Bangzhou Xin

dblp:243/6581 · DBLP profile ↗
← Back
12ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0002-4585-1613ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 6 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Computer networks · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Privacy and data protection · 64% Security and privacy of machine learning · 36%
Computer networks
1 paper
Wireless sensing and localization · 70% Physical-layer communications · 30%
Artificial intelligence
1 paper
Language models and text generation · 100%

Topics — the 11 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Natural language and speech › Language models and text generation
large language model inference
1.012026
LoopLLM: Transferable Energy-Latency Attacks in LLMs via Repetitive Generation · AAAI 2026
Security and privacy of machine learning
adversarial attack
1.012026
LoopLLM: Transferable Energy-Latency Attacks in LLMs via Repetitive Generation · AAAI 2026
Wireless sensing and localization
device-free sensing
0.712023
AFall: Wi-Fi-Based Device-Free Fall Detection System Using Spatial Angle of Arrival · IEEE Trans. Mob. Comput. 2023
Physical-layer communications › signal processing for communications › array signal processing
direction-of-arrival estimation
0.712023
AFall: Wi-Fi-Based Device-Free Fall Detection System Using Spatial Angle of Arrival · IEEE Trans. Mob. Comput. 2023
Wireless sensing and localization › human activity recognition
fall detection
0.712023
AFall: Wi-Fi-Based Device-Free Fall Detection System Using Spatial Angle of Arrival · IEEE Trans. Mob. Comput. 2023
Privacy and data protection
differential privacy
0.712023
Shuffle Differential Private Data Aggregation for Random Population · IEEE Trans. Parallel Distributed Syst. 2023
Privacy and data protection › differential privacy
privacy amplification
0.712023
Shuffle Differential Private Data Aggregation for Random Population · IEEE Trans. Parallel Distributed Syst. 2023
Privacy and data protection › differential privacy › distributed differential privacy
shuffle model
0.712023
Shuffle Differential Private Data Aggregation for Random Population · IEEE Trans. Parallel Distributed Syst. 2023
Wireless sensing and localization
wireless sensing
0.212023
AFall: Wi-Fi-Based Device-Free Fall Detection System Using Spatial Angle of Arrival · IEEE Trans. Mob. Comput. 2023
Security and privacy of machine learning
federated learning
0.212023
Shuffle Differential Private Data Aggregation for Random Population · IEEE Trans. Parallel Distributed Syst. 2023
Privacy and data protection › data aggregation
privacy-preserving data aggregation
0.212023
Shuffle Differential Private Data Aggregation for Random Population · IEEE Trans. Parallel Distributed Syst. 2023

Methods — techniques the papers use, named apart from their topics

token-aligned ensemble optimization · 2.0repetition-inducing prompt optimization · 2.0sub-gaussian distributions · 0.7poisson distribution · 0.7channel state information · 0.7binomial distribution · 0.7MUSIC · 0.7
YearPublicationVenuePosition
2026 LoopLLM: Transferable Energy-Latency Attacks in LLMs via Repetitive Generation
abstract
As large language models (LLMs) scale, their inference incurs substantial computational resources, exposing them to energy-latency attacks, where crafted prompts induce high energy and latency cost. Existing attack methods aim to prolong output by delaying the generation of termination symbols. However, as the output grows longer, controlling the termination symbols through input becomes difficult, making these methods less effective. Therefore, we propose LoopLLM, an energy-latency attack framework based on the observation that repetitive generation can trigger low-entropy decoding loops, reliably compelling LLMs to generate until their output limits. LoopLLM introduces (1) a repetition-inducing prompt optimization that exploits autoregressive vulnerabilities to induce repetitive generation, and (2) a token-aligned ensemble optimization that aggregates gradients to improve cross-model transferability. Extensive experiments on 12 open-source and 2 commercial LLMs show that LoopLLM significantly outperforms existing methods, achieving over 90% of the maximum output length, compared to 20% for baselines, and improving transferability by around 40% to DeepSeek-V3 and Gemini 2.5 Flash.
