VLDB 2026 Research / reviewers in the wild / expert
Zhendong Wu
dblp:60/6284
· DBLP profile ↗
25ranked-venue papers
12as first author
11since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 9 · 4 first-author · 6 since 2021Security and privacy · 4 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 2 since 2021Systems, architecture and hardware · 3 · 3 first-authorDatabases, data management, data science and information retrieval · 3 · 3 first-author · 2 since 2021Computer networks · 2 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HyperDistill: Structure-Aware Budgeted Evidence Distillation for Hypergraph Multi-Hop Question Answering
Hetao Chen, Zhendong Wu, Xiangqin Pang, Jitong Feng |
ICIC (24) | 2 |
| 2026 | Covert Communication-Based Coordinated Cyberattacks in Smart Substations
Hang Mu, Qianzhi Zhang, Yutao Qiu, Heqin Tong, Qiang Yang 0004, Zhendong Wu, Fushuan Wen |
IEEE Trans. Ind. Informatics | 7 |
| 2025 | Fine-Tuning Alignment of Large Language Models via Label Smoothing and Intermediate Contrastive Learning
Zhendong Wu, Qingyun Lin, Hetao Chen |
PRICAI | 2 |
| 2025 | Attention-Inverse Perturbation: A Novel Adversarial Attack Strategy by Targeting Non-Attentive RegionsabstractAdversarial attacks have gained significant research interest for their ability to expose vulnerabilities in deep neural networks. However, current studies on visual adversarial attacks predominantly focus on improving attack efficiency or success rates, typically constraining perturbation magnitudes using lp-norm while overlooking the critical requirement for human imperceptibility of adversarial examples. Although globally minor perturbations are generated, they may introduce localized artifacts (e.g., abnormal brightness or perceptible texture anomalies) that compromise visual stealthiness. To address this issue, we propose an attention-inverse perturbation (AIP) strategy, which restricts perturbations to visually non-attentive regions (e.g., backgrounds) identified through class activation mapping techniques, thereby minimizing visual discrepancies between adversarial and clean examples. Our strategy can be seamlessly integrated into existing attack methods. Extensive experiments demonstrate that the proposed AIP strategy achieves superior performance across perceptual similarity metrics (e.g., MS-SSIM, VIF, and LPIPS) with only marginal trade-offs in attack success rate, offering a practical solution for balancing imperceptibility and attack efficacy. Zhendong Wu, Ling Pang |
TrustCom | 2 |
| 2025 | FAHC: frequency adaptive hypergraph constraint for collaborative filtering
Lilan Peng, Zhendong Wu, Pengfei Zhang 0016, Hongchun Lu |
Appl. Intell. | 3 |
| 2025 | EGRTE: adversarially training a self-explaining smoothed classifier for certified robustnessabstractAbstract Deep learning has transformed fields such as computer vision, natural language processing, and audio analysis through its powerful pattern recognition and predictive capabilities. However, the robustness of these models remains a major concern, as they are highly vulnerable to adversarial attacks-subtle, intentional perturbations that lead to incorrect predictions. While recent defenses like adversarial training and defensive distillation aim to improve robustness, they have notable drawbacks, including overfitting and degraded performance under strong attacks. Certified defenses, such as robust training and Randomized Smoothing, offer theoretical guarantees within a specific perturbation radius, yet struggle to reflect real-world robustness due to efficiency bottlenecks and the unpredictable nature of actual adversarial attacks. These challenges reveal a critical gap between current defenses and real-world attack scenarios, highlighting the need for more practical and resilient solutions. To address the challenges of defense-attack gaps and the inefficiency in robust training, we introduce the Explanation-Guided Robust Training Enhancer (EGRTE). EGRTE combines a self-explaining mechanism, which guides adversarial training to focus on generalized features for improved robustness and accuracy, with a masking mechanism that transforms noised data for easier model learning. This approach not only mitigates noise effects, including adversarial perturbations, but also eliminates the need for time-intensive gradient calculations, greatly enhancing training efficiency. Comprehensive experiments on several datasets show EGRTE’s superior certified accuracy and robustness against adversarial attacks, with a 6.24-fold efficiency increase over comparable methods, positioning EGRTE as a highly effective solution for robust and efficient deep learning. Zijin Lin, Jinwen He, Yue Zhao 0018, Ruigang Liang, Zhendong Wu |
