Gelei Deng lists you as their PhD advisor. Claim this profile to confirm it and keep the rest of your record right.
Claim this profileAcademic lineage
View as a treeStudents and postdocs1
Works286 from public data
- Instruction Tuning for Large Language Models: A Survey955
This work makes a systematic review of the literature, including the general methodology of IT, the construction of IT datasets, the training of IT models, and applications to different modalities, domains and application, along with analysis of aspects that influence the outcome of IT.
- Prompt Injection attack against LLM-integrated Applications926
This study deconstructs the complexities and implications of prompt injection attacks on actual LLM-integrated applications and forms HouYi, a novel black-box prompt injection attack technique, which draws inspiration from traditional web injection attacks.
- GPT-NER: Named Entity Recognition via Large Language Models481
GPT-NER exhibits a greater ability in the low-resource and few-shot setups, when the amount of training data is extremely scarce, and performs significantly better than supervised models, which demonstrates the capabilities of GPT-ner in real-world NER applications where the number of labeled examples is limited.
- Model inversion attacks against collaborative inference418
A new set of attacks to compromise the inference data privacy in collaborative deep learning systems, where one malicious participant can accurately recover an arbitrary input fed into this system, even if he has no access to other participants' data or computations.
- 332
- Text Classification via Large Language Models296
Clue And Reasoning Prompting (CARP) adopts a progressive reasoning strategy tailored to addressing the complex linguistic phenomena involved in text classification, and achieves comparable performances to supervised models with 1,024 examples per class.
- MASTERKEY: Automated Jailbreaking of Large Language Model Chatbots275
Jailbreaker is presented, a comprehensive framework that offers an in-depth understanding of jailbreak attacks and countermeasures, and an automatic generation method for jailbreak prompts is introduced, leveraging a fine-tuned LLM to validate the potential of automated jailbreak generation across various commercial LLM chatbots.
- DeepSweep: An Evaluation Framework for Mitigating DNN Backdoor Attacks using Data Augmentation230
A systematic approach is proposed to discover the optimal policies for defending against different backdoor attacks by comprehensively evaluating 71 state-of-the-art data augmentation functions and envision this framework can be a good benchmark tool to advance future DNN backdoor studies.
- Characterization and prediction of deep learning workloads in large-scale GPU datacenters223
This work performs a large-scale analysis of real-world job traces from SenseTime, and introduces a general-purpose framework, which manages resources based on historical data, about the characteristics of DL jobs and resource management.
- MasterKey: Automated Jailbreak Across Multiple Large Language Model Chatbots206
A novel method that utilizes time-based characteristics intrinsic to the generation process to deconstruct the defense mechanisms employed by popular LLM chatbot services, and an innovative method for the automatic generation of jailbreak prompts that target robustly defended LLM chatbots.
- PentestGPT: An LLM-empowered Automatic Penetration Testing Tool204
PentestGPT is an LLM-empowered automatic penetration testing tool that leverages the abundant domain knowledge inherent in LLMs and proves effective in tackling real-world penetration testing challenges.
- 179
- Deep Learning Workload Scheduling in GPU Datacenters: A Survey160
This article surveys existing research efforts for both training and inference workloads and primarily presents how existing schedulers facilitate the respective workloads from the scheduling objectives and resource utilization manner.
- Stealthy and Efficient Adversarial Attacks against Deep Reinforcement Learning152
Two novel adversarial attack techniques to stealthily and efficiently attack the DRL agents by enabling an adversary to inject adversarial samples in a minimal set of critical moments while causing the most severe damage to the agent.
- 142
- A Comprehensive Survey in LLM(-Agent) Full Stack Safety: Data, Training and Deployment139
This paper introduces the concept of "full-stack" safety to systematically consider safety issues throughout the entire process of LLM training, deployment, and eventual commercialization, and represents the first safety survey to encompass the entire lifecycle of LLMs.
- Self-supervised learning for medical image data with anatomy-oriented imaging planes136
Thorough experiments on two anatomical structures and representative target tasks demonstrate that the proposed pretext tasks are effective in pretraining deep networks for remarkably boosted performance on the target tasks, and superior to other recent approaches.
- Triggerless Backdoor Attack for NLP Tasks with Clean Labels109
A new strategy to perform textual backdoor attack which does not require an external trigger and the poisoned samples are correctly labeled is proposed, which marks the first step towards developing triggerless attacking strategies in NLP.
- 108
- A Hitchhiker’s Guide to Jailbreaking ChatGPT via Prompt Engineering103
It was discovered that GPT-3.5 and GPT-4 could still generate inappropriate content in response to malicious prompts without the need for jailbreaking, underscores the critical need for effective prompt management within LLM systems and provides valuable insights and data to spur further research in LLM testing and jailbreak prevention.
- 96
- AquaLoRA: Toward White-box Protection for Customized Stable Diffusion Models via Watermark LoRA93
A merge watermark information into the U-Net of Stable Diffusion Models via a watermark Low-Rank Adaptation (LoRA) module in a two-stage manner and a scaling matrix to achieve flexible message updates without retraining are proposed.
- Byzantine-Resilient Decentralized Stochastic Gradient Descent88
Ubar is proposed, a novel algorithm to enhance decentralized learning with Byzantine Fault Tolerance that guarantees that each benign node in a decentralized system can train a correct model under very strong Byzantine attacks with an arbitrary number of faulty nodes.
