EDBT 2026 Demo / reviewers in the wild / expert
Hao Li 0092
dblp:17/5705-92
· DBLP profile ↗
13ranked-venue papers
6as first author
10since 2021 · last 2026
0009-0006-3815-6221ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 3 first-author · 6 since 2021Databases, data management, data science and information retrieval · 2Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Model Hijacking Attack in Federated LearningabstractMachine learning (ML), driven by prominent paradigms such as centralized and federated learning, has made significant progress in various critical applications. However, its remarkable success has been accompanied by various attacks. Recently, the model hijacking attack has shown that ML models can be hijacked to execute tasks different from their original tasks, which increases both accountability and parasitic computational risks. Nevertheless, thus far, this attack has only focused on centralized learning. In this work, we broaden the scope of this attack to the federated learning domain, where multiple clients collaboratively train a global model without sharing their data. Specifically, we present the first-of-its-kind hijacking attack against the global model in federated learning, namely HijackFL. The adversary aims to force the global model to perform a different task (called hijacking task) from its original task without the server or benign client noticing. To accomplish this, unlike existing methods that use data poisoning to modify the target model’s parameters, HijackFL searches for pixel-level perturbations based on their local model (without modifications) to align hijacking samples with the original ones in the feature space. When performing the hijacking task, the adversary applies these perturbations to the hijacking samples, compelling the global model to identify them as original ones and predict them accordingly. Extensive experiments demonstrate HijackFL significantly outperforms baselines, e.g., 92.75% vs. 10%. We further investigate the factors that affect its performance and discuss possible defenses to mitigate its impact. Zheng Li 0023, Ruichuan Chen, Paarijaat Aditya, Istemi Ekin Akkus, Manohar Vanga, Min Zhang 0043, Hao Li 0092, Yang Zhang 0016 |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2025 | Enhanced Label-Only Membership Inference Attacks with Fewer Queries
Hao Li 0092, Zheng Li 0023, Yutong Ye 0002, Min Zhang 0043, Dengguo Feng, Yang Zhang 0016 |
USENIX Security Symposium | 1 |
| 2025 | RAG-leaks: difficulty-calibrated membership inference attacks on retrieval-augmented generation
Guangshuo Wang, Hao Li 0092, Min Zhang 0043, Dengguo Feng |
Sci. China Inf. Sci. | 3 |
| 2025 | CSFuzzer: A grey-box fuzzer for network protocol using context-aware state feedback
Xiangpu Song, Yingpei Zeng, Jianliang Wu 0002, Hao Li 0092, Chaoshun Zuo, Qingchuan Zhao, Shanqing Guo |
Comput. Secur. | 4 |
| 2025 | Safe Driving Adversarial Trajectory Can Mislead: Toward More Stealthy Adversarial Attack Against Autonomous Driving Prediction ModuleabstractThe prediction module, powered by deep learning models, constitutes a fundamental component of high-level Autonomous Vehicles (AVs). Given the direct influence of the module’s prediction accuracy on AV driving behavior, ensuring its security is paramount. However, limited studies have explored the adversarial robustness of the prediction modules. Furthermore, existing methods still generate adversarial trajectories that deviate significantly from human driving behavior. These deviations can be easily identified as hazardous by AVs’ anomaly detection models and thus cannot effectively evaluate and reflect the robustness of the prediction modules. To bridge this gap, we propose a stealthy and more effective optimization-based attack method. Specifically, we reformulate the optimization problem using Lagrangian relaxation and design a Frenet-based objective function along with a distinct constraint space. We conduct extensive evaluations on 2 popular prediction models and 2 benchmark datasets. Our results show that our attack is highly effective, with over 87% attack success rates, outperforming all baseline attacks. Moreover, our attack method significantly improves the stealthiness of adversarial trajectories while guaranteeing adherence to physical constraints. Our attack is also found robust to noise from upstream modules, transferable across trajectory prediction models, and high realizability. Lastly, to verify its effectiveness in real-world applications, we conduct further simulation evaluations using a production-grade simulator. These simulations reveal that the adversarial trajectory we created could convincingly induce autonomous vehicles (AVs) to initiate hard braking. Yingkai Dong, Li Wang 0120, Zheng Li 0023, Hao Li 0092, Peng Tang 0002, Chengyu Hu 0001, Shanqing Guo |
ACM Trans. Priv. Secur. | 4 |
| 2024 | SeqMIA: Sequential-Metric Based Membership Inference AttackabstractMost existing membership inference attacks (MIAs) utilize metrics (e.g., loss) calculated on the model's final state, while recent advanced attacks leverage metrics computed at various stages, including both intermediate and final stages, throughout the model training. Nevertheless, these attacks often process multiple intermediate states of the metric independently, ignoring their time-dependent patterns. Consequently, they struggle to effectively distinguish between members and non-members who exhibit similar metric values, particularly resulting in a high false-positive rate. Hao Li 0092, Zheng Li 0023, Chengrui Hu, Yutong Ye 0002, Min Zhang 0043, Dengguo Feng, Yang Zhang 0016 |
