VLDB 2026 Research / reviewers in the wild / expert
Jirui Yang
dblp:207/9492
· DBLP profile ↗
16ranked-venue papers
2as first author
15since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 9 · 1 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 1 first-author · 5 since 2021Security and privacy · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | N-GLARE: An Non-Generative Latent Representation-Efficient LLM Safety EvaluatorabstractEvaluating the safety robustness of LLMs is critical for their deployment.However, mainstream Red Teaming methods rely on online generation and black-box output analysis.These approaches are not only costly but also suffer from feedback latency, making them unsuitable for agile diagnostics after training a new model.To address this, we propose N-GLARE (A Non-Generative, Latent Representation-Efficient LLM Safety Evaluator).N-GLARE operates entirely on the model's latent representations, bypassing the need for full text generation.It characterizes hidden layer dynamics by analyzing the APT (Angular-Probabilistic Trajectory) of latent representations and introducing the JSS (Jensen-Shannon Separability) metric.Experiments on over 40 models and 20 red teaming strategies demonstrate that the JSS metric exhibits high consistency with Red Teaming safety rankings at less than 1% token and runtime cost. Zheyu Lin, Jirui Yang, Yukui Qiu, Yubing Bao, Hengqi Guo, Yao Guan |
ACL (1) | 2 |
| 2025 | Efficient Joint Communication and Computation Placement for Large-scale SNN Simulation on SupercomputersabstractSpiking Neural Network (SNN) simulation involves emulating the activation and firing of spiking neurons on hardware platforms. This is a highly time-sensitive task, requiring the simulation of billions of neurons and their intercommunication within a few milliseconds. Each neuron performs a complex, interdependent multi-stage communication and computation task. We consider the task placement of SNN on supercomputers to accelerate SNN simulation. Existing task placement methods for SNN simulations have two major limitations. First, they lack the capability to handle large-scale SNNs with billions of neurons. Second, they focus primarily on optimizing communication delay, while neglecting multi-stage computation delays in SNN simulations. In this paper, we formalize the SNN Joint Multi-stage Communication and Computation Placement (SJCCP) problem. We demonstrate that SJCCP can be solved using an approximation algorithm with an approximation ratio of $O\left( {{k^2}\sqrt {\log n\log k} } \right)$, where n is the number of voxels in the SNN and k is the number of GPUs. To further reduce the time complexity of solving SJCCP in practice, we propose a novel efficient framework, FastSJP, tailored for large-scale SNN placement. Then we apply the FastSJP framework to a human brain simulation that runs a large-scale SNN model derived from authentic biological data on a supercomputer equipped with 1024 GPUs. Experimental results verify that our framework notably reduces time overhead, ranging from 17.31% to 28.45%, compared to state-of-the-art methods. Leveraging the computational power of the supercomputer, FastSJP maximizes the problem size and processing performance, significantly advancing the development of brain-inspired intelligence. Yubing Bao, Zhihui Lu 0002, Xin Du 0002, Qiang Duan 0002, Jirui Yang, Jin Zhao 0001, Geyong Min, Yang Chen 0001, Shijing Hu 0001, Xin Wang 0002 |
ICDCS | 5 |
| 2025 | UIFV: Data Reconstruction Attack in Vertical Federated LearningabstractVertical Federated Learning (VFL) enables collaborative machine learning without the need for participants to share their raw private data. However, recent studies have uncovered privacy risks, where adversaries might reconstruct sensitive features through data leakage during the learning process. Al-though existing data reconstruction methods are effective to some extent, they exhibit limitations in VFL scenarios, as initiating an attack requires meeting more stringent conditions. To gain a comprehensive understanding of the risks of data reconstruction in VFL, this paper proposes a unified framework, the Unified InverNet Framework in VFL (UIFV), for data reconstruction under realistic black-box threat models. Within the UIFV framework, we consider four attack scenarios, strictly adhering to VFL protocols to maintain confidentiality. Experiments on four datasets show that our methods significantly outperform state-of-the-art techniques in terms of applicability and attack precision. Our work reveals severe privacy vulnerabilities within VFL systems that pose real threats to practical VFL applications, thus confirming the necessity of further enhancing privacy protection in the VFL architecture. Overall, this paper provides a thorough analysis of the risks of data reconstruction in VFL and offers important guidance to enhance the security of VFL deployments. Jirui Yang, Peng Chen 0030, Zhihui Lu 0002, Qiang Duan 0002, Yubing Bao |
