EDBT 2026 Demo / reviewers in the wild / expert
Yingkai Dong
dblp:384/6494
· DBLP profile ↗
4ranked-venue papers
2as first author
4since 2021 · last 2025
0009-0001-6245-1240ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | DCMI: A Differential Calibration Membership Inference Attack Against Retrieval-Augmented GenerationabstractWhile Retrieval-Augmented Generation (RAG) effectively reduces hallucinations by integrating external knowledge bases, it introduces vulnerabilities to membership inference attacks (MIAs), particularly in systems handling sensitive data. Existing MIAs targeting RAG's external databases often rely on model responses but ignore the interference of non-member-retrieved documents on RAG outputs, limiting their effectiveness. To address this, we propose DCMI, a differential calibration MIA that mitigates the negative impact of non-member-retrieved documents. Specifically, DCMI leverages the sensitivity gap between member and non-member retrieved documents under query perturbation. It generates perturbed queries for calibration to isolate the contribution of member-retrieved documents while minimizing the interference from non-member-retrieved documents. Experiments under progressively relaxed assumptions show that DCMI consistently outperforms baselines—for example, achieving 97.42% AUC and 94.35% Accuracy against the RAG system with Flan-T5, exceeding the MBA baseline by over 40%. Furthermore, on real-world RAG platforms such as Dify and MaxKB, DCMI maintains a 10%-20% advantage over the baseline. These results highlight significant privacy risks in RAG systems and emphasize the need for stronger protection mechanisms. We appeal to the community's consideration of deeper investigations, like ours, against the data leakage risks in rapidly evolving RAG systems. Xiangtao Meng, Yingkai Dong, Zheng Li 0023, Shanqing Guo |
CCS | 3 |
| 2025 | Fuzz-Testing Meets LLM-Based Agents: An Automated and Efficient Framework for Jailbreaking Text-to-Image Generation ModelsabstractText-to-image (T2I) generative models have revolutionized content creation by transforming textual descriptions into high-quality images. However, these models are vulnerable to jailbreaking attacks, where carefully crafted prompts bypass safety mechanisms to produce unsafe content. While researchers have developed various jailbreak attacks to expose this risk, these methods face significant limitations, including impractical access requirements, easily detectable unnatural prompts, restricted search spaces, and high query demands on the target system. In this paper, we propose JailFuzzer, a novel fuzzing framework driven by large language model (LLM) agents, designed to efficiently generate natural and semantically meaningful jailbreak prompts in a black-box setting. Specifically, JailFuzzer employs fuzz-testing principles with three components: a seed pool for initial and jailbreak prompts, a guided mutation engine for generating meaningful variations, and an oracle function to evaluate jailbreak success. Furthermore, we construct the guided mutation engine and oracle function by LLM-based agents, which further ensures efficiency and adaptability in black-box settings. Extensive experiments demonstrate that JailFuzzer has significant advantages in jailbreaking T2I models. It generates natural and semantically coherent prompts, reducing the likelihood of detection by traditional defenses. Additionally, it achieves a high success rate in jailbreak attacks with minimal query overhead, outperforming existing methods across all key metrics. This study underscores the need for stronger safety mechanisms in generative models and provides a foundation for future research on defending against sophisticated jailbreaking attacks. JailFuzzer is open-source and available at this repository: https://github.com/YingkaiD/JailFuzzer. Yingkai Dong, Xiangtao Meng, Ning Yu 0006, Zheng Li 0023, Shanqing Guo |
SP | 1 |
| 2025 | Research on hull form optimization at multiple speeds based on machine learning and ship model experimentsabstractIn order to improve the scientificity, efficiency and systematicness of ship form optimization, the multi-objective optimization research on the David Taylor Model Basin (DTMB) 5512 ship is carried out. First, the ship model experiment quantified the still water resistance of DTMB 5512 at six speeds at Froude number (Fr) as 0.25–0.40, demonstrating an almost linear resistance velocity relationship. Meanwhile, the DTMB 5512 ship is subjected to numerical simulations using the Computational Fluid Dynamics (CFD) method and the calculated results are compared with the experimental results. Then, Random Forest (RF)-based approximate models were developed for multi-speed resistance prediction, and verified its feasibility using Maximum Absolute Error (MAE). Finally, the parametric modeling method, the CFD method, and the optimization algorithm are integrated to construct a multi-objective optimization design system for ship forms. The resistance performance of the DTMB 5512 ship is optimized using the Multi-Objective Particle Swarm Optimization (MOPSO) algorithm. The results show that under the constructed hull form optimization framework, the optimized hull forms that meet the constraint conditions can be obtained. The total resistance of the obtained optimized ship at six speeds is reduced by 2.95 %, 4.44 %, 3.71 %, 5.22 %, 5.51 % and 4.83 % respectively. The research results indicate that the optimized hull forms with improved resistance performance can be obtained through the proposed methods, significantly enhancing the optimization efficiency. It also verifies the effectiveness of the random forest method in addressing the challenges of actual engineering optimization. Jie Liu 0093, Baoji Zhang, Lifen Hu, Junying Bi, Yingkai Dong |
Eng. Appl. Artif. Intell. | 6 |
| 2025 | Safe Driving Adversarial Trajectory Can Mislead: Toward More Stealthy Adversarial Attack Against Autonomous Driving Prediction ModuleabstractThe prediction module, powered by deep learning models, constitutes a fundamental component of high-level Autonomous Vehicles (AVs). Given the direct influence of the module’s prediction accuracy on AV driving behavior, ensuring its security is paramount. However, limited studies have explored the adversarial robustness of the prediction modules. Furthermore, existing methods still generate adversarial trajectories that deviate significantly from human driving behavior. These deviations can be easily identified as hazardous by AVs’ anomaly detection models and thus cannot effectively evaluate and reflect the robustness of the prediction modules. To bridge this gap, we propose a stealthy and more effective optimization-based attack method. Specifically, we reformulate the optimization problem using Lagrangian relaxation and design a Frenet-based objective function along with a distinct constraint space. We conduct extensive evaluations on 2 popular prediction models and 2 benchmark datasets. Our results show that our attack is highly effective, with over 87% attack success rates, outperforming all baseline attacks. Moreover, our attack method significantly improves the stealthiness of adversarial trajectories while guaranteeing adherence to physical constraints. Our attack is also found robust to noise from upstream modules, transferable across trajectory prediction models, and high realizability. Lastly, to verify its effectiveness in real-world applications, we conduct further simulation evaluations using a production-grade simulator. These simulations reveal that the adversarial trajectory we created could convincingly induce autonomous vehicles (AVs) to initiate hard braking. Yingkai Dong, Li Wang 0120, Zheng Li 0023, Hao Li 0092, Peng Tang 0002, Chengyu Hu 0001, Shanqing Guo |
ACM Trans. Priv. Secur. | 1 |