VLDB 2026 Research / reviewers in the wild / expert
Na Zhao 0009
dblp:35/3393-9
· DBLP profile ↗
10ranked-venue papers
3as first author
10since 2021 · last 2026
0009-0001-0588-1674ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 5 · 1 first-author · 5 since 2021Security and privacy · 4 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LiteUpdate: A Lightweight Framework for Updating AI-Generated Image DetectorsabstractThe rapid progress of generative AI has led to the emergence of new generative models, while existing detection methods struggle to keep pace with new model series and architectures, resulting in significant degradation in the detection performance. This highlights the urgent need for continuously updating AI-generated image detectors to adapt to new generators. To overcome low efficiency and catastrophic forgetting in detector updates, we propose LiteUpdate, a lightweight framework for updating AI-generated image detectors to unseen generative models. Unlike previous approaches that use randomly sampled training data, LiteUpdate employs a representative sample selection module that leverages image confidence and gradient-based discriminative features to precisely select boundary samples. This approach improves learning and detection accuracy on new distributions with limited generated images, significantly enhancing detector update efficiency. Additionally, LiteUpdate incorporates a model merging module that fuses weights from multiple fine-tuning trajectories, including pre-trained, representative, and random updates. This balances the adaptability to new generators and mitigates the catastrophic forgetting of previously learned knowledge. Experiments demonstrate that LiteUpdate substantially boosts detection performance in various detectors with high efficiency. Specifically, on AIDE, the average detection accuracy on Midjourney improved from 87.63% to 93.03%, a 6.16% relative increase. Meanwhile, to achieve comparable accuracy, LiteUpdate attains approximately 4× speedup over conventional random sample fine-tuning. Jiajie Lu, Zhenkan Fu, Na Zhao 0009, Long Xing, Xiangkun Wang, Kejiang Chen, Weiming Zhang 0001, Nenghai Yu |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2026 | Performance-Lossless Black-Box Model WatermarkingabstractWith the development of deep learning, high-value and high-cost models have become valuable assets, and related intellectual property protection technologies have become a hot topic. However, existing model watermarking work in black-box scenarios originates mainly from training-based backdoor methods, which probably degrade primary task performance. To address this, we propose a branch backdoor-based model watermarking protocol named BranchWM to protect the intellectual property of the model. This protocol adopts a construction based on a message authentication scheme as the branch indicator, following a comparative analysis with other secure cryptographic primitives. We prove the lossless performance of the protocol by reduction. In addition, we analyze potential threats to the protocol and present a secure and feasible watermarking instantiation for language models. We further conduct empirical evaluations of the instantiated BranchWM, demonstrating its effectiveness and security for ownership verification. Na Zhao 0009, Kejiang Chen, Weiming Zhang 0001, Nenghai Yu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Disreo: Provably Secure No-Box-Extraction Linguistic Steganography Based on Distribution ReorganizationabstractExisting provably secure linguistic steganographic methods typically rely on white-box extraction, which necessitates access to large language models. This requirement is impractical in environments with limited resources. To tackle this issue, we proposeDisreo, a provably secure linguistic steganography based ondistributionreorganization, which extracts the messages without accessing the underlying language model. This is achieved through token position randomization and output probability reorganization for message embedding. Moreover, secret message extraction requires only the synchronization of token positions used during embedding, making it both feasible and fast for devices with constrained computational capabilities. Theoretically, the security ofDisreocan be reduced to the security of the encryption algorithm we employ, and our experimental analyses confirm thatDisreomaintains distribution consistency between stego and cover texts in expectations. In practice,Disreoachieves an average extraction time of 0.015 seconds for 5 bits of secret messages from 100 tokens, with a 100% extraction accuracy. By transitioning from white-box extraction to more practical no-box extraction scenarios,Disreobroadens the scope of steganography applications. Kejiang Chen, Na Zhao 0009, Yuang Qi, Weiming Zhang 0001, Nenghai Yu |
