efficient approximation solutions. However, the resultingbasic attackswould severely change the structural semantics (in particular, both local and global balance properties) of a signed network, which makes the attacks prone to be detected by the powerful attack detectors we designed. Given this, we further refine the basic attacks by integrating someconflicting metricsas penalty terms into the objective function. Therefined attacksbecome secrecy-aware, i.e., they can successfully evade attack detectors with high probability while sacrificing little attack performance. We conduct comprehensive experiments to demonstrate that the basic attacks can severely disrupt trust prediction but could be easily detected, and the refined attacks perform almost equally well while evading detection. Overall, our results significantly advance the knowledge in designing more practical attacks, reflecting more realistic threats to current trust prediction models. Moreover, the results also provide valuable insights and guidance for building up robust trust prediction systems. Yulin Zhu 0001, Tomasz P. Michalak, Xiapu Luo, Xiaoge Zhang 0001, Kai Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | FocusedCleaner: Sanitizing Poisoned Graphs for Robust GNN-Based Node ClassificationabstractGraph Neural Networks (GNNs) are vulnerable to data poisoning attacks, which will generate a poisoned graph as the input to the GNN models. We present FocusedCleaner as a poisoned graph sanitizer to effectively identify the poison injected by attackers. Specifically, FocusedCleaner provides a sanitation framework consisting of two modules: bi-level structural learning and victim node detection. In particular, the structural learning module will reverse the attack process to steadily sanitize the graph while the detection module provides the “focus” – a narrowed and more accurate search region – to structural learning. These two modules will operate in iterations and reinforce each other to sanitize a poisoned graph step by step. As an important application, we show that the adversarial robustness of GNNs trained over the sanitized graph for the node classification task is significantly improved. Extensive experiments demonstrate that FocusedCleaner outperforms the state-of-the-art baselines both on poisoned graph sanitation and improving robustness. Yulin Zhu 0001, Liang Tong, Gaolei Li, Xiapu Luo, Kai Zhou 0001 |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2022 | BinarizedAttack: Structural Poisoning Attacks to Graph-based Anomaly DetectionabstractGraph-based Anomaly Detection (GAD) is becoming prevalent due to the powerful representation abilities of graphs as well as recent advances in graph mining techniques. These GAD tools, however, expose a new attacking surface, ironically due to their unique advantage of being able to exploit the relations among data. That is, attackers now can manipulate those relations (i.e., the structure of the graph) to allow some target nodes to evade detection. In this paper, we exploit this vulnerability by designing a new type of targeted structural poisoning attacks to a representative regression-based GAD system termed OddBall. Specifically, we formulate the attack against OddBall as a bi-level optimization problem, where the key technical challenge is to efficiently solve the problem in a discrete domain. We propose a novel attack method termed BinarizedAttack based on gradient descent. Comparing to prior arts, BinarizedAttack can better use the gradient information, making it particularly suitable for solving combinatorial optimization problems. Furthermore, we investigate the attack transferability of BinarizedAttack by employing it to attack other representation-learning-based GAD systems. Our comprehensive experiments demonstrate that BinarizedAttack is very effective in enabling target nodes to evade graph-based anomaly detection tools with limited attacker's budget, and in the black-box transfer attack setting, BinarizedAttack is also tested effective and in particular, can significantly change the node embeddings learned by the GAD systems. Our research thus opens the door to studying a new type of attack against security analytic tools that rely on graph data. Yulin Zhu 0001, Yuni Lai, Kaifa Zhao, Xiapu Luo, Mingquan Yuan, Jian Ren 0001, Kai Zhou 0001 |
ICDE | 1 |
| 2021 | Structural Attack against Graph Based Android Malware DetectionabstractMalware detection techniques achieve great success with deeper insight into the semantics of malware. Among existing detection techniques, function call graph (FCG) based methods achieve promising performance due to their prominent representations of malware's functionalities. Meanwhile, recent adversarial attacks not only perturb feature vectors to deceive classifiers (i.e., feature-space attacks) but also investigate how to generate real evasive malware (i.e., problem-space attacks). However, existing problem-space attacks are limited due to their inconsistent transformations between feature space and problem space. Kaifa Zhao, Hao Zhou 0043, Yulin Zhu 0001, Xian Zhan, Kai Zhou 0001, Jianfeng Li 0006, Le Yu 0002, Wei Yuan 0001, Xiapu Luo |
CCS | 3 |
| 2021 | Attacking Similarity-Based Sign PredictionabstractIn this paper, we present a computational analysis of the problem of attacking sign prediction, whereby the aim of the attacker (a network member) is to hide from the defender (an analyst) the signs of a target set of links by removing the signs of some other, non-target, links. The problem turns out to be NP-hard if either local or global similarity measures are used for sign prediction. We propose a heuristic algorithm and test its effectiveness on several real-life and synthetic datasets. Michal Tomasz Godziszewski, Tomasz P. Michalak, Marcin Waniek, Talal Rahwan, Kai Zhou 0001, Yulin Zhu 0001 |
ICDM | 6 |