EDBT 2026 Demo / reviewers in the wild / expert
Xingshuo Han
dblp:310/0337
· DBLP profile ↗
32ranked-venue papers
7as first author
32since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 13 · 2 first-author · 13 since 2021Artificial intelligence and machine learning · 10 · 1 first-author · 10 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 4 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ReasMark: A Robust Watermark for Attributing LLM Reasoning Under Knowledge Distillation AttacksabstractPeizhuo Lv, Ruihua Zhou, Yunpeng Li, Ruigang Liang, Xingshuo Han, XiaoFeng Wang, Wei Dong, Yuling Liu. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Peizhuo Lv, Ruihua Zhou, Ruigang Liang, Xingshuo Han |
ACL (1) | 5 |
| 2026 | LTFDyG: A learnable temporal function-based dynamic graph neural network with dual-channel encoding
Xinzhi Shi, Chao Li 0022, Xingshuo Han, Shihe Su, Junyan Wu |
Appl. Intell. | 3 |
| 2026 | Verifiable and Lightweight Multi-Round Secure Federated LearningabstractFederated learning (FL) is a paradigm that ensures the confidentiality and accessibility of data without requiring the collection of private data from multiple sources. It acquires an aggregation model by integrating various local models from clients. However, clients are vulnerable to numerous security and privacy threats. Existing solutions were unable to implement training models that are both dropout-resilient and lightweight while also providing verification capabilities when large-scale clients are involved in federated training. To improve the usability of FL, we propose a verifiable and lightweight multi-round secure FL framework by designing and incorporating a double-masking mechanism to ensure secure transmission. Moreover, we optimize the secure aggregation strategy by designing a dropout-resilience method via the secret-sharing mechanism. Specifically, we establish a lightweight model-secure training scheme and provide a parameter reuse strategy by constructing a full connection graph, which reduces computational cost and communication overhead. Furthermore, we propose a secure authentication protocol that enables the client to verify the accuracy of the computing results from the server. Extensive experimental evaluations indicate that our solution demonstrates relatively modest performance but superior functionality compared to current state-of-the-art methods. In particular, we can achieve the verification function with an acceptable increase in computational cost of approximately 200ms per epoch. Shengmin Xu, Xingshuo Han, Jianting Ning, Xinlei He 0001, Guowen Xu |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | SSD: A State-Based Stealthy Backdoor Attack for IMU/GNSS Navigation System in UAV Route PlanningabstractUnmanned aerial vehicles (UAVs) are increasingly employed to perform high-risk tasks that require minimal human intervention. However, they face escalating cybersecurity threats, particularly from GNSS spoofing attacks. While previous studies have extensively investigated the impacts of GNSS spoofing on UAVs, few have focused on its effects on specific tasks. Moreover, the influence of UAV motion states on the assessment of cybersecurity risks is often overlooked. To address these gaps, we first provide a detailed evaluation of how motion states affect the effectiveness of network attacks. We demonstrate that nonlinear motion states not only enhance the effectiveness of position spoofing in GNSS spoofing attacks but also reduce the probability of detecting speed-related attacks. Building upon this, we propose a state-triggered backdoor attack method (SSD) to deceive GNSS systems and assess its risk to trajectory planning tasks. Extensive validation of SSD’s effectiveness and stealthiness is conducted. Experimental results show that, with appropriately tuned hyperparameters, SSD significantly increases positioning errors and the risk of task failure, while maintaining high stealthy rates across three state-of-the-art detectors. Zhaoxuan Wang, Yang Li 0055, Jie Zhang 0073, Xingshuo Han, Kangbo Liu, Yang Lyu, Yuan Zhou 0005, Tianwei Zhang 0004, Quan Pan 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | An LLM-Empowered Adaptive Evolutionary Algorithm for Multi-Component Deep Learning SystemsabstractMulti-objective evolutionary algorithms (MOEAs) are widely used for searching optimal solutions in complex multi-component applications. Traditional MOEAs for multi-component deep learning (MCDL) systems face challenges in enhancing the search efficiency while maintaining the diversity. To combat these, this paper proposes the first LLM-empowered adaptive evolutionary search algorithm to detect safety violations in MCDL systems. Inspired by the context-understanding ability of Large Language Models (LLMs), our approach promotes the LLM to comprehend the optimization problem and generate an initial population tailed to evolutionary objectives. Subsequently, it employs adaptive selection and variation to iteratively produce offspring, balancing the evolutionary efficiency and diversity. During the evolutionary process, to navigate away from the local optima, our approach integrates the evolutionary experience back into the LLM. This utilization harnesses the LLM's quantitative reasoning prowess to generate differential seeds, breaking away from current optimal solutions. We evaluate our approach in finding safety violations of MCDL systems, and compare its performance with state-of-the-art MOEA methods. Experimental results show that our approach can significantly improve the efficiency and diversity of the evolutionary search. Haoxiang Tian 0001, Xingshuo Han, Guoquan Wu, An Guo 0002, Yuan Zhou 0005, Jie Zhang 0073, Jun Wei 0001, Tianwei Zhang 0004 |
