EDBT 2026 Demo / reviewers in the wild / expert
Weiwei Feng
dblp:162/3225
· DBLP profile ↗
17ranked-venue papers
6as first author
15since 2021 · last 2026
0000-0002-8761-0375ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 7 · 4 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 7 · 4 first-author · 7 since 2021Security and privacy · 4 · 1 first-author · 4 since 2021Computer networks · 1Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Enhancing Cross-Task Transferability of Adversarial Examples via Spatial and Channel AttentionabstractAdversarial examples are well known to pose a security risk, when attacking deep learning models. While, most of existing adversarial attacks are designed to attack a single deep learning-based task, such as image classification. In practical scenarios, it is more necessary to study adversarial examples transferring across different vision tasks. However, it is challenging to create cross-task adversarial examples that can destroy multiple vision tasks at once due to unavailable various task-specific models and loss functions for attackers. To deal with this problem, we propose a Dual Attention-Guided Method (DAGM) for crafting cross-task adversarial examples by designing a spatial attention module and a channel attention module to capture overlapping discriminative regions and features that contribute to various tasks. Then we craft cross-task adversarial examples via reducing the dispersion (i.e., standard deviation) of feature maps re-weighted by both attention modules, which can destroy the overlapping discriminative regions and features for various tasks. Furthermore, to present theoretical explanation, we systematically analyze our method, and rigorously prove that both attention modules can provide better effectiveness of our adversarial examples, compared with existing cross-task adversarial attacks. Extensive experiments on two datasets demonstrate that our method can significantly degrade the performance of various tasks, even online CV APIs, and consistently outperform state-of-the-art methods by a large margin. Weiwei Feng, Nanqing Xu, Tianzhu Zhang 0001, Yongdong Zhang 0001, Feng Wu 0001 |
IEEE Trans. Multim. | 1 |
| 2025 | GMamba: EEG Representation Learning from Spatiotemporal Perspectives via Graph Mamba
Weiwei Feng, Nanqing Xu, Changtao Miao, Tengfei Liu 0007, Weiqiang Wang 0002 |
ICONIP (3) | 1 |
| 2025 | Mixture-of-Queries Transformer: Camouflaged Instance Segmentation via Queries Cooperation and Frequency EnhancementabstractDue to the high similarity between camouflaged instances and the surroundings and the widespread camouflage-like scenarios, the recently proposed camouflaged instance segmentation (CIS) is a challenging and relevant task. Previous approaches achieve some progress on CIS, while many overlook camouflaged objects’ color and contour nature and then decide on each candidate instinctively. In this paper, we contribute a Mixture-of-Queries Transformer (MoQT) in an end-to-end manner for CIS based on two key designs (a Frequency Enhancement Feature Extractor and a Mixture-of-Queries Decoder). First, the Frequency Enhancement Feature Extractor is responsible for capturing the camouflaged clues in the frequency domain. To expose camouflaged instances, the extractor enhances the effectiveness of contour, eliminates the interference color, and obtains suitable features simultaneously. Second, a Mixture-of-Queries Decoder utilizes multiple newly initialized experts of queries (a group of queries considered an expert) in each layer for spotting camouflaged characteristics with cooperation. These experts collaborate to generate outputs with the mixture-of-queries mechanism, refined hierarchically to a fine-grained level for more accurate instance masks. Coupling these two components enables MoQT to use multiple experts to integrate effective clues of camouflaged objects in both spatial and frequency domains. Extensive experimental results demonstrate our MoQT outperforms 19 state-of-the-art CIS approaches on both COD10K and NC4K datasets. Weiwei Feng, Nanqing Xu, Tengfei Liu 0007, Weiqiang Wang 0002 |
IJCAI | 1 |
