VLDB 2026 Research / reviewers in the wild / expert
Xingjun Ma
dblp:195/8270
· DBLP profile ↗
105ranked-venue papers
9as first author
80since 2021 · last 2026
0000-0003-2099-4973ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 71 · 7 first-author · 53 since 2021Graphics, computer vision, multimedia, augmented reality and games · 40 · 3 first-author · 28 since 2021Databases, data management, data science and information retrieval · 8 · 7 since 2021Applied, interdisciplinary, general and emerging computing · 8 · 2 first-author · 2 since 2021Security and privacy · 6 · 6 since 2021Human-computer interaction and ubiquitous computing · 5 · 1 first-authorSystems, architecture and hardware · 2 · 1 since 2021Software engineering, systems software and programming languages · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SIDE: Surrogate Conditional Data Extraction from Diffusion ModelsabstractAs diffusion probabilistic models (DPMs) become central to Generative AI (GenAI), understanding their memorization behavior is essential for evaluating risks such as data leakage, copyright infringement, and trustworthiness. While prior research finds conditional DPMs highly susceptible to data extraction attacks using explicit prompts, unconditional models are often assumed to be safe. We challenge this view by introducing Surrogate condItional Data Extraction (SIDE), a general framework that constructs data-driven surrogate conditions to enable targeted extraction from any DPM. Through extensive experiments on CIFAR-10, CelebA, ImageNet, and LAION-5B, we show that SIDE can successfully extract training data from so-called safe unconditional models, outperforming baseline attacks even on conditional models. Complementing these findings, we present a unified theoretical framework based on informative labels, demonstrating that all forms of conditioning, explicit or surrogate, amplify memorization. Our work redefines the threat landscape for DPMs, establishing precise conditioning as a fundamental vulnerability and setting a new, stronger benchmark for model privacy evaluation. Difan Zou, Xingjun Ma |
AAAI | 4 |
| 2026 | Coarse-to-Fine Open-Set Graph Node Classification with Large Language ModelsabstractDeveloping open-set classification methods capable of classifying in-distribution (ID) data while detecting out-of-distribution (OOD) samples is essential for deploying graph neural networks (GNNs) in open-world scenarios. Existing methods typically treat all OOD samples as a single class, despite real-world applications—especially high-stake settings like fraud detection and medical diagnosis—demanding deeper insights into OOD samples, including their probable labels. This raises a critical question: Can OOD detection be extended to OOD classification without true label information? To answer this question, we introduce a Coarse-to-Fine open-set Classification (CFC) method that leverages large language models (LLMs) for text-attributed graphs. CFC consists of three key components: (1) A coarse classifier that utilizes LLM prompts for OOD detection and outlier label generation; (2) A GNN-based fine classifier trained with OOD samples from (1) for enhanced OOD detection and ID classification; and (3) Refined OOD classification achieved through LLM prompts and post-processed OOD labels. Unlike methods relying on synthetic or auxiliary OOD samples, CFC employs semantic OOD data-instances that are genuinely out-of-distribution based on their inherent meaning, thus improving interpretability and practical utility. CFC enhances OOD detection by 10% compared to state-of-the-art approaches on text-attributed graphs and in the text domain, while achieving up to 70% accuracy in OOD classification on graph datasets. Xueqi Ma, Xingjun Ma, Sarah M. Erfani, Danilo P. Mandic, James Bailey 0001 |
AAAI | 2 |
| 2026 | Deliberative Searcher: Improving LLM Reliability via Reinforcement Learning with ConstraintsabstractLarge language models with search capabilities frequently exhibit miscalibrated confidence, producing incorrect answers with high certainty.We present Deliberative Searcher, a reasoning-primary framework that integrates search operations into chain-of-thought generation while maintaining explicit confidence calibration.Our method employs constrained reinforcement learning with adaptive Lagrangian multipliers to jointly optimize correctness and reliability.Experiments across five benchmarks demonstrate substantial improvements: our 7B model reduces average false-certain rates from 54% in baselines to 2%, while our 72B variant achieves competitive accuracy with closedsource models and reduces false-certain rates to 9%.The well-calibrated confidence scores also enable more efficient test-time compute: instead of standard majority voting, we use confidence-weighted aggregation and match the performance of 16-sample majority voting with only 4 samples, a 4× reduction in inference compute.These results establish calibrated confidence as a foundation for both trustworthy outputs and adaptive test-time compute, demonstrating the value of the proposed constrained RL framework in search-augmented language models. Zhenyun Yin, Xuhong Wang, Xingjun Ma, Yingchun Wang 0004 |
ACL (1) | 4 |
| 2026 | PaperAsk: A Benchmark for Reliability Evaluation of LLMs in Paper Search and ReadingabstractLarge Language Models (LLMs) increasingly serve as research assistants, yet their reliability in scholarly tasks remains under-evaluated. In this work, we introduce PaperAsk, a benchmark that systematically evaluates LLMs across four key research tasks: citation retrieval, content extraction, paper discovery, and claim verification. We evaluate GPT-4o, GPT-5, and Gemini-2.5-Flash under realistic usage conditions, using web interfaces where search operations are opaque to the user. Through controlled experiments, we find consistent reliability failures: citation retrieval fails in 48–98% of multi-reference queries, section-specific content extraction fails in 72–91% of cases, and topical paper discovery yields F1 scores below 0.32, missing over 60% of relevant literature. Further human analysis attributes these failures to the uncontrolled expansion of retrieved context and the tendency of LLMs to prioritize semantically relevant text over task instructions. Across basic tasks, the LLMs display distinct failure behaviors: ChatGPT often withholds responses rather than risk errors, whereas Gemini produces fluent but fabricated answers. To address these issues, we develop lightweight reliability classifiers trained on PaperAsk data to identify unreliable outputs. PaperAsk provides a reproducible and diagnostic framework for advancing the reliability evaluation of LLM-based scholarly assistance systems. The benchmark is publicly available at https://github.com/wuyoscar/PaperAsk. Yutao Wu 0004, Xiao Liu 0004, Yunhao Feng, Jiale Ding, Xingjun Ma |
WWW | 5 |
| 2026 | On the Adversarial Transferability of Generalized "Skip Connections"abstractSkip connection is an essential ingredient for modern deep models to be deeper and more powerful. Despite their huge success in normal scenarios (state-of-the-art classification performance on natural examples), we investigate and identify an interesting property of skip connections under adversarial scenarios, namely, the use of skip connections allows easier generation of highly transferable adversarial examples. Specifically, in ResNet-like models (with skip connections), we find that biasing backpropagation to favor gradients from skip connections-while suppressing those from residual modules via a decay factor-allows one to craft adversarial examples with high transferability. Based on this insight, we propose the Skip Gradient Method (SGM). Although starting from ResNet-like models in vision domains, we further extend SGM to more advanced architectures, including Vision Transformers (ViTs), models with varying-length paths, and other domains such as natural language processing. We conduct comprehensive transfer-based attacks against diverse model families, including ResNets, Transformers, Inceptions, Neural Architecture Search-based models, and Large Language Models (LLMs). The results demonstrate that employing SGM can greatly improve the transferability of crafted attacks in almost all cases. Furthermore, we demonstrate that SGM can still be effective under more challenging settings such as ensemble-based attacks, targeted attacks, and against defense equipped models. At last, we provide theoretical explanations and empirical insights on how SGM works. Our findings not only motivate new adversarial research into the architectural characteristics of models but also open up further challenges for secure model architecture design. Yisen Wang 0001, Yichuan Mo, Dongxian Wu, Mingjie Li 0007, Xingjun Ma, Zhouchen Lin |
IEEE Trans. Pattern Anal. Mach. Intell. | 5 |
| 2026 | NAP-Tuning: Neural Augmented Prompt Tuning for Adversarially Robust Vision-Language ModelsabstractVision-Language Models (VLMs) such as CLIP have demonstrated remarkable capabilities in understanding relationships between visual and textual data through joint embedding spaces. Despite their effectiveness, these models remain vulnerable to adversarial attacks, particularly in the image modality, posing significant security concerns. Building upon our previous work on Adversarial Prompt Tuning (AdvPT), which introduced learnable text prompts to enhance adversarial robustness in VLMs without extensive parameter training, we present a significant extension by introducing the Neural Augmentor framework for Multi-modal Adversarial Prompt Tuning (NAP-Tuning). As a significant extension, NAP-Tuning first establishes a comprehensive multi-modal (text and visual) and multi-layer prompting framework. The core of this framework is a targeted structural augmentation for feature-level purification, implemented through our Neural Augmentor approach. This framework implements feature purification by incorporating TokenRefiners-lightweight neural modules that learn to reconstruct purified features via residual connections-to directly address distortions in the feature space. This structural intervention is what enables the multi-modal and multi-layer system to effectively perform modality-specific and layer-specific feature rectification. Comprehensive experiments demonstrate that NAP-Tuning significantly outperforms existing methods across various datasets and attack types. Notably, our approach shows significant improvements over the strongest baselines under the challenging AutoAttack benchmark, outperforming them by 32.3% on ViT-B16 and 31.3% on ViT-B32 architectures while maintaining competitive clean accuracy. This work highlights the efficacy of internal feature-level intervention in prompt tuning for adversarial robustness, moving beyond input-side alignment approaches to create an adaptive defense mechanism that can identify and rectify adversarial perturbations across embedding spaces. Jiaming Zhang 0006, Xin Wang 0119, Xingjun Ma, Lingyu Qiu, Yu-Gang Jiang 0001, Jitao Sang 0001 |
IEEE Trans. Pattern Anal. Mach. Intell. | 3 |
| 2026 | Defense-to-attack: Bypassing weak defenses enables stronger jailbreaks in Vision-Language Models
Yunhan Zhao, Yige Li, Xingjun Ma |
Pattern Recognit. | 4 |
| 2026 | Shortcuts Everywhere and Nowhere: Exploring Multi-Trigger Backdoor AttacksabstractBackdoor attacks have become a significant threat to the pre-training and deployment of deep neural networks (DNNs). Although numerous methods for detecting and mitigating backdoor attacks have been proposed, most rely on identifying and eliminating the “shortcut” created by the backdoor, which links a specific source class to a target class. However, these approaches can be easily circumvented by designing multiple backdoor triggers that create shortcuts everywhere and therefore nowhere specific. In this study, we explore the concept of Multi-Trigger Backdoor Attacks (MTBAs), where multiple adversaries leverage different types of triggers to poison the same dataset. By proposing and investigating three types of multi-trigger attacks includingparallel,sequential, andhybridattacks, we demonstrate that 1) multiple triggers can coexist, overwrite, or cross-activate one another, and 2) MTBAs easily break the prevalent shortcut assumption underlying most existing backdoor detection/removal methods, rendering them ineffective. Given the security risk posed by MTBAs, we have created a multi-trigger backdoor poisoning dataset to facilitate future research on detecting and mitigating these attacks, and we also discuss potential defense strategies against MTBAs. Our code is available athttps://github.com/bboylyg/Multi-Trigger-Backdoor-Attacks. Yige Li, Jiabo He, Hanxun Huang, Jun Sun 0001, Xingjun Ma, Yu-Gang Jiang 0001 |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2025 | AIM: Additional Image Guided Generation of Transferable Adversarial AttacksabstractTransferable adversarial examples highlight the vulnerability of deep neural networks (DNNs) to imperceptible perturbations across various real-world applications. While there have been notable advancements in untargeted transferable attacks, targeted transferable attacks remain a significant challenge. In this work, we focus on generative approaches for targeted transferable attacks. Current generative attacks focus on reducing overfitting to surrogate models and the source data domain, but they often overlook the importance of enhancing transferability through additional semantics. To address this issue, we introduce a novel plug-and-play module into the general generator architecture to enhance adversarial transferability. Specifically, we propose a Semantic Injection Module (SIM) that utilizes the semantics contained in an additional guiding image to improve transferability. The guiding image provides a simple yet effective method to incorporate target semantics from the target class to create targeted and highly transferable attacks. Additionally, we propose new loss formulations that can integrate the semantic injection module more effectively for both targeted and untargeted attacks. We conduct comprehensive experiments under both targeted and untargeted attack settings to demonstrate the efficacy of our proposed approach. Xingjun Ma, Yu-Gang Jiang 0001 |
AAAI | 2 |
