VLDB 2026 Research / reviewers in the wild / expert
Yang Li 0103
dblp:37/4190-103
· DBLP profile ↗
9ranked-venue papers
2as first author
6since 2021 · last 2026
0000-0002-0489-2742ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SOOM: A Schedule-Search-Based Operator Obfuscation Method Against Model Extraction AttacksabstractDeep Neural Networks (DNNs) are gradually becoming indispensable in various technological domains. To cater to more deployment backends and increasingly complex model architectures, deep learning compiler-driven efficient compilation modes are becoming essential components of productivity. However, this deployment method exacerbates security risks. Recent studies have shown that attackers can reverse-engineer executable files to regenerate trainable deep learning models, leading to adversarial attacks and other security breaches. Previous research indicates that such attacks pose significant threats, yet progress in implementing cost-effective mitigation strategies remains limited. Existing defense mechanisms primarily focus on Trusted Execution Environments or partial encryption to protect critical model parameters, often at the expense of compiled execution efficiency. To address this gap, we propose a schedule search based operator obfuscation method (SOOM) to defend against model extraction attacks for models compiled and executed on standard CPU and GPU backends, where low latency on device inference is required. SOOM is built on TVM, a deep learning compiler, and constructs a comprehensive obfuscation space for deep learning operators. It leverages a security aware learned cost model based on XGBoost gradient boosted trees to balance security objectives and performance requirements, and ultimately generates obfuscated executable code for various deep learning operators. Extensive experiments covered over 105 operator configurations and more than 30,000 tensor computation test cases. Our method was tested against state-of-the-art model extraction attacks, raising the operator inference failure rate to as high as 89%. We also observe up to approximately 25.4% performance gains in selected cases, while the balanced setting keeps model-level latency overhead within a modest budget. Yang Li 0103, Changchun Yin, Liming Fang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2026 | SOFAN: Side-Channel Oriented Fingerprinting and Neutralization for TVM-Compiled DNNsabstractDeep learning compilers such as TVM lower neural networks through intermediate representations (IRs) into optimized, hardware-specific binaries. While enabling high-performance deployment via optimizations like operator fusion and loop tiling, they leave stable execution signatures exploitable by reverse engineering. Prior attacks often rely on a single modality, symbolic lifting, instruction classification, or side channels, each struggles under at least one realistic condition, such as deep fusion, schedule diversity, or OS noise. We present SOFAN, a side-channel oriented fingerprinting and neutralization framework for TVM-compiled DNNs. On the attack side, TCScaptures timing and cache traces to recover operator boundaries via smoothing, non-maximum suppression (NMS), and dynamic time warping (DTW). A multimodal fusion network (MFN) then integrates these side-channel signals with instruction embeddings to classify deeply fused operators. On the defense side, LASR (Leakage-Aware Schedule Rewriting) selectively perturbs critical leakage via schedule diversification, access equalization, and memory remapping, under a fixed runtime budget. Evaluated across CNNs and fusion schedules, SOFANimproves segmentation and recognition over prior baselines. LASR reduces Top-1 attack accuracy by up to 24 points (16 on average) under 10-20% runtime overhead and minimal memory cost. By aligning both attack and defense with compiler boundaries, SOFANenables practical, budget-aware protection for real-world deployments. Yang Li 0103, Changchun Yin, Liming Fang 0001 |
IEEE Trans. Reliab. | 2 |
| 2025 | MACO: Model Anti-Extraction via Compiler ObfuscationabstractDeep neural networks (DNNs) are widely deployed across applications, but growing model sizes and performance demands on edge devices necessitate aggressive compiler-based acceleration, as enabled by frameworks like TVM. Compiling models into standalone executables, however, introduces new security risks, reverse-engineering these binaries can reveal core architectures and enable unauthorized model cloning or tampering. Existing defenses largely rely on trusted execution or encryption, which target weight confidentiality but fail to protect architectural details or operator attributes, often with high runtime costs. To address these gaps, we propose MACO, a multi-tier obfuscation framework built atop TVM, spanning high-level graph rewriting and low-level IR transformations. MACO integrates three transformation categories: operator attribute obfuscation, memory layout perturbation, and dummy branching, covering the full compilation stack. A tiered design enables flexible trade-offs between security and performance. We evaluate MACO on eight common models and three attack types: side-channel, symbolic execution, and deep learning–based extraction. Results show up to 85.8% reduction in attribute inference success and 99% reduction in topology reconstruction, with the lightest tier incurring only 1.036× overhead over the unobfuscated baseline. Yang Li 0103, Liming Fang 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Understanding the Security Risks of Websites Using Cloud Storage for Direct User File UploadsabstractWith the rising demand for website data storage, leveraging cloud storage services for vast user file storage has become prevalent. Nowadays, a new file upload scenario has been introduced, allowing web users to upload files directly to the cloud storage service. This new scenario offers convenience but involves more roles (i.e., web users, web servers, and cloud storage services) and their interactions, bringing new security threats. In this paper, we perform the first systematic security study in this scenario. With in-depth analysis, we identify six new types of vulnerabilities and