Tianwei Zhang
13 papers in the PaperMetrix corpus
Papers by this author
-
Stealing Deep Reinforcement Learning Models for Fun and Profit
2020 · arXiv (Cornell University)
This paper presents the first model extraction attack against Deep Reinforcement Learning (DRL), which enables an external adversary to precisely recover a black-box DRL model only from its interaction with the environment. Model extraction attacks …
-
DeepSweep: An Evaluation Framework for Mitigating DNN Backdoor Attacks using Data Augmentation
2021
Public resources and services (e.g., datasets, training platforms, pre-trained models) have been widely adopted to ease the development of Deep Learning-based applications. However, if the third-party providers are untrusted, they can inject poisoned samples into …
-
Fine-tuning Is Not Enough: A Simple yet Effective Watermark Removal Attack for DNN Models
2021
Watermarking has become the tendency in protecting the intellectual property of DNN models. Recent works, from the adversary's perspective, attempted to subvert watermarking mechanisms by designing watermark removal attacks. However, these attacks mainly adopted sophisticated …
-
A General Framework for Defending Against Backdoor Attacks via Influence Graph
2021 · arXiv (Cornell University)
In this work, we propose a new and general framework to defend against backdoor attacks, inspired by the fact that attack triggers usually follow a \textsc{specific} type of attacking pattern, and therefore, poisoned training examples …
-
SIMC 2.0: Improved Secure ML Inference Against Malicious Clients
2022 · arXiv (Cornell University)
In this paper, we study the problem of secure ML inference against a malicious client and a semi-trusted server such that the client only learns the inference output while the server learns nothing. This problem …
-
Incremental Learning, Incremental Backdoor Threats
2022 · IEEE Transactions on Dependable and Secure Computing
Class incremental learning from a pre-trained DNN model is gaining lots of popularity. Unfortunately, the pre-trained model also introduces a new attack vector, which enables an adversary to inject a backdoor into it and further …
-
GPT-NER: Named Entity Recognition via Large Language Models
2023 · arXiv (Cornell University)
Despite the fact that large-scale Language Models (LLM) have achieved SOTA performances on a variety of NLP tasks, its performance on NER is still significantly below supervised baselines. This is due to the gap between …
-
PriFR: Privacy-preserving Large-scale File Retrieval System via Blockchain for Encrypted Cloud Data
2023
As a fundamental and commonly used service, file retrieval has been extensively studied by information retrieval, cryptography, and big data communities. In this paper, we consider the problem of privacy-preserving file retrieval. A new framework …
-
Pushing the Limits of ChatGPT on NLP Tasks
2023 · arXiv (Cornell University)
Despite the success of ChatGPT, its performances on most NLP tasks are still well below the supervised baselines. In this work, we looked into the causes, and discovered that its subpar performance was caused by …
-
AquaLoRA: Toward White-box Protection for Customized Stable Diffusion Models via Watermark LoRA
2024 · arXiv (Cornell University)
Diffusion models have achieved remarkable success in generating high-quality images. Recently, the open-source models represented by Stable Diffusion (SD) are thriving and are accessible for customization, giving rise to a vibrant community of creators and …
-
Mind the Cost of Scaffold! Benign Clients May Even Become Accomplices of Backdoor Attack
2024 · arXiv (Cornell University)
By using a control variate to calibrate the local gradient of each client, Scaffold has been widely known as a powerful solution to mitigate the impact of data heterogeneity in Federated Learning. Although Scaffold achieves …
-
When Search Goes Wrong: Red-Teaming Web-Augmented Large Language Models
2025 · arXiv (Cornell University)
Large Language Models (LLMs) have been augmented with web search to overcome the limitations of the static knowledge boundary by accessing up-to-date information from the open Internet. While this integration enhances model capability, it also …
-
ObfusBFA: A Holistic Approach to Safeguarding DNNs From Different Types of Bit-Flip Attacks
2026
Bit-flip attacks (BFAs) represent a serious threat to Deep Neural Networks (DNNs), where flipping a small number of bits in the model parameters or binary code can significantly degrade the model accuracy or mislead the …