VLDB 2026 Research / reviewers in the wild / expert
Changjiang Li
dblp:216/3218
· DBLP profile ↗
29ranked-venue papers
6as first author
27since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 13 · 1 first-author · 12 since 2021Security and privacy · 13 · 4 first-author · 13 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-author · 4 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Bridging the Copyright Gap: Do Large Vision-Language Models Recognize and Respect Copyrighted Content?abstractLarge vision-language models (LVLMs) have achieved remarkable advancements in multimodal reasoning tasks. However, their widespread accessibility raises critical concerns about potential copyright infringement. Will LVLMs accurately recognize and comply with copyright regulations when encountering copyrighted content (i.e., user input, retrieved documents) in the context? Failure to comply with copyright regulations may lead to serious legal and ethical consequences, particularly when LVLMs generate responses based on copyrighted materials (e.g., retrieved book experts, news reports). In this paper, we present a comprehensive evaluation of various LVLMs, examining how they handle copyrighted content – such as book excerpts, news articles, music lyrics, and code documentation when they are presented as visual inputs. To systematically measure copyright compliance, we introduce a large-scale benchmark dataset comprising 50,000 multimodal query-content pairs designed to evaluate how effectively LVLMs handle queries that could lead to copyright infringement. Given that real-world copyrighted content may or may not include a copyright notice, the dataset includes query-content pairs in two distinct scenarios: with and without a copyright notice. For the former, we extensively cover four types of copyright notices to account for different cases. Our evaluation reveals that even state-of-the-art closed-source LVLMs exhibit significant deficiencies in recognizing and respecting the copyrighted content, even when presented with the copyright notice. To solve this limitation, we introduce a novel tool-augmented defense framework for copyright compliance, which reduces infringement risks in all scenarios. Our findings underscore the importance of developing copyright-aware LVLMs to ensure the responsible and lawful use of copyrighted content. Naen Xu, Jinghuai Zhang, Changjiang Li, Hengyu An, Chunyi Zhou 0001, Jun Wang 0001, Yuyuan Li 0001, Tianyu Du, Shouling Ji |
AAAI | 3 |
| 2026 | ACIArena: Toward Unified Evaluation for Agent Cascading InjectionabstractHengyu An, Minxi Li, Jinghuai Zhang, Naen Xu, Chunyi Zhou, Changjiang Li, Xiaogang Xu, Tianyu Du, Shouling Ji. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Hengyu An, Minxi Li, Jinghuai Zhang, Naen Xu, Chunyi Zhou 0001, Changjiang Li, Xiaogang Xu 0002, Tianyu Du, Shouling Ji |
ACL (1) | 6 |
| 2026 | "I See What You Did There": Can Large Vision-Language Models Understand Multimodal Puns?abstractNaen Xu, Jiayi Sheng, Changjiang Li, Chunyi Zhou, Yuyuan Li, Tianyu Du, Jun Wang, Zhihui Fu, Jinbao Li, Shouling Ji. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Naen Xu, Jiayi Sheng, Changjiang Li, Chunyi Zhou 0001, Yuyuan Li 0001, Tianyu Du, Zhihui Fu, Shouling Ji |
ACL (1) | 3 |
| 2026 | Compiling Activation Steering into Weights via Null-Space Constraints for Stealthy BackdoorsabstractRui Yin, Tianxu Han, Naen Xu, Changjiang Li, Ping He, Chunyi Zhou, Jun Wang, Zhihui Fu, Tianyu Du, Jinbao Li, Shouling Ji. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Tianxu Han, Naen Xu, Changjiang Li, Chunyi Zhou 0001, Jun Wang 0020, Zhihui Fu, Tianyu Du, Shouling Ji |
ACL (1) | 4 |
| 2026 | GraphRAG Under FireabstractGraphRAG advances retrieval-augmented generation (RAG) by structuring external knowledge as multi-scale knowledge graphs, enabling language models to integrate both broad context and granular details in their generation. While GraphRAG has demonstrated success across domains, its security implications remain largely unexplored. To bridge this gap, this work examines GraphRAG's vulnerability to poisoning attacks, uncovering an intriguing security paradox: existing RAG poisoning attacks are less effective under GraphRAG than conventional RAG, due to GraphRAG's graph-based indexing and retrieval; yet, the same features also create new attack surfaces. We present GragPoison, a novel attack that exploits shared relations in