Mengda Yang

dblp:116/8591 · DBLP profile ↗
← Back
14ranked-venue papers
2as first author
14since 2021 · last 2026
0000-0002-7808-852XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 6 · 1 first-author · 6 since 2021Security and privacy · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 SLeak: Multi-Target Privacy Stealing Attack Against Split Learning
abstract
Split Learning (SL) is a distributed learning framework that has gained popularity for its privacy-preserving nature and low computational demands. However, recent studies have the potential that a server adversary to carry out inference attacks, compromising the privacy of victim clients. Nevertheless, upon re-evaluating prior studies, we found that existing methods rely on overly strong assumptions to enhance their performance, resulting in a significant decline in effectiveness under more realistic scenarios. In this work, we provide new insights into the inherent vulnerabilities of SL. Specifically, we discover that both the smashed data and the server model contain the client's representation preference, which the server adversary can exploit to build a substitute client that approximates the target client's unique feature extraction behavior. With a well-trained substitute client, the server can perfectly steal the target client's functionality, training data, and labels. Building on this observation, we introduce Split Leakage (SLeak), a new threat that targets multiple privacy stealing objectives against SL. Notably, SLeak does not depend on strong privacy priors and only requires partial same-domain auxiliary public data to conduct the attacks. Experimental results on diverse datasets and target models show that SLeak surpasses the state-of-the-art method across multiple metrics. Moreover, ablation studies further confirm its robustness and applicability under various scenarios and assumptions.
Xiaoyang Xu 0001, Wenzhe Yi, Juan Wang 0006, Hongxin Hu, Mengda Yang, Yong Zhuang, Mang Ye
IEEE Trans. Pattern Anal. Mach. Intell.5
2026 Palladium: Guarding Neural Network Training With Confidential Computing
abstract
In the era of deep learning, protecting the training data and model parameters of high-performance Deep Neural Networks (DNNs) is critical. Data holders often want to use private data to train dedicated DNNs while leveraging AI accelerators hosted on remote servers, such as GPUs or TPUs. However, cloud systems are vulnerable to adversaries who may compromise both computational integrity and user data privacy. Performing verifiable and private training without losing access to untrusted accelerators remains a significant challenge. While previous works rely on Trusted Execution Environments (TEEs) to safeguard privacy during inference, they primarily address forward propagation and are not suitable for backward propagation in training. To address this limitation, this paper proposesPalladium, the first system to achieve confidentiality, integrity, and low latency for both model parameters and training data.Palladiumleverages TEE-empowered confidential computing to protect privacy and verify integrity, while securely outsourcing most linear layer computations to untrusted GPUs to optimize performance. Specifically,Palladiumpreserves the confidentiality of outsourced parameters by transforming the weights of linear operators and generating input masks through a carefully designedCloakstrategy. It then fully recovers the execution results inside the TEE using the correspondingUnCloakstrategy. To further ensure computational integrity,Palladiumincorporates a stochastic operator verification mechanism that detects breaches outside the TEE with 99% confidence. We implement a prototype ofPalladiumbased on Libtorch and Occlum and conduct a comprehensive evaluation on four network architectures and four datasets. Evaluation results show thatPalladiumprovides strong security guarantees with reasonable performance overhead, preserves high training accuracy, and protects model privacy.