ICWS | 1 |
| 2025 | Universal Backdoor Defense via Label Consistency in Vertical Federated LearningabstractBackdoor attacks in vertical federated learning (VFL) are particularly concerning as they can covertly compromise VFL decision-making, posing a severe threat to critical applications of VFL. Existing defense mechanisms typically involve either label obfuscation during training or model pruning during inference. However, the inherent limitations on the defender's access to the global model and complete training data in VFL environments fundamentally constrain the effectiveness of these conventional methods. To address these limitations, we propose the Universal Backdoor Defense (UBD) framework. UBD leverages Label Consistent Clustering (LCC) to synthesize plausible latent triggers associated with the backdoor class. This synthesized information is then utilized for mitigating backdoor threats through Linear Probing (LP), guided by a constraint on Batch Normalization (BN) statistics. Positioned within a unified VFL backdoor defense paradigm, UBD offers a generalized framework for both detection and mitigation that critically does not necessitate access to the entire model or dataset. Extensive experiments across multiple datasets rigorously demonstrate the efficacy of the UBD framework, achieving state-of-the-art performance against diverse backdoor attack types in VFL, including both dirty-label and clean-label variants. Peng Chen 0030, Haolong Xiang, Xin Du 0002, Xiaolong Xu 0001, Xuhao Jiang, Zhihui Lu 0002, Jirui Yang, Qiang Duan 0002, Wan-Chun Dou |
IJCAI | 7 |
| 2025 | Backdoor Attack on Vertical Federated Graph Neural Network LearningabstractFederated Graph Neural Network (FedGNN) integrate federated learning (FL) with graph neural networks (GNNs) to enable privacy-preserving training on distributed graph data. Vertical Federated Graph Neural Network (VFGNN), a key branch of FedGNN, handles scenarios where data features and labels are distributed among participants. Despite the robust privacy-preserving design of VFGNN, we have found that it still faces the risk of backdoor attacks, even in situations where labels are inaccessible. This paper proposes BVG, a novel backdoor attack method that leverages multi-hop triggers and backdoor retention, requiring only four target-class nodes to execute effective attacks. Experimental results demonstrate that BVG achieves nearly 100% attack success rates across three commonly used datasets and three GNN models, with minimal impact on the main task accuracy. We also evaluated various defense methods, and the BVG method maintained high attack effectiveness even under existing defenses. This finding highlights the need for advanced defense mechanisms to counter sophisticated backdoor attacks in practical VFGNN applications. Jirui Yang, Peng Chen 0030, Zhihui Lu 0002, Jianping Zeng 0002, Qiang Duan 0002, Xin Du 0002, Ruijun Deng |
IJCAI | 1 |
| 2025 | Robust direct position determination for chirp signal-based underwater acoustic sensor networks
Wei Wang 0499, Shefeng Yan, Linlin Mao, Zeping Sui, Jirui Yang |
Signal Process. | 5 |
| 2025 | Ambiguity-Free Broadband DOA Estimation Relying on Parameterized Time-Frequency TransformabstractAn ambiguity-free direction-of-arrival (DOA) estimation scheme is proposed for sparse uniform linear arrays under low signal-to-noise ratios (SNRs) and non-stationary broadband signals. First, for achieving better DOA estimation performance at low SNRs while using non-stationary signals compared to the conventional frequency-difference (FD) paradigms, we propose parameterized time-frequency transform-based FD processing. Then, the unambiguous compressive FD beamforming is conceived to compensate the resolution loss induced by difference operation. Finally, we further derive a coarse-to-fine histogram statistics scheme to alleviate the perturbation in compressive FD beamforming with good DOA estimation accuracy. Simulation results demonstrate the superior performance of our proposed algorithm regarding robustness, resolution, and DOA estimation accuracy. Wei Wang 0499, Shefeng Yan, Linlin Mao, Zeping Sui, Jirui Yang |
IEEE Signal Process. Lett. | 5 |
