Ping Wang 0027

dblp:37/1304-27 · DBLP profile ↗
← Back
8ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0001-6192-6251ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Shadow model-guided class-label distribution inference and privacy assessment in personalized federated learning
abstract
Personalized federated learning (PFL) enables collaborative model training under heterogeneous client data by separating shared model components from personalized ones, but the uploaded shared-model updates may still reveal implicit knowledge about clients’ private data distributions. In this work, we study class-label distribution inference as a distributional knowledge reconstruction problem in PFL. We observe that updates of the shared model component encode label distribution information through their directional alignment with class-specific optimization trajectories, even when personalized parameters remain local. Based on this observation, we propose the S hadow M odel-guided class-label distribution I nference and privacy A ssessment ( SMIA ), a shadow model-guided geometric inference framework for assessing distributional privacy risks in personalized federated learning. Instead of relying on magnitude-sensitive parameter variations, SMIA characterizes the directional relationships between target-client shared updates and class-wise reference updates obtained from shadow models. These relationships are then organized into a Gram-matrix-induced geometric reconstruction system, where the client label distribution can be efficiently estimated through a closed-form solution. Extensive experiments on multiple vision and text datasets under diverse data distribution settings demonstrate that SMIA consistently outperforms prior methods across personalized federated learning scenarios. The results reveal that shared-model update directions can carry substantial distributional knowledge, highlighting the need to consider directional leakage when evaluating privacy risks in personalized federated learning systems.
Zhixuan Ma, Haichang Gao, Junxiang Huang, Ping Wang 0027
Neurocomputing4
2025 The Dark Side of Function Calling: Pathways to Jailbreaking Large Language Models
abstract
Large language models (LLMs) have demonstrated remarkable capabilities, but their power comes with significant security considerations. While extensive research has been conducted on the safety of LLMs in chat mode, the security implications of their function calling feature have been largely overlooked. This paper uncovers a critical vulnerability in the function calling process of LLMs, introducing a novel “jailbreak function” attack method that exploits alignment discrepancies, user coercion, and the absence of rigorous safety filters. Our empirical study, conducted on six state-of-the-art LLMs including GPT-4o, Claude-3.5-Sonnet, and Gemini-1.5-pro, reveals an alarming average success rate of over 90% for this attack. We provide a comprehensive analysis of why function calls are susceptible to such attacks and propose defensive strategies, including the use of defensive prompts. Our findings highlight the urgent need for enhanced security measures in the function calling capabilities of LLMs, contributing to the field of AI safety by identifying a previously unexplored risk, designing an effective attack method, and suggesting practical defensive measures
Zihui Wu, Haichang Gao, Jianping He 0008, Ping Wang 0027
COLING4
2024 Improving the Security of Audio CAPTCHAs With Adversarial Examples
abstract
CAPTCHAs (completely automated public Turing tests to tell computers and humans apart) have been the main protection against malicious attacks on public systems for many years. Audio CAPTCHAs, as one of the most important CAPTCHA forms, provide an effective test for visually impaired users. However, in recent years, most of the existing audio CAPTCHAs have been successfully attacked by machine learning-based audio recognition algorithms, showing their insecurity. In this article, a generative adversarial network (GAN)-based method is proposed to generate adversarial audio CAPTCHAs. This method is implemented by using a generator to synthesize noise, a discriminator to make it similar to the target and a threshold function to limit the size of the perturbation; then, the synthetic perturbation is combined with the original audio to generate the adversarial audio CAPTCHA. The experimental results demonstrate that the addition of adversarial examples can greatly reduce the recognition accuracy of automatic models and improve the robustness of different types of audio CAPTCHAs. We also explore ensemble learning strategies to improve the transferability of the proposed adversarial audio CAPTCHA methods. To investigate the effect of adversarial CAPTCHAs on human users, a user study is also conducted.
Ping Wang 0027, Haichang Gao, Zhongni Yuan, Jiawei Nian
IEEE Trans. Dependable Secur. Comput.1
2024 A Stability-Enhanced Dynamic Backdoor Defense in Federated Learning for IIoT
abstract
Federated learning (FL) systems enable collaborative model training among industrial Internet of Things (IIoT) devices but face significant security challenges, particularly in backdoor attacks, due to the nonindependent and identically distributed (non-IID) nature of data. To address this challenge, we propose a stability-enhanced dynamic backdoor defense approach in FL for IIoT, which maintains primary task accuracy while strengthening defenses in non-IID environments. Leveraging the similarity between data distribution and model updates, we segment non-IID scenarios into multiple quasi-IID environments. Our approach includes a dynamic client matching module, a malicious filtering module, and robust personalized aggregation to reduce the success rate of backdoor attacks while augmenting the resilience and precision of the aggregated model. The effectiveness of our strategy has been validated through analyses on the Modified National Institute of Standards and Technology database (MNIST), Canadian Institute for Advanced Research, 10 classes (CIFAR-10), Internet of Things (IoT)-23, and Washington University in St. Louis (WUSTL)-IIOT datasets in both IID and non-IID scenarios. Notably, on the IoT-23 and WUSTL-IIOT, the success rate of backdoor attacks was significantly reduced to 3.46%.
