EDBT 2026 Demo / reviewers in the wild / expert
Wenjie Qu 0001
dblp:216/6884-1
· DBLP profile ↗
19ranked-venue papers
7as first author
19since 2021 · last 2026
0009-0006-2907-008XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 7 first-author · 13 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ExtendAttack: Attacking Servers of LRMs via Extending ReasoningabstractLarge Reasoning Models (LRMs) have demonstrated promising performance in complex tasks. However, the resource-consuming reasoning processes may be exploited by attackers to maliciously occupy the resources of the servers, leading to a crash, like the DDoS attack in cyber. To this end, we propose a novel attack method on LRMs termed ExtendAttack to maliciously occupy the resources of servers by stealthily extending the reasoning processes of LRMs. Concretely, we systematically obfuscate characters within a benign prompt, transforming them into a complex, poly-base ASCII representation. This compels the model to perform a series of computationally intensive decoding sub-tasks that are deeply embedded within the semantic structure of the query itself. Extensive experiments demonstrate the effectiveness of our proposed ExtendAttack. Remarkably, it significantly increases response length and latency, with the former increasing by over 2.7 times for the o3 model on the HumanEval benchmark. Besides, it preserves the original meaning of the query and achieves comparable answer accuracy, showing the stealthiness. Zhenhao Zhu, Yue Liu 0008, Yingwei Ma, Hongcheng Gao, Nuo Chen 0002, Yanpei Guo, Wenjie Qu 0001, Zifeng Kang, Xinzhong Zhu, Jiaheng Zhang |
AAAI | 8 |
| 2026 | Celer: A Lookup Argument for Large-Scale Queries
Wenjie Qu 0001, Yanpei Guo, Zhen Xuan, Xuanming Liu, Jiaheng Zhang |
CRYPTO (9) | 1 |
| 2026 | Towards Effective Prompt Stealing Attack against Text-to-Image Diffusion Models
Shiqian Zhao, Chong Wang 0013, Yiming Li 0004, Yihao Huang 0001, Wenjie Qu 0001, Siew-Kei Lam, Yi Xie 0011, Kangjie Chen, Jie Zhang 0073, Tianwei Zhang 0004 |
NDSS | 5 |
| 2026 | UltraProofs: Scalable Reed-Solomon Code Commitment
Yanpei Guo, Alex Luoyuan Xiong, Wenjie Qu 0001, Jiaheng Zhang |
SP | 3 |
| 2026 | VerfCNN, Optimal Complexity zkSNARK for Convolutional Neural Networks
Wenjie Qu 0001, Yanpei Guo, Yue Ying, Jiaheng Zhang |
SP | 1 |
| 2025 | Mosformer: Maliciously Secure Three-Party Inference Framework for Large TransformersabstractTransformer-based models like BERT and GPT have achieved state-of-the-art performance across a wide range of AI tasks but raise serious privacy concerns when deployed as cloud inference services. To address this, secure multi-party computation (MPC) is commonly employed, encrypting both user inputs and model parameters to enable inference without revealing any private information. However, existing MPC-based secure transformer inference protocols are predominantly designed under the semi-honest security model. Extending these protocols to support malicious security remains a significant challenge, primarily due to the substantial overhead introduced by securely evaluating complex non-linear functions required for adversarial resilience. We introduce Mosformer, the first maliciously secure three-party (3PC) inference framework that efficiently supports large transformers such as BERT and GPT. We first design constant-round comparison and lookup table protocols with malicious security, leveraging verifiable distributed point functions (VDPFs). Building on these, we develop a suite of 3PC protocols for efficient and secure evaluation of complex non-linear functions in transformers. Together with optimized modulus conversion, our approach substantially reduces the overhead of secure transformer inference while preserving model accuracy. Experimental results on the vanilla transformer block show that Mosformer achieves up to a 5.3× speedup and a 4.3× reduction in communication over prior maliciously secure protocols. Despite offering stronger security guarantees, Mosformer achieves comparable or even superior online performance to state-of-the-art semi-honest 2PC and 3PC frameworks, including BOLT (Oakland 2024), BumbleBee (NDSS 2025), SHAFT (NDSS 2025), and Ditto (ICML 2024), on full-scale models such as BERT and GPT-2. Ke Cheng 0001, Yuheng Xia, Anxiao Song, Jiaxuan Fu, Wenjie Qu 0001, Yulong Shen 0001, Jiaheng Zhang |
CCS | 5 |
