VLDB 2026 Research / reviewers in the wild / expert
Mengnan Zhao 0001
dblp:173/2819-1
· DBLP profile ↗
13ranked-venue papers
8as first author
13since 2021 · last 2026
0000-0001-8319-4266ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 7 · 6 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 2 first-author · 5 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | EipFormer: Enhancing 3D instance segmentation by emphasizing instance positions
Mengnan Zhao 0001, Lihe Zhang, Yuqiu Kong |
Expert Syst. Appl. | 1 |
| 2026 | Stealthy Backdoor Carriers: The Threat of Visual Prompts to CLIPabstractVisual Prompt (VP) learning has rapidly emerged as a popular paradigm for parameter-efficient task adaptation in CLIP-based models. However, while VP optimizes pixel-space vectors without altering CLIP’s internal weights, this decoupled design inadvertently introduces critical security vulnerabilities. Attackers can exploit VP to implant covert backdoors using imperceptible trigger patterns that bypass traditional anomaly detection mechanisms, posing significant risks to real-world applications. Existing backdoor techniques, however, rely on visually noticeable patterns and exhibit inconsistencies in representation alignment, which make them prone to detection and ineffective against robust defenses. In response to these limitations, we propose Stealthy Backdoor Carriers (SBC), a novel attack framework that leverages CLIP’s inherent vulnerabilities to covertly and persistently inject backdoors.SBCadopts a dual-constrained optimization strategy that balances imperceptibility—minimizing trigger perturbations for visual stealth—and cross-modal embedding alignment—ensuring poisoned and target samples share consistent representations within CLIP’s multimodal space. Experimental results across five benchmark datasets demonstrateSBC’s exceptional effectiveness, achieving a +49.63% improvement in attack success rate relative to existing methods while maintaining robustness against advanced defenses like Neural Cleanse. Our work highlights the need for reevaluating the security implications of VP learning frameworks and provides valuable insights for mitigating prompt-based vulnerabilities in AI systems. Our code is available at https://github.com/Maozhen-Zhang/sbc.git. Maozhen Zhang, Mengnan Zhao 0001, Wei Wang 0025, Bo Wang 0024 |
IEEE Internet Things J. | 2 |
| 2026 | DualVeil: Persistent and invisible backdoor attacks in federated learning via dual optimization
Maozhen Zhang, Mengnan Zhao 0001, Wei Wang 0025, Bo Wang 0024 |
Knowl. Based Syst. | 2 |
| 2025 | CollabLearn: Propelling Weakly-Supervised Referring Image Segmentation Through Collaboration Between Semantics and DetailsabstractThis work presents a weakly supervised referring image segmentation method, namedCollabLearn, that segments objects described by free-form referring expression utilizing solely image-text pairs. Existing methods suffer from incorrect localization of referring expressions due to the lack of high-level semantics in cross-modal alignment or rough segmentation of referenced objects stemming from the absence of low-level details. To address these issues, we propose an innovative framework for generating cross-modal features encompassing both high-level semantics and low-level details via two fusion modules: a semantic awareness module and a detail cognition module. Each of these modules generates an activation map, and they mutually correct each other through a collaborative learning strategy. Specifically, the semantic awareness module performs in-depth cross-modal interaction and achieves accurate localization in a top-down manner. The detail cognition module facilitates the segmentation of entire objects in a bottom-up manner. A collaborative learning strategy is designed to enable interaction between these two modules, enforcing sufficient vision-language alignment. Experiments on three benchmarks demonstrate that CollabLearn consistently outperforms state-of-the-art weakly supervised methods. Yuqiu Kong, Mengnan Zhao 0001, Lihe Zhang |
IEEE Trans. Multim. | 3 |
| 2024 | Catastrophic Overfitting: A Potential Blessing in Disguise
Mengnan Zhao 0001, Lihe Zhang, Yuqiu Kong |
ECCV (42) | 1 |
| 2024 | Class correlation correction for unbiased scene graph generation
Mengnan Zhao 0001, Yuqiu Kong, Lihe Zhang |
Pattern Recognit. | 1 |
| 2024 | Adversarial Attacks on Scene Graph GenerationabstractScene graph generation (SGG) effectively improves semantic understanding of the visual world. However, the recent interest of researchers focuses on enhancing SGG in non-adversarial settings, which raises our curiosity about the adversarial robustness of SGG models. To bridge this gap, we perform adversarial attacks on two typical SGG tasks, Scene Graph Detection (SGDet) and Scene Graph Classification (SGCls). Specifically, we initially propose a bounding box relabeling method to reconstruct reasonable attack targets for SGCls. It solves the inconsistency between the specified bounding boxes and the scene graphs selected as attack targets. Subsequently, we introduce a two-step weighted attack by removing the predicted objects and relational triples that affect attack performance, which significantly increases the success rate of adversarial attacks on two SGG tasks. Extensive experiments demonstrate the effectiveness of our methods on five popular SGG models and four adversarial attacks. The Pytorch® implementation can be downloaded from an open-source Github project https://github.com/Dlut-lab-zmn/SGG_Attack. Mengnan Zhao 0001, Lihe Zhang, Wei Wang 0025, Yuqiu Kong |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Fast Adversarial Training with Smooth ConvergenceabstractFast adversarial training (FAT) is beneficial for improving the adversarial robustness of neural