EDBT 2026 Demo / reviewers in the wild / expert
Qiao Yan
dblp:71/1527
· DBLP profile ↗
30ranked-venue papers
2as first author
21since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 7 · 1 first-author · 7 since 2021Security and privacy · 5 · 5 since 2021Databases, data management, data science and information retrieval · 5 · 4 since 2021Computer networks · 4 · 1 since 2021Systems, architecture and hardware · 3 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Enhancing Graph Reconstruction via Node Embedding Alignment
Qiao Yan |
DASFAA (5) | 2 |
| 2026 | SliceCSRef: Dual-Level Semantic Alignment for Robust Speech Referring Expression ComprehensionabstractSpeech Referring Expression Comprehension (SREC) aims to localize the object in an image referred to by a spoken natural language query. However, raw speech is continuous and noisy, and prior ASR-free methods that align full utterances with transcripts using only global supervision can overfit to spurious correlations, limiting fine-grained grounding. To address this issue, we propose SliceCSRef, a robust SREC framework that improves generalization via dual-level semantic alignment. Beyond utterance-level speech–text alignment, SliceCSRef introduces slice-wise alignment that pairs randomly sampled speech segments with weakly matched transcript spans based on their relative temporal positions, providing fine-grained supervision without additional annotations. Experiments on six benchmarks show that SliceCSRef achieves state-of-the-art performance under standard settings and consistently improves robustness under truncated speech and playback-speed variations. Shenghua Zhong, Qiao Yan, Zhijiao Xiao, Yan Liu 0004 |
ICMR | 3 |
| 2026 | Boosting Black-Box Graph Reconstruction Attacks via Adjacency Relationship Recovery of Representative Nodes
Qiao Yan |
PAKDD (1) | 2 |
| 2026 | SM9-DTRS: a dynamic threshold ring signature scheme based on SM9 algorithmabstractAbstract In distributed scenarios such as electronic voting and blockchain, signature schemes require high anonymity, collusion resistance, and efficiency. Traditional ring signatures struggle to balance dynamism and security, while dynamic threshold ring signature research remains underdeveloped. This paper proposes SM9-DTRS, a dynamic threshold ring signature scheme based on the SM9 algorithm. It adopts a dynamic threshold mechanism and reservoir sampling for real-time signer set adjustment, and optimizes bilinear pairings via precomputation. Experimental results show SM9-DTRS achieves 55.66 ms signature generation time (44.46% reduction) and 148.93 ms verification time (21.80% reduction) compared to similar schemes. Its signature length is (256 t + 768)-bit, scaling linearly with threshold t (instead of ring size n in traditional schemes), making it suitable for bandwidth-constrained environments. Under the random oracle model, SM9-DTRS is proven unforgeable, anonymous, and collusion-resistant based on the q -SDH assumption. Qiao Yan |
Cybersecur. | 3 |
| 2026 | Leveraging CVAE Encoding for Backdoor Attacks in Few-Shot Learning With Prototypical NetworksabstractFew-shot learning (FSL) has demonstrated tremendous potential when challenged with limited training data, but the assessment of its vulnerability to backdoor attacks is still at an early stage. However, recent research revealed this deep learning framework is susceptible to backdoor attack. Existing backdoor techniques attacked FSL by manipulating triggers in the feature space, resulting in overfitting to specific perturbations, poor tolerance to real-world variability, and easy detection. Limited training samples expose these triggers or dirty labels. In this paper, we propose a novel technique that leverages latent embedding to successfully implant backdoor attack on Prototypical Network–based few-shot classification model (prototype-based FSL). Our attack is specifically designed to target the prototype-based FSL due to its effectiveness in constructing fixed class prototypes from limited examples, making it uniquely susceptible to subtle prototype shifts. Since prototypical networks do not require backpropagation on testing samples, there's less chance to detect latent backdoors. The latent mechanism serve as a crucial enhancement to traditional perturbation-based backdoors. For this purpose, our proposed approach utilizes