← Search

Jinyu Tian

15 accepted papers

2026

Deferred Poisoning: Making the Model More Vulnerable via Hessian Singularization

AAAI 2026technical

Recent studies have shown that deep learning models are very vulnerable to poisoning attacks. Many defense methods have been proposed to address this issue. However, traditional poisoning attacks are not as threatening as commonly believed. This is because they often cause differences in how the mod

Cited by 0SourcePDFScholar
2026

Forensic-Friendly Image Manipulation via Controllable Latent Diffusion

CVPR 2026

With diffusion models demonstrating superior capabilities in image editing, more users now rely on online servers for content manipulation via textual prompts rather than traditional offline tools. Despite servers attempting to prevent the proliferation of maliciously edited content via active defen

Cited by 0SourcecodeScholar
2026

NAIPv2: Debiased Pairwise Learning for Efficient Paper Quality Estimation

ICLR 2026poster

The ability to estimate the quality of scientific papers is central to how both humans and AI systems will advance scientific knowledge in the future. However, existing LLM-based estimation methods suffer from high inference cost, whereas the faster direct score regression approach is limited by sca…

Cited by 0SourcecodeScholar
2026

OAD-Promoter: Enhancing Zero-Shot VQA Using Large Language Models with Object Attribute Description

AAAI 2026technical

Large Language Models (LLMs) have become a crucial tool in Visual Question Answering (VQA) for handling knowledge-intensive questions in few-shot or zero-shot scenarios. However, their reliance on massive training datasets often causes them to inherit language biases during the acquisition of knowle

Cited by 0SourcePDFScholar
2025

Anti-Diffusion: Preventing Abuse of Modifications of Diffusion-Based Models

AAAI 2025technical

Although diffusion-based techniques have shown remarkable success in image generation and editing tasks, their abuse can lead to severe negative social impacts. Recently, some works have been proposed to provide defense against the abuse of diffusion-based methods. However, their protection may be l…

2025

Data-Free Universal Attack by Exploiting the Intrinsic Vulnerability of Deep Models

AAAI 2025technical

Deep neural networks (DNNs) are susceptible to Universal Adversarial Perturbations (UAPs), which are instance-agnostic perturbations that can deceive a target model across a wide range of samples. Unlike instance-specific adversarial examples, UAPs present a greater challenge as they must generalize…

2025

From Words to Worth: Newborn Article Impact Prediction with LLM

AAAI 2025technical

Predicting the future impact of newly published articles is pivotal for advancing scientific discovery in an era of unprecedented scholarly expansion. This paper introduces a promising approach, leveraging the capabilities of LLMs to predict the future impact of newborn articles solely based on titl…

Cited by 2SourcePDFScholar
2024

DAT: Improving Adversarial Robustness via Generative Amplitude Mix-up in Frequency Domain

NeurIPS 2024poster

To protect deep neural networks (DNNs) from adversarial attacks, adversarial training (AT) is developed by incorporating adversarial examples (AEs) into model training. Recent studies show that adversarial attacks disproportionately impact the patterns within the phase of the sample's frequency spec…

2024

DifAttack: Query-Efficient Black-Box Adversarial Attack via Disentangled Feature Space

AAAI 2024technical

This work investigates efficient score-based black-box adversarial attacks with high Attack Success Rate (ASR) and good generalizability. We design a novel attack method based on a Disentangled Feature space, called DifAttack, which differs significantly from the existing ones operating over the ent…

2023

Effective Ambiguity Attack Against Passport-Based DNN Intellectual Property Protection Schemes Through Fully Connected Layer Substitution

CVPR 2023poster

Since training a deep neural network (DNN) is costly, the well-trained deep models can be regarded as valuable intellectual property (IP) assets. The IP protection associated with deep models has been receiving increasing attentions in recent years. Passport-based method, which replaces normalizatio…

Cited by 16SourcePDFScholar
2022

Robust Image Forgery Detection Over Online Social Network Shared Images

CVPR 2022oral

The increasing abuse of image editing softwares, such as Photoshop and Meitu, causes the authenticity of digital images questionable. Meanwhile, the widespread availability of online social networks (OSNs) makes them the dominant channels for transmitting forged images to report fake news, propagate…

Cited by 85PDFcodeScholar
2021

Detecting Adversarial Examples from Sensitivity Inconsistency of Spatial-Transform Domain

AAAI 2021technical

Deep neural networks (DNNs) have been shown to be vulnerable against adversarial examples (AEs), which are maliciously designed to cause dramatic model output errors. In this work, we reveal that normal examples (NEs) are insensitive to the fluctuations occurring at the highly-curved region of the d…

Cited by 67SourcePDFScholar
2021

Probabilistic Selective Encryption of Convolutional Neural Networks for Hierarchical Services

CVPR 2021poster

Model protection is vital when deploying Convolutional Neural Networks (CNNs) for commercial services, due to the massive costs of training them. In this work, we propose a selective encryption (SE) algorithm to protect CNN models from unauthorized access, with a unique feature of providing hierarch…

Cited by 16PDFScholar
2019

Robust Subspace Clustering With Independent and Piecewise Identically Distributed Noise Modeling

CVPR 2019oral

Most of the existing subspace clustering (SC) frameworks assume that the noise contaminating the data is generated by an independent and identically distributed (i.i.d.) source, where the Gaussianity is often imposed. Though these assumptions greatly simplify the underlying problems, they do not hol…

Cited by 22PDFScholar