EDBT 2026 Demo / reviewers in the wild / expert
Chengsheng Yuan 0001
dblp:237/3404-1
· DBLP profile ↗
21ranked-venue papers
11as first author
18since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 7 · 5 first-author · 7 since 2021Artificial intelligence and machine learning · 5 · 4 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 4 since 2021Security and privacy · 3 · 2 first-author · 2 since 2021Computer networks · 2 · 1 first-author · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards Provably Secure and Highly Robust Generative Image Steganography Leveraging Latent Diffusion ModelabstractGenerative image steganography has attracted significant attention for its exceptional resistance to steganalysis. However, current generative steganography methods still face limitations in terms of the lack of provable security guarantees under statistical analysis and vulnerability to real-world, unforeseen channel attacks. To address these issues, this paper proposes a novel generative image steganography framework that leverages the Latent Diffusion Model (LDM). Notably, we have uncover a consistent trend: regardless of whether an image has undergone attacks such as compression or noise addition, the sign pattern of values in its latent vector encoded by the LDM remains largely invariant. Capitalizing on this trend, we have devised an adaptive distribution-preserving mapping (ADPM) mechanism, capable of converting a secret message into a latent vector that follows standard normal distribution in an adjustable way. Since both the secret latent vector and the latent vector randomly generated during regular image generation follow the same distribution, satisfying the optimal input conditions for the diffusion model, the proposed method can achieve provable security. Experimental results demonstrate the outstanding performance of our approach in terms of robustness, security, and extraction accuracy. Chengsheng Yuan 0001, Zhaonan Ji, Zhili Zhou 0001, Xinting Li, Zhihua Xia |
AAAI | 1 |
| 2026 | MediProtoRank: Prototype-Mediated Conditional Alignment in Hyperbolic Space for Unsupervised Keyphrase Extraction
Jingyu Cao, Chengsheng Yuan 0001, Qingcheng Liu |
ICIC (24) | 3 |
| 2026 | SSICE: Sentiment Subspace-Guided Slot Injection and Context Enhancement for Sentiment Analysis
Gu Li, Chengsheng Yuan 0001, Qingcheng Liu |
ICIC (22) | 3 |
| 2026 | A robust dual-pronged proactive defense framework against deepfakes via adversarial semi-fragile watermarking
Chengsheng Yuan 0001, Youqiang Cao, Zhili Zhou 0001, Zhangjie Fu 0001, Zhihua Xia, Q. M. Jonathan Wu |
Expert Syst. Appl. | 1 |
| 2026 | Zero-Knowledge Proof-Based IP Protection of Visual Large Models of Autonomous Driving
Chengsheng Yuan 0001, Lvyang Cao, Xinting Li, Zhili Zhou 0001, Zhihua Xia, Zhangjie Fu 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | RiceSeg-YOLO: A Multi-scale Attention-Based Instance Segmentation Model for Rice Leaf Rolling in Complex Paddy Environments
Yiling Ding, Chengsheng Yuan 0001, Qiulin Wu |
ICIC (5) | 3 |
| 2025 | MambaForDIF: Distance-Importance Features and Long-Range Dependencies for Enhancing Aspect-Based Sentiment Analysis
Kaiqi Wang, Chengsheng Yuan 0001 |
ICIC (22) | 3 |
| 2025 | AT-diff: An adversarial diffusion model for unrestricted adversarial examples generation
Chengsheng Yuan 0001, Jingfa Pang, Jianwei Fei, Xinting Li, Zhihua Xia |
Knowl. Based Syst. | 1 |
| 2025 | Compressed Domain Invariant Adversarial Representation Learning for Robust Audio Deepfake DetectionabstractThe primary aim of audio deepfake detection (ADD) is to thwart deception arising from forged audio generated through text-to-speech or voice conversion technologies. However, encoding speech signals using diverse compression algorithms introduces discrepancies that significantly impair the performance of existing countermeasure systems. To tackle these challenges, this letter proposes a robust audio deepfake detection method based on Compressed Domain Invariant Adversarial Representation Learning with Adaptive Token Pooling (DANet-ATP). This framework incorporates a Compression Codecs Discriminator (CCD) that, through adversarial learning in tandem with the backbone network, enhances the model's ability to extract more robust features across diverse compression codecs. Moreover, to efficiently prune redundant frame-level features while retaining vital spoofing cues, the letter designs a plug-and-play, parameter-free Adaptive Token Pooling module, significantly improving detection performance. Experimental results on the ASVspoof2021 DF dataset showcase the exceptional performance of the proposed model. Furthermore, a series of ablation experiments validate the validity and effectiveness of the proposed method. Chengsheng Yuan 0001, Yifei Chen 0013, Zhili Zhou 0001, Zhihua Xia, Yongfeng Huang 0001 |
