VLDB 2026 Research / reviewers in the wild / expert
Qingsong Yao
dblp:33/6363
· DBLP profile ↗
53ranked-venue papers
18as first author
31since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Applied, interdisciplinary, general and emerging computing · 19 · 5 first-author · 16 since 2021Graphics, computer vision, multimedia, augmented reality and games · 16 · 3 first-author · 14 since 2021Artificial intelligence and machine learning · 12 · 5 first-author · 6 since 2021Computer networks · 8 · 3 first-author · 3 since 2021Databases, data management, data science and information retrieval · 6 · 5 first-authorSystems, architecture and hardware · 5 · 1 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Hi-End-MAE: Hierarchical encoder-driven masked autoencoders are stronger vision learners for medical image segmentation
Fenghe Tang, Qingsong Yao, Chenxu Wu, Zihang Jiang, Shaohua Kevin Zhou |
Medical Image Anal. | 2 |
| 2026 | MHCertChain: A Multi-CA Hierarchical Certificate Blockchain With Low OverheadabstractBlockchain-based certificate management schemes provide a distributed approach for Public Key Infrastructure through the integration of blockchain services, thereby enhancing transparency and security in identity authentication. However, existing schemes often suffer from limited scalability when accommodating new CAs, high overhead of blockchain systems, and a high false-positive rate in revocation status checks. To address above issues, we propose MHCertChain, a multi-CA hierarchical certificate blockchain with low overhead. Specifically, a two-layer blockchain structure including the main chain and sub-chains is designed to enhance scalability, while the main chain stores trust paths between CAs and each automatically deployed sub-chain records user certificates issued by an end-entity CA. Then, we propose a lightweight dual-signature certificate format that contains certificate location information without requiring any external certificate location method outside the blockchain. Considering time characteristics of certificates, a time-partitioned cuckoo filter is proposed with a low false positive rate and accelerates revocation status query. Moreover, we deduce an optimal global performance parameter of such filter through mathematical modeling. We present a thorough security analysis of our MHCertChain utilizing the universally composable framework, and extensive experiments demonstrate that the CPU overhead and false positive rate are reduced by 70% and 95%, respectively, compared to state-of-the-art schemes. Blockchain-based certificate management schemes provide a distributed approach for Public Key Infrastructure through the integration of blockchain services, thereby enhancing transparency and security in identity authentication. However, existing schemes seldom discuss hierarchical CA architecture, and often suffer from limited scalability and high overhead when considering new CAs, frequent certificate authentication and revocation status verification. To address above issues, we propose MHCertChain, a multi-CA hierarchical certificate blockchain with low overhead. Specifically, a two-layer blockchain structure including the main chain and sub-chains is designed, while the main chain stores trust paths between CAs and each automatically deployed sub-chain records user certificates issued by an end-entity CA. Then, we propose a lightweight dual-signature certificate format that contains certificate location information without requiring any external certificate location method outside the blockchain. Considering time characteristics of certificates, a time-partitioned cuckoo filter is proposed with a low false positive rate and accelerates revocation status query. Moreover, we deduce an optimal global performance parameter of such filter through mathematical modeling. We present a thorough security analysis of our MHCertChain utilizing the universally composable framework, and extensive experiments demonstrate that the CPU overhead and false positive rate are reduced by 70% and 95%, respectively, compared to state-of-the-art schemes. Blockchain-based certificate management schemes provide a distributed means to increase the transparency of PKI (Public Key Infrastructure) and prevent single point attacks in web communications. However, certificate management based on hierarchical multi-CA architecture often faces the problems of poor scalability and high CPU overhead in blockchain. In this article, we are the first to propose a multi-CA hierarchical certificate blockchain with low overhead. Specifically, a two-layer blockchain structure of the main chain and sub-chain is adopted, with the main chain storing the trust paths and the sub-chain storing the user certificates. By monitoring to the CA transactions of the main chain, the sub-chain is automatically deployed. Then, in the certificate operation, we consider the high CPU overhead of traditional certificate query in blockchain and propose a dual-signature certificate format. combined with the time characteristics of the certificate, a time-partitioned cuckoo filter is proposed with a low false positive rate for the revocation status query speeding, and we find a global performance optimal parameter through mathematical modeling. Finally, we use a general composable framework to prove the security of HiCertChain, and the experiments show that the CPU overhead and false positive rate are reduced by 90% and 95%, respectively, compared with those of state-of-the-arts. Xuewen Dong, Qingsong Yao, Lingxiao Yang, Zhiwei Zhang 0004, Ning Xi 0002, Yulong Shen 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2025 | H3DE-Net: Efficient and Accurate 3D Landmark Detection in Medical ImagingabstractLandmark detection is essential