Yufei Han 0001

dblp:74/2507-1 · DBLP profile ↗
← Back
45ranked-venue papers
5as first author
34since 2021 · last 2026
0000-0002-9035-6718ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 28 · 1 first-author · 25 since 2021Artificial intelligence and machine learning · 17 · 4 first-author · 9 since 2021Databases, data management, data science and information retrieval · 8 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 2 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Robustness Evaluation of Graph Neural Network-Based Network Intrusion Detection Systems against Adversarial Flow Injection
abstract
International audience
Matthieu Mouzaoui, Yufei Han 0001, Gregory Blanc, Gabriel Rilling, Michel Hurfin
SECRYPT (1)2
2026 Graph2TTP: Knowledge Graph-Guided Paragraph-Level TTPs Identification from Cyber Threat Intelligence Reports
Patrick Zounon, Yufei Han 0001, Michel Hurfin, Frédéric Majorczyk
SECRYPT (1)2
2026 Trust Under Siege: Label Spoofing Attacks Against Machine Learning for Android Malware Detection
abstract
Machine Learning (ML) malware detectors rely heavily on crowd-sourced AntiVirus (AV) labels, with platforms like VirusTotal serving as trusted sources of malware annotations. But what if attackers could manipulate these labels to classify benign software as malicious? We introduce label spoofing attacks, a new threat that contaminates crowd-sourced datasets by embedding minimal and undetectable malicious patterns into benign samples. These patterns coerce AV engines into misclassifying legitimate files as harmful, enabling poisoning attacks against ML-based malware classifiers trained on those data. We demonstrate this scenario by developing AndroVenom, a methodology for polluting realistic data sources and launching subsequent poisoning attacks against ML malware detectors. Experiments show that not only are state-of-the-art feature extractors unable to filter such injections, but various ML models experience Denial-of-Service (DoS) with as little as 1% poisoned samples. Additionally, attackers can flip decisions for specific unaltered benign samples by modifying only 0.015% of the training data, threatening their reputation and market share, while evading anomaly detectors operating on the training data. We conclude by raising concerns about the trustworthiness of ML training processes based on AV annotations and argue that further investigation is needed to develop more reliable labeling strategies.
Tianwei Lan, Luca Demetrio, Farid Naït-Abdesselam, Yufei Han 0001, Simone Aonzo
IEEE Trans. Inf. Forensics Secur.4
2025 PROTEAN: Federated Intrusion Detection in Non-IID Environments Through Prototype-Based Knowledge Sharing
Sara Chennoufi, Yufei Han 0001, Gregory Blanc, Emiliano De Cristofaro, Christophe Kiennert
ESORICS (1)2
2025 From Risk to Resilience: Towards Assessing and Mitigating the Risk of Data Reconstruction Attacks in Federated Learning
Xiangrui Xu 0001, Zhize Li 0001, Yufei Han 0001, Bin Wang 0062, Jiqiang Liu, Wei Wang 0012
USENIX Security Symposium3
2025 RobustPFL: Robust Personalized Federated Learning
abstract
Conventional federated learning (FL) coordinated by a central server focuses on training a global model and protecting the privacy of clients' training data by storing it locally. However, the statistical heterogeneity hinders the global model from adapting to the non-IID distributions among clients. Moreover, untrusted and unreliable central servers and malicious clients may compromise model integrity and availability, thus degrading the robustness of FL. To address these challenges, we present RobustPFL, a decentralized personalized federated learning (PFL) approach that combines$\alpha$-based Layer-position Normalized Similarity ($\alpha$-LNS) and local collaborative training to improve personalized performance while utilizing a blockchain-based committee mechanism to coordinate the aggregation process, thereby achieving high personalized accuracy and robustness. Extensive experiments show that our RobustPFL approach outperforms multiple algorithms, including Local training, FedAvg, FedReptile, Per-FedAvg, FedBN, and SPFL, on MNIST, CIFAR10, EMNIST, and N-BaIoT datasets in four non-IID settings. We also evaluate RobustPFL's effectiveness against attacks—poisoning attacks and free-riding attacks. Particularly, for three prevalent poisoning attacks (backdoor, label flipping, and model poisoning attacks), we compare non-defensive (FedAvg) and defensive (Krum, trimmed mean, Bulyan, FedBN, FLAME, and FangTrmean) methods with our proposed RobustPFL. The results show that our approach achieves significant defensive effects.
Wei Wang 0012, Yufang Wu, Chao Li 0023, Guangquan Xu, Shouling Ji, Tao Li 0022, Meng Shen 0001, Yufei Han 0001
IEEE Trans. Dependable Secur. Comput.9
2025 CoBA: Collusive Backdoor Attacks With Optimized Trigger to Federated Learning
abstract
Considerable efforts have been devoted to addressing distributed backdoor attacks in federated learning (FL) systems. While significant progress has been made in enhancing the security of FL systems, our study reveals that there remains a false sense of security surrounding FL. We demonstrate that colluding malicious participants can effectively execute backdoor attacks during the FL training process, exhibiting high sparsity and stealthiness, which means they can evade common defense methods with only a few attack iterations. Our research highlights this vulnerability by proposing aCollusiveBackdoorAttack namedCoBA.CoBAis designed to enhance the sparsity and stealthiness of backdoor attacks by offering trigger tuning to facilitate learning of backdoor training data, controlling the bias of malicious local model updates, and applying the projected gradient descent technique. By conducting extensive empirical studies on 5 benchmark datasets, we make the following observations: 1)CoBAsuccessfully circumvents 15 state-of-the-art defense methods for robust FL; 2) Compared to existing backdoor attacks,CoBAconsistently achieves superior attack performance; and 3)CoBAcan achieve persistent poisoning effects through significantly sparse attack iterations. These findings raise substantial concerns regarding the integrity of FL and underscore the urgent need for heightened vigilance in defending against such attacks.
