Haibo Jin

dblp:134/7465 · DBLP profile ↗
← Back
30ranked-venue papers
15as first author
29since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 14 · 8 first-author · 13 since 2021Graphics, computer vision, multimedia, augmented reality and games · 12 · 7 first-author · 11 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 2 first-author · 7 since 2021Databases, data management, data science and information retrieval · 4 · 2 first-author · 4 since 2021Security and privacy · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 Learning to Conceal Risk: Controllable Multi-turn Red Teaming for LLMs in the Financial Domain
abstract
Large Language Models (LLMs) are increasingly deployed in finance, where unsafe behavior can lead to serious compliance and regulatory risks.However, most red-teaming research focuses on overtly harmful content and overlooks attacks that appear legitimate on the surface yet induce compliance-violating responses.We address this gap by introducing a controllable black-box multi-turn riskconcealed red-teaming framework (CoRT) that progressively conceals surface-level risk while exploiting non-compliant behaviors.CoRT contains two key components: (i) a Risk Concealment Attacker (RCA) that generates multi-turn prompts via iterative refinement, and (ii) a Risk Concealment Controller (RCC) that predicts a turn-level Risk Concealment Score (RCS) to steer RCA's follow-up style.We also build a domain-specific benchmark, FIN-Bench, with 522 instructions spanning six financial risk categories.Experiments on nine widely used LLMs show that CoRT (RCA) achieves 93.19% average attack success rate (ASR), and CoRT (RCA+RCC) further improves the average ASR to 95.00%.
Haibo Jin, Wenbin Zhang 0002, Haohan Wang, Jun Zhuang 0004
ACL (1)2
2026 Modeling of High-Precision Synchronous ADC and Cooperative Calibration of Revenue Metering Chain for Gateway Electricity Meters
Yuanrui Hong, Fubin Liu, Zhaoqiang Ge, Haibo Jin
KSEM (2)4
2026 Research on Adaptive High-Precision Gateway Energy Metering Technology for Transient Power Flow Based on Artificial Intelligence
Fubin Liu, Yuanrui Hong, Zhaoqiang Ge, Haibo Jin
KSEM (2)4
2026 Causal reliability-aware meta-learning for industrial fault diagnosis
Haibo Jin, Baokai Zhang
Eng. Appl. Artif. Intell.1
2026 Geometric Deviation: An Information-Theoretic Health Indicator for Cross-Condition Prognostics
Haibo Jin, Baokai Zhang
IEEE Signal Process. Lett.1
2026 LLM-Driven Medical Report Generation via Communication-Efficient Heterogeneous Federated Learning
abstract
Large Language Models (LLMs) have demonstrated significant potential in Medical Report Generation (MRG), yet their development requires large amounts of medical image-report pairs, which are commonly scattered across multiple centers. Centralizing these data is exceptionally challenging due to privacy regulations, thereby impeding model development and broader adoption of LLM-driven MRG models. To address this challenge, we present FedMRG, the first framework that leverages Federated Learning (FL) to enable privacy-preserving, multi-center development of LLM-driven MRG models, specifically designed to overcome the critical challenge of communication-efficient LLM training under multi-modal data heterogeneity. To start with, our framework tackles the fundamental challenge of communication overhead in federated LLM tuning by employing low-rank factorization to efficiently decompose parameter updates, significantly reducing gradient transmission costs and making LLM-driven MRG feasible in bandwidth-constrained FL settings. Furthermore, we observed the dual heterogeneity in MRG under the FL scenario: varying image characteristics across medical centers, as well as diverse reporting styles and terminology preferences. To address the data heterogeneity, we further enhance FedMRG with (1) client-aware contrastive learning in the MRG encoder, coupled with diagnosis-driven prompts, which capture both globally generalizable and locally distinctive features while maintaining diagnostic accuracy; and (2) a dual-adapter mutual boosting mechanism in the MRG decoder that harmonizes generic and specialized adapters to address variations in reporting styles and terminology. Through extensive evaluation of our established FL-MRG benchmark, we demonstrate the generalizability and adaptability of FedMRG, underscoring its potential in harnessing multi-center data and generating clinically accurate reports while maintaining communication efficiency.