conditional variational autoencoder (CVAE) along with latent attention mechanism and regularization terms to seamlessly encode backdoor trigger within the original image feature space, offering a robust and reconstructed poisoned representation while preserving data integrity. In this setup, the reconstructed poisoned subset by CVAE, combined with clean images, serves as the support set for computing class prototypes. Besides, our strategy enhances generalization by focusing on high-level abstractions and aligns well with the objectives of prototype-based FSL. The experiment results reveal that our poisoning technique achieves high Attack Success Rate (ASR) in FSL challenges while ensuring benign accuracy (BA) and preserving stealthiness. Consequently, this approach outperforms earlier techniques in terms of efficiency and performance, leading to enhanced robustness against detection while assuring that the trigger remains smoothly integrated into the data distribution. This study demonstrates that latent backdoor attacks pose a persistent and significant threat to prototype-based FSL, underscoring an urgent need for robust security measures to protect against these vulnerabilities. Sana, Qiao Yan, Sizhe Liang |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2025 | Adversarial Knowledge Transfer for Black-Box Model Inversion AttackabstractRecent advancements in model inversion attacks have raised privacy concerns, exploiting access to models to reconstruct private training data from inputs and outputs. These attacks are categorized as white-box, black-box, or label-only based on access level. We propose a new black-box model inversion attack, Label-Controlled Adversarial Knowledge Transfer (L-AdKT). L-AdKT leverages adversarial training with a Generative Adversarial Network (GAN) and a substitute model to extract knowledge from the target model. The substitute model minimizes discrepancies with the target model while guiding the generator to produce realistic samples. This approach enables white-box techniques to be applied in black-box settings. Experiments show that L-AdKT outperforms state-of-the-art black-box attacks by over 20% across benchmarks and remains robust against various defense mechanisms. Xinhao Liu 0008, Zetao Lin, Yingzhao Jiang, Qiao Yan |
ICASSP | 4 |
| 2025 | Vanishing Privacy: Fast Gradient Leakage Threat to Federated LearningabstractIn the federated learning (FL) framework, clients participate in collaborative learning tasks under the coordination of a central server. Clients train local submodels using their own data and share gradients with the server, which aggregates the gradients to achieve privacy protection. However, recent research has revealed that gradient inversion attacks (GIAs) can leak private data from the shared gradients. Prior work has only demonstrated the feasibility of recovering input data from gradients under highly restrictive conditions, such as when dealing with high-resolution face datasets, where GIAs often struggle to initiate attacks effectively, and on object datasets like Imagenet, where they encounter limitations, primarily manifested in their ability to handle only small batch sizes and high time costs. As a result, we believe that implementing GIAs on high-resolution face datasets with large batch sizes is a challenging task. In this work, we introduce Fast Gradient Leakage (FGL), which enables rapid image recovery across various network models on complex datasets, including the CelebA face dataset (1000 classes, 224×224 px). We also introduced StyleGAN as prior knowledge for images and achieved FGL with a batch size of 60 in experiments (constrained by experimental hardware). We further propose a joint gradient matching loss, where multiple distinct matching losses collectively contribute to clarifying the attack direction and enhancing the efficiency of the optimization process. Extensive experimentation validates the feasibility of our approach. We anticipate that the proposed method will serve as a valuable tool to further advance the development of privacy defense techniques. Yingzhao Jiang, Xinhao Liu 0008, Qiao Yan |
IJCNN | 3 |
| 2025 | Adaptive Multi-space Defense Framework Against Adversarial Attacks
Xiaohui Yu 0016, Qiao Yan |
ECML/PKDD (2) | 2 |
