Junhao Dong 0001

dblp:273/1553 · DBLP profile ↗
← Back
35ranked-venue papers
17as first author
35since 2021 · last 2027
0000-0002-6232-9157ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 27 · 14 first-author · 27 since 2021Graphics, computer vision, multimedia, augmented reality and games · 19 · 9 first-author · 19 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2027 Rethinking 3D point cloud adversarial attacks from models' inherent focus
Xiaowen Cai 0001, Shuqin Chen, Junhao Dong 0001, Keke Tang, Zhongliang Guo 0001, Daizong Liu
Expert Syst. Appl.4
2026 TouchFormer: A Robust Transformer-based Framework for Multimodal Material Perception
abstract
Traditional vision-based material perception methods often experience substantial performance degradation under visually impaired conditions, thereby motivating the shift toward non-visual multimodal material perception. Despite this, existing approaches frequently perform naive fusion of multimodal inputs, overlooking key challenges such as modality-specific noise, missing modalities common in real-world scenarios, and the dynamically varying importance of each modality depending on the task. These limitations lead to suboptimal performance across several benchmark tasks. In this paper, we propose a robust multimodal fusion framework, TouchFormer. Specifically, we employ a Modality-Adaptive Gating (MAG) mechanism and intra- and inter-modality attention mechanisms to adaptively integrate cross-modal features, enhancing model robustness. Additionally, we introduce a Cross-Instance Embedding Regularization(CER) strategy, which significantly improves classification accuracy in fine-grained subcategory material recognition tasks. Experimental results demonstrate that, compared to existing non-visual methods, the proposed TouchFormer framework achieves classification accuracy improvements of 2.48% and 6.83% on SSMC and USMC tasks, respectively. Furthermore, real-world robotic experiments validate TouchFormer's effectiveness in enabling robots to better perceive and interpret their environment, paving the way for its deployment in safety-critical applications such as emergency response and industrial automation.
Kailin Lyu, Long Xiao, Jianing Zeng, Junhao Dong 0001, Xuexin Liu, Zhuojun Zou, Haoyue Yang
AAAI4
2026 GaitProtector: Impersonation-Driven Gait De-Identification via Training-Free Diffusion Latent Optimization
Huiran Duan, Qian Zhou 0001, Zhongliang Guo 0001, Junhao Dong 0001, Guoying Zhao 0001, Yingli Tian
FG4
2026 Towards robust medical image segmentation: Spectro-spatial domain generalization with MRAM and DMIR
Junhao Dong 0001, Hansheng Zeng, Fuyan Zhang, Zeyu Dong, Chuanguang Yang, Yingli Tian
Comput. Vis. Image Underst.2
2026 Allies Teach Better Than Enemies: Inverse Adversaries for Robust Knowledge Distillation
abstract
Adversarially robust knowledge distillation aims to compress a large-scale robust teacher model into a lightweight student counterpart while preserving adversarial robustness and natural performance. Previous methods primarily focused on aligning knowledge (e.g., predictions) between teacher and student models to transfer robustness. However, potentially incorrect predictions from the teacher can misguide the student, negatively impacting robustness transfer. To circumvent this, we propose a novel adversarially robust knowledge distillation scheme that promotes alignment towards more benign predictions rather than incorrect ones by refining inputs into so-called "inverse adversarial examples" via simply reversing the sign of adversarial perturbation. Through a comprehensive investigation of the properties of inverse adversaries, we provide new theoretical insights showing how mimicking the behavior of the teacher model on inverse adversaries facilitates reliable robustness transfer built upon the implicit connection between robustness and the input gradient information. We thus design a gradient matching mechanism between teacher and student models utilizing inverse adversaries to facilitate robust knowledge alignment. Furthermore, inspired by our analysis of the correlation between robustness and adversarial transferability, we propose a weight-space disruption strategy that jointly interacts with both teacher and student models to find a shared direction for better robustness transfer. Empirical evaluations across various datasets demonstrate that our method achieves state-of-the-art robustness and natural performance. Notably, on ImageNet, our approach outperforms prior methods by approximately 3.8% in both clean and robust accuracy. Moreover, we show that incorporating auxiliary generated data into distillation further boosts robustness. Our method can also be generalized to multimodal architectures.
