SearcharxivSearch

arXiv subjects

Bang Wu

Publications and source records attributed to Bang Wu.

15 recordsLinked to original sources

Engineering energy-time entanglement from resonance fluorescence

Resonance fluorescence from a coherently driven two-level emitter is a minimal quantum optical field that combines phase coherence with single-photon-level nonlinearity. Here we show that it can be engineered, using only passive linear interferometry, into energy-time entanglement. By injecting resonance fluorescence from a single quantum dot into an asymmetric Mach--Zehnder interferometer operated near destructive interference of the single-photon component, we generate an output field whose coincidence statistics are dominated by the simultaneous two-photon contribution |2> and the temporally separated photon-pair contribution |11>. In a Franson geometry, these two sectors are resolved on the coincidence-delay axis, and both exhibit high-visibility nonlocal interference fringes and violate the Clauser--Horne--Shimony--Holt Bell inequality. Our results reveal a general route for engineering entanglement from resonance fluorescence using passive optics.

quant-ph

Bell Inequality Violation with Vacuum-One-Photon Number Superposition States

Entanglement is a central resource in quantum technologies, and the realization of photonic entanglement necessarily relies on interaction with matter. Resonance fluorescence (RF), originating from the coherent interaction between a driving field and a two-level system, plays a pivotal role in quantum optics. Here, we demonstrate a novel route to entanglement generation based on RF from a single quantum dot. Rather than relying on generation of multiphoton states, our approach directly exploits vacuum-one-photon number superposition states created under resonant excitation. By delocalizing this superposition via a beam splitter, we realize time-bin entanglement and observe a clear violation of the Clauser-Horn-Shimony-Holt Bell inequality using Franson-type interferometry. Our scheme removes the need for multiphoton generation, simplifies the experimental requirements, and establishes a scalable pathway toward solid-state entangled photon sources.

quant-ph

Unsupervised Backdoor Detection and Mitigation for Spiking Neural Networks

Spiking Neural Networks (SNNs) have gained increasing attention for their superior energy efficiency compared to Artificial Neural Networks (ANNs). However, their security aspects, particularly under backdoor attacks, have received limited attention. Existing defense methods developed for ANNs perform poorly or can be easily bypassed in SNNs due to their event-driven and temporal dependencies. This paper identifies the key blockers that hinder traditional backdoor defenses in SNNs and proposes an unsupervised post-training detection framework, Temporal Membrane Potential Backdoor Detection (TMPBD), to overcome these challenges. TMPBD leverages the maximum margin statistics of temporal membrane potential (TMP) in the final spiking layer to detect target labels without any attack knowledge or data access. We further introduce a robust mitigation mechanism, Neural Dendrites Suppression Backdoor Mitigation (NDSBM), which clamps dendritic connections between early convolutional layers to suppress malicious neurons while preserving benign behaviors, guided by TMP extracted from a small, clean, unlabeled dataset. Extensive experiments on multiple neuromorphic benchmarks and state-of-the-art input-aware dynamic trigger attacks demonstrate that TMPBD achieves 100% detection accuracy, while NDSBM reduces the attack success rate from 100% to 8.44%, and to 2.81% when combined with detection, without degrading clean accuracy.

cs.CR

Two-photon interference between mutually-detuned resonance fluorescence signals scattered off a semiconductor quantum dot

The radiative linewidth of a two-level emitter (TLE) fundamentally limits the bandwidth available for quantum information processing. Despite its importance, no prior experiment has systematically examined how driving detuning affects the indistinguishability of photons scattered from a TLE - a parameter critical for photonic quantum computing. Here, we perform post-selective two-photon interference measurements between mutually detuned resonance fluorescence signals from an InAs quantum dot embedded in a micropillar cavity. At small mutual laser detunings (<=0.5GHz), the results are accurately described by the pure-state model [Nat. Commun. 16, 6453 (2025)], which treats all resonance-fluorescence photons as spontaneous emission. At larger detunings, we uncover an anomalous feature in the two-photon interference, where the normalised second-order correlation function under orthogonal polarisations yields g2_vert(0) < 0.5.

quant-ph

DeFiGuard: A Price Manipulation Detection Service in DeFi using Graph Neural Networks

