VLDB 2026 Research / reviewers in the wild / expert
Yixiao Xu
dblp:231/1772
· DBLP profile ↗
16ranked-venue papers
9as first author
15since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 3 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 4 first-author · 5 since 2021Security and privacy · 3 · 2 first-author · 2 since 2021Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LoopLLM: Transferable Energy-Latency Attacks in LLMs via Repetitive GenerationabstractAs large language models (LLMs) scale, their inference incurs substantial computational resources, exposing them to energy-latency attacks, where crafted prompts induce high energy and latency cost. Existing attack methods aim to prolong output by delaying the generation of termination symbols. However, as the output grows longer, controlling the termination symbols through input becomes difficult, making these methods less effective. Therefore, we propose LoopLLM, an energy-latency attack framework based on the observation that repetitive generation can trigger low-entropy decoding loops, reliably compelling LLMs to generate until their output limits. LoopLLM introduces (1) a repetition-inducing prompt optimization that exploits autoregressive vulnerabilities to induce repetitive generation, and (2) a token-aligned ensemble optimization that aggregates gradients to improve cross-model transferability. Extensive experiments on 12 open-source and 2 commercial LLMs show that LoopLLM significantly outperforms existing methods, achieving over 90% of the maximum output length, compared to 20% for baselines, and improving transferability by around 40% to DeepSeek-V3 and Gemini 2.5 Flash. Yixiao Xu, Kangyi Ding, Bangzhou Xin, Jia-Li Yin |
AAAI | 4 |
| 2026 | AT-Field: Rethinking the Games in Adversarial TrainingabstractAdversarial training is often modeled as a two-player zero-sum game, relying on strong assumptions that limit its practical guidance. In this paper, we instead analyze the interactions between training samples and show that even the fundamental objective—minimizing training loss—may not converge. To address this, we propose AT-Field, an adversarial training framework guided by sample-wise game-theoretic relationships. Specifically, we prove that training samples across different batches can form a none-potential game, where gradient descent induces cyclic behaviors, preventing convergence. By strategically searching and grouping these samples within the same batch, AT-Field transforms none-potential games into exact potential games, which are more effectively optimized using gradient-based methods. Experiments demonstrate that AT-Field integrates seamlessly with existing adversarial training techniques, enhancing both accuracy and robustness. Yixiao Xu, Mohan Li, Zhijie Shen, Yuan Liu 0002, Zhihong Tian 0001 |
AAAI | 1 |
| 2026 | ECLIPSE: Continuous Alpha Field Modulation for Zero-Shot Educational Facial Expression Recognition
Yixiao Xu, Yulian Sheng, Junxuan Bai, Feng Zhou 0007, Ju Dai, JunJun Pan |
ICIC (19) | 1 |
| 2026 | BDpackets: A Clean-label Backdoor Attack on Network Traffic Classifiers via Feature Fusion
Mengxia Zhang, Yixiao Xu, Mohan Li, Yanbin Sun, Zhihong Tian 0001 |
INFOCOM | 2 |
| 2025 | gFlow: Distributed Real-Time Reverse Remote Rendering System Model
Yixiao Xu, Wanzhao Xu, Yicheng Gu, Yun Wang 0039, Jiangyuan Ma, Zhengwei Qi |
MMM (2) | 1 |
| 2025 | Effectively Virtual Page Prefetching via Spatial-Temporal Patterns for Memory-intensive Cloud ApplicationsabstractIn today's data-driven era, the explosive growth of global data volume has led to an increasing consumption of computing and storage resources. Effective management of virtual machines (VMs) memory usage is critical for cloud vendors to optimize system performance and resource utilization. Existing memory prefetching methods often slow down system performance, creating a difficult balance between maintaining service quality and optimizing resource use. For instance, Leap, which primarily utilizes address information, performs poorly in VM environments. The main issue is the performance drop caused by the reuse of memory resources in virtualized environments, a common situation in public clouds. Yun Wang 0039, Tianmai Deng, Ben Luo, Yibin Shen, Zhixiang Wei, Yixiao Xu, Minglang Huang, Zhengwei Qi |
PPoPP | 7 |
