VLDB 2026 Research / reviewers in the wild / expert
Yangyi Chen
dblp:05/10083
· DBLP profile ↗
30ranked-venue papers
10as first author
22since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 21 · 7 first-author · 21 since 2021Security and privacy · 6 · 3 first-authorGraphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Computer networks · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | SyncMind: Measuring Agent Out-of-Sync Recovery in Collaborative Software EngineeringabstractSoftware engineering (SE) is increasingly collaborative, with developers working together on shared complex codebases. Effective collaboration in shared environments requires participants—whether humans or AI agents—to stay on the same page as their environment evolves. When a collaborator’s understanding diverges from the current state—what we term the out-of-sync challenge—the collaborator’s actions may fail, leading to integration issues. In this work, we introduce SyncMind, a framework that systematically defines the out-of-sync problem faced by large language model (LLM) agents in collaborative software engineering (CSE). Based on SyncMind, we create SyncBench, a benchmark featuring 24,332 instances of agent out-of-sync scenarios in real-world CSE derived from 21 popular GitHub repositories with executable verification tests. Experiments on SyncBench uncover critical insights into existing LLM agents’ capabilities and limitations. Besides substantial performance gaps among agents (from Llama-3.1 agents $\leq 3.33%$ to Claude-3.5-Sonnet $\geq 28.18%$), their consistently low collaboration willingness ($\le 4.86%$) suggests fundamental limitations of existing LLM in CSE. However, when collaboration occurs, it positively correlates with out-of-sync recovery success. Minimal performance differences in agents’ resource-aware out-of-sync recoveries further reveal their significant lack of resource awareness and adaptability, shedding light on future development of resource-efficient collaborative systems. Our code and data are openly available on our project website: https://xhguo7.github.io/SyncMind/. Xuehang Guo, Xingyao Wang 0002, Yangyi Chen, Chi Han, Manling Li, Heng Ji 0001 |
ICML | 3 |
| 2024 | DRESS : Instructing Large Vision-Language Models to Align and Interact with Humans via Natural Language FeedbackabstractWe present DRESS , a large vision language model (LVLM) that innovatively exploits Natural Language feedback (NLF) from Large Language Models to enhance its alignment and interactions by addressing two key limitations in the state-of-the-art LVLMs. First, prior LVLMs generally rely only on the instruction finetuning stage to enhance alignment with human preferences. Without incorporating extra feedback, they are still prone to generate unhelpful, hallucinated, or harmful responses. Second, while the visual instruction tuning data is generally structured in a multi-turn dialogue format, the connections and dependencies among consecutive conversational turns are weak. This reduces the capacity for effective multi-turn interactions. To tackle these, we propose a novel categorization of the NLF into two key types: critique and refinement. The critique NLF identifies the strengths and weaknesses of the responses and is used to align the LVLMs with human preferences. The refinement NLF offers concrete suggestions for improvement and is adopted to improve the interaction ability of the LVLMs- which focuses on LVLMs' ability to refine responses by incorporating feedback in multi-turn interactions. To address the non-differentiable nature of NLF, we generalize conditional reinforcement learning for training. Our experimental results demonstrate that DRESS can generate more helpful (9.76%), honest (11.52%), and harmless (21.03%) responses, and more effectively learn from feedback during multi-turn interactions compared to SOTA LVLMs. Yangyi Chen, Karan Sikka, Michael Cogswell, Heng Ji 0001, Ajay Divakaran |
CVPR | 1 |
| 2024 | SaySelf: Teaching LLMs to Express Confidence with Self-Reflective RationalesabstractLarge language models (LLMs) often generate inaccurate or fabricated information and generally fail to indicate their confidence, which limits their broader applications.Previous work has elicited confidence from LLMs by direct or self-consistency prompting, or constructing specific datasets for supervised finetuning.The prompting-based approaches have inferior performance, and the training-based approaches are limited to binary or inaccurate group-level confidence estimates.In this work, we present SaySelf, a novel training framework that teaches LLMs to express more fine-grained confidence estimates.In addition, beyond the confidence scores, SaySelf initiates the process of directing LLMs to produce selfreflective rationales that clearly identify gaps in their parametric knowledge and explain their uncertainty.This is achieved by using an LLM to automatically summarize the uncertainties in specific knowledge via natural language.The summarization is based on the analysis of the inconsistency in multiple sampled reasoning chains, and the resulting data is utilized for supervised fine-tuning.Moreover, we utilize reinforcement learning with a meticulously crafted reward function to calibrate the confidence estimates, motivating LLMs to deliver accurate, high-confidence predictions and to penalize overconfidence in erroneous outputs.Experimental results demonstrate the effectiveness of SaySelf in reducing the confidence calibration error and maintaining the task performance.The generated self-reflective rationales are also reasonable and can further contribute to the calibration.The code is made public at https://github.com/xu1868/SaySelf. Direct Prompting / Group-based Calibration Training Self-Consistency Prompting Previous WorkWhat is the name of the younger son of the current President of the United States?Robert Hunter Biden.My overall confidence is 3. Robert Hunter Biden. According to my knowledge, there is a slight possibility that the current President is Trump.My overall confidence is 8. Shujin Wu, Shizhe Diao, Xiaoze Liu, Xingyao Wang 0002, Yangyi Chen, Jing Gao 0004 |
EMNLP | 6 |
| 2024 | MINT: Evaluating LLMs in Multi-turn Interaction with Tools and Language FeedbackabstractTo solve complex tasks, large language models (LLMs) often require multiple rounds of interactions with the user, sometimes assisted by external tools.