| 2024 | Generating Black-box Audio Adversarial CAPTCHAs based on Differential Evolution AlgorithmabstractAudio adversarial CAPTCHAs are commonly used on various websites and applications to distinguish human users from automated programs. However, recent advances in deep learning have given rise to several audio recognition methods that pose a challenge to the security of audio CAPTCHAs. In this paper, we propose DE _ES, a novel approach based on the differential evolution algorithm, for generating audio adversarial CAPTCHAs. Our method utilizes a momentum probability update technique to add random noise to the examples and combines differential evolution with gradient estimation to enhance the success rate of attacks. We evaluate the similarity between the adversarial examples and the original examples using audio data visualization techniques. Moreover, we apply our method to generate adversarial CAPTCHAs for two usage scenarios of audio CAPTCHAs: input-based and selection-based, respectively, to demonstrate the feasibility of the proposed algorithm. Our experimental results demonstrate that DE_ES outperforms other heuristic-based generation methods in terms of the success rate of generating audio adversarial examples, while maintaining a lower average editing distance. Thus, our method provides an effective solution for generating robust audio adversarial CAPTCHAs that can, to a certain extent, withstand the attacks of deep learning models, thereby improving the security of voice-based authentication systems. Xinhao Liu 0008, Qiao Yan |
CSCWD | 3 |
| 2024 | Clustered Federated Learning Based on Client's PrototypesabstractFederated learning empowers multiple parties to train machine learning models collaboratively while preserving data within local confines. However, due to the intrinsic non-independent and identically distributed (Non-IID) nature of client-side data, aggregating these diverse local models into a global model remains a significant challenge. Clustered Federated Learning (CFL) offers a compelling solution to mitigate the impact of data heterogeneity by organizing clients into clusters. Existing CFL methods often involve unstable, time-consuming cluster identity estimation during training. In this work, we propose an innovative federated learning approach that efficiently identifies similarities among client data distributions by analyzing client’s prototypes. Our method accurately identifies client cluster identities during the initialization phase. Clients employ the same randomly initialized model to compute the client’s prototypes for their local data and provide it to the server. The server performs one-shot client clustering by comparing the similarity of the client’s prototypes. We further design a unique inter-cluster aggregation strategy that adapts inter-cluster aggregation weights based on the similarity of the client’s prototypes, thereby enhancing model convergence. We evaluate two mixed datasets with three Non-IID settings, and our approach outperforms several popular baseline methods. Compared to IFCA and FlexCFL, our approach yields more reasonable clustering results. It achieves an average test accuracy improvement of over 11.51% in the feature and label shift Non-IID setting of the Digits-5 dataset. Weimin Lai, Zirong Xu, Qiao Yan |
CSCWD | 3 |
| 2024 | FedPGT: Prototype-based Federated Global Adversarial Training against Adversarial AttackabstractFederated learning, an innovative distributed machine learning paradigm, is designed to address critical concerns related to data silos and user data privacy breaches. However, it faces a significant challenge in the form of adversarial attacks. Recent research has attempted to mitigate this issue through techniques such as local adversarial training and model distillation. Nevertheless, these approaches are susceptible to real-world variations, ultimately leading to compromised adversarial robustness. In this paper, we propose FedPGT, an innovative approach that employs clustering techniques to assess the convergence of the model. By leveraging a prototype-based method, it guides high-quality adversarial training. FedPGT alleviates the issue of data heterogeneity in federated learning and enhances the model’s adversarial robustness. Our experimental results, conducted across three distinct datasets (MNIST, FMNIST, and EMNIST-Digits), demonstrate the efficacy of FedPGT. Zirong Xu, Weimin Lai, Qiao Yan |
