Minxing Zhang

dblp:302/0867 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
8since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Databases, data management, data science and information retrieval · 4 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 DivTrackee versus DynTracker: Promoting Diversity in Anti-Facial Recognition against Dynamic FR Strategy
abstract
The widespread adoption of facial recognition (FR) models raises serious concerns about their potential misuse, motivating the development of anti-facial recognition (AFR) to protect user facial privacy. In this paper, we argue that the static FR strategy, predominantly adopted in prior literature for evaluating AFR efficacy, cannot faithfully characterize the actual capabilities of determined trackers who aim to track a specific target identity. In particular, we introduce DynTracker, a dynamic FR strategy where the model's gallery database is iteratively updated with newly recognized target identity images. Surprisingly, such a simple approach renders all the existing AFR protections ineffective. To mitigate the privacy threats posed by DynTracker, we advocate for explicitly promoting diversity in the AFR-protected images. We hypothesize that the lack of diversity is the primary cause of the failure of existing AFR methods. Specifically, we develop DivTrackee, a novel method for crafting diverse AFR protections that builds upon a text-guided image generation framework and diversity-promoting adversarial losses. Through comprehensive experiments on various image benchmarks and feature extractors, we demonstrate DynTracker's strength in breaking existing AFR methods and the superiority of DivTrackee in preventing user facial images from being identified by dynamic FR strategies. We believe our work can act as an important initial step towards developing more effective AFR methods for protecting user facial privacy against determined trackers.
Wenshu Fan, Minxing Zhang, Hongwei Li 0001, Wenbo Jiang 0001, Hanxiao Chen 0001, Xiangyu Yue 0001, Michael Backes 0001, Xiao Zhang 0016
CCS2
2024 ReCaLL: Membership Inference via Relative Conditional Log-Likelihoods
abstract
The rapid scaling of large language models (LLMs) has raised concerns about the transparency and fair use of the data used in their pretraining.Detecting such content is challenging due to the scale of the data and limited exposure of each instance during training.We propose RECALL, (Relative Conditional Log-Likelihood), a novel membership inference attack (MIA) to detect LLMs' pretraining data by leveraging their conditional language modeling capabilities.RECALL examines the relative change in conditional log-likelihoods when prefixing target data points with non-member context.Our empirical findings show that conditioning member data on non-member prefixes induces a larger decrease in log-likelihood compared to non-member data.We conduct comprehensive experiments and show that RE-CALL achieves state-of-the-art performance on WikiMIA dataset, even with random and synthetic prefixes, and can be further improved using an ensemble approach.Moreover, we conduct an in-depth analysis of LLMs' behavior with different membership contexts, providing insights into how LLMs leverage membership information for effective inference at both the sequence and token level.
Roy Xie, Ruomin Huang, Minxing Zhang, Jian Pei 0001, Neil Zhenqiang Gong, Bhuwan Dhingra
EMNLP4
2024 Addressing Delayed Feedback in Conversion Rate Prediction: A Domain Adaptation Approach
abstract
In the rapidly evolving online display advertising market, conversion rate (CVR) prediction models are typically updated daily using datasets enriched with recent conversion logs. However, a significant challenge is the time gap, often spanning days or weeks, between ad clicks and conversions. This issue, known as delayed feedback, results in false negatives in training data, creating a dilemma between label accuracy and data freshness. Existing methods for mitigating delayed feedback are limited, due to strong underlying assumptions, insufficient use of recent data without observed conversions, or implicit control over false negatives. To address this, we propose a simple framework that redefines CVR prediction under delayed feedback as an unsupervised domain adaptation (UDA) problem. Our method learns from fresh data while minimizing the impact of inaccurate labels, by integrating existing click-through rate (CTR) or CVR models with UDA algorithms. A customized pretraining step is also incorporated to effectively utilize recent observed conversions. Comprehensive experiments on three datasets showcase the proposed method's superiority over state-of-the-art approaches and its potential to benefit from advancements in CTR modeling. The code is available at https://github.com/ThunderbornSakana/DelayAdapter.
Leisheng Yu, Yanxiao Cai, Lucas Chen, Minxing Zhang, Wei-Yen Day, Soo-Hyun Choi
ICDM4
2024 STES: A Spatiotemporal Explanation Supervision Framework
abstract
Explanation supervision is a technique that guides a deep learning model to have correct attention during training and thus improve both the interpretability and predictability of the model. However, the exploration of explanation supervision methods for spatiotemporal prediction has been limited. In this paper, we propose a framework for explanation-supervised spatiotemporal forecasting which aims to explicitly incorporate human-annotated spatiotemporal explanations as supervision signals, achieved by introducing a unique objective that integrates human explanations for general spa-tiotemporal predictive models. Specifically, to extend the explanation supervision technique to spatiotemporal prediction, our framework addresses several inherent challenges associated with spatiotemporal data. Firstly, it tackles the difficulty of identifying and correcting the spatiotemporal reasoning process. Secondly, it addresses the challenge of handling the absence of human explanation annotation through interpolation techniques. Lastly, it handles the varying influence of different time points. To evaluate the effectiveness of our approach, we conducted extensive experiments on two real-world spatiotemporal datasets. The results demonstrate the superiority of our methods in improving the interpretability of explanations and the performance of the backbone deep neural network models, surpassing existing state-of-the-art explanation supervision methods.
