EDBT 2026 Demo / reviewers in the wild / expert
Yan Liu 0069
dblp:150/4295-69
· DBLP profile ↗
9ranked-venue papers
0as first author
8since 2021 · last 2026
0000-0002-6021-1358ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 since 2021Security and privacy · 3 · 3 since 2021Computer networks · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RAGFort: Dual-Path Defense Against Proprietary Knowledge Base Extraction in Retrieval-Augmented GenerationabstractRetrieval-Augmented Generation (RAG) systems deployed over proprietary knowledge bases face growing threats from reconstruction attacks that aggregate model responses to replicate knowledge bases. Such attacks exploit both intra-class and inter-class paths—progressively extracting fine-grained knowledge within topics and diffusing it across semantically related ones, thereby enabling comprehensive extraction of the original knowledge base. However, existing defenses target only one path, leaving the other unprotected. We conduct a systematic exploration to assess the impact of protecting each path independently and find that joint protection is essential for effective defense. Based on this, we propose RAGFort, a structure-aware dual-module defense combining contrastive reindexing for inter-class isolation and constrained cascade generation for intra-class protection. Experiments across security, performance, and robustness confirm that RAGFort significantly reduces reconstruction success while preserving answer quality, offering the first comprehensive defense against knowledge base extraction attacks. Qinfeng Li, Miao Pan, Ke Xiong 0007, Ge Su, Yan Liu 0069, Hao Peng 0002, Xuhong Zhang 0002 |
AAAI | 6 |
| 2026 | WeakTr: Exploring Plain Vision Transformer for Weakly-Supervised Semantic SegmentationabstractTransformer has been very successful in various computer vision tasks and understanding the working mechanism of transformer is important. As touchstones, weakly-supervised semantic segmentation (WSSS) and class activation map (CAM) are useful tasks for analyzing vision transformers (ViT). Based on the plain ViT pre-trained with ImageNet classification, we find that multi-layer, multi-head self-attention maps can provide rich and diverse information for weakly-supervised semantic segmentation and CAM generation, e.g., different attention heads of ViT focus on different image areas and object categories. Thus we propose a novel method to end-to-end estimate the importance of attention heads, where the self-attention maps are adaptively fused for high-quality CAM results that tend to have more complete objects. Besides, we propose a ViT-based gradient clipping decoder for online retraining with the CAM results efficiently and effectively. Furthermore, the gradient clipping decoder can make good use of the knowledge in large-scale pre-trained ViT and has a scalable ability. The proposed plain Transformer-based Weakly-supervised learning method (WeakTr) obtains the superior WSSS performance on standard benchmarks, i.e., 78.5% mIoU on the $val$ set of PASCAL VOC 2012 and 51.1% mIoU on the $val$ set of COCO 2014. Source code and checkpoints are available at https://github.com/hustvl/WeakTr. Lianghui Zhu, Yingyue Li, Jiemin Fang, Yan Liu 0069, Xin Hao, Wenyu Liu 0001, Xinggang Wang |
IEEE Trans. Image Process. | 4 |
| 2025 | PatchSegDet: Attack-Agnostic Detection of Physical Adversarial Patches in Face Recognition SystemsabstractAdversarial patch attacks are an emerging security threat for real-world Face Recognition Systems (FRS). Although many adversarial patch detection methods have been proposed for image classification, to the best of our knowledge, few have yet been specifically developed for FRS. Furthermore, the characteristics of FRS attack vectors impede current detection methods from being adapted to FRS. To bridge this gap, we propose PatchSegDet, an attack-agnostic two-stage adversarial patch detection method to safeguard FRS. It employs the Segment Anything Model (SAM) to segment out suspicious features and determines whether they constitute attacks against FRS. Leveraging SAM’s remarkable generalization and zero-shot capabilities in facial image segmentation, PatchSegDet is capable of detecting patches with varying textures and patterns placed in any facial region. Extensive experiments demonstrate the effectiveness and robustness of PatchSegDet against various attack methods in both digital and physical domains. Our findings provide insights for practitioners to better defend physical adversarial patch attacks in real-world FRS. Qinfeng Li, Xuhong Zhang 0002, Xiaochu Chen, Haiqin Weng, Yan Liu 0069 |
ICME | 8 |
| 2025 | RACONTEUR: A Knowledgeable, Insightful, and Portable LLM-Powered Shell Command Explainer
Jiangyi Deng, Xinfeng Li, Yanjiao Chen, Yijie Bai, Haiqin Weng, Yan Liu 0069, Tao Wei 0002, Wenyuan Xu 0001 |
NDSS | 6 |