| 2025 | Efficient Input-Level Backdoor Defense on Text-to-Image Synthesis via Neuron Activation VariationabstractIn recent years, text-to-image (T2I) diffusion models have gained significant attention for their ability to generate high quality images reflecting text prompts. However, their growing popularity has also led to the emergence of backdoor threats, posing substantial risks. Currently, effective defense strategies against such threats are lacking due to the diversity of backdoor targets in T2I synthesis. In this paper, we propose NaviT2I, an efficient input-level backdoor defense framework against diverse T2I backdoors. Our approach is based on the new observation that trigger tokens tend to induce significant neuron activation variation in the early stage of the diffusion generation process, a phenomenon we term Early-step Activation Variation. Leveraging this insight, NaviT2I navigates T2I models to prevent malicious inputs by analyzing Neuron activation variations caused by input tokens. Extensive experiments show that NaviT2I significantly outperforms the baselines in both effectiveness and efficiency across diverse datasets, various T2I backdoors, and different model architectures including UNet and DiT. Furthermore, we show that our method remains effective under potential adaptive attacks. Shengfang Zhai, Yue Liu 0008, Huanran Chen, Zhihua Tian, Wenjie Qu 0001, Qingni Shen, Ruoxi Jia 0001, Yinpeng Dong, Jiaheng Zhang |
ICCV | 6 |
| 2025 | Prompt Inversion Attack Against Collaborative Inference of Large Language ModelsabstractLarge language models (LLMs) have been widely applied for their remarkable capability of content generation. However, the practical use of open-source LLMs is hindered by high resource requirements, making deployment expensive and limiting widespread development. The collaborative inference is a promising solution for this problem, in which users collaborate by each hosting a subset of layers and transmitting intermediate activation. Many companies are building collaborative inference platforms to reduce LLM serving costs, leveraging users' underutilized GPUs. Despite widespread interest in collaborative inference within academia and industry, the privacy risks associated with LLM collaborative inference have not been well studied. This is largely because of the challenge posed by inverting LLM activation due to its strong non-linearity. In this paper, to validate the severity of privacy threats in LLM collaborative inference, we introduce the concept of prompt inversion attack (PIA), where a malicious participant intends to recover the input prompt through the activation transmitted by its previous participant. Specifically, we design a two-stage method to execute this attack. In the first stage, we optimize the input embedding with a constraint term derived from the LLM's embedding matrix to enforce the optimized embedding to be close to the ground truth. In the second stage, we accurately recover discrete tokens by incorporating activation calibration and semantic speculation. Extensive experiments show that our PIA method substantially outperforms existing baselines. For example, our method achieves an 88.4% token accuracy on the Skytrax dataset with the Llama-65B model when inverting the maximum number of transformer layers, while the best baseline method only achieves 22.8% accuracy. The results verify the effectiveness of our PIA attack and highlights its practical threat to LLM collaborative inference systems. Wenjie Qu 0001, Yuguang Zhou, Tingsong Xiao, Binhang Yuan, Yiming Li 0004, Jiaheng Zhang |
SP | 1 |
| 2025 | HyperPianist: Pianist with Linear-Time Prover and Logarithmic Communication CostabstractRecent years have seen great improvements in zero-knowledge proofs (ZKPs). Among them, zero-knowledge SNARKs are notable for their compact and efficiently-verifiable proofs, but suffer from high prover costs. Wu et al. (Usenix Security 2018) proposed to distribute the proving task across multiple machines, and achieved significant improvements in proving time. However, existing distributed ZKP systems still have quasi-linear prover cost, and may incur a communication cost that is linear in circuit size. In this paper, we introduce HyperPianist. Inspired by the state-of-the-art distributed ZKP system Pianist (Liu et al., S&P 2024) and the multivariate proof system HyperPlonk (Chen et al., EUROCRYPT 2023), we design a distributed multivariate polynomial interactive oracle proof (PIOP) system with a linear-time prover cost and logarithmic communication cost. Unlike Pianist, HyperPianist incurs no extra overhead in prover time or communication when applied to general (non-data-parallel) circuits. To instantiate the PIOP system, we adapt two additively-homomorphic multivariate polynomial commitment schemes, multivariate KZG (Papamanthou et al., TCC 2013) and Dory (Lee et al., TCC 2021), into the distributed setting, and get HyperPianistKand HyperPianistDrespectively. Both systems have linear prover complexity and logarithmic communication cost; furthermore, HyperPianistDrequires no trusted setup. We also propose HyperPianist+, incorporating an optimized lookup argument based on Lasso (Setty et al., EUROCRYPT 2024) with lower prover cost. Experiments demonstrate HyperPianistKand HyperPianistDachieve speedups of 63.1x and 40.2x over HyperPlonk with 32 distributed machines. Compared to Pianist, HyperPianistKcan be 2.9x and 4.6x as fast and HyperPianistDcan be 2.4x and 3.8x as fast, on vanilla gates and custom gates respectively. With layered circuits, HyperPianistKis up to 5.9x as fast on custom gates, and HyperPianistDachieves a 4.7x speedup. Chongrong Li, Yun Li 0010, Cheng Hong 0001, Wenjie Qu 0001, Jiaheng Zhang |
