EDBT 2026 Demo / reviewers in the wild / expert
Tingsong Jiang
dblp:169/3183
· DBLP profile ↗
39ranked-venue papers
4as first author
31since 2021 · last 2026
0000-0003-1637-2928ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 34 · 4 first-author · 26 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 8 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Parameter-Free Fine-tuning via Redundancy Elimination for Vision Foundation ModelsabstractVision foundation models (VFMs) have demonstrated remarkable capabilities in learning universal visual representations. However, adapting these models to downstream tasks conventionally requires parameter updates, with even parameter-efficient fine-tuning methods necessitating the modification of thousands to millions of weights. In this paper, we investigate the redundancies in the segment anything model (SAM) and then propose a novel parameter-free fine-tuning method. Unlike traditional fine-tuning methods that adjust parameters, our method emphasizes selecting, reusing, and enhancing pre-trained features, offering a new perspective on fine-tuning foundation models. Specifically, we introduce a channel selection algorithm based on the model's output difference to identify redundant and effective channels. By selectively replacing the redundant channels with more effective ones, we filter out less useful features and reuse more task-irrelevant features to downstream tasks, thereby enhancing the task-specific feature representation. Experiments on both out-of-domain and in-domain datasets demonstrate the efficiency and effectiveness of our method in different vision tasks (e.g., image segmentation, depth estimation and image classification). Notably, our approach can seamlessly integrate with existing fine-tuning strategies (e.g., LoRA, Adapter), further boosting the performance of already fine-tuned models. Moreover, since our channel selection involves only model inference, our method significantly reduces GPU memory overhead. Jiahuan Long, Tingsong Jiang, Wen Yao 0001, Yizhe Xiong, Zhengqin Xu, Shuai Jia, Chao Ma 0004 |
AAAI | 2 |
| 2026 | Model-Based Imaginative Planning for Embodied AgentsabstractJunru Song, Hengzhe Jin, Yucong Huang, Tingsong Jiang, Weien Zhou, Feifei Wang, Yang Yang, Ying Wen, Wen Yao. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Junru Song, Hengzhe Jin, Yucong Huang, Tingsong Jiang, Weien Zhou |
ACL (1) | 4 |
| 2026 | Invisibility stickers against LiDAR: Adversarial attacks on point cloud intensity for LiDAR-based object detection
Junqi Wu 0002, Wen Yao 0001, Donghua Wang 0001, Jiahuan Long, Tingsong Jiang, Yang Yang 0123, Chengyin Hu, Chao Ma 0004 |
Comput. Vis. Image Underst. | 7 |
| 2025 | Robust SAM: On the Adversarial Robustness of Vision Foundation ModelsabstractThe Segment Anything Model (SAM) is a widely used vision foundation model with diverse applications, including image segmentation, detection, and tracking. Given SAM's wide applications, understanding its robustness against adversarial attacks is crucial for real-world deployment. However, research on SAM's robustness is still in its early stages. Existing attacks often overlook the role of prompts in evaluating SAM's robustness, and there has been insufficient exploration of defense methods to balance the robustness and accuracy. To address these gaps, this paper proposes an adversarial robustness framework designed to evaluate and enhance the robustness of SAM. Specifically, we introduce a cross-prompt attack method to enhance the attack transferability across different prompt types. Besides attacking, we propose a few-parameter adaptation strategy to defend SAM against various adversarial attacks. To balance robustness and accuracy, we use the singular value decomposition (SVD) to constrain the space of trainable parameters, where only singular values are adaptable. Experiments demonstrate that our cross-prompt attack method outperforms previous approaches in terms of attack success rate on both SAM and SAM 2. By adapting only 512 parameters, we achieve at least a 15% improvement in mean intersection over union (mIoU) against various adversarial attacks. Compared to previous defense methods, our approach enhances the robustness of SAM while maximally maintaining its original performance. Jiahuan Long, Zhengqin Xu, Tingsong Jiang, Wen Yao 0001, Shuai Jia, Chao Ma 0004, Xiaoqian Chen |
AAAI | 3 |
