Hangcheng Liu

dblp:277/7585 · DBLP profile ↗
← Back
19ranked-venue papers
3as first author
18since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 7 · 6 since 2021Artificial intelligence and machine learning · 5 · 1 first-author · 5 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 3 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021
YearPublicationVenuePosition
2026 ShadeEdit: A Utility-Preserving and Defense-Evasive Knowledge Manipulation Attack in Federated LLMs
abstract
Recent studies reveal that adversaries can manipulate the internal knowledge of large language models (LLMs) on selected topics through model editing, causing attacker-specified harmful or biased outputs when queried about the edited content. Once such tampered LLMs are distributed, they can mislead users on the targeted topics, thereby potentially propagating misinformation or reinforcing stereotypes. However, existing knowledge manipulation attacks rely on the ability to redistribute compromised models, which is infeasible in constrained settings like Federated Instruction Tuning (FedIT), where a central server controls LLM's training and distribution. In this work, we introduce ShadeEdit, the first attack framework that leverages strengthened model editing to enable knowledge manipulation in FedIT scenarios. ShadeEdit introduces two key components to address two challenges posed by the training process of FedIT: (1) a paraphrase-based editing dataset selection strategy to mitigate the dilution from benign updates on malicious ones by constructing a high-quality editing dataset, and (2) an adaptive manipulation mechanism to evade aggregation-based defenses via an adaptive clipping strategy. ShadeEdit achieves an average 99.5% attack success rate over eight robust aggregation algorithms while preserving instruction-following accuracy, demonstrating its strong attack effectiveness and model-utility preservation.
Hangcheng Liu, Shangwei Guo, Shudong Zhang, Tianwei Zhang 0004, Tao Xiang 0001
AAAI2
2025 FusionDisassembler: A Cross-Device Approach for Effective Instruction Disassembly in Side-Channel Attacks
abstract
Modern embedded systems are increasingly vulnerable to side-channel threats, which may non-invasively leak sensitive information about their internal operations. While prior studies have validated the feasibility of instruction reverse engineering via side-channel analysis, their effectiveness has primarily been demonstrated under ideal, device-controlled settings. In practical adversarial scenarios, heterogeneity in manufacturing processes and hardware components across devices introduces significant variations in side-channel signals, which impedes effective pattern recognition and limits the scalability of crossdevice attacks. This paper presents FusionDisassembler, a robust and generalizable instruction disassembly framework for cross-device side-channel analysis. FusionDisassembler captures power traces during program execution and identifies the corresponding assembly instructions. To address device-induced signal variability, we employ information-theoretic analysis in the timefrequency domain to extract discriminative features that remain stable across hardware. Moreover, we introduce a MultiExpert Disassembly Network, comprising multiple specialized expert subnetworks trained on different feature domains, and a lightweight router that dynamically selects the most appropriate expert based on input features. This architecture enables effective learn of distribution shifts across devices and enhances generalization in real-world attack settings. We evaluate FusionDisassembler on multiple physical devices across two microarchitectures. Extensive experiments demonstrate its effectiveness, outperforming existing approaches and establishing a new practical benchmark for side-channel-based disassembly.
