EDBT 2026 Demo / reviewers in the wild / expert
Ziyuan Luo
dblp:247/9588
· DBLP profile ↗
22ranked-venue papers
10as first author
18since 2021 · last 2026
0000-0003-1580-9809ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 14 · 4 first-author · 12 since 2021Artificial intelligence and machine learning · 13 · 7 first-author · 11 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GS-Checker: Tampering Localization for 3D Gaussian SplattingabstractRecent advances in editing technologies for 3D Gaussian Splatting (3DGS) have made it simple to manipulate 3D scenes. However, these technologies raise concerns about potential malicious manipulation of 3D content. To avoid such malicious applications, localizing tampered regions becomes crucial. In this paper, we propose GS-Checker, a novel method for locating tampered areas in 3DGS models. Our approach integrates a 3D tampering attribute into the 3D Gaussian parameters to indicate whether the Gaussian has been tampered. Additionally, we design a 3D contrastive mechanism by comparing the similarity of key attributes between 3D Gaussians to seek tampering cues at 3D level. Furthermore, we introduce a cyclic optimization strategy to refine the 3D tampering attribute, enabling more accurate tampering localization. Notably, our approach does not require expensive 3D labels for supervision. Extensive experimental results demonstrate the effectiveness of our proposed method to locate the tampered 3DGS area. Haoliang Han, Ziyuan Luo, Anderson Rocha 0001, Renjie Wan |
AAAI | 2 |
| 2026 | Creating Blank Canvas Against AI-enabled Image ForgeryabstractAIGC-based image editing technology has greatly simplified the realistic-level image modification, causing serious potential risks of image forgery. This paper introduces a new approach to tampering detection using the Segment Anything Model (SAM). Instead of training SAM to identify tampered areas, we propose a novel strategy. The entire image is transformed into a blank canvas from the perspective of neural models. Any modifications to this blank canvas would be noticeable to the models. To achieve this idea, we introduce adversarial perturbations to prevent SAM from seeing anything, allowing it to identify forged regions when the image is tampered with. Due to SAM's powerful perceiving capabilities, naive adversarial attacks cannot completely tame SAM. To thoroughly deceive SAM and make it blind to the image, we introduce a frequency-aware optimization strategy, which further enhances the capability of tamper localization. Extensive experimental results demonstrate the effectiveness of our method. Qi Song 0003, Ziyuan Luo, Renjie Wan |
AAAI | 2 |
| 2026 | Naturalistic Typographic Attacks on VLM-Based Image Quality Assessment
Ziyuan Luo, Qi Song 0003, Renjie Wan |
QoMEX | 1 |
| 2026 | Adversarially robust multimedia watermarking via data-centric optimization
Ziyuan Luo, Qi Song 0003, Haoliang Li, Anderson Rocha 0001, Renjie Wan |
Pattern Recognit. | 1 |
| 2026 | MantleMark: Migrating Watermarks From Multi-View Images to Radiance Fields via Frequency ModulationabstractMulti-view images are essential for modern radiance field reconstruction methods like Neural Radiance Fields (NeRF) and 3D Gaussian Splatting (3DGS). While image watermarking is a crucial data protection and ownership verification technique, it faces unprecedented challenges in multi-view scenarios. Traditional 2D watermarking techniques often fail to maintain detectability in rendered views, while existing 3D watermarking methods are typically limited to specific reconstruction methods and require access to the reconstruction process. To address these limitations, we propose MantleMark, a watermarking framework that migrates watermarks from multi-view images to radiance fields via frequency modulation. Our key insight is constructing a mantle-like Frequency-domain Watermarking Representation in 3D frequency space, which can be projected to create view-dependent watermarking patterns. Relying upon the Fourier Projection-Slice Theorem, we embed these patterns through magnitude spectrum modulation in the image frequency domain, enabling watermarks to migrate into 3D representations. This approach ensures watermark detectability in rendered views regardless of the reconstruction methods used by adversaries. Extensive experiments demonstrate that our method achieves robust watermark detection while maintaining high visual quality across various