EDBT 2026 Demo / reviewers in the wild / expert
Ruijie Yang
dblp:198/7804
· DBLP profile ↗
20ranked-venue papers
5as first author
20since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 8 · 2 first-author · 8 since 2021Artificial intelligence and machine learning · 6 · 6 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 2 first-author · 5 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Perceptual Distortion Reduction Framework: Toward Generating Adversarial Examples With High Perceptual Quality and Attack Success Rate
Ruijie Yang, Yuanfang Guo, Ruikui Wang, Jiantao Zhou 0001, Yunhong Wang 0001 |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2025 | GammaDiff: Deep Diffusion Models for Gamma Index Synthesis in Radiation TherapyabstractRadiation therapy is a cornerstone of tumor treatment, and accurate prediction of the gamma passing rate (GPR) for intensity-modulated radiation therapy (IMRT) plans is clinically critical. Existing AI-based predictors often lack locational information of dose accuracy. We propose GammaDiff, a diffusion-model framework for gamma distribution prediction, with three main contributions: (1) an advanced noise-prediction network that fuses CNNs for local features with transformers for global context, achieving multi-scale modeling with efficient computation; (2) a multi-scale fusion U-Net (MFUnet) that em-beds fluence maps structure via hierarchical feature integration into the noise-prediction process; and (3) a two-stage diffusion procedure in which the forward process progressively adds noise to form training samples, and the reverse process uses the opti-mized predictor to reconstruct high-fidelity gamma distributions. Extensive experiments show that GammaDiff outperforms prior methods on PSNR and SSIM, with notably higher sensitivity to failure cases, providing a more robust, reliable AI solution for plan-quality verification in radiation therapy. Yuquan Wang, Peisen Zhao, Ruijie Yang, Hongxia Deng |
BIBM | 4 |
| 2025 | Generating Editable Head Avatars with 3D Gaussian GANsabstractGenerating animatable and editable 3D head avatars is essential for various applications in computer vision and graphics. Traditional 3D-aware generative adversarial networks (GANs), often using implicit fields like Neural Radiance Fields (NeRF), achieve photo-realistic and view-consistent 3D head synthesis. However, these methods face limitations in deformation flexibility and editability, hindering the creation of lifelike and easily modifiable 3D heads. We propose a novel approach that enhances the editability and animation control of 3D head avatars by incorporating 3D Gaussian Splatting (3DGS) as an explicit 3D representation. This method enables easier illumination control and improved editability. Central to our approach is the Editable Gaussian Head (EG-Head) model, which combines a 3D Morphable Model (3DMM) with texture maps, allowing precise expression control and flexible texture editing for accurate animation while preserving identity. To capture complex non-facial geometries like hair, we use an auxiliary set of 3DGS and tri-plane features. Extensive experiments demonstrate that our approach delivers high-quality 3D-aware synthesis with state-of-the-art controllability. Our code and models are available at https://github.com/liguohao96/EGG3D. Guohao Li 0010, Hongyu Yang 0001, Yifang Men, Di Huang 0001, Weixin Li 0001, Ruijie Yang, Yunhong Wang 0001 |
ICASSP | 6 |
| 2025 | Feature Perturbation Agent based Adversarial Attack Method for Weakly Supervised Video Anomaly DetectionabstractWeakly supervised video anomaly detection (WS-VAD) techniques, based on video backbone models, are widely used in surveillance but are vulnerable to adversarial attacks. However, directly applying existing methods causes high memory consumption and low efficiency, and adversarial attacks on WS-VAD models have yet to be specifically studied. In this paper, we pioneer to propose a two-staged Feature Perturbation Agent based Adversarial Attack (FPAgent) method for WS-VAD. To better deceive detection models, we explore the deceivable feature spaces. To describe the locations of the deceivable feature spaces, we propose a feature perturbation agent, which also transforms the complex video-level attack into a simple segment-level attack. Besides, we propose a perturbation guider strategy to guide the feature vectors into the deceivable feature spaces, by computing the perturbation from the first segment of each video. The experiments have verified the effectiveness, as well as the attack efficiency and low memory consumption of our method. Zhen Yang 0037, Yuanfang Guo, Ruijie Yang, Di Huang 0001, Jiantao Zhou 0001 |
