VLDB 2026 Research / reviewers in the wild / expert
Zhehao Huang
dblp:258/1555
· DBLP profile ↗
8ranked-venue papers
1as first author
7since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 7 · 1 first-author · 6 since 2021Systems, architecture and hardware · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
6 papers |
Trustworthy machine learning · 58% Deep learning architectures and training · 14% Efficient and distributed learning · 12% |
Topics — the 15 heaviest of 17, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Trustworthy machine learning
machine unlearning |
1.6 | 2 | 2025 | Towards Natural Machine Unlearning · IEEE Trans. Pattern Anal. Mach. Intell. 2025 Unified Gradient-Based Machine Unlearning with Remain Geometry Enhancement · NeurIPS 2024 |
Machine learning › Trustworthy machine learning
privacy and data protection |
0.9 | 1 | 2025 | Towards Natural Machine Unlearning · IEEE Trans. Pattern Anal. Mach. Intell. 2025 |
Machine learning › Trustworthy machine learning › privacy
privacy and memorization |
0.9 | 1 | 2025 | Simulating Training Dynamics to Reconstruct Training Data from Deep Neural Networks · ICLR 2025 |
Machine learning › Trustworthy machine learning › privacy › privacy attack
training data reconstruction |
0.9 | 1 | 2025 | Simulating Training Dynamics to Reconstruct Training Data from Deep Neural Networks · ICLR 2025 |
Machine learning › Trustworthy machine learning
privacy |
0.8 | 1 | 2024 | Unified Gradient-Based Machine Unlearning with Remain Geometry Enhancement · NeurIPS 2024 |
Machine learning › Optimization for machine learning
second-order optimization |
0.8 | 1 | 2024 | Unified Gradient-Based Machine Unlearning with Remain Geometry Enhancement · NeurIPS 2024 |
Machine learning › Representation and self-supervised learning › representation learning
dimensionality reduction |
0.7 | 1 | 2023 | Low Dimensional Trajectory Hypothesis is True: DNNs Can Be Trained in Tiny Subspaces · IEEE Trans. Pattern Anal. Mach. Intell. 2023 |
Machine learning › Efficient and distributed learning
efficient training |
0.7 | 1 | 2023 | Trainable Weight Averaging: Efficient Training by Optimizing Historical Solutions · ICLR 2023 |
Machine learning › Efficient and distributed learning
model compression |
0.7 | 1 | 2023 | Low Dimensional Trajectory Hypothesis is True: DNNs Can Be Trained in Tiny Subspaces · IEEE Trans. Pattern Anal. Mach. Intell. 2023 |
Machine learning › Deep learning architectures and training
weight averaging |
0.7 | 1 | 2023 | Trainable Weight Averaging: Efficient Training by Optimizing Historical Solutions · ICLR 2023 |
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
0.6 | 1 | 2022 | Adversarial Attack on Attackers: Post-Process to Mitigate Black-Box Score-Based Query Attacks · NeurIPS 2022 |
Machine learning › Generative modeling
diffusion model |
0.2 | 1 | 2024 | Unified Gradient-Based Machine Unlearning with Remain Geometry Enhancement · NeurIPS 2024 |
Machine learning › Trustworthy machine learning › robustness › learning with noisy labels
robustness to label noise |
0.2 | 1 | 2023 | Low Dimensional Trajectory Hypothesis is True: DNNs Can Be Trained in Tiny Subspaces · IEEE Trans. Pattern Anal. Mach. Intell. 2023 |
Machine learning › Trustworthy machine learning › calibration
confidence calibration |
0.2 | 1 | 2022 | Adversarial Attack on Attackers: Post-Process to Mitigate Black-Box Score-Based Query Attacks · NeurIPS 2022 |
Machine learning › Trustworthy machine learning
uncertainty estimation |
0.2 | 1 | 2022 | Adversarial Attack on Attackers: Post-Process to Mitigate Black-Box Score-Based Query Attacks · NeurIPS 2022 |
Methods — techniques the papers use, named apart from their topics
training dynamics simulation · 0.9relabeling · 0.9optimization · 0.9fine-tuning · 0.9kullback-leibler divergence · 0.8hessian approximation · 0.8fast-slow parameter update · 0.8weight averaging · 0.7stochastic optimization · 0.7dynamic linear dimensionality reduction · 0.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Dynamic Ring Signature: Towards Provable Anonymity in Blockchain-Based E-Voting
Shan Jiang 0005, Zhehao Huang, Shichang Xuan, Jiaxing Shen, Huakun Huang, Xiaojie Zhu |
