EDBT 2026 Demo / reviewers in the wild / expert
Chengze Jiang
dblp:264/2180
· DBLP profile ↗
14ranked-venue papers
6as first author
13since 2021 · last 2026
0000-0002-1681-8128ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 8 · 2 first-author · 8 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 2 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Diversifying Counterattacks: Orthogonal Exploration for Robust CLlP InferenceabstractVision-language pre-training models (VLPs) demonstrate strong multimodal understanding and zero-shot generalization, yet remain vulnerable to adversarial examples, raising concerns about their reliability. Recent work, Test-Time Counterattack (TTC), improves robustness by generating perturbations that maximize the embedding deviation of adversarial inputs using PGD, pushing them away from their adversarial representations. However, due to the fundamental difference in optimization objectives between adversarial attacks and counterattacks, generating counterattacks solely based on gradients with respect to the adversarial input confines the search to a narrow space. As a result, the counterattacks could overfit limited adversarial patterns and lack the diversity to fully neutralize a broad range of perturbations. In this work, we argue that enhancing the diversity and coverage of counterattacks is crucial to improving adversarial robustness in test-time defense. Accordingly, we propose Directional Orthogonal Counterattack (DOC), which augments counterattack optimization by incorporating orthogonal gradient directions and momentum-based updates. This design expands the exploration of the counterattack space and increases the diversity of perturbations, which facilitates the discovery of more generalizable counterattacks and ultimately improves the ability to neutralize adversarial perturbations. Meanwhile, we present a directional sensitivity score based on averaged cosine similarity to boost DOC by improving example discrimination and adaptively modulating the counterattack strength. Extensive experiments on 16 datasets demonstrate that DOC improves adversarial robustness under various attacks while maintaining competitive clean accuracy. Chengze Jiang, Minjing Dong, Xinli Shi, Jie Gui |
AAAI | 1 |
| 2026 | Discrete zeroing neural dynamic with noise tolerance for image deblurring
Cong Lin 0004, Fenghao Zhuang, Chengze Jiang, Yuanyuan Wu 0002 |
Expert Syst. Appl. | 4 |
| 2026 | Discrete-time projection and asymmetric superellipse zeroing neural network for constraint-satisfying AUV trajectory tracking
Junmei Chen, Chengze Jiang, Zhiyuan Song, Chuncheng Chen, Jian Yan 0016, Xiuchun Xiao |
Neurocomputing | 2 |
| 2026 | Gradient Perturbation Guidance for Boosting Sparse Adversarial Attack TransferabilityabstractSparse adversarial attacks perturb only a few pixels to achieve an attack, making them harder to detect and more dangerous. Recently, generative sparse attacks decouple the generation of sparse adversarial examples (AEs) into dense perturbations and sparse masks. By modeling the data distribution from clean examples to sparse AEs, generative sparse attacks mitigate the poor transferability that arises from over-reliance on gradients. These methods put effort into deriving optimal sparse masks on the generated perturbation. However, the quality of perturbation generation has always been overlooked, which limits the transferability of sparse AEs. To explore the influence of perturbation quality, we conduct empirical analyses of sparse gradient-based perturbations. The results show that directly applying sparsity to gradient-based perturbations disrupts their holistic adversarial information, leading to degraded attack performance. Therefore, it is critical to extract key adversarial knowledge from gradient-based perturbations while preserving their overall integrity to guide sparse adversarial attacks. Motivated by this observation, we propose to extract essential adversarial information from gradient-based AEs to guide the generator to produce higher-quality dense perturbations and stronger transferable sparse AEs. Specifically, we introduce the Gradient Perturbation Guidance (GPG) sparse adversarial attack, which integrates gradient adversarial feature guidance and gradient perturbation guidance regularization. The former guides the generator to capture gradient-based adversarial features during encoding, while the latter refines adversarial knowledge from gradient-based perturbations during decoding. Extensive experiments on ImageNet-1K show that our GPG significantly boosts transferability compared to state-of-the-art methods under consistent sparsity constraints. Our code is available at Github. Chengze Jiang, Minjing Dong, Jie Gui, Lu Dong 0002, Yuan Yan Tang, James T. Kwok |
IEEE Trans. Circuits Syst. Video Technol. | 1 |
