Charles Fleming

dblp:18/3177 · DBLP profile ↗
← Back
16ranked-venue papers
1as first author
12since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 9 · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 3 since 2021Security and privacy · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 Agents Under Siege: Breaking Pragmatic Multi-Agent LLM Systems with Optimized Prompt Attacks
abstract
Most discussions about Large Language Model (LLM) safety have focused on single-agent settings but multi-agent LLM systems now create novel adversarial risks because their behavior depends on communication between agents and decentralized reasoning. In this work, we innovatively focus on attacking pragmatic systems that have constrains such as limited token bandwidth, latency between message delivery, and defense mechanisms. We design a \textit{permutation-invariant adversarial attack} that optimizes prompt distribution across latency and bandwidth-constraint network topologies to bypass distributed safety mechanisms within the system. Formulating the attack path as a problem of \textit{maximum-flow minimum-cost}, coupled with the novel \textit{Permutation-Invariant Evasion Loss (PIEL)}, we leverage {graph-based optimization} to maximize attack success rate while minimizing detection risk. Evaluating across models including \texttt{Llama}, \texttt{Mistral}, \texttt{Gemma}, \texttt{DeepSeek} and other variants on various datasets like \texttt{JailBreakBench} and \texttt{AdversarialBench}, our method outperforms conventional attacks by up to 7\times, exposing critical vulnerabilities in multi-agent systems. Moreover, we demonstrate that existing defenses, including variants of \texttt{Llama-Guard} and \texttt{PromptGuard}, fail to prohibit our attack, emphasizing the urgent need for multi-agent specific safety mechanisms.
Rana Muhammad Shahroz, Zhen Tan 0001, Sukwon Yun, Charles Fleming, Tianlong Chen 0001
ACL (1)4
2025 Enhancing Dance-to-Music Generation via Negative Conditioning Latent Diffusion Model
abstract
Conditional diffusion models have gained increasing attention since their impressive results for cross-modal synthesis, where the strong alignment between conditioning input and generated output can be achieved by training a time-conditioned U-Net augmented with cross-attention mechanism. In this paper, we focus on the problem of generating music synchronized with rhythmic visual cues of the given dance video. Considering that bi-directional guidance is more beneficial for training a diffusion model, we propose to enhance the quality of generated music and its synchronization with dance videos by adopting both positive rhythmic information and negative ones (PN-Diffusion) as conditions, where a dual diffusion and reverse processes is devised. Specifically, to train a sequential multi-modal U-Net structure, PN-Diffusion consists of a noise prediction objective for positive conditioning and an additional noise prediction objective for negative conditioning. To accurately define and select both positive and negative conditioning, we ingeniously utilize temporal correlations in dance videos, capturing positive and negative rhythmic cues by playing them forward and backward, respectively. Through subjective and objective evaluations of input-output correspondence in terms of dance-music beat alignment and the quality of generated music, experimental results on the AIST++ and TikTok dance video datasets demonstrate that our model outperforms SOTA dance-to-music generation models.
Changchang Sun, Gaowen Liu, Charles Fleming, Yan Yan 0002
CVPR3
2025 Targeted Forgetting of Image Subgroups in CLIP Models
abstract
Foundation models (FMs) such as CLIP have demonstrated impressive zero-shot performance across various tasks by leveraging large-scale, unsupervised pre-training. However, they often inherit harmful or unwanted knowledge from noisy internet-sourced datasets, compromising their reliability in real-world applications. Existing model unlearning methods either rely on access to pre-trained datasets or focus on coarse-grained unlearning (e.g., entire classes), leaving a critical gap for fine-grained unlearning. In this paper, we address the challenging scenario of selectively forgetting specific portions of knowledge within a class—without access to pre-trained data—while preserving the model’s overall performance. We propose a novel three-stage approach that progressively unlearns targeted knowledge while mitigating over-forgetting. It consists of (1) a forgetting stage to fine-tune the CLIP on samples to be forgotten, (2) a reminding stage to restore performance on retained samples, and (3) a restoring stage to recover zero-shot capabilities using model souping. Additionally, we introduce knowledge distillation to handle the distribution disparity between forgetting/retaining samples and unseen pre-trained data. Extensive experiments on CIFAR-10, ImageNet-1K, and style datasets demonstrate that our approach effectively unlearns specific subgroups while maintaining strong zero-shot performance on semantically similar subgroups and other categories, significantly outperforming baseline unlearning methods, which lose effectiveness under the CLIP unlearning setting.
Zeliang Zhang 0001, Gaowen Liu, Charles Fleming, Ramana Rao Kompella, Chenliang Xu
CVPR3
2025 Towards Training Robustness Against Dynamic Errors in Quantum Machine Learning
abstract
Quantum machine learning, crucial in the noisy intermediate-scale quantum (NISQ) era, confronts challenges in error mitigation. Current noise-aware training (NAT) methods often assume static error rates in quantum neural networks (QNNs), overlooking the dynamic nature of quantum noise. Our work highlights how error rates fluctuate over time and across different qubits, affecting QNN performance even when overall error rates are similar. We introduce a novel NAT strategy that dynamically adjusts to standard and fatal error conditions, incorporating a low-complexity search method to identify fatal errors during optimization. This strategy significantly improves robustness, maintaining competitive performance with leading NAT methods across varying error scenarios.
