VLDB 2026 Research / reviewers in the wild / expert
Yingxiao Xiang
dblp:204/2473
· DBLP profile ↗
13ranked-venue papers
0as first author
7since 2021 · last 2026
0000-0002-8679-7000ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 4 since 2021Security and privacy · 4 · 1 since 2021Databases, data management, data science and information retrieval · 4 · 3 since 2021Systems, architecture and hardware · 2 · 1 since 2021Computer networks · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FRBAT: Conditionally-Visible Physical Backdoor Attack via FluorescenceabstractDeep neural networks are increasingly vulnerable to physically deployable backdoor attacks, which manipulate real-world objects to induce targeted model failures. However, current physical backdoor attacks predominantly rely on perpetually visible triggers appended to target objects. These methods inevitably expose attack traces during the deployment phase, risking human suspicion prior to activation. In this paper, we propose a conditionally-visible physical backdoor attack, which can only be activated under specific optical conditions and thereby overcomes the risk of being detected after deployment and before the attack. Specifically, to ensure robust and reliable activation, we design irregular polygonal pattern as triggers to against across environmental variations. Moreover, we introduce a dual-phase mechanism (dormant and activated) to enable stealthy deployment. Our trigger remains invisible and dormant under non-attack conditions, leaving no physical traces. It activates instantaneously under specific illumination, inducing the target model to perform the desired behavior. We conduct experiments on traffic sign recognition tasks to compare our attack with six digital and seven physical attacks, and assess its performance against potential defenses. Extensive experimental results demonstrate the effectiveness, stealthiness, and robustness of our attack. Yalun Wu, Endong Tong, Yingxiao Xiang, Xiaoting Lyu, Zhen Han 0001, Jiqiang Liu |
AAAI | 4 |
| 2026 | FlipBAT: Toward Stealthy Endogenous Backdoor Attacks on Traffic Sign Recognition via Self-FlippingabstractRecent studies show that deep learning-based traffic sign recognition systems are vulnerable to backdoor attacks. These compromised models can be activated to misclassify traffic signs when exposed to specific backdoor patterns during inference. Nevertheless, existing attack methods rely on exogenous triggers (e.g., stickers or patches) that introduce external features to associate backdoor patterns with target labels, significantly increasing attack complexity. In this paper, we propose FlipBAT, a stealthy endogenous backdoor attack method that uses the image’s self-flipping as the built-in trigger, eliminating the need for external trigger patterns. Our attack supports two distinct attack modes: a multi-class backdoor attack that enables flexible target diversification via cyclic mappings, and a single-class backdoor attack that achieves higher stealthiness by minimally perturbing the source class. Extensive experiments conducted on two standard traffic sign recognition datasets (GTSRB and BelgiumTS) across three different victim models demonstrate that FlipBAT effectively establishes robust mappings between backdoor images and target classes. Notably, our method achieves efficient backdoor attacks with significantly lower poisoning rates compared to conventional approaches. Our method has also been shown to be robust against state-of-the-art backdoor defenses. Yalun Wu, Xiaoshu Cui, Yingxiao Xiang, Yingying Yao, Yuanwan Chen, Zhen Han 0001, Jiqiang Liu, Wenjia Niu |
IEEE Internet Things J. | 3 |
| 2024 | Nightfall Deception: A Novel Backdoor Attack on Traffic Sign Recognition Models via Low-Light Data Manipulation
Yalun Wu, Yingxiao Xiang, Jinkai Zheng, Zhen Han 0001, Jiqiang Liu, Wenjia Niu |
ADMA (3) | 3 |
