Chao Shen 0001

dblp:48/4825-1 · DBLP profile ↗
← Back
177ranked-venue papers
16as first author
144since 2021 · last 2026
0000-0002-6959-0569ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 67 · 10 first-author · 56 since 2021Artificial intelligence and machine learning · 51 · 1 first-author · 44 since 2021Graphics, computer vision, multimedia, augmented reality and games · 22 · 21 since 2021Applied, interdisciplinary, general and emerging computing · 14 · 1 first-author · 12 since 2021Computer networks · 12 · 1 first-author · 11 since 2021Software engineering, systems software and programming languages · 10 · 8 since 2021Databases, data management, data science and information retrieval · 10 · 1 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 8 · 3 first-author · 3 since 2021Systems, architecture and hardware · 7 · 1 first-author · 5 since 2021
YearPublicationVenuePosition
2026 From Chaos to Clarity: A Knowledge Graph-Driven Audit Dataset Generation Framework for LLM Unlearning
abstract
Recently LLMs have faced increasing demands to selectively remove specific information through Machine Unlearning. While evaluating unlearning effectiveness is crucial, existing benchmarks suffer from fundamental limitations in audit dataset generation from unstructured corpora. We identify two critical challenges: ensuring audit adequacy and handling knowledge redundancy between forget and retain datasets. Current approaches rely on ad-hoc question generation from unstructured text, leading to unpredictable coverage gaps and evaluation blind spots. Knowledge redundancy between forget and retain corpora further obscures evaluation, making it difficult to distinguish genuine unlearning failures from legitimately retained knowledge. To bring clarity to this challenge, we propose LUCID, an automated framework that leverages knowledge graphs to achieve comprehensive audit dataset generation with fine-grained coverage and systematic redundancy elimination. By converting unstructured corpora into structured knowledge representations, it transforms the ad-hoc audit dataset generation process into a transparent and automated generation pipeline that ensures both adequacy and non-redundancy. Applying LUCID to the MUSE benchmark, we generated over 69,000 and 111,000 audit cases for News and Books datasets respectively, identifying thousands of previously undetected knowledge memorization instances. Our analysis reveals that knowledge redundancy significantly skews metrics, artificially inflating ROUGE from 19.7% to 26.1% and Entailment Scores from 32.4% to 35.2%, highlighting the necessity of deduplication for accurate assessment.
Juan Zhai, Shiqing Ma, Ziyan Lei, Xiaofei Xie, Chao Shen 0001
AAAI7
2026 Privacy on the Fly: A Predictive Adversarial Transformation Network for Mobile Sensor Data
abstract
Mobile motion sensors such as accelerometers and gyroscopes are now ubiquitously accessible by third-party apps via standard APIs. While enabling rich functionalities like activity recognition and step counting, this openness has also enabled unregulated inference of sensitive user traits, such as gender, age, and even identity, without user consent. Existing privacy-preserving techniques, such as GAN-based obfuscation or differential privacy, typically require access to the full input sequence, introducing latency that is incompatible with real-time scenarios. Worse, they tend to distort temporal and semantic patterns, degrading the utility of the data for benign tasks like activity recognition. To address these limitations, we propose the Predictive Adversarial Transformation Network (PATN), a real-time privacy-preserving framework that leverages historical signals to generate adversarial perturbations proactively. The perturbations are applied immediately upon data acquisition, enabling continuous protection without disrupting application functionality. Experiments on two datasets demonstrate that PATN substantially degrades the performance of privacy inference models, achieving Attack Success Rate (ASR) of 40.11% and 44.65% (reducing inference accuracy to near-random) and increasing the Equal Error Rate (EER) from 8.30% and 7.56% to 41.65% and 46.22%. On ASR, PATN outperforms baseline methods by 16.16% and 31.96%, respectively.
Tianle Song, Chenhao Lin, Zhengyu Zhao 0001, Le Yang 0007, Chao Shen 0001
AAAI8
2026 False Friends in the Shell: Unveiling the Emoticon Semantic Confusion in Large Language Models
abstract
Emoticons are widely used in digital communication to convey affective intent, yet their safety implications for Large Language Models (LLMs) remain largely unexplored.In this paper, we identify emoticon semantic confusion, a vulnerability where LLMs misinterpret ASCII-based emoticons to perform unintended and even destructive actions.To systematically study this phenomenon, we develop an automated data generation pipeline and construct a dataset containing 3,757 code-oriented test cases spanning 21 meta-scenarios, four programming languages, and varying contextual complexities.Our study on six LLMs reveals that emoticon semantic confusion is pervasive, with an average confusion ratio exceeding 38%.More critically, over 90% of confused responses yield 'silent failures', which are syntactically valid outputs but deviate from user intent, potentially leading to destructive security consequences.Furthermore, we observe that this vulnerability readily transfers to popular agent frameworks, while existing prompt-based mitigations remain largely ineffective.We call on the community to recognize this emerging vulnerability and develop effective mitigation methods to uphold the safety and reliability of human-LLM interactions.* These authors contributed equally.
Xiaoyu Zhang 0013, Juan Zhai, Shiqing Ma, Chao Shen 0001, Yang Liu 0003
ACL (1)5
2026 Can Reasoning Path still be Effective as Input? Bridging Post-Reasoning to Chain-of-Thought Compression
abstract
Chengzhengxu Li, Xiaoming Liu, Zhaohan Zhang, Shengchao Liu, Guoxin Ma, Yu Lan, Cong Wang, Chao Shen. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026.
Chengzhengxu Li, Xiaoming Liu 0002, Zhaohan Zhang, Shengchao Liu, Guoxin Ma, Yu Lan 0001, Cong Wang 0001, Chao Shen 0001
ACL (1)8
2026 Confidence Should Be Calibrated More Than One Turn Deep
abstract
Zhaohan Zhang, Chengzhengxu Li, Xiaoming Liu, Chao Shen, Ziquan Liu, Ioannis Patras. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026.
Zhaohan Zhang, Chengzhengxu Li, Chao Shen 0001, Ziquan Liu, Ioannis Patras
ACL (1)4
2026 Achieving Interpretable DL-based Web Attack Detection through Malicious Payload Localization
Fukun Mei, Ye Wang 0002, Zhuotao Liu, Ke Xu 0002, Chao Shen 0001, Qian Wang 0002, Qi Li 0002
NDSS6
2026 A hybrid output feedback control scheme of Markovian jump systems via partly transition rates/probabilities design
Yufeng Tian, Xiaojie Su, Sam Kwong, Chao Shen 0001
Sci. China Inf. Sci.4
2026 Directed drift: An efficient and stealthy bias injection method using semantic drift against stable diffusion model
Zhuowei Niu, Qindong Sun, Mingkai Ding, Mingyue Song, Chao Shen 0001, Xuewen Huang
Neurocomputing5
2026 RES-PDF: A random, ensemble, and simultaneous purification-detection framework for adversarial example mitigation
Rui Yang 0032, Qindong Sun, Han Cao 0004, Chao Shen 0001
Neurocomputing5
2026 A Novel Ultrasonic Phased-Array Injection Attack on Voice-Controlled Devices
abstract
Ultrasonic injection attacks have emerged as a critical security threat to voice-controlled devices in the Internet of Things (IoT).However, most existing attack methods are limited to single-device, fixed-direction point-to-point attacks. For the first time, this paper presents a novel ultrasonic voice injection attack method—Phased Array Attack (PAA)—which enables flexible control of the attack direction. PAA expands the traditional point-to-point attack paradigm to a point-to-area approach, allowing any devices within a 45° sector to be attacked without physically moving the transmitting apparatus. This method significantly enhances the flexibility, scalability, and extensibility of injection attacks. PAA offers three key advantages: (1) high stealth: once deployed, it can target multiple devices; (2) high compatibility: the signal modulation process is offloaded from the hardware platform to a PC, thus avoiding limitations imposed by FPGA-based implementations and enabling the use of more powerful modulation algorithms; (3) theoretical soundness: PAA employs constructive interference and nonlinear demodulation theory to enhance attack performance. To validate the feasibility and effectiveness of the proposed approach, we developed an FPGA-based prototype attack system and systematically evaluated its performance in various application scenarios. Experimental results show that the proposed method achieves a high attack success rate at distances of up to 5 meters. These findings further highlight the severe physical-layer security challenges faced by voice-controlled devices in IoT environments.
Dongzhu Rong, Qindong Sun, Yan Wang 0088, Chao Shen 0001
IEEE Internet Things J.4
2026 FeatureTrojan: Boosting stealthy and steady backdoor attacks with feature poisoning and fine-tuning injection
Rui Yang 0032, Qindong Sun, Han Cao 0004, Chao Shen 0001
Neural Networks5
2026 Revisiting Transferable Adversarial Images: Systemization, Evaluation, and New Insights
abstract
Transferable adversarial images raise critical security concerns for computer vision systems in real-world, black-box attack scenarios. Although many transfer attacks have been proposed, existing research lacks a systematic and comprehensive evaluation. In this paper, we systemize transfer attacks into five categories around the general machine learning pipeline and provide the first comprehensive evaluation, with 23 representative attacks against 11 representative defenses, including the recent, transfer-oriented defense and the real-world Google Cloud Vision. In particular, we identify two main problems of existing evaluations: (1) for attack transferability, lack of intra-category analyses with fair hyperparameter settings, and (2) for attack stealthiness, lack of diverse measures. Our evaluation results validate that these problems have indeed caused misleading conclusions and missing points, and addressing them leads to new, consensus-challenging insights, such as (1) an early attack, DI, even outperforms all similar follow-up ones, (2) the state-of-the-art (white-box) defense, DiffPure, is even vulnerable to (black-box) transfer attacks, and (3) even under the same $L_{p}$Lp constraint, different attacks yield dramatically different stealthiness results regarding diverse imperceptibility metrics, finer-grained measures, and a user study. We hope that our analyses will serve as guidance on properly evaluating transferable adversarial images and advance the design of attacks and defenses.
Zhengyu Zhao 0001, Hanwei Zhang 0001, Renjue Li, Ronan Sicre, Laurent Amsaleg, Michael Backes 0001, Qi Li 0002, Qian Wang 0002, Chao Shen 0001
IEEE Trans. Pattern Anal. Mach. Intell.9
2026 Adaptive Reconstruction-Based Model Predictive Control for Networked Stochastic Systems Under False Data Injection Attacks
abstract
A resilient stochastic model predictive control (MPC) method based on an adaptive input reconstruction mechanism is proposed for networked stochastic systems under false data injection (FDI) attacks. To the best of our knowledge, this is the first stochastic MPC framework designed to address FDI attacks; it not only mitigates the conservatism of existing methods but also reduces system resource consumption. Particularly, an adaptive input reconstruction mechanism is introduced to relax the assumptions on FDI attack energy in existing resilient MPC methods by reconstructing feasible control inputs. In addition, the adaptive prediction horizon and terminal constraint are co-designed to reduce the computational complexity. Furthermore, the conservatism inherent in existing resilient MPC methods due to hard constraints is alleviated by transforming fixed hard constraints into stochastic constraints. Based on these designs, sufficient conditions are derived to guarantee the proposed method's recursive feasibility and the closed-loop system stability. Finally, the effectiveness of the proposed method is validated through simulations on a DC-DC converter system.
Chao Shen 0001
IEEE Trans. Cybern.3
2026 Quantitative Frequency-Based Framework for Interpreting Adversarial Examples
abstract
Deep neural networks are known to be susceptible to imperceptible adversarial perturbations. Many studies aim to interpret adversarial examples in the frequency domain. However, existing research often relies on a limited number of datasets, models, and adversarial attacks, leading to incomplete conclusions. Moreover, a quantitative interpretation of adversarial examples remains lacking. This paper proposes a quantitative frequency-based framework to comprehensively investigate adversarial examples, where six kinds of attacks against naturally and adversarially trained models across three datasets are adopted. Initially, our framework visualizes the distributions of successful adversarial perturbations in the frequency domain to locate their target regions. Subsequently, we characterize the importance of perturbations contained in different frequency bands and define adversarially effective frequency bands (AEFBs). Furthermore, we leverage the identified AEFBs to enhance two query-based black-box adversarial attacks. Our experimental results uncover the varying characteristics of adversarial perturbations, which are analyzed from dataset-level, model-level, and attack-level perspectives. After reordering frequency bands and identifying AEFBs, we further demonstrate that adversarial attacks guided by AEFBs can achieve superior performance, verifying their effectiveness and generalization. These significant findings contribute to a deeper understanding of adversarial examples and provide valuable insights for future research.
Sicong Han, Chenhao Lin, Chao Shen 0001, Zhengyu Zhao 0001, Qian Li 0024, Qian Wang 0002
IEEE Trans. Dependable Secur. Comput.3
2026 ADMM-Based Adversarial False Data Injection Attacks Against Multi-Label Locational Detection
abstract
While multi-label learning has shown excellent performance in False Data Injection Attack (FDIA) locational detection, it has also exposed some potential security risks and vulnerabilities. However, unlike the image domain, the vulnerabilities of multi-label learning in the field of power grid have just received attention and urgently need to be explored and addressed. In this paper, to achieve a better understanding for the security risks of deep learning-based multi-label FDIA detectors, we propose two Alternating Direction Method of Multipliers (ADMM) based adversarial attacks, which are applicable to two different scenarios. The proposed two ADMM-based attacks aim to reduce additional attack costs while seeking suitable adversarial perturbations, making the attacks more realistic and feasible. The experimental results verify the effectiveness of the proposed ADMM-based attacks, making noteworthy strides in fostering a profound comprehension of the vulnerabilities in the unique field of deep multi-label learning for power systems.
Jiwei Tian, Chao Shen 0001, Chenhao Lin, Meng Zhang 0011, Xiaofang Xia, Chao Ren 0006, Peican Zhu, Chunming Wu 0001, Xiang Chen 0017
IEEE Trans. Dependable Secur. Comput.2
2026 CLIP-ADA: CLIP-Guided Artifact-Invariant Generalizable Synthetic Image Detection
abstract
The rapid advancement of generative models necessitates detection methods that generalize to synthetic images containing diverse generator and semantic artifacts. Recent research has leveraged pre-trained vision-language models, such as CLIP, to extract forensic features that distinguish real and fake images, illustrating their promising performance in synthetic image detection. However, a systematic investigation into the embedding space of CLIP to guide its principled utilization for synthetic image detection remains largely unexplored. This paper addresses this gap by first analyzing the multi-stage CLIP image embedding space to uncover its relationship with cross-artifact forensic patterns. Our findings reveal that the mid-level stages primarily encode forensic and generator artifact features, while the high-level stages primarily encode semantic artifact features. Building upon these insights, we propose the CLIP-guided Dual-level Augmentation and Forensic Distribution Adaptation (CLIP-ADA) framework to perform artifact-invariant generalizable detection. Specifically, dual-level augmentation diversifies fake embeddings and suppresses artifact encoding during training to mitigate detectors from excessively relying on artifact features. Moreover, forensic distribution adaptation reformulates synthetic image detection as identifying distributional deviations from the CLIP encoded real embeddings and thereby designing adapters to extract cross-artifact forensic features in a detection scenario-adaptive manner. Extensive evaluations on both the conventional single-generator and continual learning-based multi-generator training settings demonstrate the effectiveness of our method, both suppressing the state-of-the-art methods by over 6% of average accuracy on unseen data from more than 10 generators.
Jingyi Deng, Chenken Xu, Chenhao Lin, Zhengyu Zhao 0001, Shuai Liu 0016, Qian Wang 0002, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.8
2026 Cross-Region Feature Reformer With Semantic Preservation for Adversarial Malware Detection
Qian Li 0024, Di Wu 0062, Chenhao Lin, Shuai Liu 0016, Cong Wang 0001, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.6
2026 Vul-CTG: A Multimodal Framework for Software Vulnerability Detection via Code Text and Graph Integration
abstract
Pretrained Language Models (PLMs) and Graph Neural Networks (GNNs) have emerged as promising approaches for software vulnerability detection. However, existing methods still face limitations, including the absence of fine-grained cross-modal interaction and the impact of data noise. Approaches integrating PLMs and GNNs fail to fully leverage their complementary strengths, while unreliable labels hinder generalization, further degrading real-world detection performance. To over-come these limitations, we propose Vul-CTG, a multimodal integration framework for software vulnerability detection that combines Code Text, and program Graph representations. Vul-CTG constructs enriched code graph representations by integrating statement-level source code graphs and abstract code property graphs, enabling more effective alignment between structural and semantic information. To enhance robustness against noisy labels and improve cross-modal consistency, the model incorporates contrastive learning and pre-training techniques. Central to Vul-CTG is CTG-Former, a novel alignment architecture that projects both code text and graph modalities into a unified latent space, allowing the model to capture complex structural and semantic patterns for more accurate vulnerability detection. Experimental results on recent function-level datasets demonstrate the effectiveness of Vul-CTG, showing an approximate 3% improvement in F1-score over state-of-the-art methods. Our code is available at https://github.com/ryxFry/Vul-CTG.
Shuai Liu 0016, Qian Li 0024, Xinlei He 0001, Xiaoyu Zhang 0013, Chenhao Lin, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.8
2026 On Success and Simplicity: A Second Look at Transferable Vision-Language Attack Pipeline
abstract
Vision-Language Pre-training Models (VLPMs) are known to be vulnerable to adversarial attacks. Recent transferable attacks on VLPMs have followed a common pipeline with complicated loss functions or multi-stage text/image attacks. However, in this paper, we demonstrate that such a sophisticated attack pipeline can be simpler yet more successful. Specifically, we identify three previously overlooked issues caused by inappropriate cross-modal interactions and excessive operations. To address them, we propose the Simple Vision-Language Attack (SimVLA) pipeline, which observably improves transferability and efficiency. Experiments on four datasets and three downstream tasks validate the superiority of our pipeline. For instance, on Flickr30k text-image retrieval dataset, our SimVLA outperforms the SOTA baseline in R@1 transferability by 8.01\%-14.71\%, while consuming only about 35.73\% of the time and 46.26\% of the max VRAM. Overall, the superiority of our SimVLA highlights the importance of leveraging domain knowledge (e.g., our proposed cross-modal word identification), while blindly pursuing intricate operations (e.g, complex loss functions and redundant multi-stage designs) may even be harmful. We hope our SimVLA can serve as a simple yet effective backbone for future extensions. Code is available at https://github.com/RYC-98/SimVLA.
Yuchen Ren 0002, Zhengyu Zhao 0001, Chenhao Lin, Bo Yang 0049, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.5
2026 Adversarial Video Promotion Against Text-to-Video Retrieval
Qiwei Tian, Chenhao Lin, Zhengyu Zhao 0001, Shuai Liu 0016, Qian Li 0024, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.6
2026 Semisupervised Cross-Domain Capacity Prediction for Batteries via Granular Modeling and Confidence Aware Pseudolabeling
abstract
In practical applications, the degradation behavior of lithium-ion batteries exhibits significant differences due to variations in operating conditions. Meanwhile, the scarcity of labeled data poses considerable challenges for capacity prediction in terms of both accuracy and generalization. To address these issues, this article proposes a cross-domain semisupervised capacity prediction framework that integrates multigranularity feature modeling with a confidence controlled pseudolabel selection mechanism. Specifically, the proposed method enhances the model’s ability to capture the granularity of nonlinear degradation trends in battery capacity, thereby improving prediction accuracy and stability. In addition, a pseudolabel learning strategy based on confidence filtering and stagewise regulation is designed to dynamically guide high-quality pseudolabels in the target domain into training, effectively reducing the risk of noisy label propagation. Experiments conducted on eight tasks across two heterogeneous battery datasets demonstrate R$^{2}$improvements of 1.3%–8.7% and Mean Absolute Error (MAE) reductions of 38%–80%, validating the practical potential of the proposed method under complex degradation scenarios.
Sizhe Liu, Dezhi Xu, Chao Shen 0001, Yujian Ye, Chengxi Zhang, Yan Wang 0049
IEEE Trans. Ind. Informatics3
2026 Joint Privacy-Preserving Cloud Workload Prediction Based on Federated Learning
abstract
Organizations around the world are increasingly using multiple clouds for critical workloads, which makes the accurate prediction of cloud workload a collaborative task across multiple cloud providers. Our experimental studies on four large-scale cloud workload datasets demonstrate that the workloads are highly heterogeneous, and different cloud providers have highly heterogeneous model preferences, which makes the above task challenging. Accordingly, we propose a joint privacy-preserving cloud workload prediction framework based on Federated Learning (FL), which enables the collaborative training of a workload prediction model across cloud providers with heterogeneous workloads and model preferences without exposing private workload data. To handle workload heterogeneity without privacy leakage, we first design a Generative Adversarial Network (GAN) based virtual workload dataset generation method that incorporates workloads’ temporal and resource-usage-plan-related features via temporal-aware feature calibration. Then, to handle model heterogeneity, we design a FL approach based on a hybrid local model composed of a homogeneous public model and a heterogeneous personal model. Finally, we design a Knowledge Distillation (KD) based approach to post-train the personal model with both private workload knowledge and shared workload knowledge learned from the trained global public model. Extensive experiments on various real-world workloads and actual implementations demonstrate that compared with the state-of-the-art, our framework improves workload prediction accuracy by 57.7% in average over all cloud providers.
Li Yan 0004, Zhuozhao Li, Mingjun Kao, Huanbo Gao, Xingye Sun, Chao Shen 0001
IEEE Trans. Netw.7
2026 JailGuard: A Universal Detection Framework for Prompt-based Attacks on LLM Systems
abstract
The systems and software powered by Large Language Models (LLMs) and Multi-Modal Large Language Models (MLLMs) have played a critical role in numerous scenarios. However, current LLM systems are vulnerable to prompt-based attacks, with jailbreaking attacks enabling the LLM system to generate harmful content, while hijacking attacks manipulate the LLM system to perform attacker-desired tasks, underscoring the necessity for detection tools. Unfortunately, existing detecting approaches are usually tailored to specific attacks, resulting in poor generalization in detecting various attacks across different modalities. To address it, we propose JailGuard , a universal detection framework deployed on top of LLM systems for prompt-based attacks across text and image modalities. JailGuard operates on the principle that attacks are inherently less robust than benign ones. Specifically, JailGuard mutates untrusted inputs to generate variants and leverages the discrepancy of the variants’ responses on the target model to distinguish attack samples from benign samples. We implement 18 mutators for text and image inputs and design a mutator combination policy to further improve detection generalization. The evaluation on the dataset containing 15 known attack types suggests that JailGuard achieves the best detection accuracy of 86.14%/82.90% on text and image inputs, outperforming state-of-the-art methods by 11.81–25.73% and 12.20–21.40%.
