Jian Chen 0046

dblp:49/6002-46 · DBLP profile ↗
← Back
12ranked-venue papers
7as first author
11since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 5 first-author · 7 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Breaking the Boundary Barrier: Robust Model Fingerprinting via Unlearnable Examples in Model-Parameter Space
abstract
Deep learning models represent valuable intellectual property due to their high development costs. To protect model ownership, existing fingerprinting techniques have been proposed to use adversarial examples to fingerprint a model's decision boundaries. However, these fingerprints are inherently fragile, as model decision boundaries are highly sensitive to common model modifications such as fine-tuning, pruning, and adversarial training. In this paper, we propose MFUE (Model Fingerprinting via Unlearnable Examples), a novel fingerprinting methodology that leverages the stable unlearnability of unlearnable examples to fingerprint arbitrary modified models in parameter space, fundamentally circumventing the inherent vulnerability of decision boundaries. To achieve robust model fingerprinting in parameter space, we are the first to identify that unlearnable examples, owing to their persistent training resistance, can serve as stable fingerprints beyond the model's decision boundaries. To endow unlearnable examples with robustness against arbitrary model modifications, we introduce adversarial training that simulates the randomness of model modifications by jointly optimizing the unlearnable examples over models at different training stages. We evaluate the performance of MFUE against six different attack types, including both model and input tampering. Through extensive experiments, we demonstrate that MFUE outperforms four existing methods in terms of robustness and uniqueness.
Tianlong Xu, Zixiong Wang, Gaoyang Liu, Jian Chen 0046, Ahmed M. Abdelmoniem, Chen Wang 0011
KDD (1)4
2026 Stealthy Targeted Poisoning Attacks in Vertical Split Learning via Embedding Model Manipulation
abstract
Vertical split learning (VSL) has recently emerged as a novel privacy-preserving paradigm by partitioning a model between multiple clients and a server. Despite its practical utility, recent research has revealed its vulnerability to backdoor attacks, where malicious attackers inject poisoned samples embedded with crafted triggers into the training data. In this paper, we present a stealthyTargetedPoisoningAttack within the context of VSL, termed TPA-VSL, which directly manipulates the embedding model without introducing any obvious trigger patterns. The crux of TPA-VSL is to map the embedding vector of the targeted sample to the attacker-desired class, adversely affecting the targeted sample's prediction. To achieve this, TPA-VSL features two novel components. The first component leverages the conditional generation capability of the state-of-the-art generative models — diffusion models, and uniquely guides them with an integrated multimodal encoder-decoder for informative training data generation. This approach allows us to mimic the target model and obtain the mappings of the targeted sample in the embedding space. The second component effectively poisons the embedding model by aligning the mappings of the targeted samples with those of the attacker-desired class. Experimental results demonstrate that TPA-VSL can achieve a 30% higher attack success rate on average compared to baseline attacks.
Jian Chen 0046, Yufei Kang, Chen Wang 0011, Wanyu Lin
IEEE Trans. Dependable Secur. Comput.1
2025 Backdoor Defense via Enhanced Splitting and Trap Isolation
Hongrui Yu, Wanyu Lin, Jian Chen 0046, Hailong Sun 0001, Chengbin Sun
ICCV4
2025 Unlearning Attacks for Regression Learning
abstract
Recently, the machine unlearning has emerged as a popular method for efficiently erasing the impact of personal data in machine learning (ML) models upon the data owner's removal request. However, few studies take into consideration the security concerns that may exist in the unlearning process. In this article, we propose the first unlearning attack dubbed unlearning attack for regression learning (UnAR) to deliberately influence the predictive behavior of the target sample against regression learning models. The central concept of UnAR revolves around misleading the regression model into erasing the information associated with the influential samples for the target sample. Observing that the influential samples for target data are generally located far away from the regression plane, we thus propose two novel methods, known as influential sample selection (ISS) and influential sample unlearning (ISU), to identify and subsequently eliminate the lineage of the influential samples. By doing so, we can substantially introduce bias into the prediction pertaining to the target sample, yielding the deliberate manipulation for the user adversely. We extensively evaluate UnAR on five public datasets, and the experimental results indicate our attacks can achieve prediction deviations over 35% by unlearning only 0.5% data as the influential samples.
