VLDB 2026 Research / reviewers in the wild / expert
Yikun Xu
dblp:322/2254
· DBLP profile ↗
10ranked-venue papers
4as first author
10since 2021 · last 2026
0000-0001-8111-7566ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 3 · 1 first-author · 3 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Wavelet transform-based versatile watermarking for facial manipulation source tracing and detection
Yibo Zhang 0002, Weiguo Lin, Lei Shi 0030, Wanshan Xu, Yikun Xu, Feifei Kou |
Inf. Process. Manag. | 6 |
| 2026 | Adversarial example generation for infrared images
Weiguo Lin, Yikun Xu, Yong Gan |
Pattern Recognit. | 4 |
| 2025 | Deepfake Detection via 3D Face Reconstruction-Based Image BlendingabstractDeepfake technologies leverage deep learning to generate highly realistic videos involving face swapping and expression transfer, often exceeding the threshold of human visual perception. This poses serious challenges to social governance and digital security, highlighting the urgent need for reliable forgery detection methods. Training detection models without using real forgeries is considered a promising strategy to improve generalization. These approaches simulate diverse forgery traces to generate synthetic training data. However, most existing methods rely on 2 D image manipulation and fail to capture 3D forgery characteristics such as geometric distortion, expression mismatch, and texture anomalies-leading to poor performance on reconstruction-based forgeries. To address this problem, we propose a Reconstruction-Blended Image (RBI) generation method based on 3D Morphable Models (3DMM). By perturbing facial shape and expression parameters, this approach produces training samples that better reflect 3D reconstruction artifacts. When combined with traditional Self-Blended Images (SBI), the hybrid training strategy enhances the model's ability to detect a wider range of forgeries. Experiments show that this method improves AUC by$\mathbf{1 0. 7 9} \boldsymbol{\%}$on challenging cases like Face2Face forgeries. In summary, our 3D face reconstruction-based generation strategy significantly enhances the generalization and robustness of forgery detection models, offering a practical solution to emerging deepfake threats. Weiguo Lin, Mingyang Shao, Wanshan Xu, Jing Zhou 0004, Yikun Xu |
HPCC | 6 |
| 2025 | MLPN: Multi-Scale Laplacian Pyramid Network for deepfake detection and localizationabstractSophisticated and realistic facial manipulation videos created by deepfake technology have become ubiquitous, leading to profound trust crises and security risks in contemporary society. However, various researchers concentrate on enhancing the precision and generalization of deepfake detection models, with little attention to forgery localization. Detecting deepfakes and identifying fake regions is a challenging task. We propose an end-to-end model for performing deepfake detection and forgery localization based on the Laplacian pyramid. The model is designed by an encoder–decoder architecture. Specifically, the encoder generates multi-scale features. The decoder gradually integrates multi-scale features and Laplacian residuals to reconstruct the prediction masks coarse-to-finely. Otherwise, we adopt a spatial pyramid pool approach to deal with high-level semantic features and integrate local and global information. Comprehensive experiments demonstrate that the proposed model performs satisfactorily in deepfake detection and localization. Yibo Zhang 0002, Weiguo Lin, Wanshan Xu, Yikun Xu |
J. Inf. Secur. Appl. | 5 |
| 2025 | Robust and Unstigmatized Imperceptible Perturbations for Rendering Face Manipulation IneffectiveabstractThe widespread adoption of face manipulation systems has brought entertainment and convenience to users while posing significant challenges to media forensics. Conventional active defense strategies typically generate adversarial images by introducing perturbations into the original images. When adversarial images undergo facial manipulation, they often exhibit distortions or speckle artifacts, which helps reduce the dissemination of forged content on social media platforms. Nevertheless, the widespread dissemination of degraded images may contribute to facial stigmatization. Furthermore, conventional perturbation techniques are vulnerable to failure under JPEG compression and various image processing operations on OSN platforms. To address these challenges, we introduce a robust and unstigmatized imperceptible perturbation (RUIP) method designed to counteract face manipulation. First, RUIP utilizes an end-to-end adversarial training framework to generate robust and imperceptible perturbations. Second, to mitigate facial stigmatization, we incorporate both pixel-level and feature-level guidance losses during training, ensuring that the output images remain visually natural and closely aligned with the original images. Finally, we develop a novel module, the Flexible Random Enhancement Generator (FREG), to simulate complex JPEG compression and diverse image processing operations on OSN platforms, enhancing the model’s robustness against perturbations. Extensive qualitative and quantitative experiments demonstrate that the proposed method effectively defends against face manipulation attacks while preserving the visual quality of facial images under JPEG compression and other image processing operations on OSN platforms. We propose an effective and unstigmatized defense algorithm to safeguard privacy and maintain the stability of the social media ecosystem.Code is available athttps://github.com/silencecmsj/RUIP. Yibo Zhang 0002, Weiguo Lin, Zhihong Tian 0001, Geyong Min, Yikun Xu |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2024 | DSG:A Robustness-Enhanced Self-Supervised Depth Estimation MethodabstractDepth information in images is crucial for applications in autonomous driving, 3D reconstruction, and robot navigation. Self-supervised depth estimation methods have gained considerable attention because they rely solely on unlabeled video inputs. Traditional sensing equipment, such as