CCS | 1 |
| 2024 | TULAM: trajectory-user linking via attention mechanism
Hao Li 0092, Shuyu Cao, Min Zhang 0043, Dengguo Feng |
Sci. China Inf. Sci. | 1 |
| 2023 | Demystifying Decentralized Matrix Communication Network: Ecosystem and SecurityabstractWith the emergence of Web3, decentralized network protocol technologies have been vigorously developed. As a pioneer for decentralized real-time communication systems, Matrix is an open standard based on a federation specification protocol. Anyone can set up a self-hosted homeserver to participate in the global Matrix network and communicate with others in chat rooms. In this paper, we conduct the first in-depth measurement and exploratory research on Matrix’s ecosystem and security. We designed and implemented several investigation techniques to empirically delve into Matrix federation from various aspects (homeservers, rooms, and users). In the end, we identified a number of interesting findings and potential vulnerabilities, including anti-decentralization phenomena, cybersecurity threats in homeservers, and the confidentiality of encrypted rooms being compromised. Hao Li 0092, Yanbo Wu, Ronghong Huang, Xianghang Mi, Chengyu Hu 0001, Shanqing Guo |
ICPADS | 1 |
| 2023 | An Empirical Study of Storj DCS: Ecosystem, Performance, and SecurityabstractIn the age of pervasive computing, traditionally centralized cloud storage (CCS) services may not fit in well due to their centralized architecture, limited worldwide availability, high expense, and security and privacy concerns. To address these issues, decentralized cloud storage (DCS) services emerged recently. However, previous works focus on analyzing the technical design of DCS services, e.g., their incentive mechanisms. Little is known regarding how well these DCS services work in real-world operations. In this paper, we fill this gap by providing the first empirical measurement of Storj, one of the most extensive in-operation decentralized cloud storage services, focusing on its ecosystem, performance, and security implications. Our study is made possible through multiple measurement techniques to automatically capture storage nodes, profile Storj's quality of service, understand co-located network threats, and evaluate potential attacks in a simulated environment. Leveraging these techniques, a set of insightful findings have been distilled. Particularly, we have observed over 32K storage nodes as well as 155K unique node IP addresses, which are widely distributed in 122 countries, 2,418 ASNs, and 205 /8 IPv4 prefixes. Regarding performance, storage customers located in Europe or the United States tend to enjoy a better storage performance than those in Asia-Pacific, likely due to the imbalanced distribution of storage nodes in different regions. Lastly, what is concerning is that 4.48% of IPs of storage nodes were found to have been associated with various malicious activities, especially botnets and cryptomining. Another vulnerability is that a malicious storage node could exploit multiple channels to boost its storage reputation while demoting that of benign nodes. Hao Li 0092, Xianghang Mi, Yanzhi Dou, Shanqing Guo |
IWQoS | 1 |
| 2021 | TranFuzz: An Ensemble Black-Box Attack Framework Based on Domain Adaptation and Fuzzing
Hao Li 0092, Shanqing Guo, Peng Tang 0002, Chengyu Hu 0001 |
ICICS (1) | 1 |
| 2019 | Multiple Privacy Regimes Mechanism for Local Differential Privacy
Yutong Ye 0002, Min Zhang 0043, Dengguo Feng, Hao Li 0092, Jialin Chi |
DASFAA (2) | 4 |
| 2018 | Privacy-Aware Risk-Adaptive Access Control in Health Information Systems using Topic ModelsabstractTraditional role-based access control fails to meet the privacy requirements for patient data in medical systems, as it is infeasible for policy makers to foresee what information doctors may need for diagnosis and treatment in various situations. The universal practice in hospitals is to grant doctors unlimited access, which in turn increases the risk of breaching patient privacy. In this paper, we propose a dynamic risk-adaptive access control model for health IT systems by taking into consideration the relationships between data and access behaviors. By training topic models to portray individual and group-level access behaviors, we quantify the risk for each user over a certain period of time. Malicious users are supposed to get higher risk scores than honest users due to improper requests. Thus their further access would be denied under our access control scheme. The topic model and risk scores are periodically updated to advance the self-adaptability of the system. Experimental results have shown that our solution could effectively distinguish malicious doctors even if they deliberately conceal the misconducts. Hao Li 0092, Min Zhang 0043, Zhiquan Lv |
SACMAT | 2 |
| 2014 | A Novel Privacy-Preserving Group Matching Scheme in Social Networks
Jialin Chi, Zhiquan Lv, Min Zhang 0043, Hao Li 0092, Cheng Hong 0001, Dengguo Feng |
WAIM | 4 |