EDBT 2026 Demo / reviewers in the wild / expert
Yan Wo
dblp:16/7672
· DBLP profile ↗
24ranked-venue papers
2as first author
17since 2021 · last 2026
0000-0003-1001-4425ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 14 · 2 first-author · 7 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Security and privacy · 5 · 5 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Data-free model stealing via active latent perturbation and sample selection
Haoxian Chen 0007, Yan Wo |
Knowl. Based Syst. | 2 |
| 2025 | Improving the transferability of adversarial examples through semantic-mixup inputs
Fuquan Gan, Yan Wo |
Knowl. Based Syst. | 2 |
| 2025 | Improving adversarial transferability via adaptive ensemble attack with post-optimization
Yan Wo |
Knowl. Based Syst. | 2 |
| 2025 | From coarse to fine: a two-stage common semantic space construction for unpaired cross modal retrieval
Zhanyang Liang, Yan Wo |
Multim. Syst. | 2 |
| 2025 | Boosting the Transferability of Adversarial Examples Through Gradient AggregationabstractDeep neural networks(DNNs) have been demonstrated to be vulnerable to meticulously crafted adversarial examples. Transfer-based attacks do not require access to the target model’s information, have emerged as a substantial threat to the deployment of DNNs in real-world scenarios. Although considerable works have been conducted to enhance adversarial transferability from various perspectives, the transferability remains suboptimal. In this work, we propose a novel transfer-based attack, termed Gradient Aggregation Attack (GAA). Inspired by the observation that flatter local minima can improve transferability, GAA incorporates both the worst-aware loss and substitute loss into the objective function. The worst-aware loss represents the maximum loss within the neighborhood of the adversarial example, while the substitute loss quantifies the difference between the worst-aware loss and the empirical loss, serving as a measure of the flatness of the local minima region. By optimizing the empirical loss alongside these two losses, GAA is capable of generating adversarial examples within a flat local minimum region while simultaneously enhancing its flatness, ultimately surpassing all baselines. Specifically, since directly optimizing the worst-aware loss incurs substantial computation during adversarial example generation, we approximate the worst-aware loss with a first-order Taylor expansion to mitigate this computational cost. Via rigorous theoretical analysis and extensive experiments demonstrate that our proposed GAA method generates adversarial examples corresponding to flatter local minima regions. Compared to existing transfer-based attacks, GAA effectively enhances adversarial transferability, regardless of whether the model is a normally trained or an advanced defense model. Fuquan Gan, Yan Wo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Defending Against Model Inversion Attack via Feature PurificationabstractThe Model Inversion Attack (MIA) aims to reconstruct the privacy data used to train the target model, raising significant public concerns about the privacy of machine learning models. Therefore, proposing effective methods to defend against MIA has become crucial. The relationship between MIA and defense is a typical adversarial process. If the upper bound of the attacker’s capability can be estimated through theoretical analysis, a more robust defense method can be achieved by weakening this upper bound. To achieve this goal, we simplify MIA to a problem of reconstructing estimates, and analyze the lower bound of the reconstruction error obtained by the attacker, from which we infer the theoretical upper bound of the attacker’s capability, providing a foundation for designing the defense mechanism. We find that the lower bound of reconstruction error is inversely proportional to the Fisher information. This means that smaller Fisher information can lead to a larger reconstruction error. If the attacker cannot obtain second-order information during the reconstruction estimation, the corresponding Fisher information will be reduced. Consequently, we propose a defense against model inversion attacks via feature purification (DMIAFP). To reduce the Fisher information, DMIAFP hides the private data contained within the features and its second-order information (the relationships between private data) by minimizing the first-order and second-order correlations between private data and output features. Additionally, we introduce Principal Inertia Components (PIC) for the correlation metric, and infer the theoretical upper bound of the attacker’s reconstruction ability through PIC, thereby avoiding the issue of poor defensive performance caused by data-driven instability in defense methods that train by adversarially inverse models. Experimental results show that our method achieves good performance in defense and exhibits significant advantages in removing redundant information contained in features. Shenhao Shi, Yan Wo |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2024 | Unbinding tensor product representations for image captioning with semantic alignment and complementation