| 2025 | The Effect of Domain Terms on Password SecurityabstractThe predominant authentication method still relies on usernames and passwords. To enhance memorability, domain terms may have been opted to include as part of passwords. However, there is little analysis of the extent to which such practice affects password security, so there is a lack of guidance on how users use domain terms on websites with different domain characteristics. To address the problem, we propose a novel approach to analyze the security effect of using domain terms in passwords. The methodology primarily consists of three stages. First, we utilize Web crawlers to harvest domain vocabularies, subsequently leveraging the TextRank algorithm to rank their importance. Second, we propose an algorithm for constructing a simulated domain-specific password dataset by replacing password elements with domain terms. Third, password guessing experiments are done on the dataset using PCFG (Probabilistic Context-Free Grammar) and the Markov model to evaluate the impact of domain terms on password security. The experimental results indicate that, for systems without clear domain, 20% domain terms replacement in the test set can reduce the cracking rate by up to 5.45%. In contrast, for domain-specific systems, 20% domain terms replacement in the training set can increase the cracking rate by 6.45%. These findings provide practical guidance on the application of domain knowledge in password creation for different types of systems. In summary, this study offers a novel perspective for exploring the security implications of passwords influenced by specific domains. Yubing Bao, Jianping Zeng 0002, Jirui Yang, Ruining Yang, Zhihui Lu 0002 |
ACM Trans. Priv. Secur. | 3 |
| 2024 | An Adversarial Attack Method Against Financial Fraud Detection Model Beta Wavelet Graph Neural Network via Node InjectionabstractFinancial fraud detection plays a crucial role in maintaining financial security and risk control. Many types of financial data, such as transaction networks and entity relationship networks, can be represented as graph-structured data. Graph neural networks, exemplified by the Beta Wavelet Graph Neural Network (BWGNN), are instrumental in financial fraud detection. However, current research on adversarial attacks against graph neural networks primarily focuses on vanilla GNNs, with limited exploration into adversarial attacks targeting models like BWGNN used in financial fraud detection. This paper presents effective adversarial attack methods tailored to BWGNN. Leveraging node injection as an adversarial attack method, we construct surrogate models that closely resemble the structure of BWGNN, significantly enhancing the attack performance. Additionally, by incorporating dropout layers after the input layer of the surrogate model, we further enhance the attack effectiveness. This paper reveals the adversarial vulnerabilities of financial fraud detection models represented by BWGNN, which holds significant implications for enhancing the security of fraud detection models applied in critical financial security domains. Hengqi Guo, Xiaozheng Du, Jirui Yang, Zhihui Lu 0002 |
CSCloud | 4 |
| 2024 | Mitigating critical nodes in brain simulations via edge removal
Yubing Bao, Xin Du 0002, Zhihui Lu 0002, Jirui Yang, Shih-Chia Huang, Jianfeng Feng, Qibao Zheng |
Comput. Networks | 4 |
| 2023 | A Practical Clean-Label Backdoor Attack with Limited Information in Vertical Federated LearningabstractVertical Federated Learning (VFL) facilitates collaboration on model training among multiple parties, each owning partitioned features of the distributed dataset. Although backdoor attacks have been found as one of the main threats to FL security, research on backdoor attacks in VFL is still in the infant stage. Existing methods for VFL backdoor attacks rely on predicting sample pseudo-labels using approaches such as label inference, which require substantial additional information not readily available in practical FL scenarios. To evaluate the practical vulnerability of VFL to backdoor attacks, we present a target-efficient clean backdoor (TECB) attack for VFL. The TECB approach consists of two phases – i) Clean Backdoor Poisoning (CBP) and Target Gradient Alignment (TGA). In the CBP phase, the adversary trains a backdoor trigger and poisons the model during VFL training. The poisoned model is further fine-tuned in the TGA phase to enhance its efficacy in complex multi-classification tasks. Compared to the existing methods, the proposed TECB achieves a highly effective backdoor attack with very limited information about the target class samples, which is more practical in typical VFL settings. Experimental results verify the superior performance of TECB, achieving above 97% attack success rate (ASR) on three widely used datasets (CIFAR10, CIFAR100, and CINIC-10) with only 0.1% of target labels known, which outperforms the state-of-the-art attack methods. This study uncovers the potential backdoor risks in VFL, enabling the development of secure VFL applications in areas like finance, healthcare, and beyond. Source code is available at: https://github.com/13thDayOLunarMay/TECB-attack Peng Chen 0030, Jirui Yang, Junxiong Lin, Zhihui Lu 0002, Qiang Duan 0002, Hongfeng Chai |
ICDM | 2 |
| 2023 | The KFIoU Loss for Rotated Object Detection
Xue Yang 0005, Yue Zhou 0005, Gefan Zhang, Jirui Yang, Wentao Wang 0009, Junchi Yan, Xiaopeng Zhang 0008, Qi Tian 0001 |
ICLR | 4 |
| 2023 | PatchDCT: Patch Refinement for High Quality Instance Segmentation
Qinrou Wen, Jirui Yang, Xue Yang 0005, Kewei Liang |
