VLDB 2026 Research / reviewers in the wild / expert
Hongrui Chen
dblp:292/5456
· DBLP profile ↗
11ranked-venue papers
4as first author
11since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 8 · 2 first-author · 8 since 2021Computer networks · 2 · 2 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
7 papers |
Trustworthy machine learning · 54% Generative modeling · 13% Optimization for machine learning · 11% | |
| Network and information security
4 papers |
Security and privacy of machine learning · 100% | |
| Computer graphics and multimedia
1 paper |
Computational photography and imaging · 100% |
Topics — the 19 heaviest of 23, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Security and privacy of machine learning › adversarial attack
backdoor attack |
1.9 | 2 | 2026 | Versatile Backdoor Attack With Visible, Semantic, Sample-Specific and Compatible Triggers · IEEE Trans. Pattern Anal. Mach. Intell. 2026 BackdoorBench: A Comprehensive Benchmark and Analysis of Backdoor Learning · Int. J. Comput. Vis. 2025 |
Machine learning › Trustworthy machine learning › adversarial machine learning
adversarial defense |
1.0 | 1 | 2026 | Defenses in Adversarial Machine Learning: A Systematic Survey From the Lifecycle Perspective · IEEE Trans. Pattern Anal. Mach. Intell. 2026 |
Machine learning › Trustworthy machine learning
adversarial machine learning |
1.0 | 1 | 2026 | Defenses in Adversarial Machine Learning: A Systematic Survey From the Lifecycle Perspective · IEEE Trans. Pattern Anal. Mach. Intell. 2026 |
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
1.0 | 1 | 2026 | Defenses in Adversarial Machine Learning: A Systematic Survey From the Lifecycle Perspective · IEEE Trans. Pattern Anal. Mach. Intell. 2026 |
Machine learning › Probabilistic and Bayesian machine learning › statistical dependence
conditional dependence estimation |
1.0 | 1 | 2026 | BiCD: Learning Conditional Dependence for Continuous Dataset Shift in Regression · KDD (1) 2026 |
Machine learning › Trustworthy machine learning › robustness
distribution shift |
1.0 | 1 | 2026 | BiCD: Learning Conditional Dependence for Continuous Dataset Shift in Regression · KDD (1) 2026 |
Security and privacy of machine learning › adversarial attack › backdoor attack
physical backdoor attack |
1.0 | 1 | 2026 | Versatile Backdoor Attack With Visible, Semantic, Sample-Specific and Compatible Triggers · IEEE Trans. Pattern Anal. Mach. Intell. 2026 |
Machine learning › Trustworthy machine learning
robustness evaluation |
0.9 | 1 | 2025 | BlackboxBench: A Comprehensive Benchmark of Black-Box Adversarial Attacks · IEEE Trans. Pattern Anal. Mach. Intell. 2025 |
Security and privacy of machine learning
adversarial attack |
0.9 | 1 | 2025 | BlackboxBench: A Comprehensive Benchmark of Black-Box Adversarial Attacks · IEEE Trans. Pattern Anal. Mach. Intell. 2025 |
Security and privacy of machine learning › adversarial attack
black-box attack |
0.9 | 1 | 2025 | BlackboxBench: A Comprehensive Benchmark of Black-Box Adversarial Attacks · IEEE Trans. Pattern Anal. Mach. Intell. 2025 |
Machine learning › Optimization for machine learning
convergence guarantees |
0.7 | 1 | 2023 | Improved Analysis of Score-based Generative Modeling: User-Friendly Bounds under Minimal Smoothness Assumptions · ICML 2023 |
Machine learning › Generative modeling
diffusion model |
0.7 | 1 | 2023 | Improved Analysis of Score-based Generative Modeling: User-Friendly Bounds under Minimal Smoothness Assumptions · ICML 2023 |
Machine learning › Optimization for machine learning › convergence analysis
sampling convergence |
0.7 | 1 | 2023 | Improved Analysis of Score-based Generative Modeling: User-Friendly Bounds under Minimal Smoothness Assumptions · ICML 2023 |
Machine learning › Generative modeling › diffusion model
score-based generative model |
0.7 | 1 | 2023 | Improved Analysis of Score-based Generative Modeling: User-Friendly Bounds under Minimal Smoothness Assumptions · ICML 2023 |
Machine learning › Trustworthy machine learning
robustness |
0.6 | 1 | 2022 | BackdoorBench: A Comprehensive Benchmark of Backdoor Learning · NeurIPS 2022 |
Computational photography and imaging
illumination estimation |
0.5 | 1 | 2021 | DSNet: Deep Shadow Network for Illumination Estimation · VR 2021 |
Computational photography and imaging › illumination estimation
outdoor illumination estimation |
0.5 | 1 | 2021 | DSNet: Deep Shadow Network for Illumination Estimation · VR 2021 |
Computer vision › Vision and language
vision-language model |
0.3 | 1 | 2026 | Versatile Backdoor Attack With Visible, Semantic, Sample-Specific and Compatible Triggers · IEEE Trans. Pattern Anal. Mach. Intell. 2026 |
Machine learning › Generative modeling
score estimation |
0.2 | 1 | 2023 | Improved Analysis of Score-based Generative Modeling: User-Friendly Bounds under Minimal Smoothness Assumptions · ICML 2023 |
Methods — techniques the papers use, named apart from their topics
