EDBT 2026 Demo / reviewers in the wild / expert
Hongbin Liu 0005
dblp:82/6141-5
· DBLP profile ↗
15ranked-venue papers
6as first author
15since 2021 · last 2026
0000-0003-1869-0428ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 9 · 3 first-author · 9 since 2021Security and privacy · 6 · 3 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 2 first-author · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Leave My Images Alone: Preventing Multi-Modal Large Language Models from Analyzing Images via Visual Prompt InjectionabstractMulti-modal large language models (MLLMs) have emerged as powerful tools for analyzing Internet-scale image data, offering significant benefits but also raising critical safety and societal concerns.In particular, open-weight MLLMs may be misused to extract sensitive information from personal images at scale, such as identities, locations, or other private details.In this work, we propose ImageProtector, a user-side method that proactively protects images before sharing by embedding a carefully crafted, nearly imperceptible perturbation that acts as a visual prompt injection attack on MLLMs.As a result, when an adversary analyzes a protected image with an MLLM, the MLLM is consistently induced to generate a refusal response such as "I'm sorry, I can't help with that request."We empirically demonstrate the effectiveness of ImageProtector across six MLLMs and four datasets.Additionally, we evaluate three potential countermeasures, Gaussian noise, DiffPure, and adversarial training, and show that while they partially mitigate the impact of ImageProtector, they simultaneously degrade model accuracy and/or efficiency.Our study focuses on the practically important setting of open-weight MLLMs and large-scale automated image analysis, and highlights both the promise and the limitations of perturbation-based privacy protection. Zedian Shao, Hongbin Liu 0005, Yuepeng Hu, Neil Zhenqiang Gong |
ACL (1) | 2 |
| 2025 | Tracing Back the Malicious Clients in Poisoning Attacks to Federated LearningabstractPoisoning attacks compromise the training phase of federated learning (FL) such that the learned global model misclassifies attacker-chosen inputs called target inputs. Existing defenses mainly focus on protecting the training phase of FL such that the learnt global model is poison free. However, these defenses often achieve limited effectiveness when the clients' local training data is highly non-iid or the number of malicious clients is large, as confirmed in our experiments. In this work, we propose FLForensics, the first poison-forensics method for FL. FLForensics complements existing training-phase defenses. In particular, when training-phase defenses fail and a poisoned global model is deployed, FLForensics aims to trace back the malicious clients that performed the poisoning attack after a misclassified target input is identified. We theoretically show that FLForensics can accurately distinguish between benign and malicious clients under a formal definition of poisoning attack. Moreover, we empirically show the effectiveness of FLForensics at tracing back both existing and adaptive poisoning attacks on five benchmark datasets. Yuqi Jia 0001, Minghong Fang, Hongbin Liu 0005, Jinghuai Zhang, Neil Zhenqiang Gong |
NeurIPS | 3 |
| 2025 | Periodic Recovery From Poisoning Attacks in Machine LearningabstractRecovery from poisoning attacks aims to eliminate the influence of a given set of deleted poisoned training data on a model. In practice, model recovery often happensperiodicallysince data deletion occurs repeatedly after a model has been trained. Existing efficient model recovery methods are designed forsingle-shotmodel recovery. When applied to periodic model recovery, they treat the instances of recovery independently, leading to a large total overhead over time. In this work, we propose PeriRecover, an efficient periodic model recovery method. Our key idea is to extract some common information during the original model training, which can be used to accelerate all instances of model recovery. In particular, we propose to compute and store the diagonals of the Hessian matrix of the loss function during the original model training. Given such information, each instance of model recovery can efficiently estimate the gradients to update the model instead of exactly computing them. Theoretically, we show that the model recovered by PeriRecover is close to the one recovered by training-from-scratch under some assumptions, achievingcertified recovery. Empirically, we apply PeriRecover to supervised learning and recommender systems, and we consider targeted attacks and untargeted attacks. Our results show that PeriRecover is much more efficient and/or accurate than existing model recovery methods. Yuepeng Hu, Minghong Fang, Yuqi Jia 0001, Hongbin Liu 0005, Neil Zhenqiang Gong |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | Data Poisoning Based Backdoor Attacks to Contrastive LearningabstractContrastive learning (CL) pretrains general-purpose encoders using an unlabeled pretraining dataset, which consists of images or image-text pairs. CL is vulnera-ble to data poisoning based backdoor attacks (DPBAs), in which an attacker injects poisoned inputs into the pretraining dataset so the encoder is backdoored. However, existing DPBAs achieve limited effectiveness. In this work, we take the first step to analyze the limitations of existing backdoor attacks and propose new DPBAs called CorruptEncoder to CL. CorruptEncoder introduces a new attack strategy to create poisoned inputs and uses a theory-guided method to maximize attack effectiveness. Our experiments show that CorruptEncoder substantially outperforms existing DPBAs. In particular, CorruptEncoder is the first DPBA that achieves more than 90% attack success rates with only a few (3) reference images and a small poisoning ratio (0.5%). Moreover, we also propose a de-fense, called localized cropping, to defend against DPBAs. Our results show that our defense can reduce the effectiveness of DPBAs, but it sacrifices the utility of the encoder, highlighting the need for new defenses. Jinghuai Zhang, Hongbin Liu 0005, Jinyuan Jia 0001, Neil Zhenqiang Gong |
