EDBT 2026 Demo / reviewers in the wild / expert
Yuni Lai
dblp:255/4898
· DBLP profile ↗
15ranked-venue papers
7as first author
14since 2021 · last 2026
0000-0002-2295-912XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 4 first-author · 6 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adversarial Robustness of Link Sign Prediction in Signed GraphsabstractSigned graphs serve as fundamental data structures for representing positive and negative relationships in social networks, with signed graph neural networks (SGNNs) emerging as the primary tool for their analysis. Our investigation reveals that balance theory, while essential for modeling signed relationships in SGNNs, inadvertently introduces exploitable vulnerabilities to black-box attacks. To showcase this, we propose balance-attack, a novel adversarial strategy specifically designed to compromise graph balance degree, and develop an efficient heuristic algorithm to solve the associated NP-hard optimization problem. While existing approaches attempt to restore attacked graphs through balance learning techniques, they face a critical challenge we term “Irreversibility of Balance-related Information,” as restored edges fail to align with original attack targets. To address this limitation, we introduce Balance Augmented-Signed Graph Contrastive Learning (BA-SGCL), an innovative framework that combines contrastive learning with balance augmentation techniques to achieve robust graph representations. By maintaining high balance degree in the latent space, BA-SGCL not only effectively circumvents the irreversibility challenge but also significantly enhances model resilience. Extensive experiments across multiple SGNN architectures and real-world datasets demonstrate both the effectiveness of our proposed balance-attack and the superior robustness of BA-SGCL, advancing the security and reliability of signed graph analysis in social networks. Datasets and codes of the proposed framework are at the github repositoryhttps://github.com/JialongZhou666/BA-SGCL.git. Jialong Zhou, Xing Ai, Yuni Lai, Tomasz P. Michalak, Gaolei Li, Jianhua Li 0001, Mengpei Yang, Kai Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Toward Polymorphic Backdoor Against Semantic Communication via Intensity-Based Poisoning
Xiao Yang 0016, Yuni Lai, Gaolei Li, Jun Wu 0001, Kai Zhou 0001, Jianhua Li 0001, Mingzhe Chen |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | SemanAegis: Toward Credential-Aware Semantic Communication Against Knowledge Leakage ThreatsabstractSemantic Communication (SC) achieves meaning transmission instead of bitstreams by deep semantic encoding decoding. Since the encoder-decoder contains sensitive and proprietary knowledge, its illicit leakage infringes commercial benefits and copyright, which warrants corresponding protection. However, current SC security paradigms narrowly emphasize transmission data protection while neglecting encoding knowl edge safeguarding. To bridge this gap, we present SemanAegis, the first SC knowledge protection framework. SemanAegisinte grates a built-in-system access control mechanism that remains effective even if the system is stolen, ensuring that unauthorized access attempts yield unacceptable low-fidelity outputs, while credential-embedded inputs from authorized entities are met with accurate responses. Specifically, we establish access control through backdoor implantation, whereby only inputs embedded with credentials activate the backdoor and access system, while source inputs are constrained to generate erroneous results. Moreover, we adopt a synthesizer to generate imperceptible credentials, thus guaranteeing their confidentiality. Additionally, a dedicated contrastive learning strategy is implemented to accelerate the convergence of backdoor implanting. Empirical evaluations across SC systems and benchmark datasets demonstrate SemanAegis precisely rejects unauthorized inputs, effectively mitigates knowledge extractions, and consistently preserves SC regular functionality. Xiao Yang 0016, Yuni Lai, Gaolei Li, Jun Wu 0001, Kai Zhou 0001, Mingzhe Chen |
IEEE Trans. Mob. Comput. | 2 |
| 2025 | GraphProt: Certified Black-Box Shielding Against Backdoored Graph ModelsabstractGraph learning models have been empirically proven to be vulnerable to backdoor threats, wherein adversaries submit trigger-embedded inputs to manipulate the model predictions. Current graph backdoor defenses manifest several limitations: 1) dependence on model-related details, 2) necessitation of additional fine-tuning, and 3) reliance on extra explainability tools, all of which are infeasible under stringent privacy policies. To address those limitations, we propose GraphProt, a certified black-box defense method to suppress backdoor attacks on GNN-based graph classifiers. Our GraphProt operates in a model-agnostic manner and solely leverages graph input. Specifically, GraphProt first introduces designed topology-feature-filtration to mitigate graph anomalies. Subsequently, subgraphs are sampled via a formulated strategy integrating topology and features, followed by a robust model inference through a majority vote-based subgraph prediction ensemble. Our results across benchmark attacks and datasets show GraphProt effectively reduces attack success rates while preserving regular graph classification accuracy. Xiao Yang 0016, Yuni Lai, Kai Zhou 0001, Gaolei Li, Jianhua Li 0001, Hang Zhang 0010 |
