Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Hengzhi Pei

dblp:243/7002 · DBLP profile ↗
← Back
10ranked-venue papers
3as first author
7since 2021 · last 2025
0000-0001-7036-2996ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 8 · 2 first-author · 5 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
6 papers
Trustworthy machine learning · 56% Language models and text generation · 15% Information extraction and text analysis · 11%
Network and information security
3 papers
Security and privacy of machine learning · 81% Privacy and data protection · 19%
Computer architecture, parallel and distributed computing, and storage systems
1 paper
Hardware reliability and fault tolerance · 56% High-performance computing · 44%
Software engineering, system software, and programming languages
1 paper
Program synthesis and code generation · 77% Program analysis · 23%
Databases, data mining, and information retrieval
1 paper
Data mining · 100%
Interdisciplinary, comprehensive, and emerging computing
1 paper
Computational finance and economics · 100%

Topics — the 22 heaviest of 25, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning
robustness
1.222023
DecodingTrust: A Comprehensive Assessment of Trustworthiness in GPT Models · NeurIPS 2023
Improving Certified Robustness via Statistical Learning with Logical Reasoning · NeurIPS 2022
High-performance computing
large-scale training
0.912025
Understanding Silent Data Corruption in LLM Training · ACL (1) 2025
Hardware reliability and fault tolerance › soft errors
silent data corruption
0.912025
Understanding Silent Data Corruption in LLM Training · ACL (1) 2025
Natural language and speech › Information extraction and text analysis
text classification
0.812024
TextGuard: Provable Defense against Backdoor Attacks on Text Classification · NDSS 2024
Security and privacy of machine learning › adversarial attack › backdoor attack
backdoor defense
0.812024
TextGuard: Provable Defense against Backdoor Attacks on Text Classification · NDSS 2024
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
0.712023
DecodingTrust: A Comprehensive Assessment of Trustworthiness in GPT Models · NeurIPS 2023
Security and privacy of machine learning › privacy attack
privacy leakage in language models
0.712023
DecodingTrust: A Comprehensive Assessment of Trustworthiness in GPT Models · NeurIPS 2023
Program synthesis and code generation
code completion
0.712023
Better Context Makes Better Code Language Models: A Case Study on Function Call Argument Completion · AAAI 2023
Machine learning › Trustworthy machine learning › robustness
certified robustness
0.612022
Improving Certified Robustness via Statistical Learning with Logical Reasoning · NeurIPS 2022
Knowledge, reasoning and agents › Knowledge representation and reasoning › probabilistic reasoning › probabilistic logic
markov logic networks
0.612022
Improving Certified Robustness via Statistical Learning with Logical Reasoning · NeurIPS 2022
Machine learning › Generative modeling
generative adversarial network
0.512021
Towards Generating Real-World Time Series Data · ICDM 2021
Data mining
time series generation
0.512021
Towards Generating Real-World Time Series Data · ICDM 2021
Machine learning › Trustworthy machine learning › robustness
adversarial attack
0.412020
T3: Tree-Autoencoder Constrained Adversarial Text Generation for Targeted Attack · EMNLP (1) 2020
Natural language and speech › Language models and text generation › text generation › synthetic text generation
adversarial text generation
0.412020
T3: Tree-Autoencoder Constrained Adversarial Text Generation for Targeted Attack · EMNLP (1) 2020
Natural language and speech › Language models and text generation › trustworthy language model
natural language processing robustness
0.412020
T3: Tree-Autoencoder Constrained Adversarial Text Generation for Targeted Attack · EMNLP (1) 2020
Computational finance and economics
portfolio management
0.412020
Reinforcement-Learning Based Portfolio Management with Augmented Asset Movement Prediction States · AAAI 2020
Security and privacy of machine learning › privacy attack
model inversion attack
0.412020
The Secret Revealer: Generative Model-Inversion Attacks Against Deep Neural Networks · CVPR 2020
Privacy and data protection › privacy-preserving machine learning
training data privacy
0.412020
The Secret Revealer: Generative Model-Inversion Attacks Against Deep Neural Networks · CVPR 2020
Hardware reliability and fault tolerance
soft errors
0.312025
Understanding Silent Data Corruption in LLM Training · ACL (1) 2025
Machine learning › Trustworthy machine learning
fairness and bias
0.212023
DecodingTrust: A Comprehensive Assessment of Trustworthiness in GPT Models · NeurIPS 2023
Program analysis
static analysis
0.212023
Better Context Makes Better Code Language Models: A Case Study on Function Call Argument Completion · AAAI 2023
Natural language and speech › Language models and text generation
