Wenjie Ruan

dblp:153/5200 · DBLP profile ↗
← Back
71ranked-venue papers
13as first author
43since 2021 · last 2026
0000-0002-8311-8738ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 44 · 6 first-author · 32 since 2021Graphics, computer vision, multimedia, augmented reality and games · 21 · 2 first-author · 17 since 2021Databases, data management, data science and information retrieval · 15 · 5 first-author · 7 since 2021Computer networks · 5 · 3 first-authorApplied, interdisciplinary, general and emerging computing · 5 · 5 since 2021Software engineering, systems software and programming languages · 4 · 2 since 2021Human-computer interaction and ubiquitous computing · 4 · 3 first-authorSystems, architecture and hardware · 2Security and privacy · 1 · 1 since 2021Theory of computation · 1
YearPublicationVenuePosition
2026 Fragile by Design: On the Limits of Adversarial Defenses in Personalized DreamBooth Generation
abstract
Personalized AI applications such as DreamBooth enable the generation of customized content from user images, but also raise significant privacy concerns, particularly the risk of facial identity leakage. Recent defense mechanisms like Anti-DreamBooth attempt to mitigate this risk by injecting adversarial perturbations into user photos to prevent successful personalization. However, we identify two critical yet overlooked limitations of these methods. First, the adversarial examples often exhibit perceptible artifacts such as conspicuous patterns or stripes, making them easily detectable as manipulated content. Second, the perturbations are highly fragile, as even a simple, non-learned filter can effectively remove them, thereby restoring the model's ability to memorize and reproduce user identity. To investigate this vulnerability, we propose a novel evaluation framework, AntiDB_Purify, to systematically evaluate existing defenses under realistic purification threats, including both traditional image filters and adversarial purification. Results reveal that none of the current methods maintains their protective effectiveness under such threats. These findings highlight that current defenses offer a false sense of security and underscore the urgent need for more imperceptible and robust protections to safeguard user identity in personalized generation.
Yi Zhang 0141, Xiangyu Yin 0001, Chengxuan Qin, Xingyu Zhao 0001, Xiaowei Huang 0001, Wenjie Ruan
AAAI7
2025 A Black-Box Evaluation Framework for Semantic Robustness in Bird's Eye View Detection
abstract
Camera-based Bird's Eye View (BEV) perception models receive increasing attention for their crucial role in autonomous driving, a domain where concerns about the robustness and reliability of deep learning have been raised. While only a few works have investigated the effects of randomly generated semantic perturbations, aka natural corruptions, on the multi-view BEV detection task, we develop a black-box robustness evaluation framework that adversarially optimises three common semantic perturbations: geometric transformation, colour shifting, and motion blur, to deceive BEV models, serving as the first approach in this emerging field. To address the challenge posed by optimising the semantic perturbation, we design a smoothed, distance-based surrogate function to replace the mAP metric and introduce SimpleDIRECT, a deterministic optimisation algorithm that utilises observed slopes to guide the optimisation process. By comparing with randomised perturbation and two optimisation baselines, we demonstrate the effectiveness of the proposed framework. Additionally, we provide a benchmark on the semantic robustness of ten recent BEV models. The results reveal that PolarFormer, which emphasises geometric information from multi-view images, exhibits the highest robustness, whereas BEVDet is fully compromised, with its precision reduced to zero.
Yanghao Zhang, Xiangyu Yin 0001, Zeyu Fu, Xiaowei Huang 0001, Wenjie Ruan
AAAI7
2025 Adversarial Training for Probabilistic Robustness
Yi Zhang 0141, Wenjie Ruan, Xiaowei Huang 0001, Siddartha Khastgir, Xingyu Zhao 0001
ICCV4
2025 FAP: A Foveation-Inspired Adversarial Purification Pipeline for Enhancing Robustness in Mammography Classification
abstract
Deep learning models for medical image analysis demonstrate remarkable diagnostic accuracy but remain highly vulnerable to adversarial perturbations. To address this challenge, we introduce Foveated Adversarial Purification (FAP), a biologically inspired preprocessing pipeline that integrates three core innovations. First, FAP employs eccentricity-adaptive separable Gaussian blurring, where kernel size dynamically adjusts with lesion morphology. This approach mimics the human fovea's acuity gradient, preserves high-frequency details around lesions while suppressing peripheral noise, and reduces GPU memory usage by 40% compared to conventional 2D filtering. Second, FAP introduces gradient-guided fixation sampling with sigmoid-clustered probability, which prioritizes lesion-dense regions consistent with radiologists' diagnostic scanpaths. This mechanism achieves 82% overlap with radiologist-annotated regions of interest, ensuring that preprocessing aligns with clinical saliency rather than arbitrary regions. Third, FAP implements lesion-aware adversarial training, where binary spatial masks confine perturbations to non-diagnostic regions. This preserves lesion fidelity while hardening the classifier against attacks, yielding a certified ℓ2radius of 1.12, exceeding prior defenses. Evaluated across three mammography datasets, FAP achieves substantial robustness improvements: +20.03% absolute accuracy on CMMD (coarse tumors), +16.39% on BREAST (mixed lesions), and maintains baseline performance on CBIS-DDSM (microcalcifications). By aligning computational robustness with biological vision strategies, FAP establishes a clinically interpretable and computationally efficient framework for adversarial defense in medical imaging. The implementation is released in our GitHub repository11https://github.com/ghazallalooha/FAP.
Ghazal Lalooha, Wenjie Ruan, Venus Haghighi, Xinshu Li 0001, Quan Z. Sheng
ICDM2
2025 FALCON: Fine-grained Activation Manipulation by Contrastive Orthogonal Unalignment for Large Language Model
abstract
Large language models have been widely applied, but can inadvertently encode sensitive or harmful information, raising significant safety concerns. Machine unlearning has emerged to alleviate this concern; however, existing training-time unlearning approaches, relying on coarse-grained loss combinations, have limitations in precisely separating knowledge and balancing removal effectiveness with model utility. In contrast, we propose $\textbf{F}$ine-grained $\textbf{A}$ctivation manipu$\textbf{L}$ation by $\textbf{C}$ontrastive $\textbf{O}$rthogonal u$\textbf{N}$alignment (FALCON), a novel representation-guided unlearning approach that leverages information-theoretic guidance for efficient parameter selection, employs contrastive mechanisms to enhance representation separation, and projects conflict gradients onto orthogonal subspaces to resolve conflicts between forgetting and retention objectives. Extensive experiments demonstrate that FALCON achieves superior unlearning effectiveness while maintaining model utility, exhibiting robust resistance against knowledge recovery attempts.
Jinwei Hu 0001, Zhenglin Huang, Xiangyu Yin 0001, Wenjie Ruan, Yi Dong 0002, Xiaowei Huang 0001
NeurIPS4
2025 Interpreting Safety: A LLM and STPA Approach
Shufeng Chen, Xiangyu Yin 0001, Wenjie Ruan, Siddartha Khastgir, Ji Ruan, Xingyu Zhao 0001, Xiaowei Huang 0001
PRICAI (4)4
2025 Verification on out-of-distribution detectors under natural perturbations
Peipei Xu, Geyong Min, Wenjie Ruan
Mach. Learn.5
2025 SCALA: Toward Imperceptible and Efficient Black-Box Textual Adversarial Perturbations
abstract
Deep learning models are intrinsically susceptible to textual adversarial attacks on social media, where the perturbed text can trigger aberrant behaviours of victim models and threaten security and privacy. In this paper, we present a novel word-level attack called SCALA: a Synonym-based desCending And repLace-back Ascending mechanism. Our focus is on the efficient production of adversarial examples, with a particular emphasis on minimizing human perceptibility while ensuring the visual resemblance and semantic correctness. The merits of our attacking solution lie in being:(i)imperceptible – it keeps a very low word perturbation rate based on the Hamming (L0-norm) distance, thus achieving heightened deceptiveness validated through human evaluations;(ii)efficient – our tensor-based parallelization strategy ensures the attacking efficiency compared with baselines;(iii)effective – it surpasses seven state-of-the-art attacks on five target models in terms of reducing after-attack accuracy;(iv)practical – black-box score-based setting ensures that the adversary only needs to query target models for confidence scores; and(v)transferable – our attack shows competitive transferability on the generated adversarial examples. We release our codeSCALAvia https://github.com/TrustAI/SCALA.