| 2025 | HoneypotNet: Backdoor Attacks Against Model ExtractionabstractModel extraction attacks are one type of inference-time attacks that approximate the functionality and performance of a black-box victim model by launching a certain number of queries to the model and then leveraging the model's predictions to train a substitute model. These attacks pose severe security threats to production models and MLaaS platforms and could cause significant monetary losses to the model owners. A body of work has proposed to defend machine learning models against model extraction attacks, including both active defense methods that modify the model's outputs or increase the query overhead to avoid extraction and passive defense methods that detect malicious queries or leverage watermarks to perform post-verification. In this work, we introduce a new defense paradigm called attack as defense which modifies the model's output to be poisonous such that any malicious users that attempt to use the output to train a substitute model will be poisoned. To this end, we propose a novel lightweight backdoor attack method dubbed HoneypotNet that replaces the classification layer of the victim model with a honeypot layer and then fine-tunes the honeypot layer with a shadow model (to simulate model extraction) via bi-level optimization to modify its output to be poisonous while remaining the original performance. We empirically demonstrate on four commonly used benchmark datasets that HoneypotNet can inject backdoors into substitute models with a high success rate. The injected backdoor not only facilitates ownership verification but also disrupts the functionality of substitute models, serving as a significant deterrent to model extraction attacks. Yixu Wang, Tianle Gu, Yan Teng 0002, Yingchun Wang 0004, Xingjun Ma |
AAAI | 5 |
| 2025 | CALM: Curiosity-Driven Auditing for Large Language ModelsabstractAuditing Large Language Models (LLMs) is a crucial and challenging task. In this study, we focus on auditing black-box LLMs without access to their parameters, only to the provided service. We treat this type of auditing as a black-box optimization problem where the goal is to automatically uncover input-output pairs of the target LLMs that exhibit illegal, immoral, or unsafe behaviors. For instance, we may seek a non-toxic input that the target LLM responds to with a toxic output or an input that induces the hallucinative response from the target LLM containing politically sensitive individuals. This black-box optimization is challenging due to the scarcity of feasible points, the discrete nature of the prompt space, and the large search space. To address these challenges, we propose Curiosity-Driven Auditing for Large Language Models (CALM), which uses intrinsically motivated reinforcement learning to finetune an LLM as the auditor agent to uncover potential harmful and biased input-output pairs of the target LLM. CALM successfully identifies derogatory completions involving celebrities and uncovers inputs that elicit specific names under the black-box setting. This work offers a promising direction for auditing black-box LLMs. Yi Liu 0057, Xingjun Ma, Chao Shen 0001, Cong Wang 0001 |
AAAI | 4 |
| 2025 | MMFair: Fair Learning via Min-Min OptimizationabstractEnsuring group fairness is crucial in applications like facial recognition, medical image analysis, and online comment toxicity classification. A key challenge to achieving group fairness arises from spurious correlations in datasets, where features used by models for predictions are unrelated to the true labels. The widespread use of large-scale pre-trained models as feature extractors, followed by fine-tuning for downstream tasks, can exacerbate this issue. In particular, improper fine-tuning on limited data often leads to overfitting, reinforcing spurious correlations and further undermining group fairness. To address this, we propose MMFair, an algorithm that optimizes perturbations through a min-min optimization approach. These perturbations are applied to the deep embeddings, preventing the model from associating irrelevant features with true labels, thus improving group fairness. Notably, since simple linear classifiers are prone to spurious correlations, we use a linear head in the initial stage to generate perturbations. After optimizing the perturbations in the latent space, we incorporate them into the original embeddings and then train a multi-layer perceptron (MLP) as the final classification head. This two-stage approach helps mitigate the bias problem of linear head, while leveraging the more powerful feature-learning capabilities of MLPs, leading to more stable and accurate classification results. We evaluate MMFair on the Waterbirds, CelebA, and ISIC datasets. The results show that MMFair improves the accuracy of the worst-performing group efficiently. Kejie Fang, Kun Zhai, Xingjun Ma |
CIKM | 3 |
| 2025 | TAPT: Test-Time Adversarial Prompt Tuning for Robust Inference in Vision-Language ModelsabstractLarge pre-trained Vision-Language Models (VLMs) such as CLIP have demonstrated excellent zero-shot generalizability across various downstream tasks. However, recent studies have shown that the inference performance of CLIP can be greatly degraded by small adversarial perturbations, especially its visual modality, posing significant safety threats. To mitigate this vulnerability, in this paper, we propose a novel defense method called Test-Time Adversarial Prompt Tuning (TAPT) to enhance the inference robustness of CLIP against visual adversarial attacks. TAPT is a test-time defense method that learns defensive bimodal (textual and visual) prompts to robustify the inference process of CLIP. Specifically, it is an unsupervised method that optimizes the defensive prompts for each test sample by minimizing a multi-view entropy and aligning adversarial-clean distributions. We evaluate the effectiveness of TAPT on 11 benchmark datasets, including ImageNet and 10 other zero-shot datasets, demonstrating that it enhances the zero-shot adversarial robustness of the original CLIP by at least 48.9% against AutoAttack (AA), while largely maintaining performance on clean examples. Moreover, TAPT outperforms existing adversarial prompt tuning methods across various backbones, achieving an average robustness improvement of at least 36.6%. Code is available at https://github.com/xinwong/TAPT. Xin Wang 0119, Kai Chen 0027, Jiaming Zhang 0006, Jingjing Chen 0001, Xingjun Ma |
CVPR | 5 |
| 2025 | Towards Million-Scale Adversarial Robustness Evaluation With Stronger Individual AttacksabstractAs deep learning models are increasingly deployed in safety-critical applications, evaluating their vulnerabilities to adversarial perturbations is essential for ensuring their reliability and trustworthiness. Over the past decade, a large number of white-box adversarial robustness evaluation methods (i.e., attacks) have been proposed, ranging from single-step to multi-step methods and from individual to ensemble methods. Despite these advances, challenges remain in conducting meaningful and comprehensive robustness evaluations, particularly when it comes to large-scale testing and ensuring evaluations reflect real-world adversarial risks. In this work, we focus on image classification models and propose a novel individual attack method, Probability Margin Attack (PMA), which defines the adversarial margin in the probability space rather than the logits space. We analyze the relationship between PMA and existing cross-entropy or logits-margin-based attacks, and show that PMA can outperform the current state-of-the-art individual methods. Building on PMA, we propose two types of ensemble attacks that balance effectiveness and efficiency. Furthermore, we create a million-scale dataset, CC1M, derived from the existing CC3M dataset, and use it to conduct the first million-scale white-box adversarial robustness evaluation of adversarially-trained ImageNet models. Our findings provide valuable insights into the robustness gaps between individual versus ensemble attacks and small-scale versus million-scale evaluations. Hanxun Huang, Guangnan Ye, Xingjun Ma |
CVPR | 5 |
| 2025 | Anyattack: Towards Large-scale Self-supervised Adversarial Attacks on Vision-language ModelsabstractDue to their multimodal capabilities, Vision-Language Models (VLMs) have found numerous impactful applications in real-world scenarios. However, recent studies have revealed that VLMs are vulnerable to image-based adversarial attacks. Traditional targeted adversarial attacks require specific targets and labels, limiting their real-world impact. We present AnyAttack, a self-supervised framework that transcends the limitations of conventional attacks through a novel foundation model approach. By pretraining on the massive LAION-400M dataset without label supervision, AnyAttack achieves unprecedented flexibility - enabling any image to be transformed into an attack vector targeting any desired output across different VLMs. This approach fundamentally changes the threat landscape, making adversarial capabilities accessible at an unprecedented scale. Our extensive validation across five open-source VLMs (CLIP, BLIP, BLIP2, InstructBLIP, and MiniGPT-4) demonstrates AnyAttack’s effectiveness across diverse multimodal tasks. Most concerning, Any-Attack seamlessly transfers to commercial systems including Google Gemini, Claude Sonnet, Microsoft Copilot and OpenAI GPT, revealing a systemic vulnerability requiring immediate attention. Jiaming Zhang 0006, Junhong Ye, Xingjun Ma, Yige Li, Yunfan Yang, Jitao Sang 0001, Dit-Yan Yeung |
CVPR | 3 |
| 2025 | Enhancing Federated Knowledge Distillation in Heterogeneous and Non-IID ScenariosabstractFederated Learning (FL) allows multiple participants to train models together while keeping their data private. Some FL frameworks use Knowledge Distillation to address model heterogenity, but many struggle in non-IID and heterogeneous environments, making it hard for clients to learn from each other. In this work, we show that the entropy of the softmax-averaged logits from clients reflects the model’s convergence. Based on this, we propose a new loss function, Sharpened Symmetric KL Divergence Loss (SSKL), which combines KL and Reverse KL Divergence with Label Sharpening to reduce the impact of non-IID data. Experiments demonstrate that our approach improves performance and reduces accuracy decline in non-IID and heterogeneous settings. Wenjie Lv, Xingjun Ma, Guangnan Ye, Hongfeng Chai |
ICASSP | 4 |
| 2025 | FedCAda: Adaptive Client-Side Optimization for Accelerated and Stable Federated LearningabstractFederated learning (FL) enables collaborative model training across distributed clients while preserving data privacy. However, achieving both acceleration and stability, particularly on the client side, remains a challenge. In this paper, we introduce FedCAda, an adaptive algorithm that leverages an Adam-like approach to adjust first and second moment estimates on the client side while aggregating adaptive parameters on the server side. This design aims to accelerate convergence without compromising stability and performance. We also explore several algorithms with different adjustment functions and find that stronger constraints on adaptive parameters are necessary in the early stages of FL, when information from other clients is limited. Experiments on public datasets demonstrate that FedCAda surpasses state-of-the-art methods in adaptability, convergence, and stability, advancing adaptive algorithms for FL. Liuzhi Zhou, Kun Zhai, Xingjun Ma, Guangnan Ye, Hongfeng Chai |
ICASSP | 6 |
| 2025 | Free-Form Motion Control: Controlling the 6D Poses of Camera and Objects in Video Generation
Xincheng Shuai, Henghui Ding, Zhenyuan Qin, Hao Luo 0004, Xingjun Ma, Dacheng Tao |
ICCV | 5 |
| 2025 | Ideator: Jailbreaking and Benchmarking Large Vision-Language Models Using Themselves
Juncheng Li 0018, Yixu Wang, Xiaosen Wang, Yan Teng 0002, Yingchun Wang 0004, Xingjun Ma, Yu-Gang Jiang 0001 |
ICCV | 8 |
| 2025 | StolenLoRA: Exploring LoRA Extraction Attacks via Synthetic Data
Yixu Wang, Yan Teng 0002, Yingchun Wang 0004, Xingjun Ma |
ICCV | 4 |
| 2025 | Detecting Backdoor Samples in Contrastive Language Image PretrainingabstractContrastive language-image pretraining (CLIP) has been found to be vulnerable to poisoning backdoor attacks where the adversary can achieve an almost perfect attack success rate on CLIP models by poisoning only 0.01\% of the training dataset. This raises security concerns on the current practice of pretraining large-scale models on unscrutinized web data using CLIP. In this work, we analyze the representations of backdoor-poisoned samples learned by CLIP models and find that they exhibit unique characteristics in their local subspace, i.e., their local neighborhoods are far more sparse than that of clean samples. Based on this finding, we conduct a systematic study on detecting CLIP backdoor attacks and show that these attacks can be easily and efficiently detected by traditional density ratio-based local outlier detectors, whereas existing backdoor sample detection methods fail. Our experiments also reveal that an unintentional backdoor already exists in the original CC3M dataset and has been trained into a popular open-source model released by OpenCLIP. Based on our detector, one can clean up a million-scale web dataset (e.g., CC3M) efficiently within 15 minutes using 4 Nvidia A100 GPUs. Hanxun Huang, Sarah M. Erfani, Yige Li, Xingjun Ma, James Bailey 0001 |
ICLR | 4 |
| 2025 | BlueSuffix: Reinforced Blue Teaming for Vision-Language Models Against Jailbreak AttacksabstractIn this paper, we focus on black-box defense for VLMs against jailbreak attacks.
Existing black-box defense methods are either unimodal or bimodal. Unimodal methods enhance either the vision or language module of the VLM, while bimodal methods robustify the model through text-image representation realignment.
However, these methods suffer from two limitations: 1) they fail to fully exploit the cross-modal information, or 2) they degrade the model performance on benign inputs.
To address these limitations, we propose a novel blue-team method BlueSuffix that defends target VLMs against jailbreak attacks without compromising its performance under black-box setting. BlueSuffix includes three key components: 1) a visual purifier against jailbreak images, 2) a textual purifier against jailbreak texts, and 3) a blue-team suffix generator using reinforcement fine-tuning for enhancing cross-modal robustness. We empirically show on four VLMs (LLaVA, MiniGPT-4, InstructionBLIP, and Gemini) and four safety benchmarks (Harmful Instruction, AdvBench, MM-SafetyBench, and RedTeam-2K) that BlueSuffix outperforms the baseline defenses by a significant margin.
