Min Chen 0032

dblp:50/6996-32 · DBLP profile ↗
← Back
17ranked-venue papers
3as first author
17since 2021 · last 2026
0000-0002-1128-7989ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 15 · 3 first-author · 15 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 PrivATE: Differentially Private Average Treatment Effect Estimation for Observational Data
Linkang Du, Min Chen 0032, Yunjun Gao, Shibo He, Jiming Chen 0001, Zhikun Zhang 0001
NDSS4
2026 VICTOR: Dataset Copyright Auditing in Video Recognition Systems
Zhikun Zhang 0001, Linkang Du, Min Chen 0032, Yunjun Gao, Shibo He, Jiming Chen 0001
NDSS4
2026 Revealing the Risk of Hyper-Parameter Leakage in Deep Reinforcement Learning Models
abstract
Deep reinforcement learning (DRL) has been implemented across various critical applications, including smart grids, trac management systems, and autonomous vehicles. To safeguard intellectual property and mitigate security vulnerabilities, access to DRL models is typically restricted to a black-box format. is means specic details like the structure of the policy network and optimization processes are not openly available to users. It is crucial to determine if the hyper-parameters can be inferred from observable states and actions within these models, presenting two primary challenges: 1) limited data available from the black-box model and 2) the intertwined eects of hyperparameters on the model's behavior. Since DRL models exhibit varying behaviors in identical tasks depending on their hyper-parameter congurations, we introduce a novel hyper-parameter inference attack against DRL, named HyperInfer, which allows adversaries to deduce the settings of a black-box DRL model. In order to fully assess the risk of model hyper-parameter leakage, we design two novel state generation methods that provoke divergent responses from DRL models. We also develop an inference framework to elucidate the relationship between model behavior and hyper-parameter settings. rough comprehensive experiments involving multiple DRL models and environments, we demonstrate that model behaviors can indeed reveal hyper-parameter settings, with inference accuracy surpassing 90% in scenarios such as PPO with CartPole. We also discuss keyndings relevant to practical applications and explore how knowledge of hyperparameters can facilitate more sophisticated attacks. Lastly, we propose potential defensive strategies to minimize the risk of hyper-parameter leakage in DRL models.
Linkang Du, Zhikun Zhang 0001, Min Chen 0032, Shouling Ji, Peng Cheng 0001, Jiming Chen 0001, Michael Backes 0001, Yang Zhang 0016
IEEE Trans. Dependable Secur. Comput.3
2025 SoK: Dataset Copyright Auditing in Machine Learning Systems
abstract
As the implementation of machine learning (ML) systems becomes more widespread, especially with the introduction of larger ML models, we perceive a spring demand for massive data. However, it inevitably causes infringement and misuse problems with the data, such as using unauthorized online artworks or face images to train ML models. To address this problem, many efforts have been made to audit the copyright of the model training dataset. However, existing solutions vary in auditing assumptions and capabilities, making it difficult to compare their strengths and weaknesses. In addition, robustness evaluations usually consider only part of the ML pipeline and hardly reflect the performance of algorithms in real-world ML applications. Thus, it is essential to take a practical deployment perspective on the current dataset copyright auditing tools, examining their effectiveness and limitations. Concretely, we categorize dataset copyright auditing research into two prominent strands: intrusive methods and non-intrusive methods, depending on whether they require modifications to the original dataset. Then, we break down the intrusive methods into different watermark injection options and examine the non-intrusive methods using various finger-prints. To summarize our results, we offer detailed reference tables, highlight key points, and pinpoint unresolved issues in the current literature. By combining the pipeline in ML systems and analyzing previous studies, we highlight several future directions to make auditing tools more suitable for real-world copyright protection requirements.
