Meng Xue 0001

dblp:34/6611-1 · DBLP profile ↗
← Back
9ranked-venue papers
2as first author
9since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 1 first-author · 5 since 2021Computer networks · 4 · 1 first-author · 4 since 2021
YearPublicationVenuePosition
2026 Megatron: Evasive Clean-Label Backdoor Attacks Against Vision Transformer
abstract
Vision transformers have achieved impressive performance in various vision-related tasks, but their vulnerability to backdoor attacks is under-explored. A handful of existing works focus on dirty-label attacks with wrongly-labeled poisoned training samples, which may fail if a benign model trainer corrects the labels. In this paper, we proposeMegatron, an evasive clean-label backdoor attack against vision transformers, where the attacker injects the backdoor without manipulating the data-labeling process. To generate an effective trigger, we employ a local surrogate vision transformer to approximate the victim model and customize two attention-based loss terms: latent loss and attention diffusion loss. The latent loss aligns the last attention layer between triggered samples and clean samples of the target label. The attention diffusion loss emphasizes the attention diffusion area that encompasses the trigger. A theoretical analysis is provided to underpin the rationale behind the attention diffusion loss. Extensive experiments on CIFAR-10, GTSRB, CIFAR-100, and Tiny ImageNet demonstrate the effectiveness ofMegatron.Megatroncan achieve attack success rates of over 90% even when the position of the trigger is slightly shifted during testing. Furthermore,Megatronachieves better evasiveness than baselines regarding both human visual inspection and defense strategies (i.e., DBAVT, BAVT, Beatrix, TeCo, and SAGE).
Xueluan Gong, Bowei Tian, Meng Xue 0001, Shuaike Li, Yanjiao Chen, Qian Wang 0002
IEEE Trans. Dependable Secur. Comput.3
2025 Home-based Dry Eye Assessment via Blink Kinematics Using mmWave and Clinical Knowledge Distillation
abstract
Tear Film Break-Up Time (TBUT) is a critical clinical parameter in the management of dry eye disease (DED). However, traditional TBUT assessments rely on costly and time-consuming clinical procedures, while existing home-based solutions fail to provide precise TBUT values. In this work, we present Blinic, a contactless system leveraging commercial millimeter-wave (mmWave) radar to predict precise TBUT values and assess DED severity grades at home. Blinic incorporates detailed blink kinematics that are closely linked to TBUT. To address the challenge of predicting TBUT directly from radar data, we propose a teacher-student learning framework. The teacher model, trained on electronic health records (EHRs) including image-based diagnostic tests, transfers medical insights to the student model, which uses radar-captured blink dynamics. This knowledge transfer is further enhanced by a fine-tuned large language model, DryEye-LLM, which is based on clinical diagnostic reports and employs unsupervised domain adaptation to align EHRs with radar data. To ensure accurate blink motion capture, Blinic employs an antenna-coded MIMO mmWave radar design. Additionally, a query-based multitask learning module simultaneously predicts TBUT and DED severity grades, addressing potential conflicts in feature representation. Evaluated on 192 participants in collaboration with an eye clinic, Blinic demonstrates achieving a mean absolute error of 2.73 seconds for TBUT with an average accuracy of 90.54% for DED grading in real-world settings, providing a practical solution for home-based DED management.
Meng Xue 0001, Wentao Xie 0001, Zuohuizi Yi, Shumao Wu, Yinan Zhu, Qian Zhang 0001
MobiCom1
2025 DD-LIVM: Pioneering Cross-Domain Photovoltaic Defect Detection Using Large Infrared-Visible Model
abstract
Photovoltaic (PV) defect detection is crucial for preventing power efficiency loss and fire hazards. The industry primarily relies on the fusion of infrared and visible images for defect localization and diagnosis. However, current detection methods exhibit poor generalizability in new site environments or with altered imaging setups. While recent infrared and vision foundation models (FM) facilitate domain-invariant feature maps extraction, directly concatenating them and fine-tuning achieves limited generalizability gain to PV defect detection, due to the asymmetric dual-modal semantics of defects. In this paper, we present the first large infrared-visible model DD-LIVM to enable cross-domain defect detection. The key innovation of DD-LIVM lies in its defect-specific three-step fine-tuning strategy, which utilizes alternating modality masking. Prior to feature fusion and joint fine-tuning, the infrared and visible FM encoders are alternately masked and optimized to enhance their individual semantic utility for defect localization visibility and classification granularity, with feature distances among different defect types regulated through contrastive learning. This approach allows for the extraction of generalizable and defect-specific feature maps. Moreover, for practical employment of DD-LIVM, we propose a domain-agnostic spatial alignment algorithm for infrared-visible images before dual-modal fusion, and develop source data augmentation and adaptive detection head selection schemes based on defects' infrared characteristics to further enhance the generalizability. Extensive experiments on 7,078 dual-modal images from 9 real-world scenarios across 4 cities' PV stations demonstrate that DD-LIVM achieves an accuracy of 87.7% for cross-domain defect detection, surpassing state-of-the-art methods by 17.3%.