IJCAI | 2 |
| 2025 | A Distributed Adaptive System with Strong Tie Graphs for Trust-Aware Reasoning in Adversarial GraphsabstractThis study proposes a distributed adaptive system for robust reasoning over graph-structured data under structural poisoning attacks, where adversaries strategically manipulate edges to compromise predictive integrity. We introduce the Graph Adaptive Neural Network (GANN), a modular framework that treats trust and risk zones within the graph as semi-autonomous components capable of self-regulating their propagation behaviors based on adversarial feedback. Leveraging fuzzy-theoretic Strong Tie Graphs (STiG), GANN adaptively identifies and reinforces high-confidence regions to ensure resilient node classification and secure query handling. The system operates as a surrogate defense layer, dynamically managing zone-based structural decomposition and trust calibration in response to perturbations. Its selective validation-driven adaptation mechanism restricts the attacker’s ability to exploit unlabeled data, forcing them toward costly global strategies. A confidence-based regulation framework further enhances GANN’s robustness under bounded adversarial budgets, with demonstrated effectiveness in non-IID and directed graph settings. Experimental results validate GANN’s capability as a self-adjusting distributed system, advancing adaptive defenses in graph-based data management and adversarial query environments. Yu Bu, Yulin Zhu 0001, Yuni Lai |
SMC | 3 |
| 2025 | From Bi-Level to One-Level: A Framework for Structural Attacks to Graph Anomaly DetectionabstractThe success of graph neural networks stimulates the prosperity of graph mining and the corresponding downstream tasks including graph anomaly detection (GAD). However, it has been explored that those graph mining methods are vulnerable to structural manipulations on relational data. That is, the attacker can maliciously perturb the graph structures to assist the target nodes in evading anomaly detection. In this article, we explore the structural vulnerability of two typical GAD systems: unsupervised FeXtra-based GAD and supervised graph convolutional network (GCN)-based GAD. Specifically, structural poisoning attacks against GAD are formulated as complex bi-level optimization problems. Our first major contribution is then to transform the bi-level problem into one-level leveraging different regression methods. Furthermore, we propose a new way of utilizing gradient information to optimize the one-level optimization problem in the discrete domain. Comprehensive experiments demonstrate the effectiveness of our proposed attack algorithm $\textsf {BinarizedAttack}$ . Yulin Zhu 0001, Yuni Lai, Kaifa Zhao, Xiapu Luo, Mingquan Yuan, Jun Wu 0001, Jian Ren 0001, Kai Zhou 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 2 |
| 2024 | Poster: AuditVotes: A Framework towards Deployable Certified Robustness for GNNsabstractGraph Neural Networks (GNNs) are powerful but vulnerable to adversarial attacks, necessitating the research on certified robustness that can provide GNNs with robustness guarantees. Existing randomized smoothing methods struggle with a trade-off between utility and robustness due to high noise levels. We introduce AuditVotes, which integrates randomized smoothing with two components, augmentation and conditional smoothing, aiming to improve data and vote quality. We instantiated AuditVotes with simple strategies, and preliminary results demonstrate its significant promise in enhancing certified robustness, representing a substantial step toward deploying certifiably robust GNNs in real-world applications. Yuni Lai, Kai Zhou 0001 |
CCS | 1 |
