EDBT 2026 Demo / reviewers in the wild / expert
Hui Liu 0018
dblp:93/4010-18
· DBLP profile ↗
11ranked-venue papers
10as first author
8since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 3 · 3 first-author · 2 since 2021Databases, data management, data science and information retrieval · 3 · 3 first-author · 3 since 2021Security and privacy · 2 · 2 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
3 papers |
Security and privacy of machine learning · 41% Privacy and data protection · 36% Biometric security · 22% | |
| Artificial intelligence
2 papers |
Language models and text generation · 57% Vision and language · 43% |
Topics — the 10 heaviest of 10, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Security and privacy of machine learning › adversarial attack
backdoor attack |
1.0 | 1 | 2026 | WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus Poisoning · KDD (1) 2026 |
Security and privacy of machine learning
retrieval-augmented generation security |
1.0 | 1 | 2026 | WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus Poisoning · KDD (1) 2026 |
Security and privacy of machine learning › poisoning attack
retrieval poisoning attack |
1.0 | 1 | 2026 | WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus Poisoning · KDD (1) 2026 |
Biometric security
face recognition |
0.9 | 1 | 2025 | Patronus: Plug-and-Play and Near-Lossless Facial Privacy Enhancement Against Reconstruction Attacks · IEEE Trans. Inf. Forensics Secur. 2025 |
Privacy and data protection
facial privacy protection |
0.9 | 1 | 2025 | Patronus: Plug-and-Play and Near-Lossless Facial Privacy Enhancement Against Reconstruction Attacks · IEEE Trans. Inf. Forensics Secur. 2025 |
Privacy and data protection › facial privacy protection
privacy-preserving face recognition |
0.9 | 1 | 2025 | Patronus: Plug-and-Play and Near-Lossless Facial Privacy Enhancement Against Reconstruction Attacks · IEEE Trans. Inf. Forensics Secur. 2025 |
Privacy and data protection › privacy protection mechanisms
reconstruction attack defense |
0.9 | 1 | 2025 | Patronus: Plug-and-Play and Near-Lossless Facial Privacy Enhancement Against Reconstruction Attacks · IEEE Trans. Inf. Forensics Secur. 2025 |
Biometric security
face anti-spoofing |
0.8 | 1 | 2024 | Style-conditional Prompt Token Learning for Generalizable Face Anti-spoofing · ACM Multimedia 2024 |
Natural language and speech › Language models and text generation
retrieval-augmented generation |
0.3 | 1 | 2026 | WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus Poisoning · KDD (1) 2026 |
Computer vision › Vision and language › vision-language model
vision-language pre-trained model |
0.2 | 1 | 2024 | Style-conditional Prompt Token Learning for Generalizable Face Anti-spoofing · ACM Multimedia 2024 |
Methods — techniques the papers use, named apart from their topics
word-level trigger injection · 2.0vision-language pretraining · 1.5style-conditional learning · 1.5prompt token learning · 1.5adversarial perturbation · 0.9
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | WARP: A Word-Level Backdoor Attack Targeting RAG Systems via Retrieval Corpus PoisoningabstractRetrieval-Augmented Generation (RAG) systems retrieve relevant documents from a corpus database to mitigate issues like hallucination, outdated knowledge, and limited domain coverage. While enhancing large language models (LLMs) performance, RAG also introduces a new attack surface: adversaries can inject trigger-embedded malicious documents into the corpus database, potentially causing the LLM to produce attacker-controlled outputs. Hui Liu 0018, Liguo Dong, Shui Yu 0001 |
KDD (1) | 1 |
| 2026 | Take off Your Disguise: Detecting Disguised Prompt-Based Jailbreak Attacks Against LLMsabstractLarge language models (LLMs) are typically equipped with alignment mechanisms designed to prevent the generation of harmful content. However, recent advances have led to the emergence of highly evasive disguised prompt jailbreak attacks (DPJAs), where attackers conceal real malicious intent within prompts that appear benign on the surface, thereby inducing the model to produce unsafe outputs. In this work, we propose prompt reconstruction-based detection (RePrompt), a training-free and plug-in detection framework designed to identify such jailbreak attacks. The key insight of RePrompt is that, when guided by carefully designed templates, LLMs possess the capability to uncover disguised adversarial prompts and effectively detect jailbreak attacks. RePrompt leverages the reasoning capabilities of the LLM itself to analyze and uncover the true intent behind a user’s query. When a disguised jailbreak prompt is encountered, RePrompt reconstructs the underlying malicious intent hidden beneath the surface-level disguise. Experiments