Qian Li 0024

dblp:69/5902-24 · DBLP profile ↗
← Back
33ranked-venue papers
10as first author
30since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 6 first-author · 18 since 2021Artificial intelligence and machine learning · 9 · 3 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 3 since 2021Human-computer interaction and ubiquitous computing · 2 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 EchoBat: Echo-Vision Enhancement and Echo-Layered Sampling for Video LLMs Hallucination Mitigation
abstract
Recent advancements in multimodal large language models (MLLMs) have shown remarkable progress in video understanding. However, video MLLMs (VideoMLLMs) still suffer from hallucinations, generating nonsensical or irrelevant content. This issue partly stems from over-reliance on pre-trained knowledge, sometimes neglecting the rich visual information present in the video. Additionally, many existing methods rely on uniform frame sampling, which can overlook critical visual cues. To address these challenges, we present EchoBat, a novel approach that leverages audio information as well as video temporal and logical consistency to improve preference data construction and keyframe extraction. Our method integrates Direct Preference Optimization (DPO) to mitigate hallucinations by leveraging high-quality, contextually rich preference feedback. Specifically, we use GPT-4o to generate high-quality video descriptions and integrate visually relevant segments from Whisper-derived transcripts to construct preference responses. Correspondingly, we use the reference model itself to describe the reversed video, and use GPT-4o to flashback the text and fill in the hallucination to produce non-preferred responses. This strategy enhances the model’s ability to better understand visual content and temporal, logical relationships within videos. Furthermore, we propose an echo-layered sampling strategy for keyframe extraction from videos, which can provide more precise visual supervision compared to uniform sampling. Experimental results on the three latest video hallucination benchmarks demonstrate the effectiveness of our approach.
Shuai Liu 0016, Yiheng Pan, Chenwei Tian, Qian Li 0024, Chenhao Lin
AAAI5
2026 Model Stability Defense Against Model Poisoning in Federated Learning
abstract
Federated Learning (FL) exhibits susceptible to model poisoning attacks, which compromise the availability of the collaboratively trained model by introducing detrimental local updates during the training process. The predominant line of defense against such attacks has been to impose stringent restrictions on clients' model updates. However, this strategy raises new vulnerabilities where the global model can be infiltrated by meticulously crafted malicious perturbations. This vulnerability arises due to the model's inherent sensitivity to perturbations, making it exposed and fragile. In response, this work investigates a novel defensive paradigm centered on model stability-specifically, a model's resilience against perturbations within its parameter space. As a solution, we introduce a new method named Model Stability Defense for Federated Learning (MSDFL), designed to fortify the defense of FL systems against model poisoning attacks. MSDFL utilizes a minmax optimization framework, which is fundamentally linked to empirical risk for exploring the effects of model perturbations. The core aim of our approach is to minimize the norm of the model-output Jacobian matrix without compromising predictive performance, thereby establishing defense through enhanced model stability. Moreover, we propose a refined version of MSDFL, named Holistic Model Stability Defense for Federated Learning (HMSDFL), which considers model stability across all output dimensions of the logits to effectively eradicate the disparity in model convergence speed induced by MSDFL. Extensive experimental results fully demonstrate the fidelity, robustness, compatibility, and self-protection of our methods. The source codes are maintained athttps://github.com/qqoneone/MSDFL.
Di Wu 0062, Yong Qi 0001, Saiyu Qi, Qian Li 0024, Minghao Yao, Kaitai Liang
IEEE Trans. Dependable Secur. Comput.5
2026 Quantitative Frequency-Based Framework for Interpreting Adversarial Examples
abstract
Deep neural networks are known to be susceptible to imperceptible adversarial perturbations. Many studies aim to interpret adversarial examples in the frequency domain. However, existing research often relies on a limited number of datasets, models, and adversarial attacks, leading to incomplete conclusions. Moreover, a quantitative interpretation of adversarial examples remains lacking. This paper proposes a quantitative frequency-based framework to comprehensively investigate adversarial examples, where six kinds of attacks against naturally and adversarially trained models across three datasets are adopted. Initially, our framework visualizes the distributions of successful adversarial perturbations in the frequency domain to locate their target regions. Subsequently, we characterize the importance of perturbations contained in different frequency bands and define adversarially effective frequency bands (AEFBs). Furthermore, we leverage the identified AEFBs to enhance two query-based black-box adversarial attacks. Our experimental results uncover the varying characteristics of adversarial perturbations, which are analyzed from dataset-level, model-level, and attack-level perspectives. After reordering frequency bands and identifying AEFBs, we further demonstrate that adversarial attacks guided by AEFBs can achieve superior performance, verifying their effectiveness and generalization. These significant findings contribute to a deeper understanding of adversarial examples and provide valuable insights for future research.
