Publications

A collection of my research work.

Zhongliang Guo = me Corresponding author* Equal contribution

First-Author & Corresponding-Author Publications(10)

A Gray-box Attack against Latent Diffusion Model-based Image Editing by Posterior Collapse

A Gray-box Attack against Latent Diffusion Model-based Image Editing by Posterior Collapse

Zhongliang Guo, Chun Tong Lei, Lei Fang, Shuai Zhao, Yifei Qian, Jingyu Lin, Zeyu Wang, Cunjian Chen, Ognjen Arandjelović, Chun Pong Lau

IEEE Transactions on Information Forensics and Security (IEEE T-IFS), 2026

A VAE-targeted adversarial protection framework that leverages posterior collapse phenomena to prevent unauthorized image manipulation in latent diffusion models with minimal computational overhead.

PaperCode
Artwork Protection Against Unauthorized Neural Style Transfer and Aesthetic Color Distance Metric

Artwork Protection Against Unauthorized Neural Style Transfer and Aesthetic Color Distance Metric

Zhongliang Guo, Yifei Qian, Shuai Zhao, Junhao Dong, Yanli Li, Ognjen Arandjelović, Fang Lei, Chun Pong Lau

Pattern Recognition, 2026

A proactive protection method using adaptive adversarial perturbations to prevent unauthorized neural style transfer of artwork while preserving visual quality and resisting purification-based defenses.

PaperCode
Backdoor Defense for Large Language Models with Weak-to-Strong Knowledge Distillation

Backdoor Defense for Large Language Models with Weak-to-Strong Knowledge Distillation

Yuwen Li, Xinyi Wu, Zhongliang Guo, Luwei Xiao, Yanhao Jia, Shuai Zhao

Pattern Recognition, 2026

A weak-to-strong defense against backdoor attacks in LLMs that uses a small clean teacher model to guide the poisoned student via feature-alignment knowledge distillation under PEFT, with a lightweight Lite variant.

PaperCode
Attacking Hard-Label Large Vision-Language Models with Model-Sensitive Adversarial Patch Designs

Attacking Hard-Label Large Vision-Language Models with Model-Sensitive Adversarial Patch Designs

Nian Ai, Guangke Chen, Xiaowen Cai, Zhongliang Guo, Daizong Liu, Pan Zhou, Ognjen Arandjelovi'c

Pattern Recognition, 2026

HardPatch is a query-only, hard-label adversarial patch attack on LVLMs that ranks image patches by sensitivity and iteratively perturbs the most vulnerable ones via gradient estimation with additive noise, without needing model gradients or details.

Paper
Understanding and Exploiting Phase Sensitivity for Attacking Large Vision-Language Models

Understanding and Exploiting Phase Sensitivity for Attacking Large Vision-Language Models

Daizong Liu, Junhao Dong, Xiang Fang, Hongyang He, Keyan Jin, Zhongliang Guo, Xiaoye Qu, Keke Tang

International Joint Conference on Artificial Intelligence (IJCAI), 2026

BadPhase, the first LVLM attack built on image phase sensitivity: it implants adversarial phase as a backdoor trigger via data poisoning, activated only when a textual trigger and a perturbation switcher co-occur, with the whole backdoor optimized at test time.

Paper
Rethinking 3D Point Cloud Adversarial Attacks From Models’ Inherent Focus

Rethinking 3D Point Cloud Adversarial Attacks From Models’ Inherent Focus

Li Yang, Xiaowen Cai, Shuqin Chen, Junhao Dong, Keke Tang, Zhongliang Guo, Daizong Liu

Expert Systems with Applications (ESWA), 2027

A 3D point cloud adversarial attack that, via theoretical analysis of perturbation-dependent gradients in backpropagation, uses a Laplace-based optimization function to update perturbations along the fastest gradient path, achieving faster convergence with better imperceptibility and transferability than prior IFGSM/PGD-based methods.

Paper
Artwork Protection Against Neural Style Transfer Using Locally Adaptive Adversarial Color Attack

Artwork Protection Against Neural Style Transfer Using Locally Adaptive Adversarial Color Attack

Zhongliang Guo, Yifei Qian, Kaixuan Wang, Weiye Li, Ziheng Guo, Yuheng Wang, Yanli Li, Ognjen Arandjelović, Lei Fang

27th European Conference on Artificial Intelligence (ECAI Oral), 2024

A proactive protection method using frequency-adaptive perturbations to prevent unauthorized neural style transfer while preserving visual quality of original artwork.