| 2025 | MFFI: Multi-Dimensional Face Forgery Image Dataset for Real-World ScenariosabstractRapid advances in Artificial Intelligence Generated Content (AIGC) have enabled increasingly sophisticated face forgeries, posing a significant threat to social security. However, current Deepfake detection methods are limited by constraints in existing datasets, which lack the diversity necessary in real-world scenarios. Specifically, these data sets fall short in four key areas: unknown of advanced forgery techniques, variability of facial scenes, richness of real data, and degradation of real-world propagation. To address these challenges, we propose the Multi-dimensional Face Forgery Image (MFFI ) dataset, tailored for real-world scenarios. MFFI enhances realism based on four strategic dimensions: 1) Wider Forgery Methods; 2) Varied Facial Scenes; 3) Diversified Authentic Data; 4) Multi-level Degradation Operations. MFFI integrates 50 different forgery methods and contains 1024K image samples. Benchmark evaluations show that MFFI outperforms existing public datasets in terms of scene complexity, cross-domain generalization capability, and detection difficulty gradients. These results validate the technical advance and practical utility of MFFI in simulating real-world conditions. The dataset and additional details are publicly available at https://github.com/inclusionConf/MFFI. Changtao Miao, Weiwei Feng, Qi Chu 0001, Jianshu Li, Yunfeng Diao, Wei Zhou 0021, Joey Tianyi Zhou, Xiaoshuai Hao |
ACM Multimedia | 4 |
| 2024 | MFMS: Learning Modality-Fused and Modality-Specific Features for Deepfake Detection and Localization TasksabstractThis paper presents a summary of the proposed solution to the AV-Deepfake1M competition. Deepfake technology is developing fast, and realistic generation techniques of audio and videos have aroused public concerns. With this background, the AV-Deepfake1M competition aims to address the problem of audio-video Deepfake and provides a large-scale dataset named AV-Deepfake1M to boost the research in this area. In this paper, we present our solutions which have achieved top performance in this competition. We also provide more detailed experiments to prove the effectiveness of the modules used in our methods. Changtao Miao, Jianshu Li, Wenzhong Deng, Weibin Yao, Zhe Li 0081, Bingyu Hu, Weiwei Feng, Qi Chu 0001 |
ACM Multimedia | 9 |
| 2024 | FD-GAN: Generalizable and Robust Forgery Detection via Generative Adversarial Networks
Nanqing Xu, Weiwei Feng, Tianzhu Zhang 0001, Yongdong Zhang 0001 |
Int. J. Comput. Vis. | 2 |
| 2024 | Robust and Generalized Physical Adversarial Attacks via Meta-GANabstractDeep neural networks are known to be vulnerable to adversarial examples, where adding carefully crafted adversarial perturbations to the inputs can mislead the DNN model. However, it is challenging to generate effective adversarial examples in the physical world due to many uncontrollable physical dynamics, which pose security and safety threats in the real world. Current physical attack methods aim to generate robust physical adversarial examples by simulating all possible physical dynamics. If attacking a new image or a new DNN model, they require expensive manual efforts for simulating physical dynamics or considerable time for iteratively optimizing. To tackle these limitations, we propose a robust and generalized physical adversarial attack method with Meta-GAN (Meta-GAN Attack), which is able to not only generate robust physical adversarial examples, but also generalize to attacking novel images and novel DNN models by accessing a few digital and physical images. First, we propose to craft robust physical adversarial examples with a generative attack model via simulating color and shape distortions. Second, we formulate the physical attack as a few-shot learning problem and design a novel class-agnostic and model-agnostic meta-learning algorithm to solve this problem. Extensive experiments on two benchmark datasets with four challenging experimental settings verify the superior robustness and generalization of our method by comparing to state-of-the-art physical attack methods. The source code is released at github. Weiwei Feng, Nanqing Xu, Tianzhu Zhang 0001, Baoyuan Wu, Yongdong Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | A2-CLM: Few-Shot Malware Detection Based on Adversarial Heterogeneous Graph AugmentationabstractMalware attacks, especially “few-shot” malware, have profoundly harmed the cyber ecosystem. Recently, malware detection models based on graph neural networks have achieved remarkable success. However, these efforts over-rely on sufficient labeled data for model training and thus may be brittle in few-shot malware detection because of the label scarcity. To this end, we propose a self-supervised malware detection framework based on graph contrastive learning and adversarial