Xiaoyu Zhang 0013, Cen Zhang, Tianlin Li, Yihao Huang 0001, Xiaojun Jia, Ming Hu 0003, Jie Zhang 0073, Yang Liu 0003, Shiqing Ma, Chao Shen 0001
ACM Trans. Softw. Eng. Methodol.10
2026 P3Forecast: Personalized and Adaptive Cloud Workload Prediction via GAN-Based Federated Data Augmentation
abstract
To comply with privacy regulations and self-protection from cloud outages, increasingly more users are leveraging multiple cloud providers for service deployment. However, due to the isolation of highly Non-Identically and Independently Distributed (Non-IID) workload datasets and deficiencies of existing methods as reflected in our experimental studies, no cloud providers can single-handedly capture the workload patterns of such users for accurate workload prediction. Accordingly, we proposeP3Forecast, aPersonalizedPrivacy-Preserving Cloud workload prediction framework based on Federated Generative Adversarial Networks (GANs), which allows cloud providers with Non-IID workload data to collaboratively train workload prediction models as preferred while protecting privacy. We first design a data synthesis quality assessment method based on Dynamic Time Warping (calledpattern-aware DTW), which is insusceptible to time series length and reliable for the comparison of temporal patterns. By usingpattern-aware DTWas the model aggregation weights, we adopt the Federated Learning (FL) of a GAN model for the augmentation of IID workload training datasets per cloud provider. Then, we further design a post-training method of local workload prediction models, which consists of a query mechanism based on comprehensive evaluation of data synthesis informativeness and an adaptive learning rate adjustment strategy for stable convergence. Extensive experiments driven by real-world workloads demonstrate that compared with the state-of-the-art,P3Forecastimproves workload prediction accuracy by 23.7%-64.5% on average over all cloud providers, while ensuring the fastest convergence in Federated GAN training.
Xin Yong, Li Yan 0004, Yu Kuang, Zhuozhao Li, Chao Shen 0001, Xingwei Wang 0001
IEEE Trans. Parallel Distributed Syst.5
2026 Graph Attention Network-Driven Hierarchical Learning for Anti-Jamming UAV Communications
abstract
Jamming attacks pose a significant threat to the security of air-ground communications, where the challenge becomes more severe when involving multiple unmanned aerial vehicles (UAVs) incurring complex interference. To address this issue, this paper proposes a graph attention-based reinforcement learning strategy for anti-jamming UAV communications. Specifically, we consider the multi-UAV transmission and deployment in the presence of jamming attacks. Then, we formulate a zero-sum game with the legitimate side and adversary to maximize and minimize the overall transmission rate, respectively. Given the complicated structure of the game, we decompose it into two layers, tackled in a hierarchical learning framework. Particularly, the inner layer addresses the legitimate beamforming, for which we establish the graph attention network (GAT) to track the complicated interference and jamming relationship based on the graph representation of the UAV network. The outer layer address the legitimate UAV deployment and adversarial jamming policy, which is reinterpreted in a multi-agent deep reinforcement learning framework to obtain the strategies of both sides. The inner GAT is then nested within the outer multi-agent learning framework in a hierarchical manner to approximate the equilibrium of the original game model. Simulation results demonstrate the convergence and the performance superiority of the proposed learning scheme in terms of anti-jamming transmission rate. Also, the results exhibit significant generalization capability to cover different network configurations and parameters with reliable communication performance.
Xiao Tang 0001, Chao Shen 0001, Chenhao Lin, Shuai Liu 0016, Bohui Wang, Dusit Niyato, Zhu Han 0001
IEEE Trans. Wirel. Commun.3
2025 Improving Integrated Gradient-based Transferable Adversarial Examples by Refining the Integration Path
abstract
Transferable adversarial examples are known to cause threats in practical, black-box attack scenarios. A notable approach to improving transferability is using integrated gradients (IG), originally developed for model interpretability. In this paper, we find that existing IG-based attacks have limited transferability due to their naive adoption of IG in model interpretability. To address this limitation, we focus on the IG integration path and refine it in three aspects: multiplicity, monotonicity, and diversity, supported by theoretical analyses. We propose the Multiple Monotonic Diversified Integrated Gradients (MuMoDIG) attack, which can generate highly transferable adversarial examples on different CNN and ViT models and defenses. Experiments validate that MuMoDIG outperforms the latest IG-based attack by up to 37.3% and other state-of-the-art attacks by 8.4%. In general, our study reveals that migrating established techniques to improve transferability may require non-trivial efforts.
Yuchen Ren 0002, Zhengyu Zhao 0001, Chenhao Lin, Bo Yang 0049, Lu Zhou 0002, Zhe Liu 0001, Chao Shen 0001
AAAI7
2025 CALM: Curiosity-Driven Auditing for Large Language Models
abstract
Auditing Large Language Models (LLMs) is a crucial and challenging task. In this study, we focus on auditing black-box LLMs without access to their parameters, only to the provided service. We treat this type of auditing as a black-box optimization problem where the goal is to automatically uncover input-output pairs of the target LLMs that exhibit illegal, immoral, or unsafe behaviors. For instance, we may seek a non-toxic input that the target LLM responds to with a toxic output or an input that induces the hallucinative response from the target LLM containing politically sensitive individuals. This black-box optimization is challenging due to the scarcity of feasible points, the discrete nature of the prompt space, and the large search space. To address these challenges, we propose Curiosity-Driven Auditing for Large Language Models (CALM), which uses intrinsically motivated reinforcement learning to finetune an LLM as the auditor agent to uncover potential harmful and biased input-output pairs of the target LLM. CALM successfully identifies derogatory completions involving celebrities and uncovers inputs that elicit specific names under the black-box setting. This work offers a promising direction for auditing black-box LLMs.
Yi Liu 0057, Xingjun Ma, Chao Shen 0001, Cong Wang 0001
AAAI5
2025 Iron Sharpens Iron: Defending Against Attacks in Machine-Generated Text Detection with Adversarial Training
abstract
Machine-generated Text (MGT) detection is crucial for regulating and attributing online texts.While the existing MGT detectors achieve strong performance, they remain vulnerable to simple perturbations and adversarial attacks.To build an effective defense against malicious perturbations, we view MGT detection from a threat modeling perspective, that is, analyzing the model's vulnerability from an adversary's point of view and exploring effective mitigations.To this end, we introduce an adversarial framework for training a robust MGT detector, named GREedy Adversary PromoTed DefendER (GREATER).The GREATER consists of two key components: an adversary GREATER-A and a detector GREATER-D.The GREATER-D learns to defend against the adversarial attack from GREATER-A and generalizes the defense to other attacks.GREATER-A identifies and perturbs the critical tokens in embedding space, along with greedy search and pruning to generate stealthy and disruptive adversarial examples.Besides, we update the GREATER-A and GREATER-D synchronously, encouraging the GREATER-D to generalize its defense to different attacks and varying attack intensities.Our experimental results across 10 text perturbation strategies and 6 adversarial attacks show that our GREATER-D reduces the Attack Success Rate (ASR) by 0.67% compared with SOTA defense methods while our GREATER-A is demonstrated to be more effective and efficient than SOTA attack approaches.Codes and dataset are available in https:// github.com/Liyuuuu111/GREATER.
Yuanfan Li, Zhaohan Zhang, Chengzhengxu Li, Chao Shen 0001
ACL (1)4
2025 The Invisible Hand: Unveiling Provider Bias in Large Language Models for Code Generation
abstract
Xiaoyu Zhang, Juan Zhai, Shiqing Ma, Qingshuang Bao, Weipeng Jiang, Qian Wang, Chao Shen, Yang Liu. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025.
Xiaoyu Zhang 0013, Juan Zhai, Shiqing Ma, Qingshuang Bao, Qian Wang 0002, Chao Shen 0001, Yang Liu 0003
ACL (1)7
2025 ControlLoc: Physical-World Hijacking Attack on Camera-based Perception in Autonomous Driving
abstract
Recent research shows that adversarial patches can attack object detectors in camera-based perception for Autonomous Driving (AD). However, camera-based perception includes more than object detection; it also involves Multiple Object Tracking (MOT), which enhances robustness by requiring consistent detection across multiple frames before affecting tracking and thus, driving decisions. This makes attacks on object detection alone less effective. To attack such robust systems, a digital hijacking attack has been proposed, aiming to induce dangerous scenarios such as collisions. However, this attack has limited effectiveness, especially in the physical world.
Ningfei Wang, Zhengyu Zhao 0001, Qian Wang 0002, Qi Alfred Chen, Chao Shen 0001
CCS6
2025 Improving Adversarial Transferability on Vision Transformers via Forward Propagation Refinement
abstract
Vision Transformers (ViTs) have been widely applied in various computer vision and vision-language tasks. To gain insights into their robustness in practical scenarios, transferable adversarial examples on ViTs have been extensively studied. A typical approach to improving adversarial transferability is by refining the surrogate model. However, existing work on ViTs has restricted their surrogate refinement to backward propagation. In this work, we instead focus on Forward Propagation Refinement (FPR) and specifically refine two key modules of ViTs: attention maps and token embeddings. For attention maps, we propose Attention Map Diversification (AMD), which diversifies certain attention maps and also implicitly imposes beneficial gradient vanishing during backward propagation. For token embeddings, we propose Momentum Token Embedding (MTE), which accumulates historical token embeddings to stabilize the forward updates in both the Attention and MLP blocks. We conduct extensive experiments with adversarial examples transferred from ViTs to various CNNs and ViTs, demonstrating that our FPR outperforms the current best (backward) surrogate refinement by up to 7.0% on average. We also validate its superiority against popular defenses and its compatibility with other transfer methods. Codes and appendix are available at https://github.com/RYC-98/FPR.
Yuchen Ren 0002, Zhengyu Zhao 0001, Chenhao Lin, Bo Yang 0049, Lu Zhou 0002, Zhe Liu 0001, Chao Shen 0001
CVPR7
2025 Nullu: Mitigating Object Hallucinations in Large Vision-Language Models via HalluSpace Projection
abstract
Recent studies have shown that large vision-language models (LVLMs) often suffer from the issue of object hallucinations (OH). To mitigate this issue, we introduce an efficient method that edits the model weights based on an unsafe subspace, which we call HalluSpace in this paper. With truthful and hallucinated text prompts accompanying the visual content as inputs, the HalluSpace can be identified by extracting the hallucinated embedding features and removing the truthful representations in LVLMs. By orthog-onalizing the model weights, input features will be projected into the Null space of the HalluSpace to reduce OH, based on which we name our method Nullu. We reveal that Hal-luSpaces generally contain prior information in the large language models (LLMs) applied to build LVLMs, which have been shown as essential causes of OH in previous studies. Therefore, null space projection suppresses the LLMs’ priors to filter out the hallucinated features, resulting in contextually accurate outputs. Experiments show that our method can effectively mitigate OH across different LVLM families without extra inference costs and also show strong performance in general LVLM benchmarks. Code is released at https://github.com/Ziwei-Zheng/Nullu.
Le Yang 0007, Ziwei Zheng, Boxu Chen, Zhengyu Zhao 0001, Chenhao Lin, Chao Shen 0001
CVPR6
2025 Shining Yourself: High-Fidelity Ornaments Virtual Try-on with Diffusion Model
abstract
While virtual try-on for clothes and shoes with diffusion models has gained attraction, virtual try-on for ornaments, such as bracelets, rings, earrings, and necklaces, remains largely unexplored. Due to the intricate tiny patterns and repeated geometric sub-structures in most ornaments, it is much more difficult to guarantee identity and appearance consistency under large pose and scale variances between ornaments and models. This paper proposes the task of virtual try-on for ornaments and presents a method to improve the geometric and appearance preservation of ornament virtual try-ons. Specifically, we estimate an accurate wearing mask to improve the alignments between ornaments and models in an iterative scheme alongside the denoising process. To preserve structure details, we further regularize attention layers to map the reference ornament mask to the wearing mask in an implicit way. Experimental results demonstrate that our method successfully wears ornaments from reference images onto target models, handling substantial differences in scale and pose while preserving identity and achieving realistic visual effects.
Yingmao Miao, Zhanpeng Huang, Zibin Wang, Chenhao Lin, Chao Shen 0001
CVPR6
2025 TGDrag: Adding Semantic Control into Point-based Image Editing via Text Guidance
abstract
Controllable image generation has emerged as a cutting-edge subject of interest. Current interactive point-based image editing frameworks, such as DragGAN, achieve impressive results in fine-grained and controllable image editing. However, relying solely on point-based manipulations can lead to unintended outcomes due to the inherent lack of the users’ semantic intent. To address this issue, we introduce Text-Guided Drag (TGDrag), a novel approach to adding semantic control into point-based image editing by using text prompts to guide the manipulation of handle and target points. Specifically, we design a channel correlation calculator that adaptively selects channels for the text and points to mitigate the potential influence of semantic control on point control. Furthermore, we introduce a text loss function to minimize the discrepancy between the generated images and the text prompts. Experimental results demonstrate that TGDrag achieves the expected function of semantic control while maintaining effectiveness regarding point control.
Chenhao Lin, Yanjie Zhu, Yingmao Miao, Zhengyu Zhao 0001, Shuai Liu 0016, Chao Shen 0001
ICASSP6
2025 One-Shot Face Avatar Generation in a Single Forward Pass with Identity Preservation
abstract
Face avatar generation has gained significant attention recently. With the help of the Neural Radiance Field (NeRF), existing 3D methods alleviate facial distortion in 2D methods under large pose changes. However, the state-of-the-art 3D methods still require additional optimization for generation on each given portrait, even in a one-shot manner. To address this research gap, we propose a novel one-shot approach, which achieves effective face avatar generation in only a single forward pass. This is made possible by introducing an inversion encoder trained on a large-scale dataset for accurate latent code estimation and an expression animator for accurate expression control. Our approach is also designed for better preservation of the face identity by training an additional 3D feature refiner based on cross-attention. Experimental results demonstrate the superiority of our approach in terms of 3D consistency, identity similarity, and image quality.
Yingmao Miao, Chenhao Lin, Zhengyu Zhao 0001, Shuai Liu 0016, Chao Shen 0001, Xiaohong Guan
ICASSP6
2025 Revisiting Adversarial Patch Defenses on Object Detectors: Unified Evaluation, Large-Scale Dataset, and New Insights
abstract
Developing reliable defenses against patch attacks on object detectors has attracted increasing interest. However, we identify that existing defense evaluations lack a unified and comprehensive framework, resulting in inconsistent and incomplete assessments of current methods. To address this issue, we revisit 11 representative defenses and present the first patch defense benchmark, involving 2 attack goals, 13 patch attacks, 11 object detectors, and 4 diverse metrics. This leads to the large-scale adversarial patch dataset with 94 types of patches and 94,000 images. Our comprehensive analyses reveal new insights: (1) The difficulty in defending against naturalistic patches lies in the data distribution, rather than the commonly believed high frequencies. Our new dataset with diverse patch distributions can be used to improve existing defenses by 15.09% [email protected]. (2) The average precision of the attacked object, rather than the commonly pursued patch detection accuracy, shows high consistency with defense performance. (3) Adaptive attacks can substantially bypass existing defenses, and defenses with complex/stochastic models or universal patch properties are relatively robust. We hope that our analyses will serve as guidance on properly evaluating patch attacks/defenses and advancing their design. Code and dataset are available at https://github.com/Gandolfczjh/APDE, where we will keep integrating new attacks/defenses.
Junhao Zheng, Chenhao Lin, Zhengyu Zhao 0001, Chao Shen 0001, Cong Wang 0001, Qian Wang 0002
ICCV7
2025 D3: Training-Free AI-Generated Video Detection Using Second-Order Features
Chende Zheng, Ruiqi Suo, Chenhao Lin, Zhengyu Zhao 0001, Le Yang 0007, Shuai Liu 0016, Cong Wang 0001, Chao Shen 0001
ICCV9
2025 STAFF: Speculative Coreset Selection for Task-Specific Fine-tuning
abstract
Task-specific fine-tuning is essential for the deployment of large language models (LLMs), but it requires significant computational resources and time. Existing solutions have proposed coreset selection methods to improve data efficiency and reduce model training overhead, but they still have limitations: ❶ Overlooking valuable samples at high pruning rates, which degrades the coreset’s performance. ❷ Requiring high time overhead during coreset selection to fine-tune and evaluate the target LLM. In this paper, we introduce STAFF, a speculative coreset selection method. STAFF leverages a small model from the same family as the target LLM to efficiently estimate data scores and then verifies the scores on the target LLM to accurately identify and allocate more selection budget to important regions while maintaining coverage of easy regions. We evaluate STAFF on three LLMs and three downstream tasks and show that STAFF improves the performance of SOTA methods by up to 54.3% and reduces selection overhead by up to 70.5% at different pruning rates. Furthermore, we observe that the coreset selected by STAFF at low pruning rates (i.e., 20%) can even obtain better fine-tuning performance than the full dataset.
Xiaoyu Zhang 0013, Juan Zhai, Shiqing Ma, Chao Shen 0001, Tianlin Li, Yang Liu 0003
ICLR4
2025 Evading Deepfake Detectors via Adversarially Degrading and Restoring Forged Images
abstract
Deepfake detection can prevent the misuse of deep generative techniques but is known to be vulnerable to adversarial attacks. However, most existing attacks introduce noticeable noise, resulting in an unsatisfactory trade-off between attack effectiveness and imperceptibility. In this paper, we propose a new generative attack based on adversarially Degrading and Restoring (DR) fake images, eliminating the use of noisy perturbations. Specifically, degradation works by removing high-frequency deepfake artifacts with the guidance of adversarial loss from the detector, and the subsequent restoration aims to maintain the image quality by restoring high-frequency details of natural images. Our analysis confirms that combining degradation and restoration effectively aligns the distribution of adversarial (fake) images and real images in both frequency and pixel domains. Our experimental results across eight popular detectors and three popular deep-fake datasets prove the effectiveness of our method compared with several state-of-the-art methods. Our code is available at https://github.com/fanoflck/DR_attack.
Zhengli Shi, Chenhao Lin, Zhengyu Zhao 0001, Peter Peer, Chao Shen 0001
ICME5
2025 Self-Supervised Continual Graph Learning via Adaptive Spaced Replay on Node Proxies
abstract
Most self-supervised graph learning studies typically follow an offline training paradigm, assuming that all data are readily available.This assumption, however, is not always tenable in real-world scenarios as many graph data are generated continuously.Although several continual graph learning models have emerged and achieved empirical success, they almost all rely on external supervision, making it difficult to adapt to applications with a large amount of unlabeled data from the wild.To be honest, research on self-supervised continual graph learning is still surprisingly in its infancy.Therefore, we select several well-known self-supervised graph embedding models as representatives and explore whether they are resistant to catastrophic forgetting in a continual learning setting.Empirical studies find that self-supervised representation models may be potentially better continual learners than supervised counterparts.Driven by this advantage, we propose a self-supervised continual graph representation learning framework based on adaptive spaced replay on node proxies, named Trace.Inspired by the Complementary Learning System theory, Trace employs a dual-system architecture to simulate the functionality and cooperation of the hippocampus and neocortex in the brain.Among them, the fastlearning system efficiently encodes the current input graph to acquire new knowledge and adaptively extracts node proxies from it as important knowledge cached into the memory through progressive clustering.Drawing inspiration from the Ebbinghaus forgetting curve, the slow-learning system implements adaptive spaced replay based on the memory retention rate of each preceding task instead of the widely used consecutive replay scheme for promising flexibility and efficiency.Experiments under task-incremental and class-incremental learning settings on multiple datasets corroborate
Zhen Peng 0005, Xu Hua, Jingchen Hao, Qika Lin, Bo Dong 0001, Chao Shen 0001
KDD (2)6
2025 LVLM-FDA: Protecting Large Vision-Language Models via Fast Detection of Malicious Attempts
Boxu Chen, Le Yang 0007, Ziwei Zheng, Cong Wang 0001, Qian Wang 0002, Chao Shen 0001
KSEM (1)7
2025 Jailbreak-AudioBench: In-Depth Evaluation and Analysis of Jailbreak Threats for Large Audio Language Models
abstract
Large Language Models (LLMs) demonstrate impressive zero-shot performance across a wide range of natural language processing tasks. Integrating various modality encoders further expands their capabilities, giving rise to Multimodal Large Language Models (MLLMs) that process not only text but also visual and auditory modality inputs. However, these advanced capabilities may also pose significant safety problems, as models can be exploited to generate harmful or inappropriate content through jailbreak attack. While prior work has extensively explored how manipulating textual or visual modality inputs can circumvent safeguards in LLMs and MLLMs, the vulnerability of audio-specific Jailbreak on Large Audio-Language Models (LALMs) remains largely underexplored. To address this gap, we introduce \textbf{Jailbreak-AudioBench}, which consists of the Toolbox, curated Dataset, and comprehensive Benchmark. The Toolbox supports not only text-to-audio conversion but also various editing techniques for injecting audio hidden semantics. The curated Dataset provides diverse explicit and implicit jailbreak audio examples in both original and edited forms. Utilizing this dataset, we evaluate multiple state-of-the-art LALMs and establish the most comprehensive Jailbreak benchmark to date for audio modality. Finally, Jailbreak-AudioBench establishes a foundation for advancing future research on LALMs safety alignment by enabling the in-depth exposure of more powerful jailbreak threats, such as query-based audio editing, and by facilitating the development of effective defense mechanisms.
Hao Cheng 0015, Erjia Xiao, Yichi Wang 0002, Le Yang 0007, Chao Shen 0001, Philip Torr 0001, Jindong Gu, Renjing Xu
NeurIPS6
2025 Co-design of Partly Transition Rates and Output Feedback Control of Markovian Jump Systems
abstract
This paper addresses co-design control strategies for continuous-time Markov jump systems where subsets of transition rate matrices are fixed a priori, challenging conventional co-design methodologies. A synchronously mode-dependent parametric framework is developed to address partial transition rate optimization alongside output feedback controller synthesis. Novel criterion is derived to guarantee mean-square stability by reconstructing adjustable switching parameters while preserving fixed system transitions. Stability analysis and controller design are unified through hybrid control principles. A numerical case studies validate the proposed approach, demonstrating enhanced feasibility compared to existing methods.
Ruiqing Fu, Yufeng Tian, Michael Shi, Tao Jiang 0002, Yaoyao Tan, Chao Shen 0001
SMC6
2025 Revisiting Training-Inference Trigger Intensity in Backdoor Attacks
Chenhao Lin, Chenyang Zhao 0006, Longtian Wang, Chao Shen 0001, Zhengyu Zhao 0001
USENIX Security Symposium5
2025 JBShield: Defending Large Language Models from Jailbreak Attacks through Activated Concept Analysis and Manipulation
Shenyi Zhang, Yuchen Zhai, Keyan Guo, Hongxin Hu, Zheng Fang 0014, Lingchen Zhao, Chao Shen 0001, Cong Wang 0001, Qian Wang 0002
USENIX Security Symposium8
2025 Artificial intelligence security and privacy: a survey
abstract
Abstract Artificial intelligence (AI) is revolutionizing both industries and reshaping the global economy. However, the rapid advancement of AI technologies brings significant security and privacy challenges. Recent incidents highlight vulnerabilities in AI systems, such as data leakage and malicious code injection, leading to severe financial losses and privacy breaches. Although existing studies have discussed specific security threats, they often lack detailed granularity and cover a limited scope. In this survey, we fill this gap by systematically categorizing and analyzing the threats and countermeasures in AI systems, which span both the training and inference stages, encompass centralized and distributed settings, and address both conventional and foundation AI models. By reviewing existing literature, we aim to provide AI researchers and practitioners with a thorough understanding of system vulnerabilities and current countermeasures. We hope to inspire further research into robust solutions, ultimately contributing to the development of resilient AI technologies.
