Jianmin Guo

dblp:200/7328 · DBLP profile ↗
← Back
13ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0001-6872-6383ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 4 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 4 since 2021Artificial intelligence and machine learning · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1Security and privacy · 1 · 1 since 2021
YearPublicationVenuePosition
2026 R2BD: A Reconstruction-Based Method for Generalizable and Efficient Detection of Fake Images
abstract
Recently, reconstruction-based methods have gained attention for AIGC image detection. These methods leverage pre-trained diffusion models to reconstruct inputs and measure residuals for distinguishing real from fake images. Their key advantage lies in reducing reliance on dataset-specific artifacts and improving generalization under distribution shifts. However, they are limited by significant inefficiency due to multi-step inversion and reconstruction, and their reliance on diffusion backbones further limits generalization to other generative paradigms such as GANs. In this paper, we propose a novel fake image detection framework, called R$^{2}$BD, built upon two key designs: (1) G-LDM, a unified reconstruction model that simulates the generation behaviors of VAEs, GANs, and diffusion models, thereby broadening the detection scope beyond prior diffusion-only approaches; and (2) a residual bias calculation module that distinguishes real and fake images in a single inference step, which is a significant efficiency improvement over existing methods that typically require 20$+$steps. Extensive experiments on the benchmark from 10 public datasets demonstrate that R$^{2}$BD is over 22× faster than existing reconstruction-based methods while achieving superior detection accuracy. In cross-dataset evaluations, it outperforms state-of-the-art methods by an average of 13.87%, showing strong efficiency and generalization across diverse generative methods. The code and dataset used for evaluation are available athttps://github.com/QingyuLiu/RRBD.
Zhongjie Ba, Jianmin Guo, Zhibo Wang 0001, Kui Ren 0001
IEEE Trans. Dependable Secur. Comput.3
2025 Superpose Task-specific Features for Model Merging
abstract
Model merging enables powerful capabilities in neural networks without requiring additional training.In this paper, we introduce a novel perspective on model merging by leveraging the fundamental mechanisms of neural network representation.Our approach is motivated by the linear representation hypothesis, which states that neural networks encode information through linear combinations of feature vectors.We propose a method that superposes task-specific features from individual models into a merged model.Our approach specifically targets linear transformation matrices, which are crucial for feature activation and extraction in deep networks.By formulating the merging process as a linear system, we can preserve task-specific features from individual models and create merged models that effectively maintain multi-task capabilities compared to existing methods.Extensive experiments across diverse benchmarks and models demonstrate that our method outperforms existing techniques.Code is available at https://github.com/LARS-research/STF. and task vectors (Ilharco et al., 2022;Du et al., 2024).However, these methods primarily focus on parameter-level operations and do not explicitly incorporate the fundamental working mechanisms of neural networks in their design.We argue that a principled approach to model merging should be conditioned on how deep neural networks represent and process information.Therefore, to design our merging method, we draw upon e n c .0 e n c .1 e n c .2 e n c .3 e n c .4 e n c .5 e n c .6 e n c .7 e n c .8 e n c .9 e n c .1 0 e n c .1 1 d e c .0 d e c .1 d e c .2 d e c .3 d e c .4 d e c .5 d e c .6 d e c .7 d e c .8 d e c .9 d e c .1 0 d e c .1 1 Layer 0.0 0.2 0.4 0.6 0.8 1.0 " * 𝐮 !" 𝐯 !" $ % !"&' ( !&' Merged Matrix 𝐌 (c) Identify task-specific features (e) Merging by solving linear system Task 1 Task T
Haiquan Qiu, Jianmin Guo, Quanming Yao
EMNLP4
2025 ToolSafety: A Comprehensive Dataset for Enhancing Safety in LLM-Based Agent Tool Invocations
abstract
LLMs are evolving into assistants that leverage tools, significantly expanding their capabilities but also introducing critical safety risks.Current models exhibit notable vulnerabilities, particularly in maintaining safety during multi-step tool interactions and in scenarios involving indirect harm.This paper introduces ToolSafety, a safety fine-tuning dataset designed to address these limitations.Tool-Safety comprises 5,668 direct harm samples, 4,311 indirect harm samples, and 4,311 multistep samples.Key features include support for multi-step safety through synthesized trajectories and realistic, context-aware sample generation.We fine-tuned LLaMA3.1-8B-Instruct and Qwen2.5-7B-Instructusing ToolSafety.Experimental results demonstrate that these models effectively maintain safety in multi-step and indirect harm scenarios.Further analysis into superficial alignment across different decoding strategies, languages, and jailbreak prompts indicates that while some risks persist, the issue is less severe than in multi-step settings.Overall, our approach significantly improves safety across various scenarios with small impact on helpfulness, positioning ToolSafety as a valuable resource for building safer tool-using AI systems.WARNING: This paper contains unsafe model responses.
