EDBT 2026 Demo / reviewers in the wild / expert
Jiaming Zhang 0006
dblp:81/10010-6
· DBLP profile ↗
18ranked-venue papers
10as first author
16since 2021 · last 2026
0000-0003-0991-7109ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 13 · 7 first-author · 11 since 2021Artificial intelligence and machine learning · 7 · 5 first-author · 7 since 2021Computer networks · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | NAP-Tuning: Neural Augmented Prompt Tuning for Adversarially Robust Vision-Language ModelsabstractVision-Language Models (VLMs) such as CLIP have demonstrated remarkable capabilities in understanding relationships between visual and textual data through joint embedding spaces. Despite their effectiveness, these models remain vulnerable to adversarial attacks, particularly in the image modality, posing significant security concerns. Building upon our previous work on Adversarial Prompt Tuning (AdvPT), which introduced learnable text prompts to enhance adversarial robustness in VLMs without extensive parameter training, we present a significant extension by introducing the Neural Augmentor framework for Multi-modal Adversarial Prompt Tuning (NAP-Tuning). As a significant extension, NAP-Tuning first establishes a comprehensive multi-modal (text and visual) and multi-layer prompting framework. The core of this framework is a targeted structural augmentation for feature-level purification, implemented through our Neural Augmentor approach. This framework implements feature purification by incorporating TokenRefiners-lightweight neural modules that learn to reconstruct purified features via residual connections-to directly address distortions in the feature space. This structural intervention is what enables the multi-modal and multi-layer system to effectively perform modality-specific and layer-specific feature rectification. Comprehensive experiments demonstrate that NAP-Tuning significantly outperforms existing methods across various datasets and attack types. Notably, our approach shows significant improvements over the strongest baselines under the challenging AutoAttack benchmark, outperforming them by 32.3% on ViT-B16 and 31.3% on ViT-B32 architectures while maintaining competitive clean accuracy. This work highlights the efficacy of internal feature-level intervention in prompt tuning for adversarial robustness, moving beyond input-side alignment approaches to create an adaptive defense mechanism that can identify and rectify adversarial perturbations across embedding spaces. Jiaming Zhang 0006, Xin Wang 0119, Xingjun Ma, Lingyu Qiu, Yu-Gang Jiang 0001, Jitao Sang 0001 |
IEEE Trans. Pattern Anal. Mach. Intell. | 1 |
| 2026 | SF-QC: Explore the Selection Bias of Large Language Models in Zero-Shot Out-of-Distribution Intent DetectionabstractOut-of-distribution (OOD) intent detection aims to identify user queries that exceed predefined intent categories and is a crucial technology for ensuring interaction reliability and user experience in practical applications such as dialogue systems and intelligent customer service. Although large language models (LLMs) perform excellently in natural language processing tasks, they encounter difficulties with zero-shot OOD intent detection. This article reveals the dual biases of LLMs in zero-shot OOD intent detection: 1) LLMs tend to prefer the intents that are presented earlier in the intent list; and 2) LLMs frequently misclassify unknown intent as in-distribution (ID) intent. These biases severely limit the deployment of LLMs in intent-recognition systems that require high reliability. To address this problem, we propose a novel semantics-based sorting-filtering and querying-confirming (SF-QC) method: the semantic sorting-filtering (SF) module dynamically adjusts the intent list to mitigate position preference, and then the querying-confirming (QC) module deeply validates the initial ID response to reduce OOD misclassification, starting from the root cause of biases to guide the LLM to make unbiased judgments. Experiments on two mainstream intent datasets show that our proposed SF-QC approach has up to 7.82% (Macro-F1) and 9.76% (ACC) improvement in overall performance, and up to 14.9% (Macro-F1) and 20.66% (ACC) improvement in OOD performance over the chain-of-thought (CoT) method. The excellent detection performance of SF-QC provides key technical support for the robust deployment of LLMs in practical applications such as dialogue systems, helping to reduce system risks and enhance user experience. Hengyang Lu, Xin-Yi Liu, Jiaming Zhang 0006, Chenyou Fan, Wei Fang 0001 |
IEEE Trans. Comput. Soc. Syst. | 3 |
