Geying Yang

dblp:315/9562 · DBLP profile ↗
← Back
17ranked-venue papers
3as first author
17since 2021 · last 2026
0000-0002-3456-3464ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 10 · 2 first-author · 10 since 2021Databases, data management, data science and information retrieval · 4 · 2 first-author · 4 since 2021Security and privacy · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Computer networks · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 MacPrompt: Maraconic-Guided Jailbreak Against Text-to-Image Models
abstract
Text-to-image (T2I) models have raised increasing safety concerns due to their capacity to generate NSFW and other banned objects. To mitigate these risks, safety filters and concept removal techniques have been introduced to block inappropriate prompts or erase sensitive concepts from the models. However, all the existing defense methods are not well prepared to handle diverse adversarial prompts. In this work, we introduce MacPrompt, a novel black-box and cross-lingual attack that reveals previously overlooked vulnerabilities in T2I safety mechanisms. Unlike existing attacks that rely on synonym substitution or prompt obfuscation, MacPrompt constructs macaronic adversarial prompts by performing cross-lingual character-level recombination of harmful terms, enabling fine-grained control over both semantics and appearance. By leveraging this design, MacPrompt crafts prompts with high semantic similarity to the original harmful inputs (up to 0.96) while bypassing major safety filters (up to 100%). More critically, it achieves attack success rates as high as 92% for sex-related content and 90\% for violence, effectively breaking even state-of-the-art concept removal defenses. These results underscore the pressing need to reassess the robustness of existing T2I safety mechanisms against linguistically diverse and fine-grained adversarial strategies. Warning: This paper includes sensitive examples (e.g., adult, violent, or illegal content). Unsafe images are masked but may still be disturbing.
Xi Ye 0004, Lina Wang 0001, Run Wang 0001, Geying Yang, Yufei Hou, Jiayi Yu
AAAI5
2026 PCFormer: Accelerating Privacy-preserving Transformer Inference by Partition and Combination
abstract
In recent years, transformer-based models have achieved remarkable success in sensitive domains, including healthcare, finance and personalized services, but their deployment raises significant privacy concerns. Existing secure inference studies have introduced cryptographic techniques such as Homomorphic Encryption (HE) and Secure Multi-Party Computation (MPC). However, these approaches either target isolated model components or incur prohibitive computational and communication overheads, failing to support latency-sensitive or resource-limited environments. In our investigation, we identify substantial redundancy in the nonlinear operations and their alternation with linear layers in deep learning. Motivated by this observation, we propose PCFormer, a universal optimization methodology tailored for sequences of linear and nonlinear computations in the Transformer. PCFormer introduces structure-aware partition and combination techniques specially designed for Multi-Head Attention (MHA) and Feed-Forward Network (FFN). Specifically, we reveal the discrete sources of redundancy in the Softmax and GeLU functions during inference, implementing partitions at the token and channel levels, respectively. Subsequently, these reductions are then combined with the preceding and succeeding linear operations, thereby enhancing both computational and communication efficiency. Experimental results on GLUE benchmarks demonstrate that PCFormer achieves a 1.9× speedup in both computation and communication without compromising accuracy, compared to existing privacy-preserving Transformer frameworks. Furthermore, we demonstrate that PCFormer generalizes effectively to other deep learning architectures involving structured linear-nonlinear compositions under cryptographic constraints.
Bo Zeng 0006, Zhi Pang, Tian Wu 0004, Geying Yang, Lina Wang 0001, Run Wang 0001
AAAI6
2025 A Code-based Group Signature Scheme from the Schnorr-Lyubashevsky Framework
abstract
Code-based group signatures are a promising candidate for post-quantum cryptography, but existing code-based group signature schemes struggle with the challenges of large signature sizes caused by zero-knowledge proofs. To address this issue, we propose a novel and practical code-based group signature scheme built upon the Schnorr-Lyubashevsky paradigm. Our construction achieves constant-size signatures and public keys, independent of the group cardinality, and its security is formally proven in the random oracle model under the hardness assumptions of the Syndrome Decoding (SD) and Decoding One Out of Many (DOOM) problems. To alleviate the performance bottleneck of rejection sampling, we design and implement a batch processing optimization for the signing algorithm, which significantly accelerates signature generation by applying vectorization to the most computationally intensive operations. Experimental results show that the optimization renders signing practical. Our scheme features the most compact signature size among existing codebased group signature schemes. All related code is open-sourced and available at https://github.com/Latters/CodeBasedGroupSig/.
