VLDB 2026 Research / reviewers in the wild / expert
Wenzhe Yi
dblp:346/0918
· DBLP profile ↗
13ranked-venue papers
2as first author
13since 2021 · last 2026
0000-0003-1096-2505ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 7 · 7 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SLeak: Multi-Target Privacy Stealing Attack Against Split LearningabstractSplit Learning (SL) is a distributed learning framework that has gained popularity for its privacy-preserving nature and low computational demands. However, recent studies have the potential that a server adversary to carry out inference attacks, compromising the privacy of victim clients. Nevertheless, upon re-evaluating prior studies, we found that existing methods rely on overly strong assumptions to enhance their performance, resulting in a significant decline in effectiveness under more realistic scenarios. In this work, we provide new insights into the inherent vulnerabilities of SL. Specifically, we discover that both the smashed data and the server model contain the client's representation preference, which the server adversary can exploit to build a substitute client that approximates the target client's unique feature extraction behavior. With a well-trained substitute client, the server can perfectly steal the target client's functionality, training data, and labels. Building on this observation, we introduce Split Leakage (SLeak), a new threat that targets multiple privacy stealing objectives against SL. Notably, SLeak does not depend on strong privacy priors and only requires partial same-domain auxiliary public data to conduct the attacks. Experimental results on diverse datasets and target models show that SLeak surpasses the state-of-the-art method across multiple metrics. Moreover, ablation studies further confirm its robustness and applicability under various scenarios and assumptions. Xiaoyang Xu 0001, Wenzhe Yi, Juan Wang 0006, Hongxin Hu, Mengda Yang, Yong Zhuang, Mang Ye |
IEEE Trans. Pattern Anal. Mach. Intell. | 2 |
| 2026 | Palladium: Guarding Neural Network Training With Confidential ComputingabstractIn the era of deep learning, protecting the training data and model parameters of high-performance Deep Neural Networks (DNNs) is critical. Data holders often want to use private data to train dedicated DNNs while leveraging AI accelerators hosted on remote servers, such as GPUs or TPUs. However, cloud systems are vulnerable to adversaries who may compromise both computational integrity and user data privacy. Performing verifiable and private training without losing access to untrusted accelerators remains a significant challenge. While previous works rely on Trusted Execution Environments (TEEs) to safeguard privacy during inference, they primarily address forward propagation and are not suitable for backward propagation in training. To address this limitation, this paper proposesPalladium, the first system to achieve confidentiality, integrity, and low latency for both model parameters and training data.Palladiumleverages TEE-empowered confidential computing to protect privacy and verify integrity, while securely outsourcing most linear layer computations to untrusted GPUs to optimize performance. Specifically,Palladiumpreserves the confidentiality of outsourced parameters by transforming the weights of linear operators and generating input masks through a carefully designedCloakstrategy. It then fully recovers the execution results inside the TEE using the correspondingUnCloakstrategy. To further ensure computational integrity,Palladiumincorporates a stochastic operator verification mechanism that detects breaches outside the TEE with 99% confidence. We implement a prototype ofPalladiumbased on Libtorch and Occlum and conduct a comprehensive evaluation on four network architectures and four datasets. Evaluation results show thatPalladiumprovides strong security guarantees with reasonable performance overhead, preserves high training accuracy, and protects model privacy. Wenzhe Yi, Mengda Yang, Juan Wang 0006, Hongxin Hu, Xiaoyang Xu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Learning to Defend: Auto-Augmentation Search Against Model Inversion AttacksabstractModel Inversion Attacks (MIAs) can recover private training data by accessing model weights or outputs, posing significant threats to user privacy. Existing defenses cannot provide comprehensive protection against attackers with varying levels of knowledge and often lack evaluation against the most advanced attacks. Moreover, current defenses primarily focus on regularizing latent representations or labels. While prior work has explored input-level defenses (e.g., Random Erasing), these approaches are typically limited to simple transformations, and more complex or systematically combined input-level defenses remain underexplored. As the most common input-level perturbation technique, data augmentation applies transformations like cropping directly to input images. However, finding augmentations or their combinations that achieve a good privacy-utility trade-off is challenging, as it is impossible to evaluate every