| 2025 | TAPT: Test-Time Adversarial Prompt Tuning for Robust Inference in Vision-Language ModelsabstractLarge pre-trained Vision-Language Models (VLMs) such as CLIP have demonstrated excellent zero-shot generalizability across various downstream tasks. However, recent studies have shown that the inference performance of CLIP can be greatly degraded by small adversarial perturbations, especially its visual modality, posing significant safety threats. To mitigate this vulnerability, in this paper, we propose a novel defense method called Test-Time Adversarial Prompt Tuning (TAPT) to enhance the inference robustness of CLIP against visual adversarial attacks. TAPT is a test-time defense method that learns defensive bimodal (textual and visual) prompts to robustify the inference process of CLIP. Specifically, it is an unsupervised method that optimizes the defensive prompts for each test sample by minimizing a multi-view entropy and aligning adversarial-clean distributions. We evaluate the effectiveness of TAPT on 11 benchmark datasets, including ImageNet and 10 other zero-shot datasets, demonstrating that it enhances the zero-shot adversarial robustness of the original CLIP by at least 48.9% against AutoAttack (AA), while largely maintaining performance on clean examples. Moreover, TAPT outperforms existing adversarial prompt tuning methods across various backbones, achieving an average robustness improvement of at least 36.6%. Code is available at https://github.com/xinwong/TAPT. Xin Wang 0119, Kai Chen 0027, Jiaming Zhang 0006, Jingjing Chen 0001, Xingjun Ma |
CVPR | 3 |
| 2025 | Anyattack: Towards Large-scale Self-supervised Adversarial Attacks on Vision-language ModelsabstractDue to their multimodal capabilities, Vision-Language Models (VLMs) have found numerous impactful applications in real-world scenarios. However, recent studies have revealed that VLMs are vulnerable to image-based adversarial attacks. Traditional targeted adversarial attacks require specific targets and labels, limiting their real-world impact. We present AnyAttack, a self-supervised framework that transcends the limitations of conventional attacks through a novel foundation model approach. By pretraining on the massive LAION-400M dataset without label supervision, AnyAttack achieves unprecedented flexibility - enabling any image to be transformed into an attack vector targeting any desired output across different VLMs. This approach fundamentally changes the threat landscape, making adversarial capabilities accessible at an unprecedented scale. Our extensive validation across five open-source VLMs (CLIP, BLIP, BLIP2, InstructBLIP, and MiniGPT-4) demonstrates AnyAttack’s effectiveness across diverse multimodal tasks. Most concerning, Any-Attack seamlessly transfers to commercial systems including Google Gemini, Claude Sonnet, Microsoft Copilot and OpenAI GPT, revealing a systemic vulnerability requiring immediate attention. Jiaming Zhang 0006, Junhong Ye, Xingjun Ma, Yige Li, Yunfan Yang, Jitao Sang 0001, Dit-Yan Yeung |
CVPR | 1 |
| 2025 | Enhancing few-shot out-of-distribution intent detection by reducing attention misallocation
Hengyang Lu, Jiaming Zhang 0006, Yuntao Du 0001, Chong-Jun Wang, Wei Fang 0001, Xiaojun Wu 0001 |
Neurocomputing | 2 |
| 2025 | MF-CLIP: Leveraging CLIP as Surrogate Models for No-Box Adversarial Attacks
Jiaming Zhang 0006, Lingyu Qiu, Qi Yi, Yige Li, Jitao Sang 0001, Changsheng Xu, Dit-Yan Yeung |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Adversarial Prompt Tuning for Vision-Language Models
Jiaming Zhang 0006, Xingjun Ma, Xin Wang 0119, Lingyu Qiu, Jiaqi Wang 0003, Yu-Gang Jiang 0001, Jitao Sang 0001 |
ECCV (45) | 1 |
| 2023 | ImageNet Pre-training Also Transfers Non-robustnessabstractImageNet pre-training has enabled state-of-the-art results on many tasks. In spite of its recognized contribution to generalization, we observed in this study that ImageNet pre-training also transfers adversarial non-robustness from pre-trained model into fine-tuned model in the downstream classification tasks. We first conducted experiments on various datasets and network backbones to uncover the adversarial non-robustness in fine-tuned model. Further analysis was conducted on examining the learned knowledge of fine-tuned model and standard model, and revealed that the reason leading to the non-robustness is the non-robust features transferred from ImageNet pre-trained model. Finally, we analyzed the preference for feature learning of the pre-trained model, explored the factors influencing robustness, and introduced a simple robust ImageNet pre-training solution. Our code is available at https://github.com/jiamingzhang94/ImageNet-Pretraining-transfers-non-robustness. Jiaming Zhang 0006, Jitao Sang 0001, Qi Yi, Yunfan Yang, Huiwen Dong, Jian Yu 0001 |
AAAI | 1 |
