EDBT 2026 Demo / reviewers in the wild / expert
Liqun Shan
dblp:276/6779
· DBLP profile ↗
8ranked-venue papers
4as first author
7since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 6 · 3 first-author · 6 since 2021Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Purified Distillation Slimming (PDS) for Robust Backdoor DefenseabstractBackdoor attacks pose significant risks to applications based on deep neural networks (DNNs). Current defenses fail to achieve good performance with lightweight (compact) models, limited defense data, and low poisoning rates. To address these challenges, we propose Purified Distillation Slimming (PDS), a novel knowledge distillation approach equipped with iterative pruning. Specifically, we initialize the student model from the backdoored teacher model and iteratively prune the student's neurons until the trigger pattern is deactivated. Such an approach leverages the efficacy of knowledge distillation to transfer purified knowledge from a potentially compromised teacher model to a student model, thereby filtering out backdoor triggers embedded within the training data. Concurrently, we employ network slimming to prune backdoored neurons, enhancing the model's resilience to backdoor attacks by reducing the neurons that adversaries can exploit. Through comprehensive experiments against 17 SOTA backdoor attacks, we demonstrate that our proposed method not only effectively mitigates the impact of backdoor attacks but also preserves, and in some cases even enhances, the model's performance on benign tasks. The effectiveness of PDS has been verified on multiple datasets (Cifar-10, GTSRB, and ImageNet) across several network architectures (ResNet, VGG, MobileNet, EfficientNet, and GoogLeNet). Liqun Shan, Kaiying Han, Yazhou Tu, Insup Lee 0001, Xiali Hei 0001 |
AsiaCCS | 1 |
| 2025 | AdvOSD: Adversarial One-Step Diffusion for Generalizable and Efficient Fake Image DetectionabstractDetecting synthetic images generated by more ad-vanced generative models, such as Generative Adversarial Net-works (GANs) and Diffusion Models (DMs), is still a significant challenge. The images generated by these models are very vi-sually realistic and tend to evade current detection techniques, especially those struggling with generalization and efficiency. The present study suggests AdvOSD (Adversarial One-Step Diffusion), a generalizable and efficient approach to detecting fake images. AdvOSD operates by examining the comparative robustness of real and synthetic images to an adversarial-driven, specially crafted one-step diffusion transformation. The method begins by generating an oracle prompt for an input image through a BLIP model. The prompt is further manipu-lated through targeted noun substitution with NLP techniques to craft an effective adversarial prompt for interfering with the image's reconstruction process. AdvOSD's strength lies in its one-step transformation module: the input image's latent representation and adversarial prompt embedding are fed into a LoRA-adapted UNet, which, along with a diffusion model scheduler, performs one efficient transformation step to produce a reconstructed image. Authenticity is then assessed by calculating the similarity between original and transformed images. Experimental results on several benchmark datasets demonstrate that AdvOSD achieves competitive detection ac-curacy, particularly for editted images. For efficiency, the inversion-based baseline ZeroFake reports 30.2 s/image on a DGX A100, whereas AdvOSD runs ~ 1.5 s/image on a con-sumer RTX 3060- 20 x faster despite far weaker hardware (A100: 640 GB HBM2e; 3060: 12 GB GDDR6), making it a practical solution for real-world applications. Liqun Shan, Kaiying Han, Yazhou Tu, Xiali Hei 0001 |
ACSAC | 1 |
| 2025 | LiveGuard: Voice Liveness Detection via Wavelet Scattering Transform and Mel Spectrogram ScalingabstractVoice-controlled interfaces are essential in modern smart devices, but they remain vulnerable to replay attacks that compromise voice authentication systems. Existing voice liveness detection methods often struggle to distinguish human speech from replayed audio. This paper introduces a novel approach, LiveGuard, utilizing wavelet scattering transform (WST) and Mel spectrogram scaling with a lightweight ResNet architecture to enhance voice liveness detection. WST captures robust hierarchical features, while Mel spectrogram scaling extracts fine-grained acoustic details, which the lightweight ResNet efficiently processes to identify live voice. Experimental results demonstrate accuracy improvements of 6% with WST and Mel spectrogram scaling, achieving a top accuracy of 97.17% on POCO dataset. Meanwhile, LiveGuard demonstrates superior performance on ASVspoof2019 and ASVspoof2021 benchmarks. It achieves the lowest equal error rate (EER) of 0.13%, and a min t-DCF of 0.00126 on ASVspoof2019, and an EER of 0.42% on ASVspoof2021, surpassing state-of-the-art methods. Liqun Shan, Xingli Zhang 0004, Md. Imran Hossen, Xiali Hei 0001 |
DSN | 1 |
