Hongrui Chen

dblp:292/5456 · DBLP profile ↗
← Back
11ranked-venue papers
4as first author
11since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 8 · 2 first-author · 8 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
7 papers
Trustworthy machine learning · 54% Generative modeling · 13% Optimization for machine learning · 11%
Network and information security
4 papers
Security and privacy of machine learning · 100%
Computer graphics and multimedia
1 paper
Computational photography and imaging · 100%

Topics — the 19 heaviest of 23, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Security and privacy of machine learning › adversarial attack
backdoor attack
1.922026
Versatile Backdoor Attack With Visible, Semantic, Sample-Specific and Compatible Triggers · IEEE Trans. Pattern Anal. Mach. Intell. 2026
BackdoorBench: A Comprehensive Benchmark and Analysis of Backdoor Learning · Int. J. Comput. Vis. 2025
Machine learning › Trustworthy machine learning › adversarial machine learning
adversarial defense
1.012026
Defenses in Adversarial Machine Learning: A Systematic Survey From the Lifecycle Perspective · IEEE Trans. Pattern Anal. Mach. Intell. 2026
Machine learning › Trustworthy machine learning
adversarial machine learning
1.012026
Defenses in Adversarial Machine Learning: A Systematic Survey From the Lifecycle Perspective · IEEE Trans. Pattern Anal. Mach. Intell. 2026
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
1.012026
Defenses in Adversarial Machine Learning: A Systematic Survey From the Lifecycle Perspective · IEEE Trans. Pattern Anal. Mach. Intell. 2026
Machine learning › Probabilistic and Bayesian machine learning › statistical dependence
conditional dependence estimation
1.012026
BiCD: Learning Conditional Dependence for Continuous Dataset Shift in Regression · KDD (1) 2026
Machine learning › Trustworthy machine learning › robustness
distribution shift
1.012026
BiCD: Learning Conditional Dependence for Continuous Dataset Shift in Regression · KDD (1) 2026
Security and privacy of machine learning › adversarial attack › backdoor attack
physical backdoor attack
1.012026
Versatile Backdoor Attack With Visible, Semantic, Sample-Specific and Compatible Triggers · IEEE Trans. Pattern Anal. Mach. Intell. 2026
Machine learning › Trustworthy machine learning
robustness evaluation
0.912025
BlackboxBench: A Comprehensive Benchmark of Black-Box Adversarial Attacks · IEEE Trans. Pattern Anal. Mach. Intell. 2025
Security and privacy of machine learning
adversarial attack
0.912025
BlackboxBench: A Comprehensive Benchmark of Black-Box Adversarial Attacks · IEEE Trans. Pattern Anal. Mach. Intell. 2025
Security and privacy of machine learning › adversarial attack
black-box attack
0.912025
BlackboxBench: A Comprehensive Benchmark of Black-Box Adversarial Attacks · IEEE Trans. Pattern Anal. Mach. Intell. 2025
Machine learning › Optimization for machine learning
convergence guarantees
0.712023
Improved Analysis of Score-based Generative Modeling: User-Friendly Bounds under Minimal Smoothness Assumptions · ICML 2023
Machine learning › Generative modeling
diffusion model
0.712023
Improved Analysis of Score-based Generative Modeling: User-Friendly Bounds under Minimal Smoothness Assumptions · ICML 2023
Machine learning › Optimization for machine learning › convergence analysis
sampling convergence
0.712023
Improved Analysis of Score-based Generative Modeling: User-Friendly Bounds under Minimal Smoothness Assumptions · ICML 2023
Machine learning › Generative modeling › diffusion model
score-based generative model
0.712023
Improved Analysis of Score-based Generative Modeling: User-Friendly Bounds under Minimal Smoothness Assumptions · ICML 2023
Machine learning › Trustworthy machine learning
robustness
0.612022
BackdoorBench: A Comprehensive Benchmark of Backdoor Learning · NeurIPS 2022
Computational photography and imaging
illumination estimation
0.512021
DSNet: Deep Shadow Network for Illumination Estimation · VR 2021
Computational photography and imaging › illumination estimation
outdoor illumination estimation
0.512021
DSNet: Deep Shadow Network for Illumination Estimation · VR 2021
Computer vision › Vision and language
vision-language model
0.312026
Versatile Backdoor Attack With Visible, Semantic, Sample-Specific and Compatible Triggers · IEEE Trans. Pattern Anal. Mach. Intell. 2026
Machine learning › Generative modeling
score estimation
0.212023
