VLDB 2026 Research / reviewers in the wild / expert
Huali Ren
dblp:278/1485
· DBLP profile ↗
6ranked-venue papers
1as first author
6since 2021 · last 2026
0009-0000-5823-8343ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AGFPS: An Automated Gradient-Free Framework for Prompt StealingabstractThe widespread deployment of large language models (LLMs) in downstream applications has increased the demand for high-quality system prompts, which have become valuable intellectual assets in the commercial prompt marketplace. Recent studies have demonstrated that system prompts are vulnerable to prompt stealing attacks, where adversaries can extract system prompts from LLM applications by crafting adversarial queries, thereby compromising developers' intellectual property and undermining existing business models. However, prior attack methods suffer from critical limitations including gradient dependency and poor scalability, severely restricting their practical applicability. To address these limitations, we present AGFPS, an automated gradient-free framework that leverages evolutionary optimization to systematically steal prompts. Our approach formulates prompt stealing as a discrete optimization problem, where adversarial queries are modeled as individuals in an evolving population. These individuals are optimized through elite retention, selection, adaptive crossover, and mutation operations. To mitigate local optima convergence, we introduce a progressive fitness evaluation strategy based on adaptive sequence fragmentation that exploits LLMs' autoregressive properties. Comprehensive evaluations across multiple benchmark datasets and mainstream LLMs demonstrates that AGFPS achieves a 95.2% exact system prompt stealing success rate, significantly outperforming manual baselines and surpassing gradient-based methods in 80.6% of scenarios. The generated adversarial queries exhibit remarkable transferability across heterogeneous models and diverse datasets, while maintaining robustness against various defense mechanisms. Our work exposes critical vulnerabilities in current LLM deployment practices and underscores the urgent need for enhanced security measures in LLM applications. Huali Ren, Anli Yan, Hongyang Yan, Chong-zhi Gao, Jin Li 0002 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Your Non-Transferable Learning is Fragile: Practical Breach of Protected ModelsabstractNon-transferable learning (NTL) has emerged as a promising method to protect the intellectual property of deep learning models by restricting cross-domain knowledge transfer. However, the robustness of its transferability constraints against potential attacks has not been explored, especially in practical deployment scenarios. In this paper, we propose a novel black-box attack framework - distribution drift learner (DDL), which effectively bypasses NTL protection mechanisms by only accessing input-output queries of protected models. The theoretical foundation of DDL is derived from the concept of data drift, which takes advantage of the variability of the statistical distribution between the source and target domains. The core innovation of DDL is the integration of distributed perception regularization into a lightweight autoencoder architecture, enabling efficient manipulation of data distribution by optimizing dual objectives (distributed perception loss and reconstruction loss). Training for DDL involves two key steps: First, DDL reconstructs a moderate amount of target domain samples and feeds the reconstructed images into the NTL model to obtain prediction labels. The DDL parameters are then updated by optimizing distributed perception loss and reconstruction loss. Through extensive experiments against standard NTL benchmarks (Digits, CIFAR10, and STL10), we demonstrate that DDL has successfully overcome the barriers of the transferable NTL model and improved the accuracy of the target domain by 81% from 10%. Our work reveals critical vulnerabilities in the NTL framework, particularly with respect to ownership verification and applicability authorization mechanisms, providing valuable insights for developing more robust model protection strategies in real-world applications. Anli Yan, Huali Ren, Kanghua Mo, Zhenxin Zhang, Hongyang Yan, Jin Li 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Enhancing Model Intellectual Property Protection With Robustness Fingerprint TechnologyabstractDeep neural network (DNN) models embody the intellectual property of a model owner, as the process of training the DNN model is a complex and resource-intensive task that requires significant investments in data preparation and computing resources. Numerous efforts have been made to protect the intellectual property of DNN models. However, existing methods often come with a critical limitation: they lack robustness, proving effective only in specific intellectual property threat scenarios or they either sacrifice the utility/accuracy of the model owner’s classifier because it interferes with the classifier’s training. To address these issues, we propose GMFIP, a novel generator-based model fingerprinting technology tailored for DNN intellectual property protection. GMFIP stands out for its robustness, extending its utility to various intellectual property threat scenarios rather than specific ones. Furthermore, GMFIP ensures that the utility/accuracy of the model is not affected by protection measures. Specifically, GMFIP begins with the training of the generator, which lays the groundwork for the model fingerprint. The generator generates fingerprints of the unique properties of the source model for verifying model ownership. To further improve the quality of these fingerprints, an extra selection phase dedicated to refining the fingerprints is integrated. Moreover, GMFIP is complemented by a binary classifier, which adapts the threshold setting to get optimal results. Our empirical evaluation includes an ablation study over four state-of-the-art technologies and three image benchmark datasets. Our results demonstrate that GMFIP outperforms other state-of-the-art technologies in effectively distinguishing pirated models from benign models. Anli Yan, Huali Ren, Kanghua Mo, Zhenxin Zhang, Shaowei Wang 0003, Jin Li 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Temperature-Based Watermarking and Detection for Large Language Models
Zhenxin Zhang, Huali Ren, Zhengdao Li |
ICA3PP (1) | 3 |
| 2022 | Inequality distance hyperplane multiclass support vector machinesabstractIn this study, inequality distance hyperplane multiclass support vector machines (IDH-MSVM) algorithm is proposed on the basis of multiclassification support vector machine (MSVM) which was proposed by J. Weston and C. Watkins in 1999. It only needs to solve a single objective optimization problem to deal with multiclassification problems. For original MSVM, the hyperplane distance refers to the classification interval between classical margin and hyperplane, which is equality. However, the IDH-MSVM introduces parameters to adjust distance between every classification hyperplane and classical margin, which makes the hyperplane distance inequality. The effectiveness of the proposed method is experimented on UCI standard data sets and compared with several multiclassification algorithms. Experimental results show that this method has a better classification effect on multiclassification data. Wangyong Lv, Huali Ren, Shijing Zeng |
Int. J. Intell. Syst. | 3 |
| 2022 | Knowledge graph and behavior portrait of intelligent attack against path planningabstractThe broad application of artificial intelligence (AI) shows more and more vulnerabilities. Adversaries have more opportunities to attack AI systems. For example, unmanned vehicles may be interfered with by adversaries in path planning, resulting in unmanned vehicles being unable to move according to the planned route, and even serious safety problems. On the other side, the portrait technology can extract highly refined characteristics of different attack strategies, so that unmanned vehicles can defend themselves based on the characteristics of each attack. Existing research lacks intelligent attack research on path planning in the field of unmanned vehicles, and lacks portraits of attack behaviors in this scenario. This paper combines multiagent reinforcement learning technology, time-series segmentation clustering technology, and knowledge graph technology to study the portrait technology of adversary intelligent attack behavior in the field of unmanned vehicle path planning. First, the simulation results of unmanned vehicle path planning are obtained, and the steps of adversary attack behavior are extracted by using Toeplitz inverse covariance-based clustering time-series segmentation cluster technology. Second, the knowledge graph is used to save the attack strategy, so as to form the attack behavior portrait of unmanned vehicle path planning. The test on the Neo4j platform shows that our method is universal, can effectively describe the attack steps for unmanned vehicle path planning, and provides the basis for attack detection to establish the defense system of unmanned vehicles. Li Zhang 0099, Huali Ren, Xiao Yu 0005, Quanxin Zhang 0001 |
Int. J. Intell. Syst. | 3 |