IEEE Trans. Multim. | 3 |
| 2025 | Provably Secure Image Robust Steganography via Cross-modal Error CorrectionabstractThe rapid development of image generation models has facilitated the widespread dissemination of generated images on social networks, creating favorable conditions for provably secure image steganography. However, existing methods face issues such as low quality of generated images and lack of semantic control in the generation process. To leverage provably secure steganography with more effective and high-performance image generation models, and to ensure that stego images can accurately extract secret messages even after being uploaded to social networks and subjected to lossy processing such as JPEG compression, we propose a high-quality, provably secure, and robust image steganography method based on state-of-the-art autoregressive (AR) image generation models using Vector-Quantized (VQ) tokenizers. Additionally, we employ a cross-modal error-correction framework that generates stego text from stego images to aid in restoring lossy images, ultimately enabling the extraction of secret messages embedded within the images. Extensive experiments have demonstrated that the proposed method provides advantages in stego quality, embedding capacity, and robustness, while ensuring provable undetectability. Yuang Qi, Kejiang Chen, Na Zhao 0009, Zijin Yang, Weiming Zhang 0001 |
AAAI | 3 |
| 2025 | Merging-Resistant Watermarking for LoRA ModulesabstractThe widespread adoption of Low-Rank Adaptation (LoRA) modules in parameter-efficient fine-tuning has revolutionized the deployment of large-scale deep neural networks. However, the intellectual property protection of LoRA modules remains a critical challenge. White-box watermarking is a more effective solution than black-box watermarking in the multi-bit verification scenario of protecting and tracing intellectual property. However, existing white-box watermarking methods for LoRA lack both flexible multi-bit capacity and merging robustness, leaving LoRA modules vulnerable to unauthorized use and redistribution. In this paper, we propose a novel merging-resistant watermarking method for LoRA modules. Our method embeds watermarks into the increment matrix generated during LoRA merging and decomposes the watermark-induced modifications into LoRA's standard matrices, achieving reliable watermark extraction and preserving LoRA's efficiency. Specifically, we adopt quantization index modulation to embed watermarks in the low-frequency components of selected increment matrix weights. Extensive experiments demonstrate the effectiveness, imperceptibility, and robustness of our method, making it a practical solution for safeguarding LoRA modules in real-world applications. This work responds to the limited attention given to intellectual property protection for LoRA, contributing to the secure and sustainable development of deep learning technologies. Na Zhao 0009, Kejiang Chen, Yuang Qi, Weiming Zhang 0001, Nenghai Yu |
ACM Multimedia | 1 |
| 2025 | STEAD: Robust Provably Secure Linguistic Steganography with Diffusion Language ModelabstractRecent provably secure linguistic steganography (PSLS) methods rely on mainstream autoregressive language models (ARMs) to address historically challenging tasks, that is, to disguise covert communication as ``innocuous'' natural language communication.
However, due to the characteristic of sequential generation of ARMs, the stegotext generated by ARM-based PSLS methods will produce serious error propagation once it changes, making existing methods unavailable under an active tampering attack.
To address this, we propose a robust, provably secure linguistic steganography with diffusion language models (DLMs). Unlike ARMs, DLMs can generate text in a partially parallel manner, allowing us to find robust positions for steganographic embedding that can be combined with error-correcting codes.
Furthermore, we introduce error correction strategies, including pseudo-random error correction and neighborhood search correction, during steganographic extraction.
