VLDB 2026 Research / reviewers in the wild / expert
Xingxing Wei 0001
dblp:57/4066-1
· DBLP profile ↗
69ranked-venue papers
18as first author
52since 2021 · last 2026
0000-0002-0778-8377ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 44 · 13 first-author · 34 since 2021Graphics, computer vision, multimedia, augmented reality and games · 40 · 7 first-author · 28 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 5 since 2021Databases, data management, data science and information retrieval · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Any2Critical: Safety-Critical Scenario Generation from Arbitrary Real-World Driving ContextsabstractAutonomous driving systems have achieved remarkable capabilities in real-world deployment, yet ensuring safety under corner cases remains a significant challenge due to the scarcity and constrained diversity of safety-critical scenarios. Existing generation methods may either lead to irrational vehicle behaviors or be limited by fixed collision patterns, while both heavily rely on existing map datasets, restricting the diversity. To address these fundamental limitations, we introduce Any2Critical, the first framework that can encode arbitrary real-world scenarios and generate contextually relevant safety-critical scenarios with realistic driving behaviors. Specifically, Any2Critical addresses two key challenges: (1) developing comprehensive, diverse map data by successfully leveraging everyday traffic situations as the most abundant source of real-world driving contexts, and (2) proposing an RAG-based Safety-Critical Scenario Generation Strategy based on our curated NHTSA-5K database for achieving an optimal balance between scenario diversity and behavioral rationality. Through comprehensive evaluation, we demonstrate that Any2Critical consistently achieves collision rates with an average of 89.69% across diverse scenarios and autonomous driving systems, significantly outperforming current state-of-the-art generation methods. Yubo Chen 0008, Yitong Sun 0002, Shouwei Ruan, Yinpeng Dong, Xingxing Wei 0001 |
AAAI | 8 |
| 2026 | Knowledge-Guided Adversarial Training for Infrared Object Detection via Thermal Radiation Modeling
Shukun Xiong, Maoxun Yuan, Ranjie Duan, Qing Guo 0005, Haibin Duan, Xingxing Wei 0001 |
Int. J. Comput. Vis. | 9 |
| 2026 | Removal Then Selection: A Coarse-to-Fine Fusion Perspective for RGB-Infrared Object DetectionabstractIn recent years, object detection utilizing both visible (RGB) and thermal infrared (IR) imagery has garnered extensive attention and has been widely implemented across a diverse array of fields. By leveraging the complementary properties between RGB and IR images, the object detection task can achieve reliable and robust object localization across a variety of lighting conditions, from daytime to nighttime environments. While RGB-IR multi-modal data input generally enhances overall detection performance, most existing multi-modal object detection methods fail to fully exploit the complementary potential of these two modalities. We believe that this issue arises not only from the challenges associated with effectively integrating multi-modal information but also from the presence of redundant features in both the RGB and IR modalities. The redundant information of each modality will exacerbate the fusion imprecision problems during propagation. To address this issue, we draw inspiration from the human cognitive mechanisms for processing multi-modal information and propose a novel coarse-to-fine perspective to purify and fuse features from both modalities. Specifically, following this perspective, we design a Redundant Spectrum Removal module to remove interfering information within each modality coarsely and a Dynamic Feature Selection module to finely select the desired features for feature fusion. To verify the effectiveness of the coarse-to-fine fusion strategy, we construct a new object detector called the Removal then Selection Detector (RSDet). Extensive experiments on five RGB-IR object detection datasets verify the superior performance of our method. The source code and results are available athttps://github.com/Zhao-Tian-yi/RSDet.git Tianyi Zhao 0003, Maoxun Yuan, Feng Jiang 0014, Nan Wang 0014, Xingxing Wei 0001 |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2025 | ProjAttacker: A Configurable Physical Adversarial Attack for Face Recognition via ProjectorabstractPrevious physical adversarial attacks have shown that carefully crafted perturbations can deceive face recognition systems, revealing critical security vulnerabilities. However, these attacks often struggle to impersonate multiple targets and frequently fail to bypass liveness detection. For example, attacks using human-skin masks [28] are challenging to fabricate, inconvenient to swap between users, and often fail liveness detection due to facial occlusions. A projector, however, can generate content-rich light without obstructing the face, making it ideal for non-intrusive attacks. Thus, we propose a novel physical adversarial attack using a projector and explore the superposition of projected and natural light to create adversarial facial images. This approach eliminates the need for physical artifacts on the face, effectively overcoming these limitations. Specifically, our proposed ProjAttacker generates adversarial 3D textures that are projected onto human faces. To ensure physical realizability, we introduce a light reflection function that models complex optical interactions between projected light and human skin, accounting for reflection and diffraction effects. Furthermore, we incorporate camera Image Signal Processing (ISP) simulation to maintain the robustness of adversarial perturbations across real-world diverse imaging conditions. Comprehensive evaluations conducted in both digital and physical scenarios validate the effectiveness of our method. Yuanwei Liu, Hui Wei 0004, Ruqi Xiao, Weijian Ruan, Xingxing Wei 0001, Joey Tianyi Zhou, Zheng Wang 0007 |
CVPR | 6 |
| 2025 | When Lighting Deceives: Exposing Vision-Language Models' Illumination Vulnerability Through Illumination Transformation Attack
Shouwei Ruan, Xingxing Wei 0001 |
ICCV | 5 |
| 2025 | AdvDreamer Unveils: Are Vision-Language Models Truly Ready for Real-World 3D Variations?abstractVision Language Models (VLMs) have exhibited remarkable generalization capabilities, yet their robustness in dynamic real-world scenarios remains largely unexplored. To systematically evaluate VLMs' robustness to real-world 3D variations, we propose AdvDreamer, the first framework capable of generating physically reproducible Adversarial 3D Transformation (Adv-3DT) samples from single-view observations. In AdvDreamer, we integrate three key innovations: Firstly, to characterize real-world 3D variations with limited prior knowledge precisely, we design a zero-shot Monocular Pose Manipulation pipeline built upon generative 3D priors. Secondly, to ensure the visual quality of worst-case Adv-3DT samples, we propose a Naturalness Reward Model that provides continuous naturalness regularization during adversarial optimization, effectively preventing convergence to hallucinated or unnatural elements. Thirdly, to enable systematic evaluation across diverse VLM architectures and visual-language tasks, we introduce the Inverse Semantic Probability loss as the adversarial optimization objective, which solely operates in the fundamental visual-textual alignment space. Based on the captured Adv-3DT samples with high aggressiveness and transferability, we establish MM3DTBench, the first VQA benchmark dataset tailored to evaluate VLM robustness under challenging 3D variations. Extensive evaluations of representative VLMs with varying architectures reveal that real-world 3D variations can pose severe threats to model performance across various tasks. Shouwei Ruan, Caixin Kang, Hang Su 0006, Yinpeng Dong, Xingxing Wei 0001 |
ICCV | 8 |
| 2025 | Jailbreaking Multimodal Large Language Models via Shuffle InconsistencyabstractMultimodal Large Language Models (MLLMs) have achieved impressive performance and have been put into practical use in commercial applications, but they still have potential safety mechanism vulnerabilities. Jailbreak attacks are red teaming methods that aim to bypass safety mechanisms and discover MLLMs' potential risks. Existing MLLMs' jailbreak methods often bypass the model's safety mechanism through complex optimization methods or carefully designed image and text prompts. Despite achieving some progress, they have a low attack success rate on commercial closed-source MLLMs. Unlike previous research, we empirically find that there exists a Shuffle Inconsistency between MLLMs' comprehension ability and safety ability for the shuffled harmful instruction. That is, from the perspective of comprehension ability, MLLMs can understand the shuffled harmful text-image instructions well. However, they can be easily bypassed by the shuffled harmful instructions from the perspective of safety ability, leading to harmful responses. Then we innovatively propose a text-image jailbreak attack named SI-Attack. Specifically, to fully utilize the Shuffle Inconsistency and overcome the shuffle randomness, we apply a query-based black-box optimization method to select the most harmful shuffled inputs based on the feedback of the toxic judge model. A series of experiments show that SI-Attack can improve the attack's performance on three benchmarks. In particular, SI-Attack can obviously improve the attack success rate for commercial MLLMs such as GPT-4o or Claude-3.5-Sonnet. Ranjie Duan, Caixin Kang, Shouwei Ruan, Jialing Tao, Yuefeng Chen, Hui Xue 0001, Xingxing Wei 0001 |
ICCV | 10 |
| 2025 | Rethinking Multi-Modal Object Detection From the Perspective of Mono-Modality Feature Learning
Tianyi Zhao 0003, Yanglei Gao, Maoxun Yuan, Xingxing Wei 0001 |
ICCV | 6 |