Shuwang Xu, Lusheng Chen, Geying Yang, Fangchao Yu, Yufei Hou, Lina Wang 0001
ICPADS3
2025 HIPP: Protecting Image Privacy via High-Quality Reversible Protected Version
abstract
With the rapid development of the internet, sharing photos through Social Network Platforms (SNPs) has become a new way for people to socialize, which poses serious threats to personal privacy. Recently, a thumbnail-preserving image privacy protection technique has emerged and garnered widespread attention. However, the existing schemes based on this technique often introduce noticeable noise into the protected image, resulting in poor visual quality. Motivated by the observation that a latent vector can be decoupled into the detail and contour components, in this paper, we propose HIPP, a thumbnail-preserving image privacy protection scheme that decouples the detail and contour information contained in the latent vector corresponding to the original image and reconstructs details by generation model. As a result, the generated protected image appears natural and has a thumbnail similar to the original one. Moreover, the protected images can be restored to versions that are indistinguishable from the original images. Experiments on CelebA, Helen, and LSUN datasets show that the SSIM between the restored and original images achieves 0.9899. Furthermore, compared to the previous works, HIPP achieves the lowest runtime and file expansion rate, with values of 0.07 seconds and 1.1046, respectively.
Xi Ye 0004, Lina Wang 0001, Run Wang 0001, Geying Yang
IJCAI5
2025 LPPAC: Lightweight privacy-preserving distributed payments with access control
Bo Zeng 0006, Tian Wu 0004, Fangchao Yu, Geying Yang, Lina Wang 0001
Comput. Networks4
2025 GAN-based data reconstruction attacks in split learning
Bo Zeng 0006, Sida Luo, Fangchao Yu, Geying Yang, Lina Wang 0001
Neural Networks4
2025 CSCAD: An Adaptive LightGBM Algorithm to Detect Cache Side-Channel Attacks
abstract
Cache side-channel attacks have become more sophisticated and more destructive to the security of computer architectures and cloud platforms than ever before, resulting in the leakage of privacy information. Prior efforts focused on designing countermeasures instead of timely detection. To address the challenges introduced by cache side-channel attacks, anomaly detection and feature detection were proposed. However, these methods have drawbacks in terms of computational performance and detection effectiveness. In this article, we proposed Cache Side-Channel Attack Detector(CSCAD), a novel tool for detecting cache side-channel attacks against memory events in real time. Specifically, we design a collector using Hardware Performance Counters and use improved Maximum Information Coefficient to generate feature vectors. Meanwhile, an adaptive genetic algorithm with crossover and mutation probability is proposed to optimize hyperparameters of LightGBM. Additionally, an adaptive loss function weight model with low overhead is introduced to enhance efficiency of attack detection. It is encouraging to see that CSCAD achieved a recall of 98.14%. In detecting 1000 samples, it boosted the detection speed by approximately 75% compared to conventional machine learning methods. CSCAD has outperformed the state-of-the-art methods by simultaneously achieving excellent detection speed and effectiveness.
