Search for: All records

Creators/Authors contains: "Wang, Tianhao"

Note: When clicking on a Digital Object Identifier (DOI) number, you will be taken to an external site maintained by the publisher. Some full text articles may not yet be available without a charge during the embargo (administrative interval).
What is a DOI Number?

Some links on this page may take you to non-federal websites. Their policies may differ from this site.

  1. To improve the quality of differentially private (DP) synthetic images, most studies have focused on improving core optimization techniques such as DP-SGD. Inspired by DP-FETA, this work proposes FETA-Pro, which introduces frequency features as training shortcuts. Their complexity lies between spatial features captured by central images and full images, enabling a finer-grained curriculum for DP training. FETA-Pro uses an auxiliary generator to produce images aligned with noisy frequency features, then trains another model with those images, spatial features, and DP-SGD. Across five sensitive image datasets, FETA-Pro achieves an average of 25.7% higher fidelity and 4.1% greater utility than the best-performing baseline at privacy budget epsilon = 1. 
    more » « less
    Free, publicly-accessible full text available August 12, 2027
  2. Free, publicly-accessible full text available May 30, 2027
  3. With the rapid development of large language models, the potential threat of their malicious use, particularly in generating phishing content, is becoming increasingly prevalent. Leveraging the capabilities of LLMs, malicious users can synthesize phishing emails that are free from spelling mistakes and other easily detectable features. Furthermore, such models can generate topic-specific phishing messages, tailoring content to the target domain and increasing the likelihood of success. Detecting such content remains a significant challenge, as LLM-generated phishing emails often lack clear or distinguishable linguistic features. As a result, most existing semantic-level detection approaches struggle to identify them reliably. While certain LLM-based detection methods have shown promise, they suffer from high computational costs and are constrained by the performance of the underlying language model, making them impractical for large-scale deployment. In this work, we aim to address this issue. We propose Paladin, which embeds trigger-tag associations into vanilla LLM using various insertion strategies, creating them into instrumented LLMs. When an instrumented LLM generates content related to phishing, it will automatically include detectable tags, enabling easier identification. Based on the design on implicit and explicit triggers and tags, we consider four distinct scenarios in our work. We evaluate our method from three key perspectives: stealthiness, effectiveness, and robustness, and compare it with existing baseline methods. Experimental results show that our method outperforms the baselines, achieving over 90% detection accuracy across all scenarios. 
    more » « less
    Free, publicly-accessible full text available January 1, 2027
  4. Free, publicly-accessible full text available January 1, 2027
  5. Free, publicly-accessible full text available May 26, 2027
  6. Free, publicly-accessible full text available August 1, 2027
  7. Free, publicly-accessible full text available August 13, 2026
  8. Diffusion models have begun to overshadow GANs and other generative models in industrial applications due to their superior image generation performance. The complex architecture of these models furnishes an extensive array of attack features. In light of this, we aim to design membership inference attacks (MIAs) catered to diffusion models. We first conduct an exhaustive analysis of existing MIAs on diffusion models, taking into account factors such as black-box/white-box models and the selection of attack features. We found that white-box attacks are highly applicable in real-world scenarios, and the most effective attacks presently are white-box. Departing from earlier research, which employs model loss as the attack feature for white-box MIAs, we employ model gradients in our attack, leveraging the fact that these gradients provide a more profound understanding of model responses to various samples. We subject these models to rigorous testing across a range of parameters, including training steps, timestep sampling frequency, diffusion steps, and data variance. Across all experimental settings, our method consistently demonstrated near-flawless attack performance, with attack success rate approaching 100% and attack AUCROC near 1.0. We also evaluated our attack against common defense mechanisms, and observed our attacks continue to exhibit commendable performance. 
    more » « less