EDBT 2026 Demo / reviewers in the wild / expert
Mengxin Zheng
dblp:327/9609
· DBLP profile ↗
20ranked-venue papers
7as first author
20since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 10 · 4 first-author · 10 since 2021Systems, architecture and hardware · 5 · 2 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 2 first-author · 4 since 2021Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Conjunctive Prompt Attacks in Multi-Agent LLM SystemsabstractMost LLM safety work studies single-agent models, but many real applications rely on multiple interacting agents.In these systems, prompt segmentation and inter-agent routing create attack surfaces that single-agent evaluations miss.We study conjunctive prompt attacks, where a trigger key in the user query and a hidden adversarial template in one compromised remote agent each appear benign alone but activate harmful behavior when routing brings them together.We consider an attacker who changes neither model weights nor the client agent and instead controls only trigger placement and template insertion.Across star, chain, and DAG topologies, routing-aware optimization substantially increases attack success over non-optimized baselines while keeping false activations low.Existing defenses, including PromptGuard, Llama-Guard variants, and system-level controls such as tool restrictions, do not reliably stop the attack because no single component appears malicious in isolation.These results expose a structural vulnerability in agentic LLM pipelines and motivate defenses that reason over routing and cross-agent composition. Nokimul Hasan Arif, Qian Lou, Mengxin Zheng |
ACL (1) | 3 |
| 2026 | ReliaFHE: Resilient Design for Fully Homomorphic Encryption AcceleratorsabstractThe significant computational complexity of Fully Homomorphic Encryption (FHE) has prompted numerous accelerator designs. However, existing FHE accelerators often implicitly assume that all computations are executed reliably, overlooking the fact that modern FHE schemes can be highly vulnerable to hardware faults: even a single-bit error in a ciphertext can cascade into widespread plaintext corruption. Ruizhi Zhu, Mengxin Zheng, Qian Lou, Xin Xin 0008 |
ASPLOS (2) | 4 |
| 2026 | SoK: Can Fully Homomorphic Encryption Support General AI Computation? A Functional and Cost AnalysisabstractArtificial intelligence (AI) increasingly powers sensitive applications in domains such as healthcare and finance, relying on both extit{linear operations} (e.g., matrix multiplications in large language models) and extit{non-linear operations} (e.g., sorting in retrieval-augmented generation). Fully homomorphic encryption (FHE) has emerged as a promising tool for privacy-preserving computation, but it remains unclear whether existing methods can support the full spectrum of AI workloads that combine these operations. In this SoK, we ask: extit{Can FHE support general AI computation?} We provide both a functional analysis and a cost analysis. First, we categorize ten distinct FHE approaches and evaluate their ability to support general computation. We then identify three promising candidates and benchmark workloads that mix linear and non-linear operations across different bit lengths and SIMD parallelization settings. Finally, we evaluate five real-world, privacy-sensitive AI applications that instantiate these workloads. Our results quantify the costs of achieving general computation in FHE and offer practical guidance on selecting FHE methods that best fit specific AI application requirements. Our codes are available at https://github.com/UCF-ML-Research/FHE-AI-Generality. Wei Zhang 0076, Mengxin Zheng, Minxuan Zhou, Yushun Dong, Dongjie Wang 0001, Jiafeng Xie, David Mohaisen, Hongyi Wu, Qian Lou |
Proc. Priv. Enhancing Technol. | 4 |
| 2026 | FGAIM: Identifying Drug-Target Activation and Inhibition Mechanisms via Inductive Graph Neural Networks Based on Fine-Grained Interaction StrategiesabstractDistinguishing the activation and inhibition mechanisms between drugs and targets can reveal the potential regulatory pathways of target functions, which is crucial in drug discovery and development. Although numerous deep learning-based computational methods have been proposed, most of them extract drug and target features independently while neglecting interactions between drug molecules and protein residues. In addition, existing methods approach drugs in a relatively simple way and predominantly rely on protein sequence information. Deep learning, particularly graph neural networks (GNNs), has demonstrated unique advantages in processing data with complex graph-structured relationships. Motivated by these