Kanghua Mo

dblp:278/1999 · DBLP profile ↗
← Back
4ranked-venue papers in the field
1as first author
4since 2021 · last 2024
0000-0002-3762-674XORCID · corroborated

Domains — venue-derived; a paper can count in several

Knowledge Engineering, Semantic Web & Information Systems · 3Other / Interdisciplinary · 1 (1 first)
YearPublicationVenuePosition
2024 Exploring the vulnerability of self-supervised monocular depth estimation models
Ruitao Hou, Kanghua Mo, Yucheng Long, Ning Li 0050, Yuan Rao 0002
Inf. Sci.2
2022 ESM: Selfish mining under ecological footprint
Shan Ai, Guoyu Yang, Chang Chen 0003, Kanghua Mo, Wangyong Lv, Arthur Sandor Voundi Koe
Inf. Sci.4
2022 Sender anonymity: Applying ring signature in gateway-based blockchain for IoT is not enough
Arthur Sandor Voundi Koe, Shan Ai, Anli Yan, Qi Chen 0024, Kanghua Mo, Wanqing Jie, Shiwen Zhang 0004
Inf. Sci.7
2021 Querying little is enough: Model inversion attack via latent information
abstract
As machine learning (ML) technologies evolve, various online intelligent services use ML models to provide predictions. Unfortunately, attackers can obtain the private information of the model by interacting with the online service, namely model inversion attack (MIA). However, MIA requires large data sets to be transferred to an online service to obtain the predictive value of the inference model. Besides, the huge transmission may cause the administrator's active defense. To overcome this drawback, we propose a novel MIA scheme, which leverages latent information extracted by an auxiliary neural network as high-dimensional features to simplify what inversion model should learn. The core idea of our scheme is to reuse some parameters of the local pretraining model. Extensive experiments have verified the effectiveness of our method in convolutional neural networks on LFW, pubFig, MNIST data sets. Experimental results show that even with a few queries, our inversion method still work accurately and is superior to other technologies. It is worth mentioning that our method makes it more difficult for administrators to defend against the attack and elicit more investigations for privacy-preserving.
Kanghua Mo, Xiaozhang Liu, Teng Huang 0001, Anli Yan
Int. J. Intell. Syst.1