VLDB 2026 Research / reviewers in the wild / expert
Linkang Du
dblp:246/4947
· DBLP profile ↗
19ranked-venue papers
6as first author
18since 2021 · last 2026
0009-0004-9028-9326ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 11 · 5 first-author · 10 since 2021Computer networks · 4 · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RoboFailRing: Retrieval-Augmented and Language Grounding Failure Detection for VLM-enabled Robotic ManipulationabstractReliable failure detection and causal reasoning are critical in robotic manipulation, as their absence risks robot damage and endangers human safety.Although recent Vision–Language Models (VLMs) are employed to attempt failure detection and causality reasoning, they typically make retrospective assessment only after task completion, and their reasoning accuracy is often limited.To address these issues, we introduce RoboFailRing, which enables timely failure detection during task execution and enhances the reasoning accuracy of VLMs.It achieves rapid failure detection by retrieving a pre-constructed failure memory and returning a similarity-based decision.In addition, by providing grounded failure report to VLMs, it improves the accuracy of their reasoning about the failure causes and repair strategies.We evaluate RoboFailRing on two large-scale simulated datasets comprising over 6,000 failure trajectories and covering 81 distinct manipulation tasks.The results show that the average success rate of out-of-distribution failure detection reaches 80%, while the mean detection time is cut to roughly 50% of the baseline.Moreover, evaluations on real-world systems show an average 35% gain in VLM failure-reasoning accuracy.We make our code publicly available at: https://github.com/DynamicPoet/RoboFailRing. Chenduo Ying, Linkang Du, Yuanchao Shu, Peng Cheng 0001 |
ACL (1) | 2 |
| 2026 | Transcriber: A Lightweight Dynamic Trigger Filter for Securing LLM-enabled Robots
Xiaolin Niu, Yuntao Wang 0004, Zhou Su 0001, Linkang Du |
ICC | 4 |
| 2026 | PrivATE: Differentially Private Average Treatment Effect Estimation for Observational Data
Linkang Du, Min Chen 0032, Yunjun Gao, Shibo He, Jiming Chen 0001, Zhikun Zhang 0001 |
NDSS | 3 |
| 2026 | VICTOR: Dataset Copyright Auditing in Video Recognition Systems
Zhikun Zhang 0001, Linkang Du, Min Chen 0032, Yunjun Gao, Shibo He, Jiming Chen 0001 |
NDSS | 3 |
| 2026 | URLcoat: Exploiting Web Search Capability to Jailbreak Large Language Models
Yiheng Sun, Linkang Du, Zhou Su 0001, Yuntao Wang 0004 |
SP | 2 |
| 2026 | Navigating Embodied Intelligence: Enabling Technologies, Security and Privacy, and Emerging TrendsabstractDriven by recent advances of large models and agents, embodied artificial intelligence (AI) emerges as a transformative paradigm for next-generation AI, endowing agents with physical forms and the ability to perceive, reason, and act within real-world environments. Unlike disembodied or virtual AI agent systems, embodied agents co-evolve cognition, control, and embodiment through continuous feedback loops, enabling applications ranging from humanoid robots to autonomous vehicles. In this survey, we first introduce a dual-brain architecture of embodied AI and examine its foundational technologies and key characteristics. We then analyze the security and privacy landscape, identifying critical vulnerabilities and evaluating existing/potential countermeasures. Finally, we outline emerging trends and open research directions in this emerging field, charting a roadmap toward efficient, secure, and ethically aligned embodied AI ecosystems. Yuntao Wang 0004, Xiaolin Niu, Jianle Ba, Zhou Su 0001, Linkang Du |
IEEE Internet Things J. | 5 |
| 2026 | AGAM: A randomly initialized policy network for action mask fusion in reinforcement learning
Buqing Xue, Qian Chen 0032, Zilong Wang 0001, Linkang Du, Tao Hu 0002 |
Knowl. Based Syst. | 4 |
| 2026 | Revealing the Risk of Hyper-Parameter Leakage in Deep Reinforcement Learning ModelsabstractDeep reinforcement learning (DRL) has been implemented across various critical applications, including smart grids, trac management systems, and autonomous vehicles. To safeguard intellectual property and mitigate security vulnerabilities, access to DRL models is typically restricted to a black-box format. is means specic details like the structure of the policy network and optimization processes are not openly available to users. It is crucial to determine if the hyper-parameters can be inferred from observable states and actions within these models, presenting two primary challenges: 1) limited data available from the black-box model and 2) the intertwined eects of hyperparameters on the model's behavior. Since DRL models exhibit varying behaviors in identical tasks depending on their hyper-parameter congurations, we introduce a novel hyper-parameter inference attack