Ruyi Ding

dblp:228/7706 · DBLP profile ↗
← Back
13ranked-venue papers
7as first author
13since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 4 · 2 first-author · 4 since 2021Security and privacy · 4 · 3 first-author · 4 since 2021Systems, architecture and hardware · 3 · 2 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 MoEcho: Exploiting Side-Channel Attacks to Compromise User Privacy in Mixture-of-Experts LLMs
abstract
The transformer architecture has become a cornerstone of modern AI, fueling remarkable progress across applications in natural language processing, computer vision, and multi-modal learning.As these models continue to scale explosively for performance, implementation efficiency remains a critical challenge.Mixtureof-Experts (MoE) architectures, selectively activating specialized subnetworks (experts), offer a unique balance between model accuracy and computational cost.However, the adaptive routing in MoE architectures-where input tokens are dynamically directed to specialized experts based on their semantic meaning-inadvertently opens up a new attack surface for privacy breaches.These inputdependent activation patterns leave distinctive temporal and spatial traces in hardware execution, which adversaries could exploit to deduce sensitive user data.In this work, we propose MoEcho (MoE-Echo), discovering a side-channel analysis-based attack surface that compromises user privacy on MoE-based systems.Specifically, in MoEcho, we introduce four novel architectural side-channels on different computing platforms, including Cache Occupancy Channels and Pageout+Reload on CPUs, and Performance Counter and TLB Evict+Reload on GPUs, respectively.Exploiting these vulnerabilities, we propose four attacks that effectively breach user privacy in large-language models (LLMs) and vision-language models (VLMs) based on MoE architectures: Prompt Inference Attack, Response Reconstruction Attack, Visual Inference Attack, and Visual Reconstruction Attack.We evaluate MoEcho on four open-source MoE-based models at different scales, with a specific focus on the DeepSeek architecture.Our end-to-end experiments on both CPUand GPU-deployed MoE models demonstrate a 99.8% success rate in inferring the patient's private inputs in healthcare records and 92.8% in reconstructing LLM responses.MoEcho is the first run-time * These authors contributed equally.
Ruyi Ding, Tianhong Xu, A. Adam Ding, Yunsi Fei
CCS1
2025 Graph in the Vault: Protecting Edge GNN Inference with Trusted Execution Environment
abstract
Wide deployment of machine learning models on edge devices has rendered the model intellectual property (IP) and data privacy vulnerable. We propose GNNVault, the first secure Graph Neural Network (GNN) deployment strategy based on Trusted Execution Environment (TEE). GNNVault follows the design of “partition-before-training” and includes a private GNN rectifier to complement with a public backbone model. This way, both critical GNN model parameters and the private graph used during inference are protected within secure TEE compartments. Real-world implementations with Intel SGX demonstrate that GNNVault safeguards GNN inference against state-of-the-art link stealing attacks with a negligible accuracy degradation ($\lt 2 \%$).
Ruyi Ding, Tianhong Xu, A. Adam Ding, Yunsi Fei
DAC1
2025 Probe-Me-Not: Protecting Pre-trained Encoders from Malicious Probing
Ruyi Ding, Tong Zhou 0002, Lili Su, A. Adam Ding, Xiaolin Xu 0001, Yunsi Fei
NDSS1
2024 Non-transferable Pruning
Ruyi Ding, Lili Su, A. Adam Ding, Yunsi Fei
ECCV (86)1
2024 GraphCroc: Cross-Correlation Autoencoder for Graph Structural Reconstruction
abstract
Graph-structured data is integral to many applications, prompting the development of various graph representation methods. Graph autoencoders (GAEs), in particular, reconstruct graph structures from node embeddings. Current GAE models primarily utilize self-correlation to represent graph structures and focus on node-level tasks, often overlooking multi-graph scenarios. Our theoretical analysis indicates that self-correlation generally falls short in accurately representing specific graph features such as islands, symmetrical structures, and directional edges, particularly in smaller or multiple graph contexts.To address these limitations, we introduce a cross-correlation mechanism that significantly enhances the GAE representational capabilities. Additionally, we propose the GraphCroc, a new GAE that supports flexible encoder architectures tailored for various downstream tasks and ensures robust structural reconstruction, through a mirrored encoding-decoding process. This model also tackles the challenge of representation bias during optimization by implementing a loss-balancing strategy. Both theoretical analysis and numerical evaluations demonstrate that our methodology significantly outperforms existing self-correlation-based GAEs in graph structure reconstruction.
