Haoqi Wu

dblp:280/3416 · DBLP profile ↗
← Back
16ranked-venue papers
7as first author
15since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 6 · 2 first-author · 6 since 2021Artificial intelligence and machine learning · 4 · 3 first-author · 4 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Cape: Context-Aware Prompt Perturbation Mechanism with Differential Privacy
abstract
Large Language Models (LLMs) have gained significant popularity due to their remarkable capabilities in text understanding and generation. However, despite their widespread deployment in inference services such as ChatGPT, concerns about the potential leakage of sensitive user data have arisen. Existing solutions primarily rely on privacy-enhancing technologies to mitigate such risks, facing the trade-off among efficiency, privacy, and utility. To narrow this gap, we propose Cape, a context-aware prompt perturbation mechanism based on differential privacy, to enable efficient inference with an improved privacy-utility trade-off. Concretely, we introduce a hybrid utility function that better captures the token similarity. Additionally, we propose a bucketized sampling mechanism to handle large sampling space, which might lead to long-tail phenomenons. Extensive experiments across multiple datasets, along with ablation studies, demonstrate that Cape achieves a better privacy-utility trade-off compared to prior state-of-the-art works.
Haoqi Wu
ICML1
2025 ObCLIP: Oblivious CLoud-Device Hybrid Image Generation with Privacy Preservation
abstract
Diffusion Models have gained significant popularity due to their remarkable capabilities in image generation, albeit at the cost of intensive computation requirement. Meanwhile, despite their widespread deployment in inference services such as Midjourney, concerns about the potential leakage of sensitive information in uploaded user prompts have arisen. Existing solutions either fail to strike an effective balance between utility and efficiency, or lack rigorous privacy guarantees. To bridge this gap, we propose ObCLIP, a plug-and-play safeguard that enables oblivious cloud-device hybrid generation scheme. By oblivious, each input prompt is transformed into a set of semantically similar candidate prompts that differ only in sensitive attributes (e.g., gender, ethnicity). The cloud server processes all candidate prompts without knowing which one is the real one, thus preventing any prompt leakage. To mitigate server cost, only a small portion of denoising steps is performed upon the large cloud model. The resulting intermediate latents are then transmitted back to the device, which selects the targeted latent and completes the remaining denoising using a small local model to obtain the final image. Additionally, we analyze and incorporate several cache-based accelerations that leverage temporal and batch redundancy, effectively reducing computation cost with minimal utility degradation. Extensive experiments across multiple datasets demonstrate that ObCLIP provides rigorous privacy and comparable utility to large cloud models with slightly increased server computation.
Haoqi Wu
NeurIPS1
2025 Lightweight Mamba Model Based on Spiral Scanning Mechanism for Hyperspectral Image Classification
abstract
Hyperspectral image classification (HSIC) has advanced significantly in recent years, driven by the development of advanced algorithms in remote sensing. However, the high-dimensional nature of hyperspectral data and the limited availability of labeled samples remain significant challenges, hindering the effectiveness of many existing methods. To address these limitations, we propose SpiralMamba, a novel classification framework inspired by the recent Mamba model, renowned for its efficient global feature extraction with linear complexity. To minimize the loss of spatial information when converting images into sequences for Mamba processing, we propose the innovative spiral scan embedding (SSE) module. In addition, the introduction of the Gaussian mask weighting (GMW) module enhances the feature weights around the central pixel, thereby improving the classifiability of the extracted features. We introduce the lightweight Mamba module (LWM), which reduces model parameters and computational requirements, making it particularly well-suited for HSIC with limited samples. Experimental results on three real datasets demonstrate that the SpiralMamba model outperforms existing methods in various performance metrics.
Haoqi Wu, Lili Zhang 0005, Hanlin Guo
IEEE Geosci. Remote. Sens. Lett.2
2025 Bayesian detection for distributed targets in compound Gaussian sea clutter with lognormal texture
Hongzhi Guo 0001, Zhihang Wang, Haoqi Wu, Zishu He, Ziyang Cheng 0001
Signal Process.3
2025 Adaptive radar target detection in nonzero-mean compound Gaussian sea clutter with random texture
Haoqi Wu, Zhihang Wang, Hongzhi Guo 0001, Zishu He
Signal Process.1
2024 Ditto: Quantization-aware Secure Inference of Transformers upon MPC
abstract
Due to the rising privacy concerns on sensitive client data and trained models like Transformers, secure multi-party computation (MPC) techniques are employed to enable secure inference despite attendant overhead. Existing works attempt to reduce the overhead using more MPC-friendly non-linear function approximations. However, the integration of quantization widely used in plaintext inference into the MPC domain remains unclear. To bridge this gap, we propose the framework named Ditto to enable more efficient quantization-aware secure Transformer inference. Concretely, we first incorporate an MPC-friendly quantization into Transformer inference and employ a quantization-aware distillation procedure to maintain the model utility. Then, we propose novel MPC primitives to support the type conversions that are essential in quantization and implement the quantization-aware MPC execution of secure quantized inference. This approach significantly decreases both computation and communication overhead, leading to improvements in overall efficiency. We conduct extensive experiments on Bert and GPT2 models to evaluate the performance of Ditto. The results demonstrate that Ditto is about $3.14\sim 4.40\times$ faster than MPCFormer (ICLR 2023) and $1.44\sim 2.35\times$ faster than the state-of-the-art work PUMA with negligible utility degradation.
