VLDB 2026 Research / reviewers in the wild / expert
Yilong Yang 0004
dblp:264/9367
· DBLP profile ↗
15ranked-venue papers
3as first author
13since 2021 · last 2026
0000-0002-2811-2667ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 6 since 2021Computer networks · 3 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Improving Sustainability of Adversarial Examples in Class-Incremental LearningabstractCurrent adversarial examples (AEs) are typically designed for static models. However, with the wide application of Class-Incremental Learning (CIL), models are no longer static and need to be updated with new data distributed and labeled differently from the old ones. As a result, existing AEs often fail after CIL updates due to significant domain drift. In this paper, we propose SAE to enhance the sustainability of AEs against CIL. The core idea of SAE is to enhance the robustness of AE semantics against domain drift by making them more similar to the target class while distinguishing them from all other classes. Achieving this is challenging, as relying solely on the initial CIL model to optimize AE semantics often leads to overfitting. To resolve the problem, we propose a Semantic Correction Module. This module encourages the AE semantics to be generalized, based on a generative model capable of producing universal semantics. Additionally, it incorporates the CIL model to correct the optimization direction of the AE semantics, guiding them closer to the target class. To further reduce fluctuations in AE semantics, we propose a Filtering-and-Augmentation Module, which first identifies non-target examples with target-class semantics in the latent space and then augments them to foster more stable semantics. Comprehensive experiments demonstrate that SAE outperforms baselines by an average of 31.28% when updated with a 9-fold increase in the number of classes. Taifeng Liu, Xinjing Liu, Liangqiu Dong, Yang Liu 0118, Yilong Yang 0004, Zhuo Ma 0001 |
AAAI | 5 |
| 2026 | PROTheft: A Projector-Based Model Extraction Attack in the Physical World
Xinjing Liu, Yilong Yang 0004, Taifeng Liu, Leo Yu Zhang, Yanjun Zhang 0002, Yang Liu 0118, Zhuo Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | Catch Me If You Can: Retain High Stealthiness and Durability of Backdoor Attack in Federated LearningabstractFederated Learning (FL) is vulnerable to backdoor attacks by design since it cannot inspect clients’ local data to protect their privacy. This privacy-preserving feature creates an opportunity for malicious clients to introduce backdoors. However, existing backdoor attacks face two main limitations. First, brute amplification (i.e., uniformly scaling up malicious parameters) can be easily detected, hence compromising attack stealthiness. Second, evasion strategies employed to prevent their backdoors from being overwritten by benign updates are frequently ineffective, reducing the overall attack stability upon model deployment. To address these limitations, we propose an adaptive proactive boosting strategy to enhance both the stealthiness and durability of backdoor attacks in FL. As a concrete example,ReBAintroduces a durable importance metric based on stability degrees of parameters as an update mask for malicious attackers, assigning higher weights to backdoor-related parameters during the update process. To ensure stealthiness,ReBAformulates an optimization problem regarding amplification factor by minimizing the distance between malicious and clean updates, thereby correcting malicious updates within a benign distance space. Extensive evaluations on 3 datasets and across 14 defenses demonstrate the efficacy ofReBA, outperforming over 12 baseline backdoor attacks. Our code is available at https://anonymous.4open.science/r/ReBA-D82F. Yilong Yang 0004, Xinjing Liu, Zefeng Wu, Zhuoran Ma 0002, Yong Zeng 0002, Xianjia Meng, Zhuo Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2026 | chamaeleon: Backdoor Attacks Against Vertical Federated Learning for Tabular DataabstractVertical federated learning (VFL) has made significant strides in enhancing data privacy and security for cross-silo applications. However, despite its benefits, VFL remains vulnerable to emerging security threats, particularly backdoor attacks. While most existing research on VFL backdoor attacks has focused on image and natural language processing tasks, the security of tabular data—commonly used in high-risk domains such as finance and healthcare—has been largely overlooked. In this paper, we introduce chamaeleon, a novel backdoor attack targeting VFL for tabular data. Our approach achieves two key advancements. First, to address the challenge of restricted label access in VFL, chamaeleon employs a two-step inference method to extract label information. This method combines a label classifier with a top-kconfidence filtering mechanism, enabling the precise identification of target-label samples (i.e., backdoored samples) with a precision of approximately 99.85%. Second, to overcome the limitations of fixed trigger