EDBT 2026 Demo / reviewers in the wild / expert
Ju Jia
dblp:248/5418
· DBLP profile ↗
30ranked-venue papers
14as first author
28since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 12 · 5 first-author · 10 since 2021Security and privacy · 9 · 5 first-author · 9 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 1 first-author · 6 since 2021Databases, data management, data science and information retrieval · 5 · 3 first-author · 5 since 2021Computer networks · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PhysPatch: A Physically Realizable and Transferable Adversarial Patch Attack for Multimodal Large Language Models-based Autonomous Driving SystemsabstractMultimodal Large Language Models (MLLMs) are becoming integral to autonomous driving (AD) systems due to their strong vision-language reasoning capabilities. However, MLLMs are vulnerable to adversarial attacks—particularly adversarial patch attacks—which can pose serious threats in real-world scenarios. Existing patch-based attack methods are primarily designed for object detection models. Due to the more complex architectures and strong reasoning capabilities of MLLMs, these approaches perform poorly when transferred to MLLM-based systems. To address these limitations, we propose PhysPatch, a physically realizable and transferable adversarial patch framework tailored for MLLM-based AD systems. PhysPatch jointly optimizes patch location, shape, and content to enhance attack effectiveness and real-world applicability. It introduces a semantic-based mask initialization strategy for realistic placement, an SVD-based local alignment loss with patch-guided crop-resize to improve transferability, and a potential field-based mask refinement method. Extensive experiments across open-source, commercial, and reasoning-capable MLLMs demonstrate that PhysPatch significantly outperforms state-of-the-art (SOTA) methods in steering MLLM-based AD systems toward target-aligned perception and planning outputs. Moreover, PhysPatch consistently places adversarial patches in physically feasible regions of AD scenes, ensuring strong real-world applicability and deployability. Qi Guo 0008, Xiaojun Jia, Shanmin Pang, Simeng Qin, Lin Wang 0026, Ju Jia, Yang Liu 0003, Qing Guo 0005 |
AAAI | 6 |
| 2026 | PAGPL: Privacy-Aware Graph Prompt Learning Scheme via Adaptive Perturbation-Estimated Topology RecoveryabstractGraph prompt learning (GPL) serves as a crucial framework for mitigating the knowledge transfer by reconciling the substantial mismatch between pre-training models and downstream tasks. However, prevalent GPL paradigm fail to accommodate graph data affected by privacy-induced noise. Specifically, 1) GPL typically relies on the stability of original graph structures for the design of effective prompt templates; 2) the construction of prompts lacks explicit guidance to suppress noise introduced by privacy perturbations; 3) prompt optimization on single disturbed graphs can easily lead to overfitting to noise patterns. To address these issues, we propose a novel privacy-aware graph prompt learning (PAGPL) scheme, which alleviates spurious clues caused by privacy noise injection. Initially, an adaptive structure-wise Bayesian estimation is applied to reconstruct the privacy-perturbed graphs. Subsequently, to suppress the impact of residual perturbation, a noise-resilient prompt generation is employed to filter unreliable structural and signals. Ultimately, we incorporate a multi-view-based progressive privacy consistency to promote the robustness of prompts against the semantic misalignment while improving the task-specific consistency. The experimental results reveal that our scheme outperforms state-of-the-art (SOTA) GPL approaches with a 10%–60% improvement in accuracy under various real-world privacy-perturbed scenarios. Ju Jia, Jiansen Song, Jingxuan Yu, Jiabao Guo, Xiaoshuang Jia, Di Wu 0050, Yali Yuan, Guang Cheng 0001 |
AAAI | 1 |
| 2026 | Cross-Modal Unlearning via Influential Neuron Path Editing in Multimodal Large Language ModelsabstractMultimodal Large Language Models (MLLMs) extend foundation models to real-world applications by integrating inputs such as text and vision. However, their broad knowledge capacity raises growing concerns about privacy leakage, toxicity mitigation, and intellectual property violations. Machine Unlearning (MU) offers a practical solution by selectively forgetting targeted knowledge while preserving overall model utility. When applied to MLLMs, existing neuron-editing-based MU approaches face two fundamental challenges: (i) forgetting becomes inconsistent across modalities because existing point-wise attribution methods fail to capture the structured, layer-by-layer information flow that connects different modalities; and (ii) general knowledge performance declines when sensitive neurons that also support important reasoning paths are pruned, as this disrupts the model’s ability to generalize. To alleviate these limitations, we propose a multimodal influential neuron path editor (MIP-Editor) for MU. Our approach introduces modality-specific attribution scores to identify influential neuron paths responsible for encoding forget-set knowledge and applies influential-path-aware neuron-editing via representation misdirection. This strategy also enables effective and coordinated forgetting across modalities while preserving the model's general capabilities. Experimental results demonstrate that MIP-Editor achieves a superior unlearning performance on multimodal tasks, with a maximum forgetting rate of 87.75% and up to 54.26% improvement in general knowledge retention. On textual tasks, MIP-Editor achieves up to 80.65% forgetting and preserves 77.90% of general performance. Kunhao Li, Di Wu 0050, Ju Jia, Minhui Xue 0001 |
AAAI | 6 |
