VLDB 2026 Research / reviewers in the wild / expert
Sizhe Chen
dblp:160/4580
· DBLP profile ↗
20ranked-venue papers
9as first author
16since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 9 · 5 first-author · 8 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorTheory of computation · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Proactive Control or Passive Addiction: The Joint Effects of Technical and Social Factors of Short Video Applications on Cyberloafing in the WorkplaceabstractIn the digital age, short-video platforms such as TikTok and Douyin have become increasingly embedded in daily work environments, raising concerns about their role in facilitating cyberloafing—employees’ use of the internet for non-work purposes during work hours. Drawing on socio-technical systems theory, this study develops a model examining how technological features (e.g., personalized recommendation, mobile access) and social influences (e.g., coworkers’ norms, informal acceptance) jointly shape cyberloafing. The results of an empirical survey (N = 310) among workplace employees show that system quality and information quality have no significant direct effects, while prescriptive norms and descriptive norms positively influence cyberloafing. Moreover, users’ proactive control and short video addiction serve as important mediators. This study integrates technical and social factors to explain employee cyberloafing on short-video platforms, extending research beyond traditional media. It highlights rational and irrational pathways, offering insights into workplace behavior and practical implications for managing digital distractions. Renee Rui Chen, Sizhe Chen, Jianglian Gao, Kun Chen 0001 |
Int. J. Hum. Comput. Interact. | 2 |
| 2025 | SecAlign: Defending Against Prompt Injection with Preference Optimization
Sizhe Chen, Arman Zharmagambetov, Saeed Mahloujifar, Kamalika Chaudhuri, David A. Wagner 0001, Chuan Guo 0001 |
CCS | 1 |
| 2025 | ClueCart: Supporting Game Story Interpretation and Narrative Inference from Fragmented CluesabstractIndexical storytelling is gaining popularity in video games, where the narrative unfolds through fragmented clues. This approach fosters player-generated content and discussion, as story interpreters piece together the overarching narrative from these scattered elements. However, the fragmented and non-linear nature of the clues makes systematic categorization and interpretation challenging, potentially hindering efficient story reconstruction and creative engagement. To address these challenges, we first proposed a hierarchical taxonomy to categorize narrative clues, informed by a formative study. Using this taxonomy, we designed ClueCart, a creativity support tool aimed at enhancing creators' ability to organize story clues and facilitate intricate story interpretation. We evaluated ClueCart through a between-subjects study (N=40), using Miro as a baseline. The results showed that ClueCart significantly improved creators' efficiency in organizing and retrieving clues, thereby better supporting their creative processes. Additionally, we offer design insights for future studies focused on player-centric narrative analysis. Yifan Cao 0001, Sizhe Chen, Quan Li 0002 |
CHI | 4 |
| 2025 | Prefer2SD: A Human-in-the-Loop Approach to Balancing Similarity and Diversity in In-Game Friend RecommendationsabstractIn-game friend recommendations significantly impact player retention and sustained engagement in online games. Balancing similarity and diversity in recommendations is crucial for fostering stronger social bonds across diverse player groups. However, automated recommendation systems struggle to achieve this balance, especially as player preferences evolve over time. To tackle this challenge, we introduce Prefer2SD (derived from Preference to Similarity and Diversity), an iterative, human-in-the-loop approach designed to optimize the similarity-diversity (SD) ratio in friend recommendations. Developed in collaboration with a local game company, Prefer2D leverages a visual analytics system to help experts explore, analyze, and adjust friend recommendations dynamically, incorporating players' shifting preferences. The system employs interactive visualizations that enable experts to fine-tune the balance between similarity and diversity for distinct player groups. We demonstrate the efficacy of Prefer2SD through a within-subjects study (N=12), a case study, and expert interviews, showcasing its ability to enhance in-game friend recommendations and offering insights for the broader field of personalized recommendation systems. Sizhe Chen, Xingxing Xing, Quan Li 0002 |