augmentation, termed A2-CLM, to address the challenge of few-shot malware detection. Particularly, A2-CLM first depicts the malware execution context with a sensitivity heterogeneous graph by assessing the security semantic of each behavior. Afterwards, A2-CLM designs multiple adversarial attacks to generate more practical contrastive pairs, including the PGD attack, attribute masking attack, meta-graph-guide sampling attack, direct system calls attack, and obfuscation attack, which is beneficial to strengthening the model’s effectiveness and robustness. To alleviate the training workload of contrastive learning, we introduce a momentum strategy to train the multiple graph encoders in A2-CLM. Especially on 1-shot detection tasks, A2-CLM achieves performance gains of up to 24.63% and 4.58% against supervised and self-supervised detection methods, respectively. Chen Liu 0039, Bo Li 0005, Jun Zhao 0017, Weiwei Feng, Xudong Liu 0001, Chunpei Li |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | A Unified Optimization Framework for Feature-Based Transferable AttacksabstractDespite the rapid progress and significant success of deep learning in a wide spectrum of fields, adversarial examples expose many security threats to deep learning models. Recently, an interesting property has been discovered that adversarial examples are transferable, which means adversarial examples targeting a given model can also attack another model. Therefore, many researchers are attracted by this property and work on how to improve the transferability of adversarial examples. Furthermore, compared to the traditional attack methods of disrupting output logits (dubbed logit-based attacks), recent works reveal that disrupting feature maps instead of logits can lead to more transferable adversarial examples (dubbed feature-based attacks). However, previous feature-based attacks mostly hold the intuitive designs of the optimization goals and specialization for certain scenarios with a lack of theoretical motivations and a unified framework. To overcome these limitations, we propose a Unified Feature-based Attack Framework, dubbed as UFAF, combining a dispersion loss and a distance loss, which unifies eight existing feature-based attacks. Furthermore, we also bridge the formulation gap between feature-based attacks and traditional logit-based attacks. With our UFAF, we propose an Entropy-Wasserstein (EW) attack by specifying the dispersion loss as Entropy and the distance loss as Wasserstein Distance, respectively. Besides, we provide theoretical analysis to guarantee the effectiveness of the proposed attack method. Extensive experimental results show the superior performance of our EW attack, which can outperform state-of-the-art attacks by 4.95% on attack success rates in untargeted attack settings, and by 1.95% on targeted transfer rates and 1.17% on target success rates in targeted attack settings. Moreover, our framework can help other feature-based attacks improve their performance by 7.7% in untargeted attack settings. Nanqing Xu, Weiwei Feng, Tianzhu Zhang 0001, Yongdong Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2023 | Dynamic Generative Targeted Attacks with Pattern InjectionabstractAdversarial attacks can evaluate model robustness and have been of great concern in recent years. Among various attacks, targeted attacks aim at misleading victim models to output adversary-desired predictions, which are more challenging and threatening than untargeted ones. Existing targeted attacks can be roughly divided into instance-specific and instance-agnostic attacks. Instance-specific attacks craft adversarial examples via iterative gradient updating on the specific instance. In contrast, instance-agnostic attacks learn a universal perturbation or a generative model on the global dataset to perform attacks. However, they rely too much on the classification boundary of substitute models, ignoring the realistic distribution of the target class, which may result in limited targeted attack performance. And there is no attempt to simultaneously combine the information of the specific instance and the global dataset. To deal with these limitations, we first conduct an analysis via a causal graph and propose to craft transferable targeted adversarial examples by injecting target patterns. Based on this analysis, we introduce a generative attack model composed of a cross-attention guided convolution module and a pattern injection module. Concretely, the former adopts a dynamic convolution kernel and a static convolution kernel for the specific instance and the global dataset, respectively, which can inherit the advantages of both instance-specific and instance-agnostic attacks. And the pattern injection module utilizes a pattern prototype to encode target patterns, which can guide the generation of targeted adversa rial examples. Besides, we also provide rigorous theoretical analysis to guarantee the effectiveness of our method. Extensive experiments demonstrate that our method shows superior performance than 10 existing adversarial attacks against 13 models. Weiwei Feng, Nanqing Xu, Tianzhu Zhang 0001, Yongdong Zhang 0001 |
