VLDB 2026 Research / reviewers in the wild / expert
Ji Guo
dblp:23/7807
· DBLP profile ↗
23ranked-venue papers
7as first author
18since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 8 · 3 first-author · 7 since 2021Databases, data management, data science and information retrieval · 4 · 4 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 4 since 2021Computer networks · 3 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-authorSystems, architecture and hardware · 2 · 1 first-author · 2 since 2021Security and privacy · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | When Guidance Turns Poisonous: Backdooring the SAR-guided Cloud Removal Model
Xiaolei Wen, Ji Guo, Ruinan Sun, Nina Luo |
ICC | 2 |
| 2026 | TrojanEdit: Multimodal backdoor attack against image editing model
Ji Guo, Runjia Zhang, Wenbo Jiang 0001, Yiting Zhu, Jiachen Li 0002, Jiaming He, Hongwei Li 0001 |
Neurocomputing | 1 |
| 2026 | BadDenoise: Backdoor attacks on self-supervised image denoising
Ji Guo, Yansong Lin, Man Jiang, Jielei Wang |
Pattern Recognit. | 1 |
| 2026 | A 13-GS/s 9-bit Time-Interleaved Pipelined-SAR ADC With Common-Mode Regulated Floating-Inverter-Amplifier and Rapid-Tracking Bootstrapped SwitchabstractThis article presents a 13GS/s 9-bit 8-channel time-interleaved (TI) Pipelined-SAR (Pipe-SAR) ADC. A common-mode regulated floating-inverter-amplifier (CMR-FIA) is proposed to overcome the common-mode voltage variation due to the charge leakage through the parasitic capacitor, thereby eliminating the need for common-mode feedback (CMFB) circuitry embedded in the body of FIA. By combining an adaptively biased (AB) technique, the proposed FIA facilitates the high-speed and robust Pipe-SAR ADCs. In addition, a rapid-tracking bootstrapped signal generation is introduced to achieve high-linearity with short sampling time in an ultra-high speed sampling network. The ADC prototype is fabricated is a 28nm-CMOS process, the achieved spurious-free dynamic range (SFDR) and signal-to-noise and distortion ratio (SNDR) at the Nyquist input are 56.4dB and 41.75dB, respectively. Consuming 97mW at 13GS/s, it yields a Schreier figure of merit ($\text{FoM}_{\mathrm {S}}$) of 150dB. With the proposed CMR-FIA, the ADC’s SNDR variation is within 2.48dB across the input common-mode range of 0.3V to 0.8V. Ji Guo, Danfeng Zhai, Wenning Jiang, Qi Liu 0010, Ming Liu 0022 |
IEEE Trans. Circuits Syst. I Regul. Pap. | 1 |
| 2025 | Evaluating Robustness of Large Audio Language Models to Audio Injection: An Empirical StudyabstractLarge Audio-Language Models (LALMs) are increasingly deployed in real-world applications, yet their robustness against malicious audio injection remains underexplored.To address this gap, this study systematically evaluates five leading LALMs across four attack scenarios: Audio Interference Attack, Instruction Following Attack, Context Injection Attack, and Judgment Hijacking Attack.We quantitatively assess their vulnerabilities and resilience using metrics: the Defense Success Rate, Context Robustness Score, and Judgment Robustness Index.The experiments reveal significant performance disparities, with no single model demonstrating consistent robustness across all attack types.Attack effectiveness is significantly influenced by the position of the malicious content, particularly when injected at the beginning of a sequence.Furthermore, our analysis uncovers a negative correlation between a model's instruction-following capability and its robustness: models that strictly adhere to instructions tend to be more susceptible, whereas safety-aligned models exhibit greater resistance.To facilitate future research, this work introduces a comprehensive benchmark framework.Our findings underscore the critical need for integrating robustness into training pipelines and developing multi-modal defenses, ultimately facilitating the secure deployment of LALMs.The dataset used in this work is available on Hugging Face. Guanyu Hou, Jiaming He, Yinhang Zhou, Ji Guo, Yitong Qiao, Rui Zhang 0086, Wenbo Jiang 0001 |
EMNLP | 4 |
