VLDB 2026 Research / reviewers in the wild / expert
Yalun Wu
dblp:301/9788
· DBLP profile ↗
9ranked-venue papers
5as first author
9since 2021 · last 2026
0000-0002-0891-1904ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 3 first-author · 5 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 3 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FRBAT: Conditionally-Visible Physical Backdoor Attack via FluorescenceabstractDeep neural networks are increasingly vulnerable to physically deployable backdoor attacks, which manipulate real-world objects to induce targeted model failures. However, current physical backdoor attacks predominantly rely on perpetually visible triggers appended to target objects. These methods inevitably expose attack traces during the deployment phase, risking human suspicion prior to activation. In this paper, we propose a conditionally-visible physical backdoor attack, which can only be activated under specific optical conditions and thereby overcomes the risk of being detected after deployment and before the attack. Specifically, to ensure robust and reliable activation, we design irregular polygonal pattern as triggers to against across environmental variations. Moreover, we introduce a dual-phase mechanism (dormant and activated) to enable stealthy deployment. Our trigger remains invisible and dormant under non-attack conditions, leaving no physical traces. It activates instantaneously under specific illumination, inducing the target model to perform the desired behavior. We conduct experiments on traffic sign recognition tasks to compare our attack with six digital and seven physical attacks, and assess its performance against potential defenses. Extensive experimental results demonstrate the effectiveness, stealthiness, and robustness of our attack. Yalun Wu, Endong Tong, Yingxiao Xiang, Xiaoting Lyu, Zhen Han 0001, Jiqiang Liu |
AAAI | 1 |
| 2026 | FlipBAT: Toward Stealthy Endogenous Backdoor Attacks on Traffic Sign Recognition via Self-FlippingabstractRecent studies show that deep learning-based traffic sign recognition systems are vulnerable to backdoor attacks. These compromised models can be activated to misclassify traffic signs when exposed to specific backdoor patterns during inference. Nevertheless, existing attack methods rely on exogenous triggers (e.g., stickers or patches) that introduce external features to associate backdoor patterns with target labels, significantly increasing attack complexity. In this paper, we propose FlipBAT, a stealthy endogenous backdoor attack method that uses the image’s self-flipping as the built-in trigger, eliminating the need for external trigger patterns. Our attack supports two distinct attack modes: a multi-class backdoor attack that enables flexible target diversification via cyclic mappings, and a single-class backdoor attack that achieves higher stealthiness by minimally perturbing the source class. Extensive experiments conducted on two standard traffic sign recognition datasets (GTSRB and BelgiumTS) across three different victim models demonstrate that FlipBAT effectively establishes robust mappings between backdoor images and target classes. Notably, our method achieves efficient backdoor attacks with significantly lower poisoning rates compared to conventional approaches. Our method has also been shown to be robust against state-of-the-art backdoor defenses. Yalun Wu, Xiaoshu Cui, Yingxiao Xiang, Yingying Yao, Yuanwan Chen, Zhen Han 0001, Jiqiang Liu, Wenjia Niu |
IEEE Internet Things J. | 1 |
| 2025 | H2HTalk: Evaluating Large Language Models as Emotional Companion
Boyang Wang 0006, Yalun Wu, Hongcheng Guo, Zhoujun Li 0001 |
NLPCC (1) | 2 |
| 2025 | Large multimodal models evaluation: a survey
Farong Wen, Yijin Guo, Xinyu Fang, Shengyuan Ding, Ziheng Jia, Jiahao Xiao, Ye Shen, Yushuo Zheng, Xiaorong Zhu, Yalun Wu, Ziheng Jiao, Wei Sun 0029, Zijian Chen 0001, Kaiwei Zhang, Yuqin Cao, Yue Zhou 0005, Xuemei Zhou, Juntai Cao, Wei Zhou 0021, Jinyu Cao, Ronghui Li, Yuan Tian 0017, Chunyi Li 0001, Haoning Wu 0001, Xiaohong Liu 0001, Junjun He, Yu Zhou 0016, Zesheng Wang 0004, Huiyu Duan, Yingjie Zhou 0003, Xiongkuo Min, Dongzhan Zhou, Jiezhang Cao, Xue Yang 0005, Junzhi Yu 0001, Songyang Zhang 0001, Haodong Duan, Guangtao Zhai |
Sci. China Inf. Sci. | 13 |
| 2025 | A secure and lightweight data sharing scheme in vehicular digital twin network
Guanjie Li, Tom H. Luan, Jinkai Zheng, Dihao Hu, Yalun Wu |
Peer Peer Netw. Appl. | 6 |
| 2024 | Nightfall Deception: A Novel Backdoor Attack on Traffic Sign Recognition Models via Low-Light Data Manipulation
Yalun Wu, Yingxiao Xiang, Jinkai Zheng, Zhen Han 0001, Jiqiang Liu, Wenjia Niu |
ADMA (3) | 1 |
| 2024 | Lurking in the Shadows: Imperceptible Shadow Black-Box Attacks Against Lane Detection Models
Xiaoshu Cui, Yalun Wu, Yanfeng Gu, Endong Tong, Jiqiang Liu, Wenjia Niu |
KSEM (3) | 2 |
| 2024 | Collaborative Attack Sequence Generation Model Based on Multiagent Reinforcement Learning for Intelligent Traffic Signal SystemabstractIntelligent traffic signal systems, crucial for intelligent transportation systems, have been widely studied and deployed to enhance vehicle traffic efficiency and reduce air pollution. Unfortunately, intelligent traffic signal systems are at risk of data spoofing attack, causing traffic delays, congestion, and even paralysis. In this paper, we reveal a multivehicle collaborative data spoofing attack to intelligent traffic signal systems and propose a collaborative attack sequence generation model based on multiagent reinforcement learning (RL), aiming to explore efficient and stealthy attacks. Specifically, we first model the spoofing attack based on Partially Observable Markov Decision Process (POMDP) at single and multiple intersections. This involves constructing the state space, action space, and defining a reward function for the attack. Then, based on the attack modeling, we propose an automated approach for generating collaborative attack sequences using the Multi‐Actor‐Attention‐Critic (MAAC) algorithm, a mainstream multiagent RL algorithm. Experiments conducted on the multimodal traffic simulation (VISSIM) platform demonstrate a 15% increase in delay time (DT) and a 40% reduction in attack ratio (AR) compared to the single‐vehicle attack, confirming the effectiveness and stealthiness of our collaborative attack. Yalun Wu, Yingxiao Xiang, Thar Baker, Endong Tong, Xiaoshu Cui, Zhen Han 0001, Jiqiang Liu, Wenjia Niu |
Int. J. Intell. Syst. | 1 |
| 2021 | Improving Convolutional Neural Network-Based Webshell Detection Through Reinforcement Learning
Yalun Wu, Minglu Song, Yunzhe Tian, Endong Tong, Wenjia Niu, Bowei Jia, Haixiang Huang, Jiqiang Liu |
ICICS (1) | 1 |