Sicong Han, Chenhao Lin, Chao Shen 0001, Zhengyu Zhao 0001, Qian Li 0024, Qian Wang 0002
IEEE Trans. Dependable Secur. Comput.5
2026 Cross-Region Feature Reformer With Semantic Preservation for Adversarial Malware Detection
Qian Li 0024, Di Wu 0062, Chenhao Lin, Shuai Liu 0016, Cong Wang 0001, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.1
2026 Vul-CTG: A Multimodal Framework for Software Vulnerability Detection via Code Text and Graph Integration
abstract
Pretrained Language Models (PLMs) and Graph Neural Networks (GNNs) have emerged as promising approaches for software vulnerability detection. However, existing methods still face limitations, including the absence of fine-grained cross-modal interaction and the impact of data noise. Approaches integrating PLMs and GNNs fail to fully leverage their complementary strengths, while unreliable labels hinder generalization, further degrading real-world detection performance. To over-come these limitations, we propose Vul-CTG, a multimodal integration framework for software vulnerability detection that combines Code Text, and program Graph representations. Vul-CTG constructs enriched code graph representations by integrating statement-level source code graphs and abstract code property graphs, enabling more effective alignment between structural and semantic information. To enhance robustness against noisy labels and improve cross-modal consistency, the model incorporates contrastive learning and pre-training techniques. Central to Vul-CTG is CTG-Former, a novel alignment architecture that projects both code text and graph modalities into a unified latent space, allowing the model to capture complex structural and semantic patterns for more accurate vulnerability detection. Experimental results on recent function-level datasets demonstrate the effectiveness of Vul-CTG, showing an approximate 3% improvement in F1-score over state-of-the-art methods. Our code is available at https://github.com/ryxFry/Vul-CTG.
Shuai Liu 0016, Qian Li 0024, Xinlei He 0001, Xiaoyu Zhang 0013, Chenhao Lin, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.4
2026 Adversarial Video Promotion Against Text-to-Video Retrieval
Qiwei Tian, Chenhao Lin, Zhengyu Zhao 0001, Shuai Liu 0016, Qian Li 0024, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.5
2025 Artificial intelligence security and privacy: a survey
abstract
Abstract Artificial intelligence (AI) is revolutionizing both industries and reshaping the global economy. However, the rapid advancement of AI technologies brings significant security and privacy challenges. Recent incidents highlight vulnerabilities in AI systems, such as data leakage and malicious code injection, leading to severe financial losses and privacy breaches. Although existing studies have discussed specific security threats, they often lack detailed granularity and cover a limited scope. In this survey, we fill this gap by systematically categorizing and analyzing the threats and countermeasures in AI systems, which span both the training and inference stages, encompass centralized and distributed settings, and address both conventional and foundation AI models. By reviewing existing literature, we aim to provide AI researchers and practitioners with a thorough understanding of system vulnerabilities and current countermeasures. We hope to inspire further research into robust solutions, ultimately contributing to the development of resilient AI technologies.