ISCAS | 3 |
| 2025 | Endo-CLIP: Progressive Self-supervised Pre-training on Raw Colonoscopy Records
Yili He, Peiyao Fu, Ruijie Yang, Zhihua Wang 0008, Quanlin Li, Pinghong Zhou, Xian Yang 0001, Shuo Wang 0011 |
MICCAI (11) | 4 |
| 2025 | Common knowledge learning for generating transferable adversarial examples
Ruijie Yang, Yuanfang Guo, Junfu Wang, Jiantao Zhou 0001, Yunhong Wang 0001 |
Frontiers Comput. Sci. | 1 |
| 2025 | Vector Quantization Based Query-Efficient Attack via Direct Preference OptimizationabstractThis work studies black-box adversarial attacks against deep neural networks, where the attacker only has access to the query feedback from the target model. The current state-of-the-art (SOTA) query-efficient attacks usually combine transfer-based and query-based methods by utilizing the gradient or initializations of surrogate models. However, these strategies typically incur significant computational costs and require a large number of queries during the attack process. In this paper, we propose a novel query-efficient method for generating black-box adversarial perturbations, named Vector Quantization based Query-efficient Adversarial Perturbation generation (VQQAP). Specifically, we propose a Nucleus Sampling based Discretization Module (NSDM) to create diverse adversarial examples in the discrete latent space. To directly optimize the latent vector, we formulate the optimization problem as a direct preference optimization (DPO) problem, and iteratively solve this problem based on the target model feedback. Experimental evaluations demonstrate the effectiveness and efficiency of our method. Ruijie Yang, Yuanfang Guo, Guohao Li 0010, Yunhong Wang 0001 |
IEEE Signal Process. Lett. | 1 |
| 2025 | AED-PADA: Improving Generalizability of Adversarial Example Detection via Principal Adversarial Domain AdaptationabstractAdversarial example detection, which can be conveniently applied in many scenarios, is important in the area of adversarial defense. Unfortunately, existing detection methods suffer from poor generalization performance because their training process usually relies on the examples generated from a single known adversarial attack and there exists a large discrepancy between the training and unseen testing adversarial examples. To address this issue, we propose a novel method, named Adversarial Example Detection via Principal Adversarial Domain Adaptation (AED-PADA). Specifically, our approach identifies the Principal Adversarial Domains (PADs), i.e., a combination of features of the adversarial examples generated by different attacks, which possesses a large portion of the entire adversarial feature space. Subsequently, we pioneer to exploit Multi-source Unsupervised Domain Adaptation in adversarial example detection, with PADs as the source domains. Experimental results demonstrate the superior generalization ability of our proposed AED-PADA. Note that this superiority is particularly achieved in challenging scenarios characterized by employing the minimal magnitude constraint for the perturbations. Heqi Peng, Yunhong Wang 0001, Ruijie Yang, Beichen Li 0001, Rui Wang 0032, Yuanfang Guo |
ACM Trans. Multim. Comput. Commun. Appl. | 3 |
| 2024 | Leveraging Predicate and Triplet Learning for Scene Graph GenerationabstractScene Graph Generation (SGG) aims to identify entities and predict the relationship tripletsin visual scenes. Given the prevalence of large visual variations of subject-object pairs even in the same predicate, it can be quite challenging to model and refine predicate representations directly across such pairs, which is however a common strategy adopted by most existing SGG methods. We observe that visual variations within the identical triplet are relatively small and certain relation cues are shared in the same type of triplet, which can potentially facilitate the relation learning in SGG. Moreover, for the long-tail problem widely studied in SGG task, it is also crucial to deal with the limited types and quantity of triplets in tail predicates. Accordingly, in this paper, we propose a Dual-granularity Relation Modeling (DRM) network to leverage fine-grained triplet cues besides the coarse-grained predicate ones. DRM utilizes contexts and semantics of predicate and triplet with Dual-granularity Constraints, generating compact and balanced representations from two perspectives to facilitate relation recognition. Furthermore, a Dual-granularity Knowledge Transfer (DKT) strategy is introduced to transfer variation from head predicates/triplets to tail ones, aiming to enrich the pattern diversity of tail classes to alleviate the long-tail problem. Extensive experiments demonstrate the effectiveness of our method, which establishes new state-of-the-art performance on Visual Genome, Open Image, and GQA datasets. Our code is available at https://github.com/jkli1998/DRM Jiankai Li, Yunhong Wang 0001, Xiefan Guo, Ruijie Yang, Weixin Li 0001 |