Junhao Dong 0001, Raoof Zare Moayedi, Yew-Soon Ong, Seyed-Mohsen Moosavi-Dezfooli
IEEE Trans. Pattern Anal. Mach. Intell.1
2026 SwiftDistill: Efficient robust knowledge transfer via dual-branch adversarial distillation and hardness-balanced augmentation
Junhao Dong 0001, Yuqing Wen, Zhengdao Li, Siheng Wang, Xinghua Qu, Yew-Soon Ong
Pattern Recognit.1
2026 Artwork protection against unauthorized neural style transfer and aesthetic color distance metric
Zhongliang Guo 0001, Yifei Qian, Shuai Zhao 0007, Junhao Dong 0001, Ognjen Arandjelovic, Lei Fang 0001, Chun Pong Lau 0001
Pattern Recognit.4
2026 Hard-Label Black-Box Attacks on 3D Point Clouds
abstract
With the maturity of depth sensors in various 3D safety-critical applications, 3D point cloud models have been shown to be vulnerable to adversarial attacks. Almost all existing 3D attackers simply follow the white-box or black-box setting to iteratively update coordinate perturbations based on back-propagated or estimated gradients. However, these methods are hard to deploy in real-world scenarios (no model details are provided) as they severely rely on parameters or output logits of victim models. To this end, we propose point cloud attacks from a more practical setting,i.e., hard-label black-box attack, in which attackers can only access the prediction label of 3D input. We introduce a novel 3D attack method based on a new spectrum-aware decision boundary algorithm to generate high-quality adversarial samples. In particular, we first construct a class-aware model decision boundary, by developing a learnable spectrum-fusion strategy to adaptively fuse point clouds of different classes in the spectral domain, aiming to craft their intermediate samples without distorting the original geometry. Then, we devise an iterative coordinate-spectrum optimization method with curvature-aware boundary search to move the intermediate sample along the decision boundary for generating adversarial point clouds with trivial perturbations. Experiments demonstrate that our attack competitively outperforms existing white/black-box attackers in terms of attack performance and adversary quality.
Daizong Liu, Yunbo Tao, Junhao Dong 0001, Keke Tang, Pan Zhou 0001, Wei Hu 0003, Yew-Soon Ong
IEEE Trans. Dependable Secur. Comput.3
2025 Mind the Trojan Horse: Image Prompt Adapter Enabling Scalable and Deceptive Jailbreaking
abstract
Recently, the Image Prompt Adapter (IP-Adapter) has been increasingly integrated into text-to-image diffusion models (T2I-DMs) to improve controllability. However, in this paper, we reveal that T2I-DMs equipped with the IP-Adapter (T2I-IP-DMs) enable a new jailbreak attack named the hijacking attack. We demonstrate that, by uploading imperceptible image-space adversarial examples (AEs), the adversary can hijack massive benign users to jailbreak an Image Generation Service (IGS) driven by T2I-IP-DMs and mislead the public to discredit the service provider. Worse still, the IP-Adapter’s dependency on open-source image encoders reduces the knowledge required to craft AEs. Extensive experiments verify the technical feasibility of the hijacking attack. In light of the revealed threat, we investigate several existing defenses and explore combining the IP-Adapter with adversarially trained models to overcome existing defenses’ limitations. Our code is available at https://github.com/fhdnskfbeuv/attackIPA.
Junxi Chen, Junhao Dong 0001, Xiaohua Xie
CVPR2
2025 Distinguish Then Exploit: Source-free Open Set Domain Adaptation via Weight Barcode Estimation and Sparse Label Assignment
abstract
Nowadays, domain adaptation techniques have been widely investigated for knowledge sharing from labeled source domain to unlabeled target domain. However, target domain may include some data samples that belong to unknown categories in real-world scenarios. Moreover, the target domain cannot access the source data samples due to privacy-preserving restrictions. In this paper, we focus on the source-free open set domain adaptation problem which includes two main challenges, i.e., how to distinguish known and unknown target samples and how to exploit useful source information to provide trustworthy pseudo labels for known target samples. Existing approaches that directly apply conventional domain alignment methods could lead to sample mismatch and misclassification in this scenario. To overcome these issues, we propose a Distinguish Then Exploit model (DTE) with two components, i.e., weight barcode estimation and sparse label assignment. Weight barcode estimation first calculates the marginal probability of target samples via partially unbalanced optimal transport, then quantize barcode results to distinguish unknown target samples. Sparse label assignment utilizes sparse sample-label matching via proximal term to fully exploit useful source information. Our empirically study on several datasets shows that DTE outperforms the state-of-the-art models on tackling the source-free open set domain adaptation problem.