Achim D. Brucker, Jia Hu 0001, Xiaowei Huang 0001, Wenjie Ruan
IEEE Trans. Inf. Forensics Secur.5
2024 Reward Certification for Policy Smoothed Reinforcement Learning
abstract
Reinforcement Learning (RL) has achieved remarkable success in safety-critical areas, but it can be weakened by adversarial attacks. Recent studies have introduced ``smoothed policies" to enhance its robustness. Yet, it is still challenging to establish a provable guarantee to certify the bound of its total reward. Prior methods relied primarily on computing bounds using Lipschitz continuity or calculating the probability of cumulative reward being above specific thresholds. However, these techniques are only suited for continuous perturbations on the RL agent's observations and are restricted to perturbations bounded by the l2-norm. To address these limitations, this paper proposes a general black-box certification method, called ReCePS, which is capable of directly certifying the cumulative reward of the smoothed policy under various lp-norm bounded perturbations. Furthermore, we extend our methodology to certify perturbations on action spaces. Our approach leverages f-divergence to measure the distinction between the original distribution and the perturbed distribution, subsequently determining the certification bound by solving a convex optimisation problem. We provide a comprehensive theoretical analysis and run experiments in multiple environments. Our results show that our method not only improves the tightness of certified lower bound of the mean cumulative reward but also demonstrates better efficiency than state-of-the-art methods.
Ronghui Mu, Leandro Soriano Marcolino, Yanghao Zhang, Xiaowei Huang 0001, Wenjie Ruan
AAAI6
2024 Representation-Based Robustness in Goal-Conditioned Reinforcement Learning
abstract
While Goal-Conditioned Reinforcement Learning (GCRL) has gained attention, its algorithmic robustness against adversarial perturbations remains unexplored. The attacks and robust representation training methods that are designed for traditional RL become less effective when applied to GCRL. To address this challenge, we first propose the Semi-Contrastive Representation attack, a novel approach inspired by the adversarial contrastive attack. Unlike existing attacks in RL, it only necessitates information from the policy function and can be seamlessly implemented during deployment. Then, to mitigate the vulnerability of existing GCRL algorithms, we introduce Adversarial Representation Tactics, which combines Semi-Contrastive Adversarial Augmentation with Sensitivity-Aware Regularizer to improve the adversarial robustness of the underlying RL agent against various types of perturbations. Extensive experiments validate the superior performance of our attack and defence methods across multiple state-of-the-art GCRL algorithms. Our code is available at https://github.com/TrustAI/ReRoGCRL.
Xiangyu Yin 0001, Sihao Wu, Jiaxu Liu 0001, Xingyu Zhao 0001, Xiaowei Huang 0001, Wenjie Ruan
AAAI7
2024 Boosting Adversarial Training via Fisher-Rao Norm-Based Regularization
abstract
Adversarial training is extensively utilized to improve the adversarial robustness of deep neural networks. Yet, miti-gating the degradation of standard generalization performance in adversarial-trained models remains an open prob-lem. This paper attempts to resolve this issue through the lens of model complexity. First, We leverage the Fisher-Rao norm, a geometrically invariant metric for model complexity, to establish the non-trivial bounds of the Cross-Entropy Loss-based Rademacher complexity for a ReLU-activated Multi-Layer Perceptron. Then we generalize a complexity-related variable, which is sensitive to the changes in model width and the trade-off factors in adversarial training. Moreover, intensive empirical evidence validates that this variable highly correlates with the generalization gap of Cross-Entropy loss between adversarial-trained and standard-trained models, especially during the initial and final phases of the training process. Building upon this observation, we propose a novel regularization framework, called Logit-Oriented Adversarial Training (LOAT), which can mitigate the trade-off between robustness and accuracy while imposing only a negligible increase in computational overhead. Our extensive experiments demonstrate that the proposed regularization strategy can boost the performance of the prevalent adversarial training algorithms, including PGD-AT, TRADES, TRADES (LSE), MART, and DM-AT, across various network architectures. Our code will be available at https://github.com/TrustAI/LOAT.
Xiangyu Yin 0001, Wenjie Ruan
CVPR2
2024 Towards Fairness-Aware Adversarial Learning
abstract
Although adversarial training (AT) has proven effective in enhancing the model's robustness, the recently revealed issue of fairness in robustness has not been well addressed, i.e. the robust accuracy varies significantly among different categories. In this paper, instead of uniformly evaluating the model's average class performance, we delve into the issue of robust fairness, by considering the worst-case distribution across various classes. We propose a novel learning paradigm, named Fairness-Aware Adversarial Learning (FAAL). As a generalization of conventional AT, we redefine the problem of adversarial training as a min-max-max framework, to ensure both robustness and fairness of the trained model. Specifically, by taking advantage of distributional robust optimization, our method aims to find the worst distribution among different categories, and the solution is guaranteed to obtain the upper bound performance with high probability. In particular, FAAL can fine-tune an unfair robust model to be fair within only two epochs, without compromising the overall clean and robust accuracies. Extensive experiments on various image datasets validate the superior performance and efficiency of the proposed FAAL compared to other state-of-the-art methods.
Yanghao Zhang, Ronghui Mu, Xiaowei Huang 0001, Wenjie Ruan
CVPR5
2024 ProTIP: Probabilistic Robustness Verification on Text-to-Image Diffusion Models Against Stochastic Perturbation
Yi Zhang 0141, Yun Tang 0003, Wenjie Ruan, Xiaowei Huang 0001, Siddartha Khastgir, Paul A. Jennings, Xingyu Zhao 0001
ECCV (32)3
2024 DeepGRE: Global Robustness Evaluation of Deep Neural Networks
abstract
Robustness measurements on deep neural networks (DNNs) have gained significant attention, especially in safety-critical applications. Numerous studies have been devoted to assessing the robustness of classifiers by averaging local robustness over a fixed set of data samples, such as a test set. However, the local statistics may not provide an accurate representation of the actual global robustness over the entire underlying unknown data distribution. To address this challenge, this paper proposes a novel framework, namely DeepGRE, for global robustness estimates of adversarial perturbation in combination with generative models and existing local robustness evaluation methods. Besides, DeepGRE employs Quasi-Monte Carlo approach to produce estimates of global robustness with low variance, making the assessments more reliable and statistically sound, since randomness is introduced by all samples drawn from a generative model. From a theoretical perspective, this work naturally provides an upper bound between true global robustness and estimated global robustness based on Lipschitz continuity. Also, it derives a statistical guarantee on the difference between true and empirical estimates for sample complexity. Our code is available at https://github.com/TrustAI/DeepGRE.
Jiaxu Liu 0001, Yanghao Zhang, Ronghui Mu, Wenjie Ruan
ICASSP5
2024 Position: Building Guardrails for Large Language Models Requires Systematic Design
abstract
As Large Language Models (LLMs) become more integrated into our daily lives, it is crucial to identify and mitigate their risks, especially when the risks can have profound impacts on human users and societies. Guardrails, which filter the inputs or outputs of LLMs, have emerged as a core safeguarding technology. This position paper takes a deep look at current open-source solutions (Llama Guard, Nvidia NeMo, Guardrails AI), and discusses the challenges and the road towards building more complete solutions. Drawing on robust evidence from previous research, we advocate for a systematic approach to construct guardrails for LLMs, based on comprehensive consideration of diverse contexts across various LLMs applications. We propose employing socio-technical methods through collaboration with a multi-disciplinary team to pinpoint precise technical requirements, exploring advanced neural-symbolic implementations to embrace the complexity of the requirements, and developing verification and testing to ensure the utmost quality of the final product.
Yi Dong 0002, Ronghui Mu, Gaojie Jin, Jinwei Hu 0001, Xingyu Zhao 0001, Wenjie Ruan, Xiaowei Huang 0001
ICML8
2024 PRASS: Probabilistic Risk-averse Robust Learning with Stochastic Search
Yanghao Zhang, Ronghui Mu, Jiaxu Liu 0001, Jonathan E. Fieldsend, Wenjie Ruan
IJCAI6
2024 The Implicit Bias of Gradient Descent toward Collaboration between Layers: A Dynamic Analysis of Multilayer Perceptions
abstract
The implicit bias of gradient descent has long been considered the primary mechanism explaining the superior generalization of over-parameterized neural networks without overfitting, even when the training error is zero. However, the implicit bias toward adversarial robustness has rarely been considered in the research community, although it is crucial for the trustworthiness of machine learning models. To fill this gap, in this paper, we explore whether consecutive layers collaborate to strengthen adversarial robustness during gradient descent. By quantifying this collaboration between layers using our proposed concept, co-correlation, we demonstrate a monotonically increasing trend in co-correlation, which implies a decreasing trend in adversarial robustness during gradient descent. Additionally, we observe different behaviours between narrow and wide neural networks during gradient descent. We conducted extensive experiments that verified our proposed theorems.