Shijin Duan, Gaowen Liu, Charles Fleming, Ramana Rao Kompella, Xiaolin Xu 0001, Shaolei Ren
DAC3
2025 Retracing the Past: LLMs Emit Training Data When They Get Lost
abstract
The memorization of training data in large language models (LLMs) poses significant privacy and copyright concerns.Existing data extraction methods, particularly heuristic-based divergence attacks, often exhibit limited success and offer limited insight into the fundamental drivers of memorization leakage.This paper introduces Confusion-Inducing Attacks (CIA), a principled framework for extracting memorized data by systematically maximizing model uncertainty.We empirically demonstrate that the emission of memorized text during divergence is preceded by a sustained spike in token-level prediction entropy.CIA leverages this insight by optimizing input snippets to deliberately induce this consecutive highentropy state.For aligned LLMs, we further propose mismatched Supervised Fine-tuning (SFT) to simultaneously weaken their alignment and induce targeted confusion, thereby increasing susceptibility to our attacks.Experiments on various unaligned and aligned LLMs demonstrate that our proposed attacks outperform existing baselines in extracting verbatim and near-verbatim training data without requiring prior knowledge of the training data.Our findings highlight persistent memorization risks across various LLMs and offer a more systematic method for assessing these vulnerabilities.
Myeongseob Ko, Nikhil Reddy Billa, Adam Nguyen, Charles Fleming, Ming Jin 0002, Ruoxi Jia 0001
EMNLP4
2025 Just Enough Shifts: Mitigating Over-Refusal in Aligned Language Models with Targeted Representation Fine-Tuning
abstract
Safety alignment is crucial for Large Language Models (LLMs) to resist malicious instructions but often results in over-refusals, where benign prompts are unnecessarily rejected, impairing user experience and model utility. To this end, we introduce ACTOR (Activation-Based Training for Over-Refusal Reduction), a robust and compute- and-data efficient training framework that mini- mizes over-refusals by utilizing internal activation patterns from diverse queries. ACTOR precisely identifies and adjusts the activation components that trigger refusals, providing stronger control over the refusal mechanism. By fine-tuning only a single model layer, ACTOR effectively reduces over-refusals across multiple benchmarks while maintaining the model’s ability to handle harmful queries and preserving overall utility.
Mahavir Dabas, Si Chen 0008, Charles Fleming, Ming Jin 0002, Ruoxi Jia 0001
ICML3
2025 On the Vulnerability of Applying Retrieval-Augmented Generation within Knowledge-Intensive Application Domains
abstract
Retrieval-Augmented Generation (RAG) has been empirically shown to enhance the performance of large language models (LLMs) in knowledge-intensive domains such as healthcare, finance, and legal contexts. Given a query, RAG retrieves relevant documents from a corpus and integrates them into the LLMs’ generation process. In this study, we investigate the adversarial robustness of RAG, focusing specifically on examining the retrieval system. First, across 225 different setup combinations of corpus, retriever, query, and targeted information, we show that retrieval systems are vulnerable to universal poisoning attacks in medical Q&A. In such attacks, adversaries generate poisoned documents containing a broad spectrum of targeted information, such as personally identifiable information. When these poisoned documents are inserted into a corpus, they can be accurately retrieved by any users, as long as attacker-specified queries are used. To understand this vulnerability, we discovered that the deviation from the query’s embedding to that of the poisoned document tends to follow a pattern in which the high similarity between the poisoned document and the query is retained, thereby enabling precise retrieval. Based on these findings, we develop a new detection-based defense to ensure the safe use of RAG. Through extensive experiments spanning various Q&A domains, we observed that our proposed method consistently achieves excellent detection rates in nearly all cases.
Xun Xian, Ganghua Wang, Xuan Bi, Rui Zhang 0028, Jayanth Srinivasa, Ashish Kundu, Charles Fleming, Mingyi Hong 0001, Jie Ding 0002
ICML7
2025 Probing Hidden Knowledge Holes in Unlearned LLMs
abstract
Machine unlearning has emerged as a prevalent technical solution for selectively removing unwanted knowledge absorbed during pre-training, without requiring full retraining. While recent unlearning techniques can effectively remove undesirable content without severely compromising performance on standard benchmarks, we find that they may inadvertently create ``knowledge holes''---unintended losses of benign knowledge that standard benchmarks fail to capture. To probe where unlearned models reveal knowledge holes, we propose a test case generation framework that explores both immediate neighbors of unlearned content and broader areas of potential failures. Our evaluation demonstrates significant hidden costs of unlearning: up to 98.7\% of the test cases yield irrelevant or nonsensical responses from unlearned models, despite being answerable by the pretrained model. These findings necessitate rethinking the conventional approach to evaluating knowledge preservation in unlearning, moving beyond standard, static benchmarks.