ICA3PP (8) | 2 |
| 2025 | Simulating Training Dynamics to Reconstruct Training Data from Deep Neural NetworksabstractWhether deep neural networks (DNNs) memorize the training data is a fundamental open question in understanding deep learning. A direct way to verify the memorization of DNNs is to reconstruct training data from DNNs’ parameters. Since parameters are gradually determined by data throughout training, characterizing training dynamics is important for reconstruction. Pioneering works rely on the linear training dynamics of shallow NNs with large widths, but cannot be extended to more practical DNNs which have non-linear dynamics. We propose Simulation of training Dynamics (SimuDy) to reconstruct training data from DNNs. Specifically, we simulate the training dynamics by training the model from the initial parameters with a dummy dataset, then optimize this dummy dataset so that the simulated dynamics reach the same final parameters as the true dynamics. By incorporating dummy parameters in the simulated dynamics, SimuDy effectively describes non-linear training dynamics. Experiments demonstrate that SimuDy significantly outperforms previous approaches when handling non-linear training dynamics, and for the first time, most training samples can be reconstructed from a trained ResNet’s parameters. Hanling Tian, Yuhang Liu 0003, Mingzhen He, Zhengbao He, Zhehao Huang, Ruikai Yang, Xiaolin Huang |
ICLR | 5 |
| 2025 | Towards Natural Machine UnlearningabstractMachine unlearning (MU) aims to eliminate information that has been learned from specific training data, namely forgetting data, from a pretrained model. Currently, the mainstream of relabeling-based MU methods involves modifying the forgetting data with incorrect labels and subsequently fine-tuning the model. While learning such incorrect information can indeed remove knowledge, the process is quite unnatural as the unlearning process undesirably reinforces the incorrect information and leads to over-forgetting. Towards more natural machine unlearning, we inject correct information from the remaining data to the forgetting samples when changing their labels. Through pairing these adjusted samples with their labels, the model tends to use the injected correct information and naturally suppresses the information meant to be forgotten. Albeit straightforward, such a first step towards natural machine unlearning can significantly outperform current state-of-the-art approaches. In particular, our method substantially reduces the over-forgetting problem and leads to strong robustness across different unlearning tasks, making it a promising candidate for practical machine unlearning. Zhengbao He, Tao Li 0054, Xinwen Cheng, Zhehao Huang, Xiaolin Huang |
IEEE Trans. Pattern Anal. Mach. Intell. | 4 |
| 2024 | Unified Gradient-Based Machine Unlearning with Remain Geometry EnhancementabstractMachine unlearning (MU) has emerged to enhance the privacy and trustworthiness of deep neural networks. Approximate MU is a practical method for large-scale models. Our investigation into approximate MU starts with identifying the steepest descent direction, minimizing the output Kullback-Leibler divergence to exact MU inside a parameters' neighborhood. This probed direction decomposes into three components: weighted forgetting gradient ascent, fine-tuning retaining gradient descent, and a weight saliency matrix. Such decomposition derived from Euclidean metric encompasses most existing gradient-based MU methods. Nevertheless, adhering to Euclidean space may result in sub-optimal iterative trajectories due to the overlooked geometric structure of the output probability space. We suggest embedding the unlearning update into a manifold rendered by the remaining geometry, incorporating second-order Hessian from the remaining data. It helps prevent effective unlearning from interfering with the retained performance. However, computing the second-order Hessian for large-scale models is intractable. To efficiently leverage the benefits of Hessian modulation, we propose a fast-slow parameter update strategy to implicitly approximate the up-to-date salient unlearning direction.