| 2025 | Exploiting Unknown Samples under Limited Budgets in Open-set Active LearningabstractActive Learning (AL) aims to improve model performance while reducing annotation costs by selectively labeling the most informative samples from an unlabeled dataset. In openset scenarios where the unlabeled pool may include instances from unknown classes, most existing open-set AL methods focus exclusively on known-class samples and neglect the valuable information that unknown-class samples can provide. To address this limitation, we propose ALSO (Active Learning with few-Shot in Open set), a novel framework that incorporates both known and unknown class samples during the selection process. ALSO combines uncertainty-based sampling for known classes with a similarity-driven strategy to identify and utilize representative unknown-class samples. This few-shot approach enables the model to generalize effectively with limited supervision from unknown classes, enhancing overall performance even with a small number of annotated samples. Extensive experiments on CIFAR-10, CIFAR-100, and Tiny-ImageNet demonstrate that ALSO consistently outperforms state-of-the-art methods in accuracy and precision. Zhijing Wang, Ji Guo, Wenbo Jiang 0001 |
GLOBECOM | 3 |
| 2025 | BadRefSR: Backdoor Attacks Against Reference-based Image Super ResolutionabstractReference-based image super-resolution (RefSR) represents a promising advancement in super-resolution (SR). In contrast to single-image super-resolution (SISR), RefSR leverages an additional reference image to help recover high-frequency details, yet its vulnerability to backdoor attacks has not been explored. To fill this research gap, we propose a novel attack framework called BadRefSR, which embeds backdoors in the RefSR model by adding triggers to the reference images and training with a mixed loss function. Extensive experiments across various backdoor attack settings demonstrate the effectiveness of BadRefSR. The compromised RefSR network performs normally on clean input images, while outputting attacker-specified target images on triggered input images. Our study aims to alert researchers to the potential backdoor risks in RefSR. Codes are available at https://github.com/xuefusiji/BadRefSR. Ji Guo, Jiaming He |
ICASSP | 5 |
| 2025 | Weaponizing Tokens: Backdooring Text-to-Image Generation via Token RemappingabstractText-to-image generative models have garnered immense attention for their ability to produce high-fidelity images from text prompts and enjoyed great popularity among the community. Unfortunately, previous studies have demonstrated that text-to-image models suffer from backdoor attacks, which enforce the text-guided generative models to generate images that align the backdoor target via embedding the textual triggers. However, the currently proposed backdoor attacks rely on numerous training data and complex computing resources for poisoning the core components in generative models, limiting the effectiveness and practicality in real-world scenarios. In this work, we first investigate the backdoor attack against Text-to-image generation by manipulating text tokenizer. Our backdoor attack exploits the semantic conditioning role of text tokenizer in the text-to-image generation. We propose an Automatized Remapping Framework with Optimized Tokens (AROT) for finding the best target tokens to remap the trigger token in the mapping space, according to different tasks. We conduct extensive experiments on Stable Diffusion and two defined tasks to demonstrate the effectiveness, stealthiness and robustness of our attack. Jiaming He, Wenbo Jiang 0001, Guanyu Hou, Qiyang Song, Ji Guo, Hongwei Li 0001 |
ICME | 5 |
| 2025 | When Hallucinated Concepts Cross Modals: Unveiling Backdoor Vulnerability in Multi-modal In-context LearningabstractDue to the remarkable performance of multi-modal large language models (MLLMs) in multi-modal capabilities, multi-modal in-context learning (M-ICL) has garnered widespread attention for fast adapting MLLMs to downstream tasks. However, the vulnerability of M-ICL to attacks remains largely unexplored. In this work, we take the first step to explore the backdoor vulnerability of M-ICL, which allows the adversary only to manipulate the multi-modal demonstration examples to mislead the victim model. We propose a multi-modal backdoor strategy on M-ICL via cross-modal concept mis-matching under black-box attack setting. Extensive experimental results demonstrate that our attacks exhibit high attack effectiveness while preserving the normal functionality of the victim model. Moreover, we further conduct experiments to prove our attacks are robust against backdoor defenses and still remain effective in various real-world conditions. Guanyu Hou, Jiaming He, Yitong Qiao, Jiachen Li 0002, Qiyang Song, Ji Guo, Wenbo Jiang 0001 |
MMAsia | 6 |