limitations, this study proposes a novel computational method named FGAIM, which designed to effectively identify activation and inhibition mechanisms between drugs and targets. First, a multi-scale GNN module in FGAIM is employed to learn expressive drug molecular embeddings. At the same time, protein representations are constructed by integrating pre-trained language model (PLM) embeddings and structural information derived from 3D conformations. Subsequently, FGAIM leverages a GraphSAGE module to extract features from both the primary drug graph and the fine-grained drug-protein interaction graph. Finally, the resulting drug and target embeddings are fused and fed into a Multilayer Perceptron (MLP) for classification prediction. Comparative experiments on two public datasets demonstrate that FGAIM significantly outperforms existing computational approaches and exhibits strong generalization capabilities. Further case studies reveal the advantages of FGAIM in mining previously unrecognized activation/inhibition relationships. Building upon the fine-grained interactions, we further explored the model's interpretability at the molecular structural level through analysis of attention weights. Additionally, visualization analyses confirm that FGAIM effectively captures underlying structural patterns in the data and identifies discriminative features across different categories. Yongxian Fan, Guicong Sun, Mengxin Zheng |
IEEE Trans. Comput. Biol. Bioinform. | 4 |
| 2025 | Corrosion Hammer: A Self-Activated Bit-Flip Attack to the Processing-In-Memory AcceleratorabstractIn this paper, taking ReRAM-based PIM accelerators as an example, we present a novel attack framework called Corrosion Hammer, which builds based on the Bit Flip Attack (BFA).Unlike previous BFA methods that require explicit memory fault injection techniques, such as Row Hammer, to modify sensitive bits in the victim Neural Network model, Corrosion Hammer implants the trojan during the hardware-software co-design phase and flips sensitive bits using read disturbance, which is a common noise in ReRAM caused by normal read operations.Furthermore, we explore the impact of inputs on the activation time consumption of the trojan and propose a method to expedite activation using normal input.Our experimental results demonstrate that Corrosion Hammer achieves an extremely covert trojan implantation and activation method, with an adversarial attack success rate of 92.46%.Additionally, using a specially designed method, Trojan activation is 61.98× faster compared to activation in an undisturbed normal operation state.It provides a way to significantly speed up the Trojan activation. Mengxin Zheng, Shengyu Fan, Qian Lou, Rui Hou 0001, Dan Meng 0002, Mingzhe Zhang 0005 |
CF | 2 |
| 2025 | zkVC: Fast Zero-Knowledge Proof for Private and Verifiable ComputingabstractIn the context of cloud computing, services are held on cloud servers, where the clients send their data to the server and obtain the results returned by server. However, the computation, data and results are prone to tampering due to the vulnerabilities on the server side. Thus, verifying the integrity of computation is important in the client-server setting. The cryptographic method known as Zero-Knowledge Proof (ZKP) is renowned for facilitating private and verifiable computing. ZKP allows the client to validate that the results from the server are computed correctly without violating the privacy of the server’s intellectual property. Zero-Knowledge Succinct NonInteractive Argument of Knowledge (zkSNARKs), in particular, has been widely applied in various applications like blockchain and verifiable machine learning. Despite their popularity, existing zkSNARKs approaches remain highly computationally intensive. For instance, even basic operations like matrix multiplication require an extensive number of constraints, resulting in significant overhead. In addressing this challenge, we introduce $z k V C$, which optimizes the ZKP computation for matrix multiplication, enabling rapid proof generation on the server side and efficient verification on the client side. zkVC integrates optimized ZKP modules, such as Constraint-reduced Polynomial Circuit (CRPC) and Prefix-Sum Query (PSQ), collectively yielding a more than $\mathbf{1 2}$-fold increase in proof speed over prior methods. The code is available at https://github.com/UCF-Lou-Lab-PET/zkformer. Yancheng Zhang, Mengxin Zheng, Jingtong Hu, Lei Ju 0001, Yan Solihin, Qian Lou |
DAC | 2 |
