Publications

† corresponding author, * equal contribution

GenBreak: Red Teaming Text-to-Image Generation Using Large Language Models Multi-Modal Attack
Zilong Wang, Xiang Zheng, Xiaosen Wang, Bo Wang, Xingjun Ma
IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2026
[arXiv]

Attention! Your Vision Language Model Could Be Maliciously Manipulated Multi-Modal Attack
Xiaosen Wang, Shaokang Wang, Zhijin Ge, Yuyang Luo, Shudong Zhang
Advances in Neural Information Processing Systems (NeurIPS), 2025
[arXiv] [Code]

ViT-EnsembleAttack: Augmenting Ensemble Models for Stronger Adversarial Transferability in Vision Transformers Image Attack
Hanwen Cao, Haobo Lu, Xiaosen Wang, Kun He
IEEE/CVF International Conference on Computer Vision (ICCV), 2025
[arXiv] [Code]

Alleviating noise memorization for adversarially robust few-shot learning Image Defense
Yiman Hu, Yixiong Zou, Xiaosen Wang, Yuhua Li, Kun He, Ruixuan Li
Neural Networks, 2025
[arXiv]

IDEATOR: Jailbreaking Large Vision-Language Models Using Themselves LLM Attack
Ruofan Wang, Juncheng Li, Yixu Wang, Bo Wang, Xiaosen Wang, Yan Teng, Yingchun Wang, Xingjun Ma, Yu-Gang Jiang
IEEE/CVF International Conference on Computer Vision (ICCV), 2025
[arXiv] [Code] [Poster]

Bag of Tricks to Boost Adversarial Transferability Image Attack
Zeliang Zhang, Rongyi Zhu, Wei Yao, Xiaosen Wang†, Chenliang Xu
European Conference on Computer Vision (ECCV), 2024
[arXiv] [Code]

Boosting Adversarial Transferability by Block Shuffle and Rotation Image Attack
Kunyu Wang, Xuanran He, Wenxuan Wang, Xiaosen Wang
IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2024
[arXiv] [Code]

MMA-Diffusion: MultiModal Attack on Diffusion Models Multi-Modal Attack
Yijun Yang, Ruiyuan Gao, Xiaosen Wang, Nan Xu, Qiang Xu
IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2024
[arXiv] [Code]

Rethinking the Backward Propagation for Adversarial Transferability Image Attack
Xiaosen Wang, Kangheng Tong, Kun He
Advances in Neural Information Processing Systems (NeurIPS), 2023
[arXiv] [Code] [Poster] [Slides]

Boosting Adversarial Transferability by Achieving Flat Local Maxima Image Attack
Zhijin Ge*, Hongying Liu*, Xiaosen Wang*, Fanhua Shang, Yuanyuan Liu
Advances in Neural Information Processing Systems (NeurIPS), 2023
[arXiv] [Code] [Poster] [Slides]

Diversifying the High-level Features for better Adversarial Transferability Oral Image Attack
Zhiyuan Wang, Zeliang Zhang, Siyuan Liang, Xiaosen Wang
British Machine Vision Conference (BMVC), 2023
[arXiv] [Code]

Improving the Transferability of Adversarial Examples with Arbitrary Style Transfer Image Attack
Zhijin Ge, Fanhua Shang, Hongying Liu, Yuanyuan Liu, Liang Wan, Wei Feng, Xiaosen Wang
ACM International Conference on Multimedia (ACM MM), 2023
[arXiv] [Code]

Structure Invariant Transformation for better Adversarial Transferability Image Attack
Xiaosen Wang, Zeliang Zhang, Jianping Zhang
IEEE/CVF International Conference on Computer Vision (ICCV), 2023
[arXiv] [Code] [Poster]

Improving the Transferability of Adversarial Samples by Path-Augmented Method Image Attack
Jianping Zhang, Jen-tse Huang, Wenxuan Wang, Yichen Li, Weibin Wu, Xiaosen Wang, Yuxin Su, Michael Lyu
IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2023
[arXiv] [Code]

TextHacker: Learning based Hybrid Local Search Algorithm for Text Hard-label Adversarial Attack Textual Attack
Zhen Yu*, Xiaosen Wang*, Wanxiang Che, Kun He
Findings of Conference on Empirical Methods in Natural Language Processing (EMNLP findings), 2022
[arXiv] [Code] [Poster] [Slides]

Triangle Attack: A Query-efficient Decision-based Adversarial Attack Image Attack
Xiaosen Wang, Zeliang Zhang, Kangheng Tong, Dihong Gong, Kun He, Zhifeng Li, Wei Liu
European Conference on Computer Vision (ECCV), 2022
[arXiv] [Code] [Poster] [Slides]

