VLDB 2026 Research / reviewers in the wild / expert
Du Su
dblp:164/8060
· DBLP profile ↗
13ranked-venue papers
3as first author
12since 2021 · last 2026
0000-0002-6767-6019ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 10 · 2 first-author · 9 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AuditAgent: LLM Agent for Risks Auditing in Recommender SystemsabstractAuditing recommendation systems has attracted growing attention due to increasing concerns over filter bubbles, unfairness, and data misuse. A common approach is sock-puppet auditing, where autonomous agents interact with platforms to reveal risks. However, existing approaches rely on hard-coded agents, lacking adaptability to dynamic GUI layouts and generating behaviors far from those of real users, limiting the comprehensiveness and representativeness of assessment. To address these issues, we introduce AuditAgent, an LLM-powered GUI-agent framework for risk auditing. AuditAgent simulates realistic user preferences and performs adaptive, human-like interactions on recommendation platforms. This design enables more thorough and faithful auditing, providing comprehensive assessments across multiple risk dimensions, including filter bubbles, unfairness, and data misuse. Du Su, Zhenxing Chen, Shilong Zhao, Yuanhao Liu 0001, Fei Sun 0001, Qi Cao 0005, Huawei Shen |
AAAI | 1 |
| 2026 | Safety-Utility Conflicts Are Not Global: Surgical Alignment via Head-Level DiagnosisabstractWang Cai, Yilin Wen, Jinchang Hou, Du Su, Guoqiu Wang, Zhonghou Lv, Chenfu Bao, Yunfang Wu. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Wang Cai, Yilin Wen 0007, Jinchang Hou, Du Su, Guoqiu Wang, Zhonghou Lv, Chenfu Bao, Yunfang Wu |
ACL (1) | 4 |
| 2026 | Token-Level Policy Optimization: Linking Group-Level Rewards to Token-Level Aggregation via sequence-level likelihoodabstractXingyu Lin, Yilin Wen, Du Su, En Wang, Wenbin Liu, Zhonghou Lv, Jinchang Hou, Chenfu Bao. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Yilin Wen 0007, Du Su, En Wang, Zhonghou Lv, Jinchang Hou, Chenfu Bao |
ACL (1) | 3 |
| 2026 | BaseCal: Unsupervised Confidence Calibration via Base Model SignalsabstractHexiang Tan, Wanli Yang, Junwei Zhang, Xin Chen, Rui Tang, Du Su, Jingang Wang, Yuanzhuo Wang, Fei Sun, Xueqi Cheng. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Hexiang Tan, Du Su, Jingang Wang, Yuanzhuo Wang, Fei Sun 0001, Xueqi Cheng 0001 |
ACL (1) | 6 |
| 2026 | Rethinking Implicit Hate Speech Detection: Focusing on Latent Hate Components via Dual-Process ArgumentationabstractImplicit hate speech often hides harmful intent behind innocuous wording, metaphors, or hostile tone, making it difficult for detectors that rely on surface cues. We observe that large language models (LLMs) frequently exhibit pseudo-reasoning that shows over-sensitivity to spurious cues while missing the latent semantic units that actually realize hateful intent. We call these units Latent Hate Components (LHCs) and argue they should be the anchors of inference. We propose DuPL, a Dual-Process argumentation framework that centers detection on LHCs. DuPL separates (i) Mining of LHCs via a high-recall Critical Miner and a Confusion Judge that early-exits on clear cases, from (ii) Deliberation of LHCs via component-wise argumentation and a final Integrative Decision. Across IHC, SBIC, and ToxiGen, DuPL consistently outperforms prompt-learning baselines, improving accuracy by +8.36, +4.93, and +3.78 percentage points and macro-F1 by +7.18, +5.00, and +3.99 percentage points, respectively. DuPL also lowers both false positive rate and false negative rate in most settings, indicating balanced mitigation of the two failure modes common in LLM detectors. By explicitly mining and deliberating over LHCs, DuPL turns opaque, uncontrolled reasoning into structured argumentation, yielding more accurate and interpretable decisions for web moderation. Shiqi Sun 0003, Du Su, Wei Chen 0034, Xueqi Cheng 0001 |
WWW | 2 |
| 2026 | Interaction-level Membership Inference Attack for Recommender Systems via Cluster-based User Modeling
Danyang Zong, Kaike Zhang, Qi Cao 0005, Du Su, Fei Sun 0001 |
WWW | 4 |
| 2026 | The answer lies within: Detecting Trojans from DNNs' inherent characteristics
Xuchao Liu, Qi Cao 0005, Kaike Zhang, Du Su, Huawei Shen |
Neural Networks | 4 |
| 2025 | The 1st Workshop on LLM Agents for Social SimulationabstractSocial simulation has long played a crucial role in exploring the mechanisms underlying human behavior and societal structures. Traditional social simulation relies on rule-based or statistical models, which makes it difficult to capture the complexity and variability of the real world. With the emergence and rapid development of large language model (LLM), new frontiers have been opened toward leveraging LLMs as agent to model human behavior and interactions. This cutting-edge direction has gained significant attention and demonstrated promising results, not only advancing research across a wide range of social science disciplines, but also enabling practical applications in role-playing scenarios. However, this field still faces multiple challenges, such as capturing real-world social phenomena, eliminating bias or ethical considerations, and ensuring usability and reliability. This workshop on LLM Agent for Social Simulation (LASS) aims to bring together researchers and practitioners from diverse backgrounds to foster interdisciplinary collaboration, address key challenges, explore new technologies, and chart promising future directions in this rapidly evolving field. Yige Yuan, Junkai Zhou, Bingbing Xu 0001, Liang Pang 0001, Du Su, An Zhang 0003, Teng Xiao, Fengli Xu, Zhaochun Ren, Xu Chen 0017 |
