Xia Du

dblp:219/0780 · DBLP profile ↗
← Back
19ranked-venue papers
7as first author
17since 2021 · last 2026
0000-0002-6298-846XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 10 · 3 first-author · 8 since 2021Artificial intelligence and machine learning · 8 · 2 first-author · 8 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2026 IO-RAE: Information-Obfuscation Reversible Adversarial Example for Audio Privacy Protection
abstract
The rapid advancements in artificial intelligence have significantly accelerated the adoption of speech recognition technology, leading to its widespread integration across various applications. However, this surge in usage also highlights a critical issue: audio data is highly vulnerable to unauthorized exposure and analysis, posing significant privacy risks for businesses and individuals. This paper introduces an Information-Obfuscation Reversible Adversarial Example (IO-RAE) framework, the pioneering method designed to safeguard audio privacy using reversible adversarial examples. IO-RAE leverages large language models to generate misleading yet contextually coherent content, effectively preventing unauthorized eavesdropping by humans and Automatic Speech Recognition (ASR) systems. Additionally, we propose the Cumulative Signal Attack technique, which mitigates high-frequency noise and enhances attack efficacy by targeting low-frequency signals. Our approach ensures the protection of audio data without degrading its quality or usability. Experimental evaluations demonstrate the superiority of our method, achieving a targeted misguidance rate of 96.5% and a remarkable 100% untargeted misguidance rate in obfuscating target keywords across multiple ASR models, including a commercial black-box system from Google. Furthermore, the quality of the recovered audio, measured by the Perceptual Evaluation of Speech Quality score, reached 4.45, comparable to high-quality original recordings. Notably, the recovered audio processed by ASR systems exhibited an error rate of 0%, indicating nearly lossless recovery. These results highlight the practical applicability and effectiveness of our IO-RAE framework in protecting sensitive audio privacy.
Xia Du, Jizhe Zhou 0001, Qizhen Xu, Zheng Lin 0001, Chi-Man Pun
AAAI2
2026 CIV: Leveraging causal subgraphs of vulnerability for noise reduction in vulnerability detection
Lei Xiao 0013, Xia Du
Expert Syst. Appl.3
2026 Eliminating the optimization gap: A dual-temperature approach to supervised contrastive learning
Yifan Wu 0031, Lei Xiao 0013, Xia Du
Expert Syst. Appl.4
2026 Diffbias: Harnessing diffusion models' prediction bias for adversarial patch defense
Xudong Ye, Qi Zhang 0059, Yapeng Wang 0001, Xu Yang 0010, Zuobin Ying, Jingzhang Sun, Xia Du
Neurocomputing8
2026 Defensive Adversarial CAPTCHA: A Semantics-Driven Framework for Natural Adversarial Example Generation
abstract
Traditional CAPTCHA (Completely Automated Public Turing Test to Tell Computers and Humans Apart) schemes are increasingly vulnerable to automated attacks powered by deep neural networks (DNNs). Existing adversarial attack methods often rely on the original image characteristics, resulting in distortions that hinder human interpretation and limit their applicability in scenarios where no initial input images are available. To address these challenges, we propose the Unsourced Adversarial CAPTCHA (DAC), a novel framework that generates high-fidelity adversarial examples guided by attacker-specified semantics information. Leveraging a Large Language Model (LLM), DAC enhances CAPTCHA diversity and enriches the semantic information. To address various application scenarios, we examine the white-box targeted attack scenario and the black-box untargeted attack scenario. For target attacks, we introduce two latent noise variables that are alternately guided in the diffusion step to achieve robust inversion. The synergy between gradient guidance and latent variable optimization achieved in this way ensures that the generated adversarial examples not only accurately align with the target conditions but also achieve optimal performance in terms of distributional consistency and attack effectiveness. In untargeted attacks, especially for black-box scenarios, we introduce bi-path unsourced adversarial CAPTCHA (BP-DAC), a two-step optimization strategy employing multimodal gradients and bi-path optimization for efficient misclassification. Experiments show that the defensive adversarial CAPTCHA generated by BP-DAC is able to defend against most of the unknown models, and the generated CAPTCHA is indistinguishable to both humans and DNNs.