AAAI | 2 |
| 2025 | Controllable Spoofing Attacks on Visual SLAM in Robotic Vehicles
Gelei Deng, Xingshuo Han, Shangwei Guo, Tianwei Zhang 0004 |
ACSAC | 4 |
| 2025 | Mind the Cost of Scaffold! Benign Clients May Even Become Accomplices of Backdoor Attack
Xingshuo Han, Xuanye Zhang, Haozhao Wang, Shengmin Xu, Shen Ren, Jason Zeng, Michael Heinrich, Tianwei Zhang 0004 |
ICCV | 1 |
| 2025 | BSemiFL: Semi-supervised Federated Learning via a Bayesian ApproachabstractSemi-supervised Federated Learning (SSFL) is a promising approach that allows clients to collaboratively train a global model in the absence of their local data labels. The key step of SSFL is the re-labeling where each client adopts two types of available models, namely global and local models, to re-label the local data. While various technologies such as using the global model or the average of two models have been proposed to conduct the re-labeling step, little literature delves deeply into the performance dominance and limitations of the two models. In this paper, we first theoretically and empirically demonstrate that the local model achieves higher re-labeling accuracy over local data while the global model can progressively improve the re-labeling performance by introducing the extra data knowledge of other clients. Based on these findings, we propose BSemiFL which re-labels the local data through the collaboration between the local and global model in a Bayesian approach. Specifically, to re-label any given local sample, BSemiFL first uses Bayesian inference to assess the closeness of the local/global model to the sample. Then, it applies a weighted combination of their pseudo labels, using the closeness as the weights. Theoretical analysis shows that the labeling error of our method is smaller than that of simply using the global model, the local model, or their simple average. Experimental results show that BSemiFL improves the performance by up to $9.8\%$ as compared to state-of-the-art methods. Haozhao Wang, Shengyu Wang, Hao Ren 0001, Xingshuo Han, Wenchao Xu 0001, Shangwei Guo, Tianwei Zhang 0004, Ruixuan Li 0001 |
ICML | 5 |
| 2025 | FusionDisassembler: A Cross-Device Approach for Effective Instruction Disassembly in Side-Channel AttacksabstractModern embedded systems are increasingly vulnerable to side-channel threats, which may non-invasively leak sensitive information about their internal operations. While prior studies have validated the feasibility of instruction reverse engineering via side-channel analysis, their effectiveness has primarily been demonstrated under ideal, device-controlled settings. In practical adversarial scenarios, heterogeneity in manufacturing processes and hardware components across devices introduces significant variations in side-channel signals, which impedes effective pattern recognition and limits the scalability of crossdevice attacks. This paper presents FusionDisassembler, a robust and generalizable instruction disassembly framework for cross-device side-channel analysis. FusionDisassembler captures power traces during program execution and identifies the corresponding assembly instructions. To address device-induced signal variability, we employ information-theoretic analysis in the timefrequency domain to extract discriminative features that remain stable across hardware. Moreover, we introduce a MultiExpert Disassembly Network, comprising multiple specialized expert subnetworks trained on different feature domains, and a lightweight router that dynamically selects the most appropriate expert based on input features. This architecture enables effective learn of distribution shifts across devices and enhances generalization in real-world attack settings. We evaluate FusionDisassembler on multiple physical devices across two microarchitectures. Extensive experiments demonstrate its effectiveness, outperforming existing approaches and establishing a new practical benchmark for side-channel-based disassembly. Ouchang Hai, Hangcheng Liu, Xingshuo Han |
ICPADS | 5 |
| 2025 | FusionMIA: Enhancing Membership Inference Attacks with Spy Clients and Shadow Models in Federated Learning
Zuobin Ying, Xingshuo Han, Shengmin Xu |
KSEM (3) | 4 |
| 2025 | The Fluorescent Veil: A Stealthy and Effective Physical Adversarial Patch Against Traffic Sign RecognitionabstractRecently, traffic sign recognition (TSR) systems have become a prominent target for physical adversarial attacks. These attacks typically rely on conspicuous stickers and projections, or using invisible light and acoustic signals that can be easily blocked. In this paper, we introduce a novel attack medium, i.e., fluorescent ink, to design a stealthy and effective physical adversarial patch, namely FIPatch, to advance the state-of-the-art. Specifically, we first model the fluorescence effect in the digital domain to identify the optimal attack settings, which guide the real-world fluorescence parameters. By applying a carefully designed fluorescence perturbation to the target sign, the attacker can later trigger a fluorescent effect using invisible ultraviolet light, causing the TSR system to misclassify the sign and potentially leading to traffic accidents. We conducted a comprehensive evaluation to investigate the effectiveness of FIPatch, which shows a success rate of 98.31% in low-light conditions. Furthermore, our attack successfully bypasses five popular defenses and achieves a success rate of 96.72%. Shuai Yuan 0009, Xingshuo Han, Hongwei Li 0001, Guowen Xu, Wenbo Jiang 0001, Tao Ni 0003, Qingchuan Zhao, Yuguang Fang |