Zheng Wang 0074, Geyong Min, Wenjie Ruan
NeurIPS3
2024 TARP-VP: Towards Evaluation of Transferred Adversarial Robustness and Privacy on Label Mapping Visual Prompting Models
abstract
Adversarial robustness and privacy of deep learning (DL) models are two widely studied topics in AI security. Adversarial training (AT) is an effective approach to improve the robustness of DL models against adversarial attacks. However, while models with AT demonstrate enhanced robustness, they become more susceptible to membership inference attacks (MIAs), thus increasing the risk of privacy leakage. This indicates a negative trade-off between adversarial robustness and privacy in general deep learning models. Visual prompting is a novel model reprogramming (MR) technique used for fine-tuning pre-trained models, achieving good performance in vision tasks, especially when combined with the label mapping technique. However, the performance of label-mapping-based visual prompting (LM-VP) under adversarial attacks and MIAs lacks evaluation. In this work, we regard the MR of LM-VP as a unified entity, referred to as the LM-VP model, and take a step toward jointly evaluating the adversarial robustness and privacy of LM-VP models. Experimental results show that the choice of pre-trained models significantly affects the white-box adversarial robustness of LM-VP, and standard AT even substantially degrades its performance. In contrast, transfer AT-trained LM-VP achieves a good trade-off between transferred adversarial robustness and privacy, a finding that has been consistently validated across various pre-trained models.
Yi Zhang 0141, Xingyu Zhao 0001, Xiaowei Huang 0001, Wenjie Ruan
NeurIPS6
2024 Bridging formal methods and machine learning with model checking and global optimisation
abstract
Formal methods and machine learning are two research fields with drastically different foundations and philosophies. Formal methods utilise mathematically rigorous techniques for software and hardware systems' specification, development and verification. Machine learning focuses on pragmatic approaches to gradually improve a parameterised model by observing a training data set. While historically, the two fields lack communication, this trend has changed in the past few years with an outburst of research interest in the robustness verification of neural networks. This paper will briefly review these works, and focus on the urgent need for broader and more in-depth communication between the two fields, with the ultimate goal of developing learning-enabled systems with excellent performance and acceptable safety and security. We present a specification language, MLS2, and show that it can express a set of known safety and security properties, including generalisation, uncertainty, robustness, data poisoning, backdoor, model stealing, membership inference, model inversion, interpretability, and fairness. To verify MLS2 properties, we promote the global optimisation-based methods, which have provable guarantees on the convergence to the optimal solution. Many of them have theoretical bounds on the gap between current solutions and the optimal solution.
Saddek Bensalem, Xiaowei Huang 0001, Wenjie Ruan, Qiyi Tang 0001, Changshun Wu, Xingyu Zhao 0001
J. Log. Algebraic Methods Program.3
2024 Nrat: towards adversarial training with inherent label noise
abstract
Abstract Adversarial training (AT) has been widely recognized as the most effective defense approach against adversarial attacks on deep neural networks and it is formulated as a min-max optimization. Most AT algorithms are geared towards research-oriented datasets such as MNIST, CIFAR10, etc., where the labels are generally correct. However, noisy labels, e.g., mislabelling, are inevitable in real-world datasets. In this paper, we investigate AT with inherent label noise, where the training dataset itself contains mislabeled samples. We first empirically show that the performance of AT typically degrades as the label noise rate increases. Then, we propose a Noisy-Robust Adversarial Training (NRAT) algorithm, which leverages the recent advancements in learning with noisy labels to enhance the performance of AT in the presence of label noise. For experimental comparison, we consider two essential metrics in AT: (i) trade-off between natural and robust accuracy; (ii) robust overfitting. Our experiments show that NRAT’s performance is on par with, or better than, the state-of-the-art AT methods on both evaluation metrics. Our code is publicly available at: https://github.com/TrustAI/NRAT .
Ronghui Mu, Peipei Xu, Xiaowei Huang 0001, Wenjie Ruan
Mach. Learn.6
2024 3DVerifier: efficient robustness verification for 3D point cloud models
abstract
Abstract 3D point cloud models are widely applied in safety-critical scenes, which delivers an urgent need to obtain more solid proofs to verify the robustness of models. Existing verification method for point cloud model is time-expensive and computationally unattainable on large networks. Additionally, they cannot handle the complete PointNet model with joint alignment network that contains multiplication layers, which effectively boosts the performance of 3D models. This motivates us to design a more efficient and general framework to verify various architectures of point cloud models. The key challenges in verifying the large-scale complete PointNet models are addressed as dealing with the cross-non-linearity operations in the multiplication layers and the high computational complexity of high-dimensional point cloud inputs and added layers. Thus, we propose an efficient verification framework, 3DVerifier, to tackle both challenges by adopting a linear relaxation function to bound the multiplication layer and combining forward and backward propagation to compute the certified bounds of the outputs of the point cloud models. Our comprehensive experiments demonstrate that 3DVerifier outperforms existing verification algorithms for 3D models in terms of both efficiency and accuracy. Notably, our approach achieves an orders-of-magnitude improvement in verification efficiency for the large network, and the obtained certified bounds are also significantly tighter than the state-of-the-art verifiers. We release our tool 3DVerifier via https://github.com/TrustAI/3DVerifier for use by the community.
Ronghui Mu, Wenjie Ruan, Leandro Soriano Marcolino, Qiang Ni
Mach. Learn.2
2024 DIMBA: discretely masked black-box attack in single object tracking
abstract
Abstract The adversarial attack can force a CNN-based model to produce an incorrect output by craftily manipulating human-imperceptible input. Exploring such perturbations can help us gain a deeper understanding of the vulnerability of neural networks, and provide robustness to deep learning against miscellaneous adversaries. Despite extensive studies focusing on the robustness of image, audio, and NLP, works on adversarial examples of visual object tracking—especially in a black-box manner—are quite lacking. In this paper, we propose a novel adversarial attack method to generate noises for single object tracking under black-box settings, where perturbations are merely added on initialized frames of tracking sequences, which is difficult to be noticed from the perspective of a whole video clip. Specifically, we divide our algorithm into three components and exploit reinforcement learning for localizing important frame patches precisely while reducing unnecessary computational queries overhead. Compared to existing techniques, our method requires less time to perturb videos, but to manipulate competitive or even better adversarial performance. We test our algorithm in both long-term and short-term datasets, including OTB100, VOT2018, UAV123, and LaSOT. Extensive experiments demonstrate the effectiveness of our method on three mainstream types of trackers: discrimination, Siamese-based, and reinforcement learning-based trackers. We release our attack tool, DIMBA, via GitHub https://github.com/TrustAI/DIMBA for use by the community.
Xiangyu Yin 0001, Wenjie Ruan, Jonathan E. Fieldsend
Mach. Learn.2
2024 Enhancing robustness in video recognition models: Sparse adversarial attacks and beyond
Ronghui Mu, Leandro Soriano Marcolino, Qiang Ni, Wenjie Ruan
Neural Networks4
2023 RePreM: Representation Pre-training with Masked Model for Reinforcement Learning
abstract
Inspired by the recent success of sequence modeling in RL and the use of masked language model for pre-training, we propose a masked model for pre-training in RL, RePreM (Representation Pre-training with Masked Model), which trains the encoder combined with transformer blocks to predict the masked states or actions in a trajectory. RePreM is simple but effective compared to existing representation pre-training methods in RL. It avoids algorithmic sophistication (such as data augmentation or estimating multiple models) with sequence modeling and generates a representation that captures long-term dynamics well. Empirically, we demonstrate the effectiveness of RePreM in various tasks, including dynamic prediction, transfer learning, and sample-efficient RL with both value-based and actor-critic methods. Moreover, we show that RePreM scales well with dataset size, dataset quality, and the scale of the encoder, which indicates its potential towards big RL models.