conduct large-scale real-world measurements on the top 500 Alexa Rank websites. Among these websites, 182 (36.4%) use cloud storage services, illustrating the widespread use of the cloud. Then, we perform a detailed analysis of 28 popular websites that allow user upload. Surprisingly, they all have at least one of the six vulnerabilities. Totally, we discover 79 new vulnerabilities and responsibly report them to the websites. Many popular websites respond positively, including Google, Reddit, and CSDN. We discuss the root causes of these vulnerabilities and propose possible mitigation methods. In summary, our work offers significant value in understanding the security risks of cloud storage services for websites and facilitating future research. Yuanchao Chen, Yuwei Li 0002, Yuliang Lu, Zulie Pan, Shouling Ji, Yu Chen 0053, Yang Li 0103, Yi Shen 0012 |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2024 | REDLC: Learning-driven Reverse Engineering for Deep Learning CompilersabstractDeep Learning (DL) compilers such as TVM enable the efficient deployment of diverse DL models on heterogeneous and resource-constrained devices to meet the needs for low latency, privacy protection, and enhanced reliability. However, the booming of on-device DL technology will inevitably attract new types of cybercriminals and industrial spies aiming to steal commercial models. Emerging research focused on model-stealing attacks from the perspective of DL compilers mainly uses heuristic approaches, which do not work well with compiler-optimized models. This work proposes an advanced model-stealing attack pipeline that combines code representation learning and binary analysis to efficiently reverse retrainable DL framework models from TVM-compiled executables. To further improve the accuracy of reversed models, we exploit the computational relationships to correct the prediction of operators in the models using Graph Convolutional Networks. Extensive experiments demonstrate that our approach can recover 18 common DL models with different scales downloaded from Keras repositories with 99% accuracy. Yang Li 0103, Xiaopeng Ke, Fengyuan Xu, Liming Fang 0001 |
ISSRE | 2 |
| 2021 | A Practical Model Based on Anomaly Detection for Protecting Medical IoT Control Services Against External AttacksabstractThe application of the Internet of Things (IoT) in medical field has brought unprecedented convenience to human beings. However, attackers can use device configuration vulnerabilities to hijack devices, control services, steal medical data, or make devices operate illegally. These restrictions have led to huge security risks for IoT, and have challenged the management of critical infrastructure services. Based on these problems, this article proposes an anomaly detection system for detecting illegal behavior (DIB) in medical IoT environment.The DIB system can analyze data packets transmitted by medical IoT devices, learn operation rules by itself, and remind management personnel that the device is in an abnormal operation state to ensure the safety of control service. We further propose a model that is based on rough set theory and fuzzy core vector machine (FCVM) to improve the accuracy of DIB classification anomalies. Experimental results show that the R-FCVM is effective. Liming Fang 0001, Yang Li 0103, Zhe Liu 0001, Changchun Yin, Zehong Cao |
IEEE Trans. Ind. Informatics | 2 |
| 2020 | ELPPS: An Enhanced Location Privacy Preserving Scheme in Mobile Crowd-Sensing Network Based on Edge ComputingabstractMobile Crowd-Sensing (MCS) is gradually extended to the edge network to reduce the delay of data transmission and improve the ability of data processing. However, a challenge is that there are still loopholes in the protection of privacy data, especially in location-based services. The attacker can reconstruct the location relationship network among the correlation about the environment information, identity information, and other sensing data provided by mobile users. Moreover, in the edge environment, this kind of attack is more accurate and more threatening to the location privacy information. To solve this problem, we propose a location privacy protection scheme (ELPPS) for a mobile crowd-sensing network in the edge environment, to protect the position correlation weight between sensing users through differential privacy. We use the grid anonymous algorithm to confuse the location information in order to reduce the computing cost of edge nodes. The experiment results show that the proposed framework can effectively protect the location information of the sensing users without reducing the availability of the sensing task results, and has a low delay. Yang Li 0103, Liming Fang 0001 |
TrustCom | 2 |
| 2020 | THP: A Novel Authentication Scheme to Prevent Multiple Attacks in SDN-Based IoT NetworkabstractSDN has provided significant convenience for network providers and operators in cloud computing. Such a great advantage is extending to the Internet of Things network. However, it also increases the risk if the security of an SDN network is compromised. For example, if the network operator's permission is illegally obtained by a hacker, he/she can control the entry of the SDN network. Therefore, an effective authentication scheme is needed to fit various application scenarios with high-security requirements. In this article, we design, implement, and evaluate a new authentication scheme called the hidden pattern (THP), which combines graphics password and digital challenge value to prevent multiple types of authentication attacks at the same time. We examined THP in the perspectives of both security and usability, with a total number of 694 participants in 63 days. Our evaluation shows that THP can provide better performance than the existing schemes in terms of security and usability. Liming Fang 0001, Yang Li 0103, Xinyu Yun, Zhenyu Wen, Shouling Ji, Weizhi Meng 0001, Zehong Cao, Muhammad Tanveer 0001 |
IEEE Internet Things J. | 2 |
| 2020 | A physiological and behavioral feature authentication scheme for medical cloud based on fuzzy-rough core vector machine
Liming Fang 0001, Changchun Yin, Lu Zhou 0002, Yang Li 0103, Chunhua Su, Jinyue Xia |
Inf. Sci. | 4 |