EDBT 2026 Demo / reviewers in the wild / expert
Xinlei He 0001
dblp:227/7262-1
· DBLP profile ↗
44ranked-venue papers
7as first author
43since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 5 first-author · 25 since 2021Artificial intelligence and machine learning · 13 · 1 first-author · 13 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 1 first-author · 6 since 2021Databases, data management, data science and information retrieval · 5 · 5 since 2021Computer networks · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | 6DAttack: Backdoor Attacks in the 6DoF Pose EstimationabstractRecent advances in deep learning have enabled highly accurate six-degree-of-freedom (6DoF) object pose estimation, leading to its widespread use in real-world applications such as robotics, augmented reality, virtual reality, and autonomous systems. However, backdoor attacks pose a major security risk to deep learning models. By injecting malicious triggers into training data, an attacker can cause a model to perform normally on benign inputs but behave incorrectly under specific conditions. While most research on backdoor attacks has focused on 2D vision tasks, their impact on 6DoF pose estimation remains largely unexplored. Furthermore, unlike traditional backdoors that only change the object class, backdoors against 6DoF pose estimation must additionally control continuous pose parameters, such as translation and rotation, making existing 2D backdoor attack methods not directly applicable to this setting. To address this gap, we propose a novel backdoor attack framework (6DAttack) that exposes vulnerabilities in 6DoF pose estimation. 6DAttack uses synthetic and real 3D objects of varying shapes as triggers and assigns target poses to induce controlled erroneous pose outputs while maintaining normal behavior on clean inputs. We evaluated this attack on multiple models (including PVNet, DenseFusion, and PoseDiffusion) and datasets (including LINEMOD, YCB-Video, and CO3D). Experimental results demonstrate that 6DAttack achieves extremely high attack success rates (ASRs) without compromising performance on legitimate tasks. Across various models and objects, the backdoored models achieve up to 100% ADD accuracy on clean data, while also achieving 100% ASR under trigger conditions. The accuracy of controlled erroneous pose output is also extremely high, with triggered samples achieving 97.70% ADD-P. These results demonstrate that the backdoor can be reliably implanted and activated, achieving a high ASR under trigger conditions while maintaining a negligible impact on benign data. Furthermore, we evaluate a representative defense and show that it remains ineffective under 6DAttack. Overall, our findings reveal a potentially serious and previously underexplored threat to modern 6DoF pose estimation models. Jihui Guo, Zongmin Zhang, Zhen Sun 0001, Jinlin Wu, Xinlei He 0001 |
AAAI | 7 |
| 2026 | An Improved Privacy and Utility Analysis of Differentially Private SGD with Bounded Domain and Smooth LossesabstractDifferentially Private Stochastic Gradient Descent (DPSGD) is widely used to protect sensitive data during the training of machine learning models, but its privacy guarantee often comes at a large cost of model performance due to the lack of tight theoretical bounds quantifying privacy loss. While recent efforts have achieved more accurate privacy guarantees, they still impose some assumptions prohibited from practical applications, such as convexity and complex parameter requirements, and rarely investigate in-depth the impact of privacy mechanisms on the model's utility. In this paper, we provide a rigorous privacy characterization for DPSGD with general L-smooth and non-convex loss functions, revealing converged privacy loss with iteration in bounded-domain cases. Specifically, we track the privacy loss over multiple iterations, leveraging the noisy smooth-reduction property, and further establish comprehensive convergence analysis in different scenarios. In particular, we show that for DPSGD with a bounded domain, (i) the privacy loss can still converge without the convexity assumption, (ii) a smaller bounded diameter can improve both privacy and utility simultaneously under certain conditions, and (iii) the attainable big-O order of the privacy utility trade-off for DPSGD with gradient clipping (DPSGD-GC) and for DPSGD-GC with bounded domain (DPSGD-DC) and strongly convex population risk function, respectively. Experiments via membership inference attack (MIA) in a practical setting validate insights gained from the theoretical results. Wanrong Zhang 0001, Xinlei He 0001, Kaishun Wu, Hong Xing |
AAAI | 3 |
| 2026 | Verifiable and Lightweight Multi-Round Secure Federated LearningabstractFederated learning (FL) is a paradigm that ensures the confidentiality and accessibility of data without requiring the collection of private data from multiple sources. It acquires an aggregation model by integrating various local models from clients. However, clients are vulnerable to numerous security and privacy threats. Existing solutions were unable to implement training models that are both dropout-resilient and lightweight while also providing verification capabilities when large-scale clients are involved in federated training. To improve the usability of FL, we propose a verifiable and lightweight multi-round secure FL framework by designing and incorporating a double-masking mechanism to ensure secure transmission. Moreover, we optimize the secure aggregation strategy by designing a dropout-resilience method via the secret-sharing mechanism. Specifically, we establish a lightweight model-secure training scheme and provide a parameter reuse strategy by constructing a full connection graph, which reduces computational cost and communication overhead. Furthermore, we propose a secure authentication protocol that enables the client to verify the accuracy of the computing results from the server. Extensive experimental evaluations indicate that our solution demonstrates relatively modest performance but superior functionality compared to current state-of-the-art methods. In particular, we can achieve the verification function with an acceptable increase in computational cost of approximately 200ms per epoch. Shengmin Xu, Xingshuo Han, Jianting Ning, Xinlei He 0001, Guowen Xu |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2026 | Covert Knowledge Poisoning Attacks in Retrieval-Augmented Code GenerationabstractRetrieval-Augmented Code Generation (RACG) systems enhance code generation by dynamically integrating examples retrieved from open knowledge bases, but their reliance on external sources exposes them to knowledge poisoning. While prior attacks inject explicit vulnerable code, such payloads are easily detected, limiting their real-world impact and failing to probe the full attack surface. To overcome this limitation, we propose Arachne, a covert knowledge poisoning attack that, for the first time, achieves fine-grained control over vulnerability types while evading detection. Arachne relies on two mechanisms: (1) Benign-Appearing Fragment Construction, where vulnerable code is decomposed into benign-appearing fragments that pre serve compilability and contextual cues, rendering them effectively undetectable by vulnerability analyzers; and (2) Retrieval Driven Knowledge Completion, in which retrieved