Shuai Yuan 0009

dblp:19/1243-9 · DBLP profile ↗
← Back
14ranked-venue papers
7as first author
14since 2021 · last 2026
0009-0008-6575-5101ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 7 · 2 first-author · 7 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 4 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 MartDE: A Privacy-Preserving and Cost-Efficient Evaluation Framework for Data Marketplaces
abstract
The development of machine learning models increasingly relies on high-quality data that resides in private domains. To enable secure and value-driven data exchange under strict privacy regulations, federated learning (FL) has emerged as a key primitive by enabling the trading of model utilities instead of raw data. Among existing solutions, martFL (CCS 2023) represents the state-of-the-art FL-based data marketplace architecture, integrating privacy-preserving model evaluation and verifiable trading protocols to enable robust and fair model utility trading without revealing raw data. Despite its strengths, martFL suffers from critical weaknesses at the evaluation layer, including plaintext score exposure and unverifiable and manipulable participant selection. To address these challenges, we propose MartDE, a dedicated evaluation framework that builds model-centric data marketplaces with robust, privacy-preserving, and verifiable mechanisms. MartDE introduces encrypted utility scoring with client-side decryption to preserve score confidentiality, formally bounded anomaly filtering, adaptive participant selection based on global model performance, and commitment-based verification to ensure consistency between declared and evaluated scores and selection verification. We implement MartDE and evaluate it across diverse datasets and adversarial conditions. Results show that MartDE achieves superior accuracy, robustness, and cost-efficiency, providing a strong foundation for secure and trustworthy utility-driven data marketplaces.
Xinyuan Qian 0002, Haoyong Wang, Hangcheng Cao, Shuai Yuan 0009, Senkang Hu, Qingchuan Zhao, Hongwei Li 0001, Guowen Xu
AAAI4
2026 No Trespassing: Ground-View Adversarial Patches for Privacy-Aware Management in COTS Robot Vacuum Cleaner
abstract
Robot vacuum cleaners (RVCs) with autonomous navigation and decision-making capabilities have become an integral part of modern homes. During their operations, these devices may inadvertently enter privacy-sensitive areas, leading to potential privacy breaches. However, existing defense methods risk exposing the location of private areas, require root privileges, or are designed for infrared sensors that are ineffective for camera-based RVCs. To overcome these limitations, we propose a novel solution, a ground-view adversarial patch named GPatch, preventing RVCs from entering privacy-sensitive areas. Users only need to place GPatch at the entrance of restricted areas to prevent an RVC's unauthorized access, while also providing a warning to unauthorized individuals. We evaluate GPatch in realworld environments with an average success rate of 87.27%, and experimental results demonstrate its effectiveness, robustness, and transferability, making it a practical, user-friendly, and reliable solution for safeguarding privacy in home environments.
Shuai Yuan 0009, Guowen Xu, Hongwei Li 0001, Rui Zhang 0090, Hangcheng Cao, Xinyuan Qian 0002, Tao Ni 0003, Qingchuan Zhao, Yuguang Fang
IEEE Trans. Dependable Secur. Comput.1
2026 FIGhost: Fluorescent Ink-Based Stealthy and Flexible Backdoor Attacks on Physical Traffic Sign Recognition
abstract
Traffic sign recognition (TSR) systems are crucial for autonomous driving but are vulnerable to backdoor attacks. Existing physical backdoor attacks either lack stealth, provide inflexible attack control, or ignore emerging Vision-Large-Language-Models (VLMs). In this paper, we introduce FIGhost, the first physical-world backdoor attack leveraging fluorescent ink as triggers. Fluorescent triggers are invisible under normal conditions and activated stealthily by ultraviolet light, providing superior stealthiness, flexibility, and untraceability. Inspired by real-world graffiti, we derive realistic trigger shapes and enhance their robustness via an interpolation-based fluorescence simulation algorithm. Furthermore, we develop an automated backdoor sample generation method to support three attack objectives. Extensive evaluations in the physical world demonstrate FIGhost's effectiveness against state-of-the-art detectors and VLMs, maintaining robustness under environmental variations and effectively evading existing defenses.
