EDBT 2026 Demo / reviewers in the wild / expert
Jia-Li Yin
dblp:202/7203
· DBLP profile ↗
38ranked-venue papers
12as first author
29since 2021 · last 2026
0000-0002-8087-9769ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 27 · 9 first-author · 19 since 2021Artificial intelligence and machine learning · 8 · 2 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 3 since 2021Computer networks · 2 · 2 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | LoopLLM: Transferable Energy-Latency Attacks in LLMs via Repetitive GenerationabstractAs large language models (LLMs) scale, their inference incurs substantial computational resources, exposing them to energy-latency attacks, where crafted prompts induce high energy and latency cost. Existing attack methods aim to prolong output by delaying the generation of termination symbols. However, as the output grows longer, controlling the termination symbols through input becomes difficult, making these methods less effective. Therefore, we propose LoopLLM, an energy-latency attack framework based on the observation that repetitive generation can trigger low-entropy decoding loops, reliably compelling LLMs to generate until their output limits. LoopLLM introduces (1) a repetition-inducing prompt optimization that exploits autoregressive vulnerabilities to induce repetitive generation, and (2) a token-aligned ensemble optimization that aggregates gradients to improve cross-model transferability. Extensive experiments on 12 open-source and 2 commercial LLMs show that LoopLLM significantly outperforms existing methods, achieving over 90% of the maximum output length, compared to 20% for baselines, and improving transferability by around 40% to DeepSeek-V3 and Gemini 2.5 Flash. Yixiao Xu, Kangyi Ding, Bangzhou Xin, Jia-Li Yin |
AAAI | 7 |
| 2026 | DoBlock: Blocking Malicious Association Propagation for Backdoor-Robust Federated Learning Under Domain SkewabstractFederated Learning (FL) enables privacy-preserving distributed training but remains vulnerable to backdoor attacks. Attackers can embed malicious trigger-label associations into the global model by participating in the aggregation process. Existing defense methods typically defend against backdoor attacks by detecting and filtering malicious updates that deviate from benign ones. However, we find that these defenses fail under domain skew, where differing feature distributions across clients increase update heterogeneity, making it harder to distinguish malicious updates from benign ones. To address this challenge, we propose DoBlock, a novel defense that utilizes an aggregatable domain infuser incapable of embedding malicious associations, through federated training to facilitate cross-domain knowledge sharing. Moreover, DoBlock prevents malicious association propagation by isolating local models from aggregation, as local models remain client-specific and rely solely on local data for training. Experiments on five domain skew datasets (Digits, PACS, VLCS, Office-Caltech10, and DomainNet) show that DoBlock maintains attack success rates below 2.5%, while achieving the highest main task accuracy, demonstrating superior robustness without sacrificing benign performance. Zhou Tan, Yirui Huang, Duanshu Fang, Jia-Li Yin, Shouling Ji |
AAAI | 5 |
| 2026 | SEADGAT: A Heterogeneous Graph Attention Network With Cross-Distillation for Encrypted Traffic ClassificationabstractWith the increasing severity of network security threats, encrypted traffic identification has become a core challenge in the field of network security. Graph Neural Networks (GNNs) have demonstrated significant potential in capturing the complex association patterns among encrypted traffic byte units, owing to their powerful structural modeling capabilities. However, traditional homogeneous graph modeling methods struggle to fully characterize the multidimensional heterogeneous relationships between headers and payloads in encrypted traffic. Although Heterogeneous Graph Neural Networks (HGNNs) can address such complexity, they suffer from parameter redundancy and a sharp increase in training overhead due to independent edge-type modeling, while lacking a mechanism for collaborative knowledge transfer across edge types. To address this, this paper proposes a Cross-Type Distillation mechanism, which constructs a unified structural representation path to enable bidirectional knowledge transfer between heterogeneous edge types. This approach enhancing the feature expression capability of weak semantic edges. Building on this foundation, we introduce the malicious traffic detection model SEADGAT, which employs an edge-type weight-sharing mechanism to compress the propagation weights of multiple edge types into a unified representation space and integrates them into graph attention computation. This substantially reduces training time while preserving the ability to perceive structural differences. Based on a heterogeneous graph framework, SEADGAT accurately characterizes the complex dependencies between byte units and between headers and payloads, combined with a dynamic fusion mechanism to generate comprehensive traffic representations. DFUSE is enhanced with gated cross-interactions for adaptive multimodal fusion. Experiments on packet-level and flow-level classification across multiple encrypted traffic datasets demonstrate that SEADGAT outperforms existing methods in classification accuracy, training efficiency, and model parameter scale. Yuanyuan Huang 0007, Zhitan Wei, Jia-Li Yin, Xiaolei Liu 0001 |
IEEE Internet Things J. | 5 |
