Kun Fang 0004

dblp:51/5923-4 · DBLP profile ↗
← Back
15ranked-venue papers
5as first author
15since 2021 · last 2026
0000-0001-6351-201XORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 12 · 5 first-author · 12 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 3 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 DIFT: Protecting Contrastive Learning Against Data Poisoning Backdoor Attacks
abstract
Contrastive learning (CL) is a popular learning paradigm that excels in extracting meaningful representations from unlabeled data. Recent studies have shown that CL is highly vulnerable to backdoor attacks. Current defenses against backdoor attacks in CL are primarily reactive and post-training. That is, the detection and elimination of backdoors are executed in the deployment phase of a given well-trained model. However, these post-training defenses are usually prone to degrading model utility and resource-intensive, causing that the backdoor detection and elimination from a fully-trained model is quite challenging. To address this issue, we argue for a fundamental perspective, i.e., integrating the defense into the model's training phase, and propose a novel framework to mitigate the backdoor in CL, namely Density-Based Identification and Fine-Tuning (DIFT). Specifically, DIFT identifies potential poisoned samples during the early training phase via detecting embeddings with abnormal poisoning characteristic in the feature space. Then, to remove backdoors and preserve model utility, the detected poisoned samples are leveraged to fine-tune the model, and the remaining clean samples are further involved into training the model after the fine-tuning. DIFT, as a proactive training-time defense, avoids the problematic backdoor removal and the high computational cost associated with those reactive post-training methods. We empirically evaluate DIFT on various CL algorithms against backdoor attack. Experimental results demonstrate that our method exhibits promising defense effectiveness while maintaining model's clean data accuracy.
Yulin Jin, Qingqing Ye 0001, Zhibiao Guo, Kun Fang 0004, Ruochen Du, Yingnan Zhao 0002, Haibo Hu 0001
AAAI5
2025 Multi-head ensemble of smoothed classifiers for certified robustness
Kun Fang 0004, Qinghua Tao, Yingwen Wu, Tao Li 0054, Xiaolin Huang, Jie Yang 0002
Neural Networks1
2024 Kernel PCA for Out-of-Distribution Detection
abstract
Out-of-Distribution (OoD) detection is vital for the reliability of Deep Neural Networks (DNNs). Existing works have shown the insufficiency of Principal Component Analysis (PCA) straightforwardly applied on the features of DNNs in detecting OoD data from In-Distribution (InD) data. The failure of PCA suggests that the network features residing in OoD and InD are not well separated by simply proceeding in a linear subspace, which instead can be resolved through proper non-linear mappings. In this work, we leverage the framework of Kernel PCA (KPCA) for OoD detection, and seek suitable non-linear kernels that advocate the separability between InD and OoD data in the subspace spanned by the principal components. Besides, explicit feature mappings induced from the devoted task-specific kernels are adopted so that the KPCA reconstruction error for new test samples can be efficiently obtained with large-scale data. Extensive theoretical and empirical results on multiple OoD data sets and network structures verify the superiority of our KPCA detector in efficiency and efficacy with state-of-the-art detection performance.
Kun Fang 0004, Qinghua Tao, Kexin Lv, Mingzhen He, Xiaolin Huang, Jie Yang 0002
NeurIPS1
2024 Revisiting Deep Ensemble for Out-of-Distribution Detection: A Loss Landscape Perspective
Kun Fang 0004, Qinghua Tao, Xiaolin Huang, Jie Yang 0002
Int. J. Comput. Vis.1
2024 Boosting certified robustness via an expectation-based similarity regularization
Kun Fang 0004, Xiaolin Huang, Jie Yang 0002
Image Vis. Comput.2
2024 Towards robust neural networks via orthogonal diversity
Kun Fang 0004, Qinghua Tao, Yingwen Wu, Tao Li 0054, Feipeng Cai, Xiaolin Huang, Jie Yang 0002
Pattern Recognit.1
2023 Improving adversarial robustness through a curriculum-guided reliable distillation
Kun Fang 0004, Xiaolin Huang, Jie Yang 0002
Comput. Secur.2
2023 End-to-end kernel learning via generative random Fourier features
Kun Fang 0004, Fanghui Liu 0001, Xiaolin Huang, Jie Yang 0002
Pattern Recognit.1
2023 Improving the adversarial robustness of quantized neural networks via exploiting the feature diversity
abstract
Quantized neural networks (QNNs) have become one of the most prevalent approaches in deep learning model compression due to their computational and storage efficiency. However, there is a lack of research specialized in the adversarial robustness of QNNs, which is important for applications in security-critical domains. Existing defenses focus on conventional full-precision networks, which can result in behavioral disparities and degrade the expected performance when directly transferred to QNNs. A novel defensive strategy promotes feature diversity through an orthogonal constraint, which can synergize well with quantization. Inspired by this intuition, we propose an orthogonal regularization with quantization to improve the adversarial robustness of QNNs in this paper. Moreover, we observe that quantization serves as an implicit regularization and is able to alleviate orthogonal degeneration. The proposed orthogonal regularization with quantization is validated on several typical network architectures and benchmark datasets. The results demonstrate that the proposed method can notably enhance adversarial robustness against both white-box and black-box attacks.
