VLDB 2026 Research / reviewers in the wild / expert
Xing Yang 0004
dblp:48/2364-4
· DBLP profile ↗
23ranked-venue papers
0as first author
23since 2021 · last 2026
0000-0002-8824-1356ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 10 · 10 since 2021Artificial intelligence and machine learning · 7 · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 since 2021Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | ObjectAdv: Object-Level Unrestricted Adversarial Attacks via Diffusion ModelsabstractUnrestricted adversarial attacks aim to fool DNNs by generating effective yet photorealistic examples. However, previous methods usually rely on global perturbations to enhance attack performance, which inevitably introduces visual distortions. To reduce visual distortions in the background, we propose a diffusion-based framework that focuses on local perturbations to generate object-level unrestricted adversarial examples (ObjectAdv). Since the cross-attention maps of Stable Diffusion contain the object information, we directly leverage the attention maps to localize the semantic region of object where for attacking. Second, a prompt-switching strategy is proposed for both imperceptibility and attack capacity. Specifically, to preserve layout and object shape of clean image, a prompt of true category is used at early denoising steps. At the later steps, we propose a well-designed prompt to guide the diffusion model to generate transferable adversarial examples. This local attack may cause inconsistency between the perturbed object and the background in adversarial examples. An FFT-based edge smoother is utilized to ensure seamless blending of the edges. ObjectAdv achieves an average ASR of 99.2% in white-box test on the ImageNet-compatible dataset, and outperforms existing methods on defense performance (+5%) and image quality metrics, e.g., SSIM of 0.9140 (+0.1048) and FID of 25.63 (-19.27). Xing Yang 0004, Haoqi Gao, Anjie Peng, Hui Zeng 0002 |
AAAI | 3 |
| 2026 | Salient feature aware network for red-green-blue-thermal crowd counting
Shenjian Gong, Yu Zhang 0091, Xing Yang 0004 |
Eng. Appl. Artif. Intell. | 5 |
| 2026 | Targeted attack via adversarial patch outside bounding box
Kang Deng, Qixiang Chen, Yu Zhang 0091, Shenjian Gong, Anjie Peng, Xing Yang 0004, Defu Lian |
Pattern Recognit. | 8 |
| 2026 | Understanding the adversarial robustness of deep learning-based single-pixel imaging
Yunfeng Diao, Hua Mu, Haoqi Gao, Zhaoxin Fan, Xing Yang 0004 |
Pattern Recognit. | 9 |
| 2026 | Hijack Vertical Federated Learning Models as One PartyabstractVertical Federated Learning (VFL) is an emerging paradigm that enables collaborators to build machine learning models together in a distributed fashion. However, the security of the VFL model remains underexplored, particularly regarding the Byzantine Generals Problem (BGP), which is a well-known issue in distributed systems. This paper focuses on revealing the threat of BGP in VFL systems. Specifically, we propose two attacks, the replay attack and the generation attack, to evaluate the vulnerability of VFL when there is only one malicious party. The goal of the adversary is to hijack the VFL model to give desired predictions. Moreover, considering the uneven distribution of importance among parties, we combine data poisoning with the aforementioned attacks to explore whether they can bypass the situation where the adversary has few features. The evaluation results demonstrate the effectiveness of our attacks. For instance, the adversary holding only 10 90 capability is limited and usually at the cost of performance loss of the VFL task. Our work highlights the need for advanced defenses to protect the prediction results of a VFL model and calls for more exploration of VFL's security issues. Pengyu Qiu, Xuhong Zhang 0002, Shouling Ji, Changjiang Li, Yuwen Pu, Xing Yang 0004, Ting Wang 0006 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2026 | Adversarial Semantic and Label Perturbation Attack for Pedestrian Attribute RecognitionabstractPedestrian Attribute Recognition (PAR) is an indispensable task in human-centered research and has made great progress in recent years with the development of deep neural networks. However, the potential vulnerability and anti-interference ability have still not been fully explored. To bridge this gap, this paper proposes the first adversarial attack and defense framework for pedestrian attribute recognition. Specifically, we exploit both global- and patch-level attacks on the pedestrian images, based on the pre-trained CLIP-based PAR framework. It first divides the input