Shengshan Hu

dblp:169/2268 · DBLP profile ↗
← Back
81ranked-venue papers
10as first author
72since 2021 · last 2026
0000-0003-0042-9045ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 32 · 6 first-author · 31 since 2021Artificial intelligence and machine learning · 26 · 2 first-author · 26 since 2021Security and privacy · 24 · 3 first-author · 21 since 2021Computer networks · 8 · 1 first-author · 4 since 2021Systems, architecture and hardware · 4 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Dual-View Inference Attack: Machine Unlearning Amplifies Privacy Exposure
abstract
Machine unlearning is a newly popularized technique for removing specific training data from a trained model, enabling it to comply with data deletion requests. While it protects the rights of users requesting unlearning, it also introduces new privacy risks. Prior works have primarily focused on the privacy of data that has been unlearned, while the risks to retained data remain largely unexplored. To address this gap, we focus on the privacy risks of retained data and, for the first time, reveal the vulnerabilities introduced by machine unlearning under the dual-view setting, where an adversary can query both the original and the unlearned models. From an information-theoretic perspective, we introduce the concept of privacy knowledge gain and demonstrate that the dual-view setting allows adversaries to obtain more information than querying either model alone, thereby amplifying privacy leakage. To effectively demonstrate this threat, we propose DVIA, a Dual-View Inference Attack, which extracts membership information on retained data using black-box queries to both models. DVIA eliminates the need to train an attack model and employs a lightweight likelihood ratio inference module for efficient inference. Experiments across different datasets and model architectures validate the effectiveness of DVIA and highlight the privacy risks inherent in the dual-view setting.
Lulu Xue, Shengshan Hu, Linqiang Qian, Peijin Guo, Yechao Zhang, Yanjun Zhang 0002, Dayong Ye, Leo Yu Zhang
AAAI2
2026 Scrutinising Parametric Distance Verification in Unlearning: A Coupling Perspective
Jingming Dai, Lulu Xue, Jintian Ji, Yanjun Zhang 0002, Shengshan Hu, Leo Yu Zhang
ACISP (3)5
2026 MultiADC: Advanced Antibody-Drug Conjugate Activity Prediction Through Multi-scale Feature Fusion
Zikang Guo, Peijin Guo, Shengshan Hu, Shengqing Hu, Xiaoli Lan
PAKDD (2)5
2026 Fine-Grained Poisoning Framework Against Federated Learning
abstract
Federated learning(FL) is one of the most widely used distributed machine learning frameworks. However, FL is susceptible to poisoning attacks that can degrade the quality of the global model. Recent studies on fine-grained poisoning attacks highlight a strategic shift where attackers no longer prioritize maximal disruption of the global model, but instead control the degree of model poisoning to maintain stealth and avoid detection. However, research on fine-grained poisoning is still in the infant stage. Numerous fundamental questions have yet to be addressed, including its underlying mechanisms and optimization strategies. To this end, we introduces FGP, the first comprehensive framework forFine-GrainedPoisoning on FL, which allows adversaries to precisely manipulate the global model by strategically inducing accurate and stealthy sub-optimal solution. Fundamentally, FGP innovatively formalizes fine-grained attacks as an optimization problem to minimize the distance between the current global model and the adversary's target (a sub-optimal solution). It then employs a real-time search strategy to dynamically refine the malicious model updates in each round. To ensure optimal attack performance, we further introduce a novel topology-based approach as the error feedback. Additionally, we present a formal convergence analysis of our attacks. Armed with FGP, we conduct a comprehensive evaluation of FL's robustness against fine-grained poisoning across diverse settings. Results demonstrate that FGP significantly outperforms the prior work, achieving an average$6.5\times$higher attack accuracy.
Hangtao Zhang, Yanjun Zhang 0002, Chao Chen 0015, Qiyun Shao, Shengshan Hu, Leo Yu Zhang
IEEE Trans. Dependable Secur. Comput.8
2026 Privacy-Preserving Automated Deep Learning for Secure Inference Service
abstract
Automated deep learning (AutoDL) aims to automatically discover optimal architectures of deep neural networks (DNNs) for secure inference without the studies for time-consuming and error-prone manual design. Privacy concerns have increasingly motivated the studies for privacy-preserving AutoDL (PrivAutoDL), where DNN architectures are searched directly on encrypted data without revealing the client's confidential inputs and well-trained DNN architectures. However, existing studies encounter problems in achieving a balance between provable security and efficiency while avoiding significant degradation of model utility. To tackle these problems, we design a privacy-preserving AutoDL scheme, named 2PCAutoDL, utilizing a two-party (two non-colluding cloud servers) computation model. Based on the two-server model, efficient and secure computation protocols are customized layer by layer to protect DNN models associated with client's data. In particular, we reduce the computational overhead of secure DNN: our optimized protocols achieve$1.34\times \sim 2.05\times$speedup for linear layers and$1.33 \times \sim 45 \times$speedup for non-linear layers, compared to a range of existing secure implementations in the literature. Moreover, our fresh alternative to approximate Softmax avoids the drawbacks of approximating exponential operation and yields slightly higher accuracy under appropriate configurations. The security of 2PCAutoDL is formally analyzed under the semi-honest adversary model. Extensive experiments demonstrate that the searched models from 2PCAutoDL improve the inference accuracy by 0.6% on MNIST and by 0.5% on CIFAR-10 when compared to state-of-the-art (SOTA) PrivAutoDL.
Fuyi Wang, Jinzhi Ouyang, Leo Yu Zhang, Lei Pan 0002, Shengshan Hu, Xiaoning Liu 0002, Robin Doss
IEEE Trans. Dependable Secur. Comput.5
2026 Heterogeneous Privacy-Preserving Federated Learning for Edge Intelligence
abstract
Federated learning (FL) as a distributed machine learning paradigm can be applied to edge intelligence scenarios for collaborative machine learning model building. Unfortunately, existing privacy-preserving FL applied to this scenario still faces three challenges: data heterogeneity, model heterogeneity, and privacy heterogeneity. Despite numerous privacy-preserving FL techniques proposed, they still cannot effectively address these three challenges. To solve this problem, we propose HeteroFed, a heterogeneous privacy-preserving FL framework for edge intelligence. Our HeteroFed contains heterogeneous model construction, dynamic gradient clipping, adaptive noise addition, and deviation-aware model aggregation. Specifically, we first use the heterogeneous model construction mechanism to enable personalized model training for different smart devices. Then, we propose a dynamic gradient clipping mechanism to perform dynamically adjusted gradient clipping on models uploaded by smart devices to limit the magnitude of gradients. Finally, we propose an adaptive noise addition mechanism to customize differential privacy protection for smart device models based on their convergence status. Furthermore, to mitigate the influence of noise perturbations on model performance, we propose a deviation-aware model aggregation mechanism for accurate model aggregation. Theoretical analysis demonstrates that HeteroFed achieves heterogeneous differential privacy. Extensive experiments show that HeteroFed outperforms similar methods, improving global model accuracy by 18%, 15%, 13%, and 18% on the MNIST, Fashion-MNIST, CIFAR-10, and THUCNews datasets, respectively.
Helei Cui, Zhibo Wang 0001, Lijuan Huo, Jing Wang 0036, Shengshan Hu
IEEE Trans. Inf. Forensics Secur.7
2025 NumbOD: A Spatial-Frequency Fusion Attack Against Object Detectors
abstract
With the advancement of deep learning, object detectors (ODs) with various architectures have achieved significant success in complex scenarios like autonomous driving. Previous adversarial attacks against ODs have been focused on designing customized attacks targeting their specific structures (eg, NMS and RPN), yielding some results but simultaneously constraining their scalability. Moreover, most efforts against ODs stem from image-level attacks originally designed for classification tasks, resulting in redundant computations and disturbances in object-irrelevant areas (eg, background). Consequently, how to design a model-agnostic efficient attack to comprehensively evaluate the vulnerabilities of ODs remains challenging and unresolved. In this paper, we propose NumbOD, a brand-new spatial-frequency fusion attack against various ODs, aimed at disrupting object detection within images. We directly leverage the features output by the OD without relying on its any internal structures to craft adversarial examples. Specifically, we first design a dual-track attack target selection strategy to select high-quality bounding boxes from OD outputs for targeting. Subsequently, we employ directional perturbations to shift and compress predicted boxes and change classification results to deceive ODs. Additionally, we focus on manipulating the high-frequency components of images to confuse ODs' attention on critical objects, thereby enhancing the attack efficiency. Our extensive experiments on nine ODs and two datasets show that NumbOD achieves powerful attack performance and high stealthiness.
Ziqi Zhou 0001, Zhifei Yu, Shengshan Hu, Leo Yu Zhang, Dezhong Yao 0002, Hai Jin 0001
AAAI5
2025 Detecting and Corrupting Convolution-based Unlearnable Examples
abstract
Convolution-based unlearnable examples (UEs) employ class-wise multiplicative convolutional noise to training samples, severely compromising model performance. This fire-new type of UEs have successfully countered all defense mechanisms against UEs. The failure of such defenses can be attributed to the absence of norm constraints on convolutional noise, leading to severe blurring of image features. To address this, we first design an Edge Pixel-based Detector (EPD) to identify convolution-based UEs. Upon detection of them, we propose the first defense scheme against convolution-based UEs, COrrupting these samples via random matrix multiplication by employing bilinear INterpolation (COIN) such that disrupting the distribution of class-wise multiplicative noise. To evaluate the generalization of our proposed COIN, we newly design two convolution-based UEs called VUDA and HUDA to expand the scope of convolution-based UEs. Extensive experiments demonstrate the effectiveness of detection scheme EPD and that our defense COIN outperforms 11 state-of-the-art (SOTA) defenses, achieving a significant improvement on the CIFAR and ImageNet datasets.
Xianlong Wang 0001, Zhifei Yu, Shengshan Hu, Ziqi Zhou 0001, Longling Zhang, Leo Yu Zhang
AAAI4
2025 Breaking Barriers in Physical-World Adversarial Examples: Improving Robustness and Transferability via Robust Feature
abstract
As deep neural networks (DNNs) are widely applied in the physical world, many researches are focusing on physical-world adversarial examples (PAEs), which introduce perturbations to inputs and cause the model's incorrect outputs. However, existing PAEs face two challenges: unsatisfactory attack performance (i.e., poor transferability and insufficient robustness to environment conditions), and difficulty in balancing attack effectiveness with stealthiness, where better attack effectiveness often makes PAEs more perceptible. In this paper, we explore a novel perturbation-based method to overcome the challenges. For the first challenge, we introduce a strategy Deceptive RF injection based on robust features (RFs) that are predictive, robust to perturbations, and consistent across different models. Specifically, it improves the transferability and robustness of PAEs by covering RFs of other classes onto the predictive features in clean images. For the second challenge, we introduce another strategy Adversarial Semantic Pattern Minimization, which removes most perturbations and retains only essential adversarial patterns in AEs. Based on the two strategies, we design our method Robust Feature Coverage Attack (RFCoA), comprising Robust Feature Disentanglement and Adversarial Feature Fusion. In the first stage, we extract target class RFs in feature space. In the second stage, we use attention-based feature fusion to overlay these RFs onto predictive features of clean images and remove unnecessary perturbations. Experiments show our method's superior transferability, robustness, and stealthiness compared to existing state-of-the-art methods. Additionally, our method's effectiveness can extend to Large Vision-Language Models (LVLMs), indicating its potential applicability to more complex tasks.
Yichen Wang 0013, Yuxuan Chou, Ziqi Zhou 0001, Hangtao Zhang, Shengshan Hu
AAAI6
2025 Improving Generalization of Universal Adversarial Perturbation via Dynamic Maximin Optimization
abstract
Deep neural networks (DNNs) are susceptible to universal adversarial perturbations (UAPs). These perturbations are meticulously designed to fool the target model universally across all sample classes. Unlike instance-specific adversarial examples (AEs), generating UAPs is more complex because they must be generalized across a wide range of data samples and models. Our research reveals that existing universal attack methods, which optimize UAPs using DNNs with static model parameter snapshots, do not fully leverage the potential of DNNs to generate more effective UAPs. Rather than optimizing UAPs against static DNN models with a fixed training set, we suggest using dynamic model-data pairs to generate UAPs. In particular, we introduce a dynamic maximin optimization strategy, aiming to optimize the UAP across a variety of optimal model-data pairs. We term this approach DM-UAP. DM-UAP utilizes an iterative max-min-min optimization framework that refines the model-data pairs, coupled with a curriculum UAP learning algorithm to examine the combined space of model parameters and data thoroughly. Comprehensive experiments on the ImageNet dataset demonstrate that the proposed DM-UAP markedly enhances both cross-sample universality and cross-model transferability of UAPs. Using only 500 samples for UAP generation, DM-UAP outperforms the state-of-the-art approach with an average increase in fooling ratio of 12.108%.