patterns, which can disrupt the semantic integrity of tabular data (e.g., altering “male” to “pregnant”), chamaeleon introduces a dynamic trigger design. Each backdoored sample is injected with a unique trigger, generated by a transformer-based model inspired by large language models, ensuring semantic consistency. Additionally, a one-on-two adversarial game is implemented to optimize the generator’s performance with limited training data. Extensive evaluations across six models and six datasets demonstrate the effectiveness of our proposed attack. We also examine various factors that could influence the attack success and systematically analyze potential defense mechanisms to mitigate this newly identified threat. Yilong Yang 0004, Yong Zeng 0002, Shangze Li, Yang Liu 0118, Zhuo Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | SafeLead: Detecting and Excluding Random STS Attack in UWB Ranging System
Zhuo Ma 0001, Jiayu Jin, Yang Liu 0118, Yilong Yang 0004, Xinjing Liu, Teng Li 0003, Junwei Zhang 0001, Jianfeng Ma 0001 |
INFOCOM | 4 |
| 2025 | S-Teapot: Swift and Efficient Defense Against Patch-Based Backdoor AttackabstractRecent studies emphasize the serious threat posed by backdoor attacks when training deep models on data from untrustworthy sources. Despite the emergence of various backdoor attack paradigms, the patch-based approach stands out as the most sought-after and effective method of poisoning. However, current defenses against such attacks often exhibit rudimentary and highly inefficient, sometimes necessitating days for implementation. To mitigate this, we propose a swift and efficient defense against patch-based backdoor attacks, calledS-teapot.S-teapotrapidly identifies whether an untrusted dataset has been backdoored and determines the backdoored labels based on the model's high confidence in the poisoning sample and the consistency of the backdoor pixels.S-teapotoutperforms existing backdoor attack detection schemes by a speedup factor ranging from 30 to 259. Furthermore, we leverage the abnormality of the backdoor pixels to reverse the backdoor trigger, resulting in a similarity increase of 0.6 to 32 times compared to existing methods. To obtain a clean model,S-teapotaccurately localizes poisoning samples through similarity calculations, with nearly 100% precision. Leveraging the precision of the reverse triggers,S-teapotemploys an inpaint method to convert the poisoning samples into clean ones, yielding up to 8.16% improvement in accuracy. Yilong Yang 0004, Zhuo Ma 0001, Yihua Li, Yang Liu 0118, Xinjing Liu, Jianfeng Ma 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Need for Speed: Taming Backdoor Attacks with Speed and PrecisionabstractModern deep neural network models (DNNs) require extensive data for optimal performance, prompting reliance on multiple entities for the acquisition of training datasets. One prominent security threat is backdoor attacks where the adversary party poisons a small subset of training datasets to implant a backdoor into the model, leading to misclassifications during runtime for triggered samples. To mitigate the attack, many defense methods have been proposed, such as detecting and removing poisoned samples or rectifying trojaned model weights in victim DNNs. However, existing approaches suffer from notable inefficiency as they are faced with large-scale training datasets, consequently rendering these defenses impractical in the real world. In this paper, we propose a lightweight backdoor identification and removal scheme, called ReBack. In this scheme, ReBack first extracts a subset of suspicious and benign samples, and then, proceeds with a "averaging and differencing" based method to identify target label(s). Next, leveraging the identification results, ReBack invokes a novel reverse engineering method to recover the exact trigger using only basic arithmetic atoms. Our experiments demonstrate that, for ImageNet with 750 labels, ReBack can defend against backdoor attacks in around 2 hours, showcasing a speed improvement of 18.5× to 214× compared to existing methods. For backdoor removal, the attack success rate can be decreased to 0.05% owing to 99% cosine similarity of the reversed triggers. The code is online available. Zhuo Ma 0001, Yilong Yang 0004, Yang Liu 0118, Tong Yang 0003, Xinjing Liu, Teng Li 0003, Zhan Qin |
SP | 2 |
| 2024 | Mitigate noisy data for smart IoT via GAN based machine unlearning
Zhuo Ma 0001, Yilong Yang 0004, Yang Liu 0118, Xinjing Liu, Jianfeng Ma 0001 |
Sci. China Inf. Sci. | 2 |
