Yueyun Shang

dblp:161/1090 · DBLP profile ↗
← Back
10ranked-venue papers
0as first author
8since 2021 · last 2026
0000-0002-7291-9353ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 5 · 4 since 2021Computer networks · 2 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Security and privacy · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Security and privacy of machine learning · 43% Privacy and data protection · 29% Biometric security · 14%

Topics — the 6 heaviest of 7, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Security and privacy of machine learning
adversarial attack
2.022026
ErasableMask: A Robust and Erasable Privacy Protection Scheme Against Black-Box Face Recognition Models · IEEE Trans. Multim. 2026
DIP-Watermark: A Double Identity Protection Method Based on Robust Adversarial Watermark · IEEE Trans. Dependable Secur. Comput. 2026
Security and privacy of machine learning › model intellectual property protection
adversarial watermark
1.012026
DIP-Watermark: A Double Identity Protection Method Based on Robust Adversarial Watermark · IEEE Trans. Dependable Secur. Comput. 2026
Biometric security › biometric attack
face recognition evasion
1.012026
ErasableMask: A Robust and Erasable Privacy Protection Scheme Against Black-Box Face Recognition Models · IEEE Trans. Multim. 2026
Privacy and data protection › biometric privacy
face recognition privacy
1.012026
DIP-Watermark: A Double Identity Protection Method Based on Robust Adversarial Watermark · IEEE Trans. Dependable Secur. Comput. 2026
Privacy and data protection
facial privacy protection
1.012026
ErasableMask: A Robust and Erasable Privacy Protection Scheme Against Black-Box Face Recognition Models · IEEE Trans. Multim. 2026
Digital forensics and information hiding
watermarking
1.012026
DIP-Watermark: A Double Identity Protection Method Based on Robust Adversarial Watermark · IEEE Trans. Dependable Secur. Comput. 2026

Methods — techniques the papers use, named apart from their topics

meta-optimization · 1.0meta-learning · 1.0encoder-decoder watermark embedding · 1.0curriculum learning · 1.0adversarial examples · 1.0
YearPublicationVenuePosition
2026 Universal Transferable Dual Attack on Anti-Spoofing and Recognition in Facial Security Systems
Sirun Chen, Sipeng Shen, Ziyi Liu 0009, Yueyun Shang, Dengpan Ye
ICIC (16)5
2026 MSFT-Net: Mixture Semantic-Agnostic Manipulation Trace Enhanced Architecture for Robust Image Manipulation Localization
abstract
Since the proliferation of image manipulation methods, effective image manipulation localization (IML) in scenarios with post-processing operations gradually becomes a core challenge. For a long time, IML either relies on strongly semantically related features, resulting in semantic relevance bias in the localization results, or only uses a single semantic-agnostic space feature, which is unable to maintain effective localization capabilities after image post-processing operations. Inspired by this, we propose a novel mixture semantic-agnostic manipulation trace robust localization network (MSFT-Net), which specifically utilizes mixture semantic-agnostic information to achieve effective and robust IML. The MSFT-Net introduces two new modules, the mixture shared manipulation trace enhancement module (MISE) and the Multiscale Feature Association Module (FAM). MISE dynamically links multiple semantic-agnostic feature extractors using a sparsity-enhanced mixture of shared experts, enabling the extraction of diverse manipulation features for accurate localization. Furthermore, keeping the high resolution of the localization features is very important in the mask prediction stage. Therefore, FAM outputs high-resolution fused manipulation features by using the correlation of features at the same level and the spatial context information from different levels. This further improves the effectiveness of IML in post-processing scenarios. Comprehensive experiments on five datasets demonstrate that our model significantly improves both in localization accuracy (average F1 score and IoU increasing by over 9.9% and 4.0%) and robustness. The codes will be made available.
