Guobiao Li

dblp:321/6750 · DBLP profile ↗
← Back
13ranked-venue papers
6as first author
13since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 12 · 5 first-author · 12 since 2021Artificial intelligence and machine learning · 5 · 2 first-author · 5 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Toward Detecting Hidden Functionalities in Deep Learning Models
abstract
Deep functionality hiding is an emerging technique that embeds confidential or sensitive functions within seemingly benign deep learning models (DLMs), which perform ordinary machine learning tasks. This enables such models to execute covert tasks while remaining undetected. Despite the rapid progress in deep functionality hiding, countermeasures remain unexplored. In this paper, we propose Distribution Offset Analysis (DOA), a novel method for detecting hidden functionalities in DLMs. Our key insight is that the weight distribution of a benign DLM typically follows a Gaussian distribution, whereas a container DLM with hidden functionalities exhibits notable statistical deviations from this Gaussian pattern. In our methodology, we first compute the distributional distance (i.e.,offsets) between the model's weights and an ideal Gaussian distribution. We then fuse these offsets with weight features into a unified representation, which is subsequently used to train a meta-classifier for hidden functionality detection. Through extensive experiments, we demonstrate the effectiveness of the proposed DOA method, which achieves an average detection rate of over 87% against existing state-of-the-art deep functionality hiding techniques.
Guobiao Li, Sheng Li 0006, Zhenxing Qian, Xinpeng Zhang 0001
IEEE Signal Process. Lett.1
2026 On Cover Independent Deep Neural Network Steganography
abstract
Steganography aims to hide secret data into a cover media by subtle perturbation. Recently, deep neural network (DNN) based steganography has attracted a lot of research interests. Most of the existing DNN-based steganographic schemes design the secret encoder and decoder in an asymmetrical manner, the performance of which is heavily dependent on the content of cover media. In addition, they are weak in preventing unauthorized data extraction from the stego-media (i.e., the media with hidden data). To address these two issues, we propose a novel DNN steganographic framework termed the Cover Independent DNN Steganography (CIDS). In our CIDS, we take advantage of the powerful generative models to obtain AI-generated cover media for both the sender and receiver according to a key. Then, we propose a pair of symmetrical secret encoder and decoder to conduct a bijective transformation between the secrets and perturbations. While the perturbation is combined with the cover media to produce the stego-media. Such a secret encoding/decoding strategy focuses only on the secrets and is independent of the cover media. We also propose to encrypt the perturbations to effectively prevent unauthorized data extraction. Comprehensive experiments demonstrate the advantage of our CIDS over the state-of-the-art approaches for image steganography.
Guobiao Li, Sheng Li 0006, Zicong Luo, Zhenxing Qian, Xinpeng Zhang 0001
IEEE Trans. Dependable Secur. Comput.1
2025 Embedding Robust Watermarking into Pattern to Protect the Copyright of Ceramic Artifacts
abstract
Ceramic artworks with elegant patterns present enormous collectible value and profits. To claim the copyright, the builder usually pastes their conspicuous stamp on the bottom or side of the ceramic artworks, which inevitably affects the external image of the artwork. In addition, the stamp is weak in resisting forgery attacks due to its visible nature. To address the above issues, we propose in this paper a novel framework for embedding invisible watermarking into patterns of the ceramic artworks. In the framework, a template-based watermarking embedding scheme is designed to map the watermark to an invisible template, which is added to the ceramic pattern to create its watermarked version. A distortion layer is further proposed to model the distortion of ceramic patterns in the ceramic manufacturing process, where a color-halftoning and an adaptive brightness adjustment strategy are developed to counter the print and firing operations that introduce the most significant distortions. Finally, a deep decoder is learned to extract the watermarking from the distorted pattern. Various experiments have been conducted to demonstrate the advantage of our proposed method for protecting the copyright of the ceramic artworks, which provides reliable watermark extraction accuracy without the need for a conspicuous stamp.
