← Search

Tingsong Jiang

5 accepted papers

2026

Parameter-Free Fine-tuning via Redundancy Elimination for Vision Foundation Models

AAAI 2026technical

Vision foundation models (VFMs) have demonstrated remarkable capabilities in learning universal visual representations. However, adapting these models to downstream tasks conventionally requires parameter updates, with even parameter-efficient fine-tuning methods necessitating the modification of th

Cited by 0SourcePDFScholar
2026

Thermally Activated Dual-Modal Adversarial Clothing against AI Surveillance Systems

CVPR 2026

Adversarial patches have emerged as a popular privacy-preserving approach for resisting AI-driven surveillance systems. However, their conspicuous appearance makes them difficult to deploy in real-world scenarios. In this paper, we propose a thermally activated adversarial wearable designed to ensur

Cited by 0SourceScholar
2025

Robust SAM: On the Adversarial Robustness of Vision Foundation Models

AAAI 2025technical

The Segment Anything Model (SAM) is a widely used vision foundation model with diverse applications, including image segmentation, detection, and tracking. Given SAM's wide applications, understanding its robustness against adversarial attacks is crucial for real-world deployment. However, research…

Cited by 1SourcePDFScholar
2023

RFLA: A Stealthy Reflected Light Adversarial Attack in the Physical World

ICCV 2023poster

Physical adversarial attacks against deep neural networks (DNNs) have recently gained increasing attention. The current mainstream physical attacks use printed adversarial patches or camouflage to alter the appearance of the target object. However, these approaches generate conspicuous adversarial p…

Cited by 35PDFcodeScholar
2022

FCA: Learning a 3D Full-Coverage Vehicle Camouflage for Multi-View Physical Adversarial Attack

AAAI 2022technical

Physical adversarial attacks in object detection have attracted increasing attention. However, most previous works focus on hiding the objects from the detector by generating an individual adversarial patch, which only covers the planar part of the vehicle’s surface and fails to attack the detector…