VLDB 2026 Research / reviewers in the wild / expert
Deqiang Li
dblp:72/738
· DBLP profile ↗
11ranked-venue papers
4as first author
9since 2021 · last 2026
0000-0003-3456-902XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 1 since 2021Computer networks · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BVSAP: A Bidirectional Verifiable Secure Aggregation Protocol for federated learning
Tao Li 0001, Deqiang Li, Shicheng Cui, Tingting Liu 0005, Jia Xu 0003 |
Comput. Networks | 2 |
| 2026 | Personalized trajectory privacy protection charging scheduling for mobile rechargeable devices
Deqiang Li, Haipeng Dai 0001, Linfeng Liu 0001, Jia Xu 0003 |
Comput. Commun. | 3 |
| 2026 | SMAttack: Subgraph mimicry for black-box adversarial Android malware generation
Deqiang Li, Qianmu Li |
Comput. Secur. | 2 |
| 2025 | An Improved LSTM Trajectory Prediction Method Based on Attention Mechanism in Vehicular Multi-modal EnvironmentsabstractWith the rapid development of Vehicle-to-Everything (V2X) technology, connected vehicles are now capable of acquiring high-precision environmental perception and positioning information. Accurate prediction of a vehicle’s future trajectory within the network is fundamental for enabling key functions such as autonomous path planning, proactive safety control, and driver behavior modeling. This paper addresses the problem of vehicle trajectory prediction in a V2X environment by proposing an improved Long Short-Term Memory network method based on an attention mechanism, named Attention Stack-LSTM (AS-LSTM). The proposed method integrates multi-modal perception data collected by the vehicle itself, including Inertial Measurement Unit (IMU), Global Positioning System (GPS), multi-line LiDAR, and onboard cameras. Initially, time-series features are extracted from each modality and concatenated. Then, an attention mechanism is introduced to model the dynamic temporal dependencies within the sequence, thereby enhancing the model’s ability to focus on critical time steps and important modality information, ultimately improving prediction accuracy. To validate the effectiveness of the AS-LSTM method, experiments were conducted using the publicly available NCLT dataset. The evaluation was performed under two scenarios: one excluding image features and one including them. In the small-scale NCLT subset without image features, the AS-LSTM method achieved a Mean Squared Error (MSE) in the range of [5×10−8, 7×10−8] and a coefficient of determination (R2) between [-0.780, -0.281], demonstrating stable performance. After incorporating image features, the model’s performance improved further, with MSE reduced to the range of [5×10−8, 6×10−8] and R2improved to the range of [-0.701, -0.148]. In addition, the AS-LSTM method consistently outperformed traditional LSTM, Attention LSTM, and Seq2Seq LSTM models across different learning rate settings, exhibiting superior robustness and generalization ability. In summary, the proposed AS-LSTM method effectively fuses multi-modal perceptual data from the vehicle and leverages attention mechanisms to enhance the modeling of temporal dynamics. It offers a viable solution for high-precision trajectory prediction in V2X environments and can be applied to key modules in autonomous vehicles, such as path planning, motion control, and driving behavior prediction. Jiahong Zhu, Deqiang Li |
VTC2025-Fall | 4 |
| 2025 | Towards optimal adversarial texts: character, word, and sentenceabstractAbstract Natural language processing models are widely acknowledged for their strong data fitting capabilities, diverse application scenarios, and adaptable learning methodologies. However, these models, including the large language models, exhibit sensitivity to adversarial example attacks. These examples are slightly perturbed from the pristine text but mislead the model classification. Nevertheless, the existing attack methods primarily focus on the attack effectiveness without semantics-preservation considered. Moreover, the trade-off between evasion effectiveness and concealment of perturbed texts is less investigated. In this study, we propose a multi-objective adversarial text generation framework (MOATG) that simultaneously optimizes attack success rate, imperceptibility, and semantic similarity. Tailored objective functions and dominance relations are designed for character-, word-, and sentence-level perturbations. MOATG is evaluated against five baselines across five benchmark datasets. Experimental results show that MOATG achieves a 5.38% average improvement in attack success rate and reduces word error rate by 1.48%, demonstrating its effectiveness in balancing attack strength and stealth. Pengchuan Wang, Deqiang Li, Qianmu Li |
Cybersecur. | 2 |
| 2025 | Dynamic multi-scale feature augmentation for inductive network representation learning
Shicheng Cui, Deqiang Li, Jing Zhang 0015 |
Pattern Recognit. | 2 |
| 2025 | MC-GNN: Multi-Channel Graph Neural Networks With Hilbert-Schmidt Independence CriterionabstractGraph Neural Networks (GNNs) have been proven to be useful for learning graph-based knowledge. However, one of the drawbacks of GNN techniques is that they may get stuck in the problem of over-squashing. Recent studies attribute to the message passing paradigm that it may amplify some specific local relations and distort long-range information under a certain GNN. To alleviate such phenomena, we propose a novel and general GNN framework, dubbed MC-GNN, which introduces the multi-channel neural architecture to learn and fuse multi-view graph-based information. The purpose of MC-GNN is to extract distinct channel-based graph features and adaptively adjust the importance of the features. To this end, we use the Hilbert-Schmidt Independence Criterion (HSIC) to enlarge the disparity between the embeddings encoded by each channel and follow an attention mechanism to fuse the embeddings with adaptive weight adjustment. MC-GNN can apply multiple GNN backbones, which provides a solution for learning structural relations from a multi-view perspective. Experimental results demonstrate that the proposed MC-GNN is superior to the compared state-of-the-art GNN methods. Shicheng Cui, Deqiang Li, Jing Zhang 0015 |
