VLDB 2026 Research / reviewers in the wild / expert
Yuchen Ren 0002
dblp:252/7814-2
· DBLP profile ↗
9ranked-venue papers
5as first author
9since 2021 · last 2026
0000-0002-6009-6118ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 3 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | On Success and Simplicity: A Second Look at Transferable Vision-Language Attack PipelineabstractVision-Language Pre-training Models (VLPMs) are known to be vulnerable to adversarial attacks. Recent transferable attacks on VLPMs have followed a common pipeline with complicated loss functions or multi-stage text/image attacks. However, in this paper, we demonstrate that such a sophisticated attack pipeline can be simpler yet more successful. Specifically, we identify three previously overlooked issues caused by inappropriate cross-modal interactions and excessive operations. To address them, we propose the Simple Vision-Language Attack (SimVLA) pipeline, which observably improves transferability and efficiency. Experiments on four datasets and three downstream tasks validate the superiority of our pipeline. For instance, on Flickr30k text-image retrieval dataset, our SimVLA outperforms the SOTA baseline in R@1 transferability by 8.01\%-14.71\%, while consuming only about 35.73\% of the time and 46.26\% of the max VRAM. Overall, the superiority of our SimVLA highlights the importance of leveraging domain knowledge (e.g., our proposed cross-modal word identification), while blindly pursuing intricate operations (e.g, complex loss functions and redundant multi-stage designs) may even be harmful. We hope our SimVLA can serve as a simple yet effective backbone for future extensions. Code is available at https://github.com/RYC-98/SimVLA. Yuchen Ren 0002, Zhengyu Zhao 0001, Chenhao Lin, Bo Yang 0049, Chao Shen 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Improving Integrated Gradient-based Transferable Adversarial Examples by Refining the Integration PathabstractTransferable adversarial examples are known to cause threats in practical, black-box attack scenarios. A notable approach to improving transferability is using integrated gradients (IG), originally developed for model interpretability. In this paper, we find that existing IG-based attacks have limited transferability due to their naive adoption of IG in model interpretability. To address this limitation, we focus on the IG integration path and refine it in three aspects: multiplicity, monotonicity, and diversity, supported by theoretical analyses. We propose the Multiple Monotonic Diversified Integrated Gradients (MuMoDIG) attack, which can generate highly transferable adversarial examples on different CNN and ViT models and defenses. Experiments validate that MuMoDIG outperforms the latest IG-based attack by up to 37.3% and other state-of-the-art attacks by 8.4%. In general, our study reveals that migrating established techniques to improve transferability may require non-trivial efforts. Yuchen Ren 0002, Zhengyu Zhao 0001, Chenhao Lin, Bo Yang 0049, Lu Zhou 0002, Zhe Liu 0001, Chao Shen 0001 |
AAAI | 1 |
| 2025 | Improving Adversarial Transferability on Vision Transformers via Forward Propagation RefinementabstractVision Transformers (ViTs) have been widely applied in various computer vision and vision-language tasks. To gain insights into their robustness in practical scenarios, transferable adversarial examples on ViTs have been extensively studied. A typical approach to improving adversarial transferability is by refining the surrogate model. However, existing work on ViTs has restricted their surrogate refinement to backward propagation. In this work, we instead focus on Forward Propagation Refinement (FPR) and specifically refine two key modules of ViTs: attention maps and token embeddings. For attention maps, we propose Attention Map Diversification (AMD), which diversifies certain attention maps and also implicitly imposes beneficial gradient vanishing during backward propagation. For token embeddings, we propose Momentum Token Embedding (MTE), which accumulates historical token embeddings to stabilize the forward updates in both the Attention and MLP blocks. We conduct extensive experiments with adversarial examples transferred from ViTs to various CNNs and ViTs, demonstrating that our FPR outperforms the current best (backward) surrogate refinement by up to 7.0% on average. We also validate its superiority against popular defenses and its compatibility with other transfer methods. Codes and appendix are available at https://github.com/RYC-98/FPR. Yuchen Ren 0002, Zhengyu Zhao 0001, Chenhao Lin, Bo Yang 0049, Lu Zhou 0002, Zhe Liu 0001, Chao Shen 0001 |