| 2025 | Multi-Task Robustness Enhancement Framework against Various Adversarial PatchesabstractAutonomous systems leveraging visual perception face a rising threat from adversarial patches, jeopardizing their robustness. Existing defense methods adaptable to various pre-trained models typically rely on observed patch characteristics or prior attack data, having difficulty adapting to new threats. This study innovatively focuses on modeling patch attack behavior instead of existing patches, proposing a unified robustness enhancement framework against various adversarial patches. Through self-supervised learning, we accurately locate diverse adversarial patches without prior attack knowledge. Furthermore, we introduce an efficient adaptive patch inpainting method to mitigate patch impact while maintaining visual coherence. Experiments show that our methods effectively boost the robustness of visual perception models against various adversarial patches across different tasks. Lihua Jing, Rui Wang 0032, Runbo Li, Zixuan Zhu 0002, Xingxing Wei 0001 |
ICRA | 5 |
| 2025 | NDM: A Noise-driven Detection and Mitigation Framework against Implicit Sexual Intentions in Text-to-Image Generation
Yitong Sun 0002, Huanran Chen, Shouwei Ruan, Ranjie Duan, Xingxing Wei 0001 |
ACM Multimedia | 7 |
| 2025 | UniRGB-IR: A Unified Framework for Visible-Infrared Semantic Tasks via Adapter Tuning
Maoxun Yuan, Tianyi Zhao 0003, Shan Fu, Xue Yang 0005, Xingxing Wei 0001 |
ACM Multimedia | 7 |
| 2025 | Mitigating Overthinking in Large Reasoning Models via Manifold SteeringabstractRecent advances in Large Reasoning Models (LRMs) have demonstrated remarkable capabilities in solving complex tasks such as mathematics and coding. However, these models frequently exhibit a phenomenon known as *overthinking* during inference, characterized by excessive validation loops and redundant deliberation, leading to substantial computational overheads. In this paper, we aim to mitigate overthinking by investigating the underlying mechanisms from the perspective of mechanistic interpretability. We first showcase that the tendency of overthinking can be effectively captured by a single direction in the model's activation space and the issue can be eased by intervening the activations along this direction. However, this efficacy soon reaches a plateau and even deteriorates as the intervention strength increases. We therefore systematically explore the activation space and find that the overthinking phenomenon is actually tied to a low-dimensional manifold, which indicates that the limited effect stems from the noises introduced by the high-dimensional steering direction. Based on this insight, we propose **Manifold Steering**, a novel approach that elegantly projects the steering direction onto the low-dimensional activation manifold given the theoretical approximation of the interference noise. Extensive experiments on DeepSeek-R1 distilled models validate that our method reduces output tokens by up to 71\% while maintaining and even improving the accuracy on several mathematical benchmarks. Our method also exhibits robust cross-domain transferability, delivering consistent token reduction performance in code generation and knowledge-based QA tasks. Code is available at: https://github.com/Aries-iai/Manifold_Steering. Huanran Chen, Shouwei Ruan, Yichi Zhang 0012, Xingxing Wei 0001, Yinpeng Dong |
NeurIPS | 5 |
| 2025 | DeceptionBench: A Comprehensive Benchmark for AI Deception Behaviors in Real-world ScenariosabstractDespite the remarkable advances of Large Language Models (LLMs) across diverse cognitive tasks, the rapid enhancement of these capabilities also introduces emergent deception behaviors that may induce severe risks in high-stakes deployments. More critically, the characterization of deception across realistic real-world scenarios remains underexplored. To bridge this gap, we establish DeceptionBench, the first benchmark that systematically evaluates how deceptive tendencies manifest across different societal domains, what their intrinsic behavioral patterns are, and how extrinsic factors affect them. Specifically, on the static count, the benchmark encompasses 150 meticulously designed scenarios in five domains, i.e., Economy, Healthcare, Education, Social Interaction, and Entertainment, with over 1,000 samples, providing sufficient empirical foundations for deception analysis. On the intrinsic dimension, we explore whether models exhibit self-interested egoistic tendencies or sycophantic behaviors that prioritize user appeasement. On the extrinsic dimension, we investigate how contextual factors modulate deceptive outputs under neutral conditions, reward-based incentivization, and coercive pressures. Moreover, we incorporate sustained multi-turn interaction loops to construct a more realistic simulation of real-world feedback dynamics. Extensive experiments across LLMs and Large Reasoning Models (LRMs) reveal critical vulnerabilities, particularly amplified deception under reinforcement dynamics, demonstrating that current models lack robust resistance to manipulative contextual cues and the urgent need for advanced safeguards against various deception behaviors. Code and resources are publicly available at https://github.com/Aries-iai/DeceptionBench. Yitong Sun 0002, Yichi Zhang 0012, Yinpeng Dong, Xingxing Wei 0001 |
NeurIPS | 6 |
| 2025 | Patch Grid-Based Quality Assessment for Aerial Visible-to-Infrared Image TranslationabstractAerial visible-to-infrared image translation expands infrared datasets by generating infrared images from visible images for various applications in aerial remote sensing. However, existing image translation methods do not consistently produce high-quality results for each image. In practice, it is crucial to evaluate and filter for high-quality generated images to ensure they are suitable for subsequent tasks. Additionally, generated images often lack paired data for effective evaluation. In this letter, we propose patch grid-based quality assessment (PGQA) for assessing the quality of translated infrared images from visible images in aerial remote sensing. This method decomposes global authenticity and similarity into local authenticity and similarity because the lack of paired data makes it difficult to assess the authenticity of a picture. Specifically, the method first grids real infrared images and trains them with convolutional autoencoder (CAE) networks. Similar components and contents naturally share similar feature representations, so the generated infrared images are fed into the trained autoencoder model by the same grid operation. If the average reconstruction loss is lower, the image quality is higher. This approach enables effective quality assessment of generated infrared images and is consistent with other paired methods. It enhances the utility of generated images and increases their practical value in deep learning applications. The source code is available athttps://github.com/fan-lmw/PGQA.git. Lei Zhao 0025, Nan Wang 0014, Xiaochun Song, Xingxing Wei 0001 |
IEEE Geosci. Remote. Sens. Lett. | 5 |
| 2025 | Real-World Adversarial Defense Against Patch Attacks Based on Diffusion ModelabstractAdversarial patches present significant challenges to the robustness of deep learning models, making the development of effective defenses become critical for real-world applications. This paper introduces DIFFender, a novel DIFfusion-based DeFender framework that leverages the power of a text-guided diffusion model to counter adversarial patch attacks. At the core of our approach is the discovery of the Adversarial Anomaly Perception (AAP) phenomenon, which enables the diffusion model to accurately detect and locate adversarial patches by analyzing distributional anomalies. DIFFender seamlessly integrates the tasks of patch localization and restoration within a unified diffusion model framework, enhancing defense efficacy through their close interaction. Additionally, DIFFender employs an efficient few-shot prompt-tuning algorithm, facilitating the adaptation of the pre-trained diffusion model to defense tasks without the need for extensive retraining. Our comprehensive evaluation, covering image classification and face recognition tasks, as well as real-world scenarios, demonstrates DIFFender's robust performance against adversarial attacks. The framework's versatility and generalizability across various settings, classifiers, and attack methodologies mark a significant advancement in adversarial patch defense strategies. Except for the popular visible domain, we have identified another advantage of DIFFender: its capability to easily expand into the infrared domain. Consequently, we demonstrate the good flexibility of DIFFender, which can defend against both infrared and visible adversarial patch attacks alternatively using a universal defense framework. Xingxing Wei 0001, Caixin Kang, Yinpeng Dong, Shouwei Ruan, Yubo Chen 0008, Hang Su 0006 |
IEEE Trans. Pattern Anal. Mach. Intell. | 1 |
| 2025 | Distributionally Location-Aware Transferable Adversarial Patches for Facial ImagesabstractAdversarial patch is one of the important forms of performing adversarial attacks in the physical world. To improve the naturalness and aggressiveness of existing adversarial patches, location-aware patches are proposed, where the patch's location on the target object is integrated into the optimization process to perform attacks. Although it is effective, efficiently finding the optimal location for placing the patches is challenging, especially under the black-box attack settings. In this paper, we first empirically find that the aggregation regions of adversarial patch's locations to show effective attacks for the same facial image are pretty similar across different face recognition models. Based on this observation, we then propose a novel framework called Distribution-Optimized Adversarial Patch (DOPatch) to efficiently search for the aggregation regions in a distribution modeling way. Using the distribution prior, we further design two query-based black-box attack methods: Location Optimization Attack (DOP-LOA) and Distribution Transfer Attack (DOP-DTA) to attack unseen face recognition models. We finally evaluate the proposed methods on various SOTA face recognition models and image recognition models (including the popular big models) to demonstrate our effectiveness and generalization. We also conduct extensive ablation studies and analyses to provide insights into the distribution of adversarial locations. Xingxing Wei 0001, Shouwei Ruan, Yinpeng Dong, Hang Su 0006, Xiaochun Cao |
