English Version


Mingfu XUE (薛明富)


IEEE Senior MemberCCF高级会员;CSIG高级会员

上海, 200241, 中国
Email: mfxue@cee.ecnu.edu.cn



  1. 研究方向新颖有趣。
  2. 课题组往届毕业生成果丰硕:人均科研分 50-65 分(毕业要求为 12 分);多位毕业生获评“校优秀硕士学位论文”;多位学生获“校科研创新先进个人”。
  3. 课题组项目经费宽裕,有较多的国际学术会议等交流机会。



  1. 计算机视觉、机器学习、人工智能、深度学习、大数据、图像处理中的安全问题及对抗。
  2. 人工智能安全:1)鲁棒/安全/隐私的人工智能系统,包括五类攻防:训练集中毒、训练集后门、对抗样本、模型窃取、泄露敏感数据;2)人工智能在网络空间安全攻防中的应用。
  3. 硬件安全、硬件木马检测;
  4. 深度学习模型的版权保护。



已主持科研项目 17 项,含4个国家级项目(国家自然科学基金面上基金、国家自然科学基金青年基金、XXXXXX项目、XXXXXX 项目)、 4 个省部级项目、 入选3 个 CCF 基金等。另参与 XXXXXX 项目、XXXXX 项目等 5个国家级项目。

在信息安全相关期刊和国际会议发表论文近70篇,其中30余篇SCI,如:IEEE Transactions on Dependable and Secure Computing(CCF A类), IEEE Transactions on Emerging Topics in Computing, IEEE Transactions on Industrial Informatics (中科院一区), IEEE Transactions on Artificial Intelligence,IEEE Transactions on Visualization and Computer Graphics(CCF A类)IEEE Transactions on Neural Networks and Learning Systems (中科院 一区)IEEE Transactions on Big Data, IEEE Transactions on Vehicular Technology,ACM Transactions on Multimedia Computing Communications and Applications, Information Sciences(中科院一区), Computers & Security(CCF B类) Applied Intelligence(中科院二区),Journal of Information Security and Applications (CCF C类), Peer-to-Peer Networking and Applications (CCF C类),Security and Communication Networks(CCF C类),计算机学报(CCF中文A类),电子学报(CCF中文A类),等等。 另有十余篇在审/ArXiv






1. One-to-N & N-to-One: Two Advanced Backdoor Attacks against Deep Learning Models. IEEE Transactions on Dependable and Secure Computing. 2020, SCI, CCF A, IF 7.329

2. AdvParams: An Active DNN Intellectual Property Protection Technique via Adversarial Perturbation Based Parameter Encryption . IEEE Transactions on Emerging Topics in Computing,2022,SCI,IF 7.691

3. Untargeted Backdoor Attack against Deep Neural Networks with Imperceptible Trigger. IEEE Transactions on Industrial Informatics, 2023, SCI,中科院1区,IF 12.3

4. An Explainable Intellectual Property Protection Method for Deep Neural Networks based on Intrinsic Features. IEEE Transactions on Artificial Intelligence, 2024

5. Intellectual Property Protection for Deep Learning Models: Taxonomy, Methods, Attacks, and Evaluations. IEEE Transactions on Artificial Intelligence, 2021.

6. Use the Spear as a Shield: An Adversarial Example based Privacy-Preserving Technique against Membership Inference Attacks. IEEE Transactions on Emerging Topics in Computing,2022,SCI, IF 7.691

7. Adaptive 3D Mesh Steganography Based on Feature-Preserving Distortion. IEEE Transactions on Visualization and Computer Graphics . 2023, SCI,CCF A 类

8. Localization of Conventional Inpainting With Feature Enhancement Network. IEEE Transactions on Big Data, 2022, SCI

9. PS-Net: A Learning Strategy for Accurately Exposing the Professional Photoshop Inpainting. IEEE Transactions on Neural Networks and Learning Systems. 2023, SCI, 中科院 1 区

10. PRNU-based Image Forgery Localization With Deep Multi-Scale Fusion. ACM Transactions on Multimedia Computing Communications and Applications, 2022, SCI

