VLDB 2026 Research / reviewers in the wild / expert
Tanqiu Jiang
dblp:264/2675
· DBLP profile ↗
6ranked-venue papers
4as first author
5since 2021 · last 2026
0000-0003-4838-5539ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 4 first-author · 4 since 2021Security and privacy · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
4 papers |
Security and privacy of machine learning · 82% Privacy and data protection · 18% | |
| Artificial intelligence
3 papers |
Generative modeling · 46% Language models and text generation · 31% Trustworthy machine learning · 23% | |
| Theoretical computer science
1 paper |
Algorithms and data structures · 50% Approximation and online algorithms · 50% | |
| Databases, data mining, and information retrieval
1 paper |
Knowledge graphs · 100% |
Topics — the 12 heaviest of 14, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Security and privacy of machine learning › adversarial attack
jailbreak attack |
1.0 | 1 | 2026 | AutoRAN: Automated Hijacking of Safety Reasoning in Large Reasoning Models · ACL (1) 2026 |
Security and privacy of machine learning
poisoning attack |
1.0 | 1 | 2026 | GraphRAG Under Fire · SP 2026 |
Security and privacy of machine learning
retrieval-augmented generation security |
1.0 | 1 | 2026 | GraphRAG Under Fire · SP 2026 |
Machine learning › Trustworthy machine learning › adversarial machine learning › adversarial natural language processing
adversarial prompt defense |
0.9 | 1 | 2025 | RobustKV: Defending Large Language Models against Jailbreak Attacks via KV Eviction · ICLR 2025 |
Machine learning › Generative modeling › diffusion model
differentially private diffusion model |
0.9 | 1 | 2025 | RAPID: Retrieval Augmented Training of Differentially Private Diffusion Models · ICLR 2025 |
Machine learning › Generative modeling
diffusion model |
0.9 | 1 | 2025 | RAPID: Retrieval Augmented Training of Differentially Private Diffusion Models · ICLR 2025 |
Natural language and speech › Language models and text generation
large language model safety |
0.9 | 1 | 2025 | RobustKV: Defending Large Language Models against Jailbreak Attacks via KV Eviction · ICLR 2025 |
Privacy and data protection
differential privacy |
0.9 | 1 | 2025 | RAPID: Retrieval Augmented Training of Differentially Private Diffusion Models · ICLR 2025 |
Security and privacy of machine learning › large language model safety
jailbreak defense |
0.9 | 1 | 2025 | RobustKV: Defending Large Language Models against Jailbreak Attacks via KV Eviction · ICLR 2025 |
Approximation and online algorithms
learning-augmented algorithms |
0.4 | 1 | 2020 | Learning-Augmented Data Stream Algorithms · ICLR 2020 |
Algorithms and data structures › data streams
streaming algorithms |
0.4 | 1 | 2020 | Learning-Augmented Data Stream Algorithms · ICLR 2020 |
Natural language and speech › Language models and text generation › large language model
large reasoning model |
0.3 | 1 | 2026 | AutoRAN: Automated Hijacking of Safety Reasoning in Large Reasoning Models · ACL (1) 2026 |
Methods — techniques the papers use, named apart from their topics
relation injection · 2.0relation enhancement · 2.0narrative generation · 2.0iterative refinement · 2.0execution simulation · 2.0retrieval-augmented generation · 1.7attention score ranking · 1.7KV cache eviction · 1.7machine learning predictions · 0.4
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | AutoRAN: Automated Hijacking of Safety Reasoning in Large Reasoning ModelsabstractThis paper presents AutoRAN 1 , the first framework to automate the hijacking of internal safety reasoning in large reasoning models (LRMs).At its core, AutoRAN pioneers an execution simulation paradigm that leverages a weaker but less-aligned model to simulate execution reasoning for initial hijacking attempts and iteratively refine attacks by exploiting reasoning patterns leaked through the target LRM's refusals.This approach steers the target model to bypass its own safety guardrails and elaborate on harmful instructions.We evaluate AutoRAN against state-of-the-art LRMs, including gpt-o3/o4-mini and Gemini-2.5-Flash,across multiple benchmarks (AdvBench, Harm-Bench, and StrongReject).Results show that AutoRAN achieves approaching 100% success rate within one or a few turns, effectively neutralizing reasoning-based defenses even when evaluated by robustly aligned external models.This work reveals that the transparency of the reasoning process itself creates a critical and exploitable attack surface, highlighting the urgent need for new defenses that protect models' reasoning traces rather than merely their final outputs.The code for replicating Au-toRAN is available at: https://github.com/ JACKPURCELL/AutoRAN-public. Jiacheng Liang, Tanqiu Jiang, Yuhui Wang 0003, Rongyi Zhu, Fenglong Ma, Ting Wang 0006 |
ACL (1) | 2 |
| 2026 | GraphRAG Under FireabstractGraphRAG advances retrieval-augmented generation (RAG) by structuring external knowledge as multi-scale knowledge graphs, enabling language models to integrate both broad context and granular details in their generation. While GraphRAG has demonstrated success across domains, its security implications remain largely unexplored. To bridge this gap, this work examines GraphRAG's vulnerability to poisoning attacks, uncovering an intriguing security paradox: existing RAG poisoning attacks are less effective under GraphRAG than conventional RAG, due to GraphRAG's graph-based indexing and retrieval; yet, the same features also create new attack surfaces. We present GragPoison, a novel attack that exploits shared relations in the underlying knowledge graph to craft poisoning text capable of compromising multiple queries simultaneously. GragPoison employs three key strategies: (i) relation injection to introduce false knowledge, (ii) relation enhancement to amplify poisoning influence, and (iii) narrative generation to embed malicious content within coherent text. Empirical evaluation across diverse datasets and models shows that GragPoison substantially outperforms existing attacks in terms of effectiveness (up to 98% success rate) and scalability (using less than 68% poisoning text) on multiple variations of GraphRAG. We also explore potential defensive measures and their limitations, identifying promising directions for future research. Jiacheng Liang, Yuhui Wang 0003, Changjiang Li, Tanqiu Jiang, Rongyi Zhu, Neil Zhenqiang Gong, Ting Wang 0006 |
SP | 4 |
| 2025 | RAPID: Retrieval Augmented Training of Differentially Private Diffusion ModelsabstractDifferentially private diffusion models (DPDMs) harness the remarkable generative capabilities of diffusion models while enforcing differential privacy (DP) for sensitive data. However, existing DPDM training approaches often suffer from significant utility loss, large memory footprint, and expensive inference cost, impeding their practical uses.
