Xiaowei Huang 0001

dblp:60/5414-1 · DBLP profile ↗
← Back
137ranked-venue papers
23as first author
95since 2021 · last 2026
0000-0001-6267-0366ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 86 · 14 first-author · 62 since 2021Graphics, computer vision, multimedia, augmented reality and games · 51 · 12 first-author · 33 since 2021Software engineering, systems software and programming languages · 13 · 3 first-author · 6 since 2021Systems, architecture and hardware · 11 · 6 since 2021Theory of computation · 10 · 6 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 9 · 1 first-author · 7 since 2021Security and privacy · 5 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 5 · 4 since 2021Computer networks · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Fragile by Design: On the Limits of Adversarial Defenses in Personalized DreamBooth Generation
abstract
Personalized AI applications such as DreamBooth enable the generation of customized content from user images, but also raise significant privacy concerns, particularly the risk of facial identity leakage. Recent defense mechanisms like Anti-DreamBooth attempt to mitigate this risk by injecting adversarial perturbations into user photos to prevent successful personalization. However, we identify two critical yet overlooked limitations of these methods. First, the adversarial examples often exhibit perceptible artifacts such as conspicuous patterns or stripes, making them easily detectable as manipulated content. Second, the perturbations are highly fragile, as even a simple, non-learned filter can effectively remove them, thereby restoring the model's ability to memorize and reproduce user identity. To investigate this vulnerability, we propose a novel evaluation framework, AntiDB_Purify, to systematically evaluate existing defenses under realistic purification threats, including both traditional image filters and adversarial purification. Results reveal that none of the current methods maintains their protective effectiveness under such threats. These findings highlight that current defenses offer a false sense of security and underscore the urgent need for more imperceptible and robust protections to safeguard user identity in personalized generation.
Yi Zhang 0141, Xiangyu Yin 0001, Chengxuan Qin, Xingyu Zhao 0001, Xiaowei Huang 0001, Wenjie Ruan
AAAI6
2026 Tapas Are Free! Training-Free Adaptation of Programmatic Agents via LLM-Guided Program Synthesis in Dynamic Environments
abstract
Autonomous agents in safety-critical applications must continuously adapt to dynamic conditions without compromising performance and reliability. This work introduces TAPA (Training-free Adaptation of Programmatic Agents), a novel framework that positions large language models (LLMs) as intelligent moderators of the symbolic action space. Unlike prior programmatic agents typically generate a monolithic policy program or rely on fixed symbolic action sets, TAPA synthesizes and adapts modular programs for individual high-level actions, referred to as logical primitives. By decoupling strategic intent from execution, TAPA enables meta-agents to operate over an abstract, interpretable action space while the LLM dynamically generates, composes, and refines symbolic programs tailored to each primitive. Extensive experiments across cybersecurity and swarm intelligence domains validate TAPA's effectiveness. In autonomous DDoS defense scenarios, TAPA achieves 77.7% network uptime while maintaining near-perfect detection accuracy in unknown dynamic environments. In swarm intelligence formation control under environmental and adversarial disturbances, TAPA consistently preserves consensus at runtime where baseline methods fail. This work promotes a paradigm shift for autonomous system design in evolving environments, from policy adaptation to dynamic action adaptation.
Jinwei Hu 0001, Yi Dong 0002, Youcheng Sun, Xiaowei Huang 0001
AAAI4
2026 Lying with Truths: Open-Channel Multi-Agent Collusion for Belief Manipulation via Generative Montage
abstract
As large language models (LLMs) transition to autonomous agents synthesizing real-time information, their reasoning capabilities introduce an unexpected attack surface. This paper introduces a novel threat where colluding agents steer victim beliefs using only truthful evidence fragments distributed through public channels, without relying on covert communications, backdoors, or falsified documents. By exploiting LLMs' overthinking tendency, we formalize the first cognitive collusion attack and propose Generative Montage: a Writer-Editor-Director framework that constructs deceptive narratives through adversarial debate and coordinated posting of evidence fragments, causing victims to internalize and propagate fabricated conclusions. To study this risk, we develop CoPHEME, a dataset derived from real-world rumor events, and simulate attacks across diverse LLM families. Our results show pervasive vulnerability across 14 LLM families: attack success rates reach 74.4% for proprietary models and 70.6% for open-weights models. Counterintuitively, stronger reasoning capabilities increase susceptibility, with reasoning-specialized models showing higher attack success than base models or prompts. Furthermore, these false beliefs then cascade to downstream judges, achieving over 60% deception rates, highlighting a socio-technical vulnerability in how LLM-based agents interact with dynamic information environments. Our implementation and data are available at: https://github.com/CharlesJW222/Lying_with_Truth/tree/main.
Jinwei Hu 0001, Xinmiao Huang, Youcheng Sun, Yi Dong 0002, Xiaowei Huang 0001
ACL (1)5
2026 Chain-of-Thought as a Lens: Evaluating Structured Reasoning Alignment between Human Preferences and Large Language Models
abstract
This paper primarily demonstrates a method to quantitatively assess the alignment between multi-step, structured reasoning in large language models and human preferences.We introduce the Alignment Score, a semantic-level metric that compares a model-produced chain of thought traces with a human-preferred reference by constructing semantic-entropy-based matrices over intermediate steps and measuring their divergence.Our analysis shows that Alignment Score tracks task accuracy across models and hop depths, and peaks at 2-hop reasoning.Empirical results further indicate that misalignment at greater reasoning depths is driven mainly by alignment errors such as thematic shift and redundant reasoning.Viewing chain sampling as drawing from a distribution over reasoning paths, we empirically demonstrate a strong and consistent correlation between Alignment Score and accuracy, readability, and coherence, supporting its use as a diagnostic signal.The code is available.
Zhuoyun Li, Xinmiao Huang, Xiaowei Huang 0001, Yi Dong 0002
ACL (1)4
2026 Formal Analysis of Hopfield Networks through 0-1 Integer Linear Programming and SMT Solving
Sahar M. Alzahrani, Sven Schewe, Xiaowei Huang 0001
ICAART (2)3
2026 Efficient Repair of Binarized Neural Networks Using Binary Activation Lookup Tables
Sahar M. Alzahrani, Sven Schewe, Xiaowei Huang 0001
ICAART (3)3
2026 A Unified Framework for PAC-Bayesian Norm-based Generalization Bounds
Xinping Yi, Gaojie Jin, Xiaowei Huang 0001, Shi Jin 0002
ISIT3
2026 Contrastive prompt clustering for weakly supervised semantic segmentation
Wangyu Wu, Wenqiao Zhang, Xianglin Qiu, Siqi Song, Xiaowei Huang 0001, Fei Ma 0002, Jimin Xiao
Expert Syst. Appl.7
2026 LLM-enhanced multimodal fusion for cross-domain sequential recommendation
Wangyu Wu, Wenqiao Zhang, Siqi Song, Xianglin Qiu, Xiaowei Huang 0001, Fei Ma 0002, Jimin Xiao
Expert Syst. Appl.6
2026 Revisiting Out-of-Distribution Detection in Real-Time Object Detection: From Benchmark Pitfalls to a New Mitigation Paradigm
abstract
Out-of-distribution (OoD) inputs pose a persistent challenge to deep learning models, often triggering overconfident predictions on non-target objects. While prior work has primarily focused on refining scoring functions and adjusting test-time thresholds, such algorithmic improvements offer only incremental gains. We argue that a rethinking of the entire development lifecycle is needed to mitigate these risks effectively. This work addresses two overlooked dimensions of OoD detection in object detection. First, we reveal fundamental flaws in widely used evaluation benchmarks: contrary to their design intent, up to 13% of objects in the OoD test sets actually belong to in-distribution classes, and vice versa. These quality issues severely distort the reported performance of existing methods and contribute to their high false positive rates. Second, we introduce a novel training-time mitigation paradigm that operates independently of external OoD detectors. Instead of relying solely on post-hoc scoring, we fine-tune the detector using a carefully synthesized OoD dataset that semantically resembles in-distribution objects. This process shapes a defensive decision boundary by suppressing objectness on OoD objects, leading to a 91% reduction in hallucination error of a YOLO model on BDD-100 K. Our methodology generalizes across detection paradigms such as YOLO, Faster R-CNN, and RT-DETR, and supports few-shot adaptation. Together, these contributions offer a principled and effective way to reduce OoD-induced hallucination in object detectors.
Changshun Wu, Weicheng He, Chih-Hong Cheng, Xiaowei Huang 0001, Saddek Bensalem
IEEE Trans. Pattern Anal. Mach. Intell.4
2026 You look from old classes: Towards accurate few shot class-incremental learning
Yijie Hu, Kaizhu Huang, Wei Wang 0042, Xiaowei Huang 0001, Qiufeng Wang 0001
Pattern Recognit.4
2026 DiffClick: Click-differentiated enhancement network for interactive segmentation
Siqi Song, Siyue Yu, Huiyu Zhou 0001, Xiaowei Huang 0001, Limin Yu, Jimin Xiao
Pattern Recognit.4
2026 Two-stage transfer learning for airborne multi-spectral image classifiers
abstract
In this work, we propose a novel training paradigm designed to support transfer learning for more effective classification in multispectral airborne imagery. Current state-of-the-art approaches typically rely on either leveraging solely RGB (red-green-blue) pretraining or applying in-domain transfer learning for multispectral imagery classification. Instead, our approach constructs and trains two separate neural network models (backbones): one specifically for wavelengths with available pretrained data (like visible bands) and another trained from scratch on all-bands available in the dataset. These models are then integrated with a fully-connected layer or multi-layered perceptron, which is trained on the features from both networks. This allows us to exploit the significant benefits of generalizable features learned from RGB datasets and the information provided by the full spectrum of multispectral bands. We employ the BigEarthNet and EuroSAT datasets, encompassing Sentinel-2 satellite imagery in the visual and infrared bands. This approach yields considerable performance gains in comparison with other training strategies across every evaluation metric we utilized for these datasets. The results are also consistent across a variety of backbone architectures, underlining the efficacy of our transfer learning technique in the analysis of multispectral data. • A two-stage transfer learning technique is proposed to combine RGB pre-trained models with scratch-trained models on all spectral bands, to integrate features from both to improve classification accuracy and leverage strengths for multispectral airborne imagery. • The strategy has significant performance gains compared to other approached, across multiple neural network backbones and datasets, including BigEarthNet and EuroSAT, highlighting the robustness of the proposed methodology. • The proposed method can be used with state-of-the-art pretraining architectures, enabling the integration and utilization of the latest advancements in machine learning and artificial intelligence.
Benjamin Rise, Murat Üney, Xiaowei Huang 0001
Signal Process.3
2026 Adversarial Training for Graph Neural Networks via Graph Subspace Energy Optimization
abstract
Despite impressive capability in learning over graphstructured data, graph neural networks (GNN) suffer from adversarial topology perturbation in both training and inference phases. While adversarial training has demonstrated remarkable effectiveness in image classification tasks, its suitability for GNN models has been doubted until a recent advance that shifts the focus fromtransductivetoinductivelearning. Still, GNN robustness in the inductive setting is under-explored, and it calls for deeper understanding of GNN adversarial training. To this end, we introduce a concept of graph subspace energy (GSE)—a generalization of graph energy that measures graph stability—of the adjacency matrix, as an indicator of GNN robustness against topology perturbations. To further demonstrate the effectiveness of such concept, we propose an adversarial training method with the perturbed graphs generated by maximizing the GSE regularization term, referred to as AT-GSE. To deal with the local and global topology perturbations raised respectively by LRBCD and PRBCD, we employ randomized SVD (RndSVD) and Nyström low-rank approximation to favor the different aspects of the GSE terms. An extensive set of experiments shows that AT-GSE outperforms consistently the state-of-the-art GNN adversarial training methods over different homophily and heterophily datasets in terms of adversarial accuracy, whilst more surprisingly achieving a superior clean accuracy on non-perturbed graphs.
Ganlin Liu, Ziling Liang, Xiaowei Huang 0001, Xinping Yi, Shi Jin 0002
IEEE Trans. Inf. Forensics Secur.3
2026 Clue and Context Fusion for Sarcasm Detection with Large Multimodal Models
abstract
Detecting sarcasm in social media is fundamentally different from general VLM benchmarks: it is a pragmatic contradiction problem in which the literal signal in one modality is intentionally misaligned with the intended meaning, while dominant pre-training (e.g., CLIP-style contrastive agreement) biases models toward modality alignment rather than incongruity detection. We present SCARF, a contradiction-aware framework that equips large multimodal models with explicit sarcasm cues and context-sensitive retrieval. SCARF constructs coarse scene cues and fine localized evidence via tag-constrained QA, then distills them with visual tokens into a [FUSION] control vector for the LLM; a label-contrastive retriever supplies type- and context-matched exemplars, and a local multi-view encoder surfaces micro-cues. With the same backbone and training data, SCARF attains 87.92% Acc/86.67% F1 on MMSD2.0 and 77.14% Acc/76.44% F1 zero-shot on XDMSD, outperforming a comparably fine-tuned LLaVA-1.5. Ablations show sarcasm clue fusion is the main driver of gains, and tag-constrained QA improves rationale grounding and reduces hallucinations.
Yushan Pan, Ding Wang 0006, Wei Wang 0042, Xiaowei Huang 0001, Zhijie Xu
ACM Trans. Intell. Syst. Technol.5
2025 Risk Controlled Image Retrieval
abstract
Most image retrieval research prioritizes improving predictive performance, often overlooking situations where the reliability of predictions is equally important. The gap between model performance and reliability requirements highlights the need for a systematic approach to analyze and address the risks associated with image retrieval. Uncertainty quantification technique can be applied to mitigate this issue by assessing uncertainty for retrieval sets, but it provides only a heuristic estimate of uncertainty rather than a guarantee. To address these limitations, we present Risk Controlled Image Retrieval (RCIR), which generates retrieval sets with coverage guarantee, i.e., retrieval sets that are guaranteed to contain the true nearest neighbors with a predefined probability. RCIR can be easily integrated with existing uncertainty-aware image retrieval systems, agnostic to data distribution and model selection. To the best of our knowledge, this is the first work that provides coverage guarantees to image retrieval. The validity and efficiency of RCIR are demonstrated on four real-world datasets: CAR-196, CUB-200, Pittsburgh, and ChestX-Det.