large language model · 2.0generative model · 2.0transfer-based attack · 1.7query-based attack · 1.7systematic survey · 1.0lifecycle taxonomy · 1.0kernel dependence · 1.0information-theoretic learning · 1.0graph laplacian · 1.0early stopping · 0.7backdoor defense · 0.6backdoor attack · 0.6deep shadow network · 0.5data augmentation · 0.5
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | BiCD: Learning Conditional Dependence for Continuous Dataset Shift in RegressionabstractAs a crucial data mining problem, domain adaptation (DA) under dataset shift offers an effective paradigm for transferring knowledge in changing environments (i.e., shifting data distributions). Recent theoretical advances show that learning conditional information is crucial for successful DA, and empirical models with provable performance have been developed under discrete priors. However, for many real-world complex tasks with continuous label spaces, e.g., regression, conditional information is generally intractable, and shift correction models remain unexplored due to the high-dimensional nature of continuous variables. To deal with these challenges, we propose an information-theoretic learning principle called bi-level conditional dependence (BiCD) for continuous shift setting. BiCD characterizes the conditional information of learned representations from two aspects: conditional domain dependence and conditional label dependence, where our results prove that bi-level dependence learning is sufficient to obtain representations with desired properties and to minimize the generalization error. Moreover, BiCD also admits appealing properties for practical modeling: 1) an equivalent formulation with marginal dependence is derived to avoid the explicit computation of high-dimensional conditional dependence in practical modeling; 2) a kernel dependence-based variant is developed to serve as a guaranteed numerical proxy for the vanilla BiCD; 3) a graph Laplacian understanding is provided to justify the learning mechanism of BiCD. Empirically, BiCD is evaluated on standard DA regression datasets, where the significance of the proposed dependence learning principle is validated and SOTA performance is consistently achieved. Hongrui Chen, Yiming Zhai, Mingjun Pan, You-Wei Luo |
KDD (1) | 1 |
| 2026 | Versatile Backdoor Attack With Visible, Semantic, Sample-Specific and Compatible TriggersabstractDeep neural networks (DNNs) can be manipulated to exhibit specific behaviors when exposed to specific trigger patterns, without affecting their performance on benign samples, dubbed backdoor attack. Currently, implementing backdoor attacks in physical scenarios still faces significant challenges. Physical attacks are labor-intensive and time-consuming, and the triggers are selected in a manual and heuristic way. Moreover, expanding digital attacks to physical scenarios faces many challenges due to their sensitivity to visual distortions and the absence of counterparts in the real world. To address these challenges, we define a novel trigger called the Visible, Semantic, Sample-specific, and Compatible (VSSC) trigger, to achieve effective, stealthy and robust simultaneously, which can also be effectively deployed in the physical scenario using corresponding objects. To implement the VSSC trigger, we propose an automated pipeline comprising three modules: a trigger selection module that systematically identifies suitable triggers leveraging large language models, a trigger insertion module that employs generative models to seamlessly integrate triggers into images, and a quality assessment module that ensures the natural and successful insertion of triggers through vision-language models. Extensive experimental results and analysis validate the effectiveness, stealthiness, and robustness of the VSSC trigger. It can not only maintain robustness under visual distortions but also demonstrates strong practicality in the physical scenario. By providing the first automated pipeline, VSSC transforms physical backdoor attacks from a labor-intensive craft into a systematic and realistic threat to real-world AI systems. We hope the proposed VSSC trigger and implementation approach could inspire future studies on designing more practical triggers in backdoor attacks. Ruotong Wang 0008, Hongrui Chen, Zihao Zhu 0001, Li Liu 0036, Baoyuan Wu |
IEEE Trans. Pattern Anal. Mach. Intell. | 2 |
