VLDB 2026 Research / reviewers in the wild / expert
Zhiqin Yang
dblp:251/6782
· DBLP profile ↗
12ranked-venue papers
2as first author
12since 2021 · last 2026
0000-0002-7047-2981ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 9 · 2 first-author · 9 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
7 papers |
Efficient and distributed learning · 58% Generative modeling · 20% Trustworthy machine learning · 10% | |
| Computer graphics and multimedia
3 papers |
Image and video processing · 56% Visual content generation and editing · 36% Geometric modeling and processing · 8% | |
| Network and information security
3 papers |
Security and privacy of machine learning · 49% Digital forensics and information hiding · 45% Privacy and data protection · 6% | |
| Databases, data mining, and information retrieval
1 paper |
Web and social media mining · 100% |
Topics — the 23 heaviest of 23, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Efficient and distributed learning
federated learning |
2.5 | 4 | 2025 | FedGPS: Statistical Rectification Against Data Heterogeneity in Federated Learning · NeurIPS 2025 Robust Training of Federated Models with Extremely Label Deficiency · ICLR 2024 FedFed: Feature Distillation against Data Heterogeneity in Federated Learning · NeurIPS 2023 |
Machine learning › Efficient and distributed learning › federated learning
data heterogeneity |
1.5 | 2 | 2025 | FedGPS: Statistical Rectification Against Data Heterogeneity in Federated Learning · NeurIPS 2025 FedFed: Feature Distillation against Data Heterogeneity in Federated Learning · NeurIPS 2023 |
Web and social media mining › event detection
social event detection |
1.0 | 1 | 2026 | Structural Entropy Guided Incremental Learning for Open-World Multimodal Social Event Detection · AAAI 2026 |
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
0.9 | 1 | 2025 | Multi-Scale Semantic-Guidance Networks: Robust Blind Face Restoration Against Adversarial Attacks · IEEE Trans. Inf. Forensics Secur. 2025 |
Machine learning › Generative modeling
diffusion model |
0.9 | 1 | 2025 | HumanDreamer: Generating Controllable Human-Motion Videos via Decoupled Generation · CVPR 2025 |
Machine learning › Generative modeling › video generation
text-to-video generation |
0.9 | 1 | 2025 | HumanDreamer: Generating Controllable Human-Motion Videos via Decoupled Generation · CVPR 2025 |
Image and video processing › image restoration › face restoration
blind face restoration |
0.9 | 1 | 2025 | Multi-Scale Semantic-Guidance Networks: Robust Blind Face Restoration Against Adversarial Attacks · IEEE Trans. Inf. Forensics Secur. 2025 |
Visual content generation and editing › video generation
human motion video generation |
0.9 | 1 | 2025 | HumanDreamer: Generating Controllable Human-Motion Videos via Decoupled Generation · CVPR 2025 |
Image and video processing
image restoration |
0.9 | 1 | 2025 | Multi-Scale Semantic-Guidance Networks: Robust Blind Face Restoration Against Adversarial Attacks · IEEE Trans. Inf. Forensics Secur. 2025 |
Digital forensics and information hiding
steganography |
0.9 | 1 | 2025 | Hide-in-Motion: Embedding Steganographic Copyright Information into 4D Gaussian Splatting Assets · ICRA 2025 |
Security and privacy of machine learning › adversarial attack
backdoor attack |
0.8 | 1 | 2024 | Beyond Traditional Threats: A Persistent Backdoor Attack on Federated Learning · AAAI 2024 |
Security and privacy of machine learning
federated learning security |
0.8 | 1 | 2024 | Beyond Traditional Threats: A Persistent Backdoor Attack on Federated Learning · AAAI 2024 |
Machine learning › Efficient and distributed learning › model compression › knowledge distillation
feature distillation |
0.7 | 1 | 2023 | FedFed: Feature Distillation against Data Heterogeneity in Federated Learning · NeurIPS 2023 |
Machine learning › Representation and self-supervised learning
contrastive learning |
0.3 | 1 | 2026 | Structural Entropy Guided Incremental Learning for Open-World Multimodal Social Event Detection · AAAI 2026 |
Machine learning › Optimization for machine learning › gradient-based optimization
gradient descent |
0.3 | 1 | 2025 | FedGPS: Statistical Rectification Against Data Heterogeneity in Federated Learning · NeurIPS 2025 |
Machine learning › Efficient and distributed learning
local updates |
0.3 | 1 | 2025 | FedGPS: Statistical Rectification Against Data Heterogeneity in Federated Learning · NeurIPS 2025 |
Machine learning › Deep learning architectures and training › multi-scale architecture
multi-scale network |
0.3 | 1 | 2025 | Multi-Scale Semantic-Guidance Networks: Robust Blind Face Restoration Against Adversarial Attacks · IEEE Trans. Inf. Forensics Secur. 2025 |
Visual content generation and editing
3d content creation |
