Jiacen Xu 0001

dblp:224/4836-1 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0002-9616-4274ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 5 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Entente: Cross-silo Intrusion Detection on Network Log Graphs with Federated Learning
Jiacen Xu 0001, Chenang Li, Zhou Li 0001
NDSS1
2025 Dynamic Risk Assessments for Offensive Cybersecurity Agents
abstract
Foundation models are increasingly becoming better autonomous programmers, raising the prospect that they could also automate dangerous offensive cyber‑operations. Current frontier model audits probe the cybersecurity risks of such agents, but most fail to account for the degrees of freedom available to adversaries in the real world.In particular, with strong verifiers and financial incentives, agents for offensive cybersecurity are amenable to iterative improvement by would-be adversaries. We argue that assessments should take into account an expanded threat model in the context of cybersecurity, emphasizing the varying degrees of freedom that an adversary may possess in stateful and non-stateful environments within a fixed compute budget. We show that even with a relatively small compute budget (8 H100 GPU Hours in our study), adversaries can improve an agent's cybersecurity capability on InterCode CTF by more than 40\% relative to the baseline---without any external assistance. These results highlight the need to evaluate agents' cybersecurity risk in a dynamic manner, painting a more representative picture of risk.
Boyi Wei, Benedikt Stroebl, Jiacen Xu 0001, Joie Zhang, Zhou Li 0001, Peter Henderson 0002
NeurIPS3
2024 Understanding and Bridging the Gap Between Unsupervised Network Representation Learning and Security Analytics
abstract
Cyber-attacks have become increasingly sophisticated, which also drives the development of security analytics that produce countermeasures by mining organizational logs, e.g., network and authentication logs. Graph security analytics (GSA) that can model the complex communication patterns between users/hosts/processes have been extensively developed and deployed. Among the techniques that power GSAs, Unsupervised Network Representation Learning (UNRL) is gaining traction, which learns a latent graph representation, i.e., node embedding, and customizes it for different downstream tasks. Prominent advantages have been demonstrated by UNRL-based GSAs, as UNRL trains a detection model in an unsupervised way and exempts the model developers from the duty of feature engineering.In this paper, we revisit the designs of previous UNRL-based GSAs to understand how they perform in real-world settings. We found their performance is questionable on large-scale, noisy log datasets like LANL authentication dataset, and the main reason is that they follow the standard UNRL framework that trains a generic model in an attack-agnostic way. We argue that generic attack characteristics should be considered, and propose Argus, a UNRL-based GSA with new encoder and decoder designs. Argus is also designed to work on discrete temporal graphs (DTG) to exploit the graph temporal dynamics. Our evaluation of two large-scale datasets, LANL and OpTC, shows it can outperform the state-of-the-art approaches by a large margin.
Jiacen Xu 0001, Xiaokui Shu, Zhou Li 0001
SP1
2023 Maestro: A Gamified Platform for Teaching AI Robustness
abstract
Although the prevention of AI vulnerabilities is critical to preserve the safety and privacy of users and businesses, educational tools for robust AI are still underdeveloped worldwide. We present the design, implementation, and assessment of Maestro. Maestro is an effective open-source game-based platform that contributes to the advancement of robust AI education. Maestro provides "goal-based scenarios" where college students are exposed to challenging life-inspired assignments in a "competitive programming" environment. We assessed Maestro's influence on students' engagement, motivation, and learning success in robust AI. This work also provides insights into the design features of online learning tools that promote active learning opportunities in the robust AI domain. We analyzed the reflection responses (measured with Likert scales) of 147 undergraduate students using Maestro in two quarterly college courses in AI. According to the results, students who felt the acquisition of new skills in robust AI tended to appreciate highly Maestro and scored highly on material consolidation, curiosity, and maestry in robust AI. Moreover, the leaderboard, our key gamification element in Maestro, has effectively contributed to students' engagement and learning. Results also indicate that Maestro can be effectively adapted to any course length and depth without losing its educational quality.
Margarita Geleta, Jiacen Xu 0001, Manikanta Loya, Sameer Singh 0001, Zhou Li 0001, Sergio Gago Masagué
AAAI2
2023 On Adversarial Robustness of Point Cloud Semantic Segmentation
abstract
Recent research efforts on 3D point cloud semantic segmentation (PCSS) have achieved outstanding performance by adopting neural networks. However, the robustness of these complex models have not been systematically analyzed. Given that PCSS has been applied in many safety-critical applications like autonomous driving, it is important to fill this knowledge gap, especially, how these models are affected under adversarial samples. As such, we present a comparative study of PCSS robustness. First, we formally define the attacker's objective under performance degradation and object hiding. Then, we develop new attack by whether to bound the norm. We evaluate different attack options on two datasets and three PCSS models. We found all the models are vulnerable and attacking point color is more effective. With this study, we call the attention of the research community to develop new approaches to harden PCSS models.