| 2026 | Defenses in Adversarial Machine Learning: A Systematic Survey From the Lifecycle PerspectiveabstractAdversarial phenomena have been widely observed in machine learning (ML) systems, especially those using deep neural networks. These phenomena describe situations where ML systems may produce predictions that are inconsistent and incomprehensible to humans in certain specific cases. Such behavior poses a serious security threat to the practical application of ML systems. To exploit this vulnerability, several advanced attack paradigms have been developed, mainly including backdoor attacks, weight attacks, and adversarial examples. For each individual attack paradigm, various defense mechanisms have been proposed to enhance the robustness of models against the corresponding attacks. However, due to the independence and diversity of these defense paradigms, it is challenging to assess the overall robustness of an ML system against different attack paradigms. This survey aims to provide a systematic review of all existing defense paradigms from a unified lifecycle perspective. Specifically, we decompose a complete ML system into five stages: pre-training, training, post-training, deployment, and inference. We then present a clear taxonomy to categorize representative defense methods at each stage. The unified perspective and taxonomy not only help us analyze defense mechanisms but also enable us to understand the connections and differences among different defense paradigms. It inspires future research to develop more advanced and comprehensive defense strategies. Baoyuan Wu, Mingli Zhu, Meixi Zheng, Zihao Zhu 0001, Shaokui Wei, Hongrui Chen, Danni Yuan, Li Liu 0036, Qingshan Liu 0001 |
IEEE Trans. Pattern Anal. Mach. Intell. | 7 |
| 2025 | The Imitation Game revisited: A comprehensive survey on recent advances in AI-generated text detection
Zhiwei Yang 0005, Zhengjie Feng, Rongxin Huo, Huiru Lin, Hanghan Zheng, Ruichi Nie, Hongrui Chen |
Expert Syst. Appl. | 7 |
| 2025 | BackdoorBench: A Comprehensive Benchmark and Analysis of Backdoor Learning
Baoyuan Wu, Hongrui Chen, Zihao Zhu 0001, Shaokui Wei, Danni Yuan, Mingli Zhu, Ruotong Wang 0008, Li Liu 0036 |
Int. J. Comput. Vis. | 2 |
| 2025 | BlackboxBench: A Comprehensive Benchmark of Black-Box Adversarial AttacksabstractAdversarial examples are well-known tools to evaluate the vulnerability of deep neural networks (DNNs). Although lots of adversarial attack algorithms have been developed, it's still challenging in the practical scenario that the model's parameters and architectures are inaccessible to the attacker/evaluator, i.e., black-box adversarial attacks. Due to the practical importance, there has been rapid progress from recent algorithms, reflected by the quick increase in attack success rate and quick decrease in query numbers to the target model. However, there lacks thorough evaluations and comparisons among these algorithms, causing difficulties in tracking the real progress, analyzing advantages and disadvantages of different technical routes, as well as designing future development roadmap of this field. Thus, we aim at building a comprehensive benchmark of black-box adversarial attacks, called BlackboxBench. It mainly provides: 1) a unified, extensible and modular-based codebase, implementing 29 query-based attack algorithms and 30 transfer-based attack algorithms; 2) comprehensive evaluations: we evaluate the implemented algorithms against several mainstreaming model architectures on 2 widely used datasets (CIFAR-10 and a subset of ImageNet), leading to 14,950 evaluations$^{1}$1 in total; 3) thorough analysis and new insights, as well analytical tools. Meixi Zheng, Xuanchen Yan, Zihao Zhu 0001, Hongrui Chen, Baoyuan Wu |
IEEE Trans. Pattern Anal. Mach. Intell. | 4 |
| 2024 | A Multi-Slot Load Balancing Scheme for LEO Satellite Communication Handover Target SelectionabstractThe Low-Earth-Orbit (LEO) constellation has emerged as a promising component for seamless and fast global connectivity. With the increasing number of satellites in LEO constellations, multiple satellites can simultaneously cover the same geographical area. The selection of a user's handover (HO) target can significantly impact the quality of service (QoS) for communication and the load status of the satellite network. Motivated by this, the paper introduces a multi-slot load balancing (MSLB) scheme to offer users HO target selection strategies. An optimization problem is formulated to determine the HO sequence for users according to the MSLB scheme. Subsequently, a HO sequence graph mapping (HSGM) algorithm and an iterative shortest path solving (ISPS) algorithm are developed to address this optimization problem by transforming it into a shortest path searching problem. Simulation results demonstrate that, in comparison to traditional single-slot schemes, the MSLB scheme exhibits superior performance in load balancing and improving user communication QoS. Hongrui Chen, Gaofeng Nie, Hui Tian 0003 |
WCNC | 1 |
