VLDB 2026 Research / reviewers in the wild / expert
Hao Yu 0017
dblp:64/4832-17
· DBLP profile ↗
24ranked-venue papers
6as first author
24since 2021 · last 2026
0000-0001-9044-4841ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 9 · 2 first-author · 9 since 2021Security and privacy · 9 · 3 first-author · 9 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Make Model Transparent: Brain Network Analysis via Causal and Knowledge Graph LearningabstractBrain network analysis technology reveals the organizational mechanism and information processing mode by constructing the structural connection network between brain regions. It has achieved satisfactory results in brain disease prediction tasks, promoting the progress of neuroscience. In recent years, graph transformer has become the most mainstream method for brain analysis with its powerful feature extraction ability and attention mechanism. However, these methods face two challenges, i.e., lack of interpretability, and neglect of semantic associations among brain regions. To solve these problems, we proposed a large language model (LLM)-driven causal knowledge brain network transformer framework, termed BrainCKT, which is plug-and-play, and can adapt to most of the existing mainstream graph transformer-based methods. Specifically, we constructed a brain region causal graph and used its adjacency matrix to guide the learning process of the self-attention mechanism. In addition, we constructed a brain science knowledge graph and encoded it through a pre-trained model to enhance the original brain region features. Finally, we integrated BrainCKT into four mainstream graph transformer baselines for verification. Experimental results on two brain imaging datasets proved the effectiveness of BrainCKT. Lingyuan Meng, Ke Liang 0006, Hao Yu 0017, Haotian Wang 0001, Miaomiao Li 0001, Xinwang Liu 0002 |
AAAI | 3 |
| 2026 | TVChain: Leveraging Textual-Visual Prompt Chains for Jailbreaking Large Vision-Language ModelsabstractLarge Vision-Language Models (LVLMs) enhance the capabilities of Large Language Models by integrating visual inputs, thereby enabling advanced multimodal reasoning across diverse applications. However, these enhanced reasoning capabilities introduce new security risks, particularly to jailbreaking attacks that bypass built-in safety mechanisms to elicit harmful or unauthorized outputs. While recent efforts have explored adversarial and typographic prompts, most existing attacks suffer from three key limitations: reliance on auxiliary models, limited effectiveness in black-box scenarios, and inadequate exploitation of the LVLMs' intrinsic reasoning abilities. In this work, we propose TVChain, a novel black-box jailbreaking framework that explicitly intervenes in both the visual and textual reasoning processes of LVLMs. TVChain decomposes malicious prompts into a sequence of semantically meaningful sub-images that represent relevant objects and behaviors, thereby circumventing direct exposure of illicit content. In parallel, a carefully designed chain-of-thought (CoT) textual prompt is employed to steer the model's reasoning toward reconstructing the intended activity in a covert yet effective manner. We demonstrate that this compositional prompting strategy reduces the likelihood of triggering safety mechanisms while preserving attack efficacy. Extensive evaluations on eleven LVLMs (seven open-source and four commercial) across two benchmark datasets and three state-of-the-art defenses validate the effectiveness and robustness of TVChain. Hao Yu 0017, Ke Liang 0006, Junxian Duan, Jun Wang 0118, Siwei Wang 0001, Chuan Ma 0001, Xinwang Liu 0002 |
AAAI | 1 |
| 2026 | Constructive Noise Defeats Adversarial Noise: Adversarial Example Detection for Commercial DNN Services
Meng Shen 0001, Jiangyuan Bi, Hao Yu 0017, Zhenming Bai, Wei Wang 0012, Liehuang Zhu |
NDSS | 3 |
| 2026 | Explainability-Guided Untargeted Attacks on Knowledge Graph Embedding
Yawei Lin, Hao Yu 0017, Ke Liang 0006, Mengzhu Wang, Liang Yang 0002, Xinwang Liu 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | G2uardFL: Safeguarding Federated Learning Against Backdoor Attacks via Attributed Client Graph ClusteringabstractFederated Learning (FL) offers collaborative model training across multiple decentralized devices without the need to share data directly, enhancing privacy and data security. However, FL systems are susceptible to backdoor attacks, where malicious clients inject poisoned weights during training. Existing defenses, primarily based on anomaly detection, are prone to erroneous rejections of normal weights while accepting poisoned ones, largely due to shortcomings in quantifying similarities among client models. Furthermore, other defenses demonstrate