VLDB 2026 Research / reviewers in the wild / expert
Jinqi Luo
dblp:274/6526
· DBLP profile ↗
10ranked-venue papers
4as first author
10since 2021 · last 2025
0000-0002-9689-009XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 9 · 4 first-author · 9 since 2021Graphics, computer vision, multimedia, augmented reality and games · 5 · 3 first-author · 5 since 2021Computer networks · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
8 papers |
Trustworthy machine learning · 25% Generative modeling · 23% Language models and text generation · 20% | |
| Network and information security
2 papers |
Security and privacy of machine learning · 100% | |
| Computer graphics and multimedia
1 paper |
Visual content generation and editing · 100% |
Topics — the 22 heaviest of 24, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Security and privacy of machine learning
adversarial attack |
1.4 | 2 | 2025 | SECA: Semantically Equivalent and Coherent Attacks for Eliciting LLM Hallucinations · NeurIPS 2025 Generating Adversarial yet Inconspicuous Patches with a Single Image (Student Abstract) · AAAI 2021 |
Computer vision › 3D vision › 3d generation
dynamic scene generation |
0.9 | 1 | 2025 | Voyaging into Perpetual Dynamic Scenes from a Single View · ICCV 2025 |
Machine learning › Trustworthy machine learning
hallucination |
0.9 | 1 | 2025 | SECA: Semantically Equivalent and Coherent Attacks for Eliciting LLM Hallucinations · NeurIPS 2025 |
Computer vision › 3D vision
novel view synthesis |
0.9 | 1 | 2025 | Voyaging into Perpetual Dynamic Scenes from a Single View · ICCV 2025 |
Machine learning › Generative modeling
video generation |
0.9 | 1 | 2025 | Voyaging into Perpetual Dynamic Scenes from a Single View · ICCV 2025 |
Visual content generation and editing › image editing
diffusion-based image editing |
0.9 | 1 | 2025 | Concept Lancet: Image Editing with Compositional Representation Transplant · CVPR 2025 |
Visual content generation and editing
image editing |
0.9 | 1 | 2025 | Concept Lancet: Image Editing with Compositional Representation Transplant · CVPR 2025 |
Knowledge, reasoning and agents › Multi-agent systems
agent-based simulation |
0.8 | 1 | 2024 | LogiCity: Advancing Neuro-Symbolic AI with Abstract Urban Simulation · NeurIPS 2024 |
Natural language and speech › Language models and text generation
alignment |
0.8 | 1 | 2024 | PaCE: Parsimonious Concept Engineering for Large Language Models · NeurIPS 2024 |
Machine learning › Generative modeling
concept erasure |
0.8 | 1 | 2024 | PaCE: Parsimonious Concept Engineering for Large Language Models · NeurIPS 2024 |
Natural language and speech › Language models and text generation
hallucination mitigation |
0.8 | 1 | 2024 | PaCE: Parsimonious Concept Engineering for Large Language Models · NeurIPS 2024 |
Knowledge, reasoning and agents › Knowledge representation and reasoning
neuro-symbolic reasoning |
0.8 | 1 | 2024 | LogiCity: Advancing Neuro-Symbolic AI with Abstract Urban Simulation · NeurIPS 2024 |
Natural language and speech › Language models and text generation › knowledge editing
representation editing |
0.8 | 1 | 2024 | PaCE: Parsimonious Concept Engineering for Large Language Models · NeurIPS 2024 |
Machine learning › Generative modeling › conditional generative model
counterfactual image generation |
0.7 | 1 | 2023 | Zero-Shot Model Diagnosis · CVPR 2023 |
Machine learning › Trustworthy machine learning › interpretability › model debugging
model diagnosis |
0.7 | 1 | 2023 | Zero-Shot Model Diagnosis · CVPR 2023 |
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
0.5 | 1 | 2021 | Recent Advances in Adversarial Training for Adversarial Robustness · IJCAI 2021 |
Machine learning › Trustworthy machine learning › robustness › adversarial robustness
adversarial training |
0.5 | 1 | 2021 | Recent Advances in Adversarial Training for Adversarial Robustness · IJCAI 2021 |
Security and privacy of machine learning › adversarial attack › physical adversarial attack
adversarial patch |
0.5 | 1 | 2021 | Generating Adversarial yet Inconspicuous Patches with a Single Image (Student Abstract) · AAAI 2021 |
Machine learning › Generative modeling
diffusion model |
0.3 | 1 | 2025 | Concept Lancet: Image Editing with Compositional Representation Transplant · CVPR 2025 |
Machine learning › Representation and self-supervised learning › representation learning › unsupervised representation learning
sparse coding |
0.2 | 1 | 2024 | PaCE: Parsimonious Concept Engineering for Large Language Models · NeurIPS 2024 |
Machine learning › Trustworthy machine learning › robustness
adversarial examples |
0.1 | 1 | 2021 | Recent Advances in Adversarial Training for Adversarial Robustness · IJCAI 2021 |
Machine learning › Trustworthy machine learning
robustness |
0.1 | 1 | 2021 | Generating Adversarial yet Inconspicuous Patches with a Single Image (Student Abstract) · AAAI 2021 |
Methods — techniques the papers use, named apart from their topics
zeroth-order method · 1.7sparse linear decomposition · 1.7constrained optimization · 1.7concept representation dictionary · 1.7reinforcement learning · 1.5first-order logic · 1.5deep neural network · 1.5scene outpainting · 0.9ray information · 0.9dynamic point cloud · 0.9min-max training · 0.5generative adversarial network · 0.5coarse-to-fine generation · 0.5