in medical image analysis, aiding tasks like surgical navigation, diagnosis, and treatment planning. However, it remains challenging due to the need for fine-grained local detail and long-range spatial dependency modeling in high-dimensional volumetric data. Existing approaches struggle to balance accuracy, efficiency, and robustness, especially in cases of sparse landmark distribution, anatomical variability, and noisy or incomplete scans. We propose H3DE-Net, a hybrid framework combining CNNs for local feature extraction and a lightweight transformer-based attention module for global context. A volumetric bi-level routing attention mechanism reduces computational overhead while preserving long-range dependencies, and multi-scale feature fusion enhances precision and robustness. This design integrates both global and local representations, overcoming the limitations of CNN-only or transformer-only models. Extensive experiments on a public CT dataset show that H3DE-Net achieves state-of-the-art performance, significantly improving mean radial error (MRE) and success detection rate (SDR) compared to existing methods. The model is robust in challenging scenarios with missing landmarks or anatomical variations, demonstrating its applicability in real-world clinical settings. All code, pretrained weights, and data processing scripts are publicly available for reproducibility and further research. Ronghao Xu, Yangbo Wei, Wenkai Yang, Suhua Wang, Xiaoxin Sun, Qingsong Yao |
BIBM | 9 |
| 2025 | AA-CLIP: Enhancing Zero-Shot Anomaly Detection via Anomaly-Aware CLIPabstractAnomaly detection (AD) identifies outliers for applications like defect and lesion detection. While CLIP shows promise for zero-shot AD tasks due to its strong generalization capabilities, its inherent Anomaly-Unawareness leads to limited discrimination between normal and abnormal features. To address this problem, we propose Anomaly-Aware CLIP (AA-CLIP), which enhances CLIP's anomaly discrimination ability in both text and visual spaces while preserving its generalization capability. AA-CLIP is achieved through a straightforward yet effective two-stage approach: it first creates anomaly-aware text anchors to differentiate normal and abnormal semantics clearly, then aligns patch-level visual features with these anchors for precise anomaly localization. This two-stage strategy, with the help of residual adapters, gradually adapts CLIP in a controlled manner, achieving effective AD while maintaining CLIP's class knowledge. Extensive experiments validate AA-CLIP as a resource-efficient solution for zero-shot AD tasks, achieving state-of-the-art results in industrial and medical applications. The code is available at https://github.com/Mwxinnn/AA-CLIP. Qingsong Yao, Fenghe Tang, Chenxu Wu, Yingtai Li, Rui Yan 0009, Zihang Jiang, Shaohua Kevin Zhou |
CVPR | 3 |
| 2025 | Detect Anything 3D in the Wild
Hanxue Zhang, Qingsong Yao, Yanan Sun 0005, Renrui Zhang, Hao Zhao 0002, Hongyang Li 0001, Hongzi Zhu, Zetong Yang |
ICCV | 3 |
| 2025 | Multi-Step Adaptive Attack Agent: A Dynamic Approach for Jailbreaking Large Language ModelsabstractLarge Language Models (LLMs) have showcased remarkable potential across various domains, especially in text generation. However, their vulnerability to jailbreak attacks presents considerable challenges to secure deployment, as attackers can use carefully crafted prompts to bypass safety measures and generate harmful content. Current jailbreak methods generally suffer from two significant limitations: a restricted strategy space for generating adversarial prompts and insufficient optimization of prompts based on feedback from LLMs. To overcome these challenges, we present Multistep Adaptive Attack Agent (MATA), an approach that employs a game-theoretic interaction between attack model and target model to adaptively execute jailbreak attacks on LLMs. This method enables iterative attempts based on reflection, gradually identifying the optimal jailbreak attack strategy within a complex strategy space. We compared MATA with mainstream methods across multiple open-source and closed-source LLMs, including Llama3.1, GLM4, and GPT4o. The results demonstrate that our approach exceeds existing methods in terms of attack success rate, average number of queries, and prompt diversity, effectively identifying vulnerabilities in LLMs. Huiyun Jing, Jincheng Wei, Yingshui Tan, Boren Zheng, Qingsong Yao |
ICTAI | 6 |
| 2025 | SimCroP: Radiograph Representation Learning with Similarity-Driven Cross-Granularity Pre-training
Rongsheng Wang 0003, Fenghe Tang, Qingsong Yao, Rui Yan 0009, Zhen Huang 0007, Haoran Lai, Zhiyang He, Xiaodong Tao, Zihang Jiang, Shaohua Kevin Zhou |
MICCAI (5) | 3 |
| 2025 | Towards Accurate Unified Anomaly SegmentationabstractUnsupervised anomaly detection (UAD) from images strives to model normal data distributions, creating discriminative representations to distinguish and precisely localize anomalies. Despite recent advancements in the efficient and unified one-for-all scheme, challenges persist in accurately segmenting anomalies for further monitoring. Moreover, this problem is obscured by the widely-used AUROC metric under imbalanced UAD settings. This motivates us to emphasize the significance of precise segmentation of anomaly pixels using pAP and DSC as metrics. To address the unsolved segmentation task, we introduce the Unified Anomaly Segmentation (UniAS). UniAS presents a multi-level hybrid pipeline that progressively enhances normal information from coarse to fine, incorporating a novel multi-granularity gated CNN (MGG-CNN) into Transformer layers to explicitly aggregate local details from different granularities. UniAS achieves state-of-the-art anomaly segmentation performance, attaining 65.12/59.33 and 40.06/32.50 in pAP/DSC on the MVTec-AD and VisA datasets, respectively, surpassing previous methods significantly. The codes are shared at https://github.com/Mwxinnn/UniAS. Qingsong Yao, Zhelong Huang, Zihang Jiang, Shaohua Kevin Zhou |
