VLDB 2026 Research / reviewers in the wild / expert
Ziwen He
dblp:255/6047
· DBLP profile ↗
18ranked-venue papers
4as first author
18since 2021 · last 2026
0000-0002-1019-3884ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 11 · 3 first-author · 11 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Security and privacy · 4 · 4 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MAP-Mamba: Multi-Artifacts Perception Mamba for Generalizable Face Forgery DetectionabstractFace forgery detection suffers from cross-dataset generalization challenges, where performance degradation occurs due to distribution shifts between training and testing data. Recently, pseudo-fake face generation strategy has mitigated models overfitting to specific forgery traces. However, detectors based on this strategy exhibit an overreliance on blending boundary artifacts for their classification decisions. This overreliance significantly limits their ability to generalize to more advanced face manipulation algorithms, such as FaceDancer and InSwap, which are designed to produce smooth and natural transitions in the blending boundary region. To address this, we propose MAP-Mamba, a novel Multi-Artifacts Perception Mamba framework for modeling generalizable artifact representations from “Generation” to “Enrichment” to “Strengthening”. First, we design an attribute-level face blending method that generate pseudo-fake faces containing fine-grained artifacts via three attribute generators. These pseudo-fakes mimic subtle local inconsistencies in advanced forgery algorithms, guiding the MAP-Mamba to learn diverse forgery features beyond the blending boundary artifacts. Second, considering the variability of face artifacts distribution caused by different forgery algorithms, an artifact style mixing strategy is designed to enrich the artifact style distribution in the training phase by mixing and reorganizing the artifact style features, and to enhance the model’s ability to handle unknown forgery methods. Finally, an adaptive artifact guidance mechanism is proposed to dynamically amplify the artifact-related feature to further strengthen the model’s sensitivity to key artifacts. Extensive experiments on several benchmarks show that MAP-Mamba achieves superior robustness and generalization performance. Ziwen He, Xinjue Hu, Weinan Guan, Wei Wang 0025, Zhangjie Fu 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | Fast Adversarial Training With Weak-to-Strong Spatial-Temporal Consistency in the Frequency Domain on VideosabstractAdversarial Training (AT) has been shown to significantly enhance adversarial robustness via a min-max optimization approach. However, its effectiveness in video recognition tasks is hampered by two main challenges. First, fast adversarial training for video models remains largely unexplored, which severely impedes its practical applications. Specifically, most video adversarial training methods are computationally costly, with long training times and high expenses. Second, existing methods struggle with the trade-off between clean accuracy and adversarial robustness. To address these challenges, we introduce Video Fast Adversarial Training with Weak-to-Strong consistency (VFAT-WS), the first fast adversarial training method for video data. Specifically, VFAT-WS incorporates the following key designs: First, it integrates a straightforward yet effective temporal frequency augmentation (TF-AUG), and its spatial-temporal enhanced form STF-AUG, along with Fast Gradient Sign Method (FGSM) to boost training efficiency and robustness. Second, it devises a weak-to-strong spatial-temporal consistency regularization, which seamlessly integrates the simple TF-AUG and the more complex STF-AUG. Leveraging the consistency regularization, it steers the learning process from simple to complex augmentations. Both of them work together to achieve a better trade-off between clean accuracy and robustness. Extensive experiments on UCF-101 and HMDB-51 with both CNN and Transformer-based models demonstrate that VFAT-WS achieves great improvements in adversarial robustness and corruption robustness, while accelerating training by nearly 490%. Songping Wang, Yueming Lyu, Xiantao Hu, Ziwen He, Wei Wang 0025, Caifeng Shan, Liang Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2026 | Dual Frequency Branch Framework With Reconstructed Sliding Windows Attention for AI-Generated Image DetectionabstractThe rapid advancement of Generative Adversarial Networks (GANs) and diffusion models has enabled the creation of highly realistic synthetic images, presenting significant societal risks, such as misinformation and deception. As a result, detecting AI-generated images has emerged as a critical challenge. Existing research emphasizes extracting fine-grained features to enhance detector generalization, yet they often lack consideration for the importance and interdependencies of internal elements within local regions and are limited to a single frequency domain, hindering the capture of general forgery traces. To overcome the aforementioned limitations, we first utilize a sliding window to restrict the attention mechanism to a local window, and reconstruct the features within the window to model the relationships between neighboring internal elements within the local region. Then, we design a dual frequency domain branch