EDBT 2026 Demo / reviewers in the wild / expert
Bangzhou Xin
dblp:243/6581
· DBLP profile ↗
12ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0002-4585-1613ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 6 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Computer networks · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Privacy and data protection · 64% Security and privacy of machine learning · 36% | |
| Computer networks
1 paper |
Wireless sensing and localization · 70% Physical-layer communications · 30% | |
| Artificial intelligence
1 paper |
Language models and text generation · 100% |
Topics — the 11 heaviest of 11, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Natural language and speech › Language models and text generation
large language model inference |
1.0 | 1 | 2026 | LoopLLM: Transferable Energy-Latency Attacks in LLMs via Repetitive Generation · AAAI 2026 |
Security and privacy of machine learning
adversarial attack |
1.0 | 1 | 2026 | LoopLLM: Transferable Energy-Latency Attacks in LLMs via Repetitive Generation · AAAI 2026 |
Wireless sensing and localization
device-free sensing |
0.7 | 1 | 2023 | AFall: Wi-Fi-Based Device-Free Fall Detection System Using Spatial Angle of Arrival · IEEE Trans. Mob. Comput. 2023 |
Physical-layer communications › signal processing for communications › array signal processing
direction-of-arrival estimation |
0.7 | 1 | 2023 | AFall: Wi-Fi-Based Device-Free Fall Detection System Using Spatial Angle of Arrival · IEEE Trans. Mob. Comput. 2023 |
Wireless sensing and localization › human activity recognition
fall detection |
0.7 | 1 | 2023 | AFall: Wi-Fi-Based Device-Free Fall Detection System Using Spatial Angle of Arrival · IEEE Trans. Mob. Comput. 2023 |
Privacy and data protection
differential privacy |
0.7 | 1 | 2023 | Shuffle Differential Private Data Aggregation for Random Population · IEEE Trans. Parallel Distributed Syst. 2023 |
Privacy and data protection › differential privacy
privacy amplification |
0.7 | 1 | 2023 | Shuffle Differential Private Data Aggregation for Random Population · IEEE Trans. Parallel Distributed Syst. 2023 |
Privacy and data protection › differential privacy › distributed differential privacy
shuffle model |
0.7 | 1 | 2023 | Shuffle Differential Private Data Aggregation for Random Population · IEEE Trans. Parallel Distributed Syst. 2023 |
Wireless sensing and localization
wireless sensing |
0.2 | 1 | 2023 | AFall: Wi-Fi-Based Device-Free Fall Detection System Using Spatial Angle of Arrival · IEEE Trans. Mob. Comput. 2023 |
Security and privacy of machine learning
federated learning |
0.2 | 1 | 2023 | Shuffle Differential Private Data Aggregation for Random Population · IEEE Trans. Parallel Distributed Syst. 2023 |
Privacy and data protection › data aggregation
privacy-preserving data aggregation |
0.2 | 1 | 2023 | Shuffle Differential Private Data Aggregation for Random Population · IEEE Trans. Parallel Distributed Syst. 2023 |
Methods — techniques the papers use, named apart from their topics
token-aligned ensemble optimization · 2.0repetition-inducing prompt optimization · 2.0sub-gaussian distributions · 0.7poisson distribution · 0.7channel state information · 0.7binomial distribution · 0.7MUSIC · 0.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LoopLLM: Transferable Energy-Latency Attacks in LLMs via Repetitive GenerationabstractAs large language models (LLMs) scale, their inference incurs substantial computational resources, exposing them to energy-latency attacks, where crafted prompts induce high energy and latency cost. Existing attack methods aim to prolong output by delaying the generation of termination symbols. However, as the output grows longer, controlling the termination symbols through input becomes difficult, making these methods less effective. Therefore, we propose LoopLLM, an energy-latency attack framework based on the observation that repetitive generation can trigger low-entropy decoding loops, reliably compelling LLMs to generate until their output limits. LoopLLM introduces (1) a repetition-inducing prompt optimization that exploits autoregressive vulnerabilities to induce repetitive generation, and (2) a token-aligned ensemble optimization that aggregates gradients to improve cross-model transferability. Extensive experiments on 12 open-source and 2 commercial LLMs show that LoopLLM significantly outperforms existing methods, achieving over 90% of the maximum output length, compared to 20% for baselines, and improving transferability by around 40% to DeepSeek-V3 and Gemini 2.5 Flash. Yixiao Xu, Kangyi Ding, Bangzhou Xin, Jia-Li Yin |
AAAI | 6 |