Yuejin Xie, Youliang Yuan, Wenxuan Wang 0001, Jianmin Guo, Pinjia He
EMNLP5
2024 Cube-Evo: A Query-Efficient Black-Box Attack on Video Classification System
abstract
The current progressive research in the domain of black-box adversarial attack enhances the reliability of deep neural network (DNN)-based video systems. Recent works mainly carry out black-box adversarial attacks on video systems by query-based parameter dimension reduction. However, the additional temporal dimension of video data leads to massive query consumption and low attack success rate. In this article, we embark on our efforts to design an effective adversarial attack on popular video classification systems. We deeply root the observations that the DNN-based systems are sensitive to adversarial perturbations with high frequency and reconstructed shape. Specifically, we propose a systematic attack pipeline Cube-Evo, aiming to reduce the search space dimension and obtain the effective adversarial perturbation via the optimal parameter group updating. We evaluate the proposed attack pipeline on two popular datasets: UCF101 and JESTER. Our attack pipeline reduces query consumption and achieves a high success rate on various DNN-based video classification systems. Compared with the state-of-the-art method Geo-Trap-Att, our pipeline averagely reduces 1.6× query consumption in untargeted attacks and 2.9× in targeted attacks. Besides, Cube-Evo improves 13% attack success rate on average, achieving new state-of-the-art results over diverse video classification systems.
Jianmin Guo, Heyuan Shi, Houbing Song
IEEE Trans. Reliab.4
2023 Stability Analysis and H∞ Control for Singular LPV Systems with Time-Delay
abstract
This paper deals with the asymptotical stability of singular LPV linear systems with time delay. By using a new method to deal with nonlinear terms, sufficient conditions for asymptotical stability of nonlinear quadratic systems are derived in terms of linear matrix inequalities. Certain existing results are improved. Simulation examples are presented to illustrate the effectiveness of the proposed technique.
Jianmin Guo, Caixia Guo, Shugui Kang
ICIS1
2023 SIRSM Model with Media Information Influence
abstract
The dynamic behavior research of infectious dis-ease models has always been a very important branch of biomathematics research. Since the outbreak of COVID-19 in December 2019, many scholars have formulated and evaluated prevention and control strategies by establishing mathematical models of their dynamics to understand the mechanism of epidemic diseases. And the impact of media information on infectious diseases is obvious. In this paper, a class of SIRSM models with the influence of positive media information are established, and the feasible domain of system dynamic behavior and the basic properties of system solution are analyzed and obtained. The basic regeneration number is calculated using the basic regeneration number theorem and analyzes the existence and stability of disease-free equilibrium points and positive equilibrium points. Studies have shown that positive information in the media helps to reduce the spread of infectious diseases.
Haiyan Tian, Jianmin Guo, Shugui Kang
ICIS2
2023 Prediction of the effects of small molecules on the gut microbiome using machine learning method integrating with optimal molecular features
abstract
BACKGROUND: The human gut microbiome (HGM), consisting of trillions of microorganisms, is crucial to human health. Adverse drug use is one of the most important causes of HGM disorder. Thus, it is necessary to identify drugs or compounds with anti-commensal effects on HGM in the early drug discovery stage. This study proposes a novel anti-commensal effects classification using a machine learning method and optimal molecular features. To improve the prediction performance, we explored combinations of six fingerprints and three descriptors to filter the best characterization as molecular features. RESULTS: The final consensus model based on optimal features yielded the F1-score of 0.725 ± 0.014, ACC of 82.9 ± 0.7%, and AUC of 0.791 ± 0.009 for five-fold cross-validation. In addition, this novel model outperformed the prior studies by using the same algorithm. Furthermore, the important chemical descriptors and misclassified anti-commensal compounds are analyzed to better understand and interpret the model. Finally, seven structural alerts responsible for the chemical anti-commensal effect are identified, implying valuable information for drug design. CONCLUSION: Our study would be a promising tool for screening anti-commensal compounds in the early stage of drug discovery and assessing the potential risks of these drugs in vivo.
