VLDB 2026 Research / reviewers in the wild / expert
Chi Liu 0002
dblp:36/1312-2
· DBLP profile ↗
16ranked-venue papers
6as first author
15since 2021 · last 2026
0000-0002-6428-5514ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 7 · 3 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 3 first-author · 4 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Security and privacy · 2 · 2 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Rethinking Bias in Generative Data Augmentation for Medical AI: A Frequency Recalibration MethodabstractDeveloping Medical AI relies on large datasets and easily suffers from data scarcity. Generative data augmentation (GDA) using AI generative models offers a solution to synthesize realistic medical images. However, the bias in GDA is often underestimated in medical domains, with concerns about the risk of introducing detrimental features generated by AI and harming downstream tasks. This paper identifies the frequency misalignment between real and synthesized images as one of the key factors underlying unreliable GDA and proposes the Frequency Recalibration (FreRec) method to reduce the frequency distributional discrepancy and thus improve GDA. FreRec involves (1) Statistical High-frequency Replacement (SHR) to roughly align high-frequency components and (2) Reconstructive High-frequency Mapping (RHM) to enhance image quality and reconstruct high-frequency details. Extensive experiments were conducted in various medical datasets, including brain MRIs, chest X-rays, and fundus images. The results show that FreRec significantly improves downstream medical image classification performance compared to uncalibrated AI-synthesized samples. FreRec is a standalone post-processing step that is compatible with any generative model and can integrate seamlessly with common medical GDA pipelines. Chi Liu 0002, Congcong Zhu, Sheng Shen 0005, Tianqing Zhu, Wanlei Zhou 0001 |
AAAI | 1 |
| 2026 | Fundus image-based glaucoma screening via retinal knowledge-oriented dynamic multi-level feature integration
Chi Liu 0002, Yuzhuo Zhou, Sheng Shen 0005, ZongYuan Ge, Fengshi Jing, Shiran Zhang, Anli Wang, Feilong Yang, Tianqing Zhu, Xiaotong Han |
Knowl. Based Syst. | 1 |
| 2026 | Frequency Bias Matters: Diving Into Robust and Generalized Deep Image Forgery DetectionabstractAs deep image forgery powered by AI generative models, such as GANs, continues to challenge today's digital world, detecting AI-generated forgeries has become a vital security topic. Generalizability and robustness are two critical concerns of a forgery detector, determining its reliability when facing unknown GANs and noisy samples in an open world. Although many studies focus on improving these two properties, the root causes of these problems have not been fully explored, and it is unclear if there is a connection between them. Moreover, despite recent achievements in addressing these issues from image forensic or anti-forensic aspects, a universal method that can contribute to both sides simultaneously remains practically significant yet unavailable. In this paper, we provide a fundamental explanation of these problems from a frequency perspective. Our analysis reveals that the frequency bias of a DNN forgery detector is a possible cause of generalization and robustness issues. Based on this finding, we propose a two-step frequency alignment method to remove the frequency discrepancy between real and fake images, offering double-sided benefits: it can serve as a strong black-box attack against forgery detectors in the anti-forensic context or, conversely, as a universal defense to improve detector reliability in the forensic context. We also develop corresponding attack and defense implementations and demonstrate their effectiveness, as well as the effect of the frequency alignment method, in various experimental settings involving twelve detectors, eight forgery models, and five metrics Chi Liu 0002, Tianqing Zhu, Wanlei Zhou 0001, Wei Zhao 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | RetinaGuard: Obfuscating Retinal Age in Fundus Images for Biometric Privacy PreservingabstractThe integration of AI with medical images enables the extraction of implicit image-derived biomarkers for a precise health assessment. Recently, retinal age, a biomarker predicted from fundus images, has become a proven predictor of systemic disease risks, behavioral patterns, aging trajectory and even mortality. However, the capability to infer such sensitive biometric data raises significant privacy risks, where unauthorized use of fundus images could lead to bioinformation leakage, breaching individual privacy. In response, we formulate a new research problem of biometric privacy associated with medical images and propose RetinaGuard, a novel privacy-enhancing framework that employs a feature-level generative adversarial masking mechanism to obscure retinal age while preserving image visual quality and disease diagnostic utility. The framework further utilizes a novel multiple-to-one knowledge distillation strategy incorporating a retinal foundation model and diverse surrogate age encoders to enable a universal defense against black-box age prediction models. Comprehensive evaluations confirm that RetinaGuard successfully obfuscates retinal age prediction with minimal impact on image quality and pathological feature representation. RetinaGuard is also flexible for extension to other medical image-derived biomarkers. Zhengquan Luo, Chi Liu 0002, Dongfu Xiao, Yueye Wang, Tianqing Zhu |