Haoqi Wu, Wenjing Fang, Yancheng Zheng, Junming Ma
ICML1
2024 Persymmetric Adaptive Detection Of Range-Spread Targets With Unknown Steering Vectors Based On Rao And Wald Tests
abstract
In this paper, we consider the detection of range-spread targets with unknown steering vectors for radar systems. Based on the Rao test and Wald test, we proposed two novel adaptive detectors of range-spread targets with unknown steering vectors. And we exploit the persymmetric property of the noise covariance matrix, which enables the two proposed detectors robust in the situation of limited training data. Moreover, we exploit a series of equivalent transformations to transform the test statistics into the real domain to prove the CFAR property concisely. Finally, the Monte Carlo simulations verify the effective detection performance of the proposed detectors. We found that the novel detectors perform well in a vast number of situations.
Hongzhi Guo 0001, Zhihang Wang, Haoqi Wu, Zishu He, Ziyang Cheng 0001
IGARSS3
2024 Adaptive Nonzero-Mean Detection Algorithm in Compound Gaussian Sea Clutter with Generalized Inverse Gaussian Texture
abstract
This paper deals with the target detection problem in nonzero-mean compound Gaussian (CG) sea clutter with the generalized inverse Gaussian (GIG) texture. With the improvement of radar resolution, the CG distribution is adopted to model the sea clutter. Then, considering the characteristics of real sea clutter, the CG model with the GIG texture is applied. Furthermore, sea clutter signals are assumed to be nonzero-mean. A novel adaptive two-step maximum a posteriori (MAP) generalized likelihood ratio test (GLRT) detection algorithm is proposed. Firstly, the test statistic of the proposed detector with known GIG texture, mean vector (MV), and covariance matrix (CM) is derived. Secondly, replacing with the estimates of GIG texture, MV, and CM, the adaptive detector can be acquired. The numerical results indicate the performance of the proposed detector.
Haoqi Wu, Hongzhi Guo 0001, Zhihang Wang, Zishu He
IGARSS1
2024 Nimbus: Secure and Efficient Two-Party Inference for Transformers
abstract
Transformer models have gained significant attention due to their power in machine learning tasks. Their extensive deployment has raised concerns about the potential leakage of sensitive information during inference. However, when being applied to Transformers, existing approaches based on secure two-party computation (2PC) bring about efficiency limitations in two folds: (1) resource-intensive matrix multiplications in linear layers, and (2) complex non-linear activation functions like $\mathsf{GELU}$ and $\mathsf{Softmax}$. This work presents a new two-party inference framework $\mathsf{Nimbus}$ for Transformer models. Specifically, we propose a new 2PC paradigm to securely compute matrix multiplications based on an outer-product insight, which achieves $2.9\times \sim 12.5\times$ performance improvements compared to the state-of-the-art (SOTA) protocol. Furthermore, through a new observation of utilizing the input distribution, we propose an approach of low-degree polynomial approximation for $\mathsf{GELU}$ and $\mathsf{Softmax}$, which improves the performance of the SOTA polynomial approximation by $2.9\times \sim 4.0\times$, where the average accuracy loss of our approach is 0.08\% compared to the non-2PC inference without privacy. Compared with the SOTA two-party inference, $\mathsf{Nimbus}$ improves the end-to-end performance of $BERT_{base}$ inference by $2.7\times \sim 4.7\times$ across different network settings.
Zhengyi Li 0002, Kang Yang 0002, Haoqi Wu, Xiao Wang 0012, Yu Yu 0001, Derun Zhao, Yancheng Zheng, Minyi Guo, Jingwen Leng
NeurIPS5
2024 Persymmetric Adaptive Detection for Dual-Polarimetric Radar in Lognormal Texture Sea Clutter
abstract
This letter deals with the target detection problem for polarimetric marine radar. The sea clutter is modelled as the compound Gaussian (CG) distribution with lognormal texture. We propose three detectors based on the two-step generalized likelihood ratio test (GLRT), the complex value Rao, and Wald tests by utilizing the persymmetric properties of the polarimetric speckle covariance matrix (CM). The lognormal texture component and the speckle CM are estimated by the maximuma posteriori(MAP) criterion and the polarimetric persymmetric fixed-point estimator, respectively. In addition, we provide proof of the constant false alarm rate (CFAR) properties of the designed polarimetric detectors. Moreover, we evaluate the detection performance of the proposed detectors in the simulated data and the measured sea clutter data, and the simulation results show the proposed detector outperforms the competitors more than 1dB in different situations.
