Zhihao Yue

dblp:314/6918 · DBLP profile ↗
← Back
7ranked-venue papers
1as first author
7since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
5 papers
Efficient and distributed learning · 79% Representation and self-supervised learning · 18% Optimization for machine learning · 3%
Network and information security
2 papers
Security and privacy of machine learning · 100%
Computer graphics and multimedia
1 paper
Image and video processing · 50% Image and video coding · 50%

Topics — the 13 heaviest of 13, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Efficient and distributed learning
federated learning
2.232024
Is Aggregation the Only Choice? Federated Learning via Layer-wise Model Recombination · KDD 2024
FedCross: Towards Accurate Federated Learning via Multi-Model Cross-Aggregation · ICDE 2024
GitFL: Uncertainty-Aware Real-Time Asynchronous Federated Learning Using Version Control · RTSS 2023
Machine learning › Efficient and distributed learning › federated learning
data heterogeneity
1.522024
Is Aggregation the Only Choice? Federated Learning via Layer-wise Model Recombination · KDD 2024
FedCross: Towards Accurate Federated Learning via Multi-Model Cross-Aggregation · ICDE 2024
Machine learning › Efficient and distributed learning › federated learning
model aggregation
0.812024
Is Aggregation the Only Choice? Federated Learning via Layer-wise Model Recombination · KDD 2024
Image and video coding › transform coding
discrete wavelet transform
0.812024
WaveAttack: Asymmetric Frequency Obfuscation-based Backdoor Attacks Against Deep Neural Networks · NeurIPS 2024
Image and video processing
image transform
0.812024
WaveAttack: Asymmetric Frequency Obfuscation-based Backdoor Attacks Against Deep Neural Networks · NeurIPS 2024
Security and privacy of machine learning › adversarial attack
backdoor attack
0.812024
WaveAttack: Asymmetric Frequency Obfuscation-based Backdoor Attacks Against Deep Neural Networks · NeurIPS 2024
Security and privacy of machine learning › adversarial attack › backdoor attack › trigger design
frequency-domain trigger
0.812024
WaveAttack: Asymmetric Frequency Obfuscation-based Backdoor Attacks Against Deep Neural Networks · NeurIPS 2024
Machine learning › Efficient and distributed learning › federated learning
asynchronous federated learning
0.712023
GitFL: Uncertainty-Aware Real-Time Asynchronous Federated Learning Using Version Control · RTSS 2023
Machine learning › Efficient and distributed learning › federated learning
client selection
0.712023
GitFL: Uncertainty-Aware Real-Time Asynchronous Federated Learning Using Version Control · RTSS 2023
Machine learning › Representation and self-supervised learning
contrastive learning
0.712023
Model-Contrastive Learning for Backdoor Elimination · ACM Multimedia 2023
Machine learning › Representation and self-supervised learning › contrastive learning
model-contrastive learning
0.712023
Model-Contrastive Learning for Backdoor Elimination · ACM Multimedia 2023
Security and privacy of machine learning › adversarial attack › backdoor attack
backdoor defense
0.712023
Model-Contrastive Learning for Backdoor Elimination · ACM Multimedia 2023
Machine learning › Optimization for machine learning › optimization landscape
flat minima
0.212024
Is Aggregation the Only Choice? Federated Learning via Layer-wise Model Recombination · KDD 2024

Methods — techniques the papers use, named apart from their topics

discrete wavelet transform · 2.3asymmetric frequency obfuscation · 2.3knowledge distillation · 1.3contrastive learning · 1.3weighted fusion · 0.8middleware models · 0.8layer-wise model recombination · 0.8fedavg · 0.8version control · 0.7reinforcement learning · 0.7
YearPublicationVenuePosition
2025 EqGAN: Reformation-based Feature Equalization Fusion for Few-shot Image Generation
abstract
Due to the absence or mismatch of semantic information, existing few-shot image generation methods suffer from unsatisfactory generation quality and diversity, which have minimal benefits as data augmentation for downstream classification tasks. Reformatting the contextual and textural information of features at different scales, we propose a novel Feature Equalization Fusion Generative Adversarial Network (EqGAN) for few-shot image generation. Specifically, we first decompose the encoded features into textual and structural components to mitigate the influence of irrelevant and redundant information. Based on feature correlation learning and attention mechanism, we then obtain fused features by refining different contents (i.e., textures and structures) with a more fine-grained semantic alignment. Moreover, an attention-based reconstruction loss and a consistency-based equalization loss are devised to provide better training stability and generation performance. Comprehensive experiments on three public datasets demonstrate that EqGAN not only significantly improves the FID scores (by up to 14.10%) and LPIPS scores (by up to 3.17%) of generated images, but also outperforms the state-of-the-art in terms of accuracy (by up to 3.89%) for downstream classification.