Shuai Yuan 0009, Guowen Xu, Hongwei Li 0001, Rui Zhang 0090, Xinyuan Qian 0002, Hangcheng Cao, Qingchuan Zhao
IEEE Trans. Dependable Secur. Comput.1
2025 BadComp: Backdoor Attack against Object Detection using Image Compression Operation
abstract
Currently, object detection models have achieved widespread success in real-world applications, yet remain vulnerable to backdoor attacks. Existing backdoor methods often suffer from poor stealthiness or can be easily mitigated by standard image processing techniques. In this paper, we propose a novel stealthy backdoor attack to dynamically compress target object-oriented data for backdoor embedding. By modifying the model, a high-frequency feature extraction module is added, so the model learns frequency-domain feature representations of compressed samples and achieve three attack objectives. Extensive experimental results demonstrate the effectiveness and robustness of the proposed method, achieving attack success rates exceeding 90% across three detectors.
Xi Nie, Hongwei Li 0001, Wenbo Jiang 0001, Shuai Yuan 0009, Wenshu Fan, Jian Xiong 0007
GLOBECOM4
2025 Stealthy Physical Backdoor Attacks Against Traffic Sign Recognition Systems
abstract
Recent advancements in deep learning have led to remarkable progress in autonomous driving technology, with deep neural network (DNN)-based traffic sign recognition systems (TSRS) playing a crucial role. However, recent studies indicate that TSRS are vulnerable to backdoor attacks, where the backdoor TSRS behaves normally on clean traffic signs but consistently misclassifies backdoor-triggered traffic signs into a designated target class. Notably, while backdoor attacks in the digital domain are effective, their effectiveness may diminish in the physical world due to quality degradation during image transmission. Existing physical backdoor attacks typically rely on specific stickers or transformations as backdoor triggers, which are not stealthy and natural enough in the physical world. To address these limitations, we propose two stealthy physical backdoor attacks against DNN-based TSRS from two different perspectives. On the one hand, we utilize the natural phenomenon of chipped paints on traffic signs as the backdoor trigger. Specifically, we develop an automatic traffic sign segmentation algorithm to identify the edges of the target sign and simulate chipped paint to create poisoned samples. On the other hand, instead of manipulating the target traffic sign, we use the specific filter lens (attached to the in-vehicle camera) as the backdoor trigger, where the parameters of the filter lens are optimized by the Genetic Algorithm (GA). Extensive experiments conducted on the GTSRB and TSRD datasets demonstrate the effectiveness of our proposed backdoor attacks in both digital and physical environments.
Wenbo Jiang 0001, Hongwei Li 0001, Shuai Yuan 0009, Rui Zhang 0086, Qiyang Song
ICC4
2025 Adversarial Attack with Controllable Transferability
abstract
Machine Learning as a Service (MLaaS) providers often promote the robustness of their models as a selling point for their API services. Existing methods commonly evaluate the robustness of Deep Neural Networks (DNNs) by generating highly transferable adversarial examples However, dishonest MLaaS providers may deceive consumers by falsely exaggerating the robustness of their models. In this paper, contrary to enhancing the transferability of adversarial examples, we attempt to craft adversarial examples that fail under a shielded model. In other words, ensuring that the adversarial examples fail to attack a shielded model but successfully attack other models, which we refer to as controllable transferability. To achieve this goal, we propose the Controllable Transferability Method (CTM), a framework that generates adversarial examples with controllable transferability. CTM involves generating transferable adversarial examples and refining their transferability using gradient antagonism. Experimental results demonstrate that CTM achieves high transferability across models, with controlled adversarial effects on selected models.
