Liuwan Zhu

dblp:243/3417 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0002-8511-6402ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 first-author · 3 since 2021Artificial intelligence and machine learning · 3 · 3 first-author · 3 since 2021Computer networks · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
5 papers
Security and privacy of machine learning · 60% Cyber-physical and IoT security · 27% Malware analysis · 10%
Interdisciplinary, comprehensive, and emerging computing
1 paper
Smart cities and intelligent transportation · 100%
Databases, data mining, and information retrieval
1 paper
Information retrieval · 100%
Artificial intelligence
2 papers
Vision and language · 100%

Topics — the 9 heaviest of 12, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Smart cities and intelligent transportation › navigation
vehicle localization
1.012026
D-SYNC: Enhancing Vehicle Localization with Dashcam-Satellite Image Synchronization · PerCom 2026
Cyber-physical and IoT security › GPS security
GPS spoofing detection
1.012026
D-SYNC: Enhancing Vehicle Localization with Dashcam-Satellite Image Synchronization · PerCom 2026
Security and privacy of machine learning › adversarial attack › backdoor attack › backdoor defense
backdoor detection
0.812024
SEER: Backdoor Detection for Vision-Language Models through Searching Target Text and Image Trigger Jointly · AAAI 2024
Information retrieval › cross-modal retrieval
vision-language retrieval
0.612022
Most and Least Retrievable Images in Visual-Language Query Systems · ECCV (37) 2022
Security and privacy of machine learning › adversarial attack
backdoor attack
0.512021
CLEAR: Clean-up Sample-Targeted Backdoor in Neural Networks · ICCV 2021
Security and privacy of machine learning › adversarial attack › backdoor attack
backdoor defense
0.512021
CLEAR: Clean-up Sample-Targeted Backdoor in Neural Networks · ICCV 2021
Security and privacy of machine learning › poisoning attack
backdoor attack and defense
0.412020
GangSweep: Sweep out Neural Backdoors by GAN · ACM Multimedia 2020
Malware analysis › malware detection
cryptojacking detection
0.412019
CapJack: Capture In-Browser Crypto-jacking by Deep Capsule Network through Behavioral Analysis · INFOCOM 2019
Computer vision › Vision and language
vision-language model
0.212024
SEER: Backdoor Detection for Vision-Language Models through Searching Target Text and Image Trigger Jointly · AAAI 2024