However, current evaluation protocols often emphasize benchmark performance with single-turn exchanges, neglecting the nuanced interactions among the user, LLMs, and external tools, while also underestimating the importance of natural language feedback from users. These oversights contribute to discrepancies between research benchmark evaluations and real-world use cases.
We introduce MINT, a benchmark that evaluates LLMs' ability to solve tasks with multi-turn interactions by (1) using tools and (2) leveraging natural language feedback.
To ensure reproducibility, we provide an evaluation framework where LLMs can access tools by executing Python code and receive users' natural language feedback simulated by GPT-4.
We repurpose a diverse set of established evaluation datasets focusing on reasoning, coding, and decision-making and carefully curate them into a compact subset for efficient evaluation.
Our analysis of 20 open- and closed-source LLMs offers intriguing findings.
(a) LLMs generally benefit from tools and language feedback, with performance gains (absolute, same below) of 1--8% for each turn of tool use and 2--17% with natural language feedback.
(b) Better single-turn performance does not guarantee better multi-turn performance.
(c) Surprisingly, on the LLMs evaluated, supervised instruction-finetuning (SIFT) and reinforcement learning from human feedback (RLHF) generally hurt multi-turn capabilities.
We expect MINT can help measure progress and incentivize research in improving LLMs' capabilities in multi-turn interactions, especially for open-source communities where multi-turn human evaluation can be less accessible compared to commercial LLMs with a larger user base. Xingyao Wang 0002, Zihan Wang 0010, Jiateng Liu, Yangyi Chen, Lifan Yuan, Hao Peng 0009, Heng Ji 0001 |
ICLR | 4 |
| 2024 | CRAFT: Customizing LLMs by Creating and Retrieving from Specialized ToolsetsabstractLarge language models (LLMs) are often augmented with tools to solve complex tasks. By generating code snippets and executing them through task-specific Application Programming Interfaces (APIs), they can offload certain functions to dedicated external modules, such as image encoding and performing calculations. However, most existing approaches to augment LLMs with tools are constrained
by general-purpose APIs and lack the flexibility for tailoring them to specific tasks. In this work, we present CRAFT, a general tool creation and retrieval framework for LLMs. It creates toolsets specifically curated for the tasks and equips LLMs with a component that retrieves tools from these sets to enhance their capability to solve complex tasks. For each task, we collect specific code solutions by prompting
GPT-4 to solve the training examples. Following a validation step ensuring the correctness, these solutions are abstracted into code snippets to enhance reusability, and deduplicated for higher quality. At inference time, the language model retrieves snippets from the toolsets and then executes them or generates the output conditioning on the retrieved snippets. Our method is designed to be flexible and
offers a plug-and-play approach to adapt off-the-shelf LLMs to unseen domains and modalities, without any finetuning. Experiments on vision-language, tabular processing, and mathematical reasoning tasks show that our approach achieves substantial improvements compared to strong baselines. In addition, our in-depth analysis reveals that: (1) consistent performance improvement can be achieved by
scaling up the number of tools and the capability of the backbone models; (2) each component of our approach contributes to the performance gains; (3) the created tools are well-structured and reliable with low complexity and atomicity. Lifan Yuan, Yangyi Chen, Xingyao Wang 0002, Yi R. Fung 0001, Hao Peng 0009, Heng Ji 0001 |
ICLR | 2 |
| 2024 | Executable Code Actions Elicit Better LLM AgentsabstractLarge Language Model (LLM) agents, capable of performing a broad range of actions, such as invoking tools and controlling robots, show great potential in tackling real-world challenges. LLM agents are typically prompted to produce actions by generating JSON or text in a pre-defined format, which is usually limited by constrained action space (e.g., the scope of pre-defined tools) and restricted flexibility (e.g., inability to compose multiple tools). This work proposes to use executable Python code to consolidate LLM agents’ actions into a unified action space (CodeAct). Integrated with a Python interpreter, CodeAct can execute code actions and dynamically revise prior actions or emit new actions upon new observations through multi-turn interactions. Our extensive analysis of 17 LLMs on API-Bank and a newly curated benchmark shows that CodeAct outperforms widely used alternatives (up to 20% higher success rate). The encouraging performance