11. Detection of Recolored Image by Texture Features in Chrominance Components. ACM Transactions on Multimedia Computing, Communications, and Applications. 2022, https://doi.org/10.1145/3571076,SCI

12. Detecting Backdoor in Deep Neural Networks via Intentional Adversarial Perturbations. Information Sciences . 中科院1区, SCI, 2023

13. LOPA: A Linear Offset Based Poisoning Attack Method Against Adaptive Fingerprint Authentication System. Computers & Security. 99, 2020, 102046, pp.1-13. SCI, CCF B, IF 4.438

14. PTB: Robust Physical Backdoor Attacks against Deep Neural Networks in Real World. Computers & Security, 2022. SCI, CCF B, IF 4.438

15. Dataset Authorization Control: Protect the Intellectual Property of Dataset via Reversible Feature Space Adversarial Examples. Applied Intelligence. 2022. SCI, 中科院 2 区,IF 5.3.

16. Active Intellectual Property Protection for Deep Neural Networks through Stealthy Backdoor and Users' Identities Authentication. Applied Intelligence, 2022. SCI, 中科院 2 区, IF 5.3

17. Compression-Resistant Backdoor Attack against Deep Neural Networks. Applied Intelligence, 2023. SCI, 中科院2区, IF 5.3.

18. Imperceptible and Multi-Channel Backdoor Attack. Applied Intelligence, 2023. SCI, 中科院 2 区, IF 5.3.

19. NaturalAE: Natural and robust physical adversarial examples for object detectors. Journal of Information Security and Applications. 57 (2021) 102694, 1-12. SCI, CCF C, IF 3.872

20. Backdoors Hidden in Facial Features: A Novel Invisible Backdoor Attack against Face Recognition Systems. Peer-to-Peer Networking and Applications. 2021, 14:1458–1474. SCI, CCF C, IF 3.307

21. SocialGuard: An Adversarial Example Based Privacy-Preserving Technique for Social Images. Journal of Information Security and Applications. 2021. SCI, CCF C, IF 3.872

22. ActiveGuard: An active intellectual property protection technique for deep neural networks by leveraging adversarial examples as users' fingerprints. IET Computers & Digital Techniques, 2023, SCI

23. Ten years of hardware Trojans: a survey from the attacker's perspective. IET Computers & Digital Techniques. 2020, Vol. 14, Iss. 6, pp. 231-246. SCI

24. DPAEG: A Dependency Parse Based Adversarial Examples Generation Method for Intelligent Q&A Robots. Security and Communication Networks. 2020, Volume 2020, Article ID 5890820:1-15. SCI, CCF C

25. Machine Learning Security: Threats, Countermeasures, and Evaluations. IEEE Access, 2020, Vol 8, pp. 74720-74742. SCI

26. Active DNN IP Protection: A Novel User Fingerprint Management and DNN Authorization Control Technique. The 19th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (IEEE TrustCom), 2020. EI, CCF C

27. DNN Intellectual Property Protection: Taxonomy, Attacks and Evaluations (Invited Paper). In Proceedings of the Great Lakes Symposium on VLSI 2021 (GLSVLSI '21). EI, CCF C, Session邀请报告和Invited Paper

28. Robust Backdoor Attacks against Deep Neural Networks in Real Physical World. The 20th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom 2021). EI, CCF C

29. Detect and Remove Watermark in Deep Neural Networks via Generative Adversarial Networks. 24th Information Security Conference (ISC) 2021. EI, CCF C, 录用率 24%.

30. Sample-Specific Backdoor based Active Intellectual Property Protection for Deep Neural Networks. IEEE AICAS,2022. EI,Session 邀请报告和邀请论文.

31. Embedding Backdoors as the Facial Features: Invisible Backdoor Attacks Against Face Recognition Systems. ACM TURC'20: Proceedings of the ACM Turing Celebration Conference - China. May 2020, Pages 231–235. EI, 被推荐扩展到期刊.