fragments activate the large language model's (LLM) contextual reasoning to autonomously generate complete vulnerable code. We evaluate Arachne on eight mainstream LLMs and four retrievers across four common vulnerability types. On GPT-4, Qwen2.5, Gemini 3-flash, Claude-4-sonnet and DeepSeekCoder, Arachne achieves attack success rates exceeding 70% in most settings for each vulnerability type across CWE-78, CWE-295, CWE-367, and CWE-614, peaking at 100% for CWE-367. Arachne demonstrates up to a 37% improvement in attack success rate over existing poisoning attacks. In two real-world applications, the attack achieves 87% success rate with 70% benign utility, indicating that the generated code often satisfies user requirements while introducing vulnerable code. Critically, our poisoned samples, which are designed without explicit malicious patterns, fully bypass rule-based analyzers and challenge state-of-the-art LLM based detectors, exemplifying their stealth among multiple failed defense paradigms. Our findings expose critical limitations in existing defense frameworks, highlighting the urgent need for novel defense mechanisms specifically designed for RACG systems. Xinlei He 0001, Tianshuo Cong, Ke Xu 0002, Qi Li 0002 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Vul-CTG: A Multimodal Framework for Software Vulnerability Detection via Code Text and Graph IntegrationabstractPretrained Language Models (PLMs) and Graph Neural Networks (GNNs) have emerged as promising approaches for software vulnerability detection. However, existing methods still face limitations, including the absence of fine-grained cross-modal interaction and the impact of data noise. Approaches integrating PLMs and GNNs fail to fully leverage their complementary strengths, while unreliable labels hinder generalization, further degrading real-world detection performance. To over-come these limitations, we propose Vul-CTG, a multimodal integration framework for software vulnerability detection that combines Code Text, and program Graph representations. Vul-CTG constructs enriched code graph representations by integrating statement-level source code graphs and abstract code property graphs, enabling more effective alignment between structural and semantic information. To enhance robustness against noisy labels and improve cross-modal consistency, the model incorporates contrastive learning and pre-training techniques. Central to Vul-CTG is CTG-Former, a novel alignment architecture that projects both code text and graph modalities into a unified latent space, allowing the model to capture complex structural and semantic patterns for more accurate vulnerability detection. Experimental results on recent function-level datasets demonstrate the effectiveness of Vul-CTG, showing an approximate 3% improvement in F1-score over state-of-the-art methods. Our code is available at https://github.com/ryxFry/Vul-CTG. Shuai Liu 0016, Qian Li 0024, Xinlei He 0001, Xiaoyu Zhang 0013, Chenhao Lin, Chao Shen 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | BadBone: Backdoor Attacks Against Backbone Models in Visual Prompt LearningabstractPrompt learning is a new machine learning paradigm that has attracted ample attention due to its simplicity and proven efficacy. Despite its growing adoption, the security vulnerabilities associated with this paradigm remain underexplored. In this work, we take the first step to propose BadBone, a stealthy and adaptive backdoor attack against prompt learning using bi-level optimization. Instead of backdooring the prompt learning process, we aim to compromise a backbone model such that only target downstream tasks employing prompt learning inherit the backdoor vulnerability. Extensive experiments on three different models and three datasets from various domains show that our targeted/untargeted backdoored models achieve high attack performance while maintaining utility on both pretraining and downstream tasks. Moreover, we evaluate our approach against six state-of-the-art model-level defenses, including Neural Cleanse, ABS, MNTD, NAD, CLP, and D-BR. The results demonstrate that these defenses are largely ineffective against our backdoored models and thus leave the effective defense as an important direction for future work. Our code is available at https://github.com/TrustAIRLab/BadBone. Ziqing Yang 0002, Rui Wen 0002, Xinlei He 0001, Michael Backes 0001, Yang Zhang 0016 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2026 | Building Trust Beyond Update Divergence: Dual-Refined Aggregation for Byzantine-Robust Federated LearningabstractFederated learning (FL) enables collaborative training across distributed clients but remains vulnerable to Byzantine attacks, especially stealthy ones. The threat is even amplified in non-IID settings, where client heterogeneity causes greater divergence in feature distributions and inter-client distances. Existing defenses often rely on strong assumptions or raw update distances, limiting their effectiveness under such heterogeneity. To address this gap, we proposeFedRefiner, a decoupled dual-refined aggregation algorithm designed to mitigate stealthy attacks on heterogeneous data. Our intuition is that the significance distribution of client updates reveals subtle malicious evasion, altering critical features for attack while perturbing unimportant ones, thereby exposing true inter-client distances.FedRefinergoes beyond norm-based filtering by refining both weighted scores and aggregated updates, enabling more accurate distinction between malicious behavior and benign non-IID variation. It first derives significance distribution vectors as refined updates by sparsity, then clusters them to compute weighted similarity scores for group reliability. These clusters then align raw updates into groups for group-wise refinement, yielding robust aggregated updates. We theoretically prove the convergence ofFedRefinerunder Byzantine attacks in non-IID settings. Extensive evaluation on 8 datasets against 10 attacks (including 2 adaptive ones) and 13 defenses shows thatFedRefineroutperforms state-of-the-art defenses, achieving up to a 10% gain in overall accuracy and a 14.8% improvement in worst-case performance under both IID and non-IID settings. Ablation studies further demonstrate its robustness across different hyperparameters, attacker ratios, data heterogeneity, and model/client scales, while incurring low computation and no storage overhead. Heyi Zhang, Xinlei He 0001, Jun Wu 0001, Qian Wang 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | CL-Attack: Textual Backdoor Attacks via Cross-Lingual TriggersabstractBackdoor attacks significantly compromise the security of large language models by triggering them to output specific and controlled content. Currently, triggers for textual backdoor attacks fall into two categories: fixed-token triggers and sentence-pattern triggers. However, the former are typically easy to identify and filter, while the latter, such as syntax and style, do not apply to all original samples and may lead to semantic shifts. In this paper, inspired by cross-lingual (CL) prompts of LLMs in real-world scenarios, we propose a higher-dimensional trigger method at the paragraph level, namely CL-Attack. CL-Attack injects the backdoor by using texts with specific structures that incorporate multiple languages, thereby offering greater stealthiness and universality compared to existing backdoor attack techniques. Extensive experiments on different tasks and model architectures demonstrate that CL-Attack can achieve nearly 100 percents attack success rate with a low poisoning rate in both classification and generation tasks. We also empirically show that CL-Attack is more robust against current major defense methods compared to baseline backdoor attacks. Additionally, in response to CL-Attack, we further develop a new defense called TranslateDefense, which can partially mitigate the impact of CL-Attack. Jingyi Zheng, Tianshuo Cong, Xinlei He 0001 |
