EDBT 2026 Demo / reviewers in the wild / expert
Zihan Yuan
dblp:71/8651
· DBLP profile ↗
23ranked-venue papers
10as first author
17since 2021 · last 2026
0000-0002-8972-9054ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 13 · 7 first-author · 8 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 4 since 2021Computer networks · 4 · 2 first-author · 4 since 2021Systems, architecture and hardware · 2 · 2 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Verifiable Privacy-Preserving Neural Network Inference via Multi-Key Homomorphic EncryptionabstractWith the proliferation of Internet of Things (IoT) devices, deep learning model inference that guarantees data privacy has attracted significant research interest. Secure inference based on homomorphic encryption offers a promising solution by ensuring rigorous data confidentiality. However, in typical cloud-based inference services, ciphertexts are encrypted under a single key, requiring all participants to share the same decryption key. This contradicts real-world scenarios where multiple participants (e.g., individual IoT devices or users) typically hold their own private keys. To address this issue, this paper designs a series of secure sub-protocols based on multi-key homomorphic encryption (MK-HE), enabling the computation of nonlinear functions while preserving data privacy across multiple keys. Furthermore, considering the potential malicious nature of cloud servers, we incorporate a commitment protocol to ensure the verifiability of inference results and prevent the server from returning incorrect outcomes. Theoretical and security analyses demonstrate the efficiency and privacy of our proposed protocol, which achieves lower computational time and reduced communication overhead without compromising security. Guanghui He 0003, Zihan Yuan |
IEEE Internet Things J. | 2 |
| 2026 | Erratum to "Verifiable Privacy-Preserving Neural Network Inference via Multi-Key Homomorphic Encryption"
Guanghui He 0003, Zihan Yuan |
IEEE Internet Things J. | 2 |
| 2025 | Multi-View Community-Contrastive Graph Attention Network for Fmri-Based Alzheimer's Disease ClassificationabstractFunctional brain network analysis based on fMRI is a vital tool for understanding neural mechanisms and diagnosing neurological disorders. However, existing approaches often overlook the joint modeling of topological structures and attribute information in brain connectivity graphs, limiting their performance in disease classification. To address this issue, we propose a novel Graph Neural Network framework combining multi-view modeling and supervised contrastive learning for fMRI-based Alzheimer's disease classification. Specifically, our method employs a Graph Attention Network (GAT) to encode structural relationships and a Multi-Layer Perceptron (MLP) to capture node attribute features. Furthermore, unsupervised clustering is utilized to extract community-level representations, capturing mesoscale brain network organization. To enhance feature robustness and discriminability, we introduce a dual-view supervised contrastive learning strategy. Extensive experiments on a cohort of 480 subjects from the Alzheimer's Disease Neuroimaging Initiative (ADNI) demonstrate that our proposed model consistently outperforms state-of-the-art methods across key metrics, including accuracy, recall, F1-score, and AUC, highlighting its robustness and effectiveness for Alzheimer's disease diagnosis. Bo Xu 0008, Baijiang Xu, Zihan Yuan, Jinshi Yu, Zhehuan Zhao, Lin Lin 0008 |
BIBM | 3 |
| 2025 | Convex Hull-based Algebraic Constraint for Visual Quadric SLAMabstractUsing Quadrics as the object representation has the benefits of both generality and closed-form projection derivation between image and world spaces. Although numerous constraints have been proposed for dual quadric reconstruction, we found that many of them are imprecise and provide minimal improvements to localization. After scrutinizing the existing constraints, we introduce a concise yet more precise convex hull-based algebraic constraint for object landmarks, which is applied to object reconstruction, frontend pose estimation, and backend bundle adjustment. This constraint is designed to fully leverage precise semantic segmentation, effectively mitigating mismatches between complex-shaped object contours and dual quadrics. Experiments on public datasets demonstrate that our approach is applicable to both monocular and RGB-D SLAM and achieves improved object mapping and localization than existing quadric SLAM methods. The implementation of our method is available at https://github.com/tiev-tongji/convexhull-based-algebraic-constraint. Junqiao Zhao, Shuangfu Song, Zhongyang Zhu, Zihan Yuan, Chen Ye 0002, Tiantian Feng, Qiankun Yu |
IROS | 5 |
| 2025 | Protecting copyright of stable diffusion models from ambiguity attacks
Zihan Yuan, Li Li 0103, Zichi Wang, Xinpeng Zhang 0001 |
Signal Process. | 1 |