PaperCode
A White-Box False Positive Adversarial Attack Method on Contrastive Loss-Based Offline Handwritten Signature Verification Models

A White-Box False Positive Adversarial Attack Method on Contrastive Loss-Based Offline Handwritten Signature Verification Models

Zhongliang Guo, Weiye Li, Yifei Qian, Ognjen Arandjelovic, Lei Fang

International Conference on Artificial Intelligence and Statistics (AISTATS), 2024

A novel white-box adversarial attack on signature verification models using style transfer with specialized loss functions to manipulate embedding distances while maintaining visual similarity.

PaperCode

A Siamese Transformer Network for Zero-Shot Ancient Coin Classification

Zhongliang Guo, Ognjen Arandjelović, David Reid, Yaxiong Lei, Jochen Büttner

Journal of Imaging, 2023

A pairwise matching approach for ancient coin identification using Siamese Vision Transformers, enabling robust attribution without requiring exemplars for every coin issue class.

Paper

A Method of Video Recognition Network of Face Tampering Based on Deep Learning

Zhongliang Guo, Dian Jia, Zhaokai Wang, Jiahang Wu, Yongqi Zhou

Patent, 2019

A convolutional neural network architecture with Inception modules for deepfake video detection, achieving 94.5% accuracy on FaceForensics++ through optimized hyperparameters and training strategies.

Co-Authored Publications(16)

Protecting Your Customized LLM Systems from Backdoored Instructions with Metacognitive Probing

Shuai Zhao, Zhongliang Guo, Xinyi Wu, Xiaobao Wu, Yanhao Jia, Luwei Xiao, Anh Tuan Luu

IEEE Transactions on Information Forensics and Security (IEEE T-IFS), 2026

A black-box safety-auditing agent that defends against backdoored system instructions (rather than fine-tuning-based backdoors) by using metacognitive probing—leveraging the LLM's own safety alignment against its instruction-following—to elicit and sanitize hidden triggers from user queries.

T2ICount: Enhancing Cross-modal Understanding for Zero-Shot Counting

Yifei Qian*, Zhongliang Guo*, Bowen Deng, Chun Tong Lei, Shuai Zhao, Chung Pong Lau, Xiaopeng Hong, Michael P Pound

Proceedings of the Computer Vision and Pattern Recognition Conference (CVPR Highlight), 2025

A diffusion-based zero-shot object counting framework that enhances text sensitivity through hierarchical semantic correction and cross-attention supervision for fine-grained counting.

PaperCode

Threats and Defenses in the Federated Learning Life Cycle: A Comprehensive Survey and Challenges

Yanli Li, Zhongliang Guo, Nan Yang, Huaming Chen, Dong Yuan, Weiping Ding

IEEE Transactions on Neural Networks and Learning Systems (IEEE TNNLS), 2025

A comprehensive survey of security threats and defense mechanisms throughout the federated learning lifecycle, analyzing utility-privacy trade-offs and identifying research gaps for trustworthy FL.

Paper

Instant Adversarial Purification with Adversarial Consistency Distillation

Chun Tong Lei, Hon Ming Yam, Zhongliang Guo, Yifei Qian, Chun Pong Lau

IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2025

A single-step adversarial purification framework using distillation and controlled inference in diffusion models, achieving 100-fold speedup while maintaining robust defense against adversarial attacks.

PaperCode

A Survey of Recent Backdoor Attacks and Defenses in Large Language Models

Shuai Zhao, Meihuizi Jia, Zhongliang Guo, Leilei Gan, Xiaoyu Xu, Xiaobao Wu, Jie Fu, Feng Yichao, Fengjun Pan, Anh Tuan Luu

Transactions on Machine Learning Research (TMLR Survey Certification 🏆), 2025

A comprehensive survey of backdoor attacks on large language models, systematically categorizing attacks by fine-tuning methodology and identifying future research directions in LLM security.

Paper

DiffProtect: Generative Adversarial Examples Using Diffusion Models for Facial Privacy Protection

Jiang Liu, Chun Pong Lau, Zhongliang Guo, Yuxiang Guo, Zhaoyang Wang, Rama Chellappa

Pattern Recognition, 2025

A diffusion autoencoder-based method for generating semantically meaningful adversarial perturbations that protect facial images from unauthorized recognition systems with improved visual quality and attack success rates.

PaperCode

Semi-Supervised Crowd Counting with Contextual Modeling: Facilitating Holistic Understanding of Crowd Scenes

Yifei Qian, Xiaopeng Hong, Zhongliang Guo, Ognjen Arandjelović, Carl R Donovan

IEEE Transactions on Circuits and Systems for Video Technology (IEEE T-CSVT), 2024

A semi-supervised crowd counting method built on the mean teacher framework that fosters the model's 'subitizing' ability by masking unlabeled patches and predicting them from holistic context, together with a fine-grained density classification task, reaching state-of-the-art results on ShanghaiTech A and UCF-QNRF.

