Li Li 0103

dblp:53/2189-103 · DBLP profile ↗
← Back
26ranked-venue papers
7as first author
23since 2021 · last 2026
0000-0003-4799-5896ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 13 · 4 first-author · 11 since 2021Computer networks · 7 · 1 first-author · 6 since 2021Artificial intelligence and machine learning · 6 · 1 first-author · 6 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021
YearPublicationVenuePosition
2026 CREF: Concept Response Fingerprints for Large Language Models
abstract
Protecting the intellectual property of Large Language Models (LLMs) is critical because training them requires massive computational resources and data. A key challenge is determining whether a suspicious model is derived from a specific base model after fine-tuning or structural modification. Existing fingerprinting methods rely on model weights or high-dimensional representations, leading to substantial storage overhead. We propose a non-intrusive fingerprinting framework Concept REsponse Fingerprints (CREF). Inspired by activation engineering, CREF constructs a set of concept activation vectors as semantic probes. It then measures the response strength of hidden representations along these concept activation vectors using shared inputs. The resulting concept response matrix serves as a compact fingerprint, and similarity between models is measured using centered kernel alignment. Experiments on multiple LLM families show that CREF reliably distinguishes derived models from independently trained models and remains robust to fine-tuning, pruning, parameter permutation, and scaling. Moreover, the fingerprint requires only kilobyte-level storage, making it practical for large-scale deployment and ownership verification.
Haiyong Tang, Hanzhou Wu, Gejian Zhao, Li Li 0103, Zhihua Xia, Xinpeng Zhang 0001
IH&MMSec4
2026 Lightweight AI-Generated image detection based on enhanced common artifact features
Li Li 0103, Yanli Ren, Xinpeng Zhang 0001, Guorui Feng
Expert Syst. Appl.2
2026 RI-Mark: Robust and imperceptible watermarking for diffusion models
Chengming Zhao, Li Li 0103, Yanli Ren, Guorui Feng
Expert Syst. Appl.2
2026 A Flexible and Lightweight Watermarking Framework for Stable Diffusion Models
abstract
The application of Stable Diffusion Models (SDMs) in Internet of Things (IoT) image processing raises significant ethical concerns, particularly regarding model copyright infringement and the dissemination of inappropriate Artificial Intelligence (AI)-generated images. Model watermarking technology has proven effective for copyright verification and tracing the source model of AI-generated content. While initial-noise-modification-based watermarking can provide provable security and achieve lossless embedding, existing methods rely on Denoising Diffusion Implicit Model (DDIM) inversion for watermark extraction, which suffer from inherent precision limitations that compromise extraction accuracy. More critically, most of the existing approaches of this type still rely on access to the original or a compatible SDM during watermark verification, which introduces considerable practical constraints due to the model’s size and computational demands. To address these limitations, an end-to-end flexible SDM watermarking framework is proposed that replaces the DDIM inversion process with a lightweight watermark extractor, thereby eliminating the dependency on inversion in conventional provably secure watermarking. Specifically, a universal watermark extractor across SDM V1/V2 variants is designed based on a Transformer and Multilayer Perceptron (MLP) framework, complemented by fine-tuning a pre-trained watermark decoder, to directly recover watermark information from generated images. Experimental results confirm that our watermarking method yields superior performance in terms of fidelity and robustness. The lightweight extractor offers additional advantages of low computational cost and high transmission efficiency, providing an efficient and practical solution for watermark extraction in SDM-generated image.
Huixin Luo, Li Li 0103, Xinpeng Zhang 0001
IEEE Internet Things J.2
2026 Dormant key: Unlocking universal adversarial control in text-to-image models
Jingqi Hu, Li Li 0103, Hanzhou Wu, Huixin Luo, Xinpeng Zhang 0001
Neural Networks2
2026 Aligning Normal Representations in Diffusion Model for Video Anomaly Detection
abstract
Recent advances have highlighted the potential of diffusion models in Video Anomaly Detection (VAD). Diffusion models are typically employed to generate negative instances to distinguish them from positive ones. However, the existing diffusion model architectures, generally based on the reconstruction of low-level noisy features, introduce spurious correlations due to shortcut learning, which undermines the robustness of anomaly detection. In this work, we leverage normal-specific representations to guide behavior restoration by aligning disentangled task-relevant representations within the diffusion model. we propose a normal representation-guided conditional diffusion model for unsupervised VAD by aligning normal-specific representations. Inspired by prior knowledge of anomaly discrimination, we decompose normal behavior features into normal-specific and VAD-irrelevant representations into independent channels based on contrastive learning. We introduce a group-supervised learning strategy in learning patch-wise generation guided by normal-specific representations. A gradient-based representation alignment loss enforces the alignment between normal semantics and the target patches. This process enables the diffusion model to understand normal patterns for anomaly detection. Extensive experimental results conducted on VAD benchmarks demonstrate the effectiveness of our methods.
