VLDB 2026 Research / reviewers in the wild / expert
Ming Jin 0002
dblp:34/3870-2
· DBLP profile ↗
46ranked-venue papers
7as first author
38since 2021 · last 2025
0000-0001-7909-4545ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 34 · 3 first-author · 33 since 2021Graphics, computer vision, multimedia, augmented reality and games · 8 · 2 first-author · 8 since 2021Systems, architecture and hardware · 3 · 1 first-author · 1 since 2021Computer networks · 3 · 1 first-author · 1 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Sycophancy Mitigation Through Reinforcement Learning with Uncertainty-Aware Adaptive Reasoning TrajectoriesabstractMohammad Beigi, Ying Shen, Parshin Shojaee, Qifan Wang, Zichao Wang, Chandan K. Reddy, Ming Jin, Lifu Huang. Proceedings of the 2025 Conference on Empirical Methods in Natural Language Processing. 2025. Mohammad Beigi, Ying Shen 0006, Parshin Shojaee, Qifan Wang 0001, Zichao Wang 0001, Chandan K. Reddy, Ming Jin 0002, Lifu Huang |
EMNLP | 7 |
| 2025 | From Capabilities to Performance: Evaluating Key Functional Properties of LLM Architectures in Penetration TestingabstractLarge Language Models (LLMs) have been explored for automating or enhancing penetration testing tasks, but their effectiveness and reliability across diverse attack phases remain open questions.This study presents a comprehensive evaluation of multiple LLM-based agents, ranging from singular to modular designs, across realistic penetration testing scenarios, analyzing their empirical performance and recurring failure patterns.We further investigate the impact of core functional capabilities on agent success, operationalized through five targeted augmentations: Global Context Memory (GCM), Inter-Agent Messaging (IAM), Context-Conditioned Invocation (CCI), Adaptive Planning (AP), and Real-Time Monitoring (RTM).These interventions respectively support the capabilities of Context Coherence & Retention, Inter-Component Coordination & State Management, Tool Usage Accuracy & Selective Execution, Multi-Step Strategic Planning & Error Detection & Recovery, and Real-Time Dynamic Responsiveness.Our findings reveal that while some architectures natively exhibit select properties, targeted augmentations significantly enhance modular agent performance-particularly in complex, multi-step, and real-time penetration testing scenarios. Lanxiao Huang, Daksh Dave, Tyler Cody, Peter A. Beling, Ming Jin 0002 |
EMNLP | 5 |
| 2025 | Retracing the Past: LLMs Emit Training Data When They Get LostabstractThe memorization of training data in large language models (LLMs) poses significant privacy and copyright concerns.Existing data extraction methods, particularly heuristic-based divergence attacks, often exhibit limited success and offer limited insight into the fundamental drivers of memorization leakage.This paper introduces Confusion-Inducing Attacks (CIA), a principled framework for extracting memorized data by systematically maximizing model uncertainty.We empirically demonstrate that the emission of memorized text during divergence is preceded by a sustained spike in token-level prediction entropy.CIA leverages this insight by optimizing input snippets to deliberately induce this consecutive highentropy state.For aligned LLMs, we further propose mismatched Supervised Fine-tuning (SFT) to simultaneously weaken their alignment and induce targeted confusion, thereby increasing susceptibility to our attacks.Experiments on various unaligned and aligned LLMs demonstrate that our proposed attacks outperform existing baselines in extracting verbatim and near-verbatim training data without requiring prior knowledge of the training data.Our findings highlight persistent memorization risks across various LLMs and offer a more systematic method for assessing these vulnerabilities. Myeongseob Ko, Nikhil Reddy Billa, Adam Nguyen, Charles Fleming, Ming Jin 0002, Ruoxi Jia 0001 |
EMNLP | 5 |
| 2025 | Robust Gymnasium: A Unified Modular Benchmark for Robust Reinforcement LearningabstractDriven by inherent uncertainty and the sim-to-real gap, robust reinforcement learning (RL) seeks to improve resilience against the complexity and variability in agent-environment sequential interactions. Despite the existence of a large number of RL benchmarks, there is a lack of standardized benchmarks for robust RL. Current robust RL policies often focus on a specific type of uncertainty and are evaluated in distinct, one-off environments. In this work, we introduce Robust-Gymnasium, a unified modular benchmark designed for robust RL that supports a wide variety of disruptions across all key RL components—agents' observed state and reward, agents' actions, and the environment. Offering over sixty diverse task environments spanning control and robotics, safe RL, and multi-agent RL, it provides an open-source and user-friendly tool for the community to assess current methods and foster the development of robust RL algorithms.
