EDBT 2026 Demo / reviewers in the wild / expert
Hao Wu 0078
dblp:72/4250-78
· DBLP profile ↗
12ranked-venue papers
2as first author
12since 2021 · last 2026
0000-0003-2324-2152ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 5 · 5 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A survey on JPEG image forensics: Exploring key advances and persistent challenges in compression and quantization analysis
Hao Wang 0060, Xin Cheng 0018, Jiawei Zhang 0011, Hao Wu 0078, Xue Xie, Xiangyang Luo 0001, Bin Ma 0003 |
Comput. Secur. | 4 |
| 2026 | Anti-forensic for quantization steps estimation based on direct and preemptive adversarial attacks
Jiawei Zhang 0011, Hao Wu 0078, Xin Cheng 0018, Xiangyang Luo 0001, Bin Ma 0003, Hao Wang 0060 |
Eng. Appl. Artif. Intell. | 3 |
| 2026 | SLIM: Stable Latent Integration for Robust Watermark in Diffusion ModelabstractEmbedding watermarks in the diffusion latent space improves robustness but often alters visual content due to the distribution shift between watermarked and clean latent variables. To address this issue, stable latent integration watermark (SLIM) is proposed in this paper, in which watermarks are integrated into the features output by the noise prediction network of a diffusion model, while ensuring that the perturbation introduced in the diffusion latent space remains negligible. Specifically, a watermark encoder–decoder is first trained to convert binary watermark sequences into watermark latent variables that are dimensionally compatible with the diffusion latent variables, enabling flexible and reliable embedding and extraction. The watermark latent variables are processed through the first down-sampling block of the denoising U-Net, and the resulting watermark features are fused with the block output to minimize interference with image semantics. To counteract the perturbations in diffusion features induced by watermark embedding and to ensure accurate watermark extraction, the denoising U-Net is efficiently fine-tuned using a low-rank adaptation module. Experimental results demonstrate that SLIM achieves superior generation quality while exhibiting exceptional robustness against diverse attacks compared with baseline methods. Code will be available at https://github.com/XiaoxiKong/SLIM. Xiaoxi Kong, Pengdi Chen, Bin Li 0011, Jieyu Yuan, Zhanchuan Cai, Hao Wu 0078, Lifeng Liang |
IEEE Trans. Circuits Syst. Video Technol. | 6 |
| 2026 | HENet: A Heterogeneous Encoding Network for General and Robust Adversarial Example GenerationabstractGenerator-based adversarial attack methods aim to fool deep neural networks (DNNs) by training a generator for crafting adversarial examples (AEs). However, as DNNs evolve from Convolutional Neural Networks (CNNs) to Transformers, the existing generator-based methods can hardly achieve satisfactory attack performance against different target model architectures in semi-whitebox attack scenarios. In addition, the generated AEs are susceptible to various distortions (especially for JPEG compression with low quality factors), which deteriorate the attack ability and increase the unreliability. To address these issues, we propose a dual-branch guided generative model called Heterogeneous Encoding Network (HENet) to form a robust generator-based adversarial attack framework. Specifically, our HENet introduces an Adaptive Feature Fusion Module (AFFM) to solve the dimensions and representativeness contradictions between CNNs and Transformers, which steers the perturbation generation based on a richer latent space and achieves better general attack ability. To further improve the robustness against JPEG compression, we design and integrate a Dynamic Differentiable JPEG Simulator (DDJS), which introduces an adaptive quantization mask to determine the flow of the gradient backpropagation in each frequency position. Extensive experiments prove the proposed method achieves a better attack success rate, lower perturbation magnitude, and higher robustness for various target network architectures under compressed, distorted, and lossless scenarios. Our codes will be made publicly available. Jiawei Zhang 0011, Hao Wang 0060, Hao Wu 0078, Bin Li 0011, Xiangyang Luo 0001, Bin Ma 0003 |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2025 | Pixel2Feature Attack (P2FA): Rethinking the Perturbed Space to Enhance Adversarial TransferabilityabstractAdversarial examples have been shown to deceive Deep Neural Networks (DNNs), raising widespread concerns about this security threat. More seriously, as different DNN models share critical features, feature-level attacks can generate transferable adversarial examples, thereby deceiving black-box models in real-world scenarios. Nevertheless, we have theoretically discovered the principle behind the limited transferability of existing feature-level attacks: Their attack effectiveness is essentially equivalent to perturbing features in one step along the direction of feature importance in the feature space, despite performing multiple perturbations in the pixel space. This finding indicates that existing feature-level attacks are inefficient in disrupting features through multiple pixel-space perturbations. To address this problem, we propose a P2FA that efficiently perturbs features multiple times. Specifically, we directly shift the perturbed space from pixel to feature space. Then, we perturb the features multiple times rather than just once in the feature space with the guidance of feature importance to enhance the efficiency of disrupting critical shared features. Finally, we invert the perturbed features to the pixels to generate more transferable adversarial examples. Numerous experimental results strongly demonstrate the superior transferability of P2FA over State-Of-The-Art (SOTA) attacks. Renpu Liu, Hao Wu 0078, Jiawei Zhang 0011, Xin Cheng 0018, Xiangyang Luo 0001, Bin Ma 0003 |
ICML | 2 |
