Zhihai Yang

dblp:80/8497 · DBLP profile ↗
← Back
25ranked-venue papers
12as first author
16since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 9 · 4 first-author · 5 since 2021Security and privacy · 9 · 5 first-author · 6 since 2021Databases, data management, data science and information retrieval · 6 · 3 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Are There Any Hidden Agents in Your Recommendations? Anomaly Detection via Structure Purification and Stability Verification
Zhihai Yang, Yufei Ji
PAKDD (3)2
2026 SenTS: A Unified Time-Spectral Modeling Framework with Periodic Regularization for Sensing Behavior Discrimination
Ruping Zou, Zhihai Yang
PAKDD (3)2
2026 Shoot the arrow at the target: Personalized adversarial defense driven by dynamic rewards
Zhihai Yang, Ruping Zou, Zhiquan Liu 0001
Expert Syst. Appl.2
2026 PVO-based reversible data hiding with flexible strip moving using classification-based adaptive prediction guided by CNN
Guojun Fan, Zhihai Yang, Zhibin Pan
J. Inf. Secur. Appl.4
2026 Fused multi-predictor mechanism in reversible data hiding
Guojun Fan, Shuai Ren 0001, Zhihai Yang, Zhibin Pan
Knowl. Based Syst.5
2026 Hear to reveal: Stealing keystroke content from keyboard acoustic side-channel
Zhiquan He, Zhihai Yang, Zicheng Cui, Pinghui Wang, Zhiquan Liu
Knowl. Based Syst.2
2026 Is There a Bottom Line for Poisoning? Detecting High-Concealed Injection Attacks for Recommendation
abstract
Recommender systems (RSs) are widely adopted due to their effectiveness in modeling user preferences and generating personalized recommendations. However, data poisoning attacks (PAs) manipulate recommendation results by injecting fake user profiles, thereby affecting the quality and accuracy of RSs. Moreover, emerging high-concealed PAs (HCPAs) achieve greater evasion of detection by controlling the cost of the attack, simulating the behavior patterns of benign users, and carrying out the attack with less prior knowledge. The HCPAs bring challenges: (1) the very low cost of attacks not only leads to an imbalance in data distribution but also introduces a large amount of accidental co-occurrence noise; (2) the behavioral patterns similar to benign users make it difficult to describe the characteristics of HCPAs; and (3) the prior knowledge for detecting HCPAs in real scenarios is very limited. To address these challenges, we propose STOP, an orthogonal projection bi-hypersphere detection method built on multi-view relational disentanglement and information-consistent fusion. First, we model the distributional preferences of user ratings to eliminate rating and popularity bias, and construct a co-occurrence association graph to suppress accidental overlaps. To address data imbalance caused by HCPAs, second, we introduce a distributional-consensus importance screening method that filters out benign users weakly associated with potential attackers. To address the issues of noise and the difficulty in feature characterization, third, we propose a multi-view relational disentanglement and information-consistent fusion method, which can eliminate redundant relationships, separate key relations into sequence-varying and sequence-stable components over rating sequences, and retain task-related relationships. Finally, inspired by the “convergence theorem”, we design an orthogonal projection bi-hypersphere boundary learning detection method to reduce the high false alarm rate (FAR). We extensively evaluate STOP under various HCPA scenarios, demonstrating its superiority over existing methods with an average 12.34% improvement in detection rate and an average 2.75% reduction in FAR. Furthermore, forensic analysis on real-world unlabeled data reveals distinct attacker “fingerprints”, such as extreme ratings, contradictory review styles, and analysis of target items, validating STOP's reliability in practical applications.