| 2023 | Unlearnable Clusters: Towards Label-Agnostic Unlearnable ExamplesabstractThere is a growing interest in developing unlearnable examples (UEs) against visual privacy leaks on the Internet. UEs are training samples added with invisible but unlearnable noise, which have been found can prevent unauthorized training of machine learning models. UEs typically are generated via a bilevel optimization framework with a surrogate model to remove (minimize) errors from the original samples, and then applied to protect the data against unknown target models. However, existing UE generation methods all rely on an ideal assumption called label-consistency, where the hackers and protectors are assumed to hold the same label for a given sample. In this work, we propose and promote a more practical label-agnostic setting, where the hackers may exploit the protected data quite differently from the protectors. E.g., amclass unlearnable dataset held by the protector may be exploited by the hacker as a n-class dataset. Existing UE generation methods are rendered ineffective in this challenging setting. To tackle this challenge, we present a novel technique called Unlearnable Clusters (UCs) to generate label-agnostic unlearnable examples with cluster-wise perturbations. Furthermore, we propose to leverage Vision-and-Language Pre-trained Models (VLPMs) like CLIP as the surrogate model to improve the transferability of the crafted UCs to diverse domains. We empirically verify the effectiveness of our proposed approach under a variety of settings with different datasets, target models, and even commercial platforms Microsoft Azure and Baidu PaddlePaddle. Code is available at https://github.com/jiamingzhang94/Unlearnable-Clusters. Jiaming Zhang 0006, Xingjun Ma, Qi Yi, Jitao Sang 0001, Yu-Gang Jiang 0001, Yaowei Wang 0001, Changsheng Xu |
CVPR | 1 |
| 2023 | Low-mid adversarial perturbation against unauthorized face recognition system
Jiaming Zhang 0006, Qi Yi, Dongyuan Lu, Jitao Sang 0001 |
Inf. Sci. | 1 |
| 2023 | Attention, Please! Adversarial Defense via Activation Rectification and PreservationabstractThis study provides a new understanding of the adversarial attack problem by examining the correlation between adversarial attack and visual attention change. In particular, we observed that: (1) images with incomplete attention regions are more vulnerable to adversarial attacks; and (2) successful adversarial attacks lead to deviated and scattered activation map. Therefore, we use the mask method to design an attention-preserving loss and a contrast method to design a loss that makes the model’s attention rectification. Accordingly, an attention-based adversarial defense framework is designed, under which better adversarial training or stronger adversarial attacks can be performed through the above constraints. We hope the attention-related data analysis and defense solution in this study will shed some light on the mechanism behind the adversarial attack and also facilitate future adversarial defense/attack model design. Shangxi Wu, Jitao Sang 0001, Jiaming Zhang 0006, Jian Yu 0001 |
ACM Trans. Multim. Comput. Commun. Appl. | 4 |
| 2022 | Benign Adversarial Attack: Tricking Models for GoodnessabstractIn spite of the successful application in many fields, machine learning models today suffer from notorious problems like vulnerability to adversarial examples. Beyond falling into the cat-and-mouse game between adversarial attack and defense, this paper provides alternative perspective to consider adversarial example and explore whether we can exploit it in benign applications. We first attribute adversarial example to the human-model disparity on employing non-semantic features. While largely ignored in classical machine learning mechanisms, non-semantic feature enjoys three interesting characteristics as (1) exclusive to model, (2) critical to affect inference, and (3) utilizable as features. Inspired by this, we present brave new idea of benign adversarial attack to exploit adversarial examples for goodness in three directions: (1) adversarial Turing test, (2) rejecting malicious model application, and (3) adversarial data augmentation. Each direction is positioned with motivation elaboration, justification analysis and prototype applications to showcase its potential. Jitao Sang 0001, Jiaming Zhang 0006 |
ACM Multimedia | 3 |
| 2022 | Towards Adversarial Attack on Vision-Language Pre-training ModelsabstractWhile vision-language pre-training model (VLP) has shown revolutionary improvements on various vision-language (V+L) tasks, the studies regarding its adversarial robustness remain largely unexplored. This paper studied the adversarial attack on popular VLP models and V+L tasks. First, we analyzed the performance of adversarial attacks under different settings. By examining the influence of different perturbed objects and attack targets, we concluded some key observations as guidance on both designing strong multimodal adversarial attack and constructing robust VLP models. Second, we proposed a novel multimodal attack method on the VLP models called Collaborative Multimodal Adversarial Attack (Co-Attack), which collectively carries out the attacks on the image modality and the text modality. Experimental results demonstrated that the proposed method achieves improved attack performances on different V+L downstream tasks and VLP models. The analysis observations and novel attack method hopefully provide new understanding into the adversarial robustness of VLP models, so as to contribute their safe and reliable deployment in more real-world scenarios. Jiaming Zhang 0006, Qi Yi, Jitao Sang 0001 |
ACM Multimedia | 1 |
