Lifeng Huang

dblp:164/7462 · DBLP profile ↗
← Back
19ranked-venue papers
9as first author
15since 2021 · last 2026
0000-0001-5162-9894ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 8 · 4 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 4 first-author · 6 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Adversarial contribution-based perturbation for transferable attack on point cloud
Shuxin Wei, Lifeng Huang, Chengying Gao
Pattern Recognit.2
2026 Semantic Region-Guided Transferable Attacks on Vision-Language Pretraining Models
abstract
Vision-language pre-trained (VLP) models have achieved strong performance on multimodal tasks, but they remain vulnerable to adversarial attacks. In black-box settings, transferability is often limited because perturbation generation relies on surrogate-specific saliency cues that generalize poorly across VLP architectures. In this letter, we propose Semantic Region-Guided Attack (SRGA), a transferable attack framework that replaces such cues with detector-derived semantic regions to provide more consistent cross-model guidance. Based on these regions, SRGA performs coordinated perturbation generation in both image and text modalities with lightweight regional transformations and spatially weighted optimization. Experiments on Flickr30 K and MSCOCO show that SRGA achieves competitive black-box transferability across diverse VLP architectures under multiple settings, with modest additional cost.
Jiayang Pan, Chen Wan, Wutao Chen, Lifeng Huang
IEEE Signal Process. Lett.4
2026 A Single-Chip Pulse-Driven CMOS-MEMS Flow Sensing System With Sub-mm/s Flow Detection Limit
abstract
This paper presents a single-chip CMOS-MEMS flow sensing system for high-precision bidirectional gas flow detection, featuring a pulse-excited constant temperature difference (CTD) control scheme and a low-noise analog front-end using capacitively coupled chopper instrumentation amplifier (CCIA). The MEMS sensing structure is fabricated using a cost-effective surface micromachining process and thinned to$1.38~\mu $m, significantly enhancing system sensitivity and thermal efficiency. Two sensor prototypes, with MEMS opening sizes of$130~\mu $m and$170~\mu $m (named as Sensor 130 and Sensor 170), achieve record-high sensitivities of 24.74 mV/(m/s) and 30.84 mV/(m/s), respectively, within a linear flow range of ±5 m/s. Leveraging pulse excitation, the system dramatically reduces heating power down to 1.63 mW (Sensor 130) and 1.85 mW (Sensor 170). The CCIA readout circuit exhibits an ultra-low input-referred noise density of 5.86nV/$\surd $Hz, with a 1/$f$noise corner below 0.1 Hz, greatly improving low-flow detection capabilities of the sensor system. As a result, the overall system output noise density is measured at$1.93~\mu $V/$\surd $Hz, enabling minimum detectable flow velocities (MDFV) of 0.51 mm/s (Sensor 130) and 0.41 mm/s (Sensor 170). With its compact design, low power, and exceptional circuit performance, this cost-effective CMOS-MEMS flow sensing system is well-suited for high-precision flow measurement in industrial and IoT applications.
Lifeng Huang, Linze Hong, Bo Wang 0012, Xiaofang Pan, Wei Xu 0049
IEEE Trans. Circuits Syst. I Regul. Pap.2
2026 Rethinking Fake Adversarial Examples for Single-Step Adversarial Training
Lifeng Huang, Yuquan Lin, Chen Wan, Fang Shi, Shaojian Qiu, Qiong Huang 0001
IEEE Trans. Inf. Forensics Secur.1
2025 AUTE: Peer-Alignment and Self-Unlearning Boost Adversarial Robustness for Training Ensemble Models
abstract
Adversarial attacks poses a significant threat to the security of AI-based systems. To counteract these attacks, adversarial training (AT) and ensemble learning (EL) have emerged as widely adopted methods for enhancing model robustness. However, a counter-intuitive phenomenon arises where the simple combination of these approaches may potentially compromising adversarial robustness of ensemble models. In this paper, we propose a novel method called Alignment and Unlearning for Training Ensembles (AUTE), aiming to effectively integrate AT and EL to maximize their benefits. Specifically, AUTE incorporates two key components. Firstly, AUTE divides the ensemble into a big peer model and a single member in a loop manner, aligning their outputs for boosting robustness of each member. Secondly, AUTE introduces the concept of unlearning, actively forgetting specific data with over-confident properties to preserve model capacity to learn more robust features. Extensive experiments across various datasets and networks illustrate that AUTE achieves superior performance compared to baselines. For instance, a 5-member AUTE with ResNet-20 networks outperforms state-of-the-art method by 2.1% and 3.2% in classifying clean and adversarial data. Additionally, AUTE can easily extend to non-adversarial training paradigm, surpassing current standard ensemble learning methods by a large margin.
