VLDB 2026 Research / reviewers in the wild / expert
Haodi Wang
dblp:232/4688
· DBLP profile ↗
19ranked-venue papers
9as first author
17since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 5 first-author · 7 since 2021Databases, data management, data science and information retrieval · 6 · 2 first-author · 6 since 2021Artificial intelligence and machine learning · 5 · 1 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | zkNAS: Secure and Efficient Outsourced-NAS with Zero-Cost Proxies
Haodi Wang, Tangyu Jiang, Fangda Guo, Yu Guo 0003 |
DASFAA (5) | 1 |
| 2026 | Real-time prediction of TBM muck particle size distribution based on SAM-guided and contour-regression network
Guoqiang Huang, Chengjin Qin, Pengcheng Xia 0005, Haodi Wang, Honggan Yu, Jianfeng Tao, Chengliang Liu 0001 |
Adv. Eng. Informatics | 4 |
| 2026 | Leveraging Robustness-Aware Channel Activation for Privacy Protection and Tracing ForensicsabstractSharing personal photos on social media exposes users to unauthorized identity recognition and unconsented model training, raising severe privacy and copyright concerns. Existing methods typically focus on either privacy protection, which misleads recognition models to prevent unauthorized automated recognition, or tracing forensics, which embeds traceable patterns for ownership verification. However, they fail to achieve both simultaneously. The core challenge is to jointly achieve privacy protection and tracing forensics within a single perturbation, since the two objectives rely on different feature behaviors and naive combinations are ineffective in practice. In this work, we propose ATP (Adversarial Tracing Perturbation), a novel perturbation generation method that activates robustness-aware feature channels to balance privacy and traceability. ATP leverages non-robust channel activation to mislead recognition models for privacy protection, while robust channel activation embeds traceable patterns for reliable tracing forensics. Extensive experiments on image classification and face recognition show that ATP achieves strong dual protection, improving overall dual-protection performance by bm 3.54× over the baselines while remaining effective under adaptive attacks, thereby demonstrating strong robustness and practical applicability. © 2026 IEEE. Haodi Wang, Kai Dong 0001, Jiakai Wang, Xianglong Liu 0001, Guangdong Bai |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Zero-Knowledge AI Inference with High PrecisionabstractArtificial Intelligence as a Service (AIaaS) enables users to query a model hosted by a service provider and receive inference results from a pre-trained model. Although AIaaS makes artificial intelligence more accessible, particularly for resource-limited users, it also raises verifiability and privacy concerns for the client and server, respectively. While zero-knowledge proof techniques can address these concerns simultaneously, they incur high proving costs due to the non-linear operations involved in AI inference and suffer from precision loss because they rely on fixed-point representations to model real numbers. Arman Riasi, Haodi Wang, Rouzbeh Behnia, Viet Vo, Thang Hoang |
CCS | 2 |
| 2025 | FedART: Enhancing Replay in Federated Incremental LearningabstractFederated Class-Incremental Learning (FCIL) enables distributed models to continuously learn new categories while preserving privacy, which suffers from the problem of catastrophic forgetting. To address this issue, generative replay has emerged as a mainstream solution, yet its performance is hampered by two fundamental bottlenecks: (1) low-fidelity synthesis, where generated visual samples fail to effectively represent historical knowledge, and (2) class imbalance in FCIL, which undermines fair learning across classes. In this paper, we propose a novel generative replay framework called FedART (Federated Adaptive Replay with Text-anchors). To combat low-fidelity synthesis, FedART employs a text-anchored initialization strategy. Instead of optimizing from a random start, this approach provides strong semantic priors to guide the generation process. To tackle class imbalance, we design a dual adaptive aggregation mechanism. This mechanism applies tailored weighting strategies at both the generator and classifier levels, leveraging local training dynamics to ensure both the quality of generative knowledge and the fairness of classifier aggregation. Extensive experiments on CIFAR-100 and Tiny-ImageNet demonstrate that FedART significantly outperforms state-of-the-art methods, achieving an accuracy of up to 43.62% and establishing a new and robust benchmark for enhancing the effectiveness of generative replay in FCIL. Zijiang Tan, Haodi Wang, Libin Jiao, Rongfang Bie |
