VLDB 2026 Research / reviewers in the wild / expert
Rui Duan 0005
dblp:20/5251-5
· DBLP profile ↗
6ranked-venue papers
3as first author
6since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Perception-Aware Attack Against Music Copyright Detection: Impacts and DefensesabstractRecently, adversarial machine learning attacks have posed serious security threats against practical audio signal classification systems, including speech recognition, speaker recognition, music copyright detection. Most existing studies have mainly focused on ensuring the effectiveness of attacking an audio signal classifier via creating a noise-like perturbation on the original signal, which remains a gap in preserving the human perception of adversarial audios. This paper presents a novel perspective to create adversarial audios by integrating the human perception model into the attack formulation to generate well-perceived adversarial examples. Different from conventional approaches which primarily focused on using$L_{p}$norm to preserve the audio quality, we adopt a human study to understand how human participants react to different types of music perturbations, build a Siamese Neural Network (SNN) based model to characterize the human perception. The new findings of the human perception study guide us to formulate a new computationally efficient, multiple-feature-based perception-aware (CEMF-PA) attack, which manipulates different audio signal features to find an optimal perturbed music signal against music copyright detection. This novel attack vector opens a new door to generating highly effective, well-perceived adversarial audio signals via manipulating the auditory features. Experimental results show that the proposed attack is effective against YouTube’s copyright detection. Finally, we propose the defense strategy design to make the copyright detection more robust to adversarial music signals generated by the CEMF-PA attack. Rui Duan 0005, Shangqing Zhao, Lei Ding 0003, Yao Liu 0007 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Parrot-Trained Adversarial Examples: Pushing the Practicality of Black-Box Audio Attacks against Speaker Recognition Models
Rui Duan 0005, Lei Ding 0003, Yao Liu 0007 |
NDSS | 1 |
| 2024 | Guessing on Dominant Paths: Understanding the Limitation of Wireless Authentication Using Channel State InformationabstractThe channel state information (CSI) has been extensively studied in the literature to facilitate authentication in wireless networks. The less focused is a systematic attack model to evaluate CSI-based authentication. Existing studies generally adopt either a random attack model that existing designs are resilient to or a specific-knowledge model that assumes certain inside knowledge for the attacker. This paper proposes a new, realistic attack model against CSI-based authentication. In this model, an attacker Eve tries to actively guess a user Alice’s CSI, and precode her signals to impersonate Alice to the verifier Bob who uses CSI to authenticate users. To make the CSI guessing effective and low-cost, we use theoretical analysis and CSI dataset validation to show that there is no need to guess CSI values in all signal propagation paths. Specifically, Eve can adopt a Dominant Path Construction (DomPathCon) strategy that only focuses on guessing the CSI values on the first few paths with the highest channel response amplitude (called dominant paths). Comprehensive experimental results show that DomPathCon is effective and achieves up to 61% attack success rates under different wireless network settings, which exposes new limitations of CSI-based authentication. We also propose designs to mitigate the adverse impact of DomPathCon. Rui Duan 0005, Tony Xiao Han, Shangqing Zhao, Yao Liu 0007 |
SP | 2 |
| 2022 | Perception-Aware Attack: Creating Adversarial Music via Reverse-Engineering Human PerceptionabstractPrevious adversarial audio attacks have mainly focused on ensuring the effectiveness of attacking an audio signal classifier via creating a small noise-like perturbation on the original signal. It is still unclear if an attacker is able to create audio signal perturbations that can be well perceived by human beings in addition to its attack effectiveness. In this work, we formulate the adversarial attack against music signals as a new perception-aware attack framework, which integrates human study into adversarial attack design. Specifically, we invite human participants to rate their perceived deviation based on pairs of original and perturbed music signals, and reverse-engineer the human perception process by regression analysis to predict the human-perceived deviation given a perturbed signal. The perception-aware attack is then formulated as an optimization problem that finds an optimal perturbation signal to minimize the prediction of perceived deviation from the regressed human perception model. Experiments show that the attack produces adversarial music with significantly better perceptual quality than prior work against YouTube's copyright detector. Rui Duan 0005, Shangqing Zhao, Lei Ding 0003, Yao Liu 0007 |
CCS | 1 |
| 2022 | Generalized Federated Learning via Sharpness Aware MinimizationabstractFederated Learning (FL) is a promising framework for performing privacy-preserving, distributed learning with a set of clients. However, the data distribution among clients often exhibits non-IID, i.e., distribution shift, which makes efficient optimization difficult. To tackle this problem, many FL algorithms focus on mitigating the effects of data heterogeneity across clients by increasing the performance of the global model. However, almost all algorithms leverage Empirical Risk Minimization (ERM) to be the local optimizer, which is easy to make the global model fall into a sharp valley and increase a large deviation of parts of local clients. Therefore, in this paper, we revisit the solutions to the distribution shift problem in FL with a focus on local learning generality. To this end, we propose a general, effective algorithm, \texttt{FedSAM}, based on Sharpness Aware Minimization (SAM) local optimizer, and develop a momentum FL algorithm to bridge local and global models, \texttt{MoFedSAM}. Theoretically, we show the convergence analysis of these two algorithms and demonstrate the generalization bound of \texttt{FedSAM}. Empirically, our proposed algorithms substantially outperform existing FL studies and significantly decrease the learning deviation. Rui Duan 0005, Yao Liu 0007, Bo Tang 0011 |
ICML | 3 |
| 2022 | Context-Aware Online Client Selection for Hierarchical Federated LearningabstractFederated Learning (FL) has been considered as an appealing framework to tackle data privacy issues of mobile devices compared to conventional Machine Learning (ML). Using Edge Servers (ESs) as intermediaries to perform model aggregation in proximity can reduce the transmission overhead, and it enables great potential in low-latency FL, where the hierarchical architecture of FL (HFL) has been attracted more attention. Designing a proper client selection policy can significantly improve training performance, and it has been widely investigated in conventional FL studies. However, to the best of our knowledge, systematic client selection policies have not yet been fully studied for HFL. In addition, client selection for HFL faces more challenges than conventional FL (e.g., the time-varying connection of client-ES pairs and the limited budget of the Network Operator (NO)). In this article, we investigate a client selection problem for HFL, where the NO learns the number of successful participating clients to improve training performance (i.e., select as many clients in each round) as well as under the limited budget on each ES. An online policy, called Context-aware Online Client Selection (COCS), is developed based on Contextual Combinatorial Multi-Armed Bandit (CC-MAB). COCS observes the side-information (context) of local computing and transmission of client-ES pairs and makes client selection decisions to maximize NO's utility given a limited budget. Theoretically, COCS achieves a sublinear regret compared to an Oracle policy on both strongly convex and non-convex HFL. Simulation results also support the efficiency of the proposed COCS policy on real-world datasets. Rui Duan 0005, Lixing Chen, Jie Xu 0001, Yao Liu 0007 |
IEEE Trans. Parallel Distributed Syst. | 2 |