EDBT 2026 Demo / reviewers in the wild / expert
Hanbin Hong
dblp:271/7093
· DBLP profile ↗
9ranked-venue papers
4as first author
8since 2021 · last 2025
0009-0007-0538-6669ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 3 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Harmonizing Differential Privacy Mechanisms for Federated Learning: Boosting Accuracy and ConvergenceabstractDifferentially private federated learning (DP-FL) offers a compelling approach to collaborative model training by ensuring robust privacy for clients. Despite its potential, current methods face challenges in effectively balancing privacy, utility, and performance across diverse federated learning scenarios. Addressing these challenges, we introduce UDP-FL, to our knowledge the first DP-FL framework that universally harmonizes any randomization mechanism, including those considered optimal, by employing the Gaussian Moments Accountant (viz. DP-SGD). Central to UDP-FL is the 'Harmonizer,' a dynamic module engineered to intelligently select and apply the most suitable DP mechanism tailored to each client's specific privacy requirements, data sensitivities, and computational capacities. This selection process is driven by the principle of Rényi Differential Privacy, which serves as a crucial mediator for aligning privacy budgets effectively. Our comprehensive evaluation of UDP-FL, benchmarked against established baseline methods, demonstrates superior performance in upholding privacy guarantees and enhancing model functionality. The framework's robustness has been rigorously tested against a broad spectrum of privacy attacks, making it one of the most thorough validations of a DP-FL framework to date. Shuya Feng, Meisam Mohammady, Hanbin Hong, Shenao Yan, Ashish Kundu, Binghui Wang, Yuan Hong 0001 |
CODASPY | 3 |
| 2025 | Certifying Adapters: Enabling and Enhancing the Certification of Classifier Adversarial RobustnessabstractRandomized smoothing is a leading method for achieving certified robustness in deep classifiers against ℓp-norm adversarial perturbations. However, randomized smoothing requires expensive training procedures that tune large models for different Gaussian noise levels from scratch and thus cannot leverage high-performance pre-trained neural networks. In this work, we introduce the certifying adapters framework (CAF) that enables and enhances the certification of classifier adversarial robustness. Our approach makes few assumptions about the underlying training algorithm or feature extractor, and is thus broadly applicable to different feature extractor architectures (e.g., convolutional neural networks or vision transformers) and randomized smoothing algorithms. We show that CAF (a) enables certification in uncertified models pre-trained on clean datasets and (b) substantially improves the performance of classifiers certified using randomized smoothing and SmoothAdv at multiple radii in CIFAR-10 and ImageNet. Classifiers trained with CAF achieve substantially improved certified accuracies compared to random or denoised smoothing methods. Finally, we demonstrate that CAF is insensitive to hyperparameter settings and adapter ensembles enable a single pre-trained feature extractor to defend against a range of noise perturbation scales. Jieren Deng, Hanbin Hong, Aaron Palmer, Xin Zhou 0017, Jinbo Bi, Kaleel Mahmood, Yuan Hong 0001, Derek Aguiar |
IJCNN | 2 |
| 2024 | Certifiable Black-Box Attacks with Randomized Adversarial Examples: Breaking Defenses with Provable ConfidenceabstractBlack-box adversarial attacks have demonstrated strong potential to compromise machine learning models by iteratively querying the target model or leveraging transferability from a local surrogate model.Recently, such attacks can be effectively mitigated by state-of-the-art (SOTA) defenses, e.g., detection via the pattern of sequential queries, or injecting noise into the model. To our best knowledge, we take the first step to study a new paradigm of black-box attacks with provable guarantees -- certifiable black-box attacks that can guarantee the attack success probability (ASP) of adversarial examples before querying over the target model. This new black-box attack unveils significant vulnerabilities of machine learning models, compared to traditional empirical black-box attacks, e.g., breaking strong SOTA defenses with provable confidence, constructing a space of (infinite) adversarial examples with high ASP, and the ASP of the generated adversarial examples is theoretically guaranteed without verification/queries over the target model. Specifically, we establish a novel theoretical foundation for ensuring the ASP of the black-box attack with randomized adversarial examples (AEs). Then, we propose several novel techniques to craft the randomized AEs while reducing the perturbation size for better imperceptibility. Finally, we have comprehensively evaluated the certifiable black-box attacks on the CIFAR10/100, ImageNet, and LibriSpeech datasets, while benchmarking with 16 SOTA black-box attacks, against various SOTA defenses in the domains of computer vision and speech recognition. Both theoretical and experimental results have validated the significance of the proposed attack. Hanbin Hong, Xinyu Zhang 0016, Binghui Wang, Zhongjie Ba, Yuan Hong 0001 |
CCS | 1 |
