EDBT 2026 Demo / reviewers in the wild / expert
Jiyi Zhang
dblp:215/3755
· DBLP profile ↗
14ranked-venue papers
6as first author
13since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 4 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 2 first-author · 6 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adaptive Attractors: A Defense Strategy Against Adversarial Collusion Attacks in Machine LearningabstractIn the seller-buyer setting on machine learning models, the seller generates different copies based on the original model and distributes them to buyers, such that adversarial samples generated on one buyer's copy would likely not work on other copies. A known approach achieves this using attractor-based rewriter which injects different attractors to different copies. This induces different adversarial regions in different copies, making adversarial samples generated on one copy not replicable on others. In this paper, we focus on a scenario where multiple malicious buyers collude to attack. We first give two formulations and conduct empirical studies to analyze effectiveness of collusion attack under different assumptions on the attacker's capabilities and properties of the attractors. We observe that existing attractor-based methods do not effectively mislead the colluders as number of colluders increases (Figure 2). To address this, we propose adaptive attractors whose weight is guided by a U-shape curve. Experimental results demonstrate the efficacy of our approach. With 40 copies used for collusion, our method achieves a convergence of approximately 15% and 6% attack success rates on CIFAR-10 and GTSRB datasets respectively. In contrast, employing the original attractor-based rewriter leads to linear increase in attack success rates, reaching 29% and 19% respectively. Jiyi Zhang, Han Fang 0004, Ee-Chien Chang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | Finding Input Data Domains of Image Classification Models with Hard-Label Black-Box AccessabstractUnderstanding the correct input domain for black-box models is vital for tasks such as model cloning, inversion, and membership inference. However, this area remains underexplored, hindering related methods' efficacy without domain information. In this paper, we highlight the need for discovering the data domain and propose an approach that leverages existing generative models to address this challenge. With hard-label black-box access to a neural network model, our method produces a set of embeddings that, when utilized with the generative model, yield samples closely aligned with each target class's data domain, facilitating downstream tasks. Central to our method is an objective function covering both functional relevance and embedding generality. We employ an iterative search algorithm to identify the optimal set of embeddings. Starting with initial embeddings, new data points are generated and classified by the target model. Successful classifications guide embedding resampling, refining subsequent iterations' generated images closer to the target class's data domain. Consequently, the embeddings are iteratively modified to better match the data domain of the target class. Given the vast embedding space, we introduce an optional preprocessing phase. This phase leverages a comprehensive corpus like ImageNet to select a representative subset of samples, roughly aligned with the model's input domain, to serve as starting points. Jiyi Zhang, Han Fang 0004, Ee-Chien Chang |
ACM Multimedia | 1 |
| 2024 | DP2Dataset Protection by Data PoisoningabstractA high-value dataset is the key for accurate deep learning models, therefore, protecting the dataset is particularly important. Once the dataset is stolen, the attacker can easily train a surrogate model with similar performance to the original model. One possible solution to address such threat is data poisoning, whereby the performance of the surrogate model could be greatly influenced if trained with poisoned dataset. This paper focuses on an advanced scenario where the attacker might be an experienced malicious employee who has the white-box access to the dataset and black-box access (can only query) to original business model (e.g.MLaaS model). In order to re-train a surrogate model, he may first judge whether the dataset is poisoned and then try to erase potential perturbations to restore the original dataset. Under this condition, three main requirements must be satisfied: 1.Imperceptibility, which ensures that the poisoned data is not easily identified by human eyes; 2.Robustness, which ensures that the perturbation is not easily erased. 