← Search

Shengshan Hu

30 accepted papers

2026

Dual-View Inference Attack: Machine Unlearning Amplifies Privacy Exposure

AAAI 2026technical

Machine unlearning is a newly popularized technique for removing specific training data from a trained model, enabling it to comply with data deletion requests. While it protects the rights of users requesting unlearning, it also introduces new privacy risks. Prior works have primarily focused on th

Cited by 0SourcePDFScholar
2026

UFVideo: Towards Unified Fine-Grained Video Cooperative Understanding with Large Language Models

CVPR 2026

With the advancement of multi-modal Large Language Models (LLMs), Video LLMs have been further developed to perform on holistic and specialized video understanding. However, existing works are limited to specialized video understanding tasks, failing to achieve a comprehensive and multi-grained vide

Cited by 0SourceScholar
2025

AdvEDM: Fine-grained Adversarial Attack against VLM-based Embodied Agents

NeurIPS 2025poster

Vision-Language Models (VLMs), with their strong reasoning and planning capabilities, are widely used in embodied decision-making (EDM) tasks in embodied agents, such as autonomous driving and robotic manipulation. Recent research has increasingly explored adversarial attacks on VLMs to reveal their…

Cited by 0SourceScholar
2025

An Efficient Residual-based Low-dose PET Reconstruction with Spatial-Frequency Integration

ICASSP 2025accepted

Positron emission tomography (PET) is a nuclear medical imaging technique where image quality depends on the dose of radionuclides administered to the patient. While standard-dose PET (SPET) offers high-quality imaging, it also poses radiation risks. If reconstructing low-dose PET (LPET) images can…

Cited by 0SourceScholar
2025

BadRobot: Jailbreaking Embodied LLM Agents in the Physical World

ICLR 2025poster

Embodied AI represents systems where AI is integrated into physical entities. Multimodal Large Language Model (LLM), which exhibits powerful language understanding abilities, has been extensively employed in embodied AI by facilitating sophisticated task planning. However, a critical safety issue re…

Cited by 0SourcePDFScholar
2025

Breaking Barriers in Physical-World Adversarial Examples: Improving Robustness and Transferability via Robust Feature

AAAI 2025technical

As deep neural networks (DNNs) are widely applied in the physical world, many researches are focusing on physical-world adversarial examples (PAEs), which introduce perturbations to inputs and cause the model's incorrect outputs. However, existing PAEs face two challenges: unsatisfactory attack perf…

2025

Detecting and Corrupting Convolution-based Unlearnable Examples

AAAI 2025technical

Convolution-based unlearnable examples (UEs) employ class-wise multiplicative convolutional noise to training samples, severely compromising model performance. This fire-new type of UEs have successfully countered all defense mechanisms against UEs. The failure of such defenses can be attributed to…

2025

Improving Generalization of Universal Adversarial Perturbation via Dynamic Maximin Optimization

AAAI 2025technical

Deep neural networks (DNNs) are susceptible to universal adversarial perturbations (UAPs). These perturbations are meticulously designed to fool the target model universally across all sample classes. Unlike instance-specific adversarial examples (AEs), generating UAPs is more complex because they m…

2025

MARS: A Malignity-Aware Backdoor Defense in Federated Learning

NeurIPS 2025poster

Federated Learning (FL) is a distributed paradigm aimed at protecting participant data privacy by exchanging model parameters to achieve high-quality model training. However, this distributed nature also makes FL highly vulnerable to backdoor attacks. Notably, the recently proposed state-of-the-art…

Cited by 0SourceScholar
2025

NumbOD: A Spatial-Frequency Fusion Attack Against Object Detectors

AAAI 2025technical

With the advancement of deep learning, object detectors (ODs) with various architectures have achieved significant success in complex scenarios like autonomous driving. Previous adversarial attacks against ODs have been focused on designing customized attacks targeting their specific structures (eg,…

2025

PB-UAP: Hybride Universal Adversarial Attack for Image Segmentation

ICASSP 2025accepted

With the rapid advancement of deep learning, the model robustness has become a significant research hotspot, i.e., adversarial attacks on deep neural networks. Existing works primarily focus on image classification tasks, aiming to alter the model’s predicted labels. Due to the output complexity and…

Cited by 0SourceScholar
2025

Test-Time Backdoor Detection for Object Detection Models

CVPR 2025poster

Object detection models are vulnerable to backdoor attacks, where attackers poison a small subset of training samples by embedding a predefined trigger to manipulate prediction. Detecting poisoned samples (i.e., those containing triggers) at test time can prevent backdoor activation. However, unlike…

Cited by 1SourcePDFScholar
2025

Transferable Direct Prompt Injection via Activation-Guided MCMC Sampling

EMNLP 2025

Direct Prompt Injection (DPI) attacks pose a critical security threat to Large Language Models (LLMs) due to their low barrier of execution and high potential damage. To address the impracticality of existing white-box/gray-box methods and the poor transferability of black-box methods, we propose an

Cited by 0SourcePDFScholar
2025

Vanish into Thin Air: Cross-prompt Universal Adversarial Attacks for SAM2

NeurIPS 2025spotlight

Recent studies reveal the vulnerability of the image segmentation foundation model SAM to adversarial examples. Its successor, SAM2, has attracted significant attention due to its strong generalization capability in video segmentation. However, its robustness remains unexplored, and it is unclear wh…

Cited by 0SourceScholar
2024

DarkFed: A Data-Free Backdoor Attack in Federated Learning

IJCAI 2024poster

Federated learning (FL) has been demonstrated to be susceptible to backdoor attacks. However, existing academic studies on FL backdoor attacks rely on a high proportion of real clients with main task-related data, which is impractical. In the context of real-world industrial scenarios, even the simp…

2024

DarkSAM: Fooling Segment Anything Model to Segment Nothing

NeurIPS 2024poster

Segment Anything Model (SAM) has recently gained much attention for its outstanding generalization to unseen data and tasks. Despite its promising prospect, the vulnerabilities of SAM, especially to universal adversarial perturbation (UAP) have not been thoroughly investigated yet. In this paper, we…

2024

Detector Collapse: Backdooring Object Detection to Catastrophic Overload or Blindness in the Physical World

IJCAI 2024poster

Object detection tasks, crucial in safety-critical systems like autonomous driving, focus on pinpointing object locations. These detectors are known to be susceptible to backdoor attacks. However, existing backdoor techniques have primarily been adapted from classification tasks, overlooking deeper…

Cited by 13SourcePDFScholar
2024

MISA: Unveiling the Vulnerabilities in Split Federated Learning

ICASSP 2024accepted

Federated learning (FL) and split learning (SL) are prevailing distributed paradigms in recent years. They both enable shared global model training while keeping data localized on users’ devices. The former excels in parallel execution capabilities, while the latter enjoys low dependence on edge com…

Cited by 0SourceScholar
2024

Revisiting Gradient Pruning: A Dual Realization for Defending against Gradient Attacks

AAAI 2024technical

Collaborative learning (CL) is a distributed learning framework that aims to protect user privacy by allowing users to jointly train a model by sharing their gradient updates only. However, gradient inversion attacks (GIAs), which recover users' training data from shared gradients, impose severe pri…

Cited by 2SourcePDFScholar
2024

Stealthy Backdoor Attack Towards Federated Automatic Speaker Verification

ICASSP 2024accepted

Automatic speech verification (ASV) authenticates individuals based on distinct vocal patterns, playing a pivotal role in many applications such as voice-based unlocking systems for devices. The ASV system comprises three stages: training, registration, and validation. The model refines using voice…

Cited by 0SourceScholar
2024

Towards Model Extraction Attacks in GAN-Based Image Translation via Domain Shift Mitigation

AAAI 2024technical

Model extraction attacks (MEAs) enable an attacker to replicate the functionality of a victim deep neural network (DNN) model by only querying its API service remotely, posing a severe threat to the security and integrity of pay-per-query DNN-based services. Although the majority of current research…

Cited by 3SourcePDFScholar
2024

Unlearnable 3D Point Clouds: Class-wise Transformation Is All You Need

NeurIPS 2024poster

Traditional unlearnable strategies have been proposed to prevent unauthorized users from training on the 2D image data. With more 3D point cloud data containing sensitivity information, unauthorized usage of this new type data has also become a serious concern. To address this, we propose the first…

2023

Benchmarking and Analyzing Robust Point Cloud Recognition: Bag of Tricks for Defending Adversarial Examples

ICCV 2023poster

Deep Neural Networks (DNNs) for 3D point cloud recognition are vulnerable to adversarial examples, threatening their practical deployment. Despite the many research endeavors have been made to tackle this issue in recent years, the diversity of adversarial examples on 3D point clouds makes them more…

Cited by 5PDFcodeScholar
2023

Denial-of-Service or Fine-Grained Control: Towards Flexible Model Poisoning Attacks on Federated Learning

IJCAI 2023poster

Federated learning (FL) is vulnerable to poisoning attacks, where adversaries corrupt the global aggregation results and cause denial-of-service (DoS). Unlike recent model poisoning attacks that optimize the amplitude of malicious perturbations along certain prescribed directions to cause DoS, we pr…

Cited by 17SourcePDFScholar
2023

Detecting Backdoors During the Inference Stage Based on Corruption Robustness Consistency

CVPR 2023poster

Deep neural networks are proven to be vulnerable to backdoor attacks. Detecting the trigger samples during the inference stage, i.e., the test-time trigger sample detection, can prevent the backdoor from being triggered. However, existing detection methods often require the defenders to have high ac…

2023

Downstream-agnostic Adversarial Examples

ICCV 2023poster

Self-supervised learning usually uses a large amount of unlabeled data to pre-train an encoder which can be used as a general-purpose feature extractor, such that downstream users only need to perform fine-tuning operations to enjoy the benefit of "big model". Despite this promising prospect, the se…

Cited by 30PDFcodeScholar
2023

PointCA: Evaluating the Robustness of 3D Point Cloud Completion Models against Adversarial Examples

AAAI 2023technical

Point cloud completion, as the upstream procedure of 3D recognition and segmentation, has become an essential part of many tasks such as navigation and scene understanding. While various point cloud completion models have demonstrated their powerful capabilities, their robustness against adversarial…

Cited by 13SourcePDFScholar
2023

Voice Guard: Protecting Voice Privacy with Strong and Imperceptible Adversarial Perturbation in the Time Domain

IJCAI 2023poster

Adversarial example is a rising tool for voice privacy protection. By adding imperceptible noise to public audio, it prevents tampers from using zero-shot Voice Conversion (VC) to synthesize high quality speech with target speaker identity. However, many existing studies ignore the human perception…

Cited by 7SourcePDFScholar
2022

Protecting Facial Privacy: Generating Adversarial Identity Masks via Style-Robust Makeup Transfer

CVPR 2022poster

While deep face recognition (FR) systems have shown amazing performance in identification and verification, they also arouse privacy concerns for their excessive surveillance on users, especially for public face images widely spread on social networks. Recently, some studies adopt adversarial exampl…

Cited by 130PDFcodeScholar
2022

Shielding Federated Learning: Robust Aggregation with Adaptive Client Selection

IJCAI 2022poster

Federated learning (FL) enables multiple clients to collaboratively train an accurate global model while protecting clients' data privacy. However, FL is susceptible to Byzantine attacks from malicious participants. Although the problem has gained significant attention, existing defenses have severa…