EDBT 2026 Demo / reviewers in the wild / expert
Huajie Chen
dblp:61/8969
· DBLP profile ↗
13ranked-venue papers
5as first author
7since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 3 first-author · 2 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 2Computer networks · 1Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CSC: Turning the Adversary's Poison Against Itself
Huajie Chen, Tianqing Zhu, Bo Liu 0001, Wanlei Zhou 0001 |
ACISP (2) | 3 |
| 2025 | Stand-in Model Protection: Synthetic defense for membership inference and model inversion attacks
Huajie Chen, Tianqing Zhu, Shouling Ji, Wanlei Zhou 0001 |
Knowl. Based Syst. | 1 |
| 2025 | QUEEN: Query Unlearning Against Model ExtractionabstractModel extraction attacks currently pose a non-negligible threat to the security and privacy of deep learning models. By querying the model with a small dataset and using the query results as the ground-truth labels, an adversary can steal a piracy model with performance comparable to the original model. Two key issues that cause the threat are, on the one hand, accurate and unlimited queries can be obtained by the adversary; on the other hand, the adversary can aggregate the query results to train the model step by step. The existing defenses usually employ model watermarking or fingerprinting to protect the ownership. However, these methods cannot proactively prevent the violation from happening. To mitigate the threat, we propose QUEEN (QUEry unlEarNing) that proactively launches counterattacks on potential model extraction attacks from the very beginning. To limit the potential threat, QUEEN has sensitivity measurement and outputs perturbation that prevents the adversary from training a piracy model with high performance. In sensitivity measurement, QUEEN measures the single query sensitivity by its distance from the center of its cluster in the feature space. To reduce the learning accuracy of attacks, for the highly sensitive query batch, QUEEN applies query unlearning, which is implemented by gradient reverse to perturb the softmax output such that the piracy model will generate reverse gradients to worsen its performance unconsciously. Experiments show that QUEEN outperforms the state-of-the-art defenses against various model extraction attacks with a relatively low cost to the model accuracy. The artifact is publicly available athttps://github.com/MaraPapMann/QUEEN. Huajie Chen, Tianqing Zhu, Lefeng Zhang, Bo Liu 0001, Derui Wang, Wanlei Zhou 0001, Minhui Xue 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Atmospheric Methane Retrieval Based on Back Propagation Neural Network and Simulated AVIRIS-NG DataabstractMethane (CH4) is one of the main greenhouse gases, whose retrieval is easily affected by atmospheric water (H2O) and surface albedo. In this paper, based on a radiative transfer model, the Airborne Visible/Infrared Imaging Spectrometer-Next Generation (AVIRIS-NG) radiance with different H2O and surface albedo are simulated as training data. Back Propagation (BP) feed-forward neural network algorithm in machine learning is used to train the CH4retrieval model, which is applied to quantify the atmospheric CH4concentration. This method can effectively decrease the impact of atmospheric H2O and surface albedo on CH4retrieval. Moreover, this machine learning-based approach separates the processes of model training and prediction. This enables rapid characterization of CH4emission point sources in images as the Matched Filter (MF) method, while also obtaining the column-averaged concentration of CH4, similar to the Optimal Estimation (OE) method. The research results indicate that the Mean Absolute Percentage Error (MAPE) of the optimal BP model is as low as 0.33%. If necessary, further increases in training data can improve the resolution and applicability of the model. Yunxia Huang, Guizhen Liu, Huajie Chen, Shuwu Xu |
IEEE Geosci. Remote. Sens. Lett. | 4 |
| 2024 | High-Frequency Matters: Attack and Defense for Image-Processing Model WatermarkingabstractIn recent years, there has been significant advancement in the field of model watermarking techniques. However, the protection of image-processing neural networks remains a challenge, with only a limited number of methods being developed. The objective of these techniques is to embed a watermark in the output images of the target generative network, so that the watermark signal can be detected in the output of a surrogate model obtained through model extraction attacks. This promising technique, however, has certain limits. Analysis of the frequency domain reveals that the watermark signal is mainly concealed in the high-frequency components of the output. Thus, we propose an overwriting attack that involves forging another watermark in the output of the generative network. The experimental results demonstrate the efficacy of this attack in sabotaging existing watermarking schemes for image-processing networks with an almost 100% success rate. To counter this attack, we propose an adversarial framework for the watermarking network. The framework incorporates a specially-designed adversarial training step, where the watermarking network is trained to defend against the overwriting network, thereby enhancing its robustness. Additionally, we observe an overfitting phenomenon in the existing watermarking method, which can render it ineffective. To address this issue, we modify the training process to eliminate the overfitting problem. Huajie Chen, Tianqing Zhu, Chi Liu 0002, Shui Yu 0001, Wanlei Zhou 0001 |
IEEE Trans. Serv. Comput. | 1 |
