Tian Dong 0003

dblp:25/8475-3 · DBLP profile ↗
← Back
11ranked-venue papers
3as first author
11since 2021 · last 2026
0009-0004-6442-8716ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 3 first-author · 6 since 2021Computer networks · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Authority Backdoor: A Certifiable Backdoor Mechanism for Authoring DNNs
abstract
Deep Neural Networks (DNNs), as valuable intellectual property, face unauthorized use. Existing protections, such as digital watermarking, are largely passive; they provide only post-hoc ownership verification and cannot actively prevent the illicit use of a stolen model. This work proposes a proactive protection scheme, dubbed ``Authority Backdoor," which embeds access constraints directly into the model. In particular, the scheme utilizes a backdoor learning framework to intrinsically lock a model's utility, such that it performs normally only in the presence of a specific trigger (e.g., a hardware fingerprint). But in its absence, the DNN's performance degrades to be useless. To further enhance the security of the proposed authority scheme, the certifiable robustness is integrated to prevent an adaptive attacker from removing the implanted backdoor. The resulting framework establishes a secure authority mechanism for DNNs, combining access control with certifiable robustness against adversarial attacks. Extensive experiments on diverse architectures and datasets validate the effectiveness and certifiable robustness of the proposed framework.
Shaofeng Li 0001, Tian Dong 0003, Xiangyu Xu 0001, Guangchi Liu, Zhen Ling 0001
AAAI3
2025 The Philosopher's Stone: Trojaning Plugins of Large Language Models
Tian Dong 0003, Minhui Xue 0001, Guoxing Chen, Rayne Holland, Yan Meng 0001, Shaofeng Li 0001, Zhen Liu 0008, Haojin Zhu
NDSS1
2025 Depth Gives a False Sense of Privacy: LLM Internal States Inversion
Tian Dong 0003, Yan Meng 0001, Shaofeng Li 0001, Guoxing Chen, Zhen Liu 0008, Haojin Zhu
USENIX Security Symposium1
2025 Synergistic Multi-Modal Keystroke Eavesdropping in Virtual Reality With Vision and Wi-Fi
abstract
In panoramic and immersive virtual reality (VR) scenarios, users type on a floating and invisible keyboard, which cannot be observed by external adversaries, creating the illusion that their input is confidential. While recent studies have demonstrated the feasibility of leveraging side-channel information (e.g., vision, Wi-Fi) to eavesdrop on keystrokes in VR, they assume users typically type with fixed gestures, similar to using traditional physical keyboards. However, in real world scenarios, VR creates a 3D immersive environment, allowing users to type from varying orientations. This variation significantly degrades the quality of side-channel information (e.g., occlusion in vision, instability in Wi-Fi channels), leading to ineffective inference. In this study, we propose a multi-modal keystroke eavesdropping attack called WiViLeak, which combines Wi-Fi and vision information to complement each other. To address low-quality side-channel data caused by users’ varying orientations, we develop a theoretical model to explore the relationship between users’ hand movements in physical space (from the vision modality) and fluctuating Wi-Fi signals (from the wireless modality) as users change orientation. Based on this, we design a fully transformer based orientation calibration module to recover users’ vision data, aligning it as if they were facing the camera (i.e., in a front-facing view). Meanwhile, WiViLeak reconstructs Wi-Fi data to correspond to the front-facing view, utilizing the orientation angle derived from vision data. Finally, WiViLeak extracts effective features from reconstructed, high-quality vision and Wi-Fi data to predict keystrokes. We implement a WiViLeak prototype, achieving 89.2% accuracy in eavesdropping keystrokes and 93.6% top-100 password theft accuracy, while also demonstrating robustness across various real world VR scenarios, including payments, chatting, and meetings.
Jiachun Li 0001, Yan Meng 0001, Fazhong Liu, Tian Dong 0003, Suguo Du, Guoxing Chen, Yuling Chen 0002, Haojin Zhu
IEEE Trans. Inf. Forensics Secur.4
2024 Inferring Activities and Profiles of Users Based on Trajectory Leakage in Mobile Ad Network
abstract
With the widespread use of smartphones and the development of ad networks, mobile in-app targeted ads have become more and more prevalent, leveraging users' geolocation for targeting purposes. This service involves a large amount of user location data, which may not only expose sensitive locations closely associated with the users, but also reveal the users' activities and profiles. Previous studies have utilized various machine learning methods to infer users' activities or predict their future activities based on the location data from location-based social networks (LBSNs). These approaches, however, often require large datasets for training and are also resource-intensive. Unlike active behaviors, such as checking in, where users intentionally record their location, location data are passively recorded by mobile apps in the background, making inferring activities more challenging. Considering the rapid progress in the reasoning abilities of the large language models (LLMs) in recent years, we aim to evaluate user's activity and profile leakage through LLMs with the assistance of map APIs. We conduct the experiment on the location dataset, which is generated according to specified profiles. The results of the experiment show that the LLM can infer users' activities with an accuracy rate scoring up to 96.1 %, and there is also a high probability of predicting the users' profiles, such as the occupation.