Kaiwen Cai, Xiaoxuan Lu 0001, Xingyu Zhao 0001, Wei Huang 0035, Xiaowei Huang 0001
AAAI5
2025 Training Verification-Friendly Neural Networks via Neuron Behavior Consistency
abstract
Formal verification provides critical security assurances for neural networks, yet its practical application suffers from the long verification time. This work introduces a novel method for training verification-friendly neural networks, which are robust, easy to verify, and relatively accurate. Our method integrates neuron behavior consistency into the training process, making neuron activation states remain consistent across different inputs within a local neighborhood. This reduces the number of unstable neurons and tightens the bounds of neurons thereby enhancing the network's verifiability. We evaluated our method using the MNIST, Fashion-MNIST, and CIFAR-10 datasets with various network architectures. The experimental results demonstrate that networks trained using our method are verification-friendly across different radii and architectures, whereas other tools fail to maintain verifiability as the radius increases. Additionally, we show that our method can be combined with existing approaches to further improve the verifiability of networks.
Zongxin Liu 0001, Zhe Zhao 0007, Fu Song, Jun Sun 0001, Pengfei Yang 0002, Xiaowei Huang 0001, Lijun Zhang 0001
AAAI6
2025 GNS: Solving Plane Geometry Problems by Neural-Symbolic Reasoning with Multi-Modal LLMs
abstract
With the outstanding capabilities of Large Language Models (LLMs), solving math word problems (MWP) has greatly progressed, achieving higher performance on several benchmark datasets. However, it is more challenging to solve plane geometry problems (PGPs) due to the necessity of understanding, reasoning and computation on two modality data including both geometry diagrams and textual questions, where Multi-Modal Large Language Models (MLLMs) have not been extensively explored. Previous works simply regarded a plane geometry problem as multi-modal QA task, which ignored the importance of explicit parsing geometric elements from problems. To tackle this limitation, we propose to solve plane Geometry problems by Neural-Symbolic reasoning with MLLMs (GNS). We first leverage an MLLM to understand PGPs through knowledge prediction and symbolic parsing, next perform mathematical reasoning to obtain solutions, last adopt a symbolic solver to compute answers. Correspondingly, we introduce the largest PGPs dataset GNS-260K with multiple annotations including symbolic parsing, understanding, reasoning and computation. In experiments, our Phi3-Vision-based MLLM wins the first place on the PGPs solving task of MathVista benchmark, outperforming GPT-4o, Gemini Ultra and other much larger MLLMs. While LLaVA-13B-based MLLM markedly exceeded other close-source and open-source MLLMs on the MathVerse benchmark and also achieved the new SOTA on GeoQA dataset.
Maizhen Ning, Qiufeng Wang 0001, Xiaowei Huang 0001, Kaizhu Huang
AAAI4
2025 Towards Better Robustness Against Natural Corruptions in Document Tampering Localization
abstract
Marvelous advances have been exhibited in recent document tampering localization (DTL) systems. However, confronted with corrupted tampered document images, their vulnerability is fatal in real-world scenarios. While robustness against adversarial attack has been extensively studied by adversarial training (AT), the robustness on natural corruptions remains under-explored for DTL. In this paper, to overcome forensic dependency, we propose the adversarial forensic regularization (AFR) based on min-max optimization to improve robustness. Specifically, we adopt mutual information (MI) to represent forensic dependency between two random variable over tampered and authentic pixels spaces, where the MI can be approximated by Jensen-Shannon-Divergence (JSD) with empirical sampling. To further enable a trade-off between predictive representations in clean tampered document pixels and robust ones in corrupted pixels, an additional regularization term is formulated with divergence between clean and perturbed pixels distribution (DDR). Following min-max optimization framework, our method can also work well against adversarial attacks. To evaluate our proposed method, we collect a dataset (i.e., TSorie-CRP) for evaluating robustness against natural corruptions in real scenarios. Extensive experiments demonstrate the effectiveness of our method against natural corruptions. Without any surprise, our method also achieves good performance against adversarial attack on DTL benchmark datasets.
Huiru Shao, Kaizhu Huang, Wei Wang 0042, Xiaowei Huang 0001, Qiufeng Wang 0001
AAAI4
2025 A Black-Box Evaluation Framework for Semantic Robustness in Bird's Eye View Detection
abstract
Camera-based Bird's Eye View (BEV) perception models receive increasing attention for their crucial role in autonomous driving, a domain where concerns about the robustness and reliability of deep learning have been raised. While only a few works have investigated the effects of randomly generated semantic perturbations, aka natural corruptions, on the multi-view BEV detection task, we develop a black-box robustness evaluation framework that adversarially optimises three common semantic perturbations: geometric transformation, colour shifting, and motion blur, to deceive BEV models, serving as the first approach in this emerging field. To address the challenge posed by optimising the semantic perturbation, we design a smoothed, distance-based surrogate function to replace the mAP metric and introduce SimpleDIRECT, a deterministic optimisation algorithm that utilises observed slopes to guide the optimisation process. By comparing with randomised perturbation and two optimisation baselines, we demonstrate the effectiveness of the proposed framework. Additionally, we provide a benchmark on the semantic robustness of ten recent BEV models. The results reveal that PolarFormer, which emphasises geometric information from multi-view images, exhibits the highest robustness, whereas BEVDet is fully compromised, with its precision reduced to zero.
Yanghao Zhang, Xiangyu Yin 0001, Zeyu Fu, Xiaowei Huang 0001, Wenjie Ruan
AAAI6
2025 Cognitive-Inspired Hierarchical Attention Fusion With Visual and Textual for Cross-Domain Sequential Recommendation
Wangyu Wu, Siqi Song, Xianglin Qiu, Xiaowei Huang 0001, Fei Ma 0002, Jimin Xiao
CogSci5
2025 SIDA: Social Media Image Deepfake Detection, Localization and Explanation with Large Multimodal Model
abstract
The rapid advancement of generative models in creating highly realistic images poses substantial risks for misinformation dissemination. For instance, a synthetic image, when shared on social media, can mislead extensive audiences and erode trust in digital content, resulting in severe repercussions. Despite some progress, academia has not yet created a large and diversified deepfake detection dataset for social media, nor has it devised an effective solution to address this issue. In this paper, we introduce the Social media Image Detection dataSet (SID-Set), which offers three key advantages: (1) extensive volume, featuring 300K AI-generated/tampered and authentic images with comprehensive annotations, (2) broad diversity, encompassing fully synthetic and tampered images across various classes, and (3) elevated realism, with images that are predominantly indistinguishable from genuine ones through mere visual inspection. Furthermore, leveraging the exceptional capabilities of large multimodal models, we propose a new image deepfake detection, localization, and explanation framework, named SIDA (Social media Image Detection, localization, and explanation Assistant). SIDA not only discerns the authenticity of images, but also delineates tampered regions through mask prediction and provides textual explanations of the model’s judgment criteria. Compared with state-of-the-art deepfake detection models on SID-Set and other benchmarks, extensive experiments demonstrate that SIDA achieves superior performance among diversified settings. The code, model, and dataset will be released.
Zhenglin Huang, Jinwei Hu 0001, Xiangtai Li, Yiwei He, Xingyu Zhao 0001, Bei Peng 0001, Baoyuan Wu, Xiaowei Huang 0001
CVPR8
2025 Projection Modules for Few-Shot Object Detection
abstract
In this paper, we propose a novel approach to enhance few-shot object detection (FSOD) by utilizing projection modules, which are commonly employed in self-supervised learning to improve feature transferability. We integrate a multilayer perceptron (MLP) as a projection module within a Faster RCNN model and design a tailored training strategy to facilitate the transfer of features from base to novel classes in FSOD. The MLP is used during the base training phase and removed when training on few-shot datasets to leverage more generalized intermediate features for novel classes. Our approach also incorporates affine layers before the classification and regression tasks, which perform element-wise scaling and bias adjustments on the input feature vectors. This effectively reweights the features, enhancing the separability of the feature space for their respective tasks while keeping the parameter count low to minimize overfitting. We evaluate our method against established FSOD techniques, such as Two-Stage Fine-Tuning and Decoupled Faster RCNN, using standard benchmark datasets Pascal VOC and MS COCO. Our results demonstrate significant performance improvements, especially in scenarios with very few training examples.
Benjamin Rise, Murat Üney, Xiaowei Huang 0001
ICASSP3
2025 Out-of-Distribution Detectors: Not Yet Primed for Practical Deployment
abstract
Out-of-distribution (OoD) detectors work alongside deep neural networks (DNNs) to reduce their risks in eliciting wrong predictions. Unfortunately, OoD detectors built on data-centric designs are also subject to robustness issues, as the DNNs. This paper examines the practical robustness of OoD detectors, taking computer vision tasks as examples and considering natural input perturbations that may come from camera positions and lighting conditions. Our study incorporates extensive experiments over 2000+ settings and correlation studies, highlighting significant challenges in OoD detection robustness, e.g., OoD detectors’ robustness error rate in practical settings can be as high as 28%. The paper advances our understanding of OoD detectors’ applicability in real world and the interplay of their robustness with DNNs’ robustness, calling for novel methodology to design robust OoD detectors in broader signal processing tasks.
Changshun Wu, Wendi Ding, Xiaowei Huang 0001, Saddek Bensalem
ICASSP3
2025 Adversarial Training for Probabilistic Robustness
Yi Zhang 0141, Wenjie Ruan, Xiaowei Huang 0001, Siddartha Khastgir, Xingyu Zhao 0001
ICCV5
2025 ZeroDiff: Solidified Visual-semantic Correlation in Zero-Shot Learning
abstract
Zero-shot Learning (ZSL) aims to enable classifiers to identify unseen classes. This is typically achieved by generating visual features for unseen classes based on learned visual-semantic correlations from seen classes. However, most current generative approaches heavily rely on having a sufficient number of samples from seen classes. Our study reveals that a scarcity of seen class samples results in a marked decrease in performance across many generative ZSL techniques. We argue, quantify, and empirically demonstrate that this decline is largely attributable to spurious visual-semantic correlations. To address this issue, we introduce ZeroDiff, an innovative generative framework for ZSL that incorporates diffusion mechanisms and contrastive representations to enhance visual-semantic correlations. ZeroDiff comprises three key components: (1) Diffusion augmentation, which naturally transforms limited data into an expanded set of noised data to mitigate generative model overfitting; (2) Supervised-contrastive (SC)-based representations that dynamically characterize each limited sample to support visual feature generation; and (3) Multiple feature discriminators employing a Wasserstein-distance-based mutual learning approach, evaluating generated features from various perspectives, including pre-defined semantics, SC-based representations, and the diffusion process. Extensive experiments on three popular ZSL benchmarks demonstrate that ZeroDiff not only achieves significant improvements over existing ZSL methods but also maintains robust performance even with scarce training data. Our codes are available at https://github.com/FouriYe/ZeroDiff_ICLR25.
Zihan Ye, Shreyank N. Gowda, Shiming Chen 0002, Xiaowei Huang 0001, Fahad Shahbaz Khan, Yaochu Jin, Kaizhu Huang, Xiao-Bo Jin
ICLR4
2025 Is Your Model Really A Good Math Reasoner? Evaluating Mathematical Reasoning with Checklist
abstract
Exceptional mathematical reasoning ability is one of the key features that demonstrate the power of large language models (LLMs). How to comprehensively define and evaluate the mathematical abilities of LLMs, and even reflect the user experience in real-world scenarios, has emerged as a critical issue. Current benchmarks predominantly concentrate on problem-solving capabilities, presenting a substantial risk of model overfitting and fails to accurately measure the genuine mathematical reasoning abilities. In this paper, we argue that if a model really understands a problem, it should be robustly and readily applied across a diverse array of tasks. To this end, we introduce MathCheck, a well-designed checklist for testing task generalization and reasoning robustness, as well as an automatic tool to generate checklists efficiently. MathCheck includes multiple mathematical reasoning tasks and robustness tests to facilitate a comprehensive evaluation of both mathematical reasoning ability and behavior testing. Utilizing MathCheck, we develop MathCheck-GSM and MathCheck-GEO to assess mathematical textual reasoning and multi-modal reasoning capabilities, respectively, serving as upgraded versions of benchmarks including GSM8k, GeoQA, UniGeo, and Geometry3K. We adopt MathCheck-GSM and MathCheck-GEO to evaluate over 26 LLMs and 17 multi-modal LLMs, assessing their comprehensive mathematical reasoning abilities. Our results demonstrate that while frontier LLMs like GPT-4o continue to excel in various abilities on the checklist, many other model families exhibit a significant decline. Further experiments indicate that, compared to traditional math benchmarks, MathCheck better reflects true mathematical abilities and represents mathematical intelligence more linearly, thereby supporting our design. Using MathCheck, we can also efficiently conduct informative behavior analysis to deeply investigate models. Finally, we show that our proposed checklist paradigm can easily extend to other reasoning tasks for their comprehensive evaluation.
Shudong Liu 0004, Maizhen Ning, Wei Liu 0131, Jindong Wang 0001, Derek F. Wong, Xiaowei Huang 0001, Qiufeng Wang 0001, Kaizhu Huang
ICLR7
2025 Patch Synthesis for Property Repair of Deep Neural Networks
abstract
Deep neural networks (DNNs) are prone to various dependability issues, such as adversarial attacks, which hinder their adoption in safety-critical domains. Recently, NN repair techniques have been proposed to address these issues while preserving original performance by locating and modifying guilty neurons and their parameters. However, existing repair approaches are often limited to specific data sets and do not provide theoretical guarantees for the effectiveness of the repairs. To address these limitations, we introduce Patchpro, a novel patch-based approach for property-level repair of DNNs, focusing on local robustness. The key idea behind Patchpro is to construct patch modules that, when integrated with the original network, provide specialized repairs for all samples within the robustness neighborhood while maintaining the network's original performance. Our method incorporates formal verification and a heuristic mechanism for allocating patch modules, enabling it to defend against adversarial attacks and generalize to other inputs. Patchpro demonstrates superior efficiency, scalability, and repair success rates compared to existing DNN repair methods, i.e., realizing provable property-level repair for 100% cases across multiple high-dimensional datasets.