of CodeAct motivates us to build an open-source LLM agent that interacts with environments by executing interpretable code and collaborates with users using natural language. To this end, we collect an instruction-tuning dataset CodeActInstruct that consists of 7k multi-turn interactions using CodeAct. We show that it can be used with existing data to improve models in agent-oriented tasks without compromising their general capability. CodeActAgent, finetuned from Llama2 and Mistral, is integrated with Python interpreter and uniquely tailored to perform sophisticated tasks (e.g., model training) using existing libraries and autonomously self-debug. Xingyao Wang 0002, Yangyi Chen, Lifan Yuan, Yizhe Zhang 0002, Yunzhu Li, Hao Peng 0009, Heng Ji 0001 |
ICML | 2 |
| 2024 | MIRACLE: An Online, Explainable Multimodal Interactive Concept Learning SystemabstractWe present MIRACLE, a system for online, interpretable visual concept and video action recognition. Through a chat interface, users query the recognition system with an uploaded image or video. For images, MIRACLE returns concept predictions from its structured knowledge base, justifying its predictions with heatmaps and natural language-based attribute detections. For videos, MIRACLE predicts an action and justifies its prediction with time varying entity-entity relations. With its ability to learn new concepts in an online, few-shot manner and its support of dynamic changes to its knowledge base, MIRACLE represents a step forward in interpretable multimodal learning systems. Ansel Blume, Khanh Duy Nguyen, Zhenhailong Wang, Yangyi Chen, Michal Shlapentokh-Rothman, Xiaomeng Jin, Zhen Zhu 0006, Jiateng Liu, Kuan-Hao Huang, Mankeerat Sidhu, Xuanming Zhang, Vivian Liu, Raunak Sinha, Te-Lin Wu, Abhaysinh Zala, Elias Stengel-Eskin, Da Yin, Utkarsh Mall, Zhou Yu 0005, Kai-Wei Chang 0001, Camille Cobb, Karrie Karahalios, Lydia B. Chilton, Mohit Bansal, Nanyun Peng 0001, Carl Vondrick, Derek Hoiem, Heng Ji 0001 |
ACM Multimedia | 4 |
| 2024 | Measuring and Improving Chain-of-Thought Reasoning in Vision-Language ModelsabstractYangyi Chen, Karan Sikka, Michael Cogswell, Heng Ji, Ajay Divakaran. Proceedings of the 2024 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies (Volume 1: Long Papers). 2024. Yangyi Chen, Karan Sikka, Michael Cogswell, Heng Ji 0001, Ajay Divakaran |
NAACL-HLT | 1 |
| 2024 | R-Tuning: Instructing Large Language Models to Say 'I Don't Know'abstractHanning Zhang, Shizhe Diao, Yong Lin, Yi Fung, Qing Lian, Xingyao Wang, Yangyi Chen, Heng Ji, Tong Zhang. Proceedings of the 2024 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies (Volume 1: Long Papers). 2024. Hanning Zhang, Shizhe Diao, Yi R. Fung 0001, Qing Lian, Xingyao Wang 0002, Yangyi Chen, Heng Ji 0001, Tong Zhang 0001 |
NAACL-HLT | 7 |
| 2023 | A Close Look into the Calibration of Pre-trained Language ModelsabstractPre-trained language models (PLMs) may fail in giving reliable estimates of their predictive uncertainty.We take a close look into this problem, aiming to answer two questions: (1) Do PLMs learn to become calibrated in the training process?(2) How effective are existing calibration methods?For the first question, we conduct fine-grained control experiments to study the dynamic change in PLMs' calibration performance in training.We consider six factors as control variables, including dataset difficulty, available training samples, training steps, the number of tunable parameters, model scale, and pretraining.We observe a consistent change in calibration performance across six factors.We find that PLMs don't learn to become calibrated in training, evidenced by the continual increase in confidence, no matter whether the predictions are correct or not.We highlight that our finding somewhat contradicts two established conclusions: (a) Larger PLMs are more calibrated; (b) Pretraining improves model calibration.Next, we study the effectiveness of existing calibration methods in mitigating the overconfidence issue.Besides unlearnable calibration methods (e.g., label smoothing), we adapt and extend two recently proposed learnable methods that directly collect data to train models to have reasonable confidence estimations.Experimental results show that learnable methods significantly reduce PLMs' confidence in wrong predictions.The code is available at https://github. com/lifan-yuan/PLMCalibration. Yangyi Chen, Lifan Yuan, Ganqu Cui, Zhiyuan Liu 0001, Heng Ji 0001 |
ACL (1) | 1 |