Xia Du, Jizhe Zhou 0001, Zheng Lin 0001, Chi-Man Pun, Cong Wu 0003, Tao Li 0001, Zhe Chen 0015, Wei Ni 0001, Jun Luo 0001
IEEE Trans. Dependable Secur. Comput.1
2026 PASK: Sparse Framework for Crafting Natural Adversarial Example
abstract
As audio adversarial attacks continue to evolve, Automatic Speech Recognition (ASR) models have emerged as a significant target. Traditional audio attack methods often focus on minimizing perturbation magnitude and frequency, overlooking the importance of perturbation location. However, certain audio regions hold lower importance for ASR models, making attacks on these regions less effective and more perceptible as noise. Additionally, the human ear perceives noise differently depending on its placement within the audio sequence, with noise in silent segments being more noticeable. To address these challenges, this paper proposes Pitch Sparse Audio Attack (PASK), an innovative framework designed to enhance adversarial imperceptibility through sparse perturbations. PASK introduces two key techniques: Pitch Mapping, which provides a strategic starting point for perturbation, and an adaptive grouped selective mask that achieves targeted sparsity, focusing perturbations on high-impact audio regions. Experimental results demonstrate that PASK outperforms existing methods in both effectiveness and imperceptibility. Furthermore, a human study confirms that silent-segment perturbations are more easily detected, underscoring the perceptual advantages of our approach.
Xia Du, Jizhe Zhou 0001, Qizhen Xu, Chi-Man Pun
IEEE Trans. Multim.2
2025 Investigating Value-Reasoning Reliability in Small Large Language Models
abstract
Although small Large Language models (sLLMs) have been widely deployed in practical applications, little attention has been paid to their value-reasoning abilities, particularly in terms of reasoning reliability. To address this gap, we propose a systematic evaluation framework for assessing the Value-Reasoning Reliability of sLLMs. We define Value-Reasoning Reliability as comprising: (1) Output consistency under identical prompts, (2) Output Robustness under semantically equivalent prompts, (3) Maintaining stable value reasoning in the face of attacks, and (4) Consistency of value reasoning in open-ended value expression tasks. Our framework includes three core tasks: Repetition Consistency task, Interaction Stability task, and Open-ended Expression Consistency task. We further incorporate self-reported confidence scores to evaluate the model’s value reasoning reliability from two perspectives: the model’s self-awareness of its values, and its value-based decision-making. Our findings show that models vary significantly in their stability when responding to value-related questions. Moreover, we observe considerable output randomness, which is not always correlated with the self-reported confidence or expressed value preferences. This suggests that current models lack a reliable internal mechanism for stable value reasoning when addressing value-sensitive queries.
Xia Du, Shuhan Sun
EMNLP1
2025 DP-TRAE: A Dual-Phase Merging Transferable Reversible Adversarial Example for Image Privacy Protection
abstract
In the field of digital security, Reversible Adversarial Examples (RAE) combine adversarial attacks with reversible data hiding techniques to effectively protect sensitive data and prevent unauthorized analysis by malicious Deep Neural Networks (DNNs). However, existing RAE techniques primarily focus on white-box attacks, lacking a comprehensive evaluation of their effectiveness in black-box scenarios. This limitation impedes their broader deployment in complex, dynamic environments. Furthermore, traditional black-box attacks are often characterized by poor transferability and high query costs, significantly limiting their practical applicability. To address these challenges, we propose the Dual-Phase Merging Transferable Reversible Attack method, which generates highly transferable initial adversarial perturbations in a white-box model and employs a memory-augmented black-box strategy to effectively mislead target models. Experimental results demonstrate the superiority of our approach, achieving a 99.0% attack success rate and 100% recovery rate in black-box scenarios with the DN-121 target model and 1000 attack iterations, highlighting its robustness in privacy protection. Moreover, we successfully implemented a black-box attack on a commercial model, further substantiating the potential of this approach for practical use.