NeurIPS | 2 |
| 2025 | PEFTGuard: Detecting Backdoor Attacks Against Parameter-Efficient Fine-TuningabstractFine-tuning is an essential process to improve the performance of Large Language Models (LLMs) in specific domains, with Parameter-Efficient Fine-Tuning (PEFT) gaining popularity due to its capacity to reduce computational demands through the integration of low-rank adapters. These lightweight adapters, such as LoRA, can be shared and utilized on open-source platforms. However, adversaries could exploit this mechanism to inject backdoors into these adapters, resulting in malicious behaviors like incorrect or harmful outputs, which pose serious security risks to the community. Unfortunately, few current efforts concentrate on analyzing the backdoor patterns or detecting the backdoors in the adapters. To fill this gap, we first construct and release PADBench, a comprehensive benchmark that contains 13, 300 benign and backdoored adapters fine-tuned with various datasets, attack strategies, PEFT methods, and LLMs. Moreover, we propose PEFTGuard, the first backdoor detection framework against PEFT-based adapters. Extensive evaluation upon PADBench shows that PEFTGuard outperforms existing detection methods, achieving nearly perfect detection accuracy (100%) in most cases. Notably, PEFTGuard exhibits zero-shot transferability on three aspects, including different attacks, PEFT methods, and adapter ranks. In addition, we consider various adaptive attacks to demonstrate the high robustness of PEFTGuard. We further explore several possible backdoor mitigation defenses, finding fine-mixing to be the most effective method. We envision that our benchmark and method can shed light on future LLM backdoor detection research.11Our code and dataset are available at: https://github.com/Vincent-HKUSTGZ/PEFTGuard. Zhen Sun 0001, Tianshuo Cong, Yule Liu, Chenhao Lin, Xinlei He 0001, Rongmao Chen, Xingshuo Han, Xinyi Huang 0001 |
SP | 7 |
| 2025 | The Ghost Navigator: Revisiting the Hidden Vulnerability of Localization in Autonomous Driving
Shaoyin Cheng, Linqing Hu, Jie Zhang 0073, Chengyu Shi, Xingshuo Han, Tianwei Zhang 0004, Yueqiang Cheng, Weiming Zhang 0001 |
USENIX Security Symposium | 6 |
| 2025 | Artificial intelligence security and privacy: a surveyabstractAbstract Artificial intelligence (AI) is revolutionizing both industries and reshaping the global economy. However, the rapid advancement of AI technologies brings significant security and privacy challenges. Recent incidents highlight vulnerabilities in AI systems, such as data leakage and malicious code injection, leading to severe financial losses and privacy breaches. Although existing studies have discussed specific security threats, they often lack detailed granularity and cover a limited scope. In this survey, we fill this gap by systematically categorizing and analyzing the threats and countermeasures in AI systems, which span both the training and inference stages, encompass centralized and distributed settings, and address both conventional and foundation AI models. By reviewing existing literature, we aim to provide AI researchers and practitioners with a thorough understanding of system vulnerabilities and current countermeasures. We hope to inspire further research into robust solutions, ultimately contributing to the development of resilient AI technologies. Xinlei He 0001, Guowen Xu, Xingshuo Han, Qian Wang 0002, Lingchen Zhao, Chao Shen 0001, Chenhao Lin, Zhengyu Zhao 0001, Qian Li 0024, Le Yang 0007, Shouling Ji, Shaofeng Li 0001, Haojin Zhu, Zhibo Wang 0001, Tianqing Zhu, Qi Li 0002, Chaoxiang He, Hongsheng Hu, Shuo Wang 0012, Shifeng Sun 0001, Hongwei Yao, Qinyu Zhang 0001, Kai Chen 0012, Yue Zhao 0027, Hongwei Li 0001, Xinyi Huang 0001, Dengguo Feng |
Sci. China Inf. Sci. | 3 |
| 2025 | Retrieving and Reasoning: Multivariate Feature and Attribute Cooperation for Video Anomaly DetectionabstractVideo anomaly detection (VAD), which detects abnormal patterns in video sequence, is based on several kinds of features or attributes in the existing methods. This ignores the interconnections between different features and attributes, and the initiation of an anomalous result is brought about by multiple factors. If several individual neural networks are used to perceive various types of anomalies, the system would lose awareness of the association among features and attributes, which limits the system's ability to perceive complex anomalies. In this work, we propose a dual-branch framework for VAD task, which includes deep feature retrieving and semantic attribute reasoning branch. In the former branch, three high-dimensional deep features are extracted and modeled, then the anomaly scores are obtained based on the vector retrieval database. In the latter branch, three low-dimensional semantic-level attributes are extracted for composing the attribute triplets, then use theAssociation-ruleMiningModule (AMM) to perceive potential connections among these triplets. The coefficients computed by the latter branch calibrate the anomaly scores obtained by the former while providing high-level anomaly causes. Extensive experiments show that our approach achieves state-of-the-art performance with 87.9$\%$on ShanghaiTech and 94.6$\%$on Avenue. Xingshuo Han, Xiao Wang 0029, Wei Liu 0183, Liping Ye, Xin Xu 0007 |
IEEE Signal Process. Lett. | 1 |
