Yuexin Xuan

dblp:294/8069 · DBLP profile ↗
← Back
14ranked-venue papers
2as first author
14since 2021 · last 2026
0000-0001-7887-2309ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 7 · 2 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 6 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Computer networks · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 DeepTracer: Tracing Stolen Model via Deep Coupled Watermarks
abstract
Model watermarking techniques can embed watermark information into the protected model for ownership declaration by constructing specific input-output pairs. However, existing watermarks are easily removed when facing model stealing attacks, and make it difficult for model owners to effectively verify the copyright of stolen models. In this paper, we analyze the root cause of the failure of current watermarking methods under model stealing scenarios and then explore potential solutions. Specifically, we introduce a robust watermarking framework, DeepTracer, which leverages a novel watermark samples construction method and a same-class coupling loss constraint. DeepTracer can incur a high-coupling model between watermark task and primary task that makes adversaries inevitably learn the hidden watermark task when stealing the primary task functionality. Furthermore, we propose an effective watermark samples filtering mechanism that elaborately select watermark key samples used in model ownership verification to enhance the reliability of watermarks. Extensive experiments across multiple datasets and models demonstrate that our method surpasses existing approaches in defending against various model stealing attacks, as well as watermark attacks, and achieves new state-of-the-art effectiveness and robustness.
Yunfei Yang 0001, Xiaojun Chen 0004, Yuexin Xuan, Zhendong Zhao, He Li 0010
AAAI3
2026 Buster: Implanting Semantic Backdoor Into Text Encoder to Mitigate NSFW Content Generation
Xiaojun Chen 0004, Yuexin Xuan, Zhendong Zhao, Xinfeng Li, Xiaojun Jia, Xiaofeng Wang 0001
DASFAA (5)3
2026 Personalized Subgraph Federated Learning With Decoupled Data Heterogeneity in Mobile-Edge Computing
abstract
Graph Federated Learning (FL) has attracted extensive attention in recent years due to its ability to train global graph models in a distributed manner without exposing original local data. However, fine-grained data heterogeneity remains largely overlooked in collaborative graph model training. Existing graph FL methods that address heterogeneity are mostly adapted from traditional FL and fail to account for the unique complexity of graph-specific heterogeneity. Specifically, graph heterogeneity can be further decomposed into feature heterogeneity and structural heterogeneity, which are tightly coupled during local training. To address this issue, we propose a novel local graph module, Feature and Structure Decoupling Convolution (FSD-Conv), designed to disentangle the interplay between feature bias and structural bias. With FSD-Conv, clients can learn feature-related yet structure-unbiased representations, thereby alleviating the adverse impact of graph heterogeneity in federated training. Furthermore, we introduce FedFSD, a personalized graph FL framework that achieves effective personalized model aggregation through an explainable neural network operating in a low-dimensional space. Extensive experiments on six graph datasets under both disjoint and overlapping client partitioning schemes demonstrate the effectiveness of FedFSD in handling complex graph data heterogeneity.
Bisheng Tang, Xiaojun Chen 0004, Shaopu Wang, Yuexin Xuan, Zhendong Zhao, Xingyu Gao 0001
IEEE Trans. Mob. Comput.4
2025 Take Attention Inside: Neighbor Pair Graph Contrastive Learning
abstract
Graph Contrastive Learning(GCL) is a fundamental pretraining research method in Graph Neural Networks (GNNs), which puts rich graph-level insights into the graph data to augment the data representation. However, since the existing GCLs generally regard the intra-layer node as negative samples, they cannot cope with the diverse coupled neighbor relationships, which can be pre-trained with the combination of negative and positive samples. Coupled relationships can keep the attribute preference in node-level contrast and correctly pass this preference into the downstream tasks. To further prove the effectiveness of coupled neighbor relationships in the pretraining phase, we propose a novel GNN pretraining model Neighbor Pair Contrastive Graph Siamese Networks (NPC-GSN) for graph contrast. NPC-GSN expands the dissimilar neighbor’s representation discrepancy and decreases the representation discrepancy of similar neighbors in the pretraining phase, aiming to promote downstream node classification. Our extensive experiments on five graph datasets against several pretraining GNN models demonstrate the competitive effectiveness of NPC-GSN in node classification, and the frequency domain and ablation experiments also verify the effectiveness of NPC-GSN.