- 87
- Physical Backdoor Attacks to Lane Detection Systems in Autonomous Driving83
The lane detection system is targeted, which is an indispensable module for many autonomous driving tasks, e.g., navigation, lane switching, and the first physical backdoor attacks to such system are designed and realized.
- Safety at Scale: A Comprehensive Survey of Large Model and Agent Safety76
This survey provides a systematic review of current safety research on large models, covering Vision Foundation Models, Large Language Models, Vision-Language Pre-training models, Vision-Language Models, Diffusion Models, and large-model-powered Agents, and presents a comprehensive taxonomy of safety threats to these models.
- A survey on cybersecurity attacks and defenses for unmanned aerial systems73
A comprehensive review of UAS cybersecurity research, with a focus on attack and defense technologies, analyzes the UAS architecture and classifies security threats into four categories: communication network security, software security, payload security, and intelligent security.
- Lucid: A Non-intrusive, Scalable and Interpretable Scheduler for Deep Learning Training Jobs73
Lucid is designed and implemented, a non-intrusive deep learning workload scheduler based on interpretable models that reduces the average job completion time and provides explicit system interpretations and excellent scalability for practical deployment.
- Chronus73
Chronus, an end-to-end scheduling system to provide deadline guarantee for SLO jobs and maximize the performance of best-effort jobs is presented, designed based on the unique features of DLT jobs.
- Defending against Backdoor Attacks in Natural Language Generation71
By giving a formal definition of backdoor attack and defense, this work finds that testing the backward probability of generating sources given targets yields effective defense performance against all different types of attacks, and is able to handle the one-to-many issue in many NLG tasks such as dialog generation.
- 71
- Efficient, Private and Robust Federated Learning68
Extensive evaluations conducted on three real-world datasets and various neural network architectures demonstrate that SecureFL outperforms prior art up to two orders of magnitude in efficiency with state-of-the-art byzantine robustness.
- Privacy-preserving Collaborative Learning with Automatic Transformation Search67
This paper proposes to leverage data augmentation to defeat reconstruction attacks: by preprocessing sensitive images with carefully-selected transformation policies, it becomes infeasible for the adversary to extract any useful information from the corresponding gradients.
- 66
- Efficient training of large language models on distributed infrastructures: a survey65
This survey explores recent advancements in training systems for LLMs, including innovations in training infrastructure with AI accelerators, networking, storage, and scheduling, as well as optimizations for computation, communication, and memory in distributed LLM training.
- 63
- 59
- Robust Medical Image Segmentation from Non-expert Annotations with Tri-network57
This paper proposes a novel Tri-network learning framework to alleviate the problem of insufficient accurate annotations in medical segmentation tasks by utilizing the non-expert annotations and demonstrates that this method effectively mines informative information from theNon-Expert annotations for improved segmentation performance and outperforms other competing methods.
- Stealing Deep Reinforcement Learning Models for Fun and Profit56
This paper presents the first model extraction attack against Deep Reinforcement Learning (DRL), which enables an external adversary to precisely recover a black-box DRL model only from its interaction with the environment.
- Aegis: Mitigating Targeted Bit-flip Attacks against Deep Neural Networks55
A dynamic-exit mechanism to attach extra internal classifiers (ICs) to hidden layers and randomly selects ICs for predictions during each inference to significantly increase the attack cost for the adaptive attacks where all defense mechanisms are transparent to the adversary.
- Fast Nearest Neighbor Machine Translation55
Fast kNN-MT is proposed, which constructs a significantly smaller datastore for the nearest neighbor search, and is only two times slower than the standard NMT model, enabling the practical use of knn-MT systems in real-world MT applications.
- EvilEdit: Backdooring Text-to-Image Diffusion Models in One Second53
The EvilEdit is proposed, a training-free and data-free backdoor attack against T2I diffusion models that can backdoor T2I diffusion models within one second with up to 100% success rate and preserves the functionality of the backdoored model using a protected whitelist.
- 52
- SoK: Rethinking Sensor Spoofing Attacks against Robotic Vehicles from a Systematic View51
A novel action flow model is proposed to systematically describe robotic function executions and unexplored sensor spoofing threats and two novel attack methodologies are designed to verify the feasibility of newly discovered spoofing attack vectors.
- On the (In)Security of Secure ROS251
This paper successfully identifies four security vulnerabilities in ROS2's native security module: Secure ROS2 (SROS2), and proposes a general defense solution based on the private broadcast encryption scheme to enhance the security of ROS2.
- 48
- 48
- Novel denial-of-service attacks against cloud-based multi-robot systems46
By analyzing different attack vectors in cloud-robotic platforms, this paper proposes three new DoS attacks, which manipulate the network resources, micro-architecture resources, and function parameters respectively, and alerts the robotics community to these catastrophic attacks.
- FedDSE: Distribution-aware Sub-model Extraction for Federated Learning over Resource-constrained Devices45
This paper identifies that when making predictions, different clients tend to activate different neurons of the entire model related to their respective distributions, and proposes a novel method called FedDSE, which can reduce the conflicts among clients by extracting sub-models based on the data distribution of each client.
- An Engorgio Prompt Makes Large Language Model Babble on44
This paper designs Engorgio, a novel methodology, to efficiently generate adversarial Engorgio prompts to affect the target LLM's service availability, and proposes novel loss functions to stably suppress the appearance of thetoken, whose occurrence will interrupt the LLM's generation process.
