Medoid Prototype Alignment for Cross-Plant Unknown Attack Detection in Industrial Control Systems
arXiv:2604.25544v1 [cs.CR] 28 Apr 2026
LUYAO WANG University of Malaya Malaysia Abstract: Deploying an intrusion detector trained in one industrial plant to another remains difficult because Industrial Control System (ICS) traffic is highly site-dependent, labels are scarce, and unseen attacks often appear after deployment. To address this challenge, this paper introduces a medoid prototype alignment framework for cross-plant unknown attack detection. Instead of aligning all source and target samples directly, the method first compresses heterogeneous traffic into a comparable representation space and then extracts robust medoid prototypes that summarize local operational structure in each domain. A prototype-calibrated transfer objective is further designed to align target prototypes with source prototypes while preserving source-domain discrimination and encouraging confident target predictions. This strategy reduces noisy cross-domain matching and improves transfer stability under heterogeneous industrial conditions. Experiments conducted on natural gas and water storage control systems show that the proposed method achieves the best average performance among all compared models, reaching an average accuracy of 0.843 and an average F1-score of 0.838 across four unknown-attack transfer tasks. The analysis also shows clear transfer asymmetry between source-target directions and confirms that prototype guidance is especially helpful on challenging reverse-transfer settings. These findings suggest that medoid prototype alignment is a practical solution for robust industrial intrusion detection under domain shift. Key-Words: Industrial Control Systems; Unknown Attack Detection; Cross-Plant Transfer; Prototype Alignment; Domain Adaptation; K-Medoids. Received: April 28, 2026. Revised: April 28, 2026. Accepted: April 28, 2026. Published: April 28, 2026 (WSEAS will fill these dates in case of final acceptance, following strictly the editorial process.)
1
Introduction
Although deep learning has achieved remarkable success in pattern recognition [39], representation learning [18, 31, 26, 34], medical image analysis and healthcare intelligence [2, 20, 29, 32, 35, 30, 17, 41], as well as 3D understanding and retrieval tasks [23, 5, 14, 37, 8, 3, 8, 15, 16, 22, 21, 36, 40, 7], it has also shown strong promise in security-oriented applications and generative modeling [38, 33, 27]. Despite this broad progress, its practical adoption in industrial control system intrusion detection remains relatively limited, largely because industrial environments are constrained by scarce labeled data, heterogeneous traffic distributions, and continually evolving operating conditions [28, 9, 12]. This problem becomes more difficult when the target plant contains previously unseen attacks. Building a new detector from scratch is often impractical because attack labels are costly to collect, production traffic is sensitive, and retraining pipelines may interrupt routine operations. Therefore, the central question is not simply how to improve within-plant classification accuracy, but how to reuse prior knowledge from one industrial environment to support reliable detection in another [12, 42]. Existing transfer-learning solutions mainly focus on global feature alignment. While effective in
some settings, global alignment can be brittle for ICS traffic because the data often contain bursty communication, rare anomalies, structural imbalance, and noise. Under such conditions, aligning all instances indiscriminately may obscure useful local patterns and lead to unstable target-domain correspondence. A more deployment-oriented strategy is to transfer compact structural summaries rather than individual observations. Motivated by this idea, this paper reformulates cross-plant intrusion detection as a prototype-guided adaptation problem. The proposed framework first maps heterogeneous traffic into a common low-dimensional space, then extracts medoid prototypes that represent stable operational regions in each domain, and finally learns a prototype-calibrated predictor for the target plant. This design emphasizes transferable local structure instead of dense sample-level alignment and is therefore better suited to industrial traffic with heterogeneous semantics and limited labels. The main contributions of this paper are summarized as follows: • We present a new problem formulation for cross-plant unknown attack detection that highlights prototype-level transfer rather than direct global instance matching.
Figure 1: Teaser of the proposed medoid prototype alignment idea. The figure summarizes the cross-plant deployment challenge, the prototype-guided transfer mechanism, and the resulting robustness improvement. • We propose a medoid prototype alignment framework that combines PCA-based compression, K-Medoids prototype extraction, and prototype-calibrated domain adaptation. • We redesign the empirical study around average cross-task performance, directional transfer behavior, and prototype-guidance analysis, providing a different view of industrial transfer robustness.
