VLDB 2026 Research / reviewers in the wild / expert
Zehua Ding
dblp:233/5749
· DBLP profile ↗
6ranked-venue papers
4as first author
6since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Optimal adversarial perturbation guided membership inference: Gradient-sensitive white-box and hybrid zeroth-order black-box strategies
Zehua Ding, Youliang Tian, Guorong Wang, Jinbo Xiong, Jianfeng Ma 0001 |
Expert Syst. Appl. | 1 |
| 2025 | Robust Multi-Scale Gradient Estimation for Query-Efficient Black-box Adversarial AttackabstractBlack-box adversarial attacks require only querying model outputs rather than accessing internal gradients, making them more covert and posing a substantial threat to the security of deep neural networks. However, existing score-based black box methods typically rely on single-scale finite difference gradient estimation; the step size is constrained by a pronounced tradeoff between bias and variance, which in high-dimensional settings often inflates estimation variance and destabilizes the estimated direction. To address this, we propose Robust Multi-Scale Gradient Estimation (RMSGE) to improve query efficiency and stability for black box attacks. RMSGE uses a multi-scale finite difference strategy to mitigate the conflict between bias and variance and integrates two heterogeneous sampling schemes, Natural Evolution Strategy (NES) and Simultaneous Perturbation Stochastic Approximation (SPSA), to enhance both global exploration and local sensitivity in gradient estimation. In addition, RMSGE applies momentum smoothing across scales and sampling distributions to suppress noise accumulation in high-dimensional spaces and employs a voting mechanism to fuse gradient information from multiple sources, further improving the stability and robustness of the update direction. Theoretical analysis shows that RMSGE preserves the first-order unbiasedness of finite difference estimation while effectively alleviating the tradeoff between bias and variance. Extensive experiments demonstrate that RMSGE achieves substantially higher attack success rates and query efficiency than existing black box methods across multiple benchmark datasets, validating its effectiveness. Guorong Wang, Jinchuan Tang, Zehua Ding, Youliang Tian |
TrustCom | 3 |
| 2025 | Weight decay regularized adversarial training for attacking angle imbalance
Guorong Wang, Jinchuan Tang, Zehua Ding, Shuping Dang, Gaojie Chen 0001 |
Expert Syst. Appl. | 3 |
| 2025 | Membership Feature Aggregation Attack Against Knowledge Reasoning Models in Internet of ThingsabstractThe rapid growth of Internet of Things (IoT) technology has heightened the requirement for effective data management and analysis. Knowledge graphs (KGs) and large pretrained language models (LLMs) play crucial roles in this scenario: KGs offer structured data management, while LLMs enhance data feature analysis. However, as data privacy concerns escalate, IoT machine learning models become more susceptible to membership inference attacks (MIAs). To tackle this challenge, we focus MIAs in knowledge reasoning models (KRMs) for IoT environments and propose two attack methods: 1) correlation attack (CA) and 2) feature aggregation attack (FAA). CA leverages the relational features of KGs to link member characteristics across different parameter spaces. It aggregates these features and maps them into a nonlinear space to identify linear relationships among members, thus improving membership recognition. In contrast, the FAA focuses on aggregating multiple member features, such as confidence scores, loss values, decision labels, and so on, within the KRM and projects them into a linear space. This method captures the interactions among different features, enhancing the differentiation between member and nonmember samples. The key difference is that CA explores correlations between features across member identities, while FAA aggregates various features to improve overall representation and identification. Experimental results show that both CA and FAA outperform existing methods, offering a more effective assessment of privacy risks in KRMs within IoT environments. Zehua Ding, Youliang Tian, Jinbo Xiong, Guorong Wang, Jianfeng Ma 0001 |
IEEE Internet Things J. | 1 |
| 2025 | Membership inference attacks via spatial projection-based relative information loss in MLaaS
Zehua Ding, Youliang Tian, Guorong Wang, Jinbo Xiong, Jinchuan Tang, Jianfeng Ma 0001 |
Inf. Process. Manag. | 1 |
| 2024 | Membership Inference Attacks via Dynamic Adversarial Perturbations ReductionabstractExisting membership inference attacks (MIAs) based on adversarial attacks typically introduce excessively large adversarial perturbations to change the model predictions. However, such methods are not only likely to obscure the characteristic memory of the model regarding member data but also blur the subtle characteristic differences between member and non-member data. To address this issue, we propose a novel dynamic adversarial perturbation reduction MIA (DAPR-MIA), which aims to enhance the ability to identify the membership of samples by reducing the perturbation strength. Specifically, DAPR-MIA first conducts a fine-grained analysis of the gradient components of conventional adversarial examples, assessing the impact of each element on the model decision to generate a sensitivity mask. This mask identifies dimensions within adversarial examples that significantly influence model predictions, referred to as sensitive dimensions. Then, by dynamically reducing the perturbation size in these sensitive dimensions, DAPR-MIA gradually approaches the minimum perturbation required to change the prediction result of samples, maximizing the retention of membership features within the sample. Finally, the deviation of the prediction results between the original sample and the adversarial example after perturbation attenuation on the target model is measured to infer whether the sample belongs to a member data. Experimental results show that DAPR-MIA significantly outperforms existing methods on multiple datasets and deep models, demonstrating state-of-the-art attack accuracy. Zehua Ding, Youliang Tian, Guorong Wang, Jinbo Xiong, Jianfeng Ma 0001 |
TrustCom | 1 |