Yudong Gao

dblp:39/10037 · DBLP profile ↗
← Back
16ranked-venue papers
4as first author
14since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 6 · 2 first-author · 6 since 2021Security and privacy · 3 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 3 since 2021Computer networks · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 One Cognitive Loop Is Enough: SODA unlocks Pure-Text Spatial Reasoning in Large Language Models
abstract
Shunwen Bai, Jiahuan Zhang, Haoran Huang, Yurun Wang, Jiale Liu, Yanxi Wu, Ningzhe Yu, Yudong Gao, Mingjun Cheng. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026.
Shunwen Bai, Haoran Huang, Yurun Wang, Yanxi Wu, Ningzhe Yu, Yudong Gao, Mingjun Cheng
ACL (1)8
2025 FFCBA: Feature-based Full-target Clean-label Backdoor Attacks
Yangxu Yin, Honglong Chen, Yudong Gao, Peng Sun 0003, Liantao Wu, Zhe Li 0026, Weifeng Liu 0001
ACM Multimedia3
2025 FEAT: Frequency Energy Based Backdoor Attack in Deep Neural Networks
Junwei Li 0005, Honglong Chen, Yudong Gao, Junjian Li, Jimiao Yu, Jinghan Qiu
Expert Syst. Appl.3
2025 Defending against backdoor attack on deep neural networks based on multi-scale inactivation
Anqing Zhang, Honglong Chen, Junjian Li, Yudong Gao
Inf. Sci.5
2025 A Triple Stealthy Backdoor: Hidden in Spatial, Frequency, and Feature Domains
abstract
Backdoor attacks pose significant security risks to deep neural networks (DNNs). These attacks involve models that make intentionally incorrect (and potentially targeted) predictions on poisoned inputs containing carefully crafted triggers, while operating normally with clean inputs. Prior studies have investigated the invisibility of backdoor triggers to improve attack stealthiness. However, they primarily concentrate on achieving invisibility solely in the spatial domain, ignoring the generation of invisible triggers in the frequency and feature domains. This constraint makes the poisoned images vulnerable to detection by recent defense mechanisms. To tackle this problem, we introduce a Triple stealthy BAckdoor attack approach, termed TriBA, which simultaneously ensures the invisibility of triggers in all the spatial, frequency, and feature domains, to achieve desirable attack performance, while ensuring strong stealthiness. Specifically, we initially utilize Wavelet Transform to embed the high-frequency information from the trigger image into the clean image to ensure effective attack performance. Then, to achieve strong stealthiness across both spatial and frequency domains, we integrate Fourier Transform and Cosine Transform to blend the poisoned image and clean image in the frequency domain. Furthermore, TriBA adopts an attack strategy to make the backdoor features similar to clean features in the feature space, which guarantees trigger invisibility in the feature domain while maintaining attack effectiveness. We theoretically prove the effectiveness of this strategy. Finally, TriBA has been comprehensively evaluated on four datasets against popular image classifiers, demonstrating a marked improvement over existing state-of-the-art backdoor attacks in terms of both attack success rate and stealthiness.
Yudong Gao, Honglong Chen, Peng Sun 0003, Junjian Li, Yangxu Yin, Zhibo Wang 0001, Weifeng Liu 0001
IEEE Trans. Dependable Secur. Comput.1
2025 Black-Box Adversarial Defense Based on Image Decomposition and Reconstruction
abstract
Adversarial attacks have challenged the security of deep neural networks (DNNs) recently. The most prominent adversarial attack methods include backdoor attacks, adversarial examples, etc. These attack methods inject triggers or perturbations into images, leading to extremely dangerous security vulnerability in deep learning domain. The various forms of adversarial attacks can contaminate DNNs with their distinct characteristics. The complexity of adversarial attack poses a great challenge to designing a general defense strategy. In this paper, we propose a novel defense method against most of adversarial attacks through Image Decomposition and Reconstruction (IDR). Our method can be applied to poisoned images without the need for internal information about the model or any prior knowledge of the clean/poisoned images. We apply a linear transformation on the poisoned image to destroy the perturbations or triggers and deploy a pre-trained diffusion model to reconstruct the original information. In particular, we propose a novel reverse process that utilizes the consistency of range-null space decomposition to guide the generation of purified images. The decomposition of the range-null space can guarantee the retrieval of image information, which enhances the robustness of our method and contributes to the reliable purification of poisoned images. We assess the effectiveness of our proposed IDR against various prevalent backdoor attacks, adversarial examples and Image-Scaling attack methods. The experimental results highlight the outstanding defensive capabilities of our proposed IDR, demonstrating an exceptionally high defense success rate.