The prosperity of Decentralized Finance (DeFi) unveils underlying risks, with reported losses surpassing 3.2 billion USD between 2018 and 2022 due to vulnerabilities in Decentralized Applications (DApps). One significant threat is the Price Manipulation Attack (PMA) that alters asset prices during transaction execution. As a result, PMA accounts for over 50 million USD in losses. To address the urgent need for efficient PMA detection, this paper introduces a novel detection service, DeFiGuard, using Graph Neural Networks (GNNs). In this paper, we propose cash flow graphs with four distinct features, which capture the trading behaviors from transactions. Moreover, DeFiGuard integrates transaction parsing, graph construction, model training, and PMA detection. Evaluations on a dataset of 208 PMA and 2,080 non-PMA transactions show that DeFiGuard with GNN models outperforms the baseline in Accuracy, TPR, FPR, and AUC-ROC. The results of ablation studies suggest that the combination of the four proposed node features enhances DeFiGuard's efficacy. Moreover, DeFiGuard classifies transactions within 0.892 to 5.317 seconds, which provides sufficient time for the victims (DApps and users) to take action to rescue their vulnerable funds. In conclusion, this research offers a significant step towards safeguarding the DeFi landscape from PMAs using GNNs.

cs.CR

Dynamic Graph Unlearning: A General and Efficient Post-Processing Method via Gradient Transformation

Dynamic graph neural networks (DGNNs) have emerged and been widely deployed in various web applications (e.g., Reddit) to serve users (e.g., personalized content delivery) due to their remarkable ability to learn from complex and dynamic user interaction data. Despite benefiting from high-quality services, users have raised privacy concerns, such as misuse of personal data (e.g., dynamic user-user/item interaction) for model training, requiring DGNNs to ``forget'' their data to meet AI governance laws (e.g., the ``right to be forgotten'' in GDPR). However, current static graph unlearning studies cannot \textit{unlearn dynamic graph elements} and exhibit limitations such as the model-specific design or reliance on pre-processing, which disenable their practicability in dynamic graph unlearning. To this end, we study the dynamic graph unlearning for the first time and propose an effective, efficient, general, and post-processing method to implement DGNN unlearning. Specifically, we first formulate dynamic graph unlearning in the context of continuous-time dynamic graphs, and then propose a method called Gradient Transformation that directly maps the unlearning request to the desired parameter update. Comprehensive evaluations on six real-world datasets and state-of-the-art DGNN backbones demonstrate its effectiveness (e.g., limited drop or obvious improvement in utility) and efficiency (e.g., 7.23$\times$ speed-up) advantages. Additionally, our method has the potential to handle future unlearning requests with significant performance gains (e.g., 32.59$\times$ speed-up).

cs.LG

Coherence in resonance fluorescence

Resonance fluorescence of a two-level emitter displays persistently anti-bunching irrespective of the excitation intensity, but inherits the driving laser's linewidth under weak monochromatic excitation. These properties are commonly explained in terms of two disjoined pictures, i.e., the emitter's single photon saturation or passively scattering light. Here, we propose a unified model that treats all fluorescence photons as spontaneous emission, one at a time, and can explain simultaneously both the spectral and correlation properties of the emission. We theoretically derive the excitation power dependencies, measurable at the single-photon incidence level, of the first-order coherence of the whole resonance fluorescence and super-bunching of the spectrally filtered, followed by experimental confirmation on a semiconductor quantum dot micro-pillar device. Furthermore, our model explains peculiar coincidence bunching observed in phase-dependent two-photon interference experiments. Our work provides an intuitive understanding of coherent light-matter interaction and may stimulate new applications.

quant-ph

GraphGuard: Detecting and Counteracting Training Data Misuse in Graph Neural Networks

The emergence of Graph Neural Networks (GNNs) in graph data analysis and their deployment on Machine Learning as a Service platforms have raised critical concerns about data misuse during model training. This situation is further exacerbated due to the lack of transparency in local training processes, potentially leading to the unauthorized accumulation of large volumes of graph data, thereby infringing on the intellectual property rights of data owners. Existing methodologies often address either data misuse detection or mitigation, and are primarily designed for local GNN models rather than cloud-based MLaaS platforms. These limitations call for an effective and comprehensive solution that detects and mitigates data misuse without requiring exact training data while respecting the proprietary nature of such data. This paper introduces a pioneering approach called GraphGuard, to tackle these challenges. We propose a training-data-free method that not only detects graph data misuse but also mitigates its impact via targeted unlearning, all without relying on the original training data. Our innovative misuse detection technique employs membership inference with radioactive data, enhancing the distinguishability between member and non-member data distributions. For mitigation, we utilize synthetic graphs that emulate the characteristics previously learned by the target model, enabling effective unlearning even in the absence of exact graph data. We conduct comprehensive experiments utilizing four real-world graph datasets to demonstrate the efficacy of GraphGuard in both detection and unlearning. We show that GraphGuard attains a near-perfect detection rate of approximately 100% across these datasets with various GNN models. In addition, it performs unlearning by eliminating the impact of the unlearned graph with a marginal decrease in accuracy (less than 5%).