text generation
0.112020
T3: Tree-Autoencoder Constrained Adversarial Text Generation for Targeted Attack · EMNLP (1) 2020

Methods — techniques the papers use, named apart from their topics

jailbreaking · 1.3benchmark evaluation · 1.3observation embedding · 1.0encoder-decoder · 1.0decide-and-generate decoder · 1.0synchronization mechanisms · 0.9deterministic execution · 0.9XLA compiler · 0.9state augmentation · 0.9reinforcement learning · 0.9price movement prediction · 0.9program analyzer · 0.7code language model · 0.7statistical learning · 0.6markov logic networks · 0.6generative adversarial network · 0.4differential privacy · 0.4
YearPublicationVenuePosition
2025 Understanding Silent Data Corruption in LLM Training
abstract
As the scale of training large language models (LLMs) increases, one emergent failure is silent data corruption (SDC), where hardware produces incorrect computations without explicit failure signals.In this work, we are the first to investigate the impact of real-world SDCs on LLM training by comparing model training between healthy production nodes and unhealthy nodes exhibiting SDCs.With the help from a cloud computing platform, we access the unhealthy nodes that were swept out from production by automated fleet management.Using deterministic execution via XLA compiler and our proposed synchronization mechanisms, we isolate and analyze the impact of SDC errors on these nodes at three levels: at each submodule computation, at a single optimizer step, and at a training period.Our results reveal that the impact of SDCs on computation varies on different unhealthy nodes.Although in most cases the perturbations from SDCs on submodule computation and gradients are relatively small, SDCs can lead models to converge to different optima with different weights and even cause spikes in the training loss.Our analysis sheds light on further understanding and mitigating the impact of SDCs.
Jeffrey Jian Ma, Hengzhi Pei, Leonard Lausen, George Karypis
ACL (1)2
2025 When Silicon Fails Silently: Characterizing Hardware-Induced Corruption in LLM Training
abstract
As the scale of training large language models (LLMs) increases, one emergent failure is silent data corruption (SDC), where hardware produces incorrect computations without explicit failure signals. In this work, we summarize the first investigation of the impact of real-world SDCs on LLM training presented in our ACL work [1]. In our investigation, we compare model training between healthy production nodes and unhealthy nodes exhibiting SDCs. With the help from a cloud computing platform, we access the unhealthy nodes that were swept out from production by automated fleet management. Using deterministic execution via XLA compiler and our proposed synchronization mechanisms, we isolate and analyze the impact of SDC errors on these nodes at three levels: at each submodule computation, at a single optimizer step, and at a training period. Our results reveal that the impact of SDCs on computation varies on different unhealthy nodes. Although in most cases the perturbations from SDCs on submodule computation and gradients are relatively small, SDCs can lead models to converge to different optima with different weights and even cause spikes in the training loss.
Jeffrey Jian Ma, Hengzhi Pei, Leonard Lausen, George Karypis
IOLTS2
2024 TextGuard: Provable Defense against Backdoor Attacks on Text Classification
Hengzhi Pei, Jinyuan Jia 0001, Wenbo Guo 0002, Bo Li 0026, Dawn Song
NDSS1
2023 Better Context Makes Better Code Language Models: A Case Study on Function Call Argument Completion
abstract
Pretrained code language models have enabled great progress towards program synthesis. However, common approaches only consider in-file local context and thus miss information and constraints imposed by other parts of the codebase and its external dependencies. Existing code completion benchmarks also lack such context. To resolve these restrictions we curate a new dataset of permissively licensed Python packages that includes full projects and their dependencies and provide tools to extract non-local information with the help of program analyzers. We then focus on the task of function call argument completion which requires predicting the arguments to function calls. We show that existing code completion models do not yield good results on our completion task. To better solve this task, we query a program analyzer for information relevant to a given function call, and consider ways to provide the analyzer results to different code completion models during inference and training. Our experiments show that providing access to the function implementation and function usages greatly improves the argument completion performance. Our ablation study provides further insights on how different types of information available from the program analyzer and different ways of incorporating the information affect the model performance.
