EDBT 2026 Demo / reviewers in the wild / expert
Xingyu Zhou 0002
dblp:07/10352-2
· DBLP profile ↗
10ranked-venue papers
2as first author
9since 2021 · last 2025
0000-0003-3439-4450ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 6 · 1 first-author · 5 since 2021Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Computer networks · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Exploring Universal Adversarial Attacks on DNN-Based Automatic Modulation Recognition Using Joint MetricsabstractWith its remarkable capability for automated feature extraction, deep neural networks (DNNs) have achieved significant breakthroughs in numerous fields. However, recent studies indicate that deep models are vulnerable to adversarial attacks. In the automatic modulation recognition (AMR) task, the attacker injects imperceptible adversarial perturbations into the radio signals, causing the receiver to misidentify the adversarial examples as incorrect modulation patterns. In this article, we propose an input-independent universal adversarial perturbation (UAP) generation method to attack DNN-based AMR. The proposed method, termed Joint Metric-based Universal Adversarial Perturbation (JM-UAP), strives to enhance the aggressiveness of UAPs by minimizing the similarity metric between feature vectors extracted from benign examples and adversarial examples. To achieve this, feature vectors derived from the penultimate layer of the DNN are chosen as the optimization objects. The dissimilarity between these feature vectors is assessed by combining two metrics, the Adjusted cosine similarity and the Pearson correlation. Extensive experiments demonstrate that our approach significantly reduces the accuracy of AMR models, exhibits robust transferability across various deep models and multiple signal-to-noise ratios (SNRs) datasets, and performs well even in asynchronous scenarios. Xingyu Zhou 0002, Weijun Zeng |
IEEE Trans. Wirel. Commun. | 1 |
| 2023 | A novel end-to-end deep separation network based on attention mechanism for single channel blind separation in wireless communicationabstractAbstract The traditional methods exhibit unstable performance and high complexity for separating co‐frequency modulated wireless communication signals under single‐channel conditions. In this study, an end‐to‐end deep separation network based on the attention mechanism is proposed, which employs the encoder‐separator‐decoder architecture to implement the separation. The encoder can convert the signal into a high‐dimensional feature representation for the separator to achieve separation of the signal in a high‐dimensional space. The core of the proposed deep separation network is the innovative separator, which is mainly composed of attention‐based convolution units with residual connection. The attention‐based convolution unit integrates the large kernel convolution and modified global context (GC) block to simultaneously capture the local and global information of the signal. Furthermore, we improve the GC block to implement channel weighting and location weighting for the given feature map, thus further enhancing the adaptability of the model. The experimental results show that the proposed method not only outperforms the traditional methods in separating mixed signals with the same modulation, but also enables the separation of mixed signals with different modulations. Lu Yu 0008, Xingyu Zhou 0002 |
IET Signal Process. | 4 |
| 2022 | Learning Coated Adversarial Camouflages for Object DetectorsabstractAn adversary can fool deep neural network object detectors by generating adversarial noises. Most of the existing works focus on learning local visible noises in an adversarial "patch" fashion. However, the 2D patch attached to a 3D object tends to suffer from an inevitable reduction in attack performance as the viewpoint changes. To remedy this issue, this work proposes the Coated Adversarial Camouflage (CAC) to attack the detectors in arbitrary viewpoints. Unlike the patch trained in the 2D space, our camouflage generated by a conceptually different training framework consists of 3D rendering and dense proposals attack. Specifically, we make the camouflage perform 3D spatial transformations according to the pose changes of the object. Based on the multi-view rendering results, the top-n proposals of the region proposal network are fixed, and all the classifications in the fixed dense proposals are attacked simultaneously to output errors. In addition, we build a virtual 3D scene to fairly and reproducibly evaluate different attacks. Extensive experiments demonstrate the superiority of CAC over the existing attacks, and it shows impressive performance both in the virtual scene and the real world. This poses a potential threat to the security-critical computer vision systems. Yexin Duan, Xingyu Zhou 0002, Junhua Zou, Zhengyun He, Jin Zhang 0024, Zhisong Pan 0003 |
IJCAI | 3 |
| 2022 | Adversarial attack via dual-stage network erosion
Yexin Duan, Junhua Zou, Xingyu Zhou 0002, Zhengyun He, Dazhi Zhan, Jin Zhang 0024, Zhisong Pan 0003 |
Comput. Secur. | 3 |
| 2022 | Enhancing transferability of adversarial examples via rotation-invariant attacksabstractAbstract Deep neural networks are vulnerable to adversarial examples. However, existing attacks exhibit relatively low efficacy in generating transferable adversarial examples. Improved transferability to address this issue is proposed via a rotation‐invariant attack method that maximizes the loss function w.r.t the random rotated image instead of the original input at each iteration, thus mitigating the high correlation between the adversarial examples and the source models and making the adversarial examples more transferable. Extensive experiments show that the proposed method can significantly improve the transferability of the adversarial examples with almost no extra computational cost and can be integrated into various methods. In addition, when this method is easily applied through a plug‐in, the average attack success rate against six robustly trained models increases by 5.4% over the state‐of‐the‐art baseline method, demonstrating its effectiveness and efficiency. The codes used are publicly available at https://github.com/YeXinD/Rotation‐Invariant‐Attack . Yexin Duan, Junhua Zou, Xingyu Zhou 0002, Jin Zhang 0024, Zhisong Pan 0003 |
IET Comput. Vis. | 3 |
| 2021 | Learning Indistinguishable and Transferable Adversarial Examples
Junhua Zou, Yexin Duan, Xingyu Zhou 0002, Zhisong Pan 0003 |
PRCV (4) | 4 |
| 2021 | Mask-guided noise restriction adversarial attacks for image classification
Yexin Duan, Xingyu Zhou 0002, Junhua Zou, Junyang Qiu, Jin Zhang 0024, Zhisong Pan 0003 |
Comput. Secur. | 2 |
| 2021 | Robust and label efficient bi-filtering graph convolutional networks for node classification
Shuaihui Wang, Jin Zhang 0024, Xingyu Zhou 0002, Zhen Cui 0001, Guyu Hu, Zhisong Pan 0003 |
Knowl. Based Syst. | 4 |
| 2021 | A data independent approach to generate adversarial patches
Xingyu Zhou 0002, Zhisong Pan 0003, Yexin Duan, Jin Zhang 0024, Shuaihui Wang |
Mach. Vis. Appl. | 1 |
| 2019 | Attributed network representation learning via DeepWalkabstractNetwork representation learning aims at learning a low-dimensional vector for each node in a network, which has attracted increasing research interests recently. However, most existing approaches only use topology information of each node and ignore its attributes information. In this paper, we pro pose an Improved Attributed Node Random Walks(IANRW) framework, which constructs the neighborhood of an attributed node and then leverages the skip-gram model to perform node embeddings. The method can be able to flexibly incorporate both the topology and attribute information. Additionally, it can easily deal with missing data and be applied to large networks. Extensive experiments on six datasets show that IANRW outperforms many state-of-the-art embedding models and can improve various attributed networks mining tasks. Zhisong Pan 0003, Guyu Hu, Haimin Yang, Xin Li 0120, Xingyu Zhou 0002 |
Intell. Data Anal. | 6 |