0.3 | 1 | 2025 | Hide-in-Motion: Embedding Steganographic Copyright Information into 4D Gaussian Splatting Assets · ICRA 2025 |
Geometric modeling and processing › 3d reconstruction › 3d scene reconstruction
dynamic scene reconstruction |
0.3 | 1 | 2025 | Hide-in-Motion: Embedding Steganographic Copyright Information into 4D Gaussian Splatting Assets · ICRA 2025 |
Digital forensics and information hiding
copyright protection |
0.3 | 1 | 2025 | Hide-in-Motion: Embedding Steganographic Copyright Information into 4D Gaussian Splatting Assets · ICRA 2025 |
Digital forensics and information hiding
watermarking |
0.3 | 1 | 2025 | Hide-in-Motion: Embedding Steganographic Copyright Information into 4D Gaussian Splatting Assets · ICRA 2025 |
Machine learning › Learning paradigms
semi-supervised learning |
0.2 | 1 | 2024 | Robust Training of Federated Models with Extremely Label Deficiency · ICLR 2024 |
Privacy and data protection
privacy-preserving machine learning |
0.2 | 1 | 2023 | FedFed: Feature Distillation against Data Heterogeneity in Federated Learning · NeurIPS 2023 |
Methods — techniques the papers use, named apart from their topics
knowledge distillation · 3.3structural entropy · 2.0contrastive learning · 2.0multi-scale semantic guidance · 1.7latent feature encoding · 1.7gaussian splatting · 1.7diffusion transformer · 1.7deformation modeling · 1.7adversarial training · 1.7LAMA loss · 1.7statistical distribution sharing · 0.9gradient information sharing · 0.9full combination trigger · 0.8backdoor injection · 0.8feature distillation · 0.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Structural Entropy Guided Incremental Learning for Open-World Multimodal Social Event DetectionabstractWith the explosive growth of multimodal data streams on social media, the timely detection of emerging social events has become increasingly important. As a result, Multimodal Social Event Detection in open-world settings is receiving growing attention. However, most existing methods face two major limitations: (1) They overlook the dynamic nature of open-world social media data and fail to design dedicated incremental learning frameworks. (2) They ignore the impact of noise in streaming data, leading to performance degradation over long-term detection. To overcome these limitations, we propose SeInEvent (**S**tructural **E**ntropy Guided **In**cremental Learning for Open-World Multimodal Social **Event** Detection). Our innovations are as follows: **First**, considering data dynamics, we design a self-supervised alternating incremental contrastive learning mechanism. Through knowledge distillation, historical event clusters were reviewed and consolidated, and contrastive learning was combined to absorb knowledge of unknown events, ultimately achieving incremental learning without labels. **Second**, addressing the impact of noise, we propose a Pointwise Structural Entropy-based noise filter, which quantifies each sample’s informational contribution to the event clustering structure. It enables automatic removal of noisy data and supports robust long-term detection. Extensive experiments on two public datasets demonstrate that SeInEvent achieves superior performance. Zhiwei Yang 0009, Haimei Qin, Hao Peng 0001, Lei Jiang 0003, Li Sun 0008, Zhiqin Yang |
AAAI | 7 |
| 2026 | Privacy-preserving federated SAR image target recognition with adaptive resource management in space-air-ground integrated networks
Yuchao Hou, Zhiqin Yang, Wei Xiang 0001, Di Wu 0050, Minghui LiWang, Xiaoyu Xia 0001, Zijian Li 0007, Youliang Tian, Yuzhou Sun |
Pattern Recognit. | 3 |
| 2025 | HumanDreamer: Generating Controllable Human-Motion Videos via Decoupled GenerationabstractHuman-motion video generation has been a challenging task, primarily due to the difficulty inherent in learning human body movements. While some approaches have attempted to drive human-centric video generation explicitly through pose control, these methods typically rely on poses derived from existing videos, thereby lacking flexibility. To address this, we propose HumanDreamer, a decoupled human video generation framework that first generates diverse poses from text prompts and then leverages these poses to generate human-motion videos. Specifically, we propose MotionVid, the largest dataset for human-motion pose generation. Based on the dataset, we present MotionDiT, which is trained to generate structured human-motion poses from text prompts. Besides, a novel LAMA loss is introduced, which together contribute to a significant improvement in FID by 62.4%, along with respective enhancements in R-precision for top1, top2, and top3 by 41.8%, 26.3%, and 18.3%, thereby advancing both the Text-to-Pose control accuracy and FID metrics. Our experiments across various Pose-to-Video baselines demonstrate that the poses generated by our method can produce diverse and high-quality human-motion videos. Furthermore, our model can facilitate other downstream tasks, such as pose sequence prediction and 2D-3D motion lifting. Chaojun Ni, Guosheng Zhao, Zhiqin Yang, Muyang Zhang, Xinze Chen, Guan Huang 0003, Lihong Liu, Xingang Wang 0003 |
