VLDB 2026 Research / reviewers in the wild / expert
Zizhi Jin
dblp:319/7840
· DBLP profile ↗
7ranked-venue papers
4as first author
7since 2021 · last 2026
0000-0003-3251-456XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Phantom Menace: Exploring and Enhancing the Robustness of VLA Models Against Physical Sensor AttacksabstractVision-Language-Action (VLA) models revolutionize robotic systems by enabling end-to-end perception-to-action pipelines that integrate multiple sensory modalities, such as visual signals processed by cameras and auditory signals captured by microphones. This multi-modality integration allows VLA models to interpret complex, real-world environments using diverse sensor data streams. Given the fact that VLA-based systems heavily rely on the sensory input, the security of VLA models against physical-world sensor attacks remains critically underexplored. To address this gap, we present the first systematic study of physical sensor attacks against VLAs, quantifying the influence of sensor attacks and investigating the defenses for VLA models. We introduce a novel ``Real-Sim-Real" framework that automatically simulates physics-based sensor attack vectors, including six attacks targeting cameras and two targeting microphones, and validates them on real robotic systems. Through large-scale evaluations across various VLA architectures and tasks under varying attack parameters, we demonstrate significant vulnerabilities, with susceptibility patterns that reveal critical dependencies on task types and model designs. We further develop an adversarial-training-based defense that enhances VLA robustness against out-of-distribution physical perturbations caused by sensor attacks while preserving model performance. Our findings expose an urgent need for standardized robustness benchmarks and mitigation strategies to secure VLA deployments in safety-critical environments. Xuancun Lu, Jiaxiang Chen, Shilin Xiao, Zizhi Jin, Zhangrui Chen, Hanwen Yu, Bohan Qian, Ruochen Zhou, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
AAAI | 4 |
| 2025 | PhantomLiDAR: Cross-modality Signal Injection Attacks against LiDAR
Zizhi Jin, Qinhong Jiang, Xuancun Lu, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
NDSS | 1 |
| 2025 | Laser-Based LiDAR Spoofing: Effects Validation, Capability Quantification, and CountermeasuresabstractAutonomous vehicles (AVs) and robots increasingly exploit light detection and ranging (LiDAR)-based 3-D object detection systems to detect obstacles in the environment. Correct detection and classification are important to ensure safe driving. Although previous work has demonstrated the feasibility of manipulating point clouds to spoof 3-D object detectors, most of these attempts are performed digitally. In this article, we investigate the possibility of physically fooling LiDAR-based 3-D object detection by injecting adversarial point clouds using lasers. First, we develop a laser transceiver that can inject up to 4200 points, and can measure the scanning cycle of victim LiDARs to schedule the spoofing laser signals. By designing a control signal method that converts the coordinates of point clouds to control signals and an adversarial point cloud optimization method with physical constraints of LiDARs and attack capabilities, we manage to inject spoofing point cloud with desired point cloud shapes into the victim LiDAR physically. We can launch four types of attacks, i.e., naive hiding, record-based creating, optimization-based hiding, and optimization-based creating. Extensive experiments demonstrate the effectiveness of our attacks against two commercial LiDAR and three detectors. We further analyze the impact of our attacks on four fusion-based detectors. This article concludes with experiments on defense methods and discussion on potential defense strategies at both the sensor and AV system levels. Zizhi Jin, Xiaoyu Ji 0001, Yushi Cheng, Chen Yan 0001, Wenyuan Xu 0001 |
IEEE Internet Things J. | 1 |
| 2024 | Unity is Strength? Benchmarking the Robustness of Fusion-based 3D Object Detection against Physical Sensor Attack
Zizhi Jin, Xuancun Lu, Yushi Cheng, Chen Yan 0001, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
WWW | 1 |
