VLDB 2026 Research / reviewers in the wild / expert
Fahad Shamshad
dblp:208/7362
· DBLP profile ↗
13ranked-venue papers
4as first author
9since 2021 · last 2025
0000-0003-2442-0475ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 9 · 3 first-author · 6 since 2021Artificial intelligence and machine learning · 7 · 2 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 3 since 2021Security and privacy · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | STEREO: A Two-Stage Framework for Adversarially Robust Concept Erasing from Text-to-Image Diffusion ModelsabstractThe rapid proliferation of large-scale text-to-image diffusion (T2ID) models has raised serious concerns about their potential misuse in generating harmful content. Although numerous methods have been proposed for erasing undesired concepts from T2ID models, they often provide a false sense of security; concept-erased models (CEMs) can still be manipulated via adversarial attacks to regenerate the erased concept. While a few robust concept erasure methods based on adversarial training have emerged recently, they compromise on utility (generation quality for benign concepts) to achieve robustness and/or remain vulnerable to advanced embedding space attacks. These limitations stem from the failure of robust CEMs to thoroughly search for "blind spots" in the embedding space. To bridge this gap, we propose STEREO, a novel two-stage framework that employs adversarial training as a first step rather than the only step for robust concept erasure. In the first stage, STEREO employs adversarial training as a vulnerability identification mechanism to search thoroughly enough. In the second robustly erase once stage, STEREO introduces an anchor-concept-based compositional objective to robustly erase the target concept in a single fine-tuning stage, while minimizing the degradation of model utility. We benchmark STEREO against seven state-of-the-art concept erasure methods, demonstrating its superior robustness to both white-box and black-box attacks, while largely preserving utility. Koushik Srivatsan, Fahad Shamshad, Muzammal Naseer, Vishal M. Patel, Karthik Nandakumar |
CVPR | 2 |
| 2025 | TrojanWave: Exploiting Prompt Learning for Stealthy Backdoor Attacks on Large Audio-Language ModelsabstractPrompt learning has emerged as an efficient alternative to full fine-tuning for adapting large audio-language models (ALMs) to downstream tasks.While this paradigm enables scalable deployment via Prompt-as-a-Service frameworks, it also introduces a critical yet underexplored security risk of backdoor attacks.In this work, we present TrojanWave, the first backdoor attack tailored to the prompt-learning setting in frozen ALMs.Unlike prior audio backdoor methods that require training from scratch on full datasets, TrojanWave injects backdoors solely through learnable prompts, making it highly scalable and effective in few-shot settings.TrojanWave injects imperceptible audio triggers in both time and spectral domains to effectively induce targeted misclassification during inference.To mitigate this threat, we further propose TrojanWave-Defense, a lightweight prompt purification method that neutralizes malicious prompts without hampering the clean performance.Extensive experiments across 11 diverse audio classification benchmarks demonstrate the robustness and practicality of both the attack and defense.Our code is publicly available at Github † . Asif Hanif, Maha Tufail Agro, Fahad Shamshad, Karthik Nandakumar |
EMNLP | 3 |
| 2025 | FaceAnonyMixer: Cancelable Faces via Identity Consistent Latent Space MixingabstractAdvancements in face recognition (FR) technologies have amplified privacy concerns, necessitating methods that protect identity while maintaining recognition utility. Existing face anonymization methods typically focus on obscuring identity but fail to meet the requirements of biometric template protection, including revocability, unlinkability, and irreversibility. We propose FaceAnonyMixer, a cancelable face generation framework that leverages the latent space of a pre-trained generative model to synthesize privacy-preserving face images. The core idea of FaceAnonyMixer is to irreversibly mix the latent code of a real face image with a synthetic code derived from a revocable key. The mixed latent code is further refined through a carefully designed multi-objective loss to satisfy all cancelable biometric requirements. FaceAnonyMixer is capable of generating high-quality cancelable faces that can be directly matched using existing FR systems without requiring any modifications. Extensive experiments on benchmark datasets demonstrate that FaceAnonyMixer delivers superior recognition accuracy while providing significantly stronger privacy protection, achieving over an 11% absolute gain on commercial API compared to recent cancelable biometric methods. Code is available at: https://github.com/talha-alam/faceanonymixer Mohammed Talha Alam, Fahad Shamshad, Fakhri Karray, Karthik Nandakumar |
IJCB | 2 |
| 2024 | BAPLe: Backdoor Attacks on Medical Foundational Models Using Prompt Learning
Asif Hanif, Fahad Shamshad, Muhammad Awais Hassan, Muzammal Naseer, Fahad Shahbaz Khan, Karthik Nandakumar, Salman Khan 0001, Rao Muhammad Anwer |
MICCAI (12) | 2 |
| 2024 | PromptSmooth: Certifying Robustness of Medical Vision-Language Models via Prompt Learning
Noor Hussein, Fahad Shamshad, Muzammal Naseer, Karthik Nandakumar |
MICCAI (12) | 2 |