| 2023 | Improved Analysis of Score-based Generative Modeling: User-Friendly Bounds under Minimal Smoothness AssumptionsabstractWe give an improved theoretical analysis of score-based generative modeling. Under a score estimate with small $L^2$ error (averaged across timesteps), we provide efficient convergence guarantees for any data distribution with second-order moment, by either employing early stopping or assuming smoothness condition on the score function of the data distribution. Our result does not rely on any log-concavity or functional inequality assumption and has a logarithmic dependence on the smoothness. In particular, we show that under only a finite second moment condition, approximating the following in reverse KL divergence in $\epsilon$-accuracy can be done in $\tilde O\left(\frac{d \log (1/\delta)}{\epsilon}\right)$ steps: 1) the variance-$\delta$ Gaussian perturbation of any data distribution; 2) data distributions with $1/\delta$-smooth score functions. Our analysis also provides a quantitative comparison between different discrete approximations and may guide the choice of discretization points in practice. Hongrui Chen, Holden Lee, Jianfeng Lu 0001 |
ICML | 1 |
| 2022 | BackdoorBench: A Comprehensive Benchmark of Backdoor LearningabstractBackdoor learning is an emerging and vital topic for studying deep neural networks' vulnerability (DNNs). Many pioneering backdoor attack and defense methods are being proposed, successively or concurrently, in the status of a rapid arms race. However, we find that the evaluations of new methods are often unthorough to verify their claims and accurate performance, mainly due to the rapid development, diverse settings, and the difficulties of implementation and reproducibility. Without thorough evaluations and comparisons, it is not easy to track the current progress and design the future development roadmap of the literature. To alleviate this dilemma, we build a comprehensive benchmark of backdoor learning called BackdoorBench. It consists of an extensible modular-based codebase (currently including implementations of 8 state-of-the-art (SOTA) attacks and 9 SOTA defense algorithms) and a standardized protocol of complete backdoor learning. We also provide comprehensive evaluations of every pair of 8 attacks against 9 defenses, with 5 poisoning ratios, based on 5 models and 4 datasets, thus 8,000 pairs of evaluations in total. We present abundant analysis from different perspectives about these 8,000 evaluations, studying the effects of different factors in backdoor learning. All codes and evaluations of BackdoorBench are publicly available at https://backdoorbench.github.io. Baoyuan Wu, Hongrui Chen, Zihao Zhu 0001, Shaokui Wei, Danni Yuan |
NeurIPS | 2 |
| 2021 | Long-Term Visual Localization with Semantic Enhanced Global RetrievalabstractVisual localization under varying conditions such as changes in illumination, season and weather is a fundamental task for applications such as autonomous navigation. In this paper, we present a novel method of using semantic information for global image retrieval. By exploiting the distribution of different classes in a semantic scene, the discriminative features of the scene’s structure layout is embedded into a normalized vector that can be used for retrieval, i.e. semantic retrieval. Color image retrieval is based on low-level visual features extracted by algorithms or Convolutional Neural Networks (CNNs), while semantic retrieval is based on high-level semantic features which are robust in scene appearance variations. By combining semantic retrieval with color image retrieval in the global retrieval step, we show that these two methods can complement with each other and significantly improve the localization performance. Experiments on the challenging CMU Seasons dataset show that our method is robust across large variations of appearance and achieves state-of-the-art localization performance. Hongrui Chen, Yuan Xiong, Zhong Zhou |
MSN | 1 |
| 2021 | DSNet: Deep Shadow Network for Illumination EstimationabstractIllumination consistency has applications to modeling and rendering in virtual reality. In 3D reconstruction and Mixed Reality(MR) fusion, the appearance of a large-scale outdoor scene may change in response to lighting and seasons, for example. Since 3D reconstruction from scratch is costly, it is helpful to be able to update existing models with recently captured photographs. However, the illumination conditions of the captured photograph can be arbitrary, making it challenging to fit to the existing model. To tackle this problem, this paper proposes a novel approach that can precisely estimate the illumination of the input image. Our Deep Shadow Network (DSNet) collaboratively utilizes illumination-based data augmentation for sun position estimation, along with a dataset of illumination-based augmented renderings. Our run-time rendering and optimization strategy is also discussed. We show that accurate simulation of illumination can improve the performance of visual applications including place recognition and long-term localization. Experimental results validate the effectiveness of the proposed approach, and show its superiority over the state-of-the-art. Yuan Xiong, Hongrui Chen, Zhe Zhu, Zhong Zhou |
VR | 2 |