← Search

Zhongyun Hua

8 accepted papers

2026

Debiased Dual-Invariant Defense for Adversarially Robust Person Re-Identification

AAAI 2026technical

Person re-identification (ReID) is a fundamental task in many real-world applications such as pedestrian trajectory tracking. However, advanced deep learning-based ReID models are highly susceptible to adversarial attacks, where imperceptible perturbations to pedestrian images can cause entirely inc

Cited by 0SourcePDFScholar
2026

Learning Tight Rejection Boundaries without Negatives for Strict One-Class Audio Deepfake Detection

ICML 2026poster

The rapid evolution of audio deepfakes requires robust detection capable of generalizing to unseen attacks. One-class learning offers inherent robustness for this task by characterizing real speech distributions to detect anomalies. However, establishing a compact decision boundary without spoof sup…

Cited by 0SourceScholar
2026

Nasty Adversarial Training: A Probability Sparsity Perspective for Robustness Enhancement

ICLR 2026poster

The vulnerability of deep neural networks to adversarial examples poses significant challenges to their reliable deployment. Among existing empirical defenses, adversarial training and robust distillation have proven the most effective. In this paper, we identify a property originally associated wit…

Cited by 0SourceScholar
2026

Persistent Backdoor Attacks in Class-Incremental Learning via Structural Invariant Anchoring

ICML 2026poster

Continual Learning (CL) continually performs parameter updates, posing a significant challenge to backdoor persistence. In this paper, we reveal that the most advanced attack relies on an implicit assumption that task-critical neurons remain stable across task learning; however, it does not hold in …

Cited by 0SourceScholar
2025

Multi-View Collaborative Learning Network for Speech Deepfake Detection

AAAI 2025technical

As deep learning techniques advance rapidly, deepfake speech synthesized through text-to-speech or voice conversion networks is becoming increasingly realistic, posing significant challenges for detection and raising potential threats to social security. This growing realism has prompted extensive r…

Cited by 0SourcePDFScholar
2025

Phoneme-Level Feature Discrepancies: A Key to Detecting Sophisticated Speech Deepfakes

AAAI 2025technical

Recent advancements in text-to-speech and speech conversion technologies have enabled the creation of highly convincing synthetic speech. While these innovations offer numerous practical benefits, they also cause significant security challenges when maliciously misused. Therefore, there is an urgent…

Cited by 0SourcePDFScholar
2024

Conditional Backdoor Attack via JPEG Compression

AAAI 2024technical

Deep neural network (DNN) models have been proven vulnerable to backdoor attacks. One trend of backdoor attacks is developing more invisible and dynamic triggers to make attacks stealthier. However, these invisible and dynamic triggers can be inadvertently mitigated by some widely used passive denoi…

Cited by 5SourcePDFScholar
2024

IBD-PSC: Input-level Backdoor Detection via Parameter-oriented Scaling Consistency

ICML 2024poster

Deep neural networks (DNNs) are vulnerable to backdoor attacks, where adversaries can maliciously trigger model misclassifications by implanting a hidden backdoor during model training. This paper proposes a simple yet effective input-level backdoor detection (dubbed IBD-PSC) as a `firewall' to filt…