| 2023 | CLIP2Protect: Protecting Facial Privacy Using Text-Guided Makeup via Adversarial Latent SearchabstractThe success of deep learning based face recognition systems has given rise to serious privacy concerns due to their ability to enable unauthorized tracking of users in the digital world. Existing methods for enhancing privacy fail to generate “naturalistic” images that can protect facial privacy without compromising user experience. We propose a novel two-step approach for facial privacy protection that relies on finding adversarial latent codes in the low- dimensional manifold of a pretrained generative model. The first step inverts the given face image into the latent space and finetunes the generative model to achieve an accurate reconstruction of the given image from its latent code. This step produces a good initialization, aiding the generation of high-quality faces that resemble the given identity. Subsequently, user-defined makeup text prompts and identity- preserving regularization are used to guide the search for adversarial codes in the latent space. Extensive experiments demonstrate that faces generated by our approach have stronger black-box transferability with an absolute gain of 12.06% over the state-of-the-art facial privacy protection approach under the face verification task. Finally, we demonstrate the effectiveness of the proposed approach for commercial face recognition systems. Our code is available at https://github.com/fahadshamshad/Clip2Protect. Fahad Shamshad, Muzammal Naseer, Karthik Nandakumar |
CVPR | 1 |
| 2023 | Evading Forensic Classifiers with Attribute-Conditioned Adversarial FacesabstractThe ability of generative models to produce highly realistic synthetic face images has raised security and ethical concerns. As a first line of defense against such fake faces, deep learning based forensic classifiers have been developed. While these forensic models can detect whether a face image is synthetic or real with high accuracy, they are also vulnerable to adversarial attacks. Although such attacks can be highly successful in evading detection by forensic classifiers, they introduce visible noise patterns that are detectable through careful human scrutiny. Additionally, these attacks assume access to the target model(s) which may not always be true. Attempts have been made to directly perturb the latent space of GANs to produce adversarial fake faces that can circumvent forensic classifiers. In this work, we go one step further and show that it is possible to successfully generate adversarial fake faces with a specified set of attributes (e.g., hair color, eye size, race, gender, etc.). To achieve this goal, we leverage the state-of-the-art generative model StyleGAN with disentangled representations, which enables a range of modifications without leaving the manifold of natural images. We propose a framework to search for adversarial latent codes within the feature space of StyleGAN, where the search can be guided either by a text prompt or a reference image. We also propose a meta-learning based optimization strategy to achieve transferable performance on unknown target models. Extensive experiments demonstrate that the proposed approach can produce semantically manipulated adversarial fake faces, which are true to the specified attribute set and can successfully fool forensic face classifiers, while remaining undetectable by humans. Code: https://github.com/koushiksrivats/face_attribute_attack. Fahad Shamshad, Koushik Srivatsan, Karthik Nandakumar |
CVPR | 1 |
| 2023 | Transformers in medical imaging: A survey
Fahad Shamshad, Salman Khan 0001, Syed Waqas Zamir, Muhammad Haris Khan, Munawar Hayat, Fahad Shahbaz Khan, Huazhu Fu |
Medical Image Anal. | 1 |
| 2023 | Untrained Neural Network Priors for Inverse Imaging Problems: A SurveyabstractIn recent years, advancements in machine learning (ML) techniques, in particular, deep learning (DL) methods have gained a lot of momentum in solving inverse imaging problems, often surpassing the performance provided by hand-crafted approaches. Traditionally, analytical methods have been used to solve inverse imaging problems such as image restoration, inpainting, and superresolution. Unlike analytical methods for which the problem is explicitly defined and the domain knowledge is carefully engineered into the solution, DL models do not benefit from such prior knowledge and instead make use of large datasets to predict an unknown solution to the inverse problem. Recently, a new paradigm of training deep models using a single image, named untrained neural network prior (UNNP) has been proposed to solve a variety of inverse tasks, e.g., restoration and inpainting. Since then, many researchers have proposed various applications and variants of UNNP. In this paper, we present a comprehensive review of such studies and various UNNP applications for different tasks and highlight various open research problems which require further research. Adnan Qayyum, Inaam Ilahi, Fahad Shamshad, Farid Boussaïd, Mohammed Bennamoun, Junaid Qadir 0001 |
IEEE Trans. Pattern Anal. Mach. Intell. | 3 |
| 2020 | Single-Shot Retinal Image Enhancement Using Deep Image Priors
Adnan Qayyum, Waqas Sultani, Fahad Shamshad, Junaid Qadir 0001, Rashid Tufail |
MICCAI (5) | 3 |
| 2019 | Blind Image Deconvolution using Pretrained Generative Priors
Muhammad Asim 0005, Fahad Shamshad, Ali Ahmed 0004 |
BMVC | 2 |
| 2019 | Deep Ptych: Subsampled Fourier Ptychography Using Generative PriorsabstractThis paper proposes a novel framework to regularize the highly ill-posed and non-linear Fourier ptychography problem using generative models. We demonstrate experimentally that our proposed algorithm, Deep Ptych, outperforms the existing Fourier ptychography techniques, in terms of quality of reconstruction and robustness against noise, using far fewer samples. We further modify the proposed approach to allow the generative model to explore solutions outside the range, leading to improved performance. Fahad Shamshad, Farwa Abbas, Ali Ahmed 0004 |
ICASSP | 1 |
| 2017 | Introducing Data mining for Predicting trends in School Education of Pakistan: Preliminary results and Future DirectionsabstractIn this note we present our preliminary results relating the potential of data mining and machine learning techniques in educational setup of Pakistan. Our aim is to discover meaningful and insightful patterns out of the unstructured data collected during the monitoring process of these schools. After applying data science and machine learning techniques on Alif Ailaan district based school dataset of Pakistan we have shown that very useful latent performance metrics can be unveiled. We have highlighted important future directions and their potential of helping policy makers in making effective policies thus increasing the efficiency of the current educational infrastructure in Pakistan. Muhammad Asim 0005, Fahad Shamshad, Muhammad Awais Hassan, Ali Ahmed 0004 |
ICTD | 2 |