Chenyang Zhao 0006

dblp:22/8876-6 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
2since 2021 · last 2025
0009-0000-9227-1884ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2025 Revisiting Training-Inference Trigger Intensity in Backdoor Attacks
Chenhao Lin, Chenyang Zhao 0006, Longtian Wang, Chao Shen 0001, Zhengyu Zhao 0001
USENIX Security Symposium2
2025 De2Trojan: Deployable Trojan Analysis Tool and Benchmark for the Machine Learning Lifecycle via Decoupling
abstract
Trojans (backdoors) are known to raise critical security concerns for deep neural networks in machine learning (ML) systems. Despite the extensive backdoor methods and benchmarks, existing research overlooks the perspective of the ML lifecycle (i.e., the entire process from system design to data collection to model deployment). To address this gap, this paper introduces De2Trojan, a Deployable Trojan Analysis Tool via Decoupling, which establishes a standardized pipeline to investigate backdoor attacks and defenses within the ML lifecycle. De2Trojan decouples the attack surface from the general ML process through a stage-first hijacking approach, using an abstract interface for ML lifecycle stages to enhance the deployability to the ML lifecycle. Besides, its benefits are two-fold: (1) Facilitating the systematic analyses of multi-stage attacks/defenses and their combinations, shedding light on how to improve attack and defense strategies. For example, we find that current attacks (defenses) are not effective in continuous scenarios, and combining attacks (defenses) at different stages improves their effectiveness from 30.11% (8.63%), the worst cases, to 90.27% (68.73%). (2) Making it possible to identify potentially vulnerable stages, especially when iteratively updating the model in ML lifecycle. For example, we identify that backdoor attacks in the data collection stage are more vulnerable than expected, and it is more difficult to remove them from the ML lifecycle. To eliminate the impact of such attacks, it is most effective to apply backdoor defense during the deployment stage, in addition to cleaning the data before training. Overall, we present a comprehensive benchmark of backdoors within the ML lifecycle, involving 20 representative attacks and defenses, as well as their combinations, using 11 evaluation metrics.
Chenyang Zhao 0006, Chenhao Lin, Zhengyu Zhao 0001, Qian Wang 0002, Chao Shen 0001, Xiaohong Guan
IEEE Trans. Inf. Forensics Secur.2