IUI | 3 |
| 2025 | StruQ: Defending Against Prompt Injection with Structured Queries
Sizhe Chen, Julien Piet, Chawin Sitawarin, David A. Wagner 0001 |
USENIX Security Symposium | 1 |
| 2024 | Jatmo: Prompt Injection Defense by Task-Specific Finetuning
Julien Piet, Maha Alrashed, Chawin Sitawarin, Sizhe Chen, Zeming Wei, Elizabeth Sun, Basel Alomair, David A. Wagner 0001 |
ESORICS (1) | 4 |
| 2024 | An Instance and Cloud Masks Guided Multi-source Fusion Network for Remote Sensing Object Detection
Shouhong Wan, Sizhe Chen, Peiquan Jin |
PRICAI (3) | 2 |
| 2023 | Measuring the Transferability of ℓ∞ Attacks by the ℓ2 NormabstractDeep neural networks could be fooled by adversarial examples with trivial differences to original samples. To keep the difference imperceptible in human eyes, researchers bound the adversarial perturbations by the ℓ∞norm, which is now commonly served as the standard to align the strength of different attacks for a fair comparison. However, we propose that using the ℓ∞norm alone is not sufficient in measuring the attack strength, because even with a fixed ℓ∞distance, the ℓ2distance also greatly affects the attack transferability between models. Through the discovery, we reach more in-depth understandings towards the attack mechanism, i.e., several existing methods attack black-box models better partly because they craft perturbations with 70% to 130% larger ℓ2distances. Since larger perturbations naturally lead to better transferability, we thereby advocate that the strength of attacks should be simultaneously measured by both the ℓ∞and ℓ2norm. Our proposal is firmly supported by extensive experiments on ImageNet dataset from 7 attacks, 4 white-box models, and 9 black-box models. Sizhe Chen, Qinghua Tao, Zhixing Ye, Xiaolin Huang |
ICASSP | 1 |
| 2023 | Self-Ensemble Protection: Training Checkpoints Are Good Data Protectors
Sizhe Chen, Geng Yuan, Xinwen Cheng, Yifan Gong 0004, Minghai Qin, Yanzhi Wang 0001, Xiaolin Huang |
ICLR | 1 |
| 2023 | One-Pixel Shortcut: On the Learning Preference of Deep Neural Networks
Shutong Wu, Sizhe Chen, Cihang Xie, Xiaolin Huang |
ICLR | 2 |
| 2023 | Unifying Gradients to Improve Real-World Robustness for Deep NetworksabstractThe wide application of deep neural networks (DNNs) demands an increasing amount of attention to their real-world robustness, i.e., whether a DNN resists black-box adversarial attacks, among which score-based query attacks (SQAs) are the most threatening since they can effectively hurt a victim network with only access to model outputs. Defending against SQAs requires a slight but artful variation of outputs due to the service purpose for users, who share the same output information with SQAs. In this article, we propose a real-world defense by Unifying Gradients (UniG) of different data so that SQAs could only probe a much weaker attack direction that is similar for different samples. Since such universal attack perturbations have been validated as less aggressive than the input-specific perturbations, UniG protects real-world DNNs by indicating to attackers a twisted and less informative attack direction. We implement UniG efficiently by a Hadamard product module, which is plug-and-play. According to extensive experiments on 5 SQAs, 2 adaptive attacks and 7 defense baselines, UniG significantly improves real-world robustness without hurting clean accuracy on CIFAR10 and ImageNet. For instance, UniG maintains a model of 77.80% accuracy under a 2500-query Square attack while the state-of-the-art adversarially trained model only has 67.34% on CIFAR10. Simultaneously, UniG outperforms all compared baselines in terms of clean accuracy and achieves the smallest modification of the model output. The code is released at https://github.com/snowien/UniG-pytorch . Yingwen Wu, Sizhe Chen, Kun Fang 0004, Xiaolin Huang |
ACM Trans. Intell. Syst. Technol. | 2 |