| 2025 | You Are Out of My Focus: A Defocus-Blur Backdoor Attack against Deep Learning ModelsabstractWith the widespread adoption of deep learning in image recognition, backdoor attacks have emerged as a significant security threat, drawing increasing attention from the research community. Traditional backdoor attacks are often limited to the digital domain, while few existing physical-world attacks suffer from a lack of stealthiness. In this paper, inspired by the natural defocus blur commonly caused by camera optics in real-world environments, we propose a physically-aware backdoor attack method called DBBA based on the defocus blur phenomenon. By leveraging Gaussian blur to simulate this natural phenomenon, the proposed method enhances both the stealthiness and plausibility of the trigger. To further optimize the attack effectiveness while maintaining stealthiness, we introduce a Particle Swarm Optimization (PSO) algorithm to automatically search for the optimal Gaussian blur parameters that best simulate the defocus phenomenon. We conduct extensive experiments on multiple mainstream image classification datasets and across various model architectures. Experimental results demonstrate that the proposed defocus-blur based trigger achieves a high attack effectiveness with minimal degradation in the classification accuracy of the model. In addition, evaluations against representative defense techniques reveal that the proposed method exhibits strong stealthiness and robustness. Hongwei Li 0001, Wenbo Jiang 0001, Jiaming He, Rui Zhang 0090, Ji Guo, Jiachen Li 0002 |
MMAsia | 7 |
| 2025 | Double-boundary awareness of shared categories for source-free universal domain adaptation
Zhijing Wang, Ji Guo |
Neurocomputing | 2 |
| 2025 | Backdoor attacks against Hybrid Classical-Quantum Neural Networks
Ji Guo, Wenbo Jiang 0001, Rui Zhang 0090, Wenshu Fan, Jiachen Li 0002, Guoming Lu, Hongwei Li 0001 |
Neural Networks | 1 |
| 2024 | Backdoor Attack Against Vision Transformers via Attention Gradient-Based Image ErosionabstractVision Transformers (ViTs) have outperformed traditional Convolutional Neural Networks (CNN) across various computer vision tasks. However, akin to CNN, ViTs are vulnerable to backdoor attacks, where the adversary embeds the backdoor into the victim model, causing it to make wrong predictions about testing samples containing a specific trigger. Existing backdoor attacks against ViTs have the limitation of failing to strike an optimal balance between attack stealthiness and attack effectiveness.In this work, we propose an Attention Gradient-based Erosion Backdoor (AGEB) targeted at ViTs. Considering the attention mechanism of ViTs, AGEB selectively erodes pixels in areas of maximal attention gradient, embedding a covert backdoor trigger. Unlike previous backdoor attacks against ViTs, AGEB achieves an optimal balance between attack stealthiness and attack effectiveness, ensuring the trigger remains invisible to human detection while preserving the model’s accuracy on clean samples. Extensive experimental evaluations across various ViT architectures and datasets confirm the effectiveness of AGEB, achieving a remarkable Attack Success Rate (ASR) without diminishing Clean Data Accuracy (CDA). Furthermore, the stealthiness of AGEB is rigorously validated, demonstrating minimal visual discrepancies between the clean and the triggered images. Ji Guo, Hongwei Li 0001, Wenbo Jiang 0001, Guoming Lu |
GLOBECOM | 1 |
| 2024 | Goal-oriented common benchmarking based on global and stepwise reallocation: An application to 18 ports in Korea
Zhiyong Ji, Xianhua Wu, Ji Guo, Guo Wei 0004 |
Expert Syst. Appl. | 3 |
| 2024 | A Large Group Emergency Decision-Making Approach on HFLTS With Public Preference Data MiningabstractAiming at the emergency decision-making problem of major emergencies, this article proposes a large group emergency decision-making (LGEDM) approach with public opinions mining on hesitation fuzzy language term set (HFLTS). First, extract keywords that represent general preferences on events from the Weibo platform, classify keywords using the word similarity-based keyword clustering algorithm and identify decision attributes and their weights. Next, define the similarity measure and hesitation fuzzy entropy measure of HFLTS, quantify the decision risk of experts using the risk measurement model, and cluster all experts into several subgroups using the risk metric-based group clustering algorithm. Subsequently, assign clusters' weights on their risk value and size and obtain each cluster's preference matrix by the HIOWA operator. Finally, derive the ranking results of alternatives using the sorting process, and an example of “COVID-19” is presented to verify the rationality and effectiveness of the proposed method. Mengke Zhao, Ji Guo, Xianhua Wu |