Xiaoting Lyu, Yufei Han 0001, Wei Wang 0012, Jingkai Liu, Bin Wang 0062, Kai Chen 0012, Yidong Li, Jiqiang Liu, Xiangliang Zhang 0001
IEEE Trans. Dependable Secur. Comput.2
2025 Finding the PISTE: Towards Understanding Privacy Leaks in Vertical Federated Learning Systems
abstract
Vertical Federated Learning (VFL) is a collaborative learning paradigm where participants share the same sample space while splitting the feature space. In VFL, local participants host their bottom models for feature extraction and collaboratively train a classifier by exchanging intermediate results with the server owning the labels. Both local training data and bottom models contain privacy-sensitive information and are considered the intellectual property of each participant, and thus should be protected by the design of VFL. Our study exposes the fundamental susceptibility of VFL systems to privacy leaks, which arise from the collaboration between the server and clients during both training and testing. Based on our findings, we proposePISTE, a model-agnostic framework of privacy stealing attacks against VFL. PISTE delivers three privacy inference attacks, i.e., model stealing, data reconstruction, and property inference attacks on five benchmark datasets and four different model architectures. We further discuss four potential countermeasures. Experimental results show that all of them cannot prevent all three privacy stealing attacks in PISTE. In summary, our study demonstrates the inherent yet rarely uncovered vulnerability of VFL on leaking data and model privacy.
Xiangrui Xu 0001, Wei Wang 0012, Bin Wang 0062, Chao Li 0023, Zhen Han 0001, Yufei Han 0001
IEEE Trans. Dependable Secur. Comput.8
2025 VFLMonitor: Defending One-Party Hijacking Attacks in Vertical Federated Learning
abstract
Vertical Federated Learning (VFL) is susceptible to various one-party hijacking attacks, such as Replay and Generation attacks, where a single malicious client can manipulate the model to produce attacker-specified results, thereby compromising its reliability in real-world deployments. In this paper, we first uncover the underlying mechanisms of these attacks and observe that successful attacks induce significant discrepancies in the embedding-label associations across different clients. We establish a theoretical framework demonstrating how these discrepancies can serve as reliable indicators for detecting hijacking attempts. Building upon this insight, we propose VFLMonitor, a robust defense mechanism that leverages these embedding-label discrepancies to detect and mitigate hijacking attacks. Specifically, VFLMonitor identifies suspicious queries by analyzing differences in label estimations from multiple clients and applies a majority voting rule to correct or filter out these malicious queries. Moreover, VFLMonitor introduces a novel regularization strategy during training to reduce intra-class variance in embeddings, thereby enhancing their discriminative power and improving defense effectiveness. Extensive experi21 ments were conducted on 5 real-world datasets against 2 different attack types under 3 attack scenarios. The results demonstrate that VFLMonitor can effectively identify and exclude potential hijacked requests in all types of one-party hijacking attacks, while maintaining a meager false positive rate for legitimate queries.
Xiangrui Xu 0001, Yufei Han 0001, Yongsheng Zhu, Zhen Han 0001, Guangquan Xu, Bin Wang 0062, Shouling Ji, Wei Wang 0012
IEEE Trans. Inf. Forensics Secur.3
2024 Defending Jailbreak Prompts via In-Context Adversarial Game
abstract
Large Language Models (LLMs) demonstrate remarkable capabilities across diverse applications.However, concerns regarding their security, particularly the vulnerability to jailbreak attacks, persist.Drawing inspiration from adversarial training in deep learning and LLM agent learning processes, we introduce the In-Context Adversarial Game (ICAG) for defending against jailbreaks without the need for fine-tuning.ICAG leverages agent learning to conduct an adversarial game, aiming to dynamically extend knowledge to defend against jailbreaks.Unlike traditional methods that rely on static datasets, ICAG employs an iterative process to enhance both the defense and attack agents.This continuous improvement process strengthens defenses against newly generated jailbreak prompts.Our empirical studies affirm ICAG's efficacy, where LLMs safeguarded by ICAG exhibit significantly reduced jailbreak success rates across various attack scenarios.Moreover, ICAG demonstrates remarkable transferability to other LLMs, indicating its potential as a versatile defense mechanism.The code is available at https://github.com/YujunZhou/ In-Context-Adversarial-Game.28 1 82 8 8 28 3 31 9 2 1 92 82 3 31 2 98 !" "1 3"1 28 1 82 8 8 28 3 31 # $ % # &81 !" ' " 2("2 1 % 28 1 82 8 8 28 3 31 01 23 56 781 92 81 2 8 6 9 2 1 92 82 3 31 2 98 !" "1 3"1 28 1 82 8 8 28 3 31 # $ % # &81 !" ' " 2("2 1 % "&&2 !" 