To overcome such limitations, we present RAPID: Retrieval Augmented PrIvate Diffusion model, a novel approach that integrates retrieval augmented generation (RAG) into DPDM training. Specifically, RAPID leverages available public data to build a knowledge base of sample trajectories; when training the diffusion model on private data, RAPID computes the early sampling steps as queries, retrieves similar trajectories from the knowledge base as surrogates, and focuses on training the later sampling steps in a differentially private manner. Extensive evaluation using benchmark datasets and models demonstrates that, with the same privacy guarantee, RAPID significantly outperforms state-of-the-art approaches by large margins in generative quality, memory footprint, and inference cost, suggesting that retrieval-augmented DP training represents a promising direction for developing future privacy-preserving generative models. The code is available at: https://github.com/TanqiuJiang/RAPID Tanqiu Jiang, Changjiang Li, Fenglong Ma, Ting Wang 0006 |
ICLR | 1 |
| 2025 | RobustKV: Defending Large Language Models against Jailbreak Attacks via KV EvictionabstractJailbreak attacks circumvent LLMs' built-in safeguards by concealing harmful queries within adversarial prompts. While most existing defenses attempt to mitigate the effects of adversarial prompts, they often prove inadequate as adversarial prompts can take arbitrary, adaptive forms. This paper introduces RobustKV, a novel jailbreak defense that takes a fundamentally different approach by selectively removing critical tokens of harmful queries from key-value (KV) caches. Intuitively, for an adversarial prompt to be effective, its tokens must achieve sufficient `importance' (measured by attention scores), which consequently lowers the importance of tokens in the concealed harmful query. Therefore, by carefully evicting the KVs of low-ranked tokens, RobustKV minimizes the harmful query's presence in the KV cache, thus preventing the LLM from generating informative responses. Extensive evaluation using benchmark datasets and models demonstrates that RobustKV effectively counters state-of-the-art jailbreak attacks while maintaining the LLM's performance on benign queries. Notably, RobustKV creates an interesting effectiveness-evasiveness dilemma for the adversary, leading to its robustness against adaptive attacks.{(Warning: This paper contains potentially harmful content generated by LLMs.)} Tanqiu Jiang, Jiacheng Liang, Changjiang Li, Yuhui Wang 0003, Ting Wang 0006 |
ICLR | 1 |
| 2021 | From Static to Dynamic Prediction: Wildfire Risk Assessment Based on Multiple Environmental FactorsabstractWildfire is one of the biggest disasters that frequently occurs on the west coast of the United States. Many efforts have been made to understand the causes of the increases in wildfire intensity and frequency in recent years. In this work, we propose static and dynamic prediction models to analyze and assess the areas with high wildfire risks in California by utilizing a multitude of environmental data including population density, Normalized Difference Vegetation Index (NDVI), Palmer Drought Severity Index (PDSI), tree mortality area, tree mortality number, and altitude. Moreover, we focus on a better understanding of the impacts of different factors so as to inform preventive actions. To validate our models and findings, we divide the land of California into 4,242 grids of 0.1 degrees 0.1 degrees in latitude and longitude, and compute the risk of each grid based on spatial and temporal conditions. To verify the generalizability of our models, we further expand the scope of wildfire risk assessment from California to Washington without any fine tuning. By performing counterfactual analysis, we uncover the effects of several possible methods on reducing the number of high risk wildfires. Taken together, our study has the potential to estimate, monitor, and reduce the risks of wildfires across diverse areas provided that such environment data is available. Tanqiu Jiang, Sidhant K. Bendre, Hanjia Lyu, Jiebo Luo 0001 |
IEEE BigData | 1 |
| 2020 | Learning-Augmented Data Stream Algorithms
Tanqiu Jiang, Yi Li 0002, Honghao Lin, Yisong Ruan, David P. Woodruff |
ICLR | 1 |