| 2024 | Adversarial robustness analysis of LiDAR-included models in autonomous drivingabstractIn autonomous driving systems, perception is pivotal, relying chiefly on sensors like LiDAR and cameras for environmental awareness. LiDAR, celebrated for its detailed depth perception, is being increasingly integrated into autonomous vehicles. In this article, we analyze the robustness of four LiDAR-included models against adversarial points under physical constraints. We first introduce an attack technique that, by simply adding a limited number of physically constrained adversarial points above a vehicle, can make the vehicle undetectable by the LiDAR-included models. Experiments reveal that adversarial points adversely affect the detection capabilities of both LiDAR-only and LiDAR-camera fusion models, with a tendency for more adversarial points to escalate attack success rates. Notably, voxel-based models are more susceptible to deception by these adversarial points. We also investigated the impact of the distance and angle of the added adversarial points on the attack success rate. Typically, the farther the victim object to be hidden and the closer to the front of the LiDAR, the higher the attack success rate. Additionally, we have experimentally proven that our generated adversarial points possess good cross-model adversarial transferability and validated the effectiveness of our proposed optimization method through ablation studies. Furthermore, we propose a new plug-and-play, model-agnostic defense method based on the concept of point smoothness. The ROC curve of this defense method shows an AUC value of approximately 0.909, demonstrating its effectiveness. Zizhi Jin, Yushi Cheng, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
High Confid. Comput. | 2 |
| 2023 | PLA-LiDAR: Physical Laser Attacks against LiDAR-based 3D Object Detection in Autonomous VehicleabstractAutonomous vehicles and robots increasingly exploit LiDAR-based 3D object detection systems to detect obstacles in environment. Correct detection and classification are important to ensure safe driving. Though existing work has demonstrated the feasibility of manipulating point clouds to spoof 3D object detectors, most of the attempts are conducted digitally. In this paper, we investigate the possibility of physically fooling LiDAR-based 3D object detection by injecting adversarial point clouds using lasers. First, we develop a laser transceiver that can inject up to 4200 points, which is 20 times more than prior work, and can measure the scanning cycle of victim LiDARs to schedule the spoofing laser signals. By designing a control signal method that converts the coordinates of point clouds to control signals and an adversarial point cloud optimization method with physical constraints of LiDARs and attack capabilities, we manage to inject spoofing point cloud with desired point cloud shapes into the victim LiDAR physically. We can launch four types of attacks, i.e., naive hiding, record-based creating, optimization-based hiding, and optimization-based creating. Extensive experiments demonstrate the effectiveness of our attacks against two commercial LiDAR and three detectors. We also discuss defense strategies at the sensor and AV system levels. Zizhi Jin, Xiaoyu Ji 0001, Yushi Cheng, Chen Yan 0001, Wenyuan Xu 0001 |
SP | 1 |
| 2021 | Anti-Replay: A Fast and Lightweight Voice Replay Attack Detection SystemabstractDue to the open nature of voice and voice interface, attackers can easily record the user's voice commands and spoof the voice recognition systems by replaying them. Existing voice replay attack detection methods mainly rely on extra hardware to determine the sound source or require excessively computing resources for training the classifier with a large number of acoustic features. Hence, we propose Anti-Replay, a fast and lightweight detection system for voice replay attacks. To overcome the challenge of redundant classification feature vectors and complex calculation, we first investigate the spectrum difference between live-human voice and the replayed audio caused by the non-linear distortion of the attacker's microphones and speakers and then extract 72-dimensional feature vectors. Then we employ a single deep convolutional neural network classifier (SE-ResNet50) to enhance the robustness of our classification model. Finally, we evaluate the performance of Anti-Replay on the datasets of ASVspoof2017 and ASVspoof2019. Results show that Anti-Replay can achieve an equal error rate (EER) of 2.38% and 0.82% on two datasets, respectively. Meanwhile, the training time and the model size of Anti-Replay have decreased by 56% and 84% compared with the baseline model (i.e., CQCC-GMM). Zhuoyang Shi, Chaohao Li, Zizhi Jin, Weinong Sun, Xiaoyu Ji 0001, Wenyuan Xu 0001 |
ICPADS | 3 |