VLDB 2026 Research / reviewers in the wild / expert
Yucheng Fu
dblp:227/2135
· DBLP profile ↗
5ranked-venue papers
2as first author
5since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On Approximating the f-Divergence Between Two Ising ModelsabstractThe $f$-divergence is a fundamental notion that measures the difference between two distributions. In this paper, we study the problem of approximating the $f$-divergence between two Ising models, which is a generalization of recent work on approximating the TV-distance. Given two Ising models $ν$ and $μ$, which are specified by their interaction matrices and external fields, the problem is to approximate the $f$-divergence $D_f(ν\,\|\,μ)$ within an arbitrary relative error $\mathrm{e}^{\pm \varepsilon}$. For $χ^α$-divergence with a constant integer $α$, we establish both algorithmic and hardness results. The algorithm works in a parameter regime that matches the hardness result. Our algorithm can be extended to other $f$-divergences such as $α$-divergence, Kullback-Leibler divergence, Rényi divergence, Jensen-Shannon divergence, and squared Hellinger distance. Weiming Feng 0001, Yucheng Fu |
ITCS | 2 |
| 2026 | Enhancing the Security of Large Character Set CAPTCHAs Using Transferable Adversarial ExamplesabstractThe large character set CAPTCHA is an important extension of the traditional text-based CAPTCHA with larger alphabet languages to defend against automated attack programs. However, the state-of-the-art deep learning attacks have cracked such CAPTCHA. Existing defenses against such threats increase the complexity of CAPTCHA, thus decreasing usability. We propose ACG (Adversarial Large Character Set CAPTCHA Generation), a framework with two modules: aFine-grained Generation Module, combining three novel strategies to prevent attackers from recognizing characters, and anEnsemble Generation Moduleto generate global perturbations in CAPTCHAs. It not only strengthens defense against recognition attacks but also improves robustness against diverse detection architectures through adversarial perturbations. Additionally, we develop a toolkit, Adv-Eval, consisting of CAPTCHA datasets from 10 of the most popular Chinese CAPTCHA schemes and benchmarking various attacks. We conduct extensive experiments using Adv-Eval to demonstrate ACG's efficacy, especially manifesting a significant decrease in the average success rate of diverse attacks from 51.52% to 2.56%. To the best of our knowledge, ACG is the first framework to defend large character set CAPTCHAs against detection attacks using transferable adversarial examples. Guoheng Sun, Yucheng Fu, Juntian Huang, Ruimei Zhang, Haizhou Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Benchmarking Secure Sampling Protocols for Differential PrivacyabstractDifferential privacy (DP) is widely employed to provide privacy protection for individuals by limiting information leakage from the aggregated data. Two well-known models of DP are the central model and the local model. The former requires a trustworthy server for data aggregation, while the latter requires individuals to add noise, significantly decreasing the utility of aggregated results. Recently, many studies have proposed to achieve DP with Secure Multi-party Computation (MPC) in distributed settings, namely, the distributed model, which has utility comparable to central model while, under specific security assumptions, preventing parties from obtaining others' information. One challenge of realizing DP in distributed model is efficiently sampling noise with MPC. Although many secure sampling methods have been proposed, they have different security assumptions and isolated theoretical analyses. There is a lack of experimental evaluations to measure and compare their performances. We fill this gap by benchmarking existing sampling protocols in MPC and performing comprehensive measurements of their efficiency. First, we present a taxonomy of the underlying techniques of these sampling protocols. Second, we extend widely used distributed noise generation protocols to be resilient against Byzantine attackers. Third, we implement discrete sampling protocols and align their security settings for a fair comparison. We then conduct an extensive evaluation to study their efficiency and utility. Our experiments show that (1) malicious protocols based on a technique called bitwise sampling are more efficient than other methods, and using an oblivious data structure can reduce the circuit size in high-security regimes, (2) the cost of realizing malicious security is high, under the assumption of semi-honest, using a method named distributed noise generation is much more efficient, and (3) the utility loss caused by sampling noise in MPC is small, which to a certain extent eliminates utility concerns when using the DDP protocol in practice. We open-source our code at https://github.com/yuchengxj/Secure-sampling-benchmark. Yucheng Fu, Tianhao Wang 0001 |
CCS | 1 |
| 2023 | Fighting Attacks on Large Character Set CAPTCHAs Using Transferable Adversarial ExamplesabstractOver a long period, large character set CAPTCHAs are widely used to defend against automated attack programs on the Internet. However, with the development of deep learning techniques, some attacks for large character set CAPTCHAs have been proposed, proving that they are no longer secure. To defend against black-box attacks on these CAPTCHAs, we propose a novel defense method based on transferable adversarial example techniques. On the one hand, we defend against character recognition attacks by adding adversarial perturbations to the characters of CAPTCHAs combining three strategies: Gradient-based Attacks, Input Transformations and Attention Mechanism. On the other hand, we defend against character detection attacks by leveraging an ensemble method to generate adversarial perturbations on the background of CAPTCHAs. To the best of our knowledge, this is the first study to improve the security of large character set CAPTCHAs against black-box attacks based on transferable adversarial example techniques. Using the eight most popular Chinese CAPTCHA schemes as examples, we conduct comprehensive experiments. Results show that our method improves the security of large character set CAPTCHAs by making the average success rate of black-box attacks significantly drop from 53.33% to 3.49%. Overall, our method can be helpful to the design of more secure large character set CAPTCHAs. Yucheng Fu, Guoheng Sun, Juntian Huang, Haizhou Wang 0001 |
IJCNN | 1 |
| 2022 | Latent Space Simulation for Carbon Capture Design OptimizationabstractThe CO2 capture efficiency in solvent-based carbon capture systems (CCSs) critically depends on the gas-solvent interfacial area (IA), making maximization of IA a foundational challenge in CCS design. While the IA associated with a particular CCS design can be estimated via a computational fluid dynamics (CFD) simulation, using CFD to derive the IAs associated with numerous CCS designs is prohibitively costly. Fortunately, previous works such as Deep Fluids (DF) (Kim et al., 2019) show that large simulation speedups are achievable by replacing CFD simulators with neural network (NN) surrogates that faithfully mimic the CFD simulation process. This raises the possibility of a fast, accurate replacement for a CFD simulator and therefore efficient approximation of the IAs required by CCS design optimization. Thus, here, we build on the DF approach to develop surrogates that can successfully be applied to our complex carbon-capture CFD simulations. Our optimized DF-style surrogates produce large speedups (4000x) while obtaining IA relative errors as low as 4% on unseen CCS configurations that lie within the range of training configurations. This hints at the promise of NN surrogates for our CCS design optimization problem. Nonetheless, DF has inherent limitations with respect to CCS design (e.g., limited transferability of trained models to new CCS packings). We conclude with ideas to address these challenges. Brian R. Bartoldson, Yucheng Fu, David P. Widemann, Sam Nguyen, Zhijie Xu, Brenda Ng |
AAAI | 3 |