IEEE Signal Process. Lett. | 1 |
| 2025 | DGADM-GIS: Deterministic Guided Additive Diffusion Model for Generative Image SteganographyabstractIn recent years, generative steganography has witnessed remarkable progress in the field of covert communication. It leverages techniques such as generative adversarial networks (GANs) or flow-based generative models (GLOW) to generate stego images. However, these approaches often grapple with the dilemma of achieving optimal steganographic capacity while ensuring the accurate extraction of hidden information. Additionally, the models occasionally still generate low-quality images that are highly vulnerable to detection by steganalysis tools. To tackle the aforementioned challenges and enhance the overall performance of generative image steganography, this paper proposes the deterministic guided additive diffusion model for generative image steganography (DGADM-GIS). Initially, we devise a reversible mapping function that is used for deterministic guided by a provided secret message, and then construct a secret latent Gaussian vector. Moreover, the proposed DGADM-GIS framework designs an additive sampling method based on the superposition principle of normal distribution to obtain a Gaussian vector that satisfies independent, random and obeys the standard normal distribution, which is transformed to a stego image in a way of maintaining the distribution by the diffusion model. Furthermore, we conduct error analysis experiments on our proposed scheme and derive methods to enhance the accuracy of secret information extraction. The experimental results show that our proposed steganographic method exhibits robust resistance to steganalysis. When embedding 3 bits of secret information per pixel, it achieves nearly 100% extraction accuracy. Chengsheng Yuan 0001, Zhaonan Ji, Xinting Li, Zhili Zhou 0001, Zhihua Xia, Q. M. Jonathan Wu |
IEEE Trans. Dependable Secur. Comput. | 1 |
| 2024 | CLGuard: Presentation Attack Detection Model using Clean Labels for Copyright ProtectionabstractPresentation Attack Detection Model (PADM) plays a crucial role in biometric authentication, particularly in fingerprint Liveness Detection Model (FLDM). However, FLDM is susceptible to various unauthorized usage and dissemination threats, highlighting the urgent necessity to protect its Intellectual Property (IP). While previous backdoor watermarking techniques have been effective in authenticating the IP of FLDM, they unfortunately pose a risk to its performance. Thus, this paper presents a novel model watermarking strategy named CLGuard, leveraging robust fingerprint attributes to create authentic label watermarks, facilitating the verification of ownership for FLDM. Notably, these watermarks seamlessly integrate into both the input and output layers, minimizing any irreversible modifications to the feature space of FLDM, ensuring optimal performance. Initially, a selection of High Complexity Inputs (HCI) is chosen based on robust fingerprint attributes, and watermark data is embedded into the HCI set using imperceptible backdoor. Simultaneously, a coding network is deployed to conceal the watermark data within the background layer of the samples, mitigating any adverse impacts on the model's deep feature space. Subsequently, a mapping function is established between triggers and original labels, enabling the fine-tuning of the model with embedded watermarks on a diverse mixed dataset. Ultimately, IP is authenticated by leveraging trigger sets and original misidentification sets. Comprehensive experiments on multiple benchmark datasets demonstrate that CLGuard effectively authenticates suspicious PADM IP without introducing anomalous input-output pairs, thus preserving the original task performance. Furthermore, it withstands attacks such as fine-tuning, neuronal cleanse, and watermark removal, showcasing reliability, stealthiness, fidelity, and robustness. Chengsheng Yuan 0001, Zhili Zhou 0001, Xinting Li, Zhangjie Fu 0001 |
MSN | 1 |
| 2024 | FIL-FLD: Few-Shot Incremental Learning with EMD Metric for High Generalization Fingerprint Liveness Detection
Chengsheng Yuan 0001, Wenqian Qiu, Zhili Zhou 0001, Xinting Li, Xianyi Chen |
PRCV (15) | 1 |
| 2024 | A novel hybrid network model for image steganalysis
Shichen Yang, Xingxing Jia, Fuhua Zou, Yangshijie Zhang, Chengsheng Yuan 0001 |
J. Vis. Commun. Image Represent. | 5 |