Ouchang Hai, Hangcheng Liu, Xingshuo Han
ICPADS4
2025 Model Supply Chain Poisoning: Backdooring Pre-trained Models via Embedding Indistinguishability
abstract
Pre-trained models (PTMs) are widely adopted across various downstream tasks in the machine learning supply chain. Adopting untrustworthy PTMs introduces significant security risks, where adversaries can poison the model supply chain by embedding hidden malicious behaviors (backdoors) into PTMs. However, existing backdoor attacks to PTMs can only achieve partially task-agnostic and the embedded backdoors are easily erased during the fine-tuning process. This makes it challenging for the backdoors to persist and propagate through the supply chain. In this paper, we propose a novel and severer backdoor attack, TransTroj, which enables the backdoors embedded in PTMs to efficiently transfer in the model supply chain. In particular, we first formalize this attack as an indistinguishability problem between poisoned and clean samples in the embedding space. We decompose embedding indistinguishability into pre- and post-indistinguishability, representing the similarity of the poisoned and reference embeddings before and after the attack. Then, we propose a two-stage optimization that separately optimizes triggers and victim PTMs to achieve embedding indistinguishability. We evaluate TransTroj on four PTMs and six downstream tasks. Experimental results show that our method significantly outperforms SOTA task-agnostic backdoor attacks -- achieving nearly 100% attack success rate on most downstream tasks -- and demonstrates robustness under various system settings. Our findings underscore the urgent need to secure the model supply chain against such transferable backdoor attacks. The code is available at https://github.com/haowang-cqu/TransTroj
Hao Wang 0227, Shangwei Guo, Jialing He, Hangcheng Liu, Tianwei Zhang 0004, Tao Xiang 0001
WWW4
2025 RiceSNP-ABST: a deep learning approach to identify abiotic stress-associated single nucleotide polymorphisms in rice
abstract
Given the adverse effects faced by rice due to abiotic stresses, the precise and rapid identification of single nucleotide polymorphisms (SNPs) associated with abiotic stress traits (ABST-SNPs) in rice is crucial for developing resistant rice varieties. The scarcity of high-quality data related to abiotic stress in rice has hindered the development of computational models and constrained research efforts aimed at rice improvement and breeding. Genome-wide association studies provide a better statistical power to consider ABST-SNPs in rice. Meanwhile, deep learning methods have shown their capability in predicting disease- or phenotype-associated loci, but have primarily focused on human species. Therefore, developing predictive models for identifying ABST-SNPs in rice is both urgent and valuable. In this paper, a model called RiceSNP-ABST is proposed for predicting ABST-SNPs in rice. Firstly, six training datasets were generated using a novel strategy for negative sample construction. Secondly, four feature encoding methods were proposed based on DNA sequence fragments, followed by feature selection. Finally, convolutional neural networks with residual connections were used to determine whether the sequences contained rice ABST-SNPs. RiceSNP-ABST outperformed traditional machine learning and state-of-the-art methods on the benchmark dataset and demonstrated consistent generalization on an independent dataset and cross-species datasets. Notably, multi-granularity causal structure learning was employed to elucidate the relationships among DNA structural features, aiming to identify key genetic variants more effectively. The web-based tool for the RiceSNP-ABST can be accessed at http://rice-snp-abst.aielab.cc.
Renyi Zhang, Hangcheng Liu, Xiaoshuang Liu
Briefings Bioinform.4
2025 Stealthiness Assessment of Adversarial Perturbation: From a Visual Perspective
abstract
Assessing the stealthiness of adversarial perturbations is challenging due to the lack of appropriate evaluation metrics. Existing evaluation metrics, e.g.,$L_{p}$norms or Image Quality Assessment (IQA), fall short of assessing the pixel-level stealthiness of subtle adversarial perturbations since these metrics are primarily designed for traditional distortions. To bridge this gap, we present the first comprehensive study on the subjective and objective assessment of the stealthiness of adversarial perturbations from a visual perspective at a pixel level. Specifically, we propose new subjective assessment criteria for human observers to score adversarial stealthiness in a fine-grained manner. Then, we create a large-scale adversarial example dataset comprising 10586 pairs of clean and adversarial samples encompassing twelve state-of-the-art adversarial attacks. To obtain the subjective scores according to the proposed criterion, we recruit 60 human observers, and each adversarial example is evaluated by at least 15 observers. The mean opinion score of each adversarial example is utilized for labeling. Finally, we develop a three-stage objective scoring model that mimics human scoring habits to predict adversarial perturbation’s stealthiness. Experimental results demonstrate that our objective model exhibits superior consistency with the human visual system, surpassing commonly employed metrics like PSNR and SSIM.