Improved Analysis of Score-based Generative Modeling: User-Friendly Bounds under Minimal Smoothness Assumptions · ICML 2023

Methods — techniques the papers use, named apart from their topics

large language model · 2.0generative model · 2.0transfer-based attack · 1.7query-based attack · 1.7systematic survey · 1.0lifecycle taxonomy · 1.0kernel dependence · 1.0information-theoretic learning · 1.0graph laplacian · 1.0early stopping · 0.7backdoor defense · 0.6backdoor attack · 0.6deep shadow network · 0.5data augmentation · 0.5
YearPublicationVenuePosition
2026 BiCD: Learning Conditional Dependence for Continuous Dataset Shift in Regression
abstract
As a crucial data mining problem, domain adaptation (DA) under dataset shift offers an effective paradigm for transferring knowledge in changing environments (i.e., shifting data distributions). Recent theoretical advances show that learning conditional information is crucial for successful DA, and empirical models with provable performance have been developed under discrete priors. However, for many real-world complex tasks with continuous label spaces, e.g., regression, conditional information is generally intractable, and shift correction models remain unexplored due to the high-dimensional nature of continuous variables. To deal with these challenges, we propose an information-theoretic learning principle called bi-level conditional dependence (BiCD) for continuous shift setting. BiCD characterizes the conditional information of learned representations from two aspects: conditional domain dependence and conditional label dependence, where our results prove that bi-level dependence learning is sufficient to obtain representations with desired properties and to minimize the generalization error. Moreover, BiCD also admits appealing properties for practical modeling: 1) an equivalent formulation with marginal dependence is derived to avoid the explicit computation of high-dimensional conditional dependence in practical modeling; 2) a kernel dependence-based variant is developed to serve as a guaranteed numerical proxy for the vanilla BiCD; 3) a graph Laplacian understanding is provided to justify the learning mechanism of BiCD. Empirically, BiCD is evaluated on standard DA regression datasets, where the significance of the proposed dependence learning principle is validated and SOTA performance is consistently achieved.
Hongrui Chen, Yiming Zhai, Mingjun Pan, You-Wei Luo
KDD (1)1
2026 Versatile Backdoor Attack With Visible, Semantic, Sample-Specific and Compatible Triggers
abstract
Deep neural networks (DNNs) can be manipulated to exhibit specific behaviors when exposed to specific trigger patterns, without affecting their performance on benign samples, dubbed backdoor attack. Currently, implementing backdoor attacks in physical scenarios still faces significant challenges. Physical attacks are labor-intensive and time-consuming, and the triggers are selected in a manual and heuristic way. Moreover, expanding digital attacks to physical scenarios faces many challenges due to their sensitivity to visual distortions and the absence of counterparts in the real world. To address these challenges, we define a novel trigger called the Visible, Semantic, Sample-specific, and Compatible (VSSC) trigger, to achieve effective, stealthy and robust simultaneously, which can also be effectively deployed in the physical scenario using corresponding objects. To implement the VSSC trigger, we propose an automated pipeline comprising three modules: a trigger selection module that systematically identifies suitable triggers leveraging large language models, a trigger insertion module that employs generative models to seamlessly integrate triggers into images, and a quality assessment module that ensures the natural and successful insertion of triggers through vision-language models. Extensive experimental results and analysis validate the effectiveness, stealthiness, and robustness of the VSSC trigger. It can not only maintain robustness under visual distortions but also demonstrates strong practicality in the physical scenario. By providing the first automated pipeline, VSSC transforms physical backdoor attacks from a labor-intensive craft into a systematic and realistic threat to real-world AI systems. We hope the proposed VSSC trigger and implementation approach could inspire future studies on designing more practical triggers in backdoor attacks.