| 2023 | LadderFilter: Filtering Infrequent Items with Small Memory and Time OverheadabstractData stream processing is critical in streaming databases. Existing works pay a lot of attention to frequent items. To improve the accuracy for frequent items, existing solutions focus on accurately filtering infrequent items. While these solutions are effective, they keep track of all infrequent items and require multiple hash computations and memory accesses. This increases memory and time overhead. To reduce this overhead, we propose LadderFilter, which candiscard infrequent items efficiently in terms of both memory and time. To achieve memory efficiency, LadderFilter discards (approximately) infrequent items using multiple LRU queues. To achieve time efficiency, we leverage SIMD instructions to implement LRU policy without timestamps. We apply LadderFilter to four types of sketches. Our experimental results show that LadderFilter improves the accuracy by up to 60.6×, and the throughput by up to 1.37×, and can maintain high accuracy with small memory usage. All related code is provided open-source at Github. Yuanpeng Li 0002, Feiyu Wang 0002, Yilong Yang 0004, Kaicheng Yang 0001, Tong Yang 0003, Zhuo Ma 0001, Bin Cui 0001, Steve Uhlig |
Proc. ACM Manag. Data | 4 |
| 2023 | Sniffer: A Novel Model Type Detection System against Machine-Learning-as-a-Service PlatformsabstractRecent works explore several attacks against Machine-Learning-as-a-Service (MLaaS) platforms (e.g., the model stealing attack), allegedly posing potential real-world threats beyond viability in laboratories. However, hampered by model-type-sensitive , most of the attacks can hardly break mainstream real-world MLaaS platforms. That is, many MLaaS attacks are designed against only one certain type of model, such as tree models or neural networks. As the black-box MLaaS interface hides model type info, the attacker cannot choose a proper attack method with confidence, limiting the attack performance. In this paper, we demonstrate a system, named Sniffer, that is capable of making model-type-sensitive attacks "great again" in real-world applications. Specifically, Sniffer consists of four components: Generator, Querier, Probe, and Arsenal. The first two components work for preparing attack samples. Probe, as the most characteristic component in Sniffer, implements a series of self-designed algorithms to determine the type of models hidden behind the black-box MLaaS interfaces. With model type info unraveled, an optimum method can be selected from Arsenal (containing multiple attack methods) to accomplish its attack. Our demonstration shows how the audience can interact with Sniffer in a web-based interface against five mainstream MLaaS platforms. Zhuo Ma 0001, Yilong Yang 0004, Bin Xiao 0002, Yang Liu 0118, Xinjing Liu, Zhuoran Ma 0002, Tong Yang 0003 |
Proc. VLDB Endow. | 2 |
| 2023 | Reveal Your Images: Gradient Leakage Attack Against Unbiased Sampling-Based Secure AggregationabstractRecently, some Unbiased Gradient Sampling-based (UGS) methods have been proposed to enhance the security and efficiency of federated learning through crafted unbiased random transformation and sampling, such as MinMax Sampling in SIGMOD ’22. In this paper, we propose a novel attack, GLAUS, to show that UGS is not as secure as claimed in these works and is still vulnerable to the gradient leakage attack (GLA). Specifically, we demonstrate an idea to approximately infer the gradient for GLA in the context of the UGS scenario where the real gradient is not available. Once the gradient is approximately obtained, the security of the UGS frameworks is downgraded to that of the original federated learning. The approximate gradient is refined by the following steps: 1)narrow the gradient searching rangeto the finite set; 2)obtain the magnitudeof each gradient value approximately; 3)revise the gradient signs. Versus the failure of existing attacks, extensive experiments on six datasets show that our attack is effective in reconstructing private datapoints with pixel-wise accuracy on four network sizes and three image resolutions. Finally, we show how to defend against GLAUS while maintaining the high efficiency of UGS and only introducing an additional step to hide the sampled gradient indices. Yilong Yang 0004, Zhuo Ma 0001, Bin Xiao 0002, Yang Liu 0118, Teng Li 0003, Junwei Zhang 0008 |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2022 | RevFRF: Enabling Cross-Domain Random Forest Training With Revocable Federated LearningabstractRandom forest is one of the most heated machine learning tools in a wide range of industrial scenarios. Recently, federated learning enables efficient distributed machine learning without direct revealing of private participant data. In this article, we present a novel framework of federated random forest (RevFRF), and further emphatically discuss the participant revocation problem of federated learning based on RevFRF. Specifically, RevFRF first introduces a suite of homomorphic encryption based secure protocols to implement federated random forest (RF). The protocols cover the whole lifecycle of an RF model, including construction, prediction and participant revocation. Then, referring to the practical application scenarios of RevFRF, the existing federated learning frameworks ignore a fact that even every participant in federated learning cannot maintain the cooperation with others forever. In company-level cooperation, allowing the remaining companies to use a trained model that contains the memories from an off-lying company potentially leads