VLDB 2026 Research / reviewers in the wild / expert
Taifeng Liu
dblp:374/1187
· DBLP profile ↗
6ranked-venue papers
3as first author
6since 2021 · last 2026
0000-0003-0843-165XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Improving Sustainability of Adversarial Examples in Class-Incremental LearningabstractCurrent adversarial examples (AEs) are typically designed for static models. However, with the wide application of Class-Incremental Learning (CIL), models are no longer static and need to be updated with new data distributed and labeled differently from the old ones. As a result, existing AEs often fail after CIL updates due to significant domain drift. In this paper, we propose SAE to enhance the sustainability of AEs against CIL. The core idea of SAE is to enhance the robustness of AE semantics against domain drift by making them more similar to the target class while distinguishing them from all other classes. Achieving this is challenging, as relying solely on the initial CIL model to optimize AE semantics often leads to overfitting. To resolve the problem, we propose a Semantic Correction Module. This module encourages the AE semantics to be generalized, based on a generative model capable of producing universal semantics. Additionally, it incorporates the CIL model to correct the optimization direction of the AE semantics, guiding them closer to the target class. To further reduce fluctuations in AE semantics, we propose a Filtering-and-Augmentation Module, which first identifies non-target examples with target-class semantics in the latent space and then augments them to foster more stable semantics. Comprehensive experiments demonstrate that SAE outperforms baselines by an average of 31.28% when updated with a 9-fold increase in the number of classes. Taifeng Liu, Xinjing Liu, Liangqiu Dong, Yang Liu 0118, Yilong Yang 0004, Zhuo Ma 0001 |
AAAI | 1 |
| 2026 | AttMark: Attention Based Model Watermarking Against Stealing AttacksabstractModel watermarking is a technique that embeds identification information as watermarks to verify model ownership and protect model priority against model stealing (MS) attacks. Watermark is a type of external knowledge which typically make a model sensitive to a specific trigger pattern, causing it to misclassify patterns to a targeted class. However, current fixed form of trigger pattern makes watermarks easy to be recovered by adversaries, thus compromising their secrecy. In this paper, we propose a new approach, named AttMark, which can generate unique patterns for each input via a group of generators. The application of generators adds randomness to trigger patterns by embedding characters into samples in various ways. Therefore, it challenges the convergence of watermark recovering algorithms of adversaries. Nevertheless, random trigger patterns render them more difficult to be embedded, making it even more challenging to transfer watermarks to stolen models. Thus, we design attention-based watermarks that leverage the characteristic of attention transferring in MS attacks. By minimizing the attention deviation caused by random trigger patterns, we enable the stolen model to learn watermarks simultaneously with the primary task. AttMark is evaluated on three major MS attacks and the watermark validation rate is tested against recovering and removal attacks. The results show that our watermark cannot be recovered by adversaries and has a$30\%$stronger transferability compared to prior works. Our code will be available11https://github.com/LiuJingjinga/AttMark.git. Xinjing Liu, Zhuo Ma 0001, Yang Liu 0118, Taifeng Liu, Zhan Qin |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | PROTheft: A Projector-Based Model Extraction Attack in the Physical World
Xinjing Liu, Yilong Yang 0004, Taifeng Liu, Leo Yu Zhang, Yanjun Zhang 0002, Yang Liu 0118, Zhuo Ma 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | L-HAWK: A Controllable Physical Adversarial Patch Against a Long-Distance Target
Taifeng Liu, Yang Liu 0118, Zhuo Ma 0001, Tong Yang 0003, Xinjing Liu, Teng Li 0003, Jianfeng Ma 0001 |
NDSS | 1 |
| 2024 | Model Stealing Detection for IoT Services Based on Multidimensional FeaturesabstractModel stealing (MS) attacks pose a significant security concern for machine learning models on cloud platforms, as they can reconstruct a substitute model with limited effort to evade ownership. While detection-based methods show promise in preventing MS attacks, they often face practical challenges. Specifically, setting an appropriate threshold to distinguish malicious features from benign ones is a difficult task, often leading to a tradeoff between false alarm rates and detection accuracy. To address this challenge, we design a multidimensional feature extraction-and-distinction scheme called MED. It is achieved through a two-layer optimization: 1) the inner layer of extraction to maximize the difference of extracted multidimensional features between attack and benign samples and 2) the outer layer of distinction to maximize the accuracy of distinguishing malicious features automatically. Recognizing that different MS attacks result in varied features, we design a group of feature extraction functions in the inner layer optimization, which addresses the limitations of single-feature-based detection methods. Further, we employ three differently characterized models for distinction, enabling MED to distinguish different types of malicious features. Comprehensive experiments are conducted to evaluate the effectiveness of the proposed scheme: MED can detect all types of MS attacks with no more than 100 samples, with an average detection rate greater than 0.99. Xinjing Liu, Taifeng Liu, Jiakang Dong, Zuobin Ying, Zhuo Ma 0001 |
IEEE Internet Things J. | 2 |
| 2024 | RPAU: Fooling the Eyes of UAVs via Physical Adversarial PatchesabstractRecently, Unmanned Aerial Vehicles (UAVs) deployed with deep learning models have been widely applied both in civil and military. However, the vulnerability of the deployed model to adversarial attacks has raised security concerns. Previous studies have mainly explored adversarial attacks in the digital domain. While physical attacks have posed a more serious threat to UAVs. In this paper, we have explored a novel Robust Physical Attack against UAVs named, which directly threatens the flight safety of UAVs. Specifically, three attacks are proposed in : Hiding Attack (HA), Yaw Attack (YA), and Obstacle Attack (OA). To launch the attacks, we overcome three domain-design challenges, including continuous perturbation, digital-physical domain gap, and optimum perturbation generation. For continuous perturbation, we have introduced anested patchthat realizes attacks at any distance. Further, a series of transformations are considered to narrow the gap between the digital and physical domains. Then, we proposed a time-dependent mechanism for generating optimum perturbation. We conducted comprehensive experiments in the digital domain, simulation environment, and physical domain. The experimental results validate the robustness of the proposed framework. In the digital domain, outperforms the baseline by$54.9\%$average attack success rate (ASR). More importantly, is still effective in both the simulation environment and the physical domain, achieving an average ASR of$100\%$. Taifeng Liu, Chao Yang 0016, Xinjing Liu, Ruidong Han, Jianfeng Ma 0001 |
IEEE Trans. Intell. Transp. Syst. | 1 |