VLDB 2026 Research / reviewers in the wild / expert
Hyeonjeong Ha
dblp:331/5333
· DBLP profile ↗
5ranked-venue papers
3as first author
5since 2021 · last 2026
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 5 · 3 first-author · 5 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Artificial intelligence
3 papers |
Efficient and distributed learning · 39% Trustworthy machine learning · 26% Language models and text generation · 17% | |
| Network and information security
1 paper |
Security and privacy of machine learning · 100% | |
| Databases, data mining, and information retrieval
1 paper |
Information retrieval · 100% |
Topics — the 11 heaviest of 14, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Information retrieval › retrieval-augmented generation
multimodal retrieval-augmented generation |
1.0 | 1 | 2026 | MM-PoisonRAG: Disrupting Multimodal RAG with Local and Global Knowledge Poisoning Attacks · ACL (1) 2026 |
Information retrieval
retrieval-augmented generation |
1.0 | 1 | 2026 | MM-PoisonRAG: Disrupting Multimodal RAG with Local and Global Knowledge Poisoning Attacks · ACL (1) 2026 |
Security and privacy of machine learning
poisoning attack |
1.0 | 1 | 2026 | MM-PoisonRAG: Disrupting Multimodal RAG with Local and Global Knowledge Poisoning Attacks · ACL (1) 2026 |
Security and privacy of machine learning › retrieval-augmented generation security
retrieval-augmented generation poisoning |
1.0 | 1 | 2026 | MM-PoisonRAG: Disrupting Multimodal RAG with Local and Global Knowledge Poisoning Attacks · ACL (1) 2026 |
Machine learning › Trustworthy machine learning › robustness
adversarial robustness |
0.7 | 1 | 2023 | Effective Targeted Attacks for Adversarial Self-Supervised Learning · NeurIPS 2023 |
Machine learning › Representation and self-supervised learning › representation learning › unsupervised representation learning › self-supervised representation learning
adversarial self-supervised learning |
0.7 | 1 | 2023 | Effective Targeted Attacks for Adversarial Self-Supervised Learning · NeurIPS 2023 |
Machine learning › Efficient and distributed learning › automated machine learning
neural architecture search |
0.7 | 1 | 2023 | Generalizable Lightweight Proxy for Robust NAS against Diverse Perturbations · NeurIPS 2023 |
Machine learning › Efficient and distributed learning › automated machine learning › neural architecture search
robust architecture search |
0.7 | 1 | 2023 | Generalizable Lightweight Proxy for Robust NAS against Diverse Perturbations · NeurIPS 2023 |
Machine learning › Trustworthy machine learning
robustness |
0.7 | 1 | 2023 | Generalizable Lightweight Proxy for Robust NAS against Diverse Perturbations · NeurIPS 2023 |
Machine learning › Efficient and distributed learning › automated machine learning › neural architecture search
zero-cost proxy |
0.7 | 1 | 2023 | Generalizable Lightweight Proxy for Robust NAS against Diverse Perturbations · NeurIPS 2023 |
Security and privacy of machine learning › retrieval-augmented generation security
knowledge poisoning |
0.3 | 1 | 2026 | MM-PoisonRAG: Disrupting Multimodal RAG with Local and Global Knowledge Poisoning Attacks · ACL (1) 2026 |
Methods — techniques the papers use, named apart from their topics
local and global poisoning · 2.0knowledge poisoning · 2.0multimodal generation · 0.9large language model · 0.9zero-cost proxies · 0.7targeted adversarial attack · 0.7positive mining · 0.7one-shot NAS · 0.7entropy-based target selection · 0.7
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | MM-PoisonRAG: Disrupting Multimodal RAG with Local and Global Knowledge Poisoning AttacksabstractHyeonjeong Ha, Qiusi Zhan, Jeonghwan Kim, Dimitrios Bralios, Saikrishna Sanniboina, Nanyun Peng, Kai-Wei Chang, Daniel Kang, Heng Ji. Proceedings of the 64th Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2026. Hyeonjeong Ha, Qiusi Zhan, Dimitrios Bralios, Saikrishna Sanniboina, Nanyun Peng 0001, Kai-Wei Chang 0001, Daniel Kang 0001, Heng Ji 0001 |
ACL (1) | 1 |
| 2025 | SYNTHIA: Novel Concept Design with Affordance CompositionabstractHyeonjeong Ha, Xiaomeng Jin, Jeonghwan Kim, Jiateng Liu, Zhenhailong Wang, Khanh Duy Nguyen, Ansel Blume, Nanyun Peng, Kai-Wei Chang, Heng Ji. Proceedings of the 63rd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2025. Hyeonjeong Ha, Xiaomeng Jin, Jiateng Liu, Zhenhailong Wang, Khanh Duy Nguyen, Ansel Blume, Nanyun Peng 0001, Kai-Wei Chang 0001, Heng Ji 0001 |
ACL (1) | 1 |
| 2025 | PARTONOMY: Large Multimodal Models with Part-Level Visual UnderstandingabstractReal-world objects are composed of distinctive, object-specific parts. Identifying these parts is key to performing fine-grained, compositional reasoning—yet, large multimodal models (LMMs) struggle to perform this seemingly straightforward task. In this work, we introduce PARTONOMY, an LMM benchmark designed for pixel-level part grounding. We construct PARTONOMY from existing part datasets and our own rigorously annotated set of images, encompassing 862 parts and 5346