- 44
- 43
- Pushing the Limits of ChatGPT on NLP Tasks43
Using the proposed assemble of techniques, this work is able to significantly boost the performance of ChatGPT on the selected NLP tasks, achieving performances comparable to or better than supervised baselines, or even existing SOTA performances.
- Sentence Similarity Based on Contexts43
The proposed framework is able to generate high-quality, large-scale dataset with semantic similarity scores between two sentences in an unsupervised manner, with which the train-test gap can be largely bridged.
- 43
- 43
- One-bit Flip is All You Need: When Bit-flip Attack Meets Model Training42
A training-assisted bit flip attack is proposed, in which the adversary is involved in the training stage to build a high-risk model to release and this high-risk model, obtained coupled with a corresponding malicious model, behaves normally and can escape various detection methods.
- 42
- An Investigation of Byzantine Threats in Multi-Robot Systems41
An in-depth investigation about the Byzantine threats in MRSs, where some robot is untrusted is presented, and a practical methodology to identify potential Byzantine risks in a given MRS workload built from the Robot Operating System (ROS) is designed.
- Fine-tuning Is Not Enough: A Simple yet Effective Watermark Removal Attack for DNN Models41
A novel watermark removal attack by combining imperceptible pattern embedding and spatial-level transformations, which can effectively and blindly destroy the memorization of watermarked models to the watermark samples.
- FedNLR: Federated Learning with Neuron-wise Learning Rates40
This paper proposes a novel and simple algorithm called FedNLR, which utilizes Neuron-wise Learning Rates during the FL local training process to enhance the learning of neurons bound to local classes on local data knowledge while reducing the decay of non-local classes knowledge stored in neurons.
- VideoShield: Regulating Diffusion-based Video Generation Models via Watermarking39
VideoShield is a novel watermarking framework specifically designed for popular diffusion-based video generation models that effectively extracts watermarks and detects tamper without compromising video quality and is applicable to image generation models, enabling tamper detection in generated images as well.
- Benchmarking and Analyzing 3D Human Pose and Shape Estimation Beyond Algorithms39
This work presents the first comprehensive benchmarking study from three under-explored perspectives beyond algorithms, providing strong baselines for fair comparisons of algorithms, and recommendations for building effective training configurations in the future.
- 38
- Deep Learning Workload Scheduling in GPU Datacenters: Taxonomy, Challenges and Vision38
This paper surveys existing research efforts for both training and inference workloads and presents how existing schedulers facilitate the respective workloads from the scheduling objectives and resource consumption features.
- LoongTrain: Efficient Training of Long-Sequence LLMs with Head-Context Parallelism37
The core of LoongTrain is the 2D-Attention mechanism, which combines both head-parallel and context-parallel techniques to break the scalability constraints while maintaining efficiency, and improves Model FLOPs Utilization by up to 2.88x.
- 36
- 36
- 35
- 35
- Oedipus: LLM-enchanced Reasoning CAPTCHA Solver34
Oedipus, an innovative end-to-end framework for automated reasoning CAPTCHA solving, is introduced with a novel strategy that dissects the complex and human-easy-AI-hard tasks into a sequence of simpler and AI-easy steps.
- 33
- 33
- 32
- 31
- Sentiment Analysis through LLM Negotiations31
This paper introduces a multi-LLM negotiation framework for sentiment analysis that is able to take the complementary abilities of two LLMs, have them use rationale to persuade each other for correction, and consistently yields better performances than the ICL baseline across all benchmarks.
- 30
- 30
- Model Supply Chain Poisoning: Backdooring Pre-trained Models via Embedding Indistinguishability27
This paper proposes a novel and severer backdoor attack, TransTroj, which enables the backdoors embedded in PTMs to efficiently transfer in the model supply chain and significantly outperforms SOTA task-agnostic backdoor attacks.
- 27
- Boosting Black-Box Attack to Deep Neural Networks With Conditional Diffusion Models26
A novel black-box attack strategy, Conditional Diffusion Model Attack (CDMA), to improve the query efficiency of generating AEs under query-limited situations and adopts the conditional Denoising Diffusion Probabilistic Model as the converter, which can learn the transformation from clean samples to AEs.
- Towards Byzantine-resilient Learning in Decentralized Systems26
Mozi provides a uniform Byzantine-resilient aggregation rule for benign nodes to select the useful parameter updates and filter out the malicious ones in each training iteration to achieve BFT in decentralized learning systems.
- 26
- Disrupting Vision-Language Model-Driven Navigation Services via Adversarial Object Fusion25
Adversarial Object Fusion is presented, a novel attack framework targeting vision-and-language navigation agents in service-oriented environments by generating adversarial 3D objects that can effectively degrade agent performance under adversarial conditions while maintaining minimal interference with normal navigation tasks.
- Hercules: Boosting the Performance of Privacy-Preserving Federated Learning25
A novel parallel homomorphic computation method for matrix operations, which enables fast Single Instruction and Multiple Data (SIMD) operations over ciphertexts and an efficient approximation on the sign function based on the composite polynomial approximation are presented.
