VLDB 2026 Research / reviewers in the wild / expert
Zhankai Li
dblp:343/4334
· DBLP profile ↗
6ranked-venue papers
3as first author
6since 2021 · last 2026
0009-0006-0499-768XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 2 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Colorization-Driven Generative Secret Image SharingabstractTo enhance shares visual quality and security, meaningful secret image sharing relies on pre-input cover images to endow shadow images with interpretable semantics. However, the recently proposed schemes often yield shadows with mediocre visual quality and compromised security, such as vulnerability to statistical analysis or information leakage. Generative SIS (GSIS) introduces image generation or other operations, either to generate high-quality shadows or to eliminate the need for pre-input covers. Our prior \((2,2)\) -GSIS generated meaningful shares without covers but incurred non-critical leakage and did not support lossless reconstruction. Grayscale image colorization, being a widely adopted image processing operation, offers a promising route for GSIS by enriching semantics through chrominance synthesis. We introduce a colorization-driven GSIS. Chrominance components are shared via a \((k,n)\) -threshold SIS. Near-neutral chrominance from color templates provides structural priors that guide the synthesis of share pixels. The generated chrominance supersedes the template values and directly participates in colorization. This dynamic constraint departs from the linear modification paradigm of cover-based schemes, yielding shares that are visually natural and semantically preserved, without information leakage, and enabling lossless recovery from any \( k \) of \( n \) shares. Theoretical analysis and experiments validate the effectiveness and advantages of the framework. Xuehu Yan, Zhankai Li, Yongqiang Yu, Yuliang Lu, Tao Liu 0049 |
ACM Trans. Multim. Comput. Commun. Appl. | 3 |
| 2025 | Enhancing Transferability of Targeted Adversarial Examples Via Inverse Target Gradient Competition and Spatial Distance StretchingabstractIn the field of AI security, the vulnerability of deep neural networks has garnered widespread attention. Specifically, the sensitivity of DNNs to adversarial examples (AEs) can lead to severe consequences, even small perturbations in input data can result in incorrect predictions. AEs demonstrate transferability across models, however, targeted attack success rates (TASRs) remain low due to significant differences in feature dimensions and decision boundaries. To enhance the transferability of targeted AEs, we propose a novel approach by introducing Inverse Target Gradient Competition (ITC) and Spatial Distance Stretching (SDS) in the optimization process. Specifically, we utilize a twin-network-like framework to generate both non-targeted and targeted AEs, introducing a new competition mechanism ITC where non-targeted adversarial gradients are applied each epoch to hinder the optimization of targeted adversarial perturbations, thus enhancing robustness in targeted attacks. Additionally, a top-k SDS strategy is employed, guiding AEs to penetrate target class regions in the latent multi-dimensional space while globally distancing from multiple closest non-targeted regions, ultimately achieving optimal adversarial transferability. Compared with state-of-the-art competition-based attacks, our method demonstrates significant transferability advantages, with average transferable TASRs improved by 16.1% and 21.4% on mainstream CNNs and ViTs, respectively, while also achieving an unmatched breaking-through defense capability. Zhankai Li, Shigeng Zhang, Yunan Hu, Song Guo 0001 |
ICCV | 1 |
| 2024 | UCG: A Universal Cross-Domain Generator for Transferable Adversarial ExamplesabstractGenerating transferable adversarial examples is a challenging issue in adversarial example attacks. Existing works on transferable adversarial examples generation mainly focus on models with similar architectures and trained on the same data domain. However, in practice, information such as the model architecture type and training data domain is unlikely to be revealed in deployed models. In this work, we introduce the Universal Cross-domain Generator (UCG), a pioneering framework for transferable adversarial examples that is the first to simultaneously address both cross-domain and cross-architecture challenges in adversarial attacks. The design of UCG is mainly inspired by two key observations. First, there exists some commonality in attention regions even when the structures of models are different. Second, there exists prevalent instability of intermediate-feature maps across cross-domain models. We accordingly design anattention transfermechanism and aroughness abatementmechanism to enhance the cross-architecture and cross-domain transferability of the generated adversarial examples. Moreover, we propose anintegrated transformation processingtechnique to improve the transferability of the generated adversarial examples under different transformations. Experimental results demonstrate that, compared with state-of- the-art solutions, UCG improves the average transferable attack success rate by 15.3%, 7.9%, and 8.2% in the cross-architecture task (convolutional neural networks (CNNs) to vision transformers (ViTs)), coarse-grained cross-domain tasks, and fine-grained cross-domain tasks, respectively. Zhankai Li, Weiping Wang 0003, Jie Li 0086, Kai Chen 0012, Shigeng Zhang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Foolmix: Strengthen the Transferability of Adversarial Examples