Our BlueSuffix opens up a promising direction for defending VLMs against jailbreak attacks. Code is available at https://github.com/Vinsonzyh/BlueSuffix. Yunhan Zhao, Yige Li, Xingjun Ma, Yu-Gang Jiang 0001 |
ICLR | 5 |
| 2025 | X-Transfer Attacks: Towards Super Transferable Adversarial Attacks on CLIPabstractAs Contrastive Language-Image Pre-training (CLIP) models are increasingly adopted for diverse downstream tasks and integrated into large vision-language models (VLMs), their susceptibility to adversarial perturbations has emerged as a critical concern. In this work, we introduce X-Transfer, a novel attack method that exposes a universal adversarial vulnerability in CLIP. X-Transfer generates a Universal Adversarial Perturbation (UAP) capable of deceiving various CLIP encoders and downstream VLMs across different samples, tasks, and domains. We refer to this property as super transferability—a single perturbation achieving cross-data, cross-domain, cross-model, and cross-task adversarial transferability simultaneously. This is achieved through surrogate scaling, a key innovation of our approach. Unlike existing methods that rely on fixed surrogate models, which are computationally intensive to scale, X-Transfer employs an efficient surrogate scaling strategy that dynamically selects a small subset of suitable surrogates from a large search space. Extensive evaluations demonstrate that X-Transfer significantly outperforms previous state-of-the-art UAP methods, establishing a new benchmark for adversarial transferability across CLIP models. Hanxun Huang, Sarah M. Erfani, Yige Li, Xingjun Ma, James Bailey 0001 |
ICML | 4 |
| 2025 | From Failures to Fixes: LLM-Driven Scenario Repair for Self-Evolving Autonomous DrivingabstractEnsuring robust and generalizable autonomous driving requires not only broad scenario coverage but also efficient repair of failure cases, particularly those related to challenging and safety-critical scenarios. However, existing scenario generation and selection methods often lack adaptivity and semantic relevance, limiting their impact on performance improvement. In this paper, we propose SERA, an LLM-powered framework that enables autonomous driving systems to self-evolve by repairing failure cases through targeted scenario recommendation. By analyzing performance logs, SERA identifies failure patterns and dynamically retrieves semantically aligned scenarios from a structured bank. An LLM-based reflection mechanism further refines these recommendations to maximize relevance and diversity. The selected scenarios are used for few-shot fine-tuning, enabling targeted adaptation with minimal data. Experiments on the benchmark show that SERA consistently improves key metrics across multiple autonomous driving baselines, demonstrating its effectiveness and generalizability under safety-critical conditions. Xinyu Xia 0002, Xingjun Ma, Yunfeng Hu 0003, Ting Qu 0001, Hong Chen 0003, Xun Gong 0007 |
ACM Multimedia | 2 |
| 2025 | BrokenVideos: A Benchmark Dataset for Fine-Grained Artifact Localization in AI-Generated VideosabstractThe field of video generation has witnessed remarkable advances in recent years, driven by innovations in deep generative models. Nevertheless, the fidelity of AI-generated videos remains far from perfect, with synthesized content frequently exhibiting visual artifacts, such as temporally inconsistent motion, physically implausible trajectories, unnatural object deformations, and local blurring, that undermine realism and user trust. Precise detection and spatial localization of these artifacts are of critical importance: not only are they essential for automatic quality control pipelines that improves user experience, but they also provide actionable diagnostic signals for researchers and practitioners to guide model development and evaluation. Despite its significance, the research community currently lacks a comprehensive benchmark tailored for artifact localization in AI-generated videos. Existing datasets either focus solely on detection at the video or frame level, or lack fine-grained spatial annotations necessary for developing and benchmarking localization methods. To fill this gap, we present BrokenVideos, a benchmark dataset comprising ~3,254 AI-generated videos with carefully-annotated, pixel-level masks indicating regions of visual corruption. Each annotation is the result of careful human inspection, ensuring high-quality ground truth for artifact localization tasks. We demonstrate that training existing video artifact detection models and multi-modal large language models (MLLMs) on BrokenVideos substantially enhances their ability to localize corrupted regions within generated content. Through extensive experiments and cross-model evaluations, we show that BrokenVideos provides a critical foundation for both benchmarking and advancing artifact localization research. We hope our dataset can catalyze further innovation in both video generation and its quality assurance. The dataset is available at: https://broken-video-detection-datetsets.github.io/Broken-Video-Detection-Datasets.github.io/. Weixuan Peng, Bojia Zi, Yifeng Gao 0002, Xianbiao Qi, Xingjun Ma, Yu-Gang Jiang 0001 |
ACM Multimedia | 6 |
| 2025 | T2UE: Generating Unlearnable Examples from Text DescriptionsabstractLarge-scale pre-training frameworks like CLIP have revolutionized multimodal learning, but their reliance on web-scraped datasets, frequently containing private user data, raises serious concerns about misuse. Unlearnable Examples (UEs) have emerged as a promising countermeasure against unauthorized model training, employing carefully crafted unlearnable noise to disrupt the learning of meaningful representations from protected data. Current approaches typically generate UEs by jointly optimizing unlearnable noise for both images and their associated text descriptions (or labels). However, this optimization process is often computationally prohibitive for on-device execution, forcing reliance on external third-party services. This creates a fundamental privacy paradox: users must initially expose their data to these very services to achieve protection, thereby compromising privacy in the process. Such a contradiction has severely hindered the development of practical, scalable data protection solutions. To resolve this paradox, we introduce Text-to-Unlearnable Example (T2UE), a novel framework that enables users to generate UEs using only text descriptions. T2UE circumvents the need for original image data by employing a text-to-image (T2I) model to map text descriptions into the image (noise) space, combined with an error-minimization framework to produce effective unlearnable noise. Extensive experiments show that T2UE-protected data substantially degrades performance in downstream tasks (e.g., cross-modal retrieval) for state-of-the-art models. Notably, the protective effect generalizes across diverse architectures and even to supervised learning settings. Our work demonstrates the feasibility of ''zero-contact data protection'', where personal data can be safeguarded based solely on their textual descriptions, eliminating the need for direct data exposure. Xingjun Ma, Hanxun Huang, Tianwei Song, Ye Sun 0004, Yifeng Gao 0002, Yu-Gang Jiang 0001 |
ACM Multimedia | 1 |
| 2025 | FedAPT: Federated Adversarial Prompt Tuning for Vision-Language ModelsabstractFederated Prompt Tuning (FPT) is an efficient method for cross-client collaborative fine-tuning of large Vision-Language Models (VLMs). However, models tuned using FPT are vulnerable to adversarial attacks, leading to misclassification in downstream tasks. In this work, we introduce Federated Adversarial Prompt Tuning (FedAPT), a novel method designed to enhance the adversarial robustness of FPT. We identify a key issue in FedAPT under non-independent and identically distributed (non-IID) settings: a class information gap between clients and the global model. Clients rely solely on limited local label information to generate adversarial samples for training, while the global model must defend against adversarial attacks from global labels. To address this issue, we propose a class-aware prompt generator that generates visual prompts from text prompts. This generator is guided by a Global Label Embedding (serving as a ''beacon'') which encodes cross-client label information to create more globally-aligned visual prompts. Additionally, we propose a cross-layer generator sharing strategy to enhance prompt coupling across different layers of the model, further boosting adversarial robustness. Extensive experiments on multiple image classification datasets demonstrate the superiority of FedAPT in improving adversarial robustness, outperforming existing methods by a large margin. FedAPT also exhibits exceptional generalization in cross-domain and cross-dataset scenarios, indicating its effectiveness in real-world applications. Kun Zhai, Siheng Chen, Xingjun Ma, Yu-Gang Jiang 0001 |
ACM Multimedia | 3 |
| 2025 | BackdoorLLM: A Comprehensive Benchmark for Backdoor Attacks and Defenses on Large Language ModelsabstractGenerative large language models (LLMs) have achieved state-of-the-art results on a wide range of tasks, yet they remain susceptible to backdoor attacks: carefully crafted triggers in the input can manipulate the model to produce adversary-specified outputs. While prior research has predominantly focused on backdoor risks in vision and classification settings, the vulnerability of LLMs in open-ended text generation remains underexplored. To fill this gap, we introduce \textit{BackdoorLLM}\footnote{Our BackdoorLLM benchmark was awarded First Prize in the \href{https://www.mlsafety.org/safebench/winners}{SafetyBench competition} organized by the \href{https://safe.ai/}{Center for AI Safety}.}, the first comprehensive benchmark for systematically evaluating backdoor threats in text-generation LLMs. BackdoorLLM provides: (i) a unified repository of benchmarks with a standardized training and evaluation pipeline; (ii) a diverse suite of attack modalities, including data poisoning, weight poisoning, hidden-state manipulation, and chain-of-thought hijacking; (iii) over 200 experiments spanning 8 distinct attack strategies, 7 real-world scenarios, and 6 model architectures; (iv) key insights into the factors that govern backdoor effectiveness and failure modes in LLMs; and (v) a defense toolkit encompassing 7 representative mitigation techniques. Our code and datasets are available at \url{https://github.com/bboylyg/BackdoorLLM}. We will continuously incorporate emerging attack and defense methodologies to support the research in advancing the safety and reliability of LLMs. Yige Li, Hanxun Huang, Yunhan Zhao, Xingjun Ma, Jun Sun 0001 |
NeurIPS | 4 |
| 2025 | JailBound: Jailbreaking Internal Safety Boundaries of Vision-Language ModelsabstractVision-Language Models (VLMs) exhibit impressive performance, yet the integration of powerful vision encoders has significantly broadened their attack surface, rendering them increasingly susceptible to jailbreak attacks. However, lacking well-defined attack objectives, existing jailbreak methods often struggle with gradient-based strategies prone to local optima and lacking precise directional guidance, and typically decouple visual and textual modalities, thereby limiting their effectiveness by neglecting crucial cross-modal interactions. Inspired by the Eliciting Latent Knowledge (ELK) framework, we posit that VLMs encode safety-relevant information within their internal fusion-layer representations, revealing an implicit safety decision boundary in the latent space. This motivates exploiting boundary to steer model behavior. Accordingly, we propose \textbf{JailBound}, a novel latent space jailbreak framework comprising two stages: (1) \textbf{Safety Boundary Probing}, which addresses the guidance issue by approximating decision boundary within fusion layer's latent space, thereby identifying optimal perturbation directions towards the target region; and (2) \textbf{Safety Boundary Crossing}, which overcomes the limitations of decoupled approaches by jointly optimizing adversarial perturbations across both image and text inputs. This latter stage employs an innovative mechanism to steer the model's internal state towards policy-violating outputs while maintaining cross-modal semantic consistency. Extensive experiments on six diverse VLMs demonstrate JailBound's efficacy, achieves 94.32\% white-box and 67.28\% black-box attack success averagely, which are 6.17\% and 21.13\% higher than SOTA methods, respectively. Our findings expose a overlooked safety risk in VLMs and highlight the urgent need for more robust defenses. \textcolor{red}{Warning: This paper contains potentially sensitive, harmful and offensive content.} Yixu Wang, Jie Li 0052, Xuan Tong, Yan Teng 0002, Xingjun Ma, Yingchun Wang 0004 |
NeurIPS | 7 |
| 2025 | SAMA: Towards Multi-Turn Referential Grounded Video Chat with Large Language ModelsabstractAchieving fine-grained spatio-temporal understanding in videos remains a major challenge for current Video Large Multimodal Models (Video LMMs). Addressing this challenge requires mastering two core capabilities: video referring understanding, which captures the semantics of video regions, and video grounding, which segments object regions based on natural language descriptions.
However, most existing approaches tackle these tasks in isolation, limiting progress toward unified, referentially grounded video interaction. We identify a key bottleneck in the lack of high-quality, unified video instruction data and a comprehensive benchmark for evaluating referentially grounded video chat.
To address these challenges, we contribute in three core aspects: dataset, model, and benchmark.
First, we introduce SAMA-239K, a large-scale dataset comprising 15K videos specifically curated to enable joint learning of video referring understanding, grounding, and multi-turn video chat.
Second, we propose the SAMA model, which incorporates a versatile spatio-temporal context aggregator and a Segment Anything Model to jointly enhance fine-grained video comprehension and precise grounding capabilities.
Finally, we establish SAMA-Bench, a meticulously designed benchmark consisting of 5,067 questions from 522 videos, to comprehensively evaluate the integrated capabilities of Video LMMs in multi-turn, spatio-temporal referring understanding and grounded dialogue.
Extensive experiments and benchmarking results show that SAMA not only achieves strong performance on SAMA-Bench but also sets a new state-of-the-art on general grounding benchmarks, while maintaining highly competitive performance on standard visual understanding benchmarks. Ye Sun 0004, Hao Zhang 0047, Henghui Ding, Tiehua Zhang, Xingjun Ma, Yu-Gang Jiang 0001 |
NeurIPS | 5 |
| 2025 | SafeVid: Toward Safety Aligned Video Large Multimodal ModelsabstractAs Video Large Multimodal Models (VLMMs) rapidly advance, their inherent complexity introduces significant safety challenges, particularly the issue of mismatched generalization where static safety alignments fail to transfer to dynamic video contexts. We introduce SafeVid, a framework designed to instill video-specific safety principles in VLMMs. SafeVid uniquely transfers robust textual safety alignment capabilities to the video domain by employing detailed textual video descriptions as an interpretive bridge, facilitating LLM-based rule-driven safety reasoning. This is achieved through a closed-loop system comprising: 1) generation of SafeVid-350K, a novel 350,000-pair video-specific safety preference dataset; 2) targeted alignment of VLMMs using Direct Preference Optimization (DPO); and 3) comprehensive evaluation via our new SafeVidBench benchmark. Alignment with SafeVid-350K significantly enhances VLMM safety, with models like LLaVA-NeXT-Video demonstrating substantial improvements (e.g., up to 42.39%) on SafeVidBench. SafeVid provides critical resources and a structured approach, demonstrating that leveraging textual descriptions as a conduit for safety reasoning markedly improves the safety alignment of VLMMs in complex multimodal scenarios. Yixu Wang, Yifeng Gao 0002, Xin Wang 0119, Yan Teng 0002, Xingjun Ma, Yingchun Wang 0004, Yu-Gang Jiang 0001 |
NeurIPS | 7 |
| 2025 | OmniSVG: A Unified Scalable Vector Graphics Generation ModelabstractScalable Vector Graphics (SVG) is an important image format widely adopted in graphic design because of their resolution independence and editability. The study of generating high-quality SVG has continuously drawn attention from both designers and researchers in the AIGC community. However, existing methods either produces unstructured outputs with huge computational cost or is limited to generating monochrome icons of over-simplified structures. To produce high-quality and complex SVG, we propose OmniSVG, a unified framework that leverages pre-trained Vision-Language Models (VLMs) for end-to-end multimodal SVG generation. By parameterizing SVG commands and coordinates into discrete tokens, OmniSVG decouples structural logic from low-level geometry for efficient training while maintaining the expressiveness of complex SVG structure. To further advance the development of SVG synthesis, we introduce MMSVG-2M, a multimodal dataset with two million richly annotated SVG assets, along with a standardized evaluation protocol for conditional SVG generation tasks. Extensive experiments show that OmniSVG outperforms existing methods and demonstrates its potential for integration into professional SVG design workflows. Sijin Chen, Xianfang Zeng, Fukun Yin, Gang Yu 0002, Xingjun Ma, Yu-Gang Jiang 0001 |
NeurIPS | 9 |
| 2024 | Toward Evaluating Robustness of Reinforcement Learning with Adversarial PolicyabstractReinforcement learning agents are susceptible to evasion attacks during deployment. In single-agent environments, these attacks can occur through imperceptible perturbations injected into the inputs of the victim policy network. In multi-agent environments, an attacker can manipulate an adversarial opponent to influence the victim policy's observations indirectly. While adversarial policies offer a promising technique to craft such attacks, current methods are either sample-inefficient due to poor exploration strategies or require extra surrogate model training under the black-box assumption. To address these challenges, in this paper, we propose Intrinsically Motivated Adversarial Policy (IMAP) for efficient black-box adversarial policy learning in both single- and multi-agent environments. We formulate four types of adversarial intrinsic regularizers—maximizing the adversarial state coverage, policy coverage, risk, or divergence—to discover potential vulnerabilities of the victim policy in a principled way. We also present a novel bias-reduction method to balance the extrinsic objective and the adversarial intrinsic regularizers adaptively. Our experiments validate the effectiveness of the four types of adversarial intrinsic regularizers and the bias-reduction method in enhancing black-box adversarial policy learning across a variety of environments. Our IMAP successfully evades two types of defense methods, adversarial training and robust regularizer, decreasing the performance of the state-of-the-art robust WocaR-PPO agents by 34%-54% across four single-agent tasks. IMAP also achieves a state-of-the-art attacking success rate of 83.91% in the multi-agent game YouShallNotPass. Our code is available at https://github.com/x-zheng16/IMAP. Xingjun Ma, Xinyu Wang 0007, Chao Shen 0001, Cong Wang 0001 |
DSN | 2 |
| 2024 | Adversarial Prompt Tuning for Vision-Language Models
Jiaming Zhang 0006, Xingjun Ma, Xin Wang 0119, Lingyu Qiu, Jiaqi Wang 0003, Yu-Gang Jiang 0001, Jitao Sang 0001 |
ECCV (45) | 2 |
| 2024 | LDReg: Local Dimensionality Regularized Self-Supervised LearningabstractRepresentations learned via self-supervised learning (SSL) can be susceptible to dimensional collapse, where the learned representation subspace is of extremely low dimensionality and thus fails to represent the full data distribution and modalities.