| 2026 | MPAS: Breaking Sequential Constraints of Multi-Agent Communication Topologies via Individual-Epistemic Message PropagationabstractLarge language model (LLM)-driven agents are designed to handle a wide range of tasks autonomously. As tasks become increasingly composite, the integration of multiple agents into a graph-structured system offers a promising solution. Recent advances mainly architect the communication order among agents into a specified directed acyclic graph, from which a one-by-one execution can be determined by topological sort. However, sequential architectures restrict the diversity of the information flow, hinder parallel computation, and exhibit vulnerabilities to potential backdoor threats. To overcome underlying shortcomings of sequential structures, we propose a node-wise multi-agent scheme, named message passing agent system (MPAS). Specifically, to parallelize the communication across agents, we extend the message propagation mechanism in graph representation learning to multi-agent scenarios and introduce our individual-epistemic message propagation. To further enhance expressiveness and robustness, we investigate three self-driven message aggregators. To achieve desired working flows, collaborative connections can be optimized without constraints. The experimental results reveal that compared to state-of-the-art sequential designs, MPAS could architect more advanced algorithms in 93.8% of the evaluations, reduce the average communication time from 84.6 seconds to 14.2 seconds per round on AQuA, and improve resilience against backdoor misinformation injection in 94.4% tests. Jingxuan Yu, Ju Jia, Simeng Qin, Xiaojun Jia, Siqi Ma 0001, Yihao Huang 0001, Yali Yuan, Guang Cheng 0001 |
AAAI | 2 |
| 2026 | Fake news detection with GAN-augmented contrastive learning and multimodal attentionabstractAbstract The rapid proliferation of fake news in digital media has emerged as a major threat to information credibility and public trust. Although recent advances have explored multimodal learning for fake news detection, existing models often fail to effectively integrate heterogeneous data sources and remain vulnerable to adversarial manipulations. To address these challenges, we propose (Multimodal Adversarial Deep Semantic Learning), a robust multimodal fake news detection framework that unifies generative adversarial networks (GANs) with supervised contrastive learning. Specifically, employs a multi-layer joint attention mechanism to align and fuse textual and visual features, while adversarial training encourages the extraction of event-invariant representations, enhancing generalizability across unseen news events. Additionally, contrastive learning with adversarial perturbations further strengthens feature discrimination and robustness against attacks. Extensive experiments on benchmark Twitter and Weibo datasets demonstrate that achieves state-of-the-art accuracy (85.3%) and maintains stable performance with only a 1.1% drop under adversarial conditions, outperforming existing methods in both detection accuracy and resilience. These results underscore ’s effectiveness in advancing robust multimodal fake news detection and promoting digital information integrity. Cong Wu 0003, Jing Chen 0003, Yebo Feng, Ju Jia, Zijian Zhang 0001, Jiahua Xu 0002, Teng Li 0003, Yang Liu 0003 |
Cybersecur. | 4 |
| 2026 | CTEA: Camouflaged topological element attack via causal influence discovery
Ju Jia, Pengyuan Gao, Meng Luo 0002, Cong Wu 0003, Jiabao Guo |
Expert Syst. Appl. | 1 |
| 2026 | FGRW: Fine-Grained Reversible Watermarking Based on Distribution-Adaptive Contrastive Augmentation Across Diverse Domains
Ju Jia, Bo Feng 0002, Anran Li 0001, Cong Wu 0003, Siqi Ma 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | SMInject: Specious Malignant Injection Attacks With Semantically-Enhanced Tokens in Cross-Modal RetrievalabstractThe pre-training multimodal models have achieved remarkable success with powerful cross-modal understanding capabilities, while easily being affected by deliberate injection attacks. Although the deceptive injection attacks are harmful, they are valuable in revealing the vulnerability and improving the robustness for multimodal models. Unfortunately, the existing multimodal injection attacks pay less attention to the complicated roles of different modality-related causal correlation, which results in such attacks being susceptible to detection and defense. To alleviate this issue, we propose a novel specious malignant injection attack framework, calledSMInject, which exploits both the irrationality and causal correlation across diverse modalities to stealthily manipulate the space of output. To enhance the stealthiness, we generate deceptive injections to assemble the concepts by analyzing causal correlation under four types of attacks. To further boost the effectiveness, the malignant injections are guided to penetrate in the encoded embedding space by designing the premise-hypothesis consensus alignment. Extensive experiments on representative multimodal models demonstrate that ourSMInjectachieves over 14% higher attack success rate and 6% higher Hit@5 metric than state-of-the-art methods while preserving the overall utility of models. Moreover, we highlight that theSMInjectalso exhibits the desired transferability by investigating the impact of contextual factors, such as similar attack profiles, imperceptible noise perturbations,etc. Our code is available athttps://anonymous.4open.science/r/SMInject-0DBC. Ju Jia, Jiabao Guo, Xiaojun Jia, Siqi Ma 0001, Jie Gui, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | Rethinking Frequency Modeling: Tail-Aware Dynamic Adversarial Training for Long-Tailed RobustnessabstractAdversarial training (AT) is among the most effective defenses against adversarial attacks on deep neural networks. However, in real-world scenarios where data often follow long-tailed distributions, conventional AT methods