VLDB 2026 Research / reviewers in the wild / expert
Hangtao Zhang
dblp:345/8090
· DBLP profile ↗
14ranked-venue papers
5as first author
14since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 7 · 4 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 3 first-author · 7 since 2021Security and privacy · 3 · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Fine-Grained Poisoning Framework Against Federated LearningabstractFederated learning(FL) is one of the most widely used distributed machine learning frameworks. However, FL is susceptible to poisoning attacks that can degrade the quality of the global model. Recent studies on fine-grained poisoning attacks highlight a strategic shift where attackers no longer prioritize maximal disruption of the global model, but instead control the degree of model poisoning to maintain stealth and avoid detection. However, research on fine-grained poisoning is still in the infant stage. Numerous fundamental questions have yet to be addressed, including its underlying mechanisms and optimization strategies. To this end, we introduces FGP, the first comprehensive framework forFine-GrainedPoisoning on FL, which allows adversaries to precisely manipulate the global model by strategically inducing accurate and stealthy sub-optimal solution. Fundamentally, FGP innovatively formalizes fine-grained attacks as an optimization problem to minimize the distance between the current global model and the adversary's target (a sub-optimal solution). It then employs a real-time search strategy to dynamically refine the malicious model updates in each round. To ensure optimal attack performance, we further introduce a novel topology-based approach as the error feedback. Additionally, we present a formal convergence analysis of our attacks. Armed with FGP, we conduct a comprehensive evaluation of FL's robustness against fine-grained poisoning across diverse settings. Results demonstrate that FGP significantly outperforms the prior work, achieving an average$6.5\times$higher attack accuracy. Hangtao Zhang, Yanjun Zhang 0002, Chao Chen 0015, Qiyun Shao, Shengshan Hu, Leo Yu Zhang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | TSCAN: Context-Aware Uplift Modeling via Two-Stage Training for Online Merchant Business DiagnosisabstractAccurate estimation of the Individual Treatment Effect (ITE) is essential for business diagnostics in the online food delivery industry, particularly for assessing the impact of various business strategies, such as inventory management, pricing optimization, and online marketing campaigns. A primary challenge in ITE estimation lies in sample selection bias. Conventional approaches utilize treatment regularization techniques such as Integral Probability Metric (IPM), re-weighting, and propensity score modeling to mitigate this bias. However, these regularizations may introduce undesirable information loss and limit predictive performance. Moreover, treatment effects exhibit substantial heterogeneity across external contextual factors, such as market demand, competitor activity, and time dynamics, yet existing methods fail to adequately model the interaction between treatments and context, limiting their causal expressiveness. To address these issues, we propose TSCAN: a Context-Aware uplift model based on a Two-Stage training approach, comprising CAN-U and CAN-D sub-models. In Stage 1, CAN-U generates counterfactual uplift labels while mitigating selection bias through integrated IPM and propensity score regularization. In Stage 2, CAN-D eliminates these regularizations and leverages an isotonic output layer to directly model uplift effects in a supervised manner. By reinforcing factual outcomes, CAN-D adaptively corrects estimation errors from CAN-U while circumventing the performance degradation induced by bias-mitigation regularizations. Additionally, both stages incorporate a Context-Aware Attention mechanism that dynamically fuses the embeddings of merchants, treatments, and contextual covariates, thereby capturing context-dependent heterogeneity in treatment effects. We conduct extensive experiments on two real-world datasets to validate the effectiveness of TSCAN. Ultimately, the deployment of our model for real-world merchant diagnosis on one of China’s largest online food ordering platforms validates its practical utility and impact. Hangtao Zhang |
ACM Trans. Knowl. Discov. Data | 1 |
| 2025 | Breaking Barriers in Physical-World Adversarial Examples: Improving Robustness and Transferability via Robust FeatureabstractAs deep neural networks (DNNs) are widely applied in the physical world, many researches are focusing on physical-world adversarial examples (PAEs), which introduce perturbations to inputs and cause the model's incorrect outputs. However, existing PAEs face two challenges: unsatisfactory attack performance (i.e., poor transferability and insufficient robustness to environment conditions), and difficulty in balancing attack effectiveness with stealthiness, where better attack effectiveness often makes PAEs more perceptible. In this paper, we explore a novel perturbation-based method to overcome the challenges. For the first challenge, we introduce a strategy Deceptive RF injection based on robust features (RFs) that are