Xinlei He 0001, Guowen Xu, Xingshuo Han, Qian Wang 0002, Lingchen Zhao, Chao Shen 0001, Chenhao Lin, Zhengyu Zhao 0001, Qian Li 0024, Le Yang 0007, Shouling Ji, Shaofeng Li 0001, Haojin Zhu, Zhibo Wang 0001, Tianqing Zhu, Qi Li 0002, Chaoxiang He, Hongsheng Hu, Shuo Wang 0012, Shifeng Sun 0001, Hongwei Yao, Qinyu Zhang 0001, Kai Chen 0012, Yue Zhao 0027, Hongwei Li 0001, Xinyi Huang 0001, Dengguo Feng
Sci. China Inf. Sci.6
2025 Backdoor threats in large language models - a survey
Shuai Liu 0016, Yiheng Pan, Kun Hong, Ruite Fei, Chenhao Lin, Qian Li 0024, Chao Shen 0001
Sci. China Inf. Sci.7
2025 When bipartite graph learning meets anomaly detection in attributed networks: Understand abnormalities from each attribute
Zhen Peng 0005, Qika Lin, Bo Dong 0001, Chao Shen 0001
Neural Networks5
2025 EvolGCN: A Co-Evolutionary Graph Convolutional Network Model for Dynamically Spatio-Temporal Anomaly Event Inference
abstract
Accurately spatio-temporal anomaly event inference is significant to enhance society’s safety, such as crime prevention and traffic collision reduction, etc. However, it is hard to achieve good performance for its complicated process being influenced by various kinds of factors. Previous works mainly focus on employing feature-based regression or fitting models with supposed spatio-temporal distribution to tackle this challenge, but are normally short of the following considerations: 1) mutual evolutionary influence, i.e., the dynamic evolution of interactions and dependencies among anomaly events, is changing along with the timeline and alters the probabilities or patterns of their occurrences dynamically; 2) messy features, i.e., complex attributes in the data but with noise, are difficult to select and aggregate for the representation learning algorithm with uncertainty and redundancy. To address the research gap, we put forward a co-evolutionary graph convolutional network model to explicate the dynamically spatio-temporal anomaly patterns. Specifically, we firstly take advantage of a fuzzy-rough set-based algorithm to select features by discovering the specialty and permanence attributes of different interaction features. Then, we propose a co-evolutionary learning method to embed the dynamically temporal influence into latent features with selected interaction information. Finally, we design a graph convolutional network with an attention mechanism to formulate the mutually spatial effects among the anomaly events. The proposed model is verified on the New York City crime records from the real-world, and extensive experiments show that our approach achieves 0.10129, 0.09958 and 0.10034 of the MAE (hour) in the action, location, and action-location time inference tasks, and 0.7973 and 0.4678 of the accuracy in the action and location type inference tasks, which outperform state-of-arts by 24.00%, 50.60%, 11.10%, 10.56% and 21.53% at most, respectively. Hyper-parameter and ablation experiments are also carried out further to demonstrate the sensitivity and effectiveness of our model.
Xiaoming Liu 0011, Hang Pu, Zhanwei Zhang, Yu Lan 0001, Chao Shen 0001
IEEE Trans. Dependable Secur. Comput.6
2025 An Automated Monitoring and Repairing System for DNN Training
abstract
With the widespread adoption of machine learning models, especially deep neural networks (DNNs), as an integral part of new intelligent software, the new tools to effectively support the model engineering and debugging process have received extensive attention. However, the existing tools only provide limited support for the training process. They are either post-training tools that fail to detect problems timely, resulting in wasting time and resources on training buggy models, or merely collecting the training data and still require manual analysis. In this paper, we proposeAutoTrainer, an automated monitoring and repairing system for DNN training, which provides real-time monitoring for the model training process and automatically repairs eight commonly seen training problems.AutoTrainermonitors the training process and detects potential training problems. For any detected problem,AutoTrainertries to fix it with the built-in state-of-the-art solutions. Our experiments on six datasets and 701 models show that the problem detection accuracy ofAutoTrainerreaches 100% without false positives. Moreover, it fixes 98.42% of all detected problems and improves the model accuracy by 36.42% on average.
Xiaoyu Zhang 0013, Chao Shen 0001, Shiqing Ma, Juan Zhai, Chenhao Lin
IEEE Trans. Dependable Secur. Comput.2
2025 Robust Adversarial Defenses in Federated Learning: Exploring the Impact of Data Heterogeneity
abstract
Federated Learning (FL) enables geographically distributed clients to collaboratively train machine learning models by exchanging local model parameters while preserving data privacy. In practice, FL faces two critical challenges. First, it is vulnerable to security issues as malicious clients would artificially harm the functionality of FL by launching poisoning attacks. Second, the inherent data heterogeneity among clients (termed Non-IID data in FL) naturally arises from distributed data ownership and significantly degrades model convergence and accuracy. However, with studies separately devoted to these two research lines, the interplay between data heterogeneity and security remains poorly understood. In this paper, we systematically investigate the relationship between data heterogeneity and adversarial robustness in FL. Specifically, we propose novel data partitioning algorithms that simulate Label-Conditional Non-IID and Feature-Conditional Non-IID with quantifiable heterogeneity levels. Further, we conduct extensive experiments to evaluate classical defense methods in the practical FL environment under state-of-the-art untargeted attacks. With results in various settings, we separately analyze the connection between Non-IID to defenses and attacks. Regarding attacks, with similar effects on models, Non-IID impacts the training in a different way compared with attacks. The interaction between attacks and Non-IID provides an opportunity to cause severe damage to FL. Regarding defenses, Non-IID induces heterogeneity in model distribution among clients which raises the difficulty of maintaining fidelity and robustness for defense methods.
Qian Li 0024, Di Wu 0062, Dawei Zhou 0004, Chenhao Lin, Shuai Liu 0016, Cong Wang 0001, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.7
2025 Hard Adversarial Example Mining for Improving Robust Fairness
abstract
Adversarial training (AT) is widely considered the state-of-the-art technique for improving the robustness of deep neural networks (DNNs) against adversarial examples (AEs). Nevertheless, recent studies have revealed that adversarially trained models are prone to unfairness problems. Recent works in this field usually apply class-wise regularization methods to enhance the fairness of AT. However, this paper discovers that these paradigms can be sub-optimal in improving robust fairness. Specifically, we empirically observe that the AEs that are already robust (referred to as “easy AEs” in this paper) are useless and even harmful in improving robust fairness. To this end, we propose the hard adversarial example mining (HAM) technique which concentrates on mining hard AEs while discarding the easy AEs in AT. Specifically, HAM identifies the easy AEs and hard AEs with a fast adversarial attack method. By discarding the easy AEs and reweighting the hard AEs, the robust fairness of the model can be efficiently and effectively improved. Extensive experimental results on four image classification datasets demonstrate the improvement of HAM in robust fairness and training efficiency compared to several state-of-the-art fair adversarial training methods. Our code is available athttps://github.com/yyl-github-1896/HAM.
Chenhao Lin, Yulong Yang 0002, Qian Li 0024, Zhengyu Zhao 0001, Zhe Peng, Run Wang 0001, Liming Fang 0001, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.9
2025 De2Trojan: Deployable Trojan Analysis Tool and Benchmark for the Machine Learning Lifecycle via Decoupling
abstract
Trojans (backdoors) are known to raise critical security concerns for deep neural networks in machine learning (ML) systems. Despite the extensive backdoor methods and benchmarks, existing research overlooks the perspective of the ML lifecycle (i.e., the entire process from system design to data collection to model deployment). To address this gap, this paper introduces De2Trojan, a Deployable Trojan Analysis Tool via Decoupling, which establishes a standardized pipeline to investigate backdoor attacks and defenses within the ML lifecycle. De2Trojan decouples the attack surface from the general ML process through a stage-first hijacking approach, using an abstract interface for ML lifecycle stages to enhance the deployability to the ML lifecycle. Besides, its benefits are two-fold: (1) Facilitating the systematic analyses of multi-stage attacks/defenses and their combinations, shedding light on how to improve attack and defense strategies. For example, we find that current attacks (defenses) are not effective in continuous scenarios, and combining attacks (defenses) at different stages improves their effectiveness from 30.11% (8.63%), the worst cases, to 90.27% (68.73%). (2) Making it possible to identify potentially vulnerable stages, especially when iteratively updating the model in ML lifecycle. For example, we identify that backdoor attacks in the data collection stage are more vulnerable than expected, and it is more difficult to remove them from the ML lifecycle. To eliminate the impact of such attacks, it is most effective to apply backdoor defense during the deployment stage, in addition to cleaning the data before training. Overall, we present a comprehensive benchmark of backdoors within the ML lifecycle, involving 20 representative attacks and defenses, as well as their combinations, using 11 evaluation metrics.
Chenyang Zhao 0006, Chenhao Lin, Zhengyu Zhao 0001, Qian Wang 0002, Chao Shen 0001, Xiaohong Guan
IEEE Trans. Inf. Forensics Secur.7
2025 Data-Centric Robust Training for Defending Against Transfer-Based Adversarial Attacks
abstract
Transfer-based adversarial attacks pose a severe threat to real-world deep learning systems since they do not require access to target models. Adversarial training (AT), which is recognized as the most effective defense against white-box attacks, also ensures high robustness against (black-box) transfer-based attacks. However, AT suffers from significant computational overhead because it repeatedly generates adversarial examples (AEs) throughout the entire training process. In this paper, we demonstrate that such repeated generation is unnecessary to achieve robustness against transfer-based attacks. Instead, pre-generating AEs all at once before training is sufficient, as proposed in our new defense paradigm called Data-Centric Robust Training (DCRT). DCRT employs clean data augmentation and adversarial data augmentation techniques to enhance the dataset before training. Our experimental results show that DCRT outperforms widely-used AT techniques (e.g., PGD-AT, TRADES, EAT, and FAT) in terms of transfer-based black-box robustness and even surpasses the top-1 defense on RobustBench when combined with common model-centric techniques. We also highlight additional benefits of DCRT, such as improved training efficiency and class-wise fairness.Our code will be available on GitHub.
Yulong Yang 0002, Ruiqi Cao, Qiwei Tian, Chenhao Lin, Zhengyu Zhao 0001, Qian Li 0024, Le Yang 0007, Hongshan Yang, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.10
2025 1+1>2: A Dual-Function Defense Framework for Adversarial Example Mitigation
abstract
Current state-of-the-art plug-and-play countermeasures for mitigating adversarial examples (i.e., purification and detection) exhibit several fatal limitations, impeding their deployment in safety-critical real-world applications. These limitations include susceptibility to adaptive attacks, adverse impact on benign samples, high time consumption for conducting a complete defense cycle, etc. To bridge the gap, developing more advanced plug-and-play countermeasures is urgently needed to safeguard these applications. Specifically, this paper first proposes a novel method named Gaussian-augmented GAN-based Adversarial Purification (GA-GAP). Unlike previous methods, GA-GAP enhances the density of the training data in low-robustness regions by using random Gaussian noise. Moreover, GA-GAP incorporates a pre-trained deep learning classifier into the training architecture and integrates its classification loss into the training loss function. Then, following the development of GA-GAP, this paper innovatively proposes a dual-function defense framework named Adversarial Detection on Purification (ADoP) to mitigate adversarial examples further. In ADoP, purification and detection complement each other, achieving the effect of$\mathbf {1+1\gt 2}$, which can more efficiently avoid adaptive attacks. Extensive experiments on ImageNet demonstrate that ADoP outperforms other countermeasures in multiple aspects. These aspects include superior generalization capability in purifying and detecting various adversarial examples, less adverse impact on benign samples, and practical time consumption for conducting a complete defense cycle.
Rui Yang 0032, Qindong Sun, Han Cao 0004, Chao Shen 0001, Jiaming Cai, Dongzhu Rong
IEEE Trans. Inf. Forensics Secur.4
2025 Adversarial Example Soups: Improving Transferability and Stealthiness for Free
abstract
Transferable adversarial examples cause practical security risks since they can mislead a target model without knowing its internal knowledge. A conventional recipe for maximizing transferability is to keep only the optimal adversarial example from all those obtained in the optimization pipeline. In this paper, for the first time, we revisit this convention and demonstrate that those discarded, sub-optimal adversarial examples can be reused to boost transferability. Specifically, we propose “Adversarial Example Soups” (AES), with AES-tune for averaging discarded adversarial examples in hyperparameter tuning and AES-rand for stability testing. In addition, our AES is inspired by “model soups”, which averages weights of multiple fine-tuned models for improved accuracy without increasing inference time. Extensive experiments validate the global effectiveness of our AES, boosting 10 state-of-the-art transfer attacks and their combinations by up to 13% against 10 diverse (defensive) target models. We also show the possibility of generalizing AES to other types, e.g., directly averaging multiple in-the-wild adversarial examples that yield comparable success. A promising byproduct of AES is the improved stealthiness of adversarial examples since the perturbation variances are naturally reduced.
Bo Yang 0049, Hengwei Zhang, Jindong Wang 0002, Yulong Yang 0002, Chenhao Lin, Chao Shen 0001, Zhengyu Zhao 0001
IEEE Trans. Inf. Forensics Secur.6
2025 Miniature Real-Time Compact Deep Neural Network With Zero-Shot Neural Architecture Search for Lithium-Ion Battery Fault Diagnosis
abstract
Battery energy storage systems (BESS) are essential for modern energy management, supporting renewable integration and grid stability. However, fault diagnosis for BESS requires extensive manual network tuning. To overcome this, we introduce a zero-shot neural architecture search approach for BESS fault diagnosis. First, the neural network is broken down into piecewise linear functions, and the Rademacher complexity is calculated for this class of functions. To prevent batch normalization (BN) layers from repeatedly scaling the Rademacher complexity and invalidating network comparisons, the Rademacher complexity is approximated using the variance of the BN layers. Finally, the selected models are then compressed via 8-bit quantization to facilitate deployment on mobile devices. This approach achieves 99.42% accuracy in just 0.51 GPU h, significantly reducing model search time without needing pretrained models. We validate this method on a self-developed BESS platform featuring a battery management system and custom mobile app, accessible online.
Zeyang Chen, Dezhi Xu, Chao Shen 0001, Yujian Ye, Bin Jiang 0001
IEEE Trans. Ind. Informatics3
2025 Physically Realizable Adversarial Creating Attack Against Vision-Based BEV Space 3D Object Detection
abstract
Vision-based 3D object detection, a cost-effective alternative to LiDAR-based solutions, plays a crucial role in modern autonomous driving systems. Meanwhile, deep models have been proven susceptible to adversarial examples, and attacking detection models can lead to serious driving consequences. Most previous adversarial attacks targeted 2D detectors by placing the patch in a specific region within the object's bounding box in the image, allowing it to evade detection. However, attacking 3D detector is more difficult because the adversary may be observed from different viewpoints and distances, and there is a lack of effective methods to differentiably render the 3D space poster onto the image. In this paper, we propose a novel attack setting where a carefully crafted adversarial poster (looks like meaningless graffiti) is learned and pasted on the road surface, inducing the vision-based 3D detectors to perceive a non-existent object. We show that even a single 2D poster is sufficient to deceive the 3D detector with the desired attack effect, and the poster is universal, which is effective across various scenes, viewpoints, and distances. To generate the poster, an image-3D applying algorithm is devised to establish the pixel-wise mapping relationship between the image area and the 3D space poster so that the poster can be optimized through standard backpropagation. Moreover, a ground-truth masked optimization strategy is presented to effectively learn the poster without interference from scene objects. Extensive results including real-world experiments validate the effectiveness of our adversarial attack. The transferability and defense strategy are also investigated to comprehensively understand the proposed attack.
Jian Wang 0113, Fan Li 0003, Song Lv, Lijun He 0001, Chao Shen 0001
IEEE Trans. Image Process.5
2025 Distributed Cooperative Control and Robust Optimization for Nonlinear Connected Automated Vehicles With Unknown Reaction Time Delays and Jerk Dynamics
abstract
In complex traffic environments, the driving performance of the leader vehicle in a platoon can be greatly impacted by sudden and unexpected changes in vehicle acceleration rates. This phenomenon is known as unknown jerk dynamics (JDs), and it can lead to more extreme car-following behaviors (CFBs) in platoon tracking control, which may raise safety and traffic capacity issues. To tackle these concerns, this work studies cooperative platoon tracking control and intermittent optimization problems for connected autonomous vehicles (CAVs) with unknown reaction time delays (RTDs) using a nonlinear car following model (NCFM). In a free-design but directed communication network, we assume that the leader CAV’s external inputs have unknown but bounded parameters both for the JDs and RTDs, while only a small number of nearby follower CAVs are aware of the leader CAV’s acceleration signals. To solve these issues, we consider that each follower CAV implements a distributed observer law, which provides a reference signal stated as an estimated JD of the leader CAV. Then, a distributed platoon tracking control protocol is proposed to construct cooperative tracking controllers with identical inter-vehicle constraints (ICs). This maintains the desired safety distance between the CAVs and allows each follower CAV to track its leader CAV only through local information exchange. In addition, we present a robust intermittent optimization design and a novel intermittent sampling condition that can guarantee optimally scheduled feedback gains for the cooperative platoon tracking controllers to minimize the control cost in the presence of unknown JDs and RTDs under non-identical ICs. Simulation case studies are conducted to demonstrate the effectiveness of the proposed approaches. We also demonstrate the efficient development of such a distributed cooperative car-following model for the platoon’s motion (or as an intelligent speed advising system for automated or human-driven vehicles), resulting in a trip that is safe, comfortable, and energy efficient.
Bohui Wang, Chao Shen 0001, Chenhao Lin, Chao Deng 0008, Yang Shi 0001
IEEE Trans. Intell. Transp. Syst.2
2025 Deep Graph Reinforcement Learning for UAV-Enabled Multi-User Secure Communications
abstract
While unmanned aerial vehicles (UAVs) with flexible mobility are envisioned to enhance physical layer security in wireless communications, the efficient security design that adapts to such high network dynamics is rather challenging. The conventional approaches extended from optimization perspectives are usually quite involved, especially when jointly considering factors in different scales such as deployment and transmission in UAV-related scenarios. In this paper, we address the UAV-enabled multi-user secure communications by proposing a deep graph reinforcement learning framework. Specifically, we reinterpret the security beamforming as a graph neural network (GNN) learning task, where mutual interference among users is managed through the message-passing mechanism. Then, the UAV deployment is obtained through soft actor-critic reinforcement learning, where the GNN-based security beamforming is exploited to guide the deployment strategy update. Simulation results demonstrate that the proposed approach achieves near-optimal security performance and significantly enhances the efficiency of strategy determination. Moreover, the deep graph reinforcement learning framework offers a scalable solution, adaptable to various network scenarios and configurations, establishing a robust basis for information security in UAV-enabled communications.
Xiao Tang 0001, Chao Shen 0001, Qinghe Du, Yichen Wang 0002, Dusit Niyato, Zhu Han 0001
IEEE Trans. Mob. Comput.3
2025 Sonicumos: An Enhanced Active Face Liveness Detection System via Ultrasonic and Video Signals
abstract
SONICUMOS is an enhanced behavior-based face liveness detection system that combines ultrasonic and video signals to sense the 3D head gestures. As face authentication becomes increasingly prevalent, the need for a reliable liveness detection system is paramount. Traditional behavior-based liveness detection methods (e.g., eye-blinking, nodding, etc.), which are widely deployed in mission-critical scenarios like finance and banking applications today, are prone to advanced media-based facial forgery attacks. SONICUMOS aims to incorporate the traditional behaviorbased method for active liveness detection without introducing extra user burden. By employing ultrasonic signals, SONICUMOS capitalizes on the head gestures, significantly raising the security bar. Our approach utilizes the frequency-modulated continuouswave (FMCW) ultrasonic radar for robust 3D gesture recognition compatible with face authentication. We also propose a new dual-feature fusion network that integrates audio and video features at the feature level to increase detection accuracy and resilience against numerous attacks. Our prototype has been tested on seven off-the-shelf Android/iOS smartphones, achieving an overall detection accuracy of 95.83% at an equal error rate (EER) of 4.96% when dealing with 3D impersonation attacks
Peipei Jiang 0002, Jianhao Cheng, Lingchen Zhao, Chao Shen 0001, Cong Wang 0001, Qian Wang 0002
IEEE Trans. Mob. Comput.5
2025 AdapLDP-FL: An Adaptive Local Differential Privacy for Federated Learning
abstract
Federated Learning (FL) is a technique that allows multiple participants to co-train machine learning models, while also enhancing privacy by avoiding the exposure of local data. However, it is important to note that despite its effectiveness, there is still a potential risk of leaking users’ private information through weight analysis during FL updates. Local Differential Privacy (LDP) is a technique used to prevent individual information leakage by adding noise to the user's model parameters. However, FL based on LDP lacks dynamic optimization and adaptation considering privacy and data utility, especially regarding noise constraints. This paper investigates FL under the scenario of noise optimization with LDP. Specifically, given a certain privacy budget, we design the adaptive LDP method via a noise scaler, which adaptively optimizes the noise size of every client. Second, we dynamically tailor the model direction after adding noise by the designed a direction matrix, to overcome the model drift problem caused by adding noises to the client model. Finally, our method achieves higher accuracy than some existing works with the same privacy level and the convergence speed is significantly improved.
Gaofeng Yue, Li Yan 0004, Liuwang Kang, Chao Shen 0001
IEEE Trans. Mob. Comput.4
2025 End-to-End Abnormal Subgraph Detection via Subgraph-Level Contrastive Learning
abstract
Abnormal subgraph (AS) detection plays a significant role in ensuring the security of many high-impact domains. Unlike node anomaly detection, identifying subgraph anomalies is extremely challenging due to the exponentially large subgraph space caused by various combinations of nodes and edges. Moreover, in the absence of supervisory signals, how to quantify the abnormality of subgraphs poses another pressing challenge. Traditional methods typically rely on handcrafted subgraph anomaly measures, making it hard to handle potential unknown anomalies with limited prior knowledge. Recent deep learning-based techniques are predominantly designed to discover individual node anomalies, which could be suboptimal for AS detection due to the inconsideration of collaborative behaviors between nodes in the subgraph. In fact, existing studies have put very little effort into this task, and even dedicated performance evaluation metrics are not yet available. To address the above challenges and promote related research, in this article, we propose a end-to-end unsupervised subgraph anomaly detection framework (EndSubG), which jointly models subgraph partition and AS detection as a whole instead of treating them as two separate stages. Specifically, EndSubG uncovers potential AS boundaries that violate the Homophily assumption by modeling the edge existence probability, then achieves anomaly-aware graph embedding and subgraph partition based on the refined topology. By forming a coarsened subgraph network, EndSubG picks out subgraph anomalies by learning the "subgraph-vicinity" matching patterns. Additionally, we design an evaluation metric weighted normalized mutual information centered on AS (AS-WNMI) specifically for subgraph anomaly detection, which is a variant of vanilla NMI and quantifies detection performance from both subgraph partition and anomaly recognition. The experimental results on synthetic and real-world datasets corroborate the superiority of end-to-end unsupervised subgraph anomaly detection framework (EndSubG) in terms of area under the curve (AUC), average precision (AP), and AS-WNMI. We also provide an intuitive analysis of the detected subgraphs through visualization for better understanding.
Zhen Peng 0005, Qika Lin, Bin Shi 0003, Chen Chen 0022, Bo Dong 0001, Chao Shen 0001
IEEE Trans. Neural Networks Learn. Syst.7
2025 DREAM: Debugging and Repairing AutoML Pipelines
abstract
Deep Learning models have become an integrated component of modern software systems. In response to the challenge of model design, researchers proposed Automated Machine Learning (AutoML) systems, which automatically search for model architecture and hyperparameters for a given task. Like other software systems, existing AutoML systems have shortcomings in their design. We identify two common and severe shortcomings in AutoML, performance issue (i.e., searching for the desired model takes an unreasonably long time) and ineffective search issue (i.e., AutoML systems are not able to find an accurate enough model). After analyzing the workflow of AutoML, we observe that existing AutoML systems overlook potential opportunities in search space, search method, and search feedback, which results in performance and ineffective search issues. Based on our analysis, we design and implement DREAM , an automatic and general-purpose tool to alleviate and repair the shortcomings of AutoML pipelines and conduct effective model searches for diverse tasks. It monitors the process of AutoML to collect detailed feedback and automatically repairs shortcomings by expanding search space and leveraging a feedback-driven search strategy. Our evaluation results show that DREAM can be applied on two state-of-the-art AutoML pipelines and effectively and efficiently repair their shortcomings.