SP | 5 |
| 2025 | zkGPT: An Efficient Non-interactive Zero-knowledge Proof Framework for LLM Inference
Wenjie Qu 0001, Yijun Sun, Xuanming Liu, Yanpei Guo, Jiaheng Zhang |
USENIX Security Symposium | 1 |
| 2025 | Provably Robust Multi-bit Watermarking for AI-generated Text
Wenjie Qu 0001, Wengrui Zheng, Tianyang Tao, Yanze Jiang, Zhihua Tian, Jinyuan Jia 0001, Jiaheng Zhang |
USENIX Security Symposium | 1 |
| 2025 | DeepFold: Efficient Multilinear Polynomial Commitment from Reed-Solomon Code and Its Application to Zero-knowledge Proofs
Yanpei Guo, Xuanming Liu, Kexi Huang, Wenjie Qu 0001, Tianyang Tao, Jiaheng Zhang |
USENIX Security Symposium | 4 |
| 2023 | MPass: Bypassing Learning-based Static Malware DetectorsabstractMachine learning (ML) based static malware detectors are widely deployed, but vulnerable to adversarial attacks. Unlike images or texts, tiny modifications to malware samples would significantly compromise their functionality. Consequently, existing attacks against images or texts will be significantly restricted when being deployed on malware detectors. In this work, we propose a hard-label black-box attack MPass against ML-based detectors. MPass employs a problem-space explainability method to locate critical positions of malware, applies adversarial modifications to such positions, and utilizes a runtime recovery technique to preserve the functionality. Experiments show MPass outperforms existing solutions and bypasses both state-of-the-art offline models and commercial ML-based antivirus products. Jialai Wang, Wenjie Qu 0001, Han Qiu 0001, Qi Li 0002, Zongpeng Li, Chao Zhang 0008 |
DAC | 2 |
| 2023 | A Certified Radius-Guided Attack Framework to Image Segmentation ModelsabstractImage segmentation is an important problem in many safety-critical applications such as medical imaging and autonomous driving. Recent studies show that modern image segmentation models are vulnerable to adversarial perturbations, while existing attack methods mainly follow the idea of attacking image classification models. We argue that image segmentation and classification have inherent differences, and design an attack framework specially for image segmentation models. Our goal is to thoroughly explore the vulnerabilities of modern segmentation models, i.e., aiming to misclassify as many pixels as possible under a perturbation budget in both white-box and black-box settings.Our attack framework is inspired by certified radius, which was originally used by defenders to defend against adversarial perturbations to classification models. We are the first, from the attacker perspective, to leverage the properties of certified radius and propose a certified radius guided attack framework against image segmentation models. Specifically, we first adapt randomized smoothing, the state-of-the-art certification method for classification models, to derive the pixel’s certified radius. A larger certified radius of a pixel means the pixel is theoretically more robust to adversarial perturbations. This observation inspires us to focus more on disrupting pixels with relatively smaller certified radii. Accordingly, we design a pixel-wise certified radius guided loss, when plugged into any existing white-box attack, yields our certified radius-guided white-box attack.Next, we propose the first black-box attack to image segmentation models via bandit. A key challenge is no gradient information is available. To address it, we design a novel gradient estimator, based on bandit feedback, which is query-efficient and provably unbiased and stable. We use this gradient estimator to design a projected bandit gradient descent (PBGD) attack. We further use pixels’ certified radii and design a certified radius-guided PBGD (CR-PBGD) attack. We prove our PBGD and CR-PBGD attacks can achieve asymptotically optimal attack performance with an optimal rate. We evaluate our certified-radius guided white-box and black-box attacks on multiple modern image segmentation models and datasets. Our results validate the effectiveness of our certified radius-guided attack framework. Wenjie Qu 0001, Youqi Li, Binghui Wang |
EuroS&P | 1 |
| 2023 | REaaS: Enabling Adversarially Robust Downstream Classifiers via Robust Encoder as a Service
Wenjie Qu 0001, Jinyuan Jia 0001, Neil Zhenqiang Gong |
NDSS | 1 |
