Anjie Peng

dblp:10/11281 · DBLP profile ↗
← Back
46ranked-venue papers
7as first author
38since 2021 · last 2026
0000-0001-9287-7536ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 22 · 4 first-author · 20 since 2021Graphics, computer vision, multimedia, augmented reality and games · 20 · 2 first-author · 17 since 2021Security and privacy · 3 · 1 first-authorSystems, architecture and hardware · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 ObjectAdv: Object-Level Unrestricted Adversarial Attacks via Diffusion Models
abstract
Unrestricted adversarial attacks aim to fool DNNs by generating effective yet photorealistic examples. However, previous methods usually rely on global perturbations to enhance attack performance, which inevitably introduces visual distortions. To reduce visual distortions in the background, we propose a diffusion-based framework that focuses on local perturbations to generate object-level unrestricted adversarial examples (ObjectAdv). Since the cross-attention maps of Stable Diffusion contain the object information, we directly leverage the attention maps to localize the semantic region of object where for attacking. Second, a prompt-switching strategy is proposed for both imperceptibility and attack capacity. Specifically, to preserve layout and object shape of clean image, a prompt of true category is used at early denoising steps. At the later steps, we propose a well-designed prompt to guide the diffusion model to generate transferable adversarial examples. This local attack may cause inconsistency between the perturbed object and the background in adversarial examples. An FFT-based edge smoother is utilized to ensure seamless blending of the edges. ObjectAdv achieves an average ASR of 99.2% in white-box test on the ImageNet-compatible dataset, and outperforms existing methods on defense performance (+5%) and image quality metrics, e.g., SSIM of 0.9140 (+0.1048) and FID of 25.63 (-19.27).
Xing Yang 0004, Haoqi Gao, Anjie Peng, Hui Zeng 0002
AAAI5
2026 Targeted attack via adversarial patch outside bounding box
Kang Deng, Qixiang Chen, Yu Zhang 0091, Shenjian Gong, Anjie Peng, Xing Yang 0004, Defu Lian
Pattern Recognit.7
2026 Improving adversarial transferability via semantic-style joint expectation perturbations
Bingwen Wang, Kang Deng, Anjie Peng
Pattern Recognit.7
2026 Enhancing heterogeneous model transferability via constrained möbius attack
Hui Zeng 0002, Anjie Peng
Pattern Recognit.3
2025 Everywhere Attack: Attacking Locally and Globally to Boost Targeted Transferability
abstract
Adversarial examples’ (AE) transferability refers to the phenomenon that AEs crafted with one surrogate model can also fool other models. Notwithstanding remarkable progress in untargeted transferability, its targeted counterpart remains challenging. This paper proposes an everywhere scheme to boost targeted transferability. Our idea is to attack a victim image both globally and locally. We aim to optimize ‘an army of targets’ in every local image region instead of the previous works that optimize a high-confidence target in the image. Specifically, we split a victim image into non-overlap blocks and jointly mount a targeted attack on each block. Such a strategy mitigates transfer failures caused by attention inconsistency between surrogate and victim models and thus results in stronger transferability. Our approach is method-agnostic, which means it can be easily combined with existing transferable attacks for even higher transferability. Extensive experiments on ImageNet demonstrate that the proposed approach universally improves the state-of-the-art targeted attacks by a clear margin, e.g., the transferability of the widely adopted Logit attack can be improved by 28.8%-300%. We also evaluate the crafted AEs on a real-world platform: Google Cloud Vision. Results further support the superiority of the proposed method.
Hui Zeng 0002, Sanshuai Cui, Biwei Chen, Anjie Peng
AAAI4
2025 Two Heads Are Better Than One: Averaging along Fine-Tuning to Improve Targeted Transferability
abstract
With much longer optimization time than that of untargeted attacks notwithstanding, the transferability of targeted attacks is still far from satisfactory. Recent studies reveal that fine-tuning an existing adversarial example (AE) in feature space can efficiently boost its targeted transferability. However, existing fine-tuning schemes only utilize the endpoint and ignore the valuable information in the fine-tuning trajectory. Noting that the vanilla fine-tuning trajectory tends to oscillate around the periphery of a flat region of the loss surface, we propose averaging over the fine-tuning trajectory to pull the crafted AE towards a more centered region. We compare the proposed method with existing fine-tuning schemes by integrating them with state-of-the-art targeted attacks in various attacking scenarios. Experimental results uphold the superiority of the proposed method in boosting targeted transferability. The code is available at github.com/zengh5/Avg_FT.
