Yujun Zhou 0002

dblp:162/3265-2 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
10since 2021 · last 2026
0000-0003-1376-5187ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 10 · 2 first-author · 10 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Your Reasoning Model is Secretly a Reward Model - Optimization-Free Verification from Experience
abstract
Zhenwen Liang, Ruosen Li, Yujun Zhou, Linfeng Song, Dian Yu, Xinya Du, Haitao Mi, Dong Yu. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026.
Zhenwen Liang, Ruosen Li, Yujun Zhou 0002, Linfeng Song, Dian Yu 0001, Xinya Du, Haitao Mi, Dong Yu 0001
ACL (1)3
2025 Artificial Intelligence in Spectroscopy: Advancing Chemistry from Prediction To Generation and Beyond
abstract
The rapid advent of machine learning (ML) and artificial intelligence (AI) has catalyzed major transformations in chemistry, yet the application of these methods to spectroscopic and spectrometric data—termed Spectroscopy Machine Learning (SpectraML)—remains relatively underexplored. Modern spectroscopic techniques (MS, NMR, IR, Raman, UV-Vis) generate an ever-growing volume of high-dimensional data, creating a pressing need for automated and intelligent analysis beyond traditional expert-based workflows. In this survey, we provide a unified review of SpectraML, systematically examining state-of-the-art approaches for both forward tasks (molecule-to-spectrum prediction) and inverse tasks (spectrum-to-molecule inference). We trace the historical evolution of ML in spectroscopy—from early pattern recognition to the latest foundation models capable of advanced reasoning—and offer a taxonomy of representative neural architectures, including graph-based and transformer-based methods. Addressing key challenges such as data quality, multimodal integration, and computational scalability, we highlight emerging directions like synthetic data generation, large-scale pretraining, and few- or zero-shot learning. To foster reproducible research, we release an open-source repository containing curated datasets and code implementations. Our survey serves as a roadmap for researchers, guiding advancements at the intersection of spectroscopy and AI.
Kehan Guo, Yili Shen, Gisela Abigail Gonzalez-Montiel, Yue Huang 0001, Yujun Zhou 0002, Mihir Surve, Zhichun Guo, Nitesh V. Chawla, Olaf Wiest, Xiangliang Zhang 0001
IJCAI5
2025 ChemOrch: Empowering LLMs with Chemical Intelligence via Groundbreaking Synthetic Instructions
abstract
Empowering large language models (LLMs) with chemical intelligence remains a challenge due to the scarcity of high-quality, domain-specific instruction-response datasets and the misalignment of existing synthetic data generation pipelines with the inherently hierarchical and rule-governed structure of chemical information. To address this, we propose ChemOrch, a framework that synthesizes chemically grounded instruction–response pairs through a two-stage process: task-controlled instruction generation and tool-aware response construction. ChemOrch enables controllable diversity and levels of difficulty for the generated tasks and ensures response precision through tool planning \& distillation, and tool-based self-repair mechanisms. The effectiveness of ChemOrch is evaluated based on: 1) the \textbf{high quality} of generated instruction data, demonstrating superior diversity and strong alignment with chemical constraints; 2) the \textbf{dynamic generation of evaluation tasks} that more effectively reveal LLM weaknesses in chemistry; and 3) the significant \textbf{improvement of LLM chemistry capabilities} when the generated instruction data are used for fine-tuning. Our work thus represents a critical step toward scalable and verifiable chemical intelligence in LLMs. The code is available at \url{https://anonymous.4open.science/r/ChemOrch-854A}.
Yue Huang 0001, Zhengzhe Jiang, Kehan Guo, Haomin Zhuang, Yujun Zhou 0002, Zhengqing Yuan, Jules Schleinitz, Yanbo Wang 0005, Mihir Surve, Nitesh V. Chawla, Olaf Wiest, Xiangliang Zhang 0001
NeurIPS6
2025 AdaReasoner: Adaptive Reasoning Enables More Flexible Thinking
abstract
LLMs often need effective configurations, like temperature and reasoning steps, to handle tasks requiring sophisticated reasoning and problem-solving, ranging from joke generation to mathematical reasoning. Existing prompting approaches usually adopt general-purpose, fixed configurations that work “well enough” across tasks but seldom achieve task-specific optimality. To address this gap, we introduce AdaReasoner, an LLM-agnostic plugin designed for any LLM to automate adaptive reasoning configurations for tasks requiring different types of thinking. AdaReasoner is trained using a reinforcement learning (RL) framework, combining a factorized action space with a targeted exploration strategy, along with a pretrained reward model to optimize the policy model for reasoning configurations with only a few-shot guide. AdaReasoner is backed by theoretical guarantees and experiments of fast convergence and a sublinear policy gap. Across six different LLMs and a variety of reasoning tasks, it consistently outperforms standard baselines, preserves out-of-distribution robustness, and yield gains on knowledge-intensive tasks through tailored prompts.
