Huiqiang Chen

dblp:315/9588 · DBLP profile ↗
← Back
9ranked-venue papers
5as first author
9since 2021 · last 2026
0000-0003-4811-6742ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 5 · 3 first-author · 5 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Safe and Reliable Diffusion Models via Subspace Projection
abstract
Large-scale text-to-image (T2I) diffusion models have revolutionized image generation, enabling the synthesis of highly detailed visuals from textual descriptions. However, these models may inadvertently generate inappropriate content, such as copyrighted works or offensive images. While existing methods attempt to eliminate specific unwanted concepts, they often fail to ensure robust removal-allowing the concept to reappear in subtle forms. For instance, a model may successfully avoid generating images in Van Gogh's style when explicitly prompted with “Van Gogh”, yet still reproduce his signature artwork when given the prompt “Starry Night”. In this paper, we propose SAFER, a novel and efficient approach for thoroughly removing target concepts from diffusion models. At a high level, SAFER is inspired by the observed low-dimensional structure of the text embedding space. The method first identifies a concept-specific subspace$\mathcal {S}_{c}$associated with the target concept$c$. It then projects the prompt embeddings onto the complementary subspace of$\mathcal {S}_{c}$, effectively erasing the concept from the generated images. Since concepts can be abstract and difficult to fully capture using natural language alone, we employ textual inversion to learn an optimized embedding of the target concept from a reference image. This enables more precise subspace estimation and enhances removal performance. Furthermore, we introduce a subspace expansion strategy to ensure comprehensive and robust concept erasure. Extensive experiments demonstrate that SAFER consistently and effectively erases unwanted concepts from diffusion models while preserving generation quality.
Huiqiang Chen, Tianqing Zhu, Xin Yu 0002, Longxiang Gao, Wanlei Zhou 0001
IEEE Trans. Dependable Secur. Comput.1
2025 Zero-Shot Machine Unlearning with Proxy Adversarial Data Generation
abstract
Machine unlearning aims to remove the influence of specific samples from a trained model. A key challenge in this process is over-unlearning, where the model's performance on the remaining data significantly drops due to the change in the model's parameters. Existing unlearning algorithms depend on the remaining data to prevent this issue. As such, these methods are inapplicable in a more practical scenario, where only the unlearning samples are available (i.e., zero-shot unlearning). This paper presents a novel framework, ZS-PAG, to fill this gap. Our approach offers three key innovations: (1) we approximate the inaccessible remaining data by generating adversarial samples; (2) leveraging the generated samples, we pinpoint a specific subspace to perform the unlearning process, therefore preventing over-unlearning in the challenging zero-shot scenario; and (3) we consider the influence of the unlearning process on the remaining samples and design an influence-based pseudo-labeling strategy. As a result, our method further improves the model's performance after unlearning. The proposed method holds a theoretical guarantee, and experiments on various benchmarks validate the effectiveness and superiority of our proposed method over several baselines.
Huiqiang Chen, Tianqing Zhu, Xin Yu 0002, Wanlei Zhou 0001
IJCAI1
2025 Fine-Tuning a Biased Model for Improving Fairness
abstract
Fairness has emerged as a crucial concern in machine learning since biased models would generate dissimilar predictions for different groups, perpetuating social inequalities. Although numerous techniques have been proposed to address the fairness issue in machine learning, most rely on incorporating fairness constraints during the training phase, rendering them ineffective once the model is deployed. This paper explores the potential of fine-tuning biased models to enhance fairness, particularly suitable for scenarios where retraining the model is not feasible. Our approach is rooted in an empirical analysis of the distribution of bias within a biased model, and we fine-tune the model parameter in a limited scope so that the performance of the original model can be maintained. We first observe that fine-tuning a biased model leads to deviations from its initial state, with deep layers undergoing the most significant changes. We then design and apply a bias-discovery algorithm, revealing that bias predominantly resides in the model’s deep layers. Based on these observations, we propose a straightforward yet highly effective method for debiasing the model: fine-tuning the classification head. We conduct a thorough theoretical analysis to justify the proposed method and provide guidance for fine-tuning. Furthermore, we experimentally validate our method on tabular and image datasets using four networks (CNN, AlexNet, VGG-11, and ResNet-18).
Huiqiang Chen, Tianqing Zhu, Bo Liu 0001, Wanlei Zhou 0001, Philip S. Yu
IEEE Trans. Big Data1
2025 Model Inversion Attack Against Transfer Learning: Inverting a Model Without Querying It
abstract
Transfer learning is an important approach that produces pre-trained teacher models which can be used to quickly build specialized student models. However, recent research on transfer learning has found that it is vulnerable to various attacks, e.g., misclassification and backdoor attacks. However, it is still not clear whether transfer learning is vulnerable to model inversion attacks. Launching a model inversion attack against transfer learning scheme is challenging. Not only does the student model hide its structural parameters, but it is also not queried to the adversary. Hence, when targeting a student model, existing model inversion attacks fail, as they typically rely on querying the target model. In this paper, we initiate research into model inversion attacks against transfer learning with two novel attack methods. Both are black-box attacks, suiting different situations, that do not rely on queries to the target student model. In the first method, the adversary has the data samples that share the same distribution as the training set of the teacher model. In the second method, the adversary does not have any such samples. Experiments show that highly recognizable data records can be inverted with both of these methods. This research underscores the critical insight that even when a model is shielded from public queries, it can still be susceptible to model inversion attacks.
