EDBT 2026 Demo / reviewers in the wild / expert
Han Cao 0004
dblp:36/1565-4
· DBLP profile ↗
8ranked-venue papers
3as first author
8since 2021 · last 2027
0000-0003-3985-0267ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Security and privacy · 3 · 2 first-author · 3 since 2021Computer networks · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2027 | Robust multimodal sentiment analysis via entropy-constrained cross-attention with information bottleneck-based recovery
Rong Geng 0001, Qindong Sun, Wei Teng, Han Cao 0004, Xiaoxiong Wang, Yimin Qiao |
Expert Syst. Appl. | 4 |
| 2026 | RES-PDF: A random, ensemble, and simultaneous purification-detection framework for adversarial example mitigation
Rui Yang 0032, Qindong Sun, Han Cao 0004, Chao Shen 0001 |
Neurocomputing | 3 |
| 2026 | FeatureTrojan: Boosting stealthy and steady backdoor attacks with feature poisoning and fine-tuning injection
Rui Yang 0032, Qindong Sun, Han Cao 0004, Chao Shen 0001 |
Neural Networks | 3 |
| 2025 | Decision attribution and local extremum-guided black-box adversarial attack with adjustable sparsity and discreteness
Han Cao 0004, Qindong Sun, Rong Geng 0001, Xiaoxiong Wang, Rui Yang 0032 |
J. Inf. Secur. Appl. | 1 |
| 2025 | Subspectrum mixup-based adversarial attack and evading defenses by structure-enhanced gradient purificationabstractTransferable adversarial attacks against deep neural networks (DNNs) have attracted significant attention. Attackers can use adversarial examples crafted on substitute models to attack unknown target models, highlighting the importance of boosting transferability. However, the transferability of adversarial examples produced by current methods remains relatively weak. In this paper, we first propose an iterative attack based on frequency subspectrum mixup input transformation (FSMA), considering the sensitivity difference of model decision to different frequency components. Specifically, we evenly divide the discrete cosine transform spectra of noisy original image and auxiliary image into four disjoint subspectra respectively, and perform a mixup on each pair of subspectra to obtain diversified inputs to stabilize the perturbation update direction. Secondly, given the different noise phenomena in gradients of normally trained models and defenses, and the resulting gradient structure ambiguity, a structure-enhanced gradient purification strategy (SEGP) is proposed. By narrowing the difference between normal gradient and defense gradient, the success rate of adversarial examples in evading defenses is improved. We use convolutional neural network (CNN) and Transformer-based image classifiers as substitute models to craft adversarial examples. Plentiful experiments on ImageNet-compatible dataset prove the effectiveness of the proposed FSMA and SEGP. The latter can be combined with other attacks involving multi-sample average gradient processes to improve their success rate in breaking defenses. We also conduct a quantitative analysis of subspectrum mixup, illustrating the effectiveness of performing mixup on all subspectra. Our code is available at https://github.com/Rhiannon-lucky/FSMA . Han Cao 0004, Qindong Sun, Rong Geng 0001, Xiaoxiong Wang |
Knowl. Based Syst. | 1 |
| 2025 | 1+1>2: A Dual-Function Defense Framework for Adversarial Example MitigationabstractCurrent state-of-the-art plug-and-play countermeasures for mitigating adversarial examples (i.e., purification and detection) exhibit several fatal limitations, impeding their deployment in safety-critical real-world applications. These limitations include susceptibility to adaptive attacks, adverse impact on benign samples, high time consumption for conducting a complete defense cycle, etc. To bridge the gap, developing more advanced plug-and-play countermeasures is urgently needed to safeguard these applications. Specifically, this paper first proposes a novel method named Gaussian-augmented GAN-based Adversarial Purification (GA-GAP). Unlike previous methods, GA-GAP enhances the density of the training data in low-robustness regions by using random Gaussian noise. Moreover, GA-GAP incorporates a pre-trained deep learning classifier into the training architecture and integrates its classification loss into the training loss function. Then, following the development of GA-GAP, this paper innovatively proposes a dual-function defense framework named Adversarial Detection on Purification (ADoP) to mitigate adversarial examples further. In ADoP, purification and detection complement each other, achieving the effect of$\mathbf {1+1\gt 2}$, which can more efficiently avoid adaptive attacks. Extensive experiments on ImageNet demonstrate that ADoP outperforms other countermeasures in multiple aspects. These aspects include superior generalization capability in purifying and detecting various adversarial examples, less adverse impact on benign samples, and practical time consumption for conducting a complete defense cycle. Rui Yang 0032, Qindong Sun, Han Cao 0004, Chao Shen 0001, Jiaming Cai, Dongzhu Rong |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2024 | Efficient History-Driven Adversarial Perturbation Distribution Learning in Low Frequency DomainabstractThe existence of adversarial image makes us have to doubt the credibility of artificial intelligence system. Attackers can use carefully processed adversarial images to carry out a variety of attacks. Inspired by the theory of image compressed sensing, this paper proposes a new black-box attack, \(\mathcal {N}\text{-HSA}_{LF}\) . It uses covariance matrix adaptive evolution strategy (CMA-ES) to learn the distribution of adversarial perturbation in low frequency domain, reducing the dimensionality of solution space. And sep-CMA-ES is used to set the covariance matrix as a diagonal matrix, which further reduces the dimensions that need to be updated for the covariance matrix of multivariate Gaussian distribution learned in attacks, thereby reducing the computational cost of attack. And on this basis, we propose history-driven mean update and current optimal solution-guided improvement strategies to avoid the evolution of distribution to a worse direction. The experimental results show that the proposed \(\mathcal {N}\text{-HSA}_{LF}\) can achieve a higher attack success rate with fewer queries on attacking both CNN-based and transformer-based target models under \(L_2\) -norm and \(L_\infty\) -norm constraints of perturbation. We also conduct an ablation study and the results show that the proposed improved strategies can effectively reduce the number of visits to the target model when making adversarial examples for hard examples. In addition, our attack is able to make the integrated defense strategy of GRIP-GAN and noise-embedded training ineffective to a certain extent. Han Cao 0004, Qindong Sun, Rong Geng 0001, Xiaoxiong Wang |
ACM Trans. Priv. Secur. | 1 |
| 2021 | Deep Learning Based Customer Preferences Analysis in Industry 4.0 EnvironmentabstractAbstract Customer preferences analysis and modelling using deep learning in edge computing environment are critical to enhance customer relationship management that focus on a dynamically changing market place. Existing forecasting methods work well with often seen and linear demand patterns but become less accurate with intermittent demands in the catering industry. In this paper, we introduce a throughput deep learning model for both short-term and long-term demands forecasting aimed at allowing catering businesses to be highly efficient and avoid wastage. Moreover, detailed data collected from a business online booking system in the past three years have been used to train and verify the proposed model. Meanwhile, we carefully analyzed the seasonal conditions as well as past local or national events (event analysis) that could have had critical impact on the sales. The results are compared with the best performing forecast methods Xgboost and autoregressive moving average model (ARMA), and they suggest that the proposed method significantly improves demand forecasting accuracy (up to 80%) for dishes demand along with reduction in associated costs and labor allocation. Qindong Sun, Shanshan Zhao 0002, Han Cao 0004, Shancang Li |
Mob. Networks Appl. | 4 |