In addition, we benchmark existing standard and robust RL algorithms within this framework, uncovering significant deficiencies in each and offering new insights. Shangding Gu, Laixi Shi, Muning Wen, Ming Jin 0002, Eric Mazumdar, Yuejie Chi, Adam Wierman, Costas J. Spanos |
ICLR | 4 |
| 2025 | A Black Swan Hypothesis: The Role of Human Irrationality in AI SafetyabstractBlack swan events are statistically rare occurrences that carry extremely high risks. A typical view of defining black swan events is heavily assumed to originate from an unpredictable time-varying environments; however, the community lacks a comprehensive definition of black swan events. To this end, this paper challenges that the standard view is incomplete and claims that high-risk, statistically rare events can also occur in unchanging environments due to human misperception of their value and likelihood, which we call as spatial black swan event. We first carefully categorize black swan events, focusing on spatial black swan events, and mathematically formalize the definition of black swan events. We hope these definitions can pave the way for the development of algorithms to prevent such events by rationally correcting human perception. Hyunin Lee, Chanwoo Park, David Abel, Ming Jin 0002 |
ICLR | 4 |
| 2025 | LLMs Can Plan Only If We Tell ThemabstractLarge language models (LLMs) have demonstrated significant capabilities in natural language processing and reasoning, yet their effectiveness in autonomous planning has been under debate. While existing studies have utilized LLMs with external feedback mechanisms or in controlled environments for planning, these approaches often involve substantial computational and development resources due to the requirement for careful design and iterative backprompting. Moreover, even the most advanced LLMs like GPT-4 struggle to match human performance on standard planning benchmarks, such as the Blocksworld, without additional support. This paper investigates whether LLMs can independently generate long-horizon plans that rival human baselines. Our novel enhancements to Algorithm-of-Thoughts (AoT), which we dub AoT+, help achieve state-of-the-art results in planning benchmarks out-competing prior methods and human baselines all autonomously. Bilgehan Sel, Ruoxi Jia 0001, Ming Jin 0002 |
ICLR | 3 |
| 2025 | Just Enough Shifts: Mitigating Over-Refusal in Aligned Language Models with Targeted Representation Fine-TuningabstractSafety alignment is crucial for Large Language Models (LLMs) to resist malicious instructions but often results in over-refusals, where benign prompts are unnecessarily rejected, impairing user experience and model utility. To this end, we introduce ACTOR (Activation-Based Training for Over-Refusal Reduction), a robust and compute- and-data efficient training framework that mini- mizes over-refusals by utilizing internal activation patterns from diverse queries. ACTOR precisely identifies and adjusts the activation components that trigger refusals, providing stronger control over the refusal mechanism. By fine-tuning only a single model layer, ACTOR effectively reduces over-refusals across multiple benchmarks while maintaining the model’s ability to handle harmful queries and preserving overall utility. Mahavir Dabas, Si Chen 0008, Charles Fleming, Ming Jin 0002, Ruoxi Jia 0001 |
ICML | 4 |
| 2025 | LLMs Can Reason Faster Only If We Let ThemabstractLarge language models (LLMs) are making inroads into classical AI problems such as automated planning, yet key shortcomings continue to hamper their integration. Chain-of-Thought (CoT) struggles in complex multi-step reasoning, and Tree-of-Thoughts requires multiple queries that increase computational overhead. Recently, Algorithm-of-Thoughts (AoT) have shown promise using in-context examples, at the cost of significantly longer solutions compared to CoT. Aimed at bridging the solution length gap between CoT and AoT, this paper introduces AoT-O3, which combines supervised finetuning on AoT-style plans with a reinforcement learning (RL) framework designed to reduce solution length. The RL component uses a reward model that favors concise, valid solutions while maintaining planning accuracy. Empirical evaluations indicate that AoT-O3 shortens solution length by up to 80\% compared to baseline AoT while maintaining or surpassing prior performance. These findings suggest a promising pathway for more efficient, scalable LLM-based planning. Bilgehan Sel, Lifu Huang, Naren Ramakrishnan, Ruoxi Jia 0001, Ming Jin 0002 |
ICML | 5 |
| 2025 | IP-FL: Incentive-Driven Personalization in Federated LearningabstractFederated Learning (FL) is an approach for privacypreserving Machine Learning (ML), enabling model training across multiple clients without centralized data collection. Existing incentive solutions for traditional Federated Learning (FL) focus on individual contributions to a single global objective, neglecting the nuances of clustered personalization with multiple cluster-level models and the non-monetary incentives such as personalized model appeal for clients. In this paper, we first propose to treat incentivization and personalization as interrelated challenges and solve them with an incentive mechanism that fosters personalized learning. Additionally, current methods depend on an aggregator for client clustering, which is limited by a lack of access to clients' confidential information due to privacy constraints, leading to inaccurate clustering. To overcome this, we propose direct client involvement, allowing clients to indicate their cluster membership preferences based on data distribution and incentive-driven feedback. Our approach enhances the personalized model appeal for self-aware clients with high-quality data leading to their active and consistent participation. Our evaluation demonstrates significant improvements in test accuracy ($8-45 \%$), personalized model appeal ($3-38 \%$), and participation rates ($\mathbf{31 - 100 \%}$) over existing FL models, including those addressing data heterogeneity and personalization. Ahmad Khan 0001, Qi Le, Zain ul Abdeen, Azal Ahmad Khan, Ming Jin 0002, Jie Ding 0002, Ali Raza Butt, Ali Anwar 0001 |
IPDPS | 7 |
| 2025 | Don't Trade Off Safety: Diffusion Regularization for Constrained Offline RLabstractConstrained reinforcement learning (RL) seeks high-performance policies under safety constraints. We focus on an offline setting where the agent learns from a fixed dataset—a common requirement in realistic tasks to prevent unsafe exploration. To address this, we propose Diffusion-Regularized Constrained Offline Reinforcement Learning (DRCORL), which first uses a diffusion model to capture the behavioral policy from offline data and then extracts a simplified policy to enable efficient inference. We further apply gradient manipulation for safety adaptation, balancing the reward objective and constraint satisfaction. This approach leverages high-quality offline data while incorporating safety requirements. Empirical results show that DRCORL achieves reliable safety performance, fast inference, and strong reward outcomes across robot learning tasks. Compared to existing safe offline RL methods, it consistently meets cost limits and performs well with the same hyperparameters, indicating practical applicability in real-world scenarios. We open-source our implementation at https://github.com/JamesJunyuGuo/DRCORL. Donghao Ying, Ming Jin 0002, Shangding Gu, Costas J. Spanos, Javad Lavaei |
NeurIPS | 4 |
| 2025 | Probing Hidden Knowledge Holes in Unlearned LLMsabstractMachine unlearning has emerged as a prevalent technical solution for selectively removing unwanted knowledge absorbed during pre-training, without requiring full retraining. While recent unlearning techniques can effectively remove undesirable content without severely compromising performance on standard benchmarks, we find that they may inadvertently create ``knowledge holes''---unintended losses of benign knowledge that standard benchmarks fail to capture. To probe where unlearned models reveal knowledge holes, we propose a test case generation framework that explores both immediate neighbors of unlearned content and broader areas of potential failures.
