VLDB 2026 Research / reviewers in the wild / expert
Jianpeng Ke
dblp:285/9905
· DBLP profile ↗
15ranked-venue papers
4as first author
15since 2021 · last 2025
0000-0002-4893-3665ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 11 · 4 first-author · 11 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 4 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Understanding and leveraging vocoder fingerprints for synthetic speech attribution
Jianpeng Ke |
Appl. Intell. | 1 |
| 2025 | TSIDS: Spatial-temporal fusion gating Multilayer Perceptron for network intrusion detection
Lina Wang 0001, Jianpeng Ke, Rongwei Yu |
Expert Syst. Appl. | 3 |
| 2025 | Exposing the Forgery Clues of DeepFakes via Exploring the Inconsistent Expression CuesabstractThe pervasive prevalence of DeepFakes poses a profound threat to individual privacy and the stability of society. Believing the synthetic videos of a celebrity and trumping up impersonated forgery videos as authentic are just a few consequences generated by DeepFakes. We investigate current detectors that blindly deploy deep learning techniques that are not effective in capturing subtle clues of forgery when generative models produce remarkably realistic faces. Inspired by the fact that synthetic operations inevitably modify the regions of eyes and mouth to match the target face with the identity or expression of the source face, we conjecture that the continuity of facial movement patterns representing expressions that existed in the veritable faces will be disrupted or completely broken in synthetic faces, making it a potentially formidable indicator for DeepFake detection. To prove this conjecture, we utilize a dual‐branch network to capture the inconsistent patterns of facial movements within eyes and mouth regions separately. Extensive experiments on popular FaceForensics++, Celeb‐DF‐v1, Celeb‐DF‐v2, and DFDC‐Preview datasets have demonstrated not only effectiveness but also the robust capability of our method to outperform the state‐of‐the‐art baselines. Moreover, this work represents greater robustness against adversarial attacks, achieving ASR of 54.8% in the I‐FGSM attack and 43.1% in the PGD attack on the DeepFakes dataset of FaceForensics++, respectively. Lina Wang 0001, Run Wang 0001, Jianpeng Ke, Xi Ye 0004, Yadi Wu |
Int. J. Intell. Syst. | 4 |
| 2025 | CtrlFuzz: A controllable diffusion-based fuzz testing for deep neural networks via coverage-aware manifold guidance
Aoshuang Ye, Runze Yan, Jianpeng Ke, Benxiao Tang |
Inf. Softw. Technol. | 4 |
| 2025 | DeFinder: Error-sensitive testing of deep neural networks via vulnerability interpretation
Aoshuang Ye, Benxiao Tang, Jianpeng Ke, Yiru Zhao, Tao Peng 0006 |
J. Netw. Comput. Appl. | 4 |
| 2024 | AdvShadow: Evading DeepFake Detection via Adversarial Shadow AttackabstractWith the emergence of techniques called DeepFakes, there has been a notable proliferation of DeepFake detectors rooted in deep learning. These detectors aim to expose subtle distinctions between genuine and counterfeit facial images across spatial, frequency, and physiological domains. Unfortunately, these detectors are susceptible to adversarial attacks. In this study, we introduce a novel transferable adversarial attack named AdvShadow, designed to attack DeepFake detectors by leveraging natural shadows in real-life. The proposed AdvShadow comprises three components: random shadow generator, shadow overlay network, and adversarial shadow generation. Initially, we construct a random shadowed facial dataset, utilizing additional shadow overlay network to produce adversarial samples for training. Then we generate adversarial shadows for DeepFake datasets, mitigating the disparities of luminance between real and synthesized images. Through extensive experiments, we demonstrate the effectiveness and transferability of AdvShadow for attacking under black-box settings. Mingcheng Zhang, Jianpeng Ke, Lina Wang 0001 |
ICASSP | 3 |