| 2026 | Mix2Aug: Revisiting Mixing-Based Augmentations for Improving Robust Generalization of Adversarial TrainingabstractAlthough adversarial training (AT) is currently one of the most promising methods to make deep neural networks adversarially robust, it suffers from the issue of robust overfitting and thus aggravates the robust generalization gap between the training and testing dataset. At the same time, data augmentations (DAs) are considered to be powerful tools for improving model generalization in standard training; however, they have been observed by many previous studies to be ineffective when applied in AT. In this paper, we try to break this prejudice and focus on improving the robust generalization ability of AT by DAs alone. We first take a close look at the effect of DAs in the adversarial training process and find that compared to common DAs, mixing-based augmentations (i.e.,MixUpandCutMix) can effectively prevent robust overfitting in AT. Then, after revisiting these two mixing-based DAs we found that they can be complementary and we can subtly stimulate the effectiveness ofMixUpandCutMixin improving the robust generalization of AT by a joint mixing manner. To this end, we propose a joint mixing-based augmentation scheme, namedMix2Aug, for improving robust generalization of AT and ultimately improving model robustness. Experimental results show that ourMix2Augcan significantly increase the upper limit ofMixUpandCutMixwithout the need of additional ensemble techniques, achieving state-of-the-art accuracy and robustness on extensive datasets. Zhaozhe Hu, Bin Chen 0020, Jia-Li Yin, Yaguan Qian, Shouling Ji |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2026 | Adversarial Sample Based on Structured Fusion Noise for Botnet Detection in Industrial Control SystemsabstractThe industrial control system’s artificial intelligence-based botnet intrusion detection system has a high detection performance and efficiency in an environment without interference. However, these systems are not immune to evasion through adversarial samples. In this study, we introduce a feature extraction technique tailored for ICS botnet detection. This approach classifies traffic packets based on network traffic attributes and ICS-specific identification codes, encompassing the statuses of ICS devices, enhancing detection precision. Meanwhile, this strategy addresses challenges in ICS data collection and bolsters experimental efficacy. To build a comprehensive botnet intrusion dataset within an ICS, we concurrently utilized existing ICS devices to collect both standard ICS and botnet traffic. Additionally, we present an innovative adversarial sample generation method for botnet detection models, integrating both time-domain and frequency-domain noise. Testing under three real-world ICS attack scenarios revealed our technique can markedly degrade the classification performance of eight leading AI-based detection models, emphasizing its potential for evading AI-based ICS intrusion detectors. Jimin Peng, Jia-Li Yin, Xiaolei Liu 0001 |
IEEE Trans. Netw. Serv. Manag. | 4 |
| 2025 | Adversarial-Inspired Backdoor Defense via Bridging Backdoor and Adversarial AttacksabstractBackdoor attacks and adversarial attacks are two major security threats to deep neural networks (DNNs), with the former one is a training-time data poisoning attack that aims to implant backdoor triggers into models by injecting trigger patterns into training samples, and the latter one is a testing-time attack trying to generate adversarial examples (AEs) from benign images to mislead a well-trained model. While previous works generally treat these two attacks separately, the inherent connection between these two attacks is rarely explored. In this paper, we focus on bridging backdoor and adversarial attacks and observe two intriguing phenomena when applying adversarial attacks on an infected model implanted with backdoors: 1) the sample is harder to be turned into an AE when the trigger is presented; 2) the AEs generated from backdoor samples are highly likely to be predicted as its true labels. Inspired by these observations, we proposed a novel backdoor defense method, dubbed Adversarial-Inspired Backdoor Defense (AIBD), to isolate the backdoor samples by leveraging a progressive top-q scheme and break the correlation between backdoor samples and their target labels using adversarial labels. Through extensive experiments on various datasets against six state-of-the-art backdoor attacks, the AIBD-trained models on poisoned data demonstrate superior performance over the existing defense methods. Jia-Li Yin, Weijian Wang, Lyhwa, Ximeng Liu |
AAAI | 1 |
| 2025 | KOEnsAttack: Towards Efficient Data-Free Black-Box Adversarial Attacks via Knowledge-Orthogonalized Substitute Ensembles
Chaoyong Yang, Jia-Li Yin, Zhaozhe Hu |
ICCV | 2 |
| 2025 | Focus on Generalization: Improving Adversarial Transferability via Bi-Level Bias MitigationabstractTransfer-based adversarial attacks have endowed adversarial examples with the ability to transfer from a source model to an unknown target model, which poses a more realistic threat to security-critical applications. Existing transferable adversarial attacks generally suffer from overfitting to the source model, i.e., the perturbations are locally optimal in the source model and focus on the model-specific information. We demand the adversarial perturbation to contain more generalized knowledge, which reveals the intrinsic general properties and can introduce model-general optimum into adversarial examples, for improving transferability. To this end, we devise a Bi-level Bias Mitigated Attack (BBMA), which empowers the transferability of adversarial examples by exploring generalization in two levels: 1) Progressive filtering of high-frequency sample components. We first propose to remove the sample-specific high-frequency components of samples to explore model-level generation. To simulate how a model evaluates feature importance at different stages, we devise a stride-wise step-tuning strategy to progressively produce multiple samples for aggregating the gradients. 2) Accumulated gradient-guided model attention shift. To facilitate the sample-level bias mitigation, we employ an accumulated gradient-guided attention map to distort the more generalized features during perturbation generation. Comprehensive experiments on several benchmarks demonstrate the superiority of our method in attack transferability over state-of-the-art attacks. Yiqiang Guo, Bin Chen 0020, Jia-Li Yin, Xiaolei Liu 0001, Shouling Ji |
