Minseon Kim

dblp:247/5952 · DBLP profile ↗
← Back
10ranked-venue papers
2as first author
8since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 10 · 2 first-author · 8 since 2021Graphics, computer vision, multimedia, augmented reality and games · 2 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
8 papers
Trustworthy machine learning · 26% Efficient and distributed learning · 20% Language models and text generation · 17%

Topics — the 18 heaviest of 21, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
1.732023
Effective Targeted Attacks for Adversarial Self-Supervised Learning · NeurIPS 2023
Consistency Regularization for Adversarial Robustness · AAAI 2022
Adversarial Self-Supervised Contrastive Learning · NeurIPS 2020
Machine learning › Efficient and distributed learning › automated machine learning
neural architecture search
1.322023
Generalizable Lightweight Proxy for Robust NAS against Diverse Perturbations · NeurIPS 2023
Meta-prediction Model for Distillation-Aware NAS on Unseen Datasets · ICLR 2023
Machine learning › Trustworthy machine learning
robustness
1.222023
Generalizable Lightweight Proxy for Robust NAS against Diverse Perturbations · NeurIPS 2023
Consistency Regularization for Adversarial Robustness · AAAI 2022
Natural language and speech › Language models and text generation
code generation
0.912025
Learning to Solve Complex Problems via Dataset Decomposition · NeurIPS 2025
Machine learning › Learning paradigms
curriculum learning
0.912025
Learning to Solve Complex Problems via Dataset Decomposition · NeurIPS 2025
Machine learning › Representation and self-supervised learning › representation learning › unsupervised representation learning › self-supervised representation learning
adversarial self-supervised learning
0.712023
Effective Targeted Attacks for Adversarial Self-Supervised Learning · NeurIPS 2023
Natural language and speech › Language models and text generation
controllable text generation
0.712023
Language Detoxification with Attribute-Discriminative Latent Space · ACL (1) 2023
Natural language and speech › Language models and text generation › large language model safety
detoxification
0.712023
Language Detoxification with Attribute-Discriminative Latent Space · ACL (1) 2023
Machine learning › Representation and self-supervised learning › latent space
latent space manipulation
0.712023
Language Detoxification with Attribute-Discriminative Latent Space · ACL (1) 2023
Machine learning › Efficient and distributed learning › automated machine learning › neural architecture search
robust architecture search
0.712023
Generalizable Lightweight Proxy for Robust NAS against Diverse Perturbations · NeurIPS 2023
Machine learning › Efficient and distributed learning › automated machine learning › neural architecture search
zero-cost proxy
0.712023
Generalizable Lightweight Proxy for Robust NAS against Diverse Perturbations · NeurIPS 2023
Machine learning › Learning paradigms › semi-supervised learning
consistency regularization
0.612022
Consistency Regularization for Adversarial Robustness · AAAI 2022
Machine learning › Deep learning architectures and training
regularization
0.612022
Consistency Regularization for Adversarial Robustness · AAAI 2022
Machine learning › Representation and self-supervised learning › contrastive learning › robust contrastive learning
adversarial contrastive learning
0.412020
Adversarial Self-Supervised Contrastive Learning · NeurIPS 2020
Machine learning › Representation and self-supervised learning
contrastive learning
0.412020
Adversarial Self-Supervised Contrastive Learning · NeurIPS 2020
Machine learning › Trustworthy machine learning › robustness › adversarial robustness › adversarial training
self-supervised adversarial training
0.412020
Adversarial Self-Supervised Contrastive Learning · NeurIPS 2020
Machine learning › Transfer learning and domain adaptation
meta-learning
0.212023
Meta-prediction Model for Distillation-Aware NAS on Unseen Datasets · ICLR 2023
Machine learning › Transfer learning and domain adaptation
robust transfer learning
0.112020
Adversarial Self-Supervised Contrastive Learning · NeurIPS 2020

Methods — techniques the papers use, named apart from their topics

adversarial training · 1.0teacher-student framework · 0.9step-by-step reasoning · 0.9large language model · 0.9dataset decomposition · 0.9projection · 0.7one-shot NAS · 0.7meta-prediction · 0.7knowledge distillation · 0.7attribute discriminator · 0.7
YearPublicationVenuePosition
2025 FLUID QA: A Multilingual Benchmark for Figurative Language Usage in Dialogue across English, Chinese, and Korean
abstract
Figurative language conveys stance, emotion, and social nuance, making its appropriate use essential in dialogue.While large language models (LLMs) often succeed in recognizing figurative expressions at the sentence level, their ability to use them coherently in conversation remains uncertain.We introduce FLUID QA, the first multilingual benchmark that evaluates figurative usage in dialogue across English, Korean, and Chinese.Each item embeds figurative choices into multi-turn contexts.To support interpretation, we include FLUTE-bi, a sentence-level diagnostic task.Results reveal a persistent gap: models that perform well on FLUTE-bi frequently fail on FLUID QA, especially in sarcasm and metaphor.These errors reflect systematic rhetorical confusion and limited discourse reasoning.FLUID QA provides a scalable framework for assessing usage-level figurative competence across languages.