Jian Xiong 0007, Hongwei Li 0001, Wenbo Jiang 0001, Wenshu Fan, Shuai Yuan 0009
ICC5
2025 Omni-Angle Assault: An Invisible and Powerful Physical Adversarial Attack on Face Recognition
abstract
Deep learning models employed in face recognition (FR) systems have been shown to be vulnerable to physical adversarial attacks through various modalities, including patches, projections, and infrared radiation. However, existing adversarial examples targeting FR systems often suffer from issues such as conspicuousness, limited effectiveness, and insufficient robustness. To address these challenges, we propose a novel approach for adversarial face generation, UVHat, which utilizes ultraviolet (UV) emitters mounted on a hat to enable invisible and potent attacks in black-box settings. Specifically, UVHat simulates UV light sources via video interpolation and models the positions of these light sources on a curved surface, specifically the human head in our study. To optimize attack performance, UVHat integrates a reinforcement learning-based optimization strategy, which explores a vast parameter search space, encompassing factors such as shooting distance, power, and wavelength. Extensive experimental evaluations validate that UVHat substantially improves the attack success rate in black-box settings, enabling adversarial attacks from multiple angles with enhanced robustness.
Shuai Yuan 0009, Hongwei Li 0001, Rui Zhang 0090, Hangcheng Cao, Wenbo Jiang 0001, Tao Ni 0003, Wenshu Fan, Qingchuan Zhao, Guowen Xu
ICML1
2025 The Fluorescent Veil: A Stealthy and Effective Physical Adversarial Patch Against Traffic Sign Recognition
abstract
Recently, traffic sign recognition (TSR) systems have become a prominent target for physical adversarial attacks. These attacks typically rely on conspicuous stickers and projections, or using invisible light and acoustic signals that can be easily blocked. In this paper, we introduce a novel attack medium, i.e., fluorescent ink, to design a stealthy and effective physical adversarial patch, namely FIPatch, to advance the state-of-the-art. Specifically, we first model the fluorescence effect in the digital domain to identify the optimal attack settings, which guide the real-world fluorescence parameters. By applying a carefully designed fluorescence perturbation to the target sign, the attacker can later trigger a fluorescent effect using invisible ultraviolet light, causing the TSR system to misclassify the sign and potentially leading to traffic accidents. We conducted a comprehensive evaluation to investigate the effectiveness of FIPatch, which shows a success rate of 98.31% in low-light conditions. Furthermore, our attack successfully bypasses five popular defenses and achieves a success rate of 96.72%.
Shuai Yuan 0009, Xingshuo Han, Hongwei Li 0001, Guowen Xu, Wenbo Jiang 0001, Tao Ni 0003, Qingchuan Zhao, Yuguang Fang
NeurIPS1
2025 Lightweight distributed deep learning on compressive measurements for internet of things
Guiqiang Hu, Shuai Yuan 0009
Eng. Appl. Artif. Intell.5
2024 Efficient and Privacy-Preserving Outsourcing of Gradient Boosting Decision Tree Inference
abstract
Recently, outsourcing machine learning inference services to the cloud has become increasingly popular. The inference process, however, remains an open question onhow to effectively protect the model owner's proprietary model, the user's sensitive data, and prediction results. In this work, we propose an efficient and comprehensive privacy-preserving framework for outsourcing Gradient Boosting Decision Tree (GBDT) inference utilizing pseudorandom function and additively homomorphic encryption. Specifically, we first design a transformation method for GBDT to protect the node and structure privacy of the owner's model. On top of the protected model, we further propose customized comparison and random trees permutation protocols, which substantially boost the computation and reduce the communication cost of the outsourcing inference, while preventing the user from inferring privacy associated with GBDT. Besides, we provide rigorous security analysis, and extensive experiments on 7 real-world datasets and various models demonstrating that our scheme achieves up to 36 times less runtime and 69 times less communication compared to the state-of-the-arts.
