Duohe Ma

dblp:14/1555 · DBLP profile ↗
← Back
27ranked-venue papers
5as first author
20since 2021 · last 2026
0000-0002-2160-8344ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 4 first-author · 8 since 2021Computer networks · 6 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 TriPlay-RL: Tri-Role Self-Play Reinforcement Learning for LLM Safety Alignment
abstract
Zhewen Tan, Wenhan Yu, Jianfeng Si, Tongxin Liu, Kaiqi Guan, Huiyan Jin, Jiawen Tao, Xiaokun Yuan, Xiangzheng Zhang, Duohe Ma, Tong Yang, Lin Sun. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026.
Zhewen Tan, Wenhan Yu, Jianfeng Si, Tongxin Liu, Kaiqi Guan, Huiyan Jin, Jiawen Tao, Xiaokun Yuan, Xiangzheng Zhang, Duohe Ma, Tong Yang 0003, Lin Sun 0010
ACL (1)10
2026 Mirror Asymmetry Perfect Hashing: A Memory-Efficient and Load-Intensive-Optimized Hashing Index on Hybrid DRAM-PMem Architecture
Jingcheng Ju, Zirui Liu 0002, Kaicheng Yang 0001, Yikai Zhao 0001, Tong Yang 0003, Xingchun Wang, Duohe Ma
ICDE9
2026 Beyond Patches: Superpixel Token-based Transformers for Attribute-Specific Fashion Retrieval
abstract
Attribute-Specific Fashion Retrieval (ASFR) aims to improve fine-grained image retrieval by focusing on specific attributes. However, existing patch-based attention and Transformer methods often misalign with irregular attribute regions and are prone to background noise, limiting their ability to capture subtle, pixel-level microstructures. To tackle these challenges, we propose Super Fashion., the first ASFR framework that adopts superpixel tokens within a Transformer architecture. Super Fashion initially employs an attribute-guided attention mechanism to extract attribute-related features, which in turn guide the cropping of semantically meaningful image regions. Superpixel segmentation is then leveraged on these regions to generate compact, semantically coherent superpixel tokens. By incorporating modality-specific embeddings for both attribute and superpixel tokens, the superpixel token-based Transformer facilitates adaptive interaction and fusion, thereby enhancing attribute localization and discrimination. Extensive experiments on FashionAI, DARN, and DeepFashion demonstrate relative overall MAP improvements of 1.84%, 9.27%, and 9.35% over prior SOTA. Super Fashion offers a new solution for web-based image retrieval.
Shuili Zhang, Hongzhang Mu, Wenyuan Zhang 0002, Duohe Ma, Tingwen Liu
WWW4
2025 Debiasing Multimodal Large Language Models via Noise-Aware Preference Optimization
abstract
Multimodal Large Language Models (MLLMs) excel in various tasks, yet often struggle with modality bias, where the model tends to rely heavily on a single modality and overlook critical information in other modalities, which leads to incorrect focus and generating irrelevant responses. In this paper, we propose using the paradigm of preference optimization to solve the modality bias problem, including RLAIF-V-Bias, a debiased preference optimization dataset, and a Noise-Aware Preference Optimization (NaPO) algorithm. Specifically, we first construct the dataset by introducing perturbations to reduce the informational content of certain modalities, compelling the model to rely on a specific modality when generating negative responses. To address the inevitable noise in automatically constructed data, we combine the noise-robust Mean Absolute Error (MAE) with the Binary Cross-Entropy (BCE) in Direct Preference Optimization (DPO) by a negative Box-Cox transformation, and dynamically adjust the algorithm’s noise robustness based on the evaluated noise levels in the data. Extensive experiments validate our approach, demonstrating not only its effectiveness in mitigating modality bias but also its significant role in minimizing hallucinations. The code and data is available at https://github.com/zhangzef/NaPO.
Zefeng Zhang 0001, Hengzhu Tang, Jiawei Sheng, Zhenyu Zhang 0006, Dawei Yin 0001, Duohe Ma, Tingwen Liu
CVPR8
2025 Translational Generative Retrieval via Potential Query Generation
abstract
Document retrieval aims to find documents related to the query from all candidate documents. Existing studies develop the Generative Retrieval approach, which assigns a unique DocID to each document, and then measures document-query relevance based on the probability of generating the expected DocID for the given query. However, the generated DocID can have expressive limitation of different semantic topics, leading to semantic gaps in document retrieval. Besides, existing GR models usually suffer from the catastrophic forgetting when memorizing new documents incrementally, which makes real-world application impractical. To overcome these issues, we propose Translational Generative Retrieval, which translates each document into potential queries reflecting different topics, specifically by a sequence of token probability distributions. To better model the semantics of potential queries and effectively decode the target query from the distributions, we propose DirEcted Acyclic Graph Retrieval (DEAR) model, which reforms the distributions from a non-autoregressive generative model into a Directed Acyclic Graph. Experimental results demonstrate that DEAR outperforms existing retrieval models, setting a new state-of-the-art in generative retrieval.
