VLDB 2026 Research / reviewers in the wild / expert
Fulan Qian
dblp:201/6594
· DBLP profile ↗
25ranked-venue papers
12as first author
23since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 11 · 4 first-author · 9 since 2021Databases, data management, data science and information retrieval · 6 · 4 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 4 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Eff-DFQT: Efficient Model Inversion for Data-free Quantization of Vision TransformersabstractModel inversion is a promising technique for raw data reconstruction, especially in data-free quantization of Vision Transformers (ViTs). Previous inversion methods for ViTs have focused on extracting necessary foreground information while discarding irrelevant noise. However, these mode inversion methods for ViTs are inefficient in terms of data synthesis speed. In this paper, we propose a novel method to accelerate model inversion for efficient data-free quantization of ViTs(Eff-DFQT). Our method has the following features. 1) Token fusion strategy tailored for model inversion. We propose a token fusion strategy tailored for model inversion to lower the computations for image inversion. 2) Label compensation function. We propose a label compensation function to model the label uncertainty of the inverted image and accurately capture the real labels, which improves the quality of the inverted data by compensating for the negative effects of token reduction. Extensive experimental results demonstrate that Eff-DFQT, significantly accelerates the inversion process through token fusion strategy tailored for model inversion and label compensation function, while maintaining or even improving model performance in data-free quantization of ViTs. Mengkui Li, Xinrui Chen 0001, Hai Chen, Fulan Qian |
ICME | 7 |
| 2025 | Causality Meets the Table: Debiasing LLMs for Faithful TableQA via Front-Door InterventionabstractTable Question Answering (TableQA) combines natural language understanding and structured data reasoning, posing challenges in semantic interpretation and logical inference. Recent advances in Large Language Models (LLMs) have improved TableQA performance through Direct Prompting and Agent paradigms. However, these models often rely on spurious correlations, as they tend to overfit to token co-occurrence patterns in pretraining corpora, rather than perform genuine reasoning. To address this issue, we propose Causal Intervention TableQA (CIT), which is based on a structural causal graph and applies front-door adjustment to eliminate bias caused by token co-occurrence. CIT formalizes TableQA as a causal graph and identifies token co-occurrence patterns as confounders. By applying front-door adjustment, CIT guides question variant generation and reasoning to reduce confounding effects. Experiments on multiple benchmarks show that CIT achieves state-of-the-art performance, demonstrating its effectiveness in mitigating bias. Consistent gains across various LLMs further confirm its generalizability. Zhen Yang 0010, Ziwei Du, Minghan Zhang, Jie Chen 0025, Fulan Qian, Shu Zhao 0005 |
NeurIPS | 6 |
| 2025 | Crafting Transferable Adversarial Examples Against 3D Object DetectionabstractABSTRACT 3D object detection is one of the current popular hotspots by perceiving the surrounding environment through LiDAR and camera sensors to recognise the category and location of objects in the scene. Deep neural networks (DNNs) have been found to be vulnerable to adversarial examples. Although some approaches have begun to investigate the robustness of 3D object detection models, they are currently generating adversarial examples in a white‐box setting and there is a lack of research into generating transferable adversarial examples in a black‐box setting. In this paper, a non‐end‐to‐end attack algorithm was proposed for LiDAR pipelines that crafts transferable adversarial examples against 3D object detection. Specifically, the method generates adversarial examples by restraining features with high contribution to downstream tasks and amplifying features with low contribution to downstream tasks in the feature space. Extensive experiments validate that the method produces more transferable adversarial point clouds, for example, the method generates adversarial point clouds in the nuScenes dataset that are about 10 and 7 better than the state‐of‐the‐art method on mAP and NDS, respectively. Haiyan Long, Hai Chen, Chonghao Zhang, Fulan Qian |
IET Comput. Vis. | 5 |
