VLDB 2026 Research / reviewers in the wild / expert
Yunshu Dai
dblp:329/3050
· DBLP profile ↗
15ranked-venue papers
5as first author
15since 2021 · last 2026
0009-0004-6665-0978ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 12 · 5 first-author · 12 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 1 first-author · 7 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | One for All: Synthesis-Free Fingerprint Learning for Attribution of In-the-Wild Synthetic ImagesabstractAttributing synthetic images to their source generative models is critical for digital forensics and security. While most existing attribution methods can distinguish images produced by known models and reject those from unknown ones, they are unable to verify whether a given image was produced by a specific, previously unseen model. To address this limitation, we formulate an open-set verification problem: determining whether a given image was generated by a specific model. Our key insight is that synthetic images from different models show consistent, content-independent fingerprints in their amplitude spectrum. Based on this insight, we design a dynamic fingerprint simulator capable of simulating over 1.6 trillion generative model architectures. We further train an extractor to capture model-specific fingerprint representations with supervised contrastive learning, enabling accurate attribution of synthetic images, even from previously unseen models. Our method does not rely on any synthetic images, instead, it is trained solely on real images. On DMDetection and AIGCBenchmark, which comprises dozens of state-of-the-art and in-the-wild generative models, our method improves the attribution performance (AUC) of the prior method from random level to 94.05% and 83.05%, respectively. On GenImage and OSMA datasets, we obtain 85.08%, and 88.48% OSCR, outperforming the SOTA methods by 4.30% and 9.37% under the same settings. Jianwei Fei, Yunshu Dai, Peipeng Yu, Zhihua Xia, Dasara Shullani, Daniele Baracchi, Alessandro Piva |
AAAI | 2 |
| 2026 | Secure Distribution: Anti-collusion Watermarking via Spectral Weight Modulation in Latent Diffusion Models
Yunshu Dai, Jianwei Fei, Wenhong Huang, Fangjun Huang, Zhihua Xia |
Pattern Recognit. | 1 |
| 2025 | OmniMark: Efficient and Scalable Latent Diffusion Model FingerprintingabstractWe introduce OmniMark, a novel and efficient fingerprinting method for Latent Diffusion Models (LDM). OmniMark can encode user-specific fingerprints across diverse dimensions of the weights of the LDM, including kernels, filters, channels, and spatial domains. The LDM is fine-tuned to encode the invisible fingerprint into generated images, which can be decoded by a decoder. By altering fingerprints and re-encoding the weights, OmniMark supports efficient and scalable ad-hoc generation ( Jianwei Fei, Yunshu Dai, Zhihua Xia, Fangjun Huang |
AAAI | 2 |
| 2025 | DiffAttack: Imperceptible and Transferable Audio Adversarial Attack via Diffusion ModelabstractRecently, adversarial attacks on speaker recognition systems have garnered significant interest. However, existing methods focus on injecting subtle perturbations into audio, which may compromise auditory quality. To address this problem, we propose a novel approach named DiffAttack, which employs a diffusion model for generating high-quality adversarial samples. Firstly, we extract the Mel spectrogram of the original audio. Subsequently, the Mel spectrogram is optimized to fool the speaker recognition system while preserving the high auditory quality of the attacked audio. Lastly, a conditional diffusion model is used to reconstruct the adversarial audio from the optimized Mel spectrogram. Experimental evaluations on ECAPA and ResNet, two advanced speaker recognition systems, demonstrate that our method exceeds those state-of-the-art methods in terms of attack success rate, transferability, and auditory quality. Yunshu Dai, Fangjun Huang |
ICASSP | 2 |
| 2025 | Scalable Dual Fingerprinting for Hierarchical Attribution of Text-to-Image Models
Jianwei Fei, Yunshu Dai, Peipeng Yu, Zhe Kong, Zhihua Xia |
ICCV | 2 |
