Hui Liu 0018

dblp:93/4010-18 · DBLP profile ↗
← Back
11ranked-venue papers
10as first author
8since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 3 · 3 first-author · 2 since 2021Databases, data management, data science and information retrieval · 3 · 3 first-author · 3 since 2021Security and privacy · 2 · 2 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Security and privacy of machine learning · 41% Privacy and data protection · 36% Biometric security · 22%
Artificial intelligence
2 papers
Language models and text generation · 57% Vision and language · 43%

Topics — the 10 heaviest of 10, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Security and privacy of machine learning › adversarial attack
backdoor attack
1.012026
WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus Poisoning · KDD (1) 2026
Security and privacy of machine learning
retrieval-augmented generation security
1.012026
WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus Poisoning · KDD (1) 2026
Security and privacy of machine learning › poisoning attack
retrieval poisoning attack
1.012026
WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus Poisoning · KDD (1) 2026
Biometric security
face recognition
0.912025
Patronus: Plug-and-Play and Near-Lossless Facial Privacy Enhancement Against Reconstruction Attacks · IEEE Trans. Inf. Forensics Secur. 2025
Privacy and data protection
facial privacy protection
0.912025
Patronus: Plug-and-Play and Near-Lossless Facial Privacy Enhancement Against Reconstruction Attacks · IEEE Trans. Inf. Forensics Secur. 2025
Privacy and data protection › facial privacy protection
privacy-preserving face recognition
0.912025
Patronus: Plug-and-Play and Near-Lossless Facial Privacy Enhancement Against Reconstruction Attacks · IEEE Trans. Inf. Forensics Secur. 2025
Privacy and data protection › privacy protection mechanisms
reconstruction attack defense
0.912025
Patronus: Plug-and-Play and Near-Lossless Facial Privacy Enhancement Against Reconstruction Attacks · IEEE Trans. Inf. Forensics Secur. 2025
Biometric security
face anti-spoofing
0.812024
Style-conditional Prompt Token Learning for Generalizable Face Anti-spoofing · ACM Multimedia 2024
Natural language and speech › Language models and text generation
retrieval-augmented generation
0.312026
WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus Poisoning · KDD (1) 2026
Computer vision › Vision and language › vision-language model
vision-language pre-trained model
0.212024
Style-conditional Prompt Token Learning for Generalizable Face Anti-spoofing · ACM Multimedia 2024

Methods — techniques the papers use, named apart from their topics

word-level trigger injection · 2.0vision-language pretraining · 1.5style-conditional learning · 1.5prompt token learning · 1.5adversarial perturbation · 0.9
YearPublicationVenuePosition
2026 WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus Poisoning
abstract
Retrieval-Augmented Generation (RAG) systems retrieve relevant documents from a corpus database to mitigate issues like hallucination, outdated knowledge, and limited domain coverage. While enhancing large language models (LLMs) performance, RAG also introduces a new attack surface: adversaries can inject trigger-embedded malicious documents into the corpus database, potentially causing the LLM to produce attacker-controlled outputs.
Hui Liu 0018, Liguo Dong, Shui Yu 0001
KDD (1)1
2026 Take off Your Disguise: Detecting Disguised Prompt-Based Jailbreak Attacks Against LLMs
abstract
Large language models (LLMs) are typically equipped with alignment mechanisms designed to prevent the generation of harmful content. However, recent advances have led to the emergence of highly evasive disguised prompt jailbreak attacks (DPJAs), where attackers conceal real malicious intent within prompts that appear benign on the surface, thereby inducing the model to produce unsafe outputs. In this work, we propose prompt reconstruction-based detection (RePrompt), a training-free and plug-in detection framework designed to identify such jailbreak attacks. The key insight of RePrompt is that, when guided by carefully designed templates, LLMs possess the capability to uncover disguised adversarial prompts and effectively detect jailbreak attacks. RePrompt leverages the reasoning capabilities of the LLM itself to analyze and uncover the true intent behind a user’s query. When a disguised jailbreak prompt is encountered, RePrompt reconstructs the underlying malicious intent hidden beneath the surface-level disguise. Experiments across multiple LLMs, datasets, and three representative DPJAs demonstrate that RePrompt consistently outperforms state-of-the-art defense methods, reducing the average attack success rate from 47.0% to below 1.6%, achieving a near-zero false positive rate, and limiting the average query cost to only 1.13.