Hangcheng Liu, Yuan Zhou 0005, Ying Yang 0019, Qingchuan Zhao, Tianwei Zhang 0004, Tao Xiang 0001
IEEE Trans. Inf. Forensics Secur.1
2024 VisionGuard: Secure and Robust Visual Perception of Autonomous Vehicles in Practice
abstract
Modern Autonomous Vehicles (AVs) implement the Visual Perception Module (VPM) to perceive their surroundings. This VPM adopts various Deep Neural Network (DNN) models to process the data collected from cameras and LiDAR. Prior studies have shown that these models are vulnerable to physical adversarial examples (PAEs), which pose a critical safety risk to the autonomous driving task. While a few defense methods have been proposed to safeguard AVs, most of them only target a limited set of attack types and specific scenarios, making them impractical for real-world protection.
Xingshuo Han, Haozhao Wang, Kangqiao Zhao, Gelei Deng, Yuan Xu 0033, Hangcheng Liu, Han Qiu 0001, Tianwei Zhang 0004
CCS6
2024 Beware of Road Markings: A New Adversarial Patch Attack to Monocular Depth Estimation
abstract
Monocular Depth Estimation (MDE) enables the prediction of scene depths from a single RGB image, having been widely integrated into production-grade autonomous driving systems, e.g., Tesla Autopilot. Current adversarial attacks to MDE models focus on attaching an optimized adversarial patch to a designated obstacle. Although effective, this approach presents two inherent limitations: its reliance on specific obstacles and its limited malicious impact. In contrast, we propose a pioneering attack to MDE models that \textit{decouples obstacles from patches physically and deploys optimized patches on roads}, thereby extending the attack scope to arbitrary traffic participants. This approach is inspired by our groundbreaking discovery: \textit{various MDE models with different architectures, trained for autonomous driving, heavily rely on road regions} when predicting depths for different obstacles. Based on this discovery, we design the Adversarial Road Marking (AdvRM) attack, which camouflages patches as ordinary road markings and deploys them on roads, thereby posing a continuous threat within the environment. Experimental results from both dataset simulations and real-world scenarios demonstrate that AdvRM is effective, stealthy, and robust against various MDE models, achieving about 1.507 of Mean Relative Shift Ratio (MRSR) over 8 MDE models. The code is available at \url{https://github.com/a-c-a-c/AdvRM.git}
Hangcheng Liu, Zhenhu Wu, Hao Wang 0003, Xingshuo Han, Shangwei Guo, Tao Xiang 0001, Tianwei Zhang 0004
NeurIPS1
2023 Contrastive Fusion Representation: Mitigating Adversarial Attacks on VQA Models
abstract
Visual Question Answering (VQA) is the vision-language task of answering text-based questions presented in an image and has been advanced by the remarkable success of multimodal deep networks. Similar to unimodal networks, multimodal VQA models are also vulnerable to adversarial examples, which raises severe threats to the corresponding applications. Although several adversarial training methods have been proposed, most of them focus on improving the generalization ability of VQA models on clean samples instead of mitigating the adversarial attacks. In this paper, we systemically analyze the core structure of multimodal VQA networks and propose a novel adversarial training algorithm to mitigate adversarial attacks on VQA models. Specifically, our key component is a regularization term with our carefully designed Contrastive Fusion Representation (CFR), which can reduce the sensitivity of VQA models to adversarial perturbations of both the vision and language inputs. We further enhance the adversarial training with augmented CFRs. Comprehensive experimental results show that our method can mitigate adversarial attacks as well as preserve the generalization ability on clean samples under various system settings and outperforms other defense methods.
