EDBT 2026 Demo / reviewers in the wild / expert
Huadi Zheng
dblp:198/9507
· DBLP profile ↗
21ranked-venue papers
5as first author
16since 2021 · last 2026
0000-0003-1224-9885ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 8 · 1 first-author · 6 since 2021Security and privacy · 8 · 3 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 2 first-author · 6 since 2021Computer networks · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Class-feature Watermark: A Resilient Black-box Watermark Against Model Extraction AttacksabstractMachine learning models constitute valuable intellectual property, yet remain vulnerable to model extraction attacks (MEA), where adversaries replicate their functionality through black-box queries. Model watermarking counters MEAs by embedding forensic markers for ownership verification. Current black-box watermarks prioritize MEA survival through representation entanglement, yet inadequately explore resilience against sequential MEAs and removal attacks. Our study reveals that this risk is underestimated because existing removal methods are weakened by entanglement. To address this gap, we propose Watermark Removal attacK (WRK), which circumvents entanglement constraints by exploiting decision boundaries shaped by prevailing sample-level watermark artifacts. WRK effectively reduces watermark success rates by ≥88.79% across existing watermarking benchmarks. For robust protection, we propose Class-Feature Watermarks (CFW), which improve resilience by leveraging class-level artifacts. CFW constructs a synthetic class using out-of-domain samples, eliminating vulnerable decision boundaries between original domain samples and their artifact-modified counterparts (watermark samples). CFW concurrently optimizes both MEA transferability and post-MEA stability. Experiments across multiple domains show that CFW consistently outperforms prior methods in resilience, maintaining a watermark success rate of ≥70.15% in extracted models even under the combined MEA and WRK distortion, while preserving the utility of protected models. Yaxin Xiao, Qingqing Ye 0001, Zi Liang, Haoyang Li 0018, Ronghua Li 0002, Huadi Zheng, Haibo Hu 0001 |
AAAI | 6 |
| 2026 | MirageNet: A Secure, Efficient, and Scalable DNN Protection for Edge-Computing Multimedia RetrievalabstractDeploying multimedia deep neural networks (DNNs) on edge devices reduces retrieval and inference latency, but untrusted hardware in this setting can easily leak model parameters. Existing TEE-based protections have limitations: the partial-weight obfuscation methods are vulnerable due to statistical flaws, while full-weight obfuscation struggles to balance security and efficiency. To address these, we propose a convolution decomposition obfuscation scheme (MirageNet) for protecting edge multimedia DNNs in TEE–GPU heterogeneous environments. This scheme relieves the flaw that cosine similarity remains highly consistent between pre-trained and fine-tuned models. It obfuscates via convolution-kernel element-wise operations, decoy-kernel injection, and channel/kernel permutations, maximizing GPU utilization while minimizing TEE overhead. Experiments show that the MirageNet scheme reduces attack success to a black-box level, lowers runtime overhead by 15% compared to SOTA, and preserves inference accuracy identical to the original model—meeting practical edge multimedia retrieval demands. Huadi Zheng, Yuanhang Yu, Feng Wang 0050 |
ICMR | 1 |
| 2026 | VLM-Guard: Defending Jailbreaks by Monitoring Only Hundreds of Safety-Critical Neurons
Jinyin Hu, Jiawei Zhou 0013, Minshan Xie, Zhonghao Yang 0003, Jing Li 0034, Huadi Zheng, Jie Shi 0005, Daojing He, Yu Li 0007 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | Multi-Turn Jailbreaking Large Language Models via Attention ShiftingabstractLarge Language Models (LLMs) have achieved significant performance in various natural language processing tasks but also pose safety and ethical threats, thus requiring red teaming and alignment processes to bolster their safety. To effectively exploit these aligned LLMs, recent studies have introduced jailbreak attacks based on multi-turn dialogues. These attacks aim to prompt LLMs to generate harmful or biased content by guiding them through contextual content. However, the underlying reasons for the effectiveness of multi-turn jailbreaks remain unclear. Existing attacks often focus on optimizing queries and escalating toxicity to construct dialogues, lacking a thorough analysis of the inherent vulnerabilities of LLMs. In this paper, we first conduct an in-depth analysis of the differences between single-turn and multi-turn jailbreaks and find that successful multi-turn jailbreaks can effectively disperse the attention of LLMs on keywords associated with harmful behaviors, especially in historical responses. Based on this, we propose ASJA, a new multi-turn jailbreak approach by shifting the attention of LLMs, specifically by iteratively fabricating the dialogue history through a genetic algorithm to induce LLMs to generate harmful content. Extensive experiments on three LLMs and two datasets show that our approach surpasses existing approaches in jailbreak effectiveness, the stealth of jailbreak prompts, and attack efficiency. Our work emphasizes the importance of enhancing the robustness of LLMs' attention mechanism in multi-turn dialogue scenarios for a better defense strategy. Xiaohu Du, Fan Mo 0004, Ming Wen 0001, Tu Gu, Huadi Zheng, Hai Jin 0001, Jie Shi 0005 |