Cybersecur. | 6 |
| 2024 | DPML: Prior-guided multitask learning for dental object recognition on limited panoramic radiograph dataset
Zheng Cao 0005, Chengyu Feng, Yefeng Shen, Guanchen Ye, Jian Wu 0001, Zhendong Wu, Honghao Gao, Haihua Zhu 0002 |
Expert Syst. Appl. | 7 |
| 2024 | The Effect of AR-HUD Takeover Assistance Types on Driver Situation Awareness in Highly Automated Driving: A 360-Degree Panorama ExperimentabstractHuman-machine co-driving presents a significant hurdle in automated driving system. The takeover process in automated driving system involves complex human factors, failure to takeover the vehicle and control driving behavior during the takeover process may lead to severe traffic safety hazards. An augmented reality head-up display (AR-HUD) takeover assistance information can provide real-time assistance information to the driving environment, enhancing drivers’ situation awareness (SA) and takeover decisions in highly automated driving system. This study investigated the impact of different AR-HUD types of takeover assistance information display. Three AR-HUD types, corresponding to the three pre-takeover behavioral processes (perception, understanding, and prediction), were evaluated: PSR (assistance in perceiving the source of risk), AS (assistance in analyzing situations), and MD (assistance in making decisions). The baseline (without assistance information) was used as the control group. In a driving simulation experiment using 360° panoramic video, seventy-nine participants performed SA assessment and visual tracking tasks. Questionnaire and eye-tracking data indicated that the type of AR-HUD displayed positively influenced drivers’ SA and takeover decisions, with AS being the most effective in enhancing SA and improving takeover performance. Additionally, this study compared the differences between the three types of AR-HUD and the baseline under two takeover request lead times (TORlt) of 5 seconds and 7 seconds. It was found that drivers’ SA was lower when TORlt was shorter (with the corresponding AR-HUD display also being shorter). This study provides insight concerning the impact of various types of AR-HUD takeover assistance information display and TORlt on driving safety. The findings support the further optimization of AR-HUD takeover assistance information design. Zhendong Wu, Lintao Zhao, Guocui Liu, Jingchun Chai, Jierui Huang, Xiaoqun Ai |
Int. J. Hum. Comput. Interact. | 1 |
| 2022 | Improving Transferability of Adversarial Examples with Virtual Step and Auxiliary GradientsabstractDeep neural networks have been demonstrated to be vulnerable to adversarial examples, which fool networks by adding human-imperceptible perturbations to benign examples. At present, the practical transfer-based black-box attacks are attracting significant attention. However, most existing transfer-based attacks achieve only relatively limited success rates. We propose to improve the transferability of adversarial examples through the use of a virtual step and auxiliary gradients. Here, the “virtual step” refers to using an unusual step size and clipping adversarial perturbations only in the last iteration, while the “auxiliary gradients” refer to using not only gradients corresponding to the ground-truth label (for untargeted attacks), but also gradients corresponding to some other labels to generate adversarial perturbations. Our proposed virtual step and auxiliary gradients can be easily integrated into existing gradient-based attacks. Extensive experiments on ImageNet show that the adversarial examples crafted by our method can effectively transfer to different networks. For single-model attacks, our method outperforms the state-of-the-art baselines, improving the success rates by a large margin of 12%~28%. Our code is publicly available at https://github.com/mingcheung/Virtual-Step-and-Auxiliary-Gradients. Ming Zhang 0021, Xiaohui Kuang, Zhendong Wu, Yuanping Nie |
IJCAI | 4 |