Lifeng Huang, Tian Su, Chengying Gao, Qiong Huang 0001
AAAI1
2025 Improving the Adversarial Transferability via Histogram Transformation
abstract
The transferability of adversarial examples poses a critical security threat to deep neural networks, since the adversarial examples crafted for one model can deceive other models, even without knowledge of their architecture or parameters. Among various approaches, data augmentation is one of the most effective strategies to improve transferability. In this letter, we propose a new data augmentation technique, termed the Histogram Transform Method (HTM). The proposed method extracts histograms from each RGB channel of the input image, applies shuffling, shifting, and stretching transformations, and constructs augmented examples through histogram matching and channel merging. By combining the gradients of the loss function with respect to both the augmented and input examples, we determine the adversarial perturbations needed to generate adversarial examples. Extensive experiments demonstrate that HTM enhances transferability and remains highly compatible with existing data augmentations, resulting in higher attack success rates across multiple black-box models. The source code is publicly available athttps://github.com/xiaohailu1024/HTM.
Xiaohai Lu, Chen Wan, Lifeng Huang
IEEE Signal Process. Lett.3
2025 Feature Extraction and Compliance Classification of Text Files Using Large Language Models
abstract
In industries such as finance, healthcare, and new energy vehicles, data classification and grading standards ensure regulatory compliance and protect sensitive information. However, automating text file classification under these standards presents several challenges. Traditional machine learning and deep learning approaches require large labeled datasets, which are often scarce. Existing classification methods are typically domain-specific, limiting cross-domain adaptability. Moreover, many approaches simply categorize documents as regulatory or nonregulatory and assign security levels, but fail to map them accurately to specific rules. To address these challenges, this article proposes prompt-driven grading and classification algorithm (PGCA), a prompt learning-based method for text classification and grading. PGCA integrates a structured feature repository and SQL-inspired prompt templates to efficiently extract and match features from text documents, establishing mappings between text, and classification rules and grading standards. Furthermore, the integration of a preclassification strategy enables the filtration of irrelevant rules, thereby substantially reducing computational overhead. Experiments show that PGCA achieves classification accuracy between 95.0% and 99.0%, outperforming baselines such as TsF-KNN, Gen-DT, bt-SVM, AGCRCNN, and AC-BiLSTM by 4%–25%. Additionally, the preclassification stage cuts computational costs by 63.7% while keeping accuracy loss to within 1%.
Xiang Liu 0020, Yanghao Liao, Zusheng Zhang 0001, Jingcheng Hu, Lifeng Huang
IEEE Trans. Comput. Soc. Syst.5
2024 Boosting Imperceptibility of Adversarial Attacks for Environmental Sound Classification
abstract
As artificial intelligence (AI) continues to advance, AI-based audio systems are becoming increasingly vulnerable to adversarial attacks. However, most current studies overlook the scenes of environmental sounds and the imperceptibility of attack. In response to these, we propose a novel frequency-weighted perturbation algorithm for environmental sounds called the Frequency Psychological Attack Algorithm (FPAA). This innovative algorithm incorporates auditory thresholds with psychoacoustic principles during the perturbation generation process to create highly imperceptible adversarial examples. Extensive experiments conducted on two public datasets using multiple models demonstrate that our FPAA algorithm can produce adversarial audio examples that are not only imperceptible to the human ear but also maintain high offensive capability against AI-based audio systems.
Shaojian Qiu, Xiaokang You, Wei Rong, Lifeng Huang, Yun Liang 0003
ICTAI4
2024 LAFED: Towards robust ensemble models via Latent Feature Diversification
Wenzi Zhuang, Lifeng Huang, Chengying Gao
Pattern Recognit.2
2024 FASTEN: Fast Ensemble Learning for Improved Adversarial Robustness
abstract
Recent works show that adversarial attacks threaten the security of deep neural networks (DNNs). To tackle this issue, ensemble learning methods have been proposed to train multiple sub-models and improve adversarial resistance without compromising accuracy. However, these methods often come with high computational costs, including multi-step optimization to generate high-quality augmentation data and additional network passes to optimize complicated regularization. In this paper, we present the FAST ENsemble learning method (FASTEN) to significantly reduce training costs in terms of data and optimization. Firstly, FASTEN employs a single-step technique to initialize poor augmentation data and recycles optimization knowledge to enhance data quality, which considerably reduces the data generation budget. Secondly, FASTEN introduces a low-cost regularizer to increase intra-model similarity and inter-model diversity, with most of the regularization components computed without network passes, further decreasing training costs. Empirical results on various datasets and networks demonstrate that FASTEN achieves higher robustness while requiring significantly fewer resources than current methods. For example, a 5-member FASTEN speeds up the optimization process by$7\times $and$28\times $compared to state-of-the-art DVERGE and TRS, respectively. Moreover, FASTEN outperforms the stronger of the two methods by 26.3% and 6.1% under black-box and white-box attacks, respectively. FASTEN is also compatible with existing fast adversarial training techniques, making it an advantageous choice for enhancing robustness without incurring excessive costs. The source code is publicly available athttps://github.com/mesunhlf/FASTEN.
