Zhengdao Li

dblp:318/2864 · DBLP profile ↗
← Back
13ranked-venue papers
1as first author
13since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-author · 4 since 2021Computer networks · 3 · 3 since 2021Security and privacy · 2 · 2 since 2021
YearPublicationVenuePosition
2026 A robust underwater object tracking model with cross-modal selective joint representation and relationship enhancement of text and visual features
Ning Li 0050, Chunhua Zhu, Zhengdao Li, Kongyang Chen, Yun Peng 0002
Expert Syst. Appl.3
2026 HPA: Manipulating deep reinforcement learning via adversarial interaction
Kanghua Mo, Yucheng Long, Zhengdao Li
J. Syst. Archit.5
2026 SwiftDistill: Efficient robust knowledge transfer via dual-branch adversarial distillation and hardness-balanced augmentation
Junhao Dong 0001, Yuqing Wen, Zhengdao Li, Siheng Wang, Xinghua Qu, Yew-Soon Ong
Pattern Recognit.3
2026 SecTEND: Secure Deployment of Heterogeneous Applications for Multi-Tenant FPGA-Based Platforms
abstract
Currently, FPGA-based processing systems in cloud environments are gaining popularity due to the growing demand for flexible and scalable hardware acceleration in cloud-based services. To reduce infrastructure costs and enhance resource utilization, multi-tenant sharing of computing resources has become a viable option for cloud service providers (CSPs). However, several attacks can occur during the deployment of heterogeneous applications, potentially leading to privacy leaks or even system crashes. In this paper, we propose SecTEND, a comprehensive solution for FPGA-SoCs that includes both a multi-party protocol for the secure delivery and loading of heterogeneous applications from tenants to remote devices of CSPs, and a security framework designed to ensure the protection and isolation of these applications. Within the framework, a multi-key protection mode and a hardware-accelerated cryptographic pathway are proposed and implemented. Meanwhile, several security-related functionalities, such as secure communication among parties, bitstream validation and loading are provided. Finally, we perform a security analysis, discuss possible countermeasures to further enhance the security of SecTEND, and evaluate our solution on a Xilinx UltraScale+ FPGA-SoC platform, demonstrating its security with acceptable timing overhead. Additionally, the hardware-accelerated cryptographic operations provided by the framework achieve higher throughput compared to software solutions in most cases.
Zhengdao Li, Yu-an Tan 0001, Peigen Ye, Ning Shi, Yuanzhang Li 0001
IEEE Trans. Dependable Secur. Comput.2
2025 TrapNet: Model Inversion Defense via Trapdoor
abstract
Model inversion (MI) attacks, for which effective defense strategies are still lacking, pose significant risks to privacy by reconstructing private training data through access to well-trained classifiers. Addressing this concern, this study introduces TrapNet, designed to defend against advanced MI attacks while maintaining good model utility. TrapNet intentionally injects trapdoors into the classification manifold of the protected target model. In this way, TrapNet can effectively mislead MI attack optimization. Specifically, TrapNet leverages a conditional GAN (cGAN) trained on the private dataset to generate diverse and realistic trapdoor samples. In addition, we propose a graph-matching self-obfuscation strategy and an entropy regularization technique to optimize trapdoor injection while preserving model utility. Compared to the existing defense, TrapNet can provide universal protection to all target classes without access to any auxiliary public data. Extensive experiments on CelebA, VGG-Face, and VGG-Face2 datasets demonstrate TrapNet’s superior performance over existing defenses, including the most advanced NetGuard and BiDO, against state-of-the-art model inversion attacks, i.e., PLG-MI, LOMMA, and Plug&Play.
Wanlun Ma, Derui Wang, Yiliao Song, Minhui Xue 0001, Sheng Wen, Zhengdao Li, Yang Xiang 0001
IEEE Trans. Inf. Forensics Secur.6
2025 Unsupervised Adversarial Example Detection of Vision Transformers for Trustworthy Edge Computing
abstract
Many edge computing applications based on computer vision have harnessed the power of deep learning. As an emerging deep learning model for vision, Vision Transformer models have recently achieved record-breaking performance in various vision tasks. But many recent studies on the robustness of the Vision Transformer have shown that the Vision Transformer is still vulnerable to adversarial attacks and is easily affected by adversarial attacks, causing the model to misclassify the input. In this work, we ask an intriguing question: “Can Adversarial Perturbations against Vision Transformers be detected with model explanations?” Driven by this question, we observe that benign samples and adversarial examples have different attribution maps after applying the Grad-CAM interpretability method on the Vision Transformer model. We demonstrate that an adversarial example is a Feature Shift of the input data, which leads to an Attention Deviation of the visual model. We propose a framework for capturing the Attention Deviation of vision models to defend against adversarial attacks. Furthermore, experiments show that our model achieves expectative results.
Jiaxing Li 0012, Yu-an Tan 0001, Zhengdao Li, Heng Ye, Chenxiao Xia, Yuanzhang Li 0001
ACM Trans. Multim. Comput. Commun. Appl.4
2025 EdgeSyn: Privacy-Preserving Data Publishing on Edge Network over Infinite Multimedia Data Stream
abstract
To privately publish sensitive multimedia data in an edge network with fog devices, one of the best privacy-preserving solutions is to use differential privacy (DP) mechanisms. However, existing DP data publication mechanisms for the infinite data stream of edge networks mainly focus on publishing data with specific types of data or a set of predetermined queries. This approach is not suitable for multimedia data with numerous features that require a more flexible data publishing mechanism. In this article, we propose EdgeSyn, a novel mechanism for accurately publishing multimedia data over infinite data streams in an edge network. It allocates privacy budgets with a sliding window, adopting data synthesis mechanisms to support dynamic publishing without loss of accuracy. In more detail, EdgeSyn addresses the limitations associated with data types in prior data stream publishing approaches and introduces a privacy budget management strategy that optimally allocates budgets for the implementation of data synthesis mechanisms over an infinite data stream. The experimental results show that EdgeSyn performs well under different privacy budgets and various lengths of active windows.