| 2022 | Semantic key generation based on natural languageabstractIn recent years, the public has become more aware of security concerns, and the demand for convenient and efficient encryption technology has increased. Biological data is used in identity authentication and key generation as the innate characteristic information of people. Biological key have the advantage of convenience and fast application without carrying any document; however, they also have the disadvantage of biological characteristic leaks and the inability to change. Based on the advantages and disadvantages of biological key, we propose the concept of semantic key. Language, a medium that fills the lives of people, has similar characteristics of convenience and fast application as biological key; however, semantic key will not reveal biological information. As the amount of semantic information is large, it can be changed at any time. Compared with biological key, it provides better security and flexibility. Therefore, we propose a semantic key generation framework of semantic extraction + feature stabilization + fuzzy extraction that improves the existing semantic extraction model and feature stabilization model and design the semantic key extraction model. In terms of artificial sentence formation, semantic key can be extracted with an accuracy of more than 99%, and an error rate of less than 0.5%. Zhendong Wu |
Int. J. Intell. Syst. | 1 |
| 2022 | Fingerprint bio-key generation based on a deep neural networkabstractWith the increasing use of biometric identity authentication, biological key generation technology is receiving much attention. A high-strength key that is easy to store and manage can be generated from biological characteristics, which can improve the convenience and security of user-encryption operations. However, the generation of a high-strength, stable, and robust key using the currently available fingerprint bio-key generation technology is difficult. This paper proposes a three-layer framework for fingerprint bio-key generation that is composed of a fingerprint bio-key preprocessor, fingerprint bio-key stabilizer (FPBK_Stabilizer), and fingerprint bio-key fuzzy extractor. In the FPBK_Stabilizer, feature selection and layer-by-layer convolution projection characteristics from deep neural networks are used to effectively eliminate the instability between fingerprint samples. Furthermore, a suitable multilayer convolutional projection fingerprint bio-key generation model is designed for generating the fingerprint bio-key. The results of a fingerprint bio-key generation experiment involving a fingerprint library comprising 100 people verified the efficacy of the proposed framework. Specifically, the proposed framework exhibited a generation intensity >1024 bits, accuracy rate >98.0%, and misrecognition rate <1.5%, thereby verifying its high-strength, stable, and robust fingerprint bio-key generation capability. Zhendong Wu, Zhengyin Lv, Wenqian Ding, Jianwu Zhang |
Int. J. Intell. Syst. | 1 |
| 2020 | Non-norm-bounded Attack for Generating Adversarial Examples
Ming Zhang 0021, Xiaohui Kuang, Yuanping Nie, Zhendong Wu |
ICONIP (5) | 6 |
| 2020 | A network intrusion detection method based on semantic Re-encoding and deep learning
Zhendong Wu, Liqin Hu |
J. Netw. Comput. Appl. | 1 |
| 2019 | Neuron Selecting: Defending Against Adversarial Examples in Deep Neural Networks
Ming Zhang 0021, Xiaohui Kuang, Ling Pang, Zhendong Wu |
ICICS | 5 |
| 2018 | User Password Intelligence Enhancement by Dynamic Generation Based on Markov Model
Zhendong Wu, Yihang Xia |
ICA3PP (4) | 1 |
| 2018 | Generating stable biometric keys for flexible cloud computing authentication using finger vein
Zhendong Wu, Longwei Tian, Ping Li 0018, Ting Wu 0001, Ming Jiang 0009, Chunming Wu 0001 |
Inf. Sci. | 1 |
| 2018 | Multibiometric Fusion Authentication in Wireless Multimedia Environment Using Dynamic Bayesian MethodabstractSingle biometric method has been widely used in the field of wireless multimedia authentication. However, it is vulnerable to spoofing and limited accuracy. To tackle this challenge, in this paper, we propose a multimodal fusion method for fingerprint and voiceprint by using a dynamic Bayesian method, which takes full advantage of the feature specificity extracted by a single biometrics project and authenticates users at the decision-making level. We demonstrate that this method can be extended to more modal biometric authentication and can achieve flexible accuracy of the authentication. The experiment of the method shows that the recognition rate and stability have been greatly improved, which achieves 4.46% and 5.94%, respectively, compared to the unimodal. Furthermore, it also increases 1.94% when compared with general multimodal methods for the biometric fusion recognition. Zhendong Wu, Jianwu Zhang, Hengli Yue |