| 2023 | ViStruct: Visual Structural Knowledge Extraction via Curriculum Guided Code-Vision RepresentationabstractState-of-the-art vision-language models (VLMs) still have limited performance in structural knowledge extraction, such as relations between objects.In this work, we present ViStruct, a training framework to learn VLMs for effective visual structural knowledge extraction.Two novel designs are incorporated.First, we propose to leverage the inherent structure of programming language to depict visual structural information.This approach enables explicit and consistent representation of visual structural information of multiple granularities, such as concepts, relations, and events, in a well-organized structured format.Second, we introduce curriculum-based learning for VLMs to progressively comprehend visual structures, from fundamental visual concepts to intricate event structures.Our intuition is that lower-level knowledge may contribute to complex visual structure understanding.Furthermore, we compile and release a collection of datasets tailored for visual structural knowledge extraction.We adopt a weakly-supervised approach to directly generate visual event structures from captions for ViStruct training, capitalizing on abundant image-caption pairs from the web.In experiments, we evaluate ViStruct on visual structure prediction tasks, demonstrating its effectiveness in improving the understanding of visual structures.The code is public at https://github.com/ Yangyi-Chen/vi-struct. Yangyi Chen, Xingyao Wang 0002, Manling Li, Derek Hoiem, Heng Ji 0001 |
EMNLP | 1 |
| 2023 | Beat LLMs at Their Own Game: Zero-Shot LLM-Generated Text Detection via Querying ChatGPTabstractBiru Zhu, Lifan Yuan, Ganqu Cui, Yangyi Chen, Chong Fu, Bingxiang He, Yangdong Deng, Zhiyuan Liu, Maosong Sun, Ming Gu. Proceedings of the 2023 Conference on Empirical Methods in Natural Language Processing. 2023. Biru Zhu, Lifan Yuan, Ganqu Cui, Yangyi Chen, Bingxiang He, Yangdong Deng, Zhiyuan Liu 0001, Maosong Sun 0001, Ming Gu 0001 |
EMNLP | 4 |
| 2023 | Revisiting Out-of-distribution Robustness in NLP: Benchmarks, Analysis, and LLMs EvaluationsabstractThis paper reexamines the research on out-of-distribution (OOD) robustness in the field of NLP. We find that the distribution shift settings in previous studies commonly lack adequate challenges, hindering the accurate evaluation of OOD robustness. To address these issues, we propose a benchmark construction protocol that ensures clear differentiation and challenging distribution shifts. Then we introduceBOSS, a Benchmark suite for Out-of-distribution robustneSS evaluation covering 5 tasks and 20 datasets. Based on BOSS, we conduct a series of experiments on pretrained language models for analysis and evaluation of OOD robustness. First, for vanilla fine-tuning, we examine the relationship between in-distribution (ID) and OOD performance. We identify three typical types that unveil the inner learningmechanism, which could potentially facilitate the forecasting of OOD robustness, correlating with the advancements on ID datasets. Then, we evaluate 5 classic methods on BOSS and find that, despite exhibiting some effectiveness in specific cases, they do not offer significant improvement compared to vanilla fine-tuning. Further, we evaluate 5 LLMs with various adaptation paradigms and find that when sufficient ID data is available, fine-tuning domain-specific models outperform LLMs on ID examples significantly. However, in the case of OOD instances, prioritizing LLMs with in-context learning yields better results. We identify that both fine-tuned small models and LLMs face challenges in effectively addressing downstream tasks. The code is public at https://github.com/lifan-yuan/OOD_NLP. Lifan Yuan, Yangyi Chen, Ganqu Cui, Hongcheng Gao, Fangyuan Zou, Xingyi Cheng, Heng Ji 0001, Zhiyuan Liu 0001, Maosong Sun 0001 |
NeurIPS | 2 |
| 2023 | Removing Backdoors in Pre-trained Models by Regularized Continual Pre-trainingabstractAbstract Recent research has revealed that pre-trained models (PTMs) are vulnerable to backdoor attacks before the fine-tuning stage. The attackers can implant transferable task-agnostic backdoors in PTMs, and control model outputs on any downstream task, which poses severe security threats to all downstream applications. Existing backdoor-removal defenses focus on task-specific classification models and they are not suitable for defending PTMs against task-agnostic backdoor attacks. To this end, we propose the first task-agnostic backdoor removal method for PTMs. Based on the selective activation phenomenon in backdoored PTMs, we design a simple and effective backdoor eraser, which continually pre-trains the backdoored PTMs with a regularization term in an end-to-end approach. The regularization term removes backdoor functionalities from PTMs while the continual pre-training maintains the normal functionalities of PTMs. We conduct extensive experiments on pre-trained models across different modalities and architectures. The experimental results show that our method can effectively remove backdoors inside PTMs and preserve benign functionalities of PTMs with a few downstream-task-irrelevant auxiliary data, e.g., unlabeled plain texts. The average attack success rate on three downstream datasets is reduced from 99.88% to 8.10% after our defense on the backdoored BERT. The codes are publicly available at https://github.com/thunlp/RECIPE. Biru Zhu, Ganqu Cui, Yangyi Chen, Yujia Qin, Lifan Yuan, Yangdong Deng, Zhiyuan Liu 0001, Maosong Sun 0001, Ming Gu 0001 |