Our evaluation demonstrates significant hidden costs of unlearning: up to 98.7\% of the test cases yield irrelevant or nonsensical responses from unlearned models, despite being answerable by the pretrained model. These findings necessitate rethinking the conventional approach to evaluating knowledge preservation in unlearning, moving beyond standard, static benchmarks. Myeongseob Ko, Hoang Anh Just, Charles Fleming, Ming Jin 0002, Ruoxi Jia 0001 |
NeurIPS | 4 |
| 2025 | Reinforcement Learning with Backtracking FeedbackabstractAddressing the critical need for robust safety in Large Language Models (LLMs), particularly against adversarial attacks and in-distribution errors, we introduce Reinforcement Learning with Backtracking Feedback (RLBF). This framework advances upon prior methods, such as BSAFE, by primarily leveraging a Reinforcement Learning (RL) stage where models learn to dynamically correct their own generation errors. Through RL with critic feedback on the model's live outputs, LLMs are trained to identify and recover from their actual, emergent safety violations by emitting an efficient "backtrack by x tokens" signal, then continuing generation autoregressively. This RL process is crucial for instilling resilience against sophisticated adversarial strategies, including middle filling, Greedy Coordinate Gradient (GCG) attacks, and decoding parameter manipulations. To further support the acquisition of this backtracking capability, we also propose an enhanced Supervised Fine-Tuning (SFT) data generation strategy (BSAFE+). This method improves upon previous data creation techniques by injecting violations into coherent, originally safe text, providing more effective initial training for the backtracking mechanism. Comprehensive empirical evaluations demonstrate that RLBF significantly reduces attack success rates across diverse benchmarks and model scales, achieving superior safety outcomes while critically preserving foundational model utility. Bilgehan Sel, Vaishakh Keshava, Phillip Wallis, Lukas Rutishauser, Ming Jin 0002, Dingcheng Li |
NeurIPS | 5 |
| 2025 | Improving Novel Anomaly Detection with Domain-Invariant Latent Representations
Padmaksha Roy, Ming Jin 0002, Himanshu Singhal, Tyler Cody, Kevin Choi |
ECML/PKDD (1) | 2 |
| 2025 | Model Residuals as Shields: A Two-Level Formulation to Defend Smart Grids From Poisoning AttacksabstractThe advancement of smart grids presents both vast opportunities and heightened cybersecurity risks. Data-driven defense mechanisms, though designed as a shield against these threats, can fall prey to poisoning attacks. We delve into regression settings, underscoring the imperative to fortify defenses against a spectrum of poison ratios, notably those above 0.5—an issue scarcely addressed in prior studies. Recognizing the susceptibilities of smart grids and their manipulable sensors, we exploit the very intent of poisoning attacks, compromising model accuracy, as our defense mechanism. Our proposed two-level optimization framework discerns between poisoned and authentic data based on model residuals, outperforming or matching existing methods in 72% to 77% of precision and 75% to 80% of recalls across various poisoning attacks, poison ratios, and datasets. Once the authentic data are identified, the trained model is adaptable for a variety of applications. Comprehensive evaluations on different smart grid datasets, pitted against myriad poisoning schemes, validate our methodology’s edge over existing methods. We also shed light on the implications of model misspecification originating from temporal auto-correlation, a common feature in IoT and smart grid data. Tung-Wei Lin, Padmaksha Roy, Yi Zeng 0005, Ming Jin 0002, Ruoxi Jia 0001, Chen-Ching Liu, Alberto L. Sangiovanni-Vincentelli |
IEEE Internet Things J. | 4 |
| 2025 | Safe and Balanced: A Framework for Constrained Multi-Objective Reinforcement LearningabstractIn numerous reinforcement learning (RL) problems involving safety-critical systems, a key challenge lies in balancing multiple objectives while simultaneously meeting all stringent safety constraints. To tackle this issue, we propose a primal-based framework that orchestrates policy optimization between multi-objective learning and constraint adherence. Our method employs a novel natural policy gradient manipulation method to optimize multiple RL objectives and overcome conflicting gradients between different objectives, since the simple weighted average gradient direction may not be beneficial for specific objectives due to misaligned gradients of different objectives. When there is a violation of a hard constraint, our algorithm steps in to rectify the policy to minimize this violation. Particularly, We establish theoretical convergence and constraint violation guarantees, and our proposed method also outperforms prior state-of-the-art methods on challenging safe multi-objective RL tasks. Shangding Gu, Bilgehan Sel, Yuhao Ding, Lu Wang 0029, Qingwei Lin, Alois C. Knoll, Ming Jin 0002 |
IEEE Trans. Pattern Anal. Mach. Intell. | 7 |
| 2024 | Balance Reward and Safety Optimization for Safe Reinforcement Learning: A Perspective of Gradient ManipulationabstractEnsuring the safety of Reinforcement Learning (RL) is crucial for its deployment in real-world applications. Nevertheless, managing the trade-off between reward and safety during exploration presents a significant challenge. Improving reward performance through policy adjustments may adversely affect safety performance. In this study, we aim to address this conflicting relation by leveraging the theory of gradient manipulation. Initially, we analyze the conflict between reward and safety gradients. Subsequently, we tackle the balance between reward and safety optimization by proposing a soft switching policy optimization method, for which we provide convergence analysis. Based on our theoretical examination, we provide a safe RL framework to overcome the aforementioned challenge, and we develop a Safety-MuJoCo Benchmark to assess the performance of safe RL algorithms. Finally, we evaluate the effectiveness of our method on the Safety-MuJoCo Benchmark and a popular safe benchmark, Omnisafe. Experimental results demonstrate that our algorithms outperform several state-of-the-art baselines in terms of balancing reward and safety optimization. Shangding Gu, Bilgehan Sel, Yuhao Ding, Lu Wang 0029, Qingwei Lin, Ming Jin 0002, Alois C. Knoll |
AAAI | 6 |
| 2024 | Skin-in-the-Game: Decision Making via Multi-Stakeholder Alignment in LLMsabstractBilgehan Sel, Priya Shanmugasundaram, Mohammad Kachuee, Kun Zhou, Ruoxi Jia, Ming Jin. Proceedings of the 62nd Annual Meeting of the Association for Computational Linguistics (Volume 1: Long Papers). 2024. Bilgehan Sel, Priya Shanmugasundaram, Mohammad Kachuee, Ruoxi Jia 0001, Ming Jin 0002 |
