EDBT 2026 Demo / reviewers in the wild / expert
Lin Yuan 0002
dblp:83/6071-2
· DBLP profile ↗
31ranked-venue papers
8as first author
28since 2021 · last 2026
0000-0002-8148-9770ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Graphics, computer vision, multimedia, augmented reality and games · 13 · 3 first-author · 12 since 2021Artificial intelligence and machine learning · 10 · 3 first-author · 9 since 2021Security and privacy · 3 · 2 first-author · 2 since 2021Computer networks · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Breaking the Generator Barrier: Disentangled Representation for Generalizable AI-Text DetectionabstractAs large language models (LLMs) generate text that increasingly resembles human writing, the subtle cues that distinguish AI-generated content from human-written content become increasingly challenging to capture. Reliance on generator-specific artifacts is inherently unstable, since new models emerge rapidly and reduce the robustness of such shortcuts. This generalizes unseen generators as a central and challenging problem for AI-text detection. To tackle this challenge, we propose a progressively structured framework that disentangles AI-detection semantics from generator-aware artifacts. This is achieved through a compact latent encoding that encourages semantic minimality, followed by perturbation-based regularization to reduce residual entanglement, and finally a discriminative adaptation stage that aligns representations with task objectives. Experiments on MAGE benchmark, covering 20 representative LLMs across 7 categories, demonstrate consistent improvements over state-of-the-art methods, achieving up to 24.2% accuracy gain and 26.2% F_1 improvement. Notably, performance continues to improve as the diversity of training generators increases, confirming strong scalability and generalization in open-set scenarios. Our source code will be publicly available at https://github.com/PuXiao06/DRGD. Xiao Pu 0002, Zepeng Cheng, Lin Yuan 0002, Yu Wu 0001, Xiuli Bi |
ACL (1) | 3 |
| 2026 | Silent corruption: Logic collapse and attribution fidelity failure in compressed intrusion detection systems
Md. Hamid Borkot Tulla, Lin Yuan 0002, Xiao Pu, Gwanggil Jeon |
Inf. Sci. | 2 |
| 2026 | SSD: Making Face Forgery Clues Evident Again With Self-Steganographic DetectionabstractThe rapid development of generative AI techniques enables the synthesis of highly realistic facial images, posing significant challenges for the accurate detection of face forgeries. In contrast to solely elevating detector awareness, proactively reducing the intrinsic difficulty of forgery detection can streamline detector complexity while improving both generalization and robustness. This insight motivates our defense strategy to make face forgery clues more evident. Specifically, a novel proactive approach dubbed Self-Steganographic Detection (SSD) is proposed to imperceptibly embed facial images into themselves as a form of detection evidence. The recovery process is designed to remain robust under normal manipulations while exhibiting deliberate degradation under malicious manipulations, thereby clearly revealing potential forgeries. Unlike embedding bit-level vectors, pixel-level images are informative to ensure the generalization of our approach. Due to the similarity between the protected and embedded images, SSD performs detection without storing any embedded information in advance. To support practical deployment, our approach incorporates a dual detection scheme that aims to identify unprotected images and determine the authenticity of protected images. Extensive experiments using 8 face forgery techniques demonstrate the effectiveness of our approach compared to state-of-the-art methods. Ruiyang Xia, Dawei Zhou 0004, Lin Yuan 0002, Jie Li 0001, Nannan Wang 0001, Xinbo Gao 0001 |
IEEE Trans. Pattern Anal. Mach. Intell. | 3 |
| 2026 | Dual-Space Hierarchical Learning for Deepfake DetectionabstractMost existing deepfake detection methods learn visual artifacts in Euclidean space, overlooking the intrinsic hierarchical relationships among forgery samples. In practice, manipulated images deviate progressively from real ones, forming a hierarchy that Euclidean geometry struggles to model, while hyperbolic space better captures such structures due to its exponential capacity. Motivated by this observation, we propose a dual-space hierarchical learning framework that jointly models Euclidean visual semantics and hyperbolic hierarchical representations. Specifically, Euclidean features are projected into hyperbolic space, where a Hyperbolic Hierarchy-Aware Attention (HHAA) module is introduced to capture hierarchical dependencies among samples. To effectively integrate complementary information from the two spaces, a Dual-Space Gated Fusion (DSGF) module is designed to adaptively inject hierarchical cues into Euclidean features. A joint supervision strategy is further applied to enhance discriminative representation learning. Extensive experiments on multiple deepfake detection benchmarks demonstrate that the proposed method improves detection performance and generalization ability. Hongyi Wang 0006, Lin Yuan 0002, Xinbo Gao 0001 |
