Chao Li 0076

dblp:66/190-76 · DBLP profile ↗
← Back
13ranked-venue papers
4as first author
13since 2021 · last 2026
0000-0002-2391-7319ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 12 · 4 first-author · 12 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021
YearPublicationVenuePosition
2026 An evolutionary multitasking optimization framework with fusion space for constrained multimodal multiobjective problems
Li Yan 0006, Wenao Lu, Chao Li 0076, Bo-Yang Qu 0001, Kunjie Yu, Caitong Yue, Xuzhao Chai
Expert Syst. Appl.3
2026 Adaptive decomposition-based transfer learning for dynamic constrained multi-objective optimization
Li Yan 0006, Yinjin Wu, Bo-Yang Qu 0001, Chao Li 0076, Jing J. Liang, Kunjie Yu, Caitong Yue, Baihao Qiao, Yuqi Lei
Expert Syst. Appl.4
2026 A Weight Inheritance and Guidance Strategy-Based Evolutionary Network Architecture Search
abstract
Neural Architecture Search (NAS) has emerged as an important area in deep learning since it can automatically design high performance network architectures, where Evolution-based NAS (EvoNAS) has made great progress due to the efficient optimization ability of evolutionary algorithms. However, EvoNAS requires evaluating the architectures formed by individuals in the population, and it is inevitable to consume a large amount of evaluation time and computational resources, resulting in restricting the applicability of EvoNAS. To solve the above problems, this paper proposes a Weight Inheritance and Guided Strategy based Evolutionary Network Architecture Search (WIGEvoNAS). Firstly, based on existing manually designed networks, an expanded search space is designed, which includes new convolution operations. Secondly, a weight inheritance strategy is proposed to reduce the training time of candidate architectures in each generation. Finally, a guidance mutation strategy is proposed to direct population evolution towards architectures with superior for the purpose of generating better offspring. The proposed method is compared with several state-of-the-art NAS methods and manual networks on the CIFAR-10, CIFAR-100 and the NASBench-201 benchmark datasets. The empirical results demonstrate that the proposed method achieves promising performance, with error rates of 2.52% on CIFAR-10 and 15.43% on CIFAR-100 respectively. Moreover, the proposed method significantly reduces search costs to 0.9 GPU-days.
Li Yan 0006, Jing J. Liang, Bo-Yang Qu 0001, Chao Li 0076, Kunjie Yu
IEEE Trans. Evol. Comput.5
2026 Population Historical Information-Driven Evolutionary Multitask Neural Architecture Search
abstract
Neural architecture search (NAS) has achieved significant success in automating neural network design, particularly through evolutionary NAS. To address the critical need for efficient architecture discovery across diverse scenarios, such as computer vision and natural language processing, multitask NAS (MT-NAS) methods have emerged. Nevertheless, existing MT-NAS approaches still face critical challenges, including redundant search arising from insufficient exploitation of population historical information across generations and negative transfer caused by unguided interactions between tasks. To address these limitations, a population historical information-driven evolutionary multitask neural architecture search (HIMT-NAS) algorithm is proposed. For each generation, the population historical information is recorded, which includes the operation information and the topology information. In the search process, systematic utilization of population historical information to guide evolutionary search directions, preventing redundant search. Furthermore, the proposed method adjusts cross-task knowledge transfer probability by measuring task similarity through patterns in population historical information, and then updates transfer probabilities when the information proves useful across multiple tasks. Extensive experiments on MedMNIST, CIFAR-10, CIFAR-100, and Tiny-ImageNet demonstrate consistent advantages of the proposed method over both single-task NAS methods and recent MT-NAS methods.
Kunjie Yu, Jing J. Liang, Chao Li 0076, Mingyuan Yu
IEEE Trans. Neural Networks Learn. Syst.4
2025 Optimizing Latent Variables in Integrating Transfer and Query Based Attack Framework
abstract
Black-box adversarial attacks can be categorized into transfer-based and query-based attacks. The former usually has poor transfer performance due to the mismatch between the architectures of models, while the query-based attacks require massive queries and high dimensional optimization variables. In order to solve the above problems, we propose a novel attack framework integrating the advantages of transfer- and query-based attacks, where the framework is divided into two phases: training the adversarial generator and executing the black-box attacks. In the first stage, a generator is trained by the adversarial loss function so that it can output adversarial perturbation, where the latent variables are designed as the input of the generator to reduce the dimension of the optimization variables. In the second stage, based on the trained generator, we further employ a particle swarm optimization algorithm to optimize the latent variables so that the generator can output the perturbation that can achieve a successful attack. Extensive experiments are performed on the ImageNet dataset, and the results demonstrate that the proposed framework can obtain better attack performance compared with a number of the state-of-the-art black-box adversarial attack methods. In addition, we show the flexibility of the proposed framework by extending the experiment for few-pixel attacks.