Bisheng Tang, Xiaojun Chen 0004, Shaopu Wang, Yuexin Xuan, Zhendong Zhao
ICASSP4
2025 Model-Guardian: Protecting against Data-Free Model Stealing Using Gradient Representations and Deceptive Predictions
abstract
Model stealing attack is increasingly threatening the confidentiality of machine learning models deployed in the cloud. Recent studies reveal that adversaries can exploit data synthesis techniques to steal machine learning models even in scenarios devoid of real data, leading to data-free model stealing attacks. Existing defenses against such attacks suffer from limitations, including poor effectiveness, insufficient generalization ability, and low comprehensiveness. In response, this paper introduces a novel defense framework named Model-Guardian. Comprising two components, Data-Free Model Stealing Detector (DFMS-Detector) and Deceptive Predictions (DPreds), Model-Guardian is designed to address the shortcomings of current defenses with the help of the artifact properties of synthetic samples and gradient representations of samples. Extensive experiments on seven prevalent data-free model stealing attacks showcase the effectiveness and superior generalization ability of Model-Guardian, outperforming eleven defense methods and establishing a new state-of-the-art performance. Notably, this work pioneers the utilization of various GANs and diffusion models for generating highly realistic query samples in attacks, with Model-Guardian demonstrating accurate detection capabilities.
Yunfei Yang 0001, Xiaojun Chen 0004, Yuexin Xuan, Zhendong Zhao
ICME3
2024 Lightweight Secure Aggregation for Personalized Federated Learning with Backdoor Resistance
abstract
Existing federated learning (FL) systems are highly vulnerable in terms of security and privacy due to their distributed architecture, facing poisoning attacks and inference attacks from adversaries. Some prior works have combined poisoning defenses with cryptographic tools: Secure Multi-Party Computation, Zero-Knowledge Proof, and Homomorphic Encryption to propose robust secure aggregation methods that provide security and privacy preservation for FL. Recently, Qin et al. (KDD’23) demonstrate that personalized federated learning (pFL) can effectively resist backdoor injection in poisoning attacks. In this paper, we analyze that as the number of malicious attackers increases, pFL remains vulnerable to backdoor attacks. Moreover, we reveal that current robust secure aggregation methods fail to offer efficient and robust backdoor defense for pFL. Therefore, we propose FLIGHT, a robust secure aggregation method for pFL. It implements a lightweight backdoor detection through a two-stage personalized defense mechanism and ensures privacy preservation using communication-efficient two-party secure computation (2PC) protocols. Extensive experiments on diverse datasets and neural networks validate that FLIGHT decreases run-time up to 64× compared by prior work RoFL (S&P’23), and 42× compared to FLAME (USENIX Security’22).
Tingyu Fan, Xiaojun Chen 0004, Ye Dong, Yuexin Xuan, Weizhan Jing
ACSAC5
2024 DualCOS: Query-Efficient Data-Free Model Stealing with Dual Clone Networks and Optimal Samples
abstract
Although data-free model stealing attacks are free from reliance on real data, they suffer from limitations, including low accuracy and high query budgets, which restrict their practical feasibility. In this paper, we propose a novel data-free model stealing framework called DualCOS. As a whole, DualCOS is divided into two stages: interactive training and semi-supervised boosting. To optimize the usage of query budgets, we use a dual clone model architecture to address the challenge of querying victim model during generator training. We also introduce active learning-based sampling strategy and sample reuse mechanism to achieve an efficient query process. Furthermore, once query budget is exhausted, the semi-supervised boosting is employed to continue improving the final clone accuracy. Through extensive evaluations, we demonstrate the superiority of our proposed method in terms of accuracy and query efficiency, particularly in scenarios involving hard labels and multiple classes.
Yunfei Yang 0001, Xiaojun Chen 0004, Yuexin Xuan, Zhendong Zhao
ICME3
2024 STMS: An Out-Of-Distribution Model Stealing Method Based on Causality
abstract
Machine learning, particularly deep learning, is extensively applied in various real-life scenarios. However, recent research has highlighted the severe infringement of privacy and intellectual property caused by model stealing attacks. Therefore, more researchers are dedicated to studying the principles and methods of such attacks to promote the security development of artificial intelligence. Most of the existing model stealing attacks rely on prior information of the attacked models and consider ideal conditions. In order to better understand and defend against model stealing in real-world scenarios, we propose a novel model stealing method, named STMS, based on causal inference learning. For the first time, we introduce the problem of out-of-distribution generalization into the model stealing domain. The proposed approach operates under more challenging conditions, where the training and testing data of the target model are unknown, black-box, hard-label outputs, and there is a distribution shift during the testing phase. STMS achieves comparable or better stealing accuracy and generalization performance than prior works on multiple datasets and tasks. Moreover, this universal framework can be applied to improve the effectiveness of other model stealing methods and can also be migrated to other areas of machine learning.
