Luyang Ying

dblp:401/2458 · DBLP profile ↗
← Back
3ranked-venue papers
1as first author
3since 2021 · last 2025
0009-0002-3539-4217ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
2 papers
Security and privacy of machine learning · 60% Digital forensics and information hiding · 20% Cryptographic primitives and cryptanalysis · 20%
Artificial intelligence
1 paper
Generative modeling · 100%

Topics — the 6 heaviest of 6, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Security and privacy of machine learning
adversarial attack
1.722025
Generative Collision Attack on Deep Image Hashing · IEEE Trans. Inf. Forensics Secur. 2025
AngleRoCL: Angle-Robust Concept Learning for Physically View-Invariant Adversarial Patches · NeurIPS 2025
Machine learning › Generative modeling
diffusion model
0.912025
AngleRoCL: Angle-Robust Concept Learning for Physically View-Invariant Adversarial Patches · NeurIPS 2025
Machine learning › Generative modeling › diffusion model › text-to-image generation
text-to-image diffusion model
0.912025
AngleRoCL: Angle-Robust Concept Learning for Physically View-Invariant Adversarial Patches · NeurIPS 2025
Security and privacy of machine learning › adversarial attack › physical adversarial attack
adversarial patch
0.912025
AngleRoCL: Angle-Robust Concept Learning for Physically View-Invariant Adversarial Patches · NeurIPS 2025
Cryptographic primitives and cryptanalysis › hash function cryptanalysis
collision attack
0.912025
Generative Collision Attack on Deep Image Hashing · IEEE Trans. Inf. Forensics Secur. 2025
Digital forensics and information hiding
image hashing
0.912025
Generative Collision Attack on Deep Image Hashing · IEEE Trans. Inf. Forensics Secur. 2025

Methods — techniques the papers use, named apart from their topics

text embedding optimization · 1.7concept learning · 1.7hash-to-noise network · 0.9generative adversarial network · 0.9
YearPublicationVenuePosition
2025 AngleRoCL: Angle-Robust Concept Learning for Physically View-Invariant Adversarial Patches
abstract
Cutting-edge works have demonstrated that text-to-image (T2I) diffusion models can generate adversarial patches that mislead state-of-the-art object detectors in the physical world, revealing detectors' vulnerabilities and risks. However, these methods neglect the T2I patches' attack effectiveness when observed from different views in the physical world (i.e., angle robustness of the T2I adversarial patches). In this paper, we study the angle robustness of T2I adversarial patches comprehensively, revealing their angle-robust issues, demonstrating that texts affect the angle robustness of generated patches significantly, and task-specific linguistic instructions fail to enhance the angle robustness. Motivated by the studies, we introduce Angle-Robust Concept Learning (AngleRoCL), a simple and flexible approach that learns a generalizable concept (i.e., text embeddings in implementation) representing the capability of generating angle-robust patches. The learned concept can be incorporated into textual prompts and guides T2I models to generate patches with their attack effectiveness inherently resistant to viewpoint variations. Through extensive simulation and physical-world experiments on five SOTA detectors across multiple views, we demonstrate that AngleRoCL significantly enhances the angle robustness of T2I adversarial patches compared to baseline methods. Our patches maintain high attack success rates even under challenging viewing conditions, with over 50% average relative improvement in attack effectiveness across multiple angles. This research advances the understanding of physically angle-robust patches and provides insights into the relationship between textual concepts and physical properties in T2I-generated contents. We released our code at https://github.com/tsingqguo/anglerocl.
Wenjun Ji, Luyang Ying, Deng-Ping Fan, Yuyi Wang 0001, Ming-Ming Cheng, Ivor W. Tsang, Qing Guo 0005
NeurIPS3
2025 Inversion Attack Framework for Deep Face Hashing
Zihe Huang, Luyang Ying, Chuan Qin 0001, Heng Yao 0001, Xinpeng Zhang 0001
IEEE Signal Process. Lett.2
2025 Generative Collision Attack on Deep Image Hashing
abstract
Due to the powerful feature extraction capabilities of deep neural networks (DNNs), deep image hashing has extensive applications in the fields such as image authentication, copy detection and content retrieval, making its security a critical concern. Among various security metrics, collision resistance serves as a crucial indicator of deep image hashing methods. Research on collision attacks not only reveals the potential vulnerabilities of deep image hashing but also can promote the development of more robust and secure hashing methods. In this paper, we propose a novel generative collision attack scheme, which achieves several advantages over existing attack schemes based on adversarial examples. Our scheme requires no additional perturbations added to the image, and can simultaneously generate multiple hash collision images of different classes specified by the attacker. To the best of our knowledge, this is the first generative collision attack scheme effective across various deep image hashing methods. Specifically, our attack framework consists of three parts, i.e., a Hash-to-Noise Network (HTNN), a pretrained BigGAN generator and a conditional discriminator. The designed HTNN embeds the hash code of the target image and the attacker-specified generation class information into a “noise” vector. By optimizing various hash distance loss functions between the generated and target images, this “noise” guides the generator to directly generate images that meet the collision requirement. At the same time, the discriminator ensures that the generated images are visually realistic. Extensive experimental results verify that our scheme can effectively generate multiple high-quality images with attacker-specified classes, achieving the high success rate of hash collision attack and the applicability across state-of-the-art deep hashing methods.
Luyang Ying, Cheng Xiong, Chuan Qin 0001, Xiangyang Luo 0001, Zhenxing Qian, Xinpeng Zhang 0001
IEEE Trans. Inf. Forensics Secur.1