Tingwen Liu, Jiawei Sheng, Duohe Ma, Ling Tian
ICASSP4
2025 Zero-Shot Cross-Domain Slot Filling with Retrieval Augmented In-Context Learning
abstract
Zero-shot cross-domain slot filling is becoming increasingly important due to its ability to generalize to new domains without the need for annotating domain-specific data, which aligns well with the requirements of industrial deployments. Recent advanced works deal with this task through question answering framework and make remarkable progress. However, they always rely on human efforts to manually construct question templates or prompts for all slot types, which is not only labor consuming, but also experience context inconsistency issue between the manual example and the specific test instance. To alleviate this problem, we introduce a retriever designed to extract reference samples from the training sets, serving as demonstrations to guide the model in generating the target slot entity through in-context learning. Building upon this retriever, we propose a retrieval-augmented generative framework that automatically constructs and tailors prompts to each specific test instance, eliminating the need for manual efforts. Experiment results verify that our approach attains the state-of-the-art.
Mengxiao Song, Tingwen Liu, Quangang Li, Duohe Ma, Ling Tian
ICASSP4
2025 Construction and Application of Vulnerability Intelligence Ontology Under Vulnerability Management Perspective
Guangxiang Dai, Duohe Ma
ICICS (3)3
2025 Mitigating Modality Bias in Multi-modal Entity Alignment from a Causal Perspective
abstract
Multi-Modal Entity Alignment (MMEA) aims to retrieve equivalent entities from different Multi-Modal Knowledge Graphs (MMKGs), a critical information retrieval task.Existing studies have explored various fusion paradigms and consistency constraints to improve the alignment of equivalent entities, while overlooking that the visual modality may not always contribute positively.Empirically, entities with low-similarity images usually generate unsatisfactory performance, highlighting the limitation of overly relying on visual features.We believe the model can be biased toward the visual modality, leading to a shortcut image-matching task.To address this, we propose a counterfactual debiasing framework for MMEA, termed CDMEA, which investigates visual modality bias from a causal perspective.Our approach aims to leverage both visual and graph modalities to enhance MMEA while suppressing the direct causal effect of the visual modality on model predictions.By estimating the Total Effect (TE) of both modalities and excluding the Natural Direct Effect (NDE) of the visual modality, we ensure that the model predicts based on the Total Indirect Effect (TIE), * Corresponding author.
Taoyu Su, Jiawei Sheng, Duohe Ma, Xiaodong Li 0012, Juwei Yue, Mengxiao Song, Yingkai Tang, Tingwen Liu
SIGIR3
2025 Secure personal data sharing for simultaneous, parallel or sequential processing service: Autonomously and controllably
Qiuyun Lyu, Yilong Zhou, Yizhi Ren, Lingfei Zhou, Zekai Wu, Chengyao Zhao, Duohe Ma
Future Gener. Comput. Syst.8
2025 AATM: An Anonymous Authentication Protocol for Time Span of Membership With Self-Blindness and Accountability
abstract
Internet of Things (IoT) devices using subscription services (e.g. connected vehicles accessing entertainment programs) often purchase membership credentials from service providers with limited usage counts or validity periods, we call them pay-per-use or time span of membership services. However, users’ access records, usage preferences, and habits are collected by network adversarys or membership providers for creating users’ profiles, targeted advertising, and even for being sold maliciously. To deal with these problems, lots of anonymous authentication protocols are proposed to provide users with pseudonyms to conceal their real identities. Although these protocols effectively prevent network adversarys from compromising users’ privacy, membership service providers can still gather users’ behavioral privacy via their membership credentials. Therefore, several scholars proposed k-times anonymous authentication protocols and self-blind credentials to enhance users’ privacy protection, but the k-times anonymous authentication protocols are only for pay-per-use membership services and the schemes of self-blind credentials are lack of regulating malicious users. To address these issues, this article proposes an anonymous authentication protocol for time span of membership (AATM) with self-blindness and accountability. Specifically, we utilize Structure Preserving Signatures on Equivalence Classes (SPS-EQ) and Signatures with Flexible Public Key (SFPK) to build accountable, self-blinding credentials that ensure that every time a user visits a member, he or she can create a brand new identity on their own, which not only prevents users from being linked by service providers, but also supports conditional fair regulation. Security and performance analyses show that AATM is better than the state-of-the-art schemes in terms of security and privacy-preserving capabilities, and its computation cost also meets the practical application requirements.