CVPR | 4 |
| 2024 | Multi-modal Relation Distillation for Unified 3D Representation Learning
Huiqun Wang, Yiping Bao, Panwang Pan, Ruijie Yang, Di Huang 0001 |
ECCV (33) | 6 |
| 2024 | Automatic Segmentation of Organs-At-Risk and Clinical Target Volume for Cervical Cancer Using Manifold LearningabstractAutomatic segmentation of Organs-At-Risk (OARs) and Clinical Target Volume(CTV) is crucial for the radiotherapy treatment planning of cervical cancer. This task is challenging due to the variation in sizes, shapes, and positions as well as the similar textures among the OARs and CTV. In this paper, we propose a manifold learning-based method based on U-Net. Firstly, the weight matrix of each convolutional layer is constrained to the Stiefel manifold. This constraint enhances the model’s ability to preserve the consistency of the learned feature from CT images. Secondly, we transform the optimization in Euclidean space into Riemannian optimization. This enables the model to optimize the segmentation performance on the manifold space, allowing the model to adapt to the irregular shapes of CTV and OARs. Our experimental results demonstrate that the proposed manifold learning-based method achieves superior performance in segmenting OARs and CTV for cervical cancer as compared to other SOTA methods. Overall, our proposed method demonstrates the potential of manifold learning techniques to improve the segmentation performance of medical images. Chenyu Zuo, Runhong Lei, Kai Niu 0001, Zhiqiang He 0001, Ruijie Yang |
IJCNN | 6 |
| 2024 | EndoFinder: Online Image Retrieval for Explainable Colorectal Polyp Diagnosis
Ruijie Yang, Peiyao Fu, Yizhe Zhang 0001, Zhihua Wang 0008, Quanlin Li, Pinghong Zhou, Xian Yang 0001, Shuo Wang 0011 |
MICCAI (10) | 1 |
| 2024 | Exploring transferable and robust adversarial perturbation generation across network hierarchy
Ruikui Wang, Yuanfang Guo, Ruijie Yang, Yunhong Wang 0001 |
Neurocomputing | 3 |
| 2024 | Global contrast-masked autoencoders are powerful pathological representation learners
Qun Bai, Mingchen Zou, Ruijie Yang, Ruiqun Qi, Xinghua Gao, Xiaoyu Cui |
Pattern Recognit. | 6 |
| 2023 | iDARTS: Improving DARTS by Node Normalization and Decorrelation DiscretizationabstractDifferentiable ARchiTecture Search (DARTS) uses a continuous relaxation of network representation and dramatically accelerates Neural Architecture Search (NAS) by almost thousands of times in GPU-day. However, the searching process of DARTS is unstable, which suffers severe degradation when training epochs become large, thus limiting its application. In this article, we claim that this degradation issue is caused by the imbalanced norms between different nodes and the highly correlated outputs from various operations. We then propose an improved version of DARTS, namely iDARTS, to deal with the two problems. In the training phase, it introduces node normalization to maintain the norm balance. In the discretization phase, the continuous architecture is approximated based on the similarity between the outputs of the node and the decorrelated operations rather than the values of the architecture parameters. Extensive evaluation is conducted on CIFAR-10 and ImageNet, and the error rates of 2.25% and 24.7% are reported within 0.2 and 1.9 GPU-day for architecture search, respectively, which shows its effectiveness. Additional analysis also reveals that iDARTS has the advantage in robustness and generalization over other DARTS-based counterparts. Huiqun Wang, Ruijie Yang, Di Huang 0001, Yunhong Wang 0001 |
IEEE Trans. Neural Networks Learn. Syst. | 2 |
