VLDB 2026 Research / reviewers in the wild / expert
Qilin Zhou
dblp:244/4493
· DBLP profile ↗
10ranked-venue papers
4as first author
10since 2021 · last 2026
0000-0003-2289-9849ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 6 · 2 first-author · 6 since 2021Systems, architecture and hardware · 3 · 3 since 2021Artificial intelligence and machine learning · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Multi-scale hypergraph representation learning with channel attention for next POI recommendation
Qilin Zhou, Jinkang Ye, Wei Zhou 0028, Junhao Wen 0001 |
Neurocomputing | 1 |
| 2026 | HiCert: Toward Patch Robustness Certification and Detection for Deep Learning Systems Beyond Consistent SamplesabstractPatch robustness certification is an emerging kind of provable defense technique against adversarial patch attacks for deep learning systems. Certified detection ensures the detection of all patched harmful versions of certified samples, which mitigates the failures of empirical defense techniques that could (easily) be compromised. However, existing certified detection methods are ineffective in certifying samples that are misclassified or whose mutants are inconsistently predicted to different labels. This paper proposes HiCert, a novel masking-based certified detection technique. By focusing on the problem of mutants predicted with a label different from the true label with our formal analysis, HiCert formulates a novel formal relation between harmful samples generated by identified loopholes and their benign counterparts. By checking the bound of the maximum confidence among these potentially harmful (i.e., inconsistent) mutants of each benign sample, HiCert ensures that each harmful sample either has the minimum confidence among mutants that are predicted the same as the harmful sample itself below this bound, or has at least one mutant predicted with a label different from the harmful sample itself, formulated after two novel insights. As such, HiCert systematically certifies those inconsistent samples and consistent samples to a large extent. To our knowledge, HiCert is thefirstwork capable of providing such a comprehensive patch robustness certification for certified detection. Our experiments show the high effectiveness of HiCert with a new state-of-the-art performance: It certifies significantly more benign samples, including those inconsistent and consistent, and achieves significantly higher accuracy on those samples without warnings and a significantly lower false silent ratio. Moreover, on actual patch attacks, its defense success ratio is significantly higher than its peers. Qilin Zhou, Zhengyuan Wei, Haipeng Wang 0005, Wing Kwong Chan |
IEEE Trans. Reliab. | 1 |
| 2025 | Scalable and Precise Patch Robustness Certification for Deep Learning Models with Top- $k$ PredictionsabstractPatch robustness certification is an emerging verification approach for defending against adversarial patch attacks with provable guarantees for deep learning systems. Certified recovery techniques guarantee the prediction of the sole true label of a certified sample. However, existing techniques, if applicable to top-$k$predictions, commonly conduct pairwise comparisons on those votes between labels, failing to certify the sole true label within the top$k$prediction labels precisely due to the inflation on the number of votes controlled by the attacker (i.e., attack budget); yet enumerating all combinations of vote allocation suffers from the combinatorial explosion problem. We propose CostCert, a novel, scalable, and precise voting-based certified recovery defender. CostCert verifies the true label of a sample within the top$k$predictions without pairwise comparisons and combinatorial explosion through a novel design: whether the attack budget on the sample is infeasible to cover the smallest total additional votes on top of the votes uncontrollable by the attacker to exclude the true labels from the top$k$prediction labels. Experiments show that CostCert significantly outperforms the current state-of-the-art defender PatchGuard, such as retaining up to 57.3% in certified accuracy when the patch size is 96, whereas PatchGuard has already dropped to zero. Qilin Zhou, Haipeng Wang 0005, Zhengyuan Wei, Wing Kwong Chan |
QRS | 1 |
| 2025 | Context-Aware Fuzzing for Robustness Enhancement of Deep Learning ModelsabstractIn the testing-retraining pipeline for enhancing the robustness property of deep learning (DL) models, many state-of-the-art robustness-oriented fuzzing techniques are metric-oriented. The pipeline generates adversarial examples as test cases via such a DL testing technique and retrains the DL model under test with test suites that contain these test cases. On the one hand, the strategies of these fuzzing techniques tightly integrate the key characteristics of their testing metrics. On the other hand, they are often unaware of whether their generated test cases are different from the samples surrounding these test cases and whether there are relevant test cases of other seeds when generating the current one. We propose a novel testing metric called Contextual Confidence (CC). CC measures a test case through the surrounding samples of a test case in terms of their mean probability predicted to