Source author record

Yinghua Zhang

Yinghua Zhang appears in the imported research catalog. Authorship, coauthor and topic links are available while profile ownership is still unclaimed.

ResearcherUnclaimed source record

Catalog footprint

What is connected

5works
5topics
4close collaborators

Actions

Connect this record

Log in to claim

Research graph

See the researcher in context

Open full explorer

Inspect adjacent papers, topics, institutions and collaborators without losing the researcher page.

Building this map preview

BZPEER is loading the nearby papers, people, topics and institutions for this page.

Published work

5 published item(s)

preprint2022arXiv

Cross-domain Cross-architecture Black-box Attacks on Fine-tuned Models with Transferred Evolutionary Strategies

Fine-tuning can be vulnerable to adversarial attacks. Existing works about black-box attacks on fine-tuned models (BAFT) are limited by strong assumptions. To fill the gap, we propose two novel BAFT settings, cross-domain and cross-domain cross-architecture BAFT, which only assume that (1) the target model for attacking is a fine-tuned model, and (2) the source domain data is known and accessible. To successfully attack fine-tuned models under both settings, we propose to first train an adversarial generator against the source model, which adopts an encoder-decoder architecture and maps a clean input to an adversarial example. Then we search in the low-dimensional latent space produced by the encoder of the adversarial generator. The search is conducted under the guidance of the surrogate gradient obtained from the source model. Experimental results on different domains and different network architectures demonstrate that the proposed attack method can effectively and efficiently attack the fine-tuned models.

preprint2020arXiv

Fisher Deep Domain Adaptation

Deep domain adaptation models learn a neural network in an unlabeled target domain by leveraging the knowledge from a labeled source domain. This can be achieved by learning a domain-invariant feature space. Though the learned representations are separable in the source domain, they usually have a large variance and samples with different class labels tend to overlap in the target domain, which yields suboptimal adaptation performance. To fill the gap, a Fisher loss is proposed to learn discriminative representations which are within-class compact and between-class separable. Experimental results on two benchmark datasets show that the Fisher loss is a general and effective loss for deep domain adaptation. Noticeable improvements are brought when it is used together with widely adopted transfer criteria, including MMD, CORAL and domain adversarial loss. For example, an absolute improvement of 6.67% in terms of the mean accuracy is attained when the Fisher loss is used together with the domain adversarial loss on the Office-Home dataset.

preprint2020arXiv

Two Sides of the Same Coin: White-box and Black-box Attacks for Transfer Learning

Transfer learning has become a common practice for training deep learning models with limited labeled data in a target domain. On the other hand, deep models are vulnerable to adversarial attacks. Though transfer learning has been widely applied, its effect on model robustness is unclear. To figure out this problem, we conduct extensive empirical evaluations to show that fine-tuning effectively enhances model robustness under white-box FGSM attacks. We also propose a black-box attack method for transfer learning models which attacks the target model with the adversarial examples produced by its source model. To systematically measure the effect of both white-box and black-box attacks, we propose a new metric to evaluate how transferable are the adversarial examples produced by a source model to a target model. Empirical results show that the adversarial examples are more transferable when fine-tuning is used than they are when the two networks are trained independently.

preprint2016arXiv

Homogeneous Rota-Baxter operators on $A_ω$ (II)

In this paper we study $k$-order homogeneous Rota-Baxter operators with weight $1$ on the simple $3$-Lie algebra $A_ω$ (over a field of characteristic zero), which is realized by an associative commutative algebra $A$ and a derivation $Δ$ and an involution $ω$ (Lemma \mref{lem:rbd3}). A $k$-order homogeneous Rota-Baxter operator on $A_ω$ is a linear map $R$ satisfying $R(L_m)=f(m+k)L_{m+k}$ for all generators $\{ L_m~ |~ m\in \mathbb Z \}$ of $A_ω$ and a map $f : \mathbb Z \rightarrow\mathbb F$, where $k\in \mathbb Z$. We prove that $R$ is a $k$-order homogeneous Rota-Baxter operator on $A_ω$ of weight $1$ with $k\neq 0$ if and only if $R=0$ (see Theorems 3.2, and $R$ is a $0$-order homogeneous Rota-Baxter operator on $A_ω$ of weight $1$ if and only if $R$ is one of the forty possibilities which are described in Theorems3.5, 3.7, 3.9, 3.10, 3.18, 3.21 and 3.22.

preprint2015arXiv

Homogeneous Rota-Baxter operators on $3$-Lie algebra $A_ω$

In the paper we study homogeneous Rota-Baxter operators with weight zero on the infinite dimensional simple $3$-Lie algebra $A_ω$ over a field $F$ ( $ch F=0$ ) which is realized by an associative commutative algebra $A$ and a derivation $Δ$ and an involution $ω$ ( Lemma \mref{lem:rbd3} ). A homogeneous Rota-Baxter operator on $A_ω$ is a linear map $R$ of $A_ω$ satisfying $R(L_m)=f(m)L_m$ for all generators of $A_ω$, where $f : A_ω \rightarrow F$. We proved that $R$ is a homogeneous Rota-Baxter operator on $A_ω$ if and only if $R$ is the one of the five possibilities $R_{0_1}$, $R_{0_2}$,$R_{0_3}$,$R_{0_4}$ and $R_{0_5}$, which are described in Theorem \mref{thm:thm1}, \mref{thm:thm4}, \mref{thm:thm01}, \mref{thm:thm03} and \mref{thm:thm04}. By the five homogeneous Rota-Baxter operators $R_{0_i}$, we construct new $3$-Lie algebras $(A, [ , , ]_i)$ for $1\leq i\leq 5$, such that $R_{0_i}$ is the homogeneous Rota-Baxter operator on $3$-Lie algebra $(A, [ , , ]_i)$, respectively.