struggle to handle such imbalance, resulting in severe robustness disparities across classes and limited overall robustness. Although recent efforts attempt to improve robustness through class frequency-aware weighting or distribution adjustments, our empirical analysis reveals that class frequency alone is an insufficient indicator of adversarial vulnerability, as robust accuracy does not correlate with the number of examples per class. Furthermore, AT under long-tailed distributions exhibits optimization instability, particularly for tail classes with limited data. To address these challenges, we present Tail-Aware Dynamic Adversarial Training (TAD-AT), which integrates three complementary components targeting the training loss, attack strategy, and weight average. TAD-AT captures data imbalance and performance disparity, improving adversarial robustness under long-tailed distributions. First, our training loss incorporates frequency- and accuracy-aware regularization to emphasize learning for vulnerable classes. Second, our attack adjusts perturbations based on class-wise vulnerability, encouraging robust feature learning around vulnerable regions, thereby mitigating robustness overfitting and improving clean accuracy. Third, our weight average improves robust generalization and training stability by adaptively controlling the decay rate across classes. Experiments on long-tailed benchmarks demonstrate that our TAD-AT significantly improves adversarial robustness, offering a systematic and practical solution to robustness challenges under long-tail distributions. Our code is publicly available on https://github.com/bookman233/TADAT. Chengze Jiang, Minjing Dong, Jie Gui, Ju Jia, Yuan Yan Tang, James T. Kwok |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | SelfPrompt: Autonomously Evaluating LLM Robustness via Domain-Constrained Knowledge Guidelines and Refined Adversarial PromptsabstractTraditional methods for evaluating the robustness of large language models (LLMs) often rely on standardized benchmarks, which can escalate costs and limit evaluations across varied domains. This paper introduces a novel framework designed to autonomously evaluate the robustness of LLMs by incorporating refined adversarial prompts and domain-constrained knowledge guidelines in the form of knowledge graphs. Our method systematically generates descriptive sentences from domain-constrained knowledge graph triplets to formulate adversarial prompts, enhancing the relevance and challenge of the evaluation. These prompts, generated by the LLM itself and tailored to evaluate its own robustness, undergo a rigorous filtering and refinement process, ensuring that only those with high textual fluency and semantic fidelity are used. This self-evaluation mechanism allows the LLM to evaluate its robustness without the need for external benchmarks. We assess the effectiveness of our framework through extensive testing on both proprietary models like ChatGPT and open-source models such as Llama-3.1, Phi-3, and Mistral. Results confirm that our approach not only reduces dependency on conventional data but also provides a targeted and efficient means of evaluating LLM robustness in constrained domains. Aihua Pei, Zehua Yang, Shunan Zhu, Ruoxi Cheng, Ju Jia |
COLING | 5 |
| 2025 | Backdooring Self-Supervised Contrastive Learning by Noisy AlignmentabstractSelf-supervised contrastive learning (CL) effectively learns transferable representations from unlabeled data containing images or image-text pairs but suffers vulnerability to data poisoning backdoor attacks (DPCLs). An adversary can inject poisoned images into pretraining datasets, causing compromised CL encoders to exhibit targeted misbehavior in downstream tasks. Existing DPCLs, however, achieve limited efficacy due to their dependence on fragile implicit co-occurrence between backdoor and target object and inadequate suppression of discriminative features in backdoored images. We propose Noisy Alignment (NA), a DPCL method that explicitly suppresses noise components in poisoned images. Inspired by powerful training-controllable CL attacks, we identify and extract the critical objective of noisy alignment, adapting it effectively into data-poisoning scenarios. Our method implements noisy alignment by strategically manipulating contrastive learning's random cropping mechanism, formulating this process as an image layout optimization problem with theoretically derived optimal parameters. The resulting method is simple yet effective, achieving state-of-the-art performance compared to existing DPCLs, while maintaining clean-data accuracy. Furthermore, Noisy Alignment demonstrates robustness against common backdoor defenses. Codes can be found at https://github.com/jsrdcht/Noisy-Alignment. Tuo Chen, Jie Gui, Minjing Dong, Ju Jia, Lanting Fang |
ICCV | 4 |
| 2025 | Prompt as a Double-Edged Sword: A Dynamic Equilibrium Gradient-Assigned Attack against Graph Prompt LearningabstractGraph prompt learning (GPL) is designed to bridge the gap between graph pretraining models and downstream graph tasks, providing advantages in terms of graph knowledge transfer. However, GPL is vulnerable to poisoned graph attacks that induce abnormal training via adversarial malicious perturbations. We observe that the prevalent meta-gradient attacks, which heavily rely on the training of surrogate graph neural networks (GNNs), fail to account for the impact of perturbations on GPL where the pretrained GNN remains frozen and graph prompt tokens are tuned. Moreover, their gradient-assigned strategies tend to corrupt the topological semantics on a few influential labeled graphs, which in turn diminishes the trustworthiness of the surrogate training. To address this issue, we propose a dynamic equilibrium gradient-assigned attack against GPL, named MetaGpro. To guarantee the transferability of MetaGpro, the