EDBT 2026 Demo / reviewers in the wild / expert
Yang-Wai Chow
dblp:27/1663
· DBLP profile ↗
38ranked-venue papers
13as first author
15since 2021 · last 2026
0000-0003-3348-7014ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 7 first-author · 9 since 2021Human-computer interaction and ubiquitous computing · 4 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 first-authorSystems, architecture and hardware · 1Computer networks · 1 · 1 first-author · 1 since 2021Theory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Adversarial-Example Agnostic Detection in Network Intrusion Detection Systems
Wei Zong, Yang-Wai Chow, Willy Susilo |
ACISP (3) | 3 |
| 2025 | AudioMarkNet: Audio Watermarking for Deepfake Speech Detection
Wei Zong, Yang-Wai Chow, Willy Susilo, Joonsang Baek, Seyit Ahmet Çamtepe |
USENIX Security Symposium | 2 |
| 2025 | Detecting Generative Model Inversion Attacks for Protecting Intellectual Property of Deep Neural NetworksabstractRecently, protecting the Intellectual Property (IP) of deep neural networks (DNNs) has attracted attention from researchers. This is because training DNN models can be costly especially when acquiring and labeling training data require domain expertise. DNN watermarking and fingerprinting are two techniques proposed to prevent DNN IP infringement. Although these two techniques achieve high performance on defending against previously proposed DNN stealing attacks, researchers recently show that both of them are ineffective against generative model inversion attacks. Specifically, an adversary inverts training data from well-trained DNNs and uses the inverted data to train DNNs from scratch such that DNN watermarking and fingerprinting are both bypassed. This novel model stealing strategy shows that data inverted from victim models can be effectively exploited by adversaries, which poses a new threat to the IP protection of DNNs. To combat this new threat, one potential solution is to enable defenders to prove ownership on data inverted from models being protected. If the training data of a suspected model, which can be disclosed via the judicial process, are proven to be data inverted from victim models, then IP infringement is detected. This research direction is currently underexplored. In this paper, we fill the gap in the literature to investigate countermeasures against this emerging threat. We propose a simple but effective method, called InverseDataInspector (IDI), to detect whether data are inverted from victim models. Specifically, our method first extracts features from both the inverted data and victim models. These features are then combined and used for training classifiers. Experimental results demonstrate that our method achieves high performance on detecting inverted data and also generalizes to new generative model inversion methods that are not seen when training classifiers. Yiding Yu, Wei Zong, Yang-Wai Chow, Willy Susilo |
J. Artif. Intell. Res. | 4 |
| 2024 | IPRemover: A Generative Model Inversion Attack against Deep Neural Network Fingerprinting and WatermarkingabstractTraining Deep Neural Networks (DNNs) can be expensive when data is difficult to obtain or labeling them requires significant domain expertise. Hence, it is crucial that the Intellectual Property (IP) of DNNs trained on valuable data be protected against IP infringement. DNN fingerprinting and watermarking are two lines of work in DNN IP protection. Recently proposed DNN fingerprinting techniques are able to detect IP infringement while preserving model performance by relying on the key assumption that the decision boundaries of independently trained models are intrinsically different from one another. In contrast, DNN watermarking embeds a watermark in a model and verifies IP infringement if an identical or similar watermark is extracted from a suspect model. The techniques deployed in fingerprinting and watermarking vary significantly because their underlying mechanisms are different. From an adversary's perspective, a successful IP removal attack should defeat both fingerprinting and watermarking. However, to the best of our knowledge, there is no work on such attacks in the literature yet. In this paper, we fill this gap by presenting an IP removal attack that can defeat both fingerprinting and watermarking. We consider the challenging data-free scenario whereby all data is inverted from the victim model. Under this setting, a stolen model only depends on the victim model. Experimental results demonstrate the success of our attack in defeating state-of-the-art DNN fingerprinting and watermarking techniques. This work reveals a novel attack surface that exploits generative model inversion attacks to bypass DNN IP defenses. This threat must be addressed by future defenses for reliable IP protection. Wei Zong, Yang-Wai Chow, Willy Susilo, Joonsang Baek, Jongkil Kim, Seyit Ahmet Çamtepe |
AAAI | 2 |
| 2024 | The search term 'suicide' is being used to lead web browsers to online casinosabstractWhile Search Engine Optimisation seeks to enhance PageRankings, some methods are not approved or condoned by browser developers. To understand the risks faced by suicidal gamblers in the online environment, 2 studies examined the behaviour of an online search engine. A series of Google searches in 2021 used key terms such as ‘suicide’ and ‘gambling’ that might be employed by a suicidal gambler. During these searches browser ‘hits’ included opportunities to gamble. Webpages (N = 200) offered to a potentially suicidal gambler were primarily categorised as: other suicides (20%), treatment providers (8.5%), online casinos (7%); politics (22%), academic (23.5%). From a Google search providing 1,090 hits, the links to 113 online casinos were classified as a function of Domain Name hijacking, Metatag Stuffing, Error 404, and presence of Malware. There were significant relationships between the size of the businesses whose Domain Names were hijacked, and the presence of Malware. The deliberate use by webpage designers of the word ‘suicide’ to attract customers to online casinos appears inappropriate and ethically questionable. James G. Phillips, Yang-Wai Chow, Heather Rogers, Alex Blaszczynski |
Behav. Inf. Technol. | 2 |
| 2023 | Sarcasm Relation to Time: Sarcasm Detection with Temporal Features and Deep Learning
Md Saifullah Razali, Alfian Abdul Halin, Yang-Wai Chow, Noris Mohd. Norowi, Shyamala C. Doraisamy |
PRICAI (2) | 3 |
| 2023 | HeSUN: Homomorphic Encryption for Secure Unbounded Neural Network Inference
Duy Tung Khanh Nguyen, Dung Hoang Duong, Willy Susilo, Yang-Wai Chow |
SecureComm (1) | 4 |
| 2023 | TrojanModel: A Practical Trojan Attack against Automatic Speech Recognition SystemsabstractWhile deep learning techniques have achieved great success in modern digital products, researchers have shown that deep learning models are susceptible to Trojan attacks. In a Trojan attack, an adversary stealthily modifies a deep learning model such that the model will output a predefined label whenever a trigger is present in the input. In this paper, we present TrojanModel, a practical Trojan attack against Automatic Speech Recognition (ASR) systems. ASR systems aim to transcribe voice input into text, which is easier for subsequent downstream applications to process. We consider a practical attack scenario in which an adversary inserts a Trojan into the acoustic model of a target ASR system. Unlike existing work that uses noise-like triggers that will easily arouse user suspicion, the work in this paper focuses on the use of unsuspicious sounds as a trigger, e.g., a piece of music playing in the background. In addition, TrojanModel does not require the retraining of a target model. Experimental results show that TrojanModel can achieve high attack success rates with negligible effect on the target model’s performance. We also demonstrate that the attack is effective in an over-the-air attack scenario, where audio is played over a physical speaker and received by a microphone. Wei Zong, Yang-Wai Chow, Willy Susilo, Kien Do, Svetha Venkatesh |
SP | 2 |