- 25
- InferDPT: Privacy-Preserving Inference for Closed-Box Large Language Models24
Experimental results across three datasets demonstrate that the text generation quality of <monospace>InferDPT</monospace> is comparable to that of non-private GPT-4, and RANTEXT surpasses existing state-of-the-art mechanisms, namely, SANTEXT+ and CUSTEXT+ in the trade-off between privacy and utility.
- GenderCARE: A Comprehensive Framework for Assessing and Reducing Gender Bias in Large Language Models23
This work constructs GenderPair, a novel pair-based benchmark designed to assess gender bias in LLMs comprehensively, and establishes pioneering criteria for gender equality benchmarks, spanning dimensions such as inclusivity, diversity, explainability, objectivity, robustness, and realisticity.
- 21
- Watermarking Pre-trained Encoders in Contrastive Learning21
This work proposes the first watermarking methodology for the pre-trained encoders using a task-agnostic loss function to effectively embed into the encoder a backdoor as the watermark and indicates high effectiveness and robustness against different adversarial operations.
- Ownership Verification of DNN Architectures via Hardware Cache Side Channels20
A novel watermarking scheme to achieve the ownership verification of DNN architectures by designing new algorithms based on Neural Architecture Search to generate watermarked architectures, which are unique enough to represent the ownership, while maintaining high model usability.
- Can We Mitigate Backdoor Attack Using Adversarial Detection Methods?20
Four existing adversarial defense methods for detecting backdoor examples are revised and extensive evaluations indicate that these approaches provide reliable protection against backdoor attacks, with a higher accuracy than detecting adversarial examples.
- 20
- 19
- Topology-Aware Differential Privacy for Decentralized Image Classification19
The key insight of the TOP- DP solution is to leverage the unique features of decentralized communication topologies to reduce the noise scale and improve the model usability, which is the first DP optimization work from the perspective of network topologies.
- Host-Based Dos Attacks and Defense in the Cloud19
An effective general-purpose method to defeat memory, network and disk DoS attacks, which exploit the shared computing resources in a multi-tenant cloud server to compromise the server's resource availability, is designed.
- 18
- 18
- 17
- SIMC 2.0: Improved Secure ML Inference Against Malicious Clients17
This paper proposes SIMC 2.0, which complies with the underlying structure of SIMC, but significantly optimizes both the linear and non-linear layers of the model, and designs a new coding method for parallel homomorphic computation between matrices and vectors.
- 16
- PhyScout: Detecting Sensor Spoofing Attacks via Spatio-temporal Consistency16
Compared to existing defense solutions, PhyScout offers rapid identification of sensor attacks (within 100ms) with low performance overhead (CPU-based), and conflict visualization, and presents new avenues for future research in robust and efficient defense mechanisms against sensor spoofing attacks.
- Groot: Adversarial Testing for Generative Text-to-Image Models with Tree-based Semantic Transformation16
Groot is introduced, the first automated framework leveraging tree-based semantic transformation for adversarial testing of text-to-image models and achieves a remarkable success rate on leading text-to-image models such as DALL-E 3 and Midjourney.
- 16
- 16
- Erase and Repair: An Efficient Box-Free Removal Attack on High-Capacity Deep Hiding16
A simple box-free removal attack on deep hiding that does not require any prior knowledge of the deep hiding schemes is proposed and a more powerful removal attack, efficient box- free removal attack (EBRA), which employs image inpainting techniques to remove secret images from container images is designed.
- Towards Robust and Expressive Whole-body Human Pose and Shape Estimation16
This paper proposes a novel framework to enhance the robustness of whole-body pose and shape estimation that incorporates three new modules to address the above challenges from three perspectives.
- 16
- Rethinking Machine Unlearning in Image Generation Models15
This work designs CatIGMU, a novel hierarchical task categorization framework, and introduces EvalIGMU, a comprehensive evaluation framework, to facilitate the comprehensive understanding, standardized categorization, and reliable evaluation of IGMU.
- PentestEval: Benchmarking LLM-based Penetration Testing with Modular and Stage-Level Design15
PentestEval is introduced, the first comprehensive benchmark for evaluating LLMs across six decomposed penetration testing stages: Information Collection, Weakness Gathering and Filtering, Attack Decision-Making, Exploit Generation and Revision, and Revision.
- Image-Based Geolocation Using Large Vision-Language Models15
It is revealed that LVLMs can accurately determine geolocations from images, even without explicit geographic training, and an innovative framework that significantly enhances image-based geolocation accuracy is introduced, called tool{}, an innovative framework that significantly enhances image-based geolocation accuracy.
- Cooperative collision avoidance in multirobot systems using fuzzy rules and velocity obstacles15
A distributed and hybrid motion planning method, named Fuzzy-VO, is proposed for multirobot systems that contains two basic components: fuzzy rules, which can deal with linguistic requirements and compute motion efficiently, and velocity obstacles (VOs), which can generate collision-free motion effectively.
- Improving Adversarial Robustness of 3D Point Cloud Classification Models15
Two innovative methodologies to improve the adversarial robustness of 3D point cloud classification models are designed, including a novel point cloud architecture which can smooth and disrupt the adversarial perturbations and a novel data augmentation strategy to adaptively balance the model usability and robustness.
- 15
- 14
- 14
- 14
- InternEvo: Efficient Long-sequence Large Language Model Training via Hybrid Parallelism and Redundant Sharding13
The design of InternEvo decouples all of the sharding dimensions into a new hierarchical space, and systematically analyzes the memory and communication cost of LLM training, generates an effective hybrid parallelism strategy, and implements memory management techniques to reduce GPU memory fragmentation.