framework consisting of four frequency domain subbands of DWT and the phase part of FFT to enrich the extraction of local forgery features from different perspectives. Through feature enrichment of dual frequency domain branches and fine-grained feature extraction of reconstruction sliding window attention, our method achieves superior generalization detection capabilities on both GAN and diffusion model-based generative images. Evaluated on diverse datasets comprising images from 65 distinct generative models, our approach achieves a 2.13% improvement in detection accuracy over state-of-the-art methods. Jiazhen Yan, Ziqiang Li 0001, Fan Wang 0024, Ziwen He, Zhangjie Fu 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Pair-wise Confidence Difference-based Pseudo-Label Selection for Universal Mismatched SteganalysisabstractImage steganalysis is a detection task to distinguish whether a secret message is embedded in a digital image. Due to the domain inconsistency caused by Cover Source Mismatch(CSM) and Steganographic Algorithm Mismatch (SAM), most of them suffer from significant performance degradation. Recent mismatched steganalysis focused on extracting domain invariant features by domain adversarial training or feature alignment. However these schemes are limited to unstable performance in diverse domain mismatch scenarios, and are even ineffective in some cases. In this paper, we propose a Universal Mismatched Steganalysis PCD-UMS via pair-wise confidence difference-based pseudo-label selection from the perspective of optimizing target training data. Specifically, we reveal a strong positive correlation commonality between pair-wise confidence difference and the detection performance of steganalysis among various mismatch scenarios. Based on this, a novel pseudo-label selection strategy consisting of maximum confidence difference first (MCDF) rule and pair-wise label differential storage (PLDS) rule is designed to select and filter the reliable target pseudo-labels. Furthermore, a multi-perspective pair-wise feature alignment loss is designed to initially transfer the classification ability of source steganalysis, thus solving the problem that source steganalysis fails completely under some domain mismatch scenarios. Comprehensive experiments show that our PCD-UMS outperforms the existing mismatched steganalysis by 12.07% and 3.40% in terms of detection performance under CSM and SAM scenarios. Fan Wang 0024, Zhangjie Fu 0001, Xiang Zhang 0023, Ziqiang Li 0001, Ziwen He |
ACM Multimedia | 5 |
| 2025 | Frequency Domain Distributed Perturbations: Towards Query-Efficient Black-Box Adversarial Video AttackabstractIn recent years, adversarial attacks on video recognition models have attracted increasing attention. However, most existing strategies are extensions of image-based methods, where adversarial perturbations are computed independently and embedded into individual frames. This independent per-frame perturbation process wastes computational resources and leads to excessive query consumption. To address this problem, we introduce Frequency Domain Distributed Perturbations (FDP), a straightforward yet effective black-box video attack method using temporal correlations between video frames. Specifically, FDP first converts the input video into the frequency domain and calculates globally coordinated adversarial perturbations in the spectral space. By conducting global optimization in the frequency domain, FDP improves the effectiveness of each query, significantly decreasing the total number of queries needed. The resulting perturbations are temporally distributed across frames to preserve the spatiotemporal structure. Furthermore, we introduce a frequency-sensitive mask to identify the spectral regions most critical to the model's predictions. By applying perturbations only to these key frequency bands, FDP further reduces the perturbation search space and improves query efficiency. Extensive experiments demonstrate that our method significantly reduces query consumption while achieving higher attack success rates than state-of-the-art approaches. Teng Jin, Ziwen He, Zhangjie Fu 0001, Songping Wang, Yueming Lyu |
ACM Multimedia | 2 |
| 2025 | Is Artificial Intelligence Generated Image Detection a Solved Problem?abstractThe rapid advancement of generative models, such as GANs and Diffusion models, has enabled the creation of highly realistic synthetic images, raising serious concerns about misinformation, deepfakes, and copyright infringement. Although numerous Artificial Intelligence Generated Image (AIGI) detectors have been proposed, often reporting high accuracy, their effectiveness in real-world scenarios remains questionable. To bridge this gap, we introduce AIGIBench, a comprehensive benchmark designed to rigorously evaluate the robustness and generalization capabilities of state-of-the-art AIGI detectors. AIGIBench simulates real-world challenges through four core tasks: multi-source generalization, robustness to image degradation, sensitivity to data augmentation, and impact of test-time pre-processing. It includes 23 diverse fake image subsets that span both advanced and widely adopted image generation techniques, along with real-world samples collected from social media and AI art platforms. Extensive experiments on 11 advanced detectors demonstrate that, despite their high reported accuracy in controlled settings, these detectors suffer significant performance drops on real-world data, limited benefits from common augmentations, and nuanced effects of pre-processing, highlighting the need for more robust detection strategies. By providing a unified and realistic evaluation framework, AIGIBench offers valuable insights to guide future research toward dependable and generalizable AIGI detection. Ziqiang Li 0001, Jiazhen Yan, Ziwen He, Weiwei Jiang 0001, Lizhi Xiong, Zhangjie Fu 0001 |