| 2022 | Subspace Adversarial TrainingabstractSingle-step adversarial training (AT) has received wide attention as it proved to be both efficient and robust. However, a serious problem of catastrophic overfitting exists, i.e., the robust accuracy against projected gradient descent (PGD) attack suddenly drops to 0% during the training. In this paper, we approach this problem from a novel perspective of optimization and firstly reveal the close link between the fast-growing gradient of each sample and overfitting, which can also be applied to understand robust overfitting in multi-step AT. To control the growth of the gradient, we propose a new AT method, Subspace Adversarial Training (Sub-AT), which constrains AT in a carefully extracted subspace. It successfully resolves both kinds of overfitting and significantly boosts the robustness. In subspace, we also allow single-step AT with larger steps and larger radius, further improving the robustness performance. As a result, we achieve state-of-the-art single-step AT performance. Without any regularization term, our single-step AT can reach over 51 % robust accuracy against strong PGD-50 attack of radius 8/255 on CIFAR-10, reaching a competitive performance against standard multi-step PGD-10 AT with huge computational advantages. The code is released at https://github.com/nblt/Sub-AT. Tao Li 0054, Yingwen Wu, Sizhe Chen, Kun Fang 0004, Xiaolin Huang |
CVPR | 3 |
| 2022 | Mutual Diverse-Label Adversarial Training
Sizhe Chen, Xiaolin Huang |
ICONIP (1) | 2 |
| 2022 | Adversarial Attack on Attackers: Post-Process to Mitigate Black-Box Score-Based Query AttacksabstractThe score-based query attacks (SQAs) pose practical threats to deep neural networks by crafting adversarial perturbations within dozens of queries, only using the model's output scores. Nonetheless, we note that if the loss trend of the outputs is slightly perturbed, SQAs could be easily misled and thereby become much less effective. Following this idea, we propose a novel defense, namely Adversarial Attack on Attackers (AAA), to confound SQAs towards incorrect attack directions by slightly modifying the output logits. In this way, (1) SQAs are prevented regardless of the model's worst-case robustness; (2) the original model predictions are hardly changed, i.e., no degradation on clean accuracy; (3) the calibration of confidence scores can be improved simultaneously. Extensive experiments are provided to verify the above advantages. For example, by setting $\ell_\infty=8/255$ on CIFAR-10, our proposed AAA helps WideResNet-28 secure 80.59% accuracy under Square attack (2500 queries), while the best prior defense (i.e., adversarial training) only attains 67.44%. Since AAA attacks SQA's general greedy strategy, such advantages of AAA over 8 defenses can be consistently observed on 8 CIFAR-10/ImageNet models under 6 SQAs, using different attack targets, bounds, norms, losses, and strategies. Moreover, AAA calibrates better without hurting the accuracy. Our code is available at https://github.com/Sizhe-Chen/AAA. Sizhe Chen, Zhehao Huang, Qinghua Tao, Yingwen Wu, Cihang Xie, Xiaolin Huang |
NeurIPS | 1 |
| 2022 | Universal Adversarial Attack on Attention and the Resulting Dataset DAmageNetabstractAdversarial attacks on deep neural networks (DNNs) have been found for several years. However, the existing adversarial attacks have high success rates only when the information of the victim DNN is well-known or could be estimated by the structure similarity or massive queries. In this paper, we propose to Attack on Attention (AoA), a semantic property commonly shared by DNNs. AoA enjoys a significant increase in transferability when the traditional cross entropy loss is replaced with the attention loss. Since AoA alters the loss function only, it could be easily combined with other transferability-enhancement techniques and then achieve SOTA performance. We apply AoA to generate 50000 adversarial samples from ImageNet validation set to defeat many neural networks, and thus name the dataset as DAmageNet. 13 well-trained DNNs are tested on DAmageNet, and all of them have an error rate over 85 percent. Even with defenses or adversarial training, most models still maintain an error rate over 70 percent on DAmageNet. DAmageNet is the first universal adversarial dataset. It could be downloaded freely and serve as a benchmark for robustness testing and adversarial training. Sizhe Chen, Zhengbao He, Chengjin Sun, Jie Yang 0002, Xiaolin Huang |
IEEE Trans. Pattern Anal. Mach. Intell. | 1 |
| 2022 | Relevance attack on detectors
Sizhe Chen, Xiaolin Huang, Kun Zhang 0001 |
Pattern Recognit. | 1 |