Haoxuan Che, Haibo Jin, Zhengrui Guo, Yi Lin 0009, Cheng Jin 0003, Hao Chen 0011
IEEE Trans. Medical Imaging2
2026 Multimodal arbitrary-scale super-resolution via dynamic gated fusion and low-resolution semantic guidance
Haibo Jin, Yuxuan Deng
Vis. Comput.1
2025 Revolve: Optimizing AI Systems by Tracking Response Evolution in Textual Optimization
abstract
Recent advancements in large language models (LLMs) have significantly enhanced the ability of LLM-based systems to perform complex tasks through natural language processing and tool interaction. However, optimizing these LLM-based systems for specific tasks remains challenging, often requiring manual interventions like prompt engineering and hyperparameter tuning. Existing automatic optimization methods, such as textual feedback-based techniques (*e.g.*, TextGrad), tend to focus on immediate feedback, analogous to using immediate derivatives in traditional numerical gradient descent. However, relying solely on such feedback can be limited when the adjustments made in response to this feedback are either too small or fluctuate irregularly, potentially slowing down or even stalling the optimization process. In this paper, we introduce $\textbf{REVOLVE}$, an optimization method that tracks how $\textbf{R}$esponses $\textbf{EVOLVE}$ across iterations in LLM systems. By focusing on the evolution of responses over time, REVOLVE enables more stable and effective optimization by making thoughtful, progressive adjustments at each step. Experiments across three tasks demonstrate the adaptability and efficiency of our proposal. Beyond its practical contributions, REVOLVE highlights a promising direction, where the rich knowledge from established optimization principles can be leveraged to enhance LLM systems, which paves the way for further advancements in this hybrid domain. Code is available at: https://llm-revolve.netlify.app.
Peiyan Zhang, Haibo Jin, Leyang Hu, Xinnuo Li, Liying Kang, Yangqiu Song, Haohan Wang
ICML2
2025 Evaluating the Inductive Abilities of Large Language Models: Why Chain-of-Thought Reasoning Sometimes Hurts More Than Helps
abstract
Large Language Models (LLMs) have shown remarkable progress across domains, yet their ability to perform inductive reasoning—inferring latent rules from sparse examples—remains limited. It is often assumed that chain-of-thought (CoT) prompting, as used in Large Reasoning Models (LRMs), enhances such reasoning. We investigate this assumption with creating four controlled, diagnostic game-based tasks—chess, Texas Hold’em, dice games, and blackjack—with hidden human-defined rules. We find that CoT reasoning can degrade inductive performance, with LRMs often underperforming their non-reasoning counterparts. To explain this, we present a theoretical framework that reveals how reasoning steps can amplify error through three failure modes: incorrect sub-task decomposition, incorrect sub-task solving, and incorrect final answer summarization. Based on our theoretical and empirical analysis, we introduce structured interventions that adapt CoT generation according to our identified failure types. These interventions improve inductive accuracy without retraining. Our findings suggest that effective (CoT) reasoning depends not only on taking more steps but also on ensuring those steps are well-structured.
Haibo Jin, Peiyan Zhang, Haohan Wang
NeurIPS1
2025 Joint optimization of spare parts inventory and maintenance for wind turbine systems
Haibo Jin, Jiayu Bi, Mengjiao Li
Expert Syst. Appl.1
2025 Image Steganography With Dual Strategies: Defense and Attack
abstract
This letter addresses the limitations of adversarial steganography, such as inadequate cross-model generalization capability and suboptimal stego image quality, by proposing a dual-strategy steganography framework that combines passive defense with active attack. The passive defense module utilizes a generative adversarial network, wherein the generator adopts a dual-stream U-Net architecture to analyze the cover image alongside its edge information. It incorporates a Convolutional Block Attention Module to dynamically assign feature weights, resulting in an optimized cover image for information embedding. The active attack module identifies and interferes with the essential shared features that different steganalysis models depend on for discrimination, utilizing neuron attribution results. This approach optimizes the embedding scheme in a specific manner, leading various steganalysis models to arrive at erroneous conclusions. The dynamic adjustment of loss weight progressively enhances the performance of both modules, leading to overall optimization. Experimental results indicate that the proposed framework successfully achieves a balance between high visual quality and strong cross-model generalization capability.
