VLDB 2026 Research / reviewers in the wild / expert
Yijie Bai
dblp:298/2788
· DBLP profile ↗
9ranked-venue papers
3as first author
9since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 8 · 2 first-author · 8 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Retriever: A Distributed Intrusion Detection System for NOS-Enabled NetworksabstractNetwork Operating Systems (NOS) are being widely deployed on edge devices by cloud service providers to perform fast configurations and offer high availability for new network protocols. However, NOS-enabled networks open the door to intruders that can stealthily corrupt less-guarded programmable switches to launch attacks on the entire network. Traditional centralized intrusion detection systems may neglect anomalous events on NOS-equipped switches and fail to detect such attacks. In this paper, we make the first attempt towards intrusion detection for NOS-enabled networks by designingRetriever.Retrieverfeatures a lightweight local anomaly detection module on programmable switches and a central anomaly assessment module on the central server. The local anomaly detection module selectively traces both system and network events on switches, based on which a provenance graph of events is established. Upcoming events unmatched by the provenance graph are aggregated to construct a suspicious subgraph to report to the central server. The central anomaly assessment module extracts semantic representations from reported suspicious subgraphs and computes their anomaly scores. Large-scale experiments show thatRetrievercan achieve high intrusion detection accuracy (nearly 100%) with low overheads. Runmin Ou, Yijie Bai, Yanjiao Chen, Bingchuan Tian, Zhiming Ji, Ennan Zhai, Dennis Cai, Wenyuan Xu 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | RACONTEUR: A Knowledgeable, Insightful, and Portable LLM-Powered Shell Command Explainer
Jiangyi Deng, Xinfeng Li, Yanjiao Chen, Yijie Bai, Haiqin Weng, Yan Liu 0069, Tao Wei 0002, Wenyuan Xu 0001 |
NDSS | 4 |
| 2025 | BARBIE: Robust Backdoor Detection Based on Latent Separability
Hanlei Zhang, Yijie Bai, Yanjiao Chen, Zhongming Ma, Wenyuan Xu 0001 |
NDSS | 2 |
| 2025 | Link Prediction of UAV Networks Based on Dynamic Graph Neural NetworkabstractABSTRACT Link prediction is a topic within the realm of graph theory. However, the majority of existing link prediction models are tailored for static graphs, disregarding the temporal evolution of graphs and the significance of global features during this process. Addressing the high dynamics and time‐varying feature of unmanned aerial vehicle (UAV) network, traditional static graph methods encounter issues with the loss of network feature extraction information. By slicing the motion process of UAV nodes to form dynamic sequence graphs and designing sub‐modules of structural attention and temporal attention, we characterize the spatial relationships within subgraphs of dynamic sequence graphs and the temporal relationships between subgraphs. We propose a dynamic link prediction method using dynamic graph neural networks, which possesses exchangeability and interpretability, capturing the temporal dimension features of the entire evolution process of the cluster dynamic network and characterizing the spatial relationships between nodes. A dataset of time‐varying topologies for cluster networks is constructed, enabling link prediction under complex dynamic networks with time‐varying conditions. Experimental results demonstrate that this method can accurately predict link relationships between nodes in time‐varying complex UAV network topologies. Compared with traditional dynamic graph network models such as node2vec and GraphSAGE, this model achieves a link prediction accuracy of 88.79% on the RPGM dataset, surpassing node2vec's 70.24% and GraphSAGE's 62.81%. Yijie Bai, Daojie Yu, Liyue Liang |
IET Commun. | 1 |
| 2024 | Alchemy: Data-Free Adversarial TrainingabstractMachine learning models have become integral to various aspects of daily life, prompting increased vulnerability to adversarial attacks.Adversarial training is one of the most promising and practical methods to enhance model robustness.Existing adversarial training methods, however, assume access to the original training data.But nowadays, more and more users directly download models from the open-source model platforms or tech companies, but the original training datasets are usually unreleased because of commercial interests or privacy.In such scenarios, the user cannot utilize the former adversarial training methods to improve model robustness because of the lack of original training datasets.Thus, we present the first exploration of a data-free adversarial training framework, Alchemy, which seeks to enhance model robustness without requiring access to the original training data.By addressing the notable challenges of reconstructing high-quality training data with robust features and improving the adversarial robustness to the inaccessible original dataset, our approach achieves the goals of both high accuracy maintenance and robustness improvement.Comprehensive experiments on four datasets compared with five baselines, demonstrate Alchemy 's high effectiveness.With no access to any training dataset, the average robustness improvement with Alchemy is effective in most attack scenarios.Additional evaluations underscore the framework's stability under different settings and discuss future research directions. Yijie Bai, Zhongming Ma, Yanjiao Chen, Jiangyi Deng, Shengyuan Pang, Yan Liu 0069, Wenyuan Xu 0001 |