Dimensional collapse ––– also known as the "underfilling" phenomenon ––– is one of the major causes of degraded performance on downstream tasks. Previous work has investigated the dimensional collapse problem of SSL at a global level. In this paper, we demonstrate that representations can span over high dimensional space globally, but collapse locally. To address this, we propose a method called *local dimensionality regularization (LDReg)*. Our formulation is based on the derivation of the Fisher-Rao metric to compare and optimize local distance distributions at an asymptotically small radius for each data point. By increasing the local intrinsic dimensionality, we demonstrate through a range of experiments that LDReg improves the representation quality of SSL. The results also show that LDReg can regularize dimensionality at both local and global levels. Hanxun Huang, Ricardo J. G. B. Campello, Sarah M. Erfani, Xingjun Ma, Michael E. Houle, James Bailey 0001 |
ICLR | 4 |
| 2024 | Constrained Intrinsic Motivation for Reinforcement Learning
Xingjun Ma, Chao Shen 0001, Cong Wang 0001 |
IJCAI | 2 |
| 2024 | AdvQDet: Detecting Query-Based Adversarial Attacks with Adversarial Contrastive Prompt Tuning
Xin Wang 0119, Kai Chen 0027, Xingjun Ma, Zhineng Chen, Jingjing Chen 0001, Yu-Gang Jiang 0001 |
ACM Multimedia | 3 |
| 2024 | ModelLock: Locking Your Model With a Spell
Yifeng Gao 0002, Xingjun Ma, Zuxuan Wu, Yu-Gang Jiang 0001 |
ACM Multimedia | 3 |
| 2024 | Fuse Your Latents: Video Editing with Multi-source Latent Diffusion ModelsabstractLatent Diffusion Models (LDMs) are renowned for their powerful capabilities in image and video synthesis. Yet, compared to text-to-image (T2I) editing, text-to-video (T2V) editing suffers from a lack of decent temporal consistency and structure, due to insufficient pre-training data, limited model editability, or extensive tuning costs. To address this gap, we propose FLDM (Fused Latent Diffusion Model), a training-free framework that achieves high-quality T2V editing by integrating various T2I and T2V LDMs. Specifically, FLDM utilizes a hyper-parameter with an update schedule to effectively fuse image and video latents during the denoising process. This paper is the first to reveal that T2I and T2V LDMs can complement each other in terms of structure and temporal consistency, ultimately generating high-quality videos. It is worth noting that FLDM can serve as a versatile plugin, applicable to off-the-shelf image and video LDMs, to significantly enhance the quality of video editing. Extensive quantitative and qualitative experiments on popular T2I and T2V LDMs demonstrate FLDM's superior editing quality than state-of-the-art T2V editing methods. Xing Zhang 0013, Jiaxi Gu, Renjing Pei, Songcen Xu, Xingjun Ma, Hang Xu 0004, Zuxuan Wu |
ACM Multimedia | 6 |
| 2024 | White-box Multimodal Jailbreaks Against Large Vision-Language ModelsabstractRecent advancements in Large Vision-Language Models (VLMs) have underscored their superiority in various multimodal tasks. However, the adversarial robustness of VLMs has not been fully explored. Existing methods mainly assess robustness through unimodal adversarial attacks that perturb images, while assuming inherent resilience against text-based attacks. Different from existing attacks, in this work we propose a more comprehensive strategy that jointly attacks both text and image modalities to exploit a broader spectrum of vulnerability within VLMs. Specifically, we propose a dual optimization objective aimed at guiding the model to generate highly toxic affirmative responses. Our attack method begins by optimizing an adversarial image prefix from random noise to generate diverse harmful responses in the absence of text input, thus imbuing the image with toxic semantics. Subsequently, an adversarial text suffix is integrated and co-optimized with the adversarial image prefix to maximize the probability of eliciting affirmative responses to various harmful instructions. The discovered adversarial image prefix and text suffix are collectively denoted as a Universal Master Key (UMK). When integrated into various malicious queries, UMK can circumvent the alignment defenses of VLMs and lead to the generation of objectionable content, known as jailbreaks. The experimental results demonstrate that our universal attack strategy can effectively jailbreak MiniGPT-4 with a 96% success rate, highlighting the fragility of VLMs and the exigency for new alignment strategies. Codes are available at https://github.com/roywang021/UMK. Disclaimer: This paper contains potentially disturbing and offensive content. Xingjun Ma, Hanxu Zhou, Chuanjun Ji, Guangnan Ye, Yu-Gang Jiang 0001 |
ACM Multimedia | 2 |
| 2024 | Fake Alignment: Are LLMs Really Aligned Well?abstractYixu Wang, Yan Teng, Kexin Huang, Chengqi Lyu, Songyang Zhang, Wenwei Zhang, Xingjun Ma, Yu-Gang Jiang, Yu Qiao, Yingchun Wang. Proceedings of the 2024 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies (Volume 1: Long Papers). 2024. Yixu Wang, Yan Teng 0002, Chengqi Lyu, Songyang Zhang 0001, Xingjun Ma, Yu-Gang Jiang 0001, Yu Qiao 0001, Yingchun Wang 0004 |
NAACL-HLT | 7 |
| 2024 | UnSeg: One Universal Unlearnable Example Generator is Enough against All Image SegmentationabstractImage segmentation is a crucial vision task that groups pixels within an image into semantically meaningful segments, which is pivotal in obtaining a fine-grained understanding of real-world scenes. However, an increasing privacy concern exists regarding training large-scale image segmentation models on unauthorized private data. In this work, we exploit the concept of unlearnable examples to make images unusable to model training by generating and adding unlearnable noise into the original images. Particularly, we propose a novel Unlearnable Segmentation (UnSeg) framework to train a universal unlearnable noise generator that is capable of transforming any downstream images into their unlearnable version. The unlearnable noise generator is finetuned from the Segment Anything Model (SAM) via bilevel optimization on an interactive segmentation dataset towards minimizing the training error of a surrogate model that shares the same architecture with SAM (but trains from scratch). We empirically verify the effectiveness of UnSeg across 6 mainstream image segmentation tasks, 10 widely used datasets, and 7 different network architectures, and show that the unlearnable images can reduce the segmentation performance by a large margin. Our work provides useful insights into how to leverage foundation models in a data-efficient and computationally affordable manner to protect images against image segmentation models. Ye Sun 0004, Hao Zhang 0047, Tiehua Zhang, Xingjun Ma, Yu-Gang Jiang 0001 |
NeurIPS | 4 |
| 2024 | Unlearnable Examples for Time Series
Yujing Jiang, Xingjun Ma, Sarah M. Erfani, James Bailey 0001 |
PAKDD (6) | 2 |
| 2024 | Training Sparse Graph Neural Networks via Pruning and SproutingabstractWith the emergence of large-scale graphs and deeper graph neural networks (GNNs), sparsifying GNNs including graph connections and model parameters has attracted a lot of attention. However, most existing GNN sparsification methods apply traditional neural network pruning techniques to sparsify graphs in an iterative cycle (train-then-sparsify), which not only incurs high training costs but also limits model performance. In this paper, we propose a novel Pruning and Sprouting framework for GNN (PSGNN) that not only enhances the efficiency of inference, but also boosts the performance of GNN trained on a core subgraph beyond the original graph. Based on during-training pruning, our framework gradually sparsifies the graph connections and model weights simultaneously. More specifically, PSGNN removes edges in the original graph according to the predicted label similarity between nodes from a global view. Additionally, with our graph sprouting strategy, PSGNN can generate new edges to include important yet missing topological and feature information in the original graph, while maintaining the sparsity of the graph. Extensive experiments on node classification task across different GNN architectures and graph datasets demonstrate that our proposed PSGNN method improves the performance over existing methods while saving training and inference costs. Xueqi Ma, Xingjun Ma, Sarah M. Erfani, James Bailey 0001 |
SDM | 2 |
| 2024 | Imbalanced gradients: a subtle cause of overestimated adversarial robustness
Xingjun Ma, Linxi Jiang, Hanxun Huang, Zejia Weng, James Bailey 0001, Yu-Gang Jiang 0001 |
Mach. Learn. | 1 |
| 2024 | VeriFi: Towards Verifiable Federated UnlearningabstractFederated learning (FL) has emerged as a privacy-aware collaborative learning paradigm where participants jointly train a powerful model without sharing their private data. One desirable property for FL is the implementation of theright to be forgotten (RTBF), i.e., a leaving participant has the right to request the deletion of its private data from the global model. However,unlearning itself may not be enough to implement RTBF unless the unlearning effect can be independently verified, an important aspect that has been overlooked in the current literature. Unlearning verification is particularly challenging in FL as the unlearning effect on one participant's data could be canceled by the contribution of other participants. In this work, we prompt the concept ofverifiable federated unlearningand proposeVeriFi, a unified framework that allows systematic analysis of federated unlearning and quantification of its effect, with different combinations of various unlearning and verification methods. InVeriFi, the leaving participant is granted theright to verify (RTV)to actively verify the unlearning effect in the next few rounds immediately after notifying the server of its intention to leave, along with local verification done through two steps: 1)markingthat fingerprints the leaving participant by specially-designedmarkersand 2)checkingthat examines the global model's performance change on the markers. Based onVeriFi, we have conducted so far the most systematic study on verifiable federated unlearning, covering six unlearning methods and five verification methods. Our study sheds light on the existing drawbacks and potential alternatives for both unlearning and verification methods. During the study, we also propose a more efficient and FL-friendly unlearning method$^{u}$S2U, and two more effective and robust non-invasive (without training controllability, external data, white-box model access nor introducing new security risks) verification methods$^{v}$FM and$^{v}$EM. While the proposed methods may not be a panacea for all the challenges, they address several key drawbacks of existing methods and represent a promising step toward effective, efficient, robust, and more importantly, non-invasive federated unlearning and verification. We extensively evaluateVeriFion seven datasets, including natural/facial/medical images and audios, and four types of deep learning models, including both Convolutional Neural Networks (CNNs) and Recurrent Neural Networks (RNNs). We hope, such an extensive and holistic experimental evaluation, although admittedly complex and challenging, could help establish important empirical understandings, evidence, and insights for trustworthy federated unlearning. Xiangshan Gao, Xingjun Ma, Jingyi Wang 0004, Youcheng Sun, Bo Li 0026, Shouling Ji, Peng Cheng 0001, Jiming Chen 0001 |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2024 | Privacy and Robustness in Federated Learning: Attacks and DefensesabstractAs data are increasingly being stored in different silos and societies becoming more aware of data privacy issues, the traditional centralized training of artificial intelligence (AI) models is facing efficiency and privacy challenges. Recently, federated learning (FL) has emerged as an alternative solution and continues to thrive in this new reality. Existing FL protocol designs have been shown to be vulnerable to adversaries within or outside of the system, compromising data privacy and system robustness. Besides training powerful global models, it is of paramount importance to design FL systems that have privacy guarantees and are resistant to different types of adversaries. In this article, we conduct a comprehensive survey on privacy and robustness in FL over the past five years. Through a concise introduction to the concept of FL and a unique taxonomy covering: 1) threat models; 2) privacy attacks and defenses; and 3) poisoning attacks and defenses, we provide an accessible review of this important topic. We highlight the intuitions, key techniques, and fundamental assumptions adopted by various attacks and defenses. Finally, we discuss promising future research directions toward robust and privacy-preserving FL, and their interplays with the multidisciplinary goals of FL. Lingjuan Lyu, Han Yu 0001, Xingjun Ma, Chen Chen 0043, Lichao Sun 0001, Jun Zhao 0007, Qiang Yang 0001, Philip S. Yu |
IEEE Trans. Neural Networks Learn. Syst. | 3 |
| 2023 | Unlearnable Clusters: Towards Label-Agnostic Unlearnable ExamplesabstractThere is a growing interest in developing unlearnable examples (UEs) against visual privacy leaks on the Internet. UEs are training samples added with invisible but unlearnable noise, which have been found can prevent unauthorized training of machine learning models. UEs typically are generated via a bilevel optimization framework with a surrogate model to remove (minimize) errors from the original samples, and then applied to protect the data against unknown target models. However, existing UE generation methods all rely on an ideal assumption called label-consistency, where the hackers and protectors are assumed to hold the same label for a given sample. In this work, we propose and promote a more practical label-agnostic setting, where the hackers may exploit the protected data quite differently from the protectors. E.g., amclass unlearnable dataset held by the protector may be exploited by the hacker as a n-class dataset. Existing UE generation methods are rendered ineffective in this challenging setting. To tackle this challenge, we present a novel technique called Unlearnable Clusters (UCs) to generate label-agnostic unlearnable examples with cluster-wise perturbations. Furthermore, we propose to leverage Vision-and-Language Pre-trained Models (VLPMs) like CLIP as the surrogate model to improve the transferability of the crafted UCs to diverse domains. We empirically verify the effectiveness of our proposed approach under a variety of settings with different datasets, target models, and even commercial platforms Microsoft Azure and Baidu PaddlePaddle. Code is available at https://github.com/jiamingzhang94/Unlearnable-Clusters. Jiaming Zhang 0006, Xingjun Ma, Qi Yi, Jitao Sang 0001, Yu-Gang Jiang 0001, Yaowei Wang 0001, Changsheng Xu |
CVPR | 2 |
| 2023 | Distilling Cognitive Backdoor Patterns within an Image
Hanxun Huang, Xingjun Ma, Sarah M. Erfani, James Bailey 0001 |
ICLR | 2 |
| 2023 | Transferable Unlearnable Examples
Jie Ren 0019, Han Xu 0002, Xingjun Ma, Lichao Sun 0001, Jiliang Tang |
ICLR | 4 |
