VLDB 2026 Research / reviewers in the wild / expert
Huixiang Wen
dblp:224/7414
· DBLP profile ↗
8ranked-venue papers
4as first author
8since 2021 · last 2026
0009-0003-6682-8927ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Speak and Be Known: Authenticating Users via Ear Canal Deformation on EarbudsabstractWith the increasing popularity of smart wearable devices, such as earbuds and smart watches, presents new challenges for seamless and secure user authentication due to their limited user interfaces. Conventional biometric methods, including voice, fingerprints, and facial recognition often face issues such as usability limitations, interference from noise, or vulnerability to spoofing attacks. This paper introduces a novel authentication system called BaroAuth, which utilizes the stable and unique Speech-aware Pressure Sequences (SPSs) patterns captured by a miniaturized MEMS barometer embedded in earbuds. The design of BaroAuth hinges on two important observations. First, the production of speech relies on the coordinated movements of articulatory organs, including the tongue, jaw, and soft palate. These organs, through the activity of the temporomandibular joint (TMJ), alter the shape of the ear canal, thereby causing subtle pressure changes that encode the speaker's unique physiological characteristics and articulatory dynamics. Second, SPSs show significant intra-individual consistency and considerable inter-individual variability, which barometers can effectively measure. Meanwhile, we develop the BaroAuth prototype and carry out comprehensive experiments based on it. The experimental findings reveal that BaroAuth demonstrates a mean false-acceptance rate (FAR) of 0.41% and a false-rejection rate (FRR) of 1.23%, respectively, even under complex attack scenarios. Luo Zhou, Shan Chang, Jiusong Luo, Huixiang Wen, Hongzi Zhu, Li Lu 0001 |
IEEE Trans. Mob. Comput. | 4 |
| 2025 | BaroAuth: Harnessing Ear Canal Deformation for Speaking User Authentication on EarbudsabstractThe growing adoption of smart wearable devices (e.g., earbuds and smart watches) poses new challenges for secure and seamless user authentication due to their limited interaction interfaces. Conventional biometric methods, including fingerprints, voice, and facial recognition, often suffer from usability constraints, noise interference, or susceptibility to spoofing attacks. In this paper, we propose BaroAuth, a novel authentication system that utilizes the stable and distinctive patterns of Speech-aware Pressure Sequences (SPSs) captured by miniature MEMS barometers embedded in earbuds. The design of BaroAuth is based on two key observations. First, speech production involves coordinated movements of articulatory organs, such as the jaw, tongue, and soft palate, which reshape the ear canal geometry via the temporomandibular joint (TMJ), generating subtle pressure variations that encode the speaker’s unique articulatory dynamics and physiological traits. Second, SPSs demonstrate strong intra-individual consistency and notable inter-individual variability, which can be effectively captured by barometers. We implement the prototype of BaroAuth and conduct comprehensive experiments on it. Experimental results demonstrate that BaroAuth achieves a mean false-acceptance rate (FAR) and false-rejection rate (FRR) of 1.62% and 1.74%, respectively, even under sophisticated attack scenarios. Luo Zhou, Shan Chang, Jiusong Luo, Huixiang Wen, Hongzi Zhu, Li Lu 0001 |
ICDCS | 4 |
| 2025 | ST-AuthNet: A Spatiotemporal Attention-Driven Lightweight ECG Biometric Authentication SystemabstractAmidst the rapid integration of Medical Internet of Things (MIoT) into health monitoring ecosystems, electrocardiogram (ECG)-based biometric authentication has emerged as a pivotal component in securing smart healthcare architectures, leveraging its inherent biological uniqueness and real-time monitoring capabilities. Current ECG authentication methodologies face three MIoT-specific challenges: 1) Conventional feature extraction struggles with spatial heterogeneity in multi-device 12-lead signals; 2) Single-cycle analysis lacks generalizability across physiological states; 3) Environmental noise degrades edge computing robustness. To address these limitations, this study proposes ST-AuthNet, a lightweight ECG authentication framework that synergistically integrates spatiotemporal attention mechanisms with enhanced residual networks. First, we redesign the ResNet residual block architecture by replacing conventional 1× 1 convolutional downsampling with hybrid 2× 2 average