Sirui Hao, Junjiang He, Wenshan Li 0001, Tao Li 0016, Geying Yang, Wenbo Fang, Wanying Chen
IEEE Trans. Dependable Secur. Comput.5
2025 Unknown Cyber Threat Discovery Empowered by Genetic Evolution Without Prior Knowledge
abstract
With the continuous development of cyber-attack technologies, attackers increasingly exploit zero-day vulnerabilities or leverage emerging techniques to launch sophisticated attacks, resulting in the persistent emergence of unknown cyber-attacks. However, traditional DL-based cyber-attack detection methods heavily rely on large-scale labeled training data. In practice, obtaining sufficient samples of unknown attacks is challenging, which makes it difficult for these methods to effectively defend against unknown cyber-attacks. In this paper, we propose a method for discovering unknown cyber threats empowered by genetic evolution without prior knowledge. Specifically, We, first mapped the network feature space into a gene framework, and divided the attack genes into a static gene region (SGZ) and a dynamic gene region (DGZ) according to the importance of the cyber-attack genes. Subsequently, leveraging the known attack genes, we utilized different gene evolution strategies and a Convolutional Autoencoder (CAE) to generate attack variants and potential unknown attack genes. Finally, we constructed a cyber-attack detection model incorporating both the global attention mechanism (GAM) and the local attention mechanism (LAM). The generated attack variants and unknown attack genes are the used to enhance the detection ability of the detection model for variants and unknown cyber-attacks. We conducted a large number of experiments on six real and authoritative network datasets. The experimental results show that in different scenario settings, the F1 scores of our proposed method for detecting unknown attacks are 84.64% and 95.77% respectively. The F1 score for detecting unknown attacks on the UNSW-NB15 dataset exceeds that of the baseline classifier. The F1 score for detecting unknown attacks on the CSE-CIC-IDS2018 dataset is 98.85%. In comparison with SOTA methods, the average F1 score is improved by 3.14%. In the evaluation of variant detection performance, the generation method we proposed improves the detection of variants by approximately 11.2%, surpassing generation methods such as the Conditional Generative Adversarial Network (CGAN) and the Variational Autoencoder (VAE). Meanwhile, we also comprehensively evaluated the generalization ability of our proposed method and the evolution ability of different evolution strategies on different datasets and through ablation experiments.
Wenbo Fang, Junjiang He, Wenshan Li 0001, Wengang Ma, Linlin Zhang 0005, Xiaolong Lan, Geying Yang, Jiangchuan Chen, Tao Li 0016
IEEE Trans. Inf. Forensics Secur.7
2024 A novel immune detector training method for network anomaly detection
Geying Yang, Lina Wang 0001, Qinghao Wang
Appl. Intell.2
2024 A novel fusion feature imageization with improved extreme learning machine for network anomaly detection
Geying Yang, Lina Wang 0001, Qinghao Wang
Appl. Intell.1
2024 SynDroid: An adaptive enhanced Android malware classification method based on CTGAN-SVM
Junjiang He, Wenshan Li 0001, Wenbo Fang, Geying Yang, Tao Li 0016
Comput. Secur.5
2024 Efficient Based on Improved Random Forest Defense System Against Application-Layer DDoS Attacks
abstract
Application‐layer distributed denial of service (DDoS) attacks have become the main threat to Web server security. Because application‐layer DDoS attacks have strong concealability and high authenticity, intrusion detection technologies that rely solely on judging client authenticity cannot accurately detect such attacks. In addition, application‐layer DDoS attacks are periodic and repetitive, and attack targets suddenly in a short period. In this study, we propose an efficient application‐layer DDoS detection system based on improved random forest. Firstly, the Web logs are preprocessed to extract the user session characteristics. Subsequently, we propose a Session Identification based on Separation and Aggregation (SISA) method to accurately capture user sessions. Lastly, we propose an improved random forest classification algorithm based on feature weighting to address the issue of an increasing number of features leading to prolonged calculation times in the random forest algorithm, and as the feature dimension increases, there might be instances where no subfeature is related to the category to be classified. More importantly, we compare the request source IP with the malicious IP in the threat intelligence library to deal with the periodicity and repetition of application‐layer DDoS attacks. We conducted a comprehensive experiment on the publicly available Web log dataset and the threat intelligence database of the laboratory as well as the simulated generated attack log dataset in the laboratory environment. The experimental results show that the proposed detection system can control the false alarm rate and false alarm rate within a reasonable range, improving the detection efficiency further, the detection rate is 99.85%. In secondary attack detection experiments, our proposed detection method achieves a higher detection rate in a shorter time.
