Publications (17)
Picking watermarks from noise (PWFN): an improved robust watermarking model against intensive distortions
Sijing Xie, Chengxin Zhao, Nan Sun +2
Digital watermarking is the process of embedding secret information by altering images in an undetectable way to the human eye. To increase the robustness of the model, many deep l…
Improving the Transferability of Adversarial Attacks on Face Recognition with Diverse Parameters Augmentation
Fengfan Zhou, Bangjie Yin, Hefei Ling +2
Face Recognition (FR) models are vulnerable to adversarial examples that subtly manipulate benign face images, underscoring the urgent need to improve the transferability of advers…
Improving Visual Quality and Transferability of Adversarial Attacks on Face Recognition Simultaneously with Adversarial Restoration
Fengfan Zhou, Hefei Ling, Yuxuan Shi +2
Adversarial face examples possess two critical properties: Visual Quality and Transferability. However, existing approaches rarely address these properties simultaneously, leading…
Detecting Adversarial Faces Using Only Real Face Self-Perturbations
Qian Wang, Yongqin Xian, Hefei Ling +5
Adversarial attacks aim to disturb the functionality of a target system by adding specific noise to the input samples, bringing potential threats to security and robustness when ap…
DFGC 2021: A DeepFake Game Competition
Bo Peng, Hongxing Fan, Wei Wang +20
This paper presents a summary of the DFGC 2021 competition. DeepFake technology is developing fast, and realistic face-swaps are increasingly deceiving and hard to detect. At the s…
Improving the JPEG-resistance of Adversarial Attacks on Face Recognition by Interpolation Smoothing
Kefu Guo, Fengfan Zhou, Hefei Ling +2
JPEG compression can significantly impair the performance of adversarial face examples, which previous adversarial attacks on face recognition (FR) have not adequately addressed. C…
Hands-on Guidance for Distilling Object Detectors
Yangyang Qin, Hefei Ling, Zhenghai He +2
Knowledge distillation can lead to deploy-friendly networks against the plagued computational complexity problem, but previous methods neglect the feature hierarchy in detectors. M…
Detecting Adversarial Data using Perturbation Forgery
Qian Wang, Chen Li, Yuchen Luo +4
As a defense strategy against adversarial attacks, adversarial detection aims to identify and filter out adversarial data from the data flow based on discrepancies in distribution…
SSyncOA: Self-synchronizing Object-aligned Watermarking to Resist Cropping-paste Attacks
Chengxin Zhao, Hefei Ling, Sijing Xie +3
Modern image processing tools have made it easy for attackers to crop the region or object of interest in images and paste it into other images. The challenge this cropping-paste a…
Continual Adversarial Defense
Qian Wang, Hefei Ling, Yingwei Li +3
In response to the rapidly evolving nature of adversarial attacks against visual classifiers, numerous defenses have been proposed to generalize against as many known attacks as po…
Adversarial Attacks on Both Face Recognition and Face Anti-spoofing Models
Fengfan Zhou, Qianyu Zhou, Hefei Ling +1
Adversarial attacks on Face Recognition (FR) systems have demonstrated significant effectiveness against standalone FR models. However, their practicality diminishes in complete FR…
Improving the Transferability of Adversarial Attacks on Face Recognition with Beneficial Perturbation Feature Augmentation
Fengfan Zhou, Hefei Ling, Yuxuan Shi +3
Face recognition (FR) models can be easily fooled by adversarial examples, which are crafted by adding imperceptible perturbations on benign face images. The existence of adversari…
END: Robust Dual-Decoder Watermarking Framework Against Non-Differentiable Distortions
Nan Sun, Han Fang, Yuxing Lu +2
DNN-based watermarking methods have rapidly advanced, with the ``Encoder-Noise Layer-Decoder'' (END) framework being the most widely used. To ensure end-to-end training, the noise…
DBDH: A Dual-Branch Dual-Head Neural Network for Invisible Embedded Regions Localization
Chengxin Zhao, Hefei Ling, Sijing Xie +4
Embedding invisible hyperlinks or hidden codes in images to replace QR codes has become a hot topic recently. This technology requires first localizing the embedded region in the c…
ARLON: Boosting Diffusion Transformers with Autoregressive Models for Long Video Generation
Zongyi Li, Shujie Hu, Shujie Liu +7
Text-to-video models have recently undergone rapid and substantial advancements. Nevertheless, due to limitations in data and computational resources, achieving efficient generatio…
Selective Convolutional Network: An Efficient Object Detector with Ignoring Background
Hefei Ling, Yangyang Qin, Li Zhang +2
It is well known that attention mechanisms can effectively improve the performance of many CNNs including object detectors. Instead of refining feature maps prevalently, we reduce…
Rethinking Impersonation and Dodging Attacks on Face Recognition Systems
Fengfan Zhou, Qianyu Zhou, Bangjie Yin +4
Face Recognition (FR) systems can be easily deceived by adversarial examples that manipulate benign face images through imperceptible perturbations. Adversarial attacks on FR encom…