VLDB 2026 Research / reviewers in the wild / expert
Chuanxi Chen
dblp:224/7681
· DBLP profile ↗
18ranked-venue papers
3as first author
18since 2021 · last 2026
0000-0002-3863-0417ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 6 · 1 first-author · 6 since 2021Computer networks · 6 · 1 first-author · 6 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CDCU: A centroid drifting causal unlearning method for facial privacy protection
Qianfu Qiu, Chuanxi Chen, Jun Shen 0001, Binbin Yong, Jiayin Lin |
Neurocomputing | 2 |
| 2026 | Defending Against Network Attacks for Secure AI Agent Migration in Vehicular MetaversesabstractVehicular metaverses, blending traditional vehicular networks with metaverse technology, are expected to revolutionize fields such as autonomous driving. As virtual intelligent assistants in vehicular metaverses, Artificial Intelligence (AI) agents empowered by large language models can create immersive 3D virtual spaces for passengers to enjoy on-board vehicular applications and services. To provide users with seamless and engaging virtual interactions, resource-limited vehicles offload AI agents to RoadSide Units (RSUs) with adequate communication and computational capabilities. Due to the mobility of vehicles and the limited coverage of RSUs, AI agents need to migrate from one RSU to another. However, potential network attacks pose significant challenges to ensuring reliable and efficient AI agent migration. In this paper, we first explore specific network attacks, including traffic-based attacks (i.e., DDoS attacks) and infrastructure-based attacks (i.e., malicious RSU attacks). Then, we model the AI agent migration process as a Partially Observable Markov Decision Process (POMDP) and apply multi-agent proximal policy optimization algorithms to mitigate DDoS attacks. In addition, we propose a trust assessment mechanism to counter malicious RSU attacks. Numerical results demonstrate that the proposed solutions effectively defend against these network attacks and reduce the total latency of AI agent migration by approximately 12.8%. Xinru Wen, Jinbo Wen, Ming Xiao 0001, Jiawen Kang 0001, Tao Zhang 0063, Xiaohuan Li 0001, Chuanxi Chen, Dusit Niyato |
IEEE Internet Things J. | 7 |
| 2026 | From forgotten to pan-sharpening
Jiaming Wang 0001, Yansong Lin, Chuanxi Chen, Xiao Huang 0003, Ruiqian Zhang, Yu Wang 0140, Tao Lu 0001 |
Pattern Recognit. | 3 |
| 2026 | Take Attention as Gate: An Associative Recurrent Network-Based Intrusion Detection Method for Industrial Control NetworkabstractThe Industrial Control Network (ICN), which is characterized by real-time responsiveness and reliability, plays a key role in increasing production speed, ensuring efficient processing, and managing industrial processes. Despite tremendous advantages, ICN inevitably struggles with some challenges, such as malicious user intrusion and hacker attacks. To detect malicious intrusions in ICN, Intrusion Detection Systems (IDS) have been deployed. However, network traffic in ICN often exhibits significant temporal periodicity, and computational resources are limited on edge nodes and infrastructure gateway devices. These characteristics pose significant challenges to the design and performance of IDS. To properly solve these problems, we design a new intrusion detection method for ICN. Specifically, we first design a novel neural network model called Associative Recurrent Network (ARN), which can properly handle the relationship between previous hidden state and current input. Then, we construct a novel intrusion detection method based on the ARN, which avoids gating conflicts in traditional Recurrent Neural Network (RNN), effectively captures the temporal characteristics of ICN traffic, and maintains slightly higher computational overhead than GRU, thus demonstrating good adaptability to industrial control networks. Subsequently, through theoretical analysis of computational complexity, we demonstrate that the proposed method achieves high computational efficiency, comparable to mainstream RNN methods and superior to Transformer methods. Finally, we implement a prototype system to evaluate detection accuracy. Experimental results show that our method achieves state-of-the-art performance on the industrial control systems datasets (ICS-ADD and SWaT) and the conventional network dataset (UNSW-NB15), with average accuracies of 98.93%, 95.57%, and 98.27%, respectively. Ziyi Liu 0009, Dengpan Ye, Yong Ding 0005, Yueling Liu, Chuanxi Chen |
IEEE Trans. Netw. Serv. Manag. | 7 |