Weiming Liu 0005, Jun Dan, Fan Wang 0020, Xinting Liao, Junhao Dong 0001, Hua Yu 0006, Shunjie Dong, Lianyong Qi
CVPR5
2025 BiLoRA: Almost-Orthogonal Parameter Spaces for Continual Learning
abstract
Continual learning requires models to learn tasks sequentially while maintaining a delicate balance between stability (retaining knowledge of previous tasks) and plasticity (adapting to new tasks). A key challenge is preventing interference between tasks which degrades performance when learning new tasks over previously learned tasks. Recent approaches leverage parameter-efficient fine-tuning (PEFT) which adapts pre-trained models by injecting a small number of learnable parameters. However, existing PEFT-based continual learning methods such as InfLoRA face fundamental limitations, i.e., they rely on complex optimization procedures to learn orthogonal task-specific spaces which is increasingly difficult as tasks accumulate. Thus, we propose a novel bilinear reformulation that fundamentally reimagines the task separation through fixed orthogonal bases. Our key insight is that by expanding the parameter space quadratically through two fixed bases, we can achieve "almost orthogonal" task subspaces probabilistically, eliminating the need for explicit interference elimination procedures. We provide theoretical guarantees that this approach reduces the probability of task interference from ${\mathcal{O}}\left({{{(k/d)}^2}}\right)$ to ${\mathcal{O}}\left({{{\left({k/{d^2}}\right)}^2}}\right)$, ensuring reliable task separation without complex optimization. Through extensive experiments on ImageNet-R, CIFAR-100, and DomainNet, we validate our theoretical bounds and demonstrate state-of-the-art performance with reduced parameter count. The code is available at: https://github.com/yifeiacc/BiLoRA.
Hao Zhu 0010, Junhao Dong 0001, Piotr Koniusz
CVPR3
2025 Robustifying Zero-Shot Vision Language Models by Subspaces Alignment
Junhao Dong 0001, Piotr Koniusz, Liaoyuan Feng, Hao Zhu 0010, Weiming Liu 0005, Xinghua Qu, Yew-Soon Ong
ICCV1
2025 Confound from all Sides, Distill with Resilience: Multi-Objective Adversarial Paths to Zero-Shot Robustness
Junhao Dong 0001, Jiao Liu 0006, Xinghua Qu, Yew-Soon Ong
ICCV1
2025 Improving Zero-Shot Adversarial Robustness in Vision-Language Models by Closed-form Alignment of Adversarial Path Simplices
abstract
Vision-Language Models (VLMs) such as CLIP excel at zero-shot classification due to large-scale pre-training but are vulnerable to adversarial examples. Adversarial fine-tuning robustifies zero-shot models by aligning prediction scores of individual adversaries with their clean counterparts, which typically overlooks intermediate adversarial samples along the adversarial trajectory crossing the decision boundary. Such intermediate adversaries and their vicinity produce informative representations capturing the decision boundary in detail. They can be improved by sampling adversarial candidates from simplices formed by joining two consecutive vertices on the adversarial trajectory and their clean counterpart. However, sampling simplices for adversaries is very costly. To train robust VLM, we overcome these limitations by Taylor expansion and formulating an upper-bound of alignment loss that depends on the Jacobian/Hessian obtained at clean samples. As regions between clean and intermediate adversarial samples capture a larger decision landscape, we robustify VLM by plausible adversaries from simplices by our closed-form formulation equivalent to infinite uniform sampling of the simplex. We obtain state-of-the-art robustness across 15 datasets and diverse vision-language tasks.
Junhao Dong 0001, Piotr Koniusz, Hao Zhu 0010, Weiming Liu 0005, Xinghua Qu, Yew-Soon Ong
ICML1
2025 Stabilizing Modality Gap & Lowering Gradient Norms Improve Zero-Shot Adversarial Robustness of VLMs
abstract
Contemporary Vision-Language Models (VLMs) such as CLIP offer an attractive zero-shot classification functionality facilitated by large-scale vision-language pre-training. However, they remain vulnerable to adversarial attacks, a critical security threat in realistic deployment. Adversarially robust fine-tuning provides generalizable robustness on new datasets while preserving natural performance by fine-tuning the pre-trained models. Fine-tuning robust CLIP typically relies on adversaries generated solely from the vision branch. However, this singular focus on the vision modality, coupled with static text prompts used as fixed category prototypes, limits the robustness achieved through dual-modality fine-tuning. We observe for CLIP fine-tuning that zero-shot adversarial robustness improves when we (i) stabilize the modality gap (a phenomenon where image and text features occupy different feature space regions) and (ii) lower/stabilize gradient norms. Both these steps enjoy further improvement of robustness if one fine-tunes with both visual and text adversaries. For both modalities, we leverage (i) the maximization of an effective rank of features and (ii) noise modulation of features. We show that maximizing the effective rank helps lower and stabilize the modality gap over adversaries with varying perturbation radii. The noise modulation of features, achieved by the so-called count sketching, lowers/stabilizes gradient norms. We outperform the state of the art on 15 datasets. We provide the first insights into the effects of modality gap & gradient norms in VLM fine-tuning.
