Yang-Wai Chow

dblp:27/1663 · DBLP profile ↗
← Back
38ranked-venue papers
13as first author
15since 2021 · last 2026
0000-0003-3348-7014ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 25 · 7 first-author · 9 since 2021Human-computer interaction and ubiquitous computing · 4 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 first-authorSystems, architecture and hardware · 1Computer networks · 1 · 1 first-author · 1 since 2021Theory of computation · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Adversarial-Example Agnostic Detection in Network Intrusion Detection Systems
Wei Zong, Yang-Wai Chow, Willy Susilo
ACISP (3)3
2025 AudioMarkNet: Audio Watermarking for Deepfake Speech Detection
Wei Zong, Yang-Wai Chow, Willy Susilo, Joonsang Baek, Seyit Ahmet Çamtepe
USENIX Security Symposium2
2025 Detecting Generative Model Inversion Attacks for Protecting Intellectual Property of Deep Neural Networks
abstract
Recently, protecting the Intellectual Property (IP) of deep neural networks (DNNs) has attracted attention from researchers. This is because training DNN models can be costly especially when acquiring and labeling training data require domain expertise. DNN watermarking and fingerprinting are two techniques proposed to prevent DNN IP infringement. Although these two techniques achieve high performance on defending against previously proposed DNN stealing attacks, researchers recently show that both of them are ineffective against generative model inversion attacks. Specifically, an adversary inverts training data from well-trained DNNs and uses the inverted data to train DNNs from scratch such that DNN watermarking and fingerprinting are both bypassed. This novel model stealing strategy shows that data inverted from victim models can be effectively exploited by adversaries, which poses a new threat to the IP protection of DNNs. To combat this new threat, one potential solution is to enable defenders to prove ownership on data inverted from models being protected. If the training data of a suspected model, which can be disclosed via the judicial process, are proven to be data inverted from victim models, then IP infringement is detected. This research direction is currently underexplored. In this paper, we fill the gap in the literature to investigate countermeasures against this emerging threat. We propose a simple but effective method, called InverseDataInspector (IDI), to detect whether data are inverted from victim models. Specifically, our method first extracts features from both the inverted data and victim models. These features are then combined and used for training classifiers. Experimental results demonstrate that our method achieves high performance on detecting inverted data and also generalizes to new generative model inversion methods that are not seen when training classifiers.
Yiding Yu, Wei Zong, Yang-Wai Chow, Willy Susilo
J. Artif. Intell. Res.4
2024 IPRemover: A Generative Model Inversion Attack against Deep Neural Network Fingerprinting and Watermarking
abstract
Training Deep Neural Networks (DNNs) can be expensive when data is difficult to obtain or labeling them requires significant domain expertise. Hence, it is crucial that the Intellectual Property (IP) of DNNs trained on valuable data be protected against IP infringement. DNN fingerprinting and watermarking are two lines of work in DNN IP protection. Recently proposed DNN fingerprinting techniques are able to detect IP infringement while preserving model performance by relying on the key assumption that the decision boundaries of independently trained models are intrinsically different from one another. In contrast, DNN watermarking embeds a watermark in a model and verifies IP infringement if an identical or similar watermark is extracted from a suspect model. The techniques deployed in fingerprinting and watermarking vary significantly because their underlying mechanisms are different. From an adversary's perspective, a successful IP removal attack should defeat both fingerprinting and watermarking. However, to the best of our knowledge, there is no work on such attacks in the literature yet. In this paper, we fill this gap by presenting an IP removal attack that can defeat both fingerprinting and watermarking. We consider the challenging data-free scenario whereby all data is inverted from the victim model. Under this setting, a stolen model only depends on the victim model. Experimental results demonstrate the success of our attack in defeating state-of-the-art DNN fingerprinting and watermarking techniques. This work reveals a novel attack surface that exploits generative model inversion attacks to bypass DNN IP defenses. This threat must be addressed by future defenses for reliable IP protection.