Yuanying Cai, Chuheng Zhang, Wei Shen 0005, Xuyun Zhang, Wenjie Ruan, Longbo Huang
AAAI5
2023 Certified Policy Smoothing for Cooperative Multi-Agent Reinforcement Learning
abstract
Cooperative multi-agent reinforcement learning (c-MARL) is widely applied in safety-critical scenarios, thus the analysis of robustness for c-MARL models is profoundly important. However, robustness certification for c-MARLs has not yet been explored in the community. In this paper, we propose a novel certification method, which is the first work to leverage a scalable approach for c-MARLs to determine actions with guaranteed certified bounds. c-MARL certification poses two key challenges compared to single-agent systems: (i) the accumulated uncertainty as the number of agents increases; (ii) the potential lack of impact when changing the action of a single agent into a global team reward. These challenges prevent us from directly using existing algorithms. Hence, we employ the false discovery rate (FDR) controlling procedure considering the importance of each agent to certify per-state robustness. We further propose a tree-search-based algorithm to find a lower bound of the global reward under the minimal certified perturbation. As our method is general, it can also be applied in a single-agent environment. We empirically show that our certification bounds are much tighter than those of state-of-the-art RL certification solutions. We also evaluate our method on two popular c-MARL algorithms: QMIX and VDN, under two different environments, with two and four agents. The experimental results show that our method can certify the robustness of all c-MARL models in various environments. Our tool CertifyCMARL is available at https://github.com/TrustAI/CertifyCMARL.
Ronghui Mu, Wenjie Ruan, Leandro Soriano Marcolino, Gaojie Jin, Qiang Ni
AAAI2
2023 Towards Verifying the Geometric Robustness of Large-Scale Neural Networks
abstract
Deep neural networks (DNNs) are known to be vulnerable to adversarial geometric transformation. This paper aims to verify the robustness of large-scale DNNs against the combination of multiple geometric transformations with a provable guarantee. Given a set of transformations (e.g., rotation, scaling, etc.), we develop GeoRobust, a black-box robustness analyser built upon a novel global optimisation strategy, for locating the worst-case combination of transformations that affect and even alter a network's output. GeoRobust can provide provable guarantees on finding the worst-case combination based on recent advances in Lipschitzian theory. Due to its black-box nature, GeoRobust can be deployed on large-scale DNNs regardless of their architectures, activation functions, and the number of neurons. In practice, GeoRobust can locate the worst-case geometric transformation with high precision for the ResNet50 model on ImageNet in a few seconds on average. We examined 18 ImageNet classifiers, including the ResNet family and vision transformers, and found a positive correlation between the geometric robustness of the networks and the parameter numbers. We also observe that increasing the depth of DNN is more beneficial than increasing its width in terms of improving its geometric robustness. Our tool GeoRobust is available at https://github.com/TrustAI/GeoRobust.
Peipei Xu, Wenjie Ruan, Xiaowei Huang 0001
AAAI3
2023 Reachability Analysis of Neural Network Control Systems
abstract
Neural network controllers (NNCs) have shown great promise in autonomous and cyber-physical systems. Despite the various verification approaches for neural networks, the safety analysis of NNCs remains an open problem. Existing verification approaches for neural network control systems (NNCSs) either can only work on a limited type of activation functions, or result in non-trivial over-approximation errors with time evolving. This paper proposes a verification framework for NNCS based on Lipschitzian optimisation, called DeepNNC. We first prove the Lipschitz continuity of closed-loop NNCSs by unrolling and eliminating the loops. We then reveal the working principles of applying Lipschitzian optimisation on NNCS verification and illustrate it by verifying an adaptive cruise control model. Compared to state-of-the-art verification approaches, DeepNNC shows superior performance in terms of efficiency and accuracy over a wide range of NNCs. We also provide a case study to demonstrate the capability of DeepNNC to handle a real-world, practical, and complex system. Our tool DeepNNC is available at https://github.com/TrustAI/DeepNNC.
Wenjie Ruan, Peipei Xu
AAAI2
2023 Sora: Scalable Black-Box Reachability Analyser on Neural Networks
abstract
The vulnerability of deep neural networks (DNNs) to input perturbations has posed a significant challenge. Recent work on robustness verification of DNNs not only lacks scalability but also requires severe restrictions on the architecture (layers, activation functions, etc.). To address these limitations, we propose a novel framework, SORA, for scalable blackbox reachability analysis of DNNs. SORA can work on a broad class of neural network structures, including those networks with very deep layers and a huge number of neurons with nonlinear activation functions. Based on the Lipschitz continuity, SORA verifies the reachability property of DNNs with a novel optimisation algorithm and has global convergence guarantee. Our method does not require access to the inner structures of the DNNs, hence a black-box method. Experimental results show that, compared to existing verification methods, SORA shows superior performance in terms of both efficiency and scalability, especially when handling a deep neural network with very deep layers and a large number of neurons with various types of nonlinear activation functions.
Peipei Xu, Wenjie Ruan, Xiaowei Huang 0001
ICASSP3
2023 Adversarial Driving: Attacking End-to-End Autonomous Driving
abstract
As research in deep neural networks advances, deep convolutional networks become promising for autonomous driving tasks. In particular, there is an emerging trend of employing end-to-end neural network models for autonomous driving. However, previous research has shown that deep neural network classifiers are vulnerable to adversarial attacks. While for regression tasks, the effect of adversarial attacks is not as well understood. In this research, we devise two white-box targeted attacks against end-to-end autonomous driving models. Our attacks manipulate the behavior of the autonomous driving system by perturbing the input image. In an average of 800 attacks with the same attack strength (epsilon=1), the image-specific and image-agnostic attack deviates the steering angle from the original output by 0.478 and 0.111, respectively, which is much stronger than random noises that only perturbs the steering angle by 0.002 (The steering angle ranges from [-1, 1]). Both attacks can be initiated in real-time on CPUs without employing GPUs. Demo video: https://youtu.be/I0i8uN2oOP0.
Syed Yunas, Sareh Rowlands, Wenjie Ruan, Johan Wahlström
IV4
2023 Adversarial Detection: Attacking Object Detection in Real Time
abstract
Intelligent robots rely on object detection models to perceive the environment. Following advances in deep learning security it has been revealed that object detection models are vulnerable to adversarial attacks. However, prior research primarily focuses on attacking static images or offline videos. Therefore, it is still unclear if such attacks could jeopardize real-world robotic applications in dynamic environments. This paper bridges this gap by presenting the first real-time online attack against object detection models. We devise three attacks that fabricate bounding boxes for nonexistent objects at desired locations. The attacks achieve a success rate of about 90% within about 20 iterations. The demo video is available at https://youtu.be/zJZ1aNlXsMU.
Syed Yunas, Sareh Rowlands, Wenjie Ruan, Johan Wahlström
IV4
2023 Self-adaptive Adversarial Training for Robust Medical Segmentation
Zeyu Fu, Yanghao Zhang, Wenjie Ruan
MICCAI (3)4
2023 Model-Agnostic Reachability Analysis on Deep Neural Networks
Wenjie Ruan, Peipei Xu, Geyong Min, Xiaowei Huang 0001
PAKDD (1)2
2023 Generalizing universal adversarial perturbations for deep neural networks
Yanghao Zhang, Wenjie Ruan, Xiaowei Huang 0001
Mach. Learn.2
2022 Enhancing Robust Text Classification via Category Description
abstract
Despite the success of deep neural networks on text classification, their large capacity also leads to capturing task-irrelevant patterns such as label noise. Label noise is usually introduced into the data during label collection and causes nontrivial declines in performance due to the memorization effect. Though effort has been devoted to combating the label noise in other systems such as image classification, high-quality input features are necessary for discovering task-relevant patterns before memorizing the label noise. However, such a high-quality input feature requirement is hard to be satisfied for text classification due to the nature of natural language. To combat the label noise with low-quality input features in the text classification, we propose a novel framework that exploits external category descriptions to construct prototypes that can be used to denoise the input representation and alleviate the over-fitting. However, there still remains a challenge that the external category descriptions from other corpora could be semantically discrepant with the underlying task-specific classes in the training corpus. To align their semantics, we propose two regularizers that penalize sample-wise semantic-based deviations at the local level and class-wise structure-based deviations at the global level, respectively. Our extensive experiments across two open datasets and one real-world case study demonstrate that our method is superior to state-of-the-art baselines under various settings of label noise.
