Ziwen Xu

dblp:277/6261 · DBLP profile ↗
← Back
17ranked-venue papers
4as first author
17since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 11 · 2 first-author · 11 since 2021Graphics, computer vision, multimedia, augmented reality and games · 6 · 2 first-author · 6 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Why Steering Works: Toward a Unified View of Language Model Parameter Dynamics
abstract
Ziwen Xu, Chenyan WU, Hengyu Sun, Haiwen Hong, Mengru Wang, Yunzhi Yao, Longtao Huang, Hui Xue, Shumin Deng, Zhixuan Chu, Huajun Chen, Ningyu Zhang. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026.
Ziwen Xu, Chenyan Wu, Hengyu Sun, Haiwen Hong, Yunzhi Yao, Longtao Huang, Hui Xue 0001, Shumin Deng, Zhixuan Chu, Huajun Chen, Ningyu Zhang 0001
ACL (1)1
2026 How Controllable Are Large Language Models? A Unified Evaluation across Behavioral Granularities
abstract
Ziwen Xu, Kewei Xu, Haoming Xu, Haiwen Hong, Longtao Huang, Hui Xue, Ningyu Zhang, Yongliang Shen, Guozhou Zheng, Huajun Chen, Shumin Deng. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026.
Ziwen Xu, Kewei Xu, Haiwen Hong, Longtao Huang, Hui Xue 0001, Ningyu Zhang 0001, Yongliang Shen 0001, Guozhou Zheng, Huajun Chen, Shumin Deng
ACL (1)1
2026 SoftHist: Teaching Graph Injection Attackers to Camouflage with Memory
abstract
Graph Neural Networks (GNNs) have achieved notable success in a wide range of applications. However, their vulnerability to adversarial attacks, particularly graph injection attacks (GIAs), raises serious concerns for their deployment in security-sensitive domains. Existing GIA methods, despite their demonstrated effectiveness, face several inherent limitations. They typically require training surrogate models to approximate the victim model's behavior, which may lead to performance degradation when the surrogate mismatches the target model. Furthermore, the discrete nature of graph data poses challenges for generating effective adversarial features, often resulting in suboptimal solutions. Most critically, these methods show markedly reduced effectiveness when deployed against defended GNN models, limiting real-world applicability. To address these challenges, we introduce SoftHist, a novel gradient-free reinforcement learning framework for black-box graph injection attacks. Our approach incorporates a softened embedding mechanism to avoid suboptimal feature generation, ensuring stable and stealthy node injection. Moreover, we design a topology-aware edge sampler and a defense-aware policy learner with adaptive history reuse optimized for misclassification maximization. These innovations collectively balance attack effectiveness, stealthiness, and robustness against defensive measures. Extensive experiments on eight benchmark datasets demonstrate SoftHist's significant advantages in key scenarios: (1) On discrete-feature datasets like AMComputer, the misclassification rate is 10.34%~38.09% higher than baseline methods; (2) Against defensive models such as RGCN, it maintains 98.23% success rate, surpassing state-of-the-art methods by 12.36%.
Yidong Jiang, Ziwen Xu, Linbo Shao, Peng Zhu 0002, Dawei Cheng
WSDM2
2026 Dual-domain homogeneous fusion with cross-modal mamba and progressive decoder for 3D object detection
Xuzhong Hu, Zaipeng Duan, Pei An, Ziwen Xu, Jie Ma 0003
Pattern Recognit.5
2025 Beyond Prompt Engineering: Robust Behavior Control in LLMs via Steering Target Atoms
abstract
Mengru Wang, Ziwen Xu, Shengyu Mao, Shumin Deng, Zhaopeng Tu, Huajun Chen, Ningyu Zhang. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025.
Ziwen Xu, Shengyu Mao, Shumin Deng, Zhaopeng Tu, Huajun Chen, Ningyu Zhang 0001
ACL (1)2
2025 Automating Steering for Safe Multimodal Large Language Models
abstract
Recent progress in Multimodal Large Language Models (MLLMs) has unlocked powerful cross-modal reasoning abilities, but also raised new safety concerns, particularly when faced with adversarial multimodal inputs. To improve the safety of MLLMs during inference, we introduce a modular and adaptive inference-time intervention technology, AutoSteer, without requiring any fine-tuning of the underlying model. AutoSteer incorporates three core components: (1) a novel Safety Awareness Score (SAS) that automatically identifies the most safety-relevant distinctions among the model’s internal layers; (2) an adaptive safety prober trained to estimate the likelihood of toxic outputs from intermediate representations; and (3) a lightweight Refusal Head that selectively intervenes to modulate generation when safety risks are detected. Experiments on LLaVA-OV and Chameleon across diverse safety-critical benchmarks demonstrate that AutoSteer significantly reduces the Attack Success Rate (ASR) for textual, visual, and cross-modal threats, while maintaining general abilities. These findings position AutoSteer as a practical, interpretable, and effective framework for safer deployment of multimodal AI systems.