BIBM | 2 |
| 2025 | Robust AI-Synthesized Image Detection via Multi-feature Frequency-Aware Learning
Hongfei Cai, Chi Liu 0002, Sheng Shen 0005, Youyang Qu, Peng Gui |
KSEM (1) | 2 |
| 2025 | Can LLMs Assist Computer Education? An Empirical Case Study of DeepSeek
Dongfu Xiao, Zhengquan Luo, Chi Liu 0002, Sheng Shen 0005 |
KSEM (2) | 4 |
| 2025 | Enhancing Fundus Image-Based Glaucoma Screening via Dynamic Global-Local Feature Integration
Yuzhuo Zhou, Chi Liu 0002, Sheng Shen 0005, Siyu Le, Sihan Ouyang, ZongYuan Ge |
KSEM (2) | 2 |
| 2025 | Prompt-Driven Latent Domain Generalization for Medical Image ClassificationabstractDeep learning models for medical image analysis easily suffer from distribution shifts caused by dataset artifact bias, camera variations, differences in the imaging station, etc., leading to unreliable diagnoses in real-world clinical settings. Domain generalization (DG) methods, which aim to train models on multiple domains to perform well on unseen domains, offer a promising direction to solve the problem. However, existing DG methods assume domain labels of each image are available and accurate, which is typically feasible for only a limited number of medical datasets. To address these challenges, we propose a unified DG framework for medical image classification without relying on domain labels, called Prompt-driven Latent Domain Generalization (PLDG). PLDG consists of unsupervised domain discovery and prompt learning. This framework first discovers pseudo domain labels by clustering the bias-associated style features, then leverages collaborative domain prompts to guide a Vision Transformer to learn knowledge from discovered diverse domains. To facilitate cross-domain knowledge learning between different prompts, we introduce a domain prompt generator that enables knowledge sharing between domain prompts and a shared prompt. A domain mixup strategy is additionally employed for more flexible decision margins and mitigates the risk of incorrect domain assignments. Extensive experiments on three medical image classification tasks and one debiasing task demonstrate that our method can achieve comparable or even superior performance than conventional DG algorithms without relying on domain labels. Our code is publicly available at https://github.com/SiyuanYan1/PLDG/tree/main. Siyuan Yan, Chi Liu 0002, Lie Ju, Dwarikanath Mahapatra, Brigid Betz-Stablein, Victoria Mar, Monika Janda, H. Peter Soyer, ZongYuan Ge |
IEEE Trans. Medical Imaging | 3 |
| 2024 | OphNet: A Large-Scale Video Benchmark for Ophthalmic Surgical Workflow Understanding
Peng Xia 0005, Lin Wang 0027, Siyuan Yan, Zhongxing Xu, Yimin Luo, Kaimin Song, Jürgen Leitner, Xuelian Cheng, Chi Liu 0002, Kaijing Zhou, ZongYuan Ge |
ECCV (4) | 12 |
| 2024 | DIsFU: Protecting Innocent Clients in Federated Unlearning
Fanyu Kong 0003, Xiangyun Tang, Tao Zhang 0009, Hongyang Du 0001, Jiawen Kang 0001, Chi Liu 0002 |
ICA3PP (4) | 7 |
| 2024 | Federated Learning With Heterogeneous Client Expectations: A Game Theory ApproachabstractIn federated learning (FL), local models are trained independently by clients, local model parameters are shared with a global aggregator or server, and then the updated model is used to initialize the next round of local training. FL and its variants have become synonymous with privacy-preserving distributed machine learning. However, most FL methods have maximization of model accuracy as their sole objective, and rarely are the clients’ needs and constraints considered. In this paper, we consider that clients have differing performance expectations and resource constraints, and we assume local data quality can be improved at a cost. In this light, we treat FL in the training phase as a game in satisfaction form that seeks to satisfy all clients’ expectations. We propose two novel FL methods, a deep reinforcement learning method and a stochastic method, that embrace this design approach. We also account for the scenario where certain clients can adjust their actions even after being satisfied, by introducing probabilistic parameters in both of our methods. The experimental results demonstrate that our proposed methods converge quickly to a lower cost solution than competing methods. Furthermore, it was found that the probabilistic parameters facilitate the attainment of satisfaction equilibria (SE), addressing scenarios where reaching SEs may be challenging within the confines of traditional games in satisfaction form. Sheng Shen 0005, Chi Liu 0002, Teng Joon Lim |
IEEE Trans. Knowl. Data Eng. | 2 |
