VLDB 2026 Research / reviewers in the wild / expert
Minhao Bai
dblp:361/3951
· DBLP profile ↗
9ranked-venue papers
2as first author
9since 2021 · last 2026
0009-0000-9069-6053ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | DICE: Discrete Inversion Enabling Controllable Editing for Masked Generative ModelsabstractRecent advances in discrete diffusion models have demonstrated strong performance in image generation and masked language modeling, yet they remain limited in their capacity for controlled content editing. We propose DICE (Discrete Inversion for Controllable Editing), a novel framework that pioneers precise inversion capabilities for discrete diffusion models, including both masked generative and multinomial diffusion variants. Our key innovation lies in capturing noise sequences and masking patterns during reverse diffusion process, enabling both accurate reconstruction and flexible editing without relying on predefined masks or attention-based manipulations. Through comprehensive experiments across image and text modalities using models such as Paella, VQ-Diffusion, RoBERTa and LLaDA, we demonstrate that DICE successfully maintains high fidelity to the original data while significantly expanding editing capabilities. These results establish new possibilities for fine-grained content manipulation in discrete spaces. Xiaoxiao He, Quan Dao, Ligong Han, Song Wen 0001, Minhao Bai, Di Liu 0003, Han Zhang 0010, Felix Juefei-Xu, Chaowei Tan, Bo Liu 0005, Martin Renqiang Min, Kang Li 0004, Faez Ahmed, Akash Srivastava, Hongdong Li, Junzhou Huang, Dimitris N. Metaxas |
WACV | 5 |
| 2026 | A Novel Framework of Semantic-Based Text SteganographyabstractText steganography helps protect citizens' freedom of speech and privacy in cyberspace by constructing innocent-looking texts to evade censorship and surveillance. Existing methods, especially generative ones, rely on delicate character-level manipulations, making them vulnerable to failure even under minor alterations. This paper introduces a novel framework that shifts from character-level to semantic space-based information hiding, which greatly improves improving robustness and reliability. The framework comprises three phases: preparation, where a stable semantic space is designed for hiding information; embedding, where a reversible codebook maps binary messages to semantemes via semantic encoding and source coding; and synthesis, where large language models act as multi-agent systems to produce stegotexts that preserve semantic consistency. Extensive experiments show that our method matches state-of-the-art techniques in hiding capacity and text quality, while significantly surpassing them in robustness-achieving at least an 81.2% higher correct message rate under three types of attacks. These findings highlight the strong potential of semantic-based text steganography. Jinshuai Yang, Minhao Bai, Kaiyi Pang, Yue Gao 0003, Yongfeng Huang 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | WinStega: An Adaptive Robust Enhancement Framework for Generative Linguistic SteganographyabstractWith the increasing prevalence of surveillance, safeguarding personal privacy has become a critical concern. To protect privacy, various linguistic steganography methods have been developed to conceal private information within seemingly innocuous text for covert communication. However, these methods are highly sensitive to alterations in the stego text, rendering the extraction of secret information impossible if any changes occur, thus limiting their practical application. In this paper, we introduce WinStega, an adaptive and robust linguistic steganography method that employs substring decoding to withstand edit attacks. WinStega embeds secret messages discontinuously using a sliding window approach, incorporating entropy-based constraints to enhance imperceptibility while preserving linguistic quality. This plug-and-play method does not require additional model training and can be implemented during the inference stage, enhancing the robustness of stego texts. Extensive evaluations using three language models demonstrate that WinStega produces high linguistic quality, imperceptible stegotexts and can partially recover secret messages even under adversarial attacks. Kaiyi Pang, Minhao Bai, Jinshuai Yang, Minghu Jiang, Yongfeng Huang 0001 |
ICASSP | 2 |
