← Search

Yuxin Cao

9 accepted papers

2026

Failures to Surface Harmful Contents in Video Large Language Models

AAAI 2026technical

Video Large Language Models (VideoLLMs) are increasingly deployed on numerous critical applications, where users rely on auto-generated summaries while casually skimming the video stream. We show that this interaction hides a critical safety gap: if harmful content is embedded in a video, either as

Cited by 0SourcePDFScholar
2026

Towards Stealthy and Effective Backdoor Attacks on Lane Detection: A Naturalistic Data Poisoning Approach

CVPR 2026

Deep learning-based lane detection (LD) plays a critical role in autonomous driving and advanced driver assistance systems. However, its vulnerability to backdoor attacks presents a significant security concern. Existing backdoor attack methods on LD often exhibit limited practical utility due to th

Cited by 0SourceScholar
2025

ALMGuard: Safety Shortcuts and Where to Find Them as Guardrails for Audio–Language Models

NeurIPS 2025poster

Recent advances in Audio-Language Models (ALMs) have significantly improved multimodal understanding capabilities. However, the introduction of the audio modality also brings new and unique vulnerability vectors. Previous studies have proposed jailbreak attacks that specifically target ALMs, reveali…

Cited by 0SourcecodeScholar
2025

E2E-VGuard: Adversarial Prevention for Production LLM-based End-To-End Speech Synthesis

NeurIPS 2025poster

Recent advancements in speech synthesis technology have enriched our daily lives, with high-quality and human-like audio widely adopted across real-world applications. However, malicious exploitation like voice-cloning fraud poses severe security risks. Existing defense techniques struggle to addres…

Cited by 0SourcecodeScholar
2024

Effects of Exponential Gaussian Distribution on (Double Sampling) Randomized Smoothing

ICML 2024poster

Randomized Smoothing (RS) is currently a scalable certified defense method providing robustness certification against adversarial examples. Although significant progress has been achieved in providing defenses against $\ell_p$ adversaries, the interaction between the smoothing distribution and the r…

2024

LogoStyleFool: Vitiating Video Recognition Systems via Logo Style Transfer

AAAI 2024technical

Video recognition systems are vulnerable to adversarial examples. Recent studies show that style transfer-based and patch-based unrestricted perturbations can effectively improve attack efficiency. These attacks, however, face two main challenges: 1) Adding large stylized perturbations to all pixels…

2023

Flow-Attention-based Spatio-Temporal Aggregation Network for 3D Mask Detection

NeurIPS 2023poster

Anti-spoofing detection has become a necessity for face recognition systems due to the security threat posed by spoofing attacks. Despite great success in traditional attacks, most deep-learning-based methods perform poorly in 3D masks, which can highly simulate real faces in appearance and structur…