Di Tang 0001

dblp:77/1147-1 · DBLP profile ↗
← Back
19ranked-venue papers
2as first author
15since 2021 · last 2026
0000-0002-7031-3315ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 17 · 2 first-author · 13 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Breaking the Stealth-Potency Trade-off in Clean-Image Backdoors with Generative Trigger Optimization
abstract
Clean-image backdoor attacks, which use only label manipulation in training datasets to compromise deep neural networks, pose a significant threat to security-critical applications. A critical flaw in existing methods is that the poison rate required for a successful attack induces a proportional, and thus noticeable, drop in Clean Accuracy (CA), undermining their stealthiness. This paper presents a new paradigm for clean-image attacks that minimizes this accuracy degradation by optimizing the trigger itself. We introduce Generative Clean-Image Backdoors (GCB), a framework that uses a conditional InfoGAN to identify naturally occurring image features that can serve as potent and stealthy triggers. By ensuring these triggers are easily separable from benign task-related features, GCB enables a victim model to learn the backdoor from an extremely small set of poisoned examples, resulting in a CA drop of less than 1%. Our experiments demonstrate GCB's remarkable versatility, successfully adapting to six datasets, five architectures, and four tasks, including the first demonstration of clean-image backdoors in regression and segmentation. GCB also exhibits resilience against most of the existing backdoor defenses.
Binyan Xu, Di Tang 0001, Xilin Dai, Kehuan Zhang
AAAI3
2026 Unidentifiable Identifier: Attacking Bluetooth Applications with Duplicated UUIDs
Siyu Shen, Yi Chen 0024, Fenghao Xu, Shuaike Dong, Wenrui Diao, Di Tang 0001, Kehuan Zhang
EuroS&P6
2026 Beyond Nodes vs. Edges: A Multi-View Fusion Framework for Provenance-Based Intrusion Detection
Binyan Xu, Di Tang 0001, Kehuan Zhang
SP3
2025 One Surrogate to Fool Them All: Universal, Transferable, and Targeted Adversarial Attacks with CLIP
Binyan Xu, Xilin Dai, Di Tang 0001, Kehuan Zhang
CCS3
2025 CLIP-Guided Backdoor Defense through Entropy-Based Poisoned Dataset Separation
Binyan Xu, Xilin Dai, Di Tang 0001, Kehuan Zhang
ACM Multimedia4
2024 Gradient Shaping: Enhancing Backdoor Attack Against Reverse Engineering
Rui Zhu 0044, Di Tang 0001, Guanhong Tao 0001, Shiqing Ma, XiaoFeng Wang 0001, Haixu Tang
NDSS2
2024 Tossing in the Dark: Practical Bit-Flipping on Gray-box Deep Neural Networks for Runtime Trojan Injection
Di Tang 0001, XiaoFeng Wang 0001, Zhaoyang Geng, Wenhao Wang 0001
USENIX Security Symposium2
2024 Racing on the Negative Force: Efficient Vulnerability Root-Cause Analysis through Reinforcement Learning on Counterexamples
Dandan Xu, Di Tang 0001, Yi Chen 0024, XiaoFeng Wang 0001, Kai Chen 0012, Haixu Tang, Longxing Li
USENIX Security Symposium2
2023 Selective Amnesia: On Efficient, High-Fidelity and Blind Suppression of Backdoor Effects in Trojaned Machine Learning Models
abstract
The extensive applications of deep neural network (DNN) and its increasingly complicated architecture and supply chain make the risk of backdoor attacks more realistic than ever. In such an attack, the adversary either poisons the training data of a DNN model or manipulates its training process to stealthily inject a covert backdoor task, alongside the primary task, so as to strategically misclassify inputs carrying a trigger. Defending against such an attack, particularly removing the backdoor effect from an infected model, is known to be hard. For this purpose, prior research either requires a recovered trigger, which is hard to come by, or attempts to fine-tune a model on its primary task, which becomes less effective when the clean data is scarce. In this paper, we present a simple yet surprisingly effective technique to induce "selective amnesia" on a backdoored model. Our approach, called SEAM, has been inspired by the problem of catastrophic forgetting (CF), a long standing issue in continual learning. Our idea is to retrain a given DNN model on randomly labeled clean data, to induce a CF on the model, leading to a sudden forget on both primary and backdoor tasks; then we recover the primary task by retraining the randomized model on correctly labeled clean data. We analyzed SEAM by modeling the unlearning process as continual learning and further approximating a DNN using Neural Tangent Kernel for measuring CF. Our analysis shows that our random-labeling approach actually maximizes the CF on an unknown backdoor in the absence of triggered inputs, and also preserves some feature extraction in the network to enable a fast revival of the primary task. We further evaluated SEAM on both image processing and Natural Language Processing tasks, under both data contamination and training manipulation attacks, over thousands of models either trained on popular image datasets or provided by the TrojAI competition. Our experiments show that SEAM vastly outperforms the state-of-the-art unlearning techniques, achieving a high Fidelity (measuring the gap between the accuracy of the primary task and that of the backdoor) efficiently (e.g., about 30 times faster than training a model from scratch on the MNIST dataset), with only a small amount of clean data (e.g., with a size of just 0.1% of training data for TrojAI models).