| 2023 | Fine-Grained Private Knowledge DistillationabstractKnowledge distillation has emerged as a scalable and effective way for privacy-preserving machine learning. One remaining drawback is that it consumes privacy in a client-level manner. In order to attain fine-grained privacy accountant and improve utility, this work proposes a model-free reverse k-NN labeling method towards record-level private knowledge distillation, where each private record is employed for labeling at most k queries. Theoretically, we provide bounds of labeling error rate under the centralized/local model of differential privacy. Experimentally, we demonstrate that it achieves new state-of-the-art accuracy in MNIST/SVHN/CIFAR-10 dataset with one order of magnitude lower of privacy loss. Yuntong Li, Shaowei Wang 0003, Jin Li 0002, Yuqiu Qian, Bangzhou Xin, Wei Yang 0011 |
ICASSP | 6 |
| 2023 | Sparse Black-Box Inversion Attack with Limited InformationabstractExisting black-box model inversion attacks mainly focus on training and attacking surrogate models. However, due to the deployment process of face recognition models, training surrogate models becomes extremely difficult in practice. At the same time, query-based black-box inversion attacks still suffer from low image quality and high computational costs. To bridge these gaps, in this paper, we propose BMI-S, a sparse black-box inversion attack against face recognition models. BMI-S first introduces evolution strategies to perform efficient black-box gradient estimation and achieve query-based attacks. Meanwhile, BMI-S performs sparse attacks on the key styles that contribute most to the face recognition process. By only optimizing key style control vectors, BMI-S further narrows the dimensions of the search space and accelerates the inversion attacks. Yixiao Xu, Xiaolei Liu 0001, Bangzhou Xin |
ICASSP | 4 |
| 2023 | Efficient intrusion detection toward IoT networks using cloud-edge collaboration
Yixiao Xu, Bangzhou Xin, Weizhe Zhang |
Comput. Networks | 4 |
| 2023 | DockerWatch: a two-phase hybrid detection of malware using various static features in container cloud
Qixu Wang, Xingshu Chen, Bangzhou Xin |
Soft Comput. | 5 |
| 2023 | AFall: Wi-Fi-Based Device-Free Fall Detection System Using Spatial Angle of ArrivalabstractFalling is a common health problem for elderly people. Early detection of falls allows earlier rescue measures to be implemented. Most existing Wi-Fi-based fall detection systems employ learning-based methods, which require large amounts of labeled data for prior training. To address this issue, we in this paper present AFall, a robust model-based fall detection system that does not require prior training for a single person based on Wi-Fi Channel State Information (CSI). Different from previous Wi-Fi-based fall detection systems, we model the relationship between human falls and changes of Angle of Arrival (AoA) of Wi-Fi signals reflected from human body by multiple signal classification (MUSIC) algorithm. In particular, we deploy two receivers in orthogonal spatial layouts to capture diversified AoA information. Since AoA reflected from human body is independent of environments and subjects, the performance of AFall can remain stable when the environment changes slightly, which can meet the daily needs of the elderly people. We implement AFall using commodity Wi-Fi devices and evaluate it in five different indoor environments. The experimental results demonstrate that AFall achieves an average accuracy of 84.31% and an average F1 score of 84.56%. Wei Yang 0011, Yang Xu 0020, Yangyang Geng, Bangzhou Xin, Liusheng Huang |
IEEE Trans. Mob. Comput. | 5 |
| 2023 | Shuffle Differential Private Data Aggregation for Random PopulationabstractBridging the advantages of differential privacy in both centralized model (i.e., high accuracy) and local model (i.e., minimum trust), the shuffle privacy model has potential applications in many privacy-sensitive scenarios, such as mobile user data aggregation and federated learning. Since messages from users are anonymized by semi-trusted shufflers (e.g., anonymous channels, edge servers), every user could hide message among other users’ messages and inject only part of noises (a.k.a. privacy amplification). However, existing works assume that the participating user population is known in advance, which is unrealistic for dynamic environments (e.g., mobile computing, vehicular networks). In this work, we study the shuffle privacy model with a random participating population, and give privacy amplification bounds for population size with commonly encountered binomial, Poisson, sub-Gaussian distribution and etc. For further improving accuracy, we formulate and derive optimal dummy sizes for both non-adaptive and adaptive dummies. Finally, to break the error barrier due to the constraint of sending one single message per user, we design a multi-message shuffle private protocol supporting random population. Experiment results show that our approaches reduce more than 60% error when compared to the local model and naive approaches. We hope this work provides tailored solutions of shuffle privacy for dynamic mobile/distributed computing. Shaowei Wang 0003, Xuandi Luo, Yuqiu Qian, Youwen Zhu, Kongyang Chen, Qi Chen 0024, Bangzhou Xin, Wei Yang 0011 |