| 2026 | Improving Fast Adversarial Training Paradigm: An Example Taxonomy PerspectiveabstractWhile adversarial training is an effective defense method against adversarial attacks, it notably increases the training cost. To this end, fast adversarial training (FAT) is presented for efficient training and has become a hot research topic. However, FAT suffers from catastrophic overfitting, which leads to a performance drop compared with multi-step adversarial training. However, the cause of catastrophic overfitting remains unclear and lacks exploration. In this paper, we present an example taxonomy in FAT, which suggests that catastrophic overfitting is correlated with the imbalance between the inner and outer optimization in FAT. Furthermore, we investigated the impact of varying degrees of training loss, revealing a correlation between training loss and catastrophic overfitting. Based on these observations, we redesign the loss function in FAT with the proposed dynamic label relaxation to concentrate the loss range and reduce the impact of misclassified examples. Meanwhile, we introduce batch momentum initialization to enhance diversity and prevent catastrophic overfitting in an efficient manner. Furthermore, we also propose Catastrophic Overfitting aware Loss Adaptation (COLA), which employs a separate training strategy for examples based on their loss degree. Our proposed method, named example taxonomy aware FAT (ETA), establishes an improved paradigm for FAT. Experiment results demonstrate that our ETA achieves higher robust accuracy than all other evaluated methods. Comprehensive experiments on four standard datasets demonstrate the competitiveness of our method. The source code and model checkpoints will be publicly released. Jie Gui, Chengze Jiang, Minjing Dong, Kun Tong, Xinli Shi, Yuan Yan Tang, Dacheng Tao |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2026 | Rethinking Frequency Modeling: Tail-Aware Dynamic Adversarial Training for Long-Tailed RobustnessabstractAdversarial training (AT) is among the most effective defenses against adversarial attacks on deep neural networks. However, in real-world scenarios where data often follow long-tailed distributions, conventional AT methods struggle to handle such imbalance, resulting in severe robustness disparities across classes and limited overall robustness. Although recent efforts attempt to improve robustness through class frequency-aware weighting or distribution adjustments, our empirical analysis reveals that class frequency alone is an insufficient indicator of adversarial vulnerability, as robust accuracy does not correlate with the number of examples per class. Furthermore, AT under long-tailed distributions exhibits optimization instability, particularly for tail classes with limited data. To address these challenges, we present Tail-Aware Dynamic Adversarial Training (TAD-AT), which integrates three complementary components targeting the training loss, attack strategy, and weight average. TAD-AT captures data imbalance and performance disparity, improving adversarial robustness under long-tailed distributions. First, our training loss incorporates frequency- and accuracy-aware regularization to emphasize learning for vulnerable classes. Second, our attack adjusts perturbations based on class-wise vulnerability, encouraging robust feature learning around vulnerable regions, thereby mitigating robustness overfitting and improving clean accuracy. Third, our weight average improves robust generalization and training stability by adaptively controlling the decay rate across classes. Experiments on long-tailed benchmarks demonstrate that our TAD-AT significantly improves adversarial robustness, offering a systematic and practical solution to robustness challenges under long-tail distributions. Our code is publicly available on https://github.com/bookman233/TADAT. Chengze Jiang, Minjing Dong, Jie Gui, Ju Jia, Yuan Yan Tang, James T. Kwok |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | Adaptive gradient-aware neural dynamics: Towards fast and accurate solutions for dynamic convex optimization
Chengze Jiang, Aiping Ye, Huiting He, Xiuchun Xiao, Cong Lin 0004 |
Eng. Appl. Artif. Intell. | 1 |
| 2025 | Improving Fast Adversarial Training via Self-Knowledge GuidanceabstractAdversarial training has achieved remarkable advancements in defending against adversarial attacks. Among them, fast adversarial training (FAT) is gaining attention for its ability to achieve competitive robustness with fewer computing resources. Existing FAT methods typically employ a uniform strategy that optimizes all training data equally without considering the influence of different examples, which leads to an imbalanced optimization. However, this imbalance remains unexplored in the field of FAT. In this paper, we conduct a comprehensive study of the imbalance issue in FAT and observe an obvious class disparity regarding their performances. This disparity could be embodied from a perspective of alignment between clean and robust accuracy. Based on the analysis, we mainly attribute the observed misalignment