| 2025 | Provably Robust and Secure Steganography in Asymmetric Resource ScenarioabstractTo circumvent the unbridled and ever-encroaching surveillance and censorship in cyberspace, steganography has garnered attention for its ability to hide private information in innocent-looking carriers. Current provably secure steganography approaches require a pair of encoder and decoder to hide and extract private messages, both of which must run the same model with the same input to obtain identical distributions. These requirements pose significant challenges to the practical implementation of steganography, including limited access to powerful hardware and the intolerance of any changes to the shared input. To relax the limitation of hardware and solve the challenge of vulnerable shared input, a novel and practically significant scenario with asymmetric resource should be considered, where only the encoder is high-resource and accessible to powerful models while the decoder can only read the stegano-graphic carriers without any other model's input. This paper proposes a novel provably robust and secure steganography framework for the asymmetric resource setting. Specifically, the encoder uses various permutations of distribution to hide secret bits, while the decoder relies on a sampling function to extract the hidden bits by guessing the permutation used. Further, the sampling function only takes the steganographic carrier as input, which makes the decoder independent of model's input and model itself. A comprehensive assessment of applying our framework to generative models substantiates its effectiveness. Our implementation demonstrates robustness when transmitting over binary symmetric channels with errors. Minhao Bai, Jinshuai Yang, Kaiyi Pang, Zhen Yang 0015, Yongfeng Huang 0001 |
SP | 1 |
| 2025 | Shimmer: a Provably Secure Steganography Based on Entropy Collecting Mechanism
Minhao Bai, Kaiyi Pang, Guorui Liao, Jinshuai Yang, Yongfeng Huang 0001 |
USENIX Security Symposium | 1 |
| 2025 | A plug-and-play method for linguistic alignment in language models
Kaiyi Pang, Minhao Bai, Jinshuai Yang, Yue Gao 0003, Minghu Jiang, Yongfeng Huang 0001 |
Knowl. Based Syst. | 2 |
| 2025 | ModelShield: Adaptive and Robust Watermark Against Model Extraction AttackabstractLarge language models (LLMs) demonstrate general intelligence across a variety of machine learning tasks, thereby enhancing the commercial value of their intellectual property (IP). To protect this IP, model owners typically allow user access only in a black-box manner, however, adversaries can still utilize model extraction attacks to steal the model intelligence encoded in model generation. Watermarking technology offers a promising solution for defending against such attacks by embedding unique identifiers into the model-generated content. However, existing watermarking methods often compromise the quality of generated content due to heuristic alterations and lack robust mechanisms to counteract adversarial strategies, thus limiting their practicality in real-world scenarios. In this paper, we introduce an adaptive and robust watermarking method (named ModelShield) to protect the IP of LLMs. Our method incorporates a self-watermarking mechanism that allows LLMs to autonomously insert watermarks into their generated content to avoid the degradation of model content. We also propose a robust watermark detection mechanism capable of effectively identifying watermark signals under the interference of varying adversarial strategies. Besides, ModelShield is a plug-and-play method that does not require additional model training, enhancing its applicability in LLM deployments. Extensive evaluations on two real-world datasets and three LLMs demonstrate that our method surpasses existing methods in terms of defense effectiveness and robustness while significantly reducing the degradation of watermarking on the model-generated content. Kaiyi Pang, Tao Qi 0001, Chuhan Wu, Minhao Bai, Minghu Jiang, Yongfeng Huang 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | FREmax: A Simple Method Towards Truly Secure Generative Linguistic SteganographyabstractGenerative Linguistic Steganography (GLS) is applied to protect privacy against excessive censorship by employing Language Models (LMs) to hide privacy messages in texts. To effectively circumvent censorship, GLS generates steganographic texts (stegos) that closely resemble normal human texts (covers) as possible. However, due to the inherent distribution difference between LM-generated text and human covers, existing methods that simply use LMs to generate stegos face challenges in achieving sufficient imperceptibility. To narrow the gap between stegos and covers, this paper proposes a distribution reformation method named ${\mathbf{Frequency}}$ ${\mathbf{REformed}}$ ${\mathbf{Softmax}}$ $\left( {{\mathbf{FREmax}}} \right)$. ${\mathbf{FREmax}}$ generates highly imperceptible stegos aligned with human text by reforming the softmax function in the generation stage of LMs. This reformation is based on the frequency distribution of tokens in the human corpus, ensuring that the distribution of LM-generated stegos closely resembles that of humans. Extensive experimental results show that ${\mathbf{FREmax}}$ improves the linguistic quality and imperceptibility of the generated stegos, providing a valuable remedy to existing GLS methods .1 Kaiyi Pang, Minhao Bai, Jinshuai Yang, Huili Wang 0001, Minghu Jiang, Yongfeng Huang 0001 |
ICASSP | 2 |
| 2023 | CATS: Connection-Aware and Interaction-Based Text Steganalysis in Social Networks
Kaiyi Pang, Jinshuai Yang, Yue Gao 0003, Minhao Bai, Zhongliang Yang, Minghu Jiang, Yongfeng Huang 0001 |
ICONIP (5) | 4 |