Zhecong Ren, Haibo Jin, Haicheng Qu
IEEE Signal Process. Lett.4
2025 Fight Perturbations With Perturbations: Defending Adversarial Attacks via Neuron Influence
abstract
The vulnerabilities of deep learning models towards adversarial attacks have attracted increasing attention, especially when models are deployed in security-critical domains. Numerous defense methods, including reactive and proactive ones, have been proposed for model robustness improvement. Reactive defenses, such as conducting transformations to remove perturbations, usually fail to handle large perturbations. The proactive defenses that involve retraining, suffer from the attack dependency and high computation cost. In this article, we consider defense methods from the general effect of adversarial attacks that take on neurons inside the model. We introduce the concept of neuron influence, which can quantitatively measure neurons’ contribution to correct classification. Then, we observe that almost all attacks fool the model by suppressing neurons with larger influence and enhancing those with smaller influence. Based on this, we proposeNeuron-level Inverse Perturbation(NIP), a novel defense against general adversarial attacks. It calculates neuron influence from benign examples and then modifies input examples by generating inverse perturbations that can in turn strengthen neurons with larger influence and weaken those with smaller influence. Extensive experiments on benchmark datasets and models show that NIP outperforms the state-of-the-art methods in terms of i)effective- it shows better defense success rate ($\sim \!\!\times 1.45$) against 13 adversarial attacks; ii)elastic- it maintains better defense ($\sim \!\!\times 3.4$in the worst case) on large perturbations; iii)efficient- it runs with only$\sim \!\!1/6$time cost; iv)extensible- it can be applied to speaker recognition models and Baidu online image platforms. We further evaluate NIP against potential adaptive attacks and provide interpretable analysis for its effectiveness.
Ruoxi Chen, Haibo Jin, Haibin Zheng, Jinyin Chen, Zhenguang Liu
IEEE Trans. Dependable Secur. Comput.2
2025 FedDAG: Federated Domain Adversarial Generation Toward Generalizable Medical Image Analysis
abstract
Federated domain generalization aims to train a global model from multiple source domains and ensure its generalization ability to unseen target domains. Due to the target domain being with unknown domain shifts, attempting to approximate these gaps by source domains may be the key to improving model generalization capability. Existing works mainly focus on sharing and recombining local domain-specific attributes to increase data diversity and simulate potential domain shifts. However, these methods may be insufficient since only the local attribute recombination can be hard to touch the out-of-distribution of global data. In this paper, we propose a simple-yet-efficient framework named Federated Domain Adversarial Generation (FedDAG). It aims to simulate the domain shift and improve the model generalization by adversarially generating novel domains different from local and global source domains. Specifically, it generates novel-style images by maximizing the instance-level feature discrepancy between original and generated images and trains a generalizable task model by minimizing their feature discrepancy. Further, we observed that FedDAG could cause different performance improvements for local models. It may be due to inherent data isolation and heterogeneity among clients, exacerbating the imbalance in their generalization contributions to the global model. Ignoring this imbalance can lead the global model's generalization ability to be sub-optimal, further limiting the novel domain generation procedure. Thus, to mitigate this imbalance, FedDAG hierarchically aggregates local models at the within-client and across-client levels by using the sharpness concept to evaluate client model generalization contributions. Extensive experiments across four medical benchmarks demonstrate FedDAG's ability to enhance generalization in federated medical scenarios.
Haoxuan Che, Haibo Jin, Yong Xia 0001, Hao Chen 0011
IEEE Trans. Medical Imaging3
2025 Large Language Model With Region-Guided Referring and Grounding for CT Report Generation
abstract
Computed tomography (CT) report generation is crucial to assist radiologists in interpreting CT volumes, which can be time-consuming and labor-intensive. Existing methods primarily only consider the global features of the entire volume, making it struggle to focus on specific regions and potentially missing abnormalities. To address this issue, we propose Reg2RG, the first region-guided referring and grounding framework for CT report generation, which enhances diagnostic performance by focusing on anatomical regions within the volume. Specifically, we utilize masks from a universal segmentation module to capture local features for each referring region. A local feature decoupling (LFD) strategy is proposed to preserve the local high-resolution details with little computational overhead. Then the local features are integrated with global features to capture inter-regional relationships within a cohesive context. Moreover, we propose a novel region-report alignment (RRA) training strategy. It leverages the recognition of referring regions to guide the generation of region-specific reports, enhancing the model's referring and grounding capabilities while also improving the report's interpretability. A large language model (LLM) is further employed as the language decoder to generate reports from integrated visual features, facilitating region-level comprehension. Extensive experiments on two large-scale chest CT-report datasets demonstrate the superiority of our method, which outperforms several state-of-the-art methods in terms of both natural language generation and clinical efficacy metrics while preserving promising interpretability. The code is available at https://github.com/zhi-xuan-chen/Reg2RG.