| 2025 | Watermark Removal Attack Against Text-to-Image Generative Model WatermarkingabstractThe artist's style can be quickly imitated by fine-tuning a text-to-image model using artist's artworks, which raises serious copyright concerns. Scholars have proposed many watermarking methods to protect the artists' copyright. To evaluate the security and enhance the performance of existing watermarking, this paper proposes a watermark removal attack for text-to-image generative model watermarking for the first time. This attack aims to invalidate watermarking designed to detect art theft mimicry in text-to-image models. In this method, a watermark recognition network and a watermark removal network are designed. The watermark recognition network identifies whether an artwork contains watermark, and the watermark removal network is used to remove it. Consequently, text-to-image models fine-tuned with watermark-removed artworks can reproduce an artist's style while evading watermark detection. This makes the copyright authentication of artworks ineffective. Experiments show that the proposed attack can effectively remove watermarks, with watermark extraction accuracy dropping below 48.64%. Additionally, the images after watermark removal retain high similarity to the original images, with PSNR exceeding 27.96 and SSIM exceeding 0.92. Zihan Yuan, Li Li 0103, Zichi Wang, Jingyuan Jiang, Xinpeng Zhang 0001 |
IEEE Signal Process. Lett. | 1 |
| 2025 | Generative Image Steganography Based on Text-to-Image Multimodal Generative ModelabstractImage steganography, the technique of hiding secret messages within images, has recently advanced with generative image steganography, which hides messages during image creation. However, current generative steganography methods often face criticism for their low extraction accuracy and poor robustness—particularly their vulnerability to JPEG compression. To address these challenges, we propose a novel generative image steganography method based on the text-to-image multimodal generative model (StegaMGM). StegaMGM utilizes the initial random normalization distribution in the generative process of latent diffusion models (LDMs), the secret message is hidden in the generated image through message sampling, ensuring it follows the same probability distribution as typical image generative. The content of the stego image can also be controlled through the prompts. On the receiver side, using the shared prompt and diffusion inversion, can extract secret message with high accuracy. In the experimental section, we conducted detailed experiments to demonstrate the advantages of our proposed StegaMGM framework in extraction accuracy, resistance to JPEG compression, and security. Jingyuan Jiang, Zichi Wang, Zihan Yuan, Xinpeng Zhang 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2025 | Integrity Protection of Generative Adversarial Networks Using Fragile WatermarkingabstractDeep learning has made remarkable achievements in the field of artificial intelligence. However, a well-trained deep neural network is at risk of being tampered with. Although some model watermarking schemes have been proposed to solve this problem, most of them are only oriented to discriminant models, and the integrity authentication schemes for generative models are urgently lacking. Especially, the integrity authentication problem of generative adversarial networks (GANs) that plays an important role in computer vision has not been properly solved. To address this problem, we propose a fragile model watermarking framework for GANs. Specifically, we use a secret key to generate specific information as the label and combine it with the watermark to form a trigger set. Then, we use the trigger set to train the GAN, the training process does not damage the model performance. We can achieve integrity authentication of the GAN using the output of the GAN for the specific label. A large number of experiments show that our proposed method has excellent performance, which can realize the integrity authentication of GANs. What’s more, the proposed method has good generalization and can be easily applied to different GAN architectures. Zihan Yuan, Li Li 0103, Zichi Wang, Xinpeng Zhang 0001 |
ACM Trans. Multim. Comput. Commun. Appl. | 1 |
| 2024 | Semi-fragile neural network watermarking for content authentication and tampering localization
Zihan Yuan, Xinpeng Zhang 0001, Zichi Wang, Zhao-Xia Yin |
Expert Syst. Appl. | 1 |
| 2024 | Watermarking for Stable Diffusion ModelsabstractIn the scenario of text data and image data interact of the Internet of Things (IoT) applications, the problem of copyright protection of the text-to-image models is threatened due to the replicability and portability of the neural network model. In order to solve this problem, we propose a model watermarking for the typical text-to-image diffusion models (DMs)–stable DMs (SDMs), which is a key aspect of the copyright protection of text-to-image models. Our scheme injects watermark into an SDM and makes the SDM generate watermark through a predefined prompt. The ownership of the SDM can be proved by the different output results of the model to the predefined prompt. The proposed method does not require raw training data and internal details of SDMs, which only need a predefined prompt and watermark to fine tune the pretrained SDM with minimal epoch. A large number of experiments show that our watermarking technology is effective, and can realize the copyright protection of the SDMs on the premise of less influence on the original function. Zihan Yuan, Li Li 0103, Zichi Wang, Xinpeng Zhang 0001 |