Wenzhe Yi, Mengda Yang, Juan Wang 0006, Hongxin Hu, Xiaoyang Xu 0001
IEEE Trans. Dependable Secur. Comput.2
2025 From Head to Tail: Efficient Black-box Model Inversion Attack via Long-tailed Learning
abstract
Model Inversion Attacks (MIAs) aim to reconstruct private training data from models, leading to privacy leakage, particularly in facial recognition systems. Although many studies have enhanced the effectiveness of white-box MIAs, less attention has been paid to improving efficiency and utility under limited attacker capabilities. Existing black-box MIAs necessitate an impractical number of queries, incurring significant overhead. Therefore, we analyze the limitations of existing MIAs and introduce Surrogate Model-based Inversion with Long-tailed Enhancement (SMILE), a high-resolution oriented and query-efficient MIA for the black-box setting. We begin by analyzing the initialization of MIAs from a data distribution perspective and propose a long-tailed surrogate training method to obtain high-quality initial points. We then enhance the attack’s effectiveness by employing the gradient-free black-box optimization algorithm selected by NGOpt. Our experiments show that SMILE outperforms existing state-of-the-art black-box MIAs while requiring only about 5% of the query overhead. Our code is available at https://github.com/L1ziang/SMILE.
Juan Wang 0006, Meihui Chen, Hongxin Hu, Wenzhe Yi, Xiaoyang Xu 0001, Mengda Yang, Chenjun Ma
CVPR8
2025 BiFD: A Bidirectional Feature Discrepancy Defense against Hijacking Attack in Split Learning
abstract
Split Learning (SL) is a widely adopted distributed privacy-preserving training paradigm with minimal computational overhead for clients. However, Feature-Space Hijacking Attack (FSHA) poses a significant threat against SL, where the server manipulates the client's optimization process, compromising input privacy. Some studies propose that clients can detect potential hijacking by monitoring the gradients returned by the server. However, these gradient-based methods are vulnerable to adversarial anti-detection and lack robustness to changes in model architecture. In this paper, we propose a novel detection method named Bidirectional Feature Discrepancy Defense (BiFD), which leverages features to capture richer semantic information. We also observe that hijacked features are easier to reconstruct and harder to classify, providing a key distinction between malicious and honest servers—an aspect overlooked in previous works. Extensive results across multiple datasets and model architectures demonstrate the excellent and robust performance of BiFD.
Xiaoyang Xu 0001, Wenzhe Yi, Juan Wang 0006, Yong Zhuang, Mengda Yang
ICME5
2025 I know what you MEME! Understanding and Detecting Harmful Memes with Multimodal Large Language Models
Yong Zhuang, Keyan Guo, Juan Wang 0006, Yiheng Jing, Xiaoyang Xu 0001, Wenzhe Yi, Mengda Yang, Bo Zhao 0023, Hongxin Hu
NDSS7
2025 Stealing Data from Active Party in Vertical Split Learning
Xiaoyang Xu 0001, Wenzhe Yi, Yong Zhuang, Juan Wang 0006, Mengda Yang
ECML/PKDD (5)6
2024 Is Difficulty Calibration All We Need? Towards More Practical Membership Inference Attacks
abstract
The vulnerability of machine learning models to Membership Inference Attacks (MIAs) has garnered considerable attention in recent years. These attacks determine whether a data sample belongs to the model's training set or not. Recent research has focused on reference-based attacks, which leverage difficulty calibration with independently trained reference models. While empirical studies have demonstrated its effectiveness, there is a notable gap in our understanding of the circumstances under which it succeeds or fails. In this paper, we take a further step towards a deeper understanding of the role of difficulty calibration. Our observations reveal inherent limitations in calibration methods, leading to the misclassification of non-members and suboptimal performance, particularly on high-loss samples. We further identify that these errors stem from an imperfect sampling of the potential distribution and a strong dependence of membership scores on the model parameters. By shedding light on these issues, we propose RAPID: a query-efficient and computation-efficient MIA that directly Re-leverAges the original membershiP scores to mItigate the errors in Difficulty calibration. Our experimental results, spanning 9 datasets and 5 model architectures, demonstrate that RAPID outperforms previous state-of-the-art attacks (e.g., LiRA and Canary offline) across different metrics while remaining computationally efficient. Our observations and analysis challenge the current de facto paradigm of difficulty calibration in high-precision inference, encouraging greater attention to the persistent risks posed by MIAs in more practical scenarios.