ICLR | 2 |
| 2021 | DCT-Mask: Discrete Cosine Transform Mask Representation for Instance SegmentationabstractBinary grid mask representation is broadly used in instance segmentation. A representative instantiation is Mask R-CNN which predicts masks on a 28×28 binary grid. Generally, a low-resolution grid is not sufficient to capture the details, while a high-resolution grid dramatically increases the training complexity. In this paper, we propose a new mask representation by applying the discrete cosine transform(DCT) to encode the high-resolution binary grid mask into a compact vector. Our method, termed DCT-Mask, could be easily integrated into most pixel-based instance segmentation methods. Without any bells and whistles, DCT-Mask yields significant gains on different frameworks, backbones, datasets, and training schedules. It does not require any pre-processing or pre-training, and almost no harm to the running speed. Especially, for higher-quality annotations and more complex backbones, our method has a greater improvement. Moreover, we analyze the performance of our method from the perspective of the quality of mask representation. The main reason why DCT-Mask works well is that it obtains a high-quality mask representation with low complexity. Jirui Yang, Chunbo Wei, Bing Deng, Jianqiang Huang 0001, Xian-Sheng Hua 0001, Kewei Liang |
CVPR | 2 |
| 2021 | Learning High-Precision Bounding Box for Rotated Object Detection via Kullback-Leibler DivergenceabstractExisting rotated object detectors are mostly inherited from the horizontal detection paradigm, as the latter has evolved into a well-developed area. However, these detectors are difficult to perform prominently in high-precision detection due to the limitation of current regression loss design, especially for objects with large aspect ratios. Taking the perspective that horizontal detection is a special case for rotated object detection, in this paper, we are motivated to change the design of rotation regression loss from induction paradigm to deduction methodology, in terms of the relation between rotation and horizontal detection. We show that one essential challenge is how to modulate the coupled parameters in the rotation regression loss, as such the estimated parameters can influence to each other during the dynamic joint optimization, in an adaptive and synergetic way. Specifically, we first convert the rotated bounding box into a 2-D Gaussian distribution, and then calculate the Kullback-Leibler Divergence (KLD) between the Gaussian distributions as the regression loss. By analyzing the gradient of each parameter, we show that KLD (and its derivatives) can dynamically adjust the parameter gradients according to the characteristics of the object. For instance, it will adjust the importance (gradient weight) of the angle parameter according to the aspect ratio. This mechanism can be vital for high-precision detection as a slight angle error would cause a serious accuracy drop for large aspect ratios objects. More importantly, we have proved that KLD is scale invariant. We further show that the KLD loss can be degenerated into the popular Ln-norm loss for horizontal detection. Experimental results on seven datasets using different detectors show its consistent superiority, and codes are available at https://github.com/yangxue0827/RotationDetection. Xue Yang 0005, Xiaojiang Yang, Jirui Yang, Qi Ming, Wentao Wang 0009, Qi Tian 0001, Junchi Yan |
NeurIPS | 3 |
| 2019 | SCRDet: Towards More Robust Detection for Small, Cluttered and Rotated ObjectsabstractObject detection has been a building block in computer vision. Though considerable progress has been made, there still exist challenges for objects with small size, arbitrary direction, and dense distribution. Apart from natural images, such issues are especially pronounced for aerial images of great importance. This paper presents a novel multi-category rotation detector for small, cluttered and rotated objects, namely SCRDet. Specifically, a sampling fusion network is devised which fuses multi-layer feature with effective anchor sampling, to improve the sensitivity to small objects. Meanwhile, the supervised pixel attention network and the channel attention network are jointly explored for small and cluttered object detection by suppressing the noise and highlighting the objects feature. For more accurate rotation estimation, the IoU constant factor is added to the smooth L1 loss to address the boundary problem for the rotating bounding box. Extensive experiments on two remote sensing public datasets DOTA, NWPU VHR-10 as well as natural image datasets COCO, VOC2007 and scene text data ICDAR2015 show the state-of-the-art performance of our detector. The code and models will be available at https://github.com/DetectionTeamUCAS. Xue Yang 0005, Jirui Yang, Junchi Yan, Yue Zhang 0016, Tengfei Zhang 0004, Zhi Guo, Xian Sun 0001, Kun Fu 0001 |
ICCV | 2 |