Di Ming

dblp:150/2488 · DBLP profile ↗
← Back
11ranked-venue papers
4as first author
9since 2021 · last 2026
0009-0009-7845-4487ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 10 · 4 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 3 first-author · 4 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
3 papers
Security and privacy of machine learning · 100%
Artificial intelligence
4 papers
Trustworthy machine learning · 70% Probabilistic and Bayesian machine learning · 12% Representation and self-supervised learning · 12%
Theoretical computer science
1 paper
Mathematical optimization · 100%

Topics — the 11 heaviest of 13, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Security and privacy of machine learning
adversarial attack
2.332025
SMP-Attack: Boosting the Transferability of Feature Importance-Based Adversarial Attack with Semantics-Aware Multi-Granularity Patchout · ICCV 2025
Transferable Structural Sparse Adversarial Attack Via Exact Group Sparsity Training · CVPR 2024
TRM-UAP: Enhancing the Transferability of Data-Free Universal Adversarial Perturbation via Truncated Ratio Maximization · ICCV 2023
Security and privacy of machine learning › adversarial attack
transferable adversarial attack
2.332025
SMP-Attack: Boosting the Transferability of Feature Importance-Based Adversarial Attack with Semantics-Aware Multi-Granularity Patchout · ICCV 2025
Transferable Structural Sparse Adversarial Attack Via Exact Group Sparsity Training · CVPR 2024
TRM-UAP: Enhancing the Transferability of Data-Free Universal Adversarial Perturbation via Truncated Ratio Maximization · ICCV 2023
Machine learning › Trustworthy machine learning › robustness
adversarial attack
0.812024
Boosting the Transferability of Adversarial Attack on Vision Transformer with Adaptive Token Tuning · NeurIPS 2024
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
0.812024
Boosting the Transferability of Adversarial Attack on Vision Transformer with Adaptive Token Tuning · NeurIPS 2024
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial transferability
0.812024
Boosting the Transferability of Adversarial Attack on Vision Transformer with Adaptive Token Tuning · NeurIPS 2024
Security and privacy of machine learning › adversarial attack › adversarial example generation
sparse adversarial attack
0.812024
Transferable Structural Sparse Adversarial Attack Via Exact Group Sparsity Training · CVPR 2024
Security and privacy of machine learning › adversarial attack › adversarial perturbation
universal adversarial perturbation
0.712023
TRM-UAP: Enhancing the Transferability of Data-Free Universal Adversarial Perturbation via Truncated Ratio Maximization · ICCV 2023
Machine learning › Representation and self-supervised learning › representation learning › dimensionality reduction
feature selection
0.412019
Robust Flexible Feature Selection via Exclusive L21 Regularization · IJCAI 2019
Mathematical optimization › statistical estimation › regression › sparse regression
lasso
0.412019
A Probabilistic Derivation of LASSO and L12-Norm Feature Selections · AAAI 2019
Mathematical optimization
sparse optimization
0.412019
A Probabilistic Derivation of LASSO and L12-Norm Feature Selections · AAAI 2019
Computer vision › Image recognition and object detection
image classification
0.212024
Transferable Structural Sparse Adversarial Attack Via Exact Group Sparsity Training · CVPR 2024

Methods — techniques the papers use, named apart from their topics

masked quantization · 1.5group sparsity training · 1.5generative model · 1.5semantics-aware multi-granularity patchout · 0.9self-paced learning · 0.8probabilistic derivation · 0.8lasso · 0.8l2,1-norm · 0.8l1,2-norm · 0.8gradient rescaling · 0.8adaptive token tuning · 0.8truncated ratio maximization · 0.7curriculum optimization · 0.7
YearPublicationVenuePosition
2026 DarkCORE: Efficient low-light object detection via collaborative reflectance denoising and object-oriented feature enhancement
Xin Feng 0007, Junxian Zeng, Di Ming
Expert Syst. Appl.5
2026 Enhancing the transferability and imperceptibility of adversarial attacks via rescaled variance-reduced diffusion
Di Ming
Vis. Comput.5
2025 SMP-Attack: Boosting the Transferability of Feature Importance-Based Adversarial Attack with Semantics-Aware Multi-Granularity Patchout
Di Ming
ICCV3
2025 Deep Robust Data Reconstruction via Smoothed L1-Autoencoder and Layerwise Sparse Group Lasso
abstract