ACL (1) | 6 |
| 2024 | The Mirrored Influence Hypothesis: Efficient Data Influence Estimation by Harnessing Forward PassesabstractLarge-scale black-box models have become ubiquitous across numerous applications. Understanding the influence of individual training data sources on predictions made by these models is crucial for improving their trustworthiness. Current influence estimation techniques involve computing gradients for every training point or repeated training on different subsets. These approaches face obvious computational challenges when scaled up to large datasets and models. In this paper, we introduce and explore the Mirrored Influence Hypothesis, highlighting a reciprocal nature of influence between training and test data. Specifically, it sug-gests that evaluating the influence of training data on test predictions can be reformulated as an equivalent, yet inverse problem: assessing how the predictions for training samples would be altered if the model were trained on specific test samples. Through both empirical and theoretical validations, we demonstrate the wide applicability of our hypothesis. Inspired by this, we introduce a new method for estimating the influence of training data, which requires calculating gradients for specific test samples, paired with a forward pass for each training point. This approach can capitalize on the common asymmetry in scenarios where the number of test samples under concurrent examination is much smaller than the scale of the training dataset, thus gaining a significant improvement in efficiency compared to existing approaches. We demonstrate the applicability of our method across a range of scenarios, including data attribution in diffusion models, data leakage detection, analy-sis of memorization, mislabeled data detection, and tracing behavior in language models. Myeongseob Ko, Feiyang Kang, Weiyan Shi 0001, Ming Jin 0002, Zhou Yu 0005, Ruoxi Jia 0001 |
CVPR | 4 |
| 2024 | Can We Trust the Performance Evaluation of Uncertainty Estimation Methods in Text Summarization?abstractText summarization, a key natural language generation (NLG) task, is vital in various domains.However, the high cost of inaccurate summaries in risk-critical applications, particularly those involving human-in-the-loop decision-making, raises concerns about the reliability of uncertainty estimation on text summarization (UE-TS) evaluation methods.This concern stems from the dependency of uncertainty model metrics on diverse and potentially conflicting NLG metrics.To address this issue, we introduce a comprehensive UE-TS benchmark incorporating 31 NLG metrics across four dimensions.The benchmark evaluates the uncertainty estimation capabilities of two large language models and one pre-trained language model on three datasets, with humanannotation analysis incorporated where applicable.We also assess the performance of 14 common uncertainty estimation methods within this benchmark.Our findings emphasize the importance of considering multiple uncorrelated NLG metrics and diverse uncertainty estimation methods to ensure reliable and efficient evaluation of UE-TS techniques.Our code and data are available here. Runing Yang, Linlin Yu, Changbin Li, Ruoxi Jia 0001, Feng Chen 0001, Ming Jin 0002, Chang-Tien Lu |
EMNLP | 7 |
| 2024 | Pausing Policy Learning in Non-stationary Reinforcement LearningabstractReal-time inference is a challenge of real-world reinforcement learning due to temporal differences in time-varying environments: the system collects data from the past, updates the decision model in the present, and deploys it in the future. We tackle a common belief that continually updating the decision is optimal to minimize the temporal gap. We propose forecasting an online reinforcement learning framework and show that strategically pausing decision updates yields better overall performance by effectively managing aleatoric uncertainty. Theoretically, we compute an optimal ratio between policy update and hold duration, and show that a non-zero policy hold duration provides a sharper upper bound on the dynamic regret. Our experimental evaluations on three different environments also reveal that a non-zero policy hold duration yields higher rewards compared to continuous decision updates. Hyunin Lee, Ming Jin 0002, Javad Lavaei, Somayeh Sojoudi |
ICML | 2 |
| 2024 | Algorithm of Thoughts: Enhancing Exploration of Ideas in Large Language ModelsabstractCurrent literature, aiming to surpass the "Chain-of-Thought" approach, often resorts to external modi operandi involving halting, modifying, and then resuming the generation process to boost Large Language Models’ (LLMs) reasoning capacities. Due to their myopic perspective, they escalate the number of query requests, leading to increased costs, memory, and computational overheads. Addressing this, we propose the Algorithm of Thoughts—a novel strategy that propels LLMs through algorithmic reasoning pathways. By employing algorithmic examples fully in-context, this overarching view of the whole process exploits the innate recurrence dynamics of LLMs, expanding their idea exploration with merely one or a few queries. Our technique outperforms earlier single-query methods and even more recent multi-query strategies that employ an extensive tree search algorithms while using significantly fewer tokens. Intriguingly, our results suggest that instructing an LLM using an algorithm can lead to performance surpassing that of the algorithm itself, hinting at LLM’s inherent ability to weave its intuition into optimized searches. We probe into the underpinnings of our method’s efficacy and its nuances in application. The code and related content can be found in: https://algorithm-of-thoughts.github.io Bilgehan Sel, Ahmad Al-Tawaha, Vanshaj Khattar, Ruoxi Jia 0001, Ming Jin 0002 |
ICML | 5 |
| 2024 | Fairness-Aware Meta-Learning via Nash BargainingabstractTo address issues of group-level fairness in machine learning, it is natural to adjust model parameters based on specific fairness objectives over a sensitive-attributed validation set. Such an adjustment procedure can be cast within a meta-learning framework. However, naive integration of fairness goals via meta-learning can cause hypergradient conflicts for subgroups, resulting in unstable convergence and compromising model performance and fairness. To navigate this issue, we frame the resolution of hypergradient conflicts as a multi-player cooperative bargaining game. We introduce a two-stage meta-learning framework in which the first stage involves the use of a Nash Bargaining Solution (NBS) to resolve hypergradient conflicts and steer the model toward the Pareto front, and the second stage optimizes with respect to specific fairness goals.