Ruotong Wang 0008, Hongrui Chen, Zihao Zhu 0001, Li Liu 0036, Baoyuan Wu
IEEE Trans. Pattern Anal. Mach. Intell.2
2026 Defenses in Adversarial Machine Learning: A Systematic Survey From the Lifecycle Perspective
abstract
Adversarial phenomena have been widely observed in machine learning (ML) systems, especially those using deep neural networks. These phenomena describe situations where ML systems may produce predictions that are inconsistent and incomprehensible to humans in certain specific cases. Such behavior poses a serious security threat to the practical application of ML systems. To exploit this vulnerability, several advanced attack paradigms have been developed, mainly including backdoor attacks, weight attacks, and adversarial examples. For each individual attack paradigm, various defense mechanisms have been proposed to enhance the robustness of models against the corresponding attacks. However, due to the independence and diversity of these defense paradigms, it is challenging to assess the overall robustness of an ML system against different attack paradigms. This survey aims to provide a systematic review of all existing defense paradigms from a unified lifecycle perspective. Specifically, we decompose a complete ML system into five stages: pre-training, training, post-training, deployment, and inference. We then present a clear taxonomy to categorize representative defense methods at each stage. The unified perspective and taxonomy not only help us analyze defense mechanisms but also enable us to understand the connections and differences among different defense paradigms. It inspires future research to develop more advanced and comprehensive defense strategies.
Baoyuan Wu, Mingli Zhu, Meixi Zheng, Zihao Zhu 0001, Shaokui Wei, Hongrui Chen, Danni Yuan, Li Liu 0036, Qingshan Liu 0001
IEEE Trans. Pattern Anal. Mach. Intell.7
2025 The Imitation Game revisited: A comprehensive survey on recent advances in AI-generated text detection
Zhiwei Yang 0005, Zhengjie Feng, Rongxin Huo, Huiru Lin, Hanghan Zheng, Ruichi Nie, Hongrui Chen
Expert Syst. Appl.7
2025 BackdoorBench: A Comprehensive Benchmark and Analysis of Backdoor Learning
Baoyuan Wu, Hongrui Chen, Zihao Zhu 0001, Shaokui Wei, Danni Yuan, Mingli Zhu, Ruotong Wang 0008, Li Liu 0036
Int. J. Comput. Vis.2
2025 BlackboxBench: A Comprehensive Benchmark of Black-Box Adversarial Attacks
abstract
Adversarial examples are well-known tools to evaluate the vulnerability of deep neural networks (DNNs). Although lots of adversarial attack algorithms have been developed, it's still challenging in the practical scenario that the model's parameters and architectures are inaccessible to the attacker/evaluator, i.e., black-box adversarial attacks. Due to the practical importance, there has been rapid progress from recent algorithms, reflected by the quick increase in attack success rate and quick decrease in query numbers to the target model. However, there lacks thorough evaluations and comparisons among these algorithms, causing difficulties in tracking the real progress, analyzing advantages and disadvantages of different technical routes, as well as designing future development roadmap of this field. Thus, we aim at building a comprehensive benchmark of black-box adversarial attacks, called BlackboxBench. It mainly provides: 1) a unified, extensible and modular-based codebase, implementing 29 query-based attack algorithms and 30 transfer-based attack algorithms; 2) comprehensive evaluations: we evaluate the implemented algorithms against several mainstreaming model architectures on 2 widely used datasets (CIFAR-10 and a subset of ImageNet), leading to 14,950 evaluations$^{1}$1 in total; 3) thorough analysis and new insights, as well analytical tools.
Meixi Zheng, Xuanchen Yan, Zihao Zhu 0001, Hongrui Chen, Baoyuan Wu
IEEE Trans. Pattern Anal. Mach. Intell.4
2024 A Multi-Slot Load Balancing Scheme for LEO Satellite Communication Handover Target Selection
abstract
The Low-Earth-Orbit (LEO) constellation has emerged as a promising component for seamless and fast global connectivity. With the increasing number of satellites in LEO constellations, multiple satellites can simultaneously cover the same geographical area. The selection of a user's handover (HO) target can significantly impact the quality of service (QoS) for communication and the load status of the satellite network. Motivated by this, the paper introduces a multi-slot load balancing (MSLB) scheme to offer users HO target selection strategies. An optimization problem is formulated to determine the HO sequence for users according to the MSLB scheme. Subsequently, a HO sequence graph mapping (HSGM) algorithm and an iterative shortest path solving (ISPS) algorithm are developed to address this optimization problem by transforming it into a shortest path searching problem. Simulation results demonstrate that, in comparison to traditional single-slot schemes, the MSLB scheme exhibits superior performance in load balancing and improving user communication QoS.