Junhao Dong 0001, Piotr Koniusz, Xinghua Qu, Yew-Soon Ong
KDD (1)1
2025 Robust SuperAlignment: Weak-to-Strong Robustness Generalization for Vision-Language Models
abstract
Numerous well-established studies have demonstrated the superhuman capabilities of modern Vision-Language Models (VLMs) across a wide range of tasks. However, growing is the doubt about the continuing availability of reliable high-quality labeling (supervision) from human annotators, leading to stagnation of the model's performance. To address this challenge, ``superalignment'' employs the so-called weak-to-strong generalization paradigm, where the supervision from a weak model can provide generalizable knowledge for a strong model. While effective in aligning knowledge for clean samples between the strong and weak models, the standard weak-to-strong approach typically fails to capture adversarial robustness, exposing strong VLMs to adversarial attacks. This inability to transfer adversarial robustness is because adversarial samples are normally missing in the superalignment stage. To this end, we are the first to propose the weak-to-strong (adversarial) robustness generalization method to elicit zero-shot robustness in large-scale models by an unsupervised scheme, mitigating the unreliable information source for alignment from two perspectives: alignment re-weighting and source guidance refinement. We analyze settings under which robustness generalization is possible. Extensive experiments across various vision-language benchmarks validate the effectiveness of our method in numerous scenarios, demonstrating its plug-and-play applicability to large-scale VLMs.
Junhao Dong 0001, Xinghua Qu, Zejun Ma 0001, Piotr Koniusz, Yew-Soon Ong
NeurIPS1
2025 Machine Unlearning via Task Simplex Arithmetic
abstract
As foundation Vision-Language Models (VLMs) unlock fine-tuning on smaller datasets while leveraging large-scale pre-training data, machine unlearning becomes critical in addressing privacy concerns and regulatory compliance. Task vector, representing the difference between parameters of models fine-tuned with and without specific data, is a popular retraining-free unlearning strategy. However, we observe that task vectors exhibit substantial sensitivity to various fine-tuning configurations, resulting in unstable unlearning effectiveness that correlates negatively with the prediction-level variance. While aggregating multiple functions (e.g., VLM with classifier) whose parameters are represented by different task vectors reduces function variance and improves unlearning, the computational cost of obtaining numerous task vectors and aggregating functions is computationally high. Thus, in order to capture the space of task vectors induced by diverse fine-tuning strategies, we propose modeling it within the convex hull of $(Q-1)$-simplex whose vertices represent $Q$ task vectors. Although a function ensemble can be formed by sampling numerous task vectors from such a simplex, we derive a closed-form ensemble of an infinite number of functions whose parameters are uniformly sampled from the simplex, enabling efficient function-level task vector ensembling with enhanced unlearning performance. Extensive experiments and analyses across diverse datasets and scenarios demonstrate the efficacy of our method.
Junhao Dong 0001, Hao Zhu 0010, Xinghua Qu, Yew-Soon Ong, Piotr Koniusz
NeurIPS1
2025 Solving Discrete (Semi) Unbalanced Optimal Transport with Equivalent Transformation Mechanism and KKT-Multiplier Regularization
abstract
Semi-Unbalanced Optimal Transport (SemiUOT) shows great promise in matching two probability measures by relaxing one of the marginal constraints. Previous solvers often incorporate an entropy regularization term, which can result in inaccurate matching solutions. To address this issue, we focus on determining the marginal probability distribution of SemiUOT with KL divergence using the proposed Equivalent Transformation Mechanism (ETM) approach. Furthermore, we extend the ETM-based method into exploiting the marginal probability distribution of Unbalanced Optimal Transport (UOT) with KL divergence for validating its generalization. Once the marginal probabilities of UOT/SemiUOT are determined, they can be transformed into a classical Optimal Transport (OT) problem. Moreover, we propose a KKT-Multiplier regularization term combined with Multiplier Regularized Optimal Transport (MROT) to achieve more accurate matching results. We conduct several numerical experiments to demonstrate the effectiveness of our proposed methods in addressing UOT/SemiUOT problems.
