Jianan Feng

dblp:09/743 · also Jia-Nan Feng · DBLP profile ↗
← Back
7ranked-venue papers
3as first author
7since 2021 · last 2025
0000-0002-6701-2730ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Fight Fire with Fire: Combating Adversarial Patch Attacks using Pattern-randomized Defensive Patches
abstract
Object detection has found extensive applications in various tasks, but it is also susceptible to adversarial patch attacks. The ideal defense should be effective, efficient, easy to deploy, and capable of withstanding adaptive attacks. In this paper, we adopt a counterattack strategy to propose a novel and general methodology for defending adversarial attacks. Two types of defensive patches, canary and woodpecker, are specially-crafted and injected into the model input to proactively probe or counteract potential adversarial patches. In this manner, adversarial patch attacks can be effectively detected by simply analyzing the model output, without the need to alter the target model. Moreover, we employ randomized canary and woodpecker injection patterns to defend against defense-aware attacks. The effectiveness and practicality of the proposed method are demonstrated through comprehensive experiments. The results illustrate that canary and woodpecker achieve high performance, even when confronted with unknown attack methods, while incurring limited time overhead. Furthermore, our method also exhibits sufficient robustness against defense-aware attacks, as evidenced by adaptive attack experiments.
Jianan Feng, Changqing Miao, Jianjun Huang 0001, Wei You 0001, Wenchang Shi, Bin Liang 0002
SP1
2025 We Can Always Catch You: Detecting Adversarial Patched Objects WITH or WITHOUT Signature
abstract
Recently, object detection has proven vulnerable to adversarial patch attacks. The attackers holding a specially crafted patch can hide themselves from state-of-the-art detectors, e.g., YOLO, even in the physical world. This attack can bring serious security threats, such as escaping from surveillance cameras. How to effectively detect this kind of adversarial examples to catch potential attacks has become an important problem. In this paper, we propose two detection methods: the signature-based method and the signature-independent method. First, we identify two signatures of existing adversarial patches that can be utilized to precisely locate patches within adversarial examples. By employing the signatures, a fast signature-based method is developed to detect the adversarial objects. Second, we present a robust signature-independent method based on thecontent semantics consistencyof model outputs. Adversarial objects violate this consistency, appearing locally but disappearing globally, while benign ones remain consistently present. The experiments demonstrate that two proposed methods can effectively detect attacks both in the digital and physical world. These methods each offer distinct advantage. Specifically, the signature-based method is capable of real-time detection, while the signature-independent method can detect unknown adversarial patch attacks and makes defense-aware attacks almost impossible to perform.
Jianan Feng, Jianjun Huang 0001, Bin Liang 0002
IEEE Trans. Dependable Secur. Comput.2
2023 A Good Fishman Knows All the Angles: A Critical Evaluation of Google's Phishing Page Classifier
abstract
Phishing is one of the most popular cyberspace attacks. Phishing detection has been integrated into mainstream browsers to provide online protection. The phishing detector of Google Chrome reports millions of phishing attacks per week. However, it has been proven to be vulnerable to evasion attacks. Currently, Google has upgraded Chrome/Chromium's phishing detector, introducing a CNN-based image classifier. The robustness of the new-generation detector is unclear. If it can be bypassed, its billions of users will be exposed to sophisticated attackers. This paper presents a critical evaluation of Google's phishing detector by targeted evasion testing, and investigates corresponding defensive techniques. First, we propose a three-stage evasion method against the phishing image classifier. The experiments show that it can be completely bypassed with adversarial phishing pages generated using the proposed method. Meanwhile, the phishing pages still preserve their visual utility. Second, we introduce two defense techniques to enhance the phishing detection model. The results show that even using lightweight defense methods can significantly improve the model robustness. Our research reveals that Google's new-generation phishing classifier is very vulnerable to targeted evasion attacks. A sophisticated phishers can know how to fool the classifier. Billions of Chrome users are being exposed to potential phishing attacks. To improve its robustness, necessary security enhancements should be introduced.