pedestrian image into non-overlapping patches and embeds them into feature embeddings using a projection layer. Meanwhile, the attribute set is expanded into sentences using prompts and embedded into attribute features using a pre-trained CLIP text encoder. A multi-modal Transformer is adopted to fuse the obtained vision and text tokens, and a feed-forward network is utilized for attribute recognition. Based on the aforementioned PAR framework, we adopt the adversarial semantic and label-perturbation to generate the adversarial noise, termed ASL-PAR. We also design a semantic offset defense strategy to suppress the influence of adversarial attacks. Extensive experiments conducted on both digital domains (i.e., PETA, PA100K, MSP60K, RAPv2) and physical domains fully validated the effectiveness of our proposed adversarial attack and defense strategies for the pedestrian attribute recognition. The source code of this paper will be released on https://github.com/Event-AHU/OpenPAR. Weizhe Kong, Xiao Wang 0014, Ruichong Gao, Chenglong Li 0002, Yu Zhang 0091, Xing Yang 0004, Yaowei Wang 0001, Jin Tang 0001 |
IEEE Trans. Inf. Forensics Secur. | 6 |
| 2025 | FCA-MARS: Full-Coverage Adversarial Camouflage for Few-Shot Ships with Multi-Angle Attack RobustnessabstractAdversarial attacks against ship targets are urgently needed to enhance naval stealth capabilities but face dual bottlenecks of data scarcity and physical implementation. Existing datasets fail to cover multi-view characteristics of complex aquatic environments, which restricts the optimization of adversarial textures. Compared to current mature vehicle adversarial attacks, traditional attack methods prove ineffective when applied to ships due to discontinuous surfaces (e.g., containers/decks) and dynamic waterborne interference (illumination fluctuations and wide viewing-angle variations). To address these issues, we proposed FCA-MARS (Full-Coverage Adversarial Camouflage for Few-Shot Ships with Multi-Angle Attack Robustness), a framework that combines Full-Coverage Adversarial rendering with marine-specific EOT optimization. First, we constructed the field's first high-fidelity ship dataset using Unreal Engine 4(UE4), containing over$\text{1 4, 0 0 0}$multi-scenario samples to overcome few-shot limitations. Second, we integrated differentiable rendering with the Expectation Over Transformation (EOT) framework. This integration achieved geometry-adaptive texture mapping on discontinuous surfaces while maintaining robustness against environmental disturbances. Experimental validation demonstrated strong results: an$\text{8 3. 4 \%}$attack success rate (ASR) in digital tests, 86.5% ASR in physical simulations, and a 98.25% close-range evasion rate. This approach established a physically deployable solution for maritime defense by solving the persistent challenge of camouflaging complex discontinuous geometries. Yaoran Wang, Haoqi Gao, Anjie Peng, Hui Zeng 0002, Xing Yang 0004 |
ICPADS | 6 |
| 2025 | TLENet: Two-stage Low-light Enhancement Network Based on Illuminance AdaptationabstractLow-light environments commonly cause significant degradation in image quality, thereby negatively impacting vision-related multimedia retrieval processes. Despite the advent of numerous promising low-light image enhancement techniques, restoring color fidelity and reducing noise while enhancing image brightness remains a non-trivial task. Moreover, the issue of inadequate or overly enhancement in some enhanced images further complicates the matter. To address these challenges, we introduce TLENet, a low light enhancement network based on two-stage training and single-stage testing. Specifically, TLENet first features a Color Illumination Adjustment (CIA) module, which leverages spatial information from the HSV color space to achieve precise color adjustment of images. Then, to mitigate noise amplification, TLENet incorporates a Bilateral Feature Mutual Guidance Denoising (BMGD) module. This module effectively extracts both global and local features, ensuring comprehensive image content restoration, while utilizing advanced attention mechanisms for enhanced denoising capabilities. At last, TLENet incorporates the Illumination Parameter Adaptation (IPA) module to accomplish adaptive lighting enhancement during testing. We conducted extensive quantitative and qualitative experiments on the LOLv2 and LSRW datasets, and the results showed that TLENet significantly outperformed state-of-the-art methods while requiring fewer parameters and lower computational complexity. Specifically, TLENet achieves 24.31 dB (PSNR) and 0.863 (SSIM) on the LOLv2 dataset, surpassing the second-best method(RetinexFormer & SNRNet ) by 1.51 dB (PSNR) and 0.014 (SSIM). Similarly, it achieves 20.34 dB (PSNR) and 0.573 (SSIM) on the LSRW dataset, surpassing the second-best method(LCDBNet) by 1.03 dB (PSNR) and 0.013 (SSIM). And TLENet only has 0.16M parameters and 17.01G FLOPS. Haixin Jia, Yu Zhang 0091, Guoying Zhang, Xing Yang 0004, Hengchen Xu |