| 2022 | Exploring the Impact of Adding Adversarial Perturbation onto Different Image RegionsabstractAdversarial attack has been a hot topic for a long time in machine learning and deep learning. Studying adversarial attack has vital significance to artificial intelligence security. Existing methods mainly pursue a higher attack success rate. Few researches pay attention to the region where adversarial perturbations are added. Actually, different pixels in an image usually have different contributions in results, which motivates us to apply region constraint in the image for adversarial perturbations generation. In this paper, we present an easy-to-implement way to decrease the unnecessary adversarial perturbations while preserving a relatively high attack success rate. Specifically, we do not use the same constraint of perturbations in the input image but set specific constraint for specific region. Furthermore, we point that adversarial examples work in a different way to normal images. Directly using the activated region in normal images is not optimal. Then, to get the crucial area in adversarial attacks, we propose six transformation schemes to revise the activated region which is generated by the normal image. We launch extensive experiments on ImageNet dataset and the results show that our methods can get better attack strength under the same perturbation level when compared to the baseline methods. Ruijie Yang, Yuanfang Guo, Ruikui Wang, Xiaohan Zhao, Yunhong Wang 0001 |
ISCAS | 1 |
| 2022 | JoinTW: A Joint Image-to-Image Translation and Watermarking Method
Xiaohan Zhao, Yunhong Wang 0001, Ruijie Yang, Yuanfang Guo |
PRCV (3) | 3 |
| 2022 | Achieving Scalability and Load Balance across Blockchain Shards for State ShardingabstractSharding technique is viewed as the most promising solution to improving blockchain scalability. However, to implement a sharded blockchain, developers have to address two major challenges. The first challenge is that the ratio of cross-shard transactions (TXs) across blockchain shards is very high. This issue significantly degrades the throughput of a blockchain. The second challenge is that the workloads across blockchain shards are largely imbalanced. If workloads are imbalanced, some shards have to handle an overwhelming number of TXs and become congested very possibly. Facing these two challenges, a dilemma is that it is difficult to guarantee a low cross-shard TX ratio and maintain the workload balance across all shards, simultaneously. We believe that a fine-grained account-allocation strategy can address this dilemma. To this end, we first formulate the tradeoff between such two metrics as a network-partition problem. We then solve this problem using a community-aware account partition algorithm. Furthermore, we also propose a sharding protocol, named Transformers, to apply the proposed algorithm into the sharded blockchain system. Finally, trace-driven evaluation results demonstrate that the proposed protocol outperforms other baselines in terms of throughput, latency, cross-shard TX ratio, and the queue size of transaction pool. Canlin Li, Huawei Huang, Yetong Zhao, Xiaowen Peng, Ruijie Yang, Zibin Zheng, Song Guo 0001 |
SRDS | 5 |
| 2021 | An Effective and Reliable Cross-Blockchain Data Migration Approach
Mengqiu Zhang, Qiang Qu 0001, Li Ning 0001, Jianping Fan 0002, Ruijie Yang |
PDCAT | 5 |
| 2021 | Systems pharmacology: a combination strategy for improving efficacy of PD-1/PD-L1 blockadeabstractTargeting tumor microenvironment (TME), such as immune checkpoint blockade (ICB), has achieved increased overall response rates in many advanced cancers, such as non-small cell lung cancer (NSCLC), however, only in a fraction of patients. To improve the overall and durable response rates, combining other therapeutics, such as natural products, with ICB therapy is under investigation. Unfortunately, due to the lack of systematic methods to characterize the relationship between TME and ICB, development of rational immune-combination therapy is a critical challenge. Here, we proposed a systems pharmacology strategy to identify resistance regulators of PD-1/PD-L1 blockade and develop its combinatorial drug by integrating multidimensional omics and pharmacological methods. First, a high-resolution TME cell atlas was inferred from bulk sequencing data by referring to a high-resolution single-cell data and was used to predict potential resistance regulators of PD-1/PD-L1 blockade through TME stratification analysis. Second, to explore the drug targeting the resistance regulator, we carried out the large-scale target fishing and the network analysis between multi-target drug and the resistance regulator. Finally, we predicted and verified that oxymatrine significantly enhances the infiltration of CD8+ T cells into TME and is a powerful combination agent to enhance the therapeutic effect of anti-PD-L1 in a mouse model of lung adenocarcinoma. Overall, the systems pharmacology strategy offers a paradigm to identify combinatorial drugs for ICB therapy with a systems biology perspective of drug-target-pathway-TME phenotype-ICB combination. Chunli Zheng, Jinglin Zhu, Ruijie Yang, Jiangna Yan, Ruifei Huang, Chao Huang 0030 |
Briefings Bioinform. | 5 |