EDBT 2026 Demo / reviewers in the wild / expert
Yulin Jin
dblp:328/3570
· DBLP profile ↗
13ranked-venue papers
4as first author
13since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 8 · 3 first-author · 8 since 2021Artificial intelligence and machine learning · 5 · 3 first-author · 5 since 2021Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Stochastic Universal Adversarial Perturbations with Fixed Optimization Constraint and Ensured High-probability TransferabilityabstractAdversarial perturbations (APs) have become a great concern in image classification tasks. The most challenging branch, universal adversarial perturbations (UAPs), are exploited to fool most of the unseen samples. Such one-to-all perturbations have the merit of transferability, which has strong practical significance. In this paper, we firstly define the transferability gap and the algorithm stability of the UAP algorithm, and prove the relationship between them. In analyzing the UAP algorithm stability, we prove that the convergence domain of existing UAP algorithms with dynamic constraints is excessively small, which degrades the capacity of UAPs. Thus, we further propose a new expected constraint and prove that UAPs in the expected constraint suit any sample in a high probability. Besides, we propose a Stochastic Universal Adversarial Perturbation (SUAP) that involves additive noise and the expected constraint. Finally, by treating the proposed algorithm as a stochastic differential equation, we prove an upper bound of the UAP algorithm stability of SUAP, which decreases exponentially at the beginning and then increases with a sublinear rate to at most a fixed constant. Experimental results show that SUAP is aligned with our analysis. Yulin Jin, Xiaoyu Zhang 0010, Haoyu Tong, Jian Lou 0001, Kai Wu 0003, Haibo Hu 0001, Xiaofeng Chen 0001 |
AAAI | 1 |
| 2026 | DIFT: Protecting Contrastive Learning Against Data Poisoning Backdoor AttacksabstractContrastive learning (CL) is a popular learning paradigm that excels in extracting meaningful representations from unlabeled data. Recent studies have shown that CL is highly vulnerable to backdoor attacks. Current defenses against backdoor attacks in CL are primarily reactive and post-training. That is, the detection and elimination of backdoors are executed in the deployment phase of a given well-trained model. However, these post-training defenses are usually prone to degrading model utility and resource-intensive, causing that the backdoor detection and elimination from a fully-trained model is quite challenging. To address this issue, we argue for a fundamental perspective, i.e., integrating the defense into the model's training phase, and propose a novel framework to mitigate the backdoor in CL, namely Density-Based Identification and Fine-Tuning (DIFT). Specifically, DIFT identifies potential poisoned samples during the early training phase via detecting embeddings with abnormal poisoning characteristic in the feature space. Then, to remove backdoors and preserve model utility, the detected poisoned samples are leveraged to fine-tune the model, and the remaining clean samples are further involved into training the model after the fine-tuning. DIFT, as a proactive training-time defense, avoids the problematic backdoor removal and the high computational cost associated with those reactive post-training methods. We empirically evaluate DIFT on various CL algorithms against backdoor attack. Experimental results demonstrate that our method exhibits promising defense effectiveness while maintaining model's clean data accuracy. Yulin Jin, Qingqing Ye 0001, Zhibiao Guo, Kun Fang 0004, Ruochen Du, Yingnan Zhao 0002, Haibo Hu 0001 |
AAAI | 2 |
| 2026 | ShakeSense: An Electrotactile System to Simulate Shaking a Container with Fluid ContentsabstractShaking a cup of wine or other fluids in virtual environments is engaging but has been limited by challenges in delivering real-time haptic feedback for liquid collisions. ShakeSense is a haptic rendering system that integrates electrotactile stimulation with physics-based simulation to deliver immersive feedback for liquid dynamics in handheld containers. It employs a high-density electrode array to deliver dynamic tactile sensations, conveying friction and pressure changes on the user’s fingerpad. A dedicated end-to-end pipeline computes fingerpad forces from liquid-container-finger interactions, ensuring feedback aligns with natural fluid movement. Two studies evaluated ShakeSense’s performance and user perception. Study 1 showed that electrotactile patterns were distinguishable across directions, and synchronizing container movement with stimulation enhanced perceived force changes. Study 2 demonstrated that ShakeSense effectively simulated liquid motion, capturing multidimensional, coordinated interactions, and outperformed conventional Center-of-Mass approaches. Overall, ShakeSense provides clear, fine-grained tactile feedback for fluid interactions. Zhenxuan He, Yulin Jin, Yiyang Luo, Shengsheng Jiang, Ruikai Liang, Xiaowei He 0004, Hongnan Lin, Teng Han, Feng Tian 0001 |