Compared to conventional linear and low-rank methods, autoencoders demonstrate remarkable capabilities for learning latent feature representations in an unsupervised manner. However, existing approaches, despite improvements through regularization techniques or loss modifications, often remain prone to overfitting on noisy data, thereby limiting their robustness and effectiveness in data reconstruction. Thus, in this paper, we propose a novel deep robust data reconstruction method, dubbed as SL1AE-LSGLasso, to address the challenges of modeling in complex noisy environments. Motivated by the presence of the black spot problem, we first introduce the smoothed L1-autoencoder (SL1AE) network. To enhance model robustness and enable flexible sparsity control, we further propose a layerwise sparse group lasso (LSGLasso) regularization to effectively capture complex nonlinear structures. Building on this, we develop an efficient proximal optimization algorithm to solve the robust data reconstruction problem with composite sparsity-inducing term. Extensive experiments conducted on multiple benchmark datasets validate the effectiveness of the proposed SL1AE-LSGLasso method and its proximal optimization algorithm. In comparison with state-of-the-art methods, our approach improves the performance significantly in data reconstruction and downstream clustering tasks.1
Di Ming
IJCNN3
2025 STFormer: An efficient visual Transformer model with sparse attention and adaptive token aggregation
Xin Feng 0007, Di Ming
Pattern Recognit. Lett.4
2024 Transferable Structural Sparse Adversarial Attack Via Exact Group Sparsity Training
abstract
Deep neural networks (DNNs) are vulnerable to highly transferable adversarial attacks. Especially, many studies have shown that sparse attacks pose a significant threat to DNNs on account of their exceptional imperceptibility. Cur-rent sparse attack methods mostly limit only the magnitude and number of perturbations while generally overlooking the location of the perturbations, resulting in decreased performances on attack transferability. A subset of studies indicates that perturbations existing in the significant regions with rich classification-relevant features are more effective. Leveraging this insight, we introduce the structural sparsity constraint in the framework of generative models to limit the perturbation positions. To ensure that the perturbations are generated towards classification-relevant regions, we propose an exact group sparsity training method to learn pixel-level and group-level sparsity. For purpose of improving the effectiveness of sparse training, we further put forward masked quantization network and multi-stage optimization algorithm in the training process. Utilizing CNNs as sur-rogate models, extensive experiments demonstrate that our method has higher transferability in image classification attack compared to state-of-the-art methods at approximately same sparsity levels. In cross-model ViT, object detection, and semantic segmentation attack tasks, we also achieve a better attack success rate. Code is available at https://github.com/MisterRpeng/EGS-TSSA.
Di Ming
CVPR1
2024 Boosting the Transferability of Adversarial Attack on Vision Transformer with Adaptive Token Tuning
abstract
Vision transformers (ViTs) perform exceptionally well in various computer vision tasks but remain vulnerable to adversarial attacks. Recent studies have shown that the transferability of adversarial examples exists for CNNs, and the same holds true for ViTs. However, existing ViT attacks aggressively regularize the largest token gradients to exact zero within each layer of the surrogate model, overlooking the interactions between layers, which limits their transferability in attacking black-box models. Therefore, in this paper, we focus on boosting the transferability of adversarial attacks on ViTs through adaptive token tuning (ATT). Specifically, we propose three optimization strategies: an adaptive gradient re-scaling strategy to reduce the overall variance of token gradients, a self-paced patch out strategy to enhance the diversity of input tokens, and a hybrid token gradient truncation strategy to weaken the effectiveness of attention mechanism. We demonstrate that scaling correction of gradient changes using gradient variance across different layers can produce highly transferable adversarial examples. In addition, introducing attentional truncation can mitigate the overfitting over complex interactions between tokens in deep ViT layers to further improve the transferability. On the other hand, using feature importance as a guidance to discard a subset of perturbation patches in each iteration, along with combining self-paced learning and progressively more sampled attacks, significantly enhances the transferability over attacks that use all perturbation patches. Extensive experiments conducted on ViTs, undefended CNNs, and defended CNNs validate the superiority of our proposed ATT attack method. On average, our approach improves the attack performance by 10.1% compared to state-of-the-art transfer-based attacks. Notably, we achieve the best attack performance with an average of 58.3% on three defended CNNs. Code is available at https://github.com/MisterRpeng/ATT.
