EDBT 2026 Demo / reviewers in the wild / expert
Ruitao Hou
dblp:266/2550
· DBLP profile ↗
7ranked-venue papers in the field
2as first author
7since 2021 · last 2024
0000-0003-3734-7350ORCID · corroborated
Domains — venue-derived; a paper can count in several
Other / Interdisciplinary · 4Knowledge Engineering, Semantic Web & Information Systems · 3 (2 first)
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Exploring the vulnerability of self-supervised monocular depth estimation models
Ruitao Hou, Kanghua Mo, Yucheng Long, Ning Li 0050, Yuan Rao 0002 |
Inf. Sci. | 1 |
| 2023 | Transfer subspace learning via label release and contribution degree distinction
Xiaojin Fan, Ruitao Hou, Liehuang Zhu |
Inf. Sci. | 2 |
| 2022 | ELAA: An efficient local adversarial attack using model interpretersabstractModern deep neural networks are highly vulnerable to adversarial examples, which attracts more and more researchers' attention to craft powerful adversarial examples. Most of these generation algorithms create global perturbations that would affect the visual quality of adversarial examples. To mitigate such drawbacks, some attacks attempt to generate local perturbations. However, existing local adversarial attacks are time-consuming and the generated adversarial examples are still distinguishable from clean images. In this paper, we propose a novel efficient local adversarial attack (ELAA) using model interpreters to generate severe local perturbations and improve the imperceptibly of the generated adversarial examples. Specifically, we take advantage of model interpretation methods to search the discriminative regions of clean images. Then, we generate local adversarial examples by adding masks to original clean images. We also propose a new optimization method to reduce the redundancy of local perturbations. Through extensive experiments, we show our ELAA can maintain a high attack ability while preserving the visual quality of clean images. Experimental results also demonstrate our local attack outperforms state-of-the-art local attack methods under various system settings. Shangwei Guo, Siyuan Geng, Tao Xiang 0001, Hangcheng Liu, Ruitao Hou |
Int. J. Intell. Syst. | 5 |
| 2022 | An effective and practical gradient inversion attackabstractWhile gradient aggregation playing a vital role in federated or collaborative learning, recent studies have revealed that gradient aggregation may suffer from some attacks, such as gradient inversion, where the private training data can be recovered from the shared gradients. However, the performance of the existing attack methods is limited because they usually require prior knowledge in Batch Normalization and could only reconstruct a single image or a small batch one. To make the attacks less restrictive and more applicable, we propose an effective and practical gradient inversion method in this paper. Specifically, we use cosine similarity to measure the difference of gradients between the synthesized and ground-truth images, and then construct an input regularization for the fully connected layer to ensure the fidelity of the image. Moreover, we apply the total variation denoising strategy to the convolution feature map for further improving the smoothness of the reconstructed image. Experimental results demonstrate that our method can reconstruct high fidelity training data on a large batch size for complex data sets, such as ImageNet. Zeren Luo, Chuangwei Zhu, Lujie Fang, Guang Kou, Ruitao Hou, Xianmin Wang |
Int. J. Intell. Syst. | 5 |
| 2022 | Towards explainable model extraction attacksabstractOne key factor able to boost the applications of artificial intelligence (AI) in security-sensitive domains is to leverage them responsibly, which is engaged in providing explanations for AI. To date, a plethora of explainable artificial intelligence (XAI) has been proposed to help users interpret model decisions. However, given its data-driven nature, the explanation itself is potentially susceptible to a high risk of exposing privacy. In this paper, we first show that the existing XAI is vulnerable to model extraction attacks and then present an XAI-aware dual-task model extraction attack (DTMEA). DTMEA can attack a target model with explanation services, that is, it can extract both the classification and explanation tasks of the target model. More specifically, the substitution model extracted by DTMEA is a multitask learning architecture, consisting of a sharing layer and two task-specific layers for classification and explanation. To reveal which explanation technologies are more vulnerable to expose privacy information, we conduct an empirical evaluation of four major explanation types in the benchmark data set. Experimental results show that the attack accuracy of DTMEA outperforms the predicted-only method with up to 1.25%, 1.53%, 9.25%, and 7.45% in MNIST, Fashion-MNIST, CIFAR-10, and CIFAR-100, respectively. By exposing the potential threats on explanation technologies, our research offers the insights to develop effective tools that are able to trade off security-sensitive relationships. Anli Yan, Ruitao Hou, Xiaozhang Liu, Hongyang Yan, Teng Huang 0001, Xianmin Wang |
Int. J. Intell. Syst. | 2 |
| 2022 | Privacy-preserving image retrieval in a distributed environmentabstractNowadays, several image-based smart services have been widely used in our daily lives, generating many digital images. Since smart devices outsource digital images to the cloud, researchers prefer to select some desired targets from the massive images within the cloud for analysis and improve smart services. Therefore, protective image retrieval on the cloud has attained maximum concentration for privacy-preserving purposes, and the availability assurance of images on the cloud is also a crucial link. Ensuring image security and availability in the cloud environment and precisely preserving retrieval accuracy is comes as a utility-security dilemma while few existing works have explicitly addressed it. Therefore, this paper proposes privacy-preserving image retrieval in the distributed environment based on the combination of image encryption for similarity search and secret image sharing. On the basis of them, we define two-stage encryption. The first-stage encryption algorithm is introduced by modifying Wolfram's reversible cellular automata-based image encryption, which can create a set of processing images to ensure image security and retrieval accuracy. Then, the second-stage encryption algorithm is put forward based on secret image sharing to improve image security and availability. The color histogram could be extracted from the encrypted images for similarity retrieval, and the shadows could be extracted for similar image recovery. Security analysis demonstrates that image privacy and query privacy could be well protected. Moreover, the proposed work achieves more efficient performance for similarity search and similar image recovery compared with some recent works and realizes a reasonable retrieval accuracy on encrypted images for similarity search. Fucai Zhou, Shiyue Qin, Ruitao Hou, Zongye Zhang 0001 |
Int. J. Intell. Syst. | 3 |
| 2022 | Similarity-based integrity protection for deep learning systems
Ruitao Hou, Shan Ai, Qi Chen 0024, Hongyang Yan, Teng Huang 0001, Kongyang Chen |
Inf. Sci. | 1 |