Jiahuan Long

dblp:244/4962 · DBLP profile ↗
← Back
6ranked-venue papers
4as first author
6since 2021 · last 2026
0000-0001-6892-4101ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 4 · 3 first-author · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
4 papers
Trustworthy machine learning · 48% Image recognition and object detection · 13% Efficient and distributed learning · 11%
Network and information security
1 paper
Security and privacy of machine learning · 100%

Topics — the 12 heaviest of 12, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning › robustness
adversarial attack
1.622025
CDUPatch: Color-Driven Universal Adversarial Patch Attack for Dual-Modal Visible-Infrared Detectors · ACM Multimedia 2025
PapMOT: Exploring Adversarial Patch Attack Against Multiple Object Tracking · ECCV (51) 2024
Machine learning › Efficient and distributed learning
parameter-efficient fine-tuning
1.012026
Parameter-Free Fine-tuning via Redundancy Elimination for Vision Foundation Models · AAAI 2026
Machine learning › Transfer learning and domain adaptation › foundation model adaptation
vision foundation model adaptation
1.012026
Parameter-Free Fine-tuning via Redundancy Elimination for Vision Foundation Models · AAAI 2026
Machine learning › Trustworthy machine learning › adversarial machine learning
adversarial defense
0.912025
Robust SAM: On the Adversarial Robustness of Vision Foundation Models · AAAI 2025
Machine learning › Trustworthy machine learning › adversarial machine learning › physical adversarial attack
adversarial patch attack
0.912025
CDUPatch: Color-Driven Universal Adversarial Patch Attack for Dual-Modal Visible-Infrared Detectors · ACM Multimedia 2025
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
0.912025
Robust SAM: On the Adversarial Robustness of Vision Foundation Models · AAAI 2025
Computer vision › Segmentation and scene understanding › prompt-based segmentation
segment anything model
0.912025
Robust SAM: On the Adversarial Robustness of Vision Foundation Models · AAAI 2025
Computer vision › Image recognition and object detection › object detection › multimodal object detection
visible-infrared object detection
0.912025
CDUPatch: Color-Driven Universal Adversarial Patch Attack for Dual-Modal Visible-Infrared Detectors · ACM Multimedia 2025
Computer vision › Video understanding and tracking
multi-object tracking
0.812024
PapMOT: Exploring Adversarial Patch Attack Against Multiple Object Tracking · ECCV (51) 2024
Computer vision › Image recognition and object detection
image classification
0.312026
Parameter-Free Fine-tuning via Redundancy Elimination for Vision Foundation Models · AAAI 2026
Machine learning › Trustworthy machine learning
robustness
0.312025
CDUPatch: Color-Driven Universal Adversarial Patch Attack for Dual-Modal Visible-Infrared Detectors · ACM Multimedia 2025
Security and privacy of machine learning › adversarial attack
transferable adversarial attack
0.312025
Robust SAM: On the Adversarial Robustness of Vision Foundation Models · AAAI 2025

