Zeyan Liu

dblp:284/4048 · DBLP profile ↗
← Back
11ranked-venue papers
3as first author
11since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 3 first-author · 9 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 LymphNode: A Plug-and-Play Access Control Method for Deep Neural Networks
Hanyu Pei, Zeyan Liu
DSN3
2025 Pinhole Effect on Linkability and Dispersion in Speaker Anonymization
abstract
Speaker anonymization aims to conceal speaker-specific attributes in speech signals, making the anonymized speech unlinkable to the original speaker identity. Recent approaches achieve this by disentangling speech into content and speaker components, replacing the latter with pseudo- speakers. The anonymized speech can be mapped either to a common pseudo-speaker shared across instances or to distinct pseudo-speakers unique to each instance. This paper investigates the impact of these mapping strategies on three key dimensions: speaker linkability, dispersion in the anonymized speaker space, and de-identification from the original identity. Our findings show that using distinct pseudo-speakers increases speaker dispersion and reduces linkability compared to common pseudo-speaker mapping, while maintaining de-identification, thereby enhancing overall privacy preservation. These observations are interpreted through the proposedpinhole effect, a conceptual framework introduced to explain the relationship between mapping strategies and anonymization performance. The hypothesis is validated through empirical evaluation.
Kong-Aik Lee, Zeyan Liu, Zhen-Hua Ling
IEEE Signal Process. Lett.2
2025 SnifferDog: Comprehensively Learning Heterogeneous Features of Network Traffic to Identify Malicious Flows
abstract
Deep learning has recently attracted significant attention in the field of network intrusion detection. Despite a substantial number of efforts have been made, previous works struggle to comprehensively learn the features of network traffic, resulting in inconsistent performance across various environments and attacks. To address these limitation, this study presents SnifferDog, a novel network attack detection system that takes raw packets as input and rationally extracts and integrates heterogeneous features involved in packets, flows and topology. It formats the packets and flows concurrently to achieve a high-level throughout for feature learning. Then, a flow pretraining model consisting of a LSTM, a self-attention and cross-attention layers is developed to learn both sequential and nonsequential inter packet relation features as initial flow vectors. Subsequently, a node-to-node and a node-to-edge attention layers are implemented to enhance an inductive GNN model that dynamically embeds the flow-to-flow and flow-to-topology relation features into the flow vectors. The resulting flow vectors involve comprehensive information of packet-to-packet, flow-to-flow and flow-to-topology relations, enabling high detection performance. In-lab experiments across eight datasets from diverse environments demonstrate SnifferDog’s superior effectiveness over existing solutions. A scalable prototype deployed in our institute’s network achieves a false positive rate of only 0.08%, validating SnifferDog’s practicality in real-world scenarios.
Lihua Yin, Zeyan Liu, Shijie Jia 0001, Bo Luo, Hongli Xiang
IEEE Trans. Inf. Forensics Secur.4
2024 On the Detectability of ChatGPT Content: Benchmarking, Methodology, and Evaluation through the Lens of Academic Writing
abstract
With ChatGPT under the spotlight, utilizing large language models (LLMs) to assist academic writing has drawn a significant amount of debate in the community. In this paper, we aim to present a comprehensive study of the detectability of ChatGPT-generated content within the academic literature, particularly focusing on the abstracts of scientific papers, to offer holistic support for the future development of LLM applications and policies in academia. Specifically, we first present GPABench2, a benchmarking dataset of over 2.8 million comparative samples of human-written, GPT-written, GPT-completed, and GPT-polished abstracts of scientific writing in computer science, physics, and humanities and social sciences. Second, we explore the methodology for detecting ChatGPT content. We start by examining the unsatisfactory performance of existing ChatGPT detecting tools and the challenges faced by human evaluators (including more than 240 researchers or students). We then test the hand-crafted linguistic features models as a baseline and develop a deep neural framework named CheckGPT to better capture the subtle and deep semantic and linguistic patterns in ChatGPT written literature. Last, we conduct comprehensive experiments to validate the proposed CheckGPT framework in each benchmarking task over different disciplines. To evaluate the detectability of ChatGPT content, we conduct extensive experiments on the transferability, prompt engineering, and robustness of CheckGPT.
Zeyan Liu, Zijun Yao 0001, Fengjun Li, Bo Luo
CCS1
2024 The Invisible Polyjuice Potion: an Effective Physical Adversarial Attack against Face Recognition
abstract
Face recognition systems have been targeted by recent physical adversarial machine learning attacks, which attach or project visible patterns on adversaries' faces to trick backend FR models. While these attacks have demonstrated effectiveness in the literature, they often rely on visibly suspicious patterns, are susceptible to environmental noise, or exhibit limited success rates in practice. In this paper, we propose a novel physical adversarial attack against deep face recognition systems, namely Agile (Adversarial Glasses with Infrared LasEr). It generates adjustable, invisible laser perturbations and emits them into the camera CMOS to launch dodging and impersonation attacks against facial biometrics systems. To do so, we first theoretically model physical adversarial perturbations and convert them to the digital domain. The generated synthesized attack signals are utilized to guide real-world laser settings. Our experiments with real-world attackers and a benchmark face database show that Agile is highly effective in DoS, dodging, and impersonation attacks. More importantly, the candidate impersonation target and optimal attack settings identified by Agile's attack synthesis approach are highly consistent with real-world physical attack results. The grey-box and black-box evaluation against commercial FR models also confirms the effectiveness of the Agile attack.