LiDAR, incurs high costs and has limited effectiveness in adverse driving conditions, making image-based depth estimation a more economical and versatile alternative. However, real-world applications often involve diverse and noisy environmental conditions, whereas most existing models are trained on clean, ideal datasets. Our paper presents an advanced deep-learning method for robust self-supervised depth estimation, specifically designed to operate effectively under various dynamic scenes and noise conditions, which is called DSG. Our approach takes into account the noise and disturbances that can occur in 3 driving scenarios. Results on standard datasets demonstrate the model’s effectiveness, showing excellent robustness in handling noisy and diverse conditions. These strategies enhance the decision-making and safety evaluation capabilities of autonomous vehicles, facilitate the widespread adoption of low-cost sensing devices, and significantly improve model robustness in variable environments. The proposed self-supervised depth estimation method substantially enhances the reliability and accuracy of deep learning models, especially in dynamically changing application scenes. Changhao Zhao, Yikun Xu |
SNPD | 3 |
| 2023 | The Best Protection is Attack: Fooling Scene Text Recognition With Minimal PixelsabstractScene text recognition (STR) has witnessed tremendous progress in the era of deep learning, but it also raises concerns about privacy infringement as scene texts usually contain valuable or sensitive information. Previous works in privacy protection of scene texts mainly focus on masking out the texts from the image/video. In this work, we learn from the idea of adversarial examples and use minimal pixel perturbation to protect the privacy of text information. Although there are well-established attacking methods on non-sequential vision tasks (e.g., classification), the attack on sequential tasks (e.g., scene text recognition) has not received sufficient attention yet. Moreover, existing works mainly focus on the white-box setting, which requires complete knowledge of the target model (e.g., architecture, parameters, or gradients). These requirements limit the scope of applications for the white-box adversarial attack. Therefore, we propose a novel black-box attacking approach for the STR models, only requiring prior knowledge of the model output. Besides, instead of disturbing most pixels as in existing STR attack methods, our proposed approach only manipulates a few pixels, meaning the perturbation is more inconspicuous. To determine the location and value of the manipulated pixels, we also provide an efficient Adaptive-Discrete Differential Evolution (AD$^{2}\text{E}$) by narrowing down the continuous searching space to a discrete space. It can greatly reduce the queries to the target model. Experiments on several real-world benchmarks show the effectiveness of our proposed approach. Especially, when attacking the commercial STR engine, Baidu-OCR, our method achieves higher attack success rates by a large margin than existing approaches. Our work establishes an important step towards using the black-box adversarial attack with minimal pixels to protect the privacy of text information from being easily obtained by STR models. Yikun Xu, Pengwen Dai, Zekun Li 0007, Hongjun Wang 0005, Xiaochun Cao |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | A2SC: Adversarial Attacks on Subspace ClusteringabstractMany studies demonstrate that supervised learning techniques are vulnerable to adversarial examples. However, adversarial threats in unsupervised learning have not drawn sufficient scholarly attention. In this article, we formally address the unexplored adversarial attacks in the equally important unsupervised clustering field and propose the concept of the adversarial set and adversarial set attack for clustering. To illustrate the basic idea, we design a novel adversarial space-mapping attack algorithm to confuse subspace clustering, one of the mainstream branches of unsupervised clustering. It maps a sample into one wrong class by moving it towards the closest point on the linear subspace of the target class, that is, along the normal of the closest point. This simple single-step algorithm has the power to craft the adversarial set where the image samples can be wrongly clustered, even into the targeted labels. Empirical results on different image datasets verify the effectiveness and superiority of our algorithm. We further show that deep supervised learning algorithms (such as VGG and ResNet) are also vulnerable to our crafted adversarial set, which illustrates the good cross-task transferability of the adversarial set. Yikun Xu, Xingxing Wei 0001, Pengwen Dai, Xiaochun Cao |
ACM Trans. Multim. Comput. Commun. Appl. | 1 |
| 2022 | A2SC: Adversarial Attack on Subspace ClusteringabstractMany studies demonstrate supervised learning techniques are vulnerable to adversarial examples. However, adversarial threats in unsupervised learning have not drawn sufficient scholarly attention. In this paper, we formally address the unexplored adversarial attacks in the equally, if not more, important unsupervised clustering field and propose the concept of adversarial set. To illustrate the basic idea, we design an exemplary adversarial space-mapping attack algorithm to confuse subspace clustering, one of the mainstream branches of unsupervised clustering. It maps a sample into one wrong class by moving it towards the closest point on the linear subspace of the target class, i.e. along the normal of the closest point. The simple single-step algorithm is powerful to craft the adversarial set where the samples can be wrongly clustered, even into targeted labels. The adversarial set has the merit of transferability among subspace clustering schemes. Empirical results verify the effectiveness and transferability of our algorithm. Yikun Xu, Xingxing Wei 0001 |
ICME | 1 |
| 2021 | Less Is Better: Fooling Scene Text Recognition with Minimal Perturbations
Yikun Xu, Pengwen Dai, Xiaochun Cao |
ICONIP (6) | 1 |