Rui Zhu 0044, Di Tang 0001, XiaoFeng Wang 0001, Haixu Tang
SP2
2023 Sherlock on Specs: Building LTE Conformance Tests through Automated Reasoning
Yi Chen 0024, Di Tang 0001, Yepeng Yao, Mingming Zha 0001, XiaoFeng Wang 0001, Xiaozhong Liu 0001, Haixu Tang, Baoxu Liu
USENIX Security Symposium2
2023 HOMESPY: The Invisible Sniffer of Infrared Remote Control of Smart TVs
Kong Huang, Ke Zhang 0039, Jiacen Xu 0001, Jiongyi Chen, Di Tang 0001, Kehuan Zhang
USENIX Security Symposium6
2022 Order-Disorder: Imitation Adversarial Attacks for Black-box Neural Ranking Models
abstract
Neural text ranking models have witnessed significant advancement and are increasingly being deployed in practice. Unfortunately, they also inherit adversarial vulnerabilities of general neural models, which have been detected but remain underexplored by prior studies. Moreover, the inherit adversarial vulnerabilities might be leveraged by blackhat SEO to defeat better-protected search engines. In this study, we propose an imitation adversarial attack on black-box neural passage ranking models. We first show that the target passage ranking model can be transparentized and imitated by enumerating critical queries/candidates and then train a ranking imitation model. Leveraging the ranking imitation model, we can elaborately manipulate the ranking results and transfer the manipulation attack to the target ranking model. For this purpose, we propose an innovative gradient-based attack method, empowered by the pairwise objective function, to generate adversarial triggers, which causes premeditated disorderliness with very few tokens. To equip the trigger camouflages, we add the next sentence prediction loss and the language model fluency constraint to the objective function. Experimental results on passage ranking demonstrate the effectiveness of the ranking imitation attack model and adversarial triggers against various SOTA neural ranking models. Furthermore, various mitigation analyses and human evaluation show the effectiveness of camouflages when facing potential mitigation approaches. To motivate other scholars to further investigate this novel and important problem, we make the experiment data and code publicly available.
