← Search

Zhenbo Shi

13 accepted papers

2025

AAKR: Adversarial Attack-based Knowledge Retention for Continual Semantic Segmentation

AAAI 2025technical

In the context of Continual Semantic Segmentation (CSS), replay-based methods tend to achieve better performance than knowledge distillation-based ones, as the former utilizes additional data to transfer old knowledge. However, this advantage is at the cost of necessitating additional space for sto…

Cited by 0SourcePDFScholar
2025

Leaving No OOD Instance Behind: Instance-Level OOD Fine-Tuning for Anomaly Segmentation

NeurIPS 2025poster

Out-of-distribution (OOD) fine-tuning has emerged as a promising approach for anomaly segmentation. Current OOD fine-tuning strategies typically employ global-level objectives, aiming to guide segmentation models to accurately predict a large number of anomaly pixels. However, these strategies often…

Cited by 0SourceScholar
2025

RP-PGD: Boosting Segmentation Robustness with a Region-and-Prototype Based Adversarial Attack

AAAI 2025technical

Adversarial attack and defense have been extensively explored in classification tasks, but their study in semantic segmentation remains limited. Moreover, current attacks fail to act as strong underlying attacks for adversarial training (AT), making it difficult to achieve segmentation robustness ag…

Cited by 0SourcePDFScholar
2025

Stop Diverse OOD Attacks: Knowledge Ensemble for Reliable Defense

AAAI 2025technical

Enhancing defense through model ensemble is an emerging trend, where the challenge lies in how to use ensemble knowledge to counter Out-of-Distribution (OOD) attacks. In this paper, we propose the Reliable Defense Ensemble (REE) to address this issue. REE optimizes the ensemble knowledge of models t…

Cited by 0SourcePDFScholar
2025

Tip the Scales: Achieving Balance in Adversarial Examples Across Modalities

ICASSP 2025accepted

In the field of multimodal learning, controlling the training of unimodal encoders from different perspectives is a primary approach to addressing Training Imbalance. However, the inherent capacity limitations of the modality affect the model’s capability. Therefore, generating adversarial examples…

Cited by 0SourceScholar
2024

Attacks on Continual Semantic Segmentation by Perturbing Incremental Samples

AAAI 2024technical

As an essential computer vision task, Continual Semantic Segmentation (CSS) has received a lot of attention. However, security issues regarding this task have not been fully studied. To bridge this gap, we study the problem of attacks in CSS in this paper. We first propose a new task, namely, attack…

Cited by 2SourcePDFScholar
2024

GenSeg: On Generating Unified Adversary for Segmentation

IJCAI 2024poster

Great advancements in semantic, instance, and panoptic segmentation have been made in recent years, yet the top-performing models remain vulnerable to imperceptible adversarial perturbation. Current attacks on segmentation primarily focus on a single task, and these methods typically rely on iterati…

2024

TIKP: Text-to-Image Knowledge Preservation for Continual Semantic Segmentation

AAAI 2024technical

Continual Semantic Segmentation (CSS) is an emerging trend, where catastrophic forgetting has been a perplexing problem. In this paper, we propose a Text-to-Image Knowledge Preservation (TIKP) framework to address this issue. TIKP applies Text-to-Image techniques to CSS by automatically generating p…

Cited by 5SourcePDFScholar
2022

Shape Prior Guided Attack: Sparser Perturbations on 3D Point Clouds

AAAI 2022technical

Deep neural networks are extremely vulnerable to malicious input data. As 3D data is increasingly used in vision tasks such as robots, autonomous driving and drones, the internal robustness of the classification models for 3D point cloud has received widespread attention. In this paper, we propose a…

Cited by 22SourcePDFScholar
2021

Adversarial Attacks on Object Detectors with Limited Perturbations

ICASSP 2021accepted

Deep convolutional neural networks are widely witnessed vulnerable to adversarial attacks. Recently, great progress has been achieved in attacking object detectors. However, current attacks neglect the practical utility and rely on global perturbations on the target image with a large number of patc…

Cited by 0SourceScholar
2021

Continuous Copy-Paste for One-Stage Multi-Object Tracking and Segmentation

ICCV 2021poster

Current one-step multi-object tracking and segmentation (MOTS) methods lag behind recent two-step methods. By separating the instance segmentation stage from the tracking stage, two-step methods can exploit non-video datasets as extra data for training instance segmentation. Moreover, instances belo…

Cited by 29PDFcodeScholar
2021

Mask4D: 4D Convolution Network for Light Field Occlusion Removal

ICASSP 2021accepted

Current light field (LF) occlusion removal approaches usually select only a part of sub-aperture images (SAIs) or simply stack all SAIs to reconstruct the center view, which destroys the spatial layout of SAIs. In this paper, we present a simple yet effective LF occlusion removal method name Mask4D,…

Cited by 0SourceScholar
2021

VK-Net: Category-Level Point Cloud Registration with Unsupervised Rotation Invariant Keypoints

ICASSP 2021accepted

In this paper, we propose VK-Net, a neural network that learns to discover a set of category-specific keypoints from a single point cloud in an unsupervised manner. VK-Net is able to generate semantically consistent and rotation invariant keypoints across objects of the same category and different v…

Cited by 0SourceScholar