Weiming Liu 0005, Xinting Liao, Jun Dan, Fan Wang 0020, Hua Yu 0006, Junhao Dong 0001, Shunjie Dong, Lianyong Qi, Yew-Soon Ong
NeurIPS6
2025 CrossSpectra: Exploiting Cross-Layer Smoothness for Parameter-Efficient Fine-Tuning
abstract
Parameter-efficient fine-tuning (PEFT) is essential for adapting large foundation models without excessive storage cost. However, current approaches such as LoRA treat each layer’s adaptation independently, overlooking correlations across layers. This independence causes the number of trainable parameters to grow linearly with model depth. We provide theoretical and empirical evidence that skip connections in transformers create smooth gradient propagation across layers. This smoothness leads to weight adaptations that concentrate most of their energy in low-frequency spectral components, especially along the layer dimension. Empirical analysis confirms this effect, showing that most of adaptation energy lies in low frequencies. Building on this insight, we propose CrossSpectra, which parameterizes all attention-weight adaptations $(Q, K, V)$ across layers as a single 3D tensor and represents them with sparse spectral coefficients ($\kappa_1, \kappa_2$). Using $\kappa_{1}$ non-zero coefficients within each layer’s frequency space and truncating to $\kappa_{2}$ frequencies across layers, CrossSpectra requires $\mathcal{O}(\kappa_{1}\kappa_{2})$ parameters instead of LoRA’s $\mathcal{O}(Lrd)$, where $L$ is the number of layers and $r$ the rank. Across natural-language and vision benchmarks, \methodname{} matches or surpasses baseline performance while using fewer parameters than LoRA, achieving only $0.36\%$ of LoRA’s parameter count when fine-tuning LLaMA-7B on instruction-following tasks. These results show that exploiting the \textbf{architectural smoothness of transformers} through spectral analysis yields major efficiency gains in PEFT.
Hao Zhu 0010, Junhao Dong 0001, Haoran Shi 0003, Ziqiao Meng, Piotr Koniusz, Han Yu 0001
NeurIPS3
2025 Imperceptible diffusion modification for facial privacy protection
Junhao Dong 0001, Jian-Huang Lai, Xiaohua Xie
Neurocomputing2
2025 Releasing Inequality Phenomenon in ℓ∞-Norm Adversarial Training via Input Gradient Distillation
abstract
Adversarial training (AT) is considered the most effective defense against adversarial attacks. However, a recent study revealed that ℓ∞-norm adversarial training ( ℓ∞-AT) will also induce unevenly distributed input gradients, which is called the inequality phenomenon. This phenomenon makes the ℓ∞ -norm adversarially trained model more vulnerable than the standard-trained model when high-attribution or randomly selected pixels are perturbed, enabling robust and practical closed-box attacks against ℓ∞ -adversarially trained models. In this paper, we propose a simple yet effective method called Input Gradient Distillation (IGD) to release the inequality phenomenon in ℓ∞-AT. IGD distills the standard-trained teacher model’s equal decision pattern into the ℓ∞-adversarially trained student model by aligning input gradients of the student model and the standard-trained model with the Cosine Similarity. Experiments show that IGD can mitigate the inequality phenomenon and its threats while preserving adversarial robustness. Compared to vanilla ℓ∞-AT, IGD reduces error rates against inductive noise, inductive occlusion, random noise, and noisy images in ImageNet-C by up to 60%, 16%, 50%, and 21%, respectively. Other than empirical experiments, we also conduct a theoretical analysis to explain why releasing the inequality phenomenon can improve such robustness and discuss why the severity of the inequality phenomenon varies according to the dataset’s image resolution.