| 2023 | PCSF: Privacy-Preserving Content-Based Spam FilterabstractThe purpose of privacy-preserving spam filtering is to inspect email while preserving the privacy of its detection rules and the email content. Although many solutions have emerged, they suffer from the following: 1) Theprivacyprovided is insufficient as the email content or detection rules may be exposed to third parties; 2) Due to improper use of encryption, exhaustive word search attacks are possible, potentially breaking theconfidentialityof encrypted emails; 3) When spam filtering is outsourced, email is given to the outsource, whereuser privacy may be compromisedif privacy protection measures are not properly put in place; 4) Confirmation of whether the encrypted email is spam is only determinedafterthe receiver receives the email, which can lead to a situation in which spam is loaded to the memory of the receiver’s terminal for spam filtering. This can be harmful, for example, when an attacker inserts a web browser vulnerability into the body of an email to lure users to a phishing site simply by reading the email; 5)Computationally expensive operationsare unavoidable to provide required features of privacy-preserving spam filtering. We present Privacy-preserving Content-based Spam Filter (PCSF), which is a spam filter system that does not suffer from the aforementioned issues. Additionally, our system providespre-validationbefore the receiver reads the email. We provide an implementation of our system based on the Naive Bayes spam filter and prove its security. Intae Kim, Willy Susilo, Joonsang Baek, Jongkil Kim, Yang-Wai Chow |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2022 | Privacy-preserving file sharing on cloud storage with certificateless signcryption
Pairat Thorncharoensri, Willy Susilo, Yang-Wai Chow |
Theor. Comput. Sci. | 3 |
| 2021 | Towards Visualizing and Detecting Audio Adversarial Examples for Automatic Speech Recognition
Wei Zong, Yang-Wai Chow, Willy Susilo |
ACISP | 2 |
| 2021 | SyLPEnIoT: Symmetric Lightweight Predicate Encryption for Data Privacy Applications in IoT Environments
Tran Viet Xuan Phuong, Willy Susilo, Guomin Yang, Jongkil Kim, Yang-Wai Chow, Dongxi Liu |
ESORICS (2) | 5 |
| 2021 | Black-Box Audio Adversarial Example Generation Using Variational Autoencoder
Wei Zong, Yang-Wai Chow, Willy Susilo |
ICICS (2) | 2 |
| 2021 | Targeted Universal Adversarial Perturbations for Automatic Speech Recognition
Wei Zong, Yang-Wai Chow, Willy Susilo, Santu Rana, Svetha Venkatesh |
ISC | 2 |
| 2021 | Utilizing QR codes to verify the visual fidelity of image datasets for machine learning
Yang-Wai Chow, Willy Susilo, Jianfeng Wang 0001, Richard Buckland, Joonsang Baek, Jongkil Kim, Nan Li 0007 |
J. Netw. Comput. Appl. | 1 |
| 2020 | Interactive three-dimensional visualization of network intrusion detection data for machine learning
Wei Zong, Yang-Wai Chow, Willy Susilo |
Future Gener. Comput. Syst. | 2 |
| 2019 | Dimensionality Reduction and Visualization of Network Intrusion Detection Data
Wei Zong, Yang-Wai Chow, Willy Susilo |
ACISP | 2 |
| 2018 | A 3D Approach for the Visualization of Network Intrusion Detection DataabstractWith the increasing threat of cyber attacks, machine learning techniques have been researched extensively in the area of network intrusion detection. Such techniques can potentially provide a means for the real-time automated detection of attacks and abnormal traffic patterns. However, misclassification is a common problem in machine learning techniques for intrusion detection, and a lack of insight into why such misclassification occurs impedes the improvement of machine learning models. This paper presents an approach to visualizing network intrusion detection data in 3D. The purpose of this is to facilitate the understanding of network intrusion detection datasets using a visual representation to reflect the geometric relationship between various categories of network traffic. This can potentially provide useful insight to aid the design of machine learning techniques. This paper demonstrates the usefulness of the proposed 3D visualization approach by presenting results of experiments on commonly used network intrusion detection datasets. Wei Zong, Yang-Wai Chow, Willy Susilo |
CW | 2 |
| 2018 | A Two-Stage Classifier Approach for Network Intrusion Detection
Wei Zong, Yang-Wai Chow, Willy Susilo |
ISPEC | 2 |
| 2017 | A QR Code Watermarking Approach Based on the DWT-DCT Technique
Yang-Wai Chow, Willy Susilo, Joseph Tonien, Wei Zong |
ACISP (2) | 1 |
| 2017 | Cooperative Learning in Information Security Education: Teaching Secret Sharing Concepts
Yang-Wai Chow, Willy Susilo, Guomin Yang |
CDVE | 1 |
| 2017 | Covert QR Codes: How to Hide in the Crowd
Yang-Wai Chow, Willy Susilo, Joonsang Baek |
ISPEC | 1 |
| 2016 | Exploiting the Error Correction Mechanism in QR Codes for Secret Sharing
Yang-Wai Chow, Willy Susilo, Guomin Yang, James G. Phillips, Ilung Pranata, Ari Moesriami Barmawi |