Zhihai Yang, Jianhua He 0001, Jianxin Li 0001, Pinghui Wang, Zhiquan Liu 0001
IEEE Trans. Dependable Secur. Comput.2
2026 Meet Trick With Trick: Revealing Collusion Intentions in Highly Concealed Poisoning Behavior
Zhihai Yang, Jianxin Li 0001, Pinghui Wang, Zhiquan Liu 0001
IEEE Trans. Dependable Secur. Comput.1
2026 Attacks and Detections in Recommender Systems: A Comprehensive Analysis for Models, Progresses, and Trends
abstract
Recommender systems (RSs), as crucial components of online services, can help users efficiently obtain information they may like. In reality, RSs face long-term threats. Attackers manipulate recommendation results by injecting malicious data in order to obtain benefits. At present, research on the security of RSs lacks a comprehensive understanding of attack capabilities. Moreover, existing defense strategies have not yet been systematically associated with attack characteristics. More importantly, existing defense methods rarely focus on real unlabeled data in practical application scenarios for anomaly detection and forensics. Therefore, this survey systematically analyzes the security of RSs and provides new insights. Specifically, we first categorize attack models from an attack perspective into: attack strategies based on targets, attack strategies against security and privacy, attack strategies based on prior knowledge, and attack strategies against other RSs. From a perspective of defense, existing detection models, second, can be divided into: behavioral representation based on statistics, detection based on hidden features, detection against privacy attacks, anomaly discovery based on association mining, and abnormality forensics for real-world data. Finally, we propose several potential research directions aimed at providing guidance for the security research of RSs. Additionally, to facilitate experimental reproducibility and comparative research, this survey also provides a repository of resources for attacks and defenses (https://github.com/xiaofengbbb/RS-Papers).
Zhihai Yang, Jianxin Li 0001, Pinghui Wang, Zhiquan Liu 0001
IEEE Trans. Knowl. Data Eng.2
2025 Cross-Model Watermarking via Discriminative Samples for Secure Authentication
abstract
Deep neural networks on cloud platforms face growing security threats, with AI services increasingly relying on heterogeneous models for the same task to meet diverse user needs. Existing methods fail to distinguish benign modifications from malicious attacks in cross-model scenarios. To address this challenge, we propose a non-intrusive cross-model watermarking method that generates discriminative samples as universal keys, enabling authentication without altering model parameters or architectures. Specifically, we introduce a margin enhancement loss to amplify confidence gaps between benign and malicious behaviors, ensuring high transferability across models. Both theoretical analysis and experimental results demonstrate the high efficacy of our proposed method. The generated samples maintain high visual fidelity (SSIM > 0.99), achieve over 3 times higher discriminability than existing methods, retain over 93% accuracy under benign modifications, and detect malicious attacks with accuracy dropping below 9%. Overall, our proposed method provides a robust, transferable, and non-intrusive solution for cross-model authentication, making it ideal for real-world applications where security is critical.
Juan Zhao 0007, Yudao Sun, Zhihai Yang, Hongji Chen 0005, Fan Zhang 0112, Jianxin Li 0001
ACM Multimedia3
2025 Block-diagonal graph embedding for unsupervised feature selection
Kun Jiang 0001, Zhihai Yang, Qindong Sun
Appl. Intell.2
2025 Self-weighted subspace clustering via adaptive rank constrained graph embedding
Kun Jiang 0001, Zhihai Yang, Qindong Sun
Pattern Anal. Appl.2
2022 Rating behavior evaluation and abnormality forensics analysis for injection attack detection
Zhihai Yang, Qindong Sun, Zhaoli Liu, Jinpei Yan
J. Intell. Inf. Syst.1
2022 Probabilistic Inference and Trustworthiness Evaluation of Associative Links Toward Malicious Attack Detection for Online Recommendations
abstract
The increasing use of recommender systems as personalization recommendation services such as Amazon, TripAdvisor, and Yelp, has stressed the demand for secure and usable abnormality detection techniques, due to fundamental vulnerabilities of recommender systems and their openness. With the emergence of new attacks, how to defend diverse malicious attacks for online recommendations is a challenging issue. Moreover, characterizing and evaluating sparse rating behaviors are a long-standing problem that still remains open, leading to an upsurge of research, as well as real application. This article investigates probabilistic inference and trustworthiness evaluation of behavioral links according to coupled association networks converted from rating behaviors, and presents a unified detection framework from a novel perspective to spot diverse malicious threats. First, an association graph is constructed from the original rating matrix based on both the inherent rating motivation of users and atomic propagation rules of coupled networks. Then, we evaluate the trustworthiness of link behaviors in the targeted network of coupled association network by exploiting a factor graph model of coupled network, and redetermine concerned links in the targeted network. Finally, suspicious users and items can be empirically inferred by comprehensively evaluating the trustworthiness of both links and nodes in the targeted network. Extensive experiments on synthetic data for profile injection attacks and co-visitation injection attacks, as well as real-world data including Amazon and TripAdvisor, demonstrate the effectiveness of the proposed detection approach compared with competing benchmarks.