Hui Zeng 0002, Sanshuai Cui, Biwei Chen, Anjie Peng
ICASSP4
2025 Boosting Adversarial Transferability by Constructing Adversarial Trajectories
abstract
Deep neural networks (DNNs) are susceptible to adversarial examples (AEs), which are crafted by adding human-imperceptible perturbations to benign images. Although many existing adversarial attacks have achieved great surrogate, white-box model attack performance, they exhibit low transferability. In this work, we emphasize that existing input transformation-based attacks, which linearly mix the input image with images from other categories, induce significant semantic shifts and lack sufficient input diversity, leading to inaccurate update directions. To overcome the pitfall, we propose a new attack method for constructing multiple adversarial trajectories (MAT). Specifically, MAT achieves the intent of the mixing strategy by introducing targeted perturbations instead of relying on input transformation to obtain multiple data points that are closer to the decision boundary for gradient computation. Comprehensive experiments demonstrate our method’s effectiveness. We also show that MAT is highly flexible and can seamlessly integrate with existing transfer methods. Code is available at: github.com/britney-code/MAT-Attack.
Sanshuai Cui, Anjie Peng, Hui Zeng 0002, Rong Wei
ICME3
2025 Orthogonal Frequency-Spatial Gradient Fusion Attack for Boosting Adversarial Transferability
Qingpei Zhao, Anjie Peng, Hui Zeng 0002
ICONIP (1)5
2025 FCA-MARS: Full-Coverage Adversarial Camouflage for Few-Shot Ships with Multi-Angle Attack Robustness
abstract
Adversarial attacks against ship targets are urgently needed to enhance naval stealth capabilities but face dual bottlenecks of data scarcity and physical implementation. Existing datasets fail to cover multi-view characteristics of complex aquatic environments, which restricts the optimization of adversarial textures. Compared to current mature vehicle adversarial attacks, traditional attack methods prove ineffective when applied to ships due to discontinuous surfaces (e.g., containers/decks) and dynamic waterborne interference (illumination fluctuations and wide viewing-angle variations). To address these issues, we proposed FCA-MARS (Full-Coverage Adversarial Camouflage for Few-Shot Ships with Multi-Angle Attack Robustness), a framework that combines Full-Coverage Adversarial rendering with marine-specific EOT optimization. First, we constructed the field's first high-fidelity ship dataset using Unreal Engine 4(UE4), containing over$\text{1 4, 0 0 0}$multi-scenario samples to overcome few-shot limitations. Second, we integrated differentiable rendering with the Expectation Over Transformation (EOT) framework. This integration achieved geometry-adaptive texture mapping on discontinuous surfaces while maintaining robustness against environmental disturbances. Experimental validation demonstrated strong results: an$\text{8 3. 4 \%}$attack success rate (ASR) in digital tests, 86.5% ASR in physical simulations, and a 98.25% close-range evasion rate. This approach established a physically deployable solution for maritime defense by solving the persistent challenge of camouflaging complex discontinuous geometries.
Yaoran Wang, Haoqi Gao, Anjie Peng, Hui Zeng 0002, Xing Yang 0004
ICPADS4
2025 FCSA: A Multi-Domain Enhancement Method for Improving Adversarial Transferability
abstract
Transfer-based adversarial attacks craft perturbations on a surrogate and transfer them to black-box models, yet most prior methods diversify perturbations in only one domain, spatial or frequency, which limits overall transferability. We introduce Frequency-Channel-Structure Augmentation, FCSA, a multi-domain attack that jointly enriches perturbations in the frequency, color-channel, and spatial-structure spaces. FCSA couples lightweight frequency masking with Channel Fusion, a stochastic linear mixing across RGB channels, and MultiPattern Structured Perturbation that injects multi-orientation and multi-scale texture fields. The branch gradients are fused with data-dependent nonnegative weights normalized to sum to one, yielding a single update direction and reducing inter-branch conflict. By expanding surrogate diversity across complementary domains, FCSA produces adversarial examples with stronger black-box transfer. Extensive experiments demonstrate that our method achieves strong transferability on both standard and defended models. The method can be combined with a wide range of existing techniques to further improve the transferability of adversarial examples. Our code is available at https://github.com/zhangyuguai/FCSA-Attack.