| 2025 | AdvLUT: Cloaking Geographic Location With Semantic-Based Adversarial 3-D Lookup TablesabstractThe proliferation of Internet of Things (IoT) devices equipped with cameras, such as those in electric vehicles, has increased the collection of personal image data. However, the potential misuse of cross-view geo-localization (CVGL) models, which can infer precise locations from ground view images, has been overlooked and seriously threatens individual location privacy. In this article, we introduce AdvLUT, a novel semantic-based adversarial 3-D lookup tables (3DLUTs) privacy protection framework designed to safeguard geographic location privacy against CVGL models. The AdvLUT employs a geographic feature encoder to extract semantic features rich in geographic information from the ground view input. These features then guide a specialized adversarial 3DLUT generator in producing a 3DLUT that alters the color properties of the input image, thereby obstructing accurate location inference. Furthermore, AdvLUT is designed with a generative architecture that enables rapid image processing within milliseconds, eliminating the need for the corresponding satellite image or CVGL model. Experimental results on multiple benchmark datasets and CVGL models demonstrate that our method achieves up to a 65.48% reduction in R@1 localization accuracy, with performance further improving to 69.25% after JPEG compression. Yiheng He, Dengpan Ye, Ziyi Liu 0009, Chuanxi Chen |
IEEE Internet Things J. | 5 |
| 2025 | Generalized Polarization-Spatial Modulation With Multimode TransmissionabstractPolarization-spatial modulation (PSM) has been recently proposed to improve the system performance and energy efficiency of the conventional polarization modulation (PM) by activating only a single dual-polarized (DP) antenna for signal transmission. However, the spectral efficiency (SE) of PSM is significantly degraded due to the single DP antenna transmission. To tackle this problem, we propose a generalized PSM (GPSM) scheme to enhance the SE of PSM through transmission using multiple DP antennas. In the GPSM scheme, the information bits are mapped to antenna activation patterns (AAPs), polarization matrix activation patterns (PAPs), and modulated symbols. To further enhance the SE of GPSM, we propose a more practical scheme termed multi-mode GPSM (MM-GPSM), which transmits information bits not only through the AAPs, PAPs, and modulated symbols but also via the constellation activation patterns (CAPs). A low-complexity maximum likelihood (ML) detector and a log-likelihood ratio detector for both GPSM and MM-GPSM are proposed to relieve the high computational complexity of the optimal ML detector at the cost of a negligible performance loss. An upper bound on the bit error rate (BER) is derived in closed-form to evaluate the performance of both GPSM and MM-GPSM. Simulation results show that GPSM and MM-GPSM outperform the conventional PM and PSM schemes, particularly in the high signal-to-noise ratio (SNR) region, and verify the accuracy of the theoretical analysis of the upper-bounded BER. Jun Li 0036, Shuangyuan Li, Shuping Dang, Xuan Chen 0001, Chuanxi Chen, Yuyang Peng |
IEEE Internet Things J. | 5 |
| 2025 | WEAL: Weight-wise Ensemble Adversarial Learning with Gradient Manipulation
Chuanxi Chen, Yunbo Tang, He Fang, Li Xu 0002 |
Knowl. Based Syst. | 1 |
| 2025 | Attention-Based Mean-Max Balance Assignment for Oriented Object Detection in Optical Remote Sensing ImagesabstractFor objects with arbitrary angles in optical remote sensing (RS) images, the oriented bounding box regression task often faces the problem of ambiguous boundaries between positive and negative samples. The statistical analysis of existing label assignment strategies reveals that anchors with low Intersection over Union (IoU) between ground truth (GT) may also accurately surround the GT after decoding. Therefore, this article proposes an attention-based mean-max balance assignment (AMMBA) strategy, which consists of two parts: mean-max balance assignment (MMBA) strategy and balance feature pyramid with attention (BFPA). MMBA employs the mean-max assignment (MMA) and balance assignment (BA) to dynamically calculate a positive threshold and adaptively match better positive samples for each GT for training. Meanwhile, to meet the need of MMBA for more accurate feature maps, we construct a BFPA module that integrates spatial and scale attention mechanisms to promote global information propagation. Combined with S2ANet, our AMMBA method can effectively achieve state-of-the-art performance, with a precision of 80.91% on the DOTA dataset in a simple plug-and-play fashion. Extensive experiments on three challenging optical RS image datasets (DOTA-v1.0, HRSC, and DIOR-R) further demonstrate the balance between precision and speed in single-stage object detectors. Our AMMBA has enough potential to assist all existing RS models in a simple way to achieve better detection performance. The code is available athttps://github.com/promisekoloer/AMMBA. Qifeng Lin, Daoye Zhu, Gang Fu 0003, Chuanxi Chen, Yuanlong Yu 0001 |
IEEE Trans. Geosci. Remote. Sens. | 6 |