radiance field-based reconstruction methods. Ziyuan Luo, Jun Liu 0036, Haoliang Li, Anderson Rocha 0001, Renjie Wan |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Meme Trojan: Backdoor Attacks Against Hateful Meme Detection via Cross-Modal TriggersabstractHateful meme detection aims to prevent the proliferation of hateful memes on various social media platforms. Considering its impact on social environments, this paper introduces a previously ignored but significant threat to hateful meme detection: backdoor attacks. By injecting specific triggers into meme samples, backdoor attackers can manipulate the detector to output their desired outcomes. To explore this, we propose the Meme Trojan framework to initiate backdoor attacks on hateful meme detection. Meme Trojan involves creating a novel Cross-Modal Trigger (CMT) and a learnable trigger augmentor to enhance the trigger pattern according to each input sample. Due to the cross-modal property, the proposed CMT can effectively initiate backdoor attacks on hateful meme detectors under an automatic application scenario. Additionally, the injection position and size of our triggers are adaptive to the texts contained in the meme, which ensures that the trigger is seamlessly integrated with the meme content. Our approach outperforms the state-of-the-art backdoor attack methods, showing significant improvements in effectiveness and stealthiness. We believe that this paper will draw more attention to the potential threat posed by backdoor attacks on hateful meme detection. Ruofei Wang, Hongzhan Lin 0001, Ziyuan Luo, Ka Chun Cheung, Simon See, Jing Ma 0004, Renjie Wan |
AAAI | 3 |
| 2025 | Align 3D Representation and Text Embedding for 3D Content PersonalizationabstractRecent advances in NeRF and 3DGS have significantly enhanced the efficiency and quality of 3D content synthesis. However, efficient personalization of generated 3D content remains a critical challenge. Current 3D personalization approaches predominantly rely on knowledge distillation-based methods, which require computationally expensive retraining procedures. To address this challenge, we propose Invert3D, a novel framework for convenient 3D content personalization. Nowadays, vision-language models such as CLIP enable direct image personalization through aligned vision-text embedding spaces. However, the inherent structural differences between 3D content and 2D images preclude direct application of these techniques to 3D personalization. Our approach bridges this gap by establishing alignment between 3D representations and text embedding spaces. Specifically, we develop a camera-conditioned 3D-to-text inverse mechanism that projects 3D contents into a 3D embedding aligned with text embeddings. This alignment enables efficient manipulation and personalization of 3D content through natural language prompts, eliminating the need for computationally retraining procedures. Extensive experiments demonstrate that Invert3D achieves effective personalization of 3D content. Qi Song 0003, Ziyuan Luo, Ka Chun Cheung, Simon See, Renjie Wan |
ACM Multimedia | 2 |
| 2025 | MarkSplatter: Generalizable Watermarking for 3D Gaussian Splatting Model via Splatter Image StructureabstractThe growing popularity of 3D Gaussian Splatting (3DGS) has intensified the need for effective copyright protection. Current 3DGS watermarking methods rely on computationally expensive fine-tuning procedures for each predefined message. We propose the first generalizable watermarking framework that enables efficient protection of Splatter Image-based 3DGS models through a single forward pass. We introduce GaussianBridge that transforms unstructured 3D Gaussians into Splatter Image format, enabling direct neural processing for arbitrary message embedding. To ensure imperceptibility, we design a Gaussian-Uncertainty-Perceptual heatmap prediction strategy for preserving visual quality. For robust message recovery, we develop a dense segmentation-based extraction mechanism that maintains reliable extraction even when watermarked objects occupy minimal regions in rendered views. Project page: https://kevinhuangxf.github.io/marksplatter. Xiufeng Huang, Ziyuan Luo, Qi Song 0003, Ruofei Wang, Renjie Wan |
ACM Multimedia | 2 |