surrogate GPL is utilized in our simulation across various downstream tasks. To dynamically equilibrate the relationships between the reliability of surrogate models and instable structures, the over-robust contrastive learning is integrated into the surrogate training. In this way, the gradient bias caused by excessive perturbations of labeled nodes can be effectively mitigated. Subsequently, the topology perturbation generation is exploited to assign more gradient weights to nodes that are closer to the misclassification area. The experimental results reveal that the surrogate GPL outperforms the surrogate GNN in 96% of downstream evaluations, and our MetaGpro reduces the accuracy of GPL by 2%∼20% compared to the state-of-the-art (SOTA) works mostly. The code for our MetaGpro is available here. Ju Jia, Jingxuan Yu, Di Wu 0050, Cong Wu 0003, Hengjie Zhu, Lina Wang 0001 |
KDD (2) | 1 |
| 2025 | PATFinger: Prompt-Adapted Transferable Fingerprinting against Unauthorized Multimodal Dataset UsageabstractThe multimodal datasets can be leveraged to pre-train large-scale vision-language models by providing cross-modal semantics. Current endeavors for determining the usage of datasets mainly focus on single-modal dataset ownership verification through intrusive methods and non-intrusive techniques, while cross-modal approaches remain under-explored. Intrusive methods can adapt to multimodal datasets but degrade model accuracy, while non-intrusive methods rely on label-driven decision boundaries that fail to guarantee stable behaviors for verification. To address these issues, we propose a novel prompt-adapted transferable fingerprinting scheme from a training-free perspective, called PATFinger, which incorporates the global optimal perturbation (GOP) and the adaptive prompts to capture dataset-specific distribution characteristics. Our scheme utilizes inherent dataset attributes as fingerprints instead of compelling the model to learn triggers. The GOP is derived from the sample distribution to maximize embedding drifts between different modalities. Subsequently, our PATFinger re-aligns the adaptive prompt with GOP samples to capture the cross-modal interactions on the carefully crafted surrogate model. This allows the dataset owner to check the usage of datasets by observing specific prediction behaviors linked to the PATFinger during retrieval queries. Extensive experiments demonstrate the effectiveness of our scheme against unauthorized multimodal dataset usage on various cross-modal retrieval architectures by 30% over state-of-the-art baselines. Ju Jia, Xiaojun Jia, Yihao Huang 0001, Xinfeng Li, Cong Wu 0003, Lina Wang 0001 |
SIGIR | 2 |
| 2025 | SIGFinger: A Subtle and Interactive GNN Fingerprinting Scheme Via Spatial Structure Inference PerturbationabstractThere have been significant improvements in intellectual property (IP) protection for deep learning models trained on euclidean data. However, the complex and irregular graph-structured data in non-euclidean space poses a huge challenge to the IP protection of graph neural networks (GNNs). To address this issue, we propose a subtle and interactive GNN fingerprinting scheme through spatial structure inference perturbation, which captures the stable coordination patterns of fingerprint to guarantee the reliability of copyright verification. Specifically, the data augmentation based on adaptive graph diffusion is first exploited to generate more samples, which enables the exploration of fingerprint information from coarse to fine. Subsequently, the graph-structured data are manipulated by multi-constrained spectral clustering to analyze intrinsic and extrinsic structure correlations in a causal inference manner. Ultimately, the cycle-consistent statistical optimization is performed to determine the copyright of GNN models from both intra-graph and inter-graph perspectives. Extensive experiments show that our proposed scheme can effectively verify the IP of GNN models on various challenging graph-structured datasets. Furthermore, we reveal that the space causality inference can facilitate the acquisition of inherent structural information, which improves the quality and robustness of the fingerprint under model modification operations and other model stealing attacks. Ju Jia, Cong Wu 0003, Siqi Ma 0001, Lina Wang 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | Image Steganalysis Based on Dual-Path Enhancement and Fractal DownsamplingabstractImage steganalysis has always been an important topic in the field of information security, and researchers have designed many excellent steganalysis models. However, the existing steganalysis models tend to construct a single path and increase the convolution kernels to reduce the size of feature maps, which is not comprehensive enough to extract the features and may boost the number of parameters. In addition, the single residual block stacking may pay attention to protecting stego signals and neglect the mining of hidden features. To address these issues, we propose a steganalysis model based on dual-path enhancement and fractal downsampling, which is suitable for both spatial and JPEG domains. The model reuses and strengthens noise residuals through two dual-path enhancement blocks, and designs a fractal downsampling block for downsampling at multiple levels, angles, and composition structures. The experimental results demonstrate that the proposed model achieves the best detection performance in both spatial and JPEG domains compared with other start-of-the-art methods. Besides, we design a series of ablation experiments to verify the rationality of each component. Tong Fu, Liquan Chen, Yinghua Jiang, Ju Jia, Zhangjie Fu 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Environment-Adaptive Representation Interaction for Privacy-Perturbed Graphs Against Deceptive OOD AttacksabstractGraph neural