Wei Zong, Yang-Wai Chow, Willy Susilo, Joonsang Baek, Jongkil Kim, Seyit Ahmet Çamtepe
AAAI2
2024 The search term 'suicide' is being used to lead web browsers to online casinos
abstract
While Search Engine Optimisation seeks to enhance PageRankings, some methods are not approved or condoned by browser developers. To understand the risks faced by suicidal gamblers in the online environment, 2 studies examined the behaviour of an online search engine. A series of Google searches in 2021 used key terms such as ‘suicide’ and ‘gambling’ that might be employed by a suicidal gambler. During these searches browser ‘hits’ included opportunities to gamble. Webpages (N = 200) offered to a potentially suicidal gambler were primarily categorised as: other suicides (20%), treatment providers (8.5%), online casinos (7%); politics (22%), academic (23.5%). From a Google search providing 1,090 hits, the links to 113 online casinos were classified as a function of Domain Name hijacking, Metatag Stuffing, Error 404, and presence of Malware. There were significant relationships between the size of the businesses whose Domain Names were hijacked, and the presence of Malware. The deliberate use by webpage designers of the word ‘suicide’ to attract customers to online casinos appears inappropriate and ethically questionable.
James G. Phillips, Yang-Wai Chow, Heather Rogers, Alex Blaszczynski
Behav. Inf. Technol.2
2023 Sarcasm Relation to Time: Sarcasm Detection with Temporal Features and Deep Learning
Md Saifullah Razali, Alfian Abdul Halin, Yang-Wai Chow, Noris Mohd. Norowi, Shyamala C. Doraisamy
PRICAI (2)3
2023 HeSUN: Homomorphic Encryption for Secure Unbounded Neural Network Inference
Duy Tung Khanh Nguyen, Dung Hoang Duong, Willy Susilo, Yang-Wai Chow
SecureComm (1)4
2023 TrojanModel: A Practical Trojan Attack against Automatic Speech Recognition Systems
abstract
While deep learning techniques have achieved great success in modern digital products, researchers have shown that deep learning models are susceptible to Trojan attacks. In a Trojan attack, an adversary stealthily modifies a deep learning model such that the model will output a predefined label whenever a trigger is present in the input. In this paper, we present TrojanModel, a practical Trojan attack against Automatic Speech Recognition (ASR) systems. ASR systems aim to transcribe voice input into text, which is easier for subsequent downstream applications to process. We consider a practical attack scenario in which an adversary inserts a Trojan into the acoustic model of a target ASR system. Unlike existing work that uses noise-like triggers that will easily arouse user suspicion, the work in this paper focuses on the use of unsuspicious sounds as a trigger, e.g., a piece of music playing in the background. In addition, TrojanModel does not require the retraining of a target model. Experimental results show that TrojanModel can achieve high attack success rates with negligible effect on the target model’s performance. We also demonstrate that the attack is effective in an over-the-air attack scenario, where audio is played over a physical speaker and received by a microphone.
Wei Zong, Yang-Wai Chow, Willy Susilo, Kien Do, Svetha Venkatesh
SP2
2023 PCSF: Privacy-Preserving Content-Based Spam Filter
abstract
The purpose of privacy-preserving spam filtering is to inspect email while preserving the privacy of its detection rules and the email content. Although many solutions have emerged, they suffer from the following: 1) Theprivacyprovided is insufficient as the email content or detection rules may be exposed to third parties; 2) Due to improper use of encryption, exhaustive word search attacks are possible, potentially breaking theconfidentialityof encrypted emails; 3) When spam filtering is outsourced, email is given to the outsource, whereuser privacy may be compromisedif privacy protection measures are not properly put in place; 4) Confirmation of whether the encrypted email is spam is only determinedafterthe receiver receives the email, which can lead to a situation in which spam is loaded to the memory of the receiver’s terminal for spam filtering. This can be harmful, for example, when an attacker inserts a web browser vulnerability into the body of an email to lure users to a phishing site simply by reading the email; 5)Computationally expensive operationsare unavoidable to provide required features of privacy-preserving spam filtering. We present Privacy-preserving Content-based Spam Filter (PCSF), which is a spam filter system that does not suffer from the aforementioned issues. Additionally, our system providespre-validationbefore the receiver reads the email. We provide an implementation of our system based on the Naive Bayes spam filter and prove its security.