AAAI | 5 |
| 2025 | A Sample-Level Evaluation and Generative Framework for Model Inversion AttacksabstractModel Inversion (MI) attacks, which reconstruct the training dataset of neural networks, pose significant privacy concerns in machine learning. Recent MI attacks have managed to reconstruct realistic label-level private data, such as the general appearance of a target person from all training images labeled on him. Beyond label-level privacy, in this paper we show sample-level privacy, the private information of a single target sample, is also important but under-explored in the MI literature due to the limitations of existing evaluation metrics. To address this gap, this study introduces a novel metric tailored for training-sample analysis, namely, the Diversity and Distance Composite Score (DDCS), which evaluates the reconstruction fidelity of each training sample by encompassing various MI attack attributes. This, in turn, enhances the precision of sample-level privacy assessments. Leveraging DDCS as a new evaluative lens, we observe that many training samples remain resilient against even the most advanced MI attack. As such, we further propose a transfer learning framework that augments the generative capabilities of MI attackers through the integration of entropy loss and natural gradient descent. Extensive experiments verify the effectiveness of our framework on improving state-of-the-art MI attacks over various metrics including DDCS, coverage and FID. Finally, we demonstrate that DDCS can also be useful for MI defense, by identifying samples susceptible to MI attacks in an unsupervised manner. Haoyang Li 0018, Li Bai 0004, Qingqing Ye 0001, Haibo Hu 0001, Yaxin Xiao, Huadi Zheng, Jianliang Xu |
AAAI | 6 |
| 2025 | Reminiscence Attack on Residuals: Exploiting Approximate Machine Unlearning for Privacy
Yaxin Xiao, Qingqing Ye 0001, Huadi Zheng, Haibo Hu 0001, Zi Liang, Haoyang Li 0018, Yijie Jiao |
ICCV | 4 |
| 2025 | SilentStriker: Toward Stealthy Bit-Flip Attacks on Large Language ModelsabstractThe rapid adoption of large language models (LLMs) in critical domains has spurred extensive research into their security issues. While input manipulation attacks (e.g., prompt injection) have been well-studied, Bit-Flip Attacks (BFAs)—which exploit hardware vulnerabilities to corrupt model parameters and cause severe performance degradation—have received far less attention. Existing BFA methods suffer from key limitations: they fail to balance performance degradation and output naturalness, making them prone to discovery. In this paper, we introduce SilentStriker, the first stealthy bit-flip attack against LLMs that effectively degrades task performance while maintaining output naturalness. Our core contribution lies in addressing the challenge of designing effective loss functions for LLMs with variable output length and the vast output space. Unlike prior approaches that rely on output perplexity for attack loss formulation, which in-evidently degrade the output naturalness, we reformulate the attack objective by leveraging key output tokens as targets for suppression, enabling effective joint optimization of attack effectiveness and stealthiness. Additionally, we employ an iterative, progressive search strategy to maximize attack efficacy. Experiments show that SilentStriker significantly outperforms existing baselines, achieving successful attacks without compromising the naturalness of generated text. Qingsong Peng, Jie Shi 0005, Huadi Zheng, Yu Li 0007, Zhuo Chen 0006 |
NeurIPS | 4 |