CVPR | 5 |
| 2025 | Hide-in-Motion: Embedding Steganographic Copyright Information into 4D Gaussian Splatting AssetsabstractAs 4D extensions of 3D Gaussian Splatting (4D-GS) emerge as groundbreaking techniques for dynamic scene reconstruction and novel view synthesis in robotics and computer vision, ensuring the security and trustworthiness of these assets becomes crucial. While steganography has advanced significantly in 2D and 3D media, existing methods are inadequate for the complex, dynamic nature of 4D-GS representations. To address this gap, we propose Hide-in-Motion, a novel 4D steganography method for hiding information through deformation in Gaussian splatting. Our approach introduces a composite attribute and a Decouple Feature Field for coarse-to-fine deformation modeling and embedding implicit information, along with an Opacity-Guided Adaptive strategy. Hide-in-Motion overcomes the limitations of previous techniques, enhancing both the robustness of embedded information and the quality of 4D reconstruction. Extensive evaluations demonstrate that our method successfully embeds and recovers implicit information across various modalities while maintaining high rendering quality in dynamic scenes. This work not only advances copyright protection and secure data transmission for 4D assets but also paves the way for enhancing the security and integrity of 4D digital assets. Code is available at https://github.com/CUHK-AIM-Group/Hide-in-Motion. Hengyu Liu 0007, Chenxin Li, Wentao Pan 0001, Zhiqin Yang, Yifan Liu 0010, Wuyang Li, Yixuan Yuan |
ICRA | 4 |
| 2025 | IR3D-Bench: Evaluating Vision-Language Model Scene Understanding as Agentic Inverse RenderingabstractVision-language models (VLMs) excel at descriptive tasks, but whether they truly understand scenes from visual observations remains uncertain. We introduce IR3D-Bench, a benchmark challenging VLMs to demonstrate understanding through active creation rather than passive recognition. Grounded in the analysis-by-synthesis paradigm, IR3D-Bench tasks Vision-Language Agents (VLAs) with actively using programming and rendering tools to recreate the underlying 3D structure of an input image, achieving agentic inverse rendering through tool use. This ''understanding-by-creating'' approach probes the tool-using generative capacity of VLAs, moving beyond the descriptive or conversational capacity measured by traditional scene understanding benchmarks. We provide a comprehensive suite of metrics to evaluate geometric accuracy, spatial relations, appearance attributes, and overall plausibility. Initial experiments on agentic inverse rendering powered by various state-of-the-art VLMs highlight current limitations, particularly in visual precision rather than basic tool usage. IR3D-Bench, including data and evaluation protocols, is released to facilitate systematic study and development of tool-using VLAs towards genuine scene understanding by creating. Hengyu Liu 0007, Chenxin Li, Yipeng Wu, Wuyang Li, Zhiqin Yang, Zhenyuan Zhang 0001, Yunlong Lin, Sirui Han, Brandon Yushan Feng |
NeurIPS | 6 |
| 2025 | FedGPS: Statistical Rectification Against Data Heterogeneity in Federated LearningabstractFederated Learning (FL) confronts a significant challenge known as data heterogeneity, which impairs model performance and convergence. Existing methods have made notable progress in addressing this issue. However, improving performance in certain heterogeneity scenarios remains an overlooked question: _How robust are these methods to deploy under diverse heterogeneity scenarios?_ To answer this, we conduct comprehensive evaluations across varied heterogeneity scenarios, showing that most existing methods exhibit limited robustness. Meanwhile, insights from these experiments highlight that sharing statistical information can mitigate heterogeneity by enabling clients to update with a global perspective. Motivated by this, we propose **FedGPS** (**Fed**erated **G**oal-**P**ath **S**ynergy), a novel framework that seamlessly integrates statistical distribution and gradient information from others. Specifically, FedGPS statically modifies each client’s learning objective to implicitly model the global data distribution using surrogate information, while dynamically adjusting local update directions with gradient information from other clients at each round. Extensive experiments show that FedGPS outperforms state-of-the-art methods across diverse heterogeneity scenarios, validating its effectiveness and robustness. The code is available at: <https://github.com/CUHK-AIM-Group/FedGPS>. Zhiqin Yang, Yonggang Zhang 0003, Chenxin Li, Yiu-Ming Cheung, Bo Han 0003, Yixuan Yuan |
