EDBT 2026 Demo / reviewers in the wild / expert
Renyang Liu 0001
dblp:295/6245
· DBLP profile ↗
25ranked-venue papers
11as first author
25since 2021 · last 2026
0000-0002-7121-1257ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 9 · 2 first-author · 9 since 2021Security and privacy · 8 · 5 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 4 first-author · 6 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Computer networks · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | FACTGUARD: Event-Centric and Commonsense-Guided Fake News DetectionabstractFake news detection methods based on writing style have achieved remarkable progress. However, as adversaries increasingly imitate the style of authentic news, the effectiveness of such approaches is gradually diminishing. Recent research has explored incorporating large language models (LLMs) to enhance fake news detection. Yet, despite their transformative potential, LLMs remain an untapped goldmine for fake news detection, with their real-world adoption hampered by shallow functionality exploration, ambiguous usability, and prohibitive inference costs. In this paper, we propose a novel fake news detection framework, dubbed FACTGUARD, that leverages LLMs to extract event-centric content, thereby reducing the impact of writing style on detection performance. Furthermore, our approach introduces a dynamic usability mechanism that identifies contradictions and ambiguous cases in factual reasoning, adaptively incorporating LLM advice to improve decision reliability. To ensure efficiency and practical deployment, we employ knowledge distillation to derive FACTGUARD-D, enabling the framework to operate effectively in cold-start and resource-constrained scenarios. Comprehensive experiments on two benchmark datasets demonstrate that our approach consistently outperforms existing methods in both robustness and accuracy, effectively addressing the challenges of style sensitivity and LLM usability in fake news detection. Jing He 0012, Yuanhui Xiao, Shaowen Yao 0001, Renyang Liu 0001 |
AAAI | 6 |
| 2026 | Correct When Paired, Wrong When Split: Decoupling and Editing Modality-Specific Neurons in MLLMsabstractTingchao Fu, Wenkai Wang, Fanxiao Li, Huadong Zhang, Jinhong Zhang, Dayang Li, Yunyun Dong, Renyang Liu, Wei Zhou. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Tingchao Fu, Fanxiao Li, Dayang Li, Yunyun Dong, Renyang Liu 0001, Wei Zhou 0011 |
ACL (1) | 8 |
| 2026 | PWAVEP: Purifying Imperceptible Adversarial Perturbations in 3D Point Clouds via Spectral Graph WaveletsabstractRecent progress in adversarial attacks on 3D point clouds, particularly in achieving spatial imperceptibility and high attack performance, presents significant challenges for defenders. Current defensive approaches remain cumbersome, often requiring invasive model modifications, expensive training procedures or auxiliary data access. To address these threats, in this paper, we propose a plug-and-play and non-invasive defense mechanism in the spectral domain, grounded in a theoretical and empirical analysis of the relationship between imperceptible perturbations and high-frequency spectral components. Building upon these insights, we introduce a novel purification framework, termed PWAVEP, which begins by computing a spectral graph wavelet domain saliency score and local sparsity score for each point. Guided by these values, PWAVEP adopts a hierarchical strategy, it eliminates the most salient points, which are identified as hardly recoverable adversarial outliers. Simultaneously, it applies a spectral filtering process to a broader set of moderately salient points. This process leverages a graph wavelet transform to attenuate high-frequency coefficients associated with the targeted points, thereby effectively suppressing adversarial noise. Extensive evaluations demonstrate that the proposed PWAVEP achieves superior accuracy and robustness compared to existing approaches, advancing the state-of-the-art in 3D point cloud purification. Code and datasets are available at https://github.com/a772316182/pwavep Haoran Li 0023, Renyang Liu 0001, Hongjia Liu, Chen Wang 0042, Long Yin, Jian Xu 0004 |
WWW | 2 |
| 2026 | Memory poisoning attacks on retrieval-augmented Large Language Model agents via deceptive semantic reasoning
Fanxiao Li, Yunyun Dong, Wei Zhou 0011, Renyang Liu 0001 |
Eng. Appl. Artif. Intell. | 5 |