Hui Liu 0018, Fujv Wen, Hongqin Du, Jiabao Guo, Bo Zhao 0023
IEEE Trans. Comput. Soc. Syst.1
2026 Adversarial Face Database against Deep Learning-Enabled Reconstruction Attacks
abstract
Face recognition systems offer a range of applications that enhance security, efficiency, and personalization, e.g., access control, identity verification, and personalized services. Mainstream facial recognition systems employ the Edge-Cloud architecture to protect user privacy by storing facial feature data instead of original facial images. However, recently emerging reconstruction attacks based on deep learning can recover the visual information of original facial images from facial features, resulting in face privacy disclosure. Existing anti-reconstruction approaches either compromise facial recognition accuracy or fail to meet real-time requirements. In this article, we propose a practical privacy-preserving approach based on adversarial perturbations against reconstruction attacks. By incorporating subtle adversarial interference into facial features, the mapping relationship from facial features to original facial images is disrupted, and the baseline reconstruction networks cannot recover the original face image. We conducted experiments on two facial recognition models, FaceNet and ArcFace, both widely deployed in practical scenarios. The results show that the face recognition accuracy sacrifice of less than 1% can significantly reduce the quality of the reconstructed image. In terms of efficiency, the average time to generate an adversarial facial feature is less than 10 ms, meeting the real-time requirements of facial recognition.
Hui Liu 0018, Jiageng Chen, Jiabao Guo
ACM Trans. Intell. Syst. Technol.1
2025 Research on Runtime Memory Space Reconstruction Techniques for Source-Unavailable Programs on AArch64
abstract
With the widespread adoption of AArch64 architecture processors in mobile and IoT devices, ensuring the security of applications running on AArch64 systems against memory error vulnerabilities has become a critical research focus in the field of cybersecurity. However, traditional passive defense mechanisms have increasingly shown their limitations, and the growing demand for robust protection has driven continuous advancements in active defense technologies.To address the limitations of current memory protection techniques on AArch64 systems and the need for heterogeneity in heterogeneous redundant execution, we propose BinaryDMR, an efficient, selective, and lightweight runtime memory space reconfiguration tool specifically designed for source-unavailable programs.The core idea behind BinaryDMR is to statically reconstruct the runtime memory layout of source-unavailable programs, such as commercial-off-the-shelf (COTS) binaries, using static binary rewriting and library transformation techniques, including the stack, heap, code segments, and shared libraries.We have implemented BinaryDMR and evaluated its performance using a set of binary programs, including 19 kernel utilities (focused on file I/O operations) and one network daemon, Nginx (focused on network I/O operations). Experimental results demonstrate that BinaryDMR significantly reduces the success rate of common memory error-related attacks, effectively mitigates security risks arising from software homogeneity, and delivers strong practicality with minimal performance overhead.
Hui Liu 0018, Guoqing Peng, Bo Zhao 0010
IEEE Internet Things J.1
2025 Patronus: Plug-and-Play and Near-Lossless Facial Privacy Enhancement Against Reconstruction Attacks
abstract
Reconstruction attackers can exploit facial features to recover the original user’s face, resulting in user privacy leakage. One new strategy to enhance the “Edge-Cloud” face recognition system’s privacy is to add adversarial perturbations to facial features, preventing the attackers from high-quality user image recovery. However, the existing works following this strategy suffer from unacceptable damage to face recognition accuracy. Achieving robust privacy enhancement and face recognition accuracy simultaneously is still challenging. To tackle this challenge, we propose an adversarial perturbation-based plug-and-play privacy-enhancing method (Patronus) with robustness against face image reconstruction attacks and near-lossless face recognition performance. The key insight is derived from our observation that the feature distance between two face images of the same person is significantly lower than the threshold set in the face recognition system. This leaves room for adding adversarial perturbations to the facial features without compromising face recognition accuracy. Our strategy limits the amount of adversarial perturbations in a fine-grained manner to ensure that they are within the range of not damaging face recognition accuracy. Our evaluation shows the superior performance ofPatronusin robustness against reconstruction attacks and near-lossless face recognition accuracy compared to state-of-the-art (SOTA) methods.Patronuscan be easily integrated into deployed face recognition systems as a plug-in privacy-enhancing module with low overhead.