IEEE Trans. Pattern Anal. Mach. Intell. | 1 |
| 2025 | Classification Committee for Active Deep Object DetectionabstractIn object detection, the cost of labeling is very high because it needs not only to confirm the categories of multiple objects in an image but also to determine the bounding boxes of each object accurately. Thus, integrating active learning into object detection will raise pretty positive significance. In this paper, we propose a classification committee for the active deep object detection method by introducing a discrepancy mechanism of multiple classifiers for samples' selection when training object detectors. The model contains a main detector and a classification committee. The main detector denotes the target object detector trained from a labeled pool composed of the selected informative images. The role of the classification committee is to select the most informative images according to their uncertainty values from the view of classification, which is expected to focus more on the discrepancy and representative of instances. Specifically, they compute the uncertainty for a specified instance within the image by measuring its discrepancy output by the committee pre-trained via the proposed Maximum Classifiers Discrepancy Group Loss (MCDGL). The most informative images are finally determined by selecting the ones with many high-uncertainty instances. Besides, to mitigate the impact of interference instances, we design a Focusing on Positive Instances Loss (FPIL) to provide the committee the ability to automatically focus on the representative instances as well as precisely encode their discrepancies for the same instance. Experiments are conducted on Pascal VOC and COCO datasets versus some popular object detectors. And results show that our method outperforms the state-of-the-art active learning methods, which verifies the effectiveness of the proposed method. Lei Zhao 0025, Bo Li 0006, Jixiang Jiang, Xingxing Wei 0001 |
IEEE Trans. Multim. | 4 |
| 2025 | Diverse Visible-to-Thermal Image Translation via Controllable Temperature EncodingabstractTranslating readily available visible (VIS) images into thermal infrared (TIR) images effectively alleviates the shortage of TIR data. While current methods have yielded commendable results, they fall short in generating diverse and realistic thermal infrared images, primarily due to insufficient consideration of temperature variations. In this paper, we propose a Thermally Controlled GAN (TC-GAN) that leverages VIS images to generate diverse TIR images, with the ability to control the relative temperatures of multiple objects, particularly those with temperature variations. Firstly, we introduce the physical coding module, which employs a conditional variational autoencoder GAN to learn the distributions of relative temperature information for the objects and environmental state information. Then, the physical information can be obtained by sampling the distribution. When this information is fused with the visible image, it facilitates the generation of diverse TIR images. To ensure authenticity and strengthen the physical constraints across different regions of the image, we introduce a self-attention mechanism in the generator that prioritizes the relative temperature relationships within the image. Additionally, we utilize a local discriminator that focuses on objects with actively changing temperatures and their interactions with the surrounding environment, thereby reducing the discontinuity between the target and the background. Experiments on the Drone Vehicle and AVIID datasets show that our approach outperforms mainstream diversity generation methods in terms of authenticity and diversity. Lei Zhao 0025, Bo Li 0006, Xingxing Wei 0001 |
IEEE Trans. Multim. | 4 |
| 2024 | MIAD-MARK: Adversarial Watermarking of Medical Image for Protecting Copyright and PrivacyabstractThe rapid advancement of deep learning has significantly facilitated the integration of Artificial Intelligence (AI) into clinical practices. However, the frequent utilization of vast clinical data has raised concerns about copyright and patient privacy. Here, we introduce a framework that not only enables medical image copyright protection but also prevents unauthorized AI analysis. Specifically, we adhere to this framework and propose a novel visible adversarial watermark for medical images, MIAD-MARK, utilizing adaptable affine transforms to deceive unauthorized models. Furthermore, we enhance the robustness of MIAD-MARK to resist advanced watermark removal deep neural networks. Our approach involves linear variations, allowing for reversibility to recover the original images during the authorization process. We conduct experiments on various medical datasets, including different diseases and modalities. Our results demonstrate significant decreases in medical image foundation models and standard models. Our findings underscore that MIAD-MARK offers an effective, easily implemented, and robust solution to safeguard medical image copyright and patient privacy, thereby promoting the security of AI-driven medical image diagnosis in clinical applications. Xingxing Wei 0001, Bangzheng Pu, Huazhu Fu |
BIBM | 1 |
| 2024 | Towards Transferable Targeted 3D Adversarial Attack in the Physical WorldabstractCompared with transferable untargeted attacks, transferable targeted adversarial attacks could specify the mis-classification categories of adversarial samples, posing a greater threat to security-critical tasks. In the meanwhile, 3D adversarial samples, due to their potential of multi-view robustness, can more comprehensively identify weak-nesses in existing deep learning systems, possessing great application value. However, the field of transferable targeted 3D adversarial attacks remains vacant. The goal of this work is to develop a more effective technique that could generate transferable targeted 3D adversarial examples, filling the gap in this field. To achieve this goal, we design a novel framework named TT3D that could rapidly reconstruct from few multi-view images into Transferable Targeted 3D textured meshes. While existing mesh-based texture optimization methods compute gradients in the high-dimensional mesh space and easily fall into local optima, leading to unsatisfactory transferability and distinct distortions, TT3D innovatively performs dual optimization towards both feature grid and Multi-layer Perceptron (MLP) parameters in the grid-based NeRF space, which significantly enhances black-box transferability while enjoying naturalness. Experimental results show that TT3D not only exhibits superior cross-model transferability but also maintains considerable adaptability across different renders and vision tasks. More importantly, we produce 3D adversarial examples with 3D printing techniques in the real world and verify their robust performance under various scenarios. Yinpeng Dong, Shouwei Ruan, Xiao Yang 0028, Hang Su 0006, Xingxing Wei 0001 |
CVPR | 6 |
| 2024 | DIFFender: Diffusion-Based Adversarial Defense Against Patch Attacks
Caixin Kang, Yinpeng Dong, Shouwei Ruan, Yubo Chen 0008, Hang Su 0006, Xingxing Wei 0001 |
ECCV (52) | 7 |
| 2024 | Omniview-Tuning: Boosting Viewpoint Invariance of Vision-Language Pre-training Models
Shouwei Ruan, Yinpeng Dong, Hang Su 0006, Xingxing Wei 0001 |
ECCV (26) | 6 |
| 2024 | Embodied Laser Attack: Leveraging Scene Priors to Achieve Agent-based Robust Non-contact Attacks
Yitong Sun 0002, Xingxing Wei 0001 |
ACM Multimedia | 3 |
| 2024 | MultiTrust: A Comprehensive Benchmark Towards Trustworthy Multimodal Large Language ModelsabstractDespite the superior capabilities of Multimodal Large Language Models (MLLMs) across diverse tasks, they still face significant trustworthiness challenges. Yet, current literature on the assessment of trustworthy MLLMs remains limited, lacking a holistic evaluation to offer thorough insights into future improvements. In this work, we establish MultiTrust, the first comprehensive and unified benchmark on the trustworthiness of MLLMs across five primary aspects: truthfulness, safety, robustness, fairness, and privacy. Our benchmark employs a rigorous evaluation strategy that addresses both multimodal risks and cross-modal impacts, encompassing 32 diverse tasks with self-curated datasets. Extensive experiments with 21 modern MLLMs reveal some previously unexplored trustworthiness issues and risks, highlighting the complexities introduced by the multimodality and underscoring the necessity for advanced methodologies to enhance their reliability. For instance, typical proprietary models still struggle with the perception of visually confusing images and are vulnerable to multimodal jailbreaking and adversarial attacks; MLLMs are more inclined to disclose privacy in text and reveal ideological and cultural biases even when paired with irrelevant images in inference, indicating that the multimodality amplifies the internal risks from base LLMs. Additionally, we release a scalable toolbox for standardized trustworthiness research, aiming to facilitate future advancements in this important field. Code and resources are publicly available at: https://multi-trust.github.io/. Yichi Zhang 0012, Yitong Sun 0002, Chang Liu 0077, Zhengwei Fang, Huanran Chen, Xiao Yang 0028, Xingxing Wei 0001, Hang Su 0006, Yinpeng Dong, Jun Zhu 0001 |
NeurIPS | 10 |
| 2024 | Defending Adversarial Patches via Joint Region Localizing and Inpainting
Yafu Zhang, Xingxing Wei 0001, Sha Wei |
PRCV (1) | 3 |
| 2024 | Infrared Adversarial Patches with Learnable Shapes and Locations in the Physical World
Xingxing Wei 0001, Jie Yu 0026 |
Int. J. Comput. Vis. | 1 |