Myeongseob Ko, Hoang Anh Just, Charles Fleming, Ming Jin 0002, Ruoxi Jia 0001
NeurIPS3
2025 SOFT: Selective Data Obfuscation for Protecting LLM Fine-tuning against Membership Inference Attacks
Kaiyuan Zhang 0002, Siyuan Cheng 0005, Hanxi Guo, Yuetian Chen, Zian Su, Shengwei An, Yuntao Du 0002, Charles Fleming, Ashish Kundu, Xiangyu Zhang 0001, Ninghui Li 0001
USENIX Security Symposium8
2024 Self-adapting Large Visual-Language Models to Edge Devices Across Visual Modalities
Kaiwen Cai, Zhekai Duan, Gaowen Liu, Charles Fleming, Xiaoxuan Lu 0001
ECCV (28)4
2023 Story-based authentication for mobile devices using semantically-linked images
Ilesanmi Olade, Hai-Ning Liang, Charles Fleming
Int. J. Hum. Comput. Stud.3
2022 Ulixes: Facial Recognition Privacy with Adversarial Machine Learning
abstract
Abstract Facial recognition tools are becoming exceptionally accurate in identifying people from images. However, this comes at the cost of privacy for users of online services with photo management (e.g. social media platforms). Particularly troubling is the ability to leverage unsupervised learning to recognize faces even when the user has not labeled their images. In this paper we propose Ulixes, a strategy to generate visually non-invasive facial noise masks that yield adversarial examples, preventing the formation of identifiable user clusters in the embedding space of facial encoders. This is applicable even when a user is unmasked and labeled images are available online. We demonstrate the effectiveness of Ulixes by showing that various classification and clustering methods cannot reliably label the adversarial examples we generate. We also study the effects of Ulixes in various black-box settings and compare it to the current state of the art in adversarial machine learning. Finally, we challenge the effectiveness of Ulixes against adversarially trained models and show that it is robust to countermeasures.
Thomas Cilloni, Wei Wang 0042, Charles Walter, Charles Fleming
Proc. Priv. Enhancing Technol.4
2020 Personal Mobile devices at work: factors affecting the adoption of security mechanisms
Hai-Ning Liang, Charles Fleming, Ka Lok Man
Multim. Tools Appl.2
2020 Design and Evaluation of Visualization Techniques of Off-Screen and Occluded Targets in Virtual Reality Environments
abstract
This research explores the design and evaluation of visualization techniques of targets that reside outside of users' view and/or are occluded by other elements within a virtual reality environment (VE). We first compare four techniques (3DWedge, 3DArrow, 3DMinimap, and Radar) that use different types of visual elements to provide direction and distance information of targets. To give structure to their evaluation, we also develop a framework of four tasks (one for direction and three for distance) and their assessment criteria. The results of the first study show that 3DWedge is the best-performing and most usable technique. However, all techniques, including 3DWedge, have poor performance in dense scenarios with a large number of targets. To improve support in dense scenarios, a fifth technique, 3DWedge+, is developed by using 3DWedge as its foundation and including additional visual elements that are derived from the other three techniques which are shown to be useful. A second study is conducted to evaluate the performance of 3DWedge+ in relation to the other techniques. The results show that both 3DWedge and 3DWedge+ are significantly better in distinguishing user-to-target distance and that 3DWedge+ is particularly suitable for dense scenarios. Based on these results, we provide a set of recommendations for the design of visualization techniques of off-screen and occluded targets in 3D VE.
Difeng Yu, Hai-Ning Liang, Kaixuan Fan, Charles Fleming, Konstantinos Papangelis
IEEE Trans. Vis. Comput. Graph.5
2017 Privacy-Preserving Human Activity Recognition from Extreme Low Resolution
abstract
Privacy protection from surreptitious video recordings is an important societal challenge. We desire a computer vision system (e.g., a robot) that can recognize human activities and assist our daily life, yet ensure that it is not recording video that may invade our privacy. This paper presents a fundamental approach to address such contradicting objectives: human activity recognition while only using extreme low-resolution (e.g., 16x12) anonymized videos. We introduce the paradigm of inverse super resolution (ISR), the concept of learning the optimal set of image transformations to generate multiple low-resolution (LR) training videos from a single video. Our ISR learns different types of sub-pixel transformations optimized for the activity classification, allowing the classifier to best take advantage of existing high-resolution videos (e.g., YouTube videos) by creating multiple LR training videos tailored for the problem. We experimentally confirm that the paradigm of inverse super resolution is able to benefit activity recognition from extreme low-resolution videos.
Michael S. Ryoo, Brandon Rothrock, Charles Fleming, Hyun Jong Yang
AAAI3
2012 Data Tethers: Preventing information leakage by enforcing environmental data access policies
abstract
Protecting data from accidental loss or theft is crucial in today's world of mobile computing. Data Tethers provides flexible environmental policies, which can be attached to data, specifying security requirements that must be met before accessing that data. Data Tethers uses fine-grain data flow tracking to maintain these policies on derivative data. This is implemented by dynamic recompilation of legacy applications without the need to recompile from source. We demonstrate the system's feasibility with microbenchmarks that show individual component performance and benchmarks of real user applications like word processors and spreadsheets.
Charles Fleming, Peter Peterson, Erik Kline, Peter L. Reiher
ICC1