VLDB 2026 Research / reviewers in the wild / expert
Xiaozhang Liu
dblp:77/7694 · also Xiao-Zhang Liu
· DBLP profile ↗
24ranked-venue papers
10as first author
16since 2021 · last 2026
0000-0001-9858-0063ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 15 · 7 first-author · 8 since 2021Databases, data management, data science and information retrieval · 12 · 3 first-author · 10 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards frequency-aware dehazing via advantageous feature aggregation in remote sensing images
Xiulai Li, Xiaozhang Liu, Anli Yan |
Expert Syst. Appl. | 3 |
| 2026 | Constraint-aware spatio-temporal graph completion for mobile sensing networks
Xiulai Li, Hanmeng Liu, Xiaozhang Liu |
Knowl. Based Syst. | 5 |
| 2025 | GMS-YOLO: A Lightweight Algorithm for SAR Ship Target Detection Based on YOLOv8n
Xiaozhang Liu, Xinting Zhou, Xiulai Li |
ICA3PP (3) | 1 |
| 2024 | Adaptive Threshold Learning in Frequency Domain for Classification of Breast Cancer Histopathological ImagesabstractBreast cancer has become the most common cancer in the world, and biopsy is the most reliable and widely used technique for detecting breast cancer. However, observation of histopathological images is time-consuming and labor-intensive. Currently, CNN has become the mainstream method for breast cancer histopathological image classification research. However, some studies have found that the optical microscope-generated histopathological images have noise, and the output of a well-trained convolutional neural network in image classification tasks can change drastically due to small variations in the input. Therefore, the quality of the image significantly affects the accuracy of the classification. Wavelet transform is a commonly used denoising method, but the selection of the threshold is a difficult problem, and traditional methods are difficult to find the appropriate threshold quickly and accurately. This paper proposes an adaptive threshold selection method that combines threshold selection steps with deep learning methods by using the threshold as a parameter in the CNN model to train. In this way, we associate the threshold with the classification result of the model and find the appropriate value for that image and task by back-propagation in training. The method was experimented on publicly available datasets BreaKHis and BACH. The results in BreaKHis (40x: 94.37 % , 100x: 93.85 % , 200x: 91.63 % , 400x: 93.31 % ), and BACH (91.25 % ) demonstrate that our adaptive threshold selection method can improve classification accuracy and is significantly superior to traditional threshold selection methods. Yujian Liu, Xiaozhang Liu |
Int. J. Intell. Syst. | 2 |
| 2024 | Pseudo unlearning via sample swapping with hash
Xiaojun Ren, Hongyang Yan, Xiaozhang Liu, Zhenxin Zhang |
Inf. Sci. | 4 |
| 2023 | Zeroth-Order Gradient Approximation Based DaST for Black-Box Adversarial Attacks
Yaochi Zhao, Zhuhua Hu, Xiaozhang Liu, Anli Yan |
ICIC (1) | 4 |
| 2023 | Explanation leaks: Explanation-guided model extraction attacks
Anli Yan, Teng Huang 0001, Lishan Ke, Xiaozhang Liu, Qi Chen 0024, Changyu Dong |
Inf. Sci. | 4 |
| 2023 | Holistic Implicit Factor Evaluation of Model Extraction AttacksabstractModel extraction attacks (MEAs) allow adversaries to replicate a surrogate model analogous to the target model's decision pattern. While several attacks and defenses have been studied in-depth, the underlying reasons behind our susceptibility to them often remain unclear. Analyzing these implication influence factors helps to promote secure deep learning (DL) systems, it requires studying extraction attacks in various scenarios to determine the success of different attacks and the hallmarks of DLs. However, understanding, implementing, and evaluating even a single attack requires extremely high technical effort, making it impractical to study the vast number of unique extraction attack scenarios. To this end, we present a first-of-its-kind holistic evaluation of implication factors for MEAs which relies on the attack process abstracted from state-of-the-art MEAs. Specifically, we concentrate on four perspectives. we consider the impact of the task accuracy, model architecture, and robustness of the target model on MEAs, as well as the impact of the model architecture of the surrogate model on MEAs. Our empirical evaluation includes an ablation study over sixteen model architectures and four image datasets. Surprisingly, our study shows that improving the robustness of the target model via adversarial training is more vulnerable to model extraction attacks. Anli Yan, Hongyang Yan, Xiaozhang Liu, Teng Huang 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Explanation-based data-free model extraction attacks