ACM Multimedia | 4 |
| 2025 | FeatShield: Isolating Malicious Feature Extractors for Backdoor-Robust Federated LearningabstractFederated learning remains vulnerable to backdoor attacks through malicious parameter updates, with existing defenses limited by homogeneous data assumptions or reliance on gradient anomaly detection. We reveal that FedAvg's critical flaw lies in malicious feature extractor propagation: aggregating poisoned extractors degrades defense accuracy to <70% across five benchmarks, while benign extractors with poisoned headers retain an average of 89.36% defense accuracy. Therefore, we propose FeatShield, a feature-space isolation framework that prevents backdoor propagation via non-aggregated local extractors trained on clean client data. FeatShield introduces 1) variance-aware alignment, adaptively balancing client-specific features and global consistency using local variance metrics, and 2) adversarial feature synthesis, generating non-linear synthetic features via GAN to enhance the global prediction header's generalization on main tasks. Extensive experiments on eight real-world datasets show that FeatShield achieves the best defense performance. For instance, under heterogeneous data (Dirichlet β=0.5) and strong attacks (50% malicious clients), FeatShield achieves 99.26-99.89% defense accuracy and main task accuracy exceeding FedAvg by 1.32-5.70%, demonstrating its superior resistance to backdoor attacks without sacrificing the benign performance. Zhou Tan, Yirui Huang, Jia-Li Yin, Ximeng Liu |
ACM Multimedia | 4 |
| 2024 | MEAT: Median-Ensemble Adversarial Training for Improving Robustness and GeneralizationabstractSelf-ensemble adversarial training methods improve model robustness by ensembling models at different training epochs, such as model weight averaging (WA). However, previous research has shown that self-ensemble defense methods in adversarial training (AT) still suffer from robust overfitting, which severely affects the generalization performance. Empirically, in the late phases of training, the AT becomes more overfitting to the extent that the individuals for weight averaging also suffer from overfitting and produce anomalous weight values, which causes the self-ensemble model to continue to undergo robust overfitting due to the failure in removing the weight anomalies. To solve this problem, we aim to tackle the influence of outliers in the weight space in this work and propose an easy-to-operate and effective Median-Ensemble Adversarial Training (MEAT) method to solve the robust overfitting phenomenon existing in self-ensemble defense from the source by searching for the median of the historical model weights. Experimental results show that MEAT achieves the best robustness against the powerful AutoAttack and can effectively allievate the robust overfitting. We further demonstrate that most defense methods can improve robust generalization and robustness by combining with MEAT. Zhaozhe Hu, Jia-Li Yin, Bin Chen 0020, Luojun Lin, Ximeng Liu |
ICASSP | 2 |
| 2024 | Adversarial Example Quality Assessment: A Large-scale Dataset and Strong BaselineabstractAdversarial examples (AEs), which are maliciously hand-crafted by adding perturbations to benign images, reveal the vulnerability of deep neural networks (DNNs) and have been used as a benchmark for evaluating model robustness. With great efforts have been devoted to generating AEs with stronger attack ability, the visual quality of AEs is generally neglected in previous studies. The lack of a good quality measure of AEs makes it very hard to compare the relative merits of attack techniques and is hindering technological advancement. How to evaluate the visual quality of AEs remains an understudied and unsolved problem. In this work, we make the first attempt to fill the gap by presenting an image quality assessment method specifically designed for AEs. Towards this goal, we first construct a new database, called AdvDB, developed on diverse adversarial examples with elaborated annotations. We also propose a detection-based structural similarity index (AdvDSS) for adversarial example perceptual quality assessment. Specifically, the visual saliency for capturing the near-threshold adversarial distortions is first detected via human visual system (HVS) techniques and then the structural similarity is extracted to predict the quality score. Moreover, we further propose AEQA for overall adversarial example quality assessment by integrating the perceptual quality and attack intensity of AEs. Extensive experiments validate that the proposed AdvDSS achieves state-of-the-art performance which is more consistent with human opinions. Jia-Li Yin, Menghao Chen, Ximeng Liu |
ACM Multimedia | 1 |
| 2024 | Towards Adversarial-Robust Class-Incremental Learning via Progressively Volume-Up Perturbation Generation
Yeliang You, Bin Chen 0020, Jia-Li Yin, Ximeng Liu |
PRCV (2) | 3 |