Hengzhi Pei, Jinman Zhao, Leonard Lausen, Sheng Zha, George Karypis
AAAI1
2023 DecodingTrust: A Comprehensive Assessment of Trustworthiness in GPT Models
abstract
Generative Pre-trained Transformer (GPT) models have exhibited exciting progress in capabilities, capturing the interest of practitioners and the public alike. Yet, while the literature on the trustworthiness of GPT models remains limited, practitioners have proposed employing capable GPT models for sensitive applications to healthcare and finance – where mistakes can be costly. To this end, this work proposes a comprehensive trustworthiness evaluation for large language models with a focus on GPT-4 and GPT-3.5, considering diverse perspectives – including toxicity, stereotype bias, adversarial robustness, out-of-distribution robustness, robustness on adversarial demonstrations, privacy, machine ethics, and fairness. Based on our evaluations, we discover previously unpublished vulnerabilities to trustworthiness threats. For instance, we find that GPT models can be easily misled to generate toxic and biased outputs and leak private information in both training data and conversation history. We also find that although GPT-4 is usually more trustworthy than GPT-3.5 on standard benchmarks, GPT-4 is more vulnerable given jailbreaking system or user prompts, potentially due to the reason that GPT-4 follows the (misleading) instructions more precisely. Our work illustrates a comprehensive trustworthiness evaluation of GPT models and sheds light on the trustworthiness gaps. Our benchmark is publicly available at https://decodingtrust.github.io/.
Boxin Wang, Hengzhi Pei, Chulin Xie, Mintong Kang, Chejian Xu, Zidi Xiong, Ritik Dutta, Rylan Schaeffer, Sang T. Truong, Simran Arora, Mantas Mazeika, Dan Hendrycks, Zinan Lin 0001, Yu Cheng 0001, Oluwasanmi Koyejo, Dawn Song, Bo Li 0026
NeurIPS3
2022 Improving Certified Robustness via Statistical Learning with Logical Reasoning
abstract
Intensive algorithmic efforts have been made to enable the rapid improvements of certificated robustness for complex ML models recently. However, current robustness certification methods are only able to certify under a limited perturbation radius. Given that existing pure data-driven statistical approaches have reached a bottleneck, in this paper, we propose to integrate statistical ML models with knowledge (expressed as logical rules) as a reasoning component using Markov logic networks (MLN), so as to further improve the overall certified robustness. This opens new research questions about certifying the robustness of such a paradigm, especially the reasoning component (e.g., MLN). As the first step towards understanding these questions, we first prove that the computational complexity of certifying the robustness of MLN is #P-hard. Guided by this hardness result, we then derive the first certified robustness bound for MLN by carefully analyzing different model regimes. Finally, we conduct extensive experiments on five datasets including both high-dimensional images and natural language texts, and we show that the certified robustness with knowledge-based logical reasoning indeed significantly outperforms that of the state-of-the-arts.
Zhikuan Zhao, Boxin Wang, Jiawei Zhang 0013, Linyi Li 0001, Hengzhi Pei, Bojan Karlas, Ji Liu 0002, Heng Guo 0001, Ce Zhang 0001, Bo Li 0026
NeurIPS6
2021 Towards Generating Real-World Time Series Data
abstract
Time series data generation has drawn increasing attention in recent years. Several generative adversarial network (GAN) based methods have been proposed to tackle the problem usually with the assumption that the targeted time series data are well-formatted and complete. However, real-world time series (RTS) data are far away from this utopia, e.g., long sequences with variable lengths and informative missing data raise intractable challenges for designing powerful generation algorithms. In this paper, we propose a novel generative framework for RTS data – RTSGAN to tackle the aforementioned challenges. RTSGAN first learns an encoder-decoder module which provides a mapping between a time series instance and a fixed-dimension latent vector and then learns a generation module to generate vectors in the same latent space. By combining the generator and the decoder, RTSGAN is able to generate RTS which respect the original feature distributions and the temporal dynamics. To generate time series with missing values, we further equip RTSGAN with an observation embedding layer and a decide-and-generate decoder to better utilize the informative missing patterns. Experiments on the four RTS datasets show that the proposed framework outperforms the previous generation methods in terms of synthetic data utility for downstream classification and prediction tasks. Our code is available at https://seqml.github.io/rtsgan.
