VLDB 2026 Research / reviewers in the wild / expert
Zhongliang Guo 0001
dblp:260/0858-1
· DBLP profile ↗
16ranked-venue papers
4as first author
16since 2021 · last 2027
0000-0002-6025-3021ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 12 · 3 first-author · 12 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 1 first-author · 5 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | Rethinking 3D point cloud adversarial attacks from models' inherent focus
Xiaowen Cai 0001, Shuqin Chen, Junhao Dong 0001, Keke Tang, Zhongliang Guo 0001, Daizong Liu |
Expert Syst. Appl. | 6 |
| 2026 | GaitProtector: Impersonation-Driven Gait De-Identification via Training-Free Diffusion Latent Optimization
Huiran Duan, Qian Zhou 0001, Zhongliang Guo 0001, Junhao Dong 0001, Guoying Zhao 0001, Yingli Tian |
FG | 3 |
| 2026 | Attacking hard-label large vision-language models with model-sensitive adversarial patch designs
Nian Ai, Guangke Chen, Xiaowen Cai 0001, Zhongliang Guo 0001, Daizong Liu, Pan Zhou 0001, Ognjen Arandjelovic |
Pattern Recognit. | 4 |
| 2026 | Artwork protection against unauthorized neural style transfer and aesthetic color distance metric
Zhongliang Guo 0001, Yifei Qian, Shuai Zhao 0007, Junhao Dong 0001, Ognjen Arandjelovic, Lei Fang 0001, Chun Pong Lau 0001 |
Pattern Recognit. | 1 |
| 2026 | Backdoor defense for large language models with weak-to-strong knowledge distillation
Zhongliang Guo 0001, Luwei Xiao, Yanhao Jia, Shuai Zhao 0007 |
Pattern Recognit. | 3 |
| 2026 | DiffProtect: Generative adversarial examples using diffusion models for facial privacy protectionabstractThe increasingly pervasive facial recognition (FR) systems raise serious concerns about personal privacy, especially for billions of users who have publicly shared their photos on social media. To address this challenge, several adversarial attack methods have been proposed to protect individuals from being identified by unauthorized FR systems with perturbed facial images. However, these approaches suffer from poor visual quality or low attack success rates, which limit their practical utility. Recently, diffusion models have achieved tremendous success in image generation. In this work, we ask: can diffusion models be used to generate adversarial examples against FR systems to improve both visual quality and attack performance? We propose DiffProtect, a novel method leveraging a diffusion autoencoder to generate semantically meaningful perturbations on FR systems. Extensive experiments demonstrate that DiffProtect produces more natural-looking encrypted images than state-of-the-art methods while achieving significantly higher attack success rates, e.g. , 24.5 % and 25.1 % absolute improvements on the CelebA-HQ and FFHQ datasets. We further evaluate the effectiveness of DiffProtect in the real world using a commercial FR API and validate its usefulness in practice through a user study. Our code is available at https://github.com/joellliu/DiffProtect . Jiang Liu 0014, Chun Pong Lau 0001, Zhongliang Guo 0001, Yuxiang Guo 0001, Zhao-Yang Wang, Rama Chellappa |
Pattern Recognit. | 3 |
| 2026 | Protecting Your Customized LLM Systems From Backdoored Instructions With Metacognitive Probing
Shuai Zhao 0007, Zhongliang Guo 0001, Xiaobao Wu, Yanhao Jia, Luwei Xiao, Anh Tuan Luu |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Instant Adversarial Purification with Adversarial Consistency DistillationabstractNeural networks have revolutionized numerous fields with their exceptional performance, yet they remain susceptible to adversarial attacks through subtle perturbations. While diffusion-based purification methods like DiffPure offer promising defense mechanisms, their computational overhead presents a significant practical limitation. In this paper, we introduce One Step Control Purification (OSCP), a novel defense framework that achieves robust adversarial purification in a single Neural Function Evaluation (NFE) within diffusion models. We propose Gaussian Adversarial Noise Distillation (GAND) as the distillation objective and Controlled Adversarial Purification (CAP) as the inference pipeline, which makes OSCP demonstrate remarkable effi-ciency while maintaining defense efficacy. Our proposed GAND addresses a fundamental tension between consistency distillation and adversarial perturbation, bridging the gap between natural and adversarial manifolds in the latent space, while remaining computationally efficient through Parameter-Efficient Fine-Tuning (PEFT) methods such as LoRA, eliminating the high computational budget request from full parameter fine-tuning. The CAP guides the purifi-cation process through the unlearnable edge detection operator calculated by the input image as an extra prompt, effectively preventing the purified images from deviating from their original appearance when large purification steps are used. Our experimental results on ImageNet showcase OSCP’s superior performance, achieving a 74.19% defense success rate with merely 0.1s per purification — a 100-fold speedup compared to conventional approaches. Chun Tong Lei, Hon Ming Yam, Zhongliang Guo 0001, Yifei Qian, Chun Pong Lau 0001 |
CVPR | 3 |