effectiveness only when dealing with a limited number of malicious clients, typically fewer than 10%. To alleviate these vulnerabilities, we present G2uardFL, a protective framework that translates the detection of malicious clients into an attributed graph clustering problem, thus safeguarding FL systems. Specifically, this framework employs a client graph clustering approach to identify malicious clients and integrates an adaptive mechanism to amplify the discrepancy between the aggregated model and the poisoned ones, effectively eliminating embedded backdoors. Through empirical evaluation, comparing G2uardFL with cutting-edge defenses, such as FLAME (USENIX Security 2022) [37] and DeepSight (NDSS 2022) [43], against various backdoor attacks, including 3DFed (SP 2023) [26], our results demonstrate its significant effectiveness in mitigating backdoor attacks while having a negligible impact on the aggregated model’s performance on benign samples (i.e., the primary task performance). For instance, in an FL system with 25% malicious clients, G2uardFL reduces the attack success rate to 10.61%, while maintaining a primary task performance of 80.98% on the CIFAR-10 dataset. This surpasses the performance of the best-performing baseline, which merely achieves the attack success rate of 19.54%. Hao Yu 0017, Chuan Ma 0001, Meng Liu 0014, Tianyu Du, Ming Ding 0001, Tao Xiang 0001, Shouling Ji, Xinwang Liu 0002 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2026 | A Wolf in Sheep's Clothing: Unveiling a Stealthy Backdoor Attack in Subgraph Federated LearningabstractSubgraph Federated Learning (FL) has emerged as a promising paradigm for node classification tasks wherein subgraphs derived from a global graph are distributed across multiple devices to mitigate data leakage risks. Similar to other FL systems, subgraph FL faces significant security challenges, particularly from backdoor attacks, an area that remains extensively underexplored. Existing attacks typically follow a two-phase strategy to implant backdoors. However, in subgraph FL, such attacks often lead toDivergence Amplification, a phenomenon characterized by significant parameter discrepancies between normal and backdoored models, thereby compromising attack stealthiness. To tackle this challenge, we propose BEEF, a Backdoor attack with an End-to-End Framework designed for effectiveness, stealth, and durability. Unlike conventional methods, BEEF incorporates a dedicated trigger generator, which is jointly trained with a backdoored model. To increase its stealthiness, BEEF crafts adversarial perturbations as triggers that provoke misclassification while leaving the model’s parameters entirely untouched. Furthermore, by calibrating a subset of low-salience parameters associated with backdoor activation, BEEF ensures stable performance and sustained effectiveness across FL rounds. Comprehensive evaluations across eight datasets, four models, five state-of-the-art attacks, and six aggregation methods demonstrate BEEF’s effectiveness in deceiving GNNs while maintaining minimal impact on normal data performance. Additionally, we adapt BEEF to federated graph classification tasks, broadening its applicability and practicality. Hao Yu 0017, Wenjing Yang 0002, Chuan Ma 0001, Lingyuan Meng, Liang Du 0003, Tao Xiang 0001, Xinwang Liu 0002, Kunlun He |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2026 | Tensor Multi-Rank Constraint Guided Anchor-Wise Adaptive Alignment for Multi-View ClusteringabstractAnchor graph learning has become a widely used technique for significantly reducing the computational complexity in existing multi-view clustering methods. However, most existing approaches select anchors independently for each view and then generate the consensus graph by directly fusing all anchor graphs. This process overlooks the correspondence between anchor sets across different views, i.e., the column order correspondence of the anchor graphs. To address this limitation, we propose a novel anchor-based tensor multi-rank constraint multi-view clustering method (TMC). Specifically, TMC captures the high-order structural information of the original data by constructing an anchor graph tensor and enforcing a multi-rank constraint to induce a block-diagonal structure. Additionally, to enhance anchor consistency across all view, we construct the anchor graph of each view into an anchor tensor and impose a low-rank constraint on it. In this way, the block-diagonal structure of each anchor graph maintains an approximate alignment between anchors. Furthermore, we provide theoretical proof that the generated anchor graphs inherently exhibit a block-diagonal structure. Extensive experimental results on six multi-view datasets demonstrate that TMC outperforms existing state-of-the-art methods, highlighting its effectiveness in multi-view clustering task. Jun Wang 0118, Miaomiao Li 0001, Zhenglai Li, Hao Yu 0017, Suyuan Liu, Dayu Hu, Chang Tang, Xinwang Liu 0002 |