- 13
- Catch You Everything Everywhere: Guarding Textual Inversion via Concept Watermarking13
The novel concept watermarking is proposed, where watermark information is embedded into the target concept and then extracted from generated images based on the watermarked concept, showing great resilience to different diffusion sampling processes possibly chosen by malicious users, meanwhile preserving utility for normal use.
- 13
- Rewritable High-Mobility Electrons in Oxide Heterostructure of Layered Perovskite/Perovskite13
The observation of tunable high-mobility electrons in layered perovskites/perovskite (Srn+1TinO3n+1/SrTiO3) heterostructure provides a promising platform for reconfigurable high-speed electronic devices.
- kFolden: k-Fold Ensemble for Out-Of-Distribution Detection-Fold Ensemble for Out-Of-Distribution Detection13
This work proposes a simple yet effective framework kFolden, which mimics the behaviors of OOD detection during training without the use of any external data, and develops benchmarks for Ood detection using existing text classification datasets.
- 13
- Image Can Bring Your Memory Back: A Novel Multi-Modal Guided Attack against Image Generation Model Unlearning12
Recall is proposed, a novel adversarial framework explicitly designed to compromise the robustness of unlearned IGMs, and exploits the intrinsic multi-modal conditioning capabilities of diffusion models by efficiently optimizing adversarial image prompts with guidance from a single semantically relevant reference image.
- 12
- Defense against ML-based Power Side-channel Attacks on DNN Accelerators with Adversarial Attacks12
The key insight of AIAShield is to leverage the prominent adversarial attack technique from the machine learning community to craft delicate noise, which can significantly obfuscate the adversary's side-channel observation while incurring minimal overhead to the execution of the protected model.
- Titan12
Titan, a scheduler to improve the efficiency of FM fine-tuning workloads based on their three distinct features, takes full advantage of the fixed model structure and concurrently executes the parameter transmission and gradient computation to hide the overhead of context switch.
- Enhancing Model Defense Against Jailbreaks with Proactive Safety Reasoning11
A novel defense strategy, Safety Chain-of-Thought (SCoT), is proposed, which harnesses the enhanced reasoning capabilities of LLMs for proactive assessment of harmful inputs, rather than simply blocking them.
- 11
- 11
- Backdoor Attacks against Image-to-Image Networks11
A novel backdoor attack technique is proposed, where the compromised I2I network behaves normally on clean input images, yet outputs a predefined image of the adversary for malicious input images containing the trigger.
- Mind Your Heart: Stealthy Backdoor Attack on Dynamic Deep Neural Network in Edge Computing11
This paper proposes a novel backdoor attack specifically on the dynamic multi-exit DNN models by poisoning one DNN model’s shallow hidden layers targeting not this vanilla DNNmodel but only its dynamically deployed multi- exit architectures.
- $k$NN-NER: Named Entity Recognition with Nearest Neighbor Search11
A nearest neighbor NER framework, which augments the distribution of entity labels by assigning nearest neighbors retrieved from the training set, which makes the model more capable of handling long-tail cases, along with better few-shot learning abilities.
- 11
- 11
- The Hidden Vulnerability of Watermarking for Deep Neural Networks.11
A novel watermark removal attack is designed, which can defeat state-of-the-art solutions without any prior knowledge of the adopted watermarking technique and training samples, and a novel preprocessing function is proposed, which embeds imperceptible patterns and performs spatial-level transformations over the input.
- VisionGuard: Secure and Robust Visual Perception of Autonomous Vehicles in Practice10
The key of VisionGuard is to leverage the spatiotemporal inconsistency property of PAEs to detect anomalies and it predicts the motion states from historical ones and compares them with the current driving states to identify any motion inconsistency caused by physical attacks.
- Cache Refinement Type for Side-Channel Detection of Cryptographic Software10
Evaluation results confirm the capability of CaType in identifying side channel defects with great precision, efficiency, and scalability.
- Analysis and Mitigation of Function Interaction Risks in Robot Apps10
This work presents RTron, a novel system to detect and mitigate these risks and protect the operations of robot apps, and introduces security policies for each type of risks, and design coordination nodes to enforce the policies and regulate the interactions.
- Testing the Fault-Tolerance of Multi-sensor Fusion Perception in Autonomous Driving Systems9
This work presents FADE, the first testing methodology to comprehensively assess the fault tolerance of MSF perception-based ADSs, and designs a feedback-guided differential fuzzer to uncover safety violations of ADSs caused by the injected faults.
- CamLopa: A Hidden Wireless Camera Localization Framework via Signal Propagation Path Analysis9
CamLopa is introduced, a training-free wireless camera localization framework that operates with minimal activity space constraints using low-cost, commercial-off-the-shelf (COTS) devices and without the need for training.
- 9
- Boosting Distributed Full-graph GNN Training with Asynchronous One-bit Communication9
An efficient distributed GNN training framework Sylvie is proposed, which employs one-bit quantization technique in GNNs and further pipelines the curtailed communication with computation to enormously shrink the overhead while maintaining the model quality.
