Xupeng Wang 0001

dblp:141/0617-1 · DBLP profile ↗
← Back
24ranked-venue papers
4as first author
16since 2021 · last 2026
0000-0002-4160-8552ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 13 · 2 first-author · 9 since 2021Artificial intelligence and machine learning · 6 · 2 first-author · 5 since 2021Systems, architecture and hardware · 2 · 2 since 2021Computer networks · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Joint Adversarial Attack: An Effective Approach to Evaluate Robustness of 3D Object Tracking
Riran Cheng, Xupeng Wang 0001, Ferdous Sohel
Pattern Recognit.2
2025 LiDAR-SPD: Improving Adversarial Robustness of 3D Object Detection via Spherical Projection and Diffusion
abstract
The advancements in light detection and ranging (LiDAR) sensors and 3D object detection techniques have boosted their deployment in a wide range of applications, autonomous driving, in particular. However, it has been demonstrated that 3D object detection models based on deep neural networks exhibit vulnerabilities and tend to be susceptible to adversarial attacks. Nonetheless, there exists a scarcity of defensive strategies explicitly tailored for mitigating adversarial attacks on 3D object detection. In this paper, we introduce LiDAR-SPD, a novel approach to defend against adversarial attacks targeting LiDAR-based 3D object detectors. Specifically, a spherical purification unit is designed, which encompasses two pivotal processes: spherical projection and spherical diffusion. The former leverages a spatial projection strategy to eliminate adversarial point clouds inserted in occluded regions, while the latter employs a diffusion model to regenerate points, rendering it closer to a pristine LiDAR scene. Comprehensive experiments conducted on the KITTI dataset demonstrate that our proposed LiDAR-SPD method effectively thwarts various types of adversarial attacks, decreasing the attack success rates against 3D object detectors by 60%.
Mumuxin Cai, Xupeng Wang 0001, Ferdous Sohel
ICASSP2
2025 Superpoints Guided Local Explanation For Deep 3D Trackers
abstract
3D object tracking has become a popular research topic because of its broad application prospects. However, it remains a challenging task to advance the trustworthiness of deep trackers, caused by the complex network structure of black-box models. In this paper, a local explanation method for 3D object tracking is proposed, which trains an interpretable surrogate model to reveal the contribution of superpoints in the search area. Specifically, local points of the search area with comparable geometric features are aggregated as superpoints, which serve as the fundamentals of the explanation. In contrast to the commonly used voxels, superpoints capture semantic information of the search area, and facilitate an intuitive understanding of the predictions. In addition, a distance-aware masking strategy is proposed for generating the sample set to train a surrogate model, which corresponds to latent contributions of superpoints to predictions and improves the efficacy of the explanation. Experiments have demonstrated that the proposed explainability approach can effectively provide explanations to deep tracking models.
Riran Cheng, Xupeng Wang 0001, Ferdous Sohel
ICASSP2
2025 RSM: Refined Saliency Map For Explainable 3D Object Tracking
abstract
Saliency maps play a major role in understanding the decision-making process of 3D models by illustrating the importance of individual points from the input to model predictions. However, saliency maps typically suffer from inaccuracies due to not considering the potential classification of contributions made by a point. In this paper, a two-stage explainability method for 3D object tracking is proposed to generate a refined saliency map (RSM), which refines the contributions of points to positive and negative based on their actual effects on tracking performances. Specifically, in stage I, a point-wise growing downsampling algorithm is developed to generate subsets of the search area, under which the model’s behavior is evaluated to precisely identify the points with negative contributions. Subsequently, a voxel-wise downsampling algorithm is performed along with the deviation metric to select points with positive contributions in stage II. Experiments demonstrate that RSM can generate high-quality explanations to popular 3D trackers.