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Understanding the Learning Dynamics of LoRA: A Gradient Flow Perspective on Low-Rank Adaptation in Matrix FactorizationabstractDespite the empirical success of Low-Rank Adaptation (LoRA) in fine-tuning pre-trained models, there is little theoretical understanding of how first-order methods with carefully crafted initialization adapt models to new tasks. In this work, we take the first step towards bridging this gap by theoretically analyzing the learning dynamics of LoRA for matrix factorization (MF) under gradient flow (GF), emphasizing the crucial role of initialization. For small initialization, we theoretically show that GF converges to a neighborhood of the optimal solution, with smaller initialization leading to lower final error. Our analysis shows that the final error is affected by the misalignment between the singular spaces of the pre-trained model and the target matrix, and reducing the initialization scale improves alignment. To address this misalignment, we propose a spectral initialization for LoRA in MF and theoretically prove that GF with small spectral initialization converges to the fine-tuning task with arbitrary precision. Numerical experiments from MF and image classification validate our findings. Ziqing Xu, Hancheng Min, Lachlan E. MacDonald, Jinqi Luo, Salma Tarmoun, Enrique Mallada, René Vidal |
AISTATS | 4 |
| 2025 | Concept Lancet: Image Editing with Compositional Representation TransplantabstractDiffusion models are widely used for image editing tasks. Existing editing methods often design a representation manipulation procedure by curating an edit direction in the text embedding or score space. However, such a procedure faces a key challenge: overestimating the edit strength harms visual consistency while underestimating it fails the editing task. Notably, each source image may require a different editing strength, and it is costly to search for an appropriate strength via trial-and-error. To address this challenge, we propose ${\boldsymbol{Co}}{\text{ncept}}\,{\boldsymbol{Lan}}{\text{cet}}$ (CoLan), a zero-shot plug-and-play framework for principled representation manipulation in diffusion-based image editing. At inference time, we decompose the source input in the latent (text embedding or diffusion score) space as a sparse linear combination of the representations of the collected visual concepts. This allows us to accurately estimate the presence of concepts in each image, which informs the edit. Based on the editing task (replace/add/remove), we perform a customized concept transplant process to impose the corresponding editing direction. To sufficiently model the concept space, we curate a conceptual representation dataset, CoLan-150K, which contains diverse descriptions and scenarios of visual terms and phrases for the latent dictionary. Experiments on multiple diffusion-based image editing baselines show that methods equipped with CoLan achieve state-of-the-art performance in editing effectiveness and consistency preservation. Jinqi Luo, Tianjiao Ding, Kwan Ho Ryan Chan, Hancheng Min, Chris Callison-Burch, René Vidal |
CVPR | 1 |
| 2025 | Voyaging into Perpetual Dynamic Scenes from a Single ViewabstractThe problem of generating a perpetual dynamic scene from a single view is an important problem with widespread applications in augmented and virtual reality, and robotics. However, since dynamic scenes regularly change over time, a key challenge is to ensure that different generated views be consistent with the underlying 3D motions. Prior work learns such consistency by training on multiple views, but the generated scene regions often interpolate between training views and fail to generate perpetual views. To address this issue, we propose DynamicVoyager, which reformulates dynamic scene generation as a scene outpainting problem with new dynamic content. As 2D outpainting models struggle at generating 3D consistent motions from a single 2D view, we enrich 2D pixels with information from their 3D rays that facilitates learning of 3D motion consistency. More specifically, we first map the single-view video input to a dynamic point cloud using the estimated video depths. We then render a partial video of the point cloud from a novel view and outpaint the missing regions using ray information (e.g., the distance from a ray to the point cloud) to generate 3D consistent motions. Next, we use the outpainted video to update the point cloud, which is used for outpainting the scene from future novel views. Moreover, we can control the generated content with the input text prompt. Experiments show that our model can generate perpetual scenes with consistent motions along fly-through cameras. Project page: https://tianfr.github.io/DynamicVoyager. Fengrui Tian, Tianjiao Ding, Jinqi Luo, Hancheng Min, René Vidal |
ICCV | 3 |
