VLDB 2026 Research / reviewers in the wild / expert
Zitao Chen 0001
dblp:205/5551-1
· DBLP profile ↗
13ranked-venue papers
9as first author
9since 2021 · last 2026
0000-0002-6756-8675ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 9 · 6 first-author · 9 since 2021Systems, architecture and hardware · 5 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Feed-Forward Controller-Based Recovery for Robotic Vehicles From Physical AttacksabstractRobotic Vehicles (RV) rely extensively on sensor inputs to operate autonomously. Physical attacks such as sensor tampering and spoofing can feed erroneous sensor measurements to deviate RVs from their course and result in mission failures. In this paper, we present a Feed-Forward Controller based framework for automatically recovering RVs from physical attacks. We use machine learning (ML) to design an attack resilient Feed-Forward Controller (FFC), which runs in tandem with the RV's primary controller and monitors it. Under attacks, the FFC takes over from the RV's primary controller to recover the RV, and allows the RV to complete its mission successfully. Our evaluation on 6 RV systems including 3 real RVs shows that our proposed framework prevents crashes and allows RVs to complete their missions successfully despite attacks in 86% of the cases. Further, we propose designs to streamline the implementation of the FFC-based recovery and its application in new RV systems. Pritam Dash, Guanpeng Li, Zitao Chen 0001, Mehdi Karimibiuki, Karthik Pattabiraman |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Anonymity Unveiled: A Practical Framework for Auditing Data Use in Deep Learning ModelsabstractThe rise of deep learning (DL) has led to a surging demand for training data, which incentivizes the creators of DL models to trawl through the Internet for training materials. Meanwhile, users often have limited control over whether their data (e.g., facial images) are used to train DL models without their consent, which has engendered pressing concerns. Zitao Chen 0001, Karthik Pattabiraman |
CCS | 1 |
| 2025 | A Method to Facilitate Membership Inference Attacks in Deep Learning Models
Zitao Chen 0001, Karthik Pattabiraman |
NDSS | 1 |
| 2024 | Catch Me if You Can: Detecting Unauthorized Data Use in Training Deep Learning ModelsabstractThe rise of deep learning (DL) has led to a surging demand for training data, which incentivizes the creators of DL models to trawl through the Internet for training materials. Meanwhile, users often have limited control over whether their data (e.g., facial images) are used to train DL models without their consent, which has engendered pressing concerns. Zitao Chen 0001 |
CCS | 1 |
| 2024 | Overconfidence is a Dangerous Thing: Mitigating Membership Inference Attacks by Enforcing Less Confident Prediction
Zitao Chen 0001, Karthik Pattabiraman |
NDSS | 1 |
| 2023 | Jujutsu: A Two-stage Defense against Adversarial Patch Attacks on Deep Neural NetworksabstractAdversarial patch attacks create adversarial examples by injecting arbitrary distortions within a bounded region of the input to fool deep neural networks (DNNs). These attacks are robust (i.e., physically-realizable) and universally malicious, and hence represent a severe security threat to real-world DNN-based systems. Zitao Chen 0001, Pritam Dash, Karthik Pattabiraman |
AsiaCCS | 1 |
| 2023 | Fault Injection for TensorFlow ApplicationsabstractAs machine learning (ML) has seen increasing adoption in safety-critical domains (e.g., autonomous vehicles), the reliability of ML systems has also grown in importance. While prior studies have proposed techniques to enable efficient error-resilience (e.g., selective instruction duplication), a fundamental requirement for realizing these techniques is a detailed understanding of the application's resilience. In this work, we present TensorFI 1 and TensorFI 2, high-level fault injection (FI) frameworks for TensorFlow-based applications. TensorFI 1 and 2 are able to inject both hardware and software faults in any general TensorFlow 1 and 2 program respectively. Both are configurable FI tools that are flexible, easy to use, and portable. They can be integrated into existing TensorFlow programs to assess their resilience for different fault types (e.g., bit-flips in particular operations or layers). We use TensorFI 1 and TensorFI 2 to evaluate the resilience of 11 and 10 ML programs respectively, all written in TensorFlow, including DNNs used in the autonomous vehicle domain. The results give us insights into why some of the models are more resilient. We also measure the performance overheads of the two injectors, and present 4 case studies, two for each tool, to demonstrate their utility. Niranjhana Narayanan, Zitao Chen 0001, Bo Fang 0002, Guanpeng Li, Karthik Pattabiraman, Nathan DeBardeleben |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | A Low-cost Fault Corrector for Deep Neural Networks through Range RestrictionabstractDeep neural networks (DNNs) have seen growing adoption in safety-critical domains. Unfortunately, they are also subject to unexpected failures due to hardware transient faults (soft errors). Traditional fault tolerance techniques require significant implementation efforts and/or incur major performance overheads. This work introducesRanger, a low-cost fault corrector that can directly correct the faulty prediction output due to transient faults without re-computation. This research laid the foundations of improving the fault tolerance of DNN applications under hardware transient faults and it has influenced subsequent work in the area, both in academia and industry. Zitao Chen 0001, Guanpeng Li, Karthik Pattabiraman |
