Arrow Research search

Author name cluster

Xianlong Wang

Possible papers associated with this exact author name in Arrow. This page groups case-insensitive exact name matches and is not a full identity disambiguation profile.

7 papers
1 author row

Possible papers

7

NeurIPS Conference 2025 Conference Paper

AdvEDM: Fine-grained Adversarial Attack against VLM-based Embodied Agents

  • Yichen Wang
  • Hangtao Zhang
  • Hewen Pan
  • Ziqi Zhou
  • Xianlong Wang
  • Peijin Guo
  • Lulu Xue
  • Shengshan Hu

Vision-Language Models (VLMs), with their strong reasoning and planning capabilities, are widely used in embodied decision-making (EDM) tasks in embodied agents, such as autonomous driving and robotic manipulation. Recent research has increasingly explored adversarial attacks on VLMs to reveal their vulnerabilities. However, these attacks either rely on overly strong assumptions, requiring full knowledge of the victim VLM, which is impractical for attacking VLM-based agents, or exhibit limited effectiveness. The latter stems from disrupting most semantic information in the image, which leads to a misalignment between the perception and the task context defined by system prompts. This inconsistency interrupts the VLM's reasoning process, resulting in invalid outputs that fail to affect interactions in the physical world. To this end, we propose a fine-grained adversarial attack framework, AdvEDM, which modifies the VLM's perception of only a few key objects while preserving the semantics of the remaining regions. This attack effectively reduces conflicts with the task context, making VLMs output valid but incorrect decisions and affecting the actions of agents, thus posing a more substantial safety threat in the physical world. We design two variants of based on this framework, AdvEDM-R and AdvEDM-A, which respectively remove the semantics of a specific object from the image and add the semantics of a new object into the image. The experimental results in both general scenarios and EDM tasks demonstrate fine-grained control and excellent attack performance.

AAAI Conference 2025 Conference Paper

Detecting and Corrupting Convolution-based Unlearnable Examples

  • Minghui Li
  • Xianlong Wang
  • Zhifei Yu
  • Shengshan Hu
  • Ziqi Zhou
  • Longling Zhang
  • Leo Yu Zhang

Convolution-based unlearnable examples (UEs) employ class-wise multiplicative convolutional noise to training samples, severely compromising model performance. This fire-new type of UEs have successfully countered all defense mechanisms against UEs. The failure of such defenses can be attributed to the absence of norm constraints on convolutional noise, leading to severe blurring of image features. To address this, we first design an Edge Pixel-based Detector (EPD) to identify convolution-based UEs. Upon detection of them, we propose the first defense scheme against convolution-based UEs, COrrupting these samples via random matrix multiplication by employing bilinear INterpolation (COIN) such that disrupting the distribution of class-wise multiplicative noise. To evaluate the generalization of our proposed COIN, we newly design two convolution-based UEs called VUDA and HUDA to expand the scope of convolution-based UEs. Extensive experiments demonstrate the effectiveness of detection scheme EPD and that our defense COIN outperforms 11 state-of-the-art (SOTA) defenses, achieving a significant improvement on the CIFAR and ImageNet datasets.

NeurIPS Conference 2024 Conference Paper

DarkSAM: Fooling Segment Anything Model to Segment Nothing

  • Ziqi Zhou
  • Yufei Song
  • Minghui Li
  • Shengshan Hu
  • Xianlong Wang
  • Leo Yu Zhang
  • Dezhong Yao
  • Hai Jin

Segment Anything Model (SAM) has recently gained much attention for its outstanding generalization to unseen data and tasks. Despite its promising prospect, the vulnerabilities of SAM, especially to universal adversarial perturbation (UAP) have not been thoroughly investigated yet. In this paper, we propose DarkSAM, the first prompt-free universal attack framework against SAM, including a semantic decoupling-based spatial attack and a texture distortion-based frequency attack. We first divide the output of SAM into foreground and background. Then, we design a shadow target strategy to obtain the semantic blueprint of the image as the attack target. DarkSAM is dedicated to fooling SAM by extracting and destroying crucial object features from images in both spatial and frequency domains. In the spatial domain, we disrupt the semantics of both the foreground and background in the image to confuse SAM. In the frequency domain, we further enhance the attack effectiveness by distorting the high-frequency components (i. e. , texture information) of the image. Consequently, with a single UAP, DarkSAM renders SAM incapable of segmenting objects across diverse images with varying prompts. Experimental results on four datasets for SAM and its two variant models demonstrate the powerful attack capability and transferability of DarkSAM. Our codes are available at: https: //github. com/CGCL-codes/DarkSAM.

IJCAI Conference 2024 Conference Paper

Detector Collapse: Backdooring Object Detection to Catastrophic Overload or Blindness in the Physical World

  • Hangtao Zhang
  • Shengshan Hu
  • Yichen Wang
  • Leo Yu Zhang
  • Ziqi Zhou
  • Xianlong Wang
  • Yanjun Zhang
  • Chao Chen

Object detection tasks, crucial in safety-critical systems like autonomous driving, focus on pinpointing object locations. These detectors are known to be susceptible to backdoor attacks. However, existing backdoor techniques have primarily been adapted from classification tasks, overlooking deeper vulnerabilities specific to object detection. This paper is dedicated to bridging this gap by introducing Detector Collapse (DC), a brand-new backdoor attack paradigm tailored for object detection. DC is designed to instantly incapacitate detectors (i. e. , severely impairing detector's performance and culminating in a denial-of-service). To this end, we develop two innovative attack schemes: Sponge for triggering widespread misidentifications and Blinding for rendering objects invisible. Remarkably, we introduce a novel poisoning strategy exploiting natural objects, enabling DC to act as a practical backdoor in real-world environments. Our experiments on different detectors across several benchmarks show a significant improvement (~10%-60% absolute and ~2-7x relative) in attack efficacy over state-of-the-art attacks.