IEEE Signal Process. Lett. | 4 |
| 2025 | DVW: Diffusion Visible WatermarkabstractWith the rapid development of the diffusion models, numerous exquisitely generated images have significantly increased the risk of image misuse and abuse. Despite various AI parties and companies having devoted themselves to embedding watermarks into the generated images to curb the potential detriments, the isolated embedding from the generation process makes the watermarks vulnerable to watermark removal networks. To address this issue, we propose a novel generative image watermark scheme, dubbed Diffusion Visible Watermark (DVW), which can generate watermarked images in one step without additional training or fine-tuning of the diffusion models. Specifically, DVW introduces a masked distribution alignment strategy to fuse the watermark distribution with a Gaussian noise distribution. By iterative denoising the fused aligned distribution with the pretraining diffusion models, the watermarked images with coordinated and unified distribution can be generated with natural robustness against removal. In addition, we design and integrate a dynamic transparency module to adaptively control the watermark coverage degree for better visual quality. Comprehensive experiments and analysis are conducted on two representative kinds of diffusion models, GLIDE and StableDiffusion, to prove the superior and generic robustness of our DVW against watermark removal without sacrificing the generation ability of the diffusion models. Jiawei Zhang 0011, Xiaoli Jiang, Hao Wang 0060, Lin Yuan 0002, Xiangyang Luo 0001, Bin Ma 0003 |
ACM Multimedia | 4 |
| 2025 | DichotomyIR: Universal Image Reconstruction via Dichotomy Classification and Uncertainty Elimination
Yan Zhang 0108, Shiwen He, Lin Yuan 0002, Jiaxu Leng, Xinbo Gao 0001 |
ACM Multimedia | 3 |
| 2025 | MLEP: Multi-granularity Local Entropy Patterns for Generalized AI-generated Image DetectionabstractAdvances in image generation technologies have raised growing concerns about their potential misuse, particularly in producing misinformation and deepfakes. This creates an urgent demand for effective methods to detect AI-generated images (AIGIs). While progress has been made, achieving reliable performance across diverse generative models and scenarios remains challenging due to the absence of source-invariant features and the limited generalization of existing approaches. In this study, we investigate the potential of using image entropy as a discriminative cue for AIGI detection and propose Multi-granularity Local Entropy Patterns (MLEP), a set of feature maps computed based on Shannon entropy from shuffled small patches at multiple image scales. MLEP effectively captures pixel dependencies across scales and dimensions while disrupting semantic content, thereby reducing potential content bias. Based on MLEP, we can easily build a robust CNN-based classifier capable of detecting AIGIs with enhanced reliability. Extensive experiments in an open-world setting, involving images synthesized by 32 distinct generative models, demonstrate that our approach achieves substantial improvements over state-of-the-art methods in both accuracy and generalization. Our code and models are available at https://www.github.com/fkeufss/MLEP/. Lin Yuan 0002, Xiaowan Li, Yan Zhang 0108, Jiawei Zhang 0011, Xinbo Gao 0001 |
NeurIPS | 1 |