the underlying knowledge graph to craft poisoning text capable of compromising multiple queries simultaneously. GragPoison employs three key strategies: (i) relation injection to introduce false knowledge, (ii) relation enhancement to amplify poisoning influence, and (iii) narrative generation to embed malicious content within coherent text. Empirical evaluation across diverse datasets and models shows that GragPoison substantially outperforms existing attacks in terms of effectiveness (up to 98% success rate) and scalability (using less than 68% poisoning text) on multiple variations of GraphRAG. We also explore potential defensive measures and their limitations, identifying promising directions for future research. Jiacheng Liang, Yuhui Wang 0003, Changjiang Li, Tanqiu Jiang, Rongyi Zhu, Neil Zhenqiang Gong, Ting Wang 0006 |
SP | 3 |
| 2026 | Wideband Full-Polarization Reconfigurable Antenna for Intelligent IoT Applicationsabstractnovel wideband antenna with five reconfigurable polarization states is presented for intelligent IoT applications, where polarization agility can be exploited by a higher-layer controller to enhance link reliability in dynamic multipath environments. To achieve wideband performance across all polarization states, coupling mechanisms are strategically introduced into the radiation structure, feeding structure, and feeding network simultaneously. Firstly, through equivalent circuit analysis, shorting pins, metal strips, and slots are integrated into the radiation structure. The coupling mechanisms excite first- and second-order frequency responses, resulting in significant gain improvement and overlapping bandwidth enhancement. Secondly, a co-planar capacitive feeding structure is implemented into the feeding network to improve impedance matching. Subsequently, weakly coupled transmission lines are deployed within both differential and full-polarization feeding networks. Such a configuration ensures wide overlapping bandwidth performance throughout all five polarization states by suppressing phase shift errors. Finally, by controlling the ON/OFF states of PIN diodes, the feeding network generates desired phase differences, enabling the proposed antenna to be reconfigured between five polarization states, i.e., linearly polarization (LP) with three orientations, left-hand circularly polarization (LHCP), and right-hand circularly polarization (RHCP). Experimental results demonstrate that the antenna achieves an operating bandwidth of 8–13 GHz (47.6%), with axial ratio (AR) < 3.0 dB and in-band gain fluctuation < 3.0 dB. Characterized by wide bandwidth, full-polarization agility, and standard fabrication, the design presents a viable solution for demanding multi-polarization applications in industrial Internet of Things (IoT) scenarios. Changjiang Li, Jianxing Li, Baihong Chi, Ya Kong, Jianhe Wang, Xiaoming Chen 0002 |
IEEE Internet Things J. | 1 |
| 2026 | Hijack Vertical Federated Learning Models as One PartyabstractVertical Federated Learning (VFL) is an emerging paradigm that enables collaborators to build machine learning models together in a distributed fashion. However, the security of the VFL model remains underexplored, particularly regarding the Byzantine Generals Problem (BGP), which is a well-known issue in distributed systems. This paper focuses on revealing the threat of BGP in VFL systems. Specifically, we propose two attacks, the replay attack and the generation attack, to evaluate the vulnerability of VFL when there is only one malicious party. The goal of the adversary is to hijack the VFL model to give desired predictions. Moreover, considering the uneven distribution of importance among parties, we combine data poisoning with the aforementioned attacks to explore whether they can bypass the situation where the adversary has few features. The evaluation results demonstrate the effectiveness of our attacks. For instance, the adversary holding only 10 90 capability is limited and usually at the cost of performance loss of the VFL task. Our work highlights the need for advanced defenses to protect the prediction results of a VFL model and calls for more exploration of VFL's security issues. Pengyu Qiu, Xuhong Zhang 0002, Shouling Ji, Changjiang Li, Yuwen Pu, Xing Yang 0004, Ting Wang 0006 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | Automatic Red Teaming LLM-Based Agents With Model Context Protocol ToolsabstractThe remarkable