Zhi-Xuan Chen, Yequan Bie, Haibo Jin, Hao Chen 0011
IEEE Trans. Medical Imaging3
2025 A Chain of Diagnosis Framework for Accurate and Explainable Radiology Report Generation
abstract
Despite the progress of radiology report generation (RRG), existing works face two challenges: 1) The performances in clinical efficacy are unsatisfactory, especially for lesion attributes description; 2) the generated text lacks explainability, making it difficult for radiologists to trust the results. To address the challenges, we focus on a trustworthy RRG model, which not only generates accurate descriptions of abnormalities, but also provides basis of its predictions. To this end, we propose a framework named chain of diagnosis (CoD), which maintains a chain of diagnostic process for clinically accurate and explainable RRG. It first generates question-answer (QA) pairs via diagnostic conversation to extract key findings, then prompts a large language model with QA diagnoses for accurate generation. To enhance explainability, a diagnosis grounding module is designed to match QA diagnoses and generated sentences, where the diagnoses act as a reference. Moreover, a lesion grounding module is designed to locate abnormalities in the image, further improving the working efficiency of radiologists. To facilitate label-efficient training, we propose an omni-supervised learning strategy with clinical consistency to leverage various types of annotations from different datasets. Our efforts lead to 1) an omni-labeled RRG dataset with QA pairs and lesion boxes; 2) a evaluation tool for assessing the accuracy of reports in describing lesion location and severity; 3) extensive experiments to demonstrate the effectiveness of CoD, where it outperforms both specialist and generalist models consistently on two RRG benchmarks and shows promising explainability by accurately grounding generated sentences to QA diagnoses and images.
Haibo Jin, Haoxuan Che, Sunan He, Hao Chen 0011
IEEE Trans. Medical Imaging1
2024 PromptMRG: Diagnosis-Driven Prompts for Medical Report Generation
abstract
Automatic medical report generation (MRG) is of great research value as it has the potential to relieve radiologists from the heavy burden of report writing. Despite recent advancements, accurate MRG remains challenging due to the need for precise clinical understanding and disease identification. Moreover, the imbalanced distribution of diseases makes the challenge even more pronounced, as rare diseases are underrepresented in training data, making their diagnosis unreliable. To address these challenges, we propose diagnosis-driven prompts for medical report generation (PromptMRG), a novel framework that aims to improve the diagnostic accuracy of MRG with the guidance of diagnosis-aware prompts. Specifically, PromptMRG is based on encoder-decoder architecture with an extra disease classification branch. When generating reports, the diagnostic results from the classification branch are converted into token prompts to explicitly guide the generation process. To further improve the diagnostic accuracy, we design cross-modal feature enhancement, which retrieves similar reports from the database to assist the diagnosis of a query image by leveraging the knowledge from a pre-trained CLIP. Moreover, the disease imbalanced issue is addressed by applying an adaptive logit-adjusted loss to the classification branch based on the individual learning status of each disease, which overcomes the barrier of text decoder's inability to manipulate disease distributions. Experiments on two MRG benchmarks show the effectiveness of the proposed method, where it obtains state-of-the-art clinical efficacy performance on both datasets.