| 2025 | See as You Desire: Scale-Adaptive Face Super-Resolution for Varying Low ResolutionsabstractFace super-resolution (FSR) is critical for bolstering intelligent security in Internet of Things (IoT) systems. Recent deep learning-driven FSR algorithms have attained remarkable progress. However, they always require separate model training and optimization for each scaling factor or input resolution, leading to inefficiency and impracticality. To overcome these limitations, we propose SAFNet, an innovative framework tailored for scale-adaptive FSR with arbitrary input resolution. SAFNet integrates scale information into representation learning to enable adaptive feature extraction and introduces dual-embedding attention to boost adaptive feature reconstruction. It leverages facial self-similarity and spatial-frequency collaboration to achieve precise scale-aware SR representations. This is attained through three key modules: 1) the scale adaption guidance unit (SAGU); 2) the scale-aware nonlocal self-similarity (SNLS) module; and 3) the spatial-frequency interactive modulation (SFIM) module. SAGU imports scaling factors using frequency encoding, SNLS exploits self-similarity to enrich feature representations, and SFIM incorporates spatial and frequency information to predict target pixel values adaptively. Comprehensive evaluations across four benchmark datasets reveal that SAFNet outperforms the second-best compared state-of-the-art (SOTA) method by about 0.2 dB/0.007 in PSNR/SSIM ($\times 4$on CelebA) with reduced 18.68%/42.64% computational complexity/time cost. This demonstrates SAFNet’s effectiveness and superiority, showcasing its potential as a promising solution for scale and input resolution adaptation challenges in FSR. The code will be available athttps://github.com/ICVIPLab/SAFNet. Yan Zhang 0108, Lin Yuan 0002, Xinbo Gao 0001 |
IEEE Internet Things J. | 3 |
| 2025 | Understanding the robustness of graph neural networks against adversarial attacks
Tao Wu 0003, Canyixing Cui, Xingping Xian, Shaojie Qiao, Chao Wang 0025, Lin Yuan 0002, Shui Yu 0001 |
Knowl. Based Syst. | 6 |
| 2025 | SANet: Face super-resolution based on self-similarity prior and attention integration
Yan Zhang 0108, Lin Yuan 0002, Xinbo Gao 0001 |
Pattern Recognit. | 3 |
| 2025 | GADNet: Improving image-text matching via graph-based aggregation and disentanglement
Xiao Pu 0002, Lin Yuan 0002, Yu Wu 0001, Liping Jing, Xinbo Gao 0001 |
Pattern Recognit. | 3 |
| 2025 | iFADIT: Invertible Face Anonymization via Disentangled Identity Transform
Lin Yuan 0002, Tao Wu 0003, Nannan Wang 0001, Xinbo Gao 0001 |
Pattern Recognit. | 1 |
| 2025 | Big Brother Is Watching: Proactive Deepfake Detection via Learnable Hidden FaceabstractAs deepfake technologies continue to evolve, proactive defense techniques have gained increasing attention for their potential to either neutralize deepfake operations or simplify detection through pre-embedded signals. In this paper, inspired by watermark-based forensic methods, we explore a novel detection framework built on the concept of “hiding a learnable face within a face”. Specifically, we use a semi-fragile invertible steganography network to imperceptibly embed a learnable template image within a host face image to be protected. This template serves as an indicator revealing signs of tampering when recovered through the inverse steganography process. Unlike manually designed templates, it is optimized during training to resemble a neutral facial appearance—functioning like a subtle “big brother” hidden within the image. Through a self-blending mechanism and robustness learning strategy with a simulated transmission channel, we develop a robust detector that accurately distinguishes between malicious tampering and benign processing of the steganographic image. Extensive experiments across multiple datasets validate the superiority of the proposed approach over competing passive and proactive detection methods. Shangchao Yang, Ruiyang Xia, Lin Yuan 0002, Xinbo Gao 0001 |
IEEE Signal Process. Lett. | 4 |
| 2025 | Self-Representation-Based Generative Graph Neural Networks for End-to-End Link PredictionabstractRecently, deep neural networks have revolutionized the field of link prediction, and the state-of-the-art works are typically subgraph-based discriminative methods, which construct features of local subgraphs firstly and predicting potential links via deep learning based binary subgraph classification. However, the discriminative link prediction methods always fail to automatically learn features and perform link prediction, and the performance of them depends on the construction of enclosing subgraphs and the manually-designed features for the subgraphs. To address these issues, we leverage the idea of graph disentangling and propose a novel self-representation-based generative graph neural network framework (GraphLP) for end-to-end link prediction, which learns to extract the latent patterns, i.e., recurring subgraphs, from input graphs via self-supervised learning and reconstruct graphs for link prediction using the subgraphs as structural basis. GraphLP consists of three components: self-representation-based collaborative