Lifeng Huang, Qiong Huang 0001, Peichao Qiu, Shuxin Wei, Chengying Gao
IEEE Trans. Inf. Forensics Secur.1
2024 DanceComposer: Dance-to-Music Generation Using a Progressive Conditional Music Generator
abstract
A wonderful piece of music is the essence and soul of dance, which motivates the study of automatic music generation for dance. To create appropriate music from dance, cross-modal correlations between dance and music such as rhythm and style, should be considered. However, existing dance-to-music methods have difficulties in achieving rhythmic alignment and stylistic matching simultaneously. Additionally, the diversity of generated samples is limited due to the lack of available paired data. To address these issues, we propose DanceComposer, a novel dance-to-music framework, which generates rhythmically and stylistically consistent multi-track music from dance videos. DanceComposer features a Progressive Conditional Music Generator (PCMG) that gradually incorporates rhythm and style constraints, enabling both rhythmic alignment and stylistic matching. To enhance style control, we introduce a Shared Style Module (SSM) that learns cross-modal features as stylistic constraints. This allows the PCMG can be trained on extensive music-only data and diversifies generated pieces. Quantitative and qualitative results show that our method surpasses the state-of-the-art in overall music quality, rhythmic consistency, and stylistic consistency.
Lifeng Huang, Chengying Gao
IEEE Trans. Multim.3
2023 Erosion Attack: Harnessing Corruption To Improve Adversarial Examples
abstract
Although adversarial examples pose a serious threat to deep neural networks, most transferable adversarial attacks are ineffective against black-box defense models. This may lead to the mistaken belief that adversarial examples are not truly threatening. In this paper, we propose a novel transferable attack that can defeat a wide range of black-box defenses and highlight their security limitations. We identify two intrinsic reasons why current attacks may fail, namely data-dependency and network-overfitting. They provide a different perspective on improving the transferability of attacks. To mitigate the data-dependency effect, we propose the Data Erosion method. It involves finding special augmentation data that behave similarly in both vanilla models and defenses, to help attackers fool robustified models with higher chances. In addition, we introduce the Network Erosion method to overcome the network-overfitting dilemma. The idea is conceptually simple: it extends a single surrogate model to an ensemble structure with high diversity, resulting in more transferable adversarial examples. Two proposed methods can be integrated to further enhance the transferability, referred to as Erosion Attack (EA). We evaluate the proposed EA under different defenses that empirical results demonstrate the superiority of EA over existing transferable attacks and reveal the underlying threat to current robust models. The source code is publicly available at https://github.com/mesunhlf/EA.
Lifeng Huang, Chengying Gao
IEEE Trans. Image Process.1
2022 DEFEAT: Decoupled feature attack across deep neural networks
Lifeng Huang, Chengying Gao
Neural Networks1
2022 Cyclical Adversarial Attack Pierces Black-box Deep Neural Networks
Lifeng Huang, Shuxin Wei, Chengying Gao
Pattern Recognit.1
2021 Enhancing Adversarial Examples Via Self-Augmentation
abstract
Recently, adversarial attacks pose a challenge for the security of Deep Neural Networks, which motivates researchers to establish various defense methods. However, do current defenses really achieve real security? To answer the question, we propose self-augmentation method (SA) for circumventing defenders to transferable adversarial examples. Concretely, self-augmentation includes two strategies: (1) self-ensemble, which applies additional convolution layers to an existing model to build diverse virtual models that be fused for achieving an ensemble-model effect and preventing overfitting; and (2) deviation-augmentation, which based on the observation of defense models that the input data is surrounded by highly curved loss surfaces, thus inspiring us to apply deviation vectors to input data for escaping from their vicinity space. Extensive experiments conducted on four vanilla models and ten defenses suggest the superiority of our method compared with the state-of-the-art transferable attacks. The source code is public available at https://github.com/zhuangwz/ICME2021_self_augmentation.