AAAI | 4 |
| 2025 | Are We in the AI-Generated Text World Already? Quantifying and Monitoring AIGT on Social MediaabstractSocial media platforms are experiencing a growing presence of AI-Generated Texts (AIGTs). However, the misuse of AIGTs could have profound implications for public opinion, such as spreading misinformation and manipulating narratives. Despite its importance, it remains unclear how prevalent AIGTs are on social media. To address this gap, this paper aims to quantify and monitor the AIGTs on online social media platforms. We first collect a dataset (SM-D) with around 2.4M posts from 3 major social media platforms: Medium, Quora, and Reddit. Then, we construct a diverse dataset (AIGTBench) to train and evaluate AIGT detectors. AIGTBench combines popular open-source datasets and our AIGT datasets generated from social media texts by 12 LLMs, serving as a benchmark for evaluating mainstream detectors. With this setup, we identify the best-performing detector (OSM-Det). We then apply OSM-Det to SM-D to track AIGTs across social media platforms from January 2022 to October 2024, using the AI Attribution Rate (AAR) as the metric. Specifically, Medium and Quora exhibit marked increases in AAR, rising from 1.77% to 37.03% and 2.06% to 38.95%, respectively. In contrast, Reddit shows slower growth, with AAR increasing from 1.31% to 2.45% over the same period. Our further analysis indicates that AIGTs on social media differ from human-written texts across several dimensions, including linguistic patterns, topic distributions, engagement levels, and the follower distribution of authors. We envision our analysis and findings on AIGTs in social media can shed light on future research in this domain. Zhen Sun 0001, Zongmin Zhang, Xinyue Shen 0001, Yule Liu, Michael Backes 0001, Yang Zhang 0016, Xinlei He 0001 |
ACL (1) | 8 |
| 2025 | FacLens: Transferable Probe for Foreseeing Non-Factuality in Fact-Seeking Question Answering of Large Language ModelsabstractDespite advancements in large language models (LLMs), non-factual responses still persist in fact-seeking question answering.Unlike extensive studies on post-hoc detection of these responses, this work studies non-factuality prediction (NFP), predicting whether an LLM will generate a non-factual response prior to the response generation.Previous NFP methods have shown LLMs' awareness of their knowledge, but they face challenges in terms of efficiency and transferability.In this work, we propose a lightweight model named Factuality Lens (FacLens), which effectively probes hidden representations of fact-seeking questions for the NFP task.Moreover, we discover that hidden question representations sourced from different LLMs exhibit similar NFP patterns, enabling the transferability of FacLens across different LLMs to reduce development costs.Extensive experiments highlight FacLens's superiority in both effectiveness and efficiency. 1 Haoyang Li 0015, Jing Zhang 0001, Xinlei He 0001, Qi Li 0002, Ke Xu 0002 |
EMNLP | 5 |
| 2025 | Neeko: Model Hijacking Attacks Against Generative Adversarial NetworksabstractGenerative models have garnered significant interest in the realm of machine learning but are costly to produce and face growing regulatory constraints, requiring resource-heavy training and collaboration with various stakeholders, especially data providers. Such collaborative environments have given rise to a new threat known as model hijacking attacks. Adversaries can tamper with the training process to embed a hidden task, so that train/hijack high-end models at minimal costs or even sidestep regulations. In this paper, we extend the scope of model hijacking from classifiers to generative models by introducing the first model hijacking attack tailored for Generative Adversarial Networks (GANs), namely Neeko. Neeko is based on a novel U-Net-based Disguiser and allows a compromised GAN to generate authentic-looking images from its original distribution, but when downscaled, these images are visually changed to be from the hijacking dataset distribution. Through experiments on different image benchmark datasets, we demonstrate the efficacy and stealthiness of Neeko. Neeko poses security and accountability risks associated with training public GANs on potentially malicious or illegal datasets and raises concerns about evading those regulations addressing deepfakes and synthetic images. Junjie Chu 0002, Yugeng Liu, Xinlei He 0001, Michael Backes 0001, Yang Zhang 0016, Ahmed Salem 0001 |
ICME | 3 |
| 2025 | On the Generalization and Adaptation Ability of Machine-Generated Text Detectors in Academic WritingabstractThe rising popularity of large language models (LLMs) has raised concerns about potential abuse and harmful content. As a result, developing a highly generalizable and adaptable machine-generated text (MGT) detection system has become an urgent priority. Given that LLMs are most commonly misused in academic writing, this work investigates the generalization and adaptation capabilities of MGT detectors in three key aspects specific to academic writing: First, we construct MGT-Academic, a large-scale dataset comprising over 336M tokens and 749K samples. MGT-Academic focuses on academic writing, featuring human-written texts (HWTs) and MGTs across STEM, Humanities, and Social Sciences, paired with an extensible code framework for efficient benchmarking. Second, we benchmark the performance of various detectors for binary classification and text attribution tasks in both in-domain and cross-domain settings. This benchmark reveals the often-overlooked challenges of text attribution tasks. Third, we introduce a novel text attribution task in which models must adapt to new classes over time, with little or no access to prior training data, spanning both few-shot and many-shot scenarios. We implement a range of adaptation techniques to enhance performance across these settings. Our findings provide new insights into the generalization ability of MGT detectors and lay the foundation for building robust, adaptive detection systems. The code framework is available at https://github.com/Y-L-LIU/MGTBench-2.0. Yule Liu, Zhiyuan Zhong, Zhen Sun 0001, Jingyi Zheng, Jiaheng Wei, Qingyuan Gong, Fenghua Tong, Yang Chen 0001, Yang Zhang 0016, Xinlei He 0001 |
KDD (2) | 11 |