DSN | 1 |
| 2021 | PID-Piper: Recovering Robotic Vehicles from Physical AttacksabstractRobotic Vehicles (RV) rely extensively on sensor inputs to operate autonomously. Physical attacks such as sensor tampering and spoofing can feed erroneous sensor measurements to deviate RVs from their course and result in mission failures. In this paper, we present PID-Piper, a novel framework for automatically recovering RVs from physical attacks. We use machine learning (ML) to design an attack resilient Feed-Forward Controller (FFC), which runs in tandem with the RV's primary controller and monitors it. Under attacks, the FFC takes over from the RV's primary controller to recover the RV, and allows the RV to complete its mission successfully. Our evaluation on 6 RV systems including 3 real RVs shows that PID-Piper achieves high accuracy in emulating the RV's controller, in the absence of attacks, with no false positives. Further, PID-Piper allows RVs to complete their missions successfully despite attacks in 83% of the cases, while incurring low performance overheads. Pritam Dash, Guanpeng Li, Zitao Chen 0001, Mehdi Karimibiuki, Karthik Pattabiraman |
DSN | 3 |
| 2020 | Error Resilient Machine Learning for Safety-Critical Systems: Position PaperabstractMachine learning (ML) has increasingly been adopted in safety-critical systems such as autonomous vehicles (AVs) and industrial robotics. In these domains, reliability and safety are important considerations, and hence it is critical to ensure the resilience of ML systems to faults and errors. On the other hand, soft errors are becoming more frequent in commodity computer systems due to the effects of technology scaling and reduced supply voltages. Further, traditional solutions for masking hardware faults such as Triple-Modular Redundancy (TMR) are prohibitively expensive in terms of their energy and performance overheads. Therefore, there is a compelling need to ensure the resilience of ML applications to soft errors on commodity hardware platforms.We first experimentally assess the resilience of safety-critical ML applications to soft errors. We demonstrate through fault injection experiments that even a single bit flip due to a soft error can lead to misclassification in Deep Neural Network (DNN) applications deployed in AVs, leading to safety violations. However, not all the errors in an DNN will result in serve consequences such as safety violations, and hence it is sufficient to protect the DNN from the ones that do. Unfortunately, finding all possible errors that result in safety violations is a very compute intensive task. We propose BinFI, a fault injection approach that efficiently injects critical faults that are highly likely to result in safety violations, based on the unique properties of DNNs. Finally, we propose Ranger, an approach to protect DNNs from critical faults with minimal performance overheads and no accuracy loss. We will conclude by presenting some of our ongoing work, and the future challenges in this area. Karthik Pattabiraman, Guanpeng Li, Zitao Chen 0001 |
IOLTS | 3 |
| 2020 | TensorFI: A Flexible Fault Injection Framework for TensorFlow ApplicationsabstractAs machine learning (ML) has seen increasing adoption in safety-critical domains (e.g., autonomous vehicles), the reliability of ML systems has also grown in importance. While prior studies have proposed techniques to enable efficient error-resilience (e.g., selective instruction duplication), a fundamental requirement for realizing these techniques is a detailed understanding of the application's resilience. In this work, we present TensorFI, a high-level fault injection (FI) framework for TensorFlow-based applications. TensorFI is able to inject both hardware and software faults in general TensorFlow programs. TensorFI is a configurable FI tool that is flexible, easy to use, and portable. It can be integrated into existing TensorFlow programs to assess their resilience for different fault types (e.g., faults in particular operators). We use TensorFI to evaluate the resilience of 12 ML programs, including DNNs used in the autonomous vehicle domain. The results give us insights into why some of the models are more resilient. We also present two case studies to demonstrate the usefulness of the tool. TensorFI is publicly available at https://github.com/DependableSystemsLab/TensorFI. Zitao Chen 0001, Niranjhana Narayanan, Bo Fang 0002, Guanpeng Li, Karthik Pattabiraman, Nathan DeBardeleben |
ISSRE | 1 |
| 2019 | BinFI: an efficient fault injector for safety-critical machine learning systemsabstractAs machine learning (ML) becomes pervasive in high performance computing, ML has found its way into safety-critical domains (e.g., autonomous vehicles). Thus the reliability of ML has grown in importance. Specifically, failures of ML systems can have catastrophic consequences, and can occur due to soft errors, which are increasing in frequency due to system scaling. Therefore, we need to evaluate ML systems in the presence of soft errors. Zitao Chen 0001, Guanpeng Li, Karthik Pattabiraman, Nathan DeBardeleben |
SC | 1 |
| 2018 | LiReK: A lightweight and real-time key establishment scheme for wearable embedded devices by gestures or motions
Zitao Chen 0001, Wei Ren 0002, Yi Ren 0001, Kim-Kwang Raymond Choo |
Future Gener. Comput. Syst. | 1 |