VLDB 2026 Research / reviewers in the wild / expert
Jiwei Tian
dblp:227/9574
· DBLP profile ↗
25ranked-venue papers
9as first author
19since 2021 · last 2026
0000-0002-1485-7465ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 4 first-author · 8 since 2021Computer networks · 8 · 3 first-author · 7 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Joint Hybrid Beamforming and Artificial Noise Design for Secure Multi-UAV ISAC Networks
Runze Dong, Buhong Wang, Cunqian Feng, Jiang Weng, Chen Han 0004, Jiwei Tian |
ICC | 6 |
| 2026 | UPGP:Backdoor defense via unlearning perturbation and orthogonality-constraint gradient projection
Jingtai Li, Xiujiu Yuan, Jiwei Tian, Shiwei Lu, Dengxiu Yu |
Pattern Recognit. | 3 |
| 2026 | MDA-SMuSha: An Efficient and Flexible Multi-Dimensional Data Aggregation Scheme for Privacy-Preservation in Smart GridsabstractIn smart grids, smart meters periodically collect users' fine-grained multi-dimensional energy data, which poses great concerns on users' privacy and security. Existing privacy preserving multi-dimensional aggregation schemes suffer from heavy computational burdens, especially for smart meters with limited computational resources. To address these limitations, in this paper we propose an efficient and flexible multi-dimensional data aggregation scheme called MDA-SMuSha, by which smart meters employ the Shamir's multi-secret sharing to generate a set of shared secrets, with the first one kept locally, while the remained ones are packaged and then uploaded to a control center via an aggregator. By the MDA-SMuSha scheme, aggregation results of smart meters' multi-dimensional energy data during multiple periods can be obtained, with only one time of Paillier encryption conducted on the smart meters. In addition, it allows the control center to send query requests flexibly, i.e., at a pre-specified frequency or whenever it wants to obtain statistical data of interests. Rigorous security analyses show that the MDA-SMuSha scheme satisfies security requirements of privacy-preservation, authenticity and data integrity as well as fault-tolerance. Both theoretical analyses and experiment results show that the MDA-SMuSha scheme outperforms state-of-the art methods in terms of computation costs, with comparable communication costs. Nengyu He, Xiaofang Xia, Xiangru Zhan, Jiangtao Cui, Jiwei Tian, Chi Xu 0001, Wei Liang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | ADMM-Based Adversarial False Data Injection Attacks Against Multi-Label Locational DetectionabstractWhile multi-label learning has shown excellent performance in False Data Injection Attack (FDIA) locational detection, it has also exposed some potential security risks and vulnerabilities. However, unlike the image domain, the vulnerabilities of multi-label learning in the field of power grid have just received attention and urgently need to be explored and addressed. In this paper, to achieve a better understanding for the security risks of deep learning-based multi-label FDIA detectors, we propose two Alternating Direction Method of Multipliers (ADMM) based adversarial attacks, which are applicable to two different scenarios. The proposed two ADMM-based attacks aim to reduce additional attack costs while seeking suitable adversarial perturbations, making the attacks more realistic and feasible. The experimental results verify the effectiveness of the proposed ADMM-based attacks, making noteworthy strides in fostering a profound comprehension of the vulnerabilities in the unique field of deep multi-label learning for power systems. Jiwei Tian, Chao Shen 0001, Chenhao Lin, Meng Zhang 0011, Xiaofang Xia, Chao Ren 0006, Peican Zhu, Chunming Wu 0001, Xiang Chen 0017 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Enhanced Cybersecurity Framework for Unmanned Aerial Systems: A Comprehensive STRIDE-Model Analysis and Emerging Defense StrategiesabstractRecent advancements in unmanned aerial vehicle (UAV) technology have facilitated its widespread adoption across a spectrum of sectors, such as commercial logistics, agricultural surveillance, industrial diagnostics, and military maneuvers. However, the widespread adoption has also engendered a burgeoning array of security concerns. Unmanned aerial systems (UAS) networks are characterized by high node mobility, unstable links, open communication environments, and limited platform resources, which in turn exhibit typical vulnerabilities in terms of cybersecurity. Most current studies on UAV cybersecurity issues tend to focus on individual UAVs, often neglecting the holistic cybersecurity of UAS. This paper outlines the composition of UAS network architecture. It summarizes the main cybersecurity challenges UAS faces within six categories—spoofing, tampering, information disclosure, denial of service (DoS), service refusal, and privilege escalation—based on the STRIDE threat model. Corresponding methods for risk mitigation and security protection strategies are proposed. Ultimately, the paper provides a perspective on the future development directions of UAS cybersecurity, aiming to offer a reference for addressing related issues in subsequent research and practice. Hailong Xi, Le Ru, Jiwei Tian, Shiguang Hu, Wenfei Wang, Xiaohui Luan |
