Xiao Yang 0016

dblp:57/3385-16 · DBLP profile ↗
← Back
13ranked-venue papers
11as first author
11since 2021 · last 2026
0000-0002-1736-3065ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 4 · 3 first-author · 3 since 2021Systems, architecture and hardware · 3 · 3 first-author · 3 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Ownership-Protected Semantic Communication via Signal Processing-Driven Robust Watermark
Xiao Yang 0016, Gaolei Li, Zhaohui Yang 0001, Yuchen Liu 0001, Jianhua Li 0001
ICC2
2026 Persistent Clean-Label Backdoor Attacks on Semisupervised Social Graph Node Classification
abstract
Semisupervised social graph node classification (SSGNC) attempts to deduce node-related information of social graph with limited labeled training samples. It is primarily deployed in large-scale graph processing, e.g., malicious client detection, knowledge graph, and recommender system. However, in this article, we identify that the SSGNC model is also extremely sensitive to backdoor attacks. We present a novel persistent clean-label backdoor attack (PerCBA) on SSGNC, which selectively poisons unmarked training nodes before learning to compel the trained model to misclassify trigger-embedded inputs into malicious class. Specifically, PerCBA employs a style-agnostic trigger generator with adjustable perturbation strategy to produce perturbed triggers. These triggers are pasted onto a small subset of unmarked nodes ($< \, 4\%$), enabling the adversary to covertly poison the training graph and implant backdoors into the model without modifying labels. Additionally, to ensure SSGNC robustness when confronted with homogenous threats, we present a testing sample filtering-based defense strategy for PerCBA. It employs feature distribution to identify poisoned nodes and applies Gaussian blur and thresholding to remove the trigger fraction, thereby restoring suspicious data to clean states. Extensive experiments on SOTA SSGNC models and datasets indicate that PerCBA performs high attack success rates (maxima 96.25%) while remaining evasive, and the defense method can effectively mitigate attacks and purify backdoored models.
Xiao Yang 0016, Gaolei Li, Xinzheng Feng, Xiaoyu Yi 0003, Jianhua Li 0001
IEEE Trans. Comput. Soc. Syst.1
2026 Toward Polymorphic Backdoor Against Semantic Communication via Intensity-Based Poisoning
Xiao Yang 0016, Yuni Lai, Gaolei Li, Jun Wu 0001, Kai Zhou 0001, Jianhua Li 0001, Mingzhe Chen
IEEE Trans. Inf. Forensics Secur.1
2026 SemanAegis: Toward Credential-Aware Semantic Communication Against Knowledge Leakage Threats
abstract
Semantic Communication (SC) achieves meaning transmission instead of bitstreams by deep semantic encoding decoding. Since the encoder-decoder contains sensitive and proprietary knowledge, its illicit leakage infringes commercial benefits and copyright, which warrants corresponding protection. However, current SC security paradigms narrowly emphasize transmission data protection while neglecting encoding knowl edge safeguarding. To bridge this gap, we present SemanAegis, the first SC knowledge protection framework. SemanAegisinte grates a built-in-system access control mechanism that remains effective even if the system is stolen, ensuring that unauthorized access attempts yield unacceptable low-fidelity outputs, while credential-embedded inputs from authorized entities are met with accurate responses. Specifically, we establish access control through backdoor implantation, whereby only inputs embedded with credentials activate the backdoor and access system, while source inputs are constrained to generate erroneous results. Moreover, we adopt a synthesizer to generate imperceptible credentials, thus guaranteeing their confidentiality. Additionally, a dedicated contrastive learning strategy is implemented to accelerate the convergence of backdoor implanting. Empirical evaluations across SC systems and benchmark datasets demonstrate SemanAegis precisely rejects unauthorized inputs, effectively mitigates knowledge extractions, and consistently preserves SC regular functionality.