Zhengye Zhu, Yasha Wang, Wenjie Ruan, Junfeng Zhao 0001
ICDM5
2022 Bridging Formal Methods and Machine Learning with Global Optimisation
Xiaowei Huang 0001, Wenjie Ruan, Qiyi Tang 0001, Xingyu Zhao 0001
ICFEM2
2022 Understanding Adversarial Robustness of Vision Transformers via Cauchy Problem
Zheng Wang 0074, Wenjie Ruan
ECML/PKDD (3)2
2022 PRoA: A Probabilistic Robustness Assessment Against Functional Perturbations
Wenjie Ruan, Jonathan E. Fieldsend
ECML/PKDD (3)2
2022 Coverage-Guided Testing for Recurrent Neural Networks
abstract
Recurrent neural networks (RNNs) have been applied to a broad range of applications, including natural language processing, drug discovery, and video recognition. Their vulnerability to input perturbation is also known. Aligning with a view from software defect detection, this article aims to develop a coverage-guided testing approach to systematically exploit the internal behavior of RNNs, with the expectation that such testing can detect defects with high possibility. Technically, the long short-term memory network (LSTM), a major class of RNNs, is thoroughly studied. A family of three test metrics are designed to quantify not only the values but also the temporal relations (including both stepwise and bounded-length) exhibited when LSTM processing inputs. A genetic algorithm is applied to efficiently generate test cases. The test metrics and test case generation algorithm are implemented into a tooltestRNN, which is then evaluated on a set of LSTM benchmarks. Experiments confirm thattestRNNhas advantages over the state-of-the-art tool DeepStellar and attack-based defect detection methods, owing to its working with finer temporal semantics and the consideration of the naturalness of input perturbation. Furthermore,testRNNenables meaningful information to be collected and exhibited for users to understand the testing results, which is an important step toward interpretable neural network testing.
Wei Huang 0035, Youcheng Sun, Xingyu Zhao 0001, James Sharp, Wenjie Ruan, Xiaowei Huang 0001
IEEE Trans. Reliab.5
2021 Sparse Adversarial Video Attacks with Spatial Transformations
Ronghui Mu, Wenjie Ruan, Leandro Soriano Marcolino, Qiang Ni
BMVC2
2021 Adversarial Robustness of Deep Learning: Theory, Algorithms, and Applications
abstract
This tutorial aims to introduce the fundamentals of adversarial robustness of deep learning, presenting a well-structured review of up-to-date techniques to assess the vulnerability of various types of deep learning models to adversarial examples. This tutorial will particularly highlight state-of-the-art techniques in adversarial attacks and robustness verification of deep neural networks (DNNs). We will also introduce some effective countermeasures to improve robustness of deep learning models, with a particular focus on adversarial training. We aim to provide a comprehensive overall picture about this emerging direction and enable the community to be aware of the urgency and importance of designing robust deep learning models in safety-critical data analytical applications, ultimately enabling the end-users to trust deep learning classifiers. We will also summarize potential research directions concerning the adversarial robustness of deep learning, and its potential benefits to enable accountable and trustworthy deep learning-based data analytical systems and applications.
Wenjie Ruan, Xinping Yi, Xiaowei Huang 0001
CIKM1
2021 Distilling Knowledge from Publicly Available Online EMR Data to Emerging Epidemic for Prognosis
abstract
Due to the characteristics of COVID-19, the epidemic develops rapidly and overwhelms health service systems worldwide. Many patients suffer from life-threatening systemic problems and need to be carefully monitored in ICUs. An intelligent prognosis can help physicians take an early intervention, prevent adverse outcomes, and optimize the medical resource allocation, which is urgently needed, especially in this ongoing global pandemic crisis. However, in the early stage of the epidemic outbreak, the data available for analysis is limited due to the lack of effective diagnostic mechanisms, the rarity of the cases, and privacy concerns. In this paper, we propose a distilled transfer learning framework, which leverages the existing publicly available online Electronic Medical Records to enhance the prognosis for inpatients with emerging infectious diseases. It learns to embed the COVID-19-related medical features based on massive existing EMR data. The transferred parameters are further trained to imitate the teacher model’s representation based on distillation, which embeds the health status more comprehensively on the source dataset. We conduct Length-of-Stay prediction experiments for patients in ICUs on real-world COVID-19 datasets. The experiment results indicate that our proposed model consistently outperforms competitive baseline methods. In order to further verify the scalability of o deal with different clinical tasks on different EMR datasets, we conduct an additional mortality prediction experiment on End-Stage Renal Disease datasets. The extensive experiments demonstrate that an benefit the prognosis for emerging pandemics and other diseases with limited EMR.
Liantao Ma, Xianfeng Jiao, Zhihao Yu, Chaohe Zhang, Wenjie Ruan, Yasha Wang, Wen Tang 0001, Jiangtao Wang 0001
WWW7
2021 Enabling Cost-Effective Population Health Monitoring By Exploiting Spatiotemporal Correlation: An Empirical Study
abstract
Because of its important role in health policy-shaping, population health monitoring (PHM) is considered a fundamental block for public health services. However, traditional public health data collection approaches, such as clinic-visit-based data integration or health surveys, could be very costly and time-consuming. To address this challenge, this article proposes a cost-effective approach called Compressive Population Health (CPH), where a subset of a given area is selected in terms of regions within the area for data collection in the traditional way, while leveraging inherent spatial correlations of neighboring regions to perform data inference for the rest of the area. By alternating selected regions longitudinally, this approach can validate and correct previously assessed spatial correlations. To verify whether the idea of CPH is feasible, we conduct an in-depth study based on spatiotemporal morbidity rates of chronic diseases in more than 500 regions around London for over 10 years. We introduce our CPH approach and present three extensive analytical studies. The first confirms that significant spatiotemporal correlations do exist. In the second study, by deploying multiple state-of-the-art data recovery algorithms, we verify that these spatiotemporal correlations can be leveraged to do data inference accurately using only a small number of samples. Finally, we compare different methods for region selection for traditional data collection and show how such methods can further reduce the overall cost while maintaining high PHM quality.
Jiangtao Wang 0001, Wenjie Ruan, Qiang Ni, Abdelsalam Helal
ACM Trans. Comput. Heal.3
2021 Memory Augmented Hierarchical Attention Network for Next Point-of-Interest Recommendation
abstract
Next point-of-interest (POI) recommendation has been an important task for location-based intelligent services. However, the application of such promising technique is still limited due to the following three challenges: 1) the difficulty of capturing complicated spatiotemporal patterns of user movements; 2) the hardness of modeling fine-grained long-term preferences of users; and 3) the effective learning of interaction between long- and short-term preferences. Motivated by this, we propose a memory augmented hierarchical attention network (MAHAN), which considers both short-term check-in sequences and long-term memories. To capture the complicated interest tendencies of users within a short-term period, we design a spatiotemporal self-attention network (ST-SAN). For long-term preferences modeling, we employ a memory network to maintain fine-grained preferences of users and dynamically operate them based on users' constantly updated check-ins. Moreover, we first employ a coattention network/mechanism to integrate the proposed ST-SAN and memory network, which can fully learn the dynamic interaction between long- and short-term preferences. Our extensive experiments on two publicly available data sets demonstrate the effectiveness of MAHAN.
Chenwang Zheng, Dan Tao, Jiangtao Wang 0001, Lei Cui 0006, Wenjie Ruan, Shui Yu 0001
IEEE Trans. Comput. Soc. Syst.5
2020 AdaCare: Explainable Clinical Health Status Representation Learning via Scale-Adaptive Feature Extraction and Recalibration
abstract
Deep learning-based health status representation learning and clinical prediction have raised much research interest in recent years. Existing models have shown superior performance, but there are still several major issues that have not been fully taken into consideration. First, the historical variation pattern of the biomarker in diverse time scales plays a vital role in indicating the health status, but it has not been explicitly extracted by existing works. Second, key factors that strongly indicate the health risk are different among patients. It is still challenging to adaptively make use of the features for patients in diverse conditions. Third, using prediction models as the black box will limit the reliability in clinical practice. However, none of the existing works can provide satisfying interpretability and meanwhile achieve high prediction performance. In this work, we develop a general health status representation learning model, named AdaCare. It can capture the long and short-term variations of biomarkers as clinical features to depict the health status in multiple time scales. It also models the correlation between clinical features to enhance the ones which strongly indicate the health status and thus can maintain a state-of-the-art performance in terms of prediction accuracy while providing qualitative interpretability. We conduct a health risk prediction experiment on two real-world datasets. Experiment results indicate that AdaCare outperforms state-of-the-art approaches and provides effective interpretability, which is verifiable by clinical experts.
Liantao Ma, Yasha Wang, Chaohe Zhang, Jiangtao Wang 0001, Wenjie Ruan, Wen Tang 0001
AAAI6
2020 ConCare: Personalized Clinical Feature Embedding via Capturing the Healthcare Context
abstract
Predicting the patient's clinical outcome from the historical electronic medical records (EMR) is a fundamental research problem in medical informatics. Most deep learning-based solutions for EMR analysis concentrate on learning the clinical visit embedding and exploring the relations between visits. Although those works have shown superior performances in healthcare prediction, they fail to explore the personal characteristics during the clinical visits thoroughly. Moreover, existing works usually assume that the more recent record weights more in the prediction, but this assumption is not suitable for all conditions. In this paper, we propose ConCare to handle the irregular EMR data and extract feature interrelationship to perform individualized healthcare prediction. Our solution can embed the feature sequences separately by modeling the time-aware distribution. ConCare further improves the multi-head self-attention via the cross-head decorrelation, so that the inter-dependencies among dynamic features and static baseline information can be effectively captured to form the personal health context. Experimental results on two real-world EMR datasets demonstrate the effectiveness of ConCare. The medical findings extracted by ConCare are also empirically confirmed by human experts and medical literature.