the prediction label of the test case. Based on this metric, we further propose a novel fuzzing technique Clover as a DL testing technique for the pipeline. In each fuzzing round, Clover first finds a set of seeds whose labels are the same as the label of the seed under fuzzing. At the same time, it locates the corresponding test case that achieves the highest CC values among the existing test cases of each seed in this set of seeds and shares the same prediction label as the existing test case of the seed under fuzzing that achieves the highest CC value. Clover computes the piece of difference between each such pair of a seed and a test case. It incrementally applies these pieces of differences to perturb the current test case of the seed under fuzzing that achieves the highest CC value and to perturb the resulting samples along the gradient to generate new test cases for the seed under fuzzing. Clover finally selects test cases among the generated test cases of all seeds as much as possible and with a preference to select test cases with higher CC values for improving model robustness. The experiments show that Clover outperforms the state-of-the-art coverage-based technique Adapt and loss-based fuzzing technique RobOT by 67%–129% and 48%–100% in terms of robustness improvement ratio, respectively, delivered through the same testing-retraining pipeline. For test case generation, in terms of numbers of unique adversarial labels and unique categories for the constructed test suites, Clover outperforms Adapt by \(2.0\times\) and \(3.5\times\) and RobOT by \(1.6\times\) and \(1.7\times\) on fuzzing clean models, and also outperforms Adapt by \(3.4\times\) and \(4.5\times\) and RobOT by \(9.8\times\) and \(11.0\times\) on fuzzing adversarially trained models, respectively. Haipeng Wang 0005, Zhengyuan Wei, Qilin Zhou, Wing Kwong Chan |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2024 | High-Efficiency FPGA - Based Approximate Multipliers with LUT Sharing and Carry SwitchingabstractApproximate multiplier saves energy and improves hardware performance for error-tolerant computation-intensive applications. This work proposes hardware-efficient FPGA-based approximate multipliers with look-up table (LUT) sharing and carry switching. Sharing two LUTs with the same inputs enables to fully utilize the available LUT resources. To mitigate the accuracy loss incurred from this approach, the truncated carry is partially reserved by switching it to the adjacent calculation. In addition, we create a library of 8×8 approximate multipliers to provide various multiplication choices. The proposed design can provide enhancements of up to 38.75% in power, 17.29% in latency, and 28.17% in area compared to the Xilinx exact multiplier. Our proposed designs are open-source at https://github.com/YnuGuoLab/DATE_FPGA_Approx_Mul and assist in further reproducing and development. Qilin Zhou, Xiu Chen, Heming Sun |
DATE | 2 |
| 2024 | Power-Efficient and Small-Area Approximate Multiplier Design with FPGA-Based CompressorsabstractApproximate computing has become an emerging technique to reduce power consumption. In numerous applications, multiplication is a crucial operation, designing it for approximation is effective in optimizing system performance. In this paper, we propose low-power FPGA-based multipliers by employing the novel compressor designs. Given that the compressor is the primary unit in the multiplier, we introduce novel exact and approximate compressors with low-complexity circuits to parallelly accumulate the elements. To flexibly configure the proposed compressors, a compressor-based once-through structure is proposed to 8×8 multipliers. Two variants of the approximate multipliers are provided with different accuracy-hardware trade-offs. Compared with the exact multiplier, the proposed approximate multiplier reduces power by 57.90%, area by 33.80%, and delay by 24.78%. With a similar accuracy loss, the proposed designs save more hardware resources than others. In addition, the effectiveness of approximate multipliers is assessed in image sharpening. Yi Guo 0010, Xiu Chen, Qilin Zhou, Heming Sun |
ISCAS | 3 |
| 2024 | Delving into Parameter-Efficient Fine-Tuning in Code Change Learning: An Empirical StudyabstractCompared to Full-Model Fine-Tuning (FMFT), Parameter Efficient Fine-Tuning (PEFT) has demonstrated superior performance and lower computational overhead in several code understanding tasks, such as code summarization and code search. This advantage can be attributed to PEFT's ability to alleviate the catastrophic forgetting issue of Pre-trained Language Models (PLMs) by updating only a small number of parameters. As a result, PEFT effectively harnesses the pre-trained general-purpose knowledge for downstream tasks. However, existing studies primarily involve static code comprehension, aligning with the pre-training paradigm of recent PLMs and facilitating knowledge transfer, but they do not account for dynamic code changes. Thus, it remains unclear whether PEFT outperforms FMFT in task-specific adaptation for code-change-related tasks. To address this question, we examine two prevalent PEFT methods, namely Adapter Tuning (AT) and Low-Rank Adaptation (LoRA), and compare their performance with FMFT on