Shuai Yuan 0009, Hongwei Li 0001, Xinyuan Qian 0002, Meng Hao 0001, Yixiao Zhai, Guowen Xu
IEEE Trans. Serv. Comput.1
2023 Toward Efficient and End-to-End Privacy-Preserving Distributed Gradient Boosting Decision Trees
abstract
Gradient Boosting Decision Trees (GBDTs) are popular machine learning models due to its simplicity, effectiveness, and interpretability. Recently, to alleviate serious privacy leakages in conventional centralized methods, researchers have proposed several privacy-preserving distributed GBDT solutions. However, those approaches still suffer from either insufficient privacy protection or significant runtime and communication overhead. In this paper, we propose an efficient and end-to-end privacy-preserving distributed GBDT framework, called PPD-GBDT, which uses differential privacy, polynomial approximation, and fully homomorphic encryption to achieve comprehensive privacy protection. Specifically, during the boosting phase, we design a novel model preparation method to improve the efficiency of prediction with acceptably slight accuracy/RMSE loss while preventing data owners' corruption. On the other hand, for the prediction phase, we propose a customized secure prediction method, which effectively prevents the malicious server from stealing private information. Besides, we conduct extensive experiments on six datasets and compare with three prior schemes. Evaluation results show that our privacy-preserving scheme achieves lower runtime and up to 40× less communication overhead compared to the state-of-the-arts.
Shuai Yuan 0009, Hongwei Li 0001, Xinyuan Qian 0002, Meng Hao 0001, Yixiao Zhai
ICC1
2022 CryptoFE: Practical and Privacy-Preserving Federated Learning via Functional Encryption
abstract
Cloud-based services for federated learning has received widespread attention for its ability to collaboratively train a model without collecting users' local data. Although there are existing methods such as homomorphic encryption and secure multi-party computation to address the privacy issues associated with the model parameter exchanging during aggregation, these methods will inevitably lead to huge communication overheads or slow down the training time. Functional encryption (FE) is considered as a new approach to address privacy-preserving federated learning probelms, but the only known FE solution has severe security issues such as leaking master private key, and is impractical. Thus, in this paper, we propose CryptoFE, a cloud-based privacy-preserving federated learning aggregation scheme based on FE. Compared with the only existing FE solution, CryptoFE is efficient in aggregation phase, especially when a high model precision is required, and provides formal privacy guarantees for users' gradients. The experiments with real-world data demonstrate the efficeint performance of our proposed scheme.
Xinyuan Qian 0002, Hongwei Li 0001, Meng Hao 0001, Shuai Yuan 0009, Song Guo 0001
GLOBECOM4
2021 Towards Lightweight and Efficient Distributed Intrusion Detection Framework
abstract
Federated learning (FL), as a promising distributed learning paradigm, has put many efforts into distributed intrusion detection systems (IDS), for defending against various malicious attacks, such as SQL injection and DDoS attacks. Compared with traditional IDS based on centralized deep learning (DL), FL-based solutions require not to share users' raw data while yielding better detection performance. However, state-of-the-art FL-based methods still suffer from two key limitations: 1) insufficient detection performance on non-independent and identically distributed (non-IID) data, and 2) high communication and computational overheads due to the utilization of large-scale neural network models. In this paper, we propose a lightweight collaborative intrusion detection framework, called CoLGBM, the first of its kind in the regime of decentralized IDS, where decision tree and light gradient boosting machine (LGBM) are combined for constructing the detection scheme. The main insight is that through combining user-trained decision trees (each user's decision tree is derived from its own data with unique distribution), our framework can perform effectively on non-IID data while working efficiently for handling enormous samples. Compared with the current FL-based methods, our CoLGBM achieves higher accuracy and lower overhead on both IID and non-IID data. Extensive experiment results demonstrate our scheme with high-level performance.
Shuai Yuan 0009, Hongwei Li 0001, Rui Zhang 0086, Meng Hao 0001, Rongxing Lu
GLOBECOM1
2021 One radish, One hole: Specific adversarial training for enhancing neural network's robustness
Hongwei Li 0001, Guowen Xu, Shuai Yuan 0009
Peer-to-Peer Netw. Appl.4