Xinlei He 0001, Guowen Xu, Xingshuo Han, Qian Wang 0002, Lingchen Zhao, Chao Shen 0001, Chenhao Lin, Zhengyu Zhao 0001, Qian Li 0024, Le Yang 0007, Shouling Ji, Shaofeng Li 0001, Haojin Zhu, Zhibo Wang 0001, Tianqing Zhu, Qi Li 0002, Chaoxiang He, Hongsheng Hu, Shuo Wang 0012, Shifeng Sun 0001, Hongwei Yao, Qinyu Zhang 0001, Kai Chen 0012, Yue Zhao 0027, Hongwei Li 0001, Xinyi Huang 0001, Dengguo Feng
Sci. China Inf. Sci.9
2025 Backdoor threats in large language models - a survey
Shuai Liu 0016, Yiheng Pan, Kun Hong, Ruite Fei, Chenhao Lin, Qian Li 0024, Chao Shen 0001
Sci. China Inf. Sci.6
2025 AMA: Adaptive Model Poisoning Attacks Towards Federated Learning
abstract
Federated Learning (FL) is vulnerable to model poisoning attacks, where malicious updates (e.g., gradients) can adversely interfere with the global model. Existing attacks typically rely heavily on the updates of benign clients and aggregation algorithms to craft malicious updates. However, the benign updates and aggregation algorithms are usually hard to access for attackers, which makes their attacks weak and volatile. Therefore, in this work, we aim to design an adaptive model poisoning attack based on the agnostic adversary. Specifically, we propose a new concept from the perspective of adversarial learning, called adversarial model perturbation. This perturbation targets the parameters of the local model and aims to maximally mislead its predictions. Then, we develop a novel adaptive model poisoning attack namedAdversarial Model Attack (AMA), which utilizes the adversarial model perturbation as the malicious updates to attack the global model. Instead of the benign updates and aggregation algorithms, we only leverage the original data of the malicious client to adaptively craft the malicious updates. AMA resolves the conflict between the knowledge requirement of the adversary and the impact of model poisoning attacks. Empirical results against multiple robust FL methods show that AMA surpasses state-of-the-art attack methods and updates the benchmark of attack impact on Fedavg, Trimean, Multi-Krum, FoundationFL, RFA, and Median.
Di Wu 0062, Yong Qi 0001, Saiyu Qi, Qian Li 0024
IEEE Trans. Dependable Secur. Comput.5
2025 Robust Adversarial Defenses in Federated Learning: Exploring the Impact of Data Heterogeneity
abstract
Federated Learning (FL) enables geographically distributed clients to collaboratively train machine learning models by exchanging local model parameters while preserving data privacy. In practice, FL faces two critical challenges. First, it is vulnerable to security issues as malicious clients would artificially harm the functionality of FL by launching poisoning attacks. Second, the inherent data heterogeneity among clients (termed Non-IID data in FL) naturally arises from distributed data ownership and significantly degrades model convergence and accuracy. However, with studies separately devoted to these two research lines, the interplay between data heterogeneity and security remains poorly understood. In this paper, we systematically investigate the relationship between data heterogeneity and adversarial robustness in FL. Specifically, we propose novel data partitioning algorithms that simulate Label-Conditional Non-IID and Feature-Conditional Non-IID with quantifiable heterogeneity levels. Further, we conduct extensive experiments to evaluate classical defense methods in the practical FL environment under state-of-the-art untargeted attacks. With results in various settings, we separately analyze the connection between Non-IID to defenses and attacks. Regarding attacks, with similar effects on models, Non-IID impacts the training in a different way compared with attacks. The interaction between attacks and Non-IID provides an opportunity to cause severe damage to FL. Regarding defenses, Non-IID induces heterogeneity in model distribution among clients which raises the difficulty of maintaining fidelity and robustness for defense methods.