| 2024 | Improving Fast Adversarial Training With Prior-Guided KnowledgeabstractFast adversarial training (FAT) is an efficient method to improve robustness in white-box attack scenarios. However, the original FAT suffers from catastrophic overfitting, which dramatically and suddenly reduces robustness after a few training epochs. Although various FAT variants have been proposed to prevent overfitting, they require high training time. In this paper, we investigate the relationship between adversarial example quality and catastrophic overfitting by comparing the training processes of standard adversarial training and FAT. We find that catastrophic overfitting occurs when the attack success rate of adversarial examples becomes worse. Based on this observation, we propose a positive prior-guided adversarial initialization to prevent overfitting by improving adversarial example quality without extra training time. This initialization is generated by using high-quality adversarial perturbations from the historical training process. We provide theoretical analysis for the proposed initialization and propose a prior-guided regularization method that boosts the smoothness of the loss function. Additionally, we design a prior-guided ensemble FAT method that averages the different model weights of historical models using different decay rates. Our proposed method, called FGSM-PGK, assembles the prior-guided knowledge, i.e., the prior-guided initialization and model weights, acquired during the historical training process. The proposed method can effectively improve the model's adversarial robustness in white-box attack scenarios. Evaluations of four datasets demonstrate the superiority of the proposed method. Xiaojun Jia, Yong Zhang 0034, Xingxing Wei 0001, Baoyuan Wu, Ke Ma 0001, Jue Wang 0001, Xiaochun Cao |
IEEE Trans. Pattern Anal. Mach. Intell. | 3 |
| 2024 | Unified Adversarial Patch for Visible-Infrared Cross-Modal Attacks in the Physical WorldabstractPhysical adversarial attacks have put a severe threat to DNN-based object detectors. To enhance security, a combination of visible and infrared sensors is deployed in various scenarios, which has proven effective in disabling existing single-modal physical attacks. To further demonstrate the potential risks in such cases, we design a unified adversarial patch that can perform cross-modal physical attacks, achieving evasion in both modalities simultaneously with a single patch. Given the different imaging mechanisms of visible and infrared sensors, our work manipulates patches' shape features, which can be captured in different modalities when they undergo changes. To deal with challenges, we propose a novel boundary-limited shape optimization approach that aims to achieve compact and smooth shapes for the adversarial patch, making it easy to implement in the physical world. And a score-aware iterative evaluation method is also introduced to balance the fooling degree between visible and infrared detectors during optimization, which guides the adversarial patch to iteratively reduce the predicted scores of the multi-modal sensors. Furthermore, we propose an Affine-Transformation-based enhancement strategy that makes the learnable shape robust to various angles, thus mitigating the issue of shape deformation caused by different shooting angles in the real world. Our method is evaluated against several state-of-the-art object detectors, achieving an Attack Success Rate (ASR) of over 80%. We also demonstrate the effectiveness of our approach in physical-world scenarios under various settings, including different angles, distances, postures, and scenes for both visible and infrared sensors. Xingxing Wei 0001, Yitong Sun 0002, Jie Yu 0026 |
IEEE Trans. Pattern Anal. Mach. Intell. | 1 |
| 2024 | Revisiting the Trade-Off Between Accuracy and Robustness via Weight Distribution of FiltersabstractAdversarial attacks have been proven to be potential threats to Deep Neural Networks (DNNs), and many methods are proposed to defend against adversarial attacks. However, while enhancing the robustness, the accuracy for clean examples will decline to a certain extent, implying a trade-off existed between the accuracy and adversarial robustness. In this paper, to meet the trade-off problem, we theoretically explore the underlying reason for the difference of the filters' weight distribution between standard-trained and robust-trained models and then argue that this is an intrinsic property for static neural networks, thus they are difficult to fundamentally improve the accuracy and adversarial robustness at the same time. Based on this analysis, we propose a sample-wise dynamic network architecture named Adversarial Weight-Varied Network (AW-Net), which focuses on dealing with clean and adversarial examples with a "divide and rule" weight strategy. The AW-Net adaptively adjusts the network's weights based on regulation signals generated by an adversarial router, which is directly influenced by the input sample. Benefiting from the dynamic network architecture, clean and adversarial examples can be processed with different network weights, which provides the potential to enhance both accuracy and adversarial robustness. A series of experiments demonstrate that our AW-Net is architecture-friendly to handle both clean and adversarial examples and can achieve better trade-off performance than state-of-the-art robust models. Xingxing Wei 0001, Bo Li 0006 |
IEEE Trans. Pattern Anal. Mach. Intell. | 1 |
| 2024 | Mitigating Accuracy-Robustness Trade-Off via Balanced Multi-Teacher Adversarial DistillationabstractAdversarial Training is a practical approach for improving the robustness of deep neural networks against adversarial attacks. Although bringing reliable robustness, the performance towards clean examples is negatively affected after Adversarial Training, which means a trade-off exists between accuracy and robustness. Recently, some studies have tried to use knowledge distillation methods in Adversarial Training, achieving competitive performance in improving the robustness but the accuracy for clean samples is still limited. In this paper, to mitigate the accuracy-robustness trade-off, we introduce the Balanced Multi-Teacher Adversarial Robustness Distillation (B-MTARD) to guide the model's Adversarial Training process by applying a strong clean teacher and a strong robust teacher to handle the clean examples and adversarial examples, respectively. During the optimization process, to ensure that different teachers show similar knowledge scales, we design the Entropy-Based Balance algorithm to adjust the teacher's temperature and keep the teachers' information entropy consistent. Besides, to ensure that the student has a relatively consistent learning speed from multiple teachers, we propose the Normalization Loss Balance algorithm to adjust the learning weights of different types of knowledge. A series of experiments conducted on three public datasets demonstrate that B-MTARD outperforms the state-of-the-art methods against various adversarial attacks. Xingxing Wei 0001 |
IEEE Trans. Pattern Anal. Mach. Intell. | 3 |
| 2024 | C²Former: Calibrated and Complementary Transformer for RGB-Infrared Object DetectionabstractObject detection on visible (RGB) and infrared (IR) images, as an emerging solution to facilitate robust detection for around-the-clock applications, has received extensive attention in recent years. With the help of IR images, object detectors have been more reliable and robust in practical applications by using RGB-IR combined information. However, existing methods still suffer from modality miscalibration and fusion imprecision problems. Since transformer has the powerful capability to model the pairwise correlations between different features, in this paper, we propose a novel Calibrated and Complementary Transformer called C2Former to address these two problems simultaneously. In C2Former, we design an Inter-modality Cross-Attention (ICA) module to obtain the calibrated and complementary features by learning the cross-attention relationship between the RGB and IR modality. To reduce the computational cost caused by computing the global attention in ICA, an Adaptive Feature Sampling (AFS) module is introduced to decrease the dimension of feature maps. Because C2Former performs in the feature domain, it can be embedded into existed RGB-IR object detectors via the backbone network. Thus, one single-stage and one two-stage object detector both incorporating our C2Former are constructed to evaluate its effectiveness and versatility. With extensive experiments on the DroneVehicle and KAIST RGB-IR datasets, we verify that our method can fully utilize the RGB-IR complementary information and achieve robust detection results. The code is available at https://github.com/yuanmaoxun/C2Former.git. Maoxun Yuan, Xingxing Wei 0001 |
IEEE Trans. Geosci. Remote. Sens. | 2 |
| 2024 | Boosting Adversarial Transferability With Learnable Patch-Wise MasksabstractAdversarial examples have attracted widespread attention in security-critical applications because of their transferability across different models. Although many methods have been proposed to boost adversarial transferability, a gap still exists between capabilities and practical demand. In this article, we argue that the model-specific discriminative regions are a key factor causing overfitting to the source model, and thus reducing the transferability to the target model. For that, a patch-wise mask is utilized to prune the model-specific regions when calculating adversarial perturbations. To accurately localize these regions, we present a learnable approach to automatically optimize the mask. Specifically, we simulate the target models in our framework, and adjust the patch-wise mask according to the feedback of the simulated models. To improve the efficiency, the differential evolutionary (DE) algorithm is utilized to search for patch-wise masks for a specific image. During iterative attacks, the learned masks are applied to the image to drop out the patches related to model-specific regions, thus making the gradients more generic and improving the adversarial transferability. The proposed approach is a preprocessing method and can be integrated with existing methods to further boost the transferability. Extensive experiments on the ImageNet dataset demonstrate the effectiveness of our method. We incorporate the proposed approach with existing methods to perform ensemble attacks and achieve an average success rate of 93.01% against seven advanced defense methods, which can effectively enhance the state-of-the-art transfer-based attack performance. Xingxing Wei 0001 |