Xiaoyu Zhang 0013, Juan Zhai, Shiqing Ma, Xiaohong Guan, Chao Shen 0001
ACM Trans. Softw. Eng. Methodol.5
2025 EVADE: Targeted Adversarial False Data Injection Attacks for State Estimation in Smart Grid
abstract
Although conventional false data injection attacks can circumvent the detection of bad data detection (BDD) in sustainable power grid cyber physical systems, they are easily detected by well-trained deep learning-based detectors. Still, state estimation models with deep leaning-based detectors are not secure due to the vulnerabilities and fragility of deep learning models. Using the related laws of conventional false data injection attacks and adversarial sample attacks, this paper proposes the targEted adVersarial fAlse Data injEction (EVADE) strategy to explore targeted adversarial false data injection attacks for state estimation in Smart Grid. The proposed EVADE attack strategy selects key state variables based on adversarial saliency maps to improve the attack efficiency and perturbs as few state variables as possible to reduce the attack cost. In this way, the EVADE attack strategy can bypass the detection of BDD and neural attack detection (NAD) methods (that is, maintaining deep stealthy) with a high success rate and achieve the attack target simultaneously. Experimental results demonstrate the effectiveness of the proposed strategy, posing serious and pressing concerns for sustainable cyber physical power system security.
Jiwei Tian, Chao Shen 0001, Buhong Wang, Chao Ren 0006, Xiaofang Xia, Runze Dong, Tianhao Cheng
IEEE Trans. Sustain. Comput.2
2025 Unfolded Deep Graph Learning for Networked Over-the-Air Computation
abstract
Over-the-air computation (AirComp) has emerged as a promising technology that enables simultaneous transmission and computation through wireless channels. In this paper, we investigate the networked AirComp in multiple clusters allowing diversified data computation, which is yet challenged by the transceiver coordination and interference management therein. Particularly, we aim to maximize the multi-cluster weighted-sum AirComp rate, where the transmission scalar as well as receive beamforming are jointly investigated while addressing the interference issue. From an optimization perspective, we decompose the formulated problem and adopt the alternating optimization technique with an iterative process to approximate the solution. Then, we reinterpret the iterations through the principle of algorithm unfolding, where the channel condition and mutual interference in the AirComp network constitute an underlying graph. Accordingly, the proposed unfolding architecture learns the weights parameterized by graph neural networks, which is trained through stochastic gradient descent approach. Simulation results show that our proposals outperform the conventional schemes, and the proposed unfolded graph learning substantially alleviates the interference and achieves superior computation performance, with strong and efficient adaptation to the dynamic and scalable networks.
Xiao Tang 0001, Huirong Xiao, Chao Shen 0001, Li Sun 0001, Qinghe Du, Dusit Niyato, Zhu Han 0001
IEEE Trans. Wirel. Commun.3
2024 Dialogue for Prompting: A Policy-Gradient-Based Discrete Prompt Generation for Few-Shot Learning
abstract
Prompt-based pre-trained language models (PLMs) paradigm has succeeded substantially in few-shot natural language processing (NLP) tasks. However, prior discrete prompt optimization methods require expert knowledge to design the base prompt set and identify high-quality prompts, which is costly, inefficient, and subjective. Meanwhile, existing continuous prompt optimization methods improve the performance by learning the ideal prompts through the gradient information of PLMs, whose high computational cost, and low readability and generalizability are often concerning. To address the research gap, we propose a Dialogue-comprised Policy-gradient-based Discrete Prompt Optimization (DP_2O) method. We first design a multi-round dialogue alignment strategy for readability prompt set generation based on GPT-4. Furthermore, we propose an efficient prompt screening metric to identify high-quality prompts with linear complexity. Finally, we construct a reinforcement learning (RL) framework based on policy gradients to match the prompts to inputs optimally. By training a policy network with only 0.62M parameters on the tasks in the few-shot setting, DP_2O outperforms the state-of-the-art (SOTA) method by 1.52% in accuracy on average on four open-source datasets. Moreover, subsequent experiments also demonstrate that DP_2O has good universality, robustness and generalization ability.
Chengzhengxu Li, Xiaoming Liu 0011, Yichen Wang 0002, Duyi Li, Yu Lan 0001, Chao Shen 0001
AAAI6
2024 SlowTrack: Increasing the Latency of Camera-Based Perception in Autonomous Driving Using Adversarial Examples
abstract
In Autonomous Driving (AD), real-time perception is a critical component responsible for detecting surrounding objects to ensure safe driving. While researchers have extensively explored the integrity of AD perception due to its safety and security implications, the aspect of availability (real-time performance) or latency has received limited attention. Existing works on latency-based attack have focused mainly on object detection, i.e., a component in camera-based AD perception, overlooking the entire camera-based AD perception, which hinders them to achieve effective system-level effects, such as vehicle crashes. In this paper, we propose SlowTrack, a novel framework for generating adversarial attacks to increase the execution time of camera-based AD perception. We propose a novel two-stage attack strategy along with the three new loss function designs. Our evaluation is conducted on four popular camera-based AD perception pipelines, and the results demonstrate that SlowTrack significantly outperforms existing latency-based attacks while maintaining comparable imperceptibility levels. Furthermore, we perform the evaluation on Baidu Apollo, an industry-grade full-stack AD system, and LGSVL, a production-grade AD simulator, with two scenarios to compare the system-level effects of SlowTrack and existing attacks. Our evaluation results show that the system-level effects can be significantly improved, i.e., the vehicle crash rate of SlowTrack is around 95% on average while existing works only have around 30%.
Ningfei Wang, Qi Alfred Chen, Chao Shen 0001
AAAI4
2024 Does DetectGPT Fully Utilize Perturbation? Bridging Selective Perturbation to Fine-tuned Contrastive Learning Detector would be Better
abstract
Shengchao Liu, Xiaoming Liu, Yichen Wang, Zehua Cheng, Chengzhengxu Li, Zhaohan Zhang, Yu Lan, Chao Shen. Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2024.
Shengchao Liu, Xiaoming Liu 0011, Yichen Wang 0002, Zehua Cheng, Chengzhengxu Li, Zhaohan Zhang, Yu Lan 0001, Chao Shen 0001
ACL (1)8
2024 Stumbling Blocks: Stress Testing the Robustness of Machine-Generated Text Detectors Under Attacks
abstract
Yichen Wang, Shangbin Feng, Abe Hou, Xiao Pu, Chao Shen, Xiaoming Liu, Yulia Tsvetkov, Tianxing He. Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2024.
Yichen Wang 0002, Shangbin Feng, Abe Bohan Hou, Xiao Pu 0003, Chao Shen 0001, Xiaoming Liu 0001, Yulia Tsvetkov, Tianxing He
ACL (1)5
2024 Zero-Query Adversarial Attack on Black-box Automatic Speech Recognition Systems
abstract
In recent years, extensive research has been conducted on the vulnerability of ASR systems, revealing that black-box adversarial example attacks pose significant threats to real-world ASR systems. However, most existing black-box attacks rely on queries to the target ASRs, which is impractical when queries are not permitted. In this paper, we propose ZQ-Attack, a transfer-based adversarial attack on ASR systems in the zero-query black-box setting. Through a comprehensive review and categorization of modern ASR technologies, we first meticulously select surrogate ASRs of diverse types to generate adversarial examples. Following this, ZQ-Attack initializes the adversarial perturbation with a scaled target command audio, rendering it relatively imperceptible while maintaining effectiveness. Subsequently, to achieve high transferability of adversarial perturbations, we propose a sequential ensemble optimization algorithm, which iteratively optimizes the adversarial perturbation on each surrogate model, leveraging collaborative information from other models. We conduct extensive experiments to evaluate ZQ-Attack. In the over-the-line setting, ZQ-Attack achieves a 100% success rate of attack (SRoA) with an average signal-to-noise ratio (SNR) of 21.91dB on 4 online speech recognition services, and attains an average SRoA of 100% and SNR of 19.67dB on 16 open-source ASRs. In the over-the-air setting, ZQ-Attack also achieves a 100% SRoA with an average SNR of 15.77dB on 2 commercial intelligent voice control devices.
Zheng Fang 0014, Tao Wang 0081, Lingchen Zhao, Shenyi Zhang, Bowen Li 0016, Yunjie Ge, Qi Li 0002, Chao Shen 0001, Qian Wang 0002
CCS8
2024 Physical 3D Adversarial Attacks against Monocular Depth Estimation in Autonomous Driving
abstract
Deep learning-based monocular depth estimation (MDE), extensively applied in autonomous driving, is known to be vulnerable to adversarial attacks. Previous physical attacks against MDE models rely on 2D adversarial patches, so they only affect a small, localized region in the MDE map but fail under various viewpoints. To address these limitations, we propose 3D Depth Fool (3D2Fool), the first 3D texture-based adversarial attack against MDE models. 3D2Fool is specifically optimized to generate 3D adversarial textures agnostic to model types of vehicles and to have improved robustness in bad weather conditions, such as rain and fog. Experimental results validate the superior performance of our 3D2Fool across various scenarios, including vehicles, MDE models, weather conditions, and viewpoints. Real-world experiments with printed 3D textures on physical vehicle models further demonstrate that our 3D2Fool can cause an MDE error of over 10 meters. The code is available at https://github.com/GandolfczjhI3D2Fool.
Junhao Zheng, Chenhao Lin, Zhengyu Zhao 0001, Qian Li 0024, Chao Shen 0001
CVPR6
2024 Toward Evaluating Robustness of Reinforcement Learning with Adversarial Policy
abstract
Reinforcement learning agents are susceptible to evasion attacks during deployment. In single-agent environments, these attacks can occur through imperceptible perturbations injected into the inputs of the victim policy network. In multi-agent environments, an attacker can manipulate an adversarial opponent to influence the victim policy's observations indirectly. While adversarial policies offer a promising technique to craft such attacks, current methods are either sample-inefficient due to poor exploration strategies or require extra surrogate model training under the black-box assumption. To address these challenges, in this paper, we propose Intrinsically Motivated Adversarial Policy (IMAP) for efficient black-box adversarial policy learning in both single- and multi-agent environments. We formulate four types of adversarial intrinsic regularizers—maximizing the adversarial state coverage, policy coverage, risk, or divergence—to discover potential vulnerabilities of the victim policy in a principled way. We also present a novel bias-reduction method to balance the extrinsic objective and the adversarial intrinsic regularizers adaptively. Our experiments validate the effectiveness of the four types of adversarial intrinsic regularizers and the bias-reduction method in enhancing black-box adversarial policy learning across a variety of environments. Our IMAP successfully evades two types of defense methods, adversarial training and robust regularizer, decreasing the performance of the state-of-the-art robust WocaR-PPO agents by 34%-54% across four single-agent tasks. IMAP also achieves a state-of-the-art attacking success rate of 83.91% in the multi-agent game YouShallNotPass. Our code is available at https://github.com/x-zheng16/IMAP.
Xingjun Ma, Xinyu Wang 0007, Chao Shen 0001, Cong Wang 0001
DSN5
2024 Collapse-Aware Triplet Decoupling for Adversarially Robust Image Retrieval
abstract
Adversarial training has achieved substantial performance in defending image retrieval against adversarial examples. However, existing studies in deep metric learning (DML) still suffer from two major limitations: weak adversary and model collapse. In this paper, we address these two limitations by proposing Collapse-Aware TRIplet DEcoupling (CA-TRIDE). Specifically, TRIDE yields a stronger adversary by spatially decoupling the perturbation targets into the anchor and the other candidates. Furthermore, CA prevents the consequential model collapse, based on a novel metric, collapseness, which is incorporated into the optimization of perturbation. We also identify two drawbacks of the existing robustness metric in image retrieval and propose a new metric for a more reasonable robustness evaluation. Extensive experiments on three datasets demonstrate that CA-TRIDE outperforms existing defense methods in both conventional and new metrics. Codes are available at https://github.com/michaeltian108/CA-TRIDE.
Qiwei Tian, Chenhao Lin, Zhengyu Zhao 0001, Qian Li 0024, Chao Shen 0001
ICML5
2024 Speech-Forensics: Towards Comprehensive Synthetic Speech Dataset Establishment and Analysis
Zhoulin Ji, Chenhao Lin, Chao Shen 0001
IJCAI4
2024 Constrained Intrinsic Motivation for Reinforcement Learning
Xingjun Ma, Chao Shen 0001, Cong Wang 0001
IJCAI3
2024 Efficient DNN-Powered Software with Fair Sparse Models
abstract
With the emergence of the Software 3.0 era, there is a growing trend of compressing and integrating large models into software systems, with significant societal implications. Regrettably, in numerous instances, model compression techniques impact the fairness performance of these models and thus the ethical behavior of DNN-powered software. One of the most notable example is the Lottery Ticket Hypothesis (LTH), a prevailing model pruning approach. This paper demonstrates that fairness issue of LTH-based pruning arises from both its subnetwork selection and training procedures, highlighting the inadequacy of existing remedies. To address this, we propose a novel pruning framework, Ballot, which employs a novel conflict-detection-based subnetwork selection to find accurate and fair subnetworks, coupled with a refined training process to attain a high-performance model, thereby improving the fairness of DNN-powered software. By means of this procedure, Ballot improves the fairness of pruning by 38.00%, 33.91%, 17.96%, and 35.82% compared to state-of-the-art baselines, namely Magnitude Pruning, Standard LTH, SafeCompress, and FairScratch respectively, based on our evaluation of five popular datasets and three widely used models. Our code is available at https://anonymous.4open.science/r/Ballot-506E.
Xuanqi Gao, Juan Zhai, Shiqing Ma, Xiaoyu Zhang 0013, Chao Shen 0001
ISSTA6
2024 Concentrate Attention: Towards Domain-Generalizable Prompt Optimization for Language Models
abstract
Recent advances in prompt optimization have notably enhanced the performance of pre-trained language models (PLMs) on downstream tasks. However, the potential of optimized prompts on domain generalization has been under-explored. To explore the nature of prompt generalization on unknown domains, we conduct pilot experiments and find that (i) Prompts gaining more attention weight from PLMs’ deep layers are more generalizable and (ii) Prompts with more stable attention distributions in PLMs’ deep layers are more generalizable. Thus, we offer a fresh objective towards domain-generalizable prompts optimization named ''Concentration'', which represents the ''lookback'' attention from the current decoding token to the prompt tokens, to increase the attention strength on prompts and reduce the fluctuation of attention distribution. We adapt this new objective to popular soft prompt and hard prompt optimization methods, respectively. Extensive experiments demonstrate that our idea improves comparison prompt optimization methods by 1.42% for soft prompt generalization and 2.16% for hard prompt generalization in accuracy on the multi-source domain generalization setting, while maintaining satisfying in-domain performance. The promising results validate the effectiveness of our proposed prompt optimization objective and provide key insights into domain-generalizable prompts.
Chengzhengxu Li, Xiaoming Liu 0011, Zhaohan Zhang, Yichen Wang 0002, Yu Lan 0001, Chao Shen 0001
NeurIPS7
2024 Breaking Semantic Artifacts for Generalized AI-generated Image Detection
abstract
With the continuous evolution of AI-generated images, the generalized detection of them has become a crucial aspect of AI security. Existing detectors have focused on cross-generator generalization, while it remains unexplored whether these detectors can generalize across different image scenes, e.g., images from different datasets with different semantics. In this paper, we reveal that existing detectors suffer from substantial Accuracy drops in such cross-scene generalization. In particular, we attribute their failures to ''semantic artifacts'' in both real and generated images, to which detectors may overfit. To break such ''semantic artifacts'', we propose a simple yet effective approach based on conducting an image patch shuffle and then training an end-to-end patch-based classifier. We conduct a comprehensive open-world evaluation on 31 test sets, covering 7 Generative Adversarial Networks, 18 (variants of) Diffusion Models, and another 6 CNN-based generative models. The results demonstrate that our approach outperforms previous approaches by 2.08\% (absolute) on average regarding cross-scene detection Accuracy. We also notice the superiority of our approach in open-world generalization, with an average Accuracy improvement of 10.59\% (absolute) across all test sets. Our code is available at *https://github.com/Zig-HS/FakeImageDetection*.
Chende Zheng, Chenhao Lin, Zhengyu Zhao 0001, Shuai Liu 0016, Chao Shen 0001
NeurIPS7
2024 Event-Triggered Unified Performance State Estimation for Neural Networks with Time-Varying Delays
abstract
This paper tackles the problem of event-triggered unified performance state estimation in neural networks with time-varying delays. A novel event-triggered methodology is introduced, aiming to balance the performance of the state estimator and the network's communication bandwidth. The proposed method leverages a triggered-parameter-dependent integral inequality with matrices that consider the event-triggered mechanism, capturing the interplay between the time-varying delay and system states. This innovative approach guarantees the asymptotic stability of the estimation error system, thereby meeting the$H$∞ performance criterion. The efficacy of the proposed condition is demonstrated by a numerical example.
Yufeng Tian, Xiaojie Su, Peng Shi 0001, Péter Galambos, Chao Shen 0001, Linsong Zhang
SMC5
2024 Hijacking Attacks against Neural Network by Analyzing Training Data
Yunjie Ge, Qian Wang 0002, Huayang Huang, Qi Li 0002, Cong Wang 0001, Chao Shen 0001, Lingchen Zhao, Peipei Jiang 0002, Zheng Fang 0014, Shenyi Zhang
USENIX Security Symposium6
2024 More Simplicity for Trainers, More Opportunity for Attackers: Black-Box Attacks on Speaker Recognition Systems by Inferring Feature Extractor
Yunjie Ge, Pinji Chen, Qian Wang 0002, Lingchen Zhao, Ningping Mou, Peipei Jiang 0002, Cong Wang 0001, Qi Li 0002, Chao Shen 0001
USENIX Security Symposium9
2024 Fairness in machine learning: definition, testing, debugging, and application
Xuanqi Gao, Chao Shen 0001, Chenhao Lin, Qian Li 0024, Qian Wang 0002, Qi Li 0002, Xiaohong Guan
Sci. China Inf. Sci.2
2024 Adaptive Neural Cooperative Control of Multirobot Systems With Input Quantization
abstract
This article develops the adaptive neural cooperative control scheme for a group of mobile robots with a limited sensing range in presence of input quantization by a dynamic surface control technique. First, to make the controller design feasible, the original robotic system is transformed into a new fully actuated system using a transverse function. Then, taking into consideration the effects of a hysteresis quantizer, an adaptive neural cooperative controller is developed based on the universal approximation property of the radial basis function neural networks and the connectivity preservation strategy. Furthermore, the proposed control scheme can guarantee that all closed-loop signals are semi-globally uniformly ultimately bounded. Meanwhile, desired constraints are not breached and tracking errors are within the predefined domains. Finally, several simulation results are carried out to testify the feasibility and efficiency of the theoretical findings revealed in this article.
Tiedong Ma, Xiaojie Su, Chao Shen 0001
IEEE Trans. Cybern.4
2024 Towards Benchmarking and Evaluating Deepfake Detection
abstract
Deepfake detection automatically recognizes the manipulated media by analyzing whether it contains forgeries generated through deep learning. It is natural to ask which among the existing deepfake detection approaches stand out as top performers. This question is pivotal for identifying promising research directions and offering practical guidance. Unfortunately, conducting a sound benchmark comparison of popular detection approaches based on literature results is challenging due to inconsistent evaluation conditions across studies. In this paper, our objective is to achieve a sound comparison between detection approaches by establishing a comprehensive and consistent benchmark, developing a repeatable evaluation procedure, and performing extensive performance evaluation. Accordingly, a challenging dataset consisting of the manipulated samples generated by more than 12 different methods is collected. Subsequently, we implement and evaluate 13 prominent detection approaches (comprising 11 algorithms) from existing literature, utilizing five fair-minded and practical evaluation metrics. Finally, we provide up to 882 comprehensive evaluations by training 117 detection models. The results, along with the shared data and evaluation methodology, constitute a benchmark for comparing deepfake detection approaches and measuring progress.
Jingyi Deng, Chenhao Lin, Pengbin Hu, Chao Shen 0001, Qian Wang 0002, Qi Li 0002
IEEE Trans. Dependable Secur. Comput.4
2024 KerbNet: A QoE-Aware Kernel-Based Backdoor Attack Framework
abstract
Deep neural networks are vulnerable to backdoor attacks, where a specially-designed trigger will lead to misclassification of any benign samples. However, existing backdoor attacks usually impose conspicuous patch triggers on images, which are easily detected by humans and defense algorithms. Existing works on invisible triggers, however, either have reduced attack success rate or yield detectable patterns to visual inspections. In this paper, we proposeKerbNet, a kernel-based backdoor attack framework, which applies kernel operations to clean samples as the trigger to incur misclassification. The kernel-processed samples achieve a high attack success rate while appearing natural with high Quality-of-Experience (QoE). We carefully design the kernel trigger generation algorithm by exploiting the neural network structure to propagate the influence of the trigger to the target misclassification label under the QoE constraint. We conduct extensive experiments on five datasets, i.e., MNIST, GTSRB, CIFAR-10, CelebA, and ImageNette to evaluate the effectiveness and practicality ofKerbNetunder the impact of various factors, including neuron-residing layer, kernel size, base image, loss function, model structure, and so on. We also show that our proposed attacks can evade state-of-the-art defense strategies and visual inspections. Code will be available after publication.
Xueluan Gong, Yanjiao Chen, Huayang Huang, Weihan Kong, Chao Shen 0001, Qian Wang 0002
IEEE Trans. Dependable Secur. Comput.6
2024 Towards Gradient-Based Saliency Consensus Training for Adversarial Robustness
abstract
In recent works, robust networks have consistently exhibited more discriminative saliency map that proves to indicate sufficient adversarial robustness. In existed safe training paradigms e.g., adversarial training, however, the progressive saliency information regarding on what input semantic feature model prediction relies, have not yet been fully-explored. Due to this, we consider the incorporation of posterior saliency properties of robust model in training, as an efficient supervision signal on robust learning. It thus provides an alternative direction to enhance robustness, from the saliency interpretability perspective. In this article, to harden model we propose to optimize the discrimination of intermediate gradient-based saliency and maintain its consensus in training, which encourage model to behave according to task-relevant feature from the salient region such as object edges in image. Then, we introduce Adversarially Gradient-based Saliency Consensus Training method, dubbedAdv-GSCT. Within it, we preserve the similarity between the learned model saliency and the target one as label, approximated in the most offending case representing the least but essential information scenario. Meanwhile, a constructed pseudo-input coupled with feature importance, is feed into model to ensure the discrimination of estimated target saliency. Besides providing a novel insight into adversarial defense,Adv-GSCTdiffers from the current most effective adversarial training and does not need multiple iterative generations of adversarial perturbation whose computational cost and sensitivity direction of prediction concern. Finally, extensive performance evaluations on MNIST, CIFAR-10 and ImageNet datasets demonstrate the superiority of our proposed method.