| 2022 | jTrans: jump-aware transformer for binary code similarity detectionabstractBinary code similarity detection (BCSD) has important applications in various fields such as vulnerabilities detection, software component analysis, and reverse engineering. Recent studies have shown that deep neural networks (DNNs) can comprehend instructions or control-flow graphs (CFG) of binary code and support BCSD. In this study, we propose a novel Transformer-based approach, namely jTrans, to learn representations of binary code. It is the first solution that embeds control flow information of binary code into Transformer-based language models, by using a novel jump-aware representation of the analyzed binaries and a newly-designed pre-training task. Additionally, we release to the community a newly-created large dataset of binaries, BinaryCorp, which is the most diverse to date. Evaluation results show that jTrans outperforms state-of-the-art (SOTA) approaches on this more challenging dataset by 30.5% (i.e., from 32.0% to 62.5%). In a real-world task of known vulnerability searching, jTrans achieves a recall that is 2X higher than existing SOTA baselines. Hao Wang 0226, Wenjie Qu 0001, Gilad Katz, Wenyu Zhu, Han Qiu 0001, Jianwei Zhuge, Chao Zhang 0008 |
ISSTA | 2 |
| 2022 | MultiGuard: Provably Robust Multi-label Classification against Adversarial ExamplesabstractMulti-label classification, which predicts a set of labels for an input, has many applications. However, multiple recent studies showed that multi-label classification is vulnerable to adversarial examples. In particular, an attacker can manipulate the labels predicted by a multi-label classifier for an input via adding carefully crafted, human-imperceptible perturbation to it. Existing provable defenses for multi-class classification achieve sub-optimal provable robustness guarantees when generalized to multi-label classification. In this work, we propose MultiGuard, the first provably robust defense against adversarial examples to multi-label classification. Our MultiGuard leverages randomized smoothing, which is the state-of-the-art technique to build provably robust classifiers. Specifically, given an arbitrary multi-label classifier, our MultiGuard builds a smoothed multi-label classifier via adding random noise to the input. We consider isotropic Gaussian noise in this work. Our major theoretical contribution is that we show a certain number of ground truth labels of an input are provably in the set of labels predicted by our MultiGuard when the $\ell_2$-norm of the adversarial perturbation added to the input is bounded. Moreover, we design an algorithm to compute our provable robustness guarantees. Empirically, we evaluate our MultiGuard on VOC 2007, MS-COCO, and NUS-WIDE benchmark datasets. Our code is available at: https://github.com/quwenjie/MultiGuard Jinyuan Jia 0001, Wenjie Qu 0001, Neil Zhenqiang Gong |
NeurIPS | 2 |
| 2021 | EncoderMI: Membership Inference against Pre-trained Encoders in Contrastive LearningabstractGiven a set of unlabeled images or (image, text) pairs, contrastive learning aims to pre-train an image encoder that can be used as a feature extractor for many downstream tasks. In this work, we propose EncoderMI, the first membership inference method against image encoders pre-trained by contrastive learning. In particular, given an input and a black-box access to an image encoder, EncoderMI aims to infer whether the input is in the training dataset of the image encoder. EncoderMI can be used 1) by a data owner to audit whether its (public) data was used to pre-train an image encoder without its authorization or 2) by an attacker to compromise privacy of the training data when it is private/sensitive. Our EncoderMI exploits the overfitting of the image encoder towards its training data. In particular, an overfitted image encoder is more likely to output more (or less) similar feature vectors for two augmented versions of an input in (or not in) its training dataset. We evaluate EncoderMI on image encoders pre-trained on multiple datasets by ourselves as well as the Contrastive Language-Image Pre-training (CLIP) image encoder, which is pre-trained on 400 million (image, text) pairs collected from the Internet and released by OpenAI. Our results show that EncoderMI can achieve high accuracy, precision, and recall. We also explore a countermeasure against EncoderMI via preventing overfitting through early stopping. Our results show that it achieves trade-offs between accuracy of EncoderMI and utility of the image encoder, i.e., it can reduce the accuracy of EncoderMI, but it also incurs classification accuracy loss of the downstream classifiers built based on the image encoder. Hongbin Liu 0005, Jinyuan Jia 0001, Wenjie Qu 0001, Neil Zhenqiang Gong |
CCS | 3 |
| 2021 | Mass personalization strategy under Industrial Internet of Things: A case study on furniture production
Jia Ding, Xiong Zeng, Wenjie Qu 0001, Vassilios S. Vassiliadis |
Adv. Eng. Informatics | 4 |