Chenyu Zhang 0003

dblp:136/1220-3 · DBLP profile ↗
← Back
9ranked-venue papers
2as first author
9since 2021 · last 2026
0000-0001-7822-2517ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 8 · 2 first-author · 8 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 4 since 2021
YearPublicationVenuePosition
2026 Reason2Attack: Jailbreaking Text-to-Image Models via LLM Reasoning
abstract
Text-to-Image (T2I) models typically deploy safety mechanisms to prevent the generation of sensitive images. Unfortunately, recent jailbreaking attack methods manually design instructions for the LLM to generate adversarial prompts, which effectively exposing safety vulnerabilities of T2I models. However, existing methods have two limitations: 1) relying on manually exhaustive strategies for designing adversarial prompts, lacking a unified framework, and 2) requiring numerous queries to achieve a successful attack, limiting their practical applicability. To address this issue, we propose Reason2Attack~(R2A), which aims to enhance the effectiveness and efficiency of the LLM in jailbreaking attacks. Specifically, we first use Frame Semantics theory to systematize existing manually crafted strategies and propose a unified generation framework to generate CoT adversarial prompts step by step. Following this, we propose a two-stage LLM reasoning training framework guided by the attack process. In the first stage, the LLM is fine-tuned with CoT examples generated by the unified generation framework to internalize the adversarial prompt generation process grounded in Frame Semantics. In the second stage, we incorporate the jailbreaking task into the LLM's reinforcement learning process, guided by the proposed attack process reward function that balances prompt stealthiness, effectiveness, and length, enabling the LLM to understand T2I models and safety mechanisms. Extensive experiments on various T2I models with safety mechanisms, and commercial T2I models, show the superiority and practicality of R2A.
Chenyu Zhang 0003, Lanjun Wang, Yiwen Ma, Wenhui Li 0001, Guoqing Jin, Anan Liu
AAAI1
2026 T2I-RiskyPrompt: A Benchmark for Safety Evaluation, Attack, and Defense on Text-to-Image Model
abstract
Using risky text prompts, such as pornography and violent prompts, to test the safety of text-to-image (T2I) models is a critical task. However, existing risky prompt datasets are limited in three key areas: 1) limited risky categories, 2) coarse-grained annotation, and 3) low effectiveness. To address these limitations, we introduce T2I-RiskyPrompt, a comprehensive benchmark designed for evaluating safety-related tasks in T2I models. Specifically, we first develop a hierarchical risk taxonomy, which consists of 6 primary categories and 14 fine-grained subcategories. Building upon this taxonomy, we construct a pipeline to collect and annotate risky prompts. Finally, we obtain 6,432 effective risky prompts, where each prompt is annotated with both hierarchical category labels and detailed risk reasons. Moreover, to facilitate the evaluation, we propose a reason-driven risky image detection method that explicitly aligns the MLLM with safety annotations. Based on T2I-RiskyPrompt, we conduct a comprehensive evaluation of eight T2I models, nine defense methods, five safety filters, and five attack strategies, offering nine key insights into the strengths and limitations of T2I model safety. Finally, we discuss potential applications of T2I-RiskyPrompt across various research fields.
Chenyu Zhang 0003, Tairen Zhang, Lanjun Wang, Rui-dong Chen, Wenhui Li 0001, Anan Liu
AAAI1
2025 TRCE: Towards Reliable Malicious Concept Erasure in Text-to-Image Diffusion Models
Rui-dong Chen, Honglin Guo, Lanjun Wang, Chenyu Zhang 0003, Weizhi Nie, Anan Liu
ICCV4
2025 Culture-based Adversarial Attack on Text-to-Image Models
abstract
Text-to-image (T2I) models aim to output high-quality images based on the input prompt. It commonly incorporates safety filters to prevent the generation of sensitive images. In this study, we aim to reveal the safety vulnerabilities of black-box T2I models in a real-world scenario. To address the challenges of bypassing filters and mitigating the trade-off between stealthiness and effectiveness, we investigate the concepts from Semiotics and apply cultural elements in the design of adversarial prompts. Specifically, we propose CAAM, a Culture-based Adversarial Attack on T2I Models with a generation module, which collaborates with multiple LLM-based agents to generate fluent adversarial prompts, and a feedback module, which provides feedback to compromise the stealthiness and effectiveness. Extensive experiments with open-source and commercial T2I models are conducted to demonstrate the effectiveness of our method. This paper includes model-generated content that may contain offensive or distressing material.
