← Search

Hangcheng Cao

5 accepted papers

2026

Learning Mutual View Information Graph for Adaptive Adversarial Collaborative Perception

CVPR 2026

Collaborative perception (CP) enables data sharing among connected and autonomous vehicles (CAVs) to enhance driving safety. However, CP systems are vulnerable to adversarial attacks where malicious agents forge false objects via feature-level perturbations. Current defensive systems use threshold-b

Cited by 0SourcecodeScholar
2026

MartDE: A Privacy-Preserving and Cost-Efficient Evaluation Framework for Data Marketplaces

AAAI 2026technical

The development of machine learning models increasingly relies on high-quality data that resides in private domains. To enable secure and value-driven data exchange under strict privacy regulations, federated learning (FL) has emerged as a key primitive by enabling the trading of model utilities ins

Cited by 0SourcePDFScholar
2026

RecoverMark: Robust Watermarking for Localization and Recovery of Manipulated Faces

CVPR 2026

The proliferation of AI-generated content (AIGC) has facilitated sophisticated face manipulation, severely undermining visual integrity and posing unprecedented challenges to intellectual property (IP). In response, a common proactive defense leverages fragile watermarks to detect, localize, or even

Cited by 0SourceScholar
2026

Removing Box-Free Watermarks for Image-to-Image Models via Query-Based Reverse Engineering

AAAI 2026technical

The intellectual property of deep generative networks (GNets) can be protected using a cascaded hiding network (HNet) which embeds watermarks (or marks) into GNet outputs, known as box-free watermarking. Although both GNet and HNet are encapsulated in a black box (called operation network, or ONet),

Cited by 0SourcePDFScholar
2025

Omni-Angle Assault: An Invisible and Powerful Physical Adversarial Attack on Face Recognition

ICML 2025poster

Deep learning models employed in face recognition (FR) systems have been shown to be vulnerable to physical adversarial attacks through various modalities, including patches, projections, and infrared radiation. However, existing adversarial examples targeting FR systems often suffer from issues suc…

Cited by 0SourcePDFScholar