| 2025 | Generating Transferable Adversarial Point Clouds via Autoencoders for 3D Object ClassificationabstractABSTRACT Recent studies have shown that deep neural networks are vulnerable to adversarial attacks. In the field of 3D point cloud classification, transfer‐based black‐box attack strategies have been explored to address the challenge of limited knowledge about the model in practical scenarios. However, existing approaches typically rely excessively on network structure, resulting in poor transferability of the generated adversarial examples. To address the above problem, the authors propose AEattack , an adversarial attack method capable of generating highly transferable adversarial examples. Specifically, AEattack employs an autoencoder (AE) to extract features from the point cloud data and reconstruct the adversarial point cloud based on these features. Notably, the AE does not require pre‐training, and its parameters are jointly optimised using a loss function during the process of generating adversarial point clouds. The method makes the generated adversarial point cloud not overly dependent on the network structure, but more concerned with the data distribution. Moreover, this design endows AEattack with a broader potential for application. Extensive experiments on the ModelNet40 dataset show that AEattack is capable of generating highly transferable adversarial point clouds, with up to 61.8% improvement in transferability compared to state‐of‐the‐art adversarial attacks. Hai Chen, Chonghao Zhang, Yuanjun Zou, Chenchu Xu, Fulan Qian |
IET Comput. Vis. | 7 |
| 2025 | Building robust deep recommender systems: Utilizing a weighted adversarial noise propagation framework with robust fine-tuning modules
Fulan Qian, Hai Chen, Jinggang Liu, Shu Zhao 0005, Yanping Zhang 0001 |
Knowl. Based Syst. | 1 |
| 2025 | IFM: Integrating and fine-tuning adversarial examples of recommendation system under multiple models to enhance their transferability
Fulan Qian, Yan Cui 0016, Hai Chen, Caihong Wu, Yuan-Ting Yan, Shu Zhao 0005 |
Knowl. Based Syst. | 1 |
| 2025 | Enhancing the Transferability of Adversarial Point Clouds by Initializing Transferable Adversarial NoiseabstractOne of the most popular methods for analyzing the robustness of 3D Deep Neural Networks (DNNs) is the transfer-based adversarial attack method, as it allows to analyze the robustness of an unknown model by generating an adversarial point cloud on an alternative model. However, the adversarial point clouds generated by current methods may overfit the surrogate models that generated them, thus limiting their performance in transfer attacks against different target 3D classifiers. To enhance the transferability of the adversarial point cloud, we propose in this letter an adversarial attack method by Initializing the Transferable Adversarial Noise, which named asITAN. Specifically, we pre-train on the training set a generator capable of generating the adversarial noise with transferability and diversity, and then the noise generated by the generator serves as the initial adversarial noise to be integrated into the iterations of the attack. Extensive experiments on well-recognized benchmark datasets demonstrate that the adversarial point clouds generated by the proposed ITAN could be effectively transferred across unknown 3D classifiers. Hai Chen, Shu Zhao 0005, Yuan-Ting Yan, Fulan Qian |
IEEE Signal Process. Lett. | 4 |
| 2025 | ANF: Crafting Transferable Adversarial Point Clouds via Adversarial Noise FactorizationabstractTransfer-based adversarial attacks involve generating adversarial point clouds in surrogate models and transferring them to other models to assess 3D model robustness. However, current methods rely too much on surrogate model parameters, limiting transferability. In this work, we use Shapley value to identify positive and negative features, guiding optimization of adversarial noise in feature space. To effectively mislead the 3D classifier, we factorize the adversarial noise into positive and negative noise, with the former keeping the features of the adversarial point cloud close to the negative features, and the latter and the adversarial noise moving it away from the positive features. Finally, a novel adversarial point cloud attack method with Adversarial Noise Factorization is proposed, which is abbreviated asANF. ANF simultaneously optimizes the adversarial noise and its positive and negative noise in the feature space, only relying on partial network parameters, which significantly reduces the reliance on the surrogate model and improves the transferability of the adversarial point cloud. Experiments on well-recognized benchmark datasets show that the transferability of adversarial point clouds generated by ANF could be improved by more than 26.7$\%$on average over state-of-the-art transfer-based adversarial attack methods. Hai Chen, Shu Zhao 0005, Xiao Yang 0028, Huanqian Yan, Yuan He 0011, Hui Xue 0001, Fulan Qian, Hang Su 0006 |
IEEE Trans. Big Data | 7 |