| 2023 | SRoUDA: Meta Self-Training for Robust Unsupervised Domain AdaptationabstractAs acquiring manual labels on data could be costly, unsupervised domain adaptation (UDA), which transfers knowledge learned from a rich-label dataset to the unlabeled target dataset, is gaining increasingly more popularity. While extensive studies have been devoted to improving the model accuracy on target domain, an important issue of model robustness is neglected. To make things worse, conventional adversarial training (AT) methods for improving model robustness are inapplicable under UDA scenario since they train models on adversarial examples that are generated by supervised loss function. In this paper, we present a new meta self-training pipeline, named SRoUDA, for improving adversarial robustness of UDA models. Based on self-training paradigm, SRoUDA starts with pre-training a source model by applying UDA baseline on source labeled data and taraget unlabeled data with a developed random masked augmentation (RMA), and then alternates between adversarial target model training on pseudo-labeled target data and fine-tuning source model by a meta step. While self-training allows the direct incorporation of AT in UDA, the meta step in SRoUDA further helps in mitigating error propagation from noisy pseudo labels. Extensive experiments on various benchmark datasets demonstrate the state-of-the-art performance of SRoUDA where it achieves significant model robustness improvement without harming clean accuracy. Wanqing Zhu, Jia-Li Yin, Ximeng Liu |
AAAI | 2 |
| 2023 | An Adaptive Model Ensemble Adversarial Attack for Boosting Adversarial TransferabilityabstractWhile the transferability property of adversarial examples allows the adversary to perform black-box attacks (i.e., the attacker has no knowledge about the target model), the transfer-based adversarial attacks have gained great attention. Previous works mostly study gradient variation or image transformations to amplify the distortion on critical parts of inputs. These methods can work on transferring across models with limited differences, i.e., from CNNs to CNNs, but always fail in transferring across models with wide differences, such as from CNNs to ViTs. Alternatively, model ensemble adversarial attacks are proposed to fuse outputs from surrogate models with diverse architectures to get an ensemble loss, making the generated adversarial example more likely to transfer to other models as it can fool multiple models concurrently. However, existing ensemble attacks simply fuse the outputs of the surrogate models evenly, thus are not efficacious to capture and amplify the intrinsic transfer information of adversarial examples. In this paper, we propose an adaptive ensemble attack, dubbed AdaEA, to adaptively control the fusion of the outputs from each model, via monitoring the discrepancy ratio of their contributions towards the adversarial objective. Furthermore, an extra disparity-reduced filter is introduced to further synchronize the update direction. As a result, we achieve considerable improvement over the existing ensemble attacks on various datasets, and the proposed AdaEA can also boost existing transfer-based attacks, which further demonstrates its efficacy and versatility. The source code: https://github.com/CHENBIN99/AdaEA Bin Chen 0020, Jia-Li Yin, Shukai Chen, Ximeng Liu |
ICCV | 2 |
| 2023 | MetaFBP: Learning to Learn High-Order Predictor for Personalized Facial Beauty PredictionabstractPredicting individual aesthetic preferences holds significant practical applications and academic implications for human society. However, existing studies mainly focus on learning and predicting the commonality of facial attractiveness, with little attention given to Personalized Facial Beauty Prediction (PFBP). PFBP aims to develop a machine that can adapt to individual aesthetic preferences with only a few images rated by each user. In this paper, we formulate this task from a meta-learning perspective that each user corresponds to a meta-task. To address such PFBP task, we draw inspiration from the human aesthetic mechanism that visual aesthetics in society follows a Gaussian distribution, which motivates us to disentangle user preferences into a commonality and an individuality part. To this end, we propose a novel MetaFBP framework, in which we devise a universal feature extractor to capture the aesthetic commonality and then optimize to adapt the aesthetic individuality by shifting the decision boundary of the predictor via a meta-learning mechanism. Unlike conventional meta-learning methods that may struggle with slow adaptation or overfitting to tiny support sets, we propose a novel approach that optimizes a high-order predictor for fast adaptation. In order to validate the performance of the proposed method, we build several PFBP benchmarks by using existing facial beauty prediction datasets rated by numerous users. Extensive experiments on these benchmarks demonstrate the effectiveness of the proposed MetaFBP method. Luojun Lin, Zhifeng Shen, Jia-Li Yin, Qipeng Liu 0004, Yuanlong Yu 0001, Weijie Chen 0006 |
ACM Multimedia | 3 |
| 2023 | Q-TrHDRI: A Qurey-Based Transformer for High Dynamic Range Imaging with Dynamic Scenes
Bin Chen 0020, Jia-Li Yin, Ximeng Liu |
PRCV (11) | 2 |
| 2023 | Global Learnable Attention for Single Image Super-ResolutionabstractSelf-similarity is valuable to the exploration of non-local textures in single image super-resolution (SISR). Researchers usually assume that the importance of non-local textures is positively related to their similarity scores. In this paper, we surprisingly found that when repairing severely damaged query textures, some non-local textures with low-similarity which are closer to the target can provide more accurate and richer details than the high-similarity ones. In these cases, low-similarity does not mean inferior but is usually caused by different scales or orientations. Utilizing this finding, we proposed a Global Learnable Attention (GLA) to adaptively modify similarity scores of non-local textures during training instead of only using a fixed similarity scoring function such as the dot product. The proposed GLA can explore non-local textures with low-similarity but more accurate details to repair severely damaged textures. Furthermore, we propose to adopt Super-Bit Locality-Sensitive Hashing (SB-LSH) as a preprocessing method for our GLA. With the SB-LSH, the computational complexity of our GLA is reduced from quadratic to asymptotic linear with respect to the image size. In addition, the proposed GLA can be integrated into existing deep SISR models as an efficient general building block. Based on the GLA, we constructed a Deep Learnable Similarity Network (DLSN), which achieves state-of-the-art performance for SISR tasks of different degradation types (e.g., blur and noise). Our code and a pre-trained DLSN have been uploaded to GitHub†for validation. Jian-Nan Su, Min Gan, Guang-Yong Chen, Jia-Li Yin, C. L. Philip Chen |
