EDBT 2026 Demo / reviewers in the wild / expert
Xiaohang Sui
dblp:378/3928
· DBLP profile ↗
3ranked-venue papers
0as first author
3since 2021 · last 2026
0009-0002-3653-5894ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Privacy and data protection · 64% Security and privacy of machine learning · 36% | |
| Computer graphics and multimedia
1 paper |
Image and video coding · 77% Computational photography and imaging · 23% | |
| Artificial intelligence
2 papers |
Generative modeling · 54% Efficient and distributed learning · 46% |
Topics — the 6 heaviest of 7, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Security and privacy of machine learning › adversarial attack
backdoor attack |
1.0 | 1 | 2026 | Retrievals Can Be Detrimental: Unveiling the Backdoor Vulnerability of Retrieval-Augmented Diffusion Models · ACL (1) 2026 |
Privacy and data protection › privacy-preserving machine learning
federated learning privacy |
0.9 | 1 | 2025 | GI-NAS: Boosting Gradient Inversion Attacks Through Adaptive Neural Architecture Search · IEEE Trans. Inf. Forensics Secur. 2025 |
Privacy and data protection › privacy-preserving machine learning › federated learning privacy
gradient inversion attack |
0.9 | 1 | 2025 | GI-NAS: Boosting Gradient Inversion Attacks Through Adaptive Neural Architecture Search · IEEE Trans. Inf. Forensics Secur. 2025 |
Machine learning › Generative modeling
diffusion model |
0.3 | 1 | 2026 | Retrievals Can Be Detrimental: Unveiling the Backdoor Vulnerability of Retrieval-Augmented Diffusion Models · ACL (1) 2026 |
Machine learning › Efficient and distributed learning › automated machine learning
neural architecture search |
0.3 | 1 | 2025 | GI-NAS: Boosting Gradient Inversion Attacks Through Adaptive Neural Architecture Search · IEEE Trans. Inf. Forensics Secur. 2025 |
Computational photography and imaging
omnidirectional imaging |
0.2 | 1 | 2024 | Learning Content-Weighted Pseudocylindrical Representation for 360° Image Compression · IEEE Trans. Image Process. 2024 |
Methods — techniques the papers use, named apart from their topics
retrieval-augmented diffusion models · 2.0neural architecture search · 1.7gradient inversion · 1.7rate-distortion optimization · 0.8pseudocylindrical representation · 0.8meta-learning · 0.8content-adaptive sampling · 0.8
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Retrievals Can Be Detrimental: Unveiling the Backdoor Vulnerability of Retrieval-Augmented Diffusion ModelsabstractHao Fang, Xiaohang Sui, Hongyao Yu, Kuofeng Gao, Jiawei Kong, Sijin Yu, Bin Chen, Shu-Tao Xia. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Hao Fang 0011, Xiaohang Sui, Hongyao Yu, Kuofeng Gao, Jiawei Kong 0001, Sijin Yu, Bin Chen 0011, Shutao Xia |
ACL (1) | 2 |
| 2025 | GI-NAS: Boosting Gradient Inversion Attacks Through Adaptive Neural Architecture SearchabstractGradient Inversion Attacks invert the transmitted gradients in Federated Learning (FL) systems to reconstruct the sensitive data of local clients and have raised considerable privacy concerns. A majority of gradient inversion methods rely heavily on explicit prior knowledge (e.g., a well pre-trained generative model), which is often unavailable in realistic scenarios. This is because real-world client data distributions are often highly heterogeneous, domain-specific, and unavailable to attackers, making it impractical for attackers to obtain perfectly matched pre-trained models, which inevitably suffer from fundamental distribution shifts relative to target private data. To alleviate this issue, researchers have proposed to leverage the implicit prior knowledge of an over-parameterized network. However, they only utilize a fixed neural architecture for all the attack settings. This would hinder the adaptive use of implicit architectural priors and consequently limit the generalizability. In this paper, we further exploit such implicit prior knowledge by proposing Gradient Inversion via Neural Architecture Search (GI-NAS), which adaptively searches the network and captures the implicit priors behind neural architectures. Extensive experiments verify that our proposed GI-NAS can achieve superior attack performance compared to state-of-the-art gradient inversion methods, even under more practical settings with high-resolution images, large-sized batches, and advanced defense strategies. To the best of our knowledge, we are the first to successfully introduce NAS to the gradient inversion community. We believe that this work exposes critical vulnerabilities in real-world federated learning by demonstrating high-fidelity reconstruction of sensitive data without requiring domain-specific priors, forcing urgent reassessment of FL privacy safeguards. Hao Fang 0011, Bin Chen 0011, Xiaohang Sui, Chuan Chen 0001, Shutao Xia, Ke Xu 0002 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Learning Content-Weighted Pseudocylindrical Representation for 360° Image CompressionabstractLearned 360° image compression methods using equirectangular projection (ERP) often confront a non-uniform sampling issue, inherent to sphere-to-rectangle projection. While uniformly or nearly uniformly sampling representations, along with their corresponding convolution operations, have been proposed to mitigate this issue, these methods often concentrate solely on uniform sampling rates, thus neglecting the content of the image. In this paper, we urge that different contents within 360° images have varying significance and advocate for the adoption of a content-adaptive parametric representation in 360° image compression, which takes into account both the content and sampling rate. We first introduce the parametric pseudocylindrical representation and corresponding convolution operation, upon which we build a learned 360° image codec. Then, we model the hyperparameter of the representation as the output of a network, derived from the image's content and its spherical coordinates. We treat the optimization of hyperparameters for different 360° images as distinct compression tasks and propose a meta-learning algorithm to jointly optimize the codec and the metaknowledge, i.e., the hyperparameter estimation network. A significant challenge is the lack of a direct derivative from the compression loss to the hyperparameter network. To address this, we present a novel method to relax the rate-distortion loss as a function of the hyperparameters, enabling gradient-based optimization of the metaknowledge. Experimental results on omnidirectional images demonstrate that our method achieves state-of-the-art performance and superior visual quality. Mu Li 0005, Youneng Bao, Xiaohang Sui, Jinxing Li 0003, Guangming Lu 0002, Yong Xu 0001 |
IEEE Trans. Image Process. | 3 |