Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Bingyin Zhao

dblp:237/0182 · DBLP profile ↗
← Back
8ranked-venue papers
5as first author
8since 2021 · last 2026
0000-0003-0372-8198ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Graphics, computer vision, multimedia, augmented reality and games · 5 · 4 first-author · 5 since 2021Artificial intelligence and machine learning · 4 · 2 first-author · 4 since 2021Systems, architecture and hardware · 2 · 1 first-author · 2 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Computer architecture, parallel and distributed computing, and storage systems
2 papers
Emerging computing paradigms · 48% Electronic design automation · 31% Hardware reliability and fault tolerance · 7%
Network and information security
3 papers
Security and privacy of machine learning · 69% Hardware security and side channels · 31%
Artificial intelligence
3 papers
Generative modeling · 44% Image recognition and object detection · 35% Deep learning architectures and training · 10%

Topics — the 15 heaviest of 15, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Security and privacy of machine learning › adversarial attack
backdoor attack
0.912025
UIBDiffusion: Universal Imperceptible Backdoor Attack for Diffusion Models · CVPR 2025
Computer vision › Image recognition and object detection
image classification
0.712023
Fully Attentional Networks with Self-emerging Token Labeling · ICCV 2023
Hardware security and side channels
fault attacks
0.712023
NNTesting: Neural Network Fault Attacks Detection Using Gradient-Based Test Vector Generation · DAC 2023
Emerging computing paradigms › approximate computing
approximate circuit design
0.712023
Data-Driven Feature Selection Framework for Approximate Circuit Design · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2023
Emerging computing paradigms
approximate computing
0.712023
Data-Driven Feature Selection Framework for Approximate Circuit Design · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2023
Electronic design automation
logic synthesis
0.712023
Data-Driven Feature Selection Framework for Approximate Circuit Design · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2023
Machine learning › Generative modeling
generative adversarial network
0.612022
CLPA: Clean-Label Poisoning Availability Attacks Using Generative Adversarial Nets · AAAI 2022
Security and privacy of machine learning
poisoning attack
0.612022
CLPA: Clean-Label Poisoning Availability Attacks Using Generative Adversarial Nets · AAAI 2022
Machine learning › Generative modeling
diffusion model
0.312025
UIBDiffusion: Universal Imperceptible Backdoor Attack for Diffusion Models · CVPR 2025
Machine learning › Trustworthy machine learning
robustness
0.212023
Fully Attentional Networks with Self-emerging Token Labeling · ICCV 2023
Machine learning › Deep learning architectures and training › transformer
vision transformer
0.212023
Fully Attentional Networks with Self-emerging Token Labeling · ICCV 2023
Electronic design automation › hardware verification and test
fault detection
0.212023
NNTesting: Neural Network Fault Attacks Detection Using Gradient-Based Test Vector Generation · DAC 2023
Integrated circuit design
low-power circuit design
0.212023
Data-Driven Feature Selection Framework for Approximate Circuit Design · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2023
Hardware reliability and fault tolerance
soft errors
0.212023
NNTesting: Neural Network Fault Attacks Detection Using Gradient-Based Test Vector Generation · DAC 2023
Energy-efficient computing › voltage scaling
voltage overscaling
0.212023
Data-Driven Feature Selection Framework for Approximate Circuit Design · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2023

Methods — techniques the papers use, named apart from their topics

universal adversarial perturbation · 1.7diffusion model · 1.7test vector generation · 1.3test vector compression · 1.3gradient-based optimization · 1.3triplet loss · 1.1singular vector decomposition defense · 1.1token labeling · 0.7self-emerging token labeling · 0.7error compensation circuit design · 0.7data-driven feature selection · 0.7
YearPublicationVenuePosition
2026 UltraClean: A Simple Framework to Train Robust Neural Networks against Backdoor Attacks
abstract
Backdoor attacks are emerging threats to deep neural networks, which typically embed malicious behaviors into a victim model by injecting poisoned samples. Adversaries can activate the injected backdoor during inference by presenting the trigger on input images. Prior defensive methods have achieved remarkable success in countering dirty-label backdoor attacks where the labels of poisoned samples are often mislabeled. However, these approaches do not work for a recent new type of backdoor – clean-label backdoor attacks that imperceptibly modify poisoned data and hold consistent labels. More complex and powerful algorithms are demanded to defend against such stealthy attacks. In this paper, we propose UltraClean, a general framework that simplifies the identification of poisoned samples and defends against both dirty-label and clean-label backdoor attacks. Given the fact that backdoor triggers introduce adversarial noise that intensifies in feed-forward propagation, UltraClean first generates two variants of training samples using off-the-shelf denoising functions. It then measures the susceptibility of training samples leveraging the error amplification effect in DNNs, which dilates the noise difference between the original image and denoised variants. Lastly, it filters out poisoned samples based on the susceptibility to thwart the backdoor implantation. Despite its simplicity, UltraClean achieves a superior detection rate across various datasets and significantly reduces the backdoor attack success rate while maintaining a decent model accuracy on clean data, outperforming existing defensive methods by a large margin. Code is available at https://github.com/bxz9200/UltraClean.