IEEE Trans. Knowl. Data Eng. | 4 |
| 2025 | On the Adversarial Robustness of Multi-Kernel ClusteringabstractMulti-kernel clustering (MKC) has emerged as a powerful method for capturing diverse data patterns, offering robust and generalized representations of data structures. However, the increasing deployment of MKC in real-world applications raises concerns about its vulnerability to adversarial perturbations. While adversarial robustness has been extensively studied in other domains, its impact on MKC remains largely unexplored. In this paper, we address the challenge of assessing the adversarial robustness of MKC methods in a black-box setting. Specifically, we propose *AdvMKC*, a novel reinforcement-learning-based adversarial attack framework designed to inject imperceptible perturbations into data and mislead MKC methods. AdvMKC leverages proximal policy optimization with an advantage function to overcome the instability of clustering results during optimization. Additionally, it introduces a generator-clusterer framework, where a generator produces adversarial perturbations, and a clusterer approximates MKC behavior, significantly reducing computational overhead. We provide theoretical insights into the impact of adversarial perturbations on MKC and validate these findings through experiments. Evaluations across seven datasets and eleven MKC methods (seven traditional and four robust) demonstrate AdvMKC's effectiveness, robustness, and transferability. Hao Yu 0017, Weixuan Liang, Ke Liang 0006, Suyuan Liu, Meng Liu 0014, Xinwang Liu 0002 |
ICML | 1 |
| 2025 | Efficient Federated Incomplete Multi-View ClusteringabstractMulti-view clustering (MVC) leverages complementary information from diverse data sources to enhance clustering performance. However, its practical deployment in distributed and privacy-sensitive scenarios remains challenging. Federated multi-view clustering (FMVC) has emerged as a potential solution, but existing approaches suffer from substantial limitations, including excessive communication overhead, insufficient privacy protection, and inadequate handling of missing views. To address these issues, we propose Efficient Federated Incomplete Multi-View Clustering (EFIMVC), a novel framework that introduces a localized optimization strategy to significantly reduce communication costs while ensuring theoretical convergence. EFIMVC employs both view-specific and shared anchor graphs as communication variables, thereby enhancing privacy by avoiding the transmission of sensitive embeddings. Moreover, EFIMVC seamlessly extends to scenarios with missing views, making it a practical and scalable solution for real-world applications. Extensive experiments on benchmark datasets demonstrate the superiority of EFIMVC in clustering accuracy, communication efficiency, and privacy preservation. Our code is publicly available at https://github.com/Tracesource/EFIMVC. Suyuan Liu, Hao Yu 0017, Ke Liang 0006, Siwei Wang 0001, Shengju Yu, En Zhu, Xinwang Liu 0002 |
ICML | 2 |
| 2025 | DShield: Defending against Backdoor Attacks on Graph Neural Networks via Discrepancy Learning
Hao Yu 0017, Chuan Ma 0001, Xinhang Wan, Jun Wang 0118, Tao Xiang 0001, Meng Shen 0001, Xinwang Liu 0002 |
NDSS | 1 |
| 2025 | Scalable Cross-View Sample Alignment for Multi-View Clustering with View Structure SimilarityabstractMost existing multi-view clustering methods aim to generate a consensus partition across all views, based on the assumption that all views share the same sample arrangement. However, in real-world scenarios, the collected data across different views is often unsynchronized, making it difficult to ensure consistent sample correspondence between views. To address this issue, we propose a scalable sample-alignment-based multi-view clustering method, referred to as SSA-MVC. Specifically, we first employ a cluster-label matching (CLM) algorithm to select the view whose clustering labels best match those of the others as the benchmark view. Then, for each of the remaining views, we construct representations of non-aligned samples by computing their similarities with aligned samples. Based on these representations, we build a similarity graph between the non-aligned samples of each view and those in the benchmark view, which serves as the alignment criterion. This alignment criterion is then integrated into a late-fusion framework to enable clustering without requiring aligned samples. Notably, the learned sample alignment matrix can be used to enhance existing multi-view clustering methods in scenarios where sample correspondence is unavailable. The effectiveness of the proposed SSA-MVC algorithm is validated through extensive experiments conducted on eight real-world multi-view datasets. Jun Wang 0118, Zhenglai Li, Chang Tang, Suyuan Liu, Hao Yu 0017, Chuan Tang, Miaomiao Li 0001, Xinwang Liu 0002 |