Intae Kim, Willy Susilo, Joonsang Baek, Jongkil Kim, Yang-Wai Chow
IEEE Trans. Inf. Forensics Secur.5
2022 Privacy-preserving file sharing on cloud storage with certificateless signcryption
Pairat Thorncharoensri, Willy Susilo, Yang-Wai Chow
Theor. Comput. Sci.3
2021 Towards Visualizing and Detecting Audio Adversarial Examples for Automatic Speech Recognition
Wei Zong, Yang-Wai Chow, Willy Susilo
ACISP2
2021 SyLPEnIoT: Symmetric Lightweight Predicate Encryption for Data Privacy Applications in IoT Environments
Tran Viet Xuan Phuong, Willy Susilo, Guomin Yang, Jongkil Kim, Yang-Wai Chow, Dongxi Liu
ESORICS (2)5
2021 Black-Box Audio Adversarial Example Generation Using Variational Autoencoder
Wei Zong, Yang-Wai Chow, Willy Susilo
ICICS (2)2
2021 Targeted Universal Adversarial Perturbations for Automatic Speech Recognition
Wei Zong, Yang-Wai Chow, Willy Susilo, Santu Rana, Svetha Venkatesh
ISC2
2021 Utilizing QR codes to verify the visual fidelity of image datasets for machine learning
Yang-Wai Chow, Willy Susilo, Jianfeng Wang 0001, Richard Buckland, Joonsang Baek, Jongkil Kim, Nan Li 0007
J. Netw. Comput. Appl.1
2020 Interactive three-dimensional visualization of network intrusion detection data for machine learning
Wei Zong, Yang-Wai Chow, Willy Susilo
Future Gener. Comput. Syst.2
2019 Dimensionality Reduction and Visualization of Network Intrusion Detection Data
Wei Zong, Yang-Wai Chow, Willy Susilo
ACISP2
2018 A 3D Approach for the Visualization of Network Intrusion Detection Data
abstract
With the increasing threat of cyber attacks, machine learning techniques have been researched extensively in the area of network intrusion detection. Such techniques can potentially provide a means for the real-time automated detection of attacks and abnormal traffic patterns. However, misclassification is a common problem in machine learning techniques for intrusion detection, and a lack of insight into why such misclassification occurs impedes the improvement of machine learning models. This paper presents an approach to visualizing network intrusion detection data in 3D. The purpose of this is to facilitate the understanding of network intrusion detection datasets using a visual representation to reflect the geometric relationship between various categories of network traffic. This can potentially provide useful insight to aid the design of machine learning techniques. This paper demonstrates the usefulness of the proposed 3D visualization approach by presenting results of experiments on commonly used network intrusion detection datasets.
Wei Zong, Yang-Wai Chow, Willy Susilo
CW2
2018 A Two-Stage Classifier Approach for Network Intrusion Detection
Wei Zong, Yang-Wai Chow, Willy Susilo
ISPEC2
2017 A QR Code Watermarking Approach Based on the DWT-DCT Technique
Yang-Wai Chow, Willy Susilo, Joseph Tonien, Wei Zong
ACISP (2)1
2017 Cooperative Learning in Information Security Education: Teaching Secret Sharing Concepts
Yang-Wai Chow, Willy Susilo, Guomin Yang
CDVE1
2017 Covert QR Codes: How to Hide in the Crowd
Yang-Wai Chow, Willy Susilo, Joonsang Baek
ISPEC1
2016 Exploiting the Error Correction Mechanism in QR Codes for Secret Sharing
Yang-Wai Chow, Willy Susilo, Guomin Yang, James G. Phillips, Ilung Pranata, Ari Moesriami Barmawi
ACISP (1)1
2016 Recipient Revocable Identity-Based Broadcast Encryption: How to Revoke Some Recipients in IBBE without Knowledge of the Plaintext
abstract
In this paper, we present the notion of recipient-revocable identity-based broadcast encryption scheme. In this notion, a content provider will produce encrypted content and send them to a third party (which is a broadcaster). This third party will be able to revoke some identities from the ciphertext. We present a security model to capture these requirements, as well as a concrete construction. The ciphertext consists of k+3 group elements, assuming that the maximum number of revocation identities is k. That is, the ciphertext size is linear in the maximal size of R, where R is the revocation identity set. However, we say that the additional elements compared to that from an IBBE scheme are only for the revocation but not for decryption. Therefore, the ciphertext sent to the users for decryption will be of constant size (i.e.,3 group elements). Finally, we present the proof of security of our construction.
