VLDB 2026 Research / reviewers in the wild / expert
Jiadong Lou
dblp:271/9833
· DBLP profile ↗
15ranked-venue papers
9as first author
12since 2021 · last 2025
0000-0003-3810-7877ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 6 · 4 first-author · 4 since 2021Security and privacy · 6 · 4 first-author · 5 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Towards Interpretable Adversarial Examples via Sparse Adversarial Attack
Fudong Lin, Jiadong Lou, Hao Wang 0022, Brian Jalaian, Xu Yuan 0001 |
ECML/PKDD (7) | 2 |
| 2025 | GRID: Protecting Training Graph from Link Stealing Attacks on GNN ModelsabstractGraph neural networks (GNNs) have exhibited superior performance in various classification tasks on graph-structured data. However, they encounter the potential vulnerability from the link stealing attacks, which can infer the presence of a link between two nodes via measuring the similarity of its incident nodes' prediction vectors produced by a GNN model. Such attacks pose severe security and privacy threats to the training graph used in GNN models. In this work, we propose a novel solution, called Graph Link Disguise (GRID), to defend against link stealing attacks with the formal guarantee of GNN model utility for retaining prediction accuracy. The key idea of GRID is to add carefully crafted noises to the nodes' prediction vectors for disguising adjacent nodes as n-hop indirect neighboring nodes. We take into account the graph topology and select only a subset of nodes (called core nodes) covering all links for adding noises, which can avert the noises offset and have the further advantages of reducing both the distortion loss and the computation cost. Our crafted noises can ensure 1) the noisy prediction vectors of any two adjacent nodes have their similarity level like that of two non-adjacent nodes and 2) the model prediction is unchanged to ensure zero utility loss. Extensive experiments on five datasets are conducted to show the effectiveness of our proposed GRID solution against different representative link-stealing attacks under transductive settings and inductive settings respectively, as well as two influence-based attacks. Meanwhile, it achieves a much better privacy-utility trade-off than existing methods when extended to GNNs. Jiadong Lou, Xu Yuan 0001, Xingliang Yuan, Neil Zhenqiang Gong, Nian-Feng Tzeng |
SP | 1 |
| 2025 | Variational Autoencoder Framework for Hyperspectral Retrievals (Hyper-VAE) of Phytoplankton Absorption and Chlorophyll a in Coastal Waters for NASA's EMIT and PACE MissionsabstractPhytoplankton absorb and scatter light in unique ways, subtly altering the color of water—changes that are often minor for human eyes to detect but can be captured by sensitive ocean color instruments onboard satellites from space. Hyperspectral sensors, paired with advanced algorithms, are expected to significantly enhance the characterization of phytoplankton community composition (PCC), especially in coastal waters where ocean color remote sensing applications have historically encountered significant challenges. This study presents novel machine learning-based solutions for NASA’s hyperspectral missions including EMIT (7nm), and PACE (2.5 nm), tackling high-fidelity retrievals of phytoplankton absorption coefficient (aphy) and chlorophyll a (Chl-a) from their hyperspectral remote sensing reflectance (Rrs). Given that a singleRrsspectrum may correspond to varied combinations of inherent optical properties (IOPs) and associated concentrations (e.g., Chl-a), the Variational Autoencoder (VAE) is used as a backbone in this study to handle such multi-distribution prediction problems. We first time tailor the VAE model with innovative designs to achieve hyperspectral retrievals ofaphyand of Chl-a from hyperspectralRrsin optically complex estuarine-coastal waters. Validation with extensive experimental observation demonstrates superior performance of the VAE models with high precision and low bias. The in-depth analysis of VAE’s advanced model structures and learning designs highlights the improvement and advantages of VAE-based solutions over the mixture density network (MDN) approach, particularly on high-dimensional data, such as PACE. Our study provides strong evidence that current EMIT and PACE hyperspectral data as well as the upcoming Surface Biology Geology (SBG) mission will open new pathways toward a better understanding of phytoplankton community dynamics in aquatic ecosystems when integrated with AI technologies. Jiadong Lou, Yuanheng Xiong, Xiaodong Zhang 0020, Xu Yuan 0001 |