predictive, robust to perturbations, and consistent across different models. Specifically, it improves the transferability and robustness of PAEs by covering RFs of other classes onto the predictive features in clean images. For the second challenge, we introduce another strategy Adversarial Semantic Pattern Minimization, which removes most perturbations and retains only essential adversarial patterns in AEs. Based on the two strategies, we design our method Robust Feature Coverage Attack (RFCoA), comprising Robust Feature Disentanglement and Adversarial Feature Fusion. In the first stage, we extract target class RFs in feature space. In the second stage, we use attention-based feature fusion to overlay these RFs onto predictive features of clean images and remove unnecessary perturbations. Experiments show our method's superior transferability, robustness, and stealthiness compared to existing state-of-the-art methods. Additionally, our method's effectiveness can extend to Large Vision-Language Models (LVLMs), indicating its potential applicability to more complex tasks. Yichen Wang 0013, Yuxuan Chou, Ziqi Zhou 0001, Hangtao Zhang, Shengshan Hu |
AAAI | 4 |
| 2025 | Test-Time Backdoor Detection for Object Detection ModelsabstractObject detection models are vulnerable to backdoor attacks, where attackers poison a small subset of training samples by embedding a predefined trigger to manipulate prediction. Detecting poisoned samples (i.e., those containing triggers) at test time can prevent backdoor activation. However, unlike image classification tasks, the unique characteristics of object detection—particularly its output of numerous objects—pose fresh challenges for backdoor detection. The complex attack effects (e.g., "ghost" object emergence or "vanishing" object) further render current defenses fundamentally inadequate. To this end, we design TRAnsformation Consistency Evaluation (TRACE), a brand-new method for detecting poisoned samples at test time in object detection. Our journey begins with two intriguing observations: 1) poisoned samples exhibit significantly more consistent detection results than clean ones across varied backgrounds. 2) clean samples show higher detection consistency when introduced to different focal information. Based on these phenomena, Trace applies foreground and background transformations to each test sample, then assesses transformation consistency by calculating the variance in objects confidences. Trace achieves black-box, universal backdoor detection, with extensive experiments showing a 30% improvement in AUROC over state-of-the-art defenses and resistance to adaptive attacks. Hangtao Zhang, Yichen Wang 0013, Shihui Yan, Chenyu Zhu, Ziqi Zhou 0001, Linshan Hou, Shengshan Hu, Yanjun Zhang 0002, Leo Yu Zhang |
CVPR | 1 |
| 2025 | PB-UAP: Hybride Universal Adversarial Attack for Image SegmentationabstractWith the rapid advancement of deep learning, the model robustness has become a significant research hotspot, i.e., adversarial attacks on deep neural networks. Existing works primarily focus on image classification tasks, aiming to alter the model’s predicted labels. Due to the output complexity and deeper network architectures, research on adversarial examples for segmentation models is still limited, particularly for universal adversarial perturbations. In this paper, we propose a novel universal adversarial attack method designed for segmentation models, which includes dual feature separation and low-frequency scattering modules. The two modules guide the training of adversarial examples in the pixel and frequency space, respectively. Experiments demonstrate that our method achieves high attack success rates surpassing the state-of-the-art methods, and exhibits strong transferability across different models. Ziqi Zhou 0001, Xianlong Wang 0001, Hangtao Zhang, Menghao Deng, Shengshan Hu, Leo Yu Zhang |
ICASSP | 5 |
| 2025 | BadRobot: Jailbreaking Embodied LLM Agents in the Physical WorldabstractEmbodied AI represents systems where AI is integrated into physical entities. Multimodal Large Language Model (LLM), which exhibits powerful language understanding abilities, has been extensively employed in embodied AI by facilitating sophisticated task planning. However, a critical safety issue remains overlooked: could these embodied LLMs perpetrate harmful behaviors? In response, we introduce BadRobot, the first attack paradigm designed to jailbreak robotic manipulation, making embodied LLMs violate safety and ethical constraints through typical voice-based user-system interactions. Specifically, three vulnerabilities are exploited to achieve this type of attack: (i) manipulation of LLMs within robotic systems, (ii) misalignment between linguistic outputs and physical actions, and
(iii) unintentional hazardous behaviors caused by world knowledge's flaws. Furthermore, we construct a benchmark of various malicious physical action queries to evaluate BadRobot's attack performance. Based on this benchmark, extensive experiments against existing prominent embodied LLM frameworks (e.g., Voxposer, Code as Policies, and ProgPrompt) demonstrate the effectiveness of our BadRobot. We emphasize that addressing this emerging vulnerability is crucial for the secure deployment of LLMs in robotics.