inference, high-order connectivity computation, and multi-scale pattern fusion. The key idea is to utilize the correlations between the extracted recurring subgraphs on different scales to effectively assist link inference. GraphLP also can effectively exploit the hierarchical organization patterns and incorporate them within the representation procedure, producing robust and accurate results. Compared with traditional methods and state-of-the-art methods, experimental results on public benchmark datasets demonstrate that GraphLP achieves promising performance. Different from the discriminative methods, GraphLP provides a new paradigm for generative neural-network-based link prediction. Xingping Xian, Tao Wu 0003, Shaojie Qiao, Chao Wang 0025, Lin Yuan 0002, Yanbing Liu 0004 |
IEEE Trans. Big Data | 5 |
| 2025 | Deepfake Detection Leveraging Self-Blended Artifacts Guided by Facial Embedding DiscrepancyabstractCurrent deepfake detection methods commonly use data augmentation and authenticity-content disentanglement to extract more generalized features for detection tasks. However, these methods rely exclusively on low-level spatial artifacts to distinguish real from fake images, which presents significant challenges in accurately capturing the rich forgery cues. Deepfakes create discrepancies between forged and original facial features within the face-recognition (FR) embedding space, which can serve as an additional cue for detection. To better exploit the artifacts in deepfake images, we propose a novel detection method that enhances the detector’s perception capability by incorporating not only the real and fake samples during training, but also the visual residual between real and fake images. Meanwhile, we integrate the discrepancy in facial embedding between the real and fake samples into the training procedure of artifact extraction, serving as a guidance signal with strong knowledge provided by the pretrained face recognition model. Specialized distillation loss along with additional cross-entropy losses are designed to enhance the detection capability. Experiments on multiple benchmarks demonstrate the superiority of the proposed approach in deepfake detection over literature methods. Shuodi Wang, Lin Yuan 0002, Yan Zhang 0108, Xinbo Gao 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 4 |
| 2024 | Make Privacy Renewable! Generating Privacy-Preserving Faces Supporting Cancelable Biometric Recognition
Tao Wang 0084, Yushu Zhang 0001, Xiangli Xiao, Lin Yuan 0002, Zhihua Xia, Jian Weng 0001 |
ACM Multimedia | 4 |
| 2024 | Advancing Generalized Deepfake Detector with Forgery Perception GuidanceabstractOne of the serious impacts brought by artificial intelligence is the abuse of deepfake techniques. Despite the proliferation of deepfake detection methods aimed at safeguarding the authenticity of media across the Internet, they mainly consider the improvement of detector architecture or the synthesis of forgery samples. The forgery perceptions, including the feature responses and prediction scores for forgery samples, have not been well considered. As a result, the generalization across multiple deepfake techniques always comes with complicated detector structures and expensive training costs. In this paper, we shift the focus to real-time perception analysis in the training process and generalize deepfake detectors through an efficient method dubbed Forgery Perception Guidance (FPG). In particular, after investigating the deficiencies of forgery perceptions, FPG adopts a sample refinement strategy to pertinently train the detector, thereby elevating the generalization efficiently. Moreover, FPG introduces more sample information as explicit optimizations, which makes the detector further adapt the sample diversities. Experiments demonstrate that FPG improves the generality of deepfake detectors with small training costs, minor detector modifications, and the acquirement of real data only. In particular, our approach not only outperforms the state-of-the-art on both the cross-dataset and cross-manipulation evaluation but also surpasses the baseline that needs more than 3× training time. Ruiyang Xia, Dawei Zhou 0004, Decheng Liu, Lin Yuan 0002, Shuodi Wang, Jie Li 0001, Nannan Wang 0001, Xinbo Gao 0001 |
ACM Multimedia | 4 |
