EDBT 2026 Demo / reviewers in the wild / expert
Wei Zhang 0251
dblp:10/4661-251
· DBLP profile ↗
4ranked-venue papers
0as first author
4since 2021 · last 2025
0009-0001-5132-7498ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Explore the Effect of Data Selection on Poison Efficiency in Backdoor AttacksabstractDeep Neural Networks (DNNs) have achieved remarkable success across a wide range of tasks; however, their susceptibility to backdoor attacks remains a significant concern. Existing methods predominantly focus on optimizing the construction phase of backdoor attacks, aiming to reduce the detectability of trigger patterns and enhance stealth. In contrast, the selection phase—specifically the identification of appropriate benign samples for poisoning—has received limited attention. Recent studies have explored efficient poisoning sample selection to improve attack stealth. However, the underlying factors that determine the informativeness or effectiveness of a sample for backdoor learning remain poorly understood. To address this gap, we investigate the role of forgettable event and loss landscape curvature in enhancing poisoning sample efficiency. Our findings reveal that samples most likely to be forgotten during the poisoning process are crucial for effective attacks, and that low-curvature regions of the loss surface correlate with higher poisoning efficiency. Based on these insights, we introduce the Improved Filtering and Updating Strategy (FUS++), which significantly outperforms traditional selection methods in terms of efficiency. Our contributions provide new perspectives on sample selection for backdoor attacks and propose a novel strategy to improve poisoning efficacy. Ziqiang Li 0001, Yueqi Zeng, Wei Zhang 0251, Bin Li 0025 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | Frequency Decomposition to Tap the Potential of Single Domain for Generalization
Hongjing Niu, Qingyue Yang, Wei Zhang 0251, Bin Li 0025, Feng Zhao 0004 |
BMVC | 4 |
| 2024 | A Proxy Attack-Free Strategy for Practically Improving the Poisoning Efficiency in Backdoor AttacksabstractPoisoning efficiency is crucial in poisoning-based backdoor attacks, as attackers aim to minimize the number of poisoning samples while maximizing attack efficacy. Recent studies have sought to enhance poisoning efficiency by selecting effective samples. However, these studies typically rely on a proxy backdoor injection task to identify an efficient set of poisoning samples. This proxy attack-based approach can lead to performance degradation if the proxy attack settings differ from those of the actual victims, due to the shortcut nature of backdoor learning. Furthermore, proxy attack-based methods are extremely time-consuming, as they require numerous complete backdoor injection processes for sample selection. To address these concerns, we present a Proxy attack-Free Strategy (PFS) designed to identify efficient poisoning samples based on the similarity between clean samples and their corresponding poisoning samples, as well as the diversity of the poisoning set. The proposed PFS is motivated by the observation that selecting samples with high similarity between clean and corresponding poisoning samples results in significantly higher attack success rates compared to using samples with low similarity. Additionally, we provide theoretical foundations to explain the proposed PFS. We comprehensively evaluate the proposed strategy across various datasets, triggers, poisoning rates, architectures, and training hyperparameters. Our experimental results demonstrate that PFS enhances backdoor attack efficiency while also offering a remarkable speed advantage over previous proxy attack-based selection methodologies. Ziqiang Li 0001, Beihao Xia, Xue Rui, Wei Zhang 0251, Qinglang Guo, Zhangjie Fu 0001, Bin Li 0025 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2022 | Data-Efficient Backdoor AttacksabstractRecent studies have proven that deep neural networks are vulnerable to backdoor attacks. Specifically, by mixing a small number of poisoned samples into the training set, the behavior of the trained model can be maliciously controlled. Existing attack methods construct such adversaries by randomly selecting some clean data from the benign set and then embedding a trigger into them. However, this selection strategy ignores the fact that each poisoned sample contributes inequally to the backdoor injection, which reduces the efficiency of poisoning. In this paper, we formulate improving the poisoned data efficiency by the selection as an optimization problem and propose a Filtering-and-Updating Strategy (FUS) to solve it. The experimental results on CIFAR-10 and ImageNet-10 indicate that the proposed method is effective: the same attack success rate can be achieved with only 47% to 75% of the poisoned sample volume compared to the random selection strategy. More importantly, the adversaries selected according to one setting can generalize well to other settings, exhibiting strong transferability. The prototype code of our method is now available at https://github.com/xpf/Data-Efficient-Backdoor-Attacks. Ziqiang Li 0001, Wei Zhang 0251, Bin Li 0025 |
IJCAI | 3 |