Yuxuan Chou

dblp:395/6965 · DBLP profile ↗
← Back
2ranked-venue papers
1as first author
2since 2021 · last 2026
—ORCID · unresolved

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 2 · 1 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
2 papers
Trustworthy machine learning · 69% Deep learning architectures and training · 24% Reinforcement learning · 4%

Topics — the 11 heaviest of 11, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Deep learning architectures and training › data augmentation
adaptive data augmentation
1.012026
Improving Deepfake Detection with Reinforcement Learning-Based Adaptive Data Augmentation · AAAI 2026
Machine learning › Deep learning architectures and training
data augmentation
1.012026
Improving Deepfake Detection with Reinforcement Learning-Based Adaptive Data Augmentation · AAAI 2026
Machine learning › Trustworthy machine learning
deepfake detection
1.012026
Improving Deepfake Detection with Reinforcement Learning-Based Adaptive Data Augmentation · AAAI 2026
Machine learning › Trustworthy machine learning › deepfake detection
generalizable deepfake detection
1.012026
Improving Deepfake Detection with Reinforcement Learning-Based Adaptive Data Augmentation · AAAI 2026
Machine learning › Trustworthy machine learning › robustness
adversarial attack
0.912025
Breaking Barriers in Physical-World Adversarial Examples: Improving Robustness and Transferability via Robust Feature · AAAI 2025
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
0.912025
Breaking Barriers in Physical-World Adversarial Examples: Improving Robustness and Transferability via Robust Feature · AAAI 2025
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial transferability
0.912025
Breaking Barriers in Physical-World Adversarial Examples: Improving Robustness and Transferability via Robust Feature · AAAI 2025
Machine learning › Trustworthy machine learning › robustness › adversarial examples
physical adversarial example
0.912025
Breaking Barriers in Physical-World Adversarial Examples: Improving Robustness and Transferability via Robust Feature · AAAI 2025
Machine learning › Reinforcement learning
curriculum reinforcement learning
0.312026
Improving Deepfake Detection with Reinforcement Learning-Based Adaptive Data Augmentation · AAAI 2026
Machine learning › Trustworthy machine learning › adversarial machine learning
adversarial vulnerability
0.312025
Breaking Barriers in Physical-World Adversarial Examples: Improving Robustness and Transferability via Robust Feature · AAAI 2025
Computer vision › Vision and language › vision-language model
multimodal large language model
0.312025
Breaking Barriers in Physical-World Adversarial Examples: Improving Robustness and Transferability via Robust Feature · AAAI 2025

Methods — techniques the papers use, named apart from their topics

reinforcement learning · 1.0curriculum learning · 1.0causal inference · 1.0adversarial augmentation · 1.0robust feature injection · 0.9attention-based feature fusion · 0.9adversarial semantic pattern minimization · 0.9
YearPublicationVenuePosition
2026 Improving Deepfake Detection with Reinforcement Learning-Based Adaptive Data Augmentation
abstract
The generalization capability of deepfake detectors is crucial for real-world applications. Data augmentation to generate synthetic fake faces has served as an effective strategy to enhance generalization. Interestingly, current state-of-the-art (SoTA) methods rely on fixed augmentation strategies, raising a fundamental question: Can a single static augmentation approach suffice, or does the diversity of forgery features necessitate dynamic strategies? We argue that existing methods overlook the evolving complexity of real-world forgery patterns, such as facial warping, expression manipulation, and compression artifacts, which cannot be fully simulated by fixed policies. To bridge this gap, we propose CRDA (Curriculum Reinforcement-Learning Data Augmentation), a novel framework that guides the detector to progressively master multi-domain forgery features from simple to complex. CRDA synthesizes augmented samples using a configurable pool of forgery operations and dynamically generates adversarial samples tailored to the detector’s current learning state. Key to our approach is the integration of reinforcement learning (RL) and causal inference. To efficiently explore the vast augmentation space, an RL agent dynamically selects augmentation actions based on the detector’s performance, ensuring continuous adaptation to increasingly challenging forgeries. Simultaneously, the agent’s output is designed to introduce variations in action spaces, generating heterogeneous forgery patterns. These variations are guided by causal inference theory, which mitigates spurious correlations by suppressing task-irrelevant biases and enforcing the model to focus on causally invariant features. This integration ensures robust generalization by decoupling synthetic augmentation patterns from the model’s learned representations. Extensive experiments demonstrate that the proposed method significantly improves the generalizability of the detector, achieving superior performance compared to state-of-the-art methods on multiple cross-domain datasets.
Yuxuan Chou, Tao Dai 0001, Shutao Xia
AAAI1
2025 Breaking Barriers in Physical-World Adversarial Examples: Improving Robustness and Transferability via Robust Feature
abstract
As deep neural networks (DNNs) are widely applied in the physical world, many researches are focusing on physical-world adversarial examples (PAEs), which introduce perturbations to inputs and cause the model's incorrect outputs. However, existing PAEs face two challenges: unsatisfactory attack performance (i.e., poor transferability and insufficient robustness to environment conditions), and difficulty in balancing attack effectiveness with stealthiness, where better attack effectiveness often makes PAEs more perceptible. In this paper, we explore a novel perturbation-based method to overcome the challenges. For the first challenge, we introduce a strategy Deceptive RF injection based on robust features (RFs) that are predictive, robust to perturbations, and consistent across different models. Specifically, it improves the transferability and robustness of PAEs by covering RFs of other classes onto the predictive features in clean images. For the second challenge, we introduce another strategy Adversarial Semantic Pattern Minimization, which removes most perturbations and retains only essential adversarial patterns in AEs. Based on the two strategies, we design our method Robust Feature Coverage Attack (RFCoA), comprising Robust Feature Disentanglement and Adversarial Feature Fusion. In the first stage, we extract target class RFs in feature space. In the second stage, we use attention-based feature fusion to overlay these RFs onto predictive features of clean images and remove unnecessary perturbations. Experiments show our method's superior transferability, robustness, and stealthiness compared to existing state-of-the-art methods. Additionally, our method's effectiveness can extend to Large Vision-Language Models (LVLMs), indicating its potential applicability to more complex tasks.
Yichen Wang 0013, Yuxuan Chou, Ziqi Zhou 0001, Hangtao Zhang, Shengshan Hu
AAAI2