| 2024 | SFIA: Toward a Generalized Semantic-Agnostic Method for Fake Image AttributionabstractThe proliferation of photorealistic images synthesized by generative adversarial networks (GANs) has posed serious threats to society. Therefore a new challenge task, named image attribution, is arising to attribute fake images to a specific GAN. However, existing approaches focus on model‐specific features but neglect the misguidance of semantic‐relevant features in image attribution, which leads to a significant performance decrease in cross‐dataset evaluation. To tackle the above problem, we propose a semantic‐agnostic fake image attribution (SFIA) method, which effectively distinguishes fake images by disentangling the GANs fingerprint and semantic‐relevant features in latent space. Specifically, we design a semantic eliminator based on residual block with skip connections that take images as input and outputs GAN fingerprint features. A classifier with an attention module for feature refinement is introduced to make the final decision. In addition, we develop a well‐trained reconstructor and classifier which supervise the semantic eliminator to achieve semantic‐agnostic feature extraction. Moreover, we propose an improved data augmentation combined with meta‐learning to enhance the model’s generalization in detecting unseen image categories. Comprehensive experiments on various datasets, namely, CelebA, LSUN‐church, and LSUN‐bedroom, demonstrate the effectiveness of our proposed SFIA. It achieves over 95% accuracy on three datasets and exhibits superior performance in terms of generalization to unseen data. Jianpeng Ke, Lina Wang 0001 |
Int. J. Intell. Syst. | 1 |
| 2023 | PatchFinger: A Model Fingerprinting Scheme Based on Adversarial Patch
Bo Zeng 0006, Kunhao Lai, Jianpeng Ke, Fangchao Yu, Lina Wang 0001 |
ICONIP (2) | 3 |
| 2023 | DF-UDetector: An effective method towards robust deepfake detection via feature restoration
Jianpeng Ke, Lina Wang 0001 |
Neural Networks | 1 |
| 2023 | GANAD: A GAN-based method for network anomaly detection
Lina Wang 0001, Jianpeng Ke, Rongwei Yu |
World Wide Web (WWW) | 3 |
| 2022 | Combating Multi-level Adversarial Text with Pruning based Adversarial TrainingabstractDespite significant advancements of deep learning-based models for natural language processing (NLP) tasks, previous efforts have shown that numerous models, including deep neural networks (DNNs), suffer from moderate to significant performance degradation with adversarial examples. Adversary crafts malicious text by adding, deleting, modifying chars, words, and sentences, to fool the DNN models. Therefore, adversarial training and model enhanced methods are proposed to combat the adversarial attack. However, both methods are lack generalization due to the overfitting intrinsic of neural networks. In this paper, we propose a novel framework to combat text adversarial examples, namely DisPAT, which consists an adversarial text discriminator and a robust pruned text classifier. First, we explore the adversarial examples and benign examples distribution in embedding space, indicating the feasibility of a DNN-based discriminator. To get multi-level adversarial texts, we deploy a generator, and a discriminator to identify adversarial perturbations. Notably, in the inference stage, our pipeline places the well-trained discriminator in front of the text classifier to distinguish the char-level adversarial text. Finally, we apply neuron-salience-based pruning to specifically improve the classifier performance of adversarial text. Experimental results show that our approach outperforms state-of-the-art baselines in combating both char-level and word-level adversarial text. Moreover, DisPAT achieves a very close to or even higher accuracy than that of the standard model. Jianpeng Ke, Lina Wang 0001, Aoshuang Ye |
IJCNN | 1 |
| 2022 | DANCe: Dynamic Adaptive Neuron Coverage for Fuzzing Deep Neural NetworksabstractDeep learning (DL) defines a data-driven paradigm that differs from conventional software. It utilizes training data to construct the internal logic of the deep neural networks. With aggressive development in various security-sensitive domains, deep learning raises safety concerns in academia and industrial community. Numerous researches have shown that even the most advanced deep learning systems have vulnerabilities leading to misbehaviors. Despite the urgent security threat, fuzzing test remains a reasonable way to solve the problem. However, The static parameters design in current mainstream neuron coverage disables the fuzzing work diversely on heterogeneous architectures. To address the above problems, we propose the Dynamic Adaptive Neuron Coverage (DANCe) to model the neuron behavior, which can adapt diverse models with implementing training data. The dynamic adaption mechanism enhances the ability of coverage-based fuzzing to generate adversarial examples as test cases. The proposed model is evaluated on two widely-adopted image datasets and four well-designed deep neural networks. The experimental results show that the DANCe exceeds the SOTA coverage criteria by 7% and 33% on generating adversarial examples within 1 hour and 6 hours of time limitation. Aoshuang Ye, Lina Wang 0001, Lei Zhao 0012, Jianpeng Ke |
