VLDB 2026 Research / reviewers in the wild / expert
Yanghao Zhang
dblp:233/1238
· DBLP profile ↗
13ranked-venue papers
4as first author
11since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 8 · 4 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 1 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | KaeTE: Towards Practical Neural Traffic Engineering with Lagrangian Duality and Learning-to-optimizeabstractTraffic engineering (TE) is becoming increasingly important in modern networks, as it can improve network performance by splitting traffic across paths. However, traditional TE solvers can be too slow for rapid changes, while recent machine learning (ML) solvers are fast but often fail to support dynamic network conditions, such as topology changes or link capacity changes. Moreover, they usually support only simple TE objectives that do not account for potential link overload, which makes them less practical. In this paper, we present KaeTE, an ML-based TE solver that supports dynamic network conditions and the throughput objective. The design of KaeTE leverages the convexity of the throughput objective. Specifically, KaeTE first makes the throughput objective strongly convex through regularization. KaeTE then adopts a learning-to-optimize (L2O)-inspired model to iteratively refine the dual variables. To ensure that the final TE solutions do not overload any link, KaeTE generates the final TE solutions and the corresponding throughput objective value through a constraint-aware loss function. Evaluations on both dynamic and static network conditions show that KaeTE consistently outperforms baselines in our evaluated settings. Zirui Ou, Yanghao Zhang, Jie Gui, Qun Huang 0001 |
APNet | 2 |
| 2025 | A Black-Box Evaluation Framework for Semantic Robustness in Bird's Eye View DetectionabstractCamera-based Bird's Eye View (BEV) perception models receive increasing attention for their crucial role in autonomous driving, a domain where concerns about the robustness and reliability of deep learning have been raised. While only a few works have investigated the effects of randomly generated semantic perturbations, aka natural corruptions, on the multi-view BEV detection task, we develop a black-box robustness evaluation framework that adversarially optimises three common semantic perturbations: geometric transformation, colour shifting, and motion blur, to deceive BEV models, serving as the first approach in this emerging field. To address the challenge posed by optimising the semantic perturbation, we design a smoothed, distance-based surrogate function to replace the mAP metric and introduce SimpleDIRECT, a deterministic optimisation algorithm that utilises observed slopes to guide the optimisation process. By comparing with randomised perturbation and two optimisation baselines, we demonstrate the effectiveness of the proposed framework. Additionally, we provide a benchmark on the semantic robustness of ten recent BEV models. The results reveal that PolarFormer, which emphasises geometric information from multi-view images, exhibits the highest robustness, whereas BEVDet is fully compromised, with its precision reduced to zero. Yanghao Zhang, Xiangyu Yin 0001, Zeyu Fu, Xiaowei Huang 0001, Wenjie Ruan |
AAAI | 2 |
| 2025 | Scalable Neural Network Geometric Robustness Validation via Hölder OptimisationabstractNeural Network (NN) verification methods provide local robustness
guarantees for a NN in the dense perturbation space of an input.
In this paper we introduce H$^2$V, a method for the validation of
local robustness of NNs against geometric perturbations. H$^2$V
uniquely employs a Hilbert space-filling construction to recast
multi-dimensional problems into single-dimensional ones and Hölder
optimisation, iteratively refining the estimation of the Hölder constant
for constructing the lower bound.
In common with current methods, Hölder optimisation might theoretically
converge to a local minimum, thereby resulting in a robustness result
being incorrect. However, we here identify conditions for H$^2$V
to be provably sound, and show experimentally that even
outside the soundness conditions, the risk of incorrect results can be
minimised by introducing appropriate heuristics in the global
optimisation procedure. Indeed, we found no incorrect
results validated by H$^2$V on a large set of benchmarks from
SoundnessBench and VNN-COMP.