Liantao Ma, Chaohe Zhang, Yasha Wang, Wenjie Ruan, Jiangtao Wang 0001, Wen Tang 0001
AAAI4
2020 Generalizing Universal Adversarial Attacks Beyond Additive Perturbations
abstract
The previous study has shown that universal adversarial attacks can fool deep neural networks over a large set of input images with a single human-invisible perturbation. However, current methods for universal adversarial attacks are based on additive perturbation, which cause misclassification when the perturbation is directly added to the input images. In this paper, for the first time, we show that a universal adversarial attack can also be achieved via non-additive perturbation (e.g., spatial transformation). More importantly, to unify both additive and non-additive perturbations, we propose a novel unified yet flexible framework for universal adversarial attacks, called GUAP, which is able to initiate attacks by additive perturbation, non-additive perturbation, or the combination of both. Extensive experiments are conducted on ImageNet dataset with several deep neural network models including GoogLeNet, VGG and ResNet. The empirical experiments demonstrate that GUAP can obtain up to 99.24% successful attack rate on ImageNet dataset, leading to over 19% improvements than current state-of-the-art universal adversarial attacks. The code for reproducing the experiments in this paper is available at https://github.com/TrustAI/GUAP.
Yanghao Zhang, Wenjie Ruan, Xiaowei Huang 0001
ICDM2
2020 EV Charging Recommendation Concerning Preemptive Service and Charging Urgency Policy
abstract
Compared with traditional internal combustion engine vehicles, Electric Vehicles (EVs) have the advantage of eliminating harmful gases in the environment, with great development potential in recent years. However, because the battery capacity of EVs is limited at the current stage, where to charge (to select charging station) and when/whether to charge (order the charging priority of EVs) still limit the large-scale popularity of EVs. In this paper, we develop an Urgency First Charging (UFC) charging scheduling policy, which takes the remaining parking time and charging time of EVs as the standard of charging priority. With this, the CS benefits to the shortest trip duration (summation of travelling time through CS, and charging service time at CS) is selected as optimal solution. We have conducted simulations through Helsinki's traffic scenarios. The results have shown that our proposed CS-Selection scheme effectively improves the charging comfort (in terms of waiting time and trip time) and charging efficiency (in terms of not-fully charged service due to limited parking duration).
Shuohan Liu, Yue Cao 0002, Wenjie Ruan, Qiang Ni, Michele Nati, Chakkaphong Suthaputchakun
VTC Fall3
2020 A game-based approximate verification of deep neural networks with provable guarantees
Min Wu 0011, Matthew Wicker, Wenjie Ruan, Xiaowei Huang 0001, Marta Z. Kwiatkowska
Theor. Comput. Sci.3
2019 Global Robustness Evaluation of Deep Neural Networks with Provable Guarantees for the Hamming Distance
abstract
Deployment of deep neural networks (DNNs) in safety-critical systems requires provable guarantees for their correct behaviours. We compute the maximal radius of a safe norm ball around a given input, within which there are no adversarial examples for a trained DNN. We define global robustness as an expectation of the maximal safe radius over a test dataset, and develop an algorithm to approximate the global robustness measure by iteratively computing its lower and upper bounds. Our algorithm is the first efficient method for the Hamming (L0) distance, and we hypothesise that this norm is a good proxy for a certain class of physical attacks. The algorithm is anytime, i.e., it returns intermediate bounds and robustness estimates that are gradually, but strictly, improved as the computation proceeds; tensor-based, i.e., the computation is conducted over a set of inputs simultaneously to enable efficient GPU computation; and has provable guarantees, i.e., both the bounds and the robustness estimates can converge to their optimal values. Finally, we demonstrate the utility of our approach by applying the algorithm to a set of challenging problems.
Wenjie Ruan, Min Wu 0011, Youcheng Sun, Xiaowei Huang 0001, Daniel Kroening, Marta Z. Kwiatkowska
IJCAI1
2019 Gaze-based Intention Anticipation over Driving Manoeuvres in Semi-Autonomous Vehicles
abstract
Anticipating a human collaborator's intention enables safe and efficient interaction between a human and an autonomous system. Specifically, in the context of semiautonomous driving, studies have revealed that correct and timely prediction of the driver's intention needs to be an essential part of Advanced Driver Assistance System (ADAS) design. To this end, we propose a framework that exploits drivers' time-series eye gaze and fixation patterns to anticipate their real-time intention over possible future manoeuvres, enabling a smart and collaborative ADAS that can aid drivers to overcome safety-critical situations. The method models human intention as the latent states of a hidden Markov model and uses probabilistic dynamic time warping distributions to capture the temporal characteristics of the observation patterns of the drivers. The method is evaluated on a data set of 124 experiments from 75 drivers collected in a safety-critical semi-autonomous driving scenario. The results illustrate the efficacy of the framework by correctly anticipating the drivers' intentions about 3 seconds beforehand with over 90% accuracy.
Min Wu 0011, Tyron Louw, Morteza Lahijanian, Wenjie Ruan, Xiaowei Huang 0001, Natasha Merat, Marta Z. Kwiatkowska
IROS4
2018 Reachability Analysis of Deep Neural Networks with Provable Guarantees
abstract
Verifying correctness for deep neural networks (DNNs) is challenging. We study a generic reachability problem for feed-forward DNNs which, for a given set of inputs to the network and a Lipschitz-continuous function over its outputs computes the lower and upper bound on the function values. Because the network and the function are Lipschitz continuous, all values in the interval between the lower and upper bound are reachable. We show how to obtain the safety verification problem, the output range analysis problem and a robustness measure by instantiating the reachability problem. We present a novel algorithm based on adaptive nested optimisation to solve the reachability problem. The technique has been implemented and evaluated on a range of DNNs, demonstrating its efficiency, scalability and ability to handle a broader class of networks than state-of-the-art verification approaches.
Wenjie Ruan, Xiaowei Huang 0001, Marta Z. Kwiatkowska
IJCAI1
2018 Concolic testing for deep neural networks
abstract
Concolic testing combines program execution and symbolic analysis to explore the execution paths of a software program. In this paper, we develop the first concolic testing approach for Deep Neural Networks (DNNs). More specifically, we utilise quantified linear arithmetic over rationals to express test requirements that have been studied in the literature, and then develop a coherent method to perform concolic testing with the aim of better coverage. Our experimental results show the effectiveness of the concolic testing approach in both achieving high coverage and finding adversarial examples.
Youcheng Sun, Min Wu 0011, Wenjie Ruan, Xiaowei Huang 0001, Marta Z. Kwiatkowska, Daniel Kroening
ASE3
2018 Related or Duplicate: Distinguishing Similar CQA Questions via Convolutional Neural Networks
abstract
Plenty of research attempts target the automatic duplicate detection in Community Question Answering (CQA) systems and frame the task as a supervised learning problem on the question pairs. However, these methods rely on handcrafted features, leading to the difficulty of distinguishing related and duplicate questions as they are often textually similar. To tackle this issue, we propose to leverage neural network architecture to extract "deep" features to identify whether a question pair is duplicate or related. In particular, we construct question correlation matrices, which capture the word-wise similarities between questions. The constructed matrices are input to our proposed convolutional neural network (CNN), in which the convolutional operation moves through the two dimensions of the matrices. Empirical studies on a range of real-world CQA datasets confirm the effectiveness of our proposed correlation matrices and the CNN. Our method outperforms the state-of-the-art methods and achieves better classification performance.