five popular PLMs. Specifically, we evaluate their performance on two widely-studied code-change-related tasks: Just-In-Time Defect Prediction (JIT-DP) and Commit Message Generation (CMG). The results demonstrate that both AT and LoRA achieve state-of-the-art (SOTA) results in JIT-DP and exhibit comparable performances in CMG when compared to FMFT and other SOTA approaches. Furthermore, AT and LoRA exhibit superiority in cross-lingual and low-resource scenarios. We also conduct three probing tasks to explain the efficacy of PEFT techniques on JIT-DP and CMG tasks from both static and dynamic perspectives. The study indicates that PEFT, particularly through the use of AT and LoRA, offers promising advantages in code-change-related tasks, surpassing FMFT in certain aspects. This research contributes to a deeper understanding of the capabilities of PEFT in leveraging pre-trained PLMs for dynamic code changes. The replication package is available at https://github.com/ishuoliu/PEFT4CC. Shuo Liu 0020, Jacky W. Keung, Zhen Yang 0022, Fang Liu 0032, Qilin Zhou, Yihan Liao |
SANER | 5 |
| 2024 | Hardware-Efficient Multipliers With FPGA-Based Approximation for Error-Resilient ApplicationsabstractApproximate multipliers enable hardware savings for error-resilient computation-intensive applications. Most existing approximate multipliers have been on ASIC-based circuits. They might not achieve comparable performance gains when used for FPGA-based accelerators. In this paper, we propose hardware-efficient FPGA-based accurate and approximate$4\boldsymbol {\times }4$multipliers with novel methodologies of look-up table (LUT) sharing and carry switching. The LUT resources can be fully utilized by sharing two LUTs with the same inputs. To compensate for the accuracy loss, the truncated carry is partially reserved by switching it to the adjacent calculation. For higher-order multipliers, three approximate adders are proposed to sum the result of the multipliers with arbitrary size. 140 types of$8\boldsymbol {\times }8$multipliers are constructed by combining the proposed$4\boldsymbol {\times }4$multipliers and adders, providing various multiplication choices for different demands. The proposed approximate$8\boldsymbol {\times }8$multiplier can achieve up to 38.75%, 17.29%, and 28.17% improvements in power, latency, and area over the Xilinx exact multiplier, respectively. Moreover, the proposed accurate and approximate$8\boldsymbol {\times }8$multipliers with different adders are extended to$16\boldsymbol {\times }16$multipliers. As evidenced by the performance of the$16\boldsymbol {\times }16$multipliers, our methodology demonstrates the capability to design higher-order multipliers flexibly. Compared with previous works under a similar accuracy loss, the proposed multiplier achieves more hardware savings. Furthermore, the approximate multipliers are assessed on the application of image processing to validate the practical applicability. We create a library of the proposed multipliers which is open-source athttps://github.com/YnuGuoLab/Approx_Mul_FPGA/and assist in further reproducing and development. Qilin Zhou, Xiu Chen, Heming Sun |
IEEE Trans. Circuits Syst. I Regul. Pap. | 2 |
| 2023 | A Majority Invariant Approach to Patch Robustness Certification for Deep Learning ModelsabstractPatch robustness certification ensures no patch within a given bound on a sample can manipulate a deep learning model to predict a different label. However, existing techniques cannot certify samples that cannot meet their strict bars at the classifier level or the patch region level. This paper proposes MajorCert. MajorCert firstly finds all possible label sets manipulatable by the same patch region on the same sample across the underlying classifiers, then enumerates their combinations element-wise, and finally checks whether the majority invariant of all these combinations is intact to certify samples. Qilin Zhou, Zhengyuan Wei, Haipeng Wang 0005, Wing Kwong Chan |
ASE | 1 |
| 2023 | Aster: Encoding Data Augmentation Relations into Seed Test Suites for Robustness Assessment and Fuzzing of Data-Augmented Deep Learning ModelsabstractData-augmented deep learning models are widely used in real-world applications. However, many state-of the-art loss-based or coverage-based fuzzing techniques fail to produce fuzzing samples for them from many seeds. This paper proposes Aster, a novel technique to address this problem to enhance their fuzzing effectiveness for deep learning models trained with multi-sample data augmentation methods. Aster formulates a novel reachability-based strategy to encode the insights of every seed’s direct and indirect data augmentation relation instances into the replacement seed of that seed systematically. Our experiment shows that Aster is highly effective. On average, loss-based and coverage-based fuzzing techniques can generate 166% and 110% more fuzzing samples and reduce 31% and 22% unsuccessful seeds, respectively, after adopting the replacement seeds generated by Aster to replace their original seeds. Their improved models also become up to 55% and 40% on average more robust against FGSM and PGD attacks in the experiment. Haipeng Wang 0005, Zhengyuan Wei, Qilin Zhou, Bo Jiang 0001, Wing Kwong Chan |
QRS | 3 |