| 2025 | MER-Inspector: Assessing Model Extraction Risks from An Attack-Agnostic PerspectiveabstractInformation leakage issues in machine learning-based Web applications have attracted increasing attention. While the risk of data privacy leakage has been rigorously analyzed, the theory of model function leakage, known as Model Extraction Attacks (MEAs), has not been well studied. In this paper, we are the first to understand MEAs theoretically from an attack-agnostic perspective and to propose analytical metrics for evaluating model extraction risks. By using the Neural Tangent Kernel (NTK) theory, we formulate the linearized MEA as a regularized kernel classification problem and then derive the fidelity gap and generalization error bounds of the attack performance. Based on these theoretical analyses, we propose a new theoretical metric called Model Recovery Complexity (MRC), which measures the distance of weight changes between the victim and surrogate models to quantify risk. Additionally, we find that victim model accuracy, which shows a strong positive correlation with model extraction risk, can serve as an empirical metric. By integrating these two metrics, we propose a framework, namely Model Extraction Risk Inspector (MER-Inspector), to compare the extraction risks of models under different model architectures by utilizing relative metric values. We conduct extensive experiments on 16 model architectures and 5 datasets. The experimental results demonstrate that the proposed metrics have a high correlation with model extraction risks, and MER-Inspector can accurately compare the extraction risks of any two models with up to 89.58%. Xinwei Zhang 0002, Haibo Hu 0001, Qingqing Ye 0001, Li Bai 0004, Huadi Zheng |
WWW | 5 |
| 2025 | Unlocking High-Fidelity Learning: Towards Neuron-Grained Model ExtractionabstractModel extraction (ME) attacks replicate valuable black-box machine learning (ML) models via malicious query interactions. Cutting-edge attacks focus on actively designing query samples to enhance model fidelity and imprudently adhere to the standard ML training approach. This causes a deviation from the true objective of learning a model over a task. In this paper, we innovatively shift our focus from query selection to training process optimization, aiming to boost the similarity of the copy model with the victim model from neuron to model level. We leverage neuron matching theory to attain this objective and develop a general training booster framework, MEBooster, to fully exploit this theory. MEBooster comprises an initial bootstrapping phase that furnishes initial parameters and an optimal model architecture, followed by a post-processing phase that employs fine-tuning for enhanced neuron matching. Notably, MEBooster can seamlessly integrate with all existing model extraction attacks, enhancing their overall performance. Performance evaluation shows up to 58.10% fidelity gain in image classification. From a defender's perspective, we introduce a novel defensive strategy calledStochastic Norm Enlargement(SNE) to mitigate the risk of such attacks by enlarging the model parameters' norm property in training. Performance evaluation shows up to 58.81% extractability (i.e., fidelity) reduction. Yaxin Xiao, Haibo Hu 0001, Qingqing Ye 0001, Zi Liang, Huadi Zheng |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2024 | SPMIS: An Investigation of Synthetic Spoken Misinformation DetectionabstractIn recent years, speech generation technology has advanced rapidly, fueled by generative models and large-scale training techniques. While these developments have enabled the production of high-quality synthetic speech, they have also raised concerns about the misuse of this technology, particularly for generating synthetic misinformation. Current research primarily focuses on distinguishing machine-generated speech from human-produced speech, but the more urgent challenge is detecting misinformation within spoken content. This task requires a thorough analysis of factors such as speaker identity, topic, and synthesis. To address this need, we conduct an initial investigation into synthetic spoken misinformation detection by introducing an open-source dataset, SpMis. SpMis includes speech synthesized from over 1,000 speakers across five common topics, utilizing state-of-the-art text-to-speech systems. Although our results show promising detection capabilities, they also reveal substantial challenges for practical implementation, underscoring the importance of ongoing research in this critical area. Peizhuo Liu, Renqiang He, Haorui He, Huadi Zheng, Jie Shi 0005, Tong Xiao 0001, Zhizheng Wu 0001 |
SLT | 6 |