| 2023 | Reconstructive Neuron Pruning for Backdoor DefenseabstractDeep neural networks (DNNs) have been found to be vulnerable to backdoor attacks, raising security concerns about their deployment in mission-critical applications. While existing defense methods have demonstrated promising results, it is still not clear how to effectively remove backdoor-associated neurons in backdoored DNNs. In this paper, we propose a novel defense called *Reconstructive Neuron Pruning* (RNP) to expose and prune backdoor neurons via an unlearning and then recovering process. Specifically, RNP first unlearns the neurons by maximizing the model's error on a small subset of clean samples and then recovers the neurons by minimizing the model's error on the same data. In RNP, unlearning is operated at the neuron level while recovering is operated at the filter level, forming an asymmetric reconstructive learning procedure. We show that such an asymmetric process on only a few clean samples can effectively expose and prune the backdoor neurons implanted by a wide range of attacks, achieving a new state-of-the-art defense performance. Moreover, the unlearned model at the intermediate step of our RNP can be directly used to improve other backdoor defense tasks including backdoor removal, trigger recovery, backdoor label detection, and backdoor sample detection. Code is available at https://github.com/bboylyg/RNP. Yige Li, Xixiang Lyu, Xingjun Ma, Nodens Koren, Lingjuan Lyu, Bo Li 0026, Yu-Gang Jiang 0001 |
ICML | 3 |
| 2023 | On the Importance of Spatial Relations for Few-shot Action RecognitionabstractDeep learning has achieved great success in video recognition, yet still struggles to recognize novel actions when faced with only a few examples. To tackle this challenge, few-shot action recognition methods have been proposed to transfer knowledge from a source dataset to a novel target dataset with only one or a few labeled videos. However, existing methods mainly focus on modeling the temporal relations between the query and support videos while ignoring the spatial relations. In this paper, we find that the spatial misalignment between objects also occurs in videos, notably more common than the temporal inconsistency. We are thus motivated to investigate the importance of spatial relations and propose a more accurate few-shot action recognition method that leverages both spatial and temporal information. Particularly, a novel Spatial Alignment Cross Transformer (SA-CT) which learns to re-adjust the spatial relations and incorporates the temporal information is contributed. Experiments reveal that, even without using any temporal information, the performance of SA-CT is comparable to temporal based methods on 3/4 benchmarks. To further incorporate the temporal information, we propose a simple yet effective Temporal Mixer module. The Temporal Mixer enhances the video representation and improves the performance of the full SA-CT model, achieving very competitive results. In this work, we also exploit large-scale pretrained models for few-shot action recognition, providing useful insights for this research direction. Yuqian Fu, Xingjun Ma, Lizhe Qi, Jingjing Chen 0001, Zuxuan Wu, Yu-Gang Jiang 0001 |
ACM Multimedia | 3 |
| 2023 | Relationships between tail entropies and local intrinsic dimensionality and their use for estimation and feature representation
James Bailey 0001, Michael E. Houle, Xingjun Ma |
Inf. Syst. | 3 |
| 2023 | Query-Efficient Black-Box Adversarial Attacks on Automatic Speech RecognitionabstractThe susceptibility of Deep Neural Networks (DNNs) to adversarial attacks has raised concerns regarding their practical applications in real-world scenarios. Although the vulnerability of DNNs to adversarial attacks has been extensively studied in the image domain, research in the audio domain, particularly in the black-box setting with Automatic Speech Recognition (ASR) models, remains limited. While various black-box attacks have been proposed for ASR models, such as transfer attacks, hardware attacks, and query-based attacks, this study concentrates on query-based black-box attacks. The article introduces a new gradient estimation technique, Temporal Natural Evolution Strategies (T-NES), to generate adversarial audio samples more efficiently than existing attacks. T-NES leverages the temporal correlation present in audio to speed up gradient estimation based on the probability scores returned by the target model. The empirical results on benchmark datasets, LibriSpeech and TEDLIUM, and two state-of-the-art ASR models, DeepSpeech2 and Wav2Letter, demonstrate that T-NES can generate successful attacks with up to 30% fewer queries than existing attacks within 500 queries. T-NES could provide a robust baseline for evaluating the black-box adversarial vulnerability of ASR systems. Chuxuan Tong, James Xi Zheng, Jianhua Li 0002, Xingjun Ma, Longxiang Gao, Yong Xiang 0001 |
IEEE ACM Trans. Audio Speech Lang. Process. | 4 |
| 2023 | QuoTe: Quality-oriented Testing for Deep Learning SystemsabstractRecently, there has been significant growth of interest in applying software engineering techniques for the quality assurance of deep learning (DL) systems. One popular direction is DL testing—that is, given a property of test, defects of DL systems are found either by fuzzing or guided search with the help of certain testing metrics. However, recent studies have revealed that the neuron coverage metrics, which are commonly used by most existing DL testing approaches, are not necessarily correlated with model quality (e.g., robustness, the most studied model property), and are also not an effective measurement on the confidence of the model quality after testing. In this work, we address this gap by proposing a novel testing framework called QuoTe (i.e., Qu ality- o riented Te sting). A key part of QuoTe is a quantitative measurement on (1) the value of each test case in enhancing the model property of interest (often via retraining) and (2) the convergence quality of the model property improvement. QuoTe utilizes the proposed metric to automatically select or generate valuable test cases for improving model quality. The proposed metric is also a lightweight yet strong indicator of how well the improvement converged. Extensive experiments on both image and tabular datasets with a variety of model architectures confirm the effectiveness and efficiency of QuoTe in improving DL model quality—that is, robustness and fairness. As a generic quality-oriented testing framework, future adaptations can be made to other domains (e.g., text) as well as other model properties. Jingyi Wang 0004, Xingjun Ma, Youcheng Sun, Jun Sun 0001, Peixin Zhang 0001, Peng Cheng 0001 |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2022 | Few-Shot Backdoor Attacks on Visual Object Tracking
Yiming Li 0004, Haoxiang Zhong, Xingjun Ma, Yong Jiang 0001, Shutao Xia |
ICLR | 3 |
| 2022 | Backdoor Attacks on Crowd CountingabstractCrowd counting is a regression task that estimates the number of people in a scene image, which plays a vital role in a range of safety-critical applications, such as video surveillance, traffic monitoring and flow control. In this paper, we investigate the vulnerability of deep learning based crowd counting models to backdoor attacks, a major security threat to deep learning. A backdoor attack implants a backdoor trigger into a target model via data poisoning so as to control the model's predictions at test time. Different from image classification models on which most of existing backdoor attacks have been developed and tested, crowd counting models are regression models that output multi-dimensional density maps, thus requiring different techniques to manipulate. In this paper, we propose two novel Density Manipulation Backdoor Attacks (DMBA- and DMBA+) to attack the model to produce arbitrarily large or small density estimations. Experimental results demonstrate the effectiveness of our DMBA attacks on five classic crowd counting models and four types of datasets. We also provide an in-depth analysis of the unique challenges of backdooring crowd counting models and reveal two key elements of effective attacks: 1) full and dense triggers and 2) manipulation of the ground truth counts or density maps. Our work could help evaluate the vulnerability of crowd counting models to potential backdoor attacks. Tailai Zhang, Xingjun Ma, Pan Zhou 0001, Jian Lou 0001, Zichuan Xu, Xing Di, Yu Cheng 0001, Lichao Sun 0001 |
ACM Multimedia | 3 |
| 2022 | CalFAT: Calibrated Federated Adversarial Training with Label SkewnessabstractRecent studies have shown that, like traditional machine learning, federated learning (FL) is also vulnerable to adversarial attacks.To improve the adversarial robustness of FL, federated adversarial training (FAT) methods have been proposed to apply adversarial training locally before global aggregation. Although these methods demonstrate promising results on independent identically distributed (IID) data, they suffer from training instability on non-IID data with label skewness, resulting in degraded natural accuracy. This tends to hinder the application of FAT in real-world applications where the label distribution across the clients is often skewed. In this paper, we study the problem of FAT under label skewness, and reveal one root cause of the training instability and natural accuracy degradation issues: skewed labels lead to non-identical class probabilities and heterogeneous local models. We then propose a Calibrated FAT (CalFAT) approach to tackle the instability issue by calibrating the logits adaptively to balance the classes. We show both theoretically and empirically that the optimization of CalFAT leads to homogeneous local models across the clients and better convergence points. Chen Chen 0043, Xingjun Ma, Lingjuan Lyu |
NeurIPS | 3 |
| 2022 | Copy, Right? A Testing Framework for Copyright Protection of Deep Learning ModelsabstractDeep learning models, especially those large-scale and high-performance ones, can be very costly to train, demanding a considerable amount of data and computational resources. As a result, deep learning models have become one of the most valuable assets in modern artificial intelligence. Unauthorized duplication or reproduction of deep learning models can lead to copyright infringement and cause huge economic losses to model owners, calling for effective copyright protection techniques. Existing protection techniques are mostly based on watermarking, which embeds an owner-specified watermark into the model. While being able to provide exact ownership verification, these techniques are 1) invasive, i.e., they need to tamper with the training process, which may affect the model utility or introduce new security risks into the model; 2) prone to adaptive attacks that attempt to remove/replace the watermark or adversarially block the retrieval of the watermark; and 3) not robust to the emerging model extraction attacks. Latest fingerprinting work on deep learning models, though being non-invasive, also falls short when facing the diverse and ever-growing attack scenarios.In this paper, we propose a novel testing framework for deep learning copyright protection: DEEPJUDGE. DEEPJUDGE quantitatively tests the similarities between two deep learning models: a victim model and a suspect model. It leverages a diverse set of testing metrics and efficient test case generation algorithms to produce a chain of supporting evidence to help determine whether a suspect model is a copy of the victim model. Advantages of DEEPJUDGE include: 1) non-invasive, as it works directly on the model and does not tamper with the training process; 2) efficient, as it only needs a small set of seed test cases and a quick scan of the two models; 3) flexible, i.e., it can easily incorporate new testing metrics or test case generation methods to obtain more confident and robust judgement; and 4) fairly robust to model extraction attacks and adaptive attacks. We verify the effectiveness of DEEPJUDGE under three typical copyright infringement scenarios, including model finetuning, pruning and extraction, via extensive experiments on both image classification and speech recognition datasets with a variety of model architectures. Jingyi Wang 0004, Tinglan Peng, Youcheng Sun, Peng Cheng 0001, Shouling Ji, Xingjun Ma, Bo Li 0026, Dawn Song |
SP | 7 |
| 2022 | How to Democratise and Protect AI: Fair and Differentially Private Decentralised Deep LearningabstractThis article first considers the research problem of fairness in collaborative deep learning, while ensuring privacy. A novel reputation system is proposed through digital tokens and local credibility to ensure fairness, in combination with differential privacy to guarantee privacy. In particular, we build a fair and differentially private decentralised deep learning framework called FDPDDL, which enables parties to derive more accurate local models in a fair and private manner by using our developed two-stage scheme: during the initialisation stage, artificial samples generated by Differentially Private Generative Adversarial Network (DPGAN) are used to mutually benchmark the local credibility of each party and generate initial tokens; during the update stage, Differentially Private SGD (DPSGD) is used to facilitate collaborative privacy-preserving deep learning, and local credibility and tokens of each party are updated according to the quality and quantity of individually released gradients. Experimental results on benchmark datasets under three realistic settings demonstrate that FDPDDL achieves high fairness, yields comparable accuracy to the centralised and distributed frameworks, and delivers better accuracy than the standalone framework. Lingjuan Lyu, Yitong Li 0002, Karthik Nandakumar, Jiangshan Yu, Xingjun Ma |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2021 | SpineOne: A One-Stage Detection Framework for Degenerative Discs and VertebraeabstractSpinal degeneration plagues many elders, office workers, and even the younger generations. Effective pharmic or surgical interventions can help relieve degenerative spine conditions. However, the traditional diagnosis procedure is often too laborious. Clinical experts need to localize discs and vertebrae as a preliminary step of pathological diagnosis. Machine learning systems have been developed to aid this procedure generally following a two-stage methodology: first perform anatomical localization, then pathological classification. Towards more efficient and accurate diagnosis, we propose a one-stage detection framework termed SpineOne to simultaneously localize and classify degenerative discs and vertebrae from magnetic resonance imaging (MRI) slices. SpineOne is built upon the following three key techniques: 1) a new design of the keypoint heatmap to facilitate simultaneous keypoint localization and classification; 2) the use of attention modules to better differentiate the representations between discs and vertebrae; and 3) a novel gradient-guided objective association mechanism to associate multiple learning objectives at the later training stage. Empirical results on the Spinal Disease Intelligent Diagnosis Tianchi Competition (SDID-TC) dataset of 550 exams demonstrate that our approach surpasses existing methods by a large margin. Jiabo He, Wei Liu 0127, Yu Wang 0108, Xingjun Ma, Xian-Sheng Hua 0001 |
BIBM | 4 |