| 2025 | CDUPatch: Color-Driven Universal Adversarial Patch Attack for Dual-Modal Visible-Infrared DetectorsabstractAdversarial patches are widely used to evaluate the robustness of object detection systems in real-world scenarios. These patches were initially designed to deceive single-modal detectors (e.g., visible or infrared) and have recently been extended to target visible-infrared dual-modal detectors. However, existing dual-modal adversarial patch attacks have limited attack effectiveness across diverse physical scenarios. To address this, we propose CDUPatch, a universal cross-modal patch attack against visible-infrared object detectors across scales, views, and scenarios. Specifically, we observe that color variations lead to different levels of thermal absorption, resulting in temperature differences in infrared imaging. Leveraging this property, we propose an RGB-to-infrared adapter that maps RGB patches to infrared patches, enabling unified optimization of cross-modal patches. By learning an optimal color distribution on the adversarial patch, we can manipulate its thermal response and generate an adversarial infrared texture. Additionally, we introduce a multi-scale clipping strategy and construct a new visible-infrared dataset, MSDrone, which contains aerial vehicle images in varying scales and perspectives. These data augmentation strategies enhance the robustness of our patch in real-world conditions. Experiments on four benchmark datasets (e.g., DroneVehicle, LLVIP, VisDrone, MSDrone) show that our method outperforms existing patch attacks in the digital domain. Extensive physical tests further confirm strong transferability across scales, views, and scenarios. Attack demos are provided in the supplementary materials. Jiahuan Long, Wen Yao 0001, Tingsong Jiang, Shuai Jia, Junqi Wu 0002, Xiaohu Zheng, Chao Ma 0004 |
ACM Multimedia | 3 |
| 2025 | Optimizing Latent Variables in Integrating Transfer and Query Based Attack FrameworkabstractBlack-box adversarial attacks can be categorized into transfer-based and query-based attacks. The former usually has poor transfer performance due to the mismatch between the architectures of models, while the query-based attacks require massive queries and high dimensional optimization variables. In order to solve the above problems, we propose a novel attack framework integrating the advantages of transfer- and query-based attacks, where the framework is divided into two phases: training the adversarial generator and executing the black-box attacks. In the first stage, a generator is trained by the adversarial loss function so that it can output adversarial perturbation, where the latent variables are designed as the input of the generator to reduce the dimension of the optimization variables. In the second stage, based on the trained generator, we further employ a particle swarm optimization algorithm to optimize the latent variables so that the generator can output the perturbation that can achieve a successful attack. Extensive experiments are performed on the ImageNet dataset, and the results demonstrate that the proposed framework can obtain better attack performance compared with a number of the state-of-the-art black-box adversarial attack methods. In addition, we show the flexibility of the proposed framework by extending the experiment for few-pixel attacks. Chao Li 0076, Tingsong Jiang, Handing Wang, Wen Yao 0001, Donghua Wang 0001 |
IEEE Trans. Pattern Anal. Mach. Intell. | 2 |
| 2025 | ${A^{3}D}$A3D: A Platform of Searching for Robust Neural Architectures and Efficient Adversarial AttacksabstractDue to the urgent need of the robustness of deep neural networks (DNN), numerous existing open-sourced tools or platforms are developed to evaluate the robustness of DNN models by ensembling the majority of adversarial attack or defense algorithms. Unfortunately, current platforms can neither optimize the DNN architectures nor the configuration of adversarial attacks to further enhance the model robustness or the performance of adversarial attacks. To alleviate these problems, in this paper, we propose a novel platform called auto-adversarial attack and defense ($A^{3}D$A3D), which can help search for robust neural network architectures and efficient adversarial attacks. $A^{3}D$A3D integrates multiple neural architecture search methods to find robust architectures under different robustness evaluation metrics. Besides, we provide multiple optimization algorithms to search for efficient adversarial attacks. In addition, we combine auto-adversarial attack and defense together to form a unified framework. Among auto adversarial defense, the searched efficient attack can be used as the new robustness evaluation to further enhance the robustness. In auto-adversarial attack, the searched robust architectures can be utilized as the threat model to help find stronger adversarial attacks. Experiments on CIFAR10, CIFAR100, and ImageNet datasets demonstrate the feasibility and effectiveness of the proposed platform. Wen Yao 0001, Tingsong Jiang, Chao Li 0076, Xiaoqian Chen |