CVPR | 1 |
| 2023 | PanelNet: Understanding 360 Indoor Environment via Panel RepresentationabstractIndoor 360 panoramas have two essential properties. (1) The panoramas are continuous and seamless in the horizontal direction. (2) Gravity plays an important role in indoor environment design. By leveraging these properties, we present PanelNet, a framework that understands indoor environments using a novel panel representation of 360 images. We represent an equirectangular projection (ERP) as consecutive vertical panels with corresponding 3D panel geometry. To reduce the negative impact of panoramic distortion, we incorporate a panel geometry embedding network that encodes both the local and global geometric features of a panel. To capture the geometric context in room design, we introduce Local2Global Transformer, which aggregates local information within a panel and panel-wise global context. It greatly improves the model performance with low training overhead. Our method outperforms existing methods on indoor 360 depth estimation and shows competitive results against state-of-the-art approaches on the task of indoor layout estimation and semantic segmentation. Haozheng Yu, Bing Jian, Weiwei Feng, Shan Liu 0001 |
CVPR | 4 |
| 2023 | MetaFake: Few-shot Face Forgery Detection with Meta LearningabstractWith remarkable progress achieved by facial forgery technologies, their potential security risks cause serious concern to society since they can easily fool face recognition systems and even human beings. Current forgery detection methods have achieved excellent performance when training with a large-scale database. However, they usually fail to give correct predictions in real applications where only a few fake samples created by unseen forgery methods are available. In this paper, we propose a novel method to boost the performance of identifying samples generated by unseen techniques, dubbed MetaFake, which requires only a few fake samples. Our MetaFake enjoys the part features located by meta forgery prototypes created adaptively based on each task. The local-aggregated module helps to integrate these part features for the final prediction. Besides, we establish a large database of about 0.6 million images to verify the proposed method, including fake samples synthesized by 18 forgery techniques. Extensive experiments demonstrate the superior performance of the proposed method. Nanqing Xu, Weiwei Feng |
IH&MMSec | 2 |
| 2023 | TI-MVD: A temporal interaction-enhanced model for malware variants detection
Chen Liu 0039, Bo Li 0005, Jun Zhao 0017, Ziyang Zhen, Weiwei Feng, Xudong Liu 0001 |
Knowl. Based Syst. | 5 |
| 2022 | Optimized Backstepping Tracking Control Using Reinforcement Learning for Quadrotor Unmanned Aerial Vehicle SystemabstractIn this article, an optimized tracking control scheme is studied for the quadrotor unmanned aerial vehicle (QUAV) system by combining both reinforcement learning (RL) and the backstepping technique. The RL aims to overcome the difficulty coming from solving the Hamilton–Jacobi–Bellman (HJB) equation, and it is performed via iterating both critic and actor each other, where the critic is for improving the control performance and the actor is for executing the control behavior. In mathematics, a QUAV system is composed of two connected subsystems that are, respectively, modeled by the translational and rotational dynamic equations, which are coupled via a rotation matrix; hence, the optimized tracking scheme is composed of two interconnected individual controls corresponding to the position and attitude, respectively. To achieve the two optimized position and attitude controls, the RL is constructed on the basis of the neural network (NN) approximation of the HJB equation’s solution by utilizing NN’s outstanding function approximation ability. Particularly, the position control is accomplished by introducing an intermediate control because the translational dynamic is an underactuated system. Since the proposed RL algorithm is significantly simple in comparison with the published methods, the optimized QUAV control can be easily executed in practical applications. Finally, the results are demonstrated by a Lyapunov stability analysis and a numerical simulation. Guoxing Wen 0001, Wei Hao 0003, Weiwei Feng, Kai-Zhou Gao |