| 2024 | Spatial-frequency gradient fusion based model augmentation for high transferability adversarial attack
Jingfa Pang, Chengsheng Yuan 0001, Zhihua Xia, Xinting Li, Zhangjie Fu 0001 |
Knowl. Based Syst. | 2 |
| 2023 | Glow Model-Based Latent Vector Optimization for Generative Image Steganography in Edge and Cloud Computing EnvironmentabstractIn edge and cloud computing environments, to protect and manage secret information, the sharing and recovery of each secret image are implemented by local servers. However, since existing Generative Image Steganography(GIS) schemes face issues such as low-quality image generation and small hiding capacity. This necessitates the generation of a large number of stego-images to meet the demands of information transmission, thereby imposing a excessive computational burden for those local servers, the above reasons make the existing GIS schemes not suitable for edge and cloud computing environments. To address the above issue, we propose a Latent Vector Optimization(LVO) scheme for GIS with high-quality image generation and large hiding capacity. In the proposed scheme, we introduce the concept of latent vector optimization, wherein the hiding probability of each element within the latent vector is computed based on its expected influence on the quality of the resulting stego-image. Furthermore, our LVO scheme employs an adaptive approach to identify the optimal locations for embedding information while considering a predefined hiding capacity. This adaptation involves giving priority to modifying elements in dimensions characterized by a low latent vector hiding probability, as guided by the characteristics of natural images. Simultaneously, the scheme hides the secret message within elements associated with a high latent vector hiding probability, thus achieving a large hiding capacity while minimizing any adverse effects on the stego-image quality. Compared with the existing GIS schemes, the proposed LVO scheme enhances security, provides high-quality image generation, a large data hiding capacity, meeting the requirements with fewer stego-images. This significantly reduces the communication and computational burden on local servers. Zhipeng Bao, Zhili Zhou 0001, Xutong Cui, Chengsheng Yuan 0001 |
ICPADS | 5 |
| 2023 | Deepfake Fingerprint Detection Model Intellectual Property Protection via Ridge Texture EnhancementabstractIn addition to relying on super computing power and professional domain knowledge, training a high-precision deepfake fingerprint detection model (DFDM) to authenticate the fingerprints also requires the support of massive private fingerprint data. To sum up, the DFDM should be deemed as intellectual property (IP) of the trainers, so it is crucial to protect IP. Currently, most watermarking-based IP protection schemes are implemented by introducing additional tasks, such as constructing trigger sets, fine-tuning model weights, etc., which severely impair the performance of the original task and increase the training cost. Inspired by the feature knowledge learned by the model, this letter proposes an IP protection (IPP) scheme for DFDM by verifying whether the suspect model contains the fingerprint ridge features learned by the victim model from another perspective based on the verifier. Firstly, the local binary pattern (LBP) is used to enhance the ridge texture on the fingerprint samples, so that DFDM can better learn the ridge features. Then, a DFDM lacking texture augmentation is employed as the adversarial model for training the meta-verifier without any alteration to the model parameters. Finally, the trained meta-verifier is used to determine whether the suspected model contains the ridge features in the victim model. The public fingerprint dataset (LivDet2017) was leveraged in the DFDM training process to validate our approach. Experimental results show that the proposed scheme can verify the IP of DFDM and is robust to some common attacks. Chengsheng Yuan 0001, Zhili Zhou 0001, Zhangjie Fu 0001, Zhihua Xia |
IEEE Signal Process. Lett. | 1 |
