Biwei Chen

dblp:158/4638 · DBLP profile ↗
← Back
11ranked-venue papers
2as first author
8since 2021 · last 2025
0000-0001-8239-4864ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 7 · 7 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Computer networks · 3 · 2 first-author
YearPublicationVenuePosition
2025 Everywhere Attack: Attacking Locally and Globally to Boost Targeted Transferability
abstract
Adversarial examples’ (AE) transferability refers to the phenomenon that AEs crafted with one surrogate model can also fool other models. Notwithstanding remarkable progress in untargeted transferability, its targeted counterpart remains challenging. This paper proposes an everywhere scheme to boost targeted transferability. Our idea is to attack a victim image both globally and locally. We aim to optimize ‘an army of targets’ in every local image region instead of the previous works that optimize a high-confidence target in the image. Specifically, we split a victim image into non-overlap blocks and jointly mount a targeted attack on each block. Such a strategy mitigates transfer failures caused by attention inconsistency between surrogate and victim models and thus results in stronger transferability. Our approach is method-agnostic, which means it can be easily combined with existing transferable attacks for even higher transferability. Extensive experiments on ImageNet demonstrate that the proposed approach universally improves the state-of-the-art targeted attacks by a clear margin, e.g., the transferability of the widely adopted Logit attack can be improved by 28.8%-300%. We also evaluate the crafted AEs on a real-world platform: Google Cloud Vision. Results further support the superiority of the proposed method.
Hui Zeng 0002, Sanshuai Cui, Biwei Chen, Anjie Peng
AAAI3
2025 Two Heads Are Better Than One: Averaging along Fine-Tuning to Improve Targeted Transferability
abstract
With much longer optimization time than that of untargeted attacks notwithstanding, the transferability of targeted attacks is still far from satisfactory. Recent studies reveal that fine-tuning an existing adversarial example (AE) in feature space can efficiently boost its targeted transferability. However, existing fine-tuning schemes only utilize the endpoint and ignore the valuable information in the fine-tuning trajectory. Noting that the vanilla fine-tuning trajectory tends to oscillate around the periphery of a flat region of the loss surface, we propose averaging over the fine-tuning trajectory to pull the crafted AE towards a more centered region. We compare the proposed method with existing fine-tuning schemes by integrating them with state-of-the-art targeted attacks in various attacking scenarios. Experimental results uphold the superiority of the proposed method in boosting targeted transferability. The code is available at github.com/zengh5/Avg_FT.
Hui Zeng 0002, Sanshuai Cui, Biwei Chen, Anjie Peng
ICASSP3
2024 Enhancing Targeted Transferability VIA Feature Space Fine-Tuning
abstract
Adversarial examples (AEs) have been extensively studied due to their potential for privacy protection and inspiring robust neural networks. Yet, making a targeted AE transferable across unknown models remains challenging. In this paper, to alleviate the overfitting dilemma common in an AE crafted by existing simple iterative attacks, we propose fine-tuning it in the feature space. Specifically, starting with an AE generated by a baseline attack, we encourage the features conducive to the target class and discourage the features to the original class in a middle layer of the source model. Extensive experiments demonstrate that only a few iterations of fine-tuning can boost existing attacks' targeted transferability nontrivially and universally. Our results also verify that the simple iterative attacks can yield comparable or even better transferability than the resource-intensive methods, which rest on training target-specific classifiers or generators with additional data. The code is available at: github.com/zengh5/TA_feature_FT.
Hui Zeng 0002, Biwei Chen, Anjie Peng
ICASSP2
2024 A Whale Falls, All Thrive: Mitigating Attention Gap to Improve Adversarial Transferability
Biwei Chen, Anjie Peng, Hui Zeng 0002
ICPR (22)2
2023 Adversarial Example Detection Bayesian Game
abstract
Despite the increasing attack ability and transferability of adversarial examples (AE), their security, i.e., how unlikely they can be detected, has been ignored more or less. Without the ability to circumvent popular detectors, the chance that an AE successfully fools a deep neural network is slim. This paper gives a game theory analysis of the interplay between an AE attacker and an AE detection investigator. Taking the perspective of a third party, we introduce a game theory model to evaluate the ultimate performance when both the attacker and the investigator are aware of each other. Further, a Bayesian game is adopted to address the information asymmetry in practice. Solving the mixed-strategy Nash equilibrium of the game, both parties’ optimal strategies are obtained, and the security of AEs can be evaluated. We evaluate four popular attacks under a two-step test on ImageNet. The results may throw light on how a farsighted attacker or investigator will act in this adversarial environment. Our code is available at: https://github.com/zengh5/AED_BGame.