Xia Du, Jizhe Zhou 0001, Chi-Man Pun, Zheng Lin 0001, Cong Wu 0003, Zhe Chen 0015, Jun Luo 0001
IEEE Trans. Dependable Secur. Comput.1
2025 Cross-Modal Driven Object Restoration for 3D Point Cloud Backdoor Defense
abstract
3D point cloud recognition plays a critical role in autonomous driving, robotics, and medical diagnostics. However, its vulnerability to backdoor attacks remains underexplored, posing significant security risks in real-world applications. Current defense mechanisms against 3D point cloud backdoor attacks are still in their infancy and lacking effective solutions. To address this, we propose a cross-modal driven object restoration framework that leverages 3D reconstruction to mitigate backdoor attacks. Specifically, we introduce a cross-modal semantic encoding module that projects 3D point clouds into multi-view depth maps and utilizes CLIP to extract aligned text-image features, providing semantic guidance for 3D reconstruction. Furthermore, we leverage cross-modal information as conditional guidance to drive dynamic diffusion-based 3D reconstruction and adaptively fuse semantic and geometric features through a gated self-conditioned modulator. This module dynamically selects features for fusion, effectively mitigating noise interference and distribution shifts during latent diffusion, significantly enhancing robustness to noise, and thereby achieving precise restoration of clean point clouds. Extensive experiments on ModelNet40, and ShapeNetPart datasets demonstrate that our method robustly defends against adaptive attacks under varying noise levels and significantly restores classification performance degraded by backdoor triggers.
Jiawei Lian, Xia Du, Jianghua Liu 0001, Le Hui, Jian Yang 0003
IEEE Trans. Inf. Forensics Secur.2
2024 DP-RAE: A Dual-Phase Merging Reversible Adversarial Example for Image Privacy Protection
abstract
In digital security, Reversible Adversarial Examples (RAE) blend adversarial attacks with Reversible Data Hiding (RDH) within images to thwart unauthorized access. Traditional RAE methods, however, compromise attack efficiency for the sake of perturbation concealment, diminishing the protective capacity of valuable perturbations and limiting applications to white-box scenarios. This paper proposes a novel Dual-Phase merging Reversible Adversarial Example (DP-RAE) generation framework, combining a heuristic black-box attack and RDH with Grayscale Invariance (RDH-GI) technology. This dual strategy not only evaluates and harnesses the adversarial potential of past perturbations more effectively but also guarantees flawless embedding of perturbation information and complete recovery of the original image. Experimental validation reveals our method's superiority, secured an impressive 96.9% success rate and 100% recovery rate in compromising black-box models. In particular, it achieved a 90% misdirection rate against commercial models under a constrained number of queries. This marks the first successful attempt at targeted black-box reversible adversarial attacks for commercial recognition models. This achievement highlights our framework's capability to enhance security measures without sacrificing attack performance. Moreover, our attack framework is flexible, allowing the interchangeable use of different attack and RDH modules to meet advanced technological requirements.
Xia Du, Jizhe Zhou 0001, Chi-Man Pun, Qizhen Xu
ACM Multimedia2
2024 Efficient physical image attacks using adversarial fast autoaugmentation methods
Xia Du, Chi-Man Pun, Jizhe Zhou 0001
Knowl. Based Syst.1
2023 Pre-training-free Image Manipulation Localization through Non-Mutually Exclusive Contrastive Learning
abstract
Deep Image Manipulation Localization (IML) models suffer from training data insufficiency and thus heavily rely on pre-training. We argue that contrastive learning is more suitable to tackle the data insufficiency problem for IML. Crafting mutually exclusive positives and negatives is the prerequisite for contrastive learning. However, when adopting contrastive learning in IML, we encounter three categories of image patches: tampered, authentic, and contour patches. Tampered and authentic patches are naturally mutually exclusive, but contour patches containing both tampered and authentic pixels are non-mutually exclusive to them. Simply abnegating these contour patches results in a drastic performance loss since contour patches are decisive to the learning outcomes. Hence, we propose the Nonmutually exclusive Contrastive Learning (NCL) framework to rescue conventional contrastive learning from the above dilemma. In NCL, to cope with the non-mutually exclusivity, we first establish a pivot structure with dual branches to constantly switch the role of contour patches between positives and negatives while training. Then, we devise a pivot-consistent loss to avoid spatial corruption caused by the role-switching process. In this manner, NCL both inherits the self-supervised merits to address the data insufficiency and retains a high manipulation localization accuracy. Extensive experiments verify that our NCL achieves state-of-the-art performance on all five benchmarks without any pre-training and is more robust on unseen real-life samples. https://github.com/Knightzjz/NCL-IML.