Chongye Guo, Li Li 0103, Yanli Ren, Xinpeng Zhang 0001, Guorui Feng
IEEE Trans. Circuits Syst. Video Technol.2
2025 Leveraging Spatial Invariance to Boost Adversarial Transferability
Li Li 0103, Yanli Ren, Chuan Qin 0001, Guorui Feng
ICCV2
2025 FareMark: Model-Watermark-Driven Free-Rider Detection in Federated Learning Model
abstract
Federated Learning (FL) is increasingly adopted in Internet of Things (IoT) ecosystems, where distributed devices collaboratively train machine learning models while preserving data privacy. Well-trained models have high commercial value. If stolen, it will severely harm the interests of the model owner. In FL, a free-rider client can avoid contributing data or computing resources by establishing a deceptive local model and illegally obtaining the valuable global model for free, undermining the central server’s interests. While existing model watermarking methods primarily concentrate on identifying deep learning model misuse, they fail to adequately tackle the issue of identifying free-riders. To address such an issue, this paper presents a box-free watermarking scheme that enables multiple clients who participated in the training to embed private watermarks within the jointly trained federated deep learning model, while the free rider cannot if he did not participate in the training. To avoid conflicts between different clients, each client selects a unique trigger class and embeds watermarks into the global model during the training process. Furthermore, we propose a memory-enhancing local updating strategy to effectively fuse different watermarks into the global model. The proposed method can assist the center in identifying free-rider clients while also safeguarding the FL model’s intellectual property rights. The efficiency of the embedded watermarks is validated by experiments conducted on different models, and the performance of the resilience across various training settings and the robustness against different watermark removal methods are also tested.
Li Li 0103, Xinpeng Zhang 0001, Hanzhou Wu, Guorui Feng, Weiming Zhang 0001
IEEE Internet Things J.1
2025 Robust watermarking for diffusion models based on STDM and latent space fine-tuning
Li Li 0103, Xinpeng Zhang 0001, Guorui Feng, Zichi Wang, Deyang Wu, Hanzhou Wu
J. Inf. Secur. Appl.1
2025 Protecting copyright of stable diffusion models from ambiguity attacks
Zihan Yuan, Li Li 0103, Zichi Wang, Xinpeng Zhang 0001
Signal Process.2
2025 A Watermark Forgery Attack Against Stable Diffusion Model Watermarking
Huixin Luo, Li Li 0103, Xinpeng Zhang 0001
IEEE Signal Process. Lett.2
2025 Watermark Removal Attack Against Text-to-Image Generative Model Watermarking
abstract
The artist's style can be quickly imitated by fine-tuning a text-to-image model using artist's artworks, which raises serious copyright concerns. Scholars have proposed many watermarking methods to protect the artists' copyright. To evaluate the security and enhance the performance of existing watermarking, this paper proposes a watermark removal attack for text-to-image generative model watermarking for the first time. This attack aims to invalidate watermarking designed to detect art theft mimicry in text-to-image models. In this method, a watermark recognition network and a watermark removal network are designed. The watermark recognition network identifies whether an artwork contains watermark, and the watermark removal network is used to remove it. Consequently, text-to-image models fine-tuned with watermark-removed artworks can reproduce an artist's style while evading watermark detection. This makes the copyright authentication of artworks ineffective. Experiments show that the proposed attack can effectively remove watermarks, with watermark extraction accuracy dropping below 48.64%. Additionally, the images after watermark removal retain high similarity to the original images, with PSNR exceeding 27.96 and SSIM exceeding 0.92.