| 2025 | CT-DCENet: Deep EEG Denoising via CNN-Transformer-Based Dual-Stage Collaborative Ensemble LearningabstractElectroencephalogram (EEG) artifact removal has been investigated for decades with the goal of reconstructing the clean signals for the subsequent EEG analysis. However, existing denoising methods still have limited capabilities to handle the highly mixed artifacts and the fine-grained temporal dependency of artifact-free EEG without a priori knowledge of the artifacts. To address the challenges, this study proposes a CNN-Transformer-based dual-stage collaborative ensemble learning framework (namely CT-DCENet) in the form of three modules: 1) randomized collaboration module initially utilizes four individual learners to reveal multi-group morphological characteristics of the denoised EEG, 2) linear ensemble module integrates the outputs of four individual learners via weighted linear combination to preliminarily estimate the denoised EEG, 3) information complementation module takes in the residual between the contaminated EEG and the above estimated EEG, and critically applies CNN-Transformer-based feature extractor and denoising head to learn the detailed characteristics of the denoised EEG. CT-DCENet is conducted in a dual-stage training manner to derive the morphological characteristics & the detailed characteristics of the artifact-free EEG successively. The experimental results on the public EEG datasets indicate that 1) CT-DCENet significantly outperforms the state-of-the-art counterparts (e.g., DuoCL, GCTNet) under the conditions of various artifacts and noise intensities, where the increases of SNR & PCC are 0.79 dB, 0.6% and the decrease of RRMSE is 1.9% for the removal of EMG, ECG, EOG mixed artifacts, 2) the reconstructed EEG by CT-DCENet can well fit the clean EEG with a low error achieved, especially for the peak amplitude, the high-frequency area and the boundary area of the EEG waveform, providing promising EEG data for the downstream task-oriented EEG analysis. Yunbo Tang, Weirong Huang, Chuanxi Chen, Dan Chen 0001 |
IEEE J. Biomed. Health Informatics | 3 |
| 2025 | Feature Extraction Matters More: An Effective and Efficient Universal Deepfake DisruptorabstractFace manipulation can modify a victim’s facial attributes (e.g., age or hair color) in an image, which is an important component of deepfakes. Adversarial examples are an emerging approach to combat the threat of visual misinformation to society. To efficiently protect facial images from being forged, designing a universal face anti-manipulation disruptor is essential. However, existing works treat deepfake disruption as an end-to-end process, ignoring the functional difference between feature extraction and image reconstruction. In this work, we propose FOUND , a novel F eature- O utput ensemble UN iversal D isruptor against face manipulation networks, which explores a new opinion considering attacking feature-extraction (encoding) modules as the critical task in deepfake disruption. We conduct an effective two-stage disruption process. We first perform ensemble disruption on multi-model encoders, maximizing the Wasserstein distance between features before and after the adversarial attack. Then we develop a Gradient-Ensemble strategy to enhance the disruption effect by simplifying the complex optimization problem of disrupting ensemble end-to-end models. Extensive experiments indicate that one FOUND generated with a few facial images can successfully disrupt multiple face manipulation models on cross-attribute and cross-face images, surpassing state-of-the-art universal disruptors in both success rate and efficiency. Dengpan Ye, Zhenhao Lu, Yunming Zhang, Chuanxi Chen |
ACM Trans. Multim. Comput. Commun. Appl. | 5 |
| 2024 | Once and for All: Universal Transferable Adversarial Perturbation against Deep Hashing-Based Facial Image RetrievalabstractDeep Hashing (DH)-based image retrieval has been widely applied to face-matching systems due to its accuracy and efficiency. However, this convenience comes with an increased risk of privacy leakage. DH models inherit the vulnerability to adversarial attacks, which can be used to prevent the retrieval of private images. Existing adversarial attacks against DH typically target a single image or a specific class of images, lacking universal adversarial perturbation for the entire hash dataset. In this paper, we propose the first universal transferable adversarial perturbation against DH-based facial image retrieval, a single perturbation can protect all images. Specifically, we explore the relationship between clusters learned by different DH models and define the optimization objective of universal perturbation as leaving from the overall hash center. To mitigate the challenge of single-objective optimization, we randomly obtain sub-cluster centers and further propose sub-task-based meta-learning to aid in overall optimization. We test our method with popular facial datasets and DH models, indicating impressive cross-image, -identity, -model, and -scheme universal anti-retrieval performance. Compared to state-of-the-art methods, our performance is competitive in white-box settings and exhibits significant improvements of 10%-70% in transferability in all black-box settings. Dengpan Ye, Yunna Lv, Chuanxi Chen, Yunming Zhang |