against DRL, named HyperInfer, which allows adversaries to deduce the settings of a black-box DRL model. In order to fully assess the risk of model hyper-parameter leakage, we design two novel state generation methods that provoke divergent responses from DRL models. We also develop an inference framework to elucidate the relationship between model behavior and hyper-parameter settings. rough comprehensive experiments involving multiple DRL models and environments, we demonstrate that model behaviors can indeed reveal hyper-parameter settings, with inference accuracy surpassing 90% in scenarios such as PPO with CartPole. We also discuss keyndings relevant to practical applications and explore how knowledge of hyperparameters can facilitate more sophisticated attacks. Lastly, we propose potential defensive strategies to minimize the risk of hyper-parameter leakage in DRL models. Linkang Du, Zhikun Zhang 0001, Min Chen 0032, Shouling Ji, Peng Cheng 0001, Jiming Chen 0001, Michael Backes 0001, Yang Zhang 0016 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | SoK: Dataset Copyright Auditing in Machine Learning SystemsabstractAs the implementation of machine learning (ML) systems becomes more widespread, especially with the introduction of larger ML models, we perceive a spring demand for massive data. However, it inevitably causes infringement and misuse problems with the data, such as using unauthorized online artworks or face images to train ML models. To address this problem, many efforts have been made to audit the copyright of the model training dataset. However, existing solutions vary in auditing assumptions and capabilities, making it difficult to compare their strengths and weaknesses. In addition, robustness evaluations usually consider only part of the ML pipeline and hardly reflect the performance of algorithms in real-world ML applications. Thus, it is essential to take a practical deployment perspective on the current dataset copyright auditing tools, examining their effectiveness and limitations. Concretely, we categorize dataset copyright auditing research into two prominent strands: intrusive methods and non-intrusive methods, depending on whether they require modifications to the original dataset. Then, we break down the intrusive methods into different watermark injection options and examine the non-intrusive methods using various finger-prints. To summarize our results, we offer detailed reference tables, highlight key points, and pinpoint unresolved issues in the current literature. By combining the pipeline in ML systems and analyzing previous studies, we highlight several future directions to make auditing tools more suitable for real-world copyright protection requirements. Linkang Du, Xuanru Zhou, Min Chen 0032, Chusong Zhang, Zhou Su 0001, Peng Cheng 0001, Jiming Chen 0001, Zhikun Zhang 0001 |
SP | 1 |
| 2025 | ArtistAuditor: Auditing Artist Style Pirate in Text-to-Image Generation ModelsabstractText-to-image models based on diffusion processes, such as DALL-E, Stable Diffusion, and Midjourney, are capable of transforming texts into detailed images and have widespread applications in art and design. As such, amateur users can easily imitate professional-level paintings by collecting an artist's work and fine-tuning the model, leading to concerns about artworks' copyright infringement. To tackle these issues, previous studies either add visually imperceptible perturbation to the artwork to change its underlying styles (perturbation-based methods) or embed post-training detectable watermarks in the artwork (watermark-based methods). However, when the artwork or the model has been published online, i.e., modification to the original artwork or model retraining is not feasible, these strategies might not be viable. Linkang Du, Min Chen 0032, Zhou Su 0001, Shouling Ji, Peng Cheng 0001, Jiming Chen 0001, Zhikun Zhang 0001 |
WWW | 1 |
| 2024 | PARL: Poisoning Attacks Against Reinforcement Learning-based Recommender SystemsabstractRecommender systems predict and suggest relevant options to users in various domains, such as e-commerce, streaming services, and social media. Recently, deep reinforcement learning (DRL)-based recommendation systems have become increasingly popular in academics and industry since DRL can characterize the long-term interaction between the system and users to achieve a better recommendation experience, e.g., Netflix, Spotify, Google, and YouTube. Linkang Du, Min Chen 0032, Peng Cheng 0001, Jiming Chen 0001, Zhikun Zhang 0001 |
AsiaCCS | 1 |