Trans. Assoc. Comput. Linguistics | 3 |
| 2022 | Why Should Adversarial Perturbations be Imperceptible? Rethink the Research Paradigm in Adversarial NLPabstractTextual adversarial samples play important roles in multiple subfields of NLP research, including security, evaluation, explainability, and data augmentation.However, most work mixes all these roles, obscuring the problem definitions and research goals of the security role that aims to reveal the practical concerns of NLP models.In this paper, we rethink the research paradigm of textual adversarial samples in security scenarios.We discuss the deficiencies in previous work and propose our suggestions that the research on the Security-oriented adversarial NLP (SoadNLP) should: (1) evaluate their methods on security tasks to demonstrate the real-world concerns; (2) consider realworld attackers' goals, instead of developing impractical methods.To this end, we first collect, process, and release a security datasets collection Advbench.Then, we reformalize the task and adjust the emphasis on different goals in SoadNLP.Next, we propose a simple method based on heuristic rules that can easily fulfill the actual adversarial goals to simulate real-world attack methods.We conduct experiments on both the attack and the defense sides on Advbench.Experimental results show that our method has higher practical value, indicating that the research paradigm in SoadNLP may start from our new benchmark.All the code and data of Advbench can be obtained at https: //github.com/thunlp/Advbench. Yangyi Chen, Hongcheng Gao, Ganqu Cui, Fanchao Qi, Longtao Huang, Zhiyuan Liu 0001, Maosong Sun 0001 |
EMNLP | 1 |
| 2022 | Textual Backdoor Attacks Can Be More Harmful via Two Simple TricksabstractBackdoor attacks are a kind of emergent security threat in deep learning.After being injected with a backdoor, a deep neural model will behave normally on standard inputs but give adversary-specified predictions once the input contains specific backdoor triggers.In this paper, we find two simple tricks that can make existing textual backdoor attacks much more harmful.The first trick is to add an extra training task to distinguish poisoned and clean data during the training of the victim model, and the second one is to use all the clean training data rather than remove the original clean data corresponding to the poisoned data.These two tricks are universally applicable to different attack models.We conduct experiments in three tough situations including clean data fine-tuning, low-poisoningrate, and label-consistent attacks.Experimental results show that the two tricks can significantly improve attack performance.This paper exhibits the great potential harmfulness of backdoor attacks.All the code and data can be obtained at https://github.com/ thunlp/StyleAttack. Yangyi Chen, Fanchao Qi, Hongcheng Gao, Zhiyuan Liu 0001, Maosong Sun 0001 |
EMNLP | 1 |
| 2022 | A Unified Evaluation of Textual Backdoor Learning: Frameworks and BenchmarksabstractTextual backdoor attacks are a kind of practical threat to NLP systems. By injecting a backdoor in the training phase, the adversary could control model predictions via predefined triggers. As various attack and defense models have been proposed, it is of great significance to perform rigorous evaluations. However, we highlight two issues in previous backdoor learning evaluations: (1) The differences between real-world scenarios (e.g. releasing poisoned datasets or models) are neglected, and we argue that each scenario has its own constraints and concerns, thus requires specific evaluation protocols; (2) The evaluation metrics only consider whether the attacks could flip the models' predictions on poisoned samples and retain performances on benign samples, but ignore that poisoned samples should also be stealthy and semantic-preserving. To address these issues, we categorize existing works into three practical scenarios in which attackers release datasets, pre-trained models, and fine-tuned models respectively, then discuss their unique evaluation methodologies. On metrics, to completely evaluate poisoned samples, we use grammar error increase and perplexity difference for stealthiness, along with text similarity for validity. After formalizing the frameworks, we develop an open-source toolkit OpenBackdoor to foster the implementations and evaluations of textual backdoor learning. With this toolkit, we perform extensive experiments to benchmark attack and defense models under the suggested paradigm. To facilitate the underexplored defenses against poisoned datasets, we further propose CUBE, a simple yet strong clustering-based defense baseline. We hope that our frameworks and benchmarks could serve as the cornerstones for future model development and evaluations. Ganqu Cui, Lifan Yuan, Bingxiang He, Yangyi Chen, Zhiyuan Liu 0001, Maosong Sun 0001 |