NeurIPS | 5 |
| 2025 | GZOO: Black-Box Node Injection Attack on Graph Neural Networks via Zeroth-Order OptimizationabstractThe ubiquity of Graph Neural Networks (GNNs) emphasizes the imperative to assess their resilience against node injection attacks, a type of evasion attacks that impact victim models by injecting nodes with fabricated attributes and structures. However, prevailing attacks face two primary limitations: (1) Sequential construction of attributes and structures results in suboptimal outcomes as structure information is overlooked during attribute construction and vice versa. (2) In black-box scenarios, where attackers lack access to victim model architecture and parameters, reliance on surrogate models degrades performance due to architectural discrepancies. To overcome these limitations, we introduce GZOO, a black-box node injection attack that leverages an adversarial graph generator, compromising both attribute and structure sub-generators. This integration crafts optimal attributes and structures by considering their mutual information, enhancing their influence when aggregating information from injected nodes. Furthermore, GZOO proposes a zeroth-order optimization algorithm leveraging prediction results from victim models to estimate gradients for updating generator parameters, eliminating the necessity to train surrogate models. Across sixteen datasets, GZOO significantly outperforms state-of-the-art attacks, achieving remarkable effectiveness and robustness. Notably, on the Cora dataset with the GCN model, GZOO achieves an impressive 95.69% success rate, surpassing the maximum 66.01% achieved by baselines. Hao Yu 0017, Ke Liang 0006, Dayu Hu, Wenxuan Tu, Chuan Ma 0001, Sihang Zhou 0001, Xinwang Liu 0002 |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2025 | Multiview Temporal Graph ClusteringabstractAs an emerging task, temporal graph clustering (TGC) is committed to clustering nodes on temporal graphs through interaction sequence-based batch-processing patterns. These patterns allow for more flexibility in finding a balance between time and space requirements than adjacency matrix-based static graph clustering. However, as a new task, TGC still has important unresolved challenges, such as insufficient information. This challenge manifests itself in a variety of problems in real-world datasets, including missing features (eigenvalues are missing or even nonexistent), long-tail nodes (most inactive nodes have little interaction), and noisy data (data is subject to anomalies, errors, and sparsity). These problems occur before training, making it difficult for the model to train well with insufficient information. To solve the challenge, we propose a method that introduces multiview clustering (MVC) into TGC, called MVTGC. Our method aims to perform data augmentation on the temporal graph by constructing multiple views to increase the information richness. In particular, we utilize different techniques to model a certain part of the temporal graph to generate enhanced views focusing on different angles. These views are combined into training through early fusion and late fusion and ultimately enhance the model's receptive field and information richness. Comparative experiments and a case study on real-world datasets demonstrate the significance and effectiveness of MVTGC, which achieves at most 10.48% performance improvement. The code and data are available at https://github.com/MGitHubL/MVTGC. Meng Liu 0014, Ke Liang 0006, Hao Yu 0017, Lingyuan Meng, Siwei Wang 0001, Sihang Zhou 0001, Xinwang Liu 0002 |
IEEE Trans. Neural Networks Learn. Syst. | 3 |
| 2025 | Contrastive Continual Multiview Clustering With Filtered Structural FusionabstractMultiview clustering thrives in applications where views are collected in advance by extracting consistent and complementary information among views. However, it overlooks scenarios where data views are collected sequentially, i.e., real-time data. Due to privacy issues or memory burden, previous views are not available with time in these situations. Some methods are proposed to handle it but are trapped in a stability-plasticity dilemma. In specific, these methods undergo a catastrophic forgetting of prior knowledge when a new view is attained. Such a catastrophic forgetting problem (CFP) would cause the consistent and complementary information hard to get and affect the clustering performance. To tackle