Qian Li 0024, Di Wu 0062, Dawei Zhou 0004, Chenhao Lin, Shuai Liu 0016, Cong Wang 0001, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.1
2025 Hard Adversarial Example Mining for Improving Robust Fairness
abstract
Adversarial training (AT) is widely considered the state-of-the-art technique for improving the robustness of deep neural networks (DNNs) against adversarial examples (AEs). Nevertheless, recent studies have revealed that adversarially trained models are prone to unfairness problems. Recent works in this field usually apply class-wise regularization methods to enhance the fairness of AT. However, this paper discovers that these paradigms can be sub-optimal in improving robust fairness. Specifically, we empirically observe that the AEs that are already robust (referred to as “easy AEs” in this paper) are useless and even harmful in improving robust fairness. To this end, we propose the hard adversarial example mining (HAM) technique which concentrates on mining hard AEs while discarding the easy AEs in AT. Specifically, HAM identifies the easy AEs and hard AEs with a fast adversarial attack method. By discarding the easy AEs and reweighting the hard AEs, the robust fairness of the model can be efficiently and effectively improved. Extensive experimental results on four image classification datasets demonstrate the improvement of HAM in robust fairness and training efficiency compared to several state-of-the-art fair adversarial training methods. Our code is available athttps://github.com/yyl-github-1896/HAM.
Chenhao Lin, Yulong Yang 0002, Qian Li 0024, Zhengyu Zhao 0001, Zhe Peng, Run Wang 0001, Liming Fang 0001, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.4
2025 Data-Centric Robust Training for Defending Against Transfer-Based Adversarial Attacks
abstract
Transfer-based adversarial attacks pose a severe threat to real-world deep learning systems since they do not require access to target models. Adversarial training (AT), which is recognized as the most effective defense against white-box attacks, also ensures high robustness against (black-box) transfer-based attacks. However, AT suffers from significant computational overhead because it repeatedly generates adversarial examples (AEs) throughout the entire training process. In this paper, we demonstrate that such repeated generation is unnecessary to achieve robustness against transfer-based attacks. Instead, pre-generating AEs all at once before training is sufficient, as proposed in our new defense paradigm called Data-Centric Robust Training (DCRT). DCRT employs clean data augmentation and adversarial data augmentation techniques to enhance the dataset before training. Our experimental results show that DCRT outperforms widely-used AT techniques (e.g., PGD-AT, TRADES, EAT, and FAT) in terms of transfer-based black-box robustness and even surpasses the top-1 defense on RobustBench when combined with common model-centric techniques. We also highlight additional benefits of DCRT, such as improved training efficiency and class-wise fairness.Our code will be available on GitHub.
Yulong Yang 0002, Ruiqi Cao, Qiwei Tian, Chenhao Lin, Zhengyu Zhao 0001, Qian Li 0024, Le Yang 0007, Hongshan Yang, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.7
2024 Physical 3D Adversarial Attacks against Monocular Depth Estimation in Autonomous Driving
abstract
Deep learning-based monocular depth estimation (MDE), extensively applied in autonomous driving, is known to be vulnerable to adversarial attacks. Previous physical attacks against MDE models rely on 2D adversarial patches, so they only affect a small, localized region in the MDE map but fail under various viewpoints. To address these limitations, we propose 3D Depth Fool (3D2Fool), the first 3D texture-based adversarial attack against MDE models. 3D2Fool is specifically optimized to generate 3D adversarial textures agnostic to model types of vehicles and to have improved robustness in bad weather conditions, such as rain and fog. Experimental results validate the superior performance of our 3D2Fool across various scenarios, including vehicles, MDE models, weather conditions, and viewpoints. Real-world experiments with printed 3D textures on physical vehicle models further demonstrate that our 3D2Fool can cause an MDE error of over 10 meters. The code is available at https://github.com/GandolfczjhI3D2Fool.
Junhao Zheng, Chenhao Lin, Zhengyu Zhao 0001, Qian Li 0024, Chao Shen 0001
CVPR5
2024 Collapse-Aware Triplet Decoupling for Adversarially Robust Image Retrieval
abstract
Adversarial training has achieved substantial performance in defending image retrieval against adversarial examples. However, existing studies in deep metric learning (DML) still suffer from two major limitations: weak adversary and model collapse. In this paper, we address these two limitations by proposing Collapse-Aware TRIplet DEcoupling (CA-TRIDE). Specifically, TRIDE yields a stronger adversary by spatially decoupling the perturbation targets into the anchor and the other candidates. Furthermore, CA prevents the consequential model collapse, based on a novel metric, collapseness, which is incorporated into the optimization of perturbation. We also identify two drawbacks of the existing robustness metric in image retrieval and propose a new metric for a more reasonable robustness evaluation. Extensive experiments on three datasets demonstrate that CA-TRIDE outperforms existing defense methods in both conventional and new metrics. Codes are available at https://github.com/michaeltian108/CA-TRIDE.
