EDBT 2026 Demo / reviewers in the wild / expert
Dazhong Rong
dblp:317/6961
· DBLP profile ↗
13ranked-venue papers
4as first author
13since 2021 · last 2026
0000-0001-6486-9707ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 6 · 3 first-author · 6 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Reconstruct Private Embeddings: An Interaction-Level Membership Inference Attack Against Federated Social MatchingabstractSocial matching is a task that recommends potential friends to users based on their existing friendships. This user-to-user recommendation setting extends general recommender systems by shifting the focus from user-item interactions to interactions among users themselves, and general recommendation methods are often directly applied to this setting. However, we argue that in federated learning, directly applying existing federated recommendation methods to social matching can result in privacy leakage, due to the specificity of social matching: the mutual nature of friendships. We theoretically and quantitatively reveal these security vulnerabilities and propose a novel interaction-level membership inference attack targeting federated social matching. Our attack employs a reconstruction model combining affine transformations with an MLP to capture both linear and non-linear mappings between users' public and private embeddings. Trained on a portion of leaking user data, it can reconstruct benign users' private embeddings and infer their true friends. We conduct numerous experiments on multiple datasets under various experimental settings to verify the effectiveness and robustness of our attack method. Experimental results show that: (i) Our attack approach exhibits strong robustness and effectiveness across diverse experimental setups; (ii) Existing defense methods fail to effectively resist our attack while maintaining satisfactory recommendation performance. Our findings highlight the need for new privacy-preserving techniques specifically designed for federated social matching. Lingqi Jiang, Dazhong Rong, Guoyao Yu, Jianhai Chen, Qinming He, Zhenguang Liu |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Complementary-Disentangled Neural Generalization: a Robust Framework for Stable Brain-Computer InterfacesabstractBrain-computer interfaces (BCIs) enable communication between the brain and the external environment, showing significant potential in restoration, rehabilitation and movement enhancement. However, neural drift causes BCI performance to degrade substantially over time, compromising their long-term reliability. A fundamental limitation of current methods is their failure to account for a key insight from neural preference theory that the magnitude of neural drift depends on specific motor parameters (e.g., velocity, direction, and speed), ultimately compromising performance. To overcome the limitation, we introduce a novel framework named ComplementaryDisentangled Neural Generalization (CDNG) inspired by neural preference theory. Specifically, we first conduct pre-experiments about the neural decoding preference, revealing that neural drifts differ across velocity, speed and direction. Then we adopt CDNG, which captures invariant neural representations through an ensemble of three specialized neural decoders after disentangling velocity into speed and direction. Extensive experiments on several datasets demonstrate that our method achieves state-of-the-art performance and significantly enhances cross-day generalization. Jiyu Wei, Dazhong Rong, Di Hong, Zhanjie Zhang, Xinyun Zhu, Qinming He, Yueming Wang 0001 |
BIBM | 2 |
| 2025 | Improving Unsupervised Task-driven Models of Ventral Visual Stream via Relative Position Predictivity
Dazhong Rong, Jiyu Wei, Di Hong, Yaoyao Hao, Qinming He, Yueming Wang 0001 |
CogSci | 1 |
| 2024 | Speed-enhanced Subdomain Alignment for Long-term Stable Neural Decoding in Brain-computer InterfacesabstractBrain-computer interfaces (BCIs) offer a means to convert neural signals into control signals, providing a potential restoration of movement for people with paralysis. Despite their promise, BCIs face a significant challenge in maintaining decoding accuracy over time due to neural nonstationarities. While current recalibration techniques address this issue to a degree, they either fail to adequately exploit the limited labeled data, fail to perform conditional alignment in regression tasks, or overlook the signal correlation between data from two days. This paper proposes a novel Speed-enhanced Subdomain Alignment (SeSA) framework, integrating semi-supervised learning with domain adaptation techniques in regressive neural decoding. Specifically, SeSA carries out two alignments (i.e., global alignment and conditional speed alignment) to achieve recalibration. Our comprehensive set of experiments, both qualitative and quantitative, substantiate the superior recalibration performance and robustness of our proposed SeSA. Jiyu Wei, Dazhong Rong, Xinyun Zhu, Qinming He, Yueming Wang 0001 |
BIBM | 2 |
| 2024 | CrossViewDiff: A Cross-View Diffusion Model for Satellite-to-Ground Image Synthesis
Yuankun Chen, Dazhong Rong, Yi Li 0047 |
ICANN (3) | 2 |
| 2024 | Clean-Image Backdoor Attacks
Dazhong Rong, Guoyao Yu, Shuheng Shen, Jianhai Chen, Qinming He, Weiqiang Wang 0002 |
ICANN (10) | 1 |