| 2025 | MinMaxEntropy: Bound Model Errors for Side-Channel Leakages From Information TheoryabstractSide-channel attacks and evaluations have been incessantly pursuing an accurate leakage model and try to address the following question: “How good is my leakage model?” However, the existing works do not well alleviate the attackers and evaluators from model assumption error and estimation error. The recent work named maximum entropy distribution (MED) model does not depend on any assumptions but uses nonlinear programming Newton-Raphson method to fit the leakage distribution, thus avoiding assumption error and making the estimation error arbitrarily small. It tries to address a more fundamental problem: “How to achieve the optimal leakage model?,” but still have to face with two issues: 1) the large deviation of MED model from leakage distribution and 2) the difficulty in determining the moments required in model profiling. In this article, we first introduce the nonlinear programming optimizations Levenberg-Marquardt and Conjugate Gradient methods to tackle the first issue. We then exploit Hopfield neural network to solve the minimum entropy for leakage model. Unlike the MED indicating the theoretically most unbiased, objective and reasonable leakage model, the minimum entropy corresponds to the theoretically most biased, subjective and unreasonable leakage model. This facilitates us to build a MinMaxEntropy bound from the maximum entropy and minimum entropy for estimation errors in leakage model, which theoretically represents the amount of information contained on unused higher moments. This bound well provides theoretical support for the moments constraints required to profile the MED model, thus well tackling the second issue. Experimental results fully demonstrate the superiority of our above schemes. Changhai Ou, Zhenfang Qiu, Xingshuo Han, Fan Zhang 0010, Shihui Zheng, Fei Yan 0008 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 3 |
| 2025 | Enhancing Secure Cloud Data Sharing: Dynamic User Groups and Outsourced DecryptionabstractCloud computing, as a persuasive paradigm, offers on-demand data services. However, it faces various security threats during data sharing due to trust issues. To mitigate this problem, many cloud-based data-sharing systems employ cryptographic tools to guarantee the confidentiality of sensitive data. Nevertheless, fine-grained data sharing still suffers from many challenges, especially in complex cloud environments. In this paper, we introduce two cloud-based data-sharing systems with fine-grained access control. The first solution supports dynamic user groups, while the second solution further offers outsourced decryption, enabling compatibility with resource-constrained devices. To formalize our solution theoretically, we introduce the concept of ElGamal -type cryptosystem (ETC) and server-aided ETC with key encapsulation mechanism to generalize public-key encryption with specific features implicitly specified by ElGamal encryption. Through the application of ETC, we present generic constructions for revocable attribute-based encryption (RABE) and server-aided RABE (SR-ABE) with formal definitions and security analyses. These schemes serve as the fundamental mechanisms behind our proposed solutions. By applying the state-of-the-art attribute-based encryption scheme proposed in CCS'22, we introduce instantiations of RABE and SR-ABE with various desirable properties, including large universe, attribute multi-use, key exposure resistance, fast decryption, and more. Extensive experiments substantiate the superior performance of our proposed instantiations over previous solutions. Shengmin Xu, Guomin Yang, Xiaoguo Li, Xingshuo Han, Xiaotian Yan, Xinyi Huang 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | VisionGuard: Secure and Robust Visual Perception of Autonomous Vehicles in PracticeabstractModern Autonomous Vehicles (AVs) implement the Visual Perception Module (VPM) to perceive their surroundings. This VPM adopts various Deep Neural Network (DNN) models to process the data collected from cameras and LiDAR. Prior studies have shown that these models are vulnerable to physical adversarial examples (PAEs), which pose a critical safety risk to the autonomous driving task. While a few defense methods have been proposed to safeguard AVs, most of them only target a limited set of attack types and specific scenarios, making them impractical for real-world protection. Xingshuo Han, Haozhao Wang, Kangqiao Zhao, Gelei Deng, Yuan Xu 0033, Hangcheng Liu, Han Qiu 0001, Tianwei Zhang 0004 |
CCS | 1 |
| 2024 | PhyScout: Detecting Sensor Spoofing Attacks via Spatio-temporal ConsistencyabstractExisting defense approaches against sensor spoofing attacks suf- fer from the limitations of limited specific attack types, requiring GPU computation, exhibiting considerable detection latency and struggling with the interpretability of corner cases. We developed PhyScout, a holistic sensor spoofing defense framework to over- come the above limitations. Our framework capitalizes on the ob- servation that human drivers can rapidly and accurately identify spoofing attacks by performing spatio-temporal consistency checks of their environment. We commence by defining the generalized conflicts that different sensor spoofing attacks produce regarding the spatio-temporal consistency. These conflicts are subsequently unified and formalized through a least squares problem approach. This process is modeled using image-based feature point extrac- tion and matching techniques, followed by the design of a risk identification method for each conflict. We evaluate PhyScout across various environments, including simulators, datasets, and real-world scenarios. Compared to existing defense solutions, PhyScout offers rapid identification of sensor at- tacks (within 100ms) with low performance overhead (CPU-based), and conflict visualization. It demonstrates a fresh paradigm in au- tonomous vehicle security and presents new avenues for future research in robust and efficient defense mechanisms against sensor spoofing attacks. More video demos are at our anonymous website https://sites.google.com/view/physcout. Yuan Xu 0033, Gelei Deng, Xingshuo Han, Han Qiu 0001, Tianwei Zhang 0004 |