Qiwei Tian, Chenhao Lin, Zhengyu Zhao 0001, Qian Li 0024, Chao Shen 0001
ICML4
2024 Fairness in machine learning: definition, testing, debugging, and application
Xuanqi Gao, Chao Shen 0001, Chenhao Lin, Qian Li 0024, Qian Wang 0002, Qi Li 0002, Xiaohong Guan
Sci. China Inf. Sci.5
2024 Towards Gradient-Based Saliency Consensus Training for Adversarial Robustness
abstract
In recent works, robust networks have consistently exhibited more discriminative saliency map that proves to indicate sufficient adversarial robustness. In existed safe training paradigms e.g., adversarial training, however, the progressive saliency information regarding on what input semantic feature model prediction relies, have not yet been fully-explored. Due to this, we consider the incorporation of posterior saliency properties of robust model in training, as an efficient supervision signal on robust learning. It thus provides an alternative direction to enhance robustness, from the saliency interpretability perspective. In this article, to harden model we propose to optimize the discrimination of intermediate gradient-based saliency and maintain its consensus in training, which encourage model to behave according to task-relevant feature from the salient region such as object edges in image. Then, we introduce Adversarially Gradient-based Saliency Consensus Training method, dubbedAdv-GSCT. Within it, we preserve the similarity between the learned model saliency and the target one as label, approximated in the most offending case representing the least but essential information scenario. Meanwhile, a constructed pseudo-input coupled with feature importance, is feed into model to ensure the discrimination of estimated target saliency. Besides providing a novel insight into adversarial defense,Adv-GSCTdiffers from the current most effective adversarial training and does not need multiple iterative generations of adversarial perturbation whose computational cost and sensitivity direction of prediction concern. Finally, extensive performance evaluations on MNIST, CIFAR-10 and ImageNet datasets demonstrate the superiority of our proposed method.
Qian Li 0024, Chao Shen 0001, Chenhao Lin, Saiyu Qi
IEEE Trans. Dependable Secur. Comput.1
2024 LESSON: Multi-Label Adversarial False Data Injection Attack for Deep Learning Locational Detection
abstract
Deep learning methods can not only detect false data injection attacks (FDIA) but also locate attacks of FDIA. Although adversarial false data injection attacks (AFDIA) based on deep learning vulnerabilities have been studied in the field of single-label FDIA detection, the adversarial attack and defense against multi-label FDIA locational detection are still not involved. To bridge this gap, this paper first explores the multi-label adversarial example attacks against multi-label FDIA locational detectors and proposes a general multi-label adversarial attack framework, namely muLti-labEl adverSarial falSe data injectiON attack (LESSON). The proposed LESSON attack framework includes three key designs, namely Perturbing State Variables, Tailored Loss Function Design, and Change of Variables, which can help find suitable multi-label adversarial perturbations within the physical constraints to circumvent both Bad Data Detection (BDD) and Neural Attack Location (NAL). Four typical LESSON attacks based on the proposed framework and two dimensions of attack objectives are examined, and the experimental results demonstrate the effectiveness of the proposed attack framework, posing serious and pressing security concerns in smart grids.
