EDBT 2026 Demo / reviewers in the wild / expert
Yanjie Li 0006
dblp:70/4538-6
· DBLP profile ↗
7ranked-venue papers
3as first author
7since 2021 · last 2026
0000-0001-8859-8331ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 3 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 3 since 2021Security and privacy · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
7 papers |
Trustworthy machine learning · 44% Generative modeling · 27% Image recognition and object detection · 12% | |
| Network and information security
5 papers |
Security and privacy of machine learning · 93% Biometric security · 7% |
Topics — the 22 heaviest of 24, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Security and privacy of machine learning
adversarial attack |
3.4 | 4 | 2026 | Enhancing Targeted Adversarial Attacks on Large Vision-Language Models via Intermediate Projector · IEEE Trans. Inf. Forensics Secur. 2026 StyleGuard: Preventing Text-to-Image-Model-based Style Mimicry Attacks by Style Perturbations · NeurIPS 2025 UV-Attack: Physical-World Adversarial Attacks on Person Detection via Dynamic-NeRF-based UV Mapping · ICLR 2025 |
Machine learning › Generative modeling
diffusion model |
1.6 | 2 | 2025 | StyleGuard: Preventing Text-to-Image-Model-based Style Mimicry Attacks by Style Perturbations · NeurIPS 2025 Diffusion Models as Strong Adversaries · IEEE Trans. Image Process. 2024 |
Security and privacy of machine learning › adversarial attack
physical adversarial attack |
1.5 | 2 | 2025 | UV-Attack: Physical-World Adversarial Attacks on Person Detection via Dynamic-NeRF-based UV Mapping · ICLR 2025 Physical-World Optical Adversarial Attacks on 3D Face Recognition · CVPR 2023 |
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
0.9 | 1 | 2025 | Improving Transferable Targeted Attacks with Feature Tuning Mixup · CVPR 2025 |
Computer vision › Image recognition and object detection › object detection › category-specific object detection
person detection |
0.9 | 1 | 2025 | UV-Attack: Physical-World Adversarial Attacks on Person Detection via Dynamic-NeRF-based UV Mapping · ICLR 2025 |
Machine learning › Generative modeling › diffusion model
text-to-image generation |
0.9 | 1 | 2025 | StyleGuard: Preventing Text-to-Image-Model-based Style Mimicry Attacks by Style Perturbations · NeurIPS 2025 |
Machine learning › Trustworthy machine learning › robustness › adversarial robustness › adversarial transferability
transferable targeted attack |
0.9 | 1 | 2025 | Improving Transferable Targeted Attacks with Feature Tuning Mixup · CVPR 2025 |
Security and privacy of machine learning › membership inference
label-only membership inference |
0.9 | 1 | 2025 | LOMIA: Label-Only Membership Inference Attacks against Pre-trained Large Vision-Language Models · NeurIPS 2025 |
Security and privacy of machine learning
membership inference |
0.9 | 1 | 2025 | LOMIA: Label-Only Membership Inference Attacks against Pre-trained Large Vision-Language Models · NeurIPS 2025 |
Security and privacy of machine learning › generative model security
style mimicry protection |
0.9 | 1 | 2025 | StyleGuard: Preventing Text-to-Image-Model-based Style Mimicry Attacks by Style Perturbations · NeurIPS 2025 |
Security and privacy of machine learning › model privacy
training data memorization |
0.9 | 1 | 2025 | LOMIA: Label-Only Membership Inference Attacks against Pre-trained Large Vision-Language Models · NeurIPS 2025 |
Machine learning › Trustworthy machine learning › robustness
adversarial attack |
0.8 | 1 | 2024 | Diffusion Models as Strong Adversaries · IEEE Trans. Image Process. 2024 |
Machine learning › Trustworthy machine learning › robustness › adversarial examples
adversarial example generation |
0.8 | 1 | 2024 | Diffusion Models as Strong Adversaries · IEEE Trans. Image Process. 2024 |
Machine learning › Trustworthy machine learning › adversarial machine learning › black-box attack
no-box adversarial attack |
0.8 | 1 | 2024 | Diffusion Models as Strong Adversaries · IEEE Trans. Image Process. 2024 |
Biometric security › face recognition
face recognition security |
0.7 | 1 | 2023 | Physical-World Optical Adversarial Attacks on 3D Face Recognition · CVPR 2023 |
Computer vision › Vision and language
cross-modal alignment |