Seoyoon Park, Hyeji Choi, Minseon Kim, Subin An, Gyuri Choi, Hansaem Kim
EMNLP3
2025 BlurGuard: A Simple Approach for Robustifying Image Protection Against AI-Powered Editing
abstract
Recent advances in text-to-image models have increased the exposure of powerful image editing techniques as a tool, raising concerns about their potential for malicious use. An emerging line of research to address such threats focuses on implanting “protective” adversarial noise into images before their public release, so future attempts to edit them using text-to-image models can be impeded. However, subsequent works have shown that these adversarial noises are often easily “reversed,” e.g., with techniques as simple as JPEG compression, casting doubt on the practicality of the approach. In this paper, we argue that adversarial noise for image protection should not only be imperceptible, as has been a primary focus of prior work, but also irreversible, viz., it should be difficult to detect as noise provided that the original image is hidden. We propose a surprisingly simple method to enhance the robustness of image protection methods against noise reversal techniques. Specifically, it applies an adaptive per-region Gaussian blur on the noise to adjust the overall frequency spectrum. Through extensive experiments, we show that our method consistently improves the per-sample worst-case protection performance of existing methods against a wide range of reversal techniques on diverse image editing scenarios, while also reducing quality degradation due to noise in terms of perceptual metrics. Code is available at https://github.com/jsu-kim/BlurGuard.
Yunhun Nam, Minseon Kim, Sangpil Kim, Jongheon Jeong
NeurIPS3
2025 Learning to Solve Complex Problems via Dataset Decomposition
abstract
Curriculum learning is a class of training strategies that organizes the data being exposed to a model by difficulty, gradually from simpler to more complex examples. This research explores a reverse curriculum generation approach that recursively decomposes complex datasets into simpler, more learnable components. We propose a teacher-student framework where the teacher is equipped with the ability to reason step-by-step, which is used to recursively generate easier versions of examples, enabling the student model to progressively master difficult tasks. We propose a novel scoring system to measure data difficulty based on its structural complexity and conceptual depth, allowing curriculum construction over decomposed data. Experiments on math datasets (MATH and AIME) and code generation datasets demonstrate that models trained with curricula generated by our approach exhibit superior performance compared to standard training on original datasets.
Wanru Zhao, Lucas Caccia, Zhengyan Shi, Minseon Kim, Weijia Xu, Alessandro Sordoni
NeurIPS4
2023 Language Detoxification with Attribute-Discriminative Latent Space
abstract
Transformer-based Language Models (LMs) have achieved impressive results on natural language understanding tasks, but they can also generate toxic text such as insults, threats, and profanity, limiting their real-world applications.To overcome this issue, a few text generation approaches aim to detoxify toxic texts using additional LMs or perturbations.However, previous methods require excessive memory, computations, and time which are serious bottlenecks in their real-world application.To address such limitations, we propose an effective yet efficient method for language detoxification using an attribute-discriminative latent space.Specifically, we project the latent space of an original Transformer LM onto a discriminative latent space that well-separates texts by their attributes using a projection block and an attribute discriminator.This allows the LM to control the text generation to be nontoxic with minimal memory and computation overhead.We validate our model, Attribute-Discriminative Language Model (ADLM) on detoxified language and dialogue generation tasks, on which our method significantly outperforms baselines both in performance and efficiency.
Jin Myung Kwak, Minseon Kim, Sung Ju Hwang
ACL (1)2
2023 Meta-prediction Model for Distillation-Aware NAS on Unseen Datasets
Hayeon Lee, Sohyun An, Minseon Kim, Sung Ju Hwang
ICLR3
2023 Generalizable Lightweight Proxy for Robust NAS against Diverse Perturbations
abstract
Recent neural architecture search (NAS) frameworks have been successful in finding optimal architectures for given conditions (e.g., performance or latency). However, they search for optimal architectures in terms of their performance on clean images only, while robustness against various types of perturbations or corruptions is crucial in practice. Although there exist several robust NAS frameworks that tackle this issue by integrating adversarial training into one-shot NAS, however, they are limited in that they only consider robustness against adversarial attacks and require significant computational resources to discover optimal architectures for a single task, which makes them impractical in real-world scenarios. To address these challenges, we propose a novel lightweight robust zero-cost proxy that considers the consistency across features, parameters, and gradients of both clean and perturbed images at the initialization state. Our approach facilitates an efficient and rapid search for neural architectures capable of learning generalizable features that exhibit robustness across diverse perturbations. The experimental results demonstrate that our proxy can rapidly and efficiently search for neural architectures that are consistently robust against various perturbations on multiple benchmark datasets and diverse search spaces, largely outperforming existing clean zero-shot NAS and robust NAS with reduced search cost.