MMAsia | 2 |
| 2025 | Accelerating Zero-Shot NAS With Feature Map-Based Proxy and Operation Scoring FunctionabstractNeural Architecture Search (NAS) has been extensively studied due to its ability in automatic architecture engineering. Existing NAS methods rely heavily on the gradients and data labels, which either incur immense computational costs or suffer from discretization discrepancy due to the supernet structure. Moreover, the majority of them are limited in generating diverse architectures. To alleviate these issues, in this paper, we propose a novel zero-cost proxy called $\mathsf {MeCo}$MeCo based on the Pearson correlation matrix of the feature maps. Unlike the previous work, the computation of $\mathsf {MeCo}$MeCo as well as its variant $\mathsf {MeCo_{opt}}$MeCoopt requires only one random data for a single forward pass. Based on the proposed zero-cost proxy, we further craft a new zero-shot NAS scheme called $\mathsf {FLASH}$FLASH, which harnesses a new proxy-based operation scoring function and a greedy heuristic. Compared to the existing methods, $\mathsf {FLASH}$FLASH is highly efficient and can construct diverse model architectures instead of repeated cells. We design comprehensive experiments and extensively evaluate our designs on multiple benchmarks and datasets. The experimental results show that our method is one to six orders of magnitudes more efficient than the state-of-the-art baselines with the highest model accuracy. Tangyu Jiang, Haodi Wang, Rongfang Bie, Chun Yuan 0003 |
IEEE Trans. Pattern Anal. Mach. Intell. | 2 |
| 2025 | An Efficient and Zero-Knowledge Classical Machine Learning Inference PipelineabstractMachine Learning as a Service (MLaaS) offers powerful data analytics services to clients with limited resources. However, it still raises concerns about the integrity of delegated computation and the privacy of the server's model parameters. To address these issues, zero-knowledge Machine Learning (zkML) has been suggested for computation verifiability with privacy guarantee for ML models. Nevertheless, the existing zkML schemes focus on only one classical ML classification algorithm or deep neural networks, which may not achieve satisfactory accuracy or require large-scale training data and model parameters, thus limiting their usefulness in certain applications. In this article, we propose ezDPS, an efficient and zero-knowledge scheme for classical ML inference that processes data in multiple stages for improved accuracy. Unlike prior works, each stage of the ezDPS pipeline is based on a well-established classical ML algorithm, including Discrete Wavelet Transformation, Zero-Score Normalization, Principal Components Analysis, and Support Vector Machine. We design new gadgets to prove various ML operations effectively. Our implementation of ezDPS has been fully tested on real datasets, and experimental results show that it is up to three orders of magnitude more efficient than generic circuit-based approaches, while also maintaining greater accuracy than single ML classification approaches. Haodi Wang, Rongfang Bie, Thang Hoang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | EAT-Face: Emotion-Controllable Audio-Driven Talking Face Generation via Diffusion ModelabstractAudio-driven talking face generation is a promising task with a lot of attention. Despite abundant efforts are devoted to video quality and lip synchronization, most existing works do not take the unignorable aspect of facial emotional expression into account during generation. In this paper, we propose an Emotion-controllable Audio-driven Talking Face generation framework called EAT-Face that enables us to control multiple types of emotions. Specifically, the proposed method consists of a Talking Face Reconstructor (TFR) and a Facial Emotion Controller (FEC), utilizing fused multimodal information including audio signals, visual images, and textual emotions for synthesis. Firstly, TFR predicts face images synchronized with given audios from random noises, leveraging external guidances comprised of audio features, character references, and face masks as conditions. Then, FEC further manipulates the facial emotions based on TFR, leveraging the emotion embeddings extracted from emotion texts. However, a semantic misalignment problem lies in the emotion-texts and character images. To tackle this issue, we additionally propose a strategy called joint Emotion-Visual Embedding (EVE) to mitigate the misalignment. In this way, the proposed EAT-Face is captive to control emotion more precisely. Extensive experiments involving both objective evaluations and subjective investigations demonstrate the effectiveness of our framework in synthesizing high-fidelity and emotional talking face videos. Haodi Wang, Xiaojun Jia, Xiaochun Cao |