Jimiao Yu, Honglong Chen, Junjian Li, Linghan Chen, Yudong Gao, Weifeng Liu 0001
IEEE Trans. Multim.5
2024 A Dual Stealthy Backdoor: From Both Spatial and Frequency Perspectives
abstract
Backdoor attacks pose serious security threats to deep neural networks (DNNs). Backdoored models make arbitrarily (targeted) incorrect predictions on inputs containing well-designed triggers, while behaving normally on clean inputs. Prior researches have explored the invisibility of backdoor triggers to enhance attack stealthiness. However, most of them only focus on the invisibility in the spatial domain, neglecting the generation of invisible triggers in the frequency domain. This limitation renders the generated poisoned images easily detectable by recent defense methods. To address this issue, we propose a DUal stealthy BAckdoor attack method named DUBA, which simultaneously considers the invisibility of triggers in both the spatial and frequency domains, to achieve desirable attack performance, while ensuring strong stealthiness. Specifically, we first use Wavelet Transform to embed the high-frequency information of the trigger image into the clean image to ensure attack effectiveness. Then, to attain strong stealthiness, we incorporate Fourier Transform and Cosine Transform to mix the poisoned image and clean image in the frequency domain. Moreover, DUBA adopts a novel attack strategy, training the model with weak triggers and attacking with strong triggers to further enhance attack performance and stealthiness. DUBA is evaluated extensively on four datasets against popular image classifiers, showing significant superiority over state-of-the-art backdoor attacks in attack success rate and stealthiness.
Yudong Gao, Honglong Chen, Peng Sun 0003, Junjian Li, Anqing Zhang, Zhibo Wang 0001, Weifeng Liu 0001
AAAI1
2024 Energy-based Backdoor Defense without Task-Specific Samples and Model Retraining
abstract
Backdoor defense is crucial to ensure the safety and robustness of machine learning models when under attack. However, most existing methods specialize in either the detection or removal of backdoors, but seldom both. While few works have addressed both, these methods rely on strong assumptions or entail significant overhead costs, such as the need of task-specific samples for detection and model retraining for removal. Hence, the key challenge is how to reduce overhead and relax unrealistic assumptions. In this work, we propose two Energy-Based BAckdoor defense methods, called EBBA and EBBA+, that can achieve both backdoored model detection and backdoor removal with low overhead. Our contributions are twofold: First, we offer theoretical analysis for our observation that a predefined target label is more likely to occur among the top results for various samples. Inspired by this, we develop an enhanced energy-based technique, called EBBA, to detect backdoored models without task-specific samples (i.e., samples from any tasks). Secondly, we theoretically analyze that after data corruption, the original clean label of a poisoned sample is more likely to be predicted as a top output by the model, a sharp contrast to clean samples. Accordingly, we extend EBBA to develop EBBA+, a new transferred energy approach to efficiently detect poisoned images and remove backdoors without model retraining. Extensive experiments on multiple benchmark datasets demonstrate the superior performance of our methods over baselines in both backdoor detection and removal. Notably, the proposed methods can effectively detect backdoored model and poisoned images as well as remove backdoors at the same time.