Zihan Yuan, Li Li 0103, Zichi Wang, Jingyuan Jiang, Xinpeng Zhang 0001
IEEE Signal Process. Lett.2
2025 Secure Neural Network Watermarking Protocol Against Evidence Exposure Attack
abstract
Trigger-based backdoor watermarking is an extensively utilized and effective method to safeguard the copyright of deep neural networks (DNNs), in which the trigger set could be taken as the key of the watermark. However, during the verification stage, there is a risk that the trigger set could be leaked and exposed to adversaries. If this occurs, the adversaries might apply this leaked trigger set to claim ownership of the model, posing significant copyright issues for the watermarked DNN. To address such an evidence exposure problem, a secure neural network watermarking protocol is put forward in this paper. In the proposed protocol, the trigger set is not fixed, once the trigger is utilized for verification, it is invalid and cannot be used for verification in the future. As a result, even if the trigger set is leaked during the verification process and obtained by the attacker, they cannot use it for copyright verification since it is invalid. To assist the protocol, a trigger set generation method is designed, in which the auxiliary classifier generative adversarial network (ACGAN) and the target classification model are trained together. The special logits distribution and the labels of the generated trigger samples can be ensured and verified effectively in this way. The performance of the trigger generation methods regarding effectiveness, fidelity, and robustness is verified by experiments, and the security analysis of the designed watermarking protocol is conducted.
Huixin Luo, Li Li 0103, Xinpeng Zhang 0001
IEEE Trans. Multim.2
2025 Integrity Protection of Generative Adversarial Networks Using Fragile Watermarking
abstract
Deep learning has made remarkable achievements in the field of artificial intelligence. However, a well-trained deep neural network is at risk of being tampered with. Although some model watermarking schemes have been proposed to solve this problem, most of them are only oriented to discriminant models, and the integrity authentication schemes for generative models are urgently lacking. Especially, the integrity authentication problem of generative adversarial networks (GANs) that plays an important role in computer vision has not been properly solved. To address this problem, we propose a fragile model watermarking framework for GANs. Specifically, we use a secret key to generate specific information as the label and combine it with the watermark to form a trigger set. Then, we use the trigger set to train the GAN, the training process does not damage the model performance. We can achieve integrity authentication of the GAN using the output of the GAN for the specific label. A large number of experiments show that our proposed method has excellent performance, which can realize the integrity authentication of GANs. What’s more, the proposed method has good generalization and can be easily applied to different GAN architectures.
Zihan Yuan, Li Li 0103, Zichi Wang, Xinpeng Zhang 0001
ACM Trans. Multim. Comput. Commun. Appl.2
2024 Robust Blind Video Watermarking Based on Ring Tensor and BCH Coding
abstract
Video Internet of Things (IoT) is widely used in the fields of safe city, smart transportation, and logistics warehousing, which facilitates the acquisition of important environmental and semantic information. However, the tampering of unauthorized video data may seriously violate user privacy and even harm society. Although the existing video watermarking technology provides an effective solution for copyright protection, it still faces challenges to achieve robust copyright authentication in the complex IoT environment. In this article, a robust blind video watermarking based on ring Tensor and Bose-Chaudhuri–Hocquenghem (BCH) coding is proposed. First, ring sub-bands of different sizes are constructed in the spatial domain of the video, and the ring sub-bands of consecutive video frames are combined into a ring tensor for copyright watermark embedding. Second, to balance the imperceptibility and robustness of the copyright watermark, an adaptive BCH coding scheme is developed, which uses the modified differential entropy to calculate the video complexity and automatically selects the appropriate watermark coding parameters. Finally, a quaternary synchronization watermark embedding strategy is designed to solve the time synchronization destruction caused by video frame rate conversion. A synchronization ring is constructed within each video frame using the strong correlation between adjacent frames. When the video is subjected to temporal synchronization attacks, the synchronization watermark is extracted from the synchronization ring to restore the synchronization of the copyright watermark. Extensive experimental results demonstrate that the proposed scheme can effectively resist common video processing while exhibiting excellent robustness against video attacks in complex Internet environments.
Jiayan Wang, Jing Zhao 0027, Li Li 0103, Zichi Wang, Hanzhou Wu, Deyang Wu
IEEE Internet Things J.3
2024 Adaptive Robust Watermarking for Resisting Multiple Distortions in Real Scenes
abstract
An efficient and reliable digital watermarking scheme is needed in a complex network environment to solve image copyright disputes. However, most existing digital watermarking technologies can only resist common image processing and perform poorly against complex attacks. To this end, an adaptive robust watermarking for resisting multiple distortions in real scenes is proposed in this work. First, to reduce the impact of common attacks on the robustness of the algorithm, two-level stationary wavelet transform (SWT) is applied to extract low-frequency sub-band of host image, which is subsequently divided into nonoverlapping sub-blocks. Then, a circular sub-block method is designed for watermark embedding. Moreover, an improved Schur decomposition is proposed to control the variation range of eigenvalues. Meanwhile, an adaptive robust factor and embedding strength strategy are proposed to ensure image reconstruction in real number field, thereby balancing the invisibility and robustness of the watermark. Finally, the logistic encryption and repetition code are performed on the watermark to improve the security and error correction capabilities of the watermark. Extensive experiments demonstrate that the proposed scheme has higher performance than some representative watermarking schemes in complex combined attacks and real-world scenarios.
