VLDB 2026 Research / reviewers in the wild / expert
Yaxin Li 0001
dblp:143/0251-1
· DBLP profile ↗
14ranked-venue papers
3as first author
12since 2021 · last 2024
0000-0002-6227-7844ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 10 · 2 first-author · 9 since 2021Databases, data management, data science and information retrieval · 7 · 1 first-author · 6 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 2 first-author · 3 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Exploring Memorization in Fine-tuned Language ModelsabstractShenglai Zeng, Yaxin Li, Jie Ren, Yiding Liu, Han Xu, Pengfei He, Yue Xing, Shuaiqiang Wang, Jiliang Tang, Dawei Yin. Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2024. Shenglai Zeng, Yaxin Li 0001, Jie Ren 0019, Han Xu 0002, Yue Xing 0002, Shuaiqiang Wang, Jiliang Tang, Dawei Yin 0001 |
ACL (1) | 2 |
| 2024 | Unveiling and Mitigating Memorization in Text-to-Image Diffusion Models Through Cross Attention
Jie Ren 0019, Yaxin Li 0001, Shenglai Zeng, Han Xu 0002, Lingjuan Lyu, Yue Xing 0002, Jiliang Tang |
ECCV (77) | 2 |
| 2024 | Neural Style Protection: Counteracting Unauthorized Neural Style TransferabstractArbitrary neural style transfer is an advanced AI technique that can effectively synthesize pictures with an artistic style similar to a given source picture. However, if such an AI technique is leveraged by unauthorized individuals, it can significantly infringe upon the copyright of the source picture’s owner. In this paper, we study how to protect the artistic style of source images against unauthorized style transfer by adding imperceptible perturbations to the original source pictures. In particular, our goal is to disable the neural style transfer models from producing high-quality pictures with a similar style to the source pictures with slight manipulating the source images. We introduce Neural Style Protection (NSP), which provides protection for source images against various neural style transfer models. Through extensive experiments, we demonstrate the effectiveness and generalizability of the proposed style protection algorithm across numerous style transfer models using varied metrics. Yaxin Li 0001, Jie Ren 0019, Han Xu 0002, Hui Liu 0031 |
WACV | 1 |
| 2023 | A Mix-up Strategy to Enhance Adversarial Training with Imbalanced DataabstractAdversarial training has been proven to be one of the most effective techniques to defend against adversarial examples. The majority of existing adversarial training methods assume that every class in the training data is equally distributed. However, in reality, some classes often have a large number of training data while others only have a very limited amount. Recent studies have shown that the performance of adversarial training will degrade drastically if the training data is imbalanced. In this paper, we propose a simple yet effective framework to enhance the robustness of DNN models under imbalanced scenarios. Our framework, Imb-Mix, first augments the training dataset by generating multiple adversarial examples for samples in the minority classes. This is done by first adding random noise to the original adversarial examples created by one specific adversarial attack method. It then constructs Mixup-mimic mixed examples upon the augmented dataset used by adversarial training. In addition, we theoretically prove the regularization effect of our Mixup-mimic mixed examples generation technique in Imb-Mix. Extensive experiments on various imbalanced datasets verify the effectiveness of the proposed framework. Wentao Wang 0006, Harry Shomer, Yaxin Li 0001, Jiangtao Huang, Hui Liu 0031 |
CIKM | 4 |
| 2023 | Trustworthy AI: A Computational PerspectiveabstractIn the past few decades, artificial intelligence (AI) technology has experienced swift developments, changing everyone’s daily life and profoundly altering the course of human society. The intention behind developing AI was and is to benefit humans by reducing labor, increasing everyday conveniences, and promoting social good. However, recent research and AI applications indicate that AI can cause unintentional harm to humans by, for example, making unreliable decisions in safety-critical scenarios or undermining fairness by inadvertently discriminating against a group or groups. Consequently, trustworthy AI has recently garnered increased attention regarding the need to avoid the adverse effects that AI could bring to people, so people can fully trust and live in harmony with AI technologies. A tremendous amount of research on trustworthy AI has been conducted and witnessed in recent years. In this survey, we present a comprehensive appraisal of trustworthy AI from a computational perspective to help readers understand the latest technologies for achieving trustworthy AI. Trustworthy AI is a large and complex subject, involving various dimensions. In this work, we focus on six of the most crucial dimensions in achieving trustworthy AI: (i) Safety & Robustness, (ii) Nondiscrimination & Fairness, (iii) Explainability, (iv) Privacy, (v) Accountability & Auditability, and (vi) Environmental Well-being. For each dimension, we review the recent related technologies according to a taxonomy and summarize their applications in real-world systems. We also discuss the accordant and conflicting interactions among different dimensions and discuss potential aspects for trustworthy AI to investigate in the future. Yiqi Wang 0001, Wenqi Fan, Yaxin Li 0001, Shaili Jain, Yunhao Liu 0001, Anil K. Jain 0001, Jiliang Tang |
ACM Trans. Intell. Syst. Technol. | 5 |