IJCNN | 4 |
| 2022 | Better constraints of imperceptibility, better adversarial examples in the textabstractState-of-the-art adversarial attacks in the text domain have shown their power to induce machine learning models to produce abnormal outputs. The samples generated in these attacks have three important attributes: attack ability, transferability, and imperceptibility. However, compared with the other two attributes, the imperceptibility of adversarial examples has not been well investigated. Unlike the pixel-level perturbations in images, adversarial perturbations in the text are usually traceable, reflecting changes in characters, words, or sentences. The generation of imperceptible samples in texts is more difficult than in images. Therefore, how to constrain adversarial perturbations added in the text is a crucial step to construct more natural adversarial texts. Unfortunately, recent studies merely select measurements to constrain the added adversarial perturbations, but none of them explain where these measurements are suitable, which one is better, and how they perform in different kinds of adversarial attacks. In this paper, we fill this gap by comparing the performance of these metrics in various attacks. Furthermore, we propose a stricter constraint for word-level attacks to obtain more imperceptible samples. It is also helpful to enhance existing word-level attacks for adversarial training. Wenqi Wang 0002, Lina Wang 0001, Run Wang 0001, Aoshuang Ye, Jianpeng Ke |
Int. J. Intell. Syst. | 5 |
| 2022 | Ex2: Monte Carlo Tree Search-based test inputs prioritization for fuzzing deep neural networksabstractFuzzing is considered to be an essential approach to guarantee the reliability of deep neural networks (DNNs) based systems. The DNN fuzzing leverages various inputs prioritization methods to guide the testing process. The current research mainly focus on constructing testing metrics that symbolize the logical representation of the DNN to guide the generation of test cases, which neglects the potential performance brought by implementing heuristic algorithm. Moreover, the straightforward implementation of queue structure can not represent the metamorphic relationships between generated inputs in DNN fuzzing. Therefore, developing the appropriate heuristic algorithm-based inputs prioritization method is critical to improve the performance of DNN fuzzers. In this paper, we propose a Monte Carlo Tree Search (MCTS) based inputs prioritization method called E x 2 $E{x}^{2}$ (Exploration and Exploitation) that formulates DNN testing exploration as the sequential decision process. The technique introduces an innovative tree-structure design that schedules inputs from the statistical perspective. Different from traditional DNN testing, the batch pool is maintained in the form of nodes in MCTS. The links between nodes precisely represent the metamorphic relationship between input batches, which indicates the potential value for in-depth search. Furthermore, a novel simulation mechanism is implemented to adapt MCTS in DNN testing, which attain better coverage feedback. The effectiveness of our method is comprehensively investigated on six popular deep learning models from LeNet and VGG families. The comparison experiments are conducted between DeepHunter, TensorFuzz, and DeepSmartFuzzer to demonstrate efficacy on various testing metrics. The experimental results show that the E x 2 $E{x}^{2}$ significantly enhance the coverage gain of DNN fuzzing up to 30% against the best performance in comparison groups. Aoshuang Ye, Lina Wang 0001, Lei Zhao 0012, Jianpeng Ke |
Int. J. Intell. Syst. | 4 |
| 2021 | RapidFuzz: Accelerating fuzzing via Generative Adversarial Networks
Aoshuang Ye, Lina Wang 0001, Lei Zhao 0012, Jianpeng Ke, Wenqi Wang 0002, Qinliang Liu |
Neurocomputing | 4 |