← Search

Feiyang Wang

9 accepted papers

2026

Bias in Zeroth-Order Normal Estimation for Decision-Based Attacks

ICML 2026poster

Decision-based image attacks commonly rely on zeroth-order (ZO) Monte Carlo probing to estimate decision-boundary normals and iteratively refine adversarial perturbations to minimize the $\ell_2$ norm. We theoretically analyze and empirically demonstrate an intrinsic inefficiency arising from hetero…

Cited by 0SourceScholar
2026

SeRI: Gradient-Free Sensitive Region Identification in Decision-Based Black-Box Attacks

ICLR 2026poster

Deep neural networks (DNNs) are highly vulnerable to adversarial attacks, where small, carefully crafted perturbations are added to input images to cause misclassification. These perturbations are particularly effective when concentrated in sensitive regions of an image that strongly influence the m…

Cited by 0SourcecodeScholar
2025

ADBA: Approximation Decision Boundary Approach for Black-Box Adversarial Attacks

AAAI 2025technical

Many machine learning models are susceptible to adversarial attacks, with decision-based black-box attacks representing the most critical threat in real-world applications. These attacks are extremely stealthy, generating adversarial examples using hard labels obtained from the target machine learni…

2025

RDI: An adversarial robustness evaluation metric for deep neural networks based on model statistical features

UAI 2025

Deep neural networks (DNNs) are highly susceptible to adversarial samples, raising concerns about their reliability in safety-critical tasks. Currently, methods of evaluating adversarial robustness are primarily categorized into attack-based and certified robustness evaluation approaches. The former

2025

TtBA: Two-third Bridge Approach for Decision-Based Adversarial Attack

ICML 2025poster

A key challenge in black-box adversarial attacks is the high query complexity in hard-label settings, where only the top-1 predicted label from the target deep model is accessible. In this paper, we propose a novel normal-vector-based method called Two-third Bridge Attack (TtBA). A innovative bridge…

Cited by 0SourcePDFScholar
2024

Motif-Aware Riemannian Graph Neural Network with Generative-Contrastive Learning

AAAI 2024technical

Graphs are typical non-Euclidean data of complex structures. In recent years, Riemannian graph representation learning has emerged as an exciting alternative to Euclidean ones. However, Riemannian methods are still in an early stage: most of them present a single curvature (radius) regardless of str…

2023

CONGREGATE: Contrastive Graph Clustering in Curvature Spaces

IJCAI 2023poster

Graph clustering is a longstanding research topic, and has achieved remarkable success with the deep learning methods in recent years. Nevertheless, we observe that several important issues largely remain open. On the one hand, graph clustering from the geometric perspective is appealing but has rar…

2023

Self-Supervised Continual Graph Learning in Adaptive Riemannian Spaces

AAAI 2023technical

Continual graph learning routinely finds its role in a variety of real-world applications where the graph data with different tasks come sequentially. Despite the success of prior works, it still faces great challenges. On the one hand, existing methods work with the zero-curvature Euclidean space,…

Cited by 37SourcePDFScholar
2021

Hyperbolic Variational Graph Neural Network for Modeling Dynamic Graphs

AAAI 2021technical

Learning representations for graphs plays a critical role in a wide spectrum of downstream applications. In this paper, we summarize the limitations of the prior works in three folds: representation space, modeling dynamics and modeling uncertainty. To bridge this gap, we propose to learn dynamic gr…

Cited by 81SourcePDFScholar