IEEE Trans. Multim. | 1 |
| 2023 | Benchmarking Robustness of 3D Object Detection to Common Corruptions in Autonomous Drivingabstract3D object detection is an important task in autonomous driving to perceive the surroundings. Despite the excellent performance, the existing 3D detectors lack the robustness to real-world corruptions caused by adverse weathers, sensor noises, etc., provoking concerns about the safety and reliability of autonomous driving systems. To comprehensively and rigorously benchmark the corruption robustness of 3D detectors, in this paper we design 27 types of common corruptions for both LiDAR and camera inputs considering realworld driving scenarios. By synthesizing these corruptions on public datasets, we establish three corruption robustness benchmarks-KITTI-C, nuScenes-C, and Waymo-C. Then, we conduct large-scale experiments on 24 diverse 3D object detection models to evaluate their corruption robustness. Based on the evaluation results, we draw several important findings, including: 1) motion-level corruptions are the most threatening ones that lead to significant performance drop of all models; 2) LiDAR-camerafusion models demonstrate better robustness; 3) camera-only models are extremely vulnerable to image corruptions, showing the indispensability of LiDAR point clouds. We release the benchmarks and codes at https://github.com/thu-ml/3D_Corruptions_AD to be helpful for future studies. Yinpeng Dong, Caixin Kang, Jinlai Zhang, Yikai Wang 0001, Xiao Yang 0028, Hang Su 0006, Xingxing Wei 0001, Jun Zhu 0001 |
CVPR | 8 |
| 2023 | Physically Adversarial Infrared Patches with Learnable Shapes and LocationsabstractOwing to the extensive application of infrared object detectors in the safety-critical tasks, it is necessary to evaluate their robustness against adversarial examples in the real world. However, current few physical infrared attacks are complicated to implement in practical application because of their complex transformation from digital world to physical world. To address this issue, in this paper, we propose a physically feasible infrared attack method called “adversarial infrared patches”. Considering the imaging mechanism of infrared cameras by capturing objects' thermal radiation, adversarial infrared patches conduct attacks by attaching a patch of thermal insulation materials on the target object to manipulate its thermal distribution. To enhance adversarial attacks, we present a novel aggregation regularization to guide the simultaneous learning for the patch’ shape and location on the target object. Thus, a simple gradient-based optimization can be adapted to solve for them. We verify adversarial infrared patches in different object detection tasks with various object detectors. Experimental results show that our method achieves more than 90% Attack Success Rate (ASR) versus the pedestrian detector and vehicle detector in the physical environment, where the objects are captured in different angles, distances, postures, and scenes. More importantly, adversarial infrared patch is easy to implement, and it only needs 0.5 hours to be constructed in the physical world, which verifies its effectiveness and efficiency. Xingxing Wei 0001, Jie Yu 0026 |
CVPR | 1 |
| 2023 | Towards Viewpoint-Invariant Visual Recognition via Adversarial TrainingabstractVisual recognition models are not invariant to viewpoint changes in the 3D world, as different viewing directions can dramatically affect the predictions given the same object. Compared to 2D transformations, the exploration of 3D viewpoint invariance deserves more attention for its greater practical significance. Motivated by the success of adversarial training in promoting model robustness, we propose Viewpoint-Invariant Adversarial Training (VIAT) to improve viewpoint robustness of common image classifiers. By regarding viewpoint transformation as an attack, VIAT is formulated as a minimax optimization problem, where the inner maximization characterizes diverse adversarial viewpoints by learning a Gaussian mixture distribution based on a new attack GMVFool, while the outer minimization trains a viewpoint-invariant classifier by minimizing the expected loss over the worst-case adversarial viewpoint distributions. To further improve the generalization performance, a distribution sharing strategy is introduced leveraging the transferability of adversarial viewpoints across objects. Experiments validate the effectiveness of VIAT in improving the viewpoint robustness of various image classifiers based on the diversity of adversarial viewpoints generated by GMVFool. Shouwei Ruan, Yinpeng Dong, Hang Su 0006, Jianteng Peng, Ning Chen 0002, Xingxing Wei 0001 |
ICCV | 6 |
| 2023 | Unified Adversarial Patch for Cross-modal Attacks in the Physical WorldabstractRecently, physical adversarial attacks have been presented to evade DNNs-based object detectors. To ensure the security, many scenarios are simultaneously deployed with visible sensors and infrared sensors, leading to the failures of these single-modal physical attacks. To show the potential risks under such scenes, we propose a unified adversarial patch to perform cross-modal physical attacks, i.e., fooling visible and infrared object detectors at the same time via a single patch. Considering different imaging mechanisms of visible and infrared sensors, our work focuses on modeling the shapes of adversarial patches, which can be captured in different modalities when they change. To this end, we design a novel boundary-limited shape optimization to achieve the compact and smooth shapes, and thus they can be easily implemented in the physical world. In addition, to balance the fooling degree between visible detector and infrared detector during the optimization process, we propose a score-aware iterative evaluation, which can guide the adversarial patch to iteratively reduce the predicted scores of the multi-modal sensors. We finally test our method against the one-stage detector: YOLOv3 and the two-stage detector: Faster RCNN. Results show that our unified patch achieves an Attack Success Rate (ASR) of 73.33% and 69.17%, respectively. More importantly, we verify the effective attacks in the physical world when visible and infrared sensors shoot the objects under various settings like different angles, distances, postures, and scenes. Xingxing Wei 0001, Yitong Sun 0002, Jie Yu 0026 |
ICCV | 1 |
| 2023 | Adversarial Sticker: A Stealthy Attack Method in the Physical WorldabstractTo assess the vulnerability of deep learning in the physical world, recent works introduce adversarial patches and apply them on different tasks. In this paper, we propose another kind of adversarial patch: the Meaningful Adversarial Sticker, a physically feasible and stealthy attack method by using real stickers existing in our life. Unlike the previous adversarial patches by designing perturbations, our method manipulates the sticker's pasting position and rotation angle on the objects to perform physical attacks. Because the position and rotation angle are less affected by the printing loss and color distortion, adversarial stickers can keep good attacking performance in the physical world. Besides, to make adversarial stickers more practical in real scenes, we conduct attacks in the black-box setting with the limited information rather than the white-box setting with all the details of threat models. To effectively solve for the sticker's parameters, we design the Region based Heuristic Differential Evolution Algorithm, which utilizes the new-found regional aggregation of effective solutions and the adaptive adjustment strategy of the evaluation criteria. Our method is comprehensively verified in the face recognition and then extended to the image retrieval and traffic sign recognition. Extensive experiments show the proposed method is effective and efficient in complex physical conditions and has a good generalization for different tasks. Xingxing Wei 0001, Ying Guo 0008, Jie Yu 0026 |
IEEE Trans. Pattern Anal. Mach. Intell. | 1 |
| 2023 | Simultaneously Optimizing Perturbations and Positions for Black-Box Adversarial Patch AttacksabstractAdversarial patch is an important form of real-world adversarial attack that brings serious risks to the robustness of deep neural networks. Previous methods generate adversarial patches by either optimizing their perturbation values while fixing the pasting position or manipulating the position while fixing the patch's content. This reveals that the positions and perturbations are both important to the adversarial attack. For that, in this article, we propose a novel method to simultaneously optimize the position and perturbation for an adversarial patch, and thus obtain a high attack success rate in the black-box setting. Technically, we regard the patch's position, the pre-designed hyper-parameters to determine the patch's perturbations as the variables, and utilize the reinforcement learning framework to simultaneously solve for the optimal solution based on the rewards obtained from the target model with a small number of queries. Extensive experiments are conducted on the Face Recognition (FR) task, and results on four representative FR models show that our method can significantly improve the attack success rate and query efficiency. Besides, experiments on the commercial FR service and physical environments confirm its practical application value. We also extend our method to the traffic sign recognition task to verify its generalization ability. Xingxing Wei 0001, Ying Guo 0008, Jie Yu 0026, Bo Zhang 0056 |