Shengyu Xiong, Anjie Peng, Hui Zeng 0002, Shujian Liao, Fudie Ai, Wanli Dong
ICPADS2
2025 S-DiffAdv: Enhancing Unrestricted Adversarial Attack via Sparse Diffusion
abstract
Unrestricted adversarial attacks are a class of attacks that deceive deep learning models by generating unconstrained perturbations. In existing attack methods, complex perturbations tend to overfit on surrogate models, which reduces their transferability across different tasks. To address this issue, a sparsity constraint is introduced within the diffusion model framework (S-DiffAdv) to limit the region of perturbation generation, ensuring that it focuses on critical regions that significantly impact classification. By incorporating sparsity constraint in the latent space of the diffusion model, necessary modifications are made directly to the relevant regions, resulting in high-quality, sparse adversarial examples with strong transferability. By sampling multiple examples and optimizing the perturbations, the method achieves an optimal balance between attack success rate and image quality. Extensive experiments and visualizations demonstrate that S-DiffAdv can generate high-quality and visually imperceptible adversarial examples in critical local regions. Compared to existing attack methods, it significantly improves both the attack success rate and transferability, while also optimizing computational efficiency.
Anjie Peng, Shujian Liao, Wanli Dong
IJCNN2
2025 DiffIVF: Infrared-Visible Image Fusion via Diffusion Models for Object Detection
Siyu Hu, Anjie Peng, Hui Zeng 0002, Xing Yang 0004
PRCV (8)3
2025 PDAttack: Enhancing Transferability of Unrestricted Adversarial Examples via Prompt-Driven Diffusion
Siyu Hu, Anjie Peng, Hui Zeng 0002, Xing Yang 0004
PRCV (8)3
2025 HFCNet: A Spatial-Frequency Collaborative Multi-scale Network for Infrared Small Target Detection
Fudie Ai, Wanli Dong, Shujian Liao, Shengyu Xiong, Anjie Peng
PRICAI6
2025 Directional Gradient Attacks for Inducing Controllable Detection Errors in DETR-Based Models
Shujian Liao, Shengyu Xiong, Fudie Ai, Wanli Dong, Anjie Peng, Hui Zeng 0002
PRICAI (5)6
2025 Infrared Vehicle Adversarial Patch: Physical Attacking Infrared Vehicle Detectors
abstract
The growing dependence of autonomous vehicles on infrared thermal imaging for adverse-condition perception has heightened the security importance of infrared vehicle detectors. This work proposes the Infrared Vehicle Adversarial Patch (InfVAP), a physically realizable attack framework targeting these detectors. Addressing the dual challenges of limited prior research and complex vehicle geometry, our solution introduces: (1) Pixel-level attack localization using DeepLab-v3+ segmentation to ensure precise patch placement; (2) An improved Particle Swarm Optimization (PSO) algorithm with dynamic parameter adaptation and shape optimization to enhance attack effectiveness; (3) Expectation Over Transformation (EOT)-based robustness enhancement against real-world perturbations; and (4) A top-K confidence suppression loss (K=1000) for maximum attack potency. Extensive evaluations on the FLIR ADAS V2 dataset demonstrate that InfVAP achieves state-of-the-art performance: 93.93% digital Attack Success Rate (ASR) and 80.2% physical ASR at distances of 12 meters. Comprehensive ablation studies prove all components are statistically significant, with PSO optimization contributing most to attack potency.
Hanyang Chen, Wanli Dong, Jiachuan Fan, Xiaoming Gao, Anjie Peng, Xingdi Fan
SMC5
2024 Enhancing Targeted Transferability VIA Feature Space Fine-Tuning
abstract
Adversarial examples (AEs) have been extensively studied due to their potential for privacy protection and inspiring robust neural networks. Yet, making a targeted AE transferable across unknown models remains challenging. In this paper, to alleviate the overfitting dilemma common in an AE crafted by existing simple iterative attacks, we propose fine-tuning it in the feature space. Specifically, starting with an AE generated by a baseline attack, we encourage the features conducive to the target class and discourage the features to the original class in a middle layer of the source model. Extensive experiments demonstrate that only a few iterations of fine-tuning can boost existing attacks' targeted transferability nontrivially and universally. Our results also verify that the simple iterative attacks can yield comparable or even better transferability than the resource-intensive methods, which rest on training target-specific classifiers or generators with additional data. The code is available at: github.com/zengh5/TA_feature_FT.