8 28 1 8 8 28 "&&2 !" ) "1 ! 8 2 8 28 1 8 ! 8 2) 9 *+8& 91 ,8 2 *+8& 91 ) 2'2 ! 8 2 8 28% 2 8 28 3 31 28 1 82 8 2 8 28 3 31 01 23 56 781 92 81 2 8 6 "5-.2! 2 2 "/-*+8& *+8&2 .2! 22 .2! 2 2 001 *+8& 001 .2! 2 2 * 1 81 001 (a) Self Reminder 01 23 56 781 92 81 2 8 6 28 1 82 8 8 28 3 31 9 2 1 92 82 3 31 2 98 !" "1 3"1 28 1 82 8 8 28 3 31 # $ % # &81 !" ' " 2("2 1 % 28 1 82 8 8 28 3 31 01 23 56 781 92 81 2 8 6 9 2 1 92 82 3 31 2 98 !" "1 3"1 28 1 82 8 8 28 3 31 # $ % # &81 !" ' " 2("2 1 % "&&2 !" 8 28 1 8 8 28 "&&2 !" ) "1 ! 8 2 8 28 1 8 ! 8 2) 9 *+8& 91 ,8 2 *+8& 91 ) 2'2 ! 8 2 8 28% 2 8 28 3 31 28 1 82 8 2 8 28 3 31 01 23 56 781 92 81 2 8 6 "5-.2! 2 2 "/-*+8& *+8&2 .2! 22 .2! 2 2 001 *+8& 001 .2! 2 2 * 1 81 001 (b) Our proposed In-Context Adversarial Game 0 1 2 :. 1 9 2 15 9 5 5 4-2 1*"1.9 "1 7 2 1!9 9 4 0 1 2 *"1.9 "1 7 : 2 1!9 9 4 0 1 2 : 7 :.7 18 4-9 9 -9 7 :C., 49 -99 1 =2 9 7 ::.7 49 9 ; 9 45 4 9 A49 5 :.B A49 5 :C.7 * 7 :2 1 2 1 7 :.7 18 4-9 9 -9 ,!! 57 7 :
Yujun Zhou 0002, Yufei Han 0001, Haomin Zhuang, Kehan Guo, Zhenwen Liang, Hongyan Bao, Xiangliang Zhang 0001
EMNLP2
2024 Attack-free Evaluating and Enhancing Adversarial Robustness on Categorical Data
abstract
Research on adversarial robustness has predominantly focused on continuous inputs, leaving categorical inputs, especially tabular attributes, less examined. To echo this challenge, our work aims to evaluate and enhance the robustness of classification over categorical attributes against adversarial perturbations through efficient attack-free approaches. We propose a robustness evaluation metric named Integrated Gradient-Smoothed Gradient (IGSG). It is designed to evaluate the attributional sensitivity of each feature and the decision boundary of the classifier, two aspects that significantly influence adversarial risk, according to our theoretical analysis. Leveraging this metric, we develop an IGSG-based regularization to reduce adversarial risk by suppressing the sensitivity of categorical attributes. We conduct extensive empirical studies over categorical datasets of various application domains. The results affirm the efficacy of both IGSG and IGSG-based regularization. Notably, IGSG-based regularization surpasses the state-of-the-art robust training methods by a margin of approximately 0.4% to 12.2% on average in terms of adversarial accuracy, especially on high-dimension datasets. The code is available at https://github.com/YujunZhou/IGSG.
Yujun Zhou 0002, Yufei Han 0001, Haomin Zhuang, Hongyan Bao, Xiangliang Zhang 0001
ICML2
2024 Cross-Context Backdoor Attacks against Graph Prompt Learning
abstract
Graph Prompt Learning (GPL) bridges significant disparities between pretraining and downstream applications to alleviate the knowledge transfer bottleneck in real-world graph learning. While GPL offers superior effectiveness in graph knowledge transfer and computational efficiency, the security risks posed by backdoor poisoning effects embedded in pretrained models remain largely unexplored. Our study provides a comprehensive analysis of GPL's vulnerability to backdoor attacks. We introduce CrossBA, the first cross-context backdoor attack against GPL, which manipulates only the pretraining phase without requiring knowledge of downstream applications. Our investigation reveals both theoretically and empirically that tuning trigger graphs, combined with prompt transformations, can seamlessly transfer the backdoor threat from pretrained encoders to downstream applications.Through extensive experiments involving 3 representative GPL methods across 5 distinct cross-context scenarios and 5 benchmark datasets of node and graph classification tasks, we demonstrate that CrossBA consistently achieves high attack success rates while preserving the functionality of downstream applications over clean input. We also explore potential countermeasures against CrossBA and conclude that current defenses are insufficient to mitigate CrossBA. Our study highlights the persistent backdoor threats to GPL systems, raising trustworthiness concerns in the practices of GPL techniques.