| 2020 | Type I Attack For Generative ModelsabstractGenerative models are popular tools with a wide range of applications. Nevertheless, it is as vulnerable to adversarial samples as classifiers. The existing attack methods mainly focus on generating adversarial examples by adding imperceptible perturbations to input, which leads to wrong result. However, we focus on another aspect of attack, i.e., cheating models by significant changes. The former induces Type II error and the latter causes Type I error. In this paper, we propose Type I attack to generative models such as VAE and GAN. One example given in VAE is that we can change an original image significantly to a meaningless one but their reconstruction results are similar. To implement the Type I attack, we destroy the original one by increasing the distance in input space while keeping the output similar because different inputs may correspond to similar features for the property of deep neural network. Experimental results show that our attack method is effective to generate Type I adversarial examples for generative models on large-scale image datasets. Chengjin Sun, Sizhe Chen, Xiaolin Huang |
ICIP | 2 |
| 2016 | Target Classification Using the Deep Convolutional Networks for SAR ImagesabstractThe algorithm of synthetic aperture radar automatic target recognition (SAR-ATR) is generally composed of the extraction of a set of features that transform the raw input into a representation, followed by a trainable classifier. The feature extractor is often hand designed with domain knowledge and can significantly impact the classification accuracy. By automatically learning hierarchies of features from massive training data, deep convolutional networks (ConvNets) recently have obtained state-of-the-art results in many computer vision and speech recognition tasks. However, when ConvNets was directly applied to SAR-ATR, it yielded severe overfitting due to limited training images. To reduce the number of free parameters, we present a new all-convolutional networks (A-ConvNets), which only consists of sparsely connected layers, without fully connected layers being used. Experimental results on the Moving and Stationary Target Acquisition and Recognition (MSTAR) benchmark data set illustrate that A-ConvNets can achieve an average accuracy of 99% on classification of ten-class targets and is significantly superior to the traditional ConvNets on the classification of target configuration and version variants. Sizhe Chen, Haipeng Wang 0002, Feng Xu 0001, Ya-Qiu Jin |
IEEE Trans. Geosci. Remote. Sens. | 1 |
| 2015 | Application of deep-learning algorithms to MSTAR dataabstractIn this paper, a new All-Convolutional Networks (A-ConvNets) is proposed and applied to Moving and Stationary Target Acquisition and Recognition (MSTAR) data. Conventional deep learning algorithms, especially the deep convolutional networks (ConvNets) have achieved many success state-of-art results. However, directly applying ConvNets to SAR data will yield severe overfitting because of limited data availability. The proposed A-ConvNets can significantly reduce the number of free parameters and the degree of overfitting. Average accuracy of 99.1% on classification of 10-class targets was obtained by applying A-ConvNets to MSTAR datasets. Haipeng Wang 0002, Sizhe Chen, Feng Xu 0001, Ya-Qiu Jin |
IGARSS | 2 |
| 2014 | SAR target recognition based on deep learningabstractDeep learning algorithms such as convolutional neural networks (CNN) have been successfully applied in computer vision. This paper attempts to adapt the optical camera-oriented CNN to its microwave counterpart, i.e. synthetic aperture radar (SAR). As a preliminary study, a single layer of convolutional neural network is used to automatically learn features from SAR images. Instead of using the classical backpropagation algorithm, the convolution kernel is trained on randomly sampled image patches using unsupervised sparse auto-encoder. After convolution and pooling, an input SAR image is then transformed into a series of feature maps. These feature maps are then used to train a final softmax classifier. Initial experiments on MSTAR public data set show that an accuracy of 90.1% can be achieved on three types of targets classification task, and an accuracy of 84.7% is achievable on ten types of targets classification task. Sizhe Chen, Haipeng Wang 0002 |
DSAA | 1 |