Yu He 0009, Boheng Li, Mengda Yang, Juan Wang 0006, Hongxin Hu, Xingyu Zhao 0001
CCS4
2024 CCall: Recovering Indirect Call Targets from Binaries With Cross-Domain Fine-Tuning
abstract
Reconstructing control flow graphs from stripped binaries remains a conundrum. One of the crucial challenges is recovering the targets of indirect calls. Existing solutions rely heavily on expert knowledge or have limited generalization capability. In this paper, we propose CCall, a novel solution that combines neural network models with a cross-domain fine-tuning strategy to automatically identify the targets of indirect calls. To make up for the shortcomings of existing methods and obtain sufficient code semantics from binaries, we introduce the concept of Inter-procedural Control Flow Sub graph (ICFSG) to capture the complete execution flow and path-sensitive semantics. Additionally, we pre-train a representation model for fine-grained embedding of binary code and design a composite neural network to capture the contextual relationship between indirect call sites and their targets. To improve performance when dealing with binaries exhibiting diverse semantics, we integrate domain adaptation into binary analysis and conduct a cross-domain fine-tuning strategy, which allows the model to learn the distinctive distribution and semantics of unlabeled test binaries. Evaluated on groups of binaries with over 6 million indirect call samples, CCall achieves an Fl-score of 92.54%, outperforming existing solutions. We extended our evaluations to different optimization levels, architectures, and compiles to gain deeper insights into the cross-domain capability of our solution. The evaluation demonstrates that our cross-domain fine-tuning strategy enhances the model's generalization ability and can be applied to other AI-based binary analysis tasks.
Yunru Wang, Juan Wang 0006, Mengda Yang, Fei Li 0021
COMPSAC4
2024 A Stealthy Wrongdoer: Feature-Oriented Reconstruction Attack Against Split Learning
abstract
Split Learning (SL) is a distributed learning framework renowned for its privacy-preserving features and minimal computational requirements. Previous research consistently highlights the potential privacy breaches in SL systems by server adversaries reconstructing training data. However, these studies often rely on strong assumptions or compromise system utility to enhance attack performance. This paper introduces a new semi-honest Data Reconstruction Attack on SL, named Feature-Oriented Reconstruction Attack (FORA). In contrast to prior works, FORA relies on limited prior knowledge, specifically that the server utilizes auxiliary samples from the public without knowing any client's private information. This allows FORA to conduct the attack stealthily and achieve robust performance. The key vulnerability exploited by FORA is the revelation of the model representation preference in the smashed data output by victim client. FORA constructs a substitute client through feature-level transfer learning, aiming to closely mimic the victim client's representation preference. Leveraging this substitute client, the server trains the attack model to effectively reconstruct private data. Extensive experiments showcase FORA's superior performance compared to state-of-the-art methods. Furthermore, the paper systematically evaluates the proposed method's applicability across diverse settings and advanced defense strategies.
Xiaoyang Xu 0001, Mengda Yang, Wenzhe Yi, Juan Wang 0006, Hongxin Hu, Yong Zhuang
CVPR2
2024 Penetralium: Privacy-preserving and memory-efficient neural network inference at the edge
Mengda Yang, Wenzhe Yi, Juan Wang 0006, Hongxin Hu, Xiaoyang Xu 0001
Future Gener. Comput. Syst.1
2023 GAN You See Me? Enhanced Data Reconstruction Attacks against Split Inference
abstract
Split Inference (SI) is an emerging deep learning paradigm that addresses computational constraints on edge devices and preserves data privacy through collaborative edge-cloud approaches. However, SI is vulnerable to Data Reconstruction Attacks (DRA), which aim to reconstruct users' private prediction instances. Existing attack methods suffer from various limitations. Optimization-based DRAs do not leverage public data effectively, while Learning-based DRAs depend heavily on auxiliary data quantity and distribution similarity. Consequently, these approaches yield unsatisfactory attack results and are sensitive to defense mechanisms. To overcome these challenges, we propose a GAN-based LAtent Space Search attack (GLASS) that harnesses abundant prior knowledge from public data using advanced StyleGAN technologies. Additionally, we introduce GLASS++ to enhance reconstruction stability. Our approach represents the first GAN-based DRA against SI, and extensive evaluation across different split points and adversary setups demonstrates its state-of-the-art performance. Moreover, we thoroughly examine seven defense mechanisms, highlighting our method's capability to reveal private information even in the presence of these defenses.
