VLDB 2026 Research / reviewers in the wild / expert
Tao Wang 0084
dblp:12/5838-84
· DBLP profile ↗
16ranked-venue papers
3as first author
16since 2021 · last 2026
0000-0001-5532-3999ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 1 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 2 first-author · 5 since 2021Artificial intelligence and machine learning · 4 · 4 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Make Identity Indistinguishable: Utility-Preserving Face Dataset Publication With Provable Privacy GuaranteesabstractWith the popularity of personal devices, there are abundant valuable face image datasets in the industry, which provides opportunities for the development of visual models. However, privacy concerns related to identity sensitive information hinder face datasets sharing. Despite existing works dedicated to removing identity sensitive information from images, they either lack provable privacy guarantees or compromise crucial face dataset utilities, e.g., identity correlation and image naturalness. To overcome these weaknesses, we propose a novel face dataset publication scheme that protects face images by obfuscating face features. The obfuscated features still retain a certain level of correlation, allowing the protected dataset to be used for training. In the process of obfuscating the features, we design a novel metric differential privacy mechanism, which can enhance the correlation between features while ensuring privacy. Furthermore, we construct a latent diffusion model with identity and attribute as inputs to improve the naturalness of generated images. Extensive experimental results and theoretical analysis demonstrate our scheme significantly outperforms existing works in providing privacy protection while maintaining high dataset utility for downstream tasks. Yushu Zhang 0001, Junhao Ji, Tao Wang 0084, Wenying Wen, Yong Xiang 0001 |
IEEE Trans. Pattern Anal. Mach. Intell. | 3 |
| 2026 | Medical Archive in an Image: Generating a High-Capacity Customizable Cover Image for Medical Privacy ProtectionabstractThe rapid development of medical information technology promotes the popularization of telemedicine. With remote transmission of patient archives, medical institutions can provide more efficient diagnostic service. Because of the highly sensitive nature of medical data, medical archives typically require the support of encryption to prevent leakage of patient privacy. However, the encrypted archives visually appear as snowflake-like noise, which is easily perceived by an attacker and thus appealing to the crack. In this paper, we propose an imperceptible medical archive construction scheme, which can hide personal medical data in a high-capacity customizable cover image, thus making it impossible for attackers to perceive its presence. Specifically, we first conduct a fusion of multimodal medical image data, integrating image information from various imaging techniques into a unified image, thereby enhancing diagnostic efficacy. Secondly, a high-capacity customizable cover image is generated based on the patient facial mask. Lastly, the unified image with patient demographic information is hidden in the cover image to construct the imperceptible medical archive. To enhance the hiding capacity of the cover image, we propose a Collaborative Steganography Generation Model (CSGM), which increases the low-frequency components during image synthesis, enabling more data to be embedded while maintaining high visual quality. CSGM also supports identity-aware customization using facial structure and semantic text. Experiments show that CSGM improves the PSNR of stego images by 6.95 dB and the PSNR of recovered secret images by 2.98 dB compared to state-of-the-art methods, confirming its effectiveness in imperceptibility and data recovery. Wenying Wen, Zhouxin Wu, Yushu Zhang 0001, Tao Wang 0084, Xiangli Xiao, Yuming Fang 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Detecting Malicious Concepts Without Image Generation in AI-Generated Content (AIGC)abstractThe task of text-to-image generation has achieved tremendous success in practice, with emerging concept generation models capable of producing highly personalized and customized content. Fervor for concept generation is increasing rapidly among users, and platforms for concept sharing have sprung up. The concept owners may upload malicious concepts and disguise them with non-malicious text descriptions and example images to deceive users into downloading and generating malicious content. The platform needs a quick method to determine whether a concept is malicious to prevent the spread of malicious concepts. However, simply relying on concept image generation to judge whether a concept is malicious requires time and computational resources. Especially, as the number of concepts uploaded and downloaded on the platform continues to increase, this approach becomes impractical and poses a risk of generating malicious content. In this paper, we propose Concept QuickLook, the first systematic work to incorporate malicious concept detection into research, which performs detection based solely on concept files without generating any images. We define malicious concepts and design two operational modes for detection: concept matching and fuzzy detection. Extensive experiments demonstrate that the proposed Concept QuickLook can detect malicious concepts and demonstrate practicality in concept sharing platforms. We also design robustness experiments to further validate the effectiveness of the solution. We hope this work can initiate malicious concept detection tasks and provide some inspiration. Kun Xu 0019, Wenying Wen, Tao Wang 0084, Yushu Zhang 0001, Yuming Fang 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2025 | Privacy-preserving face attribute classification via differential privacy
Tao Wang 0084, Junhao Ji, Yushu Zhang 0001, Rushi Lan |
Neurocomputing | 2 |
| 2025 | Controllable facial protection against malicious translation-based attribute editing
Yiyi Xie, Yuqian Zhou, Tao Wang 0084, Zhongyun Hua, Wenying Wen, Yushu Zhang 0001 |
Knowl. Based Syst. | 3 |
