EDBT 2026 Demo / reviewers in the wild / expert
Lu Yan
dblp:y/LuYan
· DBLP profile ↗
28ranked-venue papers
10as first author
13since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 7 · 2 first-author · 5 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 2 first-author · 4 since 2021Security and privacy · 4 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 4 · 1 first-author · 1 since 2021Computer networks · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Temporal Logic-Based Multi-Vehicle Backdoor Attacks against Offline RL Agents in End-to-end Autonomous DrivingabstractAssessing the safety of autonomous driving (AD) systems against security threats, particularly backdoor attacks, is a stepping stone for real-world deployment. However, existing works mainly focus on pixel-level triggers which are impractical to deploy in the real world. We address this gap by introducing a novel backdoor attack against the end-to-end AD systems that leverage one or more other vehicles' trajectories as triggers. To generate precise trigger trajectories, we first use temporal logic (TL) specifications to define the behaviors of attacker vehicles. Configurable behavior models are then used to generate these trajectories, which are quantitatively evaluated and iteratively refined based on the TL specifications. We further develop a negative training strategy by incorporating patch trajectories that are similar to triggers but are designated not to activate the backdoor.
It enhances the stealthiness of the attack and refines the system’s responses to trigger scenarios.
Through extensive experiments on 5 offline reinforcement learning (RL) driving agents with 6 trigger patterns and target actions combinations, we demonstrate the flexibility and effectiveness of our proposed attack, showing the under-exploration of existing end-to-end AD systems' vulnerabilities to such trajectory-based backdoor attacks.
Videos of our attack are available at: https://sites.google.com/view/tlbackdoor/home. Xuan Chen 0003, Shiwei Feng 0002, Zikang Xiong, Shengwei An, Yunshu Mao, Lu Yan, Guanhong Tao 0001, Wenbo Guo 0002, Xiangyu Zhang 0001 |
NeurIPS | 6 |
| 2025 | VERA: Variational Inference Framework for Jailbreaking Large Language ModelsabstractThe rise of API-only access to state-of-the-art LLMs highlights the need for effective black-box jailbreak methods to identify model vulnerabilities in real-world settings. Without a principled objective for gradient-based optimization, most existing approaches rely on genetic algorithms, which are limited by their initialization and dependence on manually curated prompt pools. Furthermore, these methods require individual optimization for each prompt, failing to provide a comprehensive characterization of model vulnerabilities.
To address this gap, we introduce VERA: Variational infErence fRamework for jAilbreaking. VERA casts black-box jailbreak prompting as a variational inference problem, training a small attacker LLM to approximate the target LLM’s posterior over adversarial prompts. Once trained, the attacker can generate diverse, fluent jailbreak prompts for a target query without re-optimization. Experimental results show that VERA achieves strong performance across a range of target LLMs, highlighting the value of probabilistic inference for adversarial prompt generation. Anamika Lochab, Lu Yan, Patrick Pynadath, Xiangyu Zhang 0001, Ruqi Zhang |
NeurIPS | 2 |
| 2025 | BAIT: Large Language Model Backdoor Scanning by Inverting Attack TargetabstractRecent literature has shown that LLMs are vulnerable to backdoor attacks, where malicious attackers inject a secret token sequence (i.e., trigger) into training prompts and enforce their responses to include a specific target sequence. Unlike discriminative NLP models, which have a finite output space (e.g., those in sentiment analysis), LLMs are generative models, and their output space grows exponentially with the length of response, thereby posing significant challenges to existing backdoor detection techniques, such as trigger inversion. In this paper, we conduct a theoretical analysis of the LLM backdoor learning process under specific assumptions, revealing that the autoregressive training paradigm in causal language models inherently induces strong causal