| 2025 | CipherPrune: Efficient and Scalable Private Transformer InferenceabstractPrivate Transformer inference using cryptographic protocols offers promising solutions for privacy-preserving machine learning; however, it still faces significant runtime overhead (efficiency issues) and challenges in handling long-token inputs (scalability issues). We observe that the Transformer's operational complexity scales quadratically with the number of input tokens, making it essential to reduce the input token length. Notably, each token varies in importance, and many inputs contain redundant tokens. Additionally, prior private inference methods that rely on high-degree polynomial approximations for non-linear activations are computationally expensive. Therefore, reducing the polynomial degree for less important tokens can significantly accelerate private inference. Building on these observations, we propose \textit{CipherPrune}, an efficient and scalable private inference framework that includes a secure encrypted token pruning protocol, a polynomial reduction protocol, and corresponding Transformer network optimizations. At the protocol level, encrypted token pruning adaptively removes unimportant tokens from encrypted inputs in a progressive, layer-wise manner. Additionally, encrypted polynomial reduction assigns lower-degree polynomials to less important tokens after pruning, enhancing efficiency without decryption. At the network level, we introduce protocol-aware network optimization via a gradient-based search to maximize pruning thresholds and polynomial reduction conditions while maintaining the desired accuracy. Our experiments demonstrate that CipherPrune reduces the execution overhead of private Transformer inference by approximately $6.1\times$ for 128-token inputs and $10.6\times$ for 512-token inputs, compared to previous methods, with only a marginal drop in accuracy. The code is publicly available at https://github.com/UCF-Lou-Lab-PET/cipher-prune-inference. Yancheng Zhang, Mengxin Zheng, Mimi Xie, Mingzhe Zhang 0005, Lei Jiang 0001, Qian Lou |
ICLR | 3 |
| 2025 | DictPFL: Efficient and Private Federated Learning on Encrypted GradientsabstractFederated Learning (FL) enables collaborative model training across institutions without sharing raw data. However, gradient sharing still risks privacy leakage, such as gradient inversion attacks. Homomorphic Encryption (HE) can secure aggregation but often incurs prohibitive computational and communication overhead. Existing HE-based FL methods sit at two extremes: encrypting all gradients for full privacy at high cost, or partially encrypting gradients to save resources while exposing vulnerabilities. We present **DictPFL**, a practical framework that achieves full gradient protection with minimal overhead. DictPFL encrypts every transmitted gradient while keeping non-transmitted parameters local, preserving privacy without heavy computation. It introduces two key modules: **Decompose-for-Partial-Encrypt (DePE)**, which decomposes model weights into a static dictionary and an updatable lookup table—only the latter is encrypted and aggregated, while the static dictionary remains local and requires neither sharing nor encryption; and **Prune-for-Minimum-Encrypt (PrME)**, which applies encryption-aware pruning to minimize encrypted parameters via consistent, history-guided masks. Experiments show that DictPFL reduces communication cost by 402-748$\times$ and accelerates training by 28-65$\times$ compared to fully encrypted FL, while outperforming state-of-the-art selective encryption methods by 51-155$\times$ in overhead and 4-19$\times$ in speed. Remarkably, DictPFL’s runtime is within 2$\times$ of plaintext FL, demonstrating, for the first time, that HE-based private federated learning is practical for real-world deployment. The code is publicly available at https://github.com/UCF-ML-Research/DictPFL. Yuzhang Shang, Shangqian Gao, Rui Ning, Mengxin Zheng, Xiaoqian Jiang, Qian Lou |
NeurIPS | 6 |
| 2025 | EGCPPIS: learning hierarchical equivariant graph representations with contrastive integration for protein-protein interaction site identificationabstractBACKGROUND: Protein-protein interactions regulate the dynamic operation of intracellular molecular networks, serving as the molecular basis for revealing protein functions and disease mechanisms. Recently, several computational methods for predicting protein-protein interaction sites (PPIs) have been presented as alternatives to costly and labor-intensive traditional experiments. However, existing methods generally ignore the inherent hierarchical structure of protein chains. Furthermore, the equivariance of graph structure during spatial transformations is often neglected when applying graph neural networks to modeling. Therefore, accurately identifying PPIs remains a challenging