Mengda Yang, Juan Wang 0006, Hongxin Hu, Wenzhe Yi, Xiaoyang Xu 0001
NeurIPS2
2023 Enhance the trust between IoT devices, mobile apps, and the cloud based on blockchain
Juan Wang 0006, Wenzhe Yi, Mengda Yang, Jiaci Ma, Shengzhi Zhang, Shirong Hao
J. Netw. Comput. Appl.3
2023 SvTPM: SGX-Based Virtual Trusted Platform Modules for Cloud Computing
abstract
Virtual Trusted Platform Modules (vTPMs) are widely used in commercial cloud platforms (e.g., VMware Cloud, Google Cloud, and Microsoft Azure) to provide virtual root-of-trust and security services for virtual machines. Unfortunately, current state-of-the-art vTPM implementations for cloud computing cannot provide strong protection for vTPMs at run-time and suffer from poor performance under binding vTPMs to a physical TPM. In this paper, we propose SvTPM, an SGX-based virtual trusted platform module, which provides complete life cycle protection of vTPMs in the cloud and does not rely on the physical TPM. SvTPM provides strong isolation protection so malicious cloud tenants or even cloud administrators cannot access vTPM's private keys or any other sensitive data. In this paper, we implement a prototype of SvTPM, which identifies and solves a couple of critical security challenges for vTPM protection with SGX, such as NVRAM rollback attacks, NVRAM binding attacks, and vTPM rollback attacks. SvTPM also shows how to establish trust between vTPM and SGX Platform. Our performance evaluation shows that the NVRAM launch time of SvTPM is$1700\times$faster than vTPM built upon hardware TPM. In TPM standard command evaluation, we find that SvTPM incurs negligible performance overhead while providing strong isolation and protection. To our knowledge, SvTPM is the first practical work to solve the critical security challenges of securing vTPM using SGX.
Juan Wang 0006, Jie Wang 0006, Chengyang Fan, Fei Yan 0008, Yueqiang Cheng, Yinqian Zhang, Mengda Yang, Hongxin Hu
IEEE Trans. Cloud Comput.8
2022 Measuring Data Reconstruction Defenses in Collaborative Inference Systems
abstract
The collaborative inference systems are designed to speed up the prediction processes in edge-cloud scenarios, where the local devices and the cloud system work together to run a complex deep-learning model. However, those edge-cloud collaborative inference systems are vulnerable to emerging reconstruction attacks, where malicious cloud service providers are able to recover the edge-side users’ private data. To defend against such attacks, several defense countermeasures have been recently introduced. Unfortunately, little is known about the robustness of those defense countermeasures. In this paper, we take the first step towards measuring the robustness of those state-of-the-art defenses with respect to reconstruction attacks. Specifically, we show that the latent privacy features are still retained in the obfuscated representations. Motivated by such an observation, we design a technology called Sensitive Feature Distillation (SFD) to restore sensitive information from the protected feature representations. Our experiments show that SFD can break through defense mechanisms in model partitioning scenarios, demonstrating the inadequacy of existing defense mechanisms as a privacy-preserving technique against reconstruction attacks. We hope our findings inspire further work in improving the robustness of defense mechanisms against reconstruction attacks for collaborative inference systems.
Mengda Yang, Juan Wang 0006, Hongxin Hu, Ao Ren, Xiaoyang Xu 0001, Wenzhe Yi
NeurIPS1