Kun Fang 0004, Jie Yang 0002, Xiaolin Huang
Pattern Recognit. Lett.2
2023 Unifying Gradients to Improve Real-World Robustness for Deep Networks
abstract
The wide application of deep neural networks (DNNs) demands an increasing amount of attention to their real-world robustness, i.e., whether a DNN resists black-box adversarial attacks, among which score-based query attacks (SQAs) are the most threatening since they can effectively hurt a victim network with only access to model outputs. Defending against SQAs requires a slight but artful variation of outputs due to the service purpose for users, who share the same output information with SQAs. In this article, we propose a real-world defense by Unifying Gradients (UniG) of different data so that SQAs could only probe a much weaker attack direction that is similar for different samples. Since such universal attack perturbations have been validated as less aggressive than the input-specific perturbations, UniG protects real-world DNNs by indicating to attackers a twisted and less informative attack direction. We implement UniG efficiently by a Hadamard product module, which is plug-and-play. According to extensive experiments on 5 SQAs, 2 adaptive attacks and 7 defense baselines, UniG significantly improves real-world robustness without hurting clean accuracy on CIFAR10 and ImageNet. For instance, UniG maintains a model of 77.80% accuracy under a 2500-query Square attack while the state-of-the-art adversarially trained model only has 67.34% on CIFAR10. Simultaneously, UniG outperforms all compared baselines in terms of clean accuracy and achieves the smallest modification of the model output. The code is released at https://github.com/snowien/UniG-pytorch .
Yingwen Wu, Sizhe Chen, Kun Fang 0004, Xiaolin Huang
ACM Trans. Intell. Syst. Technol.3
2022 Subspace Adversarial Training
abstract
Single-step adversarial training (AT) has received wide attention as it proved to be both efficient and robust. However, a serious problem of catastrophic overfitting exists, i.e., the robust accuracy against projected gradient descent (PGD) attack suddenly drops to 0% during the training. In this paper, we approach this problem from a novel perspective of optimization and firstly reveal the close link between the fast-growing gradient of each sample and overfitting, which can also be applied to understand robust overfitting in multi-step AT. To control the growth of the gradient, we propose a new AT method, Subspace Adversarial Training (Sub-AT), which constrains AT in a carefully extracted subspace. It successfully resolves both kinds of overfitting and significantly boosts the robustness. In subspace, we also allow single-step AT with larger steps and larger radius, further improving the robustness performance. As a result, we achieve state-of-the-art single-step AT performance. Without any regularization term, our single-step AT can reach over 51 % robust accuracy against strong PGD-50 attack of radius 8/255 on CIFAR-10, reaching a competitive performance against standard multi-step PGD-10 AT with huge computational advantages. The code is released at https://github.com/nblt/Sub-AT.
Tao Li 0054, Yingwen Wu, Sizhe Chen, Kun Fang 0004, Xiaolin Huang
CVPR4
2022 Local-Global Semantic Fusion Single-shot Classification Method
Jianwei Cai, Kun Fang 0004, Weihao Yu 0004, Jie Yang 0002
ICONIP (1)2
2022 CROON: Automatic Multi-LiDAR Calibration and Refinement Method in Road Scene
abstract
Sensor-based environmental perception is a crucial part of the autonomous driving system. In order to get an excellent perception of the surrounding environment, an intelligent system would configure multiple LiDARs (3D Light Detection and Ranging) to cover the distant and near space of the car. The precision of perception relies on the quality of sensor calibration. This research aims at developing an accurate, automatic, and robust calibration strategy for multiple LiDAR systems in the general road scene. We thus propose CROON (automatic multi-LiDAR Calibration and Refinement methOd in rOad sceNe), a two-stage method including rough and refinement calibration. The first stage can calibrate the sensor from an arbitrary initial pose, and the second stage is able to precisely calibrate the sensor iteratively. Specifically, CROON utilize the nature characteristics of road scene so that it is independent and easy to apply in large-scale conditions. Experimental results on real-world and simulated data sets demonstrate the reliability and accuracy of our method. All the related data sets and codes are open-sourced on the Github website https://github.com/OpenCalib/LiDAR2LiDAR.
Pengjin Wei, Guohang Yan, Yikang Li 0002, Kun Fang 0004, Xinyu Cai, Jie Yang 0002, Wei Liu 0044
IROS4
2021 ADVMIX: Data Augmentation for Accurate Scene Text Spotting
abstract
Accurate scene text spotting models ask for effective data augmentation algorithms. This paper presents a novel data augmentation algorithm called AdvMix that integrates techniques of adversarial attack and mixup. First, it utilizes the PGD method to synthesize adversarial samples. Second, it is the first work to implement feature-wise mixup between original data and the associated adversarial sample to enhance data augmentation. AdvMix has been evaluated over ICDAR2013 and ICDAR2015 datasets, showing its superior performance in improving accuracy of scene text spotting models.
Yizhang Huang, Kun Fang 0004, Xiaolin Huang, Jie Yang 0002
ICIP2
2021 Towards Unbiased Random Features with Lower Variance For Stationary Indefinite Kernels
abstract
Random Fourier Features (RFF) demonstrate well-appreciated performance in kernel approximation for large-scale situations but restrict kernels to be stationary and positive definite. And for non-stationary kernels, the corresponding RFF could be converted to that for stationary indefinite kernels when the inputs are restricted to the unit sphere. Numerous methods provide accessible ways to approximate stationary but indefinite kernels. However, they are either biased or possess large variance. In this article, we propose the generalized orthogonal random features, an unbiased estimation with lower variance. Experimental results on various datasets and kernels verify that our algorithm achieves lower variance and approximation error compared with the existing kernel approximation methods. With better approximation to the originally selected kernels, improved classification accuracy and regression ability is obtained with our approximation algorithm in the framework of support vector machine and regression.
Kun Fang 0004, Jie Yang 0002, Xiaolin Huang
IJCNN2