Le Yu 0002, Tian Dong 0003, Yan Meng 0001, Shaofeng Li 0001, Guoxing Chen, Haojin Zhu
MSN3
2024 Learn What You Want to Unlearn: Unlearning Inversion Attacks against Machine Unlearning
abstract
Machine unlearning has become a promising solution for fulfilling the "right to be forgotten", under which individuals can request the deletion of their data from machine learning models. However, existing studies of machine unlearning mainly focus on the efficacy and efficiency of unlearning methods, while neglecting the investigation of the privacy vulnerability during the unlearning process. With two versions of a model available to an adversary, that is, the original model and the unlearned model, machine unlearning opens up a new attack surface. In this paper, we conduct the first investigation to understand the extent to which machine unlearning can leak the confidential content of the unlearned data. Specifically, under the Machine Learning as a Service setting, we propose unlearning inversion attacks that can reveal the feature and label information of an unlearned sample by only accessing the original and unlearned model. The effectiveness of the proposed unlearning inversion attacks is evaluated through extensive experiments on benchmark datasets across various model architectures and on both exact and approximate representative unlearning approaches. The experimental results indicate that the proposed attack can reveal the sensitive information of the unlearned data. As such, we identify three possible defenses that help to mitigate the proposed attacks, while at the cost of reducing the utility of the unlearned model. The study in this paper uncovers an underexplored gap between machine unlearning and the privacy of unlearned data, highlighting the need for the careful design of mechanisms for implementing unlearning without leaking the information of the unlearned data.
Hongsheng Hu, Shuo Wang 0012, Tian Dong 0003, Minhui Xue 0001
SP3
2024 DevDet: Detecting IoT Device Impersonation Attacks via Traffic Based Identification
Hongliang Yong, Le Yu 0002, Tian Dong 0003, Yan Meng 0001, Guoxing Chen, Haojin Zhu
WASA (2)3
2023 Privacy Computing with Right to Be Forgotten in Trusted Execution Environment
abstract
Sharing private data is at risk of potential data breaches, including the violation of the “right to be forgot-ten” principle, undermining people's willingness to share their data. A common solution is to involve the Trusted Execution Environment (TEE), which allows the data provider to verify the computation process without trusting others. However, previous works have either encountered incomplete computations or lacked scalability. In this paper, we propose TEERASE,a secure data-sharing framework that addresses these issues. TEERASEprotects every phase of the data lifecycle and enables individuals to share personal data with a predefined privacy budget. In particular, TEERASEapplies comprehensive privacy budgeting mechanisms to efficiently manage privacy budgets and employs an asynchronized execution approach that decouples budget consumption from data computation. TEERASErecords the predefined privacy budgets, verifies privacy consumption requests, updates the remaining budgets, and deletes data that have exhausted their budgets by preventing any attempts to access them. We implement a prototype of TEERASEand evaluate its effectiveness with a realistic case study on Genome-Wide Association Study.
Hongzhi Luo, Shaofeng Li 0001, Tian Dong 0003, Guoxing Chen, Yan Meng 0001, Haojin Zhu
GLOBECOM4
2023 RAI2: Responsible Identity Audit Governing the Artificial Intelligence
Tian Dong 0003, Shaofeng Li 0001, Guoxing Chen, Minhui Xue 0001, Haojin Zhu, Zhen Liu 0008
NDSS1
2023 Mate! Are You Really Aware? An Explainability-Guided Testing Framework for Robustness of Malware Detectors
abstract
Numerous open-source and commercial malware detectors are available. However, their efficacy is threatened by new adversarial attacks, whereby malware attempts to evade detection, e.g., by performing feature-space manipulation. In this work, we propose an explainability-guided and model-agnostic testing framework for robustness of malware detectors when confronted with adversarial attacks. The framework introduces the concept of Accrued Malicious Magnitude (AMM) to identify which malware features could be manipulated to maximize the likelihood of evading detection. We then use this framework to test several state-of-the-art malware detectors' ability to detect manipulated malware. We find that (i) commercial antivirus engines are vulnerable to AMM-guided test cases; (ii) the ability of a manipulated malware generated using one detector to evade detection by another detector (i.e., transferability) depends on the overlap of features with large AMM values between the different detectors; and (iii) AMM values effectively measure the fragility of features (i.e., capability of feature-space manipulation to flip the prediction results) and explain the robustness of malware detectors facing evasion attacks. Our findings shed light on the limitations of current malware detectors, as well as how they can be improved.
Ruoxi Sun 0001, Minhui Xue 0001, Gareth Tyson, Tian Dong 0003, Shaofeng Li 0001, Shuo Wang 0012, Haojin Zhu, Seyit Ahmet Çamtepe, Surya Nepal
ESEC/SIGSOFT FSE4
2021 Hidden Backdoors in Human-Centric Language Models
abstract
Natural language processing (NLP) systems have been proven to be vulnerable to backdoor attacks, whereby hidden features (backdoors) are trained into a language model and may only be activated by specific inputs (called triggers), to trick the model into producing unexpected behaviors. In this paper, we create covert and natural triggers for textual backdoor attacks, hidden backdoors, where triggers can fool both modern language models and human inspection. We deploy our hidden backdoors through two state-of-the-art trigger embedding methods. The first approach via homograph replacement, embeds the trigger into deep neural networks through the visual spoofing of lookalike characters replacement. The second approach uses subtle differences between text generated by language models and real natural text to produce trigger sentences with correct grammar and high fluency. We demonstrate that the proposed hidden backdoors can be effective across three downstream security-critical NLP tasks, representative of modern human-centric NLP systems, including toxic comment detection, neural machine translation (NMT), and question answering (QA). Our two hidden backdoor attacks can achieve an Attack Success Rate (ASR) of at least 97% with an injection rate of only 3% in toxic comment detection, 95.1% ASR in NMT with less than 0.5% injected data, and finally 91.12% ASR against QA updated with only 27 poisoning data samples on a model previously trained with 92,024 samples (0.029%). We are able to demonstrate the adversary's high success rate of attacks, while maintaining functionality for regular users, with triggers inconspicuous by the human administrators.
Shaofeng Li 0001, Tian Dong 0003, Benjamin Zi Hao Zhao, Minhui Xue 0001, Haojin Zhu
CCS3