CSCWD | 3 |
| 2024 | Boosting the transferability of adversarial CAPTCHAs
Zisheng Xu, Qiao Yan |
Comput. Secur. | 2 |
| 2024 | Detect malicious websites by building a neural network to capture global and local features of websites
Longwen Zhang, Qiao Yan |
Comput. Secur. | 2 |
| 2023 | RPF3D: Range-Pillar Feature Deep Fusion 3D Detector for Autonomous Driving
Yihan Wang 0009, Qiao Yan |
ICONIP (3) | 2 |
| 2023 | MVFAN: Multi-view Feature Assisted Network for 4D Radar Object Detection
Qiao Yan, Yihan Wang 0009 |
ICONIP (4) | 1 |
| 2023 | LB-L2L-Calib 2.0: A Novel Online Extrinsic Calibration Method for Multiple Long Baseline 3D LiDARs Using ObjectsabstractIn V2X (Vehicle-to-Everything), one important work is to extrinsically calibrate multiple 3D LiDARs, which are mounted with a long baseline and large viewpoint-difference at the road-side. Current solutions either require a specific target being set up (e.g., a sphere), or require specific features existing in the environment (e.g., mutually orthogonal planes). However, it is time-consuming, sometimes even inconvenient, to set up specific targets, e.g., at busy intersections and highways. Furthermore, specific features do not always exist in the traffic scenario. Thus, the current solutions are not feasible. To address this problem, a novel extrinsic calibration method is proposed in this paper, namely LB-L2L-Calib 2.0. It is the 2.0 version of our previous work. The novelties are: 1) We propose to use the easily accessible objects on the road as features for calibration (i.e., the vehicles). Thus, it is not necessary to set up any specific targets and we do not need to worry whether specific features exist or not. The key point is we observed that the 3D bounding box centers of the vehicles are viewpoint-invariant from different viewpoints, which makes them ideal features for long baseline and large viewpoint-difference calibration. 2) To establish correct correspondence between the bounding box centers detected from different LiDARs, we propose an exhaustive searching strategy. It can robustly output correct correspondence. Extensive experiments are performed in three scenarios (simulation: intersection, real: carpark and highway), with two types of LiDAR (Velodyne and Livox), demonstrating that LB-L2L-Calib 2.0 is robust, effective, and accurate. Jun Zhang 0042, Qiao Yan, Mingxing Wen, Qiyang Lyu, Guohao Peng, Zhenyu Wu 0001, Danwei Wang |
IROS | 2 |
| 2022 | LB-L2L-Calib: Accurate and Robust Extrinsic Calibration for Multiple 3D LiDARs with Long Baseline and Large Viewpoint DifferenceabstractMulti-LiDAR system is an important part of V2X (Vehicle to Everything) to enhance the perception information for unmanned vehicles. To fuse the information from multiple 3D LiDARs, accurate extrinsic calibration between the LiDARs is essential. However, the existing multi-LiDAR calibration methods mainly focus on short baseline scenarios, where multiple LiDARs are closely mounted on a single platform (e.g., an unmanned vehicle). Besides, most methods typically use a planar target for calibration. Some of the methods require the motion of the multi-LiDAR system. The above conditions severely limit the application of these methods to V2X, where LiDARs are non-movable, the baseline and viewpoint difference between the LiDARs can be very large. In order to meet these challenges, we propose an accurate and robust extrinsic calibration method for long baseline multi-LiDAR systems, named LB-L2L-Calib (Large Baseline LiDAR to LiDAR extrinsic Calibration). (1) We use a sphere as the calibration target for multiple LiDARs with large viewpoint difference, leveraging the viewpoint-invariance of the sphere. (2) A improved sphere detection and sphere center estimation strategy is introduced to detect and extract the sphere center from a cluttered point cloud in large-scale outdoor scenario. (3) A extrinsic parameter regression scheme is introduced. Both simulation and real experiments demonstrate that LB-L2L-Calib is highly accurate and robust. Quantitative results show that the rotation and translation error is less than 0.01m and 0.01° (in simulation, Gauss noise 0.03m, the distance and viewpoint difference between two LiDARs is more than 30m and 90°). Jun Zhang 0042, Qiyang Lyu, Guohao Peng, Zhenyu Wu 0001, Qiao Yan, Danwei Wang |
ICRA | 5 |