| 2025 | TH-Bench: Evaluating Evading Attacks via Humanizing AI Text on Machine-Generated Text DetectorsabstractAs Large Language Models (LLMs) advance, Machine-Generated Texts (MGTs) have become increasingly fluent, high-quality, and informative. Existing wide-range MGT detectors are designed to identify MGTs to prevent the spread of plagiarism and misinformation. However, adversaries attempt to humanize MGTs to evade detection (named evading attacks), which requires only minor modifications to bypass MGT detectors. Unfortunately, existing attacks generally lack a unified and comprehensive evaluation framework, as they are assessed using different experimental settings, model architectures, and datasets. To fill this gap, we introduce the Text-Humanization Benchmark (TH-Bench), the first comprehensive benchmark to evaluate evading attacks against MGT detectors. TH-Bench evaluate attacks across three key dimensions: evading effectiveness, text quality, and computational overhead. Our extensive experiments evaluate 6 state-of-the-art attacks against 13 MGT detectors across 6 datasets, spanning 19 domains and generated by 11 widely used LLMs. Our findings reveal that no single evading attack excels across all three dimensions. Through in-depth analysis, we highlight the strengths and limitations of different attacks. More importantly, we identify a trade-off among three dimensions and propose two optimization insights. Through preliminary experiments, we validate their correctness and effectiveness, offering potential directions for future research. Jingyi Zheng, Zhen Sun 0001, Wenhan Dong, Yule Liu, Xinlei He 0001 |
KDD (2) | 6 |
| 2025 | Privacy-Preserving Federated Learning via Homomorphic Adversarial Networks
Wenhan Dong, Chao Lin 0003, Xinlei He 0001, Shengmin Xu, Xinyi Huang 0001 |
KSEM (2) | 3 |
| 2025 | Safety Misalignment Against Large Language Models
Yichen Gong, Delong Ran, Xinlei He 0001, Tianshuo Cong, Anyu Wang 0001, Xiaoyun Wang 0001 |
NDSS | 3 |
| 2025 | CHASM: Unveiling Covert Advertisements on Chinese Social MediaabstractCurrent benchmarks for evaluating large language models (LLMs) in social media moderation completely overlook a serious threat: covert advertisements, which disguise themselves as regular posts to deceive and mislead consumers into making purchases, leading to significant ethical and legal concerns. In this paper, we present the CHASM, a first-of-its-kind dataset designed to evaluate the capability of Multimodal Large Language Models (MLLMs) in detecting covert advertisements on social media. CHASM is a high-quality, anonymized, manually curated dataset consisting of 4,992 instances, based on real-world scenarios from the Chinese social media platform Rednote. The dataset was collected and annotated under strict privacy protection and quality control protocols. It includes many product experience sharing posts that closely resemble covert advertisements, making the dataset particularly challenging.The results show that under both zero-shot and in-context learning settings, none of the current MLLMs are sufficiently reliable for detecting covert advertisements.Our further experiments revealed that fine-tuning open-source MLLMs on our dataset yielded noticeable performance gains. However, significant challenges persist, such as detecting subtle cues in comments and differences in visual and textual structures.We provide in-depth error analysis and outline future research directions. We hope our study can serve as a call for the research community and platform moderators to develop more precise defenses against this emerging threat. Jingyi Zheng, Yule Liu, Zhen Sun 0001, Zongmin Zhang, Zifan Peng, Wenhan Dong, Xinlei He 0001 |
NeurIPS | 8 |
| 2025 | PEFTGuard: Detecting Backdoor Attacks Against Parameter-Efficient Fine-TuningabstractFine-tuning is an essential process to improve the performance of Large Language Models (LLMs) in specific domains, with Parameter-Efficient Fine-Tuning (PEFT) gaining popularity due to its capacity to reduce computational demands through the integration of low-rank adapters. These lightweight adapters, such as LoRA, can be shared and utilized on open-source platforms. However, adversaries could exploit this mechanism to inject backdoors into these adapters, resulting in malicious behaviors like incorrect or harmful outputs, which pose serious security risks to the community. Unfortunately, few current efforts concentrate on analyzing the backdoor patterns or detecting the backdoors in the adapters. To fill this gap, we first construct and release PADBench, a comprehensive benchmark that contains 13, 300 benign and backdoored adapters fine-tuned with various datasets, attack strategies, PEFT methods, and LLMs. Moreover, we propose PEFTGuard, the first backdoor detection framework against PEFT-based adapters. Extensive evaluation upon PADBench shows that PEFTGuard outperforms existing detection methods, achieving nearly perfect detection accuracy (100%) in most cases. Notably, PEFTGuard exhibits zero-shot transferability on three aspects, including different attacks, PEFT methods, and adapter ranks. In addition, we consider various adaptive attacks to demonstrate the high robustness of PEFTGuard. We further explore several possible backdoor mitigation defenses, finding fine-mixing to be the most effective method. We envision that our benchmark and method can shed light on future LLM backdoor detection research.11Our code and dataset are available at: https://github.com/Vincent-HKUSTGZ/PEFTGuard. Zhen Sun 0001, Tianshuo Cong, Yule Liu, Chenhao Lin, Xinlei He 0001, Rongmao Chen, Xingshuo Han, Xinyi Huang 0001 |
SP | 5 |
| 2025 | Unsafe LLM-Based Search: Quantitative Analysis and Mitigation of Safety Risks in AI Web Search
Zeren Luo, Zifan Peng, Yule Liu, Zhen Sun 0001, Jingyi Zheng, Xinlei He 0001 |
USENIX Security Symposium | 7 |
| 2025 | From Purity to Peril: Backdooring Merged Models From "Harmless" Benign Components
Lijin Wang, Tianshuo Cong, Xinlei He 0001, Zhan Qin, Xinyi Huang 0001 |
USENIX Security Symposium | 4 |
| 2025 | Artificial intelligence security and privacy: a surveyabstractAbstract Artificial intelligence (AI) is revolutionizing both industries and reshaping the global economy. However, the rapid advancement of AI technologies brings significant security and privacy challenges. Recent incidents highlight vulnerabilities in AI systems, such as data leakage and malicious code injection, leading to severe financial losses and privacy breaches. Although existing studies have discussed specific security threats, they often lack detailed granularity and cover a limited scope. In this survey, we fill this gap by systematically categorizing and analyzing the threats and countermeasures in AI systems, which span both the training and inference stages, encompass centralized and distributed settings, and address both conventional and foundation AI models. By reviewing existing literature, we aim to provide AI researchers and practitioners with a thorough understanding of system vulnerabilities and current countermeasures. We hope to inspire further research into robust solutions, ultimately contributing to the development of resilient AI technologies. Xinlei He 0001, Guowen Xu, Xingshuo Han, Qian Wang 0002, Lingchen Zhao, Chao Shen 0001, Chenhao Lin, Zhengyu Zhao 0001, Qian Li 0024, Le Yang 0007, Shouling Ji, Shaofeng Li 0001, Haojin Zhu, Zhibo Wang 0001, Tianqing Zhu, Qi Li 0002, Chaoxiang He, Hongsheng Hu, Shuo Wang 0012, Shifeng Sun 0001, Hongwei Yao, Qinyu Zhang 0001, Kai Chen 0012, Yue Zhao 0027, Hongwei Li 0001, Xinyi Huang 0001, Dengguo Feng |
Sci. China Inf. Sci. | 1 |