| 2021 | Revisiting Adversarial Robustness Distillation: Robust Soft Labels Make Student BetterabstractAdversarial training is one effective approach for training robust deep neural networks against adversarial attacks. While being able to bring reliable robustness, adversarial training (AT) methods in general favor high capacity models, i.e., the larger the model the better the robustness. This tends to limit their effectiveness on small models, which are more preferable in scenarios where storage or computing resources are very limited (e.g., mobile devices). In this paper, we leverage the concept of knowledge distillation to improve the robustness of small models by distilling from adversarially trained large models. We first revisit several state-of-the-art AT methods from a distillation perspective and identify one common technique that can lead to improved robustness: the use of robust soft labels – predictions of a robust model. Following this observation, we propose a novel adversarial robustness distillation method called Robust Soft Label Adversarial Distillation (RSLAD) to train robust small student models. RSLAD fully exploits the robust soft labels produced by a robust (adversarially-trained) large teacher model to guide the student’s learning on both natural and adversarial examples in all loss terms. We empirically demonstrate the effectiveness of our RSLAD approach over existing adversarial training and distillation methods in improving the robustness of small models against state-of-the-art attacks including the AutoAttack. We also provide a set of understandings on our RSLAD and the importance of robust soft labels for adversarial robustness distillation. Code: https://github.com/zibojia/RSLAD. Bojia Zi, Xingjun Ma, Yu-Gang Jiang 0001 |
ICCV | 3 |
| 2021 | Improving Adversarial Robustness via Channel-wise Activation Suppressing
Yang Bai 0011, Yuyuan Zeng, Yong Jiang 0001, Shutao Xia, Xingjun Ma, Yisen Wang 0001 |
ICLR | 5 |
| 2021 | Unlearnable Examples: Making Personal Data Unexploitable
Hanxun Huang, Xingjun Ma, Sarah M. Erfani, James Bailey 0001, Yisen Wang 0001 |
ICLR | 2 |
| 2021 | Neural Attention Distillation: Erasing Backdoor Triggers from Deep Neural Networks
Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li 0026, Xingjun Ma |
ICLR | 6 |
| 2021 | ECG-Adv-GAN: Detecting ECG Adversarial Examples with Conditional Generative Adversarial NetworksabstractElectrocardiogram (ECG) acquisition requires an automated system and analysis pipeline for understanding specific rhythm irregularities. Deep neural networks have become a popular technique for tracing ECG signals, outperforming human experts. Despite this, convolutional neural networks are susceptible to adversarial examples that can misclassify ECG signals and decrease the model’s precision. Moreover, they do not generalize well on the out-of-distribution dataset. The GAN architecture has been employed in recent works to synthesize adversarial ECG signals to increase existing training data. However, they use a disjointed CNN-based classification architecture to detect arrhythmia. Till now, no versatile architecture has been proposed that can detect adversarial examples and classify arrhythmia simultaneously. To alleviate this, we propose a novel Conditional Generative Adversarial Network to simultaneously generate ECG signals for different categories and detect cardiac abnormalities. Moreover, the model is conditioned on class-specific ECG signals to synthesize realistic adversarial examples. Consequently, we compare our architecture and show how it outperforms other classification models in normal/abnormal ECG signal detection by benchmarking real world and adversarial signals. Khondker Fariha Hossain, Sharif Amit Kamran, Alireza Tavakkoli, Lei Pan 0002, Xingjun Ma, Sutharshan Rajasegarar, Chandan Karmaker |
ICMLA | 5 |
| 2021 | RobOT: Robustness-Oriented Testing for Deep Learning SystemsabstractRecently, there has been a significant growth of interest in applying software engineering techniques for the quality assurance of deep learning (DL) systems. One popular direction is deep learning testing, where adversarial examples (a.k.a.~bugs) of DL systems are found either by fuzzing or guided search with the help of certain testing metrics. However, recent studies have revealed that the commonly used neuron coverage metrics by existing DL testing approaches are not correlated to model robustness. It is also not an effective measurement on the confidence of the model robustness after testing. In this work, we address this gap by proposing a novel testing framework called Robustness-Oriented Testing (RobOT). A key part of RobOT is a quantitative measurement on 1) the value of each test case in improving model robustness (often via retraining), and 2) the convergence quality of the model robustness improvement. RobOT utilizes the proposed metric to automatically generate test cases valuable for improving model robustness. The proposed metric is also a strong indicator on how well robustness improvement has converged through testing. Experiments on multiple benchmark datasets confirm the effectiveness and efficiency of RobOT in improving DL model robustness, with 67.02% increase on the adversarial robustness that is 50.65% higher than the state-of-the-art work DeepGini. Jingyi Wang 0004, Youcheng Sun, Xingjun Ma, Dongxia Wang 0002, Jun Sun 0001, Peng Cheng 0001 |
ICSE | 4 |
| 2021 | Noise Doesn't Lie: Towards Universal Detection of Deep InpaintingabstractDeep image inpainting aims to restore damaged or missing regions in an image with realistic contents. While having a wide range of applications such as object removal and image recovery, deep inpainting techniques also have the risk of being manipulated for image forgery. A promising countermeasure against such forgeries is deep inpainting detection, which aims to locate the inpainted regions in an image. In this paper, we make the first attempt towards universal detection of deep inpainting, where the detection network can generalize well when detecting different deep inpainting methods. To this end, we first propose a novel data generation approach to generate a universal training dataset, which imitates the noise discrepancies exist in real versus inpainted image contents to train universal detectors. We then design a Noise-Image Cross-fusion Network (NIX-Net) to effectively exploit the discriminative information contained in both the images and their noise patterns. We empirically show, on multiple benchmark datasets, that our approach outperforms existing detection methods by a large margin and generalize well to unseen deep inpainting techniques. Our universal training dataset can also significantly boost the generalizability of existing detection methods. Ang Li 0008, Qiuhong Ke, Xingjun Ma, Haiqin Weng, Zhiyuan Zong, Rui Zhang 0003 |
IJCAI | 3 |
| 2021 | Neural Architecture Search via Combinatorial Multi-Armed BanditabstractNeural Architecture Search (NAS) has gained significant popularity as an effective tool for designing high performance deep neural networks (DNNs). NAS can be performed via reinforcement learning, evolutionary algorithms, differentiable architecture search or tree-search methods. While significant progress has been made for both reinforcement learning and differentiable architecture search, tree-search methods have so far failed to achieve comparable accuracy or search efficiency. In this paper, we formulate NAS as a Combinatorial Multi-Armed Bandit (CMAB) problem (CMAB-NAS). This allows the decomposition of a large search space into smaller blocks where tree-search methods can be applied more effectively and efficiently. We further leverage a tree-based method called Nested Monte-Carlo Search to tackle the CMAB-NAS problem. On CIFAR-10, our approach discovers a cell structure that achieves a low error rate that is comparable to the state-of-the-art, using only 0.58 GPU days, which is 20 times faster than current tree-search methods. Moreover, the discovered structure transfers well to large-scale datasets such as ImageNet. Hanxun Huang, Xingjun Ma, Sarah M. Erfani, James Bailey 0001 |
IJCNN | 2 |
| 2021 | Dual Head Adversarial TrainingabstractDeep neural networks (DNNs) are known to be vulnerable to adversarial examples/attacks, raising concerns about their reliability in safety-critical applications. A number of defense methods have been proposed to train robust DNNs resistant to adversarial attacks, among which adversarial training has so far demonstrated the most promising results. However, recent studies have shown that there exists an inherent tradeoff between accuracy and robustness in adversarially-trained DNNs. In this paper, we propose a novel technique Dual Head Adversarial Training (DH-AT) to further improve the robustness of existing adversarial training methods. Different from existing improved variants of adversarial training, DH-AT modifies both the architecture of the network and the training strategy to seek more robustness. Specifically, DH-AT first attaches a second network head (or branch) to one intermediate layer of the network, then uses a lightweight convolutional neural network (CNN) to aggregate the outputs of the two heads. The training strategy is also adapted to reflect the relative importance of the two heads. We empirically show, on multiple benchmark datasets, that DH-AT can bring notable robustness improvements to existing adversarial training methods. Compared with TRADES, one state-of-the-art adversarial training method, our DH-AT can improve the robustness by 3.4% against PGD40and 2.3% against AutoAttack, and also improve the clean accuracy by 1.8%. Yujing Jiang, Xingjun Ma, Sarah M. Erfani, James Bailey 0001 |
IJCNN | 2 |
| 2021 | Microwave Link Failures Prediction via LSTM-based Feature Fusion NetworkabstractMicrowave links are widely employed in cellular data networks due to high-speed Internet access and easy installation, thus reducing network implementation costs. However, these links are prone to failure and may lead to performance degradation, unavailability and service disruption. Early detection of any link failures is critical to maintain network quality, but the complex environment and the dynamic nature of link information makes this a complicated process. In this work, we propose a Long Short-Term Memory (LSTM)-based feature fusion network (LSTM-FFN) to fuse and encode both homophy and structural equivalence relationships in the LSTM temporal feature learning network. This will simultaneously model the spatial and temporal features exhibited in Long-Term Evolution (LTE) networks to detect any link failures. Our proposed method effectively avoids the gradient exploding problem that RNN-based STGNN faced. This multi-scale topological feature fusion allows the LSTM-FFN to further explore the spatial dependencies among nodel/ink and include additional structural equivalence in modeling compared with previous network failure detection work. The evaluation results show that LSTM- FFN outperforms other statistical-based methods with and without network topology encoded, and reaches 94.1 % precision, 90.2 % recall and 92.1 % fl-score. Zichan Ruan, Shuiqiao Yang, Lei Pan 0002, Xingjun Ma, Wei Luo 0001, Marthie Grobler |
IJCNN | 4 |
| 2021 | Federated Learning with Extreme Label Skew: A Data Extension ApproachabstractThe real-world data sets often leveraged by Federated Learning (FL) applications are mostly non-independent and non-identically distributed (non-IID). This usually results from the diverse nature of the participating clients and their individual data-gathering contexts. An effective FL algorithm must incorporate the capability to produce a joint model that generalizes and captures these diverse patterns. In this work, we show how using some wild external data samples as placeholders for missing classes on client devices can alleviate the learning difficulty often posed by inbalance data distributions. Our exploration showed that this strategy enhances learning and can significantly boost test accuracy, particularly in extreme label skew scenarios. We recorded over 25% reduction in test error rate for the pathological non-IID partitions of the CIFAR10 data set. Our results are similar to those obtainable through bound-expanding strategies such as direct data sharing among clients. But unlike these techniques, our approach rules out the risk of exposing client's private data. Saheed A. Tijani, Xingjun Ma, Frank Jiang 0001, Robin Doss |
IJCNN | 2 |
| 2021 | $\alpha$-IoU: A Family of Power Intersection over Union Losses for Bounding Box RegressionabstractBounding box (bbox) regression is a fundamental task in computer vision. So far, the most commonly used loss functions for bbox regression are the Intersection over Union (IoU) loss and its variants. In this paper, we generalize existing IoU-based losses to a new family of power IoU losses that have a power IoU term and an additional power regularization term with a single power parameter $\alpha$. We call this new family of losses the $\alpha$-IoU losses and analyze properties such as order preservingness and loss/gradient reweighting. Experiments on multiple object detection benchmarks and models demonstrate that $\alpha$-IoU losses, 1) can surpass existing IoU-based losses by a noticeable performance margin; 2) offer detectors more flexibility in achieving different levels of bbox regression accuracy by modulating $\alpha$; and 3) are more robust to small datasets and noisy bboxes. Jiabo He, Sarah M. Erfani, Xingjun Ma, James Bailey 0001, Ying Chi, Xian-Sheng Hua 0001 |
NeurIPS | 3 |
| 2021 | Exploring Architectural Ingredients of Adversarially Robust Deep Neural NetworksabstractDeep neural networks (DNNs) are known to be vulnerable to adversarial attacks. A range of defense methods have been proposed to train adversarially robust DNNs, among which adversarial training has demonstrated promising results. However, despite preliminary understandings developed for adversarial training, it is still not clear, from the architectural perspective, what configurations can lead to more robust DNNs. In this paper, we address this gap via a comprehensive investigation on the impact of network width and depth on the robustness of adversarially trained DNNs. Specifically, we make the following key observations: 1) more parameters (higher model capacity) does not necessarily help adversarial robustness; 2) reducing capacity at the last stage (the last group of blocks) of the network can actually improve adversarial robustness; and 3) under the same parameter budget, there exists an optimal architectural configuration for adversarial robustness. We also provide a theoretical analysis explaning why such network configuration can help robustness. These architectural insights can help design adversarially robust DNNs. Hanxun Huang, Yisen Wang 0001, Sarah M. Erfani, Quanquan Gu, James Bailey 0001, Xingjun Ma |
NeurIPS | 6 |