NeurIPS | 3 |
| 2025 | Denoising Diffusion Probabilistic Steganography Based on Standardized Secret Noise
Xiang Zhang 0023, Tianheng Song, Fei Peng 0001, Ziwen He, Daoyong Fu, Bei Yuan, Zhangjie Fu 0001 |
IEEE Signal Process. Lett. | 4 |
| 2025 | MMDStegNet: An Adversarial Steganography Framework With Maximum Mean Discrepancy RegularizationabstractRecent advances in steganography leverage generative adversarial networks (GANs) as a robust framework for securing covert communications through adversarial training between stego-generators and steganalytic discriminators. This paradigm facilitates the synthesis of secure steganographic images by harnessing the competition between network components. However, existing GAN-based approaches suffer from asymmetric capacity between generators and discriminators: suboptimally trained discriminators provide inadequate gradient guidance for generator optimization, causing premature convergence and security degradation. To overcome this critical limitation, we propose an enhanced multi-steganalyzer adversarial architecture incorporating maximum mean discrepancy (MMD) regularization. Our framework introduces two key innovations: 1) an MMD-based regularization mechanism mitigating distributional discrepancies among multiple steganalyzers through kernel embedding optimization, and 2) a reward function with fusing gradients derived from multiple steganalyzers to boost reinforcement learning-based adversarial training. This dual strategy enables the discriminator to learn generalized forensic features while maintaining equilibrium in adversarial training dynamics, ultimately allowing the generator to produce stego images resistant to multiple steganalyzers simultaneously. Comprehensive experiments validate our method’s superiority: When evaluated across five steganalysis networks, including YedNet, CovNet, LWENet, SRNet, and SwT-SN, at 0.1-0.4 bpp payloads, the proposed framework achieves improvements in average detection error rates over state-of-the-art techniques such as SPAR-RL and GMAN. Ablation studies further confirm that MMD regularization contributes significantly to security enhancement. Ziwen He, Xingjie Dai, Xiang Zhang 0023, Zhangjie Fu 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 1 |
| 2025 | Noise-Informed Diffusion-Generated Image Detection With Anomaly AttentionabstractWith the rapid development of image generation technologies, especially the advancement of Diffusion Models, the quality of synthesized images has significantly improved, raising concerns among researchers about information security. To mitigate the malicious abuse of diffusion models, diffusion-generated image detection has proven to be an effective countermeasure. However, a key challenge for forgery detection is generalising to diffusion models not seen during training. In this paper, we address this problem by focusing on image noise. We observe that images from different diffusion models share similar noise patterns, distinct from genuine images. Building upon this insight, we introduce a novel Noise-Aware Self-Attention (NASA) module that focuses on noise regions to capture anomalous patterns. To implement a SOTA detection model, we incorporate NASA into Swin Transformer, forming an novel detection architecture NASA-Swin. Additionally, we employ a cross-modality fusion embedding to combine RGB and noise images, along with a channel mask strategy to enhance feature learning from both modalities. Extensive experiments demonstrate the effectiveness of our approach in enhancing detection capabilities for diffusion-generated images. When encountering unseen generation methods, our approach achieves the state-of-the-art performance. Weinan Guan, Wei Wang 0025, Bo Peng 0002, Ziwen He, Jing Dong 0003, Haonan Cheng |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | Exploiting Backdoors of Face Synthesis Detection with Natural TriggersabstractDeep neural networks have enhanced face synthesis detection in discriminating Artificial Intelligence Generated Content (AIGC). However, their security is threatened by the injection of carefully crafted triggers during model training (i.e., backdoor attacks). Although existing backdoor defenses and manual data selection are able to mitigate those using human-eye-sensitive triggers, such as patches or adversarial noises, the more challenging natural backdoor triggers remain insufficiently researched. To further investigate natural triggers, we propose a novel analysis-by-synthesis backdoor attack against face synthesis detection models, which embeds natural triggers in the latent space. We study such backdoor vulnerability from two perspectives: (1) Model Discrimination (Optimization-Based Trigger) : we adopt a substitute detection model and find the trigger by minimizing the cross-entropy loss; (2) Data Distribution (Custom Trigger): we manipulate the uncommon facial attributes in the long-tailed distribution to generate poisoned samples without the supervision from detection models. Furthermore, to evaluate the detection models toward the latest AIGC, we utilize both the state-of-the-art StyleGAN and Stable Diffusion for trigger generation. Finally, these backdoor triggers introduce specific semantic features to the generated poisoned samples (e.g., skin textures and smile), which are more natural and robust. Extensive experiments show that our method is superior over existing pixel space backdoor attacks on three levels: (1) Attack Success Rate : achieving an attack success rate exceeding 99 \(\%\) , comparable to baseline methods, with less than 0.1 \(\%\) model accuracy drop and under 3 \(\%\) poisoning rate; (2) Backdoor Defense : showing superior robustness when faced with existing backdoor defenses (e.g., surpassing baseline methods by over 30 \(\%\) after a 15 \({}^{\circ}\) rotation); (3) Human Inspection : being less human-eye-sensitive from a user study with 46 participants and a collection of 2,300 data points. Xiaoxuan Han, Wei Wang 0025, Ziwen He, Jing Dong 0003 |
ACM Trans. Multim. Comput. Commun. Appl. | 4 |
| 2024 | Counterfactual Explanations for Face Forgery Detection via Adversarial Removal of ArtifactsabstractHighly realistic AI generated face forgeries known as deepfakes have raised serious social concerns. Although DNN-based face forgery detection models have achieved good performance, they are vulnerable to latest generative methods that have less forgery traces and adversarial attacks. This limitation of generalization and robustness hinders the credibility of detection results and requires more explanations. In this work, we provide counterfactual explanations for face forgery detection from an artifact removal perspective. Specifically, we first invert the forgery images into the StyleGAN latent space, and then adversarially optimize their latent representations with the discrimination supervision from the target detection model. We verify the effectiveness of the proposed explanations from two aspects: (1) Counterfactual Trace Visualization: the enhanced forgery images are useful to reveal artifacts by visually contrasting the original images and two different visualization methods; (2) Transferable Adversarial Attacks: the adversarial forgery images generated by attacking the detection model are able to mislead other detection models, implying the removed artifacts are general. Extensive experiments demonstrate that our method achieves over 90% attack success rate and superior attack transferability. Compared with naive adversarial noise methods, our method adopts both generative and discriminative model priors, and optimize the latent representations in a synthesis-by-analysis way, which forces the search of counterfactual explanations on the natural face manifold. Thus, more general counterfactual traces can be found and better adversarial attack transferability can be achieved. Our code is available at https://github.com/yangli-lab/Artifact-Eraser/. Yang Li 0255, Wei Wang 0025, Ziwen He, Bo Peng 0002, Jing Dong 0003 |
ICME | 4 |
| 2024 | Mitigating Social Biases in Text-to-Image Diffusion Models via Linguistic-Aligned Attention GuidanceabstractRecent advancements in text-to-image generative models have showcased remarkable capabilities across various tasks. However, these powerful models have revealed the inherent risks of social biases. Such biases can propagate distorted real-world perspectives and spread unforeseen prejudice and discrimination. Current debiasing methods are primarily designed for scenarios with a single individual in the image and exhibit homogenous race or gender when multiple individuals are involved, harming the diversity of social groups within the image. To address this problem, we consider the semantic consistency between text prompts and generated images in text-to-image diffusion models to identify how biases are generated. We propose a novel method to locate where the biases are based on different tokens and then mitigate them for each individual. Specifically, we introduce a Linguistic-aligned Attention Guidance module consisting of Block Voting and Linguistic Alignment, to effectively locate the semantic regions related to biases. Additionally, we employ Fair Inference in these regions to generate fair attributes across arbitrary distributions while preserving the original structural and semantic information. Extensive experiments and analyses demonstrate our method outperforms existing methods for debiasing with multiple individuals across various scenarios. Yueming Lyu, Ziwen He, Bo Peng 0002, Jing Dong 0003 |
ACM Multimedia | 3 |