IET Inf. Secur. | 3 |
| 2025 | Dynamic Quasi-Hyperbolic Momentum Iterative Attack With Small Perturbation for 4D-Flight Trajectory PredictionabstractWith the rapid growth of global air traffic, 4D-flight trajectory prediction (4D-FTP) using deep learning (DL) methods has become essential for applications, such as flight delay prediction, fuel consumption analysis, and traffic management. However, the adversarial attacks pose significant security threats to DL-based 4D-FTP systems reliant on automatic dependent surveillance-broadcast (ADS-B) sensors. Furthermore, existing vulnerabilities in time-series prediction (TSP) models for 4D-FTP remain underexplored due to the lack of effective and stealthy attack methods. To address this gap, we propose the dynamic quasi-hyperbolic momentum (QHM) iterative attack with small perturbation (DQM-Attack). This method leverages QHM and dynamic step sizes to optimize gradient utilization in 4D-FTP models. In addition, attack stealth is enhanced through the manifold smooth module (MSM) and sparse smooth reinforcement learning (SS-RL). Experimental results demonstrate that DQM-Attack effectively disrupts predictions with minimal perturbations across four state-of-the-art TSP models. This study appears to be the first to address stealthy adversarial attacks on 4D-FTP systems, revealing a critical security vulnerability in air traffic management (ATM). Zhengyang Zhao 0002, Buhong Wang, Jiwei Tian, Ruochen Dong, Peican Zhu |
IEEE Internet Things J. | 4 |
| 2025 | EVADE: Targeted Adversarial False Data Injection Attacks for State Estimation in Smart GridabstractAlthough conventional false data injection attacks can circumvent the detection of bad data detection (BDD) in sustainable power grid cyber physical systems, they are easily detected by well-trained deep learning-based detectors. Still, state estimation models with deep leaning-based detectors are not secure due to the vulnerabilities and fragility of deep learning models. Using the related laws of conventional false data injection attacks and adversarial sample attacks, this paper proposes the targEted adVersarial fAlse Data injEction (EVADE) strategy to explore targeted adversarial false data injection attacks for state estimation in Smart Grid. The proposed EVADE attack strategy selects key state variables based on adversarial saliency maps to improve the attack efficiency and perturbs as few state variables as possible to reduce the attack cost. In this way, the EVADE attack strategy can bypass the detection of BDD and neural attack detection (NAD) methods (that is, maintaining deep stealthy) with a high success rate and achieve the attack target simultaneously. Experimental results demonstrate the effectiveness of the proposed strategy, posing serious and pressing concerns for sustainable cyber physical power system security. Jiwei Tian, Chao Shen 0001, Buhong Wang, Chao Ren 0006, Xiaofang Xia, Runze Dong, Tianhao Cheng |
IEEE Trans. Sustain. Comput. | 1 |
| 2024 | A General Black-box Adversarial Attack on Graph-based Fake News Detectors
Peican Zhu, Zechen Pan, Yang Liu 0144, Jiwei Tian, Keke Tang, Zhen Wang 0004 |
IJCAI | 4 |
| 2024 | Security Enhancement of UAV Swarm Empowered Downlink Transmission with Integrated Sensing and CommunicationabstractAs a promising technique for the next generation communication network, integrated sensing and communication (ISAC) has attracted incremental research attentions due to its capabilities in spectrum sharing, cost saving, and data collecting. In this paper we utilize unmanned aerial vehicle (UAV) swarm to perform downlink ISAC transmission to serve multiple terrestrial legitimate users and sensing targets. To accommodate more practical application scenarios, we assume that there are also multiple malicious eavesdroppers in the network attempting to eavesdrop on the confidential signal. In order to enhance the security of the downlink transmission while maintaining sufficient sensing performance, we propose a joint optimization of the centralized trajectory of UAV swarm, the transmit beamforming on each UAV, and the ISAC schedule, which is eventually formulated as an average secrecy rate (ASR) maximization problem. A deep reinforcement learning (DRL) based algorithm is developed to solve the considered optimization problem and its effectiveness is validated via experimental simulations, which also proves its superiority over benchmark methods. Runze Dong, Buhong Wang, Jiang Weng, Kunrui Cao, Jiwei Tian, Tianhao Cheng |