relationships among tokens in backdoor targets. We hence develop a novel LLM backdoor scanning technique, BAIT (Large Language Model Backdoor ScAnning by Inverting Attack Target). Instead of inverting back-door triggers like in existing scanning techniques for non-LLMs, BAIT determines if a model is backdoored by inverting back-door targets, leveraging the exceptionally strong causal relations among target tokens. BAIT substantially reduces the search space and effectively identifies backdoors without requiring any prior knowledge about triggers or targets. The search-based nature also enables BAIT to scan LLMs with only the black-box access. Evaluations on 153 LLMs with 8 architectures across 6 distinct attack types demonstrate that our method outperforms 5 baselines. Its superior performance allows us to rank at the top of the leaderboard in the LLM round of the TrojAI competition (a multi-year, multi-round backdoor scanning competition). Guangyu Shen, Siyuan Cheng 0005, Zhuo Zhang 0002, Guanhong Tao 0001, Kaiyuan Zhang 0002, Hanxi Guo, Lu Yan, Xiaolong Jin 0002, Shengwei An, Shiqing Ma, Xiangyu Zhang 0001 |
SP | 7 |
| 2025 | Anomaly Monitoring of Dynamic Wastewater Regeneration Process Based on Recursive Broad Learning SystemabstractIn the wastewater regeneration process, a condition monitoring system must have dynamic adaptability to new operating conditions while maintaining a lasting adaptability to existing conditions to ensure efficient and stable operation. This paper proposes a Slow Feature Recursive Broad Learning System (SF-RBLS) to achieve incremental learning of new knowledge and sustained adaptation to condition characteristics. The model takes advantage of the incremental learning mechanism of the broad learning system, enabling online learning of unknown features as new operating conditions emerge. An innovative coupling mechanism between the slow feature space and the recursive structure is constructed. Through the slow feature analysis mechanism, temporal constraints are imposed on the dynamic evolution process of the recursive window, enabling the feature extraction process to simultaneously generate long-term steady state representations and short-term dynamic responses, achieving enduring adaptability to various conditions. Experimental results demonstrate that SF-RBLS exhibits significant advantages over state-of-the-art methods in both accuracy and stability for real-time monitoring and anomaly detection, confirming its effectiveness and potential in intelligent wastewater reclamation monitoring. Lu Yan |
IEEE Trans Autom. Sci. Eng. | 2 |
| 2025 | A DEM Differencing Method for Detecting Geomorphic Changes on Topographically Complex Areas Based on RAV Remote Sensing TechniquesabstractHigh-resolution topographic data acquired by remote aerial vehicles (RAVs) have facilitated the use of digital elevation model (DEM) and DEM of difference (DoD) methods for studying geomorphic processes in complex terrain. However, insufficient understanding of systematic bias and random errors for DEMs constrained the application. In this study, we comprehensively analyzed the spatial pattern and magnitude of errors (including systematic and random errors) of DEMs derived from RAV-acquired point clouds for a topographically complex area (a subcatchment of Qiaogou in the hilly and gully loess plateau (SC_QG), China). The relationships between random errors and influential factors associated with topography, point cloud density, vegetation, and interpolation algorithms were also evaluated. On this basis, an error source thresholding (EST) method was adapted through incorporating residual systematic errors and including more impacting factors in the fuzzy inference system for random error estimation. The adapted EST (AEST) method was then employed to quantify the DoD uncertainty and geomorphic changes in two small catchments with complex terrain (i.e., SC_QG and a sub-catchment of Telagou (SC_TLG) in the hilly and gully Loess Plateau, China), while the results were verified by the changes measured by terrestrial laser scanning (TLS) and erosion pins, respectively. Results showed that mean value of systematic errors of DEMs were 0.065 and 0.005 m for SC_QG and SC_TLG, while the residual errors were reduced to 0.002 and 0.001 