| 2021 | Anti-Backdoor Learning: Training Clean Models on Poisoned DataabstractBackdoor attack has emerged as a major security threat to deep neural networks (DNNs). While existing defense methods have demonstrated promising results on detecting or erasing backdoors, it is still not clear whether robust training methods can be devised to prevent the backdoor triggers being injected into the trained model in the first place. In this paper, we introduce the concept of \emph{anti-backdoor learning}, aiming to train \emph{clean} models given backdoor-poisoned data. We frame the overall learning process as a dual-task of learning the \emph{clean} and the \emph{backdoor} portions of data. From this view, we identify two inherent characteristics of backdoor attacks as their weaknesses: 1) the models learn backdoored data much faster than learning with clean data, and the stronger the attack the faster the model converges on backdoored data; 2) the backdoor task is tied to a specific class (the backdoor target class). Based on these two weaknesses, we propose a general learning scheme, Anti-Backdoor Learning (ABL), to automatically prevent backdoor attacks during training. ABL introduces a two-stage \emph{gradient ascent} mechanism for standard training to 1) help isolate backdoor examples at an early training stage, and 2) break the correlation between backdoor examples and the target class at a later training stage. Through extensive experiments on multiple benchmark datasets against 10 state-of-the-art attacks, we empirically show that ABL-trained models on backdoor-poisoned data achieve the same performance as they were trained on purely clean data. Code is available at \url{https://github.com/bboylyg/ABL}. Yige Li, Xixiang Lyu, Nodens Koren, Lingjuan Lyu, Bo Li 0026, Xingjun Ma |
NeurIPS | 6 |
| 2021 | Gradient Driven Rewards to Guarantee Fairness in Collaborative Machine LearningabstractIn collaborative machine learning(CML), multiple agents pool their resources(e.g., data) together for a common learning task. In realistic CML settings where the agents are self-interested and not altruistic, they may be unwilling to share data or model information without adequate rewards. Furthermore, as the data/model information shared by the agents may differ in quality, designing rewards which are fair to them is important so that they would not feel exploited nor discouraged from sharing. In this paper, we adopt federated learning as the CML paradigm, propose a novel cosine gradient Shapley value(CGSV) to fairly evaluate the expected marginal contribution of each agent’s uploaded model parameter update/gradient without needing an auxiliary validation dataset, and based on the CGSV, design a novel training-time gradient reward mechanism with a fairness guarantee by sparsifying the aggregated parameter update/gradient downloaded from the server as reward to each agent such that its resulting quality is commensurate to that of the agent’s uploaded parameter update/gradient. We empirically demonstrate the effectiveness of our fair gradient reward mechanism on multiple benchmark datasets in terms of fairness, predictive performance, and time overhead. Lingjuan Lyu, Xingjun Ma, Chenglin Miao, Chuan-Sheng Foo, Kian Hsiang Low |
NeurIPS | 3 |
| 2021 | Relationships Between Local Intrinsic Dimensionality and Tail Entropy
James Bailey 0001, Michael E. Houle, Xingjun Ma |
SISAP | 3 |
| 2021 | Sub-trajectory Similarity Join with ObfuscationabstractUser trajectory data is becoming increasingly accessible due to the prevalence of GPS-equipped devices such as smartphones. Many existing studies focus on querying trajectories that are similar to each other in their entirety. We observe that trajectories partially similar to each other contain useful information about users’ travel patterns which should not be ignored. Such partially similar trajectories are critical in applications such as epidemic contact tracing. We thus propose to query trajectories that are within a given distance range from each other for a given period of time. We formulate this problem as a sub-trajectory similarity join query named as the STS-Join. We further propose a distributed index structure and a query algorithm for STS-Join, where users retain their raw location data and only send obfuscated trajectories to a server for query processing. This helps preserve user location privacy which is vital when dealing with such data. Theoretical analysis and experiments on real data confirm the effectiveness and the efficiency of our proposed index structure and query algorithm. Yanchuan Chang, Jianzhong Qi 0001, Egemen Tanin, Xingjun Ma, Hanan Samet |
SSDBM | 4 |
| 2021 | Anomaly Detection for Scenario-based Insider Activities using CGAN Augmented DataabstractInsider threats are the cyber attacks from the trusted entities within an organization. An insider attack is hard to detect as it may not leave a footprint and potentially cause huge damage to organizations. Anomaly detection is the most common approach for insider threat detection. Lack of real-world data and the skewed class distribution in the datasets makes insider threat analysis an understudied research area. In this paper, we propose a Conditional Generative Adversarial Network (CGAN) to enrich under-represented minority class samples to provide meaningful and diverse data for anomaly detection from the original malicious scenarios. Comprehensive experiments performed on benchmark dataset demonstrates the effectiveness of using CGAN augmented data, and the capability of multi-class anomaly detection for insider activity analysis. Moreover, the method is compared with other existing methods against different parameters and performance metrics. R. G. Gayathri, Atul Sajjanhar, Yong Xiang 0001, Xingjun Ma |
TrustCom | 4 |
| 2021 | Understanding adversarial attacks on deep learning based medical image analysis systems
Xingjun Ma, Yuhao Niu, Lin Gu 0003, Yisen Wang 0001, Yitian Zhao, James Bailey 0001, Feng Lu 0005 |
Pattern Recognit. | 1 |
| 2020 | Transfer of Automated Performance Feedback Models to Different Specimens in Virtual Reality Temporal Bone Surgery
Jesslyn Lamtara, Nathan Hanegbi, Benjamin Talks, Sudanthi N. R. Wijewickrema, Xingjun Ma, Patorn Piromchai, James Bailey 0001, Stephen J. O'Leary |
AIED (1) | 5 |
| 2020 | Adversarial Camouflage: Hiding Physical-World Attacks With Natural StylesabstractDeep neural networks (DNNs) are known to be vulnerable to adversarial examples. Existing works have mostly focused on either digital adversarial examples created via small and imperceptible perturbations, or physical-world adversarial examples created with large and less realistic distortions that are easily identified by human observers. In this paper, we propose a novel approach, called Adversarial Camouflage (\emph{AdvCam}), to craft and camouflage physical-world adversarial examples into natural styles that appear legitimate to human observers. Specifically, \emph{AdvCam} transfers large adversarial perturbations into customized styles, which are then “hidden” on-target object or off-target background. Experimental evaluation shows that, in both digital and physical-world scenarios, adversarial examples crafted by \emph{AdvCam} are well camouflaged and highly stealthy, while remaining effective in fooling state-of-the-art DNN image classifiers. Hence, \emph{AdvCam} is a flexible approach that can help craft stealthy attacks to evaluate the robustness of DNNs. Ranjie Duan, Xingjun Ma, Yisen Wang 0001, James Bailey 0001, A. K. Qin 0001, Yun Yang 0001 |
CVPR | 2 |
| 2020 | Clean-Label Backdoor Attacks on Video Recognition ModelsabstractDeep neural networks (DNNs) are vulnerable to backdoor attacks which can hide backdoor triggers in DNNs by poisoning training data. A backdoored model behaves normally on clean test images, yet consistently predicts a particular target class for any test examples that contain the trigger pattern. As such, backdoor attacks are hard to detect, and have raised severe security concerns in real-world applications. Thus far, backdoor research has mostly been conducted in the image domain with image classification models. In this paper, we show that existing image backdoor attacks are far less effective on videos, and outline 4 strict conditions where existing attacks are likely to fail: 1) scenarios with more input dimensions (eg. videos), 2) scenarios with high resolution, 3) scenarios with a large number of classes and few examples per class (a ``sparse dataset"), and 4) attacks with access to correct labels (eg. clean-label attacks). We propose the use of a universal adversarial trigger as the backdoor trigger to attack video recognition models, a situation where backdoor attacks are likely to be challenged by the above 4 strict conditions. We show on benchmark video datasets that our proposed backdoor attack can manipulate state-of-the-art video models with high success rates by poisoning only a small proportion of training data (without changing the labels). We also show that our proposed backdoor attack is resistant to state-of-the-art backdoor defense/detection methods, and can even be applied to improve image backdoor attacks. Our proposed video backdoor attack not only serves as a strong baseline for improving the robustness of video models, but also provides a new perspective for more understanding more powerful backdoor attacks. Xingjun Ma, James Bailey 0001, Jingjing Chen 0001, Yu-Gang Jiang 0001 |
CVPR | 2 |
| 2020 | Short-Term and Long-Term Context Aggregation Network for Video Inpainting
Ang Li 0008, Shanshan Zhao 0001, Xingjun Ma, Mingming Gong, Jianzhong Qi 0001, Rui Zhang 0003, Dacheng Tao, Kotagiri Ramamohanarao |
ECCV (4) | 3 |
| 2020 | Reflection Backdoor: A Natural Backdoor Attack on Deep Neural Networks
Yunfei Liu 0001, Xingjun Ma, James Bailey 0001, Feng Lu 0005 |
ECCV (10) | 2 |
| 2020 | Improving Adversarial Robustness Requires Revisiting Misclassified Examples
Yisen Wang 0001, Difan Zou, Jinfeng Yi, James Bailey 0001, Xingjun Ma, Quanquan Gu |
ICLR | 5 |
| 2020 | Skip Connections Matter: On the Transferability of Adversarial Examples Generated with ResNets
Dongxian Wu, Yisen Wang 0001, Shutao Xia, James Bailey 0001, Xingjun Ma |
ICLR | 5 |
| 2020 | Normalized Loss Functions for Deep Learning with Noisy LabelsabstractRobust loss functions are essential for training accurate deep neural networks (DNNs) in the presence of noisy (incorrect) labels. It has been shown that the commonly used Cross Entropy (CE) loss is not robust to noisy labels. Whilst new loss functions have been designed, they are only partially robust. In this paper, we theoretically show by applying a simple normalization that: \emph{any loss can be made robust to noisy labels}. However, in practice, simply being robust is not sufficient for a loss function to train accurate DNNs. By investigating several robust loss functions, we find that they suffer from a problem of \emph{underfitting}. To address this, we propose a framework to build robust loss functions called \emph{Active Passive Loss} (APL). APL combines two robust loss functions that mutually boost each other. Experiments on benchmark datasets demonstrate that the family of new loss functions created by our APL framework can consistently outperform state-of-the-art methods by large margins, especially under large noise rates such as 60% or 80% incorrect labels. Xingjun Ma, Hanxun Huang, Yisen Wang 0001, Simone Romano 0003, Sarah M. Erfani, James Bailey 0001 |
ICML | 1 |
| 2020 | WildDeepfake: A Challenging Real-World Dataset for Deepfake DetectionabstractIn recent years, the abuse of a face swap technique called deepfake has raised enormous public concerns. So far, a large number of deepfake videos (known as "deepfakes") have been crafted and uploaded to the internet, calling for effective countermeasures. One promising countermeasure against deepfakes is deepfake detection. Several deepfake datasets have been released to support the training and testing of deepfake detectors, such as DeepfakeDetection [1] and FaceForensics++ [23]. While this has greatly advanced deepfake detection, most of the real videos in these datasets are filmed with a few volunteer actors in limited scenes, and the fake videos are crafted by researchers using a few popular deepfake softwares. Detectors developed on these datasets may become less effective against real-world deepfakes on the internet. To better support detection against real-world deepfakes, in this paper, we introduce a new dataset WildDeepfake, which consists of 7,314 face sequences extracted from 707 deepfake videos collected completely from the internet. WildDeepfake is a small dataset that can be used, in addition to existing datasets, to develop and test the effectiveness of deepfake detectors against real-world deepfakes. We conduct a systematic evaluation of a set of baseline detection networks on both existing and our WildDeepfake datasets, and show that WildDeepfake is indeed a more challenging dataset, where the detection performance can decrease drastically. We also propose two (eg. 2D and 3D) Attention-based Deepfake Detection Networks (ADDNets) to leverage the attention masks on real/fake faces for improved detection. We empirically verify the effectiveness of ADDNets on both existing datasets and WildDeepfake. The dataset is available at: https://github.com/deepfakeinthewild/deepfake-in-the-wild. Bojia Zi, Minghao Chang, Jingjing Chen 0001, Xingjun Ma, Yu-Gang Jiang 0001 |
ACM Multimedia | 4 |
| 2020 | Exploiting patterns to explain individual predictions
Yunzhe Jia, James Bailey 0001, Kotagiri Ramamohanarao, Christopher Leckie, Xingjun Ma |
Knowl. Inf. Syst. | 5 |
| 2020 | Towards Fair and Privacy-Preserving Federated Deep ModelsabstractThe current standalone deep learning framework tends to result in overfitting and low utility. This problem can be addressed by either a centralized framework that deploys a central server to train a global model on the joint data from all parties, or a distributed framework that leverages a parameter server to aggregate local model updates. Server-based solutions are prone to the problem of a single-point-of-failure. In this respect, collaborative learning frameworks, such as federated learning (FL), are more robust. Existing federated learning frameworks overlook an important aspect of participation: fairness. All parties are given the same final model without regard to their contributions. To address these issues, we propose a decentralized Fair and Privacy-Preserving Deep Learning (FPPDL) framework to incorporate fairness into federated deep learning models. In particular, we design a local credibility mutual evaluation mechanism to guarantee fairness, and a three-layer onion-style encryption scheme to guarantee both accuracy and privacy. Different from existing FL paradigm, under FPPDL, each participant receives a different version of the FL model with performance commensurate with his contributions. Experiments on benchmark datasets demonstrate that FPPDL balances fairness, privacy and accuracy. It enables federated learning ecosystems to detect and isolate low-contribution parties, thereby promoting responsible participation. Lingjuan Lyu, Jiangshan Yu, Karthik Nandakumar, Yitong Li 0002, Xingjun Ma, Jiong Jin, Han Yu 0001, Kee Siong Ng |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2019 | Symmetric Cross Entropy for Robust Learning With Noisy LabelsabstractTraining accurate deep neural networks (DNNs) in the presence of noisy labels is an important and challenging task. Though a number of approaches have been proposed for learning with noisy labels, many open issues remain. In this paper, we show that DNN learning with Cross Entropy (CE) exhibits overfitting to noisy labels on some classes ("easy" classes), but more surprisingly, it also suffers from significant under learning on some other classes ("hard" classes). Intuitively, CE requires an extra term to facilitate learning of hard classes, and more importantly, this term should be noise tolerant, so as to avoid overfitting to noisy labels. Inspired by the symmetric KL-divergence, we propose the approach of Symmetric cross entropy Learning (SL), boosting CE symmetrically with a noise robust counterpart Reverse Cross Entropy (RCE). Our proposed SL approach simultaneously addresses both the under learning and overfitting problem of CE in the presence of noisy labels. We provide a theoretical analysis of SL and also empirically show, on a range of benchmark and real-world datasets, that SL outperforms state-of-the-art methods. We also show that SL can be easily incorporated into existing methods in order to further enhance their performance. Yisen Wang 0001, Xingjun Ma, Zaiyi Chen, Yuan Luo 0003, Jinfeng Yi, James Bailey 0001 |