Qian Li 0024, Chao Shen 0001, Chenhao Lin, Saiyu Qi
IEEE Trans. Dependable Secur. Comput.2
2024 ChildShield: An Implicit and Continuous Child Identification System on Smartphones
abstract
Smartphone addiction among child users is becoming a severe global social problem. Uncontrolled and unsupervised use of smartphones by children has posed a significant threat to the health and property of both children and their parents. Automatic identification of child users on smartphones can be an effective way to alleviate this problem. Unfortunately, existing works usually require additional input devices like cameras for face biometrics or additional applications for users’ specific touch-interaction behavior to identify child users, leading to poor user experience and privacy concerns. This paper develops a novel, implicit and continuous system, named ChildShield, for child identification on smartphones. Specifically, our system providing a built-in data acquisition service can automatically and real-timely collect users’ behavioral data in a non-conscious and privacy-preserving manner. We build a large-scale database by collecting users’ operations in 5 complex and popular mobile game applications on 12 different models of smartphones from 1875 subjects. Based on the feature extracted from multi-finger interaction data in realistic and complex usage scenarios, ChildShield can learn the discriminative behavioral patterns for accurate child identification using the specifically designed deep learning-based classifiers. Then when a child user is identified, the pre-setting subsequent operation like Enable Kids Mode in ChildShield can be executed to provide a protective shield for children. The effectiveness of ChildShield is validated on the created database. Our approach significantly outperforms existing methods, achieves an EER of 4.38% for child identification, and performs an even lower EER of 2.12% for the younger age group.
Chenhao Lin, Tianle Song, Yingmao Miao, Chao Shen 0001
IEEE Trans. Dependable Secur. Comput.7
2024 LESSON: Multi-Label Adversarial False Data Injection Attack for Deep Learning Locational Detection
abstract
Deep learning methods can not only detect false data injection attacks (FDIA) but also locate attacks of FDIA. Although adversarial false data injection attacks (AFDIA) based on deep learning vulnerabilities have been studied in the field of single-label FDIA detection, the adversarial attack and defense against multi-label FDIA locational detection are still not involved. To bridge this gap, this paper first explores the multi-label adversarial example attacks against multi-label FDIA locational detectors and proposes a general multi-label adversarial attack framework, namely muLti-labEl adverSarial falSe data injectiON attack (LESSON). The proposed LESSON attack framework includes three key designs, namely Perturbing State Variables, Tailored Loss Function Design, and Change of Variables, which can help find suitable multi-label adversarial perturbations within the physical constraints to circumvent both Bad Data Detection (BDD) and Neural Attack Location (NAL). Four typical LESSON attacks based on the proposed framework and two dimensions of attack objectives are examined, and the experimental results demonstrate the effectiveness of the proposed attack framework, posing serious and pressing security concerns in smart grids.
Jiwei Tian, Chao Shen 0001, Buhong Wang, Xiaofang Xia, Meng Zhang 0011, Chenhao Lin, Qian Li 0024
IEEE Trans. Dependable Secur. Comput.2
2024 Attention-SA: Exploiting Model-Approximated Data Semantics for Adversarial Attack
abstract
Adversarial Defense of deep neural networks have gained significant attention and there have been active research efforts on model vulnerabilities for attacking such as gradient-based attack and pre-defined semantic manipulation. However, they often lack clear adversarial pattern connecting model extracted notion and are restricted to fixed constraint, making the gradual inability to proposed robust defense. In this paper, we propose to utilize the learned semantics of model, possibly not be the true one for the correct prediction, as inspiring clue in adversarial example construction. And we propose a new attention-based semantic oriented adversarial attack without any prior constraint about semantic preservation, dubbed Attention-SA from the learned task-related decision factors perspective. Specifically, to capture the learned factor, we introduce a post-hoc soft attention with a gradient-sensitivity activation consistency to probe the information of latent representation that bridge the input and prediction. With the attention guidance, we perturb the separated and semantic units, then back-propagate the variation onto input to discover expanded adversarial examples. Finally, extensive performance evaluations on CIFAR-10 and ImageNet datasets demonstrate the superiority of our proposed method. And we verify the effectiveness of our method on various robust defenses.
Qian Li 0024, Haoran Fan, Chenhao Lin, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.5
2024 Exploiting Facial Relationships and Feature Aggregation for Multi-Face Forgery Detection
abstract
The emergence of advanced Deepfake technologies has gradually raised concerns in society, prompting significant attention to Deepfake detection. However, in real-world scenarios, Deepfakes often involve multiple faces. Despite this, most existing detection methods still detect these faces individually, overlooking the informative correlation between them and the relationship between the global information of the image and the local information of the faces. In this paper, we address this limitation by proposing FILTER, a novel framework for multi-face forgery detection that explicitly captures underlying correlations. FILTER consists of two main modules: Multi-face Relationship Learning (MRL) and Global Feature Aggregation (GFA). Specifically, MRL learns the correlation of local facial features in multi-face images, and GFA constructs the relationship between image-level labels and individual facial features to enhance performance from a global perspective. In particular, a contrastive learning loss function is used to better discriminate between real and fake faces. Extensive experiments on two publicly available multi-face forgery datasets demonstrate the state-of-the-art performance of FILTER in multi-face forgery detection. For example, on Openforensics Test-Challenge dataset, FILTER outperforms the previous state-of-the-art methods with a higher AUC score (0.980) and higher detection accuracy (92.04%).
Chenhao Lin, Fangbin Yi, Jingyi Deng, Zhengyu Zhao 0001, Qian Li 0024, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.7
2024 Exploiting the Adversarial Example Vulnerability of Transfer Learning of Source Code
abstract
State-of-the-art source code classification models exhibit excellent task transferability, in which the source code encoders are first pre-trained on a source domain dataset in a self-supervised manner and then fine-tuned on a supervised downstream dataset. Recent studies reveal that source code models are vulnerable to adversarial examples, which are crafted by applying semantic-preserving transformations that can mislead the prediction of the victim model. While existing research has introduced practical black-box adversarial attacks, these are often designed for transfer-based or query-based scenarios, necessitating access to the victim domain dataset or the query feedback of the victim system. These attack resources are very challenging or expensive to obtain in real-world situations. This paper proposes the cross-domain attack threat model against the transfer learning of source code where the adversary has only access to an open-sourced pre-trained code encoder. To achieve such realistic attacks, this paper designs the Code Transfer learning Adversarial Example (CodeTAE) method. CodeTAE applies various semantic-preserving transformations and utilizes a genetic algorithm to generate powerful identifiers, thereby enhancing the transferability of the generated adversarial examples. Experimental results on three code classification tasks show that the CodeTAE attack can achieve 30%$\sim ~80$% attack success rates under the cross-domain cross-architecture setting. Besides, the generated CodeTAE adversarial examples can be used in adversarial fine-tuning to enhance both the clean accuracy and the robustness of the code model. Our code is available athttps://github.com/yyl-github-1896/CodeTAE/.
Yulong Yang 0002, Haoran Fan, Chenhao Lin, Qian Li 0024, Zhengyu Zhao 0001, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.6
2024 Quantization Aware Attack: Enhancing Transferable Adversarial Attacks by Model Quantization
abstract
Quantized neural networks (QNNs) have received increasing attention in resource-constrained scenarios due to their exceptional generalizability. However, their robustness against realistic black-box adversarial attacks has not been extensively studied. In this scenario, adversarial transferability is pursued across QNNs with different quantization bitwidths, which particularly involve unknown architectures and defense methods. Previous studies claim that transferability is difficult to achieve across QNNs with different bitwidths on the condition that they share the same architecture. However, we discover that under different architectures, transferability can be largely improved by using a QNN quantized with an extremely low bitwidth as the substitute model. We further improve the attack transferability by proposingquantization aware attack(QAA), which fine-tunes a QNN substitute model with a multiple-bitwidth training objective. In particular, we demonstrate that QAA addresses the two issues that are commonly known to hinder transferability: 1) quantization shifts and 2) gradient misalignments. Extensive experimental results validate the high transferability of the QAA to diverse target models. For instance, when adopting the ResNet-34 substitute model on ImageNet, QAA outperforms the current best attack in attacking standardly trained DNNs, adversarially trained DNNs, and QNNs with varied bitwidths by 4.6% ~ 20.9%, 8.8% ~ 13.4%, and 2.6% ~ 11.8% (absolute), respectively. In addition, QAA is efficient since it only takes one epoch for fine-tuning. In the end, we empirically explain the effectiveness of QAA from the view of the loss landscape. Our code is available at https://github.com/yyl-github-1896/QAA/.
Yulong Yang 0002, Chenhao Lin, Qian Li 0024, Zhengyu Zhao 0001, Haoran Fan, Dawei Zhou 0004, Nannan Wang 0001, Tongliang Liu, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.9
2024 Perception-Driven Imperceptible Adversarial Attack Against Decision-Based Black-Box Models
abstract
Adversarial examples (AEs) pose significant threats to deep neural networks (DNNs), as they can deceive models into making incorrect predictions through craftily-designed malicious perturbations. The emergence of decision-based attacks, which rely solely on the top-1 decision label, further increases risks for real-world black-box models. Currently, the prevailing practice for generating effective AEs in decision-based attacks involves penalizing adversarial perturbations using the ℓp-norm. However, this approach often fails to consider the human perception of adversarial perturbations in real-world scenarios. To tackle this issue, we propose a novel and efficient Imperceptible Decision-based Black-box Attack (IDBA). Our method prioritizes optimizing the perception-related distribution of perturbations, rather than solely focusing on the ℓp-norm. Specifically, IDBA analyzes the perceptual preferences of both models and the human vision system, selectively perturbing components that influence model decisions yet remain imperceptible to human eyes. Extensive experiments demonstrate the superior performance of IDBA in both invisibility and query efficiency, a widely used metric in prior works, in comparison to state-of-the-art methods. With only 4.8K queries, IDBA achieves a Feature SIMilarity (FSIM) score of 0.92 while reducing the Learned Perceptual Image Patch Similarity (LPIPS) to 0.12, indicating remarkable imperceptibility.
Shenyi Zhang, Baolin Zheng, Peipei Jiang 0002, Lingchen Zhao, Chao Shen 0001, Qian Wang 0002
IEEE Trans. Inf. Forensics Secur.5
2024 Securing Face Liveness Detection on Mobile Devices Using Unforgeable Lip Motion Patterns
abstract
Face authentication usually utilizes deep learning models to verify users with high accuracy. However, it is vulnerable to various attacks that cheat the models by manipulating the digital counterparts of human faces. So far, lots of liveness detection schemes have been developed to prevent such attacks. Unfortunately, the attacker can still bypass them by constructing sophisticated attacks. We study the security of existing face authentication services and typical liveness detection approaches. Particularly, we develop a new type of attack, i.e., the low-cost 3D projection attack that projects manipulated face videos on a 3D face model, which can easily evade these face authentication services and liveness detection approaches. To this end, we propose FaceLip, a novel face liveness detection scheme on mobile devices, which utilizes lip motion patterns built upon well-designed acoustic signals to enable a strong security guarantee. The unique lip motions for each user are unforgeable because FaceLip verifies the patterns by analyzing acoustic signals that are dynamically generated according to random challenges, which ensures that our signals for liveness detection cannot be manipulated. We prototype FaceLip on off-the-shelf smartphones and conduct extensive experiments under different settings. Our evaluation with 44 participants validates the effectiveness and robustness of FaceLip.
Man Zhou 0004, Qian Wang 0002, Qi Li 0002, Wenyu Zhou, Jingxiao Yang, Chao Shen 0001
IEEE Trans. Mob. Comput.6
2024 Seed Selection for Testing Deep Neural Networks
abstract
Deep learning (DL) has been applied in many applications. Meanwhile, the quality of DL systems is becoming a big concern. To evaluate the quality of DL systems, a number of DL testing techniques have been proposed. To generate test cases, a set of initial seed inputs are required. Existing testing techniques usually construct seed corpus by randomly selecting inputs from training or test dataset. Till now, there is no study on how initial seed inputs affect the performance of DL testing and how to construct an optimal one. To fill this gap, we conduct the first systematic study to evaluate the impact of seed selection strategies on DL testing. Specifically, considering three popular goals of DL testing (i.e., coverage, failure detection, and robustness), we develop five seed selection strategies, including three based on single-objective optimization (SOO) and two based on multi-objective optimization (MOO). We evaluate these strategies on seven testing tools. Our results demonstrate that the selection of initial seed inputs greatly affects the testing performance. SOO-based selection can construct the best seed corpus that can boost DL testing with respect to the specific testing goal. MOO-based selection strategies can construct seed corpus that achieve balanced improvement on multiple objectives.
Yuhan Zhi, Xiaofei Xie, Chao Shen 0001, Jun Sun 0001, Xiaoyu Zhang 0013, Xiaohong Guan
ACM Trans. Softw. Eng. Methodol.3
2023 CoCo: Coherence-Enhanced Machine-Generated Text Detection Under Low Resource With Contrastive Learning
abstract
Machine-Generated Text (MGT) detection, a task that discriminates MGT from Human-Written Text (HWT), plays a crucial role in preventing misuse of text generative models, which excel in mimicking human writing style recently.The latest proposed detectors usually take coarse text sequences as input and finetune pre-trained models with standard crossentropy loss.However, these methods fail to consider the linguistic structure of texts.Moreover, they lack the ability to handle the lowresource problem, which could often happen in practice considering the enormous amount of textual data online.In this paper, we present a coherence-based contrastive learning model named COCO to detect the possible MGT under the low-resource scenario.To exploit the linguistic feature, we encode coherence information in the form of graph into the text representation.To tackle the challenges of low data resources, we employ a contrastive learning framework and propose an improved contrastive loss for preventing performance degradation brought by simple samples.The experiment results on two public datasets and two self-constructed datasets prove our approach outperforms the state-of-the-art methods significantly.Also, we surprisingly find that MGTs originated from up-to-date language models could be easier to detect than these from previous models, in our experiments.And we propose some preliminary explanations for this counter-intuitive phenomena.All the codes and datasets are open-sourced.1
Xiaoming Liu 0011, Zhaohan Zhang, Yichen Wang 0002, Hang Pu, Yu Lan 0001, Chao Shen 0001
EMNLP6
2023 Black-Box Fairness Testing with Shadow Models
Chao Shen 0001, Chenhao Lin, Jingyi Wang 0004, Jun Sun 0001, Xuanqi Gao
ICICS2
2023 Learning Heuristically-Selected and Neurally-Guided Feature for Age Group Recognition Using Unconstrained Smartphone Interaction
abstract
Owing to the boom of smartphone industries, the expansion of phone users has also been significant. Besides adults, children and elders have also begun to join the population of daily smartphone users. Such an expansion indeed facilitates the further exploration of the versatility and flexibility of digitization. However, these new users may also be susceptible to issues such as addiction, fraud, and insufficient accessibility. To fully utilize the capability of mobile devices without breaching personal privacy, we build the first corpus for age group recognition on smartphones with more than 1,445,087 unrestricted actions from 2,100 subjects. Then a series of heuristically-selected and neurally-guided features are proposed to increase the separability of the above dataset. Finally, we develop AgeCare, the first implicit and continuous system incorporated with bottom-to-top functionality without any restriction on user-phone interaction scenarios, for accurate age group recognition and age-tailored assistance on smartphones. Our system performs impressively well on this dataset and significantly surpasses the state-of-the-art methods.
Yingmao Miao, Qiwei Tian, Chenhao Lin, Tianle Song, Shuxin Gao, Chao Shen 0001
IJCAI9
2023 CILIATE: Towards Fairer Class-Based Incremental Learning by Dataset and Training Refinement
abstract
Due to the model aging problem, Deep Neural Networks (DNNs) need updates to adjust them to new data distributions. The common practice leverages incremental learning (IL), e.g., Class-based Incremental Learning (CIL) that updates output labels, to update the model with new data and a limited number of old data. This avoids heavyweight training (from scratch) using conventional methods and saves storage space by reducing the number of old data to store. But it also leads to poor performance in fairness. In this paper, we show that CIL suffers both dataset and algorithm bias problems, and existing solutions can only partially solve the problem. We propose a novel framework, CILIATE, that fixes both dataset and algorithm bias in CIL. It features a novel differential analysis guided dataset and training refinement process that identifies unique and important samples overlooked by existing CIL and enforces the model to learn from them. Through this process, CILIATE improves the fairness of CIL by 17.03%, 22.46%, and 31.79% compared to state-of-the-art methods, iCaRL, BiC, and WA, respectively, based on our evaluation on three popular datasets and widely used ResNet models. Our code is available at https://github.com/Antimony5292/CILIATE.
Xuanqi Gao, Juan Zhai, Shiqing Ma, Chao Shen 0001, Yufei Chen 0001
ISSTA4
2023 DistXplore: Distribution-Guided Testing for Evaluating and Enhancing Deep Learning Systems
abstract
Deep learning (DL) models are trained on sampled data, where the distribution of training data differs from that of real-world data (i.e., the distribution shift), which reduces the model's robustness. Various testing techniques have been proposed, including distribution-unaware and distribution-aware methods. However, distribution-unaware testing lacks effectiveness by not explicitly considering the distribution of test cases and may generate redundant errors (within same distribution). Distribution-aware testing techniques primarily focus on generating test cases that follow the training distribution, missing out-of-distribution data that may also be valid and should be considered in the testing process. In this paper, we propose a novel distribution-guided approach for generating valid test cases with diverse distributions, which can better evaluate the model's robustness (i.e., generating hard-to-detect errors) and enhance the model's robustness (i.e., enriching training data). Unlike existing testing techniques that optimize individual test cases, DistXplore optimizes test suites that represent specific distributions. To evaluate and enhance the model's robustness, we design two metrics: distribution difference, which maximizes the similarity in distribution between two different classes of data to generate hard-to-detect errors, and distribution diversity, which increase the distribution diversity of generated test cases for enhancing the model's robustness. To evaluate the effectiveness of DistXplore in model evaluation and enhancement, we compare DistXplore with 14 state-of-the-art baselines on 10 models across 4 datasets. The evaluation results show that DisXplore not only detects a larger number of errors (e.g., 2×+ on average). Furthermore, DistXplore achieves a higher improvement in empirical robustness (e.g., 5.2% more accuracy improvement than the baselines on average).
Longtian Wang, Xiaofei Xie, Xiaoning Du 0001, Qing Guo 0005, Chao Shen 0001
ESEC/SIGSOFT FSE7
2023 Redeem Myself: Purifying Backdoors in Deep Learning Models using Self Attention Distillation
abstract
Recent works have revealed the vulnerability of deep neural networks to backdoor attacks, where a backdoored model orchestrates targeted or untargeted misclassification when activated by a trigger. A line of purification methods (e.g., fine-pruning, neural attention transfer, MCR [69]) have been proposed to remove the backdoor in a model. However, they either fail to reduce the attack success rate of more advanced backdoor attacks or largely degrade the prediction capacity of the model for clean samples. In this paper, we put forward a new purification defense framework, dubbed SAGE, which utilizes self-attention distillation to purge models of backdoors. Unlike traditional attention transfer mechanisms that require a teacher model to supervise the distillation process, SAGE can realize self-purification with a small number of clean samples. To enhance the defense performance, we further propose a dynamic learning rate adjustment strategy that carefully tracks the prediction accuracy of clean samples to guide the learning rate adjustment. We compare the defense performance of SAGE with 6 state-of-the-art defense approaches against 8 backdoor attacks on 4 datasets. It is shown that SAGE can reduce the attack success rate by as much as 90% with less than 3% decrease in prediction accuracy for clean samples. We will open-source our codes upon publication.
Xueluan Gong, Yanjiao Chen, Qian Wang 0002, Yuzhe Gu, Huayang Huang, Chao Shen 0001
SP7
2023 KENKU: Towards Efficient and Stealthy Black-box Adversarial Attacks against ASR Systems
Xinghui Wu, Shiqing Ma, Chao Shen 0001, Chenhao Lin, Qian Wang 0002, Qi Li 0002, Yuan Rao 0004
USENIX Security Symposium3
2023 NetGuard: Protecting Commercial Web APIs from Model Inversion Attacks using GAN-generated Fake Samples
abstract
Recently more and more cloud service providers (e.g., Microsoft, Google, and Amazon) have commercialized their well-trained deep learning models by providing limited access via web API interfaces. However, it is shown that these APIs are susceptible to model inversion attacks, where attackers can recover the training data with high fidelity, which may cause serious privacy leakage.Existing defenses against model inversion attacks, however, hinder the model performance and are ineffective for more advanced attacks, e.g., Mirror [4]. In this paper, we proposed NetGuard, a novel utility-aware defense methodology against model inversion attacks (MIAs). Unlike previous works that perturb prediction outputs of the victim model, we propose to mislead the MIA effort by inserting engineered fake samples during the training process. A generative adversarial network (GAN) is carefully built to construct fake training samples to mislead the attack model without degrading the performance of the victim model. Besides, we adopt continual learning to further improve the utility of the victim model. Extensive experiments on CelebA, VGG-Face, and VGG-Face2 datasets show that NetGuard is superior to existing defenses, including DP [37] and Ad-mi [32] on state-of-the-art model inversion attacks, i.e., DMI [8], Mirror [4], Privacy [12], and Alignment [34].
Xueluan Gong, Yanjiao Chen, Qian Wang 0002, Cong Wang 0001, Chao Shen 0001
WWW6
2023 Sensitive region-aware black-box adversarial attacks
Chenhao Lin, Sicong Han, Jiongli Zhu, Qian Li 0024, Chao Shen 0001, Xiaohong Guan
Inf. Sci.5
2023 Robust Packetized MPC for Networked Systems Subject to Packet Dropouts and Input Saturation With Quantized Feedback
abstract
This article develops a robust packetized predictive control framework to deal with the quantized-feedback control problem of networked systems subject to Markovian packet dropouts and input saturation. In the proposed framework, the Markov chain model of packet dropout is established from the link of the controller to the actuator. To deal with the quantized measurements, a robust packetized predictive control method is presented with a quantized-feedback law. The problem of unreliable transmission is addressed by proposing a packet dropout compensation strategy with a forgetting factor. An augmented Markovian jump system model is established to take the packet dropouts into account. The synthesis of packetized predictive control is then developed by minimizing a worst case cost function with respect to the model uncertainties. The recursive feasibility of the proposed controller design problem and the mean-square stability of the closed-loop systems are proved, respectively. The proposed packetized predictive control method is demonstrated by simulating a four-tank process system.
Langwen Zhang, Bohui Wang, Yuanshi Zheng, Ali Zemouche, Xudong Zhao 0001, Chao Shen 0001
IEEE Trans. Cybern.6
2023 Kaleidoscope: Physical Backdoor Attacks Against Deep Neural Networks With RGB Filters
abstract
Recent research has shown that deep neural networks are vulnerable to backdoor attacks. A carefully-designed backdoor trigger will mislead the victim model to misclassify any sample with the trigger to the target label. Nevertheless, existing works usually utilize visible triggers, such as a white square at the corner of the image, which are easily detected by human inspections. Current efforts on developing invisible triggers yield low attack success in the physical domain. In this paper, we propose Kaleidoscope, an RGB (red, green, and blue) filter-based backdoor attack method, which utilizes RGB filter operations as the backdoor trigger. To enhance the attack success rate, we design a novel model-dependent filter trigger generation algorithm. We also introduce two constraints in the loss function to make the backdoored samples more natural and less distorted. Extensive experiments on CIFAR-10, CIFAR-100, ImageNette, and VGG-Flower have demonstrated that RGB filter-processed samples not only achieve high attack success rate but also are unnoticeable to humans. It is shown that Kaleidoscope can reach an attack success rate of more than 84% in the physical world under different lighting intensities and shooting angles. Kaleidoscope is also shown to be robust to state-of-the-art backdoor defenses, such as spectral signature, STRIP, and MNTD.