Zhiming Chi, Pengfei Yang 0002, Cheng-Chao Huang, Renjue Li, Jingyi Wang 0004, Xiaowei Huang 0001, Lijun Zhang 0001
ICSE7
2025 Mitigating Hallucinations in YOLO-based Object Detection Models: A Revisit to Out-of-Distribution Detection
abstract
Object detection systems must reliably perceive objects of interest without being overly confident to ensure safe decision-making in dynamic environments. Filtering techniques based on out-of-distribution (OoD) detection are commonly added as an extra safeguard to filter hallucinations caused by overconfidence in novel objects. Nevertheless, evaluating YOLO-family detectors and their filters under existing OoD benchmarks often leads to unsatisfactory performance. This paper studies the underlying reasons for performance bottlenecks and proposes a methodology to improve performance fundamentally. Our first contribution is a calibration of all existing evaluation results: Although images in existing OoD benchmark datasets are claimed not to have objects within in-distribution (ID) classes (i.e., categories defined in the training dataset), around 13% of objects detected by the object detector are actually ID objects. Dually, the ID dataset containing OoD objects can also negatively impact the decision boundary of filters. These ultimately lead to a significantly imprecise performance estimation. Our second contribution is to consider the task of hallucination reduction as a joint pipeline of detectors and filters. By developing a methodology to carefully synthesize an OoD dataset that semantically resembles the objects to be detected, and using the crafted OoD dataset in the fine-tuning of YOLO detectors to suppress the objectness score, we achieve a 88% reduction in overall hallucination error with a combined fine-tuned detection and filtering system on the self-driving benchmark BDD-100K. Our code and dataset are available at: https://gricad-gitlab.univ-grenoble-alpes.fr/dnn-safety/m-hood.
Weicheng He, Changshun Wu, Chih-Hong Cheng, Xiaowei Huang 0001, Saddek Bensalem
IROS4
2025 FALCON: Fine-grained Activation Manipulation by Contrastive Orthogonal Unalignment for Large Language Model
abstract
Large language models have been widely applied, but can inadvertently encode sensitive or harmful information, raising significant safety concerns. Machine unlearning has emerged to alleviate this concern; however, existing training-time unlearning approaches, relying on coarse-grained loss combinations, have limitations in precisely separating knowledge and balancing removal effectiveness with model utility. In contrast, we propose $\textbf{F}$ine-grained $\textbf{A}$ctivation manipu$\textbf{L}$ation by $\textbf{C}$ontrastive $\textbf{O}$rthogonal u$\textbf{N}$alignment (FALCON), a novel representation-guided unlearning approach that leverages information-theoretic guidance for efficient parameter selection, employs contrastive mechanisms to enhance representation separation, and projects conflict gradients onto orthogonal subspaces to resolve conflicts between forgetting and retention objectives. Extensive experiments demonstrate that FALCON achieves superior unlearning effectiveness while maintaining model utility, exhibiting robust resistance against knowledge recovery attempts.
Jinwei Hu 0001, Zhenglin Huang, Xiangyu Yin 0001, Wenjie Ruan, Yi Dong 0002, Xiaowei Huang 0001
NeurIPS7
2025 Can MLLMs Absorb Math Reasoning Abilities from LLMs as Free Lunch?
abstract
Math reasoning has been one crucial ability of large language models (LLMs), where significant advancements have been achieved in recent years. However, most efforts focus on LLMs by curating high-quality annotation data and intricate training (or inference) paradigms, while the math reasoning performance of multi-modal LLMs (MLLMs) remains lagging behind. Since the MLLM typically consists of an LLM and vision block, we wonder: \textit{Can MLLMs directly absorb math reasoning abilities from off-the-shelf math LLMs without tuning?} Recent model-merging approaches may offer insights into this question. However, they overlook the alignment between the MLLM and LLM, where we find that there is a large gap between their parameter spaces, resulting in lower performance. Our empirical evidence reveals two key factors behind this issue: the identification of crucial reasoning-associated layers in the model and the mitigation of the gaps in parameter space. Based on the empirical insights, we propose \textbf{IP-Merging} that first \textbf{I}dentifies the reasoning-associated parameters in both MLLM and Math LLM, then \textbf{P}rojects them into the subspace of MLLM aiming to maintain the alignment, finally merges parameters in this subspace. IP-Merging is a tuning-free approach since parameters are directly adjusted. Extensive experiments demonstrate that our IP-Merging method can enhance the math reasoning ability of MLLMs directly from Math LLMs without compromising their other capabilities.
Yijie Hu, Kaizhu Huang, Xiaowei Huang 0001
NeurIPS4
2025 Interpreting Safety: A LLM and STPA Approach
Shufeng Chen, Xiangyu Yin 0001, Wenjie Ruan, Siddartha Khastgir, Ji Ruan, Xingyu Zhao 0001, Xiaowei Huang 0001
PRICAI (4)8
2025 DvD: Unleashing a Generative Paradigm for Document Dewarping via Coordinates-based Diffusion Model
abstract
Document dewarping aims to rectify deformations in photographic document images, thus improving text readability, which has attracted much attention and made great progress, but it is still challenging to preserve document structures. Given recent advances in diffusion models, it is natural for us to consider their potential applicability to document dewarping. However, it is far from straightforward to adopt diffusion models in document dewarping due to their unfaithful control on highly complex document images (e.g., 2000 × 3000 resolution). In this paper, we propose DvD, the first generative model to tackle document Dewarping via a Diffusion framework. To be specific, DvD introduces a coordinate-level denoising instead of typical pixel-level denoising, generating a mapping for deformation rectification. In addition, we further propose a time-variant condition refinement mechanism to enhance the preservation of document structures. In experiments, we find that current document dewarping benchmarks can not evaluate dewarping models comprehensively. To this end, we present AnyPhotoDoc6300, a rigorously designed large-scale document dewarping benchmark comprising 6,300 real image pairs across three distinct domains, enabling fine-grained evaluation of dewarping models. Comprehensive experiments demonstrate that our proposed DvD can achieve state-of-the-art performance with acceptable computational efficiency on multiple metrics across various benchmarks, including DocUNet, DIR300, and AnyPhotoDoc6300. The new benchmark and code will be publicly available at https://github.com/hanquansanren/DvD.
Huangcheng Lu, Maizhen Ning, Xiaowei Huang 0001, Wei Wang 0042, Kaizhu Huang, Qiufeng Wang 0001
SIGGRAPH Asia4
2025 Covariance-Based Space Regularization for Few-Shot Class Incremental Learning
Yijie Hu, Guanyu Yang 0002, Zhaorui Tan, Xiaowei Huang 0001, Kaizhu Huang, Qiufeng Wang 0001
WACV4
2025 Adaptive Patch Contrast for Weakly Supervised Semantic Segmentation
Wangyu Wu, Tianhong Dai, Xiaowei Huang 0001, Jimin Xiao, Fei Ma 0002, Renrong Ouyang
Eng. Appl. Artif. Intell.4
2025 FAD: Feature augmented distillation for anomaly detection and localization
Qiyin Zhong, Xianglin Qiu, Xinqiao Zhao, Xiaowei Huang 0001, Jimin Xiao
Expert Syst. Appl.4
2025 Generative Prompt Controlled Diffusion for weakly supervised semantic segmentation
abstract
Weakly supervised semantic segmentation (WSSS), aiming to train segmentation models solely using image-level labels, has received significant attention. Existing approaches mainly concentrate on creating high-quality pseudo labels by utilizing existing images and their corresponding image-level labels. However, a major challenge arises when the available dataset is limited, as the quality of pseudo labels degrades significantly. In this paper, we tackle this challenge from a different perspective by introducing a novel approach called Generative Prompt Controlled Diffusion (GPCD) for data augmentation . This approach enhances the current labeled datasets by augmenting them with a variety of images, achieved through controlled diffusion guided by Generative Pre-trained Transformer (GPT) prompts. In this process, the existing images and image-level labels provide the necessary control information , while GPT enriches the prompts to generate diverse backgrounds. Moreover, we make an original contribution by integrating data source information as tokens into the Vision Transformer (ViT) framework, which improves the ability of downstream WSSS models to recognize the origins of augmented images. Our proposed GPCD approach clearly surpasses existing state-of-the-art methods, with its advantages being more pronounced when the available data is scarce, thereby demonstrating the effectiveness of our method. Our source code will be released.
Wangyu Wu, Tianhong Dai, Xiaowei Huang 0001, Fei Ma 0002, Jimin Xiao
Neurocomputing4
2025 Eidos revisited: Expanding Efficient, imperceptible adversarial attacks on 3D point clouds
Luo Cheng, Hanwei Zhang 0001, Qisong He, Wei Huang 0035, Renjue Li, Xiaowei Huang 0001, Holger Hermanns, Lijun Zhang 0001
J. Syst. Archit.6
2025 S$^{2}$2O: Enhancing Adversarial Training With Second-Order Statistics of Weights
abstract
Adversarial training has emerged as a highly effective way to improve the robustness of deep neural networks (DNNs). It is typically conceptualized as a min-max optimization problem over model weights and adversarial perturbations, where the weights are optimized using gradient descent methods, such as SGD. In this paper, we propose a novel approach by treating model weights as random variables, which paves the way for enhancing adversarial training through Second-Order Statistics Optimization (S$^{2}$2O) over model weights. We challenge and relax a prevalent, yet often unrealistic, assumption in prior PAC-Bayesian frameworks: the statistical independence of weights. From this relaxation, we derive an improved PAC-Bayesian robust generalization bound. Our theoretical developments suggest that optimizing the second-order statistics of weights can substantially tighten this bound. We complement this theoretical insight by conducting an extensive set of experiments that demonstrate that S$^{2}$2O not only enhances the robustness and generalization of neural networks when used in isolation, but also seamlessly augments other state-of-the-art adversarial training techniques.
Gaojie Jin, Xinping Yi, Wei Huang 0035, Sven Schewe, Xiaowei Huang 0001
IEEE Trans. Pattern Anal. Mach. Intell.5
2025 Invariant Correlation of Representation With Label
abstract
The Invariant Risk Minimization (IRM) approach aims to address the security challenge of out-of-distribution robustness (domain generalization) by training a feature representation that remains invariant across multiple environments. However, in noisy environments, noise can distort invariant features, leading to different environment-specific losses. Current IRM-related methods such as IRMv1 and VREx underperform in these settings because they enforce uniform losses across environments. While environmental noise causes environment-specific losses, it does not alter the fundamental correlation between invariant representations and labels. Based on this observation, we propose ICorr (Invariant Correlation), which leverages this correlation to extract invariant representations in noisy settings. Unlike existing approaches, ICorr accommodates different environment-specific inherent losses while maintaining a necessary condition for identifying IRM classifiers. We present a detailed case study demonstrating why previous methods may lose ground while ICorr can succeed. Through a theoretical lens, particularly from a causality perspective, we illustrate that the invariant correlation of representation with label is a necessary condition for the optimal invariant predictor in noisy environments, whereas the optimization motivations for other methods may not be. Furthermore, we empirically demonstrate the effectiveness of ICorr by comparing it with other domain generalization methods on various noisy datasets.
Gaojie Jin, Ronghui Mu, Xinping Yi, Xiaowei Huang 0001, Lijun Zhang 0001
IEEE Trans. Inf. Forensics Secur.4
2025 SCALA: Toward Imperceptible and Efficient Black-Box Textual Adversarial Perturbations
abstract
Deep learning models are intrinsically susceptible to textual adversarial attacks on social media, where the perturbed text can trigger aberrant behaviours of victim models and threaten security and privacy. In this paper, we present a novel word-level attack called SCALA: a Synonym-based desCending And repLace-back Ascending mechanism. Our focus is on the efficient production of adversarial examples, with a particular emphasis on minimizing human perceptibility while ensuring the visual resemblance and semantic correctness. The merits of our attacking solution lie in being:(i)imperceptible – it keeps a very low word perturbation rate based on the Hamming (L0-norm) distance, thus achieving heightened deceptiveness validated through human evaluations;(ii)efficient – our tensor-based parallelization strategy ensures the attacking efficiency compared with baselines;(iii)effective – it surpasses seven state-of-the-art attacks on five target models in terms of reducing after-attack accuracy;(iv)practical – black-box score-based setting ensures that the adversary only needs to query target models for confidence scores; and(v)transferable – our attack shows competitive transferability on the generated adversarial examples. We release our codeSCALAvia https://github.com/TrustAI/SCALA.
Achim D. Brucker, Jia Hu 0001, Xiaowei Huang 0001, Wenjie Ruan
IEEE Trans. Inf. Forensics Secur.4
2024 Reward Certification for Policy Smoothed Reinforcement Learning
abstract
Reinforcement Learning (RL) has achieved remarkable success in safety-critical areas, but it can be weakened by adversarial attacks. Recent studies have introduced ``smoothed policies" to enhance its robustness. Yet, it is still challenging to establish a provable guarantee to certify the bound of its total reward. Prior methods relied primarily on computing bounds using Lipschitz continuity or calculating the probability of cumulative reward being above specific thresholds. However, these techniques are only suited for continuous perturbations on the RL agent's observations and are restricted to perturbations bounded by the l2-norm. To address these limitations, this paper proposes a general black-box certification method, called ReCePS, which is capable of directly certifying the cumulative reward of the smoothed policy under various lp-norm bounded perturbations. Furthermore, we extend our methodology to certify perturbations on action spaces. Our approach leverages f-divergence to measure the distinction between the original distribution and the perturbed distribution, subsequently determining the certification bound by solving a convex optimisation problem. We provide a comprehensive theoretical analysis and run experiments in multiple environments. Our results show that our method not only improves the tightness of certified lower bound of the mean cumulative reward but also demonstrates better efficiency than state-of-the-art methods.
