EDBT 2026 Demo / reviewers in the wild / expert
Tianmeng Fang
dblp:395/2142
· DBLP profile ↗
3ranked-venue papers
1as first author
3since 2021 · last 2026
0009-0005-7234-9468ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Network security · 72% Security and privacy of machine learning · 28% | |
| Artificial intelligence
1 paper |
Generative modeling · 100% |
Topics — the 6 heaviest of 6, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Generative modeling › video generation
text-to-video generation |
1.0 | 1 | 2026 | T2VShield: Model-Agnostic Jailbreak Defense for Text-to-Video Models · Int. J. Comput. Vis. 2026 |
Security and privacy of machine learning › large language model safety
jailbreak defense |
1.0 | 1 | 2026 | T2VShield: Model-Agnostic Jailbreak Defense for Text-to-Video Models · Int. J. Comput. Vis. 2026 |
Network security
traffic analysis |
1.0 | 1 | 2026 | TrapFlow: Controllable Website Fingerprinting Defense via Dynamic Backdoor Learning · IEEE Trans. Inf. Forensics Secur. 2026 |
Network security › traffic analysis
website fingerprinting defense |
1.0 | 1 | 2026 | TrapFlow: Controllable Website Fingerprinting Defense via Dynamic Backdoor Learning · IEEE Trans. Inf. Forensics Secur. 2026 |
Network security
anonymity networks |
0.3 | 1 | 2026 | TrapFlow: Controllable Website Fingerprinting Defense via Dynamic Backdoor Learning · IEEE Trans. Inf. Forensics Secur. 2026 |
Network security › anonymity networks
tor |
0.3 | 1 | 2026 | TrapFlow: Controllable Website Fingerprinting Defense via Dynamic Backdoor Learning · IEEE Trans. Inf. Forensics Secur. 2026 |
Methods — techniques the papers use, named apart from their topics
fast levenshtein-like distance · 1.0backdoor learning · 1.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | T2VShield: Model-Agnostic Jailbreak Defense for Text-to-Video Models
Siyuan Liang 0004, Jiecheng Zhai, Tianmeng Fang, Rongcheng Tu, Aishan Liu, Xiaochun Cao, Dacheng Tao |
Int. J. Comput. Vis. | 4 |
| 2026 | A patch-based cross-view regularized framework for backdoor defense in multimodal large language models
Tianmeng Fang, Zetai Kong, Zengzhen Su, Chengjin Yu |
Pattern Anal. Appl. | 1 |
| 2026 | TrapFlow: Controllable Website Fingerprinting Defense via Dynamic Backdoor LearningabstractWebsite fingerprinting (WF) attacks, which covertly monitor user communications to identify the web pages they visit, pose a serious threat to user privacy. Existing WF defenses attempt to reduce attack accuracy by disrupting traffic patterns, but attackers can retrain their models to adapt, making these defenses ineffective. Meanwhile, their high overhead limits deployability. To overcome these limitations, we introduce a novel controllable website fingerprinting defense called TrapFlow based on backdoor learning. TrapFlow exploits the tendency of neural networks to memorize subtle patterns by injecting crafted trigger sequences into targeted website traffic, causing the attacker’s model to build incorrect associations during training. If the attacker attempts to adapt by training on such noisy data, TrapFlow ensures that the model internalizes the trigger as a dominant feature, leading to widespread misclassification across unrelated websites. Conversely, if the attacker ignores these patterns and trains only on clean data, the trigger behaves as an adversarial patch at inference time, causing model misclassification. To achieve this dual effect, we optimize the trigger using the Fast Levenshtein-like distance to maximize both its learnability and distinctiveness from normal traffic. Experiments show that TrapFlow significantly reduces the accuracy of the RF attack from 99% to 6% with 74% data overhead. This compares favorably against two SOTA defenses: FRONT reduces accuracy by only 2% at a similar overhead, while Palette achieves 32% accuracy, but with 48% more overhead. We further validate the practicality of our method in a real Tor network environment. Siyuan Liang 0004, Jiajun Gong, Tianmeng Fang, Aishan Liu, Tao Wang 0012, Xiaochun Cao, Dacheng Tao, Ee-Chien Chang |
IEEE Trans. Inf. Forensics Secur. | 3 |