| 2021 | Trustworthy Multimedia AnalysisabstractThis tutorial discusses the trustworthiness issue in multimedia analysis. Starting from introducing two types of spurious correlations learned from distilling human knowledge, we partition the (visual) feature space along two dimensions of task-relevance and semantic-orientation. Trustworthy multimedia analysis ideally relies on the task-relevant semantic features and consists of three modules as trainer, interpreter and tester. These three modules essentially form a closed loop, which respectively address goals of extracting task-relevant features, extracting task-relevant semantic features, and detecting spurious correlations to be corrected by the trainer and interpreter. Xiaowen Huang 0001, Jiaming Zhang 0006, Yi Zhang 0101, Jitao Sang 0001 |
ACM Multimedia | 2 |
| 2021 | APF: An Adversarial Privacy-preserving Filter to Protect Portrait InformationabstractWhile widely adopted in practical applications, face recognition has been disputed on the malicious use of face images and potential privacy issues. Online photo sharing services accidentally act as the main approach for the malicious crawlers to exploit face recognition to access portrait privacy. In this demo, we propose an adversarial privacy-preserving filter, which can preserve face image from malicious face recognition algorithms. This filter is generated by an end-cloud collaborated adversarial attack framework consisting of three modules: (1) Image-specific gradient generation module, to extract image-specific gradient in the user end; (2) Adversarial gradient transfer module, to fine-tune the image-specific gradient in the server; and (3) Universal adversarial perturbation enhancement module, to append image-independent perturbation to derive the final adversarial perturbation. A short video about our system is available at https://github.com/Anonymity-for-submission/3247. Jiaming Zhang 0006, Xiaowen Huang 0001 |
ACM Multimedia | 2 |
| 2021 | Robust CAPTCHAs Towards Malicious OCRabstractTuring test was originally proposed to examine whether machine's behavior is indistinguishable from a human. The most popular and practical Turing test is CAPTCHA, which is to discriminate algorithm from human by offering recognition-alike questions. The recent development of deep learning has significantly advanced the capability of algorithm in solving CAPTCHA questions, forcing CAPTCHA designers to increase question complexity. Instead of designing questions difficult for both algorithm and human, this study attempts to employ the limitations of algorithm to design robust CAPTCHA questions easily solvable to human. Specifically, our data analysis observes that human and algorithm demonstrates different vulnerability to visual distortions: adversarial perturbation is significantly annoying to algorithm yet friendly to human. We are motivated to employ adversarially perturbed images for robust CAPTCHA design in the context of character-based questions. Four modules of multi-target attack, ensemble adversarial training, image preprocessing differentiable approximation, and expectation are proposed to address the characteristics of character-based CAPTCHA cracking. Qualitative and quantitative experimental results demonstrate the effectiveness of the proposed solution. We hope this study can lead to the discussions around adversarial attack/defense in CAPTCHA design and also inspire the future attempts in employing algorithm limitation for practical usage. Jiaming Zhang 0006, Jitao Sang 0001, Shangxi Wu, Yongli Hu, Jian Yu 0001 |
IEEE Trans. Multim. | 1 |
| 2020 | Adversarial Privacy-preserving FilterabstractWhile widely adopted in practical applications, face recognition has been critically discussed regarding the malicious use of face images and the potential privacy problems, e.g., deceiving payment system and causing personal sabotage. Online photo sharing services unintentionally act as the main repository for malicious crawler and face recognition applications. This work aims to develop a privacy-preserving solution, called Adversarial Privacy-preserving Filter (APF), to protect the online shared face images from being maliciously used. We propose an end-cloud collaborated adversarial attack solution to satisfy requirements of privacy, utility and non-accessibility. Specifically, the solutions consist of three modules: (1) image-specific gradient generation, to extract image-specific gradient in the user end with a compressed probe model; (2) adversarial gradient transfer, to fine-tune the image-specific gradient in the server cloud; and (3) universal adversarial perturbation enhancement, to append image-independent perturbation to derive the final adversarial noise. Extensive experiments on three datasets validate the effectiveness and efficiency of the proposed solution. A prototype application is also released for further evaluation. We hope the end-cloud collaborated attack framework could shed light on addressing the issue of online multimedia sharing privacy-preserving issues from user side. Jiaming Zhang 0006, Jitao Sang 0001, Xiaowen Huang 0001, Yongli Hu |
ACM Multimedia | 1 |
| 2017 | A Demo for Image-Based Personality Test
Huaiwen Zhang, Jiaming Zhang 0006, Jitao Sang 0001, Changsheng Xu |
MMM (2) | 2 |