| 2022 | HDP-CNN: Highway deep pyramid convolution neural network combining word-level and character-level representations for phishing website detection
Faan Zheng, Qiao Yan, Victor C. M. Leung, F. Richard Yu, Zhong Ming 0001 |
Comput. Secur. | 2 |
| 2022 | ECC-based lightweight authentication and access control scheme for IoT E-healthcare
Hailong Yao 0001, Qiao Yan, Xingbing Fu, Caihui Lan |
Soft Comput. | 2 |
| 2022 | Gradient Feature-Oriented 3-D Domain Adaptation for Hyperspectral Image ClassificationabstractDomain adaptation, which cleverly applies the classifier learned from the source domain with sufficient labeled samples to the target domain with limited labeled samples, provides a feasible alternative to handle the small training sample problem of hyperspectral image (HSI) classification and has attracted much attention in the research field recently. Apparently, feature discriminative ability is vital for domain adaptation, which plays a crucial role during the migration process of transfer learning. In this article, a gradient feature-oriented 3-D domain adaptation (GF-3DDA) approach is proposed for HSI classification. First, 3-D Gabor is employed to remove noise from the original data, and two 2-D gradient-based features, 2-D Sobel gradient (SG) and 2-D derivative-of-Gaussian (DtG), are extended to the 3-D domain to coincide with the integrated spatial–spectral organization of HSI. Thus, the 3-D Sobel–Gabor gradient (3DSGG) and 3-D derivative-of-Gaussian-Gabor (3DDGG) features are achieved. Second, a 3-D domain adaptation method is implemented to jointly exploit the second- and fourth-order statistical descriptors in the spatial–spectral dimensions, which could effectively reduce domain shifts and thus achieve improved domain adaptation. Third, all the extracted domain-adapted feature modules are collaboratively classified by extreme learning machine (ELM), and the probability-like outputs of every ELM classifier are combined together to accomplish the classification task. Four hyperspectral data sets that each contains two scenes, i.e., Pavia, Shanghai–Hangzhou, Indiana, and Houston, are tested in the experiments. When only ten labeled samples per class are used in the target domain, the classification accuracies on four hyperspectral data sets achieved by our GF-3DDA approach are 93.31%, 84.35%, 69.32%, and 80.06%, respectively. Sen Jia 0001, Meng Xu 0002, Qiao Yan, Jun Zhou 0001, Xiuping Jia, Qingquan Li 0001 |
IEEE Trans. Geosci. Remote. Sens. | 4 |
| 2021 | The impact of propagation delay to different selfish miners in proof-of-work blockchains
Heli Wang, Qiao Yan, Victor C. M. Leung |
Peer-to-Peer Netw. Appl. | 2 |
| 2019 | An Improved MCB Localization Algorithm Based on Received Signal Strength IndicatorabstractAn improved Monte Carlo Localization Boxed (MCB) localization Algorithm based on received signal strength indicator (RSSI) for mobile wireless sensor networks node localization is proposed. Aiming at the characteristics of instantaneity, mobility and complexity of mobile node location, this algorithm combines RSSI ranging model with MCL algorithm which has high positioning accuracy, good performance and wide application. It establishes anchor node sampling box by using the actual distance of signal propagation obtained, and effectively reduces the sampling range. The simulation results show that this algorithm improves the sampling efficiency, shortens the sampling time, and increases the positioning accuracy compared to the MCL algorithm. It is a low-cost, low-power and low-complexity localization algorithm without additional hardware and communication overhead. Qiao Yan, Chunyue Zhou, Baitong Zhong, Hui Tian 0001 |
PDCAT | 1 |
