Xiao Zhang 0016

dblp:49/4478-16 · DBLP profile ↗
← Back
17ranked-venue papers
7as first author
7since 2021 · last 2025
0009-0008-1837-7670ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 14 · 7 first-author · 4 since 2021Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
10 papers
Trustworthy machine learning · 60% Learning theory · 14% Optimization for machine learning · 10%
Network and information security
3 papers
Privacy and data protection · 53% Security and privacy of machine learning · 47%
Theoretical computer science
3 papers
Mathematical optimization · 67% Information theory · 20% Algorithms and data structures · 6%

Topics — the 30 heaviest of 33, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning
robustness
1.842022
Understanding Intrinsic Robustness Using Label Uncertainty · ICLR 2022
Learning Adversarially Robust Representations via Worst-Case Mutual Information Maximization · ICML 2020
Empirically Measuring Concentration: Fundamental Limits on Intrinsic Robustness · NeurIPS 2019
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
1.732025
Provably Cost-Sensitive Adversarial Defense via Randomized Smoothing · ICML 2025
Learning Adversarially Robust Representations via Worst-Case Mutual Information Maximization · ICML 2020
Cost-Sensitive Robustness against Adversarial Examples · ICLR (Poster) 2019
Machine learning › Trustworthy machine learning › robustness
certified robustness
0.912025
Provably Cost-Sensitive Adversarial Defense via Randomized Smoothing · ICML 2025
Machine learning › Trustworthy machine learning › robustness › certified robustness
randomized smoothing
0.912025
Provably Cost-Sensitive Adversarial Defense via Randomized Smoothing · ICML 2025
Security and privacy of machine learning
adversarial example
0.912025
DivTrackee versus DynTracker: Promoting Diversity in Anti-Facial Recognition against Dynamic FR Strategy · CCS 2025
Privacy and data protection › facial privacy protection
adversarial facial privacy protection
0.912025
DivTrackee versus DynTracker: Promoting Diversity in Anti-Facial Recognition against Dynamic FR Strategy · CCS 2025
Privacy and data protection › facial privacy protection
anti-facial recognition
0.912025
DivTrackee versus DynTracker: Promoting Diversity in Anti-Facial Recognition against Dynamic FR Strategy · CCS 2025
Privacy and data protection
facial privacy protection
0.912025
DivTrackee versus DynTracker: Promoting Diversity in Anti-Facial Recognition against Dynamic FR Strategy · CCS 2025
Computer vision › Vision and language
image captioning
0.812024
Stealthy Targeted Backdoor Attacks Against Image Captioning · IEEE Trans. Inf. Forensics Secur. 2024
Security and privacy of machine learning › adversarial attack
backdoor attack
0.812024
Stealthy Targeted Backdoor Attacks Against Image Captioning · IEEE Trans. Inf. Forensics Secur. 2024
Machine learning › Learning theory
generalization bounds
0.712023
What Distributions are Robust to Indiscriminate Poisoning Attacks for Linear Learners? · NeurIPS 2023
Machine learning › Trustworthy machine learning › robustness
poisoning attack defense
0.712023
What Distributions are Robust to Indiscriminate Poisoning Attacks for Linear Learners? · NeurIPS 2023
Security and privacy of machine learning
poisoning attack
0.712023
What Distributions are Robust to Indiscriminate Poisoning Attacks for Linear Learners? · NeurIPS 2023
Mathematical optimization › continuous optimization › matrix optimization › matrix recovery
matrix completion
0.722018
A Primal-Dual Analysis of Global Optimality in Nonconvex Low-Rank Matrix Recovery · ICML 2018
Fast and Sample Efficient Inductive Matrix Completion via Multi-Phase Procrustes Flow · ICML 2018
Mathematical optimization
nonconvex optimization
0.722018
A Primal-Dual Analysis of Global Optimality in Nonconvex Low-Rank Matrix Recovery · ICML 2018
Fast and Sample Efficient Inductive Matrix Completion via Multi-Phase Procrustes Flow · ICML 2018
Machine learning › Trustworthy machine learning › uncertainty estimation › aleatoric uncertainty
label uncertainty
0.612022
Understanding Intrinsic Robustness Using Label Uncertainty · ICLR 2022
Information theory › probability theory
measure concentration
0.512021
Improved Estimation of Concentration Under ℓp-Norm Distance Metrics Using Half Spaces · ICLR 2021
Machine learning › Representation and self-supervised learning
mutual information maximization
0.412020
Learning Adversarially Robust Representations via Worst-Case Mutual Information Maximization · ICML 2020