Dengpan Ye, Yunming Zhang, Jiacheng Deng 0001, Ziyi Liu 0009, Yueyun Shang, Zhihong Tian 0001
IEEE Trans. Circuits Syst. Video Technol.6
2026 Take Fake as Real: Realistic-Like Robust Black-Box Adversarial Attack to Evade AIGC Detection
abstract
The security of AI-generated content (AIGC) detection is crucial for ensuring multimedia content credibility. To enhance detector security, research on adversarial attacks has become essential. However, most existing adversarial attacks focus only on GAN-generated facial images detection, struggle to be effective on multi-class natural images and diffusion-based detectors, and exhibit poor invisibility. To fill this gap, we first conduct an in-depth analysis of the vulnerability of AIGC detectors and discover the feature that detectors vary in vulnerability to different post-processing. Then, considering that the detector is agnostic in real-world scenarios and given this discovery, we propose a Realistic-like Robust Black-box Adversarial attack (R2BA) with post-processing fusion optimization. Unlike typical perturbations, R2BA uses real-world post-processing, i.e., Gaussian blur, JPEG compression, Gaussian noise and light spot to generate adversarial examples. Specifically, we use a stochastic particle swarm algorithm with inertia decay to optimize post-processing fusion intensity and explore the detector’s decision boundary. Guided by the detector’s fake probability, R2BA enhances/weakens the detector-vulnerable/detector-robust post-processing intensity to strike a balance between adversariality and invisibility. Extensive experiments on popular/commercial AIGC detectors and datasets demonstrate that R2BA exhibits impressive anti-detection performance, excellent invisibility, and strong robustness in GAN-based and diffusion-based cases. Compared to state-of-the-art white-box and black-box attacks, R2BA shows significant improvements of 15%–72% and 21%–47% in anti-detection performance under the original and robust scenario respectively, offering valuable insights for the security of AIGC detection in real-world applications.
Caiyun Xie, Dengpan Ye, Yunming Zhang, Yueyun Shang, Yunna Lv, Jiacheng Deng 0001, Jiawei Song
IEEE Trans. Circuits Syst. Video Technol.4
2026 DIP-Watermark: A Double Identity Protection Method Based on Robust Adversarial Watermark
abstract
The wide deployment of Face Recognition (FR) systems poses privacy risks. One countermeasure is adversarial attack, deceiving unauthorized malicious FR, but it also disrupts regular identity verification of trusted authorizers, exacerbating the potential threat of identity impersonation. To address this, we propose the first double identity protection scheme based on traceable adversarial watermarking, termed DIP-Watermark. DIP-Watermark employs a one-time watermark embedding to deceive unauthorized FR models and allows authorizers to perform identity verification by extracting the watermark. Specifically, we propose an information-guided adversarial attack against FR models. The encoder embeds an identity-specific watermark into the deep feature space of the carrier, guiding recognizable features of the image to deviate from the source identity. We further adopt a collaborative meta-optimization strategy compatible with sub-tasks, which regularizes the joint optimization direction of the encoder and decoder. This strategy enhances the representation of universal carrier features, mitigating multi-objective optimization conflicts in watermarking. Extensive experiments on two large-scale facial datasets demonstrate that DIP-Watermark achieves significant attack success rates and traceability accuracy on state-of-the-art FR models and commercial APIs. It also exhibits superior robustness against a wide range of real-world simulated distortions, outperforming existing privacy protection methods based on adversarial attacks, deep watermarking, or their simple combination. Our work potentially opens up new insights into proactive protection for FR privacy.
Yunming Zhang, Dengpan Ye, Caiyun Xie, Sipeng Shen, Ziyi Liu 0009, Jiacheng Deng 0001, Yueyun Shang, Zhihong Tian 0001
IEEE Trans. Dependable Secur. Comput.7
2026 ErasableMask: A Robust and Erasable Privacy Protection Scheme Against Black-Box Face Recognition Models
abstract
While face recognition (FR) models have brought remarkable convenience in face verification and identification, they also pose substantial privacy risks to the public. Existing facial privacy protection schemes usually adopt adversarial examples to disrupt face verification of FR models. However, these schemes often suffer from weak transferability against black-box FR models and permanently damage the identifiable information that cannot fulfill the requirements of authorized operations such as forensics and authentication. To address these limitations, we proposeErasableMask, a robust and erasable privacy protection scheme against black-box FR models. Specifically, via rethinking the inherent relationship between surrogate FR models, ErasableMask introduces a novel meta-auxiliary attack, which boosts black-box transferability by learning more general features in a stable and balancing optimization strategy. It also offers a perturbation erasion mechanism that supports the erasion of semantic perturbations in protected face without degrading image quality. To further improve performance, ErasableMask employs a curriculum learning strategy to mitigate optimization conflicts between adversarial attack and perturbation erasion. Extensive experiments on the CelebA-HQ and FFHQ datasets demonstrate that ErasableMask achieves the state-of-the-art performance in transferability, achieving over72%mean confidence in commercial FR systems. Moreover, ErasableMask also exhibits outstanding perturbation erasion performance, achieving over90%erasion success rate.
