Rui Zhang 0090

dblp:60/2536-90 · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
11since 2021 · last 2026
0009-0004-1200-2588ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 MPMA: Preference Manipulation Attack Against Model Context Protocol
abstract
Model Context Protocol (MCP) standardizes interface mapping for large language models (LLMs) to access external data and tools, which revolutionizes the paradigm of tool selection and facilitates the rapid expansion of the LLM agent tool ecosystem. However, as the MCP is increasingly adopted, third-party customized versions of the MCP server expose potential security vulnerabilities. In this paper, we first introduce a novel security threat, which we term the MCP Preference Manipulation Attack (MPMA). An attacker deploys a customized MCP server to manipulate LLMs, causing them to prioritize it over other competing MCP servers. This can result in economic benefits for attackers, such as revenue from paid MCP services or advertising income generated from free servers. To achieve MPMA, we first design a Direct Preference Manipulation Attack (DPMA) that achieves significant effectiveness by inserting the manipulative word and phrases into the tool name and description. However, such a direct modification is obvious to users and lacks stealthiness. To address these limitations, we further propose Genetic-based Advertising Preference Manipulation Attack (GAPMA). GAPMA employs four commonly used strategies to initialize descriptions and integrates a Genetic Algorithm (GA) to enhance stealthiness. The experiment results demonstrate that GAPMA balances high effectiveness and stealthiness. Our study reveals a critical vulnerability of the MCP in open ecosystems, highlighting an urgent need for robust defense mechanisms to ensure the fairness of the MCP ecosystem.
Rui Zhang 0090, Wenshu Fan, Wenbo Jiang 0001, Qingchuan Zhao, Hongwei Li 0001, Guowen Xu
AAAI2
2026 No Trespassing: Ground-View Adversarial Patches for Privacy-Aware Management in COTS Robot Vacuum Cleaner
abstract
Robot vacuum cleaners (RVCs) with autonomous navigation and decision-making capabilities have become an integral part of modern homes. During their operations, these devices may inadvertently enter privacy-sensitive areas, leading to potential privacy breaches. However, existing defense methods risk exposing the location of private areas, require root privileges, or are designed for infrared sensors that are ineffective for camera-based RVCs. To overcome these limitations, we propose a novel solution, a ground-view adversarial patch named GPatch, preventing RVCs from entering privacy-sensitive areas. Users only need to place GPatch at the entrance of restricted areas to prevent an RVC's unauthorized access, while also providing a warning to unauthorized individuals. We evaluate GPatch in realworld environments with an average success rate of 87.27%, and experimental results demonstrate its effectiveness, robustness, and transferability, making it a practical, user-friendly, and reliable solution for safeguarding privacy in home environments.
Shuai Yuan 0009, Guowen Xu, Hongwei Li 0001, Rui Zhang 0090, Hangcheng Cao, Xinyuan Qian 0002, Tao Ni 0003, Qingchuan Zhao, Yuguang Fang
IEEE Trans. Dependable Secur. Comput.4
2026 FIGhost: Fluorescent Ink-Based Stealthy and Flexible Backdoor Attacks on Physical Traffic Sign Recognition
abstract
Traffic sign recognition (TSR) systems are crucial for autonomous driving but are vulnerable to backdoor attacks. Existing physical backdoor attacks either lack stealth, provide inflexible attack control, or ignore emerging Vision-Large-Language-Models (VLMs). In this paper, we introduce FIGhost, the first physical-world backdoor attack leveraging fluorescent ink as triggers. Fluorescent triggers are invisible under normal conditions and activated stealthily by ultraviolet light, providing superior stealthiness, flexibility, and untraceability. Inspired by real-world graffiti, we derive realistic trigger shapes and enhance their robustness via an interpolation-based fluorescence simulation algorithm. Furthermore, we develop an automated backdoor sample generation method to support three attack objectives. Extensive evaluations in the physical world demonstrate FIGhost's effectiveness against state-of-the-art detectors and VLMs, maintaining robustness under environmental variations and effectively evading existing defenses.
Shuai Yuan 0009, Guowen Xu, Hongwei Li 0001, Rui Zhang 0090, Xinyuan Qian 0002, Hangcheng Cao, Qingchuan Zhao
IEEE Trans. Dependable Secur. Comput.4
2026 Hidden Tail: Adversarial Attack for Stealthy Resource Consumption Against Vision-Language Models
abstract
Vision-Language Models (VLMs) are increasingly deployed in real-world applications, but their high inference cost makes them vulnerable to resource consumption attacks. Prior attacks attempt to extend VLM output sequences by optimizing adversarial images, thereby increasing inference costs. However, these extended outputs often introduce irrelevant abnormal content, compromising attack stealthiness. This trade-off between effectiveness and stealthiness poses a major limitation for existing attacks. To address this challenge, we proposeHidden Tail, a stealthy resource consumption attack that crafts prompt-agnostic adversarial images, inducing VLMs to generate maximum-length outputs by appending special tokens invisible to users. Our method employs a composite loss function that balances semantic preservation, repetitive special token induction, and suppression of the end-of-sequence (EOS) token, optimized via a dynamic weighting strategy. Extensive experiments show thatHidden Tailoutperforms existing attacks, increasing output length by up to 19.2× and reaching the maximum token limit, while preserving attack stealthiness. These results highlight the urgent need to improve the robustness of VLMs against efficiency-oriented adversarial threats. Our code is available athttps://github.com/zhangrui4041/Hidden_Tail.