Machine learning › Representation and self-supervised learning › representation learning
robust representation learning
0.412020
Learning Adversarially Robust Representations via Worst-Case Mutual Information Maximization · ICML 2020
Machine learning › Trustworthy machine learning › robustness
adversarial examples
0.412019
Empirically Measuring Concentration: Fundamental Limits on Intrinsic Robustness · NeurIPS 2019
Machine learning › Learning theory
concentration of measure
0.412019
Empirically Measuring Concentration: Fundamental Limits on Intrinsic Robustness · NeurIPS 2019
Machine learning › Optimization for machine learning › gradient-based optimization
gradient descent
0.312018
Fast and Sample Efficient Inductive Matrix Completion via Multi-Phase Procrustes Flow · ICML 2018
Machine learning › Learning theory › matrix completion
inductive matrix completion
0.312018
Fast and Sample Efficient Inductive Matrix Completion via Multi-Phase Procrustes Flow · ICML 2018
Mathematical optimization › continuous optimization › matrix optimization › matrix recovery
low-rank matrix recovery
0.312018
A Primal-Dual Analysis of Global Optimality in Nonconvex Low-Rank Matrix Recovery · ICML 2018
Machine learning › Learning theory › high-dimensional statistics › matrix recovery
low-rank matrix recovery
0.312017
A Unified Variance Reduction-Based Framework for Nonconvex Low-Rank Matrix Recovery · ICML 2017
Machine learning › Optimization for machine learning
non-convex optimization
0.312017
A Unified Variance Reduction-Based Framework for Nonconvex Low-Rank Matrix Recovery · ICML 2017
Machine learning › Optimization for machine learning
stochastic optimization
0.312017
A Unified Variance Reduction-Based Framework for Nonconvex Low-Rank Matrix Recovery · ICML 2017
Machine learning › Optimization for machine learning
variance reduction
0.312017
A Unified Variance Reduction-Based Framework for Nonconvex Low-Rank Matrix Recovery · ICML 2017
Computer vision › Face, body and person analysis
face recognition
0.312025
DivTrackee versus DynTracker: Promoting Diversity in Anti-Facial Recognition against Dynamic FR Strategy · CCS 2025
Machine learning › Trustworthy machine learning › robustness
robust learning
0.312025
Provably Cost-Sensitive Adversarial Defense via Randomized Smoothing · ICML 2025

Methods — techniques the papers use, named apart from their topics

text-guided image generation · 1.7adversarial loss · 1.7universal perturbation · 1.5object detection · 1.5risk analysis · 1.3optimal poisoning attack · 1.3randomized smoothing · 0.9cost matrix · 0.9certified radius · 0.9ℓp-norm distance metrics · 0.5half-space approximation · 0.5unsupervised learning · 0.4restricted strong convexity · 0.3procrustes flow · 0.3primal-dual analysis · 0.3incoherence constraints · 0.3gradient-based non-convex optimization · 0.3
YearPublicationVenuePosition
2025 DivTrackee versus DynTracker: Promoting Diversity in Anti-Facial Recognition against Dynamic FR Strategy
abstract
The widespread adoption of facial recognition (FR) models raises serious concerns about their potential misuse, motivating the development of anti-facial recognition (AFR) to protect user facial privacy. In this paper, we argue that the static FR strategy, predominantly adopted in prior literature for evaluating AFR efficacy, cannot faithfully characterize the actual capabilities of determined trackers who aim to track a specific target identity. In particular, we introduce DynTracker, a dynamic FR strategy where the model's gallery database is iteratively updated with newly recognized target identity images. Surprisingly, such a simple approach renders all the existing AFR protections ineffective. To mitigate the privacy threats posed by DynTracker, we advocate for explicitly promoting diversity in the AFR-protected images. We hypothesize that the lack of diversity is the primary cause of the failure of existing AFR methods. Specifically, we develop DivTrackee, a novel method for crafting diverse AFR protections that builds upon a text-guided image generation framework and diversity-promoting adversarial losses. Through comprehensive experiments on various image benchmarks and feature extractors, we demonstrate DynTracker's strength in breaking existing AFR methods and the superiority of DivTrackee in preventing user facial images from being identified by dynamic FR strategies. We believe our work can act as an important initial step towards developing more effective AFR methods for protecting user facial privacy against determined trackers.