Chao Li 0076, Tingsong Jiang, Handing Wang, Wen Yao 0001, Donghua Wang 0001
IEEE Trans. Pattern Anal. Mach. Intell.1
2025 ${A^{3}D}$A3D: A Platform of Searching for Robust Neural Architectures and Efficient Adversarial Attacks
abstract
Due to the urgent need of the robustness of deep neural networks (DNN), numerous existing open-sourced tools or platforms are developed to evaluate the robustness of DNN models by ensembling the majority of adversarial attack or defense algorithms. Unfortunately, current platforms can neither optimize the DNN architectures nor the configuration of adversarial attacks to further enhance the model robustness or the performance of adversarial attacks. To alleviate these problems, in this paper, we propose a novel platform called auto-adversarial attack and defense ($A^{3}D$A3D), which can help search for robust neural network architectures and efficient adversarial attacks. $A^{3}D$A3D integrates multiple neural architecture search methods to find robust architectures under different robustness evaluation metrics. Besides, we provide multiple optimization algorithms to search for efficient adversarial attacks. In addition, we combine auto-adversarial attack and defense together to form a unified framework. Among auto adversarial defense, the searched efficient attack can be used as the new robustness evaluation to further enhance the robustness. In auto-adversarial attack, the searched robust architectures can be utilized as the threat model to help find stronger adversarial attacks. Experiments on CIFAR10, CIFAR100, and ImageNet datasets demonstrate the feasibility and effectiveness of the proposed platform.
Wen Yao 0001, Tingsong Jiang, Chao Li 0076, Xiaoqian Chen
IEEE Trans. Pattern Anal. Mach. Intell.4
2025 Universal Multi-View Black-Box Attack Against Object Detectors via Layout Optimization
abstract
Object detectors have demonstrated vulnerability to adversarial examples crafted by small perturbations that can deceive the object detector. Existing adversarial attacks mainly focus on white-box attacks and are merely valid at a specific viewpoint, while the universal multi-view black-box attack is less explored, limiting their generalization in practice. In this paper, we propose a novel universal multi-view black-box attack against object detectors, which optimizes a universal adversarial UV texture constructed by multiple image stickers for a 3D object via the designed layout optimization algorithm. Specifically, we treat the placement of image stickers on the UV texture as a circle-based layout optimization problem, whose objective is to find the optimal circle layout filled with image stickers so that it can deceive the object detector under the multi-view scenario. To ensure reasonable placement of image stickers, two constraints are elaborately devised. To optimize the layout, we adopt the random search algorithm enhanced by the devised important-aware selection strategy to find the most appropriate image sticker for each circle from the image sticker pools. Extensive experiments conducted on four common object detectors suggested that the detection performance decreases by a large magnitude of 74.29% on average in multi-view scenarios. Additionally, a novel evaluation tool based on the photo-realistic simulator is designed to assess the texture-based attack fairly.
Donghua Wang 0001, Wen Yao 0001, Tingsong Jiang, Chao Li 0076, Xiaoqian Chen
IEEE Trans. Circuits Syst. Video Technol.4
2024 QRPatch: A Deceptive Texture-Based Black-Box Adversarial Attacks with Genetic Algorithm
abstract
Patch-based attacks are a major black-box attack paradigm, where there is no limit to the intensity of the perturbation. The existing patch-based attack methods focus on obtaining the optimal position, shape, and pixel values against adversarial patches, however, the generated patch looks conspicuous and makes it easy to attract people's attention. Quick response(QR) code has been widely used in various fields, such as image copyright protection, stored image information. Further, it does not get noticed when a QR code is attached to the image. Therefore, we propose a deceptive texture-based black-box adversarial attack method to address the above problem. Specifically, we use the QR code pattern as the basis of the adversarial patches. Then, we model the adversarial attack as a discrete optimization problem, where the optimization variables are designed as the center coordinates of the patch pasting locations and the pixel values. Further, an upsampling technique is introduced to reduce the dimension of the optimization variables. Finally, genetic algorithm is employed as the optimizer to obtain the optimal parameter of the patch. In order to verify the effectiveness of the proposed method, we compare a number of the state-of-the-art patch-based attack methods on the ImageNet dataset, and the experimental results show that the proposed method can effectively generate deceptive adversarial examples in both digital and physical space and obtain the best attack performance, especially for the defense models.