Anli Yan, Ruitao Hou, Hongyang Yan, Xiaozhang Liu |
World Wide Web (WWW) | 4 |
| 2022 | Towards explainable model extraction attacksabstractOne key factor able to boost the applications of artificial intelligence (AI) in security-sensitive domains is to leverage them responsibly, which is engaged in providing explanations for AI. To date, a plethora of explainable artificial intelligence (XAI) has been proposed to help users interpret model decisions. However, given its data-driven nature, the explanation itself is potentially susceptible to a high risk of exposing privacy. In this paper, we first show that the existing XAI is vulnerable to model extraction attacks and then present an XAI-aware dual-task model extraction attack (DTMEA). DTMEA can attack a target model with explanation services, that is, it can extract both the classification and explanation tasks of the target model. More specifically, the substitution model extracted by DTMEA is a multitask learning architecture, consisting of a sharing layer and two task-specific layers for classification and explanation. To reveal which explanation technologies are more vulnerable to expose privacy information, we conduct an empirical evaluation of four major explanation types in the benchmark data set. Experimental results show that the attack accuracy of DTMEA outperforms the predicted-only method with up to 1.25%, 1.53%, 9.25%, and 7.45% in MNIST, Fashion-MNIST, CIFAR-10, and CIFAR-100, respectively. By exposing the potential threats on explanation technologies, our research offers the insights to develop effective tools that are able to trade off security-sensitive relationships. Anli Yan, Ruitao Hou, Xiaozhang Liu, Hongyang Yan, Teng Huang 0001, Xianmin Wang |
Int. J. Intell. Syst. | 3 |
| 2022 | Feature autoencoder for detecting adversarial examplesabstractDeep neural networks (DNNs) have gained widespread adoption in computer vision. Unfortunately, state-of-the-art DNNs are vulnerable to adversarial example (AE) attacks, where an adversary introduces imperceptible perturbations to a test example for defrauding DNNs. The obstacles have urged intensive research on improving the DNN robustness via adversarial training, that is, the clean data set is blended with adversarial examples to carry out training. However, the adversarial example attack technologies are open-ended, and the adversarial training is insufficient to focus on improving robustness performance. To circumvent this limitation, we mitigate adversarial example attacks from another perspective, which aims at detecting adversarial examples. Feature autoencoder detector (FADetector), a novel defense framework that exploits feature knowledge is proposed. One of the hallmarks of FADetector is to not involve adversarial examples to train the detector. Our extensive evaluation on MNIST and CIFAR-10 data sets demonstrates that our defense outperforms the conventional autoencoder detectors in terms of detection accuracy. Hongwei Ye, Xiaozhang Liu |
Int. J. Intell. Syst. | 2 |
| 2021 | CSRT rumor spreading model based on complex networkabstractRumors mislead judgments of people, affect economic development, and the stability of social order. The research on the rule of spreading rumors is significant and meaningful. This paper improves the traditional Barabási–Albert scale-free network and proposes a network topology model that conforms to the characteristics of sharing social networks based on the complex network theory and the actual characteristics of sharing social networks. In addition, the credulous spider rational taciturn rumor propagation model is proposed by improving the credulous spider rational model, which solves the overspread problem of the traditional rumor propagation model. This paper further studies the influence of anxiety on the spread of rumors, and finds that the anxiety of audience is increasing with the spread degree of rumors. Shan Ai, Xinyang Zheng, Yue Wang 0058, Xiaozhang Liu |
Int. J. Intell. Syst. | 5 |