| 2026 | Post-Quantum Secure Semantic Communication With Discrete Latent RepresentationsabstractSemantic communication (SemCom) has recently gained attention for its ability to achieve high transmission efficiency with minimal data distortion under limited communication resources. However, the strong correlation between source data and channel input leaves SemCom schemes vulnerable to eavesdropping. Additionally, advances in quantum computing threaten traditional cryptographic methods such as RSA due to Shor’s algorithm. To address these risks, a secure SemCom framework with post-quantum protection is essential. This paper presents a post-quantum secure semantic communication (PQSC) framework by integrating learning with errors (LWE) encryption (widely regarded as quantum-resistant) into a VQ-VAE-based SemCom system. The proposed PQSC framework not only resists quantum attacks but also defends against chosen-plaintext attacks. Experiments show that PQSC consistently outperforms baseline methods across various datasets, channel conditions, and SNR levels. To simulate practical wireless environments, we implement channel coding and modulation using Nvidia Sionna, a GPU-accelerated library for physical layer research. We further examine the trade-off between compression efficiency and computational cost. A downlink use case is modeled to analyze recovery quality, energy consumption, and latency. Our mathematical analysis offers insights into system design and parameter selection for real-world deployment. Peiyuan Si, Liangxin Qian, Renyang Liu 0001, Jun Zhao 0007, Kwok-Yan Lam |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Rethinking Machine Unlearning in Image Generation ModelsabstractWith the surge and widespread application of image generation models, data privacy and content safety have become major concerns and attracted great attention from users, service providers, and policymakers. Machine unlearning (MU) is recognized as a cost effective and promising means to address these challenges. Despite some advancements, image generation model unlearning (IGMU) still faces remarkable gaps in practice, e.g., unclear task discrimination and unlearning guidelines, lack of an effective evaluation framework, and unreliable evaluation metrics. These can hinder the understanding of unlearning mechanisms and the design of practical unlearning algorithms. We perform exhaustive assessments over existing state-of-the-art unlearning algorithms and evaluation standards, and discover several critical flaws and challenges in IGMU tasks. Driven by these limitations, we make several core contributions, to facilitate the comprehensive understanding, standardized categorization, and reliable evaluation of IGMU. Specifically, (1) We design CatIGMU, a novel hierarchical task categorization framework. It provides detailed implementation guidance for IGMU, assisting in the design of unlearning algorithms and the construction of testbeds. (2) We introduce EvalIGMU, a comprehensive evaluation framework. It includes reliable quantitative metrics across five critical aspects. (3) We construct DataIGM, a high-quality unlearning dataset, which can be used for extensive evaluations of IGMU, training content detectors for judgment, and benchmarking the state-of-the-art unlearning algorithms. With EvalIGMU and DataIGM, we discover that most existing IGMU algorithms cannot handle the unlearning well across different evaluation dimensions, especially for preservation and robustness. Data, source code, and models are available at https://github.com/ryliu68/IGMU. Renyang Liu 0001, Wenjie Feng 0001, Tianwei Zhang 0004, Wei Zhou 0011, Xueqi Cheng 0001, See-Kiong Ng |
CCS | 1 |
| 2025 | D-Judge: How Far Are We? Assessing the Discrepancies Between AI-synthesized and Natural Images through Multimodal GuidanceabstractIn the rapidly evolving field of Artificial Intelligence Generated Content (AIGC), a central challenge is distinguishing AI-synthesized images from natural images. Despite the impressive capabilities of advanced AI generative models in producing visually compelling content, significant discrepancies remain when compared to natural images. To systematically investigate and quantify these differences, we construct a large-scale multimodal dataset named DANI, comprising 5,000 natural images and over 440,000 AI-generated image (AIGI) samples produced by nine representative models using both unimodal and multimodal prompts, including Text-to-Image (T2I), Text-and-Image-to-Image (I2I), and Text and Image-to-Image (TI2I). We then introduce D-Judge, a benchmark designed to answer the critical question: how far are AI-generated images from truly realistic images? Our fine-grained evaluation framework assesses DANI across five key dimensions: naive visual quality, semantic alignment, aesthetic appeal, downstream task applicability, and coordinated human validation. Extensive experiments reveal substantial discrepancies across these dimensions, highlighting the importance of aligning quantitative metrics with human judgment to achieve a comprehensive understanding of AI-generated image quality. The code and dataset are publicly available at: https://github.com/ryliu68/DJudge, and https://huggingface.co/datasets/Renyang/DANI. Renyang Liu 0001, Ziyu Lyu, Wei Zhou 0011, See-Kiong Ng |
