← Search

Yushu Zhang

7 accepted papers

2026

Learning Tight Rejection Boundaries without Negatives for Strict One-Class Audio Deepfake Detection

ICML 2026poster

The rapid evolution of audio deepfakes requires robust detection capable of generalizing to unseen attacks. One-class learning offers inherent robustness for this task by characterizing real speech distributions to detect anomalies. However, establishing a compact decision boundary without spoof sup…

Cited by 0SourceScholar
2026

Nasty Adversarial Training: A Probability Sparsity Perspective for Robustness Enhancement

ICLR 2026poster

The vulnerability of deep neural networks to adversarial examples poses significant challenges to their reliable deployment. Among existing empirical defenses, adversarial training and robust distillation have proven the most effective. In this paper, we identify a property originally associated wit…

Cited by 0SourceScholar
2025

Multi-View Collaborative Learning Network for Speech Deepfake Detection

AAAI 2025technical

As deep learning techniques advance rapidly, deepfake speech synthesized through text-to-speech or voice conversion networks is becoming increasingly realistic, posing significant challenges for detection and raising potential threats to social security. This growing realism has prompted extensive r…

Cited by 0SourcePDFScholar
2025

Phoneme-Level Feature Discrepancies: A Key to Detecting Sophisticated Speech Deepfakes

AAAI 2025technical

Recent advancements in text-to-speech and speech conversion technologies have enabled the creation of highly convincing synthetic speech. While these innovations offer numerous practical benefits, they also cause significant security challenges when maliciously misused. Therefore, there is an urgent…

Cited by 0SourcePDFScholar
2025

Transparent Vision: A Theory of Hierarchical Invariant Representations

ICCV 2025poster

Developing robust and interpretable vision systems is a crucial step towards trustworthy artificial intelligence. One promising paradigm is to design transparent structures, e.g., geometric invariance, for fundamental representations. However, such invariants exhibit limited discriminability, limiti…

Cited by 0SourcePDFScholar
2024

Conditional Backdoor Attack via JPEG Compression

AAAI 2024technical

Deep neural network (DNN) models have been proven vulnerable to backdoor attacks. One trend of backdoor attacks is developing more invisible and dynamic triggers to make attacks stealthier. However, these invisible and dynamic triggers can be inadvertently mitigated by some widely used passive denoi…

Cited by 5SourcePDFScholar