| 2023 | QUDA: Query-Limited Data-Free Model ExtractionabstractModel extraction attack typically refers to extracting non-public information from a black-box machine learning model. Its unauthorized nature poses significant threat to intellectual property rights of the model owners. By using the well-designed queries and the predictions returned from the victim model, the adversary is able to train a clone model from scratch to obtain similar functionality as victim model. Recently, some methods have been proposed to perform model extraction attacks without using any in-distribution data (Data-free setting). Although these methods have been shown to achieve high clone accuracy, their query budgets are typically around 10 million or even exceed 20 million in some datasets, which lead to a high cost of model stealing and can be easily defended by limiting the number of queries. To illustrate the severe threats induced by model extraction attacks with limited query budget in realistic scenarios, we propose QUDA – a novel QUey-limited DAta-free model extraction attack that incorporates GAN pre-trained by public unrelated dataset to provide weak image prior and the technique of deep reinforcement learning to make query generation strategy more efficient. Compared with the state-of-the-art data-free model extraction method, QUDA achieves better results under query-limited condition (0.1M query budget) in FMNIST and CIFAR-10 datasets, and even outperforms the baseline method in most cases when QUDA uses only 10% query budget of its. QUDA issued a warning that solely relying on the limited numbers of queries or the confidentiality of training data is not reliable to protect model’s security and privacy. Potential countermeasures, such as detection-based defense approach, are also provided. Zijun Lin 0001, Chengfang Fang, Huadi Zheng, Aneez Ahmed Jaheezuddin, Jie Shi 0005 |
AsiaCCS | 4 |
| 2023 | PrivKVM*: Revisiting Key-Value Statistics Estimation With Local Differential PrivacyabstractA key factor in big data analytics and artificial intelligence is the collection of user data from a large population. However, the collection of user data comes at the price of privacy risks, not only for users but also for businesses who are vulnerable to internal and external data breaches. To address privacy issues, local differential privacy (LDP) has been proposed to enable an untrusted collector to obtain accurate statistical estimation on sensitive user data (e.g., location, health, and financial data) without actually accessing the true records. As key-value data is an extremely popular NoSQL data model, there are a few works in the literature that study LDP-based statistical estimation on key-value data. However, these works have some major limitations, including supporting small key space only, fixed key collection range, difficulty in choosing an appropriate padding length, and high communication cost. In this article, we propose a two-phase mechanism$PrivKVM^*$as an optimized and highly-complete solution to LDP-based key-value data collection and statistics estimation. We verify its correctness and effectiveness through rigorous theoretical analysis and extensive experimental results. Qingqing Ye 0001, Haibo Hu 0001, Xiaofeng Meng 0001, Huadi Zheng, Kai Huang 0011, Chengfang Fang, Jie Shi 0005 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2022 | MExMI: Pool-based Active Model Extraction Crossover Membership InferenceabstractWith increasing popularity of Machine Learning as a Service (MLaaS), ML models trained from public and proprietary data are deployed in the cloud and deliver prediction services to users. However, as the prediction API becomes a new attack surface, growing concerns have arisen on the confidentiality of ML models. Existing literatures show their vulnerability under model extraction (ME) attacks, while their private training data is vulnerable to another type of attacks, namely, membership inference (MI). In this paper, we show that ME and MI can reinforce each other through a chained and iterative reaction, which can significantly boost ME attack accuracy and improve MI by saving the query cost. As such, we build a framework MExMI for pool-based active model extraction (PAME) to exploit MI through three modules: “MI Pre-Filter”, “MI Post-Filter”, and “semi-supervised boosting”. Experimental results show that MExMI can improve up to 11.14% from the best known PAME attack and reach 94.07% fidelity with only 16k queries. Furthermore, the precision and recall of the MI attack in MExMI are on par with state-of-the-art MI attack which needs 150k queries. Yaxin Xiao, Qingqing Ye 0001, Haibo Hu 0001, Huadi Zheng, Chengfang Fang, Jie Shi 0005 |
NeurIPS | 4 |
| 2022 | Stateful-CCSH: An Efficient Authentication Scheme for High-Resolution Video Surveillance SystemabstractVideo cameras have been widely deployed for surveillance and smart city. But the authenticity of a video scene faces a great challenge due to the ease of tampering with video data without leaving visible traces. Unfortunately, existing authentication schemes are not efficient for emerging high-resolution videos. In this article, we propose stateful correlation coefficient sampling-based hash (Stateful-CCSH), which adopts correlation coefficient sampling in image hash and learns from previous frames to sample those blocks with more dynamic contents and thus, more likely to be tampered in a video forgery. To decrease the impact of false detection introduced by compression and sampling, we also propose a group smoothing-based authentication scheme. The experimental results show that Stateful-CCSH not only achieves excellent performance in forgery detection, particularly, the detection of moving object removal, but also saves significant computation and communication costs even when the video resolutions are high. Qingqing Ye 0001, Huadi Zheng, Haibo Hu 0001, Ziyang Han, Ngai-Fong Law |
