← Search

Wei Wan

10 accepted papers

2025

An Efficient Residual-based Low-dose PET Reconstruction with Spatial-Frequency Integration

ICASSP 2025accepted

Positron emission tomography (PET) is a nuclear medical imaging technique where image quality depends on the dose of radionuclides administered to the patient. While standard-dose PET (SPET) offers high-quality imaging, it also poses radiation risks. If reconstructing low-dose PET (LPET) images can…

Cited by 0SourceScholar
2025

Breaking Barriers in Physical-World Adversarial Examples: Improving Robustness and Transferability via Robust Feature

AAAI 2025technical

As deep neural networks (DNNs) are widely applied in the physical world, many researches are focusing on physical-world adversarial examples (PAEs), which introduce perturbations to inputs and cause the model's incorrect outputs. However, existing PAEs face two challenges: unsatisfactory attack perf…

2025

MARS: A Malignity-Aware Backdoor Defense in Federated Learning

NeurIPS 2025poster

Federated Learning (FL) is a distributed paradigm aimed at protecting participant data privacy by exchanging model parameters to achieve high-quality model training. However, this distributed nature also makes FL highly vulnerable to backdoor attacks. Notably, the recently proposed state-of-the-art…

Cited by 0SourceScholar
2025

NumbOD: A Spatial-Frequency Fusion Attack Against Object Detectors

AAAI 2025technical

With the advancement of deep learning, object detectors (ODs) with various architectures have achieved significant success in complex scenarios like autonomous driving. Previous adversarial attacks against ODs have been focused on designing customized attacks targeting their specific structures (eg,…

2025

PB-UAP: Hybride Universal Adversarial Attack for Image Segmentation

ICASSP 2025accepted

With the rapid advancement of deep learning, the model robustness has become a significant research hotspot, i.e., adversarial attacks on deep neural networks. Existing works primarily focus on image classification tasks, aiming to alter the model’s predicted labels. Due to the output complexity and…

Cited by 0SourceScholar
2025

Preference Identification by Interaction Overlap for Bundle Recommendation

IJCAI 2025

In the digital age, recommendation systems are crucial for enhancing user experiences, with bundle recommendations playing a key role by integrating complementary products. However, existing methods fail to accurately identify user preferences for specific items within bundles, making it difficult t

Cited by 0SourcePDFScholar
2025

Transferable Direct Prompt Injection via Activation-Guided MCMC Sampling

EMNLP 2025

Direct Prompt Injection (DPI) attacks pose a critical security threat to Large Language Models (LLMs) due to their low barrier of execution and high potential damage. To address the impracticality of existing white-box/gray-box methods and the poor transferability of black-box methods, we propose an

Cited by 0SourcePDFScholar
2024

DarkFed: A Data-Free Backdoor Attack in Federated Learning

IJCAI 2024poster

Federated learning (FL) has been demonstrated to be susceptible to backdoor attacks. However, existing academic studies on FL backdoor attacks rely on a high proportion of real clients with main task-related data, which is impractical. In the context of real-world industrial scenarios, even the simp…

2024

MISA: Unveiling the Vulnerabilities in Split Federated Learning

ICASSP 2024accepted

Federated learning (FL) and split learning (SL) are prevailing distributed paradigms in recent years. They both enable shared global model training while keeping data localized on users’ devices. The former excels in parallel execution capabilities, while the latter enjoys low dependence on edge com…

Cited by 0SourceScholar
2022

Shielding Federated Learning: Robust Aggregation with Adaptive Client Selection

IJCAI 2022poster

Federated learning (FL) enables multiple clients to collaboratively train an accurate global model while protecting clients' data privacy. However, FL is susceptible to Byzantine attacks from malicious participants. Although the problem has gained significant attention, existing defenses have severa…