pooling and 1× 1 convolutional operations, effectively mitigating low-amplitude morphological feature loss (e.g., P/T waves) during feature map compression. Next, a multi-head cross-attention mechanism is introduced to dynamically capture inter-lead spatial correlations and intra-PQRST temporal dependencies across ECG waveforms. Finally, an adaptive threshold decision module is developed to optimize model robustness against physiological variability and environmental perturbations through dynamic classification boundary adjustment. Evaluations demonstrate state-of-the-art performance with 99.77% (CYBHI), 88.60% (MIT), 76.33% (MIT2), and 92.44% (HeartID-V) accuracy, significantly outperforming existing methods in cross-scenario biometric verification. Huixiang Wen, Chaojie Ma, Jiaming Pei, Ali Kashif Bashir, Wei Liu 0138 |
IEEE Internet Things J. | 1 |
| 2025 | Closed-Box 3-D Face Reconstruction Attack on Face Recognition From a Single Imageabstract3D face recognition systems are frequently susceptible to spoofing attacks, with 3D face presentation attacks being particularly notorious. Attackers commonly exploit 3D scanning and printing techniques to generate masks of target individuals, a method proven successful in various real-world scenarios. A defining characteristic of these attacks involves acquiring 3D face models via 3D scanning, a process that is notably more expensive and cumbersome compared to obtaining 2D photos. In this work, we introduce DREAM, a novel method for recovering 3D face models from a single 2D image. Specifically, our approach adopts a black-box strategy, reconstructing sufficient depth information to compromise target recognition models—such as face identification and authentication systems—by merely accessing their output and the corresponding RGB photo. Our key insight is that achieving successful attacks doesn’t necessitate restoring the precise ground-truth depth values; instead, it only requires recovering the essential features that are salient to the target model’s decision-making process. We evaluate DREAM’s effectiveness using four public 3D face datasets. Experimental results indicate that DREAM achieves a 94% success rate on face authentication models, even in cross-dataset testing. For face identification models, the success rate is 36%. Building upon DREAM, we further propose DREAM-3D, which leverages a 3D GAN to reconstruct depth images for deceiving 3D face recognition systems. Additionally, we evaluate DREAM-3D’s effectiveness on two datastes. Experimental results indicate that DREAM-3D achieves attack success rates exceeding 90% and approximately 50% against different models. Shizong Yan, Huixiang Wen, Shan Chang, Hongzi Zhu, Luo Zhou |
IEEE Internet Things J. | 2 |
| 2024 | DepthCloak: Projecting Optical Camouflage Patches for Erroneous Monocular Depth Estimation of VehiclesabstractAdhesive adversarial patches have been common used in attacks against the computer vision task of monocular depth estimation (MDE). Compared to physical patches permanently attached to target objects, optical projection patches show great flexibility and have gained wide research attention. However, applying digital patches for direct projection may lead to partial blurring or omission of details in the captured patches, attributed to high information density, surface depth discrepancies, and non-uniform pixel distribution. To address these challenges, in this work we introduce DepthCloak, an adversarial optical patch designed to interfere with the MDE of vehicles. To this end, we first simplify the patch to a gray pattern because the projected ''black-and-white light'' has strong robustness to ambient light. We propose a generative adversarial network (GAN) based approach to simulate projections and deduce a projectable list. Then, we employ neighborhood averaging to fill sparse depth values, compress all depth values into a reduced dynamic range via nonlinear mapping, and use these values to adjust the Gaussian blur radius as weight parameters, thereby simulating depth variation effects. Finally, by integrating Moiré pattern and applying style transfer techniques, we customize adversarial patches featuring regularly arranged characteristics. We deploy DepthCloak in real driving scenarios, and extensive experiments demonstrate that DepthCloak can achieve an attack success rate of over 80% in the physical world. Huixiang Wen, Shizong Yan, Shan Chang, Jie Xu 0061, Hongzi Zhu, Yanting Zhang 0001, Bo Li 0001 |
ACM Multimedia | 1 |
