EDBT 2026 Demo / reviewers in the wild / expert
Hao Fang 0011
dblp:06/2484-11
· DBLP profile ↗
18ranked-venue papers
6as first author
18since 2021 · last 2026
0009-0004-0271-6579ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 14 · 6 first-author · 14 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 3 first-author · 8 since 2021Security and privacy · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Retrievals Can Be Detrimental: Unveiling the Backdoor Vulnerability of Retrieval-Augmented Diffusion ModelsabstractHao Fang, Xiaohang Sui, Hongyao Yu, Kuofeng Gao, Jiawei Kong, Sijin Yu, Bin Chen, Shu-Tao Xia. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Hao Fang 0011, Xiaohang Sui, Hongyao Yu, Kuofeng Gao, Jiawei Kong 0001, Sijin Yu, Bin Chen 0011, Shutao Xia |
ACL (1) | 1 |
| 2026 | When Efficiency Meets Safety: A Benchmark Security Analysis of KV Cache Compression in Large Language ModelsabstractXiaoxiao Ma, Kuofeng Gao, Zeyi Lu, Wenxi Jiang, Hao Fang, Hao Wu, Bin Chen, Shu-Tao Xia. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Kuofeng Gao, Zeyi Lu, Wenxi Jiang, Hao Fang 0011, Bin Chen 0011, Shutao Xia |
ACL (1) | 5 |
| 2026 | Rank Matters: Understanding and Defending Model Inversion Attacks via Low-Rank Feature FilteringabstractModel Inversion Attacks (MIAs) pose a significant threat to data privacy by reconstructing sensitive training samples from the knowledge embedded in trained machine learning models. Despite recent progress in enhancing the effectiveness of MIAs across diverse settings, defense strategies have lagged behind—struggling to balance model utility with robustness against increasingly sophisticated attacks. In this work, we propose the ideal inversion error to measure the privacy leakage, and our theoretical and empirical investigations reveals that higher-rank features are inherently more prone to privacy leakage. Motivated by this insight, we propose a lightweight and effective defense strategy based on low-rank feature filtering, which explicitly reduces the attack surface by constraining the dimension of intermediate representations. Extensive experiments across various model architectures and datasets demonstrate that our method consistently outperforms existing defenses, achieving state-of-the-art performance against a wide range of MIAs. Notably, our approach remains effective even in challenging regimes involving high-resolution data and high-capacity models, where prior defenses fail to provide adequate protection. The code is available at https://github.com/Chrisqcwx/LoFt. Hongyao Yu, Yixiang Qiu, Hao Fang 0011, Tianqu Zhuang, Bin Chen 0011, Sijin Yu, Bin Wang 0034, Shutao Xia, Ke Xu 0002 |
KDD (1) | 3 |
| 2026 | A temporal-aware generative network for cross-modal video universal adversarial perturbation generation
Kai-Wen Zhang, Shuo-Yang Sun, Hao Fang 0011, Changle Zhou, Bin Chen 0011, Shutao Xia |
Knowl. Based Syst. | 3 |
| 2026 | Leveraging Neural Architecture Search for improved downstream-agnostic adversarial attack
Haodong Xiao, Bin Chen 0011, Hao Fang 0011, Yulin Wu 0001, Xuan Wang 0002, Zhi Wang 0001, Shutao Xia |
Pattern Recognit. | 5 |
| 2025 | Hierarchical Features Matter: A Deep Exploration of Progressive Parameterization Method for Dataset DistillationabstractDataset distillation is an emerging dataset reduction method, which condenses large-scale datasets while maintaining task accuracy. Current parameterization methods achieve enhanced performance under extremely high compression ratio by optimizing determined synthetic dataset in informative feature domain. However, they limit themselves to a fixed optimization space for distillation, neglecting the diverse guidance across different informative latent spaces. To overcome this limitation, we propose a novel parameterization method dubbed Hierarchical Parameterization Distillation (H-PD), to systematically explore hierarchical feature within provided feature space (e.g., layers within pre-trained generative adversarial networks). We verify the correctness of our insights by applying the hierarchical optimization strategy on GAN-based parameterization method. In addition, we introduce a novel class-relevant feature distance metric to alleviate the computational burden associated with synthetic dataset evaluation, bridging the gap between synthetic and original datasets. Experimental results demonstrate that the proposed H-PD achieves a significant performance improvement under various settings with equivalent time consumption, and even surpasses current generative distillation using diffusion models under extreme compression ratios IPC=1 and IPC=10. Our code is available at https://github.com/ndhg1213/H-PD Xinhao Zhong, Hao Fang 0011, Bin Chen 0011, Xulin Gu, Meikang Qiu, Shuhan Qi, Shutao Xia |