Wei Zhang 0098, Quan Z. Sheng, Zhejun Tang, Wenjie Ruan
SIGIR4
2018 Device-free human localization and tracking with UHF passive RFID tags: A data-driven approach
Wenjie Ruan, Quan Z. Sheng, Lina Yao 0001, Xue Li 0001, Nick Falkner, Lei Yang 0025
J. Netw. Comput. Appl.1
2018 Cubic-RBF-ARX modeling and model-based optimal setting control in head and tail stages of cut tobacco drying process
Feng Zhou 0005, Hui Peng 0001, Wenjie Ruan, Yunfeng Gu
Neural Comput. Appl.3
2018 Making Sense of Doppler Effect for Multi-Modal Hand Motion Detection
abstract
Hand gesture is becoming an increasingly popular means of interacting with consumer electronic devices, such as mobile phones, tablets and laptops. In this paper, we present AudioGest, a device-free gesture recognition system that can accurately sense the hand in-air movement around user's devices. Compared to the state-of-the-art techniques, AudioGest is superior in using only one pair of built-in speaker and microphone, without any extra hardware or infrastructure support and with no training, to achieve multimodal hand detection. Specifically, our system is not only able to accurately recognize various hand gestures, but also reliably estimate the hand in-air duration, average moving speed and waving range. We achieve this by transforming the device into an active sonar system that transmits inaudible audio signal and decodes the echoes of hand's movement at its microphone. We address various challenges including cleaning the noisy reflected sound signal, interpreting the echo spectrogram into hand gestures, decoding the Doppler frequency shifts into the hand waving speed and range, as well as being robust to the environmental motion and signal drifting. We extensively evaluate our system on three electronic devices under four real-world scenarios using overall 3,900 hand gestures collected by five users for more than two weeks. Our results show that AudioGest detects six hand gestures with an accuracy up to 96 percent. By distinguishing the gesture attributions, it can provide more fine-grained control commands for various applications.
Wenjie Ruan, Quan Z. Sheng, Peipei Xu, Lei Yang 0025, Tao Gu 0001, Longfei Shangguan
IEEE Trans. Mob. Comput.1
2018 Compressive Representation for Device-Free Activity Recognition with Passive RFID Signal Strength
abstract
Understanding and recognizing human activities is a fundamental research topic for a wide range of important applications such as fall detection and remote health monitoring and intervention. Despite active research in human activity recognition over the past years, existing approaches based on computer vision or wearable sensor technologies present several significant issues such as privacy (e.g., using video camera to monitor the elderly at home) and practicality (e.g., not possible for an older person with dementia to remember wearing devices). In this paper, we present a low-cost, unobtrusive, and robust system that supports independent living of older people. The system interprets what a person is doing by deciphering signal fluctuations using radio-frequency identification (RFID) technology and machine learning algorithms. To deal with noisy, streaming, and unstable RFID signals, we develop a compressive sensing, dictionary-based approach that can learn a set of compact and informative dictionaries of activities using an unsupervised subspace decomposition. In particular, we devise a number of approaches to explore the properties of sparse coefficients of the learned dictionaries for fully utilizing the embodied discriminative information on the activity recognition task. Our approach achieves efficient and robust activity recognition via a more compact and robust representation of activities. Extensive experiments conducted in a real-life residential environment demonstrate that our proposed system offers a good overall performance and shows the promising practical potential to underpin the applications for the independent living of the elderly.
Lina Yao 0001, Quan Z. Sheng, Xue Li 0001, Tao Gu 0001, Mingkui Tan, Xianzhi Wang 0001, Sen Wang 0001, Wenjie Ruan
IEEE Trans. Mob. Comput.8
2018 Duplicate Detection in Programming Question Answering Communities
abstract
Community-based Question Answering (CQA) websites are attracting increasing numbers of users and contributors in recent years. However, duplicate questions frequently occur in CQA websites and are currently manually identified by the moderators. Automatic duplicate detection, on one hand, alleviates this laborious effort for moderators before taking close actions, and, on the other hand, helps question issuers quickly find answers. A number of studies have looked into related problems, but very limited works target Duplicate Detection in Programming CQA (PCQA), a branch of CQA that is dedicated to programmers. Existing works framed the task as a supervised learning problem on the question pairs and relied on only textual features. Moreover, the issue of selecting candidate duplicates from large volumes of historical questions is often un-addressed. To tackle these issues, we model duplicate detection as a two-stage “ranking-classification” problem over question pairs. In the first stage, we rank the historical questions according to their similarities to the newly issued question and select the top ranked ones as candidates to reduce the search space. In the second stage, we develop novel features that capture both textual similarity and latent semantics on question pairs, leveraging techniques in deep learning and information retrieval literature. Experiments on real-world questions about multiple programming languages demonstrate that our method works very well; in some cases, up to 25% improvement compared to the state-of-the-art benchmarks.
Wei Zhang 0098, Quan Z. Sheng, Jey Han Lau, Ermyas Abebe, Wenjie Ruan
ACM Trans. Internet Techn.5
2017 Recovering Missing Values from Corrupted Spatio-Temporal Sensory Data via Robust Low-Rank Tensor Completion
Wenjie Ruan, Peipei Xu, Quan Z. Sheng, Nick Falkner, Xue Li 0001, Wei Zhang 0098
DASFAA (1)1
2017 Interpolating the Missing Values for Multi-Dimensional Spatial-Temporal Sensor Data: A Tensor SVD Approach
abstract
With the booming of the Internet of Things, enormous number of smart devices/sensors have been deployed in the physical world to monitor our surroundings. Usually those devices generate high-dimensional geo-tagged time-series data. However, these sensor readings are easily missing due to the hardware malfunction, connection errors or data corruption, which severely compromise the back-end data analysis. To solve this problem, in this paper we exploit tensor-based Singular Value Decomposition method to recover the missing sensor readings. The main novelty of this paper lies in that, i) our tensor-based recovery method can well capture the multi-dimensional spatial and temporal features by transforming the irregularly deployed sensors into a sensor-array and folding the periodic temporal patterns into multiple time dimensions, ii) it only requires to tune one key parameter in an unsupervised manner, and iii) Tensor Singular Value Decomposition structure is more efficient on representation of high-dimension sensor data than other tensor recovery methods based on tensor's vectorization or flattening. The experimental results in several real-world one-year air quality and meteorology datasets demonstrate the effectiveness and accuracy of our approach.
Peipei Xu, Wenjie Ruan, Quan Z. Sheng, Tao Gu 0001, Lina Yao 0001
MobiQuitous2
2016 Recognizing Daily Living Activity Using Embedded Sensors in Smartphones: A Data-Driven Approach
Wenjie Ruan, Leon Chea, Quan Z. Sheng, Lina Yao 0001
ADMA1
2016 Forecasting Seasonal Time Series Using Weighted Gradient RBF Network based Autoregressive Model
abstract
How to accurately forecast seasonal time series is very important for many business area such as marketing decision, planning production and profit estimation. In this paper, we propose a weighted gradient Radial Basis Function Network based AutoRegressive (WGRBF-AR) model for modeling and predicting the nonlinear and non-stationary seasonal time series. This WGRBF-AR model is a synthesis of the weighted gradient RBF network and the functional-coefficient autoregressive (FAR) model through using the WGRBF networks to approximate varying coefficients of FAR model. It not only takes the advantages of the FAR model in nonlinear dynamics description but also inherits the capability of the WGRBF network to deal with non-stationarity. We test our model using ten-years retail sales data on five different commodity in US. The results demonstrate that the proposed WGRBF-AR model can achieve competitive prediction accuracy compared with the state-of-the-art.
Wenjie Ruan, Quan Z. Sheng, Peipei Xu, Nguyen Khoi Tran 0001, Nick Falkner, Xue Li 0001, Wei Zhang 0098
CIKM1
2016 When Sensor Meets Tensor: Filling Missing Sensor Values Through a Tensor Approach
abstract
In the era of the Internet of Things, enormous number of sensors have been deployed in different locations, generating massive time-series sensory data with geo-tags. However, such sensory readings are easily missing due to various reasons such as the hardware malfunction, connection errors, and data corruption. This paper focuses on this challenge--how to accurately yet efficiently recover the missing values for corrupted time-series sensor data with geo-stamps. In this paper, we formulate the time-series sensor data as a 3-order tensor that naturally preserves sensors' temporal and spatial dependencies. Then we exploit its low-rank and sparse-noise structures by drawing upon recent advances in Robust Principal Component Analysis (RPCA) and tensor completion theory. The main novelty of this paper lies in that, we design a highly efficient optimization method that combines the alternating direction method of multipliers and accelerated proximal gradient to recover the data tensor. Besides testing our method using the synthetic data, we also design a real-world testbed by passive RFID (RadioFrequency IDentification) sensors. The results demonstrate the effectiveness and accuracy of our approach.