Riran Cheng, Xupeng Wang 0001, Ferdous Sohel
ICASSP2
2025 Transferable universal adversarial attack against 3D object detection with latent feature disruption
Mumuxin Cai, Xupeng Wang 0001, Ferdous Sohel, Dian Xiao
J. Syst. Archit.2
2025 Black-Box Explainability-Guided Adversarial Attack for 3D Object Tracking
abstract
With the development of deep 3D tracking models and their broad prospects for safety-critical applications, adversarial robustness, i.e., the ability of deep models to resist malicious adversarial attacks, has become an important research topic. Previous works generate adversarial examples by tampering with points of the input point cloud indiscriminately. Consequently, they suffer from high computing costs and limited attack performance caused by the trade-off between imperceptibility and adversarial strength. In this paper, we propose a novel adversarial attack against 3D object tracking, which is guided by an occlusion-based explainability method to target points crucial for the predictions in the search area and results in a significant deviation between the predictions and the ground truth. Specifically, an attribution map is generated to reveal the importance of points to the model decision, which is achieved by measuring the variations of tracking performance under subsets generated by the downsampling strategy. To facilitate the generation of attribution maps, the downsampling strategy considers prior knowledge of 3D trackers, which assigns higher sampling probabilities to points with potentially higher contributions enclosed by bounding boxes. Multi-scale fusion is also leveraged to integrate the sensitivity of the model to local regions of varying sizes. Considering the requirement of imperceptibility on adversarial attacks, a hard geometric constraint is imposed on the targeted critical points, which produces perturbations with the property of surface invariance. Furthermore, in contrast to existing works devoted to spatial information manipulation only, multiple loss functions are developed to guide the perturbation generation, where the predicted motions of the tracking target representing the spatial-temporal information unique to the tracking task are distorted to deceive 3D trackers. Extensive experiments conducted on public benchmarks and 3D trackers demonstrate that our method can generate effective and imperceptible adversarial examples with tiny perturbations.
Riran Cheng, Xupeng Wang 0001, Ferdous Sohel
IEEE Trans. Circuits Syst. Video Technol.2
2024 Critical Path-Based Backdoor Detection for Deep Neural Networks
abstract
Backdoor attack to deep neural networks (DNNs) is among the predominant approaches to bring great threats into artificial intelligence. The existing methods to detect backdoor attacks focus on the perspective of distributions in DNNs, however, limited by its ability of generalization across DNN models. In this article, a critical-path-based backdoor detector (CPBD) is proposed, which approaches to detect backdoor attacks via DNN's interpretability. CPBD is designed to efficiently discover the characteristics of backdoors, which distinguish the critical paths in the attacked DNNs. To deal with the intractably large number of neurons, we propose to simplify the neurons, and the preserved key nodes are integrated into a set of critical paths. Thus, a DNN model can be formulated as a combination of several critical paths. Afterward, the detection of backdoors is performed based on the analysis of critical paths corresponding to different classes. Then, combining all the above steps, the CPBD algorithm is integrated to present the results in a standard and systematic manner. In addition, CPBD is able to locate neurons associated with malicious triggers, the combination of which is named as trigger propagation path. Extensive experiments are conducted, which testify the efficiency of the proposed method on multiple DNNs and different trigger sizes.
Wei Jiang 0016, Xiangyu Wen 0001, Jinyu Zhan, Xupeng Wang 0001, Chen Bian
IEEE Trans. Neural Networks Learn. Syst.4
2023 SC-Net: Salient Point and Curvature Based Adversarial Point Cloud Generation Network
abstract
Deep neural networks for 3D point clouds are receiving increasing attention. Recent works have shown that deep neural networks for 3D point clouds are vulnerable to adversarial attacks. However, existing adversarial attacks typically iteratively optimize a single sample to generate the adversarial point cloud, which requires exhausting computations. To make things worse, each point from the point cloud is processed indiscriminately, ignoring distinctions among points. To overcome the shortcomings mentioned above, we propose a method called SC-Net, which can generate an adversarial point cloud in a single forward pass. Specifically, SC-Net treats each point discriminatively by selecting salient points as attack targets. Furthermore, an elaborate Curvature-based distance loss is designed to constrain the strength of attacks to ensure surface consistency. Comparison and ablation experiments demonstrate SC-Net’s superior performance.