IEEE Trans. Geosci. Remote. Sens. | 1 |
| 2024 | Towards Robust Vision Transformer via Masked Adaptive EnsembleabstractAdversarial training (AT) can help improve the robustness of Vision Transformers (ViT) against adversarial attacks by intentionally injecting adversarial examples into the training data. However, this way of adversarial injection inevitably incurs standard accuracy degradation to some extent, thereby calling for a trade-off between standard accuracy and adversarial robustness. Besides, the prominent AT solutions are still vulnerable to adaptive attacks. To tackle such shortcomings, this paper proposes a novel ViT architecture, including a detector and a classifier bridged by our newly developed adaptive ensemble. Specifically, we empirically discover that detecting adversarial examples can benefit from the Guided Backpropagation technique. Driven by this discovery, a novel Multi-head Self-Attention (MSA) mechanism is introduced for enhancing our detector to sniff adversarial examples. Then, a classifier with two encoders is employed for extracting visual representations respectively from clean images and adversarial examples, with our adaptive ensemble to adaptively adjust the proportion of visual representations from the two encoders for accurate classification. This design enables our ViT architecture to achieve a better trade-off between standard accuracy and adversarial robustness. Besides, the adaptive ensemble technique allows us to mask off a random subset of image patches within input data, boosting our ViT's robustness against adaptive attacks, while maintaining high standard accuracy. Experimental results exhibit that our ViT architecture, on CIFAR-10, achieves the best standard accuracy and adversarial robustness of 90.3 % and 49.8 %, respectively. Fudong Lin, Jiadong Lou, Xu Yuan 0001, Nian-Feng Tzeng |
CIKM | 2 |
| 2024 | EchoSensor: Fine-grained Ultrasonic Sensing for Smart Home Intrusion DetectionabstractThis article presents the design and implementation of a novel intrusion detection system, called EchoSensor, which leverages speakers and microphones in smart home devices to capture human gait patterns for individual identification. EchoSensor harnesses the speaker to send inaudible acoustic signals (around 20 kHz) and utilizes the microphone to capture the reflected signals. As the reflected signals have unique variations in the Doppler shift respective to the gaits of different people, EchoSensor is able to profile human gait patterns from the generated spectrograms. To mine the gait information, we first propose a two-stage interference cancellation scheme to remove the background noise and environmental interference, followed by a new method to detect the starting point of walking and estimate the gait cycle time. We then perform the fine-grained analysis of the spectrograms to extract a series of features. In the end, machine learning is employed to construct an identifier for individual recognition. We implement the EchoSensor system and deploy it under different household environments to conduct intrusion detection tasks. Extensive experimental results have demonstrated that EchoSensor can achieve the averaged Intruder Gait Detection Rate (IDR) and True Family Member Gait Detection Rate (TFR) of 92.7% and 91.9%, respectively. Changlai Du, Jiadong Lou, Li Chen 0019, Xu Yuan 0001 |
ACM Trans. Sens. Networks | 3 |
| 2024 | Room-scale Location Trace Tracking via Continuous Acoustic WavesabstractThe increasing prevalence of smart devices spurs the development of emerging indoor localization technologies for supporting diverse personalized applications at home. Given marked drawbacks of popular chirp signal-based approaches, we aim at developing a novel device-free localization system via the continuous wave of the inaudible frequency. To achieve this goal, solutions are developed for fine-grained analyses, able to precisely locate moving human traces in the room-scale environment. In particular, a smart speaker is controlled to emit continuous waves at inaudible 20kHz , with a co-located microphone array to record their Doppler reflections for localization. We first develop solutions to remove potential noises and then propose a novel idea by slicing signals into a set of narrowband signals, each of which is likely to include at most one body segment’s reflection. Different from previous studies, which take original signals themselves as the baseband, our solutions employ the Doppler frequency of a narrowband signal to estimate the velocity first and apply it to get the accurate baseband frequency, which permits a precise phase measurement after I-Q (i.e., in-phase and quadrature) decomposition. A signal model is then developed, able to formulate the phase with body segment’s velocity, range, and angle. We next develop novel solutions to estimate the motion state in each narrowband signal, cluster the motion states for different body segments corresponding to the same person, and locate the moving traces while mitigating multi-path effects. Our system is implemented with commodity devices in room environments for performance evaluation. The experimental results exhibit that our system can conduct effective localization for up to three persons in a room, with the average errors of 7.49 cm for a single person, with 24.06 cm for two persons, with 51.15 cm for three persons. Xu Yuan 0001, Jiadong Lou, Li Chen 0019, Hao Wang 0022, Nian-Feng Tzeng |
ACM Trans. Sens. Networks | 3 |
| 2023 | Data Privacy Examination against Semi-Supervised LearningabstractSemi-supervised learning, which learns with only a small amount of labeled data while collecting voluminous unlabeled data to aid its training, has achieved promising performance lately, but it also raises a serious privacy concern: Whether a user’s data has been collected for use without authorization. In this paper, we propose a novel membership inference method against semi-supervised learning, serving to protect user data privacy. Due to involving both the labeled and unlabeled data, the membership patterns of semi-supervised learning’s training data cannot be well captured by the existing membership inference solutions. To this end, we propose two new metrics, i.e., inter-consistency and intra-entropy, tailored specifically to the semi-supervised learning paradigm, able to respectively measure the similarity and calculate the cross-entropy among prediction vectors from the perturbed versions. By exploiting the two metrics for membership inference, our method can dig out membership patterns imprinted on prediction outputs of semi-supervised learning models, thus facilitating effective membership inference. Extensive experiments have been conducted for comparing our method with five rectified baseline inference techniques across four datasets on six semi-supervised learning algorithms. Experimental results exhibit that our inference method achieves over 80% accuracy under each experimental setting, substantially outperforming all baseline techniques. Jiadong Lou, Xu Yuan 0001, Miao Pan, Hao Wang 0022, Nian-Feng Tzeng |
AsiaCCS | 1 |
| 2023 | Devils in Your Apps: Vulnerabilities and User Privacy Exposure in Mobile Notification SystemsabstractWitnessing the blooming adoption of push notifications on mobile devices, this new message delivery paradigm has become pervasive in diverse applications. Accompanying with its broad adoption, the potential security risks and privacy exposure issues raise public concerns regarding its great social impacts. This paper conducts the first attempt to exploit the mobile notification ecosystem. By dissecting its structural elements and implementation process, a comprehensive vulnerability analysis is conducted towards the complete flow of mobile notification from platform enrollment to messaging. Meanwhile, for privacy exposure, we first examine the implementation of privacy policy compliance by proposing a three-level inspection approach to guide our analysis. Then, our top-down methods from documentation analysis, application network traffic study, to static analysis expose the illicit data collection behaviors in released applications. In addition, we uncover the potential privacy inference resulted from the notification monitoring. To support our analysis, we conduct empirical studies on 12 most popular notification platforms and perform static analysis over 30,000+ applications. We discover: 1) six platforms either provide ambiguous KEY naming rules or offer vulnerable messaging APIs; 2) privacy policy compliance implementations are either stagnated at the documentation stages (8 of 12 platforms) or never implemented in apps, resulting in billions of users suffering from privacy exposure; and 3) some apps can stealthily monitor notification messages delivering to other apps, potentially incurring user privacy inference risks. Our study raises the urgent demand for better regulations of mobile notification deployment. Jiadong Lou, Yihe Zhang 0001, Xinghua Li 0001, Xu Yuan 0001, Ning Zhang 0017 |
