Fangjian Tao

dblp:245/1593 · DBLP profile ↗
← Back
6ranked-venue papers
0as first author
6since 2021 · last 2025
0000-0001-8637-7383ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 4 · 4 since 2021Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021
YearPublicationVenuePosition
2025 Localization and Elimination: Object Detection Physical Patch Defense Based on Adversarial Patch Characterization
abstract
Object detection plays an important role in areas such as intelligent surveillance and autonomous driving but is also faces the threat of adversarial patch attacks. Because adversarial patch attacks are highly stealthy, efficient and physically realizable, they pose a huge security risk to real-world object detectors. Therefore, we propose a segmented defense method, Localization and Elimination (LAE), for physically realizable adversarial patch attacks. The method designs three localization modules, namely, image information segmentation, heterogeneous region extraction, and local region preservation, as well as a feature fusion module, by analyzing the three intrinsic features of adversarial patches. By fusing the feature maps output from the three localization modules, the patch region feature map is finally output through the feature fusion module. Then the localized patch regions are filled with black pixels. This approach is different from other defense methods in that it can provide excellent defense performance against physically adversarial patches of different sizes, numbers, locations, and appearances in a variety of complex environmental contexts. We have demonstrated through extensive experiments that this defense method provides excellent defense performance and greater robustness than current state-of-the-art defense methods.
Zesheng Zhou, Sizheng Fu, Chunjie Cao, Fangjian Tao, Jingzhang Sun
IJCNN4
2025 JPEG-Domain Malware Detection With Pretrained Lightweight Vision Transformer Model
abstract
Malware is proliferating at an exponential rate in cyberspace, posing serious threats to on-device systems characterized by limited computational capabilities. In this work, we address the critical challenge posed by data imbalance—where rare malware families receive inadequate representation—by proposing MalViT, a lightweight Vision Transformer (ViT) architecture that directly operates in the JPEG frequency domain. Rather than converting Huffman-coded signals into RGB spatial images, MalViT leverages Discrete Cosine Transform (DCT) coefficients to reduce data redundancy and computational overhead. We further improve the model’s generalization through both pre-training and fine-tuning workflows. Comprehensive evaluations on two large-scale, real-world malware datasets, MalNet-Image (1.26 M samples) and BODMAS (51 K samples), demonstrate that MalViT accelerates data loading by nearly threefold compared to existing methods. On GPU and CPU, MalViT achieves approximately 2.0× and 4.7× faster inference throughput than MobileViT, respectively, while incurring minimal or even improved accuracy loss. When processing 224 × 224-pixel JPEG images, MalViT completes inference within an average of 3.12ms per sample, which is 8.79× faster than VisMal and 5.91× faster than ViT4Mal. Furthermore, its compact design comprises only 1.1M parameters and requires 10M MACs, making it particularly suitable for resource-constrained on-device deployment.
Binghui Zou, Chunjie Cao, Fangjian Tao, Longjuan Wang, Jingzhang Sun
IEEE Trans. Dependable Secur. Comput.3
2024 A Weighted Discrete Wavelet Transform-Based Capsule Network for Malware Classification
Tonghua Qiao, Chunjie Cao, Binghui Zou, Fangjian Tao, Yinan Cheng, Jingzhang Sun
ICPR (4)4
2023 Revisiting Graph Contrastive Learning for Anomaly Detection
abstract
Combining Graph neural networks (GNNs) with contrastive learning for anomaly detection has drawn rising attention recently. Existing graph contrastive anomaly detection (GCAD) methods have primarily focused on improving detection capability through graph augmentation and multi-scale contrast modules. However, the underlying mechanisms of how these modules work have not been fully explored. We dive into the multi-scale and graph augmentation mechanism and observed that multi-scale contrast modules do not enhance the expression, while the multi-GNN modules are the hidden contributors. Previous studies have tended to attribute the benefits brought by multi-GNN to the multi-scale modules. In the paper, we delve into the misconception and propose Multi-GNN and Augmented Graph contrastive framework MAG, which unified the existing GCAD methods in the contrastive self-supervised perspective. We extracted two variants from the MAG framework, L-MAG and M-MAG. The L-MAG is the lightweight instance of the MAG, which outperform the state-of-the-art on Cora and Pubmed with the low computational cost. The variant M-MAG equipped with multi-GNN modules further improve the detection performance. Our study sheds light on the drawback of the existing GCAD methods and demonstrates the potential of multi-GNN and graph augmentation modules. Our code is available at https://anonymous.4open.science/r/MAG-Framework-74D0.
Chunjie Cao, Fangjian Tao, Jingzhang Sun
ECAI3
2023 LGWAE: Label-Guided Weighted Autoencoder Network for Flexible Targeted Attacks of Deep Hashing
abstract
Deep hashing is frequently utilized in large-scale image retrieval because of its strong representation learning capabilities and effective processing capacity. However, deep hashing models are susceptible to adversarial examples. We propose a label-guided weighted autoencoder network (LGWAE) to generate adversarial examples for targeted hashing attacks. Specifically, we first introduce a multi-label learning network to extract the semantic features and the category code of different labels. Then, the semantic features and the benign image are collectively fed into an autoencoder in order to generate a natural-looking adversarial example. The category code is used as target hash code to supervise the generation of the adversarial example. To efficiently generate better-performing adversarial examples, we design a weighted Hamming distance loss that dynamically adjusts the loss value based on the label similarity between the benign image label and the target label. Numerous experiments demonstrate that we are capable of efficiently and effectively generating better quality adversarial samples.
Sizheng Fu, Chunjie Cao, Fangjian Tao, Binghui Zou, Jingzhang Sun
IJCNN3
2022 IMCLNet: A lightweight deep neural network for Image-based Malware Classification
Binghui Zou, Chunjie Cao, Fangjian Tao, Longjuan Wang
J. Inf. Secur. Appl.3