Hyeonjeong Ha, Minseon Kim, Sung Ju Hwang
NeurIPS2
2023 Effective Targeted Attacks for Adversarial Self-Supervised Learning
abstract
Recently, unsupervised adversarial training (AT) has been highlighted as a means of achieving robustness in models without any label information. Previous studies in unsupervised AT have mostly focused on implementing self-supervised learning (SSL) frameworks, which maximize the instance-wise classification loss to generate adversarial examples. However, we observe that simply maximizing the self-supervised training loss with an untargeted adversarial attack often results in generating ineffective adversaries that may not help improve the robustness of the trained model, especially for non-contrastive SSL frameworks without negative examples. To tackle this problem, we propose a novel positive mining for targeted adversarial attack to generate effective adversaries for adversarial SSL frameworks. Specifically, we introduce an algorithm that selects the most confusing yet similar target example for a given instance based on entropy and similarity, and subsequently perturbs the given instance towards the selected target. Our method demonstrates significant enhancements in robustness when applied to non-contrastive SSL frameworks, and less but consistent robustness improvements with contrastive SSL frameworks, on the benchmark datasets.
Minseon Kim, Hyeonjeong Ha, Sooel Son, Sung Ju Hwang
NeurIPS1
2022 Consistency Regularization for Adversarial Robustness
abstract
Adversarial training (AT) is currently one of the most successful methods to obtain the adversarial robustness of deep neural networks. However, the phenomenon of robust overfitting, i.e., the robustness starts to decrease significantly during AT, has been problematic, not only making practitioners consider a bag of tricks for a successful training, e.g., early stopping, but also incurring a significant generalization gap in the robustness. In this paper, we propose an effective regularization technique that prevents robust overfitting by optimizing an auxiliary `consistency' regularization loss during AT. Specifically, we discover that data augmentation is a quite effective tool to mitigate the overfitting in AT, and develop a regularization that forces the predictive distributions after attacking from two different augmentations of the same instance to be similar with each other. Our experimental results demonstrate that such a simple regularization technique brings significant improvements in the test robust accuracy of a wide range of AT methods. More remarkably, we also show that our method could significantly help the model to generalize its robustness against unseen adversaries, e.g., other types or larger perturbations compared to those used during training. Code is available at https://github.com/alinlab/consistency-adversarial.
Jihoon Tack, Sihyun Yu, Jongheon Jeong, Minseon Kim, Sung Ju Hwang, Jinwoo Shin
AAAI4
2020 Adversarial Self-Supervised Contrastive Learning
abstract
Existing adversarial learning approaches mostly use class labels to generate adversarial samples that lead to incorrect predictions, which are then used to augment the training of the model for improved robustness. While some recent works propose semi-supervised adversarial learning methods that utilize unlabeled data, they still require class labels. However, do we really need class labels at all, for adversarially robust training of deep neural networks? In this paper, we propose a novel adversarial attack for unlabeled data, which makes the model confuse the instance-level identities of the perturbed data samples. Further, we present a self-supervised contrastive learning framework to adversarially train a robust neural network without labeled data, which aims to maximize the similarity between a random augmentation of a data sample and its instance-wise adversarial perturbation. We validate our method, Robust Contrastive Learning (RoCL), on multiple benchmark datasets, on which it obtains comparable robust accuracy over state-of-the-art supervised adversarial learning methods, and significantly improved robustness against the \emph{black box} and unseen types of attacks. Moreover, with further joint fine-tuning with supervised adversarial loss, RoCL obtains even higher robust accuracy over using self-supervised learning alone. Notably, RoCL also demonstrate impressive results in robust transfer learning.
Minseon Kim, Jihoon Tack, Sung Ju Hwang
NeurIPS1
2019 Progressive Face Super-Resolution via Attention to Facial Landmark
Deokyun Kim, Minseon Kim, Gihyun Kwon, Dae-Shik Kim
BMVC2