Xiaowei Dong

dblp:241/7878 · DBLP profile ↗
← Back
7ranked-venue papers
0as first author
6since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 4 since 2021Artificial intelligence and machine learning · 3 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 since 2021
YearPublicationVenuePosition
2025 Vanilla Feature Distillation for Improving the Accuracy-Robustness Trade-Off in Adversarial Training
abstract
Adversarial training has been widely explored for mitigating attacks against deep models. However, a critical limitation of existing works is that robustness enhancement is at the cost of noticeable accuracy degradation. To achieve a better trade-off between robustness and accuracy, we propose the Vanilla Feature Distillation Adversarial Training (VFDAT), which conducts knowledge distillation from a pre-trained model (optimized towards high accuracy) to guide adversarial training model towards generating high-quality and well-separable features by constraining the obtained features of natural and adversarial examples. More specifically, both adversarial examples and their natural counterparts are forced to be aligned in feature space by distilling predictive representations from a pre-trained natural model. In this way, the adversarial training model can be updated towards maximally preserving the accuracy as gaining robustness. A key advantage of our method is that it can be universally adapted to and boost existing works. Exhaustive experiments on various datasets, classification models, and adversarial training algorithms demonstrate the effectiveness of our proposed method.
Guodong Cao, Zhibo Wang 0001, Xiaowei Dong, Hengchang Guo, Zhan Qin, Kui Ren 0001
IEEE Trans. Dependable Secur. Comput.3
2025 Towards Fair Federated Learning via Unbiased Feature Aggregation
abstract
Federated learning (FL) is a distributed machine learning framework that enables multiple clients to collaboratively train models without raw data exchange. Prior studies on FL mainly focus on optimizing learning performance, enhancing privacy preservation, and improving attack resilience. However, little work studies how to mitigate the unfairness of federated trained models while unfair models would make discriminatory decisions toward certain groups or populations (e.g., favoring males over females), leading to serious ethical concerns. Thus, it is crucial to mitigate model unfairness in FL, yet challenging as this requires centralized access to each data point's fairness-sensitive information (e.g., race, gender), which is prohibited in FL. In this work, we propose a novel fair FL framework FedUFA, where the server can aggregate clients’ learned knowledge in an unbiased manner, to obtain fair and high-usability federated trained models. Specifically, to unearth the bias in clients’ local data and account for potentially heterogeneous local models, we propose a knowledge distillation-based FL scheme, where clients’ knowledge of learned features on a public dataset is amalgamated to the server for aggregation. We train an unbiased feature mapper at the server to remove fairness-sensitive latent features and extract fair representations from clients’ submitted raw features. In particular, we design an adversarial training method to train the mapper, which involves apredictoraiming to maximize the prediction accuracy on the FL task and adiscriminatorintending to help identify fairness-sensitive features. Extensive experiments on real-world datasets demonstrate the effectiveness of FedUFA.
Zeqing He, Zhibo Wang 0001, Xiaowei Dong, Peng Sun 0003, Ju Ren 0001, Kui Ren 0001
IEEE Trans. Dependable Secur. Comput.3
2024 DAAP: Privacy-Preserving Model Accuracy Estimation on Unlabeled Datasets Through Distribution-Aware Adversarial Perturbation
Guodong Cao, Zhibo Wang 0001, Yunhe Feng, Xiaowei Dong
USENIX Security Symposium4
2024 Task-Free Fairness-Aware Bias Mitigation for Black-Box Deployed Models
abstract
With AI systems widely deployed in societal applications, the fairness of these models is of increasing concern, for instance, hiring systems should recommend applicants impartially from different demographic groups, and risk assessment systems must eliminate racial inequity in the criminal justice system. Therefore, ensuring fairness in these models is crucial. In this paper, we propose Task-Free Fairness-Aware Adversarial Perturbation (TF-FAAP), a flexible approach for improving the fairness of black-box deployed models by adding perturbations on input samples that blind their fairness-related attribute information without modifying the model's parameters or structures. The proposed TF-FAAP consists of a discriminator and a generator to create universal fairness-aware perturbations for a variety of tasks. The former aims to distinguish fairnessrelated attributes, and the latter generates perturbations to make the discriminator's prediction distribution of fairness-related attributes uniform. To preserve the utility of perturbed samples, we maximize the mutual information between their representations and corresponding original samples, retaining more original samples' information. In addition, the perturbation generated by TF-FAAP has a high transferability, i.e., the perturbations learned on one dataset can also alleviate the unfairness of a model trained on a different dataset. The extensive experimental evaluation demonstrated the effectiveness and superior performance of our method.