Yechao Zhang, Yingzhe Xu, Junyu Shi, Leo Yu Zhang, Shengshan Hu, Yanjun Zhang 0002
AAAI5
2025 sf SEBioID: Secure and Efficient Biometric Identification with Two-Party Computation
Fuyi Wang, Jinzhi Ouyang, Leo Yu Zhang, Lei Pan 0002, Shengshan Hu, Robin Doss, Jianying Zhou 0001
ACNS (3)5
2025 HiF-DTA: Hierarchical Feature Learning Network for Drug-Target Affinity Prediction
abstract
Accurate prediction of Drug-Target Affinity (DTA) is crucial for reducing experimental costs and accelerating early screening in computational drug discovery. While sequence-based deep learning methods avoid reliance on costly 3D structures, they still overlook simultaneous modeling of global sequence semantic features and local topological structural features within drugs and proteins, and represent drugs as flat sequences without atomic-level, substructural-level, and molecular-level multi-scale features. We propose HiF-DTA, a hierarchical network that adopts a dual-pathway strategy to extract both global sequence semantic and local topological features from drug and protein sequences, and models drugs multi-scale to learn atomic, substructural, and molecular representations fused via a multiscale bilinear attention module. Experiments on Davis, KIBA, and Metz datasets show HiF-DTA outperforms state-of-the-art baselines, with ablations confirming the importance of globallocal extraction and multi-scale fusion.
Peijin Guo, Shengshan Hu, Shengqing Hu
BIBM5
2025 Test-Time Backdoor Detection for Object Detection Models
abstract
Object detection models are vulnerable to backdoor attacks, where attackers poison a small subset of training samples by embedding a predefined trigger to manipulate prediction. Detecting poisoned samples (i.e., those containing triggers) at test time can prevent backdoor activation. However, unlike image classification tasks, the unique characteristics of object detection—particularly its output of numerous objects—pose fresh challenges for backdoor detection. The complex attack effects (e.g., "ghost" object emergence or "vanishing" object) further render current defenses fundamentally inadequate. To this end, we design TRAnsformation Consistency Evaluation (TRACE), a brand-new method for detecting poisoned samples at test time in object detection. Our journey begins with two intriguing observations: 1) poisoned samples exhibit significantly more consistent detection results than clean ones across varied backgrounds. 2) clean samples show higher detection consistency when introduced to different focal information. Based on these phenomena, Trace applies foreground and background transformations to each test sample, then assesses transformation consistency by calculating the variance in objects confidences. Trace achieves black-box, universal backdoor detection, with extensive experiments showing a 30% improvement in AUROC over state-of-the-art defenses and resistance to adaptive attacks.
Hangtao Zhang, Yichen Wang 0013, Shihui Yan, Chenyu Zhu, Ziqi Zhou 0001, Linshan Hou, Shengshan Hu, Yanjun Zhang 0002, Leo Yu Zhang
CVPR7
2025 Transferable Direct Prompt Injection via Activation-Guided MCMC Sampling
abstract
Direct Prompt Injection (DPI) attacks pose a critical security threat to Large Language Models (LLMs) due to their low barrier of execution and high potential damage.To address the impracticality of existing white-box/gray-box methods and the poor transferability of blackbox methods, we propose an activations-guided prompt injection attack framework.We first construct an Energy-based Model (EBM) using activations from a surrogate model to evaluate the quality of adversarial prompts.Guided by the trained EBM, we employ the tokenlevel Markov Chain Monte Carlo (MCMC) sampling to adaptively optimize adversarial prompts, thereby enabling gradient-free blackbox attacks.Experimental results demonstrate our superior cross-model transferability, achieving 49.6% attack success rate (ASR) across five mainstream LLMs and 34.6% improvement over human-crafted prompts, and maintaining 36.6%ASR on unseen task scenarios.Interpretability analysis reveals a correlation between activations and attack effectiveness, highlighting the critical role of semantic patterns in transferable vulnerability exploitation.
Yechao Zhang, Shengshan Hu, Pei Xiaobing, Jing Wang 0036
EMNLP5
2025 An Efficient Residual-based Low-dose PET Reconstruction with Spatial-Frequency Integration
abstract
Positron emission tomography (PET) is a nuclear medical imaging technique where image quality depends on the dose of radionuclides administered to the patient. While standard-dose PET (SPET) offers high-quality imaging, it also poses radiation risks. If reconstructing low-dose PET (LPET) images can guarantee the same level of imaging quality, LPET could serve as a safer alternative by reducing patient radiation exposure. Recent approaches using convolutional neural networks (CNNs) struggle to capture complex features of LPET images due to the fixed convolutional kernels and local receptive fields. Generative adversarial network (GAN)-based methods may suffer from mode collapse and unstable training. Diffusion model-based works can ensure stability and high-quality sample generation but come with high computational costs. Furthermore, all these methods focus solely on spatial domain information, neglecting crucial frequency domain information.To address these issues, we propose an efficient residual-based LPET reconstruction framework combining CNN and diffusion model. Our framework includes a multi-scale dynamic convolution network with a wavelet reconstruction module (MN-WR) to leverage multi-scale spatial and frequency domain information. We also introduce a residual-based diffusion model (ReD) to enhance local detail reconstruction while reducing computational costs. Finally, we design a wavelet-based frequency domain fusion (WFF) module to combine low-frequency edge information from MN-WR with high-frequency details from ReD. Experimental results on public LPET datasets show that our method outperforms state-of-the-art techniques and significantly reduces computational costs. Code is available at https://github.com/TAI-Medical-Lab/LPET-Reconstruction.
Hewen Pan, Shengqing Hu, Longling Zhang, Shengshan Hu, Peijin Guo
ICASSP6
2025 PB-UAP: Hybride Universal Adversarial Attack for Image Segmentation
abstract
With the rapid advancement of deep learning, the model robustness has become a significant research hotspot, i.e., adversarial attacks on deep neural networks. Existing works primarily focus on image classification tasks, aiming to alter the model’s predicted labels. Due to the output complexity and deeper network architectures, research on adversarial examples for segmentation models is still limited, particularly for universal adversarial perturbations. In this paper, we propose a novel universal adversarial attack method designed for segmentation models, which includes dual feature separation and low-frequency scattering modules. The two modules guide the training of adversarial examples in the pixel and frequency space, respectively. Experiments demonstrate that our method achieves high attack success rates surpassing the state-of-the-art methods, and exhibits strong transferability across different models.
Ziqi Zhou 0001, Xianlong Wang 0001, Hangtao Zhang, Menghao Deng, Shengshan Hu, Leo Yu Zhang
ICASSP8
2025 FedLTH: A Privacy-preserving Federated Learning Framework with Model Pruning on Edge Clients
abstract
Although Federated Learning (FL) enables distributed clients to cooperatively train deep learning models without sharing local data, the iterative FL training process imposes considerable computation and communication overheads on clients. Especially in cloud-edge collaboration situations, heterogeneous and resource-limited edge clients can become a bottleneck for FL. In this paper, we propose FedLTH (Federated Learning with the Lottery Ticket Hypothesis), an FL framework based on the Lottery Ticket Hypothesis and adaptive differential privacy, which aims to improve communication and computing efficiency and privacy security for resource-limited edge clients. First, the pruning rate of each client is set according to their respective resource constraints. The server divides the clients into groups with balanced data distribution and similar pruning rates to ensure the convergence of the global model. Then, a structured model pruning method based on the Lottery Ticket Hypothesis is introduced. Each client group participates in a pruning phase to reduce the computing overhead of clients. Last, an adaptive differential privacy algorithm is designed to preserve client data privacy and improve model accuracy. Through experiments on multiple datasets and non-IID scenarios, we show the effectiveness of FedLTH in privacy preservation and reducing computation and communication overheads.
Heyu Zhang, Yulai Xie 0002, Shengshan Hu, Peisong He, Jun Zheng 0017, Dan Feng 0001
ICDCS3
2025 BadRobot: Jailbreaking Embodied LLM Agents in the Physical World
abstract
Embodied AI represents systems where AI is integrated into physical entities. Multimodal Large Language Model (LLM), which exhibits powerful language understanding abilities, has been extensively employed in embodied AI by facilitating sophisticated task planning. However, a critical safety issue remains overlooked: could these embodied LLMs perpetrate harmful behaviors? In response, we introduce BadRobot, the first attack paradigm designed to jailbreak robotic manipulation, making embodied LLMs violate safety and ethical constraints through typical voice-based user-system interactions. Specifically, three vulnerabilities are exploited to achieve this type of attack: (i) manipulation of LLMs within robotic systems, (ii) misalignment between linguistic outputs and physical actions, and (iii) unintentional hazardous behaviors caused by world knowledge's flaws. Furthermore, we construct a benchmark of various malicious physical action queries to evaluate BadRobot's attack performance. Based on this benchmark, extensive experiments against existing prominent embodied LLM frameworks (e.g., Voxposer, Code as Policies, and ProgPrompt) demonstrate the effectiveness of our BadRobot. We emphasize that addressing this emerging vulnerability is crucial for the secure deployment of LLMs in robotics. Warning: This paper contains harmful AI-generated language and aggressive actions.
Hangtao Zhang, Chenyu Zhu, Xianlong Wang 0001, Ziqi Zhou 0001, Changgan Yin, Lulu Xue, Yichen Wang 0013, Shengshan Hu, Aishan Liu, Peijin Guo, Leo Yu Zhang
ICLR9
2025 Multi-Modality Representation Learning for Antibody-Antigen Interactions Prediction
abstract
While deep learning models play a crucial role in predicting antibody-antigen interactions (AAI), the scarcity of publicly available sequence-structure pairings constrains their generalization. Current AAI methods often focus on residue-level static details, overlooking fine-grained structural representations of antibodies and their inter-antibody similarities. To tackle this challenge, we introduce a multi-modality representation approach that integates 3D structural and 1D sequence data to unravel intricate intra-antibody hierarchical relationships. By harnessing these representations, we present MuLAAIP, an AAI prediction framework that utilizes graph attention networks to illuminate graph-level structural features and normalized adaptive graph convolution networks to capture inter-antibody sequence associations. Furthermore, we have curated an AAI benchmark dataset comprising both structural and sequence information along with interaction labels. Through extensive experiments on this benchmark, our results demonstrate that MuLAAIP outperforms current state-of-the-art methods in terms of predictive performance. The implementation code and dataset are publicly available at https://github.com/trashTian/MuLAAIP for reproducibility.
Peijin Guo, Hewen Pan, Ruixiang Huang, Lulu Xue, Shengqing Hu, Zikang Guo, Shengshan Hu
ICME9
2025 Robust Point Cloud Recognition Model Sharing
abstract
With the rapid development of mobile and edge-integrated sensing technologies, 3D point clouds have emerged as a fundamental data modality for understanding and interacting with the physical world. They provide rich spatial and geometric information that enables autonomous driving, mobile robotics, and intelligent IoT devices to perceive and reason about their surroundings in real time. In particular, the development of edge-deployed sensors, such as LiDAR, depth cameras, and structured-light sensors, has made it feasible to capture and process 3D point clouds directly at the network edge, empowering low-latency perception and decision-making for safety-critical systems.
Qiufan Ji, Lin Wang 0025, Cong Shi 0004, Shengshan Hu, Yingying Chen 0001, Lichao Sun 0001
SEC4
2025 Manipulating Multimodal Agents via Cross-Modal Prompt Injection
abstract
The emergence of multimodal large language models has redefined the agent paradigm by integrating language and vision modalities with external data sources, enabling agents to better interpret human instructions and execute increasingly complex tasks. However, in this paper, we identify a critical yet previously overlooked security vulnerability in multimodal agents: cross-modal prompt injection attacks. To exploit this vulnerability, we propose CrossInject, a novel attack framework in which attacker embeds adversarial perturbations across multiple modalities to align with target malicious content, allowing external instructions to hijack the agents' decision-making process and execute unauthorized tasks. Our approach incorporates two key coordinated components. First, we introduce Visual Latent Alignment, where we optimize adversarial features to the malicious instructions in the visual embedding space based on a text-to-image generative model, ensuring that adversarial images subtly encode cues for malicious task execution. Subsequently, we present Textual Guidance Enhancement, where a large language model is leveraged to construct the black-box defensive system prompt through adversarial meta-prompting and generate a malicious textual command based on it that steers the agents' output toward better compliance with attacker's requests. Extensive experiments demonstrate that our method outperforms state-of-the-art attacks, achieving at least a +30.1% increase in attack success rates across diverse tasks. Furthermore, we validate our attack's effectiveness in real-world multimodal autonomous agents, highlighting its potential implications for safety-critical applications. Code can be found in https://github.com/Larry0454/CrossInject.