Zhewei Liu, Zhengdao Li, Jingyu Jia, Siyi Lv, Tong Li 0011, Zheli Liu
ACM Trans. Multim. Comput. Commun. Appl.3
2025 Progressive Generative Steganography via High-Resolution Image Generation for Covert Communication
abstract
Recently, as one of the most popular covert communication technologies, generative steganography has received ever-increasing attention due to its promising performance against sophisticated steganalysis tools. However, it is quite difficult for the existing generative steganographic approaches to find a good tradeoff between hiding capacity and extraction accuracy, mainly due to the small capacity of their hiding spaces. To overcome this shortcoming, a Progressive Generative Steganography (PGS) network architecture is proposed to hide a secret message during the progressive image generation process to realize secure covert communication. Specifically, we first propose a robust Secret-to-Noise (S2N) mapping method to encode the secret message as a set of noise maps. Then, guided by these noise maps, a set of corresponding images ranging from low resolution to high resolution are progressively generated by the Single Generative Adversarial Networks (SINGAN). Consequently, a large-sized secret message can be hidden in the finally generated high-resolution image, since a set of high-capacity hiding spaces can be provided by the process of progressive image generation. Moreover, to improve the quality of image generation and the accuracy of secret message extraction, a Dense Secret-Feature Connection (DSFC) strategy is designed and integrated into the proposed PGS network architecture. Extensive experiments demonstrate that the proposed PGS outperforms the existing approaches in the aspects of both hiding capacity and message extraction, while maintaining promising anti-detectability and imperceptibility for covert communication.
Zhili Zhou 0001, Wensheng Zhang 0002, Zhengdao Li, Huilin Ge, Bin Qiu, Fengjun Xiao, Yongfeng Huang 0001
ACM Trans. Multim. Comput. Commun. Appl.3
2024 Temperature-Based Watermarking and Detection for Large Language Models
Zhenxin Zhang, Huali Ren, Zhengdao Li
ICA3PP (1)5
2024 Rethinking the Effectiveness of Graph Classification Datasets in Benchmarks for Assessing GNNs
Zhengdao Li, Yong Cao 0001, Kefan Shuai, Yiming Miao, Kai Hwang 0001
IJCAI1
2024 Graph Confident Learning for Software Vulnerability Detection
Qian Wang 0034, Zhengdao Li, Hetong Liang, Xiaowei Pan, Hui Li 0014, Shikai Guo
Eng. Appl. Artif. Intell.2
2023 Federated Clouds for Efficient Multitasking in Distributed Artificial Intelligence Applications
abstract
Distributed cloud/edge resources are needed to execute pervasive artificial intelligence tasks, collectively. The AI workload and data sets have variable multitasking granularity, privacy constraints, and communication latency concerns. This article presents a novelfederated cloud/edge(FCE)framework, illustrated by distributed medical image processing across multiple hospital sites. This federated cloud system appeals to train many machine learning models efficiently with workload balancing and reduced communication overheads. We tested the FCE model on a multi-cloud platform recently built at the Chinese University of Hong Kong in Shenzhen. We claim three distinct advantages in using the FCE system. First, our federated cloud system results in 41.3% reduction in total AI processing time in large-scale ML/DL experiments. Second, high machine model accuracy was achieved at 87% level in telemedicine experiments. The virtual graph helps reduce internode traffic latencies to avoid ML inference slowdowns. Third, the system can tolerate multiple cloud failures to enter a graceful degradation mode in case of node failures. The scalable performance gains in AI processing speed, model accuracy, and fault tolerance make our federated clouds a truly viable approach to solving massive AI multitasking problems in pervasive AI applications.
Yuejin Li, Kai Hwang 0001, Kefan Shuai, Zhengdao Li, Albert Y. Zomaya
IEEE Trans. Cloud Comput.4
2023 Transfer Reinforcement Learning for Adaptive Task Offloading Over Distributed Edge Clouds
abstract
In the big data era, resource-constrained mobile devices generate an overwhelmingly large amount of data with complex tasks that demand distributed execution. Offloading computation-intensive tasks to nearby edge clouds is promising to solve this problem. However, mobile end devices cannot handle heterogeneous or delay-sensitive tasks. These end devices are also energy constrained with weak adaptability to environment changes. To address and tackle these problems, we present a two-moduletransfer reinforcement learning(TRL) framework for adaptive task offloading. A domain adaptation module is used to align heterogeneous characteristics of mobile devices. The TRL makes offloading decisions with adeep reinforcement learning(DRL) module. We evaluate the performance of TRL through real-world experiments on edge clouds. Our experiment results show that TRL reduces the task processing time by a factor of 20% from using three well known DRL methods. Our method achieved (15.4$\sim$40)% reduction in task drop rate over these methods. With domain adaptation, the TRL results in (50$\sim$80)% reduction in model convergence time. These advantages in using the TRL framework make it appealing in real-life edge computing applications.
Kefan Shuai, Yiming Miao, Kai Hwang 0001, Zhengdao Li
IEEE Trans. Cloud Comput.4