IEEE Internet Things J. | 3 |
| 2022 | Protecting Decision Boundary of Machine Learning Model With Differentially Private PerturbationabstractMachine learning service API allows model owners to monetize proprietary models by offering prediction services to third-party users. However, existing literature shows that model parameters are vulnerable to extraction attacks which accumulate prediction queries and their responses to train a replica model. As countermeasures, researchers have proposed to reduce the rich API output, such as hiding the precise confidence. Nonetheless, even with response being only one bit, an adversary can still exploit fine-tuned queries with differential property to infer the decision boundary of the underlying model. In this article, we propose boundary differential privacy (BDP) against such attacks by obfuscating the prediction responses with noises. BDP guarantees an adversary cannot learn the decision boundary of any two classes by a predefined precision no matter how many queries are issued to the prediction API. We first design a perturbation algorithm called boundary randomized response for a binary model. Then we prove it satisfies$\epsilon$-BDP, followed by a generalization of this algorithm to a multiclass model. Finally, we generalize a hard boundary to soft boundary and design an adaptive perturbation algorithm that can still work in the latter case. The effectiveness and high utility of our solution are verified by extensive experiments on both linear and non-linear models. Huadi Zheng, Qingqing Ye 0001, Haibo Hu 0001, Chengfang Fang, Jie Shi 0005 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Beyond Value Perturbation: Local Differential Privacy in the Temporal SettingabstractTime series has numerous application scenarios. However, since many time series data are personal data, releasing them directly could cause privacy infringement. All existing techniques to publish privacy-preserving time series perturb the values while retaining the original temporal order. However, in many value-critical scenarios such as health and financial time series, the values must not be perturbed whereas the temporal order can be perturbed to protect privacy. As such, we propose "local differential privacy in the temporal setting" (TLDP) as the privacy notion for time series data. After quantifying the utility of a temporal perturbation mechanism in terms of the costs of a missing, repeated, empty, or delayed value, we propose three mechanisms for TLDP. Through both analytical and empirical studies, we show the last one, Threshold mechanism, is the most effective under most privacy budget settings, whereas the other two baseline mechanisms fill a niche by supporting very small or large privacy budgets. Qingqing Ye 0001, Haibo Hu 0001, Ninghui Li 0001, Xiaofeng Meng 0001, Huadi Zheng |
INFOCOM | 5 |
| 2020 | MISSILE: A System of Mobile Inertial Sensor-Based Sensitive Indoor Location EavesdroppingabstractPrivacy concerns on smartphones have been raised by the public as more and more personal data are now stored on them. In this paper, we show that location information can be compromised through mobile inertial sensors which are considered insensitive and accessible by any mobile application in both iOS and Android without special privilege. We present MISSILE, an automatic system that can infer users' indoor location using labeled sensor data as prior knowledge. The key idea is that when a user reaches a particular indoor location, it is very likely that he/she has passed through some unique interior structures of a building, such as winding corridors, fire stop doors or elevators. These structures exhibit repeatable motion and environment patterns in mobile sensors that can be recognized by supervised learning. In our MISSILE system, the location labels of training data are automatically attained by Bluetooth beacons deployed in sensitive locations. With effective feature extraction procedure robust modeling, MISSILE shows good success rate for inference attack. For example, in a university campus with 15 sensitive locations, MISSILE achieves up to 73% correct prediction score whereas a random guess can only achieve 1/(15 + 1) = 6.25%. Further improvements on system performance and countermeasures are also discussed. Huadi Zheng, Haibo Hu 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2019 | BDPL: A Boundary Differentially Private Layer Against Machine Learning Model Extraction Attacks