| 2025 | ImageSentinel: Protecting Visual Datasets from Unauthorized Retrieval-Augmented Image GenerationabstractThe widespread adoption of Retrieval-Augmented Image Generation (RAIG) has raised significant concerns about the unauthorized use of private image datasets. While these systems have shown remarkable capabilities in enhancing generation quality through reference images, protecting visual datasets from unauthorized use in such systems remains a challenging problem. Traditional digital watermarking approaches face limitations in RAIG systems, as the complex feature extraction and recombination processes fail to preserve watermark signals during generation. To address these challenges, we propose ImageSentinel, a novel framework for protecting visual datasets in RAIG. Our framework synthesizes sentinel images that maintain visual consistency with the original dataset. These sentinels enable protection verification through randomly generated character sequences that serve as retrieval keys. To ensure seamless integration, we leverage vision-language models to generate the sentinel images. Experimental results demonstrate that ImageSentinel effectively detects unauthorized dataset usage while preserving generation quality for authorized applications. Ziyuan Luo, Yangyi Zhao, Ka Chun Cheung, Simon See, Renjie Wan |
NeurIPS | 1 |
| 2025 | The NeRF Signature: Codebook-Aided Watermarking for Neural Radiance FieldsabstractNeural Radiance Fields (NeRF) have been gaining attention as a significant form of 3D content representation. With the proliferation of NeRF-based creations, the need for copyright protection has emerged as a critical issue. Although some approaches have been proposed to embed digital watermarks into NeRF, they often neglect essential model-level considerations and incur substantial time overheads, resulting in reduced imperceptibility and robustness, along with user inconvenience. In this paper, we extend the previous criteria for image watermarking to the model level and propose NeRF Signature, a novel watermarking method for NeRF. We employ a Codebook-aided Signature Embedding (CSE) that does not alter the model structure, thereby maintaining imperceptibility and enhancing robustness at the model level. Furthermore, after optimization, any desired signatures can be embedded through the CSE, and no fine-tuning is required when NeRF owners want to use new binary signatures. Then, we introduce a joint pose-patch encryption watermarking strategy to hide signatures into patches rendered from a specific viewpoint for higher robustness. In addition, we explore a Complexity-Aware Key Selection (CAKS) scheme to embed signatures in high visual complexity patches to enhance imperceptibility. The experimental results demonstrate that our method outperforms other baseline methods in terms of imperceptibility and robustness. Ziyuan Luo, Anderson Rocha 0001, Boxin Shi, Qing Guo 0005, Haoliang Li, Renjie Wan |
IEEE Trans. Pattern Anal. Mach. Intell. | 1 |
| 2024 | CogSimulator: A Model for Simulating User Cognition & Behavior with Minimal Data for Tailored Cognitive Enhancement
Weizhen Bian, Yubo Zhou, Yuanhang Luo, Ming Mo, Siyan Liu 0001, Yikai Gong, Ziyuan Luo, Aobo Wang, Renjie Wan |
CogSci | 7 |
| 2024 | Imaging Interiors: An Implicit Solution to Electromagnetic Inverse Scattering Problems
Ziyuan Luo, Boxin Shi, Haoliang Li, Renjie Wan |
ECCV (7) | 1 |
| 2024 | Protecting NeRFs' Copyright via Plug-And-Play Watermarking Base Model
Qi Song 0003, Ziyuan Luo, Ka Chun Cheung, Simon See, Renjie Wan |
ECCV (11) | 2 |
| 2024 | Geometry Cloak: Preventing TGS-based 3D Reconstruction from Copyrighted ImagesabstractSingle-view 3D reconstruction methods like Triplane Gaussian Splatting (TGS) have enabled high-quality 3D model generation from just a single image input within seconds. However, this capability raises concerns about potential misuse, where malicious users could exploit TGS to create unauthorized 3D models from copyrighted images. To prevent such infringement, we propose a novel image protection approach that embeds invisible geometry perturbations, termed ``geometry cloaks'', into images before supplying them to TGS. These carefully crafted perturbations encode a customized message that is revealed when TGS attempts 3D reconstructions of the cloaked image. Unlike conventional adversarial attacks that simply degrade output quality, our method forces TGS to fail the 3D reconstruction in a specific way - by generating an identifiable customized pattern that acts as a watermark. This watermark allows copyright holders to assert ownership over any attempted 3D reconstructions made from their protected images. Extensive experiments have verified the effectiveness of our geometry cloak. Qi Song 0003, Ziyuan Luo, Ka Chun Cheung, Simon See, Renjie Wan |