CVPR | 1 |
| 2024 | Efficient polar coordinates attack with adaptive activation strategy
Yuchen Ren 0002, Hegui Zhu, Chengqing Li |
Expert Syst. Appl. | 1 |
| 2024 | A Novel Intelligent Forecasting Framework for Quarterly or Monthly Energy ConsumptionabstractAccurately predicting quarterly or monthly energy consumption remains challenging so far. Despite the abundance of relevant studies, most of them focus on univariate modeling. Moreover, the core of nearly all multivariate forecasting studies is an unstable forecasting system based on a single model. Therefore, there is an urgent need for an efficient and rational prediction method. For the prediction task of quarterly or monthly energy consumption characterized by small samples and nonlinearity, this article develops a new joint forecasting-centered forecasting framework by integrating machine learning and grey system theory. In this forecasting framework, grey relational analysis is used to filter the influencing factors of the study object, a new adaptive weighted least squares support vector regression model is developed to describe the relationship between the study object and the filtered influencing factors, and a new difference equation prediction model is employed to predict the future values of the filtered influencing factors. The joint forecasting task is accomplished by inputting the future values of the filtered influencing factors into the trained adaptive weighted least squares support vector regression model. Experimental simulation results demonstrate that the two prediction models developed in this framework, along with the overall forecasting approach, outperform competing methods. These results confirm the effectiveness of the proposed forecasting framework in accurately predicting quarterly or monthly energy consumption, even in scenarios with limited data and nonlinear relationships. Hegui Zhu, Yuchen Ren 0002, Zhimu Wang |
IEEE Trans. Ind. Informatics | 3 |
| 2023 | Boosting Adversarial Transferability via Gradient Relevance AttackabstractPlentiful adversarial attack researches have revealed the fragility of deep neural networks (DNNs), where the imperceptible perturbations can cause drastic changes in the output. Among the diverse types of attack methods, gradient-based attacks are powerful and easy to implement, arousing wide concern for the security problem of DNNs. However, under the black-box setting, the existing gradient-based attacks have much trouble in breaking through DNN models with defense technologies, especially those adversarially trained models. To make adversarial examples more transferable, in this paper, we explore the fluctuation phenomenon on the plus-minus sign of the adversarial perturbations’ pixels during the generation of adversarial examples, and propose an ingenious Gradient Relevance Attack (GRA). Specifically, two gradient relevance frameworks are presented to better utilize the information in the neighbor-hood of the input, which can correct the update direction adaptively. Then we adjust the update step at each iteration with a decay indicator to counter the fluctuation. Experiment results on a subset of the ILSVRC 2012 validation set forcefully verify the effectiveness of GRA. Furthermore, the attack success rates of 68.7% and 64.8% on Tencent Cloud and Baidu AI Cloud further indicate that GRA can craft adversarial examples with the ability to transfer across both datasets and model architectures. Code is released at https://github.com/RYC-98/GRA. Hegui Zhu, Yuchen Ren 0002, Xiaoyan Sui, Lianping Yang, Wuming Jiang |
ICCV | 2 |
| 2023 | LIGAA: Generative adversarial attack method based on low-frequency information
Hegui Zhu, Yuchen Ren 0002, Wuming Jiang |
Comput. Secur. | 4 |
| 2023 | Boosting transferability of targeted adversarial examples with non-robust feature alignment
Hegui Zhu, Xiaoyan Sui, Yuchen Ren 0002, Yanmeng Jia |
Expert Syst. Appl. | 3 |
| 2023 | Crafting transferable adversarial examples via contaminating the salient feature variance
Yuchen Ren 0002, Hegui Zhu, Xiaoyan Sui |
Inf. Sci. | 1 |