← Search

Fangjun Huang

8 accepted papers

2026

SemanticShield: LLM-Powered Audits Expose Shilling Attacks in Recommender Systems

ICASSP 2026poster

Recommender systems (RS) are widely used in e-commerce for personalized suggestions, yet their openness makes them susceptible to shilling attacks, where adversaries inject fake behaviors to manipulate recommendations. Most existing defenses emphasize user-side behaviors while overlooking item-side…

Cited by 0SourcePDFScholar
2025

DiffAttack: Imperceptible and Transferable Audio Adversarial Attack via Diffusion Model

ICASSP 2025accepted

Recently, adversarial attacks on speaker recognition systems have garnered significant interest. However, existing methods focus on injecting subtle perturbations into audio, which may compromise auditory quality. To address this problem, we propose a novel approach named DiffAttack, which employs a…

Cited by 0SourceScholar
2025

OmniMark: Efficient and Scalable Latent Diffusion Model Fingerprinting

AAAI 2025technical

We introduce OmniMark, a novel and efficient fingerprinting method for Latent Diffusion Models (LDM). OmniMark can encode user-specific fingerprints across diverse dimensions of the weights of the LDM, including kernels, filters, channels, and spatial domains. The LDM is fine-tuned to encode the inv…

2025

Robust Secure Swap: Responsible Face Swap With Persons of Interest Redaction and Provenance Traceability

ICML 2025poster

As AI generative models evolve, face swap technology has become increasingly accessible, raising concerns over potential misuse. Celebrities may be manipulated without consent, and ordinary individuals may fall victim to identity fraud. To address these threats, we propose Secure Swap, a method that…

Cited by 0SourcePDFScholar
2025

Variance as a Catalyst: Efficient and Transferable Semantic Erasure Adversarial Attack for Customized Diffusion Models

ICML 2025poster

Latent Diffusion Models (LDMs) enable fine-tuning with only a few images and have become widely used on the Internet. However, it can also be misused to generate fake images, leading to privacy violations and social risks. Existing adversarial attack methods primarily introduce noise distortions to…

Cited by 0SourcePDFScholar
2024

IDGuard: Robust General Identity-centric POI Proactive Defense Against Face Editing Abuse

CVPR 2024poster

In this work we propose IDGuard a novel proactive defense method from the perspective of developers to protect Persons-of-Interest (POI) such as national leaders from face editing abuse. We build a bridge between identities and model behavior safeguarding POI identities rather than merely certain fa…

Cited by 1SourcePDFScholar
2024

LOFT: Latent Space Optimization and Generator Fine-Tuning for Defending Against Deepfakes

ICASSP 2024accepted

DeepFakes pose a significant threat to individual reputations and society as a whole. Existing proactive defense strategies concentrate on adding adversarial perturbations to images to disrupt or nullify the generation of DeepFakes, but these approaches are easily detectable by human perception and…

Cited by 0SourceScholar