Lifeng Huang, Chengying Gao, Wenzi Zhuang
ICME1
2020 Universal Physical Camouflage Attacks on Object Detectors
abstract
In this paper, we study physical adversarial attacks on object detectors in the wild. Previous works mostly craft instance-dependent perturbations only for rigid or planar objects. To this end, we propose to learn an adversarial pattern to effectively attack all instances belonging to the same object category, referred to as Universal Physical Camouflage Attack (UPC). Concretely, UPC crafts camouflage by jointly fooling the region proposal network, as well as misleading the classifier and the regressor to output errors. In order to make UPC effective for non-rigid or non-planar objects, we introduce a set of transformations for mimicking deformable properties. We additionally impose optimization constraint to make generated patterns look natural to human observers. To fairly evaluate the effectiveness of different physical-world attacks, we present the first standardized virtual database, AttackScenes, which simulates the real 3D world in a controllable and reproducible environment. Extensive experiments suggest the superiority of our proposed UPC compared with existing physical adversarial attackers not only in virtual environments (AttackScenes), but also in real-world physical environments.
Lifeng Huang, Chengying Gao, Yuyin Zhou, Cihang Xie, Alan L. Yuille, Changqing Zou
CVPR1
2020 Scale-aware Progressive Optimization Network
abstract
Crowd counting has attracted increasing attention due to its wide application prospect. One of the most essential challenge in this domain is large scale variation, which impacts the accuracy of density estimation. To this end, we propose a scale-aware progressive optimization network (SPO-Net) for crowd counting, which trains a scale adaptive network to achieve high-quality density map estimation and overcome the variable scale dilemma in highly congested scenes. Concretely, the first phase of SPO-Net, band-pass stage, mainly concentrates on preprocessesing the input image and fusing both high-level semantic information and low-level spatial information from separated multi-layer features. And the second phase of SPO-Net, rolling guidance stage, aims to learn a scale-adapted network from multi-scale features as well as rolling training manner. For better learning local correlation of multi-size regions and reducing redundant calculations, we introduce a progressive optimization strategy. Extensive experiments on three challenging crowd counting datasets not only demonstrate the efficacy of each part in SPO-Net, but also suggest the superiority of our proposed method compared with the state-of-the-art approaches.
Lifeng Huang, Chengying Gao
ACM Multimedia2
2019 G-UAP: Generic Universal Adversarial Perturbation that Fools RPN-based Detectors
abstract
Adversarial perturbation constructions have been demonstrated for object detection, but these are image-specific perturbations. Recent works have shown the existence of image-agnostic perturbations called universal adversarial perturbation (UAP) that can fool the classifiers over a set of natural images. In this paper, we extend this kind perturbation to attack deep proposal-based object detectors. We present a novel and effective approach called G-UAP to craft universal adversarial perturbations, which can explicitly degrade the detection accuracy of a detector on a wide range of image samples. Our method directly misleads the Region Proposal Network (RPN) of the detectors into mistaking foreground (objects) for background without specifying an adversarial label for each target (RPN’s proposal), and even without considering that how many objects and object-like targets are in the image. The experimental results over three state-of-the-art detectors and two datasets demonstrate the effectiveness of the proposed method and transferability of the universal perturbations.
Lifeng Huang, Chengying Gao
ACML2
2015 Associating sentimental orientation of Chinese neologism in social media data
abstract
Sentiment analysis has always found its practical use in collecting people's preferences towards any subject in the context of social media. Unlike normal words available in dictionaries, neologisms are not easy to be labeled with a sentimental orientation while they have been widely used in conveying people's feelings and opinions. In order to conduct a reliable sentiment analysis for neologisms, a neologism discovery method is first required. Next, a sentimental analysis based on the discovery results can be performed. This paper proposes a 2-step novel solution by having a Chinese neologism discovery method and then a sentimental orientation determination algorithm based on varied TF-IDF. For neologism discovery, statistical data include frequency, duration of appearance and the number of users using a neologism. For sentimental orientation determination, we consider keyword term frequency, and document frequency together and use a varied TF-IDF algorithm. The preliminary experimental results show good precision rate and recall rates for a collection of social media data in both neologism discovery and sentimental analysis.
Lifeng Huang, Vincent T. Y. Ng
CSCWD1