32. An Imperceptible and Owner-unique Watermarking Method for Graph Neural Networks. ACM Turing Award Celebration Conference 2024 (ACM TURC ’24). EI

33. Tracking the Leaker: An Encodable Watermarking Method for Dataset Intellectual Property Protection. ACM Turing Award Celebration Conference 2024 (ACM TURC '24). EI

34. Qing Tan, Shuren Qi, Yushu Zhang, Mingfu Xue. PRNU-based Image Forgery Localization With Convolutional Neural Network. IEEE 24th International Workshop on Multimedia Signal Processing. 2022, EI

35. ActiveGuard: Active Intellectual Property Protection for Deep Neural Networks via Adversarial Examples based User Fingerprinting. AAAI 2022 workshop, International Workshop on Practical Deep Learning in the Wild. EI

36.傅志彬 ; 祁树仁 ; 张玉书 ; 薛明富. 基于稠密连接的深度修复定位网络 . 信息网络安全, 2022 年第 7 期, 84-93. CCF T3

37.陈诺,祁树仁,张玉书,薛明富,花忠云. 基于通道间相关性的图像重着色检测. 网络与信息安全学报,2022,第8 卷第5 期,167-178. CCF中文C类

38.祁树仁,张玉书,薛明富,花忠云 . 面向多畸变稳健性的图像归因算法. 信息网络安全. 2023, 23(04), 30-38. CCF计算领域高质量科技期刊分级目录T3类








  • 2024/4 - 至今, 华东师范大学,通信与电子工程学院,教授、博士生导师
  • 2014/5 - 2024/3,南京航空航天大学,计算机科学与技术学院,先后讲师、副教授
  • 2011/7 - 2012/7,新加坡南洋理工大学,公派留学联合培养,导师:Prof. Chang Chip-Hong, IEEE Fellow
  • 2010/9 - 2014/4,东南大学,信息与通信工程(信息安全方向),博士,导师:胡爱群教授
  • 2008/9 - 2010/7,东南大学,信息与通信工程(信息安全方向),硕士(保博),导师:胡爱群教授
  • 2004/9 - 2008/7,西南交通大学,电子信息工程,学士(四次获特等奖学金,保研)



  1. 国家自然科学基金面上项目 (国家级项目) ;

  2. 国家自然科学基金青年基金(国家级项目) ;

  3. XXXXXXXXXXX(国家级项目,原XX863);

  4. XXXXXXXXXXX(国家级项目

  5. CCF-绿盟科技鲲鹏科研基金项目 (2021中国计算机大会颁奖,全国共14人);

  6. CCF-启明星辰鸿雁科研计划 ( 2016 中国计算机大会颁奖,全国共 16 人) ;

  7. CCF-绿盟科技鲲鹏科研基金项目 ( 2017 中国计算机大会颁奖,全国共 11 人) ;

  8. 江苏省自然科学基金青年基金 (省部级项目) ;

  9. 航空科学基金 — 航空人工智能专项( 省部级项目 ) ;

  10. 中国博士后科学基金面上资助(省部级项目);

  11. 江苏省博士后基金科研资助(省部级项目);

  12. 中国空间技术研究院(航天科技五院)503所项目;

  13. 中国电子科技集团30所项目;

  14. 深信服科技股份有限公司项目;

  15. 中国民航信息技术科研基地开放基金课题;

  16. 中央高校基本科研业务费专项资金;

  17. 入选工信部揭榜挂帅项目潜力单位,子课题负责人;

  18. 三个教改项目;





  4. 国家自然科学基金面上项目;

  5. 国家自然科学基金青年项目;

  6. 1个教改项目。



  1. 中国人工智能学会人工智能与安全专业委员会委员;
  2. 中国电子学会网络空间安全专家委员会委员;
  3. ACM南京分会执行委员会委员;
  4. 中国图象图形学学会数字媒体取证与安全专委会委员;
  5. 中国人工智能学会青年工作委员会委员;
  6. 江苏省计算机学会信息安全专委会;
  7. 江苏省人工智能学会智能与安全专委会委员;
  8. 江苏省网络空间安全学会数据安全专委会委员;
  9. 江苏省网络空间安全学会人工智能安全专委会委员;
  10. CAAI 智能信息网络专委会委员;
  11. 江苏省计算机学会网络与分布计算专业委员会委员;
  12. 上海市计算机学会信息安全专业委员会;
  13. 第三届全国硬件安全论坛程序主席;
  14. 中国媒体取证与安全大会(ChinaMFS 2022)出版主席;
  15. IEEE Senior MemberCCF Senior Member;CSIG高级会员;ACM会员;CAAI会员