| 2024 | Cost Aware Untargeted Poisoning Attack Against Graph Neural NetworksabstractGraph Neural Networks (GNNs) have become widely used in the field of graph mining. However, these networks are vulnerable to structural perturbations. While many research efforts have focused on analyzing vulnerability through poisoning attacks, we have identified an inefficiency in current attack losses. These losses steer the attack strategy towards modifying edges targeting misclassified nodes or resilient nodes, resulting in a waste of structural adversarial perturbation. To address this issue, we propose a novel attack loss framework called the Cost Aware Poisoning Attack (CA-attack) to improve the allocation of the attack budget by dynamically considering the classification margins of nodes. Specifically, it prioritizes nodes with smaller positive margins while postponing nodes with negative margins. Our experiments demonstrate that the proposed CA-attack significantly enhances existing attack strategies. Yuwei Han, Yuni Lai, Yulin Zhu 0001, Kai Zhou 0001 |
ICASSP | 2 |
| 2024 | Collective Certified Robustness against Graph Injection AttacksabstractWe investigate certified robustness for GNNs under graph injection attacks. Existing research only provides sample-wise certificates by verifying each node independently, leading to very limited certifying performance. In this paper, we present the first collective certificate, which certifies a set of target nodes simultaneously. To achieve it, we formulate the problem as a binary integer quadratic constrained linear programming (BQCLP). We further develop a customized linearization technique that allows us to relax the BQCLP into linear programming (LP) that can be efficiently solved. Through comprehensive experiments, we demonstrate that our collective certification scheme significantly improves certification performance with minimal computational overhead. For instance, by solving the LP within 1 minute on the Citeseer dataset, we achieve a significant increase in the certified ratio from 0.0% to 81.2% when the injected node number is 5% of the graph size. Our paper marks a crucial step towards making provable defense more practical. Our source code is available at https://github.com/Yuni-Lai/CollectiveLPCert. Yuni Lai, Bailin Pan, Kaihuang Chen, Yancheng Yuan, Kai Zhou 0001 |
ICML | 1 |
| 2024 | Node-aware Bi-smoothing: Certified Robustness against Graph Injection AttacksabstractDeep Graph Learning (DGL) has emerged as a crucial technique across various domains. However, recent studies have exposed vulnerabilities in DGL models, such as susceptibility to evasion and poisoning attacks. While empirical and provable robustness techniques have been developed to defend against graph modification attacks (GMAs), the problem of certified robustness against graph injection attacks (GIAs) remains largely unexplored. To bridge this gap, we introduce the node-aware bi-smoothing framework, which is the first certifiably robust approach for general node classification tasks against GIAs. Notably, the proposed node-aware bi-smoothing scheme is model-agnostic and is applicable for both evasion and poisoning attacks. Through rigorous theoretical analysis, we establish the certifiable conditions of our smoothing scheme. We also explore the practical implications of our node-aware bi-smoothing schemes in two contexts: as an empirical defense approach against real-world GIAs and in the context of recommendation systems. Furthermore, we extend two state-of-the-art certified robustness frameworks to address node injection attacks and compare our approach against them. Extensive evaluations demonstrate the effectiveness of our proposed certificates.1 Yuni Lai, Yulin Zhu 0001, Bailin Pan, Kai Zhou 0001 |
SP | 1 |
| 2024 | Coupled-Space Attacks Against Random-Walk-Based Anomaly DetectionabstractRandom Walks-based Anomaly Detection (RWAD) is commonly used to identify anomalous patterns in various applications. An intriguing characteristic of RWAD is that the input graph can either be pre-existing graphs or feature-derived graphs constructed from raw features. Consequently, there are two potential attack surfaces against RWAD: graph-space attacks and feature-space attacks. In this paper, we explore this vulnerability by designing practical coupled-space (interdependent feature-space and graph-space) attacks, investigating the interplay between graph-space and feature-space attacks. To this end, we conduct a thorough complexity analysis, proving that attacking RWAD is NP-hard. Then, we proceed to formulate the graph-space attack as a bi-level optimization problem and propose two strategies to solve it: alternative iteration (alterI-attack) or utilizing the closed-form solution of the random walk model (cf-attack). Finally, we utilize the results from the graph-space attacks as guidance to design more powerful feature-space attacks (i.e., graph-guided attacks). Comprehensive experiments demonstrate that our proposed attacks are effective in enabling the target nodes to evade the detection from RWAD with a limited attack budget. In addition, we conduct transfer attack experiments in a black-box setting, which show that our feature attack significantly decreases the anomaly scores of target nodes. Our study opens the door to studying the