VLDB 2026 Research / reviewers in the wild / expert
Kaiying Han
dblp:358/9258
· DBLP profile ↗
6ranked-venue papers
0as first author
6since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Purified Distillation Slimming (PDS) for Robust Backdoor DefenseabstractBackdoor attacks pose significant risks to applications based on deep neural networks (DNNs). Current defenses fail to achieve good performance with lightweight (compact) models, limited defense data, and low poisoning rates. To address these challenges, we propose Purified Distillation Slimming (PDS), a novel knowledge distillation approach equipped with iterative pruning. Specifically, we initialize the student model from the backdoored teacher model and iteratively prune the student's neurons until the trigger pattern is deactivated. Such an approach leverages the efficacy of knowledge distillation to transfer purified knowledge from a potentially compromised teacher model to a student model, thereby filtering out backdoor triggers embedded within the training data. Concurrently, we employ network slimming to prune backdoored neurons, enhancing the model's resilience to backdoor attacks by reducing the neurons that adversaries can exploit. Through comprehensive experiments against 17 SOTA backdoor attacks, we demonstrate that our proposed method not only effectively mitigates the impact of backdoor attacks but also preserves, and in some cases even enhances, the model's performance on benign tasks. The effectiveness of PDS has been verified on multiple datasets (Cifar-10, GTSRB, and ImageNet) across several network architectures (ResNet, VGG, MobileNet, EfficientNet, and GoogLeNet). Liqun Shan, Kaiying Han, Yazhou Tu, Insup Lee 0001, Xiali Hei 0001 |
AsiaCCS | 2 |
| 2026 | An Attention-Gated Graph Spiking Neural Membrane System for Structure-Activity Relationship PredictionabstractSpiking Neural P (SNP) systems have attracted increasing attention due to their biologically inspired, event-driven computation and inherent capability for temporal modeling. However, most existing SNP variants rely on fixed or purely local information propagation mechanisms, which limits their ability to capture long-range dependencies and contextual interactions in complex structured data. To address this limitation, we propose an Attention-Gated Spiking Neural membrane system (AGSNP), which incorporates an attention-guided gating mechanism directly into the spiking neuron dynamics. Unlike prior SNP models that treat attention as an external aggregation operation, AGSNP embeds attention signals into the nonlinear spiking update and memory regulation process. This design enables adaptive information propagation across distant structural components while preserving biologically inspired spiking behavior. To evaluate the effectiveness of the proposed architecture, AGSNP is instantiated within a graph-based learning framework and applied to Structure Activity Relationship (SAR) prediction. Experiments on three publicly available benchmark datasets demonstrate that AGSNP consistently outperforms representative baseline methods. Notably, under limited data availability and severe class imbalance, the proposed model achieves improvements of approximately 2.0-5.7% in AUC and related metrics on the Tox21 dataset, and 3.5-17.0% on the MUV dataset. Hong Peng 0001, Kaiying Han, Xiali Hei 0001 |
Int. J. Neural Syst. | 5 |
| 2025 | AdvOSD: Adversarial One-Step Diffusion for Generalizable and Efficient Fake Image DetectionabstractDetecting synthetic images generated by more ad-vanced generative models, such as Generative Adversarial Net-works (GANs) and Diffusion Models (DMs), is still a significant challenge. The images generated by these models are very vi-sually realistic and tend to evade current detection techniques, especially those struggling with generalization and efficiency. The present study suggests AdvOSD (Adversarial One-Step Diffusion), a generalizable and efficient approach to detecting fake images. AdvOSD operates by examining the comparative robustness of real and synthetic images to an adversarial-driven, specially crafted one-step diffusion transformation. The method begins by generating an oracle prompt for an input image through a BLIP model. The prompt is further manipu-lated through targeted noun substitution with NLP techniques to craft an effective adversarial prompt for