Meiwen Ding

dblp:347/5951 · DBLP profile ↗
← Back
2ranked-venue papers
1as first author
2since 2021 · last 2026
0009-0003-7897-581XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
2 papers
Trustworthy machine learning · 62% Video understanding and tracking · 19% Segmentation and scene understanding · 19%
Network and information security
1 paper
Security and privacy of machine learning · 50% Privacy and data protection · 50%

Topics — the 7 heaviest of 8, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning › robustness
adversarial attack
1.012026
Transferable Adversarial Attack on Referring Video Object Segmentation · IEEE Trans. Inf. Forensics Secur. 2026
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
1.012026
Transferable Adversarial Attack on Referring Video Object Segmentation · IEEE Trans. Inf. Forensics Secur. 2026
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial transferability
1.012026
Transferable Adversarial Attack on Referring Video Object Segmentation · IEEE Trans. Inf. Forensics Secur. 2026
Computer vision › Segmentation and scene understanding
referring image segmentation
1.012026
Transferable Adversarial Attack on Referring Video Object Segmentation · IEEE Trans. Inf. Forensics Secur. 2026
Computer vision › Video understanding and tracking
video object segmentation
1.012026
Transferable Adversarial Attack on Referring Video Object Segmentation · IEEE Trans. Inf. Forensics Secur. 2026
Privacy and data protection › privacy-preserving machine learning › privacy-preserving machine learning inference
collaborative inference privacy
0.912025
Theoretical Insights in Model Inversion Robustness and Conditional Entropy Maximization for Collaborative Inference Systems · CVPR 2025
Security and privacy of machine learning › privacy attack
model inversion attack
0.912025
Theoretical Insights in Model Inversion Robustness and Conditional Entropy Maximization for Collaborative Inference Systems · CVPR 2025

Methods — techniques the papers use, named apart from their topics

obfuscation-based defense · 1.7gaussian mixture estimation · 1.7conditional entropy maximization · 1.7inter-clip momentum · 1.0cross-prompt multimodal attack · 1.0
YearPublicationVenuePosition
2026 Transferable Adversarial Attack on Referring Video Object Segmentation
abstract
Referring video object segmentation (RVOS) is an emerging task that aims to segment the text-referred objects in the given video sequence. This capability plays a critical role in some real-world safety-critical applications such as autonomous driving. However, advanced RVOS models predominantly leverage deep neural networks that are inherently vulnerable to adversarial perturbations, which raises serious safety concerns. Although some studies have explored adversarial attacks on video object segmentation (VOS), the robustness and security of RVOS models against such attacks remain insufficiently investigated. This work thus, for the first time, comprehensively investigates the adversarial robustness of RVOS models. Distinct from other VOS tasks, RVOS is more challenging due to its multi-modal nature and high dependence on spatial-temporal information. Considering that, we propose a cross-prompt Multimodal attack with Inter-Clip Momentum (xM-ICM) to effectively mislead RVOS models under both white-box and black-box scenarios. The proposed xM jointly corrupts visual and textual embeddings and integrates a cross-prompt strategy during iterative optimization to enhance generalization across diverse linguistic queries. The ICM module harnesses the spatial-temporal dependencies across sequence clips via two momentum banks to preserve the perturbation coherence throughout the whole video and stabilize the adversarial optimization. Experimental results on three benchmarks and five prevalent RVOS models demonstrate the superior white-box attack performance and strong black-box transferability of our proposed method.
Meiwen Ding, Song Xia, Yi Yu 0011, Shuting He, Xudong Jiang 0001
IEEE Trans. Inf. Forensics Secur.1
2025 Theoretical Insights in Model Inversion Robustness and Conditional Entropy Maximization for Collaborative Inference Systems
abstract
By locally encoding raw data into intermediate features, collaborative inference enables end users to leverage powerful deep learning models without exposure of sensitive raw data to cloud servers. However, recent studies have revealed that these intermediate features may not sufficiently preserve privacy, as information can be leaked and raw data can be reconstructed via model inversion attacks (MIAs). Obfuscation-based methods, such as noise corruption, adversarial representation learning, and information filters, enhance the inversion robustness by obfuscating the task-irrelevant redundancy empirically. However, methods for quantifying such redundancy remain elusive, and the explicit mathematical relation between this redundancy minimization and inversion robustness enhancement has not yet been established. To address that, this work first theoretically proves that the conditional entropy of inputs given intermediate features provides a guaranteed lower bound on the reconstruction mean square error (MSE) under any MIA. Then, we derive a differentiable and solvable measure for bounding this conditional entropy based on the Gaussian mixture estimation and propose a conditional entropy maximization (CEM) algorithm to enhance the inversion robustness. Experimental results on four datasets demonstrate the effectiveness and adaptability of our proposed CEM; without compromising feature utility and computing efficiency, plugging the proposed CEM into obfuscation-based defense mechanisms consistently boosts their inversion robustness, achieving average gains ranging from 12.9% to 48.2%. Code is available at https://github.com/xiasong0501/CEM.
Song Xia, Yi Yu 0011, Wenhan Yang, Meiwen Ding, Zhuo Chen 0006, Ling-Yu Duan, Alex Chichung Kot, Xudong Jiang 0001
CVPR4