Haibo Jin, Haoxuan Che, Yi Lin 0009, Hao Chen 0011
AAAI1
2024 EditShield: Protecting Unauthorized Image Editing by Instruction-Guided Diffusion Models
Ruoxi Chen, Haibo Jin, Yixin Liu 0002, Jinyin Chen, Haohan Wang, Lichao Sun 0001
ECCV (63)2
2024 CatchBackdoor: Backdoor Detection via Critical Trojan Neural Path Fuzzing
Haibo Jin, Ruoxi Chen, Jinyin Chen, Haibin Zheng, Haohan Wang
ECCV (47)1
2024 Jailbreaking Large Language Models Against Moderation Guardrails via Cipher Characters
abstract
Large Language Models (LLMs) are typically harmless but remain vulnerable to carefully crafted prompts known as ``jailbreaks'', which can bypass protective measures and induce harmful behavior. Recent advancements in LLMs have incorporated moderation guardrails that can filter outputs, which trigger processing errors for certain malicious questions. Existing red-teaming benchmarks often neglect to include questions that trigger moderation guardrails, making it difficult to evaluate jailbreak effectiveness. To address this issue, we introduce JAMBench, a harmful behavior benchmark designed to trigger and evaluate moderation guardrails. JAMBench involves 160 manually crafted instructions covering four major risk categories at multiple severity levels. Furthermore, we propose a jailbreak method, JAM (Jailbreak Against Moderation), designed to attack moderation guardrails using jailbreak prefixes to bypass input-level filters and a fine-tuned shadow model functionally equivalent to the guardrail model to generate cipher characters to bypass output-level filters. Our extensive experiments on four LLMs demonstrate that JAM achieves higher jailbreak success ($\sim$ $\times$ 19.88) and lower filtered-out rates ($\sim$ $\times$ 1/6) than baselines.
Haibo Jin, Andy Zhou, Joe D. Menke, Haohan Wang
NeurIPS1
2024 AdvCheck: Characterizing adversarial examples via local gradient checking
Ruoxi Chen, Haibo Jin, Jinyin Chen, Haibin Zheng, Shilian Zheng, Xiaoniu Yang, Xing Yang 0004
Comput. Secur.2
2024 Rethinking Self-Training for Semi-Supervised Landmark Detection: A Selection-Free Approach
abstract
Self-training is a simple yet effective method for semi-supervised learning, during which pseudo-label selection plays an important role for handling confirmation bias. Despite its popularity, applying self-training to landmark detection faces three problems: 1) The selected confident pseudo-labels often contain data bias, which may hurt model performance; 2) It is not easy to decide a proper threshold for sample selection as the localization task can be sensitive to noisy pseudo-labels; 3) coordinate regression does not output confidence, making selection-based self-training infeasible. To address the above issues, we propose Self-Training for Landmark Detection (STLD), a method that does not require explicit pseudo-label selection. Instead, STLD constructs a task curriculum to deal with confirmation bias, which progressively transitions from more confident to less confident tasks over the rounds of self-training. Pseudo pretraining and shrink regression are two essential components for such a curriculum, where the former is the first task of the curriculum for providing a better model initialization and the latter is further added in the later rounds to directly leverage the pseudo-labels in a coarse-to-fine manner. Experiments on three facial and one medical landmark detection benchmark show that STLD outperforms the existing methods consistently in both semi- and omni-supervised settings. The code is available at https://github.com/jhb86253817/STLD.
Haibo Jin, Haoxuan Che, Hao Chen 0011
IEEE Trans. Image Process.1
2023 CertPri: Certifiable Prioritization for Deep Neural Networks via Movement Cost in Feature Space
abstract
Deep neural networks (DNNs) have demonstrated their outperformance in various software systems, but also exhibit misbehavior and even result in irreversible disasters. Therefore, it is crucial to identify the misbehavior of DNN-based software and improve DNNs' quality. Test input prioritization is one of the most appealing ways to guarantee DNNs' quality, which prioritizes test inputs so that more bug-revealing inputs can be identified earlier with limited time and manual labeling efforts. However, the existing prioritization methods are still limited from three aspects: certifiability, effectiveness, and generalizability. To overcome the challenges, we propose CertPri, a test input prioritization technique designed based on a movement cost perspective of test inputs in DNNs' feature space. CertPri differs from previous works in three key aspects: (1) certifiable - it provides a formal robustness guarantee for the movement cost; (2) effective - it leverages formally guaranteed movement costs to identify malicious bug-revealing inputs; and (3) generic - it can be applied to various tasks, data, models, and scenarios. Extensive evaluations across 2 tasks (i.e., classification and regression), 6 data forms, 4 model structures, and 2 scenarios (i.e., white-box and black-box) demonstrate CertPri's superior performance. For instance, it significantly improves 53.97 % prioritization effectiveness on average compared with baselines. Its robustness and generalizability are 1.41~2.00 times and 1.33~3.39 times that of baselines on average, respectively. The code of CertPri is open-sourced at https://github.com/haibinzheng/CertPri.
