VLDB 2026 Research / reviewers in the wild / expert
Aolin Ding
dblp:303/4560
· DBLP profile ↗
7ranked-venue papers
3as first author
7since 2021 · last 2025
0009-0007-0746-3031ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Proactive Privacy Amnesia for Large Language Models: Safeguarding PII with Negligible Impact on Model UtilityabstractWith the rise of large language models (LLMs), increasing research has recognized
their risk of leaking personally identifiable information (PII) under malicious
attacks. Although efforts have been made to protect PII in LLMs, existing methods
struggle to balance privacy protection with maintaining model utility. In this paper,
inspired by studies of amnesia in cognitive science, we propose a novel approach,
Proactive Privacy Amnesia (PPA), to safeguard PII in LLMs while preserving their
utility. This mechanism works by actively identifying and forgetting key memories
most closely associated with PII in sequences, followed by a memory implanting
using suitable substitute memories to maintain the LLM’s functionality. We conduct
evaluations across multiple models to protect common PII, such as phone numbers
and physical addresses, against prevalent PII-targeted attacks, demonstrating the
superiority of our method compared with other existing defensive techniques. The
results show that our PPA method completely eliminates the risk of phone number
exposure by 100% and significantly reduces the risk of physical address exposure
by 9.8% – 87.6%, all while maintaining comparable model utility performance. Martin Kuo, Jingyang Zhang, Minxue Tang, Louis DiValentin, Aolin Ding, Jingwei Sun 0002, Amin Hass, Tianlong Chen 0001, Yiran Chen 0001, Hai Li 0001 |
ICLR | 6 |
| 2024 | Build a Computationally Efficient Strong Defense Against Adversarial Example Attacks
Louis DiValentin, Aolin Ding |
ICISSP | 3 |
| 2024 | ModelGuard: Information-Theoretic Defense Against Model Extraction Attacks
Minxue Tang, Anna Dai, Louis DiValentin, Aolin Ding, Amin Hass, Neil Zhenqiang Gong, Yiran Chen 0001, Hai Li 0001 |
USENIX Security Symposium | 4 |
| 2023 | Get Your Cyber-Physical Tests Done! Data-Driven Vulnerability Assessment of Robotic Aerial VehiclesabstractThe rapid growth of robotic aerial vehicles (RAVs) has attracted extensive interest in numerous public and civilian applications, from flying drones to quadrotors. Security of RAV systems is posting greater challenges as RAV controller software becomes more complex and exposes a growing attack surface. Memory isolation techniques, which virtually separate the memory space and conduct hardware-based memory access control, are believed to prevent the attacker from compromising the entire system by exploiting one memory vulnerability. In this paper, we propose Ares, a new variable-level vulnerability assessment framework to explore deeper bugs from a combined cyber-physical perspective. We present a data-driven method to illustrate that, despite state-of-the-art memory isolation efforts, RAV systems are still vulnerable to physics-aware data manipulation attacks. We augment RAV control states with intermediate state variables by tracing accessible control parameters and vehicle dynamics within the same isolated memory region. With this expanded state variable space, we apply multivariate statistical analysis to investigate inter-variable quantitative data dependencies and search for vulnerable state variables. Ares utilizes a reinforcement learning-based method to show how an attacker can exploit memory bugs and parameter defects in a legitimate memory view and elaborately craft adversarial variable values to disrupt a RAV's safe operations. We demonstrate the feasibility and capability of Ares on the widely-used ArduPilot RAV framework. Our extensive empirical evaluation shows that the attacker can leverage these vulnerable state variables to achieve various RAV failures during real-time operation, and even evade existing defense solutions. Aolin Ding, Amin Hass, Nils Ole Tippenhauer, Shiqing Ma, Saman A. Zonouz |
DSN | 1 |
| 2023 | Resource-Aware DNN Partitioning for Privacy-Sensitive Edge-Cloud Systems
Aolin Ding, Amin Hass, Nader Sehatbakhsh, Saman A. Zonouz |
ICONIP (5) | 1 |
| 2022 | Reverse engineering and retrofitting robotic aerial vehicle control firmware using dispatchabstractUnmanned Aerial Vehicles as a service (UAVaaS) has increased the field deployment of Robotic Aerial Vehicles (RAVs) for different services such as transportation and terrain exploration. These RAVs are controlled by firmware, which is often closed-source, developed by vendors, and flashed into the ROM. While these binary blobs enable off-the-shelf management of RAVs, end users (individuals or organizations) have no idea if the control firmware is designed and implemented correctly, and can only rely on firmware updates from vendors when any vulnerability is discovered. This paper proposes DisPatch, the first reverse engineering and patching framework for understanding and improving controller design and implementation within RAV firmware. DisPatch first decompiles binary instructions and recovers controller functions and core controller variables by combining control theory with program analysis using symbolic execution and data flow analysis. End users can then write a patch in a domain-specific language (DSL), which will be translated and injected into the binary firmware by DisPatch automatically. We have applied DisPatch to two instances of commodity firmware from3DR IRIS+ and MantisQ RAVs and demonstrated 100% and 80.7% accuracy respectively in the controller decompilation. We have also shown the ability to prevent severe controller performance degradation by patching two real-world bugs with in the firmware and without breaking other functionality. Finally, we show that DisPatch introduces less than 0.53% of space overhead and 1.48% of runtime overhead without violating the soft real-time deadlines. DisPatch provides the first step towards an RAV binary firmware reverse engineering and patching system to customize controller design and implementation. Taegyu Kim, Aolin Ding, Sriharsha Etigowni, Jizhou Chen, Luis Garcia 0001, Saman A. Zonouz, Dongyan Xu, Jing (Dave) Tian |
MobiSys | 2 |
| 2021 | Mini-Me, You Complete Me! Data-Driven Drone Security via DNN-based Approximate ComputingabstractThe safe operation of robotic aerial vehicles (RAV) requires effective security protection of their controllers against cyber-physical attacks. The frequency and sophistication of past attacks against such embedded platforms highlight the need for better defense mechanisms. Existing estimation-based control monitors have tradeoffs, with lightweight linear state estimators lacking sufficient coverage, and heavier data-driven learned models facing implementation and accuracy issues on a constrained real-time RAV. We present Mini-Me, a data-driven online monitoring framework that models the program-level control state dynamics to detect runtime data-oriented attacks against RAVs. Mini-Me leverages the internal dataflow information and control variable dependencies of RAV controller functions to train a neural network-based approximate model as the lightweight replica of the original controller programs. Mini-Me runs the minimal approximate model and detects malicious control state deviation by comparing the estimated outputs with those outputs calculated by the original controller program. We demonstrate Mini-Me on a widely adopted RAV physical model as well as popular RAV virtual models based on open-source firmware, ArduPilot and PX4, and show its effectiveness in detecting five types of attack cases with an average 0.34% space overhead and 2.6% runtime overhead. Aolin Ding, Praveen Murthy, Luis Garcia 0001, Saman A. Zonouz |
RAID | 1 |