Linkang Du, Xuanru Zhou, Min Chen 0032, Chusong Zhang, Zhou Su 0001, Peng Cheng 0001, Jiming Chen 0001, Zhikun Zhang 0001
SP3
2025 GradEscape: A Gradient-Based Evader Against AI-Generated Text Detectors
Wenlong Meng, Shuguo Fan, Chengkun Wei, Min Chen 0032, Yuwei Li 0002, Zhikun Zhang 0001, Wenzhi Chen
USENIX Security Symposium4
2025 ArtistAuditor: Auditing Artist Style Pirate in Text-to-Image Generation Models
abstract
Text-to-image models based on diffusion processes, such as DALL-E, Stable Diffusion, and Midjourney, are capable of transforming texts into detailed images and have widespread applications in art and design. As such, amateur users can easily imitate professional-level paintings by collecting an artist's work and fine-tuning the model, leading to concerns about artworks' copyright infringement. To tackle these issues, previous studies either add visually imperceptible perturbation to the artwork to change its underlying styles (perturbation-based methods) or embed post-training detectable watermarks in the artwork (watermark-based methods). However, when the artwork or the model has been published online, i.e., modification to the original artwork or model retraining is not feasible, these strategies might not be viable.
Linkang Du, Min Chen 0032, Zhou Su 0001, Shouling Ji, Peng Cheng 0001, Jiming Chen 0001, Zhikun Zhang 0001
WWW3
2024 PARL: Poisoning Attacks Against Reinforcement Learning-based Recommender Systems
abstract
Recommender systems predict and suggest relevant options to users in various domains, such as e-commerce, streaming services, and social media. Recently, deep reinforcement learning (DRL)-based recommendation systems have become increasingly popular in academics and industry since DRL can characterize the long-term interaction between the system and users to achieve a better recommendation experience, e.g., Netflix, Spotify, Google, and YouTube.
Linkang Du, Min Chen 0032, Peng Cheng 0001, Jiming Chen 0001, Zhikun Zhang 0001
AsiaCCS3
2024 ORL-AUDITOR: Dataset Auditing in Offline Deep Reinforcement Learning
Linkang Du, Min Chen 0032, Shouling Ji, Peng Cheng 0001, Jiming Chen 0001, Zhikun Zhang 0001
NDSS2
2024 LMSanitator: Defending Prompt-Tuning Against Task-Agnostic Backdoors
Chengkun Wei, Wenlong Meng, Zhikun Zhang 0001, Min Chen 0032, Minghu Zhao, Wenjing Fang, Lei Wang 0152, Wenzhi Chen
NDSS4
2023 DPMLBench: Holistic Evaluation of Differentially Private Machine Learning
abstract
Differential privacy (DP), as a rigorous mathematical definition quantifying privacy leakage, has become a well-accepted standard for privacy protection. Combined with powerful machine learning (ML) techniques, differentially private machine learning (DPML) is increasingly important. As the most classic DPML algorithm, DP-SGD incurs a significant loss of utility, which hinders DPML's deployment in practice. Many studies have recently proposed improved algorithms based on DP-SGD to mitigate utility loss. However, these studies are isolated and cannot comprehensively measure the performance of improvements proposed in algorithms. More importantly, there is a lack of comprehensive research to compare improvements in these DPML algorithms across utility, defensive capabilities, and generalizability.
Chengkun Wei, Minghu Zhao, Zhikun Zhang 0001, Min Chen 0032, Wenlong Meng, Wenzhi Chen
CCS4
2023 Making Watermark Survive Model Extraction Attacks in Graph Neural Networks
abstract
Collecting graph data is costly and well-trained graph neural networks (GNNs) are viewed as intellectual property. To make better use of GNNs, they are used to provide cloud-based services. However, models on cloud-based services may be leaked under model extraction attacks. Adversaries can extract an imitation model by simply querying the GNNs on the cloud-based services. To protect GNNs, watermarks are embedded in the models. However, the watermarks can be removed by the model extraction attacks. To address this issue, we propose adding a watermark that cannot be ignored by queries from the model extraction attacks. Concretely, we add the soft nearest neighbor loss to the loss function of the watermark embedding process to merge the distributions for the normal tasks and watermarks. We also observe that the watermark brings a performance loss to GNNs and propose an optimization method to maintain the model performance. We evaluate our method on multiple real-world datasets to demonstrate the superiority of the method.