across multiple LLMs, datasets, and three representative DPJAs demonstrate that RePrompt consistently outperforms state-of-the-art defense methods, reducing the average attack success rate from 47.0% to below 1.6%, achieving a near-zero false positive rate, and limiting the average query cost to only 1.13. Hui Liu 0018, Fujv Wen, Hongqin Du, Jiabao Guo, Bo Zhao 0023 |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2026 | Adversarial Face Database against Deep Learning-Enabled Reconstruction AttacksabstractFace recognition systems offer a range of applications that enhance security, efficiency, and personalization, e.g., access control, identity verification, and personalized services. Mainstream facial recognition systems employ the Edge-Cloud architecture to protect user privacy by storing facial feature data instead of original facial images. However, recently emerging reconstruction attacks based on deep learning can recover the visual information of original facial images from facial features, resulting in face privacy disclosure. Existing anti-reconstruction approaches either compromise facial recognition accuracy or fail to meet real-time requirements. In this article, we propose a practical privacy-preserving approach based on adversarial perturbations against reconstruction attacks. By incorporating subtle adversarial interference into facial features, the mapping relationship from facial features to original facial images is disrupted, and the baseline reconstruction networks cannot recover the original face image. We conducted experiments on two facial recognition models, FaceNet and ArcFace, both widely deployed in practical scenarios. The results show that the face recognition accuracy sacrifice of less than 1% can significantly reduce the quality of the reconstructed image. In terms of efficiency, the average time to generate an adversarial facial feature is less than 10 ms, meeting the real-time requirements of facial recognition. Hui Liu 0018, Jiageng Chen, Jiabao Guo |
ACM Trans. Intell. Syst. Technol. | 1 |
| 2025 | Research on Runtime Memory Space Reconstruction Techniques for Source-Unavailable Programs on AArch64abstractWith the widespread adoption of AArch64 architecture processors in mobile and IoT devices, ensuring the security of applications running on AArch64 systems against memory error vulnerabilities has become a critical research focus in the field of cybersecurity. However, traditional passive defense mechanisms have increasingly shown their limitations, and the growing demand for robust protection has driven continuous advancements in active defense technologies.To address the limitations of current memory protection techniques on AArch64 systems and the need for heterogeneity in heterogeneous redundant execution, we propose BinaryDMR, an efficient, selective, and lightweight runtime memory space reconfiguration tool specifically designed for source-unavailable programs.The core idea behind BinaryDMR is to statically reconstruct the runtime memory layout of source-unavailable programs, such as commercial-off-the-shelf (COTS) binaries, using static binary rewriting and library transformation techniques, including the stack, heap, code segments, and shared libraries.We have implemented BinaryDMR and evaluated its performance using a set of binary programs, including 19 kernel utilities (focused on file I/O operations) and one network daemon, Nginx (focused on network I/O operations). Experimental results demonstrate that BinaryDMR significantly reduces the success rate of common memory error-related attacks, effectively mitigates security risks arising from software homogeneity, and delivers strong practicality with minimal performance overhead. Hui Liu 0018, Guoqing Peng, Bo Zhao 0010 |
IEEE Internet Things J. | 1 |
| 2025 | Patronus: Plug-and-Play and Near-Lossless Facial Privacy Enhancement Against Reconstruction AttacksabstractReconstruction attackers can exploit facial features to recover the original user’s face, resulting in user privacy leakage. One new strategy to enhance the “Edge-Cloud” face recognition system’s privacy is to add adversarial perturbations to facial features, preventing the attackers from high-quality user image recovery. However, the existing works following this strategy suffer from unacceptable damage to face recognition accuracy. Achieving robust privacy enhancement and face recognition accuracy simultaneously is still challenging. To tackle this challenge, we propose an adversarial perturbation-based plug-and-play privacy-enhancing method (Patronus) with robustness against face image reconstruction attacks and near-lossless face recognition performance. The key insight is derived from our observation that the feature distance between