FG | 1 |
| 2024 | Label Noise Correction for Federated Learning: A Secure, Efficient and Reliable RealizationabstractFederated learning has emerged as a promising paradigm for large-scale collaborative training tasks, harnessing diverse local datasets from different clients to jointly train global models. In real-world implementations, client data could have label noise, causing the quality of the global model to be influenced. Existing label-correction solutions assume all the clients are discreet and fail to consider detecting the malicious clients, thus are not practical or privacy-preserving. In this paper, we present zkCor, an efficient and reliable label noise correction scheme with zero-knowledge confidentiality. Our method is designed upon FedCorr [1], but with more relaxed security assumptions. zkCor is established from the ingenious synergy of the label noise correction protocol and the zero-knowledge proof (ZKP), requiring each client to provide a computation integrity proof to the aggregator in each iteration. Thus, clients are forced to jointly guarantee label-correction reliability. We further devise a batch ZKP that is efficient and more suitable for federated learning settings. We rigorously illustrate the building blocks of zkCor and complete the prototype implementation. The extensive experiments demonstrate that zkCor can gain at least 2 to 30 times better performance than the baseline approach on verification workloads with nearly no extra proof time cost from clients. Haodi Wang, Tangyu Jiang, Yu Guo 0003, Fangda Guo, Rongfang Bie, Xiaohua Jia |
ICDE | 1 |
| 2024 | New Indicators and Optimizations for Zero-Shot NAS Based on Feature Maps
Tangyu Jiang, Haodi Wang, Rongfang Bie, Libin Jiao |
KSEM (3) | 2 |
| 2024 | Transferable Multimodal Attack on Vision-Language Pre-training ModelsabstractVision-Language Pre-training (VLP) models have achieved remarkable success in practice, while easily being misled by adversarial attack. Though harmful, adversarial attacks are valuable in revealing the blind-spots of VLP models and promoting their robustness. However, existing adversarial attacking studies pay insufficient attention to the key roles of different modality-correlated features, leading to unsatisfactory transferable attacking performance. To tackle this issue, we propose the Transferable MultiModal (TMM) attack framework, which tailors both the modality consistency and modality discrepancy features. To promote transferability, we propose the attention-directed feature perturbation to disturb the modality-consistency features in critical attention regions. In light of the commonly employed cross-attention can represent the consistent features among diverse models, it is more possible to mislead the similar model perception for activating stronger transferability. For improving attacking ability, we proposed the orthogonal-guided feature heterogenization to guide the adversarial perturbation to contain more modality-discrepancy features in the encoded embeddings. Since VLP models rely more on aligned features among different modalities during decision-making, increasing the modality-discrepant could confuse the learned representation for better attacking ability. Extensive experiments under diverse settings demonstrate that the proposed TMM outperforms the comparisons by large margins, i.e., 20.47% improvements in transferable attacking ability on average. Moreover, we highlight that our TMM also shows outstanding attacking performance on large models, such as MiniGPT-4, Otter, etc. Haodi Wang, Kai Dong 0001, Zhilei Zhu, Haotong Qin, Aishan Liu, Xiaolin Fang 0001, Jiakai Wang, Xianglong Liu 0001 |
SP | 1 |