to a significant conflict of interest. Therefore, we propose the revocable federated learning concept and illustrate how RevFRF implements participant revocation in applications. Through theoretical analysis and experiments, we show that the protocols can efficiently implement federated RF and ensure the memories of a revoked participant in the trained RF to be securely removed. Yang Liu 0118, Zhuo Ma 0001, Yilong Yang 0004, Ximeng Liu, Jianfeng Ma 0001, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | Pyramid Family: Generic Frameworks for Accurate and Fast Flow Size MeasurementabstractSketches, as a kind of probabilistic data structures, have been considered as the most promising solution for network measurement in recent years. Most sketches do not work well for skewed network traffic. To address this problem, we propose a family of sketch frameworks, namely the Pyramid family. The first member of our Pyramid family is the S-Pyramid framework, which includes two techniques: counter-pair sharing for high accuracy, and word acceleration for fast speed. The second member of our Pyramid family is the Mini-Pyramid framework, which projects the S-Pyramid framework into one counter, bringing more flexibility in application while keeping the accuracy. To demonstrate the generality of our Pyramid family, we apply both frameworks to sketches of CM, CU, Count, and Augmented. To demonstrate the flexibility of the Mini-Pyramid framework, we further apply Mini-Pyramid to SBF and the On-Off sketch. The experimental results show that, the S-Pyramid framework can reduce the ARE by up to 7.12 times compared with the original sketches, while improving the throughput by up to 2.37 times; the Mini-Pyramid framework can reduce the ARE by up to 29.2 times, at the cost of 21.3% lower throughput on average. Yuanpeng Li 0002, Yilong Yang 0004, Yang Zhou 0008, Tong Yang 0003, Zhuo Ma 0001, Shigang Chen |
IEEE/ACM Trans. Netw. | 3 |
| 2020 | PE-HEALTH: Enabling Fully Encrypted CNN for Health Monitor with Optimized CommunicationabstractCloud-based Convolutional neural network (CNN) is a powerful tool for the healthcare center to provide health condition monitor service. Although the new service has future prospects in the medical, patient's privacy concerns arise because of the sensitivity of medical data. Prior works to address the concern have the following unresolved problems: 1) focus on data privacy but neglect to protect the privacy of the machine learning model itself; 2) introduce considerable communication costs for the CNN inference, which lowers the service quality of the cloud server. To push forward this area, we propose PE-HEALTH, a privacy-preserving health monitor framework that supports fully-encrypted CNN (both input data and model). In PE-HEALTH, the medical Internet of Things (IoT) sensor serves as the health condition data collector. For protecting patient privacy, the IoT sensor additively shares the collected data and uploads the shared data to the cloud server, which is efficient and suited to the energy-limited IoT sensor. To keep model privacy, PE-HEALTH allows the healthcare center to previously deploy, and then, use an encrypted CNN on the cloud server. During the CNN inference process, PE-HEALTH does not need the cloud servers to exchange any extra messages for operating the convolutional operation, which can greatly reduce the communication cost. Yang Liu 0118, Yilong Yang 0004, Zhuo Ma 0001, Ximeng Liu, Siqi Ma 0001 |
IWQoS | 2 |
| 2020 | EmIr-Auth: Eye Movement and Iris-Based Portable Remote Authentication for Smart GridabstractWith the development of Industry 4.0, the communication of smart grid has recently been taken seriously to ensure secure communication between operator and control center. However, the authentication process between them faces many challenges. Once the attacker successfully authenticated in the control center, the privacy data in the smart grid may leak and cause irreparable damage to the user. In addition, operator authentication is one of the most basic and crucial processes. Therefore, we propose theeye-movement and iris recognition based authentication (EmIr-Auth), a novel biometrics-based remote operator authentication scheme.EmIr-Authuses the recorded eye-movement trajectory and randomly selected iris image to authenticate operators, which is beneficial in that it is able to get rid of many cryptographic computations, as well as the need to minimize message exchange. Furthermore, except for a high-resolution camera, we do not require any additional biometric sensors in this scheme. Using the Burrows–Abadi–Needham logic, in this article, we demonstrate that our scheme provides secure authentication. Moreover, we analyze the attacks thatEmIr-Authcan resist by informal security analysis. Experimental results show thatEmIr-Authis efficient enough to deploy on portable devices and reduce the overhead of authentication procedure. Zhuo Ma 0001, Yilong Yang 0004, Ximeng Liu, Yang Liu 0118, Siqi Ma 0001, Kui Ren 0001 |
IEEE Trans. Ind. Informatics | 2 |