← Search

Yongbin Zhou

8 accepted papers

2026

FERD: Fairness-Enhanced Data-Free Adversarial Robustness Distillation

ICLR 2026poster

Data-Free Robustness Distillation (DFRD) aims to transfer the robustness from the teacher to the student without accessing the training data. While existing methods focus on overall robustness, they overlook the robust fairness issues, leading to severe disparity of robustness across different categ…

Cited by 0SourceScholar
2026

Multimodal Robust Prompt Distillation for 3D Point Cloud Models

AAAI 2026technical

Adversarial attacks pose a significant threat to learning-based 3D point cloud models, critically undermining their reliability in security-sensitive applications. Existing defense methods often suffer from (1) high computational overhead and (2) poor generalization ability across diverse attack typ

Cited by 0SourcePDFScholar
2026

Revisiting Visual Corruptions in LVLMs: A Shape-Texture Perspective on Model Failures

CVPR 2026

Large vision-language models (LVLMs) are highly vulnerable to visual corruptions, substantially compromising their reliability and limiting real-world deployment. Prior work has attributed this degradation primarily to insufficient visual grounding and overreliance on language priors. However, these

Cited by 0SourceScholar
2025

Benchmarking Multimodal Large Language Models Against Image Corruptions

ICCV 2025poster

Multimodal Large Language Models (MLLMs) have made significant strides in visual and language tasks. However, despite their impressive performance on standard datasets, these models encounter considerable robustness challenges when processing corrupted images, raising concerns about their reliabilit…

2025

CIARD: Cyclic Iterative Adversarial Robustness Distillation

ICCV 2025poster

Adversarial robustness distillation (ARD) aims to transfer both performance and robustness from teacher model to lightweight student model, enabling resilient performance on resource-constrained scenarios. Though existing ARD approaches enhance student model's robustness, the inevitable by-product l…

2025

One Head to Rule Them All: Amplifying LVLM Safety through a Single Critical Attention Head

NeurIPS 2025poster

Large Vision-Language Models (LVLMs) have demonstrated impressive capabilities in tasks requiring multimodal understanding. However, recent studies indicate that LVLMs are more vulnerable than LLMs to unsafe inputs and prone to generating harmful content. Existing defense strategies primarily includ…

Cited by 0SourcecodeScholar
2025

Towards a 3D Transfer-based Black-box Attack via Critical Feature Guidance

ICCV 2025poster

Deep neural networks for 3D point clouds have been demonstrated to be vulnerable to adversarial examples. Previous 3D adversarial attack methods often exploit certain information about the target models, such as model parameters or outputs, to generate adversarial point clouds. However, in realistic…

2024

"Veil Privacy on Visual Data: Concealing Privacy for Humans, Unveiling for DNNs"

ECCV 2024poster

"Privacy laws like GDPR necessitate effective approaches to safeguard data privacy. Existing works on data privacy protection of DNNs mainly concentrated on the model training phase. However, these approaches become impractical when dealing with the outsourcing of sensitive data. Furthermore, they h…

Cited by 0SourcePDFScholar