IEEE Trans. Pattern Anal. Mach. Intell. | 3 |
| 2025 | Gradient-based sparse voxel attacks on point cloud object detection
Junqi Wu 0002, Wen Yao 0001, Shuai Jia, Tingsong Jiang, Weien Zhou, Chao Ma 0004, Xiaoqian Chen |
Pattern Recognit. | 4 |
| 2025 | Universal Multi-View Black-Box Attack Against Object Detectors via Layout OptimizationabstractObject detectors have demonstrated vulnerability to adversarial examples crafted by small perturbations that can deceive the object detector. Existing adversarial attacks mainly focus on white-box attacks and are merely valid at a specific viewpoint, while the universal multi-view black-box attack is less explored, limiting their generalization in practice. In this paper, we propose a novel universal multi-view black-box attack against object detectors, which optimizes a universal adversarial UV texture constructed by multiple image stickers for a 3D object via the designed layout optimization algorithm. Specifically, we treat the placement of image stickers on the UV texture as a circle-based layout optimization problem, whose objective is to find the optimal circle layout filled with image stickers so that it can deceive the object detector under the multi-view scenario. To ensure reasonable placement of image stickers, two constraints are elaborately devised. To optimize the layout, we adopt the random search algorithm enhanced by the devised important-aware selection strategy to find the most appropriate image sticker for each circle from the image sticker pools. Extensive experiments conducted on four common object detectors suggested that the detection performance decreases by a large magnitude of 74.29% on average in multi-view scenarios. Additionally, a novel evaluation tool based on the photo-realistic simulator is designed to assess the texture-based attack fairly. Donghua Wang 0001, Wen Yao 0001, Tingsong Jiang, Chao Li 0076, Xiaoqian Chen |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2025 | Improving the Transferability of Adversarial Examples by Feature AugmentationabstractAdversarial transferability is a significant property of adversarial examples, which renders the adversarial example capable of attacking unknown models. However, the models with different architectures on the same task would concentrate on different information, which weakens adversarial transferability. To enhance the adversarial transferability, input transformation-based attacks perform random transformation over input to find a better result that can resist such transformations, but these methods ignore the model discrepancy; ensemble attacks fuse multiple models to shrink the search space to ensure that the found adversarial examples work on these models, but ensemble attacks are resource-intensive. In this article, we propose a simple but effective feature augmentation attack (FAUG) method to improve adversarial transferability. We dynamically add random noise to intermediate features of the target model during the generation of adversarial examples, thereby avoiding overfitting the target model. Specifically, we first explore the noise tolerance of the model and disclose the discrepancy under different layers and noise strengths. Then, based on that analysis, we devise a dynamic random noise generation method, which determines noise strength according to the produced features in the mini-batch. Finally, we exploit the gradient-based attack algorithm on featureaugmented models, resulting in better adversarial transferability without introducing extra computation costs. Extensive experiments conducted on the ImageNet dataset across CNN and Transformer models corroborate the efficacy of our method, e.g., we achieve improvement of +30.67% and +5.57% on input transformation-based attacks and combination methods, respectively. Donghua Wang 0001, Wen Yao 0001, Tingsong Jiang, Xiaohu Zheng, Junqi Wu 0002 |
IEEE Trans. Neural Networks Learn. Syst. | 3 |