WACV | 2 |
| 2025 | ECAMP: Entity-centered Context-aware Medical Vision Language Pre-training
Rongsheng Wang 0003, Qingsong Yao, Zihang Jiang, Haoran Lai, Zhiyang He, Xiaodong Tao, Shaohua Kevin Zhou |
Medical Image Anal. | 2 |
| 2025 | IGU-Aug: Information-Guided Unsupervised Augmentation and Pixel-Wise Contrastive Learning for Medical Image AnalysisabstractContrastive learning (CL) is a form of self-supervised learning and has been widely used for various tasks. Different from widely studied instance-level contrastive learning, pixel-wise contrastive learning mainly helps with pixel-wise dense prediction tasks. The counterpart to an instance in instance-level CL is a pixel, along with its neighboring context, in pixel-wise CL. Aiming to build better feature representation, there is a vast literature about designing instance augmentation strategies for instance-level CL; but there is little similar work on pixel augmentation for pixel-wise CL with a pixel granularity. In this paper, we attempt to bridge this gap. We first classify a pixel into three categories, namely low-, medium-, and high-informative, based on the information quantity the pixel contains. We then adaptively design separate augmentation strategies for each category in terms of augmentation intensity and sampling ratio. Extensive experiments validate that our information-guided pixel augmentation strategy succeeds in encoding more discriminative representations and surpassing other competitive approaches in unsupervised local feature matching. Furthermore, our pretrained model improves the performance of both one-shot and fully supervised models. To the best of our knowledge, we are the first to propose a pixel augmentation method with a pixel granularity for enhancing unsupervised pixel-wise contrastive learning. Code is available at https://github.com/Curli-quan/IGU-Aug. Quan Quan, Qingsong Yao, Heqin Zhu, Shaohua Kevin Zhou |
IEEE Trans. Medical Imaging | 2 |
| 2024 | Watch the Rhythm: Breaking Privacy with Accelerometer at the Extremely-Low Sampling Rate of 5HzabstractConsidering the threat from on-board eavesdropping with smartphone motion sensors, Android 12 has limited the maximum sampling rate of motion sensors to 200Hz for zero-privilege access to prevent potential wiretapping.Unfortunately, there have been some attacks targeting 200Hz, making it not a safe sampling rate any more.Smartphone manufacturers may further reduce the maximum sampling rate of the accelerometer in response to this privacy concern.It can be expected that, the maximum sampling rate will gradually decrease to a very low level, as the battle between manufacturers and adversaries continues.Existing on-board eavesdropping approaches, utilizing spectral features, cannot provide acceptable accuracy at very low sampling rates, not even at 50Hz.Therefore, this paper explores the feasibility of using the onboard accelerometer for privacy breaking with an extremely-low sampling rate, specifically, 5Hz.5Hz is a minimum sampling rate to meet normal use, otherwise the applications can only choose to work without the accelerometer.Since the lowest fundamental frequency for humans is around 85Hz, such a low sampling rate poses a significant challenge for sound recognition.According to Nyquist's law, it seems impossible to capture 85Hz with the sampling rate of 5Hz.Fortunately, we observe that the rhythm features, including pause rhythm and intensity rhythm, of accelerometer data are relatively stable at various sampling rates.On this basis, we propose an eavesdropping approach with the accelerometer at an extremely-low sampling rate.Introducing the rhythm features, we * He completed his work on this paper as a graduate student at Xidian University, unrelated to his current institution. Qingsong Yao, Xiongjia Sun, Xuewen Dong, Xiaoyu Ji 0001, Jianfeng Ma 0001 |
CCS | 1 |
| 2024 | CARZero: Cross-Attention Alignment for Radiology Zero-Shot ClassificationabstractThe advancement of Zero-Shot Learning in the medi-cal domain has been driven forward by using pretrained models on large-scale image-text pairs, focusing on image-text alignment. However, existing methods primarily rely on cosine similarity for alignment, which may not fully capture the complex relationship between medical images and reports. To address this gap, we introduce a novel approach called Cross-Attention Alignment for Radiology Zero-Shot Classification (CARZero). Our approach innovatively leverages cross-attention mechanisms to process image and report features, creating a Similarity Representation that more accurately reflects the intricate relationships in medical semantics. This representation is then linearly projected to form an image-text similarity matrix for cross-modality alignment. Additionally, recognizing the pivotal role of prompt selection in zero-shot learning, CARZero in-corporates a Large Language Model-based prompt alignment strategy. This strategy standardizes diverse diagnostic expressions into a unified format for both training and inference phases, overcoming the challenges of manual prompt design. Our approach is simple yet effective, demonstrating state-of-the-art performance in zero-shot classification on five official chest radiograph diagnostic test sets, including remarkable results on datasets with long-tail distributions of rare diseases. This achievement is attributed to our new image-text alignment strategy, which effectively addresses the complex relationship between medical images and reports. Code and models are available at https://github.com/laihaoran/CARZero. Haoran Lai, Qingsong Yao, Zihang Jiang, Rongsheng Wang 0003, Zhiyang He, Xiaodong Tao, Shaohua Kevin Zhou |