| 2018 | Joint Offloading and Resource Allocation in Mobile Edge Computing Systems: An Actor-Critic ApproachabstractOffloading computationally intensive tasks from user equipments (UEs) to mobile edge computing (MEC) servers is a promising technique to boost up the computational capacity of UEs. However, MEC will incur extra energy consumption and time delays, which motivates the deployment of energy harvesting (EH) small cell networks with MEC in mobile networks. Due to the complexity of such networks, it is challenging to effectively allocate resources for UEs. In this paper, we investigate the offloading decision, wireless and computational resources allocation problem in energy harvesting (EH) small cell networks with MEC. Different from existing literatures, our research focuses on improving mobile operators' revenue by maximizing the amount of the offloaded tasks while decreasing the energy expenditure and time-delays. Besides, queues are created at the MEC server side to store the un-executed tasks in a time slot, which is used as a punishment in our utility function to avoid serious delay. Considering the varying lengths of queues, the states of EH-batteries of small base stations (SBSs) and down-link channels, the above problem is modeled as a Markov decision process (MDP). Since the states and actions in the MDP are infinite, an online and on-policy actor-critic with eligibility traces algorithm is proposed to resolve the problem. Simulation results show the proposed algorithm has superior performances compared with the policy-gradient algorithm and Q-learning. Zhicai Zhang, F. Richard Yu, Fang Fu, Qiao Yan, Zhouyang Wang |
GLOBECOM | 4 |
| 2018 | A novel context-aware recommendation algorithm with two-level SVD in social networks
Laizhong Cui, Wenyuan Huang, Qiao Yan, F. Richard Yu, Zhenkun Wen |
Future Gener. Comput. Syst. | 3 |
| 2018 | DDSE: A novel evolutionary algorithm based on degree-descending search strategy for influence maximization in social networks
Laizhong Cui, Huaixiong Hu, Shui Yu 0001, Qiao Yan, Zhong Ming 0001, Zhenkun Wen |
J. Netw. Comput. Appl. | 4 |
| 2017 | A Multi-Objective Evolutionary Cloud Leasing Algorithm for Cloud and Peer Assisted VoD SystemsabstractAlthough the combination of cloud and Peer-to- Peer (P2P) can leverage the performance of video on demand (VoD) system, there has been no mature solution for the cloud leasing strategy for the cloud and peer assisted VoD system. It is hard to get a balance between the operating cost of content provider and the user experience. In this paper, we first model the operating cost and the delay cost. And then, we propose an optimal cloud leasing algorithm based on a well-known multi- objective optimization algorithm NSGA-II to select the most suitable cloud storage server for the requester. Compared with other multi-objective optimization algorithm, i.e. SPEA and linear programming, the experimental results show that our proposed algorithm based on NSGA-II can effectively reduce the operating cost of content provider, without compromising the user's viewing experience. Laizhong Cui, Lei-Gen Cheng, Yong Jiang 0001, Qiao Yan |
GLOBECOM | 4 |
| 2017 | Securing Outsourced Data in the Multi-Authority Cloud with Fine-Grained Access Control and Efficient Attribute RevocationabstractData outsourcing is a promising service for data owners, where their data are stored on a cloud storage provider. Since the cloud is not fully trusted, data access control has become a challenging issue in the Cloud Storage System (CSS). Ciphertext-Policy Attribute-Based Encryption (CP-ABE) is a feasible technique for ensuring access control in the CSS, where an attribute authority is responsible to manage attributes and distribute keys. In this paper, we propose a novel revocable Multi-Authority CP-ABE scheme, in which the access policy can be constructed as an arbitrary tree rather than a matrix used by existing schemes. The tree-like policy makes our scheme more flexible. Consequently, the encryption, decryption and attribute revocation operations are also more efficient. Our scheme is also proved to be secure under the standard assumption. It can resist user collusion attack, while the attribute revocation operation also achieves both forward security and backward security. Simulation results show that our scheme is highly efficient. Junwei Zhou 0002, Hui Duan, Kaitai Liang, Qiao Yan, Fei Chen 0003, F. Richard Yu, Jieming Wu, Jianyong Chen |
Comput. J. | 4 |
| 2016 | Adaptive composite operator selection and parameter control for multiobjective evolutionary algorithm
Qiuzhen Lin, Zhiwang Liu, Qiao Yan, Zhihua Du, Carlos A. Coello Coello, Zhengping Liang, Wenjun Wang 0003, Jianyong Chen |
Inf. Sci. | 3 |
| 2011 | A probe prediction approach to overlay network monitoring
Shun-an Wu, Qiao Yan, Xuesong Qiu 0001, Yanjie Ren |
CNSM | 2 |
| 2008 | An interactive co-evolutionary CAD system for garment pattern design
Zhi-Hua Hu, Yongsheng Ding, Qiao Yan |
Comput. Aided Des. | 4 |