Fuyi Yang, Chenyu Zhang 0003, Lanjun Wang
ICME2
2025 Toward Chinese Food Understanding: A Cross-Modal Ingredient-Level Benchmark
abstract
Although there are several food-level benchmarks for food-related learning, the lack of fine-grained ingredient annotation significantly impedes progress in food scene understanding. In this study, we focus on Chinese food understanding which involves fine-grained ingredient detection and cross-modal ingredient retrieval. Specifically, to support studies on Chinese food understanding, we build the first cross-modal ingredientlevel dataset called CMIngre, which contains 8,001 image-text pairs from three different sources, i.e. dishes, recipes, and usergenerated content, covering 429 distinct ingredients and 95,290 bounding boxes. Based on CMIngre, we evaluate the performance of traditional CNN-based detection algorithms and transformerbased pre-trained large models for ingredient detection. We also propose baseline methods for the cross-modal ingredient retrieval task in both the end-to-end and two-stage settings. Extensive experiments on CMIngre demonstrate the effectiveness of our proposed methods on food understanding
Lanjun Wang, Chenyu Zhang 0003, Anan Liu, Bo Yang 0055, Mingwang Hu, Xinran Qiao, Jianlin He, Qiang Liu 0040
IEEE Trans. Multim.2
2024 Multi-Modal Meta-Transfer Fusion Network for Few-Shot 3D Model Classification
Heyu Zhou, Anan Liu, Chenyu Zhang 0003, Qianyi Zhang, Mohan Kankanhalli
Int. J. Comput. Vis.3
2024 Dual-Stage Uncertainty Modeling for Unsupervised Cross-Domain 3D Model Retrieval
abstract
Unsupervised cross-domain 3D model retrieval aims to retrieve unlabeled 3D models (target domain) using labeled 2D images (source domain). Domain adaptation approaches have shown impressive performance for cross-domain 3D model retrieval. However, conventional methods typically represent samples from different domains as deterministic points, overlooking the diversity in sample characteristics and relationships. These approaches lead to challenges in achieving a robust representation of both samples and categories. To address above challenges, we propose a dual-stage uncertainty modeling (DSUM) for unsupervised cross-domain 3D model retrieval, which utilizes Gaussian distribution to effectively model the uncertainty characteristics in both sample and class and obtain the robust and domain-invariant representations. Specifically, in the multi-view uncertainty encoding stage, we discard the conventional pooling operations and utilize the uncertainty modeling among multiple views to fuse the common and specific information of 2D images and 3D models. In the cross-domain feature alignment stage, we adopt the Gaussian distribution of samples belonging to the same category, which can well maintain the sample diversity as well as facilitate to eliminate the domain discrepancy. Our method achieves improvements of 2.61% and 2.65% in terms of FT on two cross-domain datasets, respectively, verifying its superiority through extensive qualitative and quantitative experiments.
Wenhui Li 0001, Houran Zhou, Chenyu Zhang 0003, Weizhi Nie, Xuanya Li, Anan Liu
IEEE Trans. Multim.3
2023 Prototype-based semantic consistency learning for unsupervised 2D image-based 3D shape retrieval
Anan Liu, Chenyu Zhang 0003, Wenhui Li 0001, Xuanya Li
Multim. Syst.3
2022 Self-Supervised Auxiliary Domain Alignment for Unsupervised 2D Image-Based 3D Shape Retrieval
abstract
Unsupervised 2D image-based 3D shape retrieval aims to match the similar 3D unlabeled shapes when given a 2D labeled sample. Although a lot of methods have made a certain degree of progress, the performance of this task is still restricted due to the lack of target labels resulting in tremendous domain gap. In this paper, we aim to explore the discriminative representation of the unlabeled target 3D shapes and facilitate the procedure of domain adaptation by taking full advantage of multi-view information. To achieve the above goals, we propose an effective self-supervised auxiliary domain alignment (SADA) for unsupervised 2D image-based 3D shape retrieval. SADA mainly contains multi-view guided self-supervised feature learning and two auxiliary domain alignments, including intermediate domain alignment and multi-domain alignment. Firstly, we group multiple views of each 3D shape into two sub-target domains based on the view similarities and regard each other as the constraint to optimize the feature learning in an unsupervised manner. To reduce the difficulty of directly aligning the domain discrepancy, we combine the source labeled samples and target samples (pseudo labels) with the same category to generate an intermediate domain, which translates the source-target alignment into source-intermediate and intermediate-target alignments. Moreover, to explore the inner characteristics of target 3D shapes and provide more clues for better adaptation, multi-domain alignment is proposed to convert the source and single target domain alignment to the source and multiple target domain (one target domain and two sub-target domains) alignments. The adversarial training and semantic alignment are employed to fully excavate the relations between source domain and multiple target domains. Experiments on two challenging datasets show that the proposed method achieves competing performance in the unsupervised 2D image-based 3D shape retrieval task.
Anan Liu, Chenyu Zhang 0003, Wenhui Li 0001, Xingyu Gao 0001, Zhengya Sun, Xuanya Li
IEEE Trans. Circuits Syst. Video Technol.2