Haibin Zheng, Jinyin Chen, Haibo Jin
ASE3
2023 Towards Generalizable Diabetic Retinopathy Grading in Unseen Domains
Haoxuan Che, Yuhan Cheng, Haibo Jin, Hao Chen 0011
MICCAI (5)3
2023 Unsupervised Domain Adaptation for Anatomical Landmark Detection
Haibo Jin, Haoxuan Che, Hao Chen 0011
MICCAI (1)1
2023 Excitement surfeited turns to errors: Deep learning testing framework based on excitable neurons
Haibo Jin, Ruoxi Chen, Haibin Zheng, Jinyin Chen, Yao Cheng 0002, Yue Yu 0001, Tieming Chen, Xianglong Liu 0001
Inf. Sci.1
2022 RePFormer: Refinement Pyramid Transformer for Robust Facial Landmark Detection
abstract
This paper presents a Refinement Pyramid Transformer (RePFormer) for robust facial landmark detection. Most facial landmark detectors focus on learning representative image features. However, these CNN-based feature representations are not robust enough to handle complex real-world scenarios due to ignoring the internal structure of landmarks, as well as the relations between landmarks and context. In this work, we formulate the facial landmark detection task as refining landmark queries along pyramid memories. Specifically, a pyramid transformer head (PTH) is introduced to build both homologous relations among landmarks and heterologous relations between landmarks and cross-scale contexts. Besides, a dynamic landmark refinement (DLR) module is designed to decompose the landmark regression into an end-to-end refinement procedure, where the dynamically aggregated queries are transformed to residual coordinates predictions. Extensive experimental results on four facial landmark detection benchmarks and their various subsets demonstrate the superior performance and high robustness of our framework.
Jinpeng Li 0004, Haibo Jin, Shengcai Liao, Ling Shao 0001, Pheng-Ann Heng
IJCAI2
2022 Learning Robust Representation for Joint Grading of Ophthalmic Diseases via Adaptive Curriculum and Feature Disentanglement
Haoxuan Che, Haibo Jin, Hao Chen 0011
MICCAI (3)2
2022 ROBY: Evaluating the adversarial robustness of a deep model by its decision boundaries
Haibo Jin, Jinyin Chen, Haibin Zheng, Zhen Wang 0004, Jun Xiao 0001, Shanqing Yu, Zhaoyan Ming
Inf. Sci.1
2021 Pixel-in-Pixel Net: Towards Efficient Facial Landmark Detection in the Wild
Haibo Jin, Shengcai Liao, Ling Shao 0001
Int. J. Comput. Vis.1
2017 Deep person re-identification with improved embedding and efficient training
abstract
Person re-identification task has been greatly boosted by deep convolutional neural networks (CNNs) in recent years. The core of which is to enlarge the inter-class distinction as well as reduce the intra-class variance. However, to achieve this, existing deep models prefer to adopt image pairs or triplets to form verification loss, which is inefficient and unstable since the number of training pairs or triplets grows rapidly as the number of training data grows. Moreover, their performance is limited since they ignore the fact that different dimension of embedding may play different importance. In this paper, we propose to employ identification loss with center loss to train a deep model for person re-identification. The training process is efficient since it does not require image pairs or triplets for training while the inter-class distinction and intra-class variance are well handled. To boost the performance, a new feature reweighting (FRW) layer is designed to explicitly emphasize the importance of each embedding dimension, thus leading to an improved embedding. Experiments1on several benchmark datasets have shown the superiority of our method over the state-of-the-art alternatives on both accuracy and speed.
Haibo Jin, Xiaobo Wang 0001, Shengcai Liao, Stan Z. Li
IJCB1