| 2022 | Imbalanced Adversarial Training with ReweightingabstractAdversarial training has been empirically proven to be one of the most effective and reliable defense methods against adversarial attacks. However, the majority of existing studies are focused on balanced datasets, where each class has a similar amount of training examples. Research on adversarial training with imbalanced training datasets is rather limited. As the initial effort to investigate this problem, we reveal the facts that adversarially trained models present two distinguished behaviors from naturally trained models in imbalanced datasets: (1) Compared to natural training, adversarially trained models can suffer much worse performance on under-represented classes, when the training dataset is extremely imbalanced. (2) Traditional reweighting strategies which assign large weights to underrepresented classes will drastically hurt the model’s performance on well-represented classes. In this paper, to further understand our observations, we theoretically show that the poor data separability is one key reason causing this strong tension between under-represented and well-represented classes. Motivated by this finding, we propose the Separable Reweighted Adversarial Training (SRAT) framework to facilitate adversarial training under imbalanced scenarios, by learning more separable features for different classes. Extensive experiments on various datasets verify the effectiveness of the proposed framework. Wentao Wang 0006, Han Xu 0002, Yaxin Li 0001, Bhavani Thuraisingham, Jiliang Tang |
ICDM | 4 |
| 2022 | Towards Practical Robustness Evaluation and Robustness EnhancingabstractDeep neural networks (DNNs) have been widely applied on various machine learning tasks and have achieved significant performance across multiple domains. However, it well known that DNNs suffer from severe adversarial vulnerability. Thus it raises great concernswhen DNNs are adopted to safety-critical tasks. These concerns boost the area of adversarial machine learning, which mainly fo-cus on evaluating model robustness through adversarial attacks and gain reliable model performance through adversarial defenses.Among this board topic, my research work focus on a practical perspective. Specifically, there are three subtopics: (1) Enhancing robustness performance for adversarial learning from feature perspective. (2) Standardized and Reliable evaluation for black box attacks under different settings. (3) Building user-friendly adversarial learning tools to help evaluate model robustness. In this research statement, we will mainly focus on these three topics and we will take this opportunity to share our contribution to the relate problems. Yaxin Li 0001 |
WSDM | 1 |
| 2021 | DeepRobust: a Platform for Adversarial Attacks and DefensesabstractDeepRobust is a PyTorch platform for generating adversarial examples and building robust machine learning models for different data domains. Users can easily evaluate the attack performance against different defense methods with DeepRobust and get performance analyzing visualization. In this paper, we introduce the functions of DeepRobust with detailed instructions. We believe that DeepRobust is a useful tool to measure deep learning model robustness and to find the suitable countermeasures against adversarial attacks. The platform is kept updated and can be found at https://github.com/DSE-MSU/DeepRobust. More details of instruction can be found in the documentation at https://deeprobust.readthedocs.io/en/latest/. Yaxin Li 0001, Wei Jin 0009, Han Xu 0002, Jiliang Tang |
AAAI | 1 |
| 2021 | Elastic Graph Neural NetworksabstractWhile many existing graph neural networks (GNNs) have been proven to perform $\ell_2$-based graph smoothing that enforces smoothness globally, in this work we aim to further enhance the local smoothness adaptivity of GNNs via $\ell_1$-based graph smoothing. As a result, we introduce a family of GNNs (Elastic GNNs) based on $\ell_1$ and $\ell_2$-based graph smoothing. In particular, we propose a novel and general message passing scheme into GNNs. This message passing algorithm is not only friendly to back-propagation training but also achieves the desired smoothing properties with a theoretical convergence guarantee. Experiments on semi-supervised learning tasks demonstrate that the proposed Elastic GNNs obtain better adaptivity on benchmark datasets and are significantly robust to graph adversarial attacks. The implementation of Elastic GNNs is available at \url{https://github.com/lxiaorui/ElasticGNN}. Wei Jin 0009, Yao Ma 0001, Yaxin Li 0001, Hua Liu 0008, Yiqi Wang 0001, Ming Yan 0006, Jiliang Tang |
ICML | 4 |
| 2021 | To be Robust or to be Fair: Towards Fairness in Adversarial TrainingabstractAdversarial training algorithms have been proved to be reliable to improve machine learning models’ robustness against adversarial examples. However, we find that adversarial training algorithms tend to introduce severe disparity of accuracy and robustness between different groups of data. For instance, PGD adversarially trained ResNet18 model on CIFAR-10 has 93% clean accuracy and 67% PGD l_infty-8 adversarial accuracy on the class ”automobile” but only 65% and 17% on class ”cat”. This phenomenon happens in balanced datasets and does not exist in naturally trained models when only using clean samples. In this work, we empirically and theoretically show that this phenomenon can generally happen under adversarial training algorithms which minimize DNN models’ robust errors. Motivated by these findings, we propose a Fair-Robust-Learning (FRL) framework to mitigate this unfairness problem when doing adversarial defenses and experimental results validate the effectiveness of FRL. Han Xu 0002, Yaxin Li 0001, Anil K. Jain 0001, Jiliang Tang |
ICML | 3 |