NeurIPS | 2 |
| 2024 | Scenedoor: An Environmental Backdoor Attack for Face RecognitionabstractFace recognition is often used for biometric validation, which has become a significant technique in our society. Due to its sensitive applications, security vulnerabilities posed by backdoor attacks have attracted considerable focus. Current backdoor attack methods use digital perturbations or physical objects as triggers, while these additional requirements make existing backdoor attacks less viable in real-world applications. To address this issue, we propose a novel backdoor attack method named Scene Backdoor (Scenedoor), which injects a 3D scene as the trigger that effectively simplifies the backdoor activation. Any person who appears in this scene will be attacked as the attacker-desired identity. Specifically, we reconstruct a 3D scene from several 2D images and then blend the facial part extracted from the input sample with the reconstructed scene to generate the poisoned image. Extensive experiments are conducted on CelenDF (v2), CelebA-HQ, and PinsFace datasets, demonstrating that Scenedoor overtakes five state-of-the-art methods in terms of effectiveness, stealthiness, and robustness. Ruofei Wang, Ziyuan Luo, Haoliang Li, Renjie Wan |
VCIP | 2 |
| 2023 | CopyRNeRF: Protecting the CopyRight of Neural Radiance FieldsabstractNeural Radiance Fields (NeRF) have the potential to be a major representation of media. Since training a NeRF has never been an easy task, the protection of its model copyright should be a priority. In this paper, by analyzing the pros and cons of possible copyright protection solutions, we propose to protect the copyright of NeRF models by replacing the original color representation in NeRF with a watermarked color representation. Then, a distortion-resistant rendering scheme is designed to guarantee robust message extraction in 2D renderings of NeRF. Our proposed method can directly protect the copyright of NeRF models while maintaining high rendering quality and bit accuracy when compared among optional solutions. Project page: https://luo-ziyuan.github.io/copyrnerf. Ziyuan Luo, Qing Guo 0005, Ka Chun Cheung, Simon See, Renjie Wan |
ICCV | 1 |
| 2022 | Traffic Sign Recognition from Digital Images by Using Deep Learning
Jiawei Xing, Ziyuan Luo, Minh Nguyen 0001, Wei Qi Yan 0001 |
PSIVT | 2 |
| 2021 | Perceptual Evaluation of Pre-processing for Video TranscodingabstractRecently, the pre-processed video transcoding has attracted wide attention and has been increasingly used in practical applications for improving the perceptual experience and saving transmission resources. However, very few works have been conducted to evaluate the performance of pre-processing methods. In this paper, we select the source (SRC) videos and various pre-processing approaches to construct the first Pre-processed and Transcoded Video Database (PTVD). Then, we conduct the subjective experiment, showing that compared with the video sent to the codec directly at the same bitrate, the appropriate pre-processing methods indeed improve the perceptual quality. Finally, existing image/video quality metrics are evaluated on our database. The results indicate that the performance of the existing image/video quality assessment (IQA/VQA) approaches remain to be improved. We will make our database publicly available soon. Shiyu Huang 0002, Ziyuan Luo, Jiahua Xu 0001, Wei Zhou 0021, Zhibo Chen 0001 |
VCIP | 2 |
| 2020 | A vector and geometry interpretation of basic probability assignment in Dempster-Shafer theoryabstractBecause of the superiority in dealing with uncertainty expression, Dempster-Shafer theory (D-S theory) is widely used in decision theory. In D-S theory, the basic probability assignment (BPA) is the basis and core. Recently, some researchers represent BPA on a N-dimension frame of discernment (FOD) as 2 N -dimension vector in Descartes coordinate system. This representation treats a BPA as a point in the 2 N -dimensional space. A new vector and geometry interpretation of BPA is proposed in this paper. The BPA on a N-dimension FOD is represented as N-dimension vector with parameters in this method. Then BPA is expressed as subset of N-dimension Cartesian space rather than a point. The proposed method is a new way to represent BPA with vector and geometry. The essence of this method is to convert BPA to probability distribution with parameters. The applications of this representation method in D-S theory have been studied. Based on this method, problems in D-S theory can be solved, which include the fusion of BPAs, the distance between BPAs, the correspondence between BPA and probability, and the entropy of BPAs. Ziyuan Luo, Yong Deng 0001 |