CVPR | 2 |
| 2024 | PhantomPatch: Easy-ignoring Attacks on Object Detectors Using Ghosting ArtifactsabstractCurrent patches used to attack object detectors are easily noticeable as abnormal. To mitigate this shortcoming, we devise an innovative technique named PhantomPatch, which leverages lens flare phenomena to attack object detectors, particularly in autonomous driving systems. Leveraging transfer-based adversarial examples, this method fools object detectors by projecting deceptive lens flares or ghost images, which are meaningless to people, while the light source looks like nearby light for people. Thus, it is easy to ignore.In this way, we enable a cost-effective approach to manipulate the perception of the vehicle remotely. This strategy harmonizes adversarial patches with projecting image integrity correcting. Firstly, we propose to train a black-box transfer-based adversarial patch to fool the object-detecting system behind the camera. Then, the patch is printed and attached in front of a flashlight, which casts the patch onto the camera, resulting in a ghost image. We maintain the integrity of the image captured by the camera while casting the patch with image loss correction and optical distortion modeling.Our experimental results validate the effectiveness of PhantomPatch in evading existing object detectors such as YOLO V3/V5 and Faster R-CNN. Notably, during nocturnal scenarios, the technique achieves a success rate of 98.2%. Furthermore, our approach addresses limitations of existing methods, like conspicuousness and positional constraints, offering a low-cost and effective technique for adversarial attacks, especially for autonomous vehicles. Code and demo are available at https://github.com/rufus0803/PhantomPatch. Qingsong Yao, Jingwei Li 0001, Xuewen Dong, Jianfeng Ma 0001 |
ISPA | 2 |
| 2024 | HySparK: Hybrid Sparse Masking for Large Scale Medical Image Pre-training
Fenghe Tang, Ronghao Xu, Qingsong Yao, Xueming Fu, Quan Quan, Heqin Zhu, Zaiyi Liu, Shaohua Kevin Zhou |
MICCAI (11) | 3 |
| 2024 | SIX-Net: Spatial-Context Information miX-up for Electrode Landmark Detection
Heqin Zhu, Qingsong Yao, Yiyong Sun, Shaohua Kevin Zhou |
MICCAI (1) | 4 |
| 2024 | Enabling Partitionable and Combinable Object Tracking on BlockchainabstractTraditional centralized traceability systems face security risks and information credibility issues, while existing blockchain-based solutions struggle with object partitioning and combination in complex supply chains. This paper proposes a blockchain-based Non-Fungible, Partitionable, and Combinable Object (NFPCO) traceability framework to address scenarios involving multi-source and complex assembly processes. We present a formal definition and triple model for NFPCOs, along with a lightweight traceability and auditing method supporting$O(\log N)$complexity for partition-combination verification and$O(1)$complexity for state change verification. The framework is implemented in a consortium blockchain environment, enhancing system efficiency and reducing storage costs through underlying architecture extensions and efficient indexing mechanisms. The framework is implemented in a consortium blockchain environment, leveraging underlying architecture extensions and efficient indexing mechanisms to enhance system efficiency and reduce storage costs. Experimental results demonstrate that our approach provides verifiable traceability paths with low overhead, offering an effective solution for complex supply chain management and product traceability in scenarios requiring frequent partitioning and combination of objects. Ao Zhu, Qingsong Yao, Aocheng Duan, Delun Wu |
MSN | 2 |
| 2024 | FairMedFM: Fairness Benchmarking for Medical Imaging Foundation ModelsabstractThe advent of foundation models (FMs) in healthcare offers unprecedented opportunities to enhance medical diagnostics through automated classification and segmentation tasks. However, these models also raise significant concerns about their fairness, especially when applied to diverse and underrepresented populations in healthcare applications. Currently, there is a lack of comprehensive benchmarks, standardized pipelines, and easily adaptable libraries to evaluate and understand the fairness performance of FMs in medical imaging, leading to considerable challenges in formulating and implementing solutions that ensure equitable outcomes across diverse patient populations. To fill this gap, we introduce FairMedFM, a fairness benchmark for FM research in medical imaging. FairMedFM integrates with 17 popular medical imaging datasets, encompassing different modalities, dimensionalities, and sensitive attributes. It explores 20 widely used FMs, with various usages such as zero-shot learning, linear probing, parameter-efficient fine-tuning, and prompting in various downstream tasks -- classification and segmentation. Our exhaustive analysis evaluates the fairness performance over different evaluation metrics from multiple perspectives, revealing the existence of bias, varied utility-fairness trade-offs on different FMs, consistent disparities on the same datasets regardless FMs, and limited effectiveness of existing unfairness mitigation methods. Furthermore, FairMedFM provides an open-sourced codebase at https://github.com/FairMedFM/FairMedFM, supporting extendible functionalities and applications and inclusive for studies on FMs in medical imaging over the long term. Ruinan Jin, Yuan Zhong 0003, Qingsong Yao, Qi Dou 0001, Shaohua Kevin Zhou, Xiaoxiao Li 0001 |
NeurIPS | 4 |
| 2024 | Which images to label for few-shot medical image analysis?