2
Related Work
Intrusion detection for industrial control systems has traditionally been built around supervised learning with handcrafted or learned traffic features. Prior evaluations have shown that machine learning can be effective for industrial anomaly recognition, but performance depends heavily on the data source, protocol characteristics, and deployment assumptions [9, 28]. Deep learning methods have further improved representation power, for example by using convolutional models to capture temporal and packet-level patterns in industrial traffic [13]. However, most of these methods are trained and tested under relatively stable domain conditions. To reduce the cost of rebuilding models for each industrial site, transfer learning and domain adaptation have attracted increasing attention. General approaches such as Transfer Component Analysis and domain-adversarial learning provide mechanisms to reduce source-target mismatch by learning transferable features [24, 6]. In the security
domain, prior studies have shown that transfer learning can improve the detection of previously unseen attacks, especially when target labels are unavailable [42]. Recent industrial reviews also emphasize the importance of transfer learning for operational deployment and cross-system reuse [12]. Despite this progress, two gaps remain. First, many transfer approaches emphasize holistic distribution alignment and underexploit the internal structure of industrial traffic. Second, industrial data are often noisy and imbalanced, which makes direct sample-wise matching unreliable. Cluster-based summarization offers a way to stabilize correspondence by representing each local region with a robust prototype. K-Medoids is particularly appealing because medoids are real observations and are less sensitive to outliers than mean-based centers [11, 19]. In parallel, recent industrial studies have also highlighted the importance of handling imbalance and cross-domain shifts together [4]. The present work builds on these insights by using medoid prototypes as the transfer anchor for cross-plant intrusion detection.
3
Method
3.1
Problem Definition
Let the labeled source domain be 𝑛𝑠 D𝑠 = {(𝑥𝑖𝑠 , 𝑦 𝑖𝑠 )}𝑖=1 ,
where 𝑥 𝑖𝑠 ∈ R𝑑𝑠 and 𝑦 𝑖𝑠 ∈ {0, 1}. Let the target domain be 𝑡 D𝑡 = {𝑥 𝑡𝑗 } 𝑛𝑗=1 ,
where 𝑥 𝑡𝑗 ∈ R𝑑𝑡 and target labels are unavailable during training. Since the two plants may use different sensors, protocols, and control processes, the domains may satisfy 𝑑 𝑠 ≠ 𝑑𝑡 ,
𝑃𝑠 (𝑋, 𝑌 ) ≠ 𝑃𝑡 (𝑋, 𝑌 ).
The goal is to learn a target-ready detector with the help of source labels while preserving discriminative structure relevant to unknown attack detection [1].
3.2
Shared Representation Construction
Both domains are first standardized independently. Because feature dimensionality may differ across plants, direct distance computation is unreliable. To enable meaningful structural comparison, PCA is used to project both domains into a shared 𝑑 -dimensional representation space [25, 10]: 𝑧 𝑖𝑠 = 𝑊𝑠⊤ 𝑥˜𝑖𝑠 ,
For each target prototype 𝑞 ℓ𝑡 , a soft correspondence over source prototypes is computed:
𝑧 𝑡𝑗 = 𝑊𝑡⊤ 𝑥˜ 𝑡𝑗 ,
where 𝑊𝑠 and 𝑊𝑡 denote the source and target projection matrices. The compressed domains are denoted by
exp(−∥𝑞 ℓ𝑡 − 𝑞 𝑠𝑘 ∥ 22 /𝜏) . 𝑎ℓ 𝑘 = Í 𝑠 2 𝑡 𝑢 exp(−∥𝑞 ℓ − 𝑞 𝑢 ∥ 2 /𝜏)
The prototype alignment loss is then defined as
𝑡 . Z𝑡 = {𝑧 𝑡𝑗 } 𝑛𝑗=1
𝑛𝑠 , Z𝑠 = {(𝑧𝑖𝑠 , 𝑦 𝑖𝑠 )}𝑖=1
This step reduces redundancy and creates a uniform feature basis for prototype extraction.
3.3
Figure 2: Prototype extraction and cross-domain matching in the updated medoid prototype alignment module.
Medoid Prototype Extraction
L 𝑝𝑟 𝑜𝑡𝑜 =
P𝑡 = {𝑝 1𝑡 , . . . , 𝑝 𝑡𝐾𝑡 },
be the medoid sets obtained by clustering the source and target domains in the PCA space. Each medoid is an actual observation minimizing within-cluster dissimilarity [11]: min
{𝐶𝑘 }, { 𝑝𝑘 }
𝐾 ∑︁ ∑︁
∥𝑧 𝑖 − 𝑝 𝑘 ∥ 2 .