Secur. Commun. Networks | 1 |
| 2018 | GMM and CNN Hybrid Method for Short Utterance Speaker RecognitionabstractDuring the last few years, the speaker recognition technique has been widely attractive for its extensive application in many fields, such as speech communications, domestics services, and smart terminals. As a critical method, the Gaussian mixture model (GMM) makes it possible to achieve the recognition capability that is close to the hearing ability of human in a long speech. However, the GMM is failing to recognize a short utterance speaker with a high accuracy. Aiming at solving this problem, in this paper, we propose a novel model to enhance the recognition accuracy of the short utterance speaker recognition system. Different from traditional models based on the GMM, we design a method to train a convolutional neural network to process spectrograms, which can describe speakers better. Thus, the recognition system gains the considerable accuracy as well as the reasonable convergence speed. The experiment results show that our model can help to decrease the equal error rate of the recognition from 4.9% to 2.5%. Zheli Liu, Zhendong Wu, Tong Li 0011, Jin Li 0002, Chao Shen 0001 |
IEEE Trans. Ind. Informatics | 2 |
| 2017 | Surveying concurrency bug detectors based on types of detected bugs
Zhendong Wu, Kai Lu 0001 |
Sci. China Inf. Sci. | 1 |
| 2016 | High-dimension space projection-based biometric encryption for fingerprint with fuzzy minutia
Zhendong Wu, Lin You, Zhihua Jian, Jin Li 0002 |
Soft Comput. | 1 |
| 2016 | A twice face recognition algorithm
Zhendong Wu, Zipeng Yu, Jianwu Zhang |
Soft Comput. | 1 |
| 2015 | Identifying Repeated Interleavings to Improve the Efficiency of Concurrency Bug Detection
Zhendong Wu, Kai Lu 0001 |
ICA3PP (4) | 1 |
| 2015 | RaceChecker: Efficient Identification of Harmful Data RacesabstractData races hidden in concurrent programs have caused severe failures. To improve the reliability, many race detectors are proposed. However, most of the reported races are not harmful, which consumes manual effort to identify the harmful races. This paper proposes RaceChecker that can detect the potential races and identify the harmful races effectively and efficiently. Unlike previous detectors, RaceChecker combines happens-before relation and ad-hoc synchronization to prune the infeasible races so that fewer potential races are required to be verified. Before verification, RaceChecker groups the remaining potential races, guaranteeing the potential races in one group do not interfere with each other. Therefore, multiple potential races in one group can be verified together in one execution. To our knowledge, this is the first effective technique that groups the potential races to improve the efficiency. Unlike previous detectors that verify one potential race in one execution, RaceChecker dynamically controls thread scheduler to create real race conditions to verify multiple potential races in one execution, identifying the harmful races that cause program failures. We have implemented RaceChecker as a prototype tool and have experimented on a number of real-world concurrent programs. Results show that 66% of the potential races are infeasible and nearly 48% of the executions are reduced by the grouping strategy. The known harmful races are also identified effectively. By pruning and grouping, RaceChecker identifies the harmful races more efficiently. Comparing with RaceMob and RaceFuzzer, the time is reduced significantly, with an average of 45% and 81% respectively. Kai Lu 0001, Zhendong Wu, Chen Chen 0016, Xu Zhou 0004 |
PDP | 2 |
| 2015 | E-Diophantine estimating peak allocated capacity in wireless networks
Xavier Pérez Costa, Zhendong Wu, Marco Mezzavilla, José Roberto Boisson de Marca, Julio Aráuz |
Comput. Commun. | 2 |
| 2015 | Detecting harmful data races through parallel verification
Zhendong Wu, Kai Lu 0001, Xu Zhou 0004, Chen Chen 0016 |
J. Supercomput. | 1 |