Huadi Zheng, Qingqing Ye 0001, Haibo Hu 0001, Chengfang Fang, Jie Shi 0005 |
ESORICS (1) | 1 |
| 2019 | Metadata-driven Task Relation Discovery for Multi-task LearningabstractTask Relation Discovery (TRD), i.e., reveal the relation of tasks, has notable value: it is the key concept underlying Multi-task Learning (MTL) and provides a principled way for identifying redundancies across tasks. However, task relation is usually specifically determined by data scientist resulting in the additional human effort for TRD, while transfer based on brute-force methods or mere training samples may cause negative effects which degrade the learning performance. To avoid negative transfer in an automatic manner, our idea is to leverage commonly available context attributes in nowadays systems, i.e., the metadata. In this paper, we, for the first time, introduce metadata into TRD for MTL and propose a novel Metadata Clustering method, which jointly uses historical samples and additional metadata to automatically exploit the true relatedness. It also avoids the negative transfer by identifying reusable samples between related tasks. Experimental results on five real-world datasets demonstrate that the proposed method is effective for MTL with TRD, and particularly useful in complicated systems with diverse metadata but insufficient data samples. In general, this study helps in automatic relation discovery among partially related tasks and sheds new light on the development of TRD in MTL through the use of metadata as apriori information. Zimu Zheng, Quanyu Dai, Huadi Zheng, Dan Wang 0002 |
IJCAI | 4 |
| 2019 | PrivKV: Key-Value Data Collection with Local Differential PrivacyabstractLocal differential privacy (LDP), where each user perturbs her data locally before sending to an untrusted data collector, is a new and promising technique for privacy-preserving distributed data collection. The advantage of LDP is to enable the collector to obtain accurate statistical estimation on sensitive user data (e.g., location and app usage) without accessing them. However, existing work on LDP is limited to simple data types, such as categorical, numerical, and set-valued data. To the best of our knowledge, there is no existing LDP work on key-value data, which is an extremely popular NoSQL data model and the generalized form of set-valued and numerical data. In this paper, we study this problem of frequency and mean estimation on key-value data by first designing a baseline approach PrivKV within the same "perturbation-calibration" paradigm as existing LDP techniques. To address the poor estimation accuracy due to the clueless perturbation of users, we then propose two iterative solutions PrivKVM and PrivKVM+ that can gradually improve the estimation results through a series of iterations. An optimization strategy is also presented to reduce network latency and increase estimation accuracy by introducing virtual iterations in the collector side without user involvement. We verify the correctness and effectiveness of these solutions through theoretical analysis and extensive experimental results. Qingqing Ye 0001, Haibo Hu 0001, Xiaofeng Meng 0001, Huadi Zheng |
IEEE Symposium on Security and Privacy | 4 |
| 2016 | Text-independent voice conversion using deep neural network based phonetic level featuresabstractThis paper presents a phonetically-aware joint density Gaussian mixture model (JD-GMM) framework for voice conversion that no longer requires parallel data from source speaker at the training stage. Considering that the phonetic level features contain text information which should be preserved in the conversion task, we propose a method that only concatenates phonetic discriminant features and spectral features extracted from the same target speakers speech to train a JD-GMM. After the mapping relationship of these two features is trained, we can use phonetic discriminant features from source speaker to estimate target speaker's spectral features at conversion stage. The phonetic discriminant features are extracted using PCA from the output layer of a deep neural network (DNN) in an automatic speaker recognition (ASR) system. It can be seen as a low dimensional representation of the senone posteriors. We compare the proposed phonetically-aware method with conventional JD-GMM method on the Voice Conversion Challenge 2016 training database. The experimental results show that our proposed phonetically-aware feature method can obtain similar performance compared to the conventional JD-GMM in the case of using only target speech as training data. Huadi Zheng, Weicheng Cai, Tianyan Zhou, Shilei Zhang, Ming Li 0026 |
ICPR | 1 |