← Search

Zhishan Guo

3 accepted papers

2026

CertMask: Certifiable Defense Against Adversarial Patches via Theoretically Optimal Mask Coverage

AAAI 2026technical

Adversarial patch attacks inject localized perturbations into images to mislead deep vision models. These attacks can be physically deployed, posing serious risks to real-world applications. In this paper, we propose CertMask, a certifiably robust defense that constructs a provably sufficient set of

Cited by 0SourcePDFScholar
2024

Augmented Neural Fine-tuning for Efficient Backdoor Purification

ECCV 2024poster

"Recent studies have revealed the vulnerability of deep neural networks (DNNs) to various backdoor attacks, where the behavior of DNNs can be compromised by utilizing certain types of triggers or poisoning mechanisms. State-of-the-art (SOTA) defenses employ too-sophisticated mechanisms that require…

2023

SSDA: Secure Source-Free Domain Adaptation

ICCV 2023poster

Source-free domain adaptation (SFDA) is a popular unsupervised domain adaptation method where a pre-trained model from a source domain is adapted to a target domain without accessing any source data. Despite rich results in this area, existing literature overlooks the security challenges of the unsu…

Cited by 11PDFcodeScholar