TrustCom | 5 |
| 2024 | TTSAD: TCN-Transformer-SVDD Model for Anomaly Detection in air traffic ADS-B data
Buhong Wang, Jiwei Tian |
Comput. Secur. | 3 |
| 2024 | ADS-Bpois: Poisoning Attacks Against Deep-Learning-Based Air Traffic ADS-B Unsupervised Anomaly Detection ModelsabstractAs a core technology of the new generation air traffic management (ATM) system, automatic dependent surveillance-broadcast (ADS-B) becomes increasingly crucial and its anomaly detection is important for safeguarding flight safety and enhancing the efficiency of air traffic. Deep learning has been used for ADS-B flight trajectory prediction and anomaly detection, but it is known for its susceptibility to poisoning attacks when updated to adapt feature distributions from new ADS-B flight data. In the study, we propose time neighborhood interpolation combined back gradient descent poisoning attacks which not only make full use of the gradient information of ADS-B anomaly detection models but also fully consider temporal correlations and maneuvering characteristics of ADS-B data during the aircraft’s take-off, climb, turning, and descent phase. The experimental results show that our proposed poisoning attack method can successfully poison the four state-of-the-art deep learning-based ADS-B time series unsupervised anomaly detection models. What is more, the experimental results also show that our method is superior to the other poisoning attack methods in terms of success rate and stealthiness. To the fullest extent of our knowledge, we exhibit, for the first time, the susceptibility of ADS-B time series unsupervised anomaly detection models to poisoning attacks, which is vital in safety-critical and cost-critical air traffic industry. For ease of understanding, our proposed poisoning attack method is referred to as ADS-Bpois. Buhong Wang, Jiwei Tian |
IEEE Internet Things J. | 3 |
| 2024 | LESSON: Multi-Label Adversarial False Data Injection Attack for Deep Learning Locational DetectionabstractDeep learning methods can not only detect false data injection attacks (FDIA) but also locate attacks of FDIA. Although adversarial false data injection attacks (AFDIA) based on deep learning vulnerabilities have been studied in the field of single-label FDIA detection, the adversarial attack and defense against multi-label FDIA locational detection are still not involved. To bridge this gap, this paper first explores the multi-label adversarial example attacks against multi-label FDIA locational detectors and proposes a general multi-label adversarial attack framework, namely muLti-labEl adverSarial falSe data injectiON attack (LESSON). The proposed LESSON attack framework includes three key designs, namely Perturbing State Variables, Tailored Loss Function Design, and Change of Variables, which can help find suitable multi-label adversarial perturbations within the physical constraints to circumvent both Bad Data Detection (BDD) and Neural Attack Location (NAL). Four typical LESSON attacks based on the proposed framework and two dimensions of attack objectives are examined, and the experimental results demonstrate the effectiveness of the proposed attack framework, posing serious and pressing security concerns in smart grids. Jiwei Tian, Chao Shen 0001, Buhong Wang, Xiaofang Xia, Meng Zhang 0011, Chenhao Lin, Qian Li 0024 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2022 | Datadriven false data injection attacks against cyber-physical power systems
Jiwei Tian, Buhong Wang, Charalambos Konstantinou |
Comput. Secur. | 1 |