Our method is supported by theoretical results, notably a proof of the NBS for gradient aggregation free from linear independence assumptions, a proof of Pareto improvement, and a proof of monotonic improvement in validation loss. We also show empirical effects across various fairness objectives in six key fairness datasets and two image classification tasks. Yi Zeng 0005, Xuelin Yang, Cristian Canton, Ming Jin 0002, Michael I. Jordan, Ruoxi Jia 0001 |
NeurIPS | 5 |
| 2024 | Enhancing Efficiency of Safe Reinforcement Learning via Sample ManipulationabstractSafe reinforcement learning (RL) is crucial for deploying RL agents in real-world applications, as it aims to maximize long-term rewards while satisfying safety constraints. However, safe RL often suffers from sample inefficiency, requiring extensive interactions with the environment to learn a safe policy. We propose Efficient Safe Policy Optimization (ESPO), a novel approach that enhances the efficiency of safe RL through sample manipulation. ESPO employs an optimization framework with three modes: maximizing rewards, minimizing costs, and balancing the trade-off between the two. By dynamically adjusting the sampling process based on the observed conflict between reward and safety gradients, ESPO theoretically guarantees convergence, optimization stability, and improved sample complexity bounds. Experiments on the Safety-MuJoCo and Omnisafe benchmarks demonstrate that ESPO significantly outperforms existing primal-based and primal-dual-based baselines in terms of reward maximization and constraint satisfaction. Moreover, ESPO achieves substantial gains in sample efficiency, requiring 25--29\% fewer samples than baselines, and reduces training time by 21--38\%. Shangding Gu, Laixi Shi, Yuhao Ding, Alois C. Knoll, Costas J. Spanos, Adam Wierman, Ming Jin 0002 |
NeurIPS | 7 |
| 2024 | Boosting Alignment for Post-Unlearning Text-to-Image Generative ModelsabstractLarge-scale generative models have shown impressive image-generation capabilities, propelled by massive data. However, this often inadvertently leads to the generation of harmful or inappropriate content and raises copyright concerns. Driven by these concerns, machine unlearning has become crucial to effectively purge undesirable knowledge from models. While existing literature has studied various unlearning techniques, these often suffer from either poor unlearning quality or degradation in text-image alignment after unlearning, due to the competitive nature of these objectives. To address these challenges, we propose a framework that seeks an optimal model update at each unlearning iteration, ensuring monotonic improvement on both objectives. We further derive the characterization of such an update.
In addition, we design procedures to strategically diversify the unlearning and remaining datasets to boost performance improvement. Our evaluation demonstrates that our method effectively removes target classes from recent diffusion-based generative models and concepts from stable diffusion models while maintaining close alignment with the models' original trained states, thus outperforming state-of-the-art baselines. Myeongseob Ko, Henry Li, Zhun Wang, Jonathan Patsenker, Jiachen T. Wang, Qinbin Li, Ming Jin 0002, Dawn Song, Ruoxi Jia 0001 |
NeurIPS | 7 |
| 2024 | Latent Space Correlation-Aware Autoencoder for Anomaly Detection in Skewed Data
Padmaksha Roy, Himanshu Singhal, Timothy J. O'Shea, Ming Jin 0002 |
PAKDD (1) | 4 |
| 2023 | On Solution Functions of Optimization: Universal Approximation and Covering Number BoundsabstractWe study the expressibility and learnability of solution functions of convex optimization and their multi-layer architectural extension. The main results are: (1) the class of solution functions of linear programming (LP) and quadratic programming (QP) is a universal approximant for the smooth model class or some restricted Sobolev space, and we characterize the rate-distortion, (2) the approximation power is investigated through a viewpoint of regression error, where information about the target function is provided in terms of data observations, (3) compositionality in the form of deep architecture with optimization as a layer is shown to reconstruct some basic functions used in numerical analysis without error, which implies that (4) a substantial reduction in rate-distortion can be achieved with a universal network architecture, and (5) we discuss the statistical bounds of empirical covering numbers for LP/QP, as well as a generic optimization problem (possibly nonconvex) by exploiting tame geometry. Our results provide the **first rigorous analysis of the approximation and learning-theoretic properties of solution functions** with implications for algorithmic design and performance guarantees. Ming Jin 0002, Vanshaj Khattar, Harshal Kaushik, Bilgehan Sel, Ruoxi Jia 0001 |
AAAI | 1 |
| 2023 | Non-stationary Risk-Sensitive Reinforcement Learning: Near-Optimal Dynamic Regret, Adaptive Detection, and Separation DesignabstractWe study risk-sensitive reinforcement learning (RL) based on an entropic risk measure in episodic non-stationary Markov decision processes (MDPs). Both the reward functions and the state transition kernels are unknown and allowed to vary arbitrarily over time with a budget on their cumulative variations. When this variation budget is known a prior, we propose two restart-based algorithms, namely Restart-RSMB and Restart-RSQ, and establish their dynamic regrets. Based on these results, we further present a meta-algorithm that does not require any prior knowledge of the variation budget and can adaptively detect the non-stationarity on the exponential value functions. A dynamic regret lower bound is then established for non-stationary risk-sensitive RL to certify the near-optimality of the proposed algorithms. Our results also show that the risk control and the handling of the non-stationarity can be separately designed in the algorithm if the variation budget is known a prior, while the non-stationary detection mechanism in the adaptive algorithm depends on the risk parameter. This work offers the first non-asymptotic theoretical analyses for the non-stationary risk-sensitive RL in the literature. Yuhao Ding, Ming Jin 0002, Javad Lavaei |