| 2025 | A Comprehensive Study of Privacy Risks in Curriculum LearningabstractTraining a machine learning model with data following a meaningful order, i.e., from easy to hard, has been proven to be effective in accelerating the training process and achieving better model performance. The key enabling technique is curriculum learning (CL), which has seen great success and has been deployed in areas like image and text classification. Yet, how CL affects the privacy of machine learning is unclear. Given that CL changes the way a model memorizes the training data, its influence on data privacy needs to be thoroughly evaluated. To fill this knowledge gap, we perform the first study and leverage membership inference attack (MIA) and attribute inference attack (AIA) as two vectors to quantify the privacy leakage caused by CL. Our evaluation of 9 real-world datasets with attack methods (NN-based, metric-based, label-only MIA, and NN-based AIA) revealed new insights about CL. First, MIA becomes slightly more effective when CL is applied, but the impact is much more prominent to a subset of training samples ranked as difficult. Second, a model trained under CL is less vulnerable under AIA, compared to MIA. Third, the existing defense techniques like MemGuard and MixupMMD are not effective under CL. Finally, based on our insights into CL, we propose a new MIA, termed Diff-Cali, which exploits the difficulty scores for result calibration and is demonstrated to be effective against all CL methods and the normal training method. With this study, we hope to draw the community's attention to the unintended privacy risks of emerging machine-learning techniques and develop new attack benchmarks and defense solutions. Joann Qiongna Chen, Xinlei He 0001, Zheng Li 0023, Yang Zhang 0016, Zhou Li 0001 |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | MGTBench: Benchmarking Machine-Generated Text DetectionabstractNowadays, powerful large language models (LLMs) such as ChatGPT have demonstrated revolutionary power in a variety of natural language processing (NLP) tasks such as text classification, sentiment analysis, language translation, and question-answering. Consequently, the detection of machine-generated texts (MGTs) is becoming increasingly crucial as LLMs become more advanced and prevalent. These models have the ability to generate human-like language, making it challenging to discern whether a text is authored by a human or a machine. This raises concerns regarding authenticity, accountability, and potential bias. However, existing methods for detecting MGTs are evaluated using different model architectures, datasets, and experimental settings, resulting in a lack of a comprehensive evaluation framework that encompasses various methodologies. Furthermore, it remains unclear how existing detection methods would perform against powerful LLMs. Xinlei He 0001, Xinyue Shen 0001, Zeyuan Chen 0002, Michael Backes 0001, Yang Zhang 0016 |
CCS | 1 |
| 2024 | Test-Time Poisoning Attacks Against Test-Time Adaptation ModelsabstractDeploying machine learning (ML) models in the wild is challenging as it suffers from distribution shifts, where the model trained on an original domain cannot generalize well to unforeseen diverse transfer domains. To address this challenge, several test-time adaptation (TTA) methods have been proposed to improve the generalization ability of the target pre-trained models under test data to cope with the shifted distribution. The success of TTA can be credited to the continuous fine-tuning of the target model according to the distributional hint from the test samples during test time. Despite being powerful, it also opens a new attack surface, i.e., test-time poisoning attacks, which are substantially different from previous poisoning attacks that occur during the training time of ML models (i.e., adversaries cannot intervene in the training process). In this paper, we perform the first test-time poisoning attack against four mainstream TTA methods, including TTT, DUA, TENT, and RPL. Concretely, we generate poisoned samples based on the surrogate models and feed them to the target TTA models. Experimental results show that the TTA methods are generally vulnerable to test-time poisoning attacks. For instance, the adversary can feed as few as 10 poisoned samples to degrade the performance of the target model from 76.20% to 41.83%. Our results demonstrate that TTA algorithms lacking a rigorous security assessment are unsuitable for deployment in real-life scenarios. As such, we advocate for the integration of defenses against test-time poisoning attacks into the design of TTA methods.1 Tianshuo Cong, Xinlei He 0001, Yang Zhang 0016 |
SP | 2 |
| 2024 | You Only Prompt Once: On the Capabilities of Prompt Learning on Large Language Models to Tackle Toxic ContentabstractThe spread of toxic content online is an important problem that has adverse effects on user experience online and in our society at large. Motivated by the importance and impact of the problem, research focuses on developing solutions to detect toxic content, usually leveraging machine learning (ML) models trained on human-annotated datasets. While these efforts are important, these models usually do not generalize well and they can not cope with new trends (e.g., the emergence of new toxic terms). Currently, we are witnessing a shift in the approach to tackling societal issues online, particularly leveraging large language models (LLMs) like GPT-3 or T5 that are trained on vast corpora and have strong generalizability. In this work, we investigate how we can use LLMs and prompt learning to tackle the problem of toxic content, particularly focusing on three tasks; 1) Toxicity Classification, 2) Toxic Span Detection, and 3) Detoxification. We perform an extensive evaluation over five model architectures and eight datasets demonstrating that LLMs with prompt learning can achieve similar or even better performance compared to models trained on these specific tasks. We find that prompt learning achieves around 10% improvement in the toxicity classification task compared to the baselines, while for the toxic span detection task we find better performance to the best baseline (0.643 vs. 0.640 in terms of F1-score). Finally, for the detoxification task, we find that prompt learning can successfully reduce the average toxicity score (from 0.775 to 0.213) while preserving semantic meaning.1 Xinlei He 0001, Savvas Zannettou, Yang Zhang 0016 |
SP | 1 |
| 2024 | SecurityNet: Assessing Machine Learning Vulnerabilities on Public Models
Boyang Zhang 0008, Zheng Li 0023, Ziqing Yang 0002, Xinlei He 0001, Michael Backes 0001, Mario Fritz, Yang Zhang 0016 |
USENIX Security Symposium | 4 |
| 2024 | Link Stealing Attacks Against Inductive Graph Neural NetworksabstractA graph neural network (GNN) is a type of neural network that is specifically designed to process graph-structured data. Typically, GNNs can be implemented in two settings, including the transductive setting and the inductive setting. In the transductive setting, the trained model can only predict the labels of nodes that were observed at the training time. In the inductive setting, the trained model can be generalized to new nodes/graphs. Due to its flexibility, the inductive setting is the most popular GNN setting at the moment. Previous work has shown that transductive GNNs are vulnerable to a series of privacy attacks. However, a comprehensive privacy analysis of inductive GNN models is still missing. This paper fills the gap by conducting a systematic privacy analysis of inductive GNNs through the lens of link stealing attacks. We propose two types of link stealing attacks, i.e., posterior-only attacks and combined attacks. We define threat models of the posterior-only attacks with respect to node topology and the combined attacks by considering combinations of posteriors, node attributes, and graph features. Extensive evaluation on six real-world datasets demonstrates that inductive GNNs leak rich information that enables link stealing attacks with advantageous properties. Even attacks with no knowledge about graph structures can be effective. We also show that our attacks are robust to different node similarities and different graph features. As a counterpart, we investigate two possible defenses and discover they are ineffective against our attacks, which calls for more effective defenses. Yixin Wu 0001, Xinlei He 0001, Pascal Berrang, Mathias Humbert, Michael Backes 0001, Neil Zhenqiang Gong, Yang Zhang 0016 |