m after co-registration, respectively. Significant statistical relationships (${p} \lt 0.01$) were found between random errors and influential factors. The erosional volume of two study sites detected by the adapted method were −252.29 and −981.07 m3 and the corresponding depositional volume were 30.57 and 1594.32 m3, respectively. The adapted method achieved a comparable pattern and magnitude of volumetric changes with TLS results, which was superior to the original EST method in SC_QG. Besides, our method showed a lower absolute error (0.034 m) compared to the original method (0.087 m) through a comparison with erosion pins measurement in the SC_TLG. Overall, the AEST method provided a reliable tool for geomorphic change detection in areas associated with complex terrain. Dou Li, Pengfei Li 0010, Jinfei Hu, Wanqiang Yao, Lu Yan, Hooman Latifi, Bingzhe Tang, Lifeng Liu |
IEEE Trans. Geosci. Remote. Sens. | 5 |
| 2024 | Rethinking the Invisible Protection against Unauthorized Image Usage in Stable Diffusion
Shengwei An, Lu Yan, Siyuan Cheng 0005, Guangyu Shen, Kaiyuan Zhang 0002, Qiuling Xu, Guanhong Tao 0001, Xiangyu Zhang 0001 |
USENIX Security Symposium | 2 |
| 2024 | OSSEFS: An online semi-supervised ensemble fuzzy system for data streams learning with missing values
Lu Yan, Tao Zhao 0003, Xiangpeng Xie 0001, Radu-Emil Precup |
Expert Syst. Appl. | 1 |
| 2024 | CrossFix: Resolution of GitHub issues via similar bugs recommendationabstractSummary With the increasing popularity of Open‐Source Software (OSS), the number of GitHub issues reported daily in these OSS projects has been growing rapidly. To resolve these issues, developers need to spend time and effort in debugging and fixing these issues. Meanwhile, a recent approach shows that similar bugs exist across different projects, and one could use the GitHub issues from a different project for finding new bugs for a related project. To locate similar bugs for our approach, we first conduct a study of similar bugs in GitHub. Our study redefines similar bugs as bugs that share the (1) same libraries, (2) same functionalities, (3) same reproduction steps, (4) same configurations, (5) same outcomes, or (6) same errors. Moreover, our study revealed the usefulness of similar bugs in helping developers to find more contexts about the bug and fixing. Based on our study, we design CrossFix, a tool that automatically suggests relevant GitHub issues based on an open GitHub issue. The suggested GitHub issues may contain solutions written in natural language or pull requests that help developers in resolving the given issue. Our evaluation on 249 open issues from Java and Android projects shows that CrossFix could suggest similar bugs to help developers in debugging and fixing. Shin Hwei Tan, Ziqiang Li 0005, Lu Yan |
J. Softw. Evol. Process. | 3 |
| 2023 | ParaFuzz: An Interpretability-Driven Technique for Detecting Poisoned Samples in NLPabstractBackdoor attacks have emerged as a prominent threat to natural language processing (NLP) models, where the presence of specific triggers in the input can lead poisoned models to misclassify these inputs to predetermined target classes. Current detection mechanisms are limited by their inability to address more covert backdoor strategies, such as style-based attacks. In this work, we propose an innovative test-time poisoned sample detection framework that hinges on the interpretability of model predictions, grounded in the semantic meaning of inputs.
We contend that triggers (e.g., infrequent words) are
not supposed to fundamentally alter the underlying semantic meanings of poisoned samples as they want to stay stealthy. Based on this observation, we hypothesize that while the model's predictions for paraphrased clean samples should remain stable, predictions for poisoned samples should revert to their true labels upon the mutations applied to triggers during the paraphrasing process.
We employ ChatGPT, a state-of-the-art large language model, as our paraphraser and formulate the trigger-removal task as a prompt engineering problem. We adopt fuzzing, a technique commonly used for unearthing software vulnerabilities, to discover optimal paraphrase prompts that can effectively eliminate triggers while concurrently maintaining input semantics.
