Mengdie Huang

dblp:312/1395 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
8since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 first-author · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Transferable multi-level spatial-temporal graph neural network for adaptive multi-agent trajectory prediction
Yu Sun 0001, Dengyu Xiao, Mengdie Huang, Chuan Tong, Jun Luo 0006, Huayan Pu
Knowl. Based Syst.3
2026 Adaptive Multi-Agent Trajectory Prediction via Transferable Multi-Motion-Property Attention Network
Yu Sun 0001, Dengyu Xiao, Huayan Pu, Mengdie Huang, Jun Luo 0006
IEEE Trans Autom. Sci. Eng.4
2025 CARD: Robustness-Preserving Transfer Learning for Network Intrusion Detection via Contrastive Adversarial Representation Distillation
abstract
Robust neural networks are essential to build network intrusion detection systems resilient to evasion attacks. Learning such models via adversarial training demands extensive labeled data and high model capacity, making it impractical in evolving, resource-constrained threat environments. Transfer learning (TL) uses pre-trained models to enhance downstream tasks, offering a promising mitigation approach. However, most TL approaches prioritize performance on clean examples without addressing robustness against adversarial examples and random variations. Our empirical study reveals that standard fine-tuning and distillation often yield accurate but not robust models, while the few existing adversarial TL provide limited robustness. In this paper, we propose a novel robustness-preserving TL framework, Contrastive Adversarial Representation Distillation (CARD), to generate a robust target model by transferring robustness and performance from a robust source model into the target task. CARD tackles three issues: (i) target domain data scarcity; (ii) differences in data domains and model architectures between target and source tasks; and (iii) target model robustness against static and adaptive evasion attacks, and natural corruptions. Experiments on binary and multiclass detection show that CARD outperforms state-of-the-art methods in various TL tasks across data domains and model architectures when only 5% training data is available, achieving 17.67% and 8.38% higher adversarial robust accuracy as well as 9.75% and 11.42% higher natural robust accuracy than adversarial fine-tuning and distillation.
Mengdie Huang, Yingjun Lin, Ninghui Li 0001, Xiaofeng Chen 0001, Elisa Bertino
IEEE Trans. Dependable Secur. Comput.1
2025 Dimensional Robustness Certification for Deep Neural Networks in Network Intrusion Detection Systems
abstract
Network intrusion detection systems based on deep learning are gaining significant traction in cyber security due to their high prediction accuracy and strong adaptability to evolving cyber threats. However, a serious drawback is their vulnerability to evasion attacks that rely on adversarial examples. To provide robustness guarantees for deep neural networks against any possible perturbations, certified defenses against perturbations within a l p -bounded region around the input are being increasingly explored. Unfortunately, unlike existing image domain approaches that concentrate on homogeneous input feature spaces, the progress on certified defense for the network traffic domain, which is characterized by heterogeneous features, has been very limited. To address such a gap, we present the design and practicality of a novel framework, Multi-order Adaptive Randomized Smoothing (MARS), for certifying the robustness of network intrusion detectors based on deep neural networks. Experiments on various network intrusion detection systems show that MARS significantly improves the tightness of robustness certification (12.23% increase in l 2 certified radius), detection accuracy on evasion attack (7.17% improvement on \(l_{\infty }\) -PGD, 10.11% improvement on l 1 -EAD), and prediction accuracy on natural corruption (16.65% enhancement on latency, 18.23% enhancement on packet loss) compared to the SOTA method. We have also conducted an extensive analysis of the dimension-wise certified robustness of the network intrusion detector. The results indicate that the dimensional certified radii obtained using MARS reveal the robustness differences across feature dimensions, aligning with the empirical evaluation findings.
