EDBT 2026 Demo / reviewers in the wild / expert
Mingtian Tan
dblp:234/8694
· DBLP profile ↗
7ranked-venue papers
5as first author
6since 2021 · last 2026
0000-0002-7454-9085ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Inferring Events from Time Series using Language ModelsabstractMingtian Tan, Mike A Merrill, Zachary Gottesman, Tim Althoff, David Evans, Thomas Hartvigsen. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Mingtian Tan, Mike A. Merrill, Zachary Gottesman, Tim Althoff, Thomas Hartvigsen |
ACL (1) | 1 |
| 2024 | Are Language Models Actually Useful for Time Series Forecasting?abstractLarge language models (LLMs) are being applied to time series forecasting. But are language models actually useful for time series? In a series of ablation studies on three recent and popular LLM-based time series forecasting methods, we find that removing the LLM component or replacing it with a basic attention layer does not degrade forecasting performance---in most cases, the results even improve! We also find that despite their significant computational cost, pretrained LLMs do no better than models trained from scratch, do not represent the sequential dependencies in time series, and do not assist in few-shot settings. Additionally, we explore time series encoders and find that patching and attention structures perform similarly to LLM-based forecasters. All resources needed to reproduce our work are available: https://github.com/BennyTMT/LLMsForTimeSeries. Mingtian Tan, Mike A. Merrill, Tim Althoff, Thomas Hartvigsen |
NeurIPS | 1 |
| 2023 | Mitigating Membership Inference Attacks via Weighted SmoothingabstractRecent advancements in deep learning have spotlighted a crucial privacy vulnerability to membership inference attack (MIA), where adversaries can determine if specific data was present in a training set, thus potentially revealing sensitive information. In this paper, we introduce a technique, weighted smoothing (WS), to mitigate MIA risks. Our approach is anchored on the observation that training samples differ in their vulnerability to MIA, primarily based on their distance to clusters of similar samples. The intuition is clusters will make model predictions more confident and increase MIA risks. Thus WS strategically introduces noise to training samples, depending on whether they are near a cluster or isolated. We evaluate WS against MIAs on multiple benchmark datasets and model architectures, demonstrating its effectiveness. We publish code at https://github.com/BennyTMT/weighted-smoothing. Mingtian Tan, Xiaofei Xie, Jun Sun 0001, Tianhao Wang 0001 |
ACSAC | 1 |
| 2022 | Play the Imitation Game: Model Extraction Attack against Autonomous Driving LocalizationabstractThe security of the Autonomous Driving (AD) system has been gaining researchers’ and public’s attention recently. Given that AD companies have invested a huge amount of resources in developing their AD models, e.g., localization models, these models, especially their parameters, are important intellectual property and deserve strong protection. Qifan Zhang 0002, Junjie Shen 0001, Mingtian Tan, Zhe Zhou 0001, Zhou Li 0001, Qi Alfred Chen, Haipeng Zhang 0004 |
ACSAC | 3 |
| 2021 | The Many-faced God: Attacking Face Verification System with Embedding and Image RecoveryabstractFace verification system (FVS), which can automatically verify a person’s identity, has been increasingly deployed in the real-world settings. Key to its success is the inclusion of face embedding, a technique that can detect similar photos of the same person by deep neural networks. Mingtian Tan, Zhe Zhou 0001, Zhou Li 0001 |
ACSAC | 1 |
| 2021 | Invisible Probe: Timing Attacks with PCIe Congestion Side-channelabstractPCIe (Peripheral Component Interconnect express) protocol is the de facto protocol to bridge CPU and peripheral devices like GPU, NIC, and SSD drive. There is an increasing demand to install more peripheral devices on a single machine, but the PCIe interfaces offered by Intel CPUs are fixed. To resolve such contention, PCIe switch, PCH (Platform Controller Hub), or virtualization cards are installed on the machine to allow multiple devices to share a PCIe interface. Congestion happens when the collective PCIe traffic from the devices overwhelm the PCIe link capacity, and transmission delay is then introduced.In this work, we found the PCIe delay not only harms device performance but also leaks sensitive information about a user who uses the machine. In particular, as user’s activities might trigger data movement over PCIe (e.g., between CPU and GPU), by measuring PCIe congestion, an adversary accessing another device can infer the victim’s secret indirectly. Therefore, the delay resulted from I/O congestion can be exploited as a side-channel. We demonstrate the threat from PCIe congestion through 2 attack scenarios and 4 victim settings. Specifically, an attacker can learn the workload of a GPU in a remote server by probing a RDMA NIC that shares the same PCIe switch and measuring the delays. Based on the measurement, the attacker is able to know the keystroke timings of the victim, what webpage is rendered on the GPU, and what machine-learning model is running on the GPU. Besides, when the victim is using a low-speed device, e.g., an Ethernet NIC, an attacker controlling an NVMe SSD can launch a similar attack when they share a PCH or virtualization card. The evaluation result shows our attack can achieve high accuracy (e.g., 96.31% accuracy in inferring webpage visited by a victim). Mingtian Tan, Junpeng Wan, Zhe Zhou 0001, Zhou Li 0001 |
SP | 1 |
| 2018 | A survey of practical adversarial example attacksabstractAdversarial examples revealed the weakness of machine learning techniques in terms of robustness, which moreover inspired adversaries to make use of the weakness to attack systems employing machine learning. Existing researches covered the methodologies of adversarial example generation, the root reason of the existence of adversarial examples, and some defense schemes. However practical attack against real world systems did not appear until recent, mainly because of the difficulty in injecting a artificially generated example into the model behind the hosting system without breaking the integrity. Recent case study works against face recognition systems and road sign recognition systems finally abridged the gap between theoretical adversarial example generation methodologies and practical attack schemes against real systems. To guide future research in defending adversarial examples in the real world, we formalize the threat model for practical attacks with adversarial examples, and also analyze the restrictions and key procedures for launching real world adversarial example attacks. Mingtian Tan, Zhe Zhou 0001 |
Cybersecur. | 2 |