VLDB 2026 Research / reviewers in the wild / expert
Daniel Takabi
dblp:254/2719
· DBLP profile ↗
13ranked-venue papers
0as first author
13since 2021 · last 2026
0000-0003-0447-3641ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 4 · 4 since 2021Security and privacy · 4 · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Heterogeneous Graph Backdoor AttackabstractHeterogeneous Graph Neural Networks (HGNNs) excel in modeling complex, multi-typed relationships across diverse domains, yet their vulnerability to backdoor attacks remains unexplored. To address this gap, we conduct the first investigation into the susceptibility of HGNNs to existing graph backdoor attacks, revealing three critical issues: (1) high attack budget required for effective backdoor injection, (2) inefficient and unreliable backdoor activation, and (3) inaccurate attack effectiveness evaluation. To tackle these issues, we propose the Heterogeneous Graph Backdoor Attack (HGBA), the first backdoor attack specifically designed for HGNNs, introducing a novel relation-based trigger mechanism that establishes specific connections between a strategically selected trigger node and poisoned nodes via the backdoor metapath. HGBA achieves efficient and stealthy backdoor injection with minimal structural modifications and supports easy backdoor activation through two flexible strategies: Self-Node Attack and Indiscriminate Attack. Additionally, we improve the ASR measurement protocol, enabling a more accurate assessment of attack effectiveness. Extensive experiments demonstrate that HGBA far surpasses multiple state-of-the-art graph backdoor attacks in black-box settings, efficiently attacking HGNNs with low attack budgets. Ablation studies show that the strength of HBGA benefits from our trigger node selection method and backdoor metapath selection strategy. In addition, HGBA shows superior robustness against node feature perturbations and multiple types of existing graph backdoor defense mechanisms. Finally, extension experiments demonstrate that the relation-based trigger mechanism can effectively extend to tasks in homogeneous graph scenarios, thereby posing severe threats to broader security-critical domains. Lusi Li, Daniel Takabi, Masha Sosonkina, Rui Ning |
ICDCS | 3 |
| 2026 | MTD-integrated ABAC: integrating moving target defence into attribute-based access control for insider threat mitigationabstractInsider threats are prevalent security issues for organisations. While attribute-based access control (ABAC) systems manage sensitive data, they are not fully effective against insider threats. We propose integrating moving target defence (MTD) into ABAC systems to mitigate these threats. Our approach enhances the ABAC system with three modules: 1) a correlated attribute generator to estimate correlations among attribute-value pairs; 2) a policy sensitivity estimator to determine sensitivity levels of policy rules; 3) a mutation engine to dynamically mutate sensitive policy rules using correlated attributes. We evaluated our framework using a real-world dataset from an educational system, assessing the efficiency of the attribute generator, efficiency of the sensitivity estimator, overhead from the MTD components, and the framework's overall performance. Our results show that with a dataset of 200,000 records and 13 policy rules, the framework identified five sensitive rules and achieved a 100% mitigation rate without excessive overhead. Olusesi Balogun, Mohammad GhasemiGol, Zhipeng Cai 0001, Daniel Takabi |
Int. J. Inf. Comput. Secur. | 4 |
| 2025 | NEXUS: Network Exploration for eXploiting Unsafe Sequences in Multi-Turn LLM JailbreaksabstractLarge Language Models (LLMs) have revolutionized natural language processing, yet remain vulnerable to jailbreak attacks-particularly multi-turn jailbreaks that distribute malicious intent across benign exchanges, thereby bypassing alignment mechanisms.Existing approaches often suffer from limited exploration of the adversarial space, rely on hand-crafted heuristics, or lack systematic query refinement.We propose NEXUS (Network Exploration for eXploiting Unsafe Sequences), a modular framework for constructing, refining, and executing optimized multi-turn attacks.NEXUS comprises: (1) ThoughtNet, which hierarchically expands a harmful intent into a structured semantic network of topics, entities, and query chains;(2) a feedback-driven Simulator that iteratively refines and prunes these chains through attacker-victim-judge LLM collaboration using harmfulness and semantic-similarity benchmarks; and (3) a Network Traverser that adaptively navigates the refined query space for real-time attacks.This pipeline systematically uncovers stealthy, high-success adversarial paths across LLMs.Our experimental results on several closed-source and open-source LLMs show that NEXUS can achieve a higher attack success rate, between 2.1% and 19.4%, compared to state-of-the-art approaches.Our source code is available at github.com/inspire-lab/NEXUS. Javad Rafiei Asl, Sidhant Narula, Mohammad GhasemiGol, Eduardo Blanco 0002, Daniel Takabi |