𝑘=1 𝑧𝑖 ∈𝐶𝑘
Using medoids rather than means helps preserve physically meaningful operating points and reduces the impact of outliers and rare perturbations.
3.4
Prototype-Calibrated Adaptation
Let 𝑓 𝜃 (·) be the representation encoder and 𝑔 𝜙 (·) be the classifier. The latent representations of source and target samples are 𝑟 𝑖𝑠 = 𝑓 𝜃 (𝑧𝑖𝑠 ),
𝑟 𝑡𝑗 = 𝑓 𝜃 (𝑧 𝑡𝑗 ).
The latent prototypes are 𝑞 𝑠𝑘 = 𝑓 𝜃 ( 𝑝 𝑠𝑘 ),
𝑞 ℓ𝑡 = 𝑓 𝜃 ( 𝑝 ℓ𝑡 ).
𝑎 ℓ 𝑘 ∥𝑞 ℓ𝑡 − 𝑞 𝑠𝑘 ∥ 22 .
ℓ=1 𝑘=1
To preserve source discriminability, we use supervised classification on the source domain:
Instead of aligning all samples directly, we summarize each domain through K-Medoids prototypes. Let P𝑠 = {𝑝 1𝑠 , . . . , 𝑝 𝑠𝐾𝑠 },
𝐾𝑡 ∑︁ 𝐾𝑠 ∑︁
𝑛
𝑠 1 ∑︁ L 𝑠𝑢 𝑝 = CE(𝑔 𝜙 (𝑟 𝑖𝑠 ), 𝑦 𝑖𝑠 ). 𝑛𝑠 𝑖=1
We further encourage confident target predictions through entropy regularization: 𝑛
𝑡 ∑︁ 1 ∑︁ L𝑒𝑛𝑡 = − 𝑦ˆ 𝑡 log 𝑦ˆ 𝑡𝑗𝑐 , 𝑛𝑡 𝑗=1 𝑐 𝑗𝑐
where 𝑦ˆ 𝑡𝑗 = 𝑔 𝜙 (𝑟 𝑡𝑗 ) . The overall learning objective becomes L = L 𝑠𝑢 𝑝 + 𝛼L 𝑝𝑟 𝑜𝑡𝑜 + 𝛽L𝑒𝑛𝑡 .
This design links global classification with local cross-domain structure, allowing the target domain to inherit stable operational regions from the source plant without forcing hard instance-level alignment.
4
Experiments
4.1
Evaluation Questions and Setup
The empirical study is organized around three questions: • RQ1: Does medoid prototype alignment improve average cross-task performance?
Figure 3: Updated overall pipeline of the proposed medoid prototype alignment framework for cross-plant unknown attack detection. Algorithm 1 Medoid Prototype Alignment for Cross-Plant IDS Input: Source domain D𝑠 , target domain D𝑡 Output: Predicted target labels 𝑌ˆ𝑡 1. Standardize source and target traffic features 2. Apply PCA to obtain Z𝑠 and Z𝑡 3. Extract medoid prototypes P𝑠 and P𝑡 using K-Medoids 4. Encode samples and prototypes with 𝑓 𝜃 5. Compute prototype correspondences 𝑎 ℓ 𝑘 6. Optimize L 𝑠𝑢 𝑝 + 𝛼L 𝑝𝑟 𝑜𝑡𝑜 + 𝛽L𝑒𝑛𝑡 7. Predict target labels with 𝑔 𝜙 ( 𝑓 𝜃 (𝑧 𝑡𝑗 )) • RQ2: How sensitive are different models to transfer direction between plants? • RQ3: Does prototype guidance contribute additional robustness beyond standard transfer learning? Experiments are built on two industrial systems: a natural gas control system (G) and a water storage tank control system (W). Four unknown-attack transfer tasks are considered: • DoS(G)→NMRI(W), • SMRI(G)→MPCI(W), • DoS(W)→NMRI(G), • SMRI(W)→MPCI(G). The proposed method, denoted as Medoid Prototype Alignment (MPA), is compared with
Table 1: Average and standard deviation over four cross-domain unknown attack tasks. Method
Avg. ACC
Std. ACC
Avg. F1
Std. F1
MPA ANN SVM RF KNN NBM
0.843 0.518 0.503 0.470 0.455 0.328
0.022 0.021 0.013 0.014 0.027 0.030
0.838 0.400 0.280 0.285 0.355 0.138
0.023 0.090 0.122 0.079 0.115 0.127
Random Forest (RF), Support Vector Machine (SVM), Naive Bayes Model (NBM), K-Nearest Neighbors (KNN), and Artificial Neural Network (ANN). We report Accuracy and F1-score. Because unknown attack detection is sensitive to both false negatives and false alarms, average F1-score is treated as the primary indicator of practical usefulness.