IEEE Trans. Parallel Distributed Syst. | 7 |
| 2022 | Unsupervised Anomaly Detection for Container Cloud Via BILSTM-Based Variational Auto-EncoderabstractThe appearance of container technology has profoundly changed the development and deployment of multi-tier distributed applications. However, the imperfect system resource isolation features and the kernel-sharing mechanism will introduce significant security risks to the container-based cloud. In this paper, we propose a real-time unsupervised anomaly detection system for monitoring system calls in container cloud via BiLSTM-based variational auto-encoder (VAE). Our proposed BiLSTM-based VAE network leverages the generative characteristics of VAE to learn the robust representations of normal patterns by reconstruction probabilities while being sensitive to long-term dependencies. Our evaluations using real-world datasets show that the BiLSTM-based VAE network achieves excellent detection performance without introducing significant running performance overhead to the container platform. Xingshu Chen, Qixu Wang, Bangzhou Xin |
ICASSP | 5 |
| 2022 | Federated synthetic data generation with differential privacy
Bangzhou Xin, Yangyang Geng, Wei Yang 0011, Shaowei Wang 0003, Liusheng Huang |
Neurocomputing | 1 |
| 2021 | Private FLI: Anti-Gradient Leakage Recovery Data Privacy ArchitectureabstractWhile machine learning brings convenience, it also faces the issue of data privacy. For privacy issues, most researches focus on implementing homomorphic encryption or differential privacy to protect data, while ignoring the potential threats caused by the leakage of model parameters. However, a malicious attacker can still recover sensitive data information through model parameters. On the one hand, traditional methods cannot take both high accuracy and low computation time into account. On the other hand, they cannot resist the reconstruction attack from the model's parameter. In order to address this problem, this paper designs a privacy protection framework named FLI, which is inspired by public key infrastructure. In FLI, all participants and the server are trained and aggregated under one framework based on federated learning, which includes key exchange and shares with the idea of homomorphic encryption. Under the algorithm we design, the malicious adversary cannot recover effective information after obtaining the transformed parameters, while the server can still perform effective parameter aggregation. To evaluate the performance of FLI, we conduct extensive experiments. The experimental results show that the computation time is within an acceptable range while ensuring high accuracy. Huichao Wang, Wei Yang 0011, Bangzhou Xin, Yangyang Geng, Zhenbo Shi, Liusheng Huang |
IJCNN | 3 |
| 2020 | Private FL-GAN: Differential Privacy Synthetic Data Generation Based on Federated LearningabstractGenerative Adversarial Network (GAN) has already made a big splash in the field of generating realistic "fake" data. However, when data is distributed and data-holders are reluctant to share data for privacy reasons, GAN’s training is difficult. To address this issue, we propose private FL-GAN, a differential privacy generative adversarial network model based on federated learning. By strategically combining the Lipschitz limit with the differential privacy sensitivity, the model can generate high-quality synthetic data without sacrificing the privacy of the training data. We theoretically prove that private FL-GAN can provide strict privacy guarantee with differential privacy, and experimentally demonstrate our model can generate satisfactory data. Bangzhou Xin, Wei Yang 0011, Yangyang Geng, Shaowei Wang 0003, Liusheng Huang |
ICASSP | 1 |
| 2019 | Differentially Private Greedy Decision ForestabstractAs information security is increasingly valued, privacy-preserving data mining has become a research hotspot in the field of big data and signal processing. We propose a new differentially private greedy decision forest algorithm called DPGDF to help improve the accuracy of privacy-preserving data mining. Unlike previous algorithms that only employed greedy decision trees or random forests, our algorithm uses a combination of greedy trees and parallel combination theory to construct a greedy decision forest and coordinate privacy protection and prediction accuracy to achieve the best balance. Combined with smooth sensitivity, the introduction of noise is minimized, making the prediction accuracy of the algorithm notably better than the current state-of-the-art algorithms. Experiments on the UCI datasets show that the prediction accuracy of our algorithm is about 10% higher than that of those algorithms. Bangzhou Xin, Wei Yang 0011, Shaowei Wang 0003, Liusheng Huang |
ICASSP | 1 |