NeurIPS | 4 |
| 2022 | Moderate-fitting as a Natural Backdoor Defender for Pre-trained Language ModelsabstractDespite the great success of pre-trained language models (PLMs) in a large set of natural language processing (NLP) tasks, there has been a growing concern about their security in real-world applications. Backdoor attack, which poisons a small number of training samples by inserting backdoor triggers, is a typical threat to security. Trained on the poisoned dataset, a victim model would perform normally on benign samples but predict the attacker-chosen label on samples containing pre-defined triggers. The vulnerability of PLMs under backdoor attacks has been proved with increasing evidence in the literature. In this paper, we present several simple yet effective training strategies that could effectively defend against such attacks. To the best of our knowledge, this is the first work to explore the possibility of backdoor-free adaptation for PLMs. Our motivation is based on the observation that, when trained on the poisoned dataset, the PLM's adaptation follows a strict order of two stages: (1) a moderate-fitting stage, where the model mainly learns the major features corresponding to the original task instead of subsidiary features of backdoor triggers, and (2) an overfitting stage, where both features are learned adequately. Therefore, if we could properly restrict the PLM's adaptation to the moderate-fitting stage, the model would neglect the backdoor triggers but still achieve satisfying performance on the original task. To this end, we design three methods to defend against backdoor attacks by reducing the model capacity, training epochs, and learning rate, respectively. Experimental results demonstrate the effectiveness of our methods in defending against several representative NLP backdoor attacks. We also perform visualization-based analysis to attain a deeper understanding of how the model learns different features, and explore the effect of the poisoning ratio. Finally, we explore whether our methods could defend against backdoor attacks for the pre-trained CV model. The codes are publicly available at https://github.com/thunlp/Moderate-fitting. Biru Zhu, Yujia Qin, Ganqu Cui, Yangyi Chen, Weilin Zhao, Yangdong Deng, Zhiyuan Liu 0001, Jingang Wang, Wei Wu 0014, Maosong Sun 0001, Ming Gu 0001 |
NeurIPS | 4 |
| 2021 | Hidden Killer: Invisible Textual Backdoor Attacks with Syntactic TriggerabstractFanchao Qi, Mukai Li, Yangyi Chen, Zhengyan Zhang, Zhiyuan Liu, Yasheng Wang, Maosong Sun. Proceedings of the 59th Annual Meeting of the Association for Computational Linguistics and the 11th International Joint Conference on Natural Language Processing (Volume 1: Long Papers). 2021. Fanchao Qi, Mukai Li, Yangyi Chen, Zhengyan Zhang, Zhiyuan Liu 0001, Yasheng Wang, Maosong Sun 0001 |
ACL/IJCNLP (1) | 3 |
| 2021 | Multi-granularity Textual Adversarial Attack with Behavior CloningabstractRecently, the textual adversarial attack models become increasingly popular due to their successful in estimating the robustness of NLP models.However, existing works have obvious deficiencies.(1) They usually consider only a single granularity of modification strategies (e.g.word-level or sentence-level), which is insufficient to explore the holistic textual space for generation; (2) They need to query victim models hundreds of times to make a successful attack, which is highly inefficient in practice.To address such problems, in this paper we propose MAYA, a Multi-grAnularitY Attack model to effectively generate high-quality adversarial samples with fewer queries to victim models.Furthermore, we propose a reinforcement-learning based method to train a multi-granularity attack agent through behavior cloning with the expert knowledge from our MAYA algorithm to further reduce the query times.Additionally, we also adapt the agent to attack blackbox models that only output labels without confidence scores.We conduct comprehensive experiments to evaluate our attack models by attacking BiLSTM, BERT and RoBERTa in two different black-box attack settings and three benchmark datasets.Experimental results show that our models achieve overall better attacking performance and produce more fluent and grammatical adversarial samples compared to baseline models.Besides, our adversarial attack agent significantly reduces the query times in both attack settings. Yangyi Chen, Jin Su, Wei Wei 0002 |
EMNLP (1) | 1 |