Quan Quan, Qingsong Yao, Heqin Zhu, Qiyuan Wang 0001, Shaohua Kevin Zhou |
Medical Image Anal. | 2 |
| 2024 | Adversarial Medical Image With Hierarchical Feature HidingabstractDeep learning based methods for medical images can be easily compromised by adversarial examples (AEs), posing a great security flaw in clinical decision-making. It has been discovered that conventional adversarial attacks like PGD which optimize the classification logits, are easy to distinguish in the feature space, resulting in accurate reactive defenses. To better understand this phenomenon and reassess the reliability of the reactive defenses for medical AEs, we thoroughly investigate the characteristic of conventional medical AEs. Specifically, we first theoretically prove that conventional adversarial attacks change the outputs by continuously optimizing vulnerable features in a fixed direction, thereby leading to outlier representations in the feature space. Then, a stress test is conducted to reveal the vulnerability of medical images, by comparing with natural images. Interestingly, this vulnerability is a double-edged sword, which can be exploited to hide AEs. We then propose a simple-yet-effective hierarchical feature constraint (HFC), a novel add-on to conventional white-box attacks, which assists to hide the adversarial feature in the target feature distribution. The proposed method is evaluated on three medical datasets, both 2D and 3D, with different modalities. The experimental results demonstrate the superiority of HFC,i.e., it bypasses an array of state-of-the-art adversarial medical AE detectors more efficiently than competing adaptive attacks1, which reveals the deficiencies of medical reactive defense and allows to develop more robust defenses in future. Qingsong Yao, Zecheng He, Yuexiang Li, Yi Lin 0009, Kai Ma 0002, Yefeng Zheng 0001, Shaohua Kevin Zhou |
IEEE Trans. Medical Imaging | 1 |
| 2023 | FairAdaBN: Mitigating Unfairness with Adaptive Batch Normalization and Its Application to Dermatological Disease Classification
Shang Zhao 0004, Quan Quan, Qingsong Yao, Shaohua Kevin Zhou |
MICCAI (2) | 4 |
| 2023 | UOD: Universal One-Shot Detection of Anatomical Landmarks
Heqin Zhu, Quan Quan, Qingsong Yao, Zaiyi Liu, Shaohua Kevin Zhou |
MICCAI (1) | 3 |
| 2023 | Performance-Power Tradeoff in Heterogeneous SaaS Clouds With Trustworthiness GuaranteeabstractSoftware-as-a-service (SaaS) clouds grow dramatically due to cost-effectiveness, availability, and flexibility. Quality of service (QoS) and power, which represent performance and cost, respectively, are conflicting yet critical issues in the service scheduling of SaaS clouds, and some researchers have investigated the tradeoff between them. However, existing works do not involve QoS attacks in which untrusted service providers provide fake QoS values to absorb service requests, resulting in lower user experience and system profits. In this paper, we jointly consider the QoS performance, queue congestion, and energy consumption to formulate the performance-power tradeoff while considering QoS attacks. To address this NP scheduling problem, we propose a Lyapunov-based decomposition strategy that converts the original problem into three equivalent subproblems. By aggregating the solving strategies for the three subproblems, we develop the online service selection and trustworthiness management algorithm that optimizes the performance–power tradeoff while resisting QoS attacks. In addition, a light-weighted trustworthiness management strategy is designed to update trustworthiness values without storing large amounts of past information. Mathematical analyses and simulations demonstrate that our proposed control framework realizes detection and resistance of QoS attacks and a$[O(1 / V), O(V)]$tradeoff between performance and power with a performance-power tradeoff parameter V. Zijie Di, Qingsong Yao, Xuewen Dong, Yulong Shen 0001 |
IEEE Trans. Computers | 3 |
| 2023 | Load Balancing of Double Queues and Utility-Workload Tradeoff in Heterogeneous Mobile Edge ComputingabstractMobile edge computing (MEC) is a popular service paradigm by which mobile devices can offload their latency-sensitive and computation-intensive workloads to edge servers. The MEC service scheduling problem has been investigated in recent years. However, most MEC service scheduling mechanisms only consider workloads on homogeneous edge servers, causing servers’ queue backlogs to be too large when innumerable user requests arrive concurrently. In this paper, we are the first to propose a double-queue workloads scheduling model innovatively, and formulate a system (including user ends and edge server ends) utility into a scheduling optimization problem. To tackle such an NP scheduling problem, we present a Lyapunov-based decomposition strategy to convert the original problem into three equivalent subproblems. By aggregating three subproblem solving strategies, we propose the Lyapunov-based online matching algorithm for edge service scheduling, named LOMES, to obtain an optimal system utility while guaranteeing the load balancing of mobile devices and heterogeneous edge servers. Simulations further validate that LOMES realizes the load balancing of two queue lengths and a$[O(1/V); O(V)]$tradeoff between the system’s utility and workloads with a utility-workload tradeoff parameter${V}$. Xuewen Dong, Zijie Di, Liangmin Wang 0001, Qingsong Yao, Guangxia Li, Yulong Shen 0001 |
IEEE Trans. Wirel. Commun. | 4 |
| 2022 | Which images to label for few-shot medical landmark detection?abstractThe success of deep learning methods relies on the availability of well-labeled large-scale datasets. However, for medical images, annotating such abundant training data often requires experienced radiologists and consumes their limited time. Few-shot learning is developed to alleviate this burden, which achieves competitive performances with only several labeled data. However, a crucial yet previously overlooked problem in few-shot learning is about the selection of template images for annotation before learning, which affects the final performance. We herein propose a novel Sample Choosing Policy (SCP) to select “the most worthy” images for annotation, in the context of few-shot medical landmark detection. SCP consists of three parts: 1) Self-supervised training for building a pre-trained deep model to extract features from radiological images, 2) Key Point Proposal for localizing informative patches, and 3) Representative Score Estimation for searching the most representative samples or templates. The advantage of SCP is demonstrated by various experiments on three widely-used public datasets. For one-shot medical landmark detection, its use reduces the mean radial errors on Cephalometric and HandXray datasets by 14.2% (from 3.595mm to 3.083mm) and 35.5% (4.114mm to 2.653mm), respectively. Quan Quan, Qingsong Yao, Jun Li 0103, Shaohua Kevin Zhou |