| 2024 | MuFuzz: Sequence-Aware Mutation and Seed Mask Guidance for Blockchain Smart Contract FuzzingabstractAs blockchain smart contracts become more widespread and carry more valuable digital assets, they become an increasingly attractive target for attackers. Over the past few years, smart contracts have been subject to a plethora of devastating attacks, resulting in billions of dollars in financial losses. There has been a notable surge of research interest in identifying defects in smart contracts. However, existing smart contract fuzzing tools are still unsatisfactory. They struggle to screen out meaningful transaction sequences and specify critical inputs for each transaction. As a result, they can only trigger a limited range of contract states, making it difficult to unveil complicated vulnerabilities hidden in the deep state space. In this paper, we shed light on smart contract fuzzing by employing a sequence-aware mutation and seed mask guidance strategy. In particular, we first utilize data-flow-based feedback to determine transaction orders in a meaningful way and further introduce a sequence-aware mutation technique to explore deeper states. Thereafter, we design a mask-guided seed mutation strategy that biases the generated transaction inputs to hit target branches. In addition, we develop a dynamic-adaptive energy adjustment paradigm that balances the fuzzing resource allocation during a fuzzing campaign. We implement our designs into a new smart contract fuzzer named MuFuzz, and extensively evaluate it on three benchmarks. Empirical results demonstrate that MuFuzz outperforms existing tools in terms of both branch coverage and bug finding. Overall, MuFuzz achieves higher branch coverage than state-of-the-art fuzzers (up to 25%) and detects 30 % more bugs than existing bug detectors. Hanjie Wu, Zeren Du, Turan Vural, Dazhong Rong, Zheng Cao 0005, Jianhai Chen, Qinming He |
ICDE | 5 |
| 2024 | Preventing the Popular Item Embedding Based Attack in Federated RecommendationsabstractPrivacy concerns have led to the rise of federated recommender systems (FRS), which can create personalized models across distributed clients. However, FRS is vulnerable to poisoning attacks, where malicious users manipulate gradients to promote their target items intentionally. Existing attacks against FRS have limitations, as they depend on specific models and prior knowledge, restricting their real-world applicability. In our exploration of practical FRS vulnerabilities, we devise a model-agnostic and prior-knowledge-free attack, named PIECK (Popular Item Embedding based Attack). The core module of PIECK is popular item mining, which leverages embedding changes during FRS training to effectively identify the popular items. Built upon the core module, PIECK branches into two diverse solutions: The PIECKIPE solution employs an item popularity enhancement module, which aligns the embeddings of targeted items with the mined popular items to increase item exposure. The PIECKUEA further enhances the robustness of the attack by using a user embedding approximation module, which approximates private user embeddings using mined popular items. Upon identifying PIECK, we evaluate existing federated defense methods and find them ineffective against PIECK, as poisonous gradients inevitably overwhelm the cold target items. We then propose a novel defense method by introducing two regularization terms during user training, which constrain item popularity enhancement and user embedding approximation while preserving FRS performance. We evaluate PIECK and its defense across two base models, three real datasets, four top-tier attacks, and six general defense methods, affirming the efficacy of both PIECK and its defense. Jun Zhang 0069, Huan Li 0003, Dazhong Rong, Yan Zhao 0008, Ke Chen 0005, Lidan Shou |
ICDE | 3 |
| 2024 | Multiview Consistent Physical Adversarial Camouflage Generation through Semantic GuidanceabstractReal-world camouflage-based physical adversarial attacks have exhibited the capability of deceiving object detection models into predicting incorrect categories or bounding boxes. Nevertheless, a common issue with existing adversarial camouflages is their multi-view inconsistency in attack results. Specifically, the predicted category will frequently change as the observing viewpoints change. This multi-view inconsistency weakens the stealthiness of the existing adversarial camouflages and hence potentially triggers the alarm of adversarial attacks. To address this problem, we propose a novel approach for Multi-view Consistent adversarial Camouflage (MCC) generation framework. Specifically, we construct the problem of generating adversarial camouflages as a texture encoding and decoding problem for the target objects. During the encoding process, the semantic information of the target category is embedded, thereby generating adversarial camouflage with specific target semantics. Then we utilize a 3D neural renderer to generate the printable camouflage in the real world. Our approach enhances semantic constraints on adversarial camouflage in the latent space, thereby ensuring that the semantic information of the camouflage remains aligned with the specified categories, regardless of the viewpoints. As a result, the generated adversarial camouflage exhibit better stealthiness. We conduct several attack experiments against stateof-the-art object detection models within the simulated physical world. Additionally, we transfer the adversarial camouflage to the real physical world and apply it to a vehicle model. The experimental results show that our method not only has excellent attack performance, but also has significant multi-view consistency compared with other methods. Heran Zhu, Dazhong Rong |
