Haitian Zhang

dblp:334/4298 · DBLP profile ↗
← Back
4ranked-venue papers
3as first author
4since 2021 · last 2025
0009-0005-9151-7543ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
1 paper
Image recognition and object detection · 61% 3D vision · 30% Autonomous driving · 9%
Network and information security
1 paper
Security and privacy of machine learning · 100%

Topics — the 6 heaviest of 6, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Computer vision › Image recognition and object detection › object detection
class-agnostic object detection
0.912025
Detecting Every Object From Events · IEEE Trans. Pattern Anal. Mach. Intell. 2025
Computer vision › 3D vision
event-based vision
0.912025
Detecting Every Object From Events · IEEE Trans. Pattern Anal. Mach. Intell. 2025
Computer vision › Image recognition and object detection
object detection
0.912025
Detecting Every Object From Events · IEEE Trans. Pattern Anal. Mach. Intell. 2025
Security and privacy of machine learning › adversarial attack
backdoor attack
0.712023
Categorical Inference Poisoning: Verifiable Defense Against Black-Box DNN Model Stealing Without Constraining Surrogate Data and Query Times · IEEE Trans. Inf. Forensics Secur. 2023
Security and privacy of machine learning › model stealing
model stealing defense
0.712023
Categorical Inference Poisoning: Verifiable Defense Against Black-Box DNN Model Stealing Without Constraining Surrogate Data and Query Times · IEEE Trans. Inf. Forensics Secur. 2023
Robotics › Autonomous driving
perception
0.312025
Detecting Every Object From Events · IEEE Trans. Pattern Anal. Mach. Intell. 2025

Methods — techniques the papers use, named apart from their topics

recurrent vision transformer · 0.9disentangled objectness head · 0.9reliability score · 0.7energy score OOD detection · 0.7categorical inference poisoning · 0.7
YearPublicationVenuePosition
2025 Machine Learning and Derivative-Free Optimization for PID Tuning: Case Study of Improved Black Liquor Concentration Control
abstract
Proportional-Integral-Derivative (PID) controllers are instrumental in managing industrial processes. Their effectiveness hinges on the precision of their tuned parameters. Consequently, it becomes essential to monitor their performance frequently and re-tune them regularly to ensure optimal operation. However, conventional tuning methods require significant effort and expertise. This research tackles this challenge by using historical data to construct machine learning (ML) models, coupled with optimization algorithms, to streamline PID tuning. Specifically, we propose integrating an Explainable Boosting Machine (EBM) as an ML model and harnessing Bayesian Optimization (BO) within a comprehensive PID tuning framework. EBM stands out for its ease of construction and accuracy. The synergistic combination of EBM and BO yields an effective solution, as demonstrated through a case study involving black liquor concentration control in a multiple-effect evaporator system within kraft pulp manufacturing.
Mohamed El-Koujok, Haitian Zhang, Hakim Ghezzaz, Mouloud Amazouz, Ali Elkamel
CoDIT2
2025 Detecting Every Object From Events
abstract
Object detection is critical in autonomous driving, and it is more practical yet challenging to localize objects of unknown categories: an endeavour known as Class-Agnostic Object Detection (CAOD). Existing studies on CAOD predominantly rely on RGB cameras, but these frame-based sensors usually have high latency and limited dynamic range, leading to safety risks under extreme conditions like fast-moving objects, overexposure, and darkness. In this study, we turn to the event-based vision, featured by its sub-millisecond latency and high dynamic range, for robust CAOD. We propose Detecting Every Object in Events (DEOE), an approach aimed at achieving high-speed, class-agnostic object detection in event-based vision. Built upon the fast event-based backbone: recurrent vision transformer, we jointly consider the spatial and temporal consistencies to identify potential objects. The discovered potential objects are assimilated as soft positive samples to avoid being suppressed as backgrounds. Moreover, we introduce a disentangled objectness head to separate the foreground-background classification and novel object discovery tasks, enhancing the model's generalization in localizing novel objects while maintaining a strong ability to filter out the background. Extensive experiments confirm the superiority of our proposed DEOE in both open-set and closed-set settings, outperforming strong baseline methods.
Haitian Zhang, Chang Xu 0027, Xinya Wang, Bingde Liu, Guang Hua 0001, Lei Yu 0006, Wen Yang 0001
IEEE Trans. Pattern Anal. Mach. Intell.1
2024 Poisoning-Free Defense Against Black-Box Model Extraction
abstract
Recent research has shown that an adversary can use a surrogate model to steal the functionality of a target deep learning model even under the black-box condition and without data curation, while the existing defense mainly relies on API poisoning to disturb the surrogate training. Unfortunately, due to poisoning, the defense is achieved at the price of fidelity loss, sacrificing the interests of honest users. To solve this problem, we propose an Adversarial Fine-Tuning (AdvFT) framework, incorporating the generative adversarial network (GAN) structure that disturbs the feature representations of out-of-distribution (OOD) queries while preserving those of in-distribution (ID) ones, circumventing the need for OOD sample collection and API poisoning. Extensive experiments verify the effectiveness of the proposed framework. Code is available at github.com/Hatins/AdvFT.
Haitian Zhang, Guang Hua 0001, Wen Yang 0001
ICASSP1
2023 Categorical Inference Poisoning: Verifiable Defense Against Black-Box DNN Model Stealing Without Constraining Surrogate Data and Query Times
abstract
Deep Neural Network (DNN) models have offered powerful solutions for a wide range of tasks, but the cost to develop such models is nontrivial, which calls for effective model protection. Although black-box distribution can mitigate some threats, model functionality can still be stolen via black-box surrogate attacks. Recent studies have shown that surrogate attacks can be launched in several ways, while the existing defense methods commonly assume attackers with insufficient in-distribution (ID) data and restricted attacking strategies. In this paper, we relax these constraints and assume a practical threat model in which the adversary not only has sufficient ID data and query times but also can adjust the surrogate training data labeled by the victim model. Then, we propose a two-step categorical inference poisoning (CIP) framework, featuring both poisoning for performance degradation (PPD) and poisoning for backdooring (PBD). In the first poisoning step, incoming queries are classified into ID and (out-of-distribution) OOD ones using an energy score (ES) based OOD detector, and the latter are further classified into high ES and low ES ones, which are subsequently passed to a strong and a weak PPD process, respectively. In the second poisoning step, difficult ID queries are detected by a proposed reliability score (RS) measurement and are passed to PBD. In doing so, the first step OOD poisoning leads to substantial performance degradation in surrogate models, the second step ID poisoning further embeds backdoors in them, while both can preserve model fidelity. Extensive experiments confirm that CIP can not only achieve promising performance against state-of-the-art black-box surrogate attacks like KnockoffNets and data-free model extraction (DFME) but also work well against stronger attacks with sufficient ID and deceptive data, better than the existing dynamic adversarial watermarking (DAWN) and deceptive perturbation defense methods. PyTorch code is available athttps://github.com/Hatins/CIP_master.git.
Haitian Zhang, Guang Hua 0001, Xinya Wang, Hao Jiang 0010, Wen Yang 0001
IEEE Trans. Inf. Forensics Secur.1