Experiments on 4 types of backdoor attacks, including the subtle style backdoors, and 4 distinct datasets demonstrate that our approach surpasses baseline methods, including STRIP, RAP, and ONION, in precision and recall. Lu Yan, Zhuo Zhang 0002, Guanhong Tao 0001, Kaiyuan Zhang 0002, Xuan Chen 0003, Guangyu Shen, Xiangyu Zhang 0001 |
NeurIPS | 1 |
| 2022 | Malsite-Deep: Prediction of protein malonylation sites through deep learning and multi-information fusion based on NearMiss-2 strategy
Lili Song, Yaqun Zhang, Hongli Gao, Lu Yan, Bin Yu 0007 |
Knowl. Based Syst. | 5 |
| 2021 | Joint Vehicle Association and Power Allocation for Energy Efficient Connected Automated VehiclesabstractConnected Automated Vehicle (CAV) is a promising paradigm for achieving safe and intelligent transportation systems. In CAV scenario, massive raw sensor data needs to be shared among vehicles under strict latency and high data rate constraints, which poses critical challenges on existing low data rate vehicular communication on 5.9 GHz band. To address these challenges, we propose a millimeter wave (mmWave) enabled CAV network with high capacity to support the raw sensor data sharing among vehicles. A joint vehicle association and power allocation (JVAPA) algorithm is proposed to maximize date rate while minimize energy consumption for CAVs. The one-to-many vehicle association problem is formulated as a swap matching model, and the stable matching states for CAVs and BSs association are achieved. The non-convex power allocation problem is transformed into a convex problem using the first order Taylor expansion, and the optimal power allocation results are achieved. Numerical results verify that the proposed JVAPA algorithm can significantly improve the energy efficiency compared with the benchmark algorithms. Qixun Zhang, Lu Yan, Zhiyong Feng 0001, Ke Zhang 0008, Yan Zhang 0002 |
GLOBECOM | 2 |
| 2021 | Data-Enabled Digestive Medicine: A New Big Data Analytics PlatformabstractThis paper presents a big data analystics platform for clinical research and practice in the Gastroenterology Department of Xiangya Hospital at Central South University in China. This platform features a comprehensive and systematic support of big data in digestive medicine including geneneral health management, clinical gastroenterology practice, and related genomics research, which is proven to be helpful in real world clinical practices. A typical use case of integrated analysis based on electronic medical records and colonoscopy data was presented and discussed, the analaystic report on risk factors of colorectal diseases shows a reasonable recommendation about the age when people should start to screen the colorectal cancer, which could be very useful to individual and group health management for the general population in China. Lu Yan, Yonghong Peng |
IEEE ACM Trans. Comput. Biol. Bioinform. | 1 |
| 2021 | Virtual Parameter Learning-Based Adaptive Control for Protective Automatic Train OperationabstractThis article addresses the speed-distance trajectory tracking control problem for railway trains to facilitate the effectuation of automation train operation (ATO). By proposing a new virtual parameter learning-based approach, we develop an adaptive control that exhibits twofold new features with comparison to the existing literatures:i), while the nonlinear operational resistance and railway line gradient profile are unknown, the proposed control not only bears a quite computationally inexpensive simplicity in structure but also achieves accurate tracking control with respect to the speed-distance trajectory benefiting by the virtual parameter learning approach and requiring no function approximators with linearized structure, for example, common utilization of neural or fuzzy approximations, to cope with the uncertain dynamic nonlinearities in real-time, andii), by introducing a nonlinear error transformation, the protection enveloping problem, which is generally introduced by the onboard automatic train protection and wayside subsystems, operating independently from the ATO subsystem in practice, are considered explicitly to the control design for ATO for the first time. By invoking Lyapunov stability theorem, the resulting closed-loop system is guaranteed to be globally stable with rigorously analysis and proof. Meanwhile, in order to verify and validate the effectiveness and advantages of theoretical findings, experimental and comparative results, by applying the designed controller to the whole Beijing railway Yizhuang line, are shown. Zhiming Yuan, Lu Yan, Tao Zhang 0082, Shigen Gao |
IEEE Trans. Intell. Transp. Syst. | 2 |
| 2020 | High School Students' Online Interaction in a Less-developed Region in China
Lu Yan, Chunping Zheng |
ICCE | 1 |