CHI | 2 |
| 2026 | ElectroGrasp: Electrotactile Aids for Visually Impaired Individuals in Anticipatory Planning and Control of GraspabstractGrasping objects typically relies on visual input to pre-shape the hand and plan movement trajectories, a process often disrupted in visually impaired (VI) individuals. ElectroGrasp is a wearable electro-tactile system that delivers anticipatory proprioceptive and tactile information through three complementary modalities: Grasping Orientation, Size, and Shape. This system dynamically conveys spatial features-thereby enhancing anticipatory grasp planning and control through tactile perception. Three experiments were conducted to evaluate ElectroGrasp. The first examined tactile pattern discriminability, size perception thresholds, and the reliability of orientation encoding. The second assessed learning time with ElectroGrasp and its effectiveness in supporting spatial representation, demonstrating accurate spatial perception of objects from electrotactile input. The third compared grasp aperture under audio versus electrotactile cues, revealing that ElectroGrasp reduced hand overshoot and regrasp corrections. Overall, the results demonstrate that ElectroGrasp provides efficient tactile information, enables improved anticipatory grasp planning comparable to visual cues, and offers a novel assistive solution for VI users. Hechuan Zhang, Rufei Song, Ruoyan Liu, Shengsheng Jiang, Xiaohui Tan, Tianren Luo, Yulin Jin, Hongnan Lin, Teng Han, Feng Tian 0001 |
CHI | 7 |
| 2026 | StoreSketcher: An Interactive Framework for Planning Commercial Retail Scene LayoutabstractRetail space planning, arranging store sections and product placements to optimize customer flow and stimulate purchases helps retailers to increase sales and enhances the customer shopping experience. It can be challenging for retailers to arrange numerous products within limited shelf space. This paper introduces StoreSketcher, an interactive tool that assists retailers in planning retail layouts efficiently at macro and micro levels by providing intelligent suggestions. We have extracted commercial relationships between products and categories, built spatial rules for commercial objects, and developed an interactive framework for synthesizing retail layouts. When the user points to shelf space in the layout, StoreSketcher evaluates the spatial significance of the location and its commercial relation to the surrounding context to present appropriate suggestions. Quantitative experiments demonstrate that StoreSketcher significantly assists in planning well-organized retail layouts. The suggestions provided by StoreSketcher not only boost cross-selling and impulse purchasing for retailers, but also enhance product findability for customers. Hou Tam, Shao-Kui Zhang, Yulin Jin, Hanxi Zhu, Song-Hai Zhang |
Comput. Vis. Media | 3 |
| 2025 | Frequency SSL: An Explainable Method for Diffusion Facial Forgery DetectionabstractThis paper takes account of the fact that there is a lack of consideration for facial forgery detection in images generated by diffusion model among existing AI-generated images detection methods applied to generalized scenarios. Research has consistently illuminated that the disparity in data distribution between real and forgery images manifests prominently within the high-frequency components of an image. Thus, this paper introduces a novel method for diffusion facial forgery detection based on frequency-aware self-supervised learning (FreSSL), which not only enhances the discrimination capability across diverse diffusion methods but also yields a pixel-level insight into the subtle distinctions between real and diffusion spoof facial images. The proposed method starts from partitioning the facial image into high-frequency components (HFC) and low-frequency components (LFC) via Fast Fourier Transformation (FFT). Subsequently, it presents an encoder-decoder architecture trained solely on authentic facial images to reconstruct the high-frequency components from their low-frequency counterparts. Exploiting the divergence between the original HFC and the high-frequency reconstruction (HFR), we subtract them to get high-frequency difference (HFD) as the classifier input. Compared with several forgery detection methods, extensive experiments involving several diffusion models demonstrate the effectiveness of our proposed method, which not only achieves state-of-the-art detection accuracy but also demonstrates remarkable generalization performance across diverse subsets of facial forgery imagery. Chunbo Zhu, Yuanye Mo, Yulin Jin |
IJCNN | 4 |