| 2024 | IdentityKD: Identity-wise Cross-modal Knowledge Distillation for Person Recognition via mmWave Radar SensorsabstractRecent advancements in person recognition have raised concerns about identity privacy leaks.Gait recognition through millimeterwave radar provides a privacy-centric method.However, it is challenged by lower accuracy due to the sparse data these sensors capture.We are the first to investigate a cross-modal method, Iden-tityKD, to enhance gait-based person recognition with the assistance of facial data.IdentityKD involves a training process using both gait and facial data, while the inference stage is conducted exclusively with gait data.To effectively transfer facial knowledge to the gait model, we create a composite feature representation using contrastive learning.This method integrates facial and gait features into a unified embedding that captures the unique identityspecific information from both modalities.We employ two distinct contrastive learning losses.One minimizes the distance between embeddings of data pairs from the same person, enhancing intraclass compactness, while the other maximizes the distance between embeddings of data pairs from different individuals, improving inter-class separability.Additionally, we use an identity-wise distillation strategy, which tailors the training process for each individual, ensuring that the model learns to distinguish between different identities more effectively.Our experiments on a dataset of 36 subjects, each providing over 5000 face-gait pairs, demonstrate that IdentityKD improves identity recognition accuracy by 6.5% compared to baseline methods. Liqun Shan, Rujun Zhang, Sai Venkatesh Chilukoti, Xingli Zhang 0004, Insup Lee 0001, Xiali Hei 0001 |
MMAsia | 1 |
| 2024 | From Virtual Touch to Tesla Command: Unlocking Unauthenticated Control Chains From Smart Glasses for Vehicle TakeoverabstractThis paper studies vulnerabilities at the intersection of wearable devices and automated control systems. Particularly, we focus on exploiting smart glasses as an entry point and unveil the threats of taking over security-critical automated control chains without user verification or interaction. These vulnerabilities can be especially pertinent in scenarios where security mechanisms only depend on entry point security with minimal user verification (relying on complete trust over previous nodes in automated control chains). We have validated the effects of our attacks on real-world systems (e.g., Tesla vehicles) that are controlled by software and automation tools such as Apple Shortcuts or IFTTT. We show how our contactless, speaker-independent, and electromagnetic interference based attacks can control functionalities such as unlocking doors and initiating remote start of Tesla vehicles, even though the victim’s phone is in a lock-screen status. Our findings not only demonstrate the potential for unauthorized control over automated, connected systems but also highlight the urgent need for more robust security measures in the integration of wearable technology with broader automation frameworks. Xingli Zhang 0004, Yazhou Tu, Yan Long 0002, Liqun Shan, Mohamed A Elsaadani, Kevin Fu, Zhiqiang Lin 0001, Xiali Hei 0001 |
SP | 4 |
| 2024 | Paa-Tee: A Practical Adversarial Attack on Thermal Infrared Detectors with Temperature and Pose AdaptabilityabstractThermal infrared object detectors play an important role in security-related tasks, necessitating feasible adversarial attacks to evaluate their robustness. In many cases, implementing attacks in the physical space by a patch demands intricate and specialized perturbations. However, state-of-the-art adversarial attacks are often impractical, as they require fixed perturbation location and are susceptible to environmental temperature, leading to attack effects overfitting to specific poses and environments. To address this, we propose a practical adversarial attack method named Paa-Tee, with two input transformation strategies. For poses, we continuously alter the patch’s position to mitigate the impact of different poses on the patch’s location. For temperature, leveraging the principles of thermal imaging, we apply various transformations to a single input image to simulate different attack environments. Meanwhile, we utilize hot and cold pastes as low-resolution patches to implement attacks in the physical world. Extensive experiments validate the efficacy of our approach in both the digital and physical worlds. In the digital world, our attacks reduce the average precision of mainstream detectors by 65.44%. In the physical world, we achieve an average attack success rate of 63.77% under various distances, poses, angles, and environmental conditions. Zhangchi Zhao, Liqun Shan, Ziyin Zhou, Kaiying Han, Xiali Hei 0001 |
TrustCom | 3 |
| 2023 | Auditory Eyesight: Demystifying μs-Precision Keystroke Tracking Attacks on Unconstrained Keyboard Inputs
Yazhou Tu, Liqun Shan, Md. Imran Hossen, Sara Rampazzi, Kevin R. B. Butler, Xiali Hei 0001 |
USENIX Security Symposium | 2 |
| 2020 | Attention-based bidirectional gated recurrent unit neural networks for well logs prediction and lithology identification
Lili Zeng, Weijian Ren, Liqun Shan |
Neurocomputing | 3 |