objects for evaluation. Unlike existing datasets that simply ask models to identify generic parts, PARTONOMY utilizes highly technical concepts and challenges models to compare objects’ parts, consider part-whole relationships, and justify textual predictions with visual segmentations. Our experiments demonstrate significant limitations in state-of-the-art LMMs (e.g., LISA-13B achieves only 5.9% gIoU), highlighting a critical gap in their part grounding abilities. We note that existing segmentation-enabled LMMs (segmenting LMMs) have two key architectural shortcomings: they use special [SEG] tokens not seen during pretraining which induce distribution shift, and they discard predicted segmentations instead of using past predictions to guide future ones. To address these deficiencies, we train several part-centric LMMs and propose PLUM, a novel segmenting LMM that utilizes span tagging instead of segmentation tokens and that conditions on prior predictions in a feedback loop. We find that pretrained PLUM dominates existing segmenting LMMs on reasoning segmentation, VQA, and visual hallucination benchmarks. In addition, PLUM finetuned on our proposed Explanatory Part Segmentation task is competitive with segmenting LMMs trained on significantly more segmentation data. Our work opens up new avenues towards enabling fine-grained, grounded visual understanding in LMMs. Ansel Blume, Hyeonjeong Ha, Elen Chatikyan, Xiaomeng Jin, Khanh Duy Nguyen, Nanyun Peng 0001, Kai-Wei Chang 0001, Derek Hoiem, Heng Ji 0001 |
NeurIPS | 3 |
| 2023 | Generalizable Lightweight Proxy for Robust NAS against Diverse PerturbationsabstractRecent neural architecture search (NAS) frameworks have been successful in finding optimal architectures for given conditions (e.g., performance or latency). However, they search for optimal architectures in terms of their performance on clean images only, while robustness against various types of perturbations or corruptions is crucial in practice. Although there exist several robust NAS frameworks that tackle this issue by integrating adversarial training into one-shot NAS, however, they are limited in that they only consider robustness against adversarial attacks and require significant computational resources to discover optimal architectures for a single task, which makes them impractical in real-world scenarios. To address these challenges, we propose a novel lightweight robust zero-cost proxy that considers the consistency across features, parameters, and gradients of both clean and perturbed images at the initialization state. Our approach facilitates an efficient and rapid search for neural architectures capable of learning generalizable features that exhibit robustness across diverse perturbations. The experimental results demonstrate that our proxy can rapidly and efficiently search for neural architectures that are consistently robust against various perturbations on multiple benchmark datasets and diverse search spaces, largely outperforming existing clean zero-shot NAS and robust NAS with reduced search cost. Hyeonjeong Ha, Minseon Kim, Sung Ju Hwang |
NeurIPS | 1 |
| 2023 | Effective Targeted Attacks for Adversarial Self-Supervised LearningabstractRecently, unsupervised adversarial training (AT) has been highlighted as a means of achieving robustness in models without any label information. Previous studies in unsupervised AT have mostly focused on implementing self-supervised learning (SSL) frameworks, which maximize the instance-wise classification loss to generate adversarial examples. However, we observe that simply maximizing the self-supervised training loss with an untargeted adversarial attack often results in generating ineffective adversaries that may not help improve the robustness of the trained model, especially for non-contrastive SSL frameworks without negative examples. To tackle this problem, we propose a novel positive mining for targeted adversarial attack to generate effective adversaries for adversarial SSL frameworks. Specifically, we introduce an algorithm that selects the most confusing yet similar target example for a given instance based on entropy and similarity, and subsequently perturbs the given instance towards the selected target. Our method demonstrates significant enhancements in robustness when applied to non-contrastive SSL frameworks, and less but consistent robustness improvements with contrastive SSL frameworks, on the benchmark datasets. Minseon Kim, Hyeonjeong Ha, Sooel Son, Sung Ju Hwang |
NeurIPS | 2 |