Jinwen He

dblp:01/10388 · DBLP profile ↗
← Back
12ranked-venue papers
4as first author
9since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 3 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSoftware engineering, systems software and programming languages · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 HEFLGuard: Backdoor Detection in Homomorphic Encryption-Based Federated Learning
abstract
Homomorphic encryption-based federated learning (HEFL) strengthens privacy by aggregating encrypted model updates, but it also renders existing backdoor defenses that assume plaintext updates inapplicable. We present HEFLGuard, a single-server backdoor detection framework for HEFL in which the server constructs overlapping validation models from encrypted client groups and clients locally compare logits of the global and validation models on benign samples to expose backdoor behavior. HEFLGuard further combines consistency verification across non-IID validation groups with Byzantine fault-tolerant aggregation of client reports, ensuring robustness under heterogeneous data and Byzantine participants. We evaluate HEFLGuard on seven vision/text benchmarks under three backdoor types across IID and non-IID settings. HEFLGuard consistently reduces ASR from near 100% to nearly the nobackdoor level while keeping the drop in clean accuracy within 2.5%. Compared with prior work, HEFLGuard achieves higher robustness and deployability.
Congyi Li, Peizhuo Lv, Jinwen He, Kai Chen 0012
IEEE Trans. Inf. Forensics Secur.3
2025 PrivacyXray: Detecting Privacy Breaches in LLMs through Semantic Consistency and Probability Certainty
Jinwen He, Zijin Lin, Kai Chen 0012, Yue Zhao 0018
USENIX Security Symposium1
2025 EGRTE: adversarially training a self-explaining smoothed classifier for certified robustness
abstract
Abstract Deep learning has transformed fields such as computer vision, natural language processing, and audio analysis through its powerful pattern recognition and predictive capabilities. However, the robustness of these models remains a major concern, as they are highly vulnerable to adversarial attacks-subtle, intentional perturbations that lead to incorrect predictions. While recent defenses like adversarial training and defensive distillation aim to improve robustness, they have notable drawbacks, including overfitting and degraded performance under strong attacks. Certified defenses, such as robust training and Randomized Smoothing, offer theoretical guarantees within a specific perturbation radius, yet struggle to reflect real-world robustness due to efficiency bottlenecks and the unpredictable nature of actual adversarial attacks. These challenges reveal a critical gap between current defenses and real-world attack scenarios, highlighting the need for more practical and resilient solutions. To address the challenges of defense-attack gaps and the inefficiency in robust training, we introduce the Explanation-Guided Robust Training Enhancer (EGRTE). EGRTE combines a self-explaining mechanism, which guides adversarial training to focus on generalized features for improved robustness and accuracy, with a masking mechanism that transforms noised data for easier model learning. This approach not only mitigates noise effects, including adversarial perturbations, but also eliminates the need for time-intensive gradient calculations, greatly enhancing training efficiency. Comprehensive experiments on several datasets show EGRTE’s superior certified accuracy and robustness against adversarial attacks, with a 6.24-fold efficiency increase over comparable methods, positioning EGRTE as a highly effective solution for robust and efficient deep learning.
Zijin Lin, Jinwen He, Yue Zhao 0018, Ruigang Liang, Zhendong Wu
Cybersecur.2
2024 I Don't Know You, But I Can Catch You: Real-Time Defense against Diverse Adversarial Patches for Object Detectors
abstract
Deep neural networks (DNNs) have revolutionized the field of computer vision like object detection with their unparalleled performance. However, existing research has shown that DNNs are vulnerable to adversarial attacks. In the physical world, an adversary could exploit adversarial patches to implement a Hiding Attack (HA) which patches the target object to make it disappear from the detector, and an Appearing Attack (AA) which fools the detector into misclassifying the patch as a specific object. Recently, many defense methods for detectors have been proposed to mitigate the potential threats of adversarial patches. However, such methods still have limitations in generalization, robustness and efficiency. Most defenses are only effective against the HA, leaving the detector vulnerable to the AA.