capability of large language models (LLMs) has led to the wide application of LLM-based agents in various domains. To standardize interactions between LLM-based agents and external resources, model context protocol (MCP) tools have become the de facto standard and are now widely integrated into these agents. However, the incorporation of MCP tools introduces the risk of tool poisoning attacks, in which malicious MCP tools can steer the behavior of LLM-based agents toward unintended outcomes. Although previous studies have identified such vulnerabilities, their red teaming approaches have largely remained at the proof-of-concept stage, leaving the automatic red teaming of LLM-based agents under the MCP tool poisoning paradigm an open question. To bridge this gap, we propose AutoMalTool, an automated red teaming framework for LLM-based agents by generating malicious MCP tools. Our extensive evaluation shows that AutoMalTool effectively generates malicious MCP tools capable of manipulating the behavior of mainstream LLM-based agents while evading current detection mechanisms, thereby revealing new security risks in these agents. Changjiang Li, Tianyu Du, Shouling Ji |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | AIA: Autoregression-Based Injection Attacks Against Text2SQL ModelsabstractTo facilitate understanding of users' diverse queries against the back-end databases in web applications, researchers have introduced Text-to-SQL (Text2SQL) models that can generate well-structured SQL queries from users' query texts in natural language. As the Text2SQL model decouples the user queries with the back-end databases, it inherently mitigates the SQL injection risk posed by inserting users' input into pre-written SQL queries. However, what security risks to web applications may be posed by Text2SQL models remains an open question. In this paper, we present a new attack framework, named Autoregression-based Injection Attacks (AIA), to evaluate the security risks of Text2SQL models. In particular, AIA makes target models generate attack payloads by constructing specific inputs and adjusting the input auto-regressively. Our evaluation demonstrates that AIA can cause Text2SQL models to generate target output by adversarial inputs with success rates of over 70% in most scenarios. The generated adversarial input has certain transferability in target Text2SQL models. Additionally, practice experiments show that AIA can make Text2SQL models extract user lists from databases and even delete data in databases directly. Deyin Li, Xiang Ling 0001, Changjiang Li, Xiang Chen 0017, Chunming Wu 0001 |
AAAI | 3 |
| 2025 | You Can't Steal Nothing: Mitigating Prompt Leakages in LLMs via System VectorsabstractLarge language models (LLMs) have been widely adopted across various applications, leveraging customized system prompts for diverse tasks. Facing potential system prompt leakage risks, model developers have implemented strategies to prevent leakage, primarily by disabling LLMs from repeating their context when encountering known attack patterns. However, it remains vulnerable to new and unforeseen prompt-leaking techniques. In this paper, we first introduce a simple yet effective prompt leaking attack to reveal such risks. Our attack is capable of extracting system prompts from various LLM-based application, even from SOTA LLM models such as GPT-4o or Claude 3.5 Sonnet. Our findings further inspire us to search for a fundamental solution to the problems by having no system prompt in the context. To this end, we propose SysVec, a novel method that encodes system prompts as internal representation vectors rather than raw text. By doing so, SysVec minimizes the risk of unauthorized disclosure while preserving the LLM's core language capabilities. Remarkably, this approach not only enhances security but also improves the model's general instruction-following abilities. Experimental results demonstrate that SysVec effectively mitigates prompt leakage attacks, preserves the LLM's functional integrity, and helps alleviate the forgetting issue in long-context scenarios. Bochuan Cao, Changjiang Li, Yuanpu Cao, Yameng Ge, Ting Wang 0006 |
CCS | 2 |