| 2024 | Multiview-Ensemble-Learning-Based Robust Graph Convolutional Networks Against Adversarial AttacksabstractGraph neural networks (GNNs) have been widely applied in the Internet of Things (IoT) for the intelligent analysis of data collected by sensors, particularly complex relationships and dependent information between IoT devices. However, recent studies have shown that GNNs are vulnerable to adversarial attacks, which significantly limits their application in safety-critical IoT systems such as smart health monitoring, traffic monitoring, and autonomous driving. To address this issue, in addition to the low feature similarity, this study examines the vulnerability of GNNs empirically and reveals that adversarial perturbations against GNNs tend to have low structural proximity in local neighborhoods. Thus, a natural approach for defending GNNs against adversarial attacks is to utilize the related high-order robust information of the perturbed graphs. In this study, we construct auxiliary views with high-order structure and feature similarity from a perturbed graph and propose a multi-view ensemble learning-based robust graph convolutional network (MV-RGCN). Each base model in the MV-RGCN aggregates the adversarial perturbed graph and the constructed view through an adaptive aggregation mechanism, thereby eliminating the impact of adversarial perturbations. Robust representations of the base models are then integrated using an adaptive ensemble mechanism to generate predictions. Extensive experiments under adversarial attack scenarios demonstrate that the MV-RGCN outperforms state-of-the-art methods and can achieve satisfactory performance without affecting its accuracy on the original graph data. This code is available at https://github.com/thomaslok0516/MVRGCN. Tao Wu 0003, Junhui Luo, Shaojie Qiao, Chao Wang 0025, Lin Yuan 0002, Xiao Pu 0002, Xingping Xian |
IEEE Internet Things J. | 5 |
| 2024 | MiC: Image-text Matching in Circles with cross-modal generative knowledge enhancement
Xiao Pu 0002, Lin Yuan 0002, Yan Zhang 0108, Liping Jing, Xinbo Gao 0001 |
Knowl. Based Syst. | 3 |
| 2024 | Improving Image-Text Matching by Integrating Word Sense DisambiguationabstractThis letter presents a novel approach to enhance image-text matching by incorporating word sense disambiguation (WSD) within the text encoder. Our method explicitly models the senses of potentially ambiguous words, refining the semantic understanding between images and text. We introduce a sense-aware mechanism for image-text alignment by integrating a lightweight WSD component into the matching framework, optimizing both tasks simultaneously. Our WSD module operates on extensive word contexts, leveraging the power of graph attention networks (GAT), and distills knowledge from a substantially larger pre-trained WSD model through multi-task learning. Our experiments demonstrate the effectiveness of augmenting original word embeddings with sense representations derived from our WSD approach. We systematically evaluate our method against several baselines and state-of-the-art approaches on two widely-used image-text matching benchmarks: MS-COCO and Flickr30K. The results illustrate significant improvements in matching accuracy, highlighting the efficacy of our proposed approach. Xiao Pu 0002, Lin Yuan 0002, Xinbo Gao 0001 |
IEEE Signal Process. Lett. | 3 |
| 2024 | Invertible Image Obfuscation for Facial Privacy Protection via Secure FlowabstractThis paper presents a fresh paradigm for protecting facial privacy via an invertible image obfuscation framework that incorporates multiple characteristics including anonymity, diversity, reversibility, security, and lightweight all at once. We name the framework PRO-Face S, an acronym for Privacy-preserving Reversible Obfuscation of Face images via Secure flow. The core of the proposed framework is a flow-based generative model (or invertible neural network), which takes as input a face image along with its pre-obfuscated form, and outputs the privacy-protected image that visually mirrors the pre-obfuscated one. The pre-obfuscation applied can be in various forms with different types and strengths. The invertibility of the flow-based model ensures that the original image can be easily recovered from the protected image in high fidelity. An elaborate secret key mechanism is devised to securely guide the mutual transformations of privacy protection and image recovery, such that the correct recovery is only possible upon the availability of the correct secret, pre-specified by the user in the protection stage. Two modes of wrong recovery are investigated to deal with malicious recovery attempts in different scenarios. Finally, extensive experiments conducted on multiple image datasets demonstrate the superiority of the proposed framework over state-of-the-art methods. Lin Yuan 0002, Xiao Pu 0002, Yan Zhang 0108, Jiaxu Leng, Tao Wu 0003, Nannan Wang 0001, Xinbo Gao 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 1 |