EMNLP | 5 |
| 2025 | BlindTuner: On Enhancement of Privacy-Preserving Fine-Tuning of Transformers Based on Homomorphic EncryptionabstractFine-tuning pretrained models has emerged as a pivotal technique in machine learning, especially in situations with limited, task-aligned training data. However, challenges surface when data sharing encounters obstacles due to stringent privacy regulations or user apprehension regarding personal data disclosure. Earlier works based on secure multiparty computation (SMC) and fully homomorphic encryption (FHE) for privacy-preserving machine learning (PPML) focused more on privacy-preserving inference than privacy-preserving training. While privacy-preserving transfer learning has made progress, efficiency and accuracy tradeoffs remain a key limitation. In response to this gap, we introduce BlindTuner, a system that enables privacy-preserving fine-tuning by training data efficient image transformers (DEiT) directly on homomorphically encrypted data. Additionally, BlindTuner performs privacy-preserving inference, extending its usability beyond training. Experimental results show that BlindTuner achieves accuracy comparable to unencrypted models while delivering training speedups between$1.16{\times }$and$600{\times }$over existing approaches. Furthermore, we explore its application in privacy-preserving federated fine-tuning, enabling solution for collaborative learning without compromising privacy. Prajwal Panzade, Javad Rafiei Asl, Daniel Takabi, Zhipeng Cai 0001 |
IEEE Internet Things J. | 3 |
| 2025 | Privacy-Preserving Multimodal Sentiment AnalysisabstractMultimodal sentiment analysis plays a critical role in numerous IoT-driven applications, such as personalized smart assistants, healthcare monitoring systems, and intelligent transportation networks, where accurate interpretation of user emotions is vital for enhancing service quality. However, a severe threat of privacy leakage in the multimodal sentiment analysis has been overlooked by previous works. To fill this gap, we propose a Differentially Private Correlated Representation Learning (DPCRL) model to achieve privacy-preserving multimodal sentiment analysis by combining a correlated representation learning scheme with a differential privacy protection scheme. Our correlated representation learning scheme aims to achieve heterogeneous multimodal data transformation to meet the requirements of privacy-preserving multimodal sentiment analysis by learning the correlated and uncorrelated representations, where especially, a pre-determined correlation factor is employed to flexibly adjust the expected correlation among the correlated representations. The differential privacy protection scheme is used to obtain the disturbed correlated and uncorrelated representations by adding Laplace noise for -differential privacy. In particular, the correlation factor can help alleviate the side-effect of the added Laplace noise on the sentiment prediction performance. Finally, via conducting a series of real-data experiments, we validate that our proposed DPCRL model is superior to the state of the art for privacy-preserving multimodal sentiment analysis. Honghui Xu 0001, Wei Li 0059, Daniel Takabi, Zhipeng Cai 0001 |
IEEE Internet Things J. | 3 |
| 2024 | Memory Efficient Privacy-Preserving Machine Learning Based on Homomorphic Encryption
Robert Podschwadt, Parsa Ghazvinian, Mohammad GhasemiGol, Daniel Takabi |
ACNS (2) | 4 |
| 2024 | Privacy-Preserving Machine Learning Using Functional Encryption: Opportunities and ChallengesabstractWith the advent of functional encryption (FE), new possibilities for the computation of encrypted data have arisen. FE enables data owners to grant third-party access to perform specified computations without disclosing their inputs. It also provides computation results in plaintext, unlike fully homomorphic encryption (FHE). The ubiquitousness of machine learning (ML) has led to the collection of massive private data in the cloud computing environment. This raises potential privacy issues and underscores the need for more private and secure computing solutions. Numerous efforts have been made in privacy-preserving ML (PPML) to address security and privacy concerns. There are approaches based on FHE, secure multiparty computation (SMC), and, more recently, FE. Compared to FHE-based PPML techniques, FE-based PPML is still in its infancy. In this article, we provide a survey of PPML works based on FE, summarizing state-of-the-art literature. We focus on inner product-FE, function-hiding inner product encryption, and quadratic-FE-based ML models for PPML applications. We analyze the performance and usability of the available FE libraries and their applications to PPML. We also discuss future research directions for FE-based PPML approaches. To the best of our knowledge, this is the first work to survey FE-based PPML approaches. Prajwal Panzade, Daniel Takabi, Zhipeng Cai 0001 |