CVPR | 2 |
| 2025 | Your Language Model Can Secretly Write Like Humans: Contrastive Paraphrase Attacks on LLM-Generated Text DetectorsabstractHao Fang, Jiawei Kong, Tianqu Zhuang, Yixiang Qiu, Kuofeng Gao, Bin Chen, Shu-Tao Xia, Yaowei Wang, Min Zhang. Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing. 2025. Hao Fang 0011, Jiawei Kong 0001, Tianqu Zhuang, Yixiang Qiu, Kuofeng Gao, Bin Chen 0011, Shutao Xia, Yaowei Wang 0001, Min Zhang 0005 |
EMNLP | 1 |
| 2025 | RobNAS: Robust Neural Architecture Search for Point Cloud Adversarial DefenseabstractAs point clouds gain widespread application in fields such as autonomous driving and scene modeling, an increasing number of point cloud learning networks have emerged. As a result, research on 3D adversarial attacks and defenses has rapidly advanced. To the best of our knowledge, existing 3D defense methods primarily focus on enhancing the robustness of networks through point cloud processing or adversarial training, without attention given to network architecture. In this paper, we propose RobNAS, enhancing the adversarial robustness of point cloud classification networks by integrating adversarial training with Neural Architecture Search (NAS) from an architectural robustness perspective. Specifically, we first incorporate PGD-based adversarial training during the architecture search phase of RobNAS to obtain the most robust architecture. Subsequently, during the adversarial training phase, we introduce various adversarial examples to enhance the robustness of the model weights. Our experimental results demonstrate that our method achieves State-Of-The-Art (SOTA) performance. Furthermore, we aim to shed light on the promising potential of architectural robustness for learning robust point cloud representation. Shuoyang Sun, Hao Fang 0011, Bin Chen 0011, Jiawei Li 0006, Enze Huo, Shutao Xia |
ICASSP | 3 |
| 2025 | One Perturbation is Enough: On Generating Universal Adversarial Perturbations Against Vision-Language Pre-Training ModelsabstractVision-Language Pre-training (VLP) models have exhibited unprecedented capability in many applications by taking full advantage of the multimodal alignment. However, previous studies have shown they are vulnerable to maliciously crafted adversarial samples. Despite recent success, these methods are generally instance-specific and require generating perturbations for each input sample. In this paper, we reveal that VLP models are also vulnerable to the instance-agnostic universal adversarial perturbation (UAP). Specifically, we design a novel Contrastive-training Perturbation Generator with Cross-modal conditions (C-PGC) to achieve the attack. In light that the pivotal multimodal alignment is achieved through the advanced contrastive learning technique, we devise to turn this powerful weapon against themselves, i.e., employ a malicious version of contrastive learning to train the C-PGC based on our carefully crafted positive and negative image-text pairs for essentially destroying the alignment relationship learned by VLP models. Besides, C-PGC fully utilizes the characteristics of Vision-and-Language (V+L) scenarios by incorporating both unimodal and cross-modal information as effective guidance. Extensive experiments show that C-PGC successfully forces adversarial samples to move away from their original area in the VLP model's feature space, thus essentially enhancing attacks across various victim models and V+L tasks. The GitHub repository is available at https://github.com/ffhibnese/CPGC_VLP_Universal_Attacks. Hao Fang 0011, Jiawei Kong 0001, Bin Chen 0011, Jiawei Li 0006, Shutao Xia, Ke Xu 0002 |
ICCV | 1 |
| 2025 | Going Beyond Feature Similarity: Effective Dataset distillation based on Class-aware Conditional Mutual InformationabstractDataset distillation (DD) aims to minimize the time and memory consumption needed for training deep neural networks on large datasets, by creating a smaller synthetic dataset that has similar performance to that of the full real dataset. However, current dataset distillation methods often result in synthetic datasets that are excessively difficult for networks to learn from, due to the compression of a substantial amount of information from the original data through metrics measuring feature similarity, e,g., distribution matching (DM). In this work, we introduce conditional mutual information (CMI) to assess the class-aware complexity of a dataset and propose a novel method by minimizing CMI. Specifically, we minimize the distillation loss while constraining the class-aware complexity of the synthetic dataset by minimizing its empirical CMI from the feature space of pre-trained networks, simultaneously. Conducting on a thorough set of experiments, we show that our method can serve as a general regularization method to existing DD methods and improve the performance and training efficiency. Xinhao Zhong, Bin Chen 0011, Hao Fang 0011, Xulin Gu, Shutao Xia, En-Hui Yang |