Qiuyun Lyu, Xiwen Liang, Shaopeng Cheng, Yizhi Ren, Chengli Xu, Weizhi Meng 0001, Duohe Ma
IEEE Internet Things J.8
2025 Got My "Invisibility" Patch: Towards Physical Evasion Attacks on Black-Box Face Detection Systems
abstract
Modern face detection (FD) systems have demonstrated remarkable performance in identifying human faces, primarily via Deep Neural Networks (DNNs). However, these DNN-driven models exhibit inherent susceptibility to adversarial attacks, posing significant risks for intentional face obfuscation from detectors. Such obfuscation can serve both malicious purposes (e.g., evading surveillance systems) and benign objectives (e.g., protecting personal privacy). Previous studies have developed techniques to compromise the effectiveness of various FD models, yet these adversarial attacks are largely confined to the digital domain—e.g., by applying adversarial perturbations to digital input images—or demand prior knowledge of the target FD systems. In this paper, we introduces a novel framework for evading black-box face detection (FD) systems in real-world scenarios. The proposed method relies on theExpectation over Attention(EoA) algorithm, which generates thePublic Attention Heat Map(PAHM) by fusing attention mechanisms across an ensemble of publicly available FD models. Our evaluation results demonstrate that EoA outperforms state-of-the-art (SOTA) methods in white-box settings and demonstrates strong cross-model transferability in black-box scenarios, effectively evading FD systems across smartphones, laptops, and surveillance cameras.
Duohe Ma, Junye Jiang, Xiaoyan Sun 0003, Kai Chen 0012, Jun Dai 0001
IEEE Trans. Dependable Secur. Comput.1
2025 HGExplainer: Heterogeneous Graph Explainer for IoT Device Identification
abstract
IoT device identification is vital for network asset and security management. However, existing methods use statistical features that can not identify IoT devices accurately in complex network environments.GraphIoTproposes using non-statistical features and building a heterogeneous graph neural network to identify IoT devices accurately. However, heterogeneous graph neural networks lack interpretability, which reduces trust in the model. Besides, it is difficult to deploy on resource-constrained devices, limiting the broad application of IoT device identification. To make IoT device identification interpretable, easy to deploy, and with high accuracy, we get the interpretation results ofGraphIoTthrough interpretability and further build the rule set based on the interpretation results. Considering there is no suitable interpreter forGraphIoTwith many nodes and edges, we proposeHGExplainer, which reduces the time complexity by splitting the interpretation target into important relation solving and edge solving and uses a novel solution method, ExpandTree. Then, we also designed a rule extractor, which can build rule sets based on the interpretation results. Experimental results on Yourthings and UNSW datasets show thatHGExplainercan build high fidelity, concise sample-level explanations in less than 3 seconds, and the established rule set can precisely identify IoT devices.
Linna Fan, Xuan Shen, Guanglei Song, Chaocan Xiang, Duohe Ma, Yongfeng Huang 0001
IEEE Trans. Mob. Comput.8
2024 Poster: Towards Real-Time Intrusion Detection with Explainable AI-Based Detector
abstract
Identifying malicious traffic is crucial for safeguarding internal networks from privacy breaches.Intrusion Detection Systems (IDS) traditionally rely on inefficient and outdated rule-sets, necessitating a shift towards AI-driven, learning-based algorithms for enhanced detection capabilities.Despite their promise, AI-integrated IDS face deployment challenges due to complex, opaque decision-making processes that can lead to latency and an increased risk of false positives.This paper presents the Explainable AI-based Intrusion Detection System (XAI-IDS), addressing the limitations of both rule-based and AI-driven IDS by integrating interpretable deep learning models.XAI-IDS employs tree regularization to transform complex models into efficient, transparent decision trees, facilitating real-time detection with improved accuracy and explainability.Experiments on two benchmark datasets demonstrate XAI-IDS's superior performance, offering a scalable solution to the challenge of identifying malicious traffic with reduced risk of false positives.