Hui Zeng 0002, Biwei Chen, Anjie Peng
ICASSP3
2024 A Whale Falls, All Thrive: Mitigating Attention Gap to Improve Adversarial Transferability
Biwei Chen, Anjie Peng, Hui Zeng 0002
ICPR (22)3
2023 Boosting Transferability of Adversarial Example via an Enhanced Euler's Method
abstract
Adversarial examples are intentionally designed images to force convolution neural networks to give error classification outputs. Existing attacks have constructed transferable adversarial examples from the base attack algorithm, data augmentation, ensemble model, etc. Nevertheless, under the black-box case especially facing defense models, the transferability of adversarial examples still needs to be improved. In this paper, we try to develop a better base attack to boost the transferability of adversarial examples. Through analyzing the baseline gradient-based attacks, we found their iterative procedures of updating gradients are similar to numerical Euler’s methods. From the perspective of numerical analysis, we employ an enhanced Euler’s method, with less approximate errors and thus more accurate, to search a better approximate optimal solution to construct a more transferable gradient-based attack. To this end, we apply two-step gradient calculations of the enhanced Euler’s method to correct gradient descent directions. As a base attack, our attacks can be easily integrated with data augmentations and ensemble model augmentations. Experimental results show the proposed augmented attack significantly improves the transferability of adversarial examples and achieves an average attack success rate at least 3% higher than state-of-the-arts under black-box settings with defense mechanisms.
Anjie Peng, Hui Zeng 0002, Wenxin Yu 0001, Xiangui Kang
ICASSP1
2023 Make Your Enemy Your Friend: Improving Image Rotation Angle Estimation with Harmonics
abstract
It is well known that rotation introduces periodic artifacts into the resulting image. By measuring such periodicities, the rotation angle θ can be estimated from the rotated image without the availability of the original unrotated image. However, existing methods suffer from harmonics, especially when θ is small. This paper revisits the harmonics caused by rotation in the cyclic spectrum and points out that such harmonics can help our rotation angle estimation if used effectively. Based on this observation, we propose aggregating the magnitudes of the candidate peaks and their harmonics in detecting the rotation-specific peak. Both theoretical analyses and experimental results demonstrate the advantage of the proposed scheme over previous methods.
Morteza Darvish Morshedi Hosseini, Anjie Peng, Hui Zeng 0002, Miroslav Goljan
ICASSP3
2023 An Enhanced Neuron Attribution-Based Attack Via Pixel Dropping
abstract
Convolutional neural networks (CNNs) are vulnerable to adversarial examples (AEs). Existing feature-level attacks explore the neuron importance to distort the intrinsic object-aware features which are shareable among different CNNs, thus achieving great performance in transferability. In this work, we propose an enhanced neuron attribution-based attack via pixel dropping (ENAA) and try to increase the number of positive neurons to distort the object-aware features more fully than NAA. Specifically, when computing neuron attribution, we use a pixel dropping scheme to expand the regions where the source model pays attention to the image. Our ENAA can make the target model shift the attention regions of AEs far away from those of clean images. Experimental results validate that the proposed method outperforms the state-of-the-art feature-level attacks both in white-box and black-box settings.
Anjie Peng, Hui Zeng 0002, Wenxin Yu 0001
ICIP2
2023 Adversarial Example Detection Bayesian Game
abstract
Despite the increasing attack ability and transferability of adversarial examples (AE), their security, i.e., how unlikely they can be detected, has been ignored more or less. Without the ability to circumvent popular detectors, the chance that an AE successfully fools a deep neural network is slim. This paper gives a game theory analysis of the interplay between an AE attacker and an AE detection investigator. Taking the perspective of a third party, we introduce a game theory model to evaluate the ultimate performance when both the attacker and the investigator are aware of each other. Further, a Bayesian game is adopted to address the information asymmetry in practice. Solving the mixed-strategy Nash equilibrium of the game, both parties’ optimal strategies are obtained, and the security of AEs can be evaluated. We evaluate four popular attacks under a two-step test on ImageNet. The results may throw light on how a farsighted attacker or investigator will act in this adversarial environment. Our code is available at: https://github.com/zengh5/AED_BGame.