Jiawei Liu 0002, Yangyang Kang, Di Tang 0001, Kaisong Song, Changlong Sun, XiaoFeng Wang 0001, Wei Lu 0019, Xiaozhong Liu 0001
CCS3
2022 Seeing the Forest for the Trees: Understanding Security Hazards in the 3GPP Ecosystem through Intelligent Analysis on Change Requests
Yi Chen 0024, Di Tang 0001, Yepeng Yao, Mingming Zha 0001, XiaoFeng Wang 0001, Xiaozhong Liu 0001, Haixu Tang, Dongfang Zhao 0010
USENIX Security Symposium2
2021 Understanding the Brains and Brawn of Illicit Streaming App
Kong Huang, Ke Zhang 0039, Jiongyi Chen, Menghan Sun, Di Tang 0001, Kehuan Zhang
ICDF2C6
2021 Demon in the Variant: Statistical Analysis of DNNs for Robust Backdoor Contamination Detection
Di Tang 0001, XiaoFeng Wang 0001, Haixu Tang, Kehuan Zhang
USENIX Security Symposium1
2020 Your Smart Home Can't Keep a Secret: Towards Automated Fingerprinting of IoT Traffic
abstract
The IoT (Internet of Things) technology has been widely adopted in recent years and has profoundly changed the people's daily lives. However, in the meantime, such a fast-growing technology has also introduced new privacy issues, which need to be better understood and measured. In this work, we look into how private information can be leaked from network traffic generated in the smart home network. Although researchers have proposed techniques to infer IoT device types or user behaviors under clean experiment setup, the effectiveness of such approaches become questionable in the complex but realistic network environment, where common techniques like Network Address and Port Translation (NAPT) and Virtual Private Network (VPN) are enabled. To this aim, we propose a traffic analysis framework based on sequence-learning techniques like LSTM and leveraged the temporal relations between packets for the attack of device identification. We evaluated it under different environment settings (e.g., pure-IoT and noisy environment with multiple non-IoT devices). The results showed our framework was able to differentiate device types with a high accuracy. This result suggests IoT network communications pose prominent challenges to users' privacy, even when they are protected by encryption and morphed by the network gateway. As such, new privacy protection methods on IoT traffic need to be developed towards mitigating this new issue.
Shuaike Dong, Zhou Li 0001, Di Tang 0001, Jiongyi Chen, Menghan Sun, Kehuan Zhang
AsiaCCS3
2019 Stealthy Porn: Understanding Real-World Adversarial Images for Illicit Online Promotion
abstract
Recent years have witnessed the rapid progress in deep learning (DP), which also brings their potential weaknesses to the spotlights of security and machine learning studies. With important discoveries made by adversarial learning research, surprisingly little attention, however, has been paid to the real-world adversarial techniques deployed by the cybercriminal to evade image-based detection. Unlike the adversarial examples that induce misclassification using nearly imperceivable perturbation, real-world adversarial images tend to be less optimal yet equally effective. As a first step to understand the threat, we report in the paper a study on adversarial promotional porn images (APPIs) that are extensively used in underground advertising. We show that the adversary today's strategically constructs the APPIs to evade explicit content detection while still preserving their sexual appeal, even though the distortions and noise introduced are clearly observable to humans. To understand such real-world adversarial images and the underground business behind them, we develop a novel DP-based methodology called Male`na, which focuses on the regions of an image where sexual content is least obfuscated and therefore visible to the target audience of a promotion. Using this technique, we have discovered over 4,000 APPIs from 4,042,690 images crawled from popular social media, and further brought to light the unique techniques they use to evade popular explicit content detectors (e.g., Google Cloud Vision API, Yahoo Open NSFW model), and the reason that these techniques work. Also studied are the ecosystem of such illicit promotions, including the obfuscated contacts advertised through those images, compromised accounts used to disseminate them, and large APPI campaigns involving thousands of images. Another interesting finding is the apparent attempt made by cybercriminals to steal others' images for their advertising. The study highlights the importance of the research on real-world adversarial learning and makes the first step towards mitigating the threats it poses.
Kan Yuan, Di Tang 0001, Xiaojing Liao, XiaoFeng Wang 0001, Xuan Feng 0005, Yi Chen 0024, Menghan Sun, Kehuan Zhang
IEEE Symposium on Security and Privacy2
2018 Beware of Your Screen: Anonymous Fingerprinting of Device Screens for Off-line Payment Protection
abstract
QR-code mobile payment becomes increasingly popular, being offered by major banks (e.g., ICBC) and payment service providers (e.g., PayPal). Unlike mobile payment solutions provided by hardware vendors (e.g., Apple Pay and Samsung Pay), QR code payment schemes do not rely on any hardware support and can therefore be easily deployed. However, the security guarantee of the new scheme is less clear: in the absence of hardware protection, users' digital wallet can be vulnerable to an OS-level adversary, who could steal her secret for generating payment tokens.
Zhe Zhou 0001, Di Tang 0001, Wenhao Wang 0001, XiaoFeng Wang 0001, Zhou Li 0001, Kehuan Zhang
ACSAC2
2018 Face Flashing: a Secure Liveness Detection Protocol based on Light Reflections
Di Tang 0001, Zhe Zhou 0001, Yinqian Zhang, Kehuan Zhang
NDSS1