| 2021 | Adversarial Robustness in Deep Learning: From Practices to TheoriesabstractDeep neural networks (DNNs) have achieved unprecedented accomplishments in various machine learning tasks. However, recent studies demonstrate that DNNs are extremely vulnerable to adversarial examples. They are manually synthesized input samples which look benign but can severely fool the prediction of DNN models. For machine learning practitioners who are applying DNNs, understanding the behavior of adversarial examples will not only help them improve the safety of their models, but also can help them have deeper insights into the working mechanism of the DNNs. In this tutorial, we provide a comprehensive overview on the recent advances of adversarial examples and their countermeasures, from both practical and theoretical perspectives. From the practical aspect, we give a detailed introduction of the popular algorithms to generate adversarial examples under different adversary's goals. We also discuss how the defending strategies are developed to resist these attacks, and how new attacks come out to break these defenses. From the theoretical aspect, we discuss a series of intrinsic behaviors of robust DNNs which are different from traditional DNNs, especially about their optimization and generalization properties. Finally, we introduce DeepRobust, a Pytorch adversarial learning library which aims to build a comprehensive and easy-to-use platform to foster this research field. Via our tutorial, the audience can grip the main ideas of adversarial attacks and defenses and gain a deep insight of DNN's robustness. The tutorial official website is at https://sites.google.com/view/kdd21-tutorial-adv-robust. Han Xu 0002, Yaxin Li 0001, Wentao Wang 0006, Jiliang Tang |
KDD | 2 |
| 2021 | Yet Meta Learning Can Adapt Fast, it Can Also Break EasilyabstractMeta learning algorithms have been widely applied in many tasks for efficient learning, such as few-shot image classification and fast reinforcement learning. During meta training, the meta learner develops a common learning strategy, or experience, from a variety of learning tasks. Therefore, during meta test, the meta learner can use the learned strategy to quickly adapt to new tasks even with a few training samples. However, there is still a dark side about meta learning in terms of reliability and robustness. In particular, is meta learning vulnerable to adversarial attacks? In other words, would a well-trained meta learner utilize its learned experience to build wrong or likely useless knowledge, if an adversary unnoticeably manipulates the given training set? Without the understanding of this problem, it is extremely risky to apply meta learning in safety-critical applications. Thus, in this paper, we perform the initial study about adversarial attacks on meta learning under the few-shot classification problem. In particular, we formally define key elements of adversarial attacks unique to meta learning and propose the first attacking algorithm against meta learning under various settings. We evaluate the effectiveness of the proposed attacking strategy as well as the robustness of several representative meta learning algorithms. Experimental results demonstrate that the proposed attacking strategy can easily break the meta learner and meta learning is vulnerable to adversarial attacks. Han Xu 0002, Yaxin Li 0001, Hui Liu 0031, Jiliang Tang |
SDM | 2 |
| 2020 | Graphical Evolutionary Game Theoretic Analysis of Super Users in Information DiffusionabstractIn social networks, to better understand the avalanche of information flow over networks and to investigate its impact on economy and our social life, it is of crucial importance to model and analyze the information diffusion process. To address the existence of "super users" in social networks who have higher social status and potentially larger influence, we propose a graphical evolutionary game theoretic framework to investigate the impact of such super users and their strategy update rules on information propagation. We analyze the evolutionary dynamics and the stable states. Simulation results are consistent with our theoretical analysis, and demonstrate that strategy update rule is the critical factor that influences the stable states of the information diffusion process. Yuejiang Li, Yaxin Li 0001, H. Vicky Zhao, Yan Chen 0007 |
ICASSP | 2 |
| 2020 | Adversarial Attacks and Defenses: Frontiers, Advances and PracticeabstractDeep neural networks (DNN) have achieved unprecedented success in numerous machine learning tasks in various domains. However, the existence of adversarial examples leaves us a big hesitation when applying DNN models on safety-critical tasks such as autonomous vehicles and malware detection. These adversarial examples are intentionally crafted instances, either appearing in the train or test phase, which can fool the DNN models to make severe mistakes. Therefore, people are dedicated to devising more robust models to resist adversarial examples, but usually they are broken by new stronger attacks. This arms-race between adversarial attacks and defenses has been drawn increasing attention in recent years. In this tutorial, we provide a comprehensive overview on the frontiers and advances of adversarial attacks and their countermeasures. In particular, we give a detailed introduction of different types of attacks under different scenarios, including evasion and poisoning attacks, white-box and black box attacks. We will also discuss how the defending strategies develop to compete against these attacks, and how new attacks come out to break these defenses. Moreover, we will discuss the story of adversarial attacks and defenses in other data domains, especially in graph structured data. Then, we introduce DeepRobust, a Pytorch adversarial learning library which aims to build a comprehensive and easy-to-use platform to foster this research field. Finally, we summarize the tutorial with discussions on open issues and challenges about adversarial attacks and defenses. Via our tutorial, our audience can grip the main idea and key approaches of the game between adversarial attacks and defenses. Han Xu 0002, Yaxin Li 0001, Wei Jin 0009, Jiliang Tang |
KDD | 2 |