| 2025 | Robust Secure Swap: Responsible Face Swap With Persons of Interest Redaction and Provenance TraceabilityabstractAs AI generative models evolve, face swap technology has become increasingly accessible, raising concerns over potential misuse. Celebrities may be manipulated without consent, and ordinary individuals may fall victim to identity fraud. To address these threats, we propose Secure Swap, a method that protects persons of interest (POI) from face-swapping abuse and embeds a unique, invisible watermark into nonPOI swapped images for traceability. By introducing an ID Passport layer, Secure Swap redacts POI faces and generates watermarked outputs for nonPOI. A detachable watermark encoder and decoder are trained with the model to ensure provenance tracing. Experimental results demonstrate that Secure Swap not only preserves face swap functionality but also effectively prevents unauthorized swaps of POI and detects different embedded model’s watermarks with high accuracy. Specifically, our method achieves a 100% success rate in protecting POI and over 99% watermark extraction accuracy for nonPOI. Besides fidelity and effectiveness, the robustness of protected models against image-level and model-level attacks in both online and offline application scenarios is also experimentally demonstrated. Yunshu Dai, Jianwei Fei, Fangjun Huang, Chip-Hong Chang |
ICML | 1 |
| 2025 | Variance as a Catalyst: Efficient and Transferable Semantic Erasure Adversarial Attack for Customized Diffusion ModelsabstractLatent Diffusion Models (LDMs) enable fine-tuning with only a few images and have become widely used on the Internet. However, it can also be misused to generate fake images, leading to privacy violations and social risks. Existing adversarial attack methods primarily introduce noise distortions to generated images but fail to completely erase identity semantics.
In this work, we identify the variance of VAE latent code as a key factor that influences image distortion. Specifically, larger variances result in stronger distortions and ultimately erase semantic information. Based on this finding, we propose a Laplace-based (LA) loss function that optimizes along the fastest variance growth direction, ensuring each optimization step is locally optimal. Additionally, we analyze the limitations of existing methods and reveal that their loss functions often fail to align gradient signs with the direction of variance growth. They also struggle to ensure efficient optimization under different variance distributions. To address these issues, we further propose a novel Lagrange Entropy-based (LE) loss function.
Experimental results demonstrate that our methods achieve state-of-the-art performance on CelebA-HQ and VGGFace2. Both proposed loss functions effectively lead diffusion models to generate pure-noise images with identity semantics completely erased. Furthermore, our methods exhibit strong transferability across diverse models and efficiently complete attacks with minimal computational resources. Our work provides a practical and efficient solution for privacy protection. Yanmei Fang, Yunshu Dai, Fangjun Huang |
ICML | 4 |
| 2025 | Distributor-centric model watermarking for image generative models
Jianwei Fei, Yunshu Dai, Zhihua Xia |
Knowl. Based Syst. | 2 |
| 2025 | MNet: A multi-scale network for visible watermark removal
Wenhong Huang, Yunshu Dai, Jianwei Fei, Fangjun Huang |
Neural Networks | 2 |
| 2025 | New Visible Watermark Protection Mechanism Based on Information HidingabstractWith the rise of digital media, protecting image property has become a critical issue. Visible watermarks, once a key tool for copyright protection, have become increasingly vulnerable to removal methods using deep neural networks (DNNs). This poses a significant threat to the ability of visible watermarks to protect image ownership and copyright. To address this increasingly severe challenge, we propose a novel visible watermark protection mechanism based on information hiding. Unlike traditional methods of directly adding perturbations to protected images, we hide adversarial perturbations in watermarked images through a specially designed reversible information exchange (RIE) module, which includes multiple discrete wavelet transform (DWT) and affine coupling blocks. This design can concentrate the perturbations on textured areas of the watermarked images, making them less visually noticeable. Meanwhile, theoretical analysis indicates that the difference between the adversarial image (i.e., the watermarked image after embedding the adversarial perturbation) generated by our method and the watermarked image is completely controllable. To evaluate the proposed mechanism in various scenarios, based on several widely used datasets (i.e., LOGO-Gray, LOGO-H, and LOGO-L), we further synthesize two new datasets, namely LOGO-Multi and LOGO-Full. LOGO-Multi contains images embedded with multiple watermarks, and LOGO-Full contains images embedded with a watermark covering the whole image. Extensive testing on five datasets demonstrates that, compared to the baseline methods, the proposed scheme can greatly improve the