Zhihai Yang, Qindong Sun
IEEE Trans. Dependable Secur. Comput.1
2022 Three Birds With One Stone: User Intention Understanding and Influential Neighbor Disclosure for Injection Attack Detection
abstract
Recommender system, as a data-driven way to help customers locate products that match their interests, is increasingly critical for providing competitive customer suggestions in many web services. However, recommender systems are highly vulnerable to malicious injection attacks due to their fundamental vulnerabilities and openness. With the endless emergence of new attacks, how to provide a feasible way for defending different malicious threats against online recommendations is still an under-explored issue. In this paper, we explore a new way to defend malicious injection attacks through user intention understanding and influential neighbour disclosure. Specifically, we propose a detection approach, termedTBOS(ThreeBirds withOneStone), to deal with different malicious threats. InTBOS, we first develop the discrimination of attack target by combining global influence evaluation and risk attitude estimation of users. In order to makeTBOScontrollable, second, we propose to incorporate an optimal denoising mechanism to remove disturbed information before detection. To enhance the representativeness and predictability of detection model, finally, we propose to leverage a behavioral label propagation mechanism based on constructed label space for the determination of malicious injection behaviors. Extensive experiments on both synthetic and real data demonstrate thatTBOSoutperforms all baselines in different cases. Particularly, the detection performance ofTBOScan achieve an improvement of 6.08% FAR (false alarm rate) for optimal-injection attacks, an improvement of 3.83% FAR in average for co-visitation injection attacks, as well as an improvement of 2.3% for profile injection attacks over benchmarks in terms of FAR while keeping the highest DR (detection rate). Additional experiments on real-world data show thatTBOSbrings an improvement with the advantage of 6.5% FAR in average compared with baselines.
Zhihai Yang, Qindong Sun, Zhaoli Liu
IEEE Trans. Inf. Forensics Secur.1
2021 Identification of Malicious Injection Attacks in Dense Rating and Co-Visitation Behaviors
abstract
Personalized recommender systems are pervasive in different domains, ranging from e-commerce services, financial transaction systems to social networks. The generated ratings and reviews by users toward products are not only favourable to make targeted improvements on the products for online businesses, but also beneficial for other users to get a more insightful review of the products. In reality, recommender systems can also be deliberately manipulated by malicious users due to their fundamental vulnerabilities and openness. However, improving the detection performance for defending malicious threats including profile injection attacks and co-visitation injection attacks is constrained by the challenging issues: (1) various types of malicious attacks in real-world data coexist; (2) it is difficult to balance the commonality and speciality of rating behaviors in terms of accurate detection; and (3) rating behaviors between attackers and anchor users caused by the consistency of attack intentions are extremely similar. In this article, we develop a unified detection approach named IMIA-HCRF, to progressively discriminate malicious injection behaviors for recommender systems. First, disturbed data are empirically eliminated by implementing both the construction of association graph and enhancement of dense behaviors, which can be adapted to different attacks. Then, the smooth boundary of dense rating (or co-visitation) behaviors is further segmented using higher order potentials, which is finally leveraged to determine the concerned injection behaviors. Extensive experiments on both synthetic data and real-world data demonstrate that the proposed IMIA-HCRF outperforms all baselines on various metrics. The detection performance of IMIA-HCRF can achieve an improvement of 7.8% for mixed profile injection attacks as well as 6% for mixed co-visitation injection attacks over the baselines in terms of FAR (false alarm rate) while keeping the highest DR (detection rate). Additional experiments on real-world data show that IMIA-HCRF brings an improvement with the advantage of 11.5% FAR in average compared with the baselines.