| 2025 | Query-Efficient Model Inversion Attacks: An Information Flow ViewabstractModel Inversion Attacks (MIAs) pose a certain threat to the data privacy of learning-based systems, as they enable adversaries to reconstruct identifiable features of the training distribution with only query access to the victim model. In the context of deep learning, the primary challenges associated with MIAs are suboptimal attack success rates and the corresponding high computational costs. Prior efforts assumed that the expansive search space caused these limitations, employing generative models to constrain the dimensions of the search space. Despite the initial success of these generative-based solutions, recent experiments have cast doubt on this fundamental assumption, leaving two open questions about the influential factors determining MIA performance and how to manipulate these factors to improve MIAs. To answer these questions, we reframe MIAs from the perspective of information flow. This new formulation allows us to establish a lower bound for the error probability of MIAs, determined by two critical factors: (1) the size of the search space and (2) the mutual information between input and output random variables. Through a detailed analysis of generative-based MIAs within this theoretical framework, we uncover a trade-off between the size of the search space and the generation capability of generative models. Based on the theoretical conclusions, we introduce the Query-Efficient Model Inversion Approach (QE-MIA). By strategically selecting an appropriate search space and introducing additional mutual information, QE-MIA achieves a reduction of$60\%\sim 70\%$in query overhead while concurrently enhancing the attack success rate by$5\%\sim 25\%$. Yixiao Xu, Binxing Fang, Mohan Li, Xiaolei Liu 0001, Zhihong Tian 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Neural Honeypoint: An Active Defense Framework Against Model Inversion AttacksabstractLearning-based systems have been proved to be vulnerable against model inversion attacks (MIAs), where attackers steal private information of training data by querying the target model using synthetic samples. To alleviate the urgent threat introduced by MIAs, existing advancements are proposed to increase the attack overhead by limiting the information available. Although these methods successfully reduced the attack success rate (ASR) for a one-time inversion attempt, they usually compromise the usability of the protected model. More importantly, existing MIA defense methods fail to capture attack attempts, which can lead to persistent threats to data privacy. To bridge this gap, we propose Neural Honeypoint, an active defense framework against MIAs. The key insight is that MIA attackers will make a series of forward steps in the feature space while benign users will not. Motivated by the observation, defenders can deploy active defense devices (honeypoints) on critical paths to capture attack behaviors. Specifically, Neural Honeypoint first models the attackers' capabilities from the frequency domain and designs specialized honeypoints for protected classes in the training dataset. Subsequently, it deploys these honeypoints into the protected model via backdoor-like model fine-tuning. Then, defenders can distinguish model inversion examples by comparing the similarity of input features with deployed honeypoints. Experiments show that Neural Honeypoint reduces the ASRs of advanced MIAs to 0%~2%. Furthermore, it can effectively capture inversion queries, which helps defenders to detect and block attacks in time. Yixiao Xu, Mohan Li, Binxing Fang, Yuan Liu 0002, Zhihong Tian 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 1 |
| 2024 | LT-Defense: Searching-free Backdoor Defense via Exploiting the Long-tailed EffectabstractLanguage models have shown vulnerability against backdoor attacks, threatening the security of services based on them. To mitigate the threat, existing solutions attempted to search for backdoor triggers, which can be time-consuming when handling a large search space. Looking into the attack process, we observe that poisoned data will create a long-tailed effect in the victim model, causing the decision boundary to shift towards the attack targets. Inspired by this observation, we introduce LT-Defense, the first searching-free backdoor defense via exploiting the long-tailed effect. Specifically, LT-Defense employs a small set of clean examples and two metrics to distinguish backdoor-related features in the target model. Upon detecting a backdoor model, LT-Defense additionally provides test-time backdoor freezing and attack target prediction. Extensive experiments demonstrate the effectiveness of LT-Defense in both detection accuracy and efficiency, e.g., in task-agnostic scenarios, LT-Defense achieves 98% accuracy across 1440 models with less than 1% of the time cost of state-of-the-art solutions. Yixiao Xu, Binxing Fang, Mohan Li, Keke Tang, Zhihong Tian 0001 |
NeurIPS | 1 |
| 2023 | Sparse Black-Box Inversion Attack with Limited InformationabstractExisting black-box model inversion attacks mainly focus on training and attacking surrogate models. However, due to the deployment process of face recognition models, training surrogate models becomes extremely difficult in practice. At the same time, query-based black-box inversion attacks still suffer from low image quality and high computational costs. To bridge these gaps, in this paper, we propose BMI-S, a sparse black-box inversion attack against face recognition models. BMI-S first introduces evolution strategies to perform efficient black-box gradient estimation and achieve query-based attacks. Meanwhile, BMI-S performs sparse attacks on the key styles that contribute most to the face recognition process. By only optimizing key style control vectors, BMI-S further narrows the dimensions of the search space and accelerates the inversion attacks. Yixiao Xu, Xiaolei Liu 0001, Bangzhou Xin |