Wenjie Ruan, Peipei Xu, Quan Z. Sheng, Nguyen Khoi Tran 0001, Nick Falkner, Xue Li 0001, Wei Zhang 0098
CIKM1
2016 AudioGest: enabling fine-grained hand gesture detection by decoding echo signal
abstract
Hand gesture is becoming an increasingly popular means of interacting with consumer electronic devices, such as mobile phones, tablets and laptops. In this paper, we present AudioGest, a device-free gesture recognition system that can accurately sense the hand in-air movement around user's devices. Compared to the state-of-the-art, AudioGest is superior in using only one pair of built-in speaker and microphone, without any extra hardware or infrastructure support and with no training, to achieve fine-grained hand detection. Our system is able to accurately recognize various hand gestures, estimate the hand in-air time, as well as average moving speed and waving range. We achieve this by transforming the device into an active sonar system that transmits inaudible audio signal and decodes the echoes of hand at its microphone. We address various challenges including cleaning the noisy reflected sound signal, interpreting the echo spectrogram into hand gestures, decoding the Doppler frequency shifts into the hand waving speed and range, as well as being robust to the environmental motion and signal drifting. We implement the proof-of-concept prototype in three different electronic devices and extensively evaluate the system in four real-world scenarios using 3,900 hand gestures that collected by five users for more than two weeks. Our results show that AudioGest can detect six hand gestures with an accuracy up to 96%, and by distinguishing the gesture attributions, it can provide up to 162 control commands for various applications.
Wenjie Ruan, Quan Z. Sheng, Lei Yang 0025, Tao Gu 0001, Peipei Xu, Longfei Shangguan
UbiComp1
2016 Device-free indoor localization and tracking through Human-Object Interactions
abstract
Device-free indoor localization aims to localize people without requiring them to carry any devices or being actively involved in the localizing process. It underpins a wide range of applications including older people surveillance, intruder detection and indoor navigation. However, in a cluttered environment such as a residential home, the Received Signal Strength Indicator (RSSI) is heavily obstructed by furniture or metallic appliances, thus reducing the localization accuracy. This environment is important to observe as human-object interaction (HOI) events, detected by pervasive sensors, can potentially reveal people's interleaved locations during daily living activities, such as watching TV, opening the fridge door. This paper aims to enhance the performance of commercial off-the-shelf (COTS) RFID-based localization system by leveraging HOI contexts in a furnished home. Specifically, we propose a general Bayesian probabilistic framework to integrate both RSSI signals and HOI events to infer the most likely location and trajectory. Experiments conducted in a residential house demonstrate the effectiveness of our proposed method, in which we can localize a resident with average 95% accuracy and track a moving subject with 0.58m mean error distance.
Wenjie Ruan, Quan Z. Sheng, Lina Yao 0001, Tao Gu 0001, Michele Ruta, Longfei Shangguan
WoWMoM1
2015 Freedom: Online Activity Recognition via Dictionary-Based Sparse Representation of RFID Sensing Data
abstract
Understanding and recognizing the activities performed by people is a fundamental research topic for a wide range of important applications such as fall detection of elderly people. In this paper, we present the technical details behind Freedom, a low-cost, unobtrusive system that supports independent livingof the older people. The Freedom system interprets what aperson is doing by leveraging machine learning algorithmsand radio-frequency identification (RFID) technology. To dealwith noisy, streaming, unstable RFID signals, we particularlydevelop a dictionary-based approach that can learn dictionariesfor activities using an unsupervised sparse coding algorithm. Our approach achieves efficient and robust activity recognitionvia a more compact representation of the activities. Extensiveexperiments conducted in a real-life residential environmentdemonstrate that our proposed system offers a good overallperformance (e.g., achieving over 96% accuracy in recognizing23 activities) and has the potential to be further developed tosupport the independent living of elderly people.
Lina Yao 0001, Quan Z. Sheng, Xue Li 0001, Sen Wang 0001, Tao Gu 0001, Wenjie Ruan, Wan Zou
ICDM6
2015 Unobtrusive Posture Recognition via Online Learning of Multi-dimensional RFID Received Signal Strength
abstract
Activity recognition is a core component of ubiquitous computing applications (e.g., fall detection of elder people) since many of such applications require an intelligent environment to infer what a person is doing or attempting to do. Unfortunately, the success of existing approaches on activity recognition relies heavily on people's involvement such as wearing battery-powered sensors, which might not be practical in real-world situations (e.g., people may forget to wear sensors). In this paper, we propose a device-free, real-time posture recognition technique using an array of pure passive RFID tags. In particular, posture recognition is treated as a machine learning problem where a series of probabilistic model is built via learning how the Received Signal Strength Indicator (RSSI) from the tag array is distributed when a person performs different postures. We also design a segmentation algorithm to divide the continuous, multidimensional RSSI data stream into a set of individual segments by analyzing the shape of the RSSI data. Our approach for posture recognition eliminates the need for the monitored subjects to wear any devices. To the best of our knowledge, this work is the first on device-free posture recognition using low cost, unobtrusive RFID technology. Our experimental studies demonstrate the feasibility of the proposed approach for posture recognition.
Lina Yao 0001, Quan Z. Sheng, Wenjie Ruan, Xue Li 0001, Sen Wang 0001
ICPADS3
2015 Service Recommendation for Mashup Composition with Implicit Correlation Regularization
abstract
In this paper, we explore service recommendation and selection in the reusable composition context. The goal is to aid developers finding the most appropriate services in their composition tasks. We specifically focus on mashups, a domain that increasingly targets people without sophisticated programming knowledge. We propose a probabilistic matrix factorization approach with implicit correlation regularization to solve this problem. In particular, we advocate that the co-invocation of services in mashups is driven by both explicit textual similarity and implicit correlation of services, and therefore develop a latent variable model to uncover the latent connections between services by analyzing their co-invocation patterns. We crawled a real dataset from Programmable Web, and extensively evaluated the effectiveness of our proposed approach.
Lina Yao 0001, Xianzhi Wang 0001, Quan Z. Sheng, Wenjie Ruan, Wei Zhang 0098
ICWS4
2015 TagFall: Towards Unobstructive Fine-Grained Fall Detection based on UHF Passive RFID Tags
abstract
Falls are among the leading causes of hospitalization for the elderly and illness individuals. Considering that the elderly often live alone and receive only irregular visits, it is essential to develop such a system that can effectively detect a fall or abnormal activities. However, previous fall detection systems either require to wear sensors or are able to detect a fall but fail to provide fine-grained contextual information (e.g., what is the person doing before falling, falling directions). In this paper, we propose a device-free, fine-grained fall detection system based on pure passive UHF RFID tags, which not only is capable of sensing regular actions and fall events simultaneously, but also provide caregivers the contexts of fall orientations. We first augment the Angle-based Outlier Detection Method (ABOD) to classify normal actions (e.g., standing, sitting, lying and walking) and detect a fall event. Once a fall event is detected, we first segment a fix-length RSSI data stream generated by the fall and then utilize Dynamic Time Warping (DTW) based kNN to distinguish the falling direction. The experimental results demonstrate that our proposed approach can distinguish the living status before fall happening, as well as the fall orientations with a high accuracy. The experiments also show that our device-free, fine-grained fall detection system offers a good overall performance and has the potential to better support the assisted living of older people.
Wenjie Ruan, Lina Yao 0001, Quan Z. Sheng, Nick Falkner, Xue Li 0001, Tao Gu 0001
MobiQuitous1
2014 Exploring Tag-Free RFID-Based Passive Localization and Tracking via Learning-Based Probabilistic Approaches
abstract
RFID-based localization and tracking has some promising potentials. By combining localization with its identification capability, existing applications can be enhanced and new applications can be developed. In this paper, we investigate a tag-free indoor localizing and tracking problem (e.g., people tracking) without requiring subjects to carry any tags or devices in a pure passive environment. We formulate localization as a classification task. In particular, we model the received signal strength indicator (RSSI) of passive tags using multivariate Gaussian Mixture Model (GMM), and use the Expectation Maximization (EM) to learn the maximum likelihood estimates of the model parameters. Several other learning-based probabilistic approaches are also explored in the localization problem. To track a moving subject, we propose GMM based Hidden Markov Model (HMM) and k Nearest Neighbor (kNN) based HMM approaches. We conduct extensive experiments in a testbed formed by passive RFID tags, and the experimental results demonstrate the effectiveness and accuracy of our approach.
Lina Yao 0001, Wenjie Ruan, Quan Z. Sheng, Xue Li 0001, Nick Falkner
CIKM2
2014 TagTrack: device-free localization and tracking using passive RFID tags
abstract
Device-free passive localization aims to localize or track targets without requiring them to carry any devices or to be actively involved with the localization process. This technique has received much attention recently in a wide range of applications including elderly people surveillance, intrud
Wenjie Ruan, Lina Yao 0001, Quan Z. Sheng, Nick Falkner, Xue Li 0001
MobiQuitous1