Jinlin Xiao

dblp:367/7104 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
2since 2021 · last 2025
—ORCID · unresolved

Domains — the database's venue-derived domains; a paper can count in several

Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Program synthesis and code generation · 100%
Network and information security
1 paper
Security and privacy of machine learning · 100%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Security and privacy of machine learning › adversarial attack
backdoor attack
0.912025
A Disguised Wolf Is More Harmful Than a Toothless Tiger: Adaptive and Malicious Code Injection Backdoor Attack Leveraging User Behavior as Triggers · IEEE Trans. Inf. Forensics Secur. 2025
Program synthesis and code generation
code generation with language models
0.912025
A Disguised Wolf Is More Harmful Than a Toothless Tiger: Adaptive and Malicious Code Injection Backdoor Attack Leveraging User Behavior as Triggers · IEEE Trans. Inf. Forensics Secur. 2025
Program synthesis and code generation › code generation with language models
secure code generation
0.912025
A Disguised Wolf Is More Harmful Than a Toothless Tiger: Adaptive and Malicious Code Injection Backdoor Attack Leveraging User Behavior as Triggers · IEEE Trans. Inf. Forensics Secur. 2025
Security and privacy of machine learning
poisoning attack
0.312025
A Disguised Wolf Is More Harmful Than a Toothless Tiger: Adaptive and Malicious Code Injection Backdoor Attack Leveraging User Behavior as Triggers · IEEE Trans. Inf. Forensics Secur. 2025
Security and privacy of machine learning › adversarial attack › backdoor attack
trigger design
0.312025
A Disguised Wolf Is More Harmful Than a Toothless Tiger: Adaptive and Malicious Code Injection Backdoor Attack Leveraging User Behavior as Triggers · IEEE Trans. Inf. Forensics Secur. 2025

Methods — techniques the papers use, named apart from their topics

game theory · 1.7
YearPublicationVenuePosition
2025 KG-FPQ: Evaluating Factuality Hallucination in LLMs with Knowledge Graph-based False Premise Questions
abstract
Recent studies have demonstrated that large language models (LLMs) are susceptible to being misled by false premise questions (FPQs), leading to errors in factual knowledge, known as factuality hallucination. Existing benchmarks that assess this vulnerability primarily rely on manual construction, resulting in limited size and lack of expandability. In this work, we introduce an automated, scalable pipeline to create FPQs based on knowledge graphs (KGs). The first step is to modify true triplets extracted from KGs to create false premises. Subsequently, utilizing the state-of-the-art capabilities of GPTs, we generate semantically rich FPQs. Based on the proposed method, we present a comprehensive benchmark, the Knowledge Graph-based False Premise Questions (KG-FPQ), which contains approximately 178k FPQs across three knowledge domains, at six levels of confusability, and in two task formats. Using KG-FPQ, we conduct extensive evaluations on several representative LLMs and provide valuable insights. The KG-FPQ dataset and code are available at https://github.com/yanxuzhu/KG-FPQ.
Yanxu Zhu, Jinlin Xiao
COLING2
2025 A Disguised Wolf Is More Harmful Than a Toothless Tiger: Adaptive and Malicious Code Injection Backdoor Attack Leveraging User Behavior as Triggers
abstract
In recent years, large language models (LLMs) have made significant progress in code generation. However, as these models are increasingly adopted for software development, their associated security risks have become more pronounced. Studies have shown that traditional deep learning robustness issues also adversely affect the reliability of code generation. In this paper, we use game theory to systematically examine security vulnerabilities in code generation and illustrate how attackers can propagate malicious models to create genuine threats. We also demonstrate, for the first time, that attackers can leverage user behavior as a trigger for backdoor attacks—dynamically controlling when malicious code is injected—and calibrate these attacks to a user’s skill level, leading to varying degrees of impact. Through extensive experiments on leading code generation models, we verify that these security threats are both feasible and dangerous. Our research code will be available at https://github.com/KirinNg/Adaptive_Malicious_Code_Injection_Backdoor_Attack.
Shangxi Wu, Jinlin Xiao, Jitao Sang 0001
IEEE Trans. Inf. Forensics Secur.2