Xiangqi Wang, Yue Huang 0001, Yanbo Wang 0005, Kehan Guo, Yujun Zhou 0002, Xiangliang Zhang 0001
NeurIPS6
2024 Defending Jailbreak Prompts via In-Context Adversarial Game
abstract
Large Language Models (LLMs) demonstrate remarkable capabilities across diverse applications.However, concerns regarding their security, particularly the vulnerability to jailbreak attacks, persist.Drawing inspiration from adversarial training in deep learning and LLM agent learning processes, we introduce the In-Context Adversarial Game (ICAG) for defending against jailbreaks without the need for fine-tuning.ICAG leverages agent learning to conduct an adversarial game, aiming to dynamically extend knowledge to defend against jailbreaks.Unlike traditional methods that rely on static datasets, ICAG employs an iterative process to enhance both the defense and attack agents.This continuous improvement process strengthens defenses against newly generated jailbreak prompts.Our empirical studies affirm ICAG's efficacy, where LLMs safeguarded by ICAG exhibit significantly reduced jailbreak success rates across various attack scenarios.Moreover, ICAG demonstrates remarkable transferability to other LLMs, indicating its potential as a versatile defense mechanism.The code is available at https://github.com/YujunZhou/ In-Context-Adversarial-Game.28 1 82 8 8 28 3 31 9 2 1 92 82 3 31 2 98 !" "1 3"1 28 1 82 8 8 28 3 31 # $ % # &81 !" ' " 2("2 1 % 28 1 82 8 8 28 3 31 01 23 56 781 92 81 2 8 6 9 2 1 92 82 3 31 2 98 !" "1 3"1 28 1 82 8 8 28 3 31 # $ % # &81 !" ' " 2("2 1 % "&&2 !" 8 28 1 8 8 28 "&&2 !" ) "1 ! 8 2 8 28 1 8 ! 8 2) 9 *+8& 91 ,8 2 *+8& 91 ) 2'2 ! 8 2 8 28% 2 8 28 3 31 28 1 82 8 2 8 28 3 31 01 23 56 781 92 81 2 8 6 "5-.2! 2 2 "/-*+8& *+8&2 .2! 22 .2! 2 2 001 *+8& 001 .2! 2 2 * 1 81 001 (a) Self Reminder 01 23 56 781 92 81 2 8 6 28 1 82 8 8 28 3 31 9 2 1 92 82 3 31 2 98 !" "1 3"1 28 1 82 8 8 28 3 31 # $ % # &81 !" ' " 2("2 1 % 28 1 82 8 8 28 3 31 01 23 56 781 92 81 2 8 6 9 2 1 92 82 3 31 2 98 !" "1 3"1 28 1 82 8 8 28 3 31 # $ % # &81 !" ' " 2("2 1 % "&&2 !" 8 28 1 8 8 28 "&&2 !" ) "1 ! 8 2 8 28 1 8 ! 8 2) 9 *+8& 91 ,8 2 *+8& 91 ) 2'2 ! 8 2 8 28% 2 8 28 3 31 28 1 82 8 2 8 28 3 31 01 23 56 781 92 81 2 8 6 "5-.2! 2 2 "/-*+8& *+8&2 .2! 22 .2! 2 2 001 *+8& 001 .2! 2 2 * 1 81 001 (b) Our proposed In-Context Adversarial Game 0 1 2 :. 1 9 2 15 9 5 5 4-2 1*"1.9 "1 7 2 1!9 9 4 0 1 2 *"1.9 "1 7 : 2 1!9 9 4 0 1 2 : 7 :.7 18 4-9 9 -9 7 :C., 49 -99 1 =2 9 7 ::.7 49 9 ; 9 45 4 9 A49 5 :.B A49 5 :C.7 * 7 :2 1 2 1 7 :.7 18 4-9 9 -9 ,!! 57 7 :
Yujun Zhou 0002, Yufei Han 0001, Haomin Zhuang, Kehan Guo, Zhenwen Liang, Hongyan Bao, Xiangliang Zhang 0001
EMNLP1
2024 Attack-free Evaluating and Enhancing Adversarial Robustness on Categorical Data
abstract
Research on adversarial robustness has predominantly focused on continuous inputs, leaving categorical inputs, especially tabular attributes, less examined. To echo this challenge, our work aims to evaluate and enhance the robustness of classification over categorical attributes against adversarial perturbations through efficient attack-free approaches. We propose a robustness evaluation metric named Integrated Gradient-Smoothed Gradient (IGSG). It is designed to evaluate the attributional sensitivity of each feature and the decision boundary of the classifier, two aspects that significantly influence adversarial risk, according to our theoretical analysis. Leveraging this metric, we develop an IGSG-based regularization to reduce adversarial risk by suppressing the sensitivity of categorical attributes. We conduct extensive empirical studies over categorical datasets of various application domains. The results affirm the efficacy of both IGSG and IGSG-based regularization. Notably, IGSG-based regularization surpasses the state-of-the-art robust training methods by a margin of approximately 0.4% to 12.2% on average in terms of adversarial accuracy, especially on high-dimension datasets. The code is available at https://github.com/YujunZhou/IGSG.