Ronghui Mu, Leandro Soriano Marcolino, Yanghao Zhang, Xiaowei Huang 0001, Wenjie Ruan
AAAI5
2024 Representation-Based Robustness in Goal-Conditioned Reinforcement Learning
abstract
While Goal-Conditioned Reinforcement Learning (GCRL) has gained attention, its algorithmic robustness against adversarial perturbations remains unexplored. The attacks and robust representation training methods that are designed for traditional RL become less effective when applied to GCRL. To address this challenge, we first propose the Semi-Contrastive Representation attack, a novel approach inspired by the adversarial contrastive attack. Unlike existing attacks in RL, it only necessitates information from the policy function and can be seamlessly implemented during deployment. Then, to mitigate the vulnerability of existing GCRL algorithms, we introduce Adversarial Representation Tactics, which combines Semi-Contrastive Adversarial Augmentation with Sensitivity-Aware Regularizer to improve the adversarial robustness of the underlying RL agent against various types of perturbations. Extensive experiments validate the superior performance of our attack and defence methods across multiple state-of-the-art GCRL algorithms. Our code is available at https://github.com/TrustAI/ReRoGCRL.
Xiangyu Yin 0001, Sihao Wu, Jiaxu Liu 0001, Xingyu Zhao 0001, Xiaowei Huang 0001, Wenjie Ruan
AAAI6
2024 MathAttack: Attacking Large Language Models towards Math Solving Ability
abstract
With the boom of Large Language Models (LLMs), the research of solving Math Word Problem (MWP) has recently made great progress. However, there are few studies to examine the robustness of LLMs in math solving ability. Instead of attacking prompts in the use of LLMs, we propose a MathAttack model to attack MWP samples which are closer to the essence of robustness in solving math problems. Compared to traditional text adversarial attack, it is essential to preserve the mathematical logic of original MWPs during the attacking. To this end, we propose logical entity recognition to identify logical entries which are then frozen. Subsequently, the remaining text are attacked by adopting a word-level attacker. Furthermore, we propose a new dataset RobustMath to evaluate the robustness of LLMs in math solving ability. Extensive experiments on our RobustMath and two another math benchmark datasets GSM8K and MultiAirth show that MathAttack could effectively attack the math solving ability of LLMs. In the experiments, we observe that (1) Our adversarial samples from higher-accuracy LLMs are also effective for attacking LLMs with lower accuracy (e.g., transfer from larger to smaller-size LLMs, or from few-shot to zero-shot prompts); (2) Complex MWPs (such as more solving steps, longer text, more numbers) are more vulnerable to attack; (3) We can improve the robustness of LLMs by using our adversarial samples in few-shot prompts. Finally, we hope our practice and observation can serve as an important attempt towards enhancing the robustness of LLMs in math solving ability. The code and dataset is available at: https://github.com/zhouzihao501/MathAttack.
Qiufeng Wang 0001, Mingyu Jin, Jianan Ye, Wei Liu 0131, Wei Wang 0042, Xiaowei Huang 0001, Kaizhu Huang
AAAI8
2024 Towards Fairness-Aware Adversarial Learning
abstract
Although adversarial training (AT) has proven effective in enhancing the model's robustness, the recently revealed issue of fairness in robustness has not been well addressed, i.e. the robust accuracy varies significantly among different categories. In this paper, instead of uniformly evaluating the model's average class performance, we delve into the issue of robust fairness, by considering the worst-case distribution across various classes. We propose a novel learning paradigm, named Fairness-Aware Adversarial Learning (FAAL). As a generalization of conventional AT, we redefine the problem of adversarial training as a min-max-max framework, to ensure both robustness and fairness of the trained model. Specifically, by taking advantage of distributional robust optimization, our method aims to find the worst distribution among different categories, and the solution is guaranteed to obtain the upper bound performance with high probability. In particular, FAAL can fine-tune an unfair robust model to be fair within only two epochs, without compromising the overall clean and robust accuracies. Extensive experiments on various image datasets validate the superior performance and efficiency of the proposed FAAL compared to other state-of-the-art methods.
Yanghao Zhang, Ronghui Mu, Xiaowei Huang 0001, Wenjie Ruan
CVPR4
2024 Delving into Adversarial Robustness on Document Tampering Localization
Huiru Shao, Zhuang Qian, Kaizhu Huang, Wei Wang 0042, Xiaowei Huang 0001, Qiufeng Wang 0001
ECCV (65)5
2024 ProTIP: Probabilistic Robustness Verification on Text-to-Image Diffusion Models Against Stochastic Perturbation
Yi Zhang 0141, Yun Tang 0003, Wenjie Ruan, Xiaowei Huang 0001, Siddartha Khastgir, Paul A. Jennings, Xingyu Zhao 0001
ECCV (32)4
2024 Two-Stage Transfer Learning for Fusion and Classification of Airborne Hyperspectral Imagery
abstract
In this work, we introduce a novel fusion and training strategy aimed at facilitating transfer learning to enhance classification in hyperspectral airborne imagery. Our training strategy has two stages: first we train separate convolutional neural network (CNN) models, one for the bands for which pretraining is available (e.g. visual bands), and a second model trained from scratch on all available wavelengths. These models are then integrated into a new fully-connected layer, which is fine-tuned to fuse the features from both modalities. We use the BigEarthNet and EuroSAT datasets, containing Sentinel-2 satellite imagery in visual and infrared wavelengths. Our approach provides significant performance improvements across all evaluation metrics on the aforementioned data sets, exemplifying the efficacy of our two-stage transfer learning strategy in handling multi-modal data.
Benjamin Rise, Murat Üney, Xiaowei Huang 0001
ICASSP3
2024 Image Augmentation with Controlled Diffusion for Weakly-Supervised Semantic Segmentation
abstract
Weakly-supervised semantic segmentation (WSSS), which aims to train segmentation models solely using image-level labels, has achieved significant attention. Existing methods primarily focus on generating high-quality pseudo labels using available images and their image-level labels. However, the quality of pseudo labels degrades significantly when the size of available dataset is limited. Thus, in this paper, we tackle this problem from a different view by introducing a novel approach called Image Augmentation with Controlled Diffusion (IACD). This framework effectively augments existing labeled datasets by generating diverse images through controlled diffusion, where the available images and image-level labels are served as the controlling information. Moreover, we also propose a high-quality image selection strategy to mitigate the potential noise introduced by the randomness of diffusion models. In the experiments, our proposed IACD approach clearly surpasses existing state-of-the-art methods. This effect is more obvious when the amount of available data is small, demonstrating the effectiveness of our method.
Wangyu Wu, Tianhong Dai, Xiaowei Huang 0001, Fei Ma 0002, Jimin Xiao
ICASSP3
2024 Position: Building Guardrails for Large Language Models Requires Systematic Design
abstract
As Large Language Models (LLMs) become more integrated into our daily lives, it is crucial to identify and mitigate their risks, especially when the risks can have profound impacts on human users and societies. Guardrails, which filter the inputs or outputs of LLMs, have emerged as a core safeguarding technology. This position paper takes a deep look at current open-source solutions (Llama Guard, Nvidia NeMo, Guardrails AI), and discusses the challenges and the road towards building more complete solutions. Drawing on robust evidence from previous research, we advocate for a systematic approach to construct guardrails for LLMs, based on comprehensive consideration of diverse contexts across various LLMs applications. We propose employing socio-technical methods through collaboration with a multi-disciplinary team to pinpoint precise technical requirements, exploring advanced neural-symbolic implementations to embrace the complexity of the requirements, and developing verification and testing to ensure the utmost quality of the final product.
Yi Dong 0002, Ronghui Mu, Gaojie Jin, Jinwei Hu 0001, Xingyu Zhao 0001, Wenjie Ruan, Xiaowei Huang 0001
ICML9
2024 Analytically Determining the Robustness of Binarized Neural Networks
abstract
Binarized neural networks (BNNs) are a class of deep neural networks (DNNs) known for their minimal computational requirements during inference, making them ideal for low-performance environments. Despite their efficiency, BNNs are as vulnerable to safety and security issues as other types of DNNs, and hence analyzing their robustness is essential. In contrast to general DNNs, BNNs are relatively small and straightforward, making it feasible to assess their robustness analytically. We propose a method for rigorously analyzing BNN robustness based on 0–1 Integer Linear Programming (0–1 ILP), which utilizes the dual functionality of boolean variables within BNNs as both boolean (with values of ‘true’ and ‘false’) and real-valued variables constrained to binary values (0 and 1). By leveraging this duality, we formalize the robustness problem as a linear programming problem augmented with boolean reasoning. We minimize the distance to a differently classified image using either the L1-norm (binarized and non-binarized inputs) or the Lœ-norm (non-binarized inputs). We have implemented our approach using the Z3 solver and evaluated it on the MNIST and FashionMNIST datasets. Our results demonstrate the capability to construct optimal adversarial examples with minimal deviations from the ground truth images. We achieved a one-pixel difference between the original and perturbed images for all binarized images. We also identified minimal perturbations on grayscale images using the L1and Lœ-norms. For the latter, we simplified the analysis to determine the existence of epsilon-close adversarial examples across a range of epsilon values.
Sahar M. Alzahrani, Sven Schewe, Xiaowei Huang 0001
ICMLA4
2024 Data Augmentation for Continual RL via Adversarial Gradient Episodic Memory
Sihao Wu, Xingyu Zhao 0001, Xiaowei Huang 0001
ICONIP (4)3
2024 BAM: Box Abstraction Monitors for Real-time OoD Detection in Object Detection
abstract
Out-of-distribution (OoD) detection techniques for deep neural networks (DNNs) become crucial thanks to their filtering of abnormal inputs, especially when DNNs are used in safety-critical applications and interact with an open and dynamic environment. Nevertheless, integrating OoD detection into state-of-the-art (SOTA) object detection DNNs poses significant challenges, partly due to the complexity introduced by the SOTA OoD construction methods, which require the modification of DNN architecture and the introduction of complex loss functions. This paper proposes a simple, yet surprisingly effective, method that requires neither retraining nor architectural change in object detection DNN, called Box Abstraction-based Monitors (BAM). The novelty of BAM stems from using a finite union of convex box abstractions to capture the learned features of objects for in-distribution (ID) data, and an important observation that features from OoD data are more likely to fall outside of these boxes. The union of convex regions within the feature space allows the formation of non-convex and interpretable decision boundaries, overcoming the limitations of VOS-like detectors without sacrificing real-time performance. Experiments integrating BAM into Faster R-CNN-based object detection DNNs demonstrate a considerably improved performance against SOTA OoD detection techniques, with a reduction in the false detection rate of over 10% in most cases.
Changshun Wu, Weicheng He, Chih-Hong Cheng, Xiaowei Huang 0001, Saddek Bensalem
IROS4
2024 Document Registration: Towards Automated Labeling of Pixel-Level Alignment Between Warped-Flat Documents
Qiufeng Wang 0001, Kaizhu Huang, Xiaowei Huang 0001, Fengjun Guo, Xiaomeng Gu
ACM Multimedia4
2024 TARP-VP: Towards Evaluation of Transferred Adversarial Robustness and Privacy on Label Mapping Visual Prompting Models
abstract
Adversarial robustness and privacy of deep learning (DL) models are two widely studied topics in AI security. Adversarial training (AT) is an effective approach to improve the robustness of DL models against adversarial attacks. However, while models with AT demonstrate enhanced robustness, they become more susceptible to membership inference attacks (MIAs), thus increasing the risk of privacy leakage. This indicates a negative trade-off between adversarial robustness and privacy in general deep learning models. Visual prompting is a novel model reprogramming (MR) technique used for fine-tuning pre-trained models, achieving good performance in vision tasks, especially when combined with the label mapping technique. However, the performance of label-mapping-based visual prompting (LM-VP) under adversarial attacks and MIAs lacks evaluation. In this work, we regard the MR of LM-VP as a unified entity, referred to as the LM-VP model, and take a step toward jointly evaluating the adversarial robustness and privacy of LM-VP models. Experimental results show that the choice of pre-trained models significantly affects the white-box adversarial robustness of LM-VP, and standard AT even substantially degrades its performance. In contrast, transfer AT-trained LM-VP achieves a good trade-off between transferred adversarial robustness and privacy, a finding that has been consistently validated across various pre-trained models.
Yi Zhang 0141, Xingyu Zhao 0001, Xiaowei Huang 0001, Wenjie Ruan
NeurIPS5
2024 Continuous Geometry-Aware Graph Diffusion via Hyperbolic Neural PDE
Jiaxu Liu 0001, Xinping Yi, Sihao Wu, Xiangyu Yin 0001, Xiaowei Huang 0001, Shi Jin 0002
ECML/PKDD (3)6
2024 Eidos: Efficient, Imperceptible Adversarial 3D Point Clouds
Hanwei Zhang 0001, Luo Cheng, Qisong He, Wei Huang 0035, Renjue Li, Ronan Sicre, Xiaowei Huang 0001, Holger Hermanns, Lijun Zhang 0001
SETTA7
2024 Top-K Pooling with Patch Contrastive Learning for Weakly-Supervised Semantic Segmentation
abstract
Weakly Supervised Semantic Segmentation (WSSS) using only image-level labels has gained significant attention due to cost-effectiveness. Recently, Vision Transformer (ViT) based methods without class activation map (CAM) have shown greater capability in generating reliable pseudo labels than previous methods using CAM. However, the current ViT-based methods utilize max pooling to select the patch with the highest prediction score to map the patch-level classification to the image-level one, which may affect the quality of pseudo labels due to the inaccurate classification of the patches. In this paper, we introduce a novel ViT-based WSSS method named top-K pooling with patch contrastive learning (TKP-PCL), which employs a top-K pooling layer to alleviate the limitations of previous max pooling selection. A patch contrastive error (PCE) is also proposed to enhance the patch embeddings to further improve the final results. The experimental results show that our approach is very efficient and outperforms other state-of-the-art WSSS methods on the PASCAL VOC 2012 and MS COCO 2014 dataset.
