VLDB 2026 Research / reviewers in the wild / expert
Caiyun Xie
dblp:305/4910
· DBLP profile ↗
7ranked-venue papers
1as first author
7since 2021 · last 2026
0009-0003-3543-1505ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Take Fake as Real: Realistic-Like Robust Black-Box Adversarial Attack to Evade AIGC DetectionabstractThe security of AI-generated content (AIGC) detection is crucial for ensuring multimedia content credibility. To enhance detector security, research on adversarial attacks has become essential. However, most existing adversarial attacks focus only on GAN-generated facial images detection, struggle to be effective on multi-class natural images and diffusion-based detectors, and exhibit poor invisibility. To fill this gap, we first conduct an in-depth analysis of the vulnerability of AIGC detectors and discover the feature that detectors vary in vulnerability to different post-processing. Then, considering that the detector is agnostic in real-world scenarios and given this discovery, we propose a Realistic-like Robust Black-box Adversarial attack (R2BA) with post-processing fusion optimization. Unlike typical perturbations, R2BA uses real-world post-processing, i.e., Gaussian blur, JPEG compression, Gaussian noise and light spot to generate adversarial examples. Specifically, we use a stochastic particle swarm algorithm with inertia decay to optimize post-processing fusion intensity and explore the detector’s decision boundary. Guided by the detector’s fake probability, R2BA enhances/weakens the detector-vulnerable/detector-robust post-processing intensity to strike a balance between adversariality and invisibility. Extensive experiments on popular/commercial AIGC detectors and datasets demonstrate that R2BA exhibits impressive anti-detection performance, excellent invisibility, and strong robustness in GAN-based and diffusion-based cases. Compared to state-of-the-art white-box and black-box attacks, R2BA shows significant improvements of 15%–72% and 21%–47% in anti-detection performance under the original and robust scenario respectively, offering valuable insights for the security of AIGC detection in real-world applications. Caiyun Xie, Dengpan Ye, Yunming Zhang, Yueyun Shang, Yunna Lv, Jiacheng Deng 0001, Jiawei Song |
IEEE Trans. Circuits Syst. Video Technol. | 1 |
| 2026 | DIP-Watermark: A Double Identity Protection Method Based on Robust Adversarial WatermarkabstractThe wide deployment of Face Recognition (FR) systems poses privacy risks. One countermeasure is adversarial attack, deceiving unauthorized malicious FR, but it also disrupts regular identity verification of trusted authorizers, exacerbating the potential threat of identity impersonation. To address this, we propose the first double identity protection scheme based on traceable adversarial watermarking, termed DIP-Watermark. DIP-Watermark employs a one-time watermark embedding to deceive unauthorized FR models and allows authorizers to perform identity verification by extracting the watermark. Specifically, we propose an information-guided adversarial attack against FR models. The encoder embeds an identity-specific watermark into the deep feature space of the carrier, guiding recognizable features of the image to deviate from the source identity. We further adopt a collaborative meta-optimization strategy compatible with sub-tasks, which regularizes the joint optimization direction of the encoder and decoder. This strategy enhances the representation of universal carrier features, mitigating multi-objective optimization conflicts in watermarking. Extensive experiments on two large-scale facial datasets demonstrate that DIP-Watermark achieves significant attack success rates and traceability accuracy on state-of-the-art FR models and commercial APIs. It also exhibits superior robustness against a wide range of real-world simulated distortions, outperforming existing privacy protection methods based on adversarial attacks, deep watermarking, or their simple combination. Our work potentially opens up new insights into proactive protection for FR privacy. Yunming Zhang, Dengpan Ye, Caiyun Xie, Sipeng Shen, Ziyi Liu 0009, Jiacheng Deng 0001, Yueyun Shang, Zhihong Tian 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | Toward a Universal, Transferable, and Robust Adversarial Perturbation Framework Against Deep Hashing-Based Facial Image RetrievalabstractDeep Hashing (DH) based image retrieval is commonly used in facial recognition systems for its precision and effectiveness. However, this convenience is accompanied by a mounting threat to privacy. The DH model possesses vulnerability to adversarial attacks, which can be leveraged to prevent the retrieval of private images. Current adversarial attacks on DH models commonly focus on individual images or specific categories, lacking