Arrow Research search

Author name cluster

Li Bai

Possible papers associated with this exact author name in Arrow. This page groups case-insensitive exact name matches and is not a full identity disambiguation profile.

4 papers
1 author row

Possible papers

4

AAAI Conference 2025 Conference Paper

A Sample-Level Evaluation and Generative Framework for Model Inversion Attacks

  • Haoyang Li
  • Li Bai
  • Qingqing Ye
  • Haibo Hu
  • Yaxin Xiao
  • Huadi Zheng
  • Jianliang Xu

Model Inversion (MI) attacks, which reconstruct the training dataset of neural networks, pose significant privacy concerns in machine learning. Recent MI attacks have managed to reconstruct realistic label-level private data, such as the general appearance of a target person from all training images labeled on him. Beyond label-level privacy, in this paper we show sample-level privacy, the private information of a single target sample, is also important but under-explored in the MI literature due to the limitations of existing evaluation metrics. To address this gap, this study introduces a novel metric tailored for training-sample analysis, namely, the Diversity and Distance Composite Score (DDCS), which evaluates the reconstruction fidelity of each training sample by encompassing various MI attack attributes. This, in turn, enhances the precision of sample-level privacy assessments. Leveraging DDCS as a new evaluative lens, we observe that many training samples remain resilient against even the most advanced MI attack. As such, we further propose a transfer learning framework that augments the generative capabilities of MI attackers through the integration of entropy loss and natural gradient descent. Extensive experiments verify the effectiveness of our framework on improving state-of-the-art MI attacks over various metrics including DDCS, coverage and FID. Finally, we demonstrate that DDCS can also be useful for MI defense, by identifying samples susceptible to MI attacks in an unsupervised manner.

NeurIPS Conference 2025 Conference Paper

Toward Efficient Inference Attacks: Shadow Model Sharing via Mixture-of-Experts

  • Li Bai
  • Qingqing Ye
  • Xinwei Zhang
  • Sen Zhang
  • Zi Liang
  • Jianliang Xu
  • Haibo Hu

Machine learning models are often vulnerable to inference attacks that expose sensitive information from their training data. Shadow model technique is commonly employed in such attacks, like membership inference. However, the need for a large number of shadow models leads to high computational costs, limiting their practical applicability. Such inefficiency mainly stems from the independent training and use of these shadow models. To address this issue, we present a novel shadow pool training framework SHAPOOL, which constructs multiple shared models and trains them jointly within a single process. In particular, we leverage the Mixture-of-Experts mechanism as the shadow pool to interconnect individual models, enabling them to share some sub-networks and thereby improving efficiency. To ensure the shared models closely resemble independent models and serve as effective substitutes, we introduce three novel modules: path-choice routing, pathway regularization, and pathway alignment. These modules guarantee random data allocation for pathway learning, promote diversity among shared models, and maintain consistency with target models. We evaluate SHAPOOL in the context of various membership inference attacks and show that it significantly reduces the computational cost of shadow model construction while maintaining comparable attack performance.

YNIMG Journal 2011 Journal Article

Smoothness-guided 3-D reconstruction of 2-D histological images

  • Amalia Cifor
  • Li Bai
  • Alain Pitiot

This paper tackles two problems: (1) the reconstruction of 3-D volumes from 2-D post-mortem slices (e. g. , histology, autoradiography, immunohistochemistry) in the absence of external reference, and (2) the quantitative evaluation of the 3-D reconstruction. We note that the quality of a reconstructed volume is usually assessed by considering the smoothness of some reconstructed structures of interest (e. g. , the gray–white matter surfaces in brain images). Here we propose to use smoothness as a means to drive the reconstruction process itself. From a pair-wise rigid reconstruction of the 2-D slices, we first extract the boundaries of structures of interest. Those are then smoothed with a min–max curvature flow confined to the 2-D planes in which the slices lie. Finally, for each slice, we estimate a linear or flexible transformation from the sparse displacement field computed from the flow, which we apply to the original 2-D slices to obtain a smooth volume. In addition, we present a co-occurrence matrix-based technique to quantify the smoothness of reconstructed volumes. We discuss and validate the application of both our reconstruction approach and the smoothness measure on synthetic examples as well as real histological data.

YNIMG Journal 2010 Journal Article

Brain tractography using Q-ball imaging and graph theory: Improved connectivities through fibre crossings via a model-based approach

  • Stamatios N. Sotiropoulos
  • Li Bai
  • Paul S. Morgan
  • Cris S. Constantinescu
  • Christopher R. Tench

Brain tractography techniques utilize a set of diffusion-weighted magnetic resonance images to reconstruct white matter tracts, non-invasively and in-vivo. Streamline tracking techniques propagate curves from a seed to imply connectivity to distal voxels. Alternative approaches have been developed that attempt to quantify connection strength between all voxels and the seed. Tractography based on graph theory is amongst them. Despite its potential, graph-based tracking through complex fibre configurations has not been extensively studied and existing methods have inherent limitations. Anatomically unlikely connections may be identified in fibre crossing regions, by assigning relatively high connection strengths to all crossing populations. In this study, we discuss these limitations and present a new approach for robustly propagating through fibre crossings, as described by the orientation distribution functions (ODFs) derived from Q-ball imaging. Each image voxel is treated as a graph node and graph arcs connect neighbouring voxels. Weights representative of both structural and diffusivity features are assigned to each arc. To account for the existence of crossing fibre populations within a voxel, complex ODFs are decomposed into components representative of single-fibre populations and an image multigraph is created. The multigraph is searched exhaustively, but efficiently, to find the strongest paths and assign connectivity strengths between a seed and all the other image voxels. A comparison with the existing graph-based tractography as well as Q-ball driven front evolution tractography is performed on simulated data, and on human Q-ball imaging data acquired from five healthy volunteers. The new approach improves the connection strengths through fibre crossing regions, reducing the strengths of paths that are less anatomically plausible.

v2026.09.13