EDBT 2026 Demo / reviewers in the wild / expert
Fulan Qian
dblp:201/6594
· DBLP profile ↗
6ranked-venue papers in the field
4as first author
6since 2021 · last 2025
—ORCID · conflict
Domains — venue-derived; a paper can count in several
Data Mining & Knowledge Discovery · 4 (3 first)Database Systems & Data Management · 1 (1 first)Information Retrieval & Web Search · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Understanding the Robustness of Deep Recommendation under Adversarial AttacksabstractIt has been shown that deep recommendation models are susceptible to adversarial attacks, with this vulnerability potentially leading to significant economic losses in the e-commerce field. However, the robustness of deep recommendation models in response to adversarial attacks has not been systematically investigated. In this article, therefore, we comprehensively evaluate the adversarial robustness of various representative deep models in different settings, aiming to analyze their performance impact under adversarial attacks and compare it with traditional collaborative filtering models. Notably, we examine poisoning attacks under different proportions of fake users and various popularity conditions to understand why certain deep recommendation models perform exceptionally or sub-optimally. On this basis, we further proposed practical robustness improvement strategy for the problems found in the evaluation and fully verified it through rigorous experiments. Key findings include: (1) the sparser the training dataset, the weaker the robustness of a recommendation model’s performance under adversarial attacks; (2) deep recommendation models exhibit greater robustness in recommending popular items under adversarial attacks, while they are more vulnerable when attacked with non-popular items; (3) the robustness of deep recommendation models is not consistently weaker than that of traditional collaborative filtering models across all attack settings. These findings highlight the security concerns in deep recommendation systems and contribute to developing more reliable models. Fulan Qian, Hai Chen, Yan Cui 0016, Shu Zhao 0005, Yanping Zhang 0001 |
ACM Trans. Knowl. Discov. Data | 1 |
| 2025 | A Comprehensive Understanding of the Impact of Data Augmentation on the Transferability of 3D Adversarial Examplesabstract3D point cloud classifiers exhibit vulnerability to imperceptible perturbations, which poses a serious threat to the security and reliability of deep learning models in practical applications, making the robustness evaluation of deep 3D point cloud models increasingly important. Due to the difficulty in obtaining model parameters, black-box attacks have become a mainstream means of assessing the adversarial robustness of 3D classification models. The core of improving the transferability of adversarial examples generated by black-box attacks is to generate better generalized adversarial examples, where data augmentation has become one of the popular approaches. In this article, we employ five mainstream attack methods and combine six data augmentation strategies, namely point dropping, flipping, rotating, scaling, shearing, and translating, in order to comprehensively explore the impact of these strategies on the transferability of adversarial examples. Our research reveals that data augmentation methods generally improve the transferability of the adversarial examples, and the effect is better when the methods are stacked. The interaction between data augmentation methods, model characteristics, attack, and defense strategies collectively determines the transferability of adversarial examples. In order to comprehensively understand and improve the effectiveness of adversarial examples, it is necessary to comprehensively consider these complex interrelationships. Fulan Qian, Yuanjun Zou, Chonghao Zhang, Chenchu Xu, Hai Chen |
ACM Trans. Knowl. Discov. Data | 1 |
| 2024 | Training Robust Deep Collaborative Filtering Models via Adversarial Noise PropagationabstractThe recommendation performance of deep collaborative filtering models drops sharply under imperceptible adversarial perturbations. Some methods promote the robustness of recommendation systems by adversarial training. However, these methods only study shallow models and lack the exploration of deep models. Furthermore, the way these methods add adversarial noise to the weight parameters of users and items is not fully applicable to deep collaborative filtering models, because the adversarial noise is not sufficient to fully affect its network structure with multiple hidden layers. In this article, we propose a novel adversarial training framework, Random Layer-wise Adversarial Training (RAT), which trains a robust deep collaborative filtering model via adversarial noise propagation. Specifically, we inject adversarial noise into the output of the hidden layer in a random layer-wise manner. The adversarial noise propagates forward from the injected position to obtain more flexible model parameters during the adversarial training process. We validate the effectiveness of RAT on multilayer perceptron (MLP) and implement RAT on MLP-based and convolutional neural networks-based deep collaborative filtering models. Experiments on three publicly available datasets show that the deep collaborative filtering model trained by RAT not only defends against adversarial noise but also guarantees recommendation performance. Hai Chen, Fulan Qian, Chang Liu 0077, Yanping Zhang 0001, Hang Su 0006, Shu Zhao 0005 |
ACM Trans. Inf. Syst. | 2 |
| 2023 | Adaptive social recommendation combined with the multi-domain influence
Fulan Qian, Kaili Qin, Hai Chen, Jie Chen 0025, Shu Zhao 0005, Yanping Zhang 0001 |
Inf. Syst. | 1 |
| 2023 | GWNN-HF: beyond assortativity in graph wavelet neural network
Binfeng Huang, Fulan Qian, Shu Zhao 0005, Jie Chen 0025, Yanping Zhang 0001 |
Knowl. Inf. Syst. | 3 |
| 2023 | Utilizing the influence of multiple potential factors for social recommendation
Fulan Qian, Kaili Qin, Hai Chen, Jie Chen 0025, Shu Zhao 0005, Peng Zhou 0008, Yanping Zhang 0001 |
Knowl. Inf. Syst. | 1 |