Rui Zhang 0086, Tianli Yang, Wenbo Jiang 0001, Rui Zhang 0090, Qingchuan Zhao, Hongwei Li 0001, Yang Liu 0003, Guowen Xu
IEEE Trans. Dependable Secur. Comput.5
2025 Omni-Angle Assault: An Invisible and Powerful Physical Adversarial Attack on Face Recognition
abstract
Deep learning models employed in face recognition (FR) systems have been shown to be vulnerable to physical adversarial attacks through various modalities, including patches, projections, and infrared radiation. However, existing adversarial examples targeting FR systems often suffer from issues such as conspicuousness, limited effectiveness, and insufficient robustness. To address these challenges, we propose a novel approach for adversarial face generation, UVHat, which utilizes ultraviolet (UV) emitters mounted on a hat to enable invisible and potent attacks in black-box settings. Specifically, UVHat simulates UV light sources via video interpolation and models the positions of these light sources on a curved surface, specifically the human head in our study. To optimize attack performance, UVHat integrates a reinforcement learning-based optimization strategy, which explores a vast parameter search space, encompassing factors such as shooting distance, power, and wavelength. Extensive experimental evaluations validate that UVHat substantially improves the attack success rate in black-box settings, enabling adversarial attacks from multiple angles with enhanced robustness.
Shuai Yuan 0009, Hongwei Li 0001, Rui Zhang 0090, Hangcheng Cao, Wenbo Jiang 0001, Tao Ni 0003, Wenshu Fan, Qingchuan Zhao, Guowen Xu
ICML3
2025 CtrlMark: Controllable Watermarking for ControlNet Against Downstream Fine-Tuning
abstract
Text-to-image diffusion models have advanced controllable image generation, with ControlNet plugins enabling precise structural guidance and domain-specific adaptations. As these plugins become widely shared and personalized, protecting their ownership and preventing misuse becomes crucial. Existing watermarking methods address robustness against fine-tuning and personalization at the model level, but fail to address ControlNet-like plugins or modules specifically. To address this gap, we propose CtrlMark, the first watermarking framework designed specifically for ControlNet plugin modules. CtrlMark embeds a robust, triggerable watermark as a benign backdoor, activated by a composite trigger combining text and structural inputs. Furthermore, CtrlMark achieves few misactivations and strong robustness against downstream fine-tuning, by watermark penalization and leveraging a fixed latent residual embedding localized to a spatial region. Extensive experiments demonstrate CtrlMark maintains high watermark activation rates and visual fidelity, providing effective and practical protection for modular ControlNet components in diverse generation scenarios.
Rui Zhang 0090, Wenbo Jiang 0001, Hongwei Li 0001, Guowen Xu
ICPADS2
2025 You Are Out of My Focus: A Defocus-Blur Backdoor Attack against Deep Learning Models
abstract
With the widespread adoption of deep learning in image recognition, backdoor attacks have emerged as a significant security threat, drawing increasing attention from the research community. Traditional backdoor attacks are often limited to the digital domain, while few existing physical-world attacks suffer from a lack of stealthiness. In this paper, inspired by the natural defocus blur commonly caused by camera optics in real-world environments, we propose a physically-aware backdoor attack method called DBBA based on the defocus blur phenomenon. By leveraging Gaussian blur to simulate this natural phenomenon, the proposed method enhances both the stealthiness and plausibility of the trigger. To further optimize the attack effectiveness while maintaining stealthiness, we introduce a Particle Swarm Optimization (PSO) algorithm to automatically search for the optimal Gaussian blur parameters that best simulate the defocus phenomenon. We conduct extensive experiments on multiple mainstream image classification datasets and across various model architectures. Experimental results demonstrate that the proposed defocus-blur based trigger achieves a high attack effectiveness with minimal degradation in the classification accuracy of the model. In addition, evaluations against representative defense techniques reveal that the proposed method exhibits strong stealthiness and robustness.