| 2025 | VideoEraser: Concept Erasure in Text-to-Video Diffusion ModelsabstractThe rapid growth of text-to-video (T2V) diffusion models has raised concerns about privacy, copyright, and safety due to their potential misuse in generating harmful or misleading content. These models are often trained on numerous datasets, including unauthorized personal identities, artistic creations, and harmful materials, which can lead to uncontrolled production and distribution of such content. To address this, we propose VideoEraser, a training-free framework that prevents T2V diffusion models from generating videos with undesirable concepts, even when explicitly prompted with those concepts. Designed as a plug-and-play module, VideoEraser can seamlessly integrate with representative T2V diffusion models via a two-stage process: Selective Prompt Embedding Adjustment (SPEA) and Adversarial-Resilient Noise Guidance (ARNG). We conduct extensive evaluations across four tasks, including object erasure, artistic style erasure, celebrity erasure, and explicit content erasure. Experimental results show that VideoEraser consistently outperforms prior methods regarding efficacy, integrity, fidelity, robustness, and generalizability. Notably, VideoEraser achieves state-of-the-art performance in suppressing undesirable content during T2V generation, reducing it by 46% on average across four tasks compared to baselines. Naen Xu, Jinghuai Zhang, Changjiang Li, Chunyi Zhou 0001, Qingming Li, Tianyu Du, Shouling Ji |
EMNLP | 3 |
| 2025 | RAPID: Retrieval Augmented Training of Differentially Private Diffusion ModelsabstractDifferentially private diffusion models (DPDMs) harness the remarkable generative capabilities of diffusion models while enforcing differential privacy (DP) for sensitive data. However, existing DPDM training approaches often suffer from significant utility loss, large memory footprint, and expensive inference cost, impeding their practical uses.
To overcome such limitations, we present RAPID: Retrieval Augmented PrIvate Diffusion model, a novel approach that integrates retrieval augmented generation (RAG) into DPDM training. Specifically, RAPID leverages available public data to build a knowledge base of sample trajectories; when training the diffusion model on private data, RAPID computes the early sampling steps as queries, retrieves similar trajectories from the knowledge base as surrogates, and focuses on training the later sampling steps in a differentially private manner. Extensive evaluation using benchmark datasets and models demonstrates that, with the same privacy guarantee, RAPID significantly outperforms state-of-the-art approaches by large margins in generative quality, memory footprint, and inference cost, suggesting that retrieval-augmented DP training represents a promising direction for developing future privacy-preserving generative models. The code is available at: https://github.com/TanqiuJiang/RAPID Tanqiu Jiang, Changjiang Li, Fenglong Ma, Ting Wang 0006 |
ICLR | 2 |
| 2025 | RobustKV: Defending Large Language Models against Jailbreak Attacks via KV EvictionabstractJailbreak attacks circumvent LLMs' built-in safeguards by concealing harmful queries within adversarial prompts. While most existing defenses attempt to mitigate the effects of adversarial prompts, they often prove inadequate as adversarial prompts can take arbitrary, adaptive forms. This paper introduces RobustKV, a novel jailbreak defense that takes a fundamentally different approach by selectively removing critical tokens of harmful queries from key-value (KV) caches. Intuitively, for an adversarial prompt to be effective, its tokens must achieve sufficient `importance' (measured by attention scores), which consequently lowers the importance of tokens in the concealed harmful query. Therefore, by carefully evicting the KVs of low-ranked tokens, RobustKV minimizes the harmful query's presence in the KV cache, thus preventing the LLM from generating informative responses. Extensive evaluation using benchmark datasets and models demonstrates that RobustKV effectively counters state-of-the-art jailbreak attacks while maintaining the LLM's performance on benign queries. Notably, RobustKV creates an interesting effectiveness-evasiveness dilemma for the adversary, leading to its robustness against adaptive attacks.{(Warning: This paper contains potentially harmful content generated by LLMs.)} Tanqiu Jiang, Jiacheng Liang, Changjiang Li, Yuhui Wang 0003, Ting Wang 0006 |
ICLR | 4 |
| 2025 | Watch the Watchers! On the Security Risks of Robustness-Enhancing Diffusion Models
Changjiang Li, Ren Pang, Bochuan Cao, Fenglong Ma, Shouling Ji, Ting Wang 0006 |