Xiaoting Lyu, Yufei Han 0001, Wei Wang 0012, Hangwei Qian, Ivor W. Tsang, Xiangliang Zhang 0001
KDD2
2024 DYNAMO: Towards Network Attack Campaign Attribution via Density-Aware Active Learning
abstract
International audience
Helene Orsini, Yufei Han 0001
SECRYPT2
2024 SCWAD: Automated Pentesting of Web Applications
abstract
International audience
Natan Talon, Valérie Viet Triem Tong, Gilles Guette, Yufei Han 0001, Youssef Laarouchi
SECRYPT4
2024 BadVFL: Backdoor Attacks in Vertical Federated Learning
abstract
Federated learning (FL) enables multiple parties to collaboratively train a machine learning model without sharing their data; rather, they train their own model locally and send updates to a central server for aggregation. Depending on how the data is distributed among the participants, FL can be classified into Horizontal (HFL) and Vertical (VFL). In VFL, the participants share the same set of training instances but only host a different and non-overlapping subset of the whole feature space. Whereas in HFL, each participant shares the same set of features while the training set is split into locally owned training data subsets.VFL is increasingly used in applications like financial fraud detection; nonetheless, very little work has analyzed its security. In this paper, we focus on robustness in VFL, in particular, on backdoor attacks, whereby an adversary attempts to manipulate the aggregate model during the training process to trigger misclassifications. Performing backdoor attacks in VFL is more challenging than in HFL, as the adversary i) does not have access to the labels during training and ii) cannot change the labels as she only has access to the feature embeddings. We present a first-of-its-kind clean-label backdoor attack in VFL, which consists of two phases: a label inference and a backdoor phase. We demonstrate the effectiveness of the attack on three different datasets, investigate the factors involved in its success, and discuss countermeasures to mitigate its impact.
Mohammad Naseri, Yufei Han 0001, Emiliano De Cristofaro
SP2
2024 Lurking in the shadows: Unveiling Stealthy Backdoor Attacks against Personalized Federated Learning
Xiaoting Lyu, Yufei Han 0001, Wei Wang 0012, Jingkai Liu, Yongsheng Zhu, Guangquan Xu, Jiqiang Liu, Xiangliang Zhang 0001
USENIX Security Symposium2
2024 BFS2Adv: Black-box adversarial attack towards hard-to-attack short texts
Qiang Li 0007, Hongbo Cao, Bin Wang 0062, Xuhua Bao, Yufei Han 0001, Wei Wang 0012
Comput. Secur.7
2023 Towards Efficient and Domain-Agnostic Evasion Attack with High-Dimensional Categorical Inputs
abstract
Our work targets at searching feasible adversarial perturbation to attack a classifier with high-dimensional categorical inputs in a domain-agnostic setting. This is intrinsically a NP-hard knapsack problem where the exploration space becomes explosively larger as the feature dimension increases. Without the help of domain knowledge, solving this problem via heuristic method, such as Branch-and-Bound, suffers from exponential complexity, yet can bring arbitrarily bad attack results. We address the challenge via the lens of multi-armed bandit based combinatorial search. Our proposed method, namely FEAT, treats modifying each categorical feature as pulling an arm in multi-armed bandit programming. Our objective is to achieve highly efficient and effective attack using an Orthogonal Matching Pursuit (OMP)-enhanced Upper Confidence Bound (UCB) exploration strategy. Our theoretical analysis bounding the regret gap of FEAT guarantees its practical attack performance. In empirical analysis, we compare FEAT with other state-of-the-art domain-agnostic attack methods over various real-world categorical data sets of different applications. Substantial experimental observations confirm the expected efficiency and attack effectiveness of FEAT applied in different application scenarios. Our work further hints the applicability of FEAT for assessing the adversarial vulnerability of classification systems with high-dimensional categorical inputs.
Hongyan Bao, Yufei Han 0001, Yujun Zhou 0002, Xin Gao 0001, Xiangliang Zhang 0001
AAAI2
2023 Poisoning with Cerberus: Stealthy and Colluded Backdoor Attack against Federated Learning
abstract
Are Federated Learning (FL) systems free from backdoor poisoning with the arsenal of various defense strategies deployed? This is an intriguing problem with significant practical implications regarding the utility of FL services. Despite the recent flourish of poisoning-resilient FL methods, our study shows that carefully tuning the collusion between malicious participants can minimize the trigger-induced bias of the poisoned local model from the poison-free one, which plays the key role in delivering stealthy backdoor attacks and circumventing a wide spectrum of state-of-the-art defense methods in FL. In our work, we instantiate the attack strategy by proposing a distributed backdoor attack method, namely Cerberus Poisoning (CerP). It jointly tunes the backdoor trigger and controls the poisoned model changes on each malicious participant to achieve a stealthy yet successful backdoor attack against a wide spectrum of defensive mechanisms of federated learning techniques. Our extensive study on 3 large-scale benchmark datasets and 13 mainstream defensive mechanisms confirms that Cerberus Poisoning raises a significantly severe threat to the integrity and security of federated learning practices, regardless of the flourish of robust Federated Learning methods.
Xiaoting Lyu, Yufei Han 0001, Wei Wang 0012, Jingkai Liu, Bin Wang 0062, Jiqiang Liu, Xiangliang Zhang 0001
AAAI2
2023 Decoding the Secrets of Machine Learning in Malware Classification: A Deep Dive into Datasets, Feature Extraction, and Model Performance
abstract
Many studies have proposed machine-learning (ML) models for malware detection and classification, reporting an almost-perfect performance. However, they assemble ground-truth in different ways, use diverse static- and dynamic-analysis techniques for feature extraction, and even differ on what they consider a malware family. As a consequence, our community still lacks an understanding of malware classification results: whether they are tied to the nature and distribution of the collected dataset, to what extent the number of families and samples in the training dataset influence performance, and how well static and dynamic features complement each other.