Jialing He, Hangcheng Liu, Shangwei Guo, Biwen Chen, Ning Wang 0003, Tao Xiang 0001
ICME3
2023 Generative adversarial networks with adaptive learning strategy for noise-to-image synthesis
Yan Gan, Tao Xiang 0001, Hangcheng Liu, Mao Ye 0001, Mingliang Zhou 0001
Neural Comput. Appl.3
2023 Erase and Repair: An Efficient Box-Free Removal Attack on High-Capacity Deep Hiding
abstract
Deep hiding, embedding images with others using deep neural networks, has demonstrated impressive efficacy in increasing the message capacity and robustness of secret sharing. In this paper, we challenge the robustness of existing deep hiding schemes by preventing the recovery of secret images, building on our in-depth study of state-of-the-art deep hiding schemes and their vulnerabilities. Leveraging our analysis, we first propose a simple box-free removal attack on deep hiding that does not require any prior knowledge of the deep hiding schemes. To improve the removal performance on the deep hiding schemes that may be enhanced by adversarial training, we further design a more powerful removal attack, efficient box-free removal attack (EBRA), which employs image inpainting techniques to remove secret images from container images. In addition, to ensure the effectiveness of our attack and preserve the fidelity of the processed container images, we design an erasing phase based on the locality of deep hiding to remove secret information and then make full use of the visual information of container images to repair the erased visual content. Extensive evaluations show our method can completely remove secret images from container images with negligible impact on the quality of container images.
Hangcheng Liu, Tao Xiang 0001, Shangwei Guo, Tianwei Zhang 0004, Xiaofeng Liao 0001
IEEE Trans. Inf. Forensics Secur.1
2023 Towards Query-Efficient Black-Box Attacks: A Universal Dual Transferability-Based Framework
abstract
Adversarial attacks have threatened the application of deep neural networks in security-sensitive scenarios. Most existing black-box attacks fool the target model by interacting with it many times and producing global perturbations. However, all pixels are not equally crucial to the target model; thus, indiscriminately treating all pixels will increase query overhead inevitably. In addition, existing black-box attacks take clean samples as start points, which also limits query efficiency. In this article, we propose a novel black-box attack framework, constructed on a strategy of dual transferability (DT), to perturb the discriminative areas of clean examples within limited queries. The first kind of transferability is the transferability of model interpretations. Based on this property, we identify the discriminative areas of clean samples for generating local perturbations. The second is the transferability of adversarial examples, which helps us to produce local pre-perturbations for further improving query efficiency. We achieve the two kinds of transferability through an independent auxiliary model and do not incur extra query overhead. After identifying discriminative areas and generating pre-perturbations, we use the pre-perturbed samples as better start points and further perturb them locally in a black-box manner to search the corresponding adversarial examples. The DT strategy is general; thus, the proposed framework can be applied to different types of black-box attacks. We conduct extensive experiments to show that, under various system settings, our framework can significantly improve the query efficiency of existing black-box attacks and attack success rates.
Tao Xiang 0001, Hangcheng Liu, Shangwei Guo, Yan Gan, Wenjian He, Xiaofeng Liao 0001
ACM Trans. Intell. Syst. Technol.2
2022 Text's Armor: Optimized Local Adversarial Perturbation Against Scene Text Editing Attacks
abstract
Deep neural networks (DNNs) have shown their powerful capability in scene text editing (STE). With carefully designed DNNs, one can alter texts in a source image with other ones while maintaining their realistic look. However, such editing tools provide a great convenience for criminals to falsify documents or modify texts without authorization. In this paper, we propose to actively defeat text editing attacks by designing invisible "armors" for texts in the scene. We turn the adversarial vulnerability of DNN-based STE into strength and design local perturbations (i.e., "armors") specifically for texts using an optimized normalization strategy. Such local perturbations can effectively mislead STE attacks without affecting the perceptibility of scene background. To strengthen our defense capabilities, we systemically analyze and model STE attacks and provide a precise defense method to defeat attacks on different editing stages. We conduct both subjective and objective experiments to show the superior of our optimized local adversarial perturbation against state-of-the-art STE attacks. We also evaluate the portrait and landscape transferability of our perturbations.
