VLDB 2026 Research / reviewers in the wild / expert
Yuepeng Hu
dblp:267/1159
· DBLP profile ↗
8ranked-venue papers
3as first author
7since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 2 first-author · 5 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fingerprinting LLMs via Prompt InjectionabstractYuepeng Hu, Zhengyuan Jiang, Mengyuan Li, Osama Ahmed, Zhicong Huang, Cheng Hong, Neil Zhenqiang Gong. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Yuepeng Hu, Zhengyuan Jiang, Osama Ahmed, Cheng Hong 0001, Neil Zhenqiang Gong |
ACL (1) | 1 |
| 2026 | Leave My Images Alone: Preventing Multi-Modal Large Language Models from Analyzing Images via Visual Prompt InjectionabstractMulti-modal large language models (MLLMs) have emerged as powerful tools for analyzing Internet-scale image data, offering significant benefits but also raising critical safety and societal concerns.In particular, open-weight MLLMs may be misused to extract sensitive information from personal images at scale, such as identities, locations, or other private details.In this work, we propose ImageProtector, a user-side method that proactively protects images before sharing by embedding a carefully crafted, nearly imperceptible perturbation that acts as a visual prompt injection attack on MLLMs.As a result, when an adversary analyzes a protected image with an MLLM, the MLLM is consistently induced to generate a refusal response such as "I'm sorry, I can't help with that request."We empirically demonstrate the effectiveness of ImageProtector across six MLLMs and four datasets.Additionally, we evaluate three potential countermeasures, Gaussian noise, DiffPure, and adversarial training, and show that while they partially mitigate the impact of ImageProtector, they simultaneously degrade model accuracy and/or efficiency.Our study focuses on the practically important setting of open-weight MLLMs and large-scale automated image analysis, and highlights both the promise and the limitations of perturbation-based privacy protection. Zedian Shao, Hongbin Liu 0005, Yuepeng Hu, Neil Zhenqiang Gong |
ACL (1) | 3 |
| 2025 | WebInject: Prompt Injection Attack to Web AgentsabstractMulti-modal large language model (MLLM)-based web agents interact with webpage environments by generating actions based on screenshots of the webpages. In this work, we propose WebInject, a prompt injection attack that manipulates the webpage environment to induce a web agent to perform an attacker-specified action. Our attack adds a perturbation to the raw pixel values of the rendered webpage. After these perturbed pixels are mapped into a screenshot, the perturbation induces the web agent to perform the attacker-specified action. We formulate the task of finding the perturbation as an optimization problem. A key challenge in solving this problem is that the mapping between raw pixel values and screenshot is non-differentiable, making it difficult to backpropagate gradients to the perturbation. To overcome this, we train a neural network to approximate the mapping and apply projected gradient descent to solve the reformulated optimization problem. Extensive evaluation on multiple datasets shows that WebInject is highly effective and significantly outperforms baselines. John Bloch, Zedian Shao, Yuepeng Hu, Shuyan Zhou, Neil Zhenqiang Gong |
EMNLP | 4 |
| 2025 | A Transfer Attack to Image WatermarksabstractWatermark has been widely deployed by industry to detect AI-generated images. The robustness of such watermark-based detector against evasion attacks in the white-box and black-box settings is well understood in the literature. However, the robustness in the no-box setting is much less understood. In this work, we propose a new transfer evasion attack to image watermark in the no-box setting. Our transfer attack adds a perturbation to a watermarked image to evade multiple surrogate watermarking models trained by the attacker itself, and the perturbed watermarked image also evades the target watermarking model. Our major contribution is to show that, both theoretically and empirically, watermark-based AI-generated image detector based on existing watermarking methods is not robust to evasion attacks even if the attacker does not have access to the watermarking model nor the detection API. Our code is available at: https://github.com/hifi-hyp/Watermark-Transfer-Attack. Yuepeng Hu, Zhengyuan Jiang, Moyang Guo, Neil Zhenqiang Gong |
ICLR | 1 |
| 2025 | Periodic Recovery From Poisoning Attacks in Machine LearningabstractRecovery from poisoning attacks aims to eliminate the influence of a given set of deleted poisoned training data on a model. In practice, model recovery often happensperiodicallysince data deletion occurs repeatedly after a model has been trained. Existing efficient model recovery methods are designed forsingle-shotmodel recovery. When applied to periodic model recovery, they treat the instances of recovery independently, leading to a large total overhead over time. In this work, we propose PeriRecover, an efficient periodic model recovery method. Our key idea is to extract some common information during the original model training, which can be used to accelerate all instances of model recovery. In particular, we propose to compute and store the diagonals of the Hessian matrix of the loss function during the original model training. Given such information, each instance of model recovery can efficiently estimate the gradients to update the model instead of exactly computing them. Theoretically, we show that the model recovered by PeriRecover is close to the one recovered by training-from-scratch under some assumptions, achievingcertified recovery. Empirically, we apply PeriRecover to supervised learning and recommender systems, and we consider targeted attacks and untargeted attacks. Our results show that PeriRecover is much more efficient and/or accurate than existing model recovery methods. Yuepeng Hu, Minghong Fang, Yuqi Jia 0001, Hongbin Liu 0005, Neil Zhenqiang Gong |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Certifiably Robust Image Watermark
Zhengyuan Jiang, Moyang Guo, Yuepeng Hu, Jinyuan Jia 0001, Neil Zhenqiang Gong |
ECCV (77) | 3 |
| 2023 | PORE: Provably Robust Recommender Systems against Data Poisoning Attacks
Jinyuan Jia 0001, Yupei Liu, Yuepeng Hu, Neil Zhenqiang Gong |
USENIX Security Symposium | 3 |
| 2020 | Combined Vector Resonant and Active Disturbance Rejection Control for PMSLM Current Harmonic SuppressionabstractA control method that combines a vector resonant controller and an active disturbance rejection control controller is proposed in this article for suppressing the current harmonics of permanent magnet synchronous linear motors. First, the resonant controller is improved by changing its transfer function so that it can suppress current harmonics better. Then, an active disturbance rejection control (ADRC) is designed to suppress the parameter disturbance of motors, which will adversely affect the improved resonant controller. The parameter disturbance is estimated by an extended state observer, and linear feedback control is used for disturbance compensation. The ADRC and the improved resonant controller work together to not only suppress harmonics but also improve resistance against system disturbance. Finally, a linear motor control platform is built, and experimental results are presented to verify the significance and correctness of the proposed approach. Jiwen Zhao, Yuepeng Hu |
IEEE Trans. Ind. Informatics | 5 |