Savino Dambra, Yufei Han 0001, Simone Aonzo, Platon Kotzias, Antonino Vitale, Juan Caballero, Davide Balzarotti, Leyla Bilge
CCS2
2023 Towards Understanding Alerts raised by Unsupervised Network Intrusion Detection Systems
abstract
The use of Machine Learning for anomaly detection in cyber security-critical applications, such as intrusion detection systems, has been hindered by the lack of explainability. Without understanding the reason behind anomaly alerts, it is too expensive or impossible for human analysts to verify and identify cyber-attacks. Our research addresses this challenge and focuses on unsupervised network intrusion detection, where only benign network traffic is available for training the detection model. We propose a novel post-hoc explanation method, called AE-pvalues, which is based on the p-values of the reconstruction errors produced by an Auto-Encoder-based anomaly detection method. Our work identifies the most informative network traffic features associated with an anomaly alert, providing interpretations for the generated alerts. We conduct an empirical study using a large-scale network intrusion dataset, CICIDS2017, to compare the proposed AE-pvalues method with two state-of-the-art baselines applied in the unsupervised anomaly detection task. Our experimental results show that the AE-pvalues method accurately identifies abnormal influential network traffic features. Furthermore, our study demonstrates that the explanation outputs can help identify different types of network attacks in the detected anomalies, enabling human security analysts to understand the root cause of the anomalies and take prompt action to strengthen security measures.
Maxime Lanvin, Pierre-François Gimenez, Yufei Han 0001, Frédéric Majorczyk, Ludovic Mé, Eric Totel
RAID3
2023 BAGUETTE: Hunting for Evidence of Malicious Behavior in Dynamic Analysis Reports
abstract
International audience
Vincent Raulin, Pierre-François Gimenez, Yufei Han 0001, Valérie Viet Triem Tong
SECRYPT3
2023 Humans vs. Machines in Malware Classification
Simone Aonzo, Yufei Han 0001, Alessandro Mantovani, Davide Balzarotti
USENIX Security Symposium2
2023 CGIR: Conditional Generative Instance Reconstruction Attacks Against Federated Learning
abstract
Data reconstruction attack has become an emerging privacy threat to Federal Learning (FL), inspiring a rethinking of FL's ability to protect privacy. While existing data reconstruction attacks have shown some effective performance, prior arts rely on different strong assumptions to guide the reconstruction process. In this work, we propose a novel Conditional Generative Instance Reconstruction Attack (CGIR attack) that drops all these assumptions. Specifically, we propose a batch label inference attack in non-IID FL scenarios, where multiple images can share the same labels. Based on the inferred labels, we conduct a “coarse-to-fine” image reconstruction process that provides a stable and effective data reconstruction. In addition, we equip the generator with a label condition restriction so that the contents and the labels of the reconstructed images are consistent. Our extensive evaluation results on two model architectures and five image datasets show that without the auxiliary assumptions, the CGIR attack outperforms the prior arts, even for complex datasets, deep models, and large batch sizes. Furthermore, we evaluate several existing defense methods. The experimental results suggest that pruning gradients can be used as a strategy to mitigate privacy risks in FL if a model tolerates a slight accuracy loss.
Xiangrui Xu 0001, Pengrui Liu, Wei Wang 0012, Hongliang Ma, Bin Wang 0062, Zhen Han 0001, Yufei Han 0001
IEEE Trans. Dependable Secur. Comput.7
2022 AdvCat: Domain-Agnostic Robustness Assessment for Cybersecurity-Critical Applications with Categorical Inputs
abstract
Machine Learning-as-a-Service systems (MLaaS) have been largely developed for cybersecurity-critical applications, such as detecting network intrusions and fake news campaigns. Despite effectiveness, their robustness against adversarial attacks is one of the key trust concerns for MLaaS deployment. We are thus motivated to assess the adversarial robustness of the Machine Learning models residing at the core of these securitycritical applications with categorical inputs. Previous research efforts on accessing model robustness against manipulation of categorical inputs are specific to use cases and heavily depend on domain knowledge, or require white-box access to the target ML model. Such limitations prevent the robustness assessment from being as a domain-agnostic service provided to various real-world applications. We propose a provably optimal yet computationally highly efficient adversarial robustness assessment protocol for a wide band of ML-driven cybersecurity-critical applications. We demonstrate the use of the domain-agnostic robustness assessment method with substantial experimental study on fake news detection and intrusion detection problems.
Helene Orsini, Hongyan Bao, Yujun Zhou 0002, Xiangrui Xu 0001, Yufei Han 0001, Longyang Yi, Wei Wang 0012, Xin Gao 0001, Xiangliang Zhang 0001
IEEE Big Data5
2022 CERBERUS: Exploring Federated Prediction of Security Events
abstract
Modern defenses against cyberattacks increasingly rely on proactive approaches, e.g., to predict the adversary's next actions based on past events. Building accurate prediction models requires knowledge from many organizations; alas, this entails disclosing sensitive information, such as network structures, security postures, and policies, which might often be undesirable or outright impossible.