| 2025 | T2ICount: Enhancing Cross-modal Understanding for Zero-Shot CountingabstractZero-Shot object counting aims to count instances of arbitrary object categories specified by text descriptions. Existing methods typically rely on vision-language models like CLIP, but often exhibit limited sensitivity to text prompts. We present T21 Count, a diffusion-based framework that lever-ages rich prior knowledge and fine-grained visual understanding from pretrained diffusion models. While one-step demising ensures efficiency, it leads to weakened text sensitivity. To address this challenge, we propose a Hierarchical Semantic Correction Module that progressively refines text-image feature alignment, and a Representational Regional Coherence Loss that provides reliable supervision signals by leveraging the cross-attention maps extracted from the demising U-Net. Furthermore, we observe that current benchmarks mainly focus on majority objects in images, potentially masking models' text sensitivity. To address this, we contribute a challenging re-annotated subset of FSC147 for better evaluation of text-guided counting ability. Extensive experiments demonstrate that our method achieves superior performance across different benchmarks. Code is available at https://github.com/chal5yq/T2lCount. Yifei Qian, Zhongliang Guo 0001, Bowen Deng 0006, Chun Tong Lei, Shuai Zhao 0007, Chun Pong Lau 0001, Xiaopeng Hong, Michael P. Pound |
CVPR | 2 |
| 2025 | Achieving fair medical image segmentation in foundation models with adversarial visual prompt tuning
Kai Zhang 0029, Fuyan Zhang, Chuanguang Yang, Zhongliang Guo 0001, Weiping Ding 0001, Tingwen Huang |
Inf. Sci. | 6 |
| 2025 | Perspective-assisted prototype-based learning for semi-supervised crowd counting
Yifei Qian, Liangfei Zhang, Zhongliang Guo 0001, Xiaopeng Hong, Ognjen Arandjelovic, Carl Donovan |
Pattern Recognit. | 3 |
| 2025 | A Gray-Box Attack Against Latent Diffusion Model-Based Image Editing by Posterior CollapseabstractRecent advancements in Latent Diffusion Models (LDMs) have revolutionized image synthesis and manipulation, raising significant concerns about data misappropriation and intellectual property infringement. While adversarial attacks have been extensively explored as a protective measure against such misuse of generative AI, current approaches are severely limited by their heavy reliance on model-specific knowledge and substantial computational costs. Drawing inspiration from the posterior collapse phenomenon observed in VAE training, we propose the Posterior Collapse Attack (PCA), a novel framework for protecting images from unauthorized manipulation. Through comprehensive theoretical analysis and empirical validation, we identify two distinct collapse phenomena during VAE inference: diffusion collapse and concentration collapse. Based on this discovery, we design a unified loss function that can flexibly achieve both types of collapse through parameter adjustment, each corresponding to different protection objectives in preventing image manipulation. Our method significantly reduces dependence on model-specific knowledge by requiring access to only the VAE encoder, which constitutes less than 4% of LDM parameters. Notably, PCA achieves prompt-invariant protection by operating on the VAE encoder before text conditioning occurs, eliminating the need for empty prompt optimization required by existing methods. This minimal requirement enables PCA to maintain adequate transferability across various VAE-based LDM architectures while effectively preventing unauthorized image editing. Extensive experiments show PCA outperforms existing techniques in protection effectiveness, computational efficiency (runtime and VRAM), and generalization across VAE-based LDM variants. Our code is available at https://github.com/ZhongliangGuo/PosteriorCollapseAttack. Zhongliang Guo 0001, Chun Tong Lei, Lei Fang 0001, Shuai Zhao 0007, Yifei Qian, Zeyu Wang 0010, Cunjian Chen, Ognjen Arandjelovic, Chun Pong Lau 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Threats and Defenses in the Federated Learning Life Cycle: A Comprehensive Survey and ChallengesabstractFederated learning (FL) offers innovative solutions for privacy-preserving distributed machine learning (ML). Different from centralized data collection algorithms, FL enables participants to locally train their model and only share the model updates for aggregation. Since private data never leaves the end node, FL effectively mitigates privacy leakage during collaborative training. Despite its promising potential, FL is vulnerable to various attacks due to its distributed nature, affecting the entire life cycle of FL services. These threats can harm the model's utility or compromise participants' privacy, either directly or indirectly. In response, numerous defense frameworks have been proposed, demonstrating effectiveness in specific settings and scenarios. To provide a clear understanding of the current research landscape, this article reviews the most representative and state-of-the-art threats and defense frameworks throughout the FL service life cycle. We start by identifying FL threats that harm utility and privacy, including those with potential or direct impacts. Then, we dive into the defense frameworks, analyze the relationship between threats and defenses, and compare the trade-offs among different defense strategies. We subsequently revisit these studies to evaluate their practicality in real-world scenarios and conclude by summarizing existing research bottlenecks and outlining future directions. We hope this survey sheds light on trustworthy FL research and contributes to the FL community. Zhongliang Guo 0001, Huaming Chen, Dong Yuan 0001, Weiping Ding 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 2 |