Mengdie Huang, Yingjun Lin, Xiaofeng Chen 0001, Elisa Bertino
ACM Trans. Priv. Secur.1
2024 MARS: Robustness Certification for Deep Network Intrusion Detectors via Multi-Order Adaptive Randomized Smoothing
abstract
Network intrusion detectors based on deep learning have high detection accuracy and the ability to adapt to evolving cyber threats. However, a serious drawback is their vulnerability to adversarial example attacks aimed at evading detectors and natural corruptions caused by random noise in the network environment. To provide robustness guarantees for deep neural networks against various perturbations, certified defenses against any possible perturbed inputs in the lp-bounded region are gaining attention. mHowever, unlike existing approaches that focus on homogeneous image feature spaces, the progress on certified defense for the network traffic domain, which is characterized by heterogeneous features, has been very limited. To address such a gap, we propose a novel framework, Multi-order Adaptive Randomized Smoothing (MARS), for certifying the robustness of network intrusion detectors. Experiments on various deep learning-based network intrusion detector architectures show that MARS significantly improves the certification tightness (12.23% average increase in the l2certified radius), evasion attack detection accuracy (7.17% improvement on l∞-PGD, 10.11% improvement on l1-EAD), and natural corruption detection accuracy (16.65% enhancement on latency, 18.23% enhancement on packet loss) compared to BARS, the leading and only certified defense for network intrusion detectors.
Mengdie Huang, Yingjun Lin, Xiaofeng Chen 0001, Elisa Bertino
TrustCom1
2024 ARIoTEDef: Adversarially Robust IoT Early Defense System Based on Self-Evolution against Multi-step Attacks
abstract
Internet of Things (IoT) cyber threats, exemplified by jackware and crypto mining, underscore the vulnerability of IoT devices. Due to the multi-step nature of many attacks, early detection is vital for a swift response and preventing malware propagation. However, accurately detecting early-stage attacks is challenging, as attackers employ stealthy, zero-day, or adversarial machine learning to evade detection. To enhance security, we propose ARIoTEDef, an Adversarially Robust IoT Early Defense system, which identifies early-stage infections and evolves autonomously. It models multi-stage attacks based on a cyber kill chain and maintains stage-specific detectors. When anomalies in the later action stage emerge, the system retroactively analyzes event logs using an attention-based sequence-to-sequence model to identify early infections. Then, the infection detector is updated with information about the identified infections. We have evaluated ARIoTEDef against multi-stage attacks, such as the Mirai botnet. Results show that the infection detector’s average F1 score increases from 0.31 to 0.87 after one evolution round. We have also conducted an extensive analysis of ARIoTEDef against adversarial evasion attacks. Our results show that ARIoTEDef is robust and benefits from multiple rounds of evolution.
Mengdie Huang, Hyunwoo Lee 0001, Ashish Kundu, Xiaofeng Chen 0001, Anand Mudgerikar, Ninghui Li 0001, Elisa Bertino
ACM Trans. Internet Things1
2023 Boost Off/On-Manifold Adversarial Robustness for Deep Learning with Latent Representation Mixup
abstract
Deep neural networks excel at solving intuitive tasks that are hard to describe formally, such as classification, but are easily deceived by maliciously crafted samples, leading to misclassification. Recently, it has been observed that the attack-specific robustness of models obtained through adversarial training does not generalize well to novel or unseen attacks. While data augmentation through mixup in the input space has been shown to improve the generalization and robustness of models, there has been limited research progress on mixup in the latent space. Furthermore, almost no research on mixup has considered the robustness of models against emerging on-manifold adversarial attacks. In this paper, we first design a latent-space data augmentation strategy called dual-mode manifold interpolation, which allows for interpolating disentangled representations of source samples in two modes: convex mixing and binary mask mixing, to synthesize semantic samples. We then propose a resilient training framework, LatentRepresentationMixup (LarepMixup), that employs mixed examples and softlabel-based cross-entropy loss to refine the boundary. Experimental investigations on diverse datasets (CIFAR-10, SVHN, ImageNet-Mixed10) demonstrate that our approach delivers competitive performance in training models that are robust to off/on-manifold adversarial example attacks compared to leading mixup training techniques.
Mengdie Huang, Yi Xie 0011, Xiaofeng Chen 0001, Jin Li 0002, Changyu Dong, Zheli Liu, Willy Susilo
AsiaCCS1
2022 GAME: Generative-Based Adaptive Model Extraction Attack
Yi Xie 0011, Mengdie Huang, Xiaoyu Zhang 0010, Changyu Dong, Willy Susilo, Xiaofeng Chen 0001
ESORICS (1)2