Wenshu Fan, Minxing Zhang, Hongwei Li 0001, Wenbo Jiang 0001, Hanxiao Chen 0001, Xiangyu Yue 0001, Michael Backes 0001, Xiao Zhang 0016
CCS8
2025 Provably Cost-Sensitive Adversarial Defense via Randomized Smoothing
abstract
As machine learning models are deployed in critical applications, robustness against adversarial perturbations is crucial. While numerous defensive algorithms have been proposed to counter such attacks, they typically assume that all adversarial transformations are equally important, an assumption that rarely aligns with real-world applications. To address this, we study the problem of robust learning against adversarial perturbations under cost-sensitive scenarios, where the potential harm of different types of misclassifications is encoded in a cost matrix. Our solution introduces a provably robust learning algorithm to certify and optimize for cost-sensitive robustness, building on the scalable certification framework of randomized smoothing. Specifically, we formalize the definition of cost-sensitive certified radius and propose our novel adaptation of the standard certification algorithm to generate tight robustness certificates tailored to any cost matrix. In addition, we design a robust training method that improves certified cost-sensitive robustness without compromising model accuracy. Extensive experiments on benchmark datasets, including challenging ones unsolvable by existing methods, demonstrate the effectiveness of our certification algorithm and training method across various cost-sensitive scenarios.
Yuan Xin, Dingfan Chen, Michael Backes 0001, Xiao Zhang 0016
ICML4
2025 DiffPAD: Denoising Diffusion-Based Adversarial Patch Decontamination
abstract
In the ever-evolving adversarial machine learning landscape, developing effective defenses against patch attacks has become a critical challenge, necessitating reliable solutions to safeguard real-world AI systems. Although diffusion models have shown remarkable capacity in image synthesis and have been recently utilized to counter$l^{p}$-norm bounded attacks, their potential in mitigating localized patch attacks remains largely underexplored. In this work, we propose DiffPAD, a novel framework that harnesses the power of diffusion models for adversarial patch decontamination. DiffPAD first performs super-resolution restoration on downsampled input images, then adopts binarization, dynamic thresholding scheme and sliding window for effective localization of adversarial patches. Such a design is inspired by the theoretically derived correlation between patch size and diffusion restoration error that is generalized across diverse patch attack scenarios. Finally, DiffPAD applies inpainting techniques to the original input images with the estimated patch region being masked. By integrating closed-form solutions for super-resolution restoration and image inpainting into the conditional reverse sampling process of a pre-trained diffusion model, DiffPAD obviates the need for text guidance or fine-tuning. Through comprehensive experiments, we demonstrate that DiffPAD not only achieves state-of-the-art adversarial robustness against patch attacks but also excels in recovering naturalistic images without patch remnants. The source code is available at https://github.com/JasonFu1998/DiffPAD.
Jia Fu 0001, Xiao Zhang 0016, Sepideh Pashami, Fatemeh Rahimian, Anders Holst
WACV2
2024 Stealthy Targeted Backdoor Attacks Against Image Captioning
abstract
In recent years, there is an explosive growth in multimodal learning. Image captioning, a classical multimodal task, has demonstrated promising applications and attracted extensive research attention. However, recent studies have shown that image caption models are vulnerable to some security threats such as backdoor attacks. Existing backdoor attacks against image captioning typically pair a trigger either with a predefined sentence or a single word as the targeted output, yet they are unrelated to the image content, making them easily noticeable as anomalies by humans. In this paper, we present a novel method to craft targeted backdoor attacks against image caption models, which are designed to be stealthier than prior attacks. Specifically, our method first learns a special trigger by leveraging universal perturbation techniques for object detection, then places the learned trigger in the center of some specific source object and modifies the corresponding object name in the output caption to a predefined target name. During the prediction phase, the caption produced by the backdoored model for input images with the trigger can accurately convey the semantic information of the rest of the whole image, while incorrectly recognizing the source object as the predefined target. Extensive experiments demonstrate that our approach can achieve a high attack success rate while having a negligible impact on model clean performance. In addition, we show our method is stealthy in that the produced backdoor samples are indistinguishable from clean samples in both image and text domains, which can successfully bypass existing backdoor defenses, highlighting the need for better defensive mechanisms against such stealthy backdoor attacks.
Wenshu Fan, Hongwei Li 0001, Wenbo Jiang 0001, Meng Hao 0001, Shui Yu 0001, Xiao Zhang 0016
IEEE Trans. Inf. Forensics Secur.6
2023 What Distributions are Robust to Indiscriminate Poisoning Attacks for Linear Learners?
abstract
We study indiscriminate poisoning for linear learners where an adversary injects a few crafted examples into the training data with the goal of forcing the induced model to incur higher test error. Inspired by the observation that linear learners on some datasets are able to resist the best known attacks even without any defenses, we further investigate whether datasets can be inherently robust to indiscriminate poisoning attacks for linear learners. For theoretical Gaussian distributions, we rigorously characterize the behavior of an optimal poisoning attack, defined as the poisoning strategy that attains the maximum risk of the induced model at a given poisoning budget. Our results prove that linear learners can indeed be robust to indiscriminate poisoning if the class-wise data distributions are well-separated with low variance and the size of the constraint set containing all permissible poisoning points is also small. These findings largely explain the drastic variation in empirical attack performance of the state-of-the-art poisoning attacks on linear learners across benchmark datasets, making an important initial step towards understanding the underlying reasons some learning tasks are vulnerable to data poisoning attacks.
