Sanshuai Cui

dblp:272/6453 · DBLP profile ↗
← Back
7ranked-venue papers
2as first author
6since 2021 · last 2025
0000-0002-4709-5786ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 7 · 2 first-author · 6 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Everywhere Attack: Attacking Locally and Globally to Boost Targeted Transferability
abstract
Adversarial examples’ (AE) transferability refers to the phenomenon that AEs crafted with one surrogate model can also fool other models. Notwithstanding remarkable progress in untargeted transferability, its targeted counterpart remains challenging. This paper proposes an everywhere scheme to boost targeted transferability. Our idea is to attack a victim image both globally and locally. We aim to optimize ‘an army of targets’ in every local image region instead of the previous works that optimize a high-confidence target in the image. Specifically, we split a victim image into non-overlap blocks and jointly mount a targeted attack on each block. Such a strategy mitigates transfer failures caused by attention inconsistency between surrogate and victim models and thus results in stronger transferability. Our approach is method-agnostic, which means it can be easily combined with existing transferable attacks for even higher transferability. Extensive experiments on ImageNet demonstrate that the proposed approach universally improves the state-of-the-art targeted attacks by a clear margin, e.g., the transferability of the widely adopted Logit attack can be improved by 28.8%-300%. We also evaluate the crafted AEs on a real-world platform: Google Cloud Vision. Results further support the superiority of the proposed method.
Hui Zeng 0002, Sanshuai Cui, Biwei Chen, Anjie Peng
AAAI2
2025 Two Heads Are Better Than One: Averaging along Fine-Tuning to Improve Targeted Transferability
abstract
With much longer optimization time than that of untargeted attacks notwithstanding, the transferability of targeted attacks is still far from satisfactory. Recent studies reveal that fine-tuning an existing adversarial example (AE) in feature space can efficiently boost its targeted transferability. However, existing fine-tuning schemes only utilize the endpoint and ignore the valuable information in the fine-tuning trajectory. Noting that the vanilla fine-tuning trajectory tends to oscillate around the periphery of a flat region of the loss surface, we propose averaging over the fine-tuning trajectory to pull the crafted AE towards a more centered region. We compare the proposed method with existing fine-tuning schemes by integrating them with state-of-the-art targeted attacks in various attacking scenarios. Experimental results uphold the superiority of the proposed method in boosting targeted transferability. The code is available at github.com/zengh5/Avg_FT.
Hui Zeng 0002, Sanshuai Cui, Biwei Chen, Anjie Peng
ICASSP2
2025 Boosting Adversarial Transferability by Constructing Adversarial Trajectories
abstract
Deep neural networks (DNNs) are susceptible to adversarial examples (AEs), which are crafted by adding human-imperceptible perturbations to benign images. Although many existing adversarial attacks have achieved great surrogate, white-box model attack performance, they exhibit low transferability. In this work, we emphasize that existing input transformation-based attacks, which linearly mix the input image with images from other categories, induce significant semantic shifts and lack sufficient input diversity, leading to inaccurate update directions. To overcome the pitfall, we propose a new attack method for constructing multiple adversarial trajectories (MAT). Specifically, MAT achieves the intent of the mixing strategy by introducing targeted perturbations instead of relying on input transformation to obtain multiple data points that are closer to the decision boundary for gradient computation. Comprehensive experiments demonstrate our method’s effectiveness. We also show that MAT is highly flexible and can seamlessly integrate with existing transfer methods. Code is available at: github.com/britney-code/MAT-Attack.
Sanshuai Cui, Anjie Peng, Hui Zeng 0002, Rong Wei
ICME2
2023 Transferable Waveform-level Adversarial Attack against Speech Anti-spoofing Models
abstract
Speech anti-spoofing models protect media from malicious fake speech but are vulnerable to adversarial attacks. Studies of adversarial attacks are conducive to developing robust speech anti-spoofing systems. Existing transfer-based attack methods mainly craft adversarial speech examples at the handcrafted-feature level, which have limited attack ability against the real-world anti-spoofing systems, as these systems only have raw waveform input interfaces. In this work, we propose a waveform-level input data transformation, called the temporal smoothing method, to generate more transferable adversarial speech examples. In the optimization iterations of the adversarial perturbation, we randomly smooth input waveforms to prevent the adversarial examples from overfitting white-box surrogate models. The proposed transformation can be combined with any iterative gradient-based attack method. Extensive experiments demonstrate that our method significantly enhances the transferability of waveform-level adversarial speech examples.
Bingyuan Huang, Sanshuai Cui, Xiangui Kang, Enping Li
ICME2
2023 Discriminative Frequency Information Learning for End-to-End Speech Anti-Spoofing
abstract
End-to-end technology is an active research topic in speech anti-spoofing. Although end-to-end methods have achieved remarkable success in the speech anti-spoofing, channel effects brought by telephony transmission and certain challenging forms of spoofing attacks still plague them. We observe that differences in the high-frequency components between bonafide and spoofed speech help detect some most troublesome attack forms and the differences also remain after the signals are affected by transmission and codecs. Based on this observation, we aim to utilize the high-frequency information of speech signals to develop better generalization ability to unknown attacks and stronger robustness against transmission and codecs. We propose a raw waveform processing module based on sinc convolution and multiple pre-emphasis to obtain discriminative shallow feature representations. Additionally, we propose an improved backbone to learn discriminative feature embeddings, and a feature classification loss to optimize intra-class and inter-class distances simultaneously. The above modules constitute the proposed Discriminative Frequency-information SincNet, namely DFSincNet. Our proposed algorithm demonstrates competitive performance on both ASVspoof 2019 and 2021 logical access (LA) scenarios.
Bingyuan Huang, Sanshuai Cui, Jiwu Huang, Xiangui Kang
IEEE Signal Process. Lett.2
2022 Synthetic Speech Detection Based on Local Autoregression and Variance Statistics
Sanshuai Cui, Bingyuan Huang, Jiwu Huang, Xiangui Kang
IEEE Signal Process. Lett.1
2020 Autoregressive Model Based Smoothing Forensics Of Very Short Speech Clips
abstract
Smoothing is a post-processing widely used in speech tampering. Thus, we may determine whether a speech signal is original by smoothing forensics. However, in existing smoothing forensics methods, the detection performance of very short speech clips is much worse than that of long speech clips, and MP3 compression may lead to performance degradation, especially when the length of the smoothing window becomes small. Based on the observation that a very short speech clips can be considered as a stationary autoregressive (AR) process model, we proposed a robust smoothing forensics method of very short speech clips using the AR model coefficients. Experimental results on the TIMIT speech dataset demonstrate that the proposed method significantly outperforms the state-of-the-art method in terms of accuracy and robustness against various MP3 compression.
Sanshuai Cui, Enlei Li, Xiangui Kang
ICME1