VLDB 2026 Research / reviewers in the wild / expert
Qiyang Song
dblp:259/3559
· DBLP profile ↗
11ranked-venue papers
3as first author
9since 2021 · last 2026
0000-0002-1596-3331ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 2 · 1 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Focusing on Language: Revealing and Exploiting Language Attention Heads in Multilingual Large Language ModelsabstractLarge language models (LLMs) increasingly support multilingual understanding and generation. Meanwhile, efforts to interpret their internal mechanisms have emerged, offering insights to enhance multilingual performance. While multi-head self-attention (MHA) has proven critical in many areas, its role in multilingual capabilities remains underexplored. In this work, we study the contribution of MHA in supporting multilingual processing in LLMs. We propose Language Attention Head Importance Scores (LAHIS), an effective and efficient method that identifies attention head importance for multilingual capabilities via a single forward and backward pass through the LLM. Applying LAHIS to Aya-23-8B, Llama-3.2-3B, and Mistral-7B-v0.1, we reveal the existence of both language-specific and language-general heads. Language-specific heads enable cross-lingual attention transfer to guide the model toward target language contexts and mitigate off-target language generation issue, contributing to addressing challenges in multilingual LLMs. We also introduce a lightweight adaptation that learns a soft head mask to modulate attention outputs over language heads, requiring only 20 tunable parameters to improve XQuAD accuracy. Overall, our work enhances both the interpretability and multilingual capabilities of LLMs from the perspective of MHA. Qiyang Song, Qihang Zhou, Haichao Du, Shaowen Xu, Weijuan Zhang, Xiaoqi Jia |
AAAI | 2 |
| 2025 | Latent Knowledge Scalpel: Precise and Massive Knowledge Editing for Large Language ModelsabstractLarge Language Models (LLMs) often retain inaccurate or outdated information from pre-training, leading to incorrect predictions or biased outputs during inference. While existing model editing methods can address this challenge, they struggle with editing large amounts of factual information simultaneously and may compromise the general capabilities of the models. In this paper, our empirical study demonstrates that it is feasible to edit the internal representations of LLMs and replace the entities in a manner similar to editing natural language inputs. Based on this insight, we introduce the Latent Knowledge Scalpel (LKS), an LLM editor that manipulates the latent knowledge of specific entities via a lightweight hypernetwork to enable precise and large-scale editing. Experiments conducted on Llama-2 and Mistral show even with the number of simultaneous edits reaching 10,000, LKS effectively performs knowledge editing while preserving the general abilities of the edited LLMs. Code is available at: https://github.com/Linuxin-xxx/LKS. Qiyang Song, Shaowen Xu, Kerou Zhou, Xiaoqi Jia, Weijuan Zhang, Heqing Huang 0001, Yakai Li |
ECAI | 2 |
| 2025 | Stealthy Physical Backdoor Attacks Against Traffic Sign Recognition SystemsabstractRecent advancements in deep learning have led to remarkable progress in autonomous driving technology, with deep neural network (DNN)-based traffic sign recognition systems (TSRS) playing a crucial role. However, recent studies indicate that TSRS are vulnerable to backdoor attacks, where the backdoor TSRS behaves normally on clean traffic signs but consistently misclassifies backdoor-triggered traffic signs into a designated target class. Notably, while backdoor attacks in the digital domain are effective, their effectiveness may diminish in the physical world due to quality degradation during image transmission. Existing physical backdoor attacks typically rely on specific stickers or transformations as backdoor triggers, which are not stealthy and natural enough in the physical world. To address these limitations, we propose two stealthy physical backdoor attacks against DNN-based TSRS from two different perspectives. On the one hand, we utilize the natural phenomenon of chipped paints on traffic signs as the backdoor trigger. Specifically, we develop an automatic traffic sign segmentation algorithm to identify the edges of the target sign and simulate chipped paint to create poisoned samples. On the other hand, instead of manipulating the target traffic sign, we use the specific filter lens (attached to the in-vehicle camera) as the backdoor trigger, where the parameters of the filter lens are optimized by the Genetic Algorithm (GA). Extensive experiments conducted on the GTSRB and TSRD datasets demonstrate the effectiveness of our proposed backdoor attacks in both digital and physical environments. Wenbo Jiang 0001, Hongwei Li 0001, Shuai Yuan 0009, Rui Zhang 0086, Qiyang Song |
