Rui Yang 0032

dblp:92/1942-32 · DBLP profile ↗
← Back
6ranked-venue papers
5as first author
6since 2021 · last 2026
0000-0001-7439-6587ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 RES-PDF: A random, ensemble, and simultaneous purification-detection framework for adversarial example mitigation
Rui Yang 0032, Qindong Sun, Han Cao 0004, Chao Shen 0001
Neurocomputing1
2026 FeatureTrojan: Boosting stealthy and steady backdoor attacks with feature poisoning and fine-tuning injection
Rui Yang 0032, Qindong Sun, Han Cao 0004, Chao Shen 0001
Neural Networks1
2025 ADoP: A Universal, Robust, Efficient, and Plug-and-Play Adversarial Example Detector
abstract
Current state-of-the-art adversarial example detectors exhibit several fatal limitations, hindering their deployment in safety-critical real-world applications. These limitations include a lack of sufficient universality, vulnerability to adaptive attacks, high test-stage time consumption, and a lack of plug-and-play capability. To bridge the gap, this paper proposes a novel state-of-the-art adversarial example detector named Adversarial Detection on Purification (ADoP). Specifically, ADoP first incorporates a novel adversarial purification named Gaussian-augmented GAN-based Adversarial Purification (GA-GAP), which exhibits sufficient advantages. Then, ADoP effectively overcomes current limitations by fully exploiting the advantages of GA-GAP. Extensive experiments on ImageNet demonstrate ADoP’s effectiveness in universal detection, adaptive attack avoidance, reduced test-stage time, and plug-and-play capability.
Rui Yang 0032, Qindong Sun, Jiaming Cai
ICME1
2025 Decision attribution and local extremum-guided black-box adversarial attack with adjustable sparsity and discreteness
Han Cao 0004, Qindong Sun, Rong Geng 0001, Xiaoxiong Wang, Rui Yang 0032
J. Inf. Secur. Appl.5
2025 1+1>2: A Dual-Function Defense Framework for Adversarial Example Mitigation
abstract
Current state-of-the-art plug-and-play countermeasures for mitigating adversarial examples (i.e., purification and detection) exhibit several fatal limitations, impeding their deployment in safety-critical real-world applications. These limitations include susceptibility to adaptive attacks, adverse impact on benign samples, high time consumption for conducting a complete defense cycle, etc. To bridge the gap, developing more advanced plug-and-play countermeasures is urgently needed to safeguard these applications. Specifically, this paper first proposes a novel method named Gaussian-augmented GAN-based Adversarial Purification (GA-GAP). Unlike previous methods, GA-GAP enhances the density of the training data in low-robustness regions by using random Gaussian noise. Moreover, GA-GAP incorporates a pre-trained deep learning classifier into the training architecture and integrates its classification loss into the training loss function. Then, following the development of GA-GAP, this paper innovatively proposes a dual-function defense framework named Adversarial Detection on Purification (ADoP) to mitigate adversarial examples further. In ADoP, purification and detection complement each other, achieving the effect of$\mathbf {1+1\gt 2}$, which can more efficiently avoid adaptive attacks. Extensive experiments on ImageNet demonstrate that ADoP outperforms other countermeasures in multiple aspects. These aspects include superior generalization capability in purifying and detecting various adversarial examples, less adverse impact on benign samples, and practical time consumption for conducting a complete defense cycle.
Rui Yang 0032, Qindong Sun, Han Cao 0004, Chao Shen 0001, Jiaming Cai, Dongzhu Rong
IEEE Trans. Inf. Forensics Secur.1
2021 A novel and universal GAN-based countermeasure to recover adversarial examples to benign examples
Rui Yang 0032, Tianjie Cao, Xiu-Qing Chen, Feng-Rong Zhang
Comput. Secur.1