Wangyu Wu, Tianhong Dai, Xiaowei Huang 0001, Fei Ma 0002, Jimin Xiao
SMC3
2024 DeepCDCL: A CDCL-based Neural Network Verification Framework
Zongxin Liu 0001, Pengfei Yang 0002, Lijun Zhang 0001, Xiaowei Huang 0001
TASE4
2024 Formal verification of robustness and resilience of learning-enabled state estimation systems
Wei Huang 0035, Gaojie Jin, Youcheng Sun, Fan Zhang 0044, Xiaowei Huang 0001
Neurocomputing7
2024 Privacy-Preserving Distributed Learning for Residential Short-Term Load Forecasting
abstract
In the realm of power systems, the increasing involvement of residential users in load forecasting applications has heightened concerns about data privacy. Specifically, the load data can inadvertently reveal the daily routines of residential users, thereby posing a risk to their property security. While federated learning (FL) has been employed to safeguard user privacy by enabling model training without the exchange of raw data, these FL models have shown vulnerabilities to emerging attack techniques, such as Deep Leakage from Gradients and poisoning attacks. To counteract these, we initially employ a Secure-Aggregation (SecAgg) algorithm that leverages multiparty computation cryptographic techniques to mitigate the risk of gradient leakage. However, the introduction of SecAgg necessitates the deployment of additional sub-center servers for executing the multiparty computation protocol, thereby escalating computational complexity and reducing system robustness, especially in scenarios where one or more sub-centers are unavailable. To address these challenges, we introduce a Markovian Switching-based distributed training framework, the convergence of which is substantiated through rigorous theoretical analysis. The Distributed Markovian Switching (DMS) topology shows strong robustness towards the poisoning attacks as well. Case studies employing real-world power system load data validate the efficacy of our proposed algorithm. It not only significantly minimizes communication complexity but also maintains accuracy levels comparable to traditional FL methods, thereby enhancing the scalability of our load forecasting algorithm.
Yi Dong 0002, Mariana Gama, Mustafa A. Mustafa, Geert Deconinck, Xiaowei Huang 0001
IEEE Internet Things J.6
2024 Bridging formal methods and machine learning with model checking and global optimisation
abstract
Formal methods and machine learning are two research fields with drastically different foundations and philosophies. Formal methods utilise mathematically rigorous techniques for software and hardware systems' specification, development and verification. Machine learning focuses on pragmatic approaches to gradually improve a parameterised model by observing a training data set. While historically, the two fields lack communication, this trend has changed in the past few years with an outburst of research interest in the robustness verification of neural networks. This paper will briefly review these works, and focus on the urgent need for broader and more in-depth communication between the two fields, with the ultimate goal of developing learning-enabled systems with excellent performance and acceptable safety and security. We present a specification language, MLS2, and show that it can express a set of known safety and security properties, including generalisation, uncertainty, robustness, data poisoning, backdoor, model stealing, membership inference, model inversion, interpretability, and fairness. To verify MLS2 properties, we promote the global optimisation-based methods, which have provable guarantees on the convergence to the optimal solution. Many of them have theoretical bounds on the gap between current solutions and the optimal solution.
Saddek Bensalem, Xiaowei Huang 0001, Wenjie Ruan, Qiyi Tang 0001, Changshun Wu, Xingyu Zhao 0001
J. Log. Algebraic Methods Program.2
2024 Nrat: towards adversarial training with inherent label noise
abstract
Abstract Adversarial training (AT) has been widely recognized as the most effective defense approach against adversarial attacks on deep neural networks and it is formulated as a min-max optimization. Most AT algorithms are geared towards research-oriented datasets such as MNIST, CIFAR10, etc., where the labels are generally correct. However, noisy labels, e.g., mislabelling, are inevitable in real-world datasets. In this paper, we investigate AT with inherent label noise, where the training dataset itself contains mislabeled samples. We first empirically show that the performance of AT typically degrades as the label noise rate increases. Then, we propose a Noisy-Robust Adversarial Training (NRAT) algorithm, which leverages the recent advancements in learning with noisy labels to enhance the performance of AT in the presence of label noise. For experimental comparison, we consider two essential metrics in AT: (i) trade-off between natural and robust accuracy; (ii) robust overfitting. Our experiments show that NRAT’s performance is on par with, or better than, the state-of-the-art AT methods on both evaluation metrics. Our code is publicly available at: https://github.com/TrustAI/NRAT .
Ronghui Mu, Peipei Xu, Xiaowei Huang 0001, Wenjie Ruan
Mach. Learn.5
2024 Negative Hesitation Fuzzy Sets and Their Application to Pattern Recognition
abstract
The initial concept of Negative Hesitation Fuzzy Sets (NHFSs) has been introduced recently. NHFSs are applied to decision-making problems accompanied by soft set theory. In this paper, a detailed clarification of NHFSs is proposed. Meanwhile, we introduced the way to construct membership, non-membership, and negative hesitation degrees by studying the overlap area between the projections of the element and classes in a two-dimensional space. This unified construction has concluded the relationship between NHFSs and Intuitionistic Fuzzy Sets (IFSs). A corollary of cosine similarity satisfying the NHFSs is employed for the pattern recognition problems. Classification of both synthetic numerical examples and the EEG signals are evaluated for the effectiveness of NHFSs in this paper.
Youpeng Yang, Sanghyuk Lee, Hao Lan Zhang 0001, Xiaowei Huang 0001, Witold Pedrycz
IEEE Trans. Fuzzy Syst.4
2024 Scene Text Recognition via Dual-path Network with Shape-driven Attention Alignment
abstract
Scene text recognition (STR), one typical sequence-to-sequence problem, has drawn much attention recently in multimedia applications. To guarantee good performance, it is essential for STR to obtain aligned character-wise features from the whole-image feature maps. While most present works adopt fully data-driven attention-based alignment, such practice ignores specific character geometric information. In this article, built upon a group of learnable geometric points, we propose a novel shape-driven attention alignment method that is able to obtain character-wise features. Concretely, we first design a corner detector to generate a shape map to guide the attention alignments explicitly, where a series of points can be learned to represent character-wise features flexibly. We then propose a dual-path network with a mutual learning and cooperating strategy that successfully combines CNN with a ViT-based model, leading to further accuracy improvement. We conduct extensive experiments to evaluate the proposed method on various scene text benchmarks, including six popular regular and irregular datasets, two more challenging datasets (i.e., WordArt and OST), and three Chinese datasets. Experimental results indicate that our method can achieve superior performance with a comparable model size against many state-of-the-art models.
Yijie Hu, Bin Dong 0003, Kaizhu Huang, Lei Ding 0012, Wei Wang 0042, Xiaowei Huang 0001, Qiufeng Wang 0001
ACM Trans. Multim. Comput. Commun. Appl.6
2024 Hierarchical Distribution-aware Testing of Deep Learning
abstract
With its growing use in safety/security-critical applications, Deep Learning (DL) has raised increasing concerns regarding its dependability. In particular, DL has a notorious problem of lacking robustness. Input added with adversarial perturbations, i.e., Adversarial Examples (AEs) , are easily mispredicted by the DL model. Despite recent efforts made in detecting AEs via state-of-the-art attack and testing methods, they are normally input distribution–agnostic and/or disregard the perceptual quality of adversarial perturbations. Consequently, the detected AEs are irrelevant inputs in the application context or noticeably unrealistic to humans. This may lead to a limited effect on improving the DL model’s dependability, as the testing budget is likely to be wasted on detecting AEs that are encountered very rarely in its real-life operations. In this article, we propose a new robustness testing approach for detecting AEs that considers both the feature-level distribution and the pixel-level distribution, capturing the perceptual quality of adversarial perturbations. The two considerations are encoded by a novel hierarchical mechanism. First, we select test seeds based on the density of feature-level distribution and the vulnerability of adversarial robustness. The vulnerability of test seeds is indicated by the auxiliary information, which are highly correlated with local robustness. Given a test seed, we then develop a novel genetic algorithm–based local test case generation method, in which two fitness functions work alternatively to control the perceptual quality of detected AEs. Finally, extensive experiments confirm that our holistic approach considering hierarchical distributions is superior to the state-of-the-arts that either disregard any input distribution or only consider a single (non-hierarchical) distribution, in terms of not only detecting imperceptible AEs but also improving the overall robustness of the DL model under testing.
Wei Huang 0035, Xingyu Zhao 0001, Alec Banks, Victoria Cox, Xiaowei Huang 0001
ACM Trans. Softw. Eng. Methodol.5
2023 Towards Verifying the Geometric Robustness of Large-Scale Neural Networks
abstract
Deep neural networks (DNNs) are known to be vulnerable to adversarial geometric transformation. This paper aims to verify the robustness of large-scale DNNs against the combination of multiple geometric transformations with a provable guarantee. Given a set of transformations (e.g., rotation, scaling, etc.), we develop GeoRobust, a black-box robustness analyser built upon a novel global optimisation strategy, for locating the worst-case combination of transformations that affect and even alter a network's output. GeoRobust can provide provable guarantees on finding the worst-case combination based on recent advances in Lipschitzian theory. Due to its black-box nature, GeoRobust can be deployed on large-scale DNNs regardless of their architectures, activation functions, and the number of neurons. In practice, GeoRobust can locate the worst-case geometric transformation with high precision for the ResNet50 model on ImageNet in a few seconds on average. We examined 18 ImageNet classifiers, including the ResNet family and vision transformers, and found a positive correlation between the geometric robustness of the networks and the parameter numbers. We also observe that increasing the depth of DNN is more beneficial than increasing its width in terms of improving its geometric robustness. Our tool GeoRobust is available at https://github.com/TrustAI/GeoRobust.
Peipei Xu, Wenjie Ruan, Xiaowei Huang 0001
AAAI4
2023 Randomized Adversarial Training via Taylor Expansion
abstract
In recent years, there has been an explosion of research into developing more robust deep neural networks against adversarial examples. Adversarial training appears as one of the most successful methods. To deal with both the robustness against adversarial examples and the accuracy over clean examples, many works develop enhanced adversarial training methods to achieve various trade-offs between them [[19], [38], [80]], Leveraging over the studies [8], [32] that smoothed update on weights during training may help find flat minima and improve generalization, we suggest reconciling the robustness-accuracy trade-off from another perspective, i.e., by adding random noise into deterministic weights. The randomized weights enable our design of a novel adversarial training method via Taylor expansion of a small Gaussian noise, and we show that the new adversarial training method can flatten loss landscape and find flat minima. With PGD, CW, and Auto Attacks, an extensive set of experiments demonstrate that our method enhances the state-of-the-art adversarial training methods, boosting both robustness and clean accuracy. The code is available at https://github.com/Alexkael/Randomized-Adversarial-Training.
Gaojie Jin, Xinping Yi, Dengyu Wu, Ronghui Mu, Xiaowei Huang 0001
CVPR5
2023 Sora: Scalable Black-Box Reachability Analyser on Neural Networks
abstract
The vulnerability of deep neural networks (DNNs) to input perturbations has posed a significant challenge. Recent work on robustness verification of DNNs not only lacks scalability but also requires severe restrictions on the architecture (layers, activation functions, etc.). To address these limitations, we propose a novel framework, SORA, for scalable blackbox reachability analysis of DNNs. SORA can work on a broad class of neural network structures, including those networks with very deep layers and a huge number of neurons with nonlinear activation functions. Based on the Lipschitz continuity, SORA verifies the reachability property of DNNs with a novel optimisation algorithm and has global convergence guarantee. Our method does not require access to the inner structures of the DNNs, hence a black-box method. Experimental results show that, compared to existing verification methods, SORA shows superior performance in terms of both efficiency and scalability, especially when handling a deep neural network with very deep layers and a large number of neurons with various types of nonlinear activation functions.
Peipei Xu, Wenjie Ruan, Xiaowei Huang 0001
ICASSP5
2023 SAFARI: Versatile and Efficient Evaluations for Robustness of Interpretability
abstract
Interpretability of Deep Learning (DL) is a barrier to trustworthy AI. Despite great efforts made by the Explainable AI (XAI) community, explanations lack robustness— indistinguishable input perturbations may lead to different XAI results. Thus, it is vital to assess how robust DL interpretability is, given an XAI method. In this paper, we identify several challenges that the state-of-the-art is unable to cope with collectively: i) existing metrics are not comprehensive; ii) XAI techniques are highly heterogeneous; iii) misinterpretations are normally rare events. To tackle these challenges, we introduce two black-box evaluation methods, concerning the worst-case interpretation discrepancy and a probabilistic notion of how robust in general, respectively. Genetic Algorithm (GA) with bespoke fitness function is used to solve constrained optimisation for efficient worst-case evaluation. Subset Simulation (SS), dedicated to estimate rare event probabilities, is used for evaluating overall robustness. Experiments show that the accuracy, sensitivity, and efficiency of our methods outperform the state-of-the-arts. Finally, we demonstrate two applications of our methods: ranking robust XAI methods and selecting training schemes to improve both classification and interpretation robustness.
Wei Huang 0035, Xingyu Zhao 0001, Gaojie Jin, Xiaowei Huang 0001
ICCV4
2023 Progressive Supervision for Tampering Localization in Document Images
Huiru Shao, Kaizhu Huang, Wei Wang 0042, Xiaowei Huang 0001, Qiufeng Wang 0001
ICONIP (15)4
2023 A Symbolic Characters Aware Model for Solving Geometry Problems
abstract
AI has made significant progress in solving math problems, but geometry problems remain challenging due to their reliance on both text and diagrams. In the text description, symbolic characters such as "ABC" often serve as a bridge to connect the corresponding diagram. However, by simply tokenizing symbolic characters into individual letters (e.g., 'A', 'B' and 'C'), existing works fail to study them explicitly and thus lose the semantic relationship with the diagram. In this paper, we develop a symbolic character-aware model to fully explore the role of these characters in both text and diagram understanding and optimize the model under a multi-modal reasoning framework. In the text encoder, we propose merging individual symbolic characters to form one semantic unit along with geometric information from the corresponding diagram. For the diagram encoder, we pre-train it under a multi-label classification framework with the symbolic characters as labels. In addition, we enhance the geometry diagram understanding ability via a self-supervised learning method under the masked image modeling auxiliary task. By integrating the proposed model into a general encoder-decoder pipeline for solving geometry problems, we demonstrate its superiority on two benchmark datasets, including GeoQA and Geometry3K, with extensive experiments. Specifically, on GeoQA, the question-solving accuracy is increased from 60.0% to 64.1%, achieving a new state-of-the-art accuracy; on Geometry3K, we reduce the question average solving steps from 6.9 down to 6.0 with marginally higher solving accuracy.