| 2021 | A computational approach for predicting drug-target interactions from protein sequence and drug substructure fingerprint informationabstractIdentification of drug–target interactions (DTIs) is critical for discovering potential target protein candidates for new drugs. However, traditional experimental methods have limitations in discovering DTIs. They are time-consuming, tedious, and expensive, and often suffer from high false-positive rates and false-negative rates. Therefore, using computational methods to predict DTIs has received extensive attention from many researchers in recent years. To address this issue, in this paper, an effective prediction model is presented which is based on the information of drug molecular structure data and protein sequence data. It performs prediction with the following procedures. First, we transform the sequences of each target into a position-specific scoring matrix (PSSM), such that the features can retain biological evolutionary information. We then use a feature vector of molecular substructure fingerprints to describe the chemical structure information of the drug compounds. Second, the Legendre moments algorithm is used to extract new features from the PSSM. Finally, a classification algorithm called rotation forest is used to perform prediction, we tested its prediction performance on four golden standard data sets: enzymes, G-protein-coupled receptors, ion channels, and nuclear receptors. As a result, the proposed method achieves average accuracies of 0.9026, 0.8260, 0.8703, and 0.7444 on these four data sets using five-fold cross-validation. We also compare the proposed method with the support vector machine and other existing approaches. The proposed model is proved to be superior to comparative methods, showing that it is feasible, effective, and robust for predicting potential DTI. Yang Li 0111, Xiaozhang Liu, Zhu-Hong You, Liping Li 0003, Jian-Xin Guo, Zheng Wang 0065 |
Int. J. Intell. Syst. | 2 |
| 2021 | Querying little is enough: Model inversion attack via latent informationabstractAs machine learning (ML) technologies evolve, various online intelligent services use ML models to provide predictions. Unfortunately, attackers can obtain the private information of the model by interacting with the online service, namely model inversion attack (MIA). However, MIA requires large data sets to be transferred to an online service to obtain the predictive value of the inference model. Besides, the huge transmission may cause the administrator's active defense. To overcome this drawback, we propose a novel MIA scheme, which leverages latent information extracted by an auxiliary neural network as high-dimensional features to simplify what inversion model should learn. The core idea of our scheme is to reuse some parameters of the local pretraining model. Extensive experiments have verified the effectiveness of our method in convolutional neural networks on LFW, pubFig, MNIST data sets. Experimental results show that even with a few queries, our inversion method still work accurately and is superior to other technologies. It is worth mentioning that our method makes it more difficult for administrators to defend against the attack and elicit more investigations for privacy-preserving. Kanghua Mo, Xiaozhang Liu, Teng Huang 0001, Anli Yan |
Int. J. Intell. Syst. | 2 |
| 2021 | MHAT: An efficient model-heterogenous aggregation training scheme for federated learning
Hongyang Yan, Zijie Pan, Xiaozhang Liu, Zulong Zhang |
Inf. Sci. | 5 |
| 2021 | Dual attention guided multi-scale CNN for fine-grained image classification
Xiaozhang Liu, Tao Li 0043, Dejian Wang |
Inf. Sci. | 1 |
| 2020 | Video frame interpolation via optical flow estimation with image inpaintingabstractAs we all know, video frame rate determines the quality of the video. The higher the frame rate, the smoother the movements in the picture, the clearer the information expressed, and the better the viewing experience for people. Video interpolation aims to increase the video frame rate by generating a new frame image using the relevant information between two consecutive frames, which is essential in the field of computer vision. The traditional motion compensation interpolation method will cause holes and overlaps in the reconstructed frame, and is easily affected by the quality of optical flow. Therefore, this paper proposes a video frame interpolation method via optical flow estimation with image inpainting. First, the optical flow between the input frames is estimated via combined local and global-total variation (CLG-TV) optical flow estimation model. Then, the intermediate frames are synthesized under the guidance of the optical flow. Finally, the nonlocal self-similarity between the video frames is used to solve the optimization problem, to fix the pixel loss area in the interpolated frame. Quantitative and qualitative experimental results show that this method can effectively improve the quality of optical flow estimation, generate realistic and smooth video frames, and effectively increase the video frame rate. Xiaozhang Liu, Hui Liu 0016, Yuxiu Lin |
Int. J. Intell. Syst. | 1 |