IJCNN | 2 |
| 2023 | SmartDS: Middle-Tier-centric SmartNIC Enabling Application-aware Message Split for Disaggregated Block StorageabstractThe widespread deployment of storage disaggregation in the cloud has facilitated flexible scaling and storage overprovisioning, allowing for high utilization of storage capacity and IOPS. Instead of utilizing remote storage protocols to access remote disks, a middle-tier is introduced between compute servers and storage servers in order to serve I/O requests from compute servers and provide computations such as compression and decompression. However, due to the need for a cloud to concurrently serve millions of VMs that require access to disaggregated storage, the middle-tier requires a massive number of servers to process network traffic between computing and storage nodes. For example, a major cloud company may deploy hundreds of thousands of high-end servers to provide such a service for its cloud storage, because the existing CPU-based middle-tier suffers from a severe issue of compute-intensive compression/decompression on high-throughput storage traffic. To address this issue, we introduce SmartDS, a middle-tier-centric SmartNIC that serves storage I/O requests with low latency and high throughput, while maintaining high flexibility and programmability. The key idea behind SmartDS is the application-aware message split (AAMS) mechanism, which allows for the processing of the message's header on the host CPU to achieve high flexibility, and the message's payload on the SmartDS. Experimental results demonstrate that SmartDS provides up to 4.3× more throughput than a CPU-based middle-tier and enables the linear scale-up of multiple network ports and multiple SmartNICs, thus significantly reducing cloud infrastructure costs for disaggregated block storage. Jie Zhang 0081, Hongjing Huang, Lingjun Zhu, Dazhong Rong, Yijun Hou, Mo Sun 0001, Chaojie Gu, Peng Cheng 0001, Zeke Wang |
ISCA | 5 |
| 2023 | CoMeta: Enhancing Meta Embeddings with Collaborative Information in Cold-Start Problem of Recommendation
Haonan Hu, Dazhong Rong, Jianhai Chen, Qinming He, Zhenguang Liu |
KSEM (3) | 2 |
| 2022 | FedRecAttack: Model Poisoning Attack to Federated RecommendationabstractFederated Recommendation (FR) has received con-siderable popularity and attention in the past few years. In FR, for each user, its feature vector and interaction data are kept locally on its own client thus are private to others. Without the access to above information, most existing poisoning attacks against recommender systems or federated learning lose validity. Benifiting from this characteristic, FR is commonly considered fairly secured. However, we argue that there is still possible and necessary security improvement could be made in FR. To prove our opinion, in this paper we present FedRecAttack, a model poisoning attack to FR aiming to raise the exposure ratio of target items. In most recommendation scenarios, apart from pri-vate user-item interactions (e.g., clicks, watches and purchases), some interactions are public (e.g., likes, follows and comments). Motivated by this point, in FedRecAttack we make use of the public interactions to approximate users' feature vectors, thereby attacker can generate poisoned gradients accordingly and control malicious users to upload the poisoned gradients in a well-designed way. To evaluate the effectiveness and side effects of FedRecAttack, we conduct extensive experiments on three real-world datasets of different sizes from two completely different scenarios. Experimental results demonstrate that our proposed FedRecAttack achieves the state-of-the-art effectiveness while its side effects are negligible. Moreover, even with small proportion (3%) of malicious users and small proportion (1%) of public interactions, FedRecAttack remains highly effective, which reveals that FR is more vulnerable to attack than people commonly considered. Dazhong Rong, Ruoyan Zhao, Hon Ning Yuen, Jianhai Chen, Qinming He |
ICDE | 1 |
| 2022 | Poisoning Deep Learning Based Recommender Model in Federated Learning ScenariosabstractVarious attack methods against recommender systems have been proposed in the past years, and the security issues of recommender systems have drawn considerable attention. Traditional attacks attempt to make target items recommended to as many users as possible by poisoning the training data. Benifiting from the feature of protecting users' private data, federated recommendation can effectively defend such attacks. Therefore, quite a few works have devoted themselves to developing federated recommender systems. For proving current federated recommendation is still vulnerable, in this work we probe to design attack approaches targeting deep learning based recommender models in federated learning scenarios. Specifically, our attacks generate poisoned gradients for manipulated malicious users to upload based on two strategies (i.e., random approximation and hard user mining). Extensive experiments show that our well-designed attacks can effectively poison the target models, and the attack effectiveness sets the state-of-the-art. Dazhong Rong, Qinming He, Jianhai Chen |
IJCAI | 1 |