J. Glob. Inf. Manag. | 2 |
| 2023 | A global optimization feedback model with PSO for large scale group decision making in hesitant fuzzy linguistic environments
Meng-Ke Zhao, Ji Guo, Zeshui Xu |
Expert Syst. Appl. | 2 |
| 2023 | Features and Comparative Research on Ecological Civilization Vocabularies in the Five-Year Plan of China: An Analysis Based on Semantic PhrasesabstractThe Five-Year Plan (FYP) in China guides the social and economic development. The features of ecology-related vocabularies in national and regional FYPs help to study China's emphasis and focus on ecological civilization. In this paper, a multi-phrase dictionary with syntactic and semantic features is constructed to analyze the features and trends of ecology-related vocabularies through social network and phrase topic model. Then, based on studies on the 13th and 14th FYPs of China and 31 provinces and cities, it is found that remarkable different stage definitions and tasks of ecological civilization construction are proposed according to different description vocabularies, with more pragmatic measures to fulfill its “carbon” target in 2030 as a duty-bound responsibility and mission to cope with climate change. The research ideas and methods in this paper can provide references for similar policy text analysis, and the conclusions from empirical studies are helpful to grasp the focus and trends of ecological civilization-related policies in China and various provinces and cities. Shaoli He, Xianhua Wu, Ji Guo |
J. Glob. Inf. Manag. | 3 |
| 2021 | A bibliometric analysis and visualization of blockchain
Yi-Ming Guo, Zhen-Ling Huang, Ji Guo, Xing-Rong Guo, Meng-Yu Liu, Safa Ezzeddine, Mpeoane Judith Nkeli |
Future Gener. Comput. Syst. | 3 |
| 2020 | Study of haze emission efficiency based on new co-opetition data envelopment analysisabstractAbstract As haze intensifies in China, controlling haze emission has become the country's top priority for environmental protection. Because haze moves across different regions, it is necessary to develop a data envelopment analysis (DEA) model underpinned by both competition and cooperation to evaluate the haze emission efficiency in different provinces. This study innovatively adopts the spatial econometrics to construct the co‐opetition matrices of Chinese provinces, then builds the co‐opetition DEA model to evaluate the haze emission efficiency of them, and finally uses the haze data of 2015 as an example to assess the applicability of the model. The results of the study include the following: First, compared with the traditional CCR (A. Charnes & W. W. Cooper & E. Rhodes) model, this study constructs the co‐opetition DEA cross‐efficiency model that integrates haze's feature of cross‐border moving; thus, it is more in line with the reality of haze emission and movement. Second, compared with the efficiency value gained from the CCR model, the haze emission efficiency values for Tianjin and Guangdong, two decision‐making units, register greater variance when using the DEA model. The reason might lie in that they have a different spatial transportation relationship with their surrounding provinces. Third, the haze emission efficiency of provinces, according to the evaluation based on the co‐opetition DEA method, varies greatly: Those with high efficiency are mostly inland provinces with slow economic growth and adverse climatic conditions, whereas many of the provinces with low efficiency are located in the relatively prosperous East China. The specific co‐opetition DEA model constructed in this study enriches the research on the DEA model, which can be applied to the emission efficiency evaluation of similar pollutants around the world and can contribute empirical support to the haze reducing efforts of the government with its empirical results. Xianhua Wu, Yufeng Chen 0004, Ji Guo, Zhanxin Ma |
Expert Syst. J. Knowl. Eng. | 4 |