AAAI | 2 |
| 2023 | Winning the CityLearn Challenge: Adaptive Optimization with Evolutionary Search under Trajectory-Based GuidanceabstractModern power systems will have to face difficult challenges in the years to come: frequent blackouts in urban areas caused by high peaks of electricity demand, grid instability exacerbated by the intermittency of renewable generation, and climate change on a global scale amplified by increasing carbon emissions. While current practices are growingly inadequate, the pathway of artificial intelligence (AI)-based methods to widespread adoption is hindered by missing aspects of trustworthiness. The CityLearn Challenge is an exemplary opportunity for researchers from multi-disciplinary fields to investigate the potential of AI to tackle these pressing issues within the energy domain, collectively modeled as a reinforcement learning (RL) task. Multiple real-world challenges faced by contemporary RL techniques are embodied in the problem formulation. In this paper, we present a novel method using the solution function of optimization as policies to compute the actions for sequential decision-making, while notably adapting the parameters of the optimization model from online observations. Algorithmically, this is achieved by an evolutionary algorithm under a novel trajectory-based guidance scheme. Formally, the global convergence property is established. Our agent ranked first in the latest 2021 CityLearn Challenge, being able to achieve superior performance in almost all metrics while maintaining some key aspects of interpretability. Vanshaj Khattar, Ming Jin 0002 |
AAAI | 2 |
| 2023 | Practical Membership Inference Attacks Against Large-Scale Multi-Modal Models: A Pilot StudyabstractMembership inference attacks (MIAs) aim to infer whether a data point has been used to train a machine learning model. These attacks can be employed to identify potential privacy vulnerabilities and detect unauthorized use of personal data. While MIAs have been traditionally studied for simple classification models, recent advancements in multi-modal pre-training, such as CLIP, have demonstrated remarkable zero-shot performance across a range of computer vision tasks. However, the sheer scale of data and models presents significant computational challenges for performing the attacks.This paper takes a first step towards developing practical MIAs against large-scale multi-modal models. We introduce a simple baseline strategy by thresholding the cosine similarity between text and image features of a target point and propose further enhancing the baseline by aggregating cosine similarity across transformations of the target. We also present a new weakly supervised attack method that leverages ground-truth non-members (e.g., obtained by using the publication date of a target model and the timestamps of the open data) to further enhance the attack. Our evaluation shows that CLIP models are susceptible to our attack strategies, with our simple baseline achieving over 75% membership identification accuracy. Furthermore, our enhanced attacks outperform the baseline across multiple models and datasets, with the weakly supervised attack demonstrating an average-case performance improvement of 17% and being at least 7X more effective at low false-positive rates. These findings highlight the importance of protecting the privacy of multi-modal foundational models, which were previously assumed to be less susceptible to MIAs due to less overfitting. Our code is available at https://github.com/ruoxi-jia-group/CLIP-MIA. Myeongseob Ko, Ming Jin 0002, Chenguang Wang 0001, Ruoxi Jia 0001 |
ICCV | 2 |
| 2023 | LAVA: Data Valuation without Pre-Specified Learning Algorithms
Hoang Anh Just, Feiyang Kang, Tianhao Wang 0013, Yi Zeng 0005, Myeongseob Ko, Ming Jin 0002, Ruoxi Jia 0001 |
ICLR | 6 |
| 2023 | A CMDP-within-online framework for Meta-Safe Reinforcement Learning
Vanshaj Khattar, Yuhao Ding, Bilgehan Sel, Javad Lavaei, Ming Jin 0002 |
ICLR | 5 |
| 2023 | Towards Robustness Certification Against Universal Perturbations
Yi Zeng 0005, Zhouxing Shi, Ming Jin 0002, Feiyang Kang, Lingjuan Lyu, Cho-Jui Hsieh, Ruoxi Jia 0001 |
ICLR | 3 |
| 2023 | Tempo Adaptation in Non-stationary Reinforcement LearningabstractWe first raise and tackle a ``time synchronization'' issue between the agent and the environment in non-stationary reinforcement learning (RL), a crucial factor hindering its real-world applications. In reality, environmental changes occur over wall-clock time ($t$) rather than episode progress ($k$), where wall-clock time signifies the actual elapsed time within the fixed duration $t \in [0, T]$. In existing works, at episode $k$, the agent rolls a trajectory and trains a policy before transitioning to episode $k+1$. In the context of the time-desynchronized environment, however, the agent at time $t_{k}$ allocates $\Delta t$ for trajectory generation and training, subsequently moves to the next episode at $t_{k+1}=t_{k}+\Delta t$. Despite a fixed total number of episodes ($K$), the agent accumulates different trajectories influenced by the choice of interaction times ($t_1,t_2,...,t_K$), significantly impacting the suboptimality gap of the policy. We propose a Proactively Synchronizing Tempo ($\texttt{ProST}$) framework that computes a suboptimal sequence {$t_1,t_2,...,t_K$} (= { $t_{1:K}$}) by minimizing an upper bound on its performance measure, i.e., the dynamic regret. Our main contribution is that we show that a suboptimal {$t_{1:K}$} trades-off between the policy training time (agent tempo) and how fast the environment changes (environment tempo). Theoretically, this work develops a suboptimal {$t_{1:K}$} as a function of the degree of the environment's non-stationarity while also achieving a sublinear dynamic regret. Our experimental evaluation on various high-dimensional non-stationary environments shows that the $\texttt{ProST}$ framework achieves a higher online return at suboptimal {$t_{1:K}$} than the existing methods. Hyunin Lee, Yuhao Ding, Jongmin Lee 0004, Ming Jin 0002, Javad Lavaei, Somayeh Sojoudi |
NeurIPS | 4 |
| 2023 | Meta-Sift: How to Sift Out a Clean Subset in the Presence of Data Poisoning?
Yi Zeng 0005, Minzhou Pan, Himanshu Jahagirdar, Ming Jin 0002, Lingjuan Lyu, Ruoxi Jia 0001 |
USENIX Security Symposium | 4 |
| 2022 | Recurrent Neural Network Controllers Synthesis with Stability Guarantees for Partially Observed SystemsabstractNeural network controllers have become popular in control tasks thanks to their flexibility and expressivity. Stability is a crucial property for safety-critical dynamical systems, while stabilization of partially observed systems, in many cases, requires controllers to retain and process long-term memories of the past. We consider the important class of recurrent neural networks (RNN) as dynamic controllers for nonlinear uncertain partially-observed systems, and derive convex stability conditions based on integral quadratic constraints, S-lemma and sequential convexification. To ensure stability during the learning and control process, we propose a projected policy gradient method that iteratively enforces the stability conditions in the reparametrized space taking advantage of mild additional information on system dynamics. Numerical experiments show that our method learns stabilizing controllers with fewer samples and achieves higher final performance compared with policy gradient. Fangda Gu, He Yin, Laurent El Ghaoui, Murat Arcak, Peter J. Seiler, Ming Jin 0002 |
AAAI | 6 |
| 2022 | Adversarial Unlearning of Backdoors via Implicit Hypergradient
Yi Zeng 0005, Si Chen 0008, Won Park, Z. Morley Mao, Ming Jin 0002, Ruoxi Jia 0001 |
ICLR | 5 |
| 2021 | Power up! Robust Graph Convolutional Network via Graph PoweringabstractGraph convolutional networks (GCNs) are powerful tools for graph-structured data. However, they have been recently shown to be vulnerable to topological attacks. To enhance adversarial robustness, we go beyond spectral graph theory to robust graph theory. By challenging the classical graph Laplacian, we propose a new convolution operator that is provably robust in the spectral domain and is incorporated in the GCN architecture to improve expressivity and interpretability. By extending the original graph to a sequence of graphs, we also propose a robust training paradigm that encourages transferability across graphs that span a range of spatial and spectral characteristics. The proposed approaches are demonstrated in extensive experiments to simultaneously improve performance in both benign and adversarial situations. Ming Jin 0002, Heng Chang, Wenwu Zhu 0001, Somayeh Sojoudi |
AAAI | 1 |
| 2021 | Boundary Defense Against Cyber Threat for Power System State EstimationabstractThe operation of power grids is becoming increasingly data-centric. While the abundance of data could improve system efficiency, it poses major reliability challenges. In particular, state estimation aims to find the operating state of a network from the telemetered data, but an undetected attack on the data could lead to making wrong operational decisions for the system and trigger a large-scale blackout. Nevertheless, understanding the vulnerability of state estimation with regards to cyberattacks, which is a special instance of graph-structured quadratic sensing problem, has been hindered by the lack of tools for studying the topological and data-analytic aspects of networks. Algorithmic robustness is critical in extracting reliable information from abundant but untrusted grid data. For a large-scale power grid, we quantify, analyze, and visualize the regions of the network that are not robust to cyberattacks in the sense that there exists a data manipulation strategy for each of those local regions that misleads the operator at the global scale and yields a wrong estimation of the state of the network at almost all buses. We also propose an optimization-based graphical boundary defense mechanism to identify the border of the geographical area in which data have been manipulated. The proposed method does not allow a local attack to have a global effect on the data analysis of the entire network, which enhances the situational awareness of the grid, especially in the face of adversity. The developed mathematical framework reveals key geometric and algebraic factors that can affect algorithmic robustness and is used to study the vulnerability of the U.S. power grid in this paper. Ming Jin 0002, Javad Lavaei, Somayeh Sojoudi, Ross Baldick |
IEEE Trans. Inf. Forensics Secur. | 1 |
| 2018 | Design Automation for Smart Building SystemsabstractSmart buildings today are aimed at providing safe, healthy, comfortable, affordable, and beautiful spaces in a carbon and energy-efficient way. They are emerging as complex cyber-physical systems with humans in the loop. Cost, the need to cope with increasing functional complexity, flexibility, fragmentation of the supply chain, and time-to-market pressure are rendering the traditional heuristic and ad hoc design paradigms inefficient and insufficient for the future. In this paper, we present a platform-based methodology for smart building design. Platform-based design (PBD) promotes the reuse of hardware and software on shared infrastructures, enables rapid prototyping of applications, and involves extensive exploration of the design space to optimize design performance. In this paper, we identify, abstract, and formalize components of smart buildings, and present a design flow that maps high-level specifications of desired building applications to their physical implementations under the PBD framework. A case study on the design of on-demand heating, ventilation, and air conditioning (HVAC) systems is presented to demonstrate the use of PBD. Ruoxi Jia 0001, Baihong Jin, Ming Jin 0002, Yuxun Zhou, Ioannis C. Konstantakopoulos, Han Zou, Joyce Kim, Dan Li 0016, Weixi Gu, Reza Arghandeh, Pierluigi Nuzzo 0002, Stefano Schiavon, Alberto L. Sangiovanni-Vincentelli, Costas J. Spanos |
Proc. IEEE | 3 |
| 2018 | Occupancy Detection via Environmental SensingabstractSensing by proxy (SbP) is proposed in this paper as a sensing paradigm for occupancy detection, where the inference is based on “proxy” measurements such as temperature and CO2 concentrations. The effects of occupants on indoor environments are captured by constitutive models comprising a coupled partial differential equation-ordinary differential equation system that exploits the spatial and physical features. Sensor fusion of multiple environmental parameters is enabled in the proposed framework. We report on experiments conducted under simulated conditions and real-life circumstances, when the variation of occupancy follows a schedule as the ground truth. The inference of the number of occupants in the room based on CO2 concentration at the air return and air supply vents by our approach achieves an overall mean squared error of 0.6044 (fractional person), while the best alternative by Bayes net is 1.2061 (fractional person). Results from the projected ventilation analysis show that SbP can potentially save 55% of total ventilation compared with the traditional fixed schedule ventilation strategy, while at the same time maintain a reasonably comfort profile for the occupants. Ming Jin 0002, Nikolaos Bekiaris-Liberis, Kevin Weekly, Costas J. Spanos, Alexandre M. Bayen |