task. RESULTS: In this work, we propose an end-to-end GNN-based computational method, EGCPPIS, for efficiently identifying protein-protein interaction sites. First, we construct a hierarchical graph representation of the protein chain, including residue-level graph and atom-level graph. Next, EGCPPIS designs an E(n) Equivariant Graph Neural Network (EGNN) module to learn residue-level embeddings with equivariant features. After further extracting atom-level embeddings using the GraphSAGE module, we introduce the contrastive learning strategy to integrate hierarchical graph features. This strategy enables us to learn consistent embeddings between residue-level and atom-level representations. Finally, the fused embeddings are weighted using an improved gated multi-head attention mechanism. CONCLUSION: Comprehensive evaluation results on multiple datasets demonstrate that EGCPPIS significantly outperforms state-of-the-art methods. Extensive comparative experiments and case studies further confirm that EGCPPIS can reveal the decision-making patterns in PPIs prediction, facilitating the discovery of potential PPIs. The original datasets and code of EGCPPIS are available at https://github.com/GuicongSun/EGCPPIS . Guicong Sun, Yongxian Fan, Yangfeng Zhu, Mengxin Zheng |
BMC Bioinform. | 4 |
| 2025 | Corrosion Hammer: a self-activated bit-flip attack to the processing-in-memory acceleratorabstractAbstract The Resistive Random-Access-Memory (ReRAM) crossbar-based Processing-In-Memory (PIM) accelerator shows great promise in accelerating neural networks (NNs). This technique boasts low energy consumption and exceptional performance in multiplication and accumulations (MAC) operations, making ReRAM-based PIM accelerators an ideal solution for intelligent computing in wearable and low-power mobile devices. However, security concerns related to PIM have not been adequately addressed. In this paper, we present a new attack framework called SolutionName for ReRAM-based PIM accelerators. SolutionName builds upon the Bit Flip Attack (BFA), a weight modification attack that manipulates the NN function by flipping specific bits in the deployed quantized NN model. Unlike previous BFA methods that require explicit memory fault injection techniques, such as Row Hammer, to modify sensitive bits in the victim NN, SolutionName implants the trojan during the hardware-software co-design phase and flips sensitive bits using read disturbance. Read disturbance is a common noise in ReRAM caused by normal read operations. This approach enables the trojan to be activated quietly during normal use, eliminating the need for explicit attacks. Furthermore, we explore the impact of inputs on the activation time of the trojan and propose a method to expedite activation using normal input. Our experimental results demonstrate that SolutionName achieves an extremely covert trojan implantation and activation method, with an adversarial attack success rate of 94.38%. Additionally, with a specially designed method, the trojan activation can be accelerated on average by 61.98 $$\times $$ × , providing controllable activation. Mengxin Zheng, Shengyu Fan, Qian Lou, Rui Hou 0001, Dan Meng 0002, Mingzhe Zhang 0005 |
Cybersecur. | 2 |
| 2025 | MLC-DTA: Drug-target affinity prediction based on multi-level contrastive learning and equivariant graph neural networks
Mengxin Zheng, Guicong Sun, Yongxian Fan |
Neurocomputing | 1 |
| 2024 | SSL-Cleanse: Trojan Detection and Mitigation in Self-Supervised Learning
Mengxin Zheng, Qian Lou, Lei Jiang 0001, Xiaofeng Wang 0001 |
ECCV (87) | 1 |
| 2024 | Jailbreaking LLMs with Arabic Transliteration and ArabiziabstractThis study identifies the potential vulnerabilities of Large Language Models (LLMs) to 'jailbreak' attacks, specifically focusing on the Arabic language and its various forms.While most research has concentrated on English-based prompt manipulation, our investigation broadens the scope to investigate the Arabic language.We initially tested the AdvBench benchmark in Standardized Arabic, finding that even with prompt manipulation techniques like prefix injection, it was insufficient to provoke LLMs into generating unsafe content.However, when using Arabic transliteration and chatspeak (or arabizi), we found that unsafe content could be produced on platforms like OpenAI GPT-4 and Anthropic Claude 3 Sonnet.Our findings suggest that using Arabic and its various forms could expose information that might remain hidden, potentially increasing the risk of jailbreak attacks.We hypothesize that this exposure could be due to the model's learned connection to specific words, highlighting the need for more comprehensive safety training across all language forms. 1 Mansour Al Ghanim, Saleh Almohaimeed, Mengxin Zheng, Yan Solihin, Qian Lou |
