Leo Yu Zhang

dblp:117/3526 · DBLP profile ↗
← Back
16ranked-venue papers in the field
1as first author
12since 2021 · last 2026
0000-0001-9330-2662ORCID · verified

Domains — venue-derived; a paper can count in several

Knowledge Engineering, Semantic Web & Information Systems · 8 (1 first)Data Mining & Knowledge Discovery · 5Information Retrieval & Web Search · 3
YearPublicationVenuePosition
2026 Beyond Denial-of-Service: The Puppeteer's Attack for Fine-Grained Control in Ranking-Based Federated Learning
Zirui Gong, Jianting Ning, Yanjun Zhang 0002, Leo Yu Zhang
WWW5
2026 Lightweight multi-client order-revealing encryption with limited leakage
Chunyang Lv, Jianfeng Wang 0001, Shifeng Sun 0001, Saiyu Qi, Chao Chen 0015, Leo Yu Zhang, Kok-Leong Ong
Inf. Sci.6
2025 TED++: Submanifold-Aware Backdoor Detection via Layerwise Tubular-Neighbourhood Screening
abstract
As deep neural networks power increasingly critical applications, stealthy backdoor attacks, where poisoned training inputs trigger malicious model behaviour while appearing benign, pose a severe security risk. Many existing defences are vulnerable when attackers exploit subtle distance-based anomalies or when clean examples are scarce. To meet this challenge, we introduce TED++, a submanifold-aware framework that effectively detects subtle backdoors that evade existing defences. TED++ begins by constructing a tubular neighbourhood around each class's hidden-feature manifold, estimating its local “thickness” from a handful of clean activations. It then applies Locally Adaptive Ranking (LAR) to detect any activation that drifts outside the admissible tube. By aggregating these LAR-adjusted ranks across all layers, TED++ captures how faithfully an input remains on the evolving class submanifolds. Based on such characteristic “tube-constrained” behaviour, TED++ flags inputs whose LAR-based ranking sequences deviate significantly. Extensive experiments are conducted on benchmark datasets and tasks, demonstrating that TED++ achieves state-of-the-art detection performance under both adaptive-attack and limited-data scenarios. Remarkably, even with only five held-out examples per class, TED++ still delivers near-perfect detection, achieving gains of up to 14% in AUROC over the next-best method. The code is publicly available at https://github.com/namle-w/TEDpp.
Nam Le 0006, Leo Yu Zhang, Kewen Liao, Shirui Pan, Wei Luo 0001
ICDM2
2025 Scale Margin Loss for Object Detection
Yuxuan Cheng, Yanjun Zhang 0002, Leo Yu Zhang, Donald Donglong Chen, Yuming Fang 0001
KSEM (2)3
2025 MarkErase: Defeating Entangled Watermarks in Model Extraction Attacks
Xinjing Liu, Yanjun Zhang 0002, Haizhuan Yuan, Tianqing Zhu, Leo Yu Zhang
PAKDD (4)6
2025 Arms Race in Deep Learning: A Survey of Backdoor Defenses and Adaptive Attacks
Xiaoxing Mo, Nan Sun 0002, Leo Yu Zhang, Wei Luo 0001, Shang Gao 0003, Yong Xiang 0001
PAKDD (4)3
2025 Uncertainty-Aware Metabolic Stability Prediction with Dual-View Contrastive Learning
Peijin Guo, Hewen Pan, Zikang Guo, Leo Yu Zhang, Shengshan Hu, Shengqing Hu
ECML/PKDD (3)7
2025 Differentially private recommendation algorithm based on diffusion model and Rényi similarity
Yong Wang 0009, Jiangzhou Deng, Jianmei Ye, Leo Yu Zhang
Inf. Sci.6
2024 Deceptive Waves: Embedding Malicious Backdoors in PPG Authentication
Zeming Yao, Lin Li 0066, Leo Yu Zhang, Fusen Guo, Chao Chen 0015, Jun Zhang 0010
WISE (2)3
2024 Matrix factorization recommender based on adaptive Gaussian differential privacy for implicit feedback
Yong Wang 0009, Jiangzhou Deng, Chao Chen 0015, Leo Yu Zhang
Inf. Process. Manag.6
2022 A differentially private nonnegative matrix factorization for recommender system
Xun Ran, Yong Wang 0009, Leo Yu Zhang, Jun Ma 0003
Inf. Sci.3
2021 An effective and efficient fuzzy approach for managing natural noise in recommender systems
Yong Wang 0009, Leo Yu Zhang, Hong Zhu 0003
Inf. Sci.3
2020 Protecting IP of Deep Neural Networks with Watermarking: A New Label Helps
Leo Yu Zhang, Jun Zhang 0010, Longxiang Gao, Yong Xiang 0001
PAKDD (2)2
2020 A genetic algorithm for constructing bijective substitution boxes with high nonlinearity
Yong Wang 0009, Leo Yu Zhang, Jun Feng 0007, Jerry Zeyu Gao
Inf. Sci.3
2019 Efficiently and securely outsourcing compressed sensing reconstruction to a cloud
Yushu Zhang 0001, Yong Xiang 0001, Leo Yu Zhang, Lu-Xing Yang, Jiantao Zhou 0001
Inf. Sci.3
2018 Improved known-plaintext attack to permutation-only multimedia ciphers
Leo Yu Zhang, Yuansheng Liu, Cong Wang 0001, Jiantao Zhou 0001, Yushu Zhang 0001, Guanrong Chen
Inf. Sci.1