| 2024 | PLGNet: Prior-Guided Local and Global Interactive Hybrid Network for Face Super-ResolutionabstractRecent CNN-driven face super-resolution (FSR) technologies have achieved excellent breakthroughs by incorporating facial prior knowledge. However, most of them suffer from some obvious limitations. They always estimate facial priors from input low-resolution (LR) faces or coarsely enhanced LR faces, obtaining unfaithful priors that cannot be adequately exploited. This may bring noticeable artifacts to the target results, especially for large scaling factors, deteriorating the fidelity and naturalness and generating suboptimal reconstructed results. In this paper, we propose a two-stage prior-guided FSR approach to learn facial prior knowledge from the optimal SR results of stage one and explore the complementarity between priors to further guide more accurate reconstruction in stage two. Specifically, we develop an efficient local and global interactive hybrid network incorporating facial semantic and geometric priors for more discriminative results. To reach this, we devise a multiscale interconnected symmetric encoder-decoder architecture composed of Prior Interaction-Integration Modules (PIIMs), the Coarse-to-fine Feature Refinement Module (CFRM), and Feature Aggregation Modulation Modules (FAMMs). The encoder concentrates on hierarchically extracting multiscale features. The CFRM is devised to explore the potential correlations between the encoder and the decoder and further guide the refinement and reinforcement of the encoded features. The decoder aims to take full advantage of informative multiscale encoded features to reconstruct high-quality SR representations. Comprehensive evaluation and visualization results on four benchmark datasets demonstrate the superiority of the proposed PLGNet over current state-of-the-art methods. The source code of PLGNet will be available at https://github.com/lil808/PLGNet.git. Yan Zhang 0108, Lin Yuan 0002, Xinbo Gao 0001 |
IEEE Trans. Circuits Syst. Video Technol. | 3 |
| 2024 | MMNet: Multi-Collaboration and Multi-Supervision Network for Sequential Deepfake DetectionabstractAdvanced manipulation techniques have provided criminals with opportunities to make social panic or gain illicit profits through the generation of deceptive media, such as forgery face images. In response, various deepfake detection methods have been proposed to assess image authenticity. Sequential deepfake detection, which is an extension of deepfake detection, aims to identify forged facial regions with the correct sequence for recovery. Nonetheless, due to the different combinations of spatial and sequential manipulations, forgery face images exhibit substantial discrepancies that severely impact detection performance. Additionally, the recovery of forged images requires knowledge of the manipulation model to implement inverse transformations, which is difficult to ascertain as relevant techniques are often concealed by attackers. To address these issues, we propose Multi-Collaboration and Multi-Supervision Network (MMNet) that handles various spatial scales and sequential permutations in forgery face images and achieve recovery without requiring knowledge of the corresponding manipulation method. Furthermore, existing evaluation metrics only consider detection accuracy at a single inferring step, without accounting for the matching degree with ground-truth under continuous multiple steps. To overcome this limitation, we propose a novel evaluation metric called Complete Sequence Matching (CSM), which considers the detection accuracy at multiple inferring steps, reflecting the ability to detect integrally forged sequences. Extensive experiments on several typical datasets demonstrate that MMNet achieves state-of-the-art detection performance and independent recovery performance. Code will be available at https://github.com/xarryon/MMNet. Ruiyang Xia, Decheng Liu, Jie Li 0001, Lin Yuan 0002, Nannan Wang 0001, Xinbo Gao 0001 |
IEEE Trans. Inf. Forensics Secur. | 4 |