4.2
RQ1: Average Cross-Task Performance
Instead of presenting only task-wise winners, we first aggregate performance across all four transfer tasks. Table 1 reports both the average and the cross-task standard deviation. MPA achieves the strongest average behavior on both metrics, reaching 0.843 accuracy and 0.838 F1-score. Fig. 4 further visualizes these averages together with standard-deviation error bars. The gain over the strongest average baseline is particularly notable. Compared with ANN, which is the strongest baseline on the averaged metrics, MPA improves average accuracy by 62.8% and average F1-score by 109.4%. This indicates that the proposed
Table 3: Worst-case task statistics and across-task performance range. Method
Min ACC
Min F1
ACC Range
F1 Range
MPA ANN SVM RF KNN NBM
0.81 0.50 0.49 0.45 0.41 0.29
0.80 0.26 0.09 0.22 0.23 0.02
0.06 0.05 0.03 0.04 0.07 0.08
0.06 0.25 0.33 0.20 0.25 0.32
Figure 4: Average cross-task performance with standard-deviation error bars. MPA achieves the best mean behavior on both Accuracy and F1-score. Table 2: Cross-task robustness statistics derived from the four transfer tasks. Method ACC CV F1 CV Composite Dir. Gap MPA 0.026 0.027 0.030 ANN 0.040 0.224 0.078 SVM 0.026 0.435 0.113 RF 0.030 0.278 0.055 KNN 0.059 0.325 0.135 NBM 0.093 0.923 0.080 method does more than improve a single favorable task: it raises the overall transfer floor across distinct industrial conditions.
4.3
Cross-Task Robustness Statistics
To complement mean performance, we also analyze normalized dispersion and directional robustness. Table 2 reports the coefficient of variation (CV) for Accuracy and F1-score as well as a composite directional gap defined as 0.5 × (|ΔACC| + |ΔF1|) , where Δ measures the difference between G→W and W→G averages. This statistic captures whether a model remains consistent when the transfer direction changes. These statistics show that MPA combines high mean performance with very low normalized dispersion. Although RF exhibits a slightly smaller directional gap in accuracy alone, MPA has the smallest composite directional gap overall, indicating the most balanced robustness when both Accuracy and F1-score are considered.
4.4
Worst-Case Task Robustness
Average results are informative, but deployment-oriented intrusion detection also depends on how a model behaves on its hardest task. Table 3 therefore reports the worst-case Accuracy and F1-score achieved by each method across the four transfer tasks, together with the corresponding max–min range. A strong deployment-ready method
Figure 5: Worst-case robustness derived from the four transfer tasks. Left: minimum Accuracy and F1-score achieved by each model. Right: across-task performance range, where smaller values indicate more consistent behavior. should achieve both a high worst-case score and a compact range. MPA achieves the strongest worst-case behavior, maintaining at least 0.81 Accuracy and 0.80 F1-score even on its hardest task. At the same time, its performance range remains compact, especially in comparison with methods whose F1-score varies widely across tasks. This result strengthens the view that prototype-guided transfer improves not only average performance but also the lower bound of deployment reliability.
4.5
RQ2: Directional Transfer Behavior
We next examine whether transfer difficulty is symmetric. Table 4 groups results by transfer direction. For most models, using the gas system as the source domain leads to better results than using the water system as the source domain. This suggests that source-domain informativeness matters: richer control semantics appear to produce more transferable structure. MPA preserves a comparatively small directional drop, decreasing from 0.860 to 0.825 in accuracy and from 0.850 to 0.825 in F1-score. This narrower degradation suggests that prototype-level transfer improves robustness when the source plant becomes less informative or when the domain gap becomes larger.
Table 4: Directional average performance by transfer source and target. Method
G→W ACC
G→W F1
W→G ACC
W→G F1
MPA ANN SVM RF KNN NBM
0.860 0.535 0.515 0.480 0.475 0.355
0.850 0.460 0.380 0.240 0.240 0.190
0.825 0.500 0.490 0.460 0.435 0.300
0.825 0.340 0.180 0.330 0.470 0.085
Figure 6: Directional robustness analysis. Left: average Accuracy for G→W and W→G transfer. Right: composite directional gap, where lower is better.
