VLDB 2026 Research / reviewers in the wild / expert
Kunzhe Huang
dblp:275/3235
· DBLP profile ↗
7ranked-venue papers
1as first author
7since 2021 · last 2025
0009-0003-6047-2827ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 4 · 1 first-author · 4 since 2021Security and privacy · 2 · 2 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | EasyAnimate: High-Performance Video Generation Framework with Hybrid Windows Attention and Reward BackpropagationabstractThis paper introduces EasyAnimate, an efficient and high quality video generation framework that leverages diffusion transformers to achieve high-quality video production, encompassing data processing, model training, and end-to-end inference. Despite substantial advancements achieved by video diffusion models, existing video generation models still struggles with slow generation speeds and less-than-ideal video quality. To improve training and inference efficiency without compromising performance, we propose Hybrid Window Attention. We design the multidirectional sliding window attention in Hybrid Window Attention, which provides stronger receptive capabilities in 3D dimensions compared to naive one, while reducing the model's computational complexity as the video sequence length increases. To enhance video generation quality, we optimize EasyAnimate using reward backpropagation to better align with human preferences. As a post-training method, it greatly enhances the model's performance while ensuring efficiency. In addition to the aforementioned improvements, EasyAnimate integrates a series of further refinements that significantly improve both computational efficiency and model performance. We introduce a new training strategy called Training with Token Length to resolve uneven GPU utilization in training videos of varying resolutions and lengths, thereby enhancing efficiency. Additionally, we use a multimodal large language model as the text encoder to improve text comprehension of the model. Experiments demonstrate significant enhancements resulting from the above improvements. The EasyAnimate achieves state-of-the-art performance on both the VBench leaderboard and human evaluation. Code and pre-trained models are available at https://github.com/aigc-apps/EasyAnimate. Kunzhe Huang, Xinyi Zou, Yunkuo Chen, Mengli Cheng, Jun Huang 0007 |
ACM Multimedia | 2 |
| 2024 | VideoCLIP-XL: Advancing Long Description Understanding for Video CLIP ModelsabstractContrastive Language-Image Pre-training (CLIP) has been widely studied and applied in numerous applications.However, the emphasis on brief summary texts during pre-training prevents CLIP from understanding long descriptions.This issue is particularly acute regarding videos given that videos often contain abundant detailed contents.In this paper, we propose the VideoCLIP-XL (eXtra Length) model, which aims to unleash the long-description understanding capability of video CLIP models.Firstly, we establish an automatic data collection system and gather a large-scale VILD pre-training dataset 1 with VIdeo and Long-Description pairs.Then, we propose Text-similarity-guided Primary Component Matching (TPCM) to better learn the distribution of feature space while expanding the long description capability.We also introduce two new tasks namely Detail-aware Description Ranking (DDR) and Hallucination-aware Description Ranking (HDR) for further understanding improvement.Finally, we construct a Long Video Description Ranking (LVDR) benchmark 2 for evaluating the long-description capability more comprehensively.Extensive experimental results on widely-used text-video retrieval benchmarks with both short and long descriptions and our LVDR benchmark can fully demonstrate the effectiveness of our method.3 Jiapeng Wang 0003, Chengyu Wang 0001, Kunzhe Huang, Jun Huang 0007 |
EMNLP | 3 |
| 2024 | Towards Reliable and Efficient Backdoor Trigger Inversion via Decoupling Benign FeaturesabstractRecent studies revealed that using third-party models may lead to backdoor threats, where adversaries can maliciously manipulate model predictions based on backdoors implanted during model training. Arguably, backdoor trigger inversion (BTI), which generates trigger patterns of given benign samples for a backdoored model, is the most critical module for backdoor defenses used in these scenarios. With BTI, defenders can remove backdoors by fine-tuning based on generated poisoned samples with ground-truth labels or deactivate backdoors by removing trigger patterns during the inference process. However, we find that existing BTI methods suffer from relatively poor performance, $i.e.$, their generated triggers are significantly different from the ones used by the adversaries even in the feature space. We argue that it is mostly because existing methods require to 'extract' backdoor features at first, while this task is very difficult since defenders have no information ($e.g.$, trigger pattern or target label) about poisoned samples. In this paper, we explore BTI from another perspective where we decouple benign features instead of decoupling backdoor features directly. Specifically, our method consists of two main steps, including \textbf{(1)} decoupling benign features and \textbf{(2)} trigger inversion by minimizing the differences between benign samples and their generated poisoned version in decoupled benign features while maximizing the differences in remaining backdoor features. In particular, our method is more efficient since it doesn't need to `scan' all classes to speculate the target label, as required by existing BTI. We also exploit our BTI module to further design backdoor-removal and pre-processing-based defenses. Extensive experiments on benchmark datasets demonstrate that our defenses can reach state-of-the-art performances. Kunzhe Huang, Yiming Li 0004, Zhan Qin, Kui Ren 0001 |
ICLR | 2 |
| 2024 | PertEval: Unveiling Real Knowledge Capacity of LLMs with Knowledge-Invariant PerturbationsabstractExpert-designed close-ended benchmarks are indispensable in assessing the knowledge capacity of large language models (LLMs). Despite their widespread use, concerns have mounted regarding their reliability due to limited test scenarios and an unavoidable risk of data contamination. To rectify this, we present PertEval, a toolkit devised for in-depth probing of LLMs' knowledge capacity through knowledge-invariant perturbations. These perturbations employ human-like restatement techniques to generate on-the-fly test samples from static benchmarks, meticulously retaining knowledge-critical content while altering irrelevant details. Our toolkit further includes a suite of response consistency analyses that compare performance on raw vs. perturbed test sets to precisely assess LLMs' genuine knowledge capacity. Six representative LLMs are re-evaluated using PertEval. Results reveal significantly inflated performance of the LLMs on raw benchmarks, including an absolute 25.8% overestimation for GPT-4. Additionally, through a nuanced response pattern analysis, we discover that PertEval retains LLMs' uncertainty to specious knowledge, and reveals their potential rote memorization to correct options which leads to overestimated performance. We also find that the detailed response consistency analyses by PertEval could illuminate various weaknesses in existing LLMs' knowledge mastery and guide the development of refinement. Our findings provide insights for advancing more robust and genuinely knowledgeable LLMs. Our code is available at https://github.com/aigc-apps/PertEval. Jiatong Li 0002, Renjun Hu, Kunzhe Huang, Yan Zhuang 0001, Qi Liu 0003, Mengxiao Zhu 0001, Wei Lin 0016 |
NeurIPS | 3 |
| 2024 | Privacy Enhancement Via Dummy Points in the Shuffle ModelabstractThe shuffle model is recently proposed to address the issue of severe utility loss in Local Differential Privacy (LDP) due to distributed data randomization. In the shuffle model, a shuffler is utilized to break the link between the user identity and the message uploaded to the data analyst. Since less noise needs to be introduced to achieve the same privacy guarantee, following this paradigm, the utility of privacy-preserving data collection is improved. We propose DUMP (DUMmy-Point-based), a framework for privacy-preserving histogram estimation in the shuffle model. The core of DUMP is a new concept ofdummy blanket, which enables enhancing privacy by just introducing dummy points on the user side and further improving the utility of the shuffle model. We instantiate DUMP by proposing two protocols: pureDUMP and mixDUMP, and conduct a comprehensive experimental evaluation to compare them with existing protocols. The experimental results show that, under the same privacy guarantee, (1) the proposed protocols have significant improvements in communication efficiency over all existing multi-message protocols, by at least 3 orders of magnitude; (2) they achieve competitive utility, while the only known protocol (Ghaziet al., PMLR 2020) having better utility than ours employs hard-to-exactly-sample distributions which are vulnerable to floating-point attacks (CCS 2012). Hanwen Feng 0001, Kunzhe Huang, Yuke Hu, Jinfei Liu, Kui Ren 0001, Zhan Qin |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2024 | RemovalNet: DNN Fingerprint Removal AttacksabstractWith the performance of deep neural networks (DNNs) remarkably improving, DNNs have been widely used in many areas. Consequently, the DNN model has become a valuable asset, and its intellectual property is safeguarded by ownership verification techniques (e.g., DNN fingerprinting). However, the feasibility of the DNN fingerprint removal attack and its potential influence remains an open problem. In this paper, we perform the first comprehensive investigation of DNN fingerprint removal attacks. Generally, the knowledge contained in a DNN model can be categorized into general semantic and fingerprint-specific knowledge. To this end, we propose a min-max bilevel optimization-based DNN fingerprint removal attack namedRemovalNet, to evade model ownership verification. The lower-level optimization is designed to remove fingerprint-specific knowledge. While in the upper-level optimization, we distill the victim model's general semantic knowledge to maintain the surrogate model's performance. We conduct extensive experiments to evaluate thefidelity,effectiveness, andefficiencyof theRemovalNetagainst four advanced defense methods on six metrics. The empirical results demonstrate that (1) theRemovalNetiseffective. After our DNN fingerprint removal attack, the model distance between the target and surrogate models is ×100 times higher than that of the baseline attacks, (2) theRemovalNetisefficient. It uses only 0.2% (400 samples) of the substitute dataset and 1,000 iterations to conduct our attack. Besides, compared with advanced model stealing attacks, theRemovalNetsaves nearly 85% of computational resources at most, (3) theRemovalNetachieves highfidelitythat the created surrogate model maintains high accuracy after the DNN fingerprint removal process. Hongwei Yao, Zheng Li 0023, Kunzhe Huang, Jian Lou 0001, Zhan Qin, Kui Ren 0001 |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2022 | Backdoor Defense via Decoupling the Training Process
Kunzhe Huang, Yiming Li 0004, Baoyuan Wu, Zhan Qin, Kui Ren 0001 |
ICLR | 1 |