← Search

Zhihong Tian

16 accepted papers

2026

AT-Field: Rethinking the Games in Adversarial Training

AAAI 2026technical

Adversarial training is often modeled as a two-player zero-sum game, relying on strong assumptions that limit its practical guidance. In this paper, we instead analyze the interactions between training samples and show that even the fundamental objective—minimizing training loss—may not converge. To

Cited by 0SourcePDFScholar
2026

Less Is More: Sparse and Cooperative Perturbation for Point Cloud Attacks

AAAI 2026technical

Most adversarial attacks on point clouds perturb a large number of points, causing widespread geometric changes and limiting applicability in real-world scenarios. While recent works explore sparse attacks by modifying only a few points, such approaches often struggle to maintain effectiveness due t

Cited by 0SourcePDFScholar
2026

Neural Honeytrace: Plug&Play Watermarking Framework against Model Extraction Attacks

ICML 2026poster

Triggerable watermarking enables model owners to assert ownership against model extraction attacks. However, most existing approaches require additional training, which limits post-deployment flexibility, and the lack of clear theoretical foundations makes them vulnerable to adaptive attacks. In thi…

Cited by 0SourceScholar
2026

Optimal Transport-Induced Samples against Out-of-Distribution Overconfidence

ICLR 2026poster

Deep neural networks (DNNs) often produce overconfident predictions on out-of-distribution (OOD) inputs, undermining their reliability in open-world environments. Singularities in semi-discrete optimal transport (OT) mark regions of semantic ambiguity, where classifiers are particularly prone to unw…

Cited by 0SourceScholar
2026

RCMoE: A Communication-Efficient Random Compression Framework for Resource-Constrained Mixture-of-Experts Training

AAAI 2026technical

Mixture-of-Experts (MoE) architecture with experts parallelism scales LLMs efficiently by activating only a subset of experts per input, avoiding proportional training costs. However, the intensive and heterogeneous communication substantially hinders the efficiency and scalability of MoE training i

Cited by 0SourcePDFScholar
2025

Imperceptible 3D Point Cloud Attacks on Lattice-based Barycentric Coordinates

AAAI 2025technical

Imperceptible adversarial attacks on 3D point clouds rely on effective constraints. While manifold constraints have notable advantages over Euclidean ones, the global parameterization used in current methods often fails to fully preserve manifold properties. In this paper, we propose to constrain la…

Cited by 1SourcePDFScholar
2025

Imperceptible Adversarial Attacks on Point Clouds Guided by Point-to-Surface Field

ICASSP 2025accepted

Adversarial attacks on point clouds are crucial for assessing and improving the adversarial robustness of 3D deep learning models. Traditional solutions strictly limit point displacement during attacks, making it challenging to balance imperceptibility with adversarial effectiveness. In this paper,…

Cited by 0SourceScholar
2025

Mitigating Hallucinations in Large Vision-Language Models by Adaptively Constraining Information Flow

AAAI 2025technical

Large vision-language models show tremendous potential in understanding visual information through human languages. However, they are prone to suffer from object hallucination, i.e., the generated image descriptions contain objects that do not exist in the image. In this paper, we reveal that object…

2025

Simplification Is All You Need against Out-of-Distribution Overconfidence

CVPR 2025poster

Deep neural networks (DNNs) often exhibit out-of-distribution (OOD) overconfidence, producing overly confident predictions on OOD samples. We attribute this issue to the inherent over-complexity of DNNs and investigate two key aspects: capacity and nonlinearity. First, we demonstrate that reducing m…

Cited by 3SourcePDFScholar
2024

CORES: Convolutional Response-based Score for Out-of-distribution Detection

CVPR 2024poster

Deep neural networks (DNNs) often display overconfidence when encountering out-of-distribution (OOD) samples posing significant challenges in real-world applications. Capitalizing on the observation that responses on convolutional kernels are generally more pronounced for in-distribution (ID) sample…

Cited by 6SourcePDFScholar
2024

FLAT: Flux-aware Imperceptible Adversarial Attacks on 3D Point Clouds

ECCV 2024poster

"Adversarial attacks on point clouds play a vital role in assessing and enhancing the adversarial robustness of 3D deep learning models. While employing a variety of geometric constraints, existing adversarial attack solutions often display unsatisfactory imperceptibility due to inadequate considera…

Cited by 5SourcePDFScholar
2024

LT-Defense: Searching-free Backdoor Defense via Exploiting the Long-tailed Effect

NeurIPS 2024poster

Language models have shown vulnerability against backdoor attacks, threatening the security of services based on them. To mitigate the threat, existing solutions attempted to search for backdoor triggers, which can be time-consuming when handling a large search space. Looking into the attack process…

Cited by 1SourcePDFScholar
2024

Manifold Constraints for Imperceptible Adversarial Attacks on Point Clouds

AAAI 2024technical

Adversarial attacks on 3D point clouds often exhibit unsatisfactory imperceptibility, which primarily stems from the disregard for manifold-aware distortion, i.e., distortion of the underlying 2-manifold surfaces. In this paper, we develop novel manifold constraints to reduce such distortion, aiming…

Cited by 11SourcePDFScholar
2024

Reparameterization Head for Efficient Multi-Input Networks

ICASSP 2024accepted

Reparameterization techniques have demonstrated their efficacy in improving the efficiency of deep neural networks. However, their application has been largely confined to single-input network structures, leaving multi-input ones, commonly encountered in real-world applications, largely unexplored.…

Cited by 0SourceScholar
2023

Deep Manifold Attack on Point Clouds via Parameter Plane Stretching

AAAI 2023technical

Adversarial attack on point clouds plays a vital role in evaluating and improving the adversarial robustness of 3D deep learning models. Current attack methods are mainly applied by point perturbation in a non-manifold manner. In this paper, we formulate a novel manifold attack, which deforms the un…

Cited by 17SourcePDFScholar
2021

CODEs: Chamfer Out-of-Distribution Examples Against Overconfidence Issue

ICCV 2021poster

Overconfident predictions on out-of-distribution (OOD) samples is a thorny issue for deep neural networks. The key to resolve the OOD overconfidence issue inherently is to build a subset of OOD samples and then suppress predictions on them. This paper proposes the Chamfer OOD examples (CODEs), whose…

Cited by 39PDFScholar