USENIX Security Symposium | 1 |
| 2025 | PRSA: Prompt Stealing Attacks against Real-World Prompt Services
Yong Yang 0017, Changjiang Li, Qingming Li, Oubo Ma, Zonghui Wang, Yandong Gao, Wenzhi Chen, Shouling Ji |
USENIX Security Symposium | 2 |
| 2025 | Invisible-Face: Rethinking Facial Attribute Privacy in Social Media Photo SharingabstractAs social media gains popularity, users frequently share personal photos without recognizing the risks of exposing their faces to advanced facial attribute detection technologies. These technologies can extract sensitive attributes such as age, race, sexual orientation, and potential health information from facial images, raising significant privacy concerns. Despite the availability of various anonymization techniques, our research reveals that current methods inadequately protect facial attribute privacy. They often fail to balance effectiveness and utility, underscoring the pressing need for more robust solutions in today’s pervasive photo-sharing culture. To remedy this gap, we introduce Invisible-Face, a tool designed to safeguard users’ facial attribute privacy using advanced adversarial perturbation techniques. Invisible-Face uses local, directional, and resilient perturbation generative strategies to obfuscate multiple facial attributes effectively, thus ensuring privacy while retaining the utility of the facial images. Our comprehensive evaluation across various datasets and model architectures shows that Invisible-Face significantly outperforms existing privacy-preserving methods in terms of effectiveness while maintaining high image naturalness. Furthermore, our extensive real-world evaluations on four popular MLaaS platforms—Baidu Brain, Tencent Cloud, Aliyun, and Face++—reveal that Invisible-Face achieves comparable privacy protection results while preserving the visual naturalness of images, outperforming existing methods. These findings boost public awareness about the importance of facial attribute privacy and urge online social platforms to improve their protection measures. Yong Yang 0017, Changjiang Li, Xuhong Zhang 0002, Zonghui Wang, Shouling Ji, Wenzhi Chen |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Model Extraction Attacks RevisitedabstractModel extraction (ME) attacks represent one major threat to Machine-Learning-as-a-Service (MLaaS) platforms by "stealing" the functionality of confidential machine-learning models through querying black-box APIs. Over seven years have passed since ME attacks were first conceptualized in the seminal work [75]. During this period, substantial advances have been made in both ME attacks and MLaaS platforms, raising the intriguing question: How has the vulnerability of MLaaS platforms to ME attacks been evolving? Jiacheng Liang, Ren Pang, Changjiang Li, Ting Wang 0006 |
AsiaCCS | 3 |
| 2024 | Towards Query-Efficient Decision-Based Adversarial Attacks Through Frequency DomainabstractDeep neural networks are vulnerable to adversarial examples, where decision-based attacks can generate adversarial examples based solely on the predicted labels. However, these attacks typically require excessive queries to attack one example. Considering this challenge, we propose FBA (Frequency based Boundary Attack), a decision-based attack against the limitation of query efficiency. FBA incorporates a novel search process, utilizing high-frequency based importance sampling for efficient gradient estimation. Empirical results confirm the superior query efficiency of our method. Specifically, FBA surpasses SOTA attacks by achieving a 54% average improvement in query efficiency, quantified by the reduction in perturbation size within the same number of queries. Jianhao Fu, Xiang Ling 0001, Yaguan Qian, Changjiang Li, Tianyue Luo, JingZheng Wu |
ICME | 4 |
| 2024 | Improving the Robustness of Transformer-based Large Language Models with Dynamic Attention
Lujia Shen, Yuwen Pu, Shouling Ji, Changjiang Li, Xuhong Zhang 0002, Chunpeng Ge 0001, Ting Wang 0006 |
NDSS | 4 |
| 2024 | On the Difficulty of Defending Contrastive Learning against Backdoor Attacks
Changjiang Li, Ren Pang, Bochuan Cao, Zhaohan Xi, Shouling Ji, Ting Wang 0006 |
USENIX Security Symposium | 1 |