ICLR | 3 |
| 2025 | Stealthy Shield Defense: A Conditional Mutual Information-Based Approach against Black-Box Model Inversion AttacksabstractModel inversion attacks (MIAs) aim to reconstruct the private training data by accessing the public model, raising concerns about privacy leakage. Black-box MIAs, where attackers can only query the model and obtain outputs, are closer to real-world scenarios. The latest black-box attacks have outperformed state-of-the-art white-box attacks, and existing defenses cannot resist them effectively. To fill this gap, we propose Stealthy Shield Defense (SSD), a post-processing algorithm against black-box MIAs. Our idea is to modify the model's outputs to minimize the conditional mutual information (CMI). We mathematically prove that CMI is a special case of Information Bottleneck (IB), and thus inherits the benefits of IB---making predictions less dependent on inputs and more dependent on ground truths. This theoretically guarantees our effectiveness, both in resisting MIAs and preserving utility. To minimize CMI, we formulate a convex optimization problem and solve it via the water-filling method. Without the need to retrain the model, our defense is plug-and-play and easy to deploy. Experimental results indicate that SSD outperforms existing defenses, in terms of MIA resistance and model's utility, across various attack algorithms, private datasets, and model architectures. Our code is available at https://github.com/ZhuangQu/Stealthy-Shield-Defense. Tianqu Zhuang, Hongyao Yu, Yixiang Qiu, Hao Fang 0011, Bin Chen 0011, Shutao Xia |
ICLR | 4 |
| 2025 | ICAS: Detecting Training Data from Autoregressive Image Generative Models
Hongyao Yu, Yixiang Qiu, Hao Fang 0011, Tianqu Zhuang, Jiaxin Hong, Bin Chen 0011, Shutao Xia |
ACM Multimedia | 4 |
| 2025 | Grounding Language with Vision: A Conditional Mutual Information Calibrated Decoding Strategy for Reducing Hallucinations in LVLMsabstractLarge Vision-Language Models (LVLMs) are susceptible to hallucinations, where generated responses seem semantically plausible yet exhibit little or no relevance to the input image. Previous studies reveal that this issue primarily stems from LVLMs' over-reliance on language priors while disregarding the visual information during decoding. To alleviate this issue, we introduce a novel Conditional Pointwise Mutual Information (C-PMI) calibrated decoding strategy, which adaptively strengthens the mutual dependency between generated texts and input images to mitigate hallucinations. Unlike existing methods solely focusing on text token sampling, we propose to jointly model the contributions of visual and textual tokens to C-PMI, formulating hallucination mitigation as a bi-level optimization problem aimed at maximizing mutual information. To solve it, we design a token purification mechanism that dynamically regulates the decoding process by sampling text tokens remaining maximally relevant to the given image, while simultaneously refining image tokens most pertinent to the generated response. Extensive experiments across various benchmarks reveal that the proposed method significantly reduces hallucinations in LVLMs while preserving decoding efficiency. Hao Fang 0011, Changle Zhou, Jiawei Kong 0001, Kuofeng Gao, Bin Chen 0011, Guojun Ma, Shutao Xia |
NeurIPS | 1 |