universal perturbations for the entire hashing dataset. This paper introduces the UTAP series, the first universal, transferable, and robust adversarial perturbation against DH facial image retrieval, safeguarding all images with a single perturbation. We explore the relationships between clusters learned by different DH models and define the optimization goal for optimizing UTAP series as moving away from the voted overall hashcenter. To alleviate the challenges of single-objective optimization, we randomly vote for sub-cluster centers and propose sub-task-based meta-learning to aid global optimization. Furthermore, we dissect the functional roles of key components in DH models and introduce UTAP++, a feature-hashing two-stage attack that is readily adaptable to cross-model and cross-scheme ensemble adversarial attacks. Extensive experiments conducted on renowned face datasets and DH models under varied complex scenarios, encompassing cross-image, cross-model, cross-bit, cross-algorithm, model ensemble, algorithm ensemble, and image compression, reveal that the UTAP series demonstrate remarkable universality, transferability, and robustness in preventing facial image retrieval. Compared to existing state-of-the-art methods, the UTAP series excel in white-box settings and exhibits significant transferability improvements of$10\%-70\%$in all black-box settings, with 20% and 55% average robustness improvements in white-box and black-box settings, respectively. These findings underscore the practical value of the UTAP series in real-world, presenting novel effective defense strategies against unauthorized facial image retrieval. Yunna Lv, Dengpan Ye, Yiheng He, Ziyi Liu 0009, Caiyun Xie |
IEEE Trans. Circuits Syst. Video Technol. | 6 |
| 2025 | Three-in-One: Robust Enhanced Universal Transferable Anti-Facial Retrieval in Online Social NetworksabstractDeep hash-based retrieval techniques are widely used in facial retrieval systems to improve the efficiency of facial matching. However, it also carries the danger of exposing private information. Deep hash models are easily influenced by adversarial examples, which can be leveraged to protect private images from malicious retrieval. The existing adversarial example methods against deep hash models focus on universality and transferability, lacking the research on its robustness in online social networks (OSNs), which leads to their failure in anti-retrieval after post-processing. Therefore, we provide the first in-depth discussion on robustness in universal transferable anti-facial retrieval and propose Three-in-One Adversarial Perturbation (TOAP). Specifically, we construct a local and global Compression Generator (CG) to simulate complex post-processing scenarios, which can be used to mitigate perturbation. Then, we propose robust optimization objectives based on the discovery of the variation patterns of model’s distribution after post-processing, and generate adversarial examples using these objectives and meta-learning. Finally, we iteratively optimize perturbation by alternately generating adversarial examples and fine-tuning the CG, balancing the performance of perturbation while enhancing CG’s ability to mitigate them. Numerous experiments demonstrate that, in addition to its advantages in universality and transferability, TOAP significantly outperforms current state-of-the-art methods in multiple robustness metrics. It further improves universality and transferability by 5% to 28%, and achieves up to about 33% significant improvement in several simulated post-processing scenarios as well as mainstream OSNs, demonstrating that TOAP can effectively protect private images from malicious retrieval in real-world scenarios. Yunna Lv, Dengpan Ye, Caiyun Xie, Jiacheng Deng 0001, Yiheng He, Sipeng Shen |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2025 | StyleMark: Robust Style Watermarking for Artworks Against Black-Box Zero-Shot Style TransferabstractZero-shot style transfer(ZSST) enables the rendering of real-world natural images into the painting styles of arbitrary artworks without requiring fine-tuning on unseen artistic styles. This low-cost and efficient approach to artistic recreation promotes the dissemination and communication of art. However, misuse of unauthorized artistic style images for ZSST may infringe on the copyrights of artists. One countermeasure is robust watermarking, which tracks image propagation by embedding copyright watermarks into carriers. Unfortunately, the stylized image generated by ZSST lose the structural and semantic information of the original style image, hindering end-to-end robust tracking by watermarks. To fill this gap, we propose StyleMark, the first robust watermarking method for black-box ZSST, which can be seamlessly applied to artistic style images