EDBT 2026 Demo / reviewers in the wild / expert
Cheng'an Wei
dblp:353/7546
· DBLP profile ↗
4ranked-venue papers
1as first author
4since 2021 · last 2025
0009-0002-7521-5164ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 1 first-author · 4 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SCOPE: Expanding Client-Side Post-Processing for Efficient Privacy-Preserving Model InferenceabstractPrivacy-Preserving Inference (PPI) enables users to leverage powerful machine learning models without revealing sensitive input data. However, existing state-of-the-art solutions remain impractical due to significant computation and communication overheads. Shenchen Zhu, Kai Chen 0012, Yue Zhao 0018, Cheng'an Wei |
CCS | 4 |
| 2025 | Adversarial Attack and Defense for Commercial Black-box Chinese-English Speech Recognition SystemsabstractThe attacker can generate adversarial examples (AEs) to stealthily mislead automatic speech recognition (ASR) models, raising significant concerns about the security of intelligent voice control (IVC) devices. Existing adversarial attacks mainly generate AEs to mislead ASR models to output specific target English commands (e.g., open the door). However, it remains unknown whether AEs can be used to issue commands in other languages to attack commercial black-box ASR models. In this article, taking Chinese phrases (e.g., 支付宝付款) and “Chinese–English code-switching” phrases (e.g., 关闭GPS) as the target commands, we propose adversarial attacks for commercial multilingual ASR models. In particular, if a multilingual speech recognition model can recognize Chinese and English, we call it a Chinese–English speech recognition model. In English, the meaning of “支付宝付款” and “关闭GPS” are “Alipay payment” and “turn off GPS”, respectively. In detail, we generate transferable AEs based on the open-sourced conventional DataTang Mandarin ASR model. Given 55 target commands, the success rate for generating AEs of them is up to 96% and 80% for Aliyun ASR API and Tencentyun ASR API, respectively. Our AEs can trigger actual attack actions on voice assistants (e.g., Apple Siri, Xiaomi Xiaoaitongxue) or spread malicious messages through ASR API services, while the target commands in the AEs are inaudible to human beings. 1 Finally, by analyzing the spectrum differences between benign audio clips and AEs, we propose a general defense against adversarial audio attacks. Xuejing Yuan, Jiangshan Zhang, Kai Chen 0012, Cheng'an Wei, Zhenkun Ma, Xinqi Ling |
ACM Trans. Priv. Secur. | 4 |
| 2024 | AE-Morpher: Improve Physical Robustness of Adversarial Objects against LiDAR-based Detectors via Object Reconstruction
Shenchen Zhu, Yue Zhao 0018, Kai Chen 0012, Hualong Ma, Cheng'an Wei |
USENIX Security Symposium | 6 |
| 2023 | Aliasing Backdoor Attacks on Pre-trained Models
Cheng'an Wei, Yeonjoon Lee, Kai Chen 0012, Guozhu Meng, Peizhuo Lv |
USENIX Security Symposium | 1 |