ICC | 7 |
| 2025 | Weaponizing Tokens: Backdooring Text-to-Image Generation via Token RemappingabstractText-to-image generative models have garnered immense attention for their ability to produce high-fidelity images from text prompts and enjoyed great popularity among the community. Unfortunately, previous studies have demonstrated that text-to-image models suffer from backdoor attacks, which enforce the text-guided generative models to generate images that align the backdoor target via embedding the textual triggers. However, the currently proposed backdoor attacks rely on numerous training data and complex computing resources for poisoning the core components in generative models, limiting the effectiveness and practicality in real-world scenarios. In this work, we first investigate the backdoor attack against Text-to-image generation by manipulating text tokenizer. Our backdoor attack exploits the semantic conditioning role of text tokenizer in the text-to-image generation. We propose an Automatized Remapping Framework with Optimized Tokens (AROT) for finding the best target tokens to remap the trigger token in the mapping space, according to different tasks. We conduct extensive experiments on Stable Diffusion and two defined tasks to demonstrate the effectiveness, stealthiness and robustness of our attack. Jiaming He, Wenbo Jiang 0001, Guanyu Hou, Qiyang Song, Ji Guo, Hongwei Li 0001 |
ICME | 4 |
| 2025 | When Hallucinated Concepts Cross Modals: Unveiling Backdoor Vulnerability in Multi-modal In-context LearningabstractDue to the remarkable performance of multi-modal large language models (MLLMs) in multi-modal capabilities, multi-modal in-context learning (M-ICL) has garnered widespread attention for fast adapting MLLMs to downstream tasks. However, the vulnerability of M-ICL to attacks remains largely unexplored. In this work, we take the first step to explore the backdoor vulnerability of M-ICL, which allows the adversary only to manipulate the multi-modal demonstration examples to mislead the victim model. We propose a multi-modal backdoor strategy on M-ICL via cross-modal concept mis-matching under black-box attack setting. Extensive experimental results demonstrate that our attacks exhibit high attack effectiveness while preserving the normal functionality of the victim model. Moreover, we further conduct experiments to prove our attacks are robust against backdoor defenses and still remain effective in various real-world conditions. Guanyu Hou, Jiaming He, Yitong Qiao, Jiachen Li 0002, Qiyang Song, Ji Guo, Wenbo Jiang 0001 |
MMAsia | 5 |
| 2025 | Silence False Alarms: Identifying Anti-Reentrancy Patterns on Ethereum to Refine Smart Contract Reentrancy Detection
Qiyang Song, Heqing Huang 0001, Xiaoqi Jia, Yuanbo Xie, Jiahao Cao 0001 |
NDSS | 1 |
| 2022 | GPSC: A Grid-Based Privacy-Reserving Framework for Online Spatial CrowdsourcingabstractSpatial crowdsourcing (SC) allows requesters to crowdsource tasks to workers based on location proximity. To preserve privacy, the location should not be disclosed to untrustworthy entities (even the SC platform). Previous solutions to preserve workers’ location privacy require an online trusty third party (TTP), which is not practical in reality. In this paper, we design a framework that allows the SC platform to assign tasks to nearest workers in an online manner without knowing their actual locations. We propose an encryption algorithm to encrypt the locations of tasks and workers, and design an indexing method that assigns tasks to workers without losing too much privacy. We prove that there exists a trade-off between efficiency and security theoretically, which can be controlled based on user preference. We verify our method on real-world datasets and experimental results show that our method is efficient, effective and practical. Haoda Li, Qiyang Song, Guoliang Li 0001, Qi Li 0002, Rengui Wang |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2021 | Try before You Buy: Privacy-preserving Data Evaluation on Cloud-based Machine Learning Data MarketplaceabstractA cloud-based data marketplace provides a service to match data shoppers with appropriate data sellers, so that data shoppers can augment their internal data sets with external data to improve their machine learning (ML) models. Since data may contain diverse values, it is critical for a shopper to evaluate the most valuable data before making the final trade. However, evaluating ML data typically requires the cloud to access a shopper’s ML model and sellers’ data, which are both sensitive. None of the existing cloud-based data marketplaces enable ML data evaluation while preserving both model privacy and data privacy. In this paper, we develop a privacy-preserving ML data evaluation framework on a cloud-based data marketplace to protect shoppers’ ML models and sellers’ data. First, we provide a privacy-preserving framework that allows shoppers and sellers to encrypt their models and data, respectively, while preserving data functionality and model functionality in the cloud. We then develop a privacy-preserving data selection protocol that enables the cloud to help shoppers select the most valuable ML data. Also, we develop a privacy-preserving data validation protocol that allows shoppers to further check the quality of the selected data. Compared to random data selection, the experimental results show that our solution can reduce 60% prediction errors. Qiyang Song, Jiahao Cao 0001, Kun Sun 0001, Qi Li 0002, Ke Xu 0002 |
ACSAC | 1 |
| 2021 | SAP-SSE: Protecting Search Patterns and Access Patterns in Searchable Symmetric EncryptionabstractSearchable symmetric encryption (SSE) enables users to search over encrypted documents in untrusted clouds without leaking the search keywords to the clouds. Existing SSE schemes achieve high search efficiency at the expense of leaking access patterns and search patterns, where clouds can recover a large percentage of queried keywords using the leaked access patterns and search patterns. To prevent clouds from recovering users' keywords, researchers have proposed a number of solutions to protect either search patterns or access patterns. However, none of them can protect both access patterns and search patterns. Moreover, existing SSE schemes cannot work in the generic database setting that allows multiple users to write or read over encrypted documents. In this paper, we propose an efficient searchable symmetric encryption scheme, called SAP-SSE, which protects both access patterns and search patterns in the generic database setting. The main idea of protecting search patterns is to leverage re-encryption cryptosystems to shuffle index entries over multiple clouds. To protect access patterns, we distribute secure indexes to multiple clouds and then propose an index redistribution protocol that allows users to renew index entries in clouds. Furthermore, SAP-SSE provides a configurable security policy to balance security and efficiency. Formal security analysis and experimental evaluation show that SAP-SSE can prevent pattern leakage with low overhead. Qiyang Song, Zhuotao Liu, Jiahao Cao 0001, Kun Sun 0001, Qi Li 0002, Cong Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2020 | SGX-Cube: An SGX-Enhanced Single Sign-On System Against Server-Side Credential Leakage
Qiyang Song, Kun Sun 0001, Qi Li 0002 |
SecureComm (2) | 2 |
| 2019 | cSFC: Building Credible Service Function Chain on the CloudabstractTo reduce the management costs, outsourcing network function (NF) to the cloud becomes prevalent in enterprises. This trend is increasing with the advent of network function virtualization (NFV). However, such outsourcing cannot guarantee the order and security of service function chains(SFCs) as the cloud is susceptible to attacks. In this paper, we introduce credible SFC (cSFC), a practical scheme to build secure service function chains on the untrusted cloud, cooperating with encrypted transport protocols. cSFC simultaneously shields NFs from an untrusted cloud and preserves the order of SFC sequence. Meanwhile, this scheme supports a wide range of NF functionalities and preserves the privacy of session data. We implement the cSFC prototype, and the evaluation result shows that it is practical with acceptable performance. Shengsheng Yao, Qi Li 0002, Jiahao Cao 0001, Qiyang Song |
GLOBECOM | 5 |