IEEE Trans. Pattern Anal. Mach. Intell. | 4 |
| 2023 | Push Stricter to Decide Better: A Class-Conditional Feature Adaptive Framework for Improving Adversarial RobustnessabstractIn response to the threat of adversarial examples, adversarial training provides an attractive option for improving robustness by training models on online-augmented adversarial examples. However, most existing adversarial training methods focus on improving the model’s robust accuracy by strengthening the adversarial examples but neglecting the increasing shift between natural data and adversarial examples, leading to a decrease in natural accuracy. To maintain the trade-off between natural and robust accuracy, we alleviate the shift from the perspective of feature adaption and propose a Feature Adaptive Adversarial Training (FAAT) optimizing the class-conditional feature adaption across natural data and adversarial examples. Specifically, we propose to incorporate a class-conditional discriminator to encourage the features to become(1)class-discriminative and(2)invariant to the change of adversarial attacks. The novel FAAT framework enables the trade-off between natural and robust accuracy by generating features with similar distribution across natural and adversarial data within the same class and achieves higher overall robustness benefiting from the class-discriminative feature characteristics. Experiments on various datasets demonstrate that FAAT produces more discriminative features and performs favorably against state-of-the-art methods. Jia-Li Yin, Bin Chen 0020, Wanqing Zhu, Ximeng Liu |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2022 | Adaptive Actor-Critic Bilateral FilterabstractRecent research on edge-preserving image smoothing has suggested that bilateral filtering is vulnerable to maliciously perturbed filtering input. However, while most prior works analyze the adaptation of the range kernel in one-step manner, in this paper we take a more constructive view towards multi-step framework with the goal of unveiling the vulnerability of bilateral filtering. To this end, we adaptively model the width setting of range kernel as a multi-agent reinforcement learning problem and learn an adaptive actor-critic bilateral filter from local image context during successive bilateral filtering operations. By evaluating on eight benchmark datasets, we show that the performance of our filter outperforms that of state-of-the-art bilateral-filtering methods in terms of both salient structures preservation and insignificant textures and perturbation elimination. Hsiang-Yin Cheng, Jia-Li Yin |
ICASSP | 3 |
| 2022 | Actor-Critic Bilateral Filter for Noise-Robust Image SmoothingabstractBilateral filters have been used for achieving excellent edge-preserving image smoothing. However, most studies have focused on the acceleration of bilateral filtering but not on the stability of filtering process in regard to small perturbations to its inputs. In this paper, we propose a novel actor–critic bilateral filter trained with a multistep learning scheme for high-stability edge-preserving image smoothing. We first designed an edge-preserving smoothing process as a Markov decision process that involves adjusting the width setting for the range kernel of a bilateral filter. Next, we trained our actor–critic bilateral filter in a multistep manner to learn the optimal sequence of width settings. Through extensive experiments on five benchmark datasets, we determined that the proposed actor–critic bilateral filter produced satisfactory edge-preserving smoothing results. Yi-Jie Chen, Yen-Chiao Wang, Hsiang-Yin Cheng, Jia-Li Yin |
ISM | 5 |
| 2022 | Two-Pass Bilateral Smooth Filtering for Remote Sensing ImageryabstractBilateral filtering has been adopted for edge-preserving image smoothing and achieved the state-of-the-art performance. Most of the existing bilateral filters (BFs), however, focus on accelerating brute-force implementation but not on smoothing quality. In this letter, we propose a two-pass (TP) BF, TP-based BF, and an adaptive control scheme of range kernels for noise-invariant edge-preserving image smoothing. Specifically, the TP-based BF is composed of two bilateral filtering operations, which are, respectively, in charge of coarse context extraction and fine structure refinement. The control scheme of range kernels guides the TP bilateral mechanism to eliminate first high-frequency noisy pixels and then explore contribution between pixels from clean contexts. Experimental results on four aerial-imagery benchmark data sets show that our TP-based BF outperforms the existing BFs in terms of both feature- and gradient-aware measures. Hsiang-Yin Cheng, Yi-Syuan Tseng, Jia-Li Yin |
IEEE Geosci. Remote. Sens. Lett. | 4 |