Di Ming
NeurIPS1
2024 Label-aware Dual-view Graph Neural Network for Protein-Protein Interaction Classification
Xiaofei Zhu, Yanyan Lan, Xiaoyang Liu 0001, Di Ming
Expert Syst. Appl.6
2023 TRM-UAP: Enhancing the Transferability of Data-Free Universal Adversarial Perturbation via Truncated Ratio Maximization
abstract
Aiming at crafting a single universal adversarial perturbation (UAP) to fool CNN models for various data samples, universal attack enables a more efficient and accurate evaluation for the robustness of CNN models. Early universal attacks craft UAPs depending on data priors. For more practical applications, the data-free universal attacks that make UAPs from random noises have aroused much attention recently. However, existing data-free UAP methods perturb all the CNN feature layers equally via the maximization of the CNN activation, leading to poor transferability. In this paper, we propose a novel datafree universal attack without depending on any real data samples through truncated ratio maximization, which we term as TRM-UAP. Specifically, different from the maximization of the positive activation in convolution layers, we propose to optimize the UAP generation from the ratio of positive and negative activations. To further enhance the transferability of universal attack, TRM-UAP not only performs the ratio maximization merely on low-level generic features via the truncation strategy, but also incorporates a curriculum optimization algorithm that can effectively learn the diversity of artificial images. Extensive experiments on the ImageNet dataset verify that TRMUAP achieves a state-of-the-art average fooling rate and excellent transferability on different CNN models as compared to other data-free UAP methods. Code is available at https://github.com/RandolphCarter0/TRMUAP.
Di Ming
ICCV5
2019 A Probabilistic Derivation of LASSO and L12-Norm Feature Selections
abstract
LASSO and ℓ2,1-norm based feature selection had achieved success in many application areas. In this paper, we first derive LASSO and ℓ1,2-norm feature selection from a probabilistic framework, which provides an independent point of view from the usual sparse coding point of view. From here, we further propose a feature selection approach based on the probability-derived ℓ1,2-norm. We point out some inflexibility in the standard feature selection that the feature selected for all different classes are enforced to be exactly the same using the widely used ℓ2,1-norm, which enforces the joint sparsity across all the data instances. Using the probabilityderived ℓ1,2-norm feature selection, allowing certain flexibility that the selected features do not have to be exactly same for all classes, the resulting features lead to better classification on six benchmark datasets.
Di Ming, Chris Ding, Feiping Nie 0001
AAAI1
2019 Robust Flexible Feature Selection via Exclusive L21 Regularization
abstract
Recently, exclusive lasso has demonstrated its promising results in selecting discriminative features for each class. The sparsity is enforced on each feature across all the classes via L12-norm. However, the exclusive sparsity of L12-norm could not screen out a large amount of irrelevant and redundant noise features in high-dimensional data space, since each feature belongs to at least one class. Thus, in this paper, we introduce a novel regularization called "exclusive L21", which is short for "L21 with exclusive lasso", towards robust flexible feature selection. The exclusive L21 regularization is the mix of L21-norm and L12-norm, which brings out joint sparsity at inter-group level and exclusive sparsity at intra-group level simultaneously. An efficient augmented Lagrange multipliers based optimization algorithm is proposed to iteratively solve the exclusive L21 regularization in a row-wise fashion. Extensive experiments on twelve benchmark datasets demonstrate the effectiveness of the proposed regularization and the optimization algorithm as compared to state-of-the-arts.
Di Ming, Chris Ding
IJCAI1