Junxi Chen, Junhao Dong 0001, Xiaohua Xie, Jian-Huang Lai
IEEE Trans. Inf. Forensics Secur.2
2025 Generalizable and Discriminative Representations for Adversarially Robust Few-Shot Learning
abstract
Few-shot image classification (FSIC) is beneficial for a variety of real-world scenarios, aiming to construct a recognition system with limited training data. In this article, we extend the original FSIC task by incorporating defense against malicious adversarial examples. This can be an arduous challenge because numerous deep learning-based approaches remain susceptible to adversarial examples, even when trained with ample amounts of data. Previous studies on this problem have predominantly concentrated on the meta-learning framework, which involves sampling numerous few-shot tasks during the training stage. In contrast, we propose a straightforward but effective baseline via learning robust and discriminative representations without tedious meta-task sampling, which can further be generalized to unforeseen adversarial FSIC tasks. Specifically, we introduce an adversarial-aware (AA) mechanism that exploits feature-level distinctions between the legitimate and the adversarial domains to provide supplementary supervision. Moreover, we design a novel adversarial reweighting training strategy to ameliorate the imbalance among adversarial examples. To further enhance the adversarial robustness without compromising discriminative features, we propose the cyclic feature purifier during the postprocessing projection, which can reduce the interference of unforeseen adversarial examples. Furthermore, our method can obtain robust feature embeddings that maintain superior transferability, even when facing cross-domain adversarial examples. Extensive experiments and systematic analyses demonstrate that our method achieves state-of-the-art robustness as well as natural performance among adversarially robust FSIC algorithms on three standard benchmarks by a substantial margin.
Junhao Dong 0001, Yuan Wang 0030, Xiaohua Xie, Jian-Huang Lai, Yew-Soon Ong
IEEE Trans. Neural Networks Learn. Syst.1
2024 Robust Distillation via Untargeted and Targeted Intermediate Adversarial Samples
abstract
Adversarially robust knowledge distillation aims to com-press large-scale models into lightweight models while preserving adversarial robustness and natural performance on a given dataset. Existing methods typically align probability distributions of natural and adversarial samples between teacher and student models, but they overlook intermediate adversarial samples along the “adversarial path” formed by the multi-step gradient ascent of a sample towards the decision boundary. Such paths capture rich information about the decision boundary. In this paper, we propose a novel adversarially robust knowledge distillation approach by incorporating such adversarial paths into the alignment process. Recognizing the diverse impacts of intermediate adversarial samples (ranging from benign to noisy), we propose an adaptive weighting strategy to selectively em-phasize informative adversarial samples, thus ensuring efficient utilization of lightweight model capacity. Moreover, we propose a dual-branch mechanism exploiting two following insights: (i) complementary dynamics of adversar-ial paths obtained by targeted and untargeted adversarial learning, and (ii) inherent differences between the gradient ascent path from class$c_{i}$towards the nearest class bound-ary and the gradient descent path from a specific class$c_{j}$towards the decision region of$c_{i}(i\neq j)$. Comprehensive experiments demonstrate the effectiveness of our method on lightweight models under various settings.
Junhao Dong 0001, Piotr Koniusz, Junxi Chen, Z. Jane Wang 0001, Yew-Soon Ong
CVPR1
2024 Adversarially Robust Few-shot Learning via Parameter Co-distillation of Similarity and Class Concept Learners
abstract
Few-shot learning (FSL) facilitates a variety of computer vision tasks yet remains vulnerable to adversarial attacks. Existing adversarially robust FSL methods rely on either visual similarity learning or class concept learning. Our analysis reveals that these two learning paradigms are complementary, exhibiting distinct robustness due to their unique decision boundary types (concepts clustering by the visual similarity label vs. classification by the class labels). To bridge this gap, we propose a novel framework unifying adversarially robust similarity learning and class concept learning. Specifically, we distill parameters from both network branches into a “unified embedding model” during robust optimization and redistribute them to individual network branches periodically. To capture generalizable robustness across diverse branches, we initialize adversaries in each episode with cross-branch class-wise “global adversarial perturbations” instead of less informative random initialization. We also propose a branch robustness harmonization to modulate the optimization of similarity and class concept learners via their relative adversarial robustness. Extensive experiments demonstrate the state-of-the-art performance of our method in diverse few-shot scenarios.
Junhao Dong 0001, Piotr Koniusz, Junxi Chen, Xiaohua Xie, Yew-Soon Ong
CVPR1
2024 Artwork Protection Against Neural Style Transfer Using Locally Adaptive Adversarial Color Attack
abstract
Neural style transfer (NST) generates new images by combining the style of one image with the content of another. However, unauthorized NST can exploit artwork, raising concerns about artists’ rights and motivating the development of proactive protection methods. We propose Locally Adaptive Adversarial Color Attack (LAACA), empowering artists to protect their artwork from unauthorized style transfer by processing before public release. By delving into the intricacies of human visual perception and the role of different frequency components, our method strategically introduces frequency-adaptive perturbations in the image. These perturbations significantly degrade the generation quality of NST while maintaining an acceptable level of visual change in the original image, ensuring that potential infringers are discouraged from using the protected artworks, because of its bad NST generation quality. Additionally, existing metrics often overlook the importance of color fidelity in evaluating color-mattered tasks, such as the quality of NST-generated images, which is crucial in the context of artistic works. To comprehensively assess the color-mattered tasks, we propose the Aesthetic Color Distance Metric (ACDM), designed to quantify the color difference of images pre- and post-manipulations. Experimental results confirm that attacking NST using LAACA results in visually inferior style transfer, and the ACDM can efficiently measure color-mattered tasks. By providing artists with a tool to safeguard their intellectual property, our work relieves the socio-technical challenges posed by the misuse of NST in the art community.