IEEE Internet Things J. | 2 |
| 2024 | A Semantic, Syntactic, and Context-Aware Natural Language Adversarial Example GeneratorabstractMachine learning models are vulnerable to maliciously crafted Adversarial Examples (AEs). Training a machine learning model with AEs improves its robustness and stability against adversarial attacks. It is essential to develop models that produce high-quality AEs. Developing such models has been much slower in natural language processing (NLP) than in areas such as computer vision. This paper introduces a practical and efficient adversarial attack model called SSCAE forSemantic,Syntactic, andContext-aware natural languageAEs generator. SSCAE identifies important words and uses a masked language model to generate an early set of substitutions. Next, two well-known language models are employed to evaluate the initial set in terms of semantic and syntactic characteristics. We introduce (1) a dynamic threshold to capture more efficient perturbations and (2) a local greedy search to generate high-quality AEs. As a black-box method, SSCAE generates humanly imperceptible and context-aware AEs that preserve semantic consistency and the source language's syntactical and grammatical requirements. The effectiveness and superiority of the proposed SSCAE model are illustrated with fifteen comparative experiments and extensive sensitivity analysis for parameter optimization. SSCAE outperforms the existing models in all experiments while maintaining a higher semantic consistency with a lower query number and a comparable perturbation rate. Javad Rafiei Asl, Mohammad Hossein Rafiei, Manar Alohaly, Daniel Takabi |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Self-Supervised Learning for ElectroencephalographyabstractDecades of research have shown machine learning superiority in discovering highly nonlinear patterns embedded in electroencephalography (EEG) records compared with conventional statistical techniques. However, even the most advanced machine learning techniques require relatively large, labeled EEG repositories. EEG data collection and labeling are costly. Moreover, combining available datasets to achieve a large data volume is usually infeasible due to inconsistent experimental paradigms across trials. Self-supervised learning (SSL) solves these challenges because it enables learning from EEG records across trials with variable experimental paradigms, even when the trials explore different phenomena. It aggregates multiple EEG repositories to increase accuracy, reduce bias, and mitigate overfitting in machine learning training. In addition, SSL could be employed in situations where there is limited labeled training data, and manual labeling is costly. This article: 1) provides a brief introduction to SSL; 2) describes some SSL techniques employed in recent studies, including EEG; 3) proposes current and potential SSL techniques for future investigations in EEG studies; 4) discusses the cons and pros of different SSL techniques; and 5) proposes holistic implementation tips and potential future directions for EEG SSL practices. Mohammad Hossein Rafiei, Lynne V. Gauthier, Hojjat Adeli, Daniel Takabi |
IEEE Trans. Neural Networks Learn. Syst. | 4 |
| 2023 | Towards Neural Network-Based Communication System: Attack and DefenseabstractRecent progress has witnessed the excellent success of neural networks in many emerging applications, such as image recognition, text classification, and speech analysis. In order to achieve secure communication, the utilization of neural networks has been realized yet has not raised sufficient research attention. In addition, the existing neural network-based communication system falls short due to its critical security flaws. In this article, we investigate the security vulnerabilities of the existing neural communication system. Based on our analysis, we design two kinds of attack models, includingtarget man-in-the-middle attackandtarget fraud attack. After that, to improve the security performance of neural communication systems, we develop a new defense mechanism to facilitate two-way secure communication by separating secret key from plaintext and incorporating defensive loss into the training process. Moreover, we show the effectiveness of our proposed neural communication system via theoretical proof. Finally, we implement comprehensive real data experiments to evaluate the performance of our attack and defense methods from the aspects of classification accuracy, communication efficiency and communication qualify, which confirms the advantages of our proposed neural communication system compared with the state-of-the-art. Zuobin Xiong, Zhipeng Cai 0001, Chunqiang Hu, Daniel Takabi, Wei Li 0059 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | Audio-Visual