Zijin Lin, Yue Zhao 0018, Kai Chen 0012, Jinwen He
CCS4
2024 Quantum image encryption algorithm via optimized quantum circuit and parity bit-plane permutation
Jinwen He, Hegui Zhu, Xv Zhou
J. Inf. Secur. Appl.1
2024 Irregular feature enhancer for low-dose CT denoising
Jiehang Deng, Zihang Hu, Jinwen He, Guoqing Qiao, Guosheng Gu, ShaoWei Weng
Multim. Syst.3
2023 Good-looking but Lacking Faithfulness: Understanding Local Explanation Methods through Trend-based Testing
abstract
While enjoying the great achievements brought by deep learning (DL), people are also worried about the decision made by DL models, since the high degree of non-linearity of DL models makes the decision extremely difficult to understand. Consequently, attacks such as adversarial attacks are easy to carry out, but difficult to detect and explain, which has led to a boom in the research on local explanation methods for explaining model decisions. In this paper, we evaluate the faithfulness of explanation methods and find that traditional tests on faithfulness encounter the random dominance problem, i.e., the random selection performs the best, especially for complex data. To further solve this problem, we propose three trend-based faithfulness tests and empirically demonstrate that the new trend tests can better assess faithfulness than traditional tests on image, natural language and security tasks. We implement the assessment system and evaluate ten popular explanation methods. Benefiting from the trend tests, we successfully assess the explanation methods on complex data for the first time, bringing unprecedented discoveries and inspiring future research. Downstream tasks also greatly benefit from the tests. For example, model debugging equipped with faithful explanation methods performs much better for detecting and correcting accuracy and security problems.
Jinwen He, Kai Chen 0012, Guozhu Meng, Jiangshan Zhang, Congyi Li
CCS1
2022 Towards Security Threats of Deep Learning Systems: A Survey
abstract
Deep learning has gained tremendous success and great popularity in the past few years. However, deep learning systems are suffering several inherent weaknesses, which can threaten the security of learning models. Deep learning’s wide use further magnifies the impact and consequences. To this end, lots of research has been conducted with the purpose of exhaustively identifying intrinsic weaknesses and subsequently proposing feasible mitigation. Yet few are clear about how these weaknesses are incurred and how effective these attack approaches are in assaulting deep learning. In order to unveil the security weaknesses and aid in the development of a robust deep learning system, we undertake an investigation on attacks towards deep learning, and analyze these attacks to conclude some findings in multiple views. In particular, we focus on four types of attacks associated with security threats of deep learning: model extraction attack, model inversion attack, poisoning attack and adversarial attack. For each type of attack, we construct its essential workflow as well as adversary capabilities and attack goals. Pivot metrics are devised for comparing the attack approaches, by which we perform quantitative and qualitative analyses. From the analysis, we have identified significant and indispensable factors in an attack vector, e.g., how to reduce queries to target models, what distance should be used for measuring perturbation. We shed light on 18 findings covering these approaches’ merits and demerits, success probability, deployment complexity and prospects. Moreover, we discuss other potential security weaknesses and possible mitigation which can inspire relevant research in this area.
Yingzhe He, Guozhu Meng, Kai Chen 0012, Xingbo Hu, Jinwen He
IEEE Trans. Software Eng.5
2021 DRMI: A Dataset Reduction Technology based on Mutual Information for Black-box Attacks
Yingzhe He, Guozhu Meng, Kai Chen 0012, Xingbo Hu, Jinwen He
USENIX Security Symposium5
2018 Integrated chaotic systems for image encryption
Rushi Lan, Jinwen He, Shouhua Wang, Tianlong Gu
Signal Process.2
2017 An Integrated Chaotic System with Application to Image Encryption
Jinwen He, Rushi Lan, Shouhua Wang
ICONIP (5)1
2011 Face Recognition from Visible and Near-Infrared Images Using Boosted Directional Binary Code
LinLin Shen, Jinwen He, Shipei Wu, Songhao Zheng
ICIC (2)2