CCS | 3 |
| 2024 | Mutuality Attribute Makes Better Video Anomaly DetectionabstractVideo anomaly detection (VAD) is an essential but challenging task. Existing prevalent methods focus on analyzing the reconstruction or prediction difference between normal and abnormal patterns through multiple deep features, e.g., optic flow. However, these approaches independently use deep features to characterize attributes, ignore the mutuality among multiple deep features. Therefore, the constructed representation is limited to indirectly representing the anomaly from isolated attributes, and makes the network difficult to capture the high-level causes of anomaly. In this paper, we proposed a novel Mutuality Attribute-based Representation framework (MAR-VAD) for the VAD task, which absorbs the mutuality among deep features to characterize the mutuality attribute. Specifically, the mutuality attribute encapsulates high-level semantic information, such as the specific abnormal object or action, which mutually utilizes information from multiple deep features. In this way, the system is able to directly capture the high-level causes of anomaly, thus providing a more comprehensive perspective to accurately detect anomaly events. Following a process-transparent density estimation, we produce the final anomaly scores. Experiments show that MAR-VAD achieves state-of-the-art performance on ShanghaiTech and Avenue. Xingshuo Han, Xiao Wang 0029, Kui Jiang, Wei Liu 0183, Ruimin Hu, Xuefeng Pan, Xin Xu 0007 |
ICASSP | 1 |
| 2024 | FedNLR: Federated Learning with Neuron-wise Learning RatesabstractFederated Learning (FL) suffers from severe performance degradation due to the data heterogeneity among clients. Some existing work suggests that the fundamental reason is that data heterogeneity can cause local model drift, and therefore proposes to calibrate the direction of local updates to solve this problem. Though effective, existing methods generally take the model as a whole, which lacks a deep understanding of how the neurons within deep classification models evolve during local training to form model drift. In this paper, we bridge this gap by performing an intuitive and theoretical analysis of the activation changes of each neuron during local training. Our analysis shows that the high activation of some neurons on the samples of a certain class will be reduced during local training when these samples are not included in the client, which we call neuron drift, thus leading to the performance reduction of this class. Motivated by this, we propose a novel and simple algorithm called FedNLR, which utilizes Neuron-wise Learning Rates during the FL local training process. The principle behind this is to enhance the learning of neurons bound to local classes on local data knowledge while reducing the decay of non-local classes knowledge stored in neurons. Experimental results demonstrate that FedNLR achieves state-of-the-art performance on federated learning with popular deep neural networks. Haozhao Wang, Peirong Zheng, Xingshuo Han, Wenchao Xu 0001, Ruixuan Li 0001, Tianwei Zhang 0004 |
KDD | 3 |
| 2024 | Beware of Road Markings: A New Adversarial Patch Attack to Monocular Depth EstimationabstractMonocular Depth Estimation (MDE) enables the prediction of scene depths from a single RGB image, having been widely integrated into production-grade autonomous driving systems, e.g., Tesla Autopilot. Current adversarial attacks to MDE models focus on attaching an optimized adversarial patch to a designated obstacle. Although effective, this approach presents two inherent limitations: its reliance on specific obstacles and its limited malicious impact. In contrast, we propose a pioneering attack to MDE models that \textit{decouples obstacles from patches physically and deploys optimized patches on roads}, thereby extending the attack scope to arbitrary traffic participants. This approach is inspired by our groundbreaking discovery: \textit{various MDE models with different architectures, trained for autonomous driving, heavily rely on road regions} when predicting depths for different obstacles. Based on this discovery, we design the Adversarial Road Marking (AdvRM) attack, which camouflages patches as ordinary road markings and deploys them on roads, thereby posing a continuous threat within the environment. Experimental results from both dataset simulations and real-world scenarios demonstrate that AdvRM is effective, stealthy, and robust against various MDE models, achieving about 1.507 of Mean Relative Shift Ratio (MRSR) over 8 MDE models. The code is available at \url{https://github.com/a-c-a-c/AdvRM.git} Hangcheng Liu, Zhenhu Wu, Hao Wang 0003, Xingshuo Han, Shangwei Guo, Tao Xiang 0001, Tianwei Zhang 0004 |
NeurIPS | 4 |