| 2020 | MTFuzz: fuzzing with a multi-task neural networkabstractFuzzing is a widely used technique for detecting software bugs and vulnerabilities. Most popular fuzzers generate new inputs using an evolutionary search to maximize code coverage. Essentially, these fuzzers start with a set of seed inputs, mutate them to generate new inputs, and identify the promising inputs using an evolutionary fitness function for further mutation.Despite their success, evolutionary fuzzers tend to get stuck in long sequences of unproductive mutations. In recent years, machine learning (ML) based mutation strategies have reported promising results. However, the existing ML-based fuzzers are limited by the lack of quality and diversity of the training data. As the input space of the target programs is high dimensional and sparse, it is prohibitively expensive to collect many diverse samples demonstrating successful and unsuccessful mutations to train the model.In this paper, we address these issues by using a Multi-Task Neural Network that can learn a compact embedding of the input space based on diverse training samples for multiple related tasks (i.e.,predicting for different types of coverage). The compact embedding can guide the mutation process by focusing most of the mutations on the parts of the embedding where the gradient is high. MTFuzz uncovers 11 previously unseen bugs and achieves an average of 2× more edge coverage compared with 5 state-of-the-art fuzzer on 10 real-world programs Dongdong She, Rahul Krishna, Lu Yan, Suman Jana, Baishakhi Ray |
ESEC/SIGSOFT FSE | 3 |
| 2018 | Service Differentiation Strategy Based on User Demands for Https Web ServersabstractMore and more websites adopt Hypertext Transfer Protocol Secure (HTTPS) protocol to provide data security, while it also brings overhead to users and servers. Security and response time are important for user experience, unfortunately they cannot get the best at the same time. Since the demands are different various from users, it is feasible for servers to provide differentiated services. Based on this, we put forward a service differentiation strategy for https web servers. Firstly, we propose the adaptive goals cipher suite selection algorithm to meet the different demands for security and response time. Moreover, we further improve the performance by the priority strategy based on scheduling period. It reduces the response time for higher priority requests and guarantees the response time for lower priority requests, while reducing the average system response time. Experiments prove the efficiency of our method, and when the server load is high, the advantage of our strategy is more obvious. Lu Yan, Haojiang Deng, Xiaozhou Ye |
SERA | 1 |
| 2017 | New Proof for BKP IBE Scheme and Improvement in the MIMC Setting
Lu Yan, Jian Weng 0001, Zheng Yang 0001 |
ISPEC | 2 |
| 2017 | LRSSL: predict and interpret drug-disease associations based on data integration using sparse subspace learningabstractMotivation: : Exploring the potential curative effects of drugs is crucial for effective drug development. Previous studies have indicated that integration of multiple types of information could be conducive to discovering novel indications of drugs. However, how to efficiently identify the mechanism behind drug-disease associations while integrating data from different sources remains a challenging problem. Results: : In this research, we present a novel method for indication prediction of both new drugs and approved drugs. This method is based on Laplacian regularized sparse subspace learning (LRSSL), which integrates drug chemical information, drug target domain information and target annotation information. Experimental results show that the proposed method outperforms several recent approaches for predicting drug-disease associations. Some drug therapeutic effects predicted by the method could be validated by database records or literatures. Moreover, with L1-norm constraint, important drug features have been extracted from multiple drug feature profiles. Case studies suggest that the extracted drug features could be beneficial to interpretation of the predicted results. Availability and Implementation: https://github.com/LiangXujun/LRSSL. Contact: [email protected]. Supplementary information: Supplementary data are available at Bioinformatics online. Xujun Liang, Pengfei Zhang 0009, Lu Yan |
Bioinform. | 3 |
| 2014 | A Less Conservative Guaranteed Cost Stabilization of Time-Varying Delayed CNNs
Mei Jiang, Hanlin He, Lu Yan |
ISNN | 3 |
| 2012 | Guaranteed Cost Stabilization of Time-varying Delay Cellular Neural Networks via Riccati Inequality Approach
Hanlin He, Lu Yan, Jianjun Tu |
Neural Process. Lett. | 2 |
| 2009 | Multimodal security enforcement framework for wireless ad hoc networksabstractOriginal article can be found at: http://portal.acm.org/ Copyright ACM [Full text of this article is not available in the UHRA] Lu Yan, Nasser Abouzakhar, Hannan Xiao |
IWCMC | 1 |
