Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Aobo Chen 0002

dblp:158/7501-2 · DBLP profile ↗
← Back
6ranked-venue papers
2as first author
6since 2021 · last 2026
0009-0004-0502-1895ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Security and privacy of machine learning · 94% Privacy and data protection · 6%
Computer graphics and multimedia
1 paper
Audio and music processing · 67% Multimedia analysis and retrieval · 33%
Artificial intelligence
2 papers
Trustworthy machine learning · 100%

Topics — the 13 heaviest of 14, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Audio and music processing › audio security
audio deepfake detection
1.012026
Rethinking Fake Speech Detection: A Generalized Framework Leveraging Spectrogram Magnitude · NDSS 2026
Multimedia analysis and retrieval
deepfake detection
1.012026
Rethinking Fake Speech Detection: A Generalized Framework Leveraging Spectrogram Magnitude · NDSS 2026
Audio and music processing
speech processing
1.012026
Rethinking Fake Speech Detection: A Generalized Framework Leveraging Spectrogram Magnitude · NDSS 2026
Security and privacy of machine learning
membership inference
0.912025
Membership Inference Attacks With False Discovery Rate Control · ICCV 2025
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
0.812024
Rethinking Adversarial Robustness in the Context of the Right to be Forgotten · ICML 2024
Machine learning › Trustworthy machine learning › uncertainty estimation
conformal prediction
0.812024
Data Poisoning Attacks against Conformal Prediction · ICML 2024
Machine learning › Trustworthy machine learning
uncertainty estimation
0.812024
Data Poisoning Attacks against Conformal Prediction · ICML 2024
Security and privacy of machine learning
machine unlearning
0.812024
Rethinking Adversarial Robustness in the Context of the Right to be Forgotten · ICML 2024
Security and privacy of machine learning
model stealing
0.812024
Rethinking Adversarial Robustness in the Context of the Right to be Forgotten · ICML 2024
Security and privacy of machine learning
poisoning attack
0.812024
Data Poisoning Attacks against Conformal Prediction · ICML 2024
Security and privacy of machine learning › membership inference
black-box membership inference
0.312025
Membership Inference Attacks With False Discovery Rate Control · ICCV 2025
Machine learning › Trustworthy machine learning
robustness
0.212024
Data Poisoning Attacks against Conformal Prediction · ICML 2024
Privacy and data protection › privacy regulation
right to be forgotten
0.212024
Rethinking Adversarial Robustness in the Context of the Right to be Forgotten · ICML 2024

Methods — techniques the papers use, named apart from their topics

optimization framework · 1.5black-box poisoning · 1.5adversarial attack · 1.5spectrogram analysis · 1.0multiple hypothesis testing · 0.9false discovery rate control · 0.9
YearPublicationVenuePosition
2026 Rethinking Fake Speech Detection: A Generalized Framework Leveraging Spectrogram Magnitude
Zihao Liu 0001, Aobo Chen 0002, Yan Zhang 0133, Chenglin Miao
NDSS2
2026 Towards Unveiling Vulnerabilities of Large Reasoning Models in Machine Unlearning
Aobo Chen 0002, Chenglin Miao, Mengdi Huai
PAKDD (4)1
2025 Membership Inference Attacks With False Discovery Rate Control
abstract
Recent studies have shown that deep learning models are vulnerable to membership inference attacks (MIAs), which aim to infer whether a data record was used to train a target model or not. To analyze and study these vulnerabilities, various MIA methods have been proposed. Despite the significance and popularity of MIAs, existing works on MIAs are limited in providing guarantees on the false discovery rate (FDR), which refers to the expected proportion of false discoveries among the identified positive discoveries. However, it is very challenging to ensure the false discovery rate guarantees, because the underlying distribution is usually unknown, and the estimated non-member probabilities often exhibit interdependence. To tackle the above challenges, in this paper, we design a novel membership inference attack method, which can provide the guarantees on the false discovery rate. Additionally, we show that our method can also provide the marginal probability guarantee on labeling true non-member data as member data. Notably, our method can work as a wrapper that can be seamlessly integrated with existing MIA methods in a post-hoc manner, while also providing the FDR control. We perform the theoretical analysis for our method. Extensive experiments in various settings (e.g., the black-box setting and the lifelong learning setting) are also conducted to verify the desirable performance of our method.
Aobo Chen 0002, Mengdi Huai
ICCV3
2024 Data Poisoning Attacks against Conformal Prediction
abstract
The efficient and theoretically sound uncertainty quantification is crucial for building trust in deep learning models. This has spurred a growing interest in conformal prediction (CP), a powerful technique that provides a model-agnostic and distribution-free method for obtaining conformal prediction sets with theoretical guarantees. However, the vulnerabilities of such CP methods with regard to dedicated data poisoning attacks have not been studied previously. To bridge this gap, for the first time, we in this paper propose a new class of black-box data poisoning attacks against CP, where the adversary aims to cause the desired manipulations of some specific examples’ prediction uncertainty results (instead of misclassifications). Additionally, we design novel optimization frameworks for our proposed attacks. Further, we conduct extensive experiments to validate the effectiveness of our attacks on various settings (e.g., the full and split CP settings). Notably, our extensive experiments show that our attacks are more effective in manipulating uncertainty results than traditional poisoning attacks that aim at inducing misclassifications, and existing defenses against conventional attacks are ineffective against our proposed attacks.
Yangyi Li, Aobo Chen 0002, Divya Lidder, Mengdi Huai
ICML2
2024 Rethinking Adversarial Robustness in the Context of the Right to be Forgotten
abstract
The past few years have seen an intense research interest in the practical needs of the "right to be forgotten", which has motivated researchers to develop machine unlearning methods to unlearn a fraction of training data and its lineage. While existing machine unlearning methods prioritize the protection of individuals’ private data, they overlook investigating the unlearned models’ susceptibility to adversarial attacks and security breaches. In this work, we uncover a novel security vulnerability of machine unlearning based on the insight that adversarial vulnerabilities can be bolstered, especially for adversarially robust models. To exploit this observed vulnerability, we propose a novel attack called Adversarial Unlearning Attack (AdvUA), which aims to generate a small fraction of malicious unlearning requests during the unlearning process. AdvUA causes a significant reduction of adversarial robustness in the unlearned model compared to the original model, providing an entirely new capability for adversaries that is infeasible in conventional machine learning pipelines. Notably, we also show that AdvUA can effectively enhance model stealing attacks by extracting additional decision boundary information, further emphasizing the breadth and significance of our research. We also conduct both theoretical analysis and computational complexity of AdvUA. Extensive numerical studies are performed to demonstrate the effectiveness and efficiency of the proposed attack.
Yangyi Li, Aobo Chen 0002, Mengdi Huai
ICML4
2024 Modeling and Understanding Uncertainty in Medical Image Classification
Aobo Chen 0002, Yangyi Li, Kathy Morse, Chenglin Miao, Mengdi Huai
MICCAI (10)1