VLDB 2026 Research / reviewers in the wild / expert
Jindong Wang 0002
dblp:19/2969-2
· DBLP profile ↗
8ranked-venue papers
0as first author
7since 2021 · last 2026
0000-0002-7641-9014ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Rethinking adversarial transferability from a random and average perspectiveabstractAbstract Deep learning models are vulnerable to adversarial examples generated by adding imperceptible perturbations to original images. Transfer-based adversarial attacks have attracted tremendous attention as they can utilize adversarial examples crafted on surrogate models to mislead target models. An effective strategy to boost adversarial transferability is to create diverse input patterns through input transformation. However, previous works rely on probability to control the diverse input patterns, ignoring the influence of randomness brought by probability on transferability. In this work, we rethink the randomness in these input transformation methods and identify the flaw of excessive randomness, which affects further improvement of transferability. From a statistical perspective, we propose a gradient average attack, which approximates the expected value of gradients by averaging multiple gradients, alleviating the impact of excessive randomness, and generating more transferable adversarial examples. Extensive experiments on the ImageNet dataset demonstrate that our method can remarkably enhance the input transformation attacks of multiple random transformation forms (e.g. resizing and padding, cropping, rotation, translation etc.) and gains heightened transferability. In addition, our method can be seamlessly incorporated with many existing attack methods to further achieve higher attack success rates. Moreover, when attacking a practical image recognition system on the Baidu AI Cloud, the 83.0% attack success rate reveals that real-world-implemented intelligent systems are subject to serious security threats. Bo Yang 0049, Hengwei Zhang, Jindong Wang 0002 |
Comput. J. | 3 |
| 2025 | Adversarial Example Soups: Improving Transferability and Stealthiness for FreeabstractTransferable adversarial examples cause practical security risks since they can mislead a target model without knowing its internal knowledge. A conventional recipe for maximizing transferability is to keep only the optimal adversarial example from all those obtained in the optimization pipeline. In this paper, for the first time, we revisit this convention and demonstrate that those discarded, sub-optimal adversarial examples can be reused to boost transferability. Specifically, we propose “Adversarial Example Soups” (AES), with AES-tune for averaging discarded adversarial examples in hyperparameter tuning and AES-rand for stability testing. In addition, our AES is inspired by “model soups”, which averages weights of multiple fine-tuned models for improved accuracy without increasing inference time. Extensive experiments validate the global effectiveness of our AES, boosting 10 state-of-the-art transfer attacks and their combinations by up to 13% against 10 diverse (defensive) target models. We also show the possibility of generalizing AES to other types, e.g., directly averaging multiple in-the-wild adversarial examples that yield comparable success. A promising byproduct of AES is the improved stealthiness of adversarial examples since the perturbation variances are naturally reduced. Bo Yang 0049, Hengwei Zhang, Jindong Wang 0002, Yulong Yang 0002, Chenhao Lin, Chao Shen 0001, Zhengyu Zhao 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2023 | Adversarial example generation with adabelief optimizer and crop invariance
Bo Yang 0049, Hengwei Zhang, Zheming Li, Kaiyong Xu, Jindong Wang 0002 |
Appl. Intell. | 6 |
| 2023 | A differential game approach for real-time security defense decision in scale-free networks
Hengwei Zhang, Jindong Wang 0002, Jinglei Tan |
Comput. Networks | 5 |
| 2023 | Security defense decision method based on potential differential game for complex networksabstractMost defense strategies in complex networks are developed from the defense perspective, overlooking the key attack-defense characteristics in cybersecurity. A defense decision algorithm is ineffective when dealing with dynamic attacking behaviors, and when based on attack-defense analysis, stochastic uniform network models are generally used to model the target network, while most networks are large and complex. Thus, the algorithms and their results do not well suit small-world, scale-free, and high-aggregation networks. In this study, considering the structural characteristics of complex networks and the attack-defense characteristics of cybersecurity, potential differential game theory is integrated with complex networks, and a global optimal defense decision algorithm is proposed according to the overall network defense objective. Based on the evolutionary analysis of network security states, a network attack-defense potential differential game model is constructed. Adversarial analysis is carried out on the overall attack-defense strategy, and a defense decision algorithm is designed based on a saddle point equilibrium strategy. Simulation tests are carried out on small-world and scale-free networks to evaluate the effectiveness of the proposed method by comparing its performance with that of random defense strategies and classic decision algorithms. Hengwei Zhang, Yumeng Fu, Jindong Wang 0002, Jinglei Tan |
Comput. Secur. | 6 |
| 2021 | Optimal Network Defense Strategy Selection Method: A Stochastic Differential Game ModelabstractIn a real-world network confrontation process, attack and defense actions change rapidly and continuously. The network environment is complex and dynamically random. Therefore, attack and defense strategies are inevitably subject to random disturbances during their execution, and the transition of the network security state is affected accordingly. In this paper, we construct a network security state transition model by referring to the epidemic evolution process, use Gaussian noise to describe random effects during the strategy execution, and introduce a random disturbance intensity factor to describe the degree of random effects. On this basis, we establish an attack-defense stochastic differential game model, propose a saddle point equilibrium solution method, and provide an algorithm to select the optimal defense strategy. Our method achieves real-time defense decision-making in network attack-defense scenarios with random disturbances and has better real-time performance and practicality than current methods. Results of a simulation experiment show that our model and algorithm are effective and feasible. Hengwei Zhang, Hao Hu 0005, Jinglei Tan, Jindong Wang 0002 |
Secur. Commun. Networks | 5 |
| 2021 | Boosting Adversarial Attacks on Neural Networks with Better OptimizerabstractConvolutional neural networks have outperformed humans in image recognition tasks, but they remain vulnerable to attacks from adversarial examples. Since these data are crafted by adding imperceptible noise to normal images, their existence poses potential security threats to deep learning systems. Sophisticated adversarial examples with strong attack performance can also be used as a tool to evaluate the robustness of a model. However, the success rate of adversarial attacks can be further improved in black-box environments. Therefore, this study combines a modified Adam gradient descent algorithm with the iterative gradient-based attack method. The proposed Adam iterative fast gradient method is then used to improve the transferability of adversarial examples. Extensive experiments on ImageNet showed that the proposed method offers a higher attack success rate than existing iterative methods. By extending our method, we achieved a state-of-the-art attack success rate of 95.0% on defense models. Hengwei Zhang, Jindong Wang 0002, Ruiyu Dou |
Secur. Commun. Networks | 3 |
| 2018 | Diversified recommendation method combining topic model and random walk
Hengwei Zhang, Jindong Wang 0002 |
Multim. Tools Appl. | 3 |