coupled-space attack against graph anomaly detection in which the graph space relies on the feature space. Yuni Lai, Marcin Waniek, Yulin Zhu 0001, Tomasz P. Michalak, Talal Rahwan, Kai Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Toward Adversarially Robust Recommendation From Adaptive Fraudster DetectionabstractThe robustness of recommender systems under node injection attacks has garnered significant attention. Recently, GraphRfi, a Graph-Neural-Network-based (GNN-based) recommender system, was proposed and shown to effectively mitigate the impact of injected fake users. However, we demonstrate that GraphRfi remains vulnerable to attacks due to the supervised nature of its fraudster detection component, where obtaining clean labels is challenging in practice. In particular, we propose a powerful poisoning attack, MetaC, against both GNN-based and Martix-Faxtorization-based recommender systems. Furthermore, we analyze why GraphRfi fails under such an attack. Then, based on our insights obtained from vulnerability analysis, we design an adaptive fraudster detection module that explicitly considers label uncertainty. This module can serve as a plug-in for different recommender systems, resulting in a robust framework named Posterior-Detection Recommender (PDR). Comprehensive experiments show that our defense approach outperforms other benchmark methods under attacks. Overall, our research presents an effective framework for integrating fraudster detection into recommendation systems to achieve adversarial robustness. Yuni Lai, Yulin Zhu 0001, Wenqi Fan, Xiaoge Zhang 0001, Kai Zhou 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Toward Certified Robustness of Graph Neural Networks in Adversarial AIoT EnvironmentsabstractGraph neural networks (GNNs) have transformed network analysis, leading to state-of-the-art performance across a variety of tasks. Especially, GNNs are increasingly been employed as detection tools in the AIoT environment in various security applications. However, GNNs have also been shown vulnerable to adversarial graph perturbation. We present the first approach for certifying robustness of general GNNs against attacks that add or remove graph edges either at training or prediction time. Extensive experiments demonstrate that our approach significantly outperforms prior art in certified robust predictions. In addition, we show that a noncertified adaptation of our method exhibits significantly better robust accuracy against state-of-the-art attacks that past approaches. Thus, we achieve both the best certified bounds and best practical robustness of GNNs to structural attacks to date. Yuni Lai, Jialong Zhou, Xiaoge Zhang 0001, Kai Zhou 0001 |
IEEE Internet Things J. | 1 |
| 2022 | BinarizedAttack: Structural Poisoning Attacks to Graph-based Anomaly DetectionabstractGraph-based Anomaly Detection (GAD) is becoming prevalent due to the powerful representation abilities of graphs as well as recent advances in graph mining techniques. These GAD tools, however, expose a new attacking surface, ironically due to their unique advantage of being able to exploit the relations among data. That is, attackers now can manipulate those relations (i.e., the structure of the graph) to allow some target nodes to evade detection. In this paper, we exploit this vulnerability by designing a new type of targeted structural poisoning attacks to a representative regression-based GAD system termed OddBall. Specifically, we formulate the attack against OddBall as a bi-level optimization problem, where the key technical challenge is to efficiently solve the problem in a discrete domain. We propose a novel attack method termed BinarizedAttack based on gradient descent. Comparing to prior arts, BinarizedAttack can better use the gradient information, making it particularly suitable for solving combinatorial optimization problems. Furthermore, we investigate the attack transferability of BinarizedAttack by employing it to attack other representation-learning-based GAD systems. Our comprehensive experiments demonstrate that BinarizedAttack is very effective in enabling target nodes to evade graph-based anomaly detection tools with limited attacker's budget, and in the black-box transfer attack setting, BinarizedAttack is also tested effective and in particular, can significantly change the node embeddings learned by the GAD systems. Our research thus opens the door to studying a new type of attack against security analytic tools that rely on graph data. Yulin Zhu 0001, Yuni Lai, Kaifa Zhao, Xiapu Luo, Mingquan Yuan, Jian Ren 0001, Kai Zhou 0001 |
ICDE | 2 |
| 2020 | Fine-grained emotion classification of Chinese microblogs based on graph convolution networks
Yuni Lai, Linfeng Zhang 0001, Donghong Han, Rui Zhou 0001, Guoren Wang |
World Wide Web | 1 |