Lijin Wang

dblp:73/9584 · DBLP profile ↗
← Back
13ranked-venue papers
4as first author
6since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 4 · 1 since 2021Security and privacy · 4 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3Applied, interdisciplinary, general and emerging computing · 3 · 2 first-authorSystems, architecture and hardware · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2025 From Purity to Peril: Backdooring Merged Models From "Harmless" Benign Components
Lijin Wang, Tianshuo Cong, Xinlei He 0001, Zhan Qin, Xinyi Huang 0001
USENIX Security Symposium1
2025 Defending Data Inference Attacks Against Machine Learning Models by Mitigating Prediction Distinguishability
abstract
Neural networks are vulnerable to data inference attacks, including the membership inference attack, the model inversion attack, and the attribute inference attack. In this paper, we proposePurifierto defend against membership inference attacks by quantifying the differences between dataset members and non-members in three dimensions: individual shape, statistical distribution, and prediction label.Purifierinvolves transforming the confidence scores produced by the target classifier, resulting in purified confidence scores that are indistinguishable across the dimensions above. We conduct experiments on widely-used datasets and models. The results show thatPurifieroffers robust defense against membership inference attacks with superior efficacy compared to prior defense techniques while maintaining minimal utility degradation (e.g., less than 0.7% classification accuracy drop of most datasets). Additionally, our extended experiments explore the effectiveness ofPurifierin defending against the model inversion attack and the attribute inference attack.
Yiran Zhu, ChuXiao Xiang, Ruite Xu, Lijin Wang, Fan Zhang 0010, Jiarong Xu, Zhan Qin
IEEE Trans. Dependable Secur. Comput.8
2024 BounceAttack: A Query-Efficient Decision-based Adversarial Attack by Bouncing into the Wild
abstract
Deep neural networks are vulnerable to adversarial attacks. We study such threats in the decision-based black-box setting where the adversary could obtain only the predicted labels of the victim classifier within limited queries and aims at performing targeted and untargeted adversarial attacks under different perturbation constraints. In this paper, we propose BounceAttack as a query-efficient attack method. We propose the bounce vector which encourages the iterations to maximally explore the adversarial space towards the optimal adversarial example within limited queries to improve the query efficiency. We perform extensive experiments on various benchmark datasets and models. Experimental results show that BounceAttack achieves both high query efficiency and small perturbation size. BounceAttack outperforms existing attack methods. For example, BounceAttack achieves 48.1% smaller perturbation compared to the state-of-the-art attack methods on average using the same number of model queries.
Jianhao Fu, Lijin Wang
SP3
2024 Property Existence Inference against Generative Models
Lijin Wang, Lin Long, Zhan Qin
USENIX Security Symposium1
2023 Purifier: Defending Data Inference Attacks via Transforming Confidence Scores
abstract
Neural networks are susceptible to data inference attacks such as the membership inference attack, the adversarial model inversion attack and the attribute inference attack, where the attacker could infer useful information such as the membership, the reconstruction or the sensitive attributes of a data sample from the confidence scores predicted by the target classifier. In this paper, we propose a method, namely PURIFIER, to defend against membership inference attacks. It transforms the confidence score vectors predicted by the target classifier and makes purified confidence scores indistinguishable in individual shape, statistical distribution and prediction label between members and non-members. The experimental results show that PURIFIER helps defend membership inference attacks with high effectiveness and efficiency, outperforming previous defense methods, and also incurs negligible utility loss. Besides, our further experiments show that PURIFIER is also effective in defending adversarial model inversion attacks and attribute inference attacks. For example, the inversion error is raised about 4+ times on the Facescrub530 classifier, and the attribute inference accuracy drops significantly when PURIFIER is deployed in our experiment.
Lijin Wang, Da Yang 0006, Ziming Zhao 0008, Ee-Chien Chang, Fan Zhang 0010, Kui Ren 0001
AAAI2
2021 A label propagation algorithm for community detection on high-mixed networks
abstract
Abstract Community detection on high‐mixed networks has been a challenging problem for complex network researchers. In a Lancichinetti–Fortunato–Radicchi (LFR) network with a mixing parameter mu greater than or equal to 0.5, the quality of the communities partitioned by currently available algorithms will decrease rapidly with increasing mu. To address this issue, we propose a label propagation algorithm on high‐mixed networks, called LPA‐HM, for community detection. In our algorithm, the initial node labels are preprocessed using the number of common neighbors of the nodes, which greatly reduces the initial number of labels and thus improves the quality of the subsequent label propagation process. During the label propagation stage, each node is given the label that is shared by the maximum number of its neighbors. If there are several labels that meet this requirement, the influence of the labels' nodes is calculated, and the label with the maximum total influence is selected as the label of the current node. Early stop conditions based on modularity and run‐to‐run changes in the number of detected communities are incorporated in the algorithm to prevent label overpropagation. The communities that fail to satisfy the definition of weak communities are merged with their most similar neighboring communities. In experiments based on real networks and LFR networks, it is found that the LPA‐HM algorithm is well suited to community detection in a variety of networks. In a high‐mixed LFR network with mu = 0.7, the NMI measure of the LPA‐HM algorithm's community detection performance is still greater than 0.9.
Qingshou Wu, Rongwang Chen, Lijin Wang, Kun Guo 0003
Concurr. Comput. Pract. Exp.3
2020 Erratum to: Cuckoo search with varied scaling factor
Lijin Wang, Yilong Yin, Yiwen Zhong
Frontiers Comput. Sci.1
2018 Sequential quadratic programming enhanced backtracking search algorithm
Wenting Zhao 0004, Lijin Wang, Yilong Yin, Yuchun Tang
Frontiers Comput. Sci.2
2017 Hybrid discrete artificial bee colony algorithm with threshold acceptance criterion for traveling salesman problem
Yiwen Zhong, Juan Lin 0001, Lijin Wang, Hui Zhang 0006
Inf. Sci.3
2016 Best Guided Backtracking Search Algorithm for Numerical Optimization Problems
Wenting Zhao 0004, Lijin Wang, Yilong Yin
KSEM2
2016 An Improved Neural Network with Random Weights Using Backtracking Search Algorithm
Lijin Wang, Yilong Yin, Wenting Zhao 0004, Yuchun Tang
Neural Process. Lett.2
2015 Cuckoo search with varied scaling factor
Lijin Wang, Yilong Yin, Yiwen Zhong
Frontiers Comput. Sci.1
2014 An Improved Backtracking Search Algorithm for Constrained Optimization Problems
Wenting Zhao 0004, Lijin Wang, Yilong Yin, Yushan Yin
KSEM2