| 2022 | Automatic Itinerary Planning Using Triple-Agent Deep Reinforcement LearningabstractAutomatic itinerary planning that provides an epic journey for each traveler is a fundamental yet inefficient task. Most existing planning methods apply heuristic guidelines for certain objective, and thereby favor popular preferred point of interests (POIs) with high probability, which ignore the intrinsic correlation between the POIs exploration, traveler’s preferences, and distinctive attractions. To tackle the itinerary planning problem, this paper explores the connections of these three objectives in probabilistic manner based on a Bayesian model and proposes a triple-agent deep reinforcement learning approach, which generates 4-way direction, 4-way distance, and 3-way selection strategy for iteratively determining next POI to visit in the itinerary. Experiments on five real-world cities demonstrate that our triple-agent deep reinforcement learning approach can provide better planning results in comparison with state-of-the-art multiobjective optimization methods. Shengxin Chen, Jia-Li Yin, Zhaojiong Chen |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2022 | Deep Trident Decomposition Network for Single License Plate Image Glare RemovalabstractDeep convolutional neural networks have achieved state-of-the-art performance for the removal of atmospheric obscuration. However, most relevant studies have focused on eliminating the effects of atmospheric obscuration but not on the glare in images caused by reflected sunlight. On the basis of a glare image formation model, we propose a deep trident decomposition network with a large-scale sun glare image dataset for glare removal from single images. Specifically, the proposed network is designed and implemented with a trident decomposition module for decomposing an input glare image into occlusion, foreground, and coarse glare-free images by exploring background features from spatial locations. Moreover, a residual refinement module is adopted to refine the coarse glare-free image into fine glare-free image by learning the residuals from features of multiscale receptive field. The experimental results indicated that the proposed network significantly outperforms state-of-the-art atmospheric obscuration removal networks on the built dataset. Shiting Ye, Jia-Li Yin, Hsiang-Yin Cheng, Dewang Chen |
IEEE Trans. Intell. Transp. Syst. | 3 |
| 2022 | Two Exposure Fusion Using Prior-Aware Generative Adversarial NetworkabstractProducing a high dynamic range (HDR) image from two low dynamic range (LDR) images with extreme exposures is challenging due to the lack of well-exposed contents. Existing works either use pixel fusion based on weighted quantization or conduct feature fusion using deep learning techniques. In contrast to these methods, our core idea is to progressively incorporate the pixel domain knowledge of LDR images into the feature fusion process. Specifically, we propose a novel Prior-Aware Generative Adversarial Network (PA-GAN), along with a new dual-level loss for two exposure fusion. The proposed PA-GAN is composed of a content-prior-guided encoder and a detail-prior-guided decoder, respectively in charge of content fusion and detail calibration. We further train the network using a dual-level loss that combines the semantic-level loss and pixel-level loss. Extensive qualitative and quantitative evaluations on diverse image datasets demonstrate that our proposed PA-GAN has superior performance than state-of-the-art methods. Jia-Li Yin, Yan-Tsung Peng |
IEEE Trans. Multim. | 1 |
| 2022 | Automatic Intermediate Generation With Deep Reinforcement Learning for Robust Two-Exposure Image FusionabstractFusing low dynamic range (LDR) for high dynamic range (HDR) images has gained a lot of attention, especially to achieve real-world application significance when the hardware resources are limited to capture images with different exposure times. However, existing HDR image generation by picking the best parts from each LDR image often yields unsatisfactory results due to either the lack of input images or well-exposed contents. To overcome this limitation, we model the HDR image generation process in two-exposure fusion as a deep reinforcement learning problem and learn an online compensating representation to fuse with LDR inputs for HDR image generation. Moreover, we build a two-exposure dataset with reference HDR images from a public multiexposure dataset that has not yet been normalized to train and evaluate the proposed model. By assessing the built dataset, we show that our reinforcement HDR image generation significantly outperforms other competing methods under different challenging scenarios, even with limited well-exposed contents. More experimental results on a no-reference multiexposure image dataset demonstrate the generality and effectiveness of the proposed model. To the best of our knowledge, this is the first work to use a reinforcement-learning-based framework for an online compensating representation in two-exposure image fusion. Jia-Li Yin, Yan-Tsung Peng, Hau Hwang |
IEEE Trans. Neural Networks Learn. Syst. | 1 |
| 2021 | Towards Transferable Adversarial Examples Using Meta Learning
Mingyuan Fan 0003, Jia-Li Yin, Ximeng Liu, Wenzhong Guo |
ICA3PP (1) | 2 |
| 2021 | Model-Agnostic Adversarial Example Detection Through Logit Distribution LearningabstractRecent research on vision-based tasks has achieved great improvement due to the development of deep learning solutions. However, deep models have been found vulnerable to adversarial attacks where the original inputs are maliciously manipulated and cause dramatic shifts to the outputs. In this paper, we focus on adversarial attacks in image classifiers built with deep neural networks and propose a model-agnostic approach to detect adversarial inputs. We argue that the logit semantics of adversarial inputs follow a different evolution with respect to original inputs, and construct a logits-based embedding of features for effective representation learning. We train an LSTM network to further analyze the sequence of logits-based features to detect adversarial examples. Experimental results on the MNIST, CFAR-10, and CFAR-100 datasets show that our method achieves state-of-the-art accuracy for detecting adversarial examples and has strong generalizability. Yaopeng Wang, Lehui Xie, Ximeng Liu, Jia-Li Yin, Tingjie Zheng |
ICIP | 4 |
| 2021 | Robust Single-Step Adversarial Training with Regularizer
Lehui Xie, Yaopeng Wang, Jia-Li Yin, Ximeng Liu |