| 2025 | LDSGAN: Unsupervised Image-to-Image Translation With Long-Domain Search GAN for Generating High-Quality Anime ImagesabstractImage‐to‐image ( I2I ) translation has emerged as a valuable tool for privacy protection in the digital age, offering effective ways to safeguard portrait rights in cyberspace. In addition, I2I translation is applied in real‐world tasks such as image synthesis, super‐resolution, virtual fitting, and virtual live streaming. Traditional I2I translation models demonstrate strong performance when handling similar datasets. However, when the domain distance between two datasets is large, translation quality may degrade significantly due to notable differences in image shape and edges. To address this issue, we propose Long‐Domain Search GAN ( LDSGAN ), an unsupervised I2I translation network that employs a GAN structure as its backbone, incorporating a novel Real‐Time Routing Search ( RTRS ) module and Sketch Loss. Specifically, RTRS aids in expanding the search space within the target domain, aligning feature projection with images closest to the optimization target. Additionally, Sketch Loss retains human visual similarity during long‐domain distance translation. Experimental results indicate that LDSGAN surpasses existing I2I translation models in both image quality and semantic similarity between input and generated images, as reflected by its mean FID and LPIPS scores of 31.509 and 0.581, respectively. Hao Wang 0060, Chenbin Wang, Xin Cheng 0018, Hao Wu 0078, Jiawei Zhang 0011, Xiangyang Luo 0001, Bin Ma 0003 |
Int. J. Intell. Syst. | 4 |
| 2025 | A GAN-based anti-forensics method by modifying the quantization table in JPEG header file
Hao Wang 0060, Xin Cheng 0018, Hao Wu 0078, Xiangyang Luo 0001, Bin Ma 0003, Hui Zong, Jiawei Zhang 0011 |
J. Vis. Commun. Image Represent. | 3 |
| 2025 | Invisible Adversarial Watermarking: A Novel Security Mechanism for Enhancing Copyright ProtectionabstractInvisible watermarking can be used as an important tool for copyright certification in the Metaverse. However, with the advent of deep learning, Deep Neural Networks (DNNs) have posed new threats to this technique. For example, artificially trained DNNs can perform unauthorized content analysis and achieve illegal access to protected images. Furthermore, some specially crafted DNNs may even erase invisible watermarks embedded within the protected images, which eventually leads to the collapse of this protection and certification mechanism. To address these issues, inspired by the adversarial attack, we introduce Invisible Adversarial Watermarking (IAW), a novel security mechanism to enhance the copyright protection efficacy of watermarks. Specifically, we design an Adversarial Watermarking Fusion Model (AWFM) to efficiently generate Invisible Adversarial Watermark Images (IAWIs). By modeling the embedding of watermarks and adversarial perturbations as a unified task, the generated IAWIs can effectively defend against unauthorized identification, access, and erase via DNNs and identify the ownership by extracting the embedded watermark. Experimental results show that the proposed IAW presents superior extraction accuracy, attack ability, and robustness on different DNNs, and the protected images maintain good visual quality, which ensures its effectiveness as an image protection mechanism. Jiawei Zhang 0011, Hao Wu 0078, Xiangyang Luo 0001, Bin Ma 0003 |
ACM Trans. Multim. Comput. Commun. Appl. | 4 |
| 2023 | Enhancing Robustness and Imperceptibility of Blind Watermarking with Improved Message ProcessorabstractThe current state-of-the-art(SOTA) blind watermark embedding method MBRS based on deep learning is less robust to Crop, and additional diffusion layers need to be added for optimization. However, the diffusion layer will make the model less robust to noise other than Crop. Therefore, MBRS which needs to add or delete components is not a practical watermarking framework. Not only that, MBRS is easy to generate chessboard artifacts, resulting in the generated watermark being easy to be detected by the human eye. Therefore, we construct a more generalized watermarking framework and propose an improved blind watermarking method. The method addresses the shortcomings of MBRS by using an improved message processor with sub-pixel convolution layers and low-frequency features and incorporating double discriminators to improve the performance of the network. Extensive experiments show that our method demonstrates superior results compared to the SOTA method. Baowei Wang, Changyu Dai, Bin Li 0011, Weiqian Zheng, Hao Wu 0078 |
ICASSP | 7 |
| 2023 | Improving the Transferability of Adversarial Attacks through Experienced Precise Nesterov MomentumabstractDeep neural networks are vulnerable to adversarial examples. Although the adversarial example has superior white-box attack success rate, its transferability is poor under the black-box setting. Momentum is often integrated into attacks so as to prevent adversarial examples from overfitting the source model and improve the transferability of adversarial examples. How-ever, conventional momentum merely accumulates few gradients during the early iterations, resulting in the early adversarial examples already overfitting the source model. Therefore, we propose Experienced Momentum (EM), which is trained on a set of models derived by Random Channels Swapping (RCS). Since EM takes the direction of loss increasing for multiple models into account, assigning EM to the initial value of momentum to makes adversarial examples transferable across models during the early iterations. Moreover, conventional Nesterov momentum only take the previous gradients into consideration but ignore the gradient of the current data point during the whole pre-update, making the estimate of the next position imprecise. It prompts us to propose Precise Nesterov momentum (PN), which not only retains the looking-ahead property but also adopts the gradient of the current data point during the pre-update. To further improve transferability, we combine EM and PN as Experienced Precise Nesterov momentum (EPN). Extensive experiments on the ImageNet dataset against normally trained and defense models demonstrate that the proposed EPN is more effective than conventional momentum for improving transferability. Hao Wu 0078, Jiawei Zhang 0011, Bin Ma 0003, Xiangyang Luo 0001 |
IJCNN | 1 |
| 2023 | Improving Transferability of Adversarial Attacks with Gaussian Gradient Enhance Momentum
Maoyuan Wang, Hao Wu 0078, Bin Ma 0003, Xiangyang Luo 0001 |
PRCV (9) | 3 |
| 2022 | Improving the Transferability of Adversarial Attacks Through Both Front and Rear Vector Method
Hao Wu 0078, Jiawei Zhang 0011, Xiangyang Luo 0001, Bin Ma 0003 |
IWDW | 1 |