networks (GNNs) have gained increasing popularity in understanding graph-structured data due to their ability to derive meaningful representations by aggregating complicated topological information. However, privacy operations such as differential privacy mechanisms that inject noise into node features or graph structures to protect sensitive information, and distribution shifts in graph data pose tremendous security risks for the wide application of GNN models. Current researches mainly focus on defending the out-of-distribution (OOD) attacks through robust adversarial training and graph structure purification. Nonetheless, privacy perturbations of graph structures may render OOD attacks more deceptive by obfuscating the distinctiveness of nodes, leading to the failure of existing defense methods. To address these shortcomings, we propose an environment-adaptive representation interaction (EARI) scheme that strengthens the privacy perception of GNNs. Specifically, our scheme leverages the interaction between non-private and private data to enable targeted embedding propagation by the guidance of confidence score feedback. Subsequently, the representation-enriched topological aggregation is implemented to capture more discriminative features by exploiting multi-hop neighborhoods rather than stacked multilayers. Finally, the generalization-enhanced cluster-wise adaptation learning is leveraged to highlight the invariant correlations from nodes across different environments. Extensive experimental results demonstrate that our scheme can enhance the capability of learning representations from privacy-protected graph data, enabling GNNs to effectively defend against deceptive OOD attacks on various graph-structured datasets. Moreover, we reveal that the utilization of interactive topological aggregation can extremely enrich the diversity and guarantee the effectiveness for graph representations. Ju Jia, Cong Wu 0003, Yebo Feng, Siqi Ma 0001, Lina Wang 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Profit or Deceit? Mitigating Pump and Dump in DeFi via Graph and Contrastive LearningabstractPump-and-Dump (PD) schemes pose a significant threat to the stability and fairness of Decentralized Finance (DeFi) markets, often resulting in substantial financial losses for investors. The early and accurate detection of these schemes is crucial for preserving trust in the rapidly expanding cryptocurrency ecosystem. However, existing detection methods primarily rely on post-event analysis and heuristic-based approaches, which are often inadequate for real-time and precise identification of PD activities. In this paper, we present PUMPWATCHER, an innovative framework that employs Graph Neural Networks (GNNs) and contrastive learning to detect PD schemes by modeling transaction behaviors within temporal graphs. PUMPWATCHER integrates advanced transaction graph construction, temporal GNNs, and contrastive learning techniques to enhance node and edge representations, thereby improving the detection of intricate and covert PD operations. We validate PUMPWATCHER on a dataset from Uniswap, encompassing 924,508 transactions across 858 tokens within December 2022. The results show that PUMPWATCHER outperforms state-of-the-art models, achieving a superior balanced accuracy of 92.3%, while significantly minimizing false positives and negatives. These outcomes highlight its potential to set a new standard in real-time detection of market manipulation, paving the way for more secure and resilient DeFi ecosystems. Cong Wu 0003, Jing Chen 0003, Jiahua Xu 0002, Ju Jia, Yebo Feng, Yang Liu 0003, Yang Xiang 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | A Lightweight Image Forgery Prevention Scheme for IoT Using GAN-Based SteganographyabstractComputer vision (CV) applications empower various Internet of Things (IoT) scenarios. However, their advancements in image generation and manipulation tools make it increasingly easy to produce highly deceptive forged images, escalating the risk of image forgery. Cryptography-based methods can secure images but cannot support direct CV applications with compromised visual legibility. Existing generative adversarial network (GAN)-based steganography methods can effectively facilitate CV applications and image forgery prevention with high indistinguishability between stego and cover images. However, they are inefficient in resource-constrained IoT scenarios. Therefore, we propose a lightweight image forgery prevention scheme for IoT using GAN-based steganography. Our scheme embeds identity data within images. If forged, it fails to recover, triggering alerts. Our scheme can significantly improve efficiency with a lightweight generator designed by incorporating blueprint separable convolutions, sum connections and discrete wavelet transform while ensuring high effectiveness. Real-world IoT experimental results demonstrate this. Xiao Li 0014, Liquan Chen, Ju Jia, Zhongyuan Qin, Zhangjie Fu 0001 |
IEEE Trans. Ind. Informatics | 3 |
| 2025 | CSIPose: Unveiling Human Poses Using Commodity WiFi Devices Through the WallabstractThe popularity of WiFi devices and the development of WiFi sensing have alerted people to the threat of WiFi sensing-based privacy leakage, especially the privacy of human poses. Existing work on human pose estimation is deployed in indoor scenarios or simple occlusion (e.g., a wooden screen) scenarios, which are less privacy-threatening in attack scenarios. To reveal the risk of leakage of the pose privacy to users from commodity WiFi devices, we propose CSIPose, a privacy-acquisition attack that passively estimates dynamic and static human poses in through-the-wall scenarios. We design a three-branch network based on transfer learning, auto-encoder, and self-attention mechanisms to realize the supervision of video frames over CSI frames to generate human pose skeleton frames. Notably, we designAveCSI, a unified framework for preprocessing and feature extraction of CSI data corresponding to dynamic and static poses. This framework uses the average of CSI measurements to generate CSI frames to mitigate the instability of passively collected CSI data, and utilizes a self-attention mechanism to enhance key features. We evaluate the performance of CSIPose across different room layouts, subjects, devices, subject locations, and device locations. Evaluation results emphasize the generalizability of CSIPose. Finally, we discuss measures to mitigate this attack. Yangyang Gu, Jing Chen 0003, Congrui Chen, Kun He 0008, Ju Jia, Yebo Feng, Ruiying Du, Cong Wu 0003 |