this, we propose a novel method termed contrastive continual multiview clustering with filtered structural fusion (CCMVC-FSF). Precisely, considering that data correlations play a vital role in clustering and prior knowledge ought to guide the clustering process of a new view, we develop a data buffer to store filtered structural information and utilize it to guide the generation of a robust partition matrix via contrastive learning. Additionally, to address the high complexity involved in acquiring and storing structural information, we propose a sampling strategy called clustering then sample. Furthermore, we theoretically connect CCMVC-FSF with semisupervised learning and knowledge distillation. Extensive experiments exhibit the excellence of the proposed method. Our code is publicly available at https://github.com/wanxinhang/CCMVC-FSF/. Xinhang Wan, Jiyuan Liu 0003, Hao Yu 0017, Qian Qu, Ao Li 0002, Xinwang Liu 0002, Ke Liang 0006, Zhibin Dong, En Zhu |
IEEE Trans. Neural Networks Learn. Syst. | 3 |
| 2024 | Decouple then Classify: A Dynamic Multi-view Labeling Strategy with Shared and Specific InformationabstractSample labeling is the most primary and fundamental step of semi-supervised learning. In literature, most existing methods randomly label samples with a given ratio, but achieve unpromising and unstable results due to the randomness, especially in multi-view settings. To address this issue, we propose a Dynamic Multi-view Labeling Strategy with Shared and Specific Information. To be brief, by building two classifiers with existing labels to utilize decoupled shared and specific information, we select the samples of low classification confidence and label them in high priorities. The newly generated labels are also integrated to update the classifiers adaptively. The two processes are executed alternatively until a satisfying classification performance. To validate the effectiveness of the proposed method, we conduct extensive experiments on popular benchmarks, achieving promising performance. The code is publicly available at https://github.com/wanxinhang/ICML2024_decouple_then_classify. Xinhang Wan, Jiyuan Liu 0003, Xinwang Liu 0002, Yi Wen 0001, Hao Yu 0017, Siwei Wang 0001, Shengju Yu, Tianjiao Wan, Jun Wang 0118, En Zhu |
ICML | 5 |
| 2024 | scEGG: an exogenous gene-guided clustering method for single-cell transcriptomic dataabstractIn recent years, there has been significant advancement in the field of single-cell data analysis, particularly in the development of clustering methods. Despite these advancements, most algorithms continue to focus primarily on analyzing the provided single-cell matrix data. However, within medical contexts, single-cell data often encompasses a wealth of exogenous information, such as gene networks. Overlooking this aspect could result in information loss and produce clustering outcomes lacking significant clinical relevance. To address this limitation, we introduce an innovative deep clustering method for single-cell data that leverages exogenous gene information to generate discriminative cell representations. Specifically, an attention-enhanced graph autoencoder has been developed to efficiently capture topological signal patterns among cells. Concurrently, a random walk on an exogenous protein-protein interaction network enabled the acquisition of the gene's embeddings. Ultimately, the clustering process entailed integrating and reconstructing gene-cell cooperative embeddings, which yielded a discriminative representation. Extensive experiments have demonstrated the effectiveness of the proposed method. This research provides enhanced insights into the characteristics of cells, thus laying the foundation for the early diagnosis and treatment of diseases. The datasets and code can be publicly accessed in the repository at https://github.com/DayuHuu/scEGG. Dayu Hu, Renxiang Guan, Ke Liang 0006, Hao Yu 0017, Hao Quan 0004, Xinwang Liu 0002, Kunlun He |
Briefings Bioinform. | 4 |
| 2024 | Decision-Based Query Efficient Adversarial Attack via Adaptive Boundary LearningabstractDecision-based adversarial attacks pose a severe threat to real-world applications of Deep Neural Networks (DNNs), as attackers are assumed to have no prior knowledge about target model except hard labels of model outputs. Existing decision-based attacks require a large number of queries on the target model for a successful attack. In this paper, we propose DEAL, a decision-based query efficient adversarial attack based on adaptive boundary learning. DEAL relies on a local model named boundary learner, which is initialized through meta-learning mechanism to obtain the ability to adapt the decision boundaries to a new model. We conduct extensive experiments to evaluate the