Proc. Priv. Enhancing Technol. | 2 |
| 2023 | Unsafe Diffusion: On the Generation of Unsafe Images and Hateful Memes From Text-To-Image ModelsabstractState-of-the-art Text-to-Image models like Stable Diffusion and DALLE\cdot2 are revolutionizing how people generate visual content. At the same time, society has serious concerns about how adversaries can exploit such models to generate problematic or unsafe images. In this work, we focus on demystifying the generation of unsafe images and hateful memes from Text-to-Image models. We first construct a typology of unsafe images consisting of five categories (sexually explicit, violent, disturbing, hateful, and political). Then, we assess the proportion of unsafe images generated by four advanced Text-to-Image models using four prompt datasets. We find that Text-to-Image models can generate a substantial percentage of unsafe images; across four models and four prompt datasets, 14.56% of all generated images are unsafe. When comparing the four Text-to-Image models, we find different risk levels, with Stable Diffusion being the most prone to generating unsafe content (18.92% of all generated images are unsafe). Given Stable Diffusion's tendency to generate more unsafe content, we evaluate its potential to generate hateful meme variants if exploited by an adversary to attack a specific individual or community. We employ three image editing methods, DreamBooth, Textual Inversion, and SDEdit, which are supported by Stable Diffusion to generate variants. Our evaluation result shows that 24% of the generated images using DreamBooth are hateful meme variants that present the features of the original hateful meme and the target individual/community; these generated images are comparable to hateful meme variants collected from the real world. Overall, our results demonstrate that the danger of large-scale generation of unsafe images is imminent. We discuss several mitigating measures, such as curating training data, regulating prompts, and implementing safety filters, and encourage better safeguard tools to be developed to prevent unsafe generation.1 Our code is available at https://github.com/YitingQu/unsafe-diffusion. Yiting Qu, Xinyue Shen 0001, Xinlei He 0001, Michael Backes 0001, Savvas Zannettou, Yang Zhang 0016 |
CCS | 3 |
| 2023 | Can't Steal? Cont-Steal! Contrastive Stealing Attacks Against Image EncodersabstractSelf-supervised representation learning techniques have been developing rapidly to make full use of unlabeled images. They encode images into rich features that are oblivious to downstream tasks. Behind their revolutionary representation power, the requirements for dedicated model designs and a massive amount of computation resources expose image encoders to the risks of potential model stealing attacks - a cheap way to mimic the well-trained encoder performance while circumventing the demanding requirements. Yet conventional attacks only target supervised classifiers given their predicted labels and/or posteriors, which leaves the vulnerability of unsupervised encoders unexplored. In this paper, we first instantiate the conventional stealing attacks against encoders and demonstrate their severer vulnerability compared with downstream classifiers. To better leverage the rich representation of encoders, we further propose Cont-Steal, a contrastive-learning-based attack, and validate its improved stealing effectiveness in various experiment settings. As a takeaway, we appeal to our community's attention to the intellectual property protection of representation learning techniques, especially to the defenses against encoder stealing attacks like ours.11See our code in https://github.com/zeyangsha/Cont-Steal. Zeyang Sha, Xinlei He 0001, Ning Yu 0006, Michael Backes 0001, Yang Zhang 0016 |
CVPR | 2 |
| 2023 | Data Poisoning Attacks Against Multimodal EncodersabstractRecently, the newly emerged multimodal models, which leverage both visual and linguistic modalities to train powerful encoders, have gained increasing attention. However, learning from a large-scale unlabeled dataset also exposes the model to the risk of potential poisoning attacks, whereby the adversary aims to perturb the model’s training data to trigger malicious behaviors in it. In contrast to previous work, only poisoning visual modality, in this work, we take the first step to studying poisoning attacks against multimodal models in both visual and linguistic modalities. Specially, we focus on answering two questions: (1) Is the linguistic modality also vulnerable to poisoning attacks? and (2) Which modality is most vulnerable? To answer the two questions, we propose three types of poisoning attacks against multimodal models. Extensive evaluations on different datasets and model architectures show that all three attacks can achieve significant attack performance while maintaining model utility in both visual and linguistic modalities. Furthermore, we observe that the poisoning effect differs between different modalities. To mitigate the attacks, we propose both pre-training and post-training defenses. We empirically show that both defenses can significantly reduce the attack performance while preserving the model’s utility. Our code is available at https://github.com/zqypku/mm_poison/. Ziqing Yang 0002, Xinlei He 0001, Zheng Li 0023, Michael Backes 0001, Mathias Humbert, Pascal Berrang, Yang Zhang 0016 |
ICML | 2 |
| 2023 | Generated Graph DetectionabstractGraph generative models become increasingly effective for data distribution approximation and data augmentation. While they have aroused public concerns about their malicious misuses or misinformation broadcasts, just as what Deepfake visual and auditory media has been delivering to society. Hence it is essential to regulate the prevalence of generated graphs. To tackle this problem, we pioneer the formulation of the generated graph detection problem to distinguish generated graphs from real ones. We propose the first framework to systematically investigate a set of sophisticated models and their performance in four classification scenarios. Each scenario switches between seen and unseen datasets/generators during testing to get closer to real-world settings and progressively challenge the classifiers. Extensive experiments evidence that all the models are qualified for generated graph detection, with specific models having advantages in specific scenarios. Resulting from the validated generality and oblivion of the classifiers to unseen datasets/generators, we draw a safe conclusion that our solution can sustain for a decent while to curb generated graph misuses. Yihan Ma 0001, Zhikun Zhang 0001, Ning Yu 0006, Xinlei He 0001, Michael Backes 0001, Yang Zhang 0016 |