Zhongliang Guo 0001, Junhao Dong 0001, Yifei Qian, Ziheng Guo, Ognjen Arandjelovic, Lei Fang 0001
ECAI2
2024 Adversarially Robust Distillation by Reducing the Student-Teacher Variance Gap
Junhao Dong 0001, Piotr Koniusz, Junxi Chen, Yew-Soon Ong
ECCV (4)1
2024 FineCLIPER: Multi-modal Fine-grained CLIP for Dynamic Facial Expression Recognition with AdaptERs
Haojian Huang, Junhao Dong 0001, Mingzhe Zheng, Dian Shao
ACM Multimedia3
2023 The Enemy of My Enemy is My Friend: Exploring Inverse Adversaries for Improving Adversarial Training
abstract
Although current deep learning techniques have yielded superior performance on various computer vision tasks, yet they are still vulnerable to adversarial examples. Adversarial training and its variants have been shown to be the most effective approaches to defend against adversarial examples. A particular class of these methods regularize the difference between output probabilities for an adversarial and its corresponding natural example. However, it may have a negative impact if a natural example is misclassified. To circumvent this issue, we propose a novel adversarial training scheme that encourages the model to produce similar output probabilities for an adversarial example and its “inverse adversarial” counterpart. Particularly, the counterpart is generated by maximizing the likelihood in the neighborhood of the natural example. Extensive experiments on various vision datasets and architectures demonstrate that our training method achieves state-of-the-art robustness as well as natural accuracy among robust models. Furthermore, using a universal version of inverse adversarial examples, we improve the performance of single-step adversarial training techniques at a low computational cost.
Junhao Dong 0001, Seyed-Mohsen Moosavi-Dezfooli, Jian-Huang Lai, Xiaohua Xie
CVPR1
2023 Modality Balancing Mechanism for RGB-Infrared Object Detection in Aerial Image
Weibo Cai, Junhao Dong 0001, Jian-Huang Lai, Xiaohua Xie
PRCV (12)3
2023 Feature Disentanglement and Adaptive Fusion for Improving Multi-modal Tracking
Weibo Cai, Junhao Dong 0001, Jian-Huang Lai, Xiaohua Xie
PRCV (12)3
2023 Restricted Black-Box Adversarial Attack Against DeepFake Face Swapping
abstract
DeepFake face swapping presents a significant threat to online security and social media, which can replace the source face in an arbitrary photo/video with the target face of an entirely different person. In order to prevent this fraud, some researchers have begun to study the adversarial methods against DeepFake or face manipulation. However, existing works mainly focus on the white-box setting or the black-box setting driven by abundant queries, which severely limits the practical application of these methods. To tackle this problem, we introduce a practical adversarial attack that does not require any queries to the facial image forgery model. Our method is built on a substitute model based on face reconstruction and then transfers adversarial examples from the substitute model directly to inaccessible black-box DeepFake models. Specially, we propose the Transferable Cycle Adversary Generative Adversarial Network (TCA-GAN) to construct the adversarial perturbation for disrupting unknown DeepFake systems. We also present a novel post-regularization module for enhancing the transferability of generated adversarial examples. To comprehensively measure the effectiveness of our approaches, we construct a challenging baseline of DeepFake adversarial attacks for future development. Extensive experiments impressively show that the proposed adversarial attack method makes the visual quality of DeepFake face images plummet so that they are easier to be detected by humans and algorithms. Moreover, we demonstrate that the proposed algorithm can be generalized to offer face image protection against various face translation methods.