and disparity to the imbalanced optimization in FAT, which motivates us to optimize different training data adaptively to enhance robustness. Specifically, we take disparity and misalignment into consideration. First, we introduce self-knowledge guided regularization, which assigns differentiated regularization weights to each class based on its training state, alleviating class disparity. Additionally, we propose self-knowledge guided label relaxation, which adjusts label relaxation according to the training accuracy, alleviating the misalignment and improving robustness. By combining these methods, we formulate the Self-Knowledge Guided FAT (SKG-FAT), leveraging naturally generated knowledge during training to enhance the adversarial robustness without compromising training efficiency. Extensive experiments on four standard datasets demonstrate that the SKG-FAT improves the robustness and preserves competitive clean accuracy, outperforming the state-of-the-art methods. Code and checkpoints are available at SFG-FAT Code Implementation. Chengze Jiang, Minjing Dong, Jie Gui, Xinli Shi, Yuan Cao 0005, Yuan Yan Tang, James T. Kwok |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Taxonomy Driven Fast Adversarial TrainingabstractAdversarial training (AT) is an effective defense method against gradient-based attacks to enhance the robustness of neural networks. Among them, single-step AT has emerged as a hotspot topic due to its simplicity and efficiency, requiring only one gradient propagation in generating adversarial examples. Nonetheless, the problem of catastrophic overfitting (CO) that causes training collapse remains poorly understood, and there exists a gap between the robust accuracy achieved through single- and multi-step AT. In this paper, we present a surprising finding that the taxonomy of adversarial examples reveals the truth of CO. Based on this conclusion, we propose taxonomy driven fast adversarial training (TDAT) which jointly optimizes learning objective, loss function, and initialization method, thereby can be regarded as a new paradigm of single-step AT. Compared with other fast AT methods, TDAT can boost the robustness of neural networks, alleviate the influence of misclassified examples, and prevent CO during the training process while requiring almost no additional computational and memory resources. Our method achieves robust accuracy improvement of 1.59%, 1.62%, 0.71%, and 1.26% on CIFAR-10, CIFAR-100, Tiny ImageNet, and ImageNet-100 datasets, when against projected gradient descent PGD10 attack with perturbation budget 8/255. Furthermore, our proposed method also achieves state-of-the-art robust accuracy against other attacks. Code is available at https://github.com/bookman233/TDAT. Kun Tong, Chengze Jiang, Jie Gui, Yuan Cao 0005 |
AAAI | 2 |
| 2023 | A dynamic matrix equation solution method based on NCBC-ZNN and its application on hyperspectral image multi-target detection
Huiting He, Chengze Jiang, Xiuchun Xiao, Guan-Cheng Wang 0002 |
Appl. Intell. | 2 |
| 2023 | Nonlinear RNN with noise-immune: A robust and learning-free method for hyperspectral image target detection
Xiuchun Xiao, Chengze Jiang, Long Jin 0001, Haoen Huang 0001, Guan-Cheng Wang 0002 |
Expert Syst. Appl. | 2 |
| 2023 | Modified Newton Integration Neural Algorithm for Solving Time-Varying Yang-Baxter-Like Matrix Equation
Haoen Huang 0001, Zifan Huang, Chaomin Wu, Chengze Jiang, Dongyang Fu, Cong Lin 0004 |
Neural Process. Lett. | 4 |
| 2021 | Nonconvex and Bound Constraint Zeroing Neural Network for Solving Time-Varying Complex-Valued Quadratic Programming ProblemabstractMany methods are known to solve the problem of real-valued and static quadratic programming (QP) effectively. However, few of them are still useful to solve the time-varying QP problem in the complex domain. In this study, a nonconvex and bound constraint zeroing neural network (NCZNN) model is designed and theorized to solve the time-varying complex-valued QP with linear equation constraint. Besides, we construct several new types of nonconvex and bound constraint complex-valued activation functions by extending real-valued activation functions to the complex domain. Subsequently, corresponding simulation experiments are conducted, and the simulation results verify the effectiveness and robustness of the proposed NCZNN model. Moreover, the model proposed in this article is further applied to solve the issue of small target detection in remote sensing images, which is modeled to QP problem with linear equation constraint by a serial of conversions based on constrained energy minimization algorithm. Chengze Jiang, Xiuchun Xiao, Dazhao Liu, Haoen Huang 0001, Huiyan Lu |
IEEE Trans. Ind. Informatics | 1 |
| 2020 | A parallel computing method based on zeroing neural networks for time-varying complex-valued matrix Moore-Penrose inversion
Xiuchun Xiao, Chengze Jiang, Huiyan Lu, Long Jin 0001, Dazhao Liu, Haoen Huang 0001, Yi Pan 0001 |
Inf. Sci. | 2 |