| 2022 | Enhancing Physical-Layer Security for IoT With Nonorthogonal Multiple Access Assisted Semi-Grant-Free TransmissionabstractNonorthogonal multiple access (NOMA) assisted semi-grant-free transmission admits grant-free users to access the channels otherwise solely occupied by grant-based users, and has been recently attracting considerable attention in terms of accommodating massive connectivity and reducing access delay in Internet of Things (IoT). In this work, we investigate the security of semi-grant-free NOMA transmission in the presence of passive and active eavesdropping attacks. In particular, for the scenario-I with strong grant-based user and weak grant-free users, the scenario-I-based maximal user scheduling (IbMUS) and scenario-I-based optimal user scheduling (IbOUS) schemes are proposed to combat the passive and active eavesdropping, respectively. For the scenario-II with weak grant-based user and strong grant-free users, two parallel schemes, namely, the scenario-II-based maximal user scheduling (IIbMUS) and scenario-II-based optimal user scheduling (IIbOUS) schemes, are proposed to combat the passive and active eavesdropping, respectively. These proposed schemes enhance the security by scheduling a grant-free user with maximal main channel capacity/maximal secrecy capacity to access the NOMA channel on the premise of ensuring the grant-based user’s Quality of Service. Based on these proposed schemes, the exact secrecy outage probability (SOP) are analyzed to evaluate the system performance. The simulation results validates the theoretic analysis and the superiority of the proposed schemes. The IbOUS and IIbOUS schemes can achieve better performance than the IbMUS and IIbMUS schemes owing to the use of active eavesdropper’s channel state information (CSI). The SOP achieved by the proposed schemes can be further improved with the increasing number of grant-free users and decreasing target rate (or target secrecy rate). Kunrui Cao, Haiyang Ding, Buhong Wang, Lu Lv 0001, Jiwei Tian, Qingmei Wei, Fengkui Gong |
IEEE Internet Things J. | 5 |
| 2022 | Adversarial Attacks and Defenses for Deep-Learning-Based Unmanned Aerial VehiclesabstractThe introduction of deep learning (DL) technology can improve the performance of cyber–physical systems (CPSs) in many ways. However, this also brings new security issues. To tackle these challenges, this article explores the vulnerabilities of DL-based unmanned aerial vehicles (UAVs), which are typical CPSs. Although many research works have been reported previously on adversarial attacks of DL models, only few of them are concerned about safety-critical CPSs, especially regression models in such systems. In this article, we analyze the problem of adversarial attacks against DL-based UAVs and propose two adversarial attack methods against regression models in UAVs. The experiments demonstrate that the proposed nontargeted and targeted attack methods both can craft imperceptible adversarial images and pose a considerable threat to the navigation and control of UAVs. To address this problem, adversarial training and defensive distillation methods are further investigated and evaluated, increasing the robustness of DL models in UAVs. To our knowledge, this is the first study on adversarial attacks and defenses against DL-based UAVs, which calls for more attention to the security and safety of such safety-critical applications. Jiwei Tian, Buhong Wang, Rongxiao Guo, Zhen Wang 0020, Kunrui Cao |
IEEE Internet Things J. | 1 |
| 2022 | Exploring Targeted and Stealthy False Data Injection Attacks via Adversarial Machine LearningabstractState estimation methods used in cyber–physical systems (CPSs), such as smart grid, are vulnerable to false data injection attacks (FDIAs). Although substantial deep learning methods have been proposed to detect such attacks, deep neural networks (DNNs) are highly susceptible to adversarial attacks, which modify input of DNNs with unnoticeable but malicious perturbations. This article proposes a method to explore targeted and stealthy FDIAs via adversarial machine learning. We pose FDIAs as sparse optimization problems to achieve initial attack objectives and remain stealthy during attacks. We propose a parallel optimization algorithm to efficiently solve the problems and explore additional sparse-state attacks. The experimental results show that for IEEE 14-bus and 118-bus systems, the success rate of two-state sparse attacks with small-scale targets is as high as 80%. In addition, the attack success rate can continue to increase as the number of attack states increases. The proposed attacks demonstrate that attackers can implement attacks that can bypass both bad data detectors and neural network detectors while keeping the initial attack objectives unchanged, which is a critical and urgent security threat in CPS. Jiwei Tian, Buhong Wang, Zhen Wang 0020, Mete Ozay |
IEEE Internet Things J. | 1 |