Chao Li 0076, Wen Yao 0001, Handing Wang, Tingsong Jiang, Donghua Wang 0001
CEC1
2024 Black-box adversarial patch attacks using differential evolution against aerial imagery object detectors
Guijian Tang, Wen Yao 0001, Chao Li 0076, Tingsong Jiang, Shaowu Yang
Eng. Appl. Artif. Intell.3
2023 RFLA: A Stealthy Reflected Light Adversarial Attack in the Physical World
abstract
Physical adversarial attacks against deep neural networks (DNNs) have recently gained increasing attention. The current mainstream physical attacks use printed adversarial patches or camouflage to alter the appearance of the target object. However, these approaches generate conspicuous adversarial patterns that show poor stealthiness. Another physical deployable attack is the optical attack, featuring stealthiness while exhibiting weakly in the daytime with sunlight. In this paper, we propose a novel Reflected Light Attack (RFLA), featuring effective and stealthy in both the digital and physical world, which is implemented by placing the color transparent plastic sheet and a paper cut of a specific shape in front of the mirror to create different colored geometries on the target object. To achieve these goals, we devise a general framework based on the circle to model the reflected light on the target object. Specifically, we optimize a circle (composed of a coordinate and radius) to carry various geometrical shapes determined by the optimized angle. The fill color of the geometry shape and its corresponding transparency are also optimized. We extensively evaluate the effectiveness of RFLA on different datasets and models. Experiment results suggest that the proposed method achieves over 99% success rate on different datasets and models in the digital world. Additionally, we verify the effectiveness of the proposed method in different physical environments by using sunlight or a flashlight.
Donghua Wang 0001, Wen Yao 0001, Tingsong Jiang, Chao Li 0076, Xiaoqian Chen
ICCV4
2023 Adversarial patch attacks against aerial imagery object detectors
Guijian Tang, Tingsong Jiang, Weien Zhou, Chao Li 0076, Wen Yao 0001
Neurocomputing4
2023 Adaptive momentum variance for attention-guided sparse adversarial attacks
Chao Li 0076, Wen Yao 0001, Handing Wang, Tingsong Jiang
Pattern Recognit.1
2022 An Approximated Gradient Sign Method Using Differential Evolution for Black-Box Adversarial Attack
abstract
Recent studies show that deep neural networks are vulnerable to adversarial attacks in the form of subtle perturbations to the input image, which leads the model to output wrong prediction. Such an attack can easily succeed by the existing white-box attack methods, where the perturbation is calculated based on the gradient of the target network. Unfortunately, the gradient is often unavailable in the real-world scenarios, which makes the black-box adversarial attack problems practical and challenging. In fact, they can be formulated as high-dimensional black-box optimization problems at the pixel level. Although evolutionary algorithms are well known for solving black-box optimization problems, they cannot efficiently deal with the high-dimensional decision space. Therefore, we propose an approximated gradient sign method using differential evolution (DE) for solving black-box adversarial attack problems. Unlike most existing methods, it is novel that the proposed method searches the gradient sign rather than the perturbation by a DE algorithm. Also, we transform the pixel-based decision space into a dimension-reduced decision space by combining the pixel differences from the input image to neighbor images, and two different techniques for selecting neighbor images are introduced to build the transferred decision space. In addition, six variants of the proposed method are designed according to the different neighborhood selection and optimization search strategies. Finally, the performance of the proposed method is compared with a number of the state-of-the-art adversarial attack algorithms on CIFAR-10 and ImageNet datasets. The experimental results suggest that the proposed method shows superior performance for solving black-box adversarial attack problems, especially nontargeted attack problems.
Chao Li 0076, Handing Wang, Jun Zhang 0052, Wen Yao 0001, Tingsong Jiang
IEEE Trans. Evol. Comput.1