EDBT 2026 Demo / reviewers in the wild / expert
Yan Zhang 0133
dblp:04/3348-133
· DBLP profile ↗
6ranked-venue papers
3as first author
6since 2021 · last 2026
0000-0002-5562-8001ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Computer networks · 3 · 2 first-author · 3 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Rethinking Fake Speech Detection: A Generalized Framework Leveraging Spectrogram Magnitude
Zihao Liu 0001, Aobo Chen 0002, Yan Zhang 0133, Chenglin Miao |
NDSS | 3 |
| 2026 | Defending Autonomous Driving Perception against Adversarial Object-Based Attacks via Motion PlanningabstractAutonomous vehicles (AVs) rely on perception systems to detect surrounding objects using sensors such as cameras, LiDAR (Light Detection and Ranging), and millimeter-wave (mmWave) radar. However, recent studies have shown that attackers can deceive these systems by strategically placing adversarial objects (e.g., color patches, cardboard, or metal foil) in the driving environment. These attacks pose serious safety risks, yet existing defenses primarily focus on individual sensor modalities and lack generalizability across different sensing systems. To address this gap, we propose the first generalized defense mechanism capable of mitigating various attacks using adversarial objects. Our approach integrates real-time attack detection with trajectory adaptation, guiding the victim AV to positions where the attack is less effective. The defense mechanism combines a deep reinforcement learning (DRL)-based motion planning model, which dynamically adjusts the AV’s trajectory, with an uncertainty-aware filtering scheme that refines perception outputs to enhance detection robustness. Extensive experiments in both simulated and real-world environments demonstrate that our defense mechanism effectively mitigates adversarial object-based attacks across different sensing modalities and sensor fusion while maintaining safe and smooth driving behavior. Zihao Liu 0001, Yan Zhang 0133, Yi Zhu 0012, Lu Su 0001, Chunming Qiao, Chenglin Miao |
SenSys | 2 |
| 2025 | Towards Real-Time Defense against Object-Based LiDAR Attacks in Autonomous DrivingabstractLiDAR (Light Detection and Ranging)-based object detection is a cornerstone of autonomous vehicle perception systems. Modern LiDAR perception relies heavily on deep neural networks (DNNs), which enable accurate object detection by learning geometric features from 3D point clouds. However, recent studies have shown that these systems are vulnerable to object-based adversarial attacks, where physical adversarial objects are strategically placed in the environment to manipulate LiDAR point clouds and mislead detection models. These attacks are practical, stealthy, and require no specialized hardware, posing a serious threat to the safety and reliability of AVs. Despite these risks, existing defense methods suffer from significant limitations, including high computational overhead, limited generalizability and effectiveness, and the inability to operate in real time. In this paper, we propose the first real-time defense mechanism against object-based LiDAR attacks in autonomous driving. Our solution is both detection model-agnostic and attack-agnostic, requiring no prior knowledge of the number, shape, size, or placement of adversarial objects. Positioned between the sensing and perception modules of the AV pipeline, the defense processes LiDAR point clouds in real time and employs a novel generative model that enables efficient and effective identification and removal of adversarial points from suspicious regions. Extensive experiments in both simulated and real-world environments demonstrate that our approach achieves high attack detection rates with minimal latency. This work offers a practical and robust defense solution to a growing security threat in autonomous driving. Yan Zhang 0133, Zihao Liu 0001, Yi Zhu 0012, Chenglin Miao |
CCS | 1 |
| 2024 | An Online Defense against Object-based LiDAR Attacks in Autonomous DrivingabstractLiDAR (Light Detection and Ranging) has been widely used in autonomous driving to perceive the surrounding environment of self-driving cars. Advanced LiDAR perception systems typically leverage deep neural networks (DNNs) to achieve high performance. However, the vulnerability of DNNs to malicious attacks provides attackers with the means to compromise the LiDAR perception system, potentially causing traffic accidents. Recently, object-based attacks against LiDAR perception systems have drawn significant attention. In such attacks, the attacker can easily fool the LiDAR perception system by placing physical objects within the driving environment. Despite the practicality of these attacks and their potential catastrophic consequences in autonomous driving, there is currently no effective and practical defense against them. To address this issue, we propose a novel online defense mechanism against object-based LiDAR attacks. This mechanism operates in an online manner, aiming to identify and remove the adversarial LiDAR points generated by the objects used by attackers before the data is fed into the perception module of autonomous driving systems. It is not only effective and efficient for real-world autonomous driving but also attack-agnostic and capable of identifying adversarial objects used by attackers. Extensive experiments in both simulated environments and real-world scenarios using a LiDAR perception testbed demonstrate the effectiveness and practicability of the proposed defense. Yan Zhang 0133, Zihao Liu 0001, Chongliu Jia, Yi Zhu 0012, Chenglin Miao |
SenSys | 1 |
| 2023 | Protecting Your Voice from Speech Synthesis AttacksabstractIn recent years, much attention has been paid to speech synthesis, which aims to generate synthetic speeches in a voice of a target speaker. Although the speech synthesis technique has facilitated a wide spectrum of applications that positively impact our daily lives, it can also be used by attackers to perform speech synthesis attacks. An attacker can use this technique to mimic the voice of a victim and transform arbitrarily chosen text or voice samples into the same content spoken by the victim. To protect a speaker’s voice from speech synthesis attacks, in this paper, we propose two novel defense schemes that can be used by the speaker to process his or her speeches before publishing them on social media platforms or sending them to others. The processed speeches cannot only significantly degrade the performance of speech synthesis systems but also keep the sound of the speaker’s voice so that they can still be used for normal purposes. The desirable performance of the proposed defense schemes is verified through extensive experiments conducted on several real-world speaker recognition (SR) systems and a user study on a public crowdsourcing platform. Zihao Liu 0001, Yan Zhang 0133, Chenglin Miao |
ACSAC | 2 |
| 2022 | Towards Backdoor Attacks against LiDAR Object Detection in Autonomous DrivingabstractDue to the great advantage of LiDAR sensors in perceiving complex driving environments, LiDAR-based 3D object detection has recently drawn significant attention in autonomous driving. Although many advanced LiDAR object detection models have been developed, their designs are mainly based on deep learning approaches, which are usually data-hungry and expensive to train. Thus, it is common for some LiDAR perception system developers or self-driving car companies to collect training data from different sources (e.g., self-driving car users) or outsource the training work to a third party. However, these practices provide opportunities for backdoor attacks, where the attacker aims to inject a hidden trigger pattern into the victim detection model by poisoning its training set and let the model fail to detect objects when the trigger presents in the inference phase. Although backdoor attacks have posed serious security concerns, the vulnerability of LiDAR object detection to such attacks has not yet been studied. To fill the research gap, in this paper, we present the first study on backdoor attacks against LiDAR object detection in autonomous driving. Specifically, we propose a novel backdoor attack strategy based on which the attacker can achieve the attack goal by poisoning a small number of point cloud samples. In addition, the proposed attack strategy is physically realizable, and it allows the attacker to easily perform the attack using some common objects as the triggers. To make the poisoned samples difficult to be detected, we also design a stealthy attack strategy by creating some fake vehicle point clusters to hide the injected points in the point cloud. The desirable performance of our attacks is demonstrated through both simulation and real-world case study. Yan Zhang 0133, Yi Zhu 0012, Zihao Liu 0001, Chenglin Miao, Foad Hajiaghajani, Lu Su 0001, Chunming Qiao |
SenSys | 1 |