ACM Multimedia | 1 |
| 2025 | IPAttack: imperceptible adversarial patch to attack object detectors
Yongming Wen, Peiyuan Si, Wei Zhou 0011, Zongheng Zhao, Chao Yi, Renyang Liu 0001 |
Appl. Intell. | 6 |
| 2025 | Pseudo-label attention-based multiple instance learning for whole slide image classification
Jing He 0012, Ping Wang 0044, Dan Tang 0001, Shaowen Yao 0001, Renyang Liu 0001 |
Eng. Appl. Artif. Intell. | 6 |
| 2025 | Micro_NesT: multi-scale attention enhanced micro-expression recognition framework
Jing He 0012, Yuanhui Xiao, Renyang Liu 0001 |
Expert Syst. Appl. | 6 |
| 2025 | STBA: Towards Evaluating the Robustness of DNNs for Query-Limited Black-Box ScenarioabstractExtensive studies have revealed that deep neural networks (DNNs) are vulnerable to adversarial attacks, especially black-box ones, which can heavily threaten the DNNs deployed in the real world. Many attack techniques have been proposed to explore the vulnerability of DNNs and further help to improve their robustness. Despite the significant progress made recently, existing black-box attack methods still suffer from unsatisfactory performance due to the vast number of queries needed to optimize desired perturbations. Besides, the other critical challenge is that adversarial examples built in a noise-adding manner are abnormal and struggle to successfully attack robust models, whose robustness is enhanced by adversarial training against small perturbations. There is no doubt that these two issues mentioned above will significantly increase the risk of exposure and result in a failure to dig deeply into the vulnerability of DNNs. Hence, it is necessary to evaluate DNNs' fragility sufficiently under query-limited settings in a non-additional way. In this paper, we propose the Spatial Transform Black-box Attack (STBA), a novel framework to craft formidable adversarial examples in the query-limited scenario. Specifically, STBA introduces a flow field to the high-frequency part of clean images to generate adversarial examples and adopts the following two processes to enhance their naturalness and significantly improve the query efficiency: a) we apply an estimated flow field to the high-frequency part of clean images to generate adversarial examples instead of introducing external noise to the benign image, and b) we leverage an efficient gradient estimation method based on a batch of samples to optimize such an ideal flow field under query-limited settings. Compared to existing score-based black-box baselines, extensive experiments indicated that STBA could effectively improve the imperceptibility of the adversarial examples and remarkably boost the attack success rate under query-limited settings. Renyang Liu 0001, Kwok-Yan Lam, Wei Zhou 0011, Sixing Wu, Jun Zhao 0007, Dongting Hu, Mingming Gong |
IEEE Trans. Multim. | 1 |
| 2025 | Post-Deployment Fine-Tunable Semantic CommunicationabstractSemantic communication (SemCom) is an emerging way that aims to improve communication efficiency based on the semantics of content, which relies on the knowledge base (KB) and is usually dedicated to specific tasks or datasets. To improve the adaptability of SemCom systems on unknown datasets, we propose a post-deployment Fine-Tunable Semantic Communication (FTSC) system for image transmission. Towards an adaptive and efficient SemCom system, our research consists of the framework design of FTSC and its system optimization study. Firstly, the generalizability study is conducted based on a two-layer hierarchical vector quantized-variational autoencoder (VQ-VAE-2). Unlike traditional SemCom that can work on limited pretrained datasets, FTSC adapts to varied input data post-deployment, enhancing practicality in diverse communication scenarios. This system incorporates two novel fine-tuning methods: Decoder Fine-Tuning (DFT) and Latent Space-based Decoder Fine-Tuning (LSDFT). DFT updates the decoder for new images post-deployment without transmitting gradients, while LSDFT eliminates the need for raw image transmission during fine-tuning. Secondly, we study the system optimization of the proposed FTSC framework to improve the efficiency of communication resource allocation with the concern of recovery quality, time delay, and energy cost in downlink transmissions. Extensive experiments demonstrate the superiority of FTSC over Joint Photographic Experts Group (JPEG) and Joint Source-Channel Coding (JSCC) across various datasets and noise levels, and both DFT and LSDFT significantly enhance image recovery on unfamiliar datasets compared to pre-trained models. Peiyuan Si, Renyang Liu 0001, Liangxin Qian, Jun Zhao 0007, Kwok-Yan Lam |
IEEE Trans. Wirel. Commun. | 2 |