Zhikun Zhang 0001, Min Chen 0032, Shibo He
ICC3
2023 FACE-AUDITOR: Data Auditing in Facial Recognition Systems
Min Chen 0032, Zhikun Zhang 0001, Tianhao Wang 0001, Michael Backes 0001, Yang Zhang 0016
USENIX Security Symposium1
2023 PrivGraph: Differentially Private Graph Data Publication by Exploiting Community Information
Zhikun Zhang 0001, Linkang Du, Min Chen 0032, Peng Cheng 0001
USENIX Security Symposium4
2022 Graph Unlearning
abstract
Machine unlearning is a process of removing the impact of some training data from the machine learning (ML) models upon receiving removal requests. While straightforward and legitimate, retraining the ML model from scratch incurs a high computational overhead. To address this issue, a number of approximate algorithms have been proposed in the domain of image and text data, among which SISA is the state-of-the-art solution. It randomly partitions the training set into multiple shards and trains a constituent model for each shard. However, directly applying SISA to the graph data can severely damage the graph structural information, and thereby the resulting ML model utility. In this paper, we propose GraphEraser, a novel machine unlearning framework tailored to graph data. Its contributions include two novel graph partition algorithms and a learning-based aggregation method. We conduct extensive experiments on five real-world graph datasets to illustrate the unlearning efficiency and model utility of GraphEraser. It achieves 2.06x (small dataset) to 35.94x (large dataset) unlearning time improvement. On the other hand, GraphEraser achieves up to 62.5% higher F1 score and our proposed learning-based aggregation method achieves up to 112% higher F1 score. https://github.com/MinChen00/Graph-Unlearning.
Min Chen 0032, Zhikun Zhang 0001, Tianhao Wang 0001, Michael Backes 0001, Mathias Humbert, Yang Zhang 0016
CCS1
2022 Finding MNEMON: Reviving Memories of Node Embeddings
abstract
Previous security research efforts orbiting around graphs have been exclusively focusing on either (de-)anonymizing the graphs or understanding the security and privacy issues of graph neural networks. Little attention has been paid to understand the privacy risks of integrating the output from graph embedding models (e.g., node embeddings) with complex downstream machine learning pipelines. In this paper, we fill this gap and propose a novel model-agnostic graph recovery attack that exploits the implicit graph structural information preserved in the embeddings of graph nodes. We show that an adversary can recover edges with decent accuracy by only gaining access to the node embedding matrix of the original graph without interactions with the node embedding models. We demonstrate the effectiveness and applicability of our graph recovery attack through extensive experiments.
Yufei Han 0001, Zhikun Zhang 0001, Min Chen 0032, Ting Yu 0001, Michael Backes 0001, Yang Zhang 0016, Gianluca Stringhini
CCS4
2022 Inference Attacks Against Graph Neural Networks
Zhikun Zhang 0001, Min Chen 0032, Michael Backes 0001, Yang Zhang 0016
USENIX Security Symposium2
2021 When Machine Unlearning Jeopardizes Privacy
abstract
The right to be forgotten states that a data owner has the right to erase their data from an entity storing it. In the context of machine learning (ML), the right to be forgotten requires an ML model owner to remove the data owner's data from the training set used to build the ML model, a process known asmachine unlearning. While originally designed to protect the privacy of the data owner, we argue that machine unlearning may leave some imprint of the data in the ML model and thus create unintended privacy risks. In this paper, we perform the first study on investigating the unintended information leakage caused by machine unlearning. We propose a novel membership inference attack that leverages the different outputs of an ML model's two versions to infer whether a target sample is part of the training set of the original model but out of the training set of the corresponding unlearned model. Our experiments demonstrate that the proposed membership inference attack achieves strong performance. More importantly, we show that our attack in multiple cases outperforms the classical membership inference attack on the original ML model, which indicates that machine unlearning can have counterproductive effects on privacy. We notice that the privacy degradation is especially significant for well-generalized ML models where classical membership inference does not perform well. We further investigate four mechanisms to mitigate the newly discovered privacy risks and show that releasing the predicted label only, temperature scaling, and differential privacy are effective. We believe that our results can help improve privacy protection in practical implementations of machine unlearning. \footnoteOur code is available at \urlhttps://github.com/MinChen00/UnlearningLeaks.
Min Chen 0032, Zhikun Zhang 0001, Tianhao Wang 0001, Michael Backes 0001, Mathias Humbert, Yang Zhang 0016
CCS1