Maizhen Ning, Qiufeng Wang 0001, Kaizhu Huang, Xiaowei Huang 0001
ACM Multimedia4
2023 Model-Agnostic Reachability Analysis on Deep Neural Networks
Wenjie Ruan, Peipei Xu, Geyong Min, Xiaowei Huang 0001
PAKDD (1)6
2023 Model Checking for Probabilistic Multiagent Systems
Andrea Turrini, Xiaowei Huang 0001, Lei Song 0001, Yuan Feng 0001, Lijun Zhang 0001
J. Comput. Sci. Technol.3
2023 Generalizing universal adversarial perturbations for deep neural networks
Yanghao Zhang, Wenjie Ruan, Xiaowei Huang 0001
Mach. Learn.4
2023 Reliability Assessment and Safety Arguments for Machine Learning Components in System Assurance
abstract
The increasing use of Machine Learning (ML) components embedded in autonomous systems—so-called Learning-Enabled Systems (LESs)—has resulted in the pressing need to assure their functional safety. As for traditional functional safety, the emerging consensus within both, industry and academia, is to use assurance cases for this purpose. Typically assurance cases support claims of reliability in support of safety, and can be viewed as a structured way of organising arguments and evidence generated from safety analysis and reliability modelling activities. While such assurance activities are traditionally guided by consensus-based standards developed from vast engineering experience, LESs pose new challenges in safety-critical application due to the characteristics and design of ML models. In this article, we first present an overall assurance framework for LESs with an emphasis on quantitative aspects, e.g., breaking down system-level safety targets to component-level requirements and supporting claims stated in reliability metrics. We then introduce a novel model-agnostic Reliability Assessment Model (RAM) for ML classifiers that utilises the operational profile and robustness verification evidence. We discuss the model assumptions and the inherent challenges of assessing ML reliability uncovered by our RAM and propose solutions to practical use. Probabilistic safety argument templates at the lower ML component-level are also developed based on the RAM. Finally, to evaluate and demonstrate our methods, we not only conduct experiments on synthetic/benchmark datasets but also scope our methods with case studies on simulated Autonomous Underwater Vehicles and physical Unmanned Ground Vehicles.
Yi Dong 0002, Wei Huang 0035, Vibhav Bharti, Victoria Cox, Alec Banks, Sen Wang 0002, Xingyu Zhao 0001, Sven Schewe, Xiaowei Huang 0001
ACM Trans. Embed. Comput. Syst.9
2023 Transportation Object Counting With Graph-Based Adaptive Auxiliary Learning
abstract
This paper proposes an adaptive auxiliary task learning-based approach for transport object counting problems such as humans and vehicles. These problems are essential in many real-world tasks such as video surveillance, traffic monitoring, public security, and urban planning, to aid intelligent transportation systems. Unlike existing auxiliary task learning-based methods, we develop an attention-enhanced adaptively shared backbone network to enable both task-shared and task-tailored features that are learned in an end-to-end manner. The network seamlessly combines a standard Convolution Neural Network (CNN) and a Graph Convolution Network (GCN) for feature extraction and feature reasoning among different domains of tasks. Our approach gains enriched contextual information by iteratively and hierarchically fusing features across different task branches of the adaptive CNN backbone. The whole framework pays special attention to objects’ spatial locations and varied density levels, informed by object (or crowd) segmentation and density level segmentation auxiliary tasks. In particular, thanks to the proposed dilated contrastive density loss function, our network benefits from individual and regional context supervision, along with strengthened robustness. Experiments on six challenging multi-domain datasets demonstrate that our method achieves superior performance compared with state-of-the-art auxiliary task learning-based counting methods. Our code is publicly available.
Yanda Meng, Joshua Bridge, Yitian Zhao, Martha Joddrell, Yihong Qiao, Xiaoyun Yang, Xiaowei Huang 0001, Yalin Zheng
IEEE Trans. Intell. Transp. Syst.7
2022 Enhancing Adversarial Training with Second-Order Statistics of Weights
abstract
Adversarial training has been shown to be one of the most effective approaches to improve the robustness of deep neural networks. It is formalized as a min-max optimization over model weights and adversarial perturbations, where the weights can be optimized through gradient descent methods like SGD. In this paper, we show that treating model weights as random variables allows for enhancing adversarial training through Second-Order Statistics Optimization (S2O) with respect to the weights. By relaxing a common (but unrealistic) assumption of previous PAC-Bayesian frameworks that all weights are statistically independent, we derive an improved PAC-Bayesian adversarial generalization bound, which suggests that optimizing second-order statistics of weights can effectively tighten the bound. In addition to this theoretical insight, we conduct an extensive set of experiments, which show that S2O not only improves the robustness and generalization of the trained neural networks when used in isolation, but also integrates easily in state-of-the-art adversarial training techniques like TRADES, AWP, MART, and AVMixup, leading to a measurable improvement of these techniques. The code is available at https://github.com/Alexkael/S2O.
Gaojie Jin, Xinping Yi, Wei Huang 0035, Sven Schewe, Xiaowei Huang 0001
CVPR5
2022 Adversarial Label Poisoning Attack on Graph Neural Networks via Label Propagation
Ganlin Liu, Xiaowei Huang 0001, Xinping Yi
ECCV (5)2
2022 Bridging Formal Methods and Machine Learning with Global Optimisation
Xiaowei Huang 0001, Wenjie Ruan, Qiyi Tang 0001, Xingyu Zhao 0001
ICFEM1
2022 STUN: Self-Teaching Uncertainty Estimation for Place Recognition
abstract
Place recognition is key to Simultaneous Localization and Mapping (SLAM) and spatial perception. However, a place recognition in the wild often suffers from erroneous predictions due to image variations, e.g., changing viewpoints and street appearance. Integrating uncertainty estimation into the life cycle of place recognition is a promising method to mitigate the impact of variations on place recognition performance. However, existing uncertainty estimation approaches in this vein are either computationally inefficient (e.g., Monte Carlo dropout) or at the cost of dropped accuracy. This paper proposes STUN, a self-teaching framework that learns to simultaneously predict the place and estimate the prediction uncertainty given an input image. To this end, we first train a teacher net using a standard metric learning pipeline to produce embedding priors. Then, supervised by the pretrained teacher net, a student net with an additional variance branch is trained to finetune the embedding priors and estimate the uncertainty sample by sample. During the online inference phase, we only use the student net to generate a place prediction in conjunction with the uncertainty. When compared with place recognition systems that are ignorant of the uncertainty, our framework features the uncertainty estimation for free without sacrificing any prediction accuracy. Our experimental results on the large-scale Pittsburgh30k dataset demonstrate that STUN outperforms the state-of-the-art methods in both recognition accuracy and the quality of uncertainty estimation.
Kaiwen Cai, Xiaoxuan Lu 0001, Xiaowei Huang 0001
IROS3
2022 Dependability Analysis of Deep Reinforcement Learning based Robotics and Autonomous Systems through Probabilistic Model Checking
abstract
While Deep Reinforcement Learning (DRL) provides transformational capabilities to the control of Robotics and Autonomous Systems (RAS), the black-box nature of DRL and uncertain deployment environments of RAS pose new challenges on its dependability. Although existing works impose constraints on the DRL policy to ensure successful completion of the mission, it is far from adequate to assess the DRL-driven RAS in a holistic way considering all dependability properties. In this paper, we formally define a set of dependability properties in temporal logic and construct a Discrete-Time Markov Chain (DTMC) to model the dynamics of risk/failures of a DRL-driven RAS interacting with the stochastic environment. We then conduct Probabilistic Model Checking (PMC) on the designed DTMC to verify those properties. Our experimental results show that the proposed method is effective as a holistic assessment framework while uncovering conflicts between the properties that may need trade-offs in training. Moreover, we find that the standard DRL training cannot improve dependability properties, thus requiring bespoke optimisation objectives. Finally, our method offers sensitivity analysis of dependability properties to disturbance levels from environments, providing insights for the assurance of real RAS.
Yi Dong 0002, Xingyu Zhao 0001, Xiaowei Huang 0001
IROS3
2022 A Graph Neural Network Reasoner for Game Description Language
Alvaro Gunawan, Ji Ruan, Xiaowei Huang 0001
KR3
2022 Embedding and extraction of knowledge in tree ensemble classifiers
abstract
Abstract The embedding and extraction of knowledge is a recent trend in machine learning applications, e.g., to supplement training datasets that are small. Whilst, as the increasing use of machine learning models in security-critical applications, the embedding and extraction of malicious knowledge are equivalent to the notorious backdoor attack and defence, respectively. This paper studies the embedding and extraction of knowledge in tree ensemble classifiers, and focuses on knowledge expressible with a generic form of Boolean formulas, e.g., point-wise robustness and backdoor attacks. For the embedding, it is required to bepreservative(the original performance of the classifier is preserved),verifiable(the knowledge can be attested), andstealthy(the embedding cannot be easily detected). To facilitate this, we propose two novel, and effective embedding algorithms, one of which is for black-box settings and the other for white-box settings. The embedding can be done inPTIME. Beyond the embedding, we develop an algorithm to extract the embedded knowledge, by reducing the problem to be solvable with an SMT (satisfiability modulo theories) solver. While this novel algorithm can successfully extract knowledge, the reduction leads to anNPcomputation. Therefore, if applying embedding as backdoor attacks and extraction as defence, our results suggest a complexity gap (P vs. NP) between the attack and defence when working with tree ensemble classifiers. We apply our algorithms to a diverse set of datasets to validate our conclusion extensively.
Wei Huang 0035, Xingyu Zhao 0001, Xiaowei Huang 0001
Mach. Learn.3
2022 Soft pseudo-Label shrinkage for unsupervised domain adaptive person re-identification
Dingyuan Zheng, Jimin Xiao, Ke Chen 0004, Xiaowei Huang 0001, Yao Zhao 0001
Pattern Recognit.4
2022 Editorial to theme section on open environmental software systems modeling
Tao Yue 0002, Paolo Arcaini, Ji Wu 0003, Xiaowei Huang 0001
Softw. Syst. Model.4
2022 Graph-Based Region and Boundary Aggregation for Biomedical Image Segmentation
abstract
Segmentation is a fundamental task in biomedical image analysis. Unlike the existing region-based dense pixel classification methods or boundary-based polygon regression methods, we build a novel graph neural network (GNN) based deep learning framework with multiple graph reasoning modules to explicitly leverage both region and boundary features in an end-to-end manner. The mechanism extracts discriminative region and boundary features, referred to as initialized region and boundary node embeddings, using a proposed Attention Enhancement Module (AEM). The weighted links between cross-domain nodes (region and boundary feature domains) in each graph are defined in a data-dependent way, which retains both global and local cross-node relationships. The iterative message aggregation and node update mechanism can enhance the interaction between each graph reasoning module's global semantic information and local spatial characteristics. Our model, in particular, is capable of concurrently addressing region and boundary feature reasoning and aggregation at several different feature levels due to the proposed multi-level feature node embeddings in different parallel graph reasoning modules. Experiments on two types of challenging datasets demonstrate that our method outperforms state-of-the-art approaches for segmentation of polyps in colonoscopy images and of the optic disc and optic cup in colour fundus images. The trained models will be made available at: https://github.com/smallmax00/Graph_Region_Boudnary.
Yanda Meng, Hongrun Zhang, Yitian Zhao, Xiaoyun Yang, Yihong Qiao, Ian J. C. MacCormick, Xiaowei Huang 0001, Yalin Zheng
IEEE Trans. Medical Imaging7
2022 Coverage-Guided Testing for Recurrent Neural Networks
abstract
Recurrent neural networks (RNNs) have been applied to a broad range of applications, including natural language processing, drug discovery, and video recognition. Their vulnerability to input perturbation is also known. Aligning with a view from software defect detection, this article aims to develop a coverage-guided testing approach to systematically exploit the internal behavior of RNNs, with the expectation that such testing can detect defects with high possibility. Technically, the long short-term memory network (LSTM), a major class of RNNs, is thoroughly studied. A family of three test metrics are designed to quantify not only the values but also the temporal relations (including both stepwise and bounded-length) exhibited when LSTM processing inputs. A genetic algorithm is applied to efficiently generate test cases. The test metrics and test case generation algorithm are implemented into a tooltestRNN, which is then evaluated on a set of LSTM benchmarks. Experiments confirm thattestRNNhas advantages over the state-of-the-art tool DeepStellar and attack-based defect detection methods, owing to its working with finer temporal semantics and the consideration of the naturalness of input perturbation. Furthermore,testRNNenables meaningful information to be collected and exhibited for users to understand the testing results, which is an important step toward interpretable neural network testing.
Wei Huang 0035, Youcheng Sun, Xingyu Zhao 0001, James Sharp, Wenjie Ruan, Xiaowei Huang 0001
IEEE Trans. Reliab.7
2021 BI-GCN: Boundary-Aware Input-Dependent Graph Convolution Network for Biomedical Image Segmentation
Yanda Meng, Hongrun Zhang, Dongxu Gao, Yitian Zhao, Xiaoyun Yang, Xuesheng Qian, Xiaowei Huang 0001, Yalin Zheng
BMVC7
2021 Adversarial Robustness of Deep Learning: Theory, Algorithms, and Applications
abstract
This tutorial aims to introduce the fundamentals of adversarial robustness of deep learning, presenting a well-structured review of up-to-date techniques to assess the vulnerability of various types of deep learning models to adversarial examples. This tutorial will particularly highlight state-of-the-art techniques in adversarial attacks and robustness verification of deep neural networks (DNNs). We will also introduce some effective countermeasures to improve robustness of deep learning models, with a particular focus on adversarial training. We aim to provide a comprehensive overall picture about this emerging direction and enable the community to be aware of the urgency and importance of designing robust deep learning models in safety-critical data analytical applications, ultimately enabling the end-users to trust deep learning classifiers. We will also summarize potential research directions concerning the adversarial robustness of deep learning, and its potential benefits to enable accountable and trustworthy deep learning-based data analytical systems and applications.