NeurIPS | 1 |
| 2025 | Multi-Scale Semantic-Guidance Networks: Robust Blind Face Restoration Against Adversarial AttacksabstractImage processing networks are known to be vulnerable to adversarial examples, where adding carefully crafted adversarial perturbations to the inputs can mislead the model. This paper addresses the problem of robust blind face restoration (BFR) against adversarial attacks. BFR refers to recovering the HQ images from the LQ images, which suffer from diverse unknown degradation, such as noise, blur, artifact removal, low resolution, etc. Although existing BFR methods exhibit good performance, they experience significant degradation when subtle distortions and perturbations are introduced into the input images. This paper is the first to investigate, improve comprehensively, and evaluate BFR methods towards adversarial attacks. Project Gradient Descent (PGD) is employed to generate adversarial examples, and multiple types of attacks were used to thoroughly assess the robustness of various BFR methods across different objectives, regions, and levels. We evaluate the robustness of multiple BFR methods and analyze the advantages of their structures and modules towards adversarial attacks. Experimental results demonstrate that the method utilizing latent feature encoding and pre-trained discrete HQ codebook achieves better robustness than other methods, with the latter outperforming the former. Similarly, multi-scale semantic guidance information also exhibits superior performance in enhancing robustness. Therefore, we propose a powerful BFR method to mitigate this issue while maintaining better performance. Extensive experiments on three real-world datasets demonstrate our method’s state-of-the-art robustness in different scenarios. Zhenyuan Zhang 0001, Xingqun Qi, Zhenbo Song, Zhiqin Yang, Jianfeng Lu 0003, Muyi Sun, Man Zhang 0005, Zhenan Sun |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | Beyond Traditional Threats: A Persistent Backdoor Attack on Federated LearningabstractBackdoors on federated learning will be diluted by subsequent benign updates. This is reflected in the significant reduction of attack success rate as iterations increase, ultimately failing. We use a new metric to quantify the degree of this weakened backdoor effect, called attack persistence. Given that research to improve this performance has not been widely noted, we propose a Full Combination Backdoor Attack (FCBA) method. It aggregates more combined trigger information for a more complete backdoor pattern in the global model. Trained backdoored global model is more resilient to benign updates, leading to a higher attack success rate on the test set. We test on three datasets and evaluate with two models across various settings. FCBA's persistence outperforms SOTA federated learning backdoor attacks. On GTSRB, post-attack 120 rounds, our attack success rate rose over 50% from baseline. The core code of our method is available at https://github.com/PhD-TaoLiu/FCBA. Tao Liu 0038, Zhu Feng, Zhiqin Yang, Chen Xu 0008, Dapeng Man, Wu Yang 0001 |
AAAI | 4 |
| 2024 | Robust Training of Federated Models with Extremely Label DeficiencyabstractFederated semi-supervised learning (FSSL) has emerged as a powerful paradigm for collaboratively training machine learning models using distributed data with label deficiency. Advanced FSSL methods predominantly focus on training a single model on each client. However, this approach could lead to a discrepancy between the objective functions of labeled and unlabeled data, resulting in gradient conflicts. To alleviate gradient conflict, we propose a novel twin-model paradigm, called **Twinsight**, designed to enhance mutual guidance by providing insights from different perspectives of labeled and unlabeled data. In particular, Twinsight concurrently trains a supervised model with a supervised objective function while training an unsupervised model using an unsupervised objective function. To enhance the synergy between these two models, Twinsight introduces a neighborhood-preserving constraint, which encourages the preservation of the neighborhood relationship among data features extracted by both models. Our comprehensive experiments on four benchmark datasets provide substantial evidence that Twinsight can significantly outperform state-of-the-art methods across various experimental settings, demonstrating the efficacy of the proposed Twinsight. Yonggang Zhang 0003, Zhiqin Yang, Xinmei Tian 0001, Nannan Wang 0001, Tongliang Liu, Bo Han 0003 |
ICLR | 2 |