CVPR | 2 |
| 2022 | Rib Suppression in Digital Chest Tomosynthesis
Yihua Sun, Qingsong Yao, Yuanyuan Lyu, Jianji Wang 0003, Hongen Liao, Shaohua Kevin Zhou |
MICCAI (1) | 2 |
| 2021 | Delica: Decentralized Lightweight Collective Attestation for Disruptive IoT NetworksabstractThe recent advance of the Internet of Things and autonomous systems brings massive security threats to the network of low-end embedded devices. Remote attestation is a hardware-assisted technique to verify the integrity and trustworthiness of software on remote devices. The recently proposed collective remote attestations have focused on attesting to the highly dynamic and disruptive device networks. However, they are generally inefficient due to the homogeneous node setting for the robustness of attestation reports aggregation. In this work, we propose Delica, an efficient and robust collective attestation framework for dynamic and disruptive networks. We differentiate the role of provers and aggregators to limit the redundant communications and attestation evidence aggregations for efficiency. Delica is capable of mitigating DoS attacks and detecting physical and black-hole attacks. The experimental results and analysis show that Delica can greatly reduce the per-node computational cost and reduce the network attestation cost by over 75% compared with the state-of-the-art approaches on disruptive networks. Cong Sun 0001, Qingsong Yao, Duo Ding, Jianfeng Ma 0001 |
ICPADS | 3 |
| 2021 | A Hierarchical Feature Constraint to Camouflage Medical Adversarial Attacks
Qingsong Yao, Zecheng He, Yi Lin 0009, Kai Ma 0002, Yefeng Zheng 0001, Shaohua Kevin Zhou |
MICCAI (3) | 1 |
| 2021 | One-Shot Medical Landmark Detection
Qingsong Yao, Quan Quan, Li Xiao 0005, Shaohua Kevin Zhou |
MICCAI (2) | 1 |
| 2021 | You only Learn Once: Universal Anatomical Landmark Detection
Heqin Zhu, Qingsong Yao, Li Xiao 0005, Shaohua Kevin Zhou |
MICCAI (5) | 2 |
| 2021 | Optimal Mobile Crowdsensing Incentive Under Sensing InaccuracyabstractDue to the pervasive adoption of sensor-embedded mobile devices yet increasing demand on data and computing resources, mobile crowdsensing is a promising paradigm with rapid growth. One of the most challenging issues is how to maximize the utilities of crowdsensing platforms under inaccurate distributed sensing. The nature of such inaccuracy is due to the fact that energy-based sensing can be greatly impacted by thermal and environmental noise, which significantly affects task allocation strategies of crowdsensing platforms. Because of the allocation efficiency and fairness concerns, auction-based mechanisms have been extensively used in crowdsensing systems. However, the existing auction-based mechanisms for crowdsensing do not take sensing inaccuracy into consideration, while guaranteeing that each participator obtains her maximal utility by bidding with her true cost for tasks. To tackle this issue, in this article, we propose OSIER, an optimal mobile crowdsensing incentive under sensing inaccuracy. Specifically, a quantitative analytical framework on characterizing the impact of sensing inaccuracy on a crowdsensing platform is presented, and an optimization problem involving sensing inaccuracy is solved to achieve a maximum utility of the platform. Furthermore, depending on whether a user needs to perform all tasks simultaneously or not, indivisible tasks and divisible tasks are discussed, and OSIER-I and OSIER-D are presented for these two kinds of tasks. Simulation results verify the truthfulness of OSIER, and given a sample set with 5%-20% noise in spectrum sensing, OSIER can achieve 10% higher utilities than the existing crowdsensing mechanisms on average. Xuewen Dong, Zhichao You, Tom H. Luan, Qingsong Yao, Yulong Shen 0001, Jianfeng Ma 0001 |
IEEE Internet Things J. | 4 |
| 2021 | Label-Free Segmentation of COVID-19 Lesions in Lung CTabstractScarcity of annotated images hampers the building of automated solution for reliable COVID-19 diagnosis and evaluation from CT. To alleviate the burden of data annotation, we herein present a label-free approach for segmenting COVID-19 lesions in CT via voxel-level anomaly modeling that mines out the relevant knowledge from normal CT lung scans. Our modeling is inspired by the observation that the parts of tracheae and vessels, which lay in the high-intensity range where lesions belong to, exhibit strong patterns. To facilitate the learning of such patterns at a voxel level, we synthesize 'lesions' using a set of simple operations and insert the synthesized 'lesions' into normal CT lung scans to form training pairs, from which we learn a normalcy-recognizing network (NormNet) that recognizes normal tissues and separate them from possible COVID-19 lesions. Our experiments on three different public datasets validate the effectiveness of NormNet, which conspicuously outperforms a variety of unsupervised anomaly detection (UAD) methods. Qingsong Yao, Li Xiao 0005, Peihang Liu, Shaohua Kevin Zhou |
IEEE Trans. Medical Imaging | 1 |
