← Search

Guowen Xu

18 accepted papers

2026

MPMA: Preference Manipulation Attack Against Model Context Protocol

AAAI 2026technical

Model Context Protocol (MCP) standardizes interface mapping for large language models (LLMs) to access external data and tools, which revolutionizes the paradigm of tool selection and facilitates the rapid expansion of the LLM agent tool ecosystem. However, as the MCP is increasingly adopted, third-

Cited by 0SourcePDFScholar
2026

MartDE: A Privacy-Preserving and Cost-Efficient Evaluation Framework for Data Marketplaces

AAAI 2026technical

The development of machine learning models increasingly relies on high-quality data that resides in private domains. To enable secure and value-driven data exchange under strict privacy regulations, federated learning (FL) has emerged as a key primitive by enabling the trading of model utilities ins

Cited by 0SourcePDFScholar
2026

Removing Box-Free Watermarks for Image-to-Image Models via Query-Based Reverse Engineering

AAAI 2026technical

The intellectual property of deep generative networks (GNets) can be protected using a cascaded hiding network (HNet) which embeds watermarks (or marks) into GNet outputs, known as box-free watermarking. Although both GNet and HNet are encapsulated in a black box (called operation network, or ONet),

Cited by 0SourcePDFScholar
2026

TEAR: Temporal-aware Automated Red-teaming for Text-to-Video Models

CVPR 2026

Text-to-Video (T2V) models are capable of synthesizing high-quality, temporally coherent dynamic video content, but the diverse generation also inherently introduces critical safety challenges. Existing safety evaluation methods, which focus on static image and text generation, are insufficient to c

Cited by 0SourceScholar
2025

CP-Guard: Malicious Agent Detection and Defense in Collaborative Bird’s Eye View Perception

AAAI 2025technical

Collaborative Perception (CP) has shown a promising technique for autonomous driving, where multiple connected and autonomous vehicles (CAVs) share their perception information to enhance the overall perception performance and expand the perception range. However, in CP, ego CAV needs to receive mes…

Cited by 3SourcePDFScholar
2025

Decoder Gradient Shield: Provable and High-Fidelity Prevention of Gradient-Based Box-Free Watermark Removal

CVPR 2025poster

The intellectual property of deep image-to-image models can be protected by the so-called box-free watermarking. It uses an encoder and a decoder, respectively, to embed into and extract from the model's output images invisible copyright marks. Prior works have improved watermark robustness, focusin…

2025

Omni-Angle Assault: An Invisible and Powerful Physical Adversarial Attack on Face Recognition

ICML 2025poster

Deep learning models employed in face recognition (FR) systems have been shown to be vulnerable to physical adversarial attacks through various modalities, including patches, projections, and infrared radiation. However, existing adversarial examples targeting FR systems often suffer from issues suc…

Cited by 0SourcePDFScholar
2025

Power of Diversity: Enhancing Data-Free Black-Box Attack with Domain-Augmented Learning

AAAI 2025technical

Substitute training-based data-free black-box attacks pose a significant threat to enterprise-deployed models. These attacks use a generator to synthesize data and query APIs, then train a substitute model to approximate the target model's decision boundary based on the returned results. However, ex…

Cited by 0SourcePDFScholar
2025

The Fluorescent Veil: A Stealthy and Effective Physical Adversarial Patch Against Traffic Sign Recognition

NeurIPS 2025poster

Recently, traffic sign recognition (TSR) systems have become a prominent target for physical adversarial attacks. These attacks typically rely on conspicuous stickers and projections, or using invisible light and acoustic signals that can be easily blocked. In this paper, we introduce a novel attack…

Cited by 0SourceScholar
2025

The Ripple Effect: On Unforeseen Complications of Backdoor Attacks

ICML 2025poster

Recent research highlights concerns about the trustworthiness of third-party Pre-Trained Language Models (PTLMs) due to potential backdoor attacks. These backdoored PTLMs, however, are effective only for specific pre-defined downstream tasks. In reality, these PTLMs can be adapted to many other unre…

2024

SmartCooper: Vehicular Collaborative Perception with Adaptive Fusion and Judger Mechanism

ICRA 2024poster

In recent years, autonomous driving has garnered significant attention due to its potential for improving road safety through collaborative perception among connected and autonomous vehicles (CAVs). However, time-varying channel variations in vehicular transmission environments demand dynamic alloca…

Cited by 5SourceScholar
2023

Clean-image Backdoor: Attacking Multi-label Models with Poisoned Labels Only

ICLR 2023top-5%

Multi-label models have been widely used in various applications including image annotation and object detection. The fly in the ointment is its inherent vulnerability to backdoor attacks due to the adoption of deep learning techniques. However, all existing backdoor attacks exclusively require to m…

Cited by 47SourcePDFScholar
2023

Extracting Robust Models with Uncertain Examples

ICLR 2023poster

Model extraction attacks are proven to be a severe privacy threat to Machine Learning as a Service (MLaaS). A variety of techniques have been designed to steal a remote machine learning model with high accuracy and fidelity. However, how to extract a robust model with similar resilience against adve…

Cited by 8SourcePDFScholar
2023

GuardHFL: Privacy Guardian for Heterogeneous Federated Learning

ICML 2023poster

Heterogeneous federated learning (HFL) enables clients with different computation and communication capabilities to collaboratively train their own customized models via a query-response paradigm on auxiliary datasets. However, such a paradigm raises serious privacy concerns due to the leakage of hi…

Cited by 6SourcePDFScholar
2022

Improving Adversarial Robustness of 3D Point Cloud Classification Models

ECCV 2022poster

"3D point cloud classification models based on deep neural networks were proven to be vulnerable to adversarial examples, with a quantity of novel attack techniques proposed by researchers recently. It is of paramount importance to preserve the robustness of 3D models under adversarial environments,…

2022

Iron: Private Inference on Transformers

NeurIPS 2022accept

We initiate the study of private inference on Transformer-based models in the client-server setting, where clients have private inputs and servers hold proprietary models. Our main contribution is to provide several new secure protocols for matrix multiplication and complex non-linear functions like…

Cited by 123SourcePDFScholar