| 2024 | SSTA: Salient Spatially Transformed AttackabstractExtensive studies have demonstrated that deep neural networks (DNNs) are vulnerable to adversarial examples (AEs), which brings a huge security risk to the application of DNNs, especially for the AI models developed in the real world. To impede the process of fully exploiting the vulnerabilities of existing DNNs and further improving their robustness in the face of such malicious inputs, many attack methods have been proposed to build AEs. Despite the significant progress that has been made recently, existing attack methods still suffer from the unsatisfactory performance of escaping from being detected by naked human eyes due to the formulation of AE heavily relying on a noise-adding manner. Such mentioned challenges will significantly increase the risk of exposure and result in an attack to be failed. Therefore, in this paper, we propose the Salient Spatially Transformed Attack (SSTA), a novel framework to craft imperceptible AEs, which enhance the stealthiness of AEs by estimating a smooth spatial transform metric on a most critical area to generate AEs instead of adding external noise to the whole image. Compared to SOTA baselines, extensive experiments indicated that SSTA could effectively improve the imperceptibility of the AEs while maintaining a 100% attack success rate. Renyang Liu 0001, Wei Zhou 0011, Sixing Wu, Jun Zhao 0007, Kwok-Yan Lam |
ICASSP | 1 |
| 2024 | CNFA: Conditional Normalizing Flow for Query-Limited AttackabstractTraditional black-box attack methods rely on sufficient feedback from the victim model through a large number of queries until the attack is successful. This may not be acceptable in real applications, since the deployed system may be equipped with certain defense mechanisms and only return the final result (i.e., hard label) to the client. In contrast, one possible approach is formulating a hard label attack, which can be successfully executed within limited queries. To implement this idea, in this paper, we bypass the reliance on victim models and benefit from the intrinsic characteristics of adversarial examples (AEs) and the transferability of examples across different data-driven models. This motivates us to generatively reformulate the attack problem and propose a conditional normalized flow-based attack (CNFA), which builds up a statistical mapping from the benign example to its adversarial counterpart by tackling the conditional likelihood under the hard-label black-box setting. A well-trained CNFA model can directly and efficiently generate a batch of AEs for specific condition inputs. Extensive experiments validate the effectiveness of the proposed idea in a hard-label black-box setting and the superiority of CNFA over SOTA techniques. Renyang Liu 0001, Wei Zhou 0011, Haoran Li 0023, Ruxin Wang 0002 |
ICASSP | 1 |
| 2024 | DTA: distribution transform-based attack for query-limited scenarioabstractAbstract In generating adversarial examples, the conventional black-box attack methods rely on sufficient feedback from the to-be-attacked models by repeatedly querying until the attack is successful, which usually results in thousands of trials during an attack. This may be unacceptable in real applications since Machine Learning as a Service Platform (MLaaS) usually only returns the final result (i.e., hard-label) to the client and a system equipped with certain defense mechanisms could easily detect malicious queries. By contrast, a feasible way is a hard-label attack that simulates an attacked action being permitted to conduct a limited number of queries. To implement this idea, in this paper, we bypass the dependency on the to-be-attacked model and benefit from the characteristics of the distributions of adversarial examples to reformulate the attack problem in a distribution transform manner and propose a distribution transform-based attack (DTA). DTA builds a statistical mapping from the benign example to its adversarial counterparts by tackling the conditional likelihood under the hard-label black-box settings. In this way, it is no longer necessary to query the target model frequently. A well-trained DTA model can directly and efficiently generate a batch of adversarial examples for a certain input, which can be used to attack un-seen models based on the assumed transferability. Furthermore, we surprisingly find that the well-trained DTA model is not sensitive to the semantic spaces of the training dataset, meaning that the model yields acceptable attack performance on other datasets. Extensive experiments validate the effectiveness of the proposed idea and the superiority of DTA over the state-of-the-art. Renyang Liu 0001, Wei Zhou 0011, Xin Jin 0005, Yuanyu Wang, Ruxin Wang 0002 |
Cybersecur. | 1 |
| 2024 | Can LSH (locality-sensitive hashing) be replaced by neural network?