CCS | 1 |
| 2024 | Sophon: Non-Fine-Tunable Learning to Restrain Task Transferability For Pre-trained ModelsabstractInstead of building deep learning models from scratch, developers are more and more relying on adapting pre-trained models to their customized tasks. However, powerful pre-trained models may be misused for unethical or illegal tasks, e.g., privacy inference and unsafe content generation. In this paper, we introduce a pioneering learning paradigm, non-fine-tunable learning, which prevents the pre-trained model from being fine-tuned to indecent tasks while preserving its performance on the original task. To fulfill this goal, we propose Sophon, a protection framework that reinforces a given pre-trained model to be resistant to being fine-tuned in pre-defined restricted domains. Nonetheless, this is challenging due to a diversity of complicated fine-tuning strategies that may be adopted by adversaries. Inspired by model-agnostic meta-learning, we overcome this difficulty by designing sophisticated fine-tuning simulation and fine-tuning evaluation algorithms. In addition, we carefully design the optimization process to entrap the pre-trained model within a hard-to-escape local optimum regarding restricted domains. We have conducted extensive experiments on two deep learning modes (classification and generation), seven restricted domains, and six model architectures to verify the effectiveness of Sophon. Experiment results verify that fine-tuning Sophon-protected models incurs an overhead comparable to or even greater than training from scratch. Furthermore, we confirm the robustness of Sophon to three fine-tuning methods, five optimizers, various learning rates and batch sizes. Sophon may help boost further investigations into safe and responsible AI. Jiangyi Deng, Shengyuan Pang, Yanjiao Chen, Liangming Xia, Yijie Bai, Haiqin Weng, Wenyuan Xu 0001 |
SP | 5 |
| 2023 | Devil in Disguise: Breaching Graph Neural Networks Privacy through InfiltrationabstractGraph neural networks (GNNs) have been developed to mine useful information from graph data of various applications, e.g., healthcare, fraud detection, and social recommendation. However, GNNs open up new attack surfaces for privacy attacks on graph data. In this paper, we propose Infiltrator, a privacy attack that is able to pry node-level private information based on black-box access to GNNs. Different from existing works that require prior information of the victim node, we explore the possibility of conducting the attack without any information of the victim node. Our idea is to infiltrate the graph with attacker-created nodes to befriend the victim node. More specifically, we design infiltration schemes that enable the adversary to infer the label, neighboring links, and sensitive attributes of a victim node. We evaluate Infiltrator with extensive experiments on three representative GNN models and six real-world datasets. The results demonstrate that Infiltrator can achieve an attack performance of more than 98% in all three attacks, outperforming baseline approaches. We further evaluate the defense resistance of Infiltrator against the graph homophily defender and the differentially private model. Lingshuo Meng, Yijie Bai, Yanjiao Chen, Yutong Hu 0005, Wenyuan Xu 0001, Haiqin Weng |
CCS | 2 |
| 2023 | VILLAIN: Backdoor Attacks Against Vertical Split Learning
Yijie Bai, Yanjiao Chen, Hanlei Zhang, Wenyuan Xu 0001, Haiqin Weng, Dou Goodman |
USENIX Security Symposium | 1 |
| 2021 | FakeWake: Understanding and Mitigating Fake Wake-up Words of Voice AssistantsabstractIn the area of Internet of Things (IoT), voice assistants have become an important interface to operate smart speakers, smartphones, and even automobiles. To save power and protect user privacy, voice assistants send commands to the cloud only if a small set of preregistered wake-up words are detected. However, voice assistants are shown to be vulnerable to the FakeWake phenomena, whereby they are inadvertently triggered by innocent-sounding fuzzy words. In this paper, we present a systematic investigation of the FakeWake phenomena from three aspects. To start with, we design the first fuzzy word generator to automatically and efficiently produce fuzzy words instead of searching through a swarm of audio materials.We manage to generate 965 fuzzy words covering 8 most popular English and Chinese smart speakers. To explain the causes underlying the FakeWake phenomena, we construct an interpretable tree-based decision model, which reveals phonetic features that contribute to false acceptance of fuzzy words by wake-up word detectors. Finally, we propose remedies to mitigate the effect of FakeWake. The results show that the strengthened models are not only resilient to fuzzy words but also achieve better overall performance on original training datasets. Yanjiao Chen, Yijie Bai, Richard Mitev, Kaibo Wang, Ahmad-Reza Sadeghi, Wenyuan Xu 0001 |
CCS | 2 |