IEEE Internet Things J. | 1 |
| 2024 | Ambiguity attack against text-to-image diffusion model watermarking
Zihan Yuan, Li Li 0103, Zichi Wang, Xinpeng Zhang 0001 |
Signal Process. | 1 |
| 2024 | RDCIM: RISC-V Supported Full-Digital Computing-in-Memory Processor With High Energy Efficiency and Low Area OverheadabstractDigital computing-in-memory (DCIM) that merges computing logic into memory has been proven to be an efficient architecture for accelerating multiply-and-accumulates (MACs). However, low energy efficiency and high area overhead pose a primary restriction for integrating DCIM in re-configurable processors required for multi-functional workloads. To alleviate this dilemma, a novel RISC-V supported full-digital computing-in-memory processor (RDCIM) is designed and fabricated with 55nm CMOS technology. In RDCIM, an adding-on-memory-boundary (AOMB) scheme is adopted to improve the energy efficiency of DCIM. Meanwhile, a multi-precision adaptive accumulator (MPAA) and a serial-parallel conversion supported SRAM buffer (SPBUF) are employed to reduce the area overhead caused by the peripheral circuits and the intermediate buffer for multi-precision support. The results show that the energy efficiency in our design is 16.6 TOPS/W (8-bit) and 66.3 TOPS/W (4-bit). Compared to related works, the proposed RDCIM macro shows a maximum energy efficiency improvement of 1.22$\times$in a continuous computing scenario, an area saving of 1.22$\times$in the accumulator, and an area saving of 3.12$\times$in the input buffer. Moreover, in RDCIM, 5 fine-grained RISC-V extended instructions are designed to dynamically adjust the state of DCIM, reaching 1.2$\times$computation efficiency. Wente Yi, Kefan Mo, Wenjia Wang 0011, Yejun Zeng, Zihan Yuan, Bojun Cheng, Biao Pan |
IEEE Trans. Circuits Syst. I Regul. Pap. | 6 |
| 2023 | An Assessment of the Influence of Interaction and Recommendation Approaches on the Formation of Information Filter Bubbles
Zihan Yuan, Weihua Li 0007, Quan Bai 0001 |
PKAW | 1 |
| 2021 | A fusion-domain color image watermarking based on Haar transform and image correction
Decheng Liu, Qingtang Su, Zihan Yuan |
Expert Syst. Appl. | 3 |
| 2021 | A blind color digital image watermarking method based on image correction and eigenvalue decomposition
Decheng Liu, Qingtang Su, Zihan Yuan |
Signal Process. Image Commun. | 3 |
| 2021 | A color watermarking scheme in frequency domain based on quaternary coding
Decheng Liu, Qingtang Su, Zihan Yuan |
Vis. Comput. | 3 |
| 2021 | A blind image watermarking scheme combining spatial domain and frequency domain
Zihan Yuan, Qingtang Su, Decheng Liu |
Vis. Comput. | 1 |
| 2020 | Fast and robust image watermarking method in the spatial domainabstractTo solve the copyright protection problem of a colour image, a new blind colour image watermarking method combining a discrete cosine transform (DCT) in the spatial domain is presented in this study. The advantages of the spatial‐domain watermarking algorithm and frequency‐domain one are made full use in this scheme. Based on the different quantisation steps in red, green, and blue three‐layer images, the processes of watermark embedding and blind extraction are completed in the spatial domain without a real DCT domain. The scheme is realised by using the unique features of the direct current (DC) coefficient and the relativity of DC coefficients between adjacent pixel blocks. This scheme can effectively solve the problems of the large‐capacity colour image watermarking algorithm, such as long‐running time and weak robustness. Comparing with other advanced watermarking algorithms, the presented scheme has better invisibility, stronger robustness, and higher real‐time performance. Zihan Yuan, Qingtang Su, Decheng Liu |
IET Image Process. | 1 |
| 2020 | A blind color image watermarking scheme with variable steps based on Schur decomposition
Decheng Liu, Zihan Yuan, Qingtang Su |
Multim. Tools Appl. | 2 |
| 2020 | A combined domain watermarking algorithm of color image
Qingtang Su, Huanying Wang, Decheng Liu, Zihan Yuan |
Multim. Tools Appl. | 4 |
| 2020 | DCT-based color digital image blind watermarking method with variable steps
Zihan Yuan, Decheng Liu, Huanying Wang, Qingtang Su |
Multim. Tools Appl. | 1 |
| 2019 | A new watermarking scheme for colour image using QR decomposition and ternary coding
Qingtang Su, Decheng Liu, Zihan Yuan, Hongye Ning |
Multim. Tools Appl. | 4 |
| 2016 | Conjugacy relations of prefix codes
Zhenhe Cui, Zihan Yuan |
Theor. Comput. Sci. | 3 |