augmentation exhaustively through attacks. To address this, we design privacy and utility assessments for efficient evaluation and propose a Defense via Auto-Augmentation Search (DAAS). DAAS can automatically assess and identify candidates with strong privacy-utility trade-offs from a large augmentation pool. The final search results can then be leveraged for privacy-preserving training against MIAs. We evaluate DAAS across various models, datasets, and attacks, demonstrating superior defense performance compared to existing methods. Extensive ablation studies further demonstrate the effectiveness of DAAS. Wenzhe Yi, Xiaoyang Xu 0001, Yong Zhuang, Juan Wang 0006, Hongxin Hu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | From Head to Tail: Efficient Black-box Model Inversion Attack via Long-tailed LearningabstractModel Inversion Attacks (MIAs) aim to reconstruct private training data from models, leading to privacy leakage, particularly in facial recognition systems. Although many studies have enhanced the effectiveness of white-box MIAs, less attention has been paid to improving efficiency and utility under limited attacker capabilities. Existing black-box MIAs necessitate an impractical number of queries, incurring significant overhead. Therefore, we analyze the limitations of existing MIAs and introduce Surrogate Model-based Inversion with Long-tailed Enhancement (SMILE), a high-resolution oriented and query-efficient MIA for the black-box setting. We begin by analyzing the initialization of MIAs from a data distribution perspective and propose a long-tailed surrogate training method to obtain high-quality initial points. We then enhance the attack’s effectiveness by employing the gradient-free black-box optimization algorithm selected by NGOpt. Our experiments show that SMILE outperforms existing state-of-the-art black-box MIAs while requiring only about 5% of the query overhead. Our code is available at https://github.com/L1ziang/SMILE. Juan Wang 0006, Meihui Chen, Hongxin Hu, Wenzhe Yi, Xiaoyang Xu 0001, Mengda Yang, Chenjun Ma |
CVPR | 6 |
| 2025 | HVGuard: Utilizing Multimodal Large Language Models for Hateful Video DetectionabstractThe rapid growth of video platforms has transformed information dissemination and led to an explosion of multimedia content. However, this widespread reach also introduces risks, as some users exploit these platforms to spread hate speech, which is often concealed through complex rhetoric, making hateful video detection a critical challenge. Existing detection methods rely heavily on unimodal analysis or simple feature fusion, struggling to capture cross-modal interactions and reason through implicit hate in sarcasm and metaphor. To address these limitations, we propose HVGuard, the first reasoning-based hateful video detection framework with multimodal large language models (MLLMs). Our approach integrates Chain-of-Thought (CoT) reasoning to enhance multimodal interaction modeling and implicit hate interpretation. Additionally, we design a Mixture-of-Experts (MoE) network for efficient multimodal fusion and final decision-making. The framework is modular and extensible, allowing flexible integration of different MLLMs and encoders. Experimental results demonstrate that HVGuard outperforms all existing advanced detection tools, achieving an improvement of 6.88% to 13.13% in accuracy and 9.21% to 34.37% in M-F1 on two public datasets covering both English and Chinese. Yiheng Jing, Mingming Zhang 0009, Yong Zhuang, Jiacheng Guo, Juan Wang 0006, Xiaoyang Xu 0001, Wenzhe Yi, Keyan Guo, Hongxin Hu |
EMNLP | 7 |
| 2025 | BiFD: A Bidirectional Feature Discrepancy Defense against Hijacking Attack in Split LearningabstractSplit Learning (SL) is a widely adopted distributed privacy-preserving training paradigm with minimal computational overhead for clients. However, Feature-Space Hijacking Attack (FSHA) poses a significant threat against SL, where the server manipulates the client's optimization process, compromising input privacy. Some studies propose that clients can detect potential hijacking by monitoring the gradients returned by the server. However, these gradient-based methods are vulnerable to adversarial anti-detection and lack robustness to changes in model architecture. In this paper, we propose a novel detection method named Bidirectional Feature Discrepancy Defense (BiFD), which leverages features to capture richer semantic information. We also observe that hijacked features are easier to reconstruct and harder to classify, providing a key distinction between malicious and honest servers—an aspect overlooked in previous works. Extensive results across multiple datasets and model architectures demonstrate the excellent and robust performance of BiFD. Xiaoyang Xu 0001, Wenzhe Yi, Juan Wang 0006, Yong Zhuang, Mengda Yang |
ICME | 2 |
| 2025 | I know what you MEME! Understanding and Detecting Harmful Memes with Multimodal Large Language Models
Yong Zhuang, Keyan Guo, Juan Wang 0006, Yiheng Jing, Xiaoyang Xu 0001, Wenzhe Yi, Mengda Yang, Bo Zhao 0023, Hongxin Hu |
NDSS | 6 |
| 2025 | Stealing Data from Active Party in Vertical Split Learning