To assess the scalability of the approach, we report the results
obtained on large NNs ranging from Resnet34 to Resnet152 and vision
transformers. These point to state-of-the-art scalability of the approach when
validating the local robustness of large NNs against geometric
perturbations on the ImageNet dataset. Beyond image tasks, we show
that the method's scalability enables for the first time the
robustness validation of large-scale 3D-NNs in video classification
tasks against geometric perturbations for long-sequence input frames
on Kinetics/UCF101 datasets. Yanghao Zhang, Panagiotis Kouvaros, Alessio Lomuscio |
NeurIPS | 1 |
| 2025 | Usability of Pseudo-Haptic Feedback for Manual Precise Manipulation of Objects in Augmented RealityabstractManual precise manipulation of objects is a critical skill in daily life, and Augmented Reality (AR) is increasingly used to support such tasks. In this study, we propose a system utilizing pseudo-haptic feedback to support precise manipulation for six degrees of freedom (6DOF). Two types of AR instruction interfaces were developed: Visual Deviation Instruction Interface (VDI) and Pseudo-Haptic Instruction Interface (PHI). A user study with 18 participants compared the two instruction interfaces in terms of performance and user experience. The objective measures of performance (task completion time, deviation), and the subjective measures (system usability scale, NASA Task Load Index) were collected. Results show that both instruction interfaces effectively support manual precise manipulation, achieving position deviations under 2 mm and orientation deviations under 1°. PHI outperformed VDI in speed, mental effort, physical demand, performance, perceived workload, custom user experience elements and reduction deviations of manual precise manipulation. Finally, we discuss research limitations and future directions. Yunfei Qin, Weiping He, Mark Billinghurst, Yanghao Zhang, Jiepeng Dong |
Int. J. Hum. Comput. Interact. | 5 |
| 2024 | Reward Certification for Policy Smoothed Reinforcement LearningabstractReinforcement Learning (RL) has achieved remarkable success in safety-critical areas, but it can be weakened by adversarial attacks. Recent studies have introduced ``smoothed policies" to enhance its robustness. Yet, it is still challenging to establish a provable guarantee to certify the bound of its total reward. Prior methods relied primarily on computing bounds using Lipschitz continuity or calculating the probability of cumulative reward being above specific thresholds. However, these techniques are only suited for continuous perturbations on the RL agent's observations and are restricted to perturbations bounded by the l2-norm. To address these limitations, this paper proposes a general black-box certification method, called ReCePS, which is capable of directly certifying the cumulative reward of the smoothed policy under various lp-norm bounded perturbations. Furthermore, we extend our methodology to certify perturbations on action spaces. Our approach leverages f-divergence to measure the distinction between the original distribution and the perturbed distribution, subsequently determining the certification bound by solving a convex optimisation problem. We provide a comprehensive theoretical analysis and run experiments in multiple environments. Our results show that our method not only improves the tightness of certified lower bound of the mean cumulative reward but also demonstrates better efficiency than state-of-the-art methods. Ronghui Mu, Leandro Soriano Marcolino, Yanghao Zhang, Xiaowei Huang 0001, Wenjie Ruan |
AAAI | 3 |
| 2024 | UAV Swarm Path Planning Algorithm Based on Starling FlockingabstractThe study addresses the problem of how UAV swarms can effectively navigate through complex urban environments and reach their destinations quickly while avoiding obstacles. This paper investigates UAV swarm coordination algorithms that maintain the stability and safety of quadcopter UAV swarms, as well as UAV swarm path planning algorithms aimed at finding the shortest path from the cluster’s starting point to its destination. The swarm coordination algorithm is based on mimicking bird flock behavior and is divided into two processes: the construction of internal subnetwork topological structures and the design of behavioral rules among individuals. In the algorithm, a smoothing function replaces fixed parameters, making the UAVs’ power output more consistent with actual power output characteristics. The UAV swarm path planning algorithm is based on particle swarm optimization, which considers UAV kinematic constraints to find the optimal path. The performance of the algorithm is tested with 11 to 20 UAV swarm flights through different obstacle environments, demonstrating its effectiveness. Xiangchun Liu, Yanghao Zhang, Quan Yi |
CSCWD | 4 |