| 2020 | Towards Primary User Sybil-proofness for Online Spectrum Auction in Dynamic Spectrum AccessabstractDynamic spectrum access (DSA) is a promising platform to solve the spectrum shortage problem, in which auction based mechanisms have been extensively studied due to good spectrum allocation efficiency and fairness. Recently, Sybil attacks were introduced in DSA, and Sybil-proof spectrum auction mechanisms have been proposed, which guarantee that each single secondary user (SU) cannot obtain a higher utility under more than one fictitious identities. However, existing Sybil-poof spectrum auction mechanisms achieve only Sybil-proofness for SUs, but not for primary users (PUs), and simulations show that a cheating PU in those mechanisms can obtain a higher utility by Sybil attacks. In this paper, we propose TSUNAMI, the first Truthful and primary user Sybil-proof aUctioN mechAnisM for onlIne spectrum allocation. Specifically, we compute the opportunity cost of each SU and screen out cost-efficient SUs to participate in spectrum allocation. In addition, we present a bid-independent sorting method and a sequential matching approach to achieve primary user Sybil-proofness and 2-D truthfulness, which means that each SU or PU can gain her maximal utility by bidding with her true valuation of spectrum. We evaluate the performance and validate the desired properties of our proposed mechanism through extensive simulations. Xuewen Dong, Qiao Kang, Qingsong Yao, Di Lu 0001, Yang Xu 0012, Jia Liu 0009 |
INFOCOM | 3 |
| 2020 | Miss the Point: Targeted Adversarial Attack on Multiple Landmark Detection
Qingsong Yao, Zecheng He, Hu Han 0001, Shaohua Kevin Zhou |
MICCAI (4) | 1 |
| 2019 | 3D U2-Net: A 3D Universal U-Net for Multi-domain Medical Image Segmentation
Chao Huang 0009, Hu Han 0001, Qingsong Yao, Shankuan Zhu, Shaohua Kevin Zhou |
MICCAI (2) | 3 |
| 2017 | APDL: A Practical Privacy-Preserving Deep Learning Model for Smart Devices
XinDi Ma, Jianfeng Ma 0001, Sheng Gao 0002, Qingsong Yao |
MSN | 4 |
| 2017 | Certia: Certifying Interface Automata for Cyber-Physical SystemsabstractInterface automaton is a promising approach to model the temporal behaviors of system components, and its extension has been used to specify the security properties of component based systems. Currently, the formal properties of interface automata have not be certified with machine-checked proof by any proof assistant. In this work, we propose a Coq-library of interface automata which is developed in purpose to certify security properties of component-based cyber-physical systems, with an emphasis upon developing compositional verification of information flow security for cyber-physical applications. Cong Sun 0001, Qingsong Yao, Jianfeng Ma 0001 |
SMARTCOMP | 2 |
| 2015 | Vulnerability aware graphs for RFID protocol security benchmarking
Shan Chang, Li Lu 0001, Qingsong Yao |
J. Comput. Syst. Sci. | 5 |
| 2014 | Verifying Secure Interface Composition for Component-Based System DesignsabstractInformation flow security has been considered as a critical requirement on software systems, especially when heterogeneous components from different parties cooperate to achieve end-to-end enforcement on data confidentiality. Enforcing the information flow security properties on complicated systems faces a great challenge because the properties cannot be preserved under composition and most of the current approaches are not scalable enough. To address this problem, there have been several recent efforts on the compositional information flow analyses developed for different abstraction levels. But these approaches have rarely been considered to incorporate with the process of system design. Integrating the security enforcement with the model-based development process can provide the designer with ability to verify information flow security in the early stage of system development. We propose a compositional information flow verification which is integrated with model-based system design in Sys ML by an automated model translation from semi-formal behavior and structure models to interface automata. Our compositional approach is general to support the complex security lattices and a variety of in distinguish ability relations. The evaluation results show the usability of our approach on practical system designs and the scalability of the compositional verification. Cong Sun 0001, Ning Xi 0002, Jinku Li, Qingsong Yao, Jianfeng Ma 0001 |
APSEC (1) | 4 |
| 2011 | Privacy Leakage in Access Mode: Revisiting Private RFID Authentication ProtocolsabstractExisting RFID Privacy-Preserving Authentication (PPA) solutions mainly focus on the design of crypto based interactive protocols between readers and tags. Although the cryptographic mechanisms enable randomization and enhance protocol-level privacy, the access mode in RFID systems is less random and may leak private information. We introduce anew attack based on such privacy leakage in access mode, where we show that the mainstream RFID PPA protocols, including the linear, tree-based, and synchronization-based solutions, are not private. We also show that this new attack is easy to conduct, e.g., we can track tags that employ typical tree-based PPA protocols without the need of compromising tags. We discuss the applicability of the attack. Moreover, we provide useful recommendations to strengthen existing PPA protocols in defending against such attacks. The simulation results demonstrate the practicability and effectiveness of this attack. Qingsong Yao, Jinsong Han, Yong Qi 0001, Lei Yang 0025, Yunhao Liu 0001 |
ICPP | 1 |
| 2011 | MAP: Authenticating Multiple-TagsabstractThe prevalence of Radio Frequency Identification (RFID) technology requires Privacy-Preserving Authentication (PPA) protocols to combat the privacy leakage during authentication. Existing PPA protocols employ the per-tag authentication, in which the reader has to sequentially authenticate the tags within the detecting region. Such a processing pattern becomes a bottleneck in current RFID enabled systems, especially for batch-type processing applications. In this paper, we propose an efficient authentication protocol, which leverages the collaboration among multiple tags for accelerating the authentication speed. We also find that the collision, usually considered as a negative factor, is a helpful media to enable collaborative authentication among tags. Our protocol, termed as Multiple-tags privacy-preserving Authentication Protocol (MAP), authenticates a batch of tags concurrently with strong privacy protection and high efficiency guarantee. The analytical and simulation results show that the efficiency of MAP is better than O(logN) and asymptotically approaches O(1). Qingsong Yao, Jinsong Han, Saiyu Qi |
MASS | 1 |