Xiaoyang Xu 0001, Wenzhe Yi, Yong Zhuang, Juan Wang 0006, Mengda Yang |
ECML/PKDD (5) | 3 |
| 2024 | A Stealthy Wrongdoer: Feature-Oriented Reconstruction Attack Against Split LearningabstractSplit Learning (SL) is a distributed learning framework renowned for its privacy-preserving features and minimal computational requirements. Previous research consistently highlights the potential privacy breaches in SL systems by server adversaries reconstructing training data. However, these studies often rely on strong assumptions or compromise system utility to enhance attack performance. This paper introduces a new semi-honest Data Reconstruction Attack on SL, named Feature-Oriented Reconstruction Attack (FORA). In contrast to prior works, FORA relies on limited prior knowledge, specifically that the server utilizes auxiliary samples from the public without knowing any client's private information. This allows FORA to conduct the attack stealthily and achieve robust performance. The key vulnerability exploited by FORA is the revelation of the model representation preference in the smashed data output by victim client. FORA constructs a substitute client through feature-level transfer learning, aiming to closely mimic the victim client's representation preference. Leveraging this substitute client, the server trains the attack model to effectively reconstruct private data. Extensive experiments showcase FORA's superior performance compared to state-of-the-art methods. Furthermore, the paper systematically evaluates the proposed method's applicability across diverse settings and advanced defense strategies. Xiaoyang Xu 0001, Mengda Yang, Wenzhe Yi, Juan Wang 0006, Hongxin Hu, Yong Zhuang |
CVPR | 3 |
| 2024 | Penetralium: Privacy-preserving and memory-efficient neural network inference at the edge
Mengda Yang, Wenzhe Yi, Juan Wang 0006, Hongxin Hu, Xiaoyang Xu 0001 |
Future Gener. Comput. Syst. | 2 |
| 2023 | GAN You See Me? Enhanced Data Reconstruction Attacks against Split InferenceabstractSplit Inference (SI) is an emerging deep learning paradigm that addresses computational constraints on edge devices and preserves data privacy through collaborative edge-cloud approaches. However, SI is vulnerable to Data Reconstruction Attacks (DRA), which aim to reconstruct users' private prediction instances. Existing attack methods suffer from various limitations. Optimization-based DRAs do not leverage public data effectively, while Learning-based DRAs depend heavily on auxiliary data quantity and distribution similarity. Consequently, these approaches yield unsatisfactory attack results and are sensitive to defense mechanisms. To overcome these challenges, we propose a GAN-based LAtent Space Search attack (GLASS) that harnesses abundant prior knowledge from public data using advanced StyleGAN technologies. Additionally, we introduce GLASS++ to enhance reconstruction stability. Our approach represents the first GAN-based DRA against SI, and extensive evaluation across different split points and adversary setups demonstrates its state-of-the-art performance. Moreover, we thoroughly examine seven defense mechanisms, highlighting our method's capability to reveal private information even in the presence of these defenses. Mengda Yang, Juan Wang 0006, Hongxin Hu, Wenzhe Yi, Xiaoyang Xu 0001 |
NeurIPS | 6 |
| 2023 | Enhance the trust between IoT devices, mobile apps, and the cloud based on blockchain
Juan Wang 0006, Wenzhe Yi, Mengda Yang, Jiaci Ma, Shengzhi Zhang, Shirong Hao |
J. Netw. Comput. Appl. | 2 |
| 2022 | Measuring Data Reconstruction Defenses in Collaborative Inference SystemsabstractThe collaborative inference systems are designed to speed up the prediction processes in edge-cloud scenarios, where the local devices and the cloud system work together to run a complex deep-learning model. However, those edge-cloud collaborative inference systems are vulnerable to emerging reconstruction attacks, where malicious cloud service providers are able to recover the edge-side users’ private data. To defend against such attacks, several defense countermeasures have been recently introduced. Unfortunately, little is known about the robustness of those defense countermeasures. In this paper, we take the first step towards measuring the robustness of those state-of-the-art defenses with respect to reconstruction attacks. Specifically, we show that the latent privacy features are still retained in the obfuscated representations. Motivated by such an observation, we design a technology called Sensitive Feature Distillation (SFD) to restore sensitive information from the protected feature representations. Our experiments show that SFD can break through defense mechanisms in model partitioning scenarios, demonstrating the inadequacy of existing defense mechanisms as a privacy-preserving technique against reconstruction attacks. We hope our findings inspire further work in improving the robustness of defense mechanisms against reconstruction attacks for collaborative inference systems. Mengda Yang, Juan Wang 0006, Hongxin Hu, Ao Ren, Xiaoyang Xu 0001, Wenzhe Yi |
NeurIPS | 7 |