Xueluan Gong, Yanjiao Chen, Meng Xue 0001, Qian Wang 0002, Chao Shen 0001
IEEE Trans. Dependable Secur. Comput.6
2023 Securing Liveness Detection for Voice Authentication via Pop Noises
abstract
Voice authentication has been increasingly adopted for sensitive operations on mobile devices. While voice biometrics can distinguish individuals by their spectral features (such as voiceprints), they are known to be prone to spoofing attacks, where malicious attackers can use pre-recorded or synthesized samples from legitimate users or impersonate the speaking style of the targeted user to deceive the voice authentication system. In this paper, we design and implement a novel software-only anti-spoofing system on smartphones. Our system leverages thepop noise, which is generated by the user’s oral airflow when speaking the passphrase close to the microphone. The pop noise is delicate and subject to user diversity, making it hard to be recorded by replay attacks beyond a certain distance or to be imitated precisely by impersonators. Specifically, we design a new pop noise detection scheme to pinpoint pop noises at the phonemic level, based on which we establish a theoretical model to calculate the sound pressure level from the speech signal in order to get the estimated pressure signal, and then analyze the consistency with the actual pressure signal extracted from the pop noise. Furthermore, we calculate the similarity score of the unique sequences which describe the individually unique relationship between pop noises and phonemes to resist spoofing attacks. Our evaluation on a dataset of 30 participants and three smartphones shows that our system achieves over 94.79% accuracy. Our system requires no additional hardware and is robust to various factors including authentication angle, authentication distance, the length of passphrase, ambient noise, etc.
Peipei Jiang 0002, Qian Wang 0002, Xiu Lin, Man Zhou 0004, Wenbing Ding, Cong Wang 0001, Chao Shen 0001, Qi Li 0002
IEEE Trans. Dependable Secur. Comput.7
2023 Can We Mitigate Backdoor Attack Using Adversarial Detection Methods?
abstract
Deep Neural Networks are well known to be vulnerable to adversarial attacks and backdoor attacks, where minor modifications on the input are able to mislead the models to give wrong results. Although defenses against adversarial attacks have been widely studied, investigation on mitigating backdoor attacks is still at an early stage. It is unknown whether there are any connections and common characteristics between the defenses against these two attacks. We conduct comprehensive studies on the connections between adversarial examples and backdoor examples of Deep Neural Networks to seek to answer the question: can we detect backdoor using adversarial detection methods. Our insights are based on the observation that both adversarial examples and backdoor examples have anomalies during the inference process, highly distinguishable from benign samples. As a result, we revise four existing adversarial defense methods for detecting backdoor examples. Extensive evaluations indicate that these approaches provide reliable protection against backdoor attacks, with a higher accuracy than detecting adversarial examples. These solutions also reveal the relations of adversarial examples, backdoor examples and normal samples in model sensitivity, activation space and feature space. This is able to enhance our understanding about the inherent features of these two attacks and the defense opportunities.
Kaidi Jin, Tianwei Zhang 0004, Chao Shen 0001, Yufei Chen 0001, Ming Fan 0002, Chenhao Lin, Ting Liu 0002
IEEE Trans. Dependable Secur. Comput.3
2023 CrossBehaAuth: Cross-Scenario Behavioral Biometrics Authentication Using Keystroke Dynamics
abstract
Behavioral biometrics has been widely investigated and deployed in real world scenarios for human authentication. However, there has been almost nil attempt to identify behavior patterns in a cross-scenario setting, which is common in practice and needs urgent attention. This paper defines and investigates cross-scenario behavioral biometrics authentication using keystroke dynamics. A novel system called CrossBehaAuth is presented for extending keystroke dynamics-based behavior authentication to new scenarios and extensive problems. We design a temporal-aware learning mechanism based deep neural network for cross-scenario keystroke dynamics authentication. This mechanism selectively learns and encodes temporal information for efficient behavioral pattern transfer in cross-scenario settings. A local Gaussian data augmentation approach is proposed to increase the diversity of behavioral data and therefore, further improve the performance. We evaluate the proposed approach on two publicly available datasets. The extensive experimental results confirm the efficacy of our CrossBehaAuth for cross-scenario keystroke dynamics authentication. Our approach significantly improves the authentication accuracy in cross-scenario settings and even achieves comparable performance on single-scenario authentication tasks. In addition, our approach shows its generalizability and advantages in both single and cross scenario keystroke dynamics authentication.
Chenhao Lin, Chao Shen 0001, Qi Li 0002, Qian Wang 0002
IEEE Trans. Dependable Secur. Comput.3
2023 SoundID: Securing Mobile Two-Factor Authentication via Acoustic Signals
abstract
Mobile two-factor authentication (TFA), which uses mobile devices as a second security layer of protection to online accounts, has been widely applied with the proliferation of mobile phones. Currently, many studies propose to use acoustic fingerprints as the second factor. However, these solutions ignore the variations of the extracted static acoustic fingerprints incurred by the acoustic propagation process, which we show can be leveraged to develop an enhanced man-in-the-middle (MITM) attack to compromise the security strength of these systems, while hiding the traces of the attacking devices. To address this newly-uncovered vulnerability, we propose SoundID, a secure and novel authentication system that introduces a dual challenge-response design through the acoustic signals of the enrolled phone and the login device. Specifically, the enrolled phone first evaluates its proximity to the login device by the similarity of their audio recordings, and then the login authentication server compares the calculated dynamic acoustic fingerprint with the one received from the enrolled phone. To the best of our knowledge, SoundID is the first scheme that extracts dynamic acoustic fingerprints and can effectively defend against the enhanced MITM attack. SoundID combines the benefits of unpredictable influencing factors of acoustic propagation processes and the stable frequency response of the acoustic hardware, whose high complexity prevents attackers from predicting or impersonating them. We build a prototype of SoundID with off-the-shelf smartphones to validate its robustness and effectiveness. Our results show that SoundID is user-friendly and achieves over 96.62% accuracy with an equal error rate around 4.27%.
Qian Wang 0002, Man Zhou 0004, Peipei Jiang 0002, Qi Li 0002, Chao Shen 0001, Cong Wang 0001
IEEE Trans. Dependable Secur. Comput.6
2023 PressPIN: Enabling Secure PIN Authentication on Mobile Devices via Structure-Borne Sounds
abstract
PIN authentication is widely used on mobile devices due to its usability and simplicity. However, it is known to be susceptible to shoulder surfing attacks, where an adversary spies the user’s PIN by direct human observation or camera-based recording. This paper proposes PressPIN, a novel enhanced PIN authenticator on mobile devices by sensing pressures from the user’s finger. Since pressure-sensitive touch screens are unavailable on most phones, we leverage the structure-borne propagation of sounds to estimate the pressure on the screen. When the user inputs the PINs, the pressure is extracted from each number to form the$n$-bit pressure code, where$n$corresponds to the length of the PIN sequence. The pressure code is difficult to be inferred by snooping or videotaping, and increases the entropy of passwords. In this way, PressPIN provides a low-cost, user-friendly, and more secure solution resistant to shoulder surfing attacks. Our extensive experiments with 30 participants and three types of smartphones demonstrate that PressPIN can authenticate legitimate users with high accuracy (e.g., as high as 96.7% within two trials), and is robust to various types of attacks (e.g., only 2.5% attack success rate even when the adversary can observe the legitimate user’s PIN sequence and finger pressing clearly). Additionally, PressPIN requires no additional hardware (e.g., the pressure sensor) and can be readily integrated into existing authentication systems of mobile devices.
Man Zhou 0004, Qian Wang 0002, Xiu Lin, Yi Zhao 0011, Peipei Jiang 0002, Qi Li 0002, Chao Shen 0001, Cong Wang 0001
IEEE Trans. Dependable Secur. Comput.7
2023 Revisiting Gradient Regularization: Inject Robust Saliency-Aware Weight Bias for Adversarial Defense
abstract
Despite regularizing the Jacobians of neural networks to enhance model robustness has directly theoretical correlation with model prediction stability, a large defense performance gap exists when compared to the empirically perturbation-based adversarial training e.g. PGD-based, which enjoys nice discriminative saliency maps as well. To mitigate this issue, in this paper we first analyze the dilemma that the gradient map of its resulting model has no content hierarchy to mark out salient profile of input, as a negative signal of the obstructive for effective adversarial defense. Based on this, we argue that incorporating robust gradient-based saliency properties into regularized training may be helpful to reduce the performance gap. Specifically, we propose a simple method called Saliency-aware Gradient Regularization (SAGR), where a biased weight distribution strategy is introduced on positive gradient to structure and increase the impact of class-gradient components inside the Jacobian of model. The strategy maintains the dominant role of saliency-critical true-class gradient in learning process and differentiates diverse importance of gradient sensitivities that would localize input salient areas. Herein we interpret the sharpness of true-class sensitivity as robust recognition of more learning-relevant features e.g., regions containing dominant object in image for classification. Instead, false-class parts are considered as recognition-irrelevant nuisance factors e.g. the backgrounds, which are thus depressed with more strength. Experimental results demonstrate the efficacy of the proposed method and validate that distinguishment of sensitivities could further yield more robustness gain and sharper gradient saliency map.
Qian Li 0024, Chenhao Lin, Di Wu 0062, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.5
2023 Where Are the Dots: Hardening Face Authentication on Smartphones With Unforgeable Eye Movement Patterns
abstract
With the ubiquitous adoption, mobile face authentication systems have been facing constant security challenges, particularly the spoofing risks. Except for those using specialized hardware, existing proposals for face anti-spoofing on mainstream smartphones either leverage people’s 3D face characteristics or various facial expressions. While showing progress towards more resilient face authentication, they are still vulnerable to recent advanced attacks (e.g., 3D mask attacks, video attacks, etc.). This paper presents GazeGuard, an on-device face anti-spoofing system that leverages unpredictable and unforgeable eye movement patterns to provide strong security guarantees against all known attacks. Targeting mainstream smartphones, GazeGuard is designed to conduct eye movement-based authentication using only 2D front cameras. Specifically, by presenting a series of short-lasting random dots on the screen (named gazecode), GazeGuard simultaneously captures a user’s gaze responses and the corresponding deformed periocular features to ensure both the freshness and correctness for the anti-spoofing face authentication. We have extensively tested GazeGuard’s performance over 50 volunteers. Using a 4-digit gazecode (just four random dots), GazeGuard achieves an average 90.39% authentication accuracy and 81.57 out of 100 System Usability Scale (SUS) scores. Under the same settings, GazeGuard achieves detection accuracy of 95.72% for image attack, 95.59% for video attack, 99.73% for 3D mask attack, and 100% for physical adversarial attack.
Qian Wang 0002, Cong Wang 0001, Man Zhou 0004, Yi Zhao 0011, Qi Li 0002, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.7
2023 Traffic Anomaly Prediction Based on Joint Static-Dynamic Spatio-Temporal Evolutionary Learning
abstract
Accurate traffic anomaly prediction offers an opportunity to save the wounded at the right location in time. However, the complex process of traffic anomaly is affected by both various static factors and dynamic interactions. The recent evolving representation learning provides a new possibility to understand this complicated process, but with challenges of imbalanced data distribution and heterogeneity of features. To tackle these problems, this paper proposes a spatio-temporal evolution model namedSNIPERfor learning intricate feature interactions to predict traffic anomalies. Specifically, we design spatio-temporal encoders to transform spatio-temporal information into vector space indicating their natural relationship. Then, we propose a temporally dynamical evolving embedding method to pay more attention to rare traffic anomalies and develop an effective attention-based multiple graph convolutional network to formulate the spatially mutual influence from three different perspectives. The FC-LSTM is adopted to aggregate the heterogeneous features considering the spatio-temporal influences. Finally, a loss function is designed to overcome the ’over-smoothing’ and solve the imbalanced data problem. Extensive experiments show that SNIPER averagely outperforms state-of-the-arts by 3.9%, 0.9%, 1.9% and 1.6% on Chicago datasets, and 2.4%, 0.6%, 2.6% and 1.3% on New York City datasets in metrics of AUC-PR, AUC-ROC, F1 score, and accuracy, respectively.
Xiaoming Liu 0011, Zhanwei Zhang, Lingjuan Lyu, Zhaohan Zhang, Shuai Xiao 0002, Chao Shen 0001, Philip S. Yu
IEEE Trans. Knowl. Data Eng.6
2022 Verifying the Quality of Outsourced Training on Clouds
Ye Wang 0002, Zhuotao Liu, Ke Xu 0002, Qian Wang 0002, Chao Shen 0001, Qi Li 0002
ESORICS (2)6
2022 Towards Black-Box Adversarial Attacks on Interpretable Deep Learning Systems
abstract
Recent works have empirically shown that neural network interpretability is susceptible to malicious manipulations. However, existing attacks against Interpretable Deep Learning Systems (IDLSes) all focus on the white-box setting, which is obviously unpractical in real-world scenarios. In this paper, we make the first attempt to attack IDLSes in the decision-based black-box setting. We propose a new framework called Dual Black-box Adversarial Attack (DBAA) which can generate adversarial examples that are misclassified as the target class, yet have very similar interpretations to their benign cases. We conduct comprehensive experiments on different combinations of classifiers and interpreters to illustrate the effectiveness of DBAA. Empirical results show that in all the cases, DBAA achieves high attack success rates and Intersection over Union (IoU) scores.
Yike Zhan, Baolin Zheng, Qian Wang 0002, Ningping Mou, Binqing Guo, Qi Li 0002, Chao Shen 0001, Cong Wang 0001
ICME7
2022 Fairneuron: Improving Deep Neural Network Fairness with Adversary Games on Selective Neurons
abstract
With Deep Neural Network (DNN) being integrated into a growing number of critical systems with far-reaching impacts on society, there are increasing concerns on their ethical performance, such as fairness. Unfortunately, model fairness and accuracy in many cases are contradictory goals to optimize during model training. To solve this issue, there has been a number of works trying to improve model fairness by formalizing an adversarial game in the model level. This approach introduces an adversary that evaluates the fairness of a model besides its prediction accuracy on the main task, and performs joint-optimization to achieve a balanced result. In this paper, we noticed that when performing backward propagation based training, such contradictory phenomenon are also observable on individual neuron level. Based on this observation, we propose FairNeuron, a DNN model automatic repairing tool, to mitigate fairness concerns and balance the accuracy-fairness trade-off without introducing another model. It works on detecting neurons with contradictory optimization directions from accuracy and fairness training goals, and achieving a trade-off by selective dropout. Comparing with state-of-the-art methods, our approach is lightweight, scaling to large models and more efficient. Our evaluation on three datasets shows that FairNeuron can effectively improve all models' fairness while maintaining a stable utility.
Xuanqi Gao, Juan Zhai, Shiqing Ma, Chao Shen 0001, Yufei Chen 0001, Qian Wang 0002
ICSE4
2022 Property Inference Attacks Against GANs
Junhao Zhou, Yufei Chen 0001, Chao Shen 0001, Yang Zhang 0016
NDSS3
2022 Amplifying Membership Exposure via Data Poisoning
abstract
As in-the-wild data are increasingly involved in the training stage, machine learning applications become more susceptible to data poisoning attacks. Such attacks typically lead to test-time accuracy degradation or controlled misprediction. In this paper, we investigate the third type of exploitation of data poisoning - increasing the risks of privacy leakage of benign training samples. To this end, we demonstrate a set of data poisoning attacks to amplify the membership exposure of the targeted class. We first propose a generic dirty-label attack for supervised classification algorithms. We then propose an optimization-based clean-label attack in the transfer learning scenario, whereby the poisoning samples are correctly labeled and look "natural" to evade human moderation. We extensively evaluate our attacks on computer vision benchmarks. Our results show that the proposed attacks can substantially increase the membership inference precision with minimum overall test-time model performance degradation. To mitigate the potential negative impacts of our attacks, we also investigate feasible countermeasures.
Yufei Chen 0001, Chao Shen 0001, Cong Wang 0001, Yang Zhang 0016
NeurIPS2
2022 Unify Local and Global Information for Top-N Recommendation
abstract
Knowledge graph (KG), integrating complex information and containing rich semantics, is widely considered as side information to enhance the recommendation systems. However, most of the existing KG-based methods concentrate on encoding the structural information in the graph, without utilizing the collaborative signals in user-item interaction data, which are important for understanding user preferences. Therefore, the representations learned by these models are insufficient for representing semantic information of users and items in the recommendation environment. The combination of both kinds of data provides a good chance to solve this problem, but it faces the following challenges: i) the inner correlations in user-item interaction data are difficult to capture from one side of the user or item; ii) capturing the knowledge associations on the whole KG would introduce noises and variously influence the recommendation results; iii) the semantic gap between both kinds of data is hard to alleviate.
Xiaoming Liu 0011, Shaocong Wu, Zhaohan Zhang, Chao Shen 0001
SIGIR4
2022 Teacher Model Fingerprinting Attacks Against Transfer Learning
Yufei Chen 0001, Chao Shen 0001, Cong Wang 0001, Yang Zhang 0016
USENIX Security Symposium2
2022 RapidPatch: Firmware Hotpatching for Real-Time Embedded Devices
Yi He 0020, Zhenhua Zou, Kun Sun 0001, Zhuotao Liu, Ke Xu 0002, Qian Wang 0002, Chao Shen 0001, Zhi Wang 0004, Qi Li 0002
USENIX Security Symposium7
2022 Infer-AVAE: An attribute inference model based on adversarial variational autoencoder
Zhihao Ding, Xiaoming Liu 0011, Chao Shen 0001, Lingling Tong, Xiaohong Guan
Neurocomputing4
2022 Optimizing Privacy-Preserving Outsourced Convolutional Neural Network Predictions
abstract
Convolutional neural networks (CNN) is a popular architecture in machine learning for its predictive power, notably in computer vision and medical image analysis. Its great predictive power requires extensive computation, which encourages model owners to host the prediction service in a cloud platform. This article proposes a CNN prediction scheme that preserves privacy in the outsourced setting, i.e., the model-hosting server cannot learn the query, (intermediate) results, and the model. Similar to SecureML (S&P’17), a representative work that provides model privacy, we employ two non-colluding servers with secret sharing and triplet generation to minimize the usage of heavyweight cryptography. We made the following optimizations for both overall latency and accuracy. 1) We adopt asynchronous computation and SIMD for offline triplet generation and parallelizable online computation. 2) As MiniONN (CCS’17) and its improvement by the generic EzPC compiler (EuroS&P’19), we use a garbled circuit for the non-polynomial ReLU activation to keep the same accuracy as the underlying network (instead of approximating it in SecureML prediction). 3) For the pooling in CNN, we employ (linear) average-pooling, which achieves almost the same accuracy as the (non-linear, and hence less efficient) max-pooling exhibited by MiniONN and EzPC. Considering both offline and online costs, our experiments on the MNIST dataset show a latency reduction of$122\times$,$14.63\times$, and$36.69\times$compared to SecureML, MiniONN, and EzPC; and a reduction of communication costs by$1.09\times$,$36.69\times$, and$31.32\times$, respectively. On the CIFAR dataset, our scheme achieves a lower latency by$7.14\times$and$3.48\times$and lower communication costs by$13.88\times$and$77.46\times$when compared with MiniONN and EzPC, respectively.
Sherman S. M. Chow, Shengshan Hu, Yuejing Yan, Chao Shen 0001, Qian Wang 0002
IEEE Trans. Dependable Secur. Comput.5
2022 An Automated Multi-Tab Website Fingerprinting Attack
abstract
In Website Fingerprinting (WF) attack, a local passive eavesdropper utilizes network flow information to identify which web pages a user is browsing. Previous researchers have demonstrated the feasibility and effectiveness of WF attacks under a strong Single Page Assumption: the network flow extracted by the adversary belongs to a single web page. In reality, the assumption may not hold because users tend to open multiple tabs simultaneously (or within a short period of time) so that their network traffic is mixed. In this article, we propose an automated multi-tab Website Fingerprinting attack that is able to accurately classify websites regardless of the number of simultaneously opened pages. Our design is powered by two innovative designs. First, we develop a split point classification method to dynamically identify the split point between the first page and its subsequent pages. As a result, the network traffic before the split point is solely generated for the first page. Then, we propose a new chunk-based WF classifier to infer the websites based on the initial chunk of clean traffic. For both classifiers, we apply automated feature selection to select a concise yet representative feature set. We implement a prototype of our design and perform extensive evaluations using SSH and Tor-based datasets to demonstrate the effectiveness of both our system components individually and the integrated system as a whole.
Qilei Yin, Zhuotao Liu, Qi Li 0002, Tao Wang 0012, Qian Wang 0002, Chao Shen 0001, Yixiao Xu
IEEE Trans. Dependable Secur. Comput.6
2022 SEAR: Secure and Efficient Aggregation for Byzantine-Robust Federated Learning
abstract
Federated learning facilitates the collaborative training of a global model among distributed clients without sharing their training data. Secure aggregation, a new security primitive for federated learning, aims to preserve the confidentiality of both local models and training data. Unfortunately, existing secure aggregation solutions fail to defend against Byzantine failures that are common in distributed computing systems. In this work, we propose a new secure and efficient aggregation framework, SEAR, for Byzantine-robust federated learning. Relying on the trusted execution environment, i.e., Intel SGX, SEAR protects clients’ private models while enabling Byzantine resilience. Considering the limitation of the current Intel SGX's architecture (i.e., the limited trusted memory), we propose two data storage modes to efficiently implement aggregation algorithms efficiently in SGX. Moreover, to balance the efficiency and performance of aggregation, we propose a sampling-based method to efficiently detect Byzantine failures without degrading the global model's performance. We implement and evaluate SEAR in a LAN environment, and the experiment results show that SEAR is computationally efficient and robust to Byzantine adversaries. Compared to the previous practical secure aggregation framework, SEAR improves aggregation efficiency by 4-6 times while supporting Byzantine resilience at the same time.
Lingchen Zhao, Jianlin Jiang, Bo Feng 0002, Qian Wang 0002, Chao Shen 0001, Qi Li 0002
IEEE Trans. Dependable Secur. Comput.5
2021 Black-box Adversarial Attacks on Commercial Speech Platforms with Minimal Information
abstract
Adversarial attacks against commercial black-box speech platforms, including cloud speech APIs and voice control devices, have received little attention until recent years. Constructing such attacks is difficult mainly due to the unique characteristics of time-domain speech signals and the much more complex architecture of acoustic systems. The current "black-box" attacks all heavily rely on the knowledge of prediction/confidence scores or other probability information to craft effective adversarial examples (AEs), which can be intuitively defended by service providers without returning these messages. In this paper, we take one more step forward and propose two novel adversarial attacks in more practical and rigorous scenarios. For commercial cloud speech APIs, we propose Occam, a decision-only black-box adversarial attack, where only final decisions are available to the adversary. In Occam, we formulate the decision-only AE generation as a discontinuous large-scale global optimization problem, and solve it by adaptively decomposing this complicated problem into a set of sub-problems and cooperatively optimizing each one. Our Occam is a one-size-fits-all approach, which achieves 100% success rates of attacks (SRoA) with an average SNR of 14.23dB, on a wide range of popular speech and speaker recognition APIs, including Google, Alibaba, Microsoft, Tencent, iFlytek, and Jingdong, outperforming the state-of-the-art black-box attacks. For commercial voice control devices, we propose NI-Occam, the first non-interactive physical adversarial attack, where the adversary does not need to query the oracle and has no access to its internal information and training data. We, for the first time, combine adversarial attacks with model inversion attacks, and thus generate the physically-effective audio AEs with high transferability without any interaction with target devices. Our experimental results show that NI-Occam can successfully fool Apple Siri, Microsoft Cortana, Google Assistant, iFlytek and Amazon Echo with an average SRoA of 52% and SNR of 9.65dB, shedding light on non-interactive physical attacks against voice control devices.
