EDBT 2026 Demo / reviewers in the wild / expert
Sipeng Shen
dblp:376/0769
· DBLP profile ↗
5ranked-venue papers
1as first author
5since 2021 · last 2026
0000-0003-0436-4736ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Universal Transferable Dual Attack on Anti-Spoofing and Recognition in Facial Security Systems
Sirun Chen, Sipeng Shen, Ziyi Liu 0009, Yueyun Shang, Dengpan Ye |
ICIC (16) | 3 |
| 2026 | DIP-Watermark: A Double Identity Protection Method Based on Robust Adversarial WatermarkabstractThe wide deployment of Face Recognition (FR) systems poses privacy risks. One countermeasure is adversarial attack, deceiving unauthorized malicious FR, but it also disrupts regular identity verification of trusted authorizers, exacerbating the potential threat of identity impersonation. To address this, we propose the first double identity protection scheme based on traceable adversarial watermarking, termed DIP-Watermark. DIP-Watermark employs a one-time watermark embedding to deceive unauthorized FR models and allows authorizers to perform identity verification by extracting the watermark. Specifically, we propose an information-guided adversarial attack against FR models. The encoder embeds an identity-specific watermark into the deep feature space of the carrier, guiding recognizable features of the image to deviate from the source identity. We further adopt a collaborative meta-optimization strategy compatible with sub-tasks, which regularizes the joint optimization direction of the encoder and decoder. This strategy enhances the representation of universal carrier features, mitigating multi-objective optimization conflicts in watermarking. Extensive experiments on two large-scale facial datasets demonstrate that DIP-Watermark achieves significant attack success rates and traceability accuracy on state-of-the-art FR models and commercial APIs. It also exhibits superior robustness against a wide range of real-world simulated distortions, outperforming existing privacy protection methods based on adversarial attacks, deep watermarking, or their simple combination. Our work potentially opens up new insights into proactive protection for FR privacy. Yunming Zhang, Dengpan Ye, Caiyun Xie, Sipeng Shen, Ziyi Liu 0009, Jiacheng Deng 0001, Yueyun Shang, Zhihong Tian 0001 |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2026 | ErasableMask: A Robust and Erasable Privacy Protection Scheme Against Black-Box Face Recognition ModelsabstractWhile face recognition (FR) models have brought remarkable convenience in face verification and identification, they also pose substantial privacy risks to the public. Existing facial privacy protection schemes usually adopt adversarial examples to disrupt face verification of FR models. However, these schemes often suffer from weak transferability against black-box FR models and permanently damage the identifiable information that cannot fulfill the requirements of authorized operations such as forensics and authentication. To address these limitations, we proposeErasableMask, a robust and erasable privacy protection scheme against black-box FR models. Specifically, via rethinking the inherent relationship between surrogate FR models, ErasableMask introduces a novel meta-auxiliary attack, which boosts black-box transferability by learning more general features in a stable and balancing optimization strategy. It also offers a perturbation erasion mechanism that supports the erasion of semantic perturbations in protected face without degrading image quality. To further improve performance, ErasableMask employs a curriculum learning strategy to mitigate optimization conflicts between adversarial attack and perturbation erasion. Extensive experiments on the CelebA-HQ and FFHQ datasets demonstrate that ErasableMask achieves the state-of-the-art performance in transferability, achieving over72%mean confidence in commercial FR systems. Moreover, ErasableMask also exhibits outstanding perturbation erasion performance, achieving over90%erasion success rate. Sipeng Shen, Yunming Zhang, Dengpan Ye, Xiuwen Shi, Yueyun Shang, Zhihong Tian 0001 |
IEEE Trans. Multim. | 1 |
| 2025 | Three-in-One: Robust Enhanced Universal Transferable Anti-Facial Retrieval in Online Social NetworksabstractDeep hash-based retrieval techniques are widely used in facial retrieval systems to improve the efficiency of facial matching. However, it also carries the danger of exposing private information. Deep hash models are easily influenced by adversarial examples, which can be leveraged to protect private images from malicious retrieval. The existing adversarial example methods against deep hash models focus on universality and transferability, lacking the research on its robustness in online social networks (OSNs), which leads to their failure in anti-retrieval after post-processing. Therefore, we provide the first in-depth discussion on robustness in universal transferable anti-facial retrieval and propose Three-in-One Adversarial Perturbation (TOAP). Specifically, we construct a local and global Compression Generator (CG) to simulate complex post-processing scenarios, which can be used to mitigate perturbation. Then, we propose robust optimization objectives based on the discovery of the variation patterns of model’s distribution after post-processing, and generate adversarial examples using these objectives and meta-learning. Finally, we iteratively optimize perturbation by alternately generating adversarial examples and fine-tuning the CG, balancing the performance of perturbation while enhancing CG’s ability to mitigate them. Numerous experiments demonstrate that, in addition to its advantages in universality and transferability, TOAP significantly outperforms current state-of-the-art methods in multiple robustness metrics. It further improves universality and transferability by 5% to 28%, and achieves up to about 33% significant improvement in several simulated post-processing scenarios as well as mainstream OSNs, demonstrating that TOAP can effectively protect private images from malicious retrieval in real-world scenarios. Yunna Lv, Dengpan Ye, Caiyun Xie, Jiacheng Deng 0001, Yiheng He, Sipeng Shen |
IEEE Trans. Inf. Forensics Secur. | 7 |
| 2025 | StyleMark: Robust Style Watermarking for Artworks Against Black-Box Zero-Shot Style TransferabstractZero-shot style transfer(ZSST) enables the rendering of real-world natural images into the painting styles of arbitrary artworks without requiring fine-tuning on unseen artistic styles. This low-cost and efficient approach to artistic recreation promotes the dissemination and communication of art. However, misuse of unauthorized artistic style images for ZSST may infringe on the copyrights of artists. One countermeasure is robust watermarking, which tracks image propagation by embedding copyright watermarks into carriers. Unfortunately, the stylized image generated by ZSST lose the structural and semantic information of the original style image, hindering end-to-end robust tracking by watermarks. To fill this gap, we propose StyleMark, the first robust watermarking method for black-box ZSST, which can be seamlessly applied to artistic style images achieving precise attribution of artistic styles after ZSST, without compromising the social usability of artworks. Specifically, we propose a new style watermark network that adjusts the mean activations of style features through multi-scale watermark embedding, thereby planting watermark traces into the shared style feature space of style images. Furthermore, we design a distribution squeeze loss, which constrain content statistical feature distortion, forcing the reconstruction network to focus on integrating style features with watermarks, thus optimizing the intrinsic watermark distribution. Finally, based on solid end-to-end training, StyleMark mitigates the optimization conflict between robustness and watermark invisibility through decoder fine-tuning under random noise. Experimental results demonstrate that StyleMark exhibits significant robustness against black-box ZSST and common pixel-level distortions, maintains high watermark decoding accuracy under complex multi-stage processing scenarios, and securely defending against malicious adaptive attacks. Yunming Zhang, Dengpan Ye, Sipeng Shen, Caiyun Xie |
IEEE Trans. Inf. Forensics Secur. | 3 |