IEEE Trans. Syst. Man Cybern. Syst. | 3 |
| 2021 | Meta-Attack: Class-agnostic and Model-agnostic Physical Adversarial AttackabstractModern deep neural networks are often vulnerable to adversarial examples. Most exist attack methods focus on crafting adversarial examples in the digital domain, while only limited works study physical adversarial attack. However, it is more challenging to generate effective adversarial examples in the physical world due to many uncontrollable physical dynamics. Most current physical attack methods aim to generate robust physical adversarial examples by simulating all possible physical dynamics. When attacking new images or new DNN models, they require expensive manually efforts for simulating physical dynamics and considerable time for iteratively optimizing for each image. To tackle these issues, we propose a class-agnostic and model-agnostic physical adversarial attack model (Meta-Attack), which is able to not only generate robust physical adversarial examples by simulating color and shape distortions, but also generalize to attacking novel images and novel DNN models by accessing a few digital and physical images. To the best of our knowledge, this is the first work to formulate the physical attack as a few-shot learning problem. Here, the training task is redefined as the composition of a support set, a query set, and a target DNN model. Under the few-shot setting, we design a novel class-agnostic and model-agnostic meta-learning algorithm to enhance the generalization ability of our method. Extensive experimental results on two benchmark datasets with four challenging experimental settings verify the superior robustness and generalization of our method by comparing to state-of-the-art physical attack methods. Weiwei Feng, Baoyuan Wu, Tianzhu Zhang 0001, Yong Zhang 0034, Yongdong Zhang 0001 |
ICCV | 1 |
| 2020 | f-NDN: An Extended Architecture of NDN Supporting Flow Transmission ModeabstractAs a promising candidate for future Internet architecture, Named Data Networking (NDN) can achieve significant potential advantages over current TCP/IP based Internet in content distribution and mobility support, etc. However, the communication mode in NDN that one Interest packet for pulling one data packet is likely to incur Interest packets flooding and to cause extremely large-scale Pending Interest Table (PIT) of the NDN router, which may substantially degrade the performance of NDN. Moreover, the absence of predefined connections also induces another challenge for NDN to manage the successive and concurrent requests from consumers efficiently. In this paper, we propose flow-based NDN (f-NDN) architecture capable of supporting flow transmission mode for addressing the aforementioned challenges. In the context of f-NDN, a data flow is defined as an aggregate of data packets with the same name prefix, and a flow Interest packet is introduced to pull a data flow rather than a single data packet. The PIT, CS, and FIB are re-designed to enable f-NDN to operate at the granularity of flows. Bitmap structure aided error handling mechanism is further presented for f-NDN to deal with the flow transmission's uncertain failures. The built-in flow support in f-NDN allows us to conceive a flow-level multi-path transmission regime for balancing the traffic in NDN network and reducing the time consumed for pulling the entire content. Weight-based flow Interest splitting algorithm and optimal rate control algorithm are both proposed for optimizing multi-path transmission. We illustrate the capability of the proposed architecture in supporting flow transmission and multipath by implementing it in both simulator and prototype systems. The evaluation results are also presented to show its achievable performance. Xiaobin Tan, Weiwei Feng, Jinyang Lv, Zhifan Zhao, Jian Yang 0014 |
IEEE Trans. Commun. | 2 |
| 2015 | Evolving Chinese Restaurant Processes for Modeling Evolutionary Traces in Temporal Data
Peng Wang 0028, Chuan Zhou 0001, Peng Zhang 0001, Weiwei Feng, Li Guo 0001, Binxing Fang |
PAKDD (2) | 4 |