Baolin Zheng, Peipei Jiang 0002, Qian Wang 0002, Qi Li 0002, Chao Shen 0001, Cong Wang 0001, Yunjie Ge, Qingyang Teng, Shenyi Zhang
CCS5
2021 Rethinking Adversarial Examples Exploiting Frequency-Based Analysis
Sicong Han, Chenhao Lin, Chao Shen 0001, Qian Wang 0002
ICICS (2)3
2021 CARTL: Cooperative Adversarially-Robust Transfer Learning
abstract
Transfer learning eases the burden of training a well-performed model from scratch, especially when training data is scarce and computation power is limited. In deep learning, a typical strategy for transfer learning is to freeze the early layers of a pre-trained model and fine-tune the rest of its layers on the target domain. Previous work focuses on the accuracy of the transferred model but neglects the transfer of adversarial robustness. In this work, we first show that transfer learning improves the accuracy on the target domain but degrades the inherited robustness of the target model. To address such a problem, we propose a novel cooperative adversarially-robust transfer learning (CARTL) by pre-training the model via feature distance minimization and fine-tuning the pre-trained model with non-expansive fine-tuning for target domain tasks. Empirical results show that CARTL improves the inherited robustness by about 28% at most compared with the baseline with the same degree of accuracy. Furthermore, we study the relationship between the batch normalization (BN) layers and the robustness in the context of transfer learning, and we reveal that freezing BN layers can further boost the robustness transfer.
Dian Chen 0004, Hongxin Hu, Qian Wang 0002, Yinli Li, Cong Wang 0001, Chao Shen 0001, Qi Li 0002
ICML6
2021 AUTOTRAINER: An Automatic DNN Training Problem Detection and Repair System
abstract
With machine learning models especially Deep Neural Network (DNN) models becoming an integral part of the new intelligent software, new tools to support their engineering process are in high demand. Existing DNN debugging tools are either post-training which wastes a lot of time training a buggy model and requires expertises, or limited on collecting training logs without analyzing the problem not even fixing them. In this paper, we propose AUTOTRAINER, a DNN training monitoring and automatic repairing tool which supports detecting and auto repairing five commonly seen training problems. During training, it periodically checks the training status and detects potential problems. Once a problem is found, AUTOTRAINER tries to fix it by using built-in state-of-the-art solutions. It supports various model structures and input data types, such as Convolutional Neural Networks (CNNs) for image and Recurrent Neural Networks (RNNs) for texts. Our evaluation on 6 datasets, 495 models show that AUTOTRAINER can effectively detect all potential problems with 100% detection rate and no false positives. Among all models with problems, it can fix 97.33% of them, increasing the accuracy by 47.08% on average.
Xiaoyu Zhang 0013, Juan Zhai, Shiqing Ma, Chao Shen 0001
ICSE4
2021 Anti-Distillation Backdoor Attacks: Backdoors Can Really Survive in Knowledge Distillation
abstract
Motivated by resource-limited scenarios, knowledge distillation (KD) has received growing attention, effectively and quickly producing lightweight yet high-performance student models by transferring the dark knowledge from large teacher models. However, many pre-trained teacher models are downloaded from public platforms that lack necessary vetting, posing a possible threat to knowledge distillation tasks. Unfortunately, thus far, there has been little research to consider the backdoor attack from the teacher model into student models in KD, which may pose a severe threat to its wide use. In this paper, we, for the first time, propose a novel Anti-Distillation Backdoor Attack (ADBA), in which the backdoor embedded in the public teacher model can survive the knowledge distillation process and thus be transferred to secret distilled student models. We first introduce a shadow to imitate the distillation process and adopt an optimizable trigger to transfer information to help craft the desired teacher model. Our attack is powerful and effective, which achieves 95.92%, 94.79%, and 90.19% average success rates of attacks (SRoAs) against several different structure student models on MNIST, CIFAR-10, and GTSRB, respectively. Our ADBA also performs robustly under different user distillation environments with 91.72% and 92.37% average SRoAs on MNIST and CIFAR-10, respectively. Finally, we show that the ADBA has a low overhead in the injecting process, which converges on 50 and 70 epochs on CIFAR-10 and GTSRB, respectively, while the normal training epochs of these datasets are almost 200.
Yunjie Ge, Qian Wang 0002, Baolin Zheng, Xinlu Zhuang, Qi Li 0002, Chao Shen 0001, Cong Wang 0001
ACM Multimedia6
2021 An XGBoost-Based Vulnerability Analysis of Smart Grid Cascading Failures under Topology Attacks
abstract
In interconnected industrial control networks like smart grids, topology attacks on physical grids can lead to severe cascading failures and large-scale blackouts. Effective defense on vulnerable devices can significantly reduce the risk of cascading failures and improve overall system robustness. In this paper, we investigate the vulnerability analysis problem from a graph theoretical classification perspective. By calculating a node vulnerability vector composed of features based on complex network theory, node embedding, extended betweenness and power flow distribution, we propose a node vulnerability analysis method based on XGBoost classifier. A cascading failure simulation model based on DC power flow is used to simulate the smart grid behaviours under topology attacks and create the dataset for the XGBoost classifier. The effectiveness of the proposed XGBoost-based method with newly-introduced features is demonstrated by case studies.
Meng Zhang 0011, Shan Fu, Jun Yan 0007, Huiyan Zhang 0001, Chenhao Lin, Chao Shen 0001, Peng Shi 0001
SMC6
2021 A fast and scalable authentication scheme in IOT for smart living
Jianhua Li 0002, Jiong Jin, Lingjuan Lyu, Dong Yuan 0001, Longxiang Gao, Chao Shen 0001
Future Gener. Comput. Syst.7
2021 Payment-Guard: Detecting fraudulent in-app purchases in iOS system
Tianyi Yue, Xiaoming Liu 0011, Chao Shen 0001, Lingling Tong, Zhihao Ding
Neurocomputing4
2021 A Review of Deep Reinforcement Learning for Smart Building Energy Management
abstract
Global buildings account for about 30% of the total energy consumption and carbon emission, raising severe energy and environmental concerns. Therefore, it is significant and urgent to develop novel smart building energy management (SBEM) technologies for the advance of energy efficient and green buildings. However, it is a nontrivial task due to the following challenges. First, it is generally difficult to develop an explicit building thermal dynamics model that is both accurate and efficient enough for building control. Second, there are many uncertain system parameters (e.g., renewable generation output, outdoor temperature, and the number of occupants). Third, there are many spatially and temporally coupled operational constraints. Fourth, building energy optimization problems can not be solved in real time by traditional methods when they have extremely large solution spaces. Fifthly, traditional building energy management methods have respective applicable premises, which means that they have low versatility when confronted with varying building environments. With the rapid development of Internet of Things technology and computation capability, artificial intelligence technology find its significant competence in control and optimization. As a general artificial intelligence technology, deep reinforcement learning (DRL) is promising to address the above challenges. Notably, the recent years have seen the surge of DRL for SBEM. However, there lacks a systematic overview of different DRL methods for SBEM. To fill the gap, this article provides a comprehensive review of DRL for SBEM from the perspective of system scale. In particular, we identify the existing unresolved issues and point out possible future research directions.
Liang Yu 0001, Shuqi Qin, Meng Zhang 0011, Chao Shen 0001, Tao Jiang 0002, Xiaohong Guan
IEEE Internet Things J.4
2021 Defense-Resistant Backdoor Attacks Against Deep Neural Networks in Outsourced Cloud Environment
abstract
The time and monetary costs of training sophisticated deep neural networks are exorbitant, which motivates resource-limited users to outsource the training process to the cloud. Concerning that an untrustworthy cloud service provider may inject backdoors to the returned model, the user can leverage state-of-the-art defense strategies to examine the model. In this paper, we aim to develop robust backdoor attacks (named RobNet) that can evade existing defense strategies from the standpoint of malicious cloud providers. The key rationale is to diversify the triggers and strengthen the model structure so that the backdoor is hard to be detected or removed. To attain this objective, we refine the trigger generation algorithm by selecting the neuron(s) with large weights and activations and then computing the triggers via gradient descent to maximize the value of the selected neuron(s). In stark contrast to existing works that fix the trigger location, we design a multi-location patching method to make the model less sensitive to mild displacement of triggers in real attacks. Furthermore, we extend the attack space by proposing multi-trigger backdoor attacks that can misclassify inputs with different triggers into the same or different target label(s). We evaluate the performance of RobNet on MNIST, GTSRB, and CIFAR-10 datasets, against four representative defense strategies Pruning, NeuralCleanse, Strip, and ABS. The comparison with two state-of-the-art baselines BadNets and Hidden Backdoors demonstrates that RobNet achieves higher attack success rate and is more resistant to potential defenses.
Xueluan Gong, Yanjiao Chen, Qian Wang 0002, Huayang Huang, Lingshuo Meng, Chao Shen 0001, Qian Zhang 0001
IEEE J. Sel. Areas Commun.6
2021 A real-time explainable traffic collision inference framework based on probabilistic graph theory
Xiaoming Liu 0011, Yu Lan 0001, Chao Shen 0001, Xiaohong Guan
Knowl. Based Syst.4
2021 Building In-the-Cloud Network Functions: Security and Privacy Challenges
abstract
Network function virtualization (NFV) has been promising to improve the availability, programmability, and flexibility of network function deployment and communication facilities. Meanwhile, with the advancements of cloud technologies, there has been a trend to outsource network functions through virtualization to a cloud service provider, so as to alleviate the local burdens on provisioning and managing such hardware resources. Promising as it is, redirecting the communication traffic to a third-party service provider has drawn various security and privacy concerns. Traditional end-to-end encryption can protect the traffic in transmit, but it also hinders data usability. This dilemma has raised wide interests from both industry and academia, and great efforts have been made to realize privacy-preserving network function outsourcing that can guarantee the confidentiality of network communications while preserving the ability to inspect the traffic. In this article, we conduct a comprehensive survey of the state-of-the-art literature on network function outsourcing, with a special focus on privacy and security issues. We first give a brief introduction to NFV and pinpoint its challenges and security risks in the cloud context. Then, we present detailed descriptions and comparisons of existing secure network function outsourcing schemes in terms of functionality, efficiency, and security. Finally, we conclude by discussing possible future research directions.
Peipei Jiang 0002, Qian Wang 0002, Muqi Huang, Cong Wang 0001, Qi Li 0002, Chao Shen 0001, Kui Ren 0001
Proc. IEEE6
2021 Scaling Camouflage: Content Disguising Attack Against Computer Vision Applications
abstract
Recently, deep neural networks have achieved state-of-the-art performance in multiple computer vision tasks, and become core parts of computer vision applications. In most of their implementations, a standard input preprocessing component called image scaling is embedded, in order to resize the original data to match the input size of pre-trained neural networks. This article demonstrates content disguising attacks by exploiting the image scaling procedure, which cause machine's extracted content to be dramatically dissimilar with that before scaled. Different from previous adversarial attacks, our attacks happen in the data preprocessing stage, and hence they are not subject to specific machine learning models. To achieve a better deceiving and disguising effect, we propose and implement three feasible attack approaches with L0- and L∞-norm distance metrics. We have conducted a comprehensive evaluation on various image classification applications, including three local demos and two remote proprietary services. We also investigate the attack effects on a YOLO-v3 object detection demo. Our experimental results demonstrate successful content disguising against all of them, which validate our approaches are practical.
Yufei Chen 0001, Chao Shen 0001, Cong Wang 0001, Qixue Xiao, Kang Li 0001, Yu Chen 0004
IEEE Trans. Dependable Secur. Comput.2
2021 Shielding Collaborative Learning: Mitigating Poisoning Attacks Through Client-Side Detection
abstract
Collaborative learning allows multiple clients to train a joint model without sharing their data with each other. Each client performs training locally and then submits the model updates to a central server for aggregation. Since the server has no visibility into the process of generating the updates, collaborative learning is vulnerable to poisoning attacks where a malicious client can generate a poisoned update to introduce backdoor functionality to the joint model. The existing solutions for detecting poisoned updates, however, fail to defend against the recently proposed attacks, especially in the non-IID (independent and identically distributed) setting. In this article, we present a novel defense scheme to detect anomalous updates in both IID and non-IID settings. Our key idea is to realize client-side cross-validation, where each update is evaluated over other clients' local data. The server will adjust the weights of the updates based on the evaluation results when performing aggregation. To adapt to the unbalanced distribution of data in the non-IID setting, a dynamic client allocation mechanism is designed to assign detection tasks to the most suitable clients. During the detection process, we also protect the client-level privacy to prevent malicious clients from knowing the participations of other clients, by integrating differential privacy with our design without degrading the detection performance. Our experimental evaluations on three real-world datasets show that our scheme is significantly robust to two representative poisoning attacks.
Lingchen Zhao, Shengshan Hu, Qian Wang 0002, Jianlin Jiang, Chao Shen 0001, Xiangyang Luo 0001, Pengfei Hu 0001
IEEE Trans. Dependable Secur. Comput.5
2021 Towards Query-Efficient Adversarial Attacks Against Automatic Speech Recognition Systems
abstract
Adversarial attacks, which attract explosive rese- arch attention in recent years, have achieved fantastic success in fooling neural networks, especially for image-classification tasks. While for automatic speech recognition (ASR) tasks, the state-of-the-arts mainly focus on white-box attacks where the adversary is assumed to get full access to the details inside the system, e.g., network architecture, weights, etc. However, this assumption does not hold in practice. The construction of real-world adversarial examples against ASR systems is still a very challenging problem. In this paper, we, for the first time, present a novel and effective attack on ASR systems, named Selective Gradient Estimation Attack (SGEA). Compared with prior literatures, SGEA only needs limited access to the output probabilities of neural networks, and achieves extremely high efficiency and success rates. We attacked the DeepSpeech system on Mozilla Common Voice and LibriSpeech datasets in our experiments. The results demonstrate that SGEA improves the attack success rate from 35% to 98%, while reducing the number of queries by 66%.
Qian Wang 0002, Baolin Zheng, Qi Li 0002, Chao Shen 0001, Zhongjie Ba
IEEE Trans. Inf. Forensics Secur.4
2021 Network-Wide Forwarding Anomaly Detection and Localization in Software Defined Networks
abstract
A crucial requirement for Software Defined Network (SDN) is that data plane forwarding behaviors should always agree with control plane policies. Such requirement cannot be met when there areforwarding anomalies, where packets deviate from the paths specified by the controller. Most anomaly detection methods for SDN install dedicated rules to collect statistics of each flow, and check whether the statistics conform to the “flow conservation principle”. We find these methods have a limited detection scope: they look at one flow each time, thus can only check a small number of flows simultaneously. In addition, dedicated rules for statistics collection can impose a large overhead on flow tables of SDN switches. To this end, this paper presents FOCES, a network-wide forwarding anomaly detection and localization method in SDN. Different from previous methods, FOCES applies a new kind of flow conservation principle at network wide, and can check forwarding behaviors ofallflows in the network simultaneously, without installing any dedicated rules. Finally, FOCES applies a voting-based method to localize malicious switches when anomalies are detected. Experiments with four network topologies show that FOCES can achieve a detection precision higher than 90%, when the packet loss rate is no larger than 10%, and a localization accuracy of around 80% when the packet loss rate is no larger than 5%.
Peng Zhang 0011, Fangzheng Zhang, Shimin Xu, Zuoru Yang, Hao Li 0011, Qi Li 0002, Huanzhao Wang, Chao Shen 0001, Chengchen Hu
IEEE/ACM Trans. Netw.8
2021 VeriML: Enabling Integrity Assurances and Fair Payments for Machine Learning as a Service
abstract
Machine Learning as a Service (MLaaS) allows clients with limited resources to outsource their expensive ML tasks to powerful servers. Despite the huge benefits, current MLaaS solutions still lack strong assurances on: 1) service correctness (i.e., whether the MLaaS works as expected); 2) trustworthy accounting (i.e., whether the bill for the MLaaS resource consumption is correctly accounted); 3) fair payment (i.e., whether a client gets the entire MLaaS result before making the payment). Without these assurances, unfaithful service providers can return improperly-executed ML task results or partially-trained ML models while asking for over-claimed rewards. Moreover, it is hard to argue for wide adoption of MLaaS to both the client and the service provider, especially in the open market without a trusted third party. In this article, we present VeriML, a novel and efficient framework to bring integrity assurances and fair payments to MLaaS. With VeriML, clients can be assured that ML tasks are correctly executed on an untrusted server, and the resource consumption claimed by the service provider equals to the actual workload. We strategically use succinct non-interactive arguments of knowledge (SNARK) on randomly-selected iterations during the ML training phase for efficiency with tunable probabilistic assurance. We also develop multiple ML-specific optimizations to the arithmetic circuit required by SNARK. Our system implements six common algorithms: linear regression, logistic regression, neural network, support vector machine, K-means and decision tree. The experimental results have validated the practical performance of VeriML.
Lingchen Zhao, Qian Wang 0002, Cong Wang 0001, Qi Li 0002, Chao Shen 0001, Bo Feng 0002
IEEE Trans. Parallel Distributed Syst.5
2020 Adversarial Example Detection by Classification for Deep Speech Recognition
abstract
Machine Learning systems are vulnerable to adversarial attacks and will highly likely produce incorrect outputs under these attacks. There are white-box and black-box attacks regarding to adversary's access level to the victim learning algorithm. To defend the learning systems from these attacks, existing methods in the speech domain focus on modifying input signals and testing the behaviours of speech recognizers. We, however, formulate the defense as a classification problem and present a strategy for systematically generating adversarial example datasets: one for white-box attacks and one for black-box attacks, containing both adversarial and normal examples. The white-box attack is a gradient-based method on Baidu DeepSpeech with the Mozilla Common Voice database while the black-box attack is a gradient-free method on a deep model-based keyword spotting system with the Google Speech Command dataset. The generated datasets are used to train a proposed Convolutional Neural Network (CNN), together with cepstral features, to detect adversarial examples. Experimental results show that, it is possible to accurately distinct between adversarial and normal examples for known attacks, in both single-condition and multi-condition training settings, while the performance degrades dramatically for unknown attacks. The adversarial datasets and the source code are made publicly available.
Saeid Samizade, Zheng-Hua Tan, Chao Shen 0001, Xiaohong Guan
ICASSP3
2020 Audee: Automated Testing for Deep Learning Frameworks
abstract
Deep learning (DL) has been applied widely, and the quality of DL system becomes crucial, especially for safety-critical applications. Existing work mainly focuses on the quality analysis of DL models, but lacks attention to the underlying frameworks on which all DL models depend. In this work, we propose Audee, a novel approach for testing DL frameworks and localizing bugs. Audee adopts a search-based approach and implements three different mutation strategies to generate diverse test cases by exploring combinations of model structures, parameters, weights and inputs. Audee is able to detect three types of bugs: logical bugs, crashes and Not-a-Number (NaN) errors. In particular, for logical bugs, Audee adopts a cross-reference check to detect behavioural inconsistencies across multiple frameworks (e.g., TensorFlow and PyTorch), which may indicate potential bugs in their implementations. For NaN errors, Audee adopts a heuristic-based approach to generate DNNs that tend to output outliers (i.e., too large or small values), and these values are likely to produce NaN. Furthermore, Audee leverages a causal-testing based technique to localize layers as well as parameters that cause inconsistencies or bugs. To evaluate the effectiveness of our approach, we applied Audee on testing four DL frameworks, i.e., TensorFlow, PyTorch, CNTK, and Theano. We generate a large number of DNNs which cover 25 widely-used APIs in the four frameworks. The results demonstrate that Audee is effective in detecting inconsistencies, crashes and NaN errors. In total, 26 unique unknown bugs were discovered, and 7 of them have already been confirmed or fixed by the developers.
Xiaofei Xie, Yi Li 0008, Xiaoyu Zhang 0013, Yang Liu 0003, Xiaohong Li 0001, Chao Shen 0001
ASE7
2020 Passive browser identification with multi-scale Convolutional Neural Networks
Saeid Samizade, Chao Shen 0001, Chengxiang Si, Xiaohong Guan
Neurocomputing2
2020 Dissipative Filtering for Switched Fuzzy Systems With Missing Measurements
abstract
This paper investigates the dissipative filtering problem for a class of discrete-time switched fuzzy systems with missing measurements. The fuzzy plant under consideration incorporates characteristics of Takagi-Sugeno fuzzy systems and switched systems simultaneously. The occurrence of missing measurements is described by a stochastic variable that satisfies the Bernoulli binary distribution, which characterizes the effect of data loss in information transmission between the plant and the filter. Utilizing the Lyapunov function technique, sufficient conditions are developed to ensure that the resultant filtering error system is exponentially stable and strictly dissipative. Two simulation examples are presented to illustrate the validity of the proposed method.
Meng Zhang 0011, Chao Shen 0001, Zhengguang Wu, Dan Zhang 0001
IEEE Trans. Cybern.2
2020 Pattern-Growth Based Mining Mouse-Interaction Behavior for an Active User Authentication System
abstract
Analyzing mouse-interaction behaviors for implicitly identifying computer users has received growing interest from security and biometric researchers. This study presents a simple but efficient active user authentication system by modeling mouse-interaction behavior, which is accurate and competent for future deployments. A pattern-growth-based mining method is proposed to extract frequent behavior segments, in obtaining a stable and discriminative representation of mouse-interaction behavior. Then procedural features are extracted to provide an accurate and fine-grained characterization of the behavior segments. A SVM-based decision procedure using one-class learning techniques is applied to the feature space for performing authentication. Analyses are conducted using data from around 1,526,400 mouse operations of 159 participants, and the authentication performance is evaluated across various application scenarios and tasks. Our experimental results show that characteristics from frequent behavior segments are more stable and discriminative than those from holistic behavior, and the system achieves a practically useful level of performance with FAR of 0.09 percent and FRR of 1 percent. Additional experiments on usability to sample length, reliability to application task, scalability to user size, robustness to mimic attack, and response to behavior change are provided to further explore the applicability. We also compare the proposed approach with the state-of-the-art approaches for the collected data.
Chao Shen 0001, Yufei Chen 0001, Xiaohong Guan, Roy A. Maxion
IEEE Trans. Dependable Secur. Comput.1
2020 CoEvil: A Coevolutionary Model for Crime Inference Based on Fuzzy Rough Feature Selection
abstract
Millions of crimes arise each year, which threatens public safety and harms the victims. Precise crime inference is of great significance in preventing crimes. The sharply increasing large-scale heterogeneous data provide a chance to reveal the patterns and trends in crimes. Several approaches employing feature-based regression or spatiotemporal distribution fitting are proposed but lack of some considerations: 1) ignore the dynamic mutual influences among crimes and locations; and 2) overlook the large scale, incompleteness, uncertainty, and vagueness in the heterogeneous data. This article comprehensively investigates the reliability and applicability of proposing a coevolutionary model to formulate the interaction pattern among the crimes and locations and develops a fuzzy-rough-set-based feature selection method to discover the distinctiveness and permanence properties of the crimes and locations with different latent features. Extensive experiments show that our algorithm achieves the mean absolute error of 1.529 (hour) in the crime time inference and the accuracy of 0.653 and 0.633 in the crime type and location inference, which surpass the state of the arts more than 6.5, 1.9, and 1.8 times, respectively. Additional experiments on different parameter settings of our model are provided to further explore its effectiveness and scalability.