EMNLP | 3 |
| 2024 | OFHE: An Electro-Optical Accelerator for Discretized TFHEabstractThis paper presents OFHE, an electro-optical accelerator designed to process Discretized TFHE (DTFHE) operations, which encrypt multi-bit messages and support homomorphic multiplications, lookup table operations and full-domain functional bootstrappings. While DTFHE is more efficient and versatile than other fully homomorphic encryption schemes, it requires 32-, 64-, and 128-bit polynomial multiplications, which can be time-consuming. Existing TFHE accelerators are not easily upgradable to support DTFHE operations due to limited datapaths, a lack of datapath bit-width reconfigurability, and power inefficiencies when processing FFT and inverse FFT (IFFT) kernels. Compared to prior TFHE accelerators, OFHE addresses these challenges by improving the DTFHE operation latency by 8.7%, the DTFHE operation throughput by 57%, and the DTFHE operation throughput per Watt by 94%. Mengxin Zheng, Cheng Chu, Qian Lou, Nathan Youngblood, Sajjad Moazeni, Lei Jiang 0001 |
ISLPED | 1 |
| 2024 | TrojFSP: Trojan Insertion in Few-shot Prompt TuningabstractMengxin Zheng, Jiaqi Xue, Xun Chen, Yanshan Wang, Qian Lou, Lei Jiang. Proceedings of the 2024 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies (Volume 1: Long Papers). 2024. Mengxin Zheng, Yanshan Wang, Qian Lou |
NAACL-HLT | 1 |
| 2024 | HEPrune: Fast Private Training of Deep Neural Networks With Encrypted Data PruningabstractNon-interactive cryptographic computing, Fully Homomorphic Encryption (FHE), provides a promising solution for private neural network training on encrypted data. One challenge of FHE-based private training is its large computational overhead, especially the multiple rounds of forward and backward execution on each encrypted data sample. Considering the existence of largely redundant data samples, pruning them will significantly speed up the training, as proven in plain non-FHE training.
Executing the data pruning of encrypted data on the server side is not trivial since the knowledge calculation of data pruning needs complex and expensive executions on encrypted data. There is a lack of FHE-based data pruning protocol for efficient, private training. In this paper, we propose, \textit{HEPrune}, to construct a FHE data-pruning protocol and then design an FHE-friendly data-pruning algorithm under client-aided or non-client-aided settings, respectively. We also observed that data sample pruning may not always remove ciphertexts, leaving large empty slots and limiting the effects of data pruning. Thus, in HEPrune, we further propose ciphertext-wise pruning to reduce ciphertext computation numbers without hurting accuracy. Experimental results show that our work can achieve a $16\times$ speedup with only a $0.6\%$ accuracy drop over prior work.
The code is publicly available at \href{https://github.com/UCF-Lou-Lab-PET/Private-Data-Prune}. Yancheng Zhang, Mengxin Zheng, Yuzhang Shang, Qian Lou |
NeurIPS | 2 |
| 2024 | EGPDI: identifying protein-DNA binding sites based on multi-view graph embedding fusionabstractMechanisms of protein-DNA interactions are involved in a wide range of biological activities and processes. Accurately identifying binding sites between proteins and DNA is crucial for analyzing genetic material, exploring protein functions, and designing novel drugs. In recent years, several computational methods have been proposed as alternatives to time-consuming and expensive traditional experiments. However, accurately predicting protein-DNA binding sites still remains a challenge. Existing computational methods often rely on handcrafted features and a single-model architecture, leaving room for improvement. We propose a novel computational method, called EGPDI, based on multi-view graph embedding fusion. This approach involves the integration of Equivariant Graph Neural Networks (EGNN) and Graph Convolutional Networks II (GCNII), independently configured to profoundly mine the global and local node embedding representations. An advanced gated multi-head attention mechanism is subsequently employed to capture the attention weights of the dual embedding representations, thereby facilitating the integration of node features. Besides, extra node features from protein language models are introduced to provide more structural information. To our knowledge, this is the first time that multi-view graph embedding fusion has been applied to the task of protein-DNA binding site prediction. The results of five-fold cross-validation and independent testing demonstrate that EGPDI outperforms state-of-the-art methods. Further comparative experiments and case studies also verify the superiority and generalization ability of EGPDI. Mengxin Zheng, Guicong Sun, Yongxian Fan |