Jian Chen 0046, Wenlong Shi, Wanyu Lin, Chen Wang 0011, Wei Liu 0004, Hailong Sun 0001, Gaoyang Liu
IEEE Trans. Neural Networks Learn. Syst.1
2024 Manipulating Pre-Trained Encoder for Targeted Poisoning Attacks in Contrastive Learning
abstract
In recent years, contrastive learning has become very powerful for representation learning using large-scale unlabeled data, by involving pre-trained encoders to fine-tune downstream classifiers. However, the latest research indicates that contrastive learning can potentially suffer from the risks of data poisoning attacks, where the attacker injects maliciously crafted poisoned samples into the unlabeled pre-training data. To step forward, in this paper, we present a more stealthy poisoning attack dubbed PA-CL to directly poison the pre-trained encoder, such that the downstream classifier’s behavior on a single target instance to the attacker-desired class can be manipulated without affecting the overall downstream classification performance. We observe that a high similarity exists between the feature representation generated by the poisoned pre-trained encoder for the target sample and samples from the attacker-desired class. This leads to the downstream classifier misclassifying the target sample with the attacker-desired class. Therefore, we formulate our attack as an optimization problem, and design two novel loss functions, namely, the target effectiveness loss to effectively poison the pre-trained encoder, and the model utility loss to maintain the downstream classification performance. Experimental results on four real-world datasets demonstrate that the attack success rate of the proposed attack is 40% higher on average than that of the three baseline attacks, and the fluctuation of the downstream classifier’s prediction accuracy is within 5%.
Jian Chen 0046, Gaoyang Liu, Ahmed M. Abdelmoniem, Chen Wang 0011
IEEE Trans. Inf. Forensics Secur.1
2023 Class-Targeted Poisoning Attacks against DNNs
abstract
In recent years, the emergence of targeted cleanlabel poisoning attacks, which maliciously influence the training data without controlling over the labeling process to manipulate the behavior of the predictive model, is shown to be crucial threats to compromise deep learning systems. Prior targeted clean-label poisoning attacks have been demonstrated to target only one sample at a time, which is not always applicable in restricted real-world situations. In this paper, we explore targeted clean-label poisoning attacks on a per-class basis, which refers to misclassify samples from a victim class to the desired class while maintaining the classification accuracy of samples on other classes in multi-class classification tasks. To achieve this, we present the first class-targeted clean-label poisoning attack, called CTCL, which firsts craft clean label poisons along with multiple directions in the target feature space and enhance the attacking capability of poisons by reducing their the feature information of the target class. We illustrate the effectiveness of the proposed CTCL on various deep neural network models. The experiment results demonstrate that our attack is effective, with the attacking success rate over 80% compared to the other two baseline attacks on average, while the detection accuracy of state-of-the-art defenses is lower than 65% illustrating that CTCL can escape the detection of existing defenses readily.
Jian Chen 0046, Qiang Li 0009, Wensheng Zhang 0004, Chen Wang 0011
TrustCom1
2023 TEAR: Exploring Temporal Evolution of Adversarial Robustness for Membership Inference Attacks Against Federated Learning
abstract
Federated learning (FL) is a privacy-preserving machine learning paradigm that enables multiple clients to train a unified model without disclosing their private data. However, susceptibility to membership inference attacks (MIAs) arises due to the natural inclination of FL models to overfit on the training data during the training process, thereby enabling MIAs to exploit the subtle differences in the FL model’s parameters, activations, or predictions between the training and testing data to infer membership information. It is worth noting that most if not all existing MIAs against FL require access to the model’s internal information or modification of the training process, yielding them unlikely to be performed in practice. In this paper, we present with TEAR the first evidence that it is possible for an honest-but-curious federated client to perform MIA against an FL system, by exploring the Temporal Evolution of the Adversarial Robustness between the training and non-training data. We design a novel adversarial example generation method to quantify the target sample’s adversarial robustness, which can be utilized to obtain the membership features to train the inference model in a supervised manner. Extensive experiment results on five realistic datasets demonstrate that TEAR can achieve a strong inference performance compared with two existing MIAs, and is able to escape from the protection of two representative defenses.
Gaoyang Liu, Zehao Tian, Jian Chen 0046, Chen Wang 0011, Jiangchuan Liu
IEEE Trans. Inf. Forensics Secur.3
2023 Manipulating Supply Chain Demand Forecasting With Targeted Poisoning Attacks
abstract
Demand forecasting (DF) plays an essential role in supply chain management, as it provides an estimate of the goods that customers are expected to purchase in the foreseeable future. While machine learning techniques are widely used for building DF models, they also become more susceptible to data poisoning attacks. In this article, we study the vulnerability of targeted poisoning attacks for linear regression DF models, where the attacker controls the behavior of forecasting models on a specific target sample without compromising the overall forecasting performance. We devise a gradient-optimization framework for targeted regression poisoning in white-box settings, and further design a regression value manipulation strategy for targeted poisoning in black-box settings. We also discuss some possible countermeasures to defend against our attacks. Extensive experiments are conducted on two real-world datasets with four linear regression models. The results demonstrate that our attacks are very effective, and can achieve a high prediction deviation with control of less than 1% of the training samples.