IEEE Trans. Big Data | 2 |
| 2024 | PAD: Towards Principled Adversarial Malware Detection Against Evasion AttacksabstractMachine Learning (ML) techniques can facilitate the automation ofmalicious software(malware for short) detection, but suffer from evasion attacks. Many studies counter such attacks in heuristic manners, lacking theoretical guarantees and defense effectiveness. In this article, we propose a new adversarial training framework, termedPrincipledAdversarial MalwareDetection (PAD), which offers convergence guarantees for robust optimization methods. PAD lays on a learnable convex measurement that quantifies distribution-wise discrete perturbations to protect malware detectors from adversaries, whereby for smooth detectors, adversarial training can be performed with theoretical treatments. To promote defense effectiveness, we propose a new mixture of attacks to instantiate PAD to enhance deep neural network-based measurements and malware detectors. Experimental results on two Android malware datasets demonstrate: (i) the proposed method significantly outperforms the state-of-the-art defenses; (ii) it can harden ML-based malware detection against 27 evasion attacks with detection accuracies greater than 83.45%, at the price of suffering an accuracy decrease smaller than 2.16% in the absence of attacks; (iii) it matches or outperforms many anti-malware scanners in VirusTotal against realistic adversarial malware. Deqiang Li, Shicheng Cui, Yun Li 0009, Jia Xu 0003, Fu Xiao 0001, Shouhuai Xu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Can We Leverage Predictive Uncertainty to Detect Dataset Shift and Adversarial Examples in Android Malware Detection?abstractThe deep learning approach to detecting malicious software (malware) is promising but has yet to tackle the problem of dataset shift, namely that the joint distribution of examples and their labels associated with the test set is different from that of the training set. This problem causes the degradation of deep learning models without users’ notice. In order to alleviate the problem, one approach is to let a classifier not only predict the label on a given example but also present its uncertainty (or confidence) on the predicted label, whereby a defender can decide whether to use the predicted label or not. While intuitive and clearly important, the capabilities and limitations of this approach have not been well understood. In this paper, we conduct an empirical study to evaluate the quality of predictive uncertainties of malware detectors. Specifically, we re-design and build 24 Android malware detectors (by transforming four off-the-shelf detectors with six calibration methods) and quantify their uncertainties with nine metrics, including three metrics dealing with data imbalance. Our main findings are: (i) predictive uncertainty indeed helps achieve reliable malware detection in the presence of dataset shift, but cannot cope with adversarial evasion attacks; (ii) approximate Bayesian methods are promising to calibrate and generalize malware detectors to deal with dataset shift, but cannot cope with adversarial evasion attacks; (iii) adversarial evasion attacks can render calibration methods useless, and it is an open problem to quantify the uncertainty associated with the predicted labels of adversarial examples (i.e., it is not effective to use predictive uncertainty to detect adversarial examples). Deqiang Li, Shuo Chen 0003, Qianmu Li, Shouhuai Xu |
ACSAC | 1 |
| 2020 | Adversarial Deep Ensemble: Evasion Attacks and Defenses for Malware DetectionabstractMalware remains a big threat to cyber security, calling for machine learning based malware detection. While promising, such detectors are known to be vulnerable to evasion attacks. Ensemble learning typically facilitates countermeasures, while attackers can leverage this technique to improve attack effectiveness as well. This motivates us to investigate which kind of robustness the ensemble defense or effectiveness the ensemble attack can achieve, particularly when they combat with each other. We thus propose a new attack approach, named mixture of attacks, by rendering attackers capable of multiple generative methods and multiple manipulation sets, to perturb a malware example without ruining its malicious functionality. This naturally leads to a new instantiation of adversarial training, which is further geared to enhancing the ensemble of deep neural networks. We evaluate defenses using Android malware detectors against 26 different attacks upon two practical datasets. Experimental results show that the new adversarial training significantly enhances the robustness of deep neural networks against a wide range of attacks, ensemble methods promote the robustness when base classifiers are robust enough, and yet ensemble attacks can evade the enhanced malware detectors effectively, even notably downgrading the VirusTotal service. Deqiang Li, Qianmu Li |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2008 | Redundant DWT based translation invariant wavelet feature extraction for face recognitionabstractDiscrete wavelet transform (DWT) is sensitive to the translation/shift of input signals, so its effectiveness could be negatively impacted when we encounter translation among signals. To deal with such drawbacks, this paper proposes redundant DWT(RDWT) based method to achieve image registration, translation invariant wavelet feature extraction and face recognition. We select a representative face from each person to form a reference face set and perform DWT on it. For each test face, we perform RDWT and compare its redundant horizontal and vertical details with the corresponding details obtained from the reference face. The reference face that is the most similar to the test face is determined to be the recognized face. Experiments on Yaleface database prove the effectiveness of our RDWT based method. Deqiang Li, Zelin Shi |
ICPR | 1 |