| 2025 | Augmented Reality-Enabled Interaction of Intrinsic Global Physical Information for Aircraft AssemblyabstractEnhanced transparency of the assembly process is critical for intelligent aerospace manufacturing. While augmented reality (AR) technology provides valuable support for assisted assembly, existing systems are limited in their ability to deliver real-time, intuitive visualization of global, multi-dimensional physical states—such as stress distribution, dynamic strain fields, and multi-component coupled deformations. To overcome these challenges, this study proposes an AR-assisted system for real-time global physical information interaction and multi-dimensional assembly guidance. By integrating multi-view visual measurement with finite element analysis, and leveraging model order reduction and optimal sensor placement strategies, the system achieves real-time reconstruction of global displacement, stress, and strain fields. These reconstructed physical fields are overlaid onto the actual assembly environment through AR, establishing a closed-loop "measurement–perception–feedback" interaction. Experiments on aerospace composite thin-walled structures validate the system’s capability for real-time perception and interactive visualization. Compared with conventional AR systems featuring unidirectional data flow, the proposed approach significantly enhances process transparency and controllability, offering a new paradigm for intelligent assembly. Yulin Jin, Jiacheng Cui, Yongkang Lu, Yang Zhang 0011 |
INDIN | 2 |
| 2025 | Fault diagnosis via multi-sensor fusion with auxiliary contrastive learning and phased fine-tuningabstractTypically, deep learning-based fault diagnosis models fail to fully utilize the potential information in large amounts of normal state data and encounter difficulties when learning from limited fault samples. To address these challenges, this study proposes an auxiliary contrastive learning framework designed for multi-sensor data. The framework incorporates auxiliary classifiers after each sensor-specific branch to enhance feature representation, and enables model pretraining using only normal condition data. In addition, a phased fine-tuning strategy is developed, which combines full-model fine-tuning with lightweight adapter tuning to improve the adaptability of the fine-tuning process. A novel multi-sensor data augmentation technique is also introduced to enrich the contrastive learning tasks by generating structurally diverse negative samples. By enabling the effective utilization of normal condition data in model training, the proposed framework offers a new perspective for fault diagnosis applications. Experimental results on three benchmark datasets demonstrate that the proposed method significantly improves the generalization capability of the pre-trained model. Furthermore, the phased fine-tuning strategy exhibits high adaptability to the target tasks. Compared to other data fusion methods, the proposed auxiliary contrastive learning framework achieves notable performance advantages. Yulin Jin, Xiaochuan Luo, Huaxi Yulin Zhang |
Eng. Appl. Artif. Intell. | 1 |
| 2025 | Purifier$^{+}$: Plug-and-Play Backdoor Mitigation for Pre-Trained Models via Activation AlignmentabstractPre-trained models are extensively embraced in deep learning, facilitating efficient fine-tuning for downstream user-specific tasks and yielding substantial computational savings. However, backdoor attacks present a significant security threat to downstream models constructed on corrupted pre-trained models, necessitating the implementation of effective countermeasures to mitigate this threat prior to deploying the models in safety-critical applications. This paper introducesPurifierand its advanced versionPurifier$^{+}$, the former of which mitigates backdoors in pre-trained models by aligning anomaly activation to normal activation, and the latter builds on this by making importance rating about activation patterns, boosting important activation patterns and suppressing unimportant activation patterns.PurifierandPurifier$^{+}$draw inspiration from the observation that anomaly activation patterns for backdoor triggers manifest across various perspectives such as channel-wise, cube-wise, and feature-wise, each exhibiting distinct levels of granularity. Crucially, the choice of alignment granularity plays a pivotal role in ensuring robustness and accuracy. In addressing this challenge,PurifierandPurifier$^{+}$demonstrate the ability to effectively thwart various categories of backdoor triggers devoid of requiring prior information about the specific backdoor attacks. Additionally, it offers a convenient and flexible deployment feature, namely, plug-and-play capability. The comprehensive experimental results demonstrate thatPurifierandPurifier$^{+}$outperform current methodologies regarding defense efficacy and accuracy in model inference with uncontaminated samples when subjected to a series of State-of-the-Art mainstream attacks. Xiaoyu Zhang 0010, Yulin Jin, Haoyu Tong, Jian Lou 0001, Kai Wu 0003, Xiaofeng Chen 0001 |
IEEE Trans. Multim. | 2 |
| 2024 | Balancing Generalization and Robustness in Adversarial Training via Steering through Clean and Adversarial Gradient Directions
Haoyu Tong, Xiaoyu Zhang 0010, Yulin Jin, Jian Lou 0001, Kai Wu 0003, Xiaofeng Chen 0001 |
ACM Multimedia | 3 |