effectiveness of DEAL, which demonstrates that it outperforms 8 state-of-the-art attacks. Specifically for the evaluation on CIFAR-10 dataset, DEAL can achieve similar attack success rates with a maximum reduction in average number of queries of 51% in untargeted attacks and 14% in targeted attacks, respectively. Meng Shen 0001, Changyue Li, Hao Yu 0017, Qi Li 0002, Liehuang Zhu, Ke Xu 0002 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | High-order Topology for Deep Single-Cell Multiview Fuzzy ClusteringabstractSingle-cell multi-view clustering is essential for analyzing the different cell subtypes of the same cell from different views. Some attempts have been made, but most of these models still struggle to handle single-cell sequencing data, primarily due to their non-specific design for cellular data. We observe that such data distinctively exhibits: (1) a profusion of high-order topological correlations, (2) a disparate distribution of information across different views, and (3) inherent fuzzy characteristics, indicating a cell's potential to associate with multiple cluster identities. Neglecting these key cellular patterns could significantly impair medical clustering. In response, we propose a specialized application of fuzzy clustering for single-cell sequencing data, namely the deep Single-cell Multi-view Fuzzy Clustering (scMFC) method. Concretely, we employ a random walk technique to capture high-order topological relationships on the cell graph and have developed a cross-view information aggregation mechanism that adaptively assigns weights to different views. Furthermore, to accurately reflect the dynamic insight in cellular development, we propose a deep fuzzy clustering strategy that allows cells to associate with diverse clusters. Extensive experiments conducted on three real-world single-cell multi-view datasets demonstrate our method's superior performance. Dayu Hu, Zhibin Dong, Ke Liang 0006, Hao Yu 0017, Siwei Wang 0001, Xinwang Liu 0002 |
IEEE Trans. Fuzzy Syst. | 4 |
| 2024 | Spatial-Spectral Graph Contrastive Clustering With Hard Sample Mining for Hyperspectral ImagesabstractHyperspectral image (HSI) clustering is a fundamental yet challenging task that groups image pixels with similar features into distinct clusters. Among various approaches, contrastive learning methods, which employ the concept of encouraging semantically similar samples to move closer together while pushing semantically inconsistent samples apart, have garnered significant attention due to their promising performance. However, the most prevalent approaches face two major limitations: 1) treating all samples indiscriminately during optimization, where the abundance of well-categorized samples overwhelms the feature learning process and 2) tending to introduce noise when constructing positive sample pairs through view augmentation or searching the nearest neighbors, which would cause semantic drift of sample features. To solve these issues, we propose a graph autoencoder-based deep clustering framework named spatial–spectral graph contrastive clustering with hard sample mining (SSGCC) that constructs spatial–spectral dual views without data augmentation and focuses more on hard samples rather than treating all samples equally with the aid of spatial–spectral features. Concretely, we extract the spectral features and the neighborhood spatial features of the samples as dual branches to avoid the noise caused by data augmentation and develop the cluster-oriented consistency learning to facilitate the exchange of knowledge between the two spectral–spatial perspectives. In addition, we propose a hard sample mining-based contrastive learning scheme with the aid of spatial–spectral features. To better measure the importance of the samples, we combine spatial features and spectral features to calculate the similarity between sample pairs. The weights of hard sample pairs are dynamically up-weight while the easy ones are down-weighting to improve the discriminative capability. Extensive experiments on four benchmark HSI datasets demonstrate the effectiveness and superiority of the proposed methods against state-of-the-art ones. Renxiang Guan, Wenxuan Tu, Hao Yu 0017, Dayu Hu, Yuzeng Chen, Chang Tang, Qiangqiang Yuan, Xinwang Liu 0002 |
IEEE Trans. Geosci. Remote. Sens. | 4 |