Jizhe Zhou 0001, Xiaochen Ma 0001, Xia Du, Ahmed Y. Al Hammadi, Wentao Feng
ICCV3
2023 HC-GCN: hierarchical contrastive graph convolutional network for unsupervised domain adaptation on person re-identification
Si Chen 0002, Bolun Xu, Yan Yan 0001, Xia Du, Weiwei Zhuang, Yun Wu 0001
Multim. Syst.5
2023 Self-information of radicals: A new clue for zero-shot Chinese character recognition
Dahan Wang, Xia Du, Huayi Yin, Xu-Yao Zhang, Shunzhi Zhu
Pattern Recognit.3
2022 Exploiting Robust Memory Features for Unsupervised Reidentification
Jiawei Lian, Dahan Wang, Xia Du, Yun Wu 0001, Shunzhi Zhu
PRCV (2)3
2022 Semantic-Aware Non-local Network for Handwritten Mathematical Expression Recognition
Xiang-Hao Liu, Dahan Wang, Xia Du, Shunzhi Zhu
PRCV (3)3
2022 Robust Audio Patch Attacks Using Physical Sample Simulation and Adversarial Patch Noise Generation
abstract
Deep neural network (DNNs) based Automatic Speech Recognition (ASR) systems are known vulnerable to adversarial attacks that are maliciously implemented by adding small but powerful distortions to the original audio input. However, most existing methods that generate audio adversarial examples targeting ASR models cannot achieve successful robust attacks against defense methods. This paper proposes a novel framework for robust audio patch attacks using Physical Sample Simulation (PSS) and Adversarial Patch Noise Generation (APNG). First, the proposed PSS simulated real-audio with selected room impulse response for training the adversarial patches. Second, the proposed APNG generates the imperceptible audio adversarial patch examples using the voice activity detector to hide the adversarial patch noise into the non-silent locations of the input audio. Furthermore, the design Sounds Pressure Level-based adaptive noise minimization algorithm helps us further reduce the perturbation during the attack. The experimental results show that our proposed method can achieve the highest attack success rates and SNRs in various cases, comparing with other state-of-the-art attacks.
Xia Du, Chi-Man Pun
IEEE Trans. Multim.1
2020 Adversarial Image Attacks Using Multi-Sample and Most-Likely Ensemble Methods
abstract
Many studies on deep neural networks have shown very promising results for most image recognition tasks. However, these networks can often be fooled by adversarial examples that simply add small but powerful distortions to the original input. Recent works have demonstrated the vulnerability of deep learning systems to adversarial examples, but most such works directly manipulate and attack the digital images for a specific classifier only, and cannot attack the physical images in real world. In this paper, we propose the multi-sample ensemble method (MSEM) and most-likely ensemble method (MLEM) to generate adversarial attacks that successfully fool the classifier for images in both the digital and real worlds. The proposed adaptive norm algorithm can craft faster and smaller perturbation than other state-of-the-art attack methods. Besides, the proposed MLEM extended with weighted objective function can generate robust adversarial attacks that can mislead multiple classifiers (Inception-v3, Inception-v4, Resnet-v2, Ince-res-v2) simultaneously for physical images in real world. Compared with other methods, experiments show that our adversarial attack methods not only can achieve higher success rates but also can survive in the multi-model defense tests.
Xia Du, Chi-Man Pun
ACM Multimedia1
2020 A Unified Framework for Detecting Audio Adversarial Examples
abstract
Adversarial attacks have been widely recognized as the security vulnerability of deep neural networks, especially in deep automatic speech recognition (ASR) systems. The advanced detection methods against adversarial attacks mainly focus on pre-processing the input audio to alleviate the threat of adversarial noise. Although these methods could detect some simplex adversarial attacks, they fail to handle robust complex attacks especially when the attacker knows the detection details. In this paper, we propose a unified adversarial detection framework for detecting adaptive audio adversarial examples, which combines noise padding with sound reverberation. Specifically, a well-designed adaptive artificial utterances generator is proposed to balance the design complexity, such that the artificial utterances (speech with reverberation) are efficiently determined to reduce the false positive rate and false negative rate of detection results. Moreover, to destroy the continuity of the adversarial noise, we develop a novel multi-noise padding strategy, which implants the Gaussian noises in the silent fragments of the input speech by the voice activity detector. Furthermore, our proposed method can effectively tackle the robust adaptive attacks in an adaptive learning manner. Importantly, the conceived system is easily embedded into any ASR models without requiring additional retraining or modification. The experimental results show that our method consistently outperforms the state-of-the-art audio defense methods, even for the adaptive and robust attacks.
Xia Du, Chi-Man Pun, Zheng Zhang 0006
ACM Multimedia1