DSN | 1 |
| 2023 | Age of Information Optimization in Multi-Channel Based Multi-Hop Wireless NetworksabstractThe proliferation of IoT devices, with various capabilities in sensing, monitoring, and controlling, has prompted diverse emerging applications, highly relying on effective delivery of sensitive information gathered at edge devices to remote controllers for timely responses. To effectively deliver such information/status updates, this paper undertakes a holistic study of AoI in multi-hop networks by considering the relevant and realistic factors, aiming for optimizing information freshness by rapidly shipping sensitive updates captured at a source to its destination. In particular, we consider the multi-channel with OFDM (orthogonal frequency-division multiplexing) spectrum access in multi-hop networks and develop a rigorous mathematical model to optimize AoI at destination nodes. Real-world factors, including orthogonal channel access, wireless interference, and queuing model, are taken into account for the very first time to explore their impacts on the AoI. To this end, we propose two effective algorithms where the first one approximates the optimal solution as closely as we desire while the second one has polynomial time complexity, with a guaranteed performance gap to the optimal solution. The developed model and algorithms enable in-depth studies on AoI optimization problems in OFDM-based multi-hop wireless networks. Numerical results demonstrate that our solutions enjoy better AoI performance and that AoI is affected markedly by those realistic factors taken into our consideration. Jiadong Lou, Xu Yuan 0001, Purushottam Sigdel, Xiaoqi Qin, Sastry Kompella, Nian-Feng Tzeng |
IEEE Trans. Mob. Comput. | 1 |
| 2021 | Reverse Attack: Black-box Attacks on Collaborative RecommendationabstractCollaborative filtering (CF) recommender systems have been extensively developed and widely deployed in various social websites, promoting products or services to the users of interest. Meanwhile, work has been attempted at poisoning attacks to CF recommender systems for distorting the recommend results to reap commercial or personal gains stealthily. While existing poisoning attacks have demonstrated their effectiveness with the offline social datasets, they are impractical when applied to the real setting on online social websites. This paper develops a novel and practical poisoning attack solution toward the CF recommender systems without knowing involved specific algorithms nor historical social data information a priori. Instead of directly attacking the unknown recommender systems, our solution performs certain operations on the social websites to collect a set of sampling data for use in constructing a surrogate model for deeply learning the inherent recommendation patterns. This surrogate model can estimate the item proximities, learned by the recommender systems. By attacking the surrogate model, the corresponding solutions (for availability and target attacks) can be directly migrated to attack the original recommender systems. Extensive experiments validate the generated surrogate model's reproductive capability and demonstrate the effectiveness of our attack upon various CF recommender algorithms. Yihe Zhang 0001, Xu Yuan 0001, Jin Li 0002, Jiadong Lou, Li Chen 0019, Nian-Feng Tzeng |
CCS | 4 |
| 2021 | Messy States of Wiring: Vulnerabilities in Emerging Personal Payment Systems
Jiadong Lou, Xu Yuan 0001, Ning Zhang 0017 |
USENIX Security Symposium | 1 |
| 2021 | Boosting or Hindering: AoI and Throughput Interrelation in Routing-Aware Multi-Hop Wireless NetworksabstractWhile considerable work has addressed the optimal AoI under different circumstances in single-hop networks, the exploration of AoI in multi-hop wireless networks is rarely attempted. More importantly, the inherent relationships between AoI and throughput are yet to be explored, especially in multi-hop networks. This paper studies AoI in multi-hop wireless networks and explores its potential relationships with throughput for the very first time, particularly focusing on the impacts of flexible routes on the two metrics, i.e., AoI and throughput. By developing a rigorous mathematical model with interference, channel allocation, link scheduling, and routing path selection taken into consideration, we build the interrelation between AoI and throughput in multi-hop networks. A multi-criteria optimization problem is formulated with the