VLDB 2026 Research / reviewers in the wild / expert
Gejian Zhao
dblp:337/0373
· DBLP profile ↗
6ranked-venue papers
5as first author
6since 2021 · last 2026
0009-0007-5289-9264ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CREF: Concept Response Fingerprints for Large Language ModelsabstractProtecting the intellectual property of Large Language Models (LLMs) is critical because training them requires massive computational resources and data. A key challenge is determining whether a suspicious model is derived from a specific base model after fine-tuning or structural modification. Existing fingerprinting methods rely on model weights or high-dimensional representations, leading to substantial storage overhead. We propose a non-intrusive fingerprinting framework Concept REsponse Fingerprints (CREF). Inspired by activation engineering, CREF constructs a set of concept activation vectors as semantic probes. It then measures the response strength of hidden representations along these concept activation vectors using shared inputs. The resulting concept response matrix serves as a compact fingerprint, and similarity between models is measured using centered kernel alignment. Experiments on multiple LLM families show that CREF reliably distinguishes derived models from independently trained models and remains robust to fine-tuning, pruning, parameter permutation, and scaling. Moreover, the fingerprint requires only kilobyte-level storage, making it practical for large-scale deployment and ownership verification. Haiyong Tang, Hanzhou Wu, Gejian Zhao, Li Li 0103, Zhihua Xia, Xinpeng Zhang 0001 |
IH&MMSec | 3 |
| 2026 | SensMark: Robust and interpretable model watermarking via contextual sensitivity estimation and adaptive trigger insertion
Gejian Zhao, Hanzhou Wu, Bin Li 0011, Xinpeng Zhang 0001, Athanasios V. Vasilakos |
Inf. Sci. | 1 |
| 2026 | ShadowCoT: Cognitive Hijacking for Stealthy Reasoning Backdoors in LLMsabstractChain-of-Thought (CoT) enhances an LLM’s ability to perform complex reasoning tasks, but it also introduces new security issues. In this work, we present ShadowCoT, a novel backdoor attack framework that targets the internal reasoning mechanism of LLMs. Unlike prior token-level or prompt-based attacks, ShadowCoT directly manipulates the model’s cognitive reasoning path, enabling it to hijack multi-step reasoning chains and produce logically coherent but adversarial outcomes. By conditioning on internal reasoning states, ShadowCoT learns to recognize and selectively disrupt key reasoning steps, effectively mounting a self-reflective cognitive attack within the target model. Our approach introduces a lightweight yet effective multi-stage injection pipeline, which selectively rewires attention pathways and perturbs intermediate representations with minimal parameter overhead (only 0.15% updated). ShadowCoT further leverages reinforcement learning and reasoning chain pollution (RCP) to autonomously synthesize stealthy adversarial CoTs that remain undetectable to advanced defenses. Extensive experiments across diverse reasoning benchmarks and LLMs show that ShadowCoT consistently achieves a state-of-the-art average Attack Success Rate of 91.2% (peaking at 94.4%) and a Hijacking Success Rate of 84.9% while preserving benign performance. These results reveal an emergent class of cognition-level threats and highlight the urgent need for defenses beyond shallowsurface-levelconsistency. Gejian Zhao, Hanzhou Wu, Xinpeng Zhang 0001, Athanasios V. Vasilakos |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Perceptual Robust Hashing for Video Copy Detection with Unsupervised LearningabstractIn this paper, we propose an end-to-end perceptual robust hashing scheme for video copy detection based on unsupervised learning. Firstly, the spatio-temporal information in videos is effectively fused and condensed into high-dimensional features through a 3D self-attention, multi-scale feature fusion model based on 3D-CNN, in which the Inception block and the 3D self-attention mechanism are integrated. Then, we calculate the correlation distances between the extracted features to differentiate perceptual contents. Based on the similarity relationship, we can dynamically generate the pseudo-labels and exploit them to further guide the model training for video hash generation. In addition, we design the dual constraints to make the hash code obtain satisfactory robustness and discrimination. Extensive experiments demonstrate that the proposed scheme achieves superior performance of copy detection compared with existing schemes and performs well even in the case of untrained manipulations. Gejian Zhao, Chuan Qin 0001, Xiangyang Luo 0001, Xinpeng Zhang 0001, Chin-Chen Chang 0001 |
IH&MMSec | 1 |
| 2023 | TASTNet: An end-to-end deep fingerprinting net with two-dimensional attention mechanism and spatio-temporal weighted fusion for video content authentication
Gejian Zhao, Fengyong Li, Heng Yao 0001, Chuan Qin 0001 |
J. Vis. Commun. Image Represent. | 1 |
| 2022 | DNN self-embedding watermarking: Towards tampering detection and parameter recovery for deep neural network
Gejian Zhao, Chuan Qin 0001, Heng Yao 0001, Yanfang Han |
Pattern Recognit. Lett. | 1 |