Le Wang 0014, Zonghao Ying, Tianyuan Zhang 0004, Siyuan Liang 0004, Shengshan Hu, Mingchuan Zhang, Aishan Liu, Xianglong Liu 0001
ACM Multimedia5
2025 MARS: A Malignity-Aware Backdoor Defense in Federated Learning
abstract
Federated Learning (FL) is a distributed paradigm aimed at protecting participant data privacy by exchanging model parameters to achieve high-quality model training. However, this distributed nature also makes FL highly vulnerable to backdoor attacks. Notably, the recently proposed state-of-the-art (SOTA) attack, 3DFed (SP2023), uses an indicator mechanism to determine whether the backdoor models have been accepted by the defender and adaptively optimizes backdoor models, rendering existing defenses ineffective. In this paper, we first reveal that the failure of existing defenses lies in the employment of empirical statistical measures that are loosely coupled with backdoor attacks. Motivated by this, we propose a Malignity-Aware backdooR defenSe (MARS) that leverages backdoor energy (BE) to indicate the malicious extent of each neuron. To amplify malignity, we further extract the most prominent BE values from each model to form a concentrated backdoor energy (CBE). Finally, a novel Wasserstein distance-based clustering method is introduced to effectively identify backdoor models. Extensive experiments demonstrate that MARS can defend against SOTA backdoor attacks and significantly outperforms existing defenses.
Yuxuan Ning, Cheng Hong 0001, Shengshan Hu, Ziqi Zhou 0001, Yechao Zhang, Tianqing Zhu, Wanlei Zhou 0001, Leo Yu Zhang
NeurIPS5
2025 AdvEDM: Fine-grained Adversarial Attack against VLM-based Embodied Agents
abstract
Vision-Language Models (VLMs), with their strong reasoning and planning capabilities, are widely used in embodied decision-making (EDM) tasks in embodied agents, such as autonomous driving and robotic manipulation. Recent research has increasingly explored adversarial attacks on VLMs to reveal their vulnerabilities. However, these attacks either rely on overly strong assumptions, requiring full knowledge of the victim VLM, which is impractical for attacking VLM-based agents, or exhibit limited effectiveness. The latter stems from disrupting most semantic information in the image, which leads to a misalignment between the perception and the task context defined by system prompts. This inconsistency interrupts the VLM's reasoning process, resulting in invalid outputs that fail to affect interactions in the physical world. To this end, we propose a fine-grained adversarial attack framework, AdvEDM, which modifies the VLM's perception of only a few key objects while preserving the semantics of the remaining regions. This attack effectively reduces conflicts with the task context, making VLMs output valid but incorrect decisions and affecting the actions of agents, thus posing a more substantial safety threat in the physical world. We design two variants of based on this framework, AdvEDM-R and AdvEDM-A, which respectively remove the semantics of a specific object from the image and add the semantics of a new object into the image. The experimental results in both general scenarios and EDM tasks demonstrate fine-grained control and excellent attack performance.
Yichen Wang 0013, Hangtao Zhang, Hewen Pan, Ziqi Zhou 0001, Xianlong Wang 0001, Peijin Guo, Lulu Xue, Shengshan Hu, Leo Yu Zhang
NeurIPS8
2025 Vanish into Thin Air: Cross-prompt Universal Adversarial Attacks for SAM2
abstract
Recent studies reveal the vulnerability of the image segmentation foundation model SAM to adversarial examples. Its successor, SAM2, has attracted significant attention due to its strong generalization capability in video segmentation. However, its robustness remains unexplored, and it is unclear whether existing attacks on SAM can be directly transferred to SAM2. In this paper, we first analyze the performance gap of existing attacks between SAM and SAM2 and highlight two key challenges arising from their architectural differences: directional guidance from the prompt and semantic entanglement across consecutive frames. To address these issues, we propose UAP-SAM2, the first cross-prompt universal adversarial attack against SAM2 driven by dual semantic deviation. For cross-prompt transferability, we begin by designing a target-scanning strategy that divides each frame into k regions, each randomly assigned a prompt, to reduce prompt dependency during optimization. For effectiveness, we design a dual semantic deviation framework that optimizes a UAP by distorting the semantics within the current frame and disrupting the semantic consistency across consecutive frames. Extensive experiments on six datasets across two segmentation tasks demonstrate the effectiveness of the proposed method for SAM2. The comparative results show that UAP-SAM2 significantly outperforms state-of-the-art (SOTA) attacks by a large margin.
Ziqi Zhou 0001, Zijing Li, Shengshan Hu, Leo Yu Zhang, Dezhong Yao 0002, Hai Jin 0001
NeurIPS5
2025 Uncertainty-Aware Metabolic Stability Prediction with Dual-View Contrastive Learning
Peijin Guo, Hewen Pan, Zikang Guo, Leo Yu Zhang, Shengshan Hu, Shengqing Hu
ECML/PKDD (3)8
2025 Secure Transfer Learning: Training Clean Model Against Backdoor in Pre-Trained Encoder and Downstream Dataset
abstract
Transfer learning from pre-trained encoders has become essential in modern machine learning, enabling efficient model adaptation across diverse tasks. However, this combination of pre-training and downstream adaptation creates an expanded attack surface, exposing models to sophisticated backdoor embedding at both the encoder and dataset levels—an area often overlooked in prior research. Additionally, the limited computational resources typically available to users of pre-trained encoders constrain the effectiveness of generic backdoor defenses compared to end-to-end training from scratch. In this work, we investigate how to mitigate potential backdoor risks in resource-constrained transfer learning scenarios. Specifically, we first conduct an exhaustive analysis of existing defense strategies, revealing that many follow a reactive workflow based on assumptions that do not scale to unknown threats, novel attack types, or different training paradigms. In response, we introduce a proactive mindset focused on identifying clean elements and propose the Trusted Core (T-Core) Bootstrapping framework, which emphasizes the importance of pinpointing trustworthy data and neurons to enhance model security. Our empirical evaluations demonstrate the effectiveness and superiority of T-Core, specifically assessing 5 encoder poisoning attacks, 7 dataset poisoning attacks, and 14 baseline defenses across 5 benchmark datasets, addressing 4 scenarios of 3 potential backdoor threats.
Yechao Zhang, Shengshan Hu, Wei Luo 0001, Leo Yu Zhang
SP5
2025 MVSF-AB: accurate antibody-antigen binding affinity prediction via multi-view sequence feature learning
abstract
MOTIVATION: Predicting the binding affinity between antigens and antibodies accurately is crucial for assessing therapeutic antibody effectiveness and enhancing antibody engineering and vaccine design. Traditional machine learning methods have been widely used for this purpose, relying on interfacial amino acids' structural information. Nevertheless, due to technological limitations and high costs of acquiring structural data, the structures of most antigens and antibodies are unknown, and sequence-based methods have gained attention. Existing sequence-based approaches designed for protein-protein affinity prediction exhibit a significant drop in performance when applied directly to antibody-antigen affinity prediction due to imbalanced training data and lacking design in the model framework specifically for antibody-antigen, hindering the learning of key features of antibodies and antigens. Therefore, we propose MVSF-AB, a Multi-View Sequence Feature learning for accurate Antibody-antigen Binding affinity prediction. RESULTS: MVSF-AB designs a multi-view method that fuses semantic features and residue features to fully utilize the sequence information of antibody-antigen and predicts the binding affinity. Experimental results demonstrate that MVSF-AB outperforms existing approaches in predicting unobserved natural antibody-antigen affinity and maintains its effectiveness when faced with mutant strains of antibodies. AVAILABILITY AND IMPLEMENTATION: Datasets we used and source code are available on our public GitHub repository https://github.com/TAI-Medical-Lab/MVSF-AB.
Shengqing Hu, Shengshan Hu, Peijin Guo, Leo Yu Zhang, Shirui Pan, Jizhou Li, Lichao Sun 0001, Xiaoli Lan
Bioinform.4
2025 DarkHash: A Data-Free Backdoor Attack Against Deep Hashing
abstract
Benefiting from its superior feature learning capabilities and efficiency, deep hashing has achieved remarkable success in large-scale image retrieval. Recent studies have demonstrated the vulnerability of deep hashing models to backdoor attacks. Although these studies have shown promising attack results, they rely on access to the training dataset to implant the backdoor. In the real world, obtaining such data (e.g., identity information) is often prohibited due to privacy protection and intellectual property concerns. Embedding backdoors into deep hashing models without access to the training data, while maintaining retrieval accuracy for the original task, presents a novel and challenging problem. In this paper, we propose DarkHash, the first data-free backdoor attack against deep hashing. Specifically, we design a novel shadow backdoor attack framework with dual-semantic guidance. It embeds backdoor functionality and maintains original retrieval accuracy by fine-tuning only specific layers of the victim model using a surrogate dataset. We consider leveraging the relationship between individual samples and their neighbors to enhance backdoor attacks during training. By designing a topological alignment loss, we optimize both individual and neighboring poisoned samples toward the target sample, further enhancing the attack capability. Experimental results on four image datasets, five model architectures, and two hashing methods demonstrate the high effectiveness of DarkHash, outperforming existing state-of-the-art backdoor attack methods. Defense experiments show that DarkHash can withstand existing mainstream backdoor defense methods.
Ziqi Zhou 0001, Menghao Deng, Hangtao Zhang, Shengshan Hu, Leo Yu Zhang, Dezhong Yao 0002
IEEE Trans. Inf. Forensics Secur.6
2024 Towards Model Extraction Attacks in GAN-Based Image Translation via Domain Shift Mitigation
abstract
Model extraction attacks (MEAs) enable an attacker to replicate the functionality of a victim deep neural network (DNN) model by only querying its API service remotely, posing a severe threat to the security and integrity of pay-per-query DNN-based services. Although the majority of current research on MEAs has primarily concentrated on neural classifiers, there is a growing prevalence of image-to-image translation (I2IT) tasks in our everyday activities. However, techniques developed for MEA of DNN classifiers cannot be directly transferred to the case of I2IT, rendering the vulnerability of I2IT models to MEA attacks often underestimated. This paper unveils the threat of MEA in I2IT tasks from a new perspective. Diverging from the traditional approach of bridging the distribution gap between attacker queries and victim training samples, we opt to mitigate the effect caused by the different distributions, known as the domain shift. This is achieved by introducing a new regularization term that penalizes high-frequency noise, and seeking a flatter minimum to avoid overfitting to the shifted distribution. Extensive experiments on different image translation tasks, including image super-resolution and style transfer, are performed on different backbone victim models, and the new design consistently outperforms the baseline by a large margin across all metrics. A few real-life I2IT APIs are also verified to be extremely vulnerable to our attack, emphasizing the need for enhanced defenses and potentially revised API publishing policies.
Di Mi, Yanjun Zhang 0002, Leo Yu Zhang, Shengshan Hu, Haizhuan Yuan, Shirui Pan
AAAI4
2024 Revisiting Gradient Pruning: A Dual Realization for Defending against Gradient Attacks
abstract
Collaborative learning (CL) is a distributed learning framework that aims to protect user privacy by allowing users to jointly train a model by sharing their gradient updates only. However, gradient inversion attacks (GIAs), which recover users' training data from shared gradients, impose severe privacy threats to CL. Existing defense methods adopt different techniques, e.g., differential privacy, cryptography, and perturbation defenses, to defend against the GIAs. Nevertheless, all current defense methods suffer from a poor trade-off between privacy, utility, and efficiency. To mitigate the weaknesses of existing solutions, we propose a novel defense method, Dual Gradient Pruning (DGP), based on gradient pruning, which can improve communication efficiency while preserving the utility and privacy of CL. Specifically, DGP slightly changes gradient pruning with a stronger privacy guarantee. And DGP can also significantly improve communication efficiency with a theoretical analysis of its convergence and generalization. Our extensive experiments show that DGP can effectively defend against the most powerful GIAs and reduce the communication cost without sacrificing the model's utility.