Hongzhi Guo 0001, Zhihang Wang, Haoqi Wu, Zishu He, Ziyang Cheng 0001
IEEE Geosci. Remote. Sens. Lett.3
2024 Adaptive Persymmetric Subspace Detection in Non-Gaussian Sea Clutter With Structured Interference
abstract
This paper addresses the problem of subspace detection in the compound Gaussian sea clutter with lognormal texture and structured interference. We proposed three novel subspace detectors by two-step maximum a posteriori (MAP) generalized likelihood ratio test (GLRT), the Rao test, and the Wald test. In the first step, we assume the texture component and speckle covariance matrix (CM) are known, and we derive the test statistics of the proposed detectors. Then, in the second step, we substitute the estimated texture component and speckle CM to obtain the adaptive detectors. Further, we exploit the persymmetric property of the speckle CM to improve the detection performance of the proposed detectors. Moreover, we prove the constant false alarm rate (CFAR) properties of the novel subspace detectors with respect to the speckle covariance matrix and the scale parameter of the texture component of the non-Gaussian sea clutter. Besides, we verify the detection performance of the proposed subspace detectors by numerical experiments in both simulated and measured sea clutter. The simulation results show that the novel subspace detectors perform better than the comparison detectors in the case of limited training data, mismatched signals, and structured interference.
Hongzhi Guo 0001, Zhihang Wang, Haoqi Wu, Zishu He, Ziyang Cheng 0001
IEEE Trans. Geosci. Remote. Sens.3
2023 Adaptive Detection in Nonzero-Mean Compound Gaussian Sea Clutter with Inverse Gamma Texture
abstract
This paper deals with the target detection problem in nonzero-mean compound Gaussian sea clutter with inverse Gamma texture. Considering the improvement of radar resolution and the time-varying characteristics of real sea clutter, the compound Gaussian distribution with the inverse Gamma texture is adopted to model the sea clutter. Moreover, the mean of sea clutter signals is assumed to be nonzero and unknown. The novel adaptive detector based on the two-step maximum a posteriori (MAP) generalized likelihood ratio test (GLRT) is proposed. Firstly, we derive the test statistic of the proposed detector under the condition that the inverse Gamma texture, the mean vector (MV), and the covariance matrix (CM) are assumed to be known. Secondly, the adaptive detector can be obtained by replacing them with their estimates. Simulation experiments are conducted using the synthetic nonzero-mean compound Gaussian sea clutter data. The numerical results indicate the performance of the proposed detector.
Haoqi Wu, Luxin Dong, Zhihang Wang, Zishu He
IGARSS1
2023 SecretFlow-SPU: A Performant and User-Friendly Framework for Privacy-Preserving Machine Learning
Junming Ma, Yancheng Zheng, Derun Zhao, Haoqi Wu, Wenjing Fang, Chaofan Yu, Benyu Zhang, Lei Wang 0152
USENIX ATC5
2023 Improving Real-world Password Guessing Attacks via Bi-directional Transformers
Ming Xu 0006, Jitao Yu, Chuanwang Wang, Haoqi Wu, Weili Han
USENIX Security Symposium6
2022 pMPL: A Robust Multi-Party Learning Framework with a Privileged Party
abstract
In order to perform machine learning among multiple parties while protecting the privacy of raw data, privacy-preserving machine learning based on secure multi-party computation (MPL for short) has been a hot spot in recent. The configuration of MPL usually follows the peer-to-peer architecture, where each party has the same chance to reveal the output result. However, typical business scenarios often follow a hierarchical architecture where a powerful, usuallyprivileged party, leads the tasks of machine learning. Only theprivileged party can reveal the final model even if otherassistant parties collude with each other. It is even required to avoid the abort of machine learning to ensure the scheduled deadlines and/or save used computing resources when part ofassistant parties drop out.
Lushan Song, Zhexuan Wang, Xinyu Tu, Guopeng Lin, Wenqiang Ruan, Haoqi Wu, Weili Han
CCS7
2020 Automated Enforcement of the Principle of Least Privilege over Data Source Access
abstract
The state-of-the-art database-backed web applications usually assign full privileges to connections between applications and data sources. This phenomenon, which would enable a malicious attacker to easily compromise the applications through arbitrarily manipulating the data sources without the restriction of privileges, seriously breaks the principle of least privilege (PLP), a fundamental law of system security. Motivated to counter this problem, we propose a framework PDA (PLP over Data source Access) to automatically enforce this principle over data source access based on application-driven privilege separation. Our proposed PDA contributes from the following aspects: i) PDA achieves the privilege separation by intercepting database queries and enforcing privileged connections to database for each database query; ii) PDA can effectively defend against SQL-based vulnerabilities including buggy queries and SQL injection attacks. Lastly, we evaluate PDA on a widely used application platform, JForum, to demonstrate the effectiveness of PDA with a promising performance overhead of 8.13%.
Haoqi Wu, Zhengxuan Yu, Dapeng Huang, Weili Han
TrustCom1