EDBT 2026 Demo / reviewers in the wild / expert
Mengyao Zhu 0004
dblp:79/4643-4
· DBLP profile ↗
7ranked-venue papers
1as first author
7since 2021 · last 2026
0009-0001-9343-1074ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | RFA-Tex: Range-Flexible Adaptive Physical Adversarial Texture Against Real-World Person Detectors
Mengyao Zhu 0004, Xinghua Li 0001, Decheng Liu, Shunjie Yuan, Yigang Li, Yinbin Miao, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | SPD: Shallow Backdoor Protecting Deep Backdoor Against Backdoor Detection
Shunjie Yuan, Xinghua Li 0001, Xuelin Cao, Mengyao Zhu 0004, Robert H. Deng |
ICCV | 5 |
| 2025 | FL-CDF: Collaborative Defense Framework for Backdoor Mitigation in Federated LearningabstractFederated learning (FL) is vulnerable to backdoor attacks due to its distributed nature. Existing unilateral defense mechanisms often fail against persistent attack strategies, primarily due to their limited perspectives. To address the challenge of model misclassification on the server side caused by overlooked model similarity drift, and gradient misjudgment on the client side caused by semantic learning imbalances across classes, this paper proposes a collaborative defense framework for federated learning, termed FL-CDF. FL-CDF establishes an end-to-end defense through a bidirectional client-server collaboration mechanism. Specifically: (1) On the client side, an adversarial perturbation-based malicious neuron detection module is introduced. This module measures neuron activation sensitivity by generating adversarial perturbations, and adaptively prunes backdoor neurons exhibiting high sensitivity. (2) On the server side, a multi-dimensional detection scheme is designed, which integrates neuron localization, adversarial sensitivity, and model parameters. By incorporating client-side feedback on malicious neurons, the server performs robust model aggregation. Theoretical analysis verifies the robustness of FL-CDF, and extensive experiments on public benchmarks demonstrate its effectiveness. In the best-case scenario, FL-CDF improves defense performance by 42.5% compared to current state-of-the-art (SOTA) defense. Xinghua Li 0001, Yinbin Miao, Shunjie Yuan, Mengyao Zhu 0004, Ximeng Liu, Robert H. Deng |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | Robust Federated Learning Client Selection With Combinatorial Class Representations and Data AugmentationabstractThe federated learning (FL) client selection scheme can effectively mitigate global model performance degradation caused by the random aggregation of clients with heterogeneous data. Simultaneously, research has exposed FL’s susceptibility to backdoor attacks. However herein lies the dilemma, traditional client selection methods and backdoor defenses stand at odds, so their integration is an elusive goal. To resolve this, we introduce Grace, a resilient client selection framework blending combinational class sampling with data augmentation. On the client side, Grace first proposes a local model purification method, fortifying the model’s defenses by bolstering its innate robustness. After, local class representations are extracted for server-side client selection. This approach not only shields benign models from backdoor tampering but also allows the server to glean insights into local class representations without infringing upon the client’s privacy. On the server side, Grace introduces a novel representation combination sampling method. Clients are selected based on the interplay of their class representations, a strategy that simultaneously weeds out malicious actors and draws in clients whose data holds unique value. Our extensive experiments highlight Grace’s capabilities. The results are compelling: Grace enhances defense performance by over 50% compared to state-of-the-art (SOTA) backdoor defenses, and, in the best case, improves accuracy by 3.19% compared to SOTA client selection schemes. Consequently, Grace achieves substantial advancements in both security and accuracy. Xinghua Li 0001, Mengfan Xu, Shunjie Yuan, Mengyao Zhu 0004, Robert H. Deng |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2024 | PIC-BI: Practical and Intelligent Combinatorial Batch Identification for UAV assisted IoT NetworksabstractUnmanned Aerial Vehicle (UAV)-assisted IoT networks are receiving a lot of attention in academia and industry. For instance, a UAV can fly and hover over sensors, during which time the sensors simultaneously initiate batch access requests to the UAV. Typically, UAV employs batch authentication