| 2020 | A game-theoretic approach of mixing different qualities of coinsabstractPerpetrators leverage the untraceable feature to conduct illegal behaviors leading security issues with respect to mixing coins. Generally, bad coins are blocked based on a common blacklist. However, the blacklist may not be updated in time, which results in that bad coins escape the blocking. Consequently, perpetrators can still conduct illicit behaviors such as money laundering. In this paper, we apply game theory under imperfect information to study how coins' quality restrain these illicit behaviors under the incomplete scenario. More specifically, we propose a strategy for participants to submit deposits if they hope to mix coins with others even if they are not in blacklist at this time. The deposits will not be refunded when participants are included in the blacklist after mixing. Therefore, no participants have incentives to mix with bad coins. At the last part of this paper, we also simulate the incomes for participants, which indicates that deposits strategy is effective to prevent illicit behaviors. Xiaozhang Liu, Xinying Yu, Haojia Zhu, Guoyu Yang, Xiaomei Yu |
Int. J. Intell. Syst. | 1 |
| 2018 | Face pose estimation based on kernelized maximum separability
Xiaozhang Liu |
Soft Comput. | 1 |
| 2016 | Fisher discriminant analysis based on kernel cuboid for face recognition
Xiaozhang Liu, Chen-Guang Zhang |
Soft Comput. | 1 |
| 2013 | Kernel-Based 2D Fisher Discriminant Analysis with parameter Optimization for Face RecognitionabstractAs is known, kernel methods are developed to handle nonlinear classification. However, we have found that based on vector representation of face images, it is not easy to improve the performance of LDA-based methods by incorporating the kernel trick. Actually, in the case that the dimensionality of face images in vector form is far greater than the number of samples, linear classifiers are adequate and it is illogical to increase dimensions of vectors using kernel methods. In order to give full play to the strong point of the kernel technique for manipulating the nonlinearity of pattern distribution, we propose a new image feature extraction method for face recognition, called kernel-based two-dimensional Fisher discriminant analysis (K2DFDA), which deals with a face image directly as a matrix, instead of a stacked vector from rows or columns of the image. Moreover, we present a kernel parameter optimization scheme for K2DFDA, based on the maximum margin criterion and the damped Newton's method. Experimental results show the effectiveness of K2DFDA and its parameter optimization scheme. Xiaozhang Liu, Patrick Shen-Pei Wang, Guo-Can Feng |
Int. J. Pattern Recognit. Artif. Intell. | 1 |
| 2012 | Multiple kernel discriminant analysis
Xiaozhang Liu, Guo-Can Feng |
ICPR | 1 |
| 2009 | Learning Kernel in Kernel-Based LDA for Face Recognition Under Illumination VariationsabstractKernel-based methods have been proved to be an effective approach for face recognition in dealing with complex and nonlinear face image variations. While many encouraging results have been reported, the selection of kernel is ratheradhoc. This letter proposes a systematic method to construct a new kernel for kernel discriminant analysis, which is good for handling illumination problem. The proposed method first learns a kernel matrix by maximizing the difference between inter-class and intra-class similarities under the Lambertian model, and then generalizes the kernel matrix to our proposed ILLUM kernel using the scattered data interpolation technique. Experiments on the Yale-B and the CMU PIE face databases show that, the proposed kernel outperforms the popular Gaussian kernel in Kernel Discriminant Analysis and the recognition rate can be improved around 10%. Xiaozhang Liu, Pong C. Yuen, Guo-Can Feng |
IEEE Signal Process. Lett. | 1 |
| 2008 | Kernel Bisecting k-means clustering for SVM training sample reductionabstractThis paper presents a new algorithm named Kernel Bisecting k-means and Sample Removal (KBK-SR) as a sampling preprocessing for SVM training to improve the scalability. The novel clustering approach Kernel Bisecting k-means in the KBK-SR tends to fast produce balanced clusters of similar sizes in the kernel feature space, which makes KBK-SR efficient and effective for reducing training samples for nonlinear SVMs. Theoretical analysis and experimental results on three UCI real data benchmarks both show that, with very short sampling time, our algorithm dramatically accelerates SVM training while maintaining high test accuracy. Xiaozhang Liu, Guo-Can Feng |
ICPR | 1 |