cs.LG

Securing Graph Neural Networks in MLaaS: A Comprehensive Realization of Query-based Integrity Verification

The deployment of Graph Neural Networks (GNNs) within Machine Learning as a Service (MLaaS) has opened up new attack surfaces and an escalation in security concerns regarding model-centric attacks. These attacks can directly manipulate the GNN model parameters during serving, causing incorrect predictions and posing substantial threats to essential GNN applications. Traditional integrity verification methods falter in this context due to the limitations imposed by MLaaS and the distinct characteristics of GNN models. In this research, we introduce a groundbreaking approach to protect GNN models in MLaaS from model-centric attacks. Our approach includes a comprehensive verification schema for GNN's integrity, taking into account both transductive and inductive GNNs, and accommodating varying pre-deployment knowledge of the models. We propose a query-based verification technique, fortified with innovative node fingerprint generation algorithms. To deal with advanced attackers who know our mechanisms in advance, we introduce randomized fingerprint nodes within our design. The experimental evaluation demonstrates that our method can detect five representative adversarial model-centric attacks, displaying 2 to 4 times greater efficiency compared to baselines.

cs.CR

The Mollow triplets under few-photon excitation

Resonant excitation is an essential tool in the development of semiconductor quantum dots (QDs) for quantum information processing. One central challenge is to enable a transparent access to the QD signal without post-selection information loss. A viable path is through cavity enhancement, which has successfully lifted the resonantly scattered field strength over the laser background under \emph{weak} excitation. Here, we extend this success to the \emph{saturation} regime using a QD-micropillar device with a Purcell factor of 10.9 and an ultra-low background cavity reflectivity of just 0.0089. We achieve a signal to background ratio of 50 and an overall system responsivity of 3~\%, i.e., we detect on average 0.03 resonantly scattered single photons for every incident laser photon. Raising the excitation to the few-photon level, the QD response is brought into saturation where we observe the Mollow triplets as well as the associated cascade single photon emissions, without resort to any laser background rejection technique. Our work offers a new perspective toward QD cavity interface that is not restricted by the laser background.

quant-ph

Black-box Adversarial Example Attack towards FCG Based Android Malware Detection under Incomplete Feature Information

The function call graph (FCG) based Android malware detection methods have recently attracted increasing attention due to their promising performance. However, these methods are susceptible to adversarial examples (AEs). In this paper, we design a novel black-box AE attack towards the FCG based malware detection system, called BagAmmo. To mislead its target system, BagAmmo purposefully perturbs the FCG feature of malware through inserting "never-executed" function calls into malware code. The main challenges are two-fold. First, the malware functionality should not be changed by adversarial perturbation. Second, the information of the target system (e.g., the graph feature granularity and the output probabilities) is absent. To preserve malware functionality, BagAmmo employs the try-catch trap to insert function calls to perturb the FCG of malware. Without the knowledge about feature granularity and output probabilities, BagAmmo adopts the architecture of generative adversarial network (GAN), and leverages a multi-population co-evolution algorithm (i.e., Apoem) to generate the desired perturbation. Every population in Apoem represents a possible feature granularity, and the real feature granularity can be achieved when Apoem converges. Through extensive experiments on over 44k Android apps and 32 target models, we evaluate the effectiveness, efficiency and resilience of BagAmmo. BagAmmo achieves an average attack success rate of over 99.9% on MaMaDroid, APIGraph and GCN, and still performs well in the scenario of concept drift and data imbalance. Moreover, BagAmmo outperforms the state-of-the-art attack SRL in attack success rate.