Dazhou Yu, Yun Li 0005, Suman Dhakal, Yifei Zhang 0006, Zhenke Liu, Minxing Zhang, Liang Zhao 0002
SDM7
2024 Generated Distributions Are All You Need for Membership Inference Attacks Against Generative Models
abstract
Generative models have demonstrated revolutionary success in various visual creation tasks, but in the meantime, they have been exposed to the threat of leaking private information of their training data. Several membership inference attacks (MIAs) have been proposed to exhibit the privacy vulnerability of generative models by classifying a query image as a training dataset member or nonmember. However, these attacks suffer from major limitations, such as requiring shadow models and white-box access, and either ignoring or only focusing on the unique property of diffusion models, which block their generalization to multiple generative models. In contrast, we propose the first generalized membership inference attack against a variety of generative models such as generative adversarial networks, [variational] autoencoders, implicit functions, and the emerging diffusion models. We leverage only generated distributions from target generators and auxiliary nonmember datasets, therefore regarding target generators as black boxes and agnostic to their architectures or application scenarios. Experiments validate that all the generative models are vulnerable to our attack. For instance, our work achieves attack AUC > 0.99 against DDPM, DDIM, and FastDPM trained on CIFAR-10 and CelebA. And the attack against VQGAN, LDM (for the text-conditional generation), and LIIF achieves AUC > 0.90. As a result, we appeal to our community to be aware of such privacy leakage risks when designing and publishing generative models.1
Minxing Zhang, Ning Yu 0006, Rui Wen 0002, Michael Backes 0001, Yang Zhang 0016
WACV1
2023 CSGAN: Modality-Aware Trajectory Generation via Clustering-based Sequence GAN
abstract
Human mobility data is useful for various applications in urban planning, transportation, and public health, but collecting and sharing real-world trajectories can be challenging due to privacy and data quality issues. To address these problems, recent research focuses on generating synthetic trajectories, mainly using generative adversarial networks (GANs) trained by real-world trajectories. In this paper, we hypothesize that by explicitly capturing the modality of transportation (e.g., walking, biking, driving), we can generate not only more diverse and representative trajectories for different modalities but also more realistic trajectories that preserve the geographical density, trajectory, and transition level properties by capturing both cross-modality and modality-specific patterns. Towards this end, we propose a Clustering-based Sequence Generative Adversarial Network (CSGAN) that simultaneously clusters the trajectories based on their modalities and learns the essential properties of real-world trajectories to generate realistic and representative synthetic trajectories. To measure the effectiveness of generated trajectories, in addition to typical density and trajectory level statistics, we define several new metrics for a comprehensive evaluation, including modality distribution and transition probabilities both globally and within each modality. Our extensive experiments with real-world datasets show the superiority of our model in various metrics over state-of-the-art models.
Minxing Zhang, Haowen Lin, Yang Cao 0011, Cyrus Shahabi, Li Xiong 0001
MDM1
2022 Deep geometric neural network for spatial interpolation
abstract
Spatial interpolation is the task to interpolate the targeted index, such as PM2.5 values and temperature, at arbitrary locations based on the collected geospatial data. It greatly affects the key research topics in geoscience in terms of obtaining heterogeneous spatial information (e.g., soil conditions, precipitation rates, wheat yields) for geographic modeling and decision-making at local, regional, and global scales. Point-based data, collected by ground-level in-situ sensors, serve as an important data source for this task. However, several major challenges still exist: point-based data are sparse and unevenly distributed. More importantly, it is difficult to model the unknown spatial predictive mapping while handling the trade-off between spatial autocorrelation and heterogeneity. Third, representing spatial relations without substantial information loss is also a critical issue. To address these challenges, we propose a novel Deep Geometric Spatial Interpolation (DGSI) framework as the interpolation backbone that automatically interpolates the targeted index at unknown locations based on existing observations. Our proposed model takes into account both distance and orientation information, which is proven to preserve spatial information. Extensive experiments have been conducted on real-world datasets and demonstrated our model's superiority in performance over state-of-the-art models.
Minxing Zhang, Dazhou Yu, Yun Li 0005, Liang Zhao 0002
SIGSPATIAL/GIS1
2021 Membership Inference Attacks Against Recommender Systems
abstract
Recently, recommender systems have achieved promising performances and become one of the most widely used web applications. However, recommender systems are often trained on highly sensitive user data, thus potential data leakage from recommender systems may lead to severe privacy problems.
Minxing Zhang, Zhaochun Ren, Zihan Wang 0002, Pengjie Ren, Zhumin Chen, Pengfei Hu 0001, Yang Zhang 0016
CCS1