ICMR | 4 |
| 2025 | DiffIVF: Infrared-Visible Image Fusion via Diffusion Models for Object Detection
Siyu Hu, Anjie Peng, Hui Zeng 0002, Xing Yang 0004 |
PRCV (8) | 6 |
| 2025 | PDAttack: Enhancing Transferability of Unrestricted Adversarial Examples via Prompt-Driven Diffusion
Siyu Hu, Anjie Peng, Hui Zeng 0002, Xing Yang 0004 |
PRCV (8) | 6 |
| 2025 | ICDDPM: Image-conditioned denoising diffusion probabilistic model for real-world complex point cloud single view reconstruction
Luda Zhao, Yihua Hu 0001, Xing Yang 0004, Zhenglei Dou, Qilong Wu 0009 |
Expert Syst. Appl. | 3 |
| 2025 | Voxel Pillar Multi-frame Cross Attention Network for sparse point cloud robust single object tracking
Luda Zhao, Yihua Hu 0001, Xing Yang 0004, Zhenglei Dou, Yan Zhang 0118 |
Pattern Recognit. | 3 |
| 2025 | TextDefense: Adversarial Text Detection Based on Word Importance Score DispersionabstractNatural language processing (NLP) models are widely used in various scenarios, yet they are vulnerable to adversarial attacks. Existing works aim to mitigate this vulnerability, but each work targets a specific attack category or has computational overhead limitations, making them vulnerable to adaptive attacks. In this paper, we exhaustively investigate the adversarial attack algorithms in NLP and discover that existing attack algorithms mainly disrupt the importance distribution of words in a text. A well-trained model can distinguish subtle importance distribution differences between clean and adversarial texts. Based on this intuition, we propose TextDefense, a new adversarial example detection framework that utilizes the target model’s capability to defend against adversarial attacks, requiring no prior knowledge. Unlike previous approaches, TextDefense is attack-type agnostic and outperforms existing methods in experiments with different architectures, datasets, and attack methods. We also discover that the target model’s generalizability is a leading factor influencing the performance of TextDefense. Finally, we provide insights into the adversarial attacks in NLP and the principles of our defense method by analyzing the properties of the target model and the adversarial example. Lujia Shen, Yuwen Pu, Xuhong Zhang 0002, Chunpeng Ge 0001, Xing Yang 0004, Hao Peng 0002, Wei Wang 0012, Shouling Ji |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2024 | WCL-SFR: Window-Based Contrastive Learning for Signal Feature ReconstructionabstractGiven the rapid advancement of the physical industrial internet and the growing significance of military reconnaissance, a large amount of signal data will be generated, because signal transmission and reception are the basis of these scenarios. However, due to problems such as air noise, inconsistent transceiver technology, and hacker interference, a large amount of data labels will be lost. With the aim of solving this problem, we propose a Window-based Contrastive Learning for Signal Feature Reconstruction (WCL_SFR) method. This method divides the feature map into small windows and uses similarity to establish a contrastive learning mode, while incorporating a reconstruction module to improve the stability of the model’s capacity for extraction. On two commonly used signal datasets, WCL_SFR generates the most beneficial results, with an improvement of up to 28.32% compared to other contrastive learning methods. In order to simulate real scenarios, we also conducted cross-dataset migration experiments, which achieved accuracies of 65.36% and 66.17%, respectively, which greatly outperformed similar methods. Therefore, WCL_SFR is an innovative development in the field of unsupervised signal recognition. Xing Yang 0004, Hua Mu, Zhen Hong, Zhenyu Wen |
HPCC | 2 |
| 2024 | FISFuzzer: A Grey-Box Protocol Fuzzer Based on Field Inference and Scheduling
Xiangpu Song, Shanqing Guo, Xing Yang 0004 |
SecureComm (3) | 6 |
| 2024 | Like teacher, like pupil: Transferring backdoors via feature-based knowledge distillation
Jinyin Chen, Zhiqi Cao, Ruoxi Chen, Haibin Zheng, Qi Xuan 0001, Xing Yang 0004 |
Comput. Secur. | 7 |
| 2024 | AdvCheck: Characterizing adversarial examples via local gradient checking
Ruoxi Chen, Haibo Jin, Jinyin Chen, Haibin Zheng, Shilian Zheng, Xiaoniu Yang, Xing Yang 0004 |