| 2024 | QRPatch: A Deceptive Texture-Based Black-Box Adversarial Attacks with Genetic AlgorithmabstractPatch-based attacks are a major black-box attack paradigm, where there is no limit to the intensity of the perturbation. The existing patch-based attack methods focus on obtaining the optimal position, shape, and pixel values against adversarial patches, however, the generated patch looks conspicuous and makes it easy to attract people's attention. Quick response(QR) code has been widely used in various fields, such as image copyright protection, stored image information. Further, it does not get noticed when a QR code is attached to the image. Therefore, we propose a deceptive texture-based black-box adversarial attack method to address the above problem. Specifically, we use the QR code pattern as the basis of the adversarial patches. Then, we model the adversarial attack as a discrete optimization problem, where the optimization variables are designed as the center coordinates of the patch pasting locations and the pixel values. Further, an upsampling technique is introduced to reduce the dimension of the optimization variables. Finally, genetic algorithm is employed as the optimizer to obtain the optimal parameter of the patch. In order to verify the effectiveness of the proposed method, we compare a number of the state-of-the-art patch-based attack methods on the ImageNet dataset, and the experimental results show that the proposed method can effectively generate deceptive adversarial examples in both digital and physical space and obtain the best attack performance, especially for the defense models. Chao Li 0076, Wen Yao 0001, Handing Wang, Tingsong Jiang, Donghua Wang 0001 |
CEC | 4 |
| 2024 | PapMOT: Exploring Adversarial Patch Attack Against Multiple Object Tracking
Jiahuan Long, Tingsong Jiang, Wen Yao 0001, Shuai Jia, Weien Zhou, Chao Ma 0004, Xiaoqian Chen |
ECCV (51) | 2 |
| 2024 | HeteroMorpheus: Universal Control Based on Morphological Heterogeneity ModelingabstractIn the field of robotic control, designing individual controllers for each robot leads to high computational costs. Universal control policies, applicable across diverse robot morphologies, promise to mitigate this challenge. Predominantly, models based on Graph Neural Networks (GNN) and Transformers are employed, owing to their effectiveness in capturing relational dynamics across a robot’s limbs. However, these models typically employ homogeneous graph structures that overlook the functional diversity of different limbs. To bridge this gap, we introduce HeteroMorpheus, a novel method based on heterogeneous graph Transformer. This method uniquely addresses limb heterogeneity, fostering better representation of robot dynamics of various morphologies. Through extensive experiments we demonstrate the superiority of HeteroMorpheus against state-of-the-art methods in the capability of policy generalization, including zero-shot generalization and sample-efficient transfer to unfamiliar robot morphologies. Yang Yang 0123, Junru Song, Wei Peng 0010, Weien Zhou, Tingsong Jiang, Wen Yao 0001 |
IJCNN | 6 |
| 2024 | Black-box adversarial patch attacks using differential evolution against aerial imagery object detectors
Guijian Tang, Wen Yao 0001, Chao Li 0076, Tingsong Jiang, Shaowu Yang |
Eng. Appl. Artif. Intell. | 4 |
| 2024 | Adversarial patch-based false positive creation attacks against aerial imagery object detectors
Guijian Tang, Wen Yao 0001, Tingsong Jiang |
Neurocomputing | 3 |
| 2024 | Multi-objective evolutionary search of variable-length composite semantic perturbations
Wen Yao 0001, Tingsong Jiang, Xiaoqian Chen |
Inf. Sci. | 3 |
| 2024 | Adversarial infrared blocks: A multi-view black-box attack to thermal infrared detectors in physical world
Chengyin Hu, Weiwen Shi, Tingsong Jiang, Wen Yao 0001, Ling Tian, Xiaoqian Chen, Jingzhi Zhou |
Neural Networks | 3 |
| 2024 | Adversarial Infrared Curves: An attack on infrared pedestrian detectors in the physical world
Chengyin Hu, Weiwen Shi, Wen Yao 0001, Tingsong Jiang, Ling Tian, Xiaoqian Chen |
Neural Networks | 4 |
| 2024 | An invisible, robust copyright protection method for DNN-generated content
Donghua Wang 0001, Wen Yao 0001, Tingsong Jiang, Weien Zhou, Lang Lin, Xiaoqian Chen |
Neural Networks | 3 |
| 2024 | Efficient search of comprehensively robust neural architectures via multi-fidelity evaluation
Wen Yao 0001, Tingsong Jiang, Xiaoqian Chen |
Pattern Recognit. | 3 |
| 2024 | AdvOps: Decoupling adversarial examples
Donghua Wang 0001, Wen Yao 0001, Tingsong Jiang, Xiaoqian Chen |
Pattern Recognit. | 3 |
| 2024 | Improving Transferability of Universal Adversarial Perturbation With Feature DisruptionabstractDeep neural networks (DNNs) are shown to be vulnerable to universal adversarial perturbations (UAP), a single quasi-imperceptible perturbation that deceives the DNNs on most input images. The current UAP methods can be divided into data-dependent and data-independent methods. The former exhibits weak transferability in black-box models due to overly relying on model-specific features. The latter shows inferior attack performance in white-box models as it fails to exploit the model's response information to benign images. To address the above issues, this paper proposes a novel universal adversarial attack to generate UAP with strong transferability by disrupting the model-agnostic features (e.g., edges or simple texture), which are invariant to the models. Specifically, we first devise an objective function to weaken the significant channel-wise features and strengthen the less significant channel-wise features, which are partitioned by the designed strategy. Furthermore, the proposed objective function eliminates the dependency on labeled samples, allowing us to utilize out-of-distribution (OOD) data to train UAP. To enhance the attack performance with limited training samples, we exploit the average gradient of the mini-batch input to update the UAP iteratively, which encourages the UAP to capture the local information inside the mini-batch input. In addition, we introduce the momentum term to accumulate the gradient information at each iterative step for the purpose of perceiving the global information over the training set. Finally, extensive experimental results demonstrate that the proposed methods outperform the existing UAP approaches. Additionally, we exhaustively investigate the transferability of the UAP across models, datasets, and tasks. Donghua Wang 0001, Wen Yao 0001, Tingsong Jiang, Xiaoqian Chen |
IEEE Trans. Image Process. | 3 |
| 2023 | RFLA: A Stealthy Reflected Light Adversarial Attack in the Physical WorldabstractPhysical adversarial attacks against deep neural networks (DNNs) have recently gained increasing attention. The current mainstream physical attacks use printed adversarial patches or camouflage to alter the appearance of the target object. However, these approaches generate conspicuous adversarial patterns that show poor stealthiness. Another physical deployable attack is the optical attack, featuring stealthiness while exhibiting weakly in the daytime with sunlight. In this paper, we propose a novel Reflected Light Attack (RFLA), featuring effective and stealthy in both the digital and physical world, which is implemented by placing the color transparent plastic sheet and a paper cut of a specific shape in front of the mirror to create different colored geometries on the target object. To achieve these goals, we devise a general framework based on the circle to model the reflected light on the target object. Specifically, we optimize a circle (composed of a coordinate and radius) to carry various geometrical shapes determined by the optimized angle. The fill color of the geometry shape and its corresponding transparency are also optimized. We extensively evaluate the effectiveness of RFLA on different datasets and models. Experiment results suggest that the proposed method achieves over 99% success rate on different datasets and models in the digital world. Additionally, we verify the effectiveness of the proposed method in different physical environments by using sunlight or a flashlight. Donghua Wang 0001, Wen Yao 0001, Tingsong Jiang, Chao Li 0076, Xiaoqian Chen |
ICCV | 3 |
| 2023 | A multi-objective memetic algorithm for automatic adversarial attack optimization design
Wen Yao 0001, Tingsong Jiang, Xiaoqian Chen |
Neurocomputing | 3 |
| 2023 | Adversarial patch attacks against aerial imagery object detectors
Guijian Tang, Tingsong Jiang, Weien Zhou, Chao Li 0076, Wen Yao 0001 |
Neurocomputing | 2 |
| 2023 | Differential evolution based dual adversarial camouflage: Fooling human eyes and object detectors
Wen Yao 0001, Tingsong Jiang, Donghua Wang 0001, Xiaoqian Chen |
Neural Networks | 3 |
| 2023 | Adaptive momentum variance for attention-guided sparse adversarial attacks
Chao Li 0076, Wen Yao 0001, Handing Wang, Tingsong Jiang |
Pattern Recognit. | 4 |
| 2023 | Natural Weather-Style Black-Box Adversarial Attacks Against Optical Aerial DetectorsabstractMost existing adversarial attack methods against detectors involve adding adversarial perturbations to benign images to synthesiz adversarial examples. However, directly applying these methods, originally designed for natural image detectors, to optical aerial image detectors can lead to perturbations that appear unnatural and suspicious to human eyes, owing to intrinsic dissimilarities between these two types of images. Inspired by the fact that the captured optical aerial images are heavily affected by weather conditions, this paper proposes a novel method for conducting adversarial attacks against optical aerial detectors by leveraging natural weather-style perturbations. Compared to existing methods, our scheme produces more natural and stealthy adversarial examples. To enhance the practicality of the proposed method in real-world scenarios, we implement the attacks in black-box settings where only the model’s predictions are accessible. Specifically, we formulate the generation of adversarial weather perturbations in black-box as an optimization problem and effectively solve it using the Differential Evolution (DE) algorithm. Through extensive experiments, we verify the effectiveness of our method and investigate the transferability of generated adversarial examples across different models. In light of the significant generalization and effectiveness of our method, we generate and release the first dataset with adversarial weather-style perturbations based on the DOTA dataset, which we abbreviate as DOTA-W. This dataset serves as a valuable resource for evaluating and improving the robustness of optical aerial detectors. The code and dataset have been released at https://github.com/tang-agui/attADs-AWP. Guijian Tang, Wen Yao 0001, Tingsong Jiang, Weien Zhou, Yang Yang 0123, Donghua Wang 0001 |
IEEE Trans. Geosci. Remote. Sens. | 3 |
| 2022 | FCA: Learning a 3D Full-Coverage Vehicle Camouflage for Multi-View Physical Adversarial AttackabstractPhysical adversarial attacks in object detection have attracted increasing attention. However, most previous works focus on hiding the objects from the detector by generating an individual adversarial patch, which only covers the planar part of the vehicle’s surface and fails to attack the detector in physical scenarios for multi-view, long-distance and partially occluded objects. To bridge the gap between digital attacks and physical attacks, we exploit the full 3D vehicle surface to propose a robust Full-coverage Camouflage Attack (FCA) to fool detectors. Specifically, we first try rendering the nonplanar camouflage texture over the full vehicle surface. To mimic the real-world environment conditions, we then introduce a transformation function to transfer the rendered camouflaged vehicle into a photo-realistic scenario. Finally, we design an efficient loss function to optimize the camouflage texture. Experiments show that the full-coverage camouflage attack can not only outperform state-of-the-art methods under various test cases but also generalize to different environments, vehicles, and object detectors. Donghua Wang 0001, Tingsong Jiang, Weien Zhou, Zhiqiang Gong, Wen Yao 0001, Xiaoqian Chen |
AAAI | 2 |
| 2022 | Deep Monte Carlo Quantile Regression for Quantifying Aleatoric Uncertainty in Physics-informed Temperature Field ReconstructionabstractFor the temperature field reconstruction (TFR), a complex image-to-image regression problem, the convolutional neural network (CNN) is a powerful surrogate model due to the convolutional layer's good image feature extraction ability. However, a lot of labeled data is needed to train CNN, and the common CNN can not quantify the aleatoric uncertainty caused by data noise. In actual engineering, the noiseless and labeled training data is hardly obtained for the TFR. To solve these two problems, this paper proposes a deep Monte Carlo quantile regression (Deep MC-QR) method for reconstructing the temperature field and quantifying aleatoric uncertainty caused by data noise. On the one hand, the Deep MC-QR method uses physical knowledge to guide the training of CNN. Thereby, the Deep MC-QR method can reconstruct an accurate TFR surrogate model without any labeled training data. On the other hand, the Deep MC-QR method constructs a quantile level image for each input in each training epoch. Then, the trained CNN model can quantify aleatoric uncertainty by quantile level image sampling during the prediction stage. Finally, the effectiveness of the proposed Deep MC-QR method is validated by many experiments, and the influence of data noise on TFR is analyzed. Xiaohu Zheng, Wen Yao 0001, Zhiqiang Gong, Yunyang Zhang, Xiaoyu Zhao 0002, Tingsong Jiang |
IJCNN | 6 |
| 2022 | An Approximated Gradient Sign Method Using Differential Evolution for Black-Box Adversarial AttackabstractRecent studies show that deep neural networks are vulnerable to adversarial attacks in the form of subtle perturbations to the input image, which leads the model to output wrong prediction. Such an attack can easily succeed by the existing white-box attack methods, where the perturbation is calculated based on the gradient of the target network. Unfortunately, the gradient is often unavailable in the real-world scenarios, which makes the black-box adversarial attack problems practical and challenging. In fact, they can be formulated as high-dimensional black-box optimization problems at the pixel level. Although evolutionary algorithms are well known for solving black-box optimization problems, they cannot efficiently deal with the high-dimensional decision space. Therefore, we propose an approximated gradient sign method using differential evolution (DE) for solving black-box adversarial attack problems. Unlike most existing methods, it is novel that the proposed method searches the gradient sign rather than the perturbation by a DE algorithm. Also, we transform the pixel-based decision space into a dimension-reduced decision space by combining the pixel differences from the input image to neighbor images, and two different techniques for selecting neighbor images are introduced to build the transferred decision space. In addition, six variants of the proposed method are designed according to the different neighborhood selection and optimization search strategies. Finally, the performance of the proposed method is compared with a number of the state-of-the-art adversarial attack algorithms on CIFAR-10 and ImageNet datasets. The experimental results suggest that the proposed method shows superior performance for solving black-box adversarial attack problems, especially nontargeted attack problems. Chao Li 0076, Handing Wang, Jun Zhang 0052, Wen Yao 0001, Tingsong Jiang |
IEEE Trans. Evol. Comput. | 5 |
| 2018 | Revisiting Distant Supervision for Relation Extraction
Tingsong Jiang, Jing Liu 0022, Chin-Yew Lin, Zhifang Sui |
LREC | 1 |
| 2016 | Towards Time-Aware Knowledge Graph CompletionabstractKnowledge graph (KG) completion adds new facts to a KG by making inferences from existing facts. Most existing methods ignore the time information and only learn from time-unknown fact triples. In dynamic environments that evolve over time, it is important and challenging for knowledge graph completion models to take into account the temporal aspects of facts. In this paper, we present a novel time-aware knowledge graph completion model that is able to predict links in a KG using both the existing facts and the temporal information of the facts. To incorporate the happening time of facts, we propose a time-aware KG embedding model using temporal order information among facts. To incorporate the valid time of facts, we propose a joint time-aware inference model based on Integer Linear Programming (ILP) using temporal consistencyinformationasconstraints. Wefurtherintegratetwomodelstomakefulluseofglobal temporal information. We empirically evaluate our models on time-aware KG completion task. Experimental results show that our time-aware models achieve the state-of-the-art on temporal facts consistently. Tingsong Jiang, Tianyu Liu 0001, Tao Ge 0001, Lei Sha, Baobao Chang, Sujian Li, Zhifang Sui |
COLING | 1 |
| 2016 | Encoding Temporal Information for Time-Aware Link PredictionabstractMost existing knowledge base (KB) embedding methods solely learn from time-unknown fact triples but neglect the temporal information in the knowledge base.In this paper, we propose a novel time-aware KB embedding approach taking advantage of the happening time of facts.Specifically, we use temporal order constraints to model transformation between time-sensitive relations and enforce the embeddings to be temporally consistent and more accurate.We empirically evaluate our approach in two tasks of link prediction and triple classification.Experimental results show that our method outperforms other baselines on the two tasks consistently. Tingsong Jiang, Tianyu Liu 0001, Tao Ge 0001, Lei Sha, Sujian Li, Baobao Chang, Zhifang Sui |
EMNLP | 1 |
| 2016 | Capturing Argument Relationship for Chinese Semantic Role LabelingabstractIn this paper, we capture the argument relationships for Chinese semantic role labeling task, and improve the task's performance with the help of argument relationships.We split the relationship between two candidate arguments into two categories: (1) Compatible arguments: if one candidate argument belongs to a given predicate, then the other is more likely to belong to the same predicate; (2) Incompatible arguments: if one candidate argument belongs to a given predicate, then the other is less likely to belong to the same predicate.However, previous works did not explicitly model argument relationships.We use a simple maximum entropy classifier to capture the two categories of argument relationships and test its performance on the Chinese Proposition Bank (CPB).The experiments show that argument relationships is effective in Chinese semantic role labeling task. Lei Sha, Sujian Li, Baobao Chang, Zhifang Sui, Tingsong Jiang |
EMNLP | 5 |
| 2015 | Recognizing Textual Entailment Using Probabilistic InferenceabstractRecognizing Text Entailment (RTE) plays an important role in NLP applications including question answering, information retrieval, etc.In recent work, some research explore "deep" expressions such as discourse commitments or strict logic for representing the text.However, these expressions suffer from the limitation of inference inconvenience or translation loss.To overcome the limitations, in this paper, we propose to use the predicate-argument structures to represent the discourse commitments extracted from text.At the same time, with the help of the YAGO knowledge, we borrow the distant supervision technique to mine the implicit facts from the text.We also construct a probabilistic network for all the facts and conduct inference to judge the confidence of each fact for RTE.The experimental results show that our proposed method achieves a competitive result compared to the previous work. Lei Sha, Sujian Li, Baobao Chang, Zhifang Sui, Tingsong Jiang |
EMNLP | 5 |
| 2015 | Chinese Semantic Role Labeling with Bidirectional Recurrent Neural NetworksabstractTraditional approaches to Chinese Seman-tic Role Labeling (SRL) almost heavily re-ly on feature engineering. Even worse, the long-range dependencies in a sentence can hardly be modeled by these method-s. In this paper, we introduce bidirection-al recurrent neural network (RNN) with long-short-term memory (LSTM) to cap-ture bidirectional and long-range depen-dencies in a sentence with minimal fea-ture engineering. Experimental results on Chinese Proposition Bank (CPB) show a significant improvement over the state-of-the-art methods. Moreover, our model makes it convenient to introduce hetero-geneous resource, which makes a further improvement on our experimental perfor-mance. 1 Tingsong Jiang, Baobao Chang, Zhifang Sui |
EMNLP | 2 |
| 2015 | ERSOM: A Structural Ontology Matching Approach Using Automatically Learned Entity RepresentationabstractAs a key representation model of knowledge, ontology has been widely used in a lot of NLP related tasks, such as semantic parsing, information extraction and text mining etc.In this paper, we study the task of ontology matching, which concentrates on finding semantically related entities between different ontologies that describe the same domain, to solve the semantic heterogeneity problem.Previous works exploit different kinds of descriptions of an entity in ontology directly and separately to find the correspondences without considering the higher level correlations between the descriptions.Besides, the structural information of ontology haven't been utilized adequately for ontology matching.We propose in this paper an ontology matching approach, named ERSOM, which mainly includes an unsupervised representation learning method based on the deep neural networks to learn the general representation of the entities and an iterative similarity propagation method that takes advantage of more abundant structure information of the ontology to discover more mappings.The experimental results on the datasets from Ontology Alignment Evaluation Initiative (OAEI 1 ) show that ER-SOM achieves a competitive performance compared to the state-of-the-art ontology matching systems. Chuncheng Xiang, Tingsong Jiang, Baobao Chang, Zhifang Sui |
EMNLP | 2 |
| 2014 | Event Schema Induction Based on Relational Co-occurrence over Multiple Documents
Tingsong Jiang, Lei Sha, Zhifang Sui |
NLPCC | 1 |