VLDB 2026 Research / reviewers in the wild / expert
Yazhou Tu
dblp:222/2846
· DBLP profile ↗
12ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0001-7640-1829ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 4 first-author · 5 since 2021Computer networks · 3 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Purified Distillation Slimming (PDS) for Robust Backdoor DefenseabstractBackdoor attacks pose significant risks to applications based on deep neural networks (DNNs). Current defenses fail to achieve good performance with lightweight (compact) models, limited defense data, and low poisoning rates. To address these challenges, we propose Purified Distillation Slimming (PDS), a novel knowledge distillation approach equipped with iterative pruning. Specifically, we initialize the student model from the backdoored teacher model and iteratively prune the student's neurons until the trigger pattern is deactivated. Such an approach leverages the efficacy of knowledge distillation to transfer purified knowledge from a potentially compromised teacher model to a student model, thereby filtering out backdoor triggers embedded within the training data. Concurrently, we employ network slimming to prune backdoored neurons, enhancing the model's resilience to backdoor attacks by reducing the neurons that adversaries can exploit. Through comprehensive experiments against 17 SOTA backdoor attacks, we demonstrate that our proposed method not only effectively mitigates the impact of backdoor attacks but also preserves, and in some cases even enhances, the model's performance on benign tasks. The effectiveness of PDS has been verified on multiple datasets (Cifar-10, GTSRB, and ImageNet) across several network architectures (ResNet, VGG, MobileNet, EfficientNet, and GoogLeNet). Liqun Shan, Kaiying Han, Yazhou Tu, Insup Lee 0001, Xiali Hei 0001 |
AsiaCCS | 3 |
| 2026 | EMIT: Reflection-Based Charging Jamming AttackabstractRecently, Wireless Rechargeable Sensor Networks (WRSNs) based platforms have become promising for broad applications. However, if an adversary disrupts the wireless charging process in WRSNs, sensors may die due to lack of timely energy supply, compromising the reliability and availability of systems relying on sensing tasks. In this paper, we develop a zero-cost power jamming attack in WRSNs, termed rEflection-based jaMmIng aTtack (EMIT), which introduces an off-the-shelf and inconspicuous reflector such as a Coca-Cola can that intentionally reflects the wave from the charger to destructively interfere with the charging wave at the target sensor. Our approach lifts the limitations of traditional charging attacks, including high cost, complex implementation and ease of detection. We conduct extensive field experiments to evaluate EMIT attack in different types of WRSNs. The results show that on average, the success rate of EMIT attack is 90% in WRSNs with fixed charging locations, and 75% in WRSNs with dynamic charging locations. Finally, we build a real-world WRSN on university campus to study the effectiveness of EMIT attack in complex scenarios. In total, EMIT attack causes 134 sensor deaths over 66 days. Tang Liu 0001, Dié Wu, Jian Peng 0002, Wenzheng Xu, Baijun Wu, Yazhou Tu |
IEEE Trans. Mob. Comput. | 8 |
| 2025 | AdvOSD: Adversarial One-Step Diffusion for Generalizable and Efficient Fake Image DetectionabstractDetecting synthetic images generated by more ad-vanced generative models, such as Generative Adversarial Net-works (GANs) and Diffusion Models (DMs), is still a significant challenge. The images generated by these models are very vi-sually realistic and tend to evade current detection techniques, especially those struggling with generalization and efficiency. The present study suggests AdvOSD (Adversarial One-Step Diffusion), a generalizable and efficient approach to detecting fake images. AdvOSD operates by examining the comparative robustness of real and synthetic images to an adversarial-driven, specially crafted one-step diffusion transformation. The method begins by generating an oracle prompt for an input image through a BLIP model. The prompt is further manipu-lated through targeted noun substitution with NLP techniques to craft an effective adversarial prompt for interfering with the image's reconstruction process. AdvOSD's strength lies in its one-step transformation module: the input image's latent representation and adversarial prompt