EDBT 2026 Demo / reviewers in the wild / expert
Aobo Chen 0002
dblp:158/7501-2
· DBLP profile ↗
6ranked-venue papers
2as first author
6since 2021 · last 2026
0009-0004-0502-1895ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Security and privacy of machine learning · 94% Privacy and data protection · 6% | |
| Computer graphics and multimedia
1 paper |
Audio and music processing · 67% Multimedia analysis and retrieval · 33% | |
| Artificial intelligence
2 papers |
Trustworthy machine learning · 100% |
Topics — the 13 heaviest of 14, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Audio and music processing › audio security
audio deepfake detection |
1.0 | 1 | 2026 | Rethinking Fake Speech Detection: A Generalized Framework Leveraging Spectrogram Magnitude · NDSS 2026 |
Multimedia analysis and retrieval
deepfake detection |
1.0 | 1 | 2026 | Rethinking Fake Speech Detection: A Generalized Framework Leveraging Spectrogram Magnitude · NDSS 2026 |
Audio and music processing
speech processing |
1.0 | 1 | 2026 | Rethinking Fake Speech Detection: A Generalized Framework Leveraging Spectrogram Magnitude · NDSS 2026 |
Security and privacy of machine learning
membership inference |
0.9 | 1 | 2025 | Membership Inference Attacks With False Discovery Rate Control · ICCV 2025 |
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
0.8 | 1 | 2024 | Rethinking Adversarial Robustness in the Context of the Right to be Forgotten · ICML 2024 |
Machine learning › Trustworthy machine learning › uncertainty estimation
conformal prediction |
0.8 | 1 | 2024 | Data Poisoning Attacks against Conformal Prediction · ICML 2024 |
Machine learning › Trustworthy machine learning
uncertainty estimation |
0.8 | 1 | 2024 | Data Poisoning Attacks against Conformal Prediction · ICML 2024 |
Security and privacy of machine learning
machine unlearning |
0.8 | 1 | 2024 | Rethinking Adversarial Robustness in the Context of the Right to be Forgotten · ICML 2024 |
Security and privacy of machine learning
model stealing |
0.8 | 1 | 2024 | Rethinking Adversarial Robustness in the Context of the Right to be Forgotten · ICML 2024 |
Security and privacy of machine learning
poisoning attack |
0.8 | 1 | 2024 | Data Poisoning Attacks against Conformal Prediction · ICML 2024 |
Security and privacy of machine learning › membership inference
black-box membership inference |
0.3 | 1 | 2025 | Membership Inference Attacks With False Discovery Rate Control · ICCV 2025 |
Machine learning › Trustworthy machine learning
robustness |
0.2 | 1 | 2024 | Data Poisoning Attacks against Conformal Prediction · ICML 2024 |
Privacy and data protection › privacy regulation
right to be forgotten |
0.2 | 1 | 2024 | Rethinking Adversarial Robustness in the Context of the Right to be Forgotten · ICML 2024 |
Methods — techniques the papers use, named apart from their topics
optimization framework · 1.5black-box poisoning · 1.5adversarial attack · 1.5spectrogram analysis · 1.0multiple hypothesis testing · 0.9false discovery rate control · 0.9
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Rethinking Fake Speech Detection: A Generalized Framework Leveraging Spectrogram Magnitude
Zihao Liu 0001, Aobo Chen 0002, Yan Zhang 0133, Chenglin Miao |
NDSS | 2 |
| 2026 | Towards Unveiling Vulnerabilities of Large Reasoning Models in Machine Unlearning
Aobo Chen 0002, Chenglin Miao, Mengdi Huai |
PAKDD (4) | 1 |
| 2025 | Membership Inference Attacks With False Discovery Rate ControlabstractRecent studies have shown that deep learning models are vulnerable to membership inference attacks (MIAs), which aim to infer whether a data record was used to train a target model or not. To analyze and study these vulnerabilities, various MIA methods have been proposed. Despite the significance and popularity of MIAs, existing works on MIAs are limited in providing guarantees on the false discovery rate (FDR), which refers to the expected proportion of false discoveries among the identified positive discoveries. However, it is very challenging to ensure the false discovery rate guarantees, because the underlying distribution is usually unknown, and the estimated non-member probabilities often exhibit interdependence. To tackle the above challenges, in this paper, we design a novel membership inference attack method, which can provide the guarantees on the false discovery rate. Additionally, we show that our method can also provide the marginal probability guarantee on labeling true non-member data as member data. Notably, our method can work as a wrapper that can be seamlessly integrated with existing MIA methods in a post-hoc manner, while also providing the FDR control. We perform the theoretical analysis for our method. Extensive experiments in various settings (e.g., the black-box setting and the lifelong learning setting) are also conducted to verify the desirable performance of our method. Aobo Chen 0002, Mengdi Huai |
ICCV | 3 |
| 2024 | Data Poisoning Attacks against Conformal PredictionabstractThe efficient and theoretically sound uncertainty quantification is crucial for building trust in deep learning models. This has spurred a growing interest in conformal prediction (CP), a powerful technique that provides a model-agnostic and distribution-free method for obtaining conformal prediction sets with theoretical guarantees. However, the vulnerabilities of such CP methods with regard to dedicated data poisoning attacks have not been studied previously. To bridge this gap, for the first time, we in this paper propose a new class of black-box data poisoning attacks against CP, where the adversary aims to cause the desired manipulations of some specific examples’ prediction uncertainty results (instead of misclassifications). Additionally, we design novel optimization frameworks for our proposed attacks. Further, we conduct extensive experiments to validate the effectiveness of our attacks on various settings (e.g., the full and split CP settings). Notably, our extensive experiments show that our attacks are more effective in manipulating uncertainty results than traditional poisoning attacks that aim at inducing misclassifications, and existing defenses against conventional attacks are ineffective against our proposed attacks. Yangyi Li, Aobo Chen 0002, Divya Lidder, Mengdi Huai |
ICML | 2 |
| 2024 | Rethinking Adversarial Robustness in the Context of the Right to be ForgottenabstractThe past few years have seen an intense research interest in the practical needs of the "right to be forgotten", which has motivated researchers to develop machine unlearning methods to unlearn a fraction of training data and its lineage. While existing machine unlearning methods prioritize the protection of individuals’ private data, they overlook investigating the unlearned models’ susceptibility to adversarial attacks and security breaches. In this work, we uncover a novel security vulnerability of machine unlearning based on the insight that adversarial vulnerabilities can be bolstered, especially for adversarially robust models. To exploit this observed vulnerability, we propose a novel attack called Adversarial Unlearning Attack (AdvUA), which aims to generate a small fraction of malicious unlearning requests during the unlearning process. AdvUA causes a significant reduction of adversarial robustness in the unlearned model compared to the original model, providing an entirely new capability for adversaries that is infeasible in conventional machine learning pipelines. Notably, we also show that AdvUA can effectively enhance model stealing attacks by extracting additional decision boundary information, further emphasizing the breadth and significance of our research. We also conduct both theoretical analysis and computational complexity of AdvUA. Extensive numerical studies are performed to demonstrate the effectiveness and efficiency of the proposed attack. Yangyi Li, Aobo Chen 0002, Mengdi Huai |
ICML | 4 |
| 2024 | Modeling and Understanding Uncertainty in Medical Image Classification
Aobo Chen 0002, Yangyi Li, Kathy Morse, Chenglin Miao, Mengdi Huai |
MICCAI (10) | 1 |