Lulu Xue, Shengshan Hu, Ruizhi Zhao, Leo Yu Zhang, Shengqing Hu, Lichao Sun 0001, Dezhong Yao 0002
AAAI2
2024 Stealing Watermarks of Large Language Models via Mixed Integer Programming
abstract
The Large Language Model (LLM) watermark is a newly emerging technique that shows promise in addressing concerns surrounding LLM copyright, monitoring AI-generated text, and preventing its misuse. The LLM watermark scheme commonly includes generating secret keys to partition the vocabulary into green and red lists, applying a perturbation to the logits of tokens in the green list to increase their sampling likelihood, thus facilitating watermark detection to identify AI-generated text if the proportion of green tokens exceeds a threshold. However, recent research indicates that watermarking methods using numerous keys are susceptible to removal attacks, such as token editing, synonym substitution, and paraphrasing, with robustness declining as the number of keys increases. Therefore, the state-of-the-art watermark schemes that employ fewer or single keys have been demonstrated to be more robust against text editing and paraphrasing. In this paper, we propose a novel green list stealing attack against the state-of-the-art LLM watermark scheme and systematically examine its vulnerability to this attack. We formalize the attack as a mixed integer programming problem with constraints. We evaluate our attack under a comprehensive threat model, including an extreme scenario where the attacker has no prior knowledge, lacks access to the watermark detector API, and possesses no information about the LLM’s parameter settings or watermark injection/detection scheme. Extensive experiments on LLMs, such as OPT and LLaMA, demonstrate that our attack can successfully steal the green list and remove the watermark across all settings.
Zhaoxi Zhang 0001, Xiaomei Zhang 0001, Yanjun Zhang 0002, Leo Yu Zhang, Chao Chen 0015, Shengshan Hu, Asif Gill, Shirui Pan
ACSAC6
2024 ViDTA: Enhanced Drug-Target Affinity Prediction via Virtual Graph Nodes and Attention-based Feature Fusion
abstract
Drug-target interaction is fundamental in understanding how drugs affect biological systems, and accurately predicting drug-target affinity (DTA) is vital for drug discovery. Recently, deep learning methods have emerged as a significant approach for estimating the binding strength between drugs and target proteins. However, existing methods simply utilize the drug’s local information from molecular topology rather than global information. Additionally, the features of drugs and proteins are usually fused with a simple concatenation operation, limiting their effectiveness. To address these challenges, we proposed ViDTA, an enhanced DTA prediction framework. We introduce virtual nodes into the Graph Neural Network (GNN)-based drug feature extraction network, which acts as a global memory to exchange messages more efficiently. By incorporating virtual graph nodes, we seamlessly integrate local and global features of drug molecular structures, expanding the GNN’s receptive field. Additionally, we propose an attention-based linear feature fusion network for better capturing the interaction information between drugs and proteins. Experimental results evaluated on various benchmarks including Davis, Metz, and KIBA demonstrate that our proposed ViDTA outperforms the state-of-the-art baselines.
Zikang Guo, Peijin Guo, Shengshan Hu, Shengqing Hu
BIBM6
2024 ECLIPSE: Expunging Clean-Label Indiscriminate Poisons via Sparse Diffusion Purification
Xianlong Wang 0001, Shengshan Hu, Yechao Zhang, Ziqi Zhou 0001, Leo Yu Zhang, Peng Xu 0003, Hai Jin 0001
ESORICS (1)2
2024 PointAPA: Towards Availability Poisoning Attacks in 3D Point Clouds
Xianlong Wang 0001, Peng Xu 0003, Wei Liu 0304, Leo Yu Zhang, Shengshan Hu, Yanjun Zhang 0002
ESORICS (1)6
2024 MISA: Unveiling the Vulnerabilities in Split Federated Learning
abstract
Federated learning (FL) and split learning (SL) are prevailing distributed paradigms in recent years. They both enable shared global model training while keeping data localized on users’ devices. The former excels in parallel execution capabilities, while the latter enjoys low dependence on edge computing resources and strong privacy protection. Split federated learning (SFL) combines the strengths of both FL and SL, making it one of the most popular distributed architectures. Furthermore, a recent study has claimed that SFL exhibits robustness against poisoning attacks, with a fivefold improvement compared to FL in terms of robustness.In this paper, we present a novel poisoning attack known as $\color{Fuchsia} {{\text{MISA}}}$. It poisons both the top and bottom models, causing a misalignment in the global model, ultimately leading to a drastic accuracy collapse. This attack unveils the vulnerabilities in SFL, challenging the conventional belief that SFL is robust against poisoning attacks. Extensive experiments demonstrate that our proposed MISA poses a significant threat to the availability of SFL, underscoring the imperative for academia and industry to accord this matter due attention.
Yuxuan Ning, Shengshan Hu, Lulu Xue, Leo Yu Zhang, Hai Jin 0001
ICASSP3
2024 Stealthy Backdoor Attack Towards Federated Automatic Speaker Verification
abstract
Automatic speech verification (ASV) authenticates individuals based on distinct vocal patterns, playing a pivotal role in many applications such as voice-based unlocking systems for devices. The ASV system comprises three stages: training, registration, and validation. The model refines using voice data in training, extracts vocal features in registration, and contrasts these with speech patterns in validation. Modern ASV models, primarily grounded in DNN architectures, require extensive data for training. Federated learning (FL) fosters model-sharing across multiple clients while ensuring data privacy. Due to its open architecture, FL is vulnerable to backdoor attacks. However, training a stealthy backdoor attack in FL presents challenges, including diminished attack generalization owing to data heterogeneity, and conspicuous triggers that render them easily detectable. In this paper, we propose a Federated Stealthy Backdoor Attack method ($FedSBA$). FedSBA aims to improve the attack model’s generalization, enhance its persistence, and elude anomaly detection under the heterogeneous data distribution. FedSBA constructs an attack model based on a personalized transformer and encompasses a stealthy trigger. Moreover, we also propose a defensive strategy that utilizes an adaptive weight aggregation scheme. The stealthiness and effectiveness of FedSBA are demonstrated by exhibiting superior performance in comparison to previous works.
Longling Zhang, Lyqi Liu, Shengshan Hu
ICASSP5
2024 DarkFed: A Data-Free Backdoor Attack in Federated Learning
Yuxuan Ning, Shengshan Hu, Lulu Xue, Leo Yu Zhang, Yichen Wang 0013
IJCAI4
2024 Detector Collapse: Backdooring Object Detection to Catastrophic Overload or Blindness in the Physical World
Hangtao Zhang, Shengshan Hu, Yichen Wang 0013, Leo Yu Zhang, Ziqi Zhou 0001, Xianlong Wang 0001, Yanjun Zhang 0002, Chao Chen 0015
IJCAI2
2024 Transferable Adversarial Facial Images for Privacy Protection
abstract
The success of deep face recognition (FR) systems has raised serious privacy concerns due to their ability to enable unauthorized tracking of users in the digital world. Previous studies proposed introducing imperceptible adversarial noises into face images to deceive those face recognition models, thus achieving the goal of enhancing facial privacy protection. Nevertheless, they heavily rely on user-chosen references to guide the generation of adversarial noises, and cannot simultaneously construct natural and highly transferable adversarial face images in black-box scenarios. In light of this, we present a novel face privacy protection scheme with improved transferability while maintain high visual quality. We propose shaping the entire face space directly instead of exploiting one kind of facial characteristic like makeup information to integrate adversarial noises. To achieve this goal, we first exploit global adversarial latent search to traverse the latent space of the generative model, thereby creating natural adversarial face images with high transferability. We then introduce a key landmark regularization module to preserve the visual identity information. Finally, we investigate the impacts of various kinds of latent spaces and find that F latent space benefits the trade-off between visual naturalness and adversarial transferability. Extensive experiments over two datasets demonstrate that our approach significantly enhances attack transferability while maintaining high visual quality, outperforming state-of-the-art methods by an average 25% improvement in deep FR models and 10% improvement on commercial FR APIs.
Jiangxiong Wang, Ziqi Zhou 0001, Shengshan Hu, Xiaobing Pei
ACM Multimedia5
2024 Unlearnable 3D Point Clouds: Class-wise Transformation Is All You Need
abstract
Traditional unlearnable strategies have been proposed to prevent unauthorized users from training on the 2D image data. With more 3D point cloud data containing sensitivity information, unauthorized usage of this new type data has also become a serious concern. To address this, we propose the first integral unlearnable framework for 3D point clouds including two processes: (i) we propose an unlearnable data protection scheme, involving a class-wise setting established by a category-adaptive allocation strategy and multi-transformations assigned to samples; (ii) we propose a data restoration scheme that utilizes class-wise inverse matrix transformation, thus enabling authorized-only training for unlearnable data. This restoration process is a practical issue overlooked in most existing unlearnable literature, i.e., even authorized users struggle to gain knowledge from 3D unlearnable data. Both theoretical and empirical results (including 6 datasets, 16 models, and 2 tasks) demonstrate the effectiveness of our proposed unlearnable framework. Our code is available at https://github.com/CGCL-codes/UnlearnablePC.
Xianlong Wang 0001, Wei Liu 0004, Hangtao Zhang, Shengshan Hu, Yechao Zhang, Ziqi Zhou 0001, Hai Jin 0001
NeurIPS5
2024 DarkSAM: Fooling Segment Anything Model to Segment Nothing
abstract
Segment Anything Model (SAM) has recently gained much attention for its outstanding generalization to unseen data and tasks. Despite its promising prospect, the vulnerabilities of SAM, especially to universal adversarial perturbation (UAP) have not been thoroughly investigated yet. In this paper, we propose DarkSAM, the first prompt-free universal attack framework against SAM, including a semantic decoupling-based spatial attack and a texture distortion-based frequency attack. We first divide the output of SAM into foreground and background. Then, we design a shadow target strategy to obtain the semantic blueprint of the image as the attack target. DarkSAM is dedicated to fooling SAM by extracting and destroying crucial object features from images in both spatial and frequency domains. In the spatial domain, we disrupt the semantics of both the foreground and background in the image to confuse SAM. In the frequency domain, we further enhance the attack effectiveness by distorting the high-frequency components (i.e., texture information) of the image. Consequently, with a single UAP, DarkSAM renders SAM incapable of segmenting objects across diverse images with varying prompts. Experimental results on four datasets for SAM and its two variant models demonstrate the powerful attack capability and transferability of DarkSAM. Our codes are available at: https://github.com/CGCL-codes/DarkSAM.
Ziqi Zhou 0001, Shengshan Hu, Xianlong Wang 0001, Leo Yu Zhang, Dezhong Yao 0002, Hai Jin 0001
NeurIPS4
2024 Robust Backdoor Detection for Deep Learning via Topological Evolution Dynamics
abstract
A backdoor attack in deep learning inserts a hidden backdoor in the model to trigger malicious behavior upon specific input patterns. Existing detection approaches assume a metric space (for either the original inputs or their latent representations) in which normal samples and malicious samples are separable. We show that this assumption has a severe limitation by introducing a novel SSDT (Source-Specific and Dynamic-Triggers) backdoor, which obscures the difference between normal samples and malicious samples.To overcome this limitation, we move beyond looking for a perfect metric space that would work for different deep-learning models, and instead resort to more robust topological constructs. We propose TED (Topological Evolution Dynamics) as a model-agnostic basis for robust backdoor detection. The main idea of TED is to view a deep-learning model as a dynamical system that evolves inputs to outputs. In such a dynamical system, a benign input follows a natural evolution trajectory similar to other benign inputs. In contrast, a malicious sample displays a distinct trajectory, since it starts close to benign samples but eventually shifts towards the neighborhood of attacker-specified target samples to activate the backdoor.Extensive evaluations are conducted on vision and natural language datasets across different network architectures. The results demonstrate that TED not only achieves a high detection rate, but also significantly outperforms existing state-of-the-art detection approaches, particularly in addressing the sophisticated SSDT attack. The code to reproduce the results is made public on GitHub.