Yinan Zhu, Meng Xue 0001, Haiyan Hu 0003, Cong Zhang 0002, Xiaoyi Fan 0001, Qian Zhang 0001
MobiCom2
2025 An Effective and Resilient Backdoor Attack Framework Against Deep Neural Networks and Vision Transformers
abstract
Recent studies have revealed the vulnerability of Deep Neural Network (DNN) models to backdoor attacks. However, existing backdoor attacks arbitrarily set the trigger mask or use a randomly selected trigger, which restricts the effectiveness and robustness of the generated backdoor triggers. In this paper, we propose a novel attention-based mask generation methodology that searches for the optimal trigger shape and location. We also introduce a Quality-of-Experience (QoE) term into the loss function and carefully adjust the transparency value of the trigger in order to make the backdoored samples to be more natural. To further improve the prediction accuracy of the victim model, we propose an alternating retraining algorithm in the backdoor injection process. The victim model is retrained with mixed poisoned datasets in even iterations and with only benign samples in odd iterations. Besides, we launch the backdoor attack under a co-optimized attack framework that alternately optimizes the backdoor trigger and backdoored model to further improve the attack performance. Apart from DNN models, we also extend our proposed attack method against vision transformers. We evaluate our proposed method with extensive experiments on VGG-Flower, CIFAR-10, GTSRB, CIFAR-100, and ImageNette datasets. It is shown that we can increase the attack success rate by as much as 82% over baselines when the poison ratio is low and achieve a high QoE of the backdoored samples. Our proposed backdoor attack framework also showcases robustness against state-of-the-art backdoor defenses.
Xueluan Gong, Bowei Tian, Meng Xue 0001, Yuan Wu 0007, Yanjiao Chen, Qian Wang 0002
IEEE Trans. Dependable Secur. Comput.3
2025 Artemis: Defending Against Backdoor Attacks via Distribution Shift
abstract
Backdoor attacks can exploit vulnerabilities in the training process of Deep Neural Networks (DNNs), introducing hidden malicious functionality that can be activated by a specific input pattern. Existing defenses typically rely on the assumption of a significant difference between poisoned and clean samples. However, subtle differences in dynamic and low poisoning ratio attacks can conceal poisoning features, thereby evading defenses. In this work, we propose a novel backdoor defense approach calledArtemis, which utilizes distribution shifts to eliminate the discrepancy between poisoned and benign samples in the feature space. Additionally,Artemislearns from domain-invariant features after the shift. To further enhance the purification of backdoors in DNNs, we incorporate soft knowledge distillation intoArtemisto guide the alignment of features between the source dataset domain and the generated distribution-shift dataset domain. We extensively compare our proposed method with 5 state-of-the-art (SOTA) defensive techniques under 9 SOTA attacks on 4 datasets to demonstrate its effectiveness and robustness. Our results show that our method,Artemis, can successfully purify dynamic and low poisoning ratio backdoor attacks and outperform existing defenses by a significant margin. We release the code athttps://github.com/xmyun/Artemis.