Junhao Dong 0001, Yuan Wang 0030, Jian-Huang Lai, Xiaohua Xie
IEEE Trans. Inf. Forensics Secur.1
2023 Toward Intrinsic Adversarial Robustness Through Probabilistic Training
abstract
Modern deep neural networks have made numerous breakthroughs in real-world applications, yet they remain vulnerable to some imperceptible adversarial perturbations. These tailored perturbations can severely disrupt the inference of current deep learning-based methods and may induce potential security hazards to artificial intelligence applications. So far, adversarial training methods have achieved excellent robustness against various adversarial attacks by involving adversarial examples during the training stage. However, existing methods primarily rely on optimizing injective adversarial examples correspondingly generated from natural examples, ignoring potential adversaries in the adversarial domain. This optimization bias can induce the overfitting of the suboptimal decision boundary, which heavily jeopardizes adversarial robustness. To address this issue, we propose Adversarial Probabilistic Training (APT) to bridge the distribution gap between the natural and adversarial examples via modeling the latent adversarial distribution. Instead of tedious and costly adversary sampling to form the probabilistic domain, we estimate the adversarial distribution parameters in the feature level for efficiency. Moreover, we decouple the distribution alignment based on the adversarial probability model and the original adversarial example. We then devise a novel reweighting mechanism for the distribution alignment by considering the adversarial strength and the domain uncertainty. Extensive experiments demonstrate the superiority of our adversarial probabilistic training method against various types of adversarial attacks in different datasets and scenarios.
Junhao Dong 0001, Lingxiao Yang, Yuan Wang 0030, Xiaohua Xie, Jian-Huang Lai
IEEE Trans. Image Process.1
2022 Improving Adversarially Robust Few-shot Image Classification with Generalizable Representations
abstract
Few-Shot Image Classification (FSIC) aims to recognize novel image classes with limited data, which is significant in practice. In this paper, we consider the FSIC problem in the case of adversarial examples. This is an extremely challenging issue because current deep learning methods are still vulnerable when handling adversarial examples, even with massive labeled training samples. For this problem, existing works focus on training a network in the meta-learning fashion that depends on numerous sampled few-shot tasks. In comparison, we propose a simple but effective baseline through directly learning generalizable representations without tedious task sampling, which is robust to unforeseen adversarial FSIC tasks. Specifically, we introduce an adversarial-aware mechanism to establish auxiliary supervision via feature-level differences between legitimate and adversarial examples. Furthermore, we design a novel adversarial-reweighted training manner to alleviate the imbalance among adversarial examples. The feature purifier is also employed as post-processing for adversarial features. Moreover, our method can obtain generalizable representations to remain superior transferability, even facing cross-domain adversarial examples. Extensive experiments show that our method can significantly outperform state-of-the-art adversarially robust FSIC methods on two standard benchmarks.
Junhao Dong 0001, Yuan Wang 0030, Jian-Huang Lai, Xiaohua Xie
CVPR1
2022 Learning Bi-directional Feature Propagation with Latent Layout Modeling for Group Re-identification
abstract
Group re-identification (G-ReID) aims to identify the same group of persons across the disjoint cameras. The key challenge of G-ReID is the robust feature extraction against the potential group layout and membership varitions. However, previous works focus more on the appearance modeling and less on the importance of group layout. In this paper, we propose a bi-directional feature propagation framework, which propagates information between group layout and member appearance. In addition, we propose the spatial generation framework, which analyses the group image and generates new images with different group layouts to simulate various layouts in the real world. Moreover, we propose a network that learns latent layout representations and propagates the layout representations with the member appearance representations. The proposed network achieves SOTA performance on two widely used G-ReID datasets, i.e., 87.9% mAP and 89.2% Rank-1 on CSG, 92.7% mAP and 90.1% Rank-1 on RoadGroup.
Yuan Wang 0030, Jian-Huang Lai, Xiaohua Xie, Junhao Dong 0001
ICPR5
2021 Visually Maintained Image Disturbance Against Deepfake Face Swapping
abstract
As a deep learning-based application, DeepFake can generate malicious images or videos through replacing the face of a source image with the target face, which poses a significant threat to social media. In this paper, we propose a scheme to prevent such tampering by exploring adversarial examples against DeepFake. Specifically, adversarial examples are produced by adding tailored distortion to source images. The added distortion is imperceptible to human vision but can mislead the generation of face-swapped images effectively. We present three novel adversarial attacks against DeepFake autoencoders from perspectives of adversarial transferability and latent representation. Our first method synthesizes universal perturbation, which is image-agnostic. By contrast, the latter two methods directly perform the preciser perturbation specific to a source image. Extensive experiments demonstrate the effectiveness of our adversarial examples against DeepFake in terms of both reference and non-reference image quality assessment.
Junhao Dong 0001, Xiaohua Xie
ICME1