Fnu Suya, Xiao Zhang 0016, Yuan Tian 0001, David Evans 0001
NeurIPS2
2022 Understanding Intrinsic Robustness Using Label Uncertainty
Xiao Zhang 0016, David Evans 0001
ICLR1
2021 Improved Estimation of Concentration Under ℓp-Norm Distance Metrics Using Half Spaces
Jack Prescott, Xiao Zhang 0016, David Evans 0001
ICLR2
2020 Understanding the Intrinsic Robustness of Image Distributions using Conditional Generative Models
abstract
Starting with Gilmer et al. (2018), several works have demonstrated the inevitability of adversarial examples based on different assumptions about the underlying input probability space. It remains unclear, however, whether these results apply to natural image distributions. In this work, we assume the underlying data distribution is captured by some conditional generative model, and prove intrinsic robustness bounds for a general class of classifiers, which solves an open problem in Fawzi et al. (2018). Building upon the state-of-the-art conditional generative models, we study the intrinsic robustness of two common image benchmarks under L2 perturbations, and show the existence of a large gap between the robustness limits implied by our theory and the adversarial robustness achieved by current state-of-the-art robust models.
Xiao Zhang 0016, Quanquan Gu, David Evans 0001
AISTATS1
2020 Learning Adversarially Robust Representations via Worst-Case Mutual Information Maximization
abstract
Training machine learning models that are robust against adversarial inputs poses seemingly insurmountable challenges. To better understand adversarial robustness, we consider the underlying problem of learning robust representations. We develop a notion of representation vulnerability that captures the maximum change of mutual information between the input and output distributions, under the worst-case input perturbation. Then, we prove a theorem that establishes a lower bound on the minimum adversarial risk that can be achieved for any downstream classifier based on its representation vulnerability. We propose an unsupervised learning method for obtaining intrinsically robust representations by maximizing the worst-case mutual information between the input and output distributions. Experiments on downstream classification tasks support the robustness of the representations found using unsupervised learning with our training principle.
Sicheng Zhu, Xiao Zhang 0016, David Evans 0001
ICML2
2019 Learning One-hidden-layer ReLU Networks via Gradient Descent
abstract
We study the problem of learning one-hidden-layer neural networks with Rectified Linear Unit (ReLU) activation function, where the inputs are sampled from standard Gaussian distribution and the outputs are generated from a noisy teacher network. We analyze the performance of gradient descent for training such kind of neural networks based on empirical risk minimization, and provide algorithm-dependent guarantees. In particular, we prove that tensor initialization followed by gradient descent can converge to the ground-truth parameters at a linear rate up to some statistical error. To the best of our knowledge, this is the first work characterizing the recovery guarantee for practical learning of one-hidden-layer ReLU networks with multiple neurons. Numerical experiments verify our theoretical findings.
Xiao Zhang 0016, Yaodong Yu, Lingxiao Wang 0001, Quanquan Gu
AISTATS1
2019 Cost-Sensitive Robustness against Adversarial Examples
Xiao Zhang 0016, David Evans 0001
ICLR (Poster)1
2019 Empirically Measuring Concentration: Fundamental Limits on Intrinsic Robustness
abstract
Many recent works have shown that adversarial examples that fool classifiers can be found by minimally perturbing a normal input. Recent theoretical results, starting with Gilmer et al. (2018b), show that if the inputs are drawn from a concentrated metric probability space, then adversarial examples with small perturbation are inevitable. A concentrated space has the property that any subset with Ω(1) (e.g.,1/100) measure, according to the imposed distribution, has small distance to almost all (e.g., 99/100) of the points in the space. It is not clear, however, whether these theoretical results apply to actual distributions such as images. This paper presents a method for empirically measuring and bounding the concentration of a concrete dataset which is proven to converge to the actual concentration. We use it to empirically estimate the intrinsic robustness to and L2 and Linfinity perturbations of several image classification benchmarks. Code for our experiments is available at https://github.com/xiaozhanguva/Measure-Concentration.