4.6
RQ3: Effect of Prototype Guidance
Prototype guidance is most valuable when source-target correspondence is ambiguous. Based on the currently available task-level results, MPA combines the highest mean performance, the lowest composite directional gap, and one of the smallest relative dispersions across tasks. In the challenging reverse-transfer settings, the prototype-calibrated formulation reduces noisy matches by aligning compact medoid summaries rather than all individual samples. These aggregate properties are consistent with the intended role of prototype guidance: stabilizing cross-domain transfer when plant semantics differ substantially.
4.7
Qualitative Illustration of Alignment Behavior
Because the current manuscript package does not include stored embedding outputs for direct t-SNE or UMAP visualization, we provide a schematic qualitative illustration in Fig. 8. The figure does not represent measured coordinates. Instead, it summarizes the intended effect of MPA: source and target samples are initially separated in the shared feature space, while prototype-guided adaptation brings corresponding operational regions closer together through medoid matching.
4.8
Figure 7: Task-level comparison between MPA and baseline models on four unknown-attack transfer tasks.
Discussion
Three observations emerge from the experiments. First, average performance is a more informative
Figure 8: Qualitative illustration of domain alignment behavior. This figure is schematic and is included for interpretation only; it is not a measured t-SNE or UMAP embedding from the current experiment package. indicator than isolated task-wise peaks for cross-plant deployment, and MPA shows the strongest average behavior. Second, transfer direction matters: source plants with richer operational semantics generally support better adaptation. Third, summarizing each domain through medoid prototypes appears to stabilize adaptation when industrial traffic is noisy, imbalanced, or heterogeneous. Together, these observations support the idea that local structural anchors are a useful complement to conventional domain adaptation in industrial cybersecurity.
5
Conclusion
This paper presented a medoid prototype alignment framework for cross-plant unknown attack detection in Industrial Control Systems. By combining shared-space compression, robust medoid extraction, and prototype-calibrated transfer learning, the
proposed method provides a structurally grounded alternative to direct global alignment. The experimental analysis shows that the method achieves the best average performance across four cross-domain industrial tasks and remains more stable under difficult transfer directions. These results suggest that prototype-guided adaptation is a promising direction for practical industrial intrusion detection under scarce labels and evolving deployments. Future work will extend this idea to open-set labeling, online adaptation, and real-time industrial monitoring. References: [1] Shai Ben-David, John Blitzer, Koby Crammer, and Fernando Pereira. A theory of learning from different domains. Machine Learning, 79(1–2):151–175, 2010. [2] Rihao Chang, Hongbo Jiao, Weizhi Nie, Huijie Guo, Kai Xie, Zihan Wu, Lin Zhao, Yutong Bai, Yongtao Ma, Lijuan Wang, et al. Organ-agents: Virtual human physiology simulator via llms. arXiv preprint arXiv:2508.14357, 2025. [3] Rihao Chang, Yongtao Ma, Tong Hao, Weijie Wang, and Weizhi Nie. 3d shape knowledge graph for cross-domain 3d shape retrieval. CAAI Transactions on Intelligence Technology, 9(5):1199–1216, 2024. [4] Y. Chen, S. Su, D. Yu, H. He, X. Wang, Y. Ma, and H. Guo. Cross-domain industrial intrusion detection deep model trained with imbalanced data. IEEE Internet of Things Journal, 10:584–596, 2023. [5] Yuxing Chen, Weijie Wang, Sylvain Lobry, and Camille Kurtz. An llm agent for automatic geospatial data analysis. arXiv preprint arXiv:2410.18792, 2024. [6] Yaroslav Ganin, Evgeniya Ustinova, Hana Ajakan, Pascal Germain, Hugo Larochelle, François Laviolette, Mario Marchand, and Victor Lempitsky. Domain-adversarial training of neural networks. Journal of Machine Learning Research, 17(59):1–35, 2016. [7] Songxue Gao, Chuanqi Jiao, Ruidong Chen, Weijie Wang, and Weizhi Nie. Point cloud completion guided by prior knowledge via causal inference. arXiv preprint arXiv:2305.17770, 2023. [8] Xuesong Gao, Chuanqi Jiao, Ruidong Chen, Weijie Wang, and Weizhi Nie. Point-pc: Point cloud completion guided by prior knowledge
