← Search

Yu-an Tan

6 accepted papers

2025

Boosting Generative Adversarial Transferability with Self-supervised Vision Transformer Features

ICCV 2025poster

The ability of deep neural networks (DNNs) come from extracting and interpreting features from the data provided. By exploiting intermediate features in DNNs instead of relying on hard labels, we craft adversarial perturbation that generalize more effectively, boosting black-box transferability. The…

2025

Personalized Label Inference Attack in Federated Transfer Learning via Contrastive Meta Learning

AAAI 2025technical

Federated Transfer Learning (FTL) is a popular approach to solve the problem of heterogeneous feature space and label distribution. Among the mainstream strategies for FTL, parameter decoupling, which balance the impact of a single global model and multiple personalized models under data heterogenei…

Cited by 0SourcePDFScholar
2024

Towards Transferable Adversarial Attacks with Centralized Perturbation

AAAI 2024technical

Adversarial transferability enables black-box attacks on unknown victim deep neural networks (DNNs), rendering attacks viable in real-world scenarios. Current transferable attacks create adversarial perturbation over the entire image, resulting in excessive noise that overfit the source model. Conce…

Cited by 9SourcePDFScholar
2022

Decision-based Black-box Attack Against Vision Transformers via Patch-wise Adversarial Removal

NeurIPS 2022accept

Vision transformers (ViTs) have demonstrated impressive performance and stronger adversarial robustness compared to Convolutional Neural Networks (CNNs). On the one hand, ViTs' focus on global interaction between individual patches reduces the local noise sensitivity of images. On the other hand, th…

2022

Enhancing the Transferability of Adversarial Examples with Random Patch

IJCAI 2022poster

Adversarial examples can fool deep learning models, and their transferability is critical for attacking black-box models in real-world scenarios. Existing state-of-the-art transferable adversarial attacks tend to exploit intrinsic features of objects to generate adversarial examples. This paper prop…

2021

Demiguise Attack: Crafting Invisible Semantic Adversarial Perturbations with Perceptual Similarity

IJCAI 2021poster

Deep neural networks (DNNs) have been found to be vulnerable to adversarial examples. Adversarial examples are malicious images with visually imperceptible perturbations. While these carefully crafted perturbations restricted with tight Lp norm bounds are small, they are still easily perceivable by…

Cited by 35SourcePDFScholar