CIKM | 5 |
| 2025 | Jailbreak LLMs through Internal Stance ManipulationabstractTo confront the ever-evolving safety risks of LLMs, automated jailbreak attacks have proven effective for proactively identifying security vulnerabilities at scale.Existing approaches, including GCG and AutoDAN, generate adversarial prompts for malicious requests that induce LLMs to respond following a fixed affirmative template.However, we observed that the reliance on the fixed output template is ineffective for certain malicious requests, leading to suboptimal jailbreak performance.In this work, we aim to develop a method that generalizes across all malicious requests.Our approach is inspired by the discovery of LLMs' intrinsic safety mechanisms: they tend to exhibit a similar refusal stance across diverse adversarial prompts, resulting in consistent rejections.We propose Stance Manipulation (SM), a novel automated jailbreak approach that generates adversarial prompts to suppress the refusal stance and induce affirmative responses.Our experiments across four mainstream open-source LLMs demonstrate the superiority of SM's performance.Under commonly used setting, SM achieves success rates over 77.1% across all models on Advbench.Specifically, for Llama-2-7b-chat, SM outperforms the best baseline by 25.4%.In further experiments with extended iterations, SM achieves over 92.2% attack success rate across all models.Our code is publicly available at https://github.com/Zed630/Stance- Manipulation Shuangjie Fu, Du Su, Beining Huang, Fei Sun 0001, Jingang Wang, Wei Chen 0013, Huawei Shen, Xueqi Cheng 0001 |
EMNLP | 2 |
| 2025 | Too Consistent to Detect: A Study of Self-Consistent Errors in LLMsabstractHexiang Tan, Fei Sun, Sha Liu, Du Su, Qi Cao, Xin Chen, Jingang Wang, Xunliang Cai, Yuanzhuo Wang, Huawei Shen, Xueqi Cheng. Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing. 2025. Hexiang Tan, Fei Sun 0001, Du Su, Qi Cao 0005, Jingang Wang, Yuanzhuo Wang, Huawei Shen, Xueqi Cheng 0001 |
EMNLP | 4 |
| 2025 | Indirect Online Preference Optimization via Reinforcement LearningabstractHuman preference alignment (HPA) aims to ensure Large Language Models (LLMs) responding appropriately to meet human moral and ethical requirements. Existing methods, such as RLHF and DPO, rely heavily on high-quality human annotation, which restrict the efficiency of iterative online model refinement. To address the inefficiencies of human annotation acquisition, iterated online strategy advocates the use of fine-tuned LLMs to self-generate preference data. However, this approach is prone to distribution bias, because of differences between human and model annotations, as well as modeling errors between simulators and real-world contexts. To mitigate the impact of distribution bias, we adopt the principles of adversarial training, framing a zero-sum two-player game with a protagonist agent and an adversarial agent. With the adversarial agent challenging the alignment of protagonist agent, we continuously refine the protagonist’s performance. By utilizing min-max equilibrium and Nash equilibrium strategies, we propose Indirect Online Preference Optimization (IOPO) mechanism that enables the protagonist agent to converge without bias while maintaining linear computational complexity. Extensive experiments across three real-world datasets demonstrate that IOPO outperforms state-of-the-art alignment methods in both offline and online scenarios, evidenced by standard alignment metrics and human evaluations. This innovation reduces the time required for model iterations from months to one week, alleviates distribution shifts, and significantly cuts annotation costs. En Wang, Du Su, Chenfu Bao, Zhonghou Lv, Funing Yang, Yuanbo Xu |
IJCAI | 3 |
| 2021 | Infer user preferences from aggregate measurements: A novel message passing algorithm for privacy attack
Du Su, Yi Lu 0001 |
Perform. Evaluation | 1 |
| 2020 | Re-identification Attack to Privacy-Preserving Data Analysis with Noisy Sample-MeanabstractIn mining sensitive databases, access to sensitive class attributes of individual records is often prohibited by enforcing field-level security, while only aggregate class-specific statistics are allowed to be released. We consider a common privacy-preserving data analytics scenario where only a noisy sample mean of the class of interest can be queried. Such practice is widely found in medical research and business analytics settings. This paper studies the hazard of re-identification of entire class caused by revealing a noisy sample mean of the class. With a novel formulation of the re-identification attack as a generalized positive-unlabeled learning problem, we prove that the risk function of the re-identification problem is closely related to that of learning with complete data. We demonstrate that with a one-sided noisy sample mean, an effective re-identification attack can be devised with existing PU learning algorithms. We then propose a novel algorithm, growPU, that exploits the unique property of sample mean and consistently outperforms existing PU learning algorithms on the re-identification task. GrowPU achieves re-identification accuracy of 93.6% on the MNIST dataset and 88.1% on an online behavioral dataset with noiseless sample mean. With noise that guarantees 0.01-differential privacy, growPU achieves 91.9% on the MNIST dataset and 84.6% on the online behavioral dataset. Du Su, Hieu Tri Huynh, Ziao Chen, Yi Lu 0001, Wenmiao Lu |
KDD | 1 |