| 2022 | Adversarial Attack with Adaptive Gradient Variance for Deep Fake Fingerprint DetectionabstractIn recent years, fingerprint liveness detection methods based on deep neural networks have been widely used in various fingerprint recognition systems, such as fingerprint locks and smart phones, etc. However, recent research has revealed that these devices are vulnerable to the spoofing attack of adversarial examples. That is, adding some invisible perturbations to fingerprint image, the deep fake fingerprint detection network may misclassify the image as other classes. The classical example generation methods usually adopt gradient optimization method, but it is prone to falling into local optimum, resulting in poor adversarial attack performance. Accordingly, this paper proposes a novel adversarial attack method called adaptive gradient variance attack (AGVA) for deep fake fingerprint detection. Firstly, we obtain gradient information through the target network to calculate the gradient variance. Then, to avoid falling into the local optimum, the gradient direction is optimized by the gradient variance. In particular, to improve the attack performance, we propose an adaptive hyper-parameter search algorithm using stochastic gradient ascent to search the value of hyper-parameters in adversarial example generation. Experimental results show that compared to existing methods, our method achieves a better black-box attack success rate and higher robustness on the basis of ensuring the white-box attack performance. Chengsheng Yuan 0001, Baojie Cui |
MMSP | 1 |
| 2022 | A Format-compatible Searchable Encryption Scheme for JPEG Images Using Bag-of-wordsabstractThe development of cloud computing attracts enterprises and individuals to outsource their data, such as images, to the cloud server. However, direct outsourcing causes the extensive concern of privacy leakage, as images often contain rich sensitive information. A straightforward way to protect privacy is to encrypt the images using the standard cryptographic tools before outsourcing. However, in such a way the possible usage of the outsourced images would be strongly limited together with the services provided to users, like the Content-Based Image Retrieval (CBIR). In this article, we propose a secure outsourced CBIR scheme, in which an encryption scheme is designed for the widely used JPEG-format images, and the secure features can be directly extracted from such encrypted images. Specifically, the JPEG images are encrypted by the block permutation, intra-block permutation, polyalphabetic cipher, and stream cipher. Then secure local histograms are extracted from the encrypted DCT blocks and the Bag-Of-Words (BOW) model is further used to organize the encrypted local features to represent the image. The proposed image encryption gets all of the image data protected and the experimental results show that the proposed scheme achieves improved accuracy with a small file size expansion. Zhihua Xia, Qiuju Ji, Chengsheng Yuan 0001, Fengjun Xiao |
ACM Trans. Multim. Comput. Commun. Appl. | 4 |
| 2020 | A Novel Weber Local Binary Descriptor for Fingerprint Liveness DetectionabstractIn recent years, fingerprint authentication systems have been extensively deployed in various applications, including attendance systems, authentications on smartphones, mobile payment authorizations, as well as various safety certifications. However, similar to the other biometric identification technologies, fingerprint recognition is vulnerable to artificial replicas made from cheap materials, such as silicon, gelatin, etc. Thus, it is especially necessary to distinguish whether a given fingerprint is a live or a spoof one prior to such authentication. In order to solve the problems above, a novel local descriptor named Weber local binary descriptor for fingerprint liveness detection (FLD) has been proposed in this paper. The method consists of two components: the local binary differential excitation component that extracts intensity-variance features and the local binary gradient orientation component that extracts orientation features. The co-occurrence probability of the two components is calculated to construct a discriminative feature vector, which is fed into support vector machine (SVM) classifiers. The effectiveness of the proposed method is intuitively analyzed on the image samples and numerically demonstrated by Mahalanobis distance. Experiments are performed on two public databases from FLD competitions from 2011 and 2013. The results have proved that the proposed method obtains the best detection accuracy among the existing image local descriptors in FLD. Zhihua Xia, Chengsheng Yuan 0001, Rui Lv, Xingming Sun, Naixue Xiong, Yun Q. Shi 0001 |
IEEE Trans. Syst. Man Cybern. Syst. | 2 |
| 2019 | An effective comparison protocol over encrypted data in cloud computing
Leqi Jiang, Chengsheng Yuan 0001, Xingming Sun, Xiaoli Zhu |
J. Inf. Secur. Appl. | 3 |
| 2019 | Difference co-occurrence matrix using BP neural network for fingerprint liveness detection
Chengsheng Yuan 0001, Xingming Sun, Q. M. Jonathan Wu |
Soft Comput. | 1 |