VLDB 2026 Research / reviewers in the wild / expert
Yanmei Fang
dblp:81/4314
· DBLP profile ↗
15ranked-venue papers
3as first author
7since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 10 · 2 first-author · 5 since 2021Security and privacy · 4 · 1 first-author · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Variance as a Catalyst: Efficient and Transferable Semantic Erasure Adversarial Attack for Customized Diffusion ModelsabstractLatent Diffusion Models (LDMs) enable fine-tuning with only a few images and have become widely used on the Internet. However, it can also be misused to generate fake images, leading to privacy violations and social risks. Existing adversarial attack methods primarily introduce noise distortions to generated images but fail to completely erase identity semantics.
In this work, we identify the variance of VAE latent code as a key factor that influences image distortion. Specifically, larger variances result in stronger distortions and ultimately erase semantic information. Based on this finding, we propose a Laplace-based (LA) loss function that optimizes along the fastest variance growth direction, ensuring each optimization step is locally optimal. Additionally, we analyze the limitations of existing methods and reveal that their loss functions often fail to align gradient signs with the direction of variance growth. They also struggle to ensure efficient optimization under different variance distributions. To address these issues, we further propose a novel Lagrange Entropy-based (LE) loss function.
Experimental results demonstrate that our methods achieve state-of-the-art performance on CelebA-HQ and VGGFace2. Both proposed loss functions effectively lead diffusion models to generate pure-noise images with identity semantics completely erased. Furthermore, our methods exhibit strong transferability across diverse models and efficiently complete attacks with minimal computational resources. Our work provides a practical and efficient solution for privacy protection. Yanmei Fang, Yunshu Dai, Fangjun Huang |
ICML | 3 |
| 2024 | LOFT: Latent Space Optimization and Generator Fine-Tuning for Defending Against DeepfakesabstractDeepFakes pose a significant threat to individual reputations and society as a whole. Existing proactive defense strategies concentrate on adding adversarial perturbations to images to disrupt or nullify the generation of DeepFakes, but these approaches are easily detectable by human perception and can be removed. To address this challenge, we propose a three-stage framework called LOFT (Latent Space Optimization and Generator Fine-Tuning for Defending against DeepFakes). First, encoding the original image into the latent space to obtain a latent code that captures facial features. Second, utilizing Adversarial Latent Optimization to optimize the latent code for reconstructing the image and defending against DeepFake manipulation. Third, fine-tuning the generator to enhance the reconstructed image’s visual quality and defense capability further. Our study evaluates the effectiveness of our proposed framework through two distinct DeepFake tasks: attribute editing and face reenactment. Various experimental results demonstrate that our proposed framework outperforms the existing benchmark in both visual quality and defense capability. Shaoyou Zeng, Fangjun Huang, Yanmei Fang |
ICASSP | 4 |
| 2024 | Enhancing Adversarial Transferability on Vision Transformer by Permutation-Invariant AttacksabstractVision Transformers (ViTs) have demonstrated remarkable performance in computer vision. However, they are still susceptible to adversarial examples. In this paper, we propose a novel adversarial attack method tailored for ViTs, by leveraging the inherent permutation-invariant of ViTs to generate highly transferable adversarial examples. Specifically, we split the image into patches of different scales and permute the local patches to generate diverse inputs. By optimizing perturbations on the permuted image set, we can prevent the generated adversarial examples from overfitting to the surrogate model, thereby enhancing transferability. Extensive experiments conducted on ImageNet demonstrate that the permutation-invariant (PI) attack significantly improves transferability between ViTs and from ViTs to CNNs. PI is applicable to diverse ViTs and can seamlessly integrate with existing attack methods further enhancing transferability. Our approach surpasses state-of-the-art ensemble methods for input transformation and achieves a notable performance improvement of 11.9% on average. Yanmei Fang, Fangjun Huang |
ICME | 2 |
| 2024 | Patch Attacks on Vision Transformer via Skip Attention Gradients
Yanmei Fang, Fangjun Huang |
PRCV (8) | 2 |
| 2022 | Deliberate Multi-Attention Network for Image Captioning
Zedong Dan, Yanmei Fang |
PRCV (1) | 2 |
| 2021 | Spatial Steganalysis Based on Gradient-Based Neural Architecture Search
Xiaoqing Deng, Weiqi Luo 0001, Yanmei Fang |
ProvSec | 3 |
| 2021 | Upscaling factor estimation on pre-JPEG compressed images based on difference histogram of spectral peaks
Shangjun Luo, Jiarui Liu 0002, Wei Lu 0001, Yanmei Fang, Jinhua Zeng, Shaopei Shi |
Signal Process. Image Commun. | 5 |