embedding are fed into a LoRA-adapted UNet, which, along with a diffusion model scheduler, performs one efficient transformation step to produce a reconstructed image. Authenticity is then assessed by calculating the similarity between original and transformed images. Experimental results on several benchmark datasets demonstrate that AdvOSD achieves competitive detection ac-curacy, particularly for editted images. For efficiency, the inversion-based baseline ZeroFake reports 30.2 s/image on a DGX A100, whereas AdvOSD runs ~ 1.5 s/image on a con-sumer RTX 3060- 20 x faster despite far weaker hardware (A100: 640 GB HBM2e; 3060: 12 GB GDDR6), making it a practical solution for real-world applications. Liqun Shan, Kaiying Han, Yazhou Tu, Xiali Hei 0001 |
ACSAC | 3 |
| 2025 | Regional Weather Variable Predictions by Machine Learning With Near-Surface Observational and Atmospheric Numerical DataabstractAccurate and timely regional weather prediction is vital for sectors dependent on weather-related decisions. Traditional prediction methods, based on atmospheric equations, often struggle with coarse temporal resolutions and inaccuracies. This article presents a novel machine learning (ML) model, called Micro-Macro (MiMa), that integrates both near-surface observational data from Kentucky Mesonet stations (collected every 5 min, known as Micro data) and hourly atmospheric numerical outputs (termed as Macro data) for fine-resolution weather forecasting. The MiMa model employs an encoder-decoder transformer structure, with two encoders for processing multivariate data from both datasets and a decoder for forecasting weather variables over short time horizons. Each instance of the MiMa model, called a modelet, predicts the values of a specific weather parameter at an individual mesonet station. The approach is extended with Regional MiMa (Re-MiMa) modelets, which are designed to predict weather variables at ungauged locations by training on multivariate data from a few representative stations in a region, tagged with their elevations. Re-MiMa can provide highly accurate predictions across an entire region, even in areas without observational stations. Experimental results show that MiMa significantly outperforms current models, with Re-MiMa offering precise short-term forecasts for ungauged locations, marking a significant advancement in weather forecasting accuracy and applicability. Yihe Zhang 0001, Bryce Turney, Purushottam Sigdel, Xu Yuan 0001, Eric Rappin, Adrian Lago, Sytske K. Kimball, Li Chen 0019, Paul J. Darby, Lu Peng 0001, Sercan Aygün, Yazhou Tu, M. Hassan Najafi, Nian-Feng Tzeng |
IEEE Trans. Geosci. Remote. Sens. | 12 |
| 2024 | From Virtual Touch to Tesla Command: Unlocking Unauthenticated Control Chains From Smart Glasses for Vehicle TakeoverabstractThis paper studies vulnerabilities at the intersection of wearable devices and automated control systems. Particularly, we focus on exploiting smart glasses as an entry point and unveil the threats of taking over security-critical automated control chains without user verification or interaction. These vulnerabilities can be especially pertinent in scenarios where security mechanisms only depend on entry point security with minimal user verification (relying on complete trust over previous nodes in automated control chains). We have validated the effects of our attacks on real-world systems (e.g., Tesla vehicles) that are controlled by software and automation tools such as Apple Shortcuts or IFTTT. We show how our contactless, speaker-independent, and electromagnetic interference based attacks can control functionalities such as unlocking doors and initiating remote start of Tesla vehicles, even though the victim’s phone is in a lock-screen status. Our findings not only demonstrate the potential for unauthorized control over automated, connected systems but also highlight the urgent need for more robust security measures in the integration of wearable technology with broader automation frameworks. Xingli Zhang 0004, Yazhou Tu, Yan Long 0002, Liqun Shan, Mohamed A Elsaadani, Kevin Fu, Zhiqiang Lin 0001, Xiali Hei 0001 |
SP | 2 |
| 2023 | Auditory Eyesight: Demystifying μs-Precision Keystroke Tracking Attacks on Unconstrained Keyboard Inputs
Yazhou Tu, Liqun Shan, Md. Imran Hossen, Sara Rampazzi, Kevin R. B. Butler, Xiali Hei 0001 |
USENIX Security Symposium | 1 |