Theoretical proof and experimental results demonstrate that our method is secure and robust. It can resist token ambiguity in stegotext segmentation and, to some extent, withstand token-level attacks of insertion, deletion, and substitution. Yuang Qi, Na Zhao 0009, Qiyi Yao, Benlong Wu, Weiming Zhang 0001, Nenghai Yu, Kejiang Chen |
NeurIPS | 2 |
| 2025 | Provably Secure Public-Key Steganography Based on Admissible EncodingabstractThe technique of hiding secret messages within seemingly harmless covertext to evade examination by censors with rigorous security proofs is known as provably secure steganography (PSS). PSS evolves from symmetric key steganography to public-key steganography, functioning without the requirement of a pre-shared key and enabling the extension to multi-party covert communication and identity verification mechanisms. Recently, a public-key steganography method based on elliptic curves was proposed, which uses point compression to eliminate the algebraic structure of curve points. However, this method has strict requirements on the curve parameters and is only available on half of the points. To overcome these limitations, this paper proposes a more general elliptic curve public key steganography method based on admissible encoding. By applying the tensor square function to the known well-distributed encoding, we construct admissible encoding, which can create the pseudo-random public-key encryption function. The theoretical analysis and experimental results show that the proposed provable secure public-key steganography method can be deployed on all types of curves and utilize all points on the curve. Kejiang Chen, Na Zhao 0009, Weiming Zhang 0001, Nenghai Yu |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Calibration-based Steganalysis for Neural Network SteganographyabstractRecent research has shown that neural network models can be used to steal sensitive data or embed malware. Therefore, steganalysis for neural networks is urgently needed. However, existing neural network steganalysis methods do not perform well under small embedding rates. In addition, because of the large number of parameters, the neural network steganography method under a small embedding rate can embed enough information into the model for malicious purposes. To address this problem, this paper proposes a calibration-based steganalysis method, which fine-tunes the original neural network model without implicit constraints to obtain a reference model, then extracts and fuses statistical moments from the parameter distributions of the original model and its reference model, and finally trains a logistic regressor for detection. Extensive experiments show that the proposed method has superior performance in detecting steganographic neural network models under small embedding rates. Na Zhao 0009, Kejiang Chen, Chuan Qin 0003, Weiming Zhang 0001, Nenghai Yu |
IH&MMSec | 1 |
| 2023 | Discop: Provably Secure Steganography in Practice Based on "Distribution Copies"abstractSteganography is the act of disguising the transmission of secret information as seemingly innocent. Although provably secure steganography has been proposed for decades, it has not been mainstream in this field because its strict requirements (such as a perfect sampler and an explicit data distribution) are challenging to satisfy in traditional data environments. The popularity of deep generative models is gradually increasing and can provide an excellent opportunity to solve this problem. Several methods attempting to achieve provably secure steganography based on deep generative models have been proposed in recent years. However, they cannot achieve the expected security in practice due to unrealistic conditions, such as the balanced grouping of discrete elements and a perfect match between the message and channel distributions. In this paper, we propose a new provably secure steganography method in practice named Discop, which constructs several "distribution copies" during the generation process. At each time step of generation, the message determines from which "distribution copy" to sample. As long as the receiver agrees on some shared information with the sender, he can extract the message without error. To further improve the embedding rate, we recursively construct more "distribution copies" by creating Huffman trees. We prove that Discop can strictly maintain the original distribution so that the adversary cannot perform better than random guessing. Moreover, we conduct experiments on multiple generation tasks for diverse digital media, and the results show that Discop’s security and efficiency outperform those of previous methods. Jinyang Ding, Kejiang Chen, Yaofei Wang, Na Zhao 0009, Weiming Zhang 0001, Nenghai Yu |
SP | 4 |
| 2022 | Patch Steganalysis: A Sampling Based Defense Against Adversarial SteganographyabstractIn recent years, the classification accuracy of CNN (convolutional neural network) steganalyzers has rapidly improved. However, as general CNN classifiers will misclassify adversarial samples, CNN steganalyzers can hardly detect adversarial steganography, which combines adversarial samples and steganography. Adversarial training and preprocessing are two effective methods to defend against adversarial samples. But literature shows adversarial training is ineffective for adversarial steganography. Steganographic modifications will also be destroyed by preprocessing, which aims to wipe out adversarial perturbations. In this paper, we propose a novel sampling based defense method for steganalysis. Specifically, by sampling image patches, CNN steganalyzers can bypass the sparse adversarial perturbations and extract effective features. Additionally, by calculating statistical vectors and regrouping deep features, the impact on the classification accuracy of common samples is effectively compressed. The experiments show that the proposed method can significantly improve the robustness against adversarial steganography without adversarial training. Chuan Qin 0003, Na Zhao 0009, Weiming Zhang 0001, Nenghai Yu |
ICASSP | 2 |