VLDB 2026 Research / reviewers in the wild / expert
Ziqing Yang 0002
dblp:243/3448-2
· DBLP profile ↗
7ranked-venue papers
2as first author
7since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Security and privacy · 3 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BadBone: Backdoor Attacks Against Backbone Models in Visual Prompt LearningabstractPrompt learning is a new machine learning paradigm that has attracted ample attention due to its simplicity and proven efficacy. Despite its growing adoption, the security vulnerabilities associated with this paradigm remain underexplored. In this work, we take the first step to propose BadBone, a stealthy and adaptive backdoor attack against prompt learning using bi-level optimization. Instead of backdooring the prompt learning process, we aim to compromise a backbone model such that only target downstream tasks employing prompt learning inherit the backdoor vulnerability. Extensive experiments on three different models and three datasets from various domains show that our targeted/untargeted backdoored models achieve high attack performance while maintaining utility on both pretraining and downstream tasks. Moreover, we evaluate our approach against six state-of-the-art model-level defenses, including Neural Cleanse, ABS, MNTD, NAD, CLP, and D-BR. The results demonstrate that these defenses are largely ineffective against our backdoored models and thus leave the effective defense as an important direction for future work. Our code is available at https://github.com/TrustAIRLab/BadBone. Ziqing Yang 0002, Rui Wen 0002, Xinlei He 0001, Michael Backes 0001, Yang Zhang 0016 |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2025 | JailbreakRadar: Comprehensive Assessment of Jailbreak Attacks Against LLMsabstractJailbreak attacks aim to bypass the LLMs' safeguards.While researchers have proposed different jailbreak attacks in depth, they have done so in isolation-either with unaligned settings or comparing a limited range of methods.To fill this gap, we present a large-scale evaluation of various jailbreak attacks.We collect 17 representative jailbreak attacks, summarize their features, and establish a novel jailbreak attack taxonomy.Then we conduct comprehensive measurement and ablation studies across nine aligned LLMs on 160 forbidden questions from 16 violation categories.Also, we test jailbreak attacks under eight advanced defenses.Based on our taxonomy and experiments, we identify some important patterns, such as heuristicbased attacks could achieve high attack success rates but are easy to mitigate by defenses, causing low practicality.Our study offers valuable insights for future research on jailbreak attacks and defenses.We hope our work could help the community avoid incremental work and serve as an effective benchmark tool for practitioners. Junjie Chu 0002, Yugeng Liu, Ziqing Yang 0002, Xinyue Shen 0001, Michael Backes 0001, Yang Zhang 0016 |
ACL (1) | 3 |
| 2025 | Hate in Plain Sight: On the Risks of Moderating AI-Generated Hateful Illusions
Yiting Qu, Ziqing Yang 0002, Yihan Ma 0001, Michael Backes 0001, Savvas Zannettou, Yang Zhang 0016 |
ICCV | 2 |
| 2025 | Synthetic Artifact Auditing: Tracing LLM-Generated Synthetic Data Usage in Downstream Applications
Yixin Wu 0001, Ziqing Yang 0002, Michael Backes 0001, Yang Zhang 0016 |
USENIX Security Symposium | 2 |
| 2024 | SecurityNet: Assessing Machine Learning Vulnerabilities on Public Models
Boyang Zhang 0008, Zheng Li 0023, Ziqing Yang 0002, Xinlei He 0001, Michael Backes 0001, Mario Fritz, Yang Zhang 0016 |
USENIX Security Symposium | 3 |
| 2023 | Data Poisoning Attacks Against Multimodal EncodersabstractRecently, the newly emerged multimodal models, which leverage both visual and linguistic modalities to train powerful encoders, have gained increasing attention. However, learning from a large-scale unlabeled dataset also exposes the model to the risk of potential poisoning attacks, whereby the adversary aims to perturb the model’s training data to trigger malicious behaviors in it. In contrast to previous work, only poisoning visual modality, in this work, we take the first step to studying poisoning attacks against multimodal models in both visual and linguistic modalities. Specially, we focus on answering two questions: (1) Is the linguistic modality also vulnerable to poisoning attacks? and (2) Which modality is most vulnerable? To answer the two questions, we propose three types of poisoning attacks against multimodal models. Extensive evaluations on different datasets and model architectures show that all three attacks can achieve significant attack performance while maintaining model utility in both visual and linguistic modalities. Furthermore, we observe that the poisoning effect differs between different modalities. To mitigate the attacks, we propose both pre-training and post-training defenses. We empirically show that both defenses can significantly reduce the attack performance while preserving the model’s utility. Our code is available at https://github.com/zqypku/mm_poison/. Ziqing Yang 0002, Xinlei He 0001, Zheng Li 0023, Michael Backes 0001, Mathias Humbert, Pascal Berrang, Yang Zhang 0016 |
ICML | 1 |
| 2021 | UniKER: A Unified Framework for Combining Embedding and Definite Horn Rule Reasoning for Knowledge Graph InferenceabstractKnowledge graph inference has been studied extensively due to its wide applications.It has been addressed by two lines of research, i.e., the more traditional logical rule reasoning and the more recent knowledge graph embedding (KGE).Several attempts have been made to combine KGE and logical rules for better knowledge graph inference.Unfortunately, they either simply treat logical rules as additional constraints into KGE loss or use probabilistic models to approximate the exact logical inference (i.e., MAX-SAT).Even worse, both approaches need to sample ground rules to tackle the scalability issue, as the total number of ground rules is intractable in practice, making them less effective in handling logical rules.In this paper, we propose a novel framework UniKER to address these challenges by restricting logical rules to be definite Horn rules, which can fully exploit the knowledge in logical rules and enable the mutual enhancement of logical rule-based reasoning and KGE in an extremely efficient way.Extensive experiments have demonstrated that our approach is superior to existing state-of-the-art algorithms in terms of both efficiency and effectiveness. Kewei Cheng, Ziqing Yang 0002, Ming Zhang 0004, Yizhou Sun |
EMNLP (1) | 2 |