ICML | 4 |
| 2023 | On the Evolution of (Hateful) Memes by Means of Multimodal Contrastive LearningabstractThe dissemination of hateful memes online has adverse effects on social media platforms and the real world. Detecting hateful memes is challenging, one of the reasons being the evolutionary nature of memes; new hateful memes can emerge by fusing hateful connotations with other cultural ideas or symbols. In this paper, we propose a framework that leverages multimodal contrastive learning models, in particular OpenAI’s CLIP, to identify targets of hateful content and systematically investigate the evolution of hateful memes. We find that semantic regularities exist in CLIP-generated embeddings that describe semantic relationships within the same modality (images) or across modalities (images and text). Leveraging this property, we study how hateful memes are created by combining visual elements from multiple images or fusing textual information with a hateful image. We demonstrate the capabilities of our framework for analyzing the evolution of hateful memes by focusing on antisemitic memes, particularly the Happy Merchant meme. Using our framework on a dataset extracted from 4chan, we find 3.3K variants of the Happy Merchant meme, with some linked to specific countries, persons, or organizations. We envision that our framework can be used to aid human moderators by flagging new variants of hateful memes so that moderators can manually verify them and mitigate the problem of hateful content online.1 Yiting Qu, Xinlei He 0001, Shannon Pierson, Michael Backes 0001, Yang Zhang 0016, Savvas Zannettou |
SP | 2 |
| 2023 | A Plot is Worth a Thousand Words: Model Information Stealing Attacks via Scientific Plots
Boyang Zhang 0008, Xinlei He 0001, Tianhao Wang 0001, Yang Zhang 0016 |
USENIX Security Symposium | 2 |
| 2023 | Trimming Mobile Applications for Bandwidth-Challenged Networks in Developing RegionsabstractDespite continuous efforts to build and update mobile network infrastructure, mobile devices in developing regions continue to be constrained by limited bandwidth. Unfortunately, this coincides with a period of unprecedented growth in the sizes of mobile applications. Thus it is becoming prohibitively expensive for users in developing regions to download and update mobile apps critical to their economic and educational development. Unchecked, these trends can further contribute to a large and growing global digital divide. Our goal is to better understand the source of this rapid growth in mobile app code size, whether it is reflective of new functionality, and identify steps that can be taken to make existing mobile apps more friendly to bandwidth constrained mobile networks. We hypothesize that much of this growth in mobile apps is due to poor resource/code management, and do not reflect proportional increases in functionality. Our hypothesis is partially validated by mini-programs, apps with extremely small footprints gaining popularity in Chinese mobile platforms. Here, we use functionally equivalent pairs of mini-programs and Android apps to identify potential sources of “bloat,” i.e., inefficient uses of code or resources that contribute to large package sizes. We analyze a large sample of popular Android apps and quantify instances of code and resource bloat. We develop techniques for automated code and resource trimming, and successfully validate them on a large set of Android apps. We hope our results will lead to continued efforts to streamline mobile apps, making them easier to access and maintain for users in developing regions. Qinge Xie, Qingyuan Gong, Xinlei He 0001, Yang Chen 0001, Xin Wang 0002, Haitao Zheng 0001, Ben Y. Zhao |
IEEE Trans. Mob. Comput. | 3 |
| 2022 | SSLGuard: A Watermarking Scheme for Self-supervised Learning Pre-trained EncodersabstractSelf-supervised learning is an emerging machine learning (ML) paradigm. Compared to supervised learning which leverages high-quality labeled datasets, self-supervised learning relies on unlabeled datasets to pre-train powerful encoders which can then be treated as feature extractors for various downstream tasks. The huge amount of data and computational resources consumption makes the encoders themselves become the valuable intellectual property of the model owner. Recent research has shown that the ML model's copyright is threatened by model stealing attacks, which aim to train a surrogate model to mimic the behavior of a given model. We empirically show that pre-trained encoders are highly vulnerable to model stealing attacks. However, most of the current efforts of copyright protection algorithms such as watermarking concentrate on classifiers. Meanwhile, the intrinsic challenges of pre-trained encoder's copyright protection remain largely unstudied. We fill the gap by proposing SSLGuard, the first watermarking scheme for pre-trained encoders. Given a clean pre-trained encoder, SSLGuard injects a watermark into it and outputs a watermarked version. The shadow training technique is also applied to preserve the watermark under potential model stealing attacks. Our extensive evaluation shows that SSLGuard is effective in watermark injection and verification, and it is robust against model stealing and other watermark removal attacks such as input noising, output perturbing, overwriting, model pruning, and fine-tuning. Tianshuo Cong, Xinlei He 0001, Yang Zhang 0016 |
CCS | 2 |
| 2022 | Auditing Membership Leakages of Multi-Exit NetworksabstractRelying on the truth that not all inputs require the same level of computational cost to produce reliable predictions, multi-exit networks are gaining attention as a prominent approach for pushing the limits of efficient deployment. Multi-exit networks endow a backbone model with early exits, allowing predictions at intermediate layers of the model and thus saving computation time and energy. However, various current designs of multi-exit networks are only considered to achieve the best trade-off between resource usage efficiency and prediction accuracy, the privacy risks stemming from them have never been explored. This prompts the need for a comprehensive investigation of privacy risks in multi-exit networks. Zheng Li 0023, Yiyong Liu, Xinlei He 0001, Ning Yu 0006, Michael Backes 0001, Yang Zhang 0016 |
CCS | 3 |
| 2022 | Semi-Leak: Membership Inference Attacks Against Semi-supervised Learning
Xinlei He 0001, Hongbin Liu 0005, Neil Zhenqiang Gong, Yang Zhang 0016 |
ECCV (31) | 1 |
| 2022 | On Xing Tian and the Perseverance of Anti-China Sentiment Online
Xinyue Shen 0001, Xinlei He 0001, Michael Backes 0001, Jeremy Blackburn, Savvas Zannettou, Yang Zhang 0016 |
ICWSM | 2 |