interfering with the image's reconstruction process. AdvOSD's strength lies in its one-step transformation module: the input image's latent representation and adversarial prompt embedding are fed into a LoRA-adapted UNet, which, along with a diffusion model scheduler, performs one efficient transformation step to produce a reconstructed image. Authenticity is then assessed by calculating the similarity between original and transformed images. Experimental results on several benchmark datasets demonstrate that AdvOSD achieves competitive detection ac-curacy, particularly for editted images. For efficiency, the inversion-based baseline ZeroFake reports 30.2 s/image on a DGX A100, whereas AdvOSD runs ~ 1.5 s/image on a con-sumer RTX 3060- 20 x faster despite far weaker hardware (A100: 640 GB HBM2e; 3060: 12 GB GDDR6), making it a practical solution for real-world applications. Liqun Shan, Kaiying Han, Yazhou Tu, Xiali Hei 0001 |
ACSAC | 2 |
| 2025 | LiveVV: Human-Centered Live Volumetric Video Streaming SystemabstractVolumetric video (VV) has emerged as a prominent medium within the realm of extended reality (XR) with advancements in computer graphics and depth capture hardware. Users can fully immersive themselves in VV with the ability to switch their viewport in six degree of freedom (DOF), including three rotational dimensions (yaw, pitch, and roll) and three translational dimensions (X, Y, and Z). Different from traditional 2-D videos that are composed of pixel matrices, VVs employ point clouds, meshes, or voxels to represent a volumetric scene, resulting in significantly larger data sizes. While previous works have successfully achieved VV streaming in video-on-demand scenarios, the live streaming of VV remains an unresolved challenge due to the limited network bandwidth and stringent latency constraints. In this article, we proposeLiveVV, a holistic live VV streaming system that integrates multiview capture, scene segmentation and reuse, adaptive transmission, and real-time rendering.LiveVVfeatures lightweight VV capture modules for easy deployment, processes static and dynamic content separately to reduce bandwidth consumption, and incorporates a VV adaptive bitrate streaming algorithm (VABR) to ensure fluent playback with high-quality experience. Real-world implementation and evaluation demonstrate thatLiveVVachieves live VV streaming at 24 FPS frame rate with less than 350-ms latency on average, meeting the requirements of real-life application. Kaiyuan Hu, Yongting Chen, Kaiying Han, Yili Jin 0001, Junhua Liu 0003, Fangxin Wang 0001 |
IEEE Internet Things J. | 3 |
| 2024 | Can't Say Cant? Measuring and Reasoning of Dark Jargons in Large Language Models
Ziyin Zhou, Zhangchi Zhao, Qianqian Qiao, Kaiying Han, Md. Imran Hossen, Xiali Hei 0001 |
SecureComm (4) | 6 |
| 2024 | Paa-Tee: A Practical Adversarial Attack on Thermal Infrared Detectors with Temperature and Pose AdaptabilityabstractThermal infrared object detectors play an important role in security-related tasks, necessitating feasible adversarial attacks to evaluate their robustness. In many cases, implementing attacks in the physical space by a patch demands intricate and specialized perturbations. However, state-of-the-art adversarial attacks are often impractical, as they require fixed perturbation location and are susceptible to environmental temperature, leading to attack effects overfitting to specific poses and environments. To address this, we propose a practical adversarial attack method named Paa-Tee, with two input transformation strategies. For poses, we continuously alter the patch’s position to mitigate the impact of different poses on the patch’s location. For temperature, leveraging the principles of thermal imaging, we apply various transformations to a single input image to simulate different attack environments. Meanwhile, we utilize hot and cold pastes as low-resolution patches to implement attacks in the physical world. Extensive experiments validate the efficacy of our approach in both the digital and physical worlds. In the digital world, our attacks reduce the average precision of mainstream detectors by 65.44%. In the physical world, we achieve an average attack success rate of 63.77% under various distances, poses, angles, and environmental conditions. Zhangchi Zhao, Liqun Shan, Ziyin Zhou, Kaiying Han, Xiali Hei 0001 |
TrustCom | 5 |