Caixin Kang

dblp:330/9728 · DBLP profile ↗
← Back
7ranked-venue papers
1as first author
7since 2021 · last 2026
0009-0001-1924-9311ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 6 · 1 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-author · 4 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
6 papers
Trustworthy machine learning · 43% 3D vision · 22% Generative modeling · 20%
Network and information security
3 papers
Security and privacy of machine learning · 100%
Databases, data mining, and information retrieval
1 paper
Information retrieval · 100%

Topics — the 21 heaviest of 22, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning
robustness
2.132025
AdvDreamer Unveils: Are Vision-Language Models Truly Ready for Real-World 3D Variations? · ICCV 2025
Benchmarking Robustness of 3D Object Detection to Common Corruptions in Autonomous Driving · CVPR 2023
ViewFool: Evaluating the Robustness of Visual Recognition to Adversarial Viewpoints · NeurIPS 2022
Security and privacy of machine learning
adversarial defense
1.622025
Real-World Adversarial Defense Against Patch Attacks Based on Diffusion Model · IEEE Trans. Pattern Anal. Mach. Intell. 2025
DIFFender: Diffusion-Based Adversarial Defense Against Patch Attacks · ECCV (52) 2024
Information retrieval › evaluation › benchmark
robustness benchmark
1.012026
SQuTR: A Robustness Benchmark for Spoken Query to Text Retrieval under Acoustic Noise · SIGIR 2026
Information retrieval › document retrieval › spoken document retrieval
spoken query retrieval
1.012026
SQuTR: A Robustness Benchmark for Spoken Query to Text Retrieval under Acoustic Noise · SIGIR 2026
Machine learning › Generative modeling
diffusion model
0.912025
Real-World Adversarial Defense Against Patch Attacks Based on Diffusion Model · IEEE Trans. Pattern Anal. Mach. Intell. 2025
Machine learning › Generative modeling › diffusion model › conditional diffusion model
text-guided diffusion model
0.912025
Real-World Adversarial Defense Against Patch Attacks Based on Diffusion Model · IEEE Trans. Pattern Anal. Mach. Intell. 2025
Security and privacy of machine learning › adversarial defense
adversarial patch defense
0.912025
Real-World Adversarial Defense Against Patch Attacks Based on Diffusion Model · IEEE Trans. Pattern Anal. Mach. Intell. 2025
Security and privacy of machine learning › adversarial attack
jailbreak attack
0.912025
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency · ICCV 2025
Security and privacy of machine learning › adversarial attack
multimodal adversarial attack
0.912025
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency · ICCV 2025
Security and privacy of machine learning › adversarial attack › multimodal adversarial attack
vision-language model attack
0.912025
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency · ICCV 2025
Security and privacy of machine learning
adversarial attack
0.812024
DIFFender: Diffusion-Based Adversarial Defense Against Patch Attacks · ECCV (52) 2024
Security and privacy of machine learning › adversarial attack › physical adversarial attack
adversarial patch
0.812024
DIFFender: Diffusion-Based Adversarial Defense Against Patch Attacks · ECCV (52) 2024
Computer vision › 3D vision
3d object detection
0.712023
Benchmarking Robustness of 3D Object Detection to Common Corruptions in Autonomous Driving · CVPR 2023
Machine learning › Trustworthy machine learning › robustness
corruption robustness
0.712023
Benchmarking Robustness of 3D Object Detection to Common Corruptions in Autonomous Driving · CVPR 2023
Machine learning › Trustworthy machine learning › robustness evaluation
corruption robustness benchmark
0.712023
Benchmarking Robustness of 3D Object Detection to Common Corruptions in Autonomous Driving · CVPR 2023
Computer vision › 3D vision › 3d object detection
robust 3d detection
0.712023
Benchmarking Robustness of 3D Object Detection to Common Corruptions in Autonomous Driving · CVPR 2023
Computer vision › 3D vision
neural radiance field
0.612022
ViewFool: Evaluating the Robustness of Visual Recognition to Adversarial Viewpoints · NeurIPS 2022
Computer vision › Image recognition and object detection
image classification
0.422025
Real-World Adversarial Defense Against Patch Attacks Based on Diffusion Model · IEEE Trans. Pattern Anal. Mach. Intell. 2025
ViewFool: Evaluating the Robustness of Visual Recognition to Adversarial Viewpoints · NeurIPS 2022
Computer vision › Face, body and person analysis
face recognition
0.312025
Real-World Adversarial Defense Against Patch Attacks Based on Diffusion Model · IEEE Trans. Pattern Anal. Mach. Intell. 2025
Machine learning › Trustworthy machine learning › generative model safety
multimodal large language model safety
0.312025
Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency · ICCV 2025
Computer vision › Vision and language
vision-language model
0.312025
AdvDreamer Unveils: Are Vision-Language Models Truly Ready for Real-World 3D Variations? · ICCV 2025

Methods — techniques the papers use, named apart from their topics

