VLDB 2026 Research / reviewers in the wild / expert
Shenyi Zhang
dblp:52/10864
· DBLP profile ↗
10ranked-venue papers
2as first author
10since 2021 · last 2026
0009-0000-2140-7131ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 2 first-author · 6 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Divide and Conquer: Policy-Aware Jailbreak Defense for Large Language Models
Yuchen Zhai, Shenyi Zhang, Lingchen Zhao |
KSEM (4) | 3 |
| 2026 | Boosting Adversarial Transferability With Low-Cost Optimization via Maximin Expected FlatnessabstractTransfer-based attacks craft adversarial examples on white-box surrogate models and directly deploy them against black-box target models, offering practical query-free threat scenarios. While flatness-enhanced methods have recently emerged to improve transferability by enhancing the loss surface flatness of adversarial examples, their divergent flatness definitions and heuristic attack designs suffer from unexamined optimization limitations and missing theoretical foundation, thus constraining their effectiveness and efficiency. This work exposes the severely imbalanced exploitation-exploration dynamics in flatness optimization, establishing the first theoretical foundation for flatness-based transferability and proposing a principled framework to overcome these optimization pitfalls. Specifically, we systematically unify fragmented flatness definitions across existing methods, revealing their imbalanced optimization limitations in over-exploration of sensitivity peaks or over-exploitation of local plateaus. To resolve these issues, we rigorously formalize average-case flatness and transferability gaps, proving that enhancing zeroth-order average-case flatness minimizes cross-model discrepancies. Building on this theory, we design a Maximin Expected Flatness (MEF) attack that enhances zeroth-order average-case flatness while balancing flatness exploration and exploitation. Extensive evaluations across 33 models and 43 current transfer-based attacks demonstrate MEF’s superiority: it surpasses the state-of-the-art PGN attack by 4% in attack success rate at half the computational cost and achieves 8% higher success rate under the same budget. When combined with input augmentation, MEF attains 15% additional gains against defense-equipped models, establishing new robustness benchmarks. Our code is available at https://github.com/SignedQiu/MEFAttack. Chunlin Qiu, Yiheng Duan, Shenyi Zhang, Yuanjie Zhang, Lingchen Zhao, Qian Wang 0002 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Selective Masking Adversarial Attack on Automatic Speech Recognition SystemsabstractExtensive research has shown that Automatic Speech Recognition (ASR) systems are vulnerable to audio adversarial attacks. Current attacks mainly focus on single-source scenarios, ignoring dual-source scenarios where two people are speaking simultaneously. To bridge the gap, we propose a Selective Masking Adversarial attack, namely SMA attack, which ensures that one audio source is selected for recognition while the other audio source is muted in dual-source scenarios. To better adapt to the dual-source scenario, our SMA attack constructs the normal dual-source audio from the muted audio and selected audio. SMA attack initializes the adversarial perturbation with a small Gaus-sian noise and iteratively optimizes it using a selective masking optimization algorithm. Extensive experiments demonstrate that the SMA attack can generate effective and imperceptible audio adversarial examples in the dual-source scenario, achieving an average success rate of attack of 100% and signal-to-noise ratio of 37.15dB on Conformer-CTC, outperforming the baselines. Zheng Fang 0014, Shenyi Zhang, Tao Wang 0081, Bowen Li 0016, Lingchen Zhao, Zhangyi Wang |
ICME | 2 |
| 2025 | IntentBreaker: Intent-Adaptive Jailbreak Attack on Large Language Models
Yuchen Zhai, Shenyi Zhang, Lingchen Zhao, Zhangyi Wang |
ECML/PKDD (4) | 3 |
| 2025 | JBShield: Defending Large Language Models from Jailbreak Attacks through Activated Concept Analysis and Manipulation
Shenyi Zhang, Yuchen Zhai, Keyan Guo, Hongxin Hu, Zheng Fang 0014, Lingchen Zhao, Chao Shen 0001, Cong Wang 0001, Qian Wang 0002 |
USENIX Security Symposium | 1 |
| 2024 | Zero-Query Adversarial Attack on Black-box Automatic Speech Recognition SystemsabstractIn recent years, extensive research has been conducted on the vulnerability of ASR systems, revealing that black-box adversarial example attacks pose significant threats to real-world ASR systems. However, most existing black-box attacks rely on queries to the target ASRs, which is impractical when queries are not permitted. In this paper, we propose ZQ-Attack, a transfer-based adversarial attack on ASR systems in the zero-query black-box setting. Through a comprehensive review and categorization of modern ASR technologies, we first meticulously select surrogate ASRs of diverse types to generate adversarial examples. Following this, ZQ-Attack initializes the adversarial perturbation with a scaled target command audio, rendering it relatively imperceptible while maintaining effectiveness. Subsequently, to achieve high transferability of adversarial perturbations, we propose a sequential ensemble optimization algorithm, which iteratively optimizes the adversarial perturbation on each surrogate model, leveraging collaborative information from other models. We conduct extensive experiments to evaluate ZQ-Attack. In the over-the-line setting, ZQ-Attack achieves a 100% success rate of attack (SRoA) with an average signal-to-noise ratio (SNR) of 21.91dB on 4 online speech recognition services, and attains an average SRoA of 100% and SNR of 19.67dB on 16 open-source ASRs. In the over-the-air setting, ZQ-Attack also achieves a 100% SRoA with an average SNR of 15.77dB on 2 commercial intelligent voice control devices. Zheng Fang 0014, Tao Wang 0081, Lingchen Zhao, Shenyi Zhang, Bowen Li 0016, Yunjie Ge, Qi Li 0002, Chao Shen 0001, Qian Wang 0002 |