| 2008 | Analysis of Packet Relaying Models and Incentive Strategies in Wireless Ad Hoc Networks with Game TheoryabstractIn wireless ad hoc networks, nodes are both routers and terminals, and they have to cooperate to communicate. Cooperation at the network layer means routing (finding a path for a packet), and forwarding (relaying packets for others). However, because wireless nodes are usually constrained by limited power and computational resources, a selfish node may be unwilling to spend its resources in forwarding packets that are not of its direct interest, even though it expects other nodes to forward its packets to the destination. In this paper, we propose a game-theoretic model to facilitate the study of the non-cooperative behaviors in wireless ad hoc networks and analyze incentive schemes to motivate cooperation among wireless ad hoc network nodes to achieve a mutually beneficial networking result. Lu Yan, Stephen Hailes, Licia Capra |
AINA | 1 |
| 2007 | Dependability Aspects of Ubiquitous ComputingabstractWith more than 2 billions terminals in commercial operation world-wide, wireless and mobile technologies have enabled a first wave of pervasive communication systems and applications. Still, this is only the beginning, as wireless technologies such as RFID are currently contemplated with a deployment potential of ten's of billions of tags and a virtually unlimited application potential. Although significant R&D work has been undertaken over recent years on these systems, most of the research is still very application specific, with security and environmental applications dominating and demonstration driven. However, it is likely that more generic and comprehensive approach is required, where different stakeholders and research specialists work together to solve true systems level problems Lu Yan, Kaisa Sere |
ARES | 1 |
| 2006 | Implementing a Self-Timed Low-Power Java Accelerator for Network-on-Chip ApplicationsabstractThis paper presents an advanced self-timed Java accelerator core which has extremely low power consumption while providing sufficient performance for even the most demanding real-time telecommunication and multimedia applications. The goal is that the accelerator can be directly attached to any general-purpose processor core running some Java-intensive application software. Asynchronous self-timed circuit technology, where timing is based on local handshakes between circuit blocks instead of a global clock signal, provides a promising platform for obtaining a highly modular low-power Java accelerator implementation Juha Plosila, Lu Yan, Kaisa Sere |
PDCAT | 3 |
| 2006 | A Formal Model of Context-Awareness and Context-DependencyabstractThe communication environment surrounding our daily experience is increasingly characterized by mobile devices that can exchange multimedia information and provide access to various services of complex nature. The trend is now clear that future consumer computing experience will be based on multiple pervasive communication devices and services, where navigability, context-sensitivity, adaptability and ubiquity are key characteristics. Several issues have been studied, models and methodologies proposed, and tools and systems implemented. However, we look at the foundation, where some of the most relevant issues probably are a formal model of context-awareness and context-dependency. In this paper, we discuss a formal foundation and software engineering techniques for mobile context-aware and context-dependent service derivation and application development, emphasizing the relationships between context and system. Mats Neovius, Kaisa Sere, Lu Yan, Manoranjan Satpathy |
SEFM | 3 |
| 2005 | Can P2P Benefit from MANET? Performance Evaluation from Users' Perspective
Lu Yan |
MSN | 1 |
| 2005 | On-chip Debug for an Asynchronous Java AcceleratorabstractThe solution to debug a problem in a deeply embedded system is to integrate the debug and communication module inside the chip. In this paper, we propose an on-chip in-circuit emulation (ICE) architecture for debugging an asynchronous Java accelerator core which can be integrated with any existing processor and operating system. The operation of this ICE module and the debug strategy of the Java accelerator are specifically designed for asynchronous implementation. They not only facilitate the system development but also provide a manufacture test method for asynchronous chips. Juha Plosila, Lu Yan, Kaisa Sere |
PDCAT | 3 |
| 2005 | Reconfigurable Computing in Ubiquitous Computers: A RoadmapabstractReconfigurable Computing (RC) is the presence of hardware that can be reconfigured to implement specific functionality more suitable for specially tailored hardware than on a simple uniprocessor [1]. Although the concept was first proposed in the 1960s, RC has only recently become increasingly popular due to the prevalence of ubiquitous computing: the gracefully integrated software and hardware to support and ease daily activities of human society. This scenario is appealing from a scientific point of view, since most of the open problems and several of the concepts require fine-tuning. This paper describes some selected areas of RC practice in the ubiquitous computing era, and presents a roadmap for the future. Lu Yan |
PDCAT | 1 |