Zhixuan Ma, Haichang Gao, Shangwen Li, Ping Wang 0027
IEEE Trans. Ind. Informatics4
2023 Extended Research on the Security of Visual Reasoning CAPTCHA
abstract
CAPTCHA is an effective mechanism for protecting computers from malicious bots. With the development of deep learning techniques, current mainstream text-based and traditional image-based CAPTCHAs have been proven to be insecure. Therefore, a major effort has been directed toward developing new CAPTCHAs by utilizing some other hard Artificial Intelligence (AI) problems. Recently, some commercial companies (Tencent, NetEase, Geetest, etc.) have begun deploying a new type of CAPTCHA based on visual reasoning to defend against bots. As a newly proposed CAPTCHA, it is therefore natural to ask a fundamental question: are visual reasoning CAPTCHAs as secure as their designers expect? This paper explores the security of visual reasoning CAPTCHAs. We proposed a modular attack and evaluated it on six different real-world visual reasoning CAPTCHAs, which achieved overall success rates ranging from 79.2% to 98.6%. The results show that visual reasoning CAPTCHAs are not as secure as anticipated; this latest effort to use novel, hard AI problems for CAPTCHAs has not yet succeeded. Then, we summarize some guidelines for designing better visual-based CAPTCHAs, and based on the lessons we learned from our attacks, we propose a new CAPTCHA based on commonsense knowledge (CsCAPTCHA) and show its security and usability experimentally.
Ping Wang 0027, Haichang Gao, Chenxuan Xiao, Yipeng Gao, Yang Zi
IEEE Trans. Dependable Secur. Comput.1
2022 A deep learning-based attack on text CAPTCHAs by using object detection techniques
abstract
Abstract Text‐based CAPTCHAs have been widely deployed by many popular websites, and many have been attacked. However, most previous cracks were based on classification algorithms that typically rely on a series of preprocessing operations or on many training samples, thus making such attacks complicated and costly. In this study, a simple, generic, fast and end‐to‐end attack based on advanced object detection technologies is introduced. The proposed attack combines a feature extraction module, a character location and recognition module and a coordinate matching module. The experiments show that the attack can break a wide range of real‐world text CAPTCHAs deployed by the 50 most popular websites on Alexa.com and that the method achieves a high attack accuracy with only 2000 samples at an attack speed of less than 0.10 s. The attack was also evaluated on four click‐based CAPTCHAs that cannot be attacked in the end‐to‐end manner used by previous attacks, and the results demonstrated that within one step, the proposed approach achieves high success rates on both click‐based CAPTCHAs and schemes based on large‐scale character sets, such as Chinese character sets.
Jiawei Nian, Ping Wang 0027, Haichang Gao
IET Inf. Secur.2
2021 A Security Analysis of Captchas With Large Character Sets
abstract
Captcha, which can prevent computer programs from attacking websites, has been the most important security technology for many years. The most popularly deployed Captcha is the text-based scheme. The vast majority of the existing text Captchas are designed with English letters and Arabic numerals. Recently, text Captchas with large character sets are being increasingly popular. From the perspective of attackers, larger character set means greater solution space and better theoretical security. However, the security of Captchas with large character sets in real world has never been studied comprehensively. In this article, we introduce a simple, fast, and effective deep learning method to attack these newly emerging Captchas. Taking 11 Chinese Captchas as representatives, we ran our experimental attack on each of them. Our attack achieved high success rates, ranging from 34.7 to 86.9 percent at an average speed of 0.175 seconds on these schemes. All of the results show that the Chinese text Captcha can be easily broken, demonstrating that text Captchas with large character sets are also insecure in existing forms. As a substitute, we proposed a 3D image-based scheme combining semantic comprehension and dragging action. The preliminary experimental results show that it is more robust than current text-based schemes.
Ping Wang 0027, Haichang Gao, Qingxun Rao, Sainan Luo, Zhongni Yuan, Ziyu Shi
IEEE Trans. Dependable Secur. Comput.1
2018 Research on Deep Learning Techniques in Breaking Text-Based Captchas and Designing Image-Based Captcha
abstract
The ability of hackers to infiltrate computer systems using computer attack programs and bots led to the development of Captchas or Completely Automated Public Turing Tests to Tell Computers and Humans Apart. The text Captcha is the most popular Captcha scheme given its ease of construction and user friendliness. However, the next generation of hackers and programmers has decreased the expected security of these mechanisms, leaving websites open to attack. Text Captchas are still widely used, because it is believed that the attack speeds are slow, typically two to five seconds per image, and this is not seen as a critical threat. In this paper, we introduce a simple, generic, and fast attack on text Captchas that effectively challenges that supposition. With deep learning techniques, our attack demonstrates a high success rate in breaking the Roman-character-based text Captchas deployed by the top 50 most popular international websites and three Chinese Captchas that use a larger character set. These targeted schemes cover almost all existing resistance mechanisms, demonstrating that our attack techniques are also applicable to other existing Captchas. Does this work then spell the beginning of the end for text-based Captcha? We believe so. A novel image-based Captcha named Style Area Captcha (SACaptcha) is proposed in this paper, which is based on semantic information understanding, pixel-level segmentation, and deep learning techniques. Having demonstrated that text Captchas are no longer secure, we hope that our proposal shows promise in the development of image-based Captchas using deep learning techniques.
Mengyun Tang, Haichang Gao, Yi Liu 0042, Ping Wang 0027
IEEE Trans. Inf. Forensics Secur.6