| 2021 | ONION: A Simple and Effective Defense Against Textual Backdoor AttacksabstractBackdoor attacks are a kind of emergent training-time threat to deep neural networks (DNNs).They can manipulate the output of DNNs and possess high insidiousness.In the field of natural language processing, some attack methods have been proposed and achieve very high attack success rates on multiple popular models.Nevertheless, there are few studies on defending against textual backdoor attacks.In this paper, we propose a simple and effective textual backdoor defense named ONION, which is based on outlier word detection and, to the best of our knowledge, is the first method that can handle all the textual backdoor attack situations.Experiments demonstrate the effectiveness of our model in defending BiLSTM and BERT against five different backdoor attacks.All the code and data of this paper can be obtained at https: //github.com/thunlp/ONION. Fanchao Qi, Yangyi Chen, Mukai Li, Yuan Yao 0013, Zhiyuan Liu 0001, Maosong Sun 0001 |
EMNLP (1) | 2 |
| 2021 | Mind the Style of Text! Adversarial and Backdoor Attacks Based on Text Style TransferabstractAdversarial attacks and backdoor attacks are two common security threats that hang over deep learning.Both of them harness taskirrelevant features of data in their implementation.Text style is a feature that is naturally irrelevant to most NLP tasks, and thus suitable for adversarial and backdoor attacks.In this paper, we make the first attempt to conduct adversarial and backdoor attacks based on text style transfer, which is aimed at altering the style of a sentence while preserving its meaning.We design an adversarial attack method and a backdoor attack method, and conduct extensive experiments to evaluate them.Experimental results show that popular NLP models are vulnerable to both adversarial and backdoor attacks based on text style transfer-the attack success rates can exceed 90% without much effort.It reflects the limited ability of NLP models to handle the feature of text style that has not been widely realized.In addition, the style transfer-based adversarial and backdoor attack methods show superiority to baselines in many aspects.All the code and data of this paper can be obtained at https:// github.com/thunlp/StyleAttack. Fanchao Qi, Yangyi Chen, Xurui Zhang, Mukai Li, Zhiyuan Liu 0001, Maosong Sun 0001 |
EMNLP (1) | 2 |
| 2019 | Evaluation of NUMA-Aware Scheduling in Warehouse-Scale ClustersabstractNon-uniform memory access (NUMA) has been extensively studied at the machine level but few studies have examined NUMA optimizations at the cluster level. This paper introduces a holistic NUMA-aware scheduling policy that combines both machine-level and cluster-level NUMA-aware optimizations. We evaluate our holistic NUMA-aware scheduling policy on Google's production cluster trace with a cluster scheduling simulator that measures the impact of NUMAaware scheduling under two scheduling algorithms, Best Fit and Enhanced PVM (E-PVM). While our results highlight that a holistic NUMA-aware scheduling policy substantially increases the proportion of NUMA-fit tasks by 22.0% and 25.6% for both the Best Fit and E-PVM scheduling algorithms, respectively, there is a non-trivial tradeoff between cluster job packing efficiency and NUMA-fitness for the E-PVM algorithm under certain circumstances. Richard Wu, Xiangling Kong, Yangyi Chen, Rohit Jnagal, Robert Hagmann |
CLOUD | 4 |
| 2015 | Perplexed Messengers from the Cloud: Automated Security Analysis of Push-Messaging IntegrationsabstractIn this paper, we report the first large-scale, systematic study on the security qualities of emerging push-messaging services, focusing on their app-side service integrations. We identified a set of security properties different push-messaging services (e.g., Google Cloud Messaging) need to have, and automatically verified them in different integrations using a new technique, called Seminal. Seminal is designed to extract semantic information from a service's sample code, and leverage the information to evaluate the security qualities of the service's SDKs and its integrations within different apps. Using this tool, we studied 30 leading services around the world, and scanned 35,173 apps. Our findings are astonishing: over 20% apps in Google Play and 50% apps in mainstream Chinese app markets are riddled with security-critical loopholes, putting a huge amount of sensitive user data at risk. Also, our research brought to light new types of security flaws never known before, which can be exploited to cause serious confusions among popular apps and services (e.g., Facebook, Skype, Yelp, Baidu Push). Taking advantage of such confusions, the adversary can post his content to the victim's apps in the name of trusted parties and intercept her private messages. The study highlights the serious challenges in securing push-messaging services and an urgent need for improving their security qualities. Yangyi Chen, Tongxin Li 0002, XiaoFeng Wang 0001, Kai Chen 0012, Xinhui Han |
