EDBT 2026 Demo / reviewers in the wild / expert
Luoyu Chen
dblp:330/7213
· DBLP profile ↗
8ranked-venue papers
4as first author
8since 2021 · last 2026
0009-0001-5746-9817ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Pixel-Depth Prototypical Knowledge Consolidation Network for Deepfake Detection
Ahmed Asiri, Weiqi Wang 0003, Luoyu Chen, Shui Yu 0001 |
ACISP (2) | 4 |
| 2026 | Ellipsoid Control: A White-List Jailbreak Defense via Benign Latent Modeling
Luoyu Chen, Weiqi Wang 0003, Zhiyi Tian, Ahmed Asiri, Shui Yu 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | MG-Det: Deepfake Detection with Multi-granularity
Ahmed Asiri, Luoyu Chen, Zhiyi Tian, Shui Yu 0001 |
ACISP (3) | 2 |
| 2025 | Zero-shot neural architecture search with weighted response correlation
Kun Jing, Luoyu Chen, Jungang Xu, Jianwei Tai, Shuaimin Li |
Neurocomputing | 2 |
| 2025 | Backdoored Sample Cleansing for Unlabeled Datasets via Bootstrapped Dual Set PurificationabstractSelf-Supervised Learning (SSL) excels in utilizing unlabeled data for feature representation learning. However, recent studies have revealed that SSL is vulnerable to data poisoning-based backdoor attacks. To remove backdoored samples from the SSL training dataset, model optimization methods often fine-tune a trained model by contrasting the training dataset with a reserved clean dataset. This contrastive training effectively marginalizes backdoored samples from the distribution of benign ones,if and only ifboth the reserved clean dataset and the training dataset are from the same data distribution. However, presuming identical distributions between the web-scraped data and reserved data is impractical. To address this impractical assumption, our proposed Bootstrapped Dual SetPurification (AUTO) method distinguishes backdoored from benign samples by contrasting a mined ‘positive set’ and a mined ‘negative set’ within the training dataset itself. We exploit the resistance of backdoored samples in data mixing to mine a highly poisoned ‘positive set’ and a minimally poisoned ‘negative set’. Besides, AUTO mitigates unstable detection performance within different optimization steps by continuously refining the dual sets by the optimized model, enhancing the model's poison distinguishability from consistently improving supervision signals. Our extensive experiments on Cifar10, Cifar100, and Imagenet100 against existing data poisoning SSL backdoor attacks demonstrate AUTO's superiority in detection performance over all existing defenses. Luoyu Chen, Weiqi Wang 0003, Zhiyi Tian, Chenhan Zhang, Shui Yu 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | A Mutation-Based Method for Backdoored Sample Detection Without Clean DataabstractBackdoor attacks significantly threaten machine learning-based vision systems. Existing detection methods typically require clean data from a similar distribution as the dataset under inspection, limiting practical deployment. This work proposes a Mutation-Based Method (MBM) for detecting and filtering backdoored samples in image training dataset, without referencing any external clean data. MBM aims at distinguishing backdoored and benign samples distribution via their distinct stability in feature space under certain data augmentations. Firstly, MBM applies multiple data augmentation techniques, generating mutated versions of each sample to ‘deactivate’ potential triggers while maintaining natural semantics not heavily distorted. Secondly, MBM measures how sample features diverge after mutating from its origin as poison score, which we call ‘Feature Stability’. Thirdly, by analyzing extreme scores within each class, MBM effectively identifies the backdoored class, and isolates samples not from backdoored class as clean data. Finally, a benign distribution is fit to benchmark against backdoored samples from backdoored class. We validated MBM on the CIFAR-10 dataset, achieving a true positive rate above 95% and a false positive rate below 0.2% for all defense settings. Our results confirm MBM’s efficacy without reliance on external clean data. Luoyu Chen, Tao Zhang 0165, Ahmed Asiri, Weiqi Wang 0003, Shui Yu 0001 |
GLOBECOM | 1 |
| 2023 | An architecture entropy regularizer for differentiable neural architecture search
Kun Jing, Luoyu Chen, Jungang Xu |
Neural Networks | 2 |
| 2022 | A Graph Architecture Search Method Based On Grouped OperationsabstractGraph data is ubiquitous in the real world and graph neural networks (GNNs) are effective for modeling the complex relationships and dependencies between the entities. However, it's difficult to design data-specific GNNs. Recently, researchers have started to apply neural architecture search (NAS) to design GNNs. In this work, we propose a graph architecture search method to decrease the instability with a large number of candidate operations. Following SANE(Search to Aggregate NEighborhood), we focus on searching to aggregate neighbourhoods but we divide the candidate operations into groups. We use a continuous relaxation of our search space and optimize the hyper-networks with a gradient-based algorithm. Extensive experiments on several node-level and graph-level tasks demonstrate that our method achieves a promising performance. Luoyu Chen, Jungang Xu, Kun Jing, Yingfei Sun |
IJCNN | 1 |