Deyang Wu, Jiayan Wang, Jing Zhao 0027, Li Li 0103, Zichi Wang, Hanzhou Wu
IEEE Internet Things J.4
2024 Watermarking for Stable Diffusion Models
abstract
In the scenario of text data and image data interact of the Internet of Things (IoT) applications, the problem of copyright protection of the text-to-image models is threatened due to the replicability and portability of the neural network model. In order to solve this problem, we propose a model watermarking for the typical text-to-image diffusion models (DMs)–stable DMs (SDMs), which is a key aspect of the copyright protection of text-to-image models. Our scheme injects watermark into an SDM and makes the SDM generate watermark through a predefined prompt. The ownership of the SDM can be proved by the different output results of the model to the predefined prompt. The proposed method does not require raw training data and internal details of SDMs, which only need a predefined prompt and watermark to fine tune the pretrained SDM with minimal epoch. A large number of experiments show that our watermarking technology is effective, and can realize the copyright protection of the SDMs on the premise of less influence on the original function.
Zihan Yuan, Li Li 0103, Zichi Wang, Xinpeng Zhang 0001
IEEE Internet Things J.2
2024 Ambiguity attack against text-to-image diffusion model watermarking
Zihan Yuan, Li Li 0103, Zichi Wang, Xinpeng Zhang 0001
Signal Process.2
2024 Novel Robust Video Watermarking Scheme Based on Concentric Ring Subband and Visual Cryptography With Piecewise Linear Chaotic Mapping
abstract
Video watermarking based on frequency domain is proved to have good invisibility and robustness. However, most of the existing video watermarking schemes embed watermarks in the frequency domain based on subblock segmentation, while ignoring the variation relationship between video space and frequency domain features. Therefore, it is difficult to achieve robust authentication in complex application scenarios. In this paper, a ring subband is constructed in DT-CWT domain as the watermark embedding region by analyzing the relationship between video space and frequency domain characteristics under multiple attacks. Subsequently, the double watermark is embedded by modifying the DCT coefficient of the ring subband, with the copyright watermark alternately and repeatedly embedded within the ring subband, and the synchronous watermark is embedded in the outermost concentric circle. In addition, visual encryption (VC) and piecewise linear chaotic mapping (PLCM) methods are used to encrypt the watermark before it is embedded in the concentric rings, and two shared images are generated, one for the watermark embedding stage and the other for the watermark extraction stage. Experimental results demonstrate that the proposed scheme can resist common attacks, such as noise, JPEG compression, rotation, scaling, time synchronization attacks, and its robustness surpasses existing discrete wavelet transform (DWT) and DT-CWT based video watermarking schemes under complex attack scenarios.
Deyang Wu, Xinpeng Zhang 0001, Jiayan Wang, Li Li 0103, Guorui Feng
IEEE Trans. Circuits Syst. Video Technol.4
2024 Covert Task Embedding: Turning a DNN Into an Insider Agent Leaking Out Private Information
abstract
We present the covert task embedding (CTE) attack, a new general threat affecting deep neural networks (DNNs). The new attack consists in hiding a malicious privacy-sensitive task within a seemingly innocuous network, in such a way that the result of the malicious task is delivered together with the legitimate output in a stealthy way. The result of the covert task is further protected by requiring that its extraction depends on a secret key shared by the embedder and the detector. We demonstrate the feasibility of the CTE attack in various settings, wherein a face-based age estimation DNN is trained in such a way as to also detect the gender (binary classification task) or ethnicity (multiclassification task) of the framed individual and stealthily pass along such information together with the estimated age. The results of the experiments we carried out show that, in all cases, the gender and ethnicity information can be reliably extracted without impairing the accuracy of the age estimation functionality. Despite the simplicity of the estting considered in the brief, our experiments show the feasibility of the CTE attack, thus calling for the development of suitable remedies against it.