Meng Xue 0001, Zhixian Wang, Qian Zhang 0001, Xueluan Gong, Yanjiao Chen
IEEE Trans. Dependable Secur. Comput.1
2023 D-DAE: Defense-Penetrating Model Extraction Attacks
abstract
Recent studies show that machine learning models are vulnerable to model extraction attacks, where the adversary builds a substitute model that achieves almost the same performance of a black-box victim model simply via querying the victim model. To defend against such attacks, a series of methods have been proposed to disrupt the query results before returning them to potential attackers, greatly degrading the performance of existing model extraction attacks.In this paper, we make the first attempt to develop a defense-penetrating model extraction attack framework, named D-DAE, which aims to break disruption-based defenses. The linchpins of D-DAE are the design of two modules, i.e., disruption detection and disruption recovery, which can be integrated with generic model extraction attacks. More specifically, after obtaining query results from the victim model, the disruption detection module infers the defense mechanism adopted by the defender. We design a meta-learning-based disruption detection algorithm for learning the fundamental differences between the distributions of disrupted and undisrupted query results. The algorithm features a good generalization property even if we have no access to the original training dataset of the victim model. Given the detected defense mechanism, the disruption recovery module tries to restore a clean query result from the disrupted query result with well-designed generative models. Our extensive evaluations on MNIST, FashionMNIST, CIFAR-10, GTSRB, and ImageNette datasets demonstrate that D-DAE can enhance the substitute model accuracy of the existing model extraction attacks by as much as 82.24% in the face of 4 state-of-the-art defenses and combinations of multiple defenses. We also verify the effectiveness of D-DAE in penetrating unknown defenses in real-world APIs hosted by Microsoft Azure and Face++.
Yanjiao Chen, Xueluan Gong, Jianshuo Dong, Meng Xue 0001
SP5
2023 DDS: An Auction Based on a Variant of Data Shapley for Federated Learning
abstract
Federated learning (FL) has received great attention in recent years due to its good performance and privacy security. However, there are still some problems in FL, such as resource allocation, client selection and incentive mechanism. Auctions, as an incentive mechanism with many advantages, solve these problems well. In this paper, we propose DDS, a lightweight and effective method to evaluate the data value for the scenario of federated learning. Based on DDS, we can pick up clients with high training value with low calculation cost. Furthermore, our method is independent of data aggregation, which makes it possible to implement in federated learning. We also conduct the simulation experiments to demonstrate the effectiveness and robustness of our method.
Hanlei Zhang, Meng Xue 0001, Yanjiao Chen
WCNC2
2023 Kaleidoscope: Physical Backdoor Attacks Against Deep Neural Networks With RGB Filters
abstract
Recent research has shown that deep neural networks are vulnerable to backdoor attacks. A carefully-designed backdoor trigger will mislead the victim model to misclassify any sample with the trigger to the target label. Nevertheless, existing works usually utilize visible triggers, such as a white square at the corner of the image, which are easily detected by human inspections. Current efforts on developing invisible triggers yield low attack success in the physical domain. In this paper, we propose Kaleidoscope, an RGB (red, green, and blue) filter-based backdoor attack method, which utilizes RGB filter operations as the backdoor trigger. To enhance the attack success rate, we design a novel model-dependent filter trigger generation algorithm. We also introduce two constraints in the loss function to make the backdoored samples more natural and less distorted. Extensive experiments on CIFAR-10, CIFAR-100, ImageNette, and VGG-Flower have demonstrated that RGB filter-processed samples not only achieve high attack success rate but also are unnoticeable to humans. It is shown that Kaleidoscope can reach an attack success rate of more than 84% in the physical world under different lighting intensities and shooting angles. Kaleidoscope is also shown to be robust to state-of-the-art backdoor defenses, such as spectral signature, STRIP, and MNTD.
Xueluan Gong, Yanjiao Chen, Meng Xue 0001, Qian Wang 0002, Chao Shen 0001
IEEE Trans. Dependable Secur. Comput.4
2022 DetectDUI: An In-Car Detection System for Drink Driving and BACs
abstract
As one of the biggest contributors to road accidents and fatalities, drink driving is worthy of significant research attention. However, most existing systems on detecting or preventing drink driving either require special hardware or require much effort from the user, making these systems inapplicable to continuous drink driving monitoring in a real driving environment. In this paper, we presentDetectDUI, a contactless, non-invasive, real-time system that yields a relatively highly accurate drink driving monitoring by combining vital signs (heart rate and respiration rate) extracted from in-car WiFi system and driver’s psychomotor coordination through steering wheel operations. The framework consists of a series of signal processing algorithms for extracting clean and informative vital signs and psychomotor coordination, and integrate the two data streams using a self-attention convolutional neural network (i.e., C-Attention). In safe laboratory experiments with 15 participants,DetectDUIachieves drink driving detection accuracy of 96.6% and BAC predictions with an average mean error of$2\sim 5mg/dl$. These promising results provide a highly encouraging case for continued development.
Yanjiao Chen, Meng Xue 0001, Jian Zhang 0010, Runmin Ou, Qian Zhang 0001, Peng Kuang
IEEE/ACM Trans. Netw.2