- 9
- 9
- 9
- 8
- 8
- 8
- 8
- SafeGuider: Robust and Practical Content Safety Control for Text-to-Image Models8
This work introduces SafeGuider, a two-step framework designed for robust safety control without compromising generation quality, which combines an embedding-level recognition model with a safety-aware feature erasure beam search algorithm and demonstrates exceptional effectiveness in minimizing attack success rates.
- 8
- Impact-driven Context Filtering For Cross-file Code Completion7
This work proposes an adaptive retrieval context filtering framework, CODEFILTER, trained on this dataset to mitigate the harmful effects of negative retrieved contexts in code completion, and demonstrates that CODEFILTER consistently improves completion accuracy compared to approaches without filtering operations across various tasks.
- 7
- 7
- Extracting Cloud-based Model with Prior Knowledge7
This work proposes an efficient model extraction attack based on prior knowledge for the first time that leverages both prior and posterior knowledge to extract the model and thus eliminates generalizability errors and overfitting problems.
- 7
- Mitigating Query-based Neural Network Fingerprinting via Data Augmentation7
A novel attack to mitigate query-based fingerprinting methods based on data augmentation methods by proposing a randomized transformation on input samples to significantly mislead the fingerprint samples’ prediction and compromise the IP verification.
- Alleviating Robust Overfitting of Adversarial Training With Consistency Regularization7
A new AT solution is introduced, which integrates the consistency regularization and Mean Teacher (MT) strategy into AT and can effectively alleviate robust overfitting and improve the robustness of DNN models against common adversarial attacks.
- 7
- 6
- Sanitizable Cross-Domain Access Control With Policy-Driven Dynamic Authorization6
This paper presents SCPA, a cross-domain access control scheme imbued with sanitization features and propelled by policy-driven dynamic authorization, tailored for cloud-based data sharing, and provides comprehensive security proofs rigorously indicating the security of the invented SCPA.
- 6
- 6
- AutoSched: An Adaptive Self-configured Framework for Scheduling Deep Learning Training Workloads6
AutoSched is a framework that can automatically, efficiently, and dynamically adjust the configuration parameters of DLT schedulers, and improves the performance of state-of-the-art schedulers by up to 46% with 132 × configuration tuning latency reduction.
- 6
- Text's Armor: Optimized Local Adversarial Perturbation Against Scene Text Editing Attacks6
This paper proposes to actively defeat text editing attacks by designing invisible "armors" for texts in the scene by turning the adversarial vulnerability of DNN-based STE into strength and design local perturbations specifically for texts using an optimized normalization strategy.
- Privacy-preserving Decentralized Deep Learning with Multiparty Homomorphic Encryption6
D-MHE is proposed, the first secure and efficient decentralized training framework with lossless precision that can reduce the communication complexity of general Secure Multiparty Computation tasks from quadratic to linear in the number of users, making it very suitable and scalable for large-scale decentralized learning systems.
- 6
- Differentially Private Decentralized Learning6
A novel DP-SGD algorithm for decentralized learning systems that leverages the unique network characteristics of decentralized systems to effectively reduce the noise scale and improve the model usability and a novel learning protocol for both synchronous and asynchronous decentralized systems.
- FaceID-6M: A Large-Scale, Open-Source FaceID Customization Dataset5
The first large-scale, open-source FaceID dataset containing 6 million high-quality text-image pairs is collected and released, and it is demonstrated that models trained on the FaceID-6M dataset achieve performance that is comparable to, and slightly better than currently available industrial models.
- 5
- CapsuleFormer: A Capsule and Transformer combined model for Decentralized Application encrypted traffic classification5
Capsule-Former is presented, a novel encrypted traffic classification model for DApps that utilizes capsule neurons instead of traditional scalar neurons, where the neurons within the capsule embody various attributes of particular entities.
- Model X-ray : Detecting Backdoored Models via Decision Boundary5
Model X-ray is proposed, a novel backdoor detection approach based on the analysis of illustrated two-dimensional decision boundaries that can not only identify whether the target model is infected but also determine the target attacked label under the all-to-one attack strategy.
- 5
- 5
- 5
- VerifyML: Obliviously Checking Model Fairness Resilient to Malicious Model Holder5
The first secure inference framework to check the fairness degree of a given Machine learning (ML) model is presented, which allows the vast majority of overhead to be performed offline, thus meeting the low latency requirements for online inference.
- 5
- 5
- BitHydra: Towards Bit-flip Inference Cost Attack against Large Language Models4
This work proposes BitHydra, a framework that addresses the unique optimization challenge of identifying the exact weight bits that maximize generation cost via the Alternating Direction Method of Multipliers (ADMM), and demonstrates the effectiveness of the ADMM-based formulation against both standard models and potential defenses.
- 4
- 4
- 4
- Laser Shield: a Physical Defense with Polarizer against Laser Attacks on Autonomous Driving Systems4
This work proposes Laser Shield which leverages a polarizer along with a min-energy rotation mechanism to eliminate adversarial lasers from ADS scenes and is proved to surpass SOTA performance.
- Ymir: A Scheduler for Foundation Model Fine-tuning Workloads in Datacenters4
Ymir, a scheduler to improve the efficiency of FMF workloads in GPU datacenters and promotes scheduling fairness by fully exploiting the task transferability, is proposed.