Li Li 0103, Weiming Zhang 0001, Mauro Barni
IEEE Trans. Neural Networks Learn. Syst.1
2023 Robust periodic blind watermarking based on sub-block mapping and block encryption
Jiayan Wang, Deyang Wu, Li Li 0103, Jing Zhao 0027, Hanzhou Wu
Expert Syst. Appl.3
2023 Universal BlackMarks: Key-Image-Free Blackbox Multi-Bit Watermarking of Deep Neural Networks
abstract
Existing methods for Deep Neural Networks (DNN) watermarking either require accessing the internal parameters of the DNN models (white-box watermarking), or rely on backdooring to enforce a desired behavior of the model when the DNN is fed with a specific set of key input images (black-box watermarking). In this letter, we propose a black-box multi-bit DNN watermarking algorithm, suitable for multiclass classification networks, whereby the presence of the watermark can be retrieved from the output of the network in correspondence toanyinput. To read the watermark, we first apply a power function to the softmax output of the DNN model to map it from an impulse-like to a smooth distibution. Then, we extract the watermark bits by projecting the output of the DNN onto a pseudorandom key vector. Watermark embedding is achieved by adding a proper regularizer term to the training loss. The effectiveness of the proposed method is demonstrated by applying it to various network architectures working on different datasets. The experimental results demonstrate the possibility to embed a robust watermark into the output of the host DNN with a negligible impact on the accuracy of the original task.
Li Li 0103, Weiming Zhang 0001, Mauro Barni
IEEE Signal Process. Lett.1
2021 Adversarial batch image steganography against CNN-based pooled steganalysis
Li Li 0103, Weiming Zhang 0001, Chuan Qin 0003, Kejiang Chen, Wenbo Zhou 0004, Nenghai Yu
Signal Process.1
2020 Designing Near-Optimal Steganographic Codes in Practice Based on Polar Codes
abstract
Steganography is an information hiding technique for covert communication. So far Syndrome-Trellis Codes (STC), a convolutional codes-based method, is the only near-optimal coding method, i.e., it can approach the rate-distortion bound of content-adaptive steganography in practice. However, as a secure communication application, steganography needs the diversity of coding methods. This paper proposes another and a better near-optimal steganographic coding method based on polar codes, using Successive Cancellation List (SCL) decoding algorithm to minimize additive distortion in steganography. Considering a steganographic channel as a binary symmetric channel, the proposed Steganographic Polar Codes (SPC) chooses parity-check matrix by setting embedding payload as the initial value of Arikan's heuristic and computes decoding channel metric from the optimal modification probability of minimal distortion model. To overcome the inherent defect of polar codes only suiting for code length of a power of 2, we introduce three strategies to generalize SPC for arbitrary length. Experimental results validate the versatility of SPC to minimize arbitrary distortion. When compared with STC, the overall coding performance of SPC is more superior with low embedding complexity. This work verifies the availability of polar codes for the practical construction of steganographic codes and provides a methodology for designing better steganographic codes based on any advance of polar coding/decoding.
Weixiang Li, Weiming Zhang 0001, Li Li 0103, Hang Zhou 0007, Nenghai Yu
IEEE Trans. Commun.3
2020 Steganographic Security Analysis From Side Channel Steganalysis and Its Complementary Attacks
abstract
Side channel steganalysis refers to detecting a steganographer in social websites via behavior analysis. In this paper, we first design a side channel steganalysis based on the correlation between image sequences of social users, which aims to find out the behaviorally anomalous steganographer. According to the experimental results of side channel steganalysis, it is intuitively secure for the steganographer to act identically to normal social users since she can avoid being detected by side channel steganalysis. However, when faced with various detection methods, is it still secure to behave similar to a normal user? To comprehensively consider the detection means and further explore the secure behavior region of the steganographer, we design a complementary attack of side channel steganalysis. Specifically, we take the correlation of contents of images as side information and take the images with similar content as references to calibrate steganalysis features, which helps improve traditional steganalysis. The proposed side channel steganalysis and its complementary attack efficiently detect steganographers from two different aspects. When the average rank of the steganographer is used to measure the performance, side channel steganalysis can rank the steganographer within the top ten in 100 actors, and the complementary attack can raise the average rank of the steganographer by three places compared with the previous method. From the perspective of the steganographer on social networks, it can help her behave in a more secure region, where her behavior should neither deviate from that of normal users nor be too similar to that of normal users.
Li Li 0103, Weiming Zhang 0001, Kejiang Chen, Nenghai Yu
IEEE Trans. Multim.1
2019 Side Channel Steganalysis: When Behavior is Considered in Steganographer Detection
Li Li 0103, Weiming Zhang 0001, Kejiang Chen, Hongyue Zha, Nenghai Yu
Multim. Tools Appl.1