EDBT 2026 Demo / reviewers in the wild / expert
Zeping Zhang
dblp:253/2375
· DBLP profile ↗
16ranked-venue papers
4as first author
16since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 6 · 2 first-author · 6 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Consensus Learning with Multi-Party Perturbation Triggers for Secure Model AccessabstractWith the widespread deployment of deep learning models in multi-party collaborative scenarios, the issues of secure model access control and intellectual property (IP) protection have become increasingly critical. To address the limitations of existing methods that lack proactive defense mechanisms in such settings, this paper introduces a novel paradigm Consensus Learning which enables fine-grained control over model execution permissions via a multi-party joint authorization mechanism. Building on this, we propose the Collaborative Perturbation Trigger Method (CPTM), which allows participating parties to collaboratively generate perturbation-based trigger data that embed identity features. The model can only be activated using the collectively constructed trigger, enforcing tightly bound access control without modifying the model architecture. Extensive experiments on CIFAR-10, CIFAR-100, MNIST, and Face-LFW datasets demonstrate that the proposed method maintains prediction accuracy within 2% of the baseline unprotected models on authorized data. In contrast, under unauthorized or adversarial inputs, model accuracy drops below 10%, showcasing strong access control capabilities and robustness. This study offers a novel direction for building scalable, robust, and proactively protected deep learning models in multi-party collaborative environments. Yizhun Zhang, Zeping Zhang, Changhao Ding |
AAAI | 3 |
| 2026 | Multimodal privacy-leaking image detection method based on multi-image correlation
Changhao Ding, Zeping Zhang, Yizhun Zhang |
Neurocomputing | 4 |
| 2026 | Flexible Model Inversion Attack with soft biometric attribute reconstruction against face classifiers
Zeping Zhang, Changhao Ding |
J. Syst. Archit. | 1 |
| 2026 | A Knowledge-Driven dual trigger mechanism for enhancing model security in multi-Source fusion systems
Yizhun Zhang, Zeping Zhang, Changhao Ding |
Knowl. Based Syst. | 4 |
| 2026 | MDV: Resolving the Auxiliary Data Dilemma in Model Extraction DefensesabstractCurrent studies have discovered that model extraction attacks (MEA) can steal the functionality of deep learning (DL) models, thus causing economic loss and other security threats. Extraction attackers can build a clone model locally that has a different structure but similar functionality to the victim model. To counter MEA, defenders utilize realistic auxiliary data to enhance the victim model and produce misleading predictions for attack data. However, these defense methods have three critical problems caused by utilizing realistic auxiliary data. First, in some scenarios, realistic auxiliary data is absent and difficult to obtain. Secondly, the defense effectiveness brought by realistic auxiliary data is unstable. Finally, the realistic auxiliary data did not protect all categories of training data, resulting in higher clone accuracy for some categories. To address these issues, we propose Model Defense Variational Autoencoder (MDV) to generate virtual auxiliary data as a replacement for realistic auxiliary data. MDV combines the Variational Autoencoder (VAE) and classifier, compelling the latent features to obey different multivariate Gaussian distributions according to the categories. Then, MDV samples deep features from low-likelihood regions of different distributions as realistic auxiliary data. During the experimental phase, we apply our auxiliary data to different defense methods that use auxiliary data and compare the defense effects in different scenarios. Experimental results demonstrate that our method effectively addressed the three aforementioned issues. Chuang Liang, Jie Huang 0016, Zeping Zhang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Semantic Heat Guided Relational Privacy Inference Based on Panoptic Scene GraphabstractPrivacy is a subjective concept that depends on human perception and contextual interpretation, based on interaction between subject and object. With the increasing occurrence of privacy leaking incidents, awareness about implicit risks has been evolving. The leakage and misuse of relational information between critical objects emerge as core issues in such security events, defined in this study as “relational privacy”. In images, relational privacy primarily manifests through semantic relations between object pairs. To identify pairs with higher privacy potential, we propose the concept of “semantic heat”. To ensure interpretability and avoid rigid logical judgments, Probabilistic Soft Logic (PSL) is employed to construct semantic heat levels. Scene graph, providing structured semantic representations of image contents, is highly suitable for investigating relational privacy. We utilize panoptic scene graphs to mitigate noise introduced by traditional bounding boxes and leverage contextual information between object pairs. Additionally, a mask crossattention mechanism guided by textual instruction is proposed to extract interactive features between objects effectively. Finally, a two-stage relation decoder based on a Large Multi-modal Model (LMM) is designed to perform open-set relation prediction and strength judgment. Experimental results demonstrated that the proposed method achieved performance close to the state-of-theart and showed certain advantages in recall rate, enabling a more comprehensive detection of relational privacy. Jie Huang 0016, Changhao Ding, Zeping Zhang |
RAID | 4 |
| 2025 | Exploiting the connections between images and deep feature vectors in model inversion attacks
Zeping Zhang |
Neurocomputing | 1 |
| 2025 | T-TNet: A dual-dependency trigger framework for active defense and hierarchical access control via multi-domain information fusion
Yizhun Zhang, Zeping Zhang, Changhao Ding |
J. Syst. Archit. | 4 |