goal of simultaneously minimizing AoI and maximizing network throughput. By qualitatively analyzing their relationships, we exhibit that the two metrics may conflict with each other, implying the optimal solutions for the multi-criteria problem will include a set of Pareto-optimal points rather than a single point existing in the traditional optimization problem. We resort to a novel approach by transforming the multi-criteria problem into a single objective one so as to find the weakly Pareto-optimal points iteratively, thereby allowing us to screen all Pareto-optimal points for the solution. Through formal proof, our solution is demonstrated to be able to identify all Pareto-optimal points and terminate in a finite number of iterations. We conduct the simulation evaluation to identify the optimal tradeoff points of AoI and throughput, demonstrating that one performance metric may improve at the expense of degrading the other, with the routing path found as one of the key factors in determining such a tradeoff. Jiadong Lou, Xu Yuan 0001, Sastry Kompella, Nian-Feng Tzeng |
IEEE/ACM Trans. Netw. | 1 |
| 2020 | Towards Poisoning the Neural Collaborative Filtering-Based Recommender Systems
Yihe Zhang 0001, Jiadong Lou, Li Chen 0019, Xu Yuan 0001, Jin Li 0002, Tom Johnsten, Nian-Feng Tzeng |
ESORICS (1) | 2 |
| 2020 | AoI and Throughput Tradeoffs in Routing-aware Multi-hop Wireless NetworksabstractThe Age-of-Information (AoI) is a newly introduced metric for capturing information updating timeliness, as opposed to the network throughput, which is a conventional performance metric to measure the network transmission speed and robustness as a whole. While considerable work has addressed either optimal AoI or throughput individually, the inherent relationships between the two performance metrics are yet to be explored, especially in multi-hop networks. In this paper, we explore their relationships in multi-hop networks for the very first time, particularly focusing on the impacts of flexible routes on the two metrics. By developing a rigorous mathematical model with interference, channel allocation, link scheduling, and routing path selection taken into consideration, we build the interrelation between AoI and throughput in multi-hop networks. A multi-criteria optimization problem is formulated with the goal of simultaneously minimizing AoI and maximizing network throughput. To solve this problem, we resort to a novel approach by transforming the multi-criteria problem into a single objective one so as to find the weakly Pareto-optimal points iteratively, thereby allowing us to screen all Pareto-optimal points for the solution. A new algorithm based on the piece-wise linearization technique is then developed to closely linearize the non-linear terms in the single objective problem via their linear approximation segments to make it solvable. We formally prove that our algorithms can find all Pareto-optimal points in a finite number of iterations. From simulation results, we identify the tradeoff points of the optimal AoI and throughput, demonstrating that one performance metric improves at the expense of degrading the other, with the routing path found as one of the key factors in determining such a tradeoff. Jiadong Lou, Xu Yuan 0001, Sastry Kompella, Nian-Feng Tzeng |
INFOCOM | 1 |
| 2020 | Instant AoI Optimization in IoT Networks with Packet CombinationabstractThis paper studies the freshness of data delivery, measured by the recently proposed Age of Information (AoI) metric, in Internet of Things (IoT) networks. Given IoT networks with plenty of edge devices to upload their sealed packets, re-packing multiple packets into one at each sink node by removing redundant packet headers could significantly improve transmission efficiency. We investigate such packet combination behaviors in transmitting the monitored/collected data from sensing nodes to accelerate data delivery, enabling the IoT edge server to acquire the latest updates timely. Two data acquisition modes, i.e., Periodic Request and Proactive Request, at the IoT edge server are considered. Under each mode, we derive the AoI formula, develop mathematical modeling, formulate the problem, and propose a low-complexity scheduling algorithm by leveraging packet combination with an aim to minimize the Instant AoI at the edge server. Through numerical results, we demonstrate the advantages of packet combination behaviors for AoI performance improvement. Jiadong Lou, Xu Yuan 0001, Nian-Feng Tzeng |
SECON | 1 |