via causal inference. CAAI Transactions on Intelligence Technology, 2025. [9] M. R. Gauthama Raman, Chuadhry Mujeeb Ahmed, and Aditya Mathur. Machine learning for intrusion detection in industrial control systems: Challenges and lessons from experimental evaluation. Cybersecurity, 4(1):27, 2021. [10] Ian T. Jolliffe. Principal Component Analysis. Springer, New York, 2 edition, 2002. [11] Leonard Kaufman and Peter J. Rousseeuw. Partitioning around medoids (program pam). In Finding Groups in Data: An Introduction to Cluster Analysis, pages 68–125. John Wiley & Sons, New York, 1990. [12] Hamza Kheddar, Yassine Himeur, and Ali Ismail Awad. Deep transfer learning for intrusion detection in industrial control networks: A comprehensive review. Journal of Network and Computer Applications, 220:103760, 2023. [13] Moshe Kravchik and Asaf Shabtai. Detecting cyberattacks in industrial control systems using convolutional neural networks. arXiv preprint arXiv:1806.08110, 2018. [14] Chenxi Li, Weijie Wang, Qiang Li, Bruno Lepri, Nicu Sebe, and Weizhi Nie. Freeinsert: Disentangled text-guided object insertion in 3d gaussian scene without spatial priors, 2025. [15] Qi Liang, Ning Xu, Weijie Wang, and Xingjian Long. Multimodal information fusion based on lstm for 3d model retrieval. Multimedia Tools and Applications, 79(45–46):33943–33956, 2020. [16] Mingrui Ma, Tao Wang, Liyuan Song, Weijie Wang, and Guixia Liu. Rfr-wwanet: Weighted window attention-based recovery feature resolution network for unsupervised image registration. Pattern Recognition, 2023. [17] Mingrui Ma, Weijie Wang, Jie Ning, Jianfeng He, Nicu Sebe, and Bruno Lepri. Large language models for multimodal deformable image registration. arXiv preprint arXiv:2408.10703, 2024. [18] Guofeng Mei, Hao Tang, Xiaoshui Huang, Weijie Wang, Juan Liu, Jian Zhang, Luc Van Gool, and Qiang Wu. Unsupervised deep probabilistic approach for partial point cloud registration. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), 2023.
[19] Haroon Mushtaq, S. U. Khan, M. A. Jan, A. Ullah, and H. A. Khattak. A parallel architecture for the partitioning around medoids (pam) algorithm. Sensors, 18(12):4129, 2018. [20] Weizhi Nie, Ruidong Chen, Weijie Wang, Bruno Lepri, and Nicu Sebe. T2td: Text-3d generation model based on prior knowledge guidance. IEEE TPAMI, 2024. [21] Weizhi Nie, Ruidong Chen, Weijie Wang, Bruno Lepri, and Nicu Sebe. T2td: Text-3d generation model based on prior knowledge guidance. IEEE Transactions on Pattern Analysis and Machine Intelligence, 47(1):172–189, 2025. [22] Weizhi Nie, Weijie Wang, Anan Liu, and Chuang Chen. Characteristic views extraction modal based-on deep reinforcement learning for 3d model retrieval. In 2019 IEEE International Conference on Image Processing (ICIP), pages 2389–2393, 2019.
[28] Muhammad Azmi Umer, Khurum Nazir Junejo, Muhammad Taha Jilani, and Aditya P. Mathur. Machine learning for intrusion detection in industrial control systems: Applications, challenges, and recommendations. International Journal of Critical Infrastructure Protection, 38:100516, 2022. [29] Tao Wang, Weijie Wang, Fausto Giunchiglia, Fengzhi Zhao, Ye Zhang, Duo Yu, and Guixia Liu. Mbt-polyp: A new multi-branch memory-augmented transformer for polyp segmentation. Image and Vision Computing, 163:105747, 2025. [30] Tao Wang, Kai Zhang, Weijie Wang, Mingrui Ma, Ye Zhang, He Zhao, and Guixia Liu. U-hrmlp: Refining segmentation boundaries in histopathology images. In 2024 IEEE International Symposium on Biomedical Imaging (ISBI), pages 1–5, 2024.
[23] Weizhi Nie, Weijie Wang, Anan Liu, Jie Nie, and Yuxuan Su. Hgan: Holistic generative adversarial networks for two-dimensional image-based three-dimensional object retrieval. ACM Transactions on Multimedia Computing, Communications, and Applications, 15(4):1–24, 2019.