diffusion model · 2.5noise mixing · 2.0benchmark construction · 2.0toxic judge model · 1.7query-based black-box optimization · 1.7few-shot prompt tuning · 1.7naturalness reward model · 0.9generative 3d priors · 0.9adversarial optimization · 0.9corruption synthesis · 0.7
YearPublicationVenuePosition
2026 SQuTR: A Robustness Benchmark for Spoken Query to Text Retrieval under Acoustic Noise
abstract
Spoken query retrieval is an important interaction mode in modern information retrieval. However, existing evaluation datasets are often limited to simple queries under constrained noise conditions, making them inadequate for assessing the robustness of spoken query retrieval systems under complex acoustic perturbations. To address this limitation, we present SQuTR, a robustness benchmark for spoken query retrieval that includes a large-scale dataset and a unified evaluation protocol. SQuTR aggregates 37,317 unique queries from six commonly used English and Chinese text retrieval datasets, spanning multiple domains and diverse query types. We synthesize speech using voice profiles from 200 real speakers and mix 17 categories of real-world environmental noise under controlled SNR levels, enabling reproducible robustness evaluation from quiet to highly noisy conditions. Under the unified protocol, we conduct large-scale evaluations on representative cascaded and end-to-end retrieval systems. Experimental results show that retrieval performance decreases as noise increases, with substantially different drops across systems. Even large-scale retrieval models struggle under extreme noise, indicating that robustness remains a critical bottleneck. Overall, SQuTR provides a reproducible testbed for benchmarking and diagnostic analysis, and facilitates future research on robustness in spoken query to text retrieval.
Yueying Hua, Jianhao Nie, Yueping He, Caixin Kang
SIGIR7
2025 AdvDreamer Unveils: Are Vision-Language Models Truly Ready for Real-World 3D Variations?
abstract
Vision Language Models (VLMs) have exhibited remarkable generalization capabilities, yet their robustness in dynamic real-world scenarios remains largely unexplored. To systematically evaluate VLMs' robustness to real-world 3D variations, we propose AdvDreamer, the first framework capable of generating physically reproducible Adversarial 3D Transformation (Adv-3DT) samples from single-view observations. In AdvDreamer, we integrate three key innovations: Firstly, to characterize real-world 3D variations with limited prior knowledge precisely, we design a zero-shot Monocular Pose Manipulation pipeline built upon generative 3D priors. Secondly, to ensure the visual quality of worst-case Adv-3DT samples, we propose a Naturalness Reward Model that provides continuous naturalness regularization during adversarial optimization, effectively preventing convergence to hallucinated or unnatural elements. Thirdly, to enable systematic evaluation across diverse VLM architectures and visual-language tasks, we introduce the Inverse Semantic Probability loss as the adversarial optimization objective, which solely operates in the fundamental visual-textual alignment space. Based on the captured Adv-3DT samples with high aggressiveness and transferability, we establish MM3DTBench, the first VQA benchmark dataset tailored to evaluate VLM robustness under challenging 3D variations. Extensive evaluations of representative VLMs with varying architectures reveal that real-world 3D variations can pose severe threats to model performance across various tasks.
Shouwei Ruan, Caixin Kang, Hang Su 0006, Yinpeng Dong, Xingxing Wei 0001
ICCV5
2025 Jailbreaking Multimodal Large Language Models via Shuffle Inconsistency
abstract
Multimodal Large Language Models (MLLMs) have achieved impressive performance and have been put into practical use in commercial applications, but they still have potential safety mechanism vulnerabilities. Jailbreak attacks are red teaming methods that aim to bypass safety mechanisms and discover MLLMs' potential risks. Existing MLLMs' jailbreak methods often bypass the model's safety mechanism through complex optimization methods or carefully designed image and text prompts. Despite achieving some progress, they have a low attack success rate on commercial closed-source MLLMs. Unlike previous research, we empirically find that there exists a Shuffle Inconsistency between MLLMs' comprehension ability and safety ability for the shuffled harmful instruction. That is, from the perspective of comprehension ability, MLLMs can understand the shuffled harmful text-image instructions well. However, they can be easily bypassed by the shuffled harmful instructions from the perspective of safety ability, leading to harmful responses. Then we innovatively propose a text-image jailbreak attack named SI-Attack. Specifically, to fully utilize the Shuffle Inconsistency and overcome the shuffle randomness, we apply a query-based black-box optimization method to select the most harmful shuffled inputs based on the feedback of the toxic judge model. A series of experiments show that SI-Attack can improve the attack's performance on three benchmarks. In particular, SI-Attack can obviously improve the attack success rate for commercial MLLMs such as GPT-4o or Claude-3.5-Sonnet.