Hongwei Li 0001, Wenbo Jiang 0001, Jiaming He, Rui Zhang 0090, Ji Guo, Jiachen Li 0002
MMAsia6
2025 Backdoor attacks against Hybrid Classical-Quantum Neural Networks
Ji Guo, Wenbo Jiang 0001, Rui Zhang 0090, Wenshu Fan, Jiachen Li 0002, Guoming Lu, Hongwei Li 0001
Neural Networks3
2025 I2I Backdoor: Backdoor Attacks Against Image-to-Image Tasks
abstract
With the rapid development of deep learning technology, deep learning-based Image-to-Image (I2I) networks have become the predominant choice for I2I tasks like image super-resolution and denoising. Despite their remarkable performance, the security of I2I networks has not been thoroughly investigated. While some studies have probed their susceptibility to adversarial attacks, none have explored the backdoor attack against I2I networks, which is a more stealthy and severe threat. In this work, for the first time, we comprehensively investigate the vulnerability of I2I networks to backdoor attacks. We propose a backdoor attack against I2I tasks, where the backdoored I2I network behaves normally on clean input images, yet outputs a specific inappropriate image when the backdoor trigger appears on the input image. To achieve such an I2I backdoor attack, we design a universal adversarial perturbation (UAP) generation algorithm for I2I networks, where the generated UAP is used as the trigger for the I2I backdoor. Besides, multi-task learning (MTL) with dynamic weighting methods is employed in the backdoor training process to gain better results. Expanding our focus beyond I2I tasks, we extend our I2I backdoor to attack downstream tasks, including image classification and object detection. Specifically, the backdoor-triggered image processed by the backdoored image denoising network can fool the downstream image classifiers and object detectors. Extensive experiments demonstrate the effectiveness of the I2I backdoor on state-of-the-art I2I network architectures as well as the robustness against different backdoor defenses.
Wenbo Jiang 0001, Hongwei Li 0001, Jiaming He, Rui Zhang 0090, Guowen Xu, Tianwei Zhang 0004, Rongxing Lu
IEEE Trans. Dependable Secur. Comput.4
2024 BadTTS: Identifying Vulnerabilities in Neural Text-to-Speech Models
abstract
With the widespread use of deep learning systems in many applications, adversaries have strong incentives to perform attacks against these systems for their adversarial purposes. Reports have indicated that backdoor attacks on deep neural networks represent a novel form of threat. In this attack, the adversary will inject backdoors into the benign model and then mislead the model to classify the input containing backdoor triggers as a target label specified by the adversary. Existing research mainly focuses on backdoor attacks in image and text models, little attention has been paid to the backdoor attacks on text-to-speech (TTS) models. We conduct a systematic investigation of backdoor attacks on text-to-speech models and propose BadTTS, the first backdoor attack against TTS models, which is a general backdoor attack framework that tampers with input texts in three semantic levels to generate malicious output speech, including Char-Backdoor, Word-Backdoor, and Sentence-Backdoor. Our method not only efficiently injects backdoors into a TTS model but is also stealthy and has little impact on the synthesized speech quality. We implement the backdoor attack in a black-box fine-tuning setting, where the adversary has no knowledge of model architectures except for a small amount of training data. We perform empirical experiments on three representative and widely studied TTS models, indicating that backdoors can be injected into TTS models within a few fine-tuning steps. Additionally, we conduct experiments to explore the impact of different types of triggers, as well as the intermediate outputs of models, which provide insights for potential defenses against backdoor attacks.
Rui Zhang 0090, Hongwei Li 0001, Wenbo Jiang 0001, Jiaming He
GLOBECOM1
2024 Benchmark GELU in Secure Multi-Party Computation
abstract
Recently, several technology companies have released online inference services for clients based on Transformer-based large language models, which show excellent performance in various tasks. However, in these services, the inputs usually involve clients’ sensitive information. To address this problem, many works have proposed secure inference on language models such as GPT. For language models, complex mathematical functions like Gaussian Error Linear Unit (GELU) are used extensively and dominate the main cost of secure inference. In this work, we systematically study the existing secure GELU protocols and classify previous methods into two categories: polynomial-based protocols and lookup table (LUT)-based protocols. We point out several important characteristics and tradeoffs for these two classes of secure GELU protocols. Based on these observations and analysis, we propose a new secure GELU protocol, called Simple. The main technique that Simple uses involves a LUT of small size to retrieve approximate polynomials for fitting residual error functions caused by a crude approximation for GELU, which achieves state-of-the-art (SOTA) overhead and accuracy performance. We conduct extensive experiments and benchmark the previous 6 secure GELU protocols. The experimental comparison shows that our Simple protocol achieves 1.1 ∼ 8784.3× computation and 1.4 ∼ 188.8× communication improvements while reducing 1.2∼80.2× errors.
Rui Zhang 0090, Hongwei Li 0001, Meng Hao 0001, Hanxiao Chen 0001, Yuan Zhang 0006, Dianhua Tang
GLOBECOM1