| 2022 | Joint Adversarial Example and False Data Injection Attacks for State Estimation in Power SystemsabstractAlthough state estimation using a bad data detector (BDD) is a key procedure employed in power systems, the detector is vulnerable to false data injection attacks (FDIAs). Substantial deep learning methods have been proposed to detect such attacks. However, deep neural networks are susceptible to adversarial attacks or adversarial examples, where slight changes in inputs may lead to sharp changes in the corresponding outputs in even well-trained networks. This article introduces the joint adversarial example and FDIAs (AFDIAs) to explore various attack scenarios for state estimation in power systems. Considering that perturbations added directly to measurements are likely to be detected by BDDs, our proposed method of adding perturbations to state variables can guarantee that the attack is stealthy to BDDs. Then, malicious data that are stealthy to both BDDs and deep learning-based detectors can be generated. Theoretical and experimental results show that our proposed state-perturbation-based AFDIA method (S-AFDIA) can carry out attacks stealthy to both conventional BDDs and deep learning-based detectors, while our proposed measurement-perturbation-based adversarial FDIA method (M-AFDIA) succeeds if only deep learning-based detectors are used. The comparative experiments show that our proposed methods provide better performance than state-of-the-art methods. Besides, the ultimate effect of attacks can also be optimized using the proposed joint attack methods. Jiwei Tian, Buhong Wang, Zhen Wang 0020, Kunrui Cao, Mete Ozay |
IEEE Trans. Cybern. | 1 |
| 2021 | ADS-B anomaly data detection model based on VAE-SVDD
Buhong Wang, Tengyao Li, Jiwei Tian |
Comput. Secur. | 4 |
| 2021 | TOTAL: Optimal Protection Strategy Against Perfect and Imperfect False Data Injection Attacks on Power Grid Cyber-Physical SystemsabstractThis article explores the problem of protection against false data injection attacks (FDIAs) on the power system state estimation. Although many research works have been reported previously to solve the same problem, yet most of them are only for perfect FDIAs. To address the problem reasonably, all related factors influencing the success probability and corresponding attack impact of imperfect FDIAs should also be considered. Based on such considerations, a topology, parameter, accuracy, level (TOTAL) protection strategy considering all corresponding factors is proposed. The TOTAL protection strategy minimizes the attack impact of typical imperfect FDIAs (single measurement attacks) while defending against typical perfect FDIAs (single-state variable attacks). Depending on whether the protection scheme contains phasor measurement units (PMUs), we formulate the meter selection as a linear binary programming or integer programming problem, which can be solved by suitable solvers. The proposed strategy is compared with the existing methods in the literature and evaluated using the standard IEEE test cases. Jiwei Tian, Buhong Wang, Tengyao Li, Fute Shang, Kunrui Cao, Rongxiao Guo |
IEEE Internet Things J. | 1 |
| 2020 | Dynamic temporal ADS-B data attack detection based on sHDP-HMM
Tengyao Li, Buhong Wang, Fute Shang, Jiwei Tian, Kunrui Cao |
Comput. Secur. | 4 |
| 2020 | Threat model and construction strategy on ADS-B attack dataabstractWith the fast increase in airspace density and high‐safety requirements on aviation, automatic dependent surveillance‐broadcast (ADS‐B) is regarded as the primary method in the next generation air traffic surveillance. The ADS‐B data is broadcast with the plain text without sufficient security measures, which results in various attack patterns emerging. However, in terms of constrictions with laws and regulations, ADS‐B attack data is difficult to collect and obtain, which is essential for data security research studies. To deal with the absence of ADS‐B attack data in real environments, the construction strategy on ADS‐B attack data is proposed. For construction fidelity, ADS‐B data features are analysed and modelled at first. Then the popular and classical attack patterns on ADS‐B data are analysed to establish threat models. Based on the original ADS‐B data sets, the construction strategy is designed to focus on attack target selection, key parameter determination, and mixture strategy, reproducing the attack intentions. The constructed ADS‐B attack data sets are hybrid data sets including the normal and attack data. By simulation analyses, the feasibility and availability of the construction strategy were validated with real ADS‐B data. Tengyao Li, Buhong Wang, Fute Shang, Jiwei Tian, Kunrui Cao |