| 2024 | Backdooring Multimodal LearningabstractDeep Neural Networks (DNNs) are vulnerable to backdoor attacks, which poison the training set to alter the model prediction over samples with a specific trigger. While existing efforts mainly focus on unimodal scenarios, modern AI systems usually employ multiple modalities to improve the model performance, making multimodal backdoor attacks more practical but structurally more complex due to inherent modality interactions, multiple attack surfaces, unbalanced modality contributions, etc. These factors affect the effectiveness of backdooring multimodal learning significantly but have not been fully investigated yet.To bridge this gap, we present the first data and computation efficient backdoor attacks towards multimodal learning. Our solution consists of two innovations. First, we propose a novel backdoor gradient-based score (BAGS), which can accurately quantify the contribution of each data sample to the backdoor learning at a very early training stage. Therefore, it can greatly save time and computational resources for the attacker. Second, we introduce a searching strategy with two attack modes to efficiently determine the optimal poisoning modalities and data samples.Our methodology leads to the following research outcomes. First, we comprehensively evaluate the proposed solution over state-of-the-art multimodal tasks, models, datasets and settings, to verify its effectiveness, efficiency and transferability. For instance, we only need to poison 0.005% of training samples to attack the Visual Question Answering task with the success rate of >96%. For the Audio Video Speech Recognition task, we poison 0.05% of samples to achieve the success rate of >93%. Second, we disclose several interesting findings during our experiments: (1) poisoning all modalities is not always better than individual ones, sometimes even making the attack worse; (2) modality competition and complementarity coexist in multimodal learning backdoor attacks; (3) A dominant modality in multimodal learning may not dominate the backdoor attacks. We hope this work will spur future research in improving the security of multimodal learning. Code is available at https://github.com/multimodalbags/BAGS_Multimodal. Xingshuo Han, Yutong Wu 0009, Yuan Zhou 0005, Yuan Xu 0033, Han Qiu 0001, Guowen Xu, Tianwei Zhang 0004 |
SP | 1 |
| 2024 | VerifyML: Obliviously Checking Model Fairness Resilient to Malicious Model HolderabstractIn this paper, we presentVerifyML, the first secure inference framework to check the fairness degree of a given Machine learning (ML) model.VerifyMLis generic and is immune to any obstruction by the malicious model holder during the verification process. We rely on secure two-party computation (2 PC) technology to implementVerifyML, and carefully customize a series of optimization methods to boost its performance for both linear and nonlinear layer execution. Specifically, (1)VerifyMLallows the vast majority of overhead to be performed offline, thus meeting the low latency requirements for online inference. (2) To speed up offline preparation, we first design novel homomorphic parallel computing techniques to accelerate the authenticated Beaver's triple (including matrix- vector and convolution triples) generation procedure. It achieves up to$1.7\times$computation speedup and gains at least$10.7\times$less communication overhead compared to state-of-the-art work. (3) We also present a new cryptographic protocol to evaluate the activation functions of non-linear layers, which is$4\times$–$42\times$faster and has$\gt 48\times$less communication than the existing 2 PC protocol against malicious parties. In fact,VerifyMLeven beats the state-of-the-art semi-honest ML secure inference system! We provide a formal theoretical analysis forVerifyMLsecurity and demonstrate its performance superiority on mainstream ML models including ResNet-18 and LeNet. Guowen Xu, Xingshuo Han, Gelei Deng, Tianwei Zhang 0004, Shengmin Xu, Jianting Ning, Anjia Yang, Hongwei Li 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | SIMC 2.0: Improved Secure ML Inference Against Malicious ClientsabstractIn this paper, we study the problem of secure ML inference against a malicious client and a semi-trusted server such that the client only learns the inference output while the server learns nothing. This problem is first formulated by Lehmkuhlet al.with a solution (MUSE, Usenix Security'21), whose performance is then substantially improved by Chandranet al.'s work (SIMC, USENIX Security'22). However, there still exists a nontrivial gap in these efforts towards practicality, giving the challenges of overhead reduction and secure inference acceleration in an all-round way. Based on this, we propose SIMC 2.0, which complies with the underlying structure of SIMC, but significantly optimizes both the linear and non-linear layers of the model. Specifically, (1) we design a new coding method for parallel homomorphic computation between matrices and vectors. (2) We reduce the size of the garbled circuit (GC) (used to calculate non-linear activation functions,e.g., ReLU) in SIMC by about two thirds. Compared with SIMC, our experiments show that SIMC 2.0 achieves a significant speedup by up to$17.4\times$for linear layer computation, and at least$1.3\times$reduction of both the computation and communication overhead in the implementation of non-linear layers under different data dimensions. Meanwhile, SIMC 2.0 demonstrates an encouraging runtime boost by$2.3\sim 4.3\times$over SIMC on different state-of-the-art ML models. Guowen Xu, Xingshuo Han, Tianwei Zhang 0004, Shengmin Xu, Jianting Ning, Xinyi Huang 0001, Hongwei Li 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | An Adaptive