Bingyin Zhao, Yingjie Lao
WACV1
2025 UIBDiffusion: Universal Imperceptible Backdoor Attack for Diffusion Models
abstract
Recent studies show that diffusion models (DMs) are vulnerable to backdoor attacks. Existing backdoor attacks impose unconcealed triggers (e.g., a gray box and eyeglasses) that contain evident patterns, rendering remarkable attack effects yet easy detection upon human inspection and defensive algorithms. While it is possible to improve stealthiness by reducing the strength of the backdoor, doing so can significantly compromise its generality and effectiveness. In this paper, we propose UIBDiffusion, the universal imperceptible backdoor attack for diffusion models, which allows us to achieve superior attack and generation performance while evading state-of-the-art defenses. We propose a novel trigger generation approach based on universal adversarial perturbations (UAPs) and reveal that such perturbations, which are initially devised for fooling pre-trained discriminative models, can be adapted as potent imperceptible backdoor triggers for DMs. We evaluate UIBDiffusion on multiple types of DMs with different kinds of samplers across various datasets and targets. Experimental results demonstrate that UIBDiffusion brings three advantages: 1) Universality, the imperceptible trigger is universal (i.e., image and model agnostic) where a single trigger is effective to any images and all diffusion models with different samplers; 2) Utility, it achieves comparable generation quality (e.g., FID) and even better attack success rate (i.e., ASR) at low poison rates compared to the prior works; and 3) Undetectability, UIBDiffusion is plausible to human perception and can bypass Elijah and TERD, the SOTA defenses against backdoors for DMs. Code is available at https://github.com/TheLaoLab/UIBDiffusion.
Yuning Han, Bingyin Zhao, Rui Chu, Biplab Sikdar 0001, Yingjie Lao
CVPR2
2025 BAM-ICL: Causal Hijacking In-Context Learning with Budgeted Adversarial Manipulation
abstract
Recent research shows that large language models (LLMs) are vulnerable to hijacking attacks under the scenario of in-context learning (ICL) where LLMs demonstrate impressive capabilities in performing tasks by conditioning on a sequence of in-context examples (ICEs) (i.e., prompts with task-specific input-output pairs). Adversaries can manipulate the provided ICEs to steer the model toward attacker-specified outputs, effectively ''hijacking'' the model's decision-making process. Unlike traditional adversarial attacks targeting single inputs, hijacking attacks in LLMs aim to subtly manipulate the initial few examples to influence the model's behavior across a range of subsequent inputs, which requires distributed and stealthy perturbations. However, existing approaches overlook how to effectively allocate the perturbation budget across ICEs. We argue that fixed budgets miss the potential of dynamic reallocation to improve attack success while maintaining high stealthiness and text quality. In this paper, we propose BAM-ICL, a novel **b**udgeted **a**dversarial **m**anipulation hijacking attack framework for in-context learning. We also consider a more practical yet stringent scenario where ICEs arrive sequentially and only the current ICE can be perturbed. BAM-ICL mainly consists of two stages: In the offline stage, where we assume the adversary has access to data drawn from the same distribution as the target task, we develop a global gradient-based attack to learn optimal budget allocations across ICEs. In the online stage, where ICEs arrive sequentially, perturbations are generated progressively according to the learned budget profile. We evaluate BAM-ICL on diverse LLMs and datasets. The experimental results demonstrate that it achieves superior attack success rates and stealthiness, and the adversarial ICEs are highly transferable to other models.
Rui Chu, Bingyin Zhao, Hanling Jiang, Shuchin Aeron, Yingjie Lao
NeurIPS2
2023 NNTesting: Neural Network Fault Attacks Detection Using Gradient-Based Test Vector Generation
abstract
Recent studies have shown Neural Networks (NNs) are highly vulnerable to fault attacks. This work proposes a novel defensive framework, NNTesting, for detecting the fault attack and recovering the model. We first leverage gradient-based optimization to generate a set of high-quality Test Vectors (TVs) that effectively differentiate faulty profile models and further optimize the TV set by reducing the TVs through compression. The selected final TV set is then used to recover the model. The effectiveness of the proposed method is comprehensively evaluated on a wide range of models across various benchmark datasets. For instance, we successfully generate more than thousands of TV candidates using a gradient-based generation method. After compression, we achieve up to 94.76% detection success rate with only 140 TVs on the CIFAR-10 dataset.