Zeyan Liu, Bo Luo, Rongqing Hui, Fengjun Li
CCS2
2024 The Adversarial AI-Art: Understanding, Generation, Detection, and Benchmarking
Zeyan Liu, Liangqin Ren, Fengjun Li, Jiebo Luo 0001, Bo Luo
ESORICS (1)2
2024 Exploring Audio-Visual Information Fusion for Sound Event Localization and Detection In Low-Resource Realistic Scenarios
abstract
This study presents an audio-visual information fusion approach to sound event localization and detection (SELD) in low-resource scenarios. We aim at utilizing audio and video modality information through cross-modal learning and multi-modal fusion. First, we propose a cross-modal teacher-student learning (TSL) framework to transfer information from an audio-only teacher model, trained on a rich collection of audio data with multiple data augmentation techniques, to an audiovisual student model trained with only a limited set of multimodal data. Next, we propose a two-stage audio-visual fusion strategy, consisting of an early feature fusion and a late video-guided decision fusion to exploit synergies between audio and video modalities. Finally, we introduce an innovative video pixel swapping (VPS) technique to extend an audio channel swapping (ACS) method to an audio-visual joint augmentation. Evaluation results on the Detection and Classification of Acoustic Scenes and Events (DCASE) 2023 Challenge data set demonstrate significant improvements in SELD performances. Furthermore, our submission to the SELD task of the DCASE 2023 Challenge ranks first place by effectively integrating the proposed techniques into a model ensemble.
Ya Jiang, Qing Wang 0008, Jun Du 0002, Maocheng Hu, Pengfei Hu 0006, Zeyan Liu, Shi Cheng 0001, Zhaoxu Nian, Mingqi Cai, Chin-Hui Lee 0001
ICME6
2024 Certificate Transparency Revisited: The Public Inspections on Third-party Monitors
Aozhuo Sun, Jingqiang Lin 0001, Wei Wang 0314, Zeyan Liu, Bingyu Li 0003, Shushang Wen, Qiongxiao Wang, Fengjun Li
NDSS4
2024 PrivDNN: A Secure Multi-Party Computation Framework for Deep Learning using Partial DNN Encryption
abstract
In the past decade, we have witnessed an exponential growth of deep learning models, platforms, and applications. While existing DL applications and Machine Learning as a service (MLaaS) frameworks assume fully trusted models, the need for privacy-preserving DNN evaluation arises. In a secure multi-party computation scenario, both the model and the data are considered proprietary, i.e., the model owner does not want to reveal the highly valuable DL model to the user, while the user does not wish to disclose their private data samples either. Conventional privacy-preserving deep learning solutions ask the users to send encrypted samples to the model owners, who must handle the heavy lifting of ciphertext-domain computation with homomorphic encryption. In this paper, we present a novel solution, namely, PrivDNN, which (1) offloads the computation to the user side by sharing an encrypted deep learning model with them, (2) significantly improves the efficiency of DNN evaluation using partial DNN encryption, (3) ensures model accuracy and model privacy using a core neuron selection and encryption scheme. Experimental results show that PrivDNN reduces privacy-preserving DNN inference time and memory requirement by up to 97% while maintaining model performance and privacy. Codes can be found at https://github.com/LiangqinRen/PrivDNN
Liangqin Ren, Zeyan Liu, Fengjun Li, Kaitai Liang, Bo Luo
Proc. Priv. Enhancing Technol.2
2022 LoneNeuron: A Highly-Effective Feature-Domain Neural Trojan Using Invisible and Polymorphic Watermarks
abstract
The wide adoption of deep neural networks (DNNs) in real-world applications raises increasing security concerns. Neural Trojans embedded in pre-trained neural networks are a harmful attack against the DNN model supply chain. They generate false outputs when certain stealthy triggers appear in the inputs. While data-poisoning attacks have been well studied in the literature, code-poisoning and model-poisoning backdoors only start to attract attention until recently. We present a novel model-poisoning neural Trojan, namely LoneNeuron, which responds to feature-domain patterns that transform into invisible, sample-specific, and polymorphic pixel-domain watermarks. With high attack specificity, LoneNeuron achieves a 100% attack success rate, while not affecting the main task performance. With LoneNeuron's unique watermark polymorphism property, the same feature-domain trigger is resolved to multiple watermarks in the pixel domain, which further improves watermark randomness, stealthiness, and resistance against Trojan detection. Extensive experiments show that LoneNeuron could escape state-of-the-art Trojan detectors. LoneNeuron~is also the first effective backdoor attack against vision transformers (ViTs).
Zeyan Liu, Fengjun Li, Zhu Li 0001, Bo Luo
CCS1
2022 Hide and Seek: On the Stealthiness of Attacks Against Deep Learning Systems
Zeyan Liu, Fengjun Li, Jingqiang Lin 0001, Zhu Li 0001, Bo Luo
ESORICS (3)1