Xiaoxing Mo, Yechao Zhang, Leo Yu Zhang, Wei Luo 0001, Nan Sun 0002, Shengshan Hu, Shang Gao 0003, Yang Xiang 0001
SP6
2024 Why Does Little Robustness Help? A Further Step Towards Understanding Adversarial Transferability
abstract
Adversarial examples for deep neural networks (DNNs) are transferable: examples that successfully fool one white-box surrogate model can also deceive other black-box models with different architectures. Although a bunch of empirical studies have provided guidance on generating highly transferable adversarial examples, many of these findings fail to be well explained and even lead to confusing or inconsistent advice for practical use.In this paper, we take a further step towards understanding adversarial transferability, with a particular focus on surrogate aspects. Starting from the intriguing "little robustness" phenomenon, where models adversarially trained with mildly perturbed adversarial samples can serve as better surrogates for transfer attacks, we attribute it to a trade-off between two dominant factors: model smoothness and gradient similarity. Our research focuses on their joint effects on transferability, rather than demonstrating the separate relationships alone. Through a combination of theoretical and empirical analyses, we hypothesize that the data distribution shift induced by off-manifold samples in adversarial training is the reason that impairs gradient similarity.Building on these insights, we further explore the impacts of prevalent data augmentation and gradient regularization on transferability and analyze how the trade-off manifests in various training methods, thus building a comprehensive blueprint for the regulation mechanisms behind transferability. Finally, we provide a general route for constructing superior surrogates to boost transferability, which optimizes both model smoothness and gradient similarity simultaneously, e.g., the combination of input gradient regularization and sharpness-aware minimization (SAM), validated by extensive experiments. In summary, we call for attention to the united impacts of these two factors for launching effective transfer attacks, rather than optimizing one while ignoring the other, and emphasize the crucial role of manipulating surrogate models.
Yechao Zhang, Shengshan Hu, Leo Yu Zhang, Junyu Shi, Xiaogeng Liu, Hai Jin 0001
SP2
2024 Securely Fine-tuning Pre-trained Encoders Against Adversarial Examples
abstract
With the evolution of self-supervised learning, the pre-training paradigm has emerged as a predominant solution within the deep learning landscape. Model providers furnish pre-trained encoders designed to function as versatile feature extractors, enabling downstream users to harness the benefits of expansive models with minimal effort through fine-tuning. Nevertheless, recent works have exposed a vulnerability in pre-trained encoders, highlighting their susceptibility to downstream-agnostic adversarial examples (DAEs) meticulously crafted by attackers. The lingering question pertains to the feasibility of fortifying the robustness of downstream models against DAEs, particularly in scenarios where the pre-trained encoders are publicly accessible to the attackers.In this paper, we initially delve into existing defensive mechanisms against adversarial examples within the pre-training paradigm. Our findings reveal that the failure of current defenses stems from the domain shift between pre-training data and downstream tasks, as well as the sensitivity of encoder parameters. In response to these challenges, we propose Genetic Evolution-Nurtured Adversarial Fine-tuning (Gen-AF), a two-stage adversarial fine-tuning approach aimed at enhancing the robustness of downstream models. Gen-AF employs a genetic-directed dual-track adversarial fine-tuning strategy in its first stage to effectively inherit the pre-trained encoder. This involves optimizing the pre-trained encoder and classifier separately while incorporating genetic regularization to preserve the model’s topology. In the second stage, Gen-AF assesses the robust sensitivity of each layer and creates a dictionary, based on which the top-k robust redundant layers are selected with the remaining layers held fixed. Upon this foundation, we conduct evolutionary adaptability fine-tuning to further enhance the model’s generalizability. Our extensive experiments, conducted across ten self-supervised training methods and six datasets, demonstrate that Gen-AF attains high testing accuracy and robust testing accuracy against state-of-the-art DAEs.
Ziqi Zhou 0001, Wei Liu 0304, Shengshan Hu, Yechao Zhang, Lulu Xue, Leo Yu Zhang, Dezhong Yao 0002, Hai Jin 0001
SP4
2024 Depriving the Survival Space of Adversaries Against Poisoned Gradients in Federated Learning
abstract
Federated learning (FL) allows clients at the edge to learn a shared global model without disclosing their private data. However, FL is susceptible to poisoning attacks, wherein an adversary injects tainted local models that ultimately corrupt the global model. Despite various defensive mechanisms having been developed to combat poisoning attacks, they all fall short of securing practical FL scenarios with heterogeneous and unbalanced data distribution. Moreover, the cutting-edge defenses currently at our disposal demand access to a proprietary dataset that closely mirrors the distribution of clients’ data, which runs counter to the fundamental principle of privacy protection in FL. It is still challenging to devise an effective defense approach that applies to practical FL. In this work, we strive to narrow the divide between FL defense and its practical use. We first present a general framework to comprehend the effect of poisoning attacks in FL when the training data is not independent and identically distributed (non-IID). We then HeteroFL, a novel FL scheme that incorporates four complementary defensive strategies. These tactics are implemented in succession to refine the aggregated model toward approaching the global optimum. Ultimately, we devise an adaptive attack specifically for HeteroFL, aimed at offering a more thorough evaluation of its robustness. Our extensive experiments over heterogeneous datasets and models show that HeteroFL surpasses all state-of-the-art defenses in thwarting various poisoning attacks, i.e., HeteroFL achieves global model accuracies comparable to the baseline, whereas other defenses suffer a significant accuracy reduction ranging from 34% to 79%.
Jianrong Lu, Shengshan Hu, Leo Yu Zhang, Lulu Xue, Hai Jin 0001
IEEE Trans. Inf. Forensics Secur.2
2024 FingerPattern: Securing Pattern Lock via Fingerprint-Dependent Friction Sound
abstract
Pattern lock is widely used for user authentication in mobile devices due to its simplicity and ease of remembering. However, it is vulnerable to various attacks,e.g., shoulder surfing attacks. In this paper, we propose FingerPattern, a novel enhanced pattern lock authentication system by using friction sound as a second authentication factor. When the user inputs the pattern by swiping his/her fingertip on the screen, the friction sound is generated based on the user's fingerprint and is unique. Thus, FingerPattern can identify and rule out the illegality by utilizing fingerprint-dependent friction sound even if the adversary has inferred the pattern. By this method, FingerPattern secures pattern lock without the need for a change in user unlocking habits. Extensive experiments demonstrate that FingerPattern can identify legitimate users with 97.5% TAR in one attempt and defend against various attacks (e.g., only 16.8% FAR in five attempts even if the adversary can clearly spy on the user's unlocking process). FingerPattern can be incorporated into the existing pattern lock of mobile devices, which is cost-free. Furthermore, a user experience study shows that FingerPattern is well-received by users.
Man Zhou 0004, Shuao Su, Qian Wang 0002, Qi Li 0002, Shengshan Hu, Chunwu Yu, Zhengxiong Li
IEEE Trans. Mob. Comput.6
2023 PointCA: Evaluating the Robustness of 3D Point Cloud Completion Models against Adversarial Examples
abstract
Point cloud completion, as the upstream procedure of 3D recognition and segmentation, has become an essential part of many tasks such as navigation and scene understanding. While various point cloud completion models have demonstrated their powerful capabilities, their robustness against adversarial attacks, which have been proven to be fatally malicious towards deep neural networks, remains unknown. In addition, existing attack approaches towards point cloud classifiers cannot be applied to the completion models due to different output forms and attack purposes. In order to evaluate the robustness of the completion models, we propose PointCA, the first adversarial attack against 3D point cloud completion models. PointCA can generate adversarial point clouds that maintain high similarity with the original ones, while being completed as another object with totally different semantic information. Specifically, we minimize the representation discrepancy between the adversarial example and the target point set to jointly explore the adversarial point clouds in the geometry space and the feature space. Furthermore, to launch a stealthier attack, we innovatively employ the neighbourhood density information to tailor the perturbation constraint, leading to geometry-aware and distribution-adaptive modifications for each point. Extensive experiments against different premier point cloud completion networks show that PointCA can cause the performance degradation from 77.9% to 16.7%, with the structure chamfer distance kept below 0.01. We conclude that existing completion models are severely vulnerable to adversarial examples, and state-of-the-art defenses for point cloud classification will be partially invalid when applied to incomplete and uneven point cloud data.
Shengshan Hu, Wei Liu 0004, Junhui Hou, Leo Yu Zhang, Hai Jin 0001, Lichao Sun 0001
AAAI1
2023 Masked Language Model Based Textual Adversarial Example Detection
abstract
Adversarial attacks are a serious threat to the reliable deployment of machine learning models in safety-critical applications. They can misguide current models to predict incorrectly by slightly modifying the inputs. Recently, substantial work has shown that adversarial examples tend to deviate from the underlying data manifold of normal examples, whereas pre-trained masked language models can fit the manifold of normal NLP data. To explore how to use the masked language model in adversarial detection, we propose a novel textual adversarial example detection method, namely Masked Language Model-based Detection (MLMD), which can produce clearly distinguishable signals between normal examples and adversarial examples by exploring the changes in manifolds induced by the masked language model. MLMD features a plug and play usage (i.e., no need to retrain the victim model) for adversarial defense and it is agnostic to classification tasks, victim model’s architectures, and to-be-defended attack methods. We evaluate MLMD on various benchmark textual datasets, widely studied machine learning models, and state-of-the-art (SOTA) adversarial attacks (in total 3*4*4 = 48 settings). Experimental results show that MLMD can achieve strong performance, with detection accuracy up to 0.984, 0.967, and 0.901 on AG-NEWS, IMDB, and SST-2 datasets, respectively. Additionally, MLMD is superior, or at least comparable to, the SOTA detection defenses in detection accuracy and F1 score. Among many defenses based on the off-manifold assumption of adversarial examples, this work offers a new angle for capturing the manifold change. The code for this work is openly accessible at https://github.com/mlmddetection/MLMDdetection.
Xiaomei Zhang 0001, Zhaoxi Zhang 0001, Xufei Zheng, Yanjun Zhang 0002, Shengshan Hu, Leo Yu Zhang
AsiaCCS6
2023 Detecting Backdoors During the Inference Stage Based on Corruption Robustness Consistency
abstract
Deep neural networks are proven to be vulnerable to backdoor attacks. Detecting the trigger samples during the inference stage, i.e., the test-time trigger sample detection, can prevent the backdoor from being triggered. However, existing detection methods often require the defenders to have high accessibility to victim models, extra clean data, or knowledge about the appearance of backdoor triggers, limiting their practicality. In this paper, we propose the test-time corruption robustness consistency evaluation (TeCo)11https://github.com/CGCL-codes/TeCo, a novel test-time trigger sample detection method that only needs the hard-label outputs of the victim models without any extra information. Our journey begins with the intriguing observation that the backdoor-infected models have similar performance across different image corruptions for the clean images, but perform discrepantly for the trigger samples. Based on this phenomenon, we design TeCo to evaluate test-time robustness consistency by calculating the deviation of severity that leads to predictions' transition across different corruptions. Extensive experiments demonstrate that compared with state-of-the-art defenses, which even require either certain information about the trigger types or accessibility of clean data, TeCo outperforms them on different backdoor attacks, datasets, and model architectures, enjoying a higher AUROC by 10% and 5 times of stability.
Xiaogeng Liu, Shengshan Hu, Dengpan Ye, Hai Jin 0001, Chaowei Xiao
CVPR4
2023 Benchmarking and Analyzing Robust Point Cloud Recognition: Bag of Tricks for Defending Adversarial Examples
abstract
Deep Neural Networks (DNNs) for 3D point cloud recognition are vulnerable to adversarial examples, threatening their practical deployment. Despite the many research endeavors have been made to tackle this issue in recent years, the diversity of adversarial examples on 3D point clouds makes them more challenging to defend against than those on 2D images. For examples, attackers can generate adversarial examples by adding, shifting, or removing points. Consequently, existing defense strategies are hard to counter unseen point cloud adversarial examples. In this paper, we first establish a comprehensive, and rigorous point cloud adversarial robustness benchmark to evaluate adversarial robustness, which can provide a detailed understanding of the effects of the defense and attack methods. We then collect existing defense tricks in point cloud adversarial defenses and then perform extensive and systematic experiments to identify an effective combination of these tricks. Furthermore, we propose a hybrid training augmentation methods that consider various types of point cloud adversarial examples to adversarial training, significantly improving the adversarial robustness. By combining these tricks, we construct a more robust defense framework achieving an average accuracy of 83.45% against various attacks, demonstrating its capability to enabling robust learners. Our codebase are open-sourced on: https://github.com/qiufan319/benchmark_pc_attack.git.
Qiufan Ji, Lin Wang 0025, Cong Shi 0004, Shengshan Hu, Yingying Chen 0001, Lichao Sun 0001
ICCV4
2023 Downstream-agnostic Adversarial Examples
abstract
Self-supervised learning usually uses a large amount of unlabeled data to pre-train an encoder which can be used as a general-purpose feature extractor, such that downstream users only need to perform fine-tuning operations to enjoy the benefit of "large model". Despite this promising prospect, the security of pre-trained encoder has not been thoroughly investigated yet, especially when the pre-trained encoder is publicly available for commercial use.In this paper, we propose AdvEncoder, the first framework for generating downstream-agnostic universal adversarial examples based on the pre-trained encoder. AdvEncoder aims to construct a universal adversarial perturbation or patch for a set of natural images that can fool all the downstream tasks inheriting the victim pre-trained encoder. Unlike traditional adversarial example works, the pre-trained encoder only outputs feature vectors rather than classification labels. Therefore, we first exploit the high frequency component information of the image to guide the generation of adversarial examples. Then we design a generative attack framework to construct adversarial perturbations/patches by learning the distribution of the attack surrogate dataset to improve their attack success rates and transferability. Our results show that an attacker can successfully attack downstream tasks without knowing either the pre-training dataset or the downstream dataset. We also tailor four defenses for pre-trained encoders, the results of which further prove the attack ability of AdvEncoder. Our codes are available at: https://github.com/CGCL-codes/AdvEncoder.