Wenjie Ruan, Xinping Yi, Xiaowei Huang 0001
CIKM3
2021 Statistical Certification of Acceptable Robustness for Neural Networks
Chengqiang Huang, Xiaowei Huang 0001, Ke Pei
ICANN (1)3
2021 Spatial Uncertainty-Aware Semi-Supervised Crowd Counting
abstract
Semi-supervised approaches for crowd counting attract attention, as the fully supervised paradigm is expensive and laborious due to its request for a large number of images of dense crowd scenarios and their annotations. This paper proposes a spatial uncertainty-aware semi-supervised approach via regularized surrogate task (binary segmentation) for crowd counting problems. Different from existing semi-supervised learning-based crowd counting methods, to exploit the unlabeled data, our proposed spatial uncertainty-aware teacher-student framework focuses on high confident regions’ information while addressing the noisy supervision from the unlabeled data in an end-to-end manner. Specifically, we estimate the spatial uncertainty maps from the teacher model’s surrogate task to guide the feature learning of the main task (density regression) and the surrogate task of the student model at the same time. Besides, we introduce a simple yet effective differential transformation layer to enforce the inherent spatial consistency regularization between the main task and the surrogate task in the student model, which helps the surrogate task to yield more reliable predictions and generates high-quality uncertainty maps. Thus, our model can also address the task-level perturbation problems that occur spatial inconsistency between the primary and surrogate tasks in the student model. Experimental results on four challenging crowd counting datasets demonstrate that our method achieves superior performance to the state-of-the-art semi-supervised methods. Code is available at : https://github.com/smallmax00/SUA_crowd_counting
Yanda Meng, Hongrun Zhang, Yitian Zhao, Xiaoyun Yang, Xuesheng Qian, Xiaowei Huang 0001, Yalin Zheng
ICCV6
2021 A Segment-Based Layout Aware Model for Information Extraction on Document Images
Maizhen Ning, Qiufeng Wang 0001, Kaizhu Huang, Xiaowei Huang 0001
ICONIP (5)4
2021 BayLIME: Bayesian local interpretable model-agnostic explanations
abstract
Given the pressing need for assuring algorithmic transparency, Explainable AI (XAI) has emerged as one of the key areas of AI research. In this paper, we develop a novel Bayesian extension to the LIME framework, one of the most widely used approaches in XAI – which we call BayLIME. Compared to LIME, BayLIME exploits prior knowledge and Bayesian reasoning to improve both the consistency in repeated explanations of a single prediction and the robustness to kernel settings. BayLIME also exhibits better explanation fidelity than the state-of-the-art (LIME, SHAP and GradCAM) by its ability to integrate prior knowledge from, e.g., a variety of other XAI techniques, as well as verification and validation (V&V) methods. We demonstrate the desirable properties of BayLIME through both theoretical analysis and extensive experiments.
Xingyu Zhao 0001, Wei Huang 0035, Xiaowei Huang 0001, Valentin Robu, David Flynn
UAI3
2021 Enhancing Robustness Verification for Deep Neural Networks via Symbolic Propagation
abstract
Abstract Deep neural networks (DNNs) have been shown lack of robustness, as they are vulnerable to small perturbations on the inputs. This has led to safety concerns on applying DNNs to safety-critical domains. Several verification approaches based on constraint solving have been developed to automatically prove or disprove safety properties for DNNs. However, these approaches suffer from the scalability problem, i.e., only small DNNs can be handled. To deal with this, abstraction based approaches have been proposed, but are unfortunately facing the precision problem, i.e., the obtained bounds are often loose. In this paper, we focus on a variety of local robustness properties and a ( δ , ε ) -global robustness property of DNNs, and investigate novel strategies to combine the constraint solving and abstraction-based approaches to work with these properties: We propose a method to verify local robustness, which improves a recent proposal of analyzing DNNs through the classic abstract interpretation technique, by a novel symbolic propagation technique. Specifically, the values of neurons are represented symbolically and propagated from the input layer to the output layer, on top of the underlying abstract domains. It achieves significantly higher precision and thus can prove more properties. We propose a Lipschitz constant based verification framework. By utilising Lipschitz constants solved by semidefinite programming, we can prove global robustness of DNNs. We show how the Lipschitz constant can be tightened if it is restricted to small regions. A tightened Lipschitz constantcan be helpful in proving local robustness properties. Furthermore, a global Lipschitz constant can be used to accelerate batch local robustness verification, and thus support the verification of global robustness. We show how the proposed abstract interpretation and Lipschitz constant based approaches can benefit from each other to obtain more precise results. Moreover, they can be also exploited and combined to improve constraints based approach. We implement our methods in the tool PRODeep, and conduct detailed experimental results on several benchmarks
Pengfei Yang 0002, Jiangchao Liu, Cheng-Chao Huang, Renjue Li, Liqian Chen, Xiaowei Huang 0001, Lijun Zhang 0001
Formal Aspects Comput.7
2020 Regression of Instance Boundary by Aggregated CNN and GCN
Yanda Meng, Dongxu Gao, Yitian Zhao, Xiaoyun Yang, Xiaowei Huang 0001, Yalin Zheng
ECCV (8)6
2020 Explaining Image Classifiers Using Statistical Fault Localization
Youcheng Sun, Hana Chockler, Xiaowei Huang 0001, Daniel Kroening
ECCV (28)3
2020 Generalizing Universal Adversarial Attacks Beyond Additive Perturbations
abstract
The previous study has shown that universal adversarial attacks can fool deep neural networks over a large set of input images with a single human-invisible perturbation. However, current methods for universal adversarial attacks are based on additive perturbation, which cause misclassification when the perturbation is directly added to the input images. In this paper, for the first time, we show that a universal adversarial attack can also be achieved via non-additive perturbation (e.g., spatial transformation). More importantly, to unify both additive and non-additive perturbations, we propose a novel unified yet flexible framework for universal adversarial attacks, called GUAP, which is able to initiate attacks by additive perturbation, non-additive perturbation, or the combination of both. Extensive experiments are conducted on ImageNet dataset with several deep neural network models including GoogLeNet, VGG and ResNet. The empirical experiments demonstrate that GUAP can obtain up to 99.24% successful attack rate on ImageNet dataset, leading to over 19% improvements than current state-of-the-art universal adversarial attacks. The code for reproducing the experiments in this paper is available at https://github.com/TrustAI/GUAP.
Yanghao Zhang, Wenjie Ruan, Xiaowei Huang 0001
ICDM4
2020 Reliability Validation of Learning Enabled Vehicle Tracking
abstract
This paper studies the reliability of a real-world learning-enabled system, which conducts dynamic vehicle tracking based on a high-resolution wide-area motion imagery input. The system consists of multiple neural network components - to process the imagery inputs - and multiple symbolic (Kalman filter) components - to analyse the processed information for vehicle tracking. It is known that neural networks suffer from adversarial examples, which make them lack robustness. However, it is unclear if and how the adversarial examples over learning components can affect the overall system-level reliability. By integrating a coverage-guided neural network testing tool, DeepConcolic, with the vehicle tracking system, we found that (1) the overall system can be resilient to some adversarial examples thanks to the existence of other components, and (2) the overall system presents an extra level of uncertainty which cannot be determined by analysing the deep learning components only. This research suggests the need for novel verification and validation methods for learning-enabled systems.
Youcheng Sun, Simon Maskell, James Sharp, Xiaowei Huang 0001
ICRA5
2020 Maximum Power Point Tracking of Photovoltaic Systems Using Deep Q-networks
abstract
A photovoltaic (PV) generator exhibits nonlinear current-voltage characteristics and its maximum power point varies with incident atmospheric conditions. Therefore, maximum power point tracking (MPPT) control is required to maximize the output power of the PV generator. In this paper, deep Q-network based reinforcement learning strategy is proposed to optimize MPPT process for the photovoltaic system. The proposed system uses a novel control method which introduces agent to interface with the environment and finally gets the strategy of maximum reward accordingly. Simulations and experiments show the feasibility and effectiveness of the proposed system. Compared with the traditional perturb and observe (P&O) and incremental conductance (InC) methods, this method prominently saves tracking steps.
Kangshi Wang, Dou Hong, Jieming Ma, Ka Lok Man, Kaizhu Huang, Xiaowei Huang 0001
INDIN6
2020 Practical Verification of Neural Network Enabled State Estimation System for Robotics
abstract
We study for the first time the verification problem on learning-enabled state estimation systems for robotics, which use Bayes filter for localisation, and use deep neural network to process sensory input into observations for the Bayes filter. Specifically, we are interested in a robustness property of the systems: given a certain ability to an adversary for it to attack the neural network without being noticed, whether or not the state estimation system is able to function with only minor loss of localisation precision? For verification purposes, we reduce the state estimation systems to a novel class of labelled transition systems with payoffs and partial order relations, and formally express the robustness property as a constrained optimisation objective. Based on this, practical verification algorithms are developed. As a major case study, we work with a real-world dynamic tracking system that uses a Kalman filter (a special case of the Bayes filter) to localise and track a ground vehicle. Its perception system, based on convolutional neural networks, processes a high-resolution Wide Area Motion Imagery (WAMI) data stream. Experimental results show that our algorithms can not only verify the robustness of the WAMI tracking system but also provide useful counterexamples.
Wei Huang 0035, Youcheng Sun, James Sharp, Simon Maskell, Xiaowei Huang 0001
IROS6
2020 CNN-GCN Aggregation Enabled Boundary Regression for Biomedical Image Segmentation
Yanda Meng, Dongxu Gao, Yitian Zhao, Xiaoyun Yang, Xiaowei Huang 0001, Yalin Zheng
MICCAI (4)6
2020 How does Weight Correlation Affect Generalisation Ability of Deep Neural Networks?
abstract
This paper studies the novel concept of weight correlation in deep neural networks and discusses its impact on the networks' generalisation ability. For fully-connected layers, the weight correlation is defined as the average cosine similarity between weight vectors of neurons, and for convolutional layers, the weight correlation is defined as the cosine similarity between filter matrices. Theoretically, we show that, weight correlation can, and should, be incorporated into the PAC Bayesian framework for the generalisation of neural networks, and the resulting generalisation bound is monotonic with respect to the weight correlation. We formulate a new complexity measure, which lifts the PAC Bayes measure with weight correlation, and experimentally confirm that it is able to rank the generalisation errors of a set of networks more precisely than existing measures. More importantly, we develop a new regulariser for training, and provide extensive experiments that show that the generalisation error can be greatly reduced with our novel approach.
Gaojie Jin, Xinping Yi, Lijun Zhang 0001, Sven Schewe, Xiaowei Huang 0001
NeurIPS6
2020 A Safety Framework for Critical Systems Utilising Deep Neural Networks
Xingyu Zhao 0001, Alec Banks, James Sharp, Valentin Robu, David Flynn, Michael Fisher 0001, Xiaowei Huang 0001
SAFECOMP7
2020 PRODeep: a platform for robustness verification of deep neural networks
abstract
Deep neural networks (DNNs) have been applied in safety-critical domains such as self driving cars, aircraft collision avoidance systems, malware detection, etc. In such scenarios, it is important to give a safety guarantee to the robustness property, namely that outputs are invariant under small perturbations on the inputs. For this purpose, several algorithms and tools have been developed recently. In this paper, we present PRODeep, a platform for robustness verification of DNNs. PRODeep incorporates constraint-based, abstraction-based, and optimisation-based robustness checking algorithms. It has a modular architecture, enabling easy comparison of different algorithms. With experimental results, we illustrate the use of the tool, and easy combination of those techniques.
Renjue Li, Cheng-Chao Huang, Pengfei Yang 0002, Xiaowei Huang 0001, Lijun Zhang 0001, Bai Xue 0001, Holger Hermanns
ESEC/SIGSOFT FSE5
2020 A game-based approximate verification of deep neural networks with provable guarantees
Min Wu 0011, Matthew Wicker, Wenjie Ruan, Xiaowei Huang 0001, Marta Z. Kwiatkowska
Theor. Comput. Sci.4
2019 Global Robustness Evaluation of Deep Neural Networks with Provable Guarantees for the Hamming Distance
abstract
Deployment of deep neural networks (DNNs) in safety-critical systems requires provable guarantees for their correct behaviours. We compute the maximal radius of a safe norm ball around a given input, within which there are no adversarial examples for a trained DNN. We define global robustness as an expectation of the maximal safe radius over a test dataset, and develop an algorithm to approximate the global robustness measure by iteratively computing its lower and upper bounds. Our algorithm is the first efficient method for the Hamming (L0) distance, and we hypothesise that this norm is a good proxy for a certain class of physical attacks. The algorithm is anytime, i.e., it returns intermediate bounds and robustness estimates that are gradually, but strictly, improved as the computation proceeds; tensor-based, i.e., the computation is conducted over a set of inputs simultaneously to enable efficient GPU computation; and has provable guarantees, i.e., both the bounds and the robustness estimates can converge to their optimal values. Finally, we demonstrate the utility of our approach by applying the algorithm to a set of challenging problems.
Wenjie Ruan, Min Wu 0011, Youcheng Sun, Xiaowei Huang 0001, Daniel Kroening, Marta Z. Kwiatkowska
IJCAI4
2019 Gaze-based Intention Anticipation over Driving Manoeuvres in Semi-Autonomous Vehicles
abstract
Anticipating a human collaborator's intention enables safe and efficient interaction between a human and an autonomous system. Specifically, in the context of semiautonomous driving, studies have revealed that correct and timely prediction of the driver's intention needs to be an essential part of Advanced Driver Assistance System (ADAS) design. To this end, we propose a framework that exploits drivers' time-series eye gaze and fixation patterns to anticipate their real-time intention over possible future manoeuvres, enabling a smart and collaborative ADAS that can aid drivers to overcome safety-critical situations. The method models human intention as the latent states of a hidden Markov model and uses probabilistic dynamic time warping distributions to capture the temporal characteristics of the observation patterns of the drivers. The method is evaluated on a data set of 124 experiments from 75 drivers collected in a safety-critical semi-autonomous driving scenario. The results illustrate the efficacy of the framework by correctly anticipating the drivers' intentions about 3 seconds beforehand with over 90% accuracy.