visual quality of adversarial images and enhance their capability to resist various watermark removal techniques. Wenhong Huang, Yunshu Dai, Jianwei Fei, Fangjun Huang |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | IDGuard: Robust, General, Identity-Centric POI Proactive Defense Against Face Editing AbuseabstractIn this work, we propose IDGuard, a novel proactive defense method from the perspective of developers, to protect Persons-of-Interest (POI) such as national leaders from face editing abuse. We build a bridge between identities and model behavior, safeguarding POI identities rather than merely certain face images. Given a face editing model, IDGuard enables it to reject editing any image containing POI identities while retaining its editing functionality for regular use. Specifically, we insert an ID Normalization Layer into the original face editing model and introduce an ID Extractor to extract the identities of input images. To differentiate the editing behavior between POI and nonPOI, we use a transformer-based ID Encoder to encode extracted POI identities as parameters of the ID Normalization Layer. Our method supports the simultaneous protection of multiple POI and allows for the addition of new POI in the inference stage, without the need for retraining. Extensive experiments show that our method achieves 100% protection accuracy on POI images even if they are neither included in the training set nor subject to any preprocessing. Notably, our method exhibits excellent robustness against image and model attacks and maintains 100% protection performance when generalized to various face editing models, further demonstrating its practicality. Yunshu Dai, Jianwei Fei, Fangjun Huang |
CVPR | 1 |
| 2024 | Face Omron Ring: Proactive defense against face forgery with identity awareness
Yunshu Dai, Jianwei Fei, Fangjun Huang, Zhihua Xia |
Neural Networks | 1 |
| 2023 | General GAN-generated Image Detection by Data Augmentation in Fingerprint DomainabstractIn this work, we investigate improving the generalizability of GAN-generated image detectors by performing data augmentation in the fingerprint domain. Specifically, we first separate the fingerprints and contents of the GAN-generated images using an autoencoder based GAN fingerprint extractor, followed by random perturbations of the fingerprints. Then the original fingerprints are substituted with the perturbed fingerprints and added to the original contents, to produce images that are visually invariant but with distinct fingerprints. The perturbed images can successfully imitate images generated by different GANs to improve the generalization of the detectors, which is demonstrated by the spectra visualization. To our knowledge, we are the first to conduct data augmentation in the fingerprint domain. Our work explores a novel prospect that is distinct from previous works on spatial and frequency domains augmentation. Extensive cross-GAN experiments demonstrate the effectiveness of our method compared to the state-of-the-art methods in detecting fake images generated by unknown GANs. Huaming Wang, Jianwei Fei, Yunshu Dai, Lingyun Leng, Zhihua Xia |
ICME | 3 |
| 2022 | Learning Second Order Local Anomaly for General Face Forgery DetectionabstractIn this work, we propose a novel method to improve the generalization ability of CNN-based face forgery detectors. Our method considers the feature anomalies of forged faces caused by the prevalent blending operations in face forgery algorithms. Specifically, we propose a weakly supervised Second Order Local Anomaly (SOLA) learning module to mine anomalies in local regions using deep feature maps. SOLA first decomposes the neighborhood of local features by different directions and distances and then calculates the first and second order local anomaly maps which provide more general forgery traces for the classifier. We also propose a Local Enhancement Module (LEM) to improve the discrimination between local features of real and forged regions, so as to ensure accuracy in calculating anomalies. Besides, an improved Adaptive Spatial Rich Model (ASRM) is introduced to help mine subtle noise features via learnable high pass filters. With neither pixel level annotations nor external synthetic data, our method using a simple ResNet18 backbone achieves competitive performances compared with state-of-the-art works when evaluated on unseen forgeries. Jianwei Fei, Yunshu Dai, Peipeng Yu, Tianrun Shen, Zhihua Xia, Jian Weng 0001 |
CVPR | 2 |
| 2022 | Attentional Local Contrastive Learning for Face Forgery Detection
Yunshu Dai, Jianwei Fei, Huaming Wang, Zhihua Xia |
ICANN (1) | 1 |