Tao Xiang 0001, Hangcheng Liu, Shangwei Guo, Hantao Liu, Tianwei Zhang 0004
ACM Multimedia2
2022 ELAA: An efficient local adversarial attack using model interpreters
abstract
Modern deep neural networks are highly vulnerable to adversarial examples, which attracts more and more researchers' attention to craft powerful adversarial examples. Most of these generation algorithms create global perturbations that would affect the visual quality of adversarial examples. To mitigate such drawbacks, some attacks attempt to generate local perturbations. However, existing local adversarial attacks are time-consuming and the generated adversarial examples are still distinguishable from clean images. In this paper, we propose a novel efficient local adversarial attack (ELAA) using model interpreters to generate severe local perturbations and improve the imperceptibly of the generated adversarial examples. Specifically, we take advantage of model interpretation methods to search the discriminative regions of clean images. Then, we generate local adversarial examples by adding masks to original clean images. We also propose a new optimization method to reduce the redundancy of local perturbations. Through extensive experiments, we show our ELAA can maintain a high attack ability while preserving the visual quality of clean images. Experimental results also demonstrate our local attack outperforms state-of-the-art local attack methods under various system settings.
Shangwei Guo, Siyuan Geng, Tao Xiang 0001, Hangcheng Liu, Ruitao Hou
Int. J. Intell. Syst.4
2022 Evolutionary neural architecture search based on evaluation correction and functional units
Ronghua Shang, Songling Zhu, Jinhong Ren, Hangcheng Liu, Licheng Jiao
Knowl. Based Syst.4
2022 EGM: An Efficient Generative Model for Unrestricted Adversarial Examples
abstract
Unrestricted adversarial examples allow the attacker to start attacks without given clean samples, which are quite aggressive and threatening. However, existing works for generating unrestricted adversary examples are quite inefficient and cannot achieve a high success rate. In this article, we explore an end-to-end and effective solution for unrestricted adversary example generation. To stabilize the training process and make our generative model converge to satisfactory results, we design a novel decoupled two-step efficient generative model (EGM), which contains a conditional reference generator and a conditional adversarial transformer. The former is responsible for generating reference samples from noises and source classes. The latter is responsible for converting the reference sample into adversarial examples corresponding to target classes. To improve the success rate, we design a new strategy, augmentation of adversarial labels to produce dynamic target labels and enhance the exploration ability of EGM. Such a strategy can be also applied to existing attacks to improve their attack success rates, which is of independent interest. We conduct extensive experiments to evaluate our proposed model and demonstrate the necessity of decoupling the generation process in EGM. Experimental results show our EGM is much faster and achieves a higher success rate than the state-of-the-art attacks.
Tao Xiang 0001, Hangcheng Liu, Shangwei Guo, Yan Gan, Xiaofeng Liao 0001
ACM Trans. Sens. Networks2
2021 Teacher-Supervised Generative Adversarial Networks
abstract
Although generative adversarial networks (GANs) show impressive effects on image generation, existing GANs suffer an unstable training process, and thus result in poor image quality sometimes. To solve this problem, we first introduce a supervision mechanism into GANs and propose a teacher-supervised GAN (GAN-T) model. Specifically, we design a teacher supervision mechanism to inspect whether the features of generated images are as real as those of real images. If not, we add action into the generator. The action takes the encoding of the real image as prior knowledge to guide the generation of samples. We then apply our proposed method to existing GANs to show its compatibility with them. Finally, we conduct extensive experiments on the tasks of noise-to-image generation and image translation, and experimental results show that our proposed method can significantly stabilize the training process of the generator and improve the quality of generated images.