Changqing Miao, Jianan Feng, Wei You 0001, Wenchang Shi, Jianjun Huang 0001, Bin Liang 0002
CCS2
2022 CASR-Net: A color-aware super-resolution network for panchromatic image
Ling Liu 0010, Xin Jin 0005, Jianan Feng, Ruxin Wang 0002, Hangying Liao, Shin-Jye Lee, Shaowen Yao 0001
Eng. Appl. Artif. Intell.4
2022 A Deep Multitask Convolutional Neural Network for Remote Sensing Image Super-Resolution and Colorization
abstract
Remote sensing data have become increasingly vital in target detection, disaster monitoring, and military surveillance. Abundant pan-sharpening and super-resolution (SR) methods based on deep learning have been proposed and have achieved remarkable performance. However, pan-sharpening requires paired panchromatic (PAN) and multispectral (MS) images, and SR cannot increase the spectral resolution of PAN. Thus, we introduce a computational imaging-based method to recover or produce the incomplete data of single PAN or MS. This work also explores the integration of multiple tasks by a single neural network. We start with SR and colorization, study the feasibility of simultaneously finishing SR colorization, and use a model trained in SR colorization to finish pan-sharpening without MS. A generic neural network, remote sensing image improvement network (RSI-Net), is designed for remote sensing image SR, colorization, simultaneous SR colorization, and pan-sharpening. To verify its performance, RSI-Net is compared with the state-of-the-art SR and colorization methods. Experiments show that RSI-Net can be competitive in visual effects and evaluation indexes, and it performs well at simultaneous SR colorization, and RSI-Net finishes pan-sharpening and only needs to input PAN. Our experiments confirm the effect of integrating multiple tasks.
Jianan Feng, Ching-Hsun Tseng, Xin Jin 0005, Ling Liu 0010, Wei Zhou 0011, Shaowen Yao 0001
IEEE Trans. Geosci. Remote. Sens.1
2021 Data Privacy Protection based on Feature Dilution in Cloud Services
abstract
Machine learning as a service (MLaaS) brings many benefits to people's daily life. However, the service mode of MLaaS will increase the risk of users' privacy leakage. Existing works focusing on privacy-preserving based on encryption, differential privacy, and distributed framework require high computing resources or cannot be applied in MLaaS. In this paper, we propose feature dilution (FD), a noise-based desensitization algorithm to remove sensitive information in raw data. In particular, FD continuously adds raw data features to the random noise until it meets the minimum amount for an effective query, and we call this noise weak-feature noise (WFN). By fine-tuning the MLaaS architecture, we have realized that users can utilize WFN to get normal services without exposing their local private data. Meanwhile, noise addition technology is introduced by us to reduce the risk of privacy leakage caused by “weak features”. Extensive experiments have demonstrated that users can use FD to obtain effective services without exposing their private data. Finally, we conducted practical tests on weak-feature noises and found that these noises are difficult to use by malicious service providers.
Lei Cui 0006, Jianan Feng, Liwen Wu, Shaowen Yao 0001, Shui Yu 0001
GLOBECOM3
2021 CSRDNN: An Integrated Scheme for Single Satellite Image Colorization and Super-Resolution Using Deep Neural Networks
abstract
Deep convolutional neural networks have respectively achieved significant success in image super-resolution and colorization. The DNN has a strong capability to generate high quality images. Both colorization and super-resolution (SR) can be regarded as an independent pixel mapping problem, and this work combines these two visual problems into an integrated task. In this work, we propose an end-to-end model for accomplishing single satellite image colorization and SR simultaneously. Our model comprises two phases: features extraction network and recovery network. First, the residual receptive field block structure is introduced in features extraction network to learn better feature representations for image colorization and SR. Residual Receptive Field Block(RRFB) is improved by expanding the receptive field and enhancing the context connection from inception model. Second, the extracted features are transformed to a color high-resolution image by a recovery architecture. In this work, U-net is employed as the key structure of the recovery architecture. Besides, the squeeze-and-excitation blocks and complex residual blocks are incorporated into the proposed model to increase the reconstruction performance. To verify the performance, our method is compared with the state-of-the-art methods of SR and colorization. The experiments show that proposed method can get competitive in visual effect and evaluation index compared with the existing methods. In the end, the panchromatic dataset is also used to validate our model, and a good color high-resolution image can be obtained by giving a gray and low-resolution panchromatic image.
Jianan Feng, Xin Jin 0005, Ching-Hsun Tseng, Shin-Jye Lee, Shaowen Yao 0001
IJCNN1