Lyucheng Wu, Ziwen Xu, Tri Cao, Nay Oo, Bryan Hooi, Shumin Deng
EMNLP3
2025 ADS-Edit: A Multimodal Knowledge Editing Dataset for Autonomous Driving Systems
Jizhan Fang, Xiang Chen 0016, Bozhong Tian, Ziwen Xu, Huajun Chen, Ningyu Zhang 0001
ACM Multimedia5
2025 FVQ: A Large-Scale Dataset and an LMM-based Method for Face Video Quality Assessment
abstract
Face video quality assessment (FVQA) deserves to be explored in addition to general video quality assessment (VQA), as face videos are the primary content on social media platforms and human visual system (HVS) is particularly sensitive to human faces. However, FVQA is rarely explored due to the lack of large-scale FVQA datasets. To fill this gap, we present the first large-scale in-the-wild FVQA dataset, FVQ-20K, which contains 20,000 in-the-wild face videos together with corresponding mean opinion score (MOS) annotations. Along with the FVQ-20K dataset, we further propose a specialized FVQA method named FVQ-Rater to achieve human-like rating and scoring for face video, which is the first attempt to explore the potential of large multimodal models (LMMs) for the FVQA task. Concretely, we elaborately extract multi-dimensional features including spatial features, temporal features, and face-specific features (i.e., portrait features and face embeddings) to provide comprehensive visual information, and take advantage of the LoRA-based instruction tuning technique to achieve quality-specific fine-tuning, which shows superior performance on both FVQ-20K and CFVQA datasets. Extensive experiments and comprehensive analysis demonstrate the significant potential of the FVQ-20K dataset and FVQ-Rater method in promoting the development of FVQA. The code and dataset will be released at: https://github.com/wsj-sjtu/FVQ.
Sijing Wu, Ziwen Xu, Huiyu Duan, Wei Sun 0029, Guangtao Zhai
ACM Multimedia3
2025 Model Merging in Pre-training of Large Language Models
abstract
Model merging has emerged as a promising technique for enhancing large language models, though its application in large-scale pre-training remains relatively unexplored. In this paper, we present a comprehensive investigation of model merging techniques during the pre-training process. Through extensive experiments with both dense and Mixture-of-Experts (MoE) architectures ranging from millions to over 100 billion parameters, we demonstrate that merging checkpoints trained with constant learning rates not only achieves significant performance improvements but also enables accurate prediction of annealing behavior. These improvements lead to both more efficient model development and significantly lower training costs. Our detailed ablation studies on merging strategies and hyperparameters provide new insights into the underlying mechanisms while uncovering novel applications. Through comprehensive experimental analysis, we offer the open-source community practical pre-training guidelines for effective model merging.
Yunshui Li, Yiyuan Ma, Chaoyi Zhang, Jianqiao Lu, Ziwen Xu, Mengzhao Chen, Minrui Wang, Shiyi Zhan, Xunhao Lai, Yao Luo, Xingyan Bin, Hongbin Ren, Mingji Han, Wenhao Hao, Bairen Yi, LingJun Liu, Bole Ma, Xiaoying Jia 0005
NeurIPS7
2024 Detoxifying Large Language Models via Knowledge Editing
abstract
Mengru Wang, Ningyu Zhang, Ziwen Xu, Zekun Xi, Shumin Deng, Yunzhi Yao, Qishen Zhang, Linyi Yang, Jindong Wang, Huajun Chen. Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2024.