Jiwei Tian, Chao Shen 0001, Buhong Wang, Xiaofang Xia, Meng Zhang 0011, Chenhao Lin, Qian Li 0024
IEEE Trans. Dependable Secur. Comput.7
2024 Attention-SA: Exploiting Model-Approximated Data Semantics for Adversarial Attack
abstract
Adversarial Defense of deep neural networks have gained significant attention and there have been active research efforts on model vulnerabilities for attacking such as gradient-based attack and pre-defined semantic manipulation. However, they often lack clear adversarial pattern connecting model extracted notion and are restricted to fixed constraint, making the gradual inability to proposed robust defense. In this paper, we propose to utilize the learned semantics of model, possibly not be the true one for the correct prediction, as inspiring clue in adversarial example construction. And we propose a new attention-based semantic oriented adversarial attack without any prior constraint about semantic preservation, dubbed Attention-SA from the learned task-related decision factors perspective. Specifically, to capture the learned factor, we introduce a post-hoc soft attention with a gradient-sensitivity activation consistency to probe the information of latent representation that bridge the input and prediction. With the attention guidance, we perturb the separated and semantic units, then back-propagate the variation onto input to discover expanded adversarial examples. Finally, extensive performance evaluations on CIFAR-10 and ImageNet datasets demonstrate the superiority of our proposed method. And we verify the effectiveness of our method on various robust defenses.
Qian Li 0024, Haoran Fan, Chenhao Lin, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.1
2024 Exploiting Facial Relationships and Feature Aggregation for Multi-Face Forgery Detection
abstract
The emergence of advanced Deepfake technologies has gradually raised concerns in society, prompting significant attention to Deepfake detection. However, in real-world scenarios, Deepfakes often involve multiple faces. Despite this, most existing detection methods still detect these faces individually, overlooking the informative correlation between them and the relationship between the global information of the image and the local information of the faces. In this paper, we address this limitation by proposing FILTER, a novel framework for multi-face forgery detection that explicitly captures underlying correlations. FILTER consists of two main modules: Multi-face Relationship Learning (MRL) and Global Feature Aggregation (GFA). Specifically, MRL learns the correlation of local facial features in multi-face images, and GFA constructs the relationship between image-level labels and individual facial features to enhance performance from a global perspective. In particular, a contrastive learning loss function is used to better discriminate between real and fake faces. Extensive experiments on two publicly available multi-face forgery datasets demonstrate the state-of-the-art performance of FILTER in multi-face forgery detection. For example, on Openforensics Test-Challenge dataset, FILTER outperforms the previous state-of-the-art methods with a higher AUC score (0.980) and higher detection accuracy (92.04%).
Chenhao Lin, Fangbin Yi, Jingyi Deng, Zhengyu Zhao 0001, Qian Li 0024, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.6
2024 Exploiting the Adversarial Example Vulnerability of Transfer Learning of Source Code
abstract
State-of-the-art source code classification models exhibit excellent task transferability, in which the source code encoders are first pre-trained on a source domain dataset in a self-supervised manner and then fine-tuned on a supervised downstream dataset. Recent studies reveal that source code models are vulnerable to adversarial examples, which are crafted by applying semantic-preserving transformations that can mislead the prediction of the victim model. While existing research has introduced practical black-box adversarial attacks, these are often designed for transfer-based or query-based scenarios, necessitating access to the victim domain dataset or the query feedback of the victim system. These attack resources are very challenging or expensive to obtain in real-world situations. This paper proposes the cross-domain attack threat model against the transfer learning of source code where the adversary has only access to an open-sourced pre-trained code encoder. To achieve such realistic attacks, this paper designs the Code Transfer learning Adversarial Example (CodeTAE) method. CodeTAE applies various semantic-preserving transformations and utilizes a genetic algorithm to generate powerful identifiers, thereby enhancing the transferability of the generated adversarial examples. Experimental results on three code classification tasks show that the CodeTAE attack can achieve 30%$\sim ~80$% attack success rates under the cross-domain cross-architecture setting. Besides, the generated CodeTAE adversarial examples can be used in adversarial fine-tuning to enhance both the clean accuracy and the robustness of the code model. Our code is available athttps://github.com/yyl-github-1896/CodeTAE/.