Ziqi Zhou 0001, Shengshan Hu, Ruizhi Zhao, Qian Wang 0002, Leo Yu Zhang, Junhui Hou, Hai Jin 0001
ICCV2
2023 Voice Guard: Protecting Voice Privacy with Strong and Imperceptible Adversarial Perturbation in the Time Domain
abstract
Adversarial example is a rising tool for voice privacy protection. By adding imperceptible noise to public audio, it prevents tampers from using zero-shot Voice Conversion (VC) to synthesize high quality speech with target speaker identity. However, many existing studies ignore the human perception characteristics of audio data, and it is challenging to generate strong and imperceptible adversarial audio. In this paper, we propose the Voice Guard defense method, which uses a novel method to advance the adversarial perturbation to the time domain to avoid the loss caused by cross-domain conversion. And the psychoacoustic model is introduced into the defense of VC for the first time, which greatly improves the disruption ability and concealment of adversarial audio. We also standardize the evaluation metrics of adversarial audio for the first time, combining multi-dimensional metrics to define the criteria for defense. We evaluate Voice Guard on several state-of-the-art zero-shot VC models. The experimental results show that our method can ensure the perceptual quality of adversarial audio while having a strong defense capability, and is far superior to previous works in terms of disruption ability and concealment.
Dengpan Ye, Chuanxi Chen, Shengshan Hu
IJCAI5
2023 Denial-of-Service or Fine-Grained Control: Towards Flexible Model Poisoning Attacks on Federated Learning
abstract
Federated learning (FL) is vulnerable to poisoning attacks, where adversaries corrupt the global aggregation results and cause denial-of-service (DoS). Unlike recent model poisoning attacks that optimize the amplitude of malicious perturbations along certain prescribed directions to cause DoS, we propose a flexible model poisoning attack (FMPA) that can achieve versatile attack goals. We consider a practical threat scenario where no extra knowledge about the FL system (e.g., aggregation rules or updates on benign devices) is available to adversaries. FMPA exploits the global historical information to construct an estimator that predicts the next round of the global model as a benign reference. It then fine-tunes the reference model to obtain the desired poisoned model with low accuracy and small perturbations. Besides the goal of causing DoS, FMPA can be naturally extended to launch a fine-grained controllable attack, making it possible to precisely reduce the global accuracy. Armed with precise control, malicious FL service providers can gain advantages over their competitors without getting noticed, hence opening a new attack surface in FL other than DoS. Even for the purpose of DoS, experiments show that FMPA significantly decreases the global accuracy, outperforming six state-of-the-art attacks.
Hangtao Zhang, Zeming Yao, Leo Yu Zhang, Shengshan Hu, Chao Chen 0015, Alan Wee-Chung Liew, Zhetao Li
IJCAI4
2023 PointCRT: Detecting Backdoor in 3D Point Cloud via Corruption Robustness
abstract
Backdoor attacks for point clouds have elicited mounting interest with the proliferation of deep learning. The point cloud classifiers can be vulnerable to malicious actors who seek to manipulate or fool the model with specific backdoor triggers. Detecting and rejecting backdoor samples during the inference stage can effectively alleviate backdoor attacks. Recently, some black-box test-time backdoor sample detection methods have been proposed in the 2D image domain, without any underlying assumptions about the backdoor triggers. However, upon examination, we have found that these detection techniques are not effective for 3D point clouds. As a result, there is a pressing need to bridge the gap for the development of a universal approach that is specifically designed for 3D point clouds.
Shengshan Hu, Wei Liu 0304, Yechao Zhang, Xiaogeng Liu, Xianlong Wang 0001, Leo Yu Zhang, Junhui Hou
ACM Multimedia1
2023 A Four-Pronged Defense Against Byzantine Attacks in Federated Learning
abstract
Federated learning (FL) is a nascent distributed learning paradigm to train a shared global model without violating users' privacy. FL has been shown to be vulnerable to various Byzantine attacks, where malicious participants could independently or collusively upload well-crafted updates to deteriorate the performance of the global model. However, existing defenses could only mitigate part of Byzantine attacks, without providing an all-sided shield for FL. It is difficult to simply combine them as they rely on totally contradictory assumptions.
Shengshan Hu, Jianrong Lu, Longling Zhang, Leo Yu Zhang, Hai Jin 0001
ACM Multimedia2
2023 AdvCLIP: Downstream-agnostic Adversarial Examples in Multimodal Contrastive Learning
abstract
Multimodal contrastive learning aims to train a general-purpose feature extractor, such as CLIP, on vast amounts of raw, unlabeled paired image-text data. This can greatly benefit various complex downstream tasks, including cross-modal image-text retrieval and image classification. Despite its promising prospect, the security issue of cross-modal pre-trained encoder has not been fully explored yet, especially when the pre-trained encoder is publicly available for commercial use.
Ziqi Zhou 0001, Shengshan Hu, Hangtao Zhang, Yechao Zhang, Hai Jin 0001
ACM Multimedia2
2022 Protecting Facial Privacy: Generating Adversarial Identity Masks via Style-robust Makeup Transfer
abstract
While deep face recognition (FR) systems have shown amazing performance in identification and verification, they also arouse privacy concerns for their excessive surveillance on users, especially for public face images widely spread on social networks. Recently, some studies adopt adversarial examples to protect photos from being identified by unauthorized face recognition systems. However, existing methods of generating adversarial face images suffer from many limitations, such as awkward visual, white-box setting, weak transferability, making them difficult to be applied to protect face privacy in reality. In this paper, we propose adversarial makeup transfer GAN (AMT-GAN)11https://github.com/CGCL-codes/AMT-GAN, a novel face protection method aiming at constructing adversarial face images that preserve stronger black-box transferability and better visual quality simultaneously. AMT-GAN leverages generative adversarial networks (GAN) to synthesize adversarial face images with makeup transferred from reference images. In particular, we introduce a new regularization module along with a joint training strategy to reconcile the conflicts between the adversarial noises and the cycle consistence loss in makeup transfer, achieving a desirable balance between the attack strength and visual changes. Extensive experiments verify that compared with state of the arts, AMT-GAN can not only preserve a comfortable visual quality, but also achieve a higher attack success rate over commercial FR APIs, including Face++, Aliyun, and Microsoft.
Shengshan Hu, Xiaogeng Liu, Yechao Zhang, Leo Yu Zhang, Hai Jin 0001
CVPR1
2022 Attention Distraction: Watermark Removal Through Continual Learning with Selective Forgetting
abstract
Fine-tuning attacks are effective in removing the embedded watermarks in deep learning models. However, when the source data is unavailable, it is challenging to just erase the watermark without jeopardizing the model performance. In this context, we introduce Attention Distraction (AD), a novel source data-free watermark removal attack, to make the model selectively forget the embedded watermarks by customizing continual learning. In particular, AD first anchors the model's attention on the main task using some unlabeled data. Then, through continual learning, a small number of lures (randomly selected natural images) that are assigned a new label distract the model's attention away from the watermarks. Experimental results from different datasets and networks corroborate that AD can thoroughly remove the watermark with a small resource budget without compromising the model's performance on the main task, which outperforms the state-of-the-art works.
Leo Yu Zhang, Shengshan Hu, Longxiang Gao, Jun Zhang 0010, Yong Xiang 0001
ICME3
2022 Shielding Federated Learning: Robust Aggregation with Adaptive Client Selection
abstract
Federated learning (FL) enables multiple clients to collaboratively train an accurate global model while protecting clients' data privacy. However, FL is susceptible to Byzantine attacks from malicious participants. Although the problem has gained significant attention, existing defenses have several flaws: the server irrationally chooses malicious clients for aggregation even after they have been detected in previous rounds; the defenses perform ineffectively against sybil attacks or in the heterogeneous data setting. To overcome these issues, we propose MAB-RFL, a new method for robust aggregation in FL. By modelling the client selection as an extended multi-armed bandit (MAB) problem, we propose an adaptive client selection strategy to choose honest clients that are more likely to contribute high-quality updates. We then propose two approaches to identify malicious updates from sybil and non-sybil attacks, based on which rewards for each client selection decision can be accurately evaluated to discourage malicious behaviors. MAB-RFL achieves a satisfying balance between exploration and exploitation on the potential benign clients. Extensive experimental results show that MAB-RFL outperforms existing defenses in three attack scenarios under different percentages of attackers.
Shengshan Hu, Jianrong Lu, Leo Yu Zhang, Hai Jin 0001, Yuanyuan He 0002
IJCAI2
2022 Towards Privacy-Preserving Neural Architecture Search
abstract
Machine learning promotes the continuous development of signal processing in various fields, including network traffic monitoring, EEG classification, face identification, and many more. However, massive user data collected for training deep learning models raises privacy concerns and increases the difficulty of manually adjusting the network structure. To address these issues, we propose a privacy-preserving neural architecture search (PP-NAS) framework based on secure multi-party computation to protect users' data and the model's parameters/hyper-parameters. PP-NAS outsources the NAS task to two non-colluding cloud servers for making full advantage of mixed protocols design. Complement to the existing PP machine learning frameworks, we redesign the secure ReLU and Max-pooling garbled circuits for significantly better efficiency (3 ~ 436 times speed-up). We develop a new alternative to approximate the Softmax function over secret shares, which bypasses the limitation of approximating exponential operations in Softmax while improving accuracy. Extensive analyses and experiments demonstrate PP-NAS's superiority in security, efficiency, and accuracy.
Fuyi Wang, Leo Yu Zhang, Lei Pan 0002, Shengshan Hu, Robin Doss
ISCC4
2022 BadHash: Invisible Backdoor Attacks against Deep Hashing with Clean Label
abstract
Due to its powerful feature learning capability and high efficiency, deep hashing has achieved great success in large-scale image retrieval. Meanwhile, extensive works have demonstrated that deep neural networks (DNNs) are susceptible to adversarial examples, and exploring adversarial attack against deep hashing has attracted many research efforts. Nevertheless, backdoor attack, another famous threat to DNNs, has not been studied for deep hashing yet. Although various backdoor attacks have been proposed in the field of image classification, existing approaches failed to realize a truly imperceptive backdoor attack that enjoys invisible triggers and clean label setting simultaneously, and they cannot meet the intrinsic demand of image retrieval backdoor.
Shengshan Hu, Ziqi Zhou 0001, Yechao Zhang, Leo Yu Zhang, Yifeng Zheng 0001, Yuanyuan He 0002, Hai Jin 0001
ACM Multimedia1
2022 Shielding Federated Learning: Mitigating Byzantine Attacks with Less Constraints
abstract
Federated learning is a newly emerging distributed learning framework that facilitates the collaborative training of a shared global model among distributed participants with their privacy preserved. However, federated learning systems are vulnerable to Byzantine attacks from malicious participants, who can upload carefully crafted local model updates to degrade the quality of the global model and even leave a backdoor. While this problem has received significant attention recently, current defensive schemes heavily rely on various assumptions, such as a fixed Byzantine model, availability of participants' local data, minority attackers, IID data distribution, etc. To relax those constraints, this paper presents Robust-FL, the first prediction-based Byzantine-robust federated learning scheme where none of the assumptions is leveraged. The core idea of the Robust-FL is exploiting historical global model to construct an estimator based on which the local models will be filtered through similarity detection. We then cluster local models to adaptively adjust the acceptable differences between the local models and the estimator such that Byzantine users can be identified. Extensive experiments over different datasets show that our approach achieves the following advantages simultaneously: (i) independence of participants' local data, (ii) tolerance of majority attackers, (iii) generalization to variable Byzantine model.