| 2024 | High-Frequency Matters: Attack and Defense for Image-Processing Model WatermarkingabstractIn recent years, there has been significant advancement in the field of model watermarking techniques. However, the protection of image-processing neural networks remains a challenge, with only a limited number of methods being developed. The objective of these techniques is to embed a watermark in the output images of the target generative network, so that the watermark signal can be detected in the output of a surrogate model obtained through model extraction attacks. This promising technique, however, has certain limits. Analysis of the frequency domain reveals that the watermark signal is mainly concealed in the high-frequency components of the output. Thus, we propose an overwriting attack that involves forging another watermark in the output of the generative network. The experimental results demonstrate the efficacy of this attack in sabotaging existing watermarking schemes for image-processing networks with an almost 100% success rate. To counter this attack, we propose an adversarial framework for the watermarking network. The framework incorporates a specially-designed adversarial training step, where the watermarking network is trained to defend against the overwriting network, thereby enhancing its robustness. Additionally, we observe an overfitting phenomenon in the existing watermarking method, which can render it ineffective. To address this issue, we modify the training process to eliminate the overfitting problem. Huajie Chen, Tianqing Zhu, Chi Liu 0002, Shui Yu 0001, Wanlei Zhou 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2023 | Towards Robust Gan-Generated Image Detection: A Multi-View Completion RepresentationabstractGAN-generated image detection now becomes the first line of defense against the malicious uses of machine-synthesized image manipulations such as deepfakes. Although some existing detectors work well in detecting clean, known GAN samples, their success is largely attributable to overfitting unstable features such as frequency artifacts, which will cause failures when facing unknown GANs or perturbation attacks. To overcome the issue, we propose a robust detection framework based on a novel multi-view image completion representation. The framework first learns various view-to-image tasks to model the diverse distributions of genuine images. Frequency-irrelevant features can be represented from the distributional discrepancies characterized by the completion models, which are stable, generalized, and robust for detecting unknown fake patterns. Then, a multi-view classification is devised with elaborated intra- and inter-view learning strategies to enhance view-specific feature representation and cross-view feature aggregation, respectively. We evaluated the generalization ability of our framework across six popular GANs at different resolutions and its robustness against a broad range of perturbation attacks. The results confirm our method's improved effectiveness, generalization, and robustness over various baselines. Chi Liu 0002, Tianqing Zhu, Sheng Shen 0005, Wanlei Zhou 0001 |
IJCAI | 1 |
| 2023 | EPVT: Environment-Aware Prompt Vision Transformer for Domain Generalization in Skin Lesion Recognition
Siyuan Yan, Chi Liu 0002, Lie Ju, Dwarikanath Mahapatra, Victoria Mar, Monika Janda, H. Peter Soyer, ZongYuan Ge |
MICCAI (7) | 2 |
| 2023 | Making DeepFakes More Spurious: Evading Deep Face Forgery Detection via Trace Removal AttackabstractDeepFakes are raising significant social concerns. Although various Despite various DeepFake detectors having been developed as countermeasures, their vulnerability under attacks remains further explorations. Recently, several attacks, such as adversarial attacks, have successfully fooled DeepFake detectors. However, existing attacks suffer from detector-specific designs, requiring detector-side knowledge, leading to poor transferability. Moreover, they only consider simplified security scenarios; but less is known about the attacking performance in complex scenarios where the capability of detectors or attackers varies. To fill the gap, we propose a novel, detector-agnostic trace removal attack. The attack removes all possible counterfeiting traces arising from the original DeepFake manufacture procedure to make DeepFakes essentially more "realistic" and thus able to defeat arbitrary or unknown detectors. Concretely, we first perform an in-depth DeepFake trace discovery, identifying three intrinsic traces: spatial anomalies, spectral disparities, and noise fingerprints. Then an adversarial learning-based trace removal network (TR-Net) involving one generator and multiple discriminators is proposed. Each discriminator is responsible for one individual trace representation to avoid inner-trace interference. All discriminators are optimized in parallel to enforce the generator to remove various traces simultaneously. We additionally craft heterogeneous security scenarios where the detectors are embedded with different levels of defense and the attackers own varying background data knowledge. The experimental results show that the proposed trace removal attack can significantly compromise the detection accuracy of six state-of-the-art DeepFake detectors while causing only a negligible degradation in visual quality. Chi Liu 0002, Huajie Chen, Tianqing Zhu, Jun Zhang 0010, Wanlei Zhou 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2019 | Biological Age Estimated from Retinal Imaging: A Novel Biomarker of Aging
Chi Liu 0002, Zhixi Li, Xiaotong Han, Jason Ha, Mingguang He |
MICCAI (1) | 1 |