YNICL Journal 2024 Journal Article

GABAergic imbalance in Parkinson’s disease–related depression determined with MEGA-PRESS

  • Xinzi Liu
  • Yuxin Li
  • Yixiang Mo
  • Baoling Chen
  • Xusheng Hou
  • Jianbin Zhu
  • Yongzhou Xu
  • Jingyue Xue

OBJECTIVE: The pathogenesis of depression in patients with Parkinson's disease (PD) is poorly understood. Therefore, this study aimed to explore the changes in γ-aminobutyric acid (GABA) and glutamate plus glutamine (Glx) levels in patients with PD with or without depression determined using MEscher-GArwood Point Resolved Spectroscopy (MEGA-PRESS). MATERIALS AND METHODS: A total of 83 patients with primary PD and 24 healthy controls were included. Patients with PD were categorized into depressed PD (DPD, n = 19) and nondepressed PD (NDPD, n = 64) based on the 17-item Hamilton Depression Rating Scale. All participants underwent T1-weighted imaging and MEGA-PRESS sequence to acquire GABA+ and Glx values. The MEGA-PRESS sequence was conducted using 18.48 mL voxels in the left thalamus and medial frontal cortex. The GABA+, Glx, and creatine values were quantified using Gannet 3.1 software. RESULTS: The GABA+ and Glx values were not significantly disparate between patients with PD and controls in the thalamus and medial frontal cortex. However, the levels of N-acetyl aspartate/creatine and choline/creatine in the left thalamus were significantly lower in patients with PD than in controls (P = .031, P = .009). The GABA+/Water and GABA+/Creatine in the medial frontal cortex were higher in DPD than in NDPD (P = .001, P = .004). The effects of depression on Glx or other metabolite levels were not evident, and no significant difference in metabolite values was noted in the left thalamus among all groups (P > .05). CONCLUSIONS: GABA+ levels increased in the medial frontal cortex in DPD, which may be more closely related to depressive pathology. Thus, alterations in GABAergic function in special brain structures may be related to the clinical manifestations of PD symptoms, and hence mediating this function might help in treating depression in PD.

NeurIPS Conference 2024 Conference Paper

Unlearnable 3D Point Clouds: Class-wise Transformation Is All You Need

  • Xianlong Wang
  • Minghui Li
  • Wei Liu
  • Hangtao Zhang
  • Shengshan Hu
  • Yechao Zhang
  • Ziqi Zhou
  • Hai Jin

Traditional unlearnable strategies have been proposed to prevent unauthorized users from training on the 2D image data. With more 3D point cloud data containing sensitivity information, unauthorized usage of this new type data has also become a serious concern. To address this, we propose the first integral unlearnable framework for 3D point clouds including two processes: (i) we propose an unlearnable data protection scheme, involving a class-wise setting established by a category-adaptive allocation strategy and multi-transformations assigned to samples; (ii) we propose a data restoration scheme that utilizes class-wise inverse matrix transformation, thus enabling authorized-only training for unlearnable data. This restoration process is a practical issue overlooked in most existing unlearnable literature, i. e. , even authorized users struggle to gain knowledge from 3D unlearnable data. Both theoretical and empirical results (including 6 datasets, 16 models, and 2 tasks) demonstrate the effectiveness of our proposed unlearnable framework. Our code is available at https: //github. com/CGCL-codes/UnlearnablePC.

YNIMG Journal 2010 Journal Article

MR imaging of high-grade brain tumors using endogenous protein and peptide-based contrast

  • Zhibo Wen
  • Shuguang Hu
  • Fanheng Huang
  • Xianlong Wang
  • Linglang Guo
  • Xianyue Quan
  • Silun Wang
  • Jinyuan Zhou

Amide proton transfer (APT) imaging is a novel MRI technique, in which the amide protons of endogenous proteins and peptides are irradiated to accomplish indirect detection using the bulk water signal. In this paper, the APT approach was added to a standard brain MRI protocol at 3T, and twelve patients with high-grade gliomas confirmed by histopathology were scanned. It is shown that all tumors, including one with minor gadolinium enhancement, showed heterogeneous hyperintensity on the APT images. The average APT signal intensities of the viable tumor cores were significantly higher than those of peritumoral edema and normal-appearing white matter (P <0. 001). The average APT signal intensities were significantly lower in the necrotic regions than in the viable tumor cores (P =0. 004). The APT signal intensities of the cystic cavities were similar to those of the viable tumor cores (P >0. 2). The initial results show that APT imaging at the protein and peptide level may enhance non-invasive identification of tissue heterogeneity in high-grade brain tumors.

v2026.09.13