| 2024 | Towards Fairness-Aware Adversarial LearningabstractAlthough adversarial training (AT) has proven effective in enhancing the model's robustness, the recently revealed issue of fairness in robustness has not been well addressed, i.e. the robust accuracy varies significantly among different categories. In this paper, instead of uniformly evaluating the model's average class performance, we delve into the issue of robust fairness, by considering the worst-case distribution across various classes. We propose a novel learning paradigm, named Fairness-Aware Adversarial Learning (FAAL). As a generalization of conventional AT, we redefine the problem of adversarial training as a min-max-max framework, to ensure both robustness and fairness of the trained model. Specifically, by taking advantage of distributional robust optimization, our method aims to find the worst distribution among different categories, and the solution is guaranteed to obtain the upper bound performance with high probability. In particular, FAAL can fine-tune an unfair robust model to be fair within only two epochs, without compromising the overall clean and robust accuracies. Extensive experiments on various image datasets validate the superior performance and efficiency of the proposed FAAL compared to other state-of-the-art methods. Yanghao Zhang, Ronghui Mu, Xiaowei Huang 0001, Wenjie Ruan |
CVPR | 1 |
| 2024 | DeepGRE: Global Robustness Evaluation of Deep Neural NetworksabstractRobustness measurements on deep neural networks (DNNs) have gained significant attention, especially in safety-critical applications. Numerous studies have been devoted to assessing the robustness of classifiers by averaging local robustness over a fixed set of data samples, such as a test set. However, the local statistics may not provide an accurate representation of the actual global robustness over the entire underlying unknown data distribution. To address this challenge, this paper proposes a novel framework, namely DeepGRE, for global robustness estimates of adversarial perturbation in combination with generative models and existing local robustness evaluation methods. Besides, DeepGRE employs Quasi-Monte Carlo approach to produce estimates of global robustness with low variance, making the assessments more reliable and statistically sound, since randomness is introduced by all samples drawn from a generative model. From a theoretical perspective, this work naturally provides an upper bound between true global robustness and estimated global robustness based on Lipschitz continuity. Also, it derives a statistical guarantee on the difference between true and empirical estimates for sample complexity. Our code is available at https://github.com/TrustAI/DeepGRE. Jiaxu Liu 0001, Yanghao Zhang, Ronghui Mu, Wenjie Ruan |
ICASSP | 3 |
| 2024 | PRASS: Probabilistic Risk-averse Robust Learning with Stochastic Search
Yanghao Zhang, Ronghui Mu, Jiaxu Liu 0001, Jonathan E. Fieldsend, Wenjie Ruan |
IJCAI | 2 |
| 2023 | Self-adaptive Adversarial Training for Robust Medical Segmentation
Zeyu Fu, Yanghao Zhang, Wenjie Ruan |
MICCAI (3) | 3 |
| 2023 | Generalizing universal adversarial perturbations for deep neural networks
Yanghao Zhang, Wenjie Ruan, Xiaowei Huang 0001 |
Mach. Learn. | 1 |
| 2020 | Generalizing Universal Adversarial Attacks Beyond Additive PerturbationsabstractThe previous study has shown that universal adversarial attacks can fool deep neural networks over a large set of input images with a single human-invisible perturbation. However, current methods for universal adversarial attacks are based on additive perturbation, which cause misclassification when the perturbation is directly added to the input images. In this paper, for the first time, we show that a universal adversarial attack can also be achieved via non-additive perturbation (e.g., spatial transformation). More importantly, to unify both additive and non-additive perturbations, we propose a novel unified yet flexible framework for universal adversarial attacks, called GUAP, which is able to initiate attacks by additive perturbation, non-additive perturbation, or the combination of both. Extensive experiments are conducted on ImageNet dataset with several deep neural network models including GoogLeNet, VGG and ResNet. The empirical experiments demonstrate that GUAP can obtain up to 99.24% successful attack rate on ImageNet dataset, leading to over 19% improvements than current state-of-the-art universal adversarial attacks. The code for reproducing the experiments in this paper is available at https://github.com/TrustAI/GUAP. Yanghao Zhang, Wenjie Ruan, Xiaowei Huang 0001 |
ICDM | 1 |
| 2018 | Collaboratively Weighting Deep and Classic Representation via $l_2$ Regularization for Image ClassificationabstractDeep convolutional neural networks provide a powerful feature learning capability for image classification. The deep image features can be utilized to deal with many image understanding tasks like image classification and object recognition. However, the robustness obtained in one dataset can be hardly reproduced in the other domain, which leads to inefficient models far from state-of-the-art. We propose a deep collaborative weight-based classification (DeepCWC) method to resolve this problem, by providing a novel option to fully take advantage of deep features in classic machine learning. It firstly performs the $l_2$-norm based collaborative representation on the original images, as well as the deep features extracted by deep CNN models. Then, two distance vectors, obtained based on the pair of linear representations, are fused together via a novel collaborative weight. This collaborative weight enables deep and classic representations to weigh each other. We observed the complementarity between two representations in a series of experiments on 10 facial and object datasets. The proposed DeepCWC produces very promising classification results, and outperforms many other benchmark methods, especially the ones claimed for Fashion-MNIST. The code is going to be published in our public repository\footnote{https://github.com/zengsn/research}. Shaoning Zeng, Bob Zhang 0001, Yanghao Zhang, Jianping Gou |
ACML | 3 |