| 2020 | Audio Steganography Based on Iterative Adversarial Attacks Against Convolutional Neural NetworksabstractRecently, convolutional neural networks (CNNs) have demonstrated superior performance on digital multimedia steganalysis. However, some studies have noted that most CNN-based classifiers can be easily fooled by adversarial examples, which form slightly perturbed inputs to a target network according to the gradients. Inspired by this phenomenon, we first introduce a novel steganography method based on adversarial examples for digital audio in the time domain. Unlike related methods for image steganography, such as [1]-[4], which are highly dependent on some existing embedding costs, the proposed method can start from a flat or even a random embedding cost and then iteratively update the initial costs by exploiting the adversarial attacks until satisfactory security performances are obtained. The extensive experimental results show that our method significantly outperforms the existing nonadaptive and adaptive steganography methods and achieves state-of-the-art results. Moreover, we also provide experimental results to investigate why the proposed embedding modifications seem evenly located at all audio segments despite their different content complexities, which is contrary to the content adaptive principle widely employed in modern steganography methods. Junqi Wu 0002, Weiqi Luo 0001, Yanmei Fang |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2018 | Binary image steganalysis based on local texture pattern
Wei Lu 0001, Yanmei Fang, Xianjin Liu, Yuileong Yeung, Yingjie Xue |
J. Vis. Commun. Image Represent. | 3 |
| 2012 | Markov-based image forensics for photographic copying from printed pictureabstractNowadays, photographic-copying technique is very popular along with the rapid development of the image-capturing device, especially digital camera. As a result, the recaptured images, i.e., images taken from real-scene images displayed on various medium, e.g., LCD screen, are used in illegal cases now and then. In this paper, by comparing the recaptured images with their corresponding real-scene images, we find the recapturing procedure changes the statistics of the images. Then the Markov process based features extracted from the Discrete Cosine Transform(DCT) coefficients array are proposed to characterize this changes. During experimentation, a large and typical image dataset, which consisted of 3994 real-scene images and 3994 recaptured images that are taken from printed pictures with diversified image contents and camera models, is build and used for training and testing the classifier Support Vector Machine(SVM). Experimental results show that the proposed forensics scheme performs very well and outperforms the state-of-art methods. Jing Yin, Yanmei Fang |
ACM Multimedia | 2 |
| 2009 | Source class identification for DSLR and compact camerasabstractThe identification of image acquisition source is an important problem in digital image forensics. In this work, we focus on building a classifier to effectively distinguish between digital images taken from digital single lens reflex (DSLR) and compact cameras. Based on the architecture and the imaging features of DSLR and compact cameras, the images taken from different sources may have different statistical properties in both spatial and transform domains. In this work, we utilized wavelet coefficients and pixel noise statistics to model these two different source classes over 20 different digital cameras. The efficacy of the digital source class identifier, introduced in the paper, has been tested over 1000 high quality camera outputs and post-processed images (resized, re-compressed). Experimental analysis shows that the proposed method has good potential to distinguish DSLR and compact source classes. Yanmei Fang, Ahmet Emir Dirik, Xiaoxi Sun, Nasir Memon |
MMSP | 1 |
| 2008 | Steganalysis of Multiple-Base Notational System SteganographyabstractThis letter presents a method for attacking multiple-base notational system (MBNS) steganography . In the MBNS steganography, secret data are converted into symbols in a notational system with multiple bases. The pixels of a host image are then modified such that when the pixel values are divided by the bases, their remainders are equal to the symbols. Through analysis, we prove that the amount of small remainders increases due to the modification. Based on this observation, we propose a steganalytic approach which is effective in not only detecting MBNS steganography but also estimating its embedding rate. Bin Li 0011, Yanmei Fang, Jiwu Huang |
IEEE Signal Process. Lett. | 2 |
| 2005 | Revaluation of Error Correcting Coding in Watermarking Channel
Limin Gu, Yanmei Fang, Jiwu Huang |
CANS | 2 |
| 2005 | The M-band wavelets in image watermarkingabstractMulti-band (M-band) wavelet domain presents a novelty to host the watermark. In this paper, a new family of M-band wavelets, which is symmetric and parameterized with a variable /spl lambda/, is proposed and applied to image watermarking. The parameter /spl lambda/ also can be used as a key in watermark detection to improve the security of watermark. The multi-resolution analysis (MRA) of M-band wavelet transform, integrating with the CDMA (code division multiple access) encoding techniques is studied and employed to watermarking. The security, imperceptibility, and the robustness against JPEG compression and Gaussian noise, are analyzed for the proposed watermarking scheme. The experiments of watermarking based on M-band wavelet transform provide more encouraging results than those based on 2-band wavelets. Yanmei Fang, Ning Bi, Daren Huang, Jiwu Huang |
ICIP (1) | 1 |
| 2005 | Performance Analysis of CDMA-Based Watermarking with Quantization Scheme
Yanmei Fang, Limin Gu, Jiwu Huang |
ISPEC | 1 |