Hui Zeng 0002, Biwei Chen, Kang Deng, Anjie Peng
ICIP4
2023 Enhancing Targeted Transferability Via Suppressing High-Confidence Labels
abstract
While extensive studies have pushed the limit of the transferability of untargeted attacks, transferable targeted attacks remain extremely challenging. This paper finds that the labels with high confidence in the source model are also likely to retain high confidence in the target model. This simple and intuitive observation inspires us to carefully deal with the high-confidence labels in generating targeted adversarial examples for better transferability. Specifically, we integrate the untargeted loss function into the targeted attack to push the adversarial examples away from the original label while approaching the target label. Furthermore, we suppress other high-confidence labels in the source model with an orthogonal gradient. We validate the proposed scheme by mounting targeted attacks on the ImageNet dataset. Experiments on various scenarios show that our proposed scheme improves the state-of-the-art targeted attacks in transferability. Our code is available at: https://github.com/zengh5/Transferable_targeted_attack.
Hui Zeng 0002, Biwei Chen, Anjie Peng
ICIP4
2023 Fooling Downstream Classifiers via Attacking Contrastive Learning Pre-trained Models
Chenggang Li, Anjie Peng, Hui Zeng 0002, Wenxin Yu 0001
ICONIP (12)2
2023 Detecting Adversarial Examples via Classification Difference of a Robust Surrogate Model
Anjie Peng, Kang Deng, Hui Zeng 0002, Wenxin Yu 0001
ICONIP (12)1
2023 Neuron Attribution-Based Attacks Fooling Object Detectors
Guoqiang Shi, Anjie Peng, Hui Zeng 0002, Wenxin Yu 0001
ICONIP (13)2
2023 Towards Undetectable Adversarial Examples: A Steganographic Perspective
Hui Zeng 0002, Biwei Chen, Rongsong Yang, Chenggang Li, Anjie Peng
ICONIP (4)5
2023 Ignored Details in Eyes: Exposing GAN-Generated Faces by Sclera
Anjie Peng, Hui Zeng 0002
ICONIP (5)2
2023 An Enhanced Transferable Adversarial Attack Against Object Detection
abstract
In this work, we propose an enhanced adversarial attack based on DAG, to improve the transferability of adversarial example to fool CNN-based object detectors. DAG achieves excellent performance under white-box settings via attacking the detection head, but has poor transferability under black-box cases. We jointly attack the feature map of backbone and the detection head to improve the transferability. Because, we think the attack against high-level feature of backbone can transfer to disturb other homogeneous CNN-based backbones. To this end, we optimize the combination of feature loss of backbone and classification loss of region proposals to generate adversarial examples. Extensive experiments on PASCAL VOC and COCO datasets demonstrate that our attack can transfer to attack the detector with different backbone or different pipelines even under defense situations, and has achieved superior transferability than state-of-the-arts.
Guoqiang Shi, Anjie Peng, Hui Zeng 0002
IJCNN3
2023 Towards infrared human pose estimation via Transformer
abstract
Due to the limited color information and low hierarchy present in infrared images, traditional CNN-based pose estimation networks designed for visible light often exhibit weak performance when applied to infrared images for human pose estimation. In order to overcome the inherent shortcomings of infrared images and improve the accuracy of human pose estimation in this domain, we propose a novel model called FEPose. Our model incorporates the Transformer Encoder architecture to establish correlation dependencies in the infrared image space, enhancing the network's ability to sense spatial distance and mitigating the impact of low hierarchy on detection accuracy. Additionally, we introduce a specially-designed FELayer layer for infrared images, which enhances the network's response to human grayscale values while reducing the impact of background interference factors. To evaluate the effectiveness of our model, we conduct experiments on a self-built IR multi-person pose estimation dataset comprising 7621 training instances and 1082 test instances. Our most complex model achieves a PCKm of 77.5, while the simplified model achieves 75.1 PCKm.