| 2024 | SUB-PLAY: Adversarial Policies against Partially Observed Multi-Agent Reinforcement Learning SystemsabstractRecent advancements in multi-agent reinforcement learning (MARL) have opened up vast application prospects, such as swarm control of drones, collaborative manipulation by robotic arms, and multi-target encirclement. However, potential security threats during the MARL deployment need more attention and thorough investigation. Recent research reveals that attackers can rapidly exploit the victim's vulnerabilities, generating adversarial policies that result in the failure of specific tasks. For instance, reducing the winning rate of a superhuman-level Go AI to around 20%. Existing studies predominantly focus on two-player competitive environments, assuming attackers possess complete global state observation. Oubo Ma, Yuwen Pu, Linkang Du, Ruo Wang, Xiaolei Liu 0001, Yingcai Wu, Shouling Ji |
CCS | 3 |
| 2024 | Poster Abstract: Leveraging Phase Offset for Stealthy Backdoor AttacksabstractDeep neural networks (DNNs) are increasingly exposed to backdoor attacks during model training, particularly when conducted through third-party services. This work introduces a novel backdoor strategy that employs phase offsets within various frequency bands to improve the anti-interference capabilities of trigger mechanisms in image classification models. By adjusting the phase components selectively, our method embeds triggers that are difficult to detect, subtly manipulating model responses while preserving image quality. Finally, the experimental results show that our attack method is effective. Linkang Du |
MSN | 3 |
| 2024 | ORL-AUDITOR: Dataset Auditing in Offline Deep Reinforcement Learning
Linkang Du, Min Chen 0032, Shouling Ji, Peng Cheng 0001, Jiming Chen 0001, Zhikun Zhang 0001 |
NDSS | 1 |
| 2024 | Stealthy Black-Box Attack With Dynamic Threshold Against MARL-Based Traffic Signal Control SystemabstractMultiagent reinforcement learning (MARL) promises outstanding performance for multiintersection traffic signal control systems (TSCS), enabling intelligent administration of cities. However, the vulnerability of MARL algorithms to adversarial attacks has raised concerns about the security of TSCS. In this article, we explore the robustness of MARL-based TSCS against adversarial attacks, propose a black-box multiobject attack strategy, and assign an attack budget to ensure stealthiness. We design a dynamic threshold-based selection of critical states to minimize the cumulative reward with a limited number of attacks. In addition, we present a lightweight agnostic dynamic threshold-based defense mechanism by enhancing the worst-case performance of the policy. We formulate it as a min-max optimization problem, i.e., minimizing the quantity of training sample alterations while maximizing the cumulative discount reward of policy against the perturbed states. Extensive experiments on simulation of urban mobility (SUMO) demonstrate that the proposed attack policy can significantly reduce the performance of TSCS. Heng Zhang 0001, Linkang Du, Zhikun Zhang 0001, Jian Zhang 0082, Hongran Li |
IEEE Trans. Ind. Informatics | 3 |
| 2023 | PrivGraph: Differentially Private Graph Data Publication by Exploiting Community Information
Zhikun Zhang 0001, Linkang Du, Min Chen 0032, Peng Cheng 0001 |
USENIX Security Symposium | 3 |
| 2023 | Backdoor attacks against deep reinforcement learning based traffic signal control systems
Heng Zhang 0001, Zhikun Zhang 0001, Linkang Du, Yongmin Zhang, Jian Zhang 0082, Hongran Li |
Peer Peer Netw. Appl. | 4 |
| 2021 | AHEAD: Adaptive Hierarchical Decomposition for Range Query under Local Differential PrivacyabstractFor protecting users' private data, local differential privacy (LDP) has been leveraged to provide the privacy-preserving range query, thus supporting further statistical analysis. However, existing LDP-based range query approaches are limited by their properties, ie, collecting user data according to a pre-defined structure. These static frameworks would incur excessive noise added to the aggregated data especially in the low privacy budget setting. In this work, we propose an Adaptive Hierarchical Decomposition (AHEAD) protocol, which adaptively and dynamically controls the built tree structure, so that the injected noise is well controlled for maintaining high utility. Furthermore, we derive a guideline for properly choosing parameters for AHEAD so that the overall utility can be consistently competitive while rigorously satisfying LDP. Leveraging multiple real and synthetic datasets, we extensively show the effectiveness of AHEAD in both low and high dimensional range query scenarios, as well as its advantages over the state-of-the-art methods. In addition, we provide a series of useful observations for deploying \myahead in practice. Linkang Du, Zhikun Zhang 0001, Shaojie Bai, Changchang Liu, Shouling Ji, Peng Cheng 0001, Jiming Chen 0001 |
CCS | 1 |
| 2020 | PLC-Sleuth: Detecting and Localizing PLC Intrusions Using Control Invariants
Zeyu Yang 0001, Liang He 0002, Peng Cheng 0001, Jiming Chen 0001, David K. Y. Yau, Linkang Du |
RAID | 6 |