Yuliang Xue, Guobiao Li, Zhenxing Qian, Sheng Li 0006, Chunlei Bao
AAAI3
2025 Physical Marker: Revealing Invisible Hyperlinks Hidden in Printed Trademarks
abstract
Embedding links in brand logos is a promising technology, which allows consumers to access the online information of products by capturing physical logo images. Previous physical data hiding methods primarily embed data within cover media in a global manner, making them ineffective for processing brand logos in vector graphics format with a transparent background. To address this issue, we propose in this paper a novel physical deep hiding scheme for invisibly embedding links in printed trademarks. Specifically, the encoder embeds links only into the area of the brand logo under the constraints of a mask, which is generated from the transparency information of the logo image. A background variation distortion is introduced into the distortion layer that approximate practical logo print-camera environments, such that the decoder could be learnt to retrieve the link from the camera-captured logo with various backgrounds. A feature prompt subspace modulator is further proposed and employed in the encoder to enhance the invisibility of the encoded logo pattern and in the decoder to boost hyperlink extraction accuracy. Various experiments have been conducted to demonstrate the advantage of our proposed method for embedding links in printed brand logos, which provides reliable extraction accuracy under both simulated and real scenarios.
Yuliang Xue, Guobiao Li, Zhenxing Qian, Sheng Li 0006, Xinpeng Zhang 0001
AAAI3
2025 Filtering Resistant Large Language Model Watermarking via Style Injection
abstract
The exorbitant cost of training Large Language Models (LLMs) makes it essential to protect the models from illegal copying and unauthorized usage. Recent attempts at LLM protection utilize black-box watermarking schemes, which embed distinctive input-output mapping (i.e., trigger set) directly into the models. However, most of them construct trigger inputs by injecting abnormal characters into normal text, which can easily be filtered out by unauthorized users, leading to a failure in watermark verification. In this paper, we propose a novel filtering-resistant LLM watermarking scheme, which takes advantage of imperceptible text styles to trigger the watermark. To achieve this, we adopt a trigger generation network to transform normal text into stylized sentences, which are assigned a specific watermarking label to build the trigger set. We then fine-tune the LLMs on both the trigger sets and clean samples for watermark embedding and performance stabilization. To boost watermark accuracy, we further propose a feature separation loss term to distinguish between normal and trigger inputs. Experimental results indicate the effectiveness of our proposed scheme for resisting the filtering attack.
Zhaojun Guo, Guobiao Li, Junqiang Huang, Xinpeng Zhang 0001, Zhenxing Qian, Sheng Li 0006
ICASSP2
2025 Texture-Aware Neural Radiance Fields Watermarking for Resisting Feature-Modulation Surrogate Model Attacks
abstract
The exorbitant cost of training Neural Radiance Fields (NeRF) makes it essential to protect them from illegal copying and unauthorized usage. Recent attempts at NeRF protection utilize watermarking schemes, which subtly alter NeRFs such that their rendered images contain watermarks that can be extracted by a decoder. In this paper, we investigate the robustness of existing NeRF watermarking schemes against surrogate model attacks, which train a surrogate NeRF using the input-output pairs of a victim NeRF. By proposing a Feature-Modulation Surrogate Model Attack (FM-SMA), we successfully crack most of the existing NeRF watermarking schemes. As a remedy, we further propose Texture-Aware Neural Radiance Fields Watermarking (TA-NFW), which resists FM-SMA attacks by embedding watermarks within the textures of NeRF-rendered results. Various experiments have been conducted to demonstrate the vulnerability of existing NeRF watermarking methods and the robustness of TA-NFW against the proposed FM-SMA attack.
Yuliang Xue, Guobiao Li, Zhenxing Qian, Sheng Li 0006, Xinpeng Zhang 0001
ICME3
2025 Fine-grained Prompt Screening: Defending Against Backdoor Attack on Text-to-Image Diffusion Models
abstract
Text-to-image (T2I) diffusion models exhibit impressive generation capabilities in recently studies. However, they are vulnerable to backdoor attacks, where model outputs are manipulated by malicious triggers. In this paper, we propose a novel input-level defense method, called Fine-grained Prompt Screening (GrainPS). Our method is motivated by the phenomenon, i.e., Semantics Misalignment, where the backdoor trigger causes the inconsistency between the cross-attention projections of object words (the key words to determine the main content of the generated image) and their true semantics. In particular, we divide each prompt into pieces and conduct fine-grained analysis by examining the impact of the trigger on object words in the cross-attention layers rather than their global influence on the entire generated image. To assess the impact of each word on object words, we formulate "semantics alignment score'' as the metric with a carefully crafted detection strategy to identify the trigger. Therefore, our implementation can detect backdoor input prompts and localize of triggers simultaneously. Evaluations across four advanced backdoor attack scenarios demonstrate the effectiveness of our proposed defense method.