AAAI | 4 |
| 2024 | Improving Adversarial Robustness With Adversarial AugmentationsabstractDeep neural network (DNN)-based applications are extensively being researched and applied in the Internet of Things (IoT) devices in daily lives due to impressive performance. Recently, adversarial attacks pose a significant threat to the security of deep neural networks (DNNs), adversarial training has emerged as a promising and effective defense approach for defending against such attacks. However, existing adversarial training methods have shown limited success in defending against attacks unseen during training, thereby undermining their effectiveness. Besides, generating adversarial perturbations for adversarial training requires massive expensive labeled data, which is a critical obstacle in the robust DNNs-based IoT applications. In this article, we first explore the effective data augmentations by implementing adversarial attacks with self-supervised in latent space. Then, we propose new loss metric functions that can avoid collapse phenomenon of contrastive learning (CL) by measuring the distances between adversarial augmented pairs. Based on the extracted adversarial features in self-supervised CL, we propose a novel adversarial robust learning (ARL) method, which implements adversarial training without any labels and obtains more general robust encoder network. Our approach is validated on commonly used benchmark data sets and models, where it achieves comparable adversarial robustness against different adversarial attacks when compared to supervised adversarial training methods. Additionally, ARL outperforms state-of-the-art self-supervised adversarial learning techniques in terms of achieving higher robustness and clean prediction accuracy for the downstream classification task. Chuanxi Chen, Dengpan Ye, Yiheng He |
IEEE Internet Things J. | 1 |
| 2024 | Dual Defense: Adversarial, Traceable, and Invisible Robust Watermarking Against Face SwappingabstractMalicious applications of deep face swapping technology pose security threats such as misinformation dissemination and identity fraud. Some research propose the utilization of robust watermarking methods to track the copyright of facial images, facilitating post-forgery identity attribution. However, these methods cannot fundamentally prevent or eliminate the adverse impacts of face swapping. To address this issue, we present Dual Defense, an innovative framework based on robust adversarial watermarking. It simultaneously tracks image copyrights and disrupts the face swapping model by one-time embedding the robust adversarial watermark. Specifically, we propose an Original-domain Feature Emulation Attack (OFEA) method, which makes the traceable watermark adversarial through specially designed original domain adversarial loss. Additionally, we conduct a wavelet domain image structural information compensation loss, combined with a channel attention mechanism, to jointly balance watermark invisibility, adversariality, and traceability. Furthermore, we design a more comprehensive and rational evaluation method to thoroughly assess the effectiveness of adversarial attacks against face swapping models. Extensive experiments demonstrate that Dual Defense exhibits exceptional cross-task generality and dataset generalization. It maintains impressive adversariality and traceability in both original and robust settings, surpassing current forgery defense methods that possess only one of these capabilities. Yunming Zhang, Dengpan Ye, Caiyun Xie, Xin Liao 0001, Ziyi Liu 0009, Chuanxi Chen, Jiacheng Deng 0001 |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2023 | Tiny WFP: Lightweight and Effective Website Fingerprinting via Wavelet Multi-Resolution Analysis
Dengpan Ye, Chuanxi Chen |
ACNS (1) | 3 |
| 2023 | Voice Guard: Protecting Voice Privacy with Strong and Imperceptible Adversarial Perturbation in the Time DomainabstractAdversarial example is a rising tool for voice privacy protection. By adding imperceptible noise to public audio, it prevents tampers from using zero-shot Voice Conversion (VC) to synthesize high quality speech with target speaker identity. However, many existing studies ignore the human perception characteristics of audio data, and it is challenging to generate strong and imperceptible adversarial audio. In this paper, we propose the Voice Guard defense method, which uses a novel method to advance the adversarial perturbation to the time domain to avoid the loss caused by cross-domain conversion. And the psychoacoustic model is introduced into the defense of VC for the first time, which greatly improves the disruption ability and concealment of adversarial audio. We also standardize the evaluation metrics of adversarial audio for the first time, combining multi-dimensional metrics to define the criteria for defense. We evaluate Voice Guard on several state-of-the-art zero-shot VC models. The experimental results show that our method can ensure the perceptual quality of adversarial audio while having a strong defense capability, and is far superior to previous works in terms of disruption ability and concealment. Dengpan Ye, Chuanxi Chen, Shengshan Hu |