CCS | 1 |
| 2015 | Elite: Automatic Orchestration of Elastic Detection Services to Secure Cloud Hosting
Yangyi Chen, Vincent Bindschaedler, XiaoFeng Wang 0001, Stefan Berger, Dimitrios E. Pendarakis |
RAID | 1 |
| 2014 | Thwarting Wi-Fi Side-Channel Analysis through Traffic DemultiplexingabstractSide-channel information leaks have been reported in various online applications, especially, in wireless local area networks (WLANs) due to the shared-medium nature of wireless links and the ease of eavesdropping. Even when Wi-Fi traffic is encrypted, its characteristics are identifiable, which can be used to infer sensitive user activities and data. Existing countermeasures do not offer effective and efficient protection: packet padding and traffic morphing often bring in substantial communication overheads; attempts to anonymize user identifiers are vulnerable to the analysis based upon traffic statistics. In this paper, we present a new technique, called traffic demultiplexing, which offers effective protection against Wi-Fi traffic analysis without incurring noticeable overhead and performance degradation. Our approach utilizes Media Access Control (MAC) layer virtualization and packet scheduling over multiple virtual MAC interfaces to shape the traffic on each virtual MAC interface, so as to hide the original traffic characteristics. Traffic demultiplexing operates at the MAC layer and is transparent to users and other protocol stacks. We implemented our technique over Multiband Atheros Driver for Wi-Fi (MadWifi) and evaluated it in real WLAN environments. Our experimental study demonstrates that traffic demultiplexing is effective and efficient in defending against traffic analysis attacks and easy to deploy. Fan Zhang 0019, Wenbo He 0003, Yangyi Chen, Zhou Li 0001, XiaoFeng Wang 0001, Shuo Chen 0001, Xue (Steve) Liu |
IEEE Trans. Wirel. Commun. | 3 |
| 2013 | InteGuard: Toward Automatic Protection of Third-Party Web Service Integrations
Luyi Xing, Yangyi Chen, XiaoFeng Wang 0001, Shuo Chen 0001 |
NDSS | 2 |
| 2012 | Large-Scale Privacy-Preserving Mapping of Human Genomic Sequences on Hybrid Clouds
Yangyi Chen, XiaoFeng Wang 0001, Haixu Tang |
NDSS | 1 |
| 2011 | Sedic: privacy-aware data intensive computing on hybrid cloudsabstractThe emergence of cost-effective cloud services offers organizations great opportunity to reduce their cost and increase productivity. This development, however, is hampered by privacy concerns: a significant amount of organizational computing workload at least partially involves sensitive data and therefore cannot be directly outsourced to the public cloud. The scale of these computing tasks also renders existing secure outsourcing techniques less applicable. A natural solution is to split a task, keeping the computation on the private data within an organization's private cloud while moving the rest to the public commercial cloud. However, this hybrid cloud computing is not supported by today's data-intensive computing frameworks, MapReduce in particular, which forces the users to manually split their computing tasks. In this paper, we present a suite of new techniques that make such privacy-aware data-intensive computing possible. Our system, called Sedic, leverages the special features of MapReduce to automatically partition a computing job according to the security levels of the data it works on, and arrange the computation across a hybrid cloud. Specifically, we modified MapReduce's distributed file system to strategically replicate data, moving sanitized data blocks to the public cloud. Over this data placement, map tasks are carefully scheduled to outsource as much workload to the public cloud as possible, given sensitive data always stay on the private cloud. To minimize inter-cloud communication, our approach also automatically analyzes and transforms the reduction structure of a submitted job to aggregate the map outcomes within the public cloud before sending the result back to the private cloud for the final reduction. This also allows the users to interact with our system in the same way they work with MapReduce, and directly run their legacy code in our framework. We implemented Sedic on Hadoop and evaluated it using both real and synthesized computing jobs on a large-scale cloud test-bed. The study shows that our techniques effectively protect sensitive user data, offload a large amount of computation to the public cloud and also fully preserve the scalability of MapReduce. Kehuan Zhang, Xiao-yong Zhou, Yangyi Chen, XiaoFeng Wang 0001, Yaoping Ruan |
CCS | 3 |
| 2011 | To Release or Not to Release: Evaluating Information Leaks in Aggregate Human-Genome Data
Xiao-yong Zhou, Yong Fuga Li, Yangyi Chen, Haixu Tang, XiaoFeng Wang 0001 |
ESORICS | 4 |