Zhilei Zhu, Wanli Dong, Xiaoming Gao, Anjie Peng
IJCNN4
2023 DepthWise Attention: Towards Individual Channels Attention
abstract
Human keypoints detection require the capture of long-range spatial constraints and the fusion of channels information. Many studies adopt attention mechanisms to generate feature weights, thereby enhancing the information interaction capability and improving the accuracy of keypoints detection. However, most attention mechanisms currently in use redun-dantly fuse information across all channel levels, which not only increases the computational cost of the network but also weakens the feature differences between different keypoints, affecting the prediction of heatmaps. In this study, we propose a plug-and play attention module based on separate convolution, called DWA module, which avoids the redundant use of information from different channels and improves the network's ability to capture long-range spatial relationships. Additionally, we adopt a novel feature compression method to reduce errors in single-dimensional compression. Experimental results indicate that our DWA model performs well on COCO and MPII datasets, achieving good accuracy improvements with relatively small computational costs
Zhilei Zhu, Wanli Dong, Xiaoming Gao, Anjie Peng
ISCC4
2022 How Secure Are The Adversarial Examples Themselves?
abstract
Existing adversarial example generation algorithms mainly consider the success rate of spoofing target model, but pay little attention to its own security. In this paper, we propose the concept of adversarial example security as how unlikely themselves can be detected. A two-step test is proposed to deal with the adversarial attacks of different strengths. Game theory is introduced to model the interplay between the attacker and the investigator. By solving Nash equilibrium, the optimal strategies of both parties are obtained, and the security of the attacks is evaluated. Five typical attacks are compared on the ImageNet. The results show that a rational attacker tends to use a relatively weak strength. By comparing the ROC curves under Nash equilibrium, it is observed that the constrained perturbation attacks are more secure than the optimized perturbation attacks in face of the two-step test. The proposed framework can be used to evaluate the security of various potential attacks and further the research of adversarial example generation/detection.
Hui Zeng 0002, Kang Deng, Biwei Chen, Anjie Peng
ICASSP4
2022 An Enhanced Transferable Adversarial Attack of Scale-Invariant Methods
abstract
Scale-invariant method (SIM) is a state-of-the-art model augmentation method to improve the transferability of adversarial examples. However, we find that SIM is easily affected by the scaling operation with small scaling factors, and cannot stably enhance the transferability of the base attack. In this paper, we propose an enhanced transferable attack based on SIM. To alleviate the instability of SIM caused by the scaled copy which does not satisfy scale-invariance, we propose to ensemble logit-outputs of scale copies of the input image, rather than ensemble the gradients, to form an ensemble attack that generates transferable adversarial images from multiple models of the original CNN model. Compared with the existing ensemble methods, our method is fast yet effective and can be easily integrated into the gradient-based attacks. The experimental results show that the proposed integrated EL-NI-FGSM attack stably improves the transferability of NI-FGSM, and outperforms SI-NI-FGSM, achieving >8% higher of attack success rate for both white-box and black-box attacks on CIFAR-10.
Anjie Peng, Rong Wei, Wenxin Yu 0001, Hui Zeng 0002
ICIP2
2022 Countering the Anti-detection Adversarial Attacks
Anjie Peng, Chenggang Li, Xiaofang Huang, Hui Zeng 0002, Wenxin Yu 0001
ICONIP (4)1
2022 Effect of Image Down-sampling on Detection of Adversarial Examples
Anjie Peng, Chenggang Li, Hui Zeng 0002, Wenxin Yu 0001
ICONIP (4)1
2022 Towards Human Keypoint Detection in Infrared Images
Zhilei Zhu, Wanli Dong, Xiaoming Gao, Anjie Peng, Yuqin Luo
ICONIP (5)4
2022 A deep learning approach with data augmentation for median filtering forensics
Wanli Dong, Hui Zeng 0002, Xiaoming Gao, Anjie Peng
Multim. Tools Appl.5
2021 Detecting C&W Adversarial Images Based on Noise Addition-Then-Denoising
abstract
In this paper, we focus on detecting adversarial images generated by the white-box adversarial attack proposed by Carlini and Wagner (C&W for short). The C&W attack is one of the most powerful attacks which has achieved nearly 100% attack success rates for fooling deep neural network (DNN) yet keeping the visual quality of adversarial image. Considering that the C&W attack optimizes a loss function based on the logit layer of DNN to find adversarial perturbations, we first add Gaussian noise to destroy the perturbations. For the high-confidence adversarial image, a strong Gaussian noise is employed. In order to reduce the impact of such strong noise on a legitimate image, a FFDNet filter is utilized to execute denoising. By comparing the prediction on a test image with that on its noise added-then-denoised version, the proposed method detects the test image as adversarial when the predictions are different. The experiments on ImageNet show that the proposed method can effectively detect targeted and un-targeted C&W adversarial images generated on famous models: Resnet-50, Inception v2, and Inception v3, achieving higher F1 scores than the-state-of-art.