| 2023 | An Embarrassingly Simple Backdoor Attack on Self-supervised LearningabstractAs a new paradigm in machine learning, self-supervised learning (SSL) is capable of learning high-quality representations of complex data without relying on labels. In addition to eliminating the need for labeled data, research has found that SSL improves the adversarial robustness over supervised learning since lacking labels makes it more challenging for adversaries to manipulate model predictions. However, the extent to which this robustness superiority generalizes to other types of attacks remains an open question.We explore this question in the context of backdoor attacks. Specifically, we design and evaluate Ctrl, an embarrassingly simple yet highly effective self-supervised backdoor attack. By only polluting a tiny fraction of training data (≤ 1%) with indistinguishable poisoning samples, Ctrl causes any trigger-embedded input to be misclassified to the adversary's designated class with a high probability (≥ 99%) at inference time. Our findings suggest that SSL and supervised learning are comparably vulnerable to backdoor attacks. More importantly, through the lens of Ctrl, we study the inherent vulnerability of SSL to backdoor attacks. With both empirical and analytical evidence, we reveal that the representation invariance property of SSL, which benefits adversarial robustness, may also be the very reason making SSL highly susceptible to backdoor attacks. Our findings also imply that the existing defenses against supervised backdoor attacks are not easily retrofitted to the unique vulnerability of SSL. Code is available at: https://github.com/meet-cjli/CTRL Changjiang Li, Ren Pang, Zhaohan Xi, Tianyu Du, Shouling Ji, Yuan Yao 0001, Ting Wang 0006 |
ICCV | 1 |
| 2023 | The Dark Side of AutoML: Towards Architectural Backdoor Search
Ren Pang, Changjiang Li, Zhaohan Xi, Shouling Ji, Ting Wang 0006 |
ICLR | 2 |
| 2023 | IMPRESS: Evaluating the Resilience of Imperceptible Perturbations Against Unauthorized Data Usage in Diffusion-Based Generative AIabstractDiffusion-based image generation models, such as Stable Diffusion or DALL·E 2, are able to learn from given images and generate high-quality samples following the guidance from prompts. For instance, they can be used to create artistic images that mimic the style of an artist based on his/her original artworks or to maliciously edit the original images for fake content. However, such ability also brings serious ethical issues without proper authorization from the owner of the original images. In response, several attempts have been made to protect the original images from such unauthorized data usage by adding imperceptible perturbations, which are designed to mislead the diffusion model and make it unable to properly generate new samples. In this work, we introduce a perturbation purification platform, named IMPRESS, to evaluate the effectiveness of imperceptible perturbations as a protective measure.
IMPRESS is based on the key observation that imperceptible perturbations could lead to a perceptible inconsistency between the original image and the diffusion-reconstructed image, which can be used to devise a new optimization strategy for purifying the image, which may weaken the protection of the original image from unauthorized data usage (e.g., style mimicking, malicious editing).
The proposed IMPRESS platform offers a comprehensive evaluation of several contemporary protection methods, and can be used as an evaluation platform for future protection methods. Bochuan Cao, Changjiang Li, Ting Wang 0006, Jinyuan Jia 0001, Bo Li 0026 |
NeurIPS | 2 |
| 2023 | Defending Pre-trained Language Models as Few-shot Learners against Backdoor AttacksabstractPre-trained language models (PLMs) have demonstrated remarkable performance as few-shot learners. However, their security risks under such settings are largely unexplored. In this work, we conduct a pilot study showing that PLMs as few-shot learners are highly vulnerable to backdoor attacks while existing defenses are inadequate due to the unique challenges of few-shot scenarios. To address such challenges, we advocate MDP, a novel lightweight, pluggable, and effective defense for PLMs as few-shot learners. Specifically, MDP leverages the gap between the masking-sensitivity of poisoned and clean samples: with reference to the limited few-shot data as distributional anchors, it compares the representations of given samples under varying masking and identifies poisoned samples as ones with significant variations. We show analytically that MDP creates an interesting dilemma for the attacker to choose between attack effectiveness and detection evasiveness. The empirical evaluation using benchmark datasets and representative attacks validates the efficacy of MDP. The code of MDP is publicly available. Zhaohan Xi, Tianyu Du, Changjiang Li, Ren Pang, Shouling Ji, Fenglong Ma, Ting Wang 0006 |