to efficiently handle these batch accesses. However, an attacker can initiate illegal requests, causing batch authentication to fail. There are various batch identification algorithms to find illegal requests, enabling legitimate sensors to establish service connections quickly. Existing work wants to choose a suitable one based on the specific attack scenario. However, existing work assumes that the percentage r% of illegal requests is known in advance, which is impractical in real-world scenarios. Besides, existing work only selects a suitable batch identification algorithm based on r%, limiting the performance of batch identification to the capabilities of the alternative algorithms. Drawing inspiration from the Kalman filter, we first propose an adaptive estimation algorithm for the number of illegal requests to address the above problems. Based on the estimated value e%, we design a combinatorial batch identification using reinforcement learning. This approach allows the combination of different algorithms to achieve superior performance. Extensive experiments demonstrate that, for the estimation algorithm, the relative error is less than 20% in 27 out of 40 experiments. Regarding the combinatorial algorithms, the delay can be reduced by approximately 7.15% to 30.86% compared to existing methods. Zhe Ren, Xinghua Li 0001, Yinbin Miao, Mengyao Zhu 0004, Shunjie Yuan, Robert H. Deng |
CCS | 4 |
| 2024 | Intelligent Adaptive Gossip-Based Broadcast Protocol for UAV-MEC Using Multi-Agent Deep Reinforcement LearningabstractUAV-assisted mobile edge computing (UAV-MEC) has been proposed to offer computing resources for smart devices and user equipment. UAV cluster aided MEC rather than one UAV-aided MEC as edge pool is the newest edge computing architecture. Unfortunately, the data packet exchange during edge computing within the UAV cluster hasn't received enough attention. UAVs need to collaborate for the wide implementation of MEC, relying on the gossip-based broadcast protocol. However, gossip has the problem of long propagation delay, where the forwarding probability and neighbors are two factors that are difficult to balance. The existing works improve gossip from only one factor, which cannot select suitable forwarding probability and avoid redundant messages. Besides, these schemes do not consider the historical packet reception of new neighbors when UAVs fly around, which decreases forwarding efficiency. To solve these problems, we first propose a data structure called Bitgraph that can record the historical packet reception of UAVs. Then, we formulate gossip broadcasting as a partially observable Markov decision process. Based on Bitgraph, we design the reward function. Finally, we design a multi-agent reinforcement learning algorithm, Branching Deep Graph Network (BDGN), which simultaneously makes decisions on forwarding probability and neighbors. Extensive experiments illustrate that our proposal gets more than 29% advantage in terms of the propagation delay and 20% advantage in terms of the redundant messages compared to the existing works. Zhe Ren, Xinghua Li 0001, Yinbin Miao, Zhuowen Li, Mengyao Zhu 0004, Ximeng Liu, Robert H. Deng |
IEEE Trans. Mob. Comput. | 6 |
| 2021 | Sustainable Ensemble Learning Driving Intrusion Detection ModelabstractNowadays, in machine learning based intrusion detection systems, ensemble learning is a commonly adopted method to improve the detection accuracy. Unfortunately, the existing works have not considered the accumulation and reuse of historical knowledge, as well as the sensitivity of the detection model to different types of attacks, which leads to a low detection accuracy. To address the issue, this article proposes a model based on sustainable ensemble learning. In the model training stage, by taking the individual classifiers probability output and classification confidence as the training data, we build multi-class regression models such that ensemble learning adapts to different attacks. Besides, in the updating stage, an iterative updating method is presented, where the parameters and decision results of the historical model are added to the training process of the new ensemble model to realize the incremental learning. Experiment results show that the proposed model significantly outperforms the existing solutions in terms of detection accuracy, false alarm, stability and robustness. Xinghua Li 0001, Mengyao Zhu 0004, Laurence T. Yang, Mengfan Xu, Zhuo Ma 0001, Hui Li 0005, Yang Xiang 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |