← Search

Ximeng Liu

12 accepted papers

2025

Adversarial-Inspired Backdoor Defense via Bridging Backdoor and Adversarial Attacks

AAAI 2025technical

Backdoor attacks and adversarial attacks are two major security threats to deep neural networks (DNNs), with the former one is a training-time data poisoning attack that aims to implant backdoor triggers into models by injecting trigger patterns into training samples, and the latter one is a testing…

Cited by 0SourcePDFScholar
2025

Refine then Classify: Robust Graph Neural Networks with Reliable Neighborhood Contrastive Refinement

AAAI 2025technical

Graph Neural Networks (GNNs) have exhibited remarkable capabilities for dealing with graph-structured data. However, recent studies have revealed their fragility to adversarial attacks, where imperceptible perturbations to the graph structure can easily mislead predictions. To enhance adversarial ro…

Cited by 0SourcePDFScholar
2025

Strategy-Architecture Synergy: A Multi-View Graph Contrastive Paradigm for Consistent Representations

IJCAI 2025

Facing the growing diversity of multi-view data, multi-view graph-based models have made encouraging progress in handling multi-view data modeled as graphs. Graph Contrastive Learning (GCL) naturally fits multi-view graph data by treating their inherent views as augmentations. However, the developme

Cited by 0SourcePDFScholar
2024

MEAT: Median-Ensemble Adversarial Training for Improving Robustness and Generalization

ICASSP 2024accepted

Self-ensemble adversarial training methods improve model robustness by ensembling models at different training epochs, such as model weight averaging (WA). However, previous research has shown that self-ensemble defense methods in adversarial training (AT) still suffer from robust overfitting, which…

Cited by 0SourceScholar
2023

An Adaptive Model Ensemble Adversarial Attack for Boosting Adversarial Transferability

ICCV 2023poster

While the transferability property of adversarial examples allows the adversary to perform black-box attacks i.e., the attacker has no knowledge about the target model), the transfer-based adversarial attacks have gained great attention. Previous works mostly study gradient variation or image transf…

Cited by 47PDFcodeScholar
2023

Enhance Transferability of Adversarial Examples with Model Architecture

ICASSP 2023accepted

Transferability of adversarial examples is of critical importance to launch black-box adversarial attacks, where attackers are only allowed to access the output of the target model. However, under such a challenging but practical setting, the crafted adversarial examples are always prone to overfitt…

Cited by 0SourceScholar
2023

Globally Consistent Federated Graph Autoencoder for Non-IID Graphs

IJCAI 2023poster

Graph neural networks (GNNs) have been applied successfully in many machine learning tasks due to their advantages in utilizing neighboring information. Recently, with the global enactment of privacy protection regulations, federated GNNs have gained increasing attention in academia and industry. Ho…

2023

SRoUDA: Meta Self-Training for Robust Unsupervised Domain Adaptation

AAAI 2023technical

As acquiring manual labels on data could be costly, unsupervised domain adaptation (UDA), which transfers knowledge learned from a rich-label dataset to the unlabeled target dataset, is gaining increasingly more popularity. While extensive studies have been devoted to improving the model accuracy on…

2022

Combating False Sense of Security: Breaking the Defense of Adversarial Training Via Non-Gradient Adversarial Attack

ICASSP 2022accepted

Adversarial training is believed to be the most robust and effective defense method against adversarial attacks. Gradient-based adversarial attack methods are generally adopted to evaluate the effectiveness of adversarial training. However, in this paper, by diving into the existing adversarial atta…

Cited by 0SourceScholar
2022

SecMPNN: 3-Party Privacy-Preserving Molecular Structure Properties Inference

ICASSP 2022accepted

Compound screening is a key step in the development of new drugs. Current high-throughput screening methods cannot be widely adopted by laboratories due to their expensive equipment and low efficiency. The booming deep learning in recent years has provided a new answer to this question. The message…

Cited by 0SourceScholar
2021

Privacy-Preserving Optimal Insulin Dosing Decision

ICASSP 2021accepted

Precision diagnosis and treatment are blending outcomes of machine learning and the Internet of Medical Things (IoMT). In the diabetes treatment, a medical center acts as a medical service provider (MSP) with patients data from IoMT devices. The MSP calculates the accurate dosage by importing the he…

Cited by 0SourceScholar