0.3 | 1 | 2026 | Enhancing Targeted Adversarial Attacks on Large Vision-Language Models via Intermediate Projector · IEEE Trans. Inf. Forensics Secur. 2026 |
Computer vision › Vision and language
vision-language model |
0.3 | 1 | 2026 | Enhancing Targeted Adversarial Attacks on Large Vision-Language Models via Intermediate Projector · IEEE Trans. Inf. Forensics Secur. 2026 |
Computer vision › 3D vision › neural radiance field
dynamic neural radiance field |
0.3 | 1 | 2025 | UV-Attack: Physical-World Adversarial Attacks on Person Detection via Dynamic-NeRF-based UV Mapping · ICLR 2025 |
Computer vision › Vision and language › vision-language model
multimodal large language model |
0.3 | 1 | 2025 | LOMIA: Label-Only Membership Inference Attacks against Pre-trained Large Vision-Language Models · NeurIPS 2025 |
Computer vision › 3D vision
neural radiance field |
0.3 | 1 | 2025 | UV-Attack: Physical-World Adversarial Attacks on Person Detection via Dynamic-NeRF-based UV Mapping · ICLR 2025 |
Computer vision › Image recognition and object detection
image classification |
0.2 | 1 | 2024 | Diffusion Models as Strong Adversaries · IEEE Trans. Image Process. 2024 |
Computer vision › 3D vision
3d face reconstruction |
0.2 | 1 | 2023 | Physical-World Optical Adversarial Attacks on 3D Face Recognition · CVPR 2023 |
Methods — techniques the papers use, named apart from their topics
adversarial noise · 2.6residual query alignment · 2.0q-former · 2.0intermediate projector guided attack · 2.0style loss · 1.7neural radiance field · 1.7expectation over pose transformation · 1.7ensemble purification · 1.7UV mapping · 1.7stochastic update · 0.9label-only attack · 0.9feature tuning mixup · 0.9ensemble of surrogate models · 0.9
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Enhancing Targeted Adversarial Attacks on Large Vision-Language Models via Intermediate ProjectorabstractThe growing deployment of Large Vision-Language Models (VLMs) raises safety concerns, as adversaries may exploit model vulnerabilities to induce harmful outputs, with targeted black-box adversarial attacks posing a particularly severe threat. However, existing methods primarily maximize encoder-level global similarity, which lacks the granularity for stealthy and practical fine-grained attacks, where only specific target should be altered (e.g., modifying a car while preserving its background). Moreover, they largely neglect the projector, a key semantic bridge in VLMs for multimodal alignment. To address these limitations, we propose a novel black-box targeted attack framework that leverages the projector. Specifically, we utilize the widely adopted Querying Transformer (Q-Former) which transforms global image embeddings into fine-grained query outputs, to enhance attack effectiveness and granularity. For global targeted attack scenarios, we propose the Intermediate Projector Guided Attack (IPGA), which aligns the fine-grained query outputs from Q-Former with the target to enhance attack strength and exploits the intermediate pretrained Q-Former that is not fine-tuned for any specific Large Language Model (LLM) to improve transferability. For fine-grained attack scenarios, we augment IPGA with the Residual Query Alignment (RQA), which preserves unrelated content by constraining non-target query outputs, enhancing attack granularity. Extensive experiments demonstrate that IPGA significantly outperforms baselines in global targeted attacks, and IPGA with RQA (IPGA-R) attains superior success rates and content preservation over baselines in fine-grained attacks. Our method also transfers effectively to commercial VLMs such as Google Gemini and OpenAI GPT. Yanjie Li 0006, Kaisheng Liang, Bin Xiao 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2025 | Improving Transferable Targeted Attacks with Feature Tuning MixupabstractDeep neural networks (DNNs) exhibit vulnerability to adversarial examples that can transfer across different DNN models. A particularly challenging problem is developing transferable targeted attacks that can mislead DNN models into predicting specific target classes. While various methods have been proposed to enhance attack transferability, they often incur substantial computational costs while yielding limited improvements. Recent clean feature mixup methods use random