Yingbo Zhou 0001, Zhihao Yue, Yutong Ye 0001, Xian Wei, Mingsong Chen 0001
ICASSP2
2025 FiTGAN: Content Fusion with Style Transformation for Few-shot Image Generation
abstract
Due to the semantic entanglement in fusion strategies or unstable training in complicated image transformations, existing few-shot image generation methods still suffer from low generation quality and diversity. To tackle the above problems, we propose a novel fusion- and transformation-based framework named content Fusion with style Transformation Generative Adversarial Network (FiTGAN) for few-shot image generation. The basic assumption is that any image consists of a collection of content-related and style-related features. FiTGAN disentangles internal representations with two independent encoders and combines the fused contents and transformed styles to generate new images. Specifically, we design a multi-scale content fusion strategy and a reparameterized style transformation mechanism to learn more fine-grained semantics without changing category-relevant attributes. Furthermore, we formulate a content reconstruction loss and a style divergence loss to provide better training stability and generation performance. Comprehensive experiments on three well-known datasets demonstrate that FiTGAN can not only produce more realistic and diverse images for few-shot image generation but also achieve better classification accuracy for downstream visual applications with limited data.
Yingbo Zhou 0001, Yutong Ye 0001, Zhihao Yue, Xian Wei, Mingsong Chen 0001
ICASSP4
2024 FedCross: Towards Accurate Federated Learning via Multi-Model Cross-Aggregation
abstract
As a promising distributed machine learning paradigm, Federated Learning (FL) has attracted increasing attention to deal with data silo problems without compromising user privacy. By adopting the classic one-to-multi training scheme (i.e., FedAvg), where the cloud server dispatches one single global model to multiple involved clients, conventional FL methods can achieve collaborative model training without data sharing. However, since only one global model cannot always accommodate all the incompatible convergence directions of local models, existing FL approaches greatly suffer from inferior classification accuracy. To address this issue, we present an efficient FL framework named FedCross, which uses a novel multi-to-multi FL training scheme based on our proposed multi-model cross-aggregation approach. Unlike traditional FL methods, in each round of FL training, FedCross uses multiple middleware models to conduct weighted fusion individually. Since the middleware models used by FedCross can quickly converge into the same flat valley in terms of loss landscapes, the generated global model can achieve a well-generalization. Experimental results on various well-known datasets show that, compared with state-of-the-art FL methods, Fed Cross can significantly improve FL accuracy within both IID and non-IID scenarios without causing additional communication overhead.
Ming Hu 0003, Peiheng Zhou, Zhihao Yue, Zhiwei Ling, Yihao Huang 0001, Anran Li 0001, Yang Liu 0003, Xiang Lian 0001, Mingsong Chen 0001
ICDE3
2024 Is Aggregation the Only Choice? Federated Learning via Layer-wise Model Recombination
abstract
Although Federated Learning (FL) enables global model training across clients without compromising their raw data, due to the un- evenly distributed data among clients, existing Federated Averaging (FedAvg)-based methods suffer from the problem of low inference performance. Specifically, different data distributions among clients lead to various optimization directions of local models. Aggregat- ing local models usually results in a low-generalized global model, which performs worse on most of the clients. To address the above issue, inspired by the observation from a geometric perspective that a well-generalized solution is located in a flat area rather than a sharp area, we propose a novel and heuristic FL paradigm named FedMR (Federated Model Recombination). The goal of FedMR is to guide the recombined models to be trained towards a flat area. Unlike conventional FedAvg-based methods, in FedMR, the cloud server recombines collected local models by shuffling each layer of them to generate multiple recombined models for local training on clients rather than an aggregated global model. Since the area of the flat area is larger than the sharp area, when local models are located in different areas, recombined models have a higher probability of locating in a flat area. When all recombined models are located in the same flat area, they are optimized towards the same direction. We theoretically analyze the convergence of model recombination. Experimental results show that, compared with state-of-the-art FL methods, FedMR can significantly improve the inference accuracy without exposing the privacy of each client.