NeurIPS | 3 |
| 2023 | On the Security Risks of Knowledge Graph Reasoning
Zhaohan Xi, Tianyu Du, Changjiang Li, Ren Pang, Shouling Ji, Xiapu Luo, Xusheng Xiao, Fenglong Ma, Ting Wang 0006 |
USENIX Security Symposium | 3 |
| 2022 | Seeing is Living? Rethinking the Security of Facial Liveness Verification in the Deepfake Era
Changjiang Li, Li Wang 0120, Shouling Ji, Xuhong Zhang 0002, Zhaohan Xi, Shanqing Guo, Ting Wang 0006 |
USENIX Security Symposium | 1 |
| 2022 | Towards Certifying the Asymmetric Robustness for Neural Networks: Quantification and ApplicationsabstractOne intriguing property of deep neural networks (DNNs) is their vulnerability to adversarial examples – those maliciously crafted inputs that deceive target DNNs. While a plethora of defenses have been proposed to mitigate the threats of adversarial examples, they are often penetrated or circumvented by even stronger attacks. To end the constant arms race between attackers and defenders, significant efforts have been devoted to providing certifiable robustness bounds for DNNs, which ensures that for a given input its vicinity does not admit any adversarial instances. Yet, most prior works focus on the case of symmetric vicinities (e.g., a hyperrectangle centered at a given input), while ignoring the inherent heterogeneity of perturbation direction (e.g., the input is more vulnerable along a particular perturbation direction). To bridge the gap, in this article, we propose the concept ofasymmetric robustnessto account for the inherent heterogeneity of perturbation directions, and presentAmoeba1, an efficient certification framework for asymmetric robustness. Through extensive empirical evaluation on state-of-the-art DNNs and benchmark datasets, we show that compared with its symmetric counterpart, the asymmetric robustness bound of a given input describes its local geometric properties in a more precise manner, which enables use cases including (i) modeling stronger adversarial threats, (ii) interpreting DNN predictions, and makes it a more practical definition of certifiable robustness for security-sensitive domains. Changjiang Li, Shouling Ji, Haiqin Weng, Bo Li 0026, Raheem A. Beyah, Shanqing Guo, Zonghui Wang, Ting Wang 0006 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2020 | Deep learning-based visual ensemble method for high-speed railway catenary clevis fracture detection
Zhigang Liu 0001, Yang Lyu, Changjiang Li |
Neurocomputing | 5 |
| 2018 | A High-Precision Loose Strands Diagnosis Approach for Isoelectric Line in High-Speed RailwayabstractThe isoelectric line is an important component that connects the steady arm and the drop bracket of catenary in high-speed railway. The loose strands of isoelectric line can be commonly observed in real-life applications. In this paper, an automatic fault detection system for the loose strands of the isoelectric line is proposed. This system consists of three stages. First, a convolutional neural network is adopted to extract the isoelectric line features. To accurately and quickly learn these features, an improved feature extraction network, called as the isoelectric line network, is presented. Using the images captured from catenary inspection vehicles, the image areas that contain the isoelectric lines are obtained based on the Faster region-based convolutional neural network. Second, the image segmentation is carried out based on the Markov random field model. And, the accurate isoelectric line pixels are obtained from the smallest image area extracted from the first stage. In the final stage, the fault state is given by analyzing the quantity of the independent connection regions and the pixels' standard deviation. Experimental results show that the proposed system has a high detection accuracy. Furthermore, compared with the convolutional neural networks (the Simonyan and Zisserman model and the Zeiler and Fergus model) and a typical detection method (Histogram of Oriented Gradient + Support Vector Machine), the proposed network has better performance for the isoelectric line location. Zhigang Liu 0001, Liyou Wang, Changjiang Li, Zhiwei Han |
IEEE Trans. Ind. Informatics | 3 |