networks. However, previous FAT work has encountered a significant issue known as catastrophic overfitting when dealing with large perturbation budgets, i.e. the adversarial robustness of models declines to near zero during training. To address this, we analyze the training process of prior FAT work and observe that catastrophic overfitting is accompanied by the appearance of loss convergence outliers. Therefore, we argue a moderately smooth loss convergence process will be a stable FAT process that solves catastrophic overfitting. To obtain a smooth loss convergence process, we propose a novel oscillatory constraint (dubbed ConvergeSmooth) to limit the loss difference between adjacent epochs. The convergence stride of ConvergeSmooth is introduced to balance convergence and smoothing. Likewise, we design weight centralization without introducing additional hyperparameters other than the loss balance coefficient. Our proposed methods are attack-agnostic and thus can improve the training stability of various FAT techniques. Extensive experiments on popular datasets show that the proposed methods efficiently avoid catastrophic overfitting and outperform all previous FAT methods. Code is available at https://github.com/FAT-CS/ConvergeSmooth. Mengnan Zhao 0001, Lihe Zhang, Yuqiu Kong |
ICCV | 1 |
| 2023 | Temporal knowledge graph reasoning triggered by memories
Mengnan Zhao 0001, Lihe Zhang, Yuqiu Kong |
Appl. Intell. | 1 |
| 2023 | Protecting by attacking: A personal information protecting method with cross-modal adversarial examples
Mengnan Zhao 0001, Bo Wang 0024, Weikuo Guo, Wei Wang 0025 |
Neurocomputing | 1 |
| 2022 | Guided Erasable Adversarial Attack (GEAA) Toward Shared Data ProtectionabstractIn recent years, there has been increasing interest in studying the adversarial attack, which poses potential risks to deep learning applications and has stimulated numerous researches, e.g. improving the robustness of deep neural networks. In this work, we propose a novel double-stream architecture – Guided Erasable Adversarial Attack (GEAA) – for protecting high-quality labeled data with high commercial values under data-sharing scenarios. GEAA contains three phases, the double-stream adversarial attack, denoising reconstruction, and watermark extraction. Specifically, the double-stream adversarial attack injects erasable perturbations into the training data to avoid database abuse. The denoising reconstruction rebuilds the traceable denoising data from adversarial examples. The watermark extraction recovers identity information from the denoised data for copyright protection. Additionally, we introduce the annealing optimization strategy to balance these phases and a boundary constraint to degrade the availability of adversarial examples. Through extensive experiments, we demonstrate the effectiveness of the proposed framework in data protection. The Pytorch® implementations of GEAA can be downloaded from an open-source Github project https://github.com/Dlut-lab-zmn/ GEAA-for-data-protection. Mengnan Zhao 0001, Bo Wang 0024, Wei Wang 0025, Yuqiu Kong, Tianhang Zheng, Kui Ren 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2021 | Adversarial Analysis for Source Camera IdentificationabstractRecent studies highlight the vulnerability of convolutional neural networks (CNNs) to adversarial attacks, which also calls into question the reliability of forensic methods. Existing adversarial attacks generate one-to-one noise, which means these methods have not learned the fingerprint information. Therefore, we introduce two powerful attacks, fingerprint copy-move attack, and joint feature-based auto-learning attack. To validate the performance of attack methods, we move a step ahead and introduce the higher possible defense mechanism relation mismatch. which expands the characterization differences of classifiers in the same classification network. Extensive experiments show that relation mismatch is superior in recognizing adversarial examples and prove that the proposed fingerprint-based attacks are more powerful. Both proposed attacks show excellent attack transferability to unknown samples. The Pytorch® implementations of these methods can download from an open-source GitHub projecthttps://github.com/Dlut-lab-zmn/Source-attack. Bo Wang 0024, Mengnan Zhao 0001, Wei Wang 0025, Xiaorui Dai, Yi Li 0018, Yanqing Guo |
IEEE Trans. Circuits Syst. Video Technol. | 2 |
| 2021 | Are You Confident That You Have Successfully Generated Adversarial Examples?abstractDeep neural networks (DNNs) have seen extensive studies on image recognition and classification, image segmentation, and related topics. However, recent studies show that DNNs are vulnerable in defending adversarial examples. The classification network can be deceived by adding a small amount of perturbation to clean samples. There are challenges when researchers want to design a general approach to defend against a wide variety of adversarial examples. To solve this problem, we introduce a defensive method to prevent adversarial examples from generating. Instead of designing a stronger classifier, we built a more robust classification system that can be viewed as a structural black box. After adding a buffer to the classification system, attackers can be efficiently deceived. The real evaluation results of the generated adversarial examples are often contrary to what the attacker thinks. Additionally, we do not assume a specific attack method premise. This incognizance to underlying attacks demonstrates the generalizability of the buffer to potential adversarial attacks. Extensive experiments indicate that the defense method greatly improves the security performance of DNNs. Bo Wang 0024, Mengnan Zhao 0001, Wei Wang 0025, Fei Wei, Zhan Qin, Kui Ren 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 2 |