clean features to perturb the feature space but lack optimization for disrupting adversarial examples, overlooking the advantages of attack-specific perturbations. In this paper, we propose Feature Tuning Mixup (FTM), a novel method that enhances targeted attack transferability by combining both random and optimized noises in the feature space. FTM introduces learnable feature perturbations and employs an efficient stochastic update strategy for optimization. These learnable perturbations facilitate the generation of more robust adversarial examples with improved transferability. We further demonstrate that attack performance can be enhanced through an ensemble of multiple FTM-perturbed surrogate models. Extensive experiments on the ImageNet-compatible dataset across various DNN models demonstrate that our method achieves significant improvements over state-of-the-art methods while maintaining low computational cost.1 Kaisheng Liang, Xuelong Dai, Yanjie Li 0006, Dong Wang 0042, Bin Xiao 0001 |
CVPR | 3 |
| 2025 | UV-Attack: Physical-World Adversarial Attacks on Person Detection via Dynamic-NeRF-based UV MappingabstractRecent works have attacked person detectors using adversarial patches or static-3D-model-based texture modifications. However, these methods suffer from low attack success rates when faced with significant human movements. The primary challenge stems from the highly non-rigid nature of the human body and clothing. Current attacks fail to model these 3D non-rigid deformations caused by varied actions.
Fortunately, recent research has shown significant progress in using NeRF for dynamic human modeling.
In this paper, we introduce \texttt{UV-Attack}, a novel physical adversarial attack achieving high attack success rates in scenarios involving extensive and unseen actions. We address the challenges above by leveraging dynamic-NeRF-based UV mapping. Our method can generate human images across diverse actions and viewpoints and even create novel unseen actions by sampling from the SMPL parameter space. While dynamic NeRF models are capable of modeling human bodies, modifying their clothing textures is challenging due to the texture being embedded within neural network parameters.
To overcome this, \texttt{UV-Attack} generates UV maps instead of RGB images and modifies the texture stacks. This approach enables real-time texture edits and makes attacks more practical. Finally, we propose a novel Expectation over Pose Transformation loss (EoPT) to improve the evasion success rate on unseen poses and views.
Our experiments show that \texttt{UV-Attack} achieves a 92.7\% attack success rate against the FastRCNN model across varied poses in dynamic video settings, significantly outperforming the state-of-the-art AdvCaT attack, which only had a 28.5\% ASR. Moreover, we achieve 49.5\% ASR on the latest YOLOv8 detector in black-box settings. The code is available at https://github.com/PolyLiYJ/UV-Attack Yanjie Li 0006, Kaisheng Liang, Bin Xiao 0001 |
ICLR | 1 |
| 2025 | StyleGuard: Preventing Text-to-Image-Model-based Style Mimicry Attacks by Style PerturbationsabstractRecently, text-to-image diffusion models have been widely used for style mimicry and personalized customization through methods such as DreamBooth and Textual Inversion. This has raised concerns about intellectual property protection and the generation of deceptive content.
Recent studies, such as Glaze and Anti-DreamBooth, have proposed using adversarial noise to protect images from these attacks. However, recent purification-based methods, such as DiffPure and Noise Upscaling, have successfully attacked these latest defenses, showing the vulnerabilities of these methods.
Moreover, present methods show limited transferability across models, making them less effective against unknown text-to-image models.
To address these issues, we propose a novel anti-mimicry method, StyleGuard. We propose a novel style loss that optimizes the style-related features in the latent space to make it deviate from the original image, which improves model-agnostic transferability.
Additionally, to enhance the perturbation's ability to bypass diffusion-based purification, we designed a novel upscale loss that involves ensemble purifiers and upscalers during training.
