EDBT 2026 Demo / reviewers in the wild / expert
Yuefeng Peng
dblp:122/5631
· DBLP profile ↗
5ranked-venue papers
3as first author
4since 2021 · last 2026
0009-0000-1551-0642ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Exploiting Leaderboards for Large-Scale Distribution of Malicious ModelsabstractWhile poisoning attacks on machine learning models have been extensively studied, the mechanisms by which adversaries can distribute poisoned models at scale remain largely unexplored. In this paper, we shed light on how model leaderboards -- ranked platforms for model discovery and evaluation -- can serve as a powerful channel for adversaries for stealthy large-scale distribution of poisoned models. We present TrojanClimb, a general framework that enables injection of malicious behaviors while maintaining competitive leaderboard performance. We demonstrate its effectiveness across four diverse modalities: text-embedding, text-generation, text-to-speech and text-to-image, showing that adversaries can successfully achieve high leaderboard rankings while embedding arbitrary harmful functionalities, from backdoors to bias injection. Our findings reveal a significant vulnerability in the machine learning ecosystem, highlighting the urgent need to redesign leaderboard evaluation mechanisms to detect and filter malicious (e.g., poisoned) models, while exposing broader security implications for the machine learning community regarding the risks of adopting models from unverified sources. Anshuman Suri, Harsh Chaudhari, Yuefeng Peng, Ali Naseh, Alina Oprea, Amir Houmansadr |
SP | 3 |
| 2025 | Riddle Me This! Stealthy Membership Inference for Retrieval-Augmented GenerationabstractRetrieval-Augmented Generation (RAG) enables Large Language Models (LLMs) to generate grounded responses by leveraging external knowledge databases without altering model parameters. Although the absence of weight tuning prevents leakage via model parameters, it introduces the risk of inference adversaries exploiting retrieved documents in the model's context. Existing methods for membership inference and data extraction often rely on jailbreaking or carefully crafted unnatural queries, which can be easily detected or thwarted with query rewriting techniques common in RAG systems. In this work, we present øurattackfull (øurattack), a membership inference technique targeting documents in the RAG datastore. By crafting natural-text queries that are answerable only with the target document's presence, our approach demonstrates successful inference with just 30 queries while remaining stealthy; straightforward detectors identify adversarial prompts from existing methods up to ~76× more frequently than those generated by our attack. We observe a 2× improvement in TPR@1%FPR over prior inference attacks across diverse RAG configurations, all while costing less than $0.02 per document inference. Ali Naseh, Yuefeng Peng, Anshuman Suri, Harsh Chaudhari, Alina Oprea, Amir Houmansadr |
CCS | 2 |
| 2025 | Diffence: Fencing Membership Privacy With Diffusion Models
Yuefeng Peng, Ali Naseh, Amir Houmansadr |
NDSS | 1 |
| 2024 | OSLO: One-Shot Label-Only Membership Inference AttacksabstractWe introduce One-Shot Label-Only (OSLO) membership inference attacks (MIAs), which accurately infer a given sample's membership in a target model's training set with high precision using just a single query, where the target model only returns the predicted hard label.
This is in contrast to state-of-the-art label-only attacks which require $\sim6000$ queries, yet get attack precisions lower than OSLO's.
OSLO leverages transfer-based black-box adversarial attacks. The core idea is that a member sample exhibits more resistance to adversarial perturbations than a non-member. We compare OSLO against state-of-the-art label-only attacks and demonstrate that, despite requiring only one query, our method significantly outperforms previous attacks in terms of precision and true positive rate (TPR) under the same false positive rates (FPR). For example, compared to previous label-only MIAs, OSLO achieves a TPR that is at least 7$\times$ higher under a 1\% FPR and at least 22$\times$ higher under a 0.1\% FPR on CIFAR100 for a ResNet18 model. We evaluated multiple defense mechanisms against OSLO. Yuefeng Peng, Jaechul Roh, Subhransu Maji, Amir Houmansadr |
NeurIPS | 1 |
| 2012 | Mobility performance enhancements for LTE-Advanced heterogeneous networksabstractHeterogeneous Networks (HetNets) has attracted considerable attention since they can improve the system capacity and user throughput in Long Term Evolution (LTE)-Advanced system. However, due to the different coverage sizes for macro eNodeB (eNB) and pico eNB, the handover performance of UE will be impacted especially when the user equipment (UE) moves in medium or high speed in HetNets. Three metrics are agreed in 3GPP RAN WG2 to evaluate the handover performance: radio link failure (RLF) rate, handover failure (HOF) rate, and short time of stay (short ToS). In this paper, firstly, based on the three metrics, the handover performance in HetNets is analyzed. Then, we propose two schemes to solve the issue of handover performance deterioration when UE moves in medium speed. One scheme is to optimize pico-macro handover, and the other is to optimize macro-pico handover. In other words, two schemes can separately optimize pico cell leaving and attaching. Furthermore, the two schemes can be used jointly to further improve the mobility robustness in HetNets. System level simulation is employed to present the handover performance improvement. Yuefeng Peng, Wei Yang 0029, Yujian Zhang |
PIMRC | 1 |