| 2025 | Enhanced Knowledge Tracing With Learnable FilterabstractThe primary objective of knowledge tracing (KT) is to evaluate students’ understanding and mastery of knowledge through their responses to exercises, which aids in predicting their future performance. Deep neural networks have been widely applied in the area of knowledge tracing and have demonstrated encouraging results. Nevertheless, in real-world scenarios, there is a substantial amount of noise in students’ response records. These noises may amplify the inherent risk of overfitting in deep neural networks, leading to a decrease in model performance. To address these issues, we introduce a new model called filter knowledge tracing (FKT). This innovative model incorporates a learnable filter into KT to filter out noise information from students’ exercise sequences. We redefine the input paradigm of the data, using learnable filters to perform filtering operations in its frequency domain representation space, effectively removing noise. Additionally, an attention module has been introduced in the FKT model to evaluate the impact of students’ historical interactions on their current knowledge state. To validate our model, we conduct extensive experiments utilizing four publicly available datasets. The results demonstrate that FKT outperforms existing benchmarks, particularly on larger datasets, signifying an improvement in KT performance while effectively reducing the risk of overfitting. Fulan Qian, Yetong Hu, Jie Chen 0025, Shijin Wang 0001, Shu Zhao 0005 |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2025 | Empowering Object Detection: Unleashing the Potential of Decoupled and Interactive DistillationabstractDeploying state-of-the-art object detectors on resource-limited devices presents significant challenges. Knowledge distillation is an efficient and streamlined lightweight technique to improve the accuracy of compact detectors. However, its effectiveness is limited by the redundancy of different types of semantics on the feature map and the closure of same level’s feature distillation. To alleviate this problem, we propose Decoupled and Interactive Distillation, an effective and versatile method to improve knowledge distillation in some complex object detection tasks. The method has two key components. A knowledge decoupled module captures category awareness and localization awareness features. A multi-level feature interaction distillation can aggregate feature distillations from shallow to deep levels, facilitating the collaboration between feature transfers at different levels. The relevant experiments in traffic-related, 3D, rotated object detection have verified the effectiveness of the proposed method, particularly in challenging scenes. Fulan Qian, Jiacheng Hong, Huanqian Yan, Hai Chen, Chonghao Zhang, Hang Su 0006, Shu Zhao 0005 |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2025 | Understanding the Robustness of Deep Recommendation under Adversarial AttacksabstractIt has been shown that deep recommendation models are susceptible to adversarial attacks, with this vulnerability potentially leading to significant economic losses in the e-commerce field. However, the robustness of deep recommendation models in response to adversarial attacks has not been systematically investigated. In this article, therefore, we comprehensively evaluate the adversarial robustness of various representative deep models in different settings, aiming to analyze their performance impact under adversarial attacks and compare it with traditional collaborative filtering models. Notably, we examine poisoning attacks under different proportions of fake users and various popularity conditions to understand why certain deep recommendation models perform exceptionally or sub-optimally. On this basis, we further proposed practical robustness improvement strategy for the problems found in the evaluation and fully verified it through rigorous experiments. Key findings include: (1) the sparser the training dataset, the weaker the robustness of a recommendation model’s performance under adversarial attacks; (2) deep recommendation models exhibit greater robustness in recommending popular items under adversarial attacks, while they are more vulnerable when attacked with non-popular items; (3) the robustness of deep recommendation models is not consistently weaker than that of traditional collaborative filtering models across all attack settings. These findings highlight the security concerns in deep recommendation systems and contribute to developing more reliable models. Fulan Qian, Hai Chen, Yan Cui 0016, Shu Zhao 0005, Yanping Zhang 0001 |
ACM Trans. Knowl. Discov. Data | 1 |
