VLDB 2026 Research / reviewers in the wild / expert
Ruoxin Chen
dblp:274/6944
· DBLP profile ↗
10ranked-venue papers
3as first author
10since 2021 · last 2026
0000-0001-8729-3034ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 7 · 3 first-author · 7 since 2021Graphics, computer vision, multimedia, augmented reality and games · 4 · 1 first-author · 4 since 2021Security and privacy · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
6 papers |
Trustworthy machine learning · 53% Learning theory · 9% Generative modeling · 8% | |
| Computer graphics and multimedia
1 paper |
Image and video processing · 100% | |
| Network and information security
1 paper |
Security and privacy of machine learning · 50% Privacy and data protection · 50% |
Topics — the 17 heaviest of 18, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Machine learning › Trustworthy machine learning
robustness |
2.0 | 3 | 2025 | Dual Data Alignment Makes AI-Generated Image Detector Easier Generalizable · NeurIPS 2025 On Collective Robustness of Bagging Against Data Poisoning · ICML 2022 Input-Specific Robustness Certification for Randomized Smoothing · AAAI 2022 |
Machine learning › Trustworthy machine learning › robustness
certified robustness |
1.1 | 2 | 2022 | On Collective Robustness of Bagging Against Data Poisoning · ICML 2022 Input-Specific Robustness Certification for Randomized Smoothing · AAAI 2022 |
Machine learning › Trustworthy machine learning › AI-generated content detection
AI-generated image detection |
0.9 | 1 | 2025 | Dual Data Alignment Makes AI-Generated Image Detector Easier Generalizable · NeurIPS 2025 |
Machine learning › Generative modeling › diffusion model › diffusion model training
diffusion model fine-tuning |
0.9 | 1 | 2025 | Instruct Where the Model Fails: Generative Data Augmentation via Guided Self-contrastive Fine-tuning · AAAI 2025 |
Machine learning › Transfer learning and domain adaptation › few-shot learning
few-shot class-incremental learning |
0.9 | 1 | 2025 | Instruct Where the Model Fails: Generative Data Augmentation via Guided Self-contrastive Fine-tuning · AAAI 2025 |
Machine learning › Efficient and distributed learning › federated learning
privacy-preserving federated learning |
0.9 | 1 | 2025 | Temporal Gradient Inversion Attacks With Robust Optimization · IEEE Trans. Dependable Secur. Comput. 2025 |
Image and video processing
frequency domain analysis |
0.9 | 1 | 2025 | Dual Data Alignment Makes AI-Generated Image Detector Easier Generalizable · NeurIPS 2025 |
Image and video processing
image forensics |
0.9 | 1 | 2025 | Dual Data Alignment Makes AI-Generated Image Detector Easier Generalizable · NeurIPS 2025 |
Privacy and data protection › privacy-preserving machine learning › federated learning privacy
gradient inversion attack |
0.9 | 1 | 2025 | Temporal Gradient Inversion Attacks With Robust Optimization · IEEE Trans. Dependable Secur. Comput. 2025 |
Security and privacy of machine learning
privacy attack |
0.9 | 1 | 2025 | Temporal Gradient Inversion Attacks With Robust Optimization · IEEE Trans. Dependable Secur. Comput. 2025 |
Machine learning › Learning theory
generalization bounds |
0.8 | 1 | 2024 | InterpGNN: Understand and Improve Generalization Ability of Transdutive GNNs through the Lens of Interplay between Train and Test Nodes · ICLR 2024 |
Machine learning › Graph learning
graph neural network |
0.8 | 1 | 2024 | InterpGNN: Understand and Improve Generalization Ability of Transdutive GNNs through the Lens of Interplay between Train and Test Nodes · ICLR 2024 |
Machine learning › Kernel, tree and ensemble methods › ensemble learning
bagging |
0.6 | 1 | 2022 | On Collective Robustness of Bagging Against Data Poisoning · ICML 2022 |
Machine learning › Trustworthy machine learning › robustness
data poisoning |
0.6 | 1 | 2022 | On Collective Robustness of Bagging Against Data Poisoning · ICML 2022 |
Machine learning › Trustworthy machine learning › robustness › model robustness evaluation
ensemble robustness |
0.6 | 1 | 2022 | On Collective Robustness of Bagging Against Data Poisoning · ICML 2022 |
Machine learning › Trustworthy machine learning › robustness › certified robustness
randomized smoothing |
0.6 | 1 | 2022 | Input-Specific Robustness Certification for Randomized Smoothing · AAAI 2022 |
Machine learning › Learning theory › generalization bounds
PAC-Bayes bounds |
0.2 | 1 | 2024 | InterpGNN: Understand and Improve Generalization Ability of Transdutive GNNs through the Lens of Interplay between Train and Test Nodes · ICLR 2024 |
Methods — techniques the papers use, named apart from their topics
temporal gradient aggregation · 1.7robust statistics · 1.7robust optimization · 1.7generative reconstruction · 1.7data alignment · 1.7diffusion model fine-tuning · 0.9contrastive fine-tuning · 0.9VLM captioning · 0.9key-value attention · 0.8graph transformer · 0.8
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Autorep: Automatic network search with structured reparameterized based linear operation expansion and gradient proxy guided reduction
Guhao Qiu, Ruoxin Chen, Ping Li 0016, Bin Sheng 0001 |
Neural Networks | 2 |
| 2025 | Instruct Where the Model Fails: Generative Data Augmentation via Guided Self-contrastive Fine-tuningabstractData augmentation is expected to bring about unseen features of training set, enhancing the model’s ability to generalize in situations where data is limited. Generative image models trained on large web-crawled datasets such as LAION are known to produce images with stereotypes and imperceptible bias when used to augment training data, owing to dataset misalignment and the generator’s ignorance of the downstream model. We improve downstream task awareness in generated images by proposing a task-aware fine-tuning strategy that actively detects failures of downstream task in the target model to fine-tune the generation process between epochs. The dynamic fine-tuning strategy is achieved by (1) inspecting misalignment between generated data and original data via VLM captioners and (2) adjusts both prompts and diffusion model so that the strategy dynamically guides the generator by focusing on the detected bias of VLM. This is done via re-captioning the overfitted data as well as finetuning the diffusion trajectory in a contrastive manner. To co-operate with the VLM captioner, the contrastive fine-tuning process dynamically adjusts different parts of the diffusion trajectory based on detected misalignment, thus shifting the the generated distribution away from making the downstream model overfit. Our experiments on few-shot class incremental learning show that our instruction-guided finetuning strategy consistently assists the downstream model with higher classification accuracy compared to generative data augmentation baselines such as Stable Diffusion and GPT-4o, and state-of-the-art non-generative strategies. Weijian Ma, Ruoxin Chen, Ke-Yue Zhang, Shuang Wu 0001, Shouhong Ding |
AAAI | 2 |
| 2025 | Dual Data Alignment Makes AI-Generated Image Detector Easier GeneralizableabstractThe rapid increase in AI-generated images (AIGIs) underscores the need for detection methods.
Existing detectors are often trained on biased datasets, leading to overfitting on spurious correlations between non-causal image attributes and real/synthetic labels.
While these biased features enhance performance on the training data, they result in substantial performance degradation when tested on unbiased datasets.
A common solution is to perform data alignment through generative reconstruction, matching the content between real and synthetic images.
However, we find that pixel-level alignment alone is inadequate, as the reconstructed images still suffer from frequency-level misalignment, perpetuating spurious correlations.
To illustrate, we observe that reconstruction models restore the high-frequency details lost in real images, inadvertently creating a frequency-level misalignment, where synthetic images appear to have richer high-frequency content than real ones. This misalignment leads to models associating high-frequency features with synthetic labels, further reinforcing biased cues.
To resolve this, we propose Dual Data Alignment (DDA), which aligns both the pixel and frequency domains.
DDA generates synthetic images that closely resemble real ones by fusing real and synthetic image pairs in both domains, enhancing the detector's ability to identify forgeries without relying on biased features.
Moreover, we introduce two new test sets: DDA-COCO, containing DDA-aligned synthetic images, and EvalGEN, featuring the latest generative models. Our extensive evaluations demonstrate that a detector trained exclusively on DDA-aligned MSCOCO improves across diverse benchmarks.
Code is available at https://github.com/roy-ch/Dual-Data-Alignment. Ruoxin Chen, Junwei Xi, Zhiyuan Yan 0002, Ke-Yue Zhang, Shuang Wu 0001, Isabel Guan, Taiping Yao, Shouhong Ding |
NeurIPS | 1 |
| 2025 | Understanding and mitigating dimensional collapse of Graph Contrastive Learning: A non-maximum removal approach
Jiawei Sun 0001, Ruoxin Chen, Jie Li 0002, Yue Ding 0001, Chentao Wu, Zhi Liu 0002, Junchi Yan |
Neural Networks | 2 |
| 2025 | Temporal Gradient Inversion Attacks With Robust OptimizationabstractFederated Learning (FL) has emerged as a promising approach for collaborative model training without sharing private data. However, privacy concerns regarding information exchanged during FL have received significant research attention.Gradient Inversion Attacks (GIAs)have been proposed to reconstruct the private data retained by local clients from the exchanged gradients. While recovering private data, the data dimensions and the model complexity increase, which thwart data reconstruction by GIAs. Existing methods adopt prior knowledge about private data to overcome those challenges. In this article, we first observe that GIAs with gradients from a single iteration fail to reconstruct private data due to insufficient dimensions of leaked gradients, complex model architectures, and invalid gradient information. We investigate a Temporal Gradient Inversion Attack with a Robust Optimization framework, called TGIAs-RO, which recovers private data without any prior knowledge by leveraging multiple temporal gradients. To eliminate the negative impacts of outliers, e.g., invalid gradients for collaborative optimization, robust statistics are proposed. Theoretical guarantees on the recovery performance and robustness of TGIAs-RO against invalid gradients are also provided. Extensive empirical results on MNIST, CIFAR10, ImageNet and Reuters 21578 datasets show that the proposed TGIAs-RO with 10 temporal gradients improves reconstruction performance compared to state-of-the-art methods, even for large batch sizes (up to 128), complex models like ResNet18, and large datasets like ImageNet (224× 224pixels). Furthermore, the proposed attack method inspires further exploration of privacy-preserving methods in the context of FL. Bowen Li 0013, Hanlin Gu, Ruoxin Chen, Jie Li 0002, Chentao Wu, Na Ruan, Xueming Si, Lixin Fan |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2024 | InterpGNN: Understand and Improve Generalization Ability of Transdutive GNNs through the Lens of Interplay between Train and Test NodesabstractTransductive node prediction has been a popular learning setting in Graph Neural Networks (GNNs). It has been widely observed that the shortage of information flow between the distant nodes and intra-batch nodes (for large-scale graphs) often hurt the generalization of GNNs which overwhelmingly adopt message-passing. Yet there is still no formal and direct theoretical results to quantitatively capture the underlying mechanism, despite the recent advance in both theoretical and empirical studies for GNN's generalization ability. In this paper, the $L$-hop interplay (i.e., message passing capability with training nodes) for a $L$-layer GNN is successfully incorporated in our derived PAC-Bayesian bound for GNNs in the semi-supervised transductive setting. In other words, we quantitatively show how the interplay between training and testing sets influence the generalization ability which also partly explains the effectiveness of some existing empirical methods for enhancing generalization. Based on this result, we further design a plug-and-play ***Graph** **G**lobal **W**orkspace* module for GNNs (InterpGNN-GW) to enhance the interplay, utilizing the key-value attention mechanism to summarize crucial nodes' embeddings into memory and broadcast the memory to all nodes, in contrast to the pairwise attention scheme in previous graph transformers. Extensive experiments on both small-scale and large-scale graph datasets validate the effectiveness of our theory and approaches. Jiawei Sun 0001, Kailai Li 0002, Ruoxin Chen, Jie Li 0002, Chentao Wu, Yue Ding 0001, Junchi Yan |
ICLR | 3 |
| 2023 | Towards Practical Edge Inference Attacks Against Graph Neural NetworksabstractGraph Neural Networks (GNNs) have demonstrated superior performance in numerous real-world applications. Despite their success, recent studies have shown that GNNs are vulnerable under edge inference attacks aimed to infer the connectivity of a given pair of nodes. However, existing methods primarily focus on the scenario when properties of target nodes are revealed. In this paper, we propose an edge inference attack in a more realistic and practical setting. In our threat model, the adversary cannot obtain properties of target nodes but can inject a single probing node and query the target GNN for its prediction. By connecting the probing and target nodes, the adversary can infer the connectivity of the target node pair based on the prediction of the probing node. Extensive experiments show that our attack performs comparably to ones that require properties of target nodes. And when given such auxiliary knowledge, our attack outperforms state-of-the-art methods. Kailai Li 0002, Jiawei Sun 0001, Ruoxin Chen, Kexue Yu, Jie Li 0002, Chentao Wu |
ICASSP | 3 |
| 2022 | Input-Specific Robustness Certification for Randomized SmoothingabstractAlthough randomized smoothing has demonstrated high certified robustness and superior scalability to other certified defenses, the high computational overhead of the robustness certification bottlenecks the practical applicability, as it depends heavily on the large sample approximation for estimating the confidence interval. In existing works, the sample size for the confidence interval is universally set and agnostic to the input for prediction. This Input-Agnostic Sampling (IAS) scheme may yield a poor Average Certified Radius (ACR)-runtime trade-off which calls for improvement. In this paper, we propose Input-Specific Sampling (ISS) acceleration to achieve the cost-effectiveness for robustness certification, in an adaptive way of reducing the sampling size based on the input characteristic. Furthermore, our method universally controls the certified radius decline from the ISS sample size reduction. The empirical results on CIFAR-10 and ImageNet show that ISS can speed up the certification by more than three times at a limited cost of 0.05 certified radius. Meanwhile, ISS surpasses IAS on the average certified radius across the extensive hyperparameter settings. Specifically, ISS achieves ACR=0.958 on ImageNet in 250 minutes, compared to ACR=0.917 by IAS under the same condition. We release our code in https://github.com/roy-ch/Input-Specific-Certification. Ruoxin Chen, Jie Li 0002, Junchi Yan, Ping Li 0016, Bin Sheng 0001 |
AAAI | 1 |
| 2022 | Zero-Shot Scene Graph Generation with Knowledge Graph CompletionabstractLimited by the incomprehensive training samples, existing scene graph generation (SGG) methods perform poorly on predicting zero-shot (i.e., unseen) subject-predicate-object triples. To address this problem, we propose a general SGG framework to improve their zero-shot performance. The main idea of our method is to generate the information of zero-shot triples before the training of the predicate classifier and thus make the original zero-shot triples non-zero-shot. Specifically, the missing information of zero-shot triples is generated by our proposed knowledge graph completion strategy and then integrated with visual features of images. Therefore, the predicate classification of zero-shot triples is no longer just regarded as a single visual classification task but also transformed into a prediction task of missing links in a knowledge graph. The experiments on the dataset Visual Genome demonstrate that our proposed method outperforms the state-of-the-art methods in popular zero-shot metrics (i.e., zR@N, ng-zR@N) for all popular SGG tasks. Ruoxin Chen, Jie Li 0002, Jiawei Sun 0001, Shijing Yuan, Huxiao Ji, Chentao Wu |
ICME | 2 |
| 2022 | On Collective Robustness of Bagging Against Data PoisoningabstractBootstrap aggregating (bagging) is an effective ensemble protocol, which is believed can enhance robustness by its majority voting mechanism. Recent works further prove the sample-wise robustness certificates for certain forms of bagging (e.g. partition aggregation). Beyond these particular forms, in this paper, we propose the first collective certification for general bagging to compute the tight robustness against the global poisoning attack. Specifically, we compute the maximum number of simultaneously changed predictions via solving a binary integer linear programming (BILP) problem. Then we analyze the robustness of vanilla bagging and give the upper bound of the tolerable poison budget. Based on this analysis, we propose hash bagging to improve the robustness of vanilla bagging almost for free. This is achieved by modifying the random subsampling in vanilla bagging to a hash-based deterministic subsampling, as a way of controlling the influence scope for each poisoning sample universally. Our extensive experiments show the notable advantage in terms of applicability and robustness. Our code is available at https://github.com/Emiyalzn/ICML22-CRB. Ruoxin Chen, Zenan Li, Jie Li 0002, Junchi Yan, Chentao Wu |
ICML | 1 |