| 2025 | SECA: Semantically Equivalent and Coherent Attacks for Eliciting LLM HallucinationsabstractLarge Language Models (LLMs) are increasingly deployed in high-risk domains. However, state-of-the-art LLMs often exhibit hallucinations, raising serious concerns about their reliability. Prior work has explored adversarial attacks to elicit hallucinations in LLMs, but these methods often rely on unrealistic prompts, either by inserting nonsensical tokens or by altering the original semantic intent. Consequently, such approaches provide limited insight into how hallucinations arise in real-world settings. In contrast, adversarial attacks in computer vision typically involve realistic modifications to input images. However, the problem of identifying realistic adversarial prompts for eliciting LLM hallucinations remains largely underexplored. To address this gap, we propose Semantically Equivalent and Coherent Attacks (SECA), which elicit hallucinations via realistic modifications to the prompt that preserve its meaning while maintaining semantic coherence. Our contributions are threefold: (i) we formulate finding realistic attacks for hallucination elicitation as a constrained optimization problem over the input prompt space under semantic equivalence and coherence constraints; (ii) we introduce a constraint-preserving zeroth-order method to effectively search for adversarial yet feasible prompts; and (iii) we demonstrate through experiments on open-ended multiple-choice question answering tasks that SECA achieves higher attack success rates while incurring almost no semantic equivalence or semantic coherence errors compared to existing methods. SECA highlights the sensitivity of both open-source and commercial gradient-inaccessible LLMs to realistic and plausible prompt variations. Code is available at https://github.com/Buyun-Liang/SECA. Buyun Liang 0001, Liangzu Peng, Jinqi Luo, Darshan Thaker, Kwan Ho Ryan Chan, René Vidal |
NeurIPS | 3 |
| 2024 | LogiCity: Advancing Neuro-Symbolic AI with Abstract Urban SimulationabstractRecent years have witnessed the rapid development of Neuro-Symbolic (NeSy) AI systems, which integrate symbolic reasoning into deep neural networks.However, most of the existing benchmarks for NeSy AI fail to provide long-horizon reasoning tasks with complex multi-agent interactions.Furthermore, they are usually constrained by fixed and simplistic logical rules over limited entities, making them far from real-world complexities.To address these crucial gaps, we introduce LogiCity, the first simulator based on customizable first-order logic (FOL) for an urban-like environment with multiple dynamic agents.LogiCity models diverse urban elements using semantic and spatial concepts, such as $\texttt{IsAmbulance}(\texttt{X})$ and $\texttt{IsClose}(\texttt{X}, \texttt{Y})$. These concepts are used to define FOL rules that govern the behavior of various agents. Since the concepts and rules are abstractions, they can be universally applied to cities with any agent compositions, facilitating the instantiation of diverse scenarios.Besides, a key feature of LogiCity is its support for user-configurable abstractions, enabling customizable simulation complexities for logical reasoning.To explore various aspects of NeSy AI, LogiCity introduces two tasks, one features long-horizon sequential decision-making, and the other focuses on one-step visual reasoning, varying in difficulty and agent behaviors.Our extensive evaluation reveals the advantage of NeSy frameworks in abstract reasoning. Moreover, we highlight the significant challenges of handling more complex abstractions in long-horizon multi-agent scenarios or under high-dimensional, imbalanced data.With its flexible design, various features, and newly raised challenges, we believe LogiCity represents a pivotal step forward in advancing the next generation of NeSy AI.All the code and data are open-sourced at our website. Bowen Li 0007, Qiwei Du, Jinqi Luo, Yaqi Xie 0001, Simon Stepputtis, Chen Wang 0033, Katia P. Sycara, Pradeep Ravikumar, Alexander G. Gray, Xujie Si, Sebastian A. Scherer |
NeurIPS | 4 |
| 2024 | PaCE: Parsimonious Concept Engineering for Large Language ModelsabstractLarge Language Models (LLMs) are being used for a wide variety of tasks. While they are capable of generating human-like responses, they can also produce undesirable output including potentially harmful information, racist or sexist language, and hallucinations. Alignment methods are designed to reduce such undesirable output, via techniques such as fine-tuning, prompt engineering, and representation engineering. However, existing methods face several challenges: some require costly fine-tuning for every alignment task; some do not adequately remove undesirable concepts, failing alignment; some remove benign concepts, lowering the linguistic capabilities of LLMs. To address these issues, we propose Parsimonious Concept Engineering (PaCE), a novel activation engineering framework for alignment. First, to sufficiently model the concepts, we construct a large-scale concept dictionary in the activation space, in which each atom corresponds to a semantic concept. Given any alignment task, we instruct a concept partitioner to efficiently annotate the concepts as benign or undesirable. Then, at inference time, we decompose the LLM activations along the concept dictionary via sparse coding, to accurately represent the activations as linear combinations of benign and undesirable components. By removing the latter ones from the activations, we reorient the behavior of the LLM towards the alignment goal. We conduct experiments on tasks such as response detoxification, faithfulness enhancement, and sentiment revising, and show that PaCE achieves state-of-the-art alignment performance while maintaining linguistic capabilities. Jinqi Luo, Tianjiao Ding, Kwan Ho Ryan Chan, Darshan Thaker, Aditya Chattopadhyay, Chris Callison-Burch, René Vidal |