Yulong Yang 0002, Haoran Fan, Chenhao Lin, Qian Li 0024, Zhengyu Zhao 0001, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.4
2024 Quantization Aware Attack: Enhancing Transferable Adversarial Attacks by Model Quantization
abstract
Quantized neural networks (QNNs) have received increasing attention in resource-constrained scenarios due to their exceptional generalizability. However, their robustness against realistic black-box adversarial attacks has not been extensively studied. In this scenario, adversarial transferability is pursued across QNNs with different quantization bitwidths, which particularly involve unknown architectures and defense methods. Previous studies claim that transferability is difficult to achieve across QNNs with different bitwidths on the condition that they share the same architecture. However, we discover that under different architectures, transferability can be largely improved by using a QNN quantized with an extremely low bitwidth as the substitute model. We further improve the attack transferability by proposingquantization aware attack(QAA), which fine-tunes a QNN substitute model with a multiple-bitwidth training objective. In particular, we demonstrate that QAA addresses the two issues that are commonly known to hinder transferability: 1) quantization shifts and 2) gradient misalignments. Extensive experimental results validate the high transferability of the QAA to diverse target models. For instance, when adopting the ResNet-34 substitute model on ImageNet, QAA outperforms the current best attack in attacking standardly trained DNNs, adversarially trained DNNs, and QNNs with varied bitwidths by 4.6% ~ 20.9%, 8.8% ~ 13.4%, and 2.6% ~ 11.8% (absolute), respectively. In addition, QAA is efficient since it only takes one epoch for fine-tuning. In the end, we empirically explain the effectiveness of QAA from the view of the loss landscape. Our code is available at https://github.com/yyl-github-1896/QAA/.
Yulong Yang 0002, Chenhao Lin, Qian Li 0024, Zhengyu Zhao 0001, Haoran Fan, Dawei Zhou 0004, Nannan Wang 0001, Tongliang Liu, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.3
2023 FedMCSA: Personalized federated learning via model components self-attention
Yong Qi 0001, Saiyu Qi, Di Wu 0062, Qian Li 0024
Neurocomputing5
2023 Sensitive region-aware black-box adversarial attacks
Chenhao Lin, Sicong Han, Jiongli Zhu, Qian Li 0024, Chao Shen 0001, Xiaohong Guan
Inf. Sci.4
2023 Understanding and defending against White-box membership inference attack in deep learning
Di Wu 0062, Saiyu Qi, Yong Qi 0001, Qian Li 0024, Bowen Cai 0004, Jingxian Cheng
Knowl. Based Syst.4
2023 Revisiting Gradient Regularization: Inject Robust Saliency-Aware Weight Bias for Adversarial Defense
abstract
Despite regularizing the Jacobians of neural networks to enhance model robustness has directly theoretical correlation with model prediction stability, a large defense performance gap exists when compared to the empirically perturbation-based adversarial training e.g. PGD-based, which enjoys nice discriminative saliency maps as well. To mitigate this issue, in this paper we first analyze the dilemma that the gradient map of its resulting model has no content hierarchy to mark out salient profile of input, as a negative signal of the obstructive for effective adversarial defense. Based on this, we argue that incorporating robust gradient-based saliency properties into regularized training may be helpful to reduce the performance gap. Specifically, we propose a simple method called Saliency-aware Gradient Regularization (SAGR), where a biased weight distribution strategy is introduced on positive gradient to structure and increase the impact of class-gradient components inside the Jacobian of model. The strategy maintains the dominant role of saliency-critical true-class gradient in learning process and differentiates diverse importance of gradient sensitivities that would localize input salient areas. Herein we interpret the sharpness of true-class sensitivity as robust recognition of more learning-relevant features e.g., regions containing dominant object in image for classification. Instead, false-class parts are considered as recognition-irrelevant nuisance factors e.g. the backgrounds, which are thus depressed with more strength. Experimental results demonstrate the efficacy of the proposed method and validate that distinguishment of sensitivities could further yield more robustness gain and sharper gradient saliency map.
