VLDB 2026 Research / reviewers in the wild / expert
Huiyu Xu
dblp:383/4999
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0003-3797-846XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PT-Mark: Invisible Watermarking for Text-to-Image Diffusion Models via Semantic-Aware Pivotal TuningabstractWatermarking for diffusion images has drawn considerable attention due to the widespread use of text-to-image diffusion models and the increasing need for their copyright protection. Recently, advanced watermarking techniques, such as Tree-Ring, integrate watermarks by embedding traceable patterns (e.g., Rings) into the latent distribution during the diffusion process. Such methods disrupt the original semantics of the generated images due to the inevitable distribution shift caused by the watermarks, thereby limiting their practicality, particularly in digital art creation. In this work, we present Semantic-aware Pivotal Tuning Watermarks (PT-Mark), a novel invisible watermarking method that preserves both the semantics of diffusion images and the traceability of the watermark. PT-Mark preserves the original semantics of the watermarked image by gradually aligning the generation trajectory with the original (pivotal) trajectory while maintaining the traceable watermarks during whole diffusion denoising process. To achieve this, we first compute the salient regions of the watermark at each diffusion denoising step as a spatial prior to identify areas that can be aligned without disrupting the watermark pattern. Guided by the region, we then introduce an additional pivotal tuning branch that optimizes the null-text embedding to align the semantics while preserving the watermarks. Extensive evaluations demonstrate that PT-Mark can preserve the original semantics of the diffusion images while integrating robust watermarks. It achieves a 10% improvement in the performance of semantic preservation compared to state-of-the-art watermarking methods, while also showing comparable robustness against real-world perturbations and four times greater efficiency. The code is available athttps://github.com/annpion/PT-Mark. Yaopeng Wang, Huiyu Xu, Zhibo Wang 0001, Jiacheng Du, Yiming Li 0004, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | RedAgent: An Autonomous Agent for Context-Aware Red Teaming of LLM JailbreaksabstractRecently, Large Language Models (LLMs) have been in tegrated into many real-world applications like Code Copilot. These applications have significantly expanded the attack surface of LLMs, ex posing them to complex real-world jailbreak threats. Despite the promising advances in actively finding jailbreak vulnerabilities of LLMs (i.e., red teaming) in general contexts, identifying these threats in complex domain-specific contexts (e.g, mathematical LLMs) remains underexplored. In this paper, we study whether the context these real-world LLM applications work in, including different system prompts, tools, and scenarios of tasks, give rise to context-specific jailbreak threats. Particularly, we adapt general jailbreak prompts to the context of the target application via LLM rewriting to generate context-specific attacks. By measuring the differences in jailbreak responses between general attacks and context-specific attacks, we reveal that customized domain specific LLMs are more vulnerable in their specific context. Motivated by this observation, we propose a context-aware red teaming approach, RedAgent, to generate context-specific jailbreak attacks towards customized LLM applications. Through effectively retrieving and updating structured knowledge in an agent system, RedAgent efficiently perceive and utilize contextual information to adapt the jailbreak prompts to the target contexts. Extensive experiments show that our system can jailbreak most black-box LLMs within just five queries, improving the efficiency of existing red teaming methods by two times. Further, RedAgent can effectively jailbreak customized LLM applications. By generating context-specific jailbreak prompts towards 60 trending applications on the marketplace of OpenAI, we discover 600 vulnerabilities of these real world applications with only two queries per vulnerability. Huiyu Xu, Zhibo Wang 0001, Zhongjie Ba, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | ProFake: Detecting Deepfakes in the Wild against Quality Degradation with Progressive Quality-adaptive LearningabstractDespite the promising advances in deepfake detection on current datasets, detecting visual deepfakes in real-world scenarios (e.g., deepfake videos and live streaming on YouTube) remains a challenge due to the inherent quality degradation such as unpredictable compression employed by social media platforms. Such degradation perturbs discernible forgery clues and diminishes the effectiveness of deepfake detection methods, raising a critical safety concern to the misuse of forgery faces in real-world scenarios. In this paper, we aim to understand the impacts of real-world degradation on the robustness of deepfake detection. Particularly, we investigate the risk of degraded deepfakes towards their detection on two real-world scenarios (i.e., deepfake videos and deepfake live streaming on social media platforms). By measuring the effects of real-world degradations on the performance and representation capabilities of detection models, we reveal that real-world deepfakes can be simulated via common degradation operations (e.g., JPEG compression) as they are perceptually similar to deepfake detectors. By analyzing the training dynamics under different sequences of training samples, we observe that the training order of deepfakes progressing from non-degraded (easy) to heavily degraded (hard) enhances the adaptability of detection models to various degradation in real-world scenarios. Drawing from these observations, we present a novel deepfake detection method ProFake to enhance the robustness of deepfake detection against real-world quality degradations. ProFake enables quality-adaptive learning via progressively degrade, detect and assign weights for the training samples driven by the feedback of model performance and image quality, which ensures that our model gradually focuses on more challenging samples to achieve quality-adaptive deepfake detection. Extensive experiments show that compared with existing methods, ProFake improves deepfake detection accuracy by an average of over 10 % in real-world scenarios and by an average of over 30 % in heavily degraded scenarios, while maintaining comparable performance in detecting high-quality deepfakes. Huiyu Xu, Yaopeng Wang, Zhibo Wang 0001, Zhongjie Ba, Haiqin Weng, Tao Wei 0002, Kui Ren 0001 |
CCS | 1 |
| 2024 | PrivacyAsst: Safeguarding User Privacy in Tool-Using Large Language Model AgentsabstractSwift advancements in large language model (LLM) technologies lead to widespread research and applications, particularly in integrating LLMs with auxiliary tools, known as tool-using LLM agents. However, amid user interactions, the transmission of private information to both LLMs and tools poses considerable privacy risks to users. In this paper, we delve into current privacy-preserving solutions for LLMs and outline three pivotal challenges for tool-using LLM agents: generalization to both open-source and closed-source LLMs and tools, compliance with privacy requirements, and applicability to unrestricted tasks. To tackle these challenges, we present PrivacyAsst, the first privacy-preserving framework tailored for tool-using LLM agents, encompassing two solutions for different application scenarios. First, we incorporate a homomorphic encryption scheme to ensure computational security guarantees for users as a safeguard against both open-source and closed-source LLMs and tools. Moreover, we propose a shuffling-based solution to broaden the framework's applicability to unrestricted tasks. This solution employs an attribute-based forgery generative model and an attribute shuffling mechanism to craft privacy-preserving requests, effectively concealing individual inputs. Additionally, we introduce an innovative privacy concept,$t$-closeness in image data, for privacy compliance within this solution. Finally, we implement PrivacyAsst, accompanied by two case studies, demonstrating its effectiveness in advancing privacy-preserving artificial intelligence. Xinyu Zhang 0016, Huiyu Xu, Zhongjie Ba, Zhibo Wang 0001, Yuan Hong 0001, Jian Liu 0012, Zhan Qin, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |