EDBT 2026 Demo / reviewers in the wild / expert
Zeyu Zhao 0006
dblp:183/9558-6
· DBLP profile ↗
9ranked-venue papers
5as first author
9since 2021 · last 2026
0000-0002-3008-0457ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 4 · 3 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | When Does Adversarial Training Hurt Adversarial Robustness in Phase Translation of Training Data?
Ke Xu 0003, Xinghao Jiang, Tanfeng Sun, Zeyu Zhao 0006 |
ICIC (15) | 5 |
| 2026 | INN-RAE: Reversible adversarial examples based on invertible neural networks for facial protection
Zeyu Zhao 0006, Ke Xu 0003, Laijin Meng, Tanfeng Sun, Xinghao Jiang |
Expert Syst. Appl. | 1 |
| 2026 | ASGA: Attention-Based Sparse Global Attack to Video Action Recognition
Zeyu Zhao 0006, Ke Xu 0003, Tanfeng Sun, Xinghao Jiang |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2026 | SRAP: Robust and Transferable Self-Reversible Adversarial Patch for Image Privacy ProtectionabstractReversible adversarial examples offer adequate protection against malicious deep model identification and analysis. However, current methods still face challenges in terms of transferability and robustness, limiting their practical applicability. We introduce a novel technique for generating reversible adversarial examples utilizing Self-Reversible Adversarial Patch (SRAP) to address this. This approach significantly enhances the transferability and robustness of reversible adversarial examples against standard image processing techniques and adversarial defense methods. Specifically, we present a method for crafting adversarial patches that are small, non-overlapping, and adaptively integrated into specific regions. These adversarial patches are seamlessly combined with a reversible data-hiding technique that relies on prediction error expansion, resulting in adversarial examples with superior robustness and transferability. Experimental results indicate that our method achieves a remarkable transferability rate of up to 90% or higher between different models. Additionally, it exhibits strong robustness against image processing methods and adversarial defense strategies. Furthermore, our adversarial examples demonstrate an impressive attack success rate of 88% on commercial APIs, highlighting the effectiveness and practicality of our approach. Zeyu Zhao 0006, Ke Xu 0003, Tanfeng Sun, Xinghao Jiang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Feature-Aware Transferable Adversarial Attacks on Visual Object TrackingabstractVisual object tracking is susceptible to adversarial attacks, posing significant security concerns for numerous application systems. Previous attack methods focused on white-box and untargeted attacks against response map. However, obtaining the tracking model in real-world scenarios is challenging, and the resulting adversarial trajectories are often unrealistic, making the attacks easily detectable. This paper proposes a Feature-aware Transferable Adversarial Patch (FTAP) that induces any black-box trackers to follow controllable and smooth trajectories. Tracker Following Assurance module is designed to manipulate bounding boxes to be valid and tightly align with the fake target. The movement of the tracker can be precisely controlled, resulting in adversarial trajectories stable and closely resemble natural trajectories, thereby reducing the risk of detection. The adversarial perturbation is generated solely from the initial template and applied to each frame. Consequently, the well-optimized generator can output universal adversarial patch capable of attacking any video without requiring additional computations. The intermediate layer features are corrupted to make the characteristics of the fake target closer to those of ground truth. Experimental results demonstrate that the proposed FTAP achieves state-of-the-art black-box attack performance and transferability across various tracker architectures. Mengdi Dong, Ke Xu 0003, Xinghao Jiang, Zeyu Zhao 0006, Tanfeng Sun |
IEEE Trans. Circuits Syst. Video Technol. | 4 |
| 2025 | HEVC Video Adversarial Samples Detection via Joint Features of Compression and Pixel DomainsabstractDeep learning models are currently under significant threat from adversarial attacks, while adversarial detection represents an effective means of countering such assaults. However, existing adversarial detection techniques are deficient in localizing video adversarial frames, leading to poor performance on sparse video adversarial attacks. This paper presents an approach for detecting adversarial perturbations in videos based on fusion features derived from the video compression and RGB domain. Our research begins by examining how the introduction of extensive non-natural noise during video adversarial attacks severely disrupts the spatial structure of individual frames and the motion information between frames. This disruption culminates in unnatural variations in the Coding Tree Units (CTU) partitioning during the HEVC video encoding process. Then meticulously mapping the positions and partitioning information of coding units (CU), predictive units (PU), and transformation units (TU) onto specific values and sizes, constituting the video’s Compression Domain Units (CDU) features. Finally, a dual-path network utilizing both the video’s CDU features and the decoded frames RGB features is employed for detecting video adversarial samples. Extensive experiments are conducted to verify the performance. The results show that the proposed scheme outperforms or rivals the state-of-the-art methods in video adversarial detection. Zeyu Zhao 0006, Yueneng Wang, Ke Xu 0003, Tanfeng Sun, Xinghao Jiang |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | A Robust Coverless Video Steganography Based on the Similarity of Inter-FramesabstractWith a deeper understanding of the security issues in steganography, coverless steganography has become a hotspot due to no modification to the carriers. However, the existing coverless video steganographic algorithms have considered a few types of video attacks. In this paper, a robust coverless video steganography based on the similarity of inter-frames is proposed. First, a public video database is selected and preprocessed to construct a Secret Communication Video Database (SCVD). The similarity score between the first and last frames is calculated for video sorting to utilize the temporal characteristics of videos. After that, the mapping table between the secret information and the SCVD is designed for both senders and receivers. Finally, each secret information segment can be represented by one video sequence in the SCVD according to the mapping table to accomplish the data hiding and extraction. Experimental results show that the proposed method performs much better in capacity, robustness, and security than the state-of-the-art methods. It is worth mentioning that the proposed method overcomes the security issue of transmitting a large amount of auxiliary information in coverless video steganographic algorithms. Laijin Meng, Xinghao Jiang, Tanfeng Sun, Zeyu Zhao 0006, Qiang Xu 0007 |
IEEE Trans. Multim. | 4 |
| 2023 | Transferable Black-Box Attack Against Face Recognition With Spatial Mutable Adversarial PatchabstractDeep Neural Networks (DNNs) are vulnerable to adversarial patch attacks, which raises security concerns for face recognition systems using DNNs. Previous attack methods focus on the perturbation texture and generate adversarial patches with fixed shapes at random or pre-designed locations, which causes poor adversarial transferability. This paper proposes a Spatial Mutable Adversarial Patch (SMAP) method to generate a dynamic mutable patch to be injected into the face. In the proposed SMAP, the texture, position and shape of the patch are optimized simultaneously and the patch generation pipeline is end-to-end differentiable. Specifically, a Patch Location Selection Scheme is designed to find the critical patch position with the most significant influence on the target identity by the step-based gradient search. By innovatively bridging the pre-defined mask and the dynamic update of the patch, the patch position and shape are changed based on the affine transformation and sampling mechanism in each iteration, which maintains the importance of the injected patch to the adversarial objective. To evaluate the vulnerability of face recognition models, we explore more threatening impersonation attacks under the black-box setting and design a strict evaluation metric that aligns with the real-world scenario. Extensive experiments show that the proposed SMAP improves attack performance across various face recognition models and datasets. Moreover, SMAP achieves better transferability on commercial face recognition systems than existing methods. Haotian Ma 0001, Ke Xu 0003, Xinghao Jiang, Zeyu Zhao 0006, Tanfeng Sun |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2022 | Research on video adversarial attack with long living cycleabstractIn recent years, the vulnerability of networks has attracted the attention of researchers. However, in these methods, the impact of video compression coding on the added adversarial perturbation, i.e., the robustness of the video adversarial example, is not considered. When an adversarial sample is just generated, its attack capability is the strongest. However, with multiple video encoding and video decoding in Internet transmission, the added adversarial disturbance will be continuously eliminated, eventually leading to the attack on the adversarial sample performance disappearing. We define this phenomenon as the decay of the lifetime of adversarial examples. We propose an adversarial attack method based on optimized integer space to resist this performance degradation. The robustness of anti-coding, the visual concealment, and the attack success rate are all considered during the attack process. In addition, we have also reduced the rounding loss caused by normalization in the deep neural network model process. The contributions of our methods are 1) We show the performance degradation caused by video compression coding on existing video adversarial attack methods, which seems an effective way for detecting of defending video adversarial examples. 2) A robust video adversarial attack method is proposed to resist video compression coding. The experiment shows that our method performs better on the robustness of anti-coding, visual concealment, and attack success rate. Zeyu Zhao 0006, Ke Xu 0003, Xinghao Jiang, Tanfeng Sun |
UAI | 1 |