Sipeng Shen, Yunming Zhang, Dengpan Ye, Xiuwen Shi, Yueyun Shang, Zhihong Tian 0001
IEEE Trans. Multim.7
2024 Perceptual Video Hashing With Secure Anti-Noise Model for Social Video Retrieval
abstract
In real scenarios, videos are usually corrupted by multiple types of noise, which brings great challenges to retrieving social videos. However, most of the current video hashing methods for video retrieval consider the attack of a single noise model, and rarely discuss when dealing with complex noise models, which is not conducive to solving the above difficulties. Thus, we describe a novel video hashing with secure anti-noise model (SANM). To improve the robustness of noise attacks, the input video is reconstructed into a SANM by low-rank representation (LRR) and random subspace partition (RSP). LRR is useful technique for capturing the global structure of data. It focuses on recovering the underlying subspace in noisy environment and helps to make the proposed model robust to multiple noises. In addition, using chaotic mapping to control the generation of RSP can ensure the security of proposed model. Then, a new subspace decomposition descriptor (SDD) is proposed. SDD is obtained by calculating the invariant distances of the factor matrices obtained by tucker decomposition, and is used to decompose SANM to derive a compact hash. Various experiments demonstrate that the SANM hashing performs better than several state-of-the-art algorithms in terms of good robustness and discrimination, and it can accurately retrieve social videos.
Lv Chen, Dengpan Ye, Yueyun Shang
IEEE Internet Things J.3
2023 RTIM Hashing: Robust and Compact Video Hashing With a Rotation- and Translation-Invariant Model
abstract
Abstract Video hashing is a popular research topic in the fields of multimedia information and security because its fast matching and low-cost storage characteristics are widely used in many applications (video copy detection, video retrieval, video authentication, etc.). This paper describes a compact video hashing method with a rotation- and translation-invariant model (RTIM). The key contribution of this approach is that it innovatively reconstructs an input video into a 3D RTIM by combining ring partition and a pipeline histogram; this is a first in video hashing and helps make video hashes resistant to rotation and translation. Then, the proposed model is decomposed via Tucker decomposition, and the generated core tensor is used to produce a compact hash. As the core tensor is a compressed version of the original tensor, hash construction with the core tensor makes RTIM hashing compact and achieves desirable discrimination ability. Different from existing video hashing algorithms, RTIM hashing can not only resist many commonly used digital operations, especially video rotation and cyclic frame shifting, but also achieve good discrimination ability. Various experiments demonstrate the effectiveness of our algorithm. Receiver operating characteristic curve comparisons show that compared with the state-of-the-art video hashing algorithms, RTIM hashing is more robust and compact.
Lv Chen, Dengpan Ye, Yueyun Shang
Comput. J.3
2022 Robust Video Hashing Based on Local Fluctuation Preserving for Tracking Deep Fake Videos
abstract
With the rapid development of deepfake techniques, massive face manipulation videos appeared on social networks. These deepfake videos not only violated the original video of the author’s privacy, but also seriously threatened the security of the video database. Robust video hashing can map videos with similar visual content into similar hash codes, which is beneficial for tracking fake video material in social networks. In this paper, a robust video hashing algorithm based on local fluctuation preserving is proposed. The algorithm uses a shot segmentation model and local statistical descriptors, which is robust to many commonly-used digital operations and can accurately track the original version of these fake videos from a huge video database. An essential contribution is a shot segmentation model reconstruction from input video with image hashing and discrete wavelet transform, reaching initial data compression and against noise attack. In addition, as local statistical descriptors are content-based and local preserving features, the hash generated by local statistical descriptors can achieve good discrimination and ensure that the proposed hash has good tracking ability to fake videos from original videos.
Lv Chen, Dengpan Ye, Yueyun Shang, Jiaqing Huang
ICASSP3
2020 SmartSteganogaphy: Light-weight generative audio steganography model for smart embedding application
Shunzhi Jiang, Dengpan Ye, Jiaqing Huang, Yueyun Shang, Zhuoyuan Zheng
J. Netw. Comput. Appl.4
2016 Mobile crowd-sensing context aware based fine-grained access control mode
Dengpan Ye, Yueyun Shang, Jixiang Zhu, Kun Ouyang
Multim. Tools Appl.3