| 2024 | SCGM: Asymmetric Steganographic Embedding Cost Learning With Adaptive ModulationabstractRecently, the asymmetric cost-based steganographic method using generative adversarial networks has achieved significant success. This highlights the substantial potential of deep learning-based asymmetric cost generation methods over traditional methods reliant on cost enhancement. However, the current frameworks for asymmetric cost learning ignore the correlation between positive and negative embedding costs, resulting in an imbalance asymmetric embedding costs. This can cause scattered modified pixels or even anomalous modified pixels in the stego image, thereby reducing steganographic security. In this paper, we propose a novel asymmetric steganographic cost learning framework, termed Steganographic embedding Cost Generation and Modulation (SCGM), to ensure a balance between asymmetric embedding costs by maintaining the correlation and therefore improve steganographic security. In our framework, we initially train a policy network to produce symmetric costs and subsequently use an adaptive modulation module we designed to achieve asymmetry. The modulation module facilitates the adaptive transformation of learned symmetric costs into asymmetric costs by autonomously learning modulation proportions during adversarial training with steganalysis. Moreover, we develop distinct adversarial loss functions for both the symmetric cost generation and the asymmetric cost modulation phases to further enhance steganographic security. Extensive experimental results have demonstrated that SCGM attains state-of-the-art performance in steganographic security, with an average error rate across steganalyzers that exceeds the existing best asymmetric cost-based steganography method by 2.77%. Xingjie Dai, Ziwen He, Xiang Zhang 0023, Zhangjie Fu 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 2 |
| 2023 | 3D-Aware Adversarial Makeup Generation for Facial Privacy ProtectionabstractThe privacy and security of face data on social media are facing unprecedented challenges as it is vulnerable to unauthorized access and identification. A common practice for solving this problem is to modify the original data so that it could be protected from being recognized by malicious face recognition (FR) systems. However, such "adversarial examples" obtained by existing methods usually suffer from low transferability and poor image quality, which severely limits the application of these methods in real-world scenarios. In this paper, we propose a 3D-Aware Adversarial Makeup Generation GAN (3DAM-GAN). which aims to improve the quality and transferability of synthetic makeup for identity information concealing. Specifically, a UV-based generator consisting of a novel Makeup Adjustment Module (MAM) and Makeup Transfer Module (MTM) is designed to render realistic and robust makeup with the aid of symmetric characteristics of human faces. Moreover, a makeup attack mechanism with an ensemble training strategy is proposed to boost the transferability of black-box models. Extensive experiment results on several benchmark datasets demonstrate that 3DAM-GAN could effectively protect faces against various FR models, including both publicly available state-of-the-art models and commercial face verification APIs, such as Face++, Baidu, and Aliyun. Yueming Lyu, Ziwen He, Bo Peng 0002, Yunfan Liu 0001, Jing Dong 0003 |
IEEE Trans. Pattern Anal. Mach. Intell. | 3 |
| 2023 | Temporal sparse adversarial attack on sequence-based gait recognition
Ziwen He, Wei Wang 0025, Jing Dong 0003, Tieniu Tan |
Pattern Recognit. | 1 |
| 2022 | Defending Against Deepfakes with Ensemble Adversarial PerturbationabstractMaliciously manipulated images and videos, represented by prevalent deepfakes, can easily deceive human and mislead the public opinions. A great deal of effort was spent on detecting these fake images or videos. However, these detection methods always encounter various problems in practical applications. Do we have other ways to block the spread of fake image or videos? This motivates us to focus on an emerging interesting topic, disruption of deepfake generation. We propose the ensemble attacks of various types of deepfake models including facial attribute editing, face swapping and face reenactment models. With the help of hard model mining, we boost the attack success rate significantly comparing with the straightforward average ensemble. Extensive experiments demonstrate the proposed approach can successfully disrupt multiple deepfake models simultaneously under white-box or gray-box attack protocols. Weinan Guan, Ziwen He, Wei Wang 0025, Jing Dong 0003, Bo Peng 0002 |
ICPR | 2 |
| 2022 | Defeating DeepFakes via Adversarial Visual ReconstructionabstractExisting DeepFake detection methods focus on passive detection, i.e., they detect fake face images by exploiting the artifacts produced during DeepFake manipulation. These detection-based methods have their limitation that they only work for ex-post forensics but cannot erase the negative influences of DeepFakes. In this work, we propose a proactive framework for combating DeepFake before the data manipulations. The key idea is to find a well defined substitute latent representation to reconstruct target facial data, leading the reconstructed face to disable the DeepFake generation. To this end, we invert face images into latent codes with a well trained auto-encoder, and search the adversarial face embeddings in their neighbor with the gradient descent method. Extensive experiments on three typical DeepFake manipulation methods, facial attribute editing, face expression manipulation, and face swapping, have demonstrated the effectiveness of our method in different settings. Ziwen He, Wei Wang 0025, Weinan Guan, Jing Dong 0003, Tieniu Tan |
ACM Multimedia | 1 |
| 2022 | Revisiting ensemble adversarial attack
Ziwen He, Wei Wang 0025, Jing Dong 0003, Tieniu Tan |
Signal Process. Image Commun. | 1 |