| 2025 | On the Interoperability of Encrypted DatabasesabstractEncrypted database is an emerging and promising technology. It is able to run SQL operations on encrypted data. However, most existing encrypted databases haveno data interoperability, i.e., the output of an operator (e.g., addition) cannot be taken as input of another (e.g., comparison). As a result, these encrypted databases can only support simple queries like addition, multiplication and comparison, but unable to support a composition of these simple queries (e.g.,SELECT user_id FROM salary WHERE$V_{1} + V_{2} > 5000$V1+V2>5000). In SIGMOD ’14, Wong et al. propose SDB, which to the best of our knowledge is the only encrypted database that achieves data interoperability. Unfortunately, it has recently been broken (VLDB ’21). In this paper, we propose a novel encrypted database namedSDB+. It achieves data interoperability based on a suit of sophisticated designs. We formally prove thatSDB+achieves indistinguishability under chosen query attacks (IND-CQA). We provide a full-fledged implementation and run it on three benchmarks. Our experimental results show thatSDB+achieves comparable efficiency with SDB, even though the latter is insecure. Xinle Cao, Jian Liu 0012, Yan Liu 0069, Tao Wei 0002, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Constructing SDN Covert Timing Channels Between Hosts With Unprivileged AttackersabstractSoftware-defined networking (SDN) has been widely deployed due to its centralization and programmable features. However, these new features bring new threats at the same time. Previous studies have shown that SDN covert channels can be built with a privileged adversary that controls SDN key components, such as controller applications or SDN switches. In this paper, we propose new SDN covert timing channels between hosts without controlling applications, controllers, or having access to switches. Experiments in a real SDN testbed demonstrate the feasibility and effectiveness of our covert channels. To defend against the covert timing channels, we design a defense system named CovertGuard, which utilizes the timing characteristics of the covert channels’ delays to detect and eliminate covert channels effectively. Yixiong Ji, Jiahao Cao 0001, Qi Li 0002, Yan Liu 0069, Tao Wei 0002, Ke Xu 0002 |
IEEE Trans. Netw. | 4 |
| 2024 | Alchemy: Data-Free Adversarial TrainingabstractMachine learning models have become integral to various aspects of daily life, prompting increased vulnerability to adversarial attacks.Adversarial training is one of the most promising and practical methods to enhance model robustness.Existing adversarial training methods, however, assume access to the original training data.But nowadays, more and more users directly download models from the open-source model platforms or tech companies, but the original training datasets are usually unreleased because of commercial interests or privacy.In such scenarios, the user cannot utilize the former adversarial training methods to improve model robustness because of the lack of original training datasets.Thus, we present the first exploration of a data-free adversarial training framework, Alchemy, which seeks to enhance model robustness without requiring access to the original training data.By addressing the notable challenges of reconstructing high-quality training data with robust features and improving the adversarial robustness to the inaccessible original dataset, our approach achieves the goals of both high accuracy maintenance and robustness improvement.Comprehensive experiments on four datasets compared with five baselines, demonstrate Alchemy 's high effectiveness.With no access to any training dataset, the average robustness improvement with Alchemy is effective in most attack scenarios.Additional evaluations underscore the framework's stability under different settings and discuss future research directions. Yijie Bai, Zhongming Ma, Yanjiao Chen, Jiangyi Deng, Shengyuan Pang, Yan Liu 0069, Wenyuan Xu 0001 |
CCS | 6 |
| 2024 | WeakSAM: Segment Anything Meets Weakly-supervised Instance-level RecognitionabstractWeakly-supervised visual recognition using inexact supervision is a critical yet challenging learning problem. It significantly reduces human labeling costs and traditionally relies on multi-instance learning and pseudo-labeling. This paper introduces WeakSAM and solves the weakly-supervised object detection (WSOD) and segmentation by utilizing the pre-learned world knowledge contained in a vision foundation model, i.e., the Segment Anything Model (SAM). WeakSAM addresses two critical limitations in traditional WSOD retraining, i.e., pseudo ground truth (PGT) incompleteness and noisy PGT instances, through adaptive PGT generation and Region of Interest (RoI) drop regularization. It also addresses the SAM's shortcomings of requiring human prompts and category unawareness in object detection and segmentation. Our results indicate that WeakSAM significantly surpasses previous state-of-the-art methods in WSOD and WSIS benchmarks with large margins, i.e. average improvements of 7.4% and 8.5%, respectively. Lianghui Zhu, Junwei Zhou 0003, Yan Liu 0069, Xin Hao, Wenyu Liu 0001, Xinggang Wang |
ACM Multimedia | 3 |
| 2020 | ZeroWall: Detecting Zero-Day Web Attacks through Encoder-Decoder Recurrent Neural NetworksabstractThe following topics are dealt with: learning (artificial intelligence); optimisation; telecommunication traffic; Internet; cloud computing; computational complexity; mobile computing; resource allocation; security of data; and telecommunication network routing. Ruming Tang, Zeyan Li 0001, Weibin Meng, Haixin Wang 0003, Qi Li 0002, Yongqian Sun, Dan Pei, Tao Wei 0002, Yanfei Xu, Yan Liu 0069 |
INFOCOM | 11 |