PRCV (4) | 3 |
| 2021 | Deep Battery Saver: End-to-End Learning for Power Constrained Contrast EnhancementabstractDue to the problems of power-hungry displays and limited battery life in electronic devices, the concept of “green computing,” which entails a reduction in power consumption, is proposed. One often seen green computing is the power-constrained contrast enhancement (PCCE), yet it is much more challenging because of the noticeable local intensity suppressions in images. This paper aims at developing an image-quality-lossless end-to-end learning network called deep battery saver to achieve power savings in emissive displays, i.e., produce power-saved images with high perceptual quality and less power consumption. Built upon the end-to-end network of the displayed image, we propose a variational loss function for enhancing the visual quality and suppressing the power consumption, simultaneously. The basic idea is to integrate both high-level perceptual losses and low-level pixel losses by a deep residual convolutional neural network (CNN) over a devised variational loss function with strong human perceptual consistency. Such deep residual CNN network leads to a visually pleasing image representation during the suppression of power consumption. Experimental results demonstrated the superiority of our deep battery saver to existing PCCE methods. Jia-Li Yin, Yan-Tsung Peng, Chung-Chi Tsai |
IEEE Trans. Multim. | 1 |
| 2020 | Single Image Glare Removal Using Deep Convolutional NetworksabstractDeep convolutional neural networks have been investigated for atmospheric particle removal and accomplished the state-of-the-art performance. Most of the previous studies however focus on removing the effects of atmospheric particles but not on glares caused by direct or reflected sunlight on images. In this paper, we propose a decompose-refine network for single image glare removal. Specifically, our network is composed of a glare detection subnetwork and a glare removal subnetwork, which are respectively in charge of glare detection and removal. Experimental results show that our network outperforms the state-of-the-art network baselines on testing dataset. Shiting Ye, Jia-Li Yin, Dewang Chen, YunBing Wu |
ICIP | 2 |
| 2020 | Deep Prior Guided Network For High-Quality Image FusionabstractHigh dynamic range imaging requires fusing a set of low dynamic range (LDR) images at different exposure levels. Existing works combine the LDRs by either assigning each LDR a weighting map based on texture metrics at the pixel level or transferring the images into semantic space at the feature level while neglecting the fact that both texture calibration and semantic consistency are required. In this paper, we propose a novel encoder-decoder network consisting of a content prior guided (CPG) encoder and a detail prior guided (DPG) decoder for fusing the images at both the pixel level and feature level. Explicitly, the encoder constructed by the CPG layers includes the pyramid content prior to blend at the pixel level to transform the feature maps in the encoding layers. Correspondingly, the decoder comprises the DPG layers incorporated with the Laplacian pyramid detail prior to further boost the fusion performance. As the content and the detail priors are added to the network in a pyramid-structure manner, which provides fine-grained control to the features, both semantic consistency and texture calibration can be assured. Extensive experiments demonstrated the superiority of our method over existing state-of-the-art methods. Jia-Li Yin, Yan-Tsung Peng, Chung-Chi Tsai |
ICME | 1 |
| 2020 | Gaussian-Adaptive Bilateral FilterabstractRecent studies have demonstrated that a bilateral filter can increase the quality of edge-preserving image smoothing significantly. Different strategies or mechanisms have been used to eliminate the brute-force computation in bilateral filters. However, blindly decreasing the processing time of the bilateral filter cannot further ameliorate the effectiveness of filter. In addition, even when the processing speed of the filter is increased, inherent problem occurred in the Gaussian range kernel when facing a noise filtering input and its effect on edge-preserving image smoothing operation are barely discussed. In this letter, we propose a novel Gaussian-adaptive bilateral filter (GABF) to resolve the aforementioned problem. The basic idea is to acquire a low-pass guidance for the range kernel by a Gaussian spatial kernel. Such low-pass guidance lead to a clean Gaussian range kernel for later bilateral composite. The results of experiments conducted on several test datasets indicate that the proposed GABF outperforms most existing bilateral-filter-based methods. Yi-Syuan Tseng, Jia-Li Yin |
IEEE Signal Process. Lett. | 3 |
| 2020 | Power-Constrained Image Contrast Enhancement Through Sparse Representation by Joint Mixed-Norm RegularizationabstractPower-constrained image contrast enhancement is a fundamental step for improving the battery life of modern consumer devices with embedded emissive-display panels, such as organic light-emitting diodes (OLEDs). The conventional power-constrained image contrast enhancement in OLED displays is typically performed using histogram-relevant priors or heuristic curve-fitted techniques. This results in underexposure effects or color-tone changes in the reconstructed image. Therefore, this paper proposes a novel power-constrained sparse representation model by joint l2, 1, γ, and isotropic total variation norm (called mixed-norm) regularized sparse coding to simultaneously improve power saving and the perceptible visual quality of the OLED displays. The qualitative and quantitative experiments demonstrate that the proposed technique noticeably outperforms the state-of-the-art power-constrained contrastenhancement techniques. Jia-Li Yin, En-Hung Lai |
IEEE Trans. Circuits Syst. Video Technol. | 1 |