Min Wu 0011, Tyron Louw, Morteza Lahijanian, Wenjie Ruan, Xiaowei Huang 0001, Natasha Merat, Marta Z. Kwiatkowska
IROS5
2019 Analyzing Deep Neural Networks with Symbolic Propagation: Towards Higher Precision and Faster Verification
Jiangchao Liu, Pengfei Yang 0002, Liqian Chen, Xiaowei Huang 0001, Lijun Zhang 0001
SAS5
2019 Towards Integrating Formal Verification of Autonomous Robots with Battery Prognostics and Health Management
Xingyu Zhao 0001, Matthew Osborne, Jenny Lantair, Valentin Robu, David Flynn, Xiaowei Huang 0001, Michael Fisher 0001, Fabio Papacchini, Angelo Ferrando 0001
SEFM6
2019 Structural Test Coverage Criteria for Deep Neural Networks
abstract
Deep neural networks (DNNs) have a wide range of applications, and software employing them must be thoroughly tested, especially in safety-critical domains. However, traditional software test coverage metrics cannot be applied directly to DNNs. In this paper, inspired by the MC/DC coverage criterion, we propose a family of four novel test coverage criteria that are tailored to structural features of DNNs and their semantics. We validate the criteria by demonstrating that test inputs that are generated with guidance by our proposed coverage criteria are able to capture undesired behaviours in a DNN. Test cases are generated using a symbolic approach and a gradient-based heuristic search. By comparing them with existing methods, we show that our criteria achieve a balance between their ability to find bugs (proxied using adversarial examples and correlation with functional coverage) and the computational cost of test input generation. Our experiments are conducted on state-of-the-art DNNs obtained using popular open source datasets, including MNIST, CIFAR-10 and ImageNet.
Youcheng Sun, Xiaowei Huang 0001, Daniel Kroening, James Sharp, Matthew Hill, Rob Ashmore
ACM Trans. Embed. Comput. Syst.2
2019 Reasoning about Cognitive Trust in Stochastic Multiagent Systems
abstract
We consider the setting of stochastic multiagent systems modelled as stochastic multiplayer games and formulate an automated verification framework for quantifying and reasoning about agents’ trust. To capture human trust, we work with a cognitive notion of trust defined as a subjective evaluation that agentAmakes about agentB’s ability to complete a task, which in turn may lead to a decision byAto rely onB. We propose a probabilistic rational temporal logic PRTL*, which extends the probabilistic computation tree logic PCTL* with reasoning about mental attitudes (beliefs, goals, and intentions) and includes novel operators that can express concepts of social trust such as competence, disposition, and dependence. The logic can express, for example, that “agentAwill eventually trust agentBwith probability at leastpthat B will behave in a way that ensures the successful completion of a given task.” We study the complexity of the automated verification problem and, while the general problem is undecidable, we identify restrictions on the logic and the system that result in decidable, or even tractable, subproblems.
Xiaowei Huang 0001, Marta Z. Kwiatkowska, Maciej Olejnik
ACM Trans. Comput. Log.1
2018 Model Checking Probabilistic Epistemic Logic for Probabilistic Multiagent Systems
abstract
In this work we study the model checking problem for probabilistic multiagent systems with respect to the probabilistic epistemic logic PETL, which can specify both temporal and epistemic properties. We show that under the realistic assumption of uniform schedulers, i.e., the choice of every agent depends only on its observation history, PETL model checking is undecidable. By restricting the class of schedulers to be memoryless schedulers, we show that the problem becomes decidable. More importantly, we design a novel algorithm which reduces the model checking problem into a mixed integer non-linear programming problem, which can then be solved by using an SMT solver. The algorithm has been implemented in an existing model checker and experiments are conducted on examples from the IPPC competitions.
Andrea Turrini, Xiaowei Huang 0001, Lei Song 0001, Yuan Feng 0001, Lijun Zhang 0001
IJCAI3
2018 Reachability Analysis of Deep Neural Networks with Provable Guarantees
abstract
Verifying correctness for deep neural networks (DNNs) is challenging. We study a generic reachability problem for feed-forward DNNs which, for a given set of inputs to the network and a Lipschitz-continuous function over its outputs computes the lower and upper bound on the function values. Because the network and the function are Lipschitz continuous, all values in the interval between the lower and upper bound are reachable. We show how to obtain the safety verification problem, the output range analysis problem and a robustness measure by instantiating the reachability problem. We present a novel algorithm based on adaptive nested optimisation to solve the reachability problem. The technique has been implemented and evaluated on a range of DNNs, demonstrating its efficiency, scalability and ability to handle a broader class of networks than state-of-the-art verification approaches.
Wenjie Ruan, Xiaowei Huang 0001, Marta Z. Kwiatkowska
IJCAI2
2018 Concolic testing for deep neural networks
abstract
Concolic testing combines program execution and symbolic analysis to explore the execution paths of a software program. In this paper, we develop the first concolic testing approach for Deep Neural Networks (DNNs). More specifically, we utilise quantified linear arithmetic over rationals to express test requirements that have been studied in the literature, and then develop a coherent method to perform concolic testing with the aim of better coverage. Our experimental results show the effectiveness of the concolic testing approach in both achieving high coverage and finding adversarial examples.
Youcheng Sun, Min Wu 0011, Wenjie Ruan, Xiaowei Huang 0001, Marta Z. Kwiatkowska, Daniel Kroening
ASE4
2018 Feature-Guided Black-Box Safety Testing of Deep Neural Networks
Matthew Wicker, Xiaowei Huang 0001, Marta Z. Kwiatkowska
TACAS (1)2
2018 An Epistemic Strategy Logic
abstract
This article presents an extension of temporal epistemic logic with operators that can express quantification over agent strategies. Unlike previous work on alternating temporal epistemic logic, the semantics works with systems whose states explicitly encode the strategy being used by each of the agents. This provides a natural way to express what agents would know were they to be aware of some of the strategies being used by other agents. A number of examples that rely on the ability to express an agent’s knowledge about the strategies being used by other agents are presented to motivate the framework, including reasoning about game-theoretic equilibria, knowledge-based programs, and information-theoretic computer security policies. Relationships to several variants of alternating temporal epistemic logic are discussed. The computational complexity of model checking the logic and several of its fragments are also characterized.
Xiaowei Huang 0001, Ron van der Meyden
ACM Trans. Comput. Log.1
2017 Reasoning about Cognitive Trust in Stochastic Multiagent Systems
abstract
We consider the setting of stochastic multiagent systems and formulate an automated verification framework for quantifying and reasoning about agents' trust. To capture human trust, we work with a cognitive notion of trust defined as a subjective evaluation that agent A makes about agent B's ability to complete a task, which in turn may lead to a decision by A to rely on B. We propose a probabilistic rational temporal logic PRTL*, which extends the logic PCTL* with reasoning about mental attitudes (beliefs, goals and intentions), and includes novel operators that can express concepts of social trust such as competence, disposition and dependence. The logic can express, for example, that "agent A will eventually trust agent B with probability at least p that B will be have in a way that ensures the successful completion of a given task". We study the complexity of the automated verification problem and, while the general problem is undecidable, we identify restrictions on the logic and the system that result in decidable, or even tractable, subproblems.
Xiaowei Huang 0001, Marta Z. Kwiatkowska
AAAI1
2017 Safety Verification of Deep Neural Networks
Xiaowei Huang 0001, Marta Z. Kwiatkowska, Sen Wang 0002, Min Wu 0011
CAV (1)1
2017 ATL Strategic Reasoning Meets Correlated Equilibrium
abstract
This paper is motivated by analysing a Google self-driving car accident, i.e., the car hit a bus, with the framework and the tools of strategic reasoning by model checking. First of all, we find that existing ATL model checking may find a solution to the accident with {\it irrational} joint strategy of the bus and the car. This leads to a restriction of treating both the bus and the car as rational agents, by which their joint strategy is an equilibrium of certain solution concepts. Second, we find that a randomly-selected joint strategy from the set of equilibria may result in the collision of the two agents, i.e., the accident. Based on these, we suggest taking Correlated Equilibrium (CE) as agents' joint stratgey and optimising over the utilitarian value which is the expected sum of the agents' total rewards. The language ATL is extended with two new modalities to express the existence of an CE and a unique CE, respectively. We implement the extension into a software model checker and use the tool to analyse the examples in the paper. We also study the complexity of the model checking problems.
Xiaowei Huang 0001, Ji Ruan
IJCAI1
2016 Strengthening Agents Strategic Ability with Communication
Xiaowei Huang 0001, Qingliang Chen, Kaile Su
AAAI1
2016 Model Checking Probabilistic Knowledge: A PSPACE Case
abstract
Model checking probabilistic knowledge of memoryful semantics is undecidable, even for a simple formula concerning the reachability of probabilistic knowledge of a single agent. This result suggests that the usual approach of tackling undecidable model checking problems, by finding syntactic restrictions over the logic language, may not suffice. In this paper, we propose to work with an additional restriction that agent's knowledge concerns a special class of atomic propositions. A PSPACE-complete case is identified with this additional restriction, for a logic language combining LTL with limit-sure knowledge of a single agent.
Xiaowei Huang 0001, Marta Z. Kwiatkowska
AAAI1
2016 Reconfigurability in Reactive Multiagent Systems
Xiaowei Huang 0001, Qingliang Chen, Kaile Su
IJCAI1
2016 Normative Multiagent Systems: The Dynamic Generalization
Xiaowei Huang 0001, Ji Ruan, Qingliang Chen, Kaile Su
IJCAI1
2015 The Complexity of Model Checking Succinct Multiagent Systems
Xiaowei Huang 0001, Qingliang Chen, Kaile Su
IJCAI1
2015 Bounded model checking of strategy ability with perfect recall
Xiaowei Huang 0001
Artif. Intell.1
2014 Symbolic Model Checking Epistemic Strategy Logic
abstract
This paper presents a symbolic BDD-based model checking algorithm for an epistemic strategy logic with observational semantics. The logic has been shown to be more expressive than several variants of ATELand therefore the algorithm can also be used for ATEL model checking. We implement the algorithm in a model checker and apply it to an application on train control system. The performance of the algorithm is also reported, with a comparison showing improved results over a previous partially symbolic approach for ATEL model checking.
Xiaowei Huang 0001, Ron van der Meyden
AAAI1
2014 A Temporal Logic of Strategic Knowledge
Xiaowei Huang 0001, Ron van der Meyden
KR1
2014 Symbolic Synthesis for Epistemic Specifications with Observational Semantics
Xiaowei Huang 0001, Ron van der Meyden
TACAS1
2013 Symbolic Synthesis of Knowledge-based Program Implementations with Synchronous Semantics
Xiaowei Huang 0001, Ron van der Meyden
TARK1
2012 Synthesizing Strategies for Epistemic Goals by Epistemic Model Checking: An Application to Pursuit Evasion Games
abstract
The paper identifies a special case in which the complex problem of synthesis from specifications in temporal-epistemic logic can be reduced to the simpler problem of model checking such specifications. An application is given of strategy synthesis in pursuit-evasion games, where one or more pursuers with incomplete information aim to discover theexistence of an evader. Experimental results are provided to evaluate the feasibility of the approach.
Xiaowei Huang 0001, Ron van der Meyden
AAAI1
2012 Probabilistic Alternating-Time Temporal Logic of Incomplete Information and Synchronous Perfect Recall
abstract
A probabilistic variant of ATL* logic is proposed to work with multi-player games of incomplete information and synchronous perfect recall. The semantics of the logic is settled over probabilistic interpreted system and partially observed probabilistic concurrent game structure. While unexpectedly, the model checking problem is in general undecidable even for single-group fragment, we find a fragment whose complexity is in 2-EXPTIME. The usefulness of this fragment is shown over a land search scenario.
Xiaowei Huang 0001, Kaile Su, Chenyi Zhang 0001
AAAI1
2011 Model Checking Knowledge in Pursuit Evasion Games
Xiaowei Huang 0001, Patrick Maupin, Ron van der Meyden
IJCAI1
2011 Symbolic model checking of probabilistic knowledge
abstract
This paper describes an algorithm for model checking a fragment of the logic of knowledge and probability in multi-agent systems, with respect to a perfect recall interpretation of knowledge and agents' subjective probability. The algorithm has been implemented in the epistemic model checker MCK. Some experiments with the implemented algorithm are reported, in which some properties of agents' probabilistic knowledge are verified in two security protocols: Chaum's Dining Cryptographers protocol, and a protocol for Oblivious Transfer due to Rivest.
Xiaowei Huang 0001, Cheng Luo 0003, Ron van der Meyden
TARK1
2010 The Complexity of Epistemic Model Checking: Clock Semantics and Branching Time
abstract
In the clock semantics for epistemic logic, two situations are indistinguishable for an agent when it makes the same observation and the time in the situations is the same. The paper characterizes the complexity of model checking branching time logics of knowledge in finite state systems with respect to the clock semantics.
Xiaowei Huang 0001, Ron van der Meyden
ECAI1
2010 Congruence Formats for Weak Readiness Equivalence and Weak Possible Future Equivalence
abstract
Weak equivalences are important behavioral equivalences in the course of specifying and analyzing reactive systems using process algebraic languages. In this paper, we propose a series of weak equivalences named weak parametric readiness equivalences, which take two previously known behavioral equivalences, i.e. the weak readiness equivalence and the weak possible future equivalence, as their special cases. More importantly, based on the idea of structural operational semantics, a series of rule formats are presented to guarantee congruence for these weak parametric readiness equivalences, i.e. to show that the proposed rule formats can guarantee the congruence of their corresponding weak parametric readiness equivalences. This series of rule formats reflects the differences in the weak parametric readiness equivalences. We conclude that when the weak parametric readiness equivalences become coarser, their corresponding rule formats turn tighter.
Xiaowei Huang 0001
Comput. J.1
2007 What Semantic Equivalences Are Suitable for Non-interference Properties in Computer Security
Xiaowei Huang 0001
ICICS1