Warning: This paper contains harmful AI-generated language and aggressive actions. Hangtao Zhang, Chenyu Zhu, Xianlong Wang 0001, Ziqi Zhou 0001, Changgan Yin, Lulu Xue, Yichen Wang 0013, Shengshan Hu, Aishan Liu, Peijin Guo, Leo Yu Zhang |
ICLR | 1 |
| 2025 | PSFD: Proactive Spatial-Frequency Defense against Malicious Exemplar-Guided Image EditingabstractDiffusion models has threatened image authenticity by enabling highly realistic fakes. Proactive defense offers protection by adding a "protective layer" that resists such manipulation. However, current proactive defenses mainly focus on text-guided editing but are less effective for the more challenging exemplar-guided tasks. To bridge this gap, we propose Proactive Spatial-Frequency Defense (PSFD), a novel proactive defense for exemplar-guided image editing. PSFD leverages adversarial attack to add subtle perturbations to make images immune to editing. We apply protections in both the frequency and spatial domains. Spatial perturbation disrupts feature extraction by forcing visual encoders to map the image to "bad" representations. Frequency perturbation tweaks the high-frequency components to distort the image’s texture information. We design two optimization strategies: PSFD-U that aims to generate maximal variation and PSFD-T that seeks to achieve specific editing styles. Extensive experiments on MS-COCO and ImageNet demonstrate PSFD’s strong defensive capabilities and transferability. Xiaojun Mo, Meng Xie, Hangtao Zhang, Yixiang Liu, Yezhuo Peng, Yanchun Li |
ICME | 4 |
| 2025 | AdvEDM: Fine-grained Adversarial Attack against VLM-based Embodied AgentsabstractVision-Language Models (VLMs), with their strong reasoning and planning capabilities, are widely used in embodied decision-making (EDM) tasks in embodied agents, such as autonomous driving and robotic manipulation. Recent research has increasingly explored adversarial attacks on VLMs to reveal their vulnerabilities. However, these attacks either rely on overly strong assumptions, requiring full knowledge of the victim VLM, which is impractical for attacking VLM-based agents, or exhibit limited effectiveness. The latter stems from disrupting most semantic information in the image, which leads to a misalignment between the perception and the task context defined by system prompts. This inconsistency interrupts the VLM's reasoning process, resulting in invalid outputs that fail to affect interactions in the physical world. To this end, we propose a fine-grained adversarial attack framework, AdvEDM, which modifies the VLM's perception of only a few key objects while preserving the semantics of the remaining regions. This attack effectively reduces conflicts with the task context, making VLMs output valid but incorrect decisions and affecting the actions of agents, thus posing a more substantial safety threat in the physical world. We design two variants of based on this framework, AdvEDM-R and AdvEDM-A, which respectively remove the semantics of a specific object from the image and add the semantics of a new object into the image. The experimental results in both general scenarios and EDM tasks demonstrate fine-grained control and excellent attack performance. Yichen Wang 0013, Hangtao Zhang, Hewen Pan, Ziqi Zhou 0001, Xianlong Wang 0001, Peijin Guo, Lulu Xue, Shengshan Hu, Leo Yu Zhang |
NeurIPS | 2 |
| 2025 | DarkHash: A Data-Free Backdoor Attack Against Deep HashingabstractBenefiting from its superior feature learning capabilities and efficiency, deep hashing has achieved remarkable success in large-scale image retrieval. Recent studies have demonstrated the vulnerability of deep hashing models to backdoor attacks. Although these studies have shown promising attack results, they rely on access to the training dataset to implant the backdoor. In the real world, obtaining such data (e.g., identity information) is often prohibited due to privacy protection and intellectual property concerns. Embedding backdoors into deep hashing models without access to the training data, while maintaining retrieval accuracy for the original task, presents a novel and challenging problem. In this paper, we propose DarkHash, the first data-free backdoor attack against deep hashing. Specifically, we design a novel shadow backdoor attack framework with dual-semantic guidance. It embeds backdoor functionality and maintains original retrieval accuracy by fine-tuning only specific layers of the victim model using a surrogate dataset. We consider leveraging the relationship between individual samples and their neighbors to enhance backdoor attacks during training. By designing a topological alignment loss, we optimize both individual and neighboring poisoned samples toward the target sample, further enhancing the attack capability. Experimental results on four image datasets, five model architectures, and two hashing methods demonstrate the high effectiveness of DarkHash, outperforming existing state-of-the-art backdoor attack methods. Defense experiments show that DarkHash can withstand existing mainstream backdoor defense methods. Ziqi Zhou 0001, Menghao Deng, Hangtao Zhang, Shengshan Hu, Leo Yu Zhang, Dezhong Yao 0002 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Detector Collapse: Backdooring Object Detection to Catastrophic Overload or Blindness in the Physical World
Hangtao Zhang, Shengshan Hu, Yichen Wang 0013, Leo Yu Zhang, Ziqi Zhou 0001, Xianlong Wang 0001, Yanjun Zhang 0002, Chao Chen 0015 |