Shijin Duan, Ruyi Ding, A. Adam Ding, Yunsi Fei, Xiaolin Xu 0001
NeurIPS2
2023 EMShepherd: Detecting Adversarial Samples via Side-channel Leakage
abstract
Deep Neural Networks (DNN) are vulnerable to adversarial perturbations — small changes crafted deliberately on the input to mislead the model for wrong predictions. Adversarial attacks have disastrous consequences for deep learning empowered critical applications. Existing defense and detection techniques both require extensive knowledge of the model, testing inputs and even execution details. They are not viable for general deep learning implementations where the model internal is unknown, a common ‘black-box’ scenario for model users. Inspired by the fact that electromagnetic (EM) emanations of a model inference are dependent on both operations and data and may contain footprints of different input classes, we propose a framework, EMShepherd, to capture EM traces of model execution, perform processing on traces and exploit them for adversarial detection. Only benign samples and their EM traces are used to train the adversarial detector: a set of EM classifiers and class-specific unsupervised anomaly detectors. When the victim model system is under attack by an adversarial example, the model execution will be different from executions for the known classes, and the EM trace will be different. We demonstrate that our air-gapped EMShepherd can effectively detect different adversarial attacks on a commonly used FPGA deep learning accelerator for both Fashion MNIST and CIFAR-10 datasets. It achieves a detection rate on most types of adversarial samples, which is comparable to the state-of-the-art ‘white-box’ software-based detectors.
Ruyi Ding, Cheng Gongye, Siyue Wang, A. Adam Ding, Yunsi Fei
AsiaCCS1
2023 VertexSerum: Poisoning Graph Neural Networks for Link Inference
abstract
Graph neural networks (GNNs) have brought superb performance to various applications utilizing graph structural data, such as social analysis and fraud detection. The graph links, e.g., social relationships and transaction history, are sensitive and valuable information, which raises privacy concerns when using GNNs. To exploit these vulnerabilities, we propose VertexSerum, a novel graph poisoning attack that increases the effectiveness of graph link stealing by amplifying the link connectivity leakage. To infer node adjacency more accurately, we propose an attention mechanism that can be embedded into the link detection network. Our experiments demonstrate that VertexSerum significantly outperforms the SOTA link inference attack, improving the AUC scores by an average of 9.8% across four real-world datasets and three different GNN structures. Furthermore, our experiments reveal the effectiveness of VertexSerum in both black-box and online learning settings, further validating its applicability in real-world scenarios. The source code is available at https://github.com/RollinDing/VertexSerum.
Ruyi Ding, Shijin Duan, Xiaolin Xu 0001, Yunsi Fei
ICCV1
2023 Focusing on Needs: A Chatbot-Based Emotion Regulation Tool for Adolescents
abstract
Adolescents face much psychological stress in the current social environment, and effective emotional regulation is crucial to their mental health. This article introduces a paradigm of product-oriented psychological dialogue, that is, to study psychological problems first, determine user needs and the most effective way of action, and then develop tools based on this paradigm. We use the above paradigm to build an artificial intelligence-based adolescent emotion adjust the con-versational bot. Specifically, to explore adolescents' emotional regulation needs, this study collected the required data (n=317, 5,543 questionnaires) through the intensive tracking method. It revealed the mechanism of user needs and emotion regulation. Emotion regulation strategy weighting mechanism, and using the collected raw data and existing emotion support dialogue datasets (ESConv), a Chinese adolescent emotion regulation dia-logue dataset was constructed. After that, this paper fine-tunes the existing dialogue model (GPT-2 chitchat). Through these improvements, the dialogue model has dramatically improved its performance and can also provide more personalized and effective emotional regulation support according to the actual needs of adolescents. In summary, this study provides new ideas and methods for mental health support, and promotes the research and development of emotional regulation support for adolescents.