IEEE Trans. Mob. Comput. | 5 |
| 2024 | Reliable Model Watermarking: Defending against Theft without Compromising on EvasionabstractWith the rise of Machine Learning as a Service (MLaaS) platforms, safeguarding the intellectual property of deep learning models is becoming paramount. Among various protective measures, trigger set watermarking has emerged as a flexible and effective strategy for preventing unauthorized model distribution. However, this paper identifies an inherent flaw in the current paradigm of trigger set watermarking: evasion adversaries can readily exploit the shortcuts created by models memorizing watermark samples that deviate from the main task distribution, significantly impairing their generalization in adversarial settings. To counteract this, we leverage diffusion models to synthesize unrestricted adversarial examples as trigger sets. By learning the model to accurately recognize them, unique watermark behaviors are promoted through knowledge injection rather than error memorization, thus avoiding exploitable shortcuts. Furthermore, we uncover that the resistance of current trigger set watermarking against removal attacks primarily relies on significantly damaging the decision boundaries during embedding, intertwining unremovability with adverse impacts. By optimizing the knowledge transfer properties of protected models, our approach conveys watermark behaviors to extraction surrogates without aggressive decision boundary perturbation. Experimental results on CIFAR-10/100 and Imagenette datasets demonstrate the effectiveness of our method, showing not only improved robustness against evasion adversaries but also superior resistance to watermark removal attacks compared to state-of-the-art solutions. Hongyu Zhu 0004, Sichu Liang, Fangqi Li 0001, Ju Jia, Shi-Lin Wang |
ACM Multimedia | 5 |
| 2024 | A Secure and Robust Knowledge Transfer Framework via Stratified-Causality Distribution Adjustment in Intelligent Collaborative ServicesabstractThe rapid development of device-edge-cloud collaborative computing techniques has actively contributed to the popularization and application of intelligent service models. The intensity of knowledge transfer plays a vital role in enhancing the performance of intelligent services. However, the existing knowledge transfer methods are mainly implemented through data fine-tuning and model distillation, which may cause the leakage of data privacy or model copyright in intelligent collaborative systems. To address this issue, we propose a secure and robust knowledge transfer framework through stratified-causality distribution adjustment (SCDA) for device-edge-cloud collaborative services. Specifically, a simple yet effective density-based estimation is first employed to obtain uncertainty scores that guide the space stratification, which is conducive to reconstructing low-density distribution regions from high-density distribution regions more adaptively and accurately. Subsequently, we devise a novel causality-aware generative model to generate synthetic features for the out-of-distribution domain by exploring the relationship between factors and variables. Ultimately, we introduce a cycle-consistent minimax optimization mechanism to ensure the effectiveness and dependability of knowledge transfer through the influence minimization and the diversity maximization. Furthermore, extensive experiments demonstrate that our scheme can protect the security of data privacy and model copyright in intelligent collaborative services through adaptive distribution adjustment. Ju Jia, Siqi Ma 0001, Lina Wang 0001, Yang Liu 0003, Robert H. Deng |
IEEE Trans. Computers | 1 |
| 2024 | A Causality-Aligned Structure Rationalization Scheme Against Adversarial Biased Perturbations for Graph Neural NetworksabstractThe graph neural networks (GNNs) are susceptible to adversarial perturbations and distribution biases, which pose potential security concerns for real-world applications. Current endeavors mainly focus on graph matching, while the subtle relationships between the nodes and structures of graph-structured data remain under-explored. Accordingly, two fundamental challenges arise as follows: 1) the intricate connections among nodes may induce the distribution shift of graph samples even under the same scenario, and 2) the perturbations of inherent graph-structured representations can introduce spurious shortcuts, which lead to GNN models relying on biased data to make unstable predictions. To address these problems, we propose a novel causality-aligned structure rationalization (CASR) scheme to construct invariant rationales by probing the coherent and causal patterns, which facilitates GNN models to make stable and reliable predictions in case of adversarial biased perturbations. Specifically, the initial graph samples across domains are leveraged to boost the diversity of datasets and perceive the interaction between shortcuts. Subsequently, the causal invariant rationales can be obtained during the interventions. This allows the GNN model to extrapolate risk variations from a single observed environment to multiple unknown environments. Moreover, the query feedback