Zihao Zhang 0002, Nan Sang, Xupeng Wang 0001, Mumuxin Cai
ICASSP3
2023 Query-Efficient Generation of Adversarial Examples for Defensive DNNs via Multiobjective Optimization
abstract
Due to the inherent vulnerability of deep neural networks (DNNs), the adversarial example (AE) attack has become a serious threat to intelligent systems, e.g., the failure cause of an image classification system. Different to existing works, in this article we are interested in the generation of AEs for DNNs with defensive mechanisms. To make the attack more practical, we exploit a query-based method to generate image AEs in a black-box attack setting. Considering that the generation of AEs is inherently a constrained optimization problem, this article first formulates three objectives regarding defensive DNNs, i.e., attack effectiveness, attack evasiveness and attack coverage. Then, this article proposes a query-efficient AE attack based on the genetic algorithm (GA) and particle swarm optimization (PSO) to address the perturbation optimization problem. To improve the efficiency of search and query, AE-specific operators including block-level and pixel-level crossovers, discrete perturbation mutation and direction-driven reproduction are designed within the GA-based search framework. In addition, predication-based adaptation of reproduction-related parameters is implemented to speed up the search convergence. PSO-based jumping process is further devised to avoid stuck in local optimum. Benchmark-based experiments evaluated the efficiency of our method, which can achieve an attack success rate of 100% with averagely 52.95% reduced queries in contrast to existing black-box attacks on nondefensive models. For defensive DNN models, our method can obtain top attack performance with the query reduction up to 70.92% comparing with the candidates.
Wei Jiang 0016, Shen You, Jinyu Zhan, Xupeng Wang 0001, Deepak Adhikari
IEEE Trans. Evol. Comput.4
2022 Non-Rigid Transformation Based Adversarial Attack Against 3d Object Tracking
abstract
It is well-recognized that 3D visual tasks based on deep neural networks are vulnerable to adversarial attacks. Existing methods to generate adversarial examples are mainly developed from injecting imperceptible perturbations into the inputs. However, aggressive characteristic of geometric transformations, which are common in 3D objects, are rarely investigated. In this paper, we propose the non-rigid transformation based adversarial attack method against 3D object tracking. The adversarial example is generated by deforming parts of the tracking template, leading to deviation of the tracking predictions from the ground truth. Specifically, a clustering-based region segmentation module is designed to divide the tracking template into local regions. Furthermore, an objective function, which combines IoU loss, confidence loss and distance loss, is leveraged to update the poses of local regions. Experiments conducted on an efficient 3D tracker demonstrate that 3D trackers are extremely vulnerable to non-rigid deformation.
Riran Cheng, Nan Sang, Yinyuan Zhou, Xupeng Wang 0001
ICASSP4
2022 Adversary Distillation for One-Shot Attacks on 3D Target Tracking
abstract
Considering the vulnerability of existing deep models in the adversarial scenario, the robustness of 3D target tracking is not guaranteed. In this paper, we present an efficient generation based adversarial attack, termed Adversary Distillation Network (AD-Net), which is able to distract a victim tracker in a single shot. In contrast to existing adversarial attacks derived from point perturbations, the proposed method designs a generative network to distill an adversarial example from a tracking template through point-wise filtration. A binary distribution encoding layer is specialized to filter points, which is modeled as a Bernoulli distribution and approximated in a differentiable formulation. To boost the performance of adversarial example generation, a feature extraction module is deployed, which leverages the PointNet++ architecture to learn hierarchical features for the template points as well as similarities with the search areas. Experimental results on the KITTI vision benchmark show that the proposed adversarial attack can effectively mislead popular deep 3D trackers.
Xupeng Wang 0001, Ferdous Sohel, Mohammed Bennamoun
ICASSP2
2022 TH-Net: A Method Of Single 3d Object Tracking Based On Transformers And Hausdorff Distance
abstract
3D object tracking is the key of automatic driving. We propose a new 3D object tracking method called Transformer-Hausdorff Net (TH-Net). It contains three main modules: Feature Extraction, Feature Fusion, and Proposal Generation. The Feature Extraction module extracts features from the template and search area, where the permutation-invariable Transformers is leveraged to deal with the point cloud’s dis-order and sparsity. The features of template and search area are then fused by the Feature Fusion module to generate the tracking clues. Based on the tracking clues, we further generate 3D target proposal and execute verification in Proposal Generation module. TH-Net achieves a performance improvement in contrast to the state-of-the-art work on KITTI and NuScenes dataset.