| 2020 | Color Transferred Convolutional Neural Networks for Image DehazingabstractImage dehazing is a crucial image processing step for outdoor vision systems. However, images recovered through conventional image dehazing methods that use either haze-relevant priors or heuristic cues to estimate transmission maps may not lead to sufficiently accurate haze removal from single images. The most commonly observed effects are darkened and brightened artifacts on some areas of the recovered images, which cause considerable loss of fidelity, brightness, and sharpness. This paper develops a variational image dehazing method on the basis of a color-transfer image dehazing model that is superior to conventional image dehazing methods. By creating a color-transfer image dehazing model to remove haze obscuration and acquire information regarding the coefficients of the model by using the devised convolutional neural network-based deep framework as a supervised learning strategy, an image fidelity, brightness, and sharpness can be effectively restored. The experimental results verify through quantitative and qualitative evaluations of either synthesized or real haze images, and the proposed method outperforms existing single image dehazing methods. Jia-Li Yin, Yi-Chi Huang, Shao-Zhen Ye |
IEEE Trans. Circuits Syst. Video Technol. | 1 |
| 2020 | Driver Danger-Level Monitoring System Using Multi-Sourced Big Driving DataabstractDanger-level analysis is widely used to prevent potential driving risks based on driving performance. Such analysis is essential for monitoring driver performance. Moreover, danger-level analysis is vital for automotive safety systems and driving assistance applications. However, danger-level analysis that simultaneously considers driver-, vehicle-, and road-related information from driving data has rarely been conducted. Such analysis is very challenging due to the issues associated with the high volume and high variety in multisourced driving data. In this paper, we propose a novel danger-level analysis framework for dealing with high variety and high volume problems of multisourced driving data. Built upon a feature extraction method in the proposed framework, we first profile multisourced driving features for overcoming the variety problem. Next, danger-level analysis is formulated as a multiobjective pursuit problem in a linear model. The problem is then solved using a semisupervised learning strategy to overcome the volume issue. Therefore, the danger level can be accurately estimated from multisourced driving data by using the proposed framework. The experimental results indicate that the proposed framework outperforms existing machine learning techniques for multisourced driving data. Jia-Li Yin, K. Robert Lai |
IEEE Trans. Intell. Transp. Syst. | 1 |
| 2019 | Towards Unsupervised Single Image Dehazing With Deep LearningabstractDeep learning computation is often used in single-image de-hazing techniques for outdoor vision systems. Its development is restricted by the difficulties in providing a training set of degraded and ground-truth image pairs. In this paper, we develop a novel model that utilizes cycle generative adversarial network through unsupervised learning to effectively remove the requirement of a haze/depth data set. Qualitative and quantitative experiments demonstrated that the proposed model outperforms existing state-of-the-art dehazing models when tested on both synthetic and real haze images. Lu-Yao Huang, Jia-Li Yin, Shao-Zhen Ye |
ICIP | 2 |
| 2019 | Color Shifting-Aware Image DehazingabstractBuilt upon an image formation model for a single hazy image, existing image dehazing methods typically restore hazed pixels by estimating the unknown transmission map and global ambient light via exploiting image priors. They often produce visually unpleasing results when hazy images are with unwanted color shifts due to inaccurate estimation about the actual ambient light of hazy images with color shifts. To address the problem, we propose a novel color shifting-aware image dehazing model that explicitly disentangles the inference of the image formation model. Specifically, our model attempts to calibrate color fading and shifting first, and then restores the hazed pixels via the scene depth based gamma correction using the color-corrected image as the guidance. Extensive experiments show that the proposed dehazing model significantly outperforms existing dehazing methods and achieves superior dehazing results on challenging cases with unwanted color casts. Jia-Li Yin, Yan-Tsung Peng |
ISM | 1 |
| 2018 | Highly Accurate Image Reconstruction for Multimodal Noise Suppression Using Semisupervised Learning on Big DataabstractImpulse noise corruption in digital images frequently occurs because of errors generated by noisy sensors or communication channels, such as faulty memory locations in devices, malfunctioning pixels within a camera, or bit errors in transmission. Although recently developed big data streaming enhances the viability of video communication, visual distortions in images caused by impulse noise corruption can negatively affect video communication applications. In addition, sparsity, density, and multimodality in large volumes of noisy images have often been ignored in recent studies, whereas these issues have become important because of the increasing viability of video communication services. To effectively eliminate the visual effects generated by the impulse noise from the corrupted images, this study proposes a novel model that uses a devised cost function involving semisupervised learning based on a large amount of corrupted image data with a few labeled training samples. The proposed model qualitatively and quantitatively outperforms the existing state-of-the-art image reconstruction models in terms of the denoising effect. Jia-Li Yin |
IEEE Trans. Multim. | 1 |