CCS | 4 |
| 2024 | Enhancing the Transferability of Adversarial Examples with Noise Injection AugmentationabstractTransfer-based adversarial attacks highlight a critical security concern in the vulnerability of deep neural networks (DNNs). By generating deceptive inputs on a surrogate model, these attacks efficiently transfer the malicious examples to target models, even those with different architectures. However, current transfer-based adversarial attacks face a significant challenge. Existing strategies, including gradient optimization, input transformation, and model ensemble methods, struggle to strike an effective balance between computational cost and transferability. To alleviate this issue, we introduce a novel method, dubbed Noise Injection Augmentation (NIA). NIA enhances the transferability of the generated adversarial examples by introducing randomness into the surrogate models. The key idea of NIA is to explore the regularization properties of noise injection. Furthermore, we achieve stronger transferability by combining NIA with the idea of model self-ensemble. Extensive experiments show that NIA significantly enhances the attack performance of various potent adversarial attacks such as MI-FGSM, MDTI-FGSM, and S2I-FGSM by 28%, 20.4%, and 18.6%. On average, combined with the state-of-the-art transfer-based attack, NIA further improves transferability to 93.8% on normally trained models and 72% on robust models. Yiheng Duan, Yunjie Ge, Jiayi Yu, Shenyi Zhang |
ICME | 5 |
| 2024 | Hijacking Attacks against Neural Network by Analyzing Training Data
Yunjie Ge, Qian Wang 0002, Huayang Huang, Qi Li 0002, Cong Wang 0001, Chao Shen 0001, Lingchen Zhao, Peipei Jiang 0002, Zheng Fang 0014, Shenyi Zhang |
USENIX Security Symposium | 10 |
| 2024 | Perception-Driven Imperceptible Adversarial Attack Against Decision-Based Black-Box ModelsabstractAdversarial examples (AEs) pose significant threats to deep neural networks (DNNs), as they can deceive models into making incorrect predictions through craftily-designed malicious perturbations. The emergence of decision-based attacks, which rely solely on the top-1 decision label, further increases risks for real-world black-box models. Currently, the prevailing practice for generating effective AEs in decision-based attacks involves penalizing adversarial perturbations using the ℓp-norm. However, this approach often fails to consider the human perception of adversarial perturbations in real-world scenarios. To tackle this issue, we propose a novel and efficient Imperceptible Decision-based Black-box Attack (IDBA). Our method prioritizes optimizing the perception-related distribution of perturbations, rather than solely focusing on the ℓp-norm. Specifically, IDBA analyzes the perceptual preferences of both models and the human vision system, selectively perturbing components that influence model decisions yet remain imperceptible to human eyes. Extensive experiments demonstrate the superior performance of IDBA in both invisibility and query efficiency, a widely used metric in prior works, in comparison to state-of-the-art methods. With only 4.8K queries, IDBA achieves a Feature SIMilarity (FSIM) score of 0.92 while reducing the Learned Perceptual Image Patch Similarity (LPIPS) to 0.12, indicating remarkable imperceptibility. Shenyi Zhang, Baolin Zheng, Peipei Jiang 0002, Lingchen Zhao, Chao Shen 0001, Qian Wang 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | Black-box Adversarial Attacks on Commercial Speech Platforms with Minimal InformationabstractAdversarial attacks against commercial black-box speech platforms, including cloud speech APIs and voice control devices, have received little attention until recent years. Constructing such attacks is difficult mainly due to the unique characteristics of time-domain speech signals and the much more complex architecture of acoustic systems. The current "black-box" attacks all heavily rely on the knowledge of prediction/confidence scores or other probability information to craft effective adversarial examples (AEs), which can be intuitively defended by service providers without returning these messages. In this paper, we take one more step forward and propose two novel adversarial attacks in more practical and rigorous scenarios. For commercial cloud speech APIs, we propose Occam, a decision-only black-box adversarial attack, where only final decisions are available to the adversary. In Occam, we formulate the decision-only AE generation as a discontinuous large-scale global optimization problem, and solve it by adaptively decomposing this complicated problem into a set of sub-problems and cooperatively optimizing each one. Our Occam is a one-size-fits-all approach, which achieves 100% success rates of attacks (SRoA) with an average SNR of 14.23dB, on a wide range of popular speech and speaker recognition APIs, including Google, Alibaba, Microsoft, Tencent, iFlytek, and Jingdong, outperforming the state-of-the-art black-box attacks. For commercial voice control devices, we propose NI-Occam, the first non-interactive physical adversarial attack, where the adversary does not need to query the oracle and has no access to its internal information and training data. We, for the first time, combine adversarial attacks with model inversion attacks, and thus generate the physically-effective audio AEs with high transferability without any interaction with target devices. Our experimental results show that NI-Occam can successfully fool Apple Siri, Microsoft Cortana, Google Assistant, iFlytek and Amazon Echo with an average SRoA of 52% and SNR of 9.65dB, shedding light on non-interactive physical attacks against voice control devices. Baolin Zheng, Peipei Jiang 0002, Qian Wang 0002, Qi Li 0002, Chao Shen 0001, Cong Wang 0001, Yunjie Ge, Qingyang Teng, Shenyi Zhang |
CCS | 9 |