Hui Liu 0018, Hongqin Du, Jiageng Chen, Ke Zhang 0039, Kehuan Zhang, Peng Liu 0005
IEEE Trans. Inf. Forensics Secur.1
2024 Style-conditional Prompt Token Learning for Generalizable Face Anti-spoofing
abstract
Face anti-spoofing (FAS) based on domain generalization (DG) has attracted increasing attention from researchers.The reason for the poor generalization is that the model is overfitted to salient liveness-irrelevant signals.However, the previous methods alleviate the overfitting by mapping the images from multiple domains into a common feature space or promoting the separation of image features from domain-specific features and task-related features.If the text features of vision-language pre-trained (VLP) models (e.g., CLIP) are used to dynamically adjust the image features to gain a better generalization, we can not only explore a wider feature space but also avoid the potential degradation of semantic information.Specifically, we propose a FAS method of Style-Conditional Prompt Token Learning (S-CPTL), which aims to generate generalized text features by training the introduced prompt tokens to carry visual styles and use them as weights for classifiers to improve the model's generalization.Compared to the inherently static prompt token, we propose the dynamic prompt token, which can adaptively capture live-irrelevant signals from the instance-specific styles and increase their diversity through mixed feature statistics to further reduce the overfitting of the model.Thorough experimental analysis demonstrates that S-CPTL exceeds current top-performing methods in four distinct cross-dataset benchmarks.
Jiabao Guo, Huan Liu 0030, Yizhi Luo, Xueli Hu, Hang Zou 0002, Yuan Zhang 0023, Hui Liu 0018, Bo Zhao 0023
ACM Multimedia7
2024 A lightweight unsupervised adversarial detector based on autoencoder and isolation forest
Hui Liu 0018, Bo Zhao 0023, Jiabao Guo, Kehuan Zhang, Peng Liu 0005
Pattern Recognit.1
2022 GreedyFool: Multi-factor imperceptibility and its application to designing a black-box adversarial attack
Hui Liu 0018, Bo Zhao 0023, Minzhi Ji, Mengchen Li, Peng Liu 0005
Inf. Sci.1
2020 FoolChecker: A platform to evaluate the robustness of images against adversarial attacks
Hui Liu 0018, Bo Zhao 0014, Linquan Huang, Jiabao Guo
Neurocomputing1
2020 A Lightweight Image Encryption Algorithm Based on Message Passing and Chaotic Map
abstract
The popularization of 5G and the development of cloud computing further promote the application of images. The storage of images in an untrusted environment has a great risk of privacy leakage. This paper outlines a design for a lightweight image encryption algorithm based on a message-passing algorithm with a chaotic external message. The message-passing (MP) algorithm allows simple messages to be passed locally for the solution to a global problem, which causes the interaction among adjacent pixels without additional space cost. This chaotic system can generate high pseudorandom sequences with high speed performance. A two-dimensional logistic map is utilized as a pseudorandom sequence generator to yield the external message sets of edge pixels. The external message can affect edge pixels, and then adjacent pixels interact with each other to produce an encrypted image. A MATLAB simulation shows the cipher-image performs fairly uniform distribution and has acceptable information entropy of 7.996749. The proposed algorithm reduces correlation coefficients from plain-image 1 to its cipher-image 0, which covers all of the plain-image characters with high computational efficiency (speed = 18.200374 Mbit/s). Theoretical analyses and experimental results prove the proposed algorithm’s persistence to various existing attacks with low cost.
Hui Liu 0018, Bo Zhao 0023, Jianwen Zou, Linquan Huang
Secur. Commun. Networks1
2019 A novel quantum image encryption algorithm based on crossover operation and mutation operation
Hui Liu 0018, Bo Zhao 0023, Linquan Huang
Multim. Tools Appl.1