IJCAI | 4 |
| 2022 | Towards Adversarial Robustness with Multidimensional Perturbations via Contrastive LearningabstractRecent works have demonstrated that neural networks are vulnerable to adversarial attacks, while adversarial training is promising for improving robustness of deep networks. However, these models still remain vulnerable to new types of attacks not seen due to representative general samples may not be provided during training. Moreover, substantially larger datasets are necessary in adversarial robust models than those required for standard training where labeled data is expensive. In this work, we propose a novel approach to adversarial robustness, which establishes on the insights from min-max optimization that more powerful adversarial perturbations lead to more robust defense. Our algorithm is called Adversarial Training with Multidimensional Perturbations (ATMP), aims at guiding networks learn strong representations through minimizing the distance between differently augmented views via adopting an innovative contrastive learning objective function in the latent space. By perturbing the representations corresponding to key robust features, more powerful adversarial perturbations could be obtained in self-supervised form during adversarial training. Besides, we can avoid label leaking to some extent because no label information is required in generating adversarial examples. Extensive experimental results on common benchmarks show that our method can achieve high robustness against various of representative adversarial attacks. We also compare it with the existing state-of-the-art techniques, and the experiments indicate that our method is superior. Chuanxi Chen, Dengpan Ye, Hao Wang 0134 |
TrustCom | 1 |
| 2022 | Detection defense against adversarial attacks with saliency mapabstractIt is well established that neural networks are vulnerable to adversarial examples, which are almost imperceptible on human vision and can cause the deep models misbehave. Such phenomenon may lead to severely inestimable consequences in the safety and security critical applications. Existing defenses are trend to harden the robustness of models against adversarial attacks, for example, adversarial training technology. However, these are usually intractable to implement due to the high cost of retraining and the cumbersome operations of altering the model architecture or parameters. In this paper, we discuss the saliency map method from the view of enhancing model interpretability, it is similar to introducing the mechanism of the attention to the model, so as to comprehend the progress of object identification by the deep networks. We then propose a novel method combined with additional noises and utilize the inconsistency strategy to detect adversarial examples. Our experimental results of some representative adversarial attacks on common data sets including ImageNet and popular models show that our method can detect all the attacks with high detection success rate effectively. We compare it with the existing state-of-the-art technique, and the experiments indicate that our method is more general. Dengpan Ye, Chuanxi Chen, Changrui Liu, Hao Wang 0134, Shunzhi Jiang |
Int. J. Intell. Syst. | 2 |
| 2021 | Countering Spoof: Towards Detecting Deepfake with Multidimensional Biological SignalsabstractThe deepfake technology is conveniently abused with the low technology threshold, which may bring the huge social security risks. As GAN-based synthesis technology is becoming stronger, various methods are difficult to classify the fake content effectively. However, although the fake content generated by GANs can deceive the human eyes, it ignores the biological signals hidden in the face video. In this paper, we proposed a novel video forensics method with multidimensional biological signals, which extracting the difference of the biological signal between real and fake videos from three dimensions. The experimental results show that our method achieves 98% accuracy on the main public dataset. Compared with other technologies, the proposed method only extracts fake video information and is not limited to a specific generation method, so it is not affected by synthetic methods and has good adaptability. Xinlei Jin, Dengpan Ye, Chuanxi Chen |
Secur. Commun. Networks | 3 |