Yunfei Yang 0001, Xiaojun Chen 0004, Zhendong Zhao, Yuexin Xuan, Bisheng Tang
IJCNN4
2023 Unsupervised Graph Structure-Assisted Personalized Federated Learning
abstract
Non-IID data presents a significant challenge for federated learning(FL), and personalized FL is a natural solution to address this challenge. Recently, Graph Neural Network (GNN) has recently emerged to model the complex client relationship using a client graph to refine personalized models. However, this approach depends on an existing client relation graph on the server, making it impractical unless this prerequisite is satisfied. Furthermore, noisy and missing connections in the original graph structures can degrade personalization performance. In this work, we propose an unsupervised structure learning approach to improve personalized FL, where the server learns a dynamic client graph through self-supervision and generates structure-based client representations. These representations are then broadcasted to users, regulating local training using the learned knowledge as an inductive bias. Empirical studies on benchmark datasets demonstrate the significant effectiveness of our approach and the high quality of the client graphs. The code is available at https://github.com/lazyJane/FedSKA.
Xiaojun Chen 0004, Bisheng Tang, Shaopu Wang, Yuexin Xuan, Zhendong Zhao
ECAI5
2023 Practical and General Backdoor Attacks Against Vertical Federated Learning
Yuexin Xuan, Xiaojun Chen 0004, Zhendong Zhao, Bisheng Tang, Ye Dong
ECML/PKDD (2)1
2023 Generalized heterophily graph data augmentation for node classification
Bisheng Tang, Xiaojun Chen 0004, Shaopu Wang, Yuexin Xuan, Zhendong Zhao
Neural Networks4
2022 DEFEAT: Deep Hidden Feature Backdoor Attacks by Imperceptible Perturbation and Latent Representation Constraints
abstract
Backdoor attack is a type of serious security threat to deep learning models. An adversary can provide users with a model trained on poisoned data to manipulate prediction behavior in test stage using a backdoor. The backdoored models behave normally on clean images, yet can be activated and output incorrect prediction if the input is stamped with a specific trigger pattern. Most existing backdoor attacks focus on manually defining imperceptible triggers in input space without considering the abnormality of triggers' latent representations in the poisoned model. These attacks are susceptible to backdoor detection algorithms and even visual inspection. In this paper, We propose a novel and stealthy backdoor attack - DEFEAT. It poisons the clean data using adaptive imperceptible perturbation and restricts latent representation during training process to strengthen our attack's stealthiness and resistance to defense algorithms. We conduct extensive experiments on multiple image classifiers using real-world datasets to demonstrate that our attack can 1) hold against the state-of-the-art defenses, 2) deceive the victim model with high attack success without jeopardizing model utility, and 3) provide practical stealthiness on image data.
Zhendong Zhao, Xiaojun Chen 0004, Yuexin Xuan, Ye Dong, Dakui Wang, Kaitai Liang
CVPR3
2022 ACTSS: Input Detection Defense against Backdoor Attacks via Activation Subset Scanning
abstract
Deep neural networks are vulnerable to backdoor attacks where adversaries inject the trigger into partial training data to manipulate the trained model misclassification. In addition, the poisoned model behaves normally on clean inputs, and the malicious behavior only occurs when the secret trigger is present, making backdoor attacks hard to be detected. Most existing input detection methods leverage the link between triggers and outputs to reveal the poisoned inputs, which suffer from the trigger-size or the “all-to-all” attack scenario. We show that the internal activations produced by benign and poisoned inputs are significantly different in the poisoned model. In this paper, we propose a novel and run-time input detection algorithm, Activation Subset Scanning (ACTSS), which extracts the activations of incoming inputs and leverages an anomaly detection algorithm to identify malicious inputs. We search and score for the abnormal activation subset according to the statistical difference of activations between benign and poisoned data using nonparametric statistics technology. Extensive experiments are conducted on three public datasets: CIFAR10, GTSRB, and ImageNet, with three representative models. The results verify our approach's effectiveness and state-of-the-art performance, which achieve over 98% false rejection rate for different types of triggers.
Yuexin Xuan, Xiaojun Chen 0004, Zhendong Zhao, Yangyang Ding, Jianming Lv
IJCNN1
2021 Robust node embedding against graph structural perturbations
Zhendong Zhao, Xiaojun Chen 0004, Dakui Wang, Yuexin Xuan
Inf. Sci.4