Jianrong Lu, Shengshan Hu, Junyu Shi, Leo Yu Zhang, Man Zhou 0004, Yifeng Zheng 0001
MSN4
2022 Challenges and Approaches for Mitigating Byzantine Attacks in Federated Learning
abstract
Recently emerged federated learning (FL) is an attractive distributed learning framework in which numerous wireless end-user devices can train a global model with the data remained autochthonous. Compared with the traditional machine learning framework that collects user data for centralized storage, which brings huge communication burden and concerns about data privacy, this approach can not only save the network bandwidth but also protect the data privacy. Despite the promising prospect, Byzantine attack, an intractable threat in conventional distributed network, is discovered to be rather efficacious against FL as well. In this paper, we conduct a comprehensive investigation of the state-of-the-art strategies for defending against Byzantine attacks in FL. We first provide a taxonomy for the existing defense solutions according to the techniques they used, followed by an across-the-board comparison and discussion. Then we propose a new Byzantine attack method called weight attack to defeat those defense schemes, and conduct experiments to demonstrate its threat. The results show that existing defense solutions, although abundant, are still far from fully protecting FL. Finally, we indicate possible countermeasures for weight attack, and highlight several challenges and future research directions for mitigating Byzantine attacks in FL.
Junyu Shi, Shengshan Hu, Jianrong Lu, Leo Yu Zhang
TrustCom3
2022 Evaluating Membership Inference Through Adversarial Robustness
abstract
Abstract The usage of deep learning is being escalated in many applications. Due to its outstanding performance, it is being used in a variety of security and privacy-sensitive areas in addition to conventional applications. One of the key aspects of deep learning efficacy is to have abundant data. This trait leads to the usage of data which can be highly sensitive and private, which in turn causes wariness with regard to deep learning in the general public. Membership inference attacks are considered lethal as they can be used to figure out whether a piece of data belongs to the training dataset or not. This can be problematic with regard to leakage of training data information and its characteristics. To highlight the significance of these types of attacks, we propose an enhanced methodology for membership inference attacks based on adversarial robustness, by adjusting the directions of adversarial perturbations through label smoothing under a white-box setting. We evaluate our proposed method on three datasets: Fashion-MNIST, CIFAR-10 and CIFAR-100. Our experimental results reveal that the performance of our method surpasses that of the existing adversarial robustness-based method when attacking normally trained models. Additionally, through comparing our technique with the state-of-the-art metric-based membership inference methods, our proposed method also shows better performance when attacking adversarially trained models. The code for reproducing the results of this work is available at https://github.com/plll4zzx/Evaluating-Membership-Inference-Through-Adversarial-Robustness.
Zhaoxi Zhang 0001, Leo Yu Zhang, Xufei Zheng, Bilal Hussain Abbasi, Shengshan Hu
Comput. J.5
2022 Optimizing Privacy-Preserving Outsourced Convolutional Neural Network Predictions
abstract
Convolutional neural networks (CNN) is a popular architecture in machine learning for its predictive power, notably in computer vision and medical image analysis. Its great predictive power requires extensive computation, which encourages model owners to host the prediction service in a cloud platform. This article proposes a CNN prediction scheme that preserves privacy in the outsourced setting, i.e., the model-hosting server cannot learn the query, (intermediate) results, and the model. Similar to SecureML (S&P’17), a representative work that provides model privacy, we employ two non-colluding servers with secret sharing and triplet generation to minimize the usage of heavyweight cryptography. We made the following optimizations for both overall latency and accuracy. 1) We adopt asynchronous computation and SIMD for offline triplet generation and parallelizable online computation. 2) As MiniONN (CCS’17) and its improvement by the generic EzPC compiler (EuroS&P’19), we use a garbled circuit for the non-polynomial ReLU activation to keep the same accuracy as the underlying network (instead of approximating it in SecureML prediction). 3) For the pooling in CNN, we employ (linear) average-pooling, which achieves almost the same accuracy as the (non-linear, and hence less efficient) max-pooling exhibited by MiniONN and EzPC. Considering both offline and online costs, our experiments on the MNIST dataset show a latency reduction of$122\times$,$14.63\times$, and$36.69\times$compared to SecureML, MiniONN, and EzPC; and a reduction of communication costs by$1.09\times$,$36.69\times$, and$31.32\times$, respectively. On the CIFAR dataset, our scheme achieves a lower latency by$7.14\times$and$3.48\times$and lower communication costs by$13.88\times$and$77.46\times$when compared with MiniONN and EzPC, respectively.
Sherman S. M. Chow, Shengshan Hu, Yuejing Yan, Chao Shen 0001, Qian Wang 0002
IEEE Trans. Dependable Secur. Comput.3
2021 Feature-Indistinguishable Attack to Circumvent Trapdoor-Enabled Defense
abstract
Deep neural networks (DNNs) are vulnerable to adversarial attacks. A great effort has been directed to developing effective defenses against adversarial attacks and finding vulnerabilities of proposed defenses. A recently proposed defense called Trapdoor-enabled Detection (TeD) deliberately injects trapdoors into DNN models to trap and detect adversarial examples targeting categories protected by TeD. TeD can effectively detect existing state-of-the-art adversarial attacks. In this paper, we propose a novel black-box adversarial attack on TeD, called Feature-Indistinguishable Attack (FIA). It circumvents TeD by crafting adversarial examples indistinguishable in the feature (i.e., neuron-activation) space from benign examples in the target category. To achieve this goal, FIA jointly minimizes the distance to the expectation of feature representations of benign samples in the target category and maximizes the distances to positive adversarial examples generated to query TeD in the preparation phase. A constraint is used to ensure that the feature vector of a generated adversarial example is within the distribution of feature vectors of benign examples in the target category. Our extensive empirical evaluation with different configurations and variants of TeD indicates that our proposed FIA can effectively circumvent TeD. FIA opens a door for developing much more powerful adversarial attacks. The FIA code is available at: https://github.com/CGCL-codes/FeatureIndistinguishableAttack.
Chaoxiang He, Bin B. Zhu, Xiaojing Ma 0002, Hai Jin 0001, Shengshan Hu
CCS5
2021 AdvHash: Set-to-set Targeted Attack on Deep Hashing with One Single Adversarial Patch
abstract
In this paper, we propose AdvHash, the first targeted mismatch attack on deep hashing through adversarial patch. After superimposed with the same adversarial patch, any query image with a chosen label will retrieve a set of irrelevant images with the target label. Concretely, we first formulate a set-to-set problem, where a set of samples are pushed into a predefined clustered area in the Hamming space. Then we obtain a target anchor hash code and transform the attack to a set-to-point optimization. In order to generate a image-agnostic stable adversarial patch for a chosen label more efficiently, we propose a product-based weighted gradient aggregation strategy to dynamically adjust the gradient directions of the patch, by exploiting the Hamming distances between training samples and the target anchor hash code and assigning different weights to discriminatively aggregate gradients. Extensive experiments on benchmark datasets verify that AdvHash is highly effective at attacking two state-of-the-art deep hashing schemes. Our codes are available at: https://github.com/CGCL-codes/AdvHash.
Shengshan Hu, Yechao Zhang, Xiaogeng Liu, Leo Yu Zhang, Hai Jin 0001
ACM Multimedia1
2021 Shielding Federated Learning: A New Attack Approach and Its Defense
abstract
Federated learning (FL) is a newly emerging distributed learning framework that is communication-efficient with user privacy guarantee. Wireless end-user devices can collaboratively train a global model while keeping their local training data private. Nevertheless, recent studies show that FL is highly susceptible to attacks from malicious users since the server cannot directly access and audit the user's local training data. In this work, we identify a new kind of attack surface that is much easier to be carried out while remaining a high attack success rate. By exploiting the inherent flaw of the weight assignment strategy in the standard federated learning process, our attack can bypass the existing defense methods and damage the performance of the global model effectively. We then propose a new density-based detection strategy to defend against such attack by modeling the problem as anomaly detection to effectively detect anomalous updates. Experimental results on two typical datasets, MNIST and CIFAR-10, show that our attack can significantly affect the convergence of the aggregated model and reduce the accuracy of the global model. This holds true even the state-of-the-art defense strategies are deployed, while our newly proposed defense can effectively mitigate such attack.
Jianrong Lu, Shengshan Hu, Leo Yu Zhang, Xiaobing Pei
WCNC3
2021 Augmenting Encrypted Search: A Decentralized Service Realization with Enforced Execution
abstract
Searchable symmetric encryption (SSE) allows the data owner to outsource an encrypted database to a remote server in a private manner while maintaining the ability for selectively search. So far, most existing solutions focus on an honest-but-curious server, while security designs against a malicious server have not drawn enough attention. A few recent works have attempted to construct verifiable SSE that enables the data owner to verify the integrity of search results. Nevertheless, these verification mechanisms are highly dependent on specific SSE schemes, and fail to support complex queries. A general verification mechanism is desired that can be applied to all SSE schemes. In this work, instead of concentrating on a central server, we explore the potential of the smart contract, an emerging blockchain-based decentralized technology, and construct decentralized SSE schemes where the data owner can receive correct search results with assurance without worrying about potential wrongdoings of a malicious server. We study both public and private blockchain environments and propose two designs with a trade-off between security and efficiency. To better support practical applications, the multi-user setting of SSE is further investigated where the data owner allows authenticated users to search keywords in shared documents. We implement prototypes of our two designs and present experiments and evaluations to demonstrate the practicability of our decentralized SSE schemes.
Shengshan Hu, Chengjun Cai, Qian Wang 0002, Cong Wang 0001, Zhibo Wang 0001, Dengpan Ye
IEEE Trans. Dependable Secur. Comput.1
2021 Towards Private and Scalable Cross-Media Retrieval
abstract
Cross-media retrieval (CMR) is an attractive networked application where a server responds to queries with retrieval results of different modalities. Different from traditional information retrieval, CMR relies on a more enriched set of machine learning techniques to produce semantic models projecting multimodal data into a common space. A larger training dataset usually gives more accurate models, leading to a better retrieval result. Despite very promising with potential underpinnings in network analytics and multimedia applications, applying CMR in such contexts also faces severe privacy challenges, due to the fact that various data scattering among multiple parties may be sensitive and not allowed to be shared publicly. Studies jointly considering cross-media analytics, privacy protection, collaborative learning, and distributed networking contexts, are relatively sparse. In this work, we propose the first practical system for privacy-preserving cross-media retrieval by utilizing trusted processors. Our scheme enables secure aggregation of the data from distinct parties, and secure canonical correlation analysis (CCA) over collaborated data to obtain semantic models. Verification mechanisms are designed to defend against active attacks from a malicious adversary. Furthermore, to deal with large data sets, we provide a set of optimization methods to accomodate to limited trusted memory and improve the efficiency of training process in CMR. We consider issues such as data block splitting to manage memory overhead, ordering of operations as well as parameters reuse and release to simplify I/O, and parallel computation to speed up dual operations. Our experiments over both synthetic and real datasets show that our solution is very efficient in practice, outperforms the existing solutions, and performs comparably with the original CMR system.
Shengshan Hu, Leo Yu Zhang, Qian Wang 0002, Zhan Qin, Cong Wang 0001
IEEE Trans. Dependable Secur. Comput.1
2021 Shielding Collaborative Learning: Mitigating Poisoning Attacks Through Client-Side Detection
abstract
Collaborative learning allows multiple clients to train a joint model without sharing their data with each other. Each client performs training locally and then submits the model updates to a central server for aggregation. Since the server has no visibility into the process of generating the updates, collaborative learning is vulnerable to poisoning attacks where a malicious client can generate a poisoned update to introduce backdoor functionality to the joint model. The existing solutions for detecting poisoned updates, however, fail to defend against the recently proposed attacks, especially in the non-IID (independent and identically distributed) setting. In this article, we present a novel defense scheme to detect anomalous updates in both IID and non-IID settings. Our key idea is to realize client-side cross-validation, where each update is evaluated over other clients' local data. The server will adjust the weights of the updates based on the evaluation results when performing aggregation. To adapt to the unbalanced distribution of data in the non-IID setting, a dynamic client allocation mechanism is designed to assign detection tasks to the most suitable clients. During the detection process, we also protect the client-level privacy to prevent malicious clients from knowing the participations of other clients, by integrating differential privacy with our design without degrading the detection performance. Our experimental evaluations on three real-world datasets show that our scheme is significantly robust to two representative poisoning attacks.