3.Stealthiness, which ensures that the poisoned data will not be recognized by the original business model i.e. produce abnormal output. In this paper, we propose a noveldataprotection method bydatapoisoning dubbed DP$^{2}$to meet the requirements. To achieve imperceptibility and robustness, we propose a poisoning mechanism that consists of a poisoning process and a balancing process. The poisoning process is conducted by a designed dual-U-Net-based poisoning network, by training with the reference mapping strategy and the corresponding noise layer, the imperceptibility and robustness can be both achieved. Then the balancing process is performed to balance the imperceptibility and poisoning performance. As for stealthiness, we propose a recover-net to eliminate the perturbation, so that the business model with black-box access could be an enclose version of the recover-net and the original business model. Besides, based on the recover-net, the poisoned dataset could be re-applied for the normal use. Various experiments indicate superior performance of the proposed scheme in the view of imperceptibility and robustness compared with other schemes. The solution which makes the poisoned data recoverable greatly ensures the stealthiness, and the derived recoverability of poisoned data could be utilized in other scenarios. Han Fang 0004, Yupeng Qiu, Guorui Qin, Jiyi Zhang, Kejiang Chen, Weiming Zhang 0001, Ee-Chien Chang |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2023 | Flow-Based Robust Watermarking with Invertible Noise Layer for Black-Box DistortionsabstractDeep learning-based digital watermarking frameworks have been widely studied recently. Most existing methods adopt an ``encoder-noise layer-decoder''-based architecture where the embedding and extraction processes are accomplished separately by the encoder and the decoder. However, one potential drawback of such a framework is that the encoder and the decoder may not be well coupled, resulting in the fact that the encoder may embed some redundant features into the host image thus influencing the invisibility and robustness of the whole algorithm. To address this limitation, this paper proposes a flow-based robust watermarking framework. The basic component of such framework is an invertible up-down-sampling neural block that can realize the embedding and extraction simultaneously. As a consequence, the encoded feature could keep high consistency with the feature that the decoder needed, which effectively avoids the embedding of redundant features. In addition, to ensure the robustness of black-box distortion, an invertible noise layer (INL) is designed to simulate the distortion and is served as a noise layer in the training stage. Benefiting from its reversibility, INL is also applied as a preprocessing before extraction to eliminate the distortion, which further improves the robustness of the algorithm. Extensive experiments demonstrate the superiority of the proposed framework in terms of visual quality and robustness. Compared with the state-of-the-art architecture, the visual quality (measured by PSNR) of the proposed framework improves by 2dB and the extraction accuracy after JPEG compression (QF=50) improves by more than 4%. Besides, the robustness against black-box distortions can be greatly achieved with more than 95% extraction accuracy. Han Fang 0004, Yupeng Qiu, Kejiang Chen, Jiyi Zhang, Weiming Zhang 0001, Ee-Chien Chang |
AAAI | 4 |
| 2023 | Mitigating Adversarial Attacks by Distributing Different Copies to Different BuyersabstractMachine learning models are vulnerable to adversarial attacks. In this paper, we consider the scenario where a model is distributed to multiple buyers, among which a malicious buyer attempts to attack another buyer. The malicious buyer probes its copy of the model to search for adversarial samples and then presents the found samples to the victim’s copy of the model in order to replicate the attack. We point out that by distributing different copies of the model to different buyers, we can mitigate the attack such that adversarial samples found on one copy would not work on another copy. We observed that training a model with different randomness indeed mitigates such replication to a certain degree. However, there is no guarantee and retraining is computationally expensive. A number of works extended the retraining method to enhance the differences among models. However, a very limited number of models can be produced using such methods and the computational cost becomes even higher. Therefore, we propose a flexible parameter rewriting method that directly modifies the model’s parameters. This method does not require additional training and is able to generate a large number of copies in a more controllable manner, where each copy induces different adversarial regions. Experimentation studies show that rewriting can significantly mitigate the attacks while retaining high classification accuracy. For instance, on GTSRB dataset with respect to Hop Skip Jump attack, using attractor-based rewriter can reduce the success rate of replicating the attack to 0.5% while independently training copies with different randomness can reduce the success rate to 6.5%. From this study, we believe that there are many further directions worth exploring. Jiyi Zhang, Han Fang 0004, Wesley Joon-Wie Tann, Chengfang Fang, Ee-Chien Chang |
AsiaCCS | 1 |
| 2023 | A Multi-dimensional Unified Concavity and Convexity Detection Method Based on Geometric Algebra
Jiyi Zhang, Tianzi Wei |
CGI (4) | 1 |