cs.SE

Trustworthy Graph Neural Networks: Aspects, Methods and Trends

Graph neural networks (GNNs) have emerged as a series of competent graph learning methods for diverse real-world scenarios, ranging from daily applications like recommendation systems and question answering to cutting-edge technologies such as drug discovery in life sciences and n-body simulation in astrophysics. However, task performance is not the only requirement for GNNs. Performance-oriented GNNs have exhibited potential adverse effects like vulnerability to adversarial attacks, unexplainable discrimination against disadvantaged groups, or excessive resource consumption in edge computing environments. To avoid these unintentional harms, it is necessary to build competent GNNs characterised by trustworthiness. To this end, we propose a comprehensive roadmap to build trustworthy GNNs from the view of the various computing technologies involved. In this survey, we introduce basic concepts and comprehensively summarise existing efforts for trustworthy GNNs from six aspects, including robustness, explainability, privacy, fairness, accountability, and environmental well-being. Additionally, we highlight the intricate cross-aspect relations between the above six aspects of trustworthy GNNs. Finally, we present a thorough overview of trending directions for facilitating the research and industrialisation of trustworthy GNNs.

cs.LG

Defeating Misclassification Attacks Against Transfer Learning

Transfer learning is prevalent as a technique to efficiently generate new models (Student models) based on the knowledge transferred from a pre-trained model (Teacher model). However, Teacher models are often publicly available for sharing and reuse, which inevitably introduces vulnerability to trigger severe attacks against transfer learning systems. In this paper, we take a first step towards mitigating one of the most advanced misclassification attacks in transfer learning. We design a distilled differentiator via activation-based network pruning to enervate the attack transferability while retaining accuracy. We adopt an ensemble structure from variant differentiators to improve the defence robustness. To avoid the bloated ensemble size during inference, we propose a two-phase defence, in which inference from the Student model is firstly performed to narrow down the candidate differentiators to be assembled, and later only a small, fixed number of them can be chosen to validate clean or reject adversarial inputs effectively. Our comprehensive evaluations on both large and small image recognition tasks confirm that the Student models with our defence of only 5 differentiators are immune to over 90% of the adversarial inputs with an accuracy loss of less than 10%. Our comparison also demonstrates that our design outperforms prior problematic defences.

cs.LG

Model Extraction Attacks on Graph Neural Networks: Taxonomy and Realization

Machine learning models are shown to face a severe threat from Model Extraction Attacks, where a well-trained private model owned by a service provider can be stolen by an attacker pretending as a client. Unfortunately, prior works focus on the models trained over the Euclidean space, e.g., images and texts, while how to extract a GNN model that contains a graph structure and node features is yet to be explored. In this paper, for the first time, we comprehensively investigate and develop model extraction attacks against GNN models. We first systematically formalise the threat modelling in the context of GNN model extraction and classify the adversarial threats into seven categories by considering different background knowledge of the attacker, e.g., attributes and/or neighbour connections of the nodes obtained by the attacker. Then we present detailed methods which utilise the accessible knowledge in each threat to implement the attacks. By evaluating over three real-world datasets, our attacks are shown to extract duplicated models effectively, i.e., 84% - 89% of the inputs in the target domain have the same output predictions as the victim model.

cs.LG

Adapting Membership Inference Attacks to GNN for Graph Classification: Approaches and Implications

Graph Neural Networks (GNNs) are widely adopted to analyse non-Euclidean data, such as chemical networks, brain networks, and social networks, modelling complex relationships and interdependency between objects. Recently, Membership Inference Attack (MIA) against GNNs raises severe privacy concerns, where training data can be leaked from trained GNN models. However, prior studies focus on inferring the membership of only the components in a graph, e.g., an individual node or edge. How to infer the membership of an entire graph record is yet to be explored. In this paper, we take the first step in MIA against GNNs for graph-level classification. Our objective is to infer whether a graph sample has been used for training a GNN model. We present and implement two types of attacks, i.e., training-based attacks and threshold-based attacks from different adversarial capabilities. We perform comprehensive experiments to evaluate our attacks in seven real-world datasets using five representative GNN models. Both our attacks are shown effective and can achieve high performance, i.e., reaching over 0.7 attack F1 scores in most cases. Furthermore, we analyse the implications behind the MIA against GNNs. Our findings confirm that GNNs can be even more vulnerable to MIA than the models with non-graph structures. And unlike the node-level classifier, MIAs on graph-level classification tasks are more co-related with the overfitting level of GNNs rather than the statistic property of their training graphs.

cs.LG