Nan Zhong, Guobiao Li, Anda Cheng, Yinggui Wang, Zhenxing Qian, Xinpeng Zhang 0001
IJCAI3
2024 Purified and Unified Steganographic Network
abstract
Steganography is the art of hiding secret data into the cover media for covert communication. In recent years, more and more deep neural network (DNN)-based steganographic schemes are proposed to train steganographic networks for secret embedding and recovery, which are shown to be promising. Compared with the handcrafted steganographic tools, steganographic networks tend to be large in size. It raises concerns on how to imperceptibly and effectively transmit these networks to the sender and receiver to facilitate the covert communication. To address this issue, we propose in this paper a Purified and Unified Steganographic Network (PUSNet). It performs an ordinary machine learning task in a purified network, which could be triggered into steganographic networks for secret embedding or recovery using different keys. We formulate the construction of the PUSNet into a sparse weight filling problem to flexibly switch between the purified and steganographic networks. We further instantiate our PUSNet as an image denoising network with two steganographic networks concealed for secret image embedding and recovery. Comprehensive experiments demonstrate that our PUSNet achieves good performance on secret image embedding, secret image recovery, and image denoising in a single architecture. It is also shown to be capable of imperceptibly carrying the steganographic networks in a purified network. Code is available at https://github.com/albblgb/PUSNet
Guobiao Li, Sheng Li 0006, Zicong Luo, Zhenxing Qian, Xinpeng Zhang 0001
CVPR1
2024 Cover-separable Fixed Neural Network Steganography via Deep Generative Models
abstract
Image steganography is the process of hiding secret data in a cover image by subtle perturbation. Recent studies show that it is feasible to use a fixed neural network for data embedding and extraction. Such Fixed Neural Network Steganography (FNNS) demonstrates favorable performance without the need for training networks, making it more practical for real-world applications. However, the stego-images generated by the existing FNNS methods exhibit high distortion, which is prone to be detected by steganalysis tools. To deal with this issue, we propose a Cover-separable Fixed Neural Network Steganography, namely Cs-FNNS. In Cs-FNNS, we propose a Steganographic Perturbation Search (SPS) algorithm to directly encode the secret data into an imperceptible perturbation, which is combined with an AI-generated cover image for transmission. Through accessing the same deep generative models, the receiver could reproduce the cover image using a pre-agreed key, to separate the perturbation in the stego-image for data decoding. such an encoding/decoding strategy focuses on the secret data and eliminates the disturbance of the cover images, hence achieving a better performance. We apply our Cs-FNNS to the steganographic field that hiding secret images within cover images. Through comprehensive experiments, we demonstrate the superior performance of the proposed method in terms of visual quality and undetectability. Moreover, we show the flexibility of our Cs-FNNS in terms of hiding multiple secret images for different receivers. Code is available at https://github.com/albblgb/Cs-FNNS
Guobiao Li, Sheng Li 0006, Zhenxing Qian, Xinpeng Zhang 0001
ACM Multimedia1
2024 Emotion-Aware and Efficient Meme Sticker Dialogue Generation
abstract
Recent advances have emphasized the importance of meme stickers in open-domain dialogue systems.However, previous studies overlook the one-to-many issue that a single sticker could represent various emotions in different dialogue contexts.Additionally, they require retraining the model for new stickers which did not appear in previous training.To address the above issues, we propose in this paper an Emotion-Aware and Efficient Meme Sticker Dialogue generation framework.In the framework, we design an Emotion Adaptive Prompt to capture the emotional cues from the dialogue history, which is sent to an Emotion-Aware Fusion Decoder to guide the generation of text responses and to a meme sticker selector to choose the corresponding sticker.Furthermore, to improve the stickers' selection efficiency, we further incorporate the few-shot learning strategy into the proposed framework to avoid extensive model retraining for unseen meme stickers.Through extensive experiments, we demonstrate the superior performance of the proposed E 2 MSD compared to existing methods regarding the quality of response generation and the efficiency of meme sticker retrieval.