  • 2015: ICCCS2015;CBD2015;
  • 2016: CBD2016;
  • 2017: IEEE GLOBECOM2017;
  • 2018: IEEE GLOBECOM2018;CBD2018;IEEE COMNETSAT2018;全国硬件安全论坛;
  • 2019: IEEE GLOBECOM2019;IEEE COMNETSAT2019;IEEE GCC2019;IEEE MENACOMM'19;SSCC-2019;3ICT'19;CFTC2019;ICCCN2019-BDMLS workshop;CBD 2019;SSCC-CIS-2019;
  • 2020: ICCCN-BDMLS workshop2020;CCF CTC2020;CBD2020;ACM TURC 2020;3ICT2020;Globecom2020; ATS 2020
  • 2021: ACM TURC 2021;AITS 2021;SIoTEC 2021;ATS 2021;Globecom2021 CISS;CBD2021
  • 2022: Globecom2022 CISS TPC;AITS2022;ATS2022;CBD2022;
  • 2023: ICCSI 2023; Globecom 2023 CISS TPC; ATS2023; AsianHOST2023;TRIDENTCOM2023;CBD2023;
  • 2024: AsianHOST 2024 ; Globecom 2024 CISS;




  • IEEE Transactions on Information Forensics & Security;
    IEEE Transactions on Dependable and Secure Computing;
    IEEE Transactions on Pattern Analysis and Machine Intelligence;
    IEEE Transactions on Neural Networks and Learning Systems;
    IEEE Transactions on Computer-Aided Design of Integrated Circuits and Systems;
    IEEE Transactions on Circuits and Systems I: Regular Papers.
    IEEE Transactions on Circuits and Systems II: Express Briefs.
    IEEE Transactions on Emerging Topics in Computing;
    IEEE Transactions on Multimedia;
    IEEE Transactions on Circuits and Systems for Video Technology;
    IEEE Transactions on Industrial Informatics;
    IEEE Transactions on Artificial Intelligence;
    IEEE Transactions on Software Engineering;
    IEEE Transactions on Image Processing;
    IEEE Transactions on VLSI Systems;
    IEEE Transactions on Sustainable Computing;
    IEEE Transactions on Reliability;
    IEEE Transactions on Big Data;
    IEEE Transactions on Services Computing;
    IEEE Transactions on Systems, Man and Cybernetics: Systems;
    IEEE Transactions on Consumer Electronics;
    ACM Transactions on Design Automation of Electronic Systems;
    ACM Transactions on Intelligent Systems and Technology;
    IEEE Journal on Selected Areas in Communications;
    IEEE Signal Processing Letters;
    IEEE Embedded Systems Letters;
    Pattern Recognition;
    Information Sciences;
    IEEE Internet of Things;
    Computer Networks;
    IEEE Open Journal of Signal Processing;
    Journal of Systems Architecture;
    IEEE Access;
    ACM Journal on Emerging Technologies in Computing Systems;
    IET Computers & Digital Techniques;
    IET Cyber-Physical Systems: Theory & Applications;
    Electronics Letters;
    Computers and Security;
    Journal of Information Security and Applications;
    Future Generation Computer Systems;
    Knowledge and Information Systems;
    Knowledge-Based Systems;
    Information Fusion;
    Frontiers of Computer Science;
    IEEE Journal on Emerging and Selected Topics in Circuits and Systems;
    Computers in Industry;
    Neural Networks;
    Advanced Engineering Informatics;
    International Journal of Intelligent Systems;
    Integration, the VLSI Journal;
    Peer-to-Peer Networking and Applications;
    Image and Vision Computing;
    Engineering Applications of Artificial Intelligence;
    Signal, Image and Video Processing;
    Applied Soft Computing;
    China Communications;
    Security and Communication Networks;
    Applied Intelligence;
    Artificial Intelligence Review;
    Neural Computing and Applications;
    Connection Science;
    Expert Systems With Applications;
    Computer Modeling in Engineering and Sciences;
    Scientific Reports;
    Computers and Electrical Engineering;
    Wireless Communications and Mobile Computing;
    International Journal of Distributed Sensor Networks;
    Defence Technology;
    Journal of Intelligent & Fuzzy Systems;
    Journal of Internet Technology;
    Chinese Journal of Electronics;
    Digital Signal Processing;
    Computers, Materials & Continua;
    ICT Express;
    Microprocessors and Microsystems;
    EURASIP Journal on Wireless Communications and Networking;
    IEEE Open Journal of the Industrial Electronics Society;
    Journal of Semiconductors;
    Journal of King Saud University - Computer and Information Sciences;
    Journal of Sensors;
    IETE Journal of Research;
    Information Security Journal: A Global Perspective;
    International Journal of Automation and Computing;
    Software: Practice and Experience;
    Recent Patents on Computer Science;
    Recent Patents on Engineering;
    Recent Advances in Computer Science and Communications;
    Journal of Current Science and Technology;
    Review applications for the Estonian Research Council(评审爱沙尼亚研究委员会基金)