| 2024 | Fooling 3D Face Recognition with One Single 2D Imageabstract3D face recognition is subject to frequent spoofing attacks, in which 3D face presentation attack is one of the most notorious attacks. The attacker takes advantages of 3D scanning and printing techniques to generate masks of targets, which has found success in numerous real-life examples. The salient feature in such attacks is to obtain 3D face models through 3D scanning, though relatively more expensive and inconvenient when comparing with 2D photos. In this work, we propose a new method, DREAM, to recover 3D face models from single 2D image. Specifically, we adopt a black-box approach, which recovers 'sufficient' depths to defeat target recognition models (e.g., face identification and face authentication models) by accessing its output and the corresponding RGB photo. The key observation is that it is not necessary to restore the true value of depths, but only need to recover the essential features relevant to the target model. We used four public 3D face datasets to verify the effectiveness of DREAM. The experimental results show that DREAM can achieve a success rate of 94% on face authentication model, even in cross-dataset testing, and a success rate of 36% on face identification model. Shizong Yan, Huixiang Wen, Shan Chang, Hongzi Zhu, Luo Zhou |
ACM Multimedia | 2 |
| 2024 | OptiCloak: Blinding Vision-Based Autonomous Driving Systems Through Adversarial Optical ProjectionabstractStudies have proven that applying patch stickers generated through adversarial training to target objects can effectively deceive classifiers or target detectors. These ’Print-and-paste’ adversarial attacks however have three shortcomings. First, touching the target object physically is required, which may be infeasible in practice. Second, stickers might be taken as evidence to identify attackers. Third, the attack effect decreases significantly in poor light, especially at long distances. To overcome above limitations, we introduce OptiCloak, a car vanishing attack, which fools the Object Detector (OD) of a vision-based autonomous driving systems with transient projection pattern. We establish three digital-to-physical mapping models to compensate the distortions caused by perspective deformation, double image and partial light reflection in real-world. Furthermore, to avoid adversarial functionality degeneration caused by the loss of patch details in long-range attacks, we utilize MeanShift Filtering to constrain the ’resolution’ of pixels in a patch during training. We propose a gradient-free patch updating approach, which utilizes ZO-AdaMM to approximate gradients and model parameters through confidence scores of OD, making OptiCloak can work well in both white-box and black-box scenarios. We deploy OptiCloak in real-world driving scenarios, and the extensive experimental results demonstrate that OptiCloak achieves similar Attack Success Rates (ASRs) as printed patches in bright environments, while significantly improving the attack performance in gloomy environments. This effect is validated across all settings, including different angles, imaging devices, and film transparency rates. In black-box settings, the average ASR can reach 71%, with a maximum attack distance of approximately 10m. Huixiang Wen, Shan Chang, Luo Zhou, Wei Liu 0138, Hongzi Zhu |
IEEE Internet Things J. | 1 |
| 2023 | Light Projection-Based Physical-World Vanishing Attack Against Car DetectionabstractPhysical adversarial attacks directly apply adversarial perturbations to real-world objects. Perturbations usually are printed as patches and pasted on target objects. This requires attackers in the vicinity of targets, which may not be feasible in practice. In this paper, we propose a stealthy physical adversarial attack by taking advantage of the transient of light projection. The attacker utilizes a drone with a portable projector to project the adversarial light pattern on the rear windshield of a vehicle to obstruct the object detector (OD) in autonomous driving systems. This can lead to serious safety vulnerability. We train digital perturbations by back propagation on the OD in an iterative manner. Unfortunately, they do not work well in the form of light patterns due to distortion, double imaging and partial reflectance when projected as light pattern. Hence, we model the mapping from digital to light projections, and use the inverse of the mapping to compensate the projection distortion in each iteration. We employ four state-of-the-art ODs to demonstrate the effectiveness and robustness of our proposed attack. Huixiang Wen, Shan Chang, Luo Zhou |
ICASSP | 1 |