Antian Wang, Bingyin Zhao, Weihang Tan, Yingjie Lao
DAC2
2023 Fully Attentional Networks with Self-emerging Token Labeling
abstract
Recent studies indicate that Vision Transformers (ViTs) are robust against out-of-distribution scenarios. In particular, the Fully Attentional Network (FAN) - a family of ViT backbones, has achieved state-of-the-art robustness. In this paper, we revisit the FAN models and improve their pretraining with a self-emerging token labeling (STL) framework. Our method contains a two-stage training framework. Specifically, we first train a FAN token labeler (FAN-TL) to generate semantically meaningful patch token labels, followed by a FAN student model training stage that uses both the token labels and the original class label. With the proposed STL framework, our best model based on FANL-Hybrid (77.3M parameters) achieves 84.8% Top-1 accuracy and 42.1% mCE on ImageNet-1K and ImageNetC, and sets a new state-of-the-art for ImageNet-A (46.1%) and ImageNet-R (56.6%) without using extra data, outperforming the original FAN counterpart by significant margins. The proposed framework also demonstrates significantly enhanced performance on downstream tasks such as semantic segmentation, with up to 1.7% improvement in robustness over the counterpart model.
Bingyin Zhao, Zhiding Yu, Shiyi Lan, Yutao Cheng, Anima Anandkumar, Yingjie Lao, José M. Álvarez 0004
ICCV1
2023 Data-Driven Feature Selection Framework for Approximate Circuit Design
abstract
The ever-growing data scale and computation complexity raise tremendous concerns about computer systems’ efficiency (i.e., lower hardware overhead and power consumption). Orthogonal to the advancement in semiconductor manufacturing technologies, approximate computing provides an alternative paradigm to reduce the hardware cost and power dissipation by relaxing computation quality for error-resilient applications. Voltage over-scaling (VOS) and approximate logic design (ALD) have become two mainstream approaches of approximate computing due to their superior performance in efficiency-critical designs. VOS reduces the power in quadratic by scaling down supply voltage while ALD saves hardware overhead by redesigning an approximate version of a given circuit (e.g., trimming less significant circuitry). However, these primitive approximate circuits (PACs) inevitably introduce notable errors and require additional error compensation circuits (ECCs) to preserve computation accuracy. In existing works of ECC design, there lacks a systematic method that can generalize well to different approximate computing approaches. In this article, we present a data-driven feature selection framework for approximate circuit design, which is applicable to both VOS and ALD. We propose novel algorithms that profoundly analyze the correlation between input data and output errors and select the most critical features to generate compensation circuits. Extensive evaluations are performed over a variety of circuits using approximate finite impulse response (FIR) filters and the prevalent approximate computing benchmark AxBench. The experimental results show that the proposed approach achieves superior compensation performance, boosting the circuit accuracy while only introducing trivial area overhead.
Bingyin Zhao, Yingjie Lao
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst.1
2022 CLPA: Clean-Label Poisoning Availability Attacks Using Generative Adversarial Nets
abstract
Poisoning attacks are emerging threats to deep neural networks where the adversaries attempt to compromise the models by injecting malicious data points in the clean training data. Poisoning attacks target either the availability or integrity of a model. The availability attack aims to degrade the overall accuracy while the integrity attack causes misclassification only for specific instances without affecting the accuracy of clean data. Although clean-label integrity attacks are proven to be effective in recent studies, the feasibility of clean-label availability attacks remains unclear. This paper, for the first time, proposes a clean-label approach, CLPA, for the poisoning availability attack. We reveal that due to the intrinsic imperfection of classifiers, naturally misclassified inputs can be considered as a special type of poisoned data, which we refer to as "natural poisoned data''. We then propose a two-phase generative adversarial net (GAN) based poisoned data generation framework along with a triplet loss function for synthesizing clean-label poisoned samples that locate in a similar distribution as natural poisoned data. The generated poisoned data are plausible to human perception and can also bypass the singular vector decomposition (SVD) based defense. We demonstrate the effectiveness of our approach on CIFAR-10 and ImageNet dataset over a variety type of models. Codes are available at: https://github.com/bxz9200/CLPA.
Bingyin Zhao, Yingjie Lao
AAAI1
2022 Towards Class-Oriented Poisoning Attacks Against Neural Networks
abstract
Poisoning attacks on machine learning systems compromise the model performance by deliberately injecting malicious samples in the training dataset to influence the training process. Prior works focus on either availability attacks (i.e., lowering the overall model accuracy) or integrity attacks (i.e., enabling specific instance based backdoor). In this paper, we advance the adversarial objectives of the availability attacks to a per-class basis, which we refer to as class-oriented poisoning attacks. We demonstrate that the proposed attack is capable of forcing the corrupted model to predict in two specific ways: (i) classify unseen new images to a targeted "supplanter" class, and (ii) misclassify images from a "victim" class while maintaining the classification accuracy on other non-victim classes. To maximize the adversarial effect as well as reduce the computational complexity of poisoned data generation, we propose a gradient-based framework that crafts poisoning images with carefully manipulated feature information for each scenario. Using newly defined metrics at the class level, we demonstrate the effectiveness of the proposed class-oriented poisoning attacks on various models (e.g., LeNet-5, Vgg-9, and ResNet-50) over a wide range of datasets (e.g., MNIST, CIFAR-10, and ImageNet-ILSVRC2012) in an end-to-end training setting.
Bingyin Zhao, Yingjie Lao
WACV1