VLDB 2026 Research / reviewers in the wild / expert
Dylan Zapzalka
dblp:396/8624
· DBLP profile ↗
2ranked-venue papers
2as first author
2since 2021 · last 2025
—ORCID · unresolved
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
1 paper |
Trustworthy machine learning · 100% | |
| Network and information security
1 paper |
Security and privacy of machine learning · 62% Malware analysis · 38% | |
| Interdisciplinary, comprehensive, and emerging computing
1 paper |
Computational social science and digital humanities · 100% |
Topics — the 8 heaviest of 9, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Trustworthy machine learning › fairness
causal fairness |
0.9 | 1 | 2025 | Disentangling misreporting from genuine adaptation in strategic settings: a causal approach · NeurIPS 2025 |
Machine learning › Trustworthy machine learning
fairness |
0.9 | 1 | 2025 | Disentangling misreporting from genuine adaptation in strategic settings: a causal approach · NeurIPS 2025 |
Machine learning › Trustworthy machine learning
strategic behavior |
0.9 | 1 | 2025 | Disentangling misreporting from genuine adaptation in strategic settings: a causal approach · NeurIPS 2025 |
Machine learning › Trustworthy machine learning › performative prediction
strategic classification |
0.9 | 1 | 2025 | Disentangling misreporting from genuine adaptation in strategic settings: a causal approach · NeurIPS 2025 |
Computational social science and digital humanities
algorithmic decision-making |
0.9 | 1 | 2025 | Disentangling misreporting from genuine adaptation in strategic settings: a causal approach · NeurIPS 2025 |
Security and privacy of machine learning
adversarial example |
0.9 | 1 | 2025 | Semantics-Preserving Node Injection Attacks Against GNN-Based ACFG Malware Classifiers · IEEE Trans. Dependable Secur. Comput. 2025 |
Malware analysis › graph-based malware analysis
control flow graph analysis |
0.3 | 1 | 2025 | Semantics-Preserving Node Injection Attacks Against GNN-Based ACFG Malware Classifiers · IEEE Trans. Dependable Secur. Comput. 2025 |
Malware analysis
malware detection |
0.3 | 1 | 2025 | Semantics-Preserving Node Injection Attacks Against GNN-Based ACFG Malware Classifiers · IEEE Trans. Dependable Secur. Comput. 2025 |
Methods — techniques the papers use, named apart from their topics
identifiability analysis · 1.7causal inference · 1.7node injection · 0.9attributed control flow graph · 0.9
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Disentangling misreporting from genuine adaptation in strategic settings: a causal approachabstractIn settings where ML models are used to inform the allocation of resources, agents affected by the allocation decisions might have an incentive to strategically change their features to secure better outcomes. While prior work has studied strategic responses broadly, disentangling misreporting from genuine adaptation remains a fundamental challenge. In this paper, we propose a causally-motivated approach to identify and quantify how much an agent misreports on average by distinguishing deceptive changes in their features from genuine adaptation. Our key insight is that, unlike genuine adaptation, misreported features do not causally affect downstream variables (i.e., causal descendants). We exploit this asymmetry by comparing the causal effect of misreported features on their causal descendants as derived from manipulated datasets against those from unmanipulated datasets. We formally prove identifiability of the misreporting rate and characterize the variance of our estimator. We empirically validate our theoretical results using a semi-synthetic and real Medicare dataset with misreported data, demonstrating that our approach can be employed to identify misreporting in real-world scenarios. Dylan Zapzalka, Trenton Chang, Lindsay A. Warrenburg, Sae-Hwan Park, Daniel K. Shenfeld, Ravi B. Parikh, Jenna Wiens, Maggie Makar |
NeurIPS | 1 |
| 2025 | Semantics-Preserving Node Injection Attacks Against GNN-Based ACFG Malware ClassifiersabstractTo increase security for devices connected to the internet, research has gone into using Graph Neural Networks (GNNs) to inhibit the spread of malware through detection. GNN classifiers that use Attributed Control Flow Graphs (ACFGs) have demonstrated favorable results in classifying software binaries as malicious or benign. In this work, we show that such classifiers are vulnerable to Adversarial Examples (AEs) by proposing several grey-box adversarial attacks that perform node injection and preserve the semantics of a program. We demonstrate that adversaries can take advantage of the aggregation properties of GNNs to apply effective perturbation outside of the original ACFG nodes of a software binary through node injection. We conducted experiments on our methods and compared them against two similar semantics-preserving adversarial attacks. Our results have shown that our methods of applying perturbation through node injection can result in higher evasion rates while decreasing the amount of perturbation needed to fool detectors. Namely, we deliver an evasion rate of up to 94.83% with only 2.49% of total perturbation, in comparison with a maximum evasion of 79.50% at 2.78% perturbation by a state-of-the-art approach and only 27.44% at 2.95% perturbation by the baseline attack. Our results highlight the need for creating more robust GNN malware detectors. Dylan Zapzalka, Saeed Salem, David Mohaisen |
IEEE Trans. Dependable Secur. Comput. | 1 |