Searcharxiv⌕ Search

arXiv subjects

Haizhuan Yuan

Publications and source records attributed to Haizhuan Yuan.

5 recordsLinked to original sources

Towards Model Extraction Attacks in GAN-Based Image Translation via Domain Shift Mitigation

Model extraction attacks (MEAs) enable an attacker to replicate the functionality of a victim deep neural network (DNN) model by only querying its API service remotely, posing a severe threat to the security and integrity of pay-per-query DNN-based services. Although the majority of current research on MEAs has primarily concentrated on neural classifiers, there is a growing prevalence of image-to-image translation (I2IT) tasks in our everyday activities. However, techniques developed for MEA of DNN classifiers cannot be directly transferred to the case of I2IT, rendering the vulnerability of I2IT models to MEA attacks often underestimated. This paper unveils the threat of MEA in I2IT tasks from a new perspective. Diverging from the traditional approach of bridging the distribution gap between attacker queries and victim training samples, we opt to mitigate the effect caused by the different distributions, known as the domain shift. This is achieved by introducing a new regularization term that penalizes high-frequency noise, and seeking a flatter minimum to avoid overfitting to the shifted distribution. Extensive experiments on different image translation tasks, including image super-resolution and style transfer, are performed on different backbone victim models, and the new design consistently outperforms the baseline by a large margin across all metrics. A few real-life I2IT APIs are also verified to be extremely vulnerable to our attack, emphasizing the need for enhanced defenses and potentially revised API publishing policies.

cs.CR↗

Purified Two-Relaxation-Time Lattice Boltzmann Method: Removing Ghost Modes from TRT for Enhanced Stability

The two-relaxation-time (TRT) lattice Boltzmann model is widely adopted for its simplicity and tunable boundary accuracy. However, its collision operator relaxes the full symmetric non-equilibrium component, implicitly retaining non-hydrodynamic ghost modes that degrade stability at high Reynolds numbers. In this work, we establish a rigorous connection between ghost-mode filtering and regularization within the TRT framework. By decomposing the discrete velocity space into hydrodynamic and non-hydrodynamic subspaces, we prove that the TRT-regularized lattice Boltzmann (TRT-RLB) model is mathematically equivalent to the standard TRT model with ghost modes explicitly removed. This equivalence holds exactly for D2Q9 and D3Q19 lattices, where the symmetric and antisymmetric subspaces are completely spanned by the physically relevant Hermite modes and identifiable ghost modes. Based on this finding, we propose the Purified TRT (P-TRT) model, which achieves regularization-level stability through simple algebraic ghost-mode subtraction rather than expensive tensor projections. For D2Q9, the non-equilibrium collision cost is reduced from 180 to 52 floating-point operations per node, a 71% reduction. Linear stability analysis in moment space further reveals that the P-TRT operator annihilates the ghost eigenvalue, proving its spectral radius is bounded above by that of standard TRT and that stability is governed exclusively by hydrodynamic modes. Benchmarks including the double shear layer at Re up to 10^7, Taylor--Green vortex decay, force-driven Poiseuille flow, and creeping flow past a square cylinder confirm that P-TRT preserves the stability, second-order accuracy, and zero-slip boundary properties of TRT-RLB while retaining the simplicity of the TRT family.

physics.flu-dyn↗

When Better Features Mean Greater Risks: The Performance-Privacy Trade-Off in Contrastive Learning

With the rapid advancement of deep learning technology, pre-trained encoder models have demonstrated exceptional feature extraction capabilities, playing a pivotal role in the research and application of deep learning. However, their widespread use has raised significant concerns about the risk of training data privacy leakage. This paper systematically investigates the privacy threats posed by membership inference attacks (MIAs) targeting encoder models, focusing on contrastive learning frameworks. Through experimental analysis, we reveal the significant impact of model architecture complexity on membership privacy leakage: As more advanced encoder frameworks improve feature-extraction performance, they simultaneously exacerbate privacy-leakage risks. Furthermore, this paper proposes a novel membership inference attack method based on the p-norm of feature vectors, termed the Embedding Lp-Norm Likelihood Attack (LpLA). This method infers membership status, by leveraging the statistical distribution characteristics of the p-norm of feature vectors. Experimental results across multiple datasets and model architectures demonstrate that LpLA outperforms existing methods in attack performance and robustness, particularly under limited attack knowledge and query volumes. This study not only uncovers the potential risks of privacy leakage in contrastive learning frameworks, but also provides a practical basis for privacy protection research in encoder models. We hope that this work will draw greater attention to the privacy risks associated with self-supervised learning models and shed light on the importance of a balance between model utility and training data privacy. Our code is publicly available at: https://github.com/SeroneySun/LpLA_code.

cs.CR↗

Two-relaxation-time regularized lattice Boltzmann model for convection-diffusion equation with variable coefficients

In this paper, a new two-relaxation-time regularized (TRT-R) lattice Boltzmann (LB) model for convection-diffusion equation (CDE) with variable coefficients is proposed. Within this framework, we first derive a TRT-R collision operator by constructing a new regularized procedure through the high-order Hermite expansion of non-equilibrium. Then a first-order discrete-velocity form of discrete source term is introduced to improve the accuracy of the source term. Finally and most importantly, a new first-order space-derivative auxiliary term is proposed to recover the correct CDE with variable coefficients. To evaluate this model, we simulate a classic benchmark problem of the rotating Gaussian pulse. The results show that our model has better accuracy, stability and convergence than other popular LB models, especially in the case of a large time step.

math.NA↗

Particulate immersed boundary method for complex fluid-particle interaction problems with heat transfer

In our recent work [H. Zhang, F.X. Trias, A. Oliva, D. Yang, Y. Tan, Y. Sheng. PIBM: Particulate immersed boundary method for fluid-particle interaction problems. Powder Technology. 272(2015), 1-13.], a particulate immersed boundary method (PIBM) for simulating fluid-particle multiphase flow was proposed and assessed in both two- and three-dimensional applications. In this study, the PIBM was extended to solve thermal interaction problems between spherical particles and fluid. The Lattice Boltzmann Method (LBM) was adopted to solve the fluid flow and temperature fields, the PIBM was responsible for the non-slip velocity and temperature boundary conditions at the particle surface, and the kinematics and trajectory of the solid particles were evaluated by the Discrete Element Method (DEM). Four case studies were implemented to demonstrate the capability of the current coupling scheme. Firstly, numerical simulation of natural convection in a two-dimensional square cavity with an isothermal concentric annulus was carried out for verification purpose. The current results were found to have good agreements with previous references. Then, sedimentation of two- and three-dimensional isothermal particles in fluid was numerically studied, respectively. The instantaneous temperature distribution in the cavity was captured. The effect of the thermal buoyancy on particle behaviors was discussed. At last, sedimentation of three-dimensional thermosensitive particles in fluid was numerically investigated. Our results revealed that the LBM-PIBM-DEM is a promising scheme for the solution of complex fluid-particle interaction problems with heat transfer.

physics.comp-ph↗