| 2022 | Model Stealing Attacks Against Inductive Graph Neural NetworksabstractMany real-world data come in the form of graphs. Graph neural networks (GNNs), a new family of machine learning (ML) models, have been proposed to fully leverage graph data to build powerful applications. In particular, the inductive GNNs, which can generalize to unseen data, become mainstream in this direction. Machine learning models have shown great potential in various tasks and have been deployed in many real-world scenarios. To train a good model, a large amount of data as well as computational resources are needed, leading to valuable intellectual property. Previous research has shown that ML models are prone to model stealing attacks, which aim to steal the functionality of the target models. However, most of them focus on the models trained with images and texts. On the other hand, little attention has been paid to models trained with graph data, i.e., GNNs. In this paper, we fill the gap by proposing the first model stealing attacks against inductive GNNs. We systematically define the threat model and propose six attacks based on the adversary’s background knowledge and the responses of the target models. Our evaluation on six benchmark datasets shows that the proposed model stealing attacks against GNNs achieve promising performance.1 Xinlei He 0001, Yufei Han 0001, Yang Zhang 0016 |
SP | 2 |
| 2022 | ML-Doctor: Holistic Risk Assessment of Inference Attacks Against Machine Learning Models
Yugeng Liu, Rui Wen 0002, Xinlei He 0001, Ahmed Salem 0001, Zhikun Zhang 0001, Michael Backes 0001, Emiliano De Cristofaro, Mario Fritz, Yang Zhang 0016 |
USENIX Security Symposium | 3 |
| 2021 | Quantifying and Mitigating Privacy Risks of Contrastive LearningabstractData is the key factor to drive the development of machine learning (ML) during the past decade. However, high-quality data, in particular labeled data, is often hard and expensive to collect. To leverage large-scale unlabeled data, self-supervised learning, represented by contrastive learning, is introduced. The objective of contrastive learning is to map different views derived from a training sample (e.g., through data augmentation) closer in their representation space, while different views derived from different samples more distant. In this way, a contrastive model learns to generate informative representations for data samples, which are then used to perform downstream ML tasks. Recent research has shown that machine learning models are vulnerable to various privacy attacks. However, most of the current efforts concentrate on models trained with supervised learning. Meanwhile, data samples' informative representations learned with contrastive learning may cause severe privacy risks as well. In this paper, we perform the first privacy analysis of contrastive learning through the lens of membership inference and attribute inference. Our experimental results show that contrastive models trained on image datasets are less vulnerable to membership inference attacks but more vulnerable to attribute inference attacks compared to supervised models. The former is due to the fact that contrastive models are less prone to overfitting, while the latter is caused by contrastive models' capability of representing data samples expressively. To remedy this situation, we propose the first privacy-preserving contrastive learning mechanism, Talos, relying on adversarial training. Empirical results show that Talos can successfully mitigate attribute inference risks for contrastive models while maintaining their membership privacy and model utility. Xinlei He 0001, Yang Zhang 0016 |
CCS | 1 |
| 2021 | Stealing Links from Graph Neural Networks
Xinlei He 0001, Jinyuan Jia 0001, Michael Backes 0001, Neil Zhenqiang Gong, Yang Zhang 0016 |
USENIX Security Symposium | 1 |
| 2021 | DatingSec: Detecting Malicious Accounts in Dating Apps Using a Content-Based Attention NetworkabstractDating apps have gained tremendous popularity during the past decade. Compared with traditional offline dating means, dating apps ease the process of partner finding significantly. While bringing convenience to hundreds of millions of users, dating apps are vulnerable to become targets of adversaries. In this article, we focus on malicious user detection in dating apps. Existing methods overlooked the signals hidden in the textual information of user interactions, particularly the interplay of temporal-spatial behaviors and textual information, leading to limited detection performance. To tackle this, we propose DatingSec, a novel malicious user detection system for dating apps. Concretely, DatingSec leverages long short-term memory neural networks (LSTM) and an attentive module to capture the interplay of users' temporal-spatial behaviors and user-generated textual content. We evaluate DatingSec on a real-world dataset collected from Momo, a widely used dating app with more than 180 million users. Experimental results show that DatingSec outperforms state-of-the-art methods and achieves an F1-score of 0.857 and AUC of 0.940. Xinlei He 0001, Qingyuan Gong, Yang Chen 0001, Yang Zhang 0016, Xin Wang 0002, Xiaoming Fu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2021 | Cross-site Prediction on Social Influence for Cold-start Users in Online Social NetworksabstractOnline social networks (OSNs) have become a commodity in our daily life. As an important concept in sociology and viral marketing, the study of social influence has received a lot of attentions in academia. Most of the existing proposals work well on dominant OSNs, such as Twitter, since these sites are mature and many users have generated a large amount of data for the calculation of social influence. Unfortunately, cold-start users on emerging OSNs generate much less activity data, which makes it challenging to identify potential influential users among them. In this work, we propose a practical solution to predict whether a cold-start user will become an influential user on an emerging OSN, by opportunistically leveraging the user’s information on dominant OSNs. A supervised machine learning-based approach is adopted, transferring the knowledge of both the descriptive information and dynamic activities on dominant OSNs. Descriptive features are extracted from the public data on a user’s homepage. In particular, to extract useful information from the fine-grained dynamic activities that cannot be represented by the statistical indices, we use deep learning technologies to deal with the sequential activity data. Using the real data of millions of users collected from Twitter (a dominant OSN) and Medium (an emerging OSN), we evaluate the performance of our proposed framework to predict prospective influential users. Our system achieves a high prediction performance based on different social influence definitions. Qingyuan Gong, Yang Chen 0001, Xinlei He 0001, Yu Xiao 0001, Pan Hui 0001, Xin Wang 0002, Xiaoming Fu 0001 |
ACM Trans. Web | 3 |
| 2018 | Deep Learning-Based Malicious Account Detection in the Momo Social NetworkabstractDue to the rapid development of mobile devices and location-based services, location-based social networks (LBSNs) have become very popular in our daily-life. Malicious account detection is very helpful for different kinds of practical applications. In this paper, we explore the malicious account detection problem by introducing a deep learning-based framework. By using the long short-term memory (LSTM) neural network, we are able to build a classifier to achieve the binary classification. By using the real data collected from Momo, a widely used LBSN which has more than 180 million users around the world, we evaluate our framework and the result shows great promise for malicious account detection tasks. Xinlei He 0001, Qingyuan Gong, Yang Chen 0001, Tianyi Wang 0001, Xin Wang 0002 |
ICCCN | 2 |