VLDB 2026 Research / reviewers in the wild / expert
Zi Kang
dblp:322/8426
· DBLP profile ↗
11ranked-venue papers
3as first author
11since 2021 · last 2026
0000-0002-1863-2802ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 3 · 3 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Theft model-based black-box adversarial attack in embedding space
Rui Zhang 0050, Shuliang Jiang, Zi Kang, YuanLong Lv, Hui Xia 0001 |
J. Vis. Commun. Image Represent. | 3 |
| 2025 | FedBS: Solving data heterogeneity issue in federated learning using balanced subtasksabstractFederated learning has emerged as a popular paradigm for distributed machine learning, enabling participants to collaborate on model training while preserving local data privacy. However, a key challenge in deploying federated learning in real-world applications arises from the substantial heterogeneity in local data distributions across participants. These differences can have negative consequences, such as degraded performance of aggregated models. To address this issue, we propose a novel approach that advocates decomposing the skewed original task into a series of relatively balanced subtasks. Decomposing the task allows us to derive unbiased features extractors for the subtasks, which are then utilized to solve the original task. Based on this concept, we have developed the FedBS algorithm. Through comparative experiments on various datasets, we have demonstrated that FedBS outperforms traditional federated learning algorithms such as FedAvg and FedProx in terms of accuracy, convergence speed, and robustness. The main reason behind these improvements is that FedBS addresses the data heterogeneity problem in federated learning by decomposing the original task into smaller, more balanced subtasks, thereby more effectively mitigating imbalances during model training. Chuxiao Su, Rui Zhang 0050, Zi Kang, Hui Xia 0001, Cheng Zhang 0018 |
High Confid. Comput. | 4 |
| 2025 | Fast and Controllable Bias-Guided Jailbreak Attack on Large Language ModelsabstractLarge language models (LLMs), with their powerful natural language processing capabilities, can provide more advanced intelligent services for edge devices. However, deploying LLMs at the edge is vulnerable to jailbreak attacks, which can cause the model to generate unsafe content. Meanwhile, current jailbreak attack schemes are inefficient in generating highly stealthy jailbreak prompts. To address this, we propose a Fast and Controllable Bias-Guided Jailbreak Attack (FCB) scheme. First, to improve attack efficiency, we optimize the bias of the model’s output layer to guide the model in generating low-energy jailbreak prompts by directly adjusting the output layer’s logits, thereby accelerating the decoding process. Second, to enhance the stealthiness of the generated jailbreak prompts, we design token stop selection and bias normalization methods to constrain the perturbations during the iterative process, preventing the generation of jailbreak prompts without meaningful semantics. Finally, extensive experimental results demonstrate that FCB can generate highly stealthy jailbreak prompts within a short time. Specifically, compared to the current state-of-the-art controllable attack generation scheme, COLD Attack, FCB achieves up to a 8% improvement in attack success rate, reduces perplexity by up to 181.171, and shortens generation time by as much as 28 seconds. Zi Kang, Hui Xia 0001, Rui Zhang 0050, Xiaoxue Song, Chunqiang Hu |
IEEE Internet Things J. | 1 |
| 2025 | CATIL: Customized adversarial training based on instance loss
Zuming Zhang, Hui Xia 0001, Zi Kang, Rui Zhang 0050 |
Inf. Sci. | 3 |
| 2025 | Imperceptible pixel-precise adaptive multi-level sparse adversarial attacks on video recognition models
Chuxiao Su, Hui Xia 0001, Zi Kang, Rui Zhang 0050, Zuming Zhang |
Knowl. Based Syst. | 4 |
| 2024 | DFDS: Data-Free Dual Substitutes Hard-Label Black-Box Adversarial Attack
Shuliang Jiang, Yusheng He, Rui Zhang 0050, Zi Kang, Hui Xia 0001 |
KSEM (3) | 4 |
| 2024 | Invisible Backdoor Attacks on Key Regions Based on Target Neurons in Self-Supervised Learning
Xiangyun Qian, Yusheng He, Rui Zhang 0050, Zi Kang, Yilin Sheng, Hui Xia 0001 |
KSEM (3) | 4 |
| 2024 | Enhance Stealthiness and Transferability of Adversarial Attacks with Class Activation Mapping Ensemble Attack
Hui Xia 0001, Rui Zhang 0050, Zi Kang, Shuliang Jiang |
NDSS | 3 |
| 2024 | Harmonizing Transferability and Imperceptibility: A Novel Ensemble Adversarial AttackabstractContemporary research on adversarial attacks in Intelligent Internet of Things focuses on balancing two key aspects: transferability and imperceptibility. However, achieving a balance between these aspects can be challenging. To address this, we introduce an ensemble adversarial attack method based on model interpretability. This method aims to maintain the transferability of attacks while ensuring a high degree of imperceptibility. Our method generates adversarial perturbations by leveraging information from multiple models, thereby enhancing the transferability of adversarial examples. We also increase the aggressiveness of these examples by accentuating the differences in class activation mappings between adversarial and benign images. During the perturbation optimization process, class activation mappings are utilized to generate more selective perturbations, improving the imperceptibility of the adversarial examples. Experimental results demonstrate that our method effectively balances transferability and imperceptibility. Specifically, for 13 victim classifiers, compared to the most potent attack, VNIFGSM, among nine benchmark methods, OUR demonstrates a 10.31% increase in the mean of Attack Success Rate (mASR) in non-targeted attacks, and OUR’s mASR increases by 9% in targeted attacks. Meanwhile, while OUR exhibits comparable attack performance to VNIFGSM, its imperceptibility demonstrates outstanding performance. Rui Zhang 0050, Hui Xia 0001, Zi Kang, Zhengheng Li |
IEEE Internet Things J. | 3 |
| 2023 | QESAR: Query Effective Decision-Based Attack on Skeletal Action Recognition
Zi Kang, Rui Zhang 0050, Hui Xia 0001 |
PRCV (8) | 1 |
| 2023 | FGDA-GS: Fast guided decision attack based on gradient signs for skeletal action recognition
Zi Kang, Hui Xia 0001, Rui Zhang 0050, Shuliang Jiang, Zuming Zhang |
Comput. Secur. | 1 |