| 2024 | Collaborative Attack Sequence Generation Model Based on Multiagent Reinforcement Learning for Intelligent Traffic Signal SystemabstractIntelligent traffic signal systems, crucial for intelligent transportation systems, have been widely studied and deployed to enhance vehicle traffic efficiency and reduce air pollution. Unfortunately, intelligent traffic signal systems are at risk of data spoofing attack, causing traffic delays, congestion, and even paralysis. In this paper, we reveal a multivehicle collaborative data spoofing attack to intelligent traffic signal systems and propose a collaborative attack sequence generation model based on multiagent reinforcement learning (RL), aiming to explore efficient and stealthy attacks. Specifically, we first model the spoofing attack based on Partially Observable Markov Decision Process (POMDP) at single and multiple intersections. This involves constructing the state space, action space, and defining a reward function for the attack. Then, based on the attack modeling, we propose an automated approach for generating collaborative attack sequences using the Multi‐Actor‐Attention‐Critic (MAAC) algorithm, a mainstream multiagent RL algorithm. Experiments conducted on the multimodal traffic simulation (VISSIM) platform demonstrate a 15% increase in delay time (DT) and a 40% reduction in attack ratio (AR) compared to the single‐vehicle attack, confirming the effectiveness and stealthiness of our collaborative attack. Yalun Wu, Yingxiao Xiang, Thar Baker, Endong Tong, Xiaoshu Cui, Zhen Han 0001, Jiqiang Liu, Wenjia Niu |
Int. J. Intell. Syst. | 2 |
| 2021 | Security Analysis of Poisoning Attacks Against Multi-agent Reinforcement Learning
Zhiqiang Xie 0001, Yingxiao Xiang, Endong Tong, Wenjia Niu, Jiqiang Liu, Jian Wang 0071 |
ICA3PP (1) | 2 |
| 2021 | Protecting Reward Function of Reinforcement Learning via Minimal and Non-catastrophic Adversarial TrajectoryabstractReward functions are critical hyperparameters with commercial values for individual or distributed reinforcement learning (RL), as slightly different reward functions result in significantly different performance. However, existing inverse reinforcement learning (IRL) methods can be utilized to approximate reward functions just based on collected expert trajectories through observing. Thus, in the real RL process, how to generate a polluted trajectory and perform an adversarial attack on IRL for protecting reward functions has become the key issue. Meanwhile, considering the actual RL cost, generated adversarial trajectories should be minimal and non-catastrophic for ensuring normal RL performance. In this work, we propose a novel approach to craft adversarial trajectories disguised as expert ones, for decreasing the IRL performance and realize the anti-IRL ability. Firstly, we design a reward clustering-based metric to integrate both advantages of fine- and coarse-grained IRL assessment, including expected value difference (EVD) and mean reward loss (MRL). Further, based on such metric, we explore an adversarial attack based on agglomerative nesting algorithm (AGNES) clustering and determine targeted states as starting states for reward perturbation. Then we employ the intrinsic fear model to predict the probability of imminent catastrophe, supporting to generate non-catastrophic adversarial trajectories. Extensive experiments of 7 state-of-the-art IRL algorithms are implemented on the Object World benchmark, demonstrating the capability of our proposed approach in (a) decreasing the IRL performance and (b) having minimal and non-catastrophic adversarial trajectories. Tong Chen 0007, Yingxiao Xiang, Yunzhe Tian, Endong Tong, Wenjia Niu, Jiqiang Liu, Gang Li 0009, Qi Alfred Chen |
SRDS | 2 |
| 2021 | Adversarial retraining attack of asynchronous advantage actor-critic based pathfindingabstractPathfinding becomes an important component in many real-world scenarios, such as popular warehouse systems and autonomous aircraft towing vehicles. With the development of reinforcement learning (RL) especially in the context of asynchronous advantage actor-critic (A3C), pathfinding is undergoing a revolution in terms of efficient parallel learning. Similar to other artificial intelligence-based applications, A3C-based pathfinding is also threatened by the adversarial attack. In this paper, we are the first to study the adversarial attack to A3C, that can unexpectedly wake up longtime retraining mechanism until successful pathfinding. We also discover an attack example generation to launch the attack based on gradient band, in which only one baffle of extremely few unit lengths can successfully perform the attack. Experiments with detailed analysis are conducted to show a high attack success rate of 95% with an average baffle length of 2.95. We also discuss defense suggestions leveraging the insights from our analysis. Tong Chen 0007, Jiqiang Liu, Yingxiao Xiang, Wenjia Niu, Endong Tong, Shuoru Wang, He Li 0019, Liang Chang 0003, Gang Li 0009, Qi Alfred Chen |
Int. J. Intell. Syst. | 3 |