| 2025 | GI-NAS: Boosting Gradient Inversion Attacks Through Adaptive Neural Architecture SearchabstractGradient Inversion Attacks invert the transmitted gradients in Federated Learning (FL) systems to reconstruct the sensitive data of local clients and have raised considerable privacy concerns. A majority of gradient inversion methods rely heavily on explicit prior knowledge (e.g., a well pre-trained generative model), which is often unavailable in realistic scenarios. This is because real-world client data distributions are often highly heterogeneous, domain-specific, and unavailable to attackers, making it impractical for attackers to obtain perfectly matched pre-trained models, which inevitably suffer from fundamental distribution shifts relative to target private data. To alleviate this issue, researchers have proposed to leverage the implicit prior knowledge of an over-parameterized network. However, they only utilize a fixed neural architecture for all the attack settings. This would hinder the adaptive use of implicit architectural priors and consequently limit the generalizability. In this paper, we further exploit such implicit prior knowledge by proposing Gradient Inversion via Neural Architecture Search (GI-NAS), which adaptively searches the network and captures the implicit priors behind neural architectures. Extensive experiments verify that our proposed GI-NAS can achieve superior attack performance compared to state-of-the-art gradient inversion methods, even under more practical settings with high-resolution images, large-sized batches, and advanced defense strategies. To the best of our knowledge, we are the first to successfully introduce NAS to the gradient inversion community. We believe that this work exposes critical vulnerabilities in real-world federated learning by demonstrating high-fidelity reconstruction of sensitive data without requiring domain-specific priors, forcing urgent reassessment of FL privacy safeguards. Hao Fang 0011, Bin Chen 0011, Xiaohang Sui, Chuan Chen 0001, Shutao Xia, Ke Xu 0002 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | CLIP-Guided Generative Networks for Transferable Targeted Adversarial Attacks
Hao Fang 0011, Jiawei Kong 0001, Bin Chen 0011, Tao Dai 0001, Shutao Xia |
ECCV (28) | 1 |
| 2024 | A Closer Look at GAN Priors: Exploiting Intermediate Features for Enhanced Model Inversion Attacks
Yixiang Qiu, Hao Fang 0011, Hongyao Yu, Bin Chen 0011, Meikang Qiu, Shutao Xia |
ECCV (32) | 2 |
| 2024 | WaterDiff: Perceptual Image Watermarks Via Diffusion ModelabstractRecent studies have demonstrated that diffusion probabilistic models (DPMs) have numerous advantages in image generation through learning a decodable latent representation. This characteristic makes DPMs an appropriate reversible model for encoding and decoding of image watermarking. We present WaterDiff, which leverages pretrained DPMs for perceptual image watermarking problem. Specifically, WaterDiff embeds the watermark into the decomposed stochastic feature, then the stochastic features is combined with the corresponding semantic latent vector to produce a watermarked image via DPMs. This process balances the perceptual quality (stealthiness) and watermarking capacity by fully exploiting the latent diffusion prior. Extensive experiments indicate that WaterDiff guarantee both perceptual imperceptibility and robustness against state-of-the-art watermarking attacks. Yuqi Tan, Yuang Peng, Hao Fang 0011, Bin Chen 0011, Shutao Xia |
ICASSP | 3 |
| 2023 | GIFD: A Generative Gradient Inversion Method with Feature Domain OptimizationabstractFederated Learning (FL) has recently emerged as a promising distributed machine learning framework to preserve clients' privacy, by allowing multiple clients to upload the gradients calculated from their local data to a central server. Recent studies find that the exchanged gradients also take the risk of privacy leakage, e.g., an attacker can invert the shared gradients and recover sensitive data against an FL system by leveraging pre-trained generative adversarial networks (GAN) as prior knowledge. However, performing gradient inversion attacks in the latent space of the GAN model limits their expression ability and generalizability. To tackle these challenges, we propose Gradient Inversion over Feature Domains (GIFD), which disassembles the GAN model and searches the feature domains of the intermediate layers. Instead of optimizing only over the initial latent code, we progressively change the optimized layer, from the initial latent space to intermediate layers closer to the output images. In addition, we design a regularizer to avoid unreal image generation by adding a small l1ball constraint to the searching range. We also extend GIFD to the out-of-distribution (OOD) setting, which weakens the assumption that the training sets of GANs and FL tasks obey the same data distribution. Extensive experiments demonstrate that our method can achieve pixel-level reconstruction and is superior to the existing methods. Notably, GIFD also shows great generalizability under different defense strategy settings and batch sizes. Hao Fang 0011, Bin Chen 0011, Xuan Wang 0002, Zhi Wang 0001, Shutao Xia |
ICCV | 1 |