VLDB 2026 Research / reviewers in the wild / expert
Xinlei Liu 0004
dblp:224/4994-4
· DBLP profile ↗
7ranked-venue papers
5as first author
7since 2021 · last 2026
0000-0001-6586-4457ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 4 · 2 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 2 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Minimal-Overhead Backdoor Detection via Entropy-Guided Activation Substitution
Tao Hu 0002, Xinlei Liu 0004, Beilei Zhang, Qi Ouyang, Peng Yi 0003 |
KSEM (4) | 3 |
| 2026 | Generalizable poisoning-resistant backdoor detection and removal framework: From dataset perspective
Tao Hu 0002, Xinlei Liu 0004, Jichao Xie, Peng Yi 0003 |
Pattern Recognit. | 3 |
| 2026 | Gradient semi-masking for improving adversarial robustness
Xinlei Liu 0004, Tao Hu 0002, Peng Yi 0003, Jichao Xie |
Pattern Recognit. | 1 |
| 2025 | Sequential Difference Maximization: Generating Adversarial Examples via Multi-Stage OptimizationabstractEfficient adversarial attack methods are critical for assessing the robustness of computer vision models.In this paper, we reconstruct the optimization objective for generating adversarial examples as "maximizing the difference between the non-true labels' probability upper bound and the true label's probability," and propose a gradient-based attack method termed Sequential Difference Maximization (SDM).SDM establishes a three-layer optimization framework of "cycle-stage-step." The processes between cycles and between iterative steps are respectively identical, while optimization stages differ in terms of loss functions: in the initial stage, the negative probability of the true label is used as the loss function to compress the solution space; in subsequent stages, we introduce the Directional Probability Difference Ratio (DPDR) loss function to gradually increase the non-true labels' probability upper bound by compressing the irrelevant labels' probabilities.Experiments demonstrate that compared with previous SOTA methods, SDM not only exhibits stronger attack performance but also achieves higher attack cost-effectiveness.Additionally, SDM can be combined with adversarial training methods to enhance their defensive effects.The code is available at https://github.com/X-L-Liu/SDM. Xinlei Liu 0004, Tao Hu 0002, Peng Yi 0003, Weitao Han, Jichao Xie |
CIKM | 1 |
| 2025 | Alternating Guided Training for Robust Adversarial Defense
Xinlei Liu 0004, Chunlai Ma, Tao Hu 0002, Peng Yi 0003, Yiming Jiang 0002, Yuxiang Hu 0004 |
ICMR | 1 |
| 2025 | Spectral Shielding: Amplitude-Adaptive Frequency Correction Against Transferable Adversarial Attacks
Xinlei Liu 0004, Tao Hu 0002, Peng Yi 0003, Rongkui Zhou, Yiming Jiang 0002 |
PRCV (1) | 1 |
| 2024 | Robust purification defense for transfer attacks based on probabilistic scheduling algorithm of pre-trained models: A model difference perspectiveabstractNeural networks are vulnerable to meticulously crafted adversarial examples, resulting in high-confidence misclassifications in image classification tasks. Due to their stealthiness and difficulty in detection, black-box transfer attacks have become a significant focus of defense. In this article, we propose a purification defense based on probabilistic scheduling algorithm of pre-trained models (ProbSched-PTM) to counter diverse transfer attacks. We first quantify the differences among various models based on their output scores and verify the linear negative correlation between adversarial transferability and model difference. Subsequently, guided by the model difference probability, we integrate the negative momentum probability as a regularization factor to construct ProbSched-PTM. It selects the most appropriate substitute model from multiple pre-trained models to generate strong-transferability adversarial examples for training the purification model, which enables the purification model to effectively eliminate diverse adversarial perturbations. The ProbSched-PTM-based purification defense provides robust defense against unseen adversarial attacks from different substitute models. In a black-box attack scenario, utilizing ResNet-34 as the target model, our approach achieves average defense rates of over 94.8% on CIFAR-10 and over 71.2% on Mini-ImageNet, demonstrating state-of-the-art performance. Xinlei Liu 0004, Jichao Xie, Tao Hu 0002, Peng Yi 0003, Zhen Zhang 0049 |
TrustCom | 1 |