Binyou Wang, Jianmin Guo
BMC Bioinform.2
2022 RNN-Test: Towards Adversarial Testing for Recurrent Neural Network Systems
abstract
While massive efforts have been investigated in adversarial testing of convolutional neural networks (CNN), testing for recurrent neural networks (RNN) is still limited and leaves threats for vast sequential application domains. In this paper, we propose an adversarial testing framework RNN-Test for RNN systems, focusing on sequence-to-sequence (seq2seq) tasks of widespread deployments, not only classification domains. First, we design a novel search methodology customized for RNN models by maximizing the inconsistency of RNN states against their inner dependencies to produce adversarial inputs. Next, we introduce two state-based coverage metrics according to the distinctive structure of RNNs to exercise more system behaviors. Finally, RNN-Test solves the joint optimization problem to maximize state inconsistency and state coverage, and crafts adversarial inputs for various tasks of different kinds of inputs. For evaluations, we apply RNN-Test on four RNN models of common structures. On the tested models, the RNN-Test approach is demonstrated to be competitive in generating adversarial inputs, outperforming FGSM-based and DLFuzz-based methods to reduce the model performance more sharply with 2.78% to 37.94% higher success (or generation) rate. RNN-Test could also achieve 52.65% to 66.45% higher adversary rate than testRNN on MNIST LSTM model, as well as 53.76% to 58.02% more perplexity with 16% higher generation rate than DeepStellar on PTB language model.Compared with the traditional neuron coverage, the proposed state coverage metrics as guidance excel with 4.17% to 97.22% higher success (or generation) rate.
Jianmin Guo, Quan Zhang 0003, Yue Zhao 0040, Heyuan Shi, Yu Jiang 0001, Jia-Guang Sun 0001
IEEE Trans. Software Eng.1
2021 HDTest: Differential Fuzz Testing of Brain-Inspired Hyperdimensional Computing
abstract
Brain-inspired hyperdimensional computing (HDC) is an emerging computational paradigm that mimics brain cognition and leverages hyperdimensional vectors with fully distributed holographic representation and (pseudo)randomness. Compared to other machine learning (ML) methods such as deep neural networks (DNNs), HDC offers several advantages including high energy efficiency, low latency, and one-shot learning, making it a promising alternative candidate on a wide range of applications. However, the reliability and robustness of HDC models have not been explored yet. In this paper, we design, implement, and evaluate HDTest to test HDC model by automatically exposing unexpected or incorrect behaviors under rare inputs. The core idea of HDTest is based on guided differential fuzz testing. Guided by the distance between query hypervector and reference hypervector in HDC, HDTest continuously mutates original inputs to generate new inputs that can trigger incorrect behaviors of HDC model. Compared to traditional ML testing methods, HDTest does not need to manually label the original input. Using handwritten digit classification as an example, we show that HDTest can generate thousands of adversarial inputs with negligible perturbations that can successfully fool HDC models. On average, HDTest can generate around 400 adversarial inputs within one minute running on a commodity computer. Finally, by using the HDTest-generated inputs to retrain HDC models, we can strengthen the robustness of HDC models. To the best of our knowledge, this paper presents the first effort in systematically testing this emerging brain-inspired computational model.
Dongning Ma, Jianmin Guo, Yu Jiang 0001, Xun Jiao 0002
DAC2
2021 AdvDoor: adversarial backdoor attack of deep learning system
abstract
Deep Learning (DL) system has been widely used in many critical applications, such as autonomous vehicles and unmanned aerial vehicles. However, their security is threatened by backdoor attack, which is achieved by adding artificial patterns on specific training data. Existing attack methods normally poison the data using a patch, and they can be easily detected by existing detection methods. In this work, we propose the Adversarial Backdoor, which utilizes the Targeted Universal Adversarial Perturbation (TUAP) to hide the anomalies in DL models and confuse existing powerful detection methods. With extensive experiments, it is demonstrated that Adversarial Backdoor can be injected stably with an attack success rate around 98%. Moreover, Adversarial Backdoor can bypass state-of-the-art backdoor detection methods. More specifically, only around 37% of the poisoned models can be caught, and less than 29% of the poisoned data cannot bypass the detection. In contrast, for the patch backdoor, all the poisoned models and more than 80% of the poisoned data will be detected. This work intends to alarm the researchers and developers of this potential threat and to inspire the designing of effective detection methods.