Secure and Practical Data Sharing System With Verifiable Outsourced DecryptionabstractCloud computing is the widespread acceptance of a promising paradigm offering a substantial amount of storage and data services on demand. To preserve data confidentiality, many cryptosystems have been introduced. However, current solutions are incompatible with the resource-constrained end-devices because of a variety of vulnerabilities in terms of practicality and security. In this paper, we propose a practical and secure data-sharing system by introducing a new design of attribute-based encryption with verifiable outsourced decryption (VO-ABE for short). Our system offers: (1) data sharing at a fine-grained level; (2) a scalable key issuing protocol without any secure channel; (3) a verifiable outsourced decryption mechanism for resource-constrained end-devices against the malicious cloud service provider; and (4) adaptive security against the real-world attacks. To formalize our solution with cryptographic analysis, we present the formal definition of VO-ABE and its concrete construction with provable security. In particular, our design leverages the techniques of the traditional ABE, verifiable outsourced decryption, and randomness extractor to support fine-grained access control, cost-effective data sharing, and security assurance with high entropy. Moreover, our design is provably secure in the adaptive model under the standard assumption, which offers a stronger security guarantee since the state-of-the-art solution is selectively secure under the non-standard assumption and suffers from a variety of real-world attacks. The implementation and evaluation demonstrate that our solution enjoys superior functionality and better performance than the relevant solutions. More importantly, our solution is compatible with the resource-constrained end-devices since the decryption mechanism takes around 1.1ms and is 22.7x faster than the state-of-the-art solution. Shengmin Xu, Xingshuo Han, Guowen Xu, Jianting Ning, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Serv. Comput. | 2 |
| 2023 | SoK: Rethinking Sensor Spoofing Attacks against Robotic Vehicles from a Systematic ViewabstractRobotic Vehicles (RVs) have gained great popularity over the past few years. Meanwhile, they are also demonstrated to be vulnerable to sensor spoofing attacks. Although a wealth of research works have presented various attacks, some key questions remain unanswered: are these existing works complete enough to cover all the sensor spoofing threats? If not, how many attacks are not explored, and how difficult is it to realize them?This paper answers the above questions by comprehensively systematizing the knowledge of sensor spoofing attacks against RVs. Our contributions are threefold. (1) We identify seven common attack paths in an RV system pipeline. We categorize and assess existing spoofing attacks from the perspectives of spoofer property, operation, victim characteristic and attack goal. Based on this systematization, we identify 4 interesting insights about spoofing attack designs. (2) We propose a novel action flow model to systematically describe robotic function executions and unexplored sensor spoofing threats. With this model, we successfully discover 103 spoofing attack vectors, 26 of which have been verified by prior works, while 77 attacks are never considered. (3) We design two novel attack methodologies to verify the feasibility of newly discovered spoofing attack vectors. Yuan Xu 0033, Xingshuo Han, Gelei Deng, Jiwei Li 0001, Yang Liu 0003, Tianwei Zhang 0004 |
EuroS&P | 2 |
| 2023 | Computation and Data Efficient Backdoor AttacksabstractBackdoor attacks against deep neural network (DNN) models have been widely studied. Various attack techniques have been proposed for different domains and paradigms, e.g., image, point cloud, natural language processing, transfer learning, etc. The most widely-used way to embed a backdoor into a DNN model is to poison the training data. They usually randomly select samples from the benign training set for poisoning, without considering the distinct contribution of each sample to the backdoor effectiveness, making the attack less optimal.A recent work [40] proposed to use the forgetting score to measure the importance of each poisoned sample and then filter out redundant data for effective backdoor training. However, this method is empirically designed without theoretical proofing. It is also very time-consuming as it needs to go through several training stages for data selection. To address such limitations, we propose a novel confidence-based scoring methodology, which can efficiently measure the contribution of each poisoning sample based on the distance posteriors. We further introduce a greedy search algorithm to find the most informative samples for backdoor injection more promptly. Experimental evaluations on both 2D image and 3D point cloud classification tasks show that our approach can achieve comparable performance or even surpass the forgetting score-based searching method while requiring only several extra epochs’ computation of a standard training process. Our code can be found at https://github.com/WU-YU-TONG/computational_efficient_backdoor Yutong Wu 0009, Xingshuo Han, Han Qiu 0001, Tianwei Zhang 0004 |
ICCV | 2 |