IEEE Trans. Pattern Anal. Mach. Intell. | 1 |
| 2023 | Efficient Robustness Assessment via Adversarial Spatial-Temporal Focus on VideosabstractAdversarial robustness assessment for video recognition models has raised concerns owing to their wide applications on safety-critical tasks. Compared with images, videos have much high dimension, which brings huge computational costs when generating adversarial videos. This is especially serious for the query-based black-box attacks where gradient estimation for the threat models is usually utilized, and high dimensions will lead to a large number of queries. To mitigate this issue, we propose to simultaneously eliminate the temporal and spatial redundancy within the video to achieve an effective and efficient gradient estimation on the reduced searching space, and thus query number could decrease. To implement this idea, we design the novel Adversarial spatial-temporal Focus (AstFocus) attack on videos, which performs attacks on the simultaneously focused key frames and key regions from the inter-frames and intra-frames in the video. AstFocus attack is based on the cooperative Multi-Agent Reinforcement Learning (MARL) framework. One agent is responsible for selecting key frames, and another agent is responsible for selecting key regions. These two agents are jointly trained by the common rewards received from the black-box threat models to perform a cooperative prediction. By continuously querying, the reduced searching space composed of key frames and key regions is becoming precise, and the whole query number becomes less than that on the original video. Extensive experiments on four mainstream video recognition models and three widely used action recognition datasets demonstrate that the proposed AstFocus attack outperforms the SOTA methods, which is prevenient in fooling rate, query number, time, and perturbation magnitude at the same time. Xingxing Wei 0001, Songping Wang, Huanqian Yan |
IEEE Trans. Pattern Anal. Mach. Intell. | 1 |
| 2023 | A2SC: Adversarial Attacks on Subspace ClusteringabstractMany studies demonstrate that supervised learning techniques are vulnerable to adversarial examples. However, adversarial threats in unsupervised learning have not drawn sufficient scholarly attention. In this article, we formally address the unexplored adversarial attacks in the equally important unsupervised clustering field and propose the concept of the adversarial set and adversarial set attack for clustering. To illustrate the basic idea, we design a novel adversarial space-mapping attack algorithm to confuse subspace clustering, one of the mainstream branches of unsupervised clustering. It maps a sample into one wrong class by moving it towards the closest point on the linear subspace of the target class, that is, along the normal of the closest point. This simple single-step algorithm has the power to craft the adversarial set where the image samples can be wrongly clustered, even into the targeted labels. Empirical results on different image datasets verify the effectiveness and superiority of our algorithm. We further show that deep supervised learning algorithms (such as VGG and ResNet) are also vulnerable to our crafted adversarial set, which illustrates the good cross-task transferability of the adversarial set. Yikun Xu, Xingxing Wei 0001, Pengwen Dai, Xiaochun Cao |
ACM Trans. Multim. Comput. Commun. Appl. | 2 |
| 2022 | Prior-Guided Adversarial Initialization for Fast Adversarial Training
Xiaojun Jia, Yong Zhang 0034, Xingxing Wei 0001, Baoyuan Wu, Ke Ma 0001, Jue Wang 0001, Xiaochun Cao |
ECCV (4) | 3 |
| 2022 | Translation, Scale and Rotation: Cross-Modal Alignment Meets RGB-Infrared Vehicle Detection
Maoxun Yuan, Yinyan Wang, Xingxing Wei 0001 |
ECCV (9) | 3 |
| 2022 | Enhanced Accuracy and Robustness via Multi-teacher Adversarial Distillation
Jie Yu 0026, Zhenlong Sun, Bo Zhang 0056, Xingxing Wei 0001 |
ECCV (4) | 5 |
| 2022 | A2SC: Adversarial Attack on Subspace ClusteringabstractMany studies demonstrate supervised learning techniques are vulnerable to adversarial examples. However, adversarial threats in unsupervised learning have not drawn sufficient scholarly attention. In this paper, we formally address the unexplored adversarial attacks in the equally, if not more, important unsupervised clustering field and propose the concept of adversarial set. To illustrate the basic idea, we design an exemplary adversarial space-mapping attack algorithm to confuse subspace clustering, one of the mainstream branches of unsupervised clustering. It maps a sample into one wrong class by moving it towards the closest point on the linear subspace of the target class, i.e. along the normal of the closest point. The simple single-step algorithm is powerful to craft the adversarial set where the samples can be wrongly clustered, even into targeted labels. The adversarial set has the merit of transferability among subspace clustering schemes. Empirical results verify the effectiveness and transferability of our algorithm. Yikun Xu, Xingxing Wei 0001 |
ICME | 2 |
| 2022 | ViewFool: Evaluating the Robustness of Visual Recognition to Adversarial ViewpointsabstractRecent studies have demonstrated that visual recognition models lack robustness to distribution shift. However, current work mainly considers model robustness to 2D image transformations, leaving viewpoint changes in the 3D world less explored. In general, viewpoint changes are prevalent in various real-world applications (e.g., autonomous driving), making it imperative to evaluate viewpoint robustness. In this paper, we propose a novel method called ViewFool to find adversarial viewpoints that mislead visual recognition models. By encoding real-world objects as neural radiance fields (NeRF), ViewFool characterizes a distribution of diverse adversarial viewpoints under an entropic regularizer, which helps to handle the fluctuations of the real camera pose and mitigate the reality gap between the real objects and their neural representations. Experiments validate that the common image classifiers are extremely vulnerable to the generated adversarial viewpoints, which also exhibit high cross-model transferability. Based on ViewFool, we introduce ImageNet-V, a new out-of-distribution dataset for benchmarking viewpoint robustness of image classifiers. Evaluation results on 40 classifiers with diverse architectures, objective functions, and data augmentations reveal a significant drop in model performance when tested on ImageNet-V, which provides a possibility to leverage ViewFool as an effective data augmentation strategy to improve viewpoint robustness. Yinpeng Dong, Shouwei Ruan, Hang Su 0006, Caixin Kang, Xingxing Wei 0001, Jun Zhu 0001 |
NeurIPS | 5 |
| 2022 | Enhancing Transferability of Adversarial Examples with Spatial Momentum
Guoqiu Wang, Huanqian Yan, Xingxing Wei 0001 |
PRCV (1) | 3 |
| 2022 | Sparse Black-Box Video Attack with Reinforcement Learning
Xingxing Wei 0001, Huanqian Yan, Bo Li 0006 |
Int. J. Comput. Vis. | 1 |
| 2022 | A motional but temporally consistent physical video examples
Zhenyu Du 0002, Xingxing Wei 0001, Weiming Zhang 0001, Fangzheng Liu, Huanyu Bian |
J. Inf. Secur. Appl. | 2 |
| 2021 | Parallel Rectangle Flip Attack: A Query-based Black-box Attack against Object DetectionabstractObject detection has been widely used in many safety- critical tasks, such as autonomous driving. However, its vulnerability to adversarial examples has not been sufficiently studied, especially under the practical scenario of black-box attacks, where the attacker can only access the query feedback of predicted bounding-boxes and top- 1 scores returned by the attacked model. Compared with black-box attack to image classification, there are two main challenges in black-box attack to detection. Firstly, even if one bounding-box is successfully attacked, another sub- optimal bounding-box may be detected near the attacked bounding-box. Secondly, there are multiple bounding- boxes, leading to very high attack cost. To address these challenges, we propose a Parallel Rectangle Flip Attack (PRFA) via random search. We explain the difference between our method with other attacks in Fig. 1. Specifically, we generate perturbations in each rectangle patch to avoid sub-optimal detection near the attacked region. Besides, utilizing the observation that adversarial perturbations mainly locate around objects’ contours and critical points under white-box attacks, the search space of attacked rectangles is reduced to improve the attack efficiency. Moreover, we develop a parallel mechanism of attacking multiple rectangles simultaneously to further accelerate the attack process. Extensive experiments demonstrate that our method can effectively and efficiently attack various popular object detectors, including anchor-based and anchor- free, and generate transferable adversarial examples. Siyuan Liang 0004, Baoyuan Wu, Yanbo Fan, Xingxing Wei 0001, Xiaochun Cao |
ICCV | 4 |
| 2021 | Efficient Sparse Attacks on Videos using Reinforcement LearningabstractMore and more deep neural network models have been deployed in real-time video systems. However, it is proved that deep models are susceptible to the crafted adversarial examples. The adversarial examples are imperceptible and can make the normal deep models misclassify them. Although there exist a few works aiming at the adversarial examples of video recognition in the black-box attack mode, most of them need large perturbations or hundreds of thousands of queries. There are still lack of effective adversarial methods to produce adversarial videos with small perturbations and limited query numbers at the same time. Huanqian Yan, Xingxing Wei 0001 |
ACM Multimedia | 2 |
| 2021 | Black-box adversarial attacks by manipulating image attributes
Xingxing Wei 0001, Ying Guo 0008, Bo Li 0006 |
Inf. Sci. | 1 |