Xiao Yang 0016, Yuni Lai, Gaolei Li, Jun Wu 0001, Kai Zhou 0001, Mingzhe Chen
IEEE Trans. Mob. Comput.1
2025 WatCOM: Unconscious Watermarking for Semantic Communication Intellectual Property Protection
abstract
Semantic Communication (SC) enhances communication efficacy by abstracting and decoding semantic information via shared knowledge instead of bitstream, while considerably reducing redundancy and reinforcing efficiency in downstream tasks including image recognition, language processing, internet of things, etc. Due to the extensive data collection, processing, and training, the SC shared knowledge is invaluable Intellectual Property (IP), and despite the owners' desire to prevent misuse, the knowledge still remains vulnerable to theft while related IP protection has yet to be explored. To bridge this gap, we propose WatCom, the first SC IP protection methodology via watermarking. Specifically, we implant a stealthy backdoor into the semantic shared knowledge to verify model ownership, which can solely be activated by the owner-exclusive implicit trigger to validate ownership. The backdoor is implanted by poisoning-training strategy, facilitating SC system to respond normally to regular inputs while producing verification outputs (i.e., backdoor activation) for trigger-infected samples. To ensure imperceptibility, we leverage one generator to synthesize infected data that is nearly indistinguishable from regular data, which thereby obfuscates the verification information presence and enhances security against adversarial detection. Experiments based on multiple datasets and systems demonstrate WatCom can effectively verify system ownership (IP Verification Rate$\sim 100 \%$) while maintaining transmission efficacy (Peak Signal-to-Noise Ratio drop$< 2 ~\text{dB}$).
Xiao Yang 0016, Yuanhang He, Gaolei Li, Jianhua Li 0001
ICC1
2025 GraphProt: Certified Black-Box Shielding Against Backdoored Graph Models
abstract
Graph learning models have been empirically proven to be vulnerable to backdoor threats, wherein adversaries submit trigger-embedded inputs to manipulate the model predictions. Current graph backdoor defenses manifest several limitations: 1) dependence on model-related details, 2) necessitation of additional fine-tuning, and 3) reliance on extra explainability tools, all of which are infeasible under stringent privacy policies. To address those limitations, we propose GraphProt, a certified black-box defense method to suppress backdoor attacks on GNN-based graph classifiers. Our GraphProt operates in a model-agnostic manner and solely leverages graph input. Specifically, GraphProt first introduces designed topology-feature-filtration to mitigate graph anomalies. Subsequently, subgraphs are sampled via a formulated strategy integrating topology and features, followed by a robust model inference through a majority vote-based subgraph prediction ensemble. Our results across benchmark attacks and datasets show GraphProt effectively reduces attack success rates while preserving regular graph classification accuracy.
Xiao Yang 0016, Yuni Lai, Kai Zhou 0001, Gaolei Li, Jianhua Li 0001, Hang Zhang 0010
IJCAI1
2025 HyBiGraph: Toward Multi-Order Malicious Encrypted Traffic Classification via Hyper-Bipartite Graph Fusion
abstract
Malicious attacks frequently exploit encrypted traffic as a covert channel for intrusion, rendering the accurate identification of malicious encrypted traffic essential for early threat detection. Existing encrypted traffic classification methods primarily focus on low-order IP topological graph and single flow features. However, malicious IPs usually send encrypted flows mixed attack flows with benign traffic to hide themselves, while attack flows have high-order relations, leaving complex interactions between IP nodes and traffic flows. To address these limitations, we propose a novel Hyper-Bipartite Graph Fusion (HyBiGraph) framework for malicious encrypted traffic classification that integrates a bipartite graph for modeling low-order relationships and a hypergraph for propagating higher-order structural information. HyBiGraph constructs an IP-Flow bipartite graph with trainable IP embeddings updated via flow features, which enables the model to efficiently capture the contextual relationships between source and target IP. It further employs hypergraph attention with learnable hyperedges to power precise modeling of higher-order interactions among flows. Finally, residual fusion of hypergraph and bipartite graph offers a robust and efficient mechanism for integrating structural representations, enhancing classification performance. HyBiGraph was evaluated on benchmark encrypted malicious traffic datasets—USTC-TFC2016, CICIoT2023, and CICAndMal2017—attaining accuracy improvements of 2.51%, 23.93%, and 51.97% and requiring only approximately 10% training cost of baselines. Also, ablation studies validate that integrating hypergraph and bipartite graph promotes accuracy gains between 1.27% and 53.98%.
Yibin Zhou, Yunxiao Shi, Xiao Yang 0016, Gaolei Li, Jianhua Li 0001
TrustCom3
2024 InviINS: Invisible Instruction Backdoor Attacks on Peer-to-Peer Semantic Networks
abstract
Recently, Peer-to-Peer Semantic Network (P2PSN) has significantly boosted transmission efficiency among humans, machine agents, and smart devices. Despite these enhancements, the intelligent components within P2PSN pose vulnerabilities to backdoor attacks, where adversaries introduce specific pattern triggers to poison the training set, which prompts the well-trained P2PSN system to generate targeted malicious predictions when inputted with trigger-embedded data. Current backdoor methodologies exhibit several deficiencies: 1) pattern-based trigger lacking physical meaning and explainability; 2) visible trigger design that can be easily detected by defenders; 3) unstable attack performance resulting from communication interference. To overcome these shortcomings, we propose a novel invisible instruction backdoor attack scheme on Peer-to-Peer Semantic Networks: InviINS. The proposed method embeds text instructions on partial training samples as invisible triggers instead of pattern triggers, thereby poisoning the training set of P2PSN model before learning without visually discernible changes in data, and subsequently backdooring the model via training. In InviINS, adversaries can directly set instructions based on practical scenarios to launch attacks. Meanwhile, to accelerate backdoor convergence, a contrastive backdoor training methodology is presented to enhance the model’s sensitivity to instruction triggers and bolster its prediction performance on normal samples. Experiments with different poisoning-rates, signal-to-noise ratios, channel usages, and trigger types demonstrate that the InviINS can achieve a high attack success rate (~ 100%) while preserving the model performance on main tasks (accuracy drop < 3%).
