EDBT 2026 Demo / reviewers in the wild / expert
Can He
dblp:145/4309
· DBLP profile ↗
11ranked-venue papers
1as first author
8since 2021 · last 2023
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 5 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Evaluation of Three Land Surface Temperature Products From Landsat Series Using in Situ MeasurementsabstractThree operational long-term land surface temperature (LST) products from Landsat series are available to the community until now, i.e., U.S. Geological Survey (USGS) LST, Instituto Português do Mar e da Atmosfera (IPMA) LST, and China University of Geosciences (CUG) LST. A comprehensive assessment of these LST products is essential for their subsequent applications (APPs) in energy, water, and carbon cycle modeling. In this study, an evaluation of these three Landsat LST products was performed using in situ LST measurements from five networks [surface radiation budget (SURFRAD), atmospheric radiation measurement (ARM), Heihe watershed allied telemetry experimental research (HiWATER), baseline surface radiation network (BSRN), and National Data Buoy Center (NDBC)] for the period of 2009–2019. Results reveal that the overall accuracies of CUG LST with bias [root-mean-square error (RMSE)] of 0.54 K (2.19 K) and IPMA LST with bias (RMSE) of 0.59 K (2.34 K) are marginally superior to USGS LST with bias (RMSE) of 0.96 K (2.51 K). The RMSE of USGS LST is about 0.3 K less than IPMA/CUG LST at water surface sites and is about 0.4 K higher than IPMA/CUG LST at cropland and shrubland sites. As for tundra, grassland, and forest sites, the RMSEs of three Landsat LST products are similar, and the RMSE difference among three Landsat LST products is < 0.18 K. Considering the close emissivity estimates over water surface in these three LST data, USGS LST has a better performance in atmospheric correction over water surface compared with IPMA/CUG LST. For land surface sites, the RMSE of LST increases initially and then decreases with land surface emissivity (LSE) for three Landsat LST products. This indicates that the emissivity correction has a large uncertainty for moderately vegetated surface with emissivity ranging from 0.970 to 0.980. Underestimated emissivity for USGS LST at vegetated sites leads to overestimation of LST, which could have led to the higher bias and RMSE compared with IPMA/CUG LST. For the LST retrievals for the three different sensors [i.e., Thematic Mapper (TM), Enhanced Thematic Mapper Plus (ETM+), and thermal infrared sensor (TIRS)] onboard the Landsat satellite series, the accuracies are consistent and comparable, which is beneficial for providing long-term and coherent LST. Mengmeng Wang 0001, Can He, Zhengjia Zhang, Tian Hu, Sibo Duan, Kaniska Mallick, Hua Li 0005, Xiuguo Liu |
IEEE Trans. Geosci. Remote. Sens. | 2 |
| 2022 | PTB: Robust physical backdoor attacks against deep neural networks in real world
Mingfu Xue, Can He, Yinghao Wu, Shichang Sun, Yushu Zhang 0001, Jian Wang 0038, Weiqiang Liu 0001 |
Comput. Secur. | 2 |
| 2022 | One-to-N & N-to-One: Two Advanced Backdoor Attacks Against Deep Learning ModelsabstractIn recent years, deep learning models have been widely deployed in various application scenarios. The training processes of deep neural network (DNN) models are time-consuming, and require massive training data and large hardware overhead. These issues have led to the outsourced training procedure, pre-trained models supplied from third parties, or massive training data from untrusted users. However, a few recent researches indicate that, by injecting some well-designed backdoor instances into the training set, the attackers can create a concealed backdoor in the DNN model. In this way, the attacked model still works normally on the benign inputs, but when a backdoor instance is submitted, some specific abnormal behaviors will be triggered. Existing studies all focus on attacking a single target that triggered by a single backdoor (referred to as One-to-One attack), while the backdoor attacks against multiple target classes, and backdoor attacks triggered by multiple backdoors have not been studied yet. In this article, for the first time, we propose two advanced backdoor attacks, the multi-target backdoor attacks and multi-trigger backdoor attacks: 1) One-to-N attack, where the attacker can trigger multiple backdoor targets by controlling the different intensities of the same backdoor; 2) N-to-One attack, where such attack is triggered only when all the$N$backdoors are satisfied. Compared with existing One-to-One attacks, the proposed two backdoor attacks are more flexible, more powerful and more difficult to be detected. Besides, the proposed backdoor attacks can be applied under the weak attack model, where the attacker has no knowledge about the parameters and architectures of the DNN models. Experimental results show that these two attacks can achieve better or similar performances when injecting a much smaller proportion or same proportion of backdoor instances than those existing One-to-One backdoor attacks. The two attack methods can achieve high attack success rates (up to 100 percent in MNIST dataset and 92.22 percent in CIFAR-10 dataset), while the test accuracy of the DNN model has hardly dropped (as low as 0 percent in LeNet-5 model and 0.76 percent in VGG-16 model), thus will not raise administrator’s suspicions. Further, the two attacks are also evaluated on a large and realistic dataset (Youtube Aligned Face dataset), where the maximum attack success rate reaches 90 percent (One-to-N) and 94 percent (N-to-One), and the accuracy degradation of target face recognition model (VGGFace model) is only 0.05 percent. The proposed One-to-N and N-to-One attacks are demonstrated to be effective and stealthy against two state-of-the-art defense methods. Mingfu Xue, Can He, Jian Wang 