| 2024 | A White-Box False Positive Adversarial Attack Method on Contrastive Loss Based Offline Handwritten Signature Verification ModelsabstractIn this paper, we tackle the challenge of white-box false positive adversarial attacks on contrastive loss based offline handwritten signature verification models. We propose a novel attack method that treats the attack as a style transfer between closely related but distinct writing styles. To guide the generation of deceptive images, we introduce two new loss functions that enhance the attack success rate by perturbing the Euclidean distance between the embedding vectors of the original and synthesized samples, while ensuring minimal perturbations by reducing the difference between the generated image and the original image. Our method demonstrates state-of-the-art performance in white-box attacks on contrastive loss based offline handwritten signature verification models, as evidenced by our experiments. The key contributions of this paper include a novel false positive attack method, two new loss functions, effective style transfer in handwriting styles, and superior performance in white-box false positive attacks compared to other white-box attack methods. Zhongliang Guo 0001, Yifei Qian, Ognjen Arandjelovic, Lei Fang 0001 |
AISTATS | 1 |
| 2024 | Artwork Protection Against Neural Style Transfer Using Locally Adaptive Adversarial Color AttackabstractNeural style transfer (NST) generates new images by combining the style of one image with the content of another. However, unauthorized NST can exploit artwork, raising concerns about artists’ rights and motivating the development of proactive protection methods. We propose Locally Adaptive Adversarial Color Attack (LAACA), empowering artists to protect their artwork from unauthorized style transfer by processing before public release. By delving into the intricacies of human visual perception and the role of different frequency components, our method strategically introduces frequency-adaptive perturbations in the image. These perturbations significantly degrade the generation quality of NST while maintaining an acceptable level of visual change in the original image, ensuring that potential infringers are discouraged from using the protected artworks, because of its bad NST generation quality. Additionally, existing metrics often overlook the importance of color fidelity in evaluating color-mattered tasks, such as the quality of NST-generated images, which is crucial in the context of artistic works. To comprehensively assess the color-mattered tasks, we propose the Aesthetic Color Distance Metric (ACDM), designed to quantify the color difference of images pre- and post-manipulations. Experimental results confirm that attacking NST using LAACA results in visually inferior style transfer, and the ACDM can efficiently measure color-mattered tasks. By providing artists with a tool to safeguard their intellectual property, our work relieves the socio-technical challenges posed by the misuse of NST in the art community. Zhongliang Guo 0001, Junhao Dong 0001, Yifei Qian, Ziheng Guo, Ognjen Arandjelovic, Lei Fang 0001 |
ECAI | 1 |
| 2024 | Semi-Supervised Crowd Counting With Contextual Modeling: Facilitating Holistic Understanding of Crowd ScenesabstractTo alleviate the heavy annotation burden for training a reliable crowd counting model and thus make the model more practicable and accurate by being able to benefit from more data, this paper presents a new semi-supervised method based on the mean teacher framework. When there is a scarcity of labeled data available, the model is prone to overfit local patches. Within such contexts, the conventional approach of solely improving the accuracy of local patch predictions through unlabeled data proves inadequate. Consequently, we propose a more nuanced approach: fostering the model’s intrinsic ‘subitizing’ capability. This ability allows the model to accurately estimate the count in regions by leveraging its understanding of the crowd scenes, mirroring the human cognitive process. To achieve this goal, we apply masking on unlabeled data, guiding the model to make predictions for these masked patches based on the holistic cues. Furthermore, to help with feature learning, herein we incorporate a fine-grained density classification task. Our method is general and applicable to most existing crowd counting methods as it doesn’t have strict structural or loss constraints. In addition, we observe that the model trained with our framework shows strong contextual modeling capabilities, which allows it to make robust predictions even when some local details of patches are lost. Our method achieves the state-of-the-art performance, surpassing previous approaches by a large margin on challenging benchmarks such as ShanghaiTech A and UCF-QNRF. The code is available at: https://github.com/cha15yq/MRC-Crowd. Yifei Qian, Xiaopeng Hong, Zhongliang Guo 0001, Ognjen Arandjelovic, Carl Donovan |
IEEE Trans. Circuits Syst. Video Technol. | 3 |