| 2021 | Ship Detection in Spaceborne Infrared Image Based on Lightweight CNN and Multisource Feature Cascade DecisionabstractInfrared remote-sensing images have irreplaceable value in military and civilian research, such as remote surveillance and military reconnaissance. However, under the conditions of complex scenes, infrared ship detection still faces great challenges. Most importantly, because of the limited hardware resource, the spaceborne satellites usually have weak computational processing ability, which makes the traditional convolution neural network (CNN)-based detection algorithms difficult to show their power. In terms of the above facts, this article proposes a high-performance but low-computation and storage-efficient ship detection algorithm to adapt the severe spaceborne environment. Overall, our method contains the following technical steps: 1) we first present a novel iterative precise segmentation of land and sea algorithm to preprocess the complex and diverse remote-sensing scenes; 2) the multivariate Gaussian distribution is then selected to extract the ship target candidate regions to guarantee the detection recall; 3) we adopt the optical panchromatic data to assist the limited infrared data training; and 4) the cascade decision of multisource features including global and local cues is next utilized to gradually eliminate false alarms. Due to the high efficiency, the proposed method can implement well on the hardware platform of DSP and field-programmable gate array (FPGA) architecture. We conduct a series of experiments and compare with the state-of-the-art object detection algorithms. Experimental results show that our method has fewer parameters but can achieve strong detection robustness against the noise, cloud and reef interfere, which verifies the effectiveness of the proposed method. Nan Wang 0014, Bo Li 0006, Xingxing Wei 0001, Huanqian Yan |
IEEE Trans. Geosci. Remote. Sens. | 3 |
| 2020 | Efficient Adversarial Attacks for Visual Object Tracking
Siyuan Liang 0004, Xingxing Wei 0001, Siyuan Yao, Xiaochun Cao |
ECCV (26) | 2 |
| 2020 | Adv-watermark: A Novel Watermark Perturbation for Adversarial ExamplesabstractRecent research has demonstrated that adding some imperceptible perturbations to original images can fool deep learning models. However, the current adversarial perturbations are usually shown in the form of noises, and thus have no practical meaning. Image watermark is a technique widely used for copyright protection. We can regard image watermark as a king of meaningful noises and adding it to the original image will not affect people's understanding of the image content, and will not arouse people's suspicion. Therefore, it will be interesting to generate adversarial examples using watermarks. In this paper, we propose a novel watermark perturbation for adversarial examples (Adv-watermark) which combines image watermarking techniques and adversarial example algorithms. Adding a meaningful watermark to the clean images can attack the DNN models. Specifically, we propose a novel optimization algorithm, which is called Basin Hopping Evolution (BHE), to generate adversarial watermarks in the black-box attack mode. Thanks to the BHE, Adv-watermark only requires a few queries from the threat models to finish the attacks. A series of experiments conducted on ImageNet and CASIA-WebFace datasets show that the proposed method can efficiently generate adversarial examples, and outperforms the state-of-the-art attack methods. Moreover, Adv-watermark is more robust against image transformation defense methods. Xiaojun Jia, Xingxing Wei 0001, Xiaochun Cao, Xiaoguang Han 0001 |
ACM Multimedia | 2 |
| 2020 | Defense for adversarial videos by self-adaptive JPEG compression and optical textureabstractDespite demonstrated outstanding effectiveness in various computer vision tasks, Deep Neural Networks (DNNs) are known to be vulnerable to adversarial examples. Nowadays, adversarial attacks as well as their defenses w.r.t. DNNs in image domain have been intensively studied, and there are some recent works starting to explore adversarial attacks w.r.t. DNNs in video domain. However, the corresponding defense is rarely studied. In this paper, we propose a new two-stage framework for defending video adversarial attack. It contains two main components, namely self-adaptive Joint Photographic Experts Group (JPEG) compression defense and optical texture based defense (OTD). In self-adaptive JPEG compression defense, we propose to adaptively choose an appropriate JPEG quality based on an estimation of moving foreground object, such that the JPEG compression could depress most impact of adversarial noise without losing too much video quality. In OTD, we generate "optical texture" containing high-frequency information based on the optical flow map, and use it to edit Y channel (in YCrCb color space) of input frames, thus further reducing the influence of adversarial perturbation. Experimental results on a benchmark dataset demonstrate the effectiveness of our framework in recovering the classification performance on perturbed videos. Yupeng Cheng, Xingxing Wei 0001, Huazhu Fu, Shangwei Lin 0001, Weisi Lin |
MMAsia | 2 |
| 2019 | Sparse Adversarial Perturbations for VideosabstractAlthough adversarial samples of deep neural networks (DNNs) have been intensively studied on static images, their extensions in videos are never explored. Compared with images, attacking a video needs to consider not only spatial cues but also temporal cues. Moreover, to improve the imperceptibility as well as reduce the computation cost, perturbations should be added on as few frames as possible, i.e., adversarial perturbations are temporally sparse. This further motivates the propagation of perturbations, which denotes that perturbations added on the current frame can transfer to the next frames via their temporal interactions. Thus, no (or few) extra perturbations are needed for these frames to misclassify them. To this end, we propose the first white-box video attack method, which utilizes an l2,1-norm based optimization algorithm to compute the sparse adversarial perturbations for videos. We choose the action recognition as the targeted task, and networks with a CNN+RNN architecture as threat models to verify our method. Thanks to the propagation, we can compute perturbations on a shortened version video, and then adapt them to the long version video to fool DNNs. Experimental results on the UCF101 dataset demonstrate that even only one frame in a video is perturbed, the fooling rate can still reach 59.7%. Xingxing Wei 0001, Jun Zhu 0001, Sha Yuan, Hang Su 0006 |
AAAI | 1 |
| 2019 | ComDefend: An Efficient Image Compression Model to Defend Adversarial ExamplesabstractDeep neural networks (DNNs) have been demonstrated to be vulnerable to adversarial examples. Specifically, adding imperceptible perturbations to clean images can fool the well trained deep neural networks. In this paper, we propose an end-to-end image compression model to defend adversarial examples: ComDefend. The proposed model consists of a compression convolutional neural network (ComCNN) and a reconstruction convolutional neural network (ResCNN). The ComCNN is used to maintain the structure information of the original image and purify adversarial perturbations. And the ResCNN is used to reconstruct the original image with high quality. In other words, ComDefend can transform the adversarial image to its clean version, which is then fed to the trained classifier. Our method is a pre-processing module, and does not modify the classifier's structure during the whole process. Therefore it can be combined with other model-specific defense models to jointly improve the classifier's robustness. A series of experiments conducted on MNIST, CIFAR10 and ImageNet show that the proposed method outperforms the state-of-the-art defense methods, and is consistently effective to protect classifiers against adversarial attacks. Xiaojun Jia, Xingxing Wei 0001, Xiaochun Cao, Hassan Foroosh |
CVPR | 2 |
| 2019 | Transferable Adversarial Attacks for Image and Video Object DetectionabstractIdentifying adversarial examples is beneficial for understanding deep networks and developing robust models. However, existing attacking methods for image object detection have two limitations: weak transferability---the generated adversarial examples often have a low success rate to attack other kinds of detection methods, and high computation cost---they need much time to deal with video data, where many frames need polluting. To address these issues, we present a generative method to obtain adversarial images and videos, thereby significantly reducing the processing time. To enhance transferability, we manipulate the feature maps extracted by a feature network, which usually constitutes the basis of object detectors. Our method is based on the Generative Adversarial Network (GAN) framework, where we combine a high-level class loss and a low-level feature loss to jointly train the adversarial example generator. Experimental results on PASCAL VOC and ImageNet VID datasets show that our method efficiently generates image and video adversarial examples, and more importantly, these adversarial examples have better transferability, therefore being able to simultaneously attack two kinds of representative object detection models: proposal based models like Faster-RCNN and regression based models like SSD. Xingxing Wei 0001, Siyuan Liang 0004, Ning Chen 0002, Xiaochun Cao |
IJCAI | 1 |
