Zhengyun He

dblp:301/8351 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
3since 2021 · last 2022
0000-0003-3526-8018ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
YearPublicationVenuePosition
2022 Learning Coated Adversarial Camouflages for Object Detectors
abstract
An adversary can fool deep neural network object detectors by generating adversarial noises. Most of the existing works focus on learning local visible noises in an adversarial "patch" fashion. However, the 2D patch attached to a 3D object tends to suffer from an inevitable reduction in attack performance as the viewpoint changes. To remedy this issue, this work proposes the Coated Adversarial Camouflage (CAC) to attack the detectors in arbitrary viewpoints. Unlike the patch trained in the 2D space, our camouflage generated by a conceptually different training framework consists of 3D rendering and dense proposals attack. Specifically, we make the camouflage perform 3D spatial transformations according to the pose changes of the object. Based on the multi-view rendering results, the top-n proposals of the region proposal network are fixed, and all the classifications in the fixed dense proposals are attacked simultaneously to output errors. In addition, we build a virtual 3D scene to fairly and reproducibly evaluate different attacks. Extensive experiments demonstrate the superiority of CAC over the existing attacks, and it shows impressive performance both in the virtual scene and the real world. This poses a potential threat to the security-critical computer vision systems.
Yexin Duan, Xingyu Zhou 0002, Junhua Zou, Zhengyun He, Jin Zhang 0024, Zhisong Pan 0003
IJCAI5
2022 Adversarial attack via dual-stage network erosion
Yexin Duan, Junhua Zou, Xingyu Zhou 0002, Zhengyun He, Dazhi Zhan, Jin Zhang 0024, Zhisong Pan 0003
Comput. Secur.5
2022 Boosting adversarial attacks with transformed gradient
Zhengyun He, Yexin Duan, Junhua Zou, Zhengfang He
Comput. Secur.1