Yujun Zhou 0002, Yufei Han 0001, Haomin Zhuang, Hongyan Bao, Xiangliang Zhang 0001
ICML1
2024 Can LLMs Solve Molecule Puzzles? A Multimodal Benchmark for Molecular Structure Elucidation
abstract
Large Language Models (LLMs) have shown significant problem-solving capabilities across predictive and generative tasks in chemistry. However, their proficiency in multi-step chemical reasoning remains underexplored. We introduce a new challenge: molecular structure elucidation, which involves deducing a molecule’s structure from various types of spectral data. Solving such a molecular puzzle, akin to solving crossword puzzles, poses reasoning challenges that require integrating clues from diverse sources and engaging in iterative hypothesis testing. To address this challenging problem with LLMs, we present \textbf{MolPuzzle}, a benchmark comprising 217 instances of structure elucidation, which feature over 23,000 QA samples presented in a sequential puzzle-solving process, involving three interlinked sub-tasks: molecule understanding, spectrum interpretation, and molecule construction. Our evaluation of 12 LLMs reveals that the best-performing LLM, GPT-4o, performs significantly worse than humans, with only a small portion (1.4\%) of its answers exactly matching the ground truth. However, it performs nearly perfectly in the first subtask of molecule understanding, achieving accuracy close to 100\%. This discrepancy highlights the potential of developing advanced LLMs with improved chemical reasoning capabilities in the other two sub-tasks. Our MolPuzzle dataset and evaluation code are available at this \href{https://github.com/KehanGuo2/MolPuzzle}{link}.
Kehan Guo, Bozhao Nan, Yujun Zhou 0002, Taicheng Guo, Zhichun Guo, Mihir Surve, Zhenwen Liang, Nitesh V. Chawla, Olaf Wiest, Xiangliang Zhang 0001
NeurIPS3
2023 Towards Efficient and Domain-Agnostic Evasion Attack with High-Dimensional Categorical Inputs
abstract
Our work targets at searching feasible adversarial perturbation to attack a classifier with high-dimensional categorical inputs in a domain-agnostic setting. This is intrinsically a NP-hard knapsack problem where the exploration space becomes explosively larger as the feature dimension increases. Without the help of domain knowledge, solving this problem via heuristic method, such as Branch-and-Bound, suffers from exponential complexity, yet can bring arbitrarily bad attack results. We address the challenge via the lens of multi-armed bandit based combinatorial search. Our proposed method, namely FEAT, treats modifying each categorical feature as pulling an arm in multi-armed bandit programming. Our objective is to achieve highly efficient and effective attack using an Orthogonal Matching Pursuit (OMP)-enhanced Upper Confidence Bound (UCB) exploration strategy. Our theoretical analysis bounding the regret gap of FEAT guarantees its practical attack performance. In empirical analysis, we compare FEAT with other state-of-the-art domain-agnostic attack methods over various real-world categorical data sets of different applications. Substantial experimental observations confirm the expected efficiency and attack effectiveness of FEAT applied in different application scenarios. Our work further hints the applicability of FEAT for assessing the adversarial vulnerability of classification systems with high-dimensional categorical inputs.
Hongyan Bao, Yufei Han 0001, Yujun Zhou 0002, Xin Gao 0001, Xiangliang Zhang 0001
AAAI3
2022 AdvCat: Domain-Agnostic Robustness Assessment for Cybersecurity-Critical Applications with Categorical Inputs
abstract
Machine Learning-as-a-Service systems (MLaaS) have been largely developed for cybersecurity-critical applications, such as detecting network intrusions and fake news campaigns. Despite effectiveness, their robustness against adversarial attacks is one of the key trust concerns for MLaaS deployment. We are thus motivated to assess the adversarial robustness of the Machine Learning models residing at the core of these securitycritical applications with categorical inputs. Previous research efforts on accessing model robustness against manipulation of categorical inputs are specific to use cases and heavily depend on domain knowledge, or require white-box access to the target ML model. Such limitations prevent the robustness assessment from being as a domain-agnostic service provided to various real-world applications. We propose a provably optimal yet computationally highly efficient adversarial robustness assessment protocol for a wide band of ML-driven cybersecurity-critical applications. We demonstrate the use of the domain-agnostic robustness assessment method with substantial experimental study on fake news detection and intrusion detection problems.
Helene Orsini, Hongyan Bao, Yujun Zhou 0002, Xiangrui Xu 0001, Yufei Han 0001, Longyang Yi, Wei Wang 0012, Xin Gao 0001, Xiangliang Zhang 0001
IEEE Big Data3
2022 Towards Understanding the Robustness Against Evasion Attack on Categorical Data
Hongyan Bao, Yufei Han 0001, Yujun Zhou 0002, Xiangliang Zhang 0001
ICLR3