← Search

Lina Wang

16 accepted papers

2026

MacPrompt: Maraconic-Guided Jailbreak Against Text-to-Image Models

AAAI 2026technical

Text-to-image (T2I) models have raised increasing safety concerns due to their capacity to generate NSFW and other banned objects. To mitigate these risks, safety filters and concept removal techniques have been introduced to block inappropriate prompts or erase sensitive concepts from the models. H

Cited by 0SourcePDFScholar
2026

PCFormer: Accelerating Privacy-preserving Transformer Inference by Partition and Combination

AAAI 2026technical

In recent years, transformer-based models have achieved remarkable success in sensitive domains, including healthcare, finance and personalized services, but their deployment raises significant privacy concerns. Existing secure inference studies have introduced cryptographic techniques such as Homom

Cited by 0SourcePDFScholar
2026

ReLUPruner: Rethinking ReLU Importance with Taylor Expansion for Efficient Private Inference

AAAI 2026technical

With the growing adoption of Machine-Learning-As-A-Service (MLaaS), Private Inference (PI) has emerged as a promising solution to address its security concerns through cryptographic techniques. However, nonlinear operations in neural networks account for most of the computational and communication o

Cited by 0SourcePDFScholar
2026

Semantic Alignment of Malicious Question Based on Contrastive Semantic Networks and Data Augmentation (Abstract Reprint)

AAAI 2026technical

The identification and filtration of malicious texts in social media environments represent a significant technical challenge aimed at protecting users from online violence and disinformation. This complexity stems from the diversity and innovativeness of social media texts, which include unique exp

Cited by 0SourcePDFScholar
2025

Analogy-based Multi-Turn Jailbreak against Large Language Models

NeurIPS 2025poster

Large language models (LLMs) are inherently designed to support multi-turn interactions, which opens up new possibilities for jailbreak attacks that unfold gradually and potentially bypass safety mechanisms more effectively than single-turn attacks. However, current multi-turn jailbreak methods are…

Cited by 0SourceScholar
2025

Automated Red Teaming for Text-to-Image Models through Feedback-Guided Prompt Iteration with Vision-Language Models

ICCV 2025poster

Text-to-image models have achieved remarkable progress in generating high-quality images from textual prompts, yet their potential for misuse like generating unsafe content remains a critical concern. Existing safety mechanisms, such as filtering and fine-tuning, remain insufficient in preventing vu…

2025

HIPP: Protecting Image Privacy via High-Quality Reversible Protected Version

IJCAI 2025

With the rapid development of the internet, sharing photos through Social Network Platforms (SNPs) has become a new way for people to socialize, which poses serious threats to personal privacy. Recently, a thumbnail-preserving image privacy protection technique has emerged and garnered widespread at

2025

Transfer Learning of Real Image Features with Soft Contrastive Loss for Fake Image Detection

AAAI 2025technical

In the last few years, the artifact patterns in fake images synthesized by different generative models have been inconsistent, leading to the failure of previous research that relied on spotting subtle differences between real and fake. In our preliminary experiments, we find that the artifacts in f…

Cited by 0SourcePDFScholar
2024

AdvShadow: Evading DeepFake Detection via Adversarial Shadow Attack

ICASSP 2024accepted

With the emergence of techniques called DeepFakes, there has been a notable proliferation of DeepFake detectors rooted in deep learning. These detectors aim to expose subtle distinctions between genuine and counterfeit facial images across spatial, frequency, and physiological domains. Unfortunately…

Cited by 0SourceScholar
2024

Chronic Poisoning: Backdoor Attack against Split Learning

AAAI 2024technical

Split learning is a computing resource-friendly distributed learning framework that protects client training data by splitting the model between the client and server. Previous work has proved that split learning faces a severe risk of privacy leakage, as a malicious server can recover the client's…

2024

Diff-HOD: Diffusion Model for Object Detection in Hazy Weather Conditions

ICASSP 2024accepted

The presence of haze negatively affects the visibility of captured images, posing challenges for general object detection models. We observe that current techniques exhibit three limitations: 1) they typically view image restoration and object detection as separate tasks; 2) they disregard potential…

Cited by 0SourceScholar
2024

TraceEvader: Making DeepFakes More Untraceable via Evading the Forgery Model Attribution

AAAI 2024technical

In recent few years, DeepFakes are posing serve threats and concerns to both individuals and celebrities, as realistic DeepFakes facilitate the spread of disinformation. Model attribution techniques aim at attributing the adopted forgery models of DeepFakes for provenance purposes and providing expl…

Cited by 7SourcePDFScholar
2023

What can Discriminator do? Towards Box-free Ownership Verification of Generative Adversarial Networks

ICCV 2023poster

In recent decades, Generative Adversarial Network (GAN) and its variants have achieved unprecedented success in image synthesis. However, well-trained GANs are under the threat of illegal steal or leakage. The prior studies on remote ownership verification assume a black-box setting where the defend…

Cited by 15PDFcodeScholar
2022

Anti-Forgery: Towards a Stealthy and Robust DeepFake Disruption Attack via Adversarial Perceptual-aware Perturbations

IJCAI 2022poster

DeepFake is becoming a real risk to society and brings potential threats to both individual privacy and political security due to the DeepFaked multimedia are realistic and convincing. However, the popular DeepFake passive detection is an ex-post forensics countermeasure and failed in blocking the d…