Willy Susilo, Rongmao Chen, Fuchun Guo, Guomin Yang, Yi Mu 0001, Yang-Wai Chow
AsiaCCS6
2014 A Visual One-Time Password Authentication Scheme Using Mobile Devices
Yang-Wai Chow, Willy Susilo, Man Ho Au, Ari Moesriami Barmawi
ICICS1
2014 A CAPTCHA Scheme Based on the Identification of Character Locations
Vu Duc Nguyen, Yang-Wai Chow, Willy Susilo
ISPEC2
2014 On the security of text-based 3D CAPTCHAs
Vu Duc Nguyen, Yang-Wai Chow, Willy Susilo
Comput. Secur.2
2012 Breaking an Animated CAPTCHA Scheme
Vu Duc Nguyen, Yang-Wai Chow, Willy Susilo
ACNS2
2012 Attacking Animated CAPTCHAs via Character Extraction
Vu Duc Nguyen, Yang-Wai Chow, Willy Susilo
CANS2
2012 Enhancing the Perceived Visual Quality of a Size Invariant Visual Cryptography Scheme
Yang-Wai Chow, Willy Susilo, Duncan S. Wong
ICICS1
2012 Enhanced STE3D-CAP: A Novel 3D CAPTCHA Family
Yang-Wai Chow, Willy Susilo
ISPEC1
2012 Towards Formalizing a Reputation System for Cheating Detection in Peer-to-Peer-Based Massively Multiplayer Online Games
Willy Susilo, Yang-Wai Chow, Rungrat Wiangsripanawan
NSS2
2011 AniCAP: An Animated 3D CAPTCHA Scheme Based on Motion Parallax
Yang-Wai Chow, Willy Susilo
CANS1
2010 STE3D-CAP: Stereoscopic 3D CAPTCHA
Willy Susilo, Yang-Wai Chow, Hua-Yu Zhou
CANS2
2010 CAPTCHA Challenges for Massively Multiplayer Online Games: Mini-game CAPTCHAs
abstract
Botting or automated programs in Massively Multiplayer Online Games (MMOGs) has long been a problem in these networked virtual environments. The use of bots gives cheating players an unfair advantage over other honest players. Using bots, players can potentially amass a huge amount of game wealth, resources, experience points, etc. Without much effort, as bot programs can be run continuously for countless hours and will never get tired. Honest players on the other hand have to spend much more time and effort in order to gather an equal amount of game resources. This destroys the fun for legitimate players, ruins the balance of the game and threatens the game developer's revenue base as discontented players may stop playing the game. Research efforts have proposed the incorporation of CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) challenges in games to prevent or detect potential cheaters, by presenting challenges that are easy for a human to solve but are difficult for a computer to solve. However, the incorporation of CAPTCHA challenges in games is often seen in a negative light, as they are deemed to be intrusive and that they destroy the sense of immersion in the game. This research presents an approach of using CAPTCHAs in MMOGs that is both secure and adds game play value to the game.
Yang-Wai Chow, Willy Susilo, Hua-Yu Zhou
CW1
2005 Region warping in a virtual reality system with priority rendering
Yang-Wai Chow, Ronald Pose, Matthew Regan
IADIS AC1
2005 A networked virtual environment communications model using priority updating
Yang-Wai Chow, Ronald Pose, Matthew Regan
IADIS AC1
2005 Design issues in human visual perception experiments on region warping
Yang-Wai Chow, Ronald Pose, Matthew Regan
IADIS AC1