| 2024 | PRO-Face C: Privacy-Preserving Recognition of Obfuscated Face via Feature CompensationabstractThe advancement of face recognition technology has delivered substantial societal advantages. However, it has also raised global privacy concerns due to the ubiquitous collection and potential misuse of individuals’ facial data. This presents a notable paradox: while there is a societal demand for a robust face recognition ecosystem to ensure public security and convenience, an increasing number of individuals are hesitant to release their facial data. Numerous studies have endeavored to find such a utility-privacy trade-off, yet many struggle with the dilemma of prioritizing one at the expense of the other. In response to this challenge, this paper proposes PRO-Face C, a novel paradigm for privacy-preserving recognition of obfuscated faces via a dedicated feature compensation mechanism, aimed at optimizing the equilibrium between privacy preservation and utility maximization. The proposed approach is characterized by a specialized client-server architecture: the client transmits only obfuscated images to the server, which then performs identity recognition using a pre-trained model in conjunction with a suite of privacy-free complementary features. This framework facilitates accurate face identification while safeguarding the original facial appearance from explicit disclosure. Furthermore, the obfuscated image retains its visualization capability, crucial for image preview functionalities. To ensure the desired properties, we have developed an identity-guided feature compensation mechanism, complemented by several privacy-enhancing techniques. Extensive experiments conducted across multiple face datasets underscore the effectiveness of the proposed approach in diverse scenarios. Lin Yuan 0002, Xiao Pu 0002, Yan Zhang 0108, Yushu Zhang 0001, Xinbo Gao 0001, Touradj Ebrahimi |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2024 | Inspector for Face Forgery Detection: Defending Against Adversarial Attacks From Coarse to FineabstractThe emergence of face forgery has raised global concerns on social security, thereby facilitating the research on automatic forgery detection. Although current forgery detectors have demonstrated promising performance in determining authenticity, their susceptibility to adversarial perturbations remains insufficiently addressed. Given the nuanced discrepancies between real and fake instances are essential in forgery detection, previous defensive paradigms based on input processing and adversarial training tend to disrupt these discrepancies. For the detectors, the learning difficulty is thus increased, and the natural accuracy is dramatically decreased. To achieve adversarial defense without changing the instances as well as the detectors, a novel defensive paradigm called Inspector is designed specifically for face forgery detectors. Specifically, Inspector defends against adversarial attacks in a coarse-to-fine manner. In the coarse defense stage, adversarial instances with evident perturbations are directly identified and filtered out. Subsequently, in the fine defense stage, the threats from adversarial instances with imperceptible perturbations are further detected and eliminated. Experimental results across different types of face forgery datasets and detectors demonstrate that our method achieves state-of-the-art performances against various types of adversarial perturbations while better preserving natural accuracy. Code is available on https://github.com/xarryon/Inspector. Ruiyang Xia, Dawei Zhou 0004, Decheng Liu, Jie Li 0001, Lin Yuan 0002, Nannan Wang 0001, Xinbo Gao 0001 |
IEEE Trans. Image Process. | 5 |
| 2023 | Lexical knowledge enhanced text matching via distilled word sense disambiguation
Xiao Pu 0002, Lin Yuan 0002, Jiaxu Leng, Tao Wu 0003, Xinbo Gao 0001 |
Knowl. Based Syst. | 2 |
| 2022 | PRO-Face: A Generic Framework for Privacy-preserving Recognizable Obfuscation of Face ImagesabstractA number of applications (e.g., video surveillance and authentication) rely on automated face recognition to guarantee functioning of secure services, and meanwhile, have to take into account the privacy of individuals exposed under camera systems. This is the so-called Privacy-Utility trade-off. However, most existing approaches to facial privacy protection focus on removing identifiable visual information from images, leaving protected face unrecognizable to machine, which sacrifice utility for privacy. To tackle the privacy-utility challenge, we propose a novel, generic, effective, yet lightweight framework for Privacy-preserving Recognizable Obfuscation of Face images (named as PRO-Face). The framework allows one to first process a face image using any preferred obfuscation, such as image blur, pixelate and face morphing. It then leverages a Siamese network to fuse the original image with its obfuscated form, generating the final protected image visually similar to the obfuscated one from human perception (for privacy) but still recognized as the original identity by machine (for utility). The framework supports various obfuscations for facial anonymization. The face recognition can be performed accurately not only across anonymized images but also between plain and anonymized ones, based on only pre-trained recognizers. Those feature the "generic" merit of the proposed framework. In-depth objective and subjective evaluations demonstrate the effectiveness of the proposed framework in both privacy protection and utility preservation under distinct scenarios. Our source code, models and any supplementary materials are made publicly available. Lin Yuan 0002, Linguo Liu, Xiao Pu 0002, Xinbo Gao 0001 |