| 2025 | A Comprehensive Understanding of the Impact of Data Augmentation on the Transferability of 3D Adversarial Examplesabstract3D point cloud classifiers exhibit vulnerability to imperceptible perturbations, which poses a serious threat to the security and reliability of deep learning models in practical applications, making the robustness evaluation of deep 3D point cloud models increasingly important. Due to the difficulty in obtaining model parameters, black-box attacks have become a mainstream means of assessing the adversarial robustness of 3D classification models. The core of improving the transferability of adversarial examples generated by black-box attacks is to generate better generalized adversarial examples, where data augmentation has become one of the popular approaches. In this article, we employ five mainstream attack methods and combine six data augmentation strategies, namely point dropping, flipping, rotating, scaling, shearing, and translating, in order to comprehensively explore the impact of these strategies on the transferability of adversarial examples. Our research reveals that data augmentation methods generally improve the transferability of the adversarial examples, and the effect is better when the methods are stacked. The interaction between data augmentation methods, model characteristics, attack, and defense strategies collectively determines the transferability of adversarial examples. In order to comprehensively understand and improve the effectiveness of adversarial examples, it is necessary to comprehensively consider these complex interrelationships. Fulan Qian, Yuanjun Zou, Chonghao Zhang, Chenchu Xu, Hai Chen |
ACM Trans. Knowl. Discov. Data | 1 |
| 2024 | ReOP: Generating Transferable Fake Users for Recommendation Systems via Reverse OptimizationabstractRecent research has demonstrated that recommendation systems exhibit vulnerability under data poisoning attacks. The primary process of data poisoning attacks involves generating malicious data (i.e., fake users) through surrogate models and injecting the malicious data into the target models’ datasets, thereby manipulating the output results of the target models. However, current methods generating fake users based on gradient descent may cause them to fall into undesired local minimum in the loss landscape and overfitting to the surrogate model, thus limiting the performance of attacking other recommendation models. To address this problem, we propose the reverse optimization algorithm (ReOP), which utilizes the reverse direction of optimization to update fake users, enabling them to steer clear of sharp local minimum in loss landscape and navigate towards the flat local minimum. ReOP makes fake users less sensitive to model changes, alleviates their overfitting to the surrogate model, and thus significantly improves the transferability of fake users. Experimental results demonstrate that ReOP surpasses the state-of-the-art baseline methods, effectively generating fake users with significant attack effects on various target models. Fulan Qian, Yan Cui 0016, Hai Chen, Yuan-Ting Yan, Shu Zhao 0005 |
IEEE Trans. Comput. Soc. Syst. | 1 |
| 2024 | Efficient Adversarial Attack Strategy Against 3D Object Detection in Autonomous Driving SystemsabstractThe reliability and robustness of 3D object detection play an instrumental role in the practical deployment of autonomous driving systems. Despite previous research indicating that adversarial examples can negatively affect 3D object detection models, leading to misinterpretations of the environment, these models still maintain the capability to detect the majority of objects within adversarially manipulated point clouds. To further probe into the adversarial robustness of these models, we propose an effective adversarial attack method named IoU-S attack in this paper. We meticulously formulate the adversarial loss to adversely affect the decision-making behavior (such as localization, etc.) of 3D object detection, thereby compromising its ability to accurately interpret the environment. Owing to the significant relevance of this adversarial loss to 3D object detection tasks, we have integrated the IoU-S attack into three attack paradigms: point cloud perturbation, detachment, and attachment. Comprehensive experiments on the widely accepted nuScenes dataset illustrate that the IoU-S attack outperforms existing attack methods in both white-box and black-box scenarios (https://github.com/haichen-ber/IoU-S-Attack). It reinforces its potential to serve as a valuable method in understanding and enhancing the robustness of 3D object detection models against adversarial attacks. Hai Chen, Huanqian Yan, Xiao Yang 0028, Hang Su 0006, Shu Zhao 0005, Fulan Qian |
IEEE Trans. Intell. Transp. Syst. | 6 |