Free from specific modal constraints, our approach is adaptable across computer vision unlearning tasks, including classification and generation. Extensive experiments validate our efficacy and efficiency. Notably, our method successfully performs class-forgetting on ImageNet using DiT and forgets a class on CIFAR-10 using DDPM in just 50 steps, compared to thousands of steps required by previous methods. Code is available at [Unified-Unlearning-w-Remain-Geometry](https://github.com/K1nght/Unified-Unlearning-w-Remain-Geometry). Zhehao Huang, Xinwen Cheng, JingHao Zheng, Zhengbao He, Xiaolin Huang |
NeurIPS | 1 |
| 2023 | Trainable Weight Averaging: Efficient Training by Optimizing Historical Solutions
Tao Li 0054, Zhehao Huang, Qinghua Tao, Yingwen Wu, Xiaolin Huang |
ICLR | 2 |
| 2023 | Low Dimensional Trajectory Hypothesis is True: DNNs Can Be Trained in Tiny SubspacesabstractDeep neural networks (DNNs) usually contain massive parameters, but there is redundancy such that it is guessed that they could be trained in low-dimensional subspaces. In this paper, we propose a Dynamic Linear Dimensionality Reduction (DLDR) based on the low-dimensional properties of the training trajectory. The reduction method is efficient, supported by comprehensive experiments: optimizing DNNs in 40-dimensional spaces can achieve comparable performance as regular training over thousands or even millions of parameters. Since there are only a few variables to optimize, we develop an efficient quasi-Newton-based algorithm, obtain robustness to label noise, and improve the performance of well-trained models, which are three follow-up experiments that can show the advantages of finding such low-dimensional subspaces. The code is released (Pytorch: https://github.com/nblt/DLDR and Mindspore: https://gitee.com/mindspore/docs/tree/r1.6/docs/sample_code/dimension_reduce_training). Tao Li 0054, Zhehao Huang, Qinghua Tao, Yipeng Liu 0001, Xiaolin Huang |
IEEE Trans. Pattern Anal. Mach. Intell. | 3 |
| 2022 | Adversarial Attack on Attackers: Post-Process to Mitigate Black-Box Score-Based Query AttacksabstractThe score-based query attacks (SQAs) pose practical threats to deep neural networks by crafting adversarial perturbations within dozens of queries, only using the model's output scores. Nonetheless, we note that if the loss trend of the outputs is slightly perturbed, SQAs could be easily misled and thereby become much less effective. Following this idea, we propose a novel defense, namely Adversarial Attack on Attackers (AAA), to confound SQAs towards incorrect attack directions by slightly modifying the output logits. In this way, (1) SQAs are prevented regardless of the model's worst-case robustness; (2) the original model predictions are hardly changed, i.e., no degradation on clean accuracy; (3) the calibration of confidence scores can be improved simultaneously. Extensive experiments are provided to verify the above advantages. For example, by setting $\ell_\infty=8/255$ on CIFAR-10, our proposed AAA helps WideResNet-28 secure 80.59% accuracy under Square attack (2500 queries), while the best prior defense (i.e., adversarial training) only attains 67.44%. Since AAA attacks SQA's general greedy strategy, such advantages of AAA over 8 defenses can be consistently observed on 8 CIFAR-10/ImageNet models under 6 SQAs, using different attack targets, bounds, norms, losses, and strategies. Moreover, AAA calibrates better without hurting the accuracy. Our code is available at https://github.com/Sizhe-Chen/AAA. Sizhe Chen, Zhehao Huang, Qinghua Tao, Yingwen Wu, Cihang Xie, Xiaolin Huang |
NeurIPS | 2 |
| 2020 | Inequalities and stability of stochastic Hopfield neural networks with discrete and distributed delays
Dehao Ruan, Zhehao Huang, Xiaoxia Guo |
Neurocomputing | 2 |