ACM Multimedia | 1 |
| 2022 | DHT: Deformable Hybrid Transformer for Aerial Image SegmentationabstractDue to the strong ability to model global information, the transformer-based methods have shown remarkable improvements in image segmentation tasks. However, the self-attention mechanism in the transformer is computationally expensive and relies on pre-trained parameters. Moreover, the transformer method is weak in modeling local information, which is unfavorable for accurately segmenting objects from high-resolution aerial images. To this end, an efficient deformable orientational self-attention (DoA) is proposed to simultaneously extract the global information and the local information. Besides, for parameter efficiency, we design a depthwise channel self-attention (DcA) to model the contextual information among channels. Combining with the DoA and DcA, we propose the deformable hybrid transformer (DHT) to perform high-quality object segmentation on aerial images. Experiments on ISPRS Potsdam dataset and WHU building dataset illustrate that the proposed DHT can not only achieve state-of-the-art (SOTA) results but also markedly reduce the dependence of the transformer on pre-trained parameters. Yan Zhang 0108, Xiyuan Gao, Qingyan Duan, Lin Yuan 0002, Xinbo Gao 0001 |
IEEE Geosci. Remote. Sens. Lett. | 4 |
| 2017 | Context-Dependent Privacy-Aware Photo Sharing Based on Machine Learning
Lin Yuan 0002, Joël Theytaz, Touradj Ebrahimi |
SEC | 1 |
| 2017 | Image privacy protection with secure JPEG transmorphingabstractThanks to advancements in smart mobile devices and social media platforms, sharing photos and experiences has significantly bridged the authors’ lives, allowing them to stay connected despite distance and other barriers. Most approaches to protect image visual privacy focus on encrypting or permuting image data, which generate unreadable image or highly distorted visual effect and therefore may not be in users best interest from both usage and perception perspectives. In this study, the authors propose secure JPEG transmorphing, a framework for protecting image visual privacy in a secure, reversible, and highly flexible and personalised manner. Secure JPEG transmorphing allows one to apply arbitrary regional visual manipulation on image regions of interests (ROIs), while secretly preserving the information about the original ROIs in application segments (APPn markers) of the visually obfuscated JPEG image. Objective and subjective experiments have been performed and results indicate that the proposed protection scheme provides near lossless image reconstruction, controllable level of file size expansion, good degree of privacy protection and especially better subjective pleasantness. Lin Yuan 0002, Touradj Ebrahimi |
IET Signal Process. | 1 |
| 2015 | Image transmorphing with JPEGabstractPicture-related applications are extremely popular because pictures present attractive and vivid information. Nowadays, people record everyday life, communicate with each other, and enjoy entertainment using various interesting imaging applications. In many cases, processed images need to be recovered to their original versions. However, most approaches require storage or transmission of both original and processed images separately, which result in increased bandwidth and storage resources to be used. In contrast, in this paper, we present a JPEG transmorphing algorithm, which converts an image to its processed version while preserving sufficient information about the original image in the processed image. It does this by inserting partial information about the original image in the application markers of the processed JPEG image file, so that the original image can be later recovered. Experiments are conducted and results show that the proposed method offers a number of attractive features and a good performance in many applications. Lin Yuan 0002, Touradj Ebrahimi |
ICIP | 1 |