Ming Hu 0003, Zhihao Yue, Xiaofei Xie, Cheng Chen 0015, Yihao Huang 0001, Xian Wei, Xiang Lian 0001, Yang Liu 0003, Mingsong Chen 0001
KDD2
2024 WaveAttack: Asymmetric Frequency Obfuscation-based Backdoor Attacks Against Deep Neural Networks
abstract
Due to the increasing popularity of Artificial Intelligence (AI), more and more backdoor attacks are designed to mislead Deep Neural Network (DNN) predictions by manipulating training samples or processes. Although backdoor attacks have been investigated in various scenarios, they still suffer from the problems of both low fidelity of poisoned samples and non-negligible transfer in latent space, which make them easily identified by existing backdoor detection algorithms. To overcome this weakness, this paper proposes a novel frequency-based backdoor attack method named WaveAttack, which obtains high-frequency image features through Discrete Wavelet Transform (DWT) to generate highly stealthy backdoor triggers. By introducing an asymmetric frequency obfuscation method, our approach adds an adaptive residual to the training and inference stages to improve the impact of triggers, thus further enhancing the effectiveness of WaveAttack. Comprehensive experimental results show that, WaveAttack can not only achieve higher effectiveness than state-of-the-art backdoor attack methods, but also outperform them in the fidelity of images (i.e., by up to 28.27\% improvement in PSNR, 1.61\% improvement in SSIM, and 70.59\% reduction in IS). Our code is available at https://github.com/BililiCode/WaveAttack.
Jun Xia 0003, Zhihao Yue, Yingbo Zhou 0001, Zhiwei Ling, Yiyu Shi 0001, Xian Wei, Mingsong Chen 0001
NeurIPS2
2023 Model-Contrastive Learning for Backdoor Elimination
abstract
Due to the popularity of Artificial Intelligence (AI) techniques, we are witnessing an increasing number of backdoor injection attacks that are designed to maliciously threaten Deep Neural Networks (DNNs) causing misclassification. Although there exist various defense methods that can effectively erase backdoors from DNNs, they greatly suffer from both high Attack Success Rate (ASR) and a non-negligible loss in Benign Accuracy (BA). Inspired by the observation that a backdoored DNN tends to form a new cluster in its feature spaces for poisoned data, in this paper, we propose a novel two-stage backdoor defense method, named MCLDef, based on Model-Contrastive Learning (MCL). MCLDef can purify the backdoored model by pulling the feature representations of poisoned data towards those of their clean data counterparts. Due to the shrunken cluster of poisoned data, the backdoor formed by end-to-end supervised learning can be effectively eliminated. Comprehensive experimental results show that, with only 5% of clean data, MCLDef significantly outperforms state-of-the-art defense methods by up to 95.79% reduction in ASR, while in most cases, the BA degradation can be controlled within less than 2%. Our code is available at https://github.com/Zhihao151/MCL.
Zhihao Yue, Jun Xia 0003, Zhiwei Ling, Ming Hu 0003, Ting Wang 0001, Xian Wei, Mingsong Chen 0001
ACM Multimedia1
2023 GitFL: Uncertainty-Aware Real-Time Asynchronous Federated Learning Using Version Control
abstract
As a promising distributed machine learning paradigm that enables collaborative training without compromising data privacy, Federated Learning (FL) has been increasingly used in large-scale A IoT (Artificial Intelligence of Things) system design. However, due to the lack of efficient management of straggling devices, existing FL methods greatly suffer from the problems of long response time (e.g., training and communication latency) and low inference accuracy. Things become even worse when taking various uncertain factors (e.g., network delays, performance variances caused by process variation) existing in AIoT scenarios into account. To address this issue, this paper proposes a novel asynchronous FL framework named GitFL, whose implementation is inspired by the famous version control system Git. Unlike traditional FL, the cloud server of GitFL maintains a master model (i.e., the global model) together with a set of branch models indicating the trained local models committed by selected devices, where the master model is updated based on both all the pushed branch models and their version information, and only the branch models after the pull operation are dispatched to devices. By using our proposed Reinforcement Learning (RL)-based device selection mechanism, a pulled branch model with an older version will be more likely to be dispatched to a faster and less frequently selected device for the next round of local training. In this way, GitFL enables both effective controls of model staleness and adaptive load balance of versioned models among straggling devices, thus avoiding performance deterioration while ensuring real-time performance. Comprehensive experimental results on well-known models and datasets show that, compared with state-of-the-art asynchronous and synchronous FL methods, GitFL can achieve up to 2.64X training acceleration and 7.88 % inference accuracy improvements in various uncertain scenarios.
Ming Hu 0003, Zeke Xia, Dengke Yan, Zhihao Yue, Jun Xia 0003, Yihao Huang 0001, Yang Liu 0003, Mingsong Chen 0001
RTSS4