Kang Deng, Anjie Peng, Wanli Dong, Hui Zeng 0002
ICIP2
2020 Gradient-Based Adversarial Image Forensics
Anjie Peng, Kang Deng, Shenghai Luo, Hui Zeng 0002, Wenxin Yu 0001
ICONIP (2)1
2020 ISO Setting Estimation Based on Convolutional Neural Network and its Application in Image Forensics
Hui Zeng 0002, Kang Deng, Anjie Peng
IWDW3
2020 Exposing image splicing with inconsistent sensor noise levels
Hui Zeng 0002, Anjie Peng, Xiaodan Lin
Multim. Tools Appl.2
2016 A Multi-purpose countermeasure against image anti-forensics using autoregressive model
Hui Zeng 0002, Xiangui Kang, Anjie Peng
Neurocomputing3
2015 Countering anti-forensics of image resampling
abstract
Image resampling leaves behind periodical artifacts which are used as fingerprints for the forensics. A knowledgeable anti-forensic method erases such artifacts by irregular sampling. We observe that the irregular sampling followed by interpolation causes changes in local linear correlations, and propose a novel method to detect the anti-forensic method of resampling via partial autocorrelation coefficients. Experimental results on a large set of images show that the proposed method could effectively detect the anti-forensics of resampling with a low dimensional feature set.
Anjie Peng, Hui Zeng 0002, Xiaodan Lin, Xiangui Kang
ICIP1
2013 Robust Median Filtering Forensics Using an Autoregressive Model
abstract
In order to verify the authenticity of digital images, researchers have begun developing digital forensic techniques to identify image editing. One editing operation that has recently received increased attention is median filtering. While several median filtering detection techniques have recently been developed, their performance is degraded by JPEG compression. These techniques suffer similar degradations in performance when a small window of the image is analyzed, as is done in localized filtering or cut-and-paste detection, rather than the image as a whole. In this paper, we propose a new, robust median filtering forensic technique. It operates by analyzing the statistical properties of the median filter residual (MFR), which we define as the difference between an image in question and a median filtered version of itself. To capture the statistical properties of the MFR, we fit it to an autoregressive (AR) model. We then use the AR coefficients as features for median filter detection. We test the effectiveness of our proposed median filter detection techniques through a series of experiments. These results show that our proposed forensic technique can achieve important performance gains over existing methods, particularly at low false-positive rates, with a very small dimension of features.
Xiangui Kang, Matthew C. Stamm, Anjie Peng, K. J. Ray Liu
IEEE Trans. Inf. Forensics Secur.3
2012 Scalable Lossy Compression for Pixel-Value Encrypted Images
abstract
Compression of encrypted data draws much attention in recent years due to the security concerns in a service oriented environment such as cloud computing. We propose a scalable lossy compression scheme for images having their pixel value encrypted with a standard stream cipher. The encrypted data are simply compressed by transmitting a uniformly sub sampled portion of the encrypted data and some bit-planes of another uniformly sub sampled portion of the encrypted data. With a proposed content adaptive interpolation prediction method with side information, at the receiver side, a decoder performs content adaptive interpolation based on the decrypted partial information, where the received bit-plane information serves as the side information that reflects the image edge information, making the image reconstruction more precise. When more bit-planes are transmitted, higher quality of the decompressed image can be achieved. The experimental results show that our proposed scheme achieves much better performance than the existing lossy compression scheme for pixel value encrypted images, and also similar performance as the state-of-the-art lossy compression for pixel permutation based encrypted images. In addition, our proposed scheme has the following advantages: at the decoder side, no computationally intensive iteration and no additional public orthogonal matrix is needed. It works well for both smooth and texture-rich images.
Xiangui Kang, Xianyu Xu, Anjie Peng, Wenjun Zeng 0001
DCC3
2012 Robust Median Filtering Detection Based on Filtered Residual
Anjie Peng, Xiangui Kang
IWDW1