by Dual-Blending and Direction Update StrategyabstractAdversarial example attacks are deemed to be a serious threat to deep neural network (DNN) models. Generating adversarial examples in white-box settings has been well-studied, however, it remains challenging to generate transferable adversarial examples that successfully attack black-box models. This work proposes Foolmix, a novel method for generating transferable adversarial examples for black-box attacks. The design of Foolmix is inspired by our observation that adversarial examples with high transferability usually carry multi-class features in the latent space of DNN models. Thus, we propose a dual-blending strategy that blends the image with a set of random pixel-blocks and blends the gradient by calculating the loss of the blended image for both the ground-truth label and a set of random labels. The dual-blending strategy pressures the example to penetrate multiple class regions and gain multi-class features in the latent space, greatly enhancing the transferability of the generated adversarial example. However, the randomness in the blending process might also pressure the example to approach the boundary of the original class region, which lowers the robustness of the example. To mitigate this problem, we further propose an update method in the starting forward direction to guide the generated adversarial example to go deep into multi-class adversarial regions while being globally far away from the original class region. Compared to state-of-the-art transformation-based attacks, Foolmix significantly enhances the transferability of generated adversarial examples, boosting the average transferable attack success rate by 13.2% and 16.9% on mainstream CNNs and ViTs respectively, while achieving better defense breakthrough ability. Zhankai Li, Weiping Wang 0003, Jie Li 0086, Kai Chen 0012, Shigeng Zhang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | LSD: Adversarial Examples Detection Based on Label Sequences DiscrepancyabstractDeep neural network (DNN) models have been widely used in many tasks due to their superior performance. However, DNN models are usually vulnerable to adversarial example attacks, which limits their applications in many safety-critic scenarios. How to effectively detect adversarial examples to enhance the robustness of DNN models has attracted much attention in recent years. Most adversarial example detection methods require modifying or retraining the model, which is impractical and reduces the classification accuracy of normal examples. In this paper, we propose an adversarial example detection approach that does not require modification of the DNN models and meanwhile retains the classification accuracy of normal examples. The key observation is that when we transform the input example with some operations (e.g., masking a pixel with a reference value), feed the transformed example to the target model, and use the output of the intermediate layers to predict the label of the example, the generated label sequences of adversarial examples will be extremely discrepant but the label sequences of normal examples keep nearly unchanged. Motivated by this observation, we design an approach to detect adversarial examples based on the label sequence discrepancy (LSD) of the given examples. The experimental results against five mainstream adversarial attacks on three benchmark datasets demonstrate that LSD outperforms the state-of-the-art solutions in the detection rate of adversarial examples. Moreover, LSD performs well at various confidence levels and exhibits good generalizability between different attacks. Shigeng Zhang, Chengyao Hua, Zhetao Li, Yanchun Li, Xuan Liu 0001, Kai Chen 0012, Zhankai Li, Weiping Wang 0003 |
IEEE Trans. Inf. Forensics Secur. | 8 |
| 2022 | WBA: A Warping-based Approach to Generating Imperceptible Adversarial ExamplesabstractThe human can easily recognize the incongruous parts of an image, for example, perturbations unrelated to the image itself, but are poor at spotting the small geometric transformations. However, in terms of the robustness of deep neural networks (DNNs), the ability to properly recognize objects with small geometric transformations is still a challenge. In this work, we investigate the problem from the perspective of adversarial attacks: does the performance of DNNs degrade even when small geometric transformations are applied to images? To this end, we propose a novel adversarial attack method, called WBA, a Warping-Based Adversarial attack method, which does not introduce information independent of the original images but manipulates the existing pixels of the images by elastic warping transformations to generate adversarial examples that are imperceptible to the human eye. At the same time, existing adversarial attacks typically generate adversarial examples by modifying pixels in the spatial domain of the image, the addition of such perturbations introduces extra information unrelated to the image itself and is easily detected by the naked eyes. We demonstrate the effectiveness of WBA by extensive experiments on commonly used datasets, including MNIST, CIFAR10, and ImageNet. The results show that WBA can quickly generate adversarial examples with the highest adversarial strength, consumes less time, and can be comparable to optimization-based adversarial attack methods in image perception evaluation metrics such as LPIPS, SSIM, and far more than gradient direction-based iterative methods. Chengyao Hua, Shigeng Zhang, Weiping Wang 0003, Zhankai Li, Jian Zhang 0048 |
TrustCom | 4 |