0038, Weiqiang Liu 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2021 | Customized Instruction on RISC-V for Winograd-Based Convolution AccelerationabstractConvolution operation accounts for the major work-load in convolutional neural networks (CNN). However, standard instruction set for RISC-V processor cannot efficiently perform the matrix convolution between kernel and input matrices. In this paper, we construct a custom instruction under the RISC-V ISA that can perform the F(2×2,3×3) convolution within one single execution. Particularly, optimized by the Winograd algorithm, the operation only needs 16 multiplications instead of 36 multiplications as needed by standard ISA. Benefit from this cycles, as compared to 140 cycles using standard instructions. Thenew instruction, F(2×2,3×3) can be calculated within 19 clock power consumed during convolution operation is also reduced significantly. Jianghan Zhu, Qi Wang 0051, Can He, Terry Tao Ye |
ASAP | 4 |
| 2021 | Robust Backdoor Attacks against Deep Neural Networks in Real Physical WorldabstractDeep neural networks (DNN) have been widely deployed in various applications. However, many researches indicated that DNN is vulnerable to backdoor attacks. The attacker can create a hidden backdoor in target DNN model, and trigger the malicious behaviors by submitting specific backdoor instance. However, almost all the existing backdoor works focused on the digital domain, while few studies investigate the backdoor attacks in real physical world. Restricted to a variety of physical constraints, the performance of backdoor attacks in the real physical world will be severely degraded. In this paper, we propose a robust physical backdoor attack method, PTB (physical transformations for backdoors), to implement the backdoor attacks against deep learning models in the real physical world. Specifically, in the training phase, we perform a series of physical transformations on these injected backdoor instances at each round of model training, so as to simulate various transformations that a backdoor may experience in real world, thus improves its physical robustness. Experimental results on the state-of-the-art face recognition model show that, compared with the backdoor methods that without PTB, the proposed attack method can significantly improve the performance of backdoor attacks in real physical world. Under various complex physical conditions, by injecting only a very small ratio (0.5 %) of backdoor instances, the attack success rate of physical backdoor attacks with the PTB method on VGGFace is 82%, while the attack success rate of backdoor attacks without the proposed PTB method is lower than 11%. Meanwhile, the normal performance of the target DNN model has not been affected. Mingfu Xue, Can He, Shichang Sun, Jian Wang 0038, Weiqiang Liu 0001 |
TrustCom | 2 |
| 2021 | SocialGuard: An adversarial example based privacy-preserving technique for social images
Mingfu Xue, Shichang Sun, Zhiyu Wu, Can He, Jian Wang 0038, Weiqiang Liu 0001 |
J. Inf. Secur. Appl. | 4 |
| 2021 | NaturalAE: Natural and robust physical adversarial examples for object detectors
Mingfu Xue, Chengxiang Yuan, Can He, Jian Wang 0038, Weiqiang Liu 0001 |
J. Inf. Secur. Appl. | 3 |
| 2021 | Backdoors hidden in facial features: a novel invisible backdoor attack against face recognition systems
Mingfu Xue, Can He, Jian Wang 0038, Weiqiang Liu 0001 |
Peer-to-Peer Netw. Appl. | 2 |
| 2020 | Active DNN IP Protection: A Novel User Fingerprint Management and DNN Authorization Control TechniqueabstractThe training process of deep learning model is costly. As such, deep learning model can be treated as an intellectual property (IP) of the model creator. However, a pirate can illegally copy, redistribute or abuse the model without permission. In recent years, a few Deep Neural Networks (DNN) IP protection works have been proposed. However, most of existing works passively verify the copyright of the model after the piracy occurs, and lack of user identity management, thus cannot provide commercial copyright management functions. In this paper, a novel user fingerprint management and DNN authorization control technique based on backdoor is proposed to provide active DNN IP protection. The proposed method can not only verify the ownership of the model, but can also authenticate and manage the user's unique identity, so as to provide a commercially applicable DNN IP management mechanism. Experimental results on CIFAR-10, CIFAR-100 and Fashion-MNIST datasets show that the proposed method can achieve high detection rate for user authentication (up to 100% in the three datasets). Illegal users with forged fingerprints cannot pass authentication as the detection rates are all 0 % in the three datasets. Model owner can verify his ownership since he can trigger the backdoor with a high confidence. In addition, the accuracy drops are only 0.52%, 1.61 % and -0.65% on CIFAR-10, CIFAR-100 and Fashion-MNIST, respectively, which indicate that the proposed method will not affect the performance of the DNN models. The proposed method is also robust to model fine-tuning and pruning attacks. The detection rates for owner verification on CIFAR-10, CIFAR-100 and Fashion-MNIST are all 100% after model pruning attack, and are 90 %, 83 % and 93 % respectively after model fine-tuning attack, on the premise that the attacker wants to preserve the accuracy of the model. Mingfu Xue, Zhiyu Wu, Can He, Jian Wang 0038, Weiqiang Liu 0001 |
TrustCom | 3 |
| 2020 | LOPA: A linear offset based poisoning attack method against adaptive fingerprint authentication system
Mingfu Xue, Can He, Jian Wang 0038, Weiqiang Liu 0001 |
Comput. Secur. | 2 |
| 2015 | A New Image Decomposition and Reconstruction Approach - Adaptive Fourier Decomposition
Can He, Liming Zhang 0002, Xiangjian He, Wenjing Jia |
MMM (2) | 1 |