VLDB 2026 Research / reviewers in the wild / expert
Yang Xu 0021
dblp:61/3906-21
· DBLP profile ↗
6ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0001-6870-2824ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SAB:A stealing and robust backdoor attack based on steganographic algorithm against federated learning
Weida Xu, Yang Xu 0021, Sicong Zhang |
J. Inf. Secur. Appl. | 2 |
| 2026 | C/R-PMGAN: A dual-path self-supervised and patch-masked generative adversarial network for transferable black-box attack
Zihan Peng, Yang Xu 0021, Sicong Zhang, Yuanlei Yang |
Neural Networks | 2 |
| 2025 | Universal Adversarial Perturbations Against Machine-Learning-Based Intrusion Detection Systems in Industrial Internet of ThingsabstractThe security of the Industrial Internet of Things (IIoT) has emerged as a prominent concern in cyber-security due to the potential impact of attacks against IIoT on physical infrastructure. Machine learning (ML)-based intrusion detection systems (IDSs) recently have been demonstrated to be an effective tool for protecting the systems in IIoT. However, the vulnerability of ML-based IDSs to adversarial attacks hinders their further application in IIoT. This article aims to further explore the adversarial attacks in IIoT to better evaluate the security of ML-based IDSs in this area. Our research primarily focuses on the generation of universal adversarial perturbations in IIoT, a topic that received limited attention in previous literature. Two novel attack methods based on a unified framework are proposed to utilize the original input-dependent adversarial perturbations of gradient-based or optimization-based adversarial attack methods to craft universal adversarial perturbations with better performance and transferability. The proposed attack methods conceal the underlying implementation details of the target attack methods, exploiting the original adversarial perturbations in a closed-box manner. This enhances their flexibility, making them applicable in a wider range of scenarios and enabling them to be combined with most gradient-based or optimization-based attack methods. Comprehensive experiments are conducted on three mainstream intrusion detection data sets, i.e., NSL-KDD, Gas Pipeline, and edge-IIoTset, to validate the effectiveness of the proposed methods. The preliminary experimental results demonstrate the feasibility of universal adversarial perturbations in IIoT and the superiority of the proposed methods to state-of-the-art attack methods. Sicong Zhang, Yang Xu 0021, Xiaoyao Xie |
IEEE Internet Things J. | 2 |
| 2024 | Amplification methods to promote the attacks against machine learning-based intrusion detection systems
Sicong Zhang, Yang Xu 0021, Xiaoyao Xie |
Appl. Intell. | 2 |
| 2021 | SFRNet: Feature Extraction-Fusion Steganalysis Network Based on Squeeze-and-Excitation Block and RepVgg BlockabstractIn the era of big data, convolutional neural network (CNN) has been widely used in the field of image classification and has achieved excellent performance. More and more researchers are beginning to combine deep neural networks with steganalysis to improve performance in recent years. However, most of the steganalysis algorithm based on the convolutional neural network has only run test against the WOW and S-UNIWARD algorithms; meanwhile, their versatility is insufficient due to long training time and the limit of image size. This paper proposes a new network architecture, called SFRNet, to solve these problems. The feature extraction and fusion layer can extract more features from the digital image. The RepVgg block is used to accelerate the inference and increase memory utilization. The SE block improves the detection accuracy rate because it can learn feature weights to make effective feature maps with significant weights and invalid or ineffective feature maps with small weights. Experimental results show that the SFRNet has achieved excellent performance in the detection accuracy rate against four state-of-the-art steganography algorithms in the spatial domain, e.g., HUGO, WOW, S-UNIWARD, and MiPOD, under different payloads. The SFRNet detection accuracy rate achieves 89.6% against S-UNIWARD algorithm with the payload of 0.4bpp and 72.5% at 0.2bpp. As the same time, the training time of our network is greatly reduced by 35% compared with Yedroudj-Net. Guiyong Xu, Yang Xu 0021, Sicong Zhang, Xiaoyao Xie |
Secur. Commun. Networks | 2 |
| 2020 | DRHNet: A Deep Residual Network Based on Heterogeneous Kernel for SteganalysisabstractConvolutional neural networks as steganalysis have problems such as poor versatility, long training time, and limited image size. For these problems, we present a heterogeneous kernel residual learning framework called DRHNet—Dual Residual Heterogeneous Network—to save time on the networks during the training phase. Instead of using the image as an input of the network, we extract and merge the images into a feature matrix using the rich model and use the generated feature matrix as the real input of the network. The architecture we proposed has good versatility and can reduce the computation and the number of parameters while still getting higher accuracy. On BOSSbase 1.01, we evaluate the performance of DRHNet in the setting of the spatial domain and frequency domain. The preliminary experimental results show that DRHNet shows excellent steganalysis performance against the state-of-the-art steganographic algorithms. Yang Xu 0021, Zixi Fu, Guiyong Xu, Sicong Zhang, Xiaoyao Xie |
Secur. Commun. Networks | 1 |