CVPR | 2 |
| 2024 | AudioMarkBench: Benchmarking Robustness of Audio WatermarkingabstractThe increasing realism of synthetic speech, driven by advancements in text-to-speech models, raises ethical concerns regarding impersonation and disinformation. Audio watermarking offers a promising solution via embedding human-imperceptible watermarks into AI-generated audios. However, the robustness of audio watermarking against common/adversarial perturbations remains understudied. We present AudioMarkBench, the first systematic benchmark for evaluating the robustness of audio watermarking against watermark removal and watermark forgery. AudioMarkBench includes a new dataset created from Common-Voice across languages, biological sexes, and ages, 3 state-of-the-art watermarking methods, and 15 types of perturbations. We benchmark the robustness of these methods against the perturbations in no-box, black-box, and white-box settings. Our findings highlight the vulnerabilities of current watermarking techniques and emphasize the need for more robust and fair audio watermarking solutions. Our dataset and code are publicly available at https://github.com/moyangkuo/AudioMarkBench. Hongbin Liu 0005, Moyang Guo, Zhengyuan Jiang, Neil Zhenqiang Gong |
NeurIPS | 1 |
| 2024 | Mudjacking: Patching Backdoor Vulnerabilities in Foundation Models
Hongbin Liu 0005, Michael K. Reiter, Neil Zhenqiang Gong |
USENIX Security Symposium | 1 |
| 2023 | PointCert: Point Cloud Classification with Deterministic Certified Robustness GuaranteesabstractPoint cloud classification is an essential component in many security-critical applications such as autonomous driving and augmented reality. However, point cloud classifiers are vulnerable to adversarially perturbed point clouds. Existing certified defenses against adversarial point clouds suffer from a key limitation: their certified robustness guarantees are probabilistic, i.e., they produce an incorrect certified robustness guarantee with some probability. In this work, we propose a general framework, namely PointCert, that can transform an arbitrary point cloud classifier to be certifiably robust against adversarial point clouds with deterministic guarantees. PointCert certifiably predicts the same label for a point cloud when the number of arbitrarily added, deleted, and/or modified points is less than a threshold. Moreover, we propose multiple methods to optimize the certified robustness guarantees of PointCert in three application scenarios. We systematically evaluate PointCert on ModelNet and ScanObjectNN benchmark datasets. Our results show that PointCert substantially outperforms state-of-the-art certified defenses even though their robustness guarantees are probabilistic. Jinghuai Zhang, Jinyuan Jia 0001, Hongbin Liu 0005, Neil Zhenqiang Gong |
CVPR | 3 |
| 2023 | Generation-based fuzzing? Don't build a new generator, reuse!
Chengbin Pang, Hongbin Liu 0005, Neil Zhenqiang Gong, Bing Mao 0001, Jun Xu 0024 |
Comput. Secur. | 2 |
| 2022 | StolenEncoder: Stealing Pre-trained Encoders in Self-supervised LearningabstractPre-trained encoders are general-purpose feature extractors that can be used for many downstream tasks. Recent progress in self-supervised learning can pre-train highly effective encoders using a large volume of unlabeled data, leading to the emerging encoder as a service (EaaS). A pre-trained encoder may be deemed confidential because its training often requires lots of data and computation resources as well as its public release may facilitate misuse of AI, e.g., for deepfakes generation. In this paper, we propose the first attack called StolenEncoder to steal pre-trained image encoders. We evaluate StolenEncoder on multiple target encoders pre-trained by ourselves and three real-world target encoders including the ImageNet encoder pre-trained by Google, CLIP encoder pre-trained by OpenAI, and Clarifai's General Embedding encoder deployed as a paid EaaS. Our results show that the encoders stolen by StolenEncoder have similar functionality with the target encoders. In particular, the downstream classifiers built upon a target encoder and a stolen encoder have similar accuracy. Moreover, stealing a target encoder using StolenEncoder requires much less data and computation resources than pre-training it from scratch. We also explore three defenses that perturb feature vectors produced by a target encoder. Our evaluation shows that these defenses are not enough to mitigate StolenEncoder. Yupei Liu, Jinyuan Jia 0001, Hongbin Liu 0005, Neil Zhenqiang Gong |
CCS | 3 |
| 2022 | Semi-Leak: Membership Inference Attacks Against Semi-supervised Learning
Xinlei He 0001, Hongbin Liu 0005, Neil Zhenqiang Gong, Yang Zhang 0016 |