Hongrui Chen, Gaofeng Nie, Hui Tian 0003
WCNC1
2023 Improved Analysis of Score-based Generative Modeling: User-Friendly Bounds under Minimal Smoothness Assumptions
abstract
We give an improved theoretical analysis of score-based generative modeling. Under a score estimate with small $L^2$ error (averaged across timesteps), we provide efficient convergence guarantees for any data distribution with second-order moment, by either employing early stopping or assuming smoothness condition on the score function of the data distribution. Our result does not rely on any log-concavity or functional inequality assumption and has a logarithmic dependence on the smoothness. In particular, we show that under only a finite second moment condition, approximating the following in reverse KL divergence in $\epsilon$-accuracy can be done in $\tilde O\left(\frac{d \log (1/\delta)}{\epsilon}\right)$ steps: 1) the variance-$\delta$ Gaussian perturbation of any data distribution; 2) data distributions with $1/\delta$-smooth score functions. Our analysis also provides a quantitative comparison between different discrete approximations and may guide the choice of discretization points in practice.
Hongrui Chen, Holden Lee, Jianfeng Lu 0001
ICML1
2022 BackdoorBench: A Comprehensive Benchmark of Backdoor Learning
abstract
Backdoor learning is an emerging and vital topic for studying deep neural networks' vulnerability (DNNs). Many pioneering backdoor attack and defense methods are being proposed, successively or concurrently, in the status of a rapid arms race. However, we find that the evaluations of new methods are often unthorough to verify their claims and accurate performance, mainly due to the rapid development, diverse settings, and the difficulties of implementation and reproducibility. Without thorough evaluations and comparisons, it is not easy to track the current progress and design the future development roadmap of the literature. To alleviate this dilemma, we build a comprehensive benchmark of backdoor learning called BackdoorBench. It consists of an extensible modular-based codebase (currently including implementations of 8 state-of-the-art (SOTA) attacks and 9 SOTA defense algorithms) and a standardized protocol of complete backdoor learning. We also provide comprehensive evaluations of every pair of 8 attacks against 9 defenses, with 5 poisoning ratios, based on 5 models and 4 datasets, thus 8,000 pairs of evaluations in total. We present abundant analysis from different perspectives about these 8,000 evaluations, studying the effects of different factors in backdoor learning. All codes and evaluations of BackdoorBench are publicly available at https://backdoorbench.github.io.
Baoyuan Wu, Hongrui Chen, Zihao Zhu 0001, Shaokui Wei, Danni Yuan
NeurIPS2
2021 Long-Term Visual Localization with Semantic Enhanced Global Retrieval
abstract
Visual localization under varying conditions such as changes in illumination, season and weather is a fundamental task for applications such as autonomous navigation. In this paper, we present a novel method of using semantic information for global image retrieval. By exploiting the distribution of different classes in a semantic scene, the discriminative features of the scene’s structure layout is embedded into a normalized vector that can be used for retrieval, i.e. semantic retrieval. Color image retrieval is based on low-level visual features extracted by algorithms or Convolutional Neural Networks (CNNs), while semantic retrieval is based on high-level semantic features which are robust in scene appearance variations. By combining semantic retrieval with color image retrieval in the global retrieval step, we show that these two methods can complement with each other and significantly improve the localization performance. Experiments on the challenging CMU Seasons dataset show that our method is robust across large variations of appearance and achieves state-of-the-art localization performance.
Hongrui Chen, Yuan Xiong, Zhong Zhou
MSN1
2021 DSNet: Deep Shadow Network for Illumination Estimation
abstract
Illumination consistency has applications to modeling and rendering in virtual reality. In 3D reconstruction and Mixed Reality(MR) fusion, the appearance of a large-scale outdoor scene may change in response to lighting and seasons, for example. Since 3D reconstruction from scratch is costly, it is helpful to be able to update existing models with recently captured photographs. However, the illumination conditions of the captured photograph can be arbitrary, making it challenging to fit to the existing model. To tackle this problem, this paper proposes a novel approach that can precisely estimate the illumination of the input image. Our Deep Shadow Network (DSNet) collaboratively utilizes illumination-based data augmentation for sun position estimation, along with a dataset of illumination-based augmented renderings. Our run-time rendering and optimization strategy is also discussed. We show that accurate simulation of illumination can improve the performance of visual applications including place recognition and long-term localization. Experimental results validate the effectiveness of the proposed approach, and show its superiority over the state-of-the-art.
Yuan Xiong, Hongrui Chen, Zhe Zhu, Zhong Zhou
VR2