Jian Chen 0046, Jinyong Shan, Kai Peng 0001, Chen Wang 0011, Hongbo Jiang 0001
IEEE Trans. Ind. Informatics1
2022 Leveraging Model Poisoning Attacks on License Plate Recognition Systems
abstract
Computer vision-based license plate recognition (LPR) has been widely deployed for automatic vehicle identity inspection due to the offered convenience and efficiency. However, the practical LPR systems are potentially vulnerable to malicious attacks, which may lead to incorrect recognition and impact the safety of transportation. Previous studies of attacking strategies targeting LPR systems mainly focused on evasion attacks, which are less efficient than model poisoning attacks that can cause mis-classification through directly manipulating the parameters of the victim model other than perturbing each testing sample. To fill this gap, we conduct the first systematic study on the vulnerability of LPR systems against model poisoning attacks. In specific, we aim to compromise the integrity of the model training such that the attacked LPR system would mis-classify all the samples from the victim class to the attacker-chosen class. To achieve this, we fine-tune the feature extractor layers of the LPR model such that it can obtain similar feature representations given samples belong to victim and attacker-chosen classes. This is implemented in a generator-discriminator fashion, where a discriminator learns to classify the victim and attacker-chosen classes given the input samples. Subsequently, the feature extractor is fine-tuned to generate manipulated features that can confuse the discriminator. Our empirical results on the CCPD dataset demonstrate that the proposed attacking strategy can substantially compromise LPR systems with high success rates.
Jian Chen 0046, Yang Liu 0064, Chen Wang 0011, Kai Peng 0001
TrustCom1
2021 De-Pois: An Attack-Agnostic Defense against Data Poisoning Attacks
abstract
Machine learning techniques have been widely applied to various applications. However, they are potentially vulnerable to data poisoning attacks, where sophisticated attackers can disrupt the learning procedure by injecting a fraction of malicious samples into the training dataset. Existing defense techniques against poisoning attacks are largely attack-specific: they are designed for one specific type of attacks but do not work for other types, mainly due to the distinct principles they follow. Yet few general defense strategies have been developed. In this paper, we propose De-Pois, an attack-agnostic defense against poisoning attacks. The key idea of De-Pois is to train a mimic model the purpose of which is to imitate the behavior of the target model trained by clean samples. We take advantage of Generative Adversarial Networks (GANs) to facilitate informative training data augmentation as well as the mimic model construction. By comparing the prediction differences between the mimic model and the target model, De-Pois is thus able to distinguish the poisoned samples from clean ones, without explicit knowledge of any ML algorithms or types of poisoning attacks. We implement four types of poisoning attacks and evaluate De-Pois with five typical defense methods on different realistic datasets. The results demonstrate that De-Pois is effective and efficient for detecting poisoned data against all the four types of poisoning attacks, with both the accuracy and F1-score over 0.9 on average.
Jian Chen 0046, Xuxin Zhang, Rui Zhang 0066, Chen Wang 0011, Ling Liu 0001
IEEE Trans. Inf. Forensics Secur.1
2021 Attacking Recommender Systems With Plausible Profile
abstract
Recommender systems (RS) have become an essential component of web services due to their excellent performance. Despite their great success, RS have proved to be vulnerable to data poisoning attacks, which inject well-crafted fake profiles into RS, so that the target items can be maliciously recommended. In this paper, we first reveal that existing poisoning attacks in RS can be detected effortlessly, as the features of the generated fake profiles cannot be inconsistent with those of normal profiles all the time. We further propose RecUP, a poisoning attack in RS that can generate plausible profiles whose features stay almost the same as the normal ones, based on Generative Adversarial Networks (GAN). To tailor GAN for poisoning in RS, we develop HRGAN and devise a loss function to guide the training of the generator, along with a masking operation with selected potentially powerful profiles, so that the final generated profiles can perform malicious recommendations as expected. Evaluations against various defense methods using three real-world datasets show that, RecUP can generate the most plausible profiles while maintaining comparable attacking performance compared with state-of-the-art attacks.
Xuxin Zhang, Jian Chen 0046, Rui Zhang 0066, Chen Wang 0011, Ling Liu 0001
IEEE Trans. Inf. Forensics Secur.2
2004 UNM: an architecture of the universal policy-based network measurement system
abstract
The concept of universal network measurement environment (UNME) is proposed, which includes three entities, i.e., the name server, the monitoring center and the probe. The architecture that the entities follow is called the universal network measurement (UNM), which consists of three layers. The key technologies such as component management protocol, network measurement policy protocol and the network measurement cooperative layer are explored and the construction of the probe and the method how to change measurement tools into the UNM probes are introduced. Finally, a real network monitoring & measurement system following UNM is illustrated, and several network measurement applications built on it are introduced.
Rui Zhang 0066, Lihua Song, Jian Chen 0046
LANMAN5