Mohammad Naseri, Yufei Han 0001, Enrico Mariconti, Gianluca Stringhini, Emiliano De Cristofaro
CCS2
2022 Finding MNEMON: Reviving Memories of Node Embeddings
abstract
Previous security research efforts orbiting around graphs have been exclusively focusing on either (de-)anonymizing the graphs or understanding the security and privacy issues of graph neural networks. Little attention has been paid to understand the privacy risks of integrating the output from graph embedding models (e.g., node embeddings) with complex downstream machine learning pipelines. In this paper, we fill this gap and propose a novel model-agnostic graph recovery attack that exploits the implicit graph structural information preserved in the embeddings of graph nodes. We show that an adversary can recover edges with decent accuracy by only gaining access to the node embedding matrix of the original graph without interactions with the node embedding models. We demonstrate the effectiveness and applicability of our graph recovery attack through extensive experiments.
Yufei Han 0001, Zhikun Zhang 0001, Min Chen 0032, Ting Yu 0001, Michael Backes 0001, Yang Zhang 0016, Gianluca Stringhini
CCS2
2022 Errors in the CICIDS2017 Dataset and the Significant Differences in Detection Performances It Makes
Maxime Lanvin, Pierre-François Gimenez, Yufei Han 0001, Frédéric Majorczyk, Ludovic Mé, Eric Totel
CRiSIS3
2022 Towards Understanding the Robustness Against Evasion Attack on Categorical Data
Hongyan Bao, Yufei Han 0001, Yujun Zhou 0002, Xiangliang Zhang 0001
ICLR2
2022 Model Stealing Attacks Against Inductive Graph Neural Networks
abstract
Many real-world data come in the form of graphs. Graph neural networks (GNNs), a new family of machine learning (ML) models, have been proposed to fully leverage graph data to build powerful applications. In particular, the inductive GNNs, which can generalize to unseen data, become mainstream in this direction. Machine learning models have shown great potential in various tasks and have been deployed in many real-world scenarios. To train a good model, a large amount of data as well as computational resources are needed, leading to valuable intellectual property. Previous research has shown that ML models are prone to model stealing attacks, which aim to steal the functionality of the target models. However, most of them focus on the models trained with images and texts. On the other hand, little attention has been paid to models trained with graph data, i.e., GNNs. In this paper, we fill the gap by proposing the first model stealing attacks against inductive GNNs. We systematically define the threat model and propose six attacks based on the adversary’s background knowledge and the responses of the target models. Our evaluation on six benchmark datasets shows that the proposed model stealing attacks against GNNs achieve promising performance.1
Xinlei He 0001, Yufei Han 0001, Yang Zhang 0016
SP3
2021 Characterizing the Evasion Attackability of Multi-label Classifiers
abstract
Evasion attack in multi-label learning systems is an interesting, widely witnessed, yet rarely explored research topic. Characterizing the crucial factors determining the attackability of the multi-label adversarial threat is the key to interpret the origin of the adversarial vulnerability and to understand how to mitigate it. Our study is inspired by the theory of adversarial risk bound. We associate the attackability of a targeted multi-label classifier with the regularity of the classifier and the training data distribution. Beyond the theoretical attackability analysis, we further propose an efficient empirical attackability estimator via greedy label space exploration. It provides provably computational efficiency and approximation accuracy. Substantial experimental results on real-world datasets validate the unveiled attackability factors and the effectiveness of the proposed empirical attackability indicator.
Yufei Han 0001, Xiangliang Zhang 0001
AAAI2
2021 Towards Stalkerware Detection with Precise Warnings
abstract
Stalkerware enables individuals to conduct covert surveillance on a targeted person’s device. Android devices are a particularly fertile ground for stalkerware, most of which spy on a single communication channel, sensor, or category of private data, though 27% of stalkerware surveil multiple of private data sources. We present Dosmelt, a system that enables stalkerware warnings that precisely characterize the types of surveillance conducted by Android stalkerware so that surveiled individuals can take appropriate mitigating action. Our methodology uses active learning in a semi-supervised learning setting to tackle this task at scale, which would otherwise require expert labeling of significant number of stalkerware apps. Dosmelt leverages the observation that stalkerware differs from other categories of spyware in its open advertising of its surveillance capabilities, which we detect on the basis of the titles and self-descriptions of stalkerware apps that are posted on Android app stores. Dosmelt achieves up to 96% AUC for stalkerware detection with a 91% Macro-F1 score of surveillance capability attribution for stalkerware apps. Dosmelt has detected hundreds of new stalkerware apps that we have added to the Stalkerware Threat List.