Zhaojun Guo, Junqiang Huang, Guobiao Li, Wanli Peng, Xinpeng Zhang 0001, Zhenxing Qian, Sheng Li 0006
MMAsia3
2023 Steganography of Steganographic Networks
abstract
Steganography is a technique for covert communication between two parties. With the rapid development of deep neural networks (DNN), more and more steganographic networks are proposed recently, which are shown to be promising to achieve good performance. Unlike the traditional handcrafted steganographic tools, a steganographic network is relatively large in size. It raises concerns on how to covertly transmit the steganographic network in public channels, which is a crucial stage in the pipeline of steganography in real world applications. To address such an issue, we propose a novel scheme for steganography of steganographic networks in this paper. Unlike the existing steganographic schemes which focus on the subtle modification of the cover data to accommodate the secrets. We propose to disguise a steganographic network (termed as the secret DNN model) into a stego DNN model which performs an ordinary machine learning task (termed as the stego task). During the model disguising, we select and tune a subset of filters in the secret DNN model to preserve its function on the secret task, where the remaining filters are reactivated according to a partial optimization strategy to disguise the whole secret DNN model into a stego DNN model. The secret DNN model can be recovered from the stego DNN model when needed. Various experiments have been conducted to demonstrate the advantage of our proposed method for covert communication of steganographic networks as well as general DNN models.
Guobiao Li, Sheng Li 0006, Xinpeng Zhang 0001, Zhenxing Qian
AAAI1
2023 Securing Fixed Neural Network Steganography
abstract
Image steganography is the art of concealing secret information in images in a way that is imperceptible to unauthorized parties. Recent advances show that is possible to use a fixed neural network (FNN) for secret embedding and extraction. Such fixed neural network steganography (FNNS) achieves high steganographic performance without training the networks, which could be more useful in real-world applications. However, the existing FNNS schemes are vulnerable in the sense that anyone can extract the secret from the stego-image. To deal with this issue, we propose a key-based FNNS scheme to improve the security of the FNNS, where we generate key-controlled perturbations from the FNN for data embedding. As such, only the receiver who possesses the key is able to correctly extract the secret from the stego-image using the FNN. In order to improve the visual quality and undetectability of the stego-image, we further propose an adaptive perturbation optimization strategy by taking the perturbation cost into account. Experimental results show that our proposed scheme is capable of preventing unauthorized secret extraction from the stego-images. Furthermore, our scheme is able to generate stego-images with higher visual quality than the state-of-the-art FNNS scheme, especially when the FNN is a neural network for ordinary learning tasks.
Zicong Luo, Sheng Li 0006, Guobiao Li, Zhenxing Qian, Xinpeng Zhang 0001
ACM Multimedia3
2022 Encryption Resistant Deep Neural Network Watermarking
abstract
Deep neural network (DNN) watermarking is one of the main techniques to protect the DNN. Although various DNN watermarking schemes have been proposed, none of them is able to resist the DNN encryption. In this paper, we propose an encryption resistent DNN watermarking scheme, which is able to resist the parameter shuffling based DNN encryption. Unlike the existing schemes which use the kernels separately for watermarking embedding, we propose to embed the watermark into the fused kernels to resist the parameter shuffling. We further propose a MappingNet to map the the fused kernels into a higher dimension to increase the watermarking capacity. The MappingNet and the DNN are jointly trained to conduct final watermark embedding. Experimental results indicate the effectiveness of our proposed scheme for resisting the DNN encryption.
Guobiao Li, Sheng Li 0006, Zhenxing Qian, Xinpeng Zhang 0001
ICASSP1