Quan Zhang 0003, Yongqiang Tian 0001, Jianmin Guo, Yu Jiang 0001
ISSTA4
2019 Leopard: identifying vulnerable code for vulnerability assessment through program metrics
abstract
Identifying potentially vulnerable locations in a code base is critical as a pre-step for effective vulnerability assessment; i.e., it can greatly help security experts put their time and effort to where it is needed most. Metric-based and pattern-based methods have been presented for identifying vulnerable code. The former relies on machine learning and cannot work well due to the severe imbalance between non-vulnerable and vulnerable code or lack of features to characterize vulnerabilities. The latter needs the prior knowledge of known vulnerabilities and can only identify similar but not new types of vulnerabilities. In this paper, we propose and implement a generic, lightweight and extensible framework, LEOPARD, to identify potentially vulnerable functions through program metrics. LEOPARD requires no prior knowledge about known vulnerabilities. It has two steps by combining two sets of systematically derived metrics. First, it uses complexity metrics to group the functions in a target application into a set of bins. Then, it uses vulnerability metrics to rank the functions in each bin and identifies the top ones as potentially vulnerable. Our experimental results on 11 real-world projects have demonstrated that, LEOPARD can cover 74.0% of vulnerable functions by identifying 20% of functions as vulnerable and outperform machine learning-based and static analysis-based techniques. We further propose three applications of LEOPARD for manual code review and fuzzing, through which we discovered 22 new bugs in real applications like PHP, radare2 and FFmpeg, and eight of them are new vulnerabilities.
Xiaoning Du 0001, Bihuan Chen 0001, Yuekang Li, Jianmin Guo, Yaqin Zhou, Yang Liu 0003, Yu Jiang 0001
ICSE4
2018 DLFuzz: differential fuzzing testing of deep learning systems
abstract
Deep learning (DL) systems are increasingly applied to safety-critical domains such as autonomous driving cars. It is of significant importance to ensure the reliability and robustness of DL systems. Existing testing methodologies always fail to include rare inputs in the testing dataset and exhibit low neuron coverage. In this paper, we propose DLFuzz, the first differential fuzzing testing framework to guide DL systems exposing incorrect behaviors. DLFuzz keeps minutely mutating the input to maximize the neuron coverage and the prediction difference between the original input and the mutated input, without manual labeling effort or cross-referencing oracles from other DL systems with the same functionality. We present empirical evaluations on two well-known datasets to demonstrate its efficiency. Compared with DeepXplore, the state-of-the-art DL whitebox testing framework, DLFuzz does not require extra efforts to find similar functional DL systems for cross-referencing check, but could generate 338.59% more adversarial inputs with 89.82% smaller perturbations, averagely obtain 2.86% higher neuron coverage, and save 20.11% time consumption.
Jianmin Guo, Yu Jiang 0001, Yue Zhao 0040, Quan Chen 0002, Jia-Guang Sun 0001
ESEC/SIGSOFT FSE1
2017 Complementary peak reducing signals for TDCS PAPR reduction
abstract
Transform domain communication systems (TDCSs) are cognitive anti‐interference multi‐carrier communication systems with dynamic spectrum access. The inherent high peak‐to‐average power ratio (PAPR) of TDCS reduces the efficiency of the power amplifier. Adaptive waveform generation of the TDCS also causes the PAPR to vary according to the spectral conditions on hand. In this study, a complementary peak reducing signal (CPRS) method is proposed and analysed. It uses all unoccupied frequency bins to transmit data and uses all interfered frequency bins to generate CPRSs. Every data signal and its corresponding CPRS are orthogonal and complementary, so as to fully occupy all frequency bins. Therefore, the PAPR reduction of the composite signal with all frequency bins is considered. Once the optimal pseudo‐random phase sequence is determined, the sequence can adapt to all spectral conditions without side information, and the computational complexity for diverse spectral conditions is greatly reduced. Moreover, the orthogonality between the data signal and its CPRS in the frequency domain eliminates distortions and spectral spreading. As a component of the transmitting signal, CPRS may cause bit error rate (BER) loss. This study also proposes a signal power adjustment mechanism to achieve a compromise between PAPR reduction and BER loss.
Hao Huan, Jianmin Guo, Ran Tao 0003
IET Commun.3