ACISP (1) | 1 |
| 2016 | Recipient Revocable Identity-Based Broadcast Encryption: How to Revoke Some Recipients in IBBE without Knowledge of the PlaintextabstractIn this paper, we present the notion of recipient-revocable identity-based broadcast encryption scheme. In this notion, a content provider will produce encrypted content and send them to a third party (which is a broadcaster). This third party will be able to revoke some identities from the ciphertext. We present a security model to capture these requirements, as well as a concrete construction. The ciphertext consists of k+3 group elements, assuming that the maximum number of revocation identities is k. That is, the ciphertext size is linear in the maximal size of R, where R is the revocation identity set. However, we say that the additional elements compared to that from an IBBE scheme are only for the revocation but not for decryption. Therefore, the ciphertext sent to the users for decryption will be of constant size (i.e.,3 group elements). Finally, we present the proof of security of our construction. Willy Susilo, Rongmao Chen, Fuchun Guo, Guomin Yang, Yi Mu 0001, Yang-Wai Chow |
AsiaCCS | 6 |
| 2014 | A Visual One-Time Password Authentication Scheme Using Mobile Devices
Yang-Wai Chow, Willy Susilo, Man Ho Au, Ari Moesriami Barmawi |
ICICS | 1 |
| 2014 | A CAPTCHA Scheme Based on the Identification of Character Locations
Vu Duc Nguyen, Yang-Wai Chow, Willy Susilo |
ISPEC | 2 |
| 2014 | On the security of text-based 3D CAPTCHAs
Vu Duc Nguyen, Yang-Wai Chow, Willy Susilo |
Comput. Secur. | 2 |
| 2012 | Breaking an Animated CAPTCHA Scheme
Vu Duc Nguyen, Yang-Wai Chow, Willy Susilo |
ACNS | 2 |
| 2012 | Attacking Animated CAPTCHAs via Character Extraction
Vu Duc Nguyen, Yang-Wai Chow, Willy Susilo |
CANS | 2 |
| 2012 | Enhancing the Perceived Visual Quality of a Size Invariant Visual Cryptography Scheme
Yang-Wai Chow, Willy Susilo, Duncan S. Wong |
ICICS | 1 |
| 2012 | Enhanced STE3D-CAP: A Novel 3D CAPTCHA Family
Yang-Wai Chow, Willy Susilo |
ISPEC | 1 |
| 2012 | Towards Formalizing a Reputation System for Cheating Detection in Peer-to-Peer-Based Massively Multiplayer Online Games
Willy Susilo, Yang-Wai Chow, Rungrat Wiangsripanawan |
NSS | 2 |
| 2011 | AniCAP: An Animated 3D CAPTCHA Scheme Based on Motion Parallax
Yang-Wai Chow, Willy Susilo |
CANS | 1 |
| 2010 | STE3D-CAP: Stereoscopic 3D CAPTCHA
Willy Susilo, Yang-Wai Chow, Hua-Yu Zhou |
CANS | 2 |
| 2010 | CAPTCHA Challenges for Massively Multiplayer Online Games: Mini-game CAPTCHAsabstractBotting or automated programs in Massively Multiplayer Online Games (MMOGs) has long been a problem in these networked virtual environments. The use of bots gives cheating players an unfair advantage over other honest players. Using bots, players can potentially amass a huge amount of game wealth, resources, experience points, etc. Without much effort, as bot programs can be run continuously for countless hours and will never get tired. Honest players on the other hand have to spend much more time and effort in order to gather an equal amount of game resources. This destroys the fun for legitimate players, ruins the balance of the game and threatens the game developer's revenue base as discontented players may stop playing the game. Research efforts have proposed the incorporation of CAPTCHA (Completely Automated Public Turing test to tell Computers and Humans Apart) challenges in games to prevent or detect potential cheaters, by presenting challenges that are easy for a human to solve but are difficult for a computer to solve. However, the incorporation of CAPTCHA challenges in games is often seen in a negative light, as they are deemed to be intrusive and that they destroy the sense of immersion in the game. This research presents an approach of using CAPTCHAs in MMOGs that is both secure and adds game play value to the game. Yang-Wai Chow, Willy Susilo, Hua-Yu Zhou |
CW | 1 |
| 2005 | Region warping in a virtual reality system with priority rendering
Yang-Wai Chow, Ronald Pose, Matthew Regan |
IADIS AC | 1 |
| 2005 | A networked virtual environment communications model using priority updating
Yang-Wai Chow, Ronald Pose, Matthew Regan |
IADIS AC | 1 |
| 2005 | Design issues in human visual perception experiments on region warping
Yang-Wai Chow, Ronald Pose, Matthew Regan |
IADIS AC | 1 |