Renyang Liu 0001, Jun Zhao 0007, Xing Chu, Wei Zhou 0011, Jing He 0012 |
Soft Comput. | 1 |
| 2024 | Boosting Black-Box Attack to Deep Neural Networks With Conditional Diffusion ModelsabstractExisting black-box attacks have demonstrated promising potential in creating adversarial examples (AE) to deceive deep learning models. Most of these attacks need to handle a vast optimization space and require a large number of queries, hence exhibiting limited practical impacts in real-world scenarios. In this paper, we propose a novel black-box attack strategy, Conditional Diffusion Model Attack (CDMA), to improve the query efficiency of generating AEs under query-limited situations. The key insight of CDMA is to formulate the task of AE synthesis as a distribution transformation problem, i.e., benign examples and their corresponding AEs can be regarded as coming from two distinctive distributions and can transform from each other with a particular converter. Unlike the conventionalquery-and-optimizationapproach, we generate eligible AEs with direct conditional transform using the aforementioned data converter, which can significantly reduce the number of queries needed. CDMA adopts the conditional Denoising Diffusion Probabilistic Model as the converter, which can learn the transformation from clean samples to AEs, and ensure the smooth development of perturbed noise resistant to various defense strategies. We demonstrate the effectiveness and efficiency of CDMA by comparing it with nine state-of-the-art black-box attacks across three benchmark datasets. On average, CDMA can reduce the query count to a handful of times; in most cases, the query count is only ONE. We also show that CDMA can obtain > 99% attack success rate for untargeted attacks over all datasets and targeted attack over CIFAR-10 with the noise budget of ϵ = 16. Renyang Liu 0001, Wei Zhou 0011, Tianwei Zhang 0004, Kangjie Chen, Jun Zhao 0007, Kwok-Yan Lam |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2023 | Rewriting-Stego: Generating Natural and Controllable Steganographic Text with Pre-trained Language Model
Fanxiao Li, Sixing Wu, Shuoxin Wang, Bingbing Song, Renyang Liu 0001, Haoseng Lai, Wei Zhou 0011 |
DASFAA (1) | 6 |
| 2023 | AFLOW: Developing Adversarial Examples Under Extremely Noise-Limited Settings
Renyang Liu 0001, Haoran Li 0023, Yuanyu Wang, Wei Zhou 0011 |
ICICS | 1 |
| 2023 | SCME: A Self-contrastive Method for Data-Free and Query-Limited Model Extraction Attack
Renyang Liu 0001, Kwok-Yan Lam, Jun Zhao 0007, Wei Zhou 0011 |
ICONIP (5) | 1 |
| 2023 | Model Inversion Attacks on Homogeneous and Heterogeneous Graph Neural Networks
Renyang Liu 0001, Wei Zhou 0011, Xiaoyuan Liu 0002, Peiyuan Si, Haoran Li 0023 |
SecureComm (1) | 1 |
| 2023 | Type-I Generative Adversarial AttackabstractDeep neural networks are vulnerable to adversarial attacks either by examples with indistinguishable perturbations which produce incorrect predictions, or by examples with noticeable transformations that are still predicted as the original label. The latter case is known as the Type I attack which, however, has achieved limited attention in literature. We advocate that the vulnerability comes from the ambiguous distributions among different classes in the resultant feature space of the model, which is saying that the examples with different appearances may present similar features. Inspired by this, we propose a novel Type I attack method called generative adversarial attack (GAA). Specifically, GAA aims at exploiting the distribution mapping from the source domain of multiple classes to the target domain of a single class by using generative adversarial networks. A novel loss and a U-net architecture with latent