| 2021 | Transduction Shield: A Low-Complexity Method to Detect and Correct the Effects of EMI Injection Attacks on SensorsabstractThe reliability of control systems often relies on the trustworthiness of sensors. As process automation and robotics keep evolving, sensing methods such as pressure sensing are extensively used in both conventional systems and rapidly emerging applications. The goal of this paper is to investigate the threats and design a low-complexity defense method against EMI injection attacks on sensors. Yazhou Tu, Vijay Srinivas Tida, Zhongqi Pan, Xiali Hei 0001 |
AsiaCCS | 1 |
| 2020 | An Object Detection based Solver for Google's Image reCAPTCHA v2
Md. Imran Hossen, Yazhou Tu, Md Fazle Rabby, Md. Nazmul Islam, Hui Cao 0003, Xiali Hei 0001 |
RAID | 2 |
| 2019 | Trick or Heat?: Manipulating Critical Temperature-Based Control Systems Using Rectification AttacksabstractTemperature sensing and control systems are widely used in the closed-loop control of critical processes such as maintaining the thermal stability of patients, or in alarm systems for detecting temperature-related hazards. However, the security of these systems has yet to be completely explored, leaving potential attack surfaces that can be exploited to take control over critical systems. Yazhou Tu, Sara Rampazzi, Bin Hao, Angel Rodriguez, Kevin Fu, Xiali Hei 0001 |
CCS | 1 |
| 2018 | A Visible Light Channel Based Access Control Scheme for Wireless Insulin Pump SystemsabstractSmart personal insulin pumps have been widely adopted by type 1 diabetes. However, many wireless insulin pump systems lack security mechanisms to protect them from malicious attacks. In previous works, the read-write attacks over RF channels can be launched stealthily and could jeopardize patients' lives. Protecting patients from such attacks is urgent. To address this issue, we propose a novel visible light channel based access control scheme for wireless infusion insulin pumps. This scheme employs an infrared photodiode sensor as a receiver in an insulin pump, and an infrared LED as an emitter in a doctor's reader (USB) to transmit a PIN/shared key to authenticate the doctor's USB. The evaluation results demonstrate that our scheme can reliably pass the authentication process with a low false accept rate (0.05% at a distance of 5cm). Kam Kong, Xiali Hei 0001, Yazhou Tu, Xiaojiang Du |
ICC | 4 |
| 2018 | Voiceprint-Based Access Control for Wireless Insulin Pump SystemsabstractInsulin pumps have been widely used by patients with diabetes. Insulin pump systems adopt wireless channel with few cryptographic mechanisms, which makes them vulnerable to many attacks. In this paper, we focus on the wireless channel between Carelink USB and insulin pump on which the attackers can launch message eavesdropping and/or therapy manipulation attacks, which may put the patient in a life-threatening situation. Some prior solutions such as certificate-based or token-based schemes need either complicated key management or additional devices. We propose a novel voiceprint-based access control scheme comprising anti-replay speaker verification and voiceprint-based key agreement to secure the channel between the Carelink USB and insulin pump. Our scheme does not need permanent key sharing or additional devices. The anti-replay speaker verification adopts cascaded fusion of speaker verification and anti-replay countermeasure to ensure the insulin pump can be accessed by Carelink USB only after the legitimate user passes the identity verification. The evaluation on ASVspoof 2017 datasets shows that our scheme achieves a 4.02% Equal Error Rate (EER) with the existence of replay impostors. Besides, our scheme uses energy-difference-based voiceprint extraction and secure multi-party computing to generate a common cryptography (temporary) key between the Carelink USB and insulin pump, which can be used to encrypt the subsequent communication, and protect the insulin pump from eavesdropping and therapy manipulation attacks. By appropriately setting the similarity threshold of voiceprints, our key agreement scheme allows the insulin pump to establish a secure channel only with the device in its close proximity. Bin Hao, Xiali Hei 0001, Yazhou Tu, Xiaojiang Du, Jie Wu 0001 |
MASS | 3 |
| 2018 | Injected and Delivered: Fabricating Implicit Control over Actuation Systems by Spoofing Inertial Sensors
Yazhou Tu, Zhiqiang Lin 0001, Insup Lee 0001, Xiali Hei 0001 |
USENIX Security Symposium | 1 |