Saeed Mahloujifar, Xiao Zhang 0016, Mohammad Mahmoody, David Evans 0001
NeurIPS2
2018 A Unified Framework for Nonconvex Low-Rank plus Sparse Matrix Recovery
abstract
We propose a unified framework to solve general low-rank plus sparse matrix recovery problems based on matrix factorization, which covers a broad family of objective functions satisfying the restricted strong convexity and smoothness conditions. Based on projected gradient descent and the double thresholding operator, our proposed generic algorithm is guaranteed to converge to the unknown low-rank and sparse matrices at a locally linear rate, while matching the best-known robustness guarantee (i.e., tolerance for sparsity). At the core of our theory is a novel structural Lipschitz gradient condition for low-rank plus sparse matrices, which is essential for proving the linear convergence rate of our algorithm, and we believe is of independent interest to prove fast rates for general superposition-structured models. We illustrate the application of our framework through two concrete examples: robust matrix sensing and robust PCA. Empirical experiments corroborate our theory.
Xiao Zhang 0016, Lingxiao Wang 0001, Quanquan Gu
AISTATS1
2018 Fast and Sample Efficient Inductive Matrix Completion via Multi-Phase Procrustes Flow
abstract
We revisit the inductive matrix completion problem that aims to recover a rank-$r$ matrix with ambient dimension $d$ given $n$ features as the side prior information. The goal is to make use of the known $n$ features to reduce sample and computational complexities. We present and analyze a new gradient-based non-convex optimization algorithm that converges to the true underlying matrix at a linear rate with sample complexity only linearly depending on $n$ and logarithmically depending on $d$. To the best of our knowledge, all previous algorithms either have a quadratic dependency on the number of features in sample complexity or a sub-linear computational convergence rate. In addition, we provide experiments on both synthetic and real world data to demonstrate the effectiveness of our proposed algorithm.
Xiao Zhang 0016, Simon S. Du, Quanquan Gu
ICML1
2018 A Primal-Dual Analysis of Global Optimality in Nonconvex Low-Rank Matrix Recovery
abstract
We propose a primal-dual based framework for analyzing the global optimality of nonconvex low-rank matrix recovery. Our analysis are based on the restricted strongly convex and smooth conditions, which can be verified for a broad family of loss functions. In addition, our analytic framework can directly handle the widely-used incoherence constraints through the lens of duality. We illustrate the applicability of the proposed framework to matrix completion and one-bit matrix completion, and prove that all these problems have no spurious local minima. Our results not only improve the sample complexity required for characterizing the global optimality of matrix completion, but also resolve an open problem in Ge et al. (2017) regarding one-bit matrix completion. Numerical experiments show that primal-dual based algorithm can successfully recover the global optimum for various low-rank problems.
Xiao Zhang 0016, Lingxiao Wang 0001, Yaodong Yu, Quanquan Gu
ICML1
2017 A Unified Computational and Statistical Framework for Nonconvex Low-rank Matrix Estimation
abstract
We propose a unified framework for estimating low-rank matrices through nonconvex optimization based on gradient descent algorithm. Our framework is quite general and can be applied to both noisy and noiseless observations. In the general case with noisy observations, we show that our algorithm is guaranteed to linearly converge to the unknown low-rank matrix up to a minimax optimal statistical error, provided an appropriate initial estimator. While in the generic noiseless setting, our algorithm converges to the unknown low-rank matrix at a linear rate and enables exact recovery with optimal sample complexity. In addition, we develop a new initialization algorithm to provide the desired initial estimator, which outperforms existing initialization algorithms for nonconvex low-rank matrix estimation. We illustrate the superiority of our framework through three examples: matrix regression, matrix completion, and one-bit matrix completion. We also corroborate our theory through extensive experiments on synthetic data.
Lingxiao Wang 0001, Xiao Zhang 0016, Quanquan Gu
AISTATS2
2017 A Unified Variance Reduction-Based Framework for Nonconvex Low-Rank Matrix Recovery
abstract
We propose a generic framework based on a new stochastic variance-reduced gradient descent algorithm for accelerating nonconvex low-rank matrix recovery. Starting from an appropriate initial estimator, our proposed algorithm performs projected gradient descent based on a novel semi-stochastic gradient specifically designed for low-rank matrix recovery. Based upon the mild restricted strong convexity and smoothness conditions, we derive a projected notion of the restricted Lipschitz continuous gradient property, and prove that our algorithm enjoys linear convergence rate to the unknown low-rank matrix with an improved computational complexity. Moreover, our algorithm can be employed to both noiseless and noisy observations, where the (near) optimal sample complexity and statistical rate can be attained respectively. We further illustrate the superiority of our generic framework through several specific examples, both theoretically and experimentally.
Lingxiao Wang 0001, Xiao Zhang 0016, Quanquan Gu
ICML2