NeurIPS | 1 |
| 2023 | Zero-Shot Model DiagnosisabstractWhen it comes to deploying deep vision models, the behavior of these systems must be explicable to ensure confidence in their reliability and fairness. A common approach to evaluate deep learning models is to build a labeled test set with attributes of interest and assess how well it performs. However, creating a balanced test set (i.e., one that is uniformly sampled over all the important traits) is often time-consuming, expensive, and prone to mistakes. The question we try to address is: can we evaluate the sensitivity of deep learning models to arbitrary visual attributes without an annotated test set? This paper argues the case that Zero-shot Model Diagnosis (ZOOM) is possible without the need for a test set nor labeling. To avoid the need for test sets, our system relies on a generative model and CLIP. The key idea is enabling the user to select a set of prompts (relevant to the problem) and our system will automatically search for semantic counterfactual images (i.e., synthesized images that flip the prediction in the case of a binary classifier) using the generative model. We evaluate several visual tasks (classification, key-point detection, and segmentation) in multiple visual domains to demonstrate the viability of our methodology. Extensive experiments demonstrate that our method is capable of producing counterfactual images and offering sensitivity analysis for model diagnosis without the need for a test set. Jinqi Luo, Zhaoning Wang, Chen Henry Wu, Dong Huang 0007, Fernando De la Torre |
CVPR | 1 |
| 2022 | Inconspicuous Adversarial Patches for Fooling Image-Recognition Systems on Mobile DevicesabstractDeep-learning-based image-recognition systems have been widely deployed on mobile devices in today’s world. In recent studies, however, deep learning models are shown vulnerable to adversarial examples. One variant of adversarial examples, called the adversarial patch, draws researchers’ attention due to its strong attack abilities. Though adversarial patches achieve high attack success rates, they are easily being detected because of the visual inconsistency between the patches and the original images. Besides, it usually requires a large amount of data for adversarial patch generation in the literature, which is computationally expensive and time consuming. To tackle these challenges, we propose an approach to generate inconspicuous adversarial patches with one single image. In our approach, we first decide the patch locations based on the perceptual sensitivity of victim models, then produce adversarial patches in a coarse-to-fine way by utilizing multiple-scale generators and discriminators. The patches are encouraged to be consistent with the background images with adversarial training while preserving strong attack abilities. Our approach shows the strong attack abilities in white-box settings and the excellent transferability in black-box settings through extensive experiments on various models with different architectures and training methods. Compared to other adversarial patches, our adversarial patches hold the most negligible risks to be detected and can evade human observations, which is supported by the illustrations of saliency maps and results of user evaluations. Finally, we show that our adversarial patches can be applied in the physical world. Jinqi Luo, Jun Zhao 0007 |
IEEE Internet Things J. | 2 |
| 2021 | Generating Adversarial yet Inconspicuous Patches with a Single Image (Student Abstract)abstractDeep neural networks have been shown vulnerable to adversarial patches, where exotic patterns can result in model’s wrong prediction. Nevertheless, existing approaches to adversarial patch generation hardly consider the contextual consistency between patches and the image background, causing such patches to be easily detected by human observation. Additionally, these methods require a large amount of data for training, which is computationally expensive. To overcome these challenges, we propose an approach to generate adversarial yet inconspicuous patches with one single image. In our approach, adversarial patches are produced in a coarse-to-fine way with multiple scales of generators and discriminators. The selection of patch location is based on the perceptual sensitivity of victim models. Contextual information is encoded during the Min-Max training to make patches consistent with surroundings. Jinqi Luo, Jun Zhao 0007 |
AAAI | 1 |
| 2021 | Recent Advances in Adversarial Training for Adversarial RobustnessabstractAdversarial training is one of the most effective approaches for deep learning models to defend against adversarial examples. Unlike other defense strategies, adversarial training aims to enhance the robustness of models intrinsically. During the past few years, adversarial training has been studied and discussed from various aspects, which deserves a comprehensive review. For the first time in this survey, we systematically review the recent progress on adversarial training for adversarial robustness with a novel taxonomy. Then we discuss the generalization problems in adversarial training from three perspectives and highlight the challenges which are not fully tackled. Finally, we present potential future directions. Jinqi Luo, Jun Zhao 0007, Bihan Wen, Qian Wang 0002 |
IJCAI | 2 |