Bicheng Wu, Yan Wo |
Multim. Syst. | 2 |
| 2024 | Incorporating semantic consistency for improved semi-supervised image captioning
Bicheng Wu, Yan Wo |
Multim. Tools Appl. | 2 |
| 2023 | A general framework for secure biometric hashing against reconstruction attacks
Lianyi Yu, Yan Wo |
Appl. Intell. | 2 |
| 2023 | Learning domain-invariant representation for generalizing face forgery detection
Yuanlu Wu, Yan Wo, Caiyu Li |
Comput. Secur. | 2 |
| 2023 | An image compression and encryption scheme for similarity retrieval
Yan Wo |
Signal Process. Image Commun. | 2 |
| 2022 | Secure biometric hashing against relation-based attacks via maximizing min-entropy
Lianyi Yu, Qiangjiang Wang, Yan Wo |
Comput. Secur. | 3 |
| 2022 | Joint manipulation trace attention network and adaptive fusion mechanism for image splicing forgery localization
Yuanlu Wu, Yan Wo |
Multim. Tools Appl. | 2 |
| 2022 | Masquerade attack on biometric hashing via BiohashGAN
Zhangyong Wu, Yan Wo, Xudong Zhong |
Vis. Comput. | 3 |
| 2021 | Robust source camera identification against adversarial attacks
Yan Wo, Yuanlu Wu |
Comput. Secur. | 2 |
| 2021 | Learning sufficient scene representation for unsupervised cross-modal retrieval
Jieting Luo, Yan Wo, Bicheng Wu |
Neurocomputing | 2 |
| 2021 | Video smoke detection base on dense optical flow and convolutional neural network
Yuanlu Wu, Yan Wo |
Multim. Tools Appl. | 3 |
| 2020 | Non-uniform image blind deblurring by two-stage fully convolution networkabstractDeep neural networks have recently demonstrated high performance for deblurring. However, few methods are designed for both non‐uniform image blur estimation and removal with highly efficient. In this study, the authors proposed a fully convolutional network that outputs estimated blur and restored image in one feed‐forward pass for the non‐uniformly blurred image of any input‐size. The proposed network contains two subnets. The parameter estimation subnet P‐net predicts pixel‐wise parameters of multiple blur types with high accuracy. The output of P‐net is used as a condition, which guides the blur removal subnet G‐net to restore a high quality latent sharp image. P‐net and G‐net are ultimately integrated into a single framework called PG‐net, which guarantees the consistency of parameter estimation and blur removal, thereby improves algorithm efficiency. Experiment results show that the authors blur parameter estimation method as well as their deblurring method outperforms the comparison methods both quantitatively and qualitatively. Chudan Wu, Yan Wo, Guoqing Han, Zhangyong Wu, Jiyun Liang |
IET Image Process. | 2 |
| 2019 | Geometrically robust video hashing based on ST-PCT for video copy detection
Wu Tang, Yan Wo |
Multim. Tools Appl. | 2 |
| 2019 | Deep Secure Quantization: On secure biometric hashing against similarity-based attacks
Yanzhi Chen, Yan Wo, Renjie Xie, Chudan Wu |
Signal Process. | 2 |
| 2019 | Reversible cellular automata image encryption for similarity search
Yingri Su, Yan Wo |
Signal Process. Image Commun. | 2 |
| 2018 | Multi-granularity geometrically robust video hashing for tampering detection
Haichao Chen, Yan Wo |
Multim. Tools Appl. | 2 |
| 2017 | Copy-move forgery detection based on multi-radius PCETabstractCopy–move, which copies part of an image and pastes to another part of the same image, is one of the most commonly used image tampering operations. The copied part may suffer to post‐processing operations such as rotation, scaling and blur to make the forgery visually convincing. To detect the copied parts with large‐scale rotation and scaling, this study proposes a copy–move forgery detection method based on multi‐radius polar complex exponential transform (PCET). First, the multi‐radius PCET with graphic processing unit acceleration is used to extract the rotational invariant and multi‐scale features. Then, the lexicographical order matching algorithm, optimised with minimum heap is applied to get a coarse match result. After that, the accurate detection based on radius ratio and position information is used to get the accurate detection result. Compared with the state‐of‐the‐art methods, the proposed method can detect the copied parts with large‐scale rotation or scaling and is robust against Joint Photographic Experts Group (JPEG) compression, smoothing and noise degrading. Yan Wo, Kemin Yang, Haichao Chen |
IET Image Process. | 1 |
| 2015 | A saliency detection model using aggregation degree of color and texture
Yan Wo |
Signal Process. Image Commun. | 1 |