VLDB 2026 Research / reviewers in the wild / expert
Guanghao Zhou
dblp:326/4063
· DBLP profile ↗
7ranked-venue papers
3as first author
7since 2021 · last 2026
0009-0006-4549-4800ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 3 first-author · 5 since 2021Databases, data management, data science and information retrieval · 3 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | CCJA: Context-Coherent Jailbreak Attack for Aligned Large Language Models
Guanghao Zhou, Cen Chen 0001, Panjia Qiu, Mingyuan Fan 0003, Mingyuan Chu, Jun Zhou 0011 |
Mach. Learn. | 1 |
| 2025 | LSSF: Safety Alignment for Large Language Models through Low-Rank Safety Subspace FusionabstractThe safety mechanisms of large language models (LLMs) exhibit notable fragility, as even fine-tuning on datasets without harmful content may still undermine their safety capabilities.Meanwhile, existing safety alignment methods predominantly rely on the fine-tuning process, which inadvertently leads to the increased complexity and computational resources required.To address these issues, we introduce LSSF, a novel safety re-alignment framework with Low-Rank Safety Subspace Fusison.Our proposed method exploits the low-rank characteristics of safety information in LLMs by constructing a low-rank projection matrix to extract the principal components of safety vectors.Notably, this projection matrix represents the low-rank safety subspace of the LLMs, which we have observed to remain stable during fine-tuning process and is isolated from the model's general capabilities.These principal components are used to effectively restore safety alignment when combined with fine-tuned LLMs through linear arithmetic.Additionally, to account for the varying encoding densities of safety information across different layers of LLMs, we propose a novel metric called safety singular value entropy.This metric quantifies the encoding density and allows for the dynamic computation of the safety-critical rank for each safety vector.Extensive experiments demonstrate that our proposed post-hoc alignment method can effectively restore the safety alignment of finetuned models with minimal impact on their performance in downstream tasks. Guanghao Zhou, Panjia Qiu, Cen Chen 0001, Hongyu Li 0004, Jason Chu, Jun Zhou 0011 |
ACL (1) | 1 |
| 2025 | Exploring online communication in Asperger's syndrome: A combined approach with large language models and time series analysis
Xupin Zhang, Guanghao Zhou, Yanyu Zheng, Jiebo Luo 0001 |
Inf. Process. Manag. | 3 |
| 2024 | SGFL-Attack: A Similarity-Guidance Strategy for Hard-Label Textual Adversarial Attack Based on Feedback LearningabstractHard-label black-box textual adversarial attack presents a challenging task where only the predictions of the victim model are available. Moreover, several constraints further complicate the task of launching such attacks, including the inherent discrete and non-differentiable nature of text data and the need to introduce subtle perturbations that remain imperceptible to humans while preserving semantic similarity. Despite the considerable research efforts dedicated to this problem, existing methods still suffer from several limitations. For example, algorithms based on complex heuristic searches necessitate extensive querying, rendering them computationally expensive. The introduction of continuous gradient strategies into discrete text spaces often leads to estimation errors. Meanwhile, geometry-based strategies are prone to falling into local optima. To address these limitations, in this paper, we introduce SGFL-Attack, a novel approach that leverages a Similarity-Guidance strategy based on Feedback Learning for hard-label textual adversarial attack, with limited query budget. Specifically, the proposed SGFL-Attack utilizes word embedding vectors to assess the importance of words and positions in text sequences, and employs a feedback learning mechanism to determine reward or punishment based on changes in predicted labels caused by replacing words. In each iteration, SGFL-Attack guides the search based on knowledge acquired from the feedback learning mechanism, generating more similar samples while maintaining low perturbations. Moreover, to reduce the query budget, we incorporate local hash mapping to avoid redundant queries during the search process. Extensive experiments on seven widely used datasets show that the proposed SGFL-Attack method significantly outperforms state-of-the-art baselines and defenses over multiple language models. Panjia Qiu, Guanghao Zhou, Mingyuan Fan 0003, Cen Chen 0001, Yaliang Li, Wenming Zhou |
CIKM | 2 |
| 2024 | LST2A: Lexical-Syntactic Targeted Adversarial Attack for TextsabstractTextual adversarial attack in black-box scenarios is a challenging task, as only the predicted label is available, and the text space is discrete and non-differentiable. Current research in this area is still in its infancy and mostly focuses on untargeted attack, lacking the capability to control the labels of the generated adversarial examples. Meanwhile, existing textual adversarial attack methods primarily rely on word substitution operations to maintain semantic similarity between the adversarial and original examples, which greatly limits the search space for adversarial examples. To address these issues, we propose a novel Lexical-Syntactic Targeted Adversarial Attack method tailored for the black-box settings, referred to as LST2A. Our approach involves adversarial perturbations at different levels of granularities, i.e., word-level with word substitution operations and syntactic-level through rewriting the syntax of the examples. Specifically, we first embed the entire text into the embedding layer of a masked language model, and then optimize perturbations at the word level within the hidden state to generate adversarial examples with the target label. For examples that are difficult to attack successfully with only word-level perturbations at higher semantic similarity thresholds, we leverage Large Language Model (LLM) to introduce syntactic-level perturbations to these examples, making them more vulnerable to the decision boundary of the victim model. Subsequently, we re-optimize the word-level perturbations for these vulnerable examples. Extensive experiments and human evaluations demonstrate that our proposed method consistently outperforms the state-of-the-art baselines, crafting smoother, more grammatically correct adversarial examples. Guanghao Zhou, Panjia Qiu, Mingyuan Fan 0003, Cen Chen 0001, Yaliang Li, Wenmeng Zhou |
CIKM | 1 |
| 2023 | Pupil centre's localization with transformer without real pupil
Pengxiang Xue, Wenbo Huang 0003, Guangyi Jiang, Guanghao Zhou, Muhammad Raza |
Multim. Tools Appl. | 5 |
| 2022 | ORB Features and Isophotes Curvature Information for Eye Center Accurate LocalizationabstractPupil center recognition and location is an essential branch of ergonomics. It can be applied to emotion analysis and attention judgment. How to get the position of the pupil center from eye photos is the core of this field. Previous studies provided a helpful method, using scale-invariant feature transform (SIFT) to extract relevant features and combine them with the K-Nearest Neighbor (KNN) classifier. However, this method’s accuracy is not satisfying, and under some conditions, it will be position drift and other problems. We put forward a new idea to solve it by using Oriented FAST and Rotated BRIEF (ORB) features and Random Forest (RF) classifies. It is proved by experiment that our method improves the robustness of localization and the use of isophotes yields low computational cost, allowing for real-time processing. Meanwhile, we found that the ORB and RF are nearly as good, yielding an accuracy of 92.88% (BioID database). Pengxiang Xue, Wenbo Huang 0003, Guanghao Zhou |
Int. J. Pattern Recognit. Artif. Intell. | 4 |