Jiacen Xu 0001, Zhe Zhou 0001, Boyuan Feng, Yufei Ding 0001, Zhou Li 0001
DSN1
2023 Design Factors of Maestro: A Serious Game for Robust AI Education
abstract
Training tools targeting robust AI are still in their infancy. We present Maestro, an effective open-source game-based platform for robust AI training in higher education, which includes counter- measures and prevention of AI vulnerabilities. Maestro provides goal-based scenarios (GBSs) where students are exposed to challenging life-inspired assignments in a competitive programming environment. The assessment of Maestro showed that its leader-board, a key gamification element, has been crucial for effective student learning. Students who felt the acquisition of new skills in robust AI tended to appreciate highly Maestro and scored highly on material consolidation, curiosity and maestry in robust AI.
Margarita Geleta, Jiacen Xu 0001, Manikanta Loya, Sameer Singh 0001, Zhou Li 0001, Sergio Gago Masagué
SIGCSE (2)2
2023 HOMESPY: The Invisible Sniffer of Infrared Remote Control of Smart TVs
Kong Huang, Ke Zhang 0039, Jiacen Xu 0001, Jiongyi Chen, Di Tang 0001, Kehuan Zhang
USENIX Security Symposium4
2023 PROGRAPHER: An Anomaly Detection System based on Provenance Graph Embedding
Jiacen Xu 0001, Chun-lin Xiong, Zhou Li 0001, Kehuan Zhang
USENIX Security Symposium2
2021 Scalability vs. Utility: Do We Have To Sacrifice One for the Other in Data Importance Quantification?
abstract
Quantifying the importance of each training point to a learning task is a fundamental problem in machine learning and the estimated importance scores have been leveraged to guide a range of data workflows such as data summarization and domain adaption. One simple idea is to use the leave-one-out error of each training point to indicate its importance. Recent work has also proposed to use the Shapley value, as it defines a unique value distribution scheme that satisfies a set of appealing properties. However, calculating Shapley values is often expensive, which limits its applicability in real-world applications at scale. Multiple heuristics to improve the scalability of calculating Shapley values have been proposed recently, with the potential risk of compromising their utility in real-world applications.How well do existing data quantification methods perform on existing workflows? How do these methods compare with each other, empirically and theoretically? Must we sacrifice scalability for the utility in these workflows when using these methods? In this paper, we conduct a novel theoretical analysis comparing the utility of different importance quantification methods, and report extensive experimental studies on existing and proposed workflows such as noisy label detection, watermark removal, data summarization, data acquisition, and domain adaptation. We show that Shapley value approximation based on a KNN surrogate over pretrained feature embeddings obtains comparable utility with existing algorithms while achieving significant scalability improvement, often by orders of magnitude. Our theoretical analysis also justifies its advantage over the leave-one-out error.The code is available at https://github.com/AIsecure/Shapley-Study.
Ruoxi Jia 0001, Fan Wu 0011, Xuehui Sun, Jiacen Xu 0001, David Dao, Bhavya Kailkhura, Ce Zhang 0001, Bo Li 0026, Dawn Song
CVPR4
2021 Adversarial Attack Generation Empowered by Min-Max Optimization
abstract
The worst-case training principle that minimizes the maximal adversarial loss, also known as adversarial training (AT), has shown to be a state-of-the-art approach for enhancing adversarial robustness. Nevertheless, min-max optimization beyond the purpose of AT has not been rigorously explored in the adversarial context. In this paper, we show how a general notion of min-max optimization over multiple domains can be leveraged to the design of different types of adversarial attacks. In particular, given a set of risk sources, minimizing the worst-case attack loss can be reformulated as a min-max problem by introducing domain weights that are maximized over the probability simplex of the domain set. We showcase this unified framework in three attack generation problems -- attacking model ensembles, devising universal perturbation under multiple inputs, and crafting attacks resilient to data transformations. Extensive experiments demonstrate that our approach leads to substantial attack improvement over the existing heuristic strategies as well as robustness improvement over state-of-the-art defense methods against multiple perturbation types. Furthermore, we find that the self-adjusted domain weights learned from min-max optimization can provide a holistic tool to explain the difficulty level of attack across domains.
Jingkang Wang, Tianyun Zhang, Sijia Liu 0001, Jiacen Xu 0001, Makan Fardad, Bo Li 0026
NeurIPS5