mechanism can progressively promote the consistency-driven optimal rationalization by reinforcing real essences and eliminating spurious shortcuts. Extensive experiments demonstrate the effectiveness of our scheme against adversarial biased perturbations from data manipulation attacks and out-of-distribution (OOD) shifts on various graph-structured datasets. Notably, we reveal that the capture of distinctive rationales can greatly reduce the dependence on shortcut cues and improve the robustness of OOD generalization. Ju Jia, Siqi Ma 0001, Yang Liu 0003, Lina Wang 0001, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Efficient and Privacy-Preserving Feature Importance-Based Vertical Federated LearningabstractVertical Federated Learning (VFL) enables multiple data owners, each holding a different subset of features about a largely overlapping set of data samples, to collaboratively train a global model. The quality of data owners' local features affects the performance of the VFL model, which makes feature selection vitally important. However, existing feature selection methods for VFL either assume the availability of prior knowledge on the number of noisy features or prior knowledge on the post-training threshold of useful features to be selected, making them unsuitable for practical applications. To bridge this gap, we propose the Federated Stochastic Dual-Gate based Feature Selection (FedSDG-FS) approach. It consists of a Gaussian stochastic dual-gate to efficiently approximate the probability of a feature being selected. FedSDG-FS further designs a local embedding perturbation approach to achieve differential privacy for local training data. To reduce overhead, we propose a feature importance initialization method based on Gini impurity, which can accomplish its goals with only two parameter transmissions between the server and the clients. The enhanced version, FedSDG-FS++, protects the privacy for both the clients' training data and the server's labels through Partially Homomorphic Encryption (PHE) without relying on a trusted third-party. Theoretically, we analyze the convergence rate, privacy guarantees and security analysis of our methods. Extensive experiments on both synthetic and real-world datasets show that FedSDG-FS and FedSDG-FS++ significantly outperform existing approaches in terms of achieving more accurate selection of high-quality features as well as improving VFL performance in a privacy-preserving manner. Anran Li 0001, Ju Jia, Hongyi Peng, Lan Zhang 0002, Anh Tuan Luu, Han Yu 0001, Xiang-Yang Li 0001 |
IEEE Trans. Mob. Comput. | 3 |
| 2023 | Consensus-Clustering-Based Automatic Distribution Matching for Cross-Domain Image SteganalysisabstractImage steganalysis is a technique to detect whether an image contains hidden information. Although the existing cross-domain steganalysis methods have been presented to narrow the distribution gap between different domains, it is still challenging to effectively capture the transferable steganalysis representations under the condition of severe distribution shifts. To address this issue, we propose a novel consensus-clustering-based automatic distribution matching scheme, called CADM, which can automatically and accurately match inconsistent distributions in cross-domain steganalysis scenarios. First, the original steganalysis features are clustered by the spatially constrained fuzzyc-means (SCFCM) algorithm with controllable parameters to fully perceive and mine inherent structural relationships. Subsequently, the cluster consensus knowledge is derived from the perspective of intra-domain and inter-domain to facilitate the clustering and the matching. In this way, the representations of weak stego signals can be augmented by identifying cluster centers that can be combined across domains. Ultimately, the cycle-consistent optimization and adaptation is achieved by gradually adjusting the learning strength of well-aligned and poorly-aligned samples to promote the positive transfer of overlapped clusters and prevent the negative transfer of outlier clusters. Furthermore, extensive experiments on various benchmark databases for cross-domain steganalysis demonstrate the superiority of CADM over the current state-of-the-art methods. Ju Jia, Meng Luo 0002, Siqi Ma 0001, Lina Wang 0001, Yang Liu 0003 |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2022 | JPEG steganalysis based on denoising network and attention moduleabstractThe core objective of image steganalysis is to explore the presence of weak image steganographic signals. Extracting effective steganographic signal features will play an essential role in digital image steganalysis. However, existing networks rely more on spatial rich model kernels or random learnable kernels to obtain noise residuals during the stage of steganographic signal features extraction. In this paper, we proposed a JPEG steganalysis network which based on denoising network and attention module, mainly including a noise extract block, a noise analysis block, and a judgment block. Specifically, a professional denoising convolutional neural network is first introduced in noise extract block to obtain better steganalysis features. The noise analysis block is integrated with the attention module to finely extract the steganographic signals hidden in the complex texture regions, which is quite effective in improving the signal-to-noise ratio of the stego signal. The judgment block is primarily a classifier to distinguish between cover images and stego images. Comprehensive experiments show a significant improvement in performance over the state-of-the-art steganalysis scheme. Moreover, the proposed network has better generalization capability than the compared steganalysis network for the case of cover-source and quality factor mismatch, which is critical for future steganalysis systems. Tian Wu 0004, Weixiang Ren, Dewei Li 0005, Lina Wang 0001, Ju Jia |