Junjiang He, Wenbo Fang, Xiaolong Lan, Geying Yang, Tao Li 0016, Jiangchuan Chen
Int. J. Intell. Syst.4
2024 An Immune-Knowledge-Driven SCADA-Based Industrial Virus Propagation Model
abstract
Supervisory Control and Data Acquisition (SCADA) systems are the core of industrial control systems and an important part of critical infrastructure. With the deployment of 5G networks around the world, SCADA systems are no longer a relatively secure and physically isolated system like in the past, but are facing huge network virus threats. In order to solve the problem that existing models ignore the communication between nodes in the system, we propose an industrial virus transmission model SELBR based on immune knowledge by simulating the function of T cells in the immune system. By introducing E node, the model is used to realize the function of information transfer between nodes. What’s more, we fit the numerical simulation results with the actual data set to verify the existence of the model, and verify the effectiveness of the model for controlling the spread of industrial viruses through model comparison experiments. Numerical results show that the model can effectively control the spread of the virus. Finally, on the basis of parameter sensitivity analysis, preventive suggestions are put forward to further strengthen the security of SCADA system.
Junjiang He, Jiahang Tang, Hongxia Wang 0001, Geying Yang, Tao Li 0016, Xiaolong Lan
IEEE Internet Things J.5
2024 A fast dual-module hybrid high-dimensional feature selection algorithm
Geying Yang, Junjiang He, Xiaolong Lan, Tao Li 0016, Wenbo Fang
Inf. Sci.1
2023 SR-IDS: A Novel Network Intrusion Detection System Based on Self-taught Learning and Representation Learning
Qinghao Wang, Geying Yang, Lina Wang 0001
ICANN (3)2
2023 Uniformity-Comprehensive Multiobjective Optimization Evolutionary Algorithm Based on Machine Learning
abstract
When solving real‐world optimization problems, the uniformity of Pareto fronts is an essential strategy in multiobjective optimization problems (MOPs). However, it is a common challenge for many existing multiobjective optimization algorithms due to the skewed distribution of solutions and biases towards specific objective functions. This paper proposes a uniformity‐comprehensive multiobjective optimization evolutionary algorithm based on machine learning to address this limitation. Our algorithm utilizes uniform initialization and self‐organizing map (SOM) to enhance population diversity and uniformity. We track the IGD value and use K‐means and CNN refinement with crossover and mutation techniques during evolutionary stages. Our algorithm’s uniformity and objective function balance superiority were verified through comparative analysis with 13 other algorithms, including eight traditional multiobjective optimization algorithms, three machine learning‐based enhanced multiobjective optimization algorithms, and two algorithms with objective initialization improvements. Based on these comprehensive experiments, it has been proven that our algorithm outperforms other existing algorithms in these areas.
Yuxuan Luan, Junjiang He, Jingmin Yang, Xiaolong Lan, Geying Yang
Int. J. Intell. Syst.5
2023 A Modified Gray Wolf Optimizer-Based Negative Selection Algorithm for Network Anomaly Detection
abstract
Intrusion detection systems are crucial in fighting against various network attacks. By monitoring the network behavior in real time, possible attack attempts can be detected and acted upon. However, with the development of openness and flexibility of networks, artificial immunity‐based network anomaly detection methods lack continuous adaptability and hence have poor detection performance. Thus, a novel framework for network anomaly detection with adaptive regulation is built in this paper. First, a heuristic dimensionality reduction algorithm based on unsupervised clustering is proposed. This algorithm uses the correlation between features to select the best subset. Then, a hybrid partitioning strategy is introduced in the negative selection algorithm (NSA), which divides the feature space into a grid based on the sample distribution density and generates specific candidate detectors in the boundary grid to effectively mitigate the holes caused by boundary diversity. Finally, the NSA is improved by self‐set clustering and a novel gray wolf optimizer to achieve adaptive adjustment of the detector radius and position. The results show that the proposed NSA algorithm based on mixed hierarchical division and gray wolf optimization (MDGWO‐NSA) achieves a higher detection rate, lower false alarm rate, and better generation quality than other network anomaly detection algorithms.
Geying Yang, Lina Wang 0001, Rongwei Yu, Junjiang He, Bo Zeng 0006, Tian Wu 0004
Int. J. Intell. Syst.1