| 2023 | Tracing the Origin of Adversarial Attack for Forensic Investigation and DeterrenceabstractDeep neural networks are vulnerable to adversarial attacks. In this paper, we take the role of investigators who want to trace the attack and identify the source, that is, the particular model which the adversarial examples are generated from. Techniques derived would aid forensic investigation of attack incidents and serve as deterrence to potential attacks. We consider the buyers-seller setting where a machine learning model is to be distributed to various buyers and each buyer receives a slightly different copy with the same functionality. A malicious buyer generates adversarial examples from a particular copy ${\mathcal{M}_i}$ and uses them to attack other copies. From these adversarial examples, the investigator wants to identify the source ${\mathcal{M}_i}$. To address this problem, we propose a two-stage separate-and-trace framework. The model separation stage generates multiple copies of a model for the same classification task. This process injects unique features into each copy so that adversarial examples generated have distinct and traceable features. We give a parallel structure which pairs a unique tracer with the original classification model in each copy and a variational autoencoder (VAE)-based training method to achieve this goal. The tracing stage takes in adversarial examples and a few candidate models, and identifies the likely source. Based on the unique features induced by the tracer, we could effectively trace the potential adversarial copy by considering the output logits from each tracer. Empirical results show that it is possible to trace the origin of the adversarial example and the mechanism can be applied to a wide range of architectures and datasets. Jiyi Zhang, Yupeng Qiu, Chengfang Fang, Ee-Chien Chang |
ICCV | 2 |
| 2023 | A line-of-sight zoning method for intervisibility computation by considering terrain reliefabstractExisting intervisibility analysis methods suffer from computational inefficiency due to redundant sampling points. To address this issue, we propose a new approximate method called line-of-sight (LoS) zoning, which leverages continuous terrain relief to identify potentially obscuring zones (POZ) of LoS. By limiting the sampling range to a much smaller POZ, the number of sampling points is significantly reduced. The optimal sampling interval of 6 is determined by striking a balance between computational efficiency and accuracy. Through experiments in both mountainous and plain areas, regardless of the height range and resolution conditions, we demonstrate the high efficiency of the LoS zoning method, especially in scenarios with a high proportion of visible LoS. To account for potential visibility errors caused by sharp peaks in the terrain, we conducted experiments under fixed time intervals to assess the calculation quality of different methods. The results show that in mountainous and plain areas, the improvement in detection rate compared to the hopping strategy method is around 4–6 times in most scenarios. This significant performance enhancement highlights the superiority of the LoS zoning method, and shows great promise in terrain avoidance, path planning in the military, and detection of dangerous targets. Zengjie Wang, Zhenxia Liu, Wen Luo 0004, Zhaoyuan Yu, Jiyi Zhang, Linwang Yuan |
Int. J. Geogr. Inf. Sci. | 6 |
| 2023 | De-END: Decoder-Driven Watermarking NetworkabstractDeep-learning-based watermarking technique is being extensively studied. Most existing approaches adopt a similar encoder-driven scheme which we name END (Encoder-NoiseLayer-Decoder) architecture. In this paper, we revamp the architecture and creatively design a decoder-driven watermarking network dubbed De-END which greatly outperforms the existing END-based methods. The motivation for designing De-END originated from the potential drawback we discovered in END architecture: The encoder may embed redundant features that are not necessary for decoding, limiting the performance of the whole network. We conducted a detailed analysis and found that such limitations are caused by unsatisfactory coupling between the encoder and decoder in END. De-END addresses such drawbacks by adopting a Decoder -Encoder-Noiselayer-Decoder architecture. In De-END, the host image is firstly processed by the decoder to generate a latent feature map instead of being directly fed into the encoder. This latent feature map is concatenated to the original watermark message and then processed by the encoder. This change in design is crucial as it makes the feature of encoder and decoder directly shared thus the encoder and decoder are better coupled. We conducted extensive experiments and the results show that this framework outperforms the existing state-of-the-art (SOTA) END-based deep learning watermarking both in visual quality and robustness. On the premise of the same decoder structure, the visual quality (measured by PSNR) of De-END improves by 1.6dB (45.16dB to 46.84dB), and extraction accuracy after JPEG compression (QF=50) distortion outperforms more than 4% (94.9% to 99.1%). Han Fang 0004, Zhaoyang Jia, Yupeng Qiu, Jiyi Zhang, Weiming Zhang 0001, Ee-Chien Chang |
