EDBT 2026 Demo / reviewers in the wild / expert
Haoran Li 0023
dblp:50/10038-23
· DBLP profile ↗
9ranked-venue papers
3as first author
9since 2021 · last 2026
0000-0002-0409-2227ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | PWAVEP: Purifying Imperceptible Adversarial Perturbations in 3D Point Clouds via Spectral Graph WaveletsabstractRecent progress in adversarial attacks on 3D point clouds, particularly in achieving spatial imperceptibility and high attack performance, presents significant challenges for defenders. Current defensive approaches remain cumbersome, often requiring invasive model modifications, expensive training procedures or auxiliary data access. To address these threats, in this paper, we propose a plug-and-play and non-invasive defense mechanism in the spectral domain, grounded in a theoretical and empirical analysis of the relationship between imperceptible perturbations and high-frequency spectral components. Building upon these insights, we introduce a novel purification framework, termed PWAVEP, which begins by computing a spectral graph wavelet domain saliency score and local sparsity score for each point. Guided by these values, PWAVEP adopts a hierarchical strategy, it eliminates the most salient points, which are identified as hardly recoverable adversarial outliers. Simultaneously, it applies a spectral filtering process to a broader set of moderately salient points. This process leverages a graph wavelet transform to attenuate high-frequency coefficients associated with the targeted points, thereby effectively suppressing adversarial noise. Extensive evaluations demonstrate that the proposed PWAVEP achieves superior accuracy and robustness compared to existing approaches, advancing the state-of-the-art in 3D point cloud purification. Code and datasets are available at https://github.com/a772316182/pwavep Haoran Li 0023, Renyang Liu 0001, Hongjia Liu, Chen Wang 0042, Long Yin, Jian Xu 0004 |
WWW | 1 |
| 2026 | PPLLA: Privacy-preserving attribute-based LLM authorization
Jian Xu 0004, Huiyang He, Haoran Li 0023, Qiang Wang 0005, Fucai Zhou |
Inf. Sci. | 4 |
| 2025 | Metapath-free adversarial attacks against heterogeneous graph neural networks
Haoran Li 0023, Jian Xu 0004, Long Yin, Qiang Wang 0005, Yongzhen Jiang |
Inf. Sci. | 1 |
| 2024 | CNFA: Conditional Normalizing Flow for Query-Limited AttackabstractTraditional black-box attack methods rely on sufficient feedback from the victim model through a large number of queries until the attack is successful. This may not be acceptable in real applications, since the deployed system may be equipped with certain defense mechanisms and only return the final result (i.e., hard label) to the client. In contrast, one possible approach is formulating a hard label attack, which can be successfully executed within limited queries. To implement this idea, in this paper, we bypass the reliance on victim models and benefit from the intrinsic characteristics of adversarial examples (AEs) and the transferability of examples across different data-driven models. This motivates us to generatively reformulate the attack problem and propose a conditional normalized flow-based attack (CNFA), which builds up a statistical mapping from the benign example to its adversarial counterpart by tackling the conditional likelihood under the hard-label black-box setting. A well-trained CNFA model can directly and efficiently generate a batch of AEs for specific condition inputs. Extensive experiments validate the effectiveness of the proposed idea in a hard-label black-box setting and the superiority of CNFA over SOTA techniques. Renyang Liu 0001, Wei Zhou 0011, Haoran Li 0023, Ruxin Wang 0002 |
ICASSP | 4 |
| 2024 | Privacy-preserving and verifiable classifier training in edge-assisted mobile communication systems
Chen Wang 0042, Jian Xu 0004, Haoran Li 0023, Fucai Zhou, Qiang Wang 0005 |
Comput. Commun. | 3 |
| 2023 | AFLOW: Developing Adversarial Examples Under Extremely Noise-Limited Settings
Renyang Liu 0001, Haoran Li 0023, Yuanyu Wang, Wei Zhou 0011 |
ICICS | 3 |
| 2023 | Multi-scale Features Destructive Universal Adversarial Perturbations
Huangxinyue Wu, Haoran Li 0023, Wei Zhou 0011, Yunyun Dong |
ICICS | 2 |
| 2023 | Model Inversion Attacks on Homogeneous and Heterogeneous Graph Neural Networks
Renyang Liu 0001, Wei Zhou 0011, Xiaoyuan Liu 0002, Peiyuan Si, Haoran Li 0023 |
SecureComm (1) | 6 |
| 2022 | Towards Query-limited Adversarial Attacks on Graph Neural NetworksabstractGraph Neural Network (GNN) is a graph representation learning approach for graph-structured data, which has witnessed a remarkable progress in the past few years. As a counterpart, the robustness of such a model has also received considerable attention. Previous studies show that the performance of a well-trained GNN can be faded by black-box adversarial examples significantly. In practice, the attacker can only query the target model with very limited counts, yet the existing methods require hundreds of thousand queries to extend attacks, leading the attacker to be exposed easily. To perform a step forward in addressing this issue, in this paper, we propose a novel attack methods, namely Graph Query-limited Attack (GQA), in which we generate adversarial examples on the surrogate model to fool the target model. Specifically, in GQA, we use contrastive learning to fit the feature extraction layers of the surrogate model in a query-free manner, which can reduce the need of queries. Furthermore, in order to utilize query results sufficiently, we obtain a series of queries with rich information by changing the input iteratively, and storing them in a buffer for recycling usage. Experiments show that GQA can decrease the accuracy of the target model by 4.8%, with only 1% edges modified and 100 queries performed. Haoran Li 0023, Liwen Wu, Wei Zhou 0011, Ruxin Wang 0002 |
ICTAI | 1 |