two face images of the same person is significantly lower than the threshold set in the face recognition system. This leaves room for adding adversarial perturbations to the facial features without compromising face recognition accuracy. Our strategy limits the amount of adversarial perturbations in a fine-grained manner to ensure that they are within the range of not damaging face recognition accuracy. Our evaluation shows the superior performance ofPatronusin robustness against reconstruction attacks and near-lossless face recognition accuracy compared to state-of-the-art (SOTA) methods.Patronuscan be easily integrated into deployed face recognition systems as a plug-in privacy-enhancing module with low overhead. Hui Liu 0018, Hongqin Du, Jiageng Chen, Ke Zhang 0039, Kehuan Zhang, Peng Liu 0005 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Style-conditional Prompt Token Learning for Generalizable Face Anti-spoofingabstractFace anti-spoofing (FAS) based on domain generalization (DG) has attracted increasing attention from researchers.The reason for the poor generalization is that the model is overfitted to salient liveness-irrelevant signals.However, the previous methods alleviate the overfitting by mapping the images from multiple domains into a common feature space or promoting the separation of image features from domain-specific features and task-related features.If the text features of vision-language pre-trained (VLP) models (e.g., CLIP) are used to dynamically adjust the image features to gain a better generalization, we can not only explore a wider feature space but also avoid the potential degradation of semantic information.Specifically, we propose a FAS method of Style-Conditional Prompt Token Learning (S-CPTL), which aims to generate generalized text features by training the introduced prompt tokens to carry visual styles and use them as weights for classifiers to improve the model's generalization.Compared to the inherently static prompt token, we propose the dynamic prompt token, which can adaptively capture live-irrelevant signals from the instance-specific styles and increase their diversity through mixed feature statistics to further reduce the overfitting of the model.Thorough experimental analysis demonstrates that S-CPTL exceeds current top-performing methods in four distinct cross-dataset benchmarks. Jiabao Guo, Huan Liu 0030, Yizhi Luo, Xueli Hu, Hang Zou 0002, Yuan Zhang 0023, Hui Liu 0018, Bo Zhao 0023 |
ACM Multimedia | 7 |
| 2024 | A lightweight unsupervised adversarial detector based on autoencoder and isolation forest
Hui Liu 0018, Bo Zhao 0023, Jiabao Guo, Kehuan Zhang, Peng Liu 0005 |
Pattern Recognit. | 1 |
| 2022 | GreedyFool: Multi-factor imperceptibility and its application to designing a black-box adversarial attack
Hui Liu 0018, Bo Zhao 0023, Minzhi Ji, Mengchen Li, Peng Liu 0005 |
Inf. Sci. | 1 |
| 2020 | FoolChecker: A platform to evaluate the robustness of images against adversarial attacks
Hui Liu 0018, Bo Zhao 0014, Linquan Huang, Jiabao Guo |
Neurocomputing | 1 |
| 2020 | A Lightweight Image Encryption Algorithm Based on Message Passing and Chaotic MapabstractThe popularization of 5G and the development of cloud computing further promote the application of images. The storage of images in an untrusted environment has a great risk of privacy leakage. This paper outlines a design for a lightweight image encryption algorithm based on a message-passing algorithm with a chaotic external message. The message-passing (MP) algorithm allows simple messages to be passed locally for the solution to a global problem, which causes the interaction among adjacent pixels without additional space cost. This chaotic system can generate high pseudorandom sequences with high speed performance. A two-dimensional logistic map is utilized as a pseudorandom sequence generator to yield the external message sets of edge pixels. The external message can affect edge pixels, and then adjacent pixels interact with each other to produce an encrypted image. A MATLAB simulation shows the cipher-image performs fairly uniform distribution and has acceptable information entropy of 7.996749. The proposed algorithm reduces correlation coefficients from plain-image 1 to its cipher-image 0, which covers all of the plain-image characters with high computational efficiency (speed = 18.200374 Mbit/s). Theoretical analyses and experimental results prove the proposed algorithm’s persistence to various existing attacks with low cost. Hui Liu 0018, Bo Zhao 0023, Jianwen Zou, Linquan Huang |
Secur. Commun. Networks | 1 |
| 2019 | A novel quantum image encryption algorithm based on crossover operation and mutation operation
Hui Liu 0018, Bo Zhao 0023, Linquan Huang |
Multim. Tools Appl. | 1 |