| 2024 | Text-CRS: A Generalized Certified Robustness Framework against Textual Adversarial AttacksabstractThe language models, especially the basic text classification models, have been shown to be susceptible to textual adversarial attacks such as synonym substitution and word insertion attacks. To defend against such attacks, a growing body of research has been devoted to improving the model’s robustness. However, providing provable robustness guarantees instead of empirical robustness is still widely unexplored. In this paper, we propose Text-CRS, a generalized certified robustness framework for natural language processing (NLP) based on randomized smoothing. To our best knowledge, existing certified schemes for NLP can only certify the robustness against ℓ0perturbations in synonym substitution attacks. Representing each word-level adversarial operation (i.e., synonym substitution, word reordering, insertion, and deletion) as a combination of permutation and embedding transformation, we propose novel smoothing theorems to derive robustness bounds in both permutation and embedding space against such adversarial operations. To further improve certified accuracy and radius, we consider the numerical relationships between discrete words and select proper noise distributions for the randomized smoothing. Finally, we conduct substantial experiments on multiple language models and datasets. Text-CRS can address all four different word-level adversarial operations and achieve a significant accuracy improvement. We also provide the first benchmark on certified accuracy and radius of four word-level operations, besides outperforming the state-of-the-art certification against synonym substitution attacks.1 Xinyu Zhang 0016, Hanbin Hong, Yuan Hong 0001, Binghui Wang, Zhongjie Ba, Kui Ren 0001 |
SP | 2 |
| 2024 | An LLM-Assisted Easy-to-Trigger Backdoor Attack on Code Completion Models: Injecting Disguised Vulnerabilities against Strong Detection
Shenao Yan, Yue Duan, Hanbin Hong, Kiho Lee, Doowon Kim, Yuan Hong 0001 |
USENIX Security Symposium | 4 |
| 2023 | Energy-Limited UAV Visiting Planning for Age-Aware Wireless-Powered Sensor NetworksabstractUnmanned aerial vehicle (UAV) has revealed its great advantage to provide efficient data collection and wireless charging services to wireless-power sensor networks (WPSNs). Note that the UAV usually is equipped with limited battery power and therefore may not have enough energy to visit all sensor nodes (SNs) during a flight. However, the energy consumption of the UAV is rarely discussed in UAV-assisted WPSNs. In this paper, we study visiting planning problem in the UAV-assisted WPSN by considering both the energy limitation of the UAV and the age of information (AoI) of data collection. Specifically, we introduce a mixed data collection strategy to reduce the AoI of the collected data and improve the energy efficiency of the UAV during each flight. The formulated AoI-aware problem, which aims to minimize the average AoI of the collected data and meanwhile maximize the number of visiting SNs as well as the amount of data, is further tackled by utilizing the reformulation-linearization-technique (RLT) and alternating direction method of multipliers (ADMM). The results show the proposed ADMM-based algorithm can outperform other approaches in terms of system objective and energy efficiency. Hanbin Hong, Yajing Xie |
VTC Fall | 1 |
| 2022 | L-SRR: Local Differential Privacy for Location-Based Services with Staircase Randomized ResponseabstractLocation-based services (LBS) have been significantly developed and widely deployed in mobile devices. It is also well-known that LBS applications may result in severe privacy concerns by collecting sensitive locations. A strong privacy model ''local differential privacy'' (LDP) has been recently deployed in many different applications (e.g., Google RAPPOR, iOS, and Microsoft Telemetry) but not effective for LBS applications due to the low utility of existing LDP mechanisms. To address such deficiency, we propose the first LDP framework for a variety of location-based services (namely ''L-SRR''), which privately collects and analyzes user locations with high utility. Specifically, we design a novel randomization mechanism ''Staircase Randomized Response'' (SRR) and extend the empirical estimation to significantly boost the utility for SRR in different LBS applications (e.g., traffic density estimation, and k-nearest neighbors). We have conducted extensive experiments on four real LBS datasets by benchmarking with other LDP schemes in practical applications. The experimental results demonstrate that L-SRR significantly outperforms them. Han Wang 0021, Hanbin Hong, Li Xiong 0001, Zhan Qin, Yuan Hong 0001 |
CCS | 2 |
| 2022 | UniCR: Universally Approximated Certified Robustness via Randomized Smoothing
Hanbin Hong, Binghui Wang, Yuan Hong 0001 |
ECCV (5) | 1 |
| 2020 | Privacy Attributes-aware Message Passing Neural Network for Visual Privacy Attributes ClassificationabstractVisual Privacy Attribute Classification (VPAC) identifies privacy information leakage via social media images. These images containing privacy attributes such as skin color, face or gender are classified into multiple privacy attribute categories in VPAC. With limited works in this task, current methods often extract features from images and simply classify the extracted feature into multiple privacy attribute classes. The dependencies between privacy attributes, e.g., skin color and face typically coexist in the same image, are usually ignored in classification, which causes performance degradation in VPAC. In this paper, we propose a novel end-to-end Privacy Attributes-aware Message Passing Neural Network (PA-MPNN) to address VPAC. Privacy attributes are considered as nodes on a graph and an MPNN is introduced to model the privacy attribute dependencies. To generate representative features for privacy attribute nodes, a class-wise encoder-decoder is proposed to learn a latent space for each attribute. An attention mechanism with multiple correlation matrices is also introduced in MPNN to learn the privacy attributes graph automatically. Experimental results on the Privacy Attribute Dataset demonstrate that our framework achieves better performance than state-of-the-art methods for visual privacy attributes classification. Hanbin Hong, Wentao Bao, Yuan Hong 0001, Yu Kong 0001 |
ICPR | 1 |