Autoencoding for Privacy-Preserving Video StreamingabstractThe demand of sharing video streaming extremely increases due to the proliferation of Internet of Things (IoT) devices in recent years, and the explosive development of artificial intelligent (AI) detection techniques has made visual privacy protection more urgent and difficult than ever before. Although a number of approaches have been proposed, their essential drawbacks limit the effect of visual privacy protection in real applications. In this article, we propose a cycle vector-quantized variational autoencoder (cycle-VQ-VAE) framework to encode and decode the video with its extracted audio, which takes the advantage of multiple heterogeneous data sources in the video itself to protect individuals’ privacy. In our cycle-VQ-VAE framework, a fusion mechanism is designed to integrate the video and its extracted audio. Particularly, the extracted audio works as the random noise with a nonpatterned distribution, which outperforms the noise that follows a patterned distribution for hiding visual information in the video. Under this framework, we design two models, including the frame-to-frame (F2F) model and video-to-video (V2V) model, to obtain privacy-preserving video streaming. In F2F, the video is processed as a sequence of frames; while, in V2V, the relations between frames are utilized to deal with the video, greatly improving the performance of privacy protection, video compression, and video reconstruction. Moreover, the video streaming is compressed in our encoding process, which can resist side-channel inference attack during video transmission and reduce video transmission time. Through the real-data experiments, we validate the superiority of our models (F2F and V2V) over the existing methods in visual privacy protection, visual quality preservation, and video transmission efficiency. The codes of our model implementation and more experimental results are now available athttps://github.com/ahahnut/cycle-VQ-VAE. Honghui Xu 0001, Zhipeng Cai 0001, Daniel Takabi, Wei Li 0059 |
IEEE Internet Things J. | 3 |
| 2022 | Privacy Threat and Defense for Federated Learning With Non-i.i.d. Data in AIoTabstractUnder the needs of processing huge amounts of data, providing high-quality service, and protecting user privacy in artificial intelligence of things (AIoT), federated learning (FL) has been treated as a promising technique to facilitate distributed learning with privacy protection. Although the importance of developing privacy-preserving FL has attracted a lot of attentions, the existing research only focuses on FL with independent identically distributed (i.i.d.) data and lacks study of non-i.i.d. scenario. What is worse, the assumption of i.i.d. data is impractical, reducing the performance of privacy protection in real applications. In this article, we carry out an innovative exploration of privacy protection in FL with non-i.i.d. data. First, a thorough analysis on privacy leakage in FL is conducted with proving the performance upper bound of privacy inference attack. Based on our analysis, a novel algorithm, 2DP-FL, is designed to achieve differential privacy by adding noise during training local models and when distributing global model. Especially, our 2DP-FL algorithm has a flexibility of noise addition to meet various needs and has a convergence upper bound. Finally, the real-data experiments can validate the results of our the oretical analysis and the advantages of 2DP-FL in privacy protection, learning convergence, and model accuracy. Zuobin Xiong, Zhipeng Cai 0001, Daniel Takabi, Wei Li 0059 |
IEEE Trans. Ind. Informatics | 3 |
| 2021 | Non-interactive Privacy Preserving Recurrent Neural Network Prediction with Homomorphic EncryptionabstractNeural networks have enabled many new and interesting applications in a wide variety of domains. However, deep learning models are very computationally expensive and outsourcing the computation to the Cloud creates privacy concerns. Homomorphic encryption (HE) allows computation on encrypted data, thus preserving its privacy. Common neural networks architectures, such as CNNs and fully connected networks, have been adapted for HE. However, there is very little work on recurrent neural networks (RNNs). Existing solutions for RNNs over encrypted data require interaction between the data owner and the Cloud. In this paper, we present parallel RNN blocks, an RNN architecture that can be run on encrypted data without client-server interaction. We describe our proposed approach and evaluate it on a real-world dataset of online product reviews and IMDb movie reviews. Our results are promising; we can achieve 88.8% F1 score on the product reviews. The model generalizes well to the IMDb data set with a 74.36% F1 score using our proposed architecture. The performance is within 3 percentage points of our baseline. Robert Podschwadt, Daniel Takabi |
CLOUD | 2 |