Zhihai Yang, Qindong Sun, Wei Wang 0077
IEEE Trans. Inf. Forensics Secur.1
2020 Fined-grained Aspect Extraction from Online Reviews for Decision Support
abstract
With the flourish of the Web 2.0, online reviews offer valuable information for customers and businesses. Deep investigation on the online reviews can help the businesses understand customers and their needs, which can assist decision making in product design and marketing. However, the massive records with irregular structure and ambiguous words pose great challenges for online review analysis. In this paper, we focus on the movie reviews and propose a framework to mine the aspect-based opinions, and utilize the results for decision making support. Based on the different sentence characteristics of movie reviews collected from Douban, the most popular movie community in China, we divide the reviews into two categories, short reviews and long reviews. Firstly, we develop different methods to extract the fine-grained aspects including the global and local aspects from the short reviews and long reviews respectively. Secondly, a lexical updating algorithm is proposed to identify the opinion words towards different aspects. In contrast to most studies that focus on determining the overall sentiment orientation (positive versus negative), the proposed method performs fine-grained analysis to mine both the various aspects and their corresponding opinions of a movie. Finally, based on the positive and negative opinions towards different aspects, the producers can improve the marketing strategy and future products. Experimental results based on the data collected from Douban verify the efficiency and accuracy of the developed methods.
Zhaoli Liu, Qindong Sun, Zhihai Yang, Kun Jiang 0001, Jinpei Yan
TrustCom3
2020 Inference of Suspicious Co-Visitation and Co-Rating Behaviors and Abnormality Forensics for Recommender Systems
abstract
The pervasiveness of personalized collaborative recommender systems has shown the powerful capability in a wide range of E-commerce services such as Amazon, TripAdvisor, Yelp, etc. However, fundamental vulnerabilities of collaborative recommender systems leave space for malicious users to affect the recommendation results as the attackers desire. A vast majority of existing detection methods assume certain properties of malicious attacks are given in advance. In reality, improving the detection performance is usually constrained due to the challenging issues: (a) various types of malicious attacks coexist, (b) limited representations of malicious attack behaviors, and (c) practical evidences for exploring and spotting anomalies on real-world data are scarce. In this paper, we investigate a unified detection framework in an eye for an eye manner without being bothered by the details of the attacks. Firstly, co-visitation and co-rating graphs are constructed using association rules. Then, attribute representations of nodes are empirically developed from the perspectives of linkage pattern, structure-based property and inherent association of nodes. Finally, both attribute information and connective coherence of graph are combined in order to infer suspicious nodes. Extensive experiments on both synthetic and real-world data demonstrate the effectiveness of the proposed detection approach compared with competing benchmarks. Additionally, abnormality forensics metrics including distribution of rating intention, time aggregation of suspicious ratings, degree distributions before as well as after removing suspicious nodes and time series analysis of historical ratings, are provided so as to discover interesting findings such as suspicious nodes (items or ratings) on real-world data.
Zhihai Yang, Qindong Sun, Lei Zhu 0011, Wenjiang Ji
IEEE Trans. Inf. Forensics Secur.1
2018 Uncovering anomalous rating behaviors for rating systems
Zhihai Yang, Qindong Sun
Neurocomputing1
2017 Spotting anomalous ratings for rating systems by analyzing target users and items
Zhihai Yang, Zhongmin Cai, Yuan Yang 0003
Neurocomputing1
2017 Detecting abnormal profiles in collaborative filtering recommender systems
Zhihai Yang, Zhongmin Cai
J. Intell. Inf. Syst.1
2016 Detecting Anomalous Ratings Using Matrix Factorization for Recommender Systems
Zhihai Yang, Zhongmin Cai
WAIM (2)1
2016 Estimating user behavior toward detecting anomalous ratings in rating systems
Zhihai Yang, Zhongmin Cai, Xiaohong Guan
Knowl. Based Syst.1
2016 Re-scale AdaBoost for attack detection in collaborative filtering recommender systems
Zhihai Yang, Lin Xu 0001, Zhongmin Cai, Zongben Xu
Knowl. Based Syst.1
2015 Identifying Intrusion Infections via Probabilistic Inference on Bayesian Network
Yuan Yang 0003, Zhongmin Cai, Weixuan Mao, Zhihai Yang
DIMVA4