Dayong Ye, Huiqiang Chen, Shuai Zhou 0001, Tianqing Zhu, Wanlei Zhou 0001, Shouling Ji
IEEE Trans. Dependable Secur. Comput.2
2025 AFed: Algorithmic Fair Federated Learning
abstract
Federated learning (FL) has gained significant attention as it facilitates collaborative machine learning among multiple clients without centralizing their data on a server. FL ensures the privacy of participating clients by locally storing their data, which creates new challenges in fairness. Traditional debiasing methods assume centralized access to sensitive information, rendering them impractical for the FL setting. Additionally, FL is more susceptible to fairness issues than centralized machine learning due to the diverse client data sources that may be associated with group information. Therefore, training a fair model in FL without access to client local data is important and challenging. This article presents AFed, a straightforward, yet effective framework for promoting group fairness in FL. The core idea is to circumvent restricted data access by learning the global data distribution. This article proposes two approaches: AFed-G, which uses a conditional generator trained on the server side, and AFed-GAN, which improves upon AFed-G by training a conditional GAN on the client side. We augment the client data with the generated samples to help remove bias. Our theoretical analysis justifies the proposed methods, and empirical results on multiple real-world datasets demonstrate a substantial improvement in AFed over several baselines.
Huiqiang Chen, Tianqing Zhu, Wanlei Zhou 0001, Wei Zhao 0001
IEEE Trans. Neural Networks Learn. Syst.1
2024 MMOOC: A Multimodal Misinformation Dataset for Out-of-Context News Analysis
Qingzheng Xu, Heming Du, Huiqiang Chen, Bo Liu 0001, Xin Yu 0002
ACISP (3)3
2024 Machine Unlearning via Null Space Calibration
Huiqiang Chen, Tianqing Zhu, Xin Yu 0002, Wanlei Zhou 0001
IJCAI1
2024 MM-WLAuslan: Multi-View Multi-Modal Word-Level Australian Sign Language Recognition Dataset
abstract
Isolated Sign Language Recognition (ISLR) focuses on identifying individual sign language glosses. Considering the diversity of sign languages across geographical regions, developing region-specific ISLR datasets is crucial for supporting communication and research. Auslan, as a sign language specific to Australia, still lacks a dedicated large-scale word-level dataset for the ISLR task. To fill this gap, we curate \underline{\textbf{the first}} large-scale Multi-view Multi-modal Word-Level Australian Sign Language recognition dataset, dubbed MM-WLAuslan. Compared to other publicly available datasets, MM-WLAuslan exhibits three significant advantages: (1) the largest amount of data, (2) the most extensive vocabulary, and (3) the most diverse of multi-modal camera views. Specifically, we record 282K+ sign videos covering 3,215 commonly used Auslan glosses presented by 73 signers in a studio environment.Moreover, our filming system includes two different types of cameras, i.e., three Kinect-V2 cameras and a RealSense camera. We position cameras hemispherically around the front half of the model and simultaneously record videos using all four cameras. Furthermore, we benchmark results with state-of-the-art methods for various multi-modal ISLR settings on MM-WLAuslan, including multi-view, cross-camera, and cross-view. Experiment results indicate that MM-WLAuslan is a challenging ISLR dataset, and we hope this dataset will contribute to the development of Auslan and the advancement of sign languages worldwide. All datasets and benchmarks are available at MM-WLAuslan.
Heming Du, Hongwei Sheng, Hui Chen 0036, Huiqiang Chen, Zhuojie Wu, Xiaobiao Du, Jiaying Ying, Ruihan Lu, Qingzheng Xu, Xin Yu 0002
NeurIPS6
2024 M3A: A multimodal misinformation dataset for media authenticity analysis
abstract
With the development of various generative models, misinformation in news media becomes more deceptive and easier to create, posing a significant problem. However, existing datasets for misinformation study often have limited modalities, constrained sources, and a narrow range of topics. These limitations make it difficult to train models that can effectively combat real-world misinformation. To address this, we propose a comprehensive, large-scale Multimodal Misinformation dataset for Media Authenticity Analysis ( M 3 A ), featuring broad sources and fine-grained annotations for topics and sentiments. To curate M 3 A , we collect genuine news content from 60 renowned news outlets worldwide and generate fake samples using multiple techniques. These include altering named entities in texts, swapping modalities between samples, creating new modalities, and misrepresenting movie content as news. M 3 A contains 708K genuine news samples and over 6M fake news samples, spanning text, images, audio, and video. M 3 A provides detailed multi-class labels, crucial for various misinformation detection tasks, including out-of-context detection and deepfake detection. For each task, we offer extensive benchmarks using state-of-the-art models, aiming to enhance the development of robust misinformation detection systems. • We present M 3 A , a large-scale multimodal misinformation dataset with diverse news samples. • M 3 A includes texts, images, audio, and videos from multiple reputable news outlets. • M 3 A addresses limitations in existing datasets in misinformation generation methods and scale. • We provide multi-class annotations in M 3 A for various key tasks in misinformation detection. • We propose benchmarks for M 3 A using state-of-the-art models and out-of-distribution testing.
Qingzheng Xu, Huiqiang Chen, Heming Du, Hu Zhang 0005, Szymon Lukasik, Tianqing Zhu, Xin Yu 0002
Comput. Vis. Image Underst.2