| 2023 | Enhanced Multi-Relationships Integration Graph Convolutional Network for Inferring Substitutable and Complementary ItemsabstractUnderstanding the relationships between items can improve the accuracy and interpretability of recommender systems. Among these relationships, the substitute and complement relationships attract the most attention in e-commerce platforms. The substitutable items are interchangeable and might be compared with each other before purchasing, while the complementary items are used in conjunction and are usually bought together with the query item. In this paper, we focus on two issues of inferring the substitutable and complementary items: 1) how to model their mutual influence to improve the performance of downstream tasks, 2) how to further discriminate them by considering the strength of relationship for different item pairs. We propose a novel multi-task learning framework named Enhanced Multi-Relationships Integration Graph Convolutional Network (EMRIGCN). We regard the relationship inference task as a link prediction task in heterogeneous graph with different types of edges between nodes (items). To model the mutual influence between substitute and complement, EMRIGCN adopts a two-level integration module, i.e., feature and structure integration, based on experts sharing mechanism during message passing. To obtain the strength of relationship for item pairs, we build an auxiliary loss function to further increase or decrease the distances between embeddings of items with weak or strong relation in latent space. Extensive experiments on both public and industrial datasets prove that EMRIGCN significantly outperforms the state-of-the-art solutions. We also conducted A/B tests on real world recommender systems of Meituan Maicai, an online supermarket platform in China, and obtained 15.3% improvement on VBR and 15.34% improvement on RPM. Huajie Chen, Jiyuan He, Weisheng Xu, Runfeng Yao |
AAAI | 1 |
| 2023 | Making DeepFakes More Spurious: Evading Deep Face Forgery Detection via Trace Removal AttackabstractDeepFakes are raising significant social concerns. Although various Despite various DeepFake detectors having been developed as countermeasures, their vulnerability under attacks remains further explorations. Recently, several attacks, such as adversarial attacks, have successfully fooled DeepFake detectors. However, existing attacks suffer from detector-specific designs, requiring detector-side knowledge, leading to poor transferability. Moreover, they only consider simplified security scenarios; but less is known about the attacking performance in complex scenarios where the capability of detectors or attackers varies. To fill the gap, we propose a novel, detector-agnostic trace removal attack. The attack removes all possible counterfeiting traces arising from the original DeepFake manufacture procedure to make DeepFakes essentially more "realistic" and thus able to defeat arbitrary or unknown detectors. Concretely, we first perform an in-depth DeepFake trace discovery, identifying three intrinsic traces: spatial anomalies, spectral disparities, and noise fingerprints. Then an adversarial learning-based trace removal network (TR-Net) involving one generator and multiple discriminators is proposed. Each discriminator is responsible for one individual trace representation to avoid inner-trace interference. All discriminators are optimized in parallel to enforce the generator to remove various traces simultaneously. We additionally craft heterogeneous security scenarios where the detectors are embedded with different levels of defense and the attackers own varying background data knowledge. The experimental results show that the proposed trace removal attack can significantly compromise the detection accuracy of six state-of-the-art DeepFake detectors while causing only a negligible degradation in visual quality. Chi Liu 0002, Huajie Chen, Tianqing Zhu, Jun Zhang 0010, Wanlei Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | A Multi-Task Incremental Learning Framework with Category Name Embedding for Aspect-Category Sentiment AnalysisabstractT)ACSA tasks, including aspect-category sentiment analysis (ACSA) and targeted aspectcategory sentiment analysis (TACSA), aims at identifying sentiment polarity on predefined categories.Incremental learning on new categories is necessary for (T)ACSA real applications.Though current multi-task learning models achieve good performance in (T)ACSA tasks, they suffer from catastrophic forgetting problems in (T)ACSA incremental learning tasks.In this paper, to make multi-task learning feasible for incremental learning, we proposed Category Name Embedding network (CNE-net).We set both encoder and decoder shared among all categories to weaken the catastrophic forgetting problem.Besides the origin input sentence, we applied another input feature, i.e., category name, for task discrimination.Our model achieved state-of-theart on two (T)ACSA benchmark datasets.Furthermore, we proposed a dataset for (T)ACSA incremental learning and achieved the best performance compared with other strong baselines. Zehui Dai, Huajie Chen, Yadong Ding |
EMNLP (1) | 3 |
| 2019 | Charge-Based Prison Term Prediction with Deep Gating NetworkabstractHuajie Chen, Deng Cai, Wei Dai, Zehui Dai, Yadong Ding. Proceedings of the 2019 Conference on Empirical Methods in Natural Language Processing and the 9th International Joint Conference on Natural Language Processing (EMNLP-IJCNLP). 2019. Huajie Chen, Deng Cai 0002, Zehui Dai, Yadong Ding |
EMNLP/IJCNLP (1) | 1 |
| 2019 | Multi-Task Multi-Head Attention Memory Network for Fine-Grained Sentiment Analysis
Zehui Dai, Zhenhua Liu 0006, Fengyun Rao, Huajie Chen, Guangpeng Zhang, Yadong Ding, Jiyang Liu |
NLPCC (1) | 5 |
| 2017 | Joint Weighted Nonnegative Matrix Factorization for Mining Attributed Graphs
Zhichao Huang 0001, Yunming Ye, Xutao Li 0003, Feng Liu 0034, Huajie Chen |
PAKDD (1) | 5 |
| 2012 | A kernel particle filter algorithm for joint tracking and classification
Dongliang Peng 0001, Huajie Chen, Anke Xue |
FUSION | 3 |
| 2010 | Low Altitude Target Tracking Algorithm with Acoustic Wireless Sensor NetworkabstractFor the problem of low altitude target tracking with acoustic wireless network, the signal propagation time delay effect must be considered. The target has been far away from its emitting position when the signal is received by sensors. This effect leads to synchronous sensors in the measurement space sample asynchronously in the state space and the sample frequency becomes unknown and time varying. In this paper, a batch type distribution fusion algorithm is proposed which consists of two steps. First, a linear search method is used for estimating the time-varying state transition time which is the parameter of least square solution for the initial state. This initial state is used again to optimize the state transition time until the iteration termination condition is satisfied. Second, a time register procedure and a distribution fusion technique are presented to obtain the global track. Simulation results verify the efficiency of the proposed method. Anke Xue, Hongyang Chen 0001, Huajie Chen, Kaoru Sezaki |
GLOBECOM | 4 |