PaperCode

Perspective-assisted Prototype-based Learning for Semi-supervised Crowd Counting

Yifei Qian, Liangfei Zhang, Zhongliang Guo, Xiaopeng Hong, Ognjen Arandjelović

Pattern Recognition, 2025

A prototype-based semi-supervised crowd counting method that captures perspective-aware density variations, enabling effective learning from limited labeled data through tailored consistency strategies.

Paper

GaitProtector: Impersonation-Driven Gait De-Identification via Training-Free Diffusion Latent Optimization

Huiran Duan, Qian Zhou, Zhongliang Guo, Junhao Dong, Yuqi Li, Guoying Zhao, Yingli Tian

International Conference on Automatic Face and Gesture Recognition (FG), 2026

GaitProtector is a training-free gait de-identification framework that jointly optimizes obfuscation (away from source identity) and impersonation (toward a target identity) in a pretrained 3D diffusion model's latent space, achieving strong identity suppression while preserving downstream utility.

Paper

Attacking Gray-Box Large Vision-Language Models with Adaptive SVD-Structured Adversarial Alignment

Daizong Liu, Xiaowen Cai, Junhao Dong, Zhongliang Guo, Xiaoye Qu, Runwei Guan, Xiang Fang, Dengpan Ye

International Conference on Machine Learning (ICML), 2026

A gray-box adversarial attack on LVLMs that perturbs visual features—via SVD-structured semantic alignment and optimal-transport-based multi-context text matching—to match attacker-chosen target texts using only the vision encoder, achieving strong cross-model transferability.

Paper

Syntactic Paraphrase-based Synthetic Data Generation for Backdoor Attacks Against Chinese Language Models

Man Hu, Yatao Yang, Deng Pan, Zhongliang Guo, Luwei Xiao, Deyu Lin, Shuai Zhao

Information Fusion, 2025

A stealthy backdoor attack method for Chinese language models using LLM-generated syntactic paraphrasing as triggers, achieving high success rates while evading detection mechanisms.

Paper

P2P: A Poison-to-Poison Remedy for Reliable Backdoor Defense in LLMs

Shuai Zhao, Xinyi Wu, Shiqian Zhao, Xiaobao Wu, Zhongliang Guo, Yanhao Jia, Anh Tuan Luu

Findings of the Association for Computational Linguistics (ACL Findings), 2026

A general backdoor defense for LLMs that re-poisons a subset of training data with benign triggers mapped to safe labels, so prompt-based fine-tuning overrides the original malicious triggers across classification, reasoning, and summarization tasks.

Paper

Federated Knowledge Distillation for Multi-Model Architectures Lithography Hotspot Detection

Yuqi Li, Xingyou Lin, Yanli Li, Kai Zhang, Chuanguang Yang, Zhongliang Guo, Jianping Gou, Tingwen Huang, Yingli Tian

IEEE International Conference on Multimedia and Expo (ICME Oral), 2026

A hybrid federated learning framework for privacy-sensitive lithography hotspot detection that combines parameter aggregation of shared layers with logit-based knowledge distillation on a public dataset, allowing clients with heterogeneous model architectures to collaborate.

Paper

PoseCompass: Intelligent Synthetic Pose Selection for Visual Localization

Yanan Zhou, Zhaoyan Qian, Yanli Li, Nan Yang, Zhongliang Guo, Dong Yuan

IEEE International Conference on Multimedia and Expo (ICME Spotlight), 2026

A pose selection pipeline for 3DGS-based absolute pose regression that ranks synthetic views by localization difficulty, coverage novelty, and rendering observability, cutting adaptation time by 3x and median pose error by 53.8% on 7-Scenes.

Paper

Affective-ROPTester: Capability and Bias Analysis of LLMs in Predicting Retinopathy of Prematurity

Shuai Zhao, Yulin Zhang, Luwei Xiao, Xinyi Wu, Yanhao Jia, Zhongliang Guo, Xiaobao Wu, Cong-Duy Nguyen, Guoming Zhang, Anh Tuan Luu

IEEE Transactions on Affective Computing (IEEE T-AC), 2025

An automated evaluation framework investigating how emotional prompting affects large language models' performance and bias patterns in retinopathy of prematurity risk prediction using a novel Chinese benchmark.

Paper

Achieving Fair Medical Image Segmentation in Foundation Models with Adversarial Visual Prompt Tuning

Yuqi Li, Yanli Li, Kai Zhang, Fuyuan Zhang, Chuanguang Yang, Zhongliang Guo, Weiping Ding, Tingwen Huang

Information Sciences, 2025

A parameter-efficient adversarial visual prompt tuning method that mitigates demographic bias in foundation models for medical image segmentation while maintaining high performance.

Paper