| 2024 | FedEAN: Entity-Aware Adversarial Negative Sampling for Federated Knowledge Graph ReasoningabstractFederated knowledge graph reasoning (FedKGR) aims to perform reasoning over different clients while protecting data privacy, drawing increasing attention to its high practical value. Previous works primarily focus on data heterogeneity, ignoring challenges from limited data scale and primitive negative sample strategies, i.e., random entity replacement, which yield low-quality negatives and zero loss issues. Meanwhile, generative adversarial networks (GANs) are widely used in different fields to generate high-quality negative samples, but no work has been developed for FedKGR. To this end, we propose a plug-and-playEntity-awareAdversarialNegative sampling strategy for FedKGR, termed FedEAN. Specifically, we are the first to adopt GANs to generate high-quality negative samples in different clients. It takes the target triplet in each batch as input and outputs high-quality negative samples, which guaranteed by the joint training of the generator and discriminator. Moreover, we design an entity-aware adaptive negative sampling mechanism based on the similarity of entity representations before and after server aggregation, which can persevere the entity global consistency across clients during training. Extensive experiments demonstrate that FedEAN excels with various FedKGR backbones, demonstrating its ability to construct high-quality negative samples and address the zero-loss issue. Lingyuan Meng, Ke Liang 0006, Hao Yu 0017, Yue Liu 0008, Sihang Zhou 0001, Meng Liu 0014, Xinwang Liu 0002 |
IEEE Trans. Knowl. Data Eng. | 3 |
| 2023 | TMac: Temporal Multi-Modal Graph Learning for Acoustic Event ClassificationabstractAudiovisual data is everywhere in this digital age, which raises higher requirements for the deep learning models developed on them. To well handle the information of the multi-modal data is the key to a better audiovisual modal. We observe that these audiovisual data naturally have temporal attributes, such as the time information for each frame in the video. More concretely, such data is inherently multi-modal according to both audio and visual cues, which proceed in a strict chronological order. It indicates that temporal information is important in multi-modal acoustic event modeling for both intra- and inter-modal. However, existing methods deal with each modal feature independently and simply fuse them together, which neglects the mining of temporal relation and thus leads to sub-optimal performance. With this motivation, we propose a Temporal Multi-modal graph learning method for Acoustic event Classification, called TMac, by modeling such temporal information via graph learning techniques. In particular, we construct a temporal graph for each acoustic event, dividing its audio data and video data into multiple segments. Each segment can be considered as a node, and the temporal relationships between nodes can be considered as timestamps on their edges. In this case, we can smoothly capture the dynamic information in intra-modal and inter-modal. Several experiments are conducted to demonstrate TMac outperforms other SOTA models in performance. Our code is available at https://github.com/MGitHubL/TMac. Meng Liu 0014, Ke Liang 0006, Dayu Hu, Hao Yu 0017, Yue Liu 0008, Lingyuan Meng, Wenxuan Tu, Sihang Zhou 0001, Xinwang Liu 0002 |
ACM Multimedia | 4 |
| 2021 | Classification Method of Blockchain and IoT Devices Based on LSTM
Pengyu Duan, Ruiguang Li, Liehuang Zhu, Hao Yu 0017 |
BlockSys | 4 |
| 2021 | Threat Prediction of Abnormal Transaction Behavior Based on Graph Convolutional Network in Blockchain Digital Currency
Meng Shen 0001, Anqi Sang, Pengyu Duan, Hao Yu 0017, Liehuang Zhu |
BlockSys | 4 |
| 2021 | Effective and Robust Physical-World Attacks on Deep Learning Face Recognition SystemsabstractDeep neural networks (DNNs) have been increasingly used in face recognition (FR) systems. Recent studies, however, show that DNNs are vulnerable to adversarial examples, which potentially mislead DNN-based FR systems in the physical world. Existing attacks either generate perturbations working merely in the digital world, or rely on customized equipment to generate perturbations that are not robust in the ever-changing physical environment. In this paper, we propose FaceAdv, a physical-world attack that crafts adversarial stickers to deceive FR systems. It mainly consists of a sticker generator and a convertor, where the former can craft several stickers with different shapes while the latter aims to digitally attach stickers to human faces and provide feedback to the generator to improve the effectiveness. We conduct extensive experiments to evaluate the effectiveness of FaceAdv on attacking three typical FR systems (i.e., ArcFace, CosFace and FaceNet). The results show that compared with a state-of-the-art attack, FaceAdv can significantly improve the success rates of both dodging and impersonating attacks. We also conduct comprehensive evaluations to demonstrate the robustness of FaceAdv. Meng Shen 0001, Hao Yu 0017, Liehuang Zhu, Ke Xu 0002, Qi Li 0002, Jiankun Hu |
IEEE Trans. Inf. Forensics Secur. | 2 |