Extensive experiments on the WikiArt and CelebA datasets demonstrate that StyleGuard outperforms existing methods in robustness against various transformations and purifications, effectively countering style mimicry in various models. Moreover, StyleGuard is effective on different style mimicry methods, including DreamBooth and Textual Inversion. The code is available at \url{https://github.com/PolyLiYJ/StyleGuard}. Yanjie Li 0006, Xinqi Lyu, Bin Xiao 0001 |
NeurIPS | 1 |
| 2025 | LOMIA: Label-Only Membership Inference Attacks against Pre-trained Large Vision-Language ModelsabstractLarge vision-language models (VLLMs) have driven significant progress in multi-modal systems, enabling a wide range of applications across domains such as healthcare, education, and content generation. Despite the success, the large-scale datasets used to train these models often contain sensitive or personally identifiable information, raising serious privacy concerns. To audit and better understand such risks, membership inference attacks (MIAs) have become a key tool. However, existing MIAs against VLLMs predominantly assume access to full-model logits, which are typically unavailable in many practical deployments. To facilitate MIAs in a more realistic and restrictive setting, we propose a novel framework: label-only membership inference attacks (LOMIA) targeting pre-trained VLLMs where only the model’s top-1 prediction is available. Within this framework, we propose three effective attack methods, all of which exploit the intuition that training samples are more likely to be memorized by the VLLMs, resulting in outputs that exhibit higher semantic alignment and lower perplexity. Our experiments show that our framework surpasses existing label-only attack adaptations for different VLLMs and competes with state-of-the-art logits-based attacks across all metrics on three widely used open-source VLLMs and GPT-4o. Xinqi Lyu, Dong Wang 0042, Yanjie Li 0006, Bin Xiao 0001 |
NeurIPS | 4 |
| 2024 | Diffusion Models as Strong AdversariesabstractDiffusion models have demonstrated their great ability to generate high-quality images for various tasks. With such a strong performance, diffusion models can potentially pose a severe threat to both humans and deep learning models. However, their abilities as adversaries have not been well explored. Among different adversarial scenarios, the no-box adversarial attack is the most practical one, as it assumes that the attacker has no access to the training dataset or the target model. Existing works still require some data from the training dataset, which may not be feasible in real-world scenarios. In this paper, we investigate the adversarial capabilities of diffusion models by conducting no-box attacks solely using data generated by diffusion models. Specifically, our attack method generates a synthetic dataset using diffusion models to train a substitute model. We then employ a classification diffusion model to fine-tune the substitute model, considering model uncertainty and incorporating noise augmentation. Finally, we sample adversarial examples from the diffusion models using the average approximation over the diffusion substitute model with multiple inferences. Extensive experiments on the ImageNet dataset demonstrate that the proposed attack method achieves state-of-the-art performance in both no-box attack and black-box attack scenarios. Xuelong Dai, Yanjie Li 0006, Mingxing Duan, Bin Xiao 0001 |
IEEE Trans. Image Process. | 2 |
| 2023 | Physical-World Optical Adversarial Attacks on 3D Face RecognitionabstractThe success rate of current adversarial attacks remains low on real-world 3D face recognition tasks because the 3D-printing attacks need to meet the requirement that the generated points should be adjacent to the surface, which limits the adversarial example’ searching space. Additionally, they have not considered unpredictable head movements or the non-homogeneous nature of skin reflectance in the real world. To address the real-world challenges, we propose a novel structured-light attack against structured-light-based 3D face recognition. We incorporate the 3D reconstruction process and skin's reflectance in the optimization process to get the end-to-end attack and present 3D transform invariant loss and sensitivity maps to improve robustness. Our attack enables adversarial points to be placed in any position and is resilient to random head movements while maintaining the perturbation unnoticeable. Experiments show that our new method can attack point-cloud-based and depth-image-based 3D face recognition systems with a high success rate, using fewer perturbations than previous physical 3D adversarial attacks. Yanjie Li 0006, Yiquan Li, Xuelong Dai, Songtao Guo, Bin Xiao 0001 |
CVPR | 1 |