Methods — techniques the papers use, named apart from their topics

image retrieval · 2.0geo-assisted loss function · 2.0trigger inversion · 1.5joint feature-space search · 1.5fine-tuning · 0.5convex hull · 0.5perturbation mask analysis · 0.4generative adversarial network · 0.4deep learning · 0.4capsule network · 0.4
YearPublicationVenuePosition
2026 D-SYNC: Enhancing Vehicle Localization with Dashcam-Satellite Image Synchronization
abstract
This paper introduces D-SYNC, a cutting-edge framework for enhancing the security and reliability of vehicle localization systems. D-SYNC offers an innovative solution to utilize dashcam footage for vehicle localization in the scenario of the primary localization system, GPS, under security attacks or simply failing to work. D-SYNC synchronizes the visual data from dashcam recordings with geotagged satellite imagery, achieving reliable vehicle positioning and trajectory mapping without precise dashcam-to-satellite alignment. D-SYNC introduces novel designs to address critical challenges, such as the limited field of vision in dashcam videos during real-world driving and how to correlate the significantly distinct spatial and temporal patterns between dashcam sequences and satellite images. Moreover, a novel geo-assisted loss function is introduced in D-SYNC that further elevates the performance of the localization process. D-SYNC surpasses existing methods and significantly increases vehicle localization accuracy. It achieves a 91% top-1 retrieval accuracy in urban environments and a 34% improvement in sub-10 meter localization error compared to benchmarks, relying solely on dashcam and satellite imagery.
Peng Jiang 0027, Liuwan Zhu, Rui Ning, Hongyi Wu, Chunsheng Xin
PerCom2
2026 Efficient Backdoor Mitigation in Federated Learning With Contrastive Loss
Hal Ferguson, Rui Ning, Hongyi Wu, Liuwan Zhu, Chunsheng Xin, Mohammad Shahabuddin, Jiang Li 0001
IEEE Internet Things J.4
2025 RandEye: On-Sensor Stochastic Image Transformation for Backdoor-Resistant Edge Inference
abstract
The rising threat of backdoor attacks in artificial intelligence (AI) models poses significant risks across diverse applications, including medical diagnostics, autonomous navigation, and surveillance systems. Existing software-based defenses, though effective, are computationally demanding and impractical for low-latency, low-power edge AI inference. This work presents RandEye, the first hardware-based backdoor defense directly embedded into a CMOS image sensor (CIS) and adaptable to various CIS designs. RandEye applies stochastic transformations to captured images directly on the CIS to disrupt malicious input patterns crafted by adversaries, thus effectively deactivating backdoor triggers in compromised models. We introduce the design techniques of hardware-efficient affine transformations and pixel reverse transformation to achieve a lightweight on-sensor defense. RandEye integrated on a 256×256 pixel array is evaluated to achieve a low power profile of 0.35 mW and requires only 1.8% area overhead, while supporting frame rates exceeding 30 FPS for downstream image classification. For backdoored models, RandEye reduces the attack success rate to below 5% while maintaining model accuracy (ACC). When paired with model fine-tuning, RandEye further improves ACC by around 8.8% while still robustly suppressing ASR.
Wantong Li 0002, Liuwan Zhu
ACM Great Lakes Symposium on VLSI2
2024 SEER: Backdoor Detection for Vision-Language Models through Searching Target Text and Image Trigger Jointly
abstract
This paper proposes SEER, a novel backdoor detection algorithm for vision-language models, addressing the gap in the literature on multi-modal backdoor detection. While backdoor detection in single-modal models has been well studied, the investigation of such defenses in multi-modal models remains limited. Existing backdoor defense mechanisms cannot be directly applied to multi-modal settings due to their increased complexity and search space explosion. In this paper, we propose to detect backdoors in vision-language models by jointly searching image triggers and malicious target texts in feature space shared by vision and language modalities. Our extensive experiments demonstrate that SEER can achieve over 92% detection rate on backdoor detection in vision-language models in various settings without accessing training data or knowledge of downstream tasks.
Liuwan Zhu, Rui Ning, Jiang Li 0001, Chunsheng Xin, Hongyi Wu
AAAI1
2022 Most and Least Retrievable Images in Visual-Language Query Systems
Liuwan Zhu, Rui Ning, Jiang Li 0001, Chunsheng Xin, Hongyi Wu
ECCV (37)1
2021 CLEAR: Clean-up Sample-Targeted Backdoor in Neural Networks
abstract
The data poisoning attack has raised serious security concerns on the safety of deep neural networks, since it can lead to neural backdoor that misclassifies certain inputs crafted by an attacker. In particular, the sample-targeted backdoor attack is a new challenge. It targets at one or a few specific samples, called target samples, to misclassify them to a target class. Without a trigger planted in the backdoor model, the existing backdoor detection schemes fail to detect the sample-targeted backdoor as they depend on reverse-engineering the trigger or strong features of the trigger. In this paper, we propose a novel scheme to detect and mitigate sample-targeted backdoor attacks. We discover and demonstrate a unique property of the sample-targeted backdoor, which forces a boundary change such that small "pockets" are formed around the target sample. Based on this observation, we propose a novel defense mechanism to pinpoint a malicious pocket by "wrapping" them into a tight convex hull in the feature space. We design an effective algorithm to search for such a convex hull and remove the backdoor by fine-tuning the model using the identified malicious samples with the corrected label according to the convex hull. The experiments show that the proposed approach is highly efficient for detecting and mitigating a wide range of sample-targeted backdoor attacks.
Liuwan Zhu, Rui Ning, Chunsheng Xin, Chonggang Wang, Hongyi Wu
ICCV1
2020 GangSweep: Sweep out Neural Backdoors by GAN
abstract
This work proposes GangSweep, a new backdoor detection framework that leverages the super reconstructive power of Generative Adversarial Networks (GAN) to detect and ''sweep out'' neural backdoors. It is motivated by a series of intriguing empirical investigations, revealing that the perturbation masks generated by GAN are persistent and exhibit interesting statistical properties with low shifting variance and large shifting distance in feature space. Compared with the previous solutions, the proposed approach eliminates the reliance on the access to training data, and shows a high degree of robustness and efficiency for detecting and mitigating a wide range of backdoored models with various settings. Moreover, this is the first work that successfully leverages generative networks to defend against advanced neural backdoors with multiple triggers and their polymorphic forms.
Liuwan Zhu, Rui Ning, Cong Wang 0006, Chunsheng Xin, Hongyi Wu
ACM Multimedia1
2019 CapJack: Capture In-Browser Crypto-jacking by Deep Capsule Network through Behavioral Analysis
abstract
This work proposes an innovative approach, named CapJack, to detect in-browser malicious cryptocurrency mining activities by using the latest CapsNet technology. To the best of our knowledge, this is the first work to introduce CapsNet to the field of malware detection through system behavioral analysis. It is particularly effective to detect malicious miners under multitasking environments where multiple applications run simultaneously. Experimental data show appealing performance of CapJack, with a detection rate of as high as 87% instantly and 99% within a window of 11 seconds.
Rui Ning, Cong Wang 0006, Chunsheng Xin, Jiang Li 0001, Liuwan Zhu, Hongyi Wu
INFOCOM5