| 2023 | Efficient Side-Channel Attack through Balanced Labels Compression and Variational AutoencoderabstractRecently, side-channel attacks based on deep learning (DLSCAs) have attracted much attention. Many works have improved the performance of DLSCAs by designing advanced neural network architectures and training strategies. There are few studies on leakage models for DLSCAs. Existing researches usually utilize the intermediate value Hamming weight (HW) and the intermediate value itself (ID) as leakage models. Training a classifier with good performance is challenging due to the many label classes in the ID leakage model. The HW leakage model can significantly reduce the number of labels, but it will cause samples imbalance. In this paper, we propose a new DLSCA leakage model, named Balanced Labels Compression (BLC). We consider dividing sensitive intermediate values with same lowest bits into same class to obtain balanced labels. Then, we train a classifier using the compressed BLC labels and profiling energy traces. At the attack phase, the probability distribution of BLC labels is extended to the probability distribution of sensitive intermediate values. We conduct extensive comparison experiments with HW, ID, and BLC leakage models under the two scenarios of sufficient and insufficient profiling energy traces. Further, we exploit VAE to improve attack performance when energy traces are insufficient. Experimental results show that VAE-based data augmentation can significantly reduce required energy traces. Nengfu Cai, Zhiqin Yang, Shuhai Wang, Yanling Jiang, Mingsheng Liu |
MSN | 2 |
| 2023 | FedFed: Feature Distillation against Data Heterogeneity in Federated LearningabstractFederated learning (FL) typically faces data heterogeneity, i.e., distribution shifting among clients.
Sharing clients' information has shown great potentiality in mitigating data heterogeneity, yet incurs a dilemma in preserving privacy and promoting model performance. To alleviate the dilemma, we raise a fundamental question: Is it possible to share partial features in the data to tackle data heterogeneity?
In this work, we give an affirmative answer to this question by proposing a novel approach called **Fed**erated **Fe**ature **d**istillation (FedFed).
Specifically, FedFed partitions data into performance-sensitive features (i.e., greatly contributing to model performance) and performance-robust features (i.e., limitedly contributing to model performance).
The performance-sensitive features are globally shared to mitigate data heterogeneity, while the performance-robust features are kept locally.
FedFed enables clients to train models over local and shared data. Comprehensive experiments demonstrate the efficacy of FedFed in promoting model performance. Zhiqin Yang, Yonggang Zhang 0003, Yu Zheng 0021, Xinmei Tian 0001, Tongliang Liu, Bo Han 0003 |
NeurIPS | 1 |
| 2023 | RoSGAS: Adaptive Social Bot Detection with Reinforced Self-supervised GNN Architecture SearchabstractSocial bots are referred to as the automated accounts on social networks that make attempts to behave like humans. While Graph Neural Networks (GNNs) have been massively applied to the field of social bot detection, a huge amount of domain expertise and prior knowledge is heavily engaged in the state-of-the-art approaches to design a dedicated neural network architecture for a specific classification task. Involving oversized nodes and network layers in the model design, however, usually causes the over-smoothing problem and the lack of embedding discrimination. In this article, we propose RoSGAS , a novel R einf o rced and S elf-supervised G NN A rchitecture S earch framework to adaptively pinpoint the most suitable multi-hop neighborhood and the number of layers in the GNN architecture. More specifically, we consider the social bot detection problem as a user-centric subgraph embedding and classification task. We exploit the heterogeneous information network to present the user connectivity by leveraging account metadata, relationships, behavioral features, and content features. RoSGAS uses a multi-agent deep reinforcement learning (RL), 31 pages. mechanism for navigating the search of optimal neighborhood and network layers to learn individually the subgraph embedding for each target user. A nearest neighbor mechanism is developed for accelerating the RL training process, and RoSGAS can learn more discriminative subgraph embedding with the aid of self-supervised learning. Experiments on five Twitter datasets show that RoSGAS outperforms the state-of-the-art approaches in terms of accuracy, training efficiency, and stability and has better generalization when handling unseen samples. Yingguang Yang, Renyu Yang, Zhiqin Yang, Yue Wang 0129, Jie Xu 0007, Haiyong Xie 0001 |
ACM Trans. Web | 5 |