Qian Li 0024, Chenhao Lin, Di Wu 0062, Chao Shen 0001
IEEE Trans. Inf. Forensics Secur.1
2022 FLMJR: Improving Robustness of Federated Learning via Model Stability
Di Wu 0062, Yong Qi 0001, Saiyu Qi, Qian Li 0024
ESORICS (3)5
2022 Stochastic Ghost Batch for Self-distillation with Dynamic Soft Label
Qian Li 0024, Saiyu Qi, Yong Qi 0001, Di Wu 0062, Yun Lin 0001, Jin Song Dong 0001
Knowl. Based Syst.1
2022 Correction to: Multi-level word features based on CNN for fake news detection in cultural communication
Qian Li 0024, Youshui Lu, Jingxian Cheng
Pers. Ubiquitous Comput.2
2021 Semi-supervised two-phase familial analysis of Android malware with normalized graph embedding
Qian Li 0024, Yong Qi 0001, Saiyu Qi, Xinxing Liu
Knowl. Based Syst.1
2021 Adversarial Adaptive Neighborhood With Feature Importance-Aware Convex Interpolation
abstract
Adversarial Examples threaten to fool deep learning models to output erroneous predictions with high confidence. Optimization-based methods for constructing such samples have been extensively studied. While being effective in terms of aggression, they typically lack clear interpretation and constraint about their underlying generation process, which thus hinders us from leveraging the produced adversarial samples for model protection in the reverse direction. Hence, we expect them to repair bugs in the pre-trained models by produced additional training data equipped with strong attack ability rather than time-consuming full re-training from scratch. To address these issues, we first study the black-box behaviors and the intrinsic deficiency of neighborhood information in previous optimization-based adversarial attacks and defenses, respectively. Then we introduce a new method dubbed FeaCP, which uses correct predicted samples in disjoint classes to guide the generation of more explainable adversarial samples in the ambiguous region around the decision boundary instead of uncontrolled “blind spots”, via convex combination in a feature component-wise manner which takes the individual importance of feature ingredients into account. Our method incorporates the prior fact that for well-separated samples, the path connecting them would go through model's decision-boundary that lies in a low-density region, however, wherein adversarial examples are spread with high probability, thus having an impact on the ultimate trained model. In our work, the path is constructed by proposed inhomogeneous feature-wise convex interpolation rather than operating on sample-wise level, limiting the search space of FeaCP to obtain an adaptive neighborhood. Finally, we provide detailed insights and extend our method to adversarial fine-tuning using vicinity distribution to optimize the approximated decision boundary, and validate the significance of our FeaCP to model performance. The experimental results show that our method provides competitive performance on various datasets and networks.
Qian Li 0024, Yong Qi 0001, Saiyu Qi, Yun Lin 0001, Jin Song Dong 0001
IEEE Trans. Inf. Forensics Secur.1
2020 Stochastic Batch Augmentation with An Effective Distilled Dynamic Soft Label Regularizer
abstract
Data augmentation have been intensively used in training deep neural network to improve the generalization, whether in original space (e.g., image space) or representation space. Although being successful, the connection between the synthesized data and the original data is largely ignored in training, without considering the distribution information that the synthesized samples are surrounding the original sample in training. Hence, the behavior of the network is not optimized for this. However, that behavior is crucially important for generalization, even in the adversarial setting, for the safety of the deep learning system. In this work, we propose a framework called Stochastic Batch Augmentation (SBA) to address these problems. SBA stochastically decides whether to augment at iterations controlled by the batch scheduler and in which a ''distilled'' dynamic soft label regularization is introduced by incorporating the similarity in the vicinity distribution respect to raw samples. The proposed regularization provides direct supervision by the KL-Divergence between the output soft-max distributions of original and virtual data. Our experiments on CIFAR-10, CIFAR-100, and ImageNet show that SBA can improve the generalization of the neural networks and speed up the convergence of network training.
Qian Li 0024, Yong Qi 0001, Saiyu Qi, Jie Ma 0001, Jian Zhang 0087
IJCAI1
2020 Multi-level word features based on CNN for fake news detection in cultural communication
Qian Li 0024, Youshui Lu, Jingxian Cheng
Pers. Ubiquitous Comput.1
2013 Multi-view semi-supervised web image classification via co-graph
Youtian Du, Qian Li 0024, Zhongmin Cai, Xiaohong Guan
Neurocomputing2