Wenhao Li 0005, Duohe Ma, Zhaoxuan Li, Huaifeng Bao, Shuai Wang 0079, Huamin Jin, Xiaoyu Zhang 0002
CCS2
2024 Poster: Enhancing Network Traffic Analysis with Pre-trained Side-channel Feature Imputation
abstract
The recent advances in learning-based methodologies has underscored their efficacy in deducing patterns from the side-channel features of encrypted network traffic. Nonetheless, the distribution of these features has been identified as susceptible, particularly in the expansive and intricate network topologies characteristic of the modern Internet. The unpredictability of traffic bursts can result in packet loss during retransmission, thereby generating fragmented feature patterns. Unfortunately, current approaches struggle to adapt to such fragmented features, often leading to a substantial decline in performance. To surmount this challenge, this paper introduces a pre-training-based augmentation framework, denoted as Nüwa, which imputes the side-channel features of encrypted network traffic. The crux of Nüwa lies in its ability to reconstruct the side-channel features, with a particular focus on the temporal attributes of the missing packets within a traffic session. Nüwa is comprised of a word-level Sequence2Embedding module, a Traffic Noise-based Self-supervised Pre-trained Masking Strategy, and a Traffic Side-Channel Feature Imputation Module. Experiments across four diverse real-world scenarios substantiate Nüwa's capacity to restore the performance of prevalent temporal models while maintaining the integrity of the imputed features.
Faqi Zhao, Duohe Ma, Wenhao Li 0005, Feng Liu 0001, Wen Wang 0008
CCS2
2024 What You See Is The Tip Of The Iceberg: A Novel Technique For Data Leakage Prevention
abstract
Data leakage is one of the most severe security threats that can compromise sensitive data through breaches or unauthorized access. Existing techniques usually adopt encryption or access control protection methods, but inevitably affects the data usability and introduce significant overhead. In this paper, we propose a novel technique for data leakage prevention in collaborative systems by dynamically broadening the deceptive attack surface. Our proposed technique offers an adaptive deception strategy that leverages historical user behaviors and current operations to generate deceptive data, and we developed an amplifying-based calculation method to enhance the accuracy of user trust degree evaluation. Furthermore, we introduce three deceptive indicators to evaluate our technique. Experimental results show that our technique can effectively prevent data leakage while preserving data usability and imposing minimal overhead to the system.
Kai Chen 0012, Jiankai Wang, Duohe Ma, Liming Wang 0001, Zhen Xu 0009
CSCWD4
2024 Using Microposture Features and Optical Flows for Deepfake Detection
Kai Chen 0012, Duohe Ma, Liming Wang 0001, Junye Jiang
IFIP Int. Conf. Digital Forensics2
2024 AdvOcl: Naturalistic Clothing Pattern Adversarial to Person Detectors in Occlusion
abstract
Automated surveillance cameras equipped with intelligent person detection systems are believed to have reached the maturity required for deployment in Intelligent Transport Systems, Intelligent Plants, and so on. However, recent studies have revealed that Deep Learning Neural Networks (DNN), on which mainstream person detection models are built, are vulnerable to adversarial attacks. Several methods have been proposed to generate adversarial patches that can evade person detectors. Nevertheless, these methods have limitations, as these adversarial patches are either restricted to being presented without any occlusion and placed in the center of the person, or they are too large in size and standing-out in pattern to be easily ignored by human eyes. Therefore, the adversarial patches in previous works did not consider both robustness and stealthiness when human posture changes and the patches are not in the center of person and partially occluded. In this paper, we propose AdvOcl that leverages the learned image manifold of the diffusion model to generate patterns that resemble one kind of the typical textures of daily clothes, such as common floral styles. Moreover, AdvOcl improved the adaptability and adversarial effectiveness by supporting changes in posture and partially occlusion during walking or running with warping and alignment module modeling deformation of clothes. Through extensive quantitative experiments, the results demonstrate the effectiveness of the proposed approach in generating more adversarially effective and naturalistic patterns in occluded scenarios compared to other state-of-the-art patch generation methods.
Zhitong Lu, Duohe Ma, Linna Fan, Zhen Xu 0009, Kai Chen 0012
IH&MMSec2
2023 Deepfake Detection Using Multiple Facial Features
Duohe Ma, Liming Wang 0001, Zhitong Lu, Junye Jiang
IFIP Int. Conf. Digital Forensics2
2023 Every Time Can Be Different: A Data Dynamic Protection Method Based on Moving Target Defense
abstract
Traditional defense methods are hard to change the inherent vulnerabilities of static data storage, single data access, and deterministic data content, leading to frequent data leakage incidents. Moving target defense (MTD) techniques can increase data diversity and unpredictability by dynamically shifting the data attack surface. However, in the existing methods, the data lacks sufficient dynamics due to insufficient shifting space and shifting frequency of attack surface, and legitimate users are inevitably greatly affected. This study proposes a data MTD method that the data changes dynamically based on real-time multi-source user access information. Through the multidimensional user stratification mechanism, we establish a novel dynamic data model that uses the combination of random deception strategies to convert metadata properties and content of data based on the user risk levels, while data remains unchanged for legitimate users. Multiple sets of experiments demonstrate the effectiveness and low consumption of our data dynamic defense approach.