ECCV (31) | 2 |
| 2022 | Almost Tight L0-norm Certified Robustness of Top-k Predictions against Adversarial Perturbations
Jinyuan Jia 0001, Binghui Wang, Hongbin Liu 0005, Neil Zhenqiang Gong |
ICLR | 4 |
| 2022 | PoisonedEncoder: Poisoning the Unlabeled Pre-training Data in Contrastive Learning
Hongbin Liu 0005, Jinyuan Jia 0001, Neil Zhenqiang Gong |
USENIX Security Symposium | 1 |
| 2021 | EncoderMI: Membership Inference against Pre-trained Encoders in Contrastive LearningabstractGiven a set of unlabeled images or (image, text) pairs, contrastive learning aims to pre-train an image encoder that can be used as a feature extractor for many downstream tasks. In this work, we propose EncoderMI, the first membership inference method against image encoders pre-trained by contrastive learning. In particular, given an input and a black-box access to an image encoder, EncoderMI aims to infer whether the input is in the training dataset of the image encoder. EncoderMI can be used 1) by a data owner to audit whether its (public) data was used to pre-train an image encoder without its authorization or 2) by an attacker to compromise privacy of the training data when it is private/sensitive. Our EncoderMI exploits the overfitting of the image encoder towards its training data. In particular, an overfitted image encoder is more likely to output more (or less) similar feature vectors for two augmented versions of an input in (or not in) its training dataset. We evaluate EncoderMI on image encoders pre-trained on multiple datasets by ourselves as well as the Contrastive Language-Image Pre-training (CLIP) image encoder, which is pre-trained on 400 million (image, text) pairs collected from the Internet and released by OpenAI. Our results show that EncoderMI can achieve high accuracy, precision, and recall. We also explore a countermeasure against EncoderMI via preventing overfitting through early stopping. Our results show that it achieves trade-offs between accuracy of EncoderMI and utility of the image encoder, i.e., it can reduce the accuracy of EncoderMI, but it also incurs classification accuracy loss of the downstream classifiers built based on the image encoder. Hongbin Liu 0005, Jinyuan Jia 0001, Wenjie Qu 0001, Neil Zhenqiang Gong |
CCS | 1 |
| 2021 | PointGuard: Provably Robust 3D Point Cloud Classificationabstract3D point cloud classification has many safety-critical applications such as autonomous driving and robotic grasping. However, several studies showed that it is vulnerable to adversarial attacks. In particular, an attacker can make a classifier predict an incorrect label for a 3D point cloud via carefully modifying, adding, and/or deleting a small number of its points. Randomized smoothing is state-of-the-art technique to build certifiably robust 2D image classifiers. However, when applied to 3D point cloud classification, randomized smoothing can only certify robustness against adversarially modified points.In this work, we propose PointGuard, the first defense that has provable robustness guarantees against adversarially modified, added, and/or deleted points. Specifically, given a 3D point cloud and an arbitrary point cloud classifier, our PointGuard first creates multiple subsampled point clouds, each of which contains a random subset of the points in the original point cloud; then our PointGuard predicts the label of the original point cloud as the majority vote among the labels of the subsampled point clouds predicted by the point cloud classifier. Our first major theoretical contribution is that we show PointGuard provably predicts the same label for a 3D point cloud when the number of adversarially modified, added, and/or deleted points is bounded. Our second major theoretical contribution is that we prove the tightness of our derived bound when no assumptions on the point cloud classifier are made. Moreover, we design an efficient algorithm to compute our certified robustness guarantees. We also empirically evaluate PointGuard on ModelNet40 and ScanNet benchmark datasets. Hongbin Liu 0005, Jinyuan Jia 0001, Neil Zhenqiang Gong |
CVPR | 1 |
| 2021 | On the Intrinsic Differential Privacy of BaggingabstractDifferentially private machine learning trains models while protecting privacy of the sensitive training data. The key to obtain differentially private models is to introduce noise/randomness to the training process. In particular, existing differentially private machine learning methods add noise to the training data, the gradients, the loss function, and/or the model itself. Bagging, a popular ensemble learning framework, randomly creates some subsamples of the training data, trains a base model for each subsample using a base learner, and takes majority vote among the base models when making predictions. Bagging has intrinsic randomness in the training process as it randomly creates subsamples. Our major theoretical results show that such intrinsic randomness already makes Bagging differentially private without the needs of additional noise. Moreover, we prove that if no assumptions about the base learner are made, our derived privacy guarantees are tight. We empirically evaluate Bagging on MNIST and CIFAR10. Our experimental results demonstrate that Bagging achieves significantly higher accuracies than state-of-the-art differentially private machine learning methods with the same privacy budgets. Hongbin Liu 0005, Jinyuan Jia 0001, Neil Zhenqiang Gong |
IJCAI | 1 |