VLDB 2026 Research / reviewers in the wild / expert
Yexin Duan
dblp:270/0390
· DBLP profile ↗
13ranked-venue papers
4as first author
13since 2021 · last 2024
0000-0003-0769-4773ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 2 first-author · 5 since 2021Security and privacy · 5 · 2 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | MalPatch: Evading DNN-Based Malware Detection With Adversarial PatchesabstractStatic analysis is a crucial protection layer that enables modern antivirus systems to address the rampant proliferation of malware. These systems are increasingly relying on deep neural networks (DNNs) to automatically extract reliable features and achieve outstanding detection accuracy. Since DNNs are known to be vulnerable to adversarial examples, several studies have proposed practical evasion attacks to generate adversarial perturbations that can evade malware detectors. These attacks, however, require specific designs for the given input sample, prohibiting them from large-scale deployment. Therefore, it is more practical to generate sample-agnostic perturbations that do not involve recalculations regardless of the input malware sample. To this end, we leverage an adversarial patch attack, which is a special type of adversarial attack that dose not know the sample being modified during the attack construction process. In particular, we propose a new adversarial attack against malware detection systems called MalPatch. It locates the nonfunctional part of malware for adversarial patch injection to protect its executability while generating adversarial examples based on different strategies. The generated patch can be injected into any malware sample, fooling the detector into classifying it as benign. Experimental results demonstrate that MalPatch is effective under different attack settings. In the white-box setting, MalPatch achieves 69%-78% success rates against DNN detectors based on raw byte features and 47%-96% success rates against four grayscale detectors based on image features. In the black-box setting, the success rates of MalPatch against the same models reach 54%-74% and 27%-42%, respectively. We conclude by discussing several of its potential countermeasures and the generality of our approach. Dazhi Zhan, Yexin Duan, Yue Hu 0016, Shize Guo, Zhisong Pan 0003 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | AMGmal: Adaptive mask-guided adversarial attack against malware detection with minimal perturbation
Dazhi Zhan, Yexin Duan, Yue Hu 0016, Lujia Yin, Zhisong Pan 0003, Shize Guo |
Comput. Secur. | 2 |
| 2022 | Making Adversarial Examples More Transferable and IndistinguishableabstractFast gradient sign attack series are popular methods that are used to generate adversarial examples. However, most of the approaches based on fast gradient sign attack series cannot balance the indistinguishability and transferability due to the limitations of the basic sign structure. To address this problem, we propose a method, called Adam Iterative Fast Gradient Tanh Method (AI-FGTM), to generate indistinguishable adversarial examples with high transferability. Besides, smaller kernels and dynamic step size are also applied to generate adversarial examples for further increasing the attack success rates. Extensive experiments on an ImageNet-compatible dataset show that our method generates more indistinguishable adversarial examples and achieves higher attack success rates without extra running time and resource. Our best transfer-based attack NI-TI-DI-AITM can fool six classic defense models with an average success rate of 89.3% and three advanced defense models with an average success rate of 82.7%, which are higher than the state-of-the-art gradient-based attacks. Additionally, our method can also reduce nearly 20% mean perturbation. We expect that our method will serve as a new baseline for generating adversarial examples with better transferability and indistinguishability. Junhua Zou, Yexin Duan, Boyu Li 0005 |
AAAI | 2 |
| 2022 | Learning Coated Adversarial Camouflages for Object DetectorsabstractAn adversary can fool deep neural network object detectors by generating adversarial noises. Most of the existing works focus on learning local visible noises in an adversarial "patch" fashion. However, the 2D patch attached to a 3D object tends to suffer from an inevitable reduction in attack performance as the viewpoint changes. To remedy this issue, this work proposes the Coated Adversarial Camouflage (CAC) to attack the detectors in arbitrary viewpoints. Unlike the patch trained in the 2D space, our camouflage generated by a conceptually different training framework consists of 3D rendering and dense proposals attack. Specifically, we make the camouflage perform 3D spatial transformations according to the pose changes of the object. Based on the multi-view rendering results, the top-n proposals of the region proposal network are fixed, and all the classifications in the fixed dense proposals are attacked simultaneously to output errors. In addition, we build a virtual 3D scene to fairly and reproducibly evaluate different attacks. Extensive experiments demonstrate the superiority of CAC over the existing attacks, and it shows impressive performance both in the virtual scene and the real world. This poses a potential threat to the security-critical computer vision systems. Yexin Duan, Xingyu Zhou 0002, Junhua Zou, Zhengyun He, Jin Zhang 0024, Zhisong Pan 0003 |