Methods — techniques the papers use, named apart from their topics

singular value decomposition · 1.7few-parameter adaptation · 1.7cross-prompt attack · 1.7redundancy elimination · 1.0channel selection · 1.0multi-scale clipping · 0.9dataset construction · 0.9RGB-to-infrared adapter · 0.9adversarial patch · 0.8
YearPublicationVenuePosition
2026 Parameter-Free Fine-tuning via Redundancy Elimination for Vision Foundation Models
abstract
Vision foundation models (VFMs) have demonstrated remarkable capabilities in learning universal visual representations. However, adapting these models to downstream tasks conventionally requires parameter updates, with even parameter-efficient fine-tuning methods necessitating the modification of thousands to millions of weights. In this paper, we investigate the redundancies in the segment anything model (SAM) and then propose a novel parameter-free fine-tuning method. Unlike traditional fine-tuning methods that adjust parameters, our method emphasizes selecting, reusing, and enhancing pre-trained features, offering a new perspective on fine-tuning foundation models. Specifically, we introduce a channel selection algorithm based on the model's output difference to identify redundant and effective channels. By selectively replacing the redundant channels with more effective ones, we filter out less useful features and reuse more task-irrelevant features to downstream tasks, thereby enhancing the task-specific feature representation. Experiments on both out-of-domain and in-domain datasets demonstrate the efficiency and effectiveness of our method in different vision tasks (e.g., image segmentation, depth estimation and image classification). Notably, our approach can seamlessly integrate with existing fine-tuning strategies (e.g., LoRA, Adapter), further boosting the performance of already fine-tuned models. Moreover, since our channel selection involves only model inference, our method significantly reduces GPU memory overhead.
Jiahuan Long, Tingsong Jiang, Wen Yao 0001, Yizhe Xiong, Zhengqin Xu, Shuai Jia, Chao Ma 0004
AAAI1
2026 Invisibility stickers against LiDAR: Adversarial attacks on point cloud intensity for LiDAR-based object detection
Junqi Wu 0002, Wen Yao 0001, Donghua Wang 0001, Jiahuan Long, Tingsong Jiang, Yang Yang 0123, Chengyin Hu, Chao Ma 0004
Comput. Vis. Image Underst.5
2025 Robust SAM: On the Adversarial Robustness of Vision Foundation Models
abstract
The Segment Anything Model (SAM) is a widely used vision foundation model with diverse applications, including image segmentation, detection, and tracking. Given SAM's wide applications, understanding its robustness against adversarial attacks is crucial for real-world deployment. However, research on SAM's robustness is still in its early stages. Existing attacks often overlook the role of prompts in evaluating SAM's robustness, and there has been insufficient exploration of defense methods to balance the robustness and accuracy. To address these gaps, this paper proposes an adversarial robustness framework designed to evaluate and enhance the robustness of SAM. Specifically, we introduce a cross-prompt attack method to enhance the attack transferability across different prompt types. Besides attacking, we propose a few-parameter adaptation strategy to defend SAM against various adversarial attacks. To balance robustness and accuracy, we use the singular value decomposition (SVD) to constrain the space of trainable parameters, where only singular values are adaptable. Experiments demonstrate that our cross-prompt attack method outperforms previous approaches in terms of attack success rate on both SAM and SAM 2. By adapting only 512 parameters, we achieve at least a 15% improvement in mean intersection over union (mIoU) against various adversarial attacks. Compared to previous defense methods, our approach enhances the robustness of SAM while maximally maintaining its original performance.
Jiahuan Long, Zhengqin Xu, Tingsong Jiang, Wen Yao 0001, Shuai Jia, Chao Ma 0004, Xiaoqian Chen
AAAI1
2025 CDUPatch: Color-Driven Universal Adversarial Patch Attack for Dual-Modal Visible-Infrared Detectors
abstract
Adversarial patches are widely used to evaluate the robustness of object detection systems in real-world scenarios. These patches were initially designed to deceive single-modal detectors (e.g., visible or infrared) and have recently been extended to target visible-infrared dual-modal detectors. However, existing dual-modal adversarial patch attacks have limited attack effectiveness across diverse physical scenarios. To address this, we propose CDUPatch, a universal cross-modal patch attack against visible-infrared object detectors across scales, views, and scenarios. Specifically, we observe that color variations lead to different levels of thermal absorption, resulting in temperature differences in infrared imaging. Leveraging this property, we propose an RGB-to-infrared adapter that maps RGB patches to infrared patches, enabling unified optimization of cross-modal patches. By learning an optimal color distribution on the adversarial patch, we can manipulate its thermal response and generate an adversarial infrared texture. Additionally, we introduce a multi-scale clipping strategy and construct a new visible-infrared dataset, MSDrone, which contains aerial vehicle images in varying scales and perspectives. These data augmentation strategies enhance the robustness of our patch in real-world conditions. Experiments on four benchmark datasets (e.g., DroneVehicle, LLVIP, VisDrone, MSDrone) show that our method outperforms existing patch attacks in the digital domain. Extensive physical tests further confirm strong transferability across scales, views, and scenarios. Attack demos are provided in the supplementary materials.
Jiahuan Long, Wen Yao 0001, Tingsong Jiang, Shuai Jia, Junqi Wu 0002, Xiaohu Zheng, Chao Ma 0004
ACM Multimedia1
2024 PapMOT: Exploring Adversarial Patch Attack Against Multiple Object Tracking
Jiahuan Long, Tingsong Jiang, Wen Yao 0001, Shuai Jia, Weien Zhou, Chao Ma 0004, Xiaoqian Chen
ECCV (51)1
2021 Lightweight Searchable Encryption Protocol for Industrial Internet of Things
abstract
Industrial Internet of Things (IoT) has suffered from insufficient identity authentication and dynamic network topology, thereby resulting in vulnerabilities to data confidentiality. Recently, the attribute-based encryption (ABE) schemes have been regarded as a solution to ensure data transmission security and the fine-grained sharing of encrypted IoT data. However, most of existing ABE schemes that bring tremendous computational cost are not suitable for resource-constrained IoT devices. Therefore, lightweight and efficient data sharing and searching schemes suitable for IoT applications are of great importance. To this end, In this article, we propose a light searchable ABE scheme (namely LSABE). Our scheme can significantly reduce the computing cost of IoT devices with the provision of multiple-keyword searching for data users. Meanwhile, we extend the LSABE scheme to multiauthority scenarios so as to effectively generate and manage the public/secret keys in the distributed IoT environment. Finally, the experimental results demonstrate that our schemes can significantly maintain computational efficiency and save the computational cost at IoT devices, compared to other existing schemes.
Ke Zhang 0022, Jiahuan Long, Hongning Dai, Kaitai Liang, Muhammad Imran 0001
IEEE Trans. Ind. Informatics2