Guodong Cao, Zhibo Wang 0001, Yunhe Feng, Xiaowei Dong, Zhan Qin, Kui Ren 0001
IEEE Trans. Dependable Secur. Comput.4
2023 Towards Fairness-aware Adversarial Network Pruning
abstract
Network pruning aims to compress models while minimizing loss in accuracy. With the increasing focus on bias in AI systems, the bias inheriting or even magnification nature of traditional network pruning methods has raised a new perspective towards fairness-aware network pruning. Straightforward pruning plus debias methods and recent designs for monitoring disparities of demographic attributes during pruning have endeavored to enhance fairness in pruning. However, neither simple assembling of two tasks nor specifically designed pruning strategies could achieve the optimal trade-off among pruning ratio, accuracy, and fairness. This paper proposes an end-to-end learnable framework for fairness-aware network pruning, which optimizes both pruning and debias tasks jointly by adversarial training against those final evaluation metrics like accuracy for pruning, and disparate impact (DI) and equalized odds (DEO) for fairness. In other words, our fairness-aware adversarial pruning method would learn to prune without any handcraft rules. Therefore, our approach could flexibly adapt to variate network structures. Exhaustive experimentation demonstrates the generalization capacity of our approach, as well as superior performance on pruning and debias simultaneously. To highlight, the proposed method could preserve the SOTA pruning performance while significantly improving fairness by around 50% as compared to traditional pruning methods.
Lei Zhang 0006, Zhibo Wang 0001, Xiaowei Dong, Yunhe Feng, Xiaoyi Pang, Kui Ren 0001
ICCV3
2022 Fairness-aware Adversarial Perturbation Towards Bias Mitigation for Deployed Deep Models
abstract
Prioritizing fairness is of central importance in artificial intelligence (AI) systems, especially for those societal applications, e.g., hiring systems should recommend applicants equally from different demographic groups, and risk assessment systems must eliminate racism in criminal justice. Existing efforts towards the ethical development of AI systems have leveraged data science to mitigate biases in the training set or introduced fairness principles into the training process. For a deployed AI system, however, it may not allow for retraining or tuning in practice. By contrast, we propose a more flexible approach, i.e., fairness-aware adversarial perturbation (FAAP), which learns to perturb input data to blind deployed models on fairness-related features, e.g., gender and ethnicity. The key advantage is that FAAP does not modify deployed models in terms of param-eters and structures. To achieve this, we design a discriminator to distinguish fairness-related attributes based on latent representations from deployed models. Meanwhile, a perturbation generator is trained against the discriminator, such that no fairness-related features could be extracted from perturbed inputs. Exhaustive experimental evaluation demonstrates the effectiveness and superior performance of the proposed FAAP. In addition, FAAP is validated on real-world commercial deployments (inaccessible to model pa-rameters), which shows the transferability of FAAP, foreseeing the potential of black-box adaptation.
Zhibo Wang 0001, Xiaowei Dong, Henry Xue, Weifeng Chiu, Tao Wei 0002, Kui Ren 0001
CVPR2
2020 Cross-People Mobile-Phone Based Airwriting Character Recognition
abstract
Airwriting using mobile phones has many applications in human-computer interaction. However, the recognition of airwriting character needs a lot of training data from user, which brings great difficulties to the pratical application. The model learnt from a specific person often cannot yield satisfied results when used on another person. The data gap between people is mainly caused by the following factors: personal writing styles, mobile phone sensors, and ways to hold mobile phones. To address the cross-people problem, we propose a deep neural network(DNN) that combines convolutional neural network(CNN) and bilateral long short-term memory(BLSTM). In each layer of the network, we also add an AdaBN layer which is able to increase the generalization ability of the DNN. Different from the original AdaBN method, we explore the feasibility for semi-supervised learning. We implement it to our design and conduct comprehensive experiments. The evaluation results show that our system can achieve an accuracy of 99% for recognition and an improvement of 10% on average for transfer learning between various factors such as people, devices and postures. To the best of our knowledge, our work is the first to implement cross-people airwriting recognition via motion sensor signal, which is a fundamental step towards ubiquitous sensing11This work is partially supported by The National Key Research and Development Program of China (Grant No. 2016YFB0502201), and the National Natural Science Foundation of China(Grant No. 61971316)..
Haojun Ai, Xiaowei Dong
ICPR5