| 2025 | A Comprehensive Image Protection Framework Based on High-Capacity Adversarial Data HidingabstractIn recent years, a large number of personal images have been uploaded to social network platforms, contributing to the formation of image Big Data. These images are vulnerable to security threats, e.g., privacy inference, copyright infringement, and malicious tampering. Many image protection methods have been proposed, e.g., privacy protection methods based on adversarial perturbations, and copyright protection methods based on data hiding. However, these methods can only deal with a single security threat causing the image to suffer from residual threats. Therefore, this paper proposes a comprehensive image protection framework, which generates adversarial examples by embedding meaningful perturbations, achieving image privacy protection while protecting copyright and integrity by data hiding. In this framework, we design a novel high-capacity adversarial data hiding model (HADH) to support adversarially embedding of adequate robust watermarking for copyright protection and fragile watermarking for integrity protection. Experimental results show that HADH achieves a high embedding rate of 3.21 Reed-Solomon bits per pixel (RS-bpp), providing sufficient capacity for copyright and identity verification information. The capacity is even higher than other pure robust steganography schemes. In addition, the privacy protection performance is better than the existing adversarial attack-based privacy protection methods. Ming Li 0029, Tao Wang 0084, Yushu Zhang 0001, Wenying Wen |
IEEE Trans. Big Data | 3 |
| 2025 | Tailor-Made Face Privacy Protection via Class-Wise Targeted Universal Adversarial PerturbationsabstractThe widespread application of face recognition poses unprecedented threats to individual privacy, as face images can be easily and stealthily analyzed. Efforts have been made to employ adversarial perturbations to disrupt the automatic inference of unauthorized face recognition systems. However, existing schemes fail to satisfy the personalized protection requirements of individuals, which may diminish the user experience. In this paper, we propose a novel scheme that provides tailor-made face privacy protection for individuals via class-wise targeted universal adversarial perturbations (CT-UAPs). In our scheme, each individual can utilize a user-specific CT-UAP to exclusively generate protected faces whose identification outputs are a virtual identity predefined by themselves. For the generation of CT-UAPs, we develop an optimization-based method that guides the feature vectors of the protected faces to approach the class-wise feature space of the predefined virtual identity while simultaneously approaching that of the original identity. Extensive experiment results demonstrate the effectiveness of our scheme against five face recognition models. In addition, the interpretability of CT-UAPs is highlighted by the experimental results obtained through two-dimensional principal component analysis. Yushu Zhang 0001, Zixuan Yang 0004, Tao Wang 0084, Zhongyun Hua, Jian Weng 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Beyond Privacy: Generating Privacy-Preserving Faces Supporting Robust Image AuthenticationabstractThe prevalence of face capturing along with the advancement of face recognition poses a potential threat to individual privacy. To protect privacy, plenty of methods have been proposed to change identity in the face, thus blocking malicious face recognition. However, these methods fail to satisfy authentication requirements for special application scenarios, e.g., face authentication in surveillance capture. In this paper, we propose a novel face privacy protection model, which supports robust image authentication via information-conditional identity transformation. Specifically, we first introduce a basic face manipulation model (FMM), which can preserve identity-irrelevant attributes when manipulating identity. Based on FMM, we further design a lightweight protector called AIDPro, outputting a transformed identity which is different from the original one and is embedded a message presenting authentication information. Benefiting from the semantic robustness, our model does not require noise layers to achieve accurate message extraction after various image distortions. In addition, the message can be the condition to guide the identity transformation for privacy protection, which avoids extra resource consumption from supporting image authentication. Extensive experimental results demonstrate our model has comparable privacy protection performance, superior attribute preservation performance, and robust authentication performance especially in JPEG compression and screen shooting. Our code is available athttps://github.com/daizigege/AIDPro. Tao Wang 0084, Wenying Wen, Xiangli Xiao, Zhongyun Hua, Yushu Zhang 0001, Yuming Fang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Make Privacy Renewable! Generating Privacy-Preserving Faces Supporting Cancelable Biometric Recognition
Tao Wang 0084, Yushu Zhang 0001, Xiangli Xiao, Lin Yuan 0002, Zhihua Xia, Jian Weng 0001 |
ACM Multimedia | 1 |
| 2024 | Once-for-all: Efficient Visual Face Privacy Protection via Person-specific VeilsabstractAs billions of face images stored on cloud platforms contain sensitive information to human vision, the public confronts substantial threats to visual face privacy. In response, the community has proposed some perturbation-based schemes to mitigate visual privacy leakage. However, these schemes need to generate a new protective perturbation for each image, failing to satisfy the real-time requirement of cloud platforms. To address this issue, we present an efficient visual face privacy protection scheme by utilizing person-specific veils, which can be conveniently applied to all images of the same user without regeneration. The protected images exhibit significant visual differences from the originals but remain identifiable to face recognition models. Furthermore, the protected images can be recovered to originals under certain circumstances. In the process of generating the veils, we propose a feature alignment loss to promote consistency between the recognition outputs of protected and original images with approximate construction of feature subspace. Meanwhile, the block variance loss is designed to enhance the concealment of visual identity information. Extensive experimental results demonstrate that our scheme can significantly eliminate the visual appearance of original images and almost has no impact on face recognition models. Zixuan Yang 0004, Yushu Zhang 0001, Tao Wang 0084, Zhongyun Hua, Zhihua Xia, Jian Weng 0001 |