Comput. Secur. | 7 |
| 2024 | Robust multi-task learning network for complex LiDAR point cloud data preprocessingabstractThe utilization of 3D point clouds acquired via Light Detection and Ranging (LiDAR) is widespread in the fields of autonomous driving, satellite remote sensing , and spatial mapping . However, due to hardware limitations of the laser launch system and environmental interferences, the quality of point cloud data obtained through various types of LiDAR is often poor in real-world scenarios, containing extraneous noise and irrelevant data points. This poses a challenge for subsequent point cloud downstream tasks that (e.g., point cloud detection, recognition and tracking) require high-quality data. We propose a robust multi-task learning network for pre-processing LiDAR data. Our approach utilizes a shared PointNet encoder and three branching networks that perform denoising, single-object segmentation, and completion. The denoising branch network incorporates the traditional model based on geometric projection, leveraging the dual-driven approach of data and model for better capturing the characteristics of the point cloud. Regarding the segmentation branch network, we integrate an attention mechanism module suitable for single-object segmentation, enabling the network to better extract the point cloud features of complex objects. For the completion branch network, we employ a folded network structure to achieve a coarse-to-fine completion effect of the point cloud. We discuss the training methods, that is, end-to-end and step-by-step methods, which can enhance flexibility during the training and usage phase. Our proposed network outperforms prior state-of-the-art approaches in all three tasks on both ShapeNet and simulated point cloud data of the sea face scene while demonstrating superior robustness. Luda Zhao, Yihua Hu 0001, Xing Yang 0004, Zhenglei Dou, Linshuang Kang |
Expert Syst. Appl. | 3 |
| 2024 | MASiNet: Network Intrusion Detection for IoT Security Based on Meta-Learning FrameworkabstractThe rapid proliferation of Internet of Things (IoT) devices has led to an increased need for robust and efficient intrusion detection systems capable of identifying and mitigating novel threats. Traditional methods often struggle with the scarcity of labeled anomaly data, which is highly consequential, particularly in the context of IoT. In this study, we propose a novel few-shot learning approach by leveraging a Multi-Stage Attention Siamese Network (MASiNet) for network traffic intrusion detection based on meta-learning framework. Unlike traditional methods, the proposed MASiNet model is capable of detecting intrusions with minimal labeled samples, addressing the challenge of scarce anomaly data. The model is trained using various attack samples and evaluates unknown samples by comparing similarities with a small set of known attack types. A well-structured cost function design, incorporating two specific losses, is introduced to optimize the effectiveness of the training process. Tested on the NSL_KDD and UNSW-NB15 datasets in a simulated few-shot learning environment, the MASiNet model demonstrates superior performance in terms of accuracy, precision, False Alarm Rate (FAR), outperforming existing methods. Furthermore, we have validated our approach through real-world evaluations. The proposed method provides an effective solution for intrusion detection in the context of few-shot learning, offering a proficient solution that aligns with the dynamic nature of IoT networks. Yiming Wu 0009, Gaoyun Lin, Lisong Liu, Zhen Hong, Xing Yang 0004, Zoe Lin Jiang, Shouling Ji, Zhenyu Wen |
IEEE Internet Things J. | 6 |
| 2024 | TextCheater: A Query-Efficient Textual Adversarial Attack in the Hard-Label SettingabstractDesigning a query-efficient attack strategy to generate high-quality adversarial examples under the hard-label black-box setting is a fundamental yet challenging problem, especially in natural language processing (NLP). The process of searching for adversarial examples has many uncertainties (e.g., an unknown impact on the target model's prediction of the added perturbation) when confidence scores cannot be accessed, which must be compensated for with a large number of queries. To address this issue, we propose TextCheater, a decision-based metaheuristic search method that performs a query-efficient textual adversarial attack task by prohibiting invalid searches. The strategies of multiple initialization points and Tabu search are also introduced to keep the search process from falling into a local optimum. We