| 2018 | Video-to-Video Translation with Global Temporal ConsistencyabstractAlthough image-to-image translation has been widely studied, the video-to-video translation is rarely mentioned. In this paper, we propose an unified video-to-video translation framework to accom- plish different tasks, like video super-resolution, video colouriza- tion, and video segmentation, etc. A consequent question within video-to-video translation lies in the flickering appearance along with the varying frames. To overcome this issue, a usual method is to incorporate the temporal loss between adjacent frames in the optimization, which is a kind of local frame-wise temporal con- sistency. We instead present a residual error based mechanism to ensure the video-level consistency of the same location in different frames (called (lobal temporal consistency). The global and local consistency are simultaneously integrated into our video-to-video framework to achieve more stable videos. Our method is based on the GAN framework, where we present a two-channel discrimina- tor. One channel is to encode the video RGB space, and another is to encode the residual error of the video as a whole to meet the global consistency. Extensive experiments conducted on different video- to-video translation tasks verify the effectiveness and flexibleness of the proposed method. Xingxing Wei 0001, Jun Zhu 0001, Sitong Feng, Hang Su 0006 |
ACM Multimedia | 1 |
| 2017 | No embedding: A novel image cryptosystem for meaningful encryption
Xingwu Cao, Xingxing Wei 0001, Changchun Wang |
J. Vis. Commun. Image Represent. | 2 |
| 2016 | High Capacity Reversible Data Hiding in Encrypted Images by Patch-Level Sparse RepresentationabstractReversible data hiding in encrypted images has attracted considerable attention from the communities of privacy security and protection. The success of the previous methods in this area has shown that a superior performance can be achieved by exploiting the redundancy within the image. Specifically, because the pixels in the local structures (like patches or regions) have a strong similarity, they can be heavily compressed, thus resulting in a large hiding room. In this paper, to better explore the correlation between neighbor pixels, we propose to consider the patch-level sparse representation when hiding the secret data. The widely used sparse coding technique has demonstrated that a patch can be linearly represented by some atoms in an over-complete dictionary. As the sparse coding is an approximation solution, the leading residual errors are encoded and self-embedded within the cover image. Furthermore, the learned dictionary is also embedded into the encrypted image. Thanks to the powerful representation of sparse coding, a large vacated room can be achieved, and thus the data hider can embed more secret messages in the encrypted image. Extensive experiments demonstrate that the proposed method significantly outperforms the state-of-the-art methods in terms of the embedding rate and the image quality. Xiaochun Cao, Xingxing Wei 0001, Dan Meng 0002, Xiaojie Guo 0001 |
IEEE Trans. Cybern. | 3 |
| 2015 | A flexible framework of adaptive method selection for image saliency detection
Changqing Zhang 0002, Zhiqiang Tao, Xingxing Wei 0001, Xiaochun Cao |
Pattern Recognit. Lett. | 3 |
| 2015 | Structured Saliency Fusion Based on Dempster-Shafer TheoryabstractVisual saliency has been widely used in many applications. However, the performance of an individual saliency detection method varies with the different images. Integrating multiple methods together could compensate this shortcoming, and thus is expected to improve the performance of saliency detection. In this paper, we present an unsupervised Dempster–Shafer Theory (DST) based saliency fusion framework. DST simulates the similar reasoning logic with humans to make decision analysis, and has been proved a suitable method for data fusion. Inspired by this, our framework formalizes the saliency fusion as a statistics inference process, considering the results from several saliency methods to accomplish the fusion task. Furthermore, the proposed framework can flexibly incorporate a variety of inherent structured priors within the images (e.g., clusters and saliency voting) when leveraging the fusion rule of DST. Therefore, it is more close to the fusion mechanism. Experimental results on two benchmark datasets demonstrate the effectiveness and robustness of our framework. Xingxing Wei 0001, Zhiqiang Tao, Changqing Zhang 0002, Xiaochun Cao |
IEEE Signal Process. Lett. | 1 |
| 2015 | An Object-Level High-Order Contextual Descriptor Based on Semantic, Spatial, and Scale CuesabstractContext has been playing an increasingly important role in areas such as object detection, scene understanding, and image segmentation. Although many different types of contextual cues have been successfully explored, most of them only consider the pair-wise relationship between objects or parts. Several models utilize the high-order relationship for encoding contextual information. However, they mainly use a single contextual cue. In this paper, we present a novel high-order contextual descriptor (HOOD) to measure the strength of interactions among objects within an image. Heterogeneous contextual cues like semantic, spatial, and scale contexts are jointly integrated into HOOD to define the high-order interactions. The strength of these interactions are inferred by applying Bayes' rule on the pure dependence of the involved objects. As a result, an object-level graph is constructed to represent the contextually consistent interactions. Moreover, we propose a HOOD based object localization framework to verify the effectiveness of HOOD. Experimental results on two benchmark datasets including SUN09 and PASCAL2007 show that our framework outperforms the state-of-the-art context based object localization methods. Finally, we apply HOOD on two multimedia applications: structured image retrieval and out-of-context object detection, which demonstrates the potential usages of HOOD. Xiaochun Cao, Xingxing Wei 0001, Yahong Han, Xiaowu Chen 0001 |
IEEE Trans. Cybern. | 2 |
| 2015 | Robust Face Clustering Via Tensor DecompositionabstractFace clustering is a key component either in image managements or video analysis. Wild human faces vary with the poses, expressions, and illumination changes. All kinds of noises, like block occlusions, random pixel corruptions, and various disguises may also destroy the consistency of faces referring to the same person. This motivates us to develop a robust face clustering algorithm that is less sensitive to these noises. To retain the underlying structured information within facial images, we use tensors to represent faces, and then accomplish the clustering task based on the tensor data. The proposed algorithm is called robust tensor clustering (RTC), which firstly finds a lower-rank approximation of the original tensor data using a L1 norm optimization function. Because L1 norm does not exaggerate the effect of noises compared with L2 norm, the minimization of the L1 norm approximation function makes RTC robust. Then, we compute high-order singular value decomposition of this approximate tensor to obtain the final clustering results. Different from traditional algorithms solving the approximation function with a greedy strategy, we utilize a nongreedy strategy to obtain a better solution. Experiments conducted on the benchmark facial datasets and gait sequences demonstrate that RTC has better performance than the state-of-the-art clustering algorithms and is more robust to noises. Xiaochun Cao, Xingxing Wei 0001, Yahong Han, Dongdai Lin |
IEEE Trans. Cybern. | 2 |
| 2014 | Augmented Image Retrieval using Multi-order Object Layout with AttributesabstractIn image retrieval, users' search intention is usually specified by textual queries, exemplar images, concept maps, and even sketches, which can only express the search intention partially. These query strategies lack the abilities to indicate the Regions Of Interests (ROIs) and represent the spatial or semantic correlations among the ROIs, which results in the so-called semantic gap between users' search intention and images' low-level visual content. In this paper, we propose a novel image search method, which allows the users to indicate any number of Regions Of Interest (ROIs) within the query as well as utilize various semantic concepts and spatial relations to search images. Specifically, we firstly propose a structured descriptor to jointly represent the categories, attributes, and spatial relations among objects. Then, based on the defined descriptor, our method ranks the images in the database according to the matching scores w.r.t. the category, attribute, and spatial relations. We conduct the experiments on the aPascal and aYahoo datasets, and experimental results show the advantage of the proposed method compared to the state of the arts. Xiaochun Cao, Xingxing Wei 0001, Xiaojie Guo 0001, Yahong Han, Jinhui Tang 0001 |
ACM Multimedia | 2 |
| 2014 | Augmenting Image Descriptions Using Structured Prediction OutputabstractThe need for richer descriptions of images arises in a wide spectrum of applications ranging from image understanding to image retrieval. While the Automatic Image Annotation (AIA) has been extensively studied, image descriptions with the output labels lack sufficient information. This paper proposes to augment image descriptions using structured prediction output. We define a hierarchical tree-structured semantic unit to describe images, from which we can obtain not only the class and subclass one image belongs to, but also the attributes one image has. After defining a new feature map function of structured SVM, we decompose the loss function into every node of the hierarchical tree-structured semantic unit and then predict the tree-structured semantic unit for testing images. In the experiments, we evaluate the performance of the proposed method on two open benchmark datasets and compare with the state-of-the-art methods. Experimental results show the better prediction performance of the proposed method and demonstrate the strength of augmenting image descriptions. Yahong Han, Xingxing Wei 0001, Xiaochun Cao, Yi Yang 0001, Xiaofang Zhou 0001 |
IEEE Trans. Multim. | 2 |
| 2013 | Robust Tensor Clustering with Non-Greedy Maximization
Xiaochun Cao, Xingxing Wei 0001, Yahong Han, Yi Yang 0001, Dongdai Lin |
IJCAI | 2 |
| 2013 | Unified Dictionary Learning and Region Tagging with Hierarchical Sparse Representation
Xiaochun Cao, Xingxing Wei 0001, Yahong Han, Yi Yang 0001, Nicu Sebe, Alex Hauptmann 0001 |
Comput. Vis. Image Underst. | 2 |