Xiaoming Liu 0011, Chao Shen 0001, Wei Wang 0012, Xiaohong Guan
IEEE Trans. Fuzzy Syst.2
2020 Static Output Feedback Control of Switched Nonlinear Systems With Actuator Faults
abstract
This paper is focused on the static output feedback (SOF) control problem for a class of switched nonlinear systems with actuator faults. By means of the Takagi-Sugeno fuzzy model, the switched nonlinear plant is described by a family of switched fuzzy systems. Considering transmission failures may occur between controller and actuator, a reliable SOF controller against actuator faults is designed. Sufficient conditions are developed to guarantee the existence of the reliable SOF controller. Furthermore, an iterative algorithm is designed to determine the controller gains, which avoids the conservatism brought by the traditional singular value decomposition method. To validate the effectiveness of the proposed approach, a numerical example is exploited and simulation results are also presented.
Meng Zhang 0011, Peng Shi 0001, Chao Shen 0001, Zhengguang Wu
IEEE Trans. Fuzzy Syst.3
2020 We Know Who You Are: Discovering Similar Groups Across Multiple Social Networks
abstract
People use various online social networks for different purposes. The user information on each social network is usually partial. Thus, matching the users across these multiple online social networks is of great significance for providing new services as well as new insights on user behaviors. Recent research shows that group structure widely exists on social networks, in which members work together with certain purpose and are more influential than individuals on online social networks. Previous works provide outstanding solutions for mapping individuals, but few ones pay attention to the study of groups across multiple social networks. To address the research gap, we first aim to propose an effective method to detect similar group across multiple social networks. The method mainly has three steps, including detecting group structure based on random walks, extracting similarity features, and inferring group similarity using probabilistic graphical model. We evaluate our algorithm on five different types of online social networks. Experimental results show that our method achieves 0.693, 0.779, 0.729 in precision, recall, and F1-measure, which significantly surpass the state-of-the-art by 31.4%-44.3%, 17.3%-26.3%, and 25.9%-31.6%, respectively. The outstanding performance of our method demonstrates that our proposal can reach the requirement of detecting similar groups across social networks. In particular, the result of this paper paves the way for the recommendation system, link prediction and information diffusion across sites.
Xiaoming Liu 0011, Chao Shen 0001, Xiaohong Guan
IEEE Trans. Syst. Man Cybern. Syst.2
2020 Toward Hand-Dominated Activity Recognition Systems With Wristband-Interaction Behavior Analysis
abstract
The increasing usage of wearable devices for ambulatory monitoring and pervasive computing systems has given rise to the need of convenient and efficient activity recognition techniques. Hand-dominated activity recognition has great potential in understanding users' gesture and providing context-aware computing services. This paper investigates the feasibility and applicability on the usage of wristband-interaction behavior for recognizing hand-dominated activities, with the advantage of great compliance and long wearing time. For each action, sensor data from wristband are analyzed to obtain kinematic sequences. The sequences are then depicted by statistics-, frequency-, and wavelet-domain features for providing accurate and fine-grained characterization of hand-dominated actions, and the correlation between the wristband-sensor features and the actions is analyzed. Classification techniques (Naive Bayes, nearest neighbor, neural network, support vector machine, and Random Forest) are applied to the feature space for performing hand-dominated activity recognition. Analyses are conducted using the data from 51 participants with a diversity in gender, age, weight, and height. Extensive experiments demonstrate the efficacy of the proposed approach, achieving a recognition rate of 97.29% and an F-score above 0.94. Additional experiments on the effect of feature selection and wristband sampling rate are provided to further examine the effectiveness of our approach. Our data are publicly available.
Chao Shen 0001, Yufei Chen 0001, Gengshan Yang, Xiaohong Guan
IEEE Trans. Syst. Man Cybern. Syst.1
2019 Seeing is Not Believing: Camouflage Attacks on Image Scaling Algorithms
Qixue Xiao, Yufei Chen 0001, Chao Shen 0001, Yu Chen 0004, Kang Li 0001
USENIX Security Symposium3
2019 Observer-Based Sliding Mode Control for Uncertain Fuzzy Systems via Event-Triggered Strategy
abstract
This paper investigates the problem of sliding mode observer design for a class of uncertain fuzzy time-delay systems based on an event-triggered strategy. The objective is to design an event-triggered mechanism by utilizing the information of system output and observer function. Based on the delay partitioning method and the Lyapunov-Krasovskii function approach, delaydependent sufficient conditions are proposed to guarantee the overall system, including sliding mode dynamics and error dynamics, to be asymptotically stable with an H∞ performance. Furthermore, an event-triggered sliding mode controller is synthesized to ensure that the system dynamics can be driven to the sliding region near the equilibrium point in finite time. Finally, a verification example is provided to demonstrate the feasibility and efficiency of the theoretical results presented.
Xinxin Liu 0001, Xiaojie Su, Peng Shi 0001, Chao Shen 0001
IEEE Trans. Fuzzy Syst.4
2019 Using Sparse Representation to Detect Anomalies in Complex WSNs
abstract
In recent years, wireless sensor networks (WSNs) have become an active area of research for monitoring physical and environmental conditions. Due to the interdependence of sensors, a functional anomaly in one sensor can cause a functional anomaly in another sensor, which can further lead to the malfunctioning of the entire sensor network. Existing research work has analysed faulty sensor anomalies but fails to show the effectiveness throughout the entire interdependent network system. In this article, a dictionary learning algorithm based on a non-negative constraint is developed, and a sparse representation anomaly node detection method for sensor networks is proposed based on the dictionary learning. Through experiment on a specific thermal power plant in China, we verify the robustness of our proposed method in detecting abnormal nodes against four state of the art approaches and proved our method is more robust. Furthermore, the experiments are conducted on the obtained abnormal nodes to prove the interdependence of multi-layer sensor networks and reveal the conditions and causes of a system crash.
Xiaoming Li 0006, Guangquan Xu, James Xi Zheng, Kaitai Liang, Emmanouil A. Panaousis, Tao Li 0022, Wei Wang 0012, Chao Shen 0001
ACM Trans. Intell. Syst. Technol.8
2019 Digger: Detect Similar Groups in Heterogeneous Social Networks
abstract
People participate in multiple online social networks, e.g., Facebook, Twitter, and Linkedin, and these social networks with heterogeneous social content and user relationship are named as heterogeneous social networks. Group structure widely exists in heterogeneous social networks, which reveals the evolution of human cooperation. Detecting similar groups in heterogeneous networks has a great significance for many applications, such as recommendation system and spammer detection, using the wealth of group information. Although promising, this novel problem encounters a variety of technical challenges, including incomplete data, high time complexity, and ground truth. To address the research gap and technical challenges, we take advantage of a ratio-cut optimization function to model this novel problem by the linear mixed-effects method and graph spectral theory. Based on this model, we propose an efficient algorithm called D igger to detect the similar groups in the large graphs. D igger consists of three steps, including measuring user similarity, construct a matching graph, and detecting similar groups. We adopt several strategies to lower the computational cost and detail the basis of labeling the ground truth. We evaluate the effectiveness and efficiency of our algorithm on five different types of online social networks. The extensive experiments show that our method achieves 0.693, 0.783, and 0.735 in precision, recall, and F1-measure, which significantly surpass the state-of-arts by 24.4%, 15.3%, and 20.7%, respectively. The results demonstrate that our proposal can detect similar groups in heterogeneous networks effectively.
Xiaoming Liu 0011, Chao Shen 0001, Xiaohong Guan
ACM Trans. Knowl. Discov. Data2
2018 DivORAM: Towards a practical oblivious RAM with variable block size
Zheli Liu, Yanyu Huang, Jin Li 0002, Xiaochun Cheng, Chao Shen 0001
Inf. Sci.5
2018 Performance evaluation of implicit smartphones authentication via sensor-behavior analysis
Chao Shen 0001, Yufei Chen 0001, Xiaohong Guan
Inf. Sci.1
2018 Performance Analysis of Multi-Motion Sensor Behavior for Active Smartphone Authentication
abstract
The increasing use of smartphones as personal computing platforms to access personal information has stressed the demand for secure and usable authentication techniques, and for constantly protecting privacy. Smartphone sensors can measure users' unique behavioral characteristics when they interact with smartphones, based on different habits, gestures, and angle preferences of touch actions. This paper investigates the reliability and applicability of using motion-sensor behavior for active and continuous smartphone authentication across various operational scenarios, and presents a systematic evaluation of the distinctiveness and permanence properties of the behavior. For each sample of sensor behavior, kinematic information sequences are extracted and analyzed, which are characterized by statistic-, frequency-, and wavelet-domain features, to provide accurate and fine-grained characterization of users' touch actions. A Markov-based decision procedure, using one-class learning techniques, is developed and applied to the feature space for performing authentication. Analyses are conducted using the sensor data of 520 200 touch actions from 102 subjects across various operational scenarios. Extensive experiments show that motion-sensor behavior exhibits sufficient discriminability and stability for active and continuous authentication, and can achieve a false-rejection rate of 5.03% and a false-acceptance rate of 3.98%. Additional experiments on usability to operation length, sensitivity to application scenario, scalability to user size, contribution to different sensors, and response to behavior change are provided to further explore the effectiveness and applicability. We also implement an authentication system into the Android system that can react to the presence of the legitimate user.
Chao Shen 0001, Yuanxun Li, Yufei Chen 0001, Xiaohong Guan, Roy A. Maxion
IEEE Trans. Inf. Forensics Secur.1
2018 GMM and CNN Hybrid Method for Short Utterance Speaker Recognition
abstract
During the last few years, the speaker recognition technique has been widely attractive for its extensive application in many fields, such as speech communications, domestics services, and smart terminals. As a critical method, the Gaussian mixture model (GMM) makes it possible to achieve the recognition capability that is close to the hearing ability of human in a long speech. However, the GMM is failing to recognize a short utterance speaker with a high accuracy. Aiming at solving this problem, in this paper, we propose a novel model to enhance the recognition accuracy of the short utterance speaker recognition system. Different from traditional models based on the GMM, we design a method to train a convolutional neural network to process spectrograms, which can describe speakers better. Thus, the recognition system gains the considerable accuracy as well as the reasonable convergence speed. The experiment results show that our model can help to decrease the equal error rate of the recognition from 4.9% to 2.5%.
Zheli Liu, Zhendong Wu, Tong Li 0011, Jin Li 0002, Chao Shen 0001
IEEE Trans. Ind. Informatics5
2018 Adaptive Human-Machine Interactive Behavior Analysis With Wrist-Worn Devices for Password Inference
abstract
The pervasiveness of wearable devices furnished with state-of-the-art sensors has shown the powerful capability in context-aware applications. However, embedded sensors also become targets for adversaries to launch potential side-channel attacks. In this paper, we present a self-adaptive and pretraining-independent pattern attack that infers a graphical password by recovering the victim's hand movement trajectory via motion sensors of a wrist-worn smart device. With the adaptive pattern inference algorithm, the discovered attack can be launched remotely without requiring previous training data from victims or the prior knowledge about the keyboard input settings. Toward the proposed attack, we create a method to detect the sliding behavior that draws a graphical password on the screen. We also propose an inference algorithm to generate password candidates from hand movement trajectories for different keypad input settings. We implement the discovered attack on a smartwatch and conduct experiments to evaluate the impact of this attack. The evaluation results show that for complex graphical patterns, with a single try, the attack can infer the passwords at a success rate as high as 80%, and the success rate can be further boosted to over 90% within five attempts, which reveals the overlooked privacy information threat caused by sensor data leakage.
Chao Shen 0001, Yufei Chen 0001, Yao Liu 0007, Xiaohong Guan
IEEE Trans. Neural Networks Learn. Syst.1
2017 A feasible graph partition framework for parallel computing of big graph
Xiaoming Liu 0011, Xiaohong Guan, Chao Shen 0001
Knowl. Based Syst.4
2017 Dependence Guided Symbolic Execution
abstract
Symbolic execution is a powerful technique for systematically exploring the paths of a program and generating the corresponding test inputs. However, its practical usage is often limited by thepath explosionproblem, that is, the number of explored paths usually grows exponentially with the increase of program size. In this paper, we argue that for the purpose of fault detection it is not necessary to systematically explore the paths, and propose a new symbolic execution approach to mitigate the path explosion problem by predicting and eliminating the redundant paths based on symbolic value. Our approach can achieve the equivalent fault detection capability as traditional symbolic execution without exhaustive path exploration. In addition, we develop a practical implementation called Dependence Guided Symbolic Execution (DGSE) to soundly approximate our approach. Through exploiting program dependence, DGSE can predict and eliminate the redundant paths at a reasonable computational cost. Our empirical study shows that the redundant paths are abundant and widespread in a program. Compared with traditional symbolic execution, DGSE only explores 6.96 to 96.57 percent of the paths and achieves a speedup of 1.02$\times$to 49.56$\times$. We have released our tool and the benchmarks used to evaluate DGSE$^\ast$.
Haijun Wang 0002, Ting Liu 0002, Xiaohong Guan, Chao Shen 0001, Zijiang Yang 0006
IEEE Trans. Software Eng.4
2016 Modeling multimodal biometric modalities for continuous user authentication
abstract
Continuous authentication offers the ability to continuously verify users' identity for accessing to the protected resource. Although current explorations such as face and fingerprint verification have seen varying rates of success, three main problems may limit their applicability in the context of information protection and access control: they can be of low availability in some practical scenarios, they can be intrusive, and they commonly require costly equipment. This paper presents a multimodal biometrics authentication system that can continuously verify the presence of a logged-in user. Three passive biometric modalities are currently used - keystroke (i.e., behavioral biometric), face (i.e., physiological biometric), and skin color (i.e., soft biometric) - but our approach can also be readily extended to include more modalities. By fusing these three passive biometrics, the continuous authentication system combines both temporal and modality information holistically, and can keep verifying who is using the computing system, without troubling users' routine activities. Based on real data resulting from our implementation, we find the results to be very promising with a false-acceptance rate of 0% and a false-rejection rate of 0.72%. Additional experiment on the size of observation window is provided to further examine the applicability of the proposed approach.
Chao Shen 0001, Xiaohong Guan
SMC1
2016 User practice in password security: An empirical study of real-life passwords in the wild
Chao Shen 0001, Tianwen Yu, Haodi Xu, Gengshan Yang, Xiaohong Guan
Comput. Secur.1
2016 MouseIdentity: Modeling Mouse-Interaction Behavior for a User Verification System
abstract
Analysis of mouse-interaction behaviors for identifying individual computer users has experienced growing interest from information security and biometric researchers. This paper presents a simple and efficient user verification system by modeling mouse-interaction behavior, which is accurate and competent for future deployment. For each mouse-operation sample, holistic attributes of mouse trajectories are first analyzed using a power transformation method, to derive a schematic representation of behavior eigenspace. Then, a propagation-based segmentation method is developed to model the detailed dynamic process of mouse movements by performing adaptive behavior segmentation and then characterizing each obtained segment using fine-grained procedural motion metrics. Both schematic and procedural cues from mouse-interaction behaviors may be used independently for verification, being fused at the decision level using combination rules. Analyses are conducted using data from 106 subjects with 21 200 mouse-operation samples. The verification system achieves a 1.96% false-rejection rate and a 1.18% false-acceptance rate with a short verification time (about 6 s) and lightweight system overload. Additional experiments on the effect of sample length and subject pool further examine the applicability of our verification system. We also compare the proposed approach with the state-of-the-art approaches for the data collected. Our findings suggest that mouse-interaction behaviors can enhance traditional authentication systems.
Chao Shen 0001, Zhongmin Cai, Xiaohong Guan, Roy A. Maxion
IEEE Trans. Hum. Mach. Syst.1
2016 Performance Analysis of Touch-Interaction Behavior for Active Smartphone Authentication
abstract
The increasing use of touchscreen smartphones to access sensitive and privacy data has given rise to the need of secure and usable authentication technique. Smartphone users have their own unique behavioral characteristics when performing touch operations. These personal characteristics are reflected on different rhythm, strength, and angle preferences of touch-interaction behavior. This paper investigates the reliability and applicability on the usage of users' touch-interaction behavior for active authentication on smartphones. For each common type of touch operations, both static and dynamic features are extracted and analyzed for fine-grained characterization of users' touch behavior. Classification techniques (nearest neighbor, neural network, support vector machine, and random forest) are applied to the feature space for performing the task of active authentication. Analyses are conducted using data from around 134 900 touch operations of 71 participants in real-world scenarios, and the authentication performance is evaluated across various types of touch operations, varying operation lengths, different application tasks, and different application scenarios. The extensive experimental results are included to show that touch-interaction behavior exhibits sufficient discriminability and stability among smartphone users for active authentication, and achieves equal-error rates between 1.72% and 9.01% for different types of touch operations with the operation length of 11; the authentication accuracies improve when having long observation or small timespan between the training and testing phases, and express more reliably and stably in a specific task than in the free task. We also discuss a number of avenues for additional research that we believe are necessary to advance the state-of-the-art in this area.
Chao Shen 0001, Xiaohong Guan, Roy A. Maxion
IEEE Trans. Inf. Forensics Secur.1
2015 Input extraction via motion-sensor behavior analysis on smartphones
Chao Shen 0001, Shichao Pei, Xiaohong Guan
Comput. Secur.1
2015 Abnormal traffic-indexed state estimation: A cyber-physical fusion approach for Smart Grid attack detection
Ting Liu 0002, Yanan Sun 0002, Yang Liu 0090, Yuhong Gui, Dai Wang, Chao Shen 0001
Future Gener. Comput. Syst.7
2014 Performance evaluation of anomaly-detection algorithms for mouse dynamics
Chao Shen 0001, Zhongmin Cai, Xiaohong Guan, Roy A. Maxion
Comput. Secur.1
2014 Mitigating Behavioral Variability for Mouse Dynamics: A Dimensionality-Reduction-Based Approach
abstract
Mouse dynamics is the process of identifying individual users on the basis of their mouse operating behaviors. Mouse dynamics analysis techniques do not provide an acceptable level of accuracy, perhaps due to behavioral variability. This study presents a dimensionality-reduction-based approach to mitigate the behavioral variability of mouse dynamics and improve the performance of mouse-dynamics-based continuous authentication. Variability was measured over the schematic features and motor-skill features extracted from each mouse behavior data session. A unified framework of employing dimensionality reduction methods (Multidimensional Scaling, Laplacian Eigenmap, Isometric Feature Mapping, and Local Linear Embedding) was developed to reduce behavioral variability by obtaining predominant characteristics from the original feature space. Classification techniques (Random Forest, Support Vector Machine, Neural Network, and Nearest Neighbor) were applied to the transformed feature space to perform the authentication task. Analyses were conducted using data from 840 half-hour sessions of 28 participants. Results indicated that for sufficiently long sequences, the transformed feature spaces had much less variability and the corresponding authentication performance was better than the original feature space with improvements of the false-acceptance rate by 89.6% and of the false-rejection rate by 77.4% in some cases. Additionally, an investigation of the relationships between variability and authentication error rates and detection time indicated that the variability and authentication error rates reduce greatly with the increase of detection time. For the data collected, the approach fared better than the state-of-the-art approaches. These findings suggest that variability reduction could improve mouse dynamics, so it may enhance current authentication mechanisms.
Zhongmin Cai, Chao Shen 0001, Xiaohong Guan
IEEE Trans. Hum. Mach. Syst.2
2013 On User Interaction Behavior as Evidence for Computer Forensic Analysis
Chao Shen 0001, Zhongmin Cai, Roy A. Maxion, Xiaohong Guan
IWDW1
2013 User Authentication Through Mouse Dynamics
abstract
Behavior-based user authentication with pointing devices, such as mice or touchpads, has been gaining attention. As an emerging behavioral biometric, mouse dynamics aims to address the authentication problem by verifying computer users on the basis of their mouse operating styles. This paper presents a simple and efficient user authentication approach based on a fixed mouse-operation task. For each sample of the mouse-operation task, both traditional holistic features and newly defined procedural features are extracted for accurate and fine-grained characterization of a user's unique mouse behavior. Distance-measurement and eigenspace-transformation techniques are applied to obtain feature components for efficiently representing the original mouse feature space. Then a one-class learning algorithm is employed in the distance-based feature eigenspace for the authentication task. The approach is evaluated on a dataset of 5550 mouse-operation samples from 37 subjects. Extensive experimental results are included to demonstrate the efficacy of the proposed approach, which achieves a false-acceptance rate of 8.74%, and a false-rejection rate of 7.69% with a corresponding authentication time of 11.8 seconds. Two additional experiments are provided to compare the current approach with other approaches in the literature. Our dataset is publicly available to facilitate future research.
Chao Shen 0001, Zhongmin Cai, Xiaohong Guan, Youtian Du, Roy A. Maxion
IEEE Trans. Inf. Forensics Secur.1
2012 Continuous authentication for mouse dynamics: A pattern-growth approach
abstract
Mouse dynamics is the process of identifying individual users based on their mouse operating characteristics. Although previous work has reported some promising results, mouse dynamics is still a newly emerging technique and has not reached an acceptable level of performance. One of the major reasons is intrinsic behavioral variability. This study presents a novel approach by using pattern-growth-based mining method to extract frequent-behavior segments in obtaining stable mouse characteristics, employing one-class classification algorithms to perform the task of continuous user authentication. Experimental results show that mouse characteristics extracted from frequent-behavior segments are much more stable than those from holistic behavior, and the approach achieves a practically useful level of performance with FAR of 0.37% and FRR of 1.12%. These findings suggest that mouse dynamics suffice to be a significant enhancement for a traditional authentication system. Our dataset is publicly available to facilitate future research.
Chao Shen 0001, Zhongmin Cai, Xiaohong Guan
DSN1
2011 Poster: can it be more practical?: improving mouse dynamics biometric performance
Chao Shen 0001, Zhongmin Cai, Xiaohong Guan
CCS1
2009 Feature Analysis of Mouse Dynamics in Identity Authentication and Monitoring
abstract
Mouse dynamics has recently become an interesting new topic in the area of behavioral biometrics due to its non-intrusiveness and convenience. Some promising results have been shown by previous researches on identity authentication and monitoring using characteristics in users' mouse actions. This paper explores mouse dynamics further by focusing on an important issue not addressed previously: behavioral variability. With an empirical study of long term behaviors of 10 computer users, we show variations are obvious in mouse activities and can have a serious impact if not considered carefully. To tackle the problem of variability, we propose a dimensionality reduction based approach which is demonstrated to be effective in our experiments. More specifically, the classification results after preprocessing by PCA and ISOMAP are shown to be much better than direct classification. Moreover, the results of a false acceptance rate (FAR) 0.55% and false rejection rate (FRR) 3.00% by the nonlinear method ISOMAP are comparable to the best result reported in literature while being subject to more behavioral variability.
Chao Shen 0001, Zhongmin Cai, Xiaohong Guan, Huilan Sha, Jingzi Du
ICC1