IET Inf. Secur. | 4 |
| 2020 | On the Security Enhancement of Uplink NOMA Systems With Jammer SelectionabstractWe investigate physical layer security of an uplink NOMA system consisting of one base station, multiple users and one eavesdropper. During each uplink transmission, two users are paired to perform NOMA and another user is opportunistically selected from the remaining idle users to act as a friendly jammer to emit artificial noise for confusing the eavesdropper. To enhance the transmission security for the system, we propose two friendly jammer selection aided uplink NOMA transmission schemes, namely random jammer selection aided uplink NOMA transmission (RJS-UNT) scheme without knowing the eavesdropper's channel state information (CSI), and optimal jammer selection aided uplink NOMA transmission (OJS-UNT) scheme where the eavesdropper's CSI is available. For comparison purpose, a non-jammer selection aided uplink NOMA transmission (NJS-UNT) scheme is also considered. Analytical closed-form expressions for the secrecy outage probability (SOP) are derived to evaluate the secrecy performance achieved by the proposed schemes. Also, the asymptotic SOPs are provided to obtain further insights. The analysis and simulation results indicate that the schemes converge to SOP floors with the increasing SNR, while the floors achieved by the RJS-UNT and OJS-UNT schemes are significantly lower than that achieved by the NJS-UNT scheme, showing the security advantage of the proposed schemes. Kunrui Cao, Buhong Wang, Haiyang Ding, Lu Lv 0001, Jiwei Tian, Fengkui Gong |
IEEE Trans. Commun. | 5 |
| 2020 | Secure Transmission Designs for NOMA Systems Against Internal and External EavesdroppingabstractThe key idea of non-orthogonal multiple access (NOMA) is to serve multiple users in the same resource block to improve the spectral efficiency. Whereas due to the resource sharing, a security flaw of NOMA emerges in the presence of internal untrusted users, especially untrusted near users who are closer to the base station and can easily access the confidential information for paired far users. To mitigate the flaw, in this paper, we investigate the reliable and secure transmission of NOMA systems with untrusted near users, and propose joint beamforming and power allocation (JBP) scheme for the scenario. Meanwhile, from security point of view, we extend to a worse-case scenario where both untrusted near users and external eavesdroppers exist, and propose joint artificial noise aided beamforming and power allocation (JANBP) scheme to achieve a reliable and secure transmission for the scenario. The exact and asymptotic closed-form expressions of secrecy outage probability (SOP) for the two scenarios are derived to evaluate the secrecy performance achieved by the proposed schemes, respectively. The analysis and simulation results show the superiority of the proposed JBP and JANBP schemes in terms of combating internal and external eavesdropping, and also indicate the two schemes can achieve the same SOP at high SNR. Kunrui Cao, Buhong Wang, Haiyang Ding, Tengyao Li, Jiwei Tian, Fengkui Gong |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2019 | Online sequential attack detection for ADS-B data based on hierarchical temporal memory
Tengyao Li, Buhong Wang, Fute Shang, Jiwei Tian, Kunrui Cao |
Comput. Secur. | 4 |
| 2018 | Data-Driven and Low-Sparsity False Data Injection Attacks in Smart GridabstractRecent researches on data-driven and low-sparsity data injection attacks have been presented, respectively. To combine the two main goals (data-driven and low-sparsity) of research, this paper presents a data-driven and low-sparsity false data injection attack strategy. The proposed attacking strategy (EID: Eliminate-Infer-Determine) is divided into three stages. In the first step, the intercepted data is preprocessed by sparse optimization techniques to eliminate the outliers. The recovered data is then exploited to learn about the system matrix based on the parallel factorization algorithm in the second step. In the third step, the approximated system matrix is applied for the design of sparse attack vector based on the convex optimization. The simulation results show that the EID attack strategy achieves a better performance than the improved ICA-based attack strategy in constructing perfect sparse attack vectors. What is more, data-driven implementation of the proposed strategy is also presented which ensures attack performance even without the prior information of the system. Jiwei Tian, Buhong Wang |
Secur. Commun. Networks | 1 |