| 2024 | Training Robust Deep Collaborative Filtering Models via Adversarial Noise PropagationabstractThe recommendation performance of deep collaborative filtering models drops sharply under imperceptible adversarial perturbations. Some methods promote the robustness of recommendation systems by adversarial training. However, these methods only study shallow models and lack the exploration of deep models. Furthermore, the way these methods add adversarial noise to the weight parameters of users and items is not fully applicable to deep collaborative filtering models, because the adversarial noise is not sufficient to fully affect its network structure with multiple hidden layers. In this article, we propose a novel adversarial training framework, Random Layer-wise Adversarial Training (RAT), which trains a robust deep collaborative filtering model via adversarial noise propagation. Specifically, we inject adversarial noise into the output of the hidden layer in a random layer-wise manner. The adversarial noise propagates forward from the injected position to obtain more flexible model parameters during the adversarial training process. We validate the effectiveness of RAT on multilayer perceptron (MLP) and implement RAT on MLP-based and convolutional neural networks-based deep collaborative filtering models. Experiments on three publicly available datasets show that the deep collaborative filtering model trained by RAT not only defends against adversarial noise but also guarantees recommendation performance. Hai Chen, Fulan Qian, Chang Liu 0077, Yanping Zhang 0001, Hang Su 0006, Shu Zhao 0005 |
ACM Trans. Inf. Syst. | 2 |
| 2023 | Adaptive social recommendation combined with the multi-domain influence
Fulan Qian, Kaili Qin, Hai Chen, Jie Chen 0025, Shu Zhao 0005, Yanping Zhang 0001 |
Inf. Syst. | 1 |
| 2023 | GWNN-HF: beyond assortativity in graph wavelet neural network
Binfeng Huang, Fulan Qian, Shu Zhao 0005, Jie Chen 0025, Yanping Zhang 0001 |
Knowl. Inf. Syst. | 3 |
| 2023 | Utilizing the influence of multiple potential factors for social recommendation
Fulan Qian, Kaili Qin, Hai Chen, Jie Chen 0025, Shu Zhao 0005, Peng Zhou 0008, Yanping Zhang 0001 |
Knowl. Inf. Syst. | 1 |
| 2023 | Enhancing the Transferability of Adversarial Examples Based on Nesterov Momentum for Recommendation SystemsabstractThe attacker's malicious behavior of injecting well-designed adversarial examples (i.e., fake users) into recommender systems will severely affect the security of systems. It's difficult to fully obtain details of victim recommendation models (i.e., black-box model) in practical recommendation scenarios, using the transferability of adversarial examples to achieve black-box attacks is still an effective way. At present, adversarial examples generated by existing gradient-based methods are prone to drop into local minima, making it impossible to achieve the expected attack effect and reducing the transferability. In this article, we propose an attack algorithm that enhances the transferability of adversarial examples based on the Nesterov Momentum for Recommendation Systems (ETANRS). With white-box recommendation surrogate models, we utilize Nesterov momentum to generate better adversarial examples, then inject them into black-box victim models to attack. We utilize the accumulated gradients and pre-determine the update direction of the gradients to keep the optimal value from being lost, thus enhancing the transferability of the adversarial examples. Experimental results demonstrate that our method is better than state-of-the-art gradient-based attack algorithms, which affect recommendation performance. Fulan Qian, Bei Yuan, Hai Chen, Jie Chen 0025, Defu Lian, Shu Zhao 0005 |
IEEE Trans. Big Data | 1 |
| 2022 | Reduce unrelated Knowledge through Attribute Collaborative signal for knowledge graph recommendation
Fulan Qian, Yuhui Zhu, Hai Chen, Jie Chen 0025, Shu Zhao 0005, Yanping Zhang 0001 |
Expert Syst. Appl. | 1 |
| 2021 | Attribute-based Neural Collaborative Filtering
Hai Chen, Fulan Qian, Jie Chen 0025, Shu Zhao 0005, Yanping Zhang 0001 |
Expert Syst. Appl. | 2 |
| 2021 | FG-RS: Capture user fine-grained preferences through attribute information for Recommender Systems
Hai Chen, Fulan Qian, Jie Chen 0025, Shu Zhao 0005, Yanping Zhang 0001 |
Neurocomputing | 2 |
| 2021 | M-GWNN: Multi-granularity graph wavelet neural networks for semi-supervised node classification
Fulan Qian, Shu Zhao 0005, Yanping Zhang 0001 |
Neurocomputing | 2 |
| 2020 | Generative image inpainting for link prediction
Fulan Qian, Xiuquan Du, Shu Zhao 0005, Yanping Zhang 0001 |
Appl. Intell. | 1 |
| 2020 | Deep attention user-based collaborative filtering for recommendation
Jie Chen 0025, Xianshuang Wang, Shu Zhao 0005, Fulan Qian, Yanping Zhang 0001 |
Neurocomputing | 4 |