VLDB 2026 Research / reviewers in the wild / expert
Jiawei Bao
dblp:356/1366
· DBLP profile ↗
3ranked-venue papers
2as first author
3since 2021 · last 2026
0009-0008-7404-9460ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Anonymity of X-Wing and Its Variants
Jiawei Bao, Jiaxin Pan 0001 |
PKC (4) | 1 |
| 2026 | Low-visibility adversarial sample generation method based on human visual perceptionabstractAbstract With deep learning now widely applied in visual perception tasks, the question of how to enhance adversarial stealth and effectiveness while addressing the sensitivity of the human visual system has become urgent. In response to the limitations of traditional $${L_p}$$ L p norm based adversarial perturbations, which are easily noticed by the human eye in terms of brightness and color distribution, this paper introduces a low-visibility adversarial sample generation method Luminance Perception Constrained Adversarial Attack (LPCAA) that integrates brightness-aware constraints. First, it leverages the human eye’s varying sensitivity to different light wavelengths, prioritizes perturbations in the blue channel, and uses a dynamic brightness-weight function to suppress sudden changes in overall image brightness. Next, through an energy functional framework, it incorporates gradient regularization, sparsity constraints, and the $${L_2}$$ L 2 norm to guarantee smoothness and sparsity in both the spatial distribution and amplitude of the perturbations. To adaptively search for the optimal perturbation distribution across various images and models, we propose a dynamic tuning mechanism that uses finite-difference or gradient feedback to iteratively adjust perturbation strength and constraint weighting, thereby balancing attack success rates with perceptibility. Our experiments, conducted on CIFAR-10, ILSVRC2012, and other datasets, systematically evaluated multiple mainstream networks such as ResNet, VGG, MobileNet, and various defense algorithms. The findings indicate that LPCAA achieves higher attack success rates than FGSM, PGD, ColorFool, and PerC-C&W in both white-box and black-box settings, while also demonstrating notably lower perceptibility in terms of structural similarity index measure, perturbation ratio, and CIELCh color differences. Even with high-resolution images or defenses like compression and diffusion-based denoising, LPCAA leverages brightness awareness and the energy functional to maintain stable attack efficacy with minimal visual distortion. This approach not only offers a new balance between stealth and efficacy in adversarial attacks, but also poses fresh challenges for security evaluation and robust defense strategies in deep models. Binbin Tu, Haoyuan Zhou, Linfei Zhao, Jiawei Bao |
Cybersecur. | 4 |
| 2024 | Double-sided: tight proofs for guessing games in the quantum random oracle modelabstractAbstract The semi-classical One-Way to Hiding (SC-O2H) lemma given by Ambainis et al. (CRYPTO 2019) is a crucial technique to solve the reprogramming problem in the quantum random oracle model (QROM), which can lead to quadratically better bounds for many cases involving guessing games. To achieve tighter bounds, Bindel et al. (TCC, 2019) introduced the double-sided One-Way to Hiding (DS-O2H) lemma, which avoids the loss of query times suffered by the SC-O2H lemma. However, the potential of the DS-O2H lemma to provide better bounds for guessing games has not been considered by far. In this paper, a new double-sided O2H lemma is proposed. By using it, we for the first time give fully tight bounds for several cases involving guessing games. In summary, we show the following results in the QROM: (i) The hardness of inverting a random oracle with the leakage of a one-way injective function can be tightly reduced to the hardness of inverting the involved one-way injective function. (ii) Duman et al. (PKC 2023) introduced the randomness recoverability and defined two transformations $$\textsf {ACWC}_0$$ ACWC 0 and $$\textsf {ACWC}$$ ACWC relative to random oracles. For $$\textsf {ACWC}_0$$ ACWC 0 , we prove that its security can be tightly reduced to the security of the underlying public key encryption (PKE) scheme with the randomness recoverability. For $$\textsf {ACWC}$$ ACWC , we design a variant $$\textsf {ACWC}_1$$ ACWC 1 , and prove that its security can be tightly reduced to the security of the underlying PKE scheme with the unique randomness recoverability (a property slightly stronger than randomness recoverability). (iii) The security of the modular Fujisaki-Okamoto () transformation introduced by Hofheinz et al. (TCC 2017), can be tightly reduced to the security of the underlying PKE scheme with the unique randomness recoverability. Additionally, assuming the underlying PKE scheme is unique randomness recoverable, we prove the security of -like transformations "Image missing" (TCC, 2017) in the QROM, and as far as we know, our proof is tighter than the currently best proof. Jiawei Bao, Jiangxia Ge, Rui Xue 0001 |
Cybersecur. | 1 |