EDBT 2026 Demo / reviewers in the wild / expert
Tu Ouyang
dblp:34/7446
· DBLP profile ↗
6ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0002-5432-5391ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 1 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | EASE: Practical and Efficient Safety Alignment for Small Language ModelsabstractSmall language models (SLMs) are increasingly deployed on edge devices, making their safety alignment crucial yet challenging. Current shallow alignment methods that rely on direct refusal of malicious queries fail to provide robust protection, particularly against adversarial jailbreaks. While deliberative safety reasoning alignment offers deeper alignment for defending against sophisticated attacks, effectively implanting such reasoning capability in SLMs with limited capabilities remains an open challenge. Moreover, safety reasoning incurs significant computational overhead as models apply reasoning to nearly all queries, making it impractical for resource-constrained edge deployment scenarios that demand rapid responses. We propose EASE, a novel framework that enables practical and Efficient safety Alignment for Small languagE models. Our approach first identifies the optimal safety reasoning teacher that can effectively distill safety reasoning capabilities to SLMs. We then align models to selectively activate safety reasoning for dangerous adversarial jailbreak queries while providing direct responses to straightforward malicious queries and general helpful tasks. This selective mechanism enables small models to maintain robust safety guarantees against sophisticated attacks while preserving computational efficiency for benign interactions. Experimental results demonstrate that EASE reduces jailbreak attack success rates by up to 17% compared to shallow alignment methods while reducing inference overhead by up to 90% compared to deliberative safety reasoning alignment, making it practical for SLMs real-world edge deployments. Haonan Shi 0002, Tu Ouyang, An Wang 0002 |
AAAI | 3 |
| 2025 | Poster: Measuring Algorithmic Systems' Resilience Against Generative AI-Powered Attacks - Case Study on Exploiting a Code Search PlatformabstractGenerative AI applications have boomed since the GPT-3-powered ChatGPT release in 2022. Miscreants also see the opportunities of leveraging these frontier GenAI technologies to facilitate cyberattacks, from planning to execution. Nathaniel Hahn, Tu Ouyang, An Wang 0002 |
IMC | 2 |
| 2025 | Unveiling Client Privacy Leakage from Public Dataset Usage in Federated DistillationabstractFederated Distillation (FD) has emerged as a popular federated training framework, enabling clients to collaboratively train models without sharing private data. Public Dataset-Assisted Federated Distillation (PDA-FD), which leverages public datasets for knowledge sharing, has become widely adopted. Although PDA-FD enhances privacy compared to traditional Federated Learning, we demonstrate that the use of public datasets still poses significant privacy risks to clients' private training data. This paper presents the first comprehensive privacy analysis of PDA-FD in the presence of an honest-but-curious server. We show that the server can exploit clients' inference results on public datasets to extract two critical types of private information: label distributions and membership information of the private training dataset. To quantify these vulnerabilities, we introduce two novel attacks specifically designed for the PDA-FD setting: a label distribution inference attack and innovative membership inference methods based on Likelihood Ratio Attack (LiRA). Through extensive evaluation of three representative PDA-FD frameworks (FedMD, DS-FL, and Cronus), our attacks achieve state-of-the-art performance, with label distribution attacks reaching minimal KL-divergence and membership inference attacks maintaining high True Positive Rates under low False Positive Rate constraints. Our findings reveal significant privacy risks in current PDA-FD frameworks and emphasize the need for more robust privacy protection mechanisms in collaborative learning systems. Haonan Shi 0002, Tu Ouyang, An Wang 0002 |
Proc. Priv. Enhancing Technol. | 2 |
| 2024 | Learning-Based Difficulty Calibration for Enhanced Membership Inference AttacksabstractMachine learning models, in particular deep neural networks, are currently an integral part of various applications, from healthcare to finance. However, using sensitive data to train these models raises concerns about privacy and security. One method that has emerged to verify if the trained models are privacy-preserving is Membership Inference Attacks (MIA), which allows adversaries to determine whether a specific data point was part of a model's training dataset. While a series of MIAs have been proposed in the literature, only a few can achieve high True Positive Rates (TPR) in the low False Positive Rate (FPR) region (0.01% ~ 1%). This is a crucial factor to consider for an MIA to be practically useful in real-world settings. In this paper, we present a novel approach to MIA that is aimed at significantly improving TPR at low FPRs. Our method, named learning-based difficulty calibration for MIA (LDC-MIA), characterizes data records by their hardness levels using a neural network classifier to determine membership. The experiment results show that LDC-MIA can improve TPR at low FPR by up to 4x compared to the other difficulty calibration-based MIAs. It also has the highest Area Under ROC curve (AUC) across all datasets. Our method's cost is comparable with most of the existing MIAs, but is orders of magnitude more efficient than one of the state-of-the-art methods, LiRA, while achieving similar performance. Haonan Shi 0002, Tu Ouyang, An Wang 0002 |
EuroS&P | 2 |
| 2014 | A large-scale empirical analysis of email spam detection through network characteristics in a stand-alone enterprise
Tu Ouyang, Soumya Ray, Mark Allman, Michael Rabinovich |
Comput. Networks | 1 |
| 2011 | Can Network Characteristics Detect Spam Effectively in a Stand-Alone Enterprise?
Tu Ouyang, Soumya Ray, Michael Rabinovich, Mark Allman |
PAM | 1 |