Cheng'an Wei

dblp:353/7546 · DBLP profile ↗
← Back
4ranked-venue papers
1as first author
4since 2021 · last 2025
0009-0002-7521-5164ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021
YearPublicationVenuePosition
2025 SCOPE: Expanding Client-Side Post-Processing for Efficient Privacy-Preserving Model Inference
abstract
Privacy-Preserving Inference (PPI) enables users to leverage powerful machine learning models without revealing sensitive input data. However, existing state-of-the-art solutions remain impractical due to significant computation and communication overheads.
Shenchen Zhu, Kai Chen 0012, Yue Zhao 0018, Cheng'an Wei
CCS4
2025 Adversarial Attack and Defense for Commercial Black-box Chinese-English Speech Recognition Systems
abstract
The attacker can generate adversarial examples (AEs) to stealthily mislead automatic speech recognition (ASR) models, raising significant concerns about the security of intelligent voice control (IVC) devices. Existing adversarial attacks mainly generate AEs to mislead ASR models to output specific target English commands (e.g., open the door). However, it remains unknown whether AEs can be used to issue commands in other languages to attack commercial black-box ASR models. In this article, taking Chinese phrases (e.g., 支付宝付款) and “Chinese–English code-switching” phrases (e.g., 关闭GPS) as the target commands, we propose adversarial attacks for commercial multilingual ASR models. In particular, if a multilingual speech recognition model can recognize Chinese and English, we call it a Chinese–English speech recognition model. In English, the meaning of “支付宝付款” and “关闭GPS” are “Alipay payment” and “turn off GPS”, respectively. In detail, we generate transferable AEs based on the open-sourced conventional DataTang Mandarin ASR model. Given 55 target commands, the success rate for generating AEs of them is up to 96% and 80% for Aliyun ASR API and Tencentyun ASR API, respectively. Our AEs can trigger actual attack actions on voice assistants (e.g., Apple Siri, Xiaomi Xiaoaitongxue) or spread malicious messages through ASR API services, while the target commands in the AEs are inaudible to human beings. 1 Finally, by analyzing the spectrum differences between benign audio clips and AEs, we propose a general defense against adversarial audio attacks.
Xuejing Yuan, Jiangshan Zhang, Kai Chen 0012, Cheng'an Wei, Zhenkun Ma, Xinqi Ling
ACM Trans. Priv. Secur.4
2024 AE-Morpher: Improve Physical Robustness of Adversarial Objects against LiDAR-based Detectors via Object Reconstruction
Shenchen Zhu, Yue Zhao 0018, Kai Chen 0012, Hualong Ma, Cheng'an Wei
USENIX Security Symposium6
2023 Aliasing Backdoor Attacks on Pre-trained Models
Cheng'an Wei, Yeonjoon Lee, Kai Chen 0012, Guozhu Meng, Peizhuo Lv
USENIX Security Symposium1