Int. J. Intell. Syst. | 5 |
| 2022 | Partial Knowledge Transfer in Visual Recognition Systems via Joint Loss-Aware Consistency LearningabstractOne of the key challenges for the implementation of visual recognition systems in the real world is to construct prediction models that can realize the knowledge transfer from the seen data to the unseen data. Specifically, partial knowledge transfer (PKT) aims to address a more common and realistic scenario in which we are accessible to a label-rich source domain while working on a relative label-scarce target domain. The essence of PKT is to explore the latent categories across different domains and simultaneously facilitate the positive transfer from these data. In this article, we propose a joint loss-aware consistency learning (JLACL) to effectively enhance the transferability of knowledge in visual recognition systems, which conducts an iterative optimization on three-level losses, including discrepancy loss, consensus loss, and cross-entropy loss. The discrepancy loss is designed to eliminate the class distribution bias by a similarity perception metric between the source and target domains. The consensus loss can assist to preserve domain-invariant and representative features for model learning by exploring correlation. Moreover, we also find that using the cross-entropy loss to determine the shared label space, which can help to alleviate the negative transfer by suppressing the features with nonshared labels. Finally, the PKT can be successfully achieved by joint optimization of total losses. Extensive experiments on several public and challenging datasets in visual recognition applications adequately demonstrate the superiority of our proposed JLACL over existing state-of-the-art PKT methods. Ju Jia, Meng Luo 0002, Siqi Ma 0001, Lina Wang 0001 |
IEEE Trans. Ind. Informatics | 1 |
| 2022 | An Effective Imbalanced JPEG Steganalysis Scheme Based on Adaptive Cost-Sensitive Feature LearningabstractSteganalysis in real-world application often exhibit skewed sample distribution which poses a massive challenge for steganography detection. Conventional steganalysis algorithms are not effective when the training data distribution is imbalanced, and may fail in the scenario of imbalanced data distribution. To address imbalanced data distribution issue in steganalysis, a novel framework termed adaptive cost-sensitive feature learning via F-measure maximization is proposed, which is inspired by the fact that F-measure is a more suitable performance metric compared to accuracy for imbalanced data. We investigate the adaptive cost-sensitive strategy by generating and assigning different weight to each instance with misclassification occurrence. This scheme adaptively determines the weights according to the intra-class and inter-class costs from the imbalanced distribution. Features corresponding to the largest F-measure can be obtained by solving a series of adaptive cost-sensitive feature learning problems with optimization theory. In this way, the learned features are the most representative features between the cover and stego images so that imbalanced steganalysis can significantly alleviate. Extensive experiments on various imbalanced steganalysis tasks show the superiority of the proposed method over the state-of-the-art methods, and it can recognize more minority samples and has excellent classification performance. Ju Jia, Liming Zhai, Weixiang Ren, Lina Wang 0001, Yanzhen Ren |
IEEE Trans. Knowl. Data Eng. | 1 |
| 2022 | Multiperspective Progressive Structure Adaptation for JPEG Steganography Detection Across DomainsabstractThe aim of steganography detection is to identify whether the multimedia data contain hidden information. Although many detection algorithms have been presented to solve tasks with inconsistent distributions between the source and target domains, effectively exploiting transferable correlation information across domains remains challenging. As a solution, we present a novel multiperspective progressive structure adaptation (MPSA) scheme based on active progressive learning (APL) for JPEG steganography detection across domains. First, the source and target data originating from unprocessed steganalysis features are clustered together to explore the structures in different domains, where the intradomain and interdomain structures can be captured to provide adequate information for cross-domain steganography detection. Second, the structure vectors containing the global and local modalities are exploited to reduce nonlinear distribution discrepancy based on APL in the latent representation space. In this way, the signal-to-noise ratio (SNR) of a weak stego signal can be improved by selecting suitable objects and adjusting the learning sequence. Third, the structure adaptation across multiple domains is achieved by the constraints for iterative optimization to promote the discrimination and transferability of structure knowledge. In addition, a unified framework for single-source domain adaptation (SSDA) and multiple-source domain adaptation (MSDA) in mismatched steganalysis can enhance the model's capability to avoid a potential negative transfer. Extensive experiments on various benchmark cross-domain steganography detection tasks show the superiority of the proposed approach over the state-of-the-art methods. Ju Jia, Meng Luo 0002, Jinshuo Liu, Weixiang Ren, Lina Wang 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 1 |
| 2020 | Learning selection channels for image steganalysis in spatial domain
Weixiang Ren, Liming Zhai, Ju Jia, Lina Wang 0001, Lefei Zhang |
Neurocomputing | 3 |
| 2020 | Transferable heterogeneous feature subspace learning for JPEG mismatched steganalysis
Ju Jia, Liming Zhai, Weixiang Ren, Lina Wang 0001, Yanzhen Ren, Lefei Zhang |
Pattern Recognit. | 1 |