Yufei Han 0001, Kevin A. Roundy, Acar Tamersoy
ACSAC1
2021 Does Every Second Count? Time-based Evolution of Malware Behavior in Sandboxes
Alexander Küchler, Alessandro Mantovani, Yufei Han 0001, Leyla Bilge, Davide Balzarotti
NDSS3
2021 Attack Transferability Characterization for Adversarially Robust Multi-label Classification
Yufei Han 0001, Xiangliang Zhang 0001
ECML/PKDD (3)2
2020 Robust Federated Learning via Collaborative Machine Teaching
abstract
For federated learning systems deployed in the wild, data flaws hosted on local agents are widely witnessed. On one hand, given a large amount (e.g. over 60%) of training data are corrupted by systematic sensor noise and environmental perturbations, the performances of federated model training can be degraded significantly. On the other hand, it is prohibitively expensive for either clients or service providers to set up manual sanitary checks to verify the quality of data instances. In our study, we echo this challenge by proposing a collaborative and privacy-preserving machine teaching method. Specifically, we use a few trusted instances provided by teachers as benign examples in the teaching process. Our collaborative teaching approach seeks jointly the optimal tuning on the distributed training set, such that the model learned from the tuned training set predicts labels of the trusted items correctly. The proposed method couples the process of teaching and learning and thus produces directly a robust prediction model despite the extremely pervasive systematic data corruption. The experimental study on real benchmark data sets demonstrates the validity of our method.
Yufei Han 0001, Xiangliang Zhang 0001
AAAI1
2020 Attackability Characterization of Adversarial Evasion Attack on Discrete Data
abstract
Evasion attack on discrete data is a challenging, while practically interesting research topic. It is intrinsically an NP-hard combinatorial optimization problem. Characterizing the conditions guaranteeing the solvability of an evasion attack task thus becomes the key to understand the adversarial threat. Our study is inspired by the weak submodularity theory. We characterize the attackability of a targeted classifier on discrete data in evasion attack by bridging the attackability measurement and the regularity of the targeted classifier. Based on our attackability analysis, we propose a computationally efficient orthogonal matching pursuit-guided attack method for evasion attack on discrete data. It provides provably computational efficiency and attack performances. Substantial experimental results on real-world datasets validate the proposed attackability conditions and the effectiveness of the proposed attack method.
Yufei Han 0001, Hongyan Bao, Fenglong Ma, Jin Li 0002, Xiangliang Zhang 0001
KDD2
2020 Recurrent Attention Walk for Semi-supervised Classification
abstract
In this paper, we study the graph-based semi-supervised learning for classifying nodes in attributed networks, where the nodes and edges possess content information. Recent approaches like graph convolution networks and attention mechanisms have been proposed to ensemble the first-order neighbors and incorporate the relevant neighbors. However, it is costly (especially in memory) to consider all neighbors without a prior differentiation. We propose to explore the neighborhood in a reinforcement learning setting and find a walk path well-tuned for classifying the unlabelled target nodes. We let an agent (of node classification task) walk over the graph and decide where to move to maximize classification accuracy. We define the graph walk as a partially observable Markov decision process (POMDP). The proposed method is flexible for working in both transductive and inductive setting. Extensive experiments on four datasets demonstrate that our proposed method outperforms several state-of-the-art methods. Several case studies also illustrate the meaningful movement trajectory made by the agent.
Uchenna Akujuobi, Yufei Han 0001, Xiangliang Zhang 0001
WSDM3
2019 Collaborative Graph Walk for Semi-Supervised Multi-label Node Classification
abstract
In this work, we study semi-supervised multi-label node classification problem in attributed graphs. Classic solutions to multi-label node classification follow two steps, first learn node embedding and then build a node classifier on the learned embedding. To improve the discriminating power of the node embedding, we propose a novel collaborative graph walk, named Multi-Label-Graph-Walk, to finely tune node representations with the available label assignments in attributed graphs via reinforcement learning. The proposed method formulates the multi-label node classification task as simultaneous graph walks conducted by multiple label-specific agents. Furthermore, policies of the label-wise graph walks are learned in a cooperative way to capture first the predictive relation between node labels and structural attributes of graphs; and second, the correlation among the multiple label-specific classification tasks. A comprehensive experimental study demonstrates that the proposed method can achieve significantly better multi-label classification performance than the state-of-the-art approaches and conduct more efficient graph exploration.
Uchenna Akujuobi, Yufei Han 0001, Xiangliang Zhang 0001
ICDM2
2019 Collaborative and Privacy-Preserving Machine Teaching via Consensus Optimization
abstract
In this work, we define a collaborative and privacy-preserving machine teaching paradigm with multiple distributed teachers. We focus on consensus super teaching. It aims at organizing distributed teachers to jointly select a compact while informative training subset from data hosted by the teachers to make a learner learn better. The challenges arise from three perspectives. First, the state-of-the-art pool-based super teaching method applies mixed-integer non-linear programming (MINLP) which does not scale well to very large data sets. Second, it is desirable to restrict data access of the teachers to only their own data during the collaboration stage to mitigate privacy leaks. Finally, the teaching collaboration should be communication-efficient since large communication overheads can cause synchronization delays between teachers. To address these challenges, we formulate the collaborative teaching as a consensus and privacy-preserving optimization process to minimize teaching risk. We theoretically demonstrate the necessity of collaboration between teachers for improving the learner's learning. Furthermore, we show that the proposed method enjoys a similar property as the Oracle property of adaptive Lasso. Empirical study illustrates that our teaching method can deliver significantly more accurate teaching results with high speed, while the non-collaborative MINLP-based super teaching becomes prohibitively expensive to compute.
