VLDB 2026 Research / reviewers in the wild / expert
Binbin Tu
dblp:218/5379
· DBLP profile ↗
9ranked-venue papers
7as first author
8since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 6 first-author · 6 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MinBucket MPSI: Breaking the Max-Size Bottleneck in Multi-Party Private Set Intersection
Binbin Tu, Boyudong Zhu, Yang Cao 0023, Yu Chen 0003 |
NDSS | 1 |
| 2026 | Low-visibility adversarial sample generation method based on human visual perceptionabstractAbstract With deep learning now widely applied in visual perception tasks, the question of how to enhance adversarial stealth and effectiveness while addressing the sensitivity of the human visual system has become urgent. In response to the limitations of traditional $${L_p}$$ L p norm based adversarial perturbations, which are easily noticed by the human eye in terms of brightness and color distribution, this paper introduces a low-visibility adversarial sample generation method Luminance Perception Constrained Adversarial Attack (LPCAA) that integrates brightness-aware constraints. First, it leverages the human eye’s varying sensitivity to different light wavelengths, prioritizes perturbations in the blue channel, and uses a dynamic brightness-weight function to suppress sudden changes in overall image brightness. Next, through an energy functional framework, it incorporates gradient regularization, sparsity constraints, and the $${L_2}$$ L 2 norm to guarantee smoothness and sparsity in both the spatial distribution and amplitude of the perturbations. To adaptively search for the optimal perturbation distribution across various images and models, we propose a dynamic tuning mechanism that uses finite-difference or gradient feedback to iteratively adjust perturbation strength and constraint weighting, thereby balancing attack success rates with perceptibility. Our experiments, conducted on CIFAR-10, ILSVRC2012, and other datasets, systematically evaluated multiple mainstream networks such as ResNet, VGG, MobileNet, and various defense algorithms. The findings indicate that LPCAA achieves higher attack success rates than FGSM, PGD, ColorFool, and PerC-C&W in both white-box and black-box settings, while also demonstrating notably lower perceptibility in terms of structural similarity index measure, perturbation ratio, and CIELCh color differences. Even with high-resolution images or defenses like compression and diffusion-based denoising, LPCAA leverages brightness awareness and the energy functional to maintain stable attack efficacy with minimal visual distortion. This approach not only offers a new balance between stealth and efficacy in adversarial attacks, but also poses fresh challenges for security evaluation and robust defense strategies in deep models. Binbin Tu, Haoyuan Zhou, Linfei Zhao, Jiawei Bao |
Cybersecur. | 1 |
| 2026 | Hybrid Attention-Based DeepLabV3+ Network for Semantic Segmentation of Land Cover on Remote-Sensing ImageryabstractLand cover segmentation is a prominent issue of remote‐sensing imaging that has attracted significant attention. Aiming at problems such as the unbalanced distribution of land cover categories, missing boundary information, and misclassification during extraction, a novel DeepLabV3+ semantic segmentation network based on hybrid attention mechanisms is proposed. Firstly, the feature extraction part mainly uses ResNet and spatial pyramid pooling modules to enhance the generalization ability. Then, an improved BiFormer module with a gated control mechanism is designed to improve the feature dependency relationship and to strengthen the representation of deep features. For the decoder, an attention merging module adopting coordinate attention and squeeze aggregated excitation layers is proposed to mitigate the issue of information loss and further boost feature reflection capacity. Then, a joint loss function, combining cross‐entropy loss and Dice loss, is implemented to alleviate category imbalance and stabilize parameter training. Experimental results demonstrate that the improved DeepLabV3+ model outperforms others in terms of objective evaluation in the semantic segmentation of land cover in remote‐sensing imagery. This approach not only reinforces the robustness of the model but also facilitates easier adaptation to diverse application tasks. Nanmu Hui, Binbin Tu, Yunqiu Sun |
Int. J. Intell. Syst. | 3 |
| 2025 | Fast Enhanced Private Set Union in the Balanced and Unbalanced Scenarios
Binbin Tu, Yujie Bai, Yang Cao 0023, Yu Chen 0003 |
USENIX Security Symposium | 1 |
| 2024 | Fast two-party signature for upgrading ECDSA to two-party scenario easily
Binbin Tu, Yu Chen 0003, Hongrui Cui, Xianfang Wang |
Theor. Comput. Sci. | 1 |
| 2023 | Fast Unbalanced Private Set Union from Fully Homomorphic EncryptionabstractPrivate set union (PSU) allows two parties to compute the union of their sets without revealing anything else. It has been widely used in various applications. While several computationally efficient PSU protocols have been developed for the balanced case, they have a potential limitation in their communication complexity, which grows (super)-linearly with the size of the larger set. This poses a challenge when performing PSU in the unbalanced setting, where one party is a constrained device holding a small set, and another is a service provider holding a large set. Binbin Tu, Yu Chen 0003, Qi Liu 0070 |
CCS | 1 |
| 2022 | You Can Sign but Not Decrypt: Hierarchical Integrated Encryption and Signature
Min Zhang 0064, Binbin Tu, Yu Chen 0003 |
Inscrypt | 2 |
| 2022 | Efficient ECDSA-Based Adaptor Signature for Batched Atomic Swaps
Binbin Tu |
ISC | 1 |
| 2020 | Threshold trapdoor functions and their applicationsabstractThe authors introduce a new cryptographic primitive named threshold trapdoor function (TTDF). TTDF is a threshold version of the trapdoor function. Its master trapdoor can be split into many pieces, and a quorum of shared trapdoors can be used to invert the function. TTDF holds one‐wayness, even if exposing part of shared trapdoors. Based on TTDF, they give generic constructions of threshold encryption under adaptive corruption model and revocation encryption. Then, they show TTDF can be instantiated under the decisional Diffie‐Hellman assumption and the learning with errors assumption. By combining the instantiations of TTDF with the generic constructions, they obtain threshold and revocation encryptions which compare favourably over existing schemes. The experimental results show that their proposed schemes are practical. Binbin Tu, Yu Chen 0003 |
IET Inf. Secur. | 1 |