Zhehao Huang

dblp:258/1555 · DBLP profile ↗
← Back
8ranked-venue papers
1as first author
7since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 7 · 1 first-author · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Artificial intelligence
6 papers
Trustworthy machine learning · 58% Deep learning architectures and training · 14% Efficient and distributed learning · 12%

Topics — the 15 heaviest of 17, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Machine learning › Trustworthy machine learning
machine unlearning
1.622025
Towards Natural Machine Unlearning · IEEE Trans. Pattern Anal. Mach. Intell. 2025
Unified Gradient-Based Machine Unlearning with Remain Geometry Enhancement · NeurIPS 2024
Machine learning › Trustworthy machine learning
privacy and data protection
0.912025
Towards Natural Machine Unlearning · IEEE Trans. Pattern Anal. Mach. Intell. 2025
Machine learning › Trustworthy machine learning › privacy
privacy and memorization
0.912025
Simulating Training Dynamics to Reconstruct Training Data from Deep Neural Networks · ICLR 2025
Machine learning › Trustworthy machine learning › privacy › privacy attack
training data reconstruction
0.912025
Simulating Training Dynamics to Reconstruct Training Data from Deep Neural Networks · ICLR 2025
Machine learning › Trustworthy machine learning
privacy
0.812024
Unified Gradient-Based Machine Unlearning with Remain Geometry Enhancement · NeurIPS 2024
Machine learning › Optimization for machine learning
second-order optimization
0.812024
Unified Gradient-Based Machine Unlearning with Remain Geometry Enhancement · NeurIPS 2024
Machine learning › Representation and self-supervised learning › representation learning
dimensionality reduction
0.712023
Low Dimensional Trajectory Hypothesis is True: DNNs Can Be Trained in Tiny Subspaces · IEEE Trans. Pattern Anal. Mach. Intell. 2023
Machine learning › Efficient and distributed learning
efficient training
0.712023
Trainable Weight Averaging: Efficient Training by Optimizing Historical Solutions · ICLR 2023
Machine learning › Efficient and distributed learning
model compression
0.712023
Low Dimensional Trajectory Hypothesis is True: DNNs Can Be Trained in Tiny Subspaces · IEEE Trans. Pattern Anal. Mach. Intell. 2023
Machine learning › Deep learning architectures and training
weight averaging
0.712023
Trainable Weight Averaging: Efficient Training by Optimizing Historical Solutions · ICLR 2023
Machine learning › Trustworthy machine learning › robustness
adversarial robustness
0.612022
Adversarial Attack on Attackers: Post-Process to Mitigate Black-Box Score-Based Query Attacks · NeurIPS 2022
Machine learning › Generative modeling
diffusion model
0.212024
Unified Gradient-Based Machine Unlearning with Remain Geometry Enhancement · NeurIPS 2024
Machine learning › Trustworthy machine learning › robustness › learning with noisy labels
robustness to label noise
0.212023
Low Dimensional Trajectory Hypothesis is True: DNNs Can Be Trained in Tiny Subspaces · IEEE Trans. Pattern Anal. Mach. Intell. 2023
Machine learning › Trustworthy machine learning › calibration
confidence calibration
0.212022
Adversarial Attack on Attackers: Post-Process to Mitigate Black-Box Score-Based Query Attacks · NeurIPS 2022
Machine learning › Trustworthy machine learning
uncertainty estimation
0.212022
Adversarial Attack on Attackers: Post-Process to Mitigate Black-Box Score-Based Query Attacks · NeurIPS 2022