IJCAI | 1 |
| 2022 | Adversarial attack via dual-stage network erosion
Yexin Duan, Junhua Zou, Xingyu Zhou 0002, Zhengyun He, Dazhi Zhan, Jin Zhang 0024, Zhisong Pan 0003 |
Comput. Secur. | 1 |
| 2022 | Boosting adversarial attacks with transformed gradient
Zhengyun He, Yexin Duan, Junhua Zou, Zhengfang He |
Comput. Secur. | 2 |
| 2022 | Enhancing transferability of adversarial examples via rotation-invariant attacksabstractAbstract Deep neural networks are vulnerable to adversarial examples. However, existing attacks exhibit relatively low efficacy in generating transferable adversarial examples. Improved transferability to address this issue is proposed via a rotation‐invariant attack method that maximizes the loss function w.r.t the random rotated image instead of the original input at each iteration, thus mitigating the high correlation between the adversarial examples and the source models and making the adversarial examples more transferable. Extensive experiments show that the proposed method can significantly improve the transferability of the adversarial examples with almost no extra computational cost and can be integrated into various methods. In addition, when this method is easily applied through a plug‐in, the average attack success rate against six robustly trained models increases by 5.4% over the state‐of‐the‐art baseline method, demonstrating its effectiveness and efficiency. The codes used are publicly available at https://github.com/YeXinD/Rotation‐Invariant‐Attack . Yexin Duan, Junhua Zou, Xingyu Zhou 0002, Jin Zhang 0024, Zhisong Pan 0003 |
IET Comput. Vis. | 1 |
| 2022 | Understanding Universal Adversarial Attack and Defense on GraphabstractCompared with traditional machine learning model, graph neural networks (GNNs) have distinct advantages in processing unstructured data. However, the vulnerability of GNNs cannot be ignored. Graph universal adversarial attack is a special type of attack on graph which can attack any targeted victim by flipping edges connected to anchor nodes. In this paper, we propose the forward-derivative-based graph universal adversarial attack (FDGUA). Firstly, we point out that one node as training data is sufficient to generate an effective continuous attack vector. Then we discretize the continuous attack vector based on forward derivative. FDGUA can achieve impressive attack performance that three anchor nodes can result in attack success rate higher than 80% for the dataset Cora. Moreover, we propose the first graph universal adversarial training (GUAT) to defend against universal adversarial attack. Experiments show that GUAT can effectively improve the robustness of the GNNs without degrading the accuracy of the model. Guyu Hu, Yexin Duan |
Int. J. Semantic Web Inf. Syst. | 4 |
| 2021 | Learning Indistinguishable and Transferable Adversarial Examples
Junhua Zou, Yexin Duan, Xingyu Zhou 0002, Zhisong Pan 0003 |
PRCV (4) | 3 |
| 2021 | Mask-guided noise restriction adversarial attacks for image classification
Yexin Duan, Xingyu Zhou 0002, Junhua Zou, Junyang Qiu, Jin Zhang 0024, Zhisong Pan 0003 |
Comput. Secur. | 1 |
| 2021 | A fast X-shaped foreground segmentation network with CompactASPP
Jin Zhang 0024, Shuaihui Wang, Junyang Qiu, Xinran Pan, Junhua Zou, Yexin Duan, Zhisong Pan 0003, Yang Li 0015 |
Eng. Appl. Artif. Intell. | 6 |
| 2021 | A data independent approach to generate adversarial patches
Xingyu Zhou 0002, Zhisong Pan 0003, Yexin Duan, Jin Zhang 0024, Shuaihui Wang |
Mach. Vis. Appl. | 3 |
| 2021 | Meta-Knowledge Learning and Domain Adaptation for Unseen Background SubtractionabstractBackground subtraction is a classic video processing task pervading in numerous visual applications such as video surveillance and traffic monitoring. Given the diversity and variability of real application scenes, an ideal background subtraction model should be robust to various scenarios. Even though deep-learning approaches have demonstrated unprecedented improvements, they often fail to generalize to unseen scenarios, thereby less suitable for extensive deployment. In this work, we propose to tackle cross-scene background subtraction via a two-phase framework that includes meta-knowledge learning and domain adaptation. Specifically, as we observe that meta-knowledge (i.e., scene-independent common knowledge) is the cornerstone for generalizing to unseen scenes, we draw on traditional frame differencing algorithms and design a deep difference network (DDN) to encode meta-knowledge especially temporal change knowledge from various cross-scene data (source domain) without intermittent foreground motion pattern. In addition, we explore a self-training domain adaptation strategy based on iterative evolution. With iteratively updated pseudo-labels, the DDN is continuously fine-tuned and evolves progressively toward unseen scenes (target domain) in an unsupervised fashion. Our framework could be easily deployed on unseen scenes without relying on their annotations. As evidenced by our experiments on the CDnet2014 dataset, it brings a significant improvement to background subtraction. Our method has a favorable processing speed (70 fps) and outperforms the best unsupervised algorithm and top supervised algorithm designed for unseen scenes by 9% and 3%, respectively. Jin Zhang 0024, Yanyan Zhang 0009, Yexin Duan, Yang Li 0015, Zhisong Pan 0003 |
IEEE Trans. Image Process. | 4 |