Detecting Textual Adversarial Examples through Randomized Substitution and Vote Textual Defense
Xiaosen Wang*, Yifeng Xiong*, Kun He
Conference on Uncertainty in Artificial Intelligence (UAI), 2022
[arXiv] [Code] [Poster]

Robust Textual Embedding against Word-level Adversarial Attacks Textual Defense
Yichen Yang*, Xiaosen Wang*, Kun He
Conference on Uncertainty in Artificial Intelligence (UAI), 2022
[arXiv] [Code] [Poster]

Boosting Adversarial Transferability through Enhanced Momentum Image Attack
Xiaosen Wang*, Jiadong Lin*, Han Hu, Jingdong Wang, Kun He
British Machine Vision Conference (BMVC), 2021
[arXiv] [Code]

Admix: Enhancing the Transferability of Adversarial Attacks Image Attack
Xiaosen Wang, Xuanran He, Jingdong Wang, Kun He
International Conference on Computer Vision (ICCV), 2021
[arXiv] [Code] [Poster] [Slides]

Natural Language Adversarial Defense through Synonym Encoding Textual Defense
Xiaosen Wang, Hao Jin, Yichen Yang, Kun He
Conference on Uncertainty in Artificial Intelligence (UAI), 2021
[arXiv] [Code] [Poster] [Slides]

Enhancing the Transferability of Adversarial Attacks through Variance Tuning Image Attack
Xiaosen Wang, Kun He
IEEE Conference on Computer Vision and Pattern Recognition (CVPR), 2021
[arXiv] [Code] [Poster] [Slides]

Adversarial Training with Fast Gradient Projection Method against Synonym Substitution based Text Attacks Textual Defense
Xiaosen Wang*, Yichen Yang*, Yihe Deng*, Kun He
AAAI Conference on Artificial Intelligence (AAAI), 2021
[arXiv] [Code] [Poster] [Slides]

A New Anchor Word Selection Method for the Separable Topic Discovery
Kun He, Wu Wang, Xiaosen Wang†, John E. Hopcroft
WIREs Data Mining and Knowledge Discovery
[arXiv]

Preprint

Devling into Adversarial Transferability on Image Classification: Review, Benchmark, and Evaluation Image Attack
Xiaosen Wang, Zhijin Ge, Bohan Liu, Zheng Fang, Fengfan Zhou, Ruixuan Zhang, Shaokang Wang, Yuyang Luo
arXiv preprint arXiv:2602.23117, 2026
[arXiv] [Code]

Security Risk of Misalignment between Text and Image in Multi-modal Model Multi-Modal Attack
Xiaosen Wang, Zhijin Ge, Shaokang Wang
arXiv preprint arXiv:2510.26105, 2025
[arXiv]

Boosting the Local Invariance for Better Adversarial Transferability Image Attack
Bohan Liu, Xiaosen Wang†
arXiv preprint arXiv:2503.06140, 2025
[arXiv]

Disrupting Semantic and Abstract Features for Better Adversarial Transferability Image Attack
Yuyang Luo, Xiaosen Wang, Zhijin Ge, Yingzhe He
arXiv preprint arXiv:2507.16052, 2025
[arXiv]

Generating Visually Realistic Adversarial Patch Image Attack
Xiaosen Wang, Kunyu Wang
arXiv preprint arXiv:2312.03030, 2023
[arXiv]

Rethinking Mixup for Improving the Adversarial Transferability Image Attack
Xiaosen Wang, Zeyuan Yin
arXiv preprint arXiv:2311.17087, 2023
[arXiv]

Improving Adversarial Transferability with Scheduled Step Size and Dual Example Image Attack
Zeliang Zhang, Peihan Liu, Xiaosen Wang†, Chenliang Xu†
arXiv preprint arXiv:62301.12968, 2023
[arXiv]

I-PGD-AT: Efficient Adversarial Training via Imitating Iterative PGD Attack Image Defense
Xiaosen Wang, Bhavya Kailkhura, Krishnaram Kenthapadi, Bo Li
OpenReview: TEt7PsVZux6, 2021
[pdf]

Multi-stage Optimization based Adversarial Training Image Defense
Xiaosen Wang, Chuanbiao Song, Kun He, Liwei Wang
arXiv preprint arXiv:2106.15357, 2021
[arXiv]

AT-GAN: A Generative Attack Model for Adversarial Transferring on Generative Adversarial Nets Image Attack
Xiaosen Wang, Kun He, Chuanbiao Song, Liwei Wang, John E. Hopcroft
arXiv preprint arXiv:1904.07793, 2019
[arXiv]