Zihao Zhang 0002, Nan Sang, Xupeng Wang 0001
ICASSP3
2022 Interpretability-Guided Defense Against Backdoor Attacks to Deep Neural Networks
abstract
As an emerging threat to deep neural networks (DNNs), backdoor attacks have received increasing attentions due to the challenges posed by the lack of transparency inherent in DNNs. In this article, we develop an efficient algorithm from the interpretability of DNNs to defend against backdoor attacks to DNN models. To extract critical neurons, we deploy sets of control gates following neurons in layers, and the function of a DNN model can be interpreted as semantic sensitivities of neurons to input samples. A backdoor identification approach, derived from the activation frequency distribution on critical neurons, is proposed to reveal anomalies of particular neurons produced by backdoor attacks. Subsequently, a feasible and fine-grained pruning strategy is introduced to eliminate backdoors hidden in DNN models, without the need of retraining. Extensive experiments demonstrate that the proposed algorithm can identify and eliminate malicious backdoors efficiently in both single-target and multitarget scenarios with the performance of a DNN model retained to a large extent.
Wei Jiang 0016, Xiangyu Wen 0001, Jinyu Zhan, Xupeng Wang 0001
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.4
2021 Td-Net: Topology Destruction Network For Generating Adversarial Point Cloud
abstract
Despite a great progress has been made in 3D point cloud recognition, recent studies find that deep models are vulnerable to adversarial attacks generated through various point cloud transformations. However, existing spoofing attack methods neglect the influence of point cloud topology on the model recognition accuracy. In this paper, we propose a novel adversarial point cloud generation network, named Topology Destruction Network (TD-Net), which destroys topological structure of a point cloud by selectively dropping points leading to the formulation of holes on the surface. The network consists of an encoder and a decoder. The encoder first leverages a PointNet architecture to extract geometric information of the original point cloud, from which a topological adjacency matrix is encoded describing adjacency relationships between points. The decoder selects a specific point to drop associated with its neighboring points derived from the learned adjacency matrix, resulting in an adversarial point cloud with a destructed topology. Experiments on the ModelNet40 dataset demonstrate that the proposed method surpasses existing adversarial attacks in terms of reducing model recognition accuracy.
Chunhua Jiang, Xupeng Wang 0001, Mumuxin Cai
ICIP3
2021 PD-Net: Point Dropping Network for Flexible Adversarial Example Generation with $L_{0}$ Regularization
abstract
It is a challenging task to generate adversarial point clouds, considering the irregular structure of a point cloud, the large search space, and the requirement of imperception to humans. In this paper, a flexible adversarial point cloud generation method, named Point Dropping Network (PD-Net), is proposed, which can be trained to craft adversarial examples in a single forward pass. The network is designed to launch untargeted black-box attacks to deep 3D models through point dropping regularized by the$L_{0}$norm, in contrast to the widely adopted point perturbation methods. To enable incorporation into a deep neural network, the probability of a point to be dropped, which can be described by a Bernoulli distribution, is approximated by a hard concrete distribution. The network of PD-Net consists of an encoder and a decoder, where the former encodes geometric information of each point and the latter learns to drop points from their local features in an unsupervised way. Experiments on two popular deep 3D models (including PointNet and PointNet++) show that the proposed PD-Net degrades the recognition accuracy to a large extent and achieves a high flexibility at the same time.
Xupeng Wang 0001, Ferdous Sohel
IJCNN2
2021 Adversarial point cloud perturbations against 3D object detection in autonomous driving systems
Xupeng Wang 0001, Mumuxin Cai, Ferdous Sohel, Nan Sang, Zhengwei Chang
Neurocomputing1
2020 Interpretability Derived Backdoor Attacks Detection in Deep Neural Networks: Work-in-Progress
abstract
Backdoor attacks to deep neural networks (DNNs) have received increasing attentions, particularly in applications from edge computing. The detection of backdoor attacks is a challenging task, due to the lack of transparency in DNN. In this paper, we design a novel method to detect backdoor attacks in deep neural networks, which is derived from the interpretability of a DNN. A comprehensive analysis of the critical path in DNN is conducted, based on which two indicators are proposed, including the correlation coefficient and the discrete degree. Conseqently, an efficient backdoor detection algorithm is proposed, which only needs a few runtime images to identify the backdoor attacks. Initial experiments indicated the efficiency.