| 2024 | Verifiable Arbitrary Queries With Zero Knowledge Confidentiality in Decentralized StorageabstractBlockchain-based data storage has become an emerging paradigm, providing a fair and transparent data platform for decentralized applications. However, how to achieve secure on-chain verification for arbitrary SQL queries in such a decentralized storage remains under-explored. Due to the limitations of authenticated data structure (ADS), existing works either do not consider arbitrary query verification issue or fail to achieve practical gas consumption efficiency. In this paper, we present a novel arbitrary query verification scheme for decentralized storage. The proposed scheme, named$\mathsf {zkQuery}$, enables efficient public verification for arbitrary queries with zero-knowledge confidentiality.$\mathsf {zkQuery}$is built from the ingenious synergy of techniques from both zero-knowledge proof and smart contract technology. The core idea is to delegate smart contracts to fairly execute results verification and utilize our tailored zero-knowledge proof protocol to facilitate arbitrary computation in a privacy-preserving manner. The verification protocols of$\mathsf {zkQuery}$are highly customized for decentralized storage, where the complexity of on-chain verification can be completed in logarithmic time, significantly decreasing gas consumption. We rigorously provide security analysis and complete the prototype implementation. The extensive experiments over the NEAR blockchain show that$\mathsf {zkQuery}$can gain at least$2\times $better performance than the baseline approach on all metrics. Haodi Wang, Yu Guo 0003, Rongfang Bie, Xiaohua Jia |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | FedEDB: Building a Federated and Encrypted Data Store via Consortium BlockchainsabstractDecentralized storage platforms based on consortium blockchains have emerged in the spotlight of research and industry communities because they are flexible, transparent, and eliminated trust in contrast to the traditional centralized data-sharing model. However, due to wide attacking surfaces in a blockchain network, this decentralized data-sharing paradigm is subject to malicious data breaches. Untrusted blockchain nodes can directly obtain sensitive information from the query processing and their local storage. Several studies have been made for solving this dilemma, but they only focus on single-user settings and cannot be directly applied to multi-owners blockchain-based data sharing scenarios. In this paper, we introduce FedEDB, a federated and encrypted data store by using consortium blockchains. Unlike existing solutions that focus on single-user settings, our proposed schemes can efficiently support privacy-preserving and reliable multi-owner queries in the decentralized setting. We start from the practical key aggregation technique to construct the multi-owner search schemes and further refine the underling building blocks to enhance the security. Besides, we integrate the smart contract with our tailored zero-knowledge proof to enforce secure and reliable result verification protocol with fairness. We implement a prototype and thorough security analysis and comprehensive evaluation results confirm the practicability of our design. Yu Guo 0003, Yuxin Xi, Haodi Wang, Cong Wang 0001, Xiaohua Jia |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2023 | MeCo: Zero-Shot NAS with One Data and Single Forward Pass via Minimum Eigenvalue of CorrelationabstractNeural Architecture Search (NAS) is a promising paradigm in automatic architecture engineering. Zero-shot NAS can evaluate the network without training via some specific metrics called zero-cost proxies. Though effective, the existing zero-cost proxies either invoke at least one backpropagation or depend highly on the data and labels. To alleviate the above issues, in this paper, we first reveal how the Pearson correlation matrix of the feature maps impacts the convergence rate and the generalization capacity of an over-parameterized neural network. Enlightened by the theoretical analysis, we propose a novel zero-cost proxy called $\mathsf{MeCo}$, which requires only one random data for a single forward pass. We further propose an optimization approach $\mathsf{MeCo_{opt}}$ to improve the performance of our method. We design comprehensive experiments and extensively evaluate $\mathsf{MeCo}$ on multiple popular benchmarks. $\mathsf{MeCo}$ achieves the highest correlation with the ground truth (e.g., 0.89 on NATS-Bench-TSS with CIFAR-10) among all the state-of-the-art proxies, which is also fully independent of the data and labels. Moreover, we integrate $\mathsf{MeCo}$ with the existing generation method to comprise a complete NAS. The experimental results illustrate that $\mathsf{MeCo}$-based NAS can select the architecture with the highest accuracy and a low search cost. For instance, the best network searched by $\mathsf{MeCo}$-based NAS achieves 97.31% on CIFAR-10, which is 0.04% higher than the baselines under the same settings. Our code is available at https://github.com/HamsterMimi/MeCo Tangyu Jiang, Haodi Wang, Rongfang Bie |