Yudong Gao, Honglong Chen, Peng Sun 0003, Zhe Li 0026, Junjian Li, Huajie Shao
ICML1
2024 BABE: Backdoor attack with bokeh effects via latent separation suppression
Junjian Li, Honglong Chen, Yudong Gao, Shaozhong Guo, Peng Sun 0003
Eng. Appl. Artif. Intell.3
2024 Enhanced Coalescence Backdoor Attack Against DNN Based on Pixel Gradient
abstract
Abstract Deep learning has been widely used in many applications such as face recognition, autonomous driving, etc. However, deep learning models are vulnerable to various adversarial attacks, among which backdoor attack is emerging recently. Most of the existing backdoor attacks use the same trigger or the same trigger generation approach to generate the poisoned samples in the training and testing sets, which is also commonly adopted by many backdoor defense strategies. In this paper, we develop an enhanced backdoor attack (EBA) that aims to reveal the potential flaws of existing backdoor defense methods. We use a low-intensity trigger to embed the backdoor, while a high-intensity trigger to activate it. Furthermore, we propose an enhanced coalescence backdoor attack (ECBA) where multiple low-intensity incipient triggers are designed to train the backdoor model, and then, all incipient triggers are gathered on one sample and enhanced to launch the attack. Experiment results on three popular datasets show that our proposed attacks can achieve high attack success rates while maintaining the model classification accuracy of benign samples. Meanwhile, by hiding the incipient poisoned samples and preventing them from activating the backdoor, the proposed attack exhibits significant stealth and the ability to evade mainstream defense methods during the model training phase.
Jianyao Yin, Honglong Chen, Junjian Li, Yudong Gao
Neural Process. Lett.4
2024 Investigating the Backdoor on DNNs Based on Recolorization and Reconstruction: From a Multi-Channel Perspective
abstract
Recently, backdoor attacks have become a serious security threat to Deep Neural Networks (DNNs). Backdoor attacks involve embedding a hidden backdoor into a DNN model, compelling it to correctly classify benign images while erroneously classifying images with backdoor triggers as the target label. However, both current backdoor attacks and defenses have their limitations. In backdoor attacks, they are either non-stealthy or vulnerable to well-designed backdoor defense strategies. As for backdoor defenses, they often rely heavily on additional assumptions (such as determined extra clean images) and are not universally applicable, which may become impractical in the face of the latest backdoor attacks. To address the above problems, in this paper, we investigate the backdoor attack and defense strategies from a multi-channel perspective. Specifically, in terms of attacks, we propose a recolorization based attack method (RC-Attack) to generate triggers in color ab channels, which is more stealthy and effective. In terms of defenses, we propose a reconstruction-based defense method (RC-Defense) to reconstruct the color AB channels and lightness channel respectively, thus making the triggers in the reconstructed images ineffective, which is a more practical solution. Extensive experiments are conducted to demonstrate the superior performance of the proposed RC-Attack in terms of effectiveness, stealthiness and defense-resistance, and also to validate the effectiveness of the proposed RC-Defense.
Honglong Chen, Yudong Gao, Anqing Zhang, Peng Sun 0003, Nan Jiang 0013, Weifeng Liu 0001
IEEE Trans. Inf. Forensics Secur.2
2024 Towards Adaptive Privacy Protection for Interpretable Federated Learning
abstract
Federated learning (FL) is an effective privacy-preserving mechanism that collaboratively trains the global model in a distributed manner by solely sharing model parameters rather than data from local clients, like mobile devices, to a central server. Nevertheless, recent studies have illustrated that FL still suffers from gradient leakage as adversaries try to recover training data by analyzing shared parameters from local clients. To address this issue, differential privacy (DP) is adopted to add noise to the parameters of local models before aggregation occurs on the server. It, however, results in the poor performance of gradient-based interpretability, since some important weights capturing the salient region in feature maps will be perturbed. To overcome this problem, we propose a simple yet effective adaptive gradient protection (AGP) mechanism that selectively adds noisy perturbations to certain channels of each client model that have a relatively small impact on interpretability. We also offer a theoretical analysis of the convergence of FL using our method. The evaluation results on both IID and Non-IID data demonstrate that the proposed AGP can achieve a good trade-off between privacy protection and interpretability in FL. Furthermore, we verify the robustness of the proposed method against two different gradient leakage attacks.