[31] Wei Wang, Zhun Zhong, Weijie Wang, Xi Chen, Charles Ling, Boyu Wang, and Nicu Sebe. Dynamically instance-guided adaptation: A backward-free approach for test-time domain adaptive semantic segmentation. In Proceedings of the IEEE/CVF Conference on Computer Vision and Pattern Recognition (CVPR), pages 24090–24099, 2023.
[24] Sinno Jialin Pan, Ivor W. Tsang, James T. Kwok, and Qiang Yang. Domain adaptation via transfer component analysis. In Proceedings of the 21st International Joint Conference on Artificial Intelligence (IJCAI), pages 1187–1192, 2009.
[32] Weijie Wang, Guofeng Mei, Jian Zhang, Nicu Sebe, Bruno Lepri, and Fabio Poiesi. Fully-geometric cross-attention for point cloud registration. In 3DV, 2025.
[25] Karl Pearson. On lines and planes of closest fit to systems of points in space. The London, Edinburgh, and Dublin Philosophical Magazine and Journal of Science, 2(11):559–572, 1901. [26] Bin Ren, Guofeng Mei, Danda Pani Paudel, Weijie Wang, Yawei Li, Mengyuan Liu, Rita Cucchiara, Luc Van Gool, and Nicu Sebe. Bringing masked autoencoders explicit contrastive properties for point cloud self-supervised learning. In Proceedings of the Asian Conference on Computer Vision (ACCV), 2024. [27] A. Rigo, L. Stornaiuolo, Weijie Wang, M. Martino, Bruno Lepri, Nicu Sebe, and Weizhi Nie. Poci-diff: Position objects consistently and interactively with 3d-layout guided diffusion. arXiv preprint arXiv:2601.14056, 2026.
[33] Weijie Wang, Guofeng Mei, Jian Zhang, Nicu Sebe, Bruno Lepri, and Fabio Poiesi. Fully-geometric cross-attention for point cloud registration. In 3DV. IEEE, 2025. [34] Weijie Wang, Wenqi Ren, Guofeng Mei, Bin Ren, Xiaoshui Huang, Fabio Poiesi, Nicu Sebe, and Bruno Lepri. Zeroreg: Zero-shot point cloud registration with foundation models. arXiv preprint arXiv:2312.03032, 2023. [35] Weijie Wang, Nicu Sebe, and Bruno Lepri. Rethinking the learning paradigm for facial expression recognition. arXiv preprint arXiv:2209.15402, 2022. [36] Weijie Wang, Songlong Xing, Zhengyu Zhao, Nicu Sebe, and Bruno Lepri. Poinit-of-view: Poisoning initialization of views transfers across multiple 3d reconstruction systems. arXiv preprint arXiv:2604.16540, 2026.
[37] Weijie Wang, Jichao Zhang, Chang Liu, Xia Li, Xingqian Xu, Humphrey Shi, Nicu Sebe, and Bruno Lepri. Uvmap-id: A controllable and personalized uv map generative model. In ACM MM, pages 10725–10734, 2024.
Finetune like you pretrain: Boosting zero-shot adversarial robustness in vision-language models. arXiv preprint arXiv:2604.11576, 2026.
[38] Weijie Wang, Zhengyu Zhao, Nicu Sebe, and Bruno Lepri. Turn fake into real: Adversarial head turn attacks against deepfake detection. arXiv preprint arXiv:2309.01104, 2023.
[41] Zibo Xu, Qiang Li, Weizhi Nie, Weijie Wang, and Anan Liu. Structure causal models and llms integration in medical visual question answering. IEEE Transactions on Medical Imaging, 44(8):3476–3489, 2025.
[39] Xuquan Wang, Feng Zhang, Kai Zhang, Weijie Wang, Xiong Dun, and Jiande Sun. Learning spatial-spectral dual adaptive graph embedding for multispectral and hyperspectral image fusion. Pattern Recognition, 151:110365, 2024. [40] Songlong Xing, Weijie Wang, Zhengyu Zhao, Jindong Gu, Philip Torr, and Nicu Sebe.
[42] Juan Zhao, Sachin Shetty, Jan Wei Pan, Charles Kamhoua, and Kevin Kwiat. Transfer learning for detecting unknown network attacks. EURASIP Journal on Information Security, 2019(1):1, 2019.