apply our approach to three state-of-the-art language models (i.e., BERT, wordLSTM, and wordCNN) across six benchmark datasets and eight real-world commercial sentiment analysis platforms/models. Furthermore, we evaluate the Robustly optimized BERT pretraining Approach (RoBERTa) and models that enhance their robustness by adversarial training on toxicity detection and text classification tasks. The results demonstrate that our method minimizes the number of queries required for crafting plausible adversarial text while outperforming existing attack methods in the attack success rate, fluency of output sentences, and similarity between the original text and its adversary. Hao Peng 0002, Shixin Guo, Dandan Zhao 0003, Xuhong Zhang 0002, Jianmin Han, Shouling Ji, Xing Yang 0004, Ming Zhong 0009 |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2024 | MalGNE: Enhancing the Performance and Efficiency of CFG-Based Malware Detector by Graph Node Embedding in Low Dimension SpaceabstractThe rich semantic information in Control Flow Graphs (CFGs) of executable programs has made Graph Neural Networks (GNNs) a key focus for malware detection. However, existing CFG-based detection techniques face limitations in node feature extraction, such as information loss, neglect of execution sequence information, and redundancy in representation vectors. These limitations compromise the balance between high efficiency and precision when training detectors. Addressing this, we introduce an innovative Malware CFG Node Embedding (MalGNE) method. This approach utilizes a novel instruction encoding rule to address the Out-Of-Vocabulary(OOV) problem, generates high-quality initial vectors. Then, it employs aggregation layer and sequence layer to extract node aggregation feature and execution sequence feature, in conjunction with GNNs to develop a pre-trained node embedding model. The model maps the semantic information of node assembly instruction sequences into a compact, low-dimensional continuous space, ensuring high-quality feature extraction, and enhancing the performance and efficiency of the detector. We trained the MalGNE model using the BIG 2015 dataset and validated MalGNE-enhanced detector on the SOREL-20M and BODMAS datasets. MalGNE-enhanced detector demonstrates outstanding performance and efficiency in low-dimensional spaces, especially when the dimensionality of the node feature vector is reduced to 16. MalGNE-enhanced detector not only maintains a high detection accuracy of 95.49%. sacrificing only about 1.7% of accuracy to save approximately 73% of training time compared to 128 dimensions. Hao Peng 0002, Jieshuai Yang, Dandan Zhao 0003, Xiaogang Xu 0002, Yuwen Pu, Jianmin Han, Xing Yang 0004, Ming Zhong 0009, Shouling Ji |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2024 | HashVFL: Defending Against Data Reconstruction Attacks in Vertical Federated LearningabstractVertical Federated Learning (VFL) is a trending collaborative machine learning model training solution. Existing industrial frameworks employ secure multi-party computation techniques such as homomorphic encryption to ensure data security and privacy. Despite these efforts, studies have revealed that data leakage remains a risk in VFL due to the correlations between intermediate representations and raw data. Neural networks can accurately capture these correlations, allowing an adversary to reconstruct the data. This emphasizes the need for continued research into securing VFL systems. Our work shows that hashing is a promising solution to counter data reconstruction attacks. The one-way nature of hashing makes it difficult for an adversary to recover data from hash codes. However, implementing hashing in VFL presents new challenges, including vanishing gradients and information loss. To address these issues, we propose HashVFL, which integrates hashing and simultaneously achieves learnability, bit balance, and consistency. Experimental results indicate that HashVFL effectively maintains task performance while defending against data reconstruction attacks. It also brings additional benefits in reducing the degree of label leakage, mitigating adversarial attacks, and detecting abnormal inputs. We hope our work will inspire further research into the potential applications of HashVFL. Pengyu Qiu, Xuhong Zhang 0002, Shouling Ji, Chong Fu 0002, Xing Yang 0004, Ting Wang 0006 |
IEEE Trans. Inf. Forensics Secur. | 5 |
| 2023 | GONE: A generic O(1) NoisE layer for protecting privacy of deep neural networks
Haibin Zheng, Jinyin Chen, Wenchang Shangguan, Zhaoyan Ming, Xing Yang 0004 |
Comput. Secur. | 5 |