Ningyu Zhang 0001, Ziwen Xu, Zekun Xi, Shumin Deng, Yunzhi Yao, Qishen Zhang, Linyi Yang, Jindong Wang 0001, Huajun Chen
ACL (1)3
2024 WISE: Rethinking the Knowledge Memory for Lifelong Model Editing of Large Language Models
abstract
Large language models (LLMs) need knowledge updates to meet the ever-growing world facts and correct the hallucinated responses, facilitating the methods of lifelong model editing. Where the updated knowledge resides in memories is a fundamental question for model editing. In this paper, we find that editing either long-term memory (direct model parameters) or working memory (non-parametric knowledge of neural network activations/representations by retrieval) will result in an impossible triangle---reliability, generalization, and locality can not be realized together in the lifelong editing settings. For long-term memory, directly editing the parameters will cause conflicts with irrelevant pretrained knowledge or previous edits (poor reliability and locality). For working memory, retrieval-based activations can hardly make the model understand the edits and generalize (poor generalization). Therefore, we propose WISE to bridge the gap between memories. In WISE, we design a dual parametric memory scheme, which consists of the main memory for the pretrained knowledge and a side memory for the edited knowledge. We only edit the knowledge in the side memory and train a router to decide which memory to go through when given a query. For continual editing, we devise a knowledge-sharding mechanism where different sets of edits reside in distinct subspaces of parameters, and are subsequently merged into a shared memory without conflicts. Extensive experiments show that WISE can outperform previous model editing methods and overcome the impossible triangle under lifelong model editing of question answering, hallucination, and out-of-distribution settings across trending LLM architectures, e.g., GPT, LLaMA, and Mistral.
Peng Wang 0104, Ningyu Zhang 0001, Ziwen Xu, Yunzhi Yao, Yong Jiang 0005, Pengjun Xie, Fei Huang 0002, Huajun Chen
NeurIPS4
2024 Knowledge Circuits in Pretrained Transformers
abstract
The remarkable capabilities of modern large language models are rooted in their vast repositories of knowledge encoded within their parameters, enabling them to perceive the world and engage in reasoning. The inner workings of how these models store knowledge have long been a subject of intense interest and investigation among researchers. To date, most studies have concentrated on isolated components within these models, such as the Multilayer Perceptrons and attention head. In this paper, we delve into the computation graph of the language model to uncover the knowledge circuits that are instrumental in articulating specific knowledge. The experiments, conducted with GPT2 and TinyLLAMA, has allowed us to observe how certain information heads, relation heads, and Multilayer Perceptrons collaboratively encode knowledge within the model. Moreover, we evaluate the impact of current knowledge editing techniques on these knowledge circuits, providing deeper insights into the functioning and constraints of these editing methodologies. Finally, we utilize knowledge circuits to analyze and interpret language model behaviors such as hallucinations and in-context learning. We believe the knowledge circuit holds potential for advancing our understanding of Transformers and guiding the improved design of knowledge editing.
Yunzhi Yao, Ningyu Zhang 0001, Zekun Xi, Ziwen Xu, Shumin Deng, Huajun Chen
NeurIPS5
2024 Overview of the NLPCC 2024 Shared Task 10: Regulating Large Language Models
Ziwen Xu, Xiang Chen 0016, Shumin Deng, Ningyu Zhang 0001
NLPCC (5)2
2023 Context-Aware Data Augmentation for LIDAR 3d Object Detection
abstract
For 3D LIDAR object detection, data augmentation is an important module to make full use of precious annotated data. As a widely used data augmentation method, GT-aug effectively improves detection performance by inserting sampled groundtruths into LIDAR frames. However, they are often placed in unreasonable areas, leading to the loss of the semantic information between targets and backgrounds during training. To address this problem, we propose a context-aware data augmentation method (CA-aug), which ensures the proper placement of inserted objects by a simple strategy and produces realistic augmented scenes. CA-aug is lightweight and compatible with other augmentation methods. Experiments conducted on KITTI benckmark show that compared with the GT-aug and the similar method in LIDAR-aug (SOTA), it brings higher accuracy to the existing models especially for the detection of cyclists and perdestrians. We also present an in-depth study of augmentation strategies for the range-view-based (RV-based) models and demonstrate that CA-aug can fully exploit the potential of RV-based networks, boosting the moderate mAP of our test model by 8%.
Xuzhong Hu, Zaipeng Duan, Xiao Huang 0008, Ziwen Xu, Delie Ming, Jie Ma 0003
ICIP4
2023 A deep retinal image quality assessment network with salient structure priors
Ziwen Xu, Beiji Zou 0001, Qing Liu 0003
Multim. Tools Appl.1
2021 Multi-branch Multi-task 3D-CNN for Alzheimer's Disease Detection
Junhu Li, Beiji Zou 0001, Ziwen Xu, Qing Liu 0003
PRCV (3)3
2021 A Dark and Bright Channel Prior Guided Deep Network for Retinal Image Quality Assessment
Ziwen Xu, Beiji Zou 0001, Qing Liu 0003
PRCV (3)1