Zhe Li 0026, Honglong Chen, Zhichen Ni, Yudong Gao, Wei Lou
IEEE Trans. Mob. Comput.4
2024 Staged Noise Perturbation for Privacy-Preserving Federated Learning
abstract
Federated learning (FL) is a distributed machine learning paradigm that addresses the challenges of privacy leakage and data silos by collaboratively training the global model through parameter exchange, rather than data, between the central server and local clients. However, recent researches highlight the vulnerability of FL to gradient leakage attacks where adversaries exploit shared parameters from clients to reconstruct sensitive training data. Differential privacy (DP) effectively mitigates this threat by adding noise to shared parameters, yet introduces a trade-off between privacy and accuracy in FL. To better balance the privacy and accuracy, in this paper we propose a staged noise perturbation strategy, called alternating noise permutation (ANP), from a novel perspective. ANP adds Gaussian-distributed random noise to model parameters during the critical learning period of FL, following DP principles. While in non-critical learning period, ANP alternately permutes the noise during odd and even communication rounds, achieving near mutual cancellation and mitigating the negative impact. Experimental results across three datasets and two neural networks under both independent identical distribution (IID) and NonIID scenarios demonstrate that ANP significantly improves classification accuracy and exhibits robustness against gradient leakage attack, ensuring the effectiveness of FL for secure and accurate collaborative model training.
Zhe Li 0026, Honglong Chen, Yudong Gao, Zhichen Ni, Huansheng Xue, Huajie Shao
IEEE Trans. Sustain. Comput.3
2023 B³A: Bokeh Based Backdoor Attack with Feature Restrictions
abstract
Deep neural networks (DNNs) are gradually becoming the preference for the various vision applications of smart cities. However, their success heavily relies on the access to extensive training data and substantial computational resources, posing challenges in training large-scale models for diverse smart city applications. Consequently, the third-party services and resources are often utilized to train the models, exposing them to the potential backdoor attacks. Despite the escalating threat of such attacks, many existing strategies primarily focus on enhancing the stealthiness and evading defenses, often neglecting practical feasibility in the real-world scenarios. In this paper, we introduce a novel backdoor attack named bokeh based backdoor attack $(B^{3}A)$, which leverages the bokeh effect as the trigger. Once the backdoor is deployed in a vision application model, the model’s malicious behavior can be activated solely by using the captured bokeh images. Specifically, we employ saliency and depth estimation maps to synthesize the bokeh images, effectively serving as the poisoned samples. Moreover, we devise a reference model to impose constraints on the feature representations of the poisoned images, thereby further enhancing their stealthiness in the feature space. Extensive experiments demonstrate the attack effects of $B^{3}A$, even on the bokeh photos taken from Digital Still Cameras (DSC) and smartphones.
Junjian Li, Honglong Chen, Yudong Gao
MSN3
2012 Periodic transfers in mobile applications: network-wide origin, impact, and optimization
abstract
Cellular networks employ a specific radio resource management policy distinguishing them from wired and Wi-Fi networks. A lack of awareness of this important mechanism potentially leads to resource-inefficient mobile applications. We perform the first network-wide, large-scale investigation of a particular type of application traffic pattern called periodic transfers where a handset periodically exchanges some data with a remote server every t seconds. Using packet traces containing 1.5 billion packets collected from a commercial cellular carrier, we found that periodic transfers are very prevalent in today's smartphone traffic. However, they are extremely resource-inefficient for both the network and end-user devices even though they predominantly generate very little traffic. This somewhat counter-intuitive behavior is a direct consequence of the adverse interaction between such periodic transfer patterns and the cellular network radio resource management policy. For example, for popular smartphone applications such as Facebook, periodic transfers account for only 1.7% of the overall traffic volume but contribute to 30% of the total handset radio energy consumption. We found periodic transfers are generated for various reasons such as keep-alive, polling, and user behavior measurements. We further investigate the potential of various traffic shaping and resource control algorithms. Depending on their traffic patterns, applications exhibit disparate responses to optimization strategies. Jointly using several strategies with moderate aggressiveness can eliminate almost all energy impact of periodic transfers for popular applications such as Facebook and Pandora.
Feng Qian 0001, Zhaoguang Wang, Yudong Gao, Junxian Huang 0001, Alexandre Gerber, Z. Morley Mao, Subhabrata Sen, Oliver Spatscheck
WWW3
2010 On the Safety of Enterprise Policy Deployment
Yudong Gao, Ni Pan, Xu Chen 0028, Z. Morley Mao
NDSS1