IEEE Trans. Multim. | 4 |
| 2022 | Confusing and Detecting ML Adversarial Attacks with Injected AttractorsabstractMany machine learning adversarial attacks find adversarial samples of a victim model M by following the gradient of some attack objective functions, either explicitly or implicitly. To confuse and detect such attacks, we take the proactive approach that modifies those functions with the goal of misleading the attacks to some local minima, or to some designated regions that can be easily picked up by an analyzer. To achieve this goal, we propose adding a large number of artifacts, which we called attractors, onto the otherwise smooth function. An attractor is a point in the input space, where samples in its neighborhood have gradient pointing toward it. We observe that decoders of watermarking schemes exhibit properties of attractors and give a generic method that injects attractors from a watermark decoder into the victim model M. This principled approach allows us to leverage on known watermarking schemes for scalability and robustness and provides explainability of the outcomes. Experimental studies show that our method has competitive performance. For instance, for un-targeted attacks on CIFAR-10 dataset, we can reduce the overall attack success rate of DeepFool to 1.9%, whereas known defense LID, FS and MagNet can reduce the rate to 90.8%, 98.5% and 78.5% respectively. Jiyi Zhang, Ee-Chien Chang, Hwee Kuan Lee |
AsiaCCS | 1 |
| 2022 | A tensor-based approach to unify organization and operation of data for irregular spatio-temporal fieldsabstractIrregular geographic spatio-temporal-field data have been rapidly accumulating; however, data organizations and operations for different irregular types are often segregated, leading to systematic drawbacks, such as interface expansion difficulty and high coupling codes in GIS implementations. The paper proposes a unified approach to organizing and operating irregular geographic spatio-temporal-field data. The proposed approach has two components, namely ‘concepts and definitions’, and ‘logical model’. The first component introduces the concept of primitive elements, which are formal sets of data points, to serve as the smallest building blocks in the data organization. We define the corresponding primitive elements for three prevalent irregularity types (including sparse, imbalanced, and heterogeneous). The second component utilizes object-oriented programming to support the implementation of various operators. Additionally, we develop the layered architecture to decouple data organization, operation, and visualization to assure low coupling among layers. For demonstrations, we conduct case studies to show the effectiveness of our approach. Additionally, we conduct experiments to new irregularity types and illustrate the flexibility and scalability of our approach. Comparisons with classic tensor methods and spatio-temporal analysis methods show that our approach has more comprehensive supports for different data types. Dongshuang Li, Yuhao Teng, Jiyi Zhang, Wen Luo 0004, Binru Zhao, Zhaoyuan Yu, Linwang Yuan |
Int. J. Geogr. Inf. Sci. | 4 |
| 2021 | Unified Expression Frame of Geodetic Stations Based on Conformal Geometric Algebra
Zhenjun Yan, Zhaoyuan Yu, Wen Luo 0004, Jiyi Zhang, Linwang Yuan |
CGI | 5 |
| 2021 | Common Component in Black-Boxes Is Prone to Attacks
Jiyi Zhang, Wesley Joon-Wie Tann, Ee-Chien Chang, Hwee Kuan Lee |
ESORICS (1) | 1 |
| 2019 | Neural Network Inversion in Adversarial Setting via Background Knowledge AlignmentabstractThe wide application of deep learning technique has raised new security concerns about the training data and test data. In this work, we investigate the model inversion problem under adversarial settings, where the adversary aims at inferring information about the target model's training data and test data from the model's prediction values. We develop a solution to train a second neural network that acts as the inverse of the target model to perform the inversion. The inversion model can be trained with black-box accesses to the target model. We propose two main techniques towards training the inversion model in the adversarial settings. First, we leverage the adversary's background knowledge to compose an auxiliary set to train the inversion model, which does not require access to the original training data. Second, we design a truncation-based technique to align the inversion model to enable effective inversion of the target model from partial predictions that the adversary obtains on victim user's data. We systematically evaluate our approach in various machine learning tasks and model architectures on multiple image datasets. We also confirm our results on Amazon Rekognition, a commercial prediction API that offers "machine learning as a service". We show that even with partial knowledge about the black-box model's training data, and with only partial prediction values, our inversion approach is still able to perform accurate inversion of the target model, and outperform previous approaches. Jiyi Zhang, Ee-Chien Chang, Zhenkai Liang |
CCS | 2 |