ICASSP | 1 |
| 2023 | Dissecting Scale-Out Applications Performance on Diverse TLB Designs (S)abstractScale-out applications, such as various big data systems and memory computing programs comprise an important software stack in clouds.Such applications usually have large memory data footprint as well as code sizes, thus stressing the CPU's TLB efficiency.In this paper, we experimentally evaluate how various TLB design choices in modern off-the-shelf x86 CPUs impact the performance of scale-out applications.The findings aim to guide the partitioning schemes and capacity planning of TLBs, and software-hardware co-design for emerging applications. Tianmai Deng, Yixiao Xu, Zhengwei Qi |
SEKE | 2 |
| 2023 | Efficient intrusion detection toward IoT networks using cloud-edge collaboration
Yixiao Xu, Bangzhou Xin, Weizhe Zhang |
Comput. Networks | 3 |
| 2023 | Optimum: Runtime optimization for multiple mixed model deployment deep learning inference
Kaicheng Guo, Yixiao Xu, Zhengwei Qi, Haibing Guan |
J. Syst. Archit. | 2 |
| 2022 | Sparse Adversarial Attack For Video Via Gradient-Based Keyframe SelectionabstractVideos have a higher dimensionality compared with images, making adversarial video attacks more challenging. We propose a gradient-based method for self-adaptive white-box video keyframe selection and video adversarial example generation, taking advantage of that perturbations are transferable between video frames. More specifically, a gradient-based method is proposed to determine different video frames’ contribution to classification results. Based on the weights of different frames and the given boundary values, the proposed method adaptively selects a subset of frames as keyframes for perturbation. Experimental results of attacking two widely used video classification models on UCF-101 and HMDB-51 datasets show that the proposed method effectively improves the generation efficiency as well as the steganography of adversarial video examples, leading to a reduction of more than 21% of the required number of iterations and more than 25% of the average perturbation size for the untargeted attack. Yixiao Xu, Xiaolei Liu 0001, Mingyong Yin, Kangyi Ding |
ICASSP | 1 |
| 2022 | An Automated Multi-Tab Website Fingerprinting AttackabstractIn Website Fingerprinting (WF) attack, a local passive eavesdropper utilizes network flow information to identify which web pages a user is browsing. Previous researchers have demonstrated the feasibility and effectiveness of WF attacks under a strong Single Page Assumption: the network flow extracted by the adversary belongs to a single web page. In reality, the assumption may not hold because users tend to open multiple tabs simultaneously (or within a short period of time) so that their network traffic is mixed. In this article, we propose an automated multi-tab Website Fingerprinting attack that is able to accurately classify websites regardless of the number of simultaneously opened pages. Our design is powered by two innovative designs. First, we develop a split point classification method to dynamically identify the split point between the first page and its subsequent pages. As a result, the network traffic before the split point is solely generated for the first page. Then, we propose a new chunk-based WF classifier to infer the websites based on the initial chunk of clean traffic. For both classifiers, we apply automated feature selection to select a concise yet representative feature set. We implement a prototype of our design and perform extensive evaluations using SSH and Tor-based datasets to demonstrate the effectiveness of both our system components individually and the integrated system as a whole. Qilei Yin, Zhuotao Liu, Qi Li 0002, Tao Wang 0012, Qian Wang 0002, Chao Shen 0001, Yixiao Xu |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2018 | A Multi-tab Website Fingerprinting AttackabstractIn a Website Fingerprinting (WF) attack, a local, passive eavesdropper utilizes network flow information to identify which web pages a user is browsing. Previous researchers have extensively demonstrated the feasibility and effectiveness of WF, but only under the strong Single Page Assumption: the network flow extracted by the adversary always belongs to a single page. In other words, the WF classifier will never be asked to classify a network flow corresponding to more than one page, or part of a page. The Single Page Assumption is unrealistic because people often browse with multiple tabs. When this happens, the network flow induced by multiple tabs will overlap, and current WF attacks fail to classify correctly. Yixiao Xu, Tao Wang 0012, Qi Li 0002, Qingyuan Gong, Yang Chen 0001, Yong Jiang 0001 |
ACSAC | 1 |