VLDB 2026 Research / reviewers in the wild / expert
Xinyu Zhang 0016
dblp:58/4582-16
· DBLP profile ↗
7ranked-venue papers
4as first author
5since 2021 · last 2024
0000-0002-7427-5774ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 4 first-author · 5 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Certifiable Black-Box Attacks with Randomized Adversarial Examples: Breaking Defenses with Provable ConfidenceabstractBlack-box adversarial attacks have demonstrated strong potential to compromise machine learning models by iteratively querying the target model or leveraging transferability from a local surrogate model.Recently, such attacks can be effectively mitigated by state-of-the-art (SOTA) defenses, e.g., detection via the pattern of sequential queries, or injecting noise into the model. To our best knowledge, we take the first step to study a new paradigm of black-box attacks with provable guarantees -- certifiable black-box attacks that can guarantee the attack success probability (ASP) of adversarial examples before querying over the target model. This new black-box attack unveils significant vulnerabilities of machine learning models, compared to traditional empirical black-box attacks, e.g., breaking strong SOTA defenses with provable confidence, constructing a space of (infinite) adversarial examples with high ASP, and the ASP of the generated adversarial examples is theoretically guaranteed without verification/queries over the target model. Specifically, we establish a novel theoretical foundation for ensuring the ASP of the black-box attack with randomized adversarial examples (AEs). Then, we propose several novel techniques to craft the randomized AEs while reducing the perturbation size for better imperceptibility. Finally, we have comprehensively evaluated the certifiable black-box attacks on the CIFAR10/100, ImageNet, and LibriSpeech datasets, while benchmarking with 16 SOTA black-box attacks, against various SOTA defenses in the domains of computer vision and speech recognition. Both theoretical and experimental results have validated the significance of the proposed attack. Hanbin Hong, Xinyu Zhang 0016, Binghui Wang, Zhongjie Ba, Yuan Hong 0001 |
CCS | 2 |
| 2024 | Text-CRS: A Generalized Certified Robustness Framework against Textual Adversarial AttacksabstractThe language models, especially the basic text classification models, have been shown to be susceptible to textual adversarial attacks such as synonym substitution and word insertion attacks. To defend against such attacks, a growing body of research has been devoted to improving the model’s robustness. However, providing provable robustness guarantees instead of empirical robustness is still widely unexplored. In this paper, we propose Text-CRS, a generalized certified robustness framework for natural language processing (NLP) based on randomized smoothing. To our best knowledge, existing certified schemes for NLP can only certify the robustness against ℓ0perturbations in synonym substitution attacks. Representing each word-level adversarial operation (i.e., synonym substitution, word reordering, insertion, and deletion) as a combination of permutation and embedding transformation, we propose novel smoothing theorems to derive robustness bounds in both permutation and embedding space against such adversarial operations. To further improve certified accuracy and radius, we consider the numerical relationships between discrete words and select proper noise distributions for the randomized smoothing. Finally, we conduct substantial experiments on multiple language models and datasets. Text-CRS can address all four different word-level adversarial operations and achieve a significant accuracy improvement. We also provide the first benchmark on certified accuracy and radius of four word-level operations, besides outperforming the state-of-the-art certification against synonym substitution attacks.1 Xinyu Zhang 0016, Hanbin Hong, Yuan Hong 0001, Binghui Wang, Zhongjie Ba, Kui Ren 0001 |
SP | 1 |
| 2024 | PrivacyAsst: Safeguarding User Privacy in Tool-Using Large Language Model AgentsabstractSwift advancements in large language model (LLM) technologies lead to widespread research and applications, particularly in integrating LLMs with auxiliary tools, known as tool-using LLM agents. However, amid user interactions, the transmission of private information to both LLMs and tools poses considerable privacy risks to users. In this paper, we delve into current privacy-preserving solutions for LLMs and outline three pivotal challenges for tool-using LLM agents: generalization to both open-source and closed-source LLMs and tools, compliance with privacy requirements, and applicability to unrestricted tasks. To tackle these challenges, we present PrivacyAsst, the first privacy-preserving framework tailored for tool-using LLM agents, encompassing two solutions for different application scenarios. First, we incorporate a homomorphic encryption scheme to ensure computational security guarantees for users as a safeguard against both open-source and closed-source LLMs and tools. Moreover, we propose a shuffling-based solution to broaden the framework's applicability to unrestricted tasks. This solution employs an attribute-based forgery generative model and an attribute shuffling mechanism to craft privacy-preserving requests, effectively concealing individual inputs. Additionally, we introduce an innovative privacy concept,$t$-closeness in image data, for privacy compliance within this solution. Finally, we implement PrivacyAsst, accompanied by two case studies, demonstrating its effectiveness in advancing privacy-preserving artificial intelligence. Xinyu Zhang 0016, Huiyu Xu, Zhongjie Ba, Zhibo Wang 0001, Yuan Hong 0001, Jian Liu 0012, Zhan Qin, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | FLTracer: Accurate Poisoning Attack Provenance in Federated LearningabstractFederated Learning (FL) is a promising distributed learning approach that enables multiple clients to collaboratively train a shared global model. However, recent studies show that FL is vulnerable to various poisoning attacks, which can degrade the performance of global models or introduce backdoors into them. In this paper, we first conduct a comprehensive study on prior FL attacks and detection methods. The results show that all existing detection methods are only effective against limited and specific attacks. Most detection methods suffer from high false positives, which lead to significant performance degradation, especially in not independent and identically distributed (non-IID) settings. To address these issues, we propose FLTracer, the first FL attack provenance framework to accurately detect various attacks and trace the attack time, objective, type, and poisoned location of updates. Different from existing methodologies that rely solely on cross-client anomaly detection, we propose a Kalman filter-based cross-round detection to identify adversaries by seeking the behavior changes before and after the attack. Thus, this makes it resilient to data heterogeneity and is effective even in non-IID settings. To further improve the accuracy of our detection method, we employ four novel features and capture their anomalies with the joint decisions. Extensive evaluations show that FLTracer achieves an average true positive rate of over 96.88% at an average false positive rate of less than 2.67%, significantly outperforming SOTA detection methods (https://github.com/Eyr3/FLTracer). Xinyu Zhang 0016, Zhongjie Ba, Yuan Hong 0001, Tianhang Zheng, Feng Lin 0004, Li Lu 0008, Kui Ren 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | An Efficient E2E Crowd Verifiable E-Voting SystemabstractElectronic voting (e-voting), compared with article voting, has advantages in several aspects. Among those benefits, the ability to audit the electoral process at every stage is one of the most desired features of an e-voting system. In Eurocrypt 2015, Kiayias, Zacharias, and Zhang proposed a new E2E verifiable e-voting system that for the first time provides E2E verifiability without relying on external sources of randomness or the random oracle model; the main advantage of such system is in the fact that election auditors need only the election transcript and the feedback from the voters to pronounce the election process unequivocally valid. Unfortunately, their system comes with a huge performance and storage penalty for the election authority (EA) compared to other e-voting systems such as Helios. The main reason is that due to the way the EA forms the proof of the tally result, it is required toprecomputea number of ciphertexts for each voter and each possible choice of the voter. The performance penalty on the EA appears to be intrinsic to the approach: voters cannot compute an enciphered ballot themselves because there seems to be no way for them to prove that it is a valid ciphertext. In this work, we construct a new e-voting system that retains similar strong E2E characteristics (but against computational adversaries) while completely eliminating the performance and storage penalty of the EA. Our construction has similar performance to Helios and is practical. The privacy of our construction relies on the SXDH assumption over bilinear groups via complexity leveraging. Xinyu Zhang 0016, Bingsheng Zhang, Aggelos Kiayias, Thomas Zacharias 0001, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | Learning-based Practical Smartphone Eavesdropping with Built-in Accelerometer
Zhongjie Ba, Tianhang Zheng, Xinyu Zhang 0016, Zhan Qin, Baochun Li, Xue (Steve) Liu, Kui Ren 0001 |
NDSS | 3 |
| 2019 | CFP: Enabling Camera Fingerprint Concealment for Privacy-Preserving Image SharingabstractIt has been discovered that every photo carries an unique hardware fingerprint of the photographing digital camera. This camera fingerprint is remarkably effective in image-to-camera matching and has been applied in a wide variety of beneficial forensic tasks such as copyright protection and integrity validation. However, the fingerprints carried by the images can also be utilized for malicious purposes. An adversary can launch identity linking attack, which re-identifies the anonymous social network accounts, through exploiting the digital cameras' fingerprints that are carried by the posted images. Moreover, the adversary can easily frame an innocent victim or bypass camera-based smartphone authentication systems by launching identity forgery attacks, i.e., fabricating unoriginal fingerprints onto images. Currently, no effective counter measures against such attacks have been proposed yet. To solve this problem, in this paper, we first evaluate the effectiveness of the attacks in the current image sharing practices. We then propose CFP, an intermediary between smartphone users and image sharing platforms that conceals the camera fingerprint of the photographing device. Instead of removing the camera fingerprint from the image of interest, our system protects user privacy through obfuscating the camera fingerprint with a specially designed random perturbation component. With such design, the proposed system is enabled to prevent malicious utilizations of camera fingerprint while preserving the beneficial applications. Extensive experiments are conducted to demonstrate the effectiveness and efficiency of the CFP system on various social platforms. Using the CFP obfuscated images, the True Positive Rate of identity linking attacks is reduced by around 85%. For identity forgery attacks, our system enables an effective detection mechanism that could achieve 100% detection rate. Zhongjie Ba, Xinyu Zhang 0016, Zhan Qin, Kui Ren 0001 |
ICDCS | 2 |