ACM Multimedia | 3 |
| 2024 | Reversible gender privacy enhancement via adversarial perturbations
Yiyi Xie, Yuqian Zhou, Tao Wang 0084, Wenying Wen, Yushu Zhang 0001 |
Neural Networks | 3 |
| 2024 | Utility-Enhanced Image Obfuscation With Block Differential PrivacyabstractWith the popularity of cloud servers, an increasing number of people utilize cloud platforms to manage their images. Images uploaded to the cloud are no longer directly controlled by the owner, which has raised concerns among users about privacy leakage. In response, some thumbnail-preserving encryption methods have been proposed to protect image privacy. However, since privacy lacks a clear definition, these methods face challenges in quantifying privacy, making it difficult for users to assess the effectiveness of privacy protection. To address this issue, we propose an image obfuscation method based on novel differential privacy mechanism, which provides provable privacy protection while preserving thumbnails. Additionally, our method can maintain the consistency of image distributions to enhance the utility of protected images. Extensive experimental results demonstrate that our method significantly outperforms existing work in terms of privacy and utility. Junhao Ji, Tao Wang 0084, Youwen Zhu |
IEEE Signal Process. Lett. | 3 |
| 2024 | Dual Protection for Image Privacy and Copyright via Traceable Adversarial ExamplesabstractIn recent years, the uploading of massive personal images has increased the security risks, mainly including privacy breaches and copyright infringement. Adversarial examples provide a novel solution for protecting image privacy, as they can evade the detection by deep neural network (DNN)-based recognizers. However, the perturbations in the adversarial examples typically meaningless and therefore cannot be extracted as traceable information to support copyright protection. In this paper, we designed a dual protection scheme for image privacy and copyright via traceable adversarial examples. Specifically, a traceable adversarial model is proposed, which can be used to embed the invisible copyright information into images for copyright protection while fooling DNN-based recognizers for privacy protection. Inspired by the training method of generative adversarial networks (GANs), a new dynamic adversarial training strategy is designed, which allows our model for achieving stable multi-objective learning. Experimental results show that our scheme is exceptionally robust in the face of a variety of noise conditions and image processing methods, while exhibiting good model migration and defense robustness. Ming Li 0029, Zhaohui Yang 0001, Tao Wang 0084, Yushu Zhang 0001, Wenying Wen |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2023 | Identifiable Face Privacy Protection via Virtual Identity TransformationabstractMassive face images collected in smart surveillance and social networks are vulnerable to malicious access, thus compromising individual privacy. Existing schemes have been able to protect face privacy while preserving a certain level of identifiability, but have different limitations, e.g., the lack of strong transferability or the inability to retain irrelevant attributes. This letter proposes a novel face privacy protection scheme via virtual identity transformation, which guarantees strong privacy protection and high identifiability. We first solve a specific identity mask for the user, which ensures that the identity features extracted only from the user's faces can be approximated to the given virtual identity. Based on it, the identity transformation networks transform the original face into the protected form, which belongs to the virtual identity while retaining irrelevant attributes. Lastly, the virtual identity of the protected face is extracted for face recognition. Adequate experiments show that our scheme has satisfactory privacy protection, high identifiability, and strong transferability. Tao Wang 0084, Yushu Zhang 0001, Wenying Wen, Rushi Lan |
IEEE Signal Process. Lett. | 1 |
| 2023 | RAPP: Reversible Privacy Preservation for Various Face AttributesabstractThe tremendous progress in deep learning has enabled to extract soft-biometric attributes from faces, which raises privacy concerns over images collected for face recognition. Advances toward attribute privacy have been able to conceal multiple attributes while preserving identity information but suffer from limitations: they 1) only consider a few soft-biometric attributes and 2) fail to support reversibility for attribute privacy preservation. To break these limitations, we design a reversible privacy-preserving scheme for various face attributes, called reversible attribute privacy preservation (RAPP). RAPP benefits from two modules: 1) The attribute obfuscator introduces a stream cipher to determine that special attributes have to be concealed with the user-defined password, which also supports recovering original attributes. 2) The attribute adversarial network is proposed to generate perturbed images that conceal various attributes while retaining the utility of face verification. In addition, when a wrong password is provided, the returned image with wrong attribute classification results still keeps realistic, which confuses an attacker to know whether the recovery is correct. Extensive experiments demonstrate that RAPP enables to conceal various attributes and recover original images while facilitating face verification. Yushu Zhang 0001, Tao Wang 0084, Wenying Wen, Youwen Zhu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2021 | A novel deep recommend model based on rating matrix and item attributes
Yuanjun Liu 0001, Tao Wang 0084, Liangmin Guo, Xiaoyao Zheng, Yonglong Luo |
J. Intell. Inf. Syst. | 4 |