Yan Gan, Tao Xiang 0001, Hangcheng Liu, Mao Ye 0001
ICME3
2021 PRNet: A Progressive Recovery Network for Revealing Perceptually Encrypted Images
abstract
Perceptual encryption is an efficient way of protecting image content by only selectively encrypting a portion of significant data in plain images. Existing security analysis of perceptual encryption usually resorts to traditional cryptanalysis techniques, which require heavy manual work and strict prior knowledge of encryption schemes. In this paper, we introduce a new end-to-end method of analyzing the visual security of perceptually encrypted images, without any manual work or knowing any prior knowledge of the encryption scheme. Specifically, by leveraging convolutional neural networks (CNNs), we propose a progressive recovery network (PRNet) to recover visual content from perceptually encrypted images. Our PRNet is stacked with several dense attention recovery blocks (DARBs), where each DARB contains two branches: feature extraction branch and image recovery branch. These two branches cooperate to rehabilitate more detailed visual information and generate efficient feature representation via densely connected structure and dual-saliency mechanism. We conduct extensive experiments to demonstrate that PRNet works on different perceptual encryption schemes with different settings, and the results show that PRNet significantly outperforms the state-of-the-art CNN-based image restoration methods.
Tao Xiang 0001, Ying Yang 0019, Shangwei Guo, Hangcheng Liu, Hantao Liu
ACM Multimedia4
2021 Convolutional Neural Network for Visual Security Evaluation
abstract
The visual security index (VSI) is a quantized indicator for objective visual security evaluation of selectively encrypted images. One challenging problem in current research is that the performance of VSIs is highly sensitive to the extracted features and the method of similarity measurement, and it is hard to choose appropriate handcrafted features from encrypted images, as well as to find an effective similarity measurement. In this paper, we make the first attempt to present a novel convolutional neural network-based visual security index (CNNVSI). Our proposed CNNVSI is purely data-driven and trained end-to-end. We propose three specialized designs to make the approach work for encrypted low-quality images without any handcrafted features or prior knowledge about the human vision system (HVS). First, we present a patch labeling algorithm to assign each encrypted patch a visual security score. Second, we design a multiscale attention residual network (MARNet) for feature learning. Last, we propose to fuse the learned features from plain images, encrypted images and their discrepancy images. Extensive and systematic experiments are conducted on five publicly available image databases to analyze the performance of our proposed CNNVSI, and the experimental results and their analysis demonstrate that our proposed CNNVSI significantly outperforms the existing state-of-the-art methods in terms of accuracy and stability.
Ying Yang 0019, Tao Xiang 0001, Hangcheng Liu, Xiaofeng Liao 0001
IEEE Trans. Circuits Syst. Video Technol.3
2020 Visual Security Evaluation of Perceptually Encrypted Images Based on Image Importance
abstract
Perceptual/selective encryption has been gaining widespread attention as an emerging technology for image privacy protection. However, few studies focus on the visual security evaluation of perceptually encrypted images, which has a significant impact on measuring the effectiveness and practicality of these encryption methods. In this paper, we propose an image importance-based visual security index (IIBVSI) by leveraging spatial contrast and texture features. Based on the characteristics of perceptually encrypted images, we present an averaged high-order gradient magnitude map to describe the spatial contrast feature and introduce a combined local amplitude map of multiple log-Gabor filters to represent the texture feature. Specifically, the multiresolution representation of an image is first created by downsampling to simulate the hierarchical property of the human visual system. Next, for each scale of image resolution, the spatial contrast and the texture feature maps are extracted from both plain and encrypted images. Similarity measurements are then conducted on these feature maps to generate the contrast and the texture similarity maps. An image importance-based pooling strategy is subsequently proposed to combine these measurements and generate a visual security score. The final IIBVSI score is computed by averaging the visual security scores of all scales of image resolution. Extensive experiments are conducted on several publicly available databases, and the results demonstrate the superiority and robustness of our proposed IIBVSI compared with existing state-of-the-art work in the low and moderate image quality ranges.
Tao Xiang 0001, Ying Yang 0019, Hangcheng Liu, Shangwei Guo
IEEE Trans. Circuits Syst. Video Technol.3