Xiangyu Wen 0001, Wei Jiang 0016, Jinyu Zhan, Xupeng Wang 0001, Zhiyuan He 0001
EMSOFT4
2020 Leveraging Ordinal Regression With Soft Labels For 3d Head Pose Estimation From Point Sets
abstract
Head pose estimation from depth image is a challenging problem, considering its large pose variations, severer occlusions, and low quality of depth data. In contrast to existing approaches that take 2D depth image as input, we propose a novel deep regression architecture called Head PointNet, which consumes 3D point sets derived from a depth image describing the visible surface of a head. To cope with the non-stationary property of pose variation process, the network is facilitated with an ordinal regression module that incorporates metric penalties into ground truth label representation. The soft label representation encodes inter-class and intra-class information contained in the class labels simultaneously, and guides the network to learn discriminative features. Experiments on two challenging datasets, namely the Biwi Head Pose Dataset and Pandora Dataset, show that our proposed method outperforms state-of-the-art approaches.
Shihua Xiao, Nan Sang, Xupeng Wang 0001, Xiangtian Ma
ICASSP3
2020 Deep Regression Forest with Soft-Attention for Head Pose Estimation
abstract
The task of head pose estimation from a single depth image is challenging, due to the presence of large pose variations, occlusions and inhomegeneous facial feature space. To solve the problem, we propose Deep Regression Forest with Soft-Attention (SA-DRF) in a multi-task learning setup. It can be integrated with a general feature learning net and jointly learned in an end-to-end manner. The soft-attention module is facilitated to learn soft masks from the general features and feeds the forest with task-specific features to regress head poses. Experiments on the Biwi Head Pose and Pandora datasets demonstrate its superior performance compared to current state-of-the-arts.
Xiangtian Ma, Nan Sang, Xupeng Wang 0001, Shihua Xiao
ICIP3
2017 Scale space clustering evolution for salient region detection on 3D deformable shapes
Xupeng Wang 0001, Ferdous Sohel, Mohammed Bennamoun, Yulan Guo
Pattern Recognit.1
2016 Heat propagation contours for 3D non-rigid shape analysis
abstract
We present a novel local shape descriptor by means of General Adaptive Neighborhoods (GANs) based on the properties of the heat diffusion process on a Riemannian manifold. The GAN is a spatial region, surrounding the feature point and fitting its local shape structure, which is isometric. Our signature, called the Heat Propagation Contours (HPCs), is obtained by analysing the well-known heat kernel and extracting contours automatically within the GAN as heat dissipates from the feature point onto the rest of the shape. HPCs capture geometric information around the feature point by investigating the heat propagation process both in the temporal and spatial domain. HPCs share many useful characteristics with the heat based methods. Particularly, it captures the intrinsic geometry of a shape and is suitable for non-rigid shape analysis. In addition, our signature provides an elegant and efficient way to describe the neighborhood of the feature point in a multi-scale approach. The proposed descriptor is evaluated on several datasets to demonstrate its effectiveness.
Xupeng Wang 0001, Ferdous Sohel, Mohammed Bennamoun
WACV1
2015 Binary Descriptor Based on Heat Diffusion for Non-rigid Shape Analysis
Xupeng Wang 0001, Ferdous Sohel, Mohammed Bennamoun
PSIVT1
2015 Adaptive security management of real-time storage applications over NAND based storage systems
Wei Jiang 0016, Yue Ma 0001, Xia Zhang 0001, Xupeng Wang 0001, Zili Shao
J. Netw. Comput. Appl.4
2013 Online optimization of security-sensitive real-time storage applications for NAND flash memory storage systems
abstract
With many advantages like low cost, faster and non-volatile, NAND flash memory has become a critical component in building security-critical real-time embedded devices. In this paper, we are interested in online optimization of security-sensitive storage applications, whose workloads are unpredictable but have explicit deterministic or probabilistic timing constraints and certain security constraints. Sensitive data must be stored before a specific deadline, otherwise it will lose its validity. To address these challenges, this paper presents a Feedback Vulnerability and Utilization Control (FVUC) mechanism. FVUC employs two proportional-integral controllers, the Utilization Controller and Vulnerability Controller, to build a big feedback loop that dynamically monitors the system run-time status as well as decides how many flash pages would be encrypted by a cryptography algorithm. Relied on the accurate model and design, FVUC can make a balance between the utilization and vulnerability, and achieve a better overall performance. The advantages of FVUC are verified by a series of simulation experiments under a broad range of system configurations and run-time uncertainties.
Wei Jiang 0016, Yue Ma 0001, Xia Zhang 0001, Xupeng Wang 0001, Zili Shao
RTCSA4