IJCAI | 1 |
| 2024 | Unlearnable 3D Point Clouds: Class-wise Transformation Is All You NeedabstractTraditional unlearnable strategies have been proposed to prevent unauthorized users from training on the 2D image data. With more 3D point cloud data containing sensitivity information, unauthorized usage of this new type data has also become a serious concern. To address this, we propose the first integral unlearnable framework for 3D point clouds including two processes: (i) we propose an unlearnable data protection scheme, involving a class-wise setting established by a category-adaptive allocation strategy and multi-transformations assigned to samples; (ii) we propose a data restoration scheme that utilizes class-wise inverse matrix transformation, thus enabling authorized-only training for unlearnable data. This restoration process is a practical issue overlooked in most existing unlearnable literature, i.e., even authorized users struggle to gain knowledge from 3D unlearnable data. Both theoretical and empirical results (including 6 datasets, 16 models, and 2 tasks) demonstrate the effectiveness of our proposed unlearnable framework. Our code is available at https://github.com/CGCL-codes/UnlearnablePC. Xianlong Wang 0001, Wei Liu 0004, Hangtao Zhang, Shengshan Hu, Yechao Zhang, Ziqi Zhou 0001, Hai Jin 0001 |
NeurIPS | 4 |
| 2024 | Reverse Backdoor Distillation: Towards Online Backdoor Attack Detection for Deep Neural Network ModelsabstractThe backdoor attack on deep neural network models implants malicious data patterns in a model to induce attacker-desirable behaviors. Existing defense methods fall into the online and offline categories, in which the offline models achieve state-of-the-art detection rates but are restricted by heavy computation overhead. In contrast, their more deployable online counterparts lack the means to detect source-specific backdoors with large sizes. This work proposes a new online backdoor detection method—Reverse Backdoor Distillation (RBD) to handle issues associated with source-specific and source-agnostic backdoor attacks. RBD, designed with the novel perspective of distilling instead of erasing backdoor knowledge, is a complementary backdoor detection methodology that can be used in conjunction with other online backdoor defenses. Considering the fact that trigger data will cause overwhelming neuron activation while clean data will not, RBD distills backdoor attack pattern knowledge from a suspicious model to create a shadow model, which is subsequently deployed online along with the original model in scope to predict a backdoor attack. We extensively evaluate RBD on several datasets (MNIST, GTSRB, CIFAR-10) with diverse model architectures and trigger patterns. RBD outperforms online benchmarks in all experimental settings. Notably, RBD demonstrates superior capability in detecting source-specific attacks, where comparison methods fail, underscoring the effectiveness of our proposed technique. Moreover, RBD achieves a computational savings of at least 97%. Zeming Yao, Hangtao Zhang, Yicheng Guo, Xin Tian 0015, Wei Peng 0011, Yi Zou 0001, Leo Yu Zhang, Chao Chen 0015 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | Denial-of-Service or Fine-Grained Control: Towards Flexible Model Poisoning Attacks on Federated LearningabstractFederated learning (FL) is vulnerable to poisoning attacks, where adversaries corrupt the global aggregation results and cause denial-of-service (DoS). Unlike recent model poisoning attacks that optimize the amplitude of malicious perturbations along certain prescribed directions to cause DoS, we propose a flexible model poisoning attack (FMPA) that can achieve versatile attack goals. We consider a practical threat scenario where no extra knowledge about the FL system (e.g., aggregation rules or updates on benign devices) is available to adversaries. FMPA exploits the global historical information to construct an estimator that predicts the next round of the global model as a benign reference. It then fine-tunes the reference model to obtain the desired poisoned model with low accuracy and small perturbations. Besides the goal of causing DoS, FMPA can be naturally extended to launch a fine-grained controllable attack, making it possible to precisely reduce the global accuracy. Armed with precise control, malicious FL service providers can gain advantages over their competitors without getting noticed, hence opening a new attack surface in FL other than DoS. Even for the purpose of DoS, experiments show that FMPA significantly decreases the global accuracy, outperforming six state-of-the-art attacks. Hangtao Zhang, Zeming Yao, Leo Yu Zhang, Shengshan Hu, Chao Chen 0015, Alan Wee-Chung Liew, Zhetao Li |
IJCAI | 1 |
| 2023 | AdvCLIP: Downstream-agnostic Adversarial Examples in Multimodal Contrastive LearningabstractMultimodal contrastive learning aims to train a general-purpose feature extractor, such as CLIP, on vast amounts of raw, unlabeled paired image-text data. This can greatly benefit various complex downstream tasks, including cross-modal image-text retrieval and image classification. Despite its promising prospect, the security issue of cross-modal pre-trained encoder has not been fully explored yet, especially when the pre-trained encoder is publicly available for commercial use. Ziqi Zhou 0001, Shengshan Hu, Hangtao Zhang, Yechao Zhang, Hai Jin 0001 |
ACM Multimedia | 4 |