| 2016 | A novel 3D imaging method based on orthogonal-track SARabstractA novel method of three-dimensional (3D) imaging based on orthogonal-track synthetic aperture radar (SAR), is proposed in this paper. In the scheme, the SAR sensor moves along two orthogonal tracks successively and two SAR images are obtained. Then we extract the spacial information from the two-dimensional (2D) SAR images to reconstruct the 3D distribution of scatterers in the common part. The orthogonal-track SAR obtains resolving ability in the normal direction of the azimuth-range plane by combining the information obtained along orthogonal tracks. Compared with conventional single-channel 2D SAR and interferometry SAR, the orthogonal-track SAR has distinct advantage in providing detailed and precise information about spatial distribution of the observed scene, and is capable of achieving real 3D resolution cell. Ji Guo, Kaizhi Wang, Xingzhao Liu |
IGARSS | 1 |
| 2016 | X-band mini SAR radar on eight-rotor mini-UAVabstractAn X-band Synthetic Aperture Radar (SAR), the mini-SAR, mounted on an eight-rotor Unmanned Aerial Vehicle (UAV), has been designed, built and tested at Shanghai Jiao Tong University, China. The main purpose of this work is to design a light-weight, cost-effective and easy-handy miniaturize SAR system with the ability to make repeated flights for an extended study. Real-time collected data can effectively test the validity of a newly proposed image algorithm. The system can apply in modeling and calculating the scattering characteristics of complex target such as tank which is vital in military reconnaissance. Recent tests have shown that the system is suitable for further experiments to validate the SAR system design via changing the parameter setting. This paper outlines design parameters and specifications for the mini-SAR, together with results from experimental data collection and test flights. Jiali Yan, Ji Guo, Qianrong Lu, Kaizhi Wang, Xingzhao Liu |
IGARSS | 2 |
| 2014 | Development of a Universal Platform for Hardware In-the-Loop Testing of MicrogridsabstractThe operation of a microgrid becomes significantly complex with the high penetration of distributed energy resources (DERs), demand-side management, market operation, and disconnection and reconnection to the utility grid. Therefore, development of advanced tools/platforms for testing operation and control of microgrid has attracted more and more attention nowadays. The current literature reveals that the microgrid's control and management are designed to be tested either in a numerical simulation approach, or only under a specific hardware device/experiment environment; they do not deal with a comprehensive platform capable of easily executing very complex applications built by composing required functionalities in a standardized, easy-to-use, and well-defined way. To address the problem of limited testing functions of existing tools/platforms, a hardware-in-the-loop (HIL) approach, in particular combining a power-HIL (PHIL) and a signal-HIL (SHIL), is proposed in this paper. Such an approach is suitable for testing the system-level controller energy management systems (EMSs) and hardware controllers at signal level, as well as hardware devices like power converters at power level. Hence, this platform is designed for flexibility and universality. The HIL platform is presented in this work and its performance is demonstrated in a sample application. Yulun Song, Ji Guo, Antonello Monti |
IEEE Trans. Ind. Informatics | 4 |
| 2011 | A New Trust Management Framework for Detecting Malicious and Selfish Behaviour for Mobile Ad Hoc NetworksabstractWith the development of wireless network applications, wireless networks need more interactions between many entities, and a rapidly increasing requirement for designing secure applications among these entities is trust management. Therefore, a lot of attacks against distributed environment are aimed at the trust management. This article presents a new trust management framework (TMF) for Mobile Ad hoc Networks. The proposed framework calculates a node's trust value based on observations from neighbour nodes by using Grey theory and Fuzzy sets. The TMF chooses multiple rather than a single parameter to obtain trust values. Simulations conducted in a Mobile Ad hoc Network (MANET, 802.11-based) with Random Waypoint Mobility Mode show what the proposed framework can do is not only detecting abnormal trust behaviour, but also discovering which parameter for forming trust values of a mobile node is abnormal, that means it can identify the possible attack strategy in both static and mobile environment. The TMF has shown good performance in calculating trust values of mobile wireless nodes under normal and abnormal (attack) conditions, and hence can be considered as an effective trust framework for MANETs. Ji Guo, Alan Marshall 0001, Bosheng Zhou |
TrustCom | 1 |