Xiao Yang 0016, Gaolei Li, Mianxiong Dong, Kaoru Ota, Jun Wu 0001, Jianhua Li 0001
ISPA1
2024 ActIPP: Active Intellectual Property Protection of Edge-Level Graph Learning for Distributed Vehicular Networks
abstract
Edge-Level Graph Learning System (EGLS) exhibits diverse applicability in management of distributed vehicular networks, e.g., flow prediction, route planning, and accident forecasting. For the EGLS training, expensive hardware resource consumption, traffic data collection, and dedicated training procedures make the learning algorithms become valuable intellectual property (IP) for the EGLS owner (e.g., Uber and Lyft), and they cannot tolerate the infringement act of their models’ intellectual property. To enhance its IP protection, we present ActIPP, the first active IP protection methodology for EGLS, which incorporates a built-in access control function in the model to safeguard against unauthorized queries. Specifically, it is achieved via a creative edge backdoor mechanism, wherein the edge training samples are poisoned via user-specific access tokens to induce legal outputs from a well-trained EGLS model for authorized users. Moreover, related token regulating strategies were proposed to dynamically realize the addition and revocation of user tokens by model retraining to guarantee access control in EGLS. Additionally, a Graph Mutual Information-based adaptive token generation method is presented to augment the access control embedding. Based on experiments with various real-world datasets, ActIPP demonstrates high success rates of IP protection (accuracy drop < 4%) under various scenarios and efficiently prevents unauthorized access (unauthorized access accuracy < 6%).
Xiao Yang 0016, Gaolei Li, Mianxiong Dong, Kaoru Ota, Xiting Peng, Jianhua Li 0001
ISPA1
2023 Black-Box Graph Backdoor Defense
Xiao Yang 0016, Gaolei Li, Xiaoyi Tao, Jianhua Li 0001
ICA3PP (5)1
2023 Persistent Clean-Label Backdoor on Graph-Based Semi-supervised Cybercrime Detection
Xiao Yang 0016, Gaolei Li
ICDF2C (1)1
2020 Community Preference-Based Information-Centric Networking Cache
abstract
Information-centric networking (ICN) framework has been proposed to connect data content and network users together, which leads to great efficiency in comparison to conventional network. Cache policy performances as an essential part of ICN, and many studies have been conducted to research this. However, there are still two problems remaining unsolved, 1) ignoring the network user community features, 2) without considering the correlations between users and data content. To optimize these shortcomings, a community preference-based ICN cache policy was proposed. This policy will comprehensively consider the data content features and user community preference and then utilize recommendation system to cache the data into corresponding servers. Moreover, policy advantages and simulation will also be evaluated in this paper.
Xiao Yang 0016, Caijuan Chen, Haozhe Liang
MSN1
2020 Recommender System-Based Diffusion Inferring for Open Social Networks
abstract
Open social network (OSN) plays a more significant role in information propagation through the rapid developing of information technology. Since information diffusion is an essential process happens in OSN, it has been studied in many studies. Several models have been proposed to infer the diffusion process and reproduce diffusion network. However, these methods have two critical problems: 1) ignoring the effects of user social characteristics and 2) inaccuracy resulted from calculating the influence of different features independently. To address these limitations, a diffusion inferring method based on a recommender system (DIM-SPTF) was proposed. The DIM-SPTF method considers the propagation process between the users as the recommendation process of information and employs a recommender system to infer the propagation relationship. Through determining the propagation relations among all users in the observed topic data set, an information diffusion network can be finally obtained. Experimental results show that DIM-SPTF leads to improvements in performance compared with the state-of-the-art methods.
Xiao Yang 0016, Mianxiong Dong, Xiuzhen Chen, Kaoru Ota
IEEE Trans. Comput. Soc. Syst.1