← Search

Yanjun Zhang

13 accepted papers

2026

Dual-View Inference Attack: Machine Unlearning Amplifies Privacy Exposure

AAAI 2026technical

Machine unlearning is a newly popularized technique for removing specific training data from a trained model, enabling it to comply with data deletion requests. While it protects the rights of users requesting unlearning, it also introduces new privacy risks. Prior works have primarily focused on th

Cited by 0SourcePDFScholar
2026

GRASP: Hard-Label Black-Box Malware Evasion with Higher Success, Fewer Queries, and Smaller Perturbations

IJCAI 2026

Machine learning (ML)-based malware detectors are widely deployed but remain vulnerable to adversarial attacks. However, under hard-label black-box access, existing adversarial attacks on Windows Portable Executable (PE) malware are often query-inefficient and incur large file-size inflation. A comm

Cited by 0Scholar
2026

IdentityMask: A Robust Face-Centric Privacy Protection Against Unauthorized Personalization of Diffusion Models

IJCAI 2026

Unauthorized personalization based on diffusion models pose a severe and growing threat to digital privacy by enabling the unauthorized replication and exploitation of individual identities. Existing disrupting-based defenses primarily add invisible perturbations arbitrarily across the entire image

Cited by 0Scholar
2026

Persistent Backdoor Attacks in Class-Incremental Learning via Structural Invariant Anchoring

ICML 2026poster

Continual Learning (CL) continually performs parameter updates, posing a significant challenge to backdoor persistence. In this paper, we reveal that the most advanced attack relies on an implicit assumption that task-critical neurons remain stable across task learning; however, it does not hold in …

Cited by 0SourceScholar
2026

Transferable Backdoor Attacks for Code Models via Sharpness-Aware Adversarial Perturbation

AAAI 2026technical

Code models are increasingly adopted in software development but remain vulnerable to backdoor attacks via poisoned training data. Existing backdoor attacks on code models face a fundamental trade-off between transferability and stealthiness. Static trigger-based attacks insert fixed dead code patte

Cited by 0SourcePDFScholar
2026

UnlearnShield: Shielding Forgotten Privacy against Unlearning Inversion

ICASSP 2026poster

Machine unlearning is an emerging technique that aims to remove the influence of specific data from trained models, thereby enhancing privacy protection. However, recent research has uncovered critical privacy vulnerabilities, showing that adversaries can exploit unlearning inversion to reconstruct…

Cited by 0SourcePDFScholar
2025

BiMark: Unbiased Multilayer Watermarking for Large Language Models

ICML 2025poster

Recent advances in Large Language Models (LLMs) have raised urgent concerns about LLM-generated text authenticity, prompting regulatory demands for reliable identification mechanisms. Although watermarking offers a promising solution, existing approaches struggle to simultaneously achieve three cri…

Cited by 0SourcePDFScholar
2025

Improving Generalization of Universal Adversarial Perturbation via Dynamic Maximin Optimization

AAAI 2025technical

Deep neural networks (DNNs) are susceptible to universal adversarial perturbations (UAPs). These perturbations are meticulously designed to fool the target model universally across all sample classes. Unlike instance-specific adversarial examples (AEs), generating UAPs is more complex because they m…

2025

Performance Guaranteed Poisoning Attacks in Federated Learning: A Sliding Mode Approach

IJCAI 2025

Manipulation of local training data and local updates, i.e., the poisoning attack, is the main threat arising from the collaborative nature of the federated learning (FL) paradigm. Most existing poisoning attacks aim to manipulate local data/models in a way that causes denial-of-service (DoS) issues

Cited by 0SourcePDFScholar
2025

Test-Time Backdoor Detection for Object Detection Models

CVPR 2025poster

Object detection models are vulnerable to backdoor attacks, where attackers poison a small subset of training samples by embedding a predefined trigger to manipulate prediction. Detecting poisoned samples (i.e., those containing triggers) at test time can prevent backdoor activation. However, unlike…

Cited by 1SourcePDFScholar
2024

Detector Collapse: Backdooring Object Detection to Catastrophic Overload or Blindness in the Physical World

IJCAI 2024poster

Object detection tasks, crucial in safety-critical systems like autonomous driving, focus on pinpointing object locations. These detectors are known to be susceptible to backdoor attacks. However, existing backdoor techniques have primarily been adapted from classification tasks, overlooking deeper…

Cited by 13SourcePDFScholar
2024

Towards Model Extraction Attacks in GAN-Based Image Translation via Domain Shift Mitigation

AAAI 2024technical

Model extraction attacks (MEAs) enable an attacker to replicate the functionality of a victim deep neural network (DNN) model by only querying its API service remotely, posing a severe threat to the security and integrity of pay-per-query DNN-based services. Although the majority of current research…

Cited by 3SourcePDFScholar
2018

π-SoC: Heterogeneous SoC Architecture for Visual Inertial SLAM Applications

IROS 2018poster

In recent years, we have observed a clear trend in the rapid rise of autonomous vehicles and robotics. One of the core technologies enabling these applications, Simultaneous Localization And Mapping (SLAM), imposes two main challenges: first, these workloads are computationally intensive and they of…

Cited by 25SourceScholar