NeurIPS | 2 |
| 2023 | ezDPS: An Efficient and Zero-Knowledge Machine Learning Inference PipelineabstractMachine Learning as a service (MLaaS) permits resource-limited clients to access powerful data analytics services ubiquitously. Despite its merits, MLaaS poses significant concerns regarding the integrity of delegated computation and the privacy of the server’s model parameters. To address this issue, Zhang et al. (CCS'20) initiated the study of zero-knowledge Machine Learning (zkML). Few zkML schemes have been proposed afterward; however, they focus on sole ML classification algorithms that may not offer satisfactory accuracy or require large-scale training data and model parameters, which may not be desirable for some applications. We propose ezDPS, a new efficient and zero-knowledge ML inference scheme. Unlike prior works, ezDPS is a zkML pipeline in which the data is processed in multiple stages for high accuracy. Each stage of ezDPS is harnessed with an established ML algorithm that is shown to be effective in various applications, including Discrete Wavelet Transformation, Principal Components Analysis, and Support Vector Machine. We design new gadgets to prove ML operations effectively. We fully implemented ezDPS and assessed its performance on real datasets. Experimental results showed that ezDPS achieves one-to-three orders of magnitude more efficient than the generic circuit-based approach in all metrics while maintaining more desirable accuracy than single ML classification approaches. Haodi Wang, Thang Hoang |
Proc. Priv. Enhancing Technol. | 1 |
| 2022 | A deep learning network based end-to-end image composition
Haodi Wang, Xiuping Wu, Junqi Guo |
Signal Process. Image Commun. | 2 |
| 2021 | ZKCPlus: Optimized Fair-exchange Protocol Supporting Practical and Flexible Data ExchangeabstractDevising a fair-exchange protocol for digital goods has been an appealing line of research in the past decades. The Zero-Knowledge Contingent Payment (ZKCP) protocol first achieves fair exchange in a trustless manner with the aid of the Bitcoin network and zero-knowledge proofs. However, it incurs setup issues and substantial proving overhead, and has difficulties handling complicated validation of large-scale data. In this paper, we propose an improved solution ZKCPlus for practical and flexible fair exchange. ZKCPlus incorporates a new commit-and-prove non-interactive zero-knowledge (CP-NIZK) argument of knowledge under standard discrete logarithmic assumption, which is prover-efficient for data-parallel computations. With this argument we avoid the setup issues of ZKCP and reduce seller's proving overhead, more importantly enable the protocol to handle complicated data validations. We have implemented a prototype of ZKCPlus and built several applications atop it. We rework a ZKCP's classic application of trading sudoku solutions, and ZKCPlus achieves 21-67 times improvement in seller efficiency than ZKCP, with only milliseconds of setup time and 1 MB public parameters. In particular, our CP-NIZK argument shows an order of magnitude higher proving efficiency than the zkSNARK adopted by ZKCP. We also built a realistic application of trading trained CNN models. For a 3-layer CNN containing 8,620 parameters, it takes less than 1 second to prove and verify an inference computation, and also about 1 second to deliver the parameters, which is very promising for practical use. Yun Li 0010, Cun Ye, Yuguang Hu, Ivring Morpheus, Chao Zhang 0008, Yupeng Zhang 0001, Haodi Wang |
CCS | 10 |
| 2020 | Semantic Inpainting with Multi-dimensional Adversarial Network and Wasserstein Distance
Haodi Wang, Libin Jiao, Rongfang Bie, Hao Wu 0022 |
PRCV (3) | 1 |
| 2019 | Multi-scale semantic image inpainting with residual learning and GAN
Libin Jiao, Hao Wu 0022, Haodi Wang, Rongfang Bie |
Neurocomputing | 3 |