Yixiao Xu, Kangyi Ding, Bangzhou Xin, Jia-Li Yin
AAAI6
2023 Fine-Grained Private Knowledge Distillation
abstract
Knowledge distillation has emerged as a scalable and effective way for privacy-preserving machine learning. One remaining drawback is that it consumes privacy in a client-level manner. In order to attain fine-grained privacy accountant and improve utility, this work proposes a model-free reverse k-NN labeling method towards record-level private knowledge distillation, where each private record is employed for labeling at most k queries. Theoretically, we provide bounds of labeling error rate under the centralized/local model of differential privacy. Experimentally, we demonstrate that it achieves new state-of-the-art accuracy in MNIST/SVHN/CIFAR-10 dataset with one order of magnitude lower of privacy loss.
Yuntong Li, Shaowei Wang 0003, Jin Li 0002, Yuqiu Qian, Bangzhou Xin, Wei Yang 0011
ICASSP6
2023 Sparse Black-Box Inversion Attack with Limited Information
abstract
Existing black-box model inversion attacks mainly focus on training and attacking surrogate models. However, due to the deployment process of face recognition models, training surrogate models becomes extremely difficult in practice. At the same time, query-based black-box inversion attacks still suffer from low image quality and high computational costs. To bridge these gaps, in this paper, we propose BMI-S, a sparse black-box inversion attack against face recognition models. BMI-S first introduces evolution strategies to perform efficient black-box gradient estimation and achieve query-based attacks. Meanwhile, BMI-S performs sparse attacks on the key styles that contribute most to the face recognition process. By only optimizing key style control vectors, BMI-S further narrows the dimensions of the search space and accelerates the inversion attacks.
Yixiao Xu, Xiaolei Liu 0001, Bangzhou Xin
ICASSP4
2023 Efficient intrusion detection toward IoT networks using cloud-edge collaboration
Yixiao Xu, Bangzhou Xin, Weizhe Zhang
Comput. Networks4
2023 DockerWatch: a two-phase hybrid detection of malware using various static features in container cloud
Qixu Wang, Xingshu Chen, Bangzhou Xin
Soft Comput.5
2023 AFall: Wi-Fi-Based Device-Free Fall Detection System Using Spatial Angle of Arrival
abstract
Falling is a common health problem for elderly people. Early detection of falls allows earlier rescue measures to be implemented. Most existing Wi-Fi-based fall detection systems employ learning-based methods, which require large amounts of labeled data for prior training. To address this issue, we in this paper present AFall, a robust model-based fall detection system that does not require prior training for a single person based on Wi-Fi Channel State Information (CSI). Different from previous Wi-Fi-based fall detection systems, we model the relationship between human falls and changes of Angle of Arrival (AoA) of Wi-Fi signals reflected from human body by multiple signal classification (MUSIC) algorithm. In particular, we deploy two receivers in orthogonal spatial layouts to capture diversified AoA information. Since AoA reflected from human body is independent of environments and subjects, the performance of AFall can remain stable when the environment changes slightly, which can meet the daily needs of the elderly people. We implement AFall using commodity Wi-Fi devices and evaluate it in five different indoor environments. The experimental results demonstrate that AFall achieves an average accuracy of 84.31% and an average F1 score of 84.56%.
Wei Yang 0011, Yang Xu 0020, Yangyang Geng, Bangzhou Xin, Liusheng Huang
IEEE Trans. Mob. Comput.5
2023 Shuffle Differential Private Data Aggregation for Random Population
abstract
Bridging the advantages of differential privacy in both centralized model (i.e., high accuracy) and local model (i.e., minimum trust), the shuffle privacy model has potential applications in many privacy-sensitive scenarios, such as mobile user data aggregation and federated learning. Since messages from users are anonymized by semi-trusted shufflers (e.g., anonymous channels, edge servers), every user could hide message among other users’ messages and inject only part of noises (a.k.a. privacy amplification). However, existing works assume that the participating user population is known in advance, which is unrealistic for dynamic environments (e.g., mobile computing, vehicular networks). In this work, we study the shuffle privacy model with a random participating population, and give privacy amplification bounds for population size with commonly encountered binomial, Poisson, sub-Gaussian distribution and etc. For further improving accuracy, we formulate and derive optimal dummy sizes for both non-adaptive and adaptive dummies. Finally, to break the error barrier due to the constraint of sending one single message per user, we design a multi-message shuffle private protocol supporting random population. Experiment results show that our approaches reduce more than 60% error when compared to the local model and naive approaches. We hope this work provides tailored solutions of shuffle privacy for dynamic mobile/distributed computing.