- 4
- 4
- 4
- 4
- 4
- 4
- 4
- 3
- 3
- 3
- 3
- 3
- Mind the Cost of Scaffold! Benign Clients May Even Become Accomplices of Backdoor Attack3
The core idea of BadSFL is to uniquely tamper with the control variate to subtly steer benign clients' local gradient updates towards the attacker's poisoned direction, effectively turning them into unwitting accomplices, significantly enhancing the backdoor persistence.
- 3
- 3
- 3
- 3
- Smaller Is Bigger: Rethinking the Embedding Rate of Deep Hiding3
A novel Local Deep Hiding (LDH) scheme that significantly increases the embedding rate by hiding large secret images into small local regions of cover images and exhibits superior robustness to common image distortions.
- Online adaptation for autonomous unmanned systems driven by requirements satisfaction model3
This work proposes Captain, a model-driven and control-based online adaptation approach, for the AUS control software that predicts whether the requirements will be violated in the upcoming situation; identifies the unsatisfiable requirements that need to be accommodated; and finally, finds an optimal adaptation for the forthcoming situation.
- 3
- 3
- 3
- 3
- 3
- A Method for Solving Generalized Implicit Factorization Problem3
The problem of factoring RSA moduli with the implicit hint is transformed into solving small roots of a modular equation by utilizing Coppersmith's method and improving Nitaj-Ariffin's result when the unknowns are relatively small.
- 2
- A Haptic Robot Finger Designed for Guqin Instrument Playing2
A biomimetic multimodal haptic fingertip is developed and validated on selected guqin string-contact tasks, including open-string and stopped-note comparisons, harmonic-tuning, and tactile-triggered bimanual coordination, using the guqin, a traditional Chinese musical instrument.
- BURN: Backdoor Unlearning via Adversarial Boundary Analysis2
Backdoor unlearning via adversaRial bouNdary analysis is proposed, a novel defense framework that integrates false correlation decoupling, progressive data refinement, and model purification that effectively removes backdoor threats while maintaining the model's original performance.
- BadLingual: A Novel Lingual-Backdoor Attack against Large Language Models2
BadLingual is designed, a novel task-agnostic lingual-backdoor, capable of triggering any downstream tasks within the chat LLMs, regardless of the specific questions of these tasks, and a new approach using PPL-constrained Greedy Coordinate Gradient-based Search (PGCG) based adversarial training to expand the decision boundary of lingual-backdoor, thereby enhancing the generalization ability of lingual-backdoor across various tasks.
- Clean Image May Be Dangerous: Data Poisoning Attacks Against Deep Hashing2
This work is the first to study data poisoning attacks against deep hashing (PADHASH), and it is pointed out that even clean query images can be dangerous, inducing malicious target retrieval results, like undesired or illegal images.
- 2
- Holmes: Towards Effective and Harmless Model Ownership Verification to Personalized Large Vision Models via Decoupling Common Features2
A harmless model ownership verification method for personalized LVMs by decoupling similar common features by conducting model ownership verification by hypothesis test to mitigate randomness and enhance robustness is proposed.
- TPU as Cryptographic Accelerator2
This paper explores the potential of leveraging TPUs/NPUs to accelerate polynomial multiplication, thereby enhancing the performance of FHE and ZKP schemes and presents techniques to adapt polynomial multiplication to these AI-centric architectures and provides a preliminary evaluation of their effectiveness.
- AMSP: Reducing Communication Overhead of ZeRO for Efficient LLM Training2
A novel LLM training framework AMSP, which undertakes a granular partitioning of model states, encompassing parameters, gradient, and optimizer states, and incorporates a scale-aware partitioner to autonomously search for optimal partitioning strategies.
- A Unified Hardware-based Threat Detector for AI Accelerators2
UniGuard, a novel unified and non-intrusive detection methodology to safeguard FPGA-based AI accelerators, is designed to harness power side-channel information generated during model inference to spot any anomaly.
- Introduction to the Special Section on Energy-efficient and Secure Computing for Artificial Intelligence and Beyond2
This issue wants to investigate the possibility of manipulating the AI computing services to cause more financial loss or environmental damage, as well as the corresponding countermeasures, within the scope of this special issue.
- 2
- Analysis on Action Tracking Reports of COVID-19 Informs Control Strategies and Vaccine Delivery in Post-Pandemic Era2
This work takes the advantage of action tracking reports of confirmed COVID-19 patients, which contain details regarding the mobility trajectory of a patient, along with the people with whom the patient has interacted, the timing of diagnosis, and personal information, to maximize the efficiency of vaccine delivery under the general situation of vaccine supply shortage.
- Solution Complexity of Local Variants of Sabotage Game2
This work is a first attempt to understand why similar-looking variants of a graph game and their corresponding logics can have drastically different computational complexities, with the goal to bring up a more general topic that requires further studies, namely to identify the parameters of games and logic that crucially affect complexity.
- 1
- 1
- 1
- Aparecium: Revealing Secrets from Physical Photographs1
A novel deep watermarking framework dubbed Aparecium that is not only robust against different digital distortions, but also can resist different physical distortions, even in severe cases including different shapes, curvature, folding, incompleteness, long distances, and big angles while maintaining high visual quality.
- Turn That Frown Upside Down: FaceID Customization via Cross-Training Data1
CrossFaceID is proposed, the first large-scale, high-quality, and publicly available dataset specifically designed to improve the facial modification capabilities of FaceID customization models and shows that models fine-tuned on the CrossFaceID dataset retain its performance in preserving FaceID fidelity while significantly improving its face customization capabilities.