Yufei Han 0001, Yuzhe Ma, Christopher Gates 0002, Kevin A. Roundy
IJCNN1
2018 Multi-label Learning with Highly Incomplete Data via Collaborative Embedding
abstract
Tremendous efforts have been dedicated to improving the effectiveness of multi-label learning with incomplete label assignments. Most of the current techniques assume that the input features of data instances are complete. Nevertheless, the co-occurrence of highly incomplete features and weak label assignments is a challenging and widely perceived issue in real-world multi-label learning applications due to a number of practical reasons including incomplete data collection, moderate labels from annotators, etc. Existing multi-label learning algorithms are not directly applicable when the observed features are highly incomplete. In this work, we attack this problem by proposing a weakly supervised multi-label learning approach, based on the idea of collaborative embedding. This approach provides a flexible framework to conduct efficient multi-label classification at both transductive and inductive mode by coupling the process of reconstructing missing features and weak label assignments in a joint optimisation framework. It is designed to collaboratively recover feature and label information, and extract the predictive association between the feature profile and the multi-label tag of the same data instance. Substantial experiments on public benchmark datasets and real security event data validate that our proposed method can provide distinctively more accurate transductive and inductive classification than other state-of-the-art algorithms.
Yufei Han 0001, Guolei Sun, Xiangliang Zhang 0001
KDD1
2017 Predicting Cyber Threats with Virtual Security Products
abstract
Cybersecurity analysts are often presented suspicious machine activity that does not conclusively indicate compromise, resulting in undetected incidents or costly investigations into the most appropriate remediation actions. There are many reasons for this: deficiencies in the number and quality of security products that are deployed, poor configuration of those security products, and incomplete reporting of product-security telemetry. Managed Security Service Providers (MSSP's), which are tasked with detecting security incidents on behalf of multiple customers, are confronted with these data quality issues, but also possess a wealth of cross-product security data that enables innovative solutions. We use MSSP data to develop Virtual Product, which addresses the aforementioned data challenges by predicting what security events would have been triggered by a security product if it had been present. This benefits the analysts by providing more context into existing security incidents (albeit probabilistic) and by making questionable security incidents more conclusive. We achieve up to 99% AUC in predicting the incidents that some products would have detected had they been present.
Shang-Tse Chen, Yufei Han 0001, Polo Chau, Christopher Gates 0002, Michael Hart, Kevin A. Roundy
ACSAC2
2017 Marmite: Spreading Malicious File Reputation Through Download Graphs
abstract
Effective malware detection approaches need not only high accuracy, but also need to be robust to changes in the modus operandi of criminals. In this paper, we propose Marmite, a feature-agnostic system that aims at propagating known malicious reputation of certain files to unknown ones with the goal of detecting malware. Marmite does this by looking at a graph that encapsulates a comprehensive view of how files are downloaded (by which hosts and from which servers) on a global scale. The reputation of files is then propagated across the graph using semi-supervised label propagation with Bayesian confidence. We show that Marmite is able to reach high accuracy (0.94 G-mean on average) over a 10-day dataset of 200 million download events. We also demonstrate that Marmite's detection capabilities do not significantly degrade over time, by testing our system on a 30-day dataset of 660 million download events collected six months after the system was tuned and validated. Marmite still maintains a similar accuracy after this period of time.
Gianluca Stringhini, Yufei Han 0001, Xiangliang Zhang 0001
ACSAC3
2017 RiskTeller: Predicting the Risk of Cyber Incidents
abstract
The current evolution of the cyber-threat ecosystem shows that no system can be considered invulnerable. It is therefore important to quantify the risk level within a system and devise risk prediction methods such that proactive measures can be taken to reduce the damage of cyber attacks. We present RiskTeller, a system that analyzes binary file appearance logs of machines to predict which machines are at risk of infection months in advance. Risk prediction models are built by creating, for each machine, a comprehensive profile capturing its usage patterns, and then associating each profile to a risk level through both fully and semi-supervised learning methods. We evaluate RiskTeller on a year-long dataset containing information about all the binaries appearing on machines of 18 enterprises. We show that RiskTeller can use the machine profile computed for a given machine to predict subsequent infections with the highest prediction precision achieved to date.
Leyla Bilge, Yufei Han 0001, Matteo Dell'Amico
CCS2
2016 Content-Agnostic Malware Detection in Heterogeneous Malicious Distribution Graph
abstract
Malware detection has been widely studied by analysing either file dropping relationships or characteristics of the file distribution network. This paper, for the first time, studies a global heterogeneous malware delivery graph fusing file dropping relationship and the topology of the file distribution network. The integration offers a unique ability of structuring the end-to-end distribution relationship. However, it brings large heterogeneous graphs to analysis. In our study, an average daily generated graph has more than 4 million edges and 2.7 million nodes that differ in type, such as IPs, URLs, and files. We propose a novel Bayesian label propagation model to unify the multi-source information, including content-agnostic features of different node types and topological information of the heterogeneous network. Our approach does not need to examine the source codes nor inspect the dynamic behaviours of a binary. Instead, it estimates the maliciousness of a given file through a semi-supervised label propagation procedure, which has a linear time complexity w.r.t. the number of nodes and edges. The evaluation on 567 million real-world download events validates that our proposed approach efficiently detects malware with a high accuracy.
Ibrahim Alabdulmohsin, Yufei Han 0001, Xiangliang Zhang 0001
CIKM2
2016 Partially Supervised Graph Embedding for Positive Unlabelled Feature Selection
Yufei Han 0001
IJCAI1