Hengzhi Pei, Kan Ren, Yuqing Yang 0001, Chang Liu 0030, Tao Qin 0001, Dongsheng Li 0002
ICDM1
2020 Reinforcement-Learning Based Portfolio Management with Augmented Asset Movement Prediction States
abstract
Portfolio management (PM) is a fundamental financial planning task that aims to achieve investment goals such as maximal profits or minimal risks. Its decision process involves continuous derivation of valuable information from various data sources and sequential decision optimization, which is a prospective research direction for reinforcement learning (RL). In this paper, we propose SARL, a novel State-Augmented RL framework for PM. Our framework aims to address two unique challenges in financial PM: (1) data heterogeneity – the collected information for each asset is usually diverse, noisy and imbalanced (e.g., news articles); and (2) environment uncertainty – the financial market is versatile and non-stationary. To incorporate heterogeneous data and enhance robustness against environment uncertainty, our SARL augments the asset information with their price movement prediction as additional states, where the prediction can be solely based on financial data (e.g., asset prices) or derived from alternative sources such as news. Experiments on two real-world datasets, (i) Bitcoin market and (ii) HighTech stock market with 7-year Reuters news articles, validate the effectiveness of SARL over existing PM approaches, both in terms of accumulated profits and risk-adjusted profits. Moreover, extensive simulations are conducted to demonstrate the importance of our proposed state augmentation, providing new insights and boosting performance significantly over standard RL-based PM method and other baselines.
Yunan Ye, Hengzhi Pei, Boxin Wang, Yada Zhu, Ju Xiao, Bo Li 0026
AAAI2
2020 The Secret Revealer: Generative Model-Inversion Attacks Against Deep Neural Networks
abstract
This paper studies model-inversion attacks, in which the access to a model is abused to infer information about the training data. Since its first introduction by~\cite{fredrikson2014privacy}, such attacks have raised serious concerns given that training data usually contain privacy sensitive information. Thus far, successful model-inversion attacks have only been demonstrated on simple models, such as linear regression and logistic regression. Previous attempts to invert neural networks, even the ones with simple architectures, have failed to produce convincing results. Here we present a novel attack method, termed the \emph{generative model-inversion attack}, which can invert deep neural networks with high success rates. Rather than reconstructing private training data from scratch, we leverage partial public information, which can be very generic, to learn a distributional prior via generative adversarial networks (GANs) and use it to guide the inversion process. Moreover, we theoretically prove that a model's predictive power and its vulnerability to inversion attacks are indeed two sides of the same coin---highly predictive models are able to establish a strong correlation between features and labels, which coincides exactly with what an adversary exploits to mount the attacks. Our extensive experiments demonstrate that the proposed attack improves identification accuracy over the existing work by about $75\%$ for reconstructing face images from a state-of-the-art face recognition classifier. We also show that differential privacy, in its canonical form, is of little avail to defend against our attacks.
Ruoxi Jia 0001, Hengzhi Pei, Wenxiao Wang 0002, Bo Li 0026, Dawn Song
CVPR3
2020 T3: Tree-Autoencoder Constrained Adversarial Text Generation for Targeted Attack
abstract
Adversarial attacks against natural language processing systems, which perform seemingly innocuous modifications to inputs, can induce arbitrary mistakes to the target models.Though raised great concerns, such adversarial attacks can be leveraged to estimate the robustness of NLP models.Compared with the adversarial example generation in continuous data domain (e.g., image), generating adversarial text that preserves the original meaning is challenging since the text space is discrete and non-differentiable.To handle these challenges, we propose a target-controllable adversarial attack framework T3, which is applicable to a range of NLP tasks.In particular, we propose a tree-based autoencoder to embed the discrete text data into a continuous representation space, upon which we optimize the adversarial perturbation.A novel tree-based decoder is then applied to regularize the syntactic correctness of the generated text and manipulate it on either sentence (T3(SENT)) or word (T3(WORD)) level.We consider two most representative NLP tasks: sentiment analysis and question answering (QA).Extensive experimental results and human studies show that T3 generated adversarial texts can successfully manipulate the NLP models to output the targeted incorrect answer without misleading the human.Moreover, we show that the generated adversarial texts have high transferability which enables the black-box attacks in practice.Our work sheds light on an effective and general way to examine the robustness of NLP models.Our code is publicly available at
Boxin Wang, Hengzhi Pei, Boyuan Pan, Qian Chen 0003, Shuohang Wang, Bo Li 0026
EMNLP (1)2