| 2020 | Explainable Congestion Attack Prediction and Software-level Reinforcement in Intelligent Traffic Signal SystemabstractWith connected vehicle(CV) technology, the next-generation transportation system is stepping into its implementation phase via the deployment of Intelligent Traffic Signal System (I-SIG). Since the congestion attack was firstly discovered in USDOT (U.S. Department of Transportation) sponsored I-SIG, deployed in three cities including New York, such realistic threat opens a new security issue. In this work, from machine learning perspective, we perform a systematic feature analysis on congestion attack and its variations from last vehicle of different traffic flow pattern. We first adopt the Tree-regularized Gated Recurrent Unit (TGRU) to make explainable congestion attack prediction, in which 32-dimension features are defined to character a 8-phase intersection traffic. We then develop corresponding software-level security reinforcements suggestions, which can be further expanded as an important work. In massive experiments based on real-world intersection settings, we eventually distill 384 samples of congestion attacks to train a TGRU-based attack prediction model, and achieve an average 80% precision. We further discussed possible reinforcement defense methods according to our prediction model. Xiaojin Wang, Yingxiao Xiang, Wenjia Niu, Endong Tong, Jiqiang Liu |
ICPADS | 2 |
| 2020 | An Empirical Study on GAN-Based Traffic Congestion Attack Analysis: A Visualized MethodabstractWith the development of emerging intelligent traffic signal (I-SIG) system, congestion-involved security issues are drawing attentions of researchers and developers on the vulnerability introduced by connected vehicle technology, which empowers vehicles to communicate with the surrounding environment such as road-side infrastructure and traffic control units. A congestion attack to the controlled optimization of phases algorithm (COP) of I-SIG is recently revealed. Unfortunately, such analysis still lacks a timely visualized prediction on later congestion when launching an initial attack. In this paper, we argue that traffic image feature-based learning has available knowledge to reflect the relation between attack and caused congestion and propose a novel analysis framework based on cycle generative adversarial network (CycleGAN). Based on phase order, we first extract four-direction road images of one intersection and perform phase-based composition for generating new sample image of training. We then design a weighted L1 regularization loss that considers both last-vehicle attack and first-vehicle attack, to improve the training of CycleGAN with two generators and two discriminators. Experiments on simulated traffic flow data from VISSIM platform show the effectiveness of our approach. Yingxiao Xiang, Endong Tong, Wenjia Niu, Bowei Jia, Long Li 0005, Jiqiang Liu, Zhen Han 0001 |
Wirel. Commun. Mob. Comput. | 2 |
| 2019 | Adversarial attack and defense in reinforcement learning-from AI security viewabstractReinforcement learning is a core technology for modern artificial intelligence, and it has become a workhorse for AI applications ranging from Atrai Game to Connected and Automated Vehicle System (CAV). Therefore, a reliable RL system is the foundation for the security critical applications in AI, which has attracted a concern that is more critical than ever. However, recent studies discover that the interesting attack mode adversarial attack also be effective when targeting neural network policies in the context of reinforcement learning, which has inspired innovative researches in this direction. Hence, in this paper, we give the very first attempt to conduct a comprehensive survey on adversarial attacks in reinforcement learning under AI security. Moreover, we give briefly introduction on the most representative defense technologies against existing adversarial attacks. Tong Chen 0007, Jiqiang Liu, Yingxiao Xiang, Wenjia Niu, Endong Tong, Zhen Han 0001 |
Cybersecur. | 3 |
| 2017 | A Cross-Modal CCA-Based Astroturfing Detection Approach
XiaoXuan Bai, Yingxiao Xiang, Wenjia Niu, Jiqiang Liu, Tong Chen 0007 |
ICICS | 2 |
| 2017 | A Method to Effectively Detect Vulnerabilities on Path Planning of VIN
Wenjia Niu, Jiqiang Liu, Jia Zhao 0005, Tong Chen 0007, Yinqi Yang, Yingxiao Xiang |
ICICS | 7 |
| 2017 | A Hidden Astroturfing Detection Approach Base on Emotion Analysis
Tong Chen 0007, Noora Hashim Alallaq, Wenjia Niu, Yingdi Wang, XiaoXuan Bai, Yingxiao Xiang, Jiqiang Liu |
KSEM | 7 |