Int. J. Intell. Syst. | 1 |
| 2020 | A Matrix Method of Basic Belief Assignment's Negation in Dempster-Shafer TheoryabstractNegation is a new perspective to represent knowledge. The negation of probability distribution has been proposed, and it has a lot of interesting properties, which can reach a maximum entropy. Because of the defects of the classical probability theory in the expression of uncertainty, the basic belief assignment (BBA) in the Dempster-Shafer theory (D-S theory) are widely used in decision theory. Thus, negation provides a new perspective for D-S theory to measure fuzziness. In this paper, a new definition of negation of BBA is presented. In the proposed negation, BBAs are represented as vectors, and negation is realized by matrix operators. This method has a good interpretation of the matrix operators and has the merit of simplifying the problem. With several different definitions of entropy to determinate the uncertainty of BBA, the proposed negation of BBA can reach a maximum belief entropy when the entropies satisfy a certain property. Ziyuan Luo, Yong Deng 0001 |
IEEE Trans. Fuzzy Syst. | 1 |
| 2019 | No-Reference Light Field Image Quality Assessment Based on Micro-Lens ImageabstractLight field image quality assessment (LF-IQA) plays a significant role due to its guidance to Light Field (LF) contents acquisition, processing and application. The LF can be represented as 4-D signal, and its quality depends on both angular consistency and spatial quality. However, few existing LF-IQA methods concentrate on effects caused by angular inconsistency. Especially, no-reference methods lack effective utilization of 2D angular information. In this paper, we focus on measuring the 2-D angular consistency for LF-IQA. The Micro-Lens Image (MLI) refers to the angular domain of the LF image, which can simultaneously record the angular information in both horizontal and vertical directions. Since the MLI contains 2D angular information, we propose a No-Reference Light Field image Quality assessment model based on MLI (LF-QMLI). Specifically, we first utilize Global Entropy Distribution (GED) and Uniform Local Binary Pattern descriptor (ULBP) to extract features from the MLI, and then pool them together to measure angular consistency. In addition, the information entropy of SubAperture Image (SAI) is adopted to measure spatial quality. Extensive experimental results show that LF-QMLI achieves the state-of-the-art performance. Ziyuan Luo, Wei Zhou 0021, Likun Shi, Zhibo Chen 0001 |
PCS | 1 |
| 2019 | Quality Assessment of Stereoscopic 360-degree Images from Multi-viewportsabstractObjective quality assessment of stereoscopic panoramic images becomes a challenging problem owing to the rapid growth of 360-degree contents. Different from traditional 2D image quality assessment (IQA), more complex aspects are involved in 3D omnidirectional IQA, especially unlimited field of view (FoV) and extra depth perception, which brings difficulty to evaluate the quality of experience (QoE) of 3D omnidirectional images. In this paper, we propose a multi-viewport based full-reference stereo 360 IQA model. Due to the freely changeable viewports when browsing in the head-mounted display, our proposed approach processes the image inside FoV rather than the projected one such as equirectangular projection (ERP). In addition, since overall QoE depends on both image quality and depth perception, we utilize the features estimated by the difference map between left and right views which can reflect disparity. The depth perception features along with binocular image qualities are employed to further predict the overall QoE of 3D 360 images. The experimental results on our public Stereoscopic OmnidirectionaL Image quality assessment Database (SOLID) show that the proposed method achieves a significant improvement over some well-known IQA metrics and can accurately reflect the overall QoE of perceived images. Jiahua Xu 0001, Ziyuan Luo, Wei Zhou 0021, Zhibo Chen 0001 |
PCS | 2 |