Yeming Ni, Ruyi Ding, Hanchao Hou, Shiguang Ni
SMC2
2023 FaultMorse: An automated controlled-channel attack via longest recurring sequence
Lifeng Hu, Fan Zhang 0010, Ziyuan Liang, Ruyi Ding, Xingyu Cai, Zonghui Wang, Wenguang Jin
Comput. Secur.4
2022 A Cross-Platform Cache Timing Attack Framework via Deep Learning
abstract
While deep learning methods have been adopted in power side-channel analysis, they have not been applied to cache timing attacks due to the limited dimension of cache timing data. This paper proposes a persistent cache monitor based on cache line flushing instructions, which runs concurrently to a victim execution and captures detailed memory access patterns in high-dimensional timing traces. We discover a new cache timing side-channel across both inclusive and non-inclusive caches, different from the traditional “Flush+Flush” timing leakage. We then propose a non-profiling differential deep learning analysis strategy to exploit the cache timing traces for key recovery. We further propose a framework for cross-platform cache timing attack via deep learning. Knowledge learned from profiling a common reference device can be transferred to build models to attack many other victim devices, even in different processor families. We take the OpenSSL AES-128 encryption algorithm as an example victim and deploy an asynchronous cache attack. We target three different devices from Intel, AMD, and ARM processors. We examine various scenarios for assigning the teacher role to one device and the student role to other devices, and evaluate the cross-platform deep-learning attack framework. Experimental results show that this new attack is easily extendable to victim devices and is more effective than attacks without any prior knowledge.
Ruyi Ding, Cheng Gongye, Yunsi Fei, A. Adam Ding
DATE1
2022 Ran$Net: An Anti-Ransomware Methodology based on Cache Monitoring and Deep Learning
abstract
Ransomware has become a serious threat in the cyberspace. Existing software pattern-based malware detectors are specific for certain ransomware and may not capture new variants. Recognizing a common essential behavior of ransomware - employing local cryptographic software for malicious encryption and therefore leaving footprints on the victim machine's caches, this work proposes an anti-ransomware methodology, Ran$Net, based on hardware activities. It consists of a passive cache monitor to log suspicious cache activities, and a follow-on non-profiled deep learning analysis strategy to retrieve the secret cryptographic key from the timing traces generated by the monitor. We implement the first of its kind tool to combat an open-source ransomware and successfully recover the secret key.
Ruyi Ding, Cheng Gongye, A. Adam Ding, Yunsi Fei
ACM Great Lakes Symposium on VLSI3
2022 Spatio-Temporal Point Processes With Attention for Traffic Congestion Event Modeling
abstract
We present a novel framework for modeling traffic congestion events over road networks. Using multi-modal data by combining count data from traffic sensors with police reports that report traffic incidents, we aim to capture two types of triggering effect for congestion events. Current traffic congestion at one location may cause future congestion over the road network, and traffic incidents may cause spread traffic congestion. To model the non-homogeneous temporal dependence of the event on the past, we use a novel attention-based mechanism based on neural networks embedding for point processes. To incorporate the directional spatial dependence induced by the road network, we adapt the “tail-up” model from the context of spatial statistics to the traffic network setting. We demonstrate our approach’s superior performance compared to the state-of-the-art methods for both synthetic and real data.
Shixiang Zhu, Ruyi Ding, Minghe Zhang, Pascal Van Hentenryck, Yao Xie 0002
IEEE Trans. Intell. Transp. Syst.2
2021 Deep Fourier Kernel for Self-Attentive Point Processes
abstract
We present a novel attention-based model for discrete event data to capture complex non-linear temporal dependence structures. We borrow the idea from the attention mechanism and incorporate it into the point processes’ conditional intensity function. We further introduce a novel score function using Fourier kernel embedding, whose spectrum is represented using neural networks, which drastically differs from the traditional dot-product kernel and can capture a more complex similarity structure. We establish our approach’s theoretical properties and demonstrate our approach’s competitive performance compared to the state-of-the-art for synthetic and real data.
Shixiang Zhu, Minghe Zhang, Ruyi Ding, Yao Xie 0002
AISTATS3