| 2023 | Explaining Adversarial Robustness of Neural Networks from Clustering Effect PerspectiveabstractAdversarial training (AT) is the most commonly used mechanism to improve the robustness of deep neural networks. Recently, a novel adversarial attack against intermediate layers exploits the extra fragility of adversarially trained networks to output incorrect predictions. The result implies the insufficiency in the searching space of the adversarial perturbation in adversarial training. To straighten out the reason for the effectiveness of the intermediate-layer attack, we interpret the forward propagation as the Clustering Effect, characterizing that the intermediate-layer representations of neural networks for samples i.i.d. to the training set with the same label are similar, and we theoretically prove the existence of Clustering Effect by corresponding Information Bottleneck Theory. We afterward observe that the intermediate-layer attack disobeys the clustering effect of the AT-trained model. Inspired by these significant observations, we propose a regularization method to extend the perturbation searching space during training, named sufficient adversarial training (SAT). We give a proven robustness bound of neural networks through rigorous mathematical proof. The experimental evaluations manifest the superiority of SAT over other state-of-the-art AT mechanisms in defending against adversarial attacks against both output and intermediate layers. Our code and Appendix can be found at https://github.com/clustering-effect/SAT. Yulin Jin, Xiaoyu Zhang 0010, Jian Lou 0001, Zilong Wang 0001, Xiaofeng Chen 0001 |
ICCV | 1 |
| 2023 | ACQ: Few-shot Backdoor Defense via Activation Clipping and QuantizingabstractIn recent years, deep neural networks(DNNs) have relied on an increasing amount of training samples as the premise of the deployment for real-world scenarios. This gives rise to backdoor attacks, where a small fraction of poisoned data is inserted into the training dataset to manipulate the predictions of DNNs when presented with backdoor inputs. Backdoor attacks pose serious security threats during the prediction stage of DNNs. As a result, there is growing research attention to defend against backdoor attacks. This paper proposes Activation Clipping and Quantizing (ACQ), a novel backdoor elimination module via transforming the intermediate-layer output of DNNs during forward propagation by embedding Clipper and Quantizer into the backdoored DNNs. ACQ is motivated by the observation that the backdoored DNNs always output abnormally large or small intermediate-layer activations when presented with backdoored samples, eventually leading to the malicious prediction of backdoored DNNs. ACQ modifies backdoored DNNs to keep the intermediate-layer activations in a proper domain and align the forward propagation of backdoored samples with that of clean samples. Besides, we highlight that ACQ has the ability to eliminate the backdoor of DNNs in few-shot even zero-shot scenarios, which requires much fewer or even no clean samples for the backdoor elimination stage than existing approaches. Experiments demonstrate the effectiveness and robustness of ACQ against various attacks and tasks compared to existing methods. Our code and Appendix can be found in https://github.com/Backdoor-defense/ACQ Yulin Jin, Xiaoyu Zhang 0010, Jian Lou 0001, Xiaofeng Chen 0001 |
ACM Multimedia | 1 |
| 2022 | Purifier: Plug-and-play Backdoor Mitigation for Pre-trained Models Via Anomaly Activation SuppressionabstractPre-trained models have been widely adopted in deep learning development, benefiting the fine-tuning of downstream user-specific tasks with enormous computation saving. However, backdoor attacks pose severe security threat to the subsequent models built upon compromised pre-trained models, which call for effective countermeasures to mitigate the backdoor threat before deploying the victim models to safety-critical applications. This paper proposesPurifier : a novel backdoor mitigation framework for pre-trained models via suppressing anomaly activation.Purifier is motivated by the observation that, for backdoor triggers, anomaly activation patterns exist across different perspectives (e.g., channel-wise, cube-wise, and feature-wise), featuring different degrees of granularity. More importantly, choosing to suppress at the right granularity is vital to robustness and accuracy. To this end,Purifier is capable of defending against diverse types of backdoor triggers without any prior knowledge of the backdoor attacks, meanwhile featuring a convenient and flexible characteristic during deployment, i.e., plug-and-play-able. The extensive experimental results show, against a series of state-of-the-art mainstream attacks, thatPurifier performs better in terms of both defense effectiveness and model inference accuracy on clean examples than the state-of-the-art methods. Our code and Appendix can be found in \urlgithub.com/RUIYUN-ML/Purifier. Xiaoyu Zhang 0010, Yulin Jin, Tao Wang 0036, Jian Lou 0001, Xiaofeng Chen 0001 |
ACM Multimedia | 2 |