ICCV | 2 |
| 2019 | On the Convergence and Robustness of Adversarial TrainingabstractImproving the robustness of deep neural networks (DNNs) to adversarial examples is an important yet challenging problem for secure deep learning. Across existing defense techniques, adversarial training with Projected Gradient Decent (PGD) is amongst the most effective. Adversarial training solves a min-max optimization problem, with the inner maximization generating adversarial examples by maximizing the classification loss, and the outer minimization finding model parameters by minimizing the loss on adversarial examples generated from the inner maximization. A criterion that measures how well the inner maximization is solved is therefore crucial for adversarial training. In this paper, we propose such a criterion, namely First-Order Stationary Condition for constrained optimization (FOSC), to quantitatively evaluate the convergence quality of adversarial examples found in the inner maximization. With FOSC, we find that to ensure better robustness, it is essential to use adversarial examples with better convergence quality at the later stages of training. Yet at the early stages, high convergence quality adversarial examples are not necessary and may even lead to poor robustness. Based on these observations, we propose a dynamic training strategy to gradually increase the convergence quality of the generated adversarial examples, which significantly improves the robustness of adversarial training. Our theoretical and empirical results show the effectiveness of the proposed method. Yisen Wang 0001, Xingjun Ma, James Bailey 0001, Jinfeng Yi, Bowen Zhou 0001, Quanquan Gu |
ICML | 2 |
| 2019 | Generative Image Inpainting with Submanifold AlignmentabstractImage inpainting aims at restoring missing regions of corrupted images, which has many applications such as image restoration and object removal. However, current GAN-based generative inpainting models do not explicitly exploit the structural or textural consistency between restored contents and their surrounding contexts. To address this limitation, we propose to enforce the alignment (or closeness) between the local data submanifolds (subspaces) around restored images and those around the original (uncorrupted) images during the learning process of GAN-based inpainting models. We exploit Local Intrinsic Dimensionality (LID) to measure, in deep feature space, the alignment between data submanifolds learned by a GAN model and those of the original data, from a perspective of both images (denoted as iLID) and local patches (denoted as pLID) of images. We then apply iLID and pLID as regularizations for GAN-based inpainting models to encourage two different levels of submanifold alignments: 1) an image-level alignment to improve structural consistency, and 2) a patch-level alignment to improve textural details. Experimental results on four benchmark datasets show that our proposed model can generate more accurate results than state-of-the-art models. Ang Li 0008, Jianzhong Qi 0001, Rui Zhang 0003, Xingjun Ma, Kotagiri Ramamohanarao |
IJCAI | 4 |
| 2019 | Black-box Adversarial Attacks on Video Recognition ModelsabstractDeep neural networks (DNNs) are known for their vulnerability to adversarial examples. These are examples that have undergone small, carefully crafted perturbations, and which can easily fool a DNN into making misclassifications at test time. Thus far, the field of adversarial research has mainly focused on image models, under either a white-box setting, where an adversary has full access to model parameters, or a black-box setting where an adversary can only query the target model for probabilities or labels. Whilst several white-box attacks have been proposed for video models, black-box video attacks are still unexplored. To close this gap, we propose the first black-box video attack framework, called V-BAD. V-BAD utilizestentative perturbations transferred from image models andpartition-based rectifications found by the NES to obtain good adversarial gradient estimates with fewer queries to the target model. V-BAD is equivalent to estimating the projection of the adversarial gradient on a selected subspace. Using three benchmark video datasets, we demonstrate that V-BAD can craft both untargeted and targeted attacks to fool two state-of-the-art deep video recognition models. For the targeted attack, it achieves $>$93% success rate using only an average of $3.4 \sim 8.4 \times 10^4$ queries, a similar number of queries to state-of-the-art black-box image attacks. This is despite the fact that videos often have two orders of magnitude higher dimensionality than static images. We believe that V-BAD is a promising new tool to evaluate and improve the robustness of video recognition models to black-box adversarial attacks. Linxi Jiang, Xingjun Ma, Shaoxiang Chen 0001, James Bailey 0001, Yu-Gang Jiang 0001 |
ACM Multimedia | 2 |
| 2018 | Providing Automated Real-Time Technical Feedback for Virtual Reality Based Surgical Training: Is the Simpler the Better?
Sudanthi N. R. Wijewickrema, Xingjun Ma, Patorn Piromchai, Robert Briggs 0002, James Bailey 0001, Gregor E. Kennedy, Stephen J. O'Leary |
AIED (1) | 2 |
| 2018 | Development and Validation of a Virtual Reality Tutor to Teach Clinically Oriented Surgical Anatomy of the EarabstractVirtual reality (VR) is being increasingly used in medical education. However, investigations into its effectiveness in this field have yielded mixed results, indicating that no general conclusions can be drawn in this regard. Therefore, the suitability of a system to teach a given task has to be investigated on a case-by-case basis. In this paper, we focus on teaching clinically oriented surgical ear anatomy, as it is important to provide a well-rounded view of ear anatomy as a foundation for understanding clinical surgery. Although there are some VR systems that teach basic ear anatomy, for example, identification of structures and spatial relationships, to our knowledge, those that deliver a complete clinical understanding of ear anatomy do not yet exist. As such, we discuss the design and development of a 3D interactive VR tutor with integrated haptic capability to teach clinically oriented surgical anatomy of the ear and establish its effectiveness through a user study. Sudanthi N. R. Wijewickrema, Bridget Copson, Xingjun Ma, Robert Briggs 0002, James Bailey 0001, Gregor E. Kennedy, Stephen J. O'Leary |
CBMS | 3 |
| 2018 | Iterative Learning With Open-Set Noisy LabelsabstractLarge-scale datasets possessing clean label annotations are crucial for training Convolutional Neural Networks (CNNs). However, labeling large-scale data can be very costly and error-prone, and even high-quality datasets are likely to contain noisy (incorrect) labels. Existing works usually employ a closed-set assumption, whereby the samples associated with noisy labels possess a true class contained within the set of known classes in the training data. However, such an assumption is too restrictive for many applications, since samples associated with noisy labels might in fact possess a true class that is not present in the training data. We refer to this more complex scenario as the open-set noisy label problem and show that it is nontrivial in order to make accurate predictions. To address this problem, we propose a novel iterative learning framework for training CNNs on datasets with open-set noisy labels. Our approach detects noisy labels and learns deep discriminative features in an iterative fashion. To benefit from the noisy label detection, we design a Siamese network to encourage clean labels and noisy labels to be dissimilar. A reweighting module is also applied to simultaneously emphasize the learning from clean labels and reduce the effect caused by noisy labels. Experiments on CIFAR-10, ImageNet and real-world noisy (web-search) datasets demonstrate that our proposed model can robustly train CNNs in the presence of a high proportion of open-set as well as closed-set noisy labels. Yisen Wang 0001, Weiyang Liu, Xingjun Ma, James Bailey 0001, Hongyuan Zha, Shutao Xia |
CVPR | 3 |
| 2018 | Characterizing Adversarial Subspaces Using Local Intrinsic Dimensionality
Xingjun Ma, Bo Li 0026, Yisen Wang 0001, Sarah M. Erfani, Sudanthi N. R. Wijewickrema, Grant Schoenebeck, Dawn Song, Michael E. Houle, James Bailey 0001 |
ICLR | 1 |
| 2018 | Dimensionality-Driven Learning with Noisy LabelsabstractDatasets with significant proportions of noisy (incorrect) class labels present challenges for training accurate Deep Neural Networks (DNNs). We propose a new perspective for understanding DNN generalization for such datasets, by investigating the dimensionality of the deep representation subspace of training samples. We show that from a dimensionality perspective, DNNs exhibit quite distinctive learning styles when trained with clean labels versus when trained with a proportion of noisy labels. Based on this finding, we develop a new dimensionality-driven learning strategy, which monitors the dimensionality of subspaces during training and adapts the loss function accordingly. We empirically demonstrate that our approach is highly tolerant to significant proportions of noisy labels, and can effectively learn low-dimensional local subspaces that capture the data distribution. Xingjun Ma, Yisen Wang 0001, Michael E. Houle, Shuo Zhou 0001, Sarah M. Erfani, Shutao Xia, Sudanthi N. R. Wijewickrema, James Bailey 0001 |
ICML | 1 |
| 2017 | Unbiased Multivariate Correlation AnalysisabstractCorrelation measures are a key element of statistics and machine learning, and essential for a wide range of data analysis tasks. Most existing correlation measures are for pairwise relationships, but real-world data can also exhibit complex multivariate correlations, involving three or more variables. We argue that multivariate correlation measures should be comparable, interpretable, scalable and unbiased. However, no existing measures satisfy all these requirements. In this paper, we propose an unbiased multivariate correlation measure, called UMC, which satisfies all the above criteria. UMC is a cumulative entropy based non-parametric multivariate correlation measure, which can capture both linear and non-linear correlations for groups of three or more variables. It employs a correction for chance using a statistical model of independence to address the issue of bias. UMC has high interpretability and we empirically show it outperforms state-of-the-art multivariate correlation measures in terms of statistical power, as well as for use in both subspace clustering and outlier detection tasks. Yisen Wang 0001, Simone Romano 0003, Vinh Nguyen 0003, James Bailey 0001, Xingjun Ma, Shutao Xia |
AAAI | 5 |
| 2017 | Simulation for Training Cochlear Implant Electrode InsertionabstractCochlear implant surgery is performed to restore hearing in patients with a range of hearing disorders. To optimise hearing outcomes, trauma during the insertion of a cochlear implant electrode has to be minimised. Factors that contribute to the degree of trauma caused during surgery include: the location of the electrode, type of electrode, and the competence level of the surgeon. Surgical competence depends on knowledge of anatomy and experience in a range of situations, along with technical skills. Thus, during training, a surgeon should be exposed to a range of anatomical variations, where he/she can learn and practice the intricacies of the surgical procedure, as well as explore different implant options and consequences thereof. Virtual reality simulation offers a versatile platform on which such training can be conducted. In this paper, we discuss a prototype implementation for the visualisation and analysis of electrode trajectories in relation to anatomical variation, prior to its inclusion in a virtual reality training module for cochlear implant surgery. Xingjun Ma, Sudanthi N. R. Wijewickrema, Yun Zhou 0002, Bridget Copson, James Bailey 0001, Gregor E. Kennedy, Stephen J. O'Leary |
CBMS | 1 |
| 2017 | Design and Evaluation of a Virtual Reality Simulation Module for Training Advanced Temporal Bone SurgeryabstractSurgical education has traditionally relied on cadaveric dissection and supervised training in the operating theatre. However, both these forms of training have become inefficient due to issues such as scarcity of cadavers and competing priorities taking up surgeons time. Within this context, computer-based simulations such as virtual reality have gained popularity as supplemental modes of training. Virtual reality simulation offers repeated practice in a riskfree environment where standardised surgical training modules can be developed, along with systems to provide automated guidance and assessment. In this paper, we discuss the design and evaluation of such a training module, specifically aimed at training an advanced temporal bone procedure, namelycochlear implant surgery. Sudanthi N. R. Wijewickrema, Bridget Copson, Yun Zhou 0002, Xingjun Ma, Robert Briggs 0002, James Bailey 0001, Gregor E. Kennedy, Stephen J. O'Leary |
CBMS | 4 |
| 2017 | Adversarial Generation of Real-time Feedback with Neural Networks for Simulation-based TrainingabstractSimulation-based training (SBT) is gaining popularity as a low-cost and convenient training technique in a vast range of applications. However, for a SBT platform to be fully utilized as an effective training tool, it is essential that feedback on performance is provided automatically in real-time during training. It is the aim of this paper to develop an efficient and effective feedback generation method for the provision of real-time feedback in SBT. Existing methods either have low effectiveness in improving novice skills or suffer from low efficiency, resulting in their inability to be used in real-time. In this paper, we propose a neural network based method to generate feedback using the adversarial technique. The proposed method utilizes a bounded adversarial update to minimize a L1 regularized loss via back-propagation. We empirically show that the proposed method can be used to generate simple, yet effective feedback. Also, it was observed to have high effectiveness and efficiency when compared to existing methods, thus making it a promising option for real-time feedback generation in SBT. Xingjun Ma, Sudanthi N. R. Wijewickrema, Shuo Zhou 0001, Yun Zhou 0002, Zakaria Mhammedi, Stephen J. O'Leary, James Bailey 0001 |
IJCAI | 1 |
| 2017 | Providing Effective Real-Time Feedback in Simulation-Based Surgical Training
Xingjun Ma, Sudanthi N. R. Wijewickrema, Yun Zhou 0002, Shuo Zhou 0001, Stephen J. O'Leary, James Bailey 0001 |
MICCAI (2) | 1 |