Lingchen Zhao, Shengshan Hu, Qian Wang 0002, Jianlin Jiang, Chao Shen 0001, Xiangyang Luo 0001, Pengfei Hu 0001
IEEE Trans. Dependable Secur. Comput.2
2021 BOSSA: A Decentralized System for Proofs of Data Retrievability and Replication
abstract
Proofs of retrievability and proofs of replication are two cryptographic tools that enable a remote server to prove that the users' data has been correctly stored. Nevertheless, the literature either requires the users themselves to perform expensive verification jobs, or relies on a “fully trustworthy” third party auditor (TPA) to execute the public verification. In addition, none of existing solutions consider the underlying incentive issues behind a rational server who is motivated to collect users' data but tries to evade the replication checking in order to save storage resources. In this article, we propose the first decentralized system for proofs of data retrievability and replication-BOSSA, which is incentive-compatible for each party and realizes automated auditing atop off-the-shelf blockchain platforms. We deal with issues such as proof enforcements to catch malicious behaviors, new metrics to measure the contributions, and reward distributions to create a fair reciprocal environment. BOSSA also incorporates privacy-enhancing techniques to prevent decentralized peers (including blockchain nodes) from inferring private information about the outsourced data. Security analysis is presented in the context of integrity, privacy, and reliability. We implement a prototype based on BOSSA leveraging the smart contracts of Ethereum blockchain. Our extensive experimental evaluations demonstrate the practicality of our proposal.
Dian Chen 0004, Haobo Yuan, Shengshan Hu, Qian Wang 0002, Cong Wang 0001
IEEE Trans. Parallel Distributed Syst.3
2018 Searching an Encrypted Cloud Meets Blockchain: A Decentralized, Reliable and Fair Realization
abstract
Enabling search directly over encrypted data is a desirable technique to allow users to effectively utilize encrypted data outsourced to a remote server like cloud service provider. So far, most existing solutions focus on an honest-but-curious server, while security designs against a malicious server have not drawn enough attention. It is not until recently that a few works address the issue of verifiable designs that enable the data owner to verify the integrity of search results. Unfortunately, these verification mechanisms are highly dependent on the specific encrypted search index structures, and fail to support complex queries. There is a lack of a general verification mechanism that can be applied to all search schemes. Moreover, no effective countermeasures (e.g., punishing the cheater) are available when an unfaithful server is detected. In this work, we explore the potential of smart contract in Ethereum, an emerging blockchain-based decentralized technology that provides a new paradigm for trusted and transparent computing. By replacing the central server with a carefully-designed smart contract, we construct a decentralized privacy-preserving search scheme where the data owner can receive correct search results with assurance and without worrying about potential wrongdoings of a malicious server. To better support practical applications, we introduce fairness to our scheme by designing a new smart contract for a financially-fair search construction, in which every participant (especially in the multiuser setting) is treated equally and incentivized to conform to correct computations. In this way, an honest party can always gain what he deserves while a malicious one gets nothing. Finally, we implement a prototype of our construction and deploy it to a locally simulated network and an official Ethereum test network, respectively. The extensive experiments and evaluations demonstrate the practicability of our decentralized search scheme over encrypted data.
Shengshan Hu, Chengjun Cai, Qian Wang 0002, Cong Wang 0001, Xiangyang Luo 0001, Kui Ren 0001
INFOCOM1
2018 InPrivate Digging: Enabling Tree-based Distributed Data Mining with Differential Privacy
abstract
Data mining has heralded the major breakthrough in data analysis, serving as a “super cruncher” to discover hidden information and valuable knowledge in big data systems. For many applications, the collection of big data usually involves various parties who are interested in pooling their private data sets together to jointly train machine-learning models that yield more accurate prediction results. However, data owners may not be willing to disclose their own data due to privacy concerns, making it imperative to provide privacy guarantee in collaborative data mining over distributed data sets. In this paper, we focus on tree-based data mining. To begin with, we design novel privacy-preserving schemes for two most common tasks: regression and binary classification, where individual data owners can perform training locally in a differentially private manner. Then, for the first time, we design and implement a privacy-preserving system for gradient boosting decision tree (GBDT), where different regression trees trained by multiple data owners can be securely aggregated into an ensemble. We conduct extensive experiments to evaluate the performance of our system on multiple real-world data sets. The results demonstrate that our system can provide a strong privacy protection for individual data owners while maintaining the prediction accuracy of the original trained model.
Lingchen Zhao, Lihao Ni, Shengshan Hu, Yanjiao Chen, Pan Zhou 0001, Fu Xiao 0001
INFOCOM3
2018 Outsourced Biometric Identification With Privacy
abstract
Biometric identification typically scans a large-scale database of biometric records for finding a close enough match of an individual. This paper investigates how to outsource this computationally expensive scanning while protecting the privacy of both the database and the computation. Exploiting the inherent structures of biometric data and the properties of identification operations, we first present a privacy-preserving biometric identification scheme which uses a single server. We then consider its extensions in the two-server model. It achieves a higher level of privacy than our single-server solution assuming two servers are not colluding. Apart from somewhat homomorphic encryption, our second scheme uses batched protocols for secure shuffling and minimum selection. Our experiments on both synthetic and real data sets show that our solutions outperform existing schemes while preserving privacy.
Shengshan Hu, Qian Wang 0002, Sherman S. M. Chow, Minxin Du
IEEE Trans. Inf. Forensics Secur.1
2017 Learning privately: Privacy-preserving canonical correlation analysis for cross-media retrieval
abstract
A massive explosion of various types of data has been triggered in the “Big Data” era. In big data systems, machine learning plays an important role due to its effectiveness in discovering hidden information and valuable knowledge. Data privacy, however, becomes an unavoidable concern since big data usually involve multiple organizations, e.g., different healthcare systems and hospitals, who are not in the same trust domain and may be reluctant to share their data publicly. Applying traditional cryptographic tools is a straightforward approach to protect sensitive information, but it often renders learning algorithms useless inevitably. In this work, we, for the first time, propose a novel privacy-preserving scheme for canonical correlation analysis (CCA), which is a well-known learning technique and has been widely used in cross-media retrieval system. We first develop a library of building blocks to support various arithmetics over encrypted real numbers by leveraging additively homomorphic encryption and garbled circuits. Then we encrypt private data by randomly splitting the numerical data, formalize CCA problem and reduce it to a symmetric eigenvalue problem by designing new protocols for privacy-preserving QR decomposition. Finally, we solve all the eigenvalues and the corresponding eigenvectors by running Newton-Raphson method and inverse power method over the ciphertext domain. We carefully analyze the security and extensively evaluate the effectiveness of our design. The results show that our scheme is practically secure, incurs negligible errors compared with performing CCA in the clear and performs comparably in cross-media retrieval systems.
Qian Wang 0002, Shengshan Hu, Minxin Du, Jingjun Wang, Kui Ren 0001
INFOCOM2
2016 SecHOG: Privacy-Preserving Outsourcing Computation of Histogram of Oriented Gradients in the Cloud
abstract
Abundant multimedia data generated in our daily life has intrigued a variety of very important and useful real-world applications such as object detection and recognition etc. Accompany with these applications, many popular feature descriptors have been developed, e.g., SIFT, SURF and HOG. Manipulating massive multimedia data locally, however, is a storage and computation intensive task, especially for resource-constrained clients. In this work, we focus on exploring how to securely outsource the famous feature extraction algorithm--Histogram of Oriented Gradients (HOG) to untrusted cloud servers, without revealing the data owner's private information. For the first time, we investigate this secure outsourcing computation problem under two different models and accordingly propose two novel privacy-preserving HOG outsourcing protocols, by efficiently encrypting image data by somewhat homomorphic encryption (SHE) integrated with single-instruction multiple-data (SIMD), designing a new batched secure comparison protocol, and carefully redesigning every step of HOG to adapt it to the ciphertext domain. Explicit Security and effectiveness analysis are presented to show that our protocols are practically-secure and can approximate well the performance of the original HOG executed in the plaintext domain. Our extensive experimental evaluations further demonstrate that our solutions achieve high efficiency and perform comparably to the original HOG when being applied to human detection.
Qian Wang 0002, Jingjun Wang, Shengshan Hu, Qin Zou 0001, Kui Ren 0001
AsiaCCS3
2016 Secure Surfing: Privacy-Preserving Speeded-Up Robust Feature Extractor
abstract
Large-scale multimedia data are being exponentially generated, stored and processed continuously nowadays. Along with the data explosion, the data owner is highly motivated to outsource his/her huge amount of data storage and computation-expensive processing jobs to the cloud by leveraging its abundant resources for cost reduction and flexibility. Despite the fascinating advantages, security and privacy concerns are the primary obstacles that prevent the wide adoption of this promising information technology paradigm. In this work, we aim at outsourcing Speeded-up Robust Features (SURF), a widely-used feature extraction algorithm, to the intrinsically untrusted cloud, while protecting data owner's private information on the outsourced image data. We, for the first time, propose a practical privacy-preserving outsoucing scheme for SURF that can preserve its key characteristics in terms of distinctiveness and robustness. By randomly splitting the original image data and distributing the encrypted data shares to two independent cloud servers, we first design two novel efficient protocols for secure multiplication and comparison by leveraging somewhat homomorphic encryption (SHE) and single-instruction multiple-data (SIMD). We then carefully tune every step of the original SURF to adapt it to the ciphertext domain. A thorough theoretical analysis of effectiveness and security shows that our scheme is practically secure and approximates well the performance of the original SURF executed in the plaintext domain. Extensive experiments are also conducted over real-world image datasets to show that our scheme outperforms the existing solution and indeed performs comparably to the original SURF in preserving its various characteristics including image scale invariance, rotation invariance and robust matching across 3D viewpoint change etc.
Qian Wang 0002, Shengshan Hu, Jingjun Wang, Kui Ren 0001
ICDCS2
2016 Catch me in the dark: Effective privacy-preserving outsourcing of feature extractions over image data
abstract
Advances in cloud computing have greatly motivated data owners to outsource their huge amount of personal multimedia data and/or computationally expensive tasks onto the semi-trusted cloud by leveraging its abundant resources for cost saving and flexibility. From the privacy perspective, however, the outsourced multimedia data and its originated applications may reveal the data owner's private information, such as the personal identity, locations or even financial profiles. This observation has recently aroused new research interest on privacy-preserving computations over outsourced multimedia data. In this paper, we propose an effective privacy-preserving computation outsourcing protocol for the prevailing scale-invariant feature transform (SIFT) over massive encrypted image data. We first show that previous solutions to this problem have either efficiency/security or practicality issues, and none can well preserve the important characteristics of the original SIFT in terms of distinctiveness and robustness. We for the first time present a new privacy-preserving outsourcing protocol for SIFT with the preservation of its key characteristics, by randomly splitting the original image data, carefully distributing the feature extraction computations to two independent cloud servers and further leveraging the garbled circuit for secure keypoints comparisons. We both carefully analyze and extensively evaluate the security and effectiveness of our design. The results show that our solution is practically secure, outperforms the state-of-the-art and performs comparably to the original SIFT in terms of various characteristics, including rotation invariance, image scale invariance, robust matching across affine distortion and change in 3D viewpoint.
Qian Wang 0002, Shengshan Hu, Kui Ren 0001, Jingjun Wang, Zhibo Wang 0001, Minxin Du
INFOCOM2
2016 Securing SIFT: Privacy-Preserving Outsourcing Computation of Feature Extractions Over Encrypted Image Data
abstract
Advances in cloud computing have greatly motivated data owners to outsource their huge amount of personal multimedia data and/or computationally expensive tasks onto the cloud by leveraging its abundant resources for cost saving and flexibility. Despite the tremendous benefits, the outsourced multimedia data and its originated applications may reveal the data owner's private information, such as the personal identity, locations, or even financial profiles. This observation has recently aroused new research interest on privacy-preserving computations over outsourced multimedia data. In this paper, we propose an effective and practical privacy-preserving computation outsourcing protocol for the prevailing scale-invariant feature transform (SIFT) over massive encrypted image data. We first show that the previous solutions to this problem have either efficiency/security or practicality issues, and none can well preserve the important characteristics of the original SIFT in terms of distinctiveness and robustness. We then present a new scheme design that achieves efficiency and security requirements simultaneously with the preservation of its key characteristics, by randomly splitting the original image data, designing two novel efficient protocols for secure multiplication and comparison, and carefully distributing the feature extraction computations onto two independent cloud servers. We both carefully analyze and extensively evaluate the security and effectiveness of our design. The results show that our solution is practically secure, outperforms the state-of-the-art, and performs comparably with the original SIFT in terms of various characteristics, including rotation invariance, image scale invariance, robust matching across affine distortion, and addition of noise and change in 3D viewpoint and illumination.
Shengshan Hu, Qian Wang 0002, Jingjun Wang, Zhan Qin, Kui Ren 0001
IEEE Trans. Image Process.1
2015 CloudBI: Practical Privacy-Preserving Outsourcing of Biometric Identification in the Cloud
Qian Wang 0002, Shengshan Hu, Kui Ren 0001, Meiqi He, Minxin Du, Zhibo Wang 0001
ESORICS (2)2