EDBT 2026 Demo / reviewers in the wild / expert
Luyang Ying
dblp:401/2458
· DBLP profile ↗
3ranked-venue papers
1as first author
3since 2021 · last 2025
0009-0002-3539-4217ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Security and privacy of machine learning · 60% Digital forensics and information hiding · 20% Cryptographic primitives and cryptanalysis · 20% | |
| Artificial intelligence
1 paper |
Generative modeling · 100% |
Topics — the 6 heaviest of 6, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Security and privacy of machine learning
adversarial attack |
1.7 | 2 | 2025 | Generative Collision Attack on Deep Image Hashing · IEEE Trans. Inf. Forensics Secur. 2025 AngleRoCL: Angle-Robust Concept Learning for Physically View-Invariant Adversarial Patches · NeurIPS 2025 |
Machine learning › Generative modeling
diffusion model |
0.9 | 1 | 2025 | AngleRoCL: Angle-Robust Concept Learning for Physically View-Invariant Adversarial Patches · NeurIPS 2025 |
Machine learning › Generative modeling › diffusion model › text-to-image generation
text-to-image diffusion model |
0.9 | 1 | 2025 | AngleRoCL: Angle-Robust Concept Learning for Physically View-Invariant Adversarial Patches · NeurIPS 2025 |
Security and privacy of machine learning › adversarial attack › physical adversarial attack
adversarial patch |
0.9 | 1 | 2025 | AngleRoCL: Angle-Robust Concept Learning for Physically View-Invariant Adversarial Patches · NeurIPS 2025 |
Cryptographic primitives and cryptanalysis › hash function cryptanalysis
collision attack |
0.9 | 1 | 2025 | Generative Collision Attack on Deep Image Hashing · IEEE Trans. Inf. Forensics Secur. 2025 |
Digital forensics and information hiding
image hashing |
0.9 | 1 | 2025 | Generative Collision Attack on Deep Image Hashing · IEEE Trans. Inf. Forensics Secur. 2025 |
Methods — techniques the papers use, named apart from their topics
text embedding optimization · 1.7concept learning · 1.7hash-to-noise network · 0.9generative adversarial network · 0.9
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | AngleRoCL: Angle-Robust Concept Learning for Physically View-Invariant Adversarial PatchesabstractCutting-edge works have demonstrated that text-to-image (T2I) diffusion models can generate adversarial patches that mislead state-of-the-art object detectors in the physical world, revealing detectors' vulnerabilities and risks. However, these methods neglect the T2I patches' attack effectiveness when observed from different views in the physical world (i.e., angle robustness of the T2I adversarial patches). In this paper, we study the angle robustness of T2I adversarial patches comprehensively, revealing their angle-robust issues, demonstrating that texts affect the angle robustness of generated patches significantly, and task-specific linguistic instructions fail to enhance the angle robustness. Motivated by the studies, we introduce Angle-Robust Concept Learning (AngleRoCL), a simple and flexible approach that learns a generalizable concept (i.e., text embeddings in implementation) representing the capability of generating angle-robust patches. The learned concept can be incorporated into textual prompts and guides T2I models to generate patches with their attack effectiveness inherently resistant to viewpoint variations. Through extensive simulation and physical-world experiments on five SOTA detectors across multiple views, we demonstrate that AngleRoCL significantly enhances the angle robustness of T2I adversarial patches compared to baseline methods. Our patches maintain high attack success rates even under challenging viewing conditions, with over 50% average relative improvement in attack effectiveness across multiple angles. This research advances the understanding of physically angle-robust patches and provides insights into the relationship between textual concepts and physical properties in T2I-generated contents. We released our code at https://github.com/tsingqguo/anglerocl. Wenjun Ji, Luyang Ying, Deng-Ping Fan, Yuyi Wang 0001, Ming-Ming Cheng, Ivor W. Tsang, Qing Guo 0005 |
NeurIPS | 3 |
| 2025 | Inversion Attack Framework for Deep Face Hashing
Zihe Huang, Luyang Ying, Chuan Qin 0001, Heng Yao 0001, Xinpeng Zhang 0001 |
IEEE Signal Process. Lett. | 2 |
| 2025 | Generative Collision Attack on Deep Image HashingabstractDue to the powerful feature extraction capabilities of deep neural networks (DNNs), deep image hashing has extensive applications in the fields such as image authentication, copy detection and content retrieval, making its security a critical concern. Among various security metrics, collision resistance serves as a crucial indicator of deep image hashing methods. Research on collision attacks not only reveals the potential vulnerabilities of deep image hashing but also can promote the development of more robust and secure hashing methods. In this paper, we propose a novel generative collision attack scheme, which achieves several advantages over existing attack schemes based on adversarial examples. Our scheme requires no additional perturbations added to the image, and can simultaneously generate multiple hash collision images of different classes specified by the attacker. To the best of our knowledge, this is the first generative collision attack scheme effective across various deep image hashing methods. Specifically, our attack framework consists of three parts, i.e., a Hash-to-Noise Network (HTNN), a pretrained BigGAN generator and a conditional discriminator. The designed HTNN embeds the hash code of the target image and the attacker-specified generation class information into a “noise” vector. By optimizing various hash distance loss functions between the generated and target images, this “noise” guides the generator to directly generate images that meet the collision requirement. At the same time, the discriminator ensures that the generated images are visually realistic. Extensive experimental results verify that our scheme can effectively generate multiple high-quality images with attacker-specified classes, achieving the high success rate of hash collision attack and the applicability across state-of-the-art deep hashing methods. Luyang Ying, Cheng Xiong, Chuan Qin 0001, Xiangyang Luo 0001, Zhenxing Qian, Xinpeng Zhang 0001 |
IEEE Trans. Inf. Forensics Secur. | 1 |