| 2010 | Utilizing RF Interference to Enable Private Estimation in RFID SystemsabstractCounting or estimating the number of tags is crucial for RFID system. Researchers have proposed several fast cardinality estimation schemes to estimate the quantity of a batch of tags within a short time frame. Existing estimation schemes scarcely consider the privacy issue. Without effective protection, the adversary can utilize the responding signals to estimate the number of tags as accurate as the valid reader. To address this issue, we propose a novel privacy-preserving estimation scheme, termed as MEAS, which provides an active RF countermeasure against the estimation from invalid readers. MEAS comprises of two components, an Estimation Interference Device (EID) and two well-designed Interference Blanking Estimators (IBE). EID is deployed with the tags to actively generate interfering signals, which introduce sufficiently large estimation errors to invalid or malicious readers. Using a secret interference factor shared with EID, a valid reader can perform accurate estimation via two IBEs. Our theoretical analysis and simulation results show the effectiveness of MEAS. Meanwhile, MEAS can also maintain a high estimation accuracy using IBEs. Lei Yang 0025, Jinsong Han, Yong Qi 0001, Cheng Wang 0001, Qingsong Yao, Ying Chen 0004, Xiao Zhong |
ICPADS | 6 |
| 2010 | A Desynchronization Tolerant RFID Private Authentication Protocol
Qingsong Yao, Yong Qi 0001, Ying Chen 0004, Xiao Zhong |
WASA | 1 |
| 2009 | An Enhanced Synchronization Approach for RFID Private AuthenticationabstractRadio frequency identification (RFID) technologies are on their highway to pervasive usage. However privacy protection is still an important problem since RFID tags attached to items are so cost constrained. Privacy preserving authentication approaches are proposed to authenticate tags without private information leaking. Previously designed approaches based on synchronization seeks O(1) complexity. While these synchronization based methods are efficient in normal case, they have weak points when desynchronized. When maliciously scanned, information stored in tag and reader goes farther and farther away from each other. An adversary can utilize this point to track a tag. We propose an enhanced synchronization approach for RFID private authentication, ESP, to solve this problem. ESP can eliminate the problem caused by desynchronization attack and help detecting replay attack. Analysis shows that ESP enhances privacy protection while still maintaining the authentication efficiency. Qingsong Yao, Yong Qi 0001, Jizhong Zhao, Jinsong Han |
MASS | 1 |
| 2009 | Randomizing RFID Private AuthenticationabstractPrivacy protection is increasingly important during authentications in Radio Frequency Identification (RFID) systems. In order to achieve high-speed authentication in large-scale RFID systems, researchers propose tree-based approaches, in which any pair of tags share a number of key components. Such designs, being efficient, often fail to achieve forward secrecy and resistance to attacks, such as compromising and desynchronization. Indeed, these attacks may still take effect even after a tag successfully finishes the authentication and key-updating procedure. To address the issue, we propose a lightweight RFID private authentication protocol, RWP, based on the random walk concept. RWP also provides the forward security and temporal resistance to the tracking attack. The analysis results show that RWP effectively enhances the security protection for RFID private authentication, and increases the authentication efficiency from O(logN) to O(1). Qingsong Yao, Yong Qi 0001, Jinsong Han, Jizhong Zhao, Xiang-Yang Li 0001, Yunhao Liu 0001 |
PerCom | 1 |
| 2007 | Energy Efficient Multi-rate Based Time Slot Pre-schedule Scheme in WSNs for Ubiquitous EnvironmentabstractNowadays, smart spaces occupy an essential part of ubiquitous computing environment. The spaces integrated with wireless sensors networks, actuators and context-aware services become part of our daily life. Smart spaces are equipped with a large number of wireless sensors that aim to collect large quantities of context information, during the process, there exists a large amount of collisions and energy consumption. Therefore, this paper provides a novel multi-rate based local framing pre-schedule scheme to further reduce collisions and improve energy efficiency in CSMA/TDMA hybrid MAC layer of wireless sensor network. This MAC combines CSMA and TDMA functionalities together while obviates their shortcomings. Having been assigned, slot 0 is preserved as the pre-schedule slot, to inform neighbor nodes the schedule of the senders. During the pre-schedule slot, each node knows exactly the schedule of other neighbor nodes. Multi-rate and power scaling are applied to achieve further energy saving by adpoting an acceptable rate rather than maximum rate. Data rate is dynamically adjusted according to the traffic load of sending nodes, in an energy efficient data rate, to save energy. Being compared with Z-MAC in terms of performances, local framing pre-schedule and multi-rate in this experiment achieved further energy efficiency. Index Terms--MAC, CSMA, TDMA, Mult-Rate, Wireless Sensor Networks Wei Wei 0006, Yong Qi 0001, Saiyu Qi, Di Hou, Wei Wang 0015, Min Xi, Qingsong Yao |
APSCC | 7 |
| 2006 | Mining and Modeling Database User Access Patterns
Qingsong Yao, Aijun An, Jimmy Huang 0001 |
ISMIS | 1 |
| 2006 | Applying language modeling to session identification from database trace logs
Jimmy Huang 0001, Qingsong Yao, Aijun An |
Knowl. Inf. Syst. | 2 |
| 2005 | Finding and Analyzing Database User Sessions
Qingsong Yao, Aijun An, Jimmy Huang 0001 |
DASFAA | 1 |
| 2005 | A Machine Learning Approach to Identifying Database Sessions Using Unlabeled Data
Qingsong Yao, Jimmy Huang 0001, Aijun An |
DaWaK | 1 |
| 2005 | A Distance-Based Algorithm for Clustering Database User Sessions
Qingsong Yao, Aijun An, Jimmy Huang 0001 |
ISMIS | 1 |
| 2004 | Characterizing Database User's Access Patterns
Qingsong Yao, Aijun An |
DEXA | 1 |
| 2003 | Using User Access Patterns for Semantic Query Caching
Qingsong Yao, Aijun An |
DEXA | 1 |
| 2003 | SQL-Relay: An Event-Driven Rule-Based Database Gateway
Qingsong Yao, Aijun An |
WAIM | 1 |