Duohe Ma, Xiaoyan Sun 0003, Kai Chen 0012, Liming Wang 0001, Junye Jiang
ISCC2
2021 Disappeared Face: A Physical Adversarial Attack Method on Black-Box Face Detection Models
Huiyun Jing, Liming Wang 0001, Kai Chen 0012, Duohe Ma
ICICS (1)6
2020 WGT: Thwarting Web Attacks Through Web Gene Tree-based Moving Target Defense
abstract
Moving target defense (MTD) suggests a game-changing way of enhancing web security by increasing uncertainty and complexity for attackers. A good number of web MTD techniques have been investigated to counter various types of web attacks. However, in most MTD techniques, only fixed attributes of the attack surface are shifted, leaving the rest exploitable by the attackers. Currently, there are few mechanisms to support the whole attack surface movement and solve the partial coverage problem, where only a fraction of the possible attributes shift in the whole attack surface. To address this issue, this paper proposes a Web Gene Tree (WGT) based MTD mechanism. The key point is to extract all potential exploitable key attributes related to vulnerabilities as web genes, and mutate them using various MTD techniques to withstand various attacks. Experimental results indicate that, by randomly shifting web genes and diversely inserting deceptive ones, the proposed WGT mechanism outperforms other existing schemes and can significantly improve the security of web applications.
Duohe Ma, Xiaoyan Sun 0003, Kai Chen 0012, Feng Liu 0001
ICWS2
2020 What You See Is Not What You Get: Towards Deception-Based Data Moving Target Defense
abstract
The homogeneity and uniformity of static data storage and access make data leakage one of the most severe security threats. Dynamic data techniques such as data randomization and diversification, are effective approaches to mitigate data theft and illegal data modification. By increasing data diversity and dynamics, the data attack surface shifting space can be expanded to confuse attackers and influence their further actions. However, there are only a few dynamic data techniques developed because of the difficulty in encoding multiple data formats and the loss of compatibility in data formats. In this paper, we propose a new dynamic data approach that integrates the data deception techniques based on Moving Target Defense (MTD). By changing the data size, data authenticity, and users' data access privilege, the approach significantly expands the data attack surface shifting space. Moreover, the approach provides dynamic data access based upon both users' attributes and users' operations. Through dynamic analysis and experiments, the paper shows that the proposed dynamic data technique can expand the attack surface shifting space at a lower cost, protect the sensitive data, and impose no significant burden on the system.
Duohe Ma, Xiaoyan Sun 0003, Kai Chen 0012, Feng Liu 0001
IPCCC2
2018 Incomplete information Markov game theoretic approach to strategy generation for moving target defense
Liming Wang 0001, Duohe Ma
Comput. Commun.5
2017 Quantitative Security Assessment Method based on Entropy for Moving Target Defense
abstract
Moving Target Defense(MTD) provides a promising solution to reduce the chance of weakness exposure by constantly changing the target's attack surface. Though lots of MTD technologies have been researched to defend network attacks, there is little systematic study on security assessment of MTD. This paper proposes a novel method to quantify the security of MTD system which based on three factors: Vulnerability Entropy, Attack Entropy and Attenuation Entropy. This assessment model provides a theoretical and practical guidance for building MTD system and improving MTD technology.
Duohe Ma, Liming Wang 0001, Zhen Xu 0009, Meng Li 0015
AsiaCCS1
2016 A Self-adaptive Hopping Approach of Moving Target Defense to thwart Scanning Attacks
Duohe Ma, Liming Wang 0001, Zhen Xu 0009, Meng Li 0015
ICICS1
2016 Thwart eavesdropping attacks on network communication based on moving target defense
abstract
This paper addresses mainly the problem of private data protection in network communication against eavesdropping attacks. As this kind of attacks is stealthy and untraceable, it is barely detectable for those feature detection or static configuration based passive defense approaches. We propose a Moving Target Defense(MTD) method by utilizing the protocol customization ability of Protocol-Oblivious Forwarding (POF). The novel full protocol stack randomization MTD can greatly increase the difficulty of implementing network eavesdropping attack and protect the privacy of the network communication process.
Duohe Ma, Liming Wang 0001, Zhen Xu 0009, Meng Li 0015
IPCCC1
2014 Defending Blind DDoS Attack on SDN Based on Moving Target Defense
Duohe Ma, Zhen Xu 0009, Dongdai Lin
SecureComm (1)1