VLDB 2026 Research / reviewers in the wild / expert
Jiayou Lu
dblp:391/5114
· DBLP profile ↗
2ranked-venue papers
0as first author
2since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
2 papers |
Generative modeling · 100% | |
| Network and information security
2 papers |
Digital forensics and information hiding · 67% Security and privacy of machine learning · 33% | |
| Computer graphics and multimedia
1 paper |
Image and video coding · 100% |
Topics — the 6 heaviest of 6, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Generative modeling
diffusion model |
1.7 | 2 | 2025 | Robust Watermarking Using Generative Priors Against Image Editing: From Benchmarking to Advances · ICLR 2025 When and Where Do Data Poisons Attack Textual Inversion? · ICCV 2025 |
Machine learning › Generative modeling › diffusion model
image editing |
0.9 | 1 | 2025 | Robust Watermarking Using Generative Priors Against Image Editing: From Benchmarking to Advances · ICLR 2025 |
Security and privacy of machine learning
poisoning attack |
0.9 | 1 | 2025 | When and Where Do Data Poisons Attack Textual Inversion? · ICCV 2025 |
Digital forensics and information hiding › watermarking
robust watermarking |
0.9 | 1 | 2025 | Robust Watermarking Using Generative Priors Against Image Editing: From Benchmarking to Advances · ICLR 2025 |
Digital forensics and information hiding
watermarking |
0.9 | 1 | 2025 | Robust Watermarking Using Generative Priors Against Image Editing: From Benchmarking to Advances · ICLR 2025 |
Image and video coding
image quality assessment |
0.3 | 1 | 2025 | Robust Watermarking Using Generative Priors Against Image Editing: From Benchmarking to Advances · ICLR 2025 |
Methods — techniques the papers use, named apart from their topics
diffusion model adaptation · 2.6surrogate attacks · 1.7semantic sensitivity maps · 1.7safe-zone training · 1.7loss masking · 1.7JPEG compression · 1.7surrogate attack · 0.9
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | When and Where Do Data Poisons Attack Textual Inversion?abstractPoisoning attacks pose significant challenges to the robustness of diffusion models (DMs). In this paper, we systematically analyze when and where poisoning attacks textual inversion (TI), a widely used personalization technique for DMs. We first introduce Semantic Sensitivity Maps, a novel method for visualizing the influence of poisoning on text embeddings. Second, we identify and experimentally verify that DMs exhibit non-uniform learning behavior across timesteps, focusing on lower-noise samples. Poisoning attacks inherit this bias and inject adversarial signals predominantly at lower timesteps. Lastly, we observe that adversarial signals distract learning away from relevant concept regions within training data, corrupting the TI process. Based on these insights, we propose Safe-Zone Training (SZT), a novel defense mechanism comprised of 3 key components: (1) JPEG compression to weaken high-frequency poison signals, (2) restriction to high timesteps during TI training to avoid adversarial signals at lower timesteps, and (3) loss masking to constrain learning to relevant regions. Extensive experiments across multiple poisoning methods demonstrate that SZT greatly enhances the robustness of TI against all poisoning attacks, improving generative quality beyond prior published defenses. Code: www.github.com/JStyborski/Diff_Lab Data: www.github.com/JStyborski/NC10 Jeremy Styborski, Mingzhi Lyu, Jiayou Lu, Nupur Kapur, Adams Wai-Kin Kong |
ICCV | 3 |
| 2025 | Robust Watermarking Using Generative Priors Against Image Editing: From Benchmarking to AdvancesabstractCurrent image watermarking methods are vulnerable to advanced image editing techniques enabled by large-scale text-to-image models. These models can distort embedded watermarks during editing, posing significant challenges to copyright protection. In this work, we introduce W-Bench, the first comprehensive benchmark designed to evaluate the robustness of watermarking methods against a wide range of image editing techniques, including image regeneration, global editing, local editing, and image-to-video generation. Through extensive evaluations of eleven representative watermarking methods against prevalent editing techniques, we demonstrate that most methods fail to detect watermarks after such edits. To address this limitation, we propose VINE, a watermarking method that significantly enhances robustness against various image editing techniques while maintaining high image quality. Our approach involves two key innovations: (1) we analyze the frequency characteristics of image editing and identify that blurring distortions exhibit similar frequency properties, which allows us to use them as surrogate attacks during training to bolster watermark robustness; (2) we leverage a large-scale pretrained diffusion model SDXL-Turbo, adapting it for the watermarking task to achieve more imperceptible and robust watermark embedding. Experimental results show that our method achieves outstanding watermarking performance under various image editing techniques, outperforming existing methods in both image quality and robustness. Code is available at https://github.com/Shilin-LU/VINE Shilin Lu, Jiayou Lu, Adams Wai-Kin Kong |
ICLR | 3 |