Junda Lu 0001

dblp:297/0832-1 · DBLP profile ↗
← Back
5ranked-venue papers
1as first author
5since 2021 · last 2024
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 On Adversarial Training with Incorrect Labels
Benjamin Zi Hao Zhao, Junda Lu 0001, Xiaowei Zhou 0003, Dinusha Vatsalan, Muhammad Ikram 0001, Mohamed Ali Kâafar
WISE (4)2
2023 Boosting Accuracy and Robustness of Student Models via Adaptive Adversarial Distillation
abstract
Distilled student models in teacher-student architectures are widely considered for computational-effective deployment in real-time applications and edge devices. However, there is a higher risk of student models to encounter adversarial attacks at the edge. Popular enhancing schemes such as adversarial training have limited performance on compressed networks. Thus, recent studies concern about adversarial distillation (AD) that aims to inherit not only prediction accuracy but also adversarial robustness of a robust teacher model under the paradigm of robust optimization. In the min-max framework of AD, existing AD methods generally use fixed supervision information from the teacher model to guide the inner optimization for knowledge distillation which often leads to an overcorrection towards model smoothness. In this paper, we propose an adaptive adversarial distillation (AdaAD) that involves the teacher model in the knowledge optimization process in a way interacting with the student model to adaptively search for the inner results. Comparing with state-of-the-art methods, the proposed AdaAD can significantly boost both the prediction accuracy and adversarial robustness of student models in most scenarios. In particular, the ResNet-18 model trained by AdaAD achieves top-rank performance (54.23% robust accuracy) on RobustBench under AutoAttack.
Bo Huang 0017, Yi Wang 0017, Junda Lu 0001, Minhao Cheng, Wei Wang 0011
CVPR4
2022 Unsupervised Domain Adaptation for Nonintrusive Load Monitoring Via Adversarial and Joint Adaptation Network
abstract
Nonintrusive load monitoring (NILM) is a technique to disaggregate an appliance's load consumption from the aggregate load in a house. Monitoring the energy behavior has become increasingly important for home energy management. For many machine learning-based models, model training needs enough, and diverse appliance-level labeled data from different houses, which is very time-consuming, expensive, and unacceptable for users. In this article, we propose an algorithm based on the adversarial network and the joint adaptation network for energy disaggregation to decrease the distribution gaps of both the feature space and the label space between the source and target domains. With only very limited labeled data in the source domain and enough unlabeled data in the target domain, our proposed algorithm can obtain satisfactory accuracy results for NILM. Extensive experiments for intradomain and interdomain demonstrate that the proposed algorithm can significantly improve the domain adaptation. Comparing with the baseline method that without any domain adaptation, the improvement on mean absolute error with the proposed algorithm can reach 67.72%, 67.53%, and 66.56% for the washing machine (W.M), the dishwasher (D.W), and the microwave (M.V), respectively.
Yinyan Liu, Jing Qiu 0001, Junda Lu 0001, Wei Wang 0011
IEEE Trans. Ind. Informatics4
2021 A Smart Adversarial Attack on Deep Hashing Based Image Retrieval
abstract
Deep hashing based retrieval models have been widely used in large-scale image retrieval systems. Recently, there has been a surging interest in studying the adversarial attack problem in deep hashing based retrieval models. However, the effectiveness of existing adversarial attacks is limited by their poor perturbation management, unawareness of ranking weight, and only laser-focusing on the attack image. These shortages lead to high perturbation costs yet low AP reductions. To overcome these shortages, we propose a novel adversarial attack framework to improve the effectiveness of adversarial attacks. Our attack designs a dimension-wise surrogate Hamming distance function to help with wiser perturbation management. Further, in generating adversarial examples, instead of focusing on a single image, we propose to collectively incorporate relevant images combined with an AP-oriented (average precision) weight function. In addition, our attack can deal with both untargeted and targeted adversarial attacks in a flexible manner. Extensive experiments demonstrate that, with the same attack performance, our model significantly outperforms state-of-the-art models in perturbation cost on both untargeted and targeted attack tasks.
Junda Lu 0001, Yifang Sun, Wei Wang 0011, Yi Wang 0017, Xiaochun Yang 0001
ICMR1
2021 DAIR: A Query-Efficient Decision-based Attack on Image Retrieval Systems
abstract
There is an increasing interest in studying adversarial attacks on image retrieval systems. However, most of the existing attack methods are based on the white-box setting, where the attackers have access to all the model and database details, which is a strong assumption for practical attacks. The generic transfer-based attack also requires substantial resources yet the effect was shown to be unreliable. In this paper, we make the first attempt in proposing a query-efficient decision-based attack framework for the image retrieval (DAIR) to completely subvert the top-K retrieval results with human imperceptible perturbations. We propose an optimization-based method with a smoothed utility function to overcome the challenging discrete nature of the problem. To further improve the query efficiency, we propose a novel sampling method that can achieve the transferability between the surrogate and the target model efficiently. Our comprehensive experimental evaluation on the benchmark datasets shows that our DAIR method outperforms significantly the state-of-the-art decision-based methods. We also demonstrate that real image retrieval engines (Bing Visual Search and Face++ engines) can be attacked successfully with only several hundreds of queries.
Junda Lu 0001, Yi Wang 0017, Jianbin Qin, Wei Wang 0011
SIGIR2