  • 2013: IEEE WCNC;
  • 2015: ICCCS2015, CBD2015;
  • 2016: CHES2016, CBD2016;
  • 2017: IEEE ISCAS2017, IEEE MWSCAS2017, IEEE ASAP2017, ISPACS2017, CBD2017,IEEE GLOBECOM2017;
  • 2018: IEEE GLOBECOM2018, IEEE MWSCAS2018, CBD2018;
  • 2019: IEEE ISCAS2019; ISVLSI 2019; IEEE MWSCAS 2019; CFTC2019; IEEE MENACOMM'19; ICCCN2019-BDMLS workshop; MLICOM 2019; IEEE Globecom2019; IEEE COMNETSAT 2019; CBD 2019; 3ICT'19;SSCC-2019;
  • 2020: ISCAS2020; ICCCN-BDMLS workshop2020; ACM TURC 2020; CCF CTC2020; Globecom2020; CBD2020; AJCAI2020; 3ICT2020; ATS 2020;
  • 2021: AITS 2021; SIoTEC 2021; ATS 2021; Globecom2021 CISS;CBD2021;
  • 2022: ISCAS 2022;Globecom2022 CISS; CVPR 2022; ECCV 2022; ATS 2022; CBD2022; 3rd CSIG ChinaMFS 2022;
  • 2023: CVPR 2023;ICCV2023; Globecom 2023; ICCSI 2023; ATS2023;AsianHOST2023; CBD2023;
  • 2024: CVPR 2024; ISCAS 2024; ECCV 2024; ACCV 2024; AsianHOST 2024; Globecom 2024;




1. 卞荣臻,已毕业:1)以一作或二作发表2篇SCI,3篇EI,1项专利;2)获研究生一等奖学金;3)三好研究生;4)科研创新个人奖。

2. 袁成翔,已毕业:1)获校优秀硕士学位论文;2)以一作或二作发表4篇SCI,1篇EI,1项专利,另有1篇SCI在审;3)获研究生二等奖学金。

3. 何灿,已毕业:1)获校优秀硕士学位论文;2)以1作或2作或3作发表6篇SCI(1篇CCF A类,2篇CCF B类,3篇CCF C类),3篇会议(2篇CCF C类,1篇ACM会议),另有2篇SCI在审;3)研究生一等奖学金;4)三好研究生;5)科研创新个人奖;6)硕士学位论文送审得分为95、93分.



1. 吴至禹,已毕业:2项发明专利;3篇SCI论文,1篇CCF C类论文;保送浙江大学研究生;

2. 王谢燕,已毕业:1项发明专利;科创结题优秀,获学院科创二等奖;保送中国科学技术大学研究生。