modification are elaborated to ensure the stable transformation between the two domains. In this way, the generated adversarial examples have similar appearances with examples of the target domain, yet obtaining the original prediction by the model being attacked. Extensive experiments on multiple benchmarks demonstrate that the proposed method generates adversarial images that are more visually similar to the target images than the competitors, and the state-of-the-art performance is achieved. Shenghong He, Ruxin Wang 0002, Tongliang Liu, Chao Yi, Xin Jin 0005, Renyang Liu 0001, Wei Zhou 0011 |
IEEE Trans. Dependable Secur. Comput. | 6 |
| 2022 | RIA: A Reversible Network-based Imperceptible Adversarial AttackabstractThe robustness and security of deep neural network (DNN) models have received much attention in recent years. In-depth research on adversarial example generation methods that make DNN models make wrong judgments and decisions will facilitate further research on more comprehensive and practical adversarial defense methods. Most existing adversarial example generation methods focus too much on attack performance and design adversarial noise at the pixel level, resulting in the generated adversarial examples with redundant noise and evident perturbations. In this paper, we try to find the well-designed perturbations at the feature-level and propose a novel deep reversible network-based imperceptible adversarial examples generation method called RIA. Experimental results show that RIA can obtain more natural adversarial examples without losing attack performance and reducing redundant noise based on well-designed feature maps. To the best of our knowledge, in the white-box attack method research, this work is the first attempt to directly add perturbations to feature maps and use an reversible network to generate adversarial examples based on the perturbed feature maps. Fanxiao Li, Renyang Liu 0001, Zhenli He, Yunyun Dong, Wei Zhou 0011 |
ICTAI | 2 |
| 2022 | SMDAF: A novel keypoint based method for copy-move forgery detectionabstractAbstract Copy–move forgery poses a significant threat to social life and has aroused much attention in recent years. Although many copy‐move forgery detection (CMFD) methods have been proposed, the most existing CMFD methods are short of adaptability in detecting images, which leads to the limitation on detection effects. To solve this problem, the paper proposes a novel keypoint‐based CMFD method: second‐keypoint matching and double adaptive filtering (SMDAF). Motivated by image matching based on keypoint, the second‐keypoint matching method is designed to match keypoints extracted from copy–move forgery images, which can be used for both the single‐CMFD and the multiple‐CMFD. Then, a double adaptive filter (DAF) based on the AdaLAM algorithm and the KANN‐DBSCAN clustering algorithm to filter wrong keypoint matches adaptively are proposed, according to the distinct distribution of keypoints in each image. Finally, the forgery regions are presented by finding their convex hulls and padding them. Compared with existing methods, extensive experiments show that the SMDAF method significantly provides more efficiency in detecting images under simulated real‐world conditions, has better robustness when facing images with different post‐treatment attacks, and is more effective in distinguishing images that look copy–move forged but are real. Guangyu Yue, Qing Duan, Renyang Liu 0001, Wenyu Peng, Yun Liao |
IET Image Process. | 3 |
| 2021 | EnsembleFool: A method to generate adversarial examples based on model fusion strategy
Wenyu Peng, Renyang Liu 0001, Ruxin Wang 0002, Taining Cheng, Zifeng Wu, Wei Zhou 0011 |
Comput. Secur. | 2 |