- 1
- 1
- 1
- 1
- 1
- 1
- 1
- 1
- 1
- 1
- Rethinking Adversarial Training with Neural Tangent Kernel1
An in-depth investigation of AT process and properties with NTK, such as NTK evolution, and the impact of data normalization on AT and the importance of unbiased estimators in batch normalization layers is disclosed.
- A Formal Methodology for Verifying Side-Channel Vulnerabilities in Cache Architectures1
This paper designs an entropy-based noninterference reasoning framework with two unwinding conditions to assess the information leakage of the cache designs and uses this methodology to assess eight state-of-the-art cache architectures to demonstrate reliability as well as safety.
- 1
- A Software Stack for Composable Cloud Robotics System1
Modern cloud robotic applications face new challenges in managing today’s highly distributed and heterogeneous environment, and the application programmers must make numerous systematical decisions between the local robot and the cloud server.
- 1
- –
- –
- –
- –
- –
- –
- UniTG: A Unified System for Efficient and Seamless Textual Graph Learning–
UniTG is proposed, the first unified system that fuses the LM and GNN phases into a single end-to-end procedure through three co-designed components spanning the runtime, algorithm, and execution levels.
- SPPO: Making Million-Token LLM Training Practical on Modest GPU Clusters–
Adaptive Sequence Pipeline Parallel Offloading (SPPO) is proposed, a novel framework that optimizes memory and computational resource efficiency for long-sequence LLM training and develops an adaptive pipeline scheduling approach with a heuristic solver and multiplexed sequence partitioning to improve computational resource efficiency.
- –
- –
- –
- Keynote: Security Testing of Cloud-based Generative AI Services–
Recent efforts on systematically benchmarking and security testing of cloud-based generative AI services are presented, highlighting the critical challenges facing today’s large-model ecosystems but also the opportunities for building more trustworthy, robust, and responsible AI systems.
- –
- –
- –
- –
- Robust Bandwidth Estimation for Real-Time Communication with Offline Reinforcement Learning–
RBWE is a robust bandwidth estimation framework based on offline RL that integrates Q-ensemble (an ensemble of Q-functions) with a Gaussian mixture policy to mitigate OOD risks and enhance policy learning and results show that RBWE reduces overestimation errors by 18% and improves the 10th percentile Quality of Experience (QoE) by 18.6%, demonstrating its practical effectiveness in real-world RTC applications.
- –
- Computational Monogamy of Entanglement and Non-interactive Quantum Key Distribution–
A no-go theorem is proved which establishes that (in contrast to the case of ordinary multi-round QKD) entanglement is necessary for non-interactive QKD, i.e., the messages sent by Alice and Bob cannot both be unentangled with their respective quantum memories if the protocol is to be everlastingly secure.
- –
- Intelligent detection of wood defects based on 3D scanning technology–
The research results indicate that the combination of 3D scanning technology and deep learning algorithms for wood surface defect detection can achieve efficient and accurate detection, effectively improving the intelligence level and production efficiency of wood processing.
- –
- –
- –
- Off-dynamics Conditional Diffusion Planners–
This work proposes a novel approach using conditional Diffusion Probabilistic Models (DPMs) to learn the joint distribution of the large-scale off-dynamics dataset and the limited target dataset and demonstrates that by modifying the context, the model can interpolate between source and target dynamics, making it more robust to subtle shifts in the environment.
- Cerebral Artery Segmentation with Limited Data: Using Hierarchical Transformers–
This work used fewer than 100 cases to train a transformer model for artery segmentation, indicating that transformers have the potential to replace CNNs in the processing of 3D TOF-MRA medical images, even with a small training dataset.
- –
- Singular Regularization with Information Bottleneck Improves Model's Adversarial Robustness–
This paper proposes a new module to regularize adversarial information and combine information bottleneck theory, which is proposed to theoretically restrict intermediate representations, and proves that the method is interpretable and able to be explained under regional faithfulness analysis.
- –
- Double-Flow-based Steganography without Embedding for Image-to-Image Hiding–
DF-SWE is the first SWE method that can hide large images and multiple images into one image with the same size, significantly enhancing the payload capacity and can be applied in the steganography of secret images in various domains without requiring training data from the corresponding domains.
- –
- A Benchmark of Long-tailed Instance Segmentation with Noisy Labels–
This paper proposes a new dataset, which is a large vocabulary long-tailed dataset containing label noise for instance segmentation, and indicates that the noise in the training dataset will hamper the model in learning rare categories and decrease the overall performance.
- –
- A Secure Fingerprinting Framework for Distributed Image Classification–
SECUREMARK-DL is a novel fingerprinting framework that embeds a unique fingerprint into the target model for each customer, which can be extracted and verified from any suspicious model once a dispute arises, and adopts a new privacy partitioning technique in the training process to protect the training data privacy.
- –
- –
- –
- –
- –
- –
Publication data from OpenAlex, with missing venues and authors filled in from Crossref; citation counts are the higher of OpenAlex and Semantic Scholar; position from the scholar’s ORCID record, last synced 2026-10-10. One-sentence summaries under some papers are written by Semantic Scholar’s model. Citation counts may be lower than on Google Scholar, which indexes more sources.
Report an error
Wrong papers, two people merged into one, or a profile that should not be here? Tell us and we will fix or hide it. You will be asked to sign in.