Shaowei Wang 0003, Xuandi Luo, Yuqiu Qian, Youwen Zhu, Kongyang Chen, Qi Chen 0024, Bangzhou Xin, Wei Yang 0011
IEEE Trans. Parallel Distributed Syst.7
2022 Unsupervised Anomaly Detection for Container Cloud Via BILSTM-Based Variational Auto-Encoder
abstract
The appearance of container technology has profoundly changed the development and deployment of multi-tier distributed applications. However, the imperfect system resource isolation features and the kernel-sharing mechanism will introduce significant security risks to the container-based cloud. In this paper, we propose a real-time unsupervised anomaly detection system for monitoring system calls in container cloud via BiLSTM-based variational auto-encoder (VAE). Our proposed BiLSTM-based VAE network leverages the generative characteristics of VAE to learn the robust representations of normal patterns by reconstruction probabilities while being sensitive to long-term dependencies. Our evaluations using real-world datasets show that the BiLSTM-based VAE network achieves excellent detection performance without introducing significant running performance overhead to the container platform.
Xingshu Chen, Qixu Wang, Bangzhou Xin
ICASSP5
2022 Federated synthetic data generation with differential privacy
Bangzhou Xin, Yangyang Geng, Wei Yang 0011, Shaowei Wang 0003, Liusheng Huang
Neurocomputing1
2021 Private FLI: Anti-Gradient Leakage Recovery Data Privacy Architecture
abstract
While machine learning brings convenience, it also faces the issue of data privacy. For privacy issues, most researches focus on implementing homomorphic encryption or differential privacy to protect data, while ignoring the potential threats caused by the leakage of model parameters. However, a malicious attacker can still recover sensitive data information through model parameters. On the one hand, traditional methods cannot take both high accuracy and low computation time into account. On the other hand, they cannot resist the reconstruction attack from the model's parameter. In order to address this problem, this paper designs a privacy protection framework named FLI, which is inspired by public key infrastructure. In FLI, all participants and the server are trained and aggregated under one framework based on federated learning, which includes key exchange and shares with the idea of homomorphic encryption. Under the algorithm we design, the malicious adversary cannot recover effective information after obtaining the transformed parameters, while the server can still perform effective parameter aggregation. To evaluate the performance of FLI, we conduct extensive experiments. The experimental results show that the computation time is within an acceptable range while ensuring high accuracy.
Huichao Wang, Wei Yang 0011, Bangzhou Xin, Yangyang Geng, Zhenbo Shi, Liusheng Huang
IJCNN3
2020 Private FL-GAN: Differential Privacy Synthetic Data Generation Based on Federated Learning
abstract
Generative Adversarial Network (GAN) has already made a big splash in the field of generating realistic "fake" data. However, when data is distributed and data-holders are reluctant to share data for privacy reasons, GAN’s training is difficult. To address this issue, we propose private FL-GAN, a differential privacy generative adversarial network model based on federated learning. By strategically combining the Lipschitz limit with the differential privacy sensitivity, the model can generate high-quality synthetic data without sacrificing the privacy of the training data. We theoretically prove that private FL-GAN can provide strict privacy guarantee with differential privacy, and experimentally demonstrate our model can generate satisfactory data.
Bangzhou Xin, Wei Yang 0011, Yangyang Geng, Shaowei Wang 0003, Liusheng Huang
ICASSP1
2019 Differentially Private Greedy Decision Forest
abstract
As information security is increasingly valued, privacy-preserving data mining has become a research hotspot in the field of big data and signal processing. We propose a new differentially private greedy decision forest algorithm called DPGDF to help improve the accuracy of privacy-preserving data mining. Unlike previous algorithms that only employed greedy decision trees or random forests, our algorithm uses a combination of greedy trees and parallel combination theory to construct a greedy decision forest and coordinate privacy protection and prediction accuracy to achieve the best balance. Combined with smooth sensitivity, the introduction of noise is minimized, making the prediction accuracy of the algorithm notably better than the current state-of-the-art algorithms. Experiments on the UCI datasets show that the prediction accuracy of our algorithm is about 10% higher than that of those algorithms.
Bangzhou Xin, Wei Yang 0011, Shaowei Wang 0003, Liusheng Huang
ICASSP1