Stanley Wu

dblp:54/9429 · DBLP profile ↗
← Back
6ranked-venue papers
1as first author
4since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 1 first-author · 4 since 2021Systems, architecture and hardware · 2
YearPublicationVenuePosition
2025 On the Feasibility of Poisoning Text-to-Image AI Models via Adversarial Mislabeling
abstract
Today's text-to-image generative models are trained on millions of images sourced from the Internet, each paired with a detailed caption produced by Vision-Language Models (VLMs). This part of the training pipeline is critical for supplying the models with large volumes of high-quality image-caption pairs during training. However, recent work suggests that VLMs are vulnerable to stealthy adversarial attacks, where adversarial perturbations are added to images to mislead the VLMs into producing incorrect captions.
Stanley Wu, Ronik Bhaskar, Anna Yoo Jeong Ha, Shawn Shan, Haitao Zheng 0001, Ben Y. Zhao
CCS1
2024 Nightshade: Prompt-Specific Poisoning Attacks on Text-to-Image Generative Models
abstract
Trained on billions of images, diffusion-based text-to-image models seem impervious to traditional data poisoning attacks, which typically require poison samples approaching 20% of the training set. In this paper, we show that state-of-the-art text-to-image generative models are in fact highly vulnerable to poisoning attacks. Our work is driven by two key insights. First, while diffusion models are trained on billions of samples, the number of training samples associated with a specific concept or prompt is generally on the order of thousands. This suggests that these models will be vulnerable to prompt-specific poisoning attacks that corrupt a model’s ability to respond to specific targeted prompts. Second, poison samples can be carefully crafted to maximize poison potency to ensure success with very few samples.We introduce Nightshade, a prompt-specific poisoning attack optimized for potency that can completely control the output of a prompt in Stable Diffusion’s newest model (SDXL) with less than 100 poisoned training samples. Nightshade also generates stealthy poison images that look visually identical to their benign counterparts, and produces poison effects that "bleed through" to related concepts. More importantly, a moderate number of Nightshade attacks on independent prompts can destabilize a model and disable its ability to generate images for any and all prompts. Finally, we propose the use of Nightshade and similar tools as a defense for content owners against web scrapers that ignore opt-out/do-not-crawl directives, and discuss potential implications for both model trainers and content owners.
Shawn Shan, Wenxin Ding, Josephine Passananti, Stanley Wu, Haitao Zheng 0001, Ben Y. Zhao
SP4
2024 TMI! Finetuned Models Leak Private Information from their Pretraining Data
abstract
Transfer learning has become an increasingly popular technique in machine learning as a way to leverage a pretrained model trained for one task to assist with building a finetuned model for a related task. This paradigm has been especially popular for privacy in machine learning, where the pretrained model is considered public, and only the data for finetuning is considered sensitive. However, there are reasons to believe that the data used for pretraining is still sensitive, making it essential to understand how much information the finetuned model leaks about the pretraining data. In this work we propose a new membership-inference threat model where the adversary only has access to the finetuned model and would like to infer the membership of the pretraining data. To realize this threat model, we implement a novel metaclassifier-based attack, TMI, that leverages the influence of memorized pretraining samples on predictions in the downstream task. We evaluate TMI on both vision and natural language tasks across multiple transfer learning settings, including finetuning with differential privacy. Through our evaluation, we find that TMI can successfully infer membership of pretraining examples using query access to the finetuned model.
John Abascal, Stanley Wu, Alina Oprea, Jonathan R. Ullman
Proc. Priv. Enhancing Technol.2
2023 How to Combine Membership-Inference Attacks on Multiple Updated Machine Learning Models
abstract
A large body of research has shown that machine learning models are vulnerable to membership inference (MI) attacks that violate the privacy of the participants in the training data. Most MI research focuses on the case of a single standalone model, while production machine-learning platforms often update models over time, on data that often shifts in distribution, giving the attacker more information. This paper proposes new attacks that take advantage of one or more model updates to improve MI. A key part of our approach is to leverage rich information from standalone MI attacks mounted separately against the original and updated models, and to combine this information in specific ways to improve attack effectiveness. We propose a set of combination functions and tuning methods for each, and present both analytical and quantitative justification for various options. Our results on four public datasets show that our attacks are effective at using update information to give the adversary a significant advantage over attacks on standalone models, but also compared to a prior MI attack that takes advantage of model updates in a related machine-unlearning setting. We perform the first measurements of the impact of distribution shift on MI attacks with model updates, and show that a more drastic distribution shift results in significantly higher MI risk than a gradual shift. We also show that our attacks are effective at auditing differentially private fine tuning. We make our code public on Github: https://github.com/stanleykywu/model-updates.
Matthew Jagielski, Stanley Wu, Alina Oprea, Jonathan R. Ullman, Roxana Geambasu
Proc. Priv. Enhancing Technol.2
2010 Efficiency enhancement and linearity trade-offs for cascode vs. common-emitter SiGe power amplifiers in WiMAX polar transmitters
abstract
In this paper, a monolithic RF cascode SiGe power amplifier (PA) design capable of enhancing its power-added efficiency (PAE) is demonstrated. Four RF switches are adopted at the bases of the common-emitter transistors, which can be turned on/off in response to the desired output power. Simulations show that by utilizing device size variation, our cascode PA achieves higher gain and PAE compared to conventional fixed-size cascode PA in the low power region; in addition, it also provides more output power and higher average PAE than single-stage common-emitter PAs. We also studied and compared the linearity performance of our cascode PAs vs. single-stage common-emitter PAs in a RF polar TX using an envelope tracking (ET) technique. We found that even through self-biasing for the common-base device can improve the output distortion of cascode PAs, a single-stage common-emitter SiGe PA designed for comparison is still considerably more linear than cascode PAs. Therefore, more careful system linearization design will be critical when the cascode PAs are adopted in RF polar transmitters (TXs), especially for broadband wireless applications such as mobile WiMAX studied here.
Yan Li 0008, Jerry Lopez, Donald Y. C. Lie, Kevin Chen 0003, Stanley Wu, Tzu-Yi Yang
ISCAS5
2009 SiGe Class-E Power Amplifier with Envelope Tracking for Mobile WiMAX/Wibro Applications
abstract
In this paper, we report both circuits design and system simulations using highly-efficient monolithic SiGe class-E power amplifier (PA) with an open-loop envelope tracking (ET) technique for mobile WiMAX/Wibro applications. The 1-stage and 2-stage class-E PAs were designed and fabricated in a 0.18µm BiCMOS SiGe technology. The 1-stage class-E PA achieved peak power added efficiency (PAE) of 62% at output power of 21dBm in single-tone measurement. The design of linear-assisted switching envelope amplifier is also discussed, which involves balancing the tradeoff between efficiency and signal fidelity. Detailed co-design system simulations including RF circuits and digital DSP blocks show that our class-E PA can be linearized by the open-loop ET technique, and the entire ET-based transmit (TX) system meets the stringent 802.16e TX mask with ∼33% overall average efficiency at output power of 18.5dBm.
Yan Li 0008, Jerry Lopez, Donald Y. C. Lie, Kevin Chen 0003, Stanley Wu, Tzu-Yi Yang
ISCAS5