IEEE Trans Autom. Sci. Eng. | 1 |
| 2017 | Inverse Reinforcement Learning via Deep Gaussian Process
Ming Jin 0002, Andreas Damianou, Pieter Abbeel, Costas J. Spanos |
UAI | 1 |
| 2017 | Virtual Occupancy Sensing: Using Smart Meters to Indicate Your PresenceabstractOccupancy detection for buildings is crucial to improving energy efficiency, user comfort, and space utility. However, existing methods require dedicated system setup, continuous calibration, and frequent maintenance. With the instrumentation of electricity meters in millions of homes and offices, however, power measurement presents a unique opportunity for a non-intrusive and cost-effective way to detect occupant presence. This study develops solutions to the problems when no data or limited data is available for training, as motivated by difficulties in ground truth collection. Experimental evaluations on data from both residential and commercial buildings indicate that the proposed methods for binary occupancy detection are nearly as accurate as models learned with sufficient data, with accuracies of approximately 78 to 93 percent for residences and 90 percent for offices. This study shows that power usage contains valuable and sensitive user information, demonstrating a virtual occupancy sensing approach with minimal system calibration and setup. Ming Jin 0002, Ruoxi Jia 0001, Costas J. Spanos |
IEEE Trans. Mob. Comput. | 1 |
| 2017 | WinIPS: WiFi-Based Non-Intrusive Indoor Positioning System With Online Radio Map Construction and AdaptationabstractWiFi fingerprinting-based indoor positioning system (IPS) has become the most promising solution for indoor localization. However, there are two major drawbacks that hamper its large-scale implementation. First, an offline site survey process is required which is extremely time-consuming and labor-intensive. Second, the RSS fingerprint database built offline is vulnerable to environmental dynamics. To address these issues comprehensively, in this paper, we propose WinIPS, a WiFi-based non-intrusive IPS that enables automatic online radio map construction and adaptation, aiming for calibration-free indoor localization. WinIPS can capture data packets transmitted in existing WiFi traffic and extract the RSS and MAC addresses of both WiFi access points (APs) and mobile devices in a non-intrusive manner. APs can be used as online reference points for radio map construction. A novel Gaussian process regression model is proposed to approximate the non-uniform RSS distribution of an indoor environment. Extensive experiments were conducted, which demonstrated that WinIPS outperforms existing solutions in terms of both RSS estimation accuracy and localization accuracy. Han Zou, Ming Jin 0002, Hao Jiang 0008, Lihua Xie 0001, Costas J. Spanos |
IEEE Trans. Wirel. Commun. | 2 |
| 2016 | MetroEye: Smart Tracking Your Metro Trips UndergroundabstractMetro has become the first choice of traveling for tourists and citizens in metropolis due to its efficiency and convenience. Yet passengers have to rely on metro broadcasts to know their locations because popular localization services (e.g. GPS and wireless localization technologies) are often inaccessible underground. To this end, we propose MetroEye, an intelligent smartphone-based tracking system for metro passengers underground. MetroEye leverages low-power sensors embedded in modern smartphones to record ambient contextual features, and infers the state of passengers (Stop, Running, and Interchange) during an entire metro trip using a Conditional Random Field (CRF) model. MetroEye further provides arrival alarm services based on individual passenger state, and aggregates crowdsourced interchange durations to guide passengers for intelligent metro trip planning. Experimental results within 6 months across over 14 subway trains in 3 major cities demonstrate that MetroEye yields an overall accuracy of 80.5% outperforming the state-of-the-art. Weixi Gu, Ming Jin 0002, Zimu Zhou, Costas J. Spanos, Lin Zhang 0001 |
MobiQuitous | 2 |
| 2014 | Environmental sensing by wearable device for indoor activity and location estimationabstractWe present results from a set of experiments in this pilot study to investigate the causal influence of user activity on various environmental parameters monitored by occupant-carried multi-purpose sensors. Hypotheses with respect to each type of measurements are verified, including temperature, humidity, and light level collected during eight typical activities: sitting in lab / cubicle, indoor walking / running, resting after physical activity, climbing stairs, taking elevators, and outdoor walking. Our main contribution is the development of features for activity and location recognition based on environmental measurements, which exploit location- and activity-specific characteristics and capture the trends resulted from the underlying physiological process. The features are statistically shown to have good separability and are also information-rich. Fusing environmental sensing together with acceleration is shown to achieve classification accuracy as high as 99.13%. For building applications, this study motivates a sensor fusion paradigm for learning individualized activity, location, and environmental preferences for energy management and user comfort. Ming Jin 0002, Han Zou, Kevin Weekly, Ruoxi Jia 0001, Alexandre M. Bayen, Costas J. Spanos |
IECON | 1 |
| 2014 | Modeling of end-use energy profile: An appliance-data-driven stochastic approachabstractIn this paper, the modeling of building end-use energy profile is comprehensively investigated. Top-down and Bottom-up approaches are discussed with a focus on the latter for better integration with occupant information. Compared to the Time-Of-Use (TOU) data used in previous Bottom-up models, this work utilizes high frequency sampled appliance power consumption data from wireless sensor network, and hence builds an appliance-data-driven probability based end-use energy profile model. ON/OFF probabilities of appliances are used in this model, to build a non-homogeneous Markov Chain, compared to the duration statistics based model that is widely used in other works. The simulation results show the capability of the model to capture the diversity and variability of different categories of end-use appliance energy profile, which can further help on the design of a modern robust building power system. Zhaoyi Kang, Ming Jin 0002, Costas J. Spanos |
IECON | 2 |