← Search

Yingjie Lao

19 accepted papers

2026

WhisperSplat: Lossless Steganography in 3D Gaussian Splatting

ICML 2026poster

We present WhisperSplat, the first lossless steganography method for 3D Gaussian Splatting (3DGS) models that hides a full‐resolution 2D image in a single view without any degradation of the model's rendering quality elsewhere. Prior work embeds data by retraining or modifying model weights, alterin…

Cited by 0SourceScholar
2025

Advancing Adversarial Robustness in GNeRFs: The IL2-NeRF Attack

CVPR 2025poster

Generalizable Neural Radiance Fields (GNeRF) are recognized as one of the most promising techniques for novel view synthesis and 3D model generation in real-world applications. However, like other generative models in computer vision, ensuring their adversarial robustness against various threat mode…

2025

BAM-ICL: Causal Hijacking In-Context Learning with Budgeted Adversarial Manipulation

NeurIPS 2025poster

Recent research shows that large language models (LLMs) are vulnerable to hijacking attacks under the scenario of in-context learning (ICL) where LLMs demonstrate impressive capabilities in performing tasks by conditioning on a sequence of in-context examples (ICEs) (i.e., prompts with task-specific…

Cited by 0SourceScholar
2025

UIBDiffusion: Universal Imperceptible Backdoor Attack for Diffusion Models

CVPR 2025highlight

Recent studies show that diffusion models (DMs) are vulnerable to backdoor attacks. Existing backdoor attacks impose unconcealed triggers (e.g., a gray box and eyeglasses) that contain evident patterns, rendering remarkable attack effects yet easy detection upon human inspection and defensive algori…

2024

Understanding the Robustness of Randomized Feature Defense Against Query-Based Adversarial Attacks

ICLR 2024poster

Recent works have shown that deep neural networks are vulnerable to adversarial examples that find samples close to the original image but can make the model misclassify. Even with access only to the model's output, an attacker can employ black-box attacks to generate such adversarial examples. In t…

2023

Defending Backdoor Attacks on Vision Transformer via Patch Processing

AAAI 2023technical

Vision Transformers (ViTs) have a radically different architecture with significantly less inductive bias than Convolutional Neural Networks. Along with the improvement in performance, security and robustness of ViTs are also of great importance to study. In contrast to many recent works that exploi…

Cited by 34SourcePDFScholar
2023

Fully Attentional Networks with Self-emerging Token Labeling

ICCV 2023poster

Recent studies indicate that Vision Transformers (ViTs) are robust against out-of-distribution scenarios. In particular, the Fully Attentional Network (FAN) - a family of ViT backbones, has achieved state-of-the-art robustness. In this paper, we revisit the FAN models and improve their pre-training…

Cited by 8PDFcodeScholar
2022

CLPA: Clean-Label Poisoning Availability Attacks Using Generative Adversarial Nets

AAAI 2022technical

Poisoning attacks are emerging threats to deep neural networks where the adversaries attempt to compromise the models by injecting malicious data points in the clean training data. Poisoning attacks target either the availability or integrity of a model. The availability attack aims to degrade the o…

2022

DeepAuth: A DNN Authentication Framework by Model-Unique and Fragile Signature Embedding

AAAI 2022technical

Along with the evolution of deep neural networks (DNNs) in many real-world applications, the complexity of model building has also dramatically increased. Therefore, it is vital to protect the intellectual property (IP) of the model builder and ensure the trustworthiness of the deployed models. Mean…

Cited by 31SourcePDFScholar