| 2024 | Defending against model extraction attacks with OOD feature learning and decision boundary confusion
Chuang Liang, Jie Huang 0016, Zeping Zhang |
Comput. Secur. | 3 |
| 2024 | SecureNet: Proactive intellectual property protection and model security defense for DNNs based on backdoor learning
Peihao Li 0002, Jie Huang 0016, Huaqing Wu, Zeping Zhang, Chunyang Qi |
Neural Networks | 4 |
| 2024 | Aligning the domains in cross domain model inversion attack
Zeping Zhang, Jie Huang 0016 |
Neural Networks | 1 |
| 2023 | Compromise privacy in large-batch Federated Learning via model poisoning
Jie Huang 0016, Zeping Zhang, Peihao Li 0002, Chunyang Qi |
Inf. Sci. | 3 |
| 2023 | Analysis and Utilization of Hidden Information in Model Inversion AttacksabstractThe widely applications of deep learning have raised concerns about the privacy issues in deep neural networks. Model inversion attack aims to reconstruct specific details of each private training sample from a given neural network. However, limited to the availability of useful information, reconstructing distinctive private training samples still has a long way to go. In this paper, the requirements to reconstruct distinctive private training samples are investigated using information entropy. We find that more information is needed to reconstruct distinctive samples and propose to use the often ignored hidden information to achieve this goal. To better utilize this information, Amplified-MIA is proposed. In Amplified-MIA, a nonlinear amplification layer is inserted between the target network and the attack network. This nonlinear amplification layer further contains a nonlinear amplification function. The definition of the nonlinear amplification function is given and the effect of this nonlinear amplification function on the entropy of the hidden information is derived. The proposed nonlinear amplification function can amplify the small prediction vector entries and enlarge the differences between different prediction vectors in the same class. Thus, the hidden information can be better utilized by the attack network and distinctive private samples can be reconstructed. Various experiments are performed to empirically analyze the effects of the nonlinear amplification function on the reconstruction results. The reconstruction results on three different datasets show that the proposed Amplified-MIA outperforms existing works on almost all tasks. Especially, it achieves up to 68% performance gain of the Pixel Accuracy score over the direct inversion method on the hardest face reconstruction task. Zeping Zhang, Jie Huang 0016 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Compromise Privacy in Large-Batch Federated Learning via Malicious Model Parameters
Jie Huang 0016, Zeping Zhang, Chunyang Qi |
ICA3PP | 3 |
| 2022 | Unsupervised Multiple Change Detection in Remote Sensing Images via Generative Representation Learning NetworkabstractWith abundant temporal, spectral, and spatial information, multispectral images are proficient for acquiring a superior comprehension of the Earth’s condition and its changes, which enables the achievement of multiple change detection (CD) tasks. However, high temporal, spatial, and spectral information of data brings obstacles to perform multiple change analysis due to the lack of effective feature extraction operation. In addition, the traditional multiple CD methods rely too much on manual participation. Here, a generative representation learning network (GRN) and a cyclic clustering technique are combined into a unified model, which is driven to learn spatial–temporal–spectral features for unsupervised multiple CD. GRN aims to efficiently extract and merge robust difference information with a recurrent learning mechanism for self-adaptive classification refinement, in which different types of changes can be identified and highlighted. Furthermore, a cyclic training strategy is designed to refine the clustering-friendly features, in which similar change types are gradually merged into the same classes. Meanwhile, the number of change types will be optimized through a self-adaptive way and eventually converge to its stable state, which is close to the real distribution. Experimental results on real multispectral datasets demonstrate the effectiveness and superiority of the proposed model on multiple CD. Jiao Shi, Zeping Zhang, Chunhui Tan, Xiaodong Liu 0019, Yu Lei 0002 |
IEEE Geosci. Remote. Sens. Lett. | 2 |
| 2022 | Collaborative Self-Perception Network Architecture for Hyperspectral Image Change DetectionabstractDespite the great advantages in deep feature representation when dealing with change detection (CD) problem, the designs of neural networks were time-consuming processes of trial and error. In addition, the traditional CD methods based on deep neural networks (DNN) only deal with one dataset at a time, which has limited learning knowledge and undoubtedly fails to take advantage of the common characteristics among similar datasets. For hyperspectral images (HSIs) obtained by the same sensor, the spectral information has a similar physical meaning (radiance or reflectivity). To utilize the inherent similarity within hyperspectra for learning a robust difference signature, a collaborative analysis framework with self-perception network architecture (SPNA-CA) is proposed to efficiently learn from multiple datasets and leverage their synergy. Different network architecture searching tasks are established for each dataset pertinently, in which the evolutionary multitasking self-perception network architecture (SPNA) method is designed for exploring effective and reasonable network architectures. Besides, a cross-task knowledge transfer mechanism (CKTM) is proposed to transfer excellent network architecture information, which improves the efficiency of the collaborative analysis framework. Experimental results confirm the effectiveness of collaborative analysis for solving HSI-CD problems among multiple datasets. Jiao Shi, Zeping Zhang, Yu Lei 0002 |
IEEE Geosci. Remote. Sens. Lett. | 2 |