achieving precise attribution of artistic styles after ZSST, without compromising the social usability of artworks. Specifically, we propose a new style watermark network that adjusts the mean activations of style features through multi-scale watermark embedding, thereby planting watermark traces into the shared style feature space of style images. Furthermore, we design a distribution squeeze loss, which constrain content statistical feature distortion, forcing the reconstruction network to focus on integrating style features with watermarks, thus optimizing the intrinsic watermark distribution. Finally, based on solid end-to-end training, StyleMark mitigates the optimization conflict between robustness and watermark invisibility through decoder fine-tuning under random noise. Experimental results demonstrate that StyleMark exhibits significant robustness against black-box ZSST and common pixel-level distortions, maintains high watermark decoding accuracy under complex multi-stage processing scenarios, and securely defending against malicious adaptive attacks. Yunming Zhang, Dengpan Ye, Sipeng Shen, Caiyun Xie |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2025 | Towards Invisible Decision-Based Adversarial Attacks Against Visual Object TrackingabstractAdversarial attacks have become a critical focus in visual object tracking (VOT) research. Small, carefully crafted adversarial perturbations to video frames can easily disrupt the visual object tracker, leading to tracking failure. Therefore, studying adversarial attacks contributes to the development of more robust and reliable trackers. Considering that trackers are agnostic in real-world scenarios, research on decision-based black-box attacks is straightforward and practical. However, existing decision-based black-box attacks neither comprehensively analyze the unique characteristics of object tracking nor sufficiently consider the imperceptibility of adversarial perturbations. In this paper, we propose invisible local attack (ILA), a novel decision-based adversarial attack specifically for VOT with imperceptible perturbations. We assume that a significant number of pixels in a frame, irrelevant to the tracked object, do not substantially contribute to the functioning mechanism of a deep tracker. Based on this consideration, we propose a search algorithm to identify the pixel set focused on by the tracker during object tracking. The adversarial noise is then confined to these pixels and iteratively optimized through a heuristic algorithm of ILA. By perturbing only the key pixels, ILA significantly enhances both the attack performance and imperceptibility when it is applied to visual object trackers. Extensive experiments demonstrate that our ILA method achieves a 121% increase in the robustness metric and a 137% improvement in the structural similarity index measure (SSIM) across multiple datasets for various trackers compared with the state-of-the-art (SOTA) method. Ziyi Liu 0009, Caiyun Xie, Wenbing Ding, Dengpan Ye, Qian Wang 0002 |
IEEE Trans. Multim. | 2 |
| 2024 | Dual Defense: Adversarial, Traceable, and Invisible Robust Watermarking Against Face SwappingabstractMalicious applications of deep face swapping technology pose security threats such as misinformation dissemination and identity fraud. Some research propose the utilization of robust watermarking methods to track the copyright of facial images, facilitating post-forgery identity attribution. However, these methods cannot fundamentally prevent or eliminate the adverse impacts of face swapping. To address this issue, we present Dual Defense, an innovative framework based on robust adversarial watermarking. It simultaneously tracks image copyrights and disrupts the face swapping model by one-time embedding the robust adversarial watermark. Specifically, we propose an Original-domain Feature Emulation Attack (OFEA) method, which makes the traceable watermark adversarial through specially designed original domain adversarial loss. Additionally, we conduct a wavelet domain image structural information compensation loss, combined with a channel attention mechanism, to jointly balance watermark invisibility, adversariality, and traceability. Furthermore, we design a more comprehensive and rational evaluation method to thoroughly assess the effectiveness of adversarial attacks against face swapping models. Extensive experiments demonstrate that Dual Defense exhibits exceptional cross-task generality and dataset generalization. It maintains impressive adversariality and traceability in both original and robust settings, surpassing current forgery defense methods that possess only one of these capabilities. Yunming Zhang, Dengpan Ye, Caiyun Xie, Xin Liao 0001, Ziyi Liu 0009, Chuanxi Chen, Jiacheng Deng 0001 |
IEEE Trans. Inf. Forensics Secur. | 3 |