Ranjie Duan, Caixin Kang, Shouwei Ruan, Jialing Tao, Yuefeng Chen, Hui Xue 0001, Xingxing Wei 0001
ICCV5
2025 Real-World Adversarial Defense Against Patch Attacks Based on Diffusion Model
abstract
Adversarial patches present significant challenges to the robustness of deep learning models, making the development of effective defenses become critical for real-world applications. This paper introduces DIFFender, a novel DIFfusion-based DeFender framework that leverages the power of a text-guided diffusion model to counter adversarial patch attacks. At the core of our approach is the discovery of the Adversarial Anomaly Perception (AAP) phenomenon, which enables the diffusion model to accurately detect and locate adversarial patches by analyzing distributional anomalies. DIFFender seamlessly integrates the tasks of patch localization and restoration within a unified diffusion model framework, enhancing defense efficacy through their close interaction. Additionally, DIFFender employs an efficient few-shot prompt-tuning algorithm, facilitating the adaptation of the pre-trained diffusion model to defense tasks without the need for extensive retraining. Our comprehensive evaluation, covering image classification and face recognition tasks, as well as real-world scenarios, demonstrates DIFFender's robust performance against adversarial attacks. The framework's versatility and generalizability across various settings, classifiers, and attack methodologies mark a significant advancement in adversarial patch defense strategies. Except for the popular visible domain, we have identified another advantage of DIFFender: its capability to easily expand into the infrared domain. Consequently, we demonstrate the good flexibility of DIFFender, which can defend against both infrared and visible adversarial patch attacks alternatively using a universal defense framework.
Xingxing Wei 0001, Caixin Kang, Yinpeng Dong, Shouwei Ruan, Yubo Chen 0008, Hang Su 0006
IEEE Trans. Pattern Anal. Mach. Intell.2
2024 DIFFender: Diffusion-Based Adversarial Defense Against Patch Attacks
Caixin Kang, Yinpeng Dong, Shouwei Ruan, Yubo Chen 0008, Hang Su 0006, Xingxing Wei 0001
ECCV (52)1
2023 Benchmarking Robustness of 3D Object Detection to Common Corruptions in Autonomous Driving
abstract
3D object detection is an important task in autonomous driving to perceive the surroundings. Despite the excellent performance, the existing 3D detectors lack the robustness to real-world corruptions caused by adverse weathers, sensor noises, etc., provoking concerns about the safety and reliability of autonomous driving systems. To comprehensively and rigorously benchmark the corruption robustness of 3D detectors, in this paper we design 27 types of common corruptions for both LiDAR and camera inputs considering realworld driving scenarios. By synthesizing these corruptions on public datasets, we establish three corruption robustness benchmarks-KITTI-C, nuScenes-C, and Waymo-C. Then, we conduct large-scale experiments on 24 diverse 3D object detection models to evaluate their corruption robustness. Based on the evaluation results, we draw several important findings, including: 1) motion-level corruptions are the most threatening ones that lead to significant performance drop of all models; 2) LiDAR-camerafusion models demonstrate better robustness; 3) camera-only models are extremely vulnerable to image corruptions, showing the indispensability of LiDAR point clouds. We release the benchmarks and codes at https://github.com/thu-ml/3D_Corruptions_AD to be helpful for future studies.
Yinpeng Dong, Caixin Kang, Jinlai Zhang, Yikai Wang 0001, Xiao Yang 0028, Hang Su 0006, Xingxing Wei 0001, Jun Zhu 0001
CVPR2
2022 ViewFool: Evaluating the Robustness of Visual Recognition to Adversarial Viewpoints
abstract
Recent studies have demonstrated that visual recognition models lack robustness to distribution shift. However, current work mainly considers model robustness to 2D image transformations, leaving viewpoint changes in the 3D world less explored. In general, viewpoint changes are prevalent in various real-world applications (e.g., autonomous driving), making it imperative to evaluate viewpoint robustness. In this paper, we propose a novel method called ViewFool to find adversarial viewpoints that mislead visual recognition models. By encoding real-world objects as neural radiance fields (NeRF), ViewFool characterizes a distribution of diverse adversarial viewpoints under an entropic regularizer, which helps to handle the fluctuations of the real camera pose and mitigate the reality gap between the real objects and their neural representations. Experiments validate that the common image classifiers are extremely vulnerable to the generated adversarial viewpoints, which also exhibit high cross-model transferability. Based on ViewFool, we introduce ImageNet-V, a new out-of-distribution dataset for benchmarking viewpoint robustness of image classifiers. Evaluation results on 40 classifiers with diverse architectures, objective functions, and data augmentations reveal a significant drop in model performance when tested on ImageNet-V, which provides a possibility to leverage ViewFool as an effective data augmentation strategy to improve viewpoint robustness.
Yinpeng Dong, Shouwei Ruan, Hang Su 0006, Caixin Kang, Xingxing Wei 0001, Jun Zhu 0001
NeurIPS4