| 2023 | Hercules: Boosting the Performance of Privacy-Preserving Federated LearningabstractIn this paper, we address the problem of privacy-preserving federated neural network training with$N$users. We presentHercules, an efficient and high-precision training framework that can tolerate collusion of up to$N-1$users.Herculesfollows the POSEIDON framework proposed by Sav et al. (NDSS’21), but makes a qualitative leap in performance with the following contributions: (i) we design a novel parallel homomorphic computation method for matrix operations, which enables fast Single Instruction and Multiple Data (SIMD) operations over ciphertexts. For the multiplication of two$h\times h$dimensional matrices, our method reduces the computation complexity from$O(h^{3})$to$O(h)$. This greatly improves the training efficiency of the neural network since the ciphertext computation is dominated by the convolution operations; (ii) we present an efficient approximation on the sign function based on the composite polynomial approximation. It is used to approximate non-polynomial functions (i.e.,ReLUandmax), with the optimal asymptotic complexity. Extensive experiments on various benchmark datasets (BCW, ESR, CREDIT, MNIST, SVHN, CIFAR-10 and CIFAR-100) show that compared with POSEIDON,Herculesobtains up to 4% increase in model accuracy, and up to$60\times$reduction in the computation and communication cost. Guowen Xu, Xingshuo Han, Shengmin Xu, Tianwei Zhang 0004, Hongwei Li 0001, Xinyi Huang 0001, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2023 | ADS-Lead: Lifelong Anomaly Detection in Autonomous Driving SystemsabstractAutonomous Vehicles (AVs) are closely connected in the Cooperative Intelligent Transportation System (C-ITS). They are equipped with various sensors and controlled by Autonomous Driving Systems (ADSs) to provide high-level autonomy. The vehicles exchange different types of real-time data with each other, which can help reduce traffic accidents and congestion, and improve the efficiency of transportation systems. However, when interacting with the environment, AVs suffer from a broad attack surface, and the sensory data are susceptible to anomalies caused by faults, sensor malfunctions, or attacks, which may jeopardize traffic safety and result in serious accidents. In this paper, we proposeADS-Lead, an efficient collaborative anomaly detection methodology to protect the lane-following mechanism of ADSs.ADS-Leadis equipped with a novel transformer-based one-class classification model to identify time series anomalies (GPS spoofing threat) and adversarial image examples (traffic sign and lane recognition attacks). Besides, AVs inside the C-ITS form a cognitive network, enabling us to apply the federated learning technology to our anomaly detection method, where the vehicles in the C-ITS jointly update the detection model with higher model generalization and data privacy. Experiments on Baidu Apollo and two public data sets (GTSRB and Tumsimple) indicate that our method can not only detect sensor anomalies effectively and efficiently but also outperform state-of-the-art anomaly detection methods. Xingshuo Han, Yuan Zhou 0005, Kangjie Chen, Han Qiu 0001, Meikang Qiu, Yang Liu 0003, Tianwei Zhang 0004 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2023 | Secure Data Sharing With Flexible Cross-Domain Authorization in Autonomous Vehicle SystemsabstractAs an increasingly prevalent technology in intelligent autonomous transportation systems, autonomous vehicle platoon has been indicated the ability to significantly reduce fuel consumption as well as heighten highway safety and throughput. However, existing efforts rarely focus on protecting data confidentiality and authenticity in autonomous vehicle platoons. How to ensure secure and high-fidelity platoon-level communication is still in its infancy. This paper makes the first attempt for efficient and secure communication across autonomous vehicle platoons. Specifically, we presentPDSM-FC, the first privacy-preserving data share mechanism with flexible cross-domain authorization over distinctive platoons. The key insight ofPDSM-FCis the design of a new ciphertext conversion technique, which allows a ciphertext to be easily converted into another type of ciphertext, facilitating efficient access by all entities holding the legitimate authorization. As a result,PDSM-FCcan achieve high-fidelity data communication between two unique platoons in ciphertext, so as to complete specific tasks including platoon integration. Rigorous security analysis shows thatPDSM-FCis secure against various attacks such as collusion, forgery and chosen-plaintext attacks. Moreover, theoretical evaluation and extensive experiments demonstrate the practicability ofPDSM-FCin terms of functionality, storage and computation overheads. Jianfei Sun, Guowen Xu, Tianwei Zhang 0004, Xiaochun Cheng, Xingshuo Han, MingJian Tang 0001 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2022 | Physical Backdoor Attacks to Lane Detection Systems in Autonomous DrivingabstractModern autonomous vehicles adopt state-of-the-art DNN models to interpret the sensor data and perceive the environment. However, DNN models are vulnerable to different types of adversarial attacks, which pose significant risks to the security and safety of the vehicles and passengers. One prominent threat is the backdoor attack, where the adversary can compromise the DNN model by poisoning the training samples. Although lots of effort has been devoted to the investigation of the backdoor attack to conventional computer vision tasks, its practicality and applicability to the autonomous driving scenario is rarely explored, especially in the physical world. Xingshuo Han, Guowen Xu, Yuan Zhou 0005, Xuehuan Yang, Jiwei Li 0001, Tianwei Zhang 0004 |
ACM Multimedia | 1 |