Briefings Bioinform. | 1 |
| 2023 | TrojViT: Trojan Insertion in Vision TransformersabstractVision Transformers (ViTs) have demonstrated the state-of-the-art performance in various vision-related tasks. The success of ViTs motivates adversaries to perform back-door attacks on ViTs. Although the vulnerability of traditional CNNs to backdoor attacks is well-known, backdoor attacks on ViTs are seldom-studied. Compared to CNNs capturing pixel-wise local features by convolutions, ViTs extract global context information through patches and attentions. Naively transplanting CNN-specific backdoor attacks to ViTs yields only a low clean data accuracy and a low attack success rate. In this paper, we propose a stealth and practical ViT-specific backdoor attack TrojViT. Rather than an area-wise trigger used by CNN-specific backdoor attacks, TrojViT generates a patch-wise trigger designed to build a Trojan composed of some vulnerable bits on the parameters of a ViT stored in DRAM memory through patch salience ranking and attention-target loss. TrojViT further uses parameter distillation to reduce the bit number of the Trojan. Once the attacker inserts the Trojan into the ViT model by flipping the vulnerable bits, the ViT model still produces normal inference accuracy with benign inputs. But when the attacker embeds a trigger into an input, the ViT model is forced to classify the input to a predefined target class. We show that flipping only few vulnerable bits identified by TrojViT on a ViT model using the well-known RowHammer can transform the model into a backdoored one. We perform extensive experiments of multiple datasets on various ViT models. TrojViT can classify 99.64% of test images to a target class by flipping 345 bits on a ViT for ImageNet. Mengxin Zheng, Qian Lou, Lei Jiang 0001 |
CVPR | 1 |
| 2023 | Primer: Fast Private Transformer Inference on Encrypted DataabstractIt is increasingly important to enable privacy-preserving inference for cloud services based on Transformers. Post-quantum cryptographic techniques, e.g., fully homomorphic encryption (FHE), and multi-party computation (MPC), are popular methods to support private Transformer inference. However, existing works still suffer from prohibitively computational and communicational overhead. In this work, we present, Primer, to enable a fast and accurate Transformer over encrypted data for natural language processing tasks. In particular, Primer is constructed by a hybrid cryptographic protocol optimized for attention-based Transformer models, as well as techniques including computation merge and tokens-first ciphertext packing. Comprehensive experiments on encrypted language modeling show that Primer achieves state-of-the-art accuracy and reduces the inference latency by 90.6% ∼ 97.5% over previous methods. Mengxin Zheng, Qian Lou, Lei Jiang 0001 |
DAC | 1 |
| 2023 | TrojLLM: A Black-box Trojan Prompt Attack on Large Language ModelsabstractLarge Language Models (LLMs) are progressively being utilized as machine learning services and interface tools for various applications. However, the security implications of LLMs, particularly in relation to adversarial and Trojan attacks, remain insufficiently examined. In this paper, we propose TrojLLM, an automatic and black-box framework to effectively generate universal and stealthy triggers. When these triggers are incorporated into the input data, the LLMs' outputs can be maliciously manipulated. Moreover, the framework also supports embedding Trojans within discrete prompts, enhancing the overall effectiveness and precision of the triggers' attacks. Specifically, we propose a trigger discovery algorithm for generating universal triggers for various inputs by querying victim LLM-based APIs using few-shot data samples. Furthermore, we introduce a novel progressive Trojan poisoning algorithm designed to generate poisoned prompts that retain efficacy and transferability across a diverse range of models. Our experiments and results demonstrate TrojLLM's capacity to effectively insert Trojans into text prompts in real-world black-box LLM APIs including GPT-3.5 and GPT-4, while maintaining exceptional performance on clean test sets. Our work sheds light on the potential security risks in current models and offers a potential defensive approach. The source code of TrojLLM is available at https://github.com/UCF-ML-Research/TrojLLM. Mengxin Zheng, Ting Hua, Yilin Shen, Ladislau Bölöni, Qian Lou |
NeurIPS | 2 |