Hui Zeng 0002, Biwei Chen, Kang Deng, Anjie Peng
ICIP2
2023 Enhancing Targeted Transferability Via Suppressing High-Confidence Labels
abstract
While extensive studies have pushed the limit of the transferability of untargeted attacks, transferable targeted attacks remain extremely challenging. This paper finds that the labels with high confidence in the source model are also likely to retain high confidence in the target model. This simple and intuitive observation inspires us to carefully deal with the high-confidence labels in generating targeted adversarial examples for better transferability. Specifically, we integrate the untargeted loss function into the targeted attack to push the adversarial examples away from the original label while approaching the target label. Furthermore, we suppress other high-confidence labels in the source model with an orthogonal gradient. We validate the proposed scheme by mounting targeted attacks on the ImageNet dataset. Experiments on various scenarios show that our proposed scheme improves the state-of-the-art targeted attacks in transferability. Our code is available at: https://github.com/zengh5/Transferable_targeted_attack.
Hui Zeng 0002, Biwei Chen, Anjie Peng
ICIP3
2023 Towards Undetectable Adversarial Examples: A Steganographic Perspective
Hui Zeng 0002, Biwei Chen, Rongsong Yang, Chenggang Li, Anjie Peng
ICONIP (4)2
2022 How Secure Are The Adversarial Examples Themselves?
abstract
Existing adversarial example generation algorithms mainly consider the success rate of spoofing target model, but pay little attention to its own security. In this paper, we propose the concept of adversarial example security as how unlikely themselves can be detected. A two-step test is proposed to deal with the adversarial attacks of different strengths. Game theory is introduced to model the interplay between the attacker and the investigator. By solving Nash equilibrium, the optimal strategies of both parties are obtained, and the security of the attacks is evaluated. Five typical attacks are compared on the ImageNet. The results show that a rational attacker tends to use a relatively weak strength. By comparing the ROC curves under Nash equilibrium, it is observed that the constrained perturbation attacks are more secure than the optimized perturbation attacks in face of the two-step test. The proposed framework can be used to evaluate the security of various potential attacks and further the research of adversarial example generation/detection.
Hui Zeng 0002, Kang Deng, Biwei Chen, Anjie Peng
ICASSP3
2015 An Adaptive Time Division Scheduling Based Resource Allocation Algorithm for D2D Communication Underlaying Cellular Networks
abstract
This paper proposes an adaptive time division scheduling (ATDS) based resource allocation algorithm for device-to-device (D2D) communication underlaying cellular networks. The proposed ATDS algorithm introduces an adaptive TDS strategy, in which all D2D pairs in a cellular system are adaptively scheduled into a series of timeslots for communication based on an improved proportional fairness algorithm. For a particular timeslot, the scheduling priority of each D2D pair is first determined based on both the data transmission rate and the rate satisfaction ratio of each D2D pair. Then, a set of D2D pairs are assigned to the timeslot based on the priorities determined and only those D2D pairs with higher priorities are assigned to the timeslot. After that, the spectrum resources of cellular users are allocated for each D2D pair assigned to the timeslot. Simulation results show that the proposed ATDS algorithm can not only achieve a larger system throughput but also achieve a better fairness as compared with a couple of resource allocation algorithms that do not use time division scheduling.
Jun Zheng 0002, Biwei Chen, Yuan Zhang 0002
GLOBECOM2
2015 A time division scheduling resource allocation algorithm for D2D communication in cellular networks
abstract
This paper considers the resource allocation problem in device-to-device (D2D) communication underlaying cellular networks and proposes a time division scheduling (TDS) resource allocation algorithm to efficiently exploit the downlink spectrum resources of cellular users to support more D2D communication. The proposed TDS algorithm introduces a time division scheduling framework, in which the scheduling period of a base station is divided into a set of timeslots and the D2D pairs in the system are assigned to different timeslots for communication in a balanced manner in order to accommodate more D2D users in the system. In the D2D pair assignment for each timeslot, it follows a location dispersion principle in order to reduce the interference from D2D users to cellular users and thus increase the system throughput. Moreover, the minimum required data rate of each D2D pair is taken into account in the allocation of cellular resources in each timeslot. Simulation results show that the proposed TDS algorithm can significantly improve the system performance in terms of the system throughput and D2D user satisfaction ratio of a cellular system.
Biwei Chen, Jun Zheng 0002, Yuan Zhang 0002
ICC1
2014 SARA: A service-aware resource allocation scheme for device-to-device communication underlaying cellular networks
abstract
This paper considers the resource allocation problem for device-to-device (D2D) communication underlaying cellular networks and proposes a service-aware resource allocation (SARA) scheme for D2D communication to improve the network performance. SARA takes into account the different service requirements of D2D users. It consists of two allocation phases: on-demand resource allocation and secondary resource allocation. In the first phase, cellular user resources are allocated on demand to meet the different service requirements of D2D pairs. In the second phase, the remaining cellular user resources after the first phase are allocated to D2D users based on an objective function in order to improve the resource utilization. Simulation results show that the proposed SARA scheme can significantly improve the performance of a cellular system in terms of the satisfaction ratio of D2D pairs and the system throughput.
Biwei Chen, Jun Zheng 0002, Yuan Zhang 0002, Hidekazu Murata
GLOBECOM1