Methods — techniques the papers use, named apart from their topics

training dynamics simulation · 0.9relabeling · 0.9optimization · 0.9fine-tuning · 0.9kullback-leibler divergence · 0.8hessian approximation · 0.8fast-slow parameter update · 0.8weight averaging · 0.7stochastic optimization · 0.7dynamic linear dimensionality reduction · 0.7
YearPublicationVenuePosition
2025 Dynamic Ring Signature: Towards Provable Anonymity in Blockchain-Based E-Voting
Shan Jiang 0005, Zhehao Huang, Shichang Xuan, Jiaxing Shen, Huakun Huang, Xiaojie Zhu
ICA3PP (8)2
2025 Simulating Training Dynamics to Reconstruct Training Data from Deep Neural Networks
abstract
Whether deep neural networks (DNNs) memorize the training data is a fundamental open question in understanding deep learning. A direct way to verify the memorization of DNNs is to reconstruct training data from DNNs’ parameters. Since parameters are gradually determined by data throughout training, characterizing training dynamics is important for reconstruction. Pioneering works rely on the linear training dynamics of shallow NNs with large widths, but cannot be extended to more practical DNNs which have non-linear dynamics. We propose Simulation of training Dynamics (SimuDy) to reconstruct training data from DNNs. Specifically, we simulate the training dynamics by training the model from the initial parameters with a dummy dataset, then optimize this dummy dataset so that the simulated dynamics reach the same final parameters as the true dynamics. By incorporating dummy parameters in the simulated dynamics, SimuDy effectively describes non-linear training dynamics. Experiments demonstrate that SimuDy significantly outperforms previous approaches when handling non-linear training dynamics, and for the first time, most training samples can be reconstructed from a trained ResNet’s parameters.
Hanling Tian, Yuhang Liu 0003, Mingzhen He, Zhengbao He, Zhehao Huang, Ruikai Yang, Xiaolin Huang
ICLR5
2025 Towards Natural Machine Unlearning
abstract
Machine unlearning (MU) aims to eliminate information that has been learned from specific training data, namely forgetting data, from a pretrained model. Currently, the mainstream of relabeling-based MU methods involves modifying the forgetting data with incorrect labels and subsequently fine-tuning the model. While learning such incorrect information can indeed remove knowledge, the process is quite unnatural as the unlearning process undesirably reinforces the incorrect information and leads to over-forgetting. Towards more natural machine unlearning, we inject correct information from the remaining data to the forgetting samples when changing their labels. Through pairing these adjusted samples with their labels, the model tends to use the injected correct information and naturally suppresses the information meant to be forgotten. Albeit straightforward, such a first step towards natural machine unlearning can significantly outperform current state-of-the-art approaches. In particular, our method substantially reduces the over-forgetting problem and leads to strong robustness across different unlearning tasks, making it a promising candidate for practical machine unlearning.
Zhengbao He, Tao Li 0054, Xinwen Cheng, Zhehao Huang, Xiaolin Huang
IEEE Trans. Pattern Anal. Mach. Intell.4
2024 Unified Gradient-Based Machine Unlearning with Remain Geometry Enhancement
abstract
Machine unlearning (MU) has emerged to enhance the privacy and trustworthiness of deep neural networks. Approximate MU is a practical method for large-scale models. Our investigation into approximate MU starts with identifying the steepest descent direction, minimizing the output Kullback-Leibler divergence to exact MU inside a parameters' neighborhood. This probed direction decomposes into three components: weighted forgetting gradient ascent, fine-tuning retaining gradient descent, and a weight saliency matrix. Such decomposition derived from Euclidean metric encompasses most existing gradient-based MU methods. Nevertheless, adhering to Euclidean space may result in sub-optimal iterative trajectories due to the overlooked geometric structure of the output probability space. We suggest embedding the unlearning update into a manifold rendered by the remaining geometry, incorporating second-order Hessian from the remaining data. It helps prevent effective unlearning from interfering with the retained performance. However, computing the second-order Hessian for large-scale models is intractable. To efficiently leverage the benefits of Hessian modulation, we propose a fast-slow parameter update strategy to implicitly approximate the up-to-date salient unlearning direction. Free from specific modal constraints, our approach is adaptable across computer vision unlearning tasks, including classification and generation. Extensive experiments validate our efficacy and efficiency. Notably, our method successfully performs class-forgetting on ImageNet using DiT and forgets a class on CIFAR-10 using DDPM in just 50 steps, compared to thousands of steps required by previous methods. Code is available at [Unified-Unlearning-w-Remain-Geometry](https://github.com/K1nght/Unified-Unlearning-w-Remain-Geometry).
Zhehao Huang, Xinwen Cheng, JingHao Zheng, Zhengbao He, Xiaolin Huang
NeurIPS1
2023 Trainable Weight Averaging: Efficient Training by Optimizing Historical Solutions
Tao Li 0054, Zhehao Huang, Qinghua Tao, Yingwen Wu, Xiaolin Huang
ICLR2
2023 Low Dimensional Trajectory Hypothesis is True: DNNs Can Be Trained in Tiny Subspaces
abstract
Deep neural networks (DNNs) usually contain massive parameters, but there is redundancy such that it is guessed that they could be trained in low-dimensional subspaces. In this paper, we propose a Dynamic Linear Dimensionality Reduction (DLDR) based on the low-dimensional properties of the training trajectory. The reduction method is efficient, supported by comprehensive experiments: optimizing DNNs in 40-dimensional spaces can achieve comparable performance as regular training over thousands or even millions of parameters. Since there are only a few variables to optimize, we develop an efficient quasi-Newton-based algorithm, obtain robustness to label noise, and improve the performance of well-trained models, which are three follow-up experiments that can show the advantages of finding such low-dimensional subspaces. The code is released (Pytorch: https://github.com/nblt/DLDR and Mindspore: https://gitee.com/mindspore/docs/tree/r1.6/docs/sample_code/dimension_reduce_training).
Tao Li 0054, Zhehao Huang, Qinghua Tao, Yipeng Liu 0001, Xiaolin Huang
IEEE Trans. Pattern Anal. Mach. Intell.3
2022 Adversarial Attack on Attackers: Post-Process to Mitigate Black-Box Score-Based Query Attacks
abstract
The score-based query attacks (SQAs) pose practical threats to deep neural networks by crafting adversarial perturbations within dozens of queries, only using the model's output scores. Nonetheless, we note that if the loss trend of the outputs is slightly perturbed, SQAs could be easily misled and thereby become much less effective. Following this idea, we propose a novel defense, namely Adversarial Attack on Attackers (AAA), to confound SQAs towards incorrect attack directions by slightly modifying the output logits. In this way, (1) SQAs are prevented regardless of the model's worst-case robustness; (2) the original model predictions are hardly changed, i.e., no degradation on clean accuracy; (3) the calibration of confidence scores can be improved simultaneously. Extensive experiments are provided to verify the above advantages. For example, by setting $\ell_\infty=8/255$ on CIFAR-10, our proposed AAA helps WideResNet-28 secure 80.59% accuracy under Square attack (2500 queries), while the best prior defense (i.e., adversarial training) only attains 67.44%. Since AAA attacks SQA's general greedy strategy, such advantages of AAA over 8 defenses can be consistently observed on 8 CIFAR-10/ImageNet models